* [PATCH 7.2 000/457] 7.2.9-rc1 review
@ 2026-09-30 15:21 Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 001/457] drm/amd/display: Atomize IRQ register read/modify/write ops Greg Kroah-Hartman
` (467 more replies)
0 siblings, 468 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 7.2.9 release.
There are 457 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 7.2.9-rc1
Shengzhuo Wei <me@cherr.cc>
i2c: qcom-geni: release DMA channels on probe error
Karol Wachowski <karol.wachowski@linux.intel.com>
accel/ivpu: Drop IRQF_ONESHOT to allow IPC IRQ threading on PREEMPT_RT
Sean Christopherson <seanjc@google.com>
KVM: x86: Add static calls for nested virtualization ops
Sean Christopherson <seanjc@google.com>
KVM: x86: Reject nested CAP enablement if nested virtualization is disabled
Paolo Bonzini <pbonzini@redhat.com>
KVM: move TSS constants from kvm_host.h to tss.h
Sean Christopherson <seanjc@google.com>
KVM: x86/mmu: Move kvm_mmu_do_page_fault() from mmu_internal.h => mmu.c
Sean Christopherson <seanjc@google.com>
KVM: x86/mmu: Move kvm_arch_async_page_ready() below kvm_tdp_page_fault()
Sean Christopherson <seanjc@google.com>
KVM: x86: Move IRQ-related helper declarations from kvm_host.h => irq.h
Marc Zyngier <maz@kernel.org>
KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction
Marc Zyngier <maz@kernel.org>
KVM: arm64: nv: Fix life cycle of the nested_mmus array
Ilya Maximets <i.maximets@ovn.org>
net/sched: act_ct: avoid modifying shared unconfirmed ct entry
Ilya Maximets <i.maximets@ovn.org>
net/sched: act_ct: fix helper UAF due to extensions realloc
Alex Hung <alex.hung@amd.com>
drm/amd/display: Relax DML frame limit with UBSAN
Christian Brauner <brauner@kernel.org>
super: make iterate_supers_type() deletion-safe
Christian Brauner <brauner@kernel.org>
super: take lock after last reference count
Christian Brauner <brauner@kernel.org>
super: convert s_count to refcount_t s_passive
Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL
Praveen Talari <praveen.talari@oss.qualcomm.com>
i2c: qcom-geni: Store of_device_id data in driver private struct
Praveen Talari <praveen.talari@oss.qualcomm.com>
i2c: qcom-geni: Move resource initialization to separate function
Praveen Talari <praveen.talari@oss.qualcomm.com>
i2c: qcom-geni: Isolate serial engine setup
Jakub Pawlak <jakub.pawlak@intel.com>
accel/ivpu: Use separate flag for job timeout
Karol Wachowski <karol.wachowski@linux.intel.com>
accel/ivpu: Use threaded IRQ for IPC callback processing
Arnd Bergmann <arnd@arndb.de>
landlock: Work around gcc-16 -Wuninitialized warning
Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms
Darrick J. Wong <djwong@kernel.org>
xfs: fix cursor and pointer handling when recovering iunlink buckets
Darrick J. Wong <djwong@kernel.org>
xfs: fix blockgc group quota scanning when usrquota isn't enforced
Darrick J. Wong <djwong@kernel.org>
xfs: drop dquot flush lock when we can't find a buffer to flush
Darrick J. Wong <djwong@kernel.org>
xfs: don't merge different file IO error types
Darrick J. Wong <djwong@kernel.org>
xfs: don't let memory failures leak blocks and kill repairs
Darrick J. Wong <djwong@kernel.org>
xfs: don't let hidden_space go negative in xfs_metafile_resv_init
Darrick J. Wong <djwong@kernel.org>
xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits
Darrick J. Wong <djwong@kernel.org>
xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots
Darrick J. Wong <djwong@kernel.org>
xfs: fix rtgroup repair estimations
Darrick J. Wong <djwong@kernel.org>
xfs: check di_forkoff correctly in scrub
Darrick J. Wong <djwong@kernel.org>
xfs: use the correct reservations for rtrmap/refcount recovery
Darrick J. Wong <djwong@kernel.org>
xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks
Darrick J. Wong <djwong@kernel.org>
xfs: don't call xfs_exchange_range_finish for a dry run
Darrick J. Wong <djwong@kernel.org>
xfs: check padding field in xfs_ioc_commit_range
Darrick J. Wong <djwong@kernel.org>
xfs: use correct jiffies comparison function in xchk_maybe_relax
Darrick J. Wong <djwong@kernel.org>
xfs: release orphanage dir inode if chown fails
Darrick J. Wong <djwong@kernel.org>
xfs: fix attr fork block count checks in xrep_inode_blockcounts
Darrick J. Wong <djwong@kernel.org>
xfs: don't assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption
Adarsh Das <adarshdas950@gmail.com>
smb: client: delete compound mids on send failure before unlock
Zihan Xi <zihanx@nebusec.ai>
smb: client: close completed creates on compound wait errors
Zihan Xi <zihanx@nebusec.ai>
smb: client: validate POSIX create context length
Namjae Jeon <linkinjeon@kernel.org>
smb: client: use finish_no_open() for non-regular inodes
Zihan Xi <zihanx@nebusec.ai>
smb: client: preserve create-context parsing errors
Zihan Xi <zihanx@nebusec.ai>
smb: client: clean up failed cached directory opens
Zihan Xi <zihanx@nebusec.ai>
smb: client: close handle after create-context parsing failure
Zihan Xi <zihanx@nebusec.ai>
smb: client: fix create context out-of-bounds reads
Hui Peng <benquike@gmail.com>
Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: mgmt: fix race in read_unconf_index_list()
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: L2CAP: validate frame length before control and FCS access
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: ISO: release unused CIS holds after channel attach
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: ISO: balance the parent hold in hci_bind_bis()
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_sock: reject out-of-range OCF values
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_sock: validate event length before filtering
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_conn: fix CIS hold ownership on reuse
Davi Chaves Azevedo <davichazbh@gmail.com>
sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug
Tim Chen <tim.c.chen@linux.intel.com>
sched/cache: Decouple sched_cache_group from mm to fix UAF
Tejun Heo <tj@kernel.org>
sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags
Tan Chi <tanchi25@mails.ucas.ac.cn>
RISC-V: KVM: Fix HSM hart status error propagation
Xie Bo <xb@ultrarisc.com>
RISC-V: KVM: Propagate interrupted G-stage faults
Xie Bo <xb@ultrarisc.com>
RISC-V: KVM: Release unused page after MMU invalidation
Myeonghun Pak <mhun512@gmail.com>
RISC-V: KVM: Synchronize hrtimer callback during teardown
Xie Bo <xb@ultrarisc.com>
RISC-V: KVM: Serialize IMSIC attributes with vCPU migration
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Transfer the hyp stack pages out of the host stage-2
Lorenzo Stoakes (ARM) <ljs@kernel.org>
KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race
Lorenzo Stoakes (ARM) <ljs@kernel.org>
KVM: arm64: Fix spurious warning for benign stage 2 teardown race
Karl Mehltretter <kmehltretter@gmail.com>
KVM: arm64: Fix AArch32 DBGBXVR<n> handling
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Don't WARN on an unknown VM ioctl in protected mode
Sean Christopherson <seanjc@google.com>
KVM: SEV: Do cache maintenance on the source VM during intra-host migration
Sean Christopherson <seanjc@google.com>
KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV
Zeng Chi <zengchi@kylinos.cn>
KVM: Don't treat reserved xarray entries as having memory attributes
David Ballesteros <davimaba.v@proton.me>
KVM: Ensure memory attributes xarray nodes are accounted to the caller's memcg
Anthony Krowiak <akrowiak@linux.ibm.com>
s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config
Niklas Schnelle <schnelle@linux.ibm.com>
s390/pci: Don't report recovery success on skipped recovery
Niklas Schnelle <schnelle@linux.ibm.com>
s390/pci: Report SCLP status on error events when no pdev is associated
Niklas Schnelle <schnelle@linux.ibm.com>
s390/pci: Fix missing device lock in zpci_report_status()
Niklas Schnelle <schnelle@linux.ibm.com>
s390/pci: Fix leak of struct pci_dev reference in zpci_report_status()
Peter Oberparleiter <oberpar@linux.ibm.com>
s390/cmf: Fix virtual vs physical address confusion
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()
Ilya Titov <ilya.titov@wirenboard.com>
pinctrl: sunxi: keep a shadow copy of the data register output latches
Myeonghun Pak <mhun512@gmail.com>
pinctrl: single: free the IRQ on domain creation failure
Shawn Guo <shengchao.guo@oss.qualcomm.com>
pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions
Conor Dooley <conor.dooley@microchip.com>
pinctrl: mpfs-mssio: use correct regmap function to set bank voltage
Conor Dooley <conor.dooley@microchip.com>
pinctrl: mpfs-mssio: fix width of unused bank voltage setting
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
Puranjay Mohan <puranjay@kernel.org>
perf/core: Run sched_task() for PMUs with only CPU-wide events
Puranjay Mohan <puranjay@kernel.org>
perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
Zhenghui Hao <zhenghui.hao@qq.com>
parisc: parse early parameters in setup_arch()
Helge Deller <deller@gmx.de>
parisc: Increase kernel stack size to 32kb
Geert Uytterhoeven <geert+renesas@glider.be>
scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction
Stanley Jhu <stanleyjhu@google.com>
scsi: ufs: core: Keep internal commands dispatchable during error handling
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
scsi: libiscsi_tcp: Check the data direction of a Data-In PDU
Myeonghun Pak <mhun512@gmail.com>
nfc: trf7970a: power down on startup RX gain failure
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: port100: reject frames whose declared length exceeds the received data
Aamir Ahmed <elb12345@hotmail.co.uk>
nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()
Luxiao Xu <rakukuip@gmail.com>
nfc: fix use-after-free in nfc_get_local_general_bytes
Aohan Mei <henrymei@tencent.com>
netfilter: nf_tables: skip expired catchall elements on insert and delete
Luxiao Xu <rakukuip@gmail.com>
netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
Weiming Shi <bestswngs@gmail.com>
netfilter: ip6t_rpfilter: reject routes without inet6_dev
Wentao Liang <vulab@iscas.ac.cn>
net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
Ming Wang <wangming01@loongson.cn>
net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist
Zhang Yunfei <zhangyunfei1@kylinos.cn>
net: txgbe: fix FDIR filter restore for VF rules
Abhishek Ojha <abhishek.ojha@savoirfairelinux.com>
net: phy: micrel: Advance register data pointer in write loop
Alexander Sverdlin <alexander.sverdlin@siemens.com>
net: phy: intel-xway: workaround 100BASE-TX Link-Up issue
Guangshuo Li <lgs201920130244@gmail.com>
net: ena: fix MMIO read buffer leak on probe failure
Guangshuo Li <lgs201920130244@gmail.com>
net: ena: fix PHC cleanup on probe failure
Fourie Zhang <littleddfu@gmail.com>
net: bridge: mdb: restart port group walk after deletion
Gajdos Tamás <tamas@rimpianto.com>
net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read
Gajdos Tamás <tamas@rimpianto.com>
net: atl1c: fix soft lockup on out-of-range tpd_cons read
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: fix helper UAF due to extensions realloc
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: remove 'add_helper' dead code
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
Théo Lebrun <theo.lebrun@bootlin.com>
net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths
Yuqi Xu <xuyuqiabc@gmail.com>
net: ipconfig: bound DHCP option construction
Wentao Liang <vulab@iscas.ac.cn>
net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()
Gajdos Tamás <tamas@rimpianto.com>
net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read
Zijie Huang <milkory@outlook.com>
net: arp: terminate device name before lookup
Myeonghun Pak <mhun512@gmail.com>
net: airoha: npu: cancel wdt_work after releasing the WDT IRQ
Weiming Shi <bestswngs@gmail.com>
net/sched: reject IDR error pointers when deleting actions
Andrea Parri <parri.andrea@gmail.com>
net/mlx5e: fix swapped IPv6 IPsec policy masks
Ralf Lici <ralf@mandelbit.com>
net/mlx5e: advertise MACsec offload only when supported
Wentao Liang <vulab@iscas.ac.cn>
net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()
Wei Jie LAW <98lawweijie@gmail.com>
HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
Junjie Cao <junjie.cao@intel.com>
HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
Tristan Madani <tristan@talencesecurity.com>
HID: hid-oxp: use cancel_delayed_work_sync() in remove
Chen Changcheng <chenchangcheng@kylinos.cn>
HID: alps: fix use-after-free on input2 registration failure
Chen Changcheng <chenchangcheng@kylinos.cn>
HID: alps: unregister DualPoint Stick input device on remove
Willem de Bruijn <willemb@google.com>
packet: use ubuf_info completion for TX_RING packets
Angel J <iamanaws@httpd.dev>
PCI: of_property: Omit bus properties without a subordinate bus
Liz Fong-Jones <lizf@honeycomb.io>
PCI: Fix BAR resize for devices on a root bus
SJ Park <sj@kernel.org>
mm/damon/core: reset invalid quota->charge_target_from
Liew Rui Yan <aethernet65535@gmail.com>
mm/damon/core: allow esz to be set to zero
Liew Rui Yan <aethernet65535@gmail.com>
mm/damon/core: fix unconditionally skip last region
Nathan Gao <zcgao@amazon.com>
mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()
SJ Park <sj@kernel.org>
mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
Jaewook You <jaewook376@gmail.com>
mm/hugetlb: preserve mremap address delta when skipping page tables
Longlong Xia <xialonglong@kylinos.cn>
mm/hugetlb: do not dissolve gigantic pages without runtime support
Jinjiang Tu <tujinjiang@huawei.com>
mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
Karl Mehltretter <kmehltretter@gmail.com>
gpio: tps65219: Fix TPS65214 GPIO direction programming
Karl Mehltretter <kmehltretter@gmail.com>
gpio: tps65219: Use the variant-specific direction callback
Karl Mehltretter <kmehltretter@gmail.com>
gpio: tps65219: Fix GPIO input value reads
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/virtio: fix NULL pointer dereference on fence allocation failure
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/virtio: fix memory leak of fence event on execbuffer failure
Matthew Brost <matthew.brost@intel.com>
drm/xe: Keep walking on SVM eviction failure
Szymon Acedański <accek@invisiblethingslab.com>
drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV
Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
drm/xe: harden adjust_idledly() against divide-by-zero and overflow
Matthew Auld <matthew.auld@intel.com>
drm/xe/vm: nuke PTs only after unlinking contested VMAs
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau: don't bump pin count on failed re-pin in nouveau_bo_pin_locked()
Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
drm/nouveau: RCU-free the scheduler-containing nouveau_sched
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix runtime PM leak in nouveau_connector_detect()
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix gem reference leak in validate_init()
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau: fix double-free in nvif_vmm_dtor
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix bridge reference leak in nv1a_ram_new()
Guangshuo Li <lgs201920130244@gmail.com>
drm/nouveau: fix autosuspend cleanup during teardown
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM
Junrui Luo <moonafterrain@outlook.com>
drm/nouveau/dmem: pin VRAM for the whole registered range
Prike Liang <Prike.Liang@amd.com>
drm/amdgpu: move userq fence wait out of signalling section
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc()
Sunil Khatri <sunil.khatri@amd.com>
drm/amdgpu/vcn5.0.1: fix video_timeout unit mismatch in jpeg reset wait
Sunil Khatri <sunil.khatri@amd.com>
drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait
Sunil Khatri <sunil.khatri@amd.com>
drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout
Ivan Lipski <ivan.lipski@amd.com>
drm/amd/display: Bump frame warning limit for clang builds of dml
Wentao Liang <vulab@iscas.ac.cn>
drm/amd/display: Fix dc stream excess put in dm_update_crtc_state()
Asad Kamal <asad.kamal@amd.com>
drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping
Imre Deak <imre.deak@intel.com>
drm/i915/dp_mst: Fix configuring TUs for a disconnected stream
Imre Deak <imre.deak@intel.com>
drm/i915/dp_mst: Fix configuring FEC for a disconnected stream
Ankit Nautiyal <ankit.k.nautiyal@intel.com>
drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1
Christian König <ckoenig.leichtzumerken@gmail.com>
drm/i915: fix incorrect RCU teardown order
Brajesh Gupta <brajesh.gupta@imgtec.com>
drm/imagination: Fix page count for page table for map() interface
Brajesh Gupta <brajesh.gupta@imgtec.com>
drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl()
shechenglong <shechenglong@xfusion.com>
drm/client: fix restore of partially initialized client
Dongliang Qin <cccccccccccc777777@gmail.com>
rds: ib: Clear the sg list when mapping an MR fails
Hui Peng <benquike@gmail.com>
mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag()
Zixuan Chai <petalzu987@gmail.com>
llc: reserve device headroom for allocated frames
Ridham Khurana <khurana.ridham222@gmail.com>
gpio: zynq: fix runtime PM leak on request error path
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
gpio: cdev: fix kernel stack leak to user-space in error path
Wentao Liang <vulab@iscas.ac.cn>
gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()
Andrea Parri <parri.andrea@gmail.com>
kprobes: Fix permanent hang when flushing the kprobe optimizer
Hui Peng <benquike@gmail.com>
ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST
Norbert Szetei <norbert@doyensec.com>
ipv6: do not let ipv6_find_hdr() return an offset past the packet end
Fan Wu <wufan@kernel.org>
ipe: protect the dm-verity root hash with RCU
Fan Wu <wufan@kernel.org>
ipe: fix use-after-free when auditing a newly loaded policy
Wentao Liang <vulab@iscas.ac.cn>
fsl/fman: Fix clk reference leak in read_dts_node()
Josef Bacik <josef@toxicpanda.com>
writeback: report a Tasks-RCU quiescent state per cgwb drain pass
Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
workqueue: Fix NULL current_pwq deref in flush dependency check
Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes
Hao Ge <hao.ge@linux.dev>
netfs: Fix missing alloc tagging of direct mempool allocations
Christian Brauner <brauner@kernel.org>
fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbot's "WARNING in do_new_mount" saga
David Carlier <devnexen@gmail.com>
fprobe: Terminate the fgraph_data list when the reservation is not filled
Hui Peng <benquike@gmail.com>
fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT
Guopeng Zhang <zhangguopeng@kylinos.cn>
cgroup/pids: Restore pids.events notifications in local mode
Hui Peng <benquike@gmail.com>
cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict
Holger Dengler <dengler@linux.ibm.com>
crypto: s390/hmac - Generate intermediate CV for API partial block handling
Andrea Parri <parri.andrea@gmail.com>
bpf: fs/xattr: don't assume the inode is locked in path_unlink/path_rmdir
Myeonghun Pak <mhun512@gmail.com>
bna: prevent IOC timer rearm during teardown
Matthias Goergens <matthias.goergens@gmail.com>
ata: libata-scsi: bound the ATA passthru sense descriptor writes
David Carlier <devnexen@gmail.com>
arm64: errata: match the target implementation CPU's own MIDR
Fuad Tabba <fuad.tabba@linux.dev>
arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
Dairui Zhang <zhangdairui@gmail.com>
af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
Aohan Mei <henrymei@tencent.com>
sctp: discard the rest of the packet on a stale-cookie error
Willem de Bruijn <willemb@google.com>
tcp: prevent collapsing skbs across boundary in rtx queue
Eric Dumazet <edumazet@google.com>
tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
Willem de Bruijn <willemb@google.com>
virtio_net: copy zerocopy frags in start_xmit without NAPI
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
vsock: ignore empty child namespace mode writes
Melody Wang <huibo.wang@amd.com>
x86/sev: Make vTPM SVSM calls preemption-safe
Mario Limonciello <mario.limonciello@amd.com>
x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11
Masami Hiramatsu (Google) <mhiramat@kernel.org>
x86/mce: Fix hardware debug register corruption on task migration
Xiang Mei <xmei5@asu.edu>
vlan: require the MAC header to be present in __vlan_insert_inner_tag()
Matthew Brost <matthew.brost@intel.com>
drm/pagemap: dma-unmap pages before handling migration errors
Mark Amirkan <markdamirkan@gmail.com>
mptcp: return sk_wait_data() errors from recvmsg()
Zhan Xusheng <zhanxusheng1024@gmail.com>
sched/core: Account PSI IRQ time to the execution context, not the scheduling context
Puranjay Mohan <puranjay@kernel.org>
perf/core: Fill branch entries with a single assignment
Namhyung Kim <namhyung@kernel.org>
perf/core: Fix a refcount leak in attach_perf_ctx_data()
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Delete dead NVL PEBS data-source initcall
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
Hui Peng <benquike@gmail.com>
autofs: fix sbi->pipe file reference leak in autofs_kill_sb()
Amir Goldstein <amir73il@gmail.com>
ovl: fix UAF in ovl_do_mkdir() debug print
Eric Dumazet <edumazet@google.com>
vlan: ensure sufficient headroom in vlan_dev_hard_header()
Eric Dumazet <edumazet@google.com>
net/sched: sch_teql: fix shadowed err in __teql_resolve()
Eric Dumazet <edumazet@google.com>
bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
Eric Dumazet <edumazet@google.com>
llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
Eric Dumazet <edumazet@google.com>
gve: DQO: reject TSO packets with an out of range MSS
Eddie Phillips <eddiephillips@google.com>
gve: fix TX drop when GSO MSS is too small for hw
Eric Dumazet <edumazet@google.com>
gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO
Eric Dumazet <edumazet@google.com>
net: flush skb_defer_nodes in dev_cpu_dead()
Coia Prant <coiaprant@gmail.com>
net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
Ginger Li <ginger.jzllee@gmail.com>
tipc: Fix a data race on mon->peer_cnt in mon_timeout()
Sidraya Jayagond <sidraya@linux.ibm.com>
net/smc: fix UAF on lgr list traversal in smcr_port_err()
Allison Henderson <achender@kernel.org>
net/rds: size a connection's path set by the transport it ends up with
Sang-Hoon Choi <csh0052@gmail.com>
nfp: hold IPsec RX state under the XArray lock
Jiawen Wu <jiawenwu@trustnetic.com>
net: libwx: fix races in Tx timestamp handling
Jiawen Wu <jiawenwu@trustnetic.com>
net: wangxun: implement soft quiesce for PCIe error recovery
Aleksei Sviridkin <f@lex.la>
net: phylink: record the PHY only once bringup cannot fail
Yilin Zhang <yilinzhang@moonshot.ai>
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
Aleksei Sviridkin <f@lex.la>
net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq
Aleksei Sviridkin <f@lex.la>
net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
Christian Lamparter <chunkeey@gmail.com>
net: emac: move setting of netops to fix crash
Fang Xieyan <fangxy@xiaopeng.com>
net/sched: act_ife: validate metadata length before decoding
Haseeb Malik <haseebulhaq55@gmail.com>
macsec: initialize SecY before registering the netdevice
David Dai <zdai@linux.ibm.com>
bonding: crypto offload enabled, non-offload slave failover, rekey failed
Pengpeng Hou <hppiscas@163.com>
drm/imagination: clamp freelist reconstruction requests
Norbert Szetei <norbert@doyensec.com>
net: xps: reject an out of range traffic class
Sanghyun Park <sanghyun.park.cnu@gmail.com>
vxlan: use one headroom snapshot for neighbour replies
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
ip_gre: Reject enabling collect metadata through changelink
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: do not skip WoL power up on GENET V1
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: initialize u64 stats seq counter for all queues
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems
Yuya Kusakabe <yuya.kusakabe@gmail.com>
net: ipv6: keep room for the mac header in dst_dev_overhead()
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: clear stale buf->page after recycling on skb build failure
Ivan Delalande <colona@arista.com>
tg3: use random MAC address when tg3_get_device_address fails
Johan Almbladh <johan.almbladh@anyfinetworks.com>
bpf: Fix BSWAP 32 and 16 on MIPS64
Johan Almbladh <johan.almbladh@anyfinetworks.com>
bpf: Fix immediate JMP JEQ/JNE on MIPS32
Jonas Jelonek <jonas@jonasjelonek.de>
net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection
Nicolo Giuliani <nicolo.giuliani6@studio.unibo.it>
net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP
Ido Schimmel <idosch@nvidia.com>
vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
Shihuang Liu <shlomojune6@gmail.com>
net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()
Jakub Kicinski <kuba@kernel.org>
veth: manage XDP program pointers during channel resize
Nicolai Buchwitz <nb@tipi-net.de>
net: bcmgenet: stop Tx NAPI before disabling the queues
Victor Nogueira <victor@mojatatu.com>
net/sched: act_gate: budget the per-entry list in get_fill_size
Deepanshu Kartikey <kartikey406@gmail.com>
nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix slab-out-of-bounds reads when logging service names
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix -ENOMEM on connect with zero-length service name
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: st21nfca: validate ISO15693 inventory length
Cong Nguyen <congnt264@gmail.com>
nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure
Chris Gellermann <christian.gellermann@codasip.com>
nfc: virtual_ncidev: Add missing ioctl compat handler
Chris Gellermann <christian.gellermann@codasip.com>
selftests/nci: Fix out-of-bounds store on thread join
Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
selftests: nci: Fix uninitialized family ID on missing attribute
Lee Jones <lee@kernel.org>
nfc: llcp: Fix race condition in accept_queue lifecycle
Lei Zhu <zhulei@kylinos.cn>
selftests: nci: Correct pthread_create return value check
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: st21nfca: validate received frame size
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: nfcmrvl: validate helper command length before pull
Weiming Shi <bestswngs@gmail.com>
bpf: Reject dev-bound-only programs on other devices
Bernard Ladenthin <bernard.ladenthin@gmail.com>
net/sched: fix potential stack infoleak in em_text_dump()
Björn Töpel <bjorn@kernel.org>
eth: fbnic: Avoid rounding zero ring sizes
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: size the RX buffers from the frame length, not the MTU
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Capture all packets for vlan checks
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Check the dev->features for S-TAG offload testing
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Validate EEE based on the actual LPI timer value
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Support running selftests on DSA conduits
Xin Long <lucien.xin@gmail.com>
sctp: hold asoc or transport before mod_timer() in timer handlers
Bernardo Soares <bsoares.it@gmail.com>
net/mlx5: Bridge, don't fail unlink of untracked/unsupported peer ports
Bernardo Soares <bsoares.it@gmail.com>
net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: cdev: fix back-transition for iso_resource_auto client resource
Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
Emil Tsalapatis <emil@etsalapatis.com>
bpf: Reject pkt arguments in mutating subprogs
Emil Tsalapatis <emil@etsalapatis.com>
bpf: Fix bpf_sock context code generation
Emil Tsalapatis <emil@etsalapatis.com>
bpf: Fix bounds check for skb-backed dynptrs
Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>
thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds
Florian Schmaus <flo@geekplace.eu>
PM: hibernate: Freeze kernel threads after image preallocation
Coia Prant <coiaprant@gmail.com>
net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure
Jakub Kicinski <kuba@kernel.org>
genetlink: report the real command id for dump-only ops in policy dumps
bui duc phuc <phucduc.bui@gmail.com>
net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error
Muhammad Bilal <meatuni001@gmail.com>
net: spacemit: clear TX descriptor on fragment mapping failure
Mikhail Zaslonko <zaslonko@linux.ibm.com>
s390/debug: Fix NULL pointer dereference in debug_info_copy()
Mikhail Zaslonko <zaslonko@linux.ibm.com>
s390/debug: Do not register views for failed static debug areas
Nemesa Garg <nemesa.garg@intel.com>
drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable
Myeonghun Pak <mhun512@gmail.com>
tg3: clean up PHYLIB resources on probe failure
Shardul Bankar <shardul.b@mpiricsoftware.com>
udp: remove a disconnected socket from the 4-tuple hash table
Shardul Bankar <shardul.b@mpiricsoftware.com>
udp: relocate a connected socket in the 4-tuple hash table on re-connect
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: Fix dst leak for uncached routes.
Pengpeng Hou <hppiscas@163.com>
net: usb: sr9700: include receive overhead in the length check
Ivan Vecera <ivecera@redhat.com>
dpll: use exact lookup for reference sync pin id
Nicolai Buchwitz <nb@tipi-net.de>
net: don't require the hwtstamp NDOs when a PHY provides timestamping
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: Prevent rt6_insert_exception() for dying fib6_info.
Ratheesh Kannoth <rkannoth@marvell.com>
octeontx2-af: Fix memory scaling limitation in SR-IOV mode
Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
Hui Peng <benquike@gmail.com>
Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()
Ravindra <ravindra@intel.com>
Bluetooth: btintel_pcie: validate device-supplied DMA indices
Hui Peng <benquike@gmail.com>
Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough
Sk Anirban <sk.anirban@intel.com>
drm/xe/gt_throttle: Report power brake as a throttle reason on CRI
Ralf Lici <ralf@mandelbit.com>
ovpn: reject invalid peer VPN addresses
Ralf Lici <ralf@mandelbit.com>
ovpn: reject multipeer peers without VPN addresses
Ralf Lici <ralf@mandelbit.com>
ovpn: reject duplicate peer VPN addresses
Ralf Lici <ralf@mandelbit.com>
ovpn: always unhash old VPN addresses before rehashing
Ralf Lici <ralf@mandelbit.com>
ovpn: replace bind when clearing stale local source
Ralf Lici <ralf@mandelbit.com>
ovpn: replace bind when learning local endpoint
Ralf Lici <ralf@mandelbit.com>
ovpn: validate peer state before caching UDP dst
Ralf Lici <ralf@mandelbit.com>
ovpn: track UDP socket route key for peer dst cache
Ralf Lici <ralf@mandelbit.com>
ovpn: skip UDP source validation for unspecified addresses
Ralf Lici <ralf@mandelbit.com>
ovpn: preserve IPv6 scope id for netlink peer endpoints
Li Youhong <liyouhong@kylinos.cn>
drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach
Prathamesh Shete <pshete@nvidia.com>
pinctrl: tegra238: Fix register bank for AON pin groups
Benjamin Leggett <benjamin@edera.io>
drm/virtio: sync shmem backing on guest-bound transfers
Dmitry Osipenko <dmitry.osipenko@collabora.com>
Revert "drm/virtio: Allow importing prime buffers when 3D is enabled"
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: release the GEM object on virtio_gpu_vram_create() errors
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leak when drm_gem_handle_create() fails
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget
Yuqi Xu <xuyuqiabc@gmail.com>
bpf: Check params size before reading reserved fields
Aamir Ahmed <elb12345@hotmail.co.uk>
net: usb: catc: bound the RX packet length in catc_rx_done()
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Bound ownership depth through local kptrs and graph roots
Quentin Armitage <quentin@armitage.org.uk>
net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset
Yiqi Sun <sunyiqixm@gmail.com>
sctp: avoid livelock while updating retransmit path
Alexander Duyck <alexanderduyck@fb.com>
eth: fbnic: Handle FW mailbox completions flagged with an error
Alexander Duyck <alexanderduyck@fb.com>
eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox
Alexander Duyck <alexanderduyck@fb.com>
eth: fbnic: reset num_napi when the napi vectors are freed
Alexander Duyck <alexanderduyck@fb.com>
eth: fbnic: use the Rx queue napi pointer to find the napi vector
Björn Töpel <bjorn@kernel.org>
eth: fbnic: Handle maximum standalone channels
Alexander Duyck <alexanderduyck@fb.com>
net: ethtool: keep rtnl_lock for the ioctl self test
Kuniyuki Iwashima <kuniyu@google.com>
ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
net: gue: reject invalid REMCSUM offsets
Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
net/sched: act_ct: don't WARN on benign flow_offload_alloc() failure
Giuseppe Ranieri <giuseppe@ranieri.dev>
drm/nouveau/disp: don't reject HDMI config on cards without SCDC
Francesco Magazzu <postadelmaga@gmail.com>
drm/nouveau/clk: don't clobber reclock status when restoring volt/fan
Dan Carpenter <error27@gmail.com>
drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
hpp.iscas <hppiscas@163.com>
pinctrl: qcom: ipq5210: Publish the OF module alias
Joseph Qi <joseph.qi@linux.alibaba.com>
ocfs2: make ocfs2_calc_xattr_init() return void
Zeng Heng <zengheng4@huawei.com>
arm64: io: Reject non-user protection in ioremap_prot()
Naman Gulati <namangulati@google.com>
netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
Julian Anastasov <ja@ssi.bg>
ipvs: revalidate ihl before icmp_send
Karl Mehltretter <kmehltretter@gmail.com>
netfilter: nft_synproxy: use the family-aware checksum helper
Florian Westphal <fw@strlen.de>
netfilter: nfnetlink_queue: hold nfnl mutex in event notifier
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
netfilter: flowtable: publish HW_DEAD after worker is done
Frank Wunderlich <frank-w@public-files.de>
gpiolib: use of_node_name if line-name is missing
Linkui Xiao <xiaolinkui@kylinos.cn>
ipv4: fib: fix data-race and stale genid check around nh->nh_saddr
Kumar Kartikeya Dwivedi <memxor@gmail.com>
libbpf: Reject truncated ldimm64 CO-RE relocations
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Restrict CO-RE poisoning to relocatable instructions
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Preserve packet pointer class displacement in regsafe()
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Make post-verification instruction rewrites killable
Shay Drory <shayd@nvidia.com>
net/mlx5: LAG, reload IB reps of LAG master before the rest
Shay Drory <shayd@nvidia.com>
net/mlx5: SD, unload reps on shared FDB create error path
Shay Drory <shayd@nvidia.com>
net/mlx5: devcom, Base component size on linked devices
Heyang Tan <thy15333007817@163.com>
octeontx2-af: use seq_file for rsrc_alloc debugfs
Kyle Hendry <khendry@reliablecontrols.com>
net: pcs: rzn1-miic: Fix config array initialization
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: cls_u32: fix manual hash table handle IDR aliasing
Björn Töpel <bjorn@kernel.org>
eth: fbnic: Fix payload page pool error cleanup
Weiming Shi <bestswngs@gmail.com>
bpf: Skip unsettled links in link iterator
Zhiling Zou <zhilinz@nebusec.ai>
xsk: Use a 32-bit compare in xsk_map_gen_lookup
Julian Sun <sunjunchao@bytedance.com>
fs: avoid repeated scans in evict_inodes()
David Howells <dhowells@redhat.com>
netfs, afs: Fix symlink reading
David Howells <dhowells@redhat.com>
netfs: Fix netfs_read_gaps() to use separate sink folios
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Guard PMCW field accesses with dnv check
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Fix cio_update_schib() to not cache invalid schib
Karl Mehltretter <kmehltretter@gmail.com>
s390/pci/docs: Fix sriov_numvfs attribute name
Bart Van Assche <bvanassche@acm.org>
scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()
Eva Kurchatova <eva.kurchatova@virtuozzo.com>
selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode
Lee Jones <lee@kernel.org>
Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump()
Christiano Amora <christiano.amora@gmail.com>
Bluetooth: SMP: reject Security Request over BR/EDR
Andre Przywara <andre.przywara@arm.com>
pinctrl: sunxi: A523: fix voltage withstand encoding
ZHOU Jiaxiang <me@fxti.xyz>
scsi: sd_zbc: Reject disks with too many zones
ZHOU Jiaxiang <me@fxti.xyz>
scsi: block: Fix zones_cond out-of-bounds write on zone report
Ran Hongyun <ranhongyun1@huawei.com>
squashfs: Add dictionary size range check to prevent shift-out-of-bounds
Mark Brown <broonie@kernel.org>
KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP
Sebastian Ott <sebott@redhat.com>
KVM: selftests: fix steal_time for arm64 with host page size > 4K
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Match hyp text by physical address in fix_host_ownership()
Karl Mehltretter <kmehltretter@gmail.com>
KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve()
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: vgic-its: Free the caches when GITS_BASER changes
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Fix perf-backed counter accounting across stop and read
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Report snapshot write failure to the guest
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Preserve firmware counter value across stop/start
Zongmin Zhou <zhouzongmin@kylinos.cn>
KVM: riscv: Fix NACL hfence entry update order
Yicong Yang <yang.yicong@picoheart.com>
RISC-V: KVM: Fix the conversion between vsip and hvip
Benjamin Tissoires <bentiss@kernel.org>
HID: bpf: fix __hid_bpf_hw_check_params report length
Slawomir Stepien <sst@poczta.fm>
HID: amd_sfh: Validate PCI BAR size before mapping
Sarah Emery <sarah.emery@canonical.com>
pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()
Sean Anderson <sanderson@brivo.com>
pinctrl: meson: Fix typo in s4 group name
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
bpf, arm64: set up the frame pointer for the exception callback
Masoud Aghasi <maghasi@disroot.org>
bpf: Fix u32 overflow issue in map batch operations
Geliang Tang <geliang@kernel.org>
bpf, sockmap: Fix self-redirect copied_seq double-counting
Pu Lehui <pulehui@huawei.com>
bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix out-of-bounds read of rtt_min in sock_ops
Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()
Siddharth Chintamaneni <sidchintamaneni@gmail.com>
bpf: Allow terminal gotox instructions
Jim Mattson <jmattson@google.com>
KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr()
Oscar Priego Verdugo <oscar.priegov@gmail.com>
HID: elecom: fix bus type for M-XGL20DLBK
René Onier <f3nr1l@me.com>
HID: winwing: fix use-after-free in force feedback teardown
Lovekesh Solanki <lovekeshsolanki00@gmail.com>
HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
Jiayuan Chen <jiayuan.chen@linux.dev>
tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix divide-by-zero in btf_struct_walk()
Sven Schnelle <svens@linux.ibm.com>
selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
Weiming Shi <bestswngs@gmail.com>
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Daniel Borkmann <daniel@iogearbox.net>
bpf: Fix bpf_skb_change_tail wrt csum partial skbs
Steffen Eiden <seiden@linux.ibm.com>
s390/uv: Prevent potential out-of-bounds read
Steffen Eiden <seiden@linux.ibm.com>
s390/uv: Fix loop condition in uv_find_secrets
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix race in _destroy_pages_crste()
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix potential races in dat skey functions
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key()
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Add missing srcu in kvm_s390_set_irq_state()
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix IRQ injection with SIGP Stop and Store Status
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix _gaccess_shadow_fault()
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix dirty marking in adapter_indicators_set*()
Mostafa Saleh <smostafa@google.com>
remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
Dominik Kaszewski <dominik.kaszewski@amd.com>
drm/amd/display: Remove sink usage from DPMS
Sean Rhodes <sean@starlabs.systems>
ALSA: hda/realtek: Add StarFighter HDA SSID
Sean Rhodes <sean@starlabs.systems>
ALSA: hda/realtek: Limit Star Labs internal mic boost
Leo Li <sunpeng.li@amd.com>
drm/amd/display: Atomize IRQ register read/modify/write ops
-------------
Diffstat:
Documentation/arch/arm64/booting.rst | 1 +
Documentation/arch/s390/pci.rst | 2 +-
.../bindings/pinctrl/qcom,nord-tlmm.yaml | 7 +-
Makefile | 4 +-
arch/arm64/include/asm/el2_setup.h | 9 +-
arch/arm64/include/asm/io.h | 3 +-
arch/arm64/include/asm/kvm_host.h | 2 +-
arch/arm64/include/asm/kvm_nested.h | 3 +-
arch/arm64/include/asm/kvm_pkvm.h | 3 +-
arch/arm64/kernel/cpu_errata.c | 15 +-
arch/arm64/kvm/arm.c | 8 +-
arch/arm64/kvm/emulate-nested.c | 2 +-
arch/arm64/kvm/hyp/include/nvhe/mem_protect.h | 1 +
arch/arm64/kvm/hyp/nvhe/mem_protect.c | 8 +
arch/arm64/kvm/hyp/nvhe/pkvm.c | 25 +-
arch/arm64/kvm/hyp/nvhe/setup.c | 12 +-
arch/arm64/kvm/hypercalls.c | 3 +-
arch/arm64/kvm/mmu.c | 15 +-
arch/arm64/kvm/nested.c | 115 ++++----
arch/arm64/kvm/sys_regs.c | 1 +
arch/arm64/kvm/vgic/vgic-its.c | 43 +--
arch/arm64/net/bpf_jit_comp.c | 2 +
arch/mips/net/bpf_jit_comp32.c | 2 +-
arch/mips/net/bpf_jit_comp64.c | 3 +-
arch/parisc/include/asm/thread_info.h | 2 +-
arch/parisc/kernel/setup.c | 12 +
arch/riscv/include/asm/csr.h | 20 +-
arch/riscv/kvm/aia_imsic.c | 11 +-
arch/riscv/kvm/mmu.c | 10 +-
arch/riscv/kvm/nacl.c | 20 +-
arch/riscv/kvm/vcpu.c | 3 +-
arch/riscv/kvm/vcpu_exit.c | 2 +-
arch/riscv/kvm/vcpu_onereg.c | 8 +-
arch/riscv/kvm/vcpu_pmu.c | 33 +--
arch/riscv/kvm/vcpu_sbi_hsm.c | 4 +-
arch/riscv/kvm/vcpu_timer.c | 5 +-
arch/s390/crypto/hmac_s390.c | 5 +-
arch/s390/include/asm/debug.h | 8 +-
arch/s390/kernel/debug.c | 15 +-
arch/s390/kernel/uv.c | 8 +-
arch/s390/kvm/dat.c | 41 ++-
arch/s390/kvm/gaccess.c | 13 +
arch/s390/kvm/gmap.c | 6 +-
arch/s390/kvm/interrupt.c | 149 ++++++-----
arch/s390/pci/pci_event.c | 7 +-
arch/s390/pci/pci_report.c | 32 ++-
arch/s390/pci/pci_report.h | 4 +-
arch/x86/coco/sev/svsm.c | 10 +-
arch/x86/events/amd/brs.c | 9 +-
arch/x86/events/amd/lbr.c | 16 +-
arch/x86/events/intel/core.c | 80 ++++--
arch/x86/events/intel/ds.c | 68 ++---
arch/x86/events/intel/lbr.c | 63 +++--
arch/x86/events/perf_event.h | 4 -
arch/x86/include/asm/kvm-x86-nested-ops.h | 36 +++
arch/x86/include/asm/kvm_host.h | 22 +-
arch/x86/kernel/cpu/mce/core.c | 27 +-
arch/x86/kvm/hyperv.c | 6 +-
arch/x86/kvm/irq.h | 6 +
arch/x86/kvm/mmu.h | 5 +-
arch/x86/kvm/mmu/mmu.c | 129 ++++++---
arch/x86/kvm/mmu/mmu_internal.h | 66 -----
arch/x86/kvm/mmu/paging_tmpl.h | 2 +-
arch/x86/kvm/pmu.c | 8 -
arch/x86/kvm/svm/nested.c | 1 +
arch/x86/kvm/svm/sev.c | 18 +-
arch/x86/kvm/svm/svm.c | 1 +
arch/x86/kvm/tss.h | 7 +
arch/x86/kvm/vmx/nested.c | 1 +
arch/x86/kvm/vmx/pmu_intel.c | 3 +
arch/x86/kvm/vmx/vmx.c | 2 +
arch/x86/kvm/x86.c | 62 +++--
arch/x86/kvm/x86.h | 2 +-
arch/x86/pci/fixup.c | 99 +++++++
block/blk-zoned.c | 15 +-
drivers/accel/ivpu/ivpu_drv.c | 31 ++-
drivers/accel/ivpu/ivpu_drv.h | 7 +-
drivers/accel/ivpu/ivpu_hw.c | 4 +
drivers/accel/ivpu/ivpu_ipc.c | 8 +-
drivers/accel/ivpu/ivpu_ipc.h | 2 +-
drivers/accel/ivpu/ivpu_job.c | 66 ++++-
drivers/accel/ivpu/ivpu_job.h | 7 +-
drivers/accel/ivpu/ivpu_mmu.c | 1 -
drivers/accel/ivpu/ivpu_pm.c | 1 +
drivers/ata/libata-scsi.c | 10 +-
drivers/base/cacheinfo.c | 11 +-
drivers/bluetooth/btintel_pcie.c | 16 ++
drivers/bluetooth/btnxpuart.c | 8 +-
drivers/dpll/dpll_netlink.c | 3 +-
drivers/firewire/core-cdev.c | 6 +-
drivers/gpio/gpio-arizona.c | 8 +-
drivers/gpio/gpio-tps65219.c | 12 +-
drivers/gpio/gpio-zynq.c | 10 +-
drivers/gpio/gpiolib-cdev.c | 32 ++-
drivers/gpio/gpiolib.c | 7 +
drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c | 4 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 4 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c | 3 +
drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c | 2 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 16 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.h | 1 +
drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c | 1 +
drivers/gpu/drm/amd/amdgpu/vcn_v4_0_3.c | 3 +-
drivers/gpu/drm/amd/amdgpu/vcn_v5_0_1.c | 3 +-
drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 71 ++++-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 8 +-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h | 12 +
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c | 3 +-
.../drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c | 3 +-
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c | 62 +++--
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h | 28 ++
drivers/gpu/drm/amd/display/dc/dml/Makefile | 8 +-
drivers/gpu/drm/amd/display/dc/dml2_0/Makefile | 2 +-
drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 180 ++++++-------
drivers/gpu/drm/bridge/samsung-dsim.c | 2 +-
drivers/gpu/drm/clients/drm_fbdev_client.c | 8 +
drivers/gpu/drm/drm_pagemap.c | 12 +-
drivers/gpu/drm/i915/display/intel_cursor.c | 7 +-
drivers/gpu/drm/i915/display/intel_display_types.h | 2 +
drivers/gpu/drm/i915/display/intel_dp_mst.c | 24 +-
drivers/gpu/drm/i915/display/intel_dp_mst.h | 2 +
drivers/gpu/drm/i915/display/intel_link_bw.c | 3 +-
drivers/gpu/drm/i915/display/intel_psr.c | 15 ++
drivers/gpu/drm/i915/display/intel_quirks.c | 3 +
drivers/gpu/drm/i915/display/skl_universal_plane.c | 9 +-
drivers/gpu/drm/i915/gem/i915_gem_object.c | 2 +-
drivers/gpu/drm/imagination/pvr_free_list.c | 15 +-
drivers/gpu/drm/imagination/pvr_mmu.c | 19 +-
drivers/gpu/drm/imagination/pvr_mmu.h | 2 +-
drivers/gpu/drm/imagination/pvr_vm.c | 4 +-
drivers/gpu/drm/nouveau/nouveau_bo.c | 3 +-
drivers/gpu/drm/nouveau/nouveau_connector.c | 5 +-
drivers/gpu/drm/nouveau/nouveau_dmem.c | 4 +-
drivers/gpu/drm/nouveau/nouveau_drm.c | 5 +-
drivers/gpu/drm/nouveau/nouveau_gem.c | 2 +
drivers/gpu/drm/nouveau/nouveau_sched.c | 2 +-
drivers/gpu/drm/nouveau/nouveau_sched.h | 1 +
drivers/gpu/drm/nouveau/nouveau_uvmm.c | 13 +-
drivers/gpu/drm/nouveau/nvif/vmm.c | 1 +
drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c | 3 +-
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 23 +-
drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c | 2 +
drivers/gpu/drm/virtio/virtgpu_drv.h | 5 +
drivers/gpu/drm/virtio/virtgpu_gem.c | 2 +-
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 49 +++-
drivers/gpu/drm/virtio/virtgpu_prime.c | 2 +-
drivers/gpu/drm/virtio/virtgpu_submit.c | 11 +-
drivers/gpu/drm/virtio/virtgpu_vq.c | 46 ++++
drivers/gpu/drm/virtio/virtgpu_vram.c | 17 +-
drivers/gpu/drm/xe/regs/xe_gt_regs.h | 1 +
drivers/gpu/drm/xe/xe_bo.c | 7 +
drivers/gpu/drm/xe/xe_bo.h | 19 ++
drivers/gpu/drm/xe/xe_gt_throttle.c | 5 +-
drivers/gpu/drm/xe/xe_guc_ads.c | 2 +-
drivers/gpu/drm/xe/xe_hw_engine.c | 96 ++++++-
drivers/gpu/drm/xe/xe_vm.c | 21 +-
drivers/gpu/drm/xe/xe_wa_oob.rules | 2 +
drivers/hid/amd-sfh-hid/amd_sfh_common.h | 4 +
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c | 10 +
drivers/hid/bpf/hid_bpf_dispatch.c | 12 +-
drivers/hid/hid-alps.c | 25 +-
drivers/hid/hid-ids.h | 3 +
drivers/hid/hid-multitouch.c | 29 +-
drivers/hid/hid-oxp.c | 6 +-
drivers/hid/hid-quirks.c | 3 +-
drivers/hid/hid-winwing.c | 10 +-
drivers/hid/wacom_sys.c | 5 +-
drivers/i2c/busses/i2c-qcom-geni.c | 293 +++++++++++----------
drivers/net/bonding/bond_main.c | 2 +-
drivers/net/dsa/mt7530-mdio.c | 18 +-
drivers/net/dsa/mt7530.c | 3 -
drivers/net/dsa/mv88e6xxx/chip.c | 68 ++++-
drivers/net/ethernet/airoha/airoha_npu.c | 18 +-
drivers/net/ethernet/amazon/ena/ena_netdev.c | 2 +
drivers/net/ethernet/atheros/atl1c/atl1c_main.c | 3 +
drivers/net/ethernet/atheros/atl1e/atl1e_main.c | 3 +
drivers/net/ethernet/atheros/atlx/atl1.c | 3 +
drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c | 3 +-
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 34 ++-
drivers/net/ethernet/broadcom/tg3.c | 15 +-
drivers/net/ethernet/brocade/bna/bnad.c | 24 +-
drivers/net/ethernet/cadence/macb_main.c | 14 +-
drivers/net/ethernet/freescale/fman/fman.c | 1 +
drivers/net/ethernet/google/gve/gve_desc_dqo.h | 5 +
drivers/net/ethernet/google/gve/gve_tx_dqo.c | 40 ++-
drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c | 3 +
drivers/net/ethernet/ibm/emac/core.c | 16 +-
drivers/net/ethernet/marvell/octeontx2/af/common.h | 45 +++-
.../ethernet/marvell/octeontx2/af/rvu_debugfs.c | 104 +++-----
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 6 +-
.../ethernet/mellanox/mlx5/core/en/rep/bridge.c | 45 +++-
drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c | 3 +
.../mellanox/mlx5/core/en_accel/ipsec_fs.c | 4 +-
.../ethernet/mellanox/mlx5/core/en_accel/macsec.c | 2 +
drivers/net/ethernet/mellanox/mlx5/core/en_main.c | 1 -
.../net/ethernet/mellanox/mlx5/core/esw/bridge.c | 15 +-
.../net/ethernet/mellanox/mlx5/core/esw/bridge.h | 2 +
drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c | 44 +++-
.../ethernet/mellanox/mlx5/core/lag/shared_fdb.c | 1 +
.../net/ethernet/mellanox/mlx5/core/lib/devcom.c | 5 +-
drivers/net/ethernet/meta/fbnic/fbnic_csr.h | 5 +
drivers/net/ethernet/meta/fbnic/fbnic_debugfs.c | 4 +-
drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c | 16 +-
drivers/net/ethernet/meta/fbnic/fbnic_fw.c | 47 +++-
drivers/net/ethernet/meta/fbnic/fbnic_fw.h | 1 +
drivers/net/ethernet/meta/fbnic/fbnic_pci.c | 18 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 30 ++-
drivers/net/ethernet/netronome/nfp/crypto/ipsec.c | 3 +-
drivers/net/ethernet/spacemit/k1_emac.c | 3 +
drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c | 5 +-
drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c | 4 +-
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
drivers/net/ethernet/stmicro/stmmac/ring_mode.c | 4 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 21 +-
.../net/ethernet/stmicro/stmmac/stmmac_selftests.c | 153 ++++++++---
drivers/net/ethernet/ti/netcp_core.c | 2 +-
drivers/net/ethernet/wangxun/libwx/wx_hw.c | 1 +
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 65 ++++-
drivers/net/ethernet/wangxun/libwx/wx_lib.h | 1 +
drivers/net/ethernet/wangxun/libwx/wx_ptp.c | 161 ++++++++---
drivers/net/ethernet/wangxun/libwx/wx_ptp.h | 1 +
drivers/net/ethernet/wangxun/libwx/wx_type.h | 2 +
drivers/net/ethernet/wangxun/txgbe/txgbe_fdir.c | 13 +-
drivers/net/ethernet/wangxun/txgbe/txgbe_main.c | 16 ++
drivers/net/macsec.c | 84 +++---
drivers/net/mdio/mdio-realtek-rtl9300.c | 6 +
drivers/net/ovpn/netlink.c | 108 +++++++-
drivers/net/ovpn/peer.c | 121 +++++++--
drivers/net/ovpn/peer.h | 25 +-
drivers/net/ovpn/udp.c | 193 +++++++++++---
drivers/net/pcs/pcs-rzn1-miic.c | 3 +-
drivers/net/pcs/pcs-xpcs.c | 4 +-
drivers/net/phy/intel-xway.c | 29 +-
drivers/net/phy/micrel.c | 1 +
drivers/net/phy/phylink.c | 20 +-
drivers/net/usb/catc.c | 15 +-
drivers/net/usb/cdc_mbim.c | 5 +
drivers/net/usb/lan78xx.c | 2 +
drivers/net/usb/sr9700.c | 3 +-
drivers/net/veth.c | 2 +
drivers/net/virtio_net.c | 9 +
drivers/net/vrf.c | 2 -
drivers/net/vxlan/vxlan_core.c | 6 +-
drivers/nfc/microread/microread.c | 6 +-
drivers/nfc/nfcmrvl/fw_dnld.c | 11 +-
drivers/nfc/pn533/pn533.c | 14 +-
drivers/nfc/pn533/pn533.h | 4 +-
drivers/nfc/pn533/usb.c | 4 +-
drivers/nfc/pn544/pn544.c | 7 +-
drivers/nfc/port100.c | 7 +
drivers/nfc/st21nfca/core.c | 12 +-
drivers/nfc/st21nfca/i2c.c | 29 +-
drivers/nfc/trf7970a.c | 4 +-
drivers/nfc/virtual_ncidev.c | 3 +-
drivers/pci/of_property.c | 11 +-
drivers/pci/setup-bus.c | 23 +-
drivers/perf/arm_brbe.c | 2 +-
drivers/pinctrl/meson/pinctrl-meson-s4.c | 2 +-
drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c | 6 +-
drivers/pinctrl/pinctrl-generic.c | 4 +
drivers/pinctrl/pinctrl-single.c | 3 +-
drivers/pinctrl/qcom/pinctrl-ipq5210.c | 1 +
drivers/pinctrl/qcom/pinctrl-nord.c | 34 ++-
drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c | 2 +-
drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c | 2 +-
drivers/pinctrl/sunxi/pinctrl-sunxi.c | 82 ++++--
drivers/pinctrl/sunxi/pinctrl-sunxi.h | 9 +
drivers/pinctrl/tegra/pinctrl-tegra238.c | 204 +++++++-------
drivers/remoteproc/qcom_q6v5_adsp.c | 8 +-
drivers/s390/cio/chp.c | 3 +
drivers/s390/cio/cio.c | 11 +-
drivers/s390/cio/cio.h | 5 +-
drivers/s390/cio/cmf.c | 2 +-
drivers/s390/cio/device.c | 9 +-
drivers/s390/cio/device_fsm.c | 3 +
drivers/s390/cio/device_ops.c | 23 ++
drivers/s390/cio/vfio_ccw_fsm.c | 2 +-
drivers/s390/crypto/vfio_ap_ops.c | 18 +-
drivers/scsi/libiscsi_tcp.c | 3 +
drivers/scsi/megaraid/megaraid_sas_base.c | 4 +-
drivers/scsi/sd_zbc.c | 8 +-
drivers/thermal/gov_step_wise.c | 10 +-
drivers/ufs/core/ufshcd.c | 6 +
drivers/ufs/host/ufshcd-pltfrm.c | 6 +-
fs/autofs/inode.c | 4 +
fs/bpf_fs_kfuncs.c | 4 -
fs/fs-writeback.c | 25 +-
fs/inode.c | 11 +-
fs/kernfs/mount.c | 4 +-
fs/netfs/buffered_read.c | 34 +--
fs/netfs/objects.c | 4 +-
fs/netfs/read_collect.c | 5 +
fs/netfs/rolling_buffer.c | 2 +-
fs/ntfs3/inode.c | 7 +-
fs/ocfs2/namei.c | 9 +-
fs/ocfs2/xattr.c | 13 +-
fs/ocfs2/xattr.h | 8 +-
fs/overlayfs/overlayfs.h | 4 +-
fs/smb/client/cached_dir.c | 32 ++-
fs/smb/client/dir.c | 52 +++-
fs/smb/client/smb2inode.c | 6 +-
fs/smb/client/smb2misc.c | 9 +-
fs/smb/client/smb2ops.c | 28 +-
fs/smb/client/smb2pdu.c | 54 +++-
fs/smb/client/transport.c | 71 ++++-
fs/squashfs/xz_wrapper.c | 6 +-
fs/super.c | 114 ++++----
fs/xfs/libxfs/xfs_metafile.c | 8 +-
fs/xfs/libxfs/xfs_rtrefcount_btree.c | 4 +-
fs/xfs/scrub/dir.c | 2 +-
fs/xfs/scrub/health.c | 6 +-
fs/xfs/scrub/inode.c | 2 +-
fs/xfs/scrub/inode_repair.c | 2 +-
fs/xfs/scrub/newbt.c | 8 +-
fs/xfs/scrub/orphanage.c | 6 +-
fs/xfs/scrub/repair.c | 21 +-
fs/xfs/scrub/scrub.h | 2 +-
fs/xfs/scrub/trace.h | 12 +-
fs/xfs/xfs_dquot.c | 8 +-
fs/xfs/xfs_exchrange.c | 13 +-
fs/xfs/xfs_healthmon.c | 4 +-
fs/xfs/xfs_icache.c | 2 +-
fs/xfs/xfs_log_recover.c | 13 +-
fs/xfs/xfs_qm.c | 10 +-
fs/xfs/xfs_refcount_item.c | 8 +-
fs/xfs/xfs_rmap_item.c | 8 +-
include/linux/ethtool.h | 2 +
include/linux/fs/super_types.h | 2 +-
include/linux/if_vlan.h | 3 +
include/linux/mempool.h | 7 +
include/linux/mm_types.h | 15 +-
include/linux/perf_event.h | 17 --
include/linux/sched.h | 6 +-
include/linux/sched/topology.h | 4 +-
include/linux/skbuff.h | 24 +-
include/net/dst.h | 3 +-
include/net/gue.h | 19 +-
include/net/ip6_route.h | 4 +-
include/net/netfilter/nf_conntrack.h | 5 +
include/net/nfc/hci.h | 2 +-
include/net/nfc/nfc.h | 3 +-
include/net/tcp.h | 4 +-
kernel/bpf/btf.c | 140 ++++++----
kernel/bpf/core.c | 21 +-
kernel/bpf/crypto.c | 5 +-
kernel/bpf/fixups.c | 24 +-
kernel/bpf/hashtab.c | 43 ++-
kernel/bpf/memalloc.c | 50 ++--
kernel/bpf/offload.c | 2 +
kernel/bpf/states.c | 3 +
kernel/bpf/syscall.c | 15 +-
kernel/bpf/verifier.c | 17 +-
kernel/cgroup/cpuset.c | 3 +-
kernel/cgroup/pids.c | 5 +
kernel/events/core.c | 17 +-
kernel/exit.c | 11 +-
kernel/kprobes.c | 22 +-
kernel/power/hibernate.c | 26 +-
kernel/sched/core.c | 2 +-
kernel/sched/ext/ext.c | 7 +-
kernel/sched/fair.c | 173 ++++++++----
kernel/sched/topology.c | 22 +-
kernel/trace/fprobe.c | 15 ++
kernel/workqueue.c | 2 +-
mm/backing-dev.c | 5 +-
mm/damon/core.c | 39 ++-
mm/damon/ops-common.c | 7 +-
mm/damon/vaddr.c | 21 +-
mm/hugetlb.c | 20 +-
mm/rmap.c | 6 +-
mm/vma.c | 8 +
net/8021q/vlan_dev.c | 5 +
net/bluetooth/bnep/core.c | 17 +-
net/bluetooth/bnep/netdev.c | 8 +-
net/bluetooth/hci_conn.c | 14 +-
net/bluetooth/hci_sock.c | 20 +-
net/bluetooth/iso.c | 7 +
net/bluetooth/l2cap_core.c | 10 +-
net/bluetooth/mgmt.c | 27 +-
net/bluetooth/rfcomm/core.c | 3 +-
net/bluetooth/rfcomm/sock.c | 6 +-
net/bluetooth/smp.c | 17 ++
net/bridge/br_mdb.c | 2 +
net/bridge/br_stp_bpdu.c | 5 +-
net/core/dev.c | 49 +++-
net/core/dev.h | 2 +
net/core/dev_ioctl.c | 25 +-
net/core/filter.c | 46 ++--
net/core/skbuff.c | 21 +-
net/core/skmsg.c | 4 +
net/core/sock_map.c | 1 +
net/ethtool/common.h | 2 +
net/ipv4/arp.c | 1 +
net/ipv4/devinet.c | 7 +-
net/ipv4/fib_semantics.c | 13 +-
net/ipv4/fou_core.c | 4 +
net/ipv4/inet_connection_sock.c | 3 +-
net/ipv4/ip_gre.c | 12 +
net/ipv4/ipconfig.c | 45 ++--
net/ipv4/tcp_output.c | 3 +
net/ipv4/udp.c | 44 +++-
net/ipv6/exthdrs_core.c | 3 +
net/ipv6/ip6_fib.c | 2 +-
net/ipv6/ip6_gre.c | 2 +-
net/ipv6/netfilter/ip6t_rpfilter.c | 2 +-
net/ipv6/netfilter/ip6t_rt.c | 11 +-
net/ipv6/route.c | 12 +-
net/ipv6/seg6.c | 4 +-
net/llc/llc_c_ac.c | 2 +-
net/llc/llc_s_ac.c | 4 +
net/llc/llc_sap.c | 8 +-
net/mctp/route.c | 2 +-
net/mptcp/protocol.c | 2 +-
net/netfilter/ipvs/ip_vs_core.c | 6 +
net/netfilter/nf_conntrack_netlink.c | 3 +-
net/netfilter/nf_flow_table_offload.c | 7 +-
net/netfilter/nf_tables_api.c | 10 +-
net/netfilter/nfnetlink_queue.c | 8 +-
net/netfilter/nft_synproxy.c | 3 +-
net/netlink/genetlink.c | 8 +-
net/nfc/core.c | 15 +-
net/nfc/digital_dep.c | 8 +-
net/nfc/llcp.h | 1 +
net/nfc/llcp_commands.c | 2 +-
net/nfc/llcp_core.c | 173 ++++++++----
net/nfc/llcp_sock.c | 67 +++--
net/nfc/nci/core.c | 10 +-
net/nfc/netlink.c | 7 +-
net/nfc/nfc.h | 3 +-
net/openvswitch/conntrack.c | 37 ++-
net/packet/af_packet.c | 104 +++++---
net/rds/connection.c | 6 +
net/rds/ib_frmr.c | 11 +-
net/sched/act_api.c | 2 +-
net/sched/act_ct.c | 41 ++-
net/sched/act_gate.c | 30 ++-
net/sched/act_ife.c | 17 +-
net/sched/act_meta_mark.c | 6 +-
net/sched/act_meta_skbprio.c | 6 +-
net/sched/act_meta_skbtcindex.c | 6 +-
net/sched/cls_u32.c | 12 +-
net/sched/em_text.c | 2 +-
net/sched/sch_hfsc.c | 22 ++
net/sched/sch_teql.c | 7 +-
net/sctp/associola.c | 15 +-
net/sctp/input.c | 7 +-
net/sctp/sm_sideeffect.c | 37 +--
net/sctp/sm_statefuns.c | 2 +
net/smc/smc_core.c | 2 +
net/smc/smc_ib.c | 10 +-
net/tipc/group.c | 4 +-
net/tipc/monitor.c | 3 +-
net/vmw_vsock/af_vsock.c | 3 +
net/xdp/xskmap.c | 2 +-
security/ipe/eval.c | 12 +-
security/ipe/eval.h | 2 +-
security/ipe/fs.c | 8 +-
security/ipe/hooks.c | 22 +-
security/ipe/policy_fs.c | 3 +
security/landlock/access.h | 8 +
sound/hda/codecs/realtek/alc269.c | 9 +
tools/arch/riscv/include/asm/csr.h | 20 +-
tools/lib/bpf/libbpf.c | 7 +
tools/lib/bpf/relo_core.c | 58 ++--
.../testing/selftests/bpf/prog_tests/linked_list.c | 4 +-
tools/testing/selftests/cgroup/test_cpuset_prs.sh | 2 +
tools/testing/selftests/cgroup/test_memcontrol.c | 2 +-
.../ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc | 2 +-
tools/testing/selftests/kvm/steal_time.c | 30 ++-
tools/testing/selftests/nci/nci_dev.c | 45 ++--
virt/kvm/kvm_main.c | 30 ++-
471 files changed, 5769 insertions(+), 2585 deletions(-)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 001/457] drm/amd/display: Atomize IRQ register read/modify/write ops
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 002/457] ALSA: hda/realtek: Limit Star Labs internal mic boost Greg Kroah-Hartman
` (466 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello, Leo Li,
Chenyu Chen, Daniel Wheeler, Alex Deucher, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Li <sunpeng.li@amd.com>
[ Upstream commit 63e19ef3ddab806c472748c825f4dc88dcd994e8 ]
[Why]
The OTG_GLOBAL_SYNC_STATUS register controls various HW IRQ sources for
the output timing generator (OTG). VUPDATE_NO_LOCK is one of them.
To enable the IRQ, driver sets the VUPDATE_NO_LOCK_EN bit in the
GLOBAL_SYNC_STATUS register.
To ack the IRQ after it fires, the driver sets the VUPDATE_NO_LOCK_CLEAR
bit in the same GLOBAL_SYNC_STATUS register.
The bit sets are done through read/modify/write operations, which are
not atomic. Thus, the following race is possible:
Thread A: IRQ handler:
*HW IRQ fires*
# IRQ disable
val = read(GLOBAL_SYNC_STATUS)
unset(val, VUPDATE_NO_LOCK_EN)
write(val, GLOBAL_SYNC_STATUS)
# ACK reads VUPDATE_NO_LOCK_EN unset
val1 = read(GLOBAL_SYNC_STATUS)
set(val1, VUPDATE_NO_LOCK_CLEAR)
# IRQ enable
val = read(GLOBAL_SYNC_STATUS)
set(val, VUPDATE_NO_LOCK_EN)
write(val, GLOBAL_SYNC_STATUS)
# BAD! clears VUPDATE_NO_LOCK_EN
write(val1, GLOBAL_SYNC_STATUS)
Regarding the tagged Fixes: change, it appears the change made this race
more likely to occur. Since VUPDATE_NO_LOCK is now the sole IRQ source
for vblank handling, a single race on high refresh panels can lead to a
time out.
[How]
The GLOBAL_SYNC_STATUS register is only one example, other IRQ control
registers also share the same scheme. On top of GLOBAL_SYNC_STATUS,
let's clean up those as well.
To keep things simple, Let's atomize the IRQ rmw ops via a single
driver-wide spinlock. Due to the small scope of this lock, it is
unlikely to cause noticeable overhead on top of all the existing locking
within the IRQ set/handle paths.
Since DM is responsible for locking, wrap dc_interrupt_set/ack with the
spinlock in the new amdgpu_dm_irq_set/ack functions. Migrate/drop all
references in DM to dc_interrupt_set/ack to use amdgpu_dm_irq_set/ack
instead.
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5616
Fixes: c87e6635d2db ("drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock")
Reviewed-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Leo Li <sunpeng.li@amd.com>
Signed-off-by: Chenyu Chen <chen-yu.chen@amd.com>
Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 70de0a0216583a53c946155f8c8adedfdca6b4e7)
Cc: stable@vger.kernel.org
(cherry picked from commit 63e19ef3ddab806c472748c825f4dc88dcd994e8)
Modified for unit tests not present in 7.2.y
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 4 +-
.../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h | 12 ++++
.../amd/display/amdgpu_dm/amdgpu_dm_crtc.c | 3 +-
.../amd/display/amdgpu_dm/amdgpu_dm_helpers.c | 3 +-
.../drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c | 62 +++++++++++--------
.../drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h | 28 +++++++++
6 files changed, 82 insertions(+), 30 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index 5ba196dd9d7ad..bd78cfcc3477d 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -3344,7 +3344,7 @@ static void dm_gpureset_toggle_interrupts(struct amdgpu_device *adev,
if (acrtc && state->stream_status[i].plane_count != 0 &&
amdgpu_ip_version(adev, DCE_HWIP, 0) == 0) {
irq_source = IRQ_TYPE_PFLIP + acrtc->otg_inst;
- rc = dc_interrupt_set(adev->dm.dc, irq_source, enable) ? 0 : -EBUSY;
+ rc = amdgpu_dm_irq_set(adev, irq_source, enable) ? 0 : -EBUSY;
if (rc)
drm_warn(adev_to_drm(adev), "Failed to %s pflip interrupts\n",
enable ? "enable" : "disable");
@@ -3368,7 +3368,7 @@ static void dm_gpureset_toggle_interrupts(struct amdgpu_device *adev,
/* During gpu-reset we disable and then enable vblank irq, so
* don't use amdgpu_irq_get/put() to avoid refcount change.
*/
- if (!dc_interrupt_set(adev->dm.dc, irq_source, enable))
+ if (!amdgpu_dm_irq_set(adev, irq_source, enable))
drm_warn(adev_to_drm(adev), "Failed to %sable vblank interrupt\n", enable ? "en" : "dis");
} else if (acrtc && state->stream_status[i].plane_count != 0) {
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
index 797f944718108..d2602c0310b20 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
@@ -550,6 +550,18 @@ struct amdgpu_display_manager {
struct common_irq_params
vupdate_params[DC_IRQ_SOURCE_VUPDATE6 - DC_IRQ_SOURCE_VUPDATE1 + 1];
+ /**
+ * @irq_reg_lock:
+ *
+ * Serializes the read-modify-writes of the HW interrupt control
+ * registers. Several interrupt sources share one register - e.g. the
+ * enable and clear bits of both VSTARTUP (vblank) and VUPDATE_NO_LOCK
+ * live in OTG_GLOBAL_SYNC_STATUS. Therefore, enabling one source must
+ * not race with acking another. Held only across amdgpu_dm_irq_set()
+ * and amdgpu_dm_irq_ack().
+ */
+ spinlock_t irq_reg_lock;
+
/**
* @dmub_trace_params:
*
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
index f47ee9937adaa..7206439ea5d52 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
@@ -31,6 +31,7 @@
#include "amdgpu_dm_psr.h"
#include "amdgpu_dm_replay.h"
#include "amdgpu_dm_crtc.h"
+#include "amdgpu_dm_irq.h"
#include "amdgpu_dm_plane.h"
#include "amdgpu_dm_trace.h"
#include "amdgpu_dm_debugfs.h"
@@ -87,7 +88,7 @@ int amdgpu_dm_crtc_set_vupdate_irq(struct drm_crtc *crtc, bool enable)
irq_source = IRQ_TYPE_VUPDATE + acrtc->otg_inst;
- rc = dc_interrupt_set(adev->dm.dc, irq_source, enable) ? 0 : -EBUSY;
+ rc = amdgpu_dm_irq_set(adev, irq_source, enable) ? 0 : -EBUSY;
DRM_DEBUG_VBL("crtc %d - vupdate irq %sabling: r=%d\n",
acrtc->crtc_id, enable ? "en" : "dis", rc);
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c
index fe5b97e6f9603..ee7140d8dda8b 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_helpers.c
@@ -1378,12 +1378,13 @@ void dm_helpers_free_gpu_mem(
bool dm_helpers_dmub_outbox_interrupt_control(struct dc_context *ctx, bool enable)
{
+ struct amdgpu_device *adev = ctx->driver_context;
enum dc_irq_source irq_source;
bool ret;
irq_source = DC_IRQ_SOURCE_DMCUB_OUTBOX;
- ret = dc_interrupt_set(ctx->dc, irq_source, enable);
+ ret = amdgpu_dm_irq_set(adev, irq_source, enable);
DRM_DEBUG_DRIVER("Dmub trace irq %sabling: r=%d\n",
enable ? "en" : "dis", ret);
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c
index e49803a90edad..d59434e01dfdb 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.c
@@ -424,6 +424,7 @@ int amdgpu_dm_irq_init(struct amdgpu_device *adev)
DRM_DEBUG_KMS("DM_IRQ\n");
spin_lock_init(&adev->dm.irq_handler_list_table_lock);
+ spin_lock_init(&adev->dm.irq_reg_lock);
for (src = 0; src < DAL_IRQ_SOURCES_NUMBER; src++) {
/* low context handler list init */
@@ -496,7 +497,7 @@ void amdgpu_dm_irq_suspend(struct amdgpu_device *adev)
hnd_list_l = &adev->dm.irq_handler_list_low_tab[src];
hnd_list_h = &adev->dm.irq_handler_list_high_tab[src];
if (!list_empty(hnd_list_l) || !list_empty(hnd_list_h))
- dc_interrupt_set(adev->dm.dc, src, false);
+ amdgpu_dm_irq_set(adev, src, false);
DM_IRQ_TABLE_UNLOCK(adev, irq_table_flags);
@@ -533,7 +534,7 @@ void amdgpu_dm_irq_resume_early(struct amdgpu_device *adev)
hnd_list_l = &adev->dm.irq_handler_list_low_tab[src];
hnd_list_h = &adev->dm.irq_handler_list_high_tab[src];
if (!list_empty(hnd_list_l) || !list_empty(hnd_list_h))
- dc_interrupt_set(adev->dm.dc, src, true);
+ amdgpu_dm_irq_set(adev, src, true);
}
DM_IRQ_TABLE_UNLOCK(adev, irq_table_flags);
@@ -558,7 +559,7 @@ void amdgpu_dm_irq_resume_late(struct amdgpu_device *adev)
hnd_list_l = &adev->dm.irq_handler_list_low_tab[src];
hnd_list_h = &adev->dm.irq_handler_list_high_tab[src];
if (!list_empty(hnd_list_l) || !list_empty(hnd_list_h))
- dc_interrupt_set(adev->dm.dc, src, true);
+ amdgpu_dm_irq_set(adev, src, true);
}
DM_IRQ_TABLE_UNLOCK(adev, irq_table_flags);
@@ -645,6 +646,21 @@ static void amdgpu_dm_irq_immediate_work(struct amdgpu_device *adev,
DM_IRQ_TABLE_UNLOCK(adev, irq_table_flags);
}
+bool amdgpu_dm_irq_set(struct amdgpu_device *adev, enum dc_irq_source src,
+ bool enable)
+{
+ guard(spinlock_irqsave)(&adev->dm.irq_reg_lock);
+
+ return dc_interrupt_set(adev->dm.dc, src, enable);
+}
+
+void amdgpu_dm_irq_ack(struct amdgpu_device *adev, enum dc_irq_source src)
+{
+ guard(spinlock_irqsave)(&adev->dm.irq_reg_lock);
+
+ dc_interrupt_ack(adev->dm.dc, src);
+}
+
/**
* amdgpu_dm_irq_handler - Generic DM IRQ handler
* @adev: amdgpu base driver device containing the DM device
@@ -665,7 +681,7 @@ static int amdgpu_dm_irq_handler(struct amdgpu_device *adev,
entry->src_id,
entry->src_data[0]);
- dc_interrupt_ack(adev->dm.dc, src);
+ amdgpu_dm_irq_ack(adev, src);
/* Call high irq work immediately */
amdgpu_dm_irq_immediate_work(adev, src);
@@ -703,7 +719,7 @@ static int amdgpu_dm_set_hpd_irq_state(struct amdgpu_device *adev,
enum dc_irq_source src = amdgpu_dm_hpd_to_dal_irq_source(type);
bool st = (state == AMDGPU_IRQ_STATE_ENABLE);
- dc_interrupt_set(adev->dm.dc, src, st);
+ amdgpu_dm_irq_set(adev, src, st);
return 0;
}
@@ -737,7 +753,7 @@ static inline int dm_irq_state(struct amdgpu_device *adev,
if (dc && dc->caps.ips_support && dc->idle_optimizations_allowed)
dc_allow_idle_optimizations(dc, false);
- dc_interrupt_set(adev->dm.dc, irq_source, st);
+ amdgpu_dm_irq_set(adev, irq_source, st);
return 0;
}
@@ -791,7 +807,7 @@ static int amdgpu_dm_set_dmub_outbox_irq_state(struct amdgpu_device *adev,
enum dc_irq_source irq_source = DC_IRQ_SOURCE_DMCUB_OUTBOX;
bool st = (state == AMDGPU_IRQ_STATE_ENABLE);
- dc_interrupt_set(adev->dm.dc, irq_source, st);
+ amdgpu_dm_irq_set(adev, irq_source, st);
return 0;
}
@@ -817,7 +833,7 @@ static int amdgpu_dm_set_dmub_trace_irq_state(struct amdgpu_device *adev,
enum dc_irq_source irq_source = DC_IRQ_SOURCE_DMCUB_OUTBOX0;
bool st = (state == AMDGPU_IRQ_STATE_ENABLE);
- dc_interrupt_set(adev->dm.dc, irq_source, st);
+ amdgpu_dm_irq_set(adev, irq_source, st);
return 0;
}
@@ -881,9 +897,7 @@ void amdgpu_dm_set_irq_funcs(struct amdgpu_device *adev)
}
void amdgpu_dm_outbox_init(struct amdgpu_device *adev)
{
- dc_interrupt_set(adev->dm.dc,
- DC_IRQ_SOURCE_DMCUB_OUTBOX,
- true);
+ amdgpu_dm_irq_set(adev, DC_IRQ_SOURCE_DMCUB_OUTBOX, true);
}
/**
@@ -905,7 +919,7 @@ void amdgpu_dm_hpd_init(struct amdgpu_device *adev)
/* First, clear all hpd and hpdrx interrupts */
for (i = DC_IRQ_SOURCE_HPD1; i <= DC_IRQ_SOURCE_HPD6RX; i++) {
- if (!dc_interrupt_set(adev->dm.dc, i, false))
+ if (!amdgpu_dm_irq_set(adev, i, false))
drm_err(dev, "Failed to clear hpd(rx) source=%d on init\n",
i);
}
@@ -934,7 +948,7 @@ void amdgpu_dm_hpd_init(struct amdgpu_device *adev)
* of dm. Note that only hpd interrupt types are registered with
* base driver; hpd_rx types aren't. IOW, amdgpu_irq_get/put on
* hpd_rx isn't available. DM currently controls hpd_rx
- * explicitly with dc_interrupt_set()
+ * explicitly with amdgpu_dm_irq_set()
*/
if (dc_link->irq_source_hpd != DC_IRQ_SOURCE_INVALID) {
irq_type = dc_link->irq_source_hpd - DC_IRQ_SOURCE_HPD1;
@@ -943,23 +957,21 @@ void amdgpu_dm_hpd_init(struct amdgpu_device *adev)
* and what bios reports as the # of connectors with hpd
* sources. Since the # of hpd source types registered
* with base driver == mode_info.num_hpd, we have to
- * fallback to dc_interrupt_set for the remaining types.
+ * fallback to amdgpu_dm_irq_set for the remaining types.
*/
if (irq_type < adev->mode_info.num_hpd) {
if (amdgpu_irq_get(adev, &adev->hpd_irq, irq_type))
drm_err(dev, "DM_IRQ: Failed get HPD for source=%d)!\n",
dc_link->irq_source_hpd);
} else {
- dc_interrupt_set(adev->dm.dc,
- dc_link->irq_source_hpd,
- true);
+ amdgpu_dm_irq_set(adev, dc_link->irq_source_hpd,
+ true);
}
}
if (dc_link->irq_source_hpd_rx != DC_IRQ_SOURCE_INVALID) {
- dc_interrupt_set(adev->dm.dc,
- dc_link->irq_source_hpd_rx,
- true);
+ amdgpu_dm_irq_set(adev, dc_link->irq_source_hpd_rx,
+ true);
}
}
drm_connector_list_iter_end(&iter);
@@ -1003,16 +1015,14 @@ void amdgpu_dm_hpd_fini(struct amdgpu_device *adev)
drm_err(dev, "DM_IRQ: Failed put HPD for source=%d!\n",
dc_link->irq_source_hpd);
} else {
- dc_interrupt_set(adev->dm.dc,
- dc_link->irq_source_hpd,
- false);
+ amdgpu_dm_irq_set(adev, dc_link->irq_source_hpd,
+ false);
}
}
if (dc_link->irq_source_hpd_rx != DC_IRQ_SOURCE_INVALID) {
- dc_interrupt_set(adev->dm.dc,
- dc_link->irq_source_hpd_rx,
- false);
+ amdgpu_dm_irq_set(adev, dc_link->irq_source_hpd_rx,
+ false);
}
}
drm_connector_list_iter_end(&iter);
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h
index 4f6b58f4f90d7..f0a4577848f35 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_irq.h
@@ -81,6 +81,34 @@ void amdgpu_dm_irq_unregister_interrupt(struct amdgpu_device *adev,
enum dc_irq_source irq_source,
void *ih_index);
+/**
+ * amdgpu_dm_irq_set - enable or disable a DC interrupt source.
+ *
+ * @adev: AMD DRM device
+ * @src: DC interrupt source to toggle
+ * @enable: true to enable the source, false to disable it
+ *
+ * DM-wide replacement for dc_interrupt_set(). As locking is DM's
+ * responsibility, this is a thin wrapper serializes the underlying
+ * read-modify-write against the other interrupt sources sharing HW control
+ * registers with @src, so DM must never call dc_interrupt_set() directly.
+ *
+ * Returns: true if the source was toggled.
+ */
+bool amdgpu_dm_irq_set(struct amdgpu_device *adev, enum dc_irq_source src,
+ bool enable);
+
+/**
+ * amdgpu_dm_irq_ack - acknowledge a DC interrupt source.
+ *
+ * @adev: AMD DRM device
+ * @src: DC interrupt source to acknowledge
+ *
+ * DM-wide replacement for dc_interrupt_ack(), serialized the same way as
+ * amdgpu_dm_irq_set().
+ */
+void amdgpu_dm_irq_ack(struct amdgpu_device *adev, enum dc_irq_source src);
+
void amdgpu_dm_set_irq_funcs(struct amdgpu_device *adev);
void amdgpu_dm_outbox_init(struct amdgpu_device *adev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 002/457] ALSA: hda/realtek: Limit Star Labs internal mic boost
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 001/457] drm/amd/display: Atomize IRQ register read/modify/write ops Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 003/457] ALSA: hda/realtek: Add StarFighter HDA SSID Greg Kroah-Hartman
` (465 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Rhodes, Takashi Iwai,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Rhodes <sean@starlabs.systems>
[ Upstream commit 186d4adbb40138e7cb7cffc87a81e95630ced123 ]
The 30 dB internal mic boost is too high for laptops, especially with fans. Limit Star Labs internal mic boost to 10 dB.
Signed-off-by: Sean Rhodes <sean@starlabs.systems>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/be87292613b24150d6321adac102b4b25d00e9e6.1785532385.git.sean@starlabs.systems
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/hda/codecs/realtek/alc269.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/sound/hda/codecs/realtek/alc269.c b/sound/hda/codecs/realtek/alc269.c
index c31fed171c419..aa2a63d9a63e8 100644
--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -4209,6 +4209,7 @@ enum {
ALC245_FIXUP_CLEVO_NOISY_MIC,
ALC269_FIXUP_VAIO_VJFH52_MIC_NO_PRESENCE,
ALC233_FIXUP_MEDION_MTL_SPK,
+ ALC269_FIXUP_STARLABS_LIMIT_INT_MIC_BOOST,
ALC233_FIXUP_STARLABS_STARFIGHTER,
ALC294_FIXUP_BASS_SPEAKER_15,
ALC283_FIXUP_DELL_HP_RESUME,
@@ -6755,6 +6756,10 @@ static const struct hda_fixup alc269_fixups[] = {
{ }
},
},
+ [ALC269_FIXUP_STARLABS_LIMIT_INT_MIC_BOOST] = {
+ .type = HDA_FIXUP_FUNC,
+ .v.func = alc269_fixup_limit_int_mic_boost,
+ },
[ALC233_FIXUP_STARLABS_STARFIGHTER] = {
.type = HDA_FIXUP_FUNC,
.v.func = alc233_fixup_starlabs_starfighter,
@@ -8168,6 +8173,7 @@ static const struct hda_quirk alc269_fixup_vendor_tbl[] = {
SND_PCI_QUIRK_VENDOR(0x104d, "Sony VAIO", ALC269_FIXUP_SONY_VAIO),
SND_PCI_QUIRK_VENDOR(0x17aa, "Lenovo XPAD", ALC269_FIXUP_LENOVO_XPAD_ACPI),
SND_PCI_QUIRK_VENDOR(0x19e5, "Huawei Matebook", ALC255_FIXUP_MIC_MUTE_LED),
+ SND_PCI_QUIRK_VENDOR(0x2145, "Star Labs", ALC269_FIXUP_STARLABS_LIMIT_INT_MIC_BOOST),
{}
};
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 003/457] ALSA: hda/realtek: Add StarFighter HDA SSID
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 001/457] drm/amd/display: Atomize IRQ register read/modify/write ops Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 002/457] ALSA: hda/realtek: Limit Star Labs internal mic boost Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 004/457] drm/amd/display: Remove sink usage from DPMS Greg Kroah-Hartman
` (464 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Rhodes, Takashi Iwai,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Rhodes <sean@starlabs.systems>
[ Upstream commit cd401c70df472d3eddd0b6b055726a03c212181a ]
Support the new StarFighter HDA SSID while keeping the existing SSID chained to the same quirk until the new match reaches backports.
Signed-off-by: Sean Rhodes <sean@starlabs.systems>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/06865eaedf3de8dff199e9aa7e86cd135572f20f.1785532385.git.sean@starlabs.systems
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/hda/codecs/realtek/alc269.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/sound/hda/codecs/realtek/alc269.c b/sound/hda/codecs/realtek/alc269.c
index aa2a63d9a63e8..1e0612c39c89b 100644
--- a/sound/hda/codecs/realtek/alc269.c
+++ b/sound/hda/codecs/realtek/alc269.c
@@ -6763,6 +6763,8 @@ static const struct hda_fixup alc269_fixups[] = {
[ALC233_FIXUP_STARLABS_STARFIGHTER] = {
.type = HDA_FIXUP_FUNC,
.v.func = alc233_fixup_starlabs_starfighter,
+ .chained = true,
+ .chain_id = ALC269_FIXUP_STARLABS_LIMIT_INT_MIC_BOOST,
},
[ALC294_FIXUP_BASS_SPEAKER_15] = {
.type = HDA_FIXUP_FUNC,
@@ -8090,6 +8092,7 @@ static const struct hda_quirk alc269_fixup_tbl[] = {
SND_PCI_QUIRK(0x1f66, 0x0105, "Ayaneo Portable Game Player", ALC287_FIXUP_CS35L41_I2C_2),
SND_PCI_QUIRK(0x2014, 0x800a, "Positivo ARN50", ALC269_FIXUP_LIMIT_INT_MIC_BOOST),
SND_PCI_QUIRK(0x2039, 0x0001, "Inspur S14-G1", ALC295_FIXUP_CHROME_BOOK),
+ SND_PCI_QUIRK(0x2145, 0x0001, "Star Labs StarFighter", ALC233_FIXUP_STARLABS_STARFIGHTER),
SND_PCI_QUIRK(0x2782, 0x0214, "VAIO VJFE-CL", ALC269_FIXUP_LIMIT_INT_MIC_BOOST),
SND_PCI_QUIRK(0x2782, 0x0228, "Infinix ZERO BOOK 13", ALC269VB_FIXUP_INFINIX_ZERO_BOOK_13),
SND_PCI_QUIRK(0x2782, 0x0232, "CHUWI CoreBook XPro", ALC269VB_FIXUP_CHUWI_COREBOOK_XPRO),
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 004/457] drm/amd/display: Remove sink usage from DPMS
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 003/457] ALSA: hda/realtek: Add StarFighter HDA SSID Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 005/457] remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage Greg Kroah-Hartman
` (463 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Kazlauskas,
Dominik Kaszewski, George Zhang, Alex Deucher, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dominik Kaszewski <dominik.kaszewski@amd.com>
[ Upstream commit 8fa813b7fd1eccbed13e126166cf764f1f11a7d3 ]
[Why]
stream->sink is optional and can be null, so should always be checked
before dereference. Additionally, most of its usage in DPMS sequences
is for stream->sink->link, which can be replaced with stream->link,
as the two should always be the same.
[How]
* Replace stream->sink->link in DPMS on/off
* Add assert to USB4 BW allocation where sink is required
* Avoid inconsistencies in resource access, e.g. don't repeat
stream->link after it was already saved to a local variable
* Pull out effective VPG calculation to helper getter
* Formatting fixes
Reviewed-by: Nicholas Kazlauskas <nicholas.kazlauskas@amd.com>
Signed-off-by: Dominik Kaszewski <dominik.kaszewski@amd.com>
Signed-off-by: George Zhang <george.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../gpu/drm/amd/display/dc/link/link_dpms.c | 178 +++++++++---------
1 file changed, 90 insertions(+), 88 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
index ca59977487994..f49dba6b4e426 100644
--- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
@@ -2296,6 +2296,8 @@ static enum dc_status enable_link(
static bool allocate_usb4_bandwidth_for_stream(struct dc_stream_state *stream, int stream_bw)
{
+ ASSERT(stream->sink);
+
struct dc_link *link = stream->sink->link;
int req_bw = stream_bw;
@@ -2342,6 +2344,8 @@ static bool allocate_usb4_bandwidth_for_stream(struct dc_stream_state *stream, i
static bool allocate_usb4_bandwidth(struct dc_stream_state *stream)
{
+ ASSERT(stream->sink);
+
bool ret;
int bw = dc_bandwidth_in_kbps_from_timing(&stream->timing,
@@ -2361,38 +2365,43 @@ static bool deallocate_usb4_bandwidth(struct dc_stream_state *stream)
return ret;
}
+static struct vpg *get_vpg(struct pipe_ctx *pipe_ctx)
+{
+ if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
+ return pipe_ctx->stream_res.hpo_frl_stream_enc->vpg;
+ else if (dp_is_128b_132b_signal(pipe_ctx))
+ return pipe_ctx->stream_res.hpo_dp_stream_enc->vpg;
+ else
+ return pipe_ctx->stream_res.stream_enc->vpg;
+}
+
void link_set_dpms_off(struct pipe_ctx *pipe_ctx)
{
- struct dc *dc = pipe_ctx->stream->ctx->dc;
+ DC_LOGGER_INIT(pipe_ctx->stream->ctx->logger);
struct dc_stream_state *stream = pipe_ctx->stream;
- struct dc_link *link = stream->sink->link;
- struct vpg *vpg = pipe_ctx->stream_res.stream_enc->vpg;
+ struct dc *dc = stream->ctx->dc;
+ struct dc_link *link = stream->link;
+ struct vpg *vpg = get_vpg(pipe_ctx);
enum dp_panel_mode panel_mode_dp = dp_get_panel_mode(link);
- DC_LOGGER_INIT(pipe_ctx->stream->ctx->logger);
-
ASSERT(is_master_pipe_for_link(link, pipe_ctx));
- if (dp_is_128b_132b_signal(pipe_ctx))
- vpg = pipe_ctx->stream_res.hpo_dp_stream_enc->vpg;
- if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
- vpg = pipe_ctx->stream_res.hpo_frl_stream_enc->vpg;
- if (dc_is_virtual_signal(pipe_ctx->stream->signal))
+ if (dc_is_virtual_signal(stream->signal))
return;
- if (pipe_ctx->stream->sink) {
- if (pipe_ctx->stream->sink->sink_signal != SIGNAL_TYPE_VIRTUAL &&
- pipe_ctx->stream->sink->sink_signal != SIGNAL_TYPE_NONE) {
+ if (stream->sink) {
+ if (stream->sink->sink_signal != SIGNAL_TYPE_VIRTUAL &&
+ stream->sink->sink_signal != SIGNAL_TYPE_NONE) {
DC_LOG_DC("%s pipe_ctx dispname=%s signal=%x link=%d sink_count=%d\n", __func__,
- pipe_ctx->stream->sink->edid_caps.display_name,
- pipe_ctx->stream->signal, link->link_index, link->sink_count);
+ stream->sink->edid_caps.display_name,
+ stream->signal, link->link_index, link->sink_count);
}
}
link_wait_for_unlocked(link);
- if (!pipe_ctx->stream->sink->edid_caps.panel_patch.skip_avmute) {
- if (dc_is_hdmi_signal(pipe_ctx->stream->signal))
+ if (stream->sink && !stream->sink->edid_caps.panel_patch.skip_avmute) {
+ if (dc_is_hdmi_signal(stream->signal))
set_avmute(pipe_ctx, true);
}
@@ -2402,15 +2411,15 @@ void link_set_dpms_off(struct pipe_ctx *pipe_ctx)
dc->hwss.blank_stream(pipe_ctx);
if (pipe_ctx->link_config.dp_tunnel_settings.should_use_dp_bw_allocation)
- deallocate_usb4_bandwidth(pipe_ctx->stream);
+ deallocate_usb4_bandwidth(stream);
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST)
+ if (stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST)
deallocate_mst_payload(pipe_ctx);
- else if (dc_is_dp_sst_signal(pipe_ctx->stream->signal) &&
+ else if (dc_is_dp_sst_signal(stream->signal) &&
dp_is_128b_132b_signal(pipe_ctx))
update_sst_payload(pipe_ctx, false);
- if (dc_is_hdmi_signal(pipe_ctx->stream->signal)) {
+ if (dc_is_hdmi_signal(stream->signal)) {
struct ext_hdmi_settings settings = {0};
enum engine_id eng_id = pipe_ctx->stream_res.stream_enc->id;
@@ -2433,7 +2442,7 @@ void link_set_dpms_off(struct pipe_ctx *pipe_ctx)
}
}
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_DISPLAY_PORT &&
+ if (stream->signal == SIGNAL_TYPE_DISPLAY_PORT &&
!dp_is_128b_132b_signal(pipe_ctx)) {
/* In DP1.x SST mode, our encoder will go to TPS1
@@ -2443,18 +2452,18 @@ void link_set_dpms_off(struct pipe_ctx *pipe_ctx)
* state machine.
* In DP2 or MST mode, our encoder will stay video active
*/
- disable_link(pipe_ctx->stream->link, &pipe_ctx->link_res, pipe_ctx->stream->signal);
+ disable_link(link, &pipe_ctx->link_res, stream->signal);
dc->hwss.disable_stream(pipe_ctx);
} else {
dc->hwss.disable_stream(pipe_ctx);
- disable_link(pipe_ctx->stream->link, &pipe_ctx->link_res, pipe_ctx->stream->signal);
+ disable_link(link, &pipe_ctx->link_res, stream->signal);
}
edp_set_panel_assr(link, pipe_ctx, &panel_mode_dp, false);
- if (pipe_ctx->stream->timing.flags.DSC) {
- if (dc_is_dp_signal(pipe_ctx->stream->signal))
+ if (stream->timing.flags.DSC) {
+ if (dc_is_dp_signal(stream->signal))
link_set_dsc_enable(pipe_ctx, false);
- else if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
+ else if (dc_is_hdmi_frl_signal(stream->signal))
link_set_dsc_on_stream(pipe_ctx, false);
}
if (dp_is_128b_132b_signal(pipe_ctx)) {
@@ -2468,7 +2477,7 @@ void link_set_dpms_off(struct pipe_ctx *pipe_ctx)
/* for psp not exist case */
if (link->connector_signal == SIGNAL_TYPE_EDP && dc->debug.psp_disabled_wa) {
/* reset internal save state to default since eDP is off */
- enum dp_panel_mode panel_mode = dp_get_panel_mode(pipe_ctx->stream->link);
+ enum dp_panel_mode panel_mode = dp_get_panel_mode(link);
/* since current psp not loaded, we need to reset it to default */
link->panel_mode = panel_mode;
}
@@ -2478,62 +2487,57 @@ void link_set_dpms_on(
struct dc_state *state,
struct pipe_ctx *pipe_ctx)
{
- struct dc *dc = pipe_ctx->stream->ctx->dc;
+ DC_LOGGER_INIT(pipe_ctx->stream->ctx->logger);
struct dc_stream_state *stream = pipe_ctx->stream;
- struct dc_link *link = stream->sink->link;
+ struct dc *dc = stream->ctx->dc;
+ struct dc_link *link = stream->link;
enum dc_status status;
struct link_encoder *link_enc = pipe_ctx->link_res.dio_link_enc;
enum otg_out_mux_dest otg_out_dest = OUT_MUX_DIO;
- struct vpg *vpg = pipe_ctx->stream_res.stream_enc->vpg;
+ struct vpg *vpg = get_vpg(pipe_ctx);
const struct link_hwss *link_hwss = get_link_hwss(link, &pipe_ctx->link_res);
bool apply_edp_fast_boot_optimization =
- pipe_ctx->stream->apply_edp_fast_boot_optimization;
-
- DC_LOGGER_INIT(pipe_ctx->stream->ctx->logger);
+ stream->apply_edp_fast_boot_optimization;
ASSERT(is_master_pipe_for_link(link, pipe_ctx));
- if (dp_is_128b_132b_signal(pipe_ctx))
- vpg = pipe_ctx->stream_res.hpo_dp_stream_enc->vpg;
- if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
- vpg = pipe_ctx->stream_res.hpo_frl_stream_enc->vpg;
- if (dc_is_virtual_signal(pipe_ctx->stream->signal))
+ if (dc_is_virtual_signal(stream->signal))
return;
- if (pipe_ctx->stream->sink) {
- if (pipe_ctx->stream->sink->sink_signal != SIGNAL_TYPE_VIRTUAL &&
- pipe_ctx->stream->sink->sink_signal != SIGNAL_TYPE_NONE) {
+ if (stream->sink) {
+ if (stream->sink->sink_signal != SIGNAL_TYPE_VIRTUAL &&
+ stream->sink->sink_signal != SIGNAL_TYPE_NONE) {
DC_LOG_DC("%s pipe_ctx dispname=%s signal=%x link=%d sink_count=%d\n", __func__,
- pipe_ctx->stream->sink->edid_caps.display_name,
- pipe_ctx->stream->signal,
+ stream->sink->edid_caps.display_name,
+ stream->signal,
link->link_index,
link->sink_count);
}
}
- link_wait_for_unlocked(stream->link);
+ link_wait_for_unlocked(link);
if (!dc->config.unify_link_enc_assignment)
link_enc = link_enc_cfg_get_link_enc(link);
ASSERT(link_enc);
- if (!dc_is_virtual_signal(pipe_ctx->stream->signal)
- && !dc_is_hdmi_frl_signal(pipe_ctx->stream->signal)
+ if (!dc_is_virtual_signal(stream->signal)
+ && !dc_is_hdmi_frl_signal(stream->signal)
&& !dp_is_128b_132b_signal(pipe_ctx)) {
if (link_enc)
link_enc->funcs->setup(
link_enc,
- pipe_ctx->stream->signal);
+ stream->signal);
}
- pipe_ctx->stream->link->link_state_valid = true;
+ link->link_state_valid = true;
- if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
- hdmi_frl_decide_link_settings(stream, &stream->link->frl_link_settings, &pipe_ctx->dsc_padding_params);
+ if (dc_is_hdmi_frl_signal(stream->signal))
+ hdmi_frl_decide_link_settings(stream, &link->frl_link_settings, &pipe_ctx->dsc_padding_params);
if (pipe_ctx->stream_res.tg->funcs->set_out_mux) {
if (dp_is_128b_132b_signal(pipe_ctx))
otg_out_dest = OUT_MUX_HPO_DP;
- else if (dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
+ else if (dc_is_hdmi_frl_signal(stream->signal))
otg_out_dest = OUT_MUX_HPO_FRL;
else
otg_out_dest = OUT_MUX_DIO;
@@ -2542,7 +2546,7 @@ void link_set_dpms_on(
link_hwss->setup_stream_attribute(pipe_ctx);
- pipe_ctx->stream->apply_edp_fast_boot_optimization = false;
+ stream->apply_edp_fast_boot_optimization = false;
// Enable VPG before building infoframe
if (vpg && vpg->funcs->vpg_poweron)
@@ -2551,15 +2555,15 @@ void link_set_dpms_on(
resource_build_info_frame(pipe_ctx);
dc->hwss.update_info_frame(pipe_ctx);
- if (dc_is_dp_signal(pipe_ctx->stream->signal))
+ if (dc_is_dp_signal(stream->signal))
dp_trace_source_sequence(link, DPCD_SOURCE_SEQ_AFTER_UPDATE_INFO_FRAME);
/* Do not touch link on seamless boot optimization. */
- if (pipe_ctx->stream->apply_seamless_boot_optimization) {
- pipe_ctx->stream->dpms_off = false;
+ if (stream->apply_seamless_boot_optimization) {
+ stream->dpms_off = false;
/* Still enable stream features & audio on seamless boot for DP external displays */
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_DISPLAY_PORT) {
+ if (stream->signal == SIGNAL_TYPE_DISPLAY_PORT) {
enable_stream_features(pipe_ctx);
dc->hwss.enable_audio_stream(pipe_ctx);
}
@@ -2569,11 +2573,11 @@ void link_set_dpms_on(
}
/* eDP lit up by bios already, no need to enable again. */
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_EDP &&
+ if (stream->signal == SIGNAL_TYPE_EDP &&
apply_edp_fast_boot_optimization &&
- !pipe_ctx->stream->timing.flags.DSC &&
+ !stream->timing.flags.DSC &&
!pipe_ctx->next_odm_pipe) {
- pipe_ctx->stream->dpms_off = false;
+ stream->dpms_off = false;
update_psp_stream_config(pipe_ctx, false);
if (link->is_dds) {
@@ -2586,7 +2590,7 @@ void link_set_dpms_on(
return;
}
- if (pipe_ctx->stream->dpms_off)
+ if (stream->dpms_off)
return;
/* For Dp tunneling link, a pending HPD means that we have a race condition between processing
@@ -2604,9 +2608,9 @@ void link_set_dpms_on(
* will be automatically set at a later time when the video is enabled
* (DP_VID_STREAM_EN = 1).
*/
- if (pipe_ctx->stream->timing.flags.DSC) {
- if (dc_is_dp_signal(pipe_ctx->stream->signal) ||
- dc_is_virtual_signal(pipe_ctx->stream->signal))
+ if (stream->timing.flags.DSC) {
+ if (dc_is_dp_signal(stream->signal) ||
+ dc_is_virtual_signal(stream->signal))
link_set_dsc_enable(pipe_ctx, true);
}
@@ -2617,7 +2621,7 @@ void link_set_dpms_on(
if (status != DC_OK) {
DC_LOG_WARNING("enabling link %u failed: %d\n",
- pipe_ctx->stream->link->link_index,
+ link->link_index,
status);
/* Abort stream enable *unless* the failure was due to
@@ -2627,19 +2631,18 @@ void link_set_dpms_on(
*/
if ((status != DC_FAIL_DP_LINK_TRAINING &&
status != DC_FAIL_HDMI_FRL_LINK_TRAINING) ||
- pipe_ctx->stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST) {
- if (false == stream->link->link_status.link_active)
- disable_link(stream->link, &pipe_ctx->link_res,
- pipe_ctx->stream->signal);
+ stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST) {
+ if (false == link->link_status.link_active)
+ disable_link(link, &pipe_ctx->link_res,
+ stream->signal);
BREAK_TO_DEBUGGER();
return;
}
}
- if (pipe_ctx->stream->timing.flags.DSC &&
- dc_is_hdmi_frl_signal(pipe_ctx->stream->signal))
- //TODO: bring HDMI FRL in line with DP
- link_set_dsc_on_stream(pipe_ctx, true);
+ if (stream->timing.flags.DSC && dc_is_hdmi_frl_signal(stream->signal))
+ //TODO: bring HDMI FRL in line with DP
+ link_set_dsc_on_stream(pipe_ctx, true);
/* turn off otg test pattern if enable */
if (pipe_ctx->stream_res.tg->funcs->set_test_pattern)
@@ -2651,37 +2654,37 @@ void link_set_dpms_on(
* as a workaround for the incorrect value being applied
* from transmitter control.
*/
- if (!(dc_is_virtual_signal(pipe_ctx->stream->signal) ||
- dc_is_hdmi_frl_signal(pipe_ctx->stream->signal) ||
+ if (!(dc_is_virtual_signal(stream->signal) ||
+ dc_is_hdmi_frl_signal(stream->signal) ||
dp_is_128b_132b_signal(pipe_ctx))) {
if (link_enc)
link_enc->funcs->setup(
link_enc,
- pipe_ctx->stream->signal);
+ stream->signal);
}
dc->hwss.enable_stream(pipe_ctx);
/* Set DPS PPS SDP (AKA "info frames") */
- if (pipe_ctx->stream->timing.flags.DSC) {
- if (dc_is_dp_signal(pipe_ctx->stream->signal) ||
- dc_is_virtual_signal(pipe_ctx->stream->signal)) {
+ if (stream->timing.flags.DSC) {
+ if (dc_is_dp_signal(stream->signal) ||
+ dc_is_virtual_signal(stream->signal)) {
dp_set_dsc_on_rx(pipe_ctx, true);
link_set_dsc_pps_packet(pipe_ctx, true, true);
}
}
- if (dc_is_dp_signal(pipe_ctx->stream->signal))
+ if (dc_is_dp_signal(stream->signal))
dp_set_hblank_reduction_on_rx(pipe_ctx);
if (pipe_ctx->link_config.dp_tunnel_settings.should_use_dp_bw_allocation)
- allocate_usb4_bandwidth(pipe_ctx->stream);
+ allocate_usb4_bandwidth(stream);
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST)
+ if (stream->signal == SIGNAL_TYPE_DISPLAY_PORT_MST)
allocate_mst_payload(pipe_ctx);
- else if (dc_is_dp_sst_signal(pipe_ctx->stream->signal) &&
+ else if (dc_is_dp_sst_signal(stream->signal) &&
dp_is_128b_132b_signal(pipe_ctx))
update_sst_payload(pipe_ctx, true);
@@ -2690,23 +2693,22 @@ void link_set_dpms_on(
* training and stream unblank resolves the corruption issue.
* This is workaround.
*/
- if (pipe_ctx->stream->signal == SIGNAL_TYPE_EDP &&
+ if (stream->signal == SIGNAL_TYPE_EDP &&
link->is_display_mux_present)
msleep(20);
dc->hwss.unblank_stream(pipe_ctx,
- &pipe_ctx->stream->link->cur_link_settings);
+ &link->cur_link_settings);
if (stream->sink_patches.delay_ignore_msa > 0)
msleep(stream->sink_patches.delay_ignore_msa);
- if (dc_is_dp_signal(pipe_ctx->stream->signal))
+ if (dc_is_dp_signal(stream->signal))
enable_stream_features(pipe_ctx);
update_psp_stream_config(pipe_ctx, false);
dc->hwss.enable_audio_stream(pipe_ctx);
- if (dc_is_hdmi_signal(pipe_ctx->stream->signal)) {
+ if (dc_is_hdmi_signal(stream->signal))
set_avmute(pipe_ctx, false);
- }
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 005/457] remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 004/457] drm/amd/display: Remove sink usage from DPMS Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 006/457] KVM: s390: Fix dirty marking in adapter_indicators_set*() Greg Kroah-Hartman
` (462 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mostafa Saleh, Bjorn Andersson,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mostafa Saleh <smostafa@google.com>
[ Upstream commit 0d8e2195bce6f08c1c53c5ef4d7347fe46418101 ]
During adsp_map_carveout, the IOVA is computed by combining the
physical address and the SID:
iova = adsp->mem_phys | (sid << 32);
However, adsp_unmap_carveout() uses the physical address and not
the IOVA in iommu_unmap(), causing the unmap to fail or leak
mappings because the address doesn't match the original IOVA.
Cache the constructed IOVA within the qcom_adsp device struct
during mapping and use it during unmapping.
Fixes: f22eedff28af ("remoteproc: qcom: Add support for memory sandbox")
Signed-off-by: Mostafa Saleh <smostafa@google.com>
Link: https://lore.kernel.org/r/20260827203055.640116-1-smostafa@google.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/qcom_q6v5_adsp.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/remoteproc/qcom_q6v5_adsp.c b/drivers/remoteproc/qcom_q6v5_adsp.c
index c81e6c33c7479..9c5dedf0aa605 100644
--- a/drivers/remoteproc/qcom_q6v5_adsp.c
+++ b/drivers/remoteproc/qcom_q6v5_adsp.c
@@ -104,6 +104,7 @@ struct qcom_adsp {
struct completion stop_done;
phys_addr_t mem_phys;
+ unsigned long iova;
phys_addr_t mem_reloc;
void *mem_region;
size_t mem_size;
@@ -333,7 +334,7 @@ static void adsp_unmap_carveout(struct rproc *rproc)
struct qcom_adsp *adsp = rproc->priv;
if (adsp->has_iommu)
- iommu_unmap(rproc->domain, adsp->mem_phys, adsp->mem_size);
+ iommu_unmap(rproc->domain, adsp->iova, adsp->mem_size);
}
static int adsp_map_carveout(struct rproc *rproc)
@@ -341,7 +342,6 @@ static int adsp_map_carveout(struct rproc *rproc)
struct qcom_adsp *adsp = rproc->priv;
struct of_phandle_args args;
long long sid;
- unsigned long iova;
int ret;
if (!adsp->has_iommu)
@@ -358,9 +358,9 @@ static int adsp_map_carveout(struct rproc *rproc)
of_node_put(args.np);
/* Add SID configuration for ADSP Firmware to SMMU */
- iova = adsp->mem_phys | (sid << 32);
+ adsp->iova = adsp->mem_phys | (sid << 32);
- ret = iommu_map(rproc->domain, iova, adsp->mem_phys,
+ ret = iommu_map(rproc->domain, adsp->iova, adsp->mem_phys,
adsp->mem_size, IOMMU_READ | IOMMU_WRITE,
GFP_KERNEL);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 006/457] KVM: s390: Fix dirty marking in adapter_indicators_set*()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 005/457] remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 007/457] KVM: s390: Fix _gaccess_shadow_fault() Greg Kroah-Hartman
` (461 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit d215f014b3526a9898d87bfb4b866287f0864cc9 ]
When the indicator and/or summary bits are set in the guest, the
accessed page was only marked dirty in KVM if the access was performed
using the slow path; accesses through the new kvm_arch_set_irq_inatomic
fast inject path would not mark the page as dirty.
Fix by adding/moving the missing calls to mark_page_dirty(). Note that
for the inatomic path set_page_dirty{,_lock}() is not needed as the
page stays pinned; the unpin path correctly marks it as dirty.
Opportunistically reorder the local variables to be in reverse
Christmas tree order and refactor to use guard().
Fixes: 1e95e3bc6b05 ("KVM: s390: Enable adapter_indicators_set to use mapped pages")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260828115439.145885-2-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/interrupt.c | 75 ++++++++++++++++++++-------------------
1 file changed, 38 insertions(+), 37 deletions(-)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index d33dd58f4a4fd..70431eb38aa50 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -2976,61 +2976,58 @@ static int adapter_indicators_set(struct kvm *kvm,
struct s390_io_adapter *adapter,
struct kvm_s390_adapter_int *adapter_int)
{
- unsigned long bit;
- int summary_set, idx;
struct s390_map_info *ind_info, *summary_info;
- void *map;
struct page *ind_page, *summary_page;
- unsigned long flags;
+ unsigned long bit;
+ int summary_set;
+ void *map;
ind_page = NULL;
- spin_lock_irqsave(&adapter->maps_lock, flags);
- ind_info = get_map_info(adapter, adapter_int->ind_addr);
+ scoped_guard(spinlock_irqsave, &adapter->maps_lock) {
+ ind_info = get_map_info(adapter, adapter_int->ind_addr);
+ if (ind_info) {
+ map = page_address(ind_info->page);
+ bit = get_ind_bit(ind_info->addr, adapter_int->ind_offset, adapter->swap);
+ set_bit(bit, map);
+ }
+ }
if (!ind_info) {
- spin_unlock_irqrestore(&adapter->maps_lock, flags);
ind_page = pin_map_page(kvm, adapter_int->ind_addr, 0);
if (!ind_page)
return -1;
- idx = srcu_read_lock(&kvm->srcu);
map = page_address(ind_page);
bit = get_ind_bit(adapter_int->ind_addr,
adapter_int->ind_offset, adapter->swap);
set_bit(bit, map);
- mark_page_dirty(kvm, adapter_int->ind_gaddr >> PAGE_SHIFT);
set_page_dirty_lock(ind_page);
- srcu_read_unlock(&kvm->srcu, idx);
unpin_user_page(ind_page);
- } else {
- map = page_address(ind_info->page);
- bit = get_ind_bit(ind_info->addr, adapter_int->ind_offset, adapter->swap);
- set_bit(bit, map);
- spin_unlock_irqrestore(&adapter->maps_lock, flags);
}
+ scoped_guard(srcu, &kvm->srcu)
+ mark_page_dirty(kvm, gpa_to_gfn(adapter_int->ind_gaddr));
- spin_lock_irqsave(&adapter->maps_lock, flags);
- summary_info = get_map_info(adapter, adapter_int->summary_addr);
+ scoped_guard(spinlock_irqsave, &adapter->maps_lock) {
+ summary_info = get_map_info(adapter, adapter_int->summary_addr);
+ if (summary_info) {
+ map = page_address(summary_info->page);
+ bit = get_ind_bit(summary_info->addr, adapter_int->summary_offset,
+ adapter->swap);
+ summary_set = test_and_set_bit(bit, map);
+ }
+ }
if (!summary_info) {
- spin_unlock_irqrestore(&adapter->maps_lock, flags);
summary_page = pin_map_page(kvm, adapter_int->summary_addr, 0);
if (WARN_ON_ONCE(!summary_page))
return -1;
- idx = srcu_read_lock(&kvm->srcu);
map = page_address(summary_page);
bit = get_ind_bit(adapter_int->summary_addr,
adapter_int->summary_offset, adapter->swap);
summary_set = test_and_set_bit(bit, map);
- mark_page_dirty(kvm, adapter_int->summary_gaddr >> PAGE_SHIFT);
set_page_dirty_lock(summary_page);
- srcu_read_unlock(&kvm->srcu, idx);
unpin_user_page(summary_page);
- } else {
- map = page_address(summary_info->page);
- bit = get_ind_bit(summary_info->addr, adapter_int->summary_offset,
- adapter->swap);
- summary_set = test_and_set_bit(bit, map);
- spin_unlock_irqrestore(&adapter->maps_lock, flags);
}
+ scoped_guard(srcu, &kvm->srcu)
+ mark_page_dirty(kvm, gpa_to_gfn(adapter_int->summary_gaddr));
return summary_set ? 0 : 1;
}
@@ -3040,26 +3037,29 @@ static int adapter_indicators_set_fast(struct kvm *kvm,
struct kvm_s390_adapter_int *adapter_int,
int setbit)
{
+ struct s390_map_info *ind_info, *summary_info;
unsigned long bit;
int summary_set;
- struct s390_map_info *ind_info, *summary_info;
void *map;
- spin_lock(&adapter->maps_lock);
+ guard(srcu)(&kvm->srcu);
+ guard(spinlock)(&adapter->maps_lock);
+
ind_info = get_map_info(adapter, adapter_int->ind_addr);
- if (!ind_info) {
- spin_unlock(&adapter->maps_lock);
+ if (!ind_info)
return -EWOULDBLOCK;
- }
+
map = page_address(ind_info->page);
bit = get_ind_bit(ind_info->addr, adapter_int->ind_offset, adapter->swap);
- if (setbit)
+ if (setbit) {
set_bit(bit, map);
+ mark_page_dirty(kvm, gpa_to_gfn(adapter_int->ind_gaddr));
+ }
+
summary_info = get_map_info(adapter, adapter_int->summary_addr);
- if (!summary_info) {
- spin_unlock(&adapter->maps_lock);
+ if (!summary_info)
return -EWOULDBLOCK;
- }
+
map = page_address(summary_info->page);
bit = get_ind_bit(summary_info->addr, adapter_int->summary_offset,
adapter->swap);
@@ -3069,7 +3069,8 @@ static int adapter_indicators_set_fast(struct kvm *kvm,
summary_set = test_and_set_bit(bit, map);
else
summary_set = test_and_clear_bit(bit, map);
- spin_unlock(&adapter->maps_lock);
+ mark_page_dirty(kvm, gpa_to_gfn(adapter_int->summary_gaddr));
+
return summary_set ? 0 : 1;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 007/457] KVM: s390: Fix _gaccess_shadow_fault()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 006/457] KVM: s390: Fix dirty marking in adapter_indicators_set*() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 008/457] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
` (460 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit faff4c8ff3dbec6d71b89dd281a0d17c4478fa44 ]
In some circumstances, it is possible that the page of nested guest
memory that is being shadowed is not present at all in the parent guest
gmap. dat_entry_walk() will not find any leaf entry and return with
-ENOENT, which will erroneously be propagated all the way to userspace.
Fix by manually calling gmap_link() on the memory of the nested guest
that is being shadowed if the mapping was not already present.
Fixes: e38c884df921 ("KVM: s390: Switch to new gmap")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260828115439.145885-4-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/gaccess.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/arch/s390/kvm/gaccess.c b/arch/s390/kvm/gaccess.c
index 36102b2727fbf..7c1f614ec3146 100644
--- a/arch/s390/kvm/gaccess.c
+++ b/arch/s390/kvm/gaccess.c
@@ -1593,12 +1593,25 @@ static inline int ___gaccess_shadow_fault(struct kvm_vcpu *vcpu, struct gmap *sg
parent = READ_ONCE(sg->parent);
if (!parent)
return -EAGAIN;
+retry:
scoped_guard(spinlock, &parent->children_lock) {
if (READ_ONCE(sg->parent) != parent)
return -EAGAIN;
sg->invalidated = false;
rc = _gaccess_do_shadow(vcpu->arch.mc, sg, saddr, walk);
}
+ if (rc == -ENOENT) {
+ struct kvm_memory_slot *slot;
+ struct guest_fault *entries;
+
+ entries = get_entries(walk);
+ slot = kvm_vcpu_gfn_to_memslot(vcpu, entries[LEVEL_MEM].gfn);
+ if (!slot)
+ return PGM_ADDRESSING;
+ rc = gmap_link(vcpu->arch.mc, parent, entries + LEVEL_MEM, slot);
+ if (!rc)
+ goto retry;
+ }
if (!rc)
kvm_s390_release_faultin_array(vcpu->kvm, walk->raw_entries, false);
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 008/457] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 007/457] KVM: s390: Fix _gaccess_shadow_fault() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 009/457] KVM: s390: Add missing srcu in kvm_s390_set_irq_state() Greg Kroah-Hartman
` (459 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit d343407b728a80b74be3c24b59f15e60289ea527 ]
When __inject_sigp_stop() is called for a Stop and Store Status
operation, if the vCPU is running, the interrupt is marked as pending
and the status is stored by the thread performing the KVM_RUN IOCTL.
If the vCPU is already stopped, the status is stored immediately.
Storing the status means writing into userspace, which might fault, and
__inject_sigp_stop() is called from do_inject_vcpu() which in turn is
always called holding a spinlock, which is obviously an issue.
Fix this by returning -EWOULDBLOCK from __inject_sigp_stop(), and
adding a bool flag to indicate whether a store status is needed. The
callers of do_inject_vcpu() are modified to pass the pointer to the
bool flag; whenever a Store Status operation is needed, the callers can
now perform it outside the spinlock.
Opportunistically refactor kvm_s390_set_irq_state() to use
scoped_guard() and __free().
Fixes: 6cddd432e3da ("KVM: s390: handle stop irqs without action_bits")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Added Fixes tag while picking -- Claudio ]
Message-ID: <20260812104436.109741-7-imbrenda@linux.ibm.com>
Stable-dep-of: f3a557067d57 ("KVM: s390: Add missing srcu in kvm_s390_set_irq_state()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/interrupt.c | 70 +++++++++++++++++++++------------------
1 file changed, 38 insertions(+), 32 deletions(-)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index 70431eb38aa50..6397b53e33f52 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -1550,23 +1550,21 @@ static int __inject_set_prefix(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
}
#define KVM_S390_STOP_SUPP_FLAGS (KVM_S390_STOP_FLAG_STORE_STATUS)
-static int __inject_sigp_stop(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
+static int __inject_sigp_stop(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq, bool *storestatus)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
struct kvm_s390_stop_info *stop = &li->irq.stop;
- int rc = 0;
vcpu->stat.inject_stop_signal++;
trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_SIGP_STOP, 0, 0);
if (irq->u.stop.flags & ~KVM_S390_STOP_SUPP_FLAGS)
return -EINVAL;
-
if (is_vcpu_stopped(vcpu)) {
- if (irq->u.stop.flags & KVM_S390_STOP_FLAG_STORE_STATUS)
- rc = kvm_s390_store_status_unloaded(vcpu,
- KVM_S390_STORE_STATUS_NOADDR);
- return rc;
+ if (!(irq->u.stop.flags & KVM_S390_STOP_FLAG_STORE_STATUS))
+ return 0;
+ *storestatus = true;
+ return -EWOULDBLOCK;
}
if (test_and_set_bit(IRQ_PEND_SIGP_STOP, &li->pending_irqs))
@@ -2102,7 +2100,7 @@ void kvm_s390_clear_stop_irq(struct kvm_vcpu *vcpu)
spin_unlock(&li->lock);
}
-static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
+static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq, bool *storestatus)
{
int rc;
@@ -2114,7 +2112,7 @@ static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
rc = __inject_set_prefix(vcpu, irq);
break;
case KVM_S390_SIGP_STOP:
- rc = __inject_sigp_stop(vcpu, irq);
+ rc = __inject_sigp_stop(vcpu, irq, storestatus);
break;
case KVM_S390_RESTART:
rc = __inject_sigp_restart(vcpu);
@@ -2150,11 +2148,16 @@ static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
int kvm_s390_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
+ bool storestatus = false;
int rc;
spin_lock(&li->lock);
- rc = do_inject_vcpu(vcpu, irq);
+ rc = do_inject_vcpu(vcpu, irq, &storestatus);
spin_unlock(&li->lock);
+
+ if (rc == -EWOULDBLOCK && storestatus)
+ rc = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
+
if (!rc)
kvm_s390_vcpu_wakeup(vcpu);
return rc;
@@ -3190,7 +3193,8 @@ int kvm_set_msi(struct kvm_kernel_irq_routing_entry *e, struct kvm *kvm,
int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len)
{
struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
- struct kvm_s390_irq *buf;
+ struct kvm_s390_irq *buf __free(kvfree) = NULL;
+ bool tmp, storestatus = false;
int r = 0;
int n;
@@ -3198,31 +3202,33 @@ int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len
if (!buf)
return -ENOMEM;
- if (copy_from_user((void *) buf, irqstate, len)) {
- r = -EFAULT;
- goto out_free;
- }
+ if (copy_from_user((void *)buf, irqstate, len))
+ return -EFAULT;
- /*
- * Don't allow setting the interrupt state
- * when there are already interrupts pending
- */
- spin_lock(&li->lock);
- if (li->pending_irqs) {
- r = -EBUSY;
- goto out_unlock;
- }
+ scoped_guard(spinlock, &li->lock) {
+ /*
+ * Don't allow setting the interrupt state
+ * when there are already interrupts pending
+ */
+ if (li->pending_irqs)
+ return -EBUSY;
- for (n = 0; n < len / sizeof(*buf); n++) {
- r = do_inject_vcpu(vcpu, &buf[n]);
- if (r)
- break;
+ for (n = 0; n < len / sizeof(*buf); n++) {
+ tmp = false;
+ r = do_inject_vcpu(vcpu, &buf[n], &tmp);
+ if (r == -EWOULDBLOCK && tmp) {
+ storestatus = true;
+ r = 0;
+ }
+ if (r)
+ break;
+ }
}
-out_unlock:
- spin_unlock(&li->lock);
-out_free:
- vfree(buf);
+ if (storestatus) {
+ n = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
+ return r ? r : n;
+ }
return r;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 009/457] KVM: s390: Add missing srcu in kvm_s390_set_irq_state()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 008/457] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 010/457] KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key() Greg Kroah-Hartman
` (458 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit f3a557067d57ce6ae98d485c8009b223e16f5f36 ]
Like kvm_s390_inject_vcpu(), kvm_s390_set_irq_state() also needs the
kvm->srcu or the slots lock when performing the Store status operation.
Fix by taking kvm->srcu in kvm_s390_set_irq_state().
Fixes: ba5c1e9b6cee ("KVM: s390: interrupt subsystem, cpu timer, waitpsw")
Fixes: 062e44a9319f ("KVM: s390: Use srcu in kvm_arch_vcpu_unlocked_ioctl()")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260828115439.145885-7-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/interrupt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kvm/interrupt.c b/arch/s390/kvm/interrupt.c
index 6397b53e33f52..80f4802934df9 100644
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -3224,9 +3224,9 @@ int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len
break;
}
}
-
if (storestatus) {
- n = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
+ scoped_guard(srcu, &vcpu->kvm->srcu)
+ n = kvm_s390_store_status_unloaded(vcpu, KVM_S390_STORE_STATUS_NOADDR);
return r ? r : n;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 010/457] KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 009/457] KVM: s390: Add missing srcu in kvm_s390_set_irq_state() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 011/457] KVM: s390: Fix potential races in dat skey functions Greg Kroah-Hartman
` (457 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Christoph Schlameuss, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit 88e22ffd1e46b95e40a6afabe486deb1d31a3ae1 ]
Some callers pass NULL as oldkey. Calling page_cond_set_storage_key()
will cause that NULL pointer to get dereferenced.
Fix by checking for NULL and assigning the pointer to a dummy local
variable to avoid crashes.
Fixes: 8e03e8316eb2 ("KVM: s390: KVM page table management functions: storage keys")
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260812104436.109741-2-imbrenda@linux.ibm.com>
Stable-dep-of: 27554b9505dd ("KVM: s390: Fix potential races in dat skey functions")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/dat.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kvm/dat.c b/arch/s390/kvm/dat.c
index 3f2d6e8902d76..165c704fcf299 100644
--- a/arch/s390/kvm/dat.c
+++ b/arch/s390/kvm/dat.c
@@ -722,9 +722,12 @@ int dat_cond_set_storage_key(struct kvm_s390_mmu_cache *mmc, union asce asce, gf
if (rc)
return rc;
- if (!ptep)
+ if (!ptep) {
+ if (!oldkey)
+ oldkey = &prev;
return page_cond_set_storage_key(large_crste_to_phys(*crstep, gfn), skey, oldkey,
nq, mr, mc);
+ }
old = pgste_get_lock(ptep);
pgste = old;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 011/457] KVM: s390: Fix potential races in dat skey functions
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 010/457] KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 012/457] KVM: s390: Fix race in _destroy_pages_crste() Greg Kroah-Hartman
` (456 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit 27554b9505ddfc0aeab466aeb60929dfa17284c7 ]
When dat_cond_set_storage_key() finds a large page, it will
conditionally set the storage key in absolute memory using
large_crste_to_phys() to get the absolute address.
There is a race window between dat_entry_walk() and
large_crste_to_phys(): the large page could have been split
concurrently, and large_crste_to_phys() might be called with a crste
that does not designate a large page, leading to crashes.
Similar issues were also present in dat_set_storage_key().
dat_get_storage_key() and dat_reset_reference_bit() did instead check
for a potential concurrent splitting of the large page, but then
handled it incorrectly.
Fix by performing a READ_ONCE on the crste pointer, checking and using
the result, instead of dereferencing the pointer again. In case a race
is detacted, try dat_entry_walk() again.
Fixes: 8e03e8316eb2 ("KVM: s390: KVM page table management functions: storage keys")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260828115439.145885-8-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/dat.c | 36 ++++++++++++++++++++++++++++--------
1 file changed, 28 insertions(+), 8 deletions(-)
diff --git a/arch/s390/kvm/dat.c b/arch/s390/kvm/dat.c
index 165c704fcf299..a21cb3975e992 100644
--- a/arch/s390/kvm/dat.c
+++ b/arch/s390/kvm/dat.c
@@ -620,17 +620,20 @@ int dat_get_storage_key(union asce asce, gfn_t gfn, union skey *skey)
union pte *ptep;
int rc;
+again:
skey->skey = 0;
rc = dat_entry_walk(NULL, gfn, asce, DAT_WALK_ANY, TABLE_TYPE_PAGE_TABLE, &crstep, &ptep);
if (rc)
return rc;
if (!ptep) {
- union crste crste;
+ union crste crste = READ_ONCE(*crstep);
- crste = READ_ONCE(*crstep);
- if (!crste.h.fc || !crste.s.fc1.pr)
+ if (!crste_leaf(crste) && !crste.h.i)
+ goto again;
+ if (!crste.s.fc1.pr)
return 0;
+
skey->skey = page_get_storage_key(large_crste_to_phys(crste, gfn));
return 0;
}
@@ -661,13 +664,20 @@ int dat_set_storage_key(struct kvm_s390_mmu_cache *mc, union asce asce, gfn_t gf
union pte *ptep;
int rc;
+again:
rc = dat_entry_walk(mc, gfn, asce, DAT_WALK_LEAF_ALLOC, TABLE_TYPE_PAGE_TABLE,
&crstep, &ptep);
if (rc)
return rc;
if (!ptep) {
- page_set_storage_key(large_crste_to_phys(*crstep, gfn), skey.skey, !nq);
+ union crste crste = READ_ONCE(*crstep);
+
+ /* A large page has been split concurrently, try again */
+ if (!crste_leaf(crste))
+ goto again;
+
+ page_set_storage_key(large_crste_to_phys(crste, gfn), skey.skey, !nq);
return 0;
}
@@ -717,15 +727,22 @@ int dat_cond_set_storage_key(struct kvm_s390_mmu_cache *mmc, union asce asce, gf
union pte *ptep;
int rc;
+again:
rc = dat_entry_walk(mmc, gfn, asce, DAT_WALK_LEAF_ALLOC, TABLE_TYPE_PAGE_TABLE,
&crstep, &ptep);
if (rc)
return rc;
if (!ptep) {
+ union crste crste = READ_ONCE(*crstep);
+
+ /* A large page has been split concurrently, try again */
+ if (!crste_leaf(crste))
+ goto again;
if (!oldkey)
oldkey = &prev;
- return page_cond_set_storage_key(large_crste_to_phys(*crstep, gfn), skey, oldkey,
+
+ return page_cond_set_storage_key(large_crste_to_phys(crste, gfn), skey, oldkey,
nq, mr, mc);
}
@@ -766,7 +783,7 @@ int dat_reset_reference_bit(union asce asce, gfn_t gfn, union skey *skey)
int rc;
skey->skey = 0;
-
+again:
rc = dat_entry_walk(NULL, gfn, asce, DAT_WALK_ANY, TABLE_TYPE_PAGE_TABLE, &crstep, &ptep);
if (rc)
return rc;
@@ -774,9 +791,12 @@ int dat_reset_reference_bit(union asce asce, gfn_t gfn, union skey *skey)
if (!ptep) {
union crste crste = READ_ONCE(*crstep);
- if (!crste.h.fc || !crste.s.fc1.pr)
+ /* A large page has been split concurrently, try again */
+ if (!crste_leaf(crste) && !crste.h.i)
+ goto again;
+ if (!crste.s.fc1.pr)
return 0;
- skey->skey = page_reset_referenced(large_crste_to_phys(*crstep, gfn)) << 1;
+ skey->skey = page_reset_referenced(large_crste_to_phys(crste, gfn)) << 1;
return 0;
}
old = pgste_get_lock(ptep);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 012/457] KVM: s390: Fix race in _destroy_pages_crste()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 011/457] KVM: s390: Fix potential races in dat skey functions Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 013/457] s390/uv: Fix loop condition in uv_find_secrets Greg Kroah-Hartman
` (455 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
[ Upstream commit 4ca00a9154f998116fba9a32cce5bd938d228065 ]
Use READ_ONCE() in _destroy_pages_crste() to read the crste, avoid
dereferencing the pointer multiple times.
Fixes: a2c17f9270cc ("KVM: s390: New gmap code")
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260828115439.145885-9-imbrenda@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kvm/gmap.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kvm/gmap.c b/arch/s390/kvm/gmap.c
index 8abb4f55b306b..f11d4ecaef7be 100644
--- a/arch/s390/kvm/gmap.c
+++ b/arch/s390/kvm/gmap.c
@@ -991,11 +991,13 @@ static long _destroy_pages_pte(union pte *ptep, gfn_t gfn, gfn_t next, struct da
static long _destroy_pages_crste(union crste *crstep, gfn_t gfn, gfn_t next, struct dat_walk *walk)
{
phys_addr_t origin, cur, end;
+ union crste crste;
- if (!crstep->h.fc || !crstep->s.fc1.pr)
+ crste = READ_ONCE(*crstep);
+ if (!crste.h.fc || !crste.s.fc1.pr)
return 0;
- origin = crste_origin_large(*crstep);
+ origin = crste_origin_large(crste);
cur = ((max(gfn, walk->start) - gfn) << PAGE_SHIFT) + origin;
end = ((min(next, walk->end) - gfn) << PAGE_SHIFT) + origin;
for ( ; cur < end; cur += PAGE_SIZE)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 013/457] s390/uv: Fix loop condition in uv_find_secrets
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 012/457] KVM: s390: Fix race in _destroy_pages_crste() Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 014/457] s390/uv: Prevent potential out-of-bounds read Greg Kroah-Hartman
` (454 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Claudio Imbrenda,
Christoph Schlameuss, Steffen Eiden, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steffen Eiden <seiden@linux.ibm.com>
[ Upstream commit d12ce6bce5ec5175c3581e01c71e7a5abb286d9b ]
Systems with more than 85 UV secrets got -ENOENT for any secret past the
first page.
Fix this by setting the start index at the beginning of the loop in
uv_find_secret() and not at the end. First test if there are more
secrets left by comparing start_idx with list->next_secret_idx, and then
set the start index to the next secret index.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260812-uv_secrets_fix-v3-1-a85bd29e0666@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kernel/uv.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index a284f98d97168..d970b15ef126d 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -781,11 +781,14 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
struct uv_secret_list *list,
struct uv_secret_list_item_hdr *secret)
{
- u16 start_idx = 0;
+ u16 start_idx;
u16 list_rc;
int ret;
+ list->next_secret_idx = 0;
+
do {
+ start_idx = list->next_secret_idx;
uv_list_secrets(list, start_idx, &list_rc, NULL);
if (list_rc != UVC_RC_EXECUTED && list_rc != UVC_RC_MORE_DATA) {
if (list_rc == UVC_RC_INV_CMD)
@@ -796,7 +799,6 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
ret = find_secret_in_page(secret_id, list, secret);
if (ret == 0)
return ret;
- start_idx = list->next_secret_idx;
} while (list_rc == UVC_RC_MORE_DATA && start_idx < list->next_secret_idx);
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 014/457] s390/uv: Prevent potential out-of-bounds read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 013/457] s390/uv: Fix loop condition in uv_find_secrets Greg Kroah-Hartman
@ 2026-09-30 15:21 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 015/457] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
` (453 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:21 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Steffen Eiden, Christoph Schlameuss,
Claudio Imbrenda, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steffen Eiden <seiden@linux.ibm.com>
[ Upstream commit f47190b08b71e8482072978373ee88cb2dfbdaf4 ]
When the system has more than 85 secrets, the uv_secret_list struct
array only holds up to 85 items per page, resulting in an out of bounds
read in find_secret_in_page if the targeted secret is in the next page
or not stored at all.
Fix this by looping over the number of stored secrets which is the
per sub-list count of stored secrets and not the overall count.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260812-uv_secrets_fix-v3-2-a85bd29e0666@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kernel/uv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index d970b15ef126d..e70acad09cd5f 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -760,7 +760,7 @@ static int find_secret_in_page(const u8 secret_id[UV_SECRET_ID_LEN],
{
u16 i;
- for (i = 0; i < list->total_num_secrets; i++) {
+ for (i = 0; i < list->num_secr_stored; i++) {
if (memcmp(secret_id, list->secrets[i].id, UV_SECRET_ID_LEN) == 0) {
*secret = list->secrets[i].hdr;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 015/457] bpf: Fix bpf_skb_change_tail wrt csum partial skbs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-30 15:21 ` [PATCH 7.2 014/457] s390/uv: Prevent potential out-of-bounds read Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 016/457] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
` (452 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tom Hadlaw, Yusuke Suzuki,
Daniel Borkmann, Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 3b55f350c68a0aceff108f47f9d31f47ebffaf7b ]
Cilium generates ICMP "frag needed" replies from BPF when a LB DSR
packet exceeds the egress MTU. The reply is built by first trimming the
packet down to target size via bpf_skb_change_tail(), and then pushing
the ICMP error headers in front of it.
The trim is rejected for skbs which carry a checksum offload, e.g. TCP
packets aggregated by GRO on ingress where tcp_gro_complete() leaves
the skb as CHECKSUM_PARTIAL. __bpf_skb_min_len() raises the minimum
length to the end of the L4 checksum field, so a trim to 42 bytes bails
out with -EINVAL given a min_len of 52 in this case, and due to that
the ICMP generator fails. This is not the case if GRO is turned off.
Fix this bpf_skb_change_tail() restriction and drop the checksum offload
when the new length no longer covers the checksum field. The BPF program
rewrites the skb into an ICMP error and computes the checksum itself
anyway.
Fixes: 5293efe62df8 ("bpf: add bpf_skb_change_tail helper")
Reported-by: Tom Hadlaw <tom.hadlaw@isovalent.com>
Reported-by: Yusuke Suzuki <yusuke.suzuki@isovalent.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260907121025.1923656-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 1e80a52ef86d0..73c6fa3d73467 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -3871,12 +3871,6 @@ static u32 __bpf_skb_min_len(const struct sk_buff *skb)
if (offset > 0)
min_len = offset;
}
- if (skb->ip_summed == CHECKSUM_PARTIAL) {
- offset = skb_checksum_start_offset(skb) +
- skb->csum_offset + sizeof(__sum16);
- if (offset > 0)
- min_len = offset;
- }
return min_len;
}
@@ -3893,6 +3887,11 @@ static int bpf_skb_grow_rcsum(struct sk_buff *skb, unsigned int new_len)
static int bpf_skb_trim_rcsum(struct sk_buff *skb, unsigned int new_len)
{
+ if (skb->ip_summed == CHECKSUM_PARTIAL &&
+ new_len < skb_checksum_start_offset(skb) + skb->csum_offset +
+ sizeof(__sum16))
+ skb->ip_summed = CHECKSUM_NONE;
+
return __skb_trim_rcsum(skb, new_len);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 016/457] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 015/457] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 017/457] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
` (451 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+adfca3e91be95776,
Alexei Starovoitov, Weiming Shi, Daniel Borkmann, Emil Tsalapatis,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit e4a62833adff6ef0fe7c0b90393204fe3c26b5c5 ]
An LWT_SEG6LOCAL program can invalidate its cached SRH with
bpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter
may reallocate skb->head, leaving the per-CPU SRH pointer dangling.
Post-program SRH validation then writes through that pointer.
Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier
rejects this unsafe helper combination. Other LWT program types continue
to expose the helper through lwt_out_func_proto().
Fixes: 004d4b274e2a ("ipv6: sr: Add seg6local action End.BPF")
Reported-by: co+adfca3e91be95776@bugs.sh
Suggested-by: Alexei Starovoitov <alexei.starovoitov@gmail.com>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Closes: https://lore.kernel.org/all/GCy0KRM2IcQGoJQTjJEU9D0maBxXzEDHuQpq@bugs.sh/
Link: https://lore.kernel.org/bpf/DL9COXZQXX4V.1FN45QO2Q77ZH@gmail.com/
Link: https://lore.kernel.org/bpf/20260909040807.3885815-2-bestswngs@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/core/filter.c b/net/core/filter.c
index 73c6fa3d73467..d0465db6f1c42 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -8881,6 +8881,8 @@ static const struct bpf_func_proto *
lwt_seg6local_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
{
switch (func_id) {
+ case BPF_FUNC_skb_pull_data:
+ return NULL;
#if IS_ENABLED(CONFIG_IPV6_SEG6_BPF)
case BPF_FUNC_lwt_seg6_store_bytes:
return &bpf_lwt_seg6_store_bytes_proto;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 017/457] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 016/457] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 018/457] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
` (450 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sven Schnelle, Steven Rostedt,
Masami Hiramatsu (Google), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Schnelle <svens@linux.ibm.com>
[ Upstream commit d22c3e0088e85be8131f7a9283f759cdbb20726d ]
The current regex also matches symbols in modules, which makes the
test fail on s390 where name_show is present only once in the kernel,
but also multiple times in modules:
000001b1401cdc20 t name_show
000001b0c05e6c40 t name_show [mdev]
000001b0c0495f30 t name_show [i2c_core]
Fix this by changing the regular expression to only match the function
name.
Link: https://lore.kernel.org/all/20260909092954.2200558-1-svens@linux.ibm.com/
Fixes: 03b80ff8023a ("selftests/ftrace: Add new test case which checks non unique symbol")
Signed-off-by: Sven Schnelle <svens@linux.ibm.com>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc b/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
index bc9514428dbaf..07b1177c16344 100644
--- a/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
+++ b/tools/testing/selftests/ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc
@@ -6,7 +6,7 @@
SYMBOL='name_show'
# We skip this test on kernel where SYMBOL is unique or does not exist.
-if [ "$(grep -c -E "[[:alnum:]]+ t ${SYMBOL}" /proc/kallsyms)" -le '1' ]; then
+if [ "$(grep -c -E "[[:alnum:]]+ t ${SYMBOL}$" /proc/kallsyms)" -le '1' ]; then
exit_unsupported
fi
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 018/457] bpf: Fix divide-by-zero in btf_struct_walk()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 017/457] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 019/457] bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() Greg Kroah-Hartman
` (449 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Eduard Zingerman,
Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit b0b3dc66529676228cb938cbcad66920f735c223 ]
When an access goes past the struct and the last member is a flexible
array, btf_struct_walk() folds the offset back into a single element with
(off - moff) % t->size, but never checks that the element type has a size.
BTF takes an empty struct, so this in program BTF
/* event could be empty */
struct event {
#ifdef HAVE_TIMESTAMP
__u64 ts;
#endif
};
struct batch {
int nr;
struct event events[];
};
divides by zero at prog load time. Getting there needs a PTR_TO_BTF_ID that
is not MEM_ALLOC, e.g. a plain read of a local kptr stashed in a map from a
sleepable program.
Oops: divide error: 0000 [#1] SMP KASAN PTI
RIP: 0010:btf_struct_walk+0x53f/0x1570
Call Trace:
<TASK>
btf_struct_access+0x42a/0xcd0
check_ptr_to_btf_access+0x4dc/0x1160
check_mem_access+0x3a45/0x8740
check_load_mem+0x36a/0xd10
do_check_common+0x3ef0/0xb210
bpf_check+0x6d3b/0x8580
bpf_prog_load+0xf7c/0x2720
__sys_bpf+0xa83/0x3690
__x64_sys_bpf+0xc7/0x150
x64_sys_call+0x1f3f/0x27e0
do_syscall_64+0xe5/0x610
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Reject a zero-sized element type. The fixed array path in the same function
already bails out on the same thing:
btf_struct_walk()
...
/* skip empty array */
if (moff == mtrue_end)
continue;
msize /= total_nelems;
Fixes: 9c5f8a1008a1 ("bpf: Support variable length array in tracing programs")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260910122316.186384-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 022d5a594dc95..ea3d50c99ec22 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -7191,7 +7191,7 @@ static int btf_struct_walk(struct bpf_verifier_log *log, const struct btf *btf,
if (btf_type_is_int(t))
return WALK_SCALAR;
- if (!btf_type_is_struct(t))
+ if (!btf_type_is_struct(t) || !t->size)
goto error;
off = (off - moff) % t->size;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 019/457] bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 018/457] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 020/457] tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context Greg Kroah-Hartman
` (448 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei (Microsoft), Jiayuan Chen,
Kuniyuki Iwashima, Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 01b245ba016d44861690594e10f67e026ce8552f ]
sk_protocol lives in struct sock, not in struct sock_common. A timewait
or request sock handed to bpf_sock_destroy() by the tcp iterator is
neither, so reading sk->sk_protocol runs past the object:
==================================================================
BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0
Read of size 2 at addr ffff8881047d11b4 by task test_progs/428
Tainted: [W]=WARN
Call Trace:
<TASK>
dump_stack_lvl+0x91/0xf0
print_report+0xd1/0x630
kasan_report+0xf3/0x130
__asan_report_load2_noabort+0x14/0x30
bpf_sock_destroy+0xc7/0xe0
bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7
bpf_iter_run_prog+0x538/0xde0
bpf_iter_tcp_seq_show+0x26b/0x4b0
bpf_seq_read+0x424/0x1210
vfs_read+0x197/0xe40
ksys_read+0x119/0x240
__x64_sys_read+0x72/0xc0
x64_sys_call+0x647/0x27e0
do_syscall_64+0xe5/0x610
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Only check sk_protocol on full socks. tcp_abort() already knows how to
deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it
never matched the code.
Fixes: 4ddbcb886268 ("bpf: Add bpf_sock_destroy kfunc")
Reported-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Closes: https://lore.kernel.org/bpf/20260702224519.800135-1-xmei5@asu.edu/
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://lore.kernel.org/r/20260910112634.152195-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index d0465db6f1c42..5769fd10227f3 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -12659,8 +12659,9 @@ __bpf_kfunc_start_defs();
* @sock: Pointer to socket to be destroyed
*
* Return:
- * On error, may return EPROTONOSUPPORT, EINVAL.
- * EPROTONOSUPPORT if protocol specific destroy handler is not supported.
+ * On error, may return EOPNOTSUPP, or whatever the protocol specific
+ * destroy handler returns.
+ * EOPNOTSUPP if protocol specific destroy handler is not supported.
* 0 otherwise
*/
__bpf_kfunc int bpf_sock_destroy(struct sock_common *sock)
@@ -12672,8 +12673,12 @@ __bpf_kfunc int bpf_sock_destroy(struct sock_common *sock)
* Supporting protocols will need to acquire sock lock in the BPF context
* prior to invoking this kfunc.
*/
- if (!sk->sk_prot->diag_destroy || (sk->sk_protocol != IPPROTO_TCP &&
- sk->sk_protocol != IPPROTO_UDP))
+ if (!sk->sk_prot->diag_destroy)
+ return -EOPNOTSUPP;
+
+ if (sk_fullsock(sk) &&
+ sk->sk_protocol != IPPROTO_TCP &&
+ sk->sk_protocol != IPPROTO_UDP)
return -EOPNOTSUPP;
return sk->sk_prot->diag_destroy(sk, ECONNABORTED);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 020/457] tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 019/457] bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 021/457] HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio Greg Kroah-Hartman
` (447 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit eaab8cab451b9502ce224cd202550375b894a467 ]
bpf_sock_destroy() runs from the tcp iterator, under rcu_read_lock(). If
the sock is a listener that still has children in its accept queue,
tcp_abort() ends up in inet_csk_listen_stop() and the cond_resched()
there trips the debug check:
BUG: sleeping function called from invalid context at net/ipv4/inet_connection_sock.c:1523
in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 628, name: test_progs
preempt_count: 0, expected: 0
RCU nest depth: 1, expected: 0
locks held by test_progs/628: 3, last CPU#3:
#0: ffff8881158cee18 (&p->lock){+.+.}-{4:4}, at: bpf_seq_read+0x56/0x1210
#1: ffff8881106bb858 (sk_lock-AF_INET6){+.+.}-{0:0}, at: bpf_iter_tcp_seq_show+0x32b/0x4b0
#2: ffffffffb435af20 (rcu_read_lock){....}-{1:3}, at: bpf_iter_run_prog+0x46b/0xde0
CPU: 3 UID: 0 PID: 628 Comm: test_progs Tainted: G W 7.2.0+ #65 PREEMPT
Tainted: [W]=WARN
Call Trace:
<TASK>
dump_stack_lvl+0xc1/0xf0
dump_stack+0x10/0x20
__might_resched+0x3d2/0x610
inet_csk_listen_stop+0x7b/0xbf0
tcp_abort+0x23b/0x3b0
bpf_sock_destroy+0xfc/0x140
bpf_prog_448133d24601754f_iter_tcp6_server+0x81/0x8a
bpf_iter_run_prog+0x538/0xde0
bpf_iter_tcp_seq_show+0x26b/0x4b0
bpf_seq_read+0x424/0x1210
vfs_read+0x197/0xe40
ksys_read+0x119/0x240
__x64_sys_read+0x72/0xc0
x64_sys_call+0x647/0x27e0
do_syscall_64+0xe5/0x610
entry_SYSCALL_64_after_hwframe+0x76/0x7e
RIP: 0033:0x7fad39b28aca
RSP: 002b:00007ffc381c61c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000000
RAX: ffffffffffffffda RBX: 00007ffc381c6a88 RCX: 00007fad39b28aca
RDX: 0000000000000032 RSI: 00007ffc381c6250 RDI: 0000000000000014
RBP: 00007ffc381c61e0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000003
R13: 0000000000000000 R14: 000055f077c1bbb0 R15: 00007fad3a0f3000
</TASK>
The commit that added the kfunc already guards lock_sock() in tcp_abort()
and udp_abort() with has_current_bpf_ctx(), but missed the listener path.
Do the same for the cond_resched(). The loop runs inside the iterator's
rcu_read_lock(), it must not reschedule or report a quiescent state there.
Fixes: 4ddbcb886268 ("bpf: Add bpf_sock_destroy kfunc")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/20260910112736.153710-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/inet_connection_sock.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/inet_connection_sock.c b/net/ipv4/inet_connection_sock.c
index 6257459bcee24..6a30f11384547 100644
--- a/net/ipv4/inet_connection_sock.c
+++ b/net/ipv4/inet_connection_sock.c
@@ -1520,7 +1520,8 @@ void inet_csk_listen_stop(struct sock *sk)
local_bh_enable();
sock_put(child);
- cond_resched();
+ if (!has_current_bpf_ctx())
+ cond_resched();
}
if (queue->fastopenq.rskq_rst_head) {
/* Free all the reqs queued in rskq_rst_head. */
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 021/457] HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 020/457] tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 022/457] HID: winwing: fix use-after-free in force feedback teardown Greg Kroah-Hartman
` (446 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lovekesh Solanki, mayhemandcoffee,
Jiri Kosina, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lovekesh Solanki <lovekeshsolanki00@gmail.com>
[ Upstream commit aaaea79efba5a27cb9e0a5a628046d829d3f2cbb ]
Commit e716edafedad ("HID: multitouch: Check to ensure report
responses match the request") introduced validating GET_FEATURE
responses return the requested report ID.
ASUS ROG Z13 Flow (2025) GZ302EA touchpad (USB 0b05:1a30) returns
a different report ID for Win8 feature request. Before this check,
the response was still processed and allowed device to switch into
its full Touchpad Precision mode.
After the validation, the response is discarded before
hid_report_raw_event() processes it and device remains in fallback
mode and no longer exposes ABS_MT_SLOT, ABS_MT_TOOL_TYPE or the
multi-finger BTN_TOOL_* capabilities for palm rejection.
Add a device quirk to allow the known firmware behavior for
this device while preserving report ID validation for all other
devices.
The device previously matched the generic MT_CLS_WIN_8 entry, so
base the new class on MT_CLS_WIN_8 to keep it on the same quirk set
as before the regression. MT_QUIRK_CONFIDENCE must be set
explicitly: it is normally enabled by the class name check in
mt_touch_input_mapping(), which only matches the MT_CLS_WIN_8*
names, and it is what makes ABS_MT_TOOL_TYPE available for
touchpads.
Fixes: e716edafedad ("HID: multitouch: Check to ensure report responses match the request")
Signed-off-by: Lovekesh Solanki <lovekeshsolanki00@gmail.com>
Reported-by: mayhemandcoffee <mayhemandcoffee@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221774
Tested-by: mayhemandcoffee <mayhemandcoffee@gmail.com>
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221774
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-multitouch.c | 29 +++++++++++++++++++++++++++--
1 file changed, 27 insertions(+), 2 deletions(-)
diff --git a/drivers/hid/hid-multitouch.c b/drivers/hid/hid-multitouch.c
index 571166a769b90..e9da59e4bf795 100644
--- a/drivers/hid/hid-multitouch.c
+++ b/drivers/hid/hid-multitouch.c
@@ -79,6 +79,7 @@ MODULE_LICENSE("GPL");
#define MT_QUIRK_APPLE_TOUCHBAR BIT(23)
#define MT_QUIRK_YOGABOOK9I BIT(24)
#define MT_QUIRK_KEEP_LATENCY_ON_CLOSE BIT(25)
+#define MT_QUIRK_IGNORE_FEATURE_ID_MISMATCH BIT(26)
#define MT_INPUTMODE_TOUCHSCREEN 0x02
#define MT_INPUTMODE_TOUCHPAD 0x03
@@ -235,6 +236,7 @@ static void mt_post_parse(struct mt_device *td, struct mt_application *app);
#define MT_CLS_APPLE_TOUCHBAR 0x0114
#define MT_CLS_YOGABOOK9I 0x0115
#define MT_CLS_EGALAX_P80H84 0x0116
+#define MT_CLS_ASUS_ROG_Z13_FOLIO 0x0117
#define MT_CLS_SIS 0x0457
#define MT_DEFAULT_MAXCONTACT 10
@@ -405,6 +407,16 @@ static const struct mt_class mt_classes[] = {
.quirks = MT_QUIRK_ALWAYS_VALID |
MT_QUIRK_CONTACT_CNT_ACCURATE |
MT_QUIRK_ASUS_CUSTOM_UP },
+ { .name = MT_CLS_ASUS_ROG_Z13_FOLIO,
+ .quirks = MT_QUIRK_ALWAYS_VALID |
+ MT_QUIRK_IGNORE_DUPLICATES |
+ MT_QUIRK_HOVERING |
+ MT_QUIRK_CONTACT_CNT_ACCURATE |
+ MT_QUIRK_STICKY_FINGERS |
+ MT_QUIRK_WIN8_PTP_BUTTONS |
+ MT_QUIRK_CONFIDENCE |
+ MT_QUIRK_IGNORE_FEATURE_ID_MISMATCH,
+ .export_all_inputs = true },
{ .name = MT_CLS_VTL,
.quirks = MT_QUIRK_ALWAYS_VALID |
MT_QUIRK_CONTACT_CNT_ACCURATE |
@@ -507,6 +519,7 @@ static const struct attribute_group mt_attribute_group = {
static void mt_get_feature(struct hid_device *hdev, struct hid_report *report)
{
+ struct mt_device *td = hid_get_drvdata(hdev);
int ret;
u32 size = hid_report_len(report);
u8 *buf;
@@ -528,8 +541,14 @@ static void mt_get_feature(struct hid_device *hdev, struct hid_report *report)
dev_warn(&hdev->dev, "failed to fetch feature %d\n",
report->id);
} else {
- /* The report ID in the request and the response should match */
- if (report->id != buf[0]) {
+ /*
+ * The report ID in the request and the response should match.
+ * Some firmware (e.g. the ASUS ROG Z13 Folio
+ * touchpad) returns a mismatched ID on this specific fetch;
+ * tolerate it only for devices explicitly flagged as such.
+ */
+ if (report->id != buf[0] &&
+ !(td->mtclass.quirks & MT_QUIRK_IGNORE_FEATURE_ID_MISMATCH)) {
hid_err(hdev, "Returned feature report did not match the request\n");
goto free;
}
@@ -2726,6 +2745,12 @@ static const struct hid_device_id mt_devices[] = {
HID_DEVICE(BUS_I2C, HID_GROUP_MULTITOUCH_WIN_8,
I2C_VENDOR_ID_HANTICK, I2C_PRODUCT_ID_HANTICK_5288) },
+ /* Asus ROG Flow Z13 (2025) GZ302EA keyboard-cover touchpad */
+ { .driver_data = MT_CLS_ASUS_ROG_Z13_FOLIO,
+ HID_DEVICE(BUS_USB, HID_GROUP_MULTITOUCH_WIN_8,
+ USB_VENDOR_ID_ASUSTEK,
+ USB_DEVICE_ID_ASUSTEK_ROG_Z13_FOLIO) },
+
/* Generic MT device */
{ HID_DEVICE(HID_BUS_ANY, HID_GROUP_MULTITOUCH, HID_ANY_ID, HID_ANY_ID) },
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 022/457] HID: winwing: fix use-after-free in force feedback teardown
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 021/457] HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 023/457] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
` (445 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, René Onier, Jiri Kosina,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: René Onier <f3nr1l@me.com>
[ Upstream commit a1a5ad37e50ceb192c07ac7e2d7143638cd4d110 ]
winwing_init_ff() passes the driver's private data, allocated with
devm_kzalloc() in winwing_probe(), as the effect context to
input_ff_create_memless(). The memoryless force-feedback core takes
ownership of that pointer and frees it with kfree() from
input_ff_destroy() (ml_ff_destroy()) when the input device is
destroyed.
Freeing a devm-managed allocation with kfree() is an invalid free, and
the same object is then released again by devres when the HID device is
torn down, a double free. As the allocation also embeds the LED class
devices, their timers and work item live on freed memory and the slab
gets corrupted. This triggers on unbind, rmmod, hot-unplug and on system
suspend, where the firmware cache walks the now-corrupt devres list.
KASAN reports:
BUG: KASAN: invalid-free in input_ff_destroy
Allocated by task N:
winwing_probe
Pass NULL as the memless context instead and fetch the driver data from
the input device in winwing_play_effect(): the HID core already stores
the hid_device as the input device's drvdata. The force-feedback core
then owns nothing that it must not free.
Fixes: 42d020b54edc ("HID: winwing: Enable rumble effects")
Signed-off-by: René Onier <f3nr1l@me.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-winwing.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/hid/hid-winwing.c b/drivers/hid/hid-winwing.c
index 9cd25a77999e6..19b92c2c6579a 100644
--- a/drivers/hid/hid-winwing.c
+++ b/drivers/hid/hid-winwing.c
@@ -315,7 +315,8 @@ static void winwing_haptic_rumble_cb(struct work_struct *work)
static int winwing_play_effect(struct input_dev *dev, void *context,
struct ff_effect *effect)
{
- struct winwing_drv_data *data = (struct winwing_drv_data *) context;
+ struct hid_device *hdev = input_get_drvdata(dev);
+ struct winwing_drv_data *data = hid_get_drvdata(hdev);
if (effect->type != FF_RUMBLE)
return 0;
@@ -342,7 +343,12 @@ static int winwing_init_ff(struct hid_device *hdev, struct hid_input *hidinput)
input_set_capability(hidinput->input, EV_FF, FF_RUMBLE);
- return input_ff_create_memless(hidinput->input, data,
+ /*
+ * input_ff_create_memless() takes ownership of the context pointer
+ * and frees it on teardown; do not hand it the devm-managed drvdata.
+ * winwing_play_effect() fetches it from the input device instead.
+ */
+ return input_ff_create_memless(hidinput->input, NULL,
winwing_play_effect);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 023/457] HID: elecom: fix bus type for M-XGL20DLBK
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 022/457] HID: winwing: fix use-after-free in force feedback teardown Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 024/457] KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr() Greg Kroah-Hartman
` (444 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Oscar Priego Verdugo, Jiri Kosina,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oscar Priego Verdugo <oscar.priegov@gmail.com>
[ Upstream commit 8e2a4b458ad25e13422bb059758c30a6562aa9cf ]
The M-XGL20DLBK is matched as a USB device by hid-elecom, but
its entry in hid_have_special_driver[] uses HID_BLUETOOTH_DEVICE.
This prevents the special-driver quirk entry from matching the USB
device handled by hid-elecom. Use HID_USB_DEVICE there as well.
Fixes: 55633e681afb ("HID: elecom: add support for EX-G M-XGL20DLBK wireless mouse")
Signed-off-by: Oscar Priego Verdugo <oscar.priegov@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-quirks.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hid/hid-quirks.c b/drivers/hid/hid-quirks.c
index 57d8efdd9b890..0ad8ca20cb9d1 100644
--- a/drivers/hid/hid-quirks.c
+++ b/drivers/hid/hid-quirks.c
@@ -422,7 +422,7 @@ static const struct hid_device_id hid_have_special_driver[] = {
#endif
#if IS_ENABLED(CONFIG_HID_ELECOM)
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_BM084) },
- { HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XGL20DLBK) },
+ { HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XGL20DLBK) },
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_HT1MRBK_01AC) },
{ HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XT3URBK_00FB) },
{ HID_USB_DEVICE(USB_VENDOR_ID_ELECOM, USB_DEVICE_ID_ELECOM_M_XT3URBK_018F) },
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 024/457] KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 023/457] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 025/457] bpf: Allow terminal gotox instructions Greg Kroah-Hartman
` (443 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jim Mattson, Like Xu, Sandipan Das,
Sean Christopherson, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jim Mattson <jmattson@google.com>
[ Upstream commit 79a71cc2568f4b5d42284da2aa26f3b4f47ce01b ]
Commit c85cdc1cc1ea ("KVM: x86/pmu: Move handling PERF_GLOBAL_CTRL and
friends to common x86") moved the existence check for the following Intel
PMU MSRs to kvm_pmu_is_valid_msr():
- MSR_CORE_PERF_GLOBAL_STATUS
- MSR_CORE_PERF_GLOBAL_CTRL
- MSR_CORE_PERF_GLOBAL_OVF_CTRL
That commit deemed these MSRs valid whenever pmu->version > 1. It intended
to share the check with AMD PerfMonV2 because both vendor implementations
require version 2 or greater for global PMU controls. However, as noted in
the commit message, AMD uses different MSR indices for its global PMU
registers.
Commit 4a2771895ca6 ("KVM: x86/svm/pmu: Add AMD PerfMonV2 support")
subsequently added AMD PerfMonV2 support and set pmu->version = 2. Because
kvm_pmu_is_valid_msr() validated the Intel MSRs whenever pmu->version > 1,
KVM incorrectly permitted AMD guests with PerfMonV2 to access these Intel
MSRs without a #GP.
Move the validation of these Intel MSRs to intel_is_valid_msr() and remove
the common switch statement from kvm_pmu_is_valid_msr(). AMD already
validates its own global PMU MSRs in amd_is_valid_msr().
Fixes: 4a2771895ca6 ("KVM: x86/svm/pmu: Add AMD PerfMonV2 support")
Signed-off-by: Jim Mattson <jmattson@google.com>
Reviewed-by: Like Xu <likexu@tencent.com>
Reviewed-by: Sandipan Das <sandipan.das@amd.com>
Link: https://patch.msgid.link/20260902184711.138538-1-jmattson@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/kvm/pmu.c | 8 --------
arch/x86/kvm/vmx/pmu_intel.c | 3 +++
2 files changed, 3 insertions(+), 8 deletions(-)
diff --git a/arch/x86/kvm/pmu.c b/arch/x86/kvm/pmu.c
index dd1c57593f48b..7fedf25cf46fe 100644
--- a/arch/x86/kvm/pmu.c
+++ b/arch/x86/kvm/pmu.c
@@ -812,14 +812,6 @@ void kvm_pmu_deliver_pmi(struct kvm_vcpu *vcpu)
bool kvm_pmu_is_valid_msr(struct kvm_vcpu *vcpu, u32 msr)
{
- switch (msr) {
- case MSR_CORE_PERF_GLOBAL_STATUS:
- case MSR_CORE_PERF_GLOBAL_CTRL:
- case MSR_CORE_PERF_GLOBAL_OVF_CTRL:
- return kvm_pmu_has_perf_global_ctrl(vcpu_to_pmu(vcpu));
- default:
- break;
- }
return kvm_pmu_call(msr_idx_to_pmc)(vcpu, msr) ||
kvm_pmu_call(is_valid_msr)(vcpu, msr);
}
diff --git a/arch/x86/kvm/vmx/pmu_intel.c b/arch/x86/kvm/vmx/pmu_intel.c
index 1944939c4139f..e65ba7e856117 100644
--- a/arch/x86/kvm/vmx/pmu_intel.c
+++ b/arch/x86/kvm/vmx/pmu_intel.c
@@ -187,6 +187,9 @@ static bool intel_is_valid_msr(struct kvm_vcpu *vcpu, u32 msr)
int ret;
switch (msr) {
+ case MSR_CORE_PERF_GLOBAL_STATUS:
+ case MSR_CORE_PERF_GLOBAL_CTRL:
+ case MSR_CORE_PERF_GLOBAL_OVF_CTRL:
case MSR_CORE_PERF_FIXED_CTR_CTRL:
return kvm_pmu_has_perf_global_ctrl(pmu);
case MSR_IA32_PEBS_ENABLE:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 025/457] bpf: Allow terminal gotox instructions
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 024/457] KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 026/457] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
` (442 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Siddharth Chintamaneni,
Anton Protopopov, Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Siddharth Chintamaneni <sidchintamaneni@gmail.com>
[ Upstream commit 0d7823cd4cda35f2060a685fa276ff7709915abc ]
check_subprogs() treats gotox as a direct jump and validates its reserved
zero offset. When gotox is the final instruction, this produces a
synthetic successor one instruction past the end of the subprogram and
rejects an otherwise valid program.
Skip direct-offset validation for gotox and accept it as a
non-fallthrough terminal instruction. Its actual targets remain validated
from the instruction-array jump table during CFG construction.
Fixes: 493d9e0d6083 ("bpf, x86: add support for indirect jumps")
Signed-off-by: Siddharth Chintamaneni <sidchintamaneni@gmail.com>
Reviewed-by: Anton Protopopov <a.s.protopopov@gmail.com>
Link: https://lore.kernel.org/r/20260902171414.96165-1-sidchintamaneni@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 1a0cd37b03cde..dc1a9ef32b78e 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -2876,6 +2876,8 @@ static int check_subprogs(struct bpf_verifier_env *env)
subprog[cur_subprog].exit_idx = i;
goto next;
}
+ if (insn_is_gotox(&insn[i]))
+ goto next;
off = i + bpf_jmp_offset(&insn[i]) + 1;
if (off < subprog_start || off >= subprog_end) {
verbose(env, "jump out of range from insn %d to %d\n", i, off);
@@ -2889,7 +2891,8 @@ static int check_subprogs(struct bpf_verifier_env *env)
*/
if (code != (BPF_JMP | BPF_EXIT) &&
code != (BPF_JMP32 | BPF_JA) &&
- code != (BPF_JMP | BPF_JA)) {
+ code != (BPF_JMP | BPF_JA) &&
+ !insn_is_gotox(&insn[i])) {
verbose(env, "last insn is not an exit or jmp\n");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 026/457] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 025/457] bpf: Allow terminal gotox instructions Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 027/457] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
` (441 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul E. McKenney, Rik van Riel,
Jose Fernandez (Anthropic), Josef Bacik, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
[ Upstream commit 85136bf22404474a815fc0ed26ec0d1cbc1bc3f9 ]
__htab_map_lookup_and_delete_batch() has no rescheduling point. The
batch count bounds how many entries are copied out, not how many
buckets are visited, so one BPF_MAP_LOOKUP_BATCH call can walk the
map end to end. The empty-bucket fast path is worse: it stays inside
a single rcu_read_lock() / bpf_disable_instrumentation() section for
any run of consecutive empty buckets.
That holds up on small maps, but it falls apart at scale. On a
144-CPU arm64 host running a CONFIG_PREEMPT_NONE kernel, periodic
BPF_MAP_LOOKUP_BATCH calls against an LRU hash map with 16,777,216
buckets held a CPU inside the batch op for 77+ seconds and triggered
the soft lockup watchdog.
Commit 75134f16e7dd ("bpf: Add schedule points in batch ops") fixed this
same problem in the generic batch ops, but not in this htab-native path,
which every htab-based hash map variant uses for its lookup[_and_delete]
batch ops.
Complete that fix here. Leave the critical section after 64 consecutive
empty buckets, call cond_resched_tasks_rcu_qs(), and resume at the saved
bucket cursor. No locks are held at that point, and resuming from the
cursor is already the function's behavior for non-empty buckets. Add the
same call to the per-bucket loop after copy_to_user(), where every lock
has been dropped. cond_resched_rcu() is not enough here: sleeping with
bpf_prog_active elevated makes tracing programs on that CPU silently
skip their invocations.
Plain cond_resched() is not enough either. It is a no-op under PREEMPT
and PREEMPT_LAZY, the only models arm64 and x86 have offered since
commit 7dadeaa6e851 ("sched: Further restrict the preemption modes").
It is also never a Tasks RCU quiescent state, in any model: the
reschedule counts as a preemption. The walking task stays a holdout and
stalls every synchronize_rcu_tasks() caller, ftrace and BPF trampoline
teardown included, until the syscall returns [1].
cond_resched_tasks_rcu_qs() is the usual tool for that [2]. It reports
the quiescent state at each yield and still reschedules as
cond_resched() does on PREEMPT_NONE and PREEMPT_VOLUNTARY kernels.
Fixes: 057996380a42 ("bpf: Add batch ops to all htab bpf map")
Cc: "Paul E. McKenney" <paulmck@kernel.org>
Cc: Rik van Riel <riel@surriel.com>
Link: https://lore.kernel.org/bpf/20260715215314.44423f47@fangorn/ [1]
Link: https://lore.kernel.org/bpf/9d444098-7c03-4163-af12-bd0a79a51443@paulmck-laptop/ [2]
Assisted-by: LLM
Signed-off-by: Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Reviewed-by: Rik van Riel <riel@surriel.com>
Link: https://lore.kernel.org/r/20260909-b4-htab-batch-resched-v2-1-0cb529d8f95a@toxicpanda.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/hashtab.c | 24 +++++++++++++++++++++---
1 file changed, 21 insertions(+), 3 deletions(-)
diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
index 59406da06424d..419692f41ffde 100644
--- a/kernel/bpf/hashtab.c
+++ b/kernel/bpf/hashtab.c
@@ -1773,6 +1773,12 @@ static int htab_lru_percpu_map_lookup_and_delete_elem(struct bpf_map *map,
flags);
}
+/*
+ * Max consecutive empty buckets to walk in one RCU +
+ * instrumentation-disabled section before rescheduling.
+ */
+#define HTAB_BATCH_EMPTY_RESCHED 64
+
static int
__htab_map_lookup_and_delete_batch(struct bpf_map *map,
const union bpf_attr *attr,
@@ -1794,6 +1800,7 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
unsigned long flags = 0;
bool locked = false;
struct htab_elem *l;
+ u32 empty_cnt = 0;
struct bucket *b;
int ret = 0;
@@ -1972,12 +1979,21 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
}
next_batch:
- /* If we are not copying data, we can go to next bucket and avoid
- * unlocking the rcu.
+ /*
+ * If we are not copying data, we can go to next bucket and avoid
+ * unlocking the rcu. Bound the walk though: after
+ * HTAB_BATCH_EMPTY_RESCHED consecutive empty buckets, fully exit
+ * the critical section (no locks are held here) and reschedule.
*/
if (!bucket_cnt && (batch + 1 < htab->n_buckets)) {
batch++;
- goto again_nocopy;
+ if (++empty_cnt < HTAB_BATCH_EMPTY_RESCHED)
+ goto again_nocopy;
+ empty_cnt = 0;
+ rcu_read_unlock();
+ bpf_enable_instrumentation();
+ cond_resched_tasks_rcu_qs();
+ goto again;
}
rcu_read_unlock();
@@ -1991,11 +2007,13 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
}
total += bucket_cnt;
+ empty_cnt = 0;
batch++;
if (batch >= htab->n_buckets) {
ret = -ENOENT;
goto after_loop;
}
+ cond_resched_tasks_rcu_qs();
goto again;
after_loop:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 027/457] bpf: Fix out-of-bounds read of rtt_min in sock_ops
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 026/457] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 028/457] bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk Greg Kroah-Hartman
` (440 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, VEGA, Jiayuan Chen, Emil Tsalapatis,
Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
[ Upstream commit 75f8cf22463d82bb1fb0239a3d485fc8f4c8ef03 ]
A sockops prog reading skops->rtt_min never checks the sk type: on the
tcp_conn_request() path sock_ops->sk is a request_sock (non-full), and the
ctx rewrite casts it to a tcp_sock (full) and reads rtt_min past the end of
the request_sock, returning dirty adjacent memory.
SEC("sockops")
int prog(struct bpf_sock_ops *skops)
{
switch (skops->op) {
case BPF_SOCK_OPS_RWND_INIT:
leak = skops->rtt_min; /* reads the request_sock OOB */
...
}
}
For instance one such read returned rtt_min=0xffff8881, the high half of a
leaked kernel pointer.
Guarding that cast is exactly what SOCK_OPS_GET_FIELD() does -- it checks
is_locked_tcp_sock and returns 0 when sock_ops->sk is not a locked full
socket. Every other tcp_sock field in sock_ops goes through it; rtt_min is
the only one open-coded, so it skips the check.
Read rtt_min through SOCK_OPS_GET_FIELD() too. rtt_min is a bit special:
it is a struct minmax and we only want the current min, so pass
rtt_min.s[0].v. That is equivalent to the old hand-computed offset
offsetof(struct tcp_sock, rtt_min) + sizeof_field(struct minmax_sample, t)
(s[0] sits at rtt_min + 0 and .v at + sizeof(.t), i.e. what minmax_get()
returns), so the loaded field is unchanged and only the full-sock guard is
added. The two BUILD_BUG_ON()s that protected the hand-computed offset
are no longer needed.
Before patch:
0: r1 = *(u64 *)(r1 +0) ; r1 = skops->sk
1: r1 = *(u32 *)(r1 +2324) ; ((tcp_sock *)sk)->rtt_min.s[0].v
After patch:
0: *(u64 *)(r1 +56) = r9
1: r9 = *(u8 *)(r1 +50) ; is_locked_tcp_sock
2: if r9 == 0 goto pc+4 ; not a locked full sock -> 0
3: r9 = *(u64 *)(r1 +56)
4: r1 = *(u64 *)(r1 +0) ; r1 = skops->sk
5: r1 = *(u32 *)(r1 +2324) ; rtt_min.s[0].v
6: goto pc+2
7: r9 = *(u64 *)(r1 +56)
8: r1 = 0
Fixes: 44f0e43037d3 ("bpf: Add support for reading sk_state and more")
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/r/20260903100921.113374-1-jiayuan.chen@linux.dev
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 13 +------------
1 file changed, 1 insertion(+), 12 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 5769fd10227f3..70f19ef093ee1 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -10943,18 +10943,7 @@ static u32 sock_ops_convert_ctx_access(enum bpf_access_type type,
break;
case offsetof(struct bpf_sock_ops, rtt_min):
- BUILD_BUG_ON(sizeof_field(struct tcp_sock, rtt_min) !=
- sizeof(struct minmax));
- BUILD_BUG_ON(sizeof(struct minmax) <
- sizeof(struct minmax_sample));
-
- *insn++ = BPF_LDX_MEM(BPF_FIELD_SIZEOF(
- struct bpf_sock_ops_kern, sk),
- si->dst_reg, si->src_reg,
- offsetof(struct bpf_sock_ops_kern, sk));
- *insn++ = BPF_LDX_MEM(BPF_W, si->dst_reg, si->dst_reg,
- offsetof(struct tcp_sock, rtt_min) +
- sizeof_field(struct minmax_sample, t));
+ SOCK_OPS_GET_FIELD(rtt_min, rtt_min.s[0].v, struct tcp_sock);
break;
case offsetof(struct bpf_sock_ops, bpf_sock_ops_cb_flags):
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 028/457] bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 027/457] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 029/457] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
` (439 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexei Starovoitov, Hou Tao,
Pu Lehui, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 1c21452d02eec2f008e2c5535820f85adbd7587a ]
Syzkaller repeatedly triggered UAF splats related to nodes in
waiting_for_gp_ttrace within the bpf memalloc:
BUG: KASAN: slab-use-after-free in llist_del_first+0x85/0x110 lib/llist.c:61
Read of size 8 at addr ffff8881572cd080 by task syz.4.470/5112
...
llist_del_first+0x85/0x110 lib/llist.c:61
alloc_bulk+0x193/0x460 kernel/bpf/memalloc.c:229
bpf_mem_refill+0x386/0x560 kernel/bpf/memalloc.c:436
Freed by task 14:
...
__free_rcu kernel/bpf/memalloc.c:281 [inline]
__free_rcu_tasks_trace+0x48/0xd0 kernel/bpf/memalloc.c:291
rcu_tasks_invoke_cbs+0x1ec/0x3e0 kernel/rcu/tasks.h:571
rcu_tasks_one_gp+0x13d/0x220 kernel/rcu/tasks.h:621
rcu_tasks_kthread+0xf3/0x120 kernel/rcu/tasks.h:651
The reason is that the UAF occurs after the RCU Tasks Trace GP expires:
when the __free_rcu() callback runs, there is no synchronization
protecting llist_del_all() against concurrent alloc_bulk() operating on
waiting_for_gp_ttrace, leading to the race condition below:
CPU0 CPU1
__free_rcu (RCU Tasks Trace callback)
alloc_bulk
llist_del_first(&c->waiting_for_gp_ttrace)
entry = smp_load_acquire(&head->first);
do {
if (entry == NULL)
return NULL;
free_all(llist_del_all(&c->waiting_for_gp_ttrace))
llist_for_each_safe(pos, t, llnode)
free_one(pos);
next = READ_ONCE(entry->next); <-- trigger UAF
} while (!try_cmpxchg(&head->first, &entry, next));
In addition, there is also a theoretical race condition on the
free_by_rcu_ttrace list. This race requires two preconditions: an
in-flight Tasks Trace GP keeping c->call_rcu_ttrace_in_progress == 1,
and concurrent cross-CPU frees repopulating c->free_by_rcu_ttrace with
new nodes. Under these conditions, the following scenario triggers UAF:
// CPU0
// irq work is still busy (on PREEMPT_RT)
alloc_bulk()
llist_del_first(&c->free_by_rcu_ttrace)
entry = smp_load_acquire(&head->first);
do {
if (entry == NULL)
return NULL;
// CPU1
bpf_mem_alloc_destroy()
WRITE_ONCE(c->draining, true)
// wait for CPU0
irq_work_sync()
// CPU2
do_call_rcu_ttrace(tgt(CPU0))
if (c->draining) {
llist_del_all(&c->free_by_rcu_ttrace)
free_all()
}
// CPU0 continue
next = READ_ONCE(entry->next); <-- trigger UAF
while (!try_cmpxchg(&head->first, &entry, next));
Fix this by introducing a raw spinlock to synchronize the concurrent
consumption on waiting_for_gp_ttrace and free_by_rcu_ttrace.
Fixes: 04fabf00b4d3 ("bpf: Allow reuse from waiting_for_gp_ttrace list.")
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Suggested-by: Hou Tao <houtao1@huawei.com>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Acked-by: Hou Tao <houtao1@huawei.com>
Link: https://lore.kernel.org/r/20260905021139.4116529-1-pulehui@huaweicloud.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/memalloc.c | 50 ++++++++++++++++++++++++-------------------
1 file changed, 28 insertions(+), 22 deletions(-)
diff --git a/kernel/bpf/memalloc.c b/kernel/bpf/memalloc.c
index e9662db7198fe..8a8f088e83e6f 100644
--- a/kernel/bpf/memalloc.c
+++ b/kernel/bpf/memalloc.c
@@ -119,6 +119,7 @@ struct bpf_mem_cache {
struct llist_head waiting_for_gp_ttrace;
struct rcu_head rcu_ttrace;
atomic_t call_rcu_ttrace_in_progress;
+ raw_spinlock_t lock;
};
struct bpf_mem_caches {
@@ -214,25 +215,24 @@ static void alloc_bulk(struct bpf_mem_cache *c, int cnt, int node, bool atomic)
gfp = __GFP_NOWARN | __GFP_ACCOUNT;
gfp |= atomic ? GFP_NOWAIT : GFP_KERNEL;
- for (i = 0; i < cnt; i++) {
- /*
- * For every 'c' llist_del_first(&c->free_by_rcu_ttrace); is
- * done only by one CPU == current CPU. Other CPUs might
- * llist_add() and llist_del_all() in parallel.
- */
- obj = llist_del_first(&c->free_by_rcu_ttrace);
- if (!obj)
- break;
- add_obj_to_free_list(c, obj);
- }
- if (i >= cnt)
- return;
+ /*
+ * c->lock serializes concurrent llist_del_first() against
+ * llist_del_all() in __free_rcu() and do_call_rcu_ttrace().
+ */
+ scoped_guard(raw_spinlock_irqsave, &c->lock) {
+ for (i = 0; i < cnt; i++) {
+ obj = llist_del_first(&c->free_by_rcu_ttrace);
+ if (!obj)
+ break;
+ add_obj_to_free_list(c, obj);
+ }
- for (; i < cnt; i++) {
- obj = llist_del_first(&c->waiting_for_gp_ttrace);
- if (!obj)
- break;
- add_obj_to_free_list(c, obj);
+ for (; i < cnt; i++) {
+ obj = llist_del_first(&c->waiting_for_gp_ttrace);
+ if (!obj)
+ break;
+ add_obj_to_free_list(c, obj);
+ }
}
if (i >= cnt)
return;
@@ -279,8 +279,12 @@ static int free_all(struct bpf_mem_cache *c, struct llist_node *llnode, bool per
static void __free_rcu(struct rcu_head *head)
{
struct bpf_mem_cache *c = container_of(head, struct bpf_mem_cache, rcu_ttrace);
+ struct llist_node *llnode;
+
+ scoped_guard(raw_spinlock_irqsave, &c->lock)
+ llnode = llist_del_all(&c->waiting_for_gp_ttrace);
- free_all(c, llist_del_all(&c->waiting_for_gp_ttrace), !!c->percpu_size);
+ free_all(c, llnode, !!c->percpu_size);
atomic_set(&c->call_rcu_ttrace_in_progress, 0);
}
@@ -300,7 +304,8 @@ static void do_call_rcu_ttrace(struct bpf_mem_cache *c)
if (atomic_xchg(&c->call_rcu_ttrace_in_progress, 1)) {
if (unlikely(READ_ONCE(c->draining))) {
- llnode = llist_del_all(&c->free_by_rcu_ttrace);
+ scoped_guard(raw_spinlock_irqsave, &c->lock)
+ llnode = llist_del_all(&c->free_by_rcu_ttrace);
free_all(c, llnode, !!c->percpu_size);
}
return;
@@ -535,6 +540,7 @@ int bpf_mem_alloc_init(struct bpf_mem_alloc *ma, int size, bool percpu)
c->objcg = objcg;
c->percpu_size = percpu_size;
c->tgt = c;
+ raw_spin_lock_init(&c->lock);
init_refill_work(c);
prefill_mem_cache(c, cpu);
}
@@ -557,7 +563,7 @@ int bpf_mem_alloc_init(struct bpf_mem_alloc *ma, int size, bool percpu)
c->objcg = objcg;
c->percpu_size = percpu_size;
c->tgt = c;
-
+ raw_spin_lock_init(&c->lock);
init_refill_work(c);
prefill_mem_cache(c, cpu);
}
@@ -609,7 +615,7 @@ int bpf_mem_alloc_percpu_unit_init(struct bpf_mem_alloc *ma, int size)
c->objcg = objcg;
c->percpu_size = percpu_size;
c->tgt = c;
-
+ raw_spin_lock_init(&c->lock);
init_refill_work(c);
prefill_mem_cache(c, cpu);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 029/457] bpf, sockmap: Fix self-redirect copied_seq double-counting
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 028/457] bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 030/457] bpf: Fix u32 overflow issue in map batch operations Greg Kroah-Hartman
` (438 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Sitnicki, Jiayuan Chen,
Geliang Tang, Emil Tsalapatis, Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geliang Tang <tanggeliang@kylinos.cn>
[ Upstream commit 490a83d6386eec1d29f470c8d7331677fb46c3b7 ]
When a BPF stream_verdict program redirects an skb back to the same
socket (self-redirect with BPF_F_INGRESS), sk_psock_verdict_apply()
calls tcp_eat_skb() which advances tcp_sk->copied_seq. However, the
skb is then delivered to the socket's psock ingress queue and later
read by tcp_bpf_recvmsg_parser(), which also advances copied_seq via
the copied_from_self accounting path. This double-counting causes
copied_seq to advance by 2x the actual data length, triggering:
TCP recvmsg seq # bug 2: copied BF2E806, seq BF2E7FD, \
rcvnxt BF2E806, fl 0
WARNING: net/ipv4/tcp.c:2745 at tcp_recvmsg_locked+0x72b/0x2640
Call Trace:
tcp_recvmsg+0x10a/0x500
sock_recvmsg+0x168/0x1d0
__sys_recvfrom+0x19a/0x2a0
__x64_sys_recvfrom+0xe4/0x1f0
do_syscall_64+0xf7/0x530
entry_SYSCALL_64_after_hwframe+0x77/0x7f
cleanup rbuf bug: copied BF2E806 seq BF2E806 rcvnxt BF2E806
WARNING: net/ipv4/tcp.c:1609 at tcp_cleanup_rbuf+0xf2/0x1c0
Call Trace:
tcp_recvmsg_locked+0x8d1/0x2640
tcp_recvmsg+0x10a/0x500
sock_recvmsg+0x168/0x1d0
__sys_recvfrom+0x19a/0x2a0
__x64_sys_recvfrom+0xe4/0x1f0
do_syscall_64+0xf7/0x530
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix this by converting self-redirect verdict to __SK_PASS at the
beginning of sk_psock_verdict_apply(). This bypasses the
__SK_REDIRECT case entirely (which calls sk_psock_eat_skb), letting
the __SK_PASS path queue the skb to the psock ingress queue. The
data is then read via tcp_bpf_recvmsg_parser(), which advances
copied_seq exactly once through copied_from_self. Cross-socket
redirects continue through __SK_REDIRECT with sk_psock_eat_skb()
unchanged.
Fixes: e5c6de5fa025 ("bpf, sockmap: Incorrectly handling copied_seq")
Suggested-by: Jakub Sitnicki <jakub@cloudflare.com>
Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Signed-off-by: Geliang Tang <tanggeliang@kylinos.cn>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://lore.kernel.org/r/1a8e797a1b26e2f695aaac22ac644c2862f63466.1788858299.git.tanggeliang@kylinos.cn
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skmsg.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/core/skmsg.c b/net/core/skmsg.c
index 2521b643fa05d..df385a5a961e8 100644
--- a/net/core/skmsg.c
+++ b/net/core/skmsg.c
@@ -1000,6 +1000,10 @@ static int sk_psock_verdict_apply(struct sk_psock *psock, struct sk_buff *skb,
int err = 0;
u32 len, off;
+ if (verdict == __SK_REDIRECT && skb_bpf_ingress(skb) &&
+ skb_bpf_redirect_fetch(skb) == psock->sk)
+ verdict = __SK_PASS;
+
switch (verdict) {
case __SK_PASS:
err = -EIO;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 030/457] bpf: Fix u32 overflow issue in map batch operations
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 029/457] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 031/457] bpf, arm64: set up the frame pointer for the exception callback Greg Kroah-Hartman
` (437 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masoud Aghasi, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masoud Aghasi <maghasi@disroot.org>
[ Upstream commit 953824e508b27d12837e32ef37ef6248e1f6fc7a ]
Several map batch operation implementations such as
generic_map_lookup_batch() use calculations in the form of
"values + cp * map->value_size" to compute the desired userspace memory
address for reading or writing. This can overflow the u32 type
(the result of "cp * map->value_size") when the map size exceeds 4GB.
generic_map_lookup_batch() may corrupt values for some keys in
userspace memory, and in some cases it mismatches values for some keys
while still reporting success.
Other batch operations may fail to delete or update some keys,
or the syscall may return unexpected errors.
Add size_t casts to prevent the affected offset and size calculations
from overflowing.
Fixes: cb4d03ab499d ("bpf: Add generic support for lookup batch op")
Fixes: aa2e93b8e58e ("bpf: Add generic support for update and delete batch ops")
Fixes: 057996380a42 ("bpf: Add batch ops to all htab bpf map")
Signed-off-by: Masoud Aghasi <maghasi@disroot.org>
Link: https://lore.kernel.org/r/20260903082734.623904-1-maghasi@disroot.org
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/hashtab.c | 8 ++++----
kernel/bpf/syscall.c | 10 +++++-----
2 files changed, 9 insertions(+), 9 deletions(-)
diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
index 419692f41ffde..5117447ac291b 100644
--- a/kernel/bpf/hashtab.c
+++ b/kernel/bpf/hashtab.c
@@ -1998,10 +1998,10 @@ __htab_map_lookup_and_delete_batch(struct bpf_map *map,
rcu_read_unlock();
bpf_enable_instrumentation();
- if (bucket_cnt && (copy_to_user(ukeys + total * key_size, keys,
- key_size * bucket_cnt) ||
- copy_to_user(uvalues + total * value_size, values,
- value_size * bucket_cnt))) {
+ if (bucket_cnt && (copy_to_user(ukeys + (size_t)total * key_size, keys,
+ (size_t)key_size * bucket_cnt) ||
+ copy_to_user(uvalues + (size_t)total * value_size, values,
+ (size_t)value_size * bucket_cnt))) {
ret = -EFAULT;
goto after_loop;
}
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index c7cb336fb0648..57d61de03306e 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -2033,7 +2033,7 @@ int generic_map_delete_batch(struct bpf_map *map,
for (cp = 0; cp < max_count; cp++) {
err = -EFAULT;
- if (copy_from_user(key, keys + cp * map->key_size,
+ if (copy_from_user(key, keys + (size_t)cp * map->key_size,
map->key_size))
break;
@@ -2095,9 +2095,9 @@ int generic_map_update_batch(struct bpf_map *map, struct file *map_file,
for (cp = 0; cp < max_count; cp++) {
err = -EFAULT;
- if (copy_from_user(key, keys + cp * map->key_size,
+ if (copy_from_user(key, keys + (size_t)cp * map->key_size,
map->key_size) ||
- copy_from_user(value, values + cp * value_size, value_size))
+ copy_from_user(value, values + (size_t)cp * value_size, value_size))
break;
err = bpf_map_update_value(map, map_file, key, value,
@@ -2176,12 +2176,12 @@ int generic_map_lookup_batch(struct bpf_map *map,
if (err)
goto free_buf;
- if (copy_to_user(keys + cp * map->key_size, key,
+ if (copy_to_user(keys + (size_t)cp * map->key_size, key,
map->key_size)) {
err = -EFAULT;
goto free_buf;
}
- if (copy_to_user(values + cp * value_size, value, value_size)) {
+ if (copy_to_user(values + (size_t)cp * value_size, value, value_size)) {
err = -EFAULT;
goto free_buf;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 031/457] bpf, arm64: set up the frame pointer for the exception callback
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 030/457] bpf: Fix u32 overflow issue in map batch operations Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 032/457] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
` (436 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xu Kuohai, Donggeun Yoo,
Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit ef1fb82f12186dd26153b14d9fbcf4ec98db81b3 ]
A program acting as exception boundary saves all callee-saved registers,
so build_prologue() takes the exception_cb path and never calls
push_callee_regs(). That is the only place find_used_callee_regs() runs,
and with it the only place ctx->fp_used is set, so the callback prologue
does not emit the
mov x25, sp
that points BPF_REG_FP at the frame the callback runs on. x25 keeps
whatever it held when bpf_throw() was called. If the throw came from a
subprogram that uses its own BPF stack, that is the subprogram's frame
pointer, and since the subprogram never returns it never restores x25
either.
Stack accesses through BPF_REG_FP are rewritten to be stack pointer
relative, so those still land in the callback's own frame. Materializing
the register does not: a callback that passes the address of a local
variable to a helper hands over an address in the dead subprogram's
frame. That address is below the callback's stack pointer by then, and
the helper's own call chain covers it, so the helper can write over its
own return address. 0x1234 below is the value the helper was asked to
store:
pc : 0x1234
lr : 0x1234
Call trace:
0x1234 (P)
bpf_test_run+0x188/0x3e0
bpf_prog_test_run_skb+0x47c/0x998
__sys_bpf+0xbdc/0xdd8
Kernel panic - not syncing: Oops: Fatal exception in interrupt
Set ctx->fp_used on the exception callback path so that the existing code
further down sets x25 from the stack pointer. The epilogue restores it
from the main program's save area along with the other callee-saved
registers, as it already does. x86 sets the frame pointer for the
callback from the argument it is passed, and powerpc computes it from
the stack pointer.
Fixes: 5d4fa9ec5643 ("bpf, arm64: Avoid blindly saving/restoring all callee-saved registers")
Acked-by: Xu Kuohai <xukuohai@huawei.com>
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260907130624.611942-2-donggeunyoo.kernel@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/net/bpf_jit_comp.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
index d4e62484baea0..8c0c9b0fda16f 100644
--- a/arch/arm64/net/bpf_jit_comp.c
+++ b/arch/arm64/net/bpf_jit_comp.c
@@ -600,6 +600,8 @@ static int build_prologue(struct jit_ctx *ctx, bool ebpf_from_cbpf)
* 12 registers are on the stack
*/
emit(A64_SUB_I(1, A64_SP, A64_FP, 96), ctx);
+ /* The callback may use its own BPF stack, set up fp for it. */
+ ctx->fp_used = true;
}
/* Stack must be multiples of 16B */
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 032/457] pinctrl: meson: Fix typo in s4 group name
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 031/457] bpf, arm64: set up the frame pointer for the exception callback Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 033/457] pinctrl: generic: serialise pinctrl_generic_dt_node_to_map() Greg Kroah-Hartman
` (435 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Anderson, Neil Armstrong,
Linus Walleij, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Anderson <sanderson@brivo.com>
[ Upstream commit 692f32609a30f75ca3401e25b504bfd06bd5662a ]
One of the i2c pin groups has some junk at the end. The name should be
i2c2_scl_h1, and indeed that's the name used by i2c2_pins3 in
meson-s4.dtsi.
Fixes: 775214d389c25 ("pinctrl: meson: add pinctrl driver support for Meson-S4 Soc")
Signed-off-by: Sean Anderson <sanderson@brivo.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/meson/pinctrl-meson-s4.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pinctrl/meson/pinctrl-meson-s4.c b/drivers/pinctrl/meson/pinctrl-meson-s4.c
index 872948699e9fe..365dafe457a9f 100644
--- a/drivers/pinctrl/meson/pinctrl-meson-s4.c
+++ b/drivers/pinctrl/meson/pinctrl-meson-s4.c
@@ -854,7 +854,7 @@ static const char * const i2c1_groups[] = {
static const char * const i2c2_groups[] = {
"i2c2_sda_d", "i2c2_scl_d",
"i2c2_sda_h8", "i2c2_scl_h9",
- "i2c2_sda_h0", "i2c2_scl_h1l,"
+ "i2c2_sda_h0", "i2c2_scl_h1",
};
static const char * const i2c3_groups[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 033/457] pinctrl: generic: serialise pinctrl_generic_dt_node_to_map()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 032/457] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 034/457] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
` (434 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sarah Emery, Linus Walleij,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sarah Emery <sarah.emery@canonical.com>
[ Upstream commit 51ae99659469edba2e83931efa26b77d36ca02c2 ]
pinctrl_generic_add_group() documents that the caller must take care of
locking, and pinmux_generic_add_function() needs it too, but
pinctrl_generic_dt_node_to_map() calls them without holding
pctldev->mutex, and the core caller in create_pinctrl() does not take it
either.
The driver core calls pinctrl_bind_pins() before probing a device, so
two devices that reference the same pin controller can run
pinctrl_generic_dt_node_to_map() on one pctldev at the same time.
Both `add` functions take the new selector from pctldev->num_groups or
pctldev->num_functions, and radix_tree_insert() at that index.
Two racing callers can read the same selector before either
has inserted, so the second insert collides and fails:
k1-pinctrl d401e000.pinctrl:
error -EEXIST: error adding function pcie2-0-cfg
k1-pinctrl d401e000.pinctrl:
does not have pin group pcie0-0-cfg.pcie0-0-pins
leaving one consumer without its pin configuration.
This was hit on a SpacemiT K3 board, where PCIe devices probe in parallel
against the single shared pin controller.
Take pctldev->mutex across the whole function, so that the groups and the
function referring are in a single critical section.
Fixes: 43722575e5cd ("pinctrl: add generic functions + pins mapper")
Signed-off-by: Sarah Emery <sarah.emery@canonical.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/pinctrl-generic.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/pinctrl/pinctrl-generic.c b/drivers/pinctrl/pinctrl-generic.c
index fd6bdb74028aa..4277c87485135 100644
--- a/drivers/pinctrl/pinctrl-generic.c
+++ b/drivers/pinctrl/pinctrl-generic.c
@@ -3,8 +3,10 @@
#define pr_fmt(fmt) "generic pinconfig core: " fmt
#include <linux/array_size.h>
+#include <linux/cleanup.h>
#include <linux/device.h>
#include <linux/module.h>
+#include <linux/mutex.h>
#include <linux/of.h>
#include <linux/slab.h>
@@ -196,6 +198,8 @@ static int pinctrl_generic_dt_node_to_map(struct pinctrl_dev *pctldev,
int ngroups = 0;
int ret;
+ guard(mutex)(&pctldev->mutex);
+
*maps = NULL;
*num_maps = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 034/457] HID: amd_sfh: Validate PCI BAR size before mapping
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 033/457] pinctrl: generic: serialise pinctrl_generic_dt_node_to_map() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 035/457] HID: bpf: fix __hid_bpf_hw_check_params report length Greg Kroah-Hartman
` (433 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+4eadd4dfe9e66522bae8,
Slawomir Stepien, Basavaraj Natikar, Jiri Kosina, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slawomir Stepien <sst@poczta.fm>
[ Upstream commit 65bcc5f89704efe5b9d69d4ea2c1002d90c31382 ]
The amd_sfh driver maps PCI BAR 2 using pcim_iomap_regions() and
subsequently accesses MMIO registers at offsets up to 0x10958 (e.g.,
AMD_P2C_MSG3 at 0x1068C). However, the driver never validates that the BAR
size is large enough to cover these accesses. If the driver is bound to a
device with a smaller BAR 2, this leads to an out-of-bounds memory access
and a page fault during the probe function.
For example, a page fault can occur when reading from privdata->mmio +
AMD_P2C_MSG3 in mp2_select_ops():
BUG: unable to handle page fault for address: ffffc9000390368c
PGD 100000067 P4D 100000067 PUD 1012c1067 PMD 105b64067 PTE 0
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:readl arch/x86/include/asm/io.h:59 [inline]
RIP: 0010:mp2_select_ops drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:282
[inline]
RIP: 0010:amd_mp2_pci_probe+0x337/0x5f0
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c:487
Call Trace:
<TASK>
local_pci_probe drivers/pci/pci-driver.c:332 [inline]
pci_call_probe drivers/pci/pci-driver.c:394 [inline]
__pci_device_probe drivers/pci/pci-driver.c:455 [inline]
pci_device_probe+0x431/0xc90 drivers/pci/pci-driver.c:489
Fix this by verifying that the length of BAR 2 is at least 128KB before
attempting to map it. Since the maximum accessed offset is 0x10958, and PCI
BAR sizes are powers of 2, any legitimate hardware will have a BAR size of
at least 128KB.
Fixes: 4f567b9f8141 ("SFH: PCIe driver to add support of AMD sensor fusion hub")
Assisted-by: Gemini:gemini-3.7-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+4eadd4dfe9e66522bae8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Link: https://syzkaller.appspot.com/ai_job?id=3bc1c45c-548f-4ab5-8243-d2c8ec321d6c
Signed-off-by: Slawomir Stepien <sst@poczta.fm>
Acked-by: Basavaraj Natikar <Basavaraj.Natikar@amd.com>
Link: https://syzkaller.appspot.com/bug?extid=4eadd4dfe9e66522bae8
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/amd-sfh-hid/amd_sfh_common.h | 4 ++++
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c | 10 ++++++++++
2 files changed, 14 insertions(+)
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_common.h b/drivers/hid/amd-sfh-hid/amd_sfh_common.h
index 78f830c133e5c..bd8dc16feb614 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_common.h
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_common.h
@@ -12,11 +12,15 @@
#include <linux/mutex.h>
#include <linux/pci.h>
+#include <linux/sizes.h>
#include "amd_sfh_hid.h"
#define PCI_DEVICE_ID_AMD_MP2 0x15E4
#define PCI_DEVICE_ID_AMD_MP2_1_1 0x164A
+/* The BAR 2 size must cover the highest register offset (0x10958) */
+#define AMD_SFH_MIN_BAR_SIZE SZ_128K
+
#define AMD_C2P_MSG(regno) (0x10500 + ((regno) * 4))
#define AMD_P2C_MSG(regno) (0x10680 + ((regno) * 4))
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
index 4b81cebdc3359..039b6ac327d3d 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_pcie.c
@@ -451,6 +451,16 @@ static int amd_mp2_pci_probe(struct pci_dev *pdev, const struct pci_device_id *i
if (rc)
return rc;
+ if (!(pci_resource_flags(pdev, 2) & IORESOURCE_MEM)) {
+ dev_err(&pdev->dev, "BAR 2 is not IORESOURCE_MEM\n");
+ return -ENODEV;
+ }
+
+ if (pci_resource_len(pdev, 2) < AMD_SFH_MIN_BAR_SIZE) {
+ dev_err(&pdev->dev, "BAR 2 is too small\n");
+ return -EINVAL;
+ }
+
rc = pcim_iomap_regions(pdev, BIT(2), DRIVER_NAME);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 035/457] HID: bpf: fix __hid_bpf_hw_check_params report length
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 034/457] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 036/457] RISC-V: KVM: Fix the conversion between vsip and hvip Greg Kroah-Hartman
` (432 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Benjamin Tissoires, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Tissoires <bentiss@kernel.org>
[ Upstream commit c4afa4862b878d56e0cc1021298794ac1b45bc49 ]
Turns out that USB, I2C and other transport drivers (except uhid which
just passes the data) still need to have the report ID in the first
byte.
Because they expect the first byte to be the report ID or 0, when the
report ID is 0, they strip that first byte before forwarding to the
device. This means that the transport layer forwards a buffer of size
N-1 to the device, which gets rejected.
Fixes: 5599f8019661 ("HID: bpf: export hid_hw_output_report as a BPF kfunc")
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/bpf/hid_bpf_dispatch.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/hid/bpf/hid_bpf_dispatch.c b/drivers/hid/bpf/hid_bpf_dispatch.c
index 536f6d01fd14c..b1de1dd0f21d0 100644
--- a/drivers/hid/bpf/hid_bpf_dispatch.c
+++ b/drivers/hid/bpf/hid_bpf_dispatch.c
@@ -359,7 +359,7 @@ hid_bpf_release_context(struct hid_bpf_ctx *ctx)
static int
__hid_bpf_hw_check_params(struct hid_bpf_ctx *ctx, __u8 *buf, size_t *buf__sz,
- enum hid_report_type rtype)
+ enum hid_report_type rtype, bool hw_request)
{
struct hid_report_enum *report_enum;
struct hid_report *report;
@@ -388,6 +388,10 @@ __hid_bpf_hw_check_params(struct hid_bpf_ctx *ctx, __u8 *buf, size_t *buf__sz,
report_len = hid_report_len(report);
+ /* unnumbered reports need to have a report ID reserved in the first byte */
+ if (hw_request && report_enum->numbered == 0)
+ report_len += 1;
+
if (*buf__sz > report_len)
*buf__sz = report_len;
@@ -420,7 +424,7 @@ hid_bpf_hw_request(struct hid_bpf_ctx *ctx, __u8 *buf, size_t buf__sz,
return -EDEADLOCK;
/* check arguments */
- ret = __hid_bpf_hw_check_params(ctx, buf, &size, rtype);
+ ret = __hid_bpf_hw_check_params(ctx, buf, &size, rtype, true);
if (ret)
return ret;
@@ -480,7 +484,7 @@ hid_bpf_hw_output_report(struct hid_bpf_ctx *ctx, __u8 *buf, size_t buf__sz)
return -EDEADLOCK;
/* check arguments */
- ret = __hid_bpf_hw_check_params(ctx, buf, &size, HID_OUTPUT_REPORT);
+ ret = __hid_bpf_hw_check_params(ctx, buf, &size, HID_OUTPUT_REPORT, true);
if (ret)
return ret;
@@ -506,7 +510,7 @@ __hid_bpf_input_report(struct hid_bpf_ctx *ctx, enum hid_report_type type, u8 *b
return -EDEADLOCK;
/* check arguments */
- ret = __hid_bpf_hw_check_params(ctx, buf, &size, type);
+ ret = __hid_bpf_hw_check_params(ctx, buf, &size, type, false);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 036/457] RISC-V: KVM: Fix the conversion between vsip and hvip
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 035/457] HID: bpf: fix __hid_bpf_hw_check_params report length Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 037/457] KVM: riscv: Fix NACL hfence entry update order Greg Kroah-Hartman
` (431 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yicong Yang, Anup Patel, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yicong Yang <yang.yicong@picoheart.com>
[ Upstream commit 52c6b7d20d3e791a9e75aa2be2a467990154c7cd ]
Per AIA spec 1.0 Section 6.3.2, the interrupt numbers 13-63
shares same bit position between related VS shadow CSRs and
hypervisor CSRs. So there's a shift only for SSI, STI and
SEI interrupt.
Currently the KVM always does a shift for all the interrupts
(include LCOFI with number 13) when doing the conversion
between vsip and hvip. Fix this by only doing shift the SSI,
STI and SEI. Add wrappers for doing the conversion between
vsip and hvip.
Fixes: 16b0bde9a37c ("RISC-V: KVM: Add perf sampling support for guests")
Signed-off-by: Yicong Yang <yang.yicong@picoheart.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260804134018.85497-1-yang.yicong@picoheart.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/include/asm/csr.h | 20 ++++++++++++++++----
arch/riscv/kvm/vcpu.c | 3 +--
arch/riscv/kvm/vcpu_onereg.c | 8 +++-----
tools/arch/riscv/include/asm/csr.h | 20 ++++++++++++++++----
4 files changed, 36 insertions(+), 15 deletions(-)
diff --git a/arch/riscv/include/asm/csr.h b/arch/riscv/include/asm/csr.h
index 31b8988f4488d..72ff259154e9b 100644
--- a/arch/riscv/include/asm/csr.h
+++ b/arch/riscv/include/asm/csr.h
@@ -183,12 +183,24 @@
#define HGATP_MODE_SHIFT HGATP32_MODE_SHIFT
#endif
-/* VSIP & HVIP relation */
+/*
+ * VSIP & HVIP relation
+ *
+ * The bit positions are same between VSIP and HVIP for interrupt
+ * numbers 13-63, where there's a shift for the SSI, STI and SEI.
+ */
#define VSIP_TO_HVIP_SHIFT (IRQ_VS_SOFT - IRQ_S_SOFT)
-#define VSIP_VALID_MASK ((_AC(1, UL) << IRQ_S_SOFT) | \
+#define VSIP_BIAS_MASK ((_AC(1, UL) << IRQ_S_SOFT) | \
(_AC(1, UL) << IRQ_S_TIMER) | \
- (_AC(1, UL) << IRQ_S_EXT) | \
- (_AC(1, UL) << IRQ_PMU_OVF))
+ (_AC(1, UL) << IRQ_S_EXT))
+#define VSIP_NO_BIAS_MASK (_AC(1, UL) << IRQ_PMU_OVF)
+#define VSIP_VALID_MASK (VSIP_BIAS_MASK | VSIP_NO_BIAS_MASK)
+#define vsip_to_hvip(_vsip) ((((_vsip) & VSIP_BIAS_MASK) << \
+ VSIP_TO_HVIP_SHIFT) | \
+ ((_vsip) & VSIP_NO_BIAS_MASK))
+#define hvip_to_vsip(_hvip) ((((_hvip) >> VSIP_TO_HVIP_SHIFT) & \
+ VSIP_BIAS_MASK) | \
+ ((_hvip) & VSIP_NO_BIAS_MASK))
/* AIA CSR bits */
#define TOPI_IID_SHIFT 16
diff --git a/arch/riscv/kvm/vcpu.c b/arch/riscv/kvm/vcpu.c
index 977e36ab83d3f..468918309dff3 100644
--- a/arch/riscv/kvm/vcpu.c
+++ b/arch/riscv/kvm/vcpu.c
@@ -475,8 +475,7 @@ bool kvm_riscv_vcpu_has_interrupts(struct kvm_vcpu *vcpu, u64 mask)
bool ret;
raw_spin_lock_irqsave(&vcpu->arch.irqs_pending_lock, flags);
- ie = ((vcpu->arch.guest_csr.vsie & VSIP_VALID_MASK)
- << VSIP_TO_HVIP_SHIFT) & (unsigned long)mask;
+ ie = vsip_to_hvip(vcpu->arch.guest_csr.vsie) & (unsigned long)mask;
ie |= vcpu->arch.guest_csr.vsie & ~IRQ_LOCAL_MASK &
(unsigned long)mask;
ret = vcpu->arch.irqs_pending[0] & ie;
diff --git a/arch/riscv/kvm/vcpu_onereg.c b/arch/riscv/kvm/vcpu_onereg.c
index 99b9107b1ac18..9fe829eed1781 100644
--- a/arch/riscv/kvm/vcpu_onereg.c
+++ b/arch/riscv/kvm/vcpu_onereg.c
@@ -272,7 +272,7 @@ static int kvm_riscv_vcpu_general_get_csr(struct kvm_vcpu *vcpu,
if (reg_num == KVM_REG_RISCV_CSR_REG(sip)) {
kvm_riscv_vcpu_flush_interrupts(vcpu);
- *out_val = (csr->hvip >> VSIP_TO_HVIP_SHIFT) & VSIP_VALID_MASK;
+ *out_val = hvip_to_vsip(csr->hvip);
*out_val |= csr->hvip & ~IRQ_LOCAL_MASK;
} else
*out_val = ((unsigned long *)csr)[reg_num];
@@ -293,10 +293,8 @@ static int kvm_riscv_vcpu_general_set_csr(struct kvm_vcpu *vcpu,
reg_num = array_index_nospec(reg_num, regs_max);
- if (reg_num == KVM_REG_RISCV_CSR_REG(sip)) {
- reg_val &= VSIP_VALID_MASK;
- reg_val <<= VSIP_TO_HVIP_SHIFT;
- }
+ if (reg_num == KVM_REG_RISCV_CSR_REG(sip))
+ reg_val = vsip_to_hvip(reg_val);
((unsigned long *)csr)[reg_num] = reg_val;
diff --git a/tools/arch/riscv/include/asm/csr.h b/tools/arch/riscv/include/asm/csr.h
index 21d8cee046383..8df64314d6131 100644
--- a/tools/arch/riscv/include/asm/csr.h
+++ b/tools/arch/riscv/include/asm/csr.h
@@ -163,12 +163,24 @@
#define HGATP_MODE_SHIFT HGATP32_MODE_SHIFT
#endif
-/* VSIP & HVIP relation */
+/*
+ * VSIP & HVIP relation
+ *
+ * The bit positions are same between VSIP and HVIP for interrupt
+ * numbers 13-63, where there's a shift for the SSI, STI and SEI.
+ */
#define VSIP_TO_HVIP_SHIFT (IRQ_VS_SOFT - IRQ_S_SOFT)
-#define VSIP_VALID_MASK ((_AC(1, UL) << IRQ_S_SOFT) | \
+#define VSIP_BIAS_MASK ((_AC(1, UL) << IRQ_S_SOFT) | \
(_AC(1, UL) << IRQ_S_TIMER) | \
- (_AC(1, UL) << IRQ_S_EXT) | \
- (_AC(1, UL) << IRQ_PMU_OVF))
+ (_AC(1, UL) << IRQ_S_EXT))
+#define VSIP_NO_BIAS_MASK (_AC(1, UL) << IRQ_PMU_OVF)
+#define VSIP_VALID_MASK (VSIP_BIAS_MASK | VSIP_NO_BIAS_MASK)
+#define vsip_to_hvip(_vsip) ((((_vsip) & VSIP_BIAS_MASK) << \
+ VSIP_TO_HVIP_SHIFT) | \
+ ((_vsip) & VSIP_NO_BIAS_MASK))
+#define hvip_to_vsip(_hvip) ((((_hvip) >> VSIP_TO_HVIP_SHIFT) & \
+ VSIP_BIAS_MASK) | \
+ ((_hvip) & VSIP_NO_BIAS_MASK))
/* AIA CSR bits */
#define TOPI_IID_SHIFT 16
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 037/457] KVM: riscv: Fix NACL hfence entry update order
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 036/457] RISC-V: KVM: Fix the conversion between vsip and hvip Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 038/457] RISC-V: KVM: Preserve firmware counter value across stop/start Greg Kroah-Hartman
` (430 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zongmin Zhou, Anup Patel,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zongmin Zhou <zhouzongmin@kylinos.cn>
[ Upstream commit b3d346838ec65fac7fd83f5dbcedd13cadfffddb ]
The SBI v3.0 specification (section 15.1.2) requires a nested HFENCE
entry to be populated as follows:
1) find an unused entry with Config.Pending == 0
2) update the Page_Number and Page_Count words
3) update the Config word with Config.Pending set
__kvm_riscv_nacl_hfence() writes the Config word first, so the SBI
implementation (or NACL hardware) can observe a pending entry with
pnum/pcount values left over from the previous use of that entry,
resulting in incorrect TLB flush ranges.
Write pnum and pcount first and the Config word last. Since the
consumer is an external agent on coherent shared memory, use
WRITE_ONCE() to stop the compiler from reordering the stores and
smp_wmb() to make the parameter words globally visible before the
Pending bit is set.
Fixes: d466c19cead5 ("RISC-V: KVM: Add common nested acceleration support")
Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260826075009.68952-1-min_halo@163.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kvm/nacl.c | 20 ++++++++++++++++----
1 file changed, 16 insertions(+), 4 deletions(-)
diff --git a/arch/riscv/kvm/nacl.c b/arch/riscv/kvm/nacl.c
index 6f9f8963e9ddc..0a2a50c6ce035 100644
--- a/arch/riscv/kvm/nacl.c
+++ b/arch/riscv/kvm/nacl.c
@@ -42,12 +42,24 @@ void __kvm_riscv_nacl_hfence(void *shmem,
}
}
- entp = shmem + SBI_NACL_SHMEM_HFENCE_ENTRY_CONFIG(i);
- *entp = cpu_to_lelong(control);
+ /*
+ * Per SBI v3.0 section 15.1.2, the Page_Number and Page_Count
+ * words must be updated before the Config word with its Pending
+ * bit set. WRITE_ONCE() stops the compiler from reordering the
+ * stores and smp_wmb() makes the parameter words globally
+ * visible to the SBI implementation (or NACL hardware) before
+ * the Pending bit is set.
+ */
entp = shmem + SBI_NACL_SHMEM_HFENCE_ENTRY_PNUM(i);
- *entp = cpu_to_lelong(page_num);
+ WRITE_ONCE(*entp, cpu_to_lelong(page_num));
entp = shmem + SBI_NACL_SHMEM_HFENCE_ENTRY_PCOUNT(i);
- *entp = cpu_to_lelong(page_count);
+ WRITE_ONCE(*entp, cpu_to_lelong(page_count));
+
+ /* Ensure the parameter words are visible before the Pending bit */
+ smp_wmb();
+
+ entp = shmem + SBI_NACL_SHMEM_HFENCE_ENTRY_CONFIG(i);
+ WRITE_ONCE(*entp, cpu_to_lelong(control));
}
int kvm_riscv_nacl_enable(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 038/457] RISC-V: KVM: Preserve firmware counter value across stop/start
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 037/457] KVM: riscv: Fix NACL hfence entry update order Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 039/457] RISC-V: KVM: Report snapshot write failure to the guest Greg Kroah-Hartman
` (429 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SeungJu Cheon, Anup Patel,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: SeungJu Cheon <suunj1331@gmail.com>
[ Upstream commit 8b3fd1a8b305321171602bfa7c41212441cf69e4 ]
Firmware events accumulate in kvpmu->fw_event[].value while running,
but counter stop only clears fw_event[].started without saving the
value back to pmc->counter_val. A subsequent counter start without
SBI_PMU_START_FLAG_SET_INIT_VALUE reloads the stale counter_val into
fw_event[].value, losing all events counted so far.
Save fw_event[].value into counter_val when actually stopping a
running counter, and remove the now redundant synchronization from
the snapshot path.
Fixes: badc386869e2c ("RISC-V: KVM: Support firmware events")
Signed-off-by: SeungJu Cheon <suunj1331@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260825083719.643970-2-suunj1331@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kvm/vcpu_pmu.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/arch/riscv/kvm/vcpu_pmu.c b/arch/riscv/kvm/vcpu_pmu.c
index a7f948410d531..904d266a66c44 100644
--- a/arch/riscv/kvm/vcpu_pmu.c
+++ b/arch/riscv/kvm/vcpu_pmu.c
@@ -675,10 +675,12 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
goto out;
}
- if (!kvpmu->fw_event[fevent_code].started)
+ if (!kvpmu->fw_event[fevent_code].started) {
sbiret = SBI_ERR_ALREADY_STOPPED;
-
- kvpmu->fw_event[fevent_code].started = false;
+ } else {
+ kvpmu->fw_event[fevent_code].started = false;
+ pmc->counter_val = kvpmu->fw_event[fevent_code].value;
+ }
} else if (pmc->perf_event) {
if (pmc->started) {
/* Stop counting the counter */
@@ -696,9 +698,7 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
}
if (snap_flag_set && !sbiret) {
- if (pmc->cinfo.type == SBI_PMU_CTR_TYPE_FW)
- pmc->counter_val = kvpmu->fw_event[fevent_code].value;
- else if (pmc->perf_event)
+ if (pmc->perf_event)
pmc->counter_val += perf_event_read_value(pmc->perf_event,
&enabled, &running);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 039/457] RISC-V: KVM: Report snapshot write failure to the guest
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 038/457] RISC-V: KVM: Preserve firmware counter value across stop/start Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 040/457] RISC-V: KVM: Fix perf-backed counter accounting across stop and read Greg Kroah-Hartman
` (428 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SeungJu Cheon, Anup Patel,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: SeungJu Cheon <suunj1331@gmail.com>
[ Upstream commit 057dd2639ceae79adced5d8fe52c32d562edcb3a ]
If kvm_vcpu_write_guest() fails while updating the PMU snapshot area
on counter stop, the guest may receive SBI_SUCCESS without the
snapshot being updated, leaving stale data in shared memory.
Return SBI_ERR_FAILURE when the snapshot write fails.
Fixes: c2f41ddbcdd7 ("RISC-V: KVM: Implement SBI PMU Snapshot feature")
Signed-off-by: SeungJu Cheon <suunj1331@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260825083719.643970-3-suunj1331@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kvm/vcpu_pmu.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/arch/riscv/kvm/vcpu_pmu.c b/arch/riscv/kvm/vcpu_pmu.c
index 904d266a66c44..a749591a675de 100644
--- a/arch/riscv/kvm/vcpu_pmu.c
+++ b/arch/riscv/kvm/vcpu_pmu.c
@@ -727,9 +727,10 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
}
}
- if (shmem_needs_update)
- kvm_vcpu_write_guest(vcpu, kvpmu->snapshot_addr, kvpmu->sdata,
- sizeof(struct riscv_pmu_snapshot_data));
+ if (shmem_needs_update &&
+ kvm_vcpu_write_guest(vcpu, kvpmu->snapshot_addr, kvpmu->sdata,
+ sizeof(struct riscv_pmu_snapshot_data)))
+ sbiret = SBI_ERR_FAILURE;
out:
retdata->err_val = sbiret;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 040/457] RISC-V: KVM: Fix perf-backed counter accounting across stop and read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 039/457] RISC-V: KVM: Report snapshot write failure to the guest Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 041/457] KVM: arm64: vgic-its: Free the caches when GITS_BASER changes Greg Kroah-Hartman
` (427 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SeungJu Cheon, Anup Patel,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: SeungJu Cheon <suunj1331@gmail.com>
[ Upstream commit c7e2cc38c56142cdab25e6f73602a8222bf9479b ]
pmu_ctr_read() adds the event count returned by perf_event_read_value()
to counter_val, which can accumulate the same count repeatedly across
reads. kvm_riscv_vcpu_pmu_ctr_stop() also leaves counter_val stale by
not folding the current event count into it.
Make reads of perf-backed counters side-effect free, and use
perf_event_pause() when stopping a counter to fold the current event
count into counter_val while resetting it. This preserves the counter
value across stop/start and lets the snapshot path use counter_val
directly.
Fixes: 0cb74b65d2e5 ("RISC-V: KVM: Implement perf support without sampling")
Signed-off-by: SeungJu Cheon <suunj1331@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260825083719.643970-4-suunj1331@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kvm/vcpu_pmu.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/riscv/kvm/vcpu_pmu.c b/arch/riscv/kvm/vcpu_pmu.c
index a749591a675de..73d76fd19896b 100644
--- a/arch/riscv/kvm/vcpu_pmu.c
+++ b/arch/riscv/kvm/vcpu_pmu.c
@@ -270,12 +270,13 @@ static int pmu_ctr_read(struct kvm_vcpu *vcpu, unsigned long cidx,
return -EINVAL;
pmc->counter_val = kvpmu->fw_event[fevent_code].value;
+ *out_val = pmc->counter_val;
} else if (pmc->perf_event) {
- pmc->counter_val += perf_event_read_value(pmc->perf_event, &enabled, &running);
+ *out_val = pmc->counter_val +
+ perf_event_read_value(pmc->perf_event, &enabled, &running);
} else {
return -EINVAL;
}
- *out_val = pmc->counter_val;
return 0;
}
@@ -645,7 +646,6 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
{
struct kvm_pmu *kvpmu = vcpu_to_pmu(vcpu);
int i, pmc_index, sbiret = 0;
- u64 enabled, running;
struct kvm_pmc *pmc;
int fevent_code;
bool snap_flag_set = flags & SBI_PMU_STOP_FLAG_TAKE_SNAPSHOT;
@@ -683,8 +683,11 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
}
} else if (pmc->perf_event) {
if (pmc->started) {
- /* Stop counting the counter */
- perf_event_disable(pmc->perf_event);
+ /*
+ * Stop the counter and fold the live count into counter_val.
+ * Reset the event value to avoid redundant accumulation.
+ */
+ pmc->counter_val += perf_event_pause(pmc->perf_event, true);
pmc->started = false;
} else {
sbiret = SBI_ERR_ALREADY_STOPPED;
@@ -698,9 +701,6 @@ int kvm_riscv_vcpu_pmu_ctr_stop(struct kvm_vcpu *vcpu, unsigned long ctr_base,
}
if (snap_flag_set && !sbiret) {
- if (pmc->perf_event)
- pmc->counter_val += perf_event_read_value(pmc->perf_event,
- &enabled, &running);
/*
* The counter and overflow indices in the snapshot region are w.r.to
* cbase. Modify the set bit in the counter mask instead of the pmc_index
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 041/457] KVM: arm64: vgic-its: Free the caches when GITS_BASER changes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 040/457] RISC-V: KVM: Fix perf-backed counter accounting across stop and read Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 042/457] KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save Greg Kroah-Hartman
` (426 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Fuad Tabba,
Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit 8cd92f77ae4f5371a7d581f8324c24919670b304 ]
A guest that disables the ITS and re-points or shrinks GITS_BASER<n>
with VALID still set keeps the devices and collections it mapped
against the old table, as KVM frees them only when VALID is cleared.
The contents of the table are IMPLEMENTATION DEFINED, so a write that
gives GITS_BASER<n> a different address or size may lose whatever the
old value described. Free the list whenever the stored value changes,
and drop the translation cache with it.
The cache is not empty just because the ITS is disabled: its->enabled
is written under the cmd_lock, while vgic_its_resolve_lpi() tests it
under the its_lock, so an injection can still cache an entry after the
ITS was disabled. Hence the invalidation inside the its_lock section.
Test for a change rather than a write: its_restore_enable() rewrites
GITS_BASER<n> from its probe-time cache on resume, and KVM reports
GITS_TYPER.HCC as 0, so nothing re-maps the boot CPU's collection
afterwards.
Fixes: 36d6961c2b481 ("KVM: arm/arm64: vgic-its: Free caches when GITS_BASER Valid bit is cleared")
Suggested-by: Marc Zyngier <maz@kernel.org>
Link: https://lore.kernel.org/all/87ecg9owwa.wl-maz@kernel.org/
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260821064445.615838-2-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/vgic/vgic-its.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
index ed281fbf008b9..b9a6316f2e00a 100644
--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -1658,7 +1658,7 @@ static void vgic_mmio_write_its_baser(struct kvm *kvm,
unsigned long val)
{
const struct vgic_its_abi *abi = vgic_its_get_abi(its);
- u64 entry_size, table_type;
+ u64 old, entry_size, table_type;
u64 reg, *regptr, clearbits = 0;
/* When GITS_CTLR.Enable is 1, we ignore write accesses. */
@@ -1681,7 +1681,9 @@ static void vgic_mmio_write_its_baser(struct kvm *kvm,
return;
}
- reg = update_64bit_reg(*regptr, addr & 7, len, val);
+ old = *regptr;
+
+ reg = update_64bit_reg(old, addr & 7, len, val);
reg &= ~GITS_BASER_RO_MASK;
reg &= ~clearbits;
@@ -1691,7 +1693,8 @@ static void vgic_mmio_write_its_baser(struct kvm *kvm,
*regptr = reg;
- if (!(reg & GITS_BASER_VALID)) {
+ /* The ITS driver rewrites an unchanged GITS_BASER<n> on resume. */
+ if (reg != old) {
/* Take the its_lock to prevent a race with a save/restore */
mutex_lock(&its->its_lock);
switch (table_type) {
@@ -1702,6 +1705,8 @@ static void vgic_mmio_write_its_baser(struct kvm *kvm,
vgic_its_free_collection_list(kvm, its);
break;
}
+ /* A concurrent injection may have cached a translation. */
+ vgic_its_invalidate_cache(its);
mutex_unlock(&its->its_lock);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 042/457] KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 041/457] KVM: arm64: vgic-its: Free the caches when GITS_BASER changes Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 043/457] KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve() Greg Kroah-Hartman
` (425 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Fuad Tabba,
Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit cc5d96036e01ac330d24b2f0c336d60f82ab4930 ]
vgic_its_save_device_tables() aborts with -EINVAL when a device's entry
falls outside the device table, which a guest can arrange on its own: an
indirect table lets it clear an L1 entry's valid bit without touching
GITS_BASER. That fails a save userspace should be able to issue
reliably.
Skip the device instead, and point the saved DTE chain past it, as
commit ad1e686e2378d ("KVM: arm64: vgic-its: Point saved ITEs at the
next valid entry") does for ITEs. compute_next_devid_offset() takes the
next device off the list whether or not it was saved, so the predecessor
would otherwise point at an entry the save never wrote. Restore follows
that offset while it stays inside the table being scanned: within an L2
block, or anywhere in a flat table. Both need userspace to remove a
memslot under the table, since dropping an L1 entry takes the whole
block with it and scan_its_table() stops at the block boundary.
Fixes: 57a9a117154c9 ("KVM: arm64: vgic-its: Device table save/restore")
Suggested-by: Marc Zyngier <maz@kernel.org>
Link: https://lore.kernel.org/all/86bjaz5s6v.wl-maz@kernel.org/
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260821064445.615838-4-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/vgic/vgic-its.c | 32 +++++++++++++++++++-------------
1 file changed, 19 insertions(+), 13 deletions(-)
diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c
index b9a6316f2e00a..7dc5ef5a6e33a 100644
--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -2024,18 +2024,22 @@ static int vgic_its_attr_regs_access(struct kvm_device *dev,
return ret;
}
-static u32 compute_next_devid_offset(struct list_head *h,
+static u32 compute_next_devid_offset(struct vgic_its *its, u64 baser,
struct its_device *dev)
{
- struct its_device *next;
- u32 next_offset;
+ struct its_device *next = dev;
- if (list_is_last(&dev->dev_list, h))
- return 0;
- next = list_next_entry(dev, dev_list);
- next_offset = next->device_id - dev->device_id;
+ /*
+ * Point at the next device vgic_its_save_device_tables() saves. It
+ * sorts device_list first, so the subtraction cannot underflow.
+ */
+ list_for_each_entry_continue(next, &its->device_list, dev_list) {
+ if (vgic_its_check_id(its, baser, next->device_id, NULL))
+ return min_t(u32, next->device_id - dev->device_id,
+ VITS_DTE_MAX_DEVID_OFFSET);
+ }
- return min_t(u32, next_offset, VITS_DTE_MAX_DEVID_OFFSET);
+ return 0;
}
static u32 compute_next_eventid_offset(struct list_head *h, struct its_ite *ite)
@@ -2275,17 +2279,18 @@ static int vgic_its_restore_itt(struct vgic_its *its, struct its_device *dev)
* vgic_its_save_dte - Save a device table entry at a given GPA
*
* @its: ITS handle
+ * @baser: GITS_BASER<dev> the caller is saving against
* @dev: ITS device
* @ptr: GPA
*/
-static int vgic_its_save_dte(struct vgic_its *its, struct its_device *dev,
- gpa_t ptr)
+static int vgic_its_save_dte(struct vgic_its *its, u64 baser,
+ struct its_device *dev, gpa_t ptr)
{
u64 val, itt_addr_field;
u32 next_offset;
itt_addr_field = dev->itt_addr >> 8;
- next_offset = compute_next_devid_offset(&its->device_list, dev);
+ next_offset = compute_next_devid_offset(its, baser, dev);
val = (1ULL << KVM_ITS_DTE_VALID_SHIFT |
((u64)next_offset << KVM_ITS_DTE_NEXT_SHIFT) |
(itt_addr_field << KVM_ITS_DTE_ITTADDR_SHIFT) |
@@ -2384,15 +2389,16 @@ static int vgic_its_save_device_tables(struct vgic_its *its)
int ret;
gpa_t eaddr;
+ /* Don't fail a save that userspace must be able to issue. */
if (!vgic_its_check_id(its, baser,
dev->device_id, &eaddr))
- return -EINVAL;
+ continue;
ret = vgic_its_save_itt(its, dev);
if (ret)
return ret;
- ret = vgic_its_save_dte(its, dev, eaddr);
+ ret = vgic_its_save_dte(its, baser, dev, eaddr);
if (ret)
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 043/457] KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 042/457] KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 044/457] KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure Greg Kroah-Hartman
` (424 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefan Teodorescu, Marc Zyngier,
Fuad Tabba, Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit 2a2eb10795a1e495aebc7f829ccecb72c05b4fd9 ]
pkvm_vcpu_init_sve() clamps only the upper bound of the host-provided
sve_max_vl, so an invalid vector length reaches sve_state_size_from_vl()
and the WARN_ON() there, which is fatal at EL2. The existing
!sve_state_size test rejects such a length, but only after the macro has
run.
Check sve_vl_valid() before deriving the state size. A valid length
cannot yield a zero size, so the !sve_state_size test goes with it.
Fixes: 5db1bef93342 ("KVM: arm64: Track SVE state in the hypervisor vcpu structure")
Reported-by: Stefan Teodorescu <fane@google.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260825085948.1674721-2-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp/nvhe/pkvm.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c
index 24d6f164129ac..095ebfce91b08 100644
--- a/arch/arm64/kvm/hyp/nvhe/pkvm.c
+++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c
@@ -460,14 +460,15 @@ static int pkvm_vcpu_init_sve(struct pkvm_hyp_vcpu *hyp_vcpu, struct kvm_vcpu *h
/* Limit guest vector length to the maximum supported by the host. */
sve_max_vl = min(READ_ONCE(host_vcpu->arch.sve_max_vl), kvm_host_sve_max_vl);
- sve_state_size = sve_state_size_from_vl(sve_max_vl);
sve_state = kern_hyp_va(READ_ONCE(host_vcpu->arch.sve_state));
- if (!sve_state || !sve_state_size) {
+ if (!sve_vl_valid(sve_max_vl) || !sve_state) {
ret = -EINVAL;
goto err;
}
+ sve_state_size = sve_state_size_from_vl(sve_max_vl);
+
ret = hyp_pin_shared_mem(sve_state, sve_state + sve_state_size);
if (ret)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 044/457] KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 043/457] KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 045/457] KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2 Greg Kroah-Hartman
` (423 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Oliver Upton,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit a1b3c788ad31837e348075e93dbba3f447492776 ]
pkvm_vcpu_init_sve() clears KVM_ARM_VCPU_SVE in kvm->arch.vcpu_features
when it fails, but vcpu_has_sve() tests KVM_ARCH_FLAG_GUEST_HAS_SVE,
which is left set. Later vCPUs on that VM then skip the SVE setup and
register with a NULL sve_state, which the guest's first FP access hands
to sve_load_state().
Return the error without touching vcpu_features.
Fixes: 5db1bef93342 ("KVM: arm64: Track SVE state in the hypervisor vcpu structure")
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260825085948.1674721-3-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp/nvhe/pkvm.c | 13 ++++---------
1 file changed, 4 insertions(+), 9 deletions(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c
index 095ebfce91b08..73e6ee059eebb 100644
--- a/arch/arm64/kvm/hyp/nvhe/pkvm.c
+++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c
@@ -451,7 +451,7 @@ static int pkvm_vcpu_init_sve(struct pkvm_hyp_vcpu *hyp_vcpu, struct kvm_vcpu *h
unsigned int sve_max_vl;
size_t sve_state_size;
void *sve_state;
- int ret = 0;
+ int ret;
if (!vcpu_has_feature(vcpu, KVM_ARM_VCPU_SVE)) {
vcpu_clear_flag(vcpu, VCPU_SVE_FINALIZED);
@@ -462,24 +462,19 @@ static int pkvm_vcpu_init_sve(struct pkvm_hyp_vcpu *hyp_vcpu, struct kvm_vcpu *h
sve_max_vl = min(READ_ONCE(host_vcpu->arch.sve_max_vl), kvm_host_sve_max_vl);
sve_state = kern_hyp_va(READ_ONCE(host_vcpu->arch.sve_state));
- if (!sve_vl_valid(sve_max_vl) || !sve_state) {
- ret = -EINVAL;
- goto err;
- }
+ if (!sve_vl_valid(sve_max_vl) || !sve_state)
+ return -EINVAL;
sve_state_size = sve_state_size_from_vl(sve_max_vl);
ret = hyp_pin_shared_mem(sve_state, sve_state + sve_state_size);
if (ret)
- goto err;
+ return ret;
vcpu->arch.sve_state = sve_state;
vcpu->arch.sve_max_vl = sve_max_vl;
return 0;
-err:
- clear_bit(KVM_ARM_VCPU_SVE, vcpu->kvm->arch.vcpu_features);
- return ret;
}
static int vm_copy_id_regs(struct pkvm_hyp_vcpu *hyp_vcpu)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 045/457] KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 044/457] KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 046/457] KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0 Greg Kroah-Hartman
` (422 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Oliver Upton,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit 4f16c5fc8dc4c5596e3777ab9f449a54e3f85fd5 ]
pkvm_init_features_from_host() takes KVM_ARCH_FLAG_GUEST_HAS_SVE and
KVM_ARM_VCPU_SVE from the host separately, but pkvm_vcpu_init_sve()
tests the bit while vcpu_has_sve() reads the flag. A host that sets the
flag without the bit gets a vCPU with a NULL sve_state that the world
switch loads the guest's SVE state from.
Derive the flag from the bit, and drop the protected path's copy of the
host's flag, which is dead code since protected VMs are not allowed SVE.
Fixes: 41d6028e28bd ("KVM: arm64: Convert the SVE guest vcpu flag to a vm flag")
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260825085948.1674721-5-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp/nvhe/pkvm.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c
index 73e6ee059eebb..53532f0c41628 100644
--- a/arch/arm64/kvm/hyp/nvhe/pkvm.c
+++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c
@@ -360,7 +360,7 @@ static void pkvm_init_features_from_host(struct pkvm_hyp_vm *hyp_vm, const struc
if (test_bit(KVM_ARCH_FLAG_WRITABLE_IMP_ID_REGS, &host_arch_flags))
hyp_vm->kvm.arch.midr_el1 = host_kvm->arch.midr_el1;
- return;
+ goto out;
}
if (kvm_pkvm_ext_allowed(kvm, KVM_CAP_ARM_MTE))
@@ -379,13 +379,14 @@ static void pkvm_init_features_from_host(struct pkvm_hyp_vm *hyp_vm, const struc
if (kvm_pkvm_ext_allowed(kvm, KVM_CAP_ARM_PTRAUTH_GENERIC))
set_bit(KVM_ARM_VCPU_PTRAUTH_GENERIC, allowed_features);
- if (kvm_pkvm_ext_allowed(kvm, KVM_CAP_ARM_SVE)) {
+ if (kvm_pkvm_ext_allowed(kvm, KVM_CAP_ARM_SVE))
set_bit(KVM_ARM_VCPU_SVE, allowed_features);
- kvm->arch.flags |= host_arch_flags & BIT(KVM_ARCH_FLAG_GUEST_HAS_SVE);
- }
bitmap_and(kvm->arch.vcpu_features, host_kvm->arch.vcpu_features,
allowed_features, KVM_VCPU_MAX_FEATURES);
+out:
+ __assign_bit(KVM_ARCH_FLAG_GUEST_HAS_SVE, &kvm->arch.flags,
+ kvm_vcpu_has_feature(kvm, KVM_ARM_VCPU_SVE));
}
static void unpin_host_vcpu(struct kvm_vcpu *host_vcpu)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 046/457] KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 045/457] KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2 Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 047/457] KVM: arm64: Match hyp text by physical address in fix_host_ownership() Greg Kroah-Hartman
` (421 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Steffen Eiden,
Fuad Tabba, Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 64dc6f1db7e620f2e9337bb181f305fb0561da79 ]
kvm_smccc_set_filter() only rejects a range if its inclusive end,
base + nr_functions - 1, is below base. That catches an empty range
(nr_functions == 0) at every nonzero base, but at base 0 the end wraps
to U32_MAX and KVM tries to insert [0, U32_MAX], which overlaps the
reserved Arm Architecture Calls ranges. KVM_ARM_VM_SMCCC_FILTER then
returns -EEXIST instead of the -EINVAL that the smccc_filter selftest
expects for an empty range.
Reject a zero function count explicitly.
Tested with a userspace reproducer on an arm64 VHE host under QEMU TCG:
EEXIST before, EINVAL after.
Fixes: 821d935c87bc ("KVM: arm64: Introduce support for userspace SMCCC filtering")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Steffen Eiden <seiden@linux.ibm.com>
Reviewed-by: Fuad Tabba <fuad.tabba@linux.dev>
Tested-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260829054856.70549-2-kmehltretter@gmail.com
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hypercalls.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hypercalls.c b/arch/arm64/kvm/hypercalls.c
index b11b8821c9fbc..dfa25bb6f25d4 100644
--- a/arch/arm64/kvm/hypercalls.c
+++ b/arch/arm64/kvm/hypercalls.c
@@ -185,7 +185,8 @@ static int kvm_smccc_set_filter(struct kvm *kvm, struct kvm_smccc_filter __user
start = filter.base;
end = start + filter.nr_functions - 1;
- if (end < start || filter.action >= NR_SMCCC_FILTER_ACTIONS)
+ if (!filter.nr_functions || end < start ||
+ filter.action >= NR_SMCCC_FILTER_ACTIONS)
return -EINVAL;
mutex_lock(&kvm->arch.config_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 047/457] KVM: arm64: Match hyp text by physical address in fix_host_ownership()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 046/457] KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0 Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 048/457] KVM: selftests: fix steal_time for arm64 with host page size > 4K Greg Kroah-Hartman
` (420 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Vincent Donnefort,
Marc Zyngier, Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
[ Upstream commit 5a8b505ede133fb30ca3b3a19d0db00c08237615 ]
On a non-hVHE host, fix_host_ownership_walker()'s test for PAGE_HYP_EXEC
never matches: KVM_PGTABLE_PROT_UX is cleared at map time and only PX is
reported on read-back. Hyp text is therefore donated rather than left
read-only in the host stage-2, and the instruction dump in
nvhe_hyp_panic_handler() reads a page the host has no access to.
Match the text by physical address instead, in a helper a later patch
reuses. A test on the permissions would leave any other executable
mapping host-readable too.
Fixes: 80cbfd7174f31 ("KVM: arm64: Honor UX/PX attributes for EL2 S1 mappings")
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Vincent Donnefort <vdonnefort@google.com>
Tested-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260908110713.1540304-3-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/hyp/include/nvhe/mem_protect.h | 1 +
arch/arm64/kvm/hyp/nvhe/mem_protect.c | 8 ++++++++
arch/arm64/kvm/hyp/nvhe/setup.c | 2 +-
3 files changed, 10 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hyp/include/nvhe/mem_protect.h b/arch/arm64/kvm/hyp/include/nvhe/mem_protect.h
index 29935c7da1dec..cab27f7bd423a 100644
--- a/arch/arm64/kvm/hyp/include/nvhe/mem_protect.h
+++ b/arch/arm64/kvm/hyp/include/nvhe/mem_protect.h
@@ -52,6 +52,7 @@ int __pkvm_host_test_clear_young_guest(u64 gfn, u64 nr_pages, bool mkold, struct
int __pkvm_host_mkyoung_guest(u64 gfn, struct pkvm_hyp_vcpu *vcpu);
bool addr_is_memory(phys_addr_t phys);
+bool addr_is_hyp_text(phys_addr_t phys);
int host_stage2_idmap_locked(phys_addr_t addr, u64 size, enum kvm_pgtable_prot prot);
int host_stage2_set_owner_locked(phys_addr_t addr, u64 size, u8 owner_id);
int kvm_host_prepare_stage2(void *pgt_pool_base);
diff --git a/arch/arm64/kvm/hyp/nvhe/mem_protect.c b/arch/arm64/kvm/hyp/nvhe/mem_protect.c
index 4e329e39a695a..7a99361306426 100644
--- a/arch/arm64/kvm/hyp/nvhe/mem_protect.c
+++ b/arch/arm64/kvm/hyp/nvhe/mem_protect.c
@@ -443,6 +443,14 @@ bool addr_is_memory(phys_addr_t phys)
return !!find_mem_range(phys, &range);
}
+bool addr_is_hyp_text(phys_addr_t phys)
+{
+ phys_addr_t start = ALIGN_DOWN(__hyp_pa(__hyp_text_start), PAGE_SIZE);
+ phys_addr_t end = PAGE_ALIGN(__hyp_pa(__hyp_text_end));
+
+ return phys >= start && phys < end;
+}
+
static bool is_in_mem_range(u64 addr, struct kvm_mem_range *range)
{
return range->start <= addr && addr < range->end;
diff --git a/arch/arm64/kvm/hyp/nvhe/setup.c b/arch/arm64/kvm/hyp/nvhe/setup.c
index 75b00c3233102..1bdb952c662b1 100644
--- a/arch/arm64/kvm/hyp/nvhe/setup.c
+++ b/arch/arm64/kvm/hyp/nvhe/setup.c
@@ -217,7 +217,7 @@ static int fix_host_ownership_walker(const struct kvm_pgtable_visit_ctx *ctx,
case PKVM_PAGE_OWNED:
set_hyp_state(page, PKVM_PAGE_OWNED);
/* hyp text is RO in the host stage-2 to be inspected on panic. */
- if (prot == PAGE_HYP_EXEC) {
+ if (addr_is_hyp_text(phys)) {
set_host_state(page, PKVM_NOPAGE);
return host_stage2_idmap_locked(phys, PAGE_SIZE, KVM_PGTABLE_PROT_R);
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 048/457] KVM: selftests: fix steal_time for arm64 with host page size > 4K
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 047/457] KVM: arm64: Match hyp text by physical address in fix_host_ownership() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 049/457] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Greg Kroah-Hartman
` (419 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zenghui Yu, Sebastian Ott,
Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Ott <sebott@redhat.com>
[ Upstream commit 96e6757cb0674acb86ee8b558ee6bffe0eec0bb0 ]
Fix the following failure when running with 16K host page size:
==== Test Assertion Failure ====
lib/kvm_util.c:991: vm_adjust_num_guest_pages(vm->mode, npages) == npages
pid=873 tid=873 errno=0 - Success
1 0x0000000000405a27: vm_mem_add at kvm_util.c:991
2 0x000000000040241f: check_steal_time_uapi at steal_time.c:223 (discriminator 7)
3 (inlined by) main at steal_time.c:539 (discriminator 7)
4 0x00007fff8b57af3b: ?? ??:0
5 0x00007fff8b57b007: ?? ??:0
6 0x0000000000402b6f: _start at ??:?
Number of guest pages is not compatible with the host. Try npages=4
Fixes: fc240715fc50 ("KVM: selftests: arm64: Fix steal_time test after UAPI refactoring")
Reported-by: Zenghui Yu <zenghui.yu@linux.dev>
Link: https://lore.kernel.org/kvmarm/7575a845-a542-4b16-b512-aec3126f97f3@linux.dev/T/#u
Signed-off-by: Sebastian Ott <sebott@redhat.com>
Reviewed-by: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
Link: https://patch.msgid.link/20260914131013.60334-1-sebott@redhat.com
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/kvm/steal_time.c | 30 ++++++++++++++++--------
1 file changed, 20 insertions(+), 10 deletions(-)
diff --git a/tools/testing/selftests/kvm/steal_time.c b/tools/testing/selftests/kvm/steal_time.c
index 76fcdd1fd3cb4..c00cb17f9e40b 100644
--- a/tools/testing/selftests/kvm/steal_time.c
+++ b/tools/testing/selftests/kvm/steal_time.c
@@ -27,6 +27,9 @@
static void *st_gva[NR_VCPUS];
static u64 guest_stolen_time[NR_VCPUS];
+static struct kvm_vm *vm_create_steal_time(u32 nr_vcpus, void *guest_code,
+ struct kvm_vcpu *vcpus[]);
+
#if defined(__x86_64__)
/* steal_time must have 64-byte alignment */
@@ -211,17 +214,14 @@ static void check_steal_time_uapi(void)
u64 st_ipa;
int ret;
- vm = vm_create_with_one_vcpu(&vcpu, NULL);
-
struct kvm_device_attr dev = {
.group = KVM_ARM_VCPU_PVTIME_CTRL,
.attr = KVM_ARM_VCPU_PVTIME_IPA,
.addr = (u64)&st_ipa,
};
+ vm = vm_create_steal_time(1, NULL, &vcpu);
vcpu_ioctl(vcpu, KVM_HAS_DEVICE_ATTR, &dev);
- vm_userspace_mem_region_add(vm, VM_MEM_SRC_ANONYMOUS, ST_GPA_BASE, 1, 1, 0);
- virt_map(vm, ST_GPA_BASE, ST_GPA_BASE, 1);
st_ipa = (ulong)ST_GPA_BASE | 1;
ret = __vcpu_ioctl(vcpu, KVM_SET_DEVICE_ATTR, &dev);
@@ -504,6 +504,21 @@ static void run_vcpu(struct kvm_vcpu *vcpu)
}
}
+static struct kvm_vm *vm_create_steal_time(u32 nr_vcpus, void *guest_code,
+ struct kvm_vcpu *vcpus[])
+{
+ unsigned int gpages;
+ struct kvm_vm *vm;
+
+ /* Create a VM and an identity mapped memslot for the steal time structure */
+ vm = vm_create_with_vcpus(nr_vcpus, guest_code, vcpus);
+ gpages = vm_calc_num_guest_pages(VM_MODE_DEFAULT, STEAL_TIME_SIZE * nr_vcpus);
+ vm_userspace_mem_region_add(vm, VM_MEM_SRC_ANONYMOUS, ST_GPA_BASE, 1, gpages, 0);
+ virt_map(vm, ST_GPA_BASE, ST_GPA_BASE, gpages);
+
+ return vm;
+}
+
int main(int ac, char **av)
{
struct kvm_vcpu *vcpus[NR_VCPUS];
@@ -511,7 +526,6 @@ int main(int ac, char **av)
pthread_attr_t attr;
pthread_t thread;
cpu_set_t cpuset;
- unsigned int gpages;
long stolen_time;
long run_delay;
bool verbose;
@@ -526,11 +540,7 @@ int main(int ac, char **av)
pthread_attr_setaffinity_np(&attr, sizeof(cpu_set_t), &cpuset);
pthread_setaffinity_np(pthread_self(), sizeof(cpu_set_t), &cpuset);
- /* Create a VM and an identity mapped memslot for the steal time structure */
- vm = vm_create_with_vcpus(NR_VCPUS, guest_code, vcpus);
- gpages = vm_calc_num_guest_pages(VM_MODE_DEFAULT, STEAL_TIME_SIZE * NR_VCPUS);
- vm_userspace_mem_region_add(vm, VM_MEM_SRC_ANONYMOUS, ST_GPA_BASE, 1, gpages, 0);
- virt_map(vm, ST_GPA_BASE, ST_GPA_BASE, gpages);
+ vm = vm_create_steal_time(NR_VCPUS, guest_code, vcpus);
ksft_print_header();
TEST_REQUIRE(is_steal_time_supported(vcpus[0]));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 049/457] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 048/457] KVM: selftests: fix steal_time for arm64 with host page size > 4K Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 050/457] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
` (418 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leonardo Bras, Mark Brown,
Lorenzo Stoakes (ARM), Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Brown <broonie@kernel.org>
[ Upstream commit 089e4f3c4862ba3f29dff2361caa8084879194fd ]
The encoding to trap mapping currently maps a FGT on OP_GCSPOPX to
HFGITR_EL2.nGCSEPP but as per DDI0601 2026-06 this FGT controls trapping
of GCSPUSHX and GCSPOPCX, and not the separate GCSPOPX instruction.
Update the mapping to reflect the architecture.
Fixes: 863ac38984a82 ("KVM: arm64: Add missing HFGITR_EL2 FGT entries to nested virt")
Reviewed-by: Leonardo Bras <leo.bras@arm.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Link: https://patch.msgid.link/20260901-arm64-gcs-v20-2-f31750bdfadb@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kvm/emulate-nested.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/emulate-nested.c b/arch/arm64/kvm/emulate-nested.c
index 3c82f392845d1..b32742d9dd73e 100644
--- a/arch/arm64/kvm/emulate-nested.c
+++ b/arch/arm64/kvm/emulate-nested.c
@@ -1432,7 +1432,7 @@ static const struct encoding_to_trap_config encoding_to_fgt[] __initconst = {
SR_FGT(OP_AT_S1E1A, HFGITR, ATS1E1A, 1),
SR_FGT(OP_COSP_RCTX, HFGITR, COSPRCTX, 1),
SR_FGT(OP_GCSPUSHX, HFGITR, nGCSEPP, 0),
- SR_FGT(OP_GCSPOPX, HFGITR, nGCSEPP, 0),
+ SR_FGT(OP_GCSPOPCX, HFGITR, nGCSEPP, 0),
SR_FGT(OP_GCSPUSHM, HFGITR, nGCSPUSHM_EL1, 0),
SR_FGT(OP_BRB_IALL, HFGITR, nBRBIALL, 0),
SR_FGT(OP_BRB_INJ, HFGITR, nBRBINJ, 0),
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 050/457] squashfs: Add dictionary size range check to prevent shift-out-of-bounds
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 049/457] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 051/457] scsi: block: Fix zones_cond out-of-bounds write on zone report Greg Kroah-Hartman
` (417 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ran Hongyun, Phillip Lougher,
Zhihao Cheng, Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ran Hongyun <ranhongyun1@huawei.com>
[ Upstream commit 1f7745fb3580152ca902ef181b605f33cabfb1d0 ]
When an abnormal SquashFS image (COMP_OPTS flag is 1 but dictionary size
is 0) is mounted, and performs shift operations using dictionarysize, the
shift exponent is -1, causing a shift-out-of-bounds.
Detail as below:
squashfs_comp_opts(msblk, buffer, length)
squashfs_xz_comp_opts()
if (comp_opts)
n = ffs(opts->dict_size) - 1;<----opts->dict_size=0, n=-1
if (opts->dict_size != (1 << n) && opts->dict_size !=
(1 << n) + (1 << (n + 1))) <----shift-out-of-bounds
Fix it by adding a dictionary size range check before the shift operation.
Fixes: ff750311d30a ("Squashfs: add compression options support to xz decompressor")
Signed-off-by: Ran Hongyun <ranhongyun1@huawei.com>
Link: https://patch.msgid.link/20260713115525.2661734-1-ranhongyun1@huawei.com
Reviewed-by: Phillip Lougher <phillip@squashfs.org.uk>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/squashfs/xz_wrapper.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/fs/squashfs/xz_wrapper.c b/fs/squashfs/xz_wrapper.c
index 0a4ff3ec9c8cd..6610af2414493 100644
--- a/fs/squashfs/xz_wrapper.c
+++ b/fs/squashfs/xz_wrapper.c
@@ -57,10 +57,10 @@ static void *squashfs_xz_comp_opts(struct squashfs_sb_info *msblk,
opts->dict_size = le32_to_cpu(comp_opts->dictionary_size);
- /* the dictionary size should be 2^n or 2^n+2^(n+1) */
+ /* the dictionary size should be positive and 2^n or 2^n+2^(n+1) */
n = ffs(opts->dict_size) - 1;
- if (opts->dict_size != (1 << n) && opts->dict_size != (1 << n) +
- (1 << (n + 1))) {
+ if (opts->dict_size <= 0 || (opts->dict_size != (1 << n) &&
+ opts->dict_size != (1 << n) + (1 << (n + 1)))) {
err = -EIO;
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 051/457] scsi: block: Fix zones_cond out-of-bounds write on zone report
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 050/457] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 052/457] scsi: sd_zbc: Reject disks with too many zones Greg Kroah-Hartman
` (416 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, ZHOU Jiaxiang, Damien Le Moal,
Martin K. Petersen (Oracle), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: ZHOU Jiaxiang <me@fxti.xyz>
[ Upstream commit 7c431d61b69a3fd0784c20aa4cd0b8fb501b5653 ]
blk_revalidate_disk_zones() sizes the zones_cond array from the disk
capacity and zone size, but the index used by blk_revalidate_zone_cond()
comes from the device-driven report_zones() walk and is never checked
against the array size. A device reporting more zones than fit the array
makes blk_zone_set_cond() write out of bounds.
One way to reach this is a zone count exceeding 32 bits: both
blk_revalidate_zone_args.nr_zones and struct zoned_disk_info.nr_zones are
unsigned int, so a disk advertising more than UINT_MAX zones (e.g. 2^32 +
1024 zones of one 512-byte logical block) gets its zone count truncated to
a small value, undersizing the array while the report walk keeps counting
upward.
Check the index against the array size before storing the zone condition,
and refuse to revalidate when the zone count does not fit 32 bits.
Fixes: 6e945ffb6555 ("block: use zone condition to determine conventional zones")
Signed-off-by: ZHOU Jiaxiang <me@fxti.xyz>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://patch.msgid.link/7815D1B293A8F55E+20260916135822.32584-2-me@fxti.xyz
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-zoned.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/block/blk-zoned.c b/block/blk-zoned.c
index ca30caec838e7..dd6bc679210c8 100644
--- a/block/blk-zoned.c
+++ b/block/blk-zoned.c
@@ -2048,12 +2048,17 @@ static int disk_revalidate_zone_resources(struct gendisk *disk,
struct blk_revalidate_zone_args *args)
{
struct queue_limits *lim = &disk->queue->limits;
+ unsigned long long nr_zones;
unsigned int pool_size;
int ret = 0;
args->disk = disk;
- args->nr_zones =
- DIV_ROUND_UP_ULL(get_capacity(disk), lim->chunk_sectors);
+ nr_zones = DIV_ROUND_UP_ULL(get_capacity(disk), lim->chunk_sectors);
+ if (nr_zones > UINT_MAX) {
+ pr_warn("%s: Too many zones (%llu)\n", disk->disk_name, nr_zones);
+ return -EINVAL;
+ }
+ args->nr_zones = nr_zones;
/* Cached zone conditions: 1 byte per zone */
args->zones_cond = kzalloc(args->nr_zones, GFP_NOIO);
@@ -2161,6 +2166,12 @@ static int blk_revalidate_zone_cond(struct blk_zone *zone, unsigned int idx,
{
enum blk_zone_cond cond = zone->cond;
+ if (idx >= args->nr_zones) {
+ pr_warn("%s: Zone report index %u exceeds zone count %u\n",
+ args->disk->disk_name, idx, args->nr_zones);
+ return -EINVAL;
+ }
+
/* Check that the zone condition is consistent with the zone type. */
switch (cond) {
case BLK_ZONE_COND_NOT_WP:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 052/457] scsi: sd_zbc: Reject disks with too many zones
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 051/457] scsi: block: Fix zones_cond out-of-bounds write on zone report Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 053/457] pinctrl: sunxi: A523: fix voltage withstand encoding Greg Kroah-Hartman
` (415 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, ZHOU Jiaxiang, Damien Le Moal,
Martin K. Petersen (Oracle), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: ZHOU Jiaxiang <me@fxti.xyz>
[ Upstream commit b6ec0f79745967c751c85df373062c8d15e45fc4 ]
sd_zbc_read_zones() computes the number of zones with 64-bit arithmetic and
stores the result in the unsigned int nr_zones field of struct
zoned_disk_info, silently truncating counts that exceed 32 bits. The
truncated count is later used to size per-zone resources, while the device
may still report more zones than fit.
Moreover, sd_zbc_report_zones() counts the reported zones with a signed int
zone_idx, which overflows past INT_MAX. Reject devices reporting more than
INT_MAX zones at scan time; such a device is not realistic for any medium
that exists today, and accepting it produces inconsistent zone bookkeeping.
Fixes: 89d947561077 ("sd: Implement support for ZBC devices")
Signed-off-by: ZHOU Jiaxiang <me@fxti.xyz>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://patch.msgid.link/C41798AB5AA6BF2B+20260916135822.32584-3-me@fxti.xyz
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd_zbc.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/sd_zbc.c b/drivers/scsi/sd_zbc.c
index 56e455fb5addd..456beaf2e7690 100644
--- a/drivers/scsi/sd_zbc.c
+++ b/drivers/scsi/sd_zbc.c
@@ -589,7 +589,7 @@ int sd_zbc_revalidate_zones(struct scsi_disk *sdkp)
int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim,
u8 buf[SD_BUF_SIZE])
{
- unsigned int nr_zones;
+ u64 nr_zones;
u32 zone_blocks = 0;
int ret;
@@ -621,6 +621,12 @@ int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim,
goto err;
nr_zones = round_up(sdkp->capacity, zone_blocks) >> ilog2(zone_blocks);
+ if (nr_zones > INT_MAX) {
+ sd_printk(KERN_ERR, sdkp, "Too many zones (%llu)\n",
+ nr_zones);
+ ret = -EINVAL;
+ goto err;
+ }
sdkp->early_zone_info.nr_zones = nr_zones;
sdkp->early_zone_info.zone_blocks = zone_blocks;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 053/457] pinctrl: sunxi: A523: fix voltage withstand encoding
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 052/457] scsi: sd_zbc: Reject disks with too many zones Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 054/457] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
` (414 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andre Przywara, Per Larsson,
Juan Manuel Lopez Carrillo, Chen-Yu Tsai, Linus Walleij,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andre Przywara <andre.przywara@arm.com>
[ Upstream commit ef56085dfd1df3a53ecce8a4ff440cf6d67f430d ]
The Allwinner A523 uses the same GPIO voltage "withstand" programming
(setting the input level voltage thresholds) as the previous SoCs, but
for some odd reason inverts the encoding of 1.8V vs. 3.3V.
Add a new bias voltage type to note this difference, and select it for
the A523. At the same time also use the newer "CTL" version, which in
addition allows to turn off the withstand programming for I/O voltages
other than exact 1.8V or 3.3V (for instance for 2.5V sometimes used for
Ethernet PHYs). The A523 has that enable register, but didn't use it
so far.
This fixes eMMC and reportedly Ethernet operation on some A523 boards.
Fixes: 648be4cd9517 ("pinctrl: sunxi: Add support for the Allwinner A523")
Signed-off-by: Andre Przywara <andre.przywara@arm.com>
Tested-by: Per Larsson <per@palvencia.se>
Tested-by: Juan Manuel Lopez Carrillo <juanmanuellopezcarrillo@gmail.com>
Reviewed-by: Chen-Yu Tsai <wens@kernel.org>
Tested-by: Chen-Yu Tsai <wens@kernel.org> # Fixes eMMC on Orange Pi 4A
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c | 2 +-
drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c | 2 +-
drivers/pinctrl/sunxi/pinctrl-sunxi.c | 6 ++++++
drivers/pinctrl/sunxi/pinctrl-sunxi.h | 2 ++
4 files changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
index 462aa1c4a5fa6..e27e4945def26 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523-r.c
@@ -26,7 +26,7 @@ static const u8 a523_r_irq_bank_muxes[SUNXI_PINCTRL_MAX_BANKS] =
static struct sunxi_pinctrl_desc a523_r_pinctrl_data = {
.irq_banks = ARRAY_SIZE(a523_r_irq_bank_map),
.irq_bank_map = a523_r_irq_bank_map,
- .io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_SEL,
+ .io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_CTL_INV,
.pin_base = PL_BASE,
};
diff --git a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
index b6f78f1f30ac4..88d8acd5bc245 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sun55i-a523.c
@@ -26,7 +26,7 @@ static const u8 a523_irq_bank_muxes[SUNXI_PINCTRL_MAX_BANKS] =
static struct sunxi_pinctrl_desc a523_pinctrl_data = {
.irq_banks = ARRAY_SIZE(a523_irq_bank_map),
.irq_bank_map = a523_irq_bank_map,
- .io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_SEL,
+ .io_bias_cfg_variant = BIAS_VOLTAGE_PIO_POW_MODE_CTL_INV,
};
static int a523_pinctrl_probe(struct platform_device *pdev)
diff --git a/drivers/pinctrl/sunxi/pinctrl-sunxi.c b/drivers/pinctrl/sunxi/pinctrl-sunxi.c
index 25489beeb3125..7b33bcb7f840a 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sunxi.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sunxi.c
@@ -728,6 +728,7 @@ static int sunxi_pinctrl_set_io_bias_cfg(struct sunxi_pinctrl *pctl,
{
unsigned short bank;
unsigned long flags;
+ bool inverted = false;
u32 val, reg;
int uV;
@@ -766,6 +767,9 @@ static int sunxi_pinctrl_set_io_bias_cfg(struct sunxi_pinctrl *pctl,
reg &= ~IO_BIAS_MASK;
writel(reg | val, pctl->membase + sunxi_grp_config_reg(pin));
return 0;
+ case BIAS_VOLTAGE_PIO_POW_MODE_CTL_INV:
+ inverted = true;
+ fallthrough;
case BIAS_VOLTAGE_PIO_POW_MODE_CTL:
val = uV > 1800000 && uV <= 2500000 ? BIT(bank) : 0;
@@ -780,6 +784,8 @@ static int sunxi_pinctrl_set_io_bias_cfg(struct sunxi_pinctrl *pctl,
fallthrough;
case BIAS_VOLTAGE_PIO_POW_MODE_SEL:
val = uV <= 1800000 ? 1 : 0;
+ if (inverted)
+ val = !val;
raw_spin_lock_irqsave(&pctl->lock, flags);
reg = readl(pctl->membase + pctl->pow_mod_sel_offset);
diff --git a/drivers/pinctrl/sunxi/pinctrl-sunxi.h b/drivers/pinctrl/sunxi/pinctrl-sunxi.h
index 0daf7600e2fb0..b09df32a3073a 100644
--- a/drivers/pinctrl/sunxi/pinctrl-sunxi.h
+++ b/drivers/pinctrl/sunxi/pinctrl-sunxi.h
@@ -116,8 +116,10 @@ enum sunxi_desc_bias_voltage {
* Bias voltage is set through PIO_POW_MOD_SEL_REG
* and PIO_POW_MOD_CTL_REG register, as seen on
* A100 and D1 SoC, for example.
+ * Some SoCs invert the encoding for 1.8V vs. 3.3V.
*/
BIAS_VOLTAGE_PIO_POW_MODE_CTL,
+ BIAS_VOLTAGE_PIO_POW_MODE_CTL_INV,
};
struct sunxi_desc_function {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 054/457] Bluetooth: SMP: reject Security Request over BR/EDR
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 053/457] pinctrl: sunxi: A523: fix voltage withstand encoding Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 055/457] Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump() Greg Kroah-Hartman
` (413 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christiano Amora,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christiano Amora <christiano.amora@gmail.com>
[ Upstream commit f033482d76a9f18080c7a40c5f9c678bd7adc8f3 ]
Bose QC Ultra Headphones (dual-mode, same public address on both
transports) occasionally send an SMP Security Request on the BR/EDR
SMP fixed channel right after the ACL link is encrypted. The kernel
handles it as if it were an LE link: smp_cmd_security_req() has no
transport check, smp_ltk_encrypt() looks up an LTK with the ACL
connection's dst_type, and hci_find_ltk() matches the peer's LE LTK
because the LE public address type is stored as ADDR_LE_DEV_PUBLIC (0),
the same value as BDADDR_BREDR. HCI_OP_LE_START_ENC is then issued on
the ACL handle, the controller rejects it with Invalid HCI Command
Parameters, and hci_cs_le_start_enc() disconnects the link with
HCI_ERROR_AUTH_FAILURE. The headphones drop within a second of
connecting, before any profile is up; a manual reconnect works.
btmon (MediaTek MT7922, kernel 7.0.12):
> HCI Event: Encryption Change (0x08) plen 4
Status: Success (0x00)
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
Encryption: Enabled with AES-CCM (0x02)
> ACL Data RX: Handle 50 flags 0x02 dlen 6
BR/EDR SMP: Security Request (0x0b) len 1
Authentication requirement: No bonding, No MITM, SC (0x08)
< HCI Command: LE Start Encryption (0x08|0x0019) plen 28
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
> HCI Event: Command Status (0x0f) plen 4
LE Start Encryption (0x08|0x0019) ncmd 1
Status: Invalid HCI Command Parameters (0x12)
< HCI Command: Disconnect (0x01|0x0006) plen 3
Handle: 50 Address: BC:87:FA:47:73:5E (Bose Corporation)
Reason: Authentication Failure (0x05)
SMP over BR/EDR is limited to cross-transport key derivation; the
Security Request procedure (Core Specification Vol 3, Part H, Section
2.4.6, PDU in Section 3.6.7) has no BR/EDR counterpart. Reply with
Pairing Failed / Command Not Supported on a non-LE link, before the PDU
is parsed, and keep the connection. The reply is sent directly rather
than through smp_failure(): rejecting a command on the wrong transport
is not an authentication failure, and MGMT_EV_AUTH_FAILED would make
bluetoothd disconnect the device.
Tested on the affected host (kernel 7.0.12, MediaTek MT7922, Bose QC
Ultra) with the patched module built out of tree: 7 days and 49
reconnects without a drop, against 2 drops in the 3 days before the
patch. Every disconnect in that week had a userspace or remote reason.
Fixes: b5ae344d4c0f ("Bluetooth: Add full SMP BR/EDR support")
Assisted-by: LLM
Signed-off-by: Christiano Amora <christiano.amora@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/smp.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/net/bluetooth/smp.c b/net/bluetooth/smp.c
index c4470958b0d57..14bb2c82a5624 100644
--- a/net/bluetooth/smp.c
+++ b/net/bluetooth/smp.c
@@ -2268,6 +2268,23 @@ static u8 smp_cmd_security_req(struct l2cap_conn *conn, struct sk_buff *skb)
bt_dev_dbg(hdev, "conn %p", conn);
+ /* SMP over BR/EDR only covers cross-transport key derivation; the
+ * Security Request procedure has no BR/EDR counterpart. Reject it
+ * here, otherwise smp_ltk_encrypt() finds the peer's LE LTK
+ * (ADDR_LE_DEV_PUBLIC and BDADDR_BREDR are both 0) and issues
+ * HCI_OP_LE_START_ENC on the ACL handle, which the controller
+ * rejects and hci_cs_le_start_enc() turns into a disconnect. Reply
+ * without smp_failure(): this is not an authentication failure, and
+ * MGMT_EV_AUTH_FAILED would make bluetoothd drop the device.
+ */
+ if (hcon->type != LE_LINK) {
+ u8 reason = SMP_CMD_NOTSUPP;
+
+ smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason),
+ &reason);
+ return 0;
+ }
+
if (skb->len < sizeof(*rp))
return SMP_INVALID_PARAMS;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 055/457] Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 054/457] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 056/457] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
` (412 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit f2bbb36426581045a8bf7793da5419b9375e4348 ]
When CONFIG_DEV_COREDUMP=n, hci_devcd_append() returns -EOPNOTSUPP
without freeing its skb argument. This leaks the cloned skb and also
prevents nxp_set_ind_reset() from being called to perform recovery.
Fix by guarding the hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC))
call with IS_ENABLED(CONFIG_DEV_COREDUMP).
Fixes: 998e447f443f ("Bluetooth: btnxpuart: Add support for HCI coredump feature")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btnxpuart.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/bluetooth/btnxpuart.c b/drivers/bluetooth/btnxpuart.c
index e6c15bc6a30b9..73b319c7e1765 100644
--- a/drivers/bluetooth/btnxpuart.c
+++ b/drivers/bluetooth/btnxpuart.c
@@ -1397,9 +1397,11 @@ static int nxp_process_fw_dump(struct hci_dev *hdev, struct sk_buff *skb)
msecs_to_jiffies(20000));
}
- err = hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC));
- if (err < 0)
- goto free_skb;
+ if (IS_ENABLED(CONFIG_DEV_COREDUMP)) {
+ err = hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC));
+ if (err < 0)
+ goto free_skb;
+ }
if (buf_len == 0) {
bt_dev_warn(hdev, "==== FW dump complete ===");
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 056/457] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 055/457] Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 057/457] selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode Greg Kroah-Hartman
` (411 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lee Jones, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lee Jones <lee@kernel.org>
[ Upstream commit 71af682ba4692c2ed9ace4c3d4ca462ae368c029 ]
In send_cancel(), pending mesh_tx objects are removed from the
hdev->mesh_pending list and freed via mesh_send_complete(). However, if
a mesh transmission was already queued onto hdev->cmd_sync_work_list via
mesh_next(), the queued entry retains a raw pointer to mesh_tx.
When hci_cmd_sync_work later processes the entry, it attempts to execute
mesh_send_sync and its destroy callback mesh_send_start_complete using
the already freed mesh_tx pointer, leading to a use-after-free.
Fix this by invoking hci_cmd_sync_dequeue() for mesh_send_sync on the
target mesh_tx before completing it. If the entry is found and dequeued,
its destroy callback will complete and free the object; otherwise,
mesh_send_complete() is called directly.
Additionally, ensure the transmission queue advances after cancellation
or errors. In mesh_send_start_complete(), call mesh_next() on error
unless err is -ECANCELED, because hci_cmd_sync_dequeue() holds
hdev->cmd_sync_work_lock and calling mesh_next() synchronously would
deadlock. Instead, advance the queue in send_cancel() once the lock is
released and if no transmission is in progress.
Fixes: b338d91703fa ("Bluetooth: Implement support for Mesh")
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/mgmt.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index deced8a5bc2d6..9bcc35de08899 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -2310,6 +2310,8 @@ static void mesh_send_start_complete(struct hci_dev *hdev, void *data, int err)
hci_dev_clear_flag(hdev, HCI_MESH_SENDING);
/* Send Complete Error Code for handle */
mesh_send_complete(hdev, mesh_tx, false);
+ if (err != -ECANCELED)
+ mesh_next(hdev, NULL, 0);
return;
}
@@ -2419,19 +2421,28 @@ static int send_cancel(struct hci_dev *hdev, void *data)
do {
mesh_tx = mgmt_mesh_next(hdev, cmd->sk);
- if (mesh_tx)
- mesh_send_complete(hdev, mesh_tx, false);
+ if (mesh_tx) {
+ if (!hci_cmd_sync_dequeue(hdev, mesh_send_sync,
+ mesh_tx, NULL))
+ mesh_send_complete(hdev, mesh_tx, false);
+ }
} while (mesh_tx);
} else {
mesh_tx = mgmt_mesh_find(hdev, cancel->handle);
- if (mesh_tx && mesh_tx->sk == cmd->sk)
- mesh_send_complete(hdev, mesh_tx, false);
+ if (mesh_tx && mesh_tx->sk == cmd->sk) {
+ if (!hci_cmd_sync_dequeue(hdev, mesh_send_sync,
+ mesh_tx, NULL))
+ mesh_send_complete(hdev, mesh_tx, false);
+ }
}
mgmt_cmd_complete(cmd->sk, hdev->id, MGMT_OP_MESH_SEND_CANCEL,
0, NULL, 0);
+ if (!hci_dev_test_flag(hdev, HCI_MESH_SENDING))
+ mesh_next(hdev, NULL, 0);
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 057/457] selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 056/457] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 058/457] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
` (410 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Eva Kurchatova, Tejun Heo,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
[ Upstream commit c774ec8f0a5d02a06d34c27f5a7de7e333b91265 ]
O_TMPFILE, like O_CREAT, needs the third argument. Without it glibc
refuses the call at compile time as soon as fortification is on:
In function 'open',
inlined from 'get_temp_fd' at test_memcontrol.c:33:9:
/usr/include/bits/fcntl2.h:52:11: error: call to '__open_missing_mode'
declared with attribute error: open with O_CREAT or O_TMPFILE in
second argument needs 3 arguments
The fortify checks take effect only once the compiler optimises, and
cgroup/Makefile builds with "-Wall -pthread" alone, so this goes
unnoticed in a plain build. Building the tests with the flags
distributions commonly use, -O2 -D_FORTIFY_SOURCE=3, loses
test_memcontrol entirely.
Fixes: 84092dbcf901 ("selftests: cgroup: add memory controller self-tests")
Signed-off-by: Eva Kurchatova <eva.kurchatova@virtuozzo.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/cgroup/test_memcontrol.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/cgroup/test_memcontrol.c b/tools/testing/selftests/cgroup/test_memcontrol.c
index 3a84d068fbf36..0ed82347044ed 100644
--- a/tools/testing/selftests/cgroup/test_memcontrol.c
+++ b/tools/testing/selftests/cgroup/test_memcontrol.c
@@ -30,7 +30,7 @@ static int page_size;
int get_temp_fd(void)
{
- return open(".", O_TMPFILE | O_RDWR | O_EXCL);
+ return open(".", O_TMPFILE | O_RDWR | O_EXCL, 0600);
}
int alloc_pagecache(int fd, size_t size)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 058/457] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 057/457] selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 059/457] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
` (409 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kashyap Desai, Sumit Saxena,
Shivasharan S, Chandrakanth patil, Bart Van Assche,
Martin K. Petersen (Oracle), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
[ Upstream commit 42d1221d321e55afc7bba9109a77aaf5a817c8a3 ]
Protect the megasas_get_ctrl_info() call in megasas_resume() with
instance->reset_mutex using scoped_guard().
megasas_get_ctrl_info() may release and reacquire instance->reset_mutex.
Hence, calling this function without holding instance->reset_mutex is not
safe.
Fixes: c3b10a55abc9 ("scsi: megaraid_sas: Update controller info during resume")
Cc: Kashyap Desai <kashyap.desai@broadcom.com>
Cc: Sumit Saxena <sumit.saxena@broadcom.com>
Cc: Shivasharan S <shivasharan.srikanteshwara@broadcom.com>
Cc: Chandrakanth patil <chandrakanth.patil@broadcom.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/f06b5ee432b21cf293f0663e15b64f75a84b9fd5.1788204406.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/megaraid/megaraid_sas_base.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/megaraid/megaraid_sas_base.c b/drivers/scsi/megaraid/megaraid_sas_base.c
index d83abded2039b..f25ed22195fa6 100644
--- a/drivers/scsi/megaraid/megaraid_sas_base.c
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
@@ -7886,7 +7886,9 @@ megasas_resume(struct device *dev)
goto fail_init_mfi;
}
- if (megasas_get_ctrl_info(instance) != DCMD_SUCCESS)
+ scoped_guard(mutex, &instance->reset_mutex)
+ rval = megasas_get_ctrl_info(instance);
+ if (rval != DCMD_SUCCESS)
goto fail_init_mfi;
tasklet_init(&instance->isr_tasklet, instance->instancet->tasklet,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 059/457] s390/pci/docs: Fix sriov_numvfs attribute name
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 058/457] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 060/457] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
` (408 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Randy Dunlap,
Heiko Carstens, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 4525a911049543c23885a540a788d13be318a486 ]
The attribute is sriov_numvfs (drivers/pci/iov.c); the document names it
sriov_numvf, which does not exist.
Use sriov_numvfs.
Fixes: de267a7c71ba ("s390/pci: Documentation for zPCI")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/arch/s390/pci.rst | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/arch/s390/pci.rst b/Documentation/arch/s390/pci.rst
index 80f4ba1931599..565434626fb5c 100644
--- a/Documentation/arch/s390/pci.rst
+++ b/Documentation/arch/s390/pci.rst
@@ -67,7 +67,7 @@ Entries specific to zPCI functions and entries that hold zPCI information.
A physical function that currently supports a virtual function cannot be
powered off until all virtual functions are removed with:
- echo 0 > /sys/bus/pci/devices/DDDD:BB:dd.f/sriov_numvf
+ echo 0 > /sys/bus/pci/devices/DDDD:BB:dd.f/sriov_numvfs
* /sys/bus/pci/devices/DDDD:BB:dd.f/:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 060/457] s390/cio: Fix cio_update_schib() to not cache invalid schib
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 059/457] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 061/457] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
` (407 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bezenah, Vineeth Vijayan,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit 29d9e5835d89223aa913dcf7b942cc1c148bdd25 ]
When pmcw.dnv is 0, the contents of all SCHIB fields are unpredictable.
Zero sch->schib in that case to prevent subsequent code from making
decisions based on unpredictable data.
Reported-by: William Bezenah <wbezenah@linux.ibm.com>
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Fixes: 8c58a229688c ("s390/cio: Do not unregister the subchannel based on DNV")
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/cio.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/s390/cio/cio.c b/drivers/s390/cio/cio.c
index 70dc8cc765948..e1c62eb60cca7 100644
--- a/drivers/s390/cio/cio.c
+++ b/drivers/s390/cio/cio.c
@@ -453,7 +453,8 @@ EXPORT_SYMBOL_GPL(cio_commit_config);
/**
* cio_update_schib - Perform stsch and update schib if subchannel is valid.
* @sch: subchannel on which to perform stsch
- * Return zero on success, -ENODEV otherwise.
+ * Return zero on success, -ENODEV if the subchannel is not operational,
+ * -EACCES if the subchannel has no valid device.
*/
int cio_update_schib(struct subchannel *sch)
{
@@ -462,10 +463,12 @@ int cio_update_schib(struct subchannel *sch)
if (stsch(sch->schid, &schib))
return -ENODEV;
- memcpy(&sch->schib, &schib, sizeof(schib));
-
- if (!css_sch_is_valid(&schib))
+ if (!css_sch_is_valid(&schib)) {
+ memset(&sch->schib, 0, sizeof(sch->schib));
return -EACCES;
+ }
+
+ memcpy(&sch->schib, &schib, sizeof(schib));
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 061/457] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 060/457] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 062/457] s390/cio: Guard PMCW field accesses with dnv check Greg Kroah-Hartman
` (406 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bezenah, Vineeth Vijayan,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit f6f2985eabdb2bfdc82ce90a1ea3ec53ba795f34 ]
The device number valid (dnv) bit in the PMCW must be checked before
acting on any other PMCW fields for IO-type subchannels. A subchannel
with dnv=0 has no valid device number associated, making it meaningless
to evaluate the enabled (ena) state or issue any I/O instruction against
it.
Reported-by: William Bezenah <wbezenah@linux.ibm.com>
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Fixes: 8c58a229688c ("s390/cio: Do not unregister the subchannel based on DNV")
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/device_ops.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/drivers/s390/cio/device_ops.c b/drivers/s390/cio/device_ops.c
index 61c07b4a0fe89..c1ba4a19368f2 100644
--- a/drivers/s390/cio/device_ops.c
+++ b/drivers/s390/cio/device_ops.c
@@ -142,6 +142,8 @@ int ccw_device_clear(struct ccw_device *cdev, unsigned long intparm)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -198,6 +200,8 @@ int ccw_device_start_timeout_key(struct ccw_device *cdev, struct ccw1 *cpa,
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -379,6 +383,8 @@ int ccw_device_halt(struct ccw_device *cdev, unsigned long intparm)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -413,6 +419,8 @@ int ccw_device_resume(struct ccw_device *cdev)
if (!cdev || !cdev->dev.parent)
return -ENODEV;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_NOT_OPER)
@@ -548,6 +556,8 @@ int ccw_device_tm_start_timeout_key(struct ccw_device *cdev, struct tcw *tcw,
int rc;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state == DEV_STATE_VERIFY) {
@@ -694,6 +704,8 @@ int ccw_device_tm_intrg(struct ccw_device *cdev)
{
struct subchannel *sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
if (!sch->schib.pmcw.ena)
return -EINVAL;
if (cdev->private->state != DEV_STATE_ONLINE)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 062/457] s390/cio: Guard PMCW field accesses with dnv check
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 061/457] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 063/457] netfs: Fix netfs_read_gaps() to use separate sink folios Greg Kroah-Hartman
` (405 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bezenah, Vineeth Vijayan,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
[ Upstream commit 9590f4d83880dfb5a81906e48e72779248fbe8f0 ]
When PMCW.DNV is 0, no I/O device is associated with the subchannel.
However, several code paths access PMCW fields directly from the cached
sch->schib without first invoking the update helper. Add explicit DNV
validation before accessing PMCW fields from the cached SCHIB to avoid
using invalid data.
Reported-by: William Bezenah <wbezenah@linux.ibm.com>
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Fixes: 8c58a229688c ("s390/cio: Do not unregister the subchannel based on DNV")
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/s390/cio/chp.c | 3 +++
drivers/s390/cio/device.c | 9 +++++----
drivers/s390/cio/device_fsm.c | 3 +++
drivers/s390/cio/device_ops.c | 9 +++++++++
drivers/s390/cio/vfio_ccw_fsm.c | 2 +-
5 files changed, 21 insertions(+), 5 deletions(-)
diff --git a/drivers/s390/cio/chp.c b/drivers/s390/cio/chp.c
index c890f21a82ce3..eaf0527bff6cc 100644
--- a/drivers/s390/cio/chp.c
+++ b/drivers/s390/cio/chp.c
@@ -78,6 +78,9 @@ u8 chp_get_sch_opm(struct subchannel *sch)
int opm;
int i;
+ if (!sch->schib.pmcw.dnv)
+ return 0;
+
opm = 0;
chp_id_init(&chpid);
for (i = 0; i < 8; i++) {
diff --git a/drivers/s390/cio/device.c b/drivers/s390/cio/device.c
index fb591118ecb2a..68dd4a62975d2 100644
--- a/drivers/s390/cio/device.c
+++ b/drivers/s390/cio/device.c
@@ -922,7 +922,7 @@ static int ccw_device_move_to_sch(struct ccw_device *cdev,
if (!sch_is_pseudo_sch(old_sch)) {
spin_lock_irq(&old_sch->lock);
- old_enabled = old_sch->schib.pmcw.ena;
+ old_enabled = old_sch->schib.pmcw.dnv && old_sch->schib.pmcw.ena;
rc = 0;
if (old_enabled)
rc = cio_disable_subchannel(old_sch);
@@ -941,7 +941,7 @@ static int ccw_device_move_to_sch(struct ccw_device *cdev,
CIO_MSG_EVENT(0, "device_move(0.%x.%04x,0.%x.%04x)=%d\n",
cdev->private->dev_id.ssid,
cdev->private->dev_id.devno, sch->schid.ssid,
- sch->schib.pmcw.dev, rc);
+ sch->schid.sch_no, rc);
if (old_enabled) {
/* Try to re-enable the old subchannel. */
spin_lock_irq(&old_sch->lock);
@@ -1207,7 +1207,7 @@ static void io_subchannel_quiesce(struct subchannel *sch)
cdev = sch_get_cdev(sch);
if (cio_is_console(sch->schid))
goto out_unlock;
- if (!sch->schib.pmcw.ena)
+ if (!sch->schib.pmcw.dnv || !sch->schib.pmcw.ena)
goto out_unlock;
ret = cio_disable_subchannel(sch);
if (ret != -EBUSY)
@@ -1254,7 +1254,8 @@ static int recovery_check(struct device *dev, void *data)
switch (cdev->private->state) {
case DEV_STATE_ONLINE:
sch = to_subchannel(cdev->dev.parent);
- if ((sch->schib.pmcw.pam & sch->opm) == sch->vpm)
+ if (sch->schib.pmcw.dnv &&
+ (sch->schib.pmcw.pam & sch->opm) == sch->vpm)
break;
fallthrough;
case DEV_STATE_DISCONNECTED:
diff --git a/drivers/s390/cio/device_fsm.c b/drivers/s390/cio/device_fsm.c
index ab419d40a8a7a..b5686c25c83c7 100644
--- a/drivers/s390/cio/device_fsm.c
+++ b/drivers/s390/cio/device_fsm.c
@@ -170,6 +170,9 @@ __recover_lost_chpids(struct subchannel *sch, int old_lpm)
int mask, i;
struct chp_id chpid;
+ if (!sch->schib.pmcw.dnv)
+ return;
+
chp_id_init(&chpid);
for (i = 0; i<8; i++) {
mask = 0x80 >> i;
diff --git a/drivers/s390/cio/device_ops.c b/drivers/s390/cio/device_ops.c
index c1ba4a19368f2..f2f7f8cba410b 100644
--- a/drivers/s390/cio/device_ops.c
+++ b/drivers/s390/cio/device_ops.c
@@ -490,6 +490,8 @@ struct channel_path_desc_fmt0 *ccw_device_get_chp_desc(struct ccw_device *cdev,
struct chp_id chpid;
sch = to_subchannel(cdev->dev.parent);
+ if (!sch->schib.pmcw.dnv)
+ return NULL;
chp_id_init(&chpid);
chpid.id = sch->schib.pmcw.chpid[chp_idx];
return chp_get_chp_desc(chpid);
@@ -510,6 +512,8 @@ u8 *ccw_device_get_util_str(struct ccw_device *cdev, int chp_idx)
struct chp_id chpid;
u8 *util_str;
+ if (!sch->schib.pmcw.dnv)
+ return NULL;
chp_id_init(&chpid);
chpid.id = sch->schib.pmcw.chpid[chp_idx];
chp = chpid_to_chp(chpid);
@@ -662,6 +666,9 @@ int ccw_device_get_mdc(struct ccw_device *cdev, u8 mask)
struct chp_id chpid;
int mdc = 0, i;
+ if (!sch->schib.pmcw.dnv)
+ return 0;
+
/* Adjust requested path mask to excluded varied off paths. */
if (mask)
mask &= sch->lpm;
@@ -798,6 +805,8 @@ int ccw_device_get_chpid(struct ccw_device *cdev, int chp_idx, u8 *chpid)
if ((chp_idx < 0) || (chp_idx > 7))
return -EINVAL;
+ if (!sch->schib.pmcw.dnv)
+ return -ENODEV;
mask = 0x80 >> chp_idx;
if (!(sch->schib.pmcw.pim & mask))
return -ENODEV;
diff --git a/drivers/s390/cio/vfio_ccw_fsm.c b/drivers/s390/cio/vfio_ccw_fsm.c
index 5fd94e9d5c618..9a000b0231d60 100644
--- a/drivers/s390/cio/vfio_ccw_fsm.c
+++ b/drivers/s390/cio/vfio_ccw_fsm.c
@@ -399,7 +399,7 @@ static void fsm_close(struct vfio_ccw_private *private,
spin_lock_irq(&sch->lock);
- if (!sch->schib.pmcw.ena)
+ if (!sch->schib.pmcw.dnv || !sch->schib.pmcw.ena)
goto err_unlock;
ret = cio_disable_subchannel(sch);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 063/457] netfs: Fix netfs_read_gaps() to use separate sink folios
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 062/457] s390/cio: Guard PMCW field accesses with dnv check Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 064/457] netfs, afs: Fix symlink reading Greg Kroah-Hartman
` (404 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara, Namjae Jeon, netfs, linux-cifs, linux-fsdevel,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit fc3ae66514ca5e87251f79044236e3e8babd24a3 ]
Fix netfs_read_gaps() to use separate folios rather than re-using a single
sink folio to discard the unwanted data so that cifs checksum checking sees
all the data that was fetched.
Fixes: 7f84a7b9892d ("netfs: Make netfs_read_folio() handle streaming-write pages")
Reported-by: Frank Sorenson <sorenson@redhat.com>
Closes: https://lore.kernel.org/r/a385053c-1c4a-4060-a3bb-befa007ddb33@redhat.com/
Signed-off-by: David Howells <dhowells@redhat.com>
Link: https://patch.msgid.link/3228134.1789399227@warthog.procyon.org.uk
Tested-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Paulo Alcantara <pc@manguebit.org>
cc: Paulo Alcantara <pc@manguebit.org>
cc: Namjae Jeon <linkinjeon@kernel.org>
cc: netfs@lists.linux.dev
cc: linux-cifs@vger.kernel.org
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/buffered_read.c | 34 +++++++++++++++++++---------------
1 file changed, 19 insertions(+), 15 deletions(-)
diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c
index 424df70a5c30f..105194de6e13e 100644
--- a/fs/netfs/buffered_read.c
+++ b/fs/netfs/buffered_read.c
@@ -482,15 +482,14 @@ static int netfs_read_gaps(struct file *file, struct folio *folio)
struct netfs_group *group = netfs_folio_group(folio);
struct netfs_folio *finfo = netfs_folio_info(folio);
struct netfs_inode *ctx = netfs_inode(mapping->host);
- struct folio *sink = NULL;
- struct bio_vec *bvec;
+ struct bio_vec *bvec = NULL;
unsigned int from = finfo->dirty_offset;
unsigned int to = from + finfo->dirty_len;
- unsigned int off = 0, i = 0;
+ unsigned int off = 0;
size_t flen = folio_size(folio);
size_t nr_bvec = flen / PAGE_SIZE + 2;
size_t part;
- int ret;
+ int ret, i = 0, sink_from = -1, sink_to = -1;
_enter("%lx", folio->index);
@@ -515,24 +514,23 @@ static int netfs_read_gaps(struct file *file, struct folio *folio)
if (!bvec)
goto discard;
- sink = folio_alloc(GFP_KERNEL, 0);
- if (!sink) {
- kfree(bvec);
- goto discard;
- }
-
trace_netfs_folio(folio, netfs_folio_trace_read_gaps);
- rreq->direct_bv = bvec;
- rreq->direct_bv_count = nr_bvec;
if (from > 0) {
bvec_set_folio(&bvec[i++], folio, from, 0);
off = from;
}
+ sink_from = i;
while (off < to) {
+ struct folio *sink = folio_alloc(GFP_KERNEL, 0);
+
+ if (!sink)
+ goto discard;
part = min_t(size_t, to - off, PAGE_SIZE);
- bvec_set_folio(&bvec[i++], sink, part, 0);
+ bvec_set_folio(&bvec[i], sink, part, 0);
off += part;
+ sink_to = i;
+ i++;
}
if (to < flen)
bvec_set_folio(&bvec[i++], folio, flen - to, to);
@@ -553,8 +551,10 @@ static int netfs_read_gaps(struct file *file, struct folio *folio)
folio_mark_uptodate(folio);
}
- if (sink)
- folio_put(sink);
+ if (sink_to >= 0)
+ for (; sink_from <= sink_to; sink_from++)
+ folio_put(bvec_folio(&bvec[sink_from]));
+ kfree(bvec);
folio_unlock(folio);
netfs_put_request(rreq, netfs_rreq_trace_put_return);
return ret < 0 ? ret : 0;
@@ -563,6 +563,10 @@ static int netfs_read_gaps(struct file *file, struct folio *folio)
netfs_put_failed_request(rreq);
alloc_error:
folio_unlock(folio);
+ if (sink_to >= 0)
+ for (; sink_from <= sink_to; sink_from++)
+ folio_put(bvec_folio(&bvec[sink_from]));
+ kfree(bvec);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 064/457] netfs, afs: Fix symlink reading
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 063/457] netfs: Fix netfs_read_gaps() to use separate sink folios Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 065/457] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
` (403 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paulo Alcantara, Marc Dionne,
linux-afs, netfs, linux-fsdevel, Christian Brauner (Amutable),
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit c51e89c5b5db3e1927738fad7cd18b66dde68aed ]
Fix the reading of symlinks from the cache in afs by making netfslib trim
the amount read down to i_size. The problem is that afs sets the size of
the iterator to the size of the buffer (PAGE_SIZE) so that the cache can
round the read size up to the cache's DIO size.
Note that this also impacts the reading of AFS mountpoints as they're just
stored as symlinks with an odd file mode.
Link: https://patch.msgid.link/3912795.1789489319@warthog.procyon.org.uk
Fixes: c0410adf3da6 ("afs: Fix the locking used by afs_get_link()")
Reviewed-by: Paulo Alcantara <pc@manguebit.org>
cc: Paulo Alcantara <pc@manguebit.org>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: linux-afs@lists.infradead.org
cc: netfs@lists.linux.dev
cc: linux-fsdevel@vger.kernel.org
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/netfs/read_collect.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/fs/netfs/read_collect.c b/fs/netfs/read_collect.c
index 5cf22087d2439..a94197ef01811 100644
--- a/fs/netfs/read_collect.c
+++ b/fs/netfs/read_collect.c
@@ -435,6 +435,11 @@ static void netfs_rreq_assess_single(struct netfs_io_request *rreq)
netfs_single_mark_inode_dirty(rreq->inode);
}
+ /* To do DIO, the cache has to round the size up, so we need to undo
+ * the rounding.
+ */
+ rreq->transferred = min(rreq->transferred, rreq->i_size);
+
if (rreq->iocb) {
rreq->iocb->ki_pos += rreq->transferred;
if (rreq->iocb->ki_complete) {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 065/457] fs: avoid repeated scans in evict_inodes()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 064/457] netfs, afs: Fix symlink reading Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 066/457] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
` (402 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Sun, Jan Kara,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Sun <sunjunchao@bytedance.com>
[ Upstream commit 7459c021874246c196f397686e100702f059b9e7 ]
We observed hung tasks when users attempted to unmount a filesystem
after its disk had been removed while still in use. During device
removal, fs_bdev_mark_dead() calls evict_inodes() while holding s_umount.
Each time evict_inodes() drops s_inode_list_lock to reschedule, it
restarts the walk from the head of s_inodes. With many referenced inodes
at the head of the list, these restarts repeatedly scan the same inodes
without reclaiming them. This can keep s_umount held for a long time,
blocking concurrent umount attempts and triggering hung-task reports.
Keep the current inode, already marked I_FREEING, out of the disposal
batch until s_inode_list_lock is reacquired. Resume the walk from this
inode and dispose of it in a later batch or at the end of the walk.
The zero-refcount and state checks under i_lock allow this walker to
claim the inode by setting I_FREEING and removing it from the LRU.
Other reclaimers skip the inode, leaving this walker responsible for
eviction. Only evict() removes it from s_inodes, so keeping it out of
the disposal batch ensures that it remains on the list while the lock
is dropped. After reacquiring the lock, reading its current next pointer
accounts for concurrent removal of following inodes.
The existing inode lifetime rules prohibit acquiring a reference to an
inode marked I_FREEING or I_WILL_FREE. __iget() requires its caller to
hold i_lock and establish that taking a reference is valid. Inode lookup
and igrab() check these flags under i_lock when acquiring a reference
from zero. ihold() requires an existing reference, which would keep
i_count nonzero and prevent this walker from claiming the inode. These
rules already allow iput_final() and the inode shrinker to release
i_lock after setting I_FREEING and before eviction completes.
A temporary __iget() reference would also keep the inode on the list,
but its release must preserve last-reference handling. Another user can
acquire a reference, update lazy timestamps and drop its reference while
the pin is held. If the pin becomes the last reference, dropping it with
atomic_dec_and_test() and evicting directly bypasses iput()'s lazytime
handling and can lose those timestamp updates.
Releasing the pin with iput() preserves that handling, but does not
guarantee eviction. fs_bdev_mark_dead() runs with SB_ACTIVE set, so iput()
may retain the inode in cache, whereas evict_inodes() must evict eligible
zero-reference inodes. The inode may also have been freed when iput()
returns, so the walker cannot then use it to force eviction. Using
I_FREEING preserves the existing eviction behavior without introducing
an additional last-reference transition.
The xfstests auto group passed on ext4 and XFS with known unrelated
failures excluded. No new issues were observed, and the previously
reproducible hung task no longer occurs with this patch.
Fixes: ac05fbb40062 ("inode: don't softlockup when evicting inodes")
Signed-off-by: Julian Sun <sunjunchao@bytedance.com>
Link: https://patch.msgid.link/20260915044912.3183440-1-sunjunchao@bytedance.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/inode.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/fs/inode.c b/fs/inode.c
index 95e981b4e19c9..c6b08e8c5f627 100644
--- a/fs/inode.c
+++ b/fs/inode.c
@@ -883,7 +883,6 @@ void evict_inodes(struct super_block *sb)
struct inode *inode;
LIST_HEAD(dispose);
-again:
spin_lock(&sb->s_inode_list_lock);
list_for_each_entry(inode, &sb->s_inodes, i_sb_list) {
if (icount_read_once(inode))
@@ -902,19 +901,19 @@ void evict_inodes(struct super_block *sb)
inode_state_set(inode, I_FREEING);
inode_lru_list_del(inode);
spin_unlock(&inode->i_lock);
- list_add(&inode->i_lru, &dispose);
/*
- * We can have a ton of inodes to evict at unmount time given
- * enough memory, check to see if we need to go to sleep for a
- * bit so we don't livelock.
+ * Keep this inode out of dispose so it stays on s_inodes while
+ * the list lock is dropped. I_FREEING prevents new references
+ * and leaves eviction to us, so we can resume the walk from it.
*/
if (need_resched()) {
spin_unlock(&sb->s_inode_list_lock);
cond_resched();
dispose_list(&dispose);
- goto again;
+ spin_lock(&sb->s_inode_list_lock);
}
+ list_add(&inode->i_lru, &dispose);
}
spin_unlock(&sb->s_inode_list_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 066/457] xsk: Use a 32-bit compare in xsk_map_gen_lookup
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 065/457] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 067/457] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
` (401 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou,
Alexei Starovoitov, Emil Tsalapatis, Eduard Zingerman,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
[ Upstream commit 70504de0bb627848667207bec7ccfd647deb8814 ]
xsk_map_gen_lookup() loads a u32 key and compares it with max_entries
using BPF_JMP_IMM. BPF immediates are sign-extended to 64 bits, so a
max_entries value of 0x80000000 or higher becomes a threshold larger
than every zero-extended 32-bit key. An out-of-range index then skips
the bounds check and the generated lookup reads past xsk_map[].
Compare with BPF_JMP32_IMM so the check stays in 32-bit unsigned range.
Fixes: e65650f291ee ("bpf: Implement map_gen_lookup() callback for XSKMAP")
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://patch.msgid.link/7d2cb8e8dfaa9eb8fdff85156987a60960787dc3.1789056660.git.zhilinz@nebusec.ai
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xdp/xskmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/xdp/xskmap.c b/net/xdp/xskmap.c
index 3bff346308d0f..bf00d6463c191 100644
--- a/net/xdp/xskmap.c
+++ b/net/xdp/xskmap.c
@@ -124,7 +124,7 @@ static int xsk_map_gen_lookup(struct bpf_map *map, struct bpf_insn *insn_buf)
struct bpf_insn *insn = insn_buf;
*insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0);
- *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 5);
+ *insn++ = BPF_JMP32_IMM(BPF_JGE, ret, map->max_entries, 5);
*insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(sizeof(struct xsk_sock *)));
*insn++ = BPF_ALU64_IMM(BPF_ADD, mp, offsetof(struct xsk_map, xsk_map));
*insn++ = BPF_ALU64_REG(BPF_ADD, ret, mp);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 067/457] bpf: Skip unsettled links in link iterator
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 066/457] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 068/457] eth: fbnic: Fix payload page pool error cleanup Greg Kroah-Hartman
` (400 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Andrii Nakryiko, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 50e80e2bb5e2be8515205b9c496b9640ddefa434 ]
bpf_link_prime() inserts a link into link_idr before anon_inode_getfile()
succeeds and before bpf_link_settle() publishes the ID in link->id.
bpf_link_by_id() treats such an ID-zero link as unsettled, but the link
iterator takes a reference without this check.
If anon_inode_getfile() then fails, the creator removes the ID and frees
its still-private link directly. The iterator is left with a dangling
reference and its next bpf_link_put() accesses freed memory.
Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as
bpf_link_by_id() does.
BUG: KASAN: slab-use-after-free in bpf_link_put
Write of size 8 by task exp/384
Call Trace:
bpf_link_put kernel/bpf/syscall.c:3372
bpf_link_seq_next kernel/bpf/link_iter.c:33
bpf_seq_read kernel/bpf/bpf_iter.c:158
vfs_read fs/read_write.c:572
ksys_read fs/read_write.c:716
do_syscall_64 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Fixes: 9f8836127308 ("bpf: Add bpf_link iterator")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260914170206.170723-2-bestswngs@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/syscall.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index 57d61de03306e..77b3252270f3e 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -6106,7 +6106,10 @@ struct bpf_link *bpf_link_get_curr_or_next(u32 *id)
again:
link = idr_get_next(&link_idr, id);
if (link) {
- link = bpf_link_inc_not_zero(link);
+ if (link->id)
+ link = bpf_link_inc_not_zero(link);
+ else
+ link = ERR_PTR(-EAGAIN);
if (IS_ERR(link)) {
(*id)++;
goto again;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 068/457] eth: fbnic: Fix payload page pool error cleanup
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 067/457] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 069/457] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
` (399 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Björn Töpel,
Simon Horman, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Björn Töpel <bjorn@kernel.org>
[ Upstream commit 8e0b235bd918d06f54ba8fddd2c3ddc36ca59c15 ]
The payload page pool pointer contains an error pointer when its
allocation fails. The cleanup path passes that error pointer to
page_pool_destroy() instead of destroying the header page pool. This
can dereference the error pointer and leave the header page pool
allocated.
Destroy the header page pool instead.
Fixes: 8a11010fdd96 ("eth: fbnic: allocate unreadable page pool for the payloads")
Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
Link: https://lore.kernel.org/netdev/178915061000.219967.7726187707862333281@kernel.org/
Signed-off-by: Björn Töpel <bjorn@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915104917.3978113-1-bjorn@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
index e7918d3f6aba9..661dee1661afe 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
@@ -1622,7 +1622,7 @@ fbnic_alloc_qt_page_pools(struct fbnic_net *fbn, struct fbnic_q_triad *qt,
return 0;
err_destroy_sub0:
- page_pool_destroy(pp);
+ page_pool_destroy(qt->sub0.page_pool);
return PTR_ERR(pp);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 069/457] net/sched: cls_u32: fix manual hash table handle IDR aliasing
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 068/457] eth: fbnic: Fix payload page pool error cleanup Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 070/457] net: pcs: rzn1-miic: Fix config array initialization Greg Kroah-Hartman
` (398 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini + nipa),
Victor Nogueira, hybris, Jamal Hadi Salim, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 0a5f5d9e94dead312d32c366b917c64e552b72f7 ]
A u32 hash table created with an explicit handle ('tc filter add ...
handle 801: u32 divisor N') keys its IDR entry on the raw handle, while
the destroy paths free it under handle2id(handle). The two key domains
disagree for handles in the 0x800..0xFFF htid range:
handle2id() folds them back into the auto-allocated id space (1..0x7FF).
A manual table therefore leaves its raw-keyed IDR entry unreachable on
delete (a permanent leak), and its delete can drop the idr entry of an
unrelated live auto table. A later auto allocation can then hand out a
handle that aliases the live manual table; u32_lookup_ht() first-match
routes lookups and TCA_U32_LINK for that htid to the wrong table.
Key the divisor-path alloc on handle2id(handle) so allocation and
removal share one key domain. A manual handle that maps onto an id
already in use is rejected with -ENOSPC, and auto allocation skips ids
held by live manual tables.
Conditions to recreate:
ip link add test0 type dummy
tc qdisc add dev test0 clsact
tc filter add dev test0 ingress protocol ip pref 1 \
handle 801: u32 divisor 16
tc filter add dev test0 ingress protocol ip pref 2 u32 divisor 16
tc -d filter show dev test0 ingress | grep 'fh 801:'
# unpatched: two live tables with handle 0x80100000 (the pref 2 root
# hnode is auto-allocated id 1); patched: the auto hnode takes id 2.
Also tested with a poc with a live u32 table on the block, add/delete a manual
table 'handle 901: u32 divisor 1' twice; unpatched, the re-add fails with
-ENOSPC because the raw key leaked on the first delete.
Fixes: 73af53d82076 ("net: sched: cls_u32: Fix u32's systematic failure to free IDR entries for hnodes.")
Reported-by: Sashiko (gemini + nipa) <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260822222049.114526-1-jhs@mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/QDISC-LQFE.v1.20260911041746.1@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/cls_u32.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/sched/cls_u32.c b/net/sched/cls_u32.c
index a3e65c8cf29ef..76ce2d124079d 100644
--- a/net/sched/cls_u32.c
+++ b/net/sched/cls_u32.c
@@ -1003,8 +1003,16 @@ static int u32_change(struct net *net, struct sk_buff *in_skb,
return -ENOMEM;
}
} else {
- err = idr_alloc_u32(&tp_c->handle_idr, ht, &handle,
- handle, GFP_KERNEL);
+ /* The IDR is keyed on the mapped id, and that is
+ * what the destroy paths remove. Ask for it here,
+ * so a manual handle colliding with the
+ * auto-allocated id space is rejected (-ENOSPC)
+ * instead of aliasing a future auto id.
+ */
+ u32 id = handle2id(handle);
+
+ err = idr_alloc_u32(&tp_c->handle_idr, ht, &id, id,
+ GFP_KERNEL);
if (err) {
kfree(ht);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 070/457] net: pcs: rzn1-miic: Fix config array initialization
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 069/457] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 071/457] octeontx2-af: use seq_file for rsrc_alloc debugfs Greg Kroah-Hartman
` (397 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven, Kyle Hendry,
Lad Prabhakar, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Hendry <khendry@reliablecontrols.com>
[ Upstream commit daf677c2c6449011ee695d55b48b5b2977a36f88 ]
Fix memset parameters to initialize the entire DT value array
Fixes: f39e968dc168a7bd ("net: pcs: rzn1-miic: Move configuration data to SoC-specific struct")
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Kyle Hendry <khendry@reliablecontrols.com>
Reviewed-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Link: https://patch.msgid.link/20260915-rzn1-miic-fix-array-v5-1-b7173fd5b97d@reliablecontrols.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/pcs/pcs-rzn1-miic.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/pcs/pcs-rzn1-miic.c b/drivers/net/pcs/pcs-rzn1-miic.c
index 2b72fa98ddf13..cb74861e823c8 100644
--- a/drivers/net/pcs/pcs-rzn1-miic.c
+++ b/drivers/net/pcs/pcs-rzn1-miic.c
@@ -683,7 +683,8 @@ static int miic_parse_dt(struct miic *miic, u32 *mode_cfg)
if (!dt_val)
return -ENOMEM;
- memset(dt_val, MIIC_MODCTRL_CONF_NONE, sizeof(*dt_val));
+ memset(dt_val, MIIC_MODCTRL_CONF_NONE,
+ sizeof(*dt_val) * miic->of_data->conf_conv_count);
if (of_property_read_u32(np, "renesas,miic-switch-portin", &conf) == 0)
dt_val[0] = conf;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 071/457] octeontx2-af: use seq_file for rsrc_alloc debugfs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 070/457] net: pcs: rzn1-miic: Fix config array initialization Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 072/457] net/mlx5: devcom, Base component size on linked devices Greg Kroah-Hartman
` (396 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Heyang Tan, Ratheesh Kannoth,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heyang Tan <thy15333007817@163.com>
[ Upstream commit 39c6580765dad6477fb2637f6f616e0d276aae65 ]
The rsrc_alloc debugfs reader writes rows directly to userspace without
respecting the caller's read count. It also uses the current row length as
the userspace stride, which can corrupt output when rows have different
widths.
Use seq_file to handle userspace buffer sizes, offsets, and partial reads,
and write output columns directly to the seq_file buffer.
Fixes: 23205e6d06d4 ("octeontx2-af: Dump current resource provisioning status")
Signed-off-by: Heyang Tan <thy15333007817@163.com>
Reviewed-by: Ratheesh Kannoth <rkannoth@marvell.com>
Link: https://patch.msgid.link/20260914020521.146-1-thy15333007817@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../marvell/octeontx2/af/rvu_debugfs.c | 104 ++++++------------
1 file changed, 33 insertions(+), 71 deletions(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
index 904374baae6f3..2927633465d96 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
+++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_debugfs.c
@@ -714,110 +714,72 @@ static int get_max_column_width(struct rvu *rvu)
}
/* Dumps current provisioning status of all RVU block LFs */
-static ssize_t rvu_dbg_rsrc_attach_status(struct file *filp,
- char __user *buffer,
- size_t count, loff_t *ppos)
+static int rvu_dbg_rsrc_attach_status(struct seq_file *filp, void *unused)
{
- int index, off = 0, flag = 0, len = 0, i = 0;
- struct rvu *rvu = filp->private_data;
- int bytes_not_copied = 0;
+ struct rvu *rvu = filp->private;
+ int index, pf, vf, pcifunc;
struct rvu_block block;
- int pf, vf, pcifunc;
- int buf_size = 2048;
int lf_str_size;
char *lfs;
- char *buf;
-
- /* don't allow partial reads */
- if (*ppos != 0)
- return 0;
-
- buf = kzalloc(buf_size, GFP_KERNEL);
- if (!buf)
- return -ENOMEM;
- /* Get the maximum width of a column */
lf_str_size = get_max_column_width(rvu);
+ if (lf_str_size < 0)
+ return lf_str_size;
lfs = kzalloc(lf_str_size, GFP_KERNEL);
- if (!lfs) {
- kfree(buf);
+ if (!lfs)
return -ENOMEM;
- }
- off += scnprintf(&buf[off], buf_size - 1 - off, "%-*s", lf_str_size,
- "pcifunc");
- for (index = 0; index < BLK_COUNT; index++)
- if (strlen(rvu->hw->block[index].name)) {
- off += scnprintf(&buf[off], buf_size - 1 - off,
- "%-*s", lf_str_size,
- rvu->hw->block[index].name);
- }
- off += scnprintf(&buf[off], buf_size - 1 - off, "\n");
- bytes_not_copied = copy_to_user(buffer + (i * off), buf, off);
- if (bytes_not_copied)
- goto out;
+ seq_printf(filp, "%-*s", lf_str_size, "pcifunc");
+ for (index = 0; index < BLK_COUNT; index++)
+ if (strlen(rvu->hw->block[index].name))
+ seq_printf(filp, "%-*s", lf_str_size,
+ rvu->hw->block[index].name);
- i++;
- *ppos += off;
+ seq_putc(filp, '\n');
for (pf = 0; pf < rvu->hw->total_pfs; pf++) {
for (vf = 0; vf <= rvu->hw->total_vfs; vf++) {
- off = 0;
- flag = 0;
pcifunc = rvu_make_pcifunc(rvu->pdev, pf, vf);
if (!pcifunc)
continue;
- if (vf) {
+ for (index = 0; index < BLK_COUNT; index++) {
+ block = rvu->hw->block[index];
+ if (!strlen(block.name))
+ continue;
+ lfs[0] = '\0';
+ get_lf_str_list(&block, pcifunc, lfs);
+ if (strlen(lfs))
+ break;
+ }
+ if (index == BLK_COUNT)
+ continue;
+
+ if (vf)
sprintf(lfs, "PF%d:VF%d", pf, vf - 1);
- off = scnprintf(&buf[off],
- buf_size - 1 - off,
- "%-*s", lf_str_size, lfs);
- } else {
+ else
sprintf(lfs, "PF%d", pf);
- off = scnprintf(&buf[off],
- buf_size - 1 - off,
- "%-*s", lf_str_size, lfs);
- }
+ seq_printf(filp, "%-*s", lf_str_size, lfs);
for (index = 0; index < BLK_COUNT; index++) {
block = rvu->hw->block[index];
if (!strlen(block.name))
continue;
- len = 0;
- lfs[len] = '\0';
- get_lf_str_list(&block, pcifunc, lfs);
- if (strlen(lfs))
- flag = 1;
- off += scnprintf(&buf[off], buf_size - 1 - off,
- "%-*s", lf_str_size, lfs);
- }
- if (flag) {
- off += scnprintf(&buf[off],
- buf_size - 1 - off, "\n");
- bytes_not_copied = copy_to_user(buffer +
- (i * off),
- buf, off);
- if (bytes_not_copied)
- goto out;
-
- i++;
- *ppos += off;
+ lfs[0] = '\0';
+ get_lf_str_list(&block, pcifunc, lfs);
+ seq_printf(filp, "%-*s", lf_str_size, lfs);
}
+ seq_putc(filp, '\n');
}
}
-out:
kfree(lfs);
- kfree(buf);
- if (bytes_not_copied)
- return -EFAULT;
- return *ppos;
+ return 0;
}
-RVU_DEBUG_FOPS(rsrc_status, rsrc_attach_status, NULL);
+RVU_DEBUG_SEQ_FOPS(rsrc_status, rsrc_attach_status, NULL);
static int rvu_dbg_rvu_pf_cgx_map_display(struct seq_file *filp, void *unused)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 072/457] net/mlx5: devcom, Base component size on linked devices
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 071/457] octeontx2-af: use seq_file for rsrc_alloc debugfs Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 073/457] net/mlx5: SD, unload reps on shared FDB create error path Greg Kroah-Hartman
` (395 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shay Drory, Akiva Goldberger,
Tariq Toukan, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shay Drory <shayd@nvidia.com>
[ Upstream commit d09e8f64653c93da5793c16be19330968f2a32e6 ]
mlx5_devcom_comp_get_size() returns the component's kref count. That
kref is bumped in mlx5_devcom_register_component() under comp_list_lock,
before the comp_dev is linked onto comp_dev_list_head under comp->sem.
The event broadcast (mlx5_devcom_locked_send_event()) walks that list.
Hence, a caller can read the expected size, but send_event won't be sent
to all peers. In the SD group registration path, this lets a member
broadcast its role-election event over an incomplete list, electing a
primary that never completes the group, is never marked ready, and
leaves the group with a stale primary.
Track the number of linked comp_devs in a dedicated counter, maintained
under comp->sem together with the list add/remove, and return it from
mlx5_devcom_comp_get_size().
Fixes: 9bb1ac80738a ("net/mlx5: devcom, Add component size getter")
Signed-off-by: Shay Drory <shayd@nvidia.com>
Reviewed-by: Akiva Goldberger <agoldberger@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260915113459.3934760-2-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/lib/devcom.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/devcom.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/devcom.c
index 64f92427602de..75855481522b1 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lib/devcom.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/devcom.c
@@ -37,6 +37,7 @@ struct mlx5_devcom_comp {
struct mlx5_devcom_key key;
mlx5_devcom_event_handler_t handler;
struct kref ref;
+ int nr_devs;
bool ready;
struct rw_semaphore sem;
struct lock_class_key lock_key;
@@ -170,6 +171,7 @@ devcom_alloc_comp_dev(struct mlx5_devcom_dev *devc,
down_write(&comp->sem);
list_add_tail(&devcom->list, &comp->comp_dev_list_head);
+ WRITE_ONCE(comp->nr_devs, comp->nr_devs + 1);
up_write(&comp->sem);
return devcom;
@@ -182,6 +184,7 @@ devcom_free_comp_dev(struct mlx5_devcom_comp_dev *devcom)
down_write(&comp->sem);
list_del(&devcom->list);
+ WRITE_ONCE(comp->nr_devs, comp->nr_devs - 1);
up_write(&comp->sem);
kref_put(&devcom->devc->ref, mlx5_devcom_dev_release);
@@ -284,7 +287,7 @@ int mlx5_devcom_comp_get_size(struct mlx5_devcom_comp_dev *devcom)
{
struct mlx5_devcom_comp *comp = devcom->comp;
- return kref_read(&comp->ref);
+ return READ_ONCE(comp->nr_devs);
}
int mlx5_devcom_locked_send_event(struct mlx5_devcom_comp_dev *devcom,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 073/457] net/mlx5: SD, unload reps on shared FDB create error path
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 072/457] net/mlx5: devcom, Base component size on linked devices Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 074/457] net/mlx5: LAG, reload IB reps of LAG master before the rest Greg Kroah-Hartman
` (394 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shay Drory, Akiva Goldberger,
Tariq Toukan, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shay Drory <shayd@nvidia.com>
[ Upstream commit e1e29ada2b938b13ba689a06a8bd8604564da2b3 ]
mlx5_lag_shared_fdb_create() sets sd_fdb_active on every group member
before reloading the representors, so mlx5_lag_is_active() is already
true and the guard in mlx5_esw_offloads_rep_load() does not skip the
VF/SF reps. If the reload then fails, the error path clears
sd_fdb_active and destroys the shared FDB, leaving the reps loaded
while SD LAG is inactive - the state cited commit was written
to prevent.
Unload the reps in the error path as well.
Fixes: 68c2dd59a6c7 ("net/mlx5: E-Switch, Tie rep load/unload to SD LAG state")
Signed-off-by: Shay Drory <shayd@nvidia.com>
Reviewed-by: Akiva Goldberger <agoldberger@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260915113459.3934760-3-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c b/drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c
index 6b4ad3c53f2f3..424040918fa37 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c
@@ -270,6 +270,7 @@ int mlx5_lag_shared_fdb_create(struct mlx5_lag *ldev,
pf->sd_fdb_active = false;
}
mlx5_lag_destroy_single_fdb_filter(ldev, group_id);
+ mlx5_lag_unload_reps_from_locked(ldev, filter);
}
err_add_devices:
mlx5_lag_add_devices_filter(ldev, filter);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 074/457] net/mlx5: LAG, reload IB reps of LAG master before the rest
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 073/457] net/mlx5: SD, unload reps on shared FDB create error path Greg Kroah-Hartman
@ 2026-09-30 15:22 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 075/457] bpf: Make post-verification instruction rewrites killable Greg Kroah-Hartman
` (393 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:22 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shay Drory, Akiva Goldberger,
Tariq Toukan, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shay Drory <shayd@nvidia.com>
[ Upstream commit bae23d1ae62092c7f0ec6d5f7e1be5d164822638 ]
In a shared-FDB LAG the master device creates the bond IB device; the
other LAG members do not create their own, they populate a port inside
the master's IB device. mlx5_lag_reload_ib_reps_unlocked() reloaded the
members' IB reps in iteration order, with no guarantee the master is
reloaded first. When a non-master member is reloaded before the master,
it tries to populate its port in an IB device that has not been
recreated yet.
Hence, reload the master's IB reps first, then every other member.
Fixes: 2b204cdb1206 ("net/mlx5: LAG, use xa_alloc to manage LAG device indices")
Signed-off-by: Shay Drory <shayd@nvidia.com>
Reviewed-by: Akiva Goldberger <agoldberger@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260915113459.3934760-4-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/mellanox/mlx5/core/lag/lag.c | 44 ++++++++++++++-----
1 file changed, 32 insertions(+), 12 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
index c655f6e32e9b0..dd14cdc378de0 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
@@ -1266,25 +1266,45 @@ void mlx5_lag_remove_devices(struct mlx5_lag *ldev)
mlx5_lag_remove_devices_filter(ldev, MLX5_LAG_FILTER_PORTS);
}
+static int mlx5_lag_reload_ib_reps_idx(struct mlx5_lag *ldev, int idx,
+ u32 flags)
+{
+ struct lag_func *pf = mlx5_lag_pf(ldev, idx);
+ struct mlx5_eswitch *esw;
+ int ret;
+
+ if (pf->dev->priv.flags & flags)
+ return 0;
+
+ esw = pf->dev->priv.eswitch;
+ mlx5_esw_reps_block(esw);
+ ret = mlx5_eswitch_reload_ib_reps(esw);
+ mlx5_esw_reps_unblock(esw);
+
+ return ret;
+}
+
static int mlx5_lag_reload_ib_reps_unlocked(struct mlx5_lag *ldev, u32 flags,
u32 filter, bool cont_on_fail)
{
- struct lag_func *pf;
+ int master_idx = mlx5_lag_get_dev_index_by_seq_filter(ldev, MLX5_LAG_P1,
+ filter);
int ret;
int i;
+ if (master_idx < 0)
+ return -EINVAL;
+
+ ret = mlx5_lag_reload_ib_reps_idx(ldev, master_idx, flags);
+ if (ret && !cont_on_fail)
+ return ret;
+
mlx5_lag_for_each(i, 0, ldev, filter) {
- pf = mlx5_lag_pf(ldev, i);
- if (!(pf->dev->priv.flags & flags)) {
- struct mlx5_eswitch *esw;
-
- esw = pf->dev->priv.eswitch;
- mlx5_esw_reps_block(esw);
- ret = mlx5_eswitch_reload_ib_reps(esw);
- mlx5_esw_reps_unblock(esw);
- if (ret && !cont_on_fail)
- return ret;
- }
+ if (i == master_idx)
+ continue;
+ ret = mlx5_lag_reload_ib_reps_idx(ldev, i, flags);
+ if (ret && !cont_on_fail)
+ return ret;
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 075/457] bpf: Make post-verification instruction rewrites killable
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-30 15:22 ` [PATCH 7.2 074/457] net/mlx5: LAG, reload IB reps of LAG master before the rest Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 076/457] bpf: Preserve packet pointer class displacement in regsafe() Greg Kroah-Hartman
` (392 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini,
Kumar Kartikeya Dwivedi, Eduard Zingerman, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 261b61d3735b042ae25634f795c4540be0fc140c ]
After do_check() returns, the verifier runs several instruction rewrite
passes. Some of them patch or remove one instruction at a time. Each
operation moves the remaining instruction and auxiliary-data arrays and
adjusts all branch offsets, making the overall work quadratic in the
program length.
A privileged loader can submit 131072 unconditional jumps by zero followed
by a valid return. Verification finishes quickly, but bpf_opt_remove_nops()
then spends a long time removing each jump separately. Since this
post-verification work neither checks for signals nor reschedules, a pending
SIGKILL cannot terminate the task until the rewrite finishes.
Make bpf_patch_insn_data() and verifier_remove_insns() common cancellation
and rescheduling points. These helpers run from BPF_PROG_LOAD process
context, and bpf_patch_insn_data() can already sleep while reallocating
auxiliary data.
Report interrupted constant blinding as -EINTR and propagate it through
both JIT paths, including kernels that permit interpreter fallback.
Other blinding failures retain the existing fallback behavior.
This does not reduce the quadratic cost of the rewrite passes, but it makes
the work preemptible and allows a killed loader to be torn down promptly.
Fixes: 52875a04f4b2 ("bpf: verifier: remove dead code")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260917233222.2542500-2-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/core.c | 21 +++++++++++++++++----
kernel/bpf/fixups.c | 24 ++++++++++++++++++++++--
2 files changed, 39 insertions(+), 6 deletions(-)
diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
index 883cb7a800b17..71ee96a77ae26 100644
--- a/kernel/bpf/core.c
+++ b/kernel/bpf/core.c
@@ -19,6 +19,7 @@
#include <uapi/linux/btf.h>
#include <linux/filter.h>
+#include <linux/sched/signal.h>
#include <linux/skbuff.h>
#include <linux/static_call.h>
#include <linux/vmalloc.h>
@@ -1612,6 +1613,8 @@ struct bpf_prog *bpf_jit_blind_constants(struct bpf_verifier_env *env, struct bp
* fix it up here on error.
*/
bpf_jit_prog_release_other(prog, clone);
+ if (env && fatal_signal_pending(current))
+ return ERR_PTR(-EINTR);
return IS_ERR(tmp) ? tmp : ERR_PTR(-ENOMEM);
}
@@ -2641,11 +2644,14 @@ static struct bpf_prog *bpf_prog_jit_compile(struct bpf_verifier_env *env, struc
orig_prog = prog;
prog = bpf_jit_blind_constants(env, prog);
/*
- * If blinding was requested and we failed during blinding, we must fall
- * back to the interpreter.
+ * Fall back to the interpreter after blinding failures, except when
+ * the loader was killed.
*/
- if (IS_ERR(prog))
+ if (IS_ERR(prog)) {
+ if (PTR_ERR(prog) == -EINTR)
+ return prog;
goto out_restore;
+ }
prog = bpf_int_jit_compile(env, prog);
if (prog->jited) {
@@ -2668,6 +2674,8 @@ static struct bpf_prog *bpf_prog_jit_compile(struct bpf_verifier_env *env, struc
struct bpf_prog *__bpf_prog_select_runtime(struct bpf_verifier_env *env, struct bpf_prog *fp,
int *err)
{
+ struct bpf_prog *jit_prog;
+
/* In case of BPF to BPF calls, verifier did all the prep
* work with regards to JITing, etc.
*/
@@ -2690,7 +2698,12 @@ struct bpf_prog *__bpf_prog_select_runtime(struct bpf_verifier_env *env, struct
if (*err)
return fp;
- fp = bpf_prog_jit_compile(env, fp);
+ jit_prog = bpf_prog_jit_compile(env, fp);
+ if (IS_ERR(jit_prog)) {
+ *err = PTR_ERR(jit_prog);
+ return fp;
+ }
+ fp = jit_prog;
bpf_prog_jit_attempt_done(fp);
if (!fp->jited && jit_needed) {
*err = -ENOTSUPP;
diff --git a/kernel/bpf/fixups.c b/kernel/bpf/fixups.c
index 48acb61854ed4..19c1b8f1b317c 100644
--- a/kernel/bpf/fixups.c
+++ b/kernel/bpf/fixups.c
@@ -8,6 +8,7 @@
#include <linux/bsearch.h>
#include <linux/sort.h>
#include <linux/perf_event.h>
+#include <linux/sched/signal.h>
#include <net/xdp.h>
#include "disasm.h"
@@ -240,12 +241,28 @@ static void adjust_poke_descs(struct bpf_prog *prog, u32 off, u32 len)
}
}
+/*
+ * Some post-verification instruction rewriting passes require an
+ * O(prog->len) operation per instruction. Keep their shared primitives
+ * killable and preemptible.
+ */
+static bool bpf_rewrite_must_abort(void)
+{
+ if (fatal_signal_pending(current))
+ return true;
+ cond_resched();
+ return false;
+}
+
struct bpf_prog *bpf_patch_insn_data(struct bpf_verifier_env *env, u32 off,
const struct bpf_insn *patch, u32 len)
{
struct bpf_prog *new_prog;
struct bpf_insn_aux_data *new_data = NULL;
+ if (bpf_rewrite_must_abort())
+ return NULL;
+
if (len > 1) {
new_data = vrealloc(env->insn_aux_data,
array_size(env->prog->len + len - 1,
@@ -457,6 +474,9 @@ static int verifier_remove_insns(struct bpf_verifier_env *env, u32 off, u32 cnt)
unsigned int orig_prog_len = env->prog->len;
int err;
+ if (bpf_rewrite_must_abort())
+ return -EINTR;
+
if (bpf_prog_is_offloaded(env->prog->aux))
bpf_prog_offload_remove_insns(env, off, cnt);
@@ -1316,7 +1336,7 @@ int bpf_jit_subprogs(struct bpf_verifier_env *env)
}
prog = bpf_jit_blind_constants(env, prog);
if (IS_ERR(prog)) {
- err = -ENOMEM;
+ err = PTR_ERR(prog);
prog = orig_prog;
goto out_restore;
}
@@ -1395,7 +1415,7 @@ int bpf_fixup_call_args(struct bpf_verifier_env *env)
err = bpf_jit_subprogs(env);
if (err == 0)
return 0;
- if (err == -EFAULT)
+ if (err == -EFAULT || err == -EINTR)
return err;
}
#ifndef CONFIG_BPF_JIT_ALWAYS_ON
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 076/457] bpf: Preserve packet pointer class displacement in regsafe()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 075/457] bpf: Make post-verification instruction rewrites killable Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 077/457] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
` (391 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini,
Kumar Kartikeya Dwivedi, Eduard Zingerman, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit fd16449a9b3b31a8f18944c2f0e29e4e218ca2cf ]
regsafe() maps packet pointer IDs between states and checks that each
current register range is a subset of the corresponding explored
register range. It does not, however, preserve the displacement between
registers that share a packet pointer ID.
This is unsound because packet range is shared by ID. A bounds check on
one class member updates every member, and a later access can consume the
range through another member. Commit 022ac0750883 ("bpf: use reg->var_off
instead of reg->off for pointers") folded the fixed pointer offset into
r64 and removed the old off equality check, so two individually narrower
registers can prune even when their displacement has changed. The
explored path can then license an out-of-bounds packet access on the
pruned path.
Require matching range bases for packet pointers with an ID. Together
with the existing ID mapping, this preserves the displacement between
members of each packet-pointer class without adding per-ID state.
Packet pointers without an ID remain unaffected.
Fixes: 022ac0750883 ("bpf: use reg->var_off instead of reg->off for pointers")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260917233222.2542500-3-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/states.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/kernel/bpf/states.c b/kernel/bpf/states.c
index 66fb11b6c6a76..6c88ad95b63b7 100644
--- a/kernel/bpf/states.c
+++ b/kernel/bpf/states.c
@@ -635,6 +635,9 @@ static bool regsafe(struct bpf_verifier_env *env, struct bpf_reg_state *rold,
/* id relations must be preserved */
if (!check_ids(rold->id, rcur->id, idmap))
return false;
+ /* Preserve displacements between pointers sharing an ID. */
+ if (rold->id && rold->r64.base != rcur->r64.base)
+ return false;
/* new val must satisfy old val knowledge */
return range_within(rold, rcur) &&
tnum_in(rold->var_off, rcur->var_off);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 077/457] bpf: Restrict CO-RE poisoning to relocatable instructions
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 076/457] bpf: Preserve packet pointer class displacement in regsafe() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 078/457] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
` (390 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini,
Kumar Kartikeya Dwivedi, Eduard Zingerman, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 394ae398337c5f87e567f6cd63b937fc2b2f6ddc ]
CO-RE relocation records can name any instruction offset. When a
relocation cannot be resolved, bpf_core_patch_insn() currently poisons its
target before checking whether that instruction is a valid relocation
target. Malformed metadata can therefore replace jumps, calls, exits,
register-source arithmetic, or non-immediate loads instead of failing at
the relocation step.
Handle poisoning only after the instruction has passed the same class and
operand-form checks used for a resolved relocation. Route invalid forms
through the existing diagnostic and return a hard error. Keep poisoning
supported instructions, including both halves of a plain ldimm64, so an
unresolved relocation in dead code remains valid.
Extend bpf_core_poison_insn() to poison both halves of ldimm64, and return
its status directly from each validated instruction case. This avoids
routing the success path through a common label and leaves the helper free
to report errors.
The shared relocation code applies this restriction to both libbpf and
in-kernel CO-RE.
Fixes: d7a252708dbc ("libbpf: Improve handling of failed CO-RE relocations")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260917233222.2542500-7-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/relo_core.c | 58 +++++++++++++++++++++------------------
1 file changed, 31 insertions(+), 27 deletions(-)
diff --git a/tools/lib/bpf/relo_core.c b/tools/lib/bpf/relo_core.c
index 6ae3f2a15ad0c..4755de3f99957 100644
--- a/tools/lib/bpf/relo_core.c
+++ b/tools/lib/bpf/relo_core.c
@@ -980,23 +980,30 @@ static int bpf_core_calc_relo(const char *prog_name,
}
/*
- * Turn instruction for which CO_RE relocation failed into invalid one with
+ * Turn instruction for which CO-RE relocation failed into invalid one with
* distinct signature.
*/
-static void bpf_core_poison_insn(const char *prog_name, int relo_idx,
- int insn_idx, struct bpf_insn *insn)
+static int bpf_core_poison_insn(const char *prog_name, int relo_idx,
+ struct bpf_insn *insn, int insn_idx)
{
- pr_debug("prog '%s': relo #%d: substituting insn #%d w/ invalid insn\n",
- prog_name, relo_idx, insn_idx);
- insn->code = BPF_JMP | BPF_CALL;
- insn->dst_reg = 0;
- insn->src_reg = 0;
- insn->off = 0;
- /* if this instruction is reachable (not a dead code),
- * verifier will complain with the following message:
- * invalid func unknown#195896080
- */
- insn->imm = 195896080; /* => 0xbad2310 => "bad relo" */
+ int insn_cnt = is_ldimm64_insn(insn) ? 2 : 1;
+ int i;
+
+ for (i = 0; i < insn_cnt; i++) {
+ pr_debug("prog '%s': relo #%d: substituting insn #%d w/ invalid insn\n",
+ prog_name, relo_idx, insn_idx + i);
+ insn[i].code = BPF_JMP | BPF_CALL;
+ insn[i].dst_reg = 0;
+ insn[i].src_reg = 0;
+ insn[i].off = 0;
+ /*
+ * If this instruction is reachable (not dead code), the verifier
+ * will complain with "invalid func unknown#195896080".
+ */
+ insn[i].imm = 195896080; /* => 0xbad2310 => "bad relo" */
+ }
+
+ return 0;
}
static int insn_bpf_size_to_bytes(struct bpf_insn *insn)
@@ -1047,17 +1054,6 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
class = BPF_CLASS(insn->code);
- if (res->poison) {
-poison:
- /* poison second part of ldimm64 to avoid confusing error from
- * verifier about "unknown opcode 00"
- */
- if (is_ldimm64_insn(insn))
- bpf_core_poison_insn(prog_name, relo_idx, insn_idx + 1, insn + 1);
- bpf_core_poison_insn(prog_name, relo_idx, insn_idx, insn);
- return 0;
- }
-
orig_val = res->orig_val;
new_val = res->new_val;
@@ -1065,7 +1061,9 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
case BPF_ALU:
case BPF_ALU64:
if (BPF_SRC(insn->code) != BPF_K)
- return -EINVAL;
+ goto bad_insn;
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
if (res->validate && insn->imm != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (ALU/ALU64) value: got %u, exp %llu -> %llu\n",
prog_name, relo_idx,
@@ -1082,6 +1080,8 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
case BPF_LDX:
case BPF_ST:
case BPF_STX:
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
if (res->validate && insn->off != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (LDX/ST/STX) value: got %u, exp %llu -> %llu\n",
prog_name, relo_idx, insn_idx, insn->off, (unsigned long long)orig_val,
@@ -1097,7 +1097,7 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
pr_warn("prog '%s': relo #%d: insn #%d (LDX/ST/STX) accesses field incorrectly. "
"Make sure you are accessing pointers, unsigned integers, or fields of matching type and size.\n",
prog_name, relo_idx, insn_idx);
- goto poison;
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
}
orig_val = insn->off;
@@ -1140,6 +1140,9 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
return -EINVAL;
}
+ if (res->poison)
+ return bpf_core_poison_insn(prog_name, relo_idx, insn, insn_idx);
+
imm = (__u32)insn[0].imm | ((__u64)insn[1].imm << 32);
if (res->validate && imm != orig_val) {
pr_warn("prog '%s': relo #%d: unexpected insn #%d (LDIMM64) value: got %llu, exp %llu -> %llu\n",
@@ -1157,6 +1160,7 @@ int bpf_core_patch_insn(const char *prog_name, struct bpf_insn *insn,
break;
}
default:
+bad_insn:
pr_warn("prog '%s': relo #%d: trying to relocate unrecognized insn #%d, code:0x%x, src:0x%x, dst:0x%x, off:0x%x, imm:0x%x\n",
prog_name, relo_idx, insn_idx, insn->code,
insn->src_reg, insn->dst_reg, insn->off, insn->imm);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 078/457] libbpf: Reject truncated ldimm64 CO-RE relocations
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 077/457] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 079/457] ipv4: fib: fix data-race and stale genid check around nh->nh_saddr Greg Kroah-Hartman
` (389 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit b4e875d397da451fb4e9c573ff4b86db53caba05 ]
CO-RE relocation of an ldimm64 instruction operates on two instruction
slots. A malformed BPF ELF can end a function after the first slot and
attach a CO-RE relocation to it. libbpf allocates the instruction array
according to the function symbol size, so the shared relocation code would
then access beyond the allocation.
Reject a terminal ldimm64 in libbpf's relocation loop, where the program
length is available, before resolving or applying the relocation. Both
resolved and unresolved relocations validate the absent second slot, and
unresolved relocation poisoning would additionally write past the array.
The in-kernel caller is protected by the verifier's early instruction-stream
check before it applies CO-RE relocations.
Fixes: eacaaed784e2 ("libbpf: Implement enum value-based CO-RE relocations")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/20260914140852.03DA21F0089B@smtp.kernel.org
Link: https://patch.msgid.link/20260917233222.2542500-11-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/libbpf.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
index 1ab939dfb7f08..4f9ce4ff005b6 100644
--- a/tools/lib/bpf/libbpf.c
+++ b/tools/lib/bpf/libbpf.c
@@ -6162,6 +6162,13 @@ bpf_object__relocate_core(struct bpf_object *obj, const char *targ_btf_path)
return -EINVAL;
insn = &prog->insns[insn_idx];
+ if (is_ldimm64_insn(insn) && (size_t)insn_idx + 1 >= prog->insns_cnt) {
+ pr_warn("prog '%s': relo #%d: insn #%d (LDIMM64) is truncated\n",
+ prog->name, i, insn_idx);
+ err = -EINVAL;
+ goto out;
+ }
+
err = record_relo_core(prog, rec, insn_idx);
if (err) {
pr_warn("prog '%s': relo #%d: failed to record relocation: %s\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 079/457] ipv4: fib: fix data-race and stale genid check around nh->nh_saddr
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 078/457] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 080/457] gpiolib: use of_node_name if line-name is missing Greg Kroah-Hartman
` (388 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkui Xiao, Ido Schimmel,
Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkui Xiao <xiaolinkui@kylinos.cn>
[ Upstream commit 46bc52d13594848023e681860df8700c8db14354 ]
fib_select_multipath() compares nexthop_nh->nh_saddr against the flow
source address with no lock held, while fib_info_update_nhc_saddr()
stores a new value from another CPU as soon as the preferred source
address of the egress device changes.
Commit 195374d89368 ("ipv4: fib: annotate races around nh->nh_saddr_genid
and nh->nh_saddr") added WRITE_ONCE() on the store side and READ_ONCE()
in fib_result_prefsrc() after syzbot reported
BUG: KCSAN: data-race in fib_select_path / fib_select_path
but it only covered that reader. fib_select_multipath(), reached from
fib_select_path(), is a second lockless reader of nh->nh_saddr and was
left bare.
Moreover, nh_saddr is only meaningful when nh_saddr_genid matches
dev_addr_genid, as established by commit 436c3b66ec98 ("ipv4: Invalidate
nexthop cache nh_saddr more correctly."). fib_select_multipath()
skips that validation, so it can score a nexthop using a stale source
address and skew the ECMP selection.
Annotate both reads with READ_ONCE() and refresh the cached source
address via fib_info_update_nhc_saddr() when the genid does not match,
mirroring fib_result_prefsrc().
Fixes: 32607a332cfe ("ipv4: prefer multipath nexthop that matches source address")
Signed-off-by: Linkui Xiao <xiaolinkui@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260916125316.988044-1-xiaolinkui@126.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/fib_semantics.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/fib_semantics.c b/net/ipv4/fib_semantics.c
index 0483519b7fb0d..0c25f6dfb8a6f 100644
--- a/net/ipv4/fib_semantics.c
+++ b/net/ipv4/fib_semantics.c
@@ -2176,6 +2176,15 @@ static bool fib_good_nh(const struct fib_nh *nh)
return !!(state & NUD_VALID);
}
+static __be32 fib_nh_saddr(struct net *net, const struct fib_info *fi,
+ struct fib_nh *nh, int genid)
+{
+ if (READ_ONCE(nh->nh_saddr_genid) == genid)
+ return READ_ONCE(nh->nh_saddr);
+
+ return fib_info_update_nhc_saddr(net, &nh->nh_common, fi->fib_scope);
+}
+
void fib_select_multipath(struct fib_result *res, int hash,
const struct flowi4 *fl4)
{
@@ -2184,6 +2193,7 @@ void fib_select_multipath(struct fib_result *res, int hash,
bool use_neigh;
int score = -1;
__be32 saddr;
+ int genid;
if (unlikely(res->fi->nh)) {
nexthop_path_fib_result(res, hash);
@@ -2192,6 +2202,7 @@ void fib_select_multipath(struct fib_result *res, int hash,
use_neigh = READ_ONCE(net->ipv4.sysctl_fib_multipath_use_neigh);
saddr = fl4 ? fl4->saddr : 0;
+ genid = saddr ? atomic_read(&net->ipv4.dev_addr_genid) : 0;
change_nexthops(fi) {
int nh_upper_bound, nh_score = 0;
@@ -2204,7 +2215,7 @@ void fib_select_multipath(struct fib_result *res, int hash,
(use_neigh && !fib_good_nh(nexthop_nh)))
continue;
- if (saddr && nexthop_nh->nh_saddr == saddr)
+ if (saddr && fib_nh_saddr(net, fi, nexthop_nh, genid) == saddr)
nh_score += 2;
if (hash <= nh_upper_bound)
nh_score++;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 080/457] gpiolib: use of_node_name if line-name is missing
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 079/457] ipv4: fib: fix data-race and stale genid check around nh->nh_saddr Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 081/457] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
` (387 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Wunderlich, Andy Shevchenko,
Bartosz Golaszewski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Wunderlich <frank-w@public-files.de>
[ Upstream commit d54a489c8c4b627775445d54a6cbd32f209bda8f ]
Until v7.0, GPIO hogs inherited the DT node name when no line-name
property was specified. This was implemented as a fallback in
of_parse_own_gpio().
Commit d1d564ec4992 ("gpio: move hogs into GPIO core") moved hog parsing
into the GPIO core and removed this fallback.
Consequently, GPIO hogs without a line-name property are now displayed
with a ? in /sys/kernel/debug/gpio. Restore the old fallback.
Fixes: d1d564ec4992 ("gpio: move hogs into GPIO core")
Signed-off-by: Frank Wunderlich <frank-w@public-files.de>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/20260917153712.134367-1-linux@fw-web.de
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpiolib.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/gpio/gpiolib.c b/drivers/gpio/gpiolib.c
index ef8ccaf17c9ce..28f7265c5d569 100644
--- a/drivers/gpio/gpiolib.c
+++ b/drivers/gpio/gpiolib.c
@@ -1029,6 +1029,13 @@ int gpiochip_add_hog(struct gpio_chip *gc, struct fwnode_handle *fwnode)
ret = of_gpiochip_get_lflags(gc, &gpiospec, &lflags);
if (ret)
return ret;
+
+ /*
+ * If no line-name property is present, fall back to the OF
+ * node name as in the previous implementation.
+ */
+ if (!name)
+ name = to_of_node(fwnode)->name;
} else {
/*
* GPIO_ACTIVE_LOW is currently the only lookup flag
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 081/457] netfilter: flowtable: publish HW_DEAD after worker is done
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 080/457] gpiolib: use of_node_name if line-name is missing Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 082/457] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
` (386 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit d644b23afe1ef509c9961a6d84a093c2587edf02 ]
flow_offload_work_del() sets NF_FLOW_HW_DEAD before the work handler
clears NF_FLOW_HW_PENDING. Once a flow is both HW_DYING and HW_DEAD, a
concurrent garbage collection pass can remove it and schedule it for RCU
freeing.
The offload worker holds neither an RCU read lock nor a reference to the
flow. If it is preempted after publishing HW_DEAD, the RCU callback can
free the flow before the worker resumes and clears HW_PENDING, resulting
in a use-after-free.
Move HW_DEAD publication to the common worker epilogue after the pending
bit is cleared, making it the final flow access by destroy work. Order all
preceding flow accesses before publishing the bit that allows garbage
collection to free the object.
Fixes: 2c8897953f3b ("netfilter: flowtable: Add pending bit for offload work")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_offload.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nf_flow_table_offload.c b/net/netfilter/nf_flow_table_offload.c
index 801a3dd9ceea3..6757fd89c1f1a 100644
--- a/net/netfilter/nf_flow_table_offload.c
+++ b/net/netfilter/nf_flow_table_offload.c
@@ -995,7 +995,6 @@ static void flow_offload_work_del(struct flow_offload_work *offload)
flow_offload_tuple_del(offload, FLOW_OFFLOAD_DIR_ORIGINAL);
if (test_bit(NF_FLOW_HW_BIDIRECTIONAL, &offload->flow->flags))
flow_offload_tuple_del(offload, FLOW_OFFLOAD_DIR_REPLY);
- set_bit(NF_FLOW_HW_DEAD, &offload->flow->flags);
}
static void flow_offload_tuple_stats(struct flow_offload_work *offload,
@@ -1059,6 +1058,12 @@ static void flow_offload_work_handler(struct work_struct *work)
}
clear_bit(NF_FLOW_HW_PENDING, &offload->flow->flags);
+ if (offload->cmd == FLOW_CLS_DESTROY) {
+ /* Publish after the worker's last flow access. */
+ smp_mb__before_atomic();
+ set_bit(NF_FLOW_HW_DEAD, &offload->flow->flags);
+ }
+
kfree(offload);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 082/457] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 081/457] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 083/457] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
` (385 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 9461613afc59acef44a0071b0dd5075f6e993ffe ]
We must serialize the release notifier and the config netlink function.
A concurrent thread can issue close() which can call the release function
while unrelated socket processes UNBIND request for same portid:
Oops: general protection fault, [..]
RIP: 0010:__instance_destroy+0x60/0x210 [nfnetlink_queue]
Call Trace:
nfqnl_recv_config+0x9b0/0xdc0 [nfnetlink_queue]
nfnetlink_rcv_msg+0x7c2/0xeb0
? __pfx_nfnetlink_rcv_msg+0x10/0x10
After this, parallel UNBIND and URELEASE events are impossible.
This change isn't nice, but its the shortest fix given instances
are not refcounted and the nfnetlink config callback drops the
rcu read lock early due to need for sleeping allocations.
Fixes: 7af4cc3fa158 ("[NETFILTER]: Add "nfnetlink_queue" netfilter queue handler over nfnetlink")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nfnetlink_queue.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/net/netfilter/nfnetlink_queue.c b/net/netfilter/nfnetlink_queue.c
index b8aaf39cb4d8e..ec5e7716df8b5 100644
--- a/net/netfilter/nfnetlink_queue.c
+++ b/net/netfilter/nfnetlink_queue.c
@@ -1527,6 +1527,7 @@ nfqnl_rcv_nl_event(struct notifier_block *this,
if (event == NETLINK_URELEASE && n->protocol == NETLINK_NETFILTER) {
int i;
+ nfnl_lock(NFNL_SUBSYS_QUEUE);
/* destroy all instances for this portid */
spin_lock(&q->instances_lock);
for (i = 0; i < INSTANCE_BUCKETS; i++) {
@@ -1540,6 +1541,7 @@ nfqnl_rcv_nl_event(struct notifier_block *this,
}
}
spin_unlock(&q->instances_lock);
+ nfnl_unlock(NFNL_SUBSYS_QUEUE);
}
return NOTIFY_DONE;
}
@@ -1859,9 +1861,9 @@ static int nfqnl_recv_config(struct sk_buff *skb, const struct nfnl_info *info,
/* Lookup queue under RCU. After peer_portid check (or for new queue
* in BIND case), the queue is owned by the socket sending this message.
- * A socket cannot simultaneously send a message and close, so while
- * processing this CONFIG message, nfqnl_rcv_nl_event() (triggered by
- * socket close) cannot destroy this queue. Safe to use without RCU.
+ * nfqnl_rcv_nl_event() will block on the nfnl subsys mutex that is
+ * held by the caller, so the queue cannot be destroyed in parallel,
+ * even after we drop the RCU read lock.
*/
rcu_read_lock();
queue = instance_lookup(q, queue_num);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 083/457] netfilter: nft_synproxy: use the family-aware checksum helper
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 082/457] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 084/457] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
` (384 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Pablo Neira Ayuso,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit a311a898172743558b82f6035ef2aa8c310a4223 ]
nft_synproxy_do_eval() verifies the TCP checksum before it switches on
skb->protocol. It uses nf_ip_checksum(), which constructs an IPv4
pseudo header and relies on the IPv4 header checksum when folding the
whole skb. Neither operation is valid for an IPv6 packet.
A correctly checksummed IPv6 segment can therefore fail verification
when it reaches the hook as CHECKSUM_NONE or, at NF_INET_LOCAL_IN,
CHECKSUM_COMPLETE. nft_synproxy_do_eval() returns NF_DROP before
nft_synproxy_eval_v6() can send a SYN-ACK.
nft_synproxy_validate() deliberately admits NFPROTO_IPV6 and
NFPROTO_INET, and the xtables counterpart ip6t_SYNPROXY.c already calls
nf_ip6_checksum().
Use nf_checksum() with nft_pf() so the checksum helper dispatches to the
packet family's implementation.
Fixes: ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_synproxy.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nft_synproxy.c b/net/netfilter/nft_synproxy.c
index 9ed288c9d1688..554a96a000f40 100644
--- a/net/netfilter/nft_synproxy.c
+++ b/net/netfilter/nft_synproxy.c
@@ -118,7 +118,8 @@ static void nft_synproxy_do_eval(const struct nft_synproxy *priv,
return;
}
- if (nf_ip_checksum(skb, nft_hook(pkt), thoff, IPPROTO_TCP)) {
+ if (nf_checksum(skb, nft_hook(pkt), thoff, IPPROTO_TCP,
+ nft_pf(pkt))) {
regs->verdict.code = NF_DROP;
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 084/457] ipvs: revalidate ihl before icmp_send
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 083/457] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 085/457] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
` (383 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Anastasov, Pablo Neira Ayuso,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Anastasov <ja@ssi.bg>
[ Upstream commit e290145564886d6a3038810c621f738c1fe9fa51 ]
While the outer IP header is already pulled into the skb head, we must
be careful and revalidate the embedded headers after reading them from
the skb frags to prevent possible out-of-bounds access.
One such place reported by Sashiko is ip_vs_in_icmp() where local
process can change the ihl field and after pskb_may_pull() we can see
larger value. Even if icmp_send() has checks to prevent out-of-bounds
access, play safe and add check to drop the packet if the ihl field is
changed. As the outer headers are pulled, make sure the transport
header is updated too, it was used before commit 7fcc2fe39fed ("net:
icmp: avoid invalid transport header access in icmp_send tracepoint")
Fixes: f2edb9f7706d ("ipvs: implement passive PMTUD for IPIP packets")
Link: https://sashiko.dev/#/patchset/20260806105211.34622-1-ja%40ssi.bg
Signed-off-by: Julian Anastasov <ja@ssi.bg>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/ipvs/ip_vs_core.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c
index eb806813292ad..6802ce5cb1de4 100644
--- a/net/netfilter/ipvs/ip_vs_core.c
+++ b/net/netfilter/ipvs/ip_vs_core.c
@@ -1961,6 +1961,12 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related,
/* Ensure the IP header is present in headroom */
if (!pskb_may_pull(skb, hlen_orig))
goto ignore_tunnel;
+ skb_set_transport_header(skb, hlen_orig);
+ /* Before now we may used ihl from skb frag, revalidate it after
+ * copying it into skb head to prevent out-of-bounds access
+ */
+ if (ip_hdr(skb)->ihl * 4 != hlen_orig)
+ goto ignore_tunnel;
IP_VS_DBG(12, "Sending ICMP for %pI4->%pI4: t=%u, c=%u, i=%u\n",
&ip_hdr(skb)->saddr, &ip_hdr(skb)->daddr,
type, code, ntohl(info));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 085/457] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 084/457] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 086/457] arm64: io: Reject non-user protection in ioremap_prot() Greg Kroah-Hartman
` (382 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+4bd730aede2791e40bdf,
Naman Gulati, Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Naman Gulati <namangulati@google.com>
[ Upstream commit 207d591c353201f3bd3e0c89bb7d44a849c8fd59 ]
expect_iter_name() is invoked by nf_ct_expect_iterate_net() under
spin_lock_bh(&nf_conntrack_expect_lock). It does not hold
rcu_read_lock().
When accessing exp->helper with rcu_dereference() in syzbot's report,
lockdep warns:
=============================
WARNING: suspicious RCU usage
syzkaller #0 Not tainted
-----------------------------
net/netfilter/nf_conntrack_netlink.c:3393 suspicious rcu_dereference_check() usage!
locks held by syz-executor381/5628: 2, last CPU#1:
#0: ffffffff9aee42a0 (nfnl_subsys_ctnetlink_exp){+.+.}-{4:4},
at: nfnetlink_rcv_msg+0xa69/0x12b0
#1: ffffffff8ea74d58 (nf_conntrack_expect_lock){+...}-{3:3},
at: nf_ct_expect_iterate_net+0x38/0x180
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150
lockdep_rcu_suspicious+0x140/0x1d0
expect_iter_name+0xfb/0x100
nf_ct_expect_iterate_net+0xf2/0x180
ctnetlink_del_expect+0x45d/0x640
nfnetlink_rcv_msg+0xcc2/0x12b0
netlink_rcv_skb+0x226/0x4a0
nfnetlink_rcv+0x2b9/0x28c0
netlink_unicast+0x7bd/0x940
netlink_sendmsg+0x813/0xb40
____sys_sendmsg+0x54e/0x850
___sys_sendmsg+0x2a5/0x360
__sys_sendmsg+0x2a5/0x360
do_syscall_64+0x166/0x520
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Use rcu_dereference_protected() with lockdep_is_held() on
nf_conntrack_expect_lock instead, similar to expect_iter_me() in
nf_conntrack_helper.c.
Fixes: f01794106042 ("netfilter: nf_conntrack_expect: use expect->helper")
Reported-by: syzbot+4bd730aede2791e40bdf@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa4a377.f81106d8.2ab401.0024.GAE@google.com/T/#u
Signed-off-by: Naman Gulati <namangulati@google.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_conntrack_netlink.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntrack_netlink.c
index 92c3bb77d27e8..6cddfa339d71e 100644
--- a/net/netfilter/nf_conntrack_netlink.c
+++ b/net/netfilter/nf_conntrack_netlink.c
@@ -3392,7 +3392,8 @@ static bool expect_iter_name(struct nf_conntrack_expect *exp, void *data)
struct nf_conntrack_helper *helper;
const char *name = data;
- helper = rcu_dereference(exp->helper);
+ helper = rcu_dereference_protected(exp->helper,
+ lockdep_is_held(&nf_conntrack_expect_lock));
if (!helper)
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 086/457] arm64: io: Reject non-user protection in ioremap_prot()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 085/457] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 087/457] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
` (381 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zeng Heng, Catalin Marinas,
Will Deacon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zeng Heng <zengheng4@huawei.com>
[ Upstream commit bb756b11ad63832ebee58caf9e8f9381eaecff9f ]
Mapping a stack-top page via /dev/mem with PROT_NONE and then
reading that process's /proc/<pid>/cmdline triggers a spurious WARN
in ioremap_prot() through generic_access_phys():
WARNING: ./arch/arm64/include/asm/io.h:275 at generic_access_phys
Call trace:
generic_access_phys+0x1c8/0x228 (P)
__access_remote_vm+0x2b4/0x398
access_remote_vm+0x14/0x30
get_mm_cmdline+0xf8/0x2a0
proc_pid_cmdline_read+0x68/0x120
generic_access_phys() passes the protection derived from the user PTE
to ioremap_prot(). On arm64, a PROT_NONE mapping is represented by a
present-invalid PTE, so pte_present() still returns true and the
protection reaches ioremap_prot().
A PROT_NONE mapping does not have PTE_USER, causing the existing
WARN_ON_ONCE() in ioremap_prot() to fire even though this is a valid
user mapping. Execute-only mappings have the same issue and must not
be readable through this path either.
ioremap_prot() should therefore reject protection values without
PTE_USER without warning. This makes the access fail cleanly for
PROT_NONE and execute-only mappings while retaining the existing
user-protection contract.
Fixes: 8f098037139b ("arm64: io: Extract user memory type in ioremap_prot()")
Signed-off-by: Zeng Heng <zengheng4@huawei.com>
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/io.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/include/asm/io.h b/arch/arm64/include/asm/io.h
index 21c8e400107ca..31e67f6bd4a70 100644
--- a/arch/arm64/include/asm/io.h
+++ b/arch/arm64/include/asm/io.h
@@ -272,7 +272,8 @@ static inline void __iomem *ioremap_prot(phys_addr_t phys, size_t size,
pgprot_t prot;
ptval_t user_prot_val = pgprot_val(user_prot);
- if (WARN_ON_ONCE(!(user_prot_val & PTE_USER)))
+ /* Reject PROT_NONE and exec-only */
+ if (!(user_prot_val & PTE_USER))
return NULL;
prot = __pgprot_modify(PAGE_KERNEL, PTE_ATTRINDX_MASK,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 087/457] ocfs2: make ocfs2_calc_xattr_init() return void
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 086/457] arm64: io: Reject non-user protection in ioremap_prot() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 088/457] pinctrl: qcom: ipq5210: Publish the OF module alias Greg Kroah-Hartman
` (380 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joseph Qi, Andrew Morton,
kernel test robot, Mark Fasheh, Joel Becker, Junxiao Bi,
Changwei Ge, Jun Piao, Heming Zhao, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joseph Qi <joseph.qi@linux.alibaba.com>
[ Upstream commit 525c0edc032b3297d0c1056cf1fa20cf1f9e6184 ]
ocfs2_calc_xattr_init() used to read the default ACL off the parent inode
itself, so it could return an error from ocfs2_xattr_get_nolock(). Commit
bd7c05fb4a47 ("ocfs2: fix circular locking dependency in
ocfs2_init_acl()") moved that lookup before the transaction starts and
deleted the error path, but left the now vestigial 'int ret = 0'
declaration and both 'return ret' statements behind, along with an
unreachable error branch in ocfs2_mknod().
Drop the leftover variable and convert the return type to void, so the
callee states that it always succeeds and the caller no longer carries a
check that can never trigger.
No functional change.
Link: https://lore.kernel.org/20260904023751.3703334-1-joseph.qi@linux.alibaba.com
Fixes: bd7c05fb4a47 ("ocfs2: fix circular locking dependency in ocfs2_init_acl()")
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609040247.8B3lmoqX-lkp@intel.com/
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ocfs2/namei.c | 9 ++-------
fs/ocfs2/xattr.c | 13 +++++--------
fs/ocfs2/xattr.h | 8 ++++----
3 files changed, 11 insertions(+), 19 deletions(-)
diff --git a/fs/ocfs2/namei.c b/fs/ocfs2/namei.c
index ea37a50580890..4e9f8dd63dcb2 100644
--- a/fs/ocfs2/namei.c
+++ b/fs/ocfs2/namei.c
@@ -336,13 +336,8 @@ static int ocfs2_mknod(struct mnt_idmap *idmap,
goto leave;
/* calculate meta data/clusters for setting security and acl xattr */
- status = ocfs2_calc_xattr_init(dir, mode, &si, &want_clusters,
- &xattr_credits, &want_meta,
- &acl_state);
- if (status < 0) {
- mlog_errno(status);
- goto leave;
- }
+ ocfs2_calc_xattr_init(dir, mode, &si, &want_clusters, &xattr_credits,
+ &want_meta, &acl_state);
/* Reserve a cluster if creating an extent based directory. */
if (S_ISDIR(mode) && !ocfs2_supports_inline_data(osb)) {
diff --git a/fs/ocfs2/xattr.c b/fs/ocfs2/xattr.c
index 35bcbb0ff607b..bfafe059bedff 100644
--- a/fs/ocfs2/xattr.c
+++ b/fs/ocfs2/xattr.c
@@ -635,12 +635,11 @@ int ocfs2_calc_security_init(struct inode *dir,
return ret;
}
-int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
- struct ocfs2_security_xattr_info *si,
- int *want_clusters, int *xattr_credits,
- int *want_meta, struct ocfs2_acl_state *acl_state)
+void ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
+ struct ocfs2_security_xattr_info *si,
+ int *want_clusters, int *xattr_credits,
+ int *want_meta, struct ocfs2_acl_state *acl_state)
{
- int ret = 0;
struct ocfs2_super *osb = OCFS2_SB(dir->i_sb);
int s_size = 0, a_size = 0, acl_len = 0, new_clusters;
@@ -662,7 +661,7 @@ int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
}
if (!(s_size + a_size))
- return ret;
+ return;
/*
* The max space of security xattr taken inline is
@@ -728,8 +727,6 @@ int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
}
}
}
-
- return ret;
}
static int ocfs2_xattr_extend_allocation(struct inode *inode,
diff --git a/fs/ocfs2/xattr.h b/fs/ocfs2/xattr.h
index 5e18513277f18..887cc1a18b1af 100644
--- a/fs/ocfs2/xattr.h
+++ b/fs/ocfs2/xattr.h
@@ -59,10 +59,10 @@ int ocfs2_calc_security_init(struct inode *,
int *, int *, struct ocfs2_alloc_context **);
struct ocfs2_acl_state;
-int ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
- struct ocfs2_security_xattr_info *si,
- int *want_clusters, int *xattr_credits,
- int *want_meta, struct ocfs2_acl_state *acl_state);
+void ocfs2_calc_xattr_init(struct inode *dir, umode_t mode,
+ struct ocfs2_security_xattr_info *si,
+ int *want_clusters, int *xattr_credits,
+ int *want_meta, struct ocfs2_acl_state *acl_state);
/*
* xattrs can live inside an inode, as part of an external xattr block,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 088/457] pinctrl: qcom: ipq5210: Publish the OF module alias
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 087/457] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 089/457] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
` (379 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, hpp.iscas, Konrad Dybcio,
Bartosz Golaszewski, Linus Walleij, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit 447dcff90557748a5ac384aaf5d70b2c7e3b961d ]
The IPQ5210 TLMM platform driver can be a module and matches through
ipq5210_tlmm_of_match. This table is not published for OF modalias
matching.
Publish the existing table, preserving arch_initcall ordering and
the shared MSM pinctrl probe.
Fixes: a549fe22376f ("pinctrl: qcom: Introduce IPQ5210 TLMM driver")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260905134340.67477-1-hppiscas@163.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/qcom/pinctrl-ipq5210.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/pinctrl/qcom/pinctrl-ipq5210.c b/drivers/pinctrl/qcom/pinctrl-ipq5210.c
index 827a4ad07a6b0..d5b4eb3e73435 100644
--- a/drivers/pinctrl/qcom/pinctrl-ipq5210.c
+++ b/drivers/pinctrl/qcom/pinctrl-ipq5210.c
@@ -867,6 +867,7 @@ static const struct of_device_id ipq5210_tlmm_of_match[] = {
{ .compatible = "qcom,ipq5210-tlmm", },
{ },
};
+MODULE_DEVICE_TABLE(of, ipq5210_tlmm_of_match);
static int ipq5210_tlmm_probe(struct platform_device *pdev)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 089/457] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 088/457] pinctrl: qcom: ipq5210: Publish the OF module alias Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 090/457] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
` (378 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Francesco Magazzu,
Lyude Paul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <dan.carpenter@oracle.com>
[ Upstream commit aff09d9e37e02dc60bde79035ac15b136d602259 ]
If list_for_each_entry() exits without hitting a break then "pstate" is
not a valid pstate pointer. Introduce a "found" variable instead.
The check is reachable from userspace: nvkm_clk_ustate_update() takes the
pstate id straight from the 'pstate' debugfs file, so requesting an id
that is not in clk->states - or any id at all when the perf tables are
broken and the list is empty - makes the pstate->pstate != req test
dereference the list head cast to a struct nvkm_pstate, which is an
out-of-bounds read.
Fixes: 7c8565220697 ("drm/nouveau/clk: implement power state and engine clock control in core")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
[Francesco: rebased on drm-misc-next, expanded the commit message]
Signed-off-by: Francesco Magazzu <postadelmaga@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260918131620.405133-2-postadelmaga@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
index 572e638463159..5da82db71dde2 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
@@ -473,6 +473,7 @@ static int
nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
{
struct nvkm_pstate *pstate;
+ bool found = false;
int i = 0;
if (!clk->allow_reclock)
@@ -480,12 +481,14 @@ nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
if (req != -1 && req != -2) {
list_for_each_entry(pstate, &clk->states, head) {
- if (pstate->pstate == req)
+ if (pstate->pstate == req) {
+ found = true;
break;
+ }
i++;
}
- if (pstate->pstate != req)
+ if (!found)
return -EINVAL;
req = i;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 090/457] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 089/457] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 091/457] drm/nouveau/disp: dont reject HDMI config on cards without SCDC Greg Kroah-Hartman
` (377 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Francesco Magazzu, Lyude Paul,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Francesco Magazzu <postadelmaga@gmail.com>
[ Upstream commit e5cccdafc855cd5f96f4b51d38114a0360b075d7 ]
nvkm_cstate_prog() reuses 'ret' for the voltage and fan-speed restore
calls it makes after reprogramming the clocks. Those calls almost always
succeed, so the status of the reclock itself is overwritten and the
function reports success even when clk->func->calc() or clk->func->prog()
failed. The converse is also true: a successful reclock is reported as an
error if the final restore call fails, even though that failure is only
logged and otherwise ignored.
The only consumer of the return value is the error message in
nvkm_pstate_work(), so in practice a failing reclock is simply never
reported. Nothing else changes, but a function that returns success on
failure is a trap for the next caller.
Keep the calc/prog status in 'ret' and use a separate local for the
restore calls.
Fixes: 3eca809b3c05 ("drm/nouveau/clk: cosmetic changes")
Signed-off-by: Francesco Magazzu <postadelmaga@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260918131620.405133-5-postadelmaga@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
index 5da82db71dde2..fd2a9d64caba9 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c
@@ -199,16 +199,18 @@ nvkm_cstate_prog(struct nvkm_clk *clk, struct nvkm_pstate *pstate, int cstatei)
}
if (volt) {
- ret = nvkm_volt_set_id(volt, cstate->voltage,
- pstate->base.voltage, clk->temp, -1);
- if (ret && ret != -ENODEV)
- nvkm_error(subdev, "failed to lower voltage: %d\n", ret);
+ int err = nvkm_volt_set_id(volt, cstate->voltage,
+ pstate->base.voltage, clk->temp, -1);
+
+ if (err && err != -ENODEV)
+ nvkm_error(subdev, "failed to lower voltage: %d\n", err);
}
if (therm) {
- ret = nvkm_therm_cstate(therm, pstate->fanspeed, -1);
- if (ret && ret != -ENODEV)
- nvkm_error(subdev, "failed to lower fan speed: %d\n", ret);
+ int err = nvkm_therm_cstate(therm, pstate->fanspeed, -1);
+
+ if (err && err != -ENODEV)
+ nvkm_error(subdev, "failed to lower fan speed: %d\n", err);
}
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 091/457] drm/nouveau/disp: dont reject HDMI config on cards without SCDC
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 090/457] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 092/457] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
` (376 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Giuseppe Ranieri, Tano Dzhinski,
Lyude Paul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Giuseppe Ranieri <giuseppe@ranieri.dev>
[ Upstream commit 1717fcc5be575d4768279148ae9465a8b13d4339 ]
nv50_hdmi_enable() passes the sink's SCDC capability from its EDID
straight through to nvif_outp_hdmi(). On pre-Maxwell-2 cards there is no
hdmi->scdc callback, so nvkm_uoutp_mthd_hdmi() rejects the whole
configuration with -EINVAL, and nv50_hdmi_enable() returns before
hdmi->ctrl() runs and before the AVI and VSI infoframes are sent.
The result on such a card driving an SCDC-capable HDMI 2.0 sink is that
HDMI audio silently stops working. Video is unaffected, and nothing is
logged, which makes the failure hard to attribute.
SCDC is optional, and the hdmi->scdc() call further down is already
guarded against a missing callback. Requesting it on a card that cannot
do it need not invalidate the rest of the HDMI configuration, so drop
that term from the condition and let the existing guard skip SCDC alone.
Fixes: 6c6abab20b99 ("drm/nouveau/disp: add output hdmi config method")
Signed-off-by: Giuseppe Ranieri <giuseppe@ranieri.dev>
Co-Authored-By: Tano Dzhinski <tano.dzhinski@gmail.com>
Signed-off-by: Tano Dzhinski <tano.dzhinski@gmail.com>
Tested-by: Tano Dzhinski <tano.dzhinski@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260917215114.1136715-1-tano.dzhinski@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c b/drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c
index 377d0e0cef848..9887b3898505b 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c
@@ -253,8 +253,7 @@ nvkm_uoutp_mthd_hdmi(struct nvkm_outp *outp, void *argv, u32 argc)
if (!ior->func->hdmi ||
args->v0.max_ac_packet > 0x1f ||
- args->v0.rekey > 0x7f ||
- (args->v0.scdc && !ior->func->hdmi->scdc))
+ args->v0.rekey > 0x7f)
return -EINVAL;
if (!args->v0.enable) {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 092/457] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 091/457] drm/nouveau/disp: dont reject HDMI config on cards without SCDC Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 093/457] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
` (375 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+6cc37aba98dac721c415,
Nguyen Ngoc Thang, Simon Horman, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 47abe7a5c4eb53269aca3506446f851572a059a3 ]
flow_offload_alloc() returns NULL when the conntrack entry is dying
(e.g. raced with a conntrack flush) or when the GFP_ATOMIC allocation
fails; both are expected under load and neither is a kernel bug. This
path runs from softirq on every committed packet, so with
panic_on_warn=1 an unprivileged user can panic the box just by racing
a conntrack flush against a `tc ... action ct commit` classifier.
Reproduced with a custom repro under QEMU: a small, fixed set of UDP
flows through `tc filter ... action ct commit` on lo, raced against
threads flooding bare ctnetlink CT_DELETE (flush) requests. Hits
WARNING: net/sched/act_ct.c:437 (tcf_ct_flow_table_add(), inlined
into tcf_ct_act() in this build) within ~15s on the unpatched kernel;
same setup is clean on the patched kernel. The fix itself is
behavior-preserving: both branches already did `goto err_alloc`
before and after, only the WARN is removed.
Fixes: 64ff70b80fd4 ("net/sched: act_ct: Offload established connections to flow table")
Reported-by: syzbot+6cc37aba98dac721c415@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=6cc37aba98dac721c415
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915150816.36487-1-ngocthang2710.1999@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_ct.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/net/sched/act_ct.c b/net/sched/act_ct.c
index 370085ab6ea41..aba022969553b 100644
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -432,11 +432,10 @@ static void tcf_ct_flow_table_add(struct tcf_ct_flow_table *ct_ft,
if (test_and_set_bit(IPS_OFFLOAD_BIT, &ct->status))
return;
+ /* NULL if ct is dying (raced flush) or the atomic alloc failed. */
entry = flow_offload_alloc(ct);
- if (!entry) {
- WARN_ON_ONCE(1);
+ if (!entry)
goto err_alloc;
- }
if (tcp) {
ct->proto.tcp.seen[0].flags |= IP_CT_TCP_FLAG_BE_LIBERAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 093/457] net: gue: reject invalid REMCSUM offsets
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 092/457] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 094/457] net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure Greg Kroah-Hartman
` (374 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 2566866fc30965d915d0b52b5c3323b362619f0e ]
The REMCSUM option carries an absolute checksum start and checksum field
offset. gue_remcsum() passes them to skb_remcsum_process(), whose
partial path stores offset - start in the u16 skb->csum_offset variable.
If offset is less than start, this underflows.
A forwarded packet can retain CHECKSUM_PARTIAL and reach a NETIF_F_HW_CSUM
driver which trusts the metadata, leading skb_copy_and_csum_dev() to write
two bytes about 64 KiB beyond the destination buffer.
Reject reversed tuples in validate_gue_flags(), after the existing length
validation, so all GUE parsers enforce the ordering in one place.
Fixes: fe881ef11cf0 ("gue: Use checksum partial with remote checksum offload")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260915124806.2852293-2-Jeremy.Jean@oss.cyber.gouv.fr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/gue.h | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/include/net/gue.h b/include/net/gue.h
index caefd6da86939..d377155fd0b31 100644
--- a/include/net/gue.h
+++ b/include/net/gue.h
@@ -84,8 +84,9 @@ static inline size_t guehdr_priv_flags_len(__be32 flags)
}
/* Validate standard and private flags. Returns non-zero (meaning invalid)
- * if there is an unknown standard or private flags, or the options length for
- * the flags exceeds the options length specific in hlen of the GUE header.
+ * if there is an unknown standard or private flags, if the options length for
+ * the flags exceeds the options length specified in hlen of the GUE header, or
+ * if a private option contains invalid data.
*/
static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
{
@@ -103,8 +104,8 @@ static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
/* Private flags are last four bytes accounted in
* guehdr_flags_len
*/
- __be32 pflags = *(__be32 *)((void *)&guehdr[1] +
- len - GUE_LEN_PRIV);
+ void *data = (void *)&guehdr[1] + len;
+ __be32 pflags = *(__be32 *)(data - GUE_LEN_PRIV);
if (pflags & ~GUE_PFLAGS_ALL)
return 1;
@@ -112,6 +113,16 @@ static inline int validate_gue_flags(struct guehdr *guehdr, size_t optlen)
len += guehdr_priv_flags_len(pflags);
if (len > optlen)
return 1;
+
+ if (pflags & GUE_PFLAG_REMCSUM) {
+ __be16 *pd = data;
+
+ /* The field offset pd[1] must not be less
+ * than the start pd[0].
+ */
+ if (ntohs(pd[1]) < ntohs(pd[0]))
+ return 1;
+ }
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 094/457] net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 093/457] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 095/457] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
` (373 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 310d1ac61a4d5a2ca8356a3a48d263acf54503ce ]
If register_netdev() fails for one of the MTK_MAX_DEVS devices in
mtk_probe(), the error path jumps to err_deinit_ppe, skipping
mtk_unreg_dev(). The previously registered net_devices are then freed by
mtk_free_dev() while still in NETREG_REGISTERED state, hitting the
BUG_ON(dev->reg_state != NETREG_UNREGISTERED).
Route the register_netdev() failure to err_unreg_netdev so the net_devices
registered so far are properly unregistered before being freed.
Fixes: 8a8a9e89f801 ("net: ethernet: mediatek: cleanup error path inside mtk_hw_init")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260916-mtk_eth_soc-netdev-fix-v1-1-5dac50eb65b1@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mediatek/mtk_eth_soc.c b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
index b2473df74dff0..efc238abb67b3 100644
--- a/drivers/net/ethernet/mediatek/mtk_eth_soc.c
+++ b/drivers/net/ethernet/mediatek/mtk_eth_soc.c
@@ -4508,6 +4508,10 @@ static int mtk_unreg_dev(struct mtk_eth *eth)
mac = netdev_priv(eth->netdev[i]);
if (MTK_HAS_CAPS(eth->soc->caps, MTK_QDMA))
unregister_netdevice_notifier(&mac->device_notifier);
+
+ if (eth->netdev[i]->reg_state != NETREG_REGISTERED)
+ continue;
+
unregister_netdev(eth->netdev[i]);
}
@@ -5339,7 +5343,7 @@ static int mtk_probe(struct platform_device *pdev)
err = register_netdev(eth->netdev[i]);
if (err) {
dev_err(eth->dev, "error bringing up device\n");
- goto err_deinit_ppe;
+ goto err_unreg_netdev;
} else
netif_info(eth, probe, eth->netdev[i],
"mediatek frame engine at 0x%08lx, irq %d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 095/457] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 094/457] net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 096/457] net: ethtool: keep rtnl_lock for the ioctl self test Greg Kroah-Hartman
` (372 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Xuanqiang Luo,
Ido Schimmel, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit dd47bcf279f1083f09bf5266890b26263361022b ]
The cited commit accidentally added ip6gre_tunnel_unlink_md()
in ip6erspan_changelink().
Let's correct it to ip6erspan_tunnel_unlink_md().
Fixes: b80d0b93b991 ("net: ip6_gre: fix tunnel metadata device sharing.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260916230927.378957-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_gre.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv6/ip6_gre.c b/net/ipv6/ip6_gre.c
index 678678fcb5da3..e6913a7f68811 100644
--- a/net/ipv6/ip6_gre.c
+++ b/net/ipv6/ip6_gre.c
@@ -2280,7 +2280,7 @@ static int ip6erspan_changelink(struct net_device *dev, struct nlattr *tb[],
return PTR_ERR(t);
ip6erspan_set_version(data, &p);
- ip6gre_tunnel_unlink_md(ign, t);
+ ip6erspan_tunnel_unlink_md(ign, t);
ip6gre_tunnel_unlink(ign, t);
ip6erspan_tnl_change(t, &p, !tb[IFLA_MTU]);
ip6erspan_tunnel_link_md(ign, t);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 096/457] net: ethtool: keep rtnl_lock for the ioctl self test
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 095/457] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 097/457] eth: fbnic: Handle maximum standalone channels Greg Kroah-Hartman
` (371 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexanderduyck@fb.com>
[ Upstream commit 1b82958f3f035df5ccaab5430a2302f08a5d5351 ]
An offline self test that brings the interface down and back up with
netif_close() / netif_open() requires rtnl_lock for both. Since the
ethtool IOCTL path became rtnl-optional for ops-locked drivers, the
ETHTOOL_TEST ioctl runs holding only the netdev instance lock, so on an
ops-locked driver the self test now tears the device down without
rtnl_lock.
With lockdep this reproduces deterministically on every offline self
test on such a driver; note the sole lock held is the instance lock, not
rtnl:
WARNING: suspicious RCU usage
net/core/netpoll.c:207 suspicious rcu_dereference_protected() usage!
1 lock held by ethtool/107:
#0: (&dev->lock){+.+.}, at: dev_ethtool
Call Trace:
netpoll_poll_disable
__dev_close_many
netif_close_many
netif_close
fbnic_self_test
dev_ethtool_locked
dev_ethtool
dev_ioctl
sock_ioctl
__x64_sys_ioctl
Without lockdep the same condition trips ASSERT_RTNL() in
__dev_close_many() / __dev_open(); that check only samples the global
rtnl state, so it can be masked by a concurrent rtnl holder, but the
device is still being reconfigured without the lock it requires.
The ethtool self_test is a legacy ioctl-only command, so an ETHTOOL_TEST
case is only needed on the ioctl path. Add an opt-in bit for drivers whose
self test needs rtnl_lock and set it on the ops-locked drivers whose
offline self test tears the interface down and up:
- fbnic (ops-locked via queue_mgmt_ops): fbnic_self_test() offline path
uses netif_close() / netif_open().
- bnxt (ops-locked via queue_mgmt_ops): bnxt_self_test() offline path
goes through bnxt_close_nic() / bnxt_half_open_nic() /
bnxt_half_close_nic() / bnxt_open_nic(), which close and reopen the
device.
Fixes: f994752b1127 ("net: ethtool: optionally skip rtnl_lock on IOCTL path")
Signed-off-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942019771.7700.338431553546884773.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c | 3 ++-
drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c | 3 ++-
include/linux/ethtool.h | 2 ++
net/ethtool/common.h | 2 ++
4 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c b/drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c
index 62bc9cae613c3..622e89587e5db 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt_ethtool.c
@@ -5733,7 +5733,8 @@ const struct ethtool_ops bnxt_ethtool_ops = {
.op_needs_rtnl = ETHTOOL_OP_NEEDS_RTNL_SCHANNELS |
ETHTOOL_OP_NEEDS_RTNL_SRINGPARAM |
ETHTOOL_OP_NEEDS_RTNL_SCOALESCE |
- ETHTOOL_OP_NEEDS_RTNL_RSS,
+ ETHTOOL_OP_NEEDS_RTNL_RSS |
+ ETHTOOL_OP_NEEDS_RTNL_TEST,
.supported_coalesce_params = ETHTOOL_COALESCE_USECS |
ETHTOOL_COALESCE_MAX_FRAMES |
ETHTOOL_COALESCE_USECS_IRQ |
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c b/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
index 0e47088ec44ba..423f179c9d475 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
@@ -2025,7 +2025,8 @@ static const struct ethtool_ops fbnic_ethtool_ops = {
ETHTOOL_OP_NEEDS_RTNL_SPAUSEPARAM |
ETHTOOL_OP_NEEDS_RTNL_SCHANNELS |
ETHTOOL_OP_NEEDS_RTNL_SRINGPARAM |
- ETHTOOL_OP_NEEDS_RTNL_GLINK,
+ ETHTOOL_OP_NEEDS_RTNL_GLINK |
+ ETHTOOL_OP_NEEDS_RTNL_TEST,
.get_drvinfo = fbnic_get_drvinfo,
.get_regs_len = fbnic_get_regs_len,
.get_regs = fbnic_get_regs,
diff --git a/include/linux/ethtool.h b/include/linux/ethtool.h
index 12683b5d125e4..97a1adbd9eaee 100644
--- a/include/linux/ethtool.h
+++ b/include/linux/ethtool.h
@@ -944,6 +944,7 @@ struct kernel_ethtool_ts_info {
#define ETHTOOL_OP_NEEDS_RTNL_SPAUSEPARAM BIT(6)
#define ETHTOOL_OP_NEEDS_RTNL_RSS BIT(7)
#define ETHTOOL_OP_NEEDS_RTNL_GLINK BIT(8)
+#define ETHTOOL_OP_NEEDS_RTNL_TEST BIT(9)
/**
* struct ethtool_ops - optional netdev operations
@@ -981,6 +982,7 @@ struct kernel_ethtool_ts_info {
* - netdev_update_features()
* - netif_set_real_num_tx_queues()
* - ethtool_op_get_link() (syncs link watch under rtnl_lock)
+ * - netif_open() / netif_close() (used by @self_test)
*
* @get_drvinfo: Report driver/device information. Modern drivers no
* longer have to implement this callback. Most fields are
diff --git a/net/ethtool/common.h b/net/ethtool/common.h
index 4e5356e26f400..ae32e7fdb563c 100644
--- a/net/ethtool/common.h
+++ b/net/ethtool/common.h
@@ -163,6 +163,8 @@ ethtool_ioctl_needs_rtnl(const struct net_device *dev, u32 ethcmd)
return ops->op_needs_rtnl & ETHTOOL_OP_NEEDS_RTNL_RSS;
case ETHTOOL_GLINK:
return ops->op_needs_rtnl & ETHTOOL_OP_NEEDS_RTNL_GLINK;
+ case ETHTOOL_TEST:
+ return ops->op_needs_rtnl & ETHTOOL_OP_NEEDS_RTNL_TEST;
}
return false;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 097/457] eth: fbnic: Handle maximum standalone channels
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 096/457] net: ethtool: keep rtnl_lock for the ioctl self test Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 098/457] eth: fbnic: use the Rx queue napi pointer to find the napi vector Greg Kroah-Hartman
` (370 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Björn Töpel, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Björn Töpel <bjorn@kernel.org>
[ Upstream commit 1f4c73064a50f53d596c6f1d06d2d700f43c4b32 ]
Standalone channels use one NAPI vector for each Tx and Rx queue.
fbnic's allocation path excludes FBNIC_MAX_TXQS from that layout. A
64-Tx/64-Rx configuration therefore records 128 vectors but allocates
only 64, leaving NULL entries that resource setup dereferences.
Include the maximum vector count in standalone allocation.
Fixes: bc6107771bb4 ("eth: fbnic: Allocate a netdevice and napi vectors with queues")
Signed-off-by: Björn Töpel <bjorn@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942020457.7700.13129750616387075931.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
index 661dee1661afe..a30aa44508487 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
@@ -1791,7 +1791,7 @@ int fbnic_alloc_napi_vectors(struct fbnic_net *fbn)
int err;
/* Allocate 1 Tx queue per napi vector */
- if (num_napi < FBNIC_MAX_TXQS && num_napi == num_tx + num_rx) {
+ if (num_napi <= FBNIC_MAX_TXQS && num_napi == num_tx + num_rx) {
while (num_tx) {
err = fbnic_alloc_napi_vector(fbd, fbn,
num_napi, v_idx,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 098/457] eth: fbnic: use the Rx queue napi pointer to find the napi vector
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 097/457] eth: fbnic: Handle maximum standalone channels Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 099/457] eth: fbnic: reset num_napi when the napi vectors are freed Greg Kroah-Hartman
` (369 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexanderduyck@fb.com>
[ Upstream commit b5d9e9d4d0c13bc8b60d8d97e7a07fb25fea639e ]
The queue management ndos pick the napi vector for an Rx queue with:
nv = fbn->napi[idx % fbn->num_napi];
The issue is this is only correct in the cases where there are no
standalone Tx vectors. In those cases we were allocating the Tx vectors
first and then the Rx so the queues would be pointing to Tx NAPI vectors
instead of the Rx ones.
The mapping the ndos want is already recorded. fbnic_set_netif_napi()
publishes it with netif_queue_set_napi(), which stores the napi pointer
in netdev_rx_queue.napi, and fbnic_reset_netif_napi() clears it again.
Both run under the netdev instance lock that the queue management ndos
also hold, so the pointer can be read directly.
Use it and drop the divide. The pointer is NULL exactly while the
datapath is down, so fbnic_queue_mem_alloc() can reject that case rather
than reaching into freed state: netdev_rx_queue_restart() calls it
before it tests netif_running(), and fbnic_pm_suspend() leaves
netif_running() true across a PCIe recovery that never completes, so a
queue restart can arrive after fbnic_stop() has freed the rings and the
vectors. fbnic_stop() clears the association in
fbnic_reset_netif_queues() before fbnic_free_napi_vectors(), so the
NULL is always published first. fbnic_queue_start() and
fbnic_queue_stop() need no check of their own, as
netdev_rx_queue_reconfig() only reaches them once fbnic_queue_mem_alloc()
has succeeded under the same instance lock.
Fixes: da43127a8edc ("eth: fbnic: support queue ops / zero-copy Rx")
Signed-off-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942021136.7700.4391219358260544104.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 26 +++++++++++++++++---
1 file changed, 23 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
index a30aa44508487..10caacffee0f0 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
@@ -7,6 +7,7 @@
#include <linux/iopoll.h>
#include <linux/pci.h>
#include <net/netdev_queues.h>
+#include <net/netdev_rx_queue.h>
#include <net/page_pool/helpers.h>
#include <net/tcp.h>
#include <net/xdp.h>
@@ -2853,6 +2854,17 @@ void fbnic_napi_depletion_check(struct net_device *netdev)
fbnic_wrfl(fbd);
}
+/* Returns the napi vector servicing an Rx queue, or NULL if the datapath
+ * is torn down. The association is published by fbnic_set_netif_napi()
+ * and cleared by fbnic_reset_netif_napi(), both under the instance lock.
+ */
+static struct fbnic_napi_vector *fbnic_rxq_nv(struct net_device *dev, int idx)
+{
+ struct napi_struct *napi = __netif_get_rx_queue(dev, idx)->napi;
+
+ return napi ? container_of(napi, struct fbnic_napi_vector, napi) : NULL;
+}
+
static int fbnic_queue_mem_alloc(struct net_device *dev,
struct netdev_queue_config *qcfg,
void *qmem, int idx)
@@ -2865,8 +2877,16 @@ static int fbnic_queue_mem_alloc(struct net_device *dev,
if (!netif_running(dev))
return fbnic_alloc_qt_page_pools(fbn, qt, idx);
+ /* A failed PCIe recovery or resume can leave the datapath torn down
+ * while netif_running() is still true. This ndo runs before
+ * netdev_rx_queue_restart() checks netif_running(), so bail out
+ * rather than touching rings and vectors that are already freed.
+ */
+ nv = fbnic_rxq_nv(dev, idx);
+ if (!nv)
+ return -ENETDOWN;
+
real = container_of(fbn->rx[idx], struct fbnic_q_triad, cmpl);
- nv = fbn->napi[idx % fbn->num_napi];
fbnic_ring_init(&qt->sub0, real->sub0.doorbell, real->sub0.q_idx,
real->sub0.flags);
@@ -2917,7 +2937,7 @@ static int fbnic_queue_start(struct net_device *dev,
struct fbnic_q_triad *real;
real = container_of(fbn->rx[idx], struct fbnic_q_triad, cmpl);
- nv = fbn->napi[idx % fbn->num_napi];
+ nv = fbnic_rxq_nv(dev, idx);
fbnic_aggregate_ring_bdq_counters(fbn, &real->sub0);
fbnic_aggregate_ring_bdq_counters(fbn, &real->sub1);
@@ -2939,7 +2959,7 @@ static int fbnic_queue_stop(struct net_device *dev, void *qmem, int idx)
int err;
real = container_of(fbn->rx[idx], struct fbnic_q_triad, cmpl);
- nv = fbn->napi[idx % fbn->num_napi];
+ nv = fbnic_rxq_nv(dev, idx);
fbnic_dbg_nv_exit(nv);
napi_disable_locked(&nv->napi);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 099/457] eth: fbnic: reset num_napi when the napi vectors are freed
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 098/457] eth: fbnic: use the Rx queue napi pointer to find the napi vector Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 100/457] eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox Greg Kroah-Hartman
` (368 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexanderduyck@fb.com>
[ Upstream commit 4bcc4a92c603fe7f062cea22e20da2e0ad6b12c3 ]
fbn->num_napi is the count of live napi vectors, each of which owns an
IRQ. The PM path had freed them without clearing the count.
fbnic_pm_suspend() tears the datapath down via ndo_stop() and frees the
IRQs, but leaves netif_running() true so resume knows to re-open. Resume
rebuilds the datapath in __fbnic_pm_resume() and fbnic_reset_queues() sets
num_napi and __fbnic_open() re-allocates the vectors.
When the datapath is torn down but never rebuilt, num_napi is left
pointing at freed vectors under 2 different scenarios:
- a PCIe error recovery that fails (fbnic_err_slot_reset() ->
__fbnic_pm_resume() returns an error -> PCI_ERS_RESULT_DISCONNECT), so
.resume never runs; or
- an __fbnic_open() that fails partway on resume and unwinds, freeing
the vectors after fbnic_reset_queues() has already set num_napi.
The netdev is then running with num_napi > 0 but napi[] freed, and the
eventual remove/unbind close re-enters fbnic_down() -> fbnic_dbg_down()
and dereferences the freed vectors:
BUG: kernel NULL pointer dereference, address: 0000000000000210
RIP: fbnic_dbg_down+0x28
Clear num_napi when the vectors are freed: in the suspend teardown (a
good resume re-establishes it before __fbnic_open()) and on the resume
open failure. A redundant ndo_stop() then walks an empty napi[]. The
normal ndo_stop() down/up cycle is untouched and keeps num_napi for the
next ndo_open().
Fixes: bc6107771bb4 ("eth: fbnic: Allocate a netdevice and napi vectors with queues")
Signed-off-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942021809.7700.10804028989308077839.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_pci.c | 18 ++++++++++++++----
1 file changed, 14 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_pci.c b/drivers/net/ethernet/meta/fbnic/fbnic_pci.c
index 8b9bc9e8ea56c..c6698e3002a13 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_pci.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_pci.c
@@ -434,6 +434,7 @@ static int fbnic_pm_suspend(struct device *dev)
{
struct fbnic_dev *fbd = dev_get_drvdata(dev);
struct net_device *netdev = fbd->netdev;
+ struct fbnic_net *fbn;
if (fbnic_init_failure(fbd))
goto null_uc_addr;
@@ -441,11 +442,16 @@ static int fbnic_pm_suspend(struct device *dev)
rtnl_lock();
netdev_lock(netdev);
+ fbn = netdev_priv(netdev);
+
netif_device_detach(netdev);
if (netif_running(netdev))
netdev->netdev_ops->ndo_stop(netdev);
+ /* The IRQs are about to be freed, so drop the napi vector count */
+ fbn->num_napi = 0;
+
netdev_unlock(netdev);
rtnl_unlock();
@@ -508,16 +514,20 @@ static int __fbnic_pm_resume(struct device *dev)
if (fbnic_init_failure(fbd))
return 0;
+ rtnl_lock();
+ netdev_lock(netdev);
+
fbn = netdev_priv(netdev);
/* Reset the queues if needed */
fbnic_reset_queues(fbn, fbn->num_tx_queues, fbn->num_rx_queues);
- rtnl_lock();
- netdev_lock(netdev);
-
- if (netif_running(netdev))
+ if (netif_running(netdev)) {
err = __fbnic_open(fbn);
+ /* On failure the vectors are freed, so drop the count */
+ if (err)
+ fbn->num_napi = 0;
+ }
netdev_unlock(netdev);
rtnl_unlock();
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 100/457] eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 099/457] eth: fbnic: reset num_napi when the napi vectors are freed Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 101/457] eth: fbnic: Handle FW mailbox completions flagged with an error Greg Kroah-Hartman
` (367 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexanderduyck@fb.com>
[ Upstream commit 8947f13e436a4ff5eed9f8f019b2865a07af4bb2 ]
When tearing down the FW mailbox Rx ring, fbnic_mbx_reset_desc_ring()
writes AW_CFG with FLUSH set and everything else, BME included, cleared.
Clearing BME halts the device's writes to the host but leaves the staged
requests parked in the PUL write pipeline rather than draining them, so
on the write path FLUSH alone never terminates the outstanding requests
and the flush the firmware waits on never completes.
Add the FLUSH_MODE definition and set both bits so the staged writes
drain out of the pipeline on their own. BME stays cleared, so nothing
lands on the host; it is restored later in fbnic_mbx_init_desc_ring()
when the ring is rebuilt, once the outstanding writes are gone.
The read path is unaffected. AR_CFG has no equivalent mode bit and
AR_FLUSH terminates the outstanding reads by itself, so it is left as
is.
Both writes remain plain stores rather than read-modify-writes. That is
deliberate: the matching write in fbnic_mbx_init_desc_ring() restores
BME and the TLP attributes, and clears both flush bits as a side effect.
Fixes: 3b12f00ddd08 ("fbnic: Gate AXI read/write enabling on FW mailbox")
Signed-off-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942022583.7700.11050671998277309744.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_csr.h | 1 +
drivers/net/ethernet/meta/fbnic/fbnic_fw.c | 9 ++++++++-
2 files changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_csr.h b/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
index 64b958df77744..14af30e189d6c 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
@@ -974,6 +974,7 @@ enum {
/* PUL User Registers */
#define FBNIC_CSR_START_PUL_USER 0x31000 /* CSR section delimiter */
#define FBNIC_PUL_OB_TLP_HDR_AW_CFG 0x3103d /* 0xc40f4 */
+#define FBNIC_PUL_OB_TLP_HDR_AW_CFG_FLUSH_MODE CSR_BIT(20)
#define FBNIC_PUL_OB_TLP_HDR_AW_CFG_FLUSH CSR_BIT(19)
#define FBNIC_PUL_OB_TLP_HDR_AW_CFG_BME CSR_BIT(18)
#define FBNIC_PUL_OB_TLP_HDR_AW_CFG_RDE_ATTR CSR_GENMASK(17, 15)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_fw.c b/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
index 283d25fae79e7..59aa879798b9f 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
@@ -60,8 +60,15 @@ static void fbnic_mbx_reset_desc_ring(struct fbnic_dev *fbd, int mbx_idx)
*/
switch (mbx_idx) {
case FBNIC_IPC_MBX_RX_IDX:
+ /* Clearing BME blocks the device from writing to the host
+ * but leaves the requests parked in the write pipeline. The
+ * write path only clears outstanding requests when both FLUSH
+ * and FLUSH_MODE are set; FLUSH_MODE lets them drain without
+ * landing on the host.
+ */
wr32(fbd, FBNIC_PUL_OB_TLP_HDR_AW_CFG,
- FBNIC_PUL_OB_TLP_HDR_AW_CFG_FLUSH);
+ FBNIC_PUL_OB_TLP_HDR_AW_CFG_FLUSH |
+ FBNIC_PUL_OB_TLP_HDR_AW_CFG_FLUSH_MODE);
break;
case FBNIC_IPC_MBX_TX_IDX:
wr32(fbd, FBNIC_PUL_OB_TLP_HDR_AR_CFG,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 101/457] eth: fbnic: Handle FW mailbox completions flagged with an error
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 100/457] eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 102/457] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
` (366 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Duyck <alexanderduyck@fb.com>
[ Upstream commit 1b97a269a5bdde20d4e69511f27649c9cb82b7c7 ]
The firmware can complete a mailbox descriptor while also setting FW_ERR
to indicate it could not process the request, for example on a mailbox
DMA error. The completion carries no valid data.
The driver did not check FW_ERR. On the Rx mailbox it would sync and
parse the stale page as a normal message, and on the Tx mailbox it
silently freed the request. If the initial capabilities exchange in
fbnic_mbx_poll_tx_ready() hit FW_ERR -- on the Tx request or on the Rx
response descriptor -- no response was parsed and the poll spun until it
timed out even though the ring was healthy.
Check FW_ERR on both mailboxes. Count it per-mailbox in
fbnic_fw_mbx.resp_error, which is also shown in debugfs, warn (rate
limited, since the bit is firmware controlled), and drop the Rx page
instead of parsing it.
In fbnic_mbx_poll_tx_ready() re-issue the capabilities request when
either the Tx or the Rx resp_error counter advances, so a FW_ERR on the
request or on its response triggers a retry rather than a timeout. A
valid capabilities response is honored before the retry check, so a
response parsed in the same poll as an unrelated FW_ERR is not discarded.
The counters are mailbox-wide rather than keyed to the capabilities
request; that is sufficient here because the exchange runs during
bring-up before any other mailbox traffic, and any spurious retry is
bounded by the existing 10s timeout.
Fixes: da3cde08209e ("eth: fbnic: Add FW communication mechanism")
Signed-off-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/178942023343.7700.9423398932961964439.stgit@ahduyck-xeon-server.home.arpa
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_csr.h | 4 ++
.../net/ethernet/meta/fbnic/fbnic_debugfs.c | 4 +-
drivers/net/ethernet/meta/fbnic/fbnic_fw.c | 38 ++++++++++++++++++-
drivers/net/ethernet/meta/fbnic/fbnic_fw.h | 1 +
4 files changed, 44 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_csr.h b/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
index 14af30e189d6c..baba3471bf5a4 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_csr.h
@@ -1216,6 +1216,10 @@ enum {
#define FBNIC_IPC_MBX_DESC_LEN_MASK DESC_GENMASK(63, 48)
#define FBNIC_IPC_MBX_DESC_EOM DESC_BIT(46)
#define FBNIC_IPC_MBX_DESC_ADDR_MASK DESC_GENMASK(45, 3)
+/* Set with FW_CMPL when the FW completed a descriptor without successfully
+ * processing it (e.g. a mailbox DMA error); the completion has no valid data.
+ */
+#define FBNIC_IPC_MBX_DESC_FW_ERR DESC_BIT(2)
#define FBNIC_IPC_MBX_DESC_FW_CMPL DESC_BIT(1)
#define FBNIC_IPC_MBX_DESC_HOST_CMPL DESC_BIT(0)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_debugfs.c b/drivers/net/ethernet/meta/fbnic/fbnic_debugfs.c
index 3c4563c8f403f..6edfa0aa69f11 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_debugfs.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_debugfs.c
@@ -539,8 +539,8 @@ static void fbnic_dbg_fw_mbx_display(struct seq_file *s,
/* Generate header */
seq_puts(s, mbx_idx == FBNIC_IPC_MBX_RX_IDX ? "Rx\n" : "Tx\n");
- seq_printf(s, "Rdy: %d Head: %d Tail: %d\n",
- mbx->ready, mbx->head, mbx->tail);
+ seq_printf(s, "Rdy: %d Head: %d Tail: %d resp_error: %llu\n",
+ mbx->ready, mbx->head, mbx->tail, mbx->resp_error);
snprintf(hdr, sizeof(hdr), "%3s %-4s %s %-12s %s %-3s %-16s\n",
"Idx", "Len", "E", "Addr", "F", "H", "Raw");
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_fw.c b/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
index 59aa879798b9f..6d7eb8479edf4 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_fw.c
@@ -292,6 +292,12 @@ static void fbnic_mbx_process_tx_msgs(struct fbnic_dev *fbd)
if (!(desc & FBNIC_IPC_MBX_DESC_FW_CMPL))
break;
+ if (desc & FBNIC_IPC_MBX_DESC_FW_ERR) {
+ tx_mbx->resp_error++;
+ dev_warn_ratelimited(fbd->dev,
+ "FW completed a Tx mailbox request with an error\n");
+ }
+
fbnic_mbx_unmap_and_free_msg(fbd, FBNIC_IPC_MBX_TX_IDX, head);
head++;
@@ -1673,6 +1679,13 @@ static void fbnic_mbx_process_rx_msgs(struct fbnic_dev *fbd)
if (!(desc & FBNIC_IPC_MBX_DESC_FW_CMPL))
break;
+ if (desc & FBNIC_IPC_MBX_DESC_FW_ERR) {
+ rx_mbx->resp_error++;
+ dev_warn_ratelimited(fbd->dev,
+ "FW reported an error on an Rx mailbox message; dropping\n");
+ goto next_page;
+ }
+
dma_sync_single_for_cpu(fbd->dev, rx_mbx->buf_info[head].addr,
FBNIC_RX_PAGE_SIZE, DMA_FROM_DEVICE);
@@ -1740,7 +1753,9 @@ void fbnic_mbx_poll(struct fbnic_dev *fbd)
int fbnic_mbx_poll_tx_ready(struct fbnic_dev *fbd)
{
struct fbnic_fw_mbx *tx_mbx = &fbd->mbx[FBNIC_IPC_MBX_TX_IDX];
+ struct fbnic_fw_mbx *rx_mbx = &fbd->mbx[FBNIC_IPC_MBX_RX_IDX];
unsigned long timeout = jiffies + 10 * HZ + 1;
+ u64 tx_resp_error, rx_resp_error;
int err, i;
do {
@@ -1771,6 +1786,9 @@ int fbnic_mbx_poll_tx_ready(struct fbnic_dev *fbd)
* mgmt.version once we get the actual version from the firmware
* in the capabilities request message.
*/
+send_cap_req:
+ tx_resp_error = tx_mbx->resp_error;
+ rx_resp_error = rx_mbx->resp_error;
err = fbnic_fw_xmit_simple_msg(fbd, FBNIC_TLV_MSG_ID_HOST_CAP_REQ);
if (err)
goto clean_mbx;
@@ -1788,9 +1806,27 @@ int fbnic_mbx_poll_tx_ready(struct fbnic_dev *fbd)
msleep(20);
fbnic_mbx_poll(fbd);
+ /* A valid capabilities response ends the poll. Check it
+ * before the FW_ERR retry below so a response parsed in the
+ * same poll as an unrelated FW_ERR is not discarded.
+ */
+ if (fbd->fw_cap.running.mgmt.version >= MIN_FW_VER_CODE)
+ break;
+
/* set err, but wait till mgmt.version check to report it */
- if (!time_is_after_jiffies(timeout))
+ if (!time_is_after_jiffies(timeout)) {
err = -ETIMEDOUT;
+ continue;
+ }
+
+ /* The FW can flag our capabilities request (Tx) or its
+ * response (Rx) with FW_ERR, in which case it produced no
+ * usable response. The ring is not wedged, so re-issue the
+ * request instead of spinning until the timeout.
+ */
+ if (tx_mbx->resp_error != tx_resp_error ||
+ rx_mbx->resp_error != rx_resp_error)
+ goto send_cap_req;
}
return 0;
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_fw.h b/drivers/net/ethernet/meta/fbnic/fbnic_fw.h
index d84723e4cfa36..5f9969247e305 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_fw.h
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_fw.h
@@ -13,6 +13,7 @@ struct fbnic_tlv_msg;
struct fbnic_fw_mbx {
u8 ready, head, tail;
+ u64 resp_error;
struct {
struct fbnic_tlv_msg *msg;
dma_addr_t addr;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 102/457] sctp: avoid livelock while updating retransmit path
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 101/457] eth: fbnic: Handle FW mailbox completions flagged with an error Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 103/457] net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset Greg Kroah-Hartman
` (365 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yiqi Sun, Xin Long, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yiqi Sun <sunyiqixm@gmail.com>
[ Upstream commit d2c31b837406395e576afeb25958c98e9938f3f6 ]
sctp_assoc_update_retran_path() can loop forever when every remaining
transport, including retran_path, is SCTP_UNCONFIRMED: the state check
runs before the wraparound test, so the loop cannot observe that it has
completed a full pass.
Fix this by considering a transport only when it is not UNCONFIRMED,
then checking whether the walk has returned to retran_path. This makes
the full-pass termination independent of the transport state while
preserving the existing fallback selection semantics.
Also restore the NULL guard around the retran_path assignment. In the
all-UNCONFIRMED case there is no eligible replacement transport, and
installing NULL would leave later retransmit-path users and the debug
print with a NULL path.
Fixes: 4c47af4d5eb2 ("net: sctp: rework multihoming retransmission path selection to rfc4960")
Signed-off-by: Yiqi Sun <sunyiqixm@gmail.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260915095017.942213-1-sunyiqixm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/associola.c | 15 ++++++++-------
1 file changed, 8 insertions(+), 7 deletions(-)
diff --git a/net/sctp/associola.c b/net/sctp/associola.c
index 5be0bed2685ee..1220ff909fbe3 100644
--- a/net/sctp/associola.c
+++ b/net/sctp/associola.c
@@ -1285,18 +1285,19 @@ void sctp_assoc_update_retran_path(struct sctp_association *asoc)
/* Manually skip the head element. */
if (&trans->transports == &asoc->peer.transport_addr_list)
continue;
- if (trans->state == SCTP_UNCONFIRMED)
- continue;
- trans_next = sctp_trans_elect_best(trans, trans_next);
- /* Active is good enough for immediate return. */
- if (trans_next->state == SCTP_ACTIVE)
- break;
+ if (trans->state != SCTP_UNCONFIRMED) {
+ trans_next = sctp_trans_elect_best(trans, trans_next);
+ /* Active is good enough for immediate return. */
+ if (trans_next->state == SCTP_ACTIVE)
+ break;
+ }
/* We've reached the end, time to update path. */
if (trans == asoc->peer.retran_path)
break;
}
- asoc->peer.retran_path = trans_next;
+ if (trans_next)
+ asoc->peer.retran_path = trans_next;
pr_debug("%s: association:%p updated new path to addr:%pISpc\n",
__func__, asoc, &asoc->peer.retran_path->ipaddr.sa);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 103/457] net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 102/457] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 104/457] bpf: Bound ownership depth through local kptrs and graph roots Greg Kroah-Hartman
` (364 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Quentin Armitage, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quentin Armitage <quentin@armitage.org.uk>
[ Upstream commit 6c096bb08de97cdca051fecddad22cac6a1fd275 ]
Commit fa8fca88714c ("ipv4: validate IPV4_DEVCONF attributes properly")
added validation of IFLA_INET_CONF attributes, and in the process
changed the call of nla_for_each_nested() to nla_parse_nested(). A
side effect of this change is that the IFLA_INET_CONF option is now
tested for NLA_F_NESTED being set, and fails if it is not. Prior to the
commit there was no check of NLA_F_NESTED.
Change nla_parse_nested() to nla_parse(). This restores the previous
functionality of not checking NLA_F_NESTED, thereby allowing code that
(incorrectly) doesn't set NLA_F_NESTED to continue to work.
This issue was identified because keepalived started logging errors when
it was configuring macvlans that it created.
Fixes: fa8fca88714c ("ipv4: validate IPV4_DEVCONF attributes properly")
Signed-off-by: Quentin Armitage <quentin@armitage.org.uk>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260915213320.1527029-2-quentin@armitage.org.uk
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/devinet.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/net/ipv4/devinet.c b/net/ipv4/devinet.c
index a35b72662e431..a80896647154c 100644
--- a/net/ipv4/devinet.c
+++ b/net/ipv4/devinet.c
@@ -2117,9 +2117,10 @@ static int inet_validate_link_af(const struct net_device *dev,
return err;
if (tb[IFLA_INET_CONF]) {
- err = nla_parse_nested(nested_tb, IPV4_DEVCONF_MAX,
- tb[IFLA_INET_CONF], inet_devconf_policy,
- extack);
+ err = nla_parse(nested_tb, IPV4_DEVCONF_MAX,
+ nla_data(tb[IFLA_INET_CONF]),
+ nla_len(tb[IFLA_INET_CONF]),
+ inet_devconf_policy, extack);
if (err < 0)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 104/457] bpf: Bound ownership depth through local kptrs and graph roots
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 103/457] net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 105/457] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
` (363 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini,
Kumar Kartikeya Dwivedi, Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit bfc888f04588f591851e95c974954cfca58e6c19 ]
Program-allocated objects can own other local objects through referenced
kptrs. bpf_obj_free_fields() follows those pointers through
__bpf_obj_drop_impl() synchronously, before the object storage is freed
through RCU. A self-referential local kptr type therefore permits arbitrarily
deep object chains, and dropping the head can exhaust the kernel stack.
Long acyclic type chains have the same problem.
btf_check_and_fixup_fields() still assumes referenced kptrs only point to
kernel types and checks ownership through list and rbtree roots only. Its
existing rule is sufficient for graph-only cycles: the target of each graph
edge must contain a node, so every type in a cycle has both a root and a
node. The rule rejects such a type owning another root, breaking every
cycle. It also limits graph-only chains to three types, or two if the first
type contains a node, and conservatively rejects longer acyclic chains.
The missing local-kptr edges, rather than a missed graph-only cycle, are the
bug introduced by support for bpf_kptr_xchg() into local kptrs.
Replace that restriction with one bounded ownership walk covering graph
roots and local referenced kptrs. Run it after all BTF records have been
fixed up, reject cycles and paths deeper than eight record-bearing types,
and cache each type's suffix depth while checking it against the remaining
budget. This also permits the longer acyclic graph-only layouts rejected
by the old rule; update their existing BTF tests accordingly.
Keep the bound independent of MAX_CALL_FRAMES because recursive destruction
can run below a BPF call chain. A plain local pointee without special-field
metadata adds only a final non-recursing drop. Non-owning kptrs and
kernel-BTF kptrs do not recurse through local records and remain outside the
walk. Include local percpu-kptr edges too, although allocation of percpu
objects with special fields is currently forbidden, so that relaxing that
restriction cannot bypass the ownership bound.
btf_check_and_fixup_fields() continues to initialize graph_root.value_rec,
including for separately allocated map records. The ownership relationships
belong to immutable program BTF and only need validation at BTF load time.
Fixes: b0966c724584 ("bpf: Support bpf_kptr_xchg into local kptr")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260914132444.2564218-2-memxor@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 134 +++++++++++-------
.../selftests/bpf/prog_tests/linked_list.c | 4 +-
2 files changed, 88 insertions(+), 50 deletions(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index ea3d50c99ec22..c4df013bf0066 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -4269,13 +4269,10 @@ int btf_check_and_fixup_fields(const struct btf *btf, struct btf_record *rec)
{
int i;
- /* There are three types that signify ownership of some other type:
- * kptr_ref, bpf_list_head, bpf_rb_root.
- * kptr_ref only supports storing kernel types, which can't store
- * references to program allocated local types.
- *
- * Hence we only need to ensure that bpf_{list_head,rb_root} ownership
- * does not form cycles.
+ /*
+ * Check fields which require the complete BTF and initialize runtime
+ * metadata. Ownership relationships are validated after every record has
+ * been fixed up.
*/
if (IS_ERR_OR_NULL(rec) || !(rec->field_mask & (BPF_GRAPH_ROOT | BPF_UPTR)))
return 0;
@@ -4306,51 +4303,88 @@ int btf_check_and_fixup_fields(const struct btf *btf, struct btf_record *rec)
if (!meta)
return -EFAULT;
rec->fields[i].graph_root.value_rec = meta->record;
+ }
+ return 0;
+}
- /* We need to set value_rec for all root types, but no need
- * to check ownership cycle for a type unless it's also a
- * node type.
- */
- if (!(rec->field_mask & BPF_GRAPH_NODE))
+static int btf_owned_type_idx(const struct btf *btf, struct btf_struct_metas *tab,
+ const struct btf_field *field)
+{
+ struct btf_struct_meta *meta;
+ u32 btf_id;
+
+ if (field->type & BPF_GRAPH_ROOT) {
+ btf_id = field->graph_root.value_btf_id;
+ } else if (field->type == BPF_KPTR_REF || field->type == BPF_KPTR_PERCPU) {
+ if (btf_is_kernel(field->kptr.btf))
+ return -ENOENT;
+ btf_id = field->kptr.btf_id;
+ } else {
+ return -ENOENT;
+ }
+
+ meta = btf_find_struct_meta(btf, btf_id);
+ if (!meta)
+ return field->type & BPF_GRAPH_ROOT ? -EFAULT : -ENOENT;
+ return meta - tab->types;
+}
+
+/*
+ * Each ownership edge adds kernel frames through bpf_obj_free_fields() and
+ * __bpf_obj_drop_impl(). Keep the bound deliberately small because object
+ * destruction can itself run below a BPF call chain. A final pointee without
+ * special fields is not present in the struct metadata table and adds only a
+ * non-recursing drop.
+ */
+#define BTF_MAX_OWNERSHIP_DEPTH 8
+
+static int btf_ownership_depth(const struct btf *btf,
+ struct btf_struct_metas *tab, u8 *depth,
+ int idx, int depth_left)
+{
+ const struct btf_record *rec = tab->types[idx].record;
+ int i, ret, max_depth = 0;
+
+ if (!depth_left)
+ return -ELOOP;
+ if (depth[idx])
+ goto done;
+
+ for (i = 0; i < rec->cnt; i++) {
+ ret = btf_owned_type_idx(btf, tab, &rec->fields[i]);
+ if (ret == -ENOENT)
continue;
+ if (ret < 0)
+ return ret;
+ ret = btf_ownership_depth(btf, tab, depth, ret, depth_left - 1);
+ if (ret < 0)
+ return ret;
+ max_depth = max(max_depth, ret);
+ }
+ depth[idx] = max_depth + 1;
+done:
+ return depth[idx] > depth_left ? -ELOOP : depth[idx];
+}
- /* We need to ensure ownership acyclicity among all types. The
- * proper way to do it would be to topologically sort all BTF
- * IDs based on the ownership edges, since there can be multiple
- * bpf_{list_head,rb_node} in a type. Instead, we use the
- * following resaoning:
- *
- * - A type can only be owned by another type in user BTF if it
- * has a bpf_{list,rb}_node. Let's call these node types.
- * - A type can only _own_ another type in user BTF if it has a
- * bpf_{list_head,rb_root}. Let's call these root types.
- *
- * We ensure that if a type is both a root and node, its
- * element types cannot be root types.
- *
- * To ensure acyclicity:
- *
- * When A is an root type but not a node, its ownership
- * chain can be:
- * A -> B -> C
- * Where:
- * - A is an root, e.g. has bpf_rb_root.
- * - B is both a root and node, e.g. has bpf_rb_node and
- * bpf_list_head.
- * - C is only an root, e.g. has bpf_list_node
- *
- * When A is both a root and node, some other type already
- * owns it in the BTF domain, hence it can not own
- * another root type through any of the ownership edges.
- * A -> B
- * Where:
- * - A is both an root and node.
- * - B is only an node.
- */
- if (meta->record->field_mask & BPF_GRAPH_ROOT)
- return -ELOOP;
+static int btf_check_ownership_depth(const struct btf *btf,
+ struct btf_struct_metas *tab)
+{
+ u8 *depth;
+ int i, ret = 0;
+
+ depth = kvcalloc(tab->cnt, sizeof(*depth), GFP_KERNEL | __GFP_NOWARN);
+ if (!depth)
+ return -ENOMEM;
+
+ for (i = 0; i < tab->cnt; i++) {
+ ret = btf_ownership_depth(btf, tab, depth, i,
+ BTF_MAX_OWNERSHIP_DEPTH);
+ if (ret < 0)
+ break;
+ ret = 0;
}
- return 0;
+ kvfree(depth);
+ return ret;
}
static void __btf_struct_show(const struct btf *btf, const struct btf_type *t,
@@ -6045,6 +6079,10 @@ static struct btf *btf_parse(const union bpf_attr *attr, bpfptr_t uattr,
if (err < 0)
goto errout_meta;
}
+
+ err = btf_check_ownership_depth(btf, struct_meta_tab);
+ if (err < 0)
+ goto errout_meta;
}
err = bpf_log_attr_finalize(attr_log, &env->log);
diff --git a/tools/testing/selftests/bpf/prog_tests/linked_list.c b/tools/testing/selftests/bpf/prog_tests/linked_list.c
index 8defea0253ed9..178d133d59238 100644
--- a/tools/testing/selftests/bpf/prog_tests/linked_list.c
+++ b/tools/testing/selftests/bpf/prog_tests/linked_list.c
@@ -713,7 +713,7 @@ static void test_btf(void)
break;
err = btf__load_into_kernel(btf);
- ASSERT_EQ(err, -ELOOP, "check btf");
+ ASSERT_EQ(err, 0, "check btf");
btf__free(btf);
break;
}
@@ -772,7 +772,7 @@ static void test_btf(void)
break;
err = btf__load_into_kernel(btf);
- ASSERT_EQ(err, -ELOOP, "check btf");
+ ASSERT_EQ(err, 0, "check btf");
btf__free(btf);
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 105/457] net: usb: catc: bound the RX packet length in catc_rx_done()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 104/457] bpf: Bound ownership depth through local kptrs and graph roots Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 106/457] bpf: Check params size before reading reserved fields Greg Kroah-Hartman
` (362 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
[ Upstream commit 9d565b6b72fe3f41fd43636e143072848105189f ]
catc_rx_done() walks a multi-packet URB, reading a two-byte length from
each packet header. Its bound, pkt_len > urb->actual_length, ignores the
header offset and compares against the whole transfer rather than the
bytes left from pkt_start, so a crafted packet header makes
skb_copy_to_linear_data() read past the buffer.
A length below ETH_HLEN is also accepted, including zero, and
eth_type_trans() then reads a MAC header from the uninitialised tailroom
of a shorter skb. The is_f5u011 branch takes its length straight from
the transfer, so a zero-length URB reaches the same path.
Track the bytes remaining from the current packet, and reject a header
that does not fit, a length past what is left, and a length below an
Ethernet header.
A transfer shorter than an Ethernet header, including a zero-length one,
previously became a runt skb passed to netif_rx() and counted as
received; it is now counted in rx_length_errors and ends the walk.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/AS8P251MB00015FD7716F38C345619B56C8BB2@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/catc.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/net/usb/catc.c b/drivers/net/usb/catc.c
index 96e82f94edcf8..39b678f175dd9 100644
--- a/drivers/net/usb/catc.c
+++ b/drivers/net/usb/catc.c
@@ -233,17 +233,26 @@ static void catc_rx_done(struct urb *urb)
}
do {
- if(!catc->is_f5u011) {
- pkt_len = le16_to_cpup((__le16*)pkt_start);
- if (pkt_len > urb->actual_length) {
+ int remaining = urb->actual_length -
+ (pkt_start - (u8 *)urb->transfer_buffer);
+
+ if (!catc->is_f5u011) {
+ if (remaining < pkt_offset) {
catc->netdev->stats.rx_length_errors++;
catc->netdev->stats.rx_errors++;
break;
}
+ pkt_len = le16_to_cpup((__le16 *)pkt_start);
} else {
pkt_len = urb->actual_length;
}
+ if (pkt_len < ETH_HLEN || pkt_len + pkt_offset > remaining) {
+ catc->netdev->stats.rx_length_errors++;
+ catc->netdev->stats.rx_errors++;
+ break;
+ }
+
if (!(skb = dev_alloc_skb(pkt_len)))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 106/457] bpf: Check params size before reading reserved fields
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 105/457] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 107/457] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
` (361 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Yuqi Xu, Alexei Starovoitov,
Ren Wei, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuqi Xu <xuyuqiabc@gmail.com>
[ Upstream commit a11212910cf09b2fe8db9afa41ef60c4f81879c5 ]
bpf_crypto_ctx_create() is a kfunc whose second argument is declared
with the __sz annotation, so the verifier only guarantees that
params__sz bytes of params are valid. The function nevertheless reads
params->reserved[0] and params->reserved[1] (offsets 14 and 15) before
comparing params__sz against the size of struct bpf_crypto_params, so a
BPF program can pass a shorter buffer and have the kernel read past the
region that was validated for it.
Move the size check in front of the reserved field reads.
Fixes: 3e1c6f35409f ("bpf: make common crypto API for TC/XDP programs")
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Ren Wei <weir@nebusec.ai>
Link: https://patch.msgid.link/4f3ab4b03e79017e215521743996555439bf0bb3.1789802413.git.xuyuqiabc@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/crypto.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/kernel/bpf/crypto.c b/kernel/bpf/crypto.c
index 51f89cecefb4d..3f3fe2450fc6c 100644
--- a/kernel/bpf/crypto.c
+++ b/kernel/bpf/crypto.c
@@ -149,8 +149,9 @@ bpf_crypto_ctx_create(const struct bpf_crypto_params *params, u32 params__sz,
const struct bpf_crypto_type *type;
struct bpf_crypto_ctx *ctx;
- if (!params || params->reserved[0] || params->reserved[1] ||
- params__sz != sizeof(struct bpf_crypto_params)) {
+ if (!params ||
+ params__sz != sizeof(struct bpf_crypto_params) ||
+ params->reserved[0] || params->reserved[1]) {
*err = -EINVAL;
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 107/457] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 106/457] bpf: Check params size before reading reserved fields Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 108/457] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
` (360 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini + nipa),
Victor Nogueira, hybris, Jamal Hadi Salim, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 8a60ade2277e1f0e0d0578d565354e52292fa46d ]
hfsc_classify() applies the "filter may only point downwards" level check
only when the filter result carries no bound class. A filter created with
a flowid gets res.class set once at bind time, so the check never runs for
it during classification. hfsc_adjust_levels() can later raise a class's
level without revalidating existing bindings, leaving two binds that were
each legal at bind time pointing at each other; the classify walk then
bounces between two interior classes forever with the qdisc lock held and
BH disabled — a soft lockup from a single packet. The stuck walk trips
the watchdog:
watchdog: BUG: soft lockup - CPU#3 stuck for 13s! [ping:444]
RIP: 0010:u32_classify+0x542/0x17f0
...
tcf_classify+0x66/0xa0
hfsc_enqueue+0x166/0xdf0
Bound the traversal with a budget of non-descending hops, the only way a
configured walk can move without descending the class tree once levels
drift after bind time. The budget is cumulative over the whole walk and
is deliberately not reset on a descending hop: a chain that alternates a
descent with a lateral hop would return the budget every lap and never
trip. Descending hops never decrement it, so legitimately deep trees are
unaffected and a terminating lateral chain still classifies normally.
Drop the packet with a rate-limited warning once the budget is exhausted,
mirroring the merged HTB fix.
This is a follow-up to commit 729c4896ab82 ("net/sched: sch_htb: limit
htb_classify inner-class filter hops"), which bounded the same classify
loop on the HTB side but left the HFSC walk unbounded.
Conditions to recreate the bug:
- CONFIG_NET_SCHED, CONFIG_NET_SCH_HFSC, CONFIG_NET_CLS_U32,
CONFIG_LOCKUP_DETECTOR.
- Build a cycle with two legal-at-bind-time flowid binds and a level
drift: class X 1:1 (child of root) with leaf child 1:10; class Y 1:2
(sibling of X) with children 1:20 and 1:200; root u32 filter flowid
1:1; filter on X flowid 1:2 (legal when Y is a leaf); after Y's level
rises to 2, filter on Y flowid 1:1 (legal then). Send one packet (ping
on the device). Unfixed kernel: classify spins with the qdisc lock
held; with softlockup_panic=1 it panics.
- Reachable from unprivileged user via unshare -Urn (CAP_NET_ADMIN).
Fixes: a2f79227138c ("net_sched: sch_hfsc: fix classification loops")
Reported-by: Sashiko (gemini + nipa) <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/netdev/QDISC-CTUU.v2.20260913192614@mojatatu.com/
Link: https://sashiko.dev/#/patchset/QDISC-CTUU.v2.20260913192614@mojatatu.com
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/QDISC-CTUU.v2.20260913192614%40mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-CTUU.v3.20260916184908@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_hfsc.c | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/net/sched/sch_hfsc.c b/net/sched/sch_hfsc.c
index e87f5021a1995..284490fd6ca91 100644
--- a/net/sched/sch_hfsc.c
+++ b/net/sched/sch_hfsc.c
@@ -386,6 +386,15 @@ cftree_update(struct hfsc_class *cl)
#define SM_MASK ((1ULL << SM_SHIFT) - 1)
#define ISM_MASK ((1ULL << ISM_SHIFT) - 1)
+/*
+ * Cap on the non-descending hops a classify walk may take before its
+ * filter chain is treated as misconfigured. A flowid binding that was
+ * legal at bind time can become lateral once hfsc_adjust_levels()
+ * raises a class level; a few such hops are legitimate, an unbounded
+ * run means the chain cycles.
+ */
+#define HFSC_CLASSIFY_MAX_DRIFT 8
+
static inline u64
seg_x2y(u64 x, u64 sm)
{
@@ -1133,6 +1142,7 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
struct hfsc_class *head, *cl;
struct tcf_result res;
struct tcf_proto *tcf;
+ unsigned int drift;
int result;
if (TC_H_MAJ(skb->priority ^ sch->handle) == 0 &&
@@ -1142,6 +1152,7 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
*qerr = NET_XMIT_SUCCESS | __NET_XMIT_BYPASS;
head = &q->root;
+ drift = HFSC_CLASSIFY_MAX_DRIFT;
tcf = rcu_dereference_bh(q->root.filter_list);
while (tcf && (result = tcf_classify_qdisc(skb, tcf, &res, false)) >= 0) {
#ifdef CONFIG_NET_CLS_ACT
@@ -1167,6 +1178,17 @@ hfsc_classify(struct sk_buff *skb, struct Qdisc *sch, int *qerr)
if (cl->level == 0)
return cl; /* hit leaf class */
+ /*
+ * flowid binds skip the level check above (res.class is set
+ * at bind time and levels drift after), so a walk can follow
+ * lateral hops without descending; a bounded number of them
+ * is legal, more means the chain cycles.
+ */
+ if (cl->level >= head->level && drift-- == 0) {
+ pr_warn_ratelimited("hfsc: classify hop budget exhausted, dropping packet\n");
+ return NULL;
+ }
+
/* apply inner filter chain */
tcf = rcu_dereference_bh(cl->filter_list);
head = cl;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 108/457] drm/virtio: fix object leak when drm_gem_handle_create() fails
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 107/457] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 109/457] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
` (359 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Junrui Luo,
Dmitry Osipenko, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 36570ef2244cc4d7563b1f0157bc0f032498638c ]
virtio_gpu_gem_create() owns the reference taken by
virtio_gpu_object_create(). On the drm_gem_handle_create() error path it
calls drm_gem_object_release() instead of dropping that reference.
drm_gem_object_release() is the inverse of drm_gem_object_init() and does
not touch the reference count or call obj->funcs->free(), so it is only
correct as the last step of a destructor, as in
virtio_gpu_cleanup_object(). Using it here leaves the bo at refcount 1
with no remaining reference, so virtio_gpu_free_object() never runs and
the shmem pages, sg table and virtio_gpu_object are leaked. Since
virtio_gpu_object_create() has already set bo->created,
VIRTIO_GPU_CMD_RESOURCE_UNREF is not queued either, leaking the host-side
resource and the resource id.
drm_gem_handle_create_tail() drops the handle reference on all of its
internal error paths, so the caller only has to drop its own. Use
drm_gem_object_put(), matching the success path below.
Fixes: dc5698e80cf7 ("Add virtio gpu driver.")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-1-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_gem.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_gem.c b/drivers/gpu/drm/virtio/virtgpu_gem.c
index 66c3f6f74e9c6..d2f0b8a3f172b 100644
--- a/drivers/gpu/drm/virtio/virtgpu_gem.c
+++ b/drivers/gpu/drm/virtio/virtgpu_gem.c
@@ -45,7 +45,7 @@ static int virtio_gpu_gem_create(struct drm_file *file,
ret = drm_gem_handle_create(file, &obj->base.base, &handle);
if (ret) {
- drm_gem_object_release(&obj->base.base);
+ drm_gem_object_put(&obj->base.base);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 109/457] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 108/457] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 110/457] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
` (358 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 477bc3068fc3777b9d8ffd79e265b0dfdf2d3a6b ]
virtio_gpu_resource_create_ioctl() calls drm_gem_object_release() on the
drm_gem_handle_create() error path instead of dropping the reference it
owns, so obj->funcs->free() never runs and the virtio_gpu_object, its
pages and sg table, the resource id and the host-side resource are
leaked.
Use drm_gem_object_put() instead.
Fixes: 62fb7a5e1096 ("virtio-gpu: add 3d/virgl support")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-2-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
index 3d8e4ccdb7c1f..d16f07abb266a 100644
--- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
+++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
@@ -185,7 +185,7 @@ static int virtio_gpu_resource_create_ioctl(struct drm_device *dev, void *data,
ret = drm_gem_handle_create(file, obj, &handle);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 110/457] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 109/457] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 111/457] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
` (357 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 24b6d5c7641412c9ebef0d4c8b888d49a0e6b880 ]
virtio_gpu_resource_create_blob_ioctl() calls drm_gem_object_release() on
both the virtio_gpu_resource_assign_uuid() and drm_gem_handle_create()
error paths instead of dropping the reference it owns, so
obj->funcs->free() never runs and the virtio_gpu_object, the resource id
and the host-side resource are leaked.
Use drm_gem_object_put() instead.
Fixes: 897b4d1acaf5 ("drm/virtio: implement blob resources: resource create blob ioctl")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-3-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
index d16f07abb266a..fcdb07a37972c 100644
--- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
+++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
@@ -557,14 +557,14 @@ static int virtio_gpu_resource_create_blob_ioctl(struct drm_device *dev,
if (params.blob_flags & VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE) {
ret = virtio_gpu_resource_assign_uuid(vgdev, bo);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
}
ret = drm_gem_handle_create(file, obj, &handle);
if (ret) {
- drm_gem_object_release(obj);
+ drm_gem_object_put(obj);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 111/457] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 110/457] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 112/457] Revert "drm/virtio: Allow importing prime buffers when 3D is enabled" Greg Kroah-Hartman
` (356 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Junrui Luo, Dmitry Osipenko,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
[ Upstream commit 036d28db1818af2f9d80db771f5405da84d7732d ]
virtio_gpu_vram_create() frees the object with a bare kfree(vram) on
both error paths after drm_gem_private_object_init() has run, and on the
second one after drm_gem_create_mmap_offset() has linked obj->vma_node
into the device's VMA offset manager. The freed object stays in that
interval tree, so a later lookup or insertion walks freed memory, and
the dma_resv and gpuva lock are never destroyed.
Call drm_gem_object_release() before kfree() on both paths.
Fixes: 16845c5d5409 ("drm/virtio: implement blob resources: implement vram object")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260915-fixes-v2-4-a0d799e4db66@outlook.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_vram.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_vram.c b/drivers/gpu/drm/virtio/virtgpu_vram.c
index 4ae3cbc35dd36..683ea17454c2e 100644
--- a/drivers/gpu/drm/virtio/virtgpu_vram.c
+++ b/drivers/gpu/drm/virtio/virtgpu_vram.c
@@ -212,16 +212,12 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *vgdev,
/* Create fake offset */
ret = drm_gem_create_mmap_offset(obj);
- if (ret) {
- kfree(vram);
- return ret;
- }
+ if (ret)
+ goto err_release_obj;
ret = virtio_gpu_resource_id_get(vgdev, &vram->base.hw_res_handle);
- if (ret) {
- kfree(vram);
- return ret;
- }
+ if (ret)
+ goto err_release_obj;
virtio_gpu_cmd_resource_create_blob(vgdev, &vram->base, params, NULL,
0);
@@ -237,6 +233,11 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *vgdev,
*bo_ptr = &vram->base;
return 0;
+
+err_release_obj:
+ drm_gem_object_release(obj);
+ kfree(vram);
+ return ret;
}
void virtio_gpu_vram_map_deferred(struct virtio_gpu_object_vram *vram)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 112/457] Revert "drm/virtio: Allow importing prime buffers when 3D is enabled"
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 111/457] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 113/457] drm/virtio: sync shmem backing on guest-bound transfers Greg Kroah-Hartman
` (355 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Osipenko, Val Packett,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Osipenko <dmitry.osipenko@collabora.com>
[ Upstream commit 1e3b08de63274d0b009e99ef51cd6a9c0c6bf08c ]
Guest userspace may import udmabuf to vrend. Vrend doesn't support guest
blobs, and thus, further 3d operations with the imported blob are failing.
Typical scenario of the problem shown with mouse cursor RGBA image imported
into virtio-gpu, which previously was rejected by virtio-gpu driver.
Revert enabling guest blobs importing into vrend to fix the regression.
Link: https://gitlab.freedesktop.org/virgl/virglrenderer/-/work_items/674
Fixes: df4dc947c46b ("drm/virtio: Allow importing prime buffers when 3D is enabled")
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Val Packett <val@invisiblethingslab.com>
Link: https://patch.msgid.link/20260911144204.2089401-1-dmitry.osipenko@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_prime.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/virtio/virtgpu_prime.c b/drivers/gpu/drm/virtio/virtgpu_prime.c
index 70b3b836e1c99..c2748378a8ad6 100644
--- a/drivers/gpu/drm/virtio/virtgpu_prime.c
+++ b/drivers/gpu/drm/virtio/virtgpu_prime.c
@@ -310,7 +310,7 @@ struct drm_gem_object *virtgpu_gem_prime_import(struct drm_device *dev,
}
}
- if (!vgdev->has_resource_blob)
+ if (!vgdev->has_resource_blob || vgdev->has_virgl_3d)
return drm_gem_prime_import(dev, buf);
bo = kzalloc_obj(*bo);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 113/457] drm/virtio: sync shmem backing on guest-bound transfers
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 112/457] Revert "drm/virtio: Allow importing prime buffers when 3D is enabled" Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 114/457] pinctrl: tegra238: Fix register bank for AON pin groups Greg Kroah-Hartman
` (354 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Benjamin Leggett,
Dmitry Osipenko, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Leggett <benjamin@edera.io>
[ Upstream commit 598c1c3e895590f845e04455d5580ea28ffde666 ]
virtio_gpu_cmd_transfer_to_host_{2d,3d}() sync the shmem backing for the
device before the transfer, but nothing syncs for the CPU when a transfer
runs the other way. That breaks two ways. Where the DMA layer bounces, the
device writes into the bounce buffer while the guest keeps reading the
original pages. Where DMA is not coherent, the device writes memory while
the CPU keeps stale cache lines, because nothing reaches
arch_sync_dma_for_cpu(). Either way DRM_IOCTL_VIRTGPU_TRANSFER_FROM_HOST
hands back stale data.
Sashiko originally found this in
https://lore.kernel.org/dri-devel/20260806231002.27B4D1F000E9@smtp.kernel.org
but the suggestion there to fix this with dma_sync_sgtable_for_cpu()
isn't a sufficient fix, for two reasons.
- The transfer is asynchronous. virtio_gpu_cmd_transfer_from_host_3d() only
queues the command, so a sync there would run before the device had written
anything. It belongs on completion, and ahead of any fence signalling.
A waiter woken by the fence would otherwise race the sync and read the
backing pages regardless. It needs its own pass over the reclaim list
rather than a step inside the existing one, because
virtio_gpu_fence_event_process() also signals every earlier fence in the
same context, so any entry in that loop may signal an earlier entry's
fence.
- The transfer is also partial, carrying an offset, a level and a box.
Where the mapping bounces, a sync for the CPU copies the whole mapping
back, so unless the mapping is primed first the regions the device did not
write come back holding whatever the bounce buffer contained, discarding
data the guest owned.
So the fix: Prime the mapping before queueing, tag the vbuffer, and sync
for the CPU on completion before the fence is signalled.
A second transfer must not snapshot the mapping while an earlier one is
still in flight, or the snapshot would predate whatever the CPU wrote once
the earlier fence signalled and the later sync would discard it.
To mitigate this, wait for outstanding fences under the reservation before
priming.
Neither sync copies anything unless the mapping genuinely bounces:
swiotlb_sync_single_for_cpu() and its Xen counterpart look the address up
in the bounce pool and return early when it is absent. On a platform with
non-coherent DMA they still perform the necessary cache maintenance.
The range cannot be narrowed to the box, since for a non-blob resource
virtio_gpu_transfer_from_host_ioctl() rejects a caller-supplied stride and
layer_stride, leaving the layout to the host and the guest with no way to
work out which bytes the device writes. A host3d guest blob does carry
both, so its extent could be bounded, but the sync is left whole there too
rather than special-cased: priming makes the untouched regions round-trip
unchanged either way.
Behaviour changes worth noting:
- TRANSFER_FROM_HOST can now block, where before it returned as soon as the
command was queued. Repeated readbacks of one resource serialise, and a
readback can wait behind an earlier queued command that touched it, since
virtio_gpu_array_add_fence() tags uploads, execbufs and plane flushes
alike with DMA_RESV_USAGE_WRITE. -ERESTARTSYS was already possible here
via dma_resv_lock_interruptible().
- A CPU write racing an in-flight transfer to the same resource is now
lost, where before it survived and the transfer was lost instead. Priming
captures the pages as of queueing, so a write landing before completion is
overwritten by the sync.
- TRANSFER_TO_HOST can also block now, but only while a guest-bound
transfer on the same resource is outstanding, which happens only for
callers that issue both without waiting.
- Where a batch of completions contains a guest-bound transfer, the sync
pass delays fence signalling for the whole batch. Only bounced pages are
copied and the swiotlb pool bounds it. A batch with no such transfer is
unaffected.
Tested under QEMU on x86 with swiotlb=force and virtio-vga-gl
iommu_platform=on, which forces both preconditions required to hit the
original bug.
Fixes: a3b815f09bb8 ("drm/virtio: add iommu support.")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/dri-devel/20260806231002.27B4D1F000E9@smtp.kernel.org/
Signed-off-by: Benjamin Leggett <benjamin@edera.io>
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/20260814-virtgpu-from-host-sync-v4-1-64dd736b1779@edera.io
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/virtio/virtgpu_drv.h | 5 +++
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 43 ++++++++++++++++++++++++
drivers/gpu/drm/virtio/virtgpu_vq.c | 46 ++++++++++++++++++++++++++
3 files changed, 94 insertions(+)
diff --git a/drivers/gpu/drm/virtio/virtgpu_drv.h b/drivers/gpu/drm/virtio/virtgpu_drv.h
index 88fb4be92cf3e..5610add1da470 100644
--- a/drivers/gpu/drm/virtio/virtgpu_drv.h
+++ b/drivers/gpu/drm/virtio/virtgpu_drv.h
@@ -114,6 +114,8 @@ struct virtio_gpu_object {
bool dumb;
bool created;
bool attached;
+ /* a guest-bound transfer is queued and its mapping not yet synced */
+ bool from_host_pending;
bool host3d_blob, guest_blob;
uint32_t blob_mem, blob_flags;
@@ -192,6 +194,9 @@ struct virtio_gpu_vbuffer {
struct list_head list;
uint32_t seqno;
+
+ /* guest-bound transfer whose shmem backing needs a CPU sync */
+ bool sync_for_cpu;
};
struct virtio_gpu_output {
diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
index fcdb07a37972c..81e70a12b3569 100644
--- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
+++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
@@ -261,6 +261,27 @@ static int virtio_gpu_transfer_from_host_ioctl(struct drm_device *dev,
if (ret != 0)
goto err_put_free;
+ if (virtio_gpu_is_shmem(bo) && virtio_gpu_use_dma_api(vgdev->vdev)) {
+ /*
+ * The sync on completion restores the whole mapping, so an
+ * earlier transfer has to be done before this one snapshots it.
+ * Otherwise the snapshot predates anything the CPU wrote once
+ * that transfer's fence signalled, and the later sync would
+ * discard it. Nothing can add a fence behind our back here,
+ * since doing so takes the reservation we already hold.
+ * This writes the pages, so it waits as a writer does. READ
+ * usage covers existing readers.
+ */
+ long wait = dma_resv_wait_timeout(objs->objs[0]->resv,
+ DMA_RESV_USAGE_READ, true,
+ MAX_SCHEDULE_TIMEOUT);
+
+ if (wait < 0) {
+ ret = wait;
+ goto err_unlock;
+ }
+ }
+
fence = virtio_gpu_fence_alloc(vgdev, vgdev->fence_drv.context, 0);
if (!fence) {
ret = -ENOMEM;
@@ -320,6 +341,28 @@ static int virtio_gpu_transfer_to_host_ioctl(struct drm_device *dev, void *data,
if (ret != 0)
goto err_put_free;
+ /*
+ * A transfer the other way may have queued without yet syncing
+ * its mapping. Pushing the guest pages into it now would
+ * discard what the device wrote there, so wait for that sync:
+ * it runs before the fence it belongs to is signalled. The
+ * flag is only set under this reservation, so it cannot appear
+ * behind our back, and the acquire pairs with the release in
+ * that sync, so finding it clear means the pages it wrote are
+ * visible here too.
+ */
+ if (smp_load_acquire(&bo->from_host_pending)) {
+ long wait = dma_resv_wait_timeout(objs->objs[0]->resv,
+ DMA_RESV_USAGE_WRITE,
+ true,
+ MAX_SCHEDULE_TIMEOUT);
+
+ if (wait < 0) {
+ ret = wait;
+ goto err_unlock;
+ }
+ }
+
ret = -ENOMEM;
fence = virtio_gpu_fence_alloc(vgdev, vgdev->fence_drv.context,
0);
diff --git a/drivers/gpu/drm/virtio/virtgpu_vq.c b/drivers/gpu/drm/virtio/virtgpu_vq.c
index 2b7af8e4e9e61..28682a6d5937d 100644
--- a/drivers/gpu/drm/virtio/virtgpu_vq.c
+++ b/drivers/gpu/drm/virtio/virtgpu_vq.c
@@ -241,6 +241,33 @@ void virtio_gpu_dequeue_ctrl_func(struct work_struct *work)
} while (!virtqueue_enable_cb(vgdev->ctrlq.vq));
spin_unlock(&vgdev->ctrlq.qlock);
+ /*
+ * Sync guest-bound transfers before signalling anything, so that a
+ * waiter cannot read the backing pages while what the device wrote is
+ * still in a bounce buffer. This cannot be folded into the loop below:
+ * virtio_gpu_fence_event_process() also signals every earlier fence in
+ * the same context, so any entry there may signal this entry's fence.
+ */
+ list_for_each_entry(entry, &reclaim_list, list) {
+ if (entry->sync_for_cpu) {
+ struct virtio_gpu_object *bo =
+ gem_to_virtio_gpu_obj(entry->objs->objs[0]);
+
+ dma_sync_sgtable_for_cpu(vgdev->vdev->dev.parent,
+ bo->base.sgt, DMA_FROM_DEVICE);
+ /*
+ * Release, so a transfer the other way that skips its
+ * wait on the strength of this cannot go on to read
+ * the backing pages before the sync above is visible.
+ * Nothing orders the two otherwise: where the mapping
+ * bounces on a coherent device the sync is a plain
+ * copy, and dma_direct_sync_sg_for_cpu() emits its
+ * barrier only for the non-coherent case.
+ */
+ smp_store_release(&bo->from_host_pending, false);
+ }
+ }
+
list_for_each_entry(entry, &reclaim_list, list) {
resp = (struct virtio_gpu_ctrl_hdr *)entry->resp_buf;
@@ -1223,12 +1250,31 @@ void virtio_gpu_cmd_transfer_from_host_3d(struct virtio_gpu_device *vgdev,
struct virtio_gpu_object *bo = gem_to_virtio_gpu_obj(objs->objs[0]);
struct virtio_gpu_transfer_host_3d *cmd_p;
struct virtio_gpu_vbuffer *vbuf;
+ bool use_dma_api = virtio_gpu_use_dma_api(vgdev->vdev);
cmd_p = virtio_gpu_alloc_cmd(vgdev, &vbuf, sizeof(*cmd_p));
memset(cmd_p, 0, sizeof(*cmd_p));
vbuf->objs = objs;
+ if (virtio_gpu_is_shmem(bo) && use_dma_api) {
+ /*
+ * The device writes only the requested box, so prime the
+ * mapping with the current contents: otherwise the sync on
+ * completion would hand back whatever a bounce buffer held for
+ * the regions the device does not touch.
+ */
+ dma_sync_sgtable_for_device(vgdev->vdev->dev.parent,
+ bo->base.sgt, DMA_TO_DEVICE);
+ vbuf->sync_for_cpu = true;
+ /*
+ * Set under the reservation the caller holds, so a transfer
+ * the other way cannot miss it and push the guest pages into
+ * the mapping while the device still owns it.
+ */
+ WRITE_ONCE(bo->from_host_pending, true);
+ }
+
cmd_p->hdr.type = cpu_to_le32(VIRTIO_GPU_CMD_TRANSFER_FROM_HOST_3D);
cmd_p->hdr.ctx_id = cpu_to_le32(ctx_id);
cmd_p->resource_id = cpu_to_le32(bo->hw_res_handle);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 114/457] pinctrl: tegra238: Fix register bank for AON pin groups
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 113/457] drm/virtio: sync shmem backing on guest-bound transfers Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 115/457] drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach Greg Kroah-Hartman
` (353 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Prathamesh Shete, Linus Walleij,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Prathamesh Shete <pshete@nvidia.com>
[ Upstream commit ae2c5bf969573708cd5b6bb6393631255d83c3fe ]
The AON pin controller has a single register region and therefore,
the bank defined in the tegra238_functions[] and tegra238_aon_groups[]
for the AON pin groups must be 0. However, commit 25cac7292d49
("pinctrl: tegra: Add Tegra238 pinmux driver") incorrectly specified the
bank for these pins as 1 and not 0. This means that in the
tegra_pinctrl_probe() function we use an invalid index when accessing
the pmx->regs[] array which causes an incorrect address to be used for
accessing the pinmux registers.
Fix this by correcting the bank for the AON pin groups.
Fixes: 25cac7292d49 ("pinctrl: tegra: Add Tegra238 pinmux driver")
Signed-off-by: Prathamesh Shete <pshete@nvidia.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/tegra/pinctrl-tegra238.c | 204 +++++++++++------------
1 file changed, 102 insertions(+), 102 deletions(-)
diff --git a/drivers/pinctrl/tegra/pinctrl-tegra238.c b/drivers/pinctrl/tegra/pinctrl-tegra238.c
index ec482365f14f2..40aba285944eb 100644
--- a/drivers/pinctrl/tegra/pinctrl-tegra238.c
+++ b/drivers/pinctrl/tegra/pinctrl-tegra238.c
@@ -1744,57 +1744,57 @@ static const char * const tegra238_functions[] = {
#define drive_sdmmc1_dat0_pu2 DRV_PINGROUP_ENTRY_Y(0x8034, 28, 2, 30, 2, -1, -1, -1, -1, 0)
#define drive_ufs0_rst_n_pv1 DRV_PINGROUP_ENTRY_Y(0x11004, 12, 5, 24, 5, -1, -1, -1, -1, 0)
#define drive_ufs0_ref_clk_pv0 DRV_PINGROUP_ENTRY_Y(0x1100c, 12, 5, 24, 5, -1, -1, -1, -1, 0)
-#define drive_batt_oc_paa4 DRV_PINGROUP_ENTRY_Y(0x1024, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_bootv_ctl_n_paa0 DRV_PINGROUP_ENTRY_Y(0x102c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_vcomp_alert_paa2 DRV_PINGROUP_ENTRY_Y(0x105c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_hdmi_cec_pbb0 DRV_PINGROUP_ENTRY_Y(0x1064, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_touch_clk_pdd3 DRV_PINGROUP_ENTRY_Y(0x106c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart3_rx_pcc6 DRV_PINGROUP_ENTRY_Y(0x1074, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart3_tx_pcc5 DRV_PINGROUP_ENTRY_Y(0x107c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_gen8_i2c_sda_pdd2 DRV_PINGROUP_ENTRY_Y(0x1084, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_gen8_i2c_scl_pdd1 DRV_PINGROUP_ENTRY_Y(0x108c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_spi2_mosi_pcc2 DRV_PINGROUP_ENTRY_Y(0x1094, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_gen2_i2c_scl_pcc7 DRV_PINGROUP_ENTRY_Y(0x109c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_spi2_cs0_pcc3 DRV_PINGROUP_ENTRY_Y(0x10a4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_gen2_i2c_sda_pdd0 DRV_PINGROUP_ENTRY_Y(0x10ac, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_spi2_sck_pcc0 DRV_PINGROUP_ENTRY_Y(0x10b4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_spi2_miso_pcc1 DRV_PINGROUP_ENTRY_Y(0x10bc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio49_pee2 DRV_PINGROUP_ENTRY_Y(0x10c4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio50_pee4 DRV_PINGROUP_ENTRY_Y(0x10cc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio82_pee3 DRV_PINGROUP_ENTRY_Y(0x10d4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio71_pff2 DRV_PINGROUP_ENTRY_Y(0x10dc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio76_pff7 DRV_PINGROUP_ENTRY_Y(0x10e4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio74_pff5 DRV_PINGROUP_ENTRY_Y(0x10ec, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio00_paa1 DRV_PINGROUP_ENTRY_Y(0x10f4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio19_pdd6 DRV_PINGROUP_ENTRY_Y(0x10fc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio86_phh3 DRV_PINGROUP_ENTRY_Y(0x1104, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio72_pff3 DRV_PINGROUP_ENTRY_Y(0x110c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio77_pgg0 DRV_PINGROUP_ENTRY_Y(0x1114, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio80_pff6 DRV_PINGROUP_ENTRY_Y(0x111c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio84_pgg1 DRV_PINGROUP_ENTRY_Y(0x1124, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio83_pee5 DRV_PINGROUP_ENTRY_Y(0x112c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio73_pff4 DRV_PINGROUP_ENTRY_Y(0x1134, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio70_pff1 DRV_PINGROUP_ENTRY_Y(0x113c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio04_paa5 DRV_PINGROUP_ENTRY_Y(0x1144, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio85_pgg6 DRV_PINGROUP_ENTRY_Y(0x114c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio69_pff0 DRV_PINGROUP_ENTRY_Y(0x1154, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio25_paa6 DRV_PINGROUP_ENTRY_Y(0x115c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_soc_gpio26_paa7 DRV_PINGROUP_ENTRY_Y(0x1164, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart5_tx_pgg7 DRV_PINGROUP_ENTRY_Y(0x116c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart5_rx_phh0 DRV_PINGROUP_ENTRY_Y(0x1174, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart2_tx_pgg2 DRV_PINGROUP_ENTRY_Y(0x117c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart2_rx_pgg3 DRV_PINGROUP_ENTRY_Y(0x1184, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart2_cts_pgg5 DRV_PINGROUP_ENTRY_Y(0x118c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart2_rts_pgg4 DRV_PINGROUP_ENTRY_Y(0x1194, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart5_cts_phh2 DRV_PINGROUP_ENTRY_Y(0x119c, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_uart5_rts_phh1 DRV_PINGROUP_ENTRY_Y(0x11a4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_pwm7_pee1 DRV_PINGROUP_ENTRY_Y(0x11ac, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_pwm2_pdd7 DRV_PINGROUP_ENTRY_Y(0x11b4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_pwm3_pee0 DRV_PINGROUP_ENTRY_Y(0x11bc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_pwm1_paa3 DRV_PINGROUP_ENTRY_Y(0x11c4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_spi2_cs1_pcc4 DRV_PINGROUP_ENTRY_Y(0x11cc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_dmic1_clk_pdd4 DRV_PINGROUP_ENTRY_Y(0x11d4, 12, 5, 20, 5, -1, -1, -1, -1, 1)
-#define drive_dmic1_dat_pdd5 DRV_PINGROUP_ENTRY_Y(0x11dc, 12, 5, 20, 5, -1, -1, -1, -1, 1)
+#define drive_batt_oc_paa4 DRV_PINGROUP_ENTRY_Y(0x1024, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_bootv_ctl_n_paa0 DRV_PINGROUP_ENTRY_Y(0x102c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_vcomp_alert_paa2 DRV_PINGROUP_ENTRY_Y(0x105c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_hdmi_cec_pbb0 DRV_PINGROUP_ENTRY_Y(0x1064, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_touch_clk_pdd3 DRV_PINGROUP_ENTRY_Y(0x106c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart3_rx_pcc6 DRV_PINGROUP_ENTRY_Y(0x1074, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart3_tx_pcc5 DRV_PINGROUP_ENTRY_Y(0x107c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_gen8_i2c_sda_pdd2 DRV_PINGROUP_ENTRY_Y(0x1084, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_gen8_i2c_scl_pdd1 DRV_PINGROUP_ENTRY_Y(0x108c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_spi2_mosi_pcc2 DRV_PINGROUP_ENTRY_Y(0x1094, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_gen2_i2c_scl_pcc7 DRV_PINGROUP_ENTRY_Y(0x109c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_spi2_cs0_pcc3 DRV_PINGROUP_ENTRY_Y(0x10a4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_gen2_i2c_sda_pdd0 DRV_PINGROUP_ENTRY_Y(0x10ac, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_spi2_sck_pcc0 DRV_PINGROUP_ENTRY_Y(0x10b4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_spi2_miso_pcc1 DRV_PINGROUP_ENTRY_Y(0x10bc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio49_pee2 DRV_PINGROUP_ENTRY_Y(0x10c4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio50_pee4 DRV_PINGROUP_ENTRY_Y(0x10cc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio82_pee3 DRV_PINGROUP_ENTRY_Y(0x10d4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio71_pff2 DRV_PINGROUP_ENTRY_Y(0x10dc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio76_pff7 DRV_PINGROUP_ENTRY_Y(0x10e4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio74_pff5 DRV_PINGROUP_ENTRY_Y(0x10ec, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio00_paa1 DRV_PINGROUP_ENTRY_Y(0x10f4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio19_pdd6 DRV_PINGROUP_ENTRY_Y(0x10fc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio86_phh3 DRV_PINGROUP_ENTRY_Y(0x1104, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio72_pff3 DRV_PINGROUP_ENTRY_Y(0x110c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio77_pgg0 DRV_PINGROUP_ENTRY_Y(0x1114, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio80_pff6 DRV_PINGROUP_ENTRY_Y(0x111c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio84_pgg1 DRV_PINGROUP_ENTRY_Y(0x1124, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio83_pee5 DRV_PINGROUP_ENTRY_Y(0x112c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio73_pff4 DRV_PINGROUP_ENTRY_Y(0x1134, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio70_pff1 DRV_PINGROUP_ENTRY_Y(0x113c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio04_paa5 DRV_PINGROUP_ENTRY_Y(0x1144, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio85_pgg6 DRV_PINGROUP_ENTRY_Y(0x114c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio69_pff0 DRV_PINGROUP_ENTRY_Y(0x1154, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio25_paa6 DRV_PINGROUP_ENTRY_Y(0x115c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_soc_gpio26_paa7 DRV_PINGROUP_ENTRY_Y(0x1164, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart5_tx_pgg7 DRV_PINGROUP_ENTRY_Y(0x116c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart5_rx_phh0 DRV_PINGROUP_ENTRY_Y(0x1174, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart2_tx_pgg2 DRV_PINGROUP_ENTRY_Y(0x117c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart2_rx_pgg3 DRV_PINGROUP_ENTRY_Y(0x1184, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart2_cts_pgg5 DRV_PINGROUP_ENTRY_Y(0x118c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart2_rts_pgg4 DRV_PINGROUP_ENTRY_Y(0x1194, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart5_cts_phh2 DRV_PINGROUP_ENTRY_Y(0x119c, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_uart5_rts_phh1 DRV_PINGROUP_ENTRY_Y(0x11a4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_pwm7_pee1 DRV_PINGROUP_ENTRY_Y(0x11ac, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_pwm2_pdd7 DRV_PINGROUP_ENTRY_Y(0x11b4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_pwm3_pee0 DRV_PINGROUP_ENTRY_Y(0x11bc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_pwm1_paa3 DRV_PINGROUP_ENTRY_Y(0x11c4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_spi2_cs1_pcc4 DRV_PINGROUP_ENTRY_Y(0x11cc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_dmic1_clk_pdd4 DRV_PINGROUP_ENTRY_Y(0x11d4, 12, 5, 20, 5, -1, -1, -1, -1, 0)
+#define drive_dmic1_dat_pdd5 DRV_PINGROUP_ENTRY_Y(0x11dc, 12, 5, 20, 5, -1, -1, -1, -1, 0)
#define drive_sdmmc1_comp DRV_PINGROUP_ENTRY_N
@@ -1961,57 +1961,57 @@ static const struct tegra_pingroup tegra238_groups[] = {
};
static const struct tegra_pingroup tegra238_aon_groups[] = {
- PINGROUP(bootv_ctl_n_paa0, RSVD0, RSVD1, RSVD2, RSVD3, 0x1028, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio00_paa1, RSVD0, RSVD1, RSVD2, RSVD3, 0x10f0, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(vcomp_alert_paa2, SOC_THERM_OC1, RSVD1, RSVD2, RSVD3, 0x1058, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(pwm1_paa3, GP_PWM1, RSVD1, RSVD2, RSVD3, 0x11c0, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(batt_oc_paa4, SOC_THERM_OC2, RSVD1, RSVD2, RSVD3, 0x1020, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio04_paa5, RSVD0, RSVD1, RSVD2, RSVD3, 0x1140, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio25_paa6, RSVD0, RSVD1, RSVD2, RSVD3, 0x1158, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio26_paa7, RSVD0, SOC_THERM_OC3, RSVD2, RSVD3, 0x1160, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(hdmi_cec_pbb0, HDMI_CEC, RSVD1, RSVD2, RSVD3, 0x1060, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(spi2_sck_pcc0, SPI2_SCK, RSVD1, RSVD2, RSVD3, 0x10b0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(spi2_miso_pcc1, SPI2_DIN, RSVD1, RSVD2, RSVD3, 0x10b8, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(spi2_mosi_pcc2, SPI2_DOUT, RSVD1, RSVD2, RSVD3, 0x1090, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(spi2_cs0_pcc3, SPI2_CS0, RSVD1, RSVD2, RSVD3, 0x10a0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(spi2_cs1_pcc4, SPI2_CS1, RSVD1, RSVD2, RSVD3, 0x11c8, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart3_tx_pcc5, UARTC_TXD, RSVD1, RSVD2, RSVD3, 0x1078, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart3_rx_pcc6, UARTC_RXD, RSVD1, RSVD2, RSVD3, 0x1070, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(gen2_i2c_scl_pcc7, I2C2_CLK, RSVD1, RSVD2, RSVD3, 0x1098, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(gen2_i2c_sda_pdd0, I2C2_DAT, RSVD1, RSVD2, RSVD3, 0x10a8, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(gen8_i2c_scl_pdd1, I2C8_CLK, RSVD1, RSVD2, RSVD3, 0x1088, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(gen8_i2c_sda_pdd2, I2C8_DAT, RSVD1, RSVD2, RSVD3, 0x1080, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(touch_clk_pdd3, GP_PWM4, TOUCH_CLK, RSVD2, RSVD3, 0x1068, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(dmic1_clk_pdd4, DMIC1_CLK, RSVD1, DMIC5_CLK, RSVD3, 0x11d0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(dmic1_dat_pdd5, DMIC1_DAT, RSVD1, DMIC5_DAT, RSVD3, 0x11d8, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio19_pdd6, RSVD0, WDT_RESET_OUTB, RSVD2, RSVD3, 0x10f8, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio49_pee2, RSVD0, RSVD1, RSVD2, RSVD3, 0x10c0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio50_pee4, RSVD0, RSVD1, RSVD2, RSVD3, 0x10c8, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio82_pee3, RSVD0, RSVD1, RSVD2, RSVD3, 0x10d0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio71_pff2, PPC_MODE_1, RSVD1, RSVD2, RSVD3, 0x10d8, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio76_pff7, RSVD0, RSVD1, TSC_EDGE_OUT0, TSC_EDGE_OUT0A, 0x10e0, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio74_pff5, PPC_READY, PPC_I2C_DAT, RSVD2, RSVD3, 0x10e8, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio86_phh3, RSVD0, SPI5_CS1, TSC_EDGE_OUT3, TSC_EDGE_OUT0D, 0x1100, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio72_pff3, PPC_MODE_2, RSVD1, RSVD2, RSVD3, 0x1108, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio77_pgg0, RSVD0, RSVD1, TSC_EDGE_OUT1, TSC_EDGE_OUT0B, 0x1110, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio80_pff6, RSVD0, PPC_RST_N, RSVD2, RSVD3, 0x1118, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio84_pgg1, RSVD0, RSVD1, TSC_EDGE_OUT2, TSC_EDGE_OUT0C, 0x1120, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio83_pee5, RSVD0, RSVD1, RSVD2, RSVD3, 0x1128, 1, Y, -1, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio73_pff4, PPC_CC, PPC_I2C_CLK, RSVD2, RSVD3, 0x1130, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio70_pff1, PPC_MODE_0, RSVD1, RSVD2, RSVD3, 0x1138, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio85_pgg6, RSVD0, SPI4_CS1, RSVD2, RSVD3, 0x1148, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(soc_gpio69_pff0, PPC_INT_N, RSVD1, RSVD2, RSVD3, 0x1150, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart5_tx_pgg7, UARTE_TXD, SPI5_SCK, RSVD2, RSVD3, 0x1168, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart5_rx_phh0, UARTE_RXD, SPI5_MISO, RSVD2, RSVD3, 0x1170, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart2_tx_pgg2, UARTB_TXD, SPI4_SCK, RSVD2, RSVD3, 0x1178, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart2_rx_pgg3, UARTB_RXD, SPI4_MISO, RSVD2, RSVD3, 0x1180, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart2_cts_pgg5, UARTB_CTS, SPI4_CS0, RSVD2, RSVD3, 0x1188, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart2_rts_pgg4, UARTB_RTS, SPI4_MOSI, RSVD2, RSVD3, 0x1190, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart5_cts_phh2, UARTE_CTS, SPI5_CS0, RSVD2, RSVD3, 0x1198, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(uart5_rts_phh1, UARTE_RTS, SPI5_MOSI, RSVD2, RSVD3, 0x11a0, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(pwm2_pdd7, GP_PWM2, LED_BLINK, RSVD2, RSVD3, 0x11b0, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(pwm3_pee0, GP_PWM3, RSVD1, RSVD2, RSVD3, 0x11b8, 1, Y, 5, 7, 6, 8, -1, 10, 12),
- PINGROUP(pwm7_pee1, GP_PWM7, RSVD1, RSVD2, RSVD3, 0x11a8, 1, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(bootv_ctl_n_paa0, RSVD0, RSVD1, RSVD2, RSVD3, 0x1028, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio00_paa1, RSVD0, RSVD1, RSVD2, RSVD3, 0x10f0, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(vcomp_alert_paa2, SOC_THERM_OC1, RSVD1, RSVD2, RSVD3, 0x1058, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(pwm1_paa3, GP_PWM1, RSVD1, RSVD2, RSVD3, 0x11c0, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(batt_oc_paa4, SOC_THERM_OC2, RSVD1, RSVD2, RSVD3, 0x1020, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio04_paa5, RSVD0, RSVD1, RSVD2, RSVD3, 0x1140, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio25_paa6, RSVD0, RSVD1, RSVD2, RSVD3, 0x1158, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio26_paa7, RSVD0, SOC_THERM_OC3, RSVD2, RSVD3, 0x1160, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(hdmi_cec_pbb0, HDMI_CEC, RSVD1, RSVD2, RSVD3, 0x1060, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(spi2_sck_pcc0, SPI2_SCK, RSVD1, RSVD2, RSVD3, 0x10b0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(spi2_miso_pcc1, SPI2_DIN, RSVD1, RSVD2, RSVD3, 0x10b8, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(spi2_mosi_pcc2, SPI2_DOUT, RSVD1, RSVD2, RSVD3, 0x1090, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(spi2_cs0_pcc3, SPI2_CS0, RSVD1, RSVD2, RSVD3, 0x10a0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(spi2_cs1_pcc4, SPI2_CS1, RSVD1, RSVD2, RSVD3, 0x11c8, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart3_tx_pcc5, UARTC_TXD, RSVD1, RSVD2, RSVD3, 0x1078, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart3_rx_pcc6, UARTC_RXD, RSVD1, RSVD2, RSVD3, 0x1070, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(gen2_i2c_scl_pcc7, I2C2_CLK, RSVD1, RSVD2, RSVD3, 0x1098, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(gen2_i2c_sda_pdd0, I2C2_DAT, RSVD1, RSVD2, RSVD3, 0x10a8, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(gen8_i2c_scl_pdd1, I2C8_CLK, RSVD1, RSVD2, RSVD3, 0x1088, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(gen8_i2c_sda_pdd2, I2C8_DAT, RSVD1, RSVD2, RSVD3, 0x1080, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(touch_clk_pdd3, GP_PWM4, TOUCH_CLK, RSVD2, RSVD3, 0x1068, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(dmic1_clk_pdd4, DMIC1_CLK, RSVD1, DMIC5_CLK, RSVD3, 0x11d0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(dmic1_dat_pdd5, DMIC1_DAT, RSVD1, DMIC5_DAT, RSVD3, 0x11d8, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio19_pdd6, RSVD0, WDT_RESET_OUTB, RSVD2, RSVD3, 0x10f8, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio49_pee2, RSVD0, RSVD1, RSVD2, RSVD3, 0x10c0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio50_pee4, RSVD0, RSVD1, RSVD2, RSVD3, 0x10c8, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio82_pee3, RSVD0, RSVD1, RSVD2, RSVD3, 0x10d0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio71_pff2, PPC_MODE_1, RSVD1, RSVD2, RSVD3, 0x10d8, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio76_pff7, RSVD0, RSVD1, TSC_EDGE_OUT0, TSC_EDGE_OUT0A, 0x10e0, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio74_pff5, PPC_READY, PPC_I2C_DAT, RSVD2, RSVD3, 0x10e8, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio86_phh3, RSVD0, SPI5_CS1, TSC_EDGE_OUT3, TSC_EDGE_OUT0D, 0x1100, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio72_pff3, PPC_MODE_2, RSVD1, RSVD2, RSVD3, 0x1108, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio77_pgg0, RSVD0, RSVD1, TSC_EDGE_OUT1, TSC_EDGE_OUT0B, 0x1110, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio80_pff6, RSVD0, PPC_RST_N, RSVD2, RSVD3, 0x1118, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio84_pgg1, RSVD0, RSVD1, TSC_EDGE_OUT2, TSC_EDGE_OUT0C, 0x1120, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio83_pee5, RSVD0, RSVD1, RSVD2, RSVD3, 0x1128, 0, Y, -1, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio73_pff4, PPC_CC, PPC_I2C_CLK, RSVD2, RSVD3, 0x1130, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio70_pff1, PPC_MODE_0, RSVD1, RSVD2, RSVD3, 0x1138, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio85_pgg6, RSVD0, SPI4_CS1, RSVD2, RSVD3, 0x1148, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(soc_gpio69_pff0, PPC_INT_N, RSVD1, RSVD2, RSVD3, 0x1150, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart5_tx_pgg7, UARTE_TXD, SPI5_SCK, RSVD2, RSVD3, 0x1168, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart5_rx_phh0, UARTE_RXD, SPI5_MISO, RSVD2, RSVD3, 0x1170, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart2_tx_pgg2, UARTB_TXD, SPI4_SCK, RSVD2, RSVD3, 0x1178, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart2_rx_pgg3, UARTB_RXD, SPI4_MISO, RSVD2, RSVD3, 0x1180, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart2_cts_pgg5, UARTB_CTS, SPI4_CS0, RSVD2, RSVD3, 0x1188, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart2_rts_pgg4, UARTB_RTS, SPI4_MOSI, RSVD2, RSVD3, 0x1190, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart5_cts_phh2, UARTE_CTS, SPI5_CS0, RSVD2, RSVD3, 0x1198, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(uart5_rts_phh1, UARTE_RTS, SPI5_MOSI, RSVD2, RSVD3, 0x11a0, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(pwm2_pdd7, GP_PWM2, LED_BLINK, RSVD2, RSVD3, 0x11b0, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(pwm3_pee0, GP_PWM3, RSVD1, RSVD2, RSVD3, 0x11b8, 0, Y, 5, 7, 6, 8, -1, 10, 12),
+ PINGROUP(pwm7_pee1, GP_PWM7, RSVD1, RSVD2, RSVD3, 0x11a8, 0, Y, 5, 7, 6, 8, -1, 10, 12),
};
static const struct tegra_pinctrl_soc_data tegra238_pinctrl_aon = {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 115/457] drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 114/457] pinctrl: tegra238: Fix register bank for AON pin groups Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 116/457] ovpn: preserve IPv6 scope id for netlink peer endpoints Greg Kroah-Hartman
` (352 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luca Ceresoli, Li Youhong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Youhong <liyouhong@kylinos.cn>
[ Upstream commit ada667890773e033d2f40dc94176e3beb930b516 ]
When the Exynos DSI driver was generalized into samsung-dsim, the TE
GPIO acquisition was switched from gpiod_get_optional() to
devm_gpiod_get_optional() while keeping the matching gpiod_put() calls.
That combination is wrong for a managed descriptor.
However, dropping the puts and keeping the managed get is also wrong:
samsung_dsim_register_te_irq() runs from the DSI host attach callback,
and host detach/reattach can happen without destroying the device that
owns the managed action. A second attach would then request the GPIO
again without having released it.
Switch back to a non-managed gpiod_get_optional() and keep the explicit
gpiod_put() on the request_irq() error path and in
samsung_dsim_unregister_te_irq().
Fixes: e7447128ca4a ("drm: bridge: Generalize Exynos-DSI driver into a Samsung DSIM bridge")
Suggested-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Li Youhong <liyouhong@kylinos.cn>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Tested-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Link: https://patch.msgid.link/20260904014958.1572918-1-dayou5941@163.com
[Luca: remove unnecessary comment]
Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/samsung-dsim.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/samsung-dsim.c b/drivers/gpu/drm/bridge/samsung-dsim.c
index 9ee0515074c78..7e320eac2e4ad 100644
--- a/drivers/gpu/drm/bridge/samsung-dsim.c
+++ b/drivers/gpu/drm/bridge/samsung-dsim.c
@@ -1862,7 +1862,7 @@ static int samsung_dsim_register_te_irq(struct samsung_dsim *dsi, struct device
int te_gpio_irq;
int ret;
- dsi->te_gpio = devm_gpiod_get_optional(dev, "te", GPIOD_IN);
+ dsi->te_gpio = gpiod_get_optional(dev, "te", GPIOD_IN);
if (!dsi->te_gpio)
return 0;
else if (IS_ERR(dsi->te_gpio))
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 116/457] ovpn: preserve IPv6 scope id for netlink peer endpoints
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 115/457] drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 117/457] ovpn: skip UDP source validation for unspecified addresses Greg Kroah-Hartman
` (351 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 7a6d08ee0f0e30023d18779bb314db8fd9a3b6d4 ]
ovpn accepts OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID and reports
bind->remote.in6.sin6_scope_id in peer dumps, but the netlink endpoint
parser never copied the attribute into the sockaddr_in6 used to create or
update the peer bind.
As a result, an IPv6 link-local remote endpoint configured through
netlink loses its interface scope, unlike on the peer float path where
ipv6_iface_scope_id populates the field. The UDPv6 output path then
builds a flow with flowi6_oif set to zero and route lookup can fail or
select the wrong interface.
Copy the scope id when parsing non-v4-mapped IPv6 remote endpoints. The
existing precheck already rejects the scope-id attribute for IPv4 and
v4-mapped IPv6 remotes.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/netlink.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index 4dad852941982..2ba762082acc1 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -100,6 +100,8 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
struct sockaddr_in6 *sin6;
struct sockaddr_in *sin;
struct in6_addr *in6;
+ struct nlattr *scope;
+ u32 scope_id = 0;
__be16 port = 0;
__be32 *in;
@@ -114,6 +116,9 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
} else if (attrs[OVPN_A_PEER_REMOTE_IPV6]) {
ss->ss_family = AF_INET6;
in6 = nla_data(attrs[OVPN_A_PEER_REMOTE_IPV6]);
+ scope = attrs[OVPN_A_PEER_REMOTE_IPV6_SCOPE_ID];
+ if (scope)
+ scope_id = nla_get_u32(scope);
} else {
return false;
}
@@ -126,6 +131,7 @@ static bool ovpn_nl_attr_sockaddr_remote(struct nlattr **attrs,
if (!ipv6_addr_v4mapped(in6)) {
sin6 = (struct sockaddr_in6 *)ss;
sin6->sin6_port = port;
+ sin6->sin6_scope_id = scope_id;
memcpy(&sin6->sin6_addr, in6, sizeof(*in6));
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 117/457] ovpn: skip UDP source validation for unspecified addresses
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 116/457] ovpn: preserve IPv6 scope id for netlink peer endpoints Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 118/457] ovpn: track UDP socket route key for peer dst cache Greg Kroah-Hartman
` (350 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 77393b4d72dfeb764b2af2b848acc659f6fcfd0a ]
ovpn validates the cached local UDP source address before reusing or
refreshing a peer dst cache. This is only meaningful when a concrete
source address is selected.
For IPv6, calling ipv6_chk_addr with :: checks whether the unspecified
address itself is configured on the host. A peer may legitimately have
bind->local.ipv6 set to :: when no local endpoint was configured or
after a stale learned address was cleared. In that case the source
should be left unspecified and selected by ip6_dst_lookup_flow().
For IPv4, inet_confirm_addr(..., local = 0, ...) asks for local address
autoselection rather than validating a chosen source. Skip the precheck
there as well and let ip_route_output_flow select or reject the source.
Only validate non-zero/non-any source addresses.
Fixes: 08857b5ec5d9 ("ovpn: implement basic TX path (UDP)")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/udp.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c
index 7f69e8890b5b5..df4750dabd1e1 100644
--- a/drivers/net/ovpn/udp.c
+++ b/drivers/net/ovpn/udp.c
@@ -161,8 +161,8 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
if (rt)
goto transmit;
- if (unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0, fl.saddr,
- RT_SCOPE_HOST))) {
+ if (fl.saddr && unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0,
+ fl.saddr, RT_SCOPE_HOST))) {
/* we may end up here when the cached address is not usable
* anymore. In this case we reset address/cache and perform a
* new look up
@@ -238,7 +238,8 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
if (dst)
goto transmit;
- if (unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) {
+ if (!ipv6_addr_any(&fl.saddr) &&
+ unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) {
/* we may end up here when the cached address is not usable
* anymore. In this case we reset address/cache and perform a
* new look up
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 118/457] ovpn: track UDP socket route key for peer dst cache
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 117/457] ovpn: skip UDP source validation for unspecified addresses Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 119/457] ovpn: validate peer state before caching UDP dst Greg Kroah-Hartman
` (349 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 7c66b7a4ae80a9309e6dc1d24b7b6b897e6348eb ]
ovpn stores the route used to transmit UDP packets in a per-peer dst
cache. A cached dst is only valid for the route lookup inputs used when
it was resolved.
Some of those inputs are mutable while userspace still owns the UDP
socket. In particular, changes to the socket mark or UDP source port do
not invalidate ovpn's peer dst cache, so ovpn can keep using a route
selected with an old socket route key.
Replace the cached mark with a route key containing the socket-owned
lookup inputs currently used by ovpn, and reset the peer dst cache when
the key changes. Before storing a newly looked-up dst, recheck the route
key under the peer lock so a dst resolved for stale socket state is not
published.
Fixes: 08857b5ec5d9 ("ovpn: implement basic TX path (UDP)")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/peer.c | 1 +
drivers/net/ovpn/peer.h | 19 ++++++++-
drivers/net/ovpn/udp.c | 90 +++++++++++++++++++++++++++++++++++------
3 files changed, 95 insertions(+), 15 deletions(-)
diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c
index c95656ca7c357..b400783c2efab 100644
--- a/drivers/net/ovpn/peer.c
+++ b/drivers/net/ovpn/peer.c
@@ -113,6 +113,7 @@ struct ovpn_peer *ovpn_peer_new(struct ovpn_priv *ovpn, u32 id)
RCU_INIT_POINTER(peer->bind, NULL);
ovpn_crypto_state_init(&peer->crypto);
spin_lock_init(&peer->lock);
+ seqcount_spinlock_init(&peer->route_key_seq, &peer->lock);
kref_init(&peer->refcount);
ovpn_peer_stats_init(&peer->vpn_stats);
ovpn_peer_stats_init(&peer->link_stats);
diff --git a/drivers/net/ovpn/peer.h b/drivers/net/ovpn/peer.h
index dfa5c0037e02b..063535699ecd8 100644
--- a/drivers/net/ovpn/peer.h
+++ b/drivers/net/ovpn/peer.h
@@ -10,6 +10,7 @@
#ifndef _NET_OVPN_OVPNPEER_H_
#define _NET_OVPN_OVPNPEER_H_
+#include <linux/seqlock.h>
#include <net/dst_cache.h>
#include <net/strparser.h>
@@ -17,6 +18,16 @@
#include "socket.h"
#include "stats.h"
+/**
+ * struct ovpn_route_key - route key used for the peer dst cache
+ * @mark: fwmark used for route lookup
+ * @sport: UDP source port used for route lookup
+ */
+struct ovpn_route_key {
+ u32 mark;
+ __be16 sport;
+};
+
/**
* struct ovpn_peer - the main remote peer object
* @ovpn: main openvpn instance this peer belongs to
@@ -45,6 +56,8 @@
* @tcp.sk_cb.ops: pointer to the original prot_ops object (TCP only)
* @crypto: the crypto configuration (ciphers, keys, etc..)
* @dst_cache: cache for dst_entry used to send to peer
+ * @route_key: route key matching the current dst cache contents
+ * @route_key_seq: seqcount protecting lockless route_key reads
* @bind: remote peer binding
* @keepalive_interval: seconds after which a new keepalive should be sent
* @keepalive_xmit_exp: future timestamp when next keepalive should be sent
@@ -55,7 +68,7 @@
* @vpn_stats: per-peer in-VPN TX/RX stats
* @link_stats: per-peer link/transport TX/RX stats
* @delete_reason: why peer was deleted (i.e. timeout, transport error, ..)
- * @lock: protects binding to peer (bind) and keepalive* fields
+ * @lock: protects binding to peer (bind), route_key and keepalive* fields
* @refcount: reference counter
* @rcu: used to free peer in an RCU safe way
* @release_entry: entry for the socket release list
@@ -99,6 +112,8 @@ struct ovpn_peer {
} tcp;
struct ovpn_crypto_state crypto;
struct dst_cache dst_cache;
+ struct ovpn_route_key route_key;
+ seqcount_spinlock_t route_key_seq;
struct ovpn_bind __rcu *bind;
unsigned long keepalive_interval;
unsigned long keepalive_xmit_exp;
@@ -109,7 +124,7 @@ struct ovpn_peer {
struct ovpn_peer_stats vpn_stats;
struct ovpn_peer_stats link_stats;
enum ovpn_del_peer_reason delete_reason;
- spinlock_t lock; /* protects bind and keepalive* */
+ spinlock_t lock; /* protects bind, route_key and keepalive* */
struct kref refcount;
struct rcu_head rcu;
struct llist_node release_entry;
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c
index df4750dabd1e1..c6d591cb7ff45 100644
--- a/drivers/net/ovpn/udp.c
+++ b/drivers/net/ovpn/udp.c
@@ -131,6 +131,48 @@ static int ovpn_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
return 0;
}
+static bool ovpn_route_key_equal(const struct ovpn_route_key *a,
+ const struct ovpn_route_key *b)
+{
+ return a->mark == b->mark && a->sport == b->sport;
+}
+
+/**
+ * ovpn_dst_cache_check_key - reset peer dst cache after key changes
+ * @peer: the peer owning the dst cache
+ * @cache: the cache that might need to be reset
+ * @key: the route key for the packet being transmitted
+ *
+ * Reset the peer dst cache if it was populated for a different route key.
+ */
+static void ovpn_dst_cache_check_key(struct ovpn_peer *peer,
+ struct dst_cache *cache,
+ const struct ovpn_route_key *key)
+{
+ struct ovpn_route_key old_key;
+ unsigned int seq;
+
+ /* snapshot the saved key before deciding whether the cache matches */
+ do {
+ seq = read_seqcount_begin(&peer->route_key_seq);
+ old_key = peer->route_key;
+ } while (read_seqcount_retry(&peer->route_key_seq, seq));
+
+ /* nothing changed: the current cache can be reused */
+ if (likely(ovpn_route_key_equal(&old_key, key)))
+ return;
+
+ /* recheck under lock because another path may have updated the key */
+ spin_lock_bh(&peer->lock);
+ if (!ovpn_route_key_equal(&peer->route_key, key)) {
+ write_seqcount_begin(&peer->route_key_seq);
+ peer->route_key = *key;
+ dst_cache_reset(cache);
+ write_seqcount_end(&peer->route_key_seq);
+ }
+ spin_unlock_bh(&peer->lock);
+}
+
/**
* ovpn_udp4_output - send IPv4 packet over udp socket
* @peer: the destination peer
@@ -138,21 +180,23 @@ static int ovpn_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
* @cache: dst cache
* @sk: the socket to send the packet over
* @skb: the packet to send
+ * @key: the route key snapshot used for cache validation and flow lookup
*
* Return: 0 on success or a negative error code otherwise
*/
static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
struct dst_cache *cache, struct sock *sk,
- struct sk_buff *skb)
+ struct sk_buff *skb,
+ const struct ovpn_route_key *key)
{
struct rtable *rt;
struct flowi4 fl = {
.saddr = bind->local.ipv4.s_addr,
.daddr = bind->remote.in4.sin_addr.s_addr,
- .fl4_sport = inet_sk(sk)->inet_sport,
+ .fl4_sport = key->sport,
.fl4_dport = bind->remote.in4.sin_port,
.flowi4_proto = sk->sk_protocol,
- .flowi4_mark = sk->sk_mark,
+ .flowi4_mark = key->mark,
};
int ret;
@@ -193,7 +237,12 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
ret);
goto err;
}
- dst_cache_set_ip4(cache, &rt->dst, fl.saddr);
+
+ /* avoid storing a stale cache */
+ spin_lock_bh(&peer->lock);
+ if (likely(ovpn_route_key_equal(key, &peer->route_key)))
+ dst_cache_set_ip4(cache, &rt->dst, fl.saddr);
+ spin_unlock_bh(&peer->lock);
transmit:
udp_tunnel_xmit_skb(rt, sk, skb, fl.saddr, fl.daddr, 0,
@@ -213,12 +262,14 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
* @cache: dst cache
* @sk: the socket to send the packet over
* @skb: the packet to send
+ * @key: the route key snapshot used for cache validation and flow lookup
*
* Return: 0 on success or a negative error code otherwise
*/
static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
struct dst_cache *cache, struct sock *sk,
- struct sk_buff *skb)
+ struct sk_buff *skb,
+ const struct ovpn_route_key *key)
{
struct dst_entry *dst;
int ret;
@@ -226,10 +277,10 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
struct flowi6 fl = {
.saddr = bind->local.ipv6,
.daddr = bind->remote.in6.sin6_addr,
- .fl6_sport = inet_sk(sk)->inet_sport,
+ .fl6_sport = key->sport,
.fl6_dport = bind->remote.in6.sin6_port,
.flowi6_proto = sk->sk_protocol,
- .flowi6_mark = sk->sk_mark,
+ .flowi6_mark = key->mark,
.flowi6_oif = bind->remote.in6.sin6_scope_id,
};
@@ -259,7 +310,12 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
&bind->remote.in6, ret);
goto err;
}
- dst_cache_set_ip6(cache, dst, &fl.saddr);
+
+ /* avoid storing a stale cache */
+ spin_lock_bh(&peer->lock);
+ if (likely(ovpn_route_key_equal(key, &peer->route_key)))
+ dst_cache_set_ip6(cache, dst, &fl.saddr);
+ spin_unlock_bh(&peer->lock);
transmit:
/* user IPv6 packets may be larger than the transport interface
@@ -288,6 +344,7 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
* @cache: dst cache
* @sk: the socket to send the packet over
* @skb: the packet to send
+ * @key: route key snapshot used for cache validation and flow lookup
*
* rcu_read_lock should be held on entry.
* On return, the skb is consumed.
@@ -295,7 +352,8 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
* Return: 0 on success or a negative error code otherwise
*/
static int ovpn_udp_output(struct ovpn_peer *peer, struct dst_cache *cache,
- struct sock *sk, struct sk_buff *skb)
+ struct sock *sk, struct sk_buff *skb,
+ struct ovpn_route_key *key)
{
struct ovpn_bind *bind;
int ret;
@@ -315,11 +373,11 @@ static int ovpn_udp_output(struct ovpn_peer *peer, struct dst_cache *cache,
switch (bind->remote.in4.sin_family) {
case AF_INET:
- ret = ovpn_udp4_output(peer, bind, cache, sk, skb);
+ ret = ovpn_udp4_output(peer, bind, cache, sk, skb, key);
break;
#if IS_ENABLED(CONFIG_IPV6)
case AF_INET6:
- ret = ovpn_udp6_output(peer, bind, cache, sk, skb);
+ ret = ovpn_udp6_output(peer, bind, cache, sk, skb, key);
break;
#endif
default:
@@ -341,15 +399,21 @@ static int ovpn_udp_output(struct ovpn_peer *peer, struct dst_cache *cache,
void ovpn_udp_send_skb(struct ovpn_peer *peer, struct sock *sk,
struct sk_buff *skb)
{
+ struct ovpn_route_key key = {
+ .mark = READ_ONCE(sk->sk_mark),
+ .sport = READ_ONCE(inet_sk(sk)->inet_sport),
+ };
int ret;
skb->dev = peer->ovpn->dev;
- skb->mark = READ_ONCE(sk->sk_mark);
+ skb->mark = key.mark;
/* no checksum performed at this layer */
skb->ip_summed = CHECKSUM_NONE;
+ ovpn_dst_cache_check_key(peer, &peer->dst_cache, &key);
+
/* crypto layer -> transport (UDP) */
- ret = ovpn_udp_output(peer, &peer->dst_cache, sk, skb);
+ ret = ovpn_udp_output(peer, &peer->dst_cache, sk, skb, &key);
if (unlikely(ret < 0))
kfree_skb(skb);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 119/457] ovpn: validate peer state before caching UDP dst
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 118/457] ovpn: track UDP socket route key for peer dst cache Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 120/457] ovpn: replace bind when learning local endpoint Greg Kroah-Hartman
` (348 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit fa603710bdb9aea33c0d9cc2c05ed24d84f58753 ]
UDP route lookup runs without peer->lock while the bind is protected by
RCU. The route key is snapshotted separately. Either can change while
the lookup is in progress.
The TX path currently checks only the route key before publishing the
looked-up dst. If the bind changes but the route key does not, a dst
resolved from the old endpoint can be installed in the cache after the
bind replacement.
Compare both the bind pointer and the route key under peer->lock before
updating the cache. The RCU read-side critical section keeps the old
bind alive throughout the lookup, so pointer identity is sufficient to
detect a replacement.
Fixes: f0281c1d3732 ("ovpn: add support for updating local or remote UDP endpoint")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/udp.c | 33 +++++++++++++++++++++++++++++++--
1 file changed, 31 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c
index c6d591cb7ff45..eeef4a7229f5b 100644
--- a/drivers/net/ovpn/udp.c
+++ b/drivers/net/ovpn/udp.c
@@ -173,6 +173,35 @@ static void ovpn_dst_cache_check_key(struct ovpn_peer *peer,
spin_unlock_bh(&peer->lock);
}
+/**
+ * ovpn_dst_cache_current - check whether a route lookup matches peer state
+ * @peer: the peer owning the bind and dst cache
+ * @bind: the RCU bind used for the route lookup
+ * @key: the route key used for the route lookup
+ *
+ * Check that @bind is still the current peer bind and that @key still matches
+ * the peer route key. The caller must hold @peer->lock. The TX path keeps
+ * @bind inside an RCU read-side critical section, so pointer identity is enough
+ * to detect whether the bind was replaced while the route lookup was running.
+ *
+ * Return: true if the lookup result still matches the current peer state and
+ * may update the dst cache.
+ */
+static bool ovpn_dst_cache_current(const struct ovpn_peer *peer,
+ const struct ovpn_bind *bind,
+ const struct ovpn_route_key *key)
+{
+ const struct ovpn_bind *curr_bind;
+
+ lockdep_assert_held(&peer->lock);
+
+ curr_bind = rcu_dereference_protected(peer->bind,
+ lockdep_is_held(&peer->lock));
+
+ return curr_bind == bind &&
+ ovpn_route_key_equal(key, &peer->route_key);
+}
+
/**
* ovpn_udp4_output - send IPv4 packet over udp socket
* @peer: the destination peer
@@ -240,7 +269,7 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
/* avoid storing a stale cache */
spin_lock_bh(&peer->lock);
- if (likely(ovpn_route_key_equal(key, &peer->route_key)))
+ if (likely(ovpn_dst_cache_current(peer, bind, key)))
dst_cache_set_ip4(cache, &rt->dst, fl.saddr);
spin_unlock_bh(&peer->lock);
@@ -313,7 +342,7 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
/* avoid storing a stale cache */
spin_lock_bh(&peer->lock);
- if (likely(ovpn_route_key_equal(key, &peer->route_key)))
+ if (likely(ovpn_dst_cache_current(peer, bind, key)))
dst_cache_set_ip6(cache, dst, &fl.saddr);
spin_unlock_bh(&peer->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 120/457] ovpn: replace bind when learning local endpoint
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 119/457] ovpn: validate peer state before caching UDP dst Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 121/457] ovpn: replace bind when clearing stale local source Greg Kroah-Hartman
` (347 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit aea934a221ec6a867221e5b765f65f1857befd53 ]
struct ovpn_bind is published through peer->bind with RCU, but local
endpoint learning updates bind->local in place under peer->lock. UDP TX
reads the field without that lock. In particular, a concurrent IPv6
update can therefore result in a torn address read.
Use ovpn_peer_reset_sockaddr to publish a replacement bind when learning
a new local endpoint, just as a remote endpoint change does. Preserve
the current remote address and reset the dst cache only after the new
bind has been published successfully.
Track remote endpoint changes separately so that float notification and
transport-address rehashing remain limited to actual peer floats.
Fixes: f0281c1d3732 ("ovpn: add support for updating local or remote UDP endpoint")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/peer.c | 43 ++++++++++++++++++++++-------------------
1 file changed, 23 insertions(+), 20 deletions(-)
diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c
index b400783c2efab..430c6cd48db87 100644
--- a/drivers/net/ovpn/peer.c
+++ b/drivers/net/ovpn/peer.c
@@ -200,13 +200,12 @@ static void __ovpn_peer_hash_transp_addr(struct ovpn_peer *peer,
*/
void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb)
{
+ const void *local_ip = NULL;
struct sockaddr_storage ss;
struct sockaddr_in6 *sa6;
- bool reset_cache = false;
struct sockaddr_in *sa;
struct ovpn_bind *bind;
- const void *local_ip;
- size_t salen = 0;
+ bool floated = false;
spin_lock_bh(&peer->lock);
bind = rcu_dereference_protected(peer->bind,
@@ -233,8 +232,7 @@ void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb)
.sin_addr.s_addr = ip_hdr(skb)->saddr,
.sin_port = udp_hdr(skb)->source,
};
- salen = sizeof(*sa);
- reset_cache = true;
+ floated = true;
break;
}
@@ -246,10 +244,12 @@ void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb)
netdev_name(peer->ovpn->dev),
peer->id, &bind->local.ipv4.s_addr,
&ip_hdr(skb)->daddr);
- bind->local.ipv4.s_addr = ip_hdr(skb)->daddr;
- reset_cache = true;
+ local_ip = &ip_hdr(skb)->daddr;
+ memcpy(&ss, &bind->remote, sizeof(struct sockaddr_in));
+ break;
}
- break;
+ /* nothing changed */
+ goto unlock;
case htons(ETH_P_IPV6):
/* float check */
if (unlikely(!ovpn_bind_skb_src_match(bind, skb))) {
@@ -271,8 +271,7 @@ void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb)
ipv6_iface_scope_id(&ipv6_hdr(skb)->saddr,
skb->skb_iif),
};
- salen = sizeof(*sa6);
- reset_cache = true;
+ floated = true;
break;
}
@@ -285,26 +284,30 @@ void ovpn_peer_endpoints_update(struct ovpn_peer *peer, struct sk_buff *skb)
netdev_name(peer->ovpn->dev),
peer->id, &bind->local.ipv6,
&ipv6_hdr(skb)->daddr);
- bind->local.ipv6 = ipv6_hdr(skb)->daddr;
- reset_cache = true;
+ local_ip = &ipv6_hdr(skb)->daddr;
+ memcpy(&ss, &bind->remote, sizeof(struct sockaddr_in6));
+ break;
}
- break;
+ /* nothing changed */
+ goto unlock;
default:
goto unlock;
}
- if (unlikely(reset_cache))
- dst_cache_reset(&peer->dst_cache);
-
- /* if the peer did not float, we can bail out now */
- if (likely(!salen))
- goto unlock;
-
if (unlikely(ovpn_peer_reset_sockaddr(peer,
(struct sockaddr_storage *)&ss,
local_ip) < 0))
goto unlock;
+ /* reset the cache only after a successful bind update to avoid useless
+ * cache misses on concurrent TX
+ */
+ dst_cache_reset(&peer->dst_cache);
+
+ /* if only the local address changed, bail out now */
+ if (!floated)
+ goto unlock;
+
net_dbg_ratelimited("%s: peer %d floated to %pIScp",
netdev_name(peer->ovpn->dev), peer->id, &ss);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 121/457] ovpn: replace bind when clearing stale local source
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 120/457] ovpn: replace bind when learning local endpoint Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 122/457] ovpn: always unhash old VPN addresses before rehashing Greg Kroah-Hartman
` (346 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 7d8104988f423572df1f3347ce578037b1043f34 ]
The UDP output fallback clears bind->local in place when the remembered
source address is no longer usable. The bind is RCU-published and read
locklessly by concurrent TX, so an IPv6 reader can observe a torn
address.
Retry the route lookup with source address autoselection without
modifying the bind. After a successful lookup, revalidate the bind and
route key under peer->lock, reset the dst cache, and best-effort publish
a replacement bind with a wildcard local address.
Do not cache the resolved dst when clearing the local source. Replacing
the source invalidates all per-CPU cache entries, while
dst_cache_set_ip4 and dst_cache_set_ip6 update only the current CPU
slot. The current packet can still use the resolved route; if bind
allocation fails, a later cache miss retries the repair.
Fixes: 08857b5ec5d9 ("ovpn: implement basic TX path (UDP)")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/udp.c | 81 +++++++++++++++++++++++++++++-------------
1 file changed, 56 insertions(+), 25 deletions(-)
diff --git a/drivers/net/ovpn/udp.c b/drivers/net/ovpn/udp.c
index eeef4a7229f5b..055cdb1bee13b 100644
--- a/drivers/net/ovpn/udp.c
+++ b/drivers/net/ovpn/udp.c
@@ -185,7 +185,7 @@ static void ovpn_dst_cache_check_key(struct ovpn_peer *peer,
* to detect whether the bind was replaced while the route lookup was running.
*
* Return: true if the lookup result still matches the current peer state and
- * may update the dst cache.
+ * may update the dst cache or replace the bind.
*/
static bool ovpn_dst_cache_current(const struct ovpn_peer *peer,
const struct ovpn_bind *bind,
@@ -218,6 +218,9 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
struct sk_buff *skb,
const struct ovpn_route_key *key)
{
+ struct sockaddr_storage remote;
+ struct in_addr local = {};
+ bool reset_local = false;
struct rtable *rt;
struct flowi4 fl = {
.saddr = bind->local.ipv4.s_addr,
@@ -236,24 +239,17 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
if (fl.saddr && unlikely(!inet_confirm_addr(sock_net(sk), NULL, 0,
fl.saddr, RT_SCOPE_HOST))) {
- /* we may end up here when the cached address is not usable
- * anymore. In this case we reset address/cache and perform a
- * new look up
+ /* The learned local address is not usable anymore.
+ * Retry with source address autoselection.
*/
fl.saddr = 0;
- spin_lock_bh(&peer->lock);
- bind->local.ipv4.s_addr = 0;
- spin_unlock_bh(&peer->lock);
- dst_cache_reset(cache);
+ reset_local = true;
}
rt = ip_route_output_flow(sock_net(sk), &fl, sk);
if (IS_ERR(rt) && PTR_ERR(rt) == -EINVAL) {
fl.saddr = 0;
- spin_lock_bh(&peer->lock);
- bind->local.ipv4.s_addr = 0;
- spin_unlock_bh(&peer->lock);
- dst_cache_reset(cache);
+ reset_local = true;
rt = ip_route_output_flow(sock_net(sk), &fl, sk);
}
@@ -267,10 +263,28 @@ static int ovpn_udp4_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
goto err;
}
- /* avoid storing a stale cache */
+ /* avoid storing a stale cache or local address */
spin_lock_bh(&peer->lock);
- if (likely(ovpn_dst_cache_current(peer, bind, key)))
- dst_cache_set_ip4(cache, &rt->dst, fl.saddr);
+ if (likely(ovpn_dst_cache_current(peer, bind, key))) {
+ if (!reset_local) {
+ dst_cache_set_ip4(cache, &rt->dst, fl.saddr);
+ spin_unlock_bh(&peer->lock);
+ goto transmit;
+ }
+
+ /* invalidate per-CPU dst entries that may still carry
+ * the stale source
+ */
+ dst_cache_reset(cache);
+
+ /* preserve the current remote */
+ memcpy(&remote, &bind->remote, sizeof(struct sockaddr_in));
+ /* The current packet already has a valid wildcard-source route.
+ * If replacing the bind fails, leave the stale local in place;
+ * a later cache miss will retry the repair.
+ */
+ ovpn_peer_reset_sockaddr(peer, &remote, &local);
+ }
spin_unlock_bh(&peer->lock);
transmit:
@@ -300,6 +314,9 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
struct sk_buff *skb,
const struct ovpn_route_key *key)
{
+ struct in6_addr local = in6addr_any;
+ struct sockaddr_storage remote;
+ bool reset_local = false;
struct dst_entry *dst;
int ret;
@@ -320,15 +337,11 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
if (!ipv6_addr_any(&fl.saddr) &&
unlikely(!ipv6_chk_addr(sock_net(sk), &fl.saddr, NULL, 0))) {
- /* we may end up here when the cached address is not usable
- * anymore. In this case we reset address/cache and perform a
- * new look up
+ /* The learned local address is not usable anymore.
+ * Retry with source address autoselection.
*/
fl.saddr = in6addr_any;
- spin_lock_bh(&peer->lock);
- bind->local.ipv6 = in6addr_any;
- spin_unlock_bh(&peer->lock);
- dst_cache_reset(cache);
+ reset_local = true;
}
dst = ip6_dst_lookup_flow(sock_net(sk), sk, &fl, NULL);
@@ -340,10 +353,28 @@ static int ovpn_udp6_output(struct ovpn_peer *peer, struct ovpn_bind *bind,
goto err;
}
- /* avoid storing a stale cache */
+ /* avoid storing a stale cache or local address */
spin_lock_bh(&peer->lock);
- if (likely(ovpn_dst_cache_current(peer, bind, key)))
- dst_cache_set_ip6(cache, dst, &fl.saddr);
+ if (likely(ovpn_dst_cache_current(peer, bind, key))) {
+ if (!reset_local) {
+ dst_cache_set_ip6(cache, dst, &fl.saddr);
+ spin_unlock_bh(&peer->lock);
+ goto transmit;
+ }
+
+ /* invalidate per-CPU dst entries that may still carry
+ * the stale source
+ */
+ dst_cache_reset(cache);
+
+ /* preserve the current remote */
+ memcpy(&remote, &bind->remote, sizeof(struct sockaddr_in6));
+ /* The current packet already has a valid wildcard-source route.
+ * If replacing the bind fails, leave the stale local in place;
+ * a later cache miss will retry the repair.
+ */
+ ovpn_peer_reset_sockaddr(peer, &remote, &local);
+ }
spin_unlock_bh(&peer->lock);
transmit:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 122/457] ovpn: always unhash old VPN addresses before rehashing
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 121/457] ovpn: replace bind when clearing stale local source Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 123/457] ovpn: reject duplicate peer VPN addresses Greg Kroah-Hartman
` (345 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit b43beccb3713fafada57814b0a652f4a876eb75f ]
ovpn_peer_hash_vpn_ip updates the per-peer VPN address hash entries
after userspace changes a peer VPN address. The current code removes an
old hash entry only when the new address for that family is not the
unspecified address.
When an address is cleared to 0.0.0.0 or ::, its hash node therefore
remains linked in the bucket selected by the old address. The address
comparison performed during lookup prevents the old address from
matching, but the table retains a stale entry until the peer is removed
or another address is configured for that family.
Always remove both old VPN address hash entries before conditionally
adding the currently configured addresses back. This ensures that a
cleared address leaves its hash node unhashed.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/peer.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c
index 430c6cd48db87..bbd9e17fb0bfa 100644
--- a/drivers/net/ovpn/peer.c
+++ b/drivers/net/ovpn/peer.c
@@ -994,10 +994,11 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer)
if (hlist_unhashed(&peer->hash_entry_id))
return;
- if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) {
- /* remove potential old hashing */
- hlist_nulls_del_init_rcu(&peer->hash_entry_addr4);
+ /* remove potential old hashing */
+ hlist_nulls_del_init_rcu(&peer->hash_entry_addr4);
+ hlist_nulls_del_init_rcu(&peer->hash_entry_addr6);
+ if (peer->vpn_addrs.ipv4.s_addr != htonl(INADDR_ANY)) {
nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr4,
&peer->vpn_addrs.ipv4,
sizeof(peer->vpn_addrs.ipv4));
@@ -1005,9 +1006,6 @@ void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer)
}
if (!ipv6_addr_any(&peer->vpn_addrs.ipv6)) {
- /* remove potential old hashing */
- hlist_nulls_del_init_rcu(&peer->hash_entry_addr6);
-
nhead = ovpn_get_hash_head(peer->ovpn->peers->by_vpn_addr6,
&peer->vpn_addrs.ipv6,
sizeof(peer->vpn_addrs.ipv6));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 123/457] ovpn: reject duplicate peer VPN addresses
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 122/457] ovpn: always unhash old VPN addresses before rehashing Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 124/457] ovpn: reject multipeer peers without " Greg Kroah-Hartman
` (344 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit d25e885b31a0f2808d936f95c9a558a8a792669b ]
In MP mode, ovpn uses the peer VPN addresses as lookup keys for
selecting the peer that should receive an outgoing tunnel packet.
However, the netlink peer configuration path does not currently reject
duplicate VPN addresses.
If two peers are configured with the same VPN address, both can be
inserted in the VPN address hash table and lookups return whichever peer
is found first. This makes peer selection ambiguous and dependent on
hash insertion order.
Reject peer creation or update when the resulting VPN address is already
assigned to another peer. Ignore unspecified addresses because those are
not inserted in the VPN address hash tables.
This changes such configurations from being accepted to being rejected,
but they have never worked reliably because peer selection is ambiguous.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/netlink.c | 37 ++++++++++++++++-----
drivers/net/ovpn/peer.c | 67 +++++++++++++++++++++++++++++++++++++-
drivers/net/ovpn/peer.h | 6 ++++
3 files changed, 101 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index 2ba762082acc1..e23f7d1f49e01 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -480,8 +480,10 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info)
int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
{
- struct nlattr *attrs[OVPN_A_PEER_MAX + 1];
struct ovpn_priv *ovpn = info->user_ptr[0];
+ struct nlattr *attrs[OVPN_A_PEER_MAX + 1];
+ struct in6_addr vpn_addr6;
+ struct in_addr vpn_addr4;
struct ovpn_socket *sock;
struct ovpn_peer *peer;
u32 peer_id;
@@ -528,28 +530,47 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
rcu_read_unlock();
spin_lock_bh(&ovpn->lock);
- ret = ovpn_nl_peer_modify(peer, info, attrs);
- if (ret < 0) {
- spin_unlock_bh(&ovpn->lock);
- ovpn_peer_put(peer);
- return ret;
+
+ /* reject peer with conflicting VPN address */
+ if (attrs[OVPN_A_PEER_VPN_IPV4]) {
+ vpn_addr4.s_addr = nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]);
+ if (ovpn_peer_vpn_addr_conflict4(ovpn, peer, &vpn_addr4))
+ goto addr_conflict;
}
+ if (attrs[OVPN_A_PEER_VPN_IPV6]) {
+ vpn_addr6 = nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]);
+ if (ovpn_peer_vpn_addr_conflict6(ovpn, peer, &vpn_addr6))
+ goto addr_conflict;
+ }
+
+ ret = ovpn_nl_peer_modify(peer, info, attrs);
+ if (ret < 0)
+ goto unlock;
/* ret == 1 means that VPN IPv4/6 has been modified and rehashing
* is required
*/
- if (ret > 0)
+ if (ret > 0) {
ovpn_peer_hash_vpn_ip(peer);
+ ret = 0;
+ }
/* if the remote endpoint was updated, the by_transp_addr hash bucket
* also needs to be refreshed, otherwise incoming packets from the new
* remote address would fail the lockless lookup
*/
if (attrs[OVPN_A_PEER_REMOTE_IPV4] || attrs[OVPN_A_PEER_REMOTE_IPV6])
ovpn_peer_hash_transp_addr(peer);
+
+unlock:
spin_unlock_bh(&ovpn->lock);
ovpn_peer_put(peer);
- return 0;
+ return ret;
+addr_conflict:
+ NL_SET_ERR_MSG_FMT_MOD(info->extack,
+ "VPN IP is already assigned to another peer");
+ ret = -EADDRINUSE;
+ goto unlock;
}
static int ovpn_nl_send_peer(struct sk_buff *skb, const struct genl_info *info,
diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c
index bbd9e17fb0bfa..2067825bb5b61 100644
--- a/drivers/net/ovpn/peer.c
+++ b/drivers/net/ovpn/peer.c
@@ -488,7 +488,7 @@ static struct ovpn_peer *ovpn_peer_get_by_vpn_addr4(struct ovpn_priv *ovpn,
* Return: the peer if found or NULL otherwise
*/
static struct ovpn_peer *ovpn_peer_get_by_vpn_addr6(struct ovpn_priv *ovpn,
- struct in6_addr *addr)
+ const struct in6_addr *addr)
{
struct hlist_nulls_head *nhead;
struct hlist_nulls_node *ntmp;
@@ -513,6 +513,64 @@ static struct ovpn_peer *ovpn_peer_get_by_vpn_addr6(struct ovpn_priv *ovpn,
return NULL;
}
+/**
+ * ovpn_peer_vpn_addr_conflict4 - check if the VPN v4 address is already in use
+ * @ovpn: the openvpn instance to search
+ * @peer: peer being added or updated, or NULL
+ * @addr: VPN IPv4 address to check
+ *
+ * Check whether @addr is already assigned to another peer. @peer is ignored
+ * when found, allowing peer updates that keep an existing address.
+ * Unspecified addresses are ignored.
+ *
+ * Note: the caller must hold @ovpn->lock.
+ *
+ * Return: true on conflict, false otherwise.
+ */
+bool ovpn_peer_vpn_addr_conflict4(struct ovpn_priv *ovpn,
+ const struct ovpn_peer *peer,
+ const struct in_addr *addr)
+{
+ struct ovpn_peer *tmp = NULL;
+
+ lockdep_assert_held(&ovpn->lock);
+
+ /* we don't hash INADDR_ANY, no conflict in that case */
+ if (addr->s_addr != htonl(INADDR_ANY))
+ tmp = ovpn_peer_get_by_vpn_addr4(ovpn, addr->s_addr);
+
+ return tmp && tmp != peer;
+}
+
+/**
+ * ovpn_peer_vpn_addr_conflict6 - check if the VPN v6 address is already in use
+ * @ovpn: the openvpn instance to search
+ * @peer: peer being added or updated, or NULL
+ * @addr: VPN IPv6 address to check
+ *
+ * Check whether @addr is already assigned to another peer. @peer is ignored
+ * when found, allowing peer updates that keep an existing address.
+ * Unspecified addresses are ignored.
+ *
+ * Note: the caller must hold @ovpn->lock.
+ *
+ * Return: true on conflict, false otherwise.
+ */
+bool ovpn_peer_vpn_addr_conflict6(struct ovpn_priv *ovpn,
+ const struct ovpn_peer *peer,
+ const struct in6_addr *addr)
+{
+ struct ovpn_peer *tmp = NULL;
+
+ lockdep_assert_held(&ovpn->lock);
+
+ /* we don't hash ::, no conflict in that case */
+ if (!ipv6_addr_any(addr))
+ tmp = ovpn_peer_get_by_vpn_addr6(ovpn, addr);
+
+ return tmp && tmp != peer;
+}
+
/**
* ovpn_peer_transp_match - check if sockaddr and peer binding match
* @peer: the peer to get the binding from
@@ -1040,6 +1098,13 @@ static int ovpn_peer_add_mp(struct ovpn_priv *ovpn, struct ovpn_peer *peer)
goto out;
}
+ /* reject peer with conflicting VPN address */
+ if (ovpn_peer_vpn_addr_conflict4(ovpn, NULL, &peer->vpn_addrs.ipv4) ||
+ ovpn_peer_vpn_addr_conflict6(ovpn, NULL, &peer->vpn_addrs.ipv6)) {
+ ret = -EADDRINUSE;
+ goto out;
+ }
+
bind = rcu_dereference_protected(peer->bind, true);
/* peers connected via TCP have bind == NULL */
if (bind) {
diff --git a/drivers/net/ovpn/peer.h b/drivers/net/ovpn/peer.h
index 063535699ecd8..1879bfb76992d 100644
--- a/drivers/net/ovpn/peer.h
+++ b/drivers/net/ovpn/peer.h
@@ -164,6 +164,12 @@ struct ovpn_peer *ovpn_peer_get_by_transp_addr(struct ovpn_priv *ovpn,
struct ovpn_peer *ovpn_peer_get_by_id(struct ovpn_priv *ovpn, u32 peer_id);
struct ovpn_peer *ovpn_peer_get_by_dst(struct ovpn_priv *ovpn,
struct sk_buff *skb);
+bool ovpn_peer_vpn_addr_conflict4(struct ovpn_priv *ovpn,
+ const struct ovpn_peer *peer,
+ const struct in_addr *addr);
+bool ovpn_peer_vpn_addr_conflict6(struct ovpn_priv *ovpn,
+ const struct ovpn_peer *peer,
+ const struct in6_addr *addr);
void ovpn_peer_hash_vpn_ip(struct ovpn_peer *peer);
void ovpn_peer_hash_transp_addr(struct ovpn_peer *peer);
bool ovpn_peer_check_by_src(struct ovpn_priv *ovpn, struct sk_buff *skb,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 124/457] ovpn: reject multipeer peers without VPN addresses
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 123/457] ovpn: reject duplicate peer VPN addresses Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 125/457] ovpn: reject invalid peer " Greg Kroah-Hartman
` (343 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 025af3a0a892514f9f27f186338ba3d44365547a ]
In MP mode, ovpn uses the peer VPN addresses to select the peer for
outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or
IPv6 attribute, but it only checks for the presence of the attribute and
not for a usable address value.
This allows userspace to create an MP peer with only unspecified VPN
addresses, or to update an existing peer so that both VPN address
families become unspecified. Such a peer cannot be selected through the
VPN address hash tables.
Reject MP peer creation or update when the resulting peer would not have
at least one VPN address configured.
This changes such configurations from being accepted to being rejected,
but they have never been usable because the peer cannot be selected
through the VPN address hash tables.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/netlink.c | 36 ++++++++++++++++++++++++++++++------
1 file changed, 30 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index e23f7d1f49e01..e9e0f75e04433 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -352,8 +352,10 @@ static int ovpn_nl_peer_modify(struct ovpn_peer *peer, struct genl_info *info,
int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info)
{
- struct nlattr *attrs[OVPN_A_PEER_MAX + 1];
+ struct in_addr vpn_addr4 = { .s_addr = htonl(INADDR_ANY) };
+ struct in6_addr vpn_addr6 = IN6ADDR_ANY_INIT;
struct ovpn_priv *ovpn = info->user_ptr[0];
+ struct nlattr *attrs[OVPN_A_PEER_MAX + 1];
struct ovpn_socket *ovpn_sock;
struct socket *sock = NULL;
struct ovpn_peer *peer;
@@ -377,11 +379,20 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info)
return -EINVAL;
/* in MP mode VPN IPs are required for selecting the right peer */
- if (ovpn->mode == OVPN_MODE_MP && !attrs[OVPN_A_PEER_VPN_IPV4] &&
- !attrs[OVPN_A_PEER_VPN_IPV6]) {
- NL_SET_ERR_MSG_FMT_MOD(info->extack,
- "VPN IP must be provided in MP mode");
- return -EINVAL;
+ if (ovpn->mode == OVPN_MODE_MP) {
+ if (attrs[OVPN_A_PEER_VPN_IPV4])
+ vpn_addr4.s_addr =
+ nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]);
+ if (attrs[OVPN_A_PEER_VPN_IPV6])
+ vpn_addr6 =
+ nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]);
+
+ if (vpn_addr4.s_addr == htonl(INADDR_ANY) &&
+ ipv6_addr_any(&vpn_addr6)) {
+ NL_SET_ERR_MSG_FMT_MOD(info->extack,
+ "at least one VPN IP must be configured in MP mode");
+ return -EINVAL;
+ }
}
peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]);
@@ -531,6 +542,9 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
spin_lock_bh(&ovpn->lock);
+ vpn_addr4 = peer->vpn_addrs.ipv4;
+ vpn_addr6 = peer->vpn_addrs.ipv6;
+
/* reject peer with conflicting VPN address */
if (attrs[OVPN_A_PEER_VPN_IPV4]) {
vpn_addr4.s_addr = nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]);
@@ -543,6 +557,16 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
goto addr_conflict;
}
+ /* in MP mode VPN IPs are required for selecting the right peer */
+ if (ovpn->mode == OVPN_MODE_MP &&
+ vpn_addr4.s_addr == htonl(INADDR_ANY) &&
+ ipv6_addr_any(&vpn_addr6)) {
+ NL_SET_ERR_MSG_FMT_MOD(info->extack,
+ "at least one VPN IP must be configured in MP mode");
+ ret = -EINVAL;
+ goto unlock;
+ }
+
ret = ovpn_nl_peer_modify(peer, info, attrs);
if (ret < 0)
goto unlock;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 125/457] ovpn: reject invalid peer VPN addresses
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 124/457] ovpn: reject multipeer peers without " Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 126/457] drm/xe/gt_throttle: Report power brake as a throttle reason on CRI Greg Kroah-Hartman
` (342 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ralf Lici, Antonio Quartulli,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
[ Upstream commit 5940f3407b78062442cb01f541ef6eed709fc380 ]
In MP mode, ovpn uses peer VPN addresses as lookup keys for selecting
the peer that should receive outgoing tunnel packets. The netlink
configuration path currently accepts address values that cannot sensibly
identify a VPN peer, such as multicast, broadcast or loopback addresses.
Reject invalid peer VPN addresses when creating or updating an MP peer.
Keep accepting the unspecified address as the internal unset value,
provided that at least one VPN address family remains configured.
Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ovpn/netlink.c | 55 +++++++++++++++++++++++++++++---------
1 file changed, 42 insertions(+), 13 deletions(-)
diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c
index e9e0f75e04433..5432bc2eb8e80 100644
--- a/drivers/net/ovpn/netlink.c
+++ b/drivers/net/ovpn/netlink.c
@@ -185,6 +185,39 @@ static sa_family_t ovpn_nl_family_get(struct nlattr *addr4,
return AF_UNSPEC;
}
+static int ovpn_nl_peer_check_vpn_addrs(const struct in_addr *addr4,
+ const struct in6_addr *addr6,
+ struct genl_info *info)
+{
+ int addr6_type;
+
+ if (addr4->s_addr == htonl(INADDR_ANY) && ipv6_addr_any(addr6)) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "at least one VPN IP must be configured in MP mode");
+ return -EINVAL;
+ }
+
+ if (ipv4_is_multicast(addr4->s_addr) || ipv4_is_lbcast(addr4->s_addr) ||
+ ipv4_is_loopback(addr4->s_addr)) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "VPN IPv4 address must be valid unicast or any");
+ return -EADDRNOTAVAIL;
+ }
+
+ if (!ipv6_addr_any(addr6)) {
+ addr6_type = ipv6_addr_type(addr6);
+
+ if (!(addr6_type & IPV6_ADDR_UNICAST) ||
+ (addr6_type & (IPV6_ADDR_LOOPBACK | IPV6_ADDR_COMPATv4))) {
+ NL_SET_ERR_MSG_MOD(info->extack,
+ "VPN IPv6 address must be valid unicast or any");
+ return -EADDRNOTAVAIL;
+ }
+ }
+
+ return 0;
+}
+
static int ovpn_nl_peer_precheck(struct ovpn_priv *ovpn,
struct genl_info *info,
struct nlattr **attrs)
@@ -387,12 +420,10 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info)
vpn_addr6 =
nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]);
- if (vpn_addr4.s_addr == htonl(INADDR_ANY) &&
- ipv6_addr_any(&vpn_addr6)) {
- NL_SET_ERR_MSG_FMT_MOD(info->extack,
- "at least one VPN IP must be configured in MP mode");
- return -EINVAL;
- }
+ ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6,
+ info);
+ if (ret < 0)
+ return ret;
}
peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]);
@@ -558,13 +589,11 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info)
}
/* in MP mode VPN IPs are required for selecting the right peer */
- if (ovpn->mode == OVPN_MODE_MP &&
- vpn_addr4.s_addr == htonl(INADDR_ANY) &&
- ipv6_addr_any(&vpn_addr6)) {
- NL_SET_ERR_MSG_FMT_MOD(info->extack,
- "at least one VPN IP must be configured in MP mode");
- ret = -EINVAL;
- goto unlock;
+ if (ovpn->mode == OVPN_MODE_MP) {
+ ret = ovpn_nl_peer_check_vpn_addrs(&vpn_addr4, &vpn_addr6,
+ info);
+ if (ret < 0)
+ goto unlock;
}
ret = ovpn_nl_peer_modify(peer, info, attrs);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 126/457] drm/xe/gt_throttle: Report power brake as a throttle reason on CRI
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 125/457] ovpn: reject invalid peer " Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 127/457] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
` (341 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sk Anirban, Raag Jadav,
Matthew Brost, Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sk Anirban <sk.anirban@intel.com>
[ Upstream commit ea4debcd8016f73c5dee3a29250a3d7977f015ef ]
CRI defines bit 5 of the perf limit reasons register as a power brake
(PWRBRK) indicator. Add PWRBRK_MASK and a reason_pwrbrk sysfs attribute
for CRI in place of reason_ratl.
Signed-off-by: Sk Anirban <sk.anirban@intel.com>
Fixes: 8578e6d0546c ("drm/xe/gt_throttle: Drop individual show functions")
Reviewed-by: Raag Jadav <raag.jadav@intel.com>
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260909114931.1039331-2-sk.anirban@intel.com
(cherry picked from commit e199c851c0ab608a0ca89e7be1756a1461b41a2c)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/regs/xe_gt_regs.h | 1 +
drivers/gpu/drm/xe/xe_gt_throttle.c | 5 +++--
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/regs/xe_gt_regs.h b/drivers/gpu/drm/xe/regs/xe_gt_regs.h
index 08251c7a1a4b6..247a736a54aaa 100644
--- a/drivers/gpu/drm/xe/regs/xe_gt_regs.h
+++ b/drivers/gpu/drm/xe/regs/xe_gt_regs.h
@@ -651,6 +651,7 @@
#define MEM_THERMAL_MASK REG_BIT(2)
#define VR_THERMAL_MASK REG_BIT(3)
#define ICCMAX_MASK REG_BIT(4)
+#define PWRBRK_MASK REG_BIT(5)
#define SOC_AVG_THERMAL_MASK REG_BIT(6)
#define FASTVMODE_MASK REG_BIT(7)
#define PSYS_PL1_MASK REG_BIT(12)
diff --git a/drivers/gpu/drm/xe/xe_gt_throttle.c b/drivers/gpu/drm/xe/xe_gt_throttle.c
index 1e7e3a31aa698..c0af5484611d1 100644
--- a/drivers/gpu/drm/xe/xe_gt_throttle.c
+++ b/drivers/gpu/drm/xe/xe_gt_throttle.c
@@ -39,7 +39,7 @@
* - ``reason_mem_thermal``: Memory thermal
* - ``reason_vr_thermal``: VR thermal
* - ``reason_iccmax``: ICCMAX
- * - ``reason_ratl``: RATL thermal algorithm
+ * - ``reason_pwrbrk``: Power brake
* - ``reason_soc_avg_thermal``: SoC average temp
* - ``reason_fastvmode``: VR is hitting FastVMode
* - ``reason_psys_pl1``: PSYS PL1
@@ -200,6 +200,7 @@ static THROTTLE_ATTR_RO(reason_psys_pl1, PSYS_PL1_MASK);
static THROTTLE_ATTR_RO(reason_psys_pl2, PSYS_PL2_MASK);
static THROTTLE_ATTR_RO(reason_p0_freq, P0_FREQ_MASK);
static THROTTLE_ATTR_RO(reason_psys_crit, PSYS_CRIT_MASK);
+static THROTTLE_ATTR_RO(reason_pwrbrk, PWRBRK_MASK);
static struct attribute *cri_throttle_attrs[] = {
/* Common */
@@ -209,12 +210,12 @@ static struct attribute *cri_throttle_attrs[] = {
&attr_reason_pl2.attr.attr,
&attr_reason_pl4.attr.attr,
&attr_reason_prochot.attr.attr,
- &attr_reason_ratl.attr.attr,
/* CRI */
&attr_reason_vr_thermal.attr.attr,
&attr_reason_soc_thermal.attr.attr,
&attr_reason_mem_thermal.attr.attr,
&attr_reason_iccmax.attr.attr,
+ &attr_reason_pwrbrk.attr.attr,
&attr_reason_soc_avg_thermal.attr.attr,
&attr_reason_fastvmode.attr.attr,
&attr_reason_psys_pl1.attr.attr,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 127/457] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 126/457] drm/xe/gt_throttle: Report power brake as a throttle reason on CRI Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 128/457] Bluetooth: btintel_pcie: validate device-supplied DMA indices Greg Kroah-Hartman
` (340 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit f0ca020cbb9bb7f3f4ea8ba1dfcf30a282aec91e ]
Fix multiple out-of-bounds reads in Bluetooth BNEP frame processing:
1. In bnep_rx_frame() and bnep_ctrl_frame() (net/bluetooth/bnep/core.c),
use pskb_may_pull() to verify the BNEP header, control type byte,
filter count, and extension headers exist before reading them, and
return 0 after handling BNEP_CONTROL instead of falling through to
Ethernet frame submission when no extension headers follow.
2. In bnep_net_xmit() (net/bluetooth/bnep/netdev.c), verify skb->len >=
ETH_HLEN with pskb_may_pull() before reading the 14-byte Ethernet
header to prevent an out-of-bounds heap read and infoleak on short
AF_PACKET TX frames.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/bnep/core.c | 17 ++++++++++++++++-
net/bluetooth/bnep/netdev.c | 8 +++++++-
2 files changed, 23 insertions(+), 2 deletions(-)
diff --git a/net/bluetooth/bnep/core.c b/net/bluetooth/bnep/core.c
index f7d88c33e23e4..ad24d2486665a 100644
--- a/net/bluetooth/bnep/core.c
+++ b/net/bluetooth/bnep/core.c
@@ -270,9 +270,14 @@ static int bnep_rx_extension(struct bnep_session *s, struct sk_buff *skb)
BT_DBG("type 0x%x len %u", h->type, h->len);
+ if (skb->len < h->len) {
+ err = -EILSEQ;
+ break;
+ }
+
switch (h->type & BNEP_TYPE_MASK) {
case BNEP_EXT_CONTROL:
- bnep_rx_control(s, skb->data, skb->len);
+ bnep_rx_control(s, skb->data, h->len);
break;
default:
@@ -373,6 +378,11 @@ static int bnep_rx_frame(struct bnep_session *s, struct sk_buff *skb)
goto badframe;
}
+ if ((type & BNEP_TYPE_MASK) == BNEP_CONTROL) {
+ kfree_skb(skb);
+ return 0;
+ }
+
/* Strip 802.1p header */
if (ntohs(s->eh.h_proto) == ETH_P_8021Q) {
if (!skb_pull(skb, 4))
@@ -451,6 +461,11 @@ static int bnep_tx_frame(struct bnep_session *s, struct sk_buff *skb)
goto send;
}
+ if (skb->len < ETH_HLEN) {
+ kfree_skb(skb);
+ return 0;
+ }
+
iv[il++] = (struct kvec) { &type, 1 };
len++;
diff --git a/net/bluetooth/bnep/netdev.c b/net/bluetooth/bnep/netdev.c
index ee1e39a3daffb..b451ef457741f 100644
--- a/net/bluetooth/bnep/netdev.c
+++ b/net/bluetooth/bnep/netdev.c
@@ -166,6 +166,12 @@ static netdev_tx_t bnep_net_xmit(struct sk_buff *skb,
BT_DBG("skb %p, dev %p", skb, dev);
+ if (!pskb_may_pull(skb, ETH_HLEN)) {
+ dev->stats.tx_dropped++;
+ kfree_skb(skb);
+ return NETDEV_TX_OK;
+ }
+
#ifdef CONFIG_BT_BNEP_MC_FILTER
if (bnep_net_mc_filter(skb, s)) {
kfree_skb(skb);
@@ -218,7 +224,7 @@ void bnep_net_setup(struct net_device *dev)
dev->addr_len = ETH_ALEN;
ether_setup(dev);
- dev->min_mtu = 0;
+ dev->min_mtu = ETH_MIN_MTU;
dev->max_mtu = ETH_MAX_MTU;
dev->priv_flags &= ~IFF_TX_SKB_SHARING;
dev->netdev_ops = &bnep_netdev_ops;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 128/457] Bluetooth: btintel_pcie: validate device-supplied DMA indices
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 127/457] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 129/457] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
` (339 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ravindra, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ravindra <ravindra@intel.com>
[ Upstream commit 37a11129345337efd6eef8e62b03b6348cd0dd8b ]
In btintel_pcie_msix_rx_handle(), the driver processes RX completion
descriptors (urbd1) written by the PCIe device into DMA-coherent memory.
urbd1->frbd_tag (a 16-bit field fully controlled by the device firmware
via DMA) is used directly as an array index into rxq->bufs[] without any
bounds check. rxq->bufs[] has only BTINTEL_PCIE_RX_DESCS_COUNT (64)
entries, while frbd_tag can be any value 0-65535. A malicious or
malfunctioning device can write an out-of-range frbd_tag, causing the
driver to dereference an out-of-bounds data_buf pointer.
Additionally, cr_hia is read from a DMA-shared index array also writable
by the device; if the device sets cr_hia >= rxq->count, the while-loop
never terminates because cr_tia is wrapped via modulo rxq->count and can
never equal an out-of-range cr_hia.
Add bounds validation for cr_hia and frbd_tag in the RX path, and cr_hia
in the TX path. Log invalid values with bt_dev_err before returning.
Fixes: c2b636b3f788 ("Bluetooth: btintel_pcie: Add support for PCIe transport")
Signed-off-by: Ravindra <ravindra@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 3262e950a6bd8..9381895dc3cf0 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -1099,6 +1099,11 @@ static void btintel_pcie_msix_tx_handle(struct btintel_pcie_data *data)
txq = &data->txq;
+ if (cr_hia >= txq->count) {
+ bt_dev_err(data->hdev, "TXQ: invalid cr_hia %u", cr_hia);
+ return;
+ }
+
while (cr_tia != cr_hia) {
data->tx_wait_done = true;
wake_up(&data->tx_wait_q);
@@ -1588,6 +1593,11 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data)
rxq = &data->rxq;
+ if (cr_hia >= rxq->count) {
+ bt_dev_err(hdev, "RXQ: invalid cr_hia %u", cr_hia);
+ return;
+ }
+
/* The firmware sends multiple CD in a single MSI-X and it needs to
* process all received CDs in this interrupt.
*/
@@ -1595,6 +1605,12 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data)
urbd1 = &rxq->urbd1s[cr_tia];
ipc_print_urbd1(data->hdev, urbd1, cr_tia);
+ if (urbd1->frbd_tag >= rxq->count) {
+ bt_dev_err(hdev, "RXQ: invalid frbd_tag %u",
+ urbd1->frbd_tag);
+ return;
+ }
+
buf = &rxq->bufs[urbd1->frbd_tag];
if (!buf) {
bt_dev_err(hdev, "RXQ: failed to get the DMA buffer for %d",
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 129/457] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 128/457] Bluetooth: btintel_pcie: validate device-supplied DMA indices Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 130/457] bpf: Reject non-negative offsets in stack_slot_obj_get_spi() Greg Kroah-Hartman
` (338 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit 6d91041bb38b97e2feb625123cc0529d7b83a0e1 ]
While rfcomm_recv_frame() verifies that skb->len is at least
sizeof(*hdr) + 1 (4 bytes: 3-byte header + 1-byte FCS), an RFCOMM frame
with an extended 2-byte length field (!__test_ea(hdr->len)) has a 4-byte
header plus a 1-byte FCS (5 bytes minimum, sizeof(*hdr) + 2).
When a 4-byte RFCOMM frame with EA == 0 arrives:
1. The initial skb->len < sizeof(*hdr) + 1 check passes (4 < 4 is false).
2. Trimming the FCS byte decrements skb->len to 3.
3. If __check_fcs() succeeds, skb_pull(skb, 4) fails (4 > 3) and returns
NULL without advancing skb->data.
4. Because the return value of skb_pull() is ignored, the un-pulled
3-byte struct rfcomm_hdr remains at skb->data and is either queued as
application payload via rfcomm_recv_data() or parsed as a multiplexer
control command via rfcomm_recv_mcc() on DLCI 0.
Fix this by extending the length check in rfcomm_recv_frame() to also
require skb->len >= sizeof(*hdr) + 2 when !__test_ea(hdr->len).
Fixes: b230e5bf501c ("Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c
index 63fa0f542ccf1..3f757198051a2 100644
--- a/net/bluetooth/rfcomm/core.c
+++ b/net/bluetooth/rfcomm/core.c
@@ -1817,7 +1817,8 @@ static struct rfcomm_session *rfcomm_recv_frame(struct rfcomm_session *s,
return s;
}
- if (skb->len < sizeof(*hdr) + 1) {
+ if (skb->len < sizeof(*hdr) + 1 ||
+ (!__test_ea(hdr->len) && skb->len < sizeof(*hdr) + 2)) {
kfree_skb(skb);
return s;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 130/457] bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 129/457] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 131/457] octeontx2-af: Fix memory scaling limitation in SR-IOV mode Greg Kroah-Hartman
` (337 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xu Yunxiang, Andrii Nakryiko,
Sun Jian, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
[ Upstream commit 79a9172f3ab4ad8392c5e5c8944b9b7710ade620 ]
bpf_get_spi() computes (-off - 1) / BPF_REG_SIZE using C division,
which truncates toward zero. For off == 0, this produces spi 0, the
same index used by the valid stack slot at fp-8.
stack_slot_obj_get_spi() currently checks alignment and the resulting
spi bounds, but does not reject the non-negative offset itself. It can
therefore validate a PTR_TO_STACK register holding fp+0 against an
iterator stored at fp-8 even though the runtime receives the actual fp+0
pointer. An effectful iterator kfunc can then interpret memory outside
the BPF stack as iterator state.
Reject non-negative offsets before converting the offset to an spi. All
valid stack objects begin at a negative offset from the frame pointer.
Fixes: 06accc8779c1 ("bpf: add support for open-coded iterator loops")
Signed-off-by: Xu Yunxiang <xyx2021@mail.ustc.edu.cn>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Link: https://lore.kernel.org/bpf/20260920210423.345636-2-xyx2021@mail.ustc.edu.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index dc1a9ef32b78e..cb523cc5465dd 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -582,7 +582,7 @@ static int stack_slot_obj_get_spi(struct bpf_verifier_env *env, struct bpf_reg_s
}
off = reg->var_off.value;
- if (off % BPF_REG_SIZE) {
+ if (off >= 0 || off % BPF_REG_SIZE) {
verbose(env, "cannot pass in %s at an offset=%d\n", obj_kind, off);
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 131/457] octeontx2-af: Fix memory scaling limitation in SR-IOV mode
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 130/457] bpf: Reject non-negative offsets in stack_slot_obj_get_spi() Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 132/457] ipv6: Prevent rt6_insert_exception() for dying fib6_info Greg Kroah-Hartman
` (336 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Ratheesh Kannoth,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ratheesh Kannoth <rkannoth@marvell.com>
[ Upstream commit d06f2ebf67ff2962fe00d687e4f0d4703eb41a12 ]
The original code used DMA_ATTR_FORCE_CONTIGUOUS, which could exhaust
the CMA pool when a large number of VFs were requested.
Fix this by switching to the DMA streaming API. This is equivalent on
Octeon platforms, which provide full I/O coherency via the SMMU.
Cc: Leon Romanovsky <leon@kernel.org>
Fixes: 73d33dbc0723 ("octeontx2-af: Use DMA_ATTR_FORCE_CONTIGUOUS attribute in DMA alloc")
Signed-off-by: Ratheesh Kannoth <rkannoth@marvell.com>
Reviewed-by: Leon Romanovsky <leon@kernel.org>
Link: https://patch.msgid.link/20260916022111.1083017-1-rkannoth@marvell.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../ethernet/marvell/octeontx2/af/common.h | 45 ++++++++++++++++---
1 file changed, 39 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/marvell/octeontx2/af/common.h b/drivers/net/ethernet/marvell/octeontx2/af/common.h
index 779413a383b74..78e42549d9908 100644
--- a/drivers/net/ethernet/marvell/octeontx2/af/common.h
+++ b/drivers/net/ethernet/marvell/octeontx2/af/common.h
@@ -7,6 +7,10 @@
#ifndef COMMON_H
#define COMMON_H
+#include <linux/dma-mapping.h>
+#include <linux/gfp.h>
+#include <linux/mm.h>
+
#include "rvu_struct.h"
#define OTX2_ALIGN 128 /* Align to cacheline */
@@ -44,6 +48,33 @@ struct qmem {
u32 qsize;
};
+static inline void *otx2_dma_alloc_coherent(struct device *dev, size_t size,
+ dma_addr_t *dma_handle)
+{
+ dma_addr_t dma_addr;
+ void *vaddr;
+
+ vaddr = kzalloc(size, GFP_KERNEL);
+ if (!vaddr)
+ return NULL;
+
+ dma_addr = dma_map_single(dev, vaddr, size, DMA_BIDIRECTIONAL);
+ if (dma_mapping_error(dev, dma_addr)) {
+ kfree(vaddr);
+ return NULL;
+ }
+
+ *dma_handle = dma_addr;
+ return vaddr;
+}
+
+static inline void otx2_dma_free_coherent(struct device *dev, size_t size,
+ void *vaddr, dma_addr_t dma_handle)
+{
+ dma_unmap_single(dev, dma_handle, size, DMA_BIDIRECTIONAL);
+ kfree(vaddr);
+}
+
static inline int qmem_alloc(struct device *dev, struct qmem **q,
int qsize, int entry_sz)
{
@@ -60,8 +91,11 @@ static inline int qmem_alloc(struct device *dev, struct qmem **q,
qmem->entry_sz = entry_sz;
qmem->alloc_sz = (qsize * entry_sz) + OTX2_ALIGN;
- qmem->base = dma_alloc_attrs(dev, qmem->alloc_sz, &qmem->iova,
- GFP_KERNEL, DMA_ATTR_FORCE_CONTIGUOUS);
+
+ if (get_order(PAGE_ALIGN(qmem->alloc_sz)) > MAX_PAGE_ORDER)
+ return -ENOMEM;
+
+ qmem->base = otx2_dma_alloc_coherent(dev, qmem->alloc_sz, &qmem->iova);
if (!qmem->base)
return -ENOMEM;
@@ -80,10 +114,9 @@ static inline void qmem_free(struct device *dev, struct qmem *qmem)
return;
if (qmem->base)
- dma_free_attrs(dev, qmem->alloc_sz,
- qmem->base - qmem->align,
- qmem->iova - qmem->align,
- DMA_ATTR_FORCE_CONTIGUOUS);
+ otx2_dma_free_coherent(dev, qmem->alloc_sz,
+ qmem->base - qmem->align,
+ qmem->iova - qmem->align);
devm_kfree(dev, qmem);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 132/457] ipv6: Prevent rt6_insert_exception() for dying fib6_info.
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 131/457] octeontx2-af: Fix memory scaling limitation in SR-IOV mode Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 133/457] net: dont require the hwtstamp NDOs when a PHY provides timestamping Greg Kroah-Hartman
` (335 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 0346ec2f080b40d95ed05b853bb9226289e75212 ]
Before the cited commit, fib6_nh_flush_exceptions() always set
from->exception_bucket_flushed = 1 under rt6_exception_lock to
prevent rt6_insert_exception() from inserting a new exception
for a dying fib6_info.
The flag was replaced with the FIB6_EXCEPTION_BUCKET_FLUSHED
bit stored in nh->rt6i_exception_bucket.
The problem is that now the bit is only set when the bucket
is not NULL and fib6_nh_flush_exceptions() is called from
fib6_nh_release() after fib6_ref has already reached zero.
If rt6_insert_exception() is called while the target fib6_info
is being removed via fib6_purge_rt(), a new exception could be
created successfully because rt6_flush_exceptions() no longer
sets the bit.
This creates a reference cycle between the fib6_info and the
exception route, leaking the fib6_info, its nexthop device,
and all per-CPU routes in fib6_nh->rt6i_pcpu, which stalls netdev
unregistration.
[ 34.680602] unregister_netdevice: waiting for gre6 to become free. Usage count = 68
[ 44.920675] unregister_netdevice: waiting for gre6 to become free. Usage count = 68
[ 55.176582] unregister_netdevice: waiting for gre6 to become free. Usage count = 68
Let's call fib6_drop_pcpu_from() before rt6_flush_exceptions(),
to set fib6_destroying before rt6_exception_lock, and check
f6i->fib6_destroying in rt6_insert_exception().
Note that FIB6_EXCEPTION_BUCKET_FLUSHED logic is dead and
we can clean it up in net-next.
Fixes: cc5c073a693f ("ipv6: Move exception bucket to fib6_nh")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260918082209.2853582-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ip6_fib.c | 2 +-
net/ipv6/route.c | 5 +++++
2 files changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/ip6_fib.c b/net/ipv6/ip6_fib.c
index 7c5daea3f0963..fc3da984a9ab0 100644
--- a/net/ipv6/ip6_fib.c
+++ b/net/ipv6/ip6_fib.c
@@ -1043,8 +1043,8 @@ static void fib6_purge_rt(struct fib6_info *rt, struct fib6_node *fn,
struct fib6_table *table = rt->fib6_table;
/* Flush all cached dst in exception table */
- rt6_flush_exceptions(rt);
fib6_drop_pcpu_from(rt);
+ rt6_flush_exceptions(rt);
if (rt->nh) {
spin_lock(&rt->nh->lock);
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index ee707e48f4efa..c94ad52d03f24 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -1729,6 +1729,11 @@ static int rt6_insert_exception(struct rt6_info *nrt,
spin_lock_bh(&rt6_exception_lock);
+ if (f6i->fib6_destroying) {
+ err = -ENOENT;
+ goto out;
+ }
+
bucket = rcu_dereference_protected(nh->rt6i_exception_bucket,
lockdep_is_held(&rt6_exception_lock));
if (!bucket) {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 133/457] net: dont require the hwtstamp NDOs when a PHY provides timestamping
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 132/457] ipv6: Prevent rt6_insert_exception() for dying fib6_info Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 134/457] dpll: use exact lookup for reference sync pin id Greg Kroah-Hartman
` (334 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Kory Maincent,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 31995571219c8ac30913d9c0dccad033fbb0b3da ]
Removing the legacy ioctl fallback made both hwtstamp NDOs mandatory. A
device that only timestamps in its PHY implements neither, so
SIOCSHWTSTAMP fails with EOPNOTSUPP before anything looks at the PHY and
PTP stops working there.
The check only ever picked the legacy path. That path is gone, so drop it
and test where the NDOs are actually called.
SIOCGHWTSTAMP is new here, not restored. The old path went through
phy_mii_ioctl(), which only handled SIOCSHWTSTAMP.
Such a device now returns -ENODEV while absent instead of -EOPNOTSUPP,
like the ones that do implement the NDOs.
Fixes: 5062245a5a7f ("net: remove legacy way to get/set HW timestamp config")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Kory Maincent <kory.maincent@bootlin.com>
Link: https://patch.msgid.link/20260918095540.34286-1-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev_ioctl.c | 25 +++++++++----------------
1 file changed, 9 insertions(+), 16 deletions(-)
diff --git a/net/core/dev_ioctl.c b/net/core/dev_ioctl.c
index a320e264eaaf0..164643140a523 100644
--- a/net/core/dev_ioctl.c
+++ b/net/core/dev_ioctl.c
@@ -276,19 +276,18 @@ int dev_get_hwtstamp_phylib(struct net_device *dev,
if (phy_is_default_hwtstamp(dev->phydev))
return phy_hwtstamp_get(dev->phydev, cfg);
+ if (!dev->netdev_ops->ndo_hwtstamp_get)
+ return -EOPNOTSUPP;
+
return dev->netdev_ops->ndo_hwtstamp_get(dev, cfg);
}
static int dev_get_hwtstamp(struct net_device *dev, struct ifreq *ifr)
{
- const struct net_device_ops *ops = dev->netdev_ops;
struct kernel_hwtstamp_config kernel_cfg = {};
struct hwtstamp_config cfg;
int err;
- if (!ops->ndo_hwtstamp_get)
- return -EOPNOTSUPP;
-
if (!netif_device_present(dev))
return -ENODEV;
@@ -359,12 +358,18 @@ int dev_set_hwtstamp_phylib(struct net_device *dev,
cfg->source = phy_ts ? HWTSTAMP_SOURCE_PHYLIB : HWTSTAMP_SOURCE_NETDEV;
if (phy_ts && dev->see_all_hwtstamp_requests) {
+ if (!ops->ndo_hwtstamp_get)
+ return -EOPNOTSUPP;
+
err = ops->ndo_hwtstamp_get(dev, &old_cfg);
if (err)
return err;
}
if (!phy_ts || dev->see_all_hwtstamp_requests) {
+ if (!ops->ndo_hwtstamp_set)
+ return -EOPNOTSUPP;
+
err = ops->ndo_hwtstamp_set(dev, cfg, extack);
if (err) {
if (extack->_msg)
@@ -390,7 +395,6 @@ int dev_set_hwtstamp_phylib(struct net_device *dev,
static int dev_set_hwtstamp(struct net_device *dev, struct ifreq *ifr)
{
- const struct net_device_ops *ops = dev->netdev_ops;
struct kernel_hwtstamp_config kernel_cfg = {};
struct netlink_ext_ack extack = {};
struct hwtstamp_config cfg;
@@ -413,9 +417,6 @@ static int dev_set_hwtstamp(struct net_device *dev, struct ifreq *ifr)
return err;
}
- if (!ops->ndo_hwtstamp_set)
- return -EOPNOTSUPP;
-
if (!netif_device_present(dev))
return -ENODEV;
@@ -441,15 +442,11 @@ static int dev_set_hwtstamp(struct net_device *dev, struct ifreq *ifr)
int generic_hwtstamp_get_lower(struct net_device *dev,
struct kernel_hwtstamp_config *kernel_cfg)
{
- const struct net_device_ops *ops = dev->netdev_ops;
int err;
if (!netif_device_present(dev))
return -ENODEV;
- if (!ops->ndo_hwtstamp_get)
- return -EOPNOTSUPP;
-
netdev_lock_ops(dev);
err = dev_get_hwtstamp_phylib(dev, kernel_cfg);
netdev_unlock_ops(dev);
@@ -462,15 +459,11 @@ int generic_hwtstamp_set_lower(struct net_device *dev,
struct kernel_hwtstamp_config *kernel_cfg,
struct netlink_ext_ack *extack)
{
- const struct net_device_ops *ops = dev->netdev_ops;
int err;
if (!netif_device_present(dev))
return -ENODEV;
- if (!ops->ndo_hwtstamp_set)
- return -EOPNOTSUPP;
-
netdev_lock_ops(dev);
err = dev_set_hwtstamp_phylib(dev, kernel_cfg, extack);
netdev_unlock_ops(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 134/457] dpll: use exact lookup for reference sync pin id
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 133/457] net: dont require the hwtstamp NDOs when a PHY provides timestamping Greg Kroah-Hartman
@ 2026-09-30 15:23 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 135/457] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
` (333 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:23 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ivan Vecera, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivan Vecera <ivecera@redhat.com>
[ Upstream commit 7cce782d8327b7291334c4a304cf3fd909a74d9d ]
dpll_pin_ref_sync_state_set() looks up the reference sync pin in the
pin->ref_sync_pins xarray, which is keyed by the sync pin's id (see
dpll_pin_ref_sync_pair_add() using xa_insert() with ref_sync_pin->id).
The pin id to operate on is supplied by userspace via DPLL_A_PIN_ID.
The lookup however used xa_find() with a ULONG_MAX limit, which returns
the first present entry with an index greater than or equal to the
requested id, not the entry stored exactly at that id. If userspace
passes an id that is not paired as a reference sync pin, but another
pin with a higher id is present in the xarray, xa_find() silently
returns that wrong pin and the subsequent ref_sync_set() operates on
it. The request only fails when the given id is larger than every
present key.
Use xa_load() for an exact-key lookup instead, mirroring the deletion
path in dpll_pin_ref_sync_pair_del().
Fixes: 58256a26bfb3 ("dpll: add reference sync get/set")
Signed-off-by: Ivan Vecera <ivecera@redhat.com>
Link: https://patch.msgid.link/20260917143736.526221-1-ivecera@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dpll/dpll_netlink.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dpll/dpll_netlink.c b/drivers/dpll/dpll_netlink.c
index 9e55745e33e4f..9f274c6253c66 100644
--- a/drivers/dpll/dpll_netlink.c
+++ b/drivers/dpll/dpll_netlink.c
@@ -1282,8 +1282,7 @@ dpll_pin_ref_sync_state_set(struct dpll_pin *pin,
unsigned long i;
int ret;
- ref_sync_pin = xa_find(&pin->ref_sync_pins, &ref_sync_pin_idx,
- ULONG_MAX, XA_PRESENT);
+ ref_sync_pin = xa_load(&pin->ref_sync_pins, ref_sync_pin_idx);
if (!ref_sync_pin) {
NL_SET_ERR_MSG(extack, "reference sync pin not found");
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 135/457] net: usb: sr9700: include receive overhead in the length check
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-30 15:23 ` [PATCH 7.2 134/457] dpll: use exact lookup for reference sync pin id Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 136/457] ipv6: Fix dst leak for uncached routes Greg Kroah-Hartman
` (332 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ethan Nelson-Moore, Pengpeng Hou,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <hppiscas@163.com>
[ Upstream commit c06bde80ae7a7b595732f7cabcb92cf08db9d56a ]
The receive fixup subtracts the Ethernet CRC from the reported packet
length, but compares that payload length against the whole remaining
receive buffer. The following copy starts after the three-byte header,
and the cursor advance consumes both that header and the four-byte CRC.
Require the payload to fit after SR_RX_OVERHEAD before copying it or
advancing to the next packet. The loop already ensures that the
remaining buffer is larger than the overhead, so the subtraction is
safe.
The issue was found by our static-analysis tool.
Fixes: c9b37458e956 ("USB2NET : SR9700 : One chip USB 1.1 USB2NET SR9700Device Driver Support")
Reviewed-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Tested-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Signed-off-by: Pengpeng Hou <hppiscas@163.com>
Link: https://patch.msgid.link/20260920034745.18468-1-hppiscas@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/usb/sr9700.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/usb/sr9700.c b/drivers/net/usb/sr9700.c
index 937e6fef3ac6d..50981a28376a5 100644
--- a/drivers/net/usb/sr9700.c
+++ b/drivers/net/usb/sr9700.c
@@ -355,7 +355,8 @@ static int sr9700_rx_fixup(struct usbnet *dev, struct sk_buff *skb)
/* ignore the CRC length */
len = (skb->data[1] | (skb->data[2] << 8)) - 4;
- if (len > ETH_FRAME_LEN || len > skb->len || len < 0)
+ if (len > ETH_FRAME_LEN || len < 0 ||
+ len > skb->len - SR_RX_OVERHEAD)
return 0;
/* the last packet of current skb */
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 136/457] ipv6: Fix dst leak for uncached routes.
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 135/457] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 137/457] udp: relocate a connected socket in the 4-tuple hash table on re-connect Greg Kroah-Hartman
` (331 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Hangbin Liu,
Xuanqiang Luo, Ido Schimmel, Eric Dumazet, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit be31fe6333f534155e6b408f1ef6d77974bb41aa ]
ip6_route_output_flags(), ip6_rt_put_flags(), and ip6_dst_check()
detect an uncached route by list_empty(&rt->dst.rt_uncached),
which replaced the static DST_NOCACHE flag check in commit
a4c2fd7f7891 ("net: remove DST_NOCACHE flag").
When a device is unregistered, rt6_uncached_list_flush_dev()
unlinks uncached routes tied to the device from rt6_uncached_list.
Previously, they were moved to another list with list_move()
(__list_del_entry() + list_add()), and since commit 98aa546af5e4
("inet: remove (struct uncached_list)->quarantine"), the routes
are just unlinked with list_del_init().
If list_del_init() runs concurrently, list_empty() evaluates to
true; ip6_route_output_flags() calls dst_hold_safe() incorrectly
and ip6_rt_put_flags() skips ip6_rt_put(), leaking dst, and thus
dev tied via rt->from as well.
The same race is partially fixed by commit 9a6f0c4d5796 ("dst:
fix races in rt6_uncached_list_del() and rt_del_uncached_list()").
Let's check rt6->dst.rt_uncached_list instead.
Note that IPv4 does not have the same issue.
Fixes: 98aa546af5e4 ("inet: remove (struct uncached_list)->quarantine")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260920191558.2990636-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/ip6_route.h | 4 ++--
net/ipv6/route.c | 7 ++++---
2 files changed, 6 insertions(+), 5 deletions(-)
diff --git a/include/net/ip6_route.h b/include/net/ip6_route.h
index 745ab62154ace..0a6c4ceb95a7a 100644
--- a/include/net/ip6_route.h
+++ b/include/net/ip6_route.h
@@ -101,12 +101,12 @@ static inline struct dst_entry *ip6_route_output(struct net *net,
}
/* Only conditionally release dst if flags indicates
- * !RT6_LOOKUP_F_DST_NOREF or dst is in uncached_list.
+ * !RT6_LOOKUP_F_DST_NOREF or dst is uncached.
*/
static inline void ip6_rt_put_flags(struct rt6_info *rt, int flags)
{
if (!(flags & RT6_LOOKUP_F_DST_NOREF) ||
- !list_empty(&rt->dst.rt_uncached))
+ rt->dst.rt_uncached_list)
ip6_rt_put(rt);
}
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index c94ad52d03f24..8fddcc631fcb6 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -139,6 +139,7 @@ void rt6_uncached_list_add(struct rt6_info *rt)
{
struct uncached_list *ul = raw_cpu_ptr(&rt6_uncached_list);
+ /* Set once and never cleared: non-NULL marks an uncached route. */
rt->dst.rt_uncached_list = ul;
spin_lock_bh(&ul->lock);
@@ -2726,8 +2727,8 @@ struct dst_entry *ip6_route_output_flags(struct net *net,
rcu_read_lock();
dst = ip6_route_output_flags_noref(net, sk, fl6, flags);
rt6 = dst_rt6_info(dst);
- /* For dst cached in uncached_list, refcnt is already taken. */
- if (list_empty(&rt6->dst.rt_uncached) && !dst_hold_safe(dst)) {
+ /* For an uncached dst, refcnt is already taken. */
+ if (!rt6->dst.rt_uncached_list && !dst_hold_safe(dst)) {
dst = &net->ipv6.ip6_null_entry->dst;
dst_hold(dst);
}
@@ -2836,7 +2837,7 @@ INDIRECT_CALLABLE_SCOPE struct dst_entry *ip6_dst_check(struct dst_entry *dst,
from = rcu_dereference(rt->from);
if (from && (rt->rt6i_flags & RTF_PCPU ||
- unlikely(!list_empty(&rt->dst.rt_uncached))))
+ unlikely(rt->dst.rt_uncached_list)))
dst_ret = rt6_dst_from_check(rt, from, cookie);
else
dst_ret = rt6_check(rt, from, cookie);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 137/457] udp: relocate a connected socket in the 4-tuple hash table on re-connect
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 136/457] ipv6: Fix dst leak for uncached routes Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 138/457] udp: remove a disconnected socket from the 4-tuple hash table Greg Kroah-Hartman
` (330 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shardul Bankar, Kuniyuki Iwashima,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shardul Bankar <shardul.b@mpiricsoftware.com>
[ Upstream commit 5fd0783b99d4af98f65cd58b56ec203d1d426104 ]
A connected UDP socket that connects again to a different peer is not
re-filed in the 4-tuple hash table:
sk binds to 127.0.0.1:21001
sk connects to 127.0.0.2:20001 // filed under hash(sk, peer1)
sk connects to 127.0.0.3:20002 // still filed under hash(sk, peer1)
packet from 127.0.0.3:20002 // hash(sk, peer2) misses, so the
// lookup falls back to scoring the
// hash2 chain for this address
// and port
udp_lib_hash4() returns early when the socket is already hashed, assuming
->rehash() relocates it. ->rehash() runs from __ip{4,6}_datagram_connect()
only while the receive address is unset, which a second connect never is:
the first connect assigns it, whether the socket was bound to a specific
address or to the wildcard. commit 644f9108f3a5 ("udp: Make rehash4
independent in udp_lib_rehash()") added that early return and named
connect(AF_UNSPEC) as the way around it. That workaround does not help a
socket with both SOCK_BINDADDR_LOCK and SOCK_BINDPORT_LOCK set, because
__udp_disconnect() skips ->rehash() for the first and ->unhash() for the
second.
Delivery is correct either way.
Relocate the socket when the hash it is filed under differs from the one
requested, which is what commit 78c91ae2c6de ("ipv4/udp: Add 4-tuple hash
for connected socket") did before the early return became unconditional. It
is done here under hslot->lock, which that version did not take, to match
udp_lib_rehash() and udp_lib_unhash(). hslot2 is unchanged, so hash4_cnt
needs no adjustment, as in udp_lib_rehash(). A first connect is unaffected,
and IPv6 shares the code.
With 500 sockets on the port, a re-connected socket measured 522,553 pps
without this change and 2,055,078 with it. The UDP side was noted as
remaining work in [1].
Link: https://lore.kernel.org/netdev/apnHqmYZQ4yzOP4N@v4bel/ [1]
Fixes: 644f9108f3a5 ("udp: Make rehash4 independent in udp_lib_rehash()")
Assisted-by: LLM
Signed-off-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260917-udp_hash4_fix_v1-v1-1-718891af0d7a@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/udp.c | 19 ++++++++++++++-----
1 file changed, 14 insertions(+), 5 deletions(-)
diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index 45e96b7219896..aa095ab833ecd 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -616,14 +616,23 @@ void udp_lib_hash4(struct sock *sk, u16 hash)
struct net *net = sock_net(sk);
struct udp_table *udptable;
- /* Connected udp socket can re-connect to another remote address, which
- * will be handled by rehash. Thus no need to redo hash4 here.
+ udptable = net->ipv4.udp_table;
+ hslot = udp_hashslot(udptable, net, udp_sk(sk)->udp_port_hash);
+
+ /* A connected socket can re-connect to another address. rehash()
+ * relocates it, but only runs when the local address changes, so a
+ * socket bound to a specific address would stay filed under the
+ * previous peer's hash. Move it here.
*/
- if (udp_hashed4(sk))
+ if (udp_hashed4(sk)) {
+ if (udp_sk(sk)->udp_lrpa_hash != hash) {
+ spin_lock_bh(&hslot->lock);
+ udp_rehash4(udptable, sk, hash);
+ spin_unlock_bh(&hslot->lock);
+ }
return;
+ }
- udptable = net->ipv4.udp_table;
- hslot = udp_hashslot(udptable, net, udp_sk(sk)->udp_port_hash);
hslot2 = udp_hashslot2(udptable, udp_sk(sk)->udp_portaddr_hash);
hslot4 = udp_hashslot4(udptable, hash);
udp_sk(sk)->udp_lrpa_hash = hash;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 138/457] udp: remove a disconnected socket from the 4-tuple hash table
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 137/457] udp: relocate a connected socket in the 4-tuple hash table on re-connect Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 139/457] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
` (329 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shardul Bankar, Kuniyuki Iwashima,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shardul Bankar <shardul.b@mpiricsoftware.com>
[ Upstream commit 9e95b1a94c9c49b4ba722251bbca2759b9c51737 ]
A UDP socket bound to a specific address and port keeps its entry in the
4-tuple hash table after it is disconnected:
sk binds to 127.0.0.1:21001
sk connects to 127.0.0.2:20001 // filed in the 4-tuple table
sk disconnects, connect(AF_UNSPEC) // still filed, peer now 0.0.0.0:0
__udp_disconnect() takes a socket out of that table only as a side effect
of ->rehash() or ->unhash(), and it skips ->rehash() when
SOCK_BINDADDR_LOCK is set and ->unhash() when SOCK_BINDPORT_LOCK is set.
commit 6996a2d2d0a6 ("udp: Unhash auto-bound connected sk from 4-tuple hash
table when disconnected.") fixed the same end state for a wildcard-bound
socket, by a path this one does not take.
The entry is counted whether or not anything hits it. hash4_cnt on the
hash2 slot stays raised for as long as the socket lives, so udp_has_hash4()
keeps sending every packet for that address and port through the 4-tuple
lookup first.
On IPv6 it can also be hit. __udp_disconnect() does not clear sk_v6_daddr,
so udp_v6_rehash() files the entry under the peer the socket was connected
to with a zero dport, and inet6_match() compares that same
field: a datagram from the former peer with a zero source port matches,
and source port zero is accepted on receive. On IPv4 the peer is cleared,
so a match would need a zero source address as well, which the routing
layer rejects as martian. The stale sk_v6_daddr is a separate defect, not
addressed here; removing the entry closes this path either way.
The entry can also be relocated. __udp_disconnect() clears sk_bound_dev_if,
so a subsequent SO_BINDTODEVICE calls ->rehash(), and because the receive
address is still specific udp_lib_rehash() moves the entry instead of
removing it, into the bucket that (rcv_saddr, num, 0, 0) hashes to -- a
pure function of the address and port, so every socket reaching this state
on one address and port collects in one bucket. The bucket cannot be chosen
from outside, as udp_ehashfn() is seeded with a per-boot secret. This last
one became reachable only with commit 644f9108f3a5 ("udp: Make rehash4
independent in udp_lib_rehash()"), which moved the hash4 handling out of a
branch a disconnected socket does not take; the stale entry itself dates
from the commit in Fixes.
Take the socket out of the table before __udp_disconnect() runs, while it
still matches how it was filed. This also reaches the wildcard case ahead
of udp_lib_rehash()'s udp_unhash4() branch, leaving that branch unreachable
from udp_disconnect(); removing it belongs in net-next. udp_disconnect()
and udp_abort() are the only UDP entries into __udp_disconnect(), which is
shared with raw, ping and l2tp sockets that are not struct udp_sock:
ping_prot.obj_size is sizeof(struct inet_sock), so udp_hashed4() on one
would read past the allocation.
Fixes: 78c91ae2c6de ("ipv4/udp: Add 4-tuple hash for connected socket")
Assisted-by: LLM
Signed-off-by: Shardul Bankar <shardul.b@mpiricsoftware.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260917-udp_hash4_fix_v1-v1-2-718891af0d7a@mpiricsoftware.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/udp.c | 23 +++++++++++++++++++++++
1 file changed, 23 insertions(+)
diff --git a/net/ipv4/udp.c b/net/ipv4/udp.c
index aa095ab833ecd..59afce196079a 100644
--- a/net/ipv4/udp.c
+++ b/net/ipv4/udp.c
@@ -2193,9 +2193,31 @@ int __udp_disconnect(struct sock *sk, int flags)
}
EXPORT_SYMBOL(__udp_disconnect);
+/* __udp_disconnect() takes a socket out of the 4-tuple hash table only via
+ * ->rehash() or ->unhash(), and neither runs for a socket bound to a
+ * specific address and port. Remove it here, before its peer is cleared.
+ */
+static void udp_unhash4_on_disconnect(struct sock *sk)
+{
+ struct net *net = sock_net(sk);
+ struct udp_table *udptable;
+ struct udp_hslot *hslot;
+
+ if (!udp_hashed4(sk))
+ return;
+
+ udptable = net->ipv4.udp_table;
+ hslot = udp_hashslot(udptable, net, udp_sk(sk)->udp_port_hash);
+
+ spin_lock_bh(&hslot->lock);
+ udp_unhash4(udptable, sk);
+ spin_unlock_bh(&hslot->lock);
+}
+
int udp_disconnect(struct sock *sk, int flags)
{
lock_sock(sk);
+ udp_unhash4_on_disconnect(sk);
__udp_disconnect(sk, flags);
release_sock(sk);
return 0;
@@ -3107,6 +3129,7 @@ int udp_abort(struct sock *sk, int err)
sk->sk_err = err;
sk_error_report(sk);
+ udp_unhash4_on_disconnect(sk);
__udp_disconnect(sk, 0);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 139/457] tg3: clean up PHYLIB resources on probe failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 138/457] udp: remove a disconnected socket from the 4-tuple hash table Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 140/457] drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable Greg Kroah-Hartman
` (328 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Paolo Abeni,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit a92e1a412c53dc0d9ad639e7abf8b3fc70a5b6ad ]
tg3_get_invariants() can register an MDIO bus and connect a PHY for
USE_PHYLIB devices. If tg3_init_one() later fails, its common error path
releases the mappings and netdev without undoing those PHYLIB resources.
Disconnect the PHY and unregister the MDIO bus before the remaining
teardown. Guard PHY cleanup with USE_PHYLIB to match tg3_phy_init(), and
call tg3_mdio_fini() unconditionally to match tg3_mdio_init(). The existing
IS_CONNECTED and MDIOBUS_INITED flags make both helpers safe when
initialization only completed partially.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 158d7abdae85 ("tg3: Add mdio bus registration")
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260917183336.36239-1-mhun512@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/tg3.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/tg3.c b/drivers/net/ethernet/broadcom/tg3.c
index 73a4b569b03e3..caa7a6caa6e2f 100644
--- a/drivers/net/ethernet/broadcom/tg3.c
+++ b/drivers/net/ethernet/broadcom/tg3.c
@@ -18047,6 +18047,10 @@ static int tg3_init_one(struct pci_dev *pdev,
return 0;
err_out_apeunmap:
+ if (tg3_flag(tp, USE_PHYLIB))
+ tg3_phy_fini(tp);
+ tg3_mdio_fini(tp);
+
if (tp->aperegs) {
iounmap(tp->aperegs);
tp->aperegs = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 140/457] drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 139/457] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 141/457] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
` (327 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nemesa Garg, Jouni Högander,
Suraj Kandpal, Jani Nikula, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nemesa Garg <nemesa.garg@intel.com>
[ Upstream commit 2777ec9852277a06ae68fee0c4f1a32783e4a999 ]
Selective fetch is dropped while pipe CRC is active, and the planes keep
their SEL_FETCH_PLANE_CTL / SEL_FETCH_CUR_CTL enable bit set in hardware
over that. A plane disabled while selective fetch is off never gets the
bit cleared, as the disable path is guarded by enable_psr2_sel_fetch.
Once selective fetch comes back the hardware resumes fetching for a
plane that is no longer enabled and keeps its DDB range reserved.
Clear the bits as selective fetch is turned off instead. Atomic check
has both the old and the new crtc state, so record the transition there
and let the plane and cursor arm paths write the registers to 0 for that
commit.
v2: Drop the old_crtc_state->hw.active check. [Jouni]
Fixes: b1f5279b5981 ("drm/i915/psr: Move plane sel fetch configuration into plane source files")
Closes: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8739
Assisted-by: Copilot:Claude-Opus-5
Signed-off-by: Nemesa Garg <nemesa.garg@intel.com>
Reviewed-by: Jouni Högander <jouni.hogander@intel.com>
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Link: https://patch.msgid.link/20260909110332.3528029-3-nemesa.garg@intel.com
(cherry picked from commit a4c0e7f80429eda6990960971aebd4e4b9533cc6)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/i915/display/intel_cursor.c | 7 +++++--
.../gpu/drm/i915/display/intel_display_types.h | 2 ++
drivers/gpu/drm/i915/display/intel_psr.c | 15 +++++++++++++++
.../gpu/drm/i915/display/skl_universal_plane.c | 9 ++++-----
4 files changed, 26 insertions(+), 7 deletions(-)
diff --git a/drivers/gpu/drm/i915/display/intel_cursor.c b/drivers/gpu/drm/i915/display/intel_cursor.c
index 52347668f27d6..dad0e0eb0e0c0 100644
--- a/drivers/gpu/drm/i915/display/intel_cursor.c
+++ b/drivers/gpu/drm/i915/display/intel_cursor.c
@@ -536,7 +536,8 @@ static void i9xx_cursor_disable_sel_fetch_arm(struct intel_dsb *dsb,
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- if (!crtc_state->enable_psr2_sel_fetch)
+ if (!crtc_state->enable_psr2_sel_fetch &&
+ !crtc_state->clear_psr2_sel_fetch)
return;
intel_de_write_dsb(display, dsb, SEL_FETCH_CUR_CTL(pipe), 0);
@@ -569,8 +570,10 @@ static void i9xx_cursor_update_sel_fetch_arm(struct intel_dsb *dsb,
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- if (!crtc_state->enable_psr2_sel_fetch)
+ if (!crtc_state->enable_psr2_sel_fetch) {
+ i9xx_cursor_disable_sel_fetch_arm(dsb, plane, crtc_state);
return;
+ }
if (drm_rect_height(&plane_state->psr2_sel_fetch_area) > 0) {
if (crtc_state->enable_psr2_su_region_et) {
diff --git a/drivers/gpu/drm/i915/display/intel_display_types.h b/drivers/gpu/drm/i915/display/intel_display_types.h
index 96422641ae441..18e6b01efd380 100644
--- a/drivers/gpu/drm/i915/display/intel_display_types.h
+++ b/drivers/gpu/drm/i915/display/intel_display_types.h
@@ -1177,6 +1177,8 @@ struct intel_crtc_state {
bool has_sel_update;
bool enable_psr2_sel_fetch;
bool enable_psr2_su_region_et;
+ /* Drop the stale selective fetch enable bits as selective fetch is turned off */
+ bool clear_psr2_sel_fetch;
bool req_psr2_sdp_prior_scanline;
bool has_panel_replay;
bool link_off_after_as_sdp_when_pr_active;
diff --git a/drivers/gpu/drm/i915/display/intel_psr.c b/drivers/gpu/drm/i915/display/intel_psr.c
index beaa1d62613db..87128104476a3 100644
--- a/drivers/gpu/drm/i915/display/intel_psr.c
+++ b/drivers/gpu/drm/i915/display/intel_psr.c
@@ -2933,6 +2933,8 @@ int intel_psr2_sel_fetch_update(struct intel_atomic_state *state,
struct intel_crtc *crtc)
{
struct intel_display *display = to_intel_display(state);
+ const struct intel_crtc_state *old_crtc_state =
+ intel_atomic_get_old_crtc_state(state, crtc);
struct intel_crtc_state *crtc_state = intel_atomic_get_new_crtc_state(state, crtc);
struct intel_plane_state *new_plane_state, *old_plane_state;
struct intel_plane *plane;
@@ -2945,6 +2947,19 @@ int intel_psr2_sel_fetch_update(struct intel_atomic_state *state,
bool full_update = false, su_area_changed;
int i, ret;
+ /*
+ * Selective fetch is not always usable, for instance it is dropped
+ * while pipe CRC is active. The planes keep their selective fetch
+ * enable bit set in hardware over that, and a plane disabled while
+ * selective fetch is off never gets the bit cleared. Once selective
+ * fetch comes back the hardware would resume fetching for a plane that
+ * is no longer enabled and keep its DDB range reserved, so have the
+ * plane update drop the bit for every plane of the pipe as selective
+ * fetch is turned off.
+ */
+ crtc_state->clear_psr2_sel_fetch = old_crtc_state->enable_psr2_sel_fetch &&
+ !crtc_state->enable_psr2_sel_fetch;
+
if (!crtc_state->enable_psr2_sel_fetch)
return 0;
diff --git a/drivers/gpu/drm/i915/display/skl_universal_plane.c b/drivers/gpu/drm/i915/display/skl_universal_plane.c
index 164b7d61c9a31..3dad2da4c3aaf 100644
--- a/drivers/gpu/drm/i915/display/skl_universal_plane.c
+++ b/drivers/gpu/drm/i915/display/skl_universal_plane.c
@@ -885,7 +885,8 @@ static void icl_plane_disable_sel_fetch_arm(struct intel_dsb *dsb,
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- if (!crtc_state->enable_psr2_sel_fetch)
+ if (!crtc_state->enable_psr2_sel_fetch &&
+ !crtc_state->clear_psr2_sel_fetch)
return;
intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id), 0);
@@ -1634,10 +1635,8 @@ static void icl_plane_update_sel_fetch_arm(struct intel_dsb *dsb,
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- if (!crtc_state->enable_psr2_sel_fetch)
- return;
-
- if (drm_rect_height(&plane_state->psr2_sel_fetch_area) > 0)
+ if (crtc_state->enable_psr2_sel_fetch &&
+ drm_rect_height(&plane_state->psr2_sel_fetch_area) > 0)
intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id),
SEL_FETCH_PLANE_CTL_ENABLE);
else
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 141/457] s390/debug: Do not register views for failed static debug areas
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 140/457] drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 142/457] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
` (326 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikhail Zaslonko, Heiko Carstens,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikhail Zaslonko <zaslonko@linux.ibm.com>
[ Upstream commit 28e29992b034acffc9342df216c06097825ce610 ]
__REGISTER_STATIC_DEBUG_INFO() calls debug_register_view()
unconditionally, even when debug_register_static() has failed. In that
case _debug_register() was never reached and id->debugfs_root_entry is
still NULL, so debugfs_create_file() places the view file in the debugfs
root directory. For sclp_err this leaves a /sys/kernel/debug/hex_ascii
file with nothing to indicate which debug log it belongs to.
debug_register_static() is not exported and the macro is its only
caller, so let it return an error code and skip the view registration
when it fails. No debugfs files are created for such an area then.
Reproduce by booting with s390dbf=sclp_err::100000000. The sclp_err
registration fails, no s390dbf/sclp_err/ directory is created, and a
hex_ascii file appears in the debugfs root instead.
Fixes: d72541f94512 ("s390/debug: add early tracing support")
Signed-off-by: Mikhail Zaslonko <zaslonko@linux.ibm.com>
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/include/asm/debug.h | 8 ++++++--
arch/s390/kernel/debug.c | 12 +++++++++---
2 files changed, 15 insertions(+), 5 deletions(-)
diff --git a/arch/s390/include/asm/debug.h b/arch/s390/include/asm/debug.h
index 39d484c597748..ad438d6352c8e 100644
--- a/arch/s390/include/asm/debug.h
+++ b/arch/s390/include/asm/debug.h
@@ -460,7 +460,11 @@ static int VNAME(var, active_entries)[EARLY_AREAS] __initdata
#define __REGISTER_STATIC_DEBUG_INFO(var, name, pages, areas, view) \
static int __init VNAME(var, reg)(void) \
{ \
- debug_register_static(&var, (pages), (areas)); \
+ int rc; \
+ \
+ rc = debug_register_static(&var, (pages), (areas)); \
+ if (rc) \
+ return rc; \
debug_register_view(&var, (view)); \
return 0; \
} \
@@ -493,7 +497,7 @@ static debug_info_t __refdata var = \
static debug_info_t __used __section(".s390dbf_info") *VNAME(var, info) = &var; \
__REGISTER_STATIC_DEBUG_INFO(var, name, pages, nr_areas, view)
-void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas);
+int debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas);
#endif /* MODULE */
diff --git a/arch/s390/kernel/debug.c b/arch/s390/kernel/debug.c
index e06abf1dbc218..d193c6fd1ecc7 100644
--- a/arch/s390/kernel/debug.c
+++ b/arch/s390/kernel/debug.c
@@ -948,8 +948,12 @@ EXPORT_SYMBOL(debug_register);
*
* Note: This function is called automatically via an initcall generated by
* DEFINE_STATIC_DEBUG_INFO.
+ *
+ * Return:
+ * - 0 on success
+ * - negative error code on failure
*/
-void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
+int debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
{
unsigned long flags;
debug_info_t *copy;
@@ -957,7 +961,7 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
if (!initialized) {
pr_err("Tried to register debug feature %s too early\n",
id->name);
- return;
+ return -EINVAL;
}
debug_get_param(id->name, &id->level, &pages_per_area);
@@ -973,7 +977,7 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
id->active_entries = NULL;
raw_spin_unlock_irqrestore(&id->lock, flags);
- return;
+ return -ENOMEM;
}
/* Replace static trace area with dynamic copy. */
@@ -991,6 +995,8 @@ void debug_register_static(debug_info_t *id, int pages_per_area, int nr_areas)
mutex_lock(&debug_mutex);
_debug_register(id);
mutex_unlock(&debug_mutex);
+
+ return 0;
}
/* Remove debugfs entries. */
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 142/457] s390/debug: Fix NULL pointer dereference in debug_info_copy()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 141/457] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 143/457] net: spacemit: clear TX descriptor on fragment mapping failure Greg Kroah-Hartman
` (325 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikhail Zaslonko,
Peter Oberparleiter, Heiko Carstens, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikhail Zaslonko <zaslonko@linux.ibm.com>
[ Upstream commit 012bfcd5a51082d5a65f096dfb9ca652b5267965 ]
When debug_register_static() fails, it clears areas, active_pages and
active_entries but leaves the area bounds unchanged. Copying such an
area, either by opening its view file or via debug_dump(), makes
debug_info_copy() dereference the NULL pointers.
Skip the copy loop when the source has no areas.
Closes: https://lore.kernel.org/r/20260903132123.12F271F00A3F@smtp.kernel.org
Fixes: d72541f94512 ("s390/debug: add early tracing support")
Signed-off-by: Mikhail Zaslonko <zaslonko@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kernel/debug.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kernel/debug.c b/arch/s390/kernel/debug.c
index d193c6fd1ecc7..71c966f4c5d03 100644
--- a/arch/s390/kernel/debug.c
+++ b/arch/s390/kernel/debug.c
@@ -432,7 +432,8 @@ static debug_info_t *debug_info_copy(debug_info_t *in, int mode)
debug_info_free(rc);
} while (1);
- if (mode == NO_AREAS)
+ /* debug_register_static() failure leaves areas NULL, bounds intact */
+ if (mode == NO_AREAS || !in->areas)
goto out;
for (i = 0; i < in->nr_areas; i++) {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 143/457] net: spacemit: clear TX descriptor on fragment mapping failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 142/457] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 144/457] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
` (324 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, Vivian Wang,
Troy Mitchell, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
[ Upstream commit 2d14720beb58870b15a52b236c3ab0be0e06e915 ]
emac_tx_mem_map() writes TX_DESC_0_OWN into the ring descriptor for
every slot beyond old_head as soon as that slot's memset()'d local
copy is committed with "*tx_desc_addr = tx_desc", i.e. before the
buffers for that slot have necessarily all been mapped successfully.
If emac_tx_map_frag() then fails on a later fragment, the err_free_skb
path calls emac_free_tx_buf() to unmap and drop the skb, but leaves
the already-written descriptor memory untouched, and tx_ring->head is
never advanced past old_head (the "tx_ring->head = head" store is
skipped by the goto).
So a slot between old_head and the rolled-back head can be left with
TX_DESC_0_OWN set and buffer_addr_{1,2} pointing at DMA mappings that
emac_free_tx_buf() just tore down, while software considers that slot
free again. The next successful emac_tx_mem_map() call only rebuilds
old_head itself; if the DMA engine auto-advances into the following
descriptor once it finishes old_head's packet, it will fetch that
stale, already-unmapped address.
emac_tx_clean_desc() already treats emac_free_tx_buf() and clearing
the descriptor as a pair when reclaiming completed descriptors; do
the same in the mapping failure path.
Fixes: bfec6d7f2001 ("net: spacemit: Add K1 Ethernet MAC")
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Reviewed-by: Vivian Wang <wangruikang@iscas.ac.cn>
Reviewed-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Link: https://patch.msgid.link/20260919191937.271202-1-meatuni001@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/spacemit/k1_emac.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/spacemit/k1_emac.c b/drivers/net/ethernet/spacemit/k1_emac.c
index f7f16397a2c2a..d641ac26a1e86 100644
--- a/drivers/net/ethernet/spacemit/k1_emac.c
+++ b/drivers/net/ethernet/spacemit/k1_emac.c
@@ -803,6 +803,9 @@ static void emac_tx_mem_map(struct emac_priv *priv, struct sk_buff *skb)
while (i != head) {
emac_free_tx_buf(priv, i);
+ tx_desc_addr = &((struct emac_desc *)tx_ring->desc_addr)[i];
+ memset(tx_desc_addr, 0, sizeof(*tx_desc_addr));
+
if (++i == tx_ring->total_cnt)
i = 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 144/457] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 143/457] net: spacemit: clear TX descriptor on fragment mapping failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 145/457] genetlink: report the real command id for dump-only ops in policy dumps Greg Kroah-Hartman
` (323 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, bui duc phuc, Simon Horman,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: bui duc phuc <phucduc.bui@gmail.com>
[ Upstream commit ac4334522e4ba4a3b6710dd5d4cc98092824b8ca ]
pm_runtime_get_sync() leaves the runtime PM usage counter incremented even
when it fails, but the error path in netcp_probe() does not call
pm_runtime_put_noidle() to balance it, leaking a reference each time
resume fails.
Use pm_runtime_resume_and_get() instead, which automatically drops the
usage counter on failure, fixing the leak.
Fixes: 84640e27f230 ("net: netcp: Add Keystone NetCP core ethernet driver")
Signed-off-by: bui duc phuc <phucduc.bui@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260918042804.13101-1-phucduc.bui@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ti/netcp_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/netcp_core.c b/drivers/net/ethernet/ti/netcp_core.c
index eb8fc2ed05f45..4f9e20468bbbf 100644
--- a/drivers/net/ethernet/ti/netcp_core.c
+++ b/drivers/net/ethernet/ti/netcp_core.c
@@ -2225,7 +2225,7 @@ static int netcp_probe(struct platform_device *pdev)
return -ENOMEM;
pm_runtime_enable(&pdev->dev);
- ret = pm_runtime_get_sync(&pdev->dev);
+ ret = pm_runtime_resume_and_get(&pdev->dev);
if (ret < 0) {
dev_err(dev, "Failed to enable NETCP power-domain\n");
pm_runtime_disable(&pdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 145/457] genetlink: report the real command id for dump-only ops in policy dumps
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 144/457] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 146/457] net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure Greg Kroah-Hartman
` (322 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Paolo Abeni,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 261e8a37ecbaf462cdf9c336d2b2f5056088401a ]
The op-to-policy map a CTRL_CMD_GETPOLICY dump returns is the only way
for userspace to find out which policy index belongs to which command.
ctrl_dumppolicy_put_op() tags the nest with doit->cmd, but an op which
only has a dumpit has no doit and every path which fills the split ops
in zeroes it out, so those entries all claim to be command 0. nlctrl's
own CTRL_CMD_GETPOLICY and NETDEV_CMD_QSTATS_GET are both in that group:
[{'family-id': 16, 'op-policy': {'do': 0, 'dump': 0, 'op-id': 3}},
{'family-id': 16, 'op-policy': {'dump': 1, 'op-id': 0}},
ctrl_fill_info() gets this right - it uses the iterator's cmd for
CTRL_ATTR_OP_ID - so the two introspection interfaces of the same family
contradict each other today.
Pass the command in rather than reconstructing it from
doit->cmd | dumpit->cmd inside the helper, both callers already have it.
Fixes: 26588edbef60 ("genetlink: support split policies in ctrl_dumppolicy_put_op()")
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Link: https://patch.msgid.link/20260918222949.4190284-1-kuba@kernel.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netlink/genetlink.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/net/netlink/genetlink.c b/net/netlink/genetlink.c
index 41d37442f1868..5cc1037d4917e 100644
--- a/net/netlink/genetlink.c
+++ b/net/netlink/genetlink.c
@@ -1656,7 +1656,7 @@ static void *ctrl_dumppolicy_prep(struct sk_buff *skb,
}
static int ctrl_dumppolicy_put_op(struct sk_buff *skb,
- struct netlink_callback *cb,
+ struct netlink_callback *cb, u32 cmd,
struct genl_split_ops *doit,
struct genl_split_ops *dumpit)
{
@@ -1677,7 +1677,7 @@ static int ctrl_dumppolicy_put_op(struct sk_buff *skb,
if (!nest_pol)
goto err;
- nest_op = nla_nest_start(skb, doit->cmd);
+ nest_op = nla_nest_start(skb, cmd);
if (!nest_op)
goto err;
@@ -1721,7 +1721,8 @@ static int ctrl_dumppolicy(struct sk_buff *skb, struct netlink_callback *cb)
&doit, &dumpit)))
return -ENOENT;
- if (ctrl_dumppolicy_put_op(skb, cb, &doit, &dumpit))
+ if (ctrl_dumppolicy_put_op(skb, cb, ctx->op,
+ &doit, &dumpit))
return skb->len;
/* done with the per-op policy index list */
@@ -1730,6 +1731,7 @@ static int ctrl_dumppolicy(struct sk_buff *skb, struct netlink_callback *cb)
while (ctx->dump_map) {
if (ctrl_dumppolicy_put_op(skb, cb,
+ ctx->op_iter->cmd,
&ctx->op_iter->doit,
&ctx->op_iter->dumpit))
return skb->len;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 146/457] net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 145/457] genetlink: report the real command id for dump-only ops in policy dumps Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 147/457] PM: hibernate: Freeze kernel threads after image preallocation Greg Kroah-Hartman
` (321 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Coia Prant, Simon Horman,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Coia Prant <coiaprant@gmail.com>
[ Upstream commit 9892d71cf0ce3ff3d4fed2d9a3968fd4feb1c918 ]
xpcs_init_clks() takes references with clk_bulk_get_optional() and then
enables them with clk_bulk_prepare_enable(). If the enable step fails,
the function returns without dropping the references.
xpcs_create() handles the failure through out_free_data, which calls
xpcs_free_data() but never xpcs_clear_clks(), so the clk references are
leaked.
Add the missing clk_bulk_put() on the enable failure path. The
prepare/enable side is already rolled back by
clk_bulk_prepare_enable() itself.
Fixes: f6bb3e9d98c2 ("net: pcs: xpcs: Add Synopsys DW xPCS platform device driver")
Signed-off-by: Coia Prant <coiaprant@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260919172021.2336748-1-coiaprant@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/pcs/pcs-xpcs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/pcs/pcs-xpcs.c b/drivers/net/pcs/pcs-xpcs.c
index 0337e2bcc0125..b415b93d77c15 100644
--- a/drivers/net/pcs/pcs-xpcs.c
+++ b/drivers/net/pcs/pcs-xpcs.c
@@ -1545,8 +1545,10 @@ static int xpcs_init_clks(struct dw_xpcs *xpcs)
return dev_err_probe(dev, ret, "Failed to get clocks\n");
ret = clk_bulk_prepare_enable(DW_XPCS_NUM_CLKS, xpcs->clks);
- if (ret)
+ if (ret) {
+ clk_bulk_put(DW_XPCS_NUM_CLKS, xpcs->clks);
return dev_err_probe(dev, ret, "Failed to enable clocks\n");
+ }
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 147/457] PM: hibernate: Freeze kernel threads after image preallocation
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 146/457] net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 148/457] thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds Greg Kroah-Hartman
` (320 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Schmaus,
Mario Limonciello (AMD), Matthew Leach, Rafael J. Wysocki,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Schmaus <flo@geekplace.eu>
[ Upstream commit 41112a787f9182c7f2d27122817861e3f22ef928 ]
Commit 783c81098445 ("PM: hibernate: call preallocate_image() after freeze
prepare") moved hibernate_preallocate_memory() after dpm_prepare() so
that device drivers have the opportunity to release pinned/unswappable
memory during their ->prepare() callback before memory is preallocated
for the snapshot image.
However, that commit also placed hibernate_preallocate_memory() after
freeze_kernel_threads(). While it was assumed during review that swap
I/O submitted via submit_bio() is synchronous and would not depend on
frozen kernel threads, this does not hold in practice. Calling
hibernate_preallocate_memory() with kernel threads frozen leads to
intermittent deadlocks during hibernation.
Inside hibernate_preallocate_memory(), shrink_all_memory() is invoked with
.may_writepage = 1 and .may_swap = 1 to aggressively reclaim and swap out
pages. Any writeback or swap I/O that relies on freezable kernel threads,
block device helpers, or WQ_FREEZABLE workqueues (such as those in storage
drivers, device mapper, or filesystems) deadlocks waiting on tasks that
are stuck in the refrigerator.
Fix this by reordering hibernation_snapshot():
1. Call dpm_prepare(PMSG_FREEZE) first, allowing device drivers to
release pinned resources while kernel threads are still active.
2. Call hibernate_preallocate_memory() second, performing page
reclaim and swapout while storage layers, workqueues, and kernel
threads are alive.
3. Call freeze_kernel_threads() third, only after all memory
preallocation and swap I/O have completed.
Additionally, restore the call to swsusp_free() in the cleanup path so
that preallocated image memory is properly freed if freeze_kernel_threads()
fails or if TEST_FREEZER is enabled.
Fixes: 783c81098445 ("PM: hibernate: call preallocate_image() after freeze prepare")
Signed-off-by: Florian Schmaus <flo@geekplace.eu>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Tested-by: Matthew Leach <matthew.leach@collabora.com>
Reviewed-by: Matthew Leach <matthew.leach@collabora.com>
Link: https://patch.msgid.link/20260920-fix-hibernation-v1-1-f9940c2d7d7f@geekplace.eu
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/power/hibernate.c | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c
index d2479c69d71a4..c13f68ab7f6e0 100644
--- a/kernel/power/hibernate.c
+++ b/kernel/power/hibernate.c
@@ -408,9 +408,18 @@ int hibernation_snapshot(int platform_mode)
if (error)
goto Close;
+ error = dpm_prepare(PMSG_FREEZE);
+ if (error)
+ goto Complete;
+
+ /* Preallocate image memory before freezing kernel threads and shutting down devices. */
+ error = hibernate_preallocate_memory();
+ if (error)
+ goto Complete;
+
error = freeze_kernel_threads();
if (error)
- goto Close;
+ goto Cleanup;
if (hibernation_test(TEST_FREEZER)) {
@@ -422,15 +431,6 @@ int hibernation_snapshot(int platform_mode)
goto Thaw;
}
- error = dpm_prepare(PMSG_FREEZE);
- if (error)
- goto Complete;
-
- /* Preallocate image memory before shutting down devices. */
- error = hibernate_preallocate_memory();
- if (error)
- goto Complete;
-
console_suspend_all();
pm_restrict_gfp_mask();
@@ -464,10 +464,12 @@ int hibernation_snapshot(int platform_mode)
platform_end(platform_mode);
return error;
- Complete:
- dpm_complete(PMSG_RECOVER);
Thaw:
thaw_kernel_threads();
+ Cleanup:
+ swsusp_free();
+ Complete:
+ dpm_complete(PMSG_RECOVER);
goto Close;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 148/457] thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 147/457] PM: hibernate: Freeze kernel threads after image preallocation Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 149/457] bpf: Fix bounds check for skb-backed dynptrs Greg Kroah-Hartman
` (319 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manaf Meethalavalappu Pallikunhi,
Rafael J. Wysocki, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>
[ Upstream commit ec0d89150a9381d591344a9f6f5428655c227a7f ]
When two or more thermal zones bind to a common cooling device and one zone
uses a non-zero instance->lower value, there is a bug where the instance
holds a stale mitigation vote even after its trip is cleared.
Problem scenario:
- thermal-zone1: Trip at 50°C, cooling-map with lower=0
- thermal-zone2: Trip at 55°C, cooling-map with lower=2
- Both zones share the same cooling device (e.g., CPU)
Issue flow:
1. Both trips trigger, zone1 requests state 5, zone2 also mitigates
2. Zone2 trip clears (temp < 53°C due to hysteresis)
3. When throttle=false and trend=THERMAL_TREND_DROPPING:
- Current code checks: if (cur_state <= instance->lower)
return THERMAL_NO_TARGET
- Since cur_state (5) > instance->lower (2),
it returns instance->lower (2)
- This is the BUG where it returns instance->lower even though
trip is cleared
4. Zone2's passive polling stops (tz->passive reaches 0) - no more updates
for zone2
5. Zone2's stale vote of 2 persists indefinitely
6. Even when zone1 wants to reduce cooling to state, the cooling device
cannot go below state 2 due to zone2's stale vote
When a trip is cleared (throttle == false), always return THERMAL_NO_TARGET
instead of instance->lower. Remove the unnecessary check comparing
cur_state with instance->lower. Since passive polling is already
deactivated when the trip is cleared, the instance should always be
deactivated regardless of its current cooling state. This ensures that
instances with non-zero lower bounds do not retain stale mitigation votes
after their trips are cleared.
Fixes: 042a3d80f118 ("thermal: core: Move passive polling management to the core")
Signed-off-by: Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260922-step_wise_multi_zone_stale_vote_fix-v1-1-789f68dab229@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/gov_step_wise.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)
diff --git a/drivers/thermal/gov_step_wise.c b/drivers/thermal/gov_step_wise.c
index ea277c466d8d2..4fa4377f0d428 100644
--- a/drivers/thermal/gov_step_wise.c
+++ b/drivers/thermal/gov_step_wise.c
@@ -65,14 +65,12 @@ static unsigned long get_target_state(struct thermal_instance *instance,
min(instance->lower + 1, instance->upper),
instance->upper);
} else if (trend == THERMAL_TREND_DROPPING) {
- if (cur_state <= instance->lower)
- return THERMAL_NO_TARGET;
-
/*
- * If 'throttle' is false, no mitigation is necessary, so
- * request the lower state for this instance.
+ * If 'throttle' is false, no mitigation is necessary and
+ * passive polling is already deactivated, so clear this
+ * instance state by returning THERMAL_NO_TARGET.
*/
- return instance->lower;
+ return THERMAL_NO_TARGET;
}
return instance->target;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 149/457] bpf: Fix bounds check for skb-backed dynptrs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 148/457] thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 150/457] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
` (318 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini, Emil Tsalapatis,
Alexei Starovoitov, Jiayuan Chen, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emil Tsalapatis <emil@etsalapatis.com>
[ Upstream commit ed6eec97b534979dcf28b40c389cee57bd6561d4 ]
The skb_pointer_if_linear() function checks whether a
memory region of length len starting at offset off into
the skb is in the linear area, and returns a pointer to
the region if so. The check currently subtracts between
skb_headlen and offset of the check, and since skb_headlen
is unsigned the subtraction can underflow. This causes the
bounds check to spuriously pass and generate an arbitrary
pointer of the form *(skb->data + off).
The only user of this helper is currently skb-backed BPF
dynptr code. Returning the wrong pointer leads to the
dynptr erroneously being backed with invalid memory.
Ensure the subtraction cannot underflow, and fail the check if
it would. Use u64 arithmetic to also prevent overflow when
calculating (skb_headlen(skb) - off) since off is unsigned.
Fixes: 6f5a630d7c57 ("bpf, net: Introduce skb_pointer_if_linear().")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-2-emil@etsalapatis.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/skbuff.h | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index f7dd3db9459c6..039f3c38743ca 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -4372,7 +4372,10 @@ skb_header_pointer_careful(const struct sk_buff *skb, int offset,
static inline void * __must_check
skb_pointer_if_linear(const struct sk_buff *skb, int offset, int len)
{
- if (likely(skb_headlen(skb) - offset >= len))
+ unsigned int uoffset = (unsigned int)offset;
+
+ if (likely(uoffset <= skb_headlen(skb) &&
+ (unsigned int)len <= skb_headlen(skb) - uoffset))
return skb->data + offset;
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 150/457] bpf: Fix bpf_sock context code generation
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 149/457] bpf: Fix bounds check for skb-backed dynptrs Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 151/457] bpf: Reject pkt arguments in mutating subprogs Greg Kroah-Hartman
` (317 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini, Emil Tsalapatis,
Alexei Starovoitov, Jiayuan Chen, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emil Tsalapatis <emil@etsalapatis.com>
[ Upstream commit 4a4852376e3a2727ea40e61143d6d7c22bb6dfad ]
Currently, the ctx access code reads the rx_queue_mapping
field with either a 4-byte or 2-byte load. The rest of the bits
in the register are marked known zero by the verifier. However,
the emitted ctx access code places in the register on certain
the special value (-1) using BPF_MOV_IMM64, which gets sign-extended
to turn on all the bits in the register. By shifting this value right,
the program ends up with a value at runtime above what the verifier
assumes is possible.
Fix this by ensuring the read value is as wide as the assumed size.
Use MOV32 instructions instead of MOV64 instructions to keep
the upper bits zero as assumed by the verifier. Also properly report
the size of the destination variable (the bpf_sock field, 4 bytes) instead
of the source (the socket field, 2 bytes).
Fixes: c3c16f2ea6d2 ("bpf: Add rx_queue_mapping to bpf_sock")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Link: https://patch.msgid.link/20260922172028.6269-4-emil@etsalapatis.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/filter.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 70f19ef093ee1..1acc53dd04efc 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -10403,11 +10403,12 @@ u32 bpf_sock_convert_ctx_access(enum bpf_access_type type,
target_size));
*insn++ = BPF_JMP_IMM(BPF_JNE, si->dst_reg, NO_QUEUE_MAPPING,
1);
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#else
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
- *target_size = 2;
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#endif
+ *target_size = sizeof_field(struct bpf_sock, rx_queue_mapping);
+
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 151/457] bpf: Reject pkt arguments in mutating subprogs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 150/457] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 152/457] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
` (316 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Carlini, Emil Tsalapatis,
Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emil Tsalapatis <emil@etsalapatis.com>
[ Upstream commit a6c1edfbe240e4377038a0e1d233ad81fde9a21b ]
The verifier tracks changes in how PTR_TO_PACKET registers'
bounds are modified across subprog boundaries. PTR_TO_PACKET
registers are actually passed as PTR_TO_MEM, which is assumed
valid for the entire call. This is not the case with packet memory,
where a pskb_* call may invalidate its memory region.
Reject BPF code that passes PTR_TO_PACKET pointers to subprogs that
may mutate a packet. We cannot pass the pointer as a true PTR_TO_PACKET
because we would also need to somehow pass the PTR_TO_PACKET_META
or PTR_TO_PACKET_END to the subprog. Since we cannot avoid representing
the pointer in the subprog as PTR_TO_MEM, only permit it if the
subprog is guaranteed not to mutate the packet.
Fixes: 80f281664f5a ("bpf: Support pointers in global func args")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260922172028.6269-6-emil@etsalapatis.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index cb523cc5465dd..ccf735d74dc82 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -9264,6 +9264,16 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
return ret;
if (check_mem_reg(env, reg, argno, arg->mem_size))
return -EINVAL;
+ /*
+ * PTR_TO_PACKET get passed as PTR_TO_MEM, preventing
+ * us from adjusting bounds tracking info.
+ */
+ if ((reg_is_pkt_pointer_any(reg) || reg_is_dynptr_slice_pkt(reg)) &&
+ sub->changes_pkt_data) {
+ bpf_log(log, "%s is a packet pointer, but func#%d may change packet data\n",
+ reg_arg_name(env, argno), subprog);
+ return -EINVAL;
+ }
if (!(arg->arg_type & PTR_MAYBE_NULL) &&
(type_may_be_null(reg->type) || bpf_register_is_null(reg))) {
bpf_log(log, "%s is expected to be non-NULL\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 152/457] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 151/457] bpf: Reject pkt arguments in mutating subprogs Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 153/457] firewire: cdev: fix back-transition for iso_resource_auto client resource Greg Kroah-Hartman
` (315 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhao Gongyi, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
[ Upstream commit 814a81c842bd88f6bd8a4ce550d560df071a5d03 ]
sock_map_alloc() only rejects max_entries == 0 and otherwise allows any
u32 value. sock_map_free() then walks the sks[] array with a signed int
iterator:
int i;
for (i = 0; i < stab->map.max_entries; i++)
struct sock **psk = &stab->sks[i];
When a SOCKMAP is created with max_entries = 0xffffffff (UINT_MAX), the
allocation of 32 GiB can succeed on large-memory hosts. During free the
counter reaches 0x80000000, wraps to INT_MIN, is sign-extended by movslq
and turned into a ~16 GiB negative offset from stab->sks, pointing far
below the allocation.
The faulting access is an xchg() write in sock_map_free(). Without
KASAN, the same out-of-bounds write can fault on an unmapped vmalloc page
or corrupt an unrelated allocation if that vmalloc address is populated.
On a KASAN kernel with CONFIG_KASAN_VMALLOC=y, the shadow check for that
address hits an unmapped shadow page and oopses first:
BUG: unable to handle page fault for address: fffff521b59c5a00
RIP: 0010:kasan_check_range+0x107/0x190
Call Trace:
sock_map_free+0x93/0x190
map_create+0x68d/0xb30
__sys_bpf+0x21e/0x2e70
Vmcore confirmed stab->map.max_entries == 0xffffffff, stab->sks ==
0xffffc911ace2d000, and the faulting address sks + (s64)INT_MIN * 8
exactly at 0xffffc90dace2d000. The same buggy path is reached on the
normal close()/bpf_map_free_deferred() path whenever such a map is
destroyed.
sock_map_alloc() used to bound its allocation size through
bpf_map_charge_init(), but the bound was dropped when rlimit-based memory
accounting was removed. Reject max_entries > INT_MAX at creation time so
the signed iterator in sock_map_free() never sees a value that would
overflow.
Triggered by syzkaller and reproduced on both a 6.6-based KASAN kernel
and the upstream v7.3-rc2 kernel.
Fixes: 0d2c4f964050 ("bpf: Eliminate rlimit-based memory accounting for sockmap and sockhash maps")
Signed-off-by: Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260917121016.48171-1-zhaogongyi@bytedance.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock_map.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/sock_map.c b/net/core/sock_map.c
index 9efbd8ca7db83..09d20318a0eae 100644
--- a/net/core/sock_map.c
+++ b/net/core/sock_map.c
@@ -41,6 +41,7 @@ static struct bpf_map *sock_map_alloc(union bpf_attr *attr)
struct bpf_stab *stab;
if (attr->max_entries == 0 ||
+ attr->max_entries > INT_MAX ||
attr->key_size != 4 ||
(attr->value_size != sizeof(u32) &&
attr->value_size != sizeof(u64)) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 153/457] firewire: cdev: fix back-transition for iso_resource_auto client resource
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 152/457] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 154/457] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
` (314 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Sakamoto, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Sakamoto <o-takashi@sakamocchi.jp>
[ Upstream commit c6b51091cafff9ce6c03c1416aa13864d17ab97c ]
The todo member of iso_resource_auto structure represents the state of the
client resource and normally transitions in the following order:
ISO_RES_AUTO_ALLOC -> ISO_RES_AUTO_REALLOC -> ISO_RES_AUTO_DEALLOC
However, concurrent access from the work item and the file descriptor
release function can cause the state to transition backwards from
ISO_RES_AUTO_DEALLOC to ISO_RES_AUTO_REALLOC.
Prevent the back-transition by checking the current state before
updating it in the work item.
Fixes: fcabbf40fae5 ("firewire: core: move allocation/reallocation paths into specific branch after isoc resource management in cdev")
Link: https://lore.kernel.org/r/20260922132639.191593-1-o-takashi@sakamocchi.jp
Signed-off-by: Takashi Sakamoto <o-takashi@sakamocchi.jp>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firewire/core-cdev.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/firewire/core-cdev.c b/drivers/firewire/core-cdev.c
index e49d8a58be09e..664952a67a11a 100644
--- a/drivers/firewire/core-cdev.c
+++ b/drivers/firewire/core-cdev.c
@@ -1397,8 +1397,10 @@ static void iso_resource_auto_work(struct work_struct *work)
} else {
// Transit from allocation to reallocation, except if the client requested
// deallocation in the meantime.
- scoped_guard(spinlock_irq, &client->lock)
- r->todo = ISO_RES_AUTO_REALLOC;
+ scoped_guard(spinlock_irq, &client->lock) {
+ if (r->todo == ISO_RES_AUTO_ALLOC)
+ r->todo = ISO_RES_AUTO_REALLOC;
+ }
if (channel >= 0)
r->params.channels_mask = BIT_ULL(channel);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 154/457] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 153/457] firewire: cdev: fix back-transition for iso_resource_auto client resource Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 155/457] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
` (313 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernardo Soares, Vlad Buslov,
Saeed Mahameed, Mark Bloch, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernardo Soares <bsoares.it@gmail.com>
[ Upstream commit 35e6f970f553954d92ba20afa885139a8e7dd0d7 ]
mlx5 registers the bridge offload switchdev notifiers once per eswitch
instance, but the notifier chains are global, so every instance sees
every event and must filter out the ones that aren't its own. The
existing filter, mlx5_esw_bridge_dev_same_hw(), only checks that the
event netdevice sits on the same HCA - intentional for merged eswitch,
where one bridge can span representors of several eswitches on one
HCA - but same-HCA doesn't mean the instance actually has that port:
peer ports are only created reactively from NETDEV_CHANGEUPPER, so an
instance brought up after a sibling PF's port was already enslaved has
none. The port object and attribute handlers claim the event anyway
once same-HW passes, then fail the port lookup and return -EINVAL,
which gets reported to user space even though the owning instance
already handled it (e.g. "bridge vlan add ... RTNETLINK answers:
Invalid argument"). Fix by filtering on the tracked port instead.
The same gap exists in the generic recursive lower-device walk used by
attribute changes on a bridge with more than one representor enslaved
directly: mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get() is entered
with the bridge master netdevice, falls through to its generic
netdev_for_each_lower_dev() loop, and returns as soon as the recursion
into any one lower device yields a non-NULL rep - the underlying base
case, mlx5_esw_bridge_rep_vport_num_vhca_id_get(), only checks
mlx5_esw_bridge_dev_same_hw(), not ownership by the calling instance's
br_offloads. mlx5_esw_bridge_lag_rep_get(), used for the LAG-master
case, already filters on mlx5_esw_bridge_dev_same_esw() per candidate
and so cannot select a sibling's rep; it is not the source of this bug.
On a merged-eswitch HCA with a bridge spanning representors of more
than one eswitch instance directly, the walk can return a sibling's rep
instead of continuing to the one the calling instance actually owns, so
the attribute change fails the same way as above. Fix by checking
mlx5_esw_bridge_port_exists() at the point each rep is picked, same as
the previous fix did for the notifier filter.
Fixes: c358ea1741bc ("net/mlx5: Bridge, allow merged eswitch connectivity")
Signed-off-by: Bernardo Soares <bsoares.it@gmail.com>
Cc: Vlad Buslov <vladbu@nvidia.com>
Cc: Saeed Mahameed <saeedm@nvidia.com>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Link: https://patch.msgid.link/20260918095931.29792-2-bsoares.it@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../mellanox/mlx5/core/en/rep/bridge.c | 45 +++++++++++++++----
.../ethernet/mellanox/mlx5/core/esw/bridge.c | 6 +++
.../ethernet/mellanox/mlx5/core/esw/bridge.h | 2 +
3 files changed, 44 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
index baac38bece14a..4b7b0a0fc2b2f 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/rep/bridge.c
@@ -85,9 +85,16 @@ mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(struct net_device *dev, struct m
struct net_device *lower_dev;
struct list_head *iter;
- if (netif_is_lag_master(dev) || mlx5e_eswitch_rep(dev))
- return mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, esw, vport_num,
- esw_owner_vhca_id);
+ if (netif_is_lag_master(dev) || mlx5e_eswitch_rep(dev)) {
+ struct net_device *rep;
+
+ rep = mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, esw, vport_num,
+ esw_owner_vhca_id);
+ if (rep && !mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id,
+ esw->br_offloads))
+ return NULL;
+ return rep;
+ }
netdev_for_each_lower_dev(dev, lower_dev, iter) {
struct net_device *rep;
@@ -104,6 +111,28 @@ mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(struct net_device *dev, struct m
return NULL;
}
+static bool mlx5_esw_bridge_rep_port_lookup(struct net_device *dev,
+ struct mlx5_esw_bridge_offloads *br_offloads,
+ u16 *vport_num, u16 *esw_owner_vhca_id)
+{
+ if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, vport_num,
+ esw_owner_vhca_id))
+ return false;
+
+ return mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id, br_offloads);
+}
+
+static bool mlx5_esw_bridge_lower_rep_port_lookup(struct net_device *dev,
+ struct mlx5_esw_bridge_offloads *br_offloads,
+ u16 *vport_num, u16 *esw_owner_vhca_id)
+{
+ if (!mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(dev, br_offloads->esw, vport_num,
+ esw_owner_vhca_id))
+ return false;
+
+ return mlx5_esw_bridge_port_exists(*vport_num, *esw_owner_vhca_id, br_offloads);
+}
+
static bool mlx5_esw_bridge_is_local(struct net_device *dev, struct net_device *rep,
struct mlx5_eswitch *esw)
{
@@ -218,8 +247,7 @@ mlx5_esw_bridge_port_obj_add(struct net_device *dev,
u16 vport_num, esw_owner_vhca_id;
int err;
- if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_rep_port_lookup(dev, br_offloads, &vport_num, &esw_owner_vhca_id))
return 0;
port_obj_info->handled = true;
@@ -251,8 +279,7 @@ mlx5_esw_bridge_port_obj_del(struct net_device *dev,
const struct switchdev_obj_port_mdb *mdb;
u16 vport_num, esw_owner_vhca_id;
- if (!mlx5_esw_bridge_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_rep_port_lookup(dev, br_offloads, &vport_num, &esw_owner_vhca_id))
return 0;
port_obj_info->handled = true;
@@ -283,8 +310,8 @@ mlx5_esw_bridge_port_obj_attr_set(struct net_device *dev,
u16 vport_num, esw_owner_vhca_id;
int err = 0;
- if (!mlx5_esw_bridge_lower_rep_vport_num_vhca_id_get(dev, br_offloads->esw, &vport_num,
- &esw_owner_vhca_id))
+ if (!mlx5_esw_bridge_lower_rep_port_lookup(dev, br_offloads, &vport_num,
+ &esw_owner_vhca_id))
return 0;
port_attr_info->handled = true;
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index 87b5fd3495945..ac90ccda12722 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -1686,6 +1686,12 @@ int mlx5_esw_bridge_vport_peer_unlink(struct net_device *br_netdev, u16 vport_nu
extack);
}
+bool mlx5_esw_bridge_port_exists(u16 vport_num, u16 esw_owner_vhca_id,
+ struct mlx5_esw_bridge_offloads *br_offloads)
+{
+ return mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
+}
+
int mlx5_esw_bridge_port_vlan_add(u16 vport_num, u16 esw_owner_vhca_id, u16 vid, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
index d6f5391619930..a4e59cc210894 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.h
@@ -80,6 +80,8 @@ int mlx5_esw_bridge_vlan_proto_set(u16 vport_num, u16 esw_owner_vhca_id, u16 pro
struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_mcast_set(u16 vport_num, u16 esw_owner_vhca_id, bool enable,
struct mlx5_esw_bridge_offloads *br_offloads);
+bool mlx5_esw_bridge_port_exists(u16 vport_num, u16 esw_owner_vhca_id,
+ struct mlx5_esw_bridge_offloads *br_offloads);
int mlx5_esw_bridge_port_vlan_add(u16 vport_num, u16 esw_owner_vhca_id, u16 vid, u16 flags,
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 155/457] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 154/457] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 156/457] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
` (312 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernardo Soares, Mark Bloch,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernardo Soares <bsoares.it@gmail.com>
[ Upstream commit 2e51097c982b7b22382fda3202ba29f0ea33e8c0 ]
mlx5_esw_bridge_vport_unlink() returns -EINVAL when the port isn't
tracked by this instance's br_offloads. This is reachable on a sibling
instance that registered its notifier after the port was already
enslaved: it never saw the NETDEV_CHANGEUPPER link event, so
peer_link() never created a peer port for it, but it does see the
later unlink event and fails. Return 0 instead, and give
mlx5_esw_bridge_vport_peer_unlink() the same merged_eswitch capability
guard peer_link() already has, since without it peer_link() likewise
never creates a port to unlink.
This also matters beyond the -EINVAL itself:
mlx5_esw_bridge_switchdev_port_event() runs on the per-netns
netdev_chain, and notifier_from_errno(-EINVAL) sets NOTIFY_STOP_MASK,
which call_netdevice_notifiers_info() checks to stop calling further
listeners on that chain - so the old -EINVAL silently dropped the
event for any listener registered later on the same chain, even
though none of it was visible to user space since
__netdev_upper_dev_unlink() discards the return value.
Fixes: c358ea1741bc ("net/mlx5: Bridge, allow merged eswitch connectivity")
Signed-off-by: Bernardo Soares <bsoares.it@gmail.com>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Link: https://patch.msgid.link/20260918095931.29792-3-bsoares.it@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
index ac90ccda12722..b4cf3c5ac0dde 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/esw/bridge.c
@@ -1649,10 +1649,8 @@ int mlx5_esw_bridge_vport_unlink(struct net_device *br_netdev, u16 vport_num,
int err;
port = mlx5_esw_bridge_port_lookup(vport_num, esw_owner_vhca_id, br_offloads);
- if (!port) {
- NL_SET_ERR_MSG_MOD(extack, "Port is not attached to any bridge");
- return -EINVAL;
- }
+ if (!port)
+ return 0;
if (port->bridge->ifindex != br_netdev->ifindex) {
NL_SET_ERR_MSG_MOD(extack, "Port is attached to another bridge");
return -EINVAL;
@@ -1682,6 +1680,9 @@ int mlx5_esw_bridge_vport_peer_unlink(struct net_device *br_netdev, u16 vport_nu
struct mlx5_esw_bridge_offloads *br_offloads,
struct netlink_ext_ack *extack)
{
+ if (!MLX5_CAP_ESW(br_offloads->esw->dev, merged_eswitch))
+ return 0;
+
return mlx5_esw_bridge_vport_unlink(br_netdev, vport_num, esw_owner_vhca_id, br_offloads,
extack);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 156/457] sctp: hold asoc or transport before mod_timer() in timer handlers
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 155/457] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 157/457] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
` (311 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tangxin Xie, Xin Long,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xin Long <lucien.xin@gmail.com>
[ Upstream commit cae23ae3f7887a1cf8a75da38edcebeef695040f ]
Take the association or transport reference before rearming a timer in the
timer handlers.
The existing code calls mod_timer() before taking the reference needed by
the rearmed timer without holding the sock lock. This creates a race with
timer cleanup: if the timer is deleted after mod_timer() returns but before
the reference is taken, the cleanup path can drop the timer's reference and
destroy the transport or association. The timer handler then takes a
reference on the already freed object and eventually drops it, causing a
refcount underflow.
Hold the object before mod_timer() and drop the reference if mod_timer()
reports that the timer was already pending in timer handlers. Apply the
same ordering to the proto-unreachable path, which can rearm a transport
timer outside the timer handlers without holding the sock lock.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Tangxin Xie <xietangxin@h-partners.com>
Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/c31b5e3ee2b7274e804f5eba2f21e2412e7eef7a.1790013825.git.lucien.xin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sctp/input.c | 7 ++++---
net/sctp/sm_sideeffect.c | 37 ++++++++++++++++++++++---------------
2 files changed, 26 insertions(+), 18 deletions(-)
diff --git a/net/sctp/input.c b/net/sctp/input.c
index 864741fae4187..9494cfa51106c 100644
--- a/net/sctp/input.c
+++ b/net/sctp/input.c
@@ -436,9 +436,10 @@ void sctp_icmp_proto_unreachable(struct sock *sk,
if (timer_pending(&t->proto_unreach_timer))
return;
else {
- if (!mod_timer(&t->proto_unreach_timer,
- jiffies + (HZ/20)))
- sctp_transport_hold(t);
+ sctp_transport_hold(t);
+ if (mod_timer(&t->proto_unreach_timer,
+ jiffies + (HZ / 20)))
+ sctp_transport_put(t);
}
} else {
struct net *net = sock_net(sk);
diff --git a/net/sctp/sm_sideeffect.c b/net/sctp/sm_sideeffect.c
index 0d99b7e8c082f..35f540fb15fc1 100644
--- a/net/sctp/sm_sideeffect.c
+++ b/net/sctp/sm_sideeffect.c
@@ -244,8 +244,9 @@ void sctp_generate_t3_rtx_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->T3_rtx_timer, jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->T3_rtx_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -280,8 +281,9 @@ static void sctp_generate_timeout_event(struct sctp_association *asoc,
timeout_type);
/* Try again later. */
- if (!mod_timer(&asoc->timers[timeout_type], jiffies + (HZ/20)))
- sctp_association_hold(asoc);
+ sctp_association_hold(asoc);
+ if (mod_timer(&asoc->timers[timeout_type], jiffies + (HZ / 20)))
+ sctp_association_put(asoc);
goto out_unlock;
}
@@ -378,8 +380,9 @@ void sctp_generate_heartbeat_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->hb_timer, jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->hb_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -388,8 +391,9 @@ void sctp_generate_heartbeat_event(struct timer_list *t)
timeout = sctp_transport_timeout(transport);
if (elapsed < timeout) {
elapsed = timeout - elapsed;
- if (!mod_timer(&transport->hb_timer, jiffies + elapsed))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->hb_timer, jiffies + elapsed))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -422,9 +426,10 @@ void sctp_generate_proto_unreach_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->proto_unreach_timer,
- jiffies + (HZ/20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->proto_unreach_timer,
+ jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -458,8 +463,9 @@ void sctp_generate_reconf_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->reconf_timer, jiffies + (HZ / 20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->reconf_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
@@ -495,8 +501,9 @@ void sctp_generate_probe_event(struct timer_list *t)
pr_debug("%s: sock is busy\n", __func__);
/* Try again later. */
- if (!mod_timer(&transport->probe_timer, jiffies + (HZ / 20)))
- sctp_transport_hold(transport);
+ sctp_transport_hold(transport);
+ if (mod_timer(&transport->probe_timer, jiffies + (HZ / 20)))
+ sctp_transport_put(transport);
goto out_unlock;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 157/457] net: stmmac: selftests: Support running selftests on DSA conduits
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 156/457] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 158/457] net: stmmac: selftests: Validate EEE based on the actual LPI timer value Greg Kroah-Hartman
` (310 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit d68acbf93531abdb5b02b21994cd4c15a3c95b42 ]
Most stmmac selftests rely on dev_add_pack() to add custom handlers,
that validate the packets sent to ourselves through MAC loopback.
However, when the stmmac-driven interface is a DSA CPU conduit, all
frames that are received have ETH_P_XDSA as a protocol, even though they
don't actually contain any tag as they come from the loopback and not
the switch.
This will prevent any incoming packet to match our packet handlers.
Let's register a ETH_P_ALL packet handler when we detect that we're a
DSA conduit, and use a proxy packet handler to filter the h_proto.
As this allows external frames to be received through our .func(), the
packet handler is added after the dev->addr field is populated in our
selftest attributes.
Note that we may still receive incoming packets from the switch, but
these frames shouldn't interfere with the very specific frames used for
selftests, and stmmac selftests in general aren't safe against external
traffic interferences.
This was validated on a WPQ864 devkit for IPQ8064, that has the SoC
connected to a QCA8k switch.
The ARP offload's packet handler is left alone, this feature is just not
implemented in stmmac and due for removal.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-2-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../stmicro/stmmac/stmmac_selftests.c | 89 +++++++++++++++----
1 file changed, 71 insertions(+), 18 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index f97f32369e903..a65eac55323af 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -13,6 +13,7 @@
#include <linux/ip.h>
#include <linux/phy.h>
#include <linux/udp.h>
+#include <net/dsa.h>
#include <net/pkt_cls.h>
#include <net/pkt_sched.h>
#include <net/tcp.h>
@@ -238,6 +239,9 @@ struct stmmac_test_priv {
struct stmmac_packet_attrs *packet;
struct packet_type pt;
struct completion comp;
+ __be16 packet_type;
+ int (*func)(struct sk_buff *skb, struct net_device *ndev,
+ struct packet_type *pt, struct net_device *orig_ndev);
int double_vlan;
int vlan_id;
int ok;
@@ -317,6 +321,50 @@ static int stmmac_test_loopback_validate(struct sk_buff *skb,
return 0;
}
+static int stmmac_sft_filter(struct sk_buff *skb, struct net_device *ndev,
+ struct packet_type *pt,
+ struct net_device *orig_ndev)
+{
+ struct stmmac_test_priv *tpriv = pt->af_packet_priv;
+ struct ethhdr *hdr = eth_hdr(skb);
+ int ret = 0;
+
+ if (hdr->h_proto == tpriv->packet_type) {
+ struct sk_buff *nskb = skb_clone(skb, GFP_ATOMIC);
+
+ if (nskb)
+ ret = tpriv->func(nskb, ndev, pt, orig_ndev);
+ }
+
+ kfree_skb(skb);
+ return ret;
+}
+
+static void stmmac_sft_add_pack(struct packet_type *pt)
+{
+ struct stmmac_test_priv *tpriv = pt->af_packet_priv;
+
+ if (netdev_uses_dsa(tpriv->pt.dev)) {
+ tpriv->packet_type = tpriv->pt.type;
+ tpriv->func = tpriv->pt.func;
+
+ /* DSA conduit will report ETH_P_XDSA, so our packet handler
+ * won't match. Let's register a ETH_P_ALL match and filter
+ * manually in stmmac_sft_filter.
+ */
+ tpriv->pt.type = htons(ETH_P_ALL);
+ tpriv->pt.func = stmmac_sft_filter;
+ tpriv->pt.ignore_outgoing = true;
+ }
+
+ dev_add_pack(pt);
+}
+
+static void stmmac_sft_remove_pack(struct packet_type *pt)
+{
+ dev_remove_pack(pt);
+}
+
static int __stmmac_test_loopback(struct stmmac_priv *priv,
struct stmmac_packet_attrs *attr)
{
@@ -338,7 +386,7 @@ static int __stmmac_test_loopback(struct stmmac_priv *priv,
tpriv->packet = attr;
if (!attr->dont_wait)
- dev_add_pack(&tpriv->pt);
+ stmmac_sft_add_pack(&tpriv->pt);
skb = stmmac_test_get_udp_skb(priv, attr);
if (!skb) {
@@ -361,7 +409,7 @@ static int __stmmac_test_loopback(struct stmmac_priv *priv,
cleanup:
if (!attr->dont_wait)
- dev_remove_pack(&tpriv->pt);
+ stmmac_sft_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -787,7 +835,7 @@ static int stmmac_test_flowctrl(struct stmmac_priv *priv)
tpriv->pt.func = stmmac_test_flowctrl_validate;
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
- dev_add_pack(&tpriv->pt);
+ stmmac_sft_add_pack(&tpriv->pt);
/* Compute minimum number of packets to make FIFO full */
pkt_count = rx_fifo_size;
@@ -843,7 +891,7 @@ static int stmmac_test_flowctrl(struct stmmac_priv *priv)
cleanup:
dev_mc_del(priv->dev, paddr);
dev_set_promiscuity(priv->dev, -1);
- dev_remove_pack(&tpriv->pt);
+ stmmac_sft_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -948,18 +996,20 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
* HASH values.
*/
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(ETH_P_8021Q), tpriv->vlan_id);
if (ret)
goto cleanup;
+ attr.vlan = 1;
+ attr.dst = priv->dev->dev_addr;
+ attr.sport = 9;
+ attr.dport = 9;
+
+ stmmac_sft_add_pack(&tpriv->pt);
+
for (i = 0; i < 4; i++) {
- attr.vlan = 1;
attr.vlan_id_out = tpriv->vlan_id + i;
- attr.dst = priv->dev->dev_addr;
- attr.sport = 9;
- attr.dport = 9;
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
@@ -986,9 +1036,9 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
}
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(ETH_P_8021Q), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -1042,18 +1092,20 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
* HASH values.
*/
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(ETH_P_8021AD), tpriv->vlan_id);
if (ret)
goto cleanup;
+ attr.vlan = 2;
+ attr.dst = priv->dev->dev_addr;
+ attr.sport = 9;
+ attr.dport = 9;
+
+ stmmac_sft_add_pack(&tpriv->pt);
+
for (i = 0; i < 4; i++) {
- attr.vlan = 2;
attr.vlan_id_out = tpriv->vlan_id + i;
- attr.dst = priv->dev->dev_addr;
- attr.sport = 9;
- attr.dport = 9;
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
@@ -1080,9 +1132,9 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
}
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(ETH_P_8021AD), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
@@ -1313,7 +1365,6 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
tpriv->vlan_id = 0x123;
- dev_add_pack(&tpriv->pt);
ret = vlan_vid_add(priv->dev, htons(proto), tpriv->vlan_id);
if (ret)
@@ -1321,6 +1372,8 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
attr.dst = priv->dev->dev_addr;
+ stmmac_sft_add_pack(&tpriv->pt);
+
skb = stmmac_test_get_udp_skb(priv, &attr);
if (!skb) {
ret = -ENOMEM;
@@ -1338,9 +1391,9 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
ret = tpriv->ok ? 0 : -ETIMEDOUT;
vlan_del:
+ stmmac_sft_remove_pack(&tpriv->pt);
vlan_vid_del(priv->dev, htons(proto), tpriv->vlan_id);
cleanup:
- dev_remove_pack(&tpriv->pt);
kfree(tpriv);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 158/457] net: stmmac: selftests: Validate EEE based on the actual LPI timer value
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 157/457] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 159/457] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
` (309 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit c8c1795aa8106293020a836d01e127e98f442925 ]
The EEE selftest is a 2-step test :
- It validates that we enter in LPI mode with the
irq_tx_path_in_lpi_mode_n counter
- It then validates that we exit LPI when sending a frame, with the
irq_tx_path_exit_lpi_mode_n counter.
The current state of the test lacks 2 main things :
- We don't know exactly when was the previous frame sent (it's from the
previous selftest)
- The timeout is hardcoded, while the LPI is entered after a
user-configurable delay. On top of that, the timeout loop uses a
pre-decrement iterator (--retries) that actually only iterate nine
times, so 900ms while the default LPI value is 1 second.
Let's therefore make it more deterministic :
- Send a frame at the beginning of the test
- Wait for more than the lpi timer value, we timeout after about twice
the value,
- Then send another frame, and verify that we do go out of LPI, also
with a timeout.
As LPI timer can get pretty high, bail out if LPI timer is over 5
seconds.
Note that the test's goal isn't to validate the LPI timer value itself,
only that we enter/leave LPI mode.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-3-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../stmicro/stmmac/stmmac_selftests.c | 44 ++++++++++++++++---
1 file changed, 37 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index a65eac55323af..045d644ae50b5 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -31,6 +31,7 @@ struct stmmachdr {
sizeof(struct stmmachdr))
#define STMMAC_TEST_PKT_MAGIC 0xdeadcafecafedeadULL
#define STMMAC_LB_TIMEOUT msecs_to_jiffies(200)
+#define STMMAC_SFT_MAX_LPI (5 * USEC_PER_SEC)
struct stmmac_packet_attrs {
int vlan;
@@ -482,12 +483,16 @@ static int stmmac_test_mmc(struct stmmac_priv *priv)
static int stmmac_test_eee(struct stmmac_priv *priv)
{
struct stmmac_extra_stats *initial, *final;
- int retries = 10;
+ unsigned long timeout, max_duration;
int ret;
if (!priv->dma_cap.eee || !priv->eee_active)
return -EOPNOTSUPP;
+ /* Bail out if the configured LPI timer is too long */
+ if (priv->tx_lpi_timer > STMMAC_SFT_MAX_LPI)
+ return -EOPNOTSUPP;
+
initial = kzalloc_obj(*initial);
if (!initial)
return -ENOMEM;
@@ -498,14 +503,21 @@ static int stmmac_test_eee(struct stmmac_priv *priv)
goto out_free_initial;
}
+ /* Snapshot stats, we want to count the in_lpi events. We may enter
+ * LPI just after the packet was sent.
+ */
memcpy(initial, &priv->xstats, sizeof(*initial));
+ /* Send a frame, then wait to enter LPI */
ret = stmmac_test_mac_loopback(priv);
if (ret)
goto out_free_final;
+ max_duration = usecs_to_jiffies(2 * priv->tx_lpi_timer);
+
/* We have no traffic in the line so, sooner or later it will go LPI */
- while (--retries) {
+ timeout = jiffies + max_duration;
+ while (!time_after(jiffies, timeout)) {
memcpy(final, &priv->xstats, sizeof(*final));
if (final->irq_tx_path_in_lpi_mode_n >
@@ -514,20 +526,38 @@ static int stmmac_test_eee(struct stmmac_priv *priv)
msleep(100);
}
- if (!retries) {
+ memcpy(final, &priv->xstats, sizeof(*final));
+ if (final->irq_tx_path_in_lpi_mode_n <=
+ initial->irq_tx_path_in_lpi_mode_n) {
ret = -ETIMEDOUT;
goto out_free_final;
}
- if (final->irq_tx_path_in_lpi_mode_n <=
- initial->irq_tx_path_in_lpi_mode_n) {
- ret = -EINVAL;
+ /* Re-snapshot, as we want to measure exit_lpi events. We should be
+ * in LPI right now.
+ */
+ memcpy(initial, &priv->xstats, sizeof(*initial));
+
+ /* TX something so we go out of LPI */
+ ret = stmmac_test_mac_loopback(priv);
+ if (ret)
goto out_free_final;
+
+ /* Wait for the exit LPI interrupt */
+ timeout = jiffies + max_duration;
+ while (!time_after(jiffies, timeout)) {
+ memcpy(final, &priv->xstats, sizeof(*final));
+
+ if (final->irq_tx_path_exit_lpi_mode_n >
+ initial->irq_tx_path_exit_lpi_mode_n)
+ break;
+ msleep(100);
}
+ memcpy(final, &priv->xstats, sizeof(*final));
if (final->irq_tx_path_exit_lpi_mode_n <=
initial->irq_tx_path_exit_lpi_mode_n) {
- ret = -EINVAL;
+ ret = -ETIMEDOUT;
goto out_free_final;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 159/457] net: stmmac: selftests: Check the dev->features for S-TAG offload testing
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 158/457] net: stmmac: selftests: Validate EEE based on the actual LPI timer value Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 160/457] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
` (308 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit ba804b23d76d278ee475b8427fa7c5623ce5e270 ]
The S-TAG offload insertion incorrectly checks the dvlan (double vlan)
DMA cap, which is different than S-TAG support. Use
NETIF_F_HW_VLAN_STAG_TX to check if the feature is supported instead.
Note that this flag isn't set in stmmac yet, but contrary to ARP
offload, this is a feature that has a chance to get there eventually so
let's leave the selftest here for now. It'll report -EOPNOTSUPP in the
meantime.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-4-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index 045d644ae50b5..53bb911b69ffb 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -1435,7 +1435,7 @@ static int stmmac_test_vlanoff(struct stmmac_priv *priv)
static int stmmac_test_svlanoff(struct stmmac_priv *priv)
{
- if (!priv->dma_cap.dvlan)
+ if (!(priv->dev->features & NETIF_F_HW_VLAN_STAG_TX))
return -EOPNOTSUPP;
return stmmac_test_vlanoff_common(priv, true);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 160/457] net: stmmac: selftests: Capture all packets for vlan checks
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 159/457] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 161/457] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
` (307 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit 960db6f65788c21249ea04a947d5c01e38d19294 ]
While we use vlan_vid_add to trigger the tag filtering machinery
in the driver, there's no netdev associated to the VLAN. This causes the
skb to arrive with empty skb->vlan_tci fields, as the packet is marked
OTHERHOST in __netif_receive_skb_core(), and we fail our validation.
Let's use the proxy mechanism introduced for DSA, that registers a
ETH_P_ALL packet handler that runs earlier, before the vlan netdev
lookup, then filters for the correct ethertype before passing an skb
clone to our validation function.
As we may receive external frames with the right tag from the outside,
let's move the address check in the vlan validation function earlier.
Fixes: 091810dbded9 ("net: stmmac: Introduce selftests support")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-5-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../stmicro/stmmac/stmmac_selftests.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index 53bb911b69ffb..b3b05a7753335 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -243,6 +243,7 @@ struct stmmac_test_priv {
__be16 packet_type;
int (*func)(struct sk_buff *skb, struct net_device *ndev,
struct packet_type *pt, struct net_device *orig_ndev);
+ bool capture_all;
int double_vlan;
int vlan_id;
int ok;
@@ -345,13 +346,15 @@ static void stmmac_sft_add_pack(struct packet_type *pt)
{
struct stmmac_test_priv *tpriv = pt->af_packet_priv;
- if (netdev_uses_dsa(tpriv->pt.dev)) {
+ if (netdev_uses_dsa(tpriv->pt.dev) || tpriv->capture_all) {
tpriv->packet_type = tpriv->pt.type;
tpriv->func = tpriv->pt.func;
/* DSA conduit will report ETH_P_XDSA, so our packet handler
* won't match. Let's register a ETH_P_ALL match and filter
- * manually in stmmac_sft_filter.
+ * manually in stmmac_sft_filter. This is also useful for
+ * VLAN tests, to capture packets otherwise marked as
+ * OTHERHOST.
*/
tpriv->pt.type = htons(ETH_P_ALL);
tpriv->pt.func = stmmac_sft_filter;
@@ -963,6 +966,11 @@ static int stmmac_test_vlan_validate(struct sk_buff *skb,
goto out;
if (skb_headlen(skb) < (STMMAC_TEST_PKT_SIZE - ETH_HLEN))
goto out;
+
+ ehdr = (struct ethhdr *)skb_mac_header(skb);
+ if (!ether_addr_equal_unaligned(ehdr->h_dest, tpriv->packet->dst))
+ goto out;
+
if (tpriv->vlan_id) {
if (skb->vlan_proto != htons(proto))
goto out;
@@ -974,10 +982,6 @@ static int stmmac_test_vlan_validate(struct sk_buff *skb,
}
}
- ehdr = (struct ethhdr *)skb_mac_header(skb);
- if (!ether_addr_equal_unaligned(ehdr->h_dest, tpriv->packet->dst))
- goto out;
-
ihdr = ip_hdr(skb);
if (tpriv->double_vlan)
ihdr = (struct iphdr *)(skb_network_header(skb) + 4);
@@ -1019,6 +1023,7 @@ static int __stmmac_test_vlanfilt(struct stmmac_priv *priv)
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
+ tpriv->capture_all = true;
/*
* As we use HASH filtering, false positives may appear. This is a
@@ -1115,6 +1120,7 @@ static int __stmmac_test_dvlanfilt(struct stmmac_priv *priv)
tpriv->pt.dev = priv->dev;
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
+ tpriv->capture_all = true;
/*
* As we use HASH filtering, false positives may appear. This is a
@@ -1395,6 +1401,7 @@ static int stmmac_test_vlanoff_common(struct stmmac_priv *priv, bool svlan)
tpriv->pt.af_packet_priv = tpriv;
tpriv->packet = &attr;
tpriv->vlan_id = 0x123;
+ tpriv->capture_all = true;
ret = vlan_vid_add(priv->dev, htons(proto), tpriv->vlan_id);
if (ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 161/457] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 160/457] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 162/457] net: stmmac: size the RX buffers from the frame length, not the MTU Greg Kroah-Hartman
` (306 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Nicolai Buchwitz,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit b42e7012773a0e81e97a2dda6ef907f5147a6658 ]
DMA bufsize selection isn't made on the MTU but the actual frame length,
so including the L2 header. On DWMAC4, if the len is exactly BUF_SIZE_8KiB,
the next larger size is incorrectly selected.
Lets fix the comparison and while at it, rename the parameter from len
to mtu.
Fixes: c3efed5ad1b0 ("net: stmmac: Enable dwmac4 jumbo frame more than 8KiB").
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260917215339.2022523-6-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c | 4 ++--
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
drivers/net/ethernet/stmicro/stmmac/ring_mode.c | 4 ++--
3 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c b/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
index 2994df41ec2c4..c6a8f8d735015 100644
--- a/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
+++ b/drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c
@@ -474,11 +474,11 @@ static void dwmac4_set_sarc(struct dma_desc *p, u32 sarc_type)
sarc_type));
}
-static int set_16kib_bfsize(int mtu)
+static int set_16kib_bfsize(int len)
{
int ret = 0;
- if (unlikely(mtu >= BUF_SIZE_8KiB))
+ if (unlikely(len > BUF_SIZE_8KiB))
ret = BUF_SIZE_16KiB;
return ret;
}
diff --git a/drivers/net/ethernet/stmicro/stmmac/hwif.h b/drivers/net/ethernet/stmicro/stmmac/hwif.h
index 9314bcb85c221..857f7562c6c6d 100644
--- a/drivers/net/ethernet/stmicro/stmmac/hwif.h
+++ b/drivers/net/ethernet/stmicro/stmmac/hwif.h
@@ -540,7 +540,7 @@ struct stmmac_mode_ops {
bool (*is_jumbo_frm)(unsigned int len, bool enh_desc);
int (*jumbo_frm)(struct stmmac_tx_queue *tx_q, struct sk_buff *skb,
int csum);
- int (*set_16kib_bfsize)(int mtu);
+ int (*set_16kib_bfsize)(int len);
void (*init_desc3)(struct dma_desc *p);
void (*refill_desc3)(struct stmmac_rx_queue *rx_q, struct dma_desc *p);
void (*clean_desc3)(struct stmmac_tx_queue *tx_q, struct dma_desc *p);
diff --git a/drivers/net/ethernet/stmicro/stmmac/ring_mode.c b/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
index 78fc6aa5bbe95..dd796cb74419e 100644
--- a/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
+++ b/drivers/net/ethernet/stmicro/stmmac/ring_mode.c
@@ -123,10 +123,10 @@ static void clean_desc3(struct stmmac_tx_queue *tx_q, struct dma_desc *p)
p->des3 = 0;
}
-static int set_16kib_bfsize(int mtu)
+static int set_16kib_bfsize(int len)
{
int ret = 0;
- if (unlikely(mtu > BUF_SIZE_8KiB))
+ if (unlikely(len > BUF_SIZE_8KiB))
ret = BUF_SIZE_16KiB;
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 162/457] net: stmmac: size the RX buffers from the frame length, not the MTU
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 161/457] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 163/457] net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test Greg Kroah-Hartman
` (305 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit b8a26d46c0a4254f8bfe143681adb9d18d020299 ]
When picking the buffsize to use based on the MTU, we shouldn't check
only the MTU value, but also :
- ETH_HLEN for the L2 header,
- up to 2 VLAN tags,
- the FCS,
The default bufsize is 1536 bytes, which is enough to contain all the
above so this hasn't surfaced before, but the addition of NET_IP_ALIGN
to the start of buffer address tripped the Jumbo selftest, leading to
this discovery.
With that, we don't need the '>=' checks on the buffer len, we can use
more consistent comparison operators in stmmac_set_bfsize.
Fixes: 286a83721720 ("stmmac: add CHAINED descriptor mode support (V4)")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-7-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/stmicro/stmmac/stmmac_main.c | 20 ++++++++++---------
1 file changed, 11 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index 5f717f02c3c01..9c4d92a19f2c0 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -1536,17 +1536,17 @@ static unsigned int stmmac_rx_offset(struct stmmac_priv *priv)
return NET_SKB_PAD + NET_IP_ALIGN;
}
-static int stmmac_set_bfsize(int mtu)
+static int stmmac_set_bfsize(int len)
{
int ret;
- if (mtu >= BUF_SIZE_8KiB)
+ if (len > BUF_SIZE_8KiB)
ret = BUF_SIZE_16KiB;
- else if (mtu >= BUF_SIZE_4KiB)
+ else if (len > BUF_SIZE_4KiB)
ret = BUF_SIZE_8KiB;
- else if (mtu >= BUF_SIZE_2KiB)
+ else if (len > BUF_SIZE_2KiB)
ret = BUF_SIZE_4KiB;
- else if (mtu > DEFAULT_BUFSIZE)
+ else if (len > DEFAULT_BUFSIZE)
ret = BUF_SIZE_2KiB;
else
ret = DEFAULT_BUFSIZE;
@@ -4063,7 +4063,7 @@ static struct stmmac_dma_conf *
stmmac_setup_dma_desc(struct stmmac_priv *priv, unsigned int mtu)
{
struct stmmac_dma_conf *dma_conf;
- int bfsize, ret;
+ int bfsize, len, ret;
u8 chan;
dma_conf = kzalloc_obj(*dma_conf);
@@ -4073,13 +4073,15 @@ stmmac_setup_dma_desc(struct stmmac_priv *priv, unsigned int mtu)
return ERR_PTR(-ENOMEM);
}
- /* Returns 0 or BUF_SIZE_16KiB if mtu > 8KiB and dwmac4 or ring mode */
- bfsize = stmmac_set_16kib_bfsize(priv, mtu);
+ len = mtu + ETH_HLEN + 2 * VLAN_HLEN + ETH_FCS_LEN;
+
+ /* Returns 0 or BUF_SIZE_16KiB if len > 8KiB and dwmac4 or ring mode */
+ bfsize = stmmac_set_16kib_bfsize(priv, len);
if (bfsize < 0)
bfsize = 0;
if (bfsize < BUF_SIZE_16KiB)
- bfsize = stmmac_set_bfsize(mtu);
+ bfsize = stmmac_set_bfsize(len);
dma_conf->dma_buf_sz = bfsize;
/* Chose the tx/rx size from the already defined one in the
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 163/457] net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 162/457] net: stmmac: size the RX buffers from the frame length, not the MTU Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 164/457] eth: fbnic: Avoid rounding zero ring sizes Greg Kroah-Hartman
` (304 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Chevallier <maxime.chevallier@bootlin.com>
[ Upstream commit c4ac6e94eb9423126bda907a7f2933284f7450ff ]
On dwmac1000, we currently only support single-descriptor frames. The
Jumbo test started failing when NET_IP_ALIGN was added to align the IP
header, as this tests tries to send the biggest possible frame.
On dwmac1000 the DMA transfer is aligned on 4-bytes, so adding a 2-byte
shift at the start-of-buffer address means it takes a whole extra 4-byte
DMA burst to receive the Jumbo packet, causing it to spill over the next
descriptor.
This doesn't seem to happen on dwmac4 and xgmac that appear to correctly
handle unaligned xfers (only tested on dwmac4)
Let's account for that in the Jumbo test, reduce the size of our big
packet by the align size.
Fixes: 23680bf5f8c6 ("net: stmmac: restore NET_IP_ALIGN in the RX DMA offset")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260917215339.2022523-8-maxime.chevallier@bootlin.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
index b3b05a7753335..75647992cbb44 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_selftests.c
@@ -1809,6 +1809,9 @@ static int __stmmac_test_jumbo(struct stmmac_priv *priv, u16 queue)
struct stmmac_packet_attrs attr = { };
int size = priv->dma_conf.dma_buf_sz;
+ if (!dwmac_is_xmac(priv->plat->core_type))
+ size -= NET_IP_ALIGN;
+
attr.dst = priv->dev->dev_addr;
attr.max_size = size - ETH_FCS_LEN;
attr.queue_mapping = queue;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 164/457] eth: fbnic: Avoid rounding zero ring sizes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 163/457] net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 165/457] net/sched: fix potential stack infoleak in em_text_dump() Greg Kroah-Hartman
` (303 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Alexander Duyck,
Björn Töpel, Joe Damato, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Björn Töpel <bjorn@kernel.org>
[ Upstream commit 0160953d8eec75c3c55562158c46442ff1fd410b ]
roundup_pow_of_two() is undefined for zero. ethtool permits a zero ring
size to reach the driver, where the minimum-size check should reject it.
Leave zero unchanged while rounding nonzero ring sizes. The minimum-size
check then rejects zero deterministically without changing the established
behavior for other values.
Fixes: 6cbf18a05c06 ("eth: fbnic: support ring size configuration")
Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
Link: https://lore.kernel.org/netdev/178971206933.22033.236948278674126701@kernel.org/
Suggested-by: Alexander Duyck <alexanderduyck@fb.com>
Signed-off-by: Björn Töpel <bjorn@kernel.org>
Reviewed-by: Joe Damato <joe@dama.to>
Link: https://patch.msgid.link/20260918114641.1281172-1-bjorn@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c b/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
index 423f179c9d475..76e9a545bb165 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_ethtool.c
@@ -313,6 +313,11 @@ fbnic_get_ringparam(struct net_device *netdev, struct ethtool_ringparam *ring,
kernel_ring->hds_thresh = fbn->hds_thresh;
}
+static u32 fbnic_ring_size_pow2(u32 size)
+{
+ return size ? roundup_pow_of_two(size) : 0;
+}
+
static void fbnic_set_rings(struct fbnic_net *fbn,
struct ethtool_ringparam *ring,
struct kernel_ethtool_ringparam *kernel_ring)
@@ -334,10 +339,10 @@ fbnic_set_ringparam(struct net_device *netdev, struct ethtool_ringparam *ring,
struct fbnic_net *clone;
int err;
- ring->rx_pending = roundup_pow_of_two(ring->rx_pending);
- ring->rx_mini_pending = roundup_pow_of_two(ring->rx_mini_pending);
- ring->rx_jumbo_pending = roundup_pow_of_two(ring->rx_jumbo_pending);
- ring->tx_pending = roundup_pow_of_two(ring->tx_pending);
+ ring->rx_pending = fbnic_ring_size_pow2(ring->rx_pending);
+ ring->rx_mini_pending = fbnic_ring_size_pow2(ring->rx_mini_pending);
+ ring->rx_jumbo_pending = fbnic_ring_size_pow2(ring->rx_jumbo_pending);
+ ring->tx_pending = fbnic_ring_size_pow2(ring->tx_pending);
/* These are absolute minimums allowing the device and driver to operate
* but not necessarily guarantee reasonable performance. Settings below
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 165/457] net/sched: fix potential stack infoleak in em_text_dump()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 164/457] eth: fbnic: Avoid rounding zero ring sizes Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 166/457] bpf: Reject dev-bound-only programs on other devices Greg Kroah-Hartman
` (302 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bernard Ladenthin, Jamal Hadi Salim,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bernard Ladenthin <bernard.ladenthin@gmail.com>
[ Upstream commit 9c572a83037a7dcd653ba3a9cc468c16b857d0c9 ]
em_text_dump() allocates struct tcf_em_text on the stack without zeroing
it. strscpy() writes the algorithm name and a NUL terminator into
conf.algo[], leaving the remaining bytes uninitialised. nla_put_nohdr()
then copies the full struct to the netlink response.
KMSAN on Linux 7.2-rc6 reports two kernel-infoleak splats from this path,
one triggered via "tc filter show" and one via a raw RTM_GETTFILTER dump:
BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x1c9/0x2620
nla_put_nohdr+0x83/0x130
em_text_dump+0x291/0x550
Local variable conf created at: em_text_dump+0x5d/0x550
Bytes 168-179 of 199 are uninitialized
I am not certain whether this constitutes a real security problem in
practice: the test was conducted in a controlled KMSAN environment and
the leaked stack bytes may or may not carry sensitive data on actual
production kernels. I am reporting it because KMSAN flagged it as a
kernel-infoleak and the fix is straightforward. I can provide a
userspace reproducer on request.
The original code used strncpy() which zero-pads to the destination size.
Commit b04202d6065c ("net/sched: replace strncpy with strscpy") replaced
it with strscpy(), which does not pad, creating this condition.
Zero-initialising the struct closes it.
Fixes: b04202d6065c ("net/sched: replace strncpy with strscpy")
Link: https://lore.kernel.org/netdev/20250327143733.187438-1-richard120310@gmail.com/
Assisted-by: Claude:claude-sonnet-4-6 [KMSAN]
Signed-off-by: Bernard Ladenthin <bernard.ladenthin@gmail.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/20260918133953.12494-1-bernard.ladenthin@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/em_text.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sched/em_text.c b/net/sched/em_text.c
index 343f1aebeec2a..4132f8c3c5fc9 100644
--- a/net/sched/em_text.c
+++ b/net/sched/em_text.c
@@ -113,7 +113,7 @@ static void em_text_destroy(struct tcf_ematch *m)
static int em_text_dump(struct sk_buff *skb, struct tcf_ematch *m)
{
struct text_match *tm = EM_TEXT_PRIV(m);
- struct tcf_em_text conf;
+ struct tcf_em_text conf = {};
strscpy(conf.algo, tm->config->ops->name);
conf.from_offset = tm->from_offset;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 166/457] bpf: Reject dev-bound-only programs on other devices
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 165/457] net/sched: fix potential stack infoleak in em_text_dump() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 167/457] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
` (301 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+ac0a8c41de69121d, Weiming Shi,
Alexei Starovoitov, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 6db1ce73e9853f533eb7f413f14ba00f8ec6f80d ]
__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.
Oops: general protection fault, probably for non-canonical address
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
Call Trace:
...
tun_build_skb (drivers/net/tun.c:1739)
tun_get_user (drivers/net/tun.c:1856)
tun_chr_write_iter (drivers/net/tun.c:2091)
vfs_write (fs/read_write.c:595 fs/read_write.c:687)
ksys_write (fs/read_write.c:739)
do_syscall_64 (arch/x86/entry/syscall_64.c:84)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Fixes: 2b3486bc2d23 ("bpf: Introduce device-bound XDP programs")
Reported-by: <co+ac0a8c41de69121d@bugs.sh>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20260917161335.1020405-2-bestswngs@gmail.com/
Link: https://patch.msgid.link/20260920132303.4109240-3-bestswngs@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/offload.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/bpf/offload.c b/kernel/bpf/offload.c
index 0d6f5569588c3..d855399812eec 100644
--- a/kernel/bpf/offload.c
+++ b/kernel/bpf/offload.c
@@ -698,6 +698,8 @@ static bool __bpf_offload_dev_match(struct bpf_prog *prog,
return false;
if (offload->netdev == netdev)
return true;
+ if (!bpf_prog_is_offloaded(prog->aux))
+ return false;
ondev1 = bpf_offload_find_netdev(offload->netdev);
ondev2 = bpf_offload_find_netdev(netdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 167/457] nfc: nfcmrvl: validate helper command length before pull
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 166/457] bpf: Reject dev-bound-only programs on other devices Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 168/457] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
` (300 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 686f942332b1667f13f3b8d6a2f50bcfbf42e277 ]
The firmware download receive path removes the NCI data header and
reads the helper command before validating the remaining packet length.
A short frame can therefore reach the data access before the malformed
packet is rejected.
Validate the complete helper command length before stripping the NCI
data header.
Fixes: 3194c6870158 ("NFC: nfcmrvl: add firmware download support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084325.40276-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/nfcmrvl/fw_dnld.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/nfc/nfcmrvl/fw_dnld.c b/drivers/nfc/nfcmrvl/fw_dnld.c
index 2b8f401d8fd7a..8b9d5257320dc 100644
--- a/drivers/nfc/nfcmrvl/fw_dnld.c
+++ b/drivers/nfc/nfcmrvl/fw_dnld.c
@@ -263,9 +263,14 @@ static int process_state_fw_dnld(struct nfcmrvl_private *priv,
* B8..N: payload
*/
- /* Remove NCI HDR */
- skb_pull(skb, 3);
- if (skb->data[0] != HELPER_CMD_PACKET_FORMAT || skb->len != 5) {
+ if (skb->len != NCI_DATA_HDR_SIZE + 5) {
+ nfc_err(priv->dev, "bad command");
+ return -EINVAL;
+ }
+
+ /* Remove NCI header */
+ skb_pull(skb, NCI_DATA_HDR_SIZE);
+ if (skb->data[0] != HELPER_CMD_PACKET_FORMAT) {
nfc_err(priv->dev, "bad command");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 168/457] nfc: st21nfca: validate received frame size
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 167/457] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 169/457] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
` (299 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit a653c01ce447f10c36b901646888c0330363af4f ]
st21nfca_hci_i2c_repack() trims a received frame at its EOF marker
before removing byte stuffing. It then assumes the truncated frame
contains the LLC header and two CRC bytes, and it unconditionally reads
the byte after an escape marker.
A malformed frame can place EOF immediately after the start marker or can
end its data portion with an escape marker. The former leaves too few
bytes for check_crc(), while the latter makes the unstuffing loop read past
the current skb length.
Require the minimum framing bytes both before and after unstuffing. Use
separate input and output cursors while removing byte stuffing, and reject
an escape marker without its encoded byte. This keeps malformed frames
within the received frame boundary before CRC processing.
Fixes: 3096e25a3e40 ("NFC: st21nfca: Fix incorrect byte stuffing revocation")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084405.41546-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/st21nfca/i2c.c | 29 +++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
diff --git a/drivers/nfc/st21nfca/i2c.c b/drivers/nfc/st21nfca/i2c.c
index aa5f4922b6b04..11ba4fb498283 100644
--- a/drivers/nfc/st21nfca/i2c.c
+++ b/drivers/nfc/st21nfca/i2c.c
@@ -289,27 +289,36 @@ static int check_crc(u8 *buf, int buflen)
*/
static int st21nfca_hci_i2c_repack(struct sk_buff *skb)
{
- int i, j, r, size;
+ int read, write, r, size;
- if (skb->len < 1 || (skb->len > 1 && skb->data[1] != 0))
+ if (skb->len < ST21NFCA_FRAME_HEADROOM ||
+ !IS_START_OF_FRAME(skb->data))
return -EBADMSG;
size = get_frame_size(skb->data, skb->len);
if (size > 0) {
+ if (size < ST21NFCA_FRAME_HEADROOM + 2)
+ return -EBADMSG;
+
skb_trim(skb, size);
/* remove ST21NFCA byte stuffing for upper layer */
- for (i = 1, j = 0; i < skb->len; i++) {
- if (skb->data[i + j] ==
+ for (read = 1, write = 1; read < skb->len;) {
+ if (skb->data[read] ==
(u8) ST21NFCA_ESCAPE_BYTE_STUFFING) {
- skb->data[i] = skb->data[i + j + 1]
- | ST21NFCA_BYTE_STUFFING_MASK;
- i++;
- j++;
+ if (read + 1 == skb->len)
+ return -EBADMSG;
+
+ skb->data[write++] = skb->data[read + 1]
+ | ST21NFCA_BYTE_STUFFING_MASK;
+ read += 2;
+ } else {
+ skb->data[write++] = skb->data[read++];
}
- skb->data[i] = skb->data[i + j];
}
/* remove byte stuffing useless byte */
- skb_trim(skb, i - j);
+ skb_trim(skb, write);
+ if (skb->len < ST21NFCA_FRAME_HEADROOM + 2)
+ return -EBADMSG;
/* remove ST21NFCA_SOF_EOF from head */
skb_pull(skb, 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 169/457] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 168/457] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 170/457] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
` (298 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
[ Upstream commit bf1460acdf8cf5a07c819f59785d40f20d113099 ]
nfc_llcp_recv_dm() handles DM(NOBOUND)/DM(REJ) for a socket that is still
linked on local->connecting_sockets: it looks the socket up with
nfc_llcp_connecting_sock_get(), sets sk->sk_state = LLCP_CLOSED and
returns, without taking the socket lock and without unlinking the socket
from the connecting_sockets list.
llcp_sock_release() selects the list to unlink from by sk_state: a socket
in LLCP_CONNECTING is unlinked from connecting_sockets, otherwise from the
sockets list. Because recv_dm left the socket physically on
connecting_sockets but in the LLCP_CLOSED state, release() takes the else
branch and calls nfc_llcp_sock_unlink(&local->sockets, sk). That runs
sk_del_node_init() while holding sockets.lock, i.e. it removes the socket
from the connecting_sockets hlist under the wrong lock. A concurrent
connect() linking another socket onto connecting_sockets under
connecting_sockets.lock then mutates the same hlist unserialized, which
corrupts the list and desyncs the sk_add_node()/sk_del_node_init()
sock_hold()/__sock_put() pairing. An unprivileged local process holding
LLCP sockets, with the DM supplied by the remote peer over an established
LLCP link, can drive this to leak kernel sockets without bound (the
mis-decrement goes through the non-freeing __sock_put() path, so the
object is never released), leading to memory exhaustion / DoS.
This is the same class of bug that was fixed in the sibling handler
nfc_llcp_recv_cc() by commit b493ea2765cc ("nfc: llcp: Fix use-after-free
race in nfc_llcp_recv_cc()"); recv_dm did not receive the equivalent fix.
Fix it the same way: take lock_sock(), re-check that the socket is still
hashed (release() may have won the race), and for the NOBOUND/REJ case
unlink it from connecting_sockets before moving it to LLCP_CLOSED. The
unlink drops the connecting_sockets membership reference via
sk_del_node_init(), leaving the socket unhashed, so the later
nfc_llcp_sock_unlink() in llcp_sock_release() becomes a no-op and no
double put occurs.
Fixes: a69f32af86e3 ("NFC: Socket linked list")
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Link: https://patch.msgid.link/20260716232657.203145-1-qwe.aldo@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_core.c | 25 +++++++++++++++++++++++++
1 file changed, 25 insertions(+)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index cac1b5487064d..bd6361e2efa4f 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1251,6 +1251,7 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
struct nfc_llcp_sock *llcp_sock;
struct sock *sk;
u8 dsap, ssap, reason;
+ bool connecting = false;
dsap = nfc_llcp_dsap(skb);
ssap = nfc_llcp_ssap(skb);
@@ -1262,6 +1263,7 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
case LLCP_DM_NOBOUND:
case LLCP_DM_REJ:
llcp_sock = nfc_llcp_connecting_sock_get(local, dsap);
+ connecting = true;
break;
default:
@@ -1276,10 +1278,33 @@ static void nfc_llcp_recv_dm(struct nfc_llcp_local *local,
sk = &llcp_sock->sk;
+ lock_sock(sk);
+
+ /* Check if socket was destroyed whilst waiting for the lock */
+ if (!sk_hashed(sk)) {
+ release_sock(sk);
+ nfc_llcp_sock_put(llcp_sock);
+ return;
+ }
+
+ /*
+ * For DM(NOBOUND)/DM(REJ) the socket is still linked on the
+ * connecting_sockets list. Unlink it here, under the socket lock,
+ * before moving it to LLCP_CLOSED: llcp_sock_release() selects the
+ * list to unlink from by sk_state, so leaving a connecting socket
+ * in the CLOSED state would make it unlink from the wrong list and
+ * corrupt the connecting_sockets list / desync the socket refcount.
+ * This mirrors nfc_llcp_recv_cc().
+ */
+ if (connecting)
+ nfc_llcp_sock_unlink(&local->connecting_sockets, sk);
+
sk->sk_err = ENXIO;
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
+ release_sock(sk);
+
nfc_llcp_sock_put(llcp_sock);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 170/457] selftests: nci: Correct pthread_create return value check
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 169/457] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 171/457] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
` (297 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lei Zhu, David Heidelberg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lei Zhu <zhulei@kylinos.cn>
[ Upstream commit 3d8afc5243ea2ee803d98e69eb4a01748167ac1b ]
The pthread_create() functions returns 0 on success and a positive value on
failure. Modify the return value check to correctly detect failure cases.
Fixes: 72696bd8a09d ("selftests: nci: Extract the start/stop discovery function")
Signed-off-by: Lei Zhu <zhulei@kylinos.cn>
Link: https://patch.msgid.link/20260729072426.303484-1-zhulei_szu@163.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index 312f84ee0444f..c053f5cf2745d 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -438,7 +438,7 @@ FIXTURE_SETUP(NCI)
else
rc = pthread_create(&thread_t, NULL, virtual_dev_open,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_UP, self->dev_idex);
@@ -509,7 +509,7 @@ FIXTURE_TEARDOWN(NCI)
rc = pthread_create(&thread_t, NULL, virtual_deinit,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
@@ -590,7 +590,7 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
rc = pthread_create(&thread_t, NULL, virtual_poll_start,
(void *)&virtual_fd);
- if (rc < 0)
+ if (rc)
return rc;
rc = send_cmd_mt_nla(sd, fid, pid, NFC_CMD_START_POLL, 2, nla_start_poll_type,
@@ -610,7 +610,7 @@ int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
rc = pthread_create(&thread_t, NULL, virtual_poll_stop,
(void *)&virtual_fd);
- if (rc < 0)
+ if (rc)
return rc;
rc = send_cmd_with_idx(sd, fid, pid,
@@ -830,6 +830,8 @@ int disconnect_tag(int nfc_sock, int virtual_fd)
status = pthread_create(&thread_t, NULL, virtual_deactivate_proc,
(void *)&virtual_fd);
+ if (status)
+ return status;
close(nfc_sock);
pthread_join(thread_t, (void **)&status);
@@ -874,7 +876,7 @@ TEST_F(NCI, deinit)
else
rc = pthread_create(&thread_t, NULL, virtual_deinit,
(void *)&self->virtual_nci_fd);
- ASSERT_GT(rc, -1);
+ ASSERT_EQ(rc, 0);
rc = send_cmd_with_idx(self->sd, self->fid, self->pid,
NFC_CMD_DEV_DOWN, self->dev_idex);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 171/457] nfc: llcp: Fix race condition in accept_queue lifecycle
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 170/457] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 172/457] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
` (296 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lee Jones, David Heidelberg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lee Jones <lee@kernel.org>
[ Upstream commit c3eef2f988a3db9690369d7cef9a3344dd9788d3 ]
In nfc_llcp_socket_release(), sockets and listener accept queues are
walked under the local sockets rwlock and bh_lock_sock(). However,
bh_lock_sock() does not synchronise against process-context lock_sock()
held by nfc_llcp_accept_dequeue() during accept(). Because
socket_release() does not check sock_owned_by_user(), both paths can
concurrently unlink and release the same child socket, resulting in
use-after-free or a NULL pointer dereference of child->parent in
nfc_llcp_accept_unlink().
Fix this synchronisation race by having nfc_llcp_socket_release() use
process-context lock_sock() instead of bh_lock_sock():
1. Pop sockets from the local sockets list under the write lock using
nfc_llcp_sock_list_pop() so lock_sock() can be acquired without
holding the rwlock.
2. Because lock_sock() can sleep, defer the final release of the
nfc_llcp_local structure to a workqueue (release_work). This avoids
a sleeping-in-atomic bug when the last local reference is dropped
from softirq context. Additionally, hold a single device reference
on local from registration until final destruction.
3. In nfc_llcp_local_get(), use kref_get_unless_zero() to prevent
resurrecting a local object whose teardown has been scheduled.
4. In llcp_sock_accept(), verify that the listener socket state is still
LLCP_LISTEN after waking from schedule_timeout() to prevent hangs if
the listener is closed concurrently.
5. When unlinking unaccepted child sockets during listener release,
unlink them from local->sockets, call sock_orphan(), and drop their
initial sk_alloc creation reference via sock_put().
6. Make nfc_llcp_accept_unlink() idempotent by guarding parent access with
a NULL check.
Fixes: 50b78b2a6500 ("NFC: Fix sleeping in atomic when releasing socket")
Signed-off-by: Lee Jones <lee@kernel.org>
Link: https://patch.msgid.link/20260902123033.1169067-1-lee@kernel.org
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp.h | 1 +
net/nfc/llcp_core.c | 125 +++++++++++++++++++++++++++-----------------
net/nfc/llcp_sock.c | 49 ++++++++++++-----
3 files changed, 116 insertions(+), 59 deletions(-)
diff --git a/net/nfc/llcp.h b/net/nfc/llcp.h
index d8345ed57c954..23ae7a0112d37 100644
--- a/net/nfc/llcp.h
+++ b/net/nfc/llcp.h
@@ -91,6 +91,7 @@ struct nfc_llcp_local {
struct hlist_head pending_sdreqs;
struct timer_list sdreq_timer;
struct work_struct sdreq_timeout_work;
+ struct work_struct release_work;
u8 sdreq_next_tid;
/* sockets array */
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index bd6361e2efa4f..23553e7426ec2 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -20,6 +20,8 @@ static LIST_HEAD(llcp_devices);
/* Protects llcp_devices list */
static DEFINE_SPINLOCK(llcp_devices_lock);
+static struct workqueue_struct *llcp_wq;
+
static void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb);
void nfc_llcp_sock_link(struct llcp_sock_list *l, struct sock *sk)
@@ -63,21 +65,33 @@ static void nfc_llcp_socket_purge(struct nfc_llcp_sock *sock)
}
}
+static struct sock *nfc_llcp_sock_list_pop(struct llcp_sock_list *l)
+{
+ struct sock *sk;
+
+ write_lock(&l->lock);
+ sk = sk_head(&l->head);
+ if (sk) {
+ sock_hold(sk);
+ sk_del_node_init(sk);
+ }
+ write_unlock(&l->lock);
+
+ return sk;
+}
+
static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
int err)
{
struct sock *sk;
- struct hlist_node *tmp;
struct nfc_llcp_sock *llcp_sock;
skb_queue_purge(&local->tx_queue);
- write_lock(&local->sockets.lock);
-
- sk_for_each_safe(sk, tmp, &local->sockets.head) {
+ while ((sk = nfc_llcp_sock_list_pop(&local->sockets))) {
llcp_sock = nfc_llcp_sock(sk);
- bh_lock_sock(sk);
+ lock_sock(sk);
nfc_llcp_socket_purge(llcp_sock);
@@ -91,17 +105,27 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
list_for_each_entry_safe(lsk, n,
&llcp_sock->accept_queue,
accept_queue) {
- accept_sk = &lsk->sk;
- bh_lock_sock(accept_sk);
-
- nfc_llcp_accept_unlink(accept_sk);
+ bool put_creation = false;
- if (err)
- accept_sk->sk_err = err;
- accept_sk->sk_state = LLCP_CLOSED;
- accept_sk->sk_state_change(sk);
+ accept_sk = &lsk->sk;
+ lock_sock_nested(accept_sk,
+ SINGLE_DEPTH_NESTING);
+
+ if (nfc_llcp_sock(accept_sk)->parent == sk) {
+ nfc_llcp_accept_unlink(accept_sk);
+ nfc_llcp_sock_unlink(&local->sockets, accept_sk);
+
+ if (err)
+ accept_sk->sk_err = err;
+ accept_sk->sk_state = LLCP_CLOSED;
+ accept_sk->sk_state_change(accept_sk);
+ sock_orphan(accept_sk);
+ put_creation = true;
+ }
- bh_unlock_sock(accept_sk);
+ release_sock(accept_sk);
+ if (put_creation)
+ sock_put(accept_sk); /* creation ref */
}
}
@@ -110,23 +134,18 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
- bh_unlock_sock(sk);
-
- sk_del_node_init(sk);
+ release_sock(sk);
+ sock_put(sk);
}
- write_unlock(&local->sockets.lock);
-
/* If we still have a device, we keep the RAW sockets alive */
if (device == true)
return;
- write_lock(&local->raw_sockets.lock);
-
- sk_for_each_safe(sk, tmp, &local->raw_sockets.head) {
+ while ((sk = nfc_llcp_sock_list_pop(&local->raw_sockets))) {
llcp_sock = nfc_llcp_sock(sk);
- bh_lock_sock(sk);
+ lock_sock(sk);
nfc_llcp_socket_purge(llcp_sock);
@@ -135,26 +154,20 @@ static void nfc_llcp_socket_release(struct nfc_llcp_local *local, bool device,
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
- bh_unlock_sock(sk);
-
- sk_del_node_init(sk);
+ release_sock(sk);
+ sock_put(sk);
}
-
- write_unlock(&local->raw_sockets.lock);
}
static struct nfc_llcp_local *nfc_llcp_local_get(struct nfc_llcp_local *local)
{
- /* Since using nfc_llcp_local may result in usage of nfc_dev, whenever
- * we hold a reference to local, we also need to hold a reference to
- * the device to avoid UAF.
- */
- if (!nfc_get_device(local->dev->idx))
+ if (!local)
return NULL;
- kref_get(&local->ref);
+ if (kref_get_unless_zero(&local->ref))
+ return local;
- return local;
+ return NULL;
}
static void local_cleanup(struct nfc_llcp_local *local)
@@ -172,30 +185,34 @@ static void local_cleanup(struct nfc_llcp_local *local)
nfc_llcp_free_sdp_tlv_list(&local->pending_sdreqs);
}
-static void local_release(struct kref *ref)
+static void local_release_work(struct work_struct *work)
{
struct nfc_llcp_local *local;
+ struct nfc_dev *dev;
- local = container_of(ref, struct nfc_llcp_local, ref);
+ local = container_of(work, struct nfc_llcp_local, release_work);
+ dev = local->dev;
local_cleanup(local);
kfree(local);
+ nfc_put_device(dev);
}
-int nfc_llcp_local_put(struct nfc_llcp_local *local)
+static void local_release(struct kref *ref)
{
- struct nfc_dev *dev;
- int ret;
+ struct nfc_llcp_local *local;
- if (local == NULL)
- return 0;
+ local = container_of(ref, struct nfc_llcp_local, ref);
- dev = local->dev;
+ queue_work(llcp_wq, &local->release_work);
+}
- ret = kref_put(&local->ref, local_release);
- nfc_put_device(dev);
+int nfc_llcp_local_put(struct nfc_llcp_local *local)
+{
+ if (!local)
+ return 0;
- return ret;
+ return kref_put(&local->ref, local_release);
}
static struct nfc_llcp_sock *nfc_llcp_sock_get(struct nfc_llcp_local *local,
@@ -1705,6 +1722,7 @@ int nfc_llcp_register_device(struct nfc_dev *ndev)
INIT_WORK(&local->rx_work, nfc_llcp_rx_work);
INIT_WORK(&local->timeout_work, nfc_llcp_timeout_work);
+ INIT_WORK(&local->release_work, local_release_work);
rwlock_init(&local->sockets.lock);
rwlock_init(&local->connecting_sockets.lock);
@@ -1748,10 +1766,23 @@ void nfc_llcp_unregister_device(struct nfc_dev *dev)
int __init nfc_llcp_init(void)
{
- return nfc_llcp_sock_init();
+ int ret;
+
+ llcp_wq = alloc_workqueue("nfc_llcp_wq", WQ_UNBOUND, 0);
+ if (!llcp_wq)
+ return -ENOMEM;
+
+ ret = nfc_llcp_sock_init();
+ if (ret) {
+ destroy_workqueue(llcp_wq);
+ return ret;
+ }
+
+ return 0;
}
void nfc_llcp_exit(void)
{
nfc_llcp_sock_exit();
+ destroy_workqueue(llcp_wq);
}
diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index 5558d8a4d48b3..ce6875eb58fbc 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -392,11 +392,12 @@ void nfc_llcp_accept_unlink(struct sock *sk)
pr_debug("state %d\n", sk->sk_state);
- list_del_init(&llcp_sock->accept_queue);
- sk_acceptq_removed(llcp_sock->parent);
- llcp_sock->parent = NULL;
-
- sock_put(sk);
+ if (llcp_sock->parent) {
+ list_del_init(&llcp_sock->accept_queue);
+ sk_acceptq_removed(llcp_sock->parent);
+ llcp_sock->parent = NULL;
+ sock_put(sk);
+ }
}
void nfc_llcp_accept_enqueue(struct sock *parent, struct sock *sk)
@@ -423,12 +424,20 @@ struct sock *nfc_llcp_accept_dequeue(struct sock *parent,
list_for_each_entry_safe(lsk, n, &llcp_parent->accept_queue,
accept_queue) {
+ struct nfc_llcp_local *local;
+
sk = &lsk->sk;
- lock_sock(sk);
+ lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
if (sk->sk_state == LLCP_CLOSED) {
- release_sock(sk);
+ local = nfc_llcp_sock(sk)->local;
+
nfc_llcp_accept_unlink(sk);
+ if (local)
+ nfc_llcp_sock_unlink(&local->sockets, sk);
+ sock_orphan(sk);
+ release_sock(sk);
+ sock_put(sk);
continue;
}
@@ -464,7 +473,7 @@ static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
pr_debug("parent %p\n", sk);
- lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
+ lock_sock(sk);
if (sk->sk_state != LLCP_LISTEN) {
ret = -EBADFD;
@@ -490,7 +499,12 @@ static int llcp_sock_accept(struct socket *sock, struct socket *newsock,
release_sock(sk);
timeo = schedule_timeout(timeo);
- lock_sock_nested(sk, SINGLE_DEPTH_NESTING);
+ lock_sock(sk);
+
+ if (sk->sk_state != LLCP_LISTEN) {
+ ret = -EBADFD;
+ break;
+ }
}
__set_current_state(TASK_RUNNING);
remove_wait_queue(sk_sleep(sk), &wait);
@@ -629,13 +643,24 @@ static int llcp_sock_release(struct socket *sock)
list_for_each_entry_safe(lsk, n, &llcp_sock->accept_queue,
accept_queue) {
+ bool put_creation = false;
+
accept_sk = &lsk->sk;
- lock_sock(accept_sk);
+ lock_sock_nested(accept_sk, SINGLE_DEPTH_NESTING);
- nfc_llcp_send_disconnect(lsk);
- nfc_llcp_accept_unlink(accept_sk);
+ if (nfc_llcp_sock(accept_sk)->parent == sk) {
+ nfc_llcp_send_disconnect(lsk);
+ nfc_llcp_accept_unlink(accept_sk);
+ nfc_llcp_sock_unlink(&local->sockets, accept_sk);
+
+ accept_sk->sk_state = LLCP_CLOSED;
+ sock_orphan(accept_sk);
+ put_creation = true;
+ }
release_sock(accept_sk);
+ if (put_creation)
+ sock_put(accept_sk); /* creation ref */
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 172/457] selftests: nci: Fix uninitialized family ID on missing attribute
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 171/457] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 173/457] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
` (295 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chaithanya Lagisetty, Hangbin Liu,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
[ Upstream commit eda518d2cdb6074a0bcdfa06af291616bcb5c421 ]
get_family_id() walks the generic netlink CTRL_CMD_GETFAMILY reply
looking for the CTRL_ATTR_FAMILY_ID attribute and returns the parsed
value in the local variable "id". If the reply does not carry that
attribute, the parsing loop never assigns "id" and the function returns
an indeterminate stack value, which the caller stores in self->fid and
uses for subsequent netlink requests.
Initialize "id" to 0 so a missing attribute yields a deterministic
(invalid) family ID instead of a garbage value.
Fixes: f595cf1242f3 ("selftests: Add nci suite")
Signed-off-by: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260901070618.3299012-1-nagachaithanya9911@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index c053f5cf2745d..23fd38acfcf42 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -182,7 +182,7 @@ static int get_family_id(int sd, __u32 pid, __u32 *event_group)
} ans;
struct nlattr *na;
int resp_len;
- __u16 id;
+ __u16 id = 0;
int len;
int rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 173/457] selftests/nci: Fix out-of-bounds store on thread join
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 172/457] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 174/457] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
` (294 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann, Simon Horman,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
[ Upstream commit 6be581aeffc215bfc77939cd59902b0dbc4af23e ]
The NCI test collects the exit status of its helper threads by passing
the address of an int to pthread_join():
int status;
...
pthread_join(thread_t, (void **) &status);
pthread_join() stores a void pointer to the memory location. On 64-bit
systems, a void pointer is wider than an int, so the store overruns the
4 bytes of space allocated on the stack for the integer and corrupts the
adjacent stack. On our CHERI system, this caused a fault due to a
capability bounds violation.
Fix this by introducing a helper that joins a thread through a void
pointer and converts the result back to an integer, which is what the
helper threads return.
While here, also fix the logic in disconnect_tag() if the helper thread
creation failed. Previously, it would have joined a thread that was
never created when pthread_create() failed.
Fixes: f595cf1242f3 ("selftests: Add nci suite")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904095915.3372241-1-christian.gellermann@codasip.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/nci/nci_dev.c | 31 +++++++++++++++++----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/tools/testing/selftests/nci/nci_dev.c b/tools/testing/selftests/nci/nci_dev.c
index 23fd38acfcf42..07427fa42888d 100644
--- a/tools/testing/selftests/nci/nci_dev.c
+++ b/tools/testing/selftests/nci/nci_dev.c
@@ -8,6 +8,7 @@
#include <stdlib.h>
#include <errno.h>
+#include <stdint.h>
#include <string.h>
#include <sys/ioctl.h>
#include <fcntl.h>
@@ -87,6 +88,16 @@ struct msgtemplate {
char buf[MAX_MSG_SIZE];
};
+static int join_thread_status(pthread_t thread)
+{
+ void *thread_ret = NULL;
+
+ if (pthread_join(thread, &thread_ret))
+ return -1;
+
+ return (int)(intptr_t)thread_ret;
+}
+
static int create_nl_socket(void)
{
int fd;
@@ -444,7 +455,7 @@ FIXTURE_SETUP(NCI)
NFC_CMD_DEV_UP, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
ASSERT_EQ(status, 0);
self->open_state = true;
}
@@ -514,7 +525,7 @@ FIXTURE_TEARDOWN(NCI)
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
ASSERT_EQ(status, 0);
}
@@ -585,7 +596,6 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
void *nla_start_poll_data[2] = {&dev_idx, &proto};
int nla_start_poll_len[2] = {4, 4};
pthread_t thread_t;
- int status;
int rc;
rc = pthread_create(&thread_t, NULL, virtual_poll_start,
@@ -598,14 +608,12 @@ int start_polling(int dev_idx, int proto, int virtual_fd, int sd, int fid, int p
if (rc != 0)
return rc;
- pthread_join(thread_t, (void **)&status);
- return status;
+ return join_thread_status(thread_t);
}
int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
{
pthread_t thread_t;
- int status;
int rc;
rc = pthread_create(&thread_t, NULL, virtual_poll_stop,
@@ -618,8 +626,7 @@ int stop_polling(int dev_idx, int virtual_fd, int sd, int fid, int pid)
if (rc != 0)
return rc;
- pthread_join(thread_t, (void **)&status);
- return status;
+ return join_thread_status(thread_t);
}
TEST_F(NCI, start_poll)
@@ -834,8 +841,10 @@ int disconnect_tag(int nfc_sock, int virtual_fd)
return status;
close(nfc_sock);
- pthread_join(thread_t, (void **)&status);
- return status;
+ if (status)
+ return -1;
+
+ return join_thread_status(thread_t);
}
TEST_F(NCI, t4t_tag_read)
@@ -882,7 +891,7 @@ TEST_F(NCI, deinit)
NFC_CMD_DEV_DOWN, self->dev_idex);
EXPECT_EQ(rc, 0);
- pthread_join(thread_t, (void **)&status);
+ status = join_thread_status(thread_t);
self->open_state = 0;
ASSERT_EQ(status, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 174/457] nfc: virtual_ncidev: Add missing ioctl compat handler
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 173/457] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 175/457] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
` (293 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Gellermann, Simon Horman,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Gellermann <christian.gellermann@codasip.com>
[ Upstream commit 51814683e28fc64eceb415962376956c3cfc75a7 ]
The compat handler for ioctls to the virtual nci device is missing. So,
nci-specific ioctls of a compat task return with -1 and errno set to
ENOTTY. Add a handler.
The handling of an ioctl() call of a compat task to get the index of
virtual nci device (IOCTL_GET_NCIDEV_IDX) lands in the default case of
the ioctl compat handler (see fs/ioctl.c):
COMPAT_SYSCALL_DEFINE3(ioctl, ...)
{
...
default:
error = do_vfs_ioctl(fd_file(f), fd, cmd, ...);
if (error != -ENOIOCTLCMD)
break;
if (fd_file(f)->f_op->compat_ioctl)
error = fd_file(f)->f_op->compat_ioctl(fd_file(f), cmd, arg);
if (error == -ENOIOCTLCMD)
error = -ENOTTY;
...
}
There, do_vfs_ioctl() returns -ENOIOCTLCMD and compat_ioctl is not
set for virtual_ncidev_fops, i.e. f_op->compat_ioctl == NULL. So, the
ioctl() syscall returns with -1 and errno set to ENOTTY to the compat
task.
To fix this, use the compat_ptr_ioctl helper for compat handling here.
It shall be used for ioctls that "either ignore the argument or pass a
pointer to a compatible data type". The driver's sole ioctl takes a user
void pointer and copies nfc_dev->idx to it, a 4-byte integer across all
ABIs.
This issue has been found by running the nci_dev kernel selftest as
rv64 binary on top of a CHERI kernel, where the ioctl() ends up in
the ioctl compat handler, similar to a 32-bit application on top of a
64-bit kernel.
Fixes: e624e6c3e777 ("nfc: Add a virtual nci device driver")
Signed-off-by: Chris Gellermann <christian.gellermann@codasip.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260904164252.18351-1-christian.gellermann@codasip.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/virtual_ncidev.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/nfc/virtual_ncidev.c b/drivers/nfc/virtual_ncidev.c
index 8eeb447ac96e9..e51c647b27ebe 100644
--- a/drivers/nfc/virtual_ncidev.c
+++ b/drivers/nfc/virtual_ncidev.c
@@ -195,7 +195,8 @@ static const struct file_operations virtual_ncidev_fops = {
.write = virtual_ncidev_write,
.open = virtual_ncidev_open,
.release = virtual_ncidev_close,
- .unlocked_ioctl = virtual_ncidev_ioctl
+ .unlocked_ioctl = virtual_ncidev_ioctl,
+ .compat_ioctl = compat_ptr_ioctl,
};
static struct miscdevice miscdev = {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 175/457] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 174/457] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 176/457] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
` (292 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Simon Horman,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit 66f4300206b82b0b143ef0d9be90cd8d29f23a47 ]
nfc_genl_llc_sdreq() builds a list of TLV nodes while walking nested
netlink attrs, but 3 error paths (nested-attr parse failure, TLV alloc
ENOMEM, nfc_llcp_send_snl_sdreq() failure) all skip freeing what was
already queued.
Route them through a new free_list label, mirroring the SDRES path in
the same file which already does this. Harmless on the success path
too -- send_snl_sdreq() drains the list as it moves nodes, so it's
already empty by the time free_list runs.
Fixes: d9b8d8e19b07 ("NFC: llcp: Service Name Lookup netlink interface")
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260914121129.2098606-1-congnt264@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/netlink.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/nfc/netlink.c b/net/nfc/netlink.c
index 0c58824cb150d..224bdfa2dd0dc 100644
--- a/net/nfc/netlink.c
+++ b/net/nfc/netlink.c
@@ -1181,7 +1181,7 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
if (rc != 0) {
rc = -EINVAL;
- goto put_local;
+ goto free_list;
}
if (!sdp_attrs[NFC_SDP_ATTR_URI])
@@ -1200,7 +1200,7 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
sdreq = nfc_llcp_build_sdreq_tlv(tid, uri, uri_len);
if (sdreq == NULL) {
rc = -ENOMEM;
- goto put_local;
+ goto free_list;
}
tlvs_len += sdreq->tlv_len;
@@ -1215,6 +1215,9 @@ static int nfc_genl_llc_sdreq(struct sk_buff *skb, struct genl_info *info)
rc = nfc_llcp_send_snl_sdreq(local, &sdreq_list, tlvs_len);
+free_list:
+ nfc_llcp_free_sdp_tlv_list(&sdreq_list);
+
put_local:
nfc_llcp_local_put(local);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 176/457] nfc: st21nfca: validate ISO15693 inventory length
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 175/457] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 177/457] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
` (291 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, David Heidelberg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 7f2ea5ed588c03d481f0301e6c3d4240132383fb ]
The ISO15693 inventory helper removes a two-byte prefix without checking
that it exists, then accepts a one-byte remainder before reading data[1] as
the DSFID.
Require the prefix and at least two remaining bytes before copying the UID
data and reading the DSFID.
Fixes: 7974728094d3 ("NFC: st21nfca: Add ISO15693 Reader/Writer support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260830132958.6397-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/st21nfca/core.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/nfc/st21nfca/core.c b/drivers/nfc/st21nfca/core.c
index fd39a05c96222..34d797a29d21b 100644
--- a/drivers/nfc/st21nfca/core.c
+++ b/drivers/nfc/st21nfca/core.c
@@ -577,9 +577,7 @@ static int st21nfca_get_iso15693_inventory(struct nfc_hci_dev *hdev,
if (r < 0)
goto exit;
- skb_pull(inventory_skb, 2);
-
- if (inventory_skb->len == 0 ||
+ if (!skb_pull(inventory_skb, 2) || inventory_skb->len < 2 ||
inventory_skb->len > NFC_ISO15693_UID_MAXSIZE) {
r = -EPROTO;
goto exit;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 177/457] nfc: llcp: fix -ENOMEM on connect with zero-length service name
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 176/457] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 178/457] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
` (290 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ömer Mete Kaya,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit c04981e42d94f39c1dba965cc462a046e946a6c5 ]
When service_name_len is 0, kmemdup() returns ZERO_SIZE_PTR which
passes the NULL check, causing nfc_llcp_send_connect() to attempt
building a zero-length service name TLV and fail with -ENOMEM.
Fix by setting service_name to NULL directly when service_name_len is 0.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260909122029.34081-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_sock.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index ce6875eb58fbc..1e5ee4bcde684 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -759,12 +759,16 @@ static int llcp_sock_connect(struct socket *sock, struct sockaddr_unsized *_addr
llcp_sock->service_name_len = min_t(unsigned int,
addr->service_name_len,
NFC_LLCP_MAX_SERVICE_NAME);
- llcp_sock->service_name = kmemdup(addr->service_name,
- llcp_sock->service_name_len,
- GFP_KERNEL);
- if (!llcp_sock->service_name) {
- ret = -ENOMEM;
- goto sock_llcp_release;
+ if (llcp_sock->service_name_len == 0) {
+ llcp_sock->service_name = NULL;
+ } else {
+ llcp_sock->service_name = kmemdup(addr->service_name,
+ llcp_sock->service_name_len,
+ GFP_KERNEL);
+ if (!llcp_sock->service_name) {
+ ret = -ENOMEM;
+ goto sock_llcp_release;
+ }
}
nfc_llcp_sock_link(&local->connecting_sockets, sk);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 178/457] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 177/457] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 179/457] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
` (289 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ömer Mete Kaya,
David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit 408cff6bd60636df201274d320edfdfde9ed41db ]
nfc_llcp_wks_sap() compares only service_name_len bytes, so a short
service_name like "u" matches longer WKS strings like "urn:nfc:sn:snep".
Fix by requiring exact length match before strncmp().
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260909121437.33744-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 23553e7426ec2..fc267533a67f2 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -369,7 +369,8 @@ static int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len)
if (wks[sap] == NULL)
continue;
- if (strncmp(wks[sap], service_name, service_name_len) == 0)
+ if (strlen(wks[sap]) == service_name_len &&
+ !strncmp(wks[sap], service_name, service_name_len))
return sap;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 179/457] nfc: llcp: fix slab-out-of-bounds reads when logging service names
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 178/457] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 180/457] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
` (288 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1e3df0852e82c21ca418,
Ömer Mete Kaya, David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ömer Mete Kaya <omermetekaya0@gmail.com>
[ Upstream commit 7dcf371a35632f035baf77bcf2c129165f772ce4 ]
nfc_llcp_wks_sap() and nfc_llcp_build_sdreq_tlv() pass non-null-
terminated strings to pr_debug() using the %s format specifier.
The buffers are allocated via kmemdup() or come from netlink
attributes and are not guaranteed to be null-terminated, causing
__dynamic_pr_debug() to read beyond the allocated region:
KASAN: slab-out-of-bounds Read in __dynamic_pr_debug
Fix both call sites by using %.*s with the explicit length to limit
the output to the actual length of the string.
Fixes: d9b8d8e19b07 ("NFC: llcp: Service Name Lookup netlink interface")
Reported-by: syzbot+1e3df0852e82c21ca418@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1e3df0852e82c21ca418
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260908161952.731468-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/nfc/llcp_commands.c | 2 +-
net/nfc/llcp_core.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/nfc/llcp_commands.c b/net/nfc/llcp_commands.c
index ca89fe967d6a2..80a00938c8696 100644
--- a/net/nfc/llcp_commands.c
+++ b/net/nfc/llcp_commands.c
@@ -135,7 +135,7 @@ struct nfc_llcp_sdp_tlv *nfc_llcp_build_sdreq_tlv(u8 tid, const char *uri,
{
struct nfc_llcp_sdp_tlv *sdreq;
- pr_debug("uri: %s, len: %zu\n", uri, uri_len);
+ pr_debug("uri: %.*s, len: %zu\n", (int)uri_len, uri, uri_len);
/* sdreq->tlv_len is u8, takes uri_len, + 3 for header, + 1 for NULL */
if (WARN_ON_ONCE(uri_len > U8_MAX - 4))
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index fc267533a67f2..10665b2089873 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -358,7 +358,7 @@ static int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len)
{
int sap, num_wks;
- pr_debug("%s\n", service_name);
+ pr_debug("%.*s\n", (int)service_name_len, service_name);
if (service_name == NULL)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 180/457] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 179/457] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 181/457] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
` (287 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1853daab1a47603d4678,
Deepanshu Kartikey, David Heidelberg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Deepanshu Kartikey <kartikey406@gmail.com>
[ Upstream commit b61732f47316d45f27706db7812950145d3327b5 ]
frame->ccid.datalen is read directly from the USB response frame
and used, unchecked, as an index into frame->data[]. A malicious or
malfunctioning device can set this field to an arbitrary value,
causing the driver to read far outside the received buffer.
Bound ccid.datalen against the maximum possible ACR122 frame size
before using it. This replaces the existing datalen == 0 check,
since datalen < 2 already covers that case and additionally
rejects datalen == 1, which would still underflow the
"datalen - 2" offset used below.
Fixes: 9815c7cf22da ("NFC: pn533: Separate physical layer from the core implementation")
Reported-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1853daab1a47603d4678
Tested-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Assisted-by: LLM
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260923035627.6210-1-kartikey406@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nfc/pn533/usb.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/nfc/pn533/usb.c b/drivers/nfc/pn533/usb.c
index efb07f944fce2..972eaac09e592 100644
--- a/drivers/nfc/pn533/usb.c
+++ b/drivers/nfc/pn533/usb.c
@@ -319,7 +319,9 @@ static bool pn533_acr122_is_rx_frame_valid(void *_frame, struct pn533 *dev)
if (frame->ccid.type != 0x83)
return false;
- if (!frame->ccid.datalen)
+ if (frame->ccid.datalen < 2 ||
+ frame->ccid.datalen > PN533_ACR122_FRAME_MAX_PAYLOAD_LEN +
+ PN533_ACR122_RX_FRAME_TAIL_LEN)
return false;
if (frame->data[frame->ccid.datalen - 2] == 0x63)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 181/457] net/sched: act_gate: budget the per-entry list in get_fill_size
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 180/457] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 182/457] net: bcmgenet: stop Tx NAPI before disabling the queues Greg Kroah-Hartman
` (286 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, hybris, Jamal Hadi Salim,
Victor Nogueira, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Victor Nogueira <victor@mojatatu.com>
[ Upstream commit cfa165cbfbed9d0f4bbc22fef4309f595a3ab187 ]
tcf_gate_get_fill_size returns only the TCA_GATE_PARMS size, but
tcf_gate_dump also emits three 64-bit timestamps, the clock id, flags,
priority and the variable-length TCA_GATE_ENTRY_LIST nest. The per-entry
nest is unbounded: parse_gate_list places no cap on the number of
sched-entries, so a gate with many entries can push the real dump well
past the skb that tca_get_fill allocates from this size.
RTM_NEWACTION then fails the add-notify with -EINVAL while the action is
already committed to the IDR, and a subsequent RTM_GETACTION on the
installed gate also returns -EINVAL because its dump no longer fits.
Fix this by accounting for the missing fields in tcf_gate_get_fill_size
along with all elements in the entries list.
Note that sizing the reply from the action lets an oversized gate
install cleanly for the first time: with the input unbounded by
parse_gate_list, the sized skb can now grow well above
NLMSG_GOODSIZE per netlink request (a transient GFP_KERNEL allocation
reachable only with namespace-local CAP_NET_ADMIN). Overload from a
malicious netns admin is hardening material, not net, per the
discussion at
https://lore.kernel.org/netdev/20260914191108.55a1a4f1@kernel.org/;
a follow-up patch for net-next will cap the sched-entry count.
Fixes: 4e76e75d6aba ("net sched actions: calculate add/delete event message size")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Tested-by: hybris <hybris@mojatatu.ai>
Co-developed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Victor Nogueira <victor@mojatatu.com>
Link: https://patch.msgid.link/QDISC-3BLH.v1.20260914203033@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_gate.c | 30 +++++++++++++++++++++++++++++-
1 file changed, 29 insertions(+), 1 deletion(-)
diff --git a/net/sched/act_gate.c b/net/sched/act_gate.c
index fdbfcaa3e2ab9..a3c96519936ba 100644
--- a/net/sched/act_gate.c
+++ b/net/sched/act_gate.c
@@ -681,7 +681,35 @@ static void tcf_gate_stats_update(struct tc_action *a, u64 bytes, u64 packets,
static size_t tcf_gate_get_fill_size(const struct tc_action *act)
{
- return nla_total_size(sizeof(struct tc_gate));
+ struct tcf_gate *gact = to_gate(act);
+ const struct tcf_gate_params *p;
+ struct tcfg_gate_entry *entry;
+ size_t size = nla_total_size(sizeof(struct tc_gate)) /* TCA_GATE_PARMS */
+ + 3 * nla_total_size_64bit(sizeof(u64)) /* TCA_GATE_BASE_TIME
+ * TCA_GATE_CYCLE_TIME
+ * TCA_GATE_CYCLE_TIME_EXT
+ */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_CLOCKID */
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_FLAGS */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_PRIORITY */
+ + nla_total_size(0); /* TCA_GATE_ENTRY_LIST */
+ /* TCA_GATE_TM is budgeted by tcf_action_shared_attrs_size() */
+
+ rcu_read_lock();
+ p = rcu_dereference(gact->param);
+ if (p) {
+ list_for_each_entry_rcu(entry, &p->entries, list)
+ /* TCA_GATE_ONE_ENTRY nest and its attributes */
+ size += nla_total_size(0)
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_ENTRY_INDEX */
+ + nla_total_size(0) /* TCA_GATE_ENTRY_GATE */
+ + nla_total_size(sizeof(u32)) /* TCA_GATE_ENTRY_INTERVAL */
+ + nla_total_size(sizeof(s32)) /* TCA_GATE_ENTRY_MAX_OCTETS */
+ + nla_total_size(sizeof(s32)); /* TCA_GATE_ENTRY_IPV */
+ }
+ rcu_read_unlock();
+
+ return size;
}
static void tcf_gate_entry_destructor(void *priv)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 182/457] net: bcmgenet: stop Tx NAPI before disabling the queues
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 181/457] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 183/457] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
` (285 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 7e87508b5c4d81210d0a736ed01962e52f5c4c56 ]
bcmgenet_netif_stop() and the Wake-on-LAN branch of bcmgenet_suspend()
both disable the Tx queues first and stop Tx NAPI several steps later. A
completion in flight calls netif_tx_wake_queue() in between, and nothing
stops the queue again, so a transmit can reach the rings after they have
been freed.
Close is safe because dev_deactivate_many() stops the qdisc first.
bcmgenet_suspend() does not, so stop Tx NAPI before the queues on both
paths.
KASAN on a Raspberry Pi CM4, driven from an MTU change because suspend
freezes user space before the callback runs:
BUG: KASAN: use-after-free in bcmgenet_xmit+0x17f8/0x2258
Write of size 8 at addr ffffff8055844a68 by task ksoftirqd/0/14
bcmgenet_xmit+0x17f8/0x2258
dev_hard_start_xmit+0x13c/0x588
sch_direct_xmit+0x108/0x340
__dev_queue_xmit+0x1190/0x3848
Fixes: 254f3239dd07 ("net: bcmgenet: revise suspend/resume")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260922130639.1660797-1-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index b916080f4ff17..ca62041efecd7 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -3441,6 +3441,8 @@ static void bcmgenet_netif_stop(struct net_device *dev, bool stop_phy)
{
struct bcmgenet_priv *priv = netdev_priv(dev);
+ /* Stop completion polling before it can wake a stopped queue */
+ bcmgenet_disable_tx_napi(priv);
netif_tx_disable(dev);
/* Disable MAC receive */
@@ -3455,7 +3457,6 @@ static void bcmgenet_netif_stop(struct net_device *dev, bool stop_phy)
/* Disable MAC transmit. TX DMA disabled must be done before this */
umac_enable_set(priv, CMD_TX_EN, false);
- bcmgenet_disable_tx_napi(priv);
bcmgenet_disable_rx_napi(priv);
bcmgenet_intr_disable(priv);
@@ -4320,6 +4321,8 @@ static int bcmgenet_suspend(struct device *d)
netif_device_detach(dev);
if (device_may_wakeup(d) && priv->wolopts) {
+ /* Stop completion polling before it can wake a stopped queue */
+ bcmgenet_disable_tx_napi(priv);
netif_tx_disable(dev);
/* Suspend non-wake Rx data flows */
@@ -4348,7 +4351,6 @@ static int bcmgenet_suspend(struct device *d)
netdev_warn(priv->dev,
"Timed out while disabling TX DMA\n");
- bcmgenet_disable_tx_napi(priv);
bcmgenet_disable_rx_napi(priv);
disable_irq(priv->irq1);
bcmgenet_tx_reclaim_all(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 183/457] veth: manage XDP program pointers during channel resize
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 182/457] net: bcmgenet: stop Tx NAPI before disabling the queues Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 184/457] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
` (284 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Stanislav Fomichev,
Jiayuan Chen, Jason Xing, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 7104a370714346b667712913dc16abf14bbc97ed ]
veth_set_channels() tears down XDP resources for removed RX queues
without clearing rq->xdp_prog. If the program is then detached or
replaced, those queues keep the old pointer after bpf_prog_put().
A later channel increase can re-enable NAPI and run the freed program.
BUG: unable to handle page fault for address: ffffc90000256048
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: veth_xdp_rcv_skb (include/linux/filter.h:779
include/net/xdp.h:696 drivers/net/veth.c:820)
Call Trace:
veth_xdp_rcv (drivers/net/veth.c:941)
veth_poll (drivers/net/veth.c:986)
__napi_poll (net/core/dev.c:7787)
net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)
handle_softirqs (kernel/softirq.c:645)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: 4752eeb3d891 ("veth: implement support for set_channel ethtool op")
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Jason Xing <kerneljasonxing@gmail.com>
Link: https://patch.msgid.link/20260921231856.1798630-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/veth.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/veth.c b/drivers/net/veth.c
index 6ab84c837a332..2780b2dd073d1 100644
--- a/drivers/net/veth.c
+++ b/drivers/net/veth.c
@@ -1053,6 +1053,7 @@ static int __veth_napi_enable_range(struct net_device *dev, int start, int end)
for (i = start; i < end; i++) {
struct veth_rq *rq = &priv->rq[i];
+ rcu_assign_pointer(rq->xdp_prog, priv->_xdp_prog);
napi_enable(&rq->xdp_napi);
rcu_assign_pointer(priv->rq[i].napi, &priv->rq[i].xdp_napi);
}
@@ -1087,6 +1088,7 @@ static void veth_napi_del_range(struct net_device *dev, int start, int end)
rcu_assign_pointer(priv->rq[i].napi, NULL);
napi_disable(&rq->xdp_napi);
+ rcu_assign_pointer(rq->xdp_prog, NULL);
__netif_napi_del(&rq->xdp_napi);
}
synchronize_net();
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 184/457] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 183/457] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 185/457] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
` (283 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Shihuang Liu,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shihuang Liu <shlomojune6@gmail.com>
[ Upstream commit 3b4e0b0c008a8c1b474730248cd5b873026c74bd ]
skb_maybe_pull_tail() subtracts skb_headlen(skb) from the unsigned max
argument and passes the result to __pskb_pull_tail() as a signed int. The
function does not ensure that max is at least skb_headlen(skb).
This can happen while parsing IPv6 extension headers when an skb already
has a linear area larger than MAX_IPV6_HDR_LEN. Once the parser needs data
beyond the linear area, max - skb_headlen(skb) wraps and is converted to a
negative delta. __pskb_pull_tail() then passes that negative length to
skb_copy_bits(), where it can become a very large copy length.
Pass the requested length itself as the pull bound at the three
extension-header call sites, so the delta can no longer go negative.
Fixes: 1431fb31ecba ("xen-netback: fix fragment detection in checksum setup")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Shihuang Liu <shlomojune6@gmail.com>
Link: https://patch.msgid.link/20260919133604.50948-1-shlomojune6@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skbuff.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index c485be081aeaa..89ee7907e4996 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -5965,7 +5965,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct ipv6_opt_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct ipv6_opt_hdr));
if (err < 0)
goto out;
@@ -5980,7 +5981,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct ip_auth_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct ip_auth_hdr));
if (err < 0)
goto out;
@@ -5995,7 +5997,8 @@ static int skb_checksum_setup_ipv6(struct sk_buff *skb, bool recalculate)
err = skb_maybe_pull_tail(skb,
off +
sizeof(struct frag_hdr),
- MAX_IPV6_HDR_LEN);
+ off +
+ sizeof(struct frag_hdr));
if (err < 0)
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 185/457] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 184/457] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 186/457] net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP Greg Kroah-Hartman
` (282 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefano Sasso, Ido Schimmel,
David Ahern, Eric Dumazet, Andrea Mayer, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit ab7aa05c06ae340e5c7530bb78fa8d23794e460b ]
The VRF device is an Ethernet device but it can have non-Ethernet ports
such as IP tunnels. Before the cited commit, capturing packets from such
ports on the VRF device resulted in these packets being detected as
malformed since they lack an Ethernet header.
The cited commit fixed it by pushing a dummy Ethernet header to such
packets before the capture and pulling it afterwards. In the case of
CHECKSUM_COMPLETE packets it also updated skb->csum with the checksum of
the dummy Ethernet header. This is wrong as skb->csum should not include
the checksum of the Ethernet header ("checksum of the _whole_ packet as
seen by netif_rx()").
This also means that L4 protocols receive a corrupted skb->csum and
potentially drop the packet, as is the case with UDP packets whose
checksum was completed by software.
Fix by removing the unnecessary call to skb_postpush_rcsum().
Fixes: 048939088220 ("vrf: add mac header for tunneled packets when sniffer is attached")
Reported-by: Stefano Sasso <stesasso@gmail.com>
Closes: https://lore.kernel.org/netdev/CALtE316UtL3x7LL6uxfXzx8rW6AbzYPeDOb478hqJCr_-dj=Wg@mail.gmail.com/
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Link: https://patch.msgid.link/20260922131239.2509494-1-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vrf.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/vrf.c b/drivers/net/vrf.c
index 46209917ae4d6..bae0b69cf894c 100644
--- a/drivers/net/vrf.c
+++ b/drivers/net/vrf.c
@@ -1175,8 +1175,6 @@ static int vrf_prepare_mac_header(struct sk_buff *skb,
skb->protocol = eth->h_proto;
skb->pkt_type = PACKET_HOST;
- skb_postpush_rcsum(skb, skb->data, ETH_HLEN);
-
skb_pull_inline(skb, ETH_HLEN);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 186/457] net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 185/457] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 187/457] net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection Greg Kroah-Hartman
` (281 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrew Lunn, Nicolo Giuliani,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolo Giuliani <nicolo.giuliani6@studio.unibo.it>
[ Upstream commit 6b491af01aa5c0633a580e3b11bc7277adc903b2 ]
The 88E6191X and 88E6193X are 6393 family devices that share
mv88e6393x_ops with the 88E6393X and are marked as ptp_support. Marvell's
UMSD driver describes both as parts without AVB (88E6193X: "BGA package -
No AVB, No Routing, No Cut-through"), and the register access confirms it
on an 88E6193X: the whole indirect AVB register space behind Global 2
registers 0x16 and 0x17 reads zero, for every port, block and address,
with the 6390 and with the 6352 command encoding. Writes to the TAI
registers, including the clock period register and the TAI global
configuration register, read back as zero.
Since commit 7e3c18097a70 ("net: dsa: mv88e6xxx: read cycle counter
period from hardware") the PTP setup reads the TAI clock period, so the
switch fails to probe:
mv88e6xxx ...: unexpected cycle counter period of 0 ps
Add mv88e6191x_ops, a copy of mv88e6393x_ops without avb_ops and ptp_ops,
use it for the 88E6191X and the 88E6193X and stop setting ptp_support for
them. The 88E6393X is unchanged.
Tested on an 88E6193X (Sophos XGS 107w): the switch probes and the ports
work. I do not have an 88E6191X, it is changed because UMSD describes it
the same way.
Fixes: de776d0d316f ("net: dsa: mv88e6xxx: add support for mv88e6393x family")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Nicolo Giuliani <nicolo.giuliani6@studio.unibo.it>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260921-send-net-v2-1-031ad720f140@studio.unibo.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mv88e6xxx/chip.c | 68 ++++++++++++++++++++++++++++++--
1 file changed, 64 insertions(+), 4 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 7f68a0c558026..a4a8c7e11bf4f 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -5639,6 +5639,68 @@ static const struct mv88e6xxx_ops mv88e6390x_ops = {
.pcs_ops = &mv88e6390_pcs_ops,
};
+static const struct mv88e6xxx_ops mv88e6191x_ops = {
+ /* MV88E6XXX_FAMILY_6393 without AVB and PTP: 6191X and 6193X */
+ .irl_init_all = mv88e6390_g2_irl_init_all,
+ .get_eeprom = mv88e6xxx_g2_get_eeprom8,
+ .set_eeprom = mv88e6xxx_g2_set_eeprom8,
+ .set_switch_mac = mv88e6xxx_g2_set_switch_mac,
+ .phy_read = mv88e6xxx_g2_smi_phy_read_c22,
+ .phy_write = mv88e6xxx_g2_smi_phy_write_c22,
+ .phy_read_c45 = mv88e6xxx_g2_smi_phy_read_c45,
+ .phy_write_c45 = mv88e6xxx_g2_smi_phy_write_c45,
+ .port_set_link = mv88e6xxx_port_set_link,
+ .port_sync_link = mv88e6xxx_port_sync_link,
+ .port_set_rgmii_delay = mv88e6390_port_set_rgmii_delay,
+ .port_set_speed_duplex = mv88e6393x_port_set_speed_duplex,
+ .port_tag_remap = mv88e6390_port_tag_remap,
+ .port_set_policy = mv88e6393x_port_set_policy,
+ .port_set_frame_mode = mv88e6351_port_set_frame_mode,
+ .port_set_ucast_flood = mv88e6352_port_set_ucast_flood,
+ .port_set_mcast_flood = mv88e6352_port_set_mcast_flood,
+ .port_set_ether_type = mv88e6393x_port_set_ether_type,
+ .port_set_jumbo_size = mv88e6165_port_set_jumbo_size,
+ .port_egress_rate_limiting = mv88e6097_port_egress_rate_limiting,
+ .port_pause_limit = mv88e6390_port_pause_limit,
+ .port_disable_learn_limit = mv88e6xxx_port_disable_learn_limit,
+ .port_disable_pri_override = mv88e6xxx_port_disable_pri_override,
+ .port_get_cmode = mv88e6352_port_get_cmode,
+ .port_set_cmode = mv88e6393x_port_set_cmode,
+ .port_setup_message_port = mv88e6xxx_setup_message_port,
+ .port_set_upstream_port = mv88e6393x_port_set_upstream_port,
+ .port_enable_tcam = mv88e6xxx_port_enable_tcam,
+ .stats_snapshot = mv88e6390_g1_stats_snapshot,
+ .stats_set_histogram = mv88e6390_g1_stats_set_histogram,
+ .stats_get_sset_count = mv88e6320_stats_get_sset_count,
+ .stats_get_strings = mv88e6320_stats_get_strings,
+ .stats_get_stat = mv88e6390_stats_get_stat,
+ /* .set_cpu_port is missing because this family does not support a global
+ * CPU port, only per port CPU port which is set via
+ * .port_set_upstream_port method.
+ */
+ .set_egress_port = mv88e6393x_set_egress_port,
+ .watchdog_ops = &mv88e6393x_watchdog_ops,
+ .mgmt_rsvd2cpu = mv88e6393x_port_mgmt_rsvd2cpu,
+ .pot_clear = mv88e6xxx_g2_pot_clear,
+ .hardware_reset_pre = mv88e6xxx_g2_eeprom_wait,
+ .hardware_reset_post = mv88e6xxx_g2_eeprom_wait,
+ .reset = mv88e6352_g1_reset,
+ .rmu_disable = mv88e6390_g1_rmu_disable,
+ .atu_get_hash = mv88e6165_g1_atu_get_hash,
+ .atu_set_hash = mv88e6165_g1_atu_set_hash,
+ .vtu_getnext = mv88e6390_g1_vtu_getnext,
+ .vtu_loadpurge = mv88e6390_g1_vtu_loadpurge,
+ .stu_getnext = mv88e6390_g1_stu_getnext,
+ .stu_loadpurge = mv88e6390_g1_stu_loadpurge,
+ .serdes_get_lane = mv88e6393x_serdes_get_lane,
+ .serdes_irq_mapping = mv88e6390_serdes_irq_mapping,
+ /* TODO: serdes stats */
+ .gpio_ops = &mv88e6352_gpio_ops,
+ .phylink_get_caps = mv88e6393x_phylink_get_caps,
+ .pcs_ops = &mv88e6393x_pcs_ops,
+ .tcam_ops = &mv88e6393_tcam_ops,
+};
+
static const struct mv88e6xxx_ops mv88e6393x_ops = {
/* MV88E6XXX_FAMILY_6393 */
.irl_init_all = mv88e6390_g2_irl_init_all,
@@ -6163,8 +6225,7 @@ static const struct mv88e6xxx_info mv88e6xxx_table[] = {
.atu_move_port_mask = 0x1f,
.pvt = true,
.multi_chip = true,
- .ptp_support = true,
- .ops = &mv88e6393x_ops,
+ .ops = &mv88e6191x_ops,
},
[MV88E6193X] = {
@@ -6190,8 +6251,7 @@ static const struct mv88e6xxx_info mv88e6xxx_table[] = {
.atu_move_port_mask = 0x1f,
.pvt = true,
.multi_chip = true,
- .ptp_support = true,
- .ops = &mv88e6393x_ops,
+ .ops = &mv88e6191x_ops,
},
[MV88E6220] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 187/457] net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 186/457] net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 188/457] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
` (280 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jonas Jelonek, Markus Stockhausen,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonas Jelonek <jonas@jonasjelonek.de>
[ Upstream commit 89a8a1eef2d441b7825a6c0116ce817235a7ffe6 ]
The RTL931x indirect access engine has a separate nine-bit extended page
field. The driver leaves it at zero, and otto_emdio_run_cmd() therefore
programs extended page zero for every Clause 22 transaction. This
overrides page selection made through PHY register 30, causing accesses
to private PHY pages to hit extended page zero instead.
Set the field to its 0x1ff "do not change" value for RTL931x Clause 22
reads and writes. This preserves extended page selection made through
PHY register 30 and restores access to its private register pages.
Fixes: 5ebdcac59aff ("net: mdio: realtek-rtl9300: Add support for RTL931x")
Signed-off-by: Jonas Jelonek <jonas@jonasjelonek.de>
Acked-by: Markus Stockhausen <markus.stockhausen@gmx.de>
Link: https://patch.msgid.link/20260918211955.3955777-1-jonas@jonasjelonek.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/mdio/mdio-realtek-rtl9300.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/mdio/mdio-realtek-rtl9300.c b/drivers/net/mdio/mdio-realtek-rtl9300.c
index afd52a1cd7f83..9ce2b78075320 100644
--- a/drivers/net/mdio/mdio-realtek-rtl9300.c
+++ b/drivers/net/mdio/mdio-realtek-rtl9300.c
@@ -88,6 +88,8 @@
#define RTL9310_SMI_INDRT_ACCESS_BC_PHYID_CTRL 0x0c14
#define RTL9310_BC_PORT_ID GENMASK(10, 5)
#define RTL9310_SMI_INDRT_ACCESS_CTRL_1 0x0c04
+#define RTL9310_SMI_INDRT_EXT_PAGE GENMASK(8, 0)
+#define RTL9310_SMI_INDRT_EXT_PAGE_NO_CHANGE 0x1ff
#define RTL9310_SMI_INDRT_ACCESS_CTRL_2_LOW 0x0c08
#define RTL9310_SMI_INDRT_ACCESS_CTRL_2_HIGH 0x0c0c
#define RTL9310_SMI_INDRT_ACCESS_CTRL_3 0x0c10 /* I/O fields flipped */
@@ -325,6 +327,8 @@ static int otto_emdio_9310_read_c22(struct mii_bus *bus, int port, int regnum, u
.broadcast = FIELD_PREP(RTL9310_BC_PORT_ID, port),
.c22_data = FIELD_PREP(RTL9310_PHY_CTRL_REG_ADDR, regnum) |
FIELD_PREP(RTL9310_PHY_CTRL_MAIN_PAGE, RAW_PAGE(priv)),
+ .ext_page = FIELD_PREP(RTL9310_SMI_INDRT_EXT_PAGE,
+ RTL9310_SMI_INDRT_EXT_PAGE_NO_CHANGE),
};
return otto_emdio_read_cmd(bus, RTL9310_PHY_CTRL_TYPE_C22, &cmd_data,
@@ -337,6 +341,8 @@ static int otto_emdio_9310_write_c22(struct mii_bus *bus, int port, int regnum,
struct otto_emdio_cmd_regs cmd_data = {
.c22_data = FIELD_PREP(RTL9310_PHY_CTRL_REG_ADDR, regnum) |
FIELD_PREP(RTL9310_PHY_CTRL_MAIN_PAGE, RAW_PAGE(priv)),
+ .ext_page = FIELD_PREP(RTL9310_SMI_INDRT_EXT_PAGE,
+ RTL9310_SMI_INDRT_EXT_PAGE_NO_CHANGE),
.io_data = FIELD_PREP(RTL9310_PHY_CTRL_INDATA, value),
.port_mask_high = (u32)(BIT_ULL(port) >> 32),
.port_mask_low = (u32)(BIT_ULL(port)),
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 188/457] bpf: Fix immediate JMP JEQ/JNE on MIPS32
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 187/457] net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 189/457] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
` (279 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Almbladh, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Almbladh <johan.almbladh@anyfinetworks.com>
[ Upstream commit db762fd96be225bd06161c9631160c755d891693 ]
An addu instruction was emitted instead of addiu, causing the immediate
value 1 to be interpreted as register $at. This made the comparison
result invalid when the immediate operand was negative. Note that $at
is mapped to BPF_REG_AX, which is used for constant blinding.
Fix the instruction to use the immediate form.
Found with test_bpf on MIPS32r1 emulated by QEMU.
Fixes: eb63cfcd2ee8 ("mips, bpf: Add eBPF JIT for 32-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-1-johan.almbladh@anyfinetworks.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/net/bpf_jit_comp32.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/mips/net/bpf_jit_comp32.c b/arch/mips/net/bpf_jit_comp32.c
index 40a878b672f5d..15a2a153dc873 100644
--- a/arch/mips/net/bpf_jit_comp32.c
+++ b/arch/mips/net/bpf_jit_comp32.c
@@ -1111,7 +1111,7 @@ static void emit_jmp_i64(struct jit_context *ctx,
emit(ctx, xor, tmp, lo(dst), tmp);
}
if (imm < 0) { /* Compare sign extension */
- emit(ctx, addu, MIPS_R_T9, hi(dst), 1);
+ emit(ctx, addiu, MIPS_R_T9, hi(dst), 1);
emit(ctx, or, tmp, tmp, MIPS_R_T9);
} else { /* Compare zero extension */
emit(ctx, or, tmp, tmp, hi(dst));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 189/457] bpf: Fix BSWAP 32 and 16 on MIPS64
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 188/457] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 190/457] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
` (278 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Almbladh, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Almbladh <johan.almbladh@anyfinetworks.com>
[ Upstream commit 8110ba09777873443db286b3cbb89b0e6311c554 ]
The 16/32-bit byteswap implementations for MIPS64r1 and earlier do
not have an explicit zero extension afterwards. The input is first
sign-extended to 64 bits, and the byteswap sequence can then leave
the result sign-extended depending on the value of the low bits.
Add the missing zero-extension.
Found with test_bpf on MIPS64r1 emulated by QEMU.
Fixes: fbc802de6b10 ("mips, bpf: Add new eBPF JIT for 64-bit MIPS")
Signed-off-by: Johan Almbladh <johan.almbladh@anyfinetworks.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260923105158.3514342-2-johan.almbladh@anyfinetworks.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/net/bpf_jit_comp64.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/arch/mips/net/bpf_jit_comp64.c b/arch/mips/net/bpf_jit_comp64.c
index fa7e9aa37f498..6681ccac9dd9e 100644
--- a/arch/mips/net/bpf_jit_comp64.c
+++ b/arch/mips/net/bpf_jit_comp64.c
@@ -305,8 +305,7 @@ static void emit_bswap_r64(struct jit_context *ctx, u8 dst, u32 width)
case 16:
emit_sext(ctx, dst, dst);
emit_bswap_r(ctx, dst, width);
- if (cpu_has_mips64r2 || cpu_has_mips64r6)
- emit_zext(ctx, dst);
+ emit_zext(ctx, dst);
break;
}
clobber_reg(ctx, dst);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 190/457] tg3: use random MAC address when tg3_get_device_address fails
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 189/457] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 191/457] net: stmmac: clear stale buf->page after recycling on skb build failure Greg Kroah-Hartman
` (277 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Ivan Delalande,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivan Delalande <colona@arista.com>
[ Upstream commit 4eb3f195ef08c5acaed87958297e41cc49588dde ]
Some of the tg3 NICs we use (BCM57762) reset the SRAM MAC address to the
placeholder address on link flaps, tg3_chip_reset, etc. We've typically
fixed it from userspace, but since e4c00ba7274b ("tg3: replace
placeholder MAC address with device property") was merged, tg3 just
fails probe as we don't have a way to get it through the generic
device_get_mac_address infrastructure as fallback on our systems.
Make the driver assign a random address in this condition instead of
being fatal for probe. Set deferred_probe_reason through dev_warn_probe
if the address isn't yet available from the provider.
Fixes: e4c00ba7274b ("tg3: replace placeholder MAC address with device property")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Link: https://lore.kernel.org/netdev/20260909191751.651aa5c4@kernel.org/
Signed-off-by: Ivan Delalande <colona@arista.com>
Link: https://patch.msgid.link/20260918224715.GA654128@visor
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/tg3.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/tg3.c b/drivers/net/ethernet/broadcom/tg3.c
index caa7a6caa6e2f..8b6806a79edff 100644
--- a/drivers/net/ethernet/broadcom/tg3.c
+++ b/drivers/net/ethernet/broadcom/tg3.c
@@ -17915,11 +17915,14 @@ static int tg3_init_one(struct pci_dev *pdev,
err = tg3_get_device_address(tp, addr);
if (err) {
- dev_err(&pdev->dev,
- "Could not obtain valid ethernet address, aborting\n");
- goto err_out_apeunmap;
+ dev_warn_probe(&pdev->dev, err,
+ "Could not obtain a valid ethernet address\n");
+ if (err == -EPROBE_DEFER)
+ goto err_out_apeunmap;
+ eth_hw_addr_random(dev);
+ } else {
+ eth_hw_addr_set(dev, addr);
}
- eth_hw_addr_set(dev, addr);
intmbx = MAILBOX_INTERRUPT_0 + TG3_64BIT_REG_LOW;
rcvmbx = MAILBOX_RCVRET_CON_IDX_0 + TG3_64BIT_REG_LOW;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 191/457] net: stmmac: clear stale buf->page after recycling on skb build failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 190/457] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 192/457] net: ipv6: keep room for the mac header in dst_dev_overhead() Greg Kroah-Hartman
` (276 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 0a7822e34a0bfde31b194ac3da3253e5032b44cc ]
In stmmac_rx(), when napi_build_skb() fails the descriptor page is
recycled back to the page pool with page_pool_recycle_direct(), but
buf->page is left pointing at the recycled page, unlike every other
consumption site in the function which clears the pointer after handing
the page away.
With the stale pointer stmmac_rx_refill() skips the replacement
allocation and programs the already-recycled page back into the RX
descriptor.
Clear buf->page on the napi_build_skb() failure path to keep the buffer
lifecycle consistent with the other consumption sites.
Fixes: df542f669307 ("net: stmmac: Switch to zero-copy in non-XDP RX path")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260921-stmmac-fix-napi-build-skb-error-v1-1-3d54bf6d9bb6@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index 9c4d92a19f2c0..29025eb416987 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -5885,6 +5885,7 @@ static int stmmac_rx(struct stmmac_priv *priv, int limit, u32 queue)
if (!skb) {
page_pool_recycle_direct(rx_q->page_pool,
buf->page);
+ buf->page = NULL;
rx_dropped++;
count++;
goto drain_data;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 192/457] net: ipv6: keep room for the mac header in dst_dev_overhead()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 191/457] net: stmmac: clear stale buf->page after recycling on skb build failure Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 193/457] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
` (275 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Mayer, Yuya Kusakabe,
Justin Iurman, Gabriel Goller, Eric Dumazet, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuya Kusakabe <yuya.kusakabe@gmail.com>
[ Upstream commit 87cd6b717e4069dca34e0866e57eaeb44d3b173e ]
The seg6, ioam6 and rpl lwtunnels size their skb_cow_head() request as
the length they are about to push plus dst_dev_overhead(), then push the
new headers and rebuild the mac header below them with
skb_mac_header_rebuild(). That rebuild needs skb->mac_len of headroom,
but dst_dev_overhead() leaves LL_RESERVED_SPACE() of the egress device,
16 bytes for plain Ethernet.
Where the mac header is longer than that, as it is on ingress through a
VLAN device with reorder_hdr off, the rebuild runs out of room:
skb_set_mac_header(skb, -skb->mac_len) computes a negative offset,
stores it unchecked in the u16 skb->mac_header, and the memmove that
follows writes skb->mac_len bytes about 64 KB past skb->head.
Forwarding plain ping6 traffic through such a device reproduces it on
all five seg6 encapsulation modes and on the rpl and ioam6 inline paths;
skb->mac_header comes back as 65534 on a 704-byte head.
Return the larger of the two. The helper already returns skb->mac_len
when it has no dst, so this only makes the other branch agree, and it
covers every caller rather than each call site in turn.
Fixes: 40475b63761a ("net: ipv6: seg6_iptunnel: mitigate 2-realloc issue")
Fixes: dce525185bc9 ("net: ipv6: ioam6_iptunnel: mitigate 2-realloc issue")
Fixes: 985ec6f5e623 ("net: ipv6: rpl_iptunnel: mitigate 2-realloc issue")
Suggested-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Signed-off-by: Yuya Kusakabe <yuya.kusakabe@gmail.com>
Reviewed-by: Justin Iurman <justin.iurman@gmail.com>
Reviewed-by: Gabriel Goller <g.goller@proxmox.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Link: https://patch.msgid.link/20260922-seg6-maclen-headroom-v3-1-7b2f982ef79d@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/dst.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/include/net/dst.h b/include/net/dst.h
index 307073eae7f83..dbedfe72e1fd1 100644
--- a/include/net/dst.h
+++ b/include/net/dst.h
@@ -455,7 +455,8 @@ static inline unsigned int dst_dev_overhead(struct dst_entry *dst,
struct sk_buff *skb)
{
if (likely(dst))
- return LL_RESERVED_SPACE(dst->dev);
+ return max_t(unsigned int, skb->mac_len,
+ LL_RESERVED_SPACE(dst->dev));
return skb->mac_len;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 193/457] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 192/457] net: ipv6: keep room for the mac header in dst_dev_overhead() Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 194/457] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
` (274 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 0e2bec77ea62895416600c90588f593516572bca ]
When bcmgenet was converted to 64-bit statistics, STAT_RTNL members were
switched to point into struct rtnl_link_stats64, whose fields are 64-bit
(__u64) regardless of architecture.
However, bcmgenet_get_ethtool_stats() retained a legacy check:
if (sizeof(unsigned long) != sizeof(u32) &&
s->stat_sizeof == sizeof(unsigned long))
On 32-bit systems, sizeof(unsigned long) == sizeof(u32), causing this
condition to evaluate to false. As a result, 64-bit RTNL stats fields were
read via *(u32 *)p. On 32-bit Big-Endian systems (such as MIPS BE), this
reads the high 32 bits and returns 0 until the counter exceeds 4GB; on
32-bit Little-Endian systems (such as 32-bit ARM), the value is truncated
to 32 bits.
Fix this by checking if s->stat_sizeof == sizeof(u64) so 64-bit fields are
always read as 64-bit values.
Fixes: 59aa6e3072aa ("net: bcmgenet: switch to use 64bit statistics")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-2-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index ca62041efecd7..47a6c073c8d94 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -1346,9 +1346,8 @@ static void bcmgenet_get_ethtool_stats(struct net_device *dev,
p = (char *)&stats64;
p += s->stat_offset;
- if (sizeof(unsigned long) != sizeof(u32) &&
- s->stat_sizeof == sizeof(unsigned long))
- data[i] = *(unsigned long *)p;
+ if (s->stat_sizeof == sizeof(u64))
+ data[i] = *(u64 *)p;
else
data[i] = *(u32 *)p;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 194/457] net: bcmgenet: initialize u64 stats seq counter for all queues
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 193/457] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
@ 2026-09-30 15:24 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 195/457] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
` (273 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 3aeaa609fda19c09d5298c9fedaaa3b6229601b5 ]
bcmgenet_gstrings_stats statically defines ethtool statistics for queues
0 through GENET_MAX_MQ_CNT (4). However, bcmgenet_probe() only initialized
the u64_stats_sync seq counter up to priv->hw_params->rx_queues and
priv->hw_params->tx_queues.
Since priv->hw_params->rx_queues is 0 across all hardware versions (and
priv->hw_params->tx_queues is 0 on GENET V1), rings 1..4 have uninitialized
u64_stats_sync structures. When ethtool -S is run on 32-bit kernels,
bcmgenet_get_ethtool_stats() reads stats from rx_rings[1..4], causing
lockdep warnings due to the uninitialized sequence counters.
Initialize the sequence counters for all GENET_MAX_MQ_CNT + 1 queues.
Fixes: ffc2c8c4a714 ("net: bcmgenet: Initialize u64 stats seq counter")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-3-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 47a6c073c8d94..2ab37bb031ed2 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -4135,10 +4135,10 @@ static int bcmgenet_probe(struct platform_device *pdev)
priv->rx_rings[i].rx_max_coalesced_frames = 1;
/* Initialize u64 stats seq counter for 32bit machines */
- for (i = 0; i <= priv->hw_params->rx_queues; i++)
+ for (i = 0; i <= GENET_MAX_MQ_CNT; i++) {
u64_stats_init(&priv->rx_rings[i].stats64.syncp);
- for (i = 0; i <= priv->hw_params->tx_queues; i++)
u64_stats_init(&priv->tx_rings[i].stats64.syncp);
+ }
/* libphy will determine the link state */
netif_carrier_off(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 195/457] net: bcmgenet: do not skip WoL power up on GENET V1
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-09-30 15:24 ` [PATCH 7.2 194/457] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 196/457] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
` (272 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit cbbc1aee7776c7fa1d89e6cb963a23e58c495dca ]
bcmgenet_power_up() had an early check for bcmgenet_has_ext(priv) before
dispatching by power mode. GENET V1 does not have the EXT block (unlike
GENET V2+), which causes bcmgenet_power_up() to immediately return 0.
As a consequence, when waking up from GENET_POWER_WOL_MAGIC on GENET V1,
bcmgenet_wol_power_up_cfg() is never invoked to disable the WoL clock,
clear wake event masks, and restore normal PHY and MAC operations.
Move the bcmgenet_has_ext() checks to the GENET_POWER_PASSIVE and
GENET_POWER_CABLE_SENSE cases where the EXT registers are actually
accessed, allowing GENET_POWER_WOL_MAGIC cleanup to execute on all
hardware versions.
Fixes: c3ae64ae0c08 ("net: bcmgenet: handle GENET_POWER_WOL_MAGIC")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-4-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 2ab37bb031ed2..07032e4193ea1 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -1762,13 +1762,12 @@ static int bcmgenet_power_up(struct bcmgenet_priv *priv,
int ret = 0;
u32 reg;
- if (!bcmgenet_has_ext(priv))
- return ret;
-
- reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
-
switch (mode) {
case GENET_POWER_PASSIVE:
+ if (!bcmgenet_has_ext(priv))
+ break;
+
+ reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
reg &= ~(EXT_PWR_DOWN_DLL | EXT_PWR_DOWN_BIAS |
EXT_ENERGY_DET_MASK);
if (GENET_IS_V5(priv) && !bcmgenet_has_ephy_16nm(priv)) {
@@ -1792,8 +1791,12 @@ static int bcmgenet_power_up(struct bcmgenet_priv *priv,
break;
case GENET_POWER_CABLE_SENSE:
+ if (!bcmgenet_has_ext(priv))
+ break;
+
/* enable APD */
if (!GENET_IS_V5(priv)) {
+ reg = bcmgenet_ext_readl(priv, EXT_EXT_PWR_MGMT);
reg |= EXT_PWR_DN_EN_LD;
bcmgenet_ext_writel(priv, reg, EXT_EXT_PWR_MGMT);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 196/457] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 195/457] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 197/457] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
` (271 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit 273941c85fc2632cd3e56ddff737b9245de7697d ]
bcmgenet_set_mac_addr() did not check whether the provided MAC address is a
valid Ethernet address before applying it. Userspace could configure an
invalid address (such as all zeroes or a multicast address) while the
interface is down.
Add a call to is_valid_ether_addr() and return -EADDRNOTAVAIL if the MAC
address is not valid.
Fixes: 1c1008c793fa ("net: bcmgenet: add main driver file")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-5-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 07032e4193ea1..011376a1678a1 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -3635,6 +3635,9 @@ static int bcmgenet_set_mac_addr(struct net_device *dev, void *p)
if (netif_running(dev))
return -EBUSY;
+ if (!is_valid_ether_addr(addr->sa_data))
+ return -EADDRNOTAVAIL;
+
eth_hw_addr_set(dev, addr->sa_data);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 197/457] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 196/457] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 198/457] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
` (270 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Florian Fainelli,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Fainelli <florian.fainelli@broadcom.com>
[ Upstream commit d64e277b955be4506931802837499b62c8f3968a ]
bcmgenet_get_coalesce() reads DMA_RING0_TIMEOUT to calculate
rx_coalesce_usecs without masking out bits outside DMA_TIMEOUT_MASK
(16 bits). If upper bits are non-zero or contain status/flags, the
computed value of rx_coalesce_usecs returned to userspace via ethtool
becomes corrupted.
Mask the register read with DMA_TIMEOUT_MASK before computing the
timeout in microseconds.
Fixes: 4a29645bfe6c ("net: bcmgenet: Implement RX coalescing control knobs")
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260921220021.281418-6-florian.fainelli@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 011376a1678a1..21668e41b6964 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -852,7 +852,8 @@ static int bcmgenet_get_coalesce(struct net_device *dev,
ec->rx_max_coalesced_frames =
bcmgenet_rdma_ring_readl(priv, 0, DMA_MBUF_DONE_THRESH);
ec->rx_coalesce_usecs =
- bcmgenet_rdma_readl(priv, DMA_RING0_TIMEOUT) * 8192 / 1000;
+ (bcmgenet_rdma_readl(priv, DMA_RING0_TIMEOUT) &
+ DMA_TIMEOUT_MASK) * 8192 / 1000;
for (i = 0; i <= priv->hw_params->rx_queues; i++) {
ring = &priv->rx_rings[i];
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 198/457] ip_gre: Reject enabling collect metadata through changelink
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 197/457] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 199/457] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
` (269 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Ido Schimmel,
Hangbin Liu, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
[ Upstream commit a3f315be9d30eeb6938d11fa17fd4b32d52f7c42 ]
ipgre_netlink_parms() can enable collect_md on an existing GRE, GRETAP
or ERSPAN device. Unlike newlink, changelink does not enforce metadata
tunnel uniqueness. Converting a non-metadata device can therefore
replace the metadata receive entry for another device of the same type
in the same netns. Deleting either device then clears the shared entry,
breaking metadata receive lookup for the surviving device.
If parameter validation fails after collect_md is set, deleting the
modified device can also clear an entry it never owned.
Reject enabling metadata mode in both changelink callbacks before any
encapsulation or tunnel parameters are modified. Allow requests that
repeat the metadata attribute on an existing metadata device.
Fixes: 2e15ea390e6f ("ip_gre: Add support to collect tunnel metadata.")
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260921031859.9283-1-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/ip_gre.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c
index 0ba1e94e9012c..384c02b9700b8 100644
--- a/net/ipv4/ip_gre.c
+++ b/net/ipv4/ip_gre.c
@@ -1460,6 +1460,12 @@ static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[],
if (!rtnl_dev_link_net_capable(dev, t->net))
return -EPERM;
+ if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) {
+ NL_SET_ERR_MSG(extack,
+ "Enabling collect_md on an existing device is not supported");
+ return -EOPNOTSUPP;
+ }
+
err = ipgre_newlink_encap_setup(dev, data);
if (err)
return err;
@@ -1492,6 +1498,12 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[],
if (!rtnl_dev_link_net_capable(dev, t->net))
return -EPERM;
+ if (data && data[IFLA_GRE_COLLECT_METADATA] && !t->collect_md) {
+ NL_SET_ERR_MSG(extack,
+ "Enabling collect_md on an existing device is not supported");
+ return -EOPNOTSUPP;
+ }
+
err = ipgre_newlink_encap_setup(dev, data);
if (err)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 199/457] vxlan: use one headroom snapshot for neighbour replies
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 198/457] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 200/457] net: xps: reject an out of range traffic class Greg Kroah-Hartman
` (268 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanghyun Park, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanghyun Park <sanghyun.park.cnu@gmail.com>
[ Upstream commit 481506a756dcd828ef42391cb08f38d8d96d38fc ]
vxlan_na_create() samples LL_RESERVED_SPACE() to size the reply skb and then
samples it again to reserve headroom. A concurrent vxlan_changelink() can
update needed_headroom between the two reads, creating a TOCTOU race. The
second value can exceed the allocation and make the Ethernet header write out
of bounds.
The race is reproducible on the unpatched kernel. It occurred when
vxlan_na_create() generated a neighbour reply while vxlan_changelink() changed
the link headroom. KASAN caught a four-byte write two bytes beyond a 704-byte
skbuff_small_head allocation.
Snapshot the headroom once and use that value for both allocation and
reservation.
Fixes: 4b29dba9c085 ("vxlan: fix nonfunctional neigh_reduce()")
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
Link: https://patch.msgid.link/20260918032842.502409-2-sanghyun.park.cnu@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/vxlan/vxlan_core.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index e045e1ee9e594..c4bcaadba471d 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -1958,13 +1958,15 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
struct ipv6hdr *pip6;
u8 *daddr;
int na_olen = 8; /* opt hdr + ETH_ALEN for target */
+ int headroom;
int ns_olen;
int i, len;
if (dev == NULL || !pskb_may_pull(request, request->len))
return NULL;
- len = LL_RESERVED_SPACE(dev) + sizeof(struct ipv6hdr) +
+ headroom = LL_RESERVED_SPACE(dev);
+ len = headroom + sizeof(struct ipv6hdr) +
sizeof(*na) + na_olen + dev->needed_tailroom;
reply = alloc_skb(len, GFP_ATOMIC);
if (reply == NULL)
@@ -1972,7 +1974,7 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
reply->protocol = htons(ETH_P_IPV6);
reply->dev = dev;
- skb_reserve(reply, LL_RESERVED_SPACE(request->dev));
+ skb_reserve(reply, headroom);
skb_push(reply, sizeof(struct ethhdr));
skb_reset_mac_header(reply);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 200/457] net: xps: reject an out of range traffic class
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 199/457] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 201/457] drm/imagination: clamp freelist reconstruction requests Greg Kroah-Hartman
` (267 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
[ Upstream commit 4da3b7b8b50f3e2fde54a4c18a82a8e3f6223910 ]
Only the entries below dev->num_tc are valid in dev->tc_to_txq[], and
dev->prio_tc_map[] may only name classes below it. netdev_set_num_tc()
lowers dev->num_tc without touching either array.
netdev_txq_to_tc() walks all TC_MAX_QUEUE slots and
netdev_get_prio_tc_map() returns the entry as it stands, so a leftover
entry is handed out as a traffic class >= dev->num_tc. Taking that
class from netdev_txq_to_tc(), __netif_set_xps_queue() rejects only a
negative one and indexes an XPS map sized for dev->num_tc classes:
tci = j * num_tc + tc;
RCU_INIT_POINTER(new_dev_maps->attr_map[tci], map);
attr_map[] holds nr_ids * num_tc entries and j runs over the ids named
in the mask, so a class that is not below num_tc pushes tci past the end
of the map for the last ids and the store overruns it.
Any caller that lowers num_tc leaves such entries behind, and
mqprio_destroy() tears down with netdev_set_num_tc(dev, 0) rather than
netdev_reset_tc(). After mqprio with 8 classes then 1, tc_to_txq[1..7]
still describe txq 1..7. The splat is from an XPS write to txq 2 on a
veth with 8 rx queues: attr_map[] has 8 * 1 entries, tci = j + 2, and
j == 6 stores one past the end of the 88-byte map:
BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue (net/core/dev.c:2954)
Write of size 8 at addr ffff88813016bc58 by task xps_oob/634
__netif_set_xps_queue (net/core/dev.c:2954)
xps_rxqs_store (net/core/net-sysfs.c:1880)
netdev_queue_attr_store (net/core/net-sysfs.c:1390)
Allocated by task 634:
__kmalloc_noprof (mm/slub.c:5439)
__netif_set_xps_queue (net/core/dev.c:2937)
The buggy address is located 0 bytes to the right of
allocated 88-byte region [ffff88813016bc00, ffff88813016bc58)
Reject a class the map has no room for.
Fixes: 184c449f91fe ("net: Add support for XPS with QoS via traffic classes")
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/162DD16F-54C6-444A-9E09-0B8CB3D591F2@doyensec.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 65cdaf0c81f71..a48958a3f76c1 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -2897,7 +2897,7 @@ int __netif_set_xps_queue(struct net_device *dev, const unsigned long *mask,
dev = netdev_get_tx_queue(dev, index)->sb_dev ? : dev;
tc = netdev_txq_to_tc(dev, index);
- if (tc < 0)
+ if (tc < 0 || tc >= num_tc)
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 201/457] drm/imagination: clamp freelist reconstruction requests
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 200/457] net: xps: reject an out of range traffic class Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 202/457] bonding: crypto offload enabled, non-offload slave failover, rekey failed Greg Kroah-Hartman
` (266 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Alessio Belle,
Brajesh Gupta, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <hppiscas@163.com>
[ Upstream commit 45585c3aa285854face65293acc95eff73063d6d ]
The firmware reconstruction count controls accesses to the request's
fixed freelist ID array and the copy into the fixed response array.
Neither access currently bounds the count to those protocol arrays.
Clamp the count to the request capacity, which is shared by the response
layout, and use that count consistently for reconstruction and response
publication. Keep the firmware recovery exchange instead of dropping an
oversized request without a response, as discussed with the firmware
maintainer.
The issue was found by our static-analysis tool.
Fixes: 6eedddab733b ("drm/imagination: Implement free list and HWRT create and destroy ioctls")
Assisted-by: gpt 5
Signed-off-by: Pengpeng Hou <hppiscas@163.com>
Reviewed-by: Alessio Belle <alessio.belle@imgtec.com>
Link: https://patch.msgid.link/20260920034329.16614-1-hppiscas@163.com
Signed-off-by: Brajesh Gupta <brajesh.gupta@imgtec.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/imagination/pvr_free_list.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/imagination/pvr_free_list.c b/drivers/gpu/drm/imagination/pvr_free_list.c
index e85cac83834c6..faf5e586d8dc1 100644
--- a/drivers/gpu/drm/imagination/pvr_free_list.c
+++ b/drivers/gpu/drm/imagination/pvr_free_list.c
@@ -8,6 +8,7 @@
#include "pvr_vm.h"
#include <drm/drm_gem.h>
+#include <drm/drm_print.h>
#include <linux/slab.h>
#include <linux/xarray.h>
#include <uapi/drm/pvr_drm.h>
@@ -612,13 +613,21 @@ pvr_free_list_process_reconstruct_req(struct pvr_device *pvr_dev,
};
struct rogue_fwif_freelists_reconstruction_data *resp =
&resp_cmd.cmd_data.free_lists_reconstruction_data;
+ u32 count = min_t(u32, req->freelist_count,
+ ARRAY_SIZE(req->freelist_ids));
- for (u32 i = 0; i < req->freelist_count; i++)
+ if (count != req->freelist_count) {
+ drm_warn_once(from_pvr_device(pvr_dev),
+ "Requested reconstruction of %u freelists, limiting to %u\n",
+ req->freelist_count, count);
+ }
+
+ for (u32 i = 0; i < count; i++)
pvr_free_list_reconstruct(pvr_dev, req->freelist_ids[i]);
- resp->freelist_count = req->freelist_count;
+ resp->freelist_count = count;
memcpy(resp->freelist_ids, req->freelist_ids,
- req->freelist_count * sizeof(resp->freelist_ids[0]));
+ count * sizeof(resp->freelist_ids[0]));
WARN_ON(pvr_kccb_send_cmd(pvr_dev, &resp_cmd, NULL));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 202/457] bonding: crypto offload enabled, non-offload slave failover, rekey failed
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 201/457] drm/imagination: clamp freelist reconstruction requests Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 203/457] macsec: initialize SecY before registering the netdevice Greg Kroah-Hartman
` (265 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Dai, Hangbin Liu, Paolo Abeni,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Dai <zdai@linux.ibm.com>
[ Upstream commit 00efbbd40bd5fd92c67b7cf1aab8904fa59a96f6 ]
Create a bonding device (i.e. bond0) in active-backup mode, 2 slaves.
Active slave: offload capable interface (i.e. eth1), primary interface.
Backup slave: non-offload capable interface(i.e. eth2).
Configure strongswan service swantl.conf child SA "hw_offload = crypto"
Start strongswan service
IPSec Crytpo Offload is enabled on top of bond0. i.e.
ip xfrm state |grep offload
crypto offload parameters: dev bond0 dir out mode crypto
crypto offload parameters: dev bond0 dir in mode crypto
Active slave eth1 takes adavantage of IPSec Crypto Offload capability.
If active slave eth1 is down for any reason (i.e. eth1 link down):
ip link set down dev eth1
non-offload capable interface eth2 failover to becomes active slave.
The existing SAs can continue use software IPsec after failover.
Traffic still keeps going properly.
However if eth1 link had not recovered yet, strongswan service does
new child SA rekey, or uses swanctl command to do new child SA rekey,
it will fail because active slave eth2 doesn't support crypto offload.
In bond_ipsec_add_sa routine, it returns -EINVAL now, which is
treated as fatal error by xfrm_dev_state_add routine in kernel xfrm.
To make the non-offload active slave survive the child SA rekey, need
to make bond_ipsec_add_sa routine returns -EOPNOTSUPP instead when
active slave doesn't support IPsec Crypto offload, the xfrm will
gracefully fallback to create new SA using Software IPsec.
Network traffic can keep going.
After offload capable interface eth1 link is up, becomes active slave,
next time strongswan child SA rekey will create a new SA which enables
crypto offload again.
Fixes: 18cb261afd7b ("bonding: support hardware encryption offload to slaves")
Signed-off-by: David Dai <zdai@linux.ibm.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260918211155.1664493-1-zdai@linux.ibm.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/bonding/bond_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
index 6ea46a617ee60..34c5bbbed9aee 100644
--- a/drivers/net/bonding/bond_main.c
+++ b/drivers/net/bonding/bond_main.c
@@ -490,7 +490,7 @@ static int bond_ipsec_add_sa(struct net_device *bond_dev,
!real_dev->xfrmdev_ops->xdo_dev_state_add ||
netif_is_bond_master(real_dev)) {
NL_SET_ERR_MSG_MOD(extack, "Slave does not support ipsec offload");
- err = -EINVAL;
+ err = -EOPNOTSUPP;
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 203/457] macsec: initialize SecY before registering the netdevice
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 202/457] bonding: crypto offload enabled, non-offload slave failover, rekey failed Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 204/457] net/sched: act_ife: validate metadata length before decoding Greg Kroah-Hartman
` (264 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f2f6312ad1b5a0bfe316,
Sabrina Dubroca, Haseeb Malik, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haseeb Malik <haseebulhaq55@gmail.com>
[ Upstream commit c2de369c5c5b8599ca10fd5ca8d11fcd845c1331 ]
Creating a MACsec device with MAC offload over an LRO-capable lower
device triggers a warning in rtmsg_ifinfo_build_skb() when IPv4
forwarding is enabled by default.
register_netdevice() invokes inetdev_init(), which disables LRO and emits
a NETDEV_FEAT_CHANGE notification. This reaches macsec_fill_info() before
macsec_add_dev() initializes the SecY. key_len is still zero, so
macsec_fill_info() returns -EMSGSIZE and trips the WARN_ON in
rtmsg_ifinfo_build_skb(), even though the skb has enough space.
Even without the warning, notifications during registration can report
uninitialized SecY attributes, including the SCI. This ordering has existed
since the driver was introduced.
Initialize the SecY and apply the new-link attributes before registration.
Move MAC address inheritance into macsec_newlink() so the SCI can also be
initialized before registration-time notifications report it. Move the
per-CPU statistics and metadata destination allocation into ndo_init(),
and release partial allocations on failure.
Fixes: c09440f7dcb3 ("macsec: introduce IEEE 802.1AE driver")
Reported-by: syzbot+f2f6312ad1b5a0bfe316@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f2f6312ad1b5a0bfe316
Suggested-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://lists.openwall.net/linux-kernel/2026/08/19/552
Signed-off-by: Haseeb Malik <haseebulhaq55@gmail.com>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20260921-fix-macsec-net-v3-1-accf94f93f5e@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/macsec.c | 84 +++++++++++++++++++++++---------------------
1 file changed, 43 insertions(+), 41 deletions(-)
diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c
index ee0e2eb7dbc61..e4871cd765790 100644
--- a/drivers/net/macsec.c
+++ b/drivers/net/macsec.c
@@ -3539,6 +3539,22 @@ static int macsec_dev_init(struct net_device *dev)
if (err)
return err;
+ err = -ENOMEM;
+ macsec->stats = netdev_alloc_pcpu_stats(struct pcpu_secy_stats);
+ if (!macsec->stats)
+ goto destroy_gro_cells;
+
+ macsec->secy.tx_sc.stats =
+ netdev_alloc_pcpu_stats(struct pcpu_tx_sc_stats);
+ if (!macsec->secy.tx_sc.stats)
+ goto free_secy_stats;
+
+ macsec->secy.tx_sc.md_dst = metadata_dst_alloc(0, METADATA_MACSEC,
+ GFP_KERNEL);
+ if (!macsec->secy.tx_sc.md_dst)
+ goto free_tx_sc_stats;
+ macsec->secy.tx_sc.md_dst->u.macsec_info.sci = macsec->secy.sci;
+
macsec_inherit_tso_max(dev);
dev->hw_features = real_dev->hw_features & MACSEC_OFFLOAD_FEATURES;
@@ -3551,8 +3567,6 @@ static int macsec_dev_init(struct net_device *dev)
macsec_set_head_tail_room(dev);
- if (is_zero_ether_addr(dev->dev_addr))
- eth_hw_addr_inherit(dev, real_dev);
if (is_zero_ether_addr(dev->broadcast))
memcpy(dev->broadcast, real_dev->broadcast, dev->addr_len);
@@ -3560,6 +3574,14 @@ static int macsec_dev_init(struct net_device *dev)
netdev_hold(real_dev, &macsec->dev_tracker, GFP_KERNEL);
return 0;
+
+free_tx_sc_stats:
+ free_percpu(macsec->secy.tx_sc.stats);
+free_secy_stats:
+ free_percpu(macsec->stats);
+destroy_gro_cells:
+ gro_cells_destroy(&macsec->gro_cells);
+ return err;
}
static void macsec_dev_uninit(struct net_device *dev)
@@ -4114,26 +4136,11 @@ static sci_t dev_to_sci(struct net_device *dev, __be16 port)
return make_sci(dev->dev_addr, port);
}
-static int macsec_add_dev(struct net_device *dev, sci_t sci, u8 icv_len)
+static void macsec_init_secy(struct net_device *dev, sci_t sci, u8 icv_len)
{
struct macsec_dev *macsec = macsec_priv(dev);
struct macsec_secy *secy = &macsec->secy;
- macsec->stats = netdev_alloc_pcpu_stats(struct pcpu_secy_stats);
- if (!macsec->stats)
- return -ENOMEM;
-
- secy->tx_sc.stats = netdev_alloc_pcpu_stats(struct pcpu_tx_sc_stats);
- if (!secy->tx_sc.stats)
- return -ENOMEM;
-
- secy->tx_sc.md_dst = metadata_dst_alloc(0, METADATA_MACSEC, GFP_KERNEL);
- if (!secy->tx_sc.md_dst)
- /* macsec and secy percpu stats will be freed when unregistering
- * net_device in macsec_free_netdev()
- */
- return -ENOMEM;
-
if (sci == MACSEC_UNDEF_SCI)
sci = dev_to_sci(dev, MACSEC_PORT_ES);
@@ -4147,15 +4154,12 @@ static int macsec_add_dev(struct net_device *dev, sci_t sci, u8 icv_len)
secy->xpn = DEFAULT_XPN;
secy->sci = sci;
- secy->tx_sc.md_dst->u.macsec_info.sci = sci;
secy->tx_sc.active = true;
secy->tx_sc.encoding_sa = DEFAULT_ENCODING_SA;
secy->tx_sc.encrypt = DEFAULT_ENCRYPT;
secy->tx_sc.send_sci = DEFAULT_SEND_SCI;
secy->tx_sc.end_station = false;
secy->tx_sc.scb = false;
-
- return 0;
}
static struct lock_class_key macsec_netdev_addr_lock_key;
@@ -4218,6 +4222,24 @@ static int macsec_newlink(struct net_device *dev,
if (rx_handler && rx_handler != macsec_handle_frame)
return -EBUSY;
+ if (is_zero_ether_addr(dev->dev_addr))
+ eth_hw_addr_inherit(dev, real_dev);
+
+ if (data && data[IFLA_MACSEC_SCI])
+ sci = nla_get_sci(data[IFLA_MACSEC_SCI]);
+ else if (data && data[IFLA_MACSEC_PORT])
+ sci = dev_to_sci(dev, nla_get_be16(data[IFLA_MACSEC_PORT]));
+ else
+ sci = dev_to_sci(dev, MACSEC_PORT_ES);
+
+ /* Registration can notify listeners before returning. */
+ macsec_init_secy(dev, sci, icv_len);
+ if (data) {
+ err = macsec_changelink_common(dev, data);
+ if (err)
+ return err;
+ }
+
err = register_netdevice(dev);
if (err < 0)
return err;
@@ -4230,31 +4252,11 @@ static int macsec_newlink(struct net_device *dev,
if (err < 0)
goto unregister;
- /* need to be already registered so that ->init has run and
- * the MAC addr is set
- */
- if (data && data[IFLA_MACSEC_SCI])
- sci = nla_get_sci(data[IFLA_MACSEC_SCI]);
- else if (data && data[IFLA_MACSEC_PORT])
- sci = dev_to_sci(dev, nla_get_be16(data[IFLA_MACSEC_PORT]));
- else
- sci = dev_to_sci(dev, MACSEC_PORT_ES);
-
if (rx_handler && sci_exists(real_dev, sci)) {
err = -EBUSY;
goto unlink;
}
- err = macsec_add_dev(dev, sci, icv_len);
- if (err)
- goto unlink;
-
- if (data) {
- err = macsec_changelink_common(dev, data);
- if (err)
- goto del_dev;
- }
-
/* If h/w offloading is available, propagate to the device */
if (macsec_is_offloaded(macsec)) {
const struct macsec_ops *ops;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 204/457] net/sched: act_ife: validate metadata length before decoding
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 203/457] macsec: initialize SecY before registering the netdevice Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 205/457] net: emac: move setting of netops to fix crash Greg Kroah-Hartman
` (263 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fang Xieyan, Paolo Abeni,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fang Xieyan <fangxy@xiaopeng.com>
[ Upstream commit d6ec384c87cc851cfd13bb18c99ce351ccee6192 ]
skbmark_decode(), skbprio_decode() and skbtcindex_decode() read fixed-size
values from the TLV payload without validating its length.
A malformed IFE frame can declare a shorter payload, causing the decoders
to consume bytes beyond the declared metadata value:
[TLV type=IFE_META_SKBMARK len=4]
-> dlen == 0, but decode reads 4 bytes
The decoder may therefore set skb metadata from unintended input.
Validate the payload length before decoding and return -EINVAL for
invalid lengths. Read the values with get_unaligned_be32() and
get_unaligned_be16(), as TLV payloads are not guaranteed to be
aligned. Teach tcf_ife_decode() to log a decoder error separately
from an unknown metaid; both are counted as overlimits and decoding
continues with the remaining metadata.
The metadata length issue was found by an automated audit of the IFE
decode path at v6.18-rc7 and reproduced with a userspace sanitizer
model of the decode path. Compile-tested on x86_64 with defconfig and
NET_ACT_IFE=y: act_ife.o and the three act_meta_*.o build
warning-free.
Fixes: 084e2f6566d2 ("Support to encoding decoding skb mark on IFE action")
Fixes: 200e10f46936 ("Support to encoding decoding skb prio on IFE action")
Fixes: 408fbc22ef1e ("net sched ife action: Introduce skb tcindex metadata encap decap")
Assisted-by: Hawkeye:GLM-5.3-flash
Assisted-by: Qoder:Qwen3.8-Max
Signed-off-by: Fang Xieyan <fangxy@xiaopeng.com>
Link: https://patch.msgid.link/20260921125441.81459-1-fangxy@xiaopeng.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/act_ife.c | 17 ++++++++++++-----
net/sched/act_meta_mark.c | 6 ++++--
net/sched/act_meta_skbprio.c | 6 ++++--
net/sched/act_meta_skbtcindex.c | 6 ++++--
4 files changed, 24 insertions(+), 11 deletions(-)
diff --git a/net/sched/act_ife.c b/net/sched/act_ife.c
index 9cea71fc1db3d..2afd68983ece4 100644
--- a/net/sched/act_ife.c
+++ b/net/sched/act_ife.c
@@ -737,6 +737,7 @@ static int tcf_ife_decode(struct sk_buff *skb, const struct tc_action *a,
u8 *curr_data;
u16 mtype;
u16 dlen;
+ int ret;
curr_data = ife_tlv_meta_decode(tlv_data, ifehdr_end, &mtype,
&dlen, NULL);
@@ -745,13 +746,19 @@ static int tcf_ife_decode(struct sk_buff *skb, const struct tc_action *a,
return TC_ACT_SHOT;
}
- if (find_decode_metaid(skb, p, mtype, dlen, curr_data)) {
- /* abuse overlimits to count when we receive metadata
- * but dont have an ops for it
+ ret = find_decode_metaid(skb, p, mtype, dlen, curr_data);
+ if (ret < 0) {
+ /* abuse overlimits to count metadata we cannot
+ * decode: no ops for it, or the decoder rejected it
*/
- pr_info_ratelimited("Unknown metaid %d dlen %d\n",
- mtype, dlen);
qstats_cpu_overlimit_inc(ife->common.cpu_qstats);
+
+ if (ret == -ENOENT)
+ pr_info_ratelimited("Unknown metaid %d dlen %d\n",
+ mtype, dlen);
+ else
+ pr_info_ratelimited("Failed to decode metaid %d dlen %d err %d\n",
+ mtype, dlen, ret);
}
}
diff --git a/net/sched/act_meta_mark.c b/net/sched/act_meta_mark.c
index ea0573cb8b2d6..e2f61b22bf0f8 100644
--- a/net/sched/act_meta_mark.c
+++ b/net/sched/act_meta_mark.c
@@ -10,6 +10,7 @@
#include <linux/string.h>
#include <linux/errno.h>
#include <linux/skbuff.h>
+#include <linux/unaligned.h>
#include <linux/rtnetlink.h>
#include <linux/module.h>
#include <linux/init.h>
@@ -28,9 +29,10 @@ static int skbmark_encode(struct sk_buff *skb, void *skbdata,
static int skbmark_decode(struct sk_buff *skb, void *data, u16 len)
{
- u32 ifemark = *(u32 *)data;
+ if (len != sizeof(u32))
+ return -EINVAL;
- skb->mark = ntohl(ifemark);
+ skb->mark = get_unaligned_be32(data);
return 0;
}
diff --git a/net/sched/act_meta_skbprio.c b/net/sched/act_meta_skbprio.c
index 2df3133ce5adc..5cdb57931eab4 100644
--- a/net/sched/act_meta_skbprio.c
+++ b/net/sched/act_meta_skbprio.c
@@ -10,6 +10,7 @@
#include <linux/string.h>
#include <linux/errno.h>
#include <linux/skbuff.h>
+#include <linux/unaligned.h>
#include <linux/rtnetlink.h>
#include <linux/module.h>
#include <linux/init.h>
@@ -33,9 +34,10 @@ static int skbprio_encode(struct sk_buff *skb, void *skbdata,
static int skbprio_decode(struct sk_buff *skb, void *data, u16 len)
{
- u32 ifeprio = *(u32 *)data;
+ if (len != sizeof(u32))
+ return -EINVAL;
- skb->priority = ntohl(ifeprio);
+ skb->priority = get_unaligned_be32(data);
return 0;
}
diff --git a/net/sched/act_meta_skbtcindex.c b/net/sched/act_meta_skbtcindex.c
index 44547caead469..8803710c09058 100644
--- a/net/sched/act_meta_skbtcindex.c
+++ b/net/sched/act_meta_skbtcindex.c
@@ -10,6 +10,7 @@
#include <linux/string.h>
#include <linux/errno.h>
#include <linux/skbuff.h>
+#include <linux/unaligned.h>
#include <linux/rtnetlink.h>
#include <linux/module.h>
#include <linux/init.h>
@@ -28,9 +29,10 @@ static int skbtcindex_encode(struct sk_buff *skb, void *skbdata,
static int skbtcindex_decode(struct sk_buff *skb, void *data, u16 len)
{
- u16 ifetc_index = *(u16 *)data;
+ if (len != sizeof(u16))
+ return -EINVAL;
- skb->tc_index = ntohs(ifetc_index);
+ skb->tc_index = get_unaligned_be16(data);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 205/457] net: emac: move setting of netops to fix crash
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 204/457] net/sched: act_ife: validate metadata length before decoding Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 206/457] bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element Greg Kroah-Hartman
` (262 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lamparter,
Nicolai Buchwitz, Maxime Chevallier, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lamparter <chunkeey@gmail.com>
[ Upstream commit 7c9f391ec89cb621d7af375ace2eb9a6248e5b9d ]
fixes the following crash on driver initialization:
|BUG: Kernel NULL pointer dereference on read at 0x00000158
|Faulting instruction address: 0xc0566b40
|Oops: Kernel access of bad area, sig: 11 [#1]
|BE PAGE_SIZE=4K PowerPC 44x Platform
|Modules linked in:
|CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Tainted: GW 7.3.0-rc3+ #1
|Tainted: [W]=WARN
|Hardware name: MyBook Live APM821XX 0x12c41c83 PowerPC 44x Platform
|NIP: c0566b40 LR: c05648f8 CTR: c04c1e9c
|REGS: c1053a20 TRAP: 0300 Tainted: GW (7.3.0-rc3+)
|MSR: 0002b000 <CE,EE,FP,ME> CR: 24008808 XER: 00000000
|DEAR: 00000158 ESR: 00000000
|GPR00: c05648f8 c1053b10 c1063600 c1030000 c5ab3000 00000000 [...]
|GPR08: 00000002 00000000 00000000 c1053b40 84002808 00000000 [...]
|GPR16: cfffd210 00000002 c0beafcc cfffc960 00000000 c1030644 [...]
|GPR24: c0beafbc c1037000 00000000 0000000a 00000000 c1030000 [...]
|NIP [c0566b40] phy_link_topo_add_phy+0x2c/0x1d0
|LR [c05648f8] phy_attach_direct+0x1a4/0x368
|Call Trace:
|[c1053b10] [c0811e04] klist_put+0x54/0xb4 (unreliable)
|[c1053b40] [c05648f8] phy_attach_direct+0x1a4/0x368
|[c1053b70] [c0564ae8] phy_connect_direct+0x2c/0x60
|[c1053b90] [c056c7a8] of_phy_connect+0x50/0x74
|[c1053bc0] [c0572a88] emac_probe+0xd50/0x119c
|[c1053c90] [c04cb770] platform_probe+0x74/0xa4
|[c1053cb0] [c04c8f08] really_probe+0x120/0x2b0
|[c1053cd0] [c04c9254] __driver_probe_device+0x1bc/0x1fc
|[c1053d00] [c04c9334] driver_probe_device+0x38/0xa8
|[c1053d30] [c04c9560] __driver_attach+0xf4/0x10c
|[c1053d50] [c04c6af8] bus_for_each_dev+0x68/0xd0
|[c1053d90] [c04c7c34] bus_add_driver+0xcc/0x1ec
|[c1053dc0] [c04c9f6c] driver_register+0xcc/0x110
|[c1053de0] [c0aa3f40] emac_init+0x1c4/0x200
This bug showed up starting with v7.3-rc1. At the NIP in
phy_link_topo_add_phy() is a netdev_need_ops_lock() check.
This was added by the following
commit ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
The bug shows up because at the time of_phy_connect() was called, the
netdev_ops were *not yet* determined. My fix is to move the code that
sets netdev_ops+commac.ops+ethtool_ops further up as emac_init_config()
derives that by looking at the device-tree and sets the required
dev->phy_mode accordingly.
During review, the Sashiko bot's AI stated that the commac assignment
became a dead store. Great catch! To keep the original behavior as-is,
one mentioned option "set dev->commac.ops = &emac_commac_ops only in
the non-gige case?" sounded like a great plan. So the dev->commac.ops
assignment for the non-gige-case moves into the else block.
This patch was tested on a WD MyBook Live (RGMII). the device now works again.
Fixes: ded86da4bbb7 ("net: ethtool: relax ethnl_req_get_phydev() locking assertion")
Signed-off-by: Christian Lamparter <chunkeey@gmail.com>
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/49cd7343bc0e507c022071f3e2b5662b053dca73.1790007431.git.chunkeey@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ibm/emac/core.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/ibm/emac/core.c b/drivers/net/ethernet/ibm/emac/core.c
index 1d46cf6c2c127..e7043523457c1 100644
--- a/drivers/net/ethernet/ibm/emac/core.c
+++ b/drivers/net/ethernet/ibm/emac/core.c
@@ -3044,6 +3044,15 @@ static int emac_probe(struct platform_device *ofdev)
if (err)
goto err_gone;
+ if (emac_phy_supports_gige(dev->phy_mode)) {
+ ndev->netdev_ops = &emac_gige_netdev_ops;
+ dev->commac.ops = &emac_commac_sg_ops;
+ } else {
+ ndev->netdev_ops = &emac_netdev_ops;
+ dev->commac.ops = &emac_commac_ops;
+ }
+ ndev->ethtool_ops = &emac_ethtool_ops;
+
dev->emacp = devm_platform_ioremap_resource(ofdev, 0);
if (IS_ERR(dev->emacp)) {
err = PTR_ERR(dev->emacp);
@@ -3076,7 +3085,6 @@ static int emac_probe(struct platform_device *ofdev)
dev->mdio_instance = platform_get_drvdata(dev->mdio_dev);
/* Register with MAL */
- dev->commac.ops = &emac_commac_ops;
dev->commac.dev = dev;
dev->commac.tx_chan_mask = MAL_CHAN_MASK(dev->mal_tx_chan);
dev->commac.rx_chan_mask = MAL_CHAN_MASK(dev->mal_rx_chan);
@@ -3144,12 +3152,6 @@ static int emac_probe(struct platform_device *ofdev)
ndev->features |= ndev->hw_features | NETIF_F_RXCSUM;
}
ndev->watchdog_timeo = 5 * HZ;
- if (emac_phy_supports_gige(dev->phy_mode)) {
- ndev->netdev_ops = &emac_gige_netdev_ops;
- dev->commac.ops = &emac_commac_sg_ops;
- } else
- ndev->netdev_ops = &emac_netdev_ops;
- ndev->ethtool_ops = &emac_ethtool_ops;
/* MTU range: 46 - 1500 or whatever is in OF */
ndev->min_mtu = EMAC_MIN_MTU;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 206/457] bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 205/457] net: emac: move setting of netops to fix crash Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 207/457] net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621 Greg Kroah-Hartman
` (261 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Alexei Starovoitov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit c3a66e5f5bab3912e9f84223c5a982bf4333d5a1 ]
pcpu_init_value() initializes the per-cpu area of a newly created
[lru_]percpu_hash element. The area is recycled, so when the value
comes from a BPF program (onallcpus == false) it writes the running
CPU's slot and zeroes the rest.
bpf_percpu_hash_update() passes onallcpus == true, which delegates to
pcpu_copy_value(). pcpu_copy_value() writes only the CPU named in
map_flags when BPF_F_CPU is set, so on the create path the other slots
keep the recycled element's values:
update(k1, 0xdeadc0de, BPF_F_ALL_CPUS) every CPU holds 0xdeadc0de
delete(k1) element back on the freelist
update(k2, 0xc0ffee, BPF_F_CPU | 0) creates, writes CPU 0 only
lookup(k2) CPU 0 0xc0ffee, rest 0xdeadc0de
Zero-fill the other CPUs on that arm too.
Fixes: c6936161fd55 ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags support for percpu_hash and lru_percpu_hash maps")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://patch.msgid.link/20260924102321.2120434-2-donggeunyoo.kernel@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/hashtab.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
index 5117447ac291b..61ef6191f79ad 100644
--- a/kernel/bpf/hashtab.c
+++ b/kernel/bpf/hashtab.c
@@ -1055,14 +1055,17 @@ static void pcpu_init_value(struct bpf_htab *htab, void __percpu *pptr,
/* When not setting the initial value on all cpus, zero-fill element
* values for other cpus. Otherwise, bpf program has no way to ensure
* known initial values for cpus other than current one
- * (onallcpus=false always when coming from bpf prog).
+ * (onallcpus=false always when coming from bpf prog,
+ * map_flags & BPF_F_CPU when coming from syscall but setting
+ * only one cpu).
*/
- if (!onallcpus) {
- int current_cpu = raw_smp_processor_id();
+ if (!onallcpus || (map_flags & BPF_F_CPU)) {
+ int init_cpu = (map_flags & BPF_F_CPU) ? map_flags >> 32 :
+ raw_smp_processor_id();
int cpu;
for_each_possible_cpu(cpu) {
- if (cpu == current_cpu)
+ if (cpu == init_cpu)
copy_map_value(&htab->map, per_cpu_ptr(pptr, cpu), value);
else /* Since elem is preallocated, we cannot touch special fields */
zero_map_value(&htab->map, per_cpu_ptr(pptr, cpu));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 207/457] net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 206/457] bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 208/457] net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq Greg Kroah-Hartman
` (260 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aleksei Sviridkin, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aleksei Sviridkin <f@lex.la>
[ Upstream commit c2cdef41e0b4d8ed23a5b41e6ad4e64594e055e4 ]
The core and io supplies are only requested for ID_MT7530: both the
devm_regulator_get() in probe and the regulator_enable() in
mt7530_setup() are guarded by the switch id, but mt7530_remove()
disables them unconditionally. On an MT7621 or an MT7531 both pointers
are still NULL from devm_kzalloc(), so rmmod or a sysfs unbind calls
regulator_disable() on NULL.
Fixes: ddda1ac116c8 ("net: dsa: mt7530: support the 7530 switch on the Mediatek MT7621 SoC")
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Link: https://patch.msgid.link/20260918015020.2518315-2-f@lex.la
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mt7530-mdio.c | 20 +++++++++++---------
1 file changed, 11 insertions(+), 9 deletions(-)
diff --git a/drivers/net/dsa/mt7530-mdio.c b/drivers/net/dsa/mt7530-mdio.c
index 784dd58a71589..de42f70afcfa1 100644
--- a/drivers/net/dsa/mt7530-mdio.c
+++ b/drivers/net/dsa/mt7530-mdio.c
@@ -227,15 +227,17 @@ mt7530_remove(struct mdio_device *mdiodev)
if (!priv)
return;
- ret = regulator_disable(priv->core_pwr);
- if (ret < 0)
- dev_err(priv->dev,
- "Failed to disable core power: %d\n", ret);
-
- ret = regulator_disable(priv->io_pwr);
- if (ret < 0)
- dev_err(priv->dev, "Failed to disable io pwr: %d\n",
- ret);
+ if (priv->id == ID_MT7530) {
+ ret = regulator_disable(priv->core_pwr);
+ if (ret < 0)
+ dev_err(priv->dev,
+ "Failed to disable core power: %d\n", ret);
+
+ ret = regulator_disable(priv->io_pwr);
+ if (ret < 0)
+ dev_err(priv->dev, "Failed to disable io pwr: %d\n",
+ ret);
+ }
mt7530_remove_common(priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 208/457] net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 207/457] net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621 Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 209/457] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
` (259 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aleksei Sviridkin, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aleksei Sviridkin <f@lex.la>
[ Upstream commit 0d80ba0a204c6a16bd7778b50de578dff107c0fe ]
mt7530_remove_common() disposes the per-PHY interrupt mappings from
.remove, but the regmap-irq chip that owns the domain is devm-registered,
so its parent interrupt is only freed once .remove has returned. The
switch's own regmap-irq thread can therefore still dispatch on a mapping
that is already gone: irq_find_mapping() returns 0, irq_to_desc() returns
NULL and handle_nested_irq() locks desc->lock without checking it. The
attached PHYs have not given those interrupts back yet either, which the
kernel warns about a moment before the fault.
regmap_del_irq_chip() disposes the same mappings itself, after freeing the
parent interrupt and before removing the domain, so there is nothing left
for the driver to do here. Until it runs the descriptors stay alive, and a
late dispatch on one of them is harmless: dsa_unregister_switch() has freed
the PHY handlers by then, so handle_nested_irq() finds no action and
returns.
Fixes: 254f6b272e3b ("dsa: mt7530: Utilize REGMAP_IRQ for interrupt handling")
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Link: https://patch.msgid.link/20260918015020.2518315-3-f@lex.la
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mt7530.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/net/dsa/mt7530.c b/drivers/net/dsa/mt7530.c
index 56ee8dc34f518..93dba4498c420 100644
--- a/drivers/net/dsa/mt7530.c
+++ b/drivers/net/dsa/mt7530.c
@@ -3539,9 +3539,6 @@ EXPORT_SYMBOL_GPL(mt7530_probe_common);
void
mt7530_remove_common(struct mt7530_priv *priv)
{
- if (priv->irq_domain)
- mt7530_free_mdio_irq(priv);
-
dsa_unregister_switch(priv->ds);
mutex_destroy(&priv->reg_mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 209/457] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 208/457] net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 210/457] net: phylink: record the PHY only once bringup cannot fail Greg Kroah-Hartman
` (258 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kimi Security Team, Weiming Shi,
Yilin Zhang, Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yilin Zhang <yilinzhang@moonshot.ai>
[ Upstream commit fe99bbeee5c5dbd3abc30721a8079ced59649d97 ]
When tcp_send_synack() replaces the cloned SYN skb at the head of the
retransmit queue with a copy, it frees the original with
tcp_rtx_queue_unlink_and_free() and only repairs tp->highest_sack.
tp->retransmit_skb_hint keeps pointing at the freed
skbuff_fclone_cache object.
The dangling hint is read in tcp_verify_retransmit_hint() and used as
the root of the rbtree walk in tcp_xmit_retransmit_queue(). An
unprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with
an attacker-supplied ICMP fragmentation-needed message, after which a
simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
Read of size 4 at addr ffff88800604d928 by task swapper/1/0
Call Trace:
tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
tcp_simple_retransmit (net/ipv4/tcp_input.c:3158)
tcp_v4_err (net/ipv4/tcp_ipv4.c:587)
Sync the hint to the copy.
Fixes: c31b70c9968f ("tcp: Add logic to check for SYN w/ data in tcp_simple_retransmit")
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Tested-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/8a9dff4063a2745653b7e88ceb745d75efa16e68.1790224474.git.yilinzhang@moonshot.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/tcp_output.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index f72a6b1fe749b..0b89b624af8ed 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -3886,6 +3886,7 @@ void tcp_send_active_reset(struct sock *sk, enum sk_rst_reason reason)
*/
int tcp_send_synack(struct sock *sk)
{
+ struct tcp_sock *tp = tcp_sk(sk);
struct sk_buff *skb;
skb = tcp_rtx_queue_head(sk);
@@ -3903,6 +3904,8 @@ int tcp_send_synack(struct sock *sk)
if (!nskb)
return -ENOMEM;
INIT_LIST_HEAD(&nskb->tcp_tsorted_anchor);
+ if (skb == tp->retransmit_skb_hint)
+ tp->retransmit_skb_hint = nskb;
tcp_highest_sack_replace(sk, skb, nskb);
tcp_rtx_queue_unlink_and_free(skb, sk);
__skb_header_release(nskb);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 210/457] net: phylink: record the PHY only once bringup cannot fail
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 209/457] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 211/457] net: wangxun: implement soft quiesce for PCIe error recovery Greg Kroah-Hartman
` (257 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aleksei Sviridkin, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aleksei Sviridkin <f@lex.la>
[ Upstream commit a940003f44e7e441c228151dd212642152700ec8 ]
phylink_bringup_phy() stores the PHY in pl->phydev before its last
fallible step: on a MAC whose phylink ops implement LPI,
phy_eee_rx_clock_stop() can fail with a real MDIO error. The callers
unwind with phy_detach(), which knows nothing about pl->phydev, so a
pointer to a PHY that is no longer attached outlives the failed
connect.
What that costs depends on how the caller got here.
phylink_connect_phy() goes through phylink_attach_phy(), which refuses
to attach while pl->phydev is set, turning a transient MDIO error into
a permanent -EBUSY. The SFP path is worse than that: sfp_sm_probe_phy()
answers the failure with phy_device_remove() and phy_device_free(), and
it assigns sfp->mod_phy only past that error return, so nothing clears
pl->phydev and it is left pointing at a freed phy_device that
phylink_resolve() and the ethtool helpers go on reading.
phylink_fwnode_phy_connect() has no such check, so a later connect
overwrites the stale pointer and hides the problem. A disconnect does
not: phylink_disconnect_phy() hands that pointer to phy_disconnect(),
and the second phy_detach() on the same PHY drops references the first
one already released.
Found while making a DSA port survive a PHY whose driver arrives after
the switch probes: keeping the port across a failed connect and
retrying is what makes this window reachable.
Publish the pointer after the last call that can fail instead of
unwinding it afterwards. Nothing between the two points reads
pl->phydev, and the registration that follows cannot fail:
phy_request_interrupt() falls back to polling on its own. The PHY-side
state keeps the order it had, so no MDIO operation moves relative to
another.
Fixes: 03abf2a7c654 ("net: phylink: add EEE management")
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Link: https://patch.msgid.link/20260920222044.1752860-1-f@lex.la
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/phy/phylink.c | 20 +++++++++++++++++---
1 file changed, 17 insertions(+), 3 deletions(-)
diff --git a/drivers/net/phy/phylink.c b/drivers/net/phy/phylink.c
index 27fd9aa2027a4..3477e1104a43a 100644
--- a/drivers/net/phy/phylink.c
+++ b/drivers/net/phy/phylink.c
@@ -2131,7 +2131,6 @@ static int phylink_bringup_phy(struct phylink *pl, struct phy_device *phy,
mutex_lock(&pl->phydev_mutex);
mutex_lock(&phy->lock);
mutex_lock(&pl->state_mutex);
- pl->phydev = phy;
pl->phy_state.interface = interface;
pl->phy_state.pause = MLO_PAUSE_NONE;
pl->phy_state.speed = SPEED_UNKNOWN;
@@ -2198,10 +2197,25 @@ static int phylink_bringup_phy(struct phylink *pl, struct phy_device *phy,
ret = 0;
}
- if (ret == 0 && phy_interrupt_is_valid(phy))
+ if (ret)
+ return ret;
+
+ /* Nothing below can fail, so the PHY can be recorded now. Doing it
+ * here rather than above keeps a failed bringup from leaving
+ * pl->phydev pointing at a PHY the caller is about to detach.
+ */
+ mutex_lock(&pl->phydev_mutex);
+ mutex_lock(&phy->lock);
+ mutex_lock(&pl->state_mutex);
+ pl->phydev = phy;
+ mutex_unlock(&pl->state_mutex);
+ mutex_unlock(&phy->lock);
+ mutex_unlock(&pl->phydev_mutex);
+
+ if (phy_interrupt_is_valid(phy))
phy_request_interrupt(phy);
- return ret;
+ return 0;
}
static int phylink_attach_phy(struct phylink *pl, struct phy_device *phy,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 211/457] net: wangxun: implement soft quiesce for PCIe error recovery
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 210/457] net: phylink: record the PHY only once bringup cannot fail Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 212/457] net: libwx: fix races in Tx timestamp handling Greg Kroah-Hartman
` (256 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiawen Wu, Aleksandr Loktionov,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiawen Wu <jiawenwu@trustnetic.com>
[ Upstream commit c023e9769de94cb7b7897297e71f50b0f436c473 ]
Function wx_soft_quiesce() provide a lightweight shutdown path during
PCIe error recovery. It avoids MMIO-dependent operations in PCIe error
status.
Waiting for the service task to complete may unnecessarily delay PCIe
error recovery, especially if the work item is already blocked by the
hardware failure that triggered AER. So the service task is not
explicitly cancelled in quiesce path. As a measure to block the service
task, the checking of WX_STATE_DOWN and WX_STATE_RESETTING is added at
the entry of relevant work item.
Signed-off-by: Jiawen Wu <jiawenwu@trustnetic.com>
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Link: https://patch.msgid.link/20260803064334.21876-5-jiawenwu@trustnetic.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 3173cba11701 ("net: libwx: fix races in Tx timestamp handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 18 +++++++++++++
drivers/net/ethernet/wangxun/libwx/wx_lib.h | 1 +
drivers/net/ethernet/wangxun/libwx/wx_ptp.c | 27 +++++++++++++++++++
drivers/net/ethernet/wangxun/libwx/wx_ptp.h | 1 +
.../net/ethernet/wangxun/txgbe/txgbe_main.c | 16 +++++++++++
5 files changed, 63 insertions(+)
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_lib.c b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
index 5d99e870de5ef..7e2ae41a321e1 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_lib.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
@@ -3348,5 +3348,23 @@ void wx_service_timer(struct timer_list *t)
}
EXPORT_SYMBOL(wx_service_timer);
+void wx_soft_quiesce(struct wx *wx)
+{
+ if (!netif_running(wx->netdev) ||
+ test_and_set_bit(WX_STATE_DOWN, wx->state))
+ return;
+
+ pci_clear_master(wx->pdev);
+ netif_tx_stop_all_queues(wx->netdev);
+ netif_carrier_off(wx->netdev);
+ netif_tx_disable(wx->netdev);
+ wx_napi_disable_all(wx);
+ wx_ptp_quiesce(wx);
+
+ clear_bit(WX_FLAG_NEED_DO_RESET, wx->flags);
+ timer_delete_sync(&wx->service_timer);
+}
+EXPORT_SYMBOL(wx_soft_quiesce);
+
MODULE_DESCRIPTION("Common library for Wangxun(R) Ethernet drivers.");
MODULE_LICENSE("GPL");
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_lib.h b/drivers/net/ethernet/wangxun/libwx/wx_lib.h
index aed6ea8cf0d64..11bd79985e171 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_lib.h
+++ b/drivers/net/ethernet/wangxun/libwx/wx_lib.h
@@ -41,5 +41,6 @@ void wx_set_ring(struct wx *wx, u32 new_tx_count,
void wx_service_event_schedule(struct wx *wx);
void wx_service_event_complete(struct wx *wx);
void wx_service_timer(struct timer_list *t);
+void wx_soft_quiesce(struct wx *wx);
#endif /* _WX_LIB_H_ */
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_ptp.c b/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
index 1165518d55225..4708e7f3958f7 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
@@ -321,6 +321,9 @@ static long wx_ptp_do_aux_work(struct ptp_clock_info *ptp)
struct wx *wx = container_of(ptp, struct wx, ptp_caps);
int ts_done;
+ if (!test_bit(WX_STATE_PTP_RUNNING, wx->state))
+ return HZ;
+
ts_done = wx_ptp_tx_hwtstamp_work(wx);
wx_ptp_overflow_check(wx);
@@ -836,6 +839,30 @@ void wx_ptp_stop(struct wx *wx)
}
EXPORT_SYMBOL(wx_ptp_stop);
+void wx_ptp_quiesce(struct wx *wx)
+{
+ if (!test_and_clear_bit(WX_STATE_PTP_RUNNING, wx->state))
+ return;
+
+ clear_bit(WX_FLAG_PTP_PPS_ENABLED, wx->flags);
+
+ if (wx->ptp_clock)
+ ptp_cancel_worker_sync(wx->ptp_clock);
+
+ if (wx->ptp_tx_skb) {
+ dev_kfree_skb_any(wx->ptp_tx_skb);
+ wx->ptp_tx_skb = NULL;
+ }
+ clear_bit_unlock(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+
+ if (wx->ptp_clock) {
+ ptp_clock_unregister(wx->ptp_clock);
+ wx->ptp_clock = NULL;
+ dev_info(&wx->pdev->dev, "removed PHC on %s\n", wx->netdev->name);
+ }
+}
+EXPORT_SYMBOL(wx_ptp_quiesce);
+
/**
* wx_ptp_rx_hwtstamp - utility function which checks for RX time stamp
* @wx: pointer to wx struct
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_ptp.h b/drivers/net/ethernet/wangxun/libwx/wx_ptp.h
index 50db90a6e3ee6..ad2f824875d51 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_ptp.h
+++ b/drivers/net/ethernet/wangxun/libwx/wx_ptp.h
@@ -10,6 +10,7 @@ void wx_ptp_reset(struct wx *wx);
void wx_ptp_init(struct wx *wx);
void wx_ptp_suspend(struct wx *wx);
void wx_ptp_stop(struct wx *wx);
+void wx_ptp_quiesce(struct wx *wx);
void wx_ptp_rx_hwtstamp(struct wx *wx, struct sk_buff *skb);
int wx_hwtstamp_get(struct net_device *dev,
struct kernel_hwtstamp_config *cfg);
diff --git a/drivers/net/ethernet/wangxun/txgbe/txgbe_main.c b/drivers/net/ethernet/wangxun/txgbe/txgbe_main.c
index c277863baf67a..00123c0e3f222 100644
--- a/drivers/net/ethernet/wangxun/txgbe/txgbe_main.c
+++ b/drivers/net/ethernet/wangxun/txgbe/txgbe_main.c
@@ -93,12 +93,24 @@ static void txgbe_module_detection_subtask(struct wx *wx)
{
int err;
+ if (test_bit(WX_STATE_DOWN, wx->state) ||
+ test_bit(WX_STATE_RESETTING, wx->state))
+ return;
+
if (!test_and_clear_bit(WX_FLAG_NEED_MODULE_RESET, wx->flags))
return;
/* wait for SFF module ready */
msleep(200);
+ /* Re-check state to avoid racing with down/reset paths.
+ * Module identification is deferred to the next up event,
+ * so it is safe to bail out here.
+ */
+ if (test_bit(WX_STATE_DOWN, wx->state) ||
+ test_bit(WX_STATE_RESETTING, wx->state))
+ return;
+
err = txgbe_identify_module(wx);
if (err == -ENODEV)
set_bit(WX_FLAG_NEED_MODULE_RESET, wx->flags);
@@ -106,6 +118,10 @@ static void txgbe_module_detection_subtask(struct wx *wx)
static void txgbe_link_config_subtask(struct wx *wx)
{
+ if (test_bit(WX_STATE_DOWN, wx->state) ||
+ test_bit(WX_STATE_RESETTING, wx->state))
+ return;
+
if (!test_and_clear_bit(WX_FLAG_NEED_LINK_CONFIG, wx->flags))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 212/457] net: libwx: fix races in Tx timestamp handling
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 211/457] net: wangxun: implement soft quiesce for PCIe error recovery Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 213/457] nfp: hold IPsec RX state under the XArray lock Greg Kroah-Hartman
` (255 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Jiawen Wu, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiawen Wu <jiawenwu@trustnetic.com>
[ Upstream commit 3173cba1170131816972ed2b6185cb970ba8b747 ]
wx->ptp_tx_skb is shared between the Tx path, the PTP auxiliary
worker and the timestamp cleanup paths. The
WX_STATE_PTP_TX_IN_PROGRESS bit prevents multiple Tx paths from
submitting timestamp requests, but does not serialize the worker
against cleanup.
As a result, wx_ptp_clear_tx_timestamp() can free an skb after
wx_ptp_tx_hwtstamp_work() has obtained its pointer. The worker may
then pass the freed skb to skb_tstamp_tx() and release the same
reference again.
The cleanup path may also clear the in-progress bit while the worker
is still processing the old skb. This allows the Tx path to publish a
new skb which the worker can subsequently overwrite with NULL,
leaking its reference.
Add a dedicated spinlock to protect publication and consumption of
the Tx timestamp skb. Detach the skb and clear the in-progress bit
while holding the lock, then deliver the timestamp and release the skb
after dropping it. Use the same locked cleanup in the quiesce path,
but keep the detach there free of register accesses: quiesce runs
during PCIe error recovery, where MMIO is not reliable, and it
deliberately did not touch the device before. The lock is taken with
interrupts disabled, because netpoll can call ndo_start_xmit() with
hard interrupts already off.
When handling a Tx DMA mapping failure, keep the transmit path
reference until after comparing the skb under the lock. This prevents
skb address reuse from making the error path mistake a newer timestamp
request for the failed one.
Fixes: 06e75161b9d4 ("net: wangxun: Add support for PTP clock")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/6C7EC12D69217315%2B20260818074721.45536-1-jiawenwu%40trustnetic.com
Signed-off-by: Jiawen Wu <jiawenwu@trustnetic.com>
Link: https://patch.msgid.link/77431AF9A0E369F3+20260921071549.1141804-1-jiawenwu@trustnetic.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/wangxun/libwx/wx_hw.c | 1 +
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 47 ++++--
drivers/net/ethernet/wangxun/libwx/wx_ptp.c | 142 +++++++++++++------
drivers/net/ethernet/wangxun/libwx/wx_type.h | 2 +
4 files changed, 132 insertions(+), 60 deletions(-)
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_hw.c b/drivers/net/ethernet/wangxun/libwx/wx_hw.c
index 260e14d5d5412..9119c931b3a3f 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_hw.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_hw.c
@@ -2517,6 +2517,7 @@ int wx_sw_init(struct wx *wx)
}
spin_lock_init(&wx->hw_stats_lock);
+ spin_lock_init(&wx->ptp_tx_lock);
mutex_init(&wx->reset_lock);
bitmap_zero(wx->state, WX_STATE_NBITS);
bitmap_zero(wx->flags, WX_PF_FLAGS_NBITS);
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_lib.c b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
index 7e2ae41a321e1..287172348b07e 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_lib.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_lib.c
@@ -1163,9 +1163,11 @@ static int wx_tx_map(struct wx_ring *tx_ring,
i--;
}
- dev_kfree_skb_any(first->skb);
- first->skb = NULL;
-
+ /* first->skb is released by the caller, which keeps a reference on it
+ * until the PTP cleanup has compared it against wx->ptp_tx_skb. That
+ * prevents the address from being reused by a newer request while the
+ * comparison is pending.
+ */
tx_ring->next_to_use = i;
return -ENOMEM;
@@ -1612,9 +1614,11 @@ static netdev_tx_t wx_xmit_frame_ring(struct sk_buff *skb,
if (unlikely(skb_shinfo(skb)->tx_flags & SKBTX_HW_TSTAMP) &&
wx->ptp_clock) {
+ unsigned long flags;
+
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
if (wx->tstamp_config.tx_type == HWTSTAMP_TX_ON &&
- !test_and_set_bit_lock(WX_STATE_PTP_TX_IN_PROGRESS,
- wx->state)) {
+ !test_and_set_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state)) {
skb_shinfo(skb)->tx_flags |= SKBTX_IN_PROGRESS;
tx_flags |= WX_TX_FLAGS_TSTAMP;
wx->ptp_tx_skb = skb_get(skb);
@@ -1622,6 +1626,7 @@ static netdev_tx_t wx_xmit_frame_ring(struct sk_buff *skb,
} else {
wx->tx_hwtstamp_skipped++;
}
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
}
/* record initial flags and protocol */
@@ -1640,19 +1645,35 @@ static netdev_tx_t wx_xmit_frame_ring(struct sk_buff *skb,
wx->atr(tx_ring, first, ptype);
if (wx_tx_map(tx_ring, first, hdr_len))
- goto cleanup_tx_tstamp;
+ goto out_drop;
return NETDEV_TX_OK;
out_drop:
- dev_kfree_skb_any(first->skb);
- first->skb = NULL;
-cleanup_tx_tstamp:
+ /* The frame never reached the hardware, so no timestamp will ever be
+ * reported for it and the request has to be cancelled. The slot is
+ * shared, though: wx_ptp_clear_tx_timestamp() or wx_ptp_tx_hang() may
+ * have dropped our request already, and a transmit on another queue
+ * can have claimed the slot since. Only cancel it while it is still
+ * ours, otherwise we would free somebody else's skb and release their
+ * in-progress bit.
+ */
if (unlikely(tx_flags & WX_TX_FLAGS_TSTAMP)) {
- dev_kfree_skb_any(wx->ptp_tx_skb);
- wx->ptp_tx_skb = NULL;
- wx->tx_hwtstamp_errors++;
- clear_bit_unlock(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+ struct sk_buff *ptp_tx_skb = NULL;
+ unsigned long flags;
+
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
+ if (wx->ptp_tx_skb == skb) {
+ ptp_tx_skb = wx->ptp_tx_skb;
+ wx->ptp_tx_skb = NULL;
+ clear_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+ wx->tx_hwtstamp_errors++;
+ }
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+
+ dev_kfree_skb_any(ptp_tx_skb);
}
+ dev_kfree_skb_any(first->skb);
+ first->skb = NULL;
return NETDEV_TX_OK;
}
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_ptp.c b/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
index 4708e7f3958f7..65b8937f6e94c 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
+++ b/drivers/net/ethernet/wangxun/libwx/wx_ptp.c
@@ -129,6 +129,34 @@ static int wx_ptp_settime64(struct ptp_clock_info *ptp,
return 0;
}
+/**
+ * __wx_ptp_detach_tx_skb - detach the skb tracking the Tx timestamp request
+ * @wx: the private board structure
+ *
+ * Detach the skb of the outstanding request and release the in-progress bit,
+ * so that a new request can be submitted.
+ *
+ * This performs no register access. Callers that need a timestamp the hardware
+ * may have left latched must unlatch it themselves, while the device is known
+ * to be alive. wx_ptp_quiesce() runs during PCIe error recovery, where MMIO is
+ * not reliable, and therefore deliberately skips the unlatch.
+ *
+ * Context: Expects wx->ptp_tx_lock to be held by the caller.
+ * Return: the detached skb, or NULL if no request was outstanding. The caller
+ * owns the returned reference and must release it once the lock is dropped.
+ */
+static struct sk_buff *__wx_ptp_detach_tx_skb(struct wx *wx)
+{
+ struct sk_buff *skb = wx->ptp_tx_skb;
+
+ lockdep_assert_held(&wx->ptp_tx_lock);
+
+ wx->ptp_tx_skb = NULL;
+ clear_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+
+ return skb;
+}
+
/**
* wx_ptp_clear_tx_timestamp - utility function to clear Tx timestamp state
* @wx: the private board structure
@@ -139,12 +167,16 @@ static int wx_ptp_settime64(struct ptp_clock_info *ptp,
*/
static void wx_ptp_clear_tx_timestamp(struct wx *wx)
{
+ struct sk_buff *skb;
+ unsigned long flags;
+
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
+ /* Unlatch a timestamp the hardware may have left pending. */
rd32ptp(wx, WX_TSC_1588_STMPH);
- if (wx->ptp_tx_skb) {
- dev_kfree_skb_any(wx->ptp_tx_skb);
- wx->ptp_tx_skb = NULL;
- }
- clear_bit_unlock(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+ skb = __wx_ptp_detach_tx_skb(wx);
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+
+ dev_kfree_skb_any(skb);
}
/**
@@ -175,49 +207,54 @@ static void wx_ptp_convert_to_hwtstamp(struct wx *wx,
}
/**
- * wx_ptp_tx_hwtstamp - utility function which checks for TX time stamp
+ * wx_ptp_tx_hwtstamp_work - check for a pending Tx time stamp
* @wx: the private board struct
*
- * if the timestamp is valid, we convert it into the timecounter ns
- * value, then store that result into the shhwtstamps structure which
- * is passed up the network stack
+ * If a Tx timestamp request is outstanding and the hardware has latched a
+ * valid value, we convert it into the timecounter ns value, then store that
+ * result into the shhwtstamps structure which is passed up the network stack.
+ *
+ * Return: 0 when there is nothing left to poll for, -1 when the timestamp is
+ * not available yet and the caller should poll again.
*/
-static void wx_ptp_tx_hwtstamp(struct wx *wx)
+static int wx_ptp_tx_hwtstamp_work(struct wx *wx)
{
struct skb_shared_hwtstamps shhwtstamps;
- struct sk_buff *skb = wx->ptp_tx_skb;
+ unsigned long flags;
+ struct sk_buff *skb;
+ u32 tsynctxctl;
u64 regval = 0;
- regval |= (u64)rd32ptp(wx, WX_TSC_1588_STMPL);
- regval |= (u64)rd32ptp(wx, WX_TSC_1588_STMPH) << 32;
-
- wx_ptp_convert_to_hwtstamp(wx, &shhwtstamps, regval);
-
- wx->ptp_tx_skb = NULL;
- clear_bit_unlock(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
- skb_tstamp_tx(skb, &shhwtstamps);
- dev_kfree_skb_any(skb);
- wx->tx_hwtstamp_pkts++;
-}
-
-static int wx_ptp_tx_hwtstamp_work(struct wx *wx)
-{
- u32 tsynctxctl;
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
/* we have to have a valid skb to poll for a timestamp */
if (!wx->ptp_tx_skb) {
- wx_ptp_clear_tx_timestamp(wx);
+ rd32ptp(wx, WX_TSC_1588_STMPH);
+ __wx_ptp_detach_tx_skb(wx);
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
return 0;
}
/* stop polling once we have a valid timestamp */
tsynctxctl = rd32ptp(wx, WX_TSC_1588_CTL);
- if (tsynctxctl & WX_TSC_1588_CTL_VALID) {
- wx_ptp_tx_hwtstamp(wx);
- return 0;
+ if (!(tsynctxctl & WX_TSC_1588_CTL_VALID)) {
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+ return -1;
}
- return -1;
+ regval |= (u64)rd32ptp(wx, WX_TSC_1588_STMPL);
+ regval |= (u64)rd32ptp(wx, WX_TSC_1588_STMPH) << 32;
+ skb = wx->ptp_tx_skb;
+ wx->ptp_tx_skb = NULL;
+ clear_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+
+ wx_ptp_convert_to_hwtstamp(wx, &shhwtstamps, regval);
+ skb_tstamp_tx(skb, &shhwtstamps);
+ dev_kfree_skb_any(skb);
+ wx->tx_hwtstamp_pkts++;
+
+ return 0;
}
/**
@@ -296,24 +333,29 @@ static void wx_ptp_rx_hang(struct wx *wx)
*/
static void wx_ptp_tx_hang(struct wx *wx)
{
- bool timeout = time_is_before_jiffies(wx->ptp_tx_start +
- WX_PTP_TX_TIMEOUT);
-
- if (!wx->ptp_tx_skb)
- return;
+ struct sk_buff *skb = NULL;
+ unsigned long flags;
- if (!test_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state))
- return;
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
/* If we haven't received a timestamp within the timeout, it is
* reasonable to assume that it will never occur, so we can unlock the
* timestamp bit when this occurs.
*/
- if (timeout) {
- wx_ptp_clear_tx_timestamp(wx);
- wx->tx_hwtstamp_timeouts++;
- dev_warn(&wx->pdev->dev, "clearing Tx timestamp hang\n");
+ if (wx->ptp_tx_skb &&
+ test_bit(WX_STATE_PTP_TX_IN_PROGRESS, wx->state) &&
+ time_is_before_jiffies(wx->ptp_tx_start + WX_PTP_TX_TIMEOUT)) {
+ rd32ptp(wx, WX_TSC_1588_STMPH);
+ skb = __wx_ptp_detach_tx_skb(wx);
}
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+
+ if (!skb)
+ return;
+
+ dev_kfree_skb_any(skb);
+ wx->tx_hwtstamp_timeouts++;
+ dev_warn(&wx->pdev->dev, "clearing Tx timestamp hang\n");
}
static long wx_ptp_do_aux_work(struct ptp_clock_info *ptp)
@@ -841,6 +883,9 @@ EXPORT_SYMBOL(wx_ptp_stop);
void wx_ptp_quiesce(struct wx *wx)
{
+ struct sk_buff *skb;
+ unsigned long flags;
+
if (!test_and_clear_bit(WX_STATE_PTP_RUNNING, wx->state))
return;
@@ -849,11 +894,14 @@ void wx_ptp_quiesce(struct wx *wx)
if (wx->ptp_clock)
ptp_cancel_worker_sync(wx->ptp_clock);
- if (wx->ptp_tx_skb) {
- dev_kfree_skb_any(wx->ptp_tx_skb);
- wx->ptp_tx_skb = NULL;
- }
- clear_bit_unlock(WX_STATE_PTP_TX_IN_PROGRESS, wx->state);
+ /* Drop a pending Tx timestamp request. Do not touch the registers
+ * here: quiesce runs during PCIe error recovery, where the device may
+ * already be gone and MMIO is not reliable.
+ */
+ spin_lock_irqsave(&wx->ptp_tx_lock, flags);
+ skb = __wx_ptp_detach_tx_skb(wx);
+ spin_unlock_irqrestore(&wx->ptp_tx_lock, flags);
+ dev_kfree_skb_any(skb);
if (wx->ptp_clock) {
ptp_clock_unregister(wx->ptp_clock);
diff --git a/drivers/net/ethernet/wangxun/libwx/wx_type.h b/drivers/net/ethernet/wangxun/libwx/wx_type.h
index 0520288d18ab9..e63a1666d8ed1 100644
--- a/drivers/net/ethernet/wangxun/libwx/wx_type.h
+++ b/drivers/net/ethernet/wangxun/libwx/wx_type.h
@@ -1413,6 +1413,8 @@ struct wx {
unsigned long last_overflow_check;
unsigned long last_rx_ptp_check;
unsigned long ptp_tx_start;
+ /* protects ptp_tx_skb, ptp_tx_start and the in-progress state bit */
+ spinlock_t ptp_tx_lock;
seqlock_t hw_tc_lock; /* seqlock for ptp */
struct cyclecounter hw_cc;
struct timecounter hw_tc;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 213/457] nfp: hold IPsec RX state under the XArray lock
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 212/457] net: libwx: fix races in Tx timestamp handling Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 214/457] net/rds: size a connections path set by the transport it ends up with Greg Kroah-Hartman
` (254 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Changyul Lee, Sang-Hoon Choi,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sang-Hoon Choi <csh0052@gmail.com>
[ Upstream commit 1a983a4e14c635c40354be110cd9a1a5c94e01e6 ]
nfp_net_ipsec_rx() drops the XArray lock before taking a reference to the
xfrm_state it found. The delete path can erase the entry and drop the last
state reference in that interval. RX can then try to increment a zero
refcount after the state has been queued for destruction.
The driver queues firmware invalidation asynchronously; the delete path
does not wait for the command to complete or drain pending RX processing.
The XFRM garbage collector waits for an RCU grace period before freeing
the state. That delays reclamation but does not make acquiring a reference
from zero valid.
Take the xfrm_state reference before releasing the XArray lock so
xa_erase() cannot run between lookup and reference acquisition.
Fixes: 57f273adbcd4 ("nfp: add framework to support ipsec offloading")
Reported-by: Changyul Lee <lcy8047@gmail.com>
Signed-off-by: Sang-Hoon Choi <csh0052@gmail.com>
Link: https://patch.msgid.link/179001455912.44752.17153022439349797877.idr-bug-92@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/netronome/nfp/crypto/ipsec.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/netronome/nfp/crypto/ipsec.c b/drivers/net/ethernet/netronome/nfp/crypto/ipsec.c
index 9e7c285eaa6bc..960d7513aa8dd 100644
--- a/drivers/net/ethernet/netronome/nfp/crypto/ipsec.c
+++ b/drivers/net/ethernet/netronome/nfp/crypto/ipsec.c
@@ -625,11 +625,12 @@ int nfp_net_ipsec_rx(struct nfp_meta_parsed *meta, struct sk_buff *skb)
xa_lock(&nn->xa_ipsec);
x = xa_load(&nn->xa_ipsec, saidx);
+ if (x)
+ xfrm_state_hold(x);
xa_unlock(&nn->xa_ipsec);
if (!x)
return -EINVAL;
- xfrm_state_hold(x);
sp->xvec[sp->len++] = x;
sp->olen++;
xo = xfrm_offload(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 214/457] net/rds: size a connections path set by the transport it ends up with
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 213/457] nfp: hold IPsec RX state under the XArray lock Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 215/457] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
` (253 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit ba3d1f480c7a3fba963e7867ad6cc557c197acbc ]
__rds_conn_create() computes npaths from the caller's transport before
it decides whether a connection to one of the host's own addresses is
to be handled by the loopback transport instead. That substitution is
what an RDS/TCP socket sending to a local address gets, and after it
the path init loop still runs for the TCP transport's RDS_MPATH_WORKERS
paths and allocates an ordered workqueue for each, while
rds_loop_conn_alloc() only ever provides transport data for path 0.
rds_conn_destroy() sizes its teardown from c_trans, by then the
loopback transport, so it visits path 0 only - and
rds_conn_path_destroy() would skip the other paths anyway, since it
returns before destroy_workqueue() for a path without transport data.
kfree(c_path) then drops the last pointers to seven workqueues. That
repeats for every such connection, on every netns teardown or module
unload, and every distinct local destination address is a separate
connection.
Recompute npaths once the transport is final, so that creation and
destruction agree on the set of paths. The c_path array stays sized
for the caller's transport; the unused entries are freed with it.
Fixes: 4716af3897e9 ("net/rds: Give each connection path its own workqueue")
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260921215027.174657-1-achender@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/rds/connection.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/rds/connection.c b/net/rds/connection.c
index b6c4beb50eaf0..c752a8623cfca 100644
--- a/net/rds/connection.c
+++ b/net/rds/connection.c
@@ -276,6 +276,12 @@ static struct rds_connection *__rds_conn_create(struct net *net,
conn->c_trans = trans;
+ /* The transport may just have been swapped for loopback; size the
+ * set of paths - which is also what rds_conn_destroy() tears down
+ * again - by the transport the connection actually uses.
+ */
+ npaths = (trans->t_mp_capable ? RDS_MPATH_WORKERS : 1);
+
init_waitqueue_head(&conn->c_hs_waitq);
for (i = 0; i < npaths; i++) {
__rds_conn_path_init(conn, &conn->c_path[i],
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 215/457] net/smc: fix UAF on lgr list traversal in smcr_port_err()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 214/457] net/rds: size a connections path set by the transport it ends up with Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 216/457] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
` (252 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mahanta Jambigi, Sidraya Jayagond,
Dust Li, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sidraya Jayagond <sidraya@linux.ibm.com>
[ Upstream commit 61cb282fe97b3b0ba32ca09417a693162bf4ae3f ]
smcr_port_err() traverses smc_lgr_list.list without holding
smc_lgr_list.lock, allowing a concurrent smc_lgr_terminate_sched()
to free an lgr while it is still being dereferenced.
Hold smc_lgr_list.lock across the traversal. Update
smc_ib_gid_check() to call smcr_port_err() after releasing the lock.
Fixes: 541afa10c126 ("net/smc: add smcr_port_err() and smcr_link_down() processing")
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Signed-off-by: Sidraya Jayagond <sidraya@linux.ibm.com>
Reviewed-by: Dust Li <dust.li@linux.alibaba.com>
Link: https://patch.msgid.link/20260922073149.474762-1-sidraya@linux.ibm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/smc/smc_core.c | 2 ++
net/smc/smc_ib.c | 10 ++++++++--
2 files changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/smc/smc_core.c b/net/smc/smc_core.c
index 04aedd957543a..9974149659c2f 100644
--- a/net/smc/smc_core.c
+++ b/net/smc/smc_core.c
@@ -1849,6 +1849,7 @@ void smcr_port_err(struct smc_ib_device *smcibdev, u8 ibport)
struct smc_link_group *lgr, *n;
int i;
+ spin_lock_bh(&smc_lgr_list.lock);
list_for_each_entry_safe(lgr, n, &smc_lgr_list.list, list) {
if (strncmp(smcibdev->pnetid[ibport - 1], lgr->pnet_id,
SMC_MAX_PNETID_LEN))
@@ -1863,6 +1864,7 @@ void smcr_port_err(struct smc_ib_device *smcibdev, u8 ibport)
smcr_link_down_cond_sched(lnk);
}
}
+ spin_unlock_bh(&smc_lgr_list.lock);
}
static void smc_link_down_work(struct work_struct *work)
diff --git a/net/smc/smc_ib.c b/net/smc/smc_ib.c
index 9bb495707445e..daaa8a72da90f 100644
--- a/net/smc/smc_ib.c
+++ b/net/smc/smc_ib.c
@@ -333,6 +333,7 @@ static bool smc_ib_check_link_gid(u8 gid[SMC_GID_SIZE], bool smcrv2,
static void smc_ib_gid_check(struct smc_ib_device *smcibdev, u8 ibport)
{
struct smc_link_group *lgr;
+ bool stale_gid = false;
int i;
spin_lock_bh(&smc_lgr_list.lock);
@@ -348,11 +349,16 @@ static void smc_ib_gid_check(struct smc_ib_device *smcibdev, u8 ibport)
continue;
if (!smc_ib_check_link_gid(lgr->lnk[i].gid,
lgr->smc_version == SMC_V2,
- smcibdev, ibport))
- smcr_port_err(smcibdev, ibport);
+ smcibdev, ibport)) {
+ stale_gid = true;
+ goto out;
+ }
}
}
+out:
spin_unlock_bh(&smc_lgr_list.lock);
+ if (stale_gid)
+ smcr_port_err(smcibdev, ibport);
}
static int smc_ib_remember_port_attr(struct smc_ib_device *smcibdev, u8 ibport)
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 216/457] tipc: Fix a data race on mon->peer_cnt in mon_timeout()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 215/457] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 217/457] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
` (251 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ginger Li, Tung Nguyen,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ginger Li <ginger.jzllee@gmail.com>
[ Upstream commit 8e1937fed6738460554ec123c64839e2445e7d53 ]
mon_timeout() evaluates dom_size(mon->peer_cnt) before it takes mon->lock,
while mon->peer_cnt is updated under that lock by tipc_mon_add_peer() and
tipc_mon_remove_peer(). The value can therefore be stale, and the decision
whether the local domain has to be recomputed can be based on an outdated
member count.
Read mon->peer_cnt inside the write_lock_bh(&mon->lock) protected region.
Fixes: 35c55c9877f8 ("tipc: add neighbor monitoring framework")
Signed-off-by: Ginger Li <ginger.jzllee@gmail.com>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260922080909.21123-1-ginger.jzllee@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/tipc/monitor.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/tipc/monitor.c b/net/tipc/monitor.c
index a94b9b36a7008..1a438e312d66b 100644
--- a/net/tipc/monitor.c
+++ b/net/tipc/monitor.c
@@ -632,9 +632,10 @@ static void mon_timeout(struct timer_list *t)
{
struct tipc_monitor *mon = timer_container_of(mon, t, timer);
struct tipc_peer *self;
- int best_member_cnt = dom_size(mon->peer_cnt) - 1;
+ int best_member_cnt;
write_lock_bh(&mon->lock);
+ best_member_cnt = dom_size(mon->peer_cnt) - 1;
self = mon->self;
if (self && (best_member_cnt != self->applied)) {
mon_update_local_domain(mon);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 217/457] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 216/457] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 218/457] net: flush skb_defer_nodes in dev_cpu_dead() Greg Kroah-Hartman
` (250 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Heiko Stuebner,
Lorenzo Bianconi, Coia Prant, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Coia Prant <coiaprant@gmail.com>
[ Upstream commit 8db67bb6a1fffa4df68fbbc22e39943aeeff9178 ]
gmac_clk_enable() enables the bulk clocks first and then the optional
PHY clock. If clk_prepare_enable() on the PHY clock fails, the function
returns without rolling back the bulk clocks, and bsp_priv->clk_enabled
stays false, so the later gmac_clk_enable(bsp_priv, false) becomes a
no-op and the bulk clock references are leaked.
Add the missing clk_bulk_disable_unprepare() on that failure path.
Fixes: ea449f7fa0bf ("net: ethernet: stmmac: dwmac-rk: rework optional clock handling")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Heiko Stuebner <heiko@sntech.de>
Acked-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Signed-off-by: Coia Prant <coiaprant@gmail.com>
Link: https://patch.msgid.link/20260923123713.3137146-1-coiaprant@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
index 8d7042e689261..72bdbcb5e863a 100644
--- a/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
+++ b/drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c
@@ -1162,8 +1162,11 @@ static int gmac_clk_enable(struct rk_priv_data *bsp_priv, bool enable)
return ret;
ret = clk_prepare_enable(bsp_priv->clk_phy);
- if (ret)
+ if (ret) {
+ clk_bulk_disable_unprepare(bsp_priv->num_clks,
+ bsp_priv->clks);
return ret;
+ }
rk_configure_io_clksel(bsp_priv);
rk_ungate_rmii_clock(bsp_priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 218/457] net: flush skb_defer_nodes in dev_cpu_dead()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 217/457] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 219/457] gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO Greg Kroah-Hartman
` (249 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Kris Pan,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 06e3f54e8b22040ada01a28343badf1990b4dd7d ]
When a CPU goes offline, dev_cpu_dead() drains its softnet queues
(completion_queue, output_queue, poll_list, process_queue, and
input_pkt_queue), but leaves net_hotdata.skb_defer_nodes untouched.
If oldcpu goes offline while holding pending skbs in its
skb_defer_nodes lists (e.g. below the sysctl_skb_defer_max >> 1 IPI
threshold, or if the IPI races with CPU teardown), those skbs remain
stranded until oldcpu is brought back online. If any of these skbs
hold page_pool fragments, page_pool_destroy() will stall indefinitely
waiting for inflight pages to be returned when a netdev or driver is
torn down while oldcpu is offline.
Additionally, if smp_call_function_single_async() fails in
kick_defer_list_purge() because the target CPU went offline, reset
defer_ipi_scheduled to 0 so future IPI kicks are not blocked when the
CPU comes back online.
Also, if oldcpu was the last online CPU on its NUMA node, drain that
node's slot across all CPUs so no skbs deferred from that node remain
stranded on idle remote CPUs (or if the node itself is subsequently
offlined).
Finally, in skb_attempt_defer_free(), re-check cpu_online(cpu) and
whether the caller migrated CPUs after llist_add(), flushing the node
list if so, to close the preemption TOCTOU race against CPU/node
teardown.
Fixes: 68822bdf76f1 ("net: generalize skb freeing deferral to per-cpu lists")
Fixes: 5628f3fe3b16 ("net: add NUMA awareness to skb_attempt_defer_free()")
Closes: https://lore.kernel.org/netdev/20260916003430.3612956-1-kris.pan@intel.com/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Kris Pan <kris.pan@intel.com>
Link: https://patch.msgid.link/20260923130318.607255-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 47 +++++++++++++++++++++++++++++++++++------------
net/core/dev.h | 2 ++
net/core/skbuff.c | 12 +++++++++---
3 files changed, 46 insertions(+), 15 deletions(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index a48958a3f76c1..55e1f4045d2c6 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -5370,7 +5370,8 @@ void kick_defer_list_purge(unsigned int cpu)
backlog_unlock_irq_restore(sd, flags);
} else if (!cmpxchg(&sd->defer_ipi_scheduled, 0, 1)) {
- smp_call_function_single_async(cpu, &sd->defer_csd);
+ if (smp_call_function_single_async(cpu, &sd->defer_csd))
+ WRITE_ONCE(sd->defer_ipi_scheduled, 0);
}
}
@@ -6894,25 +6895,35 @@ bool napi_complete_done(struct napi_struct *n, int work_done)
}
EXPORT_SYMBOL(napi_complete_done);
-static void skb_defer_free_flush(void)
+static void __skb_defer_free_flush(struct skb_defer_node *sdn, int budget)
{
struct llist_node *free_list;
struct sk_buff *skb, *next;
+
+ if (llist_empty(&sdn->defer_list))
+ return;
+ atomic_long_set(&sdn->defer_count, 0);
+ free_list = llist_del_all(&sdn->defer_list);
+
+ llist_for_each_entry_safe(skb, next, free_list, ll_node) {
+ prefetch(next);
+ napi_consume_skb(skb, budget);
+ }
+}
+
+void skb_defer_node_flush(struct skb_defer_node *sdn)
+{
+ __skb_defer_free_flush(sdn, 0);
+}
+
+static void skb_defer_free_flush(void)
+{
struct skb_defer_node *sdn;
int node;
for_each_node(node) {
sdn = this_cpu_ptr(net_hotdata.skb_defer_nodes) + node;
-
- if (llist_empty(&sdn->defer_list))
- continue;
- atomic_long_set(&sdn->defer_count, 0);
- free_list = llist_del_all(&sdn->defer_list);
-
- llist_for_each_entry_safe(skb, next, free_list, ll_node) {
- prefetch(next);
- napi_consume_skb(skb, 1);
- }
+ __skb_defer_free_flush(sdn, 1);
}
}
@@ -12773,6 +12784,7 @@ static int dev_cpu_dead(unsigned int oldcpu)
struct sk_buff **list_skb;
struct sk_buff *skb;
unsigned int cpu;
+ int node;
struct softnet_data *sd, *oldsd, *remsd = NULL;
local_irq_disable();
@@ -12833,6 +12845,17 @@ static int dev_cpu_dead(unsigned int oldcpu)
rps_input_queue_head_incr(oldsd);
}
+ for_each_node(node)
+ skb_defer_node_flush(per_cpu_ptr(net_hotdata.skb_defer_nodes,
+ oldcpu) + node);
+ node = cpu_to_node(oldcpu);
+ if (node_possible(node) &&
+ !cpumask_intersects(cpumask_of_node(node), cpu_online_mask)) {
+ for_each_possible_cpu(cpu)
+ skb_defer_node_flush(per_cpu_ptr(net_hotdata.skb_defer_nodes,
+ cpu) + node);
+ }
+
return 0;
}
diff --git a/net/core/dev.h b/net/core/dev.h
index b757faead4d1a..04fb0e9a571e0 100644
--- a/net/core/dev.h
+++ b/net/core/dev.h
@@ -399,6 +399,8 @@ static inline void napi_assert_will_not_race(const struct napi_struct *napi)
WARN_ON(READ_ONCE(napi->list_owner) != -1);
}
+struct skb_defer_node;
+void skb_defer_node_flush(struct skb_defer_node *sdn);
void kick_defer_list_purge(unsigned int cpu);
int dev_set_hwtstamp_phylib(struct net_device *dev,
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 89ee7907e4996..39102b3660034 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -7348,8 +7348,8 @@ void skb_attempt_defer_free(struct sk_buff *skb)
struct skb_defer_node *sdn;
unsigned long defer_count;
unsigned int defer_max;
+ int cpu, my_cpu;
bool kick;
- int cpu;
if (static_branch_unlikely(&skb_defer_disable_key))
goto nodefer;
@@ -7359,7 +7359,8 @@ void skb_attempt_defer_free(struct sk_buff *skb)
goto nodefer;
cpu = skb->alloc_cpu;
- if (cpu == raw_smp_processor_id() ||
+ my_cpu = raw_smp_processor_id();
+ if (cpu == my_cpu ||
WARN_ON_ONCE(cpu >= nr_cpu_ids) ||
!cpu_online(cpu)) {
nodefer: kfree_skb_napi_cache(skb);
@@ -7370,7 +7371,7 @@ nodefer: kfree_skb_napi_cache(skb);
DEBUG_NET_WARN_ON_ONCE(skb->destructor);
DEBUG_NET_WARN_ON_ONCE(skb_nfct(skb));
- sdn = per_cpu_ptr(net_hotdata.skb_defer_nodes, cpu) + numa_node_id();
+ sdn = per_cpu_ptr(net_hotdata.skb_defer_nodes, cpu) + cpu_to_node(my_cpu);
defer_max = READ_ONCE(net_hotdata.sysctl_skb_defer_max);
defer_count = atomic_long_inc_return(&sdn->defer_count);
@@ -7380,6 +7381,11 @@ nodefer: kfree_skb_napi_cache(skb);
llist_add(&skb->ll_node, &sdn->defer_list);
+ if (unlikely(!cpu_online(cpu) || my_cpu != raw_smp_processor_id())) {
+ skb_defer_node_flush(sdn);
+ return;
+ }
+
/* Send an IPI every time queue reaches half capacity. */
kick = (defer_count - 1) == (defer_max >> 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 219/457] gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 218/457] net: flush skb_defer_nodes in dev_cpu_dead() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 220/457] gve: fix TX drop when GSO MSS is too small for hw Greg Kroah-Hartman
` (248 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Ankit Garg,
Harshitha Ramamurthy, Joshua Washington, Willem de Bruijn,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 83769c23fb1879edc916a526ba424285033baf2d ]
gve_can_send_tso() computes how many buffers each segment of a GSO
packet would span, and for this it needs the length of the headers
that the device replicates in front of every segment.
It unconditionally uses skb_tcp_all_headers(), which reads the doff
field of the TCP header. SKB_GSO_UDP_L4 packets have no TCP header:
tcp_hdrlen() then reads one byte of the UDP payload, and header_len
can be anything in [0, 60] instead of the transport offset plus the
eight bytes of the UDP header that gve_prep_tso() programs into the
TSO context descriptor.
A wrong header length shifts all the segment boundaries computed in
the loop, so the number of buffers per segment can be over or under
estimated. In the first case, GSO is needlessly disabled for this
packet by gve_features_check_dqo() and the stack has to segment it.
In the second case, the driver hands the device a packet whose
segments span more than GVE_TX_MAX_DATA_DESCS buffers.
Use the UDP header length for SKB_GSO_UDP_L4 packets, matching what
gve_prep_tso() does.
Fixes: 014c607f86ab ("gve: add support for UDP GSO for DQO format")
Closes: https://lore.kernel.org/netdev/CANn89i+MS4L60sFQ49=-f-mibeveUfcrpVkD5X+Qy6SOnEpd6w@mail.gmail.com/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Ankit Garg <nktgrg@google.com>
Cc: Harshitha Ramamurthy <hramamurthy@google.com>
Cc: Joshua Washington <joshwash@google.com>
Cc: Willem de Bruijn <willemb@google.com>
Reviewed-by: Ankit Garg <nktgrg@google.com>
Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260923145942.731365-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/google/gve/gve_tx_dqo.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/google/gve/gve_tx_dqo.c b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
index 80ab0a449ff54..0f6f7c5dbb2e0 100644
--- a/drivers/net/ethernet/google/gve/gve_tx_dqo.c
+++ b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
@@ -918,13 +918,19 @@ static bool gve_can_send_tso(const struct sk_buff *skb)
{
const int max_bufs_per_seg = GVE_TX_MAX_DATA_DESCS - 1;
const struct skb_shared_info *shinfo = skb_shinfo(skb);
- const int header_len = skb_tcp_all_headers(skb);
const int gso_size = shinfo->gso_size;
int cur_seg_num_bufs;
int prev_frag_size;
int cur_seg_size;
+ int header_len;
int i;
+ /* Must match the header length programmed by gve_prep_tso(). */
+ if (skb_is_gso_tcp(skb))
+ header_len = skb_tcp_all_headers(skb);
+ else
+ header_len = skb_transport_offset(skb) + sizeof(struct udphdr);
+
cur_seg_size = skb_headlen(skb) - header_len;
prev_frag_size = skb_headlen(skb);
cur_seg_num_bufs = cur_seg_size > 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 220/457] gve: fix TX drop when GSO MSS is too small for hw
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 219/457] gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 221/457] gve: DQO: reject TSO packets with an out of range MSS Greg Kroah-Hartman
` (247 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eddie Phillips, Eric Dumazet,
Harshitha Ramamurthy, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eddie Phillips <eddiephillips@google.com>
[ Upstream commit 3b430ea6234087957b0d3cd181e3116722b59819 ]
The device has a strict requirement that the minimum MSS
(gso_size) for TSO/GSO packets must be at least 88 bytes. If a packet
below this threshold is pushed to the hardware, it can cause
hardware to silently drop the packet, leading to increased latency
and retransmissions.
Currently, this is validated too late in the transmit pipeline
(gve_prep_tso), leading to silent drops.
Fix this by moving the validation into the .ndo_features_check
callback (gve_features_check_dqo). If we detect a GSO packet with
a gso_size smaller than GVE_TX_MIN_TSO_MSS_DQO, we clear the GSO
feature flags for this packet.
Fixes: a57e5de476be ("gve: DQO: Add TX path")
Signed-off-by: Eddie Phillips <eddiephillips@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260924004252.1196328-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/google/gve/gve_tx_dqo.c | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/google/gve/gve_tx_dqo.c b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
index 0f6f7c5dbb2e0..e5fe17b047981 100644
--- a/drivers/net/ethernet/google/gve/gve_tx_dqo.c
+++ b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
@@ -577,17 +577,6 @@ static int gve_prep_tso(struct sk_buff *skb)
int header_len;
int err;
- /* Note: HW requires MSS (gso_size) to be <= 9728 and the total length
- * of the TSO to be <= 262143.
- *
- * However, we don't validate these because:
- * - Hypervisor enforces a limit of 9K MTU
- * - Kernel will not produce a TSO larger than 64k
- */
-
- if (unlikely(shinfo->gso_size < GVE_TX_MIN_TSO_MSS_DQO))
- return -1;
-
/* Needed because we will modify header. */
err = skb_cow_head(skb, 0);
if (err < 0)
@@ -925,6 +914,9 @@ static bool gve_can_send_tso(const struct sk_buff *skb)
int header_len;
int i;
+ if (unlikely(gso_size < GVE_TX_MIN_TSO_MSS_DQO))
+ return false;
+
/* Must match the header length programmed by gve_prep_tso(). */
if (skb_is_gso_tcp(skb))
header_len = skb_tcp_all_headers(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 221/457] gve: DQO: reject TSO packets with an out of range MSS
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 220/457] gve: fix TX drop when GSO MSS is too small for hw Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 222/457] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
` (246 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Harshitha Ramamurthy,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 296c83b5ccc808c080865eb20fd7a477b0355bb7 ]
gve_prep_tso() notes that the device requires the MSS to be <= 9728,
but does not enforce it, assuming the 9K MTU enforced by the hypervisor
and the 64KB limit on TSO sizes are enough.
This does not hold for packets that were not generated locally.
A guest behind a tap, or any packet socket user, can provide an
arbitrary gso_size in virtio_net_hdr. Layer 2 forwarding does not check
the MTU for GSO packets (is_skb_forwardable()), and gso_features_check()
only bounds skb->len and gso_segs, never gso_size.
Such a packet reaches gve_tx_fill_tso_ctx_desc(), which puts gso_size
into the mss field of the TSO context descriptor. This field is 14 bits
wide, so a gso_size of 16384 is silently turned into an MSS of zero.
Drop these packets from gve_prep_tso(), and make sure that
gve_features_check_dqo() leaves their GSO bits alone: skb_segment()
splits at gso_size regardless of the MTU, so falling back to software
segmentation would give the device non TSO packets bigger than the
9728 bytes it supports.
Note that the device can still be given oversized non TSO packets when
the stack segments in software for other reasons, for instance after
TSO has been disabled with ethtool. This is a generic issue, because
the MTU check is skipped for GSO packets in the forwarding path, and
is addressed separately.
Fixes: a57e5de476be ("gve: DQO: Add TX path")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260924004252.1196328-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/google/gve/gve_desc_dqo.h | 5 ++++
drivers/net/ethernet/google/gve/gve_tx_dqo.c | 26 ++++++++++++++++++-
2 files changed, 30 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/google/gve/gve_desc_dqo.h b/drivers/net/ethernet/google/gve/gve_desc_dqo.h
index f7786b03c7444..d2c86c8eeae2a 100644
--- a/drivers/net/ethernet/google/gve/gve_desc_dqo.h
+++ b/drivers/net/ethernet/google/gve/gve_desc_dqo.h
@@ -14,6 +14,11 @@
#define GVE_TX_MAX_HDR_SIZE_DQO 255
#define GVE_TX_MIN_TSO_MSS_DQO 88
+/* HW limit. This also has to fit in the 14 bits of the mss field of
+ * struct gve_tx_tso_context_desc_dqo.
+ */
+#define GVE_TX_MAX_TSO_MSS_DQO 9728
+
#ifndef __LITTLE_ENDIAN_BITFIELD
#error "Only little endian supported"
#endif
diff --git a/drivers/net/ethernet/google/gve/gve_tx_dqo.c b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
index e5fe17b047981..616c1921aebea 100644
--- a/drivers/net/ethernet/google/gve/gve_tx_dqo.c
+++ b/drivers/net/ethernet/google/gve/gve_tx_dqo.c
@@ -577,6 +577,20 @@ static int gve_prep_tso(struct sk_buff *skb)
int header_len;
int err;
+ /* Note: HW requires the total length of the TSO to be <= 262143,
+ * this is enforced by netif_set_tso_max_size().
+ *
+ * MSS (gso_size) can not be trusted: packets forwarded from a tap or
+ * injected by a packet socket can carry an arbitrary value, while the
+ * mss field of the TSO context descriptor is only 14 bits wide.
+ *
+ * A too big MSS is dropped here instead of being rejected from
+ * gve_features_check_dqo(), because software segmentation would
+ * produce packets larger than the device can send.
+ */
+ if (unlikely(shinfo->gso_size > GVE_TX_MAX_TSO_MSS_DQO))
+ return -1;
+
/* Needed because we will modify header. */
err = skb_cow_head(skb, 0);
if (err < 0)
@@ -964,7 +978,17 @@ netdev_features_t gve_features_check_dqo(struct sk_buff *skb,
struct net_device *dev,
netdev_features_t features)
{
- if (skb_is_gso(skb) && !gve_can_send_tso(skb))
+ if (!skb_is_gso(skb))
+ return features;
+
+ /* Keep the GSO bits for a too big MSS, so that gve_prep_tso() drops
+ * the packet: software segmentation would give packets larger than
+ * the device can send.
+ */
+ if (skb_shinfo(skb)->gso_size > GVE_TX_MAX_TSO_MSS_DQO)
+ return features;
+
+ if (!gve_can_send_tso(skb))
return features & ~NETIF_F_GSO_MASK;
return features;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 222/457] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 221/457] gve: DQO: reject TSO packets with an out of range MSS Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 223/457] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
` (245 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 72f9dd522f8d6c5a00be9695c7bb74631eb5069e ]
In llc_conn_ac_resend_i_xxx_x_set_0_or_send_rr(), if llc_mac_hdr_init()
fails, kfree_skb(skb) is called instead of kfree_skb(nskb). This leaks
the newly allocated nskb, reads from the freed skb via LLC_I_GET_NR(pdu),
and double-frees skb when llc_conn_state_process() drops its reference.
In llc_sap_action_send_xid_r() and llc_sap_action_send_test_r(), nskb is
leaked if llc_mac_hdr_init() returns an error.
Free nskb in all three error paths.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/llc/llc_c_ac.c | 2 +-
net/llc/llc_s_ac.c | 4 ++++
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/llc/llc_c_ac.c b/net/llc/llc_c_ac.c
index 724ecd741d4cf..1aa7fe28acddb 100644
--- a/net/llc/llc_c_ac.c
+++ b/net/llc/llc_c_ac.c
@@ -437,7 +437,7 @@ int llc_conn_ac_resend_i_xxx_x_set_0_or_send_rr(struct sock *sk,
if (likely(!rc))
llc_conn_send_pdu(sk, nskb);
else
- kfree_skb(skb);
+ kfree_skb(nskb);
}
if (rc) {
nr = LLC_I_GET_NR(pdu);
diff --git a/net/llc/llc_s_ac.c b/net/llc/llc_s_ac.c
index 98deee5603735..831998211b52e 100644
--- a/net/llc/llc_s_ac.c
+++ b/net/llc/llc_s_ac.c
@@ -121,6 +121,8 @@ int llc_sap_action_send_xid_r(struct llc_sap *sap, struct sk_buff *skb)
rc = llc_mac_hdr_init(nskb, mac_sa, mac_da);
if (likely(!rc))
rc = dev_queue_xmit(nskb);
+ else
+ kfree_skb(nskb);
out:
return rc;
}
@@ -170,6 +172,8 @@ int llc_sap_action_send_test_r(struct llc_sap *sap, struct sk_buff *skb)
rc = llc_mac_hdr_init(nskb, mac_sa, mac_da);
if (likely(!rc))
rc = dev_queue_xmit(nskb);
+ else
+ kfree_skb(nskb);
out:
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 223/457] bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 222/457] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 224/457] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
` (244 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
bridge, Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ac704ff08e511c87643799c385f55ecd69b85e03 ]
If llc_mac_hdr_init() fails (for instance if the port device type does
not support LLC or dev_hard_header() fails), br_send_bpdu() should drop
the skb instead of resetting the mac header to the LLC payload and
transmitting a malformed frame.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Cc: Ido Schimmel <idosch@nvidia.com>
Cc: bridge@lists.linux.dev
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260924082951.1599377-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_stp_bpdu.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/bridge/br_stp_bpdu.c b/net/bridge/br_stp_bpdu.c
index 74ec42ba1e7d0..21d092f5acbb8 100644
--- a/net/bridge/br_stp_bpdu.c
+++ b/net/bridge/br_stp_bpdu.c
@@ -52,7 +52,10 @@ static void br_send_bpdu(struct net_bridge_port *p,
LLC_SAP_BSPAN, LLC_PDU_CMD);
llc_pdu_init_as_ui_cmd(skb);
- llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr);
+ if (llc_mac_hdr_init(skb, p->dev->dev_addr, p->br->group_addr)) {
+ kfree_skb(skb);
+ return;
+ }
skb_reset_mac_header(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 224/457] net/sched: sch_teql: fix shadowed err in __teql_resolve()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 223/457] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 225/457] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
` (243 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jamal Hadi Salim, Jiri Pirko,
Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 907b978e82cb4c1c245fc2985bb27c5d5c88c8f6 ]
__teql_resolve() declares an inner 'int err;' inside the
'if (neigh_event_send(n, skb_res) == 0)' block, shadowing the outer
'int err = 0;'. As a result, a negative return from dev_hard_header()
is written to the inner variable and __teql_resolve() still returns 0.
Remove the shadowed variable and set the outer err to -EINVAL when
dev_hard_header() returns a negative error.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Jiri Pirko <jiri@resnulli.us>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/sched/sch_teql.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/net/sched/sch_teql.c b/net/sched/sch_teql.c
index 9e52afc2d9808..409ce50cc0dbc 100644
--- a/net/sched/sch_teql.c
+++ b/net/sched/sch_teql.c
@@ -265,14 +265,11 @@ __teql_resolve(struct sk_buff *skb, struct sk_buff *skb_res,
}
if (neigh_event_send(n, skb_res) == 0) {
- int err;
char haddr[MAX_ADDR_LEN];
neigh_ha_snapshot(haddr, n, dev);
- err = dev_hard_header(skb, dev, ntohs(skb_protocol(skb, false)),
- haddr, NULL, skb->len);
-
- if (err < 0)
+ if (dev_hard_header(skb, dev, ntohs(skb_protocol(skb, false)),
+ haddr, NULL, skb->len) < 0)
err = -EINVAL;
} else {
err = (skb_res == NULL) ? -EAGAIN : 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 225/457] vlan: ensure sufficient headroom in vlan_dev_hard_header()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 224/457] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 226/457] ovl: fix UAF in ovl_do_mkdir() debug print Greg Kroah-Hartman
` (242 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zixuan Chai, Hangbin Liu,
Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit cd5dd68267c4238795fadaf02b3575ca3f8a6500 ]
Callers that only reserve ETH_HLEN or less (such as llc_alloc_frame()),
or skbs allocated before dynamic device/headroom changes (e.g. toggling
VLAN_FLAG_REORDER_HDR or bonding/team switching slaves), can reach
vlan_dev_hard_header() with insufficient headroom and trigger
skb_under_panic().
Use skb_cow_head() in vlan_dev_hard_header() when VLAN_FLAG_REORDER_HDR
is not set to ensure sufficient headroom for the VLAN header(s) and the
underlying device hard header.
Use READ_ONCE() to read dev->hard_header_len and dev->needed_headroom as
they can be updated concurrently under RTNL (e.g. in
vlan_transfer_features()) while vlan_dev_hard_header() runs locklessly on
the transmit path. Also avoid LL_RESERVED_SPACE(dev) here so that the
extra HH_DATA_MOD alignment padding does not trigger unnecessary
pskb_expand_head() reallocations on inner stacked VLAN devices after the
outer VLAN header has been pushed.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Zixuan Chai <petalzu987@gmail.com>
Closes: https://lore.kernel.org/netdev/cover.1789987105.git.petalzu987@gmail.com/
Link: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Hangbin Liu <liuhangbin@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/8021q/vlan_dev.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/8021q/vlan_dev.c b/net/8021q/vlan_dev.c
index 2859cbac3f266..c949c6a829456 100644
--- a/net/8021q/vlan_dev.c
+++ b/net/8021q/vlan_dev.c
@@ -55,6 +55,11 @@ static int vlan_dev_hard_header(struct sk_buff *skb, struct net_device *dev,
int rc;
if (!(vlan->flags & VLAN_FLAG_REORDER_HDR)) {
+ unsigned int hlen = READ_ONCE(dev->hard_header_len) +
+ READ_ONCE(dev->needed_headroom);
+
+ if (skb_cow_head(skb, hlen) < 0)
+ return -ENOMEM;
vhdr = skb_push(skb, VLAN_HLEN);
vlan_tci = vlan->vlan_id;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 226/457] ovl: fix UAF in ovl_do_mkdir() debug print
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 225/457] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 227/457] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
` (241 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+ced26b784bf977d223dd,
Amir Goldstein, Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amir Goldstein <amir73il@gmail.com>
[ Upstream commit ae146bc1abdeb4607abf2975b858c053024e8ac1 ]
ovl_do_mkdir() prints the input dentry with %pd after vfs_mkdir().
Since commit fe497f0759e0 ("VFS: change vfs_mkdir() to unlock on
failure."), vfs_mkdir() calls end_creating() on the input dentry on
failure and may replace it on success, so the post-call %pd can
use-after-free the dentry when CONFIG_OVERLAY_FS_DEBUG is enabled.
Print the dentry before the call and only the result afterward.
Reported-by: syzbot+ced26b784bf977d223dd@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ced26b784bf977d223dd
Fixes: fe497f0759e0 ("VFS: change vfs_mkdir() to unlock on failure.")
Signed-off-by: Amir Goldstein <amir73il@gmail.com>
Link: https://patch.msgid.link/20260921104013.40475-1-amir73il@gmail.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/overlayfs/overlayfs.h | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/overlayfs/overlayfs.h b/fs/overlayfs/overlayfs.h
index b75df37f70ac3..3fea90fe37c75 100644
--- a/fs/overlayfs/overlayfs.h
+++ b/fs/overlayfs/overlayfs.h
@@ -254,8 +254,10 @@ static inline struct dentry *ovl_do_mkdir(struct ovl_fs *ofs,
{
struct dentry *ret;
+ /* vfs_mkdir() drops @dentry on failure and may replace it on success */
+ pr_debug("mkdir(%pd2, 0%o)\n", dentry, mode);
ret = vfs_mkdir(ovl_upper_mnt_idmap(ofs), dir, dentry, mode, NULL);
- pr_debug("mkdir(%pd2, 0%o) = %i\n", dentry, mode, PTR_ERR_OR_ZERO(ret));
+ pr_debug("...mkdir = %i\n", PTR_ERR_OR_ZERO(ret));
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 227/457] autofs: fix sbi->pipe file reference leak in autofs_kill_sb()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 226/457] ovl: fix UAF in ovl_do_mkdir() debug print Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 228/457] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
` (240 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
[ Upstream commit aa5e44b29ffe4eaa08cc2237fd65bc2596bc023e ]
When autofs_fill_super() fails before clearing AUTOFS_SBI_CATATONIC (for
example, when find_get_pid() fails on an invalid pgrp mount option, or
when an fs_context is closed before mounting), deactivate_locked_super()
invokes autofs_kill_sb() -> autofs_catatonic_mode(sbi).
Because AUTOFS_SBI_CATATONIC is still set in sbi->flags,
autofs_catatonic_mode() returns early without calling fput(sbi->pipe),
permanently leaking the pipe struct file reference.
Explicitly release sbi->pipe in autofs_kill_sb() if it is still non-NULL
after autofs_catatonic_mode().
Fixes: ebc921ca9b92 ("autofs: copy autofs4 to autofs")
Signed-off-by: Hui Peng <benquike@gmail.com>
Link: https://patch.msgid.link/20260919204808.2812930-1-benquike@gmail.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/autofs/inode.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/autofs/inode.c b/fs/autofs/inode.c
index 6b15a3717ba7e..066c16f2ea569 100644
--- a/fs/autofs/inode.c
+++ b/fs/autofs/inode.c
@@ -51,6 +51,10 @@ void autofs_kill_sb(struct super_block *sb)
if (sbi) {
/* Free wait queues, close pipe */
autofs_catatonic_mode(sbi);
+ if (sbi->pipe) {
+ fput(sbi->pipe);
+ sbi->pipe = NULL;
+ }
put_pid(sbi->oz_pgrp);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 228/457] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 227/457] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 229/457] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
` (239 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Dapeng Mi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit cec38d5c098a350dcf084d345025136ade7e6d1e ]
When reinstating PEBS counters into PERF_GLOBAL_CTRL for a KVM guest, mask
the value with perf's desired/original PERF_GLOBAL_CTRL value to ensure
KVM doesn't unintentionally set reserved bits in PERF_GLOBAL_CTRL. E.g.
if the guest's PEBS_ENABLE value had bit 63, "Enable Precise Store", set,
then using the raw guest PEBS value would propagate bit 63 to the guest's
PERF_GLOBAL_CTRL value (which thankfully would be a failed VM-Entry, not
a VMX Abort).
The only reason this bug isn't reachable is because KVM doesn't support
"Enable Precise Store" (which is probably a KVM bug?), i.e. bit 63 can't
be set in kvm_pmu->pebs_enable and thus not in arr[pebs_enable].guest. In
other words, this _should_ be a glorified NOP in the current code base.
Fixes: c59a1f106f5c ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-2-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index 24c1f40595449..cf39dd2111cb9 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -5361,7 +5361,7 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
arr[pebs_enable].guest &= ~kvm_pmu->host_cross_mapped_mask;
arr[global_ctrl].guest &= ~kvm_pmu->host_cross_mapped_mask;
/* Set hw GLOBAL_CTRL bits for PEBS counter when it runs for guest */
- arr[global_ctrl].guest |= arr[pebs_enable].guest;
+ arr[global_ctrl].guest |= intel_ctrl & arr[pebs_enable].guest;
}
return arr;
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 229/457] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 228/457] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 230/457] perf/x86/intel: Dont pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused Greg Kroah-Hartman
` (238 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Dapeng Mi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 4b64dbdc5861477f148e13d1ed127e7fe7182e4f ]
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
*never* insert an entry for PEBS_ENABLED if the CPU properly isolates PEBS
events, in which case disabling counters via PERF_GLOBAL_CTRL is sufficient
to prevent unwanted PEBS events in the guest (or host). Because perf loads
PEBS_ENABLE with the unfiltered cpu_hw_events.pebs_enabled, i.e. with both
host and guest masks, there is no need to load different values for the
guest versus host, perf+KVM can and should simply control which counters
are enabled/disabled via PERF_GLOBAL_CTRL.
Avoiding touching PEBS_ENABLED "fixes" a bug where PEBS_ENABLED can end up
with "stuck" bits if a PEBS event is throttled between generating the list
and actually entering the guest (Intel CPUs can't arbtitrarily block NMIs).
Fixes in quotes because leaving PEBS_ENABLED as-is doesn't fix the
underlying problem of perf (via PMIs) being able to modify state after the
perf<=>KVM handoff.
But not writing PEBS_ENABLED is desirable no matter what, as stating the
obvious, leaving PEBS_ENABLED as-is avoids three MSR writes on every VMX
transition: one each on entry/exit, and one more explicit WRMSR to zero
PEBS_ENABLED before VM-Entry (KVM assumes the only reason PEBS_ENABLED is
in the load list is if the CPU lacks PEBS isolation and thus needs a
quiescent period).
Opportunistically add comments to (better) explain the rules for generating
the set of PEBS counters that will be active while the guest is running,
along with a FIXME for the suspected hack-a-fix where perf disables guest
PEBS if _any_ PEBS event is configured to count in the host (commit
854250329c02 ("KVM: x86/pmu: Disable guest PEBS temporarily in two rare
situations") doesn't explain the motivation, at all).
Fixes: c59a1f106f5c ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-3-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 55 ++++++++++++++++++++++++------------
1 file changed, 37 insertions(+), 18 deletions(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index cf39dd2111cb9..b927f0e88e7fc 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -5294,12 +5294,15 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
struct kvm_pmu *kvm_pmu = (struct kvm_pmu *)data;
u64 intel_ctrl = hybrid(cpuc->pmu, intel_ctrl);
u64 pebs_mask = cpuc->pebs_enabled & x86_pmu.pebs_capable;
- int global_ctrl, pebs_enable;
+ u64 guest_pebs_mask;
+ int global_ctrl;
/*
* In addition to obeying exclude_guest/exclude_host, remove bits being
* used for PEBS when running a guest, because PEBS writes to virtual
- * addresses (not physical addresses).
+ * addresses (not physical addresses). If the guest wants to utilize
+ * PEBS, and PEBS can be safely enabled in the guest, bits for the guest's
+ * PEBS-enabled counters will be OR'd back in as appropriate.
*/
*nr = 0;
global_ctrl = (*nr)++;
@@ -5346,24 +5349,40 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
};
}
- pebs_enable = (*nr)++;
- arr[pebs_enable] = (struct perf_guest_switch_msr){
- .msr = MSR_IA32_PEBS_ENABLE,
- .host = cpuc->pebs_enabled & ~cpuc->intel_ctrl_guest_mask,
- .guest = pebs_mask & ~cpuc->intel_ctrl_host_mask & kvm_pmu->pebs_enable,
- };
+ /*
+ * Restrict guest PEBS events to counters that (a) perf supports, (b)
+ * the guest wants to use for PEBS, (c) are not excluded from counting
+ * in the guest, and (d) _are_ excluded from counting in the host.
+ */
+ guest_pebs_mask = pebs_mask & intel_ctrl & kvm_pmu->pebs_enable &
+ ~cpuc->intel_ctrl_host_mask &
+ cpuc->intel_ctrl_guest_mask;
- if (arr[pebs_enable].host) {
- /* Disable guest PEBS if host PEBS is enabled. */
- arr[pebs_enable].guest = 0;
- } else {
- /* Disable guest PEBS thoroughly for cross-mapped PEBS counters. */
- arr[pebs_enable].guest &= ~kvm_pmu->host_cross_mapped_mask;
- arr[global_ctrl].guest &= ~kvm_pmu->host_cross_mapped_mask;
- /* Set hw GLOBAL_CTRL bits for PEBS counter when it runs for guest */
- arr[global_ctrl].guest |= intel_ctrl & arr[pebs_enable].guest;
- }
+ /*
+ * Disable counters where the guest PMC is different than the host PMC
+ * being used on behalf of the guest, as the PEBS record includes
+ * PERF_GLOBAL_STATUS, i.e. the guest will see overflow status for the
+ * wrong counter(s).
+ */
+ guest_pebs_mask &= ~kvm_pmu->host_cross_mapped_mask;
+
+ /*
+ * FIXME: Allow guest and host usage of PEBS events to co-exist instead
+ * of disabling guest PEBS entirely if the host is using PEBS.
+ * What exactly goes wrong if guest and host are using PEBS is
+ * unknown.
+ */
+ if (pebs_mask & ~cpuc->intel_ctrl_guest_mask)
+ guest_pebs_mask = 0;
+ /*
+ * Do NOT mess with PEBS_ENABLED. As above, disabling counters via
+ * PERF_GLOBAL_CTRL is sufficient, and loading a stale PEBS_ENABLED,
+ * e.g. on VM-Exit, can put the system in a bad state. Simply enable
+ * counters in PERF_GLOBAL_CTRL, as perf load PEBS_ENABLED with the
+ * full value, i.e. perf *also* relies on PERF_GLOBAL_CTRL.
+ */
+ arr[global_ctrl].guest |= guest_pebs_mask;
return arr;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 230/457] perf/x86/intel: Dont pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 229/457] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 231/457] perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs() Greg Kroah-Hartman
` (237 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Jim Mattson, Dapeng Mi,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit d06260e99eb93d2942b7af4ccd789eb8a6c829d3 ]
When filling the list of MSRs to be loaded by KVM on VM-Enter and VM-Exit,
load the guest values for DS_AREA and (conditionally) MSR_PEBS_DATA_CFG if
and only if PEBS will be active in the guest, i.e. only if a PEBS record
may be generated while running the guest. As shown by the !pebs_ept path,
it's perfectly safe to run with the host's DS_AREA, so long as PEBS-enabled
counters are disabled via PERF_GLOBAL_CTRL.
Omitting DS_AREA and MSR_PEBS_DATA_CFG when PEBS is unused saves two MSR
writes per MSR on each VMX transition, i.e. eliminates two/four pointless
MSR writes on each VMX roundtrip when PEBS isn't being used by the guest.
Fixes: c59a1f106f5c ("KVM: x86/pmu: Add IA32_PEBS_ENABLE MSR emulation for extended PEBS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Jim Mattson <jmattson@google.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-4-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 39 +++++++++++++++++++++++-------------
1 file changed, 25 insertions(+), 14 deletions(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index b927f0e88e7fc..b9d7fdf6c6585 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -5332,23 +5332,14 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
return arr;
}
+ /*
+ * If the guest won't use PEBS or the CPU doesn't support PEBS in the
+ * guest, then there's nothing more to do as disabling PMCs via
+ * PERF_GLOBAL_CTRL is sufficient on CPUs with guest/host isolation.
+ */
if (!kvm_pmu || !x86_pmu.pebs_ept)
return arr;
- arr[(*nr)++] = (struct perf_guest_switch_msr){
- .msr = MSR_IA32_DS_AREA,
- .host = (unsigned long)cpuc->ds,
- .guest = kvm_pmu->ds_area,
- };
-
- if (x86_pmu.intel_cap.pebs_baseline) {
- arr[(*nr)++] = (struct perf_guest_switch_msr){
- .msr = MSR_PEBS_DATA_CFG,
- .host = cpuc->active_pebs_data_cfg,
- .guest = kvm_pmu->pebs_data_cfg,
- };
- }
-
/*
* Restrict guest PEBS events to counters that (a) perf supports, (b)
* the guest wants to use for PEBS, (c) are not excluded from counting
@@ -5375,6 +5366,26 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
if (pebs_mask & ~cpuc->intel_ctrl_guest_mask)
guest_pebs_mask = 0;
+ /*
+ * Context switch DS_AREA and PEBS_DATA_CFG if and only if PEBS will be
+ * active in the guest; if no records will be generated while the guest
+ * is running, then simply keep the host values resident in hardware.
+ */
+ arr[(*nr)++] = (struct perf_guest_switch_msr){
+ .msr = MSR_IA32_DS_AREA,
+ .host = (unsigned long)cpuc->ds,
+ .guest = guest_pebs_mask ? kvm_pmu->ds_area : (unsigned long)cpuc->ds,
+ };
+
+ if (x86_pmu.intel_cap.pebs_baseline) {
+ arr[(*nr)++] = (struct perf_guest_switch_msr){
+ .msr = MSR_PEBS_DATA_CFG,
+ .host = cpuc->active_pebs_data_cfg,
+ .guest = guest_pebs_mask ? kvm_pmu->pebs_data_cfg :
+ cpuc->active_pebs_data_cfg,
+ };
+ }
+
/*
* Do NOT mess with PEBS_ENABLED. As above, disabling counters via
* PERF_GLOBAL_CTRL is sufficient, and loading a stale PEBS_ENABLED,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 231/457] perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 230/457] perf/x86/intel: Dont pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 232/457] perf/x86/intel: Delete dead NVL PEBS data-source initcall Greg Kroah-Hartman
` (236 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
Peter Zijlstra (Intel), Ingo Molnar, Jim Mattson, Dapeng Mi,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit a391618e1d563f099e4c2a704f45d08329ccdf7c ]
Drop "support" for passing a NULL @data/@kvm_pmu param when getting guest
MSRs. KVM, the only in-tree user, unconditionally passes a non-NULL
pointer, and carrying code that suggests @data may be NULL is confusing,
e.g. incorrectly implies that there are scenarios where KVM doesn't pass
a PMU context.
Fixes: 8183a538cd95 ("KVM: x86/pmu: Add IA32_DS_AREA MSR emulation to support guest DS")
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Jim Mattson <jmattson@google.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260921191418.950933-5-seanjc@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index b9d7fdf6c6585..41134233fc512 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -5333,11 +5333,11 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
}
/*
- * If the guest won't use PEBS or the CPU doesn't support PEBS in the
- * guest, then there's nothing more to do as disabling PMCs via
- * PERF_GLOBAL_CTRL is sufficient on CPUs with guest/host isolation.
+ * If the CPU doesn't support PEBS in the guest, then there's nothing
+ * more to do as disabling PMCs via PERF_GLOBAL_CTRL is sufficient on
+ * CPUs with guest/host isolation.
*/
- if (!kvm_pmu || !x86_pmu.pebs_ept)
+ if (!x86_pmu.pebs_ept)
return arr;
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 232/457] perf/x86/intel: Delete dead NVL PEBS data-source initcall
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 231/457] perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 233/457] perf/core: Fix a refcount leak in attach_perf_ctx_data() Greg Kroah-Hartman
` (235 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
[ Upstream commit 858b37ca19d3f695f7fa94cd14be5a856fd8e7d7 ]
Nova Lake now uses the OMR data-source table for PEBS data-source
decoding and no longer depends on the legacy static pebs_data_source[]
mapping.
Remove the dead intel_pmu_pebs_data_source_lnl() initialization call
for NVL.
Fixes: c847a208f43b ("perf/x86/intel: Add core PMU support for Novalake")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-9-dapeng1.mi@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/core.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index 41134233fc512..689acaeeabada 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -8785,8 +8785,6 @@ __init int intel_pmu_init(void)
/* Initialize Atom core specific PerfMon capabilities.*/
pmu = &x86_pmu.hybrid_pmu[X86_HYBRID_PMU_ATOM_IDX];
intel_pmu_init_arw(&pmu->pmu);
-
- intel_pmu_pebs_data_source_lnl();
break;
default:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 233/457] perf/core: Fix a refcount leak in attach_perf_ctx_data()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 232/457] perf/x86/intel: Delete dead NVL PEBS data-source initcall Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 234/457] perf/core: Fill branch entries with a single assignment Greg Kroah-Hartman
` (234 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namhyung Kim, Peter Zijlstra (Intel),
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namhyung Kim <namhyung@kernel.org>
[ Upstream commit cca4980630b3c7a85f53cb43c6018184ce5d4e37 ]
The attach_perf_ctx_data() can race on global and !global cases. The
global case is protected by global_ctx_data_rwsem and shares a single
reference count using perf_ctx_data.global field.
But when it races with !global case, it may miss to set the global field
and result in a reference count leak.
CPU1 CPU2
----------------------------------------------------------------
attach_task_ctx_data(.global=1) attach_task_ctx_data(.global=0)
cd1 = alloc_perf_ctx_data(); cd2 = alloc_perf_ctx_data();
// { .global = 0, .refcount = 1 };
try_cmpxchg(); // success,
// task->perf_ctx_data = cd2
try_cmpxhg(); // fail; old = cd2
refcount_inc_not_zero(&old->refcount); // success
// old.refcount = 2
free_perf_ctx_data(cd1);
Then later detach_global_ctx_data() will see the data but it's not
marked as global, so it won't call detach_task_ctx_data().
Fixes: 506e64e710ff ("perf: attach/detach PMU specific data")
Assisted-by: Sashiko.dev:Gemini-3.1-pro
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260920231639.11910-1-namhyung@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/events/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/events/core.c b/kernel/events/core.c
index 60e60809bedc7..866c595321868 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -5454,6 +5454,8 @@ attach_task_ctx_data(struct task_struct *task, struct kmem_cache *ctx_cache,
}
if (refcount_inc_not_zero(&old->refcount)) {
+ if (global)
+ old->global = true;
free_perf_ctx_data(cd); /* unused */
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 234/457] perf/core: Fill branch entries with a single assignment
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 233/457] perf/core: Fix a refcount leak in attach_perf_ctx_data() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 235/457] sched/core: Account PSI IRQ time to the execution context, not the scheduling context Greg Kroah-Hartman
` (233 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Peter Zijlstra, Puranjay Mohan,
Yifan Wu, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Puranjay Mohan <puranjay@kernel.org>
[ Upstream commit 24b620729e53d978b3e425f55bc66efd3bab1f59 ]
perf_clear_branch_entry_bitfields() clears the bitfields of struct
perf_branch_entry one by one and leaves from/to alone, since callers
overwrite those straight away. The list has to be kept in sync with the
struct by hand and has already fallen behind: new_type and priv were
added to perf_branch_entry and never added here.
Only BRBE writes those two, and neither for every record.
brbe_set_perf_entry_type() leaves new_type alone for a branch type it
does not recognise, and priv is not set for source-only records.
arm_pmuv3.c allocates the per-CPU branch stack with kmalloc(), so such a
record reaches userspace with whatever the slot held: uninitialised
kmalloc() data on the first pass over the buffer, the previous record's
values after that. Nothing under arch/x86/events/ writes either field,
so only arm64 is affected.
Assign the whole entry at each site instead. Everything not named is
then zero, and there is no list to keep in sync. The bitfields add up to
exactly 64 bits, so the struct has no padding to leave undefined.
perf_clear_branch_entry_bitfields() has no callers left, so remove it.
perf_entry_from_brbe_regset() assigns an empty literal instead, since it
fills from/to conditionally. PERF_BR_SPEC_NA is 0, so dropping the
explicit spec assignment changes nothing.
Fixes: b190bc4ac9e6 ("perf: Extend branch type classification")
Fixes: 5402d25aa571 ("perf: Capture branch privilege information")
Suggested-by: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Puranjay Mohan <puranjay@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yifan Wu <wuyifan50@huawei.com>
Link: https://patch.msgid.link/20260810133540.1947118-4-puranjay@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/amd/brs.c | 9 +++--
arch/x86/events/amd/lbr.c | 16 ++++-----
arch/x86/events/intel/lbr.c | 65 ++++++++++++++++++++-----------------
drivers/perf/arm_brbe.c | 2 +-
include/linux/perf_event.h | 17 ----------
5 files changed, 48 insertions(+), 61 deletions(-)
diff --git a/arch/x86/events/amd/brs.c b/arch/x86/events/amd/brs.c
index dc564688f3d73..54b13faba116c 100644
--- a/arch/x86/events/amd/brs.c
+++ b/arch/x86/events/amd/brs.c
@@ -343,11 +343,10 @@ void amd_brs_drain(void)
if (!amd_brs_match_plm(event, from, to))
continue;
- perf_clear_branch_entry_bitfields(br+nr);
-
- br[nr].from = from;
- br[nr].to = to;
-
+ br[nr] = (struct perf_branch_entry){
+ .from = from,
+ .to = to,
+ };
nr++;
}
empty:
diff --git a/arch/x86/events/amd/lbr.c b/arch/x86/events/amd/lbr.c
index 9d9c961989d51..a55646fcb8465 100644
--- a/arch/x86/events/amd/lbr.c
+++ b/arch/x86/events/amd/lbr.c
@@ -184,13 +184,6 @@ void amd_pmu_lbr_read(void)
entry.to.split.reserved)
continue;
- perf_clear_branch_entry_bitfields(br + out);
-
- br[out].from = sign_ext_branch_ip(entry.from.split.ip);
- br[out].to = sign_ext_branch_ip(entry.to.split.ip);
- br[out].mispred = entry.from.split.mispredict;
- br[out].predicted = !br[out].mispred;
-
/*
* Set branch speculation information using the status of
* the valid and spec bits.
@@ -208,7 +201,14 @@ void amd_pmu_lbr_read(void)
* speculative and took the correct path
*/
idx = (entry.to.split.valid << 1) | entry.to.split.spec;
- br[out].spec = lbr_spec_map[idx];
+
+ br[out] = (struct perf_branch_entry){
+ .from = sign_ext_branch_ip(entry.from.split.ip),
+ .to = sign_ext_branch_ip(entry.to.split.ip),
+ .mispred = entry.from.split.mispredict,
+ .predicted = !entry.from.split.mispredict,
+ .spec = lbr_spec_map[idx],
+ };
out++;
}
diff --git a/arch/x86/events/intel/lbr.c b/arch/x86/events/intel/lbr.c
index 52d14927a1917..1ed29d58f119f 100644
--- a/arch/x86/events/intel/lbr.c
+++ b/arch/x86/events/intel/lbr.c
@@ -756,10 +756,10 @@ void intel_pmu_lbr_read_32(struct cpu_hw_events *cpuc)
rdmsrq(x86_pmu.lbr_from + lbr_idx, msr_lastbranch.lbr);
- perf_clear_branch_entry_bitfields(br);
-
- br->from = msr_lastbranch.from;
- br->to = msr_lastbranch.to;
+ *br = (struct perf_branch_entry){
+ .from = msr_lastbranch.from,
+ .to = msr_lastbranch.to,
+ };
br++;
}
cpuc->lbr_stack.nr = i;
@@ -847,14 +847,15 @@ void intel_pmu_lbr_read_64(struct cpu_hw_events *cpuc)
if (abort && x86_pmu.lbr_double_abort && out > 0)
out--;
- perf_clear_branch_entry_bitfields(br+out);
- br[out].from = from;
- br[out].to = to;
- br[out].mispred = mis;
- br[out].predicted = pred;
- br[out].in_tx = in_tx;
- br[out].abort = abort;
- br[out].cycles = cycles;
+ br[out] = (struct perf_branch_entry){
+ .from = from,
+ .to = to,
+ .mispred = mis,
+ .predicted = pred,
+ .in_tx = in_tx,
+ .abort = abort,
+ .cycles = cycles,
+ };
out++;
}
cpuc->lbr_stack.nr = out;
@@ -905,6 +906,7 @@ static void intel_pmu_store_lbr(struct cpu_hw_events *cpuc,
struct perf_branch_entry *e;
struct lbr_entry *lbr;
u64 from, to, info;
+ bool mispred;
int i;
for (i = 0; i < x86_pmu.lbr_nr; i++) {
@@ -921,24 +923,27 @@ static void intel_pmu_store_lbr(struct cpu_hw_events *cpuc,
to = rdlbr_to(i, lbr);
info = rdlbr_info(i, lbr);
- perf_clear_branch_entry_bitfields(e);
-
- e->from = from;
- e->to = to;
- e->mispred = get_lbr_mispred(info);
- e->predicted = !e->mispred;
- e->in_tx = !!(info & LBR_INFO_IN_TX);
- e->abort = !!(info & LBR_INFO_ABORT);
- e->cycles = get_lbr_cycles(info);
- e->type = get_lbr_br_type(info);
-
- /*
- * Leverage the reserved field of cpuc->lbr_entries[i] to
- * temporarily store the branch counters information.
- * The later code will decide what content can be disclosed
- * to the perf tool. Pleae see intel_pmu_lbr_counters_reorder().
- */
- e->reserved = (info >> LBR_INFO_BR_CNTR_OFFSET) & LBR_INFO_BR_CNTR_FULL_MASK;
+ mispred = get_lbr_mispred(info);
+
+ *e = (struct perf_branch_entry){
+ .from = from,
+ .to = to,
+ .mispred = mispred,
+ .predicted = !mispred,
+ .in_tx = !!(info & LBR_INFO_IN_TX),
+ .abort = !!(info & LBR_INFO_ABORT),
+ .cycles = get_lbr_cycles(info),
+ .type = get_lbr_br_type(info),
+ /*
+ * Leverage the reserved field of
+ * cpuc->lbr_entries[i] to temporarily store the
+ * branch counters information. The later code will
+ * decide what content can be disclosed to the perf
+ * tool. Pleae see intel_pmu_lbr_counters_reorder().
+ */
+ .reserved = (info >> LBR_INFO_BR_CNTR_OFFSET) &
+ LBR_INFO_BR_CNTR_FULL_MASK,
+ };
}
cpuc->lbr_stack.nr = i;
diff --git a/drivers/perf/arm_brbe.c b/drivers/perf/arm_brbe.c
index ba554e0c846c4..254be4da8ae29 100644
--- a/drivers/perf/arm_brbe.c
+++ b/drivers/perf/arm_brbe.c
@@ -604,7 +604,7 @@ static bool perf_entry_from_brbe_regset(int index, struct perf_branch_entry *ent
return false;
brbinf = bregs.brbinf;
- perf_clear_branch_entry_bitfields(entry);
+ *entry = (struct perf_branch_entry){ };
if (brbe_record_is_complete(brbinf)) {
entry->from = bregs.brbsrc;
entry->to = bregs.brbtgt;
diff --git a/include/linux/perf_event.h b/include/linux/perf_event.h
index 48d851fbd8ea5..310681cccb50a 100644
--- a/include/linux/perf_event.h
+++ b/include/linux/perf_event.h
@@ -1467,23 +1467,6 @@ static inline u32 perf_sample_data_size(struct perf_sample_data *data,
return size;
}
-/*
- * Clear all bitfields in the perf_branch_entry.
- * The to and from fields are not cleared because they are
- * systematically modified by caller.
- */
-static inline void perf_clear_branch_entry_bitfields(struct perf_branch_entry *br)
-{
- br->mispred = 0;
- br->predicted = 0;
- br->in_tx = 0;
- br->abort = 0;
- br->cycles = 0;
- br->type = 0;
- br->spec = PERF_BR_SPEC_NA;
- br->reserved = 0;
-}
-
extern void perf_output_sample(struct perf_output_handle *handle,
struct perf_event_header *header,
struct perf_sample_data *data,
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 235/457] sched/core: Account PSI IRQ time to the execution context, not the scheduling context
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 234/457] perf/core: Fill branch entries with a single assignment Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 236/457] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
` (232 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Peter Zijlstra (Intel),
Ingo Molnar, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhan Xusheng <zhanxusheng1024@gmail.com>
[ Upstream commit a0bb6fac53fa7cf1cadb487b43d4c9276a6b82e3 ]
psi_account_irqtime() has two callers which share rq->psi_irq_time, and
they disagree about the context: __schedule() passes the outgoing rq->curr,
sched_tick() passes rq->donor. Under proxy execution the donor is blocked
on a mutex while rq->curr burns the CPU.
The tick charges PSI_IRQ_FULL to the donor's cgroup and advances the
timestamp, so the call from __schedule() then finds delta <= 0 and charges
nothing. The delta is not counted twice, it lands on the wrong cgroup.
Pass rq->curr, which is what the call read before commit af0c8b2bf67b
("sched: Split scheduler and execution contexts") renamed 'curr' to
'donor' across sched_tick(). Without CONFIG_SCHED_PROXY_EXEC the two rq
members are a union, so this only changes anything where that option is set,
and it depends on EXPERT.
Fixes: af0c8b2bf67b ("sched: Split scheduler and execution contexts")
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/20260918132915.1236312-1-zhanxusheng@xiaomi.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/sched/core.c b/kernel/sched/core.c
index 3d6c55598726f..c104562638e33 100644
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -5802,7 +5802,7 @@ void sched_tick(void)
curr = rq->curr;
donor = rq->donor;
- psi_account_irqtime(rq, donor, NULL);
+ psi_account_irqtime(rq, curr, NULL);
update_rq_clock(rq);
hw_pressure = arch_scale_hw_pressure(cpu_of(rq));
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 236/457] mptcp: return sk_wait_data() errors from recvmsg()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 235/457] sched/core: Account PSI IRQ time to the execution context, not the scheduling context Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 237/457] drm/pagemap: dma-unmap pages before handling migration errors Greg Kroah-Hartman
` (231 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Matthieu Baerts (NGI0),
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
[ Upstream commit 60404266ef3e0a1cd8f7a164060e0c83efb72f4b ]
Commit 581302298524 ("mptcp: error out earlier on disconnect") made
mptcp_recvmsg() stop when sk_wait_data() returns an error. The error is
stored in err, but the function then jumps to a path which returns
copied. When no data was copied, recvmsg() therefore returns zero and
reports a false EOF.
Store the result in copied, which is the value returned by the function.
This also keeps the usual partial-read result when data was copied before
the error.
A recvmsg() blocked in one thread reproduces the issue when another
thread disconnects the same MPTCP socket with connect(AF_UNSPEC).
Before this change recvmsg() returns zero; afterwards it returns -EPIPE.
Fixes: 581302298524 ("mptcp: error out earlier on disconnect")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20260913-b4-send-mptcp-recv-error-v1-1-4eaa3684a8b8@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mptcp/protocol.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mptcp/protocol.c b/net/mptcp/protocol.c
index 49c46498af960..de6f289a6e14e 100644
--- a/net/mptcp/protocol.c
+++ b/net/mptcp/protocol.c
@@ -2401,7 +2401,7 @@ static int mptcp_recvmsg(struct sock *sk, struct msghdr *msg, size_t len,
mptcp_cleanup_rbuf(msk, copied);
err = sk_wait_data(sk, &timeo, last);
if (err < 0) {
- err = copied ? : err;
+ copied = copied ? : err;
goto out_err;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 237/457] drm/pagemap: dma-unmap pages before handling migration errors
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 236/457] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 238/457] vlan: require the MAC header to be present in __vlan_insert_inner_tag() Greg Kroah-Hartman
` (230 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Matthew Brost,
Himal Prasad Ghimiray, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Brost <matthew.brost@intel.com>
[ Upstream commit 9e6372ec2a3990662ae0a67f56ac0aee19848d5b ]
drm_pagemap_migrate_unmap_pages() relies on the pages array to determine
which pages require DMA unmapping. However,
drm_pagemap_migration_unlock_put_pages() clears the array as part of its
cleanup, leaving drm_pagemap_migrate_unmap_pages() with no valid page
information if it is called afterward.
Call drm_pagemap_migrate_unmap_pages() before
drm_pagemap_migration_unlock_put_pages() so the pages array remains
valid during DMA unmapping.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: f86ad0ed620c ("drm/gpusvm, drm/pagemap: Move migration functionality to drm_pagemap")
Cc: stable@vger.kernel.org
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
Link: https://patch.msgid.link/20260902063504.3024362-1-matthew.brost@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_pagemap.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/drm_pagemap.c b/drivers/gpu/drm/drm_pagemap.c
index 89e1ddff84dd2..a0546955d0b9f 100644
--- a/drivers/gpu/drm/drm_pagemap.c
+++ b/drivers/gpu/drm/drm_pagemap.c
@@ -1368,13 +1368,13 @@ int drm_pagemap_evict_to_ram(struct drm_pagemap_devmem *devmem_allocation)
goto err_finalize;
err_finalize:
+ drm_pagemap_migrate_unmap_pages(devmem_allocation->dev, pagemap_addr, dst, npages,
+ DMA_FROM_DEVICE, &state);
if (err)
drm_pagemap_migration_unlock_put_pages(npages, dst);
migrate_device_pages(src, dst, npages);
drm_pagemap_retire_migrated_pages(src, npages);
migrate_device_finalize(src, dst, npages);
- drm_pagemap_migrate_unmap_pages(devmem_allocation->dev, pagemap_addr, dst, npages,
- DMA_FROM_DEVICE, &state);
err_free:
kvfree(buf);
@@ -1494,15 +1494,15 @@ static int __drm_pagemap_migrate_to_ram(struct vm_area_struct *vas,
goto err_finalize;
err_finalize:
+ if (dev)
+ drm_pagemap_migrate_unmap_pages(dev, pagemap_addr, migrate.dst,
+ npages, DMA_FROM_DEVICE,
+ &state);
if (err)
drm_pagemap_migration_unlock_put_pages(npages, migrate.dst);
migrate_vma_pages(&migrate);
drm_pagemap_retire_migrated_pages(migrate.src, npages);
migrate_vma_finalize(&migrate);
- if (dev)
- drm_pagemap_migrate_unmap_pages(dev, pagemap_addr, migrate.dst,
- npages, DMA_FROM_DEVICE,
- &state);
err_free:
kvfree(buf);
err_out:
--
2.53.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 238/457] vlan: require the MAC header to be present in __vlan_insert_inner_tag()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 237/457] drm/pagemap: dma-unmap pages before handling migration errors Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 239/457] x86/mce: Fix hardware debug register corruption on task migration Greg Kroah-Hartman
` (229 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+0ea1ac045375cf05, Xiang Mei,
Simon Horman, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
commit ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a upstream.
__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),
never that mac_len bytes of MAC header are present. Its ETH_HLEN
wrappers - __vlan_insert_tag() under skb_vlan_push(), and
vlan_insert_tag() under validate_xmit_vlan() on the generic transmit
path - therefore rewrite the first 16 bytes at skb->data: a 12-byte
memmove plus two 2-byte stores at +12 and +14. No caller supplies the
bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().
An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a
one-byte AF_PACKET/SOCK_RAW frame. The first vlan push only sets a
hwaccel tag; the next - clsact "action vlan push" or
bpf_skb_vlan_push() - enters the helper with skb->len still 1. The
head comes from skbuff_small_head without __GFP_ZERO, so each push
drags bytes from beyond skb->tail into the frame. After three the
one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised
slab:
0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81
`------------------------------'
only 0x5a was sent; the rest is slab, here the top 56 bits of a
linear-map address
Require the MAC header the helper rewrites to be present, so such a
frame is dropped rather than transmitted.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Reported-by: co+0ea1ac045375cf05@bugs.sh
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915083152.705309-1-xmei5@asu.edu
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/if_vlan.h | 3 +++
1 file changed, 3 insertions(+)
--- a/include/linux/if_vlan.h
+++ b/include/linux/if_vlan.h
@@ -365,6 +365,9 @@ static inline int __vlan_insert_inner_ta
const u8 meta_len = mac_len > ETH_TLEN ? skb_metadata_len(skb) : 0;
struct vlan_ethhdr *veth;
+ if (unlikely(!pskb_may_pull(skb, mac_len)))
+ return -EINVAL;
+
if (skb_cow_head(skb, meta_len + VLAN_HLEN) < 0)
return -ENOMEM;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 239/457] x86/mce: Fix hardware debug register corruption on task migration
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 238/457] vlan: require the MAC header to be present in __vlan_insert_inner_tag() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 240/457] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
` (228 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Borislav Petkov (AMD), Peter Zijlstra (Intel), stable
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
commit b8d1d5b63a8ef532038eebd9d97d406860385668 upstream.
In exc_machine_check_user(), local_db_save() and local_db_restore() are
invoked in the outer entry stubs (DEFINE_IDTENTRY_MCE_USER,
DEFINE_FREDENTRY_MCE, and DEFINE_IDTENTRY_RAW), surrounding
exc_machine_check_user().
However, exc_machine_check_user() calls irqentry_exit_to_user_mode(), which
handles pending thread work and may schedule() if TIF_NEED_RESCHED is set. If
the task migrates to another CPU during schedule(), local_db_restore() runs on
the new CPU with the dr7 state saved from the old CPU. This corrupts the new
CPU's DR7 hardware debug register and leaves the old CPU's DR7 disabled. In
short, local_db_save() and local_db_restore() pair must be run on the same
CPU.
To fix this, move local_db_save() and local_db_restore() inside
exc_machine_check_user() and exc_machine_check_kernel(). In
exc_machine_check_user(), DR7 is saved and restored strictly around
do_machine_check() to avoid schedule() during migration. In
exc_machine_check_kernel(), local_db_save() is called at the entry point to
prevent early memory accesses from triggering nested #DB exceptions, and
restored on all exits.
Fixes: cd840e424f27 ("x86/entry, mce: Disallow #DB during #MC")
Assisted-by: LLM
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: <stable@kernel.org>
Link: https://patch.msgid.link/179005109564.388919.3937970081044095776.stgit@devnote2
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kernel/cpu/mce/core.c | 27 ++++++++++-----------------
1 file changed, 10 insertions(+), 17 deletions(-)
--- a/arch/x86/kernel/cpu/mce/core.c
+++ b/arch/x86/kernel/cpu/mce/core.c
@@ -2108,6 +2108,9 @@ bool filter_mce(struct mce *m)
static __always_inline void exc_machine_check_kernel(struct pt_regs *regs)
{
irqentry_state_t irq_state;
+ unsigned long dr7;
+
+ dr7 = local_db_save();
WARN_ON_ONCE(user_mode(regs));
@@ -2116,20 +2119,26 @@ static __always_inline void exc_machine_
* mce_check_crashing_cpu() for details.
*/
if (mca_cfg.initialized && mce_check_crashing_cpu())
- return;
+ goto out;
irq_state = irqentry_nmi_enter(regs);
do_machine_check(regs);
irqentry_nmi_exit(regs, irq_state);
+out:
+ local_db_restore(dr7);
}
static __always_inline void exc_machine_check_user(struct pt_regs *regs)
{
+ unsigned long dr7;
+
irqentry_enter_from_user_mode(regs);
+ dr7 = local_db_save();
do_machine_check(regs);
+ local_db_restore(dr7);
irqentry_exit_to_user_mode(regs);
}
@@ -2138,21 +2147,13 @@ static __always_inline void exc_machine_
/* MCE hit kernel mode */
DEFINE_IDTENTRY_MCE(exc_machine_check)
{
- unsigned long dr7;
-
- dr7 = local_db_save();
exc_machine_check_kernel(regs);
- local_db_restore(dr7);
}
/* The user mode variant. */
DEFINE_IDTENTRY_MCE_USER(exc_machine_check)
{
- unsigned long dr7;
-
- dr7 = local_db_save();
exc_machine_check_user(regs);
- local_db_restore(dr7);
}
#ifdef CONFIG_X86_FRED
@@ -2169,28 +2170,20 @@ DEFINE_IDTENTRY_MCE_USER(exc_machine_che
*/
DEFINE_FREDENTRY_MCE(exc_machine_check)
{
- unsigned long dr7;
-
- dr7 = local_db_save();
if (user_mode(regs))
exc_machine_check_user(regs);
else
exc_machine_check_kernel(regs);
- local_db_restore(dr7);
}
#endif
#else
/* 32bit unified entry point */
DEFINE_IDTENTRY_RAW(exc_machine_check)
{
- unsigned long dr7;
-
- dr7 = local_db_save();
if (user_mode(regs))
exc_machine_check_user(regs);
else
exc_machine_check_kernel(regs);
- local_db_restore(dr7);
}
#endif
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 240/457] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 239/457] x86/mce: Fix hardware debug register corruption on task migration Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 241/457] x86/sev: Make vTPM SVSM calls preemption-safe Greg Kroah-Hartman
` (227 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikael Etienne, Arthur Husband,
Alvin Lim, Mario Limonciello, Bjorn Helgaas, David Laight,
John Smith, Lennert Buytenhek, Niklas Cassel, Roland Waltersson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
commit 4fde448225123442c5796f54b7a4400e2d3cbaf6 upstream.
Multiple users report data corruption during 64-bit DMA transfers on
systems with AMD NBIO 7.7 and 7.11 controllers.
This occurs when BIOS enables AMD "enhanced atomic operations" on PCIe Root
Ports. When enhanced atomics are enabled, any 64-bit DMA access may be
corrupted.
Disable enhanced atomics using SMN for NBIO 7.7 and 7.11 based models.
Reported-by: Mikael Etienne <mikael1022bzh@gmail.com>
Closes: https://lore.kernel.org/178789300872.392066.15963676631650361573@gmail.com/
Reported-by: Arthur Husband <artmoty@gmail.com>
Closes: https://lore.kernel.org/20260406222335.379935-1-artmoty@gmail.com/
Reported-by: Alvin Lim <alvinwylim@gmail.com>
Closes: https://lore.kernel.org/20260621100844.1224301-1-alvinwylim@gmail.com/
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
[bhelgaas: commit log, s/IOVA/DMA/ in comment]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org
Cc: David Laight <david.laight.linux@gmail.com>
Cc: John Smith <imjohnsmith4000@gmail.com>
Cc: Lennert Buytenhek <kernel@wantstofly.org>
Cc: Niklas Cassel <cassel@kernel.org>
Cc: Roland Waltersson <roland.waltersson@netinsight.net>
Link: https://patch.msgid.link/20260908190600.226485-2-mario.limonciello@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/pci/fixup.c | 99 +++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 99 insertions(+)
--- a/arch/x86/pci/fixup.c
+++ b/arch/x86/pci/fixup.c
@@ -886,6 +886,105 @@ static void quirk_clear_strap_no_soft_re
}
}
DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x15b8, quirk_clear_strap_no_soft_reset_dev2_f0);
+
+/*
+ * Enhanced atomic operations can cause corruption with 64-bit DMA
+ * on these devices.
+ */
+#define RX_ENH_ATOMIC_EN BIT(8)
+
+static const u32 nbio_7_7_pcie_smn_addrs[] = {
+ 0x111401d0,
+ 0x111411d0,
+ 0x111421d0,
+ 0x111431d0,
+ 0x111441d0,
+ 0x112401d0,
+ 0x112411d0,
+ 0x112421d0,
+ 0x112431d0,
+ 0x112441d0,
+ 0x112451d0,
+ 0x113401d0,
+ 0x114401d0,
+};
+
+static const u32 nbio_7_11_pcie_smn_addrs[] = {
+ 0x112401d0,
+ 0x112411d0,
+ 0x112421d0,
+ 0x112431d0,
+ 0x112441d0,
+ 0x112451d0,
+ 0x113401d0,
+ 0x113411d0,
+ 0x113421d0,
+ 0x113431d0,
+ 0x113441d0,
+ 0x113451d0,
+};
+
+static void quirk_amd_nbio_enhanced_atomic(struct pci_dev *host_bridge,
+ const u32 *smn_addrs,
+ size_t nr_smn_addrs)
+{
+ bool changed = false;
+ size_t i;
+ u32 data;
+ int ret;
+
+ for (i = 0; i < nr_smn_addrs; i++) {
+ ret = amd_smn_read(0, smn_addrs[i], &data);
+ if (ret)
+ continue;
+ if (!(data & RX_ENH_ATOMIC_EN))
+ continue;
+ data = data & ~RX_ENH_ATOMIC_EN;
+ ret = amd_smn_write(0, smn_addrs[i], data);
+ if (ret)
+ continue;
+ if (changed)
+ continue;
+ ret = amd_smn_read(0, smn_addrs[i], &data);
+ if (ret)
+ continue;
+ if (data & RX_ENH_ATOMIC_EN)
+ continue;
+ changed = true;
+ }
+
+ if (changed)
+ pci_info(host_bridge, "enhanced atomics disabled\n");
+}
+
+static void quirk_amd_nbio_7_7_disable_enhanced_atomic(struct pci_dev *dev)
+{
+ quirk_amd_nbio_enhanced_atomic(dev, nbio_7_7_pcie_smn_addrs,
+ ARRAY_SIZE(nbio_7_7_pcie_smn_addrs));
+}
+
+static void quirk_amd_nbio_7_11_disable_enhanced_atomic(struct pci_dev *dev)
+{
+ quirk_amd_nbio_enhanced_atomic(dev, nbio_7_11_pcie_smn_addrs,
+ ARRAY_SIZE(nbio_7_11_pcie_smn_addrs));
+}
+
+/* Phoenix, Hawk Point (NBIO 7.7) */
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x14E8,
+ quirk_amd_nbio_7_7_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x14E8,
+ quirk_amd_nbio_7_7_disable_enhanced_atomic);
+
+/* Strix, Krackan, Strix Halo (NBIO 7.11) */
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x1507,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x1507,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_FINAL(PCI_VENDOR_ID_AMD, 0x1122,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+DECLARE_PCI_FIXUP_RESUME(PCI_VENDOR_ID_AMD, 0x1122,
+ quirk_amd_nbio_7_11_disable_enhanced_atomic);
+
#endif
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 241/457] x86/sev: Make vTPM SVSM calls preemption-safe
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 240/457] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 242/457] vsock: ignore empty child namespace mode writes Greg Kroah-Hartman
` (226 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Melody Wang, Borislav Petkov (AMD),
Stefano Garzarella
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Melody Wang <huibo.wang@amd.com>
commit 6c43c72748fffd29dec15cd1f31e9a32949bc437 upstream.
Two functions in the SVSM vTPM guest implementation do not disable
preemption when fetching the SVSM Calling Area Address (CAA).
The SVSM CAA is a per-CPU structure. When a thread is preempted and migrated
to a different CPU after fetching the per-CPU CAA, the SVSM call will execute
on the new CPU with the original CPU's CAA. Which is wrong.
Move the CAA fetching operation inside svsm_perform_call_protocol() which
disables interrupts around the SVSM call and thus runs preemption-safe.
Fixes: 770de678bc28 ("x86/sev: Add SVSM vTPM probe/send_command functions")
Signed-off-by: Melody Wang <huibo.wang@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/a5bc0d4a2c462a0089109e145c21626b244b2ff0.1789345277.git.huibo.wang@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/coco/sev/svsm.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/arch/x86/coco/sev/svsm.c
+++ b/arch/x86/coco/sev/svsm.c
@@ -74,6 +74,14 @@ int svsm_perform_call_protocol(struct sv
flags = native_local_irq_save();
+ /*
+ * 'caa' is a per-CPU variable. To avoid using a stale or incorrect
+ * 'caa' if the task is preempted or migrated to another CPU after it
+ * is fetched, always fetch 'caa' and then issue the SVSM call with
+ * interrupts disabled. This ensures the correct 'caa' is used.
+ */
+ call->caa = svsm_get_caa();
+
ghcb = __sev_get_ghcb(&state);
do {
@@ -321,7 +329,6 @@ int snp_svsm_vtpm_send_command(u8 *buffe
{
struct svsm_call call = {};
- call.caa = svsm_get_caa();
call.rax = SVSM_VTPM_CALL(SVSM_VTPM_CMD);
call.rcx = __pa(buffer);
@@ -345,7 +352,6 @@ bool snp_svsm_vtpm_probe(void)
if (!snp_vmpl)
return false;
- call.caa = svsm_get_caa();
call.rax = SVSM_VTPM_CALL(SVSM_VTPM_QUERY);
if (svsm_perform_call_protocol(&call))
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 242/457] vsock: ignore empty child namespace mode writes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 241/457] x86/sev: Make vTPM SVSM calls preemption-safe Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 243/457] virtio_net: copy zerocopy frags in start_xmit without NAPI Greg Kroah-Hartman
` (225 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luigi Leonardi, Aldo Ariel Panzardo,
Stefano Garzarella, Bobby Eshleman, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit 2ec28c09b320ba241bea8a70ee5cb9ccf4a099e8 upstream.
__vsock_net_mode_string() returns success without updating new_mode when
the transfer length is zero. Its caller then reads the uninitialized enum
and may permanently store a stack-derived value in the write-once child
mode.
Return before calling __vsock_net_mode_string() when *lenp is zero so
that the helper is never invoked with nothing to parse and new_mode is
never read uninitialized. This also prevents an empty write from
locking the current mode.
Fixes: eafb64f40ca4 ("vsock: add netns to vsock core")
Cc: stable@vger.kernel.org
Reviewed-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
Link: https://patch.msgid.link/20260915173050.3176344-1-qwe.aldo@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/vmw_vsock/af_vsock.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/vmw_vsock/af_vsock.c
+++ b/net/vmw_vsock/af_vsock.c
@@ -2873,6 +2873,9 @@ static int vsock_net_child_mode_string(c
net = container_of(table->data, struct net, vsock.child_ns_mode);
+ if (!*lenp)
+ return 0;
+
ret = __vsock_net_mode_string(table, write, buffer, lenp, ppos,
vsock_net_child_mode(net), &new_mode);
if (ret)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 243/457] virtio_net: copy zerocopy frags in start_xmit without NAPI
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 242/457] vsock: ignore empty child namespace mode writes Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 244/457] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
` (224 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, mst, jasowangio, Willem de Bruijn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Willem de Bruijn <willemb@google.com>
commit 07e1a9408b6c2f9d0cfb757b67dabb52da7a32b2 upstream.
Virtio-net without NAPI frees completed skbs lazily on the next
start_xmit. Senders waiting for in-flight zerocopy buffers can
deadlock if they cannot transmit more packets, as then no
completed packets will be freed.
When !use_napi, virtio-net already calls skb_orphan to avoid waiting
up for transmitted skbs to be freed. For zerocopy packets that
require deep copying on orphan (i.e. those that do not set
SKBFL_DONT_ORPHAN, such as PACKET_TX_RING), call skb_orphan_frags
before orphaning to release the buffers.
This fixes the tpacket_snd slot reuse bug on skb_orphan for
virtio-net, and prevents PACKET_TX_RING from running out of slots.
This fix also touches vhost_net zerocopy packets, which also do not
set SKBFL_DONT_ORPHAN. This is fine: vhost_net packets only encounter
virtio-net in nested virtualization, and only if napi_tx is
explicitly disabled (it has been default-enabled since Linux 4.12).
In that rare case, copying the frags is desirable anyway to prevent
holding guest descriptors pinned across unbounded intervals.
This is a prerequisite for the next patch, which converts
PACKET_TX_RING to standard zerocopy completion. Without this patch
first, a bounded ring sender can stall indefinitely behind a
virtio-net virtqueue that cannot reclaim.
Fixes: 5cd8d46ea156 ("packet: copy user buffers before orphan or clone")
Cc: stable@vger.kernel.org
Cc: mst@redhat.com
Cc: jasowangio@gmail.com
Signed-off-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260919004748.1463985-2-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/virtio_net.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/net/virtio_net.c
+++ b/drivers/net/virtio_net.c
@@ -3349,6 +3349,14 @@ static netdev_tx_t start_xmit(struct sk_
else
virtqueue_disable_cb(sq->vq);
+ if (!use_napi &&
+ unlikely(skb_orphan_frags(skb, GFP_ATOMIC))) {
+ DEV_STATS_INC(dev, tx_dropped);
+ dev_kfree_skb_any(skb);
+ kick = !xmit_more || netif_xmit_stopped(txq);
+ goto kick_vq;
+ }
+
/* timestamp packet in software */
skb_tx_timestamp(skb);
@@ -3381,6 +3389,7 @@ static netdev_tx_t start_xmit(struct sk_
kick = use_napi ? __netdev_tx_sent_queue(txq, skb->len, xmit_more) :
!xmit_more || netif_xmit_stopped(txq);
+kick_vq:
if (kick) {
if (virtqueue_kick_prepare(sq->vq) && virtqueue_notify(sq->vq)) {
u64_stats_update_begin(&sq->stats.syncp);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 244/457] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 243/457] virtio_net: copy zerocopy frags in start_xmit without NAPI Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 245/457] tcp: prevent collapsing skbs across boundary in rtx queue Greg Kroah-Hartman
` (223 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Burton, Eric Dumazet,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
commit 99cc2a62e07a44a22254d7beca9ef1f8ad886d0d upstream.
Commit 48a5fe38772b ("tipc: fix bc_ackers underflow on duplicate
GRP_ACK_MSG") rejected duplicate/stale ACKs in tipc_group_proto_rcv()
by returning early when less_eq(acked, m->bc_acked).
However, that check remains incomplete in two ways:
1. When grp->bc_ackers is zero (e.g. on a quiet group, when replicast
ACKs were not requested, or after all expected members have already
acknowledged), an unexpected GRP_ACK_MSG with acked > m->bc_acked
passes less_eq() and unconditionally decrements grp->bc_ackers.
Because bc_ackers is a u16, this wraps to 65535, causing
tipc_group_bc_cong() to permanently report congestion and blocking
all future group broadcasts on the socket.
2. During an active broadcast round (grp->bc_ackers > 0), the sender
transmits packet S and advances grp->bc_snd_nxt to S + 1. Receivers
increment their expected counter to S + 1 upon consuming packet S,
so the only valid ACK value for the current round is strictly
acked == grp->bc_snd_nxt.
However, tipc_group_update_bc_members() initializes each member's
m->bc_acked to prev = grp->bc_snd_nxt - 1 (S - 1 before increment).
This leaves a 2-sequence gap (S - 1 to S + 1) in sequence space.
An incoming ACK is therefore neither rejected as duplicate nor
prevented from decrementing grp->bc_ackers if an unexpected or stale
value (such as S) is received. A member sending acked = S followed
by acked = S + 1 could decrement grp->bc_ackers twice in the same
round, prematurely clearing bc_ackers or underflowing it.
Fix this by:
- Dropping GRP_ACK_MSG immediately if grp->bc_ackers is zero.
- Requiring acked == grp->bc_snd_nxt and rejecting duplicates where
m->bc_acked == acked. Because replicast broadcast rounds are strictly
sequential, only grp->bc_snd_nxt can be acknowledged, and each member
can acknowledge at most once per round.
Note that a related pre-existing issue in tipc_group_delete_member()
(where grp->bc_ackers decrementing to zero upon member departure does
not restore *grp->open or trigger a socket wakeup) will be addressed
in a separate patch.
Fixes: 48a5fe38772b ("tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG")
Fixes: 2f487712b893 ("tipc: guarantee that group broadcast doesn't bypass group unicast")
Reported-by: James Burton <jamesburton@meta.com>
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260913044233.193927-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/tipc/group.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/tipc/group.c
+++ b/net/tipc/group.c
@@ -797,10 +797,10 @@ void tipc_group_proto_rcv(struct tipc_gr
tipc_group_open(m, usr_wakeup);
return;
case GRP_ACK_MSG:
- if (!m)
+ if (!m || !grp->bc_ackers)
return;
acked = msg_grp_bc_acked(hdr);
- if (less_eq(acked, m->bc_acked))
+ if (acked != grp->bc_snd_nxt || m->bc_acked == acked)
return;
m->bc_acked = acked;
if (--grp->bc_ackers)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 245/457] tcp: prevent collapsing skbs across boundary in rtx queue
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 244/457] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 246/457] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
` (222 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Willem de Bruijn, Eric Dumazet,
Daniel Zahka, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Willem de Bruijn <willemb@google.com>
commit fc6d80eb504458d6416b75a94188b268c95c6533 upstream.
tcp_write_collapse_fence() sets TCP_SKB_CB(skb)->eor = 1 on
tcp_write_queue_tail(sk) to prevent skbs queued after a switch to
device encryption from being collapsed into earlier skbs.
The fence is a no-op if all earlier data has already been transmitted
when the switch happens: sk->sk_write_queue is empty. The not yet
acknowledged earlier skbs wait in sk->tcp_rtx_queue with eor 0.
On a subsequent retransmit or SACK shift, tcp_retrans_try_collapse() or
tcp_shift_skb_data() can then merge an skb queued after the switch into
one queued before it.
Both users of the fence are affected:
- psp: devices only encrypt skbs with skb->decrypted set. The merged skb
keeps decrypted = 0 from the earlier skb, so merged data sent after
psp_sock_assoc_set_tx() is retransmitted in cleartext.
- tls device offload: the merged skb straddles the start marker set in
tls_set_device_offload(). The software fallback (fill_sg_in() returns
-EINVAL) and the mlx5, nfp and funeth drivers cannot handle such an
skb and drop it. Every retransmit rebuilds the same skb, so the
connection stalls.
Fix this in two places, for defense in depth:
1. Fall back to tcp_rtx_queue_tail(sk) in tcp_write_collapse_fence()
when tcp_write_queue_tail(sk) is NULL.
2. Check !skb_cmp_decrypted(to, from) in tcp_skb_can_collapse(), as
tcp_skb_can_collapse_rx() does on receive. skb_shift(), which both
collapse paths call, already has a DEBUG_NET_WARN_ON_ONCE() for this
condition.
Fixes: e8f69799810c ("net/tls: Add generic NIC offload infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Willem de Bruijn <willemb@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Daniel Zahka <daniel.zahka@gmail.com>
Link: https://patch.msgid.link/20260924154427.953800-1-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/net/tcp.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/include/net/tcp.h
+++ b/include/net/tcp.h
@@ -1232,9 +1232,9 @@ static inline bool tcp_skb_can_collapse_
static inline bool tcp_skb_can_collapse(const struct sk_buff *to,
const struct sk_buff *from)
{
- /* skb_cmp_decrypted() not needed, use tcp_write_collapse_fence() */
return likely(tcp_skb_can_collapse_to(to) &&
mptcp_skb_can_collapse(to, from) &&
+ !skb_cmp_decrypted(to, from) &&
skb_pure_zcopy_same(to, from) &&
skb_frags_readable(to) == skb_frags_readable(from));
}
@@ -2327,7 +2327,7 @@ static inline void tcp_rtx_queue_unlink_
static inline void tcp_write_collapse_fence(struct sock *sk)
{
- struct sk_buff *skb = tcp_write_queue_tail(sk);
+ struct sk_buff *skb = tcp_write_queue_tail(sk) ?: tcp_rtx_queue_tail(sk);
if (skb)
TCP_SKB_CB(skb)->eor = 1;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 246/457] sctp: discard the rest of the packet on a stale-cookie error
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 245/457] tcp: prevent collapsing skbs across boundary in rtx queue Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 247/457] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
` (221 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xin Long, TencentOS Corvus AI,
Aohan Mei, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit 4498467a8af06cfa3d71cb04bd7c4170dec8f449 upstream.
When an association is in COOKIE-ECHOED state and the peer sends a
bundled [ERROR(Stale Cookie)][DATA] packet from one of its non-primary
addresses, processing the ERROR chunk takes the non-fatal stale-cookie
retry path sctp_sf_do_5_2_6_stale(), which queues
SCTP_CMD_DEL_NON_PRIMARY while keeping the association alive.
sctp_cmd_del_non_primary() removes every non-primary transport -
including the very transport this packet arrived on, which is still
referenced by the receive lookup and shared by all chunks of the
packet via chunk->transport.
sctp_assoc_rm_peer() does redirect asoc->peer.last_data_from away from
the removed transport, but right afterwards the bundled DATA chunk
makes sctp_assoc_bh_rcv() re-register
asoc->peer.last_data_from = chunk->transport unconditionally, undoing
the redirection with the just-removed transport.
Once the packet is done, the receive reference is dropped and the
transport is RCU-freed, while the surviving association keeps the
dangling last_data_from. A later FWD-TSN (or the delayed SACK timer)
makes sctp_gen_sack() dereference it (->param_flags and friends), and
sctp_make_sack()/sctp_outq_select_transport() may write to the freed
object and link it into the live transport list. This is a
use-after-free triggerable by any malicious SCTP peer (or a local
unprivileged user acting as one) with no capabilities required:
BUG: KASAN: slab-use-after-free in sctp_do_sm+0x498a/0x5660
Read of size 4 at addr ffff88800e1e356c by task poc/115
Call Trace: sctp_do_sm <- sctp_assoc_bh_rcv <- sctp_inq_push <-
sctp_rcv <- ip_protocol_deliver_rcu <- ip_rcv
Allocated: sctp_transport_new <- sctp_assoc_add_peer <-
sctp_process_init (INIT-ACK processing)
Freed: kfree <- sctp_transport_destroy_rcu <- rcu_core
(call_rcu queued by sctp_transport_put at end of sctp_rcv)
The buggy address is located 364 bytes inside of freed 1024-byte
region [ffff88800e1e3400, ffff88800e1e3800), cache kmalloc-1k
Note that commit 03a9d10ecf71 ("sctp: drop a chunk if its transport
was removed") only covers the window between the receive lookup and
the chunk processing (e.g. an ASCONF DEL-IP racing the socket backlog);
here the transport is removed *while* the packet is being processed,
by an earlier chunk of the same packet, so the drop in sctp_inq_push()
does not reach this path. Verified with the bundled [ERROR(Stale
Cookie)][DATA] + FWD-TSN reproducer: the KASAN report above still
fires with that commit applied, and is gone with this patch on top.
Fix it by discarding the rest of the packet on this path, as suggested
by Xin. After the stale-cookie ERROR has sent the association back to
COOKIE-WAIT and removed the non-primary transports, the remaining
chunks of the packet can only run against the restarted handshake
while referencing the removed arrival transport through
chunk->transport: besides the last_data_from registration above,
sctp_cmd_setup_t2() and the sctp_make_*() reply builders would also
copy that pointer into association-lifetime state that
sctp_assoc_rm_peer() has already sanitized. Let the peer retransmit
them, in line with what sctp_inq_push() does for chunks whose
transport was removed before processing.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Suggested-by: Xin Long <lucien.xin@gmail.com>
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260921093707.1432184-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sctp/sm_statefuns.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -2654,6 +2654,8 @@ static enum sctp_disposition sctp_sf_do_
sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(reply));
+ sctp_add_cmd_sf(commands, SCTP_CMD_DISCARD_PACKET, SCTP_NULL());
+
return SCTP_DISPOSITION_CONSUME;
nomem:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 247/457] af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 246/457] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 248/457] arm64/boot: Disable trapping of PMZR_EL0 writes to EL2 Greg Kroah-Hartman
` (220 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dairui Zhang, Willem de Bruijn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dairui Zhang <zhangdairui@gmail.com>
commit 56d82862a0a243ac14ba11b6d7b57ddc2d064b95 upstream.
prb_calc_retire_blk_tmo() computes in 32-bit int arithmetic:
mbits = (blk_size_in_bytes * 8) / (1024 * 1024);
If I'm reading the validation right, tp_block_size is user
controlled and packet_set_ring() only rejects values that are <= 0
as int or not page aligned, so a 256MiB block goes right through
(and alloc_one_pg_vec_page() even has a vzalloc fallback for it).
0x10000000 * 8 wraps to INT_MIN, and on a NIC reporting 1 Gbps
(div == 1) the function ends up returning -2047.
The condition is actually (8 * size) mod 2^32 >= 2^31 && div == 1,
so the trigger set is [256,512), [768,1024), [1280,1536) and
[1792,2048) MiB. Other sizes wrap to non-negative values and faster
links divide the unsigned value back below 2^31, which is why this
doesn't blow up for everyone.
What makes it fatal is what happens next in init_prb_bdqc():
p1->interval_ktime = ms_to_ktime(prb_calc_retire_blk_tmo(...));
hrtimer_start(&p1->retire_blk_timer, p1->interval_ktime,
HRTIMER_MODE_REL_SOFT);
A negative relative timeout expires immediately. The callback
unconditionally returns HRTIMER_RESTART, and hrtimer_forward() turns
the negative interval into hrtimer_resolution:
if (interval < hrtimer_resolution)
interval = hrtimer_resolution;
So the SOFT timer re-fires at the maximum rate forever, holding
sk_receive_queue.lock each pass. One CPU spins in softirq until the
socket is closed. Repeat with more rings and the machine is gone.
The overflow itself is ancient - it was introduced together with
TPACKET_V3 in f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer
implementation."). Its effect prior to f7460d2989fa ("net:
af_packet: Use hrtimer to do the retire operation", v6.18) was not
as clear-cut, though: the return value was stored into an unsigned
short retire_blk_tov, so a negative result was truncated, and a
0-jiffy delay loop could be programmed as well. Neither is nearly
as detrimental as the immediate maximum-rate spin the hrtimer
conversion turned it into.
(Unrelated to CVE-2019-20812 - that one was the ethtool failure path
returning 0, which now returns DEFAULT_PRB_RETIRE_TOV.)
Reproducer, needs CAP_NET_RAW (a --network host container has it by
default) and a 1 Gbps NIC (QEMU e1000 works):
int fd = socket(AF_PACKET, SOCK_RAW, htons(ETH_P_ALL));
bind(fd, ...);
int v = TPACKET_V3;
setsockopt(fd, SOL_PACKET, PACKET_VERSION, &v, sizeof(v));
struct tpacket_req3 req = {
.tp_block_size = 0x10000000,
.tp_block_nr = 1,
.tp_frame_size = 2048,
.tp_frame_nr = 0x10000000 / 2048,
.tp_retire_blk_tov = 0,
};
setsockopt(fd, SOL_PACKET, PACKET_RX_RING, &req, sizeof(req));
Compute in 64 bits instead. The operands are already bounded by the
existing validation, so nothing else changes. If you'd prefer a
different fix, just say so and I'll respin.
Fixes: f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Dairui Zhang <zhangdairui@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260923050101.1510064-1-zhangdairui@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/af_packet.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -617,7 +617,7 @@ static int prb_calc_retire_blk_tmo(struc
return DEFAULT_PRB_RETIRE_TOV;
div = ecmd.base.speed / 1000;
- mbits = (blk_size_in_bytes * 8) / (1024 * 1024);
+ mbits = (u64)blk_size_in_bytes * 8 / (1024 * 1024);
if (div)
mbits /= div;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 248/457] arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 247/457] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 249/457] arm64: errata: match the target implementation CPUs own MIDR Greg Kroah-Hartman
` (219 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Anshuman Khandual,
Oliver Upton, Will Deacon
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
commit 2bc6b218717b9d08f466f88209251d54bc09b207 upstream.
__init_el2_fgt2() writes one mask to both HDFGRTR2_EL2 and HDFGWTR2_EL2.
PMZR_EL0 is write-only, so its trap bit, nPMZR_EL0, exists only in
HDFGWTR2_EL2 and is therefore never set: a PMZR_EL0 write from the host
traps to EL2, where the nVHE hypervisor has no handler and BUG()s. The
kernel never writes PMZR_EL0, but kernel.perf_user_access=1 has the PMU
driver set PMUSERENR_EL0.UEN for a task with a user-read event, so a
write from EL0 reaches the trap and takes the host down without a panic
message.
Accumulate the HDFGWTR2_EL2 bits separately, as __init_el2_fgt() already
does for HDFGWTR_EL2, and set nPMZR_EL0 with the other FEAT_PMUv3p9
bits.
Fixes: 858c7bfcb35e1 ("arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Reviewed-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/arch/arm64/booting.rst | 1 +
arch/arm64/include/asm/el2_setup.h | 9 ++++++++-
2 files changed, 9 insertions(+), 1 deletion(-)
--- a/Documentation/arch/arm64/booting.rst
+++ b/Documentation/arch/arm64/booting.rst
@@ -465,6 +465,7 @@ Before jumping into the kernel, the foll
- HDFGWTR2_EL2.nPMICNTR_EL0 (bit 2) must be initialised to 0b1.
- HDFGWTR2_EL2.nPMICFILTR_EL0 (bit 3) must be initialised to 0b1.
- HDFGWTR2_EL2.nPMUACR_EL1 (bit 4) must be initialised to 0b1.
+ - HDFGWTR2_EL2.nPMZR_EL0 (bit 21) must be initialised to 0b1.
For CPUs with SPE data source filtering (FEAT_SPE_FDS):
--- a/arch/arm64/include/asm/el2_setup.h
+++ b/arch/arm64/include/asm/el2_setup.h
@@ -418,6 +418,7 @@
b.lt .Lskip_fgt2_\@
mov x0, xzr
+ mov x2, xzr
mrs x1, id_aa64dfr0_el1
ubfx x1, x1, #ID_AA64DFR0_EL1_PMUVer_SHIFT, #4
cmp x1, #ID_AA64DFR0_EL1_PMUVer_V3P9
@@ -426,6 +427,11 @@
orr x0, x0, #HDFGRTR2_EL2_nPMICNTR_EL0
orr x0, x0, #HDFGRTR2_EL2_nPMICFILTR_EL0
orr x0, x0, #HDFGRTR2_EL2_nPMUACR_EL1
+ orr x2, x2, #HDFGWTR2_EL2_nPMICNTR_EL0
+ orr x2, x2, #HDFGWTR2_EL2_nPMICFILTR_EL0
+ orr x2, x2, #HDFGWTR2_EL2_nPMUACR_EL1
+ /* PMZR_EL0 is write-only, so it has no read trap to disable */
+ orr x2, x2, #HDFGWTR2_EL2_nPMZR_EL0
.Lskip_pmuv3p9_\@:
/* If SPE is implemented, */
__spe_vers_imp .Lskip_spefds_\@, ID_AA64DFR0_EL1_PMSVer_IMP, x1
@@ -436,10 +442,11 @@
cbz x1, .Lskip_spefds_\@
/* disable traps of PMSDSFR to EL2. */
orr x0, x0, #HDFGRTR2_EL2_nPMSDSFR_EL1
+ orr x2, x2, #HDFGWTR2_EL2_nPMSDSFR_EL1
.Lskip_spefds_\@:
msr_s SYS_HDFGRTR2_EL2, x0
- msr_s SYS_HDFGWTR2_EL2, x0
+ msr_s SYS_HDFGWTR2_EL2, x2
msr_s SYS_HFGRTR2_EL2, xzr
msr_s SYS_HFGWTR2_EL2, xzr
msr_s SYS_HFGITR2_EL2, xzr
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 249/457] arm64: errata: match the target implementation CPUs own MIDR
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 248/457] arm64/boot: Disable trapping of PMZR_EL0 writes to EL2 Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 250/457] ata: libata-scsi: bound the ATA passthru sense descriptor writes Greg Kroah-Hartman
` (218 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, David Carlier, Will Deacon
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Carlier <devnexen@gmail.com>
commit b7403afb7a5f85073243df10238b3483958ad69e upstream.
__is_affected_midr_range() is handed the MIDR and REVIDR of one target
implementation CPU, but tests the erratum's range with is_midr_in_range(),
which re-scans all of target_impl_cpus[] and ignores the @midr argument.
The range test is thus constant across the per-CPU loop in
is_affected_midr_range() and only answers "is any target CPU in range".
Since just the fixed_revs REVIDR check uses the iteration's own registers,
an out-of-range target CPU can decide whether a MIDR_FIXED() exemption
applies. A VM then enables a workaround whose only in-range CPU is fixed
silicon, e.g. erratum 2658417 on a Cortex-A510 r1p1 with REVIDR_EL1[25]
set.
Factor the range test into __is_midr_in_range(), which takes an explicit
MIDR, and use it in __is_affected_midr_range().
Fixes: 86edf6bdcf05 ("smccc/kvm_guest: Enable errata based on implementation CPUs")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: David Carlier <devnexen@gmail.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kernel/cpu_errata.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
--- a/arch/arm64/kernel/cpu_errata.c
+++ b/arch/arm64/kernel/cpu_errata.c
@@ -28,18 +28,21 @@ bool cpu_errata_set_target_impl(u64 num,
return true;
}
+static inline bool __is_midr_in_range(u32 midr, struct midr_range const *range)
+{
+ return midr_is_cpu_model_range(midr, range->model,
+ range->rv_min, range->rv_max);
+}
+
static inline bool is_midr_in_range(struct midr_range const *range)
{
int i;
if (!target_impl_cpu_num)
- return midr_is_cpu_model_range(read_cpuid_id(), range->model,
- range->rv_min, range->rv_max);
+ return __is_midr_in_range(read_cpuid_id(), range);
for (i = 0; i < target_impl_cpu_num; i++) {
- if (midr_is_cpu_model_range(target_impl_cpus[i].midr,
- range->model,
- range->rv_min, range->rv_max))
+ if (__is_midr_in_range(target_impl_cpus[i].midr, range))
return true;
}
return false;
@@ -59,7 +62,7 @@ __is_affected_midr_range(const struct ar
u32 midr, u32 revidr)
{
const struct arm64_midr_revidr *fix;
- if (!is_midr_in_range(&entry->midr_range))
+ if (!__is_midr_in_range(midr, &entry->midr_range))
return false;
midr &= MIDR_REVISION_MASK | MIDR_VARIANT_MASK;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 250/457] ata: libata-scsi: bound the ATA passthru sense descriptor writes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 249/457] arm64: errata: match the target implementation CPUs own MIDR Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 251/457] bna: prevent IOC timer rearm during teardown Greg Kroah-Hartman
` (217 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Matthias Goergens,
Niklas Cassel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthias Goergens <matthias.goergens@gmail.com>
commit 80320b278fea07ffcda3f57b67b61658e0a4e1ca upstream.
When an ATA PASS-THROUGH command to an ATAPI device fails, the sense
buffer holds the device's REQUEST SENSE reply, and
ata_scsi_set_passthru_sense_fields() trusts its additional length
byte, sb[7], when adding the ATA Status Return descriptor. A faulty
or malicious device can use that to make the kernel read and write
past the 96-byte buffer in three ways:
- scsi_sense_desc_find() is passed sb[7] + 8 as the buffer length, so
its clamp against sb[7] does nothing and the walk runs off the end.
- A type-9 descriptor found near the end is filled in unchecked.
- A new descriptor at sb[8 + len] needs len + 22 bytes, not len + 14,
so len 75..82 writes up to 8 bytes past the end.
Reproduced with KASAN under qemu, with the emulated ATAPI REQUEST SENSE
reply patched:
BUG: KASAN: slab-out-of-bounds in scsi_sense_desc_find+0x1a5/0x210
BUG: KASAN: slab-out-of-bounds in ata_scsi_qc_complete+0x1a15/0x1a50
Both are gone with this patch, and a valid descriptor is still filled
in.
Fixes: 97981926224a ("ata: libata-scsi: Do not overwrite valid sense data when CK_COND=1")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Matthias Goergens <matthias.goergens@gmail.com>
Link: https://lore.kernel.org/r/20260923175203.1576825-1-matthias.goergens@gmail.com
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libata-scsi.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/drivers/ata/libata-scsi.c
+++ b/drivers/ata/libata-scsi.c
@@ -261,12 +261,18 @@ static void ata_scsi_set_passthru_sense_
/* descriptor format */
len = sb[7];
- desc = (char *)scsi_sense_desc_find(sb, len + 8, 9);
+ desc = (char *)scsi_sense_desc_find(sb, SCSI_SENSE_BUFFERSIZE, 9);
if (!desc) {
- if (SCSI_SENSE_BUFFERSIZE < len + 14)
+ /*
+ * The descriptor is written at sb[8 + len] and is 14
+ * bytes long, so it needs len + 22 bytes of buffer.
+ */
+ if (len + 22 > SCSI_SENSE_BUFFERSIZE)
return;
sb[7] = len + 14;
desc = sb + 8 + len;
+ } else if (desc - sb > SCSI_SENSE_BUFFERSIZE - 14) {
+ return;
}
desc[0] = 9;
desc[1] = 12;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 251/457] bna: prevent IOC timer rearm during teardown
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 250/457] ata: libata-scsi: bound the ATA passthru sense descriptor writes Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 252/457] bpf: fs/xattr: dont assume the inode is locked in path_unlink/path_rmdir Greg Kroah-Hartman
` (216 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 77b1718e39e5c9f6956fb60807326af20baf889d upstream.
bna: prevent IOC timer rearm during teardown
bnad_pci_remove() and the probe disable_ioceth path call
timer_delete_sync() for ioc_timer, sem_timer and hb_timer, but not for
iocpf_timer. bnad_iocpf_timeout() then takes bnad->bna_lock after
free_netdev() has freed the struct bnad.
Deleting iocpf_timer last does not fix this. sem_timer and
iocpf_timer rearm each other: bnad_iocpf_sem_timeout() can arm
iocpf_timer, and bnad_iocpf_timeout() arms sem_timer from
bfa_ioc_hw_sem_get() when the semaphore is busy.
timer_delete_sync() only waits out its own callback.
bnad_ioceth_disable() can time out and leave that callback live.
Shut all four IOC timers down with timer_shutdown_sync() on both
paths, so a later mod_timer() is ignored.
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: 1d32f7696286 ("bna: IOC failure auto recovery fix")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260922014605.588040-1-mhun512@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/brocade/bna/bnad.c | 24 ++++++++++++++++++------
1 file changed, 18 insertions(+), 6 deletions(-)
--- a/drivers/net/ethernet/brocade/bna/bnad.c
+++ b/drivers/net/ethernet/brocade/bna/bnad.c
@@ -2571,6 +2571,22 @@ bnad_ioceth_disable(struct bnad *bnad)
return err;
}
+/*
+ * The IOC timers rearm one another, so deleting one cannot stop a
+ * sibling callback from arming it again. Shut them down so a later
+ * mod_timer() is ignored.
+ */
+static void
+bnad_ioc_timers_shutdown(struct bnad *bnad)
+{
+ struct bfa_ioc *ioc = &bnad->bna.ioceth.ioc;
+
+ timer_shutdown_sync(&ioc->ioc_timer);
+ timer_shutdown_sync(&ioc->sem_timer);
+ timer_shutdown_sync(&ioc->hb_timer);
+ timer_shutdown_sync(&ioc->iocpf_timer);
+}
+
static int
bnad_ioceth_enable(struct bnad *bnad)
{
@@ -3727,9 +3743,7 @@ probe_uninit:
bnad_res_free(bnad, &bnad->mod_res_info[0], BNA_MOD_RES_T_MAX);
disable_ioceth:
bnad_ioceth_disable(bnad);
- timer_delete_sync(&bnad->bna.ioceth.ioc.ioc_timer);
- timer_delete_sync(&bnad->bna.ioceth.ioc.sem_timer);
- timer_delete_sync(&bnad->bna.ioceth.ioc.hb_timer);
+ bnad_ioc_timers_shutdown(bnad);
spin_lock_irqsave(&bnad->bna_lock, flags);
bna_uninit(bna);
spin_unlock_irqrestore(&bnad->bna_lock, flags);
@@ -3770,9 +3784,7 @@ bnad_pci_remove(struct pci_dev *pdev)
mutex_lock(&bnad->conf_mutex);
bnad_ioceth_disable(bnad);
- timer_delete_sync(&bnad->bna.ioceth.ioc.ioc_timer);
- timer_delete_sync(&bnad->bna.ioceth.ioc.sem_timer);
- timer_delete_sync(&bnad->bna.ioceth.ioc.hb_timer);
+ bnad_ioc_timers_shutdown(bnad);
spin_lock_irqsave(&bnad->bna_lock, flags);
bna_uninit(bna);
spin_unlock_irqrestore(&bnad->bna_lock, flags);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 252/457] bpf: fs/xattr: dont assume the inode is locked in path_unlink/path_rmdir
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 251/457] bna: prevent IOC timer rearm during teardown Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 253/457] crypto: s390/hmac - Generate intermediate CV for API partial block handling Greg Kroah-Hartman
` (215 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Parri,
Christian Brauner (Amutable)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Parri <parri.andrea@gmail.com>
commit 35d442ed1f86465e49df3119fb898f985186db13 upstream.
bpf_lsm_has_d_inode_locked() makes the verifier rewrite
bpf_[set|remove]_dentry_xattr() to the _locked variants, which assume
that the caller already holds the inode's i_rwsem. The path_unlink and
path_rmdir hooks are listed, but security_path_unlink() and
security_path_rmdir() run before vfs_unlink()/vfs_rmdir() take the
victim inode's i_rwsem, so a sleepable BPF LSM program attached to
either hook mutates the victim's xattrs without the lock held.
Drop the two path hooks from d_inode_locked_hooks so that the verifier
keeps the locking bpf_[set|remove]_dentry_xattr() variants, which take
the lock themselves.
Fixes: 56467292794b8 ("bpf: fs/xattr: Add BPF kfuncs to set and remove xattrs")
Cc: stable@vger.kernel.org
Signed-off-by: Andrea Parri <parri.andrea@gmail.com>
Link: https://patch.msgid.link/20260922145530.369775-1-parri.andrea@gmail.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/bpf_fs_kfuncs.c | 4 ----
1 file changed, 4 deletions(-)
--- a/fs/bpf_fs_kfuncs.c
+++ b/fs/bpf_fs_kfuncs.c
@@ -419,10 +419,6 @@ BTF_ID(func, bpf_lsm_inode_rmdir)
BTF_ID(func, bpf_lsm_inode_setattr)
BTF_ID(func, bpf_lsm_inode_setxattr)
BTF_ID(func, bpf_lsm_inode_unlink)
-#ifdef CONFIG_SECURITY_PATH
-BTF_ID(func, bpf_lsm_path_unlink)
-BTF_ID(func, bpf_lsm_path_rmdir)
-#endif /* CONFIG_SECURITY_PATH */
BTF_SET_END(d_inode_locked_hooks)
bool bpf_lsm_has_d_inode_locked(const struct bpf_prog *prog)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 253/457] crypto: s390/hmac - Generate intermediate CV for API partial block handling
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 252/457] bpf: fs/xattr: dont assume the inode is locked in path_unlink/path_rmdir Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 254/457] cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict Greg Kroah-Hartman
` (214 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Holger Dengler, Harald Freudenberger,
Herbert Xu
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Holger Dengler <dengler@linux.ibm.com>
commit 10396a2d6d41d594975b6ece712278570c3c970c upstream.
The API partial block handling requires a intermediate chaining
value (CV). The internal function hash_data() sets the function code
correctly, so also call cpacf_kimd() instruction for intermediate CV
generation, as cpacf_klmd() always generate the final hash value.
Cc: stable@vger.kernel.org # 6.15+
Fixes: 08811169ac01 ("crypto: s390/hmac - Use API partial block handling")
Signed-off-by: Holger Dengler <dengler@linux.ibm.com>
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/crypto/hmac_s390.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/arch/s390/crypto/hmac_s390.c
+++ b/arch/s390/crypto/hmac_s390.c
@@ -150,7 +150,10 @@ static int hash_data(const u8 *in, unsig
#undef PARAM_INIT
- cpacf_klmd(func, ¶m, in, inlen);
+ if (final)
+ cpacf_klmd(func, ¶m, in, inlen);
+ else
+ cpacf_kimd(func, ¶m, in, inlen);
memcpy(digest, ¶m, digestsize);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 254/457] cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 253/457] crypto: s390/hmac - Generate intermediate CV for API partial block handling Greg Kroah-Hartman
@ 2026-09-30 15:25 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 255/457] cgroup/pids: Restore pids.events notifications in local mode Greg Kroah-Hartman
` (213 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:25 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guopeng Zhang, Hui Peng, Waiman Long,
Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 31c88350b7dd1522792f726f79607f31bb55c50f upstream.
When a remote partition is created underneath an existing local partition
via a non-partition (PRS_MEMBER) intermediate cgroup, update_prstate() sees
parent->partition_root_state == PRS_MEMBER and calls
remote_partition_enable().
Commit 86888c7bd117 ("cgroup/cpuset: Add warnings to catch inconsistency
in exclusive CPUs") replaced the cpumask_intersects(tmp->new_cpus,
subpartitions_cpus) error check in remote_partition_enable() with
WARN_ON_ONCE(). As a result, remote_partition_enable() emits a warning
and proceeds to enable the remote partition on CPUs that are already
owned by the ancestor local partition in subpartitions_cpus.
This can be reproduced on Linux 7.3.0-rc3 with:
mkdir -p /tmp/cg1
mount -t cgroup2 none /tmp/cg1
echo "+cpuset" > /tmp/cg1/cgroup.subtree_control
mkdir /tmp/cg1/A
echo 1 > /tmp/cg1/A/cpuset.cpus
echo 1 > /tmp/cg1/A/cpuset.cpus.exclusive
echo root > /tmp/cg1/A/cpuset.cpus.partition
echo "+cpuset" > /tmp/cg1/A/cgroup.subtree_control
mkdir /tmp/cg1/A/B
echo 1 > /tmp/cg1/A/B/cpuset.cpus
echo 1 > /tmp/cg1/A/B/cpuset.cpus.exclusive
echo "+cpuset" > /tmp/cg1/A/B/cgroup.subtree_control
mkdir /tmp/cg1/A/B/D
echo 1 > /tmp/cg1/A/B/D/cpuset.cpus
echo 1 > /tmp/cg1/A/B/D/cpuset.cpus.exclusive
echo root > /tmp/cg1/A/B/D/cpuset.cpus.partition
which triggers:
WARNING: kernel/cgroup/cpuset.c:1594 at remote_partition_enable+0x1c1/0x300
and leaves both /tmp/cg1/A and /tmp/cg1/A/B/D as active root partitions
claiming exclusive CPU 1.
Fix this by returning PERR_NOCPUS when tmp->new_cpus intersects
subpartitions_cpus in remote_partition_enable(), matching the error code
used by remote_cpus_update() for the same subpartitions_cpus conflict, and
add a regression test case to
tools/testing/selftests/cgroup/test_cpuset_prs.sh.
Tested in QEMU on Linux 7.3.0-rc3 using the reproducer above and
tools/testing/selftests/cgroup/test_cpuset_prs.sh.
Fixes: 86888c7bd117 ("cgroup/cpuset: Add warnings to catch inconsistency in exclusive CPUs")
Suggested-by: Guopeng Zhang <guopeng.zhang@linux.dev>
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Reviewed-by: Waiman Long <longman@redhat.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/cgroup/cpuset.c | 3 ++-
tools/testing/selftests/cgroup/test_cpuset_prs.sh | 2 ++
2 files changed, 4 insertions(+), 1 deletion(-)
--- a/kernel/cgroup/cpuset.c
+++ b/kernel/cgroup/cpuset.c
@@ -1552,10 +1552,11 @@ static int remote_partition_enable(struc
* above it or remote partition root underneath it is not allowed.
*/
compute_excpus(cs, tmp->new_cpus);
- WARN_ON_ONCE(cpumask_intersects(tmp->new_cpus, subpartitions_cpus));
if (!cpumask_intersects(tmp->new_cpus, cpu_active_mask) ||
cpumask_subset(top_cpuset.effective_cpus, tmp->new_cpus))
return PERR_INVCPUS;
+ if (cpumask_intersects(tmp->new_cpus, subpartitions_cpus))
+ return PERR_NOCPUS;
if (((new_prs == PRS_ISOLATED) &&
!isolated_cpus_can_update(tmp->new_cpus, NULL)) ||
prstate_housekeeping_conflict(new_prs, tmp->new_cpus))
--- a/tools/testing/selftests/cgroup/test_cpuset_prs.sh
+++ b/tools/testing/selftests/cgroup/test_cpuset_prs.sh
@@ -298,6 +298,8 @@ TEST_MATRIX=(
" C0-4:X2-4 C1-4:X2-4:P2 C2-4:X4:P1 \
. . . X1 . 0 A1:0-1|A2:2-4|A3:2-4 \
A1:P0|A2:P2|A3:P-1 2-4"
+ " CX1-3:P1 CX1-3 CX1-3 . . . P1 . 0 A1:1-3|A2:1-3|A3:1-3 \
+ A1:P1|A2:P0|A3:P-1"
# Remote partition offline tests
" C0-3 C1-3 C2-3 . X2-3 X2-3 X2-3:P2:O2=0 . 0 A1:0-1|A2:1|A3:3 A1:P0|A3:P2 2-3"
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 255/457] cgroup/pids: Restore pids.events notifications in local mode
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-09-30 15:25 ` [PATCH 7.2 254/457] cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 256/457] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
` (212 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guopeng Zhang, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guopeng Zhang <zhangguopeng@kylinos.cn>
commit 1765a153d985c231357145e26798f9408db10e42 upstream.
A fork rejected by the pids controller increments the counter reported by
pids.events. When local event accounting is selected, however, pids_event()
returns after notifying only events_local_file, leaving pids.events pollers
asleep.
On legacy hierarchies, pids.events.local does not exist. With
pids_localevents, pids.events reports the same local counter. In both
cases, pids.events changes without generating a notification.
This can be reproduced with a pids_localevents mount:
mkdir /tmp/test
mount -t cgroup2 -o pids_localevents none /tmp/test
mkdir /tmp/test/t
echo 1 > /tmp/test/t/pids.max
cat /tmp/test/t/pids.events # max 0
timeout 3 inotifywait -e modify /tmp/test/t/pids.events &
sh -c 'echo $$ > /tmp/test/t/cgroup.procs; (true &)' 2>/dev/null
wait
cat /tmp/test/t/pids.events # max 1
Without this patch, inotifywait times out without reporting an event.
Notify pids.events before returning from the local event path.
Fixes: 3f26a885a068 ("cgroup/pids: Add pids.events.local")
Cc: stable@vger.kernel.org # v6.11+
Signed-off-by: Guopeng Zhang <zhangguopeng@kylinos.cn>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/cgroup/pids.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/kernel/cgroup/pids.c
+++ b/kernel/cgroup/pids.c
@@ -253,6 +253,11 @@ static void pids_event(struct pids_cgrou
}
if (!cgroup_subsys_on_dfl(pids_cgrp_subsys) ||
cgrp_dfl_root.flags & CGRP_ROOT_PIDS_LOCAL_EVENTS) {
+ /*
+ * pids.events reports the local counter on legacy hierarchies
+ * and when pids_localevents is enabled.
+ */
+ cgroup_file_notify(&p->events_file);
cgroup_file_notify(&p->events_local_file);
return;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 256/457] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 255/457] cgroup/pids: Restore pids.events notifications in local mode Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 257/457] fprobe: Terminate the fgraph_data list when the reservation is not filled Greg Kroah-Hartman
` (211 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Peng, Hangbin Liu,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit d22609f3d13fc5baacd92c222731b03c593401db upstream.
Commit 7a9bc9e3f423 ("fou: Don't allow 0 for FOU_ATTR_IPPROTO.") added
NLA_POLICY_MIN(NLA_U8, 1) to fou_nl_policy[FOU_ATTR_IPPROTO], which
rejects an explicitly supplied FOU_ATTR_IPPROTO == 0 attribute with
-ERANGE.
However, FOU_ATTR_IPPROTO is an optional netlink attribute. When a user
sends FOU_CMD_ADD with FOU_ATTR_TYPE set to FOU_ENCAP_DIRECT and omits
FOU_ATTR_IPPROTO entirely, nla_policy validation succeeds and
parse_nl_config() leaves cfg->protocol as 0 (from memset(cfg, 0,
sizeof(*cfg))). fou_create() then creates a FOU_ENCAP_DIRECT socket with
fou->protocol == 0.
In fou_udp_recv(), returning -fou->protocol to udp_queue_rcv_one_skb()
triggers IP protocol resubmission when fou->protocol > 0, whereas
returning 0 tells the UDP tunnel layer that the skb was consumed without
freeing it. When fou->protocol == 0, every packet received on the socket
returns 0 from fou_udp_recv() and leaks the sk_buff.
Reject FOU_ENCAP_DIRECT when !cfg->protocol in fou_create() so that
creating a direct encapsulation port without FOU_ATTR_IPPROTO fails with
-EINVAL while leaving FOU_CMD_DEL and FOU_CMD_GET (which share
parse_nl_config()) unaffected.
Tested in QEMU against Linux 7.3.0-rc3 by sending a FOU_CMD_ADD Generic
Netlink request with FOU_ATTR_PORT = 5555 and FOU_ATTR_TYPE =
FOU_ENCAP_DIRECT while omitting FOU_ATTR_IPPROTO. On the unfixed kernel,
FOU_CMD_ADD succeeds (err = 0), FOU_CMD_GET reports fou->type = 1 and
fou->protocol = 0, and sending 4000 UDP packets to 127.0.0.1:5555 leaks
all 4000 sk_buffs (SUnreclaim in /proc/meminfo grows from 41456 kB to
59008 kB, +17552 kB); with this patch applied, FOU_CMD_ADD is rejected
with -EINVAL (-22).
Fixes: 23461551c006 ("fou: Support for foo-over-udp RX path")
Fixes: 7a9bc9e3f423 ("fou: Don't allow 0 for FOU_ATTR_IPPROTO.")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Peng <benquike@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260921045920.1613098-1-benquike@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/fou_core.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/net/ipv4/fou_core.c
+++ b/net/ipv4/fou_core.c
@@ -600,6 +600,10 @@ static int fou_create(struct net *net, s
/* Initial for fou type */
switch (cfg->type) {
case FOU_ENCAP_DIRECT:
+ if (!cfg->protocol) {
+ err = -EINVAL;
+ goto error;
+ }
tunnel_cfg.encap_rcv = fou_udp_recv;
tunnel_cfg.gro_receive = fou_gro_receive;
tunnel_cfg.gro_complete = fou_gro_complete;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 257/457] fprobe: Terminate the fgraph_data list when the reservation is not filled
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 256/457] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 258/457] fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbots "WARNING in do_new_mount" saga Greg Kroah-Hartman
` (210 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
David Carlier
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Carlier <devnexen@gmail.com>
commit 1d653a183973f5283a3db5a38cd5e195eb152244 upstream.
fprobe_fgraph_entry() reserves shadow stack space for every fprobe with
an exit handler, but only fills it for those whose entry handler returns
0. fgraph_reserve_data() does not clear the area, so fprobe_return()
parses the unused tail as headers left over from an earlier call, and an
exit handler can run twice or despite its entry handler asking to skip
it.
Write a zero word after the last entry to terminate the walk. A zeroed
slot does not decode to a NULL fprobe on the arches that encode the
header into one unsigned long, since arch_decode_fprobe_header_fp() ORs
in FPROBE_HEADER_MSB_PATTERN, so make read_fprobe_header() return NULL
for a zeroed slot.
Link: https://lore.kernel.org/all/20260917212407.384468-1-devnexen@gmail.com/
Fixes: e0a384434ae1 ("tracing: fprobe: do not zero out unused fgraph_data")
Cc: stable@vger.kernel.org
Suggested-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: David Carlier <devnexen@gmail.com>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/fprobe.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
--- a/kernel/trace/fprobe.c
+++ b/kernel/trace/fprobe.c
@@ -171,6 +171,11 @@ static inline bool write_fprobe_header(u
static inline void read_fprobe_header(unsigned long *stack,
struct fprobe **fp, unsigned int *size_words)
{
+ if (!*stack) {
+ *fp = NULL;
+ *size_words = 0;
+ return;
+ }
*fp = arch_decode_fprobe_header_fp(*stack);
*size_words = arch_decode_fprobe_header_size(*stack);
}
@@ -203,6 +208,12 @@ static inline void read_fprobe_header(un
{
struct __fprobe_header *fph = (struct __fprobe_header *)stack;
+ if (!*stack) {
+ *fp = NULL;
+ *size_words = 0;
+ return;
+ }
+
*fp = fph->fp;
*size_words = fph->size_words;
}
@@ -642,6 +653,10 @@ static int fprobe_fgraph_entry(struct ft
}
}
+ /* Terminate the list, fgraph_reserve_data() does not clear it. */
+ if (used && used < reserved_words)
+ fgraph_data[used] = 0;
+
/* If any exit_handler is set, data must be used. */
return used != 0;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 258/457] fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbots "WARNING in do_new_mount" saga
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 257/457] fprobe: Terminate the fgraph_data list when the reservation is not filled Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 259/457] netfs: Fix missing alloc tagging of direct mempool allocations Greg Kroah-Hartman
` (209 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Kara,
syzbot+2a13ad6914e6fcec716c, Christian Brauner (Amutable)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
commit 1abd643f3783ea8f8e273c18697ff0413aa92dc7 upstream.
ntfs_create_inode() creates a new inode via ntfs_new_inode(). It hashes
it with insert_inode_locked() and so it's marked as I_NEW until
unlock_new_inode().
ntfs 3 calls d_instantiate() in between though... Since the dentry was
already hashed by the lookup before the create any path walk finds it
without touching the parent's i_rwsem and so can lock the inode.
If the inode is a directory unlock_new_inode() calls
lockdep_annotate_inode_mutex_key() and marks i_rwsem with the
i_mutex_dir_key class.
That resets the count and the owner of a lock somebody else may already
hold by now...
syzbot has been spamming us with the same godforsaken bug
"WARNING in do_new_mount"
since 2023. I can't take it anymore so I went looking. Afaict, syzbot's
executor chdirs into a freshly mounted ntfs3 image, creates a
directory and then mounts some pseudofs on it. Everytime the mkdir()
takes longer than syzbot waits mount() runs concurrently:
mkdir("./sys") mount(NULL, "./sys", "sysfs")
ntfs_create_inode()
d_instantiate()
user_path_at() finds the dentry
do_lock_mount()
inode_lock(inode)
namespace_lock()
unlock_new_inode()
lockdep_annotate_inode_mutex_key()
init_rwsem(&inode->i_rwsem)
unlock_mount()
inode_unlock(inode)
The mount side then releases a lock that according to the rwsem nobody
holds:
DEBUG_RWSEMS_WARN_ON((rwsem_owner(sem) != current) && ...):
count = 0x0, magic = 0xffff888043a854e8, owner = 0x0,
curr 0xffff888000244880, list empty
WARNING: CPU: 0 PID: 5346 at kernel/locking/rwsem.c:1368 __up_write
Call Trace:
inode_unlock include/linux/fs.h:877 [inline]
unlock_mount fs/namespace.c:2892 [inline]
do_new_mount_fc fs/namespace.c:3828 [inline]
do_new_mount+0x777/0xa40 fs/namespace.c:3887
On PREEMPT_RT the same thing shows up as
DEBUG_LOCKS_WARN_ON(rt_mutex_owner(lock) != current)
WARNING: kernel/locking/rtmutex_common.h:193 at rt_mutex_slowunlock
The up_write() underflows the reset count. A following inode_lock() on
that directory then never returns. A path walk into the new directory
racing with the mkdir() corrupts the lock the same way via
inode_lock_shared() in lookup_slow().
Switch to d_instantiate_new() and drop the trailing unlock_new_inode().
All error paths bail out before that point with I_NEW still set and
keep using discard_new_inode().
May we never see this fscking bug report again.
Link: https://patch.msgid.link/20260909-work-ntfs3-d_instantiate_new-v1-1-2db697162ce8@kernel.org
Fixes: 82cae269cfa9 ("fs/ntfs3: Add initialization of super block")
Reviewed-by: Jan Kara <jack@suse.cz>
Cc: stable@vger.kernel.org # v5.15+
Reported-by: syzbot+2a13ad6914e6fcec716c@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/6a9beced.a5e650b3.26d8a.000b.GAE@google.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/ntfs3/inode.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--- a/fs/ntfs3/inode.c
+++ b/fs/ntfs3/inode.c
@@ -1648,10 +1648,10 @@ int ntfs_create_inode(struct mnt_idmap *
goto out6;
/*
- * Call 'd_instantiate' after inode->i_op is set
+ * Call 'd_instantiate_new' after inode->i_op is set
* but before finish_open.
*/
- d_instantiate(dentry, inode);
+ d_instantiate_new(dentry, inode);
/* Set original time. inode times (i_ctime) may be changed in ntfs_init_acl. */
inode_set_atime_to_ts(inode, ni->i_crtime);
@@ -1699,9 +1699,6 @@ out1:
if (!fnd)
ni_unlock(dir_ni);
- if (!err)
- unlock_new_inode(inode);
-
return err;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 259/457] netfs: Fix missing alloc tagging of direct mempool allocations
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 258/457] fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbots "WARNING in do_new_mount" saga Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 260/457] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
` (208 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Erhard Furtner, Suren Baghdasaryan,
Hao Ge, Vlastimil Babka (SUSE), Christian Brauner (Amutable)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hao Ge <hao.ge@linux.dev>
commit b78b728e21c32ec4c330b299f657fb1eb02dffc2 upstream.
Commit 1d78d56c43ef ("netfs: Fix folio_queue ENOMEM in writeback by
adding a mempool") added a mempool for the folio_queues and made the
request, subrequest and folio_queue allocations distinguish between
writeback and everything else. Writeback is part of memory reclaim
and must not fail due to ENOMEM, so it allocates under GFP_NOFS
through mempool_alloc(), which may dip into the pool's reserve and,
if that runs empty, wait for elements to be returned. The
GFP_KERNEL paths, which can return -ENOMEM to their callers, invoke
the pool's ->alloc() callback directly instead.
The direct call, however, skips the alloc_hooks() wrapper that the
mempool_alloc() macro provides. The pool callbacks, mempool_alloc_slab()
and mempool_kmalloc(), call kmem_cache_alloc_noprof() and kmalloc_noprof()
and rely on current->alloc_tag having been set by the caller. With
CONFIG_MEM_ALLOC_PROFILING_DEBUG=y this leads to
current->alloc_tag not set
WARNING: ./include/linux/alloc_tag.h:161 at __alloc_tagging_slab_alloc_hook
alloc_tag was not set
WARNING: ./include/linux/alloc_tag.h:166 at __alloc_tagging_slab_free_hook
at allocation and free time respectively, as reported when reading
files on a CIFS mount. The allocations are also missing from
/proc/allocinfo.
Wrap the direct ->alloc() invocations in alloc_hooks() with a new
mempool_alloc_noreserve() helper in include/linux/mempool.h, next to
the other alloc_hooks()-wrapped macros such as mempool_alloc(). The
GFP_KERNEL paths keep their failable allocation semantics, they just
get tagged now.
Fixes: 1d78d56c43ef ("netfs: Fix folio_queue ENOMEM in writeback by adding a mempool")
Reported-by: Erhard Furtner <erhard_f@mailbox.org>
Closes: https://lore.kernel.org/all/0b004319-9ef7-437c-a4dd-174d6a9a83db@mailbox.org/
Tested-by: Erhard Furtner <erhard_f@mailbox.org>
Suggested-by: Suren Baghdasaryan <surenb@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Hao Ge <hao.ge@linux.dev>
Link: https://patch.msgid.link/20260923063759.34667-1-hao.ge@linux.dev
Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/netfs/objects.c | 4 ++--
fs/netfs/rolling_buffer.c | 2 +-
include/linux/mempool.h | 7 +++++++
3 files changed, 10 insertions(+), 3 deletions(-)
--- a/fs/netfs/objects.c
+++ b/fs/netfs/objects.c
@@ -34,7 +34,7 @@ struct netfs_io_request *netfs_alloc_req
rreq = mempool_alloc(mempool, gfp);
} else {
- rreq = mempool->alloc(gfp, mempool->pool_data);
+ rreq = mempool_alloc_noreserve(mempool, gfp);
if (!rreq)
return ERR_PTR(-ENOMEM);
}
@@ -214,7 +214,7 @@ struct netfs_io_subrequest *netfs_alloc_
struct kmem_cache *cache = mempool->pool_data;
if (rreq->gfp == GFP_KERNEL)
- subreq = mempool->alloc(rreq->gfp, mempool->pool_data);
+ subreq = mempool_alloc_noreserve(mempool, rreq->gfp);
else
subreq = mempool_alloc(mempool, rreq->gfp);
if (!subreq)
--- a/fs/netfs/rolling_buffer.c
+++ b/fs/netfs/rolling_buffer.c
@@ -29,7 +29,7 @@ struct folio_queue *netfs_folioq_alloc(u
struct folio_queue *fq;
if (gfp == GFP_KERNEL)
- fq = netfs_folioq_pool.alloc(gfp, netfs_folioq_pool.pool_data);
+ fq = mempool_alloc_noreserve(&netfs_folioq_pool, gfp);
else
fq = mempool_alloc(&netfs_folioq_pool, gfp);
if (fq) {
--- a/include/linux/mempool.h
+++ b/include/linux/mempool.h
@@ -70,6 +70,13 @@ int mempool_alloc_bulk_noprof(struct mem
#define mempool_alloc_bulk(...) \
alloc_hooks(mempool_alloc_bulk_noprof(__VA_ARGS__))
+/*
+ * Allocate a new element without dipping into the pool's reserves or
+ * waiting. Returns NULL on failure.
+ */
+#define mempool_alloc_noreserve(_pool, _gfp) \
+ alloc_hooks((_pool)->alloc(_gfp, (_pool)->pool_data))
+
void *mempool_alloc_preallocated(struct mempool *pool) __malloc;
void mempool_free(void *element, struct mempool *pool);
unsigned int mempool_free_bulk(struct mempool *pool, void **elem,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 260/457] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 259/457] netfs: Fix missing alloc tagging of direct mempool allocations Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 261/457] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
` (207 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tejun Heo, Roman Gushchin,
Patrick Lu (Anthropic), Jan Kara, Christian Brauner (Amutable)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
commit f6988c90671e83db79df1b7b9d6fdb0e5947fd84 upstream.
cleanup_offline_cgwb() prepares at most WB_MAX_INODES_PER_ISW inodes
per call and is called again until the dying wb is drained, but every
call walks wb->b_attached and then wb->b_dirty_time from the same end.
Inodes already prepared (they stay on the list with I_WB_SWITCH set
until the switch worker runs) and inodes that cannot be switched
(I_FREEING, I_WILL_FREE, !SB_ACTIVE, DAX, already on the target wb)
stay where they are, so each pass rescans a growing run of them under
wb->list_lock and a full drain is quadratic in the number of inodes on
the list. With ~17M inodes attached to one dying cgwb we saw this end
in soft lockups, with CPUs reported stuck for 21-48s.
Walk both lists from the oldest end and move every scanned inode to
the newest end, so the next pass starts where the previous one stopped
and the drain becomes linear. b_attached is unordered, so nobody sees
the reorder there. b_dirty_time is ordered by dirtied_when, but the
oldest unscanned inode stays at the end move_expired_inodes() picks
from, sync takes the whole list regardless of order, and prepared
inodes leave the list as soon as the switch work runs and get a new
dirtied_time_when on the new wb anyway, so the only inodes left out of
order are the ones that can never switch (DAX), and only on the dying
wb.
Fixes: c22d70a162d3 ("writeback, cgroup: release dying cgwbs by switching attached inodes")
Cc: stable@vger.kernel.org
Acked-by: Tejun Heo <tj@kernel.org>
Acked-by: Roman Gushchin <roman.gushchin@linux.dev>
Signed-off-by: Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
Link: https://patch.msgid.link/20260911-wb-cgwb-rotate-v2-1-a9ab253a1295@gmail.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/fs-writeback.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
--- a/fs/fs-writeback.c
+++ b/fs/fs-writeback.c
@@ -726,19 +726,34 @@ static bool isw_prepare_wbs_switch(struc
struct inode_switch_wbs_context *isw,
struct list_head *list, int *nr)
{
- struct inode *inode;
+ struct inode *inode, *tmp;
+ LIST_HEAD(scanned);
+ bool full = false;
+
+ /*
+ * Walk from the oldest end and move scanned inodes to the newest
+ * end, so the next scan resumes at unscanned inodes instead of
+ * re-walking an ever-growing run of prepared and skipped ones.
+ * For b_dirty_time this keeps the oldest unscanned inode at the
+ * end move_expired_inodes() picks from; b_attached is unordered.
+ */
+ list_for_each_entry_safe_reverse(inode, tmp, list, i_io_list) {
+ list_move(&inode->i_io_list, &scanned);
- list_for_each_entry(inode, list, i_io_list) {
if (!inode_prepare_wbs_switch(inode, new_wb))
continue;
isw->inodes[*nr] = inode;
(*nr)++;
- if (*nr >= WB_MAX_INODES_PER_ISW - 1)
- return true;
+ if (*nr >= WB_MAX_INODES_PER_ISW - 1) {
+ full = true;
+ break;
+ }
}
- return false;
+ list_splice(&scanned, list);
+
+ return full;
}
/**
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 261/457] workqueue: Fix NULL current_pwq deref in flush dependency check
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 260/457] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 262/457] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
` (206 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pavankumar Kondeti, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
commit db6365ced4d5855e321f772b240c0e473bcfcdd5 upstream.
check_flush_dependency() uses current_wq_worker() to determine whether
the caller is a workqueue worker and then dereferences worker->current_pwq
to test whether the current workqueue is WQ_MEM_RECLAIM.
current_wq_worker() only means that %current has PF_WQ_WORKER set. A
kworker can reach check_flush_dependency() while it is not executing a
work item. One such path is worker_thread() acting as the pool manager,
where create_worker() does GFP_KERNEL allocation and the allocation path
invokes the OOM notifier. In that state worker->current_pwq is NULL
because current_pwq is set only by process_one_work() and cleared again
after the work function returns.
[ 416.760634][ T375] Call trace:
[ 416.760638][ T375] check_flush_dependency+0x80/0x120 (P)
[ 416.760648][ T375] __flush_work+0x98/0x224
[ 416.760657][ T375] flush_work+0x30/0x44
[ 416.760665][ T375] ...
[ 416.760710][ T375] blocking_notifier_call_chain+0x58/0xa0
[ 416.760719][ T375] out_of_memory+0xb4/0x458
[ 416.760730][ T375] __alloc_pages_may_oom+0x11c/0x1a8
[ 416.760739][ T375] __alloc_pages_slowpath+0x314/0x46c
[ 416.760746][ T375] __alloc_frozen_pages_noprof+0x110/0x1a4
[ 416.760753][ T375] new_slab+0x12c/0x484
[ 416.760759][ T375] ___slab_alloc+0x7a8/0xc7c
[ 416.760765][ T375] __slab_alloc+0x74/0xd8
[ 416.760772][ T375] __kmalloc_cache_node_noprof+0x2ac/0x304
[ 416.760779][ T375] alloc_worker+0x28/0x60
[ 416.760785][ T375] create_worker+0x4c/0x20c
[ 416.760790][ T375] worker_thread+0xe8/0x2b8
[ 416.760796][ T375] kthread+0x1a8/0x200
[ 416.760805][ T375] ret_from_fork+0x10/0x20
Guard the WQ_MEM_RECLAIM-worker warning with worker->current_pwq. If the
kworker is not currently executing a work item, there is no current
workqueue to diagnose with that warning. The PF_MEMALLOC warning is left
unchanged so explicit reclaim context flushing a !WQ_MEM_RECLAIM target
is still reported.
Fixes: fca839c00a12 ("workqueue: warn if memory reclaim tries to flush !WQ_MEM_RECLAIM workqueue")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/workqueue.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -3844,7 +3844,7 @@ static void check_flush_dependency(struc
WARN_ONCE(current->flags & PF_MEMALLOC,
"workqueue: PF_MEMALLOC task %d(%s) is flushing !WQ_MEM_RECLAIM %s:%ps",
current->pid, current->comm, target_wq->name, target_func);
- WARN_ONCE(worker && ((worker->current_pwq->wq->flags &
+ WARN_ONCE(worker && worker->current_pwq && ((worker->current_pwq->wq->flags &
(WQ_MEM_RECLAIM | __WQ_LEGACY)) == WQ_MEM_RECLAIM),
"workqueue: WQ_MEM_RECLAIM %s:%ps is flushing !WQ_MEM_RECLAIM %s:%ps",
worker->current_pwq->wq->name, worker->current_func,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 262/457] writeback: report a Tasks-RCU quiescent state per cgwb drain pass
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 261/457] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 263/457] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
` (205 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Josef Bacik, Andrew Morton,
Tejun Heo, Roman Gushchin, Jan Kara, Lorenzo Stoakes (ARM),
David Hildenbrand, Dennis Zhou, Liam R. Howlett,
Matthew Wilcox (Oracle), Michal Hocko, Mike Rapoport,
Paul E . McKenney, Suren Baghdasaryan, Vlastimil Babka
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Josef Bacik <josef@toxicpanda.com>
commit 407a5d205179a4ab186571b0e16ec42725dc77bc upstream.
cleanup_offline_cgwbs_workfn() drains a dying cgwb by calling
cleanup_offline_cgwb() until it returns false, with a cond_resched()
between passes. On a CONFIG_PREEMPTION kernel that cond_resched() does
nothing: _cond_resched() is a plain "return 0", and under PREEMPT_DYNAMIC
the full and lazy modes disable it. Since commit 7dadeaa6e851 ("sched:
Further restrict the preemption modes") those are the only two models on
the architectures with PREEMPT_LAZY support, arm64 and x86 among them, so
the drain loop never reports a Tasks-RCU quiescent state.
A worker draining a cgwb with millions of attached inodes runs for
minutes. On a 6.18 arm64 host in lazy mode the cgwb worker drained one
dying cgroup's writeback domain for over 11 minutes. A BPF program unlink
(bpf_trampoline_unlink_prog -> bpf_trampoline_update ->
unregister_ftrace_direct -> ftrace_shutdown -> synchronize_rcu_tasks())
waited on that grace period while holding the trampoline mutex, 42 tasks
queued behind it in D state, and the hung task detector fired at 614 s and
panicked the host. Any BPF or ftrace detach during a long drain inherits
the drain's length.
Fix this by calling cond_resched_tasks_rcu_qs() so we do not stall out
anybody who calls sycnrhonize_rcu_tasks(). We put this in a do { } while
loop because if we have many small cgroups cleanup_offline_cgwb() will
return false and we will never call cond_resched_tasks_rcu_qs(), creating
the same problem.
Link: https://lore.kernel.org/20260909-cgwb-tasks-rcu-qs-v1-1-967a7754771f@toxicpanda.com
Fixes: c22d70a162d3 ("writeback, cgroup: release dying cgwbs by switching attached inodes")
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Link: https://lore.kernel.org/bpf/9d444098-7c03-4163-af12-bd0a79a51443@paulmck-laptop/
Assisted-by: LLM
Acked-by: Tejun Heo <tj@kernel.org>
Reviewed-by: Roman Gushchin <roman.gushchin@linux.dev>
Reviewed-by: Jan Kara <jack@suse.cz>
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dennis Zhou <dennis@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: "Paul E . McKenney" <paulmck@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/backing-dev.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/mm/backing-dev.c
+++ b/mm/backing-dev.c
@@ -910,8 +910,9 @@ static void cleanup_offline_cgwbs_workfn
continue;
spin_unlock_irq(&cgwb_lock);
- while (cleanup_offline_cgwb(wb))
- cond_resched();
+ do {
+ cond_resched_tasks_rcu_qs();
+ } while (cleanup_offline_cgwb(wb));
spin_lock_irq(&cgwb_lock);
wb_put(wb);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 263/457] fsl/fman: Fix clk reference leak in read_dts_node()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 262/457] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 264/457] ipe: fix use-after-free when auditing a newly loaded policy Greg Kroah-Hartman
` (204 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Simon Horman,
Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit a644f09b2090ad22a13fbcf9d141084f573108ef upstream.
of_clk_get() returns a clock with its reference count incremented, but
read_dts_node() only uses it to read the rate and never calls clk_put().
The clock is not stored anywhere, so the reference cannot be released
later either.
Release the clock once its rate has been read, which also covers the
error path taken when the rate is zero.
Fixes: 414fd46e7762 ("fsl/fman: Add FMan support")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260917110135.2148068-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/freescale/fman/fman.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/ethernet/freescale/fman/fman.c
+++ b/drivers/net/ethernet/freescale/fman/fman.c
@@ -2734,6 +2734,7 @@ static struct fman *read_dts_node(struct
}
clk_rate = clk_get_rate(clk);
+ clk_put(clk);
if (!clk_rate) {
err = -EINVAL;
dev_err(&of_dev->dev, "%s: Failed to determine FM%d clock rate\n",
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 264/457] ipe: fix use-after-free when auditing a newly loaded policy
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 263/457] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 265/457] ipe: protect the dm-verity root hash with RCU Greg Kroah-Hartman
` (203 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <wufan@kernel.org>
commit 9814077275eca36ebf8d510d2f076d235ff9f51a upstream.
new_policy() audits the policy after ipe_new_policyfs_node() publishes it
and drops the new directory's inode lock. A concurrent delete can free
the policy while ipe_audit_policy_load() is still using it.
Audit the successful load under that lock.
Fixes: f44554b5067b ("audit,ipe: add IPE auditing support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
[FW: remove model name according to latest guideline]
Signed-off-by: Fan Wu <wufan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/ipe/fs.c | 8 +++-----
security/ipe/policy_fs.c | 3 +++
2 files changed, 6 insertions(+), 5 deletions(-)
--- a/security/ipe/fs.c
+++ b/security/ipe/fs.c
@@ -159,18 +159,16 @@ static ssize_t new_policy(struct file *f
}
rc = ipe_new_policyfs_node(p);
- if (rc)
- goto out;
out:
kfree(copy);
if (rc < 0) {
ipe_free_policy(p);
ipe_audit_policy_load(ERR_PTR(rc));
- } else {
- ipe_audit_policy_load(p);
+ return rc;
}
- return (rc < 0) ? rc : len;
+
+ return len;
}
static const struct file_operations np_fops = {
--- a/security/ipe/policy_fs.c
+++ b/security/ipe/policy_fs.c
@@ -481,6 +481,9 @@ int ipe_new_policyfs_node(struct ipe_pol
inode_lock(root);
p->policyfs = policyfs;
root->i_private = p;
+ /* Only audit signed policies from userspace */
+ if (p->pkcs7)
+ ipe_audit_policy_load(p);
inode_unlock(root);
return 0;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 265/457] ipe: protect the dm-verity root hash with RCU
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 264/457] ipe: fix use-after-free when auditing a newly loaded policy Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 266/457] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
` (202 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <wufan@kernel.org>
commit 2776e9c28513a1c855a94792b292cbcc533418c8 upstream.
ipe_bdev_setintegrity() frees the old root hash when dm-verity publishes
a new one on ->preresume, while policy evaluation can still be
dereferencing it.
Protect the root hash with RCU. The evaluation path already runs under
rcu_read_lock().
Fixes: e155858dd995 ("ipe: add support for dm-verity as a trust provider")
Cc: stable@vger.kernel.org
Assisted-by: LLM
[FW: remove model name according to latest guideline]
Signed-off-by: Fan Wu <wufan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/ipe/eval.c | 12 ++++++++----
security/ipe/eval.h | 2 +-
security/ipe/hooks.c | 22 +++++++++++++++++-----
3 files changed, 26 insertions(+), 10 deletions(-)
--- a/security/ipe/eval.c
+++ b/security/ipe/eval.c
@@ -134,10 +134,14 @@ static bool evaluate_boot_verified(const
static bool evaluate_dmv_roothash(const struct ipe_eval_ctx *const ctx,
struct ipe_prop *p)
{
- return !!ctx->ipe_bdev &&
- !!ctx->ipe_bdev->root_hash &&
- ipe_digest_eval(p->value,
- ctx->ipe_bdev->root_hash);
+ const struct digest_info *root_hash;
+
+ if (!ctx->ipe_bdev)
+ return false;
+
+ root_hash = rcu_dereference(ctx->ipe_bdev->root_hash);
+
+ return root_hash && ipe_digest_eval(p->value, root_hash);
}
#else
static bool evaluate_dmv_roothash(const struct ipe_eval_ctx *const ctx,
--- a/security/ipe/eval.h
+++ b/security/ipe/eval.h
@@ -27,7 +27,7 @@ struct ipe_bdev {
#ifdef CONFIG_IPE_PROP_DM_VERITY_SIGNATURE
bool dm_verity_signed;
#endif /* CONFIG_IPE_PROP_DM_VERITY_SIGNATURE */
- struct digest_info *root_hash;
+ struct digest_info __rcu *root_hash;
};
#endif /* CONFIG_IPE_PROP_DM_VERITY */
--- a/security/ipe/hooks.c
+++ b/security/ipe/hooks.c
@@ -9,6 +9,7 @@
#include <linux/binfmts.h>
#include <linux/mman.h>
#include <linux/blk_types.h>
+#include <linux/rcupdate.h>
#include "ipe.h"
#include "hooks.h"
@@ -232,7 +233,20 @@ void ipe_bdev_free_security(struct block
{
struct ipe_bdev *blob = ipe_bdev(bdev);
- ipe_digest_free(blob->root_hash);
+ ipe_digest_free(rcu_access_pointer(blob->root_hash));
+}
+
+static void ipe_set_dmverity_roothash(struct ipe_bdev *blob,
+ struct digest_info *info)
+{
+ struct digest_info *old;
+
+ /* Protected by device-mapper's md->suspend_lock */
+ old = rcu_replace_pointer(blob->root_hash, info, true);
+ if (old) {
+ synchronize_rcu();
+ ipe_digest_free(old);
+ }
}
#ifdef CONFIG_IPE_PROP_DM_VERITY_SIGNATURE
@@ -280,8 +294,7 @@ int ipe_bdev_setintegrity(struct block_d
return -EINVAL;
if (!value) {
- ipe_digest_free(blob->root_hash);
- blob->root_hash = NULL;
+ ipe_set_dmverity_roothash(blob, NULL);
return 0;
}
@@ -301,8 +314,7 @@ int ipe_bdev_setintegrity(struct block_d
info->digest_len = digest->digest_len;
- ipe_digest_free(blob->root_hash);
- blob->root_hash = info;
+ ipe_set_dmverity_roothash(blob, info);
return 0;
err:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 266/457] ipv6: do not let ipv6_find_hdr() return an offset past the packet end
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 265/457] ipe: protect the dm-verity root hash with RCU Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 267/457] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
` (201 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Eric Dumazet,
Norbert Szetei, Ido Schimmel, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
commit ee319bd3a0e976af5087cbe59ebc50a66f31d202 upstream.
ipv6_find_hdr() walks the extension header chain, skipping each header by
the length that header itself declares. ipv6_optlen() returns up to 2048,
and the skip is never checked against skb->len, so the offset stored in
*offset can point past the end of the packet.
openvswitch installs that offset as the transport header, and
update_ipv6_checksum() then reads and writes the transport checksum field
out of bounds:
BUG: KASAN: slab-use-after-free in inet_proto_csum_replace16+0x445/0x470
Read of size 2 at addr ffff88810b754b06 by task ovs_ipv6_oob/629
CPU: 4 UID: 1000 PID: 629 Comm: ovs_ipv6_oob Tainted: G N 7.3.0-rc3+ #348
Call Trace:
inet_proto_csum_replace16+0x445/0x470
set_ipv6_addr+0x3dd/0x460
do_execute_actions+0x6a3d/0x7c40
ovs_execute_actions+0xfd/0x480
ovs_packet_cmd_execute+0xc38/0xf20
genl_rcv_msg+0x59e/0x870
netlink_rcv_skb+0x18b/0x450
genl_rcv+0x2d/0x40
netlink_unicast+0x6bc/0xa20
The buggy address belongs to the object at ffff88810b754980
which belongs to the cache skbuff_small_head of size 704
The buggy address is located 390 bytes inside of
freed 704-byte region [ffff88810b754980, ffff88810b754c40)
Other callers use that offset too, so bound it here rather than in one
caller.
Reject a header whose declared length does not fit in the packet.
ipv6_find_hdr() already fails with -EBADMSG on a malformed chain, so this
adds no new failure mode.
Fixes: f8f626754ebe ("ipv6: Move ipv6_find_hdr() out of Netfilter code.")
Suggested-by: Ilya Maximets <i.maximets@ovn.org>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/8F80BA1A-DDFD-432D-9075-242A3435FEB5@doyensec.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/exthdrs_core.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/ipv6/exthdrs_core.c
+++ b/net/ipv6/exthdrs_core.c
@@ -278,6 +278,9 @@ int ipv6_find_hdr(const struct sk_buff *
hdrlen = ipv6_optlen(hp);
if (!found) {
+ if (skb->len - start < hdrlen)
+ return -EBADMSG;
+
nexthdr = hp->nexthdr;
start += hdrlen;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 267/457] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 266/457] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 268/457] kprobes: Fix permanent hang when flushing the kprobe optimizer Greg Kroah-Hartman
` (200 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hui Peng, Hangbin Liu, Justin Iurman,
Andrea Mayer, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 2d959c75c27f90e9ec489d18ce5ee6b852ad4741 upstream.
In seg6_genl_policy, SEG6_ATTR_DST is defined with .type = NLA_BINARY and
.len = sizeof(struct in6_addr). For NLA_BINARY, .len only enforces the
maximum payload length and permits shorter payloads (e.g., 0 bytes).
When seg6_genl_set_tunsrc() copies sizeof(struct in6_addr) bytes via
kmemdup(val, sizeof(*val), GFP_KERNEL), a short SEG6_ATTR_DST attribute
triggers a 16-byte out-of-bounds read past skb->tail into uninitialized
skb->head memory, which is stored in sdata->tun_src and leaked back to
userspace via SEG6_CMD_GET_TUNSRC.
Switch SEG6_ATTR_DST in seg6_genl_policy to
NLA_POLICY_EXACT_LEN(sizeof(struct in6_addr)) so that generic netlink
validation rejects any attribute whose length is not exactly
sizeof(struct in6_addr) with -ERANGE.
Tested in QEMU against Linux 7.3.0-rc3 by sending a SEG6_CMD_SET_TUNSRC
Generic Netlink message with a 0-byte SEG6_ATTR_DST attribute followed
by SEG6_CMD_GET_TUNSRC. On the unfixed kernel, SEG6_CMD_SET_TUNSRC
succeeds (err = 0) and SEG6_CMD_GET_TUNSRC leaks 16 bytes of
uninitialized kernel heap memory (tun_src =
836a61ecc4d25a1042a8d60411cfb378); with this patch applied,
SEG6_CMD_SET_TUNSRC is rejected by netlink policy validation with
-ERANGE (-34) and tun_src remains zeroed.
Fixes: 915d7e5e5930 ("ipv6: sr: add code base for control plane support of SR-IPv6")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Peng <benquike@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Reviewed-by: Justin Iurman <justin.iurman@gmail.com>
Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Link: https://patch.msgid.link/20260921044025.1535982-1-benquike@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/seg6.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/ipv6/seg6.c
+++ b/net/ipv6/seg6.c
@@ -138,8 +138,8 @@ out:
static struct genl_family seg6_genl_family;
static const struct nla_policy seg6_genl_policy[SEG6_ATTR_MAX + 1] = {
- [SEG6_ATTR_DST] = { .type = NLA_BINARY,
- .len = sizeof(struct in6_addr) },
+ [SEG6_ATTR_DST] =
+ NLA_POLICY_EXACT_LEN(sizeof(struct in6_addr)),
[SEG6_ATTR_DSTLEN] = { .type = NLA_S32, },
[SEG6_ATTR_HMACKEYID] = { .type = NLA_U32, },
[SEG6_ATTR_SECRET] = { .type = NLA_BINARY, },
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 268/457] kprobes: Fix permanent hang when flushing the kprobe optimizer
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 267/457] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 269/457] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
` (199 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Andrea Parri,
Masami Hiramatsu (Google)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Parri <parri.andrea@gmail.com>
commit 5bfa9f1a9dcb6ecb607adbc1c0226605c972935b upstream.
Writing 0 to /proc/sys/debug/kprobes-optimization while a kprobe is
jump-optimized never returns. The writer sleeps in D state forever with
kprobe_sysctl_mutex held, so any later read or write of that sysctl
hangs as well. For example, with vfs_read+9 as an optimizable address
in this build:
# cd /sys/kernel/tracing
# echo 'p:myprobe vfs_read+9' >> kprobe_events
# echo 1 > events/kprobes/myprobe/enable
# # wait until /sys/kernel/debug/kprobes/list shows [OPTIMIZED]
# echo 0 > /proc/sys/debug/kprobes-optimization
INFO: task sh:246 blocked for more than 10 seconds.
Call Trace:
<TASK>
__schedule+0x1176/0x4f70
schedule+0xdc/0x2c0
schedule_timeout+0x17b/0x260
wait_for_completion+0x173/0x3c0
wait_for_kprobe_optimizer_locked+0xbc/0x130
proc_kprobes_optimization_handler+0x156/0x1b0
proc_sys_call_handler+0x324/0x490
vfs_write+0x52d/0xfe0
ksys_write+0xff/0x200
do_syscall_64+0x106/0x630
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
...
INFO: task cat:265 is blocked on a mutex likely owned by task sh:246.
wait_for_kprobe_optimizer_locked() reinitializes optimizer_completion,
asks the optimizer thread to flush and sleeps in wait_for_completion().
The thread drains the (un)optimizing lists, but calls complete() only
if completion_done() is true, i.e. if the completion is already done,
which never happens while someone waits. disarm_all_kprobes() and
kprobe_trace_self_tests_init() wait the same way.
Calling complete() unconditionally would not be enough: the waiter
drops kprobe_mutex while it sleeps, and nothing else serializes the
sysctl handler against the debugfs "enabled" file. A second flusher
that still finds the lists non-empty, e.g. because a disabled probe is
queued for unoptimizing, reinitializes the completion under the first:
sysctl write debugfs "enabled" write
unoptimize_all_kprobes()
wait_for_kprobe_optimizer_locked()
init_completion(c)
mutex_unlock(&kprobe_mutex)
wait_for_completion(c)
disarm_all_kprobes()
wait_for_kprobe_optimizer_locked()
init_completion(c)
// c->wait is reset, the first
// waiter is off the queue
mutex_unlock(&kprobe_mutex)
wait_for_completion(c)
kprobe_optimizer()
complete(c)
// wakes the debugfs writer only
where c is &optimizer_completion. Lining up the two writes during an
optimizer pass loses the sysctl writer this way.
Replace the completion with a counter of optimizer passes, bumped at the
end of each pass and signalled with wake_up_var_locked(), both under
kprobe_mutex. A flusher samples the count and waits with
wait_var_event_mutex(), which drops kprobe_mutex only while sleeping, so
a new count means a whole pass ran in the meantime. Nothing is
reinitialized, so several flushers can sleep in the wait at once.
Link: https://lore.kernel.org/all/20260924092142.199198-1-parri.andrea@gmail.com/
Fixes: 73c12f209462 ("kprobes: Use dedicated kthread for kprobe optimizer")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Andrea Parri <parri.andrea@gmail.com>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/kprobes.c | 22 ++++++++++++++--------
1 file changed, 14 insertions(+), 8 deletions(-)
diff --git a/kernel/kprobes.c b/kernel/kprobes.c
index 6337da5cab9e..4edd8ca5c657 100644
--- a/kernel/kprobes.c
+++ b/kernel/kprobes.c
@@ -42,6 +42,7 @@
#include <linux/execmem.h>
#include <linux/cleanup.h>
#include <linux/wait.h>
+#include <linux/wait_bit.h>
#include <asm/sections.h>
#include <asm/cacheflush.h>
@@ -526,7 +527,8 @@ enum {
OPTIMIZER_ST_FLUSHING = 2,
};
-static DECLARE_COMPLETION(optimizer_completion);
+/* Bumped at the end of each kprobe_optimizer() pass, under 'kprobe_mutex' */
+static unsigned long optimizer_passes;
#define OPTIMIZE_DELAY 5
@@ -654,9 +656,9 @@ static void kprobe_optimizer(void)
do_free_cleaned_kprobes();
}
- /* Step 5: Kick optimizer again if needed. But if there is a flush requested, */
- if (completion_done(&optimizer_completion))
- complete(&optimizer_completion);
+ /* Step 5: Wake up flushers, and kick optimizer again if needed. */
+ optimizer_passes++;
+ wake_up_var_locked(&optimizer_passes, &kprobe_mutex);
if (!list_empty(&optimizing_list) || !list_empty(&unoptimizing_list))
kick_kprobe_optimizer(); /*normal kick*/
@@ -708,7 +710,8 @@ static void wait_for_kprobe_optimizer_locked(void)
lockdep_assert_held(&kprobe_mutex);
while (!list_empty(&optimizing_list) || !list_empty(&unoptimizing_list)) {
- init_completion(&optimizer_completion);
+ unsigned long passes = optimizer_passes;
+
/*
* Set state to OPTIMIZER_ST_FLUSHING and wake up the thread if it's
* idle. If it's already kicked, it will see the state change.
@@ -717,9 +720,12 @@ static void wait_for_kprobe_optimizer_locked(void)
OPTIMIZER_ST_FLUSHING) != OPTIMIZER_ST_FLUSHING)
wake_up(&kprobe_optimizer_wait);
- mutex_unlock(&kprobe_mutex);
- wait_for_completion(&optimizer_completion);
- mutex_lock(&kprobe_mutex);
+ /*
+ * kprobe_optimizer() holds 'kprobe_mutex' for a whole pass, which
+ * this drops while sleeping, so a new count means a full pass ran.
+ */
+ wait_var_event_mutex(&optimizer_passes,
+ optimizer_passes != passes, &kprobe_mutex);
}
}
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 269/457] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 268/457] kprobes: Fix permanent hang when flushing the kprobe optimizer Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 270/457] gpio: cdev: fix kernel stack leak to user-space in error path Greg Kroah-Hartman
` (198 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Charles Keepax,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit e9d810279f84b30738f7790c0ed15f8dd5b9024a upstream.
Switching a persistent GPIO line from input to output acquires a
runtime PM reference on the parent device, but if the subsequent
regmap_update_bits() fails the reference is never dropped and no later
direction_in() can balance it since the direction was never changed.
Drop the reference on the update failure path.
Fixes: 27a49ed17e22 ("gpio: arizona: Add support for GPIOs that need to be maintained")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260916094701.2007509-1-vulab@iscas.ac.cn
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-arizona.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpio/gpio-arizona.c
+++ b/drivers/gpio/gpio-arizona.c
@@ -115,8 +115,12 @@ static int arizona_gpio_direction_out(st
if (value)
value = ARIZONA_GPN_LVL;
- return regmap_update_bits(arizona->regmap, ARIZONA_GPIO1_CTRL + offset,
- ARIZONA_GPN_DIR | ARIZONA_GPN_LVL, value);
+ ret = regmap_update_bits(arizona->regmap, ARIZONA_GPIO1_CTRL + offset,
+ ARIZONA_GPN_DIR | ARIZONA_GPN_LVL, value);
+ if (ret < 0 && (val & ARIZONA_GPN_DIR) && persistent)
+ pm_runtime_put_autosuspend(chip->parent);
+
+ return ret;
}
static int arizona_gpio_set(struct gpio_chip *chip, unsigned int offset,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 270/457] gpio: cdev: fix kernel stack leak to user-space in error path
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 269/457] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 271/457] gpio: zynq: fix runtime PM leak on request " Greg Kroah-Hartman
` (197 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Kent Gibson,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 1feb5d39b05afd902ed9fc902ec5b15be03a4bdb upstream.
If we fail to acquire the GPIO chip guard in gpio_desc_to_lineinfo(), we
return immediately before zeroing the info struct we'll end up passing
to the user-space later in lineinfo_get_v1(). This may leak the kernel
stack contents. Make gpio_desc_to_lineinfo() return int so that the
-ENODEV returned on failure to acquire the guard can be propagated to
the callers.
While not strictly necessary: move the memset() before trying to acquire
the SRCU read lock too for good measure.
Fixes: d83cee3d2bb1 ("gpio: protect the pointer to gpio_chip in gpio_device with SRCU")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260912123529.7951-1-tzungbi%40kernel.org?part=3
Reviewed-by: Kent Gibson <warthog618@gmail.com>
Link: https://patch.msgid.link/20260922-gpio-cdev-stack-leak-fixes-v3-1-7a0c7a4299d5@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpiolib-cdev.c | 32 +++++++++++++++++++++++++-------
1 file changed, 25 insertions(+), 7 deletions(-)
--- a/drivers/gpio/gpiolib-cdev.c
+++ b/drivers/gpio/gpiolib-cdev.c
@@ -2172,18 +2172,19 @@ static void gpio_v2_line_info_changed_to
#endif /* CONFIG_GPIO_CDEV_V1 */
-static void gpio_desc_to_lineinfo(struct gpio_desc *desc,
- struct gpio_v2_line_info *info, bool atomic)
+static int gpio_desc_to_lineinfo(struct gpio_desc *desc,
+ struct gpio_v2_line_info *info, bool atomic)
{
u32 debounce_period_us;
unsigned long dflags;
const char *label;
+ memset(info, 0, sizeof(*info));
+
CLASS(gpio_chip_guard, guard)(desc);
if (!guard.gc)
- return;
+ return -ENODEV;
- memset(info, 0, sizeof(*info));
info->offset = gpiod_hwgpio(desc);
if (desc->name)
@@ -2258,6 +2259,8 @@ static void gpio_desc_to_lineinfo(struct
debounce_period_us;
info->num_attrs++;
}
+
+ return 0;
}
struct gpio_chardev_data {
@@ -2309,6 +2312,7 @@ static int lineinfo_get_v1(struct gpio_c
struct gpio_desc *desc;
struct gpioline_info lineinfo;
struct gpio_v2_line_info lineinfo_v2;
+ int ret;
if (copy_from_user(&lineinfo, ip, sizeof(lineinfo)))
return -EFAULT;
@@ -2326,7 +2330,10 @@ static int lineinfo_get_v1(struct gpio_c
return -EBUSY;
}
- gpio_desc_to_lineinfo(desc, &lineinfo_v2, false);
+ ret = gpio_desc_to_lineinfo(desc, &lineinfo_v2, false);
+ if (ret)
+ return ret;
+
gpio_v2_line_info_to_v1(&lineinfo_v2, &lineinfo);
if (copy_to_user(ip, &lineinfo, sizeof(lineinfo))) {
@@ -2344,6 +2351,7 @@ static int lineinfo_get(struct gpio_char
{
struct gpio_desc *desc;
struct gpio_v2_line_info lineinfo;
+ int ret;
if (copy_from_user(&lineinfo, ip, sizeof(lineinfo)))
return -EFAULT;
@@ -2363,7 +2371,10 @@ static int lineinfo_get(struct gpio_char
if (test_and_set_bit(lineinfo.offset, cdev->watched_lines))
return -EBUSY;
}
- gpio_desc_to_lineinfo(desc, &lineinfo, false);
+
+ ret = gpio_desc_to_lineinfo(desc, &lineinfo, false);
+ if (ret)
+ return ret;
if (copy_to_user(ip, &lineinfo, sizeof(lineinfo))) {
if (watch)
@@ -2489,6 +2500,7 @@ static int lineinfo_changed_notify(struc
struct lineinfo_changed_ctx *ctx;
struct gpio_desc *desc = data;
struct file *fp;
+ int ret;
if (!test_bit(gpiod_hwgpio(desc), cdev->watched_lines))
return NOTIFY_DONE;
@@ -2519,7 +2531,13 @@ static int lineinfo_changed_notify(struc
ctx->chg.event_type = action;
ctx->chg.timestamp_ns = ktime_get_ns();
- gpio_desc_to_lineinfo(desc, &ctx->chg.info, true);
+
+ ret = gpio_desc_to_lineinfo(desc, &ctx->chg.info, true);
+ if (ret) {
+ fput(fp);
+ return NOTIFY_DONE;
+ }
+
/* Keep the GPIO device alive until we emit the event. */
ctx->gdev = gpio_device_get(desc->gdev);
ctx->cdev = cdev;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 271/457] gpio: zynq: fix runtime PM leak on request error path
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 270/457] gpio: cdev: fix kernel stack leak to user-space in error path Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 272/457] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
` (196 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ridham Khurana, Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ridham Khurana <khurana.ridham222@gmail.com>
commit e9438ab5328a177c9c0e5df87eb92a7162841e98 upstream.
pm_runtime_get_sync() leaves the usage counter incremented even when it
fails, and zynq_gpio_request() returns the error without dropping it.
gpiolib does not call ->free() when ->request() fails, so zynq_gpio_free(),
which holds the only matching pm_runtime_put(), never runs. The reference
is leaked and the controller can no longer runtime-suspend, so its clock
stays enabled.
Switch to pm_runtime_resume_and_get(), which only increments the usage
counter on success.
Fixes: 3242ba117e9b ("gpio: Add driver for Zynq GPIO controller")
Cc: stable@vger.kernel.org
Signed-off-by: Ridham Khurana <khurana.ridham222@gmail.com>
Link: https://patch.msgid.link/20260922092102.1053513-1-khurana.ridham222@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-zynq.c | 10 +---------
1 file changed, 1 insertion(+), 9 deletions(-)
--- a/drivers/gpio/gpio-zynq.c
+++ b/drivers/gpio/gpio-zynq.c
@@ -798,15 +798,7 @@ static int zynq_gpio_runtime_resume(stru
static int zynq_gpio_request(struct gpio_chip *chip, unsigned int offset)
{
- int ret;
-
- ret = pm_runtime_get_sync(chip->parent);
-
- /*
- * If the device is already active pm_runtime_get() will return 1 on
- * success, but gpio_request still needs to return 0.
- */
- return ret < 0 ? ret : 0;
+ return pm_runtime_resume_and_get(chip->parent);
}
static void zynq_gpio_free(struct gpio_chip *chip, unsigned int offset)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 272/457] llc: reserve device headroom for allocated frames
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 271/457] gpio: zynq: fix runtime PM leak on request " Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 273/457] mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag() Greg Kroah-Hartman
` (195 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, VEGA, Zixuan Chai, Ren Wei,
Eric Dumazet, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zixuan Chai <petalzu987@gmail.com>
commit 72b5b9a28b996e09b8b5b944370c79851bb68f52 upstream.
llc_alloc_frame() reserves link-layer headroom using the device type.
This is insufficient for stacked Ethernet devices such as VLAN devices,
where vlan_dev_hard_header() pushes a VLAN header before the lower
device's Ethernet header. An LLC response on such a device can
therefore underflow skb headroom in eth_header().
Use LL_RESERVED_SPACE() to account for the device's actual required
headroom while preserving the existing LLC device-type check.
Fixes: bf9ae5386bca ("llc: use dev_hard_header")
Cc: stable@vger.kernel.org
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Zixuan Chai <petalzu987@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924012613.2533934-1-weir@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/llc/llc_sap.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/net/llc/llc_sap.c
+++ b/net/llc/llc_sap.c
@@ -19,12 +19,12 @@
#include <linux/llc.h>
#include <linux/slab.h>
-static int llc_mac_header_len(unsigned short devtype)
+static int llc_mac_header_len(struct net_device *dev)
{
- switch (devtype) {
+ switch (dev->type) {
case ARPHRD_ETHER:
case ARPHRD_LOOPBACK:
- return sizeof(struct ethhdr);
+ return LL_RESERVED_SPACE(dev);
}
return 0;
}
@@ -45,7 +45,7 @@ struct sk_buff *llc_alloc_frame(struct s
int hlen = type == LLC_PDU_TYPE_U ? 3 : 4;
struct sk_buff *skb;
- hlen += llc_mac_header_len(dev->type);
+ hlen += llc_mac_header_len(dev);
skb = alloc_skb(hlen + data_size, GFP_ATOMIC);
if (skb) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 273/457] mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 272/457] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 274/457] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
` (194 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jeremy Kerr, Hui Peng,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 26cc0e69cce062cd3aa6fae33074684669c35a71 upstream.
When a socket transmits a packet with MCTP_TAG_PREALLOC set,
mctp_lookup_prealloc_tag() iterates over the per-netns &mns->keys list
and matches netid, req_tag, peer_addr, and manual_alloc, without
checking whether tmp->sk == &msk->sk. This allows any MCTP socket in the
same network namespace to use and consume another socket's preallocated
tag.
Iterate the socket's own tag list (&msk->keys via sklist) instead of the
namespace-wide &mns->keys list in mctp_lookup_prealloc_tag(), ensuring
that only tags allocated by msk are matched.
Tested in QEMU against Linux 7.3.0-rc3 by allocating a manual tag
(0x18) on socket A via SIOCMCTPALLOCTAG for peer EID 9 and sending a
4-byte message with MCTP_TAG_PREALLOC from socket B in the same network
namespace. On the unfixed kernel, sendto(sock_b) using socket A's
preallocated tag succeeds (ret = 4); with this patch applied,
sendto(sock_b) fails with -ENOENT (errno = 2) while sendto(sock_a)
succeeds (ret = 4).
Fixes: 63ed1aab3d40 ("mctp: Add SIOCMCTP{ALLOC,DROP}TAG ioctls for tag control")
Suggested-by: Jeremy Kerr <jk@codeconstruct.com.au>
Cc: stable@vger.kernel.org
Signed-off-by: Hui Peng <benquike@gmail.com>
Link: https://patch.msgid.link/20260921051002.1656692-1-benquike@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mctp/route.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/mctp/route.c
+++ b/net/mctp/route.c
@@ -825,7 +825,7 @@ static struct mctp_sk_key *mctp_lookup_p
spin_lock_irqsave(&mns->keys_lock, flags);
- hlist_for_each_entry(tmp, &mns->keys, hlist) {
+ hlist_for_each_entry(tmp, &msk->keys, sklist) {
if (tmp->net != netid)
continue;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 274/457] rds: ib: Clear the sg list when mapping an MR fails
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 273/457] mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 275/457] drm/client: fix restore of partially initialized client Greg Kroah-Hartman
` (193 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dongliang Qin, Allison Henderson,
Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dongliang Qin <cccccccccccc777777@gmail.com>
commit 58eb1b3325edac42dc6df72c80962bd53a3c8ca7 upstream.
rds_ib_map_frmr() stores the caller's scatterlist in the MR before DMA
mapping and registration can fail. On failure, __rds_rdma_map() unpins
the pages and frees the scatterlist, but rds_ib_free_frmr() can still
return the MR to the pool with the stale pointer set.
This leaves the pool with a dangling scatterlist and can lead to local
privilege escalation. KASAN detects the resulting use-after-free when the
MR is later torn down:
BUG: KASAN: slab-use-after-free in __rds_ib_teardown_mr
Read of size 8
Call Trace:
__rds_ib_teardown_mr
rds_ib_unreg_frmr
rds_ib_flush_mr_pool
rds_ib_flush_mrs
rds_free_mr
rds_setsockopt
Store the scatterlist in the MR only after DMA mapping succeeds. If DMA
mapping fails, return directly while the MR fields remain clear; the caller
keeps ownership of the scatterlist and its pinned pages. If a later
registration step fails, unmap the scatterlist and clear the MR fields
before returning.
Fixes: 1659185fb4d0 ("RDS: IB: Support Fastreg MR (FRMR) memory registration mode")
Cc: stable@vger.kernel.org
Signed-off-by: Dongliang Qin <cccccccccccc777777@gmail.com>
Reviewed-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260922031546.3874605-1-cccccccccccc777777@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_frmr.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
--- a/net/rds/ib_frmr.c
+++ b/net/rds/ib_frmr.c
@@ -204,19 +204,16 @@ static int rds_ib_map_frmr(struct rds_ib
*/
rds_ib_teardown_mr(ibmr);
- ibmr->sg = sg;
- ibmr->sg_len = sg_len;
- ibmr->sg_dma_len = 0;
frmr->sg_byte_len = 0;
- WARN_ON(ibmr->sg_dma_len);
- ibmr->sg_dma_len = ib_dma_map_sg(dev, ibmr->sg, ibmr->sg_len,
+ ibmr->sg_dma_len = ib_dma_map_sg(dev, sg, sg_len,
DMA_BIDIRECTIONAL);
if (unlikely(!ibmr->sg_dma_len)) {
pr_warn("RDS/IB: %s failed!\n", __func__);
return -EBUSY;
}
- frmr->sg_byte_len = 0;
+ ibmr->sg = sg;
+ ibmr->sg_len = sg_len;
frmr->dma_npages = 0;
len = 0;
@@ -264,6 +261,8 @@ out_unmap:
ib_dma_unmap_sg(rds_ibdev->dev, ibmr->sg, ibmr->sg_len,
DMA_BIDIRECTIONAL);
ibmr->sg_dma_len = 0;
+ ibmr->sg = NULL;
+ ibmr->sg_len = 0;
return ret;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 275/457] drm/client: fix restore of partially initialized client
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 274/457] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 276/457] drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl() Greg Kroah-Hartman
` (192 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, shechenglong, Thomas Zimmermann
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: shechenglong <shechenglong@xfusion.com>
commit 1fca688e9443003e33cf30453e7a7560367656c9 upstream.
I got a null-ptr-deref report when closing a DRM file descriptor:
WARNING: drivers/gpu/drm/drm_atomic.c:2031 at
__drm_atomic_helper_set_config+0x18e/0x1b0 [drm]
Call Trace:
drm_client_modeset_commit_atomic+0x16b/0x220 [drm]
drm_client_modeset_commit_locked+0x56/0x160 [drm]
drm_client_modeset_commit+0x21/0x40 [drm]
__drm_fb_helper_restore_fbdev_mode_unlocked.part.0+0x7b/0x80
drm_fbdev_client_restore+0xe/0x20 [drm_client_lib]
drm_client_dev_restore+0x9f/0xc0 [drm]
drm_release+0xc5/0xe0 [drm]
The warning is followed by a NULL pointer dereference:
BUG: kernel NULL pointer dereference, address: 0000000000000008
RIP:
__drm_fb_helper_restore_fbdev_mode_unlocked.part.0+0x41/0x80
[drm_kms_helper]
Call Trace:
drm_fbdev_client_restore+0xe/0x20 [drm_client_lib]
drm_client_dev_restore+0x9f/0xc0 [drm]
drm_release+0xc5/0xe0 [drm]
__fput+0xdc/0x2b0
__x64_sys_close+0x39/0x80
do_syscall_64+0x8d/0x460
entry_SYSCALL_64_after_hwframe+0x76/0x7e
drm_client_register() adds the DRM client to the device client list
before invoking the initial hotplug callback. If the hotplug callback
fails, the client remains registered.
For the fbdev client, a failure during drm_fb_helper_initial_config()
causes the partially initialized fbdev helper to be cleaned up.
drm_fb_helper_fini() releases fb_helper->info and leaves it NULL.
The fbdev client therefore remains registered even though there is no
fully initialized framebuffer device.
Later, when userspace closes the DRM file descriptor, drm_release()
can invoke the restore callbacks of registered DRM clients:
drm_release()
drm_client_dev_restore()
drm_fbdev_client_restore()
drm_fb_helper_restore_fbdev_mode_unlocked()
drm_fbdev_client_restore() currently restores the fbdev state
unconditionally. For a partially initialized fbdev client this can
submit an incomplete modeset state and subsequently access fbdev
state which has not been initialized, resulting in the warning and
NULL pointer dereference above.
drm_fbdev_client_unregister() already uses fb_helper->info to
distinguish a fully probed framebuffer device from a partially
initialized client.
Use the same condition in drm_fbdev_client_restore() and skip restore
if no framebuffer device has been successfully initialized.
Signed-off-by: shechenglong <shechenglong@xfusion.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: 5d08c44e47b9 ("drm/fbdev: Add memory-agnostic fbdev client")
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Cc: <stable@vger.kernel.org> # v6.13+
Link: https://patch.msgid.link/20260907035147.1339-1-shechenglong@xfusion.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/clients/drm_fbdev_client.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/gpu/drm/clients/drm_fbdev_client.c
+++ b/drivers/gpu/drm/clients/drm_fbdev_client.c
@@ -42,6 +42,14 @@ static int drm_fbdev_client_restore(stru
{
struct drm_fb_helper *fb_helper = drm_fb_helper_from_client(client);
+ /*
+ * The client is registered before the initial fbdev probe.
+ * If probing failed, the client remains registered but there
+ * is no valid fbdev framebuffer to restore.
+ */
+ if (!fb_helper->info || !fb_helper->fb)
+ return 0;
+
drm_fb_helper_restore_fbdev_mode_unlocked(fb_helper, force);
return 0;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 276/457] drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 275/457] drm/client: fix restore of partially initialized client Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 277/457] drm/imagination: Fix page count for page table for map() interface Greg Kroah-Hartman
` (191 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexandru Dadu, Alessio Belle,
Brajesh Gupta
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brajesh Gupta <brajesh.gupta@imgtec.com>
commit 7b824c293a6b56de8285a97984c507cba56bc4c4 upstream.
Map failure from pvr_mmu_map_sgl() interface was not returned correctly
to pvr_mmu_map() interface. This resulted in pvr_mmu_map() interface to
continue instead of returning an error to caller.
Fix it by returning a proper error code from pvr_mmu_map_sgl() interface.
Call stack for crash:
[ 1179.286237] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008
[ 1179.295067] Mem abort info:
[ 1179.297877] ESR = 0x0000000096000004
[ 1179.301656] EC = 0x25: DABT (current EL), IL = 32 bits
[ 1179.306987] SET = 0, FnV = 0
[ 1179.310048] EA = 0, S1PTW = 0
[ 1179.313198] FSC = 0x04: level 0 translation fault
[ 1179.318096] Data abort info:
[ 1179.320993] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
[ 1179.326483] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[ 1179.331546] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[ 1179.336895] user pgtable: 4k pages, 48-bit VAs, pgdp=000000009822a000
[ 1179.343402] [0000000000000008] pgd=0000000000000000, p4d=0000000000000000
[ 1179.350243] Internal error: Oops: 0000000096000004 [#2] SMP
[ 1179.355908] Modules linked in: powervr gpu_sched drm_shmem_helper drm_gpuvm drm_exec xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils dwc3_am62 at24 sa2ul sha512 libsha512 sha256 authenc sch_fq_codel fuse dm_mod ipv6
[ 1179.378992] CPU: 1 UID: 1000 PID: 680 Comm: deqp-vk Tainted: G D 6.17.0 #1 PREEMPT
[ 1179.388120] Tainted: [D]=DIE
[ 1179.390994] Hardware name: Texas Instruments AM625 SK (DT)
[ 1179.396467] pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 1179.403415] pc : pvr_mmu_op_context_unmap_curr_page+0x6c/0x134 [powervr]
[ 1179.410140] lr : pvr_mmu_op_context_unmap_curr_page+0x58/0x134 [powervr]
[ 1179.416848] sp : ffff8000839ab8c0
[ 1179.420153] x29: ffff8000839ab8c0 x28: 0000000000000001 x27: 000000008f386000
[ 1179.427283] x26: ffff000016d1df98 x25: 0000000000247000 x24: 00000000000001e6
[ 1179.434413] x23: 0000000000000002 x22: 000000000000ffff x21: 0000000000000247
[ 1179.441540] x20: 0000000000000245 x19: ffff000016d1df60 x18: 0000000000000002
[ 1179.448668] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000001
[ 1179.455793] x14: 0000000000060810 x13: ffff80007fffffff x12: ffff000004190480
[ 1179.462921] x11: ffff8000853f7000 x10: ffff8000811ae000 x9 : ffff0000041900b8
[ 1179.470051] x8 : 0000000000000000 x7 : 00000000990c4001 x6 : 0000000000000007
[ 1179.477177] x5 : ffff000016d1df60 x4 : 0000000000000000 x3 : ffff00000a7d8000
[ 1179.484306] x2 : 00000000000001ff x1 : 0000000000000000 x0 : 0000000000000000
[ 1179.491433] Call trace:
[ 1179.493872] pvr_mmu_op_context_unmap_curr_page+0x6c/0x134 [powervr] (P)
[ 1179.500582] pvr_mmu_map+0x31c/0x388 [powervr]
[ 1179.505027] pvr_vm_gpuva_map+0x40/0x88 [powervr]
[ 1179.509732] __drm_gpuvm_sm_map+0x250/0x44c [drm_gpuvm]
[ 1179.514952] drm_gpuvm_sm_map+0x48/0x5c [drm_gpuvm]
[ 1179.519822] pvr_vm_bind_op_exec+0x64/0x70 [powervr]
[ 1179.524785] pvr_vm_map+0x1f8/0x2a8 [powervr]
[ 1179.529142] pvr_ioctl_vm_map+0x12c/0x188 [powervr]
[ 1179.534018] drm_ioctl_kernel+0xb8/0x128
[ 1179.537941] drm_ioctl+0x21c/0x4ec
[ 1179.541337] __arm64_sys_ioctl+0xac/0x108
[ 1179.545344] invoke_syscall+0x44/0x100
[ 1179.549091] el0_svc_common.constprop.0+0x40/0xe0
[ 1179.553790] do_el0_svc+0x1c/0x28
[ 1179.557106] el0_svc+0x34/0xf0
[ 1179.560159] el0t_64_sync_handler+0xd0/0xe4
[ 1179.564334] el0t_64_sync+0x198/0x19c
[ 1179.567996] Code: 54000300 35000360 f9402261 79409a62 (f9400421)
[ 1179.574081] ---[ end trace 0000000000000000 ]---
Fixes: ff5f643de0bf ("drm/imagination: Add GEM and VM related code")
Reviewed-by: Alexandru Dadu <alexandru.dadu@imgtec.com>
Reviewed-by: Alessio Belle <alessio.belle@imgtec.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260922-mmu_fix-v4-1-12f1a871456a@imgtec.com
Signed-off-by: Brajesh Gupta <brajesh.gupta@imgtec.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/imagination/pvr_mmu.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/imagination/pvr_mmu.c
+++ b/drivers/gpu/drm/imagination/pvr_mmu.c
@@ -12,6 +12,7 @@
#include "pvr_rogue_mmu_defs.h"
#include <drm/drm_drv.h>
+#include <drm/drm_print.h>
#include <linux/atomic.h>
#include <linux/bitops.h>
#include <linux/dma-mapping.h>
@@ -2553,7 +2554,9 @@ pvr_mmu_map_sgl(struct pvr_mmu_op_contex
err_destroy_pages:
memcpy(&op_ctx->curr_page, &ptr_copy, sizeof(op_ctx->curr_page));
- err = pvr_mmu_op_context_unmap_curr_page(op_ctx, page);
+ if (pvr_mmu_op_context_unmap_curr_page(op_ctx, page))
+ drm_err(from_pvr_device(op_ctx->mmu_ctx->pvr_dev),
+ "%s : Failure in unmapping pages\n", __func__);
return err;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 277/457] drm/imagination: Fix page count for page table for map() interface
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 276/457] drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 278/457] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
` (190 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexandru Dadu, Alessio Belle,
Brajesh Gupta
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brajesh Gupta <brajesh.gupta@imgtec.com>
commit 0a8224058a5835297dcf4a46bbcd16f77a9fe424 upstream.
The GPU virtual start address wasn't included in the calculation for the
amount of page tables required for mapping a BO object in map() interface.
It resulted in map failure later due to not enough pages at L0/L1 level.
Update pvr_mmu_op_context_create() interface to pass device address as well
to allow correct calculation for page table memory.
If L0 tables cover 2MB (0x200000), the range defined by device address
0x80001ff000 (general heap at 2MB - 4KB) and size 0x2000 (two 4KB pages)
requires two L0 pages to be mapped, but without the base
address a range of 0x2000 computes to a single L0 page which is not enough.
Fixes: ff5f643de0bf ("drm/imagination: Add GEM and VM related code")
Reviewed-by: Alexandru Dadu <alexandru.dadu@imgtec.com>
Reviewed-by: Alessio Belle <alessio.belle@imgtec.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260922-mmu_fix-v4-2-12f1a871456a@imgtec.com
Signed-off-by: Brajesh Gupta <brajesh.gupta@imgtec.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/imagination/pvr_mmu.c | 14 ++++++++------
drivers/gpu/drm/imagination/pvr_mmu.h | 2 +-
drivers/gpu/drm/imagination/pvr_vm.c | 4 ++--
3 files changed, 11 insertions(+), 9 deletions(-)
--- a/drivers/gpu/drm/imagination/pvr_mmu.c
+++ b/drivers/gpu/drm/imagination/pvr_mmu.c
@@ -2336,6 +2336,7 @@ void pvr_mmu_op_context_destroy(struct p
* pvr_mmu_op_context_create() - Create an MMU op context.
* @ctx: MMU context associated with owning VM context.
* @sgt: Scatter gather table containing pages pinned for use by this context.
+ * @device_addr: Virtual device address at the start of the requested mapping.
* @sgt_offset: Start offset of the requested device-virtual memory mapping.
* @size: Size in bytes of the requested device-virtual memory mapping. For an
* unmapping, this should be zero so that no page tables are allocated.
@@ -2347,8 +2348,9 @@ void pvr_mmu_op_context_destroy(struct p
*/
struct pvr_mmu_op_context *
pvr_mmu_op_context_create(struct pvr_mmu_context *ctx, struct sg_table *sgt,
- u64 sgt_offset, u64 size)
+ u64 device_addr, u64 sgt_offset, u64 size)
{
+ u64 start_addr = device_addr + sgt_offset;
int err;
struct pvr_mmu_op_context *op_ctx = kzalloc_obj(*op_ctx);
@@ -2364,16 +2366,16 @@ pvr_mmu_op_context_create(struct pvr_mmu
if (size) {
/*
* The number of page table objects we need to prealloc is
- * indicated by the mapping size, start offset and the sizes
+ * indicated by the mapping size, start address and the sizes
* of the areas mapped per PT or PD. The range calculation is
* identical to that for the index into a table for a device
* address, so we reuse those functions here.
*/
- const u32 l1_start_idx = pvr_page_table_l2_idx(sgt_offset);
- const u32 l1_end_idx = pvr_page_table_l2_idx(sgt_offset + size);
+ const u32 l1_start_idx = pvr_page_table_l2_idx(start_addr);
+ const u32 l1_end_idx = pvr_page_table_l2_idx(start_addr + size);
const u32 l1_count = l1_end_idx - l1_start_idx + 1;
- const u32 l0_start_idx = pvr_page_table_l1_idx(sgt_offset);
- const u32 l0_end_idx = pvr_page_table_l1_idx(sgt_offset + size);
+ const u32 l0_start_idx = pvr_page_table_l1_idx(start_addr);
+ const u32 l0_end_idx = pvr_page_table_l1_idx(start_addr + size);
const u32 l0_count = l0_end_idx - l0_start_idx + 1;
/*
--- a/drivers/gpu/drm/imagination/pvr_mmu.h
+++ b/drivers/gpu/drm/imagination/pvr_mmu.h
@@ -99,7 +99,7 @@ dma_addr_t pvr_mmu_get_root_table_dma_ad
void pvr_mmu_op_context_destroy(struct pvr_mmu_op_context *op_ctx);
struct pvr_mmu_op_context *
pvr_mmu_op_context_create(struct pvr_mmu_context *ctx,
- struct sg_table *sgt, u64 sgt_offset, u64 size);
+ struct sg_table *sgt, u64 device_addr, u64 sgt_offset, u64 size);
int pvr_mmu_map(struct pvr_mmu_op_context *op_ctx, u64 size, u64 flags,
u64 device_addr);
--- a/drivers/gpu/drm/imagination/pvr_vm.c
+++ b/drivers/gpu/drm/imagination/pvr_vm.c
@@ -276,7 +276,7 @@ pvr_vm_bind_op_map_init(struct pvr_vm_bi
goto err_bind_op_fini;
bind_op->mmu_op_ctx =
- pvr_mmu_op_context_create(vm_ctx->mmu_ctx, sgt, offset, size);
+ pvr_mmu_op_context_create(vm_ctx->mmu_ctx, sgt, device_addr, offset, size);
err = PTR_ERR_OR_ZERO(bind_op->mmu_op_ctx);
if (err) {
bind_op->mmu_op_ctx = NULL;
@@ -318,7 +318,7 @@ pvr_vm_bind_op_unmap_init(struct pvr_vm_
}
bind_op->mmu_op_ctx =
- pvr_mmu_op_context_create(vm_ctx->mmu_ctx, NULL, 0, 0);
+ pvr_mmu_op_context_create(vm_ctx->mmu_ctx, NULL, device_addr, 0, 0);
err = PTR_ERR_OR_ZERO(bind_op->mmu_op_ctx);
if (err) {
bind_op->mmu_op_ctx = NULL;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 278/457] drm/i915: fix incorrect RCU teardown order
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 277/457] drm/imagination: Fix page count for page table for map() interface Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 279/457] drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1 Greg Kroah-Hartman
` (189 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König, Tvrtko Ursulin,
Tvrtko Ursulin, Jani Nikula
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian König <ckoenig.leichtzumerken@gmail.com>
commit d2da6696e0c4e60414706e607029d0bb0330c67e upstream.
i915_gem_busy_ioctl uses dma_resv_for_each_fence_unlocked() to iterate
over the fences in an GEM object without holding a reference but only
the RCU read side lock.
What can happen here is that the GEM object is destroyed concurrently
while i915_gem_busy_ioctl is still running. This won't free the GEM
objects memory, but still drops all the dma_fence references.
Now when dma_resv_for_each_fence_unlocked() sees a destroyed dma_fence it
assumes that a new fence list was installed and re-starts the loop.
But in the case of a destroyed GEM object a new fence list is never
installed, only the old one freed and therefore the iteration never
finishes resulting in an endless loop.
The solution is to drop the fence references only after the RCU grace
period.
The fixes tag is not necessary the patch introducing the problem, but the
one making it so worse that we need to address it.
This problem was pointed out by Sashiko-bot.
Signed-off-by: Christian König <christian.koenig@amd.com>
Fixes: 912ff2ebd695 ("drm/i915: use the new iterator in i915_gem_busy_ioctl v2")
CC: stable@vger.kernel.org
Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Signed-off-by: Tvrtko Ursulin <tursulin@ursulin.net>
Link: https://lore.kernel.org/r/20260903113621.54660-1-christian.koenig@amd.com
(cherry picked from commit 5113479556025093bf8133bb2dcaa33be2d50921)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/gem/i915_gem_object.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/i915/gem/i915_gem_object.c
+++ b/drivers/gpu/drm/i915/gem/i915_gem_object.c
@@ -89,6 +89,7 @@ struct drm_i915_gem_object *i915_gem_obj
void i915_gem_object_free(struct drm_i915_gem_object *obj)
{
+ dma_resv_fini(&obj->base._resv);
return kmem_cache_free(slab_objects, obj);
}
@@ -144,7 +145,6 @@ void __i915_gem_object_fini(struct drm_i
{
mutex_destroy(&obj->mm.get_page.lock);
mutex_destroy(&obj->mm.get_dma_page.lock);
- dma_resv_fini(&obj->base._resv);
}
/**
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 279/457] drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 278/457] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 280/457] drm/i915/dp_mst: Fix configuring FEC for a disconnected stream Greg Kroah-Hartman
` (188 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Annoy Cc, Ankit Nautiyal,
Nemesa Garg, Jani Nikula
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
commit 5271d81f99dd01d983d439930eb056952485e15e upstream.
The eDP panel on the HP Pavilion Plus Laptop 14-ew1xxx advertises HBR3
while leaving the TPS4 support bit clear. The output however flickers, once
link is trained with HBR3.
Until commit 8c9006283e4b ("Revert "drm/i915/dp: Reject HBR3 when sink
doesn't support TPS4"") such sinks were capped at HBR2 by the TPS4 check
which incidentally kept this panel stable. That check was reverted because
other panels legitimately need HBR3 without advertising TPS4, and the
per-machine QUIRK_EDP_LIMIT_RATE_HBR2 was introduced to handle the affected
machines instead.
Add the machine to the list of devices that need the
QUIRK_EDP_LIMIT_RATE_HBR2.
Fixes: 8c9006283e4b ("Revert "drm/i915/dp: Reject HBR3 when sink doesn't support TPS4"")
Reported-by: Annoy Cc <annoycc@gmail.com>
Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16743
Cc: <stable@vger.kernel.org> # v6.18+
Tested-by: Annoy Cc <annoycc@gmail.com>
Signed-off-by: Ankit Nautiyal <ankit.k.nautiyal@intel.com>
Reviewed-by: Nemesa Garg <nemesa.garg@intel.com>
Link: https://patch.msgid.link/20260907034555.2753846-1-ankit.k.nautiyal@intel.com
(cherry picked from commit 550b703fdbb2a2022faa75b4b11ab135241afbd9)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/display/intel_quirks.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/gpu/drm/i915/display/intel_quirks.c
+++ b/drivers/gpu/drm/i915/display/intel_quirks.c
@@ -257,6 +257,9 @@ static struct intel_quirk intel_quirks[]
/* Dell XPS 13 7390 2-in-1 */
{ 0x8a52, 0x1028, 0x08b0, quirk_edp_limit_rate_hbr2 },
+ /* HP Pavilion Plus Laptop 14-ew1xxx */
+ { 0x7d55, 0x103c, 0x8c31, quirk_edp_limit_rate_hbr2 },
+
/* Xiaomi Book Pro 14 2026 */
{ 0xb081, 0x1d72, 0x2424, quirk_disable_psr2 },
};
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 280/457] drm/i915/dp_mst: Fix configuring FEC for a disconnected stream
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 279/457] drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1 Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 281/457] drm/i915/dp_mst: Fix configuring TUs " Greg Kroah-Hartman
` (187 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luca Coelho, Imre Deak, Jani Nikula
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Imre Deak <imre.deak@intel.com>
commit acbe9a3b60b9a6ace8ef11fe898f586251c84592 upstream.
During an atomic commit after all the MST stream CRTC state is computed
the driver ensures that the FEC is configured the same way (enabled or
disabled) for all the streams on a given MST topology's link.
drm_dp_mst_port_downstream_of_parent() used to determine if a stream is
downstream of an MST port will return false if the whole topology is
disconnected, since in that case it can't verify that the port/
parent_port passed to it is in the given MST topology. This is a problem
during the above FEC configuration check, since
intel_dp_mst_check_dsc_change()->get_pipes_downstream_of_mst_ports()
will not return all the stream CRTCs/pipes for the topology as expected.
Since passing parent_port==NULL to get_pipes_downstream_of_mst_port()
is meant to return all the streams for the given topology (i.e. mst_mgr)
skip checking if an MST port is downstream of a parent port in this
case.
This fixes a problem where the FEC configuration check explained above
failed to ensure that all streams' FEC is configured the same way if the
topology was disconnected, leading to a FEC state mismatch error.
Cc: stable@vger.kernel.org # v6.10+
Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16073
Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16384
Reviewed-by: Luca Coelho <luciano.coelho@intel.com>
Signed-off-by: Imre Deak <imre.deak@intel.com>
Link: https://patch.msgid.link/20260907174413.741851-1-imre.deak@intel.com
(cherry picked from commit 270681fbffbba2b6ccf5b7e3c34b8b563b36167f)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/display/intel_dp_mst.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/i915/display/intel_dp_mst.c
+++ b/drivers/gpu/drm/i915/display/intel_dp_mst.c
@@ -813,7 +813,8 @@ static u8 get_pipes_downstream_of_mst_po
if (&connector->mst.dp->mst.mgr != mst_mgr)
continue;
- if (connector->mst.port != parent_port &&
+ if (parent_port &&
+ connector->mst.port != parent_port &&
!drm_dp_mst_port_downstream_of_parent(mst_mgr,
connector->mst.port,
parent_port))
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 281/457] drm/i915/dp_mst: Fix configuring TUs for a disconnected stream
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 280/457] drm/i915/dp_mst: Fix configuring FEC for a disconnected stream Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 282/457] drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping Greg Kroah-Hartman
` (186 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luca Coelho, Imre Deak, Jani Nikula
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Imre Deak <imre.deak@intel.com>
commit a443e0b8d647c1401b110d9f919d8c6cb8607260 upstream.
During an atomic commit after all the MST stream CRTC state is computed
the driver ensures that the sum of TUs of all the streams on a given MST
topology link is within limits (63 for 8b10 and 64 for 128b132b). For a
disconnected stream the DRM MST core's BW verification doesn't ensure
this, because the topology state it uses for this is destroyed as soon
as the stream (i.e. MST connector/port) is disconnected. The driver
should keep the link state valid even for such disconnected streams, as
userspace may disable them one-by-one only in a deferred way. Ensure the
link's sum of TUs stays within limits in this case by simply reusing the
maximum link BPP limit from the stream's (i.e. CRTC's) old state.
The disconnection can happen either via the whole topology getting
disconnected or via only the given stream's port getting disconnected.
Check for both of these conditions separately, as a connector gets
unregistered after a link disconnect event only in a deferred way.
Cc: stable@vger.kernel.org # v6.10+
Link: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16073
Link: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16384
Reviewed-by: Luca Coelho <luciano.coelho@intel.com>
Signed-off-by: Imre Deak <imre.deak@intel.com>
Link: https://patch.msgid.link/20260907174413.741851-2-imre.deak@intel.com
(cherry picked from commit ee00f8fbb2b202002ab90834e02e9ba372773a36)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/i915/display/intel_dp_mst.c | 21 +++++++++++++++++++++
drivers/gpu/drm/i915/display/intel_dp_mst.h | 2 ++
drivers/gpu/drm/i915/display/intel_link_bw.c | 3 ++-
3 files changed, 25 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/i915/display/intel_dp_mst.c
+++ b/drivers/gpu/drm/i915/display/intel_dp_mst.c
@@ -2122,6 +2122,27 @@ bool intel_dp_mst_crtc_needs_modeset(str
return false;
}
+bool intel_dp_mst_stream_disconnected(struct intel_atomic_state *state,
+ const struct intel_crtc *crtc)
+{
+ struct intel_connector *connector;
+
+ connector = get_connector_in_state_for_crtc(state, crtc);
+ if (!connector)
+ return false;
+
+ if (!connector->mst.dp)
+ return false;
+
+ if (!connector->mst.dp->mst.mgr.mst_state)
+ return true;
+
+ if (drm_connector_is_unregistered(&connector->base))
+ return true;
+
+ return false;
+}
+
/**
* intel_dp_mst_prepare_probe - Prepare an MST link for topology probing
* @intel_dp: DP port object
--- a/drivers/gpu/drm/i915/display/intel_dp_mst.h
+++ b/drivers/gpu/drm/i915/display/intel_dp_mst.h
@@ -28,6 +28,8 @@ int intel_dp_mst_atomic_check_link(struc
struct intel_link_bw_limits *limits);
bool intel_dp_mst_crtc_needs_modeset(struct intel_atomic_state *state,
struct intel_crtc *crtc);
+bool intel_dp_mst_stream_disconnected(struct intel_atomic_state *state,
+ const struct intel_crtc *crtc);
void intel_dp_mst_prepare_probe(struct intel_dp *intel_dp);
bool intel_dp_mst_verify_dpcd_state(struct intel_dp *intel_dp);
--- a/drivers/gpu/drm/i915/display/intel_link_bw.c
+++ b/drivers/gpu/drm/i915/display/intel_link_bw.c
@@ -64,7 +64,8 @@ void intel_link_bw_init_limits(struct in
intel_atomic_get_new_crtc_state(state, crtc);
int forced_bpp_x16 = get_forced_link_bpp_x16(state, crtc);
- if (state->base.duplicated && crtc_state) {
+ if ((state->base.duplicated && crtc_state) ||
+ intel_dp_mst_stream_disconnected(state, crtc)) {
limits->max_bpp_x16[pipe] = crtc_state->max_link_bpp_x16;
if (intel_dsc_enabled_on_link(crtc_state))
limits->link_dsc_pipes |= BIT(pipe);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 282/457] drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 281/457] drm/i915/dp_mst: Fix configuring TUs " Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 283/457] drm/amd/display: Fix dc stream excess put in dm_update_crtc_state() Greg Kroah-Hartman
` (185 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Asad Kamal, Lijo Lazar, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Asad Kamal <asad.kamal@amd.com>
commit c3a31087b1c8df679b653c1a09d9abe5ff7ec8ef upstream.
kfd_dev_mapping caches the address_space of the first /dev/kfd opener
so that the GPU reset path can call unmap_mapping_range() to zap all
userspace mappings of doorbell and MMIO ranges. This design has two
bugs that both manifest under SRIOV with multiple containers:
1. Use-after-free / rwsem deadlock. The cached pointer refers to an
inode owned by the first opener's container. When that container
exits and its inode is released, kfd_dev_mapping becomes a dangling
pointer. A subsequent GPU reset dereferences it inside
unmap_mapping_range(), which takes i_mmap_rwsem on the freed inode,
causing a hard hang observable as an uninterruptible rwsem wait.
2. Multi-container gap. Only the first opener's address_space is cached;
VMAs created by later openers live in a different address_space and
are never reached by unmap_mapping_range(). After a GPU reset those
stale mappings keep doorbell and MMIO pages accessible to guest
userspace with no GPU behind them, risking PCIe transaction timeouts
and NMI panics.
Fix both bugs with the same approach used by DRM core (drm_drv.c):
create a private pseudo-filesystem at module init time and allocate one
anonymous inode from it. In kfd_open() redirect every opener's
file->f_mapping to that inode's address_space. The inode is
module-owned, lives exactly as long as the amdgpu module, and collects
VMAs from all openers in one address_space. A single
unmap_mapping_range() call in the reset path then correctly reaches
every container's mappings with no dangling pointer risk.
The hang manifests as an NMI backtrace on the GPU reset workqueue stuck
spinning in rwsem_down_read_slowpath() with a corrupted i_mmap_rwsem:
Workqueue: amdgpu-reset-dev xgpu_ai_mailbox_flr_work [amdgpu]
Call Trace:
<TASK>
kvm_wait+0x1f/0x40
__pv_queued_spin_lock_slowpath+0x31d/0x3a0
_raw_spin_lock_irq+0x51/0x80
rwsem_down_read_slowpath+0xb3/0x550
down_read+0x48/0xd0
unmap_mapping_range+0x71/0x140
kfd_dev_unmap_mapping_range+0x5b/0x140 [amdgpu]
amdgpu_amdkfd_clear_kfd_mapping+0xd8/0x190 [amdgpu]
amdgpu_device_gpu_recover+0x232/0x450 [amdgpu]
xgpu_ai_mailbox_flr_work+0xb5/0xc0 [amdgpu]
process_one_work+0x18e/0x3e0
worker_thread+0x2e3/0x420
kthread+0x10a/0x230
Fixes: 70cadefcc616 ("drm/amdgpu: unmap all user mappings of framebuffer and doorbell before mode1 reset")
Signed-off-by: Asad Kamal <asad.kamal@amd.com>
Reviewed-by: Lijo Lazar <lijo.lazar@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 1128b4a52de1572e87431de837fd9850cb99542c)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_chardev.c | 71 +++++++++++++++++++-----
1 file changed, 57 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
index 504a286368eb..344da6c0e96a 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
@@ -35,6 +35,7 @@
#include <linux/time.h>
#include <linux/mm.h>
#include <linux/mman.h>
+#include <linux/pseudo_fs.h>
#include <linux/ptrace.h>
#include <linux/dma-buf.h>
#include <linux/processor.h>
@@ -70,18 +71,54 @@ static const struct class kfd_class = {
};
/*
- * Cache the address space of the chardev on first open so that the reset
- * path can drop all userspace mappings of doorbell and MMIO ranges via
- * unmap_mapping_range().
+ * Private pseudo-filesystem for KFD, Provides a stable, module-owned
+ * inode whose address_space is the unmap target for all /dev/kfd
+ * openers during GPU reset.
*/
-static struct address_space *kfd_dev_mapping;
+static struct vfsmount *kfd_fs_mnt;
+static int kfd_fs_cnt;
+
+static int kfd_fs_init_fs_context(struct fs_context *fc)
+{
+ return init_pseudo(fc, 0x4b464400 /* "KFD" */) ? 0 : -ENOMEM;
+}
+
+static struct file_system_type kfd_fs_type = {
+ .name = "kfd",
+ .init_fs_context = kfd_fs_init_fs_context,
+ .kill_sb = kill_anon_super,
+};
+
+static struct inode *kfd_fs_inode_new(void)
+{
+ struct inode *inode;
+ int r;
+
+ r = simple_pin_fs(&kfd_fs_type, &kfd_fs_mnt, &kfd_fs_cnt);
+ if (r < 0)
+ return ERR_PTR(r);
+
+ inode = alloc_anon_inode(kfd_fs_mnt->mnt_sb);
+ if (IS_ERR(inode))
+ simple_release_fs(&kfd_fs_mnt, &kfd_fs_cnt);
+
+ return inode;
+}
+
+static void kfd_fs_inode_free(struct inode *inode)
+{
+ if (inode) {
+ iput(inode);
+ simple_release_fs(&kfd_fs_mnt, &kfd_fs_cnt);
+ }
+}
+
+static struct inode *kfd_anon_inode;
void kfd_dev_unmap_mapping_range(loff_t const holebegin, loff_t const holelen)
{
- struct address_space *mapping = READ_ONCE(kfd_dev_mapping);
-
- if (mapping)
- unmap_mapping_range(mapping, holebegin, holelen, 1);
+ if (kfd_anon_inode)
+ unmap_mapping_range(kfd_anon_inode->i_mapping, holebegin, holelen, 1);
}
static inline struct kfd_process_device *kfd_lock_pdd_by_id(struct kfd_process *p, __u32 gpu_id)
@@ -107,6 +144,13 @@ int kfd_chardev_init(void)
{
int err = 0;
+ kfd_anon_inode = kfd_fs_inode_new();
+ if (IS_ERR(kfd_anon_inode)) {
+ err = PTR_ERR(kfd_anon_inode);
+ kfd_anon_inode = NULL;
+ return err;
+ }
+
kfd_char_dev_major = register_chrdev(0, kfd_dev_name, &kfd_fops);
err = kfd_char_dev_major;
if (err < 0)
@@ -130,6 +174,8 @@ int kfd_chardev_init(void)
err_class_create:
unregister_chrdev(kfd_char_dev_major, kfd_dev_name);
err_register_chrdev:
+ kfd_fs_inode_free(kfd_anon_inode);
+ kfd_anon_inode = NULL;
return err;
}
@@ -138,6 +184,8 @@ void kfd_chardev_exit(void)
device_destroy(&kfd_class, MKDEV(kfd_char_dev_major, 0));
class_unregister(&kfd_class);
unregister_chrdev(kfd_char_dev_major, kfd_dev_name);
+ kfd_fs_inode_free(kfd_anon_inode);
+ kfd_anon_inode = NULL;
kfd_device = NULL;
}
@@ -150,12 +198,7 @@ static int kfd_open(struct inode *inode, struct file *filep)
if (iminor(inode) != 0)
return -ENODEV;
- /*
- * /dev/kfd is a single chardev so all opens share one inode. Cache
- * its address_space on the first open for use by the reset path.
- */
- if (!READ_ONCE(kfd_dev_mapping))
- cmpxchg(&kfd_dev_mapping, NULL, inode->i_mapping);
+ filep->f_mapping = kfd_anon_inode->i_mapping;
is_32bit_user_mode = in_compat_syscall();
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 283/457] drm/amd/display: Fix dc stream excess put in dm_update_crtc_state()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 282/457] drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 284/457] drm/amd/display: Bump frame warning limit for clang builds of dml Greg Kroah-Hartman
` (184 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit c5fd4eaad50d620c7e09ac2082b2fb55ee54170e upstream.
In dm_update_crtc_state(), when a modeset is required the newly created
stream is stored in dm_new_crtc_state->stream and an extra reference is
taken with dc_stream_retain(). The reference returned by
create_validate_stream_for_sink() is released as an extra reference at
the skip_modeset label, leaving the stream owned by the new CRTC state.
If amdgpu_dm_check_crtc_color_mgmt() fails afterwards, the code jumps
to the fail label which releases new_stream again. Since the extra
reference was already released at skip_modeset, this drops the
reference owned by dm_new_crtc_state->stream and the stream is
released while the atomic state still points to it, leading to a
premature free of the dc stream.
Set new_stream to NULL after releasing the extra reference at the
skip_modeset label so that a later goto fail cannot release the
reference owned by the new CRTC state.
Fixes: 7cd4b70091a5 ("drm/amd/display: Rework CRTC color management")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 102a47065a62dc8f6bbbb47cf082a2934282eb08)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -12348,8 +12348,10 @@ static int dm_update_crtc_state(struct a
skip_modeset:
/* Release extra reference */
- if (new_stream)
+ if (new_stream) {
dc_stream_release(new_stream);
+ new_stream = NULL;
+ }
new_stream = NULL;
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 284/457] drm/amd/display: Bump frame warning limit for clang builds of dml
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 283/457] drm/amd/display: Fix dc stream excess put in dm_update_crtc_state() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 285/457] drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout Greg Kroah-Hartman
` (183 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ivan Lipski, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivan Lipski <ivan.lipski@amd.com>
commit 18779dd84515db093fedb4ebaf0998c9b165a5fb upstream.
[Why&How]
When building the DML files with clang without any sanitizer or LTO,
the following -Wframe-larger-than errors break the build under
CONFIG_WERROR:
display_mode_vba_30.c: error: stack frame size (2512) exceeds limit
(2048) in 'dml30_ModeSupportAndSystemConfigurationFull'
display_mode_vba_31.c: error: stack frame size (2416) exceeds limit
(2048) in 'dml31_ModeSupportAndSystemConfigurationFull'
display_mode_vba_314.c: error: stack frame size (2392) exceeds limit
(2048) in 'dml314_ModeSupportAndSystemConfigurationFull'
Clang consistently spills more than gcc, pushing the frame past the 2048
byte limit.
Apply an existing approach of increasing the warn stack size to the
non-sanitizer path so plain clang builds use a 3072 byte limit.
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5642
Signed-off-by: Ivan Lipski <ivan.lipski@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 21711b6e66bb7b41b1aec67b2d99aafe768c8fcb)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/dml/Makefile | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/display/dc/dml/Makefile
+++ b/drivers/gpu/drm/amd/display/dc/dml/Makefile
@@ -36,7 +36,11 @@ ifneq ($(CONFIG_FRAME_WARN),0)
frame_warn_limit := 3072
endif
else
- frame_warn_limit := 2048
+ ifeq ($(CONFIG_CC_IS_CLANG),y)
+ frame_warn_limit := 3072
+ else
+ frame_warn_limit := 2048
+ endif
endif
ifeq ($(call test-lt, $(CONFIG_FRAME_WARN), $(frame_warn_limit)),y)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 285/457] drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 284/457] drm/amd/display: Bump frame warning limit for clang builds of dml Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 286/457] drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait Greg Kroah-Hartman
` (182 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Christian König,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sunil Khatri <sunil.khatri@amd.com>
commit cd195f1616b2bb5fb7765465326c4d5d64a620a0 upstream.
Function amdgpu_userq_start_hang_detect_work() calls msecs_to_jiffies()
on adev->gfx_timeout/compute_timeout/sdma_timeout before arming
hang_detect_work. These timeout values already hold jiffies values from
amdgpu_device_get_job_timeout_settings() at device init.
This silently shrinks the real hang-detect deadline to (2 * HZ) ms
instead of the intended timeout. e.g. 500ms instead of the 2000ms
default on a CONFIG_HZ=250 kernel, only coincidentally correct at
HZ=1000. The shortened window is easily exceeded by ordinary
fence-completion latency, causing hang_detect_work to fire and
trigger a per-queue or full GPU reset for queues that are not
actually hung.
Pass the jiffies value directly to queue_delayed_work() instead of
converting it a second time.
Fixes: fc3336be9c62 ("drm/amd/amdgpu: Add independent hang detect work for user queue fence")
Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 13d44ca033cb74756c2aef0ade54a75cdf2f6271)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
@@ -167,27 +167,27 @@ static void amdgpu_userq_hang_detect_wor
void amdgpu_userq_start_hang_detect_work(struct amdgpu_usermode_queue *queue)
{
struct amdgpu_device *adev;
- unsigned long timeout_ms;
+ unsigned long timeout_jiffies;
adev = queue->userq_mgr->adev;
/* Determine timeout based on queue type */
switch (queue->queue_type) {
case AMDGPU_RING_TYPE_GFX:
- timeout_ms = adev->gfx_timeout;
+ timeout_jiffies = adev->gfx_timeout;
break;
case AMDGPU_RING_TYPE_COMPUTE:
- timeout_ms = adev->compute_timeout;
+ timeout_jiffies = adev->compute_timeout;
break;
case AMDGPU_RING_TYPE_SDMA:
- timeout_ms = adev->sdma_timeout;
+ timeout_jiffies = adev->sdma_timeout;
break;
default:
- timeout_ms = adev->gfx_timeout;
+ timeout_jiffies = adev->gfx_timeout;
break;
}
queue_delayed_work(adev->reset_domain->wq, &queue->hang_detect_work,
- msecs_to_jiffies(timeout_ms));
+ timeout_jiffies);
}
void amdgpu_userq_process_fence_irq(struct amdgpu_device *adev, u32 doorbell)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 286/457] drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 285/457] drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 287/457] drm/amdgpu/vcn5.0.1: " Greg Kroah-Hartman
` (181 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jesse.Zhang, Sunil Khatri,
Christian König, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sunil Khatri <sunil.khatri@amd.com>
commit 6b13ddbf5bb8deec337f9b4887f579097a953f6a upstream.
vcn_v4_0_3_reset_jpeg_pre_helper() passes adev->video_timeout directly
to amdgpu_fence_wait_polling(), whose timeout parameter is documented
and implemented in usecs (busy-wait loop decrementing by udelay(2)).
adev->video_timeout is set in jiffies by
amdgpu_device_get_job_timeout_settings(), via msecs_to_jiffies().
Passing it unconverted means the intended ~2s wait for outstanding
JPEG fences to complete before the JPEG queue is torn down actually
lasts only a couple of microseconds (HZ jiffies interpreted as usecs),
so pending jobs are almost never given a real chance to finish before
the reset path forces completion in the following helper.
Convert the jiffies value to usecs with jiffies_to_usecs() before
passing it to amdgpu_fence_wait_polling().
Fixes: d25c67fd9d6f ("drm/amdgpu/vcn4.0.3: rework reset handling")
Cc: Jesse.Zhang <Jesse.Zhang@amd.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 5feabbd673c10ebee22b880e4d812f08974d2ef7)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/vcn_v4_0_3.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0_3.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0_3.c
@@ -1672,7 +1672,8 @@ static int vcn_v4_0_3_reset_jpeg_pre_hel
/* if Jobs are still pending after timeout,
* We'll handle them in the bottom helper
*/
- amdgpu_fence_wait_polling(ring, wait_seq, adev->video_timeout);
+ amdgpu_fence_wait_polling(ring, wait_seq,
+ jiffies_to_usecs(adev->video_timeout));
}
return 0;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 287/457] drm/amdgpu/vcn5.0.1: fix video_timeout unit mismatch in jpeg reset wait
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 286/457] drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 288/457] drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc() Greg Kroah-Hartman
` (180 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jesse.Zhang, Sunil Khatri,
Christian König, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sunil Khatri <sunil.khatri@amd.com>
commit f952ed353a27b46c86c9525a39b7a642850b8139 upstream.
vcn_v5_0_1_reset_jpeg_pre_helper() passes adev->video_timeout directly
to amdgpu_fence_wait_polling(), whose timeout parameter is documented
and implemented in usecs (busy-wait loop decrementing by udelay(2)).
adev->video_timeout is set in jiffies by
amdgpu_device_get_job_timeout_settings(), via msecs_to_jiffies().
Passing it unconverted means the intended ~2s wait for outstanding
JPEG fences to complete before the JPEG queue is torn down actually
lasts only a couple of microseconds (HZ jiffies interpreted as usecs),
so pending jobs are almost never given a real chance to finish before
the reset path forces completion in the following helper.
Convert the jiffies value to usecs with jiffies_to_usecs() before
passing it to amdgpu_fence_wait_polling().
Fixes: fab47d2db5ca ("drm/amdgpu/vcn5.0.1: rework reset handling")
Cc: Jesse.Zhang <Jesse.Zhang@amd.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit b8334fec8b90ebffcaa01001a23edca9f29a05e9)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/vcn_v5_0_1.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v5_0_1.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v5_0_1.c
@@ -1318,7 +1318,8 @@ static int vcn_v5_0_1_reset_jpeg_pre_hel
/* if Jobs are still pending after timeout,
* We'll handle them in the bottom helper
*/
- amdgpu_fence_wait_polling(ring, wait_seq, adev->video_timeout);
+ amdgpu_fence_wait_polling(ring, wait_seq,
+ jiffies_to_usecs(adev->video_timeout));
}
return 0;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 288/457] drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 287/457] drm/amdgpu/vcn5.0.1: " Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 289/457] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
` (179 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lijo Lazar, Wentao Liang,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit a997baa61179b450bd55c4810c7ccfed3b753a54 upstream.
amdgpu_acpi_enumerate_xcc() looks up each XCC ACPI device with
acpi_dev_get_first_match_dev(), which takes a reference to the device.
The reference is dropped with acpi_dev_put() after the XCC info is
initialized, but if the kzalloc_obj() allocation of the XCC info fails
the function returns -ENOMEM without releasing the reference, leaking
the last reference to the ACPI device.
Drop the ACPI device reference on the allocation failure path before
returning.
Fixes: 4d5275ab0b18 ("drm/amdgpu: Add parsing of acpi xcc objects")
Reviewed-by: Lijo Lazar <lijo.lazar@amd.com>
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 9211ef48b31ec66999cf55e04d0cbc60cd855fd5)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c
@@ -1167,8 +1167,10 @@ int amdgpu_acpi_enumerate_xcc(void)
}
xcc_info = kzalloc_obj(struct amdgpu_acpi_xcc_info);
- if (!xcc_info)
+ if (!xcc_info) {
+ acpi_dev_put(acpi_dev);
return -ENOMEM;
+ }
INIT_LIST_HEAD(&xcc_info->list);
xcc_info->handle = acpi_device_handle(acpi_dev);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 289/457] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 288/457] drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 290/457] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
` (178 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit b4f7b4459b1b155e4c4977a6482b5df2cf08758c upstream.
amdgpu_vm_init() initializes vm->last_update, vm->last_unlocked and
vm->last_tlb_flush with references to the stub fence taken via
dma_fence_get_stub(). The error label at the end of the function
releases the last_unlocked and last_tlb_flush references with
dma_fence_put(), but the reference stored in vm->last_update is never
dropped, so whenever the page table root creation, the reservation of
the root BO or the PASID registration fails, the stub fence reference
leaks.
Drop the vm->last_update reference together with the other stub fence
references on the error path.
Fixes: 187916e6ed9d ("drm/amdgpu: install stub fence into potential unused fence pointers")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit e7979c84fc05a176bdf855ee664871b1648404c9)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -2665,6 +2665,7 @@ error_free_root:
amdgpu_bo_unref(&root_bo);
error_free_delayed:
+ dma_fence_put(vm->last_update);
dma_fence_put(vm->last_tlb_flush);
dma_fence_put(vm->last_unlocked);
ttm_lru_bulk_move_fini(&adev->mman.bdev, &vm->lru_bulk_move);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 290/457] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 289/457] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 291/457] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
` (177 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 2b86ab1bd6673c525adda88819d7658ba9e784ec upstream.
amdgpu_debugfs_test_ib_show() resumes the device with
pm_runtime_get_sync() before taking the reset domain semaphore with
down_write_killable(). If the write lock acquisition is interrupted,
the function returns without calling pm_runtime_put_autosuspend(),
leaking the runtime PM reference acquired for the device and keeping
the GPU awake.
Drop the runtime PM reference on the interrupted down_write_killable()
error path before returning.
Fixes: 6049db43d6dd ("drm/amdgpu: change reset lock from mutex to rw_semaphore")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ec30a576c2d4c0364549e6c04218f50704ef56c8)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
@@ -1773,8 +1773,10 @@ static int amdgpu_debugfs_test_ib_show(s
/* Avoid accidently unparking the sched thread during GPU reset */
r = down_write_killable(&adev->reset_domain->sem);
- if (r)
+ if (r) {
+ pm_runtime_put_autosuspend(dev->dev);
return r;
+ }
/* hold on the scheduler */
for (i = 0; i < AMDGPU_MAX_RINGS; i++) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 291/457] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 290/457] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 292/457] drm/amdgpu: move userq fence wait out of signalling section Greg Kroah-Hartman
` (176 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit aea841bc62a76242396610d22d8ff40c13065f64 upstream.
amdgpu_ring_init() initializes ring->vmid_wait with a reference to the
stub fence taken via dma_fence_get_stub(). When a later step of the
initialization fails, e.g. amdgpu_fence_driver_init_ring(), a writeback
slot allocation or the ring buffer allocation, the function returns an
error without releasing the stub fence reference and the reference is
leaked if the ring is torn down without amdgpu_ring_fini().
Move the stub fence assignment to the end of the initialization, right
before the ring is registered with the GPU scheduler, where no further
failure is possible. The stub fence is only consumed by command
submission handling in amdgpu_ids.c once the ring is up and running, so
nothing reads it during the error-prone part of the initialization.
Fixes: 48e9fbd1a284 ("drm/amdgpu: initialize the vmid_wait with the stub fence")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f2b96986851203e9c50ca0d13aaa3581ca3e8ebd)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c
@@ -254,7 +254,6 @@ int amdgpu_ring_init(struct amdgpu_devic
ring->adev = adev;
ring->num_hw_submission = sched_hw_submission;
ring->sched_score = sched_score;
- ring->vmid_wait = dma_fence_get_stub();
ring->idx = adev->num_rings++;
adev->rings[ring->idx] = ring;
@@ -374,6 +373,7 @@ int amdgpu_ring_init(struct amdgpu_devic
ring->max_dw = max_dw;
ring->hw_prio = hw_prio;
+ ring->vmid_wait = dma_fence_get_stub();
if (!ring->no_scheduler && ring->funcs->type < AMDGPU_HW_IP_NUM) {
hw_ip = ring->funcs->type;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 292/457] drm/amdgpu: move userq fence wait out of signalling section
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 291/457] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 293/457] drm/nouveau/dmem: pin VRAM for the whole registered range Greg Kroah-Hartman
` (175 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Prike Liang, Vitaly Prosyak,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Prike Liang <Prike.Liang@amd.com>
commit 3022bdfe3e6d776e9273d6892f7c193138ca0666 upstream.
The eviction fence suspend worker waits for every pending userq fence
from inside a dma_fence_begin_signalling() critical section. Waiting on
another DMA fence while responsible for signalling one violates the
cross-driver fence contract and is reported by lockdep as a
dma_fence_map dependency.
Move the wait before dma_fence_begin_signalling(). Keep userq_mutex held
so queue lifetime remains stable while inspecting last_fence.
Fixes: fc61df151617 ("drm/amdgpu: annotate eviction fence signaling path")
Signed-off-by: Prike Liang <Prike.Liang@amd.com>
Reviewed-by: Vitaly Prosyak <vitaly.prosyak@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 3bd4fbc5ed89621340b5cd249869092691a9c81f)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c | 3 +++
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c | 4 +---
drivers/gpu/drm/amd/amdgpu/amdgpu_userq.h | 1 +
3 files changed, 5 insertions(+), 3 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_eviction_fence.c
@@ -68,6 +68,9 @@ amdgpu_eviction_fence_suspend_worker(str
mutex_lock(&uq_mgr->userq_mutex);
+ /* Fence waits are not allowed in a fence signalling critical section. */
+ amdgpu_userq_wait_for_signal(uq_mgr);
+
/*
* This is intentionally after taking the userq_mutex since we do
* allocate memory while holding this lock, but only after ensuring that
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.c
@@ -1168,7 +1168,7 @@ amdgpu_userq_evict_all(struct amdgpu_use
return ret;
}
-static void
+void
amdgpu_userq_wait_for_signal(struct amdgpu_userq_mgr *uq_mgr)
{
struct amdgpu_usermode_queue *queue;
@@ -1187,8 +1187,6 @@ amdgpu_userq_wait_for_signal(struct amdg
void
amdgpu_userq_evict(struct amdgpu_userq_mgr *uq_mgr)
{
- /* Wait for any pending userqueue fence work to finish */
- amdgpu_userq_wait_for_signal(uq_mgr);
amdgpu_userq_evict_all(uq_mgr);
}
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.h
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_userq.h
@@ -156,6 +156,7 @@ void amdgpu_userq_mgr_cancel_reset_work(
void amdgpu_userq_mgr_cancel_resume(struct amdgpu_userq_mgr *userq_mgr);
void amdgpu_userq_mgr_fini(struct amdgpu_userq_mgr *userq_mgr);
+void amdgpu_userq_wait_for_signal(struct amdgpu_userq_mgr *uq_mgr);
void amdgpu_userq_evict(struct amdgpu_userq_mgr *uq_mgr);
void amdgpu_userq_ensure_ev_fence(struct amdgpu_userq_mgr *userq_mgr,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 293/457] drm/nouveau/dmem: pin VRAM for the whole registered range
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 292/457] drm/amdgpu: move userq fence wait out of signalling section Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 294/457] drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM Greg Kroah-Hartman
` (174 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Junrui Luo, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junrui Luo <moonafterrain@outlook.com>
commit 64ca4cdd1031206424e6455f0ae4fb0560d8f46a upstream.
Commit c32287471077 ("gpu/drm/nouveau: enable THP support for GPU memory
migration") grew the device-private region that
nouveau_dmem_chunk_alloc() registers from DMEM_CHUNK_SIZE to
DMEM_CHUNK_SIZE * NR_CHUNKS, but left the VRAM buffer object backing that
region at DMEM_CHUNK_SIZE.
nouveau_dmem_page_addr() returns chunk->bo->offset plus the page's offset
within the registered region, so every page past the first chunk resolves
to VRAM outside the buffer object.
Size the buffer object to the region it backs.
Fixes: c32287471077 ("gpu/drm/nouveau: enable THP support for GPU memory migration")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: LLM
Cc: stable@vger.kernel.org
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260817-nouveau-fixes-v1-1-f518d0c735f3@outlook.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_dmem.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/nouveau/nouveau_dmem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c
@@ -339,8 +339,8 @@ nouveau_dmem_chunk_alloc(struct nouveau_
chunk->pagemap.ops = &nouveau_dmem_pagemap_ops;
chunk->pagemap.owner = drm->dev;
- ret = nouveau_bo_new_pin(&drm->client, NOUVEAU_GEM_DOMAIN_VRAM, DMEM_CHUNK_SIZE,
- &chunk->bo);
+ ret = nouveau_bo_new_pin(&drm->client, NOUVEAU_GEM_DOMAIN_VRAM,
+ DMEM_CHUNK_SIZE * NR_CHUNKS, &chunk->bo);
if (ret)
goto out_release;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 294/457] drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 293/457] drm/nouveau/dmem: pin VRAM for the whole registered range Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 295/457] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
` (173 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 3359a372efb6d585c97019ee1b7f1874442bcebe upstream.
nouveau_uvmm_sm() calls op_map(), which passes bo->resource through
nouveau_mem() to nouveau_uvma_map(). nouveau_uvmm_vmm_map() then reads
mem->mem.type.
But this is only valid when bo->resource is backed by struct nouveau_mem,
as is the case for VRAM and TT resources. If the BO is left in
TTM_PL_SYSTEM, bo->resource is only a struct ttm_resource. Treating it
as struct nouveau_mem makes the mem->mem.type read past the end of the
resource, causing a KASAN: slab-use-after-free Read in nouveau_uvmm_sm
report:
BUG: KASAN: slab-use-after-free in nouveau_uvmm_vmm_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:152 [inline]
BUG: KASAN: slab-use-after-free in nouveau_uvma_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:199 [inline]
BUG: KASAN: slab-use-after-free in op_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:849 [inline]
BUG: KASAN: slab-use-after-free in nouveau_uvmm_sm.constprop.0+0x6ab/0x900 drivers/gpu/drm/nouveau/nouveau_uvmm.c:903
Read of size 1 at addr ffff888127d3e3a0 by task kworker/0:1/11
CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 7.2.0 #5 PREEMPT(lazy)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: nouveau_sched_wq_2224 drm_sched_run_job_work
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x95/0xe0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcb/0x5a0 mm/kasan/report.c:482
kasan_report+0xca/0x100 mm/kasan/report.c:595
nouveau_uvmm_vmm_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:152 [inline]
nouveau_uvma_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:199 [inline]
op_map drivers/gpu/drm/nouveau/nouveau_uvmm.c:849 [inline]
nouveau_uvmm_sm.constprop.0+0x6ab/0x900 drivers/gpu/drm/nouveau/nouveau_uvmm.c:903
nouveau_uvmm_sm_unmap drivers/gpu/drm/nouveau/nouveau_uvmm.c:932 [inline]
nouveau_uvmm_bind_job_run+0xd6/0x250 drivers/gpu/drm/nouveau/nouveau_uvmm.c:1532
nouveau_job_run drivers/gpu/drm/nouveau/nouveau_sched.c:350 [inline]
nouveau_sched_run_job+0x62/0xd0 drivers/gpu/drm/nouveau/nouveau_sched.c:364
drm_sched_run_job_work+0x356/0xa10 drivers/gpu/drm/scheduler/sched_main.c:1061
process_one_work+0x8a5/0x1900 kernel/workqueue.c:3322
process_scheduled_works kernel/workqueue.c:3405 [inline]
worker_thread+0x5dd/0xd80 kernel/workqueue.c:3486
kthread+0x31d/0x420 kernel/kthread.c:436
ret_from_fork+0x662/0x940 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Allocated by task 2224 on cpu 0 at 66.550027s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__do_kmalloc_node mm/slub.c:5334 [inline]
__kmalloc_noprof+0x304/0x7c0 mm/slub.c:5359
_kmalloc_noprof include/linux/slab.h:992 [inline]
dma_resv_list_alloc+0x27/0x90 drivers/dma-buf/dma-resv.c:106
dma_resv_reserve_fences+0x60e/0xa30 drivers/dma-buf/dma-resv.c:205
ttm_bo_alloc_resource+0x12c/0xbd0 drivers/gpu/drm/ttm/ttm_bo.c:721
ttm_bo_validate+0x1bc/0x4a0 drivers/gpu/drm/ttm/ttm_bo.c:856
ttm_bo_init_reserved+0x2c3/0x570 drivers/gpu/drm/ttm/ttm_bo.c:970
nouveau_bo_init+0x159/0x2c0 drivers/gpu/drm/nouveau/nouveau_bo.c:359
nouveau_gem_new+0x234/0x5f0 drivers/gpu/drm/nouveau/nouveau_gem.c:272
nouveau_gem_ioctl_new+0x1eb/0x420 drivers/gpu/drm/nouveau/nouveau_gem.c:352
drm_ioctl_kernel+0x192/0x350 drivers/gpu/drm/drm_ioctl.c:817
drm_ioctl+0x4f8/0xb40 drivers/gpu/drm/drm_ioctl.c:914
nouveau_drm_ioctl+0xea/0x2c0 drivers/gpu/drm/nouveau/nouveau_drm.c:1338
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x180/0x1d0 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 2223 on cpu 0 at 66.554063s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253 [inline]
__kasan_slab_free+0x61/0x80 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235 [inline]
slab_free_hook mm/slub.c:2677 [inline]
__rcu_free_sheaf_prepare+0xb6/0x2e0 mm/slub.c:2928
rcu_free_sheaf+0x1b/0x120 mm/slub.c:5978
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x521/0x1490 kernel/rcu/tree.c:2897
handle_softirqs+0x1b1/0x8a0 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
invoke_softirq kernel/softirq.c:496 [inline]
__irq_exit_rcu+0x137/0x1c0 kernel/softirq.c:735
irq_exit_rcu+0x9/0x20 kernel/softirq.c:752
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062 [inline]
sysvec_apic_timer_interrupt+0x70/0x80 arch/x86/kernel/apic/apic.c:1062
asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:674
The buggy address belongs to the object at ffff888127d3e380
which belongs to the cache kmalloc-96 of size 96
The buggy address is located 32 bytes inside of
freed 96-byte region [ffff888127d3e380, ffff888127d3e3e0)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x127d3e
flags: 0x200000000000000(node=0|zone=2)
page_type: f5(slab)
raw: 0200000000000000 ffff888100041280 dead000000000122 0000000000000000
raw: 0000000000000000 0000000000200020 00000000f5000000 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff888127d3e280: 00 00 00 00 00 00 00 00 00 fc fc fc fc fc fc fc
ffff888127d3e300: 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc fc
>ffff888127d3e380: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
^
ffff888127d3e400: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc
ffff888127d3e480: 00 00 00 00 00 00 00 00 00 00 fc fc fc fc fc fc
Fix by resetting the placement to the BO's valid domains before
calling nouveau_bo_validate(), matching the handling in
nouveau_uvmm_bo_validate(), so map jobs do not run for SYSTEM resources;
Reject BO that cannot reside in VRAM or GART;
Also skip op_map() when the GPUVA has been invalidated, matching the
handling in the unmap and remap paths.
Found when fuzzing the nouveau driver with a modified Syzkaller.
Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI")
Cc: stable@vger.kernel.org
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: Codex:gpt-5.5
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/0D77BEC410CE0129+20260907052204.1431488-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_uvmm.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
@@ -846,6 +846,9 @@ op_map(struct nouveau_uvma *uvma)
{
struct nouveau_bo *nvbo = nouveau_gem_object(uvma->va.gem.obj);
+ if (drm_gpuva_invalidated(&uvma->va))
+ return;
+
nouveau_uvma_map(uvma, nouveau_mem(nvbo->bo.resource));
}
@@ -1232,6 +1235,7 @@ bind_lock_validate(struct nouveau_job *j
drm_gpuva_for_each_op(va_op, op->ops) {
struct drm_gem_object *obj = op_gem_obj(va_op);
+ struct nouveau_bo *nvbo;
if (unlikely(!obj))
continue;
@@ -1246,8 +1250,13 @@ bind_lock_validate(struct nouveau_job *j
if (va_op->op == DRM_GPUVA_OP_UNMAP)
continue;
- ret = nouveau_bo_validate(nouveau_gem_object(obj),
- true, false);
+ nvbo = nouveau_gem_object(obj);
+ if (!(nvbo->valid_domains &
+ (NOUVEAU_GEM_DOMAIN_VRAM | NOUVEAU_GEM_DOMAIN_GART)))
+ return -EINVAL;
+
+ nouveau_bo_placement_set(nvbo, nvbo->valid_domains, 0);
+ ret = nouveau_bo_validate(nvbo, true, false);
if (ret)
return ret;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 295/457] drm/nouveau: fix autosuspend cleanup during teardown
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 294/457] drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 296/457] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
` (172 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit fefd9480ec361969f1a836df46326a1801062c26 upstream.
nouveau_drm_device_init() calls pm_runtime_use_autosuspend(), but
nouveau_drm_device_fini() does not call the matching
pm_runtime_dont_use_autosuspend().
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to the common
device teardown path.
This issue was found by manual code inspection.
Fixes: 5addcf0a5f0f ("nouveau: add runtime PM support (v0.9)")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260808134137.2864847-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_drm.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -585,6 +585,7 @@ nouveau_drm_device_fini(struct nouveau_d
if (nouveau_pmops_runtime()) {
pm_runtime_get_sync(dev->dev);
pm_runtime_forbid(dev->dev);
+ pm_runtime_dont_use_autosuspend(dev->dev);
}
nouveau_led_fini(dev);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 296/457] drm/nouveau: Fix bridge reference leak in nv1a_ram_new()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 295/457] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 297/457] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
` (171 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 67b4411538c8341692548429d43256f25be99f7a upstream.
pci_get_domain_bus_and_slot() takes a reference to the PCI device,
which is never released once the memory size has been read from its
config space. Drop the reference before returning.
Fixes: 2fa6d6cdaf283c05 ("drm/nouveau: deprecate pci_get_bus_and_slot()")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260916180036.2090118-1-vulab@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c
@@ -51,6 +51,8 @@ nv1a_ram_new(struct nvkm_fb *fb, struct
mib = ((mem >> 4) & 127) + 1;
}
+ pci_dev_put(bridge);
+
return nvkm_ram_new_(&nv04_ram_func, fb, NVKM_RAM_TYPE_STOLEN,
mib * 1024 * 1024, pram);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 297/457] drm/nouveau: fix double-free in nvif_vmm_dtor
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 296/457] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 298/457] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
` (170 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 97077ac87afe9e91ec074ef0be64454e7ccbf344 upstream.
On failure, nouveau_cli_init() calls nouveau_cli_fini() to tear
the client down. Then, nouveau_drm_open() also enters into its
cleanup path and calls nouveau_cli_fini() AGAIN. nouveau_cli_fini()
calls nouveau_vmm_fini():
void
nouveau_vmm_fini(struct nouveau_vmm *vmm)
{
nouveau_svmm_fini(&vmm->svmm);
nvif_vmm_dtor(&vmm->vmm);
vmm->cli = NULL;
}
Inside nvif_vmm_dtor(), vmm->page is freed unconditionally:
void
nvif_vmm_dtor(struct nvif_vmm *vmm)
{
kfree(vmm->page);
nvif_object_dtor(&vmm->object);
}
vmm->page is never cleared after being freed, so the second call of
nvif_vmm_dtor() will cause a double-free.
Found by fuzzing the nouveau driver with a modified Syzkaller:
BUG: KASAN: double-free in nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
Free of addr ffff888010fcdc30 by task syz.0.173/2567
CPU: 1 UID: 0 PID: 2567 Comm: syz.0.173 Not tainted 7.2.0 #24 PREEMPT(lazy)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x95/0xe0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0xcb/0x5a0 mm/kasan/report.c:482
kasan_report_invalid_free+0xaa/0xd0 mm/kasan/report.c:557
check_slab_allocation+0xe4/0x110 mm/kasan/common.c:235
kasan_slab_pre_free include/linux/kasan.h:199 [inline]
slab_free_hook mm/slub.c:2622 [inline]
slab_free mm/slub.c:6377 [inline]
kfree+0x192/0x590 mm/slub.c:6692
nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
nouveau_vmm_fini+0x16/0x50 drivers/gpu/drm/nouveau/nouveau_vmm.c:127
nouveau_cli_fini+0x10e/0x210 drivers/gpu/drm/nouveau/nouveau_drm.c:225
nouveau_drm_open+0x24e/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1255
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fc6d687594d
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc6d5295008 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 00007fc6d6b06180 RCX: 00007fc6d687594d
RDX: 0000000000022501 RSI: 0000200000000000 RDI: ffffffffffffff9c
RBP: 00007fc6d691c303 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fc6d6b06218 R14: 00007fc6d6b06180 R15: 00007ffd9451d760
</TASK>
Allocated by task 2567 on cpu 1 at 163.593900s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
poison_kmalloc_redzone mm/kasan/common.c:398 [inline]
__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415
kasan_kmalloc include/linux/kasan.h:263 [inline]
__do_kmalloc_node mm/slub.c:5334 [inline]
__kmalloc_noprof+0x304/0x7c0 mm/slub.c:5359
_kmalloc_noprof include/linux/slab.h:992 [inline]
nvif_vmm_ctor+0x3c0/0x7e0 drivers/gpu/drm/nouveau/nvif/vmm.c:237
nouveau_vmm_init+0x40/0x90 drivers/gpu/drm/nouveau/nouveau_vmm.c:134
nouveau_cli_init+0x7b9/0xe10 drivers/gpu/drm/nouveau/nouveau_drm.c:293
nouveau_drm_open+0x236/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1243
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 2567 on cpu 1 at 163.601355s:
kasan_save_stack+0x24/0x50 mm/kasan/common.c:57
kasan_save_track+0x17/0x60 mm/kasan/common.c:78
kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584
poison_slab_object mm/kasan/common.c:253 [inline]
__kasan_slab_free+0x61/0x80 mm/kasan/common.c:285
kasan_slab_free include/linux/kasan.h:235 [inline]
slab_free_hook mm/slub.c:2677 [inline]
slab_free mm/slub.c:6377 [inline]
kfree+0x383/0x590 mm/slub.c:6692
nvif_vmm_dtor+0x31/0x50 drivers/gpu/drm/nouveau/nvif/vmm.c:194
nouveau_vmm_fini+0x16/0x50 drivers/gpu/drm/nouveau/nouveau_vmm.c:127
nouveau_cli_fini+0x10e/0x210 drivers/gpu/drm/nouveau/nouveau_drm.c:225
nouveau_cli_init+0x593/0xe10 drivers/gpu/drm/nouveau/nouveau_drm.c:324
nouveau_drm_open+0x236/0x740 drivers/gpu/drm/nouveau/nouveau_drm.c:1243
drm_file_alloc+0x5f2/0xad0 drivers/gpu/drm/drm_file.c:176
drm_open_helper+0x1d7/0x4a0 drivers/gpu/drm/drm_file.c:335
drm_open+0x190/0x3d0 drivers/gpu/drm/drm_file.c:388
drm_stub_open+0x1f2/0x460 drivers/gpu/drm/drm_drv.c:1211
chrdev_open+0x21c/0x660 fs/char_dev.c:411
do_dentry_open+0x59d/0x12b0 fs/open.c:947
vfs_open+0x82/0x390 fs/open.c:1052
do_open fs/namei.c:4700 [inline]
path_openat+0x2345/0x3420 fs/namei.c:4863
do_file_open+0x207/0x460 fs/namei.c:4892
do_sys_openat2+0xd1/0x1d0 fs/open.c:1368
do_sys_open fs/open.c:1374 [inline]
__do_sys_openat fs/open.c:1390 [inline]
__se_sys_openat fs/open.c:1385 [inline]
__x64_sys_openat+0x144/0x200 fs/open.c:1385
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x690 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff888010fcdc30
which belongs to the cache kmalloc-16 of size 16
The buggy address is located 0 bytes inside of
16-byte region [ffff888010fcdc30, ffff888010fcdc40)
The buggy address belongs to the physical page:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x10fcd
flags: 0x100000000000000(node=0|zone=1)
page_type: f5(slab)
raw: 0100000000000000 ffff88800d441640 dead000000000100 dead000000000122
raw: 0000000000000000 0000000000550055 00000000f5000000 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff888010fcdb00: fc fc 00 04 fc fc fc fc fa fb fc fc fc fc fa fb
ffff888010fcdb80: fc fc fc fc fa fb fc fc fc fc 00 07 fc fc fc fc
>ffff888010fcdc00: fa fb fc fc fc fc fa fb fc fc fc fc fa fb fc fc
^
ffff888010fcdc80: fc fc fa fb fc fc fc fc 00 04 fc fc fc fc fa fb
ffff888010fcdd00: fc fc fc fc 00 00 fc fc fc fc fa fb fc fc fc fc
Fix by removing the redundant teardown in nouveau_drm_open(),
since nouveau_cli_init() already does the cleanup work.
Also clear vmm->page after its freeing.
Cc: stable@vger.kernel.org
Fixes: 20d8a88e557a ("drm/nouveau: tidy up the client init/fini interfaces")
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: LLM
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/03BA723D9E5FF725+20260916103138.2651605-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_drm.c | 4 +---
drivers/gpu/drm/nouveau/nvif/vmm.c | 1 +
2 files changed, 2 insertions(+), 3 deletions(-)
--- a/drivers/gpu/drm/nouveau/nouveau_drm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
@@ -1252,10 +1252,8 @@ nouveau_drm_open(struct drm_device *dev,
mutex_unlock(&drm->clients_lock);
done:
- if (ret && cli) {
- nouveau_cli_fini(cli);
+ if (ret && cli)
kfree(cli);
- }
pm_runtime_mark_last_busy(dev->dev);
pm_runtime_put_autosuspend(dev->dev);
--- a/drivers/gpu/drm/nouveau/nvif/vmm.c
+++ b/drivers/gpu/drm/nouveau/nvif/vmm.c
@@ -192,6 +192,7 @@ void
nvif_vmm_dtor(struct nvif_vmm *vmm)
{
kfree(vmm->page);
+ vmm->page = NULL;
nvif_object_dtor(&vmm->object);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 298/457] drm/nouveau: Fix gem reference leak in validate_init()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 297/457] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 299/457] drm/nouveau: Fix runtime PM leak in nouveau_connector_detect() Greg Kroah-Hartman
` (169 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 5ea72f7b7139b123713a7983448f910bc4514d9e upstream.
On the ttm_bo_reserve() failure and "vma not found" error paths, the
loop breaks without adding the looked-up object to any validate list,
so the reference taken by drm_gem_object_lookup() is never released;
validate_fini() only walks the spliced lists. Drop the reference
before breaking out on both paths.
Fixes: 19ca10d82e33bcfe ("drm/nouveau/gem: lookup VMAs for buffers referenced by pushbuf ioctl")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260916180202.2090231-1-vulab@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_gem.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/nouveau/nouveau_gem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_gem.c
@@ -522,6 +522,7 @@ retry:
if (unlikely(ret)) {
if (ret != -ERESTARTSYS)
NV_PRINTK(err, cli, "fail reserve\n");
+ drm_gem_object_put(gem);
break;
}
}
@@ -531,6 +532,7 @@ retry:
struct nouveau_vma *vma = nouveau_vma_find(nvbo, vmm);
if (!vma) {
NV_PRINTK(err, cli, "vma not found!\n");
+ drm_gem_object_put(gem);
ret = -EINVAL;
break;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 299/457] drm/nouveau: Fix runtime PM leak in nouveau_connector_detect()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 298/457] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 300/457] drm/nouveau: RCU-free the scheduler-containing nouveau_sched Greg Kroah-Hartman
` (168 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 1e04611d3735543bd80a67d9d13dc13f503746fb upstream.
If nvif_outp_edid_get() fails, nouveau_connector_detect() returns
early without dropping the runtime PM reference taken at the start
of the function, keeping the device powered on until the next
successful detect.
Balance the reference on the error path like the other exit paths
do.
Fixes: 0cd7e0718139 ("drm/nouveau/disp: add output method to fetch edid")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260916180342.2090360-1-vulab@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_connector.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nouveau_connector.c
+++ b/drivers/gpu/drm/nouveau/nouveau_connector.c
@@ -600,8 +600,11 @@ nouveau_connector_detect(struct drm_conn
new_edid = drm_get_edid(connector, nv_encoder->i2c);
} else {
ret = nvif_outp_edid_get(&nv_encoder->outp, (u8 **)&new_edid);
- if (ret < 0)
+ if (ret < 0) {
+ pm_runtime_mark_last_busy(dev->dev);
+ pm_runtime_put_autosuspend(dev->dev);
return connector_status_disconnected;
+ }
}
nouveau_connector_set_edid(nv_connector, new_edid);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 300/457] drm/nouveau: RCU-free the scheduler-containing nouveau_sched
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 299/457] drm/nouveau: Fix runtime PM leak in nouveau_connector_detect() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 301/457] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
` (167 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jonghyuk Kim(MalHyuk), Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
commit f7eae6d8d768fabd6b59779ca7da79e02c74e113 upstream.
struct nouveau_sched embeds a struct drm_gpu_scheduler (base).
nouveau_sched_destroy() calls nouveau_sched_fini() (which does
drm_sched_fini(&sched->base)) and then frees the object with plain
kfree(sched).
drm_sched_fence_get_timeline_name() returns fence->sched->name, and the
scheduler fence keeps a .release callback so it is not ops-detached on
signalling. A finished fence exported to userspace via drm_syncobj /
sync_file therefore keeps pointing at &sched->base after nouveau_sched_destroy(),
and a later get_timeline_name() -- reachable unprivileged through
SYNC_IOC_FILE_INFO -- dereferences freed memory (KASAN slab-use-after-free
read).
Per the dma-fence lifetime contract the exporter must keep the data backing a
signalled fence alive for an RCU grace period. Free the scheduler-containing
object with kfree_rcu() instead of kfree().
Fixes: 5f03a507b29e ("drm/nouveau: implement 1:1 scheduler - entity relationship")
Cc: stable@vger.kernel.org
Signed-off-by: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260902012717.880724-1-malhyuk97@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_sched.c | 2 +-
drivers/gpu/drm/nouveau/nouveau_sched.h | 1 +
2 files changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nouveau_sched.c
+++ b/drivers/gpu/drm/nouveau/nouveau_sched.c
@@ -517,7 +517,7 @@ nouveau_sched_destroy(struct nouveau_sch
struct nouveau_sched *sched = *psched;
nouveau_sched_fini(sched);
- kfree(sched);
+ kfree_rcu(sched, rcu);
*psched = NULL;
}
--- a/drivers/gpu/drm/nouveau/nouveau_sched.h
+++ b/drivers/gpu/drm/nouveau/nouveau_sched.h
@@ -98,6 +98,7 @@ void nouveau_job_free(struct nouveau_job
struct nouveau_sched {
struct drm_gpu_scheduler base;
+ struct rcu_head rcu;
struct drm_sched_entity entity;
struct workqueue_struct *wq;
struct mutex mutex;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 301/457] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 300/457] drm/nouveau: RCU-free the scheduler-containing nouveau_sched Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 302/457] drm/xe/vm: nuke PTs only after unlinking contested VMAs Greg Kroah-Hartman
` (166 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Lyude Paul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 6a6870d3077faa501ca97760057ddca22b68418d upstream.
nouveau_bo_pin_locked() checks whether an already pinned BO is in a
memory domain compatible with a new pin request. When the domains are
incompatible, it sets -EBUSY but still calls ttm_bo_pin() before
returning.
Callers treat a failed nouveau_bo_pin() as not having acquired a new pin,
so the extra pin count is never decreased by a matching unpin.
This triggers the warning in ttm_bo_release():
WARN_ON_ONCE(bo->pin_count);
Found when fuzzing the nouveau driver with a modified Syzkaller:
WARNING: drivers/gpu/drm/ttm/ttm_bo.c:256 at ttm_bo_release+0x827/0x9e0 drivers/gpu/drm/ttm/ttm_bo.c:256, CPU#1: syz.3.24/2212
Modules linked in:
CPU: 1 UID: 0 PID: 2212 Comm: syz.3.24 Not tainted 7.2.0 #24 PREEMPT(lazy)
nouveau 0000:01:00.0: gsp:msg fn:103 len:0x40/0x20 res:0x19 resp:0x19
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:ttm_bo_release+0x827/0x9e0 drivers/gpu/drm/ttm/ttm_bo.c:256
Code: 02 00 0f 85 51 01 00 00 48 8b 7b 08 e8 d2 20 01 00 e9 80 fd ff ff e8 d8 15 c0 fe 90 0f 0b 90 e9 e1 f8 ff ff e8 ca 15 c0 fe 90 <0f> 0b 90 e9 a4 f8 ff ff e8 bc 15 c0 fe be 03 00 00 00 4c 89 e7 e8
msg: 00000000: 05 00 d0 c1 04 00 f0 f1 01 30 00 00 2d 90 00 00 .........0..-...
RSP: 0018:ffffc9000f5cf710 EFLAGS: 00010293
RAX: 0000000000000000 RBX: ffff888018e5d2a8 RCX: ffffffff82bb1b36
RDX: ffff888017b68000 RSI: 0000000000000004 RDI: ffff888018e5d2a8
msg: 00000010: 19 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
RBP: ffff88801261c720 R08: 0000000000000001 R09: ffffed10031cba55
R10: ffff888018e5d2ab R11: 00000000000000f3 R12: ffff888018e5d290
R13: ffff888018e5d2d4 R14: ffff88801b219c18 R15: dffffc0000000000
FS: 0000000000000000(0000) GS:ffff8880e0f6f000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000001b31223ffc CR3: 0000000028e00005 CR4: 0000000000770ef0
PKRU: 80000000
Call Trace:
<TASK>
kref_put include/linux/kref.h:65 [inline]
ttm_bo_put drivers/gpu/drm/ttm/ttm_bo.c:325 [inline]
ttm_bo_fini+0x55/0x80 drivers/gpu/drm/ttm/ttm_bo.c:330
nouveau_gem_object_del+0xb2/0x1b0 drivers/gpu/drm/nouveau/nouveau_gem.c:90
drm_gem_object_free+0x5f/0x90 drivers/gpu/drm/drm_gem.c:1165
kref_put include/linux/kref.h:65 [inline]
__drm_gem_object_put include/drm/drm_gem.h:562 [inline]
drm_gem_object_put include/drm/drm_gem.h:575 [inline]
nouveau_abi16_chan_fini.constprop.0+0x44f/0x5a0 drivers/gpu/drm/nouveau/nouveau_abi16.c:195
nouveau 0000:01:00.0: syz.2.23[2209]: Unknown handle 0x00000000
nouveau_abi16_fini+0x1d0/0x340 drivers/gpu/drm/nouveau/nouveau_abi16.c:225
nouveau_drm_postclose+0x18b/0x3e0 drivers/gpu/drm/nouveau/nouveau_drm.c:1284
nouveau 0000:01:00.0: syz.2.23[2209]: validate_init
drm_file_free.part.0+0x6d6/0xb60 drivers/gpu/drm/drm_file.c:267
drm_file_free drivers/gpu/drm/drm_file.c:237 [inline]
drm_close_helper.isra.0+0x11a/0x160 drivers/gpu/drm/drm_file.c:290
drm_release+0x1ab/0x330 drivers/gpu/drm/drm_file.c:438
__fput+0x39c/0xa60 fs/file_table.c:512
nouveau 0000:01:00.0: syz.2.23[2209]: validate: -2
task_work_run+0x15a/0x230 kernel/task_work.c:233
exit_task_work include/linux/task_work.h:40 [inline]
do_exit+0x82b/0x25a0 kernel/exit.c:1009
do_group_exit+0xc2/0x280 kernel/exit.c:1152
get_signal+0x1d6e/0x1f30 kernel/signal.c:3046
arch_do_signal_or_restart+0x7d/0x6e0 arch/x86/kernel/signal.c:337
__exit_to_user_mode_loop kernel/entry/common.c:66 [inline]
exit_to_user_mode_loop+0xdf/0x440 kernel/entry/common.c:101
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:207 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:230 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:318 [inline]
do_syscall_64+0x4f8/0x690 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f12bac8594d
Code: Unable to access opcode bytes at 0x7f12bac85923.
RSP: 002b:00007f12b96e70d8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca
RAX: 0000000000000001 RBX: 00007f12baf15fa8 RCX: 00007f12bac8594d
RDX: 00000000000f4240 RSI: 0000000000000081 RDI: 00007f12baf15fac
RBP: 00007f12baf15fa0 R08: 00007f12baee8000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f12baf16038 R14: 0000000000000006 R15: 00007ffe2ed394b0
</TASK>
irq event stamp: 47867
hardirqs last enabled at (47883): [<ffffffff815cafc6>] __up_console_sem+0x66/0x70 kernel/printk/printk.c:347
hardirqs last disabled at (47892): [<ffffffff815cafab>] __up_console_sem+0x4b/0x70 kernel/printk/printk.c:345
softirqs last enabled at (47880): [<ffffffff81434277>] __do_softirq kernel/softirq.c:656 [inline]
softirqs last enabled at (47880): [<ffffffff81434277>] invoke_softirq kernel/softirq.c:496 [inline]
softirqs last enabled at (47880): [<ffffffff81434277>] __irq_exit_rcu+0x137/0x1c0 kernel/softirq.c:735
softirqs last disabled at (47875): [<ffffffff81434277>] __do_softirq kernel/softirq.c:656 [inline]
softirqs last disabled at (47875): [<ffffffff81434277>] invoke_softirq kernel/softirq.c:496 [inline]
softirqs last disabled at (47875): [<ffffffff81434277>] __irq_exit_rcu+0x137/0x1c0 kernel/softirq.c:735
Fix by calling ttm_bo_pin() only when the existing placement is compatible
with the new pin request. This matches the correct behavior in other DRM
drivers such as amdgpu_bo_pin() in amdgpu.
Cc: stable@vger.kernel.org
Fixes: ad76b3f7c7a0 ("drm/nouveau: teach nouveau_bo_pin() how to force a contig vram allocation")
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: LLM
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/EACEF2F4E098413F+20260918025312.2814889-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nouveau_bo.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nouveau_bo.c
+++ b/drivers/gpu/drm/nouveau/nouveau_bo.c
@@ -578,8 +578,9 @@ int nouveau_bo_pin_locked(struct nouveau
"0x%08x vs 0x%08x\n", bo,
bo->resource->mem_type, domain);
ret = -EBUSY;
+ } else {
+ ttm_bo_pin(&nvbo->bo);
}
- ttm_bo_pin(&nvbo->bo);
goto out;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 302/457] drm/xe/vm: nuke PTs only after unlinking contested VMAs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 301/457] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 303/457] drm/xe: harden adjust_idledly() against divide-by-zero and overflow Greg Kroah-Hartman
` (165 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Auld, Thomas Hellström,
Matthew Brost, Rodrigo Vivi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Auld <matthew.auld@intel.com>
commit 24a22fb3c731474b68e986af6804db450fb88617 upstream.
In xe_vm_close_and_put(), external-BO VMAs are queued on the contested
list for deferred destruction via xe_vma_destroy_unlocked(). However,
xe_vm_pt_destroy() was previously invoked before processing contested
VMAs, destroying vm->pt_root while those VMAs were still linked to their
respective buffer objects (vm_bo->list.gpuva).
If a concurrent thread evicts one of those shared buffer objects,
xe_bo_trigger_rebind() holding only bo->resv walks the BO's VMAs and, in
fault mode, calls xe_vm_invalidate_vma() -> xe_pt_zap_ptes(). Because
vm->pt_root[tile->id] is already NULL, dereferencing pt->level causes a
NULL ptr deref.
Fix this by deferring xe_vm_free_scratch() and xe_vm_pt_destroy() until
after all contested VMAs have been unlinked and destroyed.
User is reporting hitting a NULL ptr deref in xe_pt_zap_ptes(), which
could be explained by this race.
Assisted-by: LLM
Fixes: b06d47be7c83 ("drm/xe: Port Xe to GPUVA")
Link: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/9290
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: <stable@vger.kernel.org> # v6.12+
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260918131034.598078-2-matthew.auld@intel.com
(cherry picked from commit c2863648959489767f08892fd6e90577d2ea0b6a)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_vm.c | 21 +++++++++------------
1 file changed, 9 insertions(+), 12 deletions(-)
--- a/drivers/gpu/drm/xe/xe_vm.c
+++ b/drivers/gpu/drm/xe/xe_vm.c
@@ -1933,21 +1933,13 @@ void xe_vm_close_and_put(struct xe_vm *v
vma->gpuva.flags |= XE_VMA_DESTROYED;
}
- /*
- * All vm operations will add shared fences to resv.
- * The only exception is eviction for a shared object,
- * but even so, the unbind when evicted would still
- * install a fence to resv. Hence it's safe to
- * destroy the pagetables immediately.
- */
- xe_vm_free_scratch(vm);
- xe_vm_pt_destroy(vm);
xe_vm_unlock(vm);
/*
- * VM is now dead, cannot re-add nodes to vm->vmas if it's NULL
- * Since we hold a refcount to the bo, we can remove and free
- * the members safely without locking.
+ * Unlink and destroy all contested external-BO VMAs before destroying
+ * the page tables. Otherwise, concurrent eviction holding only bo->resv
+ * can walk the BO's VMAs and attempt to invalidate/zap page tables that
+ * have already been freed.
*/
list_for_each_entry_safe(vma, next_vma, &contested,
combined_links.destroy) {
@@ -1955,6 +1947,11 @@ void xe_vm_close_and_put(struct xe_vm *v
xe_vma_destroy_unlocked(vma);
}
+ xe_vm_lock(vm, false);
+ xe_vm_free_scratch(vm);
+ xe_vm_pt_destroy(vm);
+ xe_vm_unlock(vm);
+
xe_svm_fini(vm);
up_write(&vm->lock);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 303/457] drm/xe: harden adjust_idledly() against divide-by-zero and overflow
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 302/457] drm/xe/vm: nuke PTs only after unlinking contested VMAs Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 304/457] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV Greg Kroah-Hartman
` (164 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tangudu Tilak Tirumalesh,
Vinay Belgaumkar, Matt Roper, Rodrigo Vivi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
commit 90f467577ebc28c5bc4ba2f0f1b83a4419fb0740 upstream.
adjust_idledly() has several corner-case issues flagged during review:
1. If xe_gt_clock_init() failed to recognise the crystal clock,
gt->info.timestamp_base is 0, which makes idledly_units_ps also 0.
The subsequent DIV_ROUND_CLOSEST(..., idledly_units_ps) is then a
divide-by-zero and panics the kernel.
2. The tick-to-ns conversions are done in u32:
idledly * idledly_units_ps, (maxcnt - 1) * 1000
Both overflow u32 before DIV_ROUND_CLOSEST() sees them.
3. If IDLE_WAIT_TIME reads back as 0, maxcnt evaluates to 0 and
the maxcnt - 1 clamp wraps to 0xFFFFFFFF in u32.
4. The register only stores whole ticks, so the clamped ns value has
to be converted to ticks and back. DIV_ROUND_CLOSEST() can round
that conversion up past maxcnt:
maxcnt = 640 ns, one tick = 666664 ps
clamp: maxcnt - 1 = 639 ns
ns -> ticks: 639000 / 666664 = 0.958 -> rounds to 1 tick
tick -> ns: 1 * 666664 / 1000 = 667 ns
667 ns is programmed into RING_IDLEDLY, but 667 >= maxcnt (640),
so xe_gt_WARN_ON() fires again on every subsequent init.
Return early if timestamp_base is 0 (the unknown-crystal path).
Do the conversions in u64 via the *_ULL() helpers so they cannot wrap.
Clamp with a floor (DIV_ROUND_DOWN_ULL) so the programmed delay stays
strictly below maxcnt, and guard the maxcnt == 0 case with a zero delay
while still writing RING_IDLEDLY so INHIBIT_SWITCH_UNTIL_PREEMPTED is
cleared.
v2: Drop the redundant warn on the timestamp_base == 0 path;
xe_gt_clock_init() already warns on an unrecognised crystal clock.
Keep the early return to avoid the divide-by-zero. - Vinay
v3: Field-mask the RING_IDLEDLY write with REG_FIELD_PREP(IDLE_DELAY, ...)
instead of writing the raw tick count, which could clobber
INHIBIT_SWITCH_UNTIL_PREEMPTED and reserved bits. Split the
inhibit-switch clear from the maxcnt clamp so a set inhibit bit no
longer forces a needless delay overwrite when the delay itself is
already valid. Use gt_to_xe(gt) instead of gt_to_xe(hwe->gt).
Fixes: d2de4410a88f ("drm/xe: Apply Wa_16023105232")
Cc: stable@vger.kernel.org
Assisted-by: GitHub_Copilot:claude-opus-4.8
Signed-off-by: Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
Reviewed-by: Vinay Belgaumkar <vinay.belgaumkar@intel.com>
Link: https://patch.msgid.link/20260916100545.779894-2-tilak.tirumalesh.tangudu@intel.com
Signed-off-by: Matt Roper <matthew.d.roper@intel.com>
(cherry picked from commit d864065ea25e9d12897c175de9176ce46677e176)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_hw_engine.c | 27 +++++++++++++++++++++------
1 file changed, 21 insertions(+), 6 deletions(-)
--- a/drivers/gpu/drm/xe/xe_hw_engine.c
+++ b/drivers/gpu/drm/xe/xe_hw_engine.c
@@ -584,22 +584,37 @@ static void adjust_idledly(struct xe_hw_
u32 idledly_units_ps = 8 * gt->info.timestamp_base;
u32 maxcnt_units_ns = 640;
bool inhibit_switch = 0;
+ bool wa_applied = false;
+
+ if (!IS_SRIOV_VF(gt_to_xe(gt)) && XE_GT_WA(gt, 16023105232)) {
+ /* xe_gt_clock_init() warns and zeroes timestamp_base on unknown crystal clock. */
+ if (!idledly_units_ps)
+ return;
- if (!IS_SRIOV_VF(gt_to_xe(hwe->gt)) && XE_GT_WA(gt, 16023105232)) {
idledly = xe_mmio_read32(>->mmio, RING_IDLEDLY(hwe->mmio_base));
maxcnt = xe_mmio_read32(>->mmio, RING_PWRCTX_MAXCNT(hwe->mmio_base));
inhibit_switch = idledly & INHIBIT_SWITCH_UNTIL_PREEMPTED;
idledly = REG_FIELD_GET(IDLE_DELAY, idledly);
- idledly = DIV_ROUND_CLOSEST(idledly * idledly_units_ps, 1000);
+ idledly = DIV_ROUND_CLOSEST_ULL((u64)idledly * idledly_units_ps, 1000);
maxcnt = REG_FIELD_GET(IDLE_WAIT_TIME, maxcnt);
maxcnt *= maxcnt_units_ns;
- if (xe_gt_WARN_ON(gt, idledly >= maxcnt || inhibit_switch)) {
- idledly = DIV_ROUND_CLOSEST(((maxcnt - 1) * 1000),
- idledly_units_ps);
- xe_mmio_write32(>->mmio, RING_IDLEDLY(hwe->mmio_base), idledly);
+ /* Clear the inhibit switch without disturbing a valid delay. */
+ if (inhibit_switch)
+ wa_applied = true;
+
+ if (xe_gt_WARN_ON(gt, idledly >= maxcnt)) {
+ /* Floor below maxcnt; write 0 to still clear the inhibit bit. */
+ idledly = maxcnt ?
+ DIV_ROUND_DOWN_ULL((u64)(maxcnt - 1) * 1000,
+ idledly_units_ps) : 0;
+ wa_applied = true;
}
+
+ if (wa_applied)
+ xe_mmio_write32(>->mmio, RING_IDLEDLY(hwe->mmio_base),
+ REG_FIELD_PREP(IDLE_DELAY, idledly));
}
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 304/457] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 303/457] drm/xe: harden adjust_idledly() against divide-by-zero and overflow Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 305/457] drm/xe: Keep walking on SVM eviction failure Greg Kroah-Hartman
` (163 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Marczykowski-Górecki,
Christoph Hellwig, Robert Beckett, Szymon Acedański,
Thomas Hellström, Rodrigo Vivi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Szymon Acedański <accek@invisiblethingslab.com>
commit 141008dec73521ccf64878517460cec8b3297251 upstream.
Fix display corruption on Xen PV dom0, where DMA buffers are not
guaranteed machine-contiguous, in which case bounce buffering kicks
in, breaking xe's memory coherency assumptions.
Apply the same workaround i915 carries in i915_sg_segment_size() since
commit 78a07fe777c4 ("drm/i915: stop abusing swiotlb_max_segment").
Fixes: dd08ebf6c352 ("drm/xe: Introduce a new DRM driver for Intel GPUs")
Reported-by: Marek Marczykowski-Górecki <marmarek@invisiblethingslab.com>
Closes: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8382
Link: https://lore.kernel.org/xen-devel/aYtznP_tT6xNPwf-@mail-itl/
Link: https://lore.kernel.org/all/20221020110308.1582518-1-hch@lst.de/ # i915 counterpart
Cc: Christoph Hellwig <hch@lst.de>
Cc: Robert Beckett <bob.beckett@collabora.com>
Cc: stable@vger.kernel.org # v6.8+
Signed-off-by: Szymon Acedański <accek@invisiblethingslab.com>
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Link: https://patch.msgid.link/20260916173030.3223833-1-accek@invisiblethingslab.com
(cherry picked from commit 77f704158f099b952681f207478a22d5b8218edb)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_bo.h | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
--- a/drivers/gpu/drm/xe/xe_bo.h
+++ b/drivers/gpu/drm/xe/xe_bo.h
@@ -9,6 +9,8 @@
#include <drm/drm_prime.h>
#include <drm/ttm/ttm_tt.h>
+#include <xen/xen.h>
+
#include "xe_bo_types.h"
#include "xe_ggtt.h"
#include "xe_macros.h"
@@ -574,6 +576,23 @@ static inline unsigned int xe_sg_segment
struct scatterlist __maybe_unused sg;
size_t max = BIT_ULL(sizeof(sg.length) * 8) - 1;
+ /*
+ * For Xen PV guests pages aren't contiguous in DMA (machine) address
+ * space. The DMA API takes care of that both in dma_alloc_* (by
+ * calling into the hypervisor to make the pages contiguous) and in
+ * dma_map_* (by bounce buffering). But xe (like i915, see commit
+ * 78a07fe777c4) ignores the coherency aspects of the DMA API and thus
+ * can't cope with bounce buffering actually happening, so add a hack
+ * here to force small allocations and mappings when running in PV
+ * mode on Xen.
+ *
+ * Note this will still break if bounce buffering is required for other
+ * reasons, like confidential computing hypervisors or PCIe root ports
+ * with addressing limitations.
+ */
+ if (xen_pv_domain())
+ return PAGE_SIZE;
+
max = min_t(size_t, max, dma_max_mapping_size(dev));
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 305/457] drm/xe: Keep walking on SVM eviction failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 304/457] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 306/457] drm/virtio: fix memory leak of fence event on execbuffer failure Greg Kroah-Hartman
` (162 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Brost, Himal Prasad Ghimiray,
Rodrigo Vivi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Brost <matthew.brost@intel.com>
commit be1df8badae513e01d9575398438716cfae18655 upstream.
The desired behavior for SVM eviction failures, which can occur due to
various uncontrollable races, is for TTM to continue walking the LRU
list and look for another eviction candidate. This is expressed by
returning -ENOSPC from the ->move() callback.
Adjust the SVM eviction failure path because of races in ->move() to
return -ENOSPC so that TTM continues searching for another buffer to
evict.
Fixes: 3ca608dc7561 ("drm/xe: Basic SVM BO eviction")
Cc: stable@vger.kernel.org
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
Link: https://patch.msgid.link/20260917203158.292823-1-matthew.brost@intel.com
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
(cherry picked from commit 36a86c23588b8f57c9d20feb4cf5a2ab27e3baba)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/xe/xe_bo.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/gpu/drm/xe/xe_bo.c
+++ b/drivers/gpu/drm/xe/xe_bo.c
@@ -1025,6 +1025,13 @@ static int xe_bo_move(struct ttm_buffer_
} else {
drm_dbg(&xe->drm, "Evict system allocator BO failed=%pe\n",
ERR_PTR(ret));
+ /*
+ * The semantic we want upon SVM eviction failure
+ * because of racing access is keep walking for
+ * eviction, which is -ENOSPC.
+ */
+ if (ret == -EBUSY)
+ ret = -ENOSPC;
}
goto out;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 306/457] drm/virtio: fix memory leak of fence event on execbuffer failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 305/457] drm/xe: Keep walking on SVM eviction failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 307/457] drm/virtio: fix NULL pointer dereference on fence allocation failure Greg Kroah-Hartman
` (161 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Dmitry Osipenko
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit b74aad23d99b279bb34d135795f39a6d8ecdc075 upstream.
virtio_gpu_execbuffer_ioctl() reserves a DRM event with
drm_event_reserve_init() when VIRTGPU_EXECBUF_RING_IDX selects a ring that
userspace has enabled polling for. virtio_gpu_init_submit() does this
before the BO handles, the command buffer, the syncobj arrays and the
in-fence are processed, so every later error path runs with the event
already pending, including plain argument validation failures such as an
invalid bo_handle or an in-syncobj that carries no fence.
On those paths, virtio_gpu_cleanup_submit() drops the out-fence without
cancelling the event. The fence is freed without ever having been emitted,
taking the only driver-side pointer to the event with it. Closing the DRM
file does not help. drm_events_release() unlinks pending events but
deliberately leaves the freeing to the driver's later drm_send_event(),
which never runs for an orphaned event, so the allocation is leaked
permanently.
Found when fuzzing the virtio driver with Syzkaller:
BUG: memory leak
unreferenced object 0xffff88802c176e80 (size 96):
comm "syz.1.367", pid 10561, jiffies 4294960122
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
c8 6e 17 2c 80 88 ff ff 00 00 00 00 00 00 00 00 .n.,............
backtrace (crc e1973c6b):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4597 [inline]
slab_alloc_node mm/slub.c:4917 [inline]
__kmalloc_cache_noprof+0x49d/0x6f0 mm/slub.c:5485
_kmalloc_noprof include/linux/slab.h:988 [inline]
_kzalloc_noprof include/linux/slab.h:1309 [inline]
virtio_gpu_fence_event_create drivers/gpu/drm/virtio/virtgpu_submit.c:282 [inline]
virtio_gpu_init_submit drivers/gpu/drm/virtio/virtgpu_submit.c:398 [inline]
virtio_gpu_execbuffer_ioctl+0xbbf/0x1aa0 drivers/gpu/drm/virtio/virtgpu_submit.c:505
drm_ioctl_kernel+0x1f4/0x3e0 drivers/gpu/drm/drm_ioctl.c:817
drm_ioctl+0x5f4/0xc70 drivers/gpu/drm/drm_ioctl.c:914
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fix by cancelling and freeing the DRM event on the execbuffer error path
before dropping the fence. Clear the fence's event pointer after
cancellation so it does not retain a dangling pointer.
Fixes: cd7f5ca33585 ("drm/virtio: implement context init: add virtio_gpu_fence_event")
Cc: stable@vger.kernel.org
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: Codex:gpt-5.6-luna
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/D320EAB5680C1411+20260908121323.2405044-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/virtio/virtgpu_submit.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/gpu/drm/virtio/virtgpu_submit.c
+++ b/drivers/gpu/drm/virtio/virtgpu_submit.c
@@ -538,6 +538,10 @@ int virtio_gpu_execbuffer_ioctl(struct d
virtio_gpu_process_post_deps(&submit);
virtio_gpu_complete_submit(&submit);
cleanup:
+ if (ret && submit.out_fence && submit.out_fence->e) {
+ drm_event_cancel_free(dev, &submit.out_fence->e->base);
+ submit.out_fence->e = NULL;
+ }
virtio_gpu_cleanup_submit(&submit);
return ret;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 307/457] drm/virtio: fix NULL pointer dereference on fence allocation failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 306/457] drm/virtio: fix memory leak of fence event on execbuffer failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 308/457] gpio: tps65219: Fix GPIO input value reads Greg Kroah-Hartman
` (160 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peiyang He, Dmitry Osipenko
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
commit 846b3c64fe3e77d9db20a7e3e62dbbb637c773e1 upstream.
virtio_gpu_fence_alloc() can fail due to memory pressure and return NULL,
but its caller like virtio_gpu_init_submit() never checks it. Later,
virtio_gpu_init_submit() passes the NULL fence to
virtio_gpu_fence_event_create(), which unconditionally dereferences it.
Found when fuzzing the virtio driver with Syzkaller:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000012: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000090-0x0000000000000097]
CPU: 1 UID: 0 PID: 9991 Comm: syz.0.121 Not tainted 7.2.0 #4 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014
RIP: 0010:virtio_gpu_fence_event_create drivers/gpu/drm/virtio/virtgpu_submit.c:295 [inline]
RIP: 0010:virtio_gpu_init_submit drivers/gpu/drm/virtio/virtgpu_submit.c:398 [inline]
RIP: 0010:virtio_gpu_execbuffer_ioctl+0xc78/0x1aa0 drivers/gpu/drm/virtio/virtgpu_submit.c:505
Code: 85 ed 0f 85 21 09 00 00 e8 05 5a c9 fb 48 8b 44 24 10 48 8d b8 90 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 9a 0d 00 00 48 8b 44 24 10 4c 89 b0 90 00 00 00
RSP: 0018:ffffc900039dfad0 EFLAGS: 00010216
RAX: dffffc0000000000 RBX: ffffc900039dfdd8 RCX: ffffffff85f6fd3d
RDX: 0000000000000012 RSI: ffffffff85f6fd4b RDI: 0000000000000090
RBP: 0000000000000000 R0virtio_gpu_virgl_process_cmd: ctrl 0x102, error 0x1203
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880132c4000
R13: 0000000000000000 R14: ffff888073b6c700 R15: 000000000000003b
FS: 00007fab480b96c0(0000) GS:ffff8880eb6e9000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007effbf5e55a8 CR3: 0000000048d19000 CR4: 0000000000350ef0
Call Trace:
<TASK>
drm_ioctl_kernel+0x1f4/0x3e0 drivers/gpu/drm/drm_ioctl.c:817
drm_ioctl+0x5f4/0xc70 drivers/gpu/drm/drm_ioctl.c:914
vfs_ioctl fs/ioctl.c:51 [inline]
__do_sys_ioctl fs/ioctl.c:597 [inline]
__se_sys_ioctl fs/ioctl.c:583 [inline]
__x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fab471a82bd
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fab480b9018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fab47435fa0 RCX: 00007fab471a82bd
RDX: 00002000000000c0 RSI: 00000000c0406442 RDI: 0000000000000003
RBP: 00007fab480b9080 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007fab47436038 R14: 00007fab47435fa0 R15: 00007ffe85ab0740
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:virtio_gpu_fence_event_create drivers/gpu/drm/virtio/virtgpu_submit.c:295 [inline]
RIP: 0010:virtio_gpu_init_submit drivers/gpu/drm/virtio/virtgpu_submit.c:398 [inline]
RIP: 0010:virtio_gpu_execbuffer_ioctl+0xc78/0x1aa0 drivers/gpu/drm/virtio/virtgpu_submit.c:505
Code: 85 ed 0f 85 21 09 00 00 e8 05 5a c9 fb 48 8b 44 24 10 48 8d b8 90 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 9a 0d 00 00 48 8b 44 24 10 4c 89 b0 90 00 00 00
RSP: 0018:ffffc900039dfad0 EFLAGS: 00010216
RAX: dffffc0000000000 RBX: ffffc900039dfdd8 RCX: ffffffff85f6fd3d
RDX: 0000000000000012 RSI: ffffffff85f6fd4b RDI: 0000000000000090
RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff8880132c4000
R13: 0000000000000000 R14: ffff888073b6c700 R15: 000000000000003b
FS: 00007fab480b96c0(0000) GS:ffff888098ae9000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f24c3759000 CR3: 0000000048d19000 CR4: 0000000000350ef0
----------------
Code disassembly (best guess):
0: 85 ed test %ebp,%ebp
2: 0f 85 21 09 00 00 jne 0x929
8: e8 05 5a c9 fb call 0xfbc95a12
d: 48 8b 44 24 10 mov 0x10(%rsp),%rax
12: 48 8d b8 90 00 00 00 lea 0x90(%rax),%rdi
19: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
20: fc ff df
23: 48 89 fa mov %rdi,%rdx
26: 48 c1 ea 03 shr $0x3,%rdx
* 2a: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1) <-- trapping instruction
2e: 0f 85 9a 0d 00 00 jne 0xdce
34: 48 8b 44 24 10 mov 0x10(%rsp),%rax
39: 4c 89 b0 90 00 00 00 mov %r14,0x90(%rax)
Fix by checking virtio_gpu_fence_alloc() in virtio_gpu_init_submit() and
returning -ENOMEM before any later code can dereference the NULL fence.
Fixes: 70d1ace56db6 ("drm/virtio: Conditionally allocate virtio_gpu_fence")
Cc: stable@vger.kernel.org
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Assisted-by: Codex:gpt-5.5
Signed-off-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Link: https://patch.msgid.link/00EFE4BA92889B14+20260909091114.2622550-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/virtio/virtgpu_submit.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/virtio/virtgpu_submit.c
+++ b/drivers/gpu/drm/virtio/virtgpu_submit.c
@@ -389,10 +389,13 @@ static int virtio_gpu_init_submit(struct
if ((exbuf->flags & VIRTGPU_EXECBUF_FENCE_FD_OUT) ||
exbuf->num_out_syncobjs ||
exbuf->num_bo_handles ||
- drm_fence_event)
+ drm_fence_event) {
out_fence = virtio_gpu_fence_alloc(vgdev, fence_ctx, ring_idx);
- else
+ if (!out_fence)
+ return -ENOMEM;
+ } else {
out_fence = NULL;
+ }
if (drm_fence_event) {
err = virtio_gpu_fence_event_create(dev, file, out_fence, ring_idx);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 308/457] gpio: tps65219: Fix GPIO input value reads
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 307/457] drm/virtio: fix NULL pointer dereference on fence allocation failure Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 309/457] gpio: tps65219: Use the variant-specific direction callback Greg Kroah-Hartman
` (159 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jonathan Cormier,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 4cbe530c0233c7413aaaeb029a4f32dd6aadacbb upstream.
TPS65219_MFP_GPIO_STATUS_MASK is already BIT(4). Passing it to BIT()
again tests bit 16, which cannot be set in the 8-bit MFP_CTRL register,
so GPIO0 is always reported low when configured as an input.
Test the register value with the mask directly.
Fixes: 57e30e00bd5b ("gpio: tps65219: add GPIO support for TPS65219 PMIC")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Jonathan Cormier <jcormier@criticallink.com>
Link: https://patch.msgid.link/20260919171100.90430-2-kmehltretter@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-tps65219.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpio/gpio-tps65219.c
+++ b/drivers/gpio/gpio-tps65219.c
@@ -79,7 +79,7 @@ static int tps65219_gpio_get(struct gpio
if (ret)
return ret;
- ret = !!(val & BIT(TPS65219_MFP_GPIO_STATUS_MASK));
+ ret = !!(val & TPS65219_MFP_GPIO_STATUS_MASK);
dev_warn(dev, "GPIO%d = %d, MULTI_DEVICE_ENABLE, not a standard GPIO\n", offset, ret);
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 309/457] gpio: tps65219: Use the variant-specific direction callback
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 308/457] gpio: tps65219: Fix GPIO input value reads Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 310/457] gpio: tps65219: Fix TPS65214 GPIO direction programming Greg Kroah-Hartman
` (158 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 93cf8cedeaaa05714f709b539cfb976e0b80c830 upstream.
The TPS65214 template installs its own get_direction callback because
its direction bit is in GENERAL_CONFIG. The shared get and direction
callbacks nevertheless call tps65219_gpio_get_direction() directly and
interpret the unrelated TPS65219 MFP bit.
On TPS65214 this can reject reads from an input and skip the change from
input to output. Call the callback selected by the gpio_chip template
instead.
Fixes: 1b6ab07c0c80 ("gpio: tps65219: Add support for TI TPS65214 PMIC")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260919171100.90430-3-kmehltretter@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-tps65219.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/drivers/gpio/gpio-tps65219.c
+++ b/drivers/gpio/gpio-tps65219.c
@@ -87,7 +87,7 @@ static int tps65219_gpio_get(struct gpio
* status bit.
*/
- if (tps65219_gpio_get_direction(gc, offset) == GPIO_LINE_DIRECTION_OUT)
+ if (gc->get_direction(gc, offset) == GPIO_LINE_DIRECTION_OUT)
return -ENOTSUPP;
return ret;
@@ -176,7 +176,7 @@ static int tps65219_gpio_direction_input
return -ENOTSUPP;
}
- if (tps65219_gpio_get_direction(gc, offset) == GPIO_LINE_DIRECTION_IN)
+ if (gc->get_direction(gc, offset) == GPIO_LINE_DIRECTION_IN)
return 0;
return gpio->change_dir(gc, offset, GPIO_LINE_DIRECTION_IN);
@@ -190,7 +190,7 @@ static int tps65219_gpio_direction_outpu
if (offset != TPS6521X_GPIO0_IDX)
return 0;
- if (tps65219_gpio_get_direction(gc, offset) == GPIO_LINE_DIRECTION_OUT)
+ if (gc->get_direction(gc, offset) == GPIO_LINE_DIRECTION_OUT)
return 0;
return gpio->change_dir(gc, offset, GPIO_LINE_DIRECTION_OUT);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 310/457] gpio: tps65219: Fix TPS65214 GPIO direction programming
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 309/457] gpio: tps65219: Use the variant-specific direction callback Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 311/457] mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish Greg Kroah-Hartman
` (157 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 270437f3fe62516f16482742a7762a075e7a9457 upstream.
GPIO_LINE_DIRECTION_OUT and GPIO_LINE_DIRECTION_IN have the values 0
and 1, respectively, while the TPS65214 GPIO_CONFIG field is BIT(1).
regmap_update_bits() masks the supplied value, so passing either
direction value clears the field and selects input mode.
Translate the GPIO direction to the register encoding used by
tps65214_gpio_get_direction(), setting GPIO_CONFIG for output and
clearing it for input.
Fixes: 1b6ab07c0c80 ("gpio: tps65219: Add support for TI TPS65214 PMIC")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260919171100.90430-4-kmehltretter@gmail.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpio-tps65219.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/gpio/gpio-tps65219.c
+++ b/drivers/gpio/gpio-tps65219.c
@@ -158,8 +158,10 @@ static int tps65214_gpio_change_directio
if (ret)
dev_err(dev, "GPIO%d configured as VSEL, not GPIO\n", offset);
+ val = direction == GPIO_LINE_DIRECTION_OUT ?
+ TPS65214_GPIO0_DIR_MASK : 0;
ret = regmap_update_bits(gpio->tps->regmap, TPS65219_REG_GENERAL_CONFIG,
- TPS65214_GPIO0_DIR_MASK, direction);
+ TPS65214_GPIO0_DIR_MASK, val);
if (ret)
dev_err(dev, "Fail to change direction to %u for GPIO%d.\n", direction, offset);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 311/457] mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 310/457] gpio: tps65219: Fix TPS65214 GPIO direction programming Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 312/457] mm/hugetlb: do not dissolve gigantic pages without runtime support Greg Kroah-Hartman
` (156 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jinjiang Tu, Andrew Morton,
Lance Yang, Lorenzo Stoakes (ARM), David Hildenbrand (Arm),
Vlastimil Babka (SUSE), Minchan Kim, Harry Yoo,
Hiroyouki Kamezawa, Jann Horn, Kefeng Wang, Larry Woodman,
Liam R. Howlett, Nanyong Sun, Rik van Riel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinjiang Tu <tujinjiang@huawei.com>
commit b6ac0b3f6013c168f22cad97e79967accacb08e1 upstream.
On arm64 server, we find that a task trying to grab the anon_vma lock
triggers hungtask.
INFO: task main:2354726 blocked for more than 120 seconds.
Tainted: G E 5.10.0-0021.aarch64 #1
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:main state:D stack: 0 pid:2354726 ppid:2350673 flags:0x00000a01
Call trace:
__switch_to+0x7c/0xbc
__schedule+0x3b4/0x8a0
schedule+0x50/0xe0
rwsem_down_write_slowpath+0x3cc/0x6cc
down_write+0x60/0x260
__anon_vma_prepare+0x6c/0x210
do_anonymous_page+0x258/0x660
handle_pte_fault+0x188/0x214
__handle_mm_fault+0x1b0/0x380
handle_mm_fault+0xf4/0x284
do_page_fault+0x19c/0x494
do_translation_fault+0xcc/0xf8
do_mem_abort+0x48/0xac
el0_da+0x44/0x80
el0_sync_handler+0x88/0xb4
el0_sync+0x160/0x180
After analyzing the vmcore, we found the anon_vma->root->rwsem.count is
-1. There is another anon_vma whose anon_vma->root->rwsem.count is 1, the
anon_vma->root->rwsem.owner shows the lock is held, but the stack of the
task shows the task doesn't hold the anon_vma lock.
After adding more debugging info, we found __anon_vma_prepare() reuses
anon_vma and triggers the UAF of anon_vma->root due to missing memory
barrier, leading to locking and unlocking two different anon_vma->root,
thus leading to an anon_vma will never be unlocked, and another anon_vma
couldn't be locked anymore.
This race requires two adjacent VMAs that are not merged but are
anon_vma-compatible (e.g., they differ in VMA_ACCESS_FLAGS that can be
changed by mprotect()). Two threads fault on each VMA concurrently, both
calling __anon_vma_prepare() with only mmap_lock held for reading.
THREAD A THREAD B
__anon_vma_prepare __anon_vma_prepare
find_mergeable_anon_vma() -> NULL
anon_vma = anon_vma_alloc();
anon_vma->root = anon_vma;
// the two stores may be reordered
vma->anon_vma = anon_vma;
// finds A's anon_vma
anon_vma = find_mergeable_anon_vma(vma);
anon_vma_lock_write(anon_vma);
// may still see the old root
down_write(&anon_vma->root->rwsem);
anon_vma_unlock_write(anon_vma);
// see the new root, never unlock old
up_write(&anon_vma->root->rwsem);
thread A triggers page fault and calls __anon_vma_prepare() to prepare
anon_vma for the faulting vma. __anon_vma_prepare() allocates and
initializes a new anon_vma, and then publishes it to the vma with a plain
store. anon_vma_prepare() only requires the mmap_lock to be held for
reading, so two threads can fault on adjacent VMAs at the same time.
While thread A publishes a new anon_vma, thread B could find the anon_vma
via find_mergeable_anon_vma() and then locks anon_vma->root->rwsem.
The store to anon_vma->root in anon_vma_alloc() and the store to
vma->anon_vma can be reordered. The anon_vma_lock_write() and spin_lock()
only provide acquire semantics, which do not prevent prior stores from
being reordered after them. The release semantics of the corresponding
spin_unlock() and anon_vma_unlock_write() come too late, the store to
vma->anon_vma is already published before they take effect. As a result,
thread B can observe the following order:
vma->anon_vma = anon_vma;
anon_vma->root = anon_vma;
The anon_vma slab is SLAB_TYPESAFE_BY_RCU, so a newly allocated anon_vma
may reuse memory from a previously freed one. The constructor
(anon_vma_ctor) does not reset anon_vma->root, and __put_anon_vma()
doesn't clear it either, so the old root value persists until
anon_vma_alloc() overwrites it. If that store isn't visible, thread B
reads a root that points to the old anon_vma and locks it.
As a result, thread B can call anon_vma_lock_write() with the old root,
and call anon_vma_unlock_write() with the new root, leading to an anon_vma
will never be unlocked, and another anon_vma couldn't be locked anymore
(its count is dropped from 0 to -1 due to wrong unlock).
To fix it, change the plain store `vma->anon_vma = anon_vma` to store
release, so that the fields of anon_vma are visible before anon_vma is
published to vma->anon_vma.
At read side, the load of anon_vma and anon_vma->root have address
dependency. According to Documentation/memory-barriers.txt and some
investigations, only Alpha needs address-dependency barriers and it has
been handled by READ_ONCE() in reusable_anon_vma().
We reproduced this issue in v5.10 with KSM enabled. The kernel doesn't
merge commit cf7e7a3503df ("mm: prevent KSM from breaking VMA merging for
new VMAs"), so there are many adjacent VMAs that aren't merged but are
compatible for anon_vma.
Without this fix, our production environment could reproduce this issue
about 2-5 times each month. After adding a smp_mb() before
anon_vma_lock_write(anon_vma) in __anon_vma_prepare(), which is different
to this patch, this issue hasn't been reproduced for one month.
Link: https://lore.kernel.org/20260908122924.554373-1-tujinjiang@huawei.com
Fixes: 5c341ee1dfc8 ("mm: track the root (oldest) anon_vma")
Signed-off-by: Jinjiang Tu <tujinjiang@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Cc: Minchan Kim <minchan@kernel.org>
Cc: Harry Yoo <harry@kernel.org>
Cc: Hiroyouki Kamezawa <kamezawa.hiroyu@jp.fujitsu.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jinjiang Tu <tujinjiang@huawei.com>
Cc: Kefeng Wang <wangkefeng.wang@huawei.com>
Cc: Larry Woodman <lwoodman@redhat.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Nanyong Sun <sunnanyong@huawei.com>
Cc: Rik van Riel <riel@surriel.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/rmap.c | 6 +++++-
mm/vma.c | 8 ++++++++
2 files changed, 13 insertions(+), 1 deletion(-)
--- a/mm/rmap.c
+++ b/mm/rmap.c
@@ -209,7 +209,11 @@ int __anon_vma_prepare(struct vm_area_st
/* page_table_lock to protect against threads */
spin_lock(&mm->page_table_lock);
if (likely(!vma->anon_vma)) {
- vma->anon_vma = anon_vma;
+ /*
+ * Make anon_vma fields visible before anon_vma is published.
+ * Paired with an address dependency in reusable_anon_vma().
+ */
+ smp_store_release(&vma->anon_vma, anon_vma);
anon_vma_chain_assign(vma, avc, anon_vma);
anon_vma_interval_tree_insert(avc, &anon_vma->rb_root);
anon_vma->num_active_vmas++;
--- a/mm/vma.c
+++ b/mm/vma.c
@@ -1995,6 +1995,13 @@ static int anon_vma_compatible(struct vm
* acceptable for merging, so we can do all of this optimistically. But
* we do that READ_ONCE() to make sure that we never re-load the pointer.
*
+ * The READ_ONCE() establishes an address dependency between anon_vma and
+ * any access to its fields, which pairs with the assignment to
+ * vma->anon_vma performed with release semantics in __anon_vma_prepare().
+ *
+ * This is especially important as anon_vma's are SLAB_TYPESAFE_BY_RCU so
+ * accessing an uninitialised anon_vma's fields may result in a UAF.
+ *
* IOW: that the "list_is_singular()" test on the anon_vma_chain only
* matters for the 'stable anon_vma' case (ie the thing we want to avoid
* is to return an anon_vma that is "complex" due to having gone through
@@ -2009,6 +2016,7 @@ static struct anon_vma *reusable_anon_vm
struct vm_area_struct *b)
{
if (anon_vma_compatible(a, b)) {
+ /* Paired with a memory barrier in __anon_vma_prepare(). */
struct anon_vma *anon_vma = READ_ONCE(old->anon_vma);
if (anon_vma && list_is_singular(&old->anon_vma_chain))
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 312/457] mm/hugetlb: do not dissolve gigantic pages without runtime support
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 311/457] mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 313/457] mm/hugetlb: preserve mremap address delta when skipping page tables Greg Kroah-Hartman
` (155 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Longlong Xia, Andrew Morton,
Muchun Song, David Hildenbrand, Miaohe Lin, Michal Hocko,
Oscar Salvador
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Longlong Xia <xialonglong@kylinos.cn>
commit a363c62a653cc8b3e21da9545fa4e028ef50f9c3 upstream.
dissolve_free_hugetlb_folio() doesn't check
hstate_is_gigantic_no_runtime(h) though remove_hugetlb_folio()/
update_and_free_hugetlb_folio() silently bail for such folios, so it frees
a still-listed folio and, on vmemmap restore failure, the
add_hugetlb_folio() rollback corrupts the free list.
Link: https://lore.kernel.org/20260823044118.1097121-2-xialonglong2025@163.com
Fixes: 6eb4e88a6d27 ("hugetlb: create remove_hugetlb_page() to separate functionality")
Signed-off-by: Longlong Xia <xialonglong@kylinos.cn>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Assisted-by: Codex:gpt-5.6-sol
Acked-by: Muchun Song <muchun.song@linux.dev>
Cc: David Hildenbrand <david@kernel.org>
Cc: Miaohe Lin <linmiaohe@huawei.com>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/hugetlb.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -1977,6 +1977,15 @@ retry:
struct hstate *h = folio_hstate(folio);
bool adjust_surplus = false;
+ /*
+ * remove_hugetlb_folio()/update_and_free_hugetlb_folio() bail
+ * for gigantic hstates without runtime support, so dissolving one
+ * here would leave it on the free list and, on vmemmap restore
+ * failure, the add_hugetlb_folio() rollback corrupts that list.
+ */
+ if (hstate_is_gigantic_no_runtime(h))
+ goto out;
+
if (!available_huge_pages(h))
goto out;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 313/457] mm/hugetlb: preserve mremap address delta when skipping page tables
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 312/457] mm/hugetlb: do not dissolve gigantic pages without runtime support Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 314/457] mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold() Greg Kroah-Hartman
` (154 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jaewook You, Andrew Morton,
David Hildenbrand (Arm), Johan Hovold, Muchun Song,
Oscar Salvador
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jaewook You <jaewook376@gmail.com>
commit 9bdad082d44bdcf93716973dcba6be77e8a06e7b upstream.
move_hugetlb_page_tables() optimizes mremap() by advancing to the last
entry in the page table when the source page table does not exist, either
initially or after unsharing a PMD table. The common loop increment then
steps to the first entry in the next page table.
However, the code advances both the source and destination addresses to
the last entries in their respective page tables, which is wrong. The
destination address must be advanced only by the same amount as the source
address.
If the source and destination offsets within their page tables differ, the
destination address can be advanced too far, causing follow-up issues.
Fix this by advancing the destination address by the source advance
distance.
With a reproducer, we were able to trigger a kernel panic on x86-64. With
this fix in place, we can no longer reproduce the issue.
Link: https://lore.kernel.org/20260914132352.472-1-jaewook376@gmail.com
Fixes: e95a9851787b ("hugetlb: skip to end of PT page mapping when pte not present")
Fixes: 4ddb4d91b82f ("hugetlb: do not update address in huge_pmd_unshare")
Signed-off-by: Jaewook You <jaewook376@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Cc: Johan Hovold <johan@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: <stable@vger.kernel.org>
Assisted-by: LLM
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/hugetlb.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -5143,18 +5143,21 @@ int move_hugetlb_page_tables(struct vm_a
hugetlb_vma_lock_write(vma);
i_mmap_lock_write(mapping);
for (; old_addr < old_end; old_addr += sz, new_addr += sz) {
+ const unsigned long offset_to_last_entry =
+ (old_addr | last_addr_mask) - old_addr;
+
src_pte = hugetlb_walk(vma, old_addr, sz);
if (!src_pte) {
- old_addr |= last_addr_mask;
- new_addr |= last_addr_mask;
+ old_addr += offset_to_last_entry;
+ new_addr += offset_to_last_entry;
continue;
}
if (huge_pte_none(huge_ptep_get(mm, old_addr, src_pte)))
continue;
if (huge_pmd_unshare(&tlb, vma, old_addr, src_pte)) {
- old_addr |= last_addr_mask;
- new_addr |= last_addr_mask;
+ old_addr += offset_to_last_entry;
+ new_addr += offset_to_last_entry;
continue;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 314/457] mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 313/457] mm/hugetlb: preserve mremap address delta when skipping page tables Greg Kroah-Hartman
@ 2026-09-30 15:26 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 315/457] mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold() Greg Kroah-Hartman
` (153 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:26 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton, Baolin Wang
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: SJ Park <sj@kernel.org>
commit 39c0ceedd54557bdc1542de08d22b2ed33e534e4 upstream.
damon_hugetlb_mkold() reads the page table entry into a local variable,
unsets the accessed bit in the variable, and updates the page table entry
with the updated variable value. If hardware updates the same page table
entry in parallel, the hw updates could be lost. For example,
hardware-updated dirty bits might be lost.
Avoid the parallel updates by clearing the page table entry when reading
it together, using huge_ptep_get_and_clear(). If a parallel write to the
memory is made after the clearing, the hw will see the page table entry is
cleared, trigger page fault and wait until it is handled. The page fault
handling will wait for damon_hugetlb_mkold() due to the page table lock.
Because hugetlbfs is an in-memory file system and hugetlb pages cannot be
reclaimed, no critical issue is expected to my best knowledge. But
definitely this is a nasty bug that should be fixed sooner rather than
later.
The issue was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260907170358.100168-1-sj@kernel.org
Link: https://lore.kernel.org/20260830160545.98969-1-sj@kernel.org [1]
Fixes: 49f4203aae06 ("mm/damon: add access checking for hugetlb pages")
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: <stable@vger.kernel.org> # 5.17.x
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/damon/vaddr.c | 21 ++++++++++++++-------
1 file changed, 14 insertions(+), 7 deletions(-)
--- a/mm/damon/vaddr.c
+++ b/mm/damon/vaddr.c
@@ -292,22 +292,29 @@ out:
}
#ifdef CONFIG_HUGETLB_PAGE
+static bool damon_hugetlb_ptep_mkold(pte_t *pte, struct mm_struct *mm,
+ struct vm_area_struct *vma, unsigned long addr, pte_t *entry)
+{
+ unsigned long psize = huge_page_size(hstate_vma(vma));
+
+ if (!pte_young(*entry))
+ return false;
+ *entry = huge_ptep_get_and_clear(mm, addr, pte, psize);
+ *entry = pte_mkold(*entry);
+ set_huge_pte_at(mm, addr, pte, *entry, psize);
+ return true;
+}
+
static void damon_hugetlb_mkold(pte_t *pte, struct mm_struct *mm,
struct vm_area_struct *vma, unsigned long addr)
{
bool referenced = false;
pte_t entry = huge_ptep_get(mm, addr, pte);
struct folio *folio = pfn_folio(pte_pfn(entry));
- unsigned long psize = huge_page_size(hstate_vma(vma));
folio_get(folio);
- if (pte_young(entry)) {
- referenced = true;
- entry = pte_mkold(entry);
- set_huge_pte_at(mm, addr, pte, entry, psize);
- }
-
+ referenced = damon_hugetlb_ptep_mkold(pte, mm, vma, addr, &entry);
if (mmu_notifier_clear_young(mm, addr,
addr + huge_page_size(hstate_vma(vma))))
referenced = true;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 315/457] mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-09-30 15:26 ` [PATCH 7.2 314/457] mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 316/457] mm/damon/core: fix unconditionally skip last region Greg Kroah-Hartman
` (152 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nathan Gao, SJ Park, Andrew Morton,
Baolin Wang, David Hildenbrand (Arm), Ryan Roberts
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nathan Gao <zcgao@amazon.com>
commit f166586f74dd5d9cbadaabf86ef81c8ddf6cafa7 upstream.
__damon_va_prepare_access_check() picks a random byte address within the
region and stores it in r->sampling_addr. damon_va_mkold() passes it into
a page table walk, which hands it to damon_ptep_mkold() as the address of
the page to sample:
damon_va_mkold(mm, r->sampling_addr)
damon_va_walk_page_range(mm, addr, addr + 1)
damon_mkold_pmd_entry()
damon_ptep_mkold(pte, vma, addr)
ptep_test_and_clear_young(vma, addr, pte)
mmu_notifier_clear_young(mm, addr, addr + PAGE_SIZE)
For arm64, before commit 6f0e1142173a ("arm64: mm: support batch clearing
of the young flag for large folios"), the contpte helper walked exactly
CONT_PTES entries from the aligned-down page table pointer and used @addr
only to pass down to each entry, so an unaligned value was harmless:
ptep = contpte_align_down(ptep);
addr = ALIGN_DOWN(addr, CONT_PTE_SIZE);
for (i = 0; i < CONT_PTES; i++, ptep++, addr += PAGE_SIZE)
Now the range to walk is derived from @addr instead: end = addr + nr *
PAGE_SIZE, rounded up to CONT_PTE_SIZE. For a sample in the last page of
a contpte block, the sub-page offset puts end just past the block
boundary, so the round-up lands a whole block further and the walk clears
PTE_AF in CONT_PTES entries beyond the sampled block. For the last block
in a page table page, those entries are past the end of that page, so the
walk writes into the page that follows.
Triggered by the full 7.1/7.2 kernel selftest suite on arm64 (EC2
c/m6g.4xlarge). The kernel sometimes crashes at or shortly after the
DAMON test.
What the overrun does depends on the page that happens to follow the page
table, so there is no single signature. If that page is read-only, the
write faults in the sampling path itself:
Unable to handle kernel write to read-only memory at virtual address ffff0003c5d2d000
FSC = 0x0f: level 3 permission fault
CM = 0, WnR = 1, TnD = 0, TagAccess = 0
CPU: 10 UID: 0 PID: 3487 Comm: kdamond.2
pc : contpte_test_and_clear_young_ptes+0x70/0xc0
lr : damon_ptep_mkold+0x1e8/0x1f8
Call trace:
contpte_test_and_clear_young_ptes+0x70/0xc0 (P)
damon_mkold_pmd_entry+0x150/0x170
walk_pmd_range+0x110/0x2b0
walk_pud_range+0x10c/0x208
walk_pgd_range+0x134/0x258
__walk_page_range+0x98/0x1b0
walk_page_range_vma_unsafe+0x90/0x148
walk_page_range_vma+0x28/0x40
damon_va_walk_page_range+0x114/0x2b8
damon_va_prepare_access_checks+0xec/0x1a8
kdamond_fn+0x534/0x770
kthread+0x128/0x138
ret_from_fork+0x10/0x20
Otherwise the page is writable, the PTE_AF clearing succeeds silently and
the damage only surfaces later, in whatever happened to own the page, so
the backtrace is unrelated to DAMON and differs between runs.
Pass a page-aligned address to the ptep_test_and_clear_young() call in
damon_ptep_mkold(), which is the only place DAMON can reach
contpte_test_and_clear_young_ptes() from. Nothing else sees the aligned
address, and r->sampling_addr itself is left as is, so the sampling and
region bookkeeping semantics are unchanged.
Link: https://lore.kernel.org/20260904002829.116381-1-sj@kernel.org
Fixes: 6f0e1142173a ("arm64: mm: support batch clearing of the young flag for large folios")
Signed-off-by: Nathan Gao <zcgao@amazon.com>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: SJ Park <sj@kernel.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: David Hildenbrand (Arm) <david@kernel.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/damon/ops-common.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/mm/damon/ops-common.c b/mm/damon/ops-common.c
index fbda70d8ea4d..8fc61d06d358 100644
--- a/mm/damon/ops-common.c
+++ b/mm/damon/ops-common.c
@@ -61,7 +61,12 @@ void damon_ptep_mkold(pte_t *pte, struct vm_area_struct *vma, unsigned long addr
* device aspects.
*/
if (likely(pte_present(pteval)))
- young |= ptep_test_and_clear_young(vma, addr, pte);
+ /*
+ * Arch implementation of ptep_test_and_clear_young() may
+ * require aligned @addr
+ */
+ young |= ptep_test_and_clear_young(vma, PAGE_ALIGN_DOWN(addr),
+ pte);
young |= mmu_notifier_clear_young(vma->vm_mm, addr, addr + PAGE_SIZE);
if (young)
folio_set_young(folio);
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 316/457] mm/damon/core: fix unconditionally skip last region
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 315/457] mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 317/457] mm/damon/core: allow esz to be set to zero Greg Kroah-Hartman
` (151 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Liew Rui Yan, SJ Park, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liew Rui Yan <aethernet65535@gmail.com>
commit b3723b596b548c837a766aae3553c14a7b15af2b upstream.
Once quota set, the charge_{target,addr}_from unconditionally skips and
resets at the last region of the tracked target, so the last region can be
skipped even when it has not been processed.
Example:
1. Target has 2 regions: R1 (0-100 bytes) and R2 (100-200 bytes).
2. Quota is configured to process only 100 bytes per window.
3. Window 1: Processes R1 (0-100). Quota is full. charge_{target,
addr}_from is saved at (Target, 100).
4. Window 2: The loop reaches R2. Because R2 is
damon_last_region(t), the old code unconditionally returns true,
skipping R2 entirely and resetting the charge_{target,addr}_from.
Result: R2 is permanently skipped even though it has never been
processed.
However, it is important to note that this is a very minor issue. This is
because it is triggered only when the previous window saved/kept
charge_{target,addr}_from, and in the next window, all regions except the
last region were skipped by damos_skip_charged_region().
Fix this by only resetting the charge_{target,addr}_from when last region
is reached, only skipping when it is applied or cannot split.
Link: https://lore.kernel.org/20260908134739.96919-1-sj@kernel.org
Fixes: 50585192bc2e ("mm/damon/schemes: skip already charged targets and regions")
Signed-off-by: Liew Rui Yan <aethernet65535@gmail.com>
Reviewed-by: SJ Park <sj@kernel.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: <stable@vger.kernel.org> # v5.16.x
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/damon/core.c | 25 ++++++++++++++-----------
1 file changed, 14 insertions(+), 11 deletions(-)
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -2145,36 +2145,39 @@ static bool damos_skip_charged_region(st
{
struct damos_quota *quota = &s->quota;
unsigned long sz_to_skip;
+ bool skip = false;
/* Skip previously charged regions */
if (quota->charge_target_from) {
if (t != quota->charge_target_from)
return true;
- if (r == damon_last_region(t)) {
- quota->charge_target_from = NULL;
- quota->charge_addr_from = 0;
- return true;
- }
if (quota->charge_addr_from &&
- r->ar.end <= quota->charge_addr_from)
- return true;
+ r->ar.end <= quota->charge_addr_from) {
+ skip = true;
+ goto out;
+ }
if (quota->charge_addr_from && r->ar.start <
quota->charge_addr_from) {
sz_to_skip = ALIGN_DOWN(quota->charge_addr_from -
r->ar.start, min_region_sz);
if (!sz_to_skip) {
- if (damon_sz_region(r) <= min_region_sz)
- return true;
+ if (damon_sz_region(r) <= min_region_sz) {
+ skip = true;
+ goto out;
+ }
sz_to_skip = min_region_sz;
}
damon_split_region_at(t, r, sz_to_skip);
- return true;
+ skip = true;
}
+ }
+out:
+ if (r == damon_last_region(t)) {
quota->charge_target_from = NULL;
quota->charge_addr_from = 0;
}
- return false;
+ return skip;
}
static void damos_update_stat(struct damos *s,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 317/457] mm/damon/core: allow esz to be set to zero
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 316/457] mm/damon/core: fix unconditionally skip last region Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 318/457] mm/damon/core: reset invalid quota->charge_target_from Greg Kroah-Hartman
` (150 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Liew Rui Yan, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liew Rui Yan <aethernet65535@gmail.com>
commit 90179da203ba8b708c84a12a07cd44be0f346334 upstream.
When the temporal quota goal tuner determines that the goal has been
achieved (score >= 10000), it sets esz_bp to zero so that the esz becomes
zero. However, damos_set_effective_quota() clamps the esz to
min_region_sz when quota->ms is set.
This is a minor issue, the main problem is that it doesn't match the
description in the documentation, which state that if the goal has already
been [over-]achieved, the quota will be set to zero.
Fix this by set quota (esz) as minimum as possible.
Link: https://lore.kernel.org/20260908135413.97570-1-sj@kernel.org
Fixes: 8bbde987c2b8 ("mm/damon/core: disallow time-quota setting zero esz")
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Liew Rui Yan <aethernet65535@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # v7.1.x
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/damon/core.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -2896,6 +2896,7 @@ static void damos_set_effective_quota(st
struct damos_quota *quota = &s->quota;
unsigned long throughput;
unsigned long esz = ULONG_MAX;
+ unsigned long esz_time;
if (!quota->ms && list_empty("a->goals)) {
quota->esz = quota->sz;
@@ -2916,8 +2917,8 @@ static void damos_set_effective_quota(st
1000000, quota->total_charged_ns);
else
throughput = PAGE_SIZE * 1024;
- esz = min(throughput * quota->ms, esz);
- esz = max(ctx->min_region_sz, esz);
+ esz_time = max(throughput * quota->ms, ctx->min_region_sz);
+ esz = min(esz_time, esz);
}
if (quota->sz && quota->sz < esz)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 318/457] mm/damon/core: reset invalid quota->charge_target_from
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 317/457] mm/damon/core: allow esz to be set to zero Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 319/457] PCI: Fix BAR resize for devices on a root bus Greg Kroah-Hartman
` (149 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton, Enze Li
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: SJ Park <sj@kernel.org>
commit eb64948249781bda35de04feab5a0acc36aa9051 upstream.
DAMOS can suddenly stop working if a target process that the quota is just
fully charged on is terminated. Fix by catching and processing the corner
case.
When DAMOS quota is fully charged, the target and the region to continue
applying the action in the next round is saved in
damos_quota->charge_{target,addr}_from. In the next round, DAMOS iterates
targets and regions from the beginning. It skips applying the action to
the regions until it visits and skips the saved target/region.
Virtual address space targets become invalid if the process is terminated.
Trying to apply the scheme to invalid target is just a waste of time.
Hence commit 6e4930e33329 ("mm/damon/core: fix wasteful CPU calls by
skipping non-existent targets") made the logic to skip invalid targets.
However, it does skip before the charged target/region skipping/updating.
Let's suppose the user runs DAMOS for multiple virtual address spaces with
a quota. The quota exceeded in the middle of a virtual address space.
And the process of the address space is terminated. Then the
charge_target_from points to the invalid target. The pointer update logic
is skipped for the invalid target, so the charge_target_from is never
updated. DAMOS action to every target/region is skipped. From the user's
perspective, it would look like suddenly DAMOS has stopped working.
No critical leak or crash can happen. The user could reinstall the
scheme. But this makes use of DAMOS under certain setups quite
unreliable.
When the invalid target is found, further check the corner case and reset
the pointer.
This issue was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260910142846.172957-1-sj@kernel.org
Link: https://lore.kernel.org/20260830064708.40CA61F000E9@smtp.kernel.org [1]
Fixes: 6e4930e33329 ("mm/damon/core: fix wasteful CPU calls by skipping non-existent targets")
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Enze Li <lienze@kylinos.cn>
Cc: <stable@vger.kernel.org> # 7.0.x
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/damon/core.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -3047,8 +3047,15 @@ static void kdamond_apply_schemes(struct
max_region_sz = damon_region_sz_limit(c);
mutex_lock(&c->walk_control_lock);
damon_for_each_target(t, c) {
- if (c->ops.target_valid && c->ops.target_valid(t) == false)
+ if (c->ops.target_valid && c->ops.target_valid(t) == false) {
+ damon_for_each_scheme(s, c) {
+ if (s->quota.charge_target_from != t)
+ continue;
+ s->quota.charge_target_from = NULL;
+ s->quota.charge_addr_from = 0;
+ }
continue;
+ }
damos_apply_target(c, t, max_region_sz);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 319/457] PCI: Fix BAR resize for devices on a root bus
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 318/457] mm/damon/core: reset invalid quota->charge_target_from Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 320/457] PCI: of_property: Omit bus properties without a subordinate bus Greg Kroah-Hartman
` (148 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilpo Järvinen, Liz Fong-Jones,
Bjorn Helgaas
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liz Fong-Jones <lizf@honeycomb.io>
commit d58384c22739848efe14b34e9586e4f1242f33c0 upstream.
pci_do_resource_release_and_resize() releases device BARs that share a
bridge window with the BAR being resized, but when the device sits directly
on a root bus (pdev->bus->self == NULL) it then skips resource assignment
entirely and returns success, leaving the BARs it just released unassigned
(IORESOURCE_UNSET).
Skipping pbus_reassign_bridge_resources() is correct in that case -- there
is no bridge window to adjust -- but the device BARs still have to be
reassigned. Before the BAR release was consolidated into the PCI core, this
case worked for amdgpu because the driver released the BARs itself and then
called pci_assign_unassigned_bus_resources() unconditionally after the
resize, which assigns unassigned device BARs also on a root bus. Commit
db92e3fef53e ("drm/amdgpu: Remove driver side BAR release before resize")
removed that call, so nothing assigns the released BARs anymore.
This breaks amdgpu completely on the SolidRun HoneyComb LX2K (NXP LX2160A,
arm64, ACPI), where ACPI doesn't expose the Root Port so the GPU endpoint
appears directly on a "root bus" of its segment:
amdgpu 0004:01:00.0: BAR 0 [mem 0xa400000000-0xa40fffffff 64bit pref]: releasing
amdgpu 0004:01:00.0: BAR 2 [mem 0xa410000000-0xa4101fffff 64bit pref]: releasing
amdgpu 0004:01:00.0: sw_init of IP block <gmc_v8_0> failed -19
amdgpu 0004:01:00.0: amdgpu_device_ip_init failed
amdgpu 0004:01:00.0: Fatal error during GPU init
No error is logged because the resize path reports success; amdgpu then
finds BAR 0 IORESOURCE_UNSET and bails out with -ENODEV.
When there is no upstream bridge, call pci_bus_assign_resources() on the
root bus to place the BARs released above, using the same alignment-sorted
algorithm as normal enumeration instead of a manual per-BAR loop. This also
walks the rest of the hierarchy under the root bus, as
pci_assign_unassigned_bus_resources() used to for amdgpu before commit
db92e3fef53e ("drm/amdgpu: Remove driver side BAR release before resize")
removed that call -- the core-side fix that commit asked for ("such a
problem should be fixed inside pci_resize_resource() instead").
pci_bus_assign_resources() returns void, so failure is detected by checking
whether the released BARs are still assigned afterward; if not, roll back
as in the bridged case. This is stricter than the bridged path -- it fails
on any unplaced resource, not just required ones -- since a root bus
typically has one shared window, and failing loudly seemed better than
leaving something silently unassigned.
The root bus path also had a locking bug that any fix here necessarily
touches: the old "goto out" jumped to up_read(&pci_bus_sem) without a
matching down_read() (as does the "goto restore" taken when
pci_dev_res_add_to_list() fails in the release loop). Take pci_bus_sem
before the BAR release loop so every path through the function holds it
exactly once.
Fixes: 337b1b566db0 ("PCI: Fix restoring BARs on BAR resize rollback path")
Link: https://bugs.launchpad.net/ubuntu/+source/linux-hwe-7.0/+bug/2159596
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Assisted-by: Claude:claude-fable-5 checkpatch
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Liz Fong-Jones <lizf@honeycomb.io>
[bhelgaas: commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260918035633.566823-1-lizf@honeycomb.io
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/setup-bus.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
--- a/drivers/pci/setup-bus.c
+++ b/drivers/pci/setup-bus.c
@@ -2380,6 +2380,7 @@ int pci_do_resource_release_and_resize(s
struct resource *res = pci_resource_n(pdev, resno);
struct pci_dev_resource *dev_res;
struct pci_bus *bus = pdev->bus;
+ struct pci_dev *bridge = pci_upstream_bridge(pdev);
struct resource *b_win, *r;
LIST_HEAD(saved);
unsigned int i;
@@ -2397,6 +2398,8 @@ int pci_do_resource_release_and_resize(s
if (ret)
return ret;
+ down_read(&pci_bus_sem);
+
pci_dev_for_each_resource(pdev, r, i) {
if (i >= PCI_BRIDGE_RESOURCES)
break;
@@ -2415,13 +2418,21 @@ int pci_do_resource_release_and_resize(s
pci_resize_resource_set_size(pdev, resno, size);
- if (!bus->self)
- goto out;
-
- down_read(&pci_bus_sem);
- ret = pbus_reassign_bridge_resources(bus, res, &saved);
- if (ret)
- goto restore;
+ if (bridge) {
+ ret = pbus_reassign_bridge_resources(bus, res, &saved);
+ if (ret)
+ goto restore;
+ } else {
+ /* No bridge window to adjust; let the core reassign the bus. */
+ pci_bus_assign_resources(bus);
+
+ list_for_each_entry(dev_res, &saved, list) {
+ if (!resource_assigned(dev_res->res)) {
+ ret = -ENOSPC;
+ goto restore;
+ }
+ }
+ }
out:
up_read(&pci_bus_sem);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 320/457] PCI: of_property: Omit bus properties without a subordinate bus
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 319/457] PCI: Fix BAR resize for devices on a root bus Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 321/457] packet: use ubuf_info completion for TX_RING packets Greg Kroah-Hartman
` (147 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Angel J, Bjorn Helgaas
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Angel J <iamanaws@httpd.dev>
commit 8805840aad73df7146778be243a196d48b4f6430 upstream.
A bridge (a device with a Type 1 header) may not have a secondary bus
allocated (pdev->subordinate), e.g., if there are no available bus numbers
or the bridge secondary/subordinate bus numbers are not writable.
The dynamic OF helpers of_pci_prop_bus_range() and of_pci_prop_intr_map()
dereference pdev->subordinate without checking it. When
CONFIG_PCI_DYNAMIC_OF_NODES is enabled, this can cause a NULL pointer
dereference and early boot hang.
Generate 'bus-range' and 'interrupt-map' properties only when a subordinate
bus exists. Keep the node and its remaining properties for bridges without
one.
The problem was latent since 407d1a51921e ("PCI: Create device tree node
for bridge"), but wasn't reachable until 1f340724419e ("PCI: of: Create
device tree PCI host bridge node"), which appeared in v6.15. Before
1f340724419e, of_pci_make_dev_node() returned early because the parent OF
node was missing.
Fixes: 407d1a51921e ("PCI: Create device tree node for bridge")
Signed-off-by: Angel J <iamanaws@httpd.dev>
[bhelgaas: move pdev->subordinate test to callees, commit log]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org # v6.6+
Link: https://patch.msgid.link/20260918195540.GA1187209@bhelgaas
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/of_property.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
--- a/drivers/pci/of_property.c
+++ b/drivers/pci/of_property.c
@@ -95,9 +95,13 @@ static int of_pci_prop_bus_range(struct
struct of_changeset *ocs,
struct device_node *np)
{
- u32 bus_range[] = { pdev->subordinate->busn_res.start,
- pdev->subordinate->busn_res.end };
+ u32 bus_range[2];
+ if (!pdev->subordinate)
+ return 0;
+
+ bus_range[0] = pdev->subordinate->busn_res.start;
+ bus_range[1] = pdev->subordinate->busn_res.end;
return of_changeset_add_prop_u32_array(ocs, np, "bus-range", bus_range,
ARRAY_SIZE(bus_range));
}
@@ -220,6 +224,9 @@ static int of_pci_prop_intr_map(struct p
int ret;
u8 pin;
+ if (!pdev->subordinate)
+ return 0;
+
pnode = pci_device_to_OF_node(pdev->bus->self);
if (!pnode)
pnode = pci_bus_to_OF_node(pdev->bus);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 321/457] packet: use ubuf_info completion for TX_RING packets
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 320/457] PCI: of_property: Omit bus properties without a subordinate bus Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 322/457] HID: alps: unregister DualPoint Stick input device on remove Greg Kroah-Hartman
` (146 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Katherine Leaver, Bjoern Doebel,
Willem de Bruijn, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Willem de Bruijn <willemb@google.com>
commit 9518405613863d0bf0700927a21367f5942cf058 upstream.
tpacket_snd sends skbs with frags pointing into its ring slots. Slots
are released when skb->destructor is called.
A call to skb_orphan calls skb->destructor before the skb is freed.
This can cause the slot to be reused while still linked into the skb.
Switch to standard zerocopy completion (ubuf_info) so the slot is only
released once all references to the payload are freed or copied.
Restore skb->destructor to standard sock_wfree.
The ubuf_info completion callback can be called with a NULL skb, but
only from net_zcopy_put and related API, used by zerocopy implementations
that hold their own reference on the uarg, such as MSG_ZEROCOPY. This
uarg is only ever completed from skb_zcopy_clear, so skb is always set.
To prevent userspace from aliasing in-flight state on shared ring
slots, allocate tpacket_uarg per packet, rather than per slot. This
adds a small allocation to the transmit path. Use standard kmalloc to
allow backporting to stable kernels.
The uarg holds an sk_wmem_alloc reference, rather than an sk_refcnt
reference. packet_free_tx_ring waits on sk_wmem_alloc before freeing
the ring pages. Always allocate vec->deferred for tx_ring so page-backed
rings also wait on sk_wmem_alloc when skb_copy_ubufs drops page refs
before calling tpacket_ubuf_complete.
Drop the tx_ring.pg_vec test that tpacket_destruct_skb performed before
accessing the slot. The sk_wmem_alloc reference now guarantees that the
slot is valid. The test is also not sufficient by itself, as it reads
pg_vec without pg_vec_lock, so it can race with packet_set_ring.
As a result a slot is released when its payload is copied, which can
be before transmission (e.g., in skb_orphan_frags_rx). If copied
before skb_tx_timestamp() is called, no slot timestamp is recorded,
similar to when skb_orphan() was called early in the datapath before
this patch.
Revert the now unused previous skb_zcopy_.._nouarg infra.
Depends on commit 992cc9f94ca9 ("net/packet: defer vmalloc TX_RING
free until skbs finish").
Reported-by: Katherine Leaver <kleaver@janestreet.com>
Reported-by: Bjoern Doebel <doebel@amazon.de>
Closes: https://lore.kernel.org/netdev/20260909085542.3370986-1-doebel@amazon.de/
Fixes: 5cd8d46ea156 ("packet: copy user buffers before orphan or clone")
Cc: stable@vger.kernel.org
Signed-off-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260919004748.1463985-3-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/skbuff.h | 19 ---------
net/packet/af_packet.c | 102 ++++++++++++++++++++++++++++++-------------------
2 files changed, 65 insertions(+), 56 deletions(-)
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -1834,22 +1834,6 @@ static inline void skb_zcopy_set(struct
}
}
-static inline void skb_zcopy_set_nouarg(struct sk_buff *skb, void *val)
-{
- skb_shinfo(skb)->destructor_arg = (void *)((uintptr_t) val | 0x1UL);
- skb_shinfo(skb)->flags |= SKBFL_ZEROCOPY_FRAG;
-}
-
-static inline bool skb_zcopy_is_nouarg(struct sk_buff *skb)
-{
- return (uintptr_t) skb_shinfo(skb)->destructor_arg & 0x1UL;
-}
-
-static inline void *skb_zcopy_get_nouarg(struct sk_buff *skb)
-{
- return (void *)((uintptr_t) skb_shinfo(skb)->destructor_arg & ~0x1UL);
-}
-
static inline void net_zcopy_put(struct ubuf_info *uarg)
{
if (uarg)
@@ -1872,8 +1856,7 @@ static inline void skb_zcopy_clear(struc
struct ubuf_info *uarg = skb_zcopy(skb);
if (uarg) {
- if (!skb_zcopy_is_nouarg(skb))
- uarg->ops->complete(skb, uarg, zerocopy_success);
+ uarg->ops->complete(skb, uarg, zerocopy_success);
skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY;
}
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2530,26 +2530,6 @@ drop_n_account:
goto drop_n_restore;
}
-static void tpacket_destruct_skb(struct sk_buff *skb)
-{
- struct packet_sock *po = pkt_sk(skb->sk);
-
- if (likely(po->tx_ring.pg_vec)) {
- void *ph;
- __u32 ts;
-
- ph = skb_zcopy_get_nouarg(skb);
-
- ts = __packet_set_timestamp(po, ph, skb);
- __packet_set_status(po, ph, TP_STATUS_AVAILABLE | ts);
-
- packet_dec_pending(&po->tx_ring);
- complete(&po->skb_completion);
- }
-
- sock_wfree(skb);
-}
-
static int __packet_snd_vnet_parse(struct virtio_net_hdr *vnet_hdr, size_t len)
{
if ((vnet_hdr->flags & VIRTIO_NET_HDR_F_NEEDS_CSUM) &&
@@ -2589,27 +2569,56 @@ static int packet_snd_vnet_parse(struct
return 0;
}
+struct tpacket_uarg {
+ struct ubuf_info ubuf;
+ struct packet_sock *po;
+ void *ph;
+};
+
+static void tpacket_ubuf_complete(struct sk_buff *skb, struct ubuf_info *uarg,
+ bool success)
+{
+ struct tpacket_uarg *tu = container_of(uarg, struct tpacket_uarg, ubuf);
+ struct packet_sock *po = tu->po;
+ void *ph = tu->ph;
+ __u32 ts;
+
+ DEBUG_NET_WARN_ON_ONCE(!skb);
+
+ if (!refcount_dec_and_test(&uarg->refcnt))
+ return;
+
+ ts = __packet_set_timestamp(po, ph, skb);
+ __packet_set_status(po, ph, TP_STATUS_AVAILABLE | ts);
+
+ packet_dec_pending(&po->tx_ring);
+ complete(&po->skb_completion);
+
+ kfree(tu);
+ sk_free(&po->sk);
+}
+
+static const struct ubuf_info_ops tpacket_ubuf_ops = {
+ .complete = tpacket_ubuf_complete,
+};
+
static int tpacket_fill_skb(struct packet_sock *po, struct sk_buff *skb,
- void *frame, struct net_device *dev, void *data, int tp_len,
+ struct net_device *dev, void *data, int tp_len,
__be16 proto, unsigned char *addr, int hlen, int copylen,
int hard_header_len,
const struct sockcm_cookie *sockc)
{
- union tpacket_uhdr ph;
int to_write, offset, len, nr_frags, len_max;
struct socket *sock = po->sk.sk_socket;
struct page *page;
int err;
- ph.raw = frame;
-
skb->protocol = proto;
skb->dev = dev;
skb->priority = sockc->priority;
skb->mark = sockc->mark;
skb_set_delivery_type_by_clockid(skb, sockc->transmit_time, po->sk.sk_clockid);
skb_setup_tx_timestamp(skb, sockc);
- skb_zcopy_set_nouarg(skb, ph.raw);
skb_reserve(skb, hlen);
skb_reset_network_header(skb);
@@ -2749,6 +2758,7 @@ static int tpacket_snd(struct packet_soc
struct virtio_net_hdr vnet_hdr;
bool has_vnet_hdr = false;
struct sockcm_cookie sockc;
+ struct tpacket_uarg *uarg;
__be16 proto;
int err, reserve = 0;
void *ph;
@@ -2876,7 +2886,7 @@ static int tpacket_snd(struct packet_soc
err = len_sum;
goto out_status;
}
- tp_len = tpacket_fill_skb(po, skb, ph, dev, data, tp_len, proto,
+ tp_len = tpacket_fill_skb(po, skb, dev, data, tp_len, proto,
addr, hlen, copylen, hard_header_len,
&sockc);
if (likely(tp_len >= 0) &&
@@ -2908,7 +2918,24 @@ tpacket_error:
virtio_net_hdr_set_proto(skb, &vnet_hdr);
}
- skb->destructor = tpacket_destruct_skb;
+ uarg = kmalloc(sizeof(*uarg), GFP_KERNEL);
+ if (unlikely(!uarg)) {
+ if (likely(len_sum > 0))
+ err = len_sum;
+ else
+ err = -ENOMEM;
+ goto out_status;
+ }
+ uarg->po = po;
+ uarg->ph = ph;
+ uarg->ubuf.ops = &tpacket_ubuf_ops;
+ uarg->ubuf.flags = SKBFL_ZEROCOPY_FRAG;
+ refcount_set(&uarg->ubuf.refcnt, 1);
+
+ /* Hold a sk_wmem_alloc reference until completion */
+ refcount_inc(&po->sk.sk_wmem_alloc);
+ skb_zcopy_init(skb, &uarg->ubuf);
+
__packet_set_status(po, ph, TP_STATUS_SENDING);
packet_inc_pending(&po->tx_ring);
@@ -4486,21 +4513,20 @@ static struct pgv *alloc_pg_vec(struct t
vec->len = block_nr;
pg_vec = vec->pg_vec;
+ if (tx_ring) {
+ vec->deferred = kzalloc_obj(*vec->deferred,
+ GFP_KERNEL | __GFP_NOWARN);
+ if (!vec->deferred)
+ goto out_free_pgvec;
+ vec->deferred->vec = vec;
+ INIT_DELAYED_WORK(&vec->deferred->work,
+ packet_free_pg_vec_work);
+ }
+
for (i = 0; i < block_nr; i++) {
pg_vec[i].buffer = alloc_one_pg_vec_page(order);
if (unlikely(!pg_vec[i].buffer))
goto out_free_pgvec;
-
- if (tx_ring && !vec->deferred &&
- is_vmalloc_addr(pg_vec[i].buffer)) {
- vec->deferred = kzalloc_obj(*vec->deferred,
- GFP_KERNEL | __GFP_NOWARN);
- if (!vec->deferred)
- goto out_free_pgvec;
- vec->deferred->vec = vec;
- INIT_DELAYED_WORK(&vec->deferred->work,
- packet_free_pg_vec_work);
- }
}
out:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 322/457] HID: alps: unregister DualPoint Stick input device on remove
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 321/457] packet: use ubuf_info completion for TX_RING packets Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 323/457] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
` (145 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Changcheng, Jiri Kosina
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Changcheng <chenchangcheng@kylinos.cn>
commit aa9dde93e05a837645fdfd577eea71f0733f0694 upstream.
alps_input_configured() allocates a second input device ("DualPoint
Stick") with input_allocate_device() and registers it, but the
alps_driver struct has no .remove handler and input2 is not tracked in
hdev->inputs. The default remove path (hid_hw_stop -> hidinput_disconnect)
only iterates hdev->inputs, so input2 is never unregistered and leaks
on every device removal.
Add a .remove handler that stops the device first (preventing URB
callbacks from touching input2 during teardown) and then unregisters
input2.
Fixes: 2562756dde55 ("HID: add Alps I2C HID Touchpad-Stick support")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-alps.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
--- a/drivers/hid/hid-alps.c
+++ b/drivers/hid/hid-alps.c
@@ -823,6 +823,24 @@ static int alps_probe(struct hid_device
return 0;
}
+static void alps_remove(struct hid_device *hdev)
+{
+ struct alps_dev *data = hid_get_drvdata(hdev);
+
+ /*
+ * input2 ("DualPoint Stick") is allocated separately and is not
+ * tracked in hdev->inputs, so the default remove path
+ * (hid_hw_stop -> hidinput_disconnect) does not unregister it.
+ *
+ * Stop the device first so that no URB callback can touch input2
+ * while it is being unregistered, then drop it explicitly.
+ */
+ hid_hw_stop(hdev);
+
+ if (data->input2)
+ input_unregister_device(data->input2);
+}
+
static const struct hid_device_id alps_id[] = {
{ HID_DEVICE(HID_BUS_ANY, HID_GROUP_ANY,
USB_VENDOR_ID_ALPS_JP, HID_DEVICE_ID_ALPS_U1_DUAL) },
@@ -845,6 +863,7 @@ static struct hid_driver alps_driver = {
.input_configured = alps_input_configured,
.resume = pm_ptr(alps_post_resume),
.reset_resume = pm_ptr(alps_post_reset),
+ .remove = alps_remove,
};
module_hid_driver(alps_driver);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 323/457] HID: alps: fix use-after-free on input2 registration failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 322/457] HID: alps: unregister DualPoint Stick input device on remove Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 324/457] HID: hid-oxp: use cancel_delayed_work_sync() in remove Greg Kroah-Hartman
` (144 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Changcheng, Jiri Kosina
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Changcheng <chenchangcheng@kylinos.cn>
commit d3aba3442798ce4a4c8ce3104d7b286d61e605f9 upstream.
alps_input_configured() stores data->input2 before calling
input_register_device(). If registration fails, input_free_device()
frees the input device but data->input2 still points to the freed memory.
alps_input_configured() calls hid_hw_open() before allocating input2, so
URBs are already active and raw_event can fire during the failure window.
A U1_SP_ABSOLUTE_REPORT_ID report arriving then causes u1_raw_event()
to dereference the freed data->input2 -> use-after-free.
Fix by only storing input2 into drvdata after successful registration
and adding a NULL guard in the raw_event path.
Fixes: 2562756dde55 ("HID: add Alps I2C HID Touchpad-Stick support")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-alps.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/hid/hid-alps.c
+++ b/drivers/hid/hid-alps.c
@@ -407,6 +407,8 @@ static int u1_raw_event(struct alps_dev
return 1;
case U1_SP_ABSOLUTE_REPORT_ID:
+ if (!hdata->input2)
+ return 0;
sp_x = get_unaligned_le16(data+2);
sp_y = get_unaligned_le16(data+4);
@@ -738,7 +740,6 @@ static int alps_input_configured(struct
goto exit;
}
- data->input2 = input2;
input2->phys = input->phys;
input2->name = "DualPoint Stick";
input2->id.bustype = BUS_I2C;
@@ -762,11 +763,12 @@ static int alps_input_configured(struct
__set_bit(INPUT_PROP_POINTER, input2->propbit);
__set_bit(INPUT_PROP_POINTING_STICK, input2->propbit);
- if (input_register_device(data->input2)) {
+ if (input_register_device(input2)) {
input_free_device(input2);
ret = -ENOENT;
goto exit;
}
+ data->input2 = input2;
}
exit:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 324/457] HID: hid-oxp: use cancel_delayed_work_sync() in remove
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 323/457] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 325/457] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
` (143 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tristan Madani, Derek J. Clark,
Jiri Kosina
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tristan Madani <tristan@talencesecurity.com>
commit abd24922c2a9797d6184be0561dd85e7bcdfd091 upstream.
oxp_hid_remove() uses cancel_delayed_work() for all three delayed work
items. cancel_delayed_work() only dequeues a pending work item without
waiting for a currently executing callback to finish. If any of the
work callbacks (oxp_rgb_queue_fn, oxp_btn_queue_fn, oxp_mcu_init_fn) is
running at the time of removal, the callback continues executing
concurrently with hid_hw_close() and hid_hw_stop(), accessing the HID
device after it has been closed and stopped.
Use cancel_delayed_work_sync() instead to ensure that any in-progress
work callback completes before device teardown proceeds.
Fixes: 84910c459d65 ("HID: hid-oxp: Add OneXPlayer configuration driver")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Derek J. Clark <derekjohn.clark@gmail.com>
Link: https://lore.kernel.org/r/20260804-oxp-fix-v2-1-b2d56e4c8a2c@cherr.cc
Link: https://lore.kernel.org/r/20260804-oxp-fix-v1-1-51a4fe787167@cherr.cc
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-oxp.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/hid/hid-oxp.c b/drivers/hid/hid-oxp.c
index d2ded6b08ce9..1e691ebc1199 100644
--- a/drivers/hid/hid-oxp.c
+++ b/drivers/hid/hid-oxp.c
@@ -1552,9 +1552,9 @@ static int oxp_hid_probe(struct hid_device *hdev,
static void oxp_hid_remove(struct hid_device *hdev)
{
- cancel_delayed_work(&drvdata.oxp_rgb_queue);
- cancel_delayed_work(&drvdata.oxp_btn_queue);
- cancel_delayed_work(&drvdata.oxp_mcu_init);
+ cancel_delayed_work_sync(&drvdata.oxp_rgb_queue);
+ cancel_delayed_work_sync(&drvdata.oxp_btn_queue);
+ cancel_delayed_work_sync(&drvdata.oxp_mcu_init);
hid_hw_close(hdev);
hid_hw_stop(hdev);
}
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 325/457] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 324/457] HID: hid-oxp: use cancel_delayed_work_sync() in remove Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 326/457] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
` (142 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marco Carvalho, Junjie Cao,
Benjamin Tissoires
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junjie Cao <junjie.cao@intel.com>
commit cdb669a3b8f844aca71fc3224990157d61562165 upstream.
The SDINNOVATION gaming keyboard (USB ID 36ae:feab) stops reporting
input events after its RGB lighting mode is switched about twice.
Disabling USB autosuspend and unbinding the other HID interfaces make
no difference; the issue does not occur on Windows.
HID_QUIRK_ALWAYS_POLL alone resolves it, verified on 7.1.8 via
usbhid.quirks=0x36ae:0xfeab:0x400.
Reported-by: Marco Carvalho <marcocarvalho.web@gmail.com>
Link: https://bugzilla.redhat.com/show_bug.cgi?id=2514627
Cc: stable@vger.kernel.org
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-ids.h | 3 +++
drivers/hid/hid-quirks.c | 1 +
2 files changed, 4 insertions(+)
--- a/drivers/hid/hid-ids.h
+++ b/drivers/hid/hid-ids.h
@@ -1283,6 +1283,9 @@
#define USB_DEVICE_ID_SAMSUNG_WIRELESS_UNIVERSAL_KBD 0xa006
#define USB_DEVICE_ID_SAMSUNG_WIRELESS_MULTI_HOGP_KBD 0xa064
+#define USB_VENDOR_ID_SDINNOVATION 0x36ae
+#define USB_DEVICE_ID_SDINNOVATION_GAMING_KBD 0xfeab
+
#define USB_VENDOR_ID_SEMICO 0x1a2c
#define USB_DEVICE_ID_SEMICO_USB_KEYKOARD 0x0023
#define USB_DEVICE_ID_SEMICO_USB_KEYKOARD2 0x0027
--- a/drivers/hid/hid-quirks.c
+++ b/drivers/hid/hid-quirks.c
@@ -183,6 +183,7 @@ static const struct hid_device_id hid_qu
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X52_2), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X52_PRO), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
{ HID_USB_DEVICE(USB_VENDOR_ID_SAITEK, USB_DEVICE_ID_SAITEK_X65), HID_QUIRK_INCREMENT_USAGE_ON_DUPLICATE },
+ { HID_USB_DEVICE(USB_VENDOR_ID_SDINNOVATION, USB_DEVICE_ID_SDINNOVATION_GAMING_KBD), HID_QUIRK_ALWAYS_POLL },
{ HID_USB_DEVICE(USB_VENDOR_ID_SEMICO, USB_DEVICE_ID_SEMICO_USB_KEYKOARD2), HID_QUIRK_NO_INIT_REPORTS },
{ HID_USB_DEVICE(USB_VENDOR_ID_SEMICO, USB_DEVICE_ID_SEMICO_USB_KEYKOARD), HID_QUIRK_NO_INIT_REPORTS },
{ HID_USB_DEVICE(USB_VENDOR_ID_SENNHEISER, USB_DEVICE_ID_SENNHEISER_BTD500USB), HID_QUIRK_NOGET },
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 326/457] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 325/457] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 327/457] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
` (141 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Gerecke, Wei Jie Law,
Jason Gerecke, Jiri Kosina
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Jie LAW <98lawweijie@gmail.com>
commit 9aa237cf66495b2426ddde8532e9b08a0ed83aaa upstream.
The 'wacom_wac_pen_serial_enforce()' function may calculate and pass an
invalid offset to hid_field_extract(), resulting in memory reads at
incorrect addresses -- possibly beyond the end of the report. If a
field in the HID descriptor lists more usages than its Report Count
actually reserves space for, the function's inner 'j' will walk past
the end of the field:
for (i = 0; i < report->maxfield; i++) {
for (j = 0; j < report->field[i]->maxusage; j++) {
...
value = hid_field_extract(hdev, raw_data + 1,
offset + j * size, size);
A descriptor listing 12288 usages against Report Count 1 has the loop
extract the usage at index 12287 from bit offset 98296 -- about 12 KB
past a 2-byte received report. The value is stored in
wacom_wac->serial[0] and can reach userspace as an MSC_SERIAL event,
making this an information disclosure.
Clamp the loop to field->report_count, the number of value slots the
report holds. Value slots past the last declared usage are still
scanned; they reuse that usage (HID 1.11, 6.2.2.8).
Verified on v6.12.105 with a UHID reproducer: a 2-byte report from
such a descriptor trips KASAN before the patch and not after it.
Fixes: 83417206427b ("HID: wacom: Queue events with missing type/serial data for later processing")
Suggested-by: Jason Gerecke <killertofu@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Assisted-by: GLM:glm-5.3
Signed-off-by: Wei Jie Law <98lawweijie@gmail.com>
Reviewed-by: Jason Gerecke <jason.gerecke@wacom.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/wacom_sys.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/hid/wacom_sys.c
+++ b/drivers/hid/wacom_sys.c
@@ -113,8 +113,9 @@ static int wacom_wac_pen_serial_enforce(
/* Queue events which have invalid tool type or serial number */
for (i = 0; i < report->maxfield; i++) {
- for (j = 0; j < report->field[i]->maxusage; j++) {
- struct hid_field *field = report->field[i];
+ struct hid_field *field = report->field[i];
+
+ for (j = 0; j < field->report_count; j++) {
struct hid_usage *usage = &field->usage[j];
unsigned int equivalent_usage = wacom_equivalent_usage(usage->hid);
unsigned int offset;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 327/457] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 326/457] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 328/457] net/mlx5e: advertise MACsec offload only when supported Greg Kroah-Hartman
` (140 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Tariq Toukan,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 0bf6bb567f0edaa771e7dd208ef98da50e6a4485 upstream.
When the reverse entry is found but its counter is already being
released, refcount_inc_not_zero() fails and the reference taken by
mlx5_tc_ct_entry_get() is never dropped before falling through to
create_counter. Drop it so the reverse entry is not kept alive forever
by a shared counter lookup that did not use it.
Fixes: 1edae2335adf ("net/mlx5e: CT: Use the same counter for both directions")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260917113131.2149024-1-vulab@iscas.ac.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c
@@ -1082,6 +1082,9 @@ mlx5_tc_ct_shared_counter_get(struct mlx
spin_unlock_bh(&ct_priv->ht_lock);
+ if (rev_entry)
+ mlx5_tc_ct_entry_put(rev_entry);
+
create_counter:
shared_counter = mlx5_tc_ct_counter_create(ct_priv);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 328/457] net/mlx5e: advertise MACsec offload only when supported
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 327/457] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 329/457] net/mlx5e: fix swapped IPv6 IPsec policy masks Greg Kroah-Hartman
` (139 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tariq Toukan, Ralf Lici,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ralf Lici <ralf@mandelbit.com>
commit 4581c3d2adc3c73a019bc38db64ca11f28bbd7fd upstream.
Commit 339ccec8d43d ("net/mlx5: Enable MACsec offload feature for VLAN
interface") added NETIF_F_HW_MACSEC unconditionally to vlan_features so
that VLAN devices could inherit MACsec offload support.
mlx5e_build_nic_netdev subsequently copies vlan_features into
hw_features and features. As a result, all mlx5e NIC netdevices
advertise MACsec hardware offload, even when the firmware does not
support it and the driver does not install macsec_ops.
Set the MACsec feature bits in mlx5e_macsec_build_netdev, after device
capabilities have been validated. This preserves MACsec-over-VLAN
support and the ethtool feature control on capable devices, without
advertising either on unsupported hardware.
Fixes: 339ccec8d43d ("net/mlx5: Enable MACsec offload feature for VLAN interface")
Cc: stable@vger.kernel.org
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Link: https://patch.msgid.link/20260917122724.654639-1-ralf@mandelbit.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c | 2 ++
drivers/net/ethernet/mellanox/mlx5/core/en_main.c | 1 -
2 files changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c
@@ -1724,6 +1724,8 @@ void mlx5e_macsec_build_netdev(struct ml
mlx5_core_dbg(priv->mdev, "mlx5e: MACsec acceleration enabled\n");
netdev->macsec_ops = &macsec_offload_ops;
netdev->features |= NETIF_F_HW_MACSEC;
+ netdev->hw_features |= NETIF_F_HW_MACSEC;
+ netdev->vlan_features |= NETIF_F_HW_MACSEC;
netif_keep_dst(netdev);
}
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
@@ -5851,7 +5851,6 @@ static void mlx5e_build_nic_netdev(struc
netdev->vlan_features |= NETIF_F_SG;
netdev->vlan_features |= NETIF_F_HW_CSUM;
- netdev->vlan_features |= NETIF_F_HW_MACSEC;
netdev->vlan_features |= NETIF_F_GRO;
netdev->vlan_features |= NETIF_F_TSO;
netdev->vlan_features |= NETIF_F_TSO6;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 329/457] net/mlx5e: fix swapped IPv6 IPsec policy masks
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 328/457] net/mlx5e: advertise MACsec offload only when supported Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 330/457] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
` (138 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Parri, Tariq Toukan,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Parri <parri.andrea@gmail.com>
commit 10de7ed8ef4840da9ca21de4c29578657ac367db upstream.
IPv6 XFRM policies may use different source and destination prefix
lengths. mlx5e_ipsec_policy_mask() builds the corresponding masks
independently, but setup_fte_addr6() installs each mask in the opposite
address field.
When the prefix lengths differ, this makes the source match use the
destination prefix and the destination match use the source prefix. The
resulting hardware rule can both miss traffic covered by the policy and
match traffic outside it.
Install each mask in its corresponding match field.
Fixes: ca7992f52c2c ("net/mlx5e: Properly match IPsec subnet addresses")
Cc: stable@vger.kernel.org
Signed-off-by: Andrea Parri <parri.andrea@gmail.com>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260917115542.177675-1-parri.andrea@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec_fs.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec_fs.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec_fs.c
@@ -1564,14 +1564,14 @@ static void setup_fte_addr6(struct mlx5_
memcpy(MLX5_ADDR_OF(fte_match_param, spec->match_value,
outer_headers.src_ipv4_src_ipv6.ipv6_layout.ipv6), saddr, 16);
memcpy(MLX5_ADDR_OF(fte_match_param, spec->match_criteria,
- outer_headers.src_ipv4_src_ipv6.ipv6_layout.ipv6), dmask, 16);
+ outer_headers.src_ipv4_src_ipv6.ipv6_layout.ipv6), smask, 16);
}
if (!addr6_all_zero(daddr)) {
memcpy(MLX5_ADDR_OF(fte_match_param, spec->match_value,
outer_headers.dst_ipv4_dst_ipv6.ipv6_layout.ipv6), daddr, 16);
memcpy(MLX5_ADDR_OF(fte_match_param, spec->match_criteria,
- outer_headers.dst_ipv4_dst_ipv6.ipv6_layout.ipv6), smask, 16);
+ outer_headers.dst_ipv4_dst_ipv6.ipv6_layout.ipv6), dmask, 16);
}
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 330/457] net/sched: reject IDR error pointers when deleting actions
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 329/457] net/mlx5e: fix swapped IPv6 IPsec policy masks Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 331/457] net: airoha: npu: cancel wdt_work after releasing the WDT IRQ Greg Kroah-Hartman
` (137 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit c82b797abe668d0b668601a93ba2c0b071a63574 upstream.
tcf_action_delete() drops the reference held by its lookup before calling
tcf_idr_delete_index() with the saved action index. An unlocked
classifier can remove that action and reserve the same IDR slot with
ERR_PTR(-EBUSY) in between.
tcf_idr_delete_index() only checks the lookup result for NULL. It
therefore treats the reservation as a tc_action and dereferences
tcfa_bindcnt. A hardware execution breakpoint was used to schedule the
interleaving without changing the kernel source. KASAN reported this
decoded trace:
BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010
Read of size 4 at addr 0000000000000010 by task poc/150
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002
RIP: tca_action_gd+0x5c0/0x1010:
arch_atomic_read at arch/x86/include/asm/atomic.h:23
raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457
atomic_read at include/linux/atomic/atomic-instrumented.h:33
tcf_idr_delete_index at net/sched/act_api.c:766
tcf_action_delete at net/sched/act_api.c:1859
tcf_del_notify at net/sched/act_api.c:2014
tca_action_gd at net/sched/act_api.c:2064
R13: 0000000000000010 R15: fffffffffffffff0
Kernel panic - not syncing: Fatal exception
R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces
the address in R13. With the guard applied, the same reproducer returned
-ENOENT without a KASAN report or panic. Treat error pointers as absent
and return -ENOENT.
Fixes: 0190c1d452a9 ("net: sched: atomically check-allocate action")
Cc: stable@vger.kernel.org
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260914065123.4109709-2-bestswngs@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_api.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -758,7 +758,7 @@ static int tcf_idr_delete_index(struct t
mutex_lock(&idrinfo->lock);
p = idr_find(&idrinfo->action_idr, index);
- if (!p) {
+ if (IS_ERR_OR_NULL(p)) {
mutex_unlock(&idrinfo->lock);
return -ENOENT;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 331/457] net: airoha: npu: cancel wdt_work after releasing the WDT IRQ
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 330/457] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 332/457] net: arp: terminate device name before lookup Greg Kroah-Hartman
` (136 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Lorenzo Bianconi, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 4bdee8060d1e4581624e68fbd369b1afb14df4bc upstream.
airoha_npu_remove() calls cancel_work_sync() on each core's wdt_work,
but the watchdog IRQ that queues it is requested with devm_request_irq()
and is freed only after .remove() returns. airoha_npu_wdt_handler() can
therefore schedule_work() again once the cancel has returned. struct
airoha_npu, which contains the work, is devm_kzalloc()'d and is freed in
that same unwind, so the late work dereferences freed memory.
Register the work with devm_work_autocancel() before devm_request_irq()
and drop .remove(). Devres runs in reverse order, so the IRQ is freed
before cancel_work_sync(), including when probe fails. A cancel left in
.remove() cannot get that order. Initializing the work first also stops
a pending watchdog interrupt from queuing an uninitialized work item.
Probe currently calls INIT_WORK() only after devm_request_irq().
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: 23290c7bc190 ("net: airoha: Introduce Airoha NPU support")
Cc: stable@vger.kernel.org # 6.15+
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Acked-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260922000914.542068-1-mhun512@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/airoha/airoha_npu.c | 18 ++++++------------
1 file changed, 6 insertions(+), 12 deletions(-)
--- a/drivers/net/ethernet/airoha/airoha_npu.c
+++ b/drivers/net/ethernet/airoha/airoha_npu.c
@@ -5,6 +5,7 @@
*/
#include <linux/devcoredump.h>
+#include <linux/devm-helpers.h>
#include <linux/firmware.h>
#include <linux/platform_device.h>
#include <linux/of_net.h>
@@ -749,12 +750,15 @@ static int airoha_npu_probe(struct platf
if (irq < 0)
return irq;
+ err = devm_work_autocancel(dev, &core->wdt_work,
+ airoha_npu_wdt_work);
+ if (err)
+ return err;
+
err = devm_request_irq(dev, irq, airoha_npu_wdt_handler,
IRQF_SHARED, "airoha-npu-wdt", core);
if (err)
return err;
-
- INIT_WORK(&core->wdt_work, airoha_npu_wdt_work);
}
/* wlan IRQ lines */
@@ -801,18 +805,8 @@ static int airoha_npu_probe(struct platf
return 0;
}
-static void airoha_npu_remove(struct platform_device *pdev)
-{
- struct airoha_npu *npu = platform_get_drvdata(pdev);
- int i;
-
- for (i = 0; i < ARRAY_SIZE(npu->cores); i++)
- cancel_work_sync(&npu->cores[i].wdt_work);
-}
-
static struct platform_driver airoha_npu_driver = {
.probe = airoha_npu_probe,
- .remove = airoha_npu_remove,
.driver = {
.name = "airoha-npu",
.of_match_table = of_airoha_npu_match,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 332/457] net: arp: terminate device name before lookup
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 331/457] net: airoha: npu: cancel wdt_work after releasing the WDT IRQ Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 333/457] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
` (135 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zijie Huang, Ren Wei,
Ido Schimmel, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijie Huang <milkory@outlook.com>
commit d8b6529e80bcb4fb8177121404cbb3377acaebd2 upstream.
The ARP ioctl copies a user-provided struct arpreq into a stack object. Its
arp_dev field may contain IFNAMSIZ bytes without a NUL terminator.
Such input is passed to dev_get_by_name_rcu() or __dev_get_by_name(), where
strcmp() can read past the end of the stack object when a matching
alternative interface name exists.
Terminate the field before the lookup to prevent the out-of-bounds read.
Fixes: 36fbf1e52bd3 ("net: rtnetlink: add linkprop commands to add and delete alternative ifnames")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zijie Huang <milkory@outlook.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/fabf02a70787d17299e4b3153eadffaf20d154b3.1789910973.git.milkory@outlook.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/arp.c | 1 +
1 file changed, 1 insertion(+)
--- a/net/ipv4/arp.c
+++ b/net/ipv4/arp.c
@@ -1278,6 +1278,7 @@ int arp_ioctl(struct net *net, unsigned
err = copy_from_user(&r, arg, sizeof(struct arpreq));
if (err)
return -EFAULT;
+ r.arp_dev[IFNAMSIZ - 1] = '\0';
break;
default:
return -EINVAL;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 333/457] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 332/457] net: arp: terminate device name before lookup Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 334/457] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
` (134 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 43e746821f5f5afbbf68e388bf9fbe221e03bfca upstream.
Same issue as atl1c (see the first commit in this series, "net:
atl1c: fix soft lockup on out-of-range tpd_cons read"): the hardware
can report an out-of-range cmb_tpd_next_to_clean (seen as 0xffff)
while the PCIe link/MAC is resetting. An out-of-range value can
never be reached and the loop below would spin forever. Treat it as
"nothing new to clean" instead.
Fixes: f3cc28c797604f ("Add Attansic L1 ethernet driver.")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-4-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atlx/atl1.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atlx/atl1.c
+++ b/drivers/net/ethernet/atheros/atlx/atl1.c
@@ -2066,6 +2066,9 @@ static int atl1_intr_tx(struct atl1_adap
sw_tpd_next_to_clean = atomic_read(&tpd_ring->next_to_clean);
cmb_tpd_next_to_clean = le16_to_cpu(adapter->cmb.cmb->tpd_cons_idx);
+ if (unlikely(cmb_tpd_next_to_clean >= tpd_ring->count))
+ cmb_tpd_next_to_clean = sw_tpd_next_to_clean;
+
while (cmb_tpd_next_to_clean != sw_tpd_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[sw_tpd_next_to_clean];
if (buffer_info->dma) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 334/457] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 333/457] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 335/457] net: ipconfig: bound DHCP option construction Greg Kroah-Hartman
` (133 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Simon Horman,
Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 999e8295bc41d6ce45b8e54f88150efa96f3f01e upstream.
hns_dsaf_find_platform_device() returns the mdio platform device with its
reference count incremented. hns_mac_register_phy() never drops that
reference, so the mdio device can not be released.
Release the reference on both the deferred probe and the normal path.
Fixes: 1d1afa2ebf82 ("net: hns: register phy device in each mac initial sequence")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260917110828.2148390-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c
+++ b/drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c
@@ -793,6 +793,7 @@ static int hns_mac_register_phy(struct h
dev_err(mac_cb->dev,
"mac%d mdio is NULL, dsaf will probe again later\n",
mac_cb->mac_id);
+ put_device(&pdev->dev);
return -EPROBE_DEFER;
}
@@ -801,6 +802,8 @@ static int hns_mac_register_phy(struct h
dev_dbg(mac_cb->dev, "mac%d register phy addr:%d\n",
mac_cb->mac_id, addr);
+ put_device(&pdev->dev);
+
return rc;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 335/457] net: ipconfig: bound DHCP option construction
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 334/457] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 336/457] net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths Greg Kroah-Hartman
` (132 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Yuqi Xu, Ren Wei, Simon Horman,
Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuqi Xu <xuyuqiabc@gmail.com>
commit e47a1958e12abc3a17b5231a4f21c8f1bf662e08 upstream.
ic_dhcp_init_options() appends the hostname (option 12), vendor-class
(option 60) and client-ID (option 61) options into the fixed 312-byte
bootp_pkt.exten[] buffer. Only the client-ID branch checked the
remaining space; the hostname and vendor-class writes were unbounded.
A 64-byte hostname together with the maximum 252-byte dhcpclass=
identifier needs 18 + (2 + 64) + (2 + 252) = 338 of the 312 available
bytes even before the terminating END marker, so the vendor-class memcpy
runs past the end of exten[]. With CONFIG_FORTIFY_SOURCE this is
reported as a field-spanning write and, when the kernel is booted with
panic_on_warn=1, aborts boot with a panic.
Route the optional options through a common helper that makes sure the
option, its 2-byte header and the END marker all fit and drops an option
that would not. Configurations with short options keep sending exactly
the same bytes as before.
Fixes: 130c0f47fdf9 ("ipconfig: send host-name in DHCP requests")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
Reviewed-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/7808dfbfa2162dfd0b19f59aff5742d6e0db2abb.1789798023.git.xuyuqiabc@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/ipconfig.c | 45 ++++++++++++++++++++++++++-------------------
1 file changed, 26 insertions(+), 19 deletions(-)
--- a/net/ipv4/ipconfig.c
+++ b/net/ipv4/ipconfig.c
@@ -676,6 +676,24 @@ static const u8 ic_bootp_cookie[4] = { 9
#ifdef IPCONFIG_DHCP
+static bool __init
+ic_dhcp_add_option(u8 **options, const u8 *end, u8 type, const void *value,
+ int len)
+{
+ u8 *e = *options;
+
+ /* leave room for the option header and the END marker */
+ if (len > U8_MAX || end - e < len + 3)
+ return false;
+
+ *e++ = type;
+ *e++ = len;
+ memcpy(e, value, len);
+ *options = e + len;
+
+ return true;
+}
+
static void __init
ic_dhcp_init_options(u8 *options, struct ic_device *d)
{
@@ -691,6 +709,7 @@ ic_dhcp_init_options(u8 *options, struct
42, /* NTP servers */
};
u8 mt = (ic_servaddr == NONE) ? DHCPDISCOVER : DHCPREQUEST;
+ u8 *end = options + sizeof(((struct bootp_pkt *)0)->exten);
u8 *e = options;
int len;
@@ -721,31 +740,19 @@ ic_dhcp_init_options(u8 *options, struct
e += sizeof(ic_req_params);
if (ic_host_name_set) {
- *e++ = 12; /* host-name */
len = strlen(utsname()->nodename);
- *e++ = len;
- memcpy(e, utsname()->nodename, len);
- e += len;
+ ic_dhcp_add_option(&e, end, 12, utsname()->nodename, len);
}
if (*vendor_class_identifier) {
- pr_info("DHCP: sending class identifier \"%s\"\n",
- vendor_class_identifier);
- *e++ = 60; /* Class-identifier */
len = strlen(vendor_class_identifier);
- *e++ = len;
- memcpy(e, vendor_class_identifier, len);
- e += len;
+ if (ic_dhcp_add_option(&e, end, 60, vendor_class_identifier, len))
+ pr_info("DHCP: sending class identifier \"%s\"\n",
+ vendor_class_identifier);
}
len = strlen(dhcp_client_identifier + 1);
- /* the minimum length of identifier is 2, include 1 byte type,
- * and can not be larger than the length of options
- */
- if (len >= 1 && len < 312 - (e - options) - 1) {
- *e++ = 61;
- *e++ = len + 1;
- memcpy(e, dhcp_client_identifier, len + 1);
- e += len + 1;
- }
+ /* the minimum length of identifier is 2, include 1 byte type */
+ if (len >= 1)
+ ic_dhcp_add_option(&e, end, 61, dhcp_client_identifier, len + 1);
*e++ = 255; /* End of the list */
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 336/457] net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 335/457] net: ipconfig: bound DHCP option construction Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 337/457] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
` (131 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Théo Lebrun, Nicolai Buchwitz,
Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Théo Lebrun <theo.lebrun@bootlin.com>
commit 23d42b9a3bcd55b17d3b371544fedc708c2397e9 upstream.
Fix 3 leaks in macb_alloc() error paths:
- Tx buffer allocated but crossing a 4G boundary: Tx leaked.
- Rx buffer allocation fails: Tx leaked.
- Rx buffer allocated but crossing a 4G boundary: Tx & Rx leaked.
This is because our error handling calls macb_free(bp) which in turn
frees the buffers stored in bp->queues[0], but nothing has been stored
in there. Fix by storing allocated buffers into bp->queues[0] ASAP.
Fixes: 78d901897b3c ("net: macb: single dma_alloc_coherent() for DMA descriptors")
Cc: stable@vger.kernel.org
Signed-off-by: Théo Lebrun <theo.lebrun@bootlin.com>
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Link: https://patch.msgid.link/20260918-macb-alloc-leak-v1-1-aba9a3d4f6e3@bootlin.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/cadence/macb_main.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -2756,14 +2756,24 @@ static int macb_alloc_consistent(struct
size = bp->num_queues * macb_tx_ring_size_per_queue(bp);
tx = dma_alloc_coherent(dev, size, &tx_dma, GFP_KERNEL);
- if (!tx || upper_32_bits(tx_dma) != upper_32_bits(tx_dma + size - 1))
+ if (!tx)
+ goto out_err;
+ /* Record the buffer so that the error path frees it. */
+ bp->queues[0].tx_ring = tx;
+ bp->queues[0].tx_ring_dma = tx_dma;
+ if (upper_32_bits(tx_dma) != upper_32_bits(tx_dma + size - 1))
goto out_err;
netdev_dbg(bp->netdev, "Allocated %zu bytes for %u TX rings at %08lx (mapped %p)\n",
size, bp->num_queues, (unsigned long)tx_dma, tx);
size = bp->num_queues * macb_rx_ring_size_per_queue(bp);
rx = dma_alloc_coherent(dev, size, &rx_dma, GFP_KERNEL);
- if (!rx || upper_32_bits(rx_dma) != upper_32_bits(rx_dma + size - 1))
+ if (!rx)
+ goto out_err;
+ /* Record the buffer so that the error path frees it. */
+ bp->queues[0].rx_ring = rx;
+ bp->queues[0].rx_ring_dma = rx_dma;
+ if (upper_32_bits(rx_dma) != upper_32_bits(rx_dma + size - 1))
goto out_err;
netdev_dbg(bp->netdev, "Allocated %zu bytes for %u RX rings at %08lx (mapped %p)\n",
size, bp->num_queues, (unsigned long)rx_dma, rx);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 337/457] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 336/457] net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 338/457] net: openvswitch: conntrack: remove add_helper dead code Greg Kroah-Hartman
` (130 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Axel Mierczuk, Ilya Maximets,
Aaron Conole, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit 26b2bd70d22457556e2fa01cbf1192cb1a94d619 upstream.
In a case where skb with an unconfirmed ct entry gets cloned, we may
end up committing both but with different sets of extensions.
The series of events:
1. The first clone wants to commit and runs the helpers wiring up
the extension pointer into the expectation list.
2. Then it looses the confirmation keeping the entry unconfirmed.
3. Second clone now wants to commit labels and adds the new extension
for that breaking the pointer in the expectation list causing
UAF on the destruction path later.
While this is possible to trigger, there should be no practical
network pipeline where committing both clones without modifications
into the same zone is needed. So, let's just reset the entry in case
for some reason we got an skb with a shared one during commit. This
doesn't affect any known use cases, but avoids any potential problems
with sharing and modification of the unconfirmed ct entry.
The fixes tag points to the introduction of helpers, since that's the
main UAF trigger for the sharing.
Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action")
Cc: stable@vger.kernel.org
Reported-by: Axel Mierczuk <axel.mierczuk@1password.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260921145655.3167436-2-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/net/netfilter/nf_conntrack.h | 5 +++++
net/openvswitch/conntrack.c | 12 ++++++++++++
2 files changed, 17 insertions(+)
--- a/include/net/netfilter/nf_conntrack.h
+++ b/include/net/netfilter/nf_conntrack.h
@@ -185,6 +185,11 @@ static inline void nf_ct_put(struct nf_c
nf_ct_destroy(&ct->ct_general);
}
+static inline bool nf_ct_shared(const struct nf_conn *ct)
+{
+ return refcount_read(&ct->ct_general.use) > 1;
+}
+
/* load module; enable/disable conntrack in this namespace */
int nf_ct_netns_get(struct net *net, u8 nfproto);
void nf_ct_netns_put(struct net *net, u8 nfproto);
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -734,6 +734,18 @@ static int __ovs_ct_lookup(struct net *n
enum ip_conntrack_info ctinfo;
struct nf_conn *ct;
+ /* If the ct entry is not confirmed and shared with some other skb,
+ * e.g., a cloned one, we can't just modify it with the commit as we
+ * must not modify the extension set. Reset.
+ */
+ if (cached && info->commit) {
+ ct = nf_ct_get(skb, &ctinfo);
+ if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) {
+ nf_reset_ct(skb);
+ cached = false;
+ }
+ }
+
if (!cached) {
struct nf_hook_state state = {
.hook = NF_INET_PRE_ROUTING,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 338/457] net: openvswitch: conntrack: remove add_helper dead code
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 337/457] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 339/457] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Greg Kroah-Hartman
` (129 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Aaron Conole,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit 5e6c14dd42a1c1fe938e573dc6c9098145b2b0c4 upstream.
This variable can only become 'true' when the connection is not
confirmed, but it is only checked when it is confirmed. So, it can be
treated as being always false and just removed.
Fixes: 3c1860543fcc ("openvswitch: add nf_ct_is_confirmed check before assigning the helper")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260921145655.3167436-3-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 10 ++--------
1 file changed, 2 insertions(+), 8 deletions(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -779,8 +779,6 @@ static int __ovs_ct_lookup(struct net *n
ct = nf_ct_get(skb, &ctinfo);
if (ct) {
- bool add_helper = false;
-
/* Packets starting a new connection must be NATted before the
* helper, so that the helper knows about the NAT. We enforce
* this by delaying both NAT and helper calls for unconfirmed
@@ -812,7 +810,6 @@ static int __ovs_ct_lookup(struct net *n
GFP_ATOMIC);
if (err)
return err;
- add_helper = true;
/* helper installed, add seqadj if NAT is required */
if (info->nat && !nfct_seqadj(ct)) {
@@ -822,13 +819,10 @@ static int __ovs_ct_lookup(struct net *n
}
/* Call the helper only if:
- * - nf_conntrack_in() was executed above ("!cached") or a
- * helper was just attached ("add_helper") for a confirmed
- * connection, or
+ * - nf_conntrack_in() was executed above ("!cached"), or
* - When committing an unconfirmed connection.
*/
- if ((nf_ct_is_confirmed(ct) ? !cached || add_helper :
- info->commit)) {
+ if ((nf_ct_is_confirmed(ct) ? !cached : info->commit)) {
int err = nf_ct_helper(skb, ct, ctinfo, info->family);
err = verdict_to_errno(err);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 339/457] net: openvswitch: conntrack: fix helper UAF due to extensions realloc
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 338/457] net: openvswitch: conntrack: remove add_helper dead code Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 340/457] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
` (128 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Axel Mierczuk, Ilya Maximets,
Aaron Conole, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
commit 1a4151e6be57b098b7a5ebfbde58585e83200cdc upstream.
While calling the helpers, a raw pointer to the extensions area is
wired into expectations list:
-> nf_ct_helper()
-> helper->help()
-> nf_ct_expect_related_report()
-> nf_ct_expect_insert()
-> hlist_add_head_rcu(&exp->lnode, &master_help->expectations)
In case the connection is not confirmed yet, more extensions can be
added afterwards with *_ext_add() calls reallocating the extension
space and leaving the now invalid pointer in the expectations list
that is later accessed while removing the expectation.
Make sure that helpers are called at the end after all the other
extensions are already added.
Note that the helper rejection now leaves the mark and labels set,
but that's not different from how the NAT was handled before or how
the mark and the labels were handled on confirmation failure. And
there are no atomicity guarantees provided by the API anyway.
Fixes: cae3a2627520 ("openvswitch: Allow attaching helpers to ct action")
Cc: stable@vger.kernel.org
Reported-by: Axel Mierczuk <axel.mierczuk@1password.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260921145655.3167436-4-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -818,11 +818,14 @@ static int __ovs_ct_lookup(struct net *n
}
}
- /* Call the helper only if:
- * - nf_conntrack_in() was executed above ("!cached"), or
- * - When committing an unconfirmed connection.
+ /* Call the helper only if nf_conntrack_in() was executed
+ * above ("!cached").
+ *
+ * For unconfirmed connections it will be called later during
+ * commit as we need to have all the other extensions allocated
+ * before the call.
*/
- if ((nf_ct_is_confirmed(ct) ? !cached : info->commit)) {
+ if (nf_ct_is_confirmed(ct) && !cached) {
int err = nf_ct_helper(skb, ct, ctinfo, info->family);
err = verdict_to_errno(err);
@@ -1026,6 +1029,14 @@ static int ovs_ct_commit(struct net *net
return err;
nf_conn_act_ct_ext_add(skb, ct, ctinfo);
+
+ /* Call the helpers now. We couldn't do this before as
+ * all the extensions must be allocated before the call.
+ */
+ err = nf_ct_helper(skb, ct, ctinfo, info->family);
+ err = verdict_to_errno(err);
+ if (err)
+ return err;
} else if (IS_ENABLED(CONFIG_NF_CONNTRACK_LABELS) &&
labels_nonzero(&info->labels.mask)) {
err = ovs_ct_set_labels(ct, key, &info->labels.value,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 340/457] net: atl1c: fix soft lockup on out-of-range tpd_cons read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 339/457] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 341/457] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
` (127 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 36c2009d90f2210ef92e6f4f2850e8b57b09e754 upstream.
The hardware can report an out-of-range tpd_cons (seen as 0xffff)
while the PCIe link/MAC is resetting. An out-of-range value can
never be reached and the loop below would spin forever. To avoid
a soft lockup treat it as "nothing new to clean" instead.
Reproduced on two machines, same NIC (Qualcomm Atheros AR8151 v2.0,
4-port), triggered by rebooting a Mikrotik CCR2004 PCIe card that
the ports are directly linked to:
- Ubuntu 26.04.1 LTS, kernel 7.0.0-31-generic. The link-flap
precursor, before the lockup was captured with a full trace
elsewhere:
atl1c 0000:05:00.0 enp5s0f0: NETDEV WATCHDOG: CPU: 4: transmit queue 2 timed out 489984 ms
atl1c 0000:05:00.0: MAC state machine can't be idle since disabled for 10ms second
atl1c 0000:05:00.0: atl1c: enp5s0f0 NIC Link is Up<65535 Mbps Full Duplex>
65535 (0xffff) here is the same value tpd_cons reads back once the
loop below gets stuck.
- Proxmox VE, kernel 7.0.14-11-pve. Same NIC/trigger, this time
caught by the soft lockup watchdog with a full stack trace:
watchdog: BUG: soft lockup - CPU#12 stuck for 354s! [napi/eth%d-0:329]
CPU: 12 UID: 0 PID: 329 Comm: napi/eth%d-0 Tainted: P O L 7.0.14-11-pve #1 PREEMPT(lazy)
RIP: 0010:atl1c_clean_tx+0x142/0x2d0 [atl1c]
Call Trace:
<TASK>
__napi_poll+0x32/0x1e0
napi_threaded_poll_loop+0x286/0x2e0
napi_threaded_poll+0xfd/0x140
kthread+0xf7/0x130
ret_from_fork+0x2da/0x3a0
ret_from_fork_asm+0x1a/0x30
</TASK>
Fixes: 43250ddd75a35d ("atl1c: Atheros L1C Gigabit Ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-2-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atl1c/atl1c_main.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atl1c/atl1c_main.c
+++ b/drivers/net/ethernet/atheros/atl1c/atl1c_main.c
@@ -1602,6 +1602,9 @@ static int atl1c_clean_tx(struct napi_st
AT_READ_REGW(&adapter->hw, atl1c_qregs[tpd_ring->num].tpd_cons,
&hw_next_to_clean);
+ if (unlikely(hw_next_to_clean >= tpd_ring->count))
+ hw_next_to_clean = next_to_clean;
+
while (next_to_clean != hw_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[next_to_clean];
if (buffer_info->skb) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 341/457] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 340/457] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 342/457] net: bridge: mdb: restart port group walk after deletion Greg Kroah-Hartman
` (126 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gajdos Tamás, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gajdos Tamás <tamas@rimpianto.com>
commit 374bf9e4b90f979e052332c4faca2d745c491a12 upstream.
Same issue as atl1c (see the first commit in this series, "net:
atl1c: fix soft lockup on out-of-range tpd_cons read"): the hardware
can report an out-of-range hw_next_to_clean (seen as 0xffff) while
the PCIe link/MAC is resetting. An out-of-range value can never be
reached and the loop below would spin forever. Treat it as "nothing
new to clean" instead.
Fixes: a6a5325239c202 ("atl1e: Atheros L1E Gigabit Ethernet driver")
Cc: stable@vger.kernel.org
Signed-off-by: Gajdos Tamás <tamas@rimpianto.com>
Link: https://patch.msgid.link/20260921091334.3571525-3-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/atheros/atl1e/atl1e_main.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/net/ethernet/atheros/atl1e/atl1e_main.c
+++ b/drivers/net/ethernet/atheros/atl1e/atl1e_main.c
@@ -1234,6 +1234,9 @@ static bool atl1e_clean_tx_irq(struct at
u16 hw_next_to_clean = AT_READ_REGW(&adapter->hw, REG_TPD_CONS_IDX);
u16 next_to_clean = atomic_read(&tx_ring->next_to_clean);
+ if (unlikely(hw_next_to_clean >= tx_ring->count))
+ hw_next_to_clean = next_to_clean;
+
while (next_to_clean != hw_next_to_clean) {
tx_buffer = &tx_ring->tx_buffer[next_to_clean];
if (tx_buffer->dma) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 342/457] net: bridge: mdb: restart port group walk after deletion
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 341/457] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 343/457] net: ena: fix PHC cleanup on probe failure Greg Kroah-Hartman
` (125 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fourie Zhang, Nikolay Aleksandrov,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fourie Zhang <littleddfu@gmail.com>
commit ab1404ac81154a89fb61ac50ae9a04cd8d4834dc upstream.
br_mdb_flush_pgs() keeps a pointer-to-pointer cursor while walking
mp->ports. br_multicast_del_pg() can re-enter the same MDB entry through
br_multicast_sg_del_exclude_ports() and unlink other port groups. If the
cursor points into one of those groups, the next iteration dereferences a
stale cursor and can leave mp->ports pointing at freed memory.
A following RTM_GETMDB exposes the dangling pointer:
BUG: KASAN: slab-use-after-free in br_mdb_dump
Read of size 8
br_mdb_dump
rtnl_mdb_dump
rtnl_dumpit
netlink_dump
Reset the cursor to mp->ports after every deletion. The deletion removes at
least the selected group, so the restarted walk always makes progress.
Fixes: a6acb535afb2 ("bridge: mdb: Add MDB bulk deletion support")
Cc: stable@vger.kernel.org
Signed-off-by: Fourie Zhang <fouriezhang@tencent.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260920110852.60293-1-fouriezhang@tencent.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bridge/br_mdb.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/bridge/br_mdb.c
+++ b/net/bridge/br_mdb.c
@@ -1523,6 +1523,8 @@ static void br_mdb_flush_pgs(struct net_
}
br_multicast_del_pg(mp, p, pp);
+ /* br_multicast_del_pg() can remove other groups from this list. */
+ pp = &mp->ports;
}
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 343/457] net: ena: fix PHC cleanup on probe failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 342/457] net: bridge: mdb: restart port group walk after deletion Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 344/457] net: ena: fix MMIO read buffer leak " Greg Kroah-Hartman
` (124 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 0958ea4355e2e9220ad4e13da3b7d94f365ed34f upstream.
ena_probe() initializes the PHC as part of ena_device_init(), but the
probe failure path does not destroy it before freeing the PHC private
data.
The normal removal path calls ena_phc_destroy() through
ena_destroy_device() before ena_phc_free(). However, if probe fails
after ena_device_init() succeeds, the error path reaches ena_phc_free()
without unregistering the PTP clock or destroying the device PHC
resources.
Call ena_phc_destroy() in the probe error path before freeing the PHC
private data.
This issue was found by manual code inspection.
Cc: stable@vger.kernel.org tags and describe this as a consistency cleanup
Fixes: e0ea34158ee8 ("net: ena: Add PHC support in the ENA driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: stable
Link: https://patch.msgid.link/20260921154202.471662-2-lgs201920130244@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/amazon/ena/ena_netdev.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/ethernet/amazon/ena/ena_netdev.c
+++ b/drivers/net/ethernet/amazon/ena/ena_netdev.c
@@ -4126,6 +4126,7 @@ err_worker_destroy:
err_device_destroy:
ena_com_delete_host_info(ena_dev);
ena_com_admin_destroy(ena_dev);
+ ena_phc_destroy(adapter);
ena_devlink_destroy:
ena_devlink_free(devlink);
err_metrics_destroy:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 344/457] net: ena: fix MMIO read buffer leak on probe failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 343/457] net: ena: fix PHC cleanup on probe failure Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 345/457] net: phy: intel-xway: workaround 100BASE-TX Link-Up issue Greg Kroah-Hartman
` (123 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 9476b4468862927297c94c440863cd8ed1e7cc83 upstream.
ena_device_init() initializes the MMIO read mechanism with
ena_com_mmio_reg_read_request_init(), which allocates a coherent DMA
buffer for MMIO read responses.
The normal removal path releases this buffer through
ena_com_mmio_reg_read_request_destroy(). However, if ena_probe() fails
after ena_device_init() succeeds, the error path destroys the admin
resources and eventually frees ena_dev without destroying the MMIO read
request, leaving the coherent DMA buffer allocated.
Call ena_com_mmio_reg_read_request_destroy() in the probe error path
before releasing the remaining device resources.
This issue was found by manual code inspection.
Fixes: 1738cd3ed342 ("net: ena: Add a driver for Amazon Elastic Network Adapters (ENA)")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260921154202.471662-3-lgs201920130244@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/amazon/ena/ena_netdev.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/ethernet/amazon/ena/ena_netdev.c
+++ b/drivers/net/ethernet/amazon/ena/ena_netdev.c
@@ -4127,6 +4127,7 @@ err_device_destroy:
ena_com_delete_host_info(ena_dev);
ena_com_admin_destroy(ena_dev);
ena_phc_destroy(adapter);
+ ena_com_mmio_reg_read_request_destroy(ena_dev);
ena_devlink_destroy:
ena_devlink_free(devlink);
err_metrics_destroy:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 345/457] net: phy: intel-xway: workaround 100BASE-TX Link-Up issue
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 344/457] net: ena: fix MMIO read buffer leak " Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 346/457] net: phy: micrel: Advance register data pointer in write loop Greg Kroah-Hartman
` (122 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Sverdlin, Andrew Lunn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Sverdlin <alexander.sverdlin@siemens.com>
commit b94773dc4df7026a6f29b2c65e96e88d29cdb576 upstream.
MaxLinear GSW12x/GSW14x Ethernet Switch Errata Sheet states:
"An issue has been sporadically observed after device power-on on the first
link-up attempt in 100BASE-TX mode resulting in either the link-up taking a
long time, or failing to link-up altogether...
Workaround:
After power-on, enable Cable Diagnostic Mode for all ports and disable
it..."
Implement the proposed workaround unconditionally in the Intel XWAY driver
(MaxLinear GSW1xx switches incorporate Intel XWAY PHYs) because the
diagnostic bits have the same meaning even in older integral PHYs such as
GPY111/PEF7071/PHY11G. So it's not clear how to distinguish the affected
newer integrated PHYs, but the workaround should not hurt the older PHYs.
Cc: stable@vger.kernel.org
Fixes: 22335939ec90 ("net: dsa: add driver for MaxLinear GSW1xx switch family")
Signed-off-by: Alexander Sverdlin <alexander.sverdlin@siemens.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260922075251.23386-1-alexander.sverdlin@siemens.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/phy/intel-xway.c | 29 ++++++++++++++++++++++++++++-
1 file changed, 28 insertions(+), 1 deletion(-)
--- a/drivers/net/phy/intel-xway.c
+++ b/drivers/net/phy/intel-xway.c
@@ -16,6 +16,11 @@
#define XWAY_MDIO_ISTAT 0x1A /* interrupt status */
#define XWAY_MDIO_LED 0x1B /* led control */
+#define XWAY_MDIO_GCTRL_TM_MASK GENMASK(15, 13)
+#define XWAY_MDIO_GCTRL_TM(mode) FIELD_PREP(XWAY_MDIO_GCTRL_TM_MASK, (mode))
+#define XWAY_MDIO_GCTRL_TM_NOP XWAY_MDIO_GCTRL_TM(0) /* Normal operation */
+#define XWAY_MDIO_GCTRL_TM_CDIAG XWAY_MDIO_GCTRL_TM(6) /* Cable diagnostics */
+
#define XWAY_MDIO_ERRCNT_SEL GENMASK(11, 8)
#define XWAY_MDIO_ERRCNT_COUNT GENMASK(7, 0)
#define XWAY_MDIO_ERRCNT_SEL_RXERR 0
@@ -326,6 +331,28 @@ static int xway_gphy_probe(struct phy_de
return 0;
}
+static int xway_11g_int_config_init(struct phy_device *phydev)
+{
+ int err;
+
+ /* An issue has been sporadically observed after device power-on on the
+ * first link-up attempt in 100BASE-TX mode resulting in either the
+ * link-up taking a long time, or failing to link-up altogether.
+ *
+ * Workaround:
+ * After power-on, enable Cable Diagnostic Mode for all ports and
+ * disable it.
+ */
+ err = phy_modify(phydev, MII_CTRL1000, XWAY_MDIO_GCTRL_TM_MASK, XWAY_MDIO_GCTRL_TM_CDIAG);
+ if (err)
+ return err;
+ err = phy_modify(phydev, MII_CTRL1000, XWAY_MDIO_GCTRL_TM_MASK, XWAY_MDIO_GCTRL_TM_NOP);
+ if (err)
+ return err;
+
+ return xway_gphy_config_init(phydev);
+}
+
static int xway_gphy14_config_aneg(struct phy_device *phydev)
{
int reg, err;
@@ -735,7 +762,7 @@ static struct phy_driver xway_gphy[] = {
.phy_id_mask = 0xffffffff,
.name = "Intel XWAY PHY11G (xRX v1.2 integrated)",
/* PHY_GBIT_FEATURES */
- .config_init = xway_gphy_config_init,
+ .config_init = xway_11g_int_config_init,
.probe = xway_gphy_probe,
.handle_interrupt = xway_gphy_handle_interrupt,
.config_intr = xway_gphy_config_intr,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 346/457] net: phy: micrel: Advance register data pointer in write loop
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 345/457] net: phy: intel-xway: workaround 100BASE-TX Link-Up issue Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 347/457] net: txgbe: fix FDIR filter restore for VF rules Greg Kroah-Hartman
` (121 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abhishek Ojha, Andrew Lunn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abhishek Ojha <abhishek.ojha@savoirfairelinux.com>
commit 95c4d54ed02283e9a09e8cd7360e384daa67a741 upstream.
lanphy_write_reg_data() does not advance the data pointer while iterating
over the register table. As a result, it writes the first entry num times
and leaves the remaining errata registers unconfigured.
Single-entry tables are unaffected, but tables with multiple entries
leave every entry after the first unapplied.
Advance the data pointer after each successful write so every table entry
is applied in order.
Fixes: c8732e933925 ("net: phy: micrel: lan8842 errata")
Cc: stable@vger.kernel.org
Signed-off-by: Abhishek Ojha <abhishek.ojha@savoirfairelinux.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260916231928.1336305-1-abhishek.ojha@savoirfairelinux.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/phy/micrel.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/net/phy/micrel.c
+++ b/drivers/net/phy/micrel.c
@@ -6285,6 +6285,7 @@ static int lanphy_write_reg_data(struct
data->val);
if (ret)
break;
+ data++;
}
return ret;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 347/457] net: txgbe: fix FDIR filter restore for VF rules
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 346/457] net: phy: micrel: Advance register data pointer in write loop Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 348/457] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
` (120 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhang Yunfei, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhang Yunfei <zhangyunfei1@kylinos.cn>
commit 651010592bdce7005c1179498327e51bfc4fe1a5 upstream.
txgbe_fdir_filter_restore() reprograms every filter from
txgbe->fdir_filter_list after a reset. It extracts the ring part of
filter->action with ethtool_get_flow_spec_ring() and maps it onto a
PF rx ring, silently dropping the VF part of the cookie that
txgbe_add_ethtool_fdir_entry() stores there (input->action =
fsp->ring_cookie).
For a rule directed at a VF, restore therefore reprograms the filter
to the PF queue with the same ring index: after any down/up or
txgbe_reinit_locked(), traffic matching the rule is steered to the
PF instead of the VF.
Handle VF rules the same way txgbe_add_ethtool_fdir_entry() does:
validate vf against wx->num_vfs and ring against
wx->num_rx_queues_per_pool, and map the ring onto the absolute
queue index ((vf - 1) * wx->num_rx_queues_per_pool) + ring.
Fixes: 7a91722e0dd4 ("net: txgbe: Support the FDIR rules assigned to VFs")
Cc: stable@vger.kernel.org
Signed-off-by: Zhang Yunfei <zhangyunfei1@kylinos.cn>
Link: https://patch.msgid.link/20260911091123.798931-1-zhangyunfei1@kylinos.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/wangxun/txgbe/txgbe_fdir.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
--- a/drivers/net/ethernet/wangxun/txgbe/txgbe_fdir.c
+++ b/drivers/net/ethernet/wangxun/txgbe/txgbe_fdir.c
@@ -591,15 +591,24 @@ static void txgbe_fdir_filter_restore(st
queue = TXGBE_RDB_FDIR_DROP_QUEUE;
} else {
u32 ring = ethtool_get_flow_spec_ring(filter->action);
+ u8 vf = ethtool_get_flow_spec_ring_vf(filter->action);
- if (ring >= wx->num_rx_queues) {
+ if (!vf && ring >= wx->num_rx_queues) {
wx_err(wx, "FDIR restore failed, ring:%u\n",
ring);
continue;
+ } else if (vf && (vf > wx->num_vfs ||
+ ring >= wx->num_rx_queues_per_pool)) {
+ wx_err(wx, "FDIR restore failed, vf:%u, ring:%u\n",
+ vf, ring);
+ continue;
}
/* Map the ring onto the absolute queue index */
- queue = wx->rx_ring[ring]->reg_idx;
+ if (!vf)
+ queue = wx->rx_ring[ring]->reg_idx;
+ else
+ queue = ((vf - 1) * wx->num_rx_queues_per_pool) + ring;
}
ret = txgbe_fdir_write_perfect_filter(wx,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 348/457] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 347/457] net: txgbe: fix FDIR filter restore for VF rules Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 349/457] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
` (119 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ming Wang, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ming Wang <wangming01@loongson.cn>
commit f75f21ef36285e5f56ee0c428bd2909ee81165b9 upstream.
The MeiG Smart SRM821 5G module (0x2dee:0x4d53) crashes and drops off
the USB bus when it receives a Zero Length Packet (ZLP) after sending
or receiving an NTB of exactly 16384 bytes (tx_max).
According to the MBIM specification, devices do not require a ZLP
if the NTB size is exactly dwNtbOutMaxSize. However, the cdc_mbim
driver defaults to sending ZLPs for devices not explicitly whitelisted
to accommodate non-conformant hardware. This default behavior breaks
the strictly conformant MeiG SRM821 module.
Add this device to the ZLP conformance whitelist (cdc_mbim_info) so
the driver will pad the NTB to avoid sending ZLPs, preventing the
device firmware from crashing.
Cc: stable@vger.kernel.org
Signed-off-by: Ming Wang <wangming01@loongson.cn>
Link: https://patch.msgid.link/20260920074500.826121-1-wangming01@loongson.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/cdc_mbim.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/net/usb/cdc_mbim.c
+++ b/drivers/net/usb/cdc_mbim.c
@@ -635,6 +635,11 @@ static const struct usb_device_id mbim_d
.driver_info = (unsigned long)&cdc_mbim_info,
},
+ /* MeiG Smart SRM821 ZLP conformance */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x2dee, 0x4d53, USB_CLASS_COMM, USB_CDC_SUBCLASS_MBIM, USB_CDC_PROTO_NONE),
+ .driver_info = (unsigned long)&cdc_mbim_info,
+ },
+
/* Some Huawei devices, ME906s-158 (12d1:15c1) and E3372
* (12d1:157d), are known to fail unless the NDP is placed
* after the IP packets. Applying the quirk to all Huawei
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 349/457] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 348/457] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 350/457] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
` (118 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 17741334d00bf5ebd37f8c1c36bc9c146a351deb upstream.
usb_get_from_anchor() hands over a reference to the URB, which the caller
must release. lan78xx_submit_deferred_urbs() never does, so every deferred
Tx URB keeps an extra reference: the counter grows on each suspend/resume
cycle and the URBs are never freed when the buffers are released. Drop
the reference after submitting, and on the path that drops the packet
instead of submitting it.
Fixes: 5f4cc6e25148 ("lan78xx: Fix race conditions in suspend/resume handling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260917115811.2150119-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/usb/lan78xx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/net/usb/lan78xx.c
+++ b/drivers/net/usb/lan78xx.c
@@ -5239,10 +5239,12 @@ static bool lan78xx_submit_deferred_urbs
!netif_carrier_ok(dev->net) ||
pipe_halted) {
lan78xx_release_tx_buf(dev, skb);
+ usb_put_urb(urb);
continue;
}
ret = usb_submit_urb(urb, GFP_ATOMIC);
+ usb_put_urb(urb);
if (ret == 0) {
netif_trans_update(dev->net);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 350/457] netfilter: ip6t_rpfilter: reject routes without inet6_dev
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 349/457] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 351/457] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
` (117 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+459f67f4d8af8ce6,
Florian Westphal, Weiming Shi, Pablo Neira Ayuso
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
commit 1b9b5323725e458906c7620a3bc10398b51ad954 upstream.
ip6_route_lookup() can return an error-free route whose rt6i_idev is
NULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears
down its inet6_dev while fib6_ifdown() leaves routes using nexthop objects
in the FIB. An unprivileged user can construct this state with rtnetlink
in a private user and network namespace, then trigger a NULL dereference
through an IPv6 rpfilter lookup:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75)
Call Trace:
ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316)
nf_hook_slow (net/netfilter/core.c:619)
ipv6_rcv (net/ipv6/ip6_input.c:351)
__netif_receive_skb_one_core (net/core/dev.c:6216)
process_backlog (net/core/dev.c:6680)
__napi_poll (net/core/dev.c:7739)
net_rx_action (net/core/dev.c:7959)
handle_softirqs (kernel/softirq.c:622)
do_softirq.part.0 (kernel/softirq.c:523)
__local_bh_enable_ip (kernel/softirq.c:450)
__dev_queue_xmit (net/core/dev.c:4913)
packet_sendmsg (net/packet/af_packet.c:3139)
__sys_sendto (net/socket.c:2252)
__x64_sys_sendto (net/socket.c:2259)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Reject routes without an inet6_dev immediately after lookup. Such routes
are not eligible for reverse-path filtering, and the check protects all
later rt6i_idev dereferences.
Fixes: e26f9a480fb6 ("netfilter: add ipv6 reverse path filter match")
Reported-by: co+459f67f4d8af8ce6@bugs.sh
Closes: https://lore.kernel.org/all/VtWUkE8QzJt5CroTj2V2v3ZQ0gwbXZ7nq7I3@bugs.sh/
Suggested-by: Florian Westphal <fw@strlen.de>
Assisted-by: Claude:gpt-5
Cc: stable@vger.kernel.org
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/netfilter/ip6t_rpfilter.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/ipv6/netfilter/ip6t_rpfilter.c
+++ b/net/ipv6/netfilter/ip6t_rpfilter.c
@@ -61,7 +61,7 @@ static bool rpfilter_lookup_reverse6(str
fl6.flowi6_oif = dev->ifindex;
rt = (void *)ip6_route_lookup(net, &fl6, skb, lookup_flags);
- if (rt->dst.error)
+ if (rt->dst.error || !rt->rt6i_idev)
goto out;
if (rt->rt6i_flags & (RTF_REJECT|RTF_ANYCAST))
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 351/457] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 350/457] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 352/457] netfilter: nf_tables: skip expired catchall elements on insert and delete Greg Kroah-Hartman
` (116 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Florian Westphal, Luxiao Xu,
Ren Wei, Pablo Neira Ayuso
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luxiao Xu <rakukuip@gmail.com>
commit 82313c169eddc02b1bf5ba6b427803e272d3ec42 upstream.
rt_mt6_check() permits rules to be configured with rtinfo->addrnr == 0
even when address matching (IP6T_RT_FST_MASK) is requested.
In the IP6T_RT_FST_NSTRICT path, rt_mt6() evaluates packet routing
addresses against rtinfo->addrs[i] and terminates backwards at the bottom
of the loop:
if (ipv6_addr_equal(ap, &rtinfo->addrs[i])) {
i++;
}
if (i == rtinfo->addrnr)
break;
When addrnr is 0, if the first packet address matches rtinfo->addrs[0],
i is incremented to 1. Because i is now strictly greater than addrnr (0),
the loop termination condition (i == rtinfo->addrnr) is bypassed and will
never be satisfied.
If a crafted IPv6 packet contains matching routing addresses, i will
advance past IP6T_RT_HOPS (16). The subsequent call to ipv6_addr_equal()
reads beyond struct ip6t_rt, triggering UBSAN/KASAN out-of-bounds warnings
or kernel panics.
Fix this by:
1. Rejecting rules in rt_mt6_check() where IP6T_RT_FST_MASK is set but
rtinfo->addrnr is zero.
2. In rt_mt6(), moving the termination condition (i < rtinfo->addrnr)
into the for-loop header condition and removing the backwards break
at the end of the loop body.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Suggested-by: Florian Westphal <fw@strlen.de>
Assisted-by: LLM
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/netfilter/ip6t_rt.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/ipv6/netfilter/ip6t_rt.c
+++ b/net/ipv6/netfilter/ip6t_rt.c
@@ -96,7 +96,8 @@ static bool rt_mt6(const struct sk_buff
unsigned int i = 0;
for (temp = 0;
- temp < (unsigned int)((hdrlen - 8) / 16);
+ temp < (unsigned int)((hdrlen - 8) / 16) &&
+ i < rtinfo->addrnr;
temp++) {
ap = skb_header_pointer(skb,
ptr
@@ -112,8 +113,6 @@ static bool rt_mt6(const struct sk_buff
if (ipv6_addr_equal(ap, &rtinfo->addrs[i]))
i++;
- if (i == rtinfo->addrnr)
- break;
}
if (i == rtinfo->addrnr)
return ret;
@@ -162,6 +161,12 @@ static int rt_mt6_check(const struct xt_
pr_debug("too many addresses specified\n");
return -EINVAL;
}
+
+ if ((rtinfo->flags & IP6T_RT_FST_MASK) && !rtinfo->addrnr) {
+ pr_info_ratelimited("address list match requested but addrnr is 0\n");
+ return -EINVAL;
+ }
+
if ((rtinfo->flags & (IP6T_RT_RES | IP6T_RT_FST_MASK)) &&
(!(rtinfo->flags & IP6T_RT_TYP) ||
(rtinfo->rt_type != 0) ||
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 352/457] netfilter: nf_tables: skip expired catchall elements on insert and delete
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 351/457] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 353/457] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
` (115 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI, Aohan Mei,
Pablo Neira Ayuso
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit 70194dc37670bd08e44b471389861cc01bd3a3c9 upstream.
nft_setelem_catchall_insert() looks up duplicates with
nft_set_elem_active() only, while nft_set_catchall_lookup() and the
dump path additionally skip expired elements.
Once a catchall element with a timeout expires, this predicate drift
makes it invisible to userspace dumps, yet it still blocks
re-insertion: with NLM_F_EXCL the request fails with -EEXIST, and
without it the request reports success but silently inserts nothing.
The stale entry only goes away when the (user-tunable) gc interval
elapses, so the catchall rule may silently stop matching for an
arbitrarily long time after its first expiration.
The delete path shows the same drift: nft_setelem_catchall_deactivate()
picks the first active-next entry in the catchall list, so with an
expired entry still pending GC it retires the stale entry instead of
the fresh one, and it deactivates an element that userspace no longer
sees instead of failing with -ENOENT.
Align both walks with the lookup and dump predicates: only an element
that is active and not expired counts as a duplicate or delete
candidate, using the per-netns timestamp taken at transaction start,
in line with the set backend .insert/.deactivate and catchall GC sync
paths.
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support")
Assisted-by: CodeBuddy:Kimi-K3
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/netfilter/nf_tables_api.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -6990,11 +6990,14 @@ static int nft_setelem_catchall_insert(c
{
struct nft_set_elem_catchall *catchall;
u8 genmask = nft_genmask_next(net);
+ u64 tstamp = nft_net_tstamp(net);
struct nft_set_ext *ext;
list_for_each_entry(catchall, &set->catchall_list, list) {
ext = nft_set_elem_ext(set, catchall->elem);
- if (nft_set_elem_active(ext, genmask)) {
+ if (nft_set_elem_active(ext, genmask) &&
+ !__nft_set_elem_expired(ext, tstamp) &&
+ !nft_set_elem_is_dead(ext)) {
*priv = catchall->elem;
return -EEXIST;
}
@@ -7087,11 +7090,14 @@ static int nft_setelem_catchall_deactiva
struct nft_set_elem *elem)
{
struct nft_set_elem_catchall *catchall;
+ u64 tstamp = nft_net_tstamp(net);
struct nft_set_ext *ext;
list_for_each_entry(catchall, &set->catchall_list, list) {
ext = nft_set_elem_ext(set, catchall->elem);
- if (!nft_is_active_next(net, ext))
+ if (!nft_is_active_next(net, ext) ||
+ __nft_set_elem_expired(ext, tstamp) ||
+ nft_set_elem_is_dead(ext))
continue;
kfree(elem->priv);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 353/457] nfc: fix use-after-free in nfc_get_local_general_bytes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 352/457] netfilter: nf_tables: skip expired catchall elements on insert and delete Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 354/457] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
` (114 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxiao Xu, Ren Wei,
Simon Horman, David Heidelberg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luxiao Xu <rakukuip@gmail.com>
commit dcab71a7011918f6fdba7adcec02d217dcb84b8d upstream.
Commit 6709d4b7bc2e ("net: nfc: Fix use-after-free caused by
nfc_llcp_find_local") attempted to fix a use-after-free (UAF) issue by
invoking nfc_llcp_local_put(local) after accessing local->gb. However,
if the reference count drops to zero, local is freed immediately,
leading to a use-after-free when callers access the returned pointer.
Alternative approaches using dynamic allocation (e.g. kmemdup) introduced
memory leaks because callers consistently treat the returned pointer as
borrowed memory.
Fix this properly by refactoring nfc_llcp_general_bytes() and
nfc_get_local_general_bytes() to accept a caller-provided output buffer
(out_gb) and its maximum length (gb_max_len). The general bytes are
safely copied into out_gb before calling nfc_llcp_local_put(local),
ensuring safe lifetime management without ownership transfer complications.
Update all callers across drivers (microread, pn533, pn544, st21nfca,
digital_dep, and nci) to provide their own destination buffers and pass
them to nfc_get_local_general_bytes().
Fixes: 6709d4b7bc2e ("net: nfc: Fix use-after-free caused by nfc_llcp_find_local")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/3cbaac3bee23f8ff3a3284ed32d347696eb1d208.1788841683.git.rakukuip@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nfc/microread/microread.c | 6 +++---
drivers/nfc/pn533/pn533.c | 14 ++++++++------
drivers/nfc/pn533/pn533.h | 4 +++-
drivers/nfc/pn544/pn544.c | 7 +++----
drivers/nfc/st21nfca/core.c | 8 ++++----
include/net/nfc/hci.h | 2 +-
include/net/nfc/nfc.h | 3 ++-
net/nfc/core.c | 15 +++++++--------
net/nfc/digital_dep.c | 8 ++++----
net/nfc/llcp_core.c | 17 +++++++++++++----
net/nfc/nci/core.c | 10 +++++-----
net/nfc/nfc.h | 3 ++-
12 files changed, 55 insertions(+), 42 deletions(-)
--- a/drivers/nfc/microread/microread.c
+++ b/drivers/nfc/microread/microread.c
@@ -251,9 +251,9 @@ static int microread_start_poll(struct n
param[1] |= (1 << 1);
if ((im_protocols | tm_protocols) & NFC_PROTO_NFC_DEP_MASK) {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb), &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/drivers/nfc/pn533/pn533.c
+++ b/drivers/nfc/pn533/pn533.c
@@ -1355,10 +1355,11 @@ static int pn533_poll_dep(struct nfc_dev
u8 *next, nfcid3[NFC_NFCID3_MAXSIZE];
u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
- if (!dev->gb) {
- dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
-
- if (!dev->gb || !dev->gb_len) {
+ if (!dev->gb_len) {
+ nfc_get_local_general_bytes(nfc_dev, dev->gb,
+ sizeof(dev->gb),
+ &dev->gb_len);
+ if (!dev->gb_len) {
dev->poll_dep = 0;
queue_work(dev->wq, &dev->rf_work);
}
@@ -1656,8 +1657,9 @@ static int pn533_start_poll(struct nfc_d
}
if (tm_protocols) {
- dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
- if (dev->gb == NULL)
+ nfc_get_local_general_bytes(nfc_dev, dev->gb,
+ sizeof(dev->gb), &dev->gb_len);
+ if (dev->gb_len == 0)
tm_protocols = 0;
}
--- a/drivers/nfc/pn533/pn533.h
+++ b/drivers/nfc/pn533/pn533.h
@@ -6,6 +6,8 @@
* Copyright (C) 2012-2013 Tieto Poland
*/
+#include <net/nfc/nfc.h>
+
#define PN533_DEVICE_STD 0x1
#define PN533_DEVICE_PASORI 0x2
#define PN533_DEVICE_ACR122U 0x3
@@ -166,7 +168,7 @@ struct pn533 {
struct timer_list listen_timer;
int cancel_listen;
- u8 *gb;
+ u8 gb[NFC_MAX_GT_LEN];
size_t gb_len;
u8 tgt_available_prots;
--- a/drivers/nfc/pn544/pn544.c
+++ b/drivers/nfc/pn544/pn544.c
@@ -377,10 +377,9 @@ static int pn544_hci_start_poll(struct n
return r;
if ((im_protocols | tm_protocols) & NFC_PROTO_NFC_DEP_MASK) {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
- pr_debug("generate local bytes %p\n", hdev->gb);
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb), &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/drivers/nfc/st21nfca/core.c
+++ b/drivers/nfc/st21nfca/core.c
@@ -351,10 +351,10 @@ static int st21nfca_hci_start_poll(struc
if (r < 0)
return r;
} else {
- hdev->gb = nfc_get_local_general_bytes(hdev->ndev,
- &hdev->gb_len);
-
- if (hdev->gb == NULL || hdev->gb_len == 0) {
+ nfc_get_local_general_bytes(hdev->ndev, hdev->gb,
+ sizeof(hdev->gb),
+ &hdev->gb_len);
+ if (hdev->gb_len == 0) {
im_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
tm_protocols &= ~NFC_PROTO_NFC_DEP_MASK;
}
--- a/include/net/nfc/hci.h
+++ b/include/net/nfc/hci.h
@@ -144,7 +144,7 @@ struct nfc_hci_dev {
data_exchange_cb_t async_cb;
void *async_cb_context;
- u8 *gb;
+ u8 gb[NFC_MAX_GT_LEN];
size_t gb_len;
unsigned long quirks;
--- a/include/net/nfc/nfc.h
+++ b/include/net/nfc/nfc.h
@@ -273,7 +273,8 @@ struct sk_buff *nfc_alloc_recv_skb(unsig
int nfc_set_remote_general_bytes(struct nfc_dev *dev,
const u8 *gt, u8 gt_len);
-u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, size_t *gb_len);
+u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, u8 *out_gb,
+ size_t gb_max_len, size_t *gb_len);
int nfc_fw_download_done(struct nfc_dev *dev, const char *firmware_name,
u32 result);
--- a/net/nfc/core.c
+++ b/net/nfc/core.c
@@ -279,10 +279,10 @@ static struct nfc_target *nfc_find_targe
int nfc_dep_link_up(struct nfc_dev *dev, int target_index, u8 comm_mode)
{
- int rc = 0;
- u8 *gb;
- size_t gb_len;
struct nfc_target *target;
+ u8 gb[NFC_MAX_GT_LEN];
+ size_t gb_len = 0;
+ int rc = 0;
pr_debug("dev_name=%s comm %d\n", dev_name(&dev->dev), comm_mode);
@@ -301,7 +301,7 @@ int nfc_dep_link_up(struct nfc_dev *dev,
goto error;
}
- gb = nfc_llcp_general_bytes(dev, &gb_len);
+ nfc_get_local_general_bytes(dev, gb, sizeof(gb), &gb_len);
if (gb_len > NFC_MAX_GT_LEN) {
rc = -EINVAL;
goto error;
@@ -644,11 +644,10 @@ int nfc_set_remote_general_bytes(struct
}
EXPORT_SYMBOL(nfc_set_remote_general_bytes);
-u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, size_t *gb_len)
+u8 *nfc_get_local_general_bytes(struct nfc_dev *dev, u8 *out_gb,
+ size_t gb_max_len, size_t *gb_len)
{
- pr_debug("dev_name=%s\n", dev_name(&dev->dev));
-
- return nfc_llcp_general_bytes(dev, gb_len);
+ return nfc_llcp_general_bytes(dev, out_gb, gb_max_len, gb_len);
}
EXPORT_SYMBOL(nfc_get_local_general_bytes);
--- a/net/nfc/digital_dep.c
+++ b/net/nfc/digital_dep.c
@@ -1490,14 +1490,14 @@ static int digital_tg_send_atr_res(struc
struct digital_atr_req *atr_req)
{
struct digital_atr_res *atr_res;
+ u8 gb[NFC_MAX_GT_LEN];
struct sk_buff *skb;
- u8 *gb, payload_bits;
+ u8 payload_bits;
size_t gb_len;
int rc;
- gb = nfc_get_local_general_bytes(ddev->nfc_dev, &gb_len);
- if (!gb)
- gb_len = 0;
+ nfc_get_local_general_bytes(ddev->nfc_dev, gb, sizeof(gb),
+ &gb_len);
skb = digital_skb_alloc(ddev, sizeof(struct digital_atr_res) + gb_len);
if (!skb)
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -653,23 +653,32 @@ out:
return ret;
}
-u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len)
+u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, u8 *out_gb, size_t gb_max_len,
+ size_t *general_bytes_len)
{
struct nfc_llcp_local *local;
+ if (!out_gb || !general_bytes_len)
+ return NULL;
+
local = nfc_llcp_find_local(dev);
- if (local == NULL) {
+ if (!local) {
*general_bytes_len = 0;
return NULL;
}
nfc_llcp_build_gb(local);
- *general_bytes_len = local->gb_len;
+ if (local->gb_len) {
+ *general_bytes_len = min_t(size_t, local->gb_len, gb_max_len);
+ memcpy(out_gb, local->gb, *general_bytes_len);
+ } else {
+ *general_bytes_len = 0;
+ }
nfc_llcp_local_put(local);
- return local->gb;
+ return out_gb;
}
int nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len)
--- a/net/nfc/nci/core.c
+++ b/net/nfc/nci/core.c
@@ -780,15 +780,15 @@ static int nci_set_local_general_bytes(s
{
struct nci_dev *ndev = nfc_get_drvdata(nfc_dev);
struct nci_set_config_param param;
+ u8 gb[NFC_MAX_GT_LEN];
int rc;
- param.val = nfc_get_local_general_bytes(nfc_dev, ¶m.len);
- if ((param.val == NULL) || (param.len == 0))
+ nfc_get_local_general_bytes(nfc_dev, gb, sizeof(gb),
+ ¶m.len);
+ if (param.len == 0)
return 0;
- if (param.len > NFC_MAX_GT_LEN)
- return -EINVAL;
-
+ param.val = gb;
param.id = NCI_PN_ATR_REQ_GEN_BYTES;
rc = nci_request(ndev, nci_set_config_req, ¶m,
--- a/net/nfc/nfc.h
+++ b/net/nfc/nfc.h
@@ -49,7 +49,8 @@ void nfc_llcp_mac_is_up(struct nfc_dev *
int nfc_llcp_register_device(struct nfc_dev *dev);
void nfc_llcp_unregister_device(struct nfc_dev *dev);
int nfc_llcp_set_remote_gb(struct nfc_dev *dev, const u8 *gb, u8 gb_len);
-u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, size_t *general_bytes_len);
+u8 *nfc_llcp_general_bytes(struct nfc_dev *dev, u8 *out_gb, size_t gb_max_len,
+ size_t *general_bytes_len);
int nfc_llcp_data_received(struct nfc_dev *dev, struct sk_buff *skb);
struct nfc_llcp_local *nfc_llcp_find_local(struct nfc_dev *dev);
int nfc_llcp_local_put(struct nfc_llcp_local *local);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 354/457] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 353/457] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 355/457] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
` (113 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Simon Horman,
David Heidelberg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
commit 273f9d667cde649f8de9d72b1303cc2f4b658c50 upstream.
nfc_llcp_recv_hdlc() reads the sequence byte skb->data[2], via
nfc_llcp_ns()/nfc_llcp_nr(), before any length check. The receive path
only guarantees the two-byte LLCP header -- __nfc_llcp_recv() checks it
with pskb_may_pull() and nfc_llcp_recv_agf() admits two-byte inner PDUs
-- so a two-byte I, RR or RNR PDU reads one byte of uninitialised skb
tailroom. The byte becomes N(R)/N(S); a peer can already set those with
a well-formed PDU, so this is acting on uninitialised memory, not new
peer control.
Guard the read with pskb_may_pull(), as commit 95674f506c63 ("nfc: llcp:
reject PDUs shorter than the LLCP header") did for the two-byte header,
so the sequence byte is present and linear before it is read. RR and RNR
PDUs are LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE bytes and an I PDU is
longer, so no valid frame is rejected; a truncated PDU is malformed, so
return without a DM reply.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/AS8P251MB0001789BBF04B72745C7D96BC8BA2@AS8P251MB0001.EURP251.PROD.OUTLOOK.COM
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/nfc/llcp_core.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1101,6 +1101,9 @@ static void nfc_llcp_recv_hdlc(struct nf
struct sock *sk;
u8 dsap, ssap, ptype, ns, nr;
+ if (!pskb_may_pull(skb, LLCP_HEADER_SIZE + LLCP_SEQUENCE_SIZE))
+ return;
+
ptype = nfc_llcp_ptype(skb);
dsap = nfc_llcp_dsap(skb);
ssap = nfc_llcp_ssap(skb);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 355/457] nfc: port100: reject frames whose declared length exceeds the received data
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 354/457] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 356/457] nfc: trf7970a: power down on startup RX gain failure Greg Kroah-Hartman
` (112 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Simon Horman,
David Heidelberg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doruk Tan Ozturk <doruk@0sec.ai>
commit 092c6a605cbd6414ef499834c2e0da69c2c3388e upstream.
port100_recv_response() passes the URB transfer buffer to
port100_rx_frame_is_valid(), which checksums le16_to_cpu(frame->datalen)
bytes of frame->data. datalen is a 16-bit field supplied by the device
and is never checked against the number of bytes actually received
(urb->actual_length), so a device reporting a datalen larger than the
received frame makes port100_data_checksum() read out of bounds past the
transfer buffer.
Reject a response whose declared frame size does not fit the received
length before validating it.
Found by 0sec (https://0sec.ai) using automated source analysis; the
missing bound is evident from source. Compile-tested.
Fixes: 562d4d59b8a1 ("NFC: Sony Port-100 Series driver")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260711123651.32595-1-doruk@0sec.ai
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nfc/port100.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/nfc/port100.c
+++ b/drivers/nfc/port100.c
@@ -636,6 +636,13 @@ static void port100_recv_response(struct
in_frame = dev->in_urb->transfer_buffer;
+ if (urb->actual_length < PORT100_FRAME_HEADER_LEN ||
+ urb->actual_length < port100_rx_frame_size(in_frame)) {
+ nfc_err(&dev->interface->dev, "Received a truncated frame\n");
+ cmd->status = -EIO;
+ goto sched_wq;
+ }
+
if (!port100_rx_frame_is_valid(in_frame)) {
nfc_err(&dev->interface->dev, "Received an invalid frame\n");
cmd->status = -EIO;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 356/457] nfc: trf7970a: power down on startup RX gain failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 355/457] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 357/457] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
` (111 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Paul Geurts,
David Heidelberg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit d2acbde7e67df44efa8f0963462d1192e7694ffc upstream.
trf7970a_startup() powers up the device before applying the optional RX
gain reduction. If the register read or write fails, it returns without
undoing that power-up. Probe's unwind only drops the separate regulator
references acquired by probe, leaving the additional VIN enable from
startup unbalanced. The system resume caller also has no power-down on
this error.
Call trf7970a_power_down() before returning the RX gain error to deassert
the enable GPIOs, release the startup VIN reference and restore the
powered-off state. Runtime PM has not been enabled yet, so the full
shutdown helper is not appropriate here. Preserve the original SPI error.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 5d69351820ea ("NFC: trf7970a: Create device-tree parameter for RX gain reduction")
Cc: stable@vger.kernel.org
Assisted-by: OpenAI:GPT-5.6
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Paul Geurts <paul.geurts@prodrive-technologies.com>
Link: https://patch.msgid.link/20260913042625.31296-1-mhun512@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nfc/trf7970a.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/nfc/trf7970a.c
+++ b/drivers/nfc/trf7970a.c
@@ -1997,8 +1997,10 @@ static int trf7970a_startup(struct trf79
return ret;
ret = trf7970a_update_rx_gain_reduction(trf);
- if (ret)
+ if (ret) {
+ trf7970a_power_down(trf);
return ret;
+ }
pm_runtime_set_active(trf->dev);
pm_runtime_enable(trf->dev);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 357/457] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 356/457] nfc: trf7970a: power down on startup RX gain failure Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 358/457] scsi: ufs: core: Keep internal commands dispatchable during error handling Greg Kroah-Hartman
` (110 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Mike Christie,
Martin K. Petersen (Oracle)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
commit bce07e2f37b5e4a427d36fd6b1c14067b27591db upstream.
The Data-In branch of iscsi_tcp_hdr_dissect() resolves the ITT to a task
and copies the PDU's data segment into that command's scatterlist without
asking whether the command was reading. iscsi_tcp_r2t_rsp() in the same
file does ask, and rejects an R2T for a command that is not DMA_TO_DEVICE.
A target that answers a WRITE command's ITT with a Data-In therefore has
the initiator write target-supplied bytes into the pages that write was
about to send. Those are the caller's own pinned pages for an O_DIRECT
write, and page cache pages for a buffered one.
Observed against a test target that emits one 512-byte Data-In naming a 128
KB write's ITT, after the R2T for that write. With O_DIRECT the caller's
buffer ends up holding 512 bytes of the target's data while pwrite()
returns 131072. Buffered is quieter: pwrite() and fsync() both succeed,
nothing is logged, and reading those blocks back returns the target's bytes
out of the page cache without a command going on the wire.
Check the direction before using the scatterlist, the way the R2T path
already does.
Cc: stable@vger.kernel.org
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Reviewed-by: Mike Christie <michael.christie@oracle.com>
Link: https://patch.msgid.link/20260801133635.1986706-1-yhlee@isslab.korea.ac.kr
Fixes: a081c13e39b5 ("[SCSI] iscsi_tcp: split module into lib and lld")
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/libiscsi_tcp.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/scsi/libiscsi_tcp.c
+++ b/drivers/scsi/libiscsi_tcp.c
@@ -480,6 +480,9 @@ static int iscsi_tcp_data_in(struct iscs
int datasn = be32_to_cpu(rhdr->datasn);
unsigned total_in_length = task->sc->sdb.length;
+ if (task->sc->sc_data_direction != DMA_FROM_DEVICE)
+ return ISCSI_ERR_PROTO;
+
/*
* lib iscsi will update this in the completion handling if there
* is status.
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 358/457] scsi: ufs: core: Keep internal commands dispatchable during error handling
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 357/457] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 359/457] scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction Greg Kroah-Hartman
` (109 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanley Jhu, Bart Van Assche,
Martin K. Petersen (Oracle)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanley Jhu <stanleyjhu@google.com>
commit b52d695d062095327b944acf7daabbc816ab319b upstream.
Commit 08b12cda6c44 ("scsi: ufs: core: Switch to scsi_get_internal_cmd()")
switched UFS internal commands to allocate requests on
hba->host->pseudo_sdev->request_queue, which shares the host tagset with
regular LUNs.
During error recovery, ufshcd_err_handling_prepare() calls
blk_mq_quiesce_tagset(&hba->host->tag_set), marking all queues in the
tagset as quiesced, including pseudo_sdev->request_queue. When
ufshcd_verify_dev_init() subsequently issues internal commands (e.g. NOP
OUT UPIU) via blk_execute_rq(), blk_mq_run_hw_queue() skips running the
quiesced queue, resulting in an unrecoverable circular wait deadlock.
Keep quiescing the tagset and unquiesce the pseudo SCSI device on top of
that, so internal commands stay dispatchable while the logical units remain
quiesced. Re-quiesce the pseudo device before unquiescing the tagset so
that quiesce_depth stays balanced.
Clock scaling and ufshcd_pause_command_processing() are unaffected: they
keep quiescing the whole tagset, internal commands included.
Fixes: 08b12cda6c44 ("scsi: ufs: core: Switch to scsi_get_internal_cmd()")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/6f78c4bd-a70b-402d-abfd-599091b67674@acm.org/
Signed-off-by: Stanley Jhu <stanleyjhu@google.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260912131625.2301486-1-stanleyjhu@google.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ufs/core/ufshcd.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -6748,11 +6748,17 @@ static void ufshcd_err_handling_prepare(
}
/* Wait for ongoing ufshcd_queuecommand() calls to finish. */
blk_mq_quiesce_tagset(&hba->host->tag_set);
+ /*
+ * Internal commands are submitted on the pseudo SCSI device. Let them
+ * through so that the error handler can recover the link.
+ */
+ blk_mq_unquiesce_queue(hba->host->pseudo_sdev->request_queue);
cancel_work_sync(&hba->eeh_work);
}
static void ufshcd_err_handling_unprepare(struct ufs_hba *hba)
{
+ blk_mq_quiesce_queue_nowait(hba->host->pseudo_sdev->request_queue);
blk_mq_unquiesce_tagset(&hba->host->tag_set);
ufshcd_release(hba);
if (ufshcd_is_clkscaling_supported(hba))
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 359/457] scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 358/457] scsi: ufs: core: Keep internal commands dispatchable during error handling Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 360/457] parisc: Increase kernel stack size to 32kb Greg Kroah-Hartman
` (108 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Koichiro Den, Geert Uytterhoeven,
Martin K. Petersen (Oracle)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geert Uytterhoeven <geert+renesas@glider.be>
commit c9ee6511332687ea714ad8ab86a53cb837d86eea upstream.
Since commit e72323f3b09f ("scsi: ufs: core: Configure only active lanes
during link"), the following error is observed on R-Car S4:
ufshcd-renesas e6860000.ufs: Tx lane mismatch [config,reported] [2,1]
ufshcd-renesas e6860000.ufs: link startup failed -67
ufshcd-renesas e6860000.ufs: error -ENOLINK: Initialization failed with error -67
ufshcd-renesas e6860000.ufs: probe with driver ufshcd-renesas failed with error -67
R-Car S4 has one UFS lane per direction, as described in section 152.1 of
its hardware manual. Without lanes-per-direction, the UFS platform driver
defaults to two lanes.
Previously, the core used PA_CONNECTEDRXDATALANES and
PA_CONNECTEDTXDATALANES to configure the link without checking them against
lanes-per-direction, so the missing property did not prevent
initialization.
While fixing the R-Car S4 DTS is the proper solution, doing only that would
still break backwards compatibility with existing DTBs. Hence add a quirk
to let lanes-per-direction default to one on R-Car S4.
Fixes: e72323f3b09f9c89 ("scsi: ufs: core: Configure only active lanes during link")
Reported-by: Koichiro Den <den@valinux.co.jp>
Closes: https://lore.kernel.org/20260911073058.253000-1-den@valinux.co.jp
Cc: stable@vger.kernel.org # 7.2+
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/ae0cc2bd764e6dfffce99db3d8b44a55887c508c.1789394185.git.geert+renesas@glider.be
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ufs/host/ufshcd-pltfrm.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/ufs/host/ufshcd-pltfrm.c
+++ b/drivers/ufs/host/ufshcd-pltfrm.c
@@ -206,7 +206,11 @@ static void ufshcd_init_lanes_per_dir(st
dev_dbg(hba->dev,
"%s: failed to read lanes-per-direction, ret=%d\n",
__func__, ret);
- hba->lanes_per_direction = UFSHCD_DEFAULT_LANES_PER_DIRECTION;
+ /* Old R-Car S4 DTBs lack "lanes-per-direction = <1>" */
+ if (of_device_is_compatible(dev->of_node, "renesas,r8a779f0-ufs"))
+ hba->lanes_per_direction = 1;
+ else
+ hba->lanes_per_direction = UFSHCD_DEFAULT_LANES_PER_DIRECTION;
}
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 360/457] parisc: Increase kernel stack size to 32kb
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 359/457] scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 361/457] parisc: parse early parameters in setup_arch() Greg Kroah-Hartman
` (107 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Helge Deller, John David Anglin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Helge Deller <deller@gmx.de>
commit 94b7e3a7e871ae27d4935c76959dfc61829f27f9 upstream.
For 64-bit Linux kernels, increase the default kernel stack size
(THREAD_SIZE_ORDER) to 32 kB, in order to avoid kernel crashes which have been
triggered recently when building the debian vtk9 package with gcc 17:
stackcheck: kworker/u128:0 will most likely overflow kernel stack (sp:179a83af0, stk bottom-top:179a80000-179a84000)
Kernel panic - not syncing: low stack detected by irq handler - check messages
CPU: 2 UID: 0 PID: 30760 Comm: kworker/u128:0 Tainted: G W 6.18.46-dirty #1 NONE
Tainted: [W]=WARN
Hardware name: 9000/800/rp3440
Workqueue: writeback wb_workfn (flush-259:0)
Backtrace:
[<000000004022f050>] show_stack+0x70/0x90
[<000000004022378c>] dump_stack_lvl+0x124/0x190
[<000000004022382c>] dump_stack+0x34/0x48
[<000000004020212c>] vpanic+0x204/0x648
[<00000000402025c4>] panic+0x54/0x58
[<0000000040232230>] do_cpu_irq_mask+0x3f8/0x440
[<0000000040227070>] intr_return+0x0/0xc
Signed-off-by: Helge Deller <deller@gmx.de>
Reported-by: John David Anglin <dave.anglin@bell.net>
Cc: stable@vger.kernel.org # v6.18+
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/parisc/include/asm/thread_info.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/arch/parisc/include/asm/thread_info.h
+++ b/arch/parisc/include/asm/thread_info.h
@@ -24,7 +24,7 @@ struct thread_info {
/* thread information allocation */
-#ifdef CONFIG_IRQSTACKS
+#if defined(CONFIG_IRQSTACKS) && !defined(CONFIG_64BIT)
#define THREAD_SIZE_ORDER 2 /* PA-RISC requires at least 16k stack */
#else
#define THREAD_SIZE_ORDER 3 /* PA-RISC requires at least 32k stack */
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 361/457] parisc: parse early parameters in setup_arch()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 360/457] parisc: Increase kernel stack size to 32kb Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 362/457] perf/core: Fix NULL pmu_ctx passed to pmu->sched_task() Greg Kroah-Hartman
` (106 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mike Rapoport (Microsoft),
Zhenghui Hao, Helge Deller
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhenghui Hao <zhenghui.hao@qq.com>
commit 289e99e7a263c6fd6a5d07d6d8f2156b70f3a9d5 upstream.
parisc is one of the few architectures that does not call
parse_early_param() from setup_arch(). That was mostly harmless until
commit d49004c5f0c1 ("arch, mm: consolidate initialization of nodes,
zones and memory map") moved the consumer of several hugetlb command
line parameters into mm_core_init_early(), which runs before the
generic parse_early_param() call in start_kernel().
As a result hugepages=, hugepagesz=, default_hugepagesz=, hugetlb_cma=
and hugetlb_free_vmemmap= are recorded after they have already been
consumed and are silently dropped on parisc.
Call parse_early_param() from setup_arch(), after the command line has
been set up and the memory inventory has been taken. jump_label_init()
must be called first because early parameter handlers may enable or
disable static keys. Both functions are safe to call more than once:
the generic calls in start_kernel() remain in place and turn into no-ops.
Suggested-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Fixes: d49004c5f0c1 ("arch, mm: consolidate initialization of nodes, zones and memory map")
Cc: <stable@vger.kernel.org>
Signed-off-by: Zhenghui Hao <zhenghui.hao@qq.com>
Tested-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/parisc/kernel/setup.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/arch/parisc/kernel/setup.c b/arch/parisc/kernel/setup.c
index d3e17a7a8901..4d3015a411d6 100644
--- a/arch/parisc/kernel/setup.c
+++ b/arch/parisc/kernel/setup.c
@@ -132,6 +132,18 @@ void __init setup_arch(char **cmdline_p)
parisc_cache_init();
paging_init();
+ /*
+ * Parse early parameters before mm_core_init_early() runs.
+ * Several early_param() handlers only record data that is consumed
+ * from there - for example hugepages=, hugepagesz=,
+ * default_hugepagesz=, hugetlb_cma= and hugetlb_free_vmemmap= - so
+ * the generic parse_early_param() call in start_kernel() is too late
+ * for them. jump_label_init() must come first, since early param
+ * handlers may enable or disable static keys.
+ */
+ jump_label_init();
+ parse_early_param();
+
#ifdef CONFIG_PA11
dma_ops_init();
#endif
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 362/457] perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 361/457] parisc: parse early parameters in setup_arch() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 363/457] perf/core: Run sched_task() for PMUs with only CPU-wide events Greg Kroah-Hartman
` (105 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Puranjay Mohan,
Peter Zijlstra (Intel), Yifan Wu
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Puranjay Mohan <puranjay@kernel.org>
commit 36bb85cf36cab15fb611cb44b78a5df06e4e69a2 upstream.
perf_pmu_sched_task() returns early when cpuctx->task_ctx is set, and
cpc->task_epc is only non-NULL while a task context is scheduled in on
this CPU. __perf_pmu_sched_task() therefore always passes NULL:
Unable to handle kernel NULL pointer dereference at virtual address 00
pc : armv8pmu_sched_task+0x14/0x50
Call trace:
armv8pmu_sched_task+0x14/0x50 (P)
perf_pmu_sched_task+0xac/0x108
__perf_event_task_sched_out+0x6c/0xe0
Pass &cpc->epc instead, the CPU-wide context for this PMU, which the
function already dereferences a few lines up to find pmu.
armv8pmu_sched_task() is the only in-tree implementation that
dereferences the argument, and it only reads ->pmu, so the oops needs
BRBE, added in v6.17.
Fixes: bd2756811766 ("perf: Rewrite core context handling")
Signed-off-by: Puranjay Mohan <puranjay@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yifan Wu <wuyifan50@huawei.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260810133540.1947118-2-puranjay@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/events/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -3914,7 +3914,7 @@ static void __perf_pmu_sched_task(struct
perf_ctx_lock(cpuctx, cpuctx->task_ctx);
perf_pmu_disable(pmu);
- pmu->sched_task(cpc->task_epc, task, sched_in);
+ pmu->sched_task(&cpc->epc, task, sched_in);
perf_pmu_enable(pmu);
perf_ctx_unlock(cpuctx, cpuctx->task_ctx);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 363/457] perf/core: Run sched_task() for PMUs with only CPU-wide events
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 362/457] perf/core: Fix NULL pmu_ctx passed to pmu->sched_task() Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 364/457] perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification Greg Kroah-Hartman
` (104 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Puranjay Mohan,
Peter Zijlstra (Intel), Yifan Wu
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Puranjay Mohan <puranjay@kernel.org>
commit 3d8d74100954a3b17e5c5e37adfe14e16b1db103 upstream.
perf_pmu_sched_task() returns early when cpuctx->task_ctx is set and
leaves the work to perf_ctx_sched_task_cb(), which only walks
ctx->pmu_ctx_list. A PMU whose events are all CPU-wide is not on that
list, so nothing calls its sched_task(). With
perf record -b -e cycles -a -- ls
armv8pmu_sched_task() is skipped on every switch to a task that has a
perf context but no event on that PMU, and BRBE records leak across the
task boundary. intel_pmu_lbr_add() calls perf_sched_cb_inc()
unconditionally too, so LBR records leak the same way on x86.
Drop the early return and skip only the CPCs that
perf_ctx_sched_task_cb() handles. That one needs a gate of its own to
make the split exact: it tests cpc->sched_cb_usage, which
perf_sched_cb_inc() sets per CPU for every branch stack user, so a task
with an event for that PMU pinned to another CPU would be handled twice.
On x86 the second __intel_pmu_lbr_restore() finds lbr_stack_state ==
LBR_NONE and calls intel_pmu_lbr_reset(), throwing away the callstack
the first one restored.
cpc->task_epc is set only while a task context is scheduled in, and
there is one epc per PMU on ctx->pmu_ctx_list, so the two gates are
inverses.
For the CPCs perf_pmu_sched_task() picks up, the callback now runs
outside the perf_ctx_disable() and perf_ctx_enable() pair in
perf_event_context_sched_in(). __perf_pmu_sched_task() disables the PMU
around the call itself.
Fixes: bd2756811766 ("perf: Rewrite core context handling")
Signed-off-by: Puranjay Mohan <puranjay@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yifan Wu <wuyifan50@huawei.com>
Link: https://patch.msgid.link/20260810133540.1947118-3-puranjay@kernel.org
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/events/core.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -3764,6 +3764,9 @@ static void perf_ctx_sched_task_cb(struc
list_for_each_entry(pmu_ctx, &ctx->pmu_ctx_list, pmu_ctx_entry) {
cpc = this_cpc(pmu_ctx->pmu);
+ if (cpc->task_epc != pmu_ctx)
+ continue;
+
if (cpc->sched_cb_usage && pmu_ctx->pmu->sched_task)
pmu_ctx->pmu->sched_task(pmu_ctx, task, sched_in);
}
@@ -3924,15 +3927,17 @@ static void perf_pmu_sched_task(struct t
struct task_struct *next,
bool sched_in)
{
- struct perf_cpu_context *cpuctx = this_cpu_ptr(&perf_cpu_context);
struct perf_cpu_pmu_context *cpc, *cpc2;
- /* cpuctx->task_ctx will be handled in perf_event_context_sched_in/out */
- if (prev == next || cpuctx->task_ctx)
+ if (prev == next)
return;
- list_for_each_entry_safe(cpc, cpc2, this_cpu_ptr(&sched_cb_list), sched_cb_entry)
+ list_for_each_entry_safe(cpc, cpc2, this_cpu_ptr(&sched_cb_list), sched_cb_entry) {
+ if (cpc->task_epc)
+ continue;
+
__perf_pmu_sched_task(cpc, sched_in ? next : prev, sched_in);
+ }
}
static void perf_event_switch(struct task_struct *task,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 364/457] perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 363/457] perf/core: Run sched_task() for PMUs with only CPU-wide events Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 365/457] perf/x86/intel: Fix GRT " Greg Kroah-Hartman
` (103 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit e961d6db42d1f1b66c81438969a648f08573bd9c upstream.
The same bug exists on Crestmont as on Gracemont:
intel_cmt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_cmt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
This fixes incorrect STORE sample classification.
Fixes: e99fb45436ea ("perf/x86/intel: Update event constraints and cache_extra_regsfor MTL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-3-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -1298,8 +1298,8 @@ struct event_constraint intel_grt_pebs_e
struct event_constraint intel_cmt_pebs_event_constraints[] = {
/* Allow all events as PEBS with no flags */
- INTEL_HYBRID_LAT_CONSTRAINT(0x5d0, 0x3),
- INTEL_HYBRID_LAT_CONSTRAINT(0x6d0, 0xff),
+ INTEL_HYBRID_LDLAT_CONSTRAINT(0x5d0, 0x3),
+ INTEL_HYBRID_STLAT_CONSTRAINT(0x6d0, 0xff),
EVENT_CONSTRAINT_END
};
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 365/457] perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 364/457] perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 366/457] perf/x86/intel: Fix DKT " Greg Kroah-Hartman
` (102 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 89dc568e8c0be60e05e5fcd0b528c79077d7b84b upstream.
On Gracemont, intel_grt_pebs_event_constraints[] applies LAT_CONSTRAINT
constraints to MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set
explicit LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via __grt_latency_data())
uses the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_grt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
Also update __grt_latency_data() to explicitly interpret these flags when
assigning the sampled memory operation direction.
This fixes incorrect STORE sample classification.
Fixes: 39a41278f041 ("perf/x86/intel: Fix PEBS memory access info encoding for ADL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-2-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -455,6 +455,7 @@ static inline void pebs_set_tlb_lock(u64
static u64 __grt_latency_data(struct perf_event *event, u64 status,
u8 dse, bool tlb, bool lock, bool blk)
{
+ union perf_mem_data_src src;
u64 val;
WARN_ON_ONCE(is_hybrid() &&
@@ -470,7 +471,16 @@ static u64 __grt_latency_data(struct per
else
val |= P(BLK, NA);
- return val;
+ src.val = val;
+
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_LDLAT | PERF_X86_EVENT_PEBS_LD_HSW))
+ src.mem_op = P(OP, LOAD);
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_STLAT | PERF_X86_EVENT_PEBS_ST_HSW))
+ src.mem_op = P(OP, STORE);
+
+ return src.val;
}
u64 grt_latency_data(struct perf_event *event, u64 status)
@@ -1291,8 +1301,8 @@ struct event_constraint intel_glm_pebs_e
struct event_constraint intel_grt_pebs_event_constraints[] = {
/* Allow all events as PEBS with no flags */
- INTEL_HYBRID_LAT_CONSTRAINT(0x5d0, 0x3),
- INTEL_HYBRID_LAT_CONSTRAINT(0x6d0, 0x3f),
+ INTEL_HYBRID_LDLAT_CONSTRAINT(0x5d0, 0x3),
+ INTEL_HYBRID_STLAT_CONSTRAINT(0x6d0, 0x3f),
EVENT_CONSTRAINT_END
};
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 366/457] perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 365/457] perf/x86/intel: Fix GRT " Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 367/457] perf/x86/intel: Fix Panther Cove PEBS data-source snoop states Greg Kroah-Hartman
` (101 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 8302c5f475fa5a4ed36a7d32c7b965023d5d7066 upstream.
Same bug exists on Darkmont as on Gracemont:
intel_dkt_pebs_event_constraints[] applies LAT_CONSTRAINT constraints to
MEM_UOPS_RETIRED.{LOAD,STORE}_LATENCY, but does not set explicit
LOAD/STORE flags for those events.
The PEBS latency path (pebs_latency_data(), via cmt_latency_data) uses
the event flags to determine memory operation direction. Without an
explicit STORE flag, samples from MEM_UOPS_RETIRED.STORE_LATENCY can be
misclassified as LOADs.
Set explicit LOAD/STORE flags in intel_dkt_pebs_event_constraints[] for:
- MEM_UOPS_RETIRED.LOAD_LATENCY
- MEM_UOPS_RETIRED.STORE_LATENCY
This fixes incorrect STORE sample classification. Additionally remove
INTEL_HYBRID_LAT_CONSTRAINT() since no one uses it anymore.
Fixes: 65fd435095bb ("perf/x86/intel: Update event constraints for PTL")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.2+
Link: https://patch.msgid.link/20260917015234.981153-4-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 4 ++--
arch/x86/events/perf_event.h | 4 ----
2 files changed, 2 insertions(+), 6 deletions(-)
diff --git a/arch/x86/events/intel/ds.c b/arch/x86/events/intel/ds.c
index fa7e0268b4f2..ea5b331c58d1 100644
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -1315,8 +1315,8 @@ struct event_constraint intel_cmt_pebs_event_constraints[] = {
struct event_constraint intel_dkt_pebs_event_constraints[] = {
/* Allow all events as PEBS with no flags */
- INTEL_HYBRID_LAT_CONSTRAINT(0x5d0, 0xff),
- INTEL_HYBRID_LAT_CONSTRAINT(0x6d0, 0xff),
+ INTEL_HYBRID_LDLAT_CONSTRAINT(0x5d0, 0xff),
+ INTEL_HYBRID_STLAT_CONSTRAINT(0x6d0, 0xff),
EVENT_CONSTRAINT_END
};
diff --git a/arch/x86/events/perf_event.h b/arch/x86/events/perf_event.h
index 4680cba91340..fab9da78a5c7 100644
--- a/arch/x86/events/perf_event.h
+++ b/arch/x86/events/perf_event.h
@@ -517,10 +517,6 @@ struct cpu_hw_events {
__EVENT_CONSTRAINT(c, n, INTEL_ARCH_EVENT_MASK|X86_ALL_EVENT_FLAGS, \
HWEIGHT(n), 0, PERF_X86_EVENT_PEBS_ST)
-#define INTEL_HYBRID_LAT_CONSTRAINT(c, n) \
- __EVENT_CONSTRAINT(c, n, INTEL_ARCH_EVENT_MASK|X86_ALL_EVENT_FLAGS, \
- HWEIGHT(n), 0, PERF_X86_EVENT_PEBS_LAT_HYBRID)
-
#define INTEL_HYBRID_LDLAT_CONSTRAINT(c, n) \
__EVENT_CONSTRAINT(c, n, INTEL_ARCH_EVENT_MASK|X86_ALL_EVENT_FLAGS, \
HWEIGHT(n), 0, PERF_X86_EVENT_PEBS_LAT_HYBRID|PERF_X86_EVENT_PEBS_LD_HSW)
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 367/457] perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 366/457] perf/x86/intel: Fix DKT " Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 368/457] perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints Greg Kroah-Hartman
` (100 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 0ac5d6ca2c3b7d047963b67dccef17902dc6c017 upstream.
For Panther Cove, the snoop states for the data source encodings
"Prefetch Promotion" and "Cross Core Prefetch Promotion" should be
SNOOP_NONE instead of SNOOP_MISS.
Fix the incorrect snooping states for Panther Cove.
Fixes: d2bdcde9626c ("perf/x86/intel: Add support for PEBS memory auxiliary info field in DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-8-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/x86/events/intel/ds.c b/arch/x86/events/intel/ds.c
index 72179bcf6d0d..d0329a7eb8a5 100644
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -277,8 +277,8 @@ static u64 pnc_pebs_l2_hit_data_source[PNC_PEBS_DATA_SOURCE_MAX] = {
0, /* 0x06: Reserved */
OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, HIT), /* 0x07: L2 Hit Snoop HIT */
OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, HITM), /* 0x08: L2 Hit Snoop Hit Modified */
- OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, MISS), /* 0x09: Prefetch Promotion */
- OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, MISS), /* 0x0a: Cross Core Prefetch Promotion */
+ OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, NONE), /* 0x09: Prefetch Promotion */
+ OP_LH | P(LVL, L2) | LEVEL(L2) | P(SNOOP, NONE), /* 0x0a: Cross Core Prefetch Promotion */
0, /* 0x0b: Reserved */
0, /* 0x0c: Reserved */
0, /* 0x0d: Reserved */
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 368/457] perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 367/457] perf/x86/intel: Fix Panther Cove PEBS data-source snoop states Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 369/457] perf/x86/intel: Remove incorrect Panther Cove " Greg Kroah-Hartman
` (99 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 7c944595cc43a664019edc22505b6d6f6039be5e upstream.
On Lion Cove, PEBS data source is valid only for these events:
- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)
The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_lnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.
As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.
Remove those non-data-source memory events from the Lion Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.
Also update lnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.
Fixes: a932aa0e868f ("perf/x86: Add Lunar Lake and Arrow Lake support")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260917015234.981153-6-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 22 +++++-----------------
1 file changed, 5 insertions(+), 17 deletions(-)
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -573,7 +573,11 @@ static u64 lnc_latency_data(struct perf_
val |= P(BLK, NA);
src.val = val;
- if (event->hw.flags & PERF_X86_EVENT_PEBS_ST_HSW)
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_LDLAT | PERF_X86_EVENT_PEBS_LD_HSW))
+ src.mem_op = P(OP, LOAD);
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_STLAT | PERF_X86_EVENT_PEBS_ST_HSW))
src.mem_op = P(OP, STORE);
return src.val;
@@ -1516,24 +1520,8 @@ struct event_constraint intel_lnc_pebs_e
INTEL_FLAGS_UEVENT_CONSTRAINT(0x012a, 0x1), /* OCR.* events */
INTEL_FLAGS_UEVENT_CONSTRAINT(0x012b, 0x1), /* OCR.* events */
- INTEL_FLAGS_UEVENT_CONSTRAINT(0x04a4, 0x1), /* TOPDOWN.BAD_SPEC_SLOTS */
- INTEL_FLAGS_UEVENT_CONSTRAINT(0x08a4, 0x1), /* TOPDOWN.BR_MISPREDICT_SLOTS */
- INTEL_FLAGS_UEVENT_CONSTRAINT(0x10a4, 0x8), /* TOPDOWN.MEMORY_BOUND_SLOTS */
-
INTEL_HYBRID_LDLAT_CONSTRAINT(0x1cd, 0x3fc),
INTEL_HYBRID_STLAT_CONSTRAINT(0x2cd, 0x3),
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x11d0, 0xf), /* MEM_INST_RETIRED.STLB_MISS_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x12d0, 0xf), /* MEM_INST_RETIRED.STLB_MISS_STORES */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x21d0, 0xf), /* MEM_INST_RETIRED.LOCK_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x41d0, 0xf), /* MEM_INST_RETIRED.SPLIT_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x42d0, 0xf), /* MEM_INST_RETIRED.SPLIT_STORES */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x81d0, 0xf), /* MEM_INST_RETIRED.ALL_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x82d0, 0xf), /* MEM_INST_RETIRED.ALL_STORES */
- INTEL_FLAGS_UEVENT_CONSTRAINT(0x87d0, 0x3ff), /* MEM_INST_RETIRED.ANY */
-
- INTEL_FLAGS_EVENT_CONSTRAINT_DATALA_LD_RANGE(0xd1, 0xd4, 0xf),
-
- INTEL_FLAGS_EVENT_CONSTRAINT(0xd0, 0xf),
/*
* Everything else is handled by PMU_FL_PEBS_ALL, because we
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 369/457] perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 368/457] perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 370/457] perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3 Greg Kroah-Hartman
` (98 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 9f93d33ad65af9853974c1ec4ba1f937e8ba1376 upstream.
Same issue exists on Panther Cove, PEBS data source is valid only for
these events:
- MEM_TRANS_RETIRED.LOAD_LATENCY (0x1cd)
- MEM_TRANS_RETIRED.STORE_SAMPLE (0x2cd)
The perfmon database (https://github.com/intel/perfmon) previously
tagged additional memory events such as MEM_INST_RETIRED.STLB_MISS_LOADS
with L1_Hit_Indication, implying PEBS data-source support, which is
incorrect. The database has since been fixed, but
intel_pnc_pebs_event_constraints[] still follows the old definition and
marks those events as data-source capable.
As a result, get_data_src() may decode data-source information for
events that do not provide valid PEBS data-source data and mislead
users.
Remove those non-data-source memory events from the Pather Cove PEBS
constraint table so matching falls back to the regular non-PEBS
constraints, which already provide the same counter constraints.
Also update pnc_latency_data() to decode LOAD/STORE flags explicitly
when setting memory operation direction, for consistency with other
*_latency_data() helpers.
Fixes: d345b6bb8860 ("perf/x86/intel: Add core PMU support for DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-7-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/ds.c | 18 +++++-------------
1 file changed, 5 insertions(+), 13 deletions(-)
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -635,7 +635,11 @@ u64 pnc_latency_data(struct perf_event *
val |= P(BLK, NA);
src.val = val;
- if (event->hw.flags & PERF_X86_EVENT_PEBS_ST_HSW)
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_LDLAT | PERF_X86_EVENT_PEBS_LD_HSW))
+ src.mem_op = P(OP, LOAD);
+ if (event->hw.flags &
+ (PERF_X86_EVENT_PEBS_STLAT | PERF_X86_EVENT_PEBS_ST_HSW))
src.mem_op = P(OP, STORE);
return src.val;
@@ -1537,18 +1541,6 @@ struct event_constraint intel_pnc_pebs_e
INTEL_HYBRID_LDLAT_CONSTRAINT(0x1cd, 0xfc),
INTEL_HYBRID_STLAT_CONSTRAINT(0x2cd, 0x3),
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x11d0, 0xf), /* MEM_INST_RETIRED.STLB_MISS_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x12d0, 0xf), /* MEM_INST_RETIRED.STLB_MISS_STORES */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x21d0, 0xf), /* MEM_INST_RETIRED.LOCK_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x41d0, 0xf), /* MEM_INST_RETIRED.SPLIT_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x42d0, 0xf), /* MEM_INST_RETIRED.SPLIT_STORES */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_LD(0x81d0, 0xf), /* MEM_INST_RETIRED.ALL_LOADS */
- INTEL_FLAGS_UEVENT_CONSTRAINT_DATALA_ST(0x82d0, 0xf), /* MEM_INST_RETIRED.ALL_STORES */
-
- INTEL_FLAGS_EVENT_CONSTRAINT_DATALA_LD_RANGE(0xd1, 0xd4, 0xf),
-
- INTEL_FLAGS_EVENT_CONSTRAINT(0xd0, 0xf),
- INTEL_FLAGS_EVENT_CONSTRAINT(0xd6, 0xf),
/*
* Everything else is handled by PMU_FL_PEBS_ALL, because we
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 370/457] perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 369/457] perf/x86/intel: Remove incorrect Panther Cove " Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 371/457] pinctrl: mpfs-mssio: fix width of unused bank voltage setting Greg Kroah-Hartman
` (97 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dapeng Mi, Peter Zijlstra (Intel),
Ingo Molnar
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
commit 04a7ef3b7aa3af34202285043e3423a2e3983595 upstream.
Per the latest Panther Cove event definitions, the following events are
only supported on PMCs 0-3:
- UOPS_DISPATCHED.INT_EU_ALL (0x1b2)
- UOPS_DISPATCHED.ALU (0x2b2)
Add explicit event constraints for these two events so scheduling does
not place them on unsupported counters.
Fixes: d345b6bb8860 ("perf/x86/intel: Add core PMU support for DMR")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@vger.kernel.org> # v7.0+
Link: https://patch.msgid.link/20260917015234.981153-10-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c
index a7dbbed8f94e..ecf6d6325dfe 100644
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -506,6 +506,8 @@ static struct event_constraint intel_pnc_event_constraints[] = {
INTEL_EVENT_CONSTRAINT(0xce, 0x1),
INTEL_UEVENT_CONSTRAINT(0x01b1, 0x8),
+ INTEL_UEVENT_CONSTRAINT(0x01b2, 0xf),
+ INTEL_UEVENT_CONSTRAINT(0x02b2, 0xf),
INTEL_UEVENT_CONSTRAINT(0x0847, 0xf),
INTEL_UEVENT_CONSTRAINT(0x0446, 0xf),
INTEL_UEVENT_CONSTRAINT(0x0846, 0xf),
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 371/457] pinctrl: mpfs-mssio: fix width of unused bank voltage setting
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 370/457] perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3 Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 372/457] pinctrl: mpfs-mssio: use correct regmap function to set bank voltage Greg Kroah-Hartman
` (96 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Linus Walleij
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Conor Dooley <conor.dooley@microchip.com>
commit e6c5d6c589764a41218cbd81bd7d6c9b906e2cf0 upstream.
The bank voltages are only 4 bits wide, so when a pin was unused the
driver was not correctly interpreting it as being at zero volts, because
the driver's value for unused had two extra set bits.
CC: stable@vger.kernel.org
Fixes: 488d704ed7b7 ("pinctrl: add polarfire soc mssio pinctrl driver")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c b/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
index ea1026a0d22c..dafca82f3e54 100644
--- a/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
+++ b/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
@@ -86,7 +86,7 @@ static struct mpfs_pinctrl_bank_voltage mpfs_pinctrl_bank_voltages[8] = {
{ .uv = 1800000, .val = 4 },
{ .uv = 2500000, .val = 6 },
{ .uv = 3300000, .val = 8 },
- { .uv = 0, .val = 0x3f }, // pin unused
+ { .uv = 0, .val = 0xf }, // pin unused
};
static int mpfs_pinctrl_get_drive_strength_ma(u32 drive_strength)
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 372/457] pinctrl: mpfs-mssio: use correct regmap function to set bank voltage
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 371/457] pinctrl: mpfs-mssio: fix width of unused bank voltage setting Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 373/457] pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions Greg Kroah-Hartman
` (95 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Conor Dooley, Linus Walleij
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Conor Dooley <conor.dooley@microchip.com>
commit 8039b75af5808572ff3656eaed07d348aed3989a upstream.
regmap_assign_bits() is not the correct function to use for an RMW
operation, as it maps to regmap_set_bits() or regmap_clear_bits() and
the former will never zero a bit. Use regmap_update_bits() instead,
which will actually set the bank voltages to what have been requested.
CC: stable@vger.kernel.org
Fixes: 488d704ed7b7 ("pinctrl: add polarfire soc mssio pinctrl driver")
Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c b/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
index dafca82f3e54..92d38e5336de 100644
--- a/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
+++ b/drivers/pinctrl/microchip/pinctrl-mpfs-mssio.c
@@ -156,10 +156,10 @@ static void mpfs_pinctrl_set_bank_voltage(struct mpfs_pinctrl *pctrl, unsigned i
u32 val = FIELD_PREP(MPFS_PINCTRL_BANK_VOLTAGE_MASK, bank_voltage);
if (pin < MPFS_PINCTRL_BANK2_START)
- regmap_assign_bits(pctrl->sysreg_regmap, MPFS_PINCTRL_MSSIO_BANK4_CFG_CR,
+ regmap_update_bits(pctrl->sysreg_regmap, MPFS_PINCTRL_MSSIO_BANK4_CFG_CR,
MPFS_PINCTRL_BANK_VOLTAGE_MASK, val);
else
- regmap_assign_bits(pctrl->sysreg_regmap, MPFS_PINCTRL_MSSIO_BANK2_CFG_CR,
+ regmap_update_bits(pctrl->sysreg_regmap, MPFS_PINCTRL_MSSIO_BANK2_CFG_CR,
MPFS_PINCTRL_BANK_VOLTAGE_MASK, val);
}
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 373/457] pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 372/457] pinctrl: mpfs-mssio: use correct regmap function to set bank voltage Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 374/457] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
` (94 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shawn Guo, Konrad Dybcio,
Bartosz Golaszewski, Linus Walleij
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shawn Guo <shengchao.guo@oss.qualcomm.com>
commit b0be01f133aa36d2fd12d71c916cb8a47826b4ed upstream.
QUP1 SE2 and SE3 pack all four of their lanes pair-wise onto only two
pins each: lanes 0/1 (I2C SDA/SCL) at mux value 2 and lanes 2/3 (UART
TX/RX) at mux value 1, on gpio127/gpio128 and gpio129/gpio130
respectively.
Both mux values were named "qup1_se2" (respectively "qup1_se3"), so the
two distinct lane pairs became indistinguishable. msm_pinmux_set_mux()
stops at the first entry matching the requested function, which means
mux value 1 was always selected and the I2C lanes could never be muxed
out. In practice i2c9 and i2c10 got the UART lanes and did not work,
while uart9 and uart10 happened to be muxed correctly.
Give each lane pair its own function, following the _01/_23 naming
already used for the same hardware arrangement by the shikra, eliza,
hawi and maili TLMM drivers. Both functions still cover the full pin
pair, so a single pinctrl state per protocol remains sufficient.
Drop gpio129/gpio130 from the SE2 group list, since those pins
belong to SE3 and were never reachable through the SE2 function.
Also rename QUP1 SE2/SE3 functions in the binding doc accordingly.
While at it, add missing "gpio", "qup3_se0_mira" and "qup3_se0_mirb"
to the binding function enum to get the list complete.
Fixes: c24dd0826f06 ("pinctrl: qcom: add the TLMM driver for the Nord platforms")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260830030201.135637-1-shengchao.guo@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
.../bindings/pinctrl/qcom,nord-tlmm.yaml | 7 ++--
drivers/pinctrl/qcom/pinctrl-nord.c | 34 +++++++++++++------
2 files changed, 27 insertions(+), 14 deletions(-)
diff --git a/Documentation/devicetree/bindings/pinctrl/qcom,nord-tlmm.yaml b/Documentation/devicetree/bindings/pinctrl/qcom,nord-tlmm.yaml
index 4bb511719f31..56758a85ead8 100644
--- a/Documentation/devicetree/bindings/pinctrl/qcom,nord-tlmm.yaml
+++ b/Documentation/devicetree/bindings/pinctrl/qcom,nord-tlmm.yaml
@@ -67,7 +67,7 @@ $defs:
Specify the alternative function to be configured for the specified
pins.
- enum: [ aoss_cti, atest_char, atest_usb20, atest_usb21,
+ enum: [ gpio, aoss_cti, atest_char, atest_usb20, atest_usb21,
aud_intfc0_clk, aud_intfc0_data, aud_intfc0_ws,
aud_intfc10_clk, aud_intfc10_data, aud_intfc10_ws,
aud_intfc1_clk, aud_intfc1_data, aud_intfc1_ws,
@@ -98,9 +98,10 @@ $defs:
pcie3_clk_req_n, phase_flag, pll_bist_sync, pll_clk_aux,
prng_rosc0, prng_rosc1, pwrbrk_i_n, qdss, qdss_cti, qspi,
qup0_se0, qup0_se1, qup0_se2, qup0_se3, qup0_se4, qup0_se5,
- qup1_se0, qup1_se1, qup1_se3, qup1_se2, qup1_se4, qup1_se5,
+ qup1_se0, qup1_se1, qup1_se2_01, qup1_se2_23, qup1_se3_01,
+ qup1_se3_23, qup1_se4, qup1_se5,
qup1_se6, qup2_se0, qup2_se1, qup2_se2, qup2_se3, qup2_se4,
- qup2_se5, qup2_se6,
+ qup2_se5, qup2_se6, qup3_se0_mira, qup3_se0_mirb,
sailss_ospi, sdc4_clk, sdc4_cmd, sdc4_data, smb_alert,
smb_alert_n, smb_clk, smb_dat, tb_trig_sdc4, tmess_prng0,
tmess_prng1, tsc_timer, tsense_pwm, usb0_hs,
diff --git a/drivers/pinctrl/qcom/pinctrl-nord.c b/drivers/pinctrl/qcom/pinctrl-nord.c
index 7c21306e77ff..7f37f8e819ba 100644
--- a/drivers/pinctrl/qcom/pinctrl-nord.c
+++ b/drivers/pinctrl/qcom/pinctrl-nord.c
@@ -570,8 +570,10 @@ enum nord_functions {
msm_mux_qup0_se5,
msm_mux_qup1_se0,
msm_mux_qup1_se1,
- msm_mux_qup1_se2,
- msm_mux_qup1_se3,
+ msm_mux_qup1_se2_01,
+ msm_mux_qup1_se2_23,
+ msm_mux_qup1_se3_01,
+ msm_mux_qup1_se3_23,
msm_mux_qup1_se4,
msm_mux_qup1_se5,
msm_mux_qup1_se6,
@@ -1152,11 +1154,19 @@ static const char *const qup1_se1_groups[] = {
"gpio123", "gpio124", "gpio125", "gpio126",
};
-static const char *const qup1_se2_groups[] = {
- "gpio127", "gpio128", "gpio129", "gpio130",
+static const char *const qup1_se2_01_groups[] = {
+ "gpio127", "gpio128",
};
-static const char *const qup1_se3_groups[] = {
+static const char *const qup1_se2_23_groups[] = {
+ "gpio127", "gpio128",
+};
+
+static const char *const qup1_se3_01_groups[] = {
+ "gpio129", "gpio130",
+};
+
+static const char *const qup1_se3_23_groups[] = {
"gpio129", "gpio130",
};
@@ -1428,8 +1438,10 @@ static const struct pinfunction nord_functions[] = {
MSM_PIN_FUNCTION(qup0_se5),
MSM_PIN_FUNCTION(qup1_se0),
MSM_PIN_FUNCTION(qup1_se1),
- MSM_PIN_FUNCTION(qup1_se2),
- MSM_PIN_FUNCTION(qup1_se3),
+ MSM_PIN_FUNCTION(qup1_se2_01),
+ MSM_PIN_FUNCTION(qup1_se2_23),
+ MSM_PIN_FUNCTION(qup1_se3_01),
+ MSM_PIN_FUNCTION(qup1_se3_23),
MSM_PIN_FUNCTION(qup1_se4),
MSM_PIN_FUNCTION(qup1_se5),
MSM_PIN_FUNCTION(qup1_se6),
@@ -1633,13 +1645,13 @@ static const struct msm_pingroup nord_groups[] = {
_, _, _, _, _, _, _),
[126] = PINGROUP(126, qup1_se1, qup1_se0, ccu_i2c_scl, mdp1_vsync_out,
_, atest_usb20, ddr_pxi, _, _, _, _),
- [127] = PINGROUP(127, qup1_se2, qup1_se2, _, atest_usb21, ddr_pxi,
+ [127] = PINGROUP(127, qup1_se2_23, qup1_se2_01, _, atest_usb21, ddr_pxi,
_, _, _, _, _, _),
- [128] = PINGROUP(128, qup1_se2, qup1_se2, _, atest_usb20, ddr_pxi,
+ [128] = PINGROUP(128, qup1_se2_23, qup1_se2_01, _, atest_usb20, ddr_pxi,
_, _, _, _, _, _),
- [129] = PINGROUP(129, qup1_se3, qup1_se3, ccu_i2c_sda, mdp1_vsync_out,
+ [129] = PINGROUP(129, qup1_se3_23, qup1_se3_01, ccu_i2c_sda, mdp1_vsync_out,
_, atest_usb21, ddr_pxi, _, _, _, _),
- [130] = PINGROUP(130, qup1_se3, qup1_se3, ccu_i2c_scl, mdp1_vsync_out,
+ [130] = PINGROUP(130, qup1_se3_23, qup1_se3_01, ccu_i2c_scl, mdp1_vsync_out,
_, atest_usb20, ddr_pxi, _, _, _, _),
[131] = PINGROUP(131, qup1_se4, qup1_se6, ccu_i2c_sda, mdp1_vsync_out,
_, atest_usb21, ddr_pxi, _, _, _, _),
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 374/457] pinctrl: single: free the IRQ on domain creation failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 373/457] pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions Greg Kroah-Hartman
@ 2026-09-30 15:27 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 375/457] pinctrl: sunxi: keep a shadow copy of the data register output latches Greg Kroah-Hartman
` (93 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:27 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Linus Walleij
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 1d9bb9c870632adea249cfdec49ac37e6f069164 upstream.
pcs_irq_init_chained_handler() requests a shared IRQ on affected SoCs, but
its domain creation failure path only removes a chained handler. That does
not release the action installed by request_irq(). The probe can continue
without interrupt support while leaving the shared IRQ action registered.
Use pcs_irq_free() to undo the appropriate type of handler registration.
At this point pcs->domain is NULL, so the helper only releases the parent
IRQ handler. Then mark the IRQ invalid, as the other initialization error
paths already do, to prevent another release from a later probe unwind or
remove.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 3e6cee1786a1 ("pinctrl: single: Add support for wake-up interrupts")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/pinctrl-single.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/pinctrl/pinctrl-single.c
+++ b/drivers/pinctrl/pinctrl-single.c
@@ -1628,7 +1628,8 @@ static int pcs_irq_init_chained_handler(
&pcs_irqdomain_ops,
pcs_soc);
if (!pcs->domain) {
- irq_set_chained_handler(pcs_soc->irq, NULL);
+ pcs_irq_free(pcs);
+ pcs_soc->irq = -1;
return -EINVAL;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 375/457] pinctrl: sunxi: keep a shadow copy of the data register output latches
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-09-30 15:27 ` [PATCH 7.2 374/457] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 376/457] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
` (92 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ilya Titov, Linus Walleij
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Titov <ilya.titov@wirenboard.com>
commit a13f7f5d14af9baf34eb12c25962f8d3542b281d upstream.
On Allwinner SoCs, reading a bank's data register returns the pin level,
not the output latch, for pins that are muxed as inputs. Writing a GPIO
therefore corrupts the output latches of all input-muxed pins in the
same bank: the read-modify-write in sunxi_pinctrl_gpio_set() reads back
their pin levels and writes those into their latches.
This breaks emulated open-drain lines (e.g. a bit-banged I2C bus from
i2c-gpio). Such a line is released high by muxing it as input and
letting the pull-up raise it, so any concurrent GPIO write in the same
bank stores 1 into its latch. Driving the line low afterwards is a
non-atomic data-then-mux sequence in sunxi_pinctrl_gpio_direction_output();
if the poisoning write lands between the two steps, the pin actively
drives high (push-pull) instead of low.
Observed in practice as sporadic glitches on a T507 board bit-banging
I2C on port E while other PE GPIOs are toggled. On a scope the failure
is unmistakable: on a clock pulse where SCL should fall to GND, the line
instead steps *above* its idle high level for the whole low phase — the
pad drives a strong push-pull 3.3 V high, higher than the level the
pull-up sustains on the loaded bus — before the next transition recovers
it. The same can hit SDA, corrupting data instead of clocks.
Steps to reproduce on any sunxi board with a bit-banged (i2c-gpio) bus:
# background: toggle any other GPIO of the same bank, e.g. line 21
gpioset -c <chip> --toggle 100us 21=0 &
# foreground: keep the bit-banged bus busy
while :; do i2cdetect -y <bus> 0x50 0x57; done
# watch SCL/SDA with a scope or logic analyzer: sporadic clock-low
# phases driven high (above the pull-up level) instead of low
The bank spinlock cannot help: the racing write is a perfectly valid
whole-register RMW that faithfully writes back what the hardware
returned. There are no set/clear registers on this IP to write a single
bit atomically.
Fix it the same way gpio-mmio handles hardware whose data register read
does not return the output latch: keep a shadow copy of each bank's
latches, base the read-modify-write on the shadow, and only write the
register. The shadow is seeded from the hardware at probe time so pins
left in output mode by the bootloader keep their state. Pins that reach
output mode through the gpiolib paths write their value (and thereby
their shadow bit) before the mux switch in
sunxi_pinctrl_gpio_direction_output(); pins muxed to gpio_out directly
through a pinmux node bypass that path, so sunxi_pmx_set() refreshes
their shadow bit from the latch (readable once the pin is in output
mode) to keep them driving their pre-existing level.
Seeding the shadow reads the PIO registers at probe time, which requires
the bus clock to be enabled. The clock was only requested at the very
end of probe, after devm_pinctrl_register() had already claimed the pin
hogs described in the device tree - which mux pins, and thus access
registers, with the clock still gated. Move the request ahead of both.
Boards whose bootloader leaves the PIO clock running are unaffected,
which is why the pre-existing hog problem has gone unnoticed since
commit 950707c0eb5c ("pinctrl: sunxi: add clock support").
Fixes: df7b34f4c3d2 ("pinctrl: sunxi: Fix gpio_set behaviour")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Titov <ilya.titov@wirenboard.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pinctrl/sunxi/pinctrl-sunxi.c | 76 +++++++++++++++++++++++++++-------
drivers/pinctrl/sunxi/pinctrl-sunxi.h | 7 +++
2 files changed, 68 insertions(+), 15 deletions(-)
--- a/drivers/pinctrl/sunxi/pinctrl-sunxi.c
+++ b/drivers/pinctrl/sunxi/pinctrl-sunxi.c
@@ -843,6 +843,21 @@ static void sunxi_pmx_set(struct pinctrl
writel((readl(pctl->membase + reg) & ~mask) | config << shift,
pctl->membase + reg);
+ /*
+ * A pin muxed to gpio_out directly through a pinmux node bypasses
+ * sunxi_pinctrl_gpio_set() and drives whatever its output latch
+ * holds. Now that the pin is in output mode the data register
+ * reads back the latch, so refresh the shadow to keep such pins
+ * driving their pre-existing level.
+ */
+ if (config == SUN4I_FUNC_OUTPUT) {
+ u32 *shadow = &pctl->dat_shadow[pin / PINS_PER_BANK];
+
+ sunxi_data_reg(pctl, pin, ®, &shift, &mask);
+ *shadow = (*shadow & ~mask) |
+ (readl(pctl->membase + reg) & mask);
+ }
+
raw_spin_unlock_irqrestore(&pctl->lock, flags);
}
@@ -1023,21 +1038,29 @@ static int sunxi_pinctrl_gpio_set(struct
int value)
{
struct sunxi_pinctrl *pctl = gpiochip_get_data(chip);
- u32 reg, shift, mask, val;
+ u32 *shadow = &pctl->dat_shadow[offset / PINS_PER_BANK];
+ u32 reg, shift, mask;
unsigned long flags;
sunxi_data_reg(pctl, offset, ®, &shift, &mask);
raw_spin_lock_irqsave(&pctl->lock, flags);
- val = readl(pctl->membase + reg);
-
+ /*
+ * Reading the data register returns the pin level, not the output
+ * latch, for pins muxed as inputs. A read-modify-write based on
+ * the register would therefore corrupt the latches of input-muxed
+ * pins in the same bank (e.g. an emulated open-drain I2C line
+ * released high), making them drive the wrong level once switched
+ * to output. Base the read-modify-write on a shadow copy of the
+ * latches instead.
+ */
if (value)
- val |= mask;
+ *shadow |= mask;
else
- val &= ~mask;
+ *shadow &= ~mask;
- writel(val, pctl->membase + reg);
+ writel(*shadow, pctl->membase + reg);
raw_spin_unlock_irqrestore(&pctl->lock, flags);
@@ -1578,7 +1601,7 @@ int sunxi_pinctrl_init_with_flags(struct
struct pinctrl_pin_desc *pins;
struct sunxi_pinctrl *pctl;
struct pinmux_ops *pmxops;
- int i, ret, last_pin, pin_idx;
+ int i, ret, last_pin, pin_idx, nbanks;
struct clk *clk;
pctl = devm_kzalloc(&pdev->dev, sizeof(*pctl), GFP_KERNEL);
@@ -1616,6 +1639,37 @@ int sunxi_pinctrl_init_with_flags(struct
if (!pctl->irq_array)
return -ENOMEM;
+ /*
+ * The bus clock has to be enabled before the pinctrl device
+ * registers, as the pin hogs claimed from there access registers.
+ */
+ ret = of_clk_get_parent_count(node);
+ clk = devm_clk_get_enabled(&pdev->dev, ret == 1 ? NULL : "apb");
+ if (IS_ERR(clk))
+ return PTR_ERR(clk);
+
+ /*
+ * Seed the output latch shadow from the hardware so pins the
+ * bootloader left in output mode keep their state; see
+ * sunxi_pinctrl_gpio_set() for why a shadow is needed. This must
+ * happen before the pinctrl device registers, as pin hogs can mux
+ * pins to gpio_out and thereby update the shadow.
+ */
+ last_pin = pctl->desc->pins[pctl->desc->npins - 1].pin.number;
+ nbanks = DIV_ROUND_UP(last_pin + 1 - pctl->desc->pin_base,
+ PINS_PER_BANK);
+ pctl->dat_shadow = devm_kcalloc(&pdev->dev, nbanks,
+ sizeof(*pctl->dat_shadow), GFP_KERNEL);
+ if (!pctl->dat_shadow)
+ return -ENOMEM;
+
+ for (i = 0; i < nbanks; i++) {
+ u32 reg, shift, mask;
+
+ sunxi_data_reg(pctl, i * PINS_PER_BANK, ®, &shift, &mask);
+ pctl->dat_shadow[i] = readl(pctl->membase + reg);
+ }
+
ret = sunxi_pinctrl_build_state(pdev);
if (ret) {
dev_err(&pdev->dev, "dt probe failed: %d\n", ret);
@@ -1671,7 +1725,6 @@ int sunxi_pinctrl_init_with_flags(struct
if (!pctl->chip)
return -ENOMEM;
- last_pin = pctl->desc->pins[pctl->desc->npins - 1].pin.number;
pctl->chip->owner = THIS_MODULE;
pctl->chip->request = gpiochip_generic_request;
pctl->chip->free = gpiochip_generic_free;
@@ -1705,13 +1758,6 @@ int sunxi_pinctrl_init_with_flags(struct
goto gpiochip_error;
}
- ret = of_clk_get_parent_count(node);
- clk = devm_clk_get_enabled(&pdev->dev, ret == 1 ? NULL : "apb");
- if (IS_ERR(clk)) {
- ret = PTR_ERR(clk);
- goto gpiochip_error;
- }
-
pctl->irq = devm_kcalloc(&pdev->dev,
pctl->desc->irq_banks,
sizeof(*pctl->irq),
--- a/drivers/pinctrl/sunxi/pinctrl-sunxi.h
+++ b/drivers/pinctrl/sunxi/pinctrl-sunxi.h
@@ -85,6 +85,7 @@
#define IO_BIAS_MASK GENMASK(3, 0)
#define SUN4I_FUNC_INPUT 0
+#define SUN4I_FUNC_OUTPUT 1
#define SUN4I_FUNC_IRQ 6
#define SUN4I_FUNC_DISABLED_OLD 7
#define SUN4I_FUNC_DISABLED_NEW 15
@@ -177,6 +178,12 @@ struct sunxi_pinctrl {
int *irq;
unsigned *irq_array;
raw_spinlock_t lock;
+ /*
+ * Output latch shadow, one word per bank. Seeded lockless at
+ * probe before the pinctrl device registers, protected by @lock
+ * afterwards.
+ */
+ u32 *dat_shadow;
struct pinctrl_dev *pctl_dev;
unsigned long flags;
u32 bank_mem_size;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 376/457] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 375/457] pinctrl: sunxi: keep a shadow copy of the data register output latches Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 377/457] s390/cmf: Fix virtual vs physical address confusion Greg Kroah-Hartman
` (91 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vineeth Vijayan, Peter Oberparleiter,
Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vineeth Vijayan <vneethv@linux.ibm.com>
commit 5b76268dac968612f7283d59b539036de955b7d9 upstream.
The channel path registry entry associated with a CHPID may be removed
while the subchannel's PMCW still references that CHPID. In this case,
chpid_to_chp() can return NULL, leading to a NULL pointer dereference.
Add the missing NULL check before dereferencing the returned pointer.
Fixes: 199652309a4d ("s390/cio: add helper to query utility strings per given ccw device")
Cc: stable@vger.kernel.org
Signed-off-by: Vineeth Vijayan <vneethv@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/cio/device_ops.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/s390/cio/device_ops.c
+++ b/drivers/s390/cio/device_ops.c
@@ -517,6 +517,8 @@ u8 *ccw_device_get_util_str(struct ccw_d
chp_id_init(&chpid);
chpid.id = sch->schib.pmcw.chpid[chp_idx];
chp = chpid_to_chp(chpid);
+ if (!chp)
+ return NULL;
util_str = kmalloc(sizeof(chp->desc_fmt3.util_str), GFP_KERNEL);
if (!util_str)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 377/457] s390/cmf: Fix virtual vs physical address confusion
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 376/457] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 378/457] s390/pci: Fix leak of struct pci_dev reference in zpci_report_status() Greg Kroah-Hartman
` (90 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Oberparleiter, Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Oberparleiter <oberpar@linux.ibm.com>
commit f4d04425e66af2ecee9d1a49ae0484436f3c2fd1 upstream.
The measurement block address is an absolute address. Define the
associated schib_config and schib fields as dma64_t to enable automatic
detection of incorrect assignments. Also add the missing virt_to_dma64()
translation.
Without this fix, a wrong address will be used by firmware when storing
extended format channel measurement data on kernels built with
CONFIG_RANDOMIZE_IDENTITY_BASE=y.
Fixes: 14edd0d73bfe ("s390/cmf: fix virtual vs physical address confusion")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/cio/cio.h | 5 +++--
drivers/s390/cio/cmf.c | 2 +-
2 files changed, 4 insertions(+), 3 deletions(-)
--- a/drivers/s390/cio/cio.h
+++ b/drivers/s390/cio/cio.h
@@ -7,6 +7,7 @@
#include <linux/mod_devicetable.h>
#include <asm/chpid.h>
#include <asm/cio.h>
+#include <asm/dma-types.h>
#include <asm/fcx.h>
#include <asm/schid.h>
#include <asm/tpi.h>
@@ -49,7 +50,7 @@ struct pmcw {
/* Target SCHIB configuration. */
struct schib_config {
- u64 mba;
+ dma64_t mba;
u32 intparm;
u16 mbi;
u32 isc:3;
@@ -66,7 +67,7 @@ struct schib_config {
struct schib {
struct pmcw pmcw; /* path management control word */
union scsw scsw; /* subchannel status word */
- __u64 mba; /* measurement block address */
+ dma64_t mba; /* measurement block address */
__u8 mda[4]; /* model dependent area */
} __attribute__ ((packed,aligned(4)));
--- a/drivers/s390/cio/cmf.c
+++ b/drivers/s390/cio/cmf.c
@@ -183,7 +183,7 @@ static int set_schib(struct ccw_device *
sch->config.mbfc = mbfc;
/* address can be either a block address or a block index */
if (mbfc)
- sch->config.mba = address;
+ sch->config.mba = address ? virt_to_dma64((void *)address) : 0;
else
sch->config.mbi = address;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 378/457] s390/pci: Fix leak of struct pci_dev reference in zpci_report_status()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 377/457] s390/cmf: Fix virtual vs physical address confusion Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 379/457] s390/pci: Fix missing device lock " Greg Kroah-Hartman
` (89 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Benjamin Block,
Farhan Ali, Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
commit 09b7040a1b79f4f61cdad6d9af972e045bb7c498 upstream.
In zpci_report_status(), a reference to the pdev associated with the
zdev being reported about is acquired using pci_get_slot(). This
reference needs to be dropped with pci_dev_put(), but this call is
missing, thus leaking the reference. On subsequent hot unplug, this will
cause the struct pci_dev to not be released, leaking memory and
preventing reattach.
At the same time, the only existing caller already holds a pdev
reference. So instead of reacquiring and then dropping another reference,
simply pass the existing pdev pointer to zpci_report_status(). This gets
rid of the need for pci_get_slot() as well as the zdev->zbus check.
Cc: stable@vger.kernel.org
Fixes: 4ec6054e7321 ("s390/pci: Report PCI error recovery results via SCLP")
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Benjamin Block <bblock@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/pci/pci_event.c | 2 +-
arch/s390/pci/pci_report.c | 11 +++++------
arch/s390/pci/pci_report.h | 4 +++-
3 files changed, 9 insertions(+), 8 deletions(-)
--- a/arch/s390/pci/pci_event.c
+++ b/arch/s390/pci/pci_event.c
@@ -257,7 +257,7 @@ static pci_ers_result_t zpci_event_attem
pci_uevent_ers(pdev, PCI_ERS_RESULT_RECOVERED);
out_unlock:
device_unlock(&pdev->dev);
- zpci_report_status(zdev, "recovery", status_str);
+ zpci_report_status(zdev, pdev, "recovery", status_str);
return ers_res;
}
--- a/arch/s390/pci/pci_report.c
+++ b/arch/s390/pci/pci_report.c
@@ -89,7 +89,8 @@ static struct debug_view debug_log_view
/**
* zpci_report_status - Report the status of operations on a PCI device
- * @zdev: The PCI device for which to report status
+ * @zdev: The zPCI device for which to report status
+ * @pdev: The PCI device associated with the zdev if any, NULL otherwise
* @operation: A string representing the operation reported
* @status: A string representing the status of the operation
*
@@ -103,15 +104,15 @@ static struct debug_view debug_log_view
*
* Return: 0 on success an error code < 0 otherwise.
*/
-int zpci_report_status(struct zpci_dev *zdev, const char *operation, const char *status)
+int zpci_report_status(struct zpci_dev *zdev, struct pci_dev *pdev,
+ const char *operation, const char *status)
{
struct zpci_report_error *report;
struct pci_driver *driver = NULL;
- struct pci_dev *pdev = NULL;
char *buf, *end;
int ret;
- if (!zdev || !zdev->zbus)
+ if (!zdev)
return -ENODEV;
/* Protected virtualization hosts get nothing from us */
@@ -121,8 +122,6 @@ int zpci_report_status(struct zpci_dev *
report = (void *)get_zeroed_page(GFP_KERNEL);
if (!report)
return -ENOMEM;
- if (zdev->zbus->bus)
- pdev = pci_get_slot(zdev->zbus->bus, zdev->devfn);
if (pdev)
driver = to_pci_driver(pdev->dev.driver);
--- a/arch/s390/pci/pci_report.h
+++ b/arch/s390/pci/pci_report.h
@@ -8,9 +8,11 @@
*/
#ifndef __S390_PCI_REPORT_H
#define __S390_PCI_REPORT_H
+#include <linux/pci.h>
struct zpci_dev;
-int zpci_report_status(struct zpci_dev *zdev, const char *operation, const char *status);
+int zpci_report_status(struct zpci_dev *zdev, struct pci_dev *pdev,
+ const char *operation, const char *status);
#endif /* __S390_PCI_REPORT_H */
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 379/457] s390/pci: Fix missing device lock in zpci_report_status()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 378/457] s390/pci: Fix leak of struct pci_dev reference in zpci_report_status() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 380/457] s390/pci: Report SCLP status on error events when no pdev is associated Greg Kroah-Hartman
` (88 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Benjamin Block,
Farhan Ali, Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
commit 0261aef4b15efcee2860ab857e5cb05e9bfa47b0 upstream.
When pdev is non-NULL, zpci_report_status() accesses the device's driver.
To get a consistent state matching the recovery, the device lock needs to
be held. Do so by expanding the existing device lock critical section.
The lock only needs to be held when the pdev is non-NULL, so extract
the pdev-specific reporting into a helper function which also adds a
lockdep assertion to detect calls without the device lock held.
Cc: stable@vger.kernel.org
Fixes: 4ec6054e7321 ("s390/pci: Report PCI error recovery results via SCLP")
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Benjamin Block <bblock@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/pci/pci_event.c | 2 +-
arch/s390/pci/pci_report.c | 21 +++++++++++++++------
2 files changed, 16 insertions(+), 7 deletions(-)
--- a/arch/s390/pci/pci_event.c
+++ b/arch/s390/pci/pci_event.c
@@ -256,8 +256,8 @@ static pci_ers_result_t zpci_event_attem
driver->err_handler->resume(pdev);
pci_uevent_ers(pdev, PCI_ERS_RESULT_RECOVERED);
out_unlock:
- device_unlock(&pdev->dev);
zpci_report_status(zdev, pdev, "recovery", status_str);
+ device_unlock(&pdev->dev);
return ers_res;
}
--- a/arch/s390/pci/pci_report.c
+++ b/arch/s390/pci/pci_report.c
@@ -87,6 +87,19 @@ static struct debug_view debug_log_view
NULL
};
+static ssize_t zpci_report_pdev(struct pci_dev *pdev, char *buf, size_t size)
+{
+ struct pci_driver *driver;
+ const char *start = buf;
+ char *end = buf + size;
+
+ device_lock_assert(&pdev->dev);
+ buf += scnprintf(buf, end - buf, "state: %s\n", zpci_state_str(pdev->error_state));
+ driver = to_pci_driver(pdev->dev.driver);
+ buf += scnprintf(buf, end - buf, "driver: %s\n", (driver) ? driver->name : "n/a");
+ return buf - start;
+}
+
/**
* zpci_report_status - Report the status of operations on a PCI device
* @zdev: The zPCI device for which to report status
@@ -108,7 +121,6 @@ int zpci_report_status(struct zpci_dev *
const char *operation, const char *status)
{
struct zpci_report_error *report;
- struct pci_driver *driver = NULL;
char *buf, *end;
int ret;
@@ -122,16 +134,13 @@ int zpci_report_status(struct zpci_dev *
report = (void *)get_zeroed_page(GFP_KERNEL);
if (!report)
return -ENOMEM;
- if (pdev)
- driver = to_pci_driver(pdev->dev.driver);
buf = report->data.log_data;
end = report->data.log_data + ZPCI_REPORT_DATA_SIZE;
buf += scnprintf(buf, end - buf, "report: %s\n", operation);
buf += scnprintf(buf, end - buf, "status: %s\n", status);
- buf += scnprintf(buf, end - buf, "state: %s\n",
- (pdev) ? zpci_state_str(pdev->error_state) : "n/a");
- buf += scnprintf(buf, end - buf, "driver: %s\n", (driver) ? driver->name : "n/a");
+ if (pdev)
+ buf += zpci_report_pdev(pdev, buf, end - buf);
ret = debug_dump(pci_debug_msg_id, &debug_log_view, buf, end - buf, true);
if (ret < 0)
pr_err("Reading PCI debug messages failed with code %d\n", ret);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 380/457] s390/pci: Report SCLP status on error events when no pdev is associated
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 379/457] s390/pci: Fix missing device lock " Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 381/457] s390/pci: Dont report recovery success on skipped recovery Greg Kroah-Hartman
` (87 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Benjamin Block,
Farhan Ali, Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
commit a1120bea9bc8ea9d9ab2f9904a63b9a228bf2ffc upstream.
With commit 4ec6054e7321 ("s390/pci: Report PCI error recovery results
via SCLP") SCLP reports are generated when recovery is performed in
response to an error event. If such an error event arrives but no pdev
is currently associated with the zdev, e.g. because it was removed or
not yet probed, no report is generated. Fix this by generating a report
specific to an error event for a zdev without an associated pdev.
Cc: stable@vger.kernel.org
Fixes: 4ec6054e7321 ("s390/pci: Report PCI error recovery results via SCLP")
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Benjamin Block <bblock@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/pci/pci_event.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/arch/s390/pci/pci_event.c
+++ b/arch/s390/pci/pci_event.c
@@ -320,8 +320,10 @@ static void __zpci_event_error(struct zp
pr_err("%s: Event 0x%x reports an error for PCI function 0x%x\n",
pdev ? pci_name(pdev) : "n/a", ccdf->pec, ccdf->fid);
- if (!pdev)
+ if (!pdev) {
+ zpci_report_status(zdev, NULL, "error event", "no pdev bound");
goto no_pdev;
+ }
switch (ccdf->pec) {
case 0x002a: /* Error event concerns FMB */
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 381/457] s390/pci: Dont report recovery success on skipped recovery
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 380/457] s390/pci: Report SCLP status on error events when no pdev is associated Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 382/457] s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config Greg Kroah-Hartman
` (86 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Benjamin Block,
Farhan Ali, Heiko Carstens
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Schnelle <schnelle@linux.ibm.com>
commit 3a43be7a1fd06a35cf9e621b88283b3b6e7d281c upstream.
When a PCI device is already in the permanent failure state, recovery is
skipped, but the SCLP recovery report still shows success. Fix this by
changing the status string to explicitly state that recovery was skipped
due to permanent failure.
Cc: stable@vger.kernel.org
Fixes: 4ec6054e7321 ("s390/pci: Report PCI error recovery results via SCLP")
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Benjamin Block <bblock@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/pci/pci_event.c | 1 +
1 file changed, 1 insertion(+)
--- a/arch/s390/pci/pci_event.c
+++ b/arch/s390/pci/pci_event.c
@@ -190,6 +190,7 @@ static pci_ers_result_t zpci_event_attem
device_lock(&pdev->dev);
if (pdev->error_state == pci_channel_io_perm_failure) {
ers_res = PCI_ERS_RESULT_DISCONNECT;
+ status_str = "skipped (permanent failure)";
goto out_unlock;
}
pdev->error_state = pci_channel_io_frozen;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 382/457] s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 381/457] s390/pci: Dont report recovery success on skipped recovery Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 383/457] KVM: Ensure memory attributes xarray nodes are accounted to the callers memcg Greg Kroah-Hartman
` (85 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
Halil Pasic, Claudio Imbrenda
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anthony Krowiak <akrowiak@linux.ibm.com>
commit 65e05ec252a9b79e75930d3c4dd42d8877db04c5 upstream.
Three related problems exist in the handling of KVM interrupt and page
resources when a queue is removed from the host's AP configuration
while assigned to a mediated device (mdev).
Problem 1:
~~~~~~~~~
AP_RESPONSE_Q_NOT_AVAIL not handled in vfio_ap_mdev_reset_queue()
When the AP bus removes a queue device whose adapter or domain has
been removed from the host's AP configuration,
vfio_ap_mdev_remove_queue() is called. If the queue is still in the
host's AP configuration at that point, it calls
vfio_ap_mdev_reset_queue(), which issues a PQAP(ZAPQ). Since the
adapter is already gone from the host configuration, ap_zapq() returns
AP_RESPONSE_Q_NOT_AVAIL (0x01). This response code is not handled in
vfio_ap_mdev_reset_queue()'s switch statement and falls through to
the default case, which issues a WARN but does not call
vfio_ap_free_aqic_resources(). As a result, if IRQ handling was
enabled for the queue by the guest, the KVM GISC registration and
the pinned guest page holding the notification indicator byte (NIB)
are both leaked.
This is fixed by adding AP_RESPONSE_Q_NOT_AVAIL to the same case as
AP_RESPONSE_DECONFIGURED and AP_RESPONSE_CHECKSTOPPED in
vfio_ap_mdev_reset_queue(). Like those response codes, Q_NOT_AVAIL
indicates the queue is not operational and no further reset attempts
are possible; the correct action is to free the IRQ resources
immediately.
Problem 2:
~~~~~~~~~
AP_RESPONSE_Q_NOT_AVAIL not handled in apq_status_check()
In vfio_ap_mdev_reset_queue(), there are four cases that indicate a queue
reset has not yet completed, in which case apq_reset_check() is queued to
a work queue to verify completion of the reset operation. This function
uses the PQAP(TAPQ) function to get the queue's status and calls
apq_status_check() to verify whether the reset has completed, failed or
needs to be executed again. As described in Problem #1 above,
apq_reset_check() does not specifically check for AP_RESPONSE_Q_NOT_AVAIL,
thereby potentially leaking KVM GISC registration and the pinned guest page
holding the NIB.
This is fixed by adding a case statement for AP_RESPONSE_Q_NOT_AVAIL to
apq_status_check() and returning -ENODEV for that case. The caller,
apq_reset_check() will then check for this return code and call
vfio_ap_free_aqic_resources() to prevent the leak.
Problem 3:
~~~~~~~~~
vfio_ap_free_aqic_resources() leaks saved_isc when kvm is NULL
vfio_ap_free_aqic_resources() guards the call to
kvm_s390_gisc_unregister() with:
if (q->saved_isc != VFIO_AP_ISC_INVALID &&
!WARN_ON(!(q->matrix_mdev && q->matrix_mdev->kvm)))
If matrix_mdev->kvm is NULL -- which can happen when
vfio_ap_mdev_unset_kvm() has already run and cleared kvm before a
subsequent cleanup path reaches this function -- the WARN_ON fires
and the entire block is skipped. This leaves q->saved_isc set to a
non-invalid value, creating a potential double-free on any subsequent
call to this function.
When kvm is NULL the KVM guest is already torn down, so
kvm_s390_gisc_unregister() need not and cannot be called; however,
q->saved_isc must always be cleared. Fix this by separating the
kvm_s390_gisc_unregister() call from the q->saved_isc reset. The
WARN_ON now guards only the genuinely impossible case of matrix_mdev
being NULL. A NULL kvm is handled gracefully by skipping only the
unregister call, and q->saved_isc = VFIO_AP_ISC_INVALID is set
unconditionally whenever saved_isc was not already invalid.
Additionally, add an else clause to the host-config check in
vfio_ap_mdev_remove_queue() to call vfio_ap_free_aqic_resources()
directly when the queue is not in the host's AP configuration. This
serves as a backstop: when the AP bus fires the driver .remove
callback after an adapter is removed from the host config, the queue
is by definition no longer addressable, so vfio_ap_mdev_reset_queue()
would always return Q_NOT_AVAIL. The else clause handles this case
directly without the unnecessary ap_zapq() call, and ensures cleanup
occurs even if kvm has already been set to NULL by a prior call to
vfio_ap_mdev_unset_kvm().
Fixes: b9bd10c43456d ("s390/vfio-ap: do not reset queue removed from host config")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Acked-by: Halil Pasic <pasic@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260818193349.1877940-2-akrowiak@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/s390/crypto/vfio_ap_ops.c | 18 ++++++++++++++----
1 file changed, 14 insertions(+), 4 deletions(-)
--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -277,9 +277,9 @@ static void vfio_ap_free_aqic_resources(
{
if (!q)
return;
- if (q->saved_isc != VFIO_AP_ISC_INVALID &&
- !WARN_ON(!(q->matrix_mdev && q->matrix_mdev->kvm))) {
- kvm_s390_gisc_unregister(q->matrix_mdev->kvm, q->saved_isc);
+ if (q->saved_isc != VFIO_AP_ISC_INVALID) {
+ if (!WARN_ON(!q->matrix_mdev) && q->matrix_mdev->kvm)
+ kvm_s390_gisc_unregister(q->matrix_mdev->kvm, q->saved_isc);
q->saved_isc = VFIO_AP_ISC_INVALID;
}
if (q->saved_iova && !WARN_ON(!q->matrix_mdev)) {
@@ -1935,6 +1935,8 @@ static int apq_status_check(int apqn, st
* a value indicating a reset needs to be performed again.
*/
return -EAGAIN;
+ case AP_RESPONSE_Q_NOT_AVAIL:
+ return -ENODEV;
default:
WARN(true,
"failed to verify reset of queue %02x.%04x: TAPQ rc=%u\n",
@@ -1961,6 +1963,10 @@ static void apq_reset_check(struct work_
ret = apq_status_check(q->apqn, &status);
if (ret == -EIO)
return;
+ if (ret == -ENODEV) {
+ vfio_ap_free_aqic_resources(q);
+ return;
+ }
if (ret == -EBUSY) {
pr_notice_ratelimited(WAIT_MSG, elapsed,
AP_QID_CARD(q->apqn),
@@ -2004,6 +2010,7 @@ static void vfio_ap_mdev_reset_queue(str
break;
case AP_RESPONSE_DECONFIGURED:
case AP_RESPONSE_CHECKSTOPPED:
+ case AP_RESPONSE_Q_NOT_AVAIL:
vfio_ap_free_aqic_resources(q);
break;
default:
@@ -2528,12 +2535,15 @@ void vfio_ap_mdev_remove_queue(struct ap
/*
* If the queue is not in the host's AP configuration, then resetting
* it will fail with response code 01, (APQN not valid); so, let's make
- * sure it is in the host's config.
+ * sure it is in the host's config. If it is not, free the KVM GISC
+ * resources.
*/
if (test_bit_inv(apid, (unsigned long *)matrix_dev->info.apm) &&
test_bit_inv(apqi, (unsigned long *)matrix_dev->info.aqm)) {
vfio_ap_mdev_reset_queue(q);
flush_work(&q->reset_work);
+ } else {
+ vfio_ap_free_aqic_resources(q);
}
done:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 383/457] KVM: Ensure memory attributes xarray nodes are accounted to the callers memcg
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 382/457] s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 384/457] KVM: Dont treat reserved xarray entries as having memory attributes Greg Kroah-Hartman
` (84 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, David Ballesteros,
Sean Christopherson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Ballesteros <davimaba.v@proton.me>
commit 382e5d514b6f35bdda2ab9044b4eed23d2ec4254 upstream.
Explicitly instantiate the memory attributes xarray with XA_FLAGS_ACCOUNT
to ensure that all allocations are accounted to the memcg. Frustratingly,
memory allocations done in the "fastpath" do not honor the passed in gfp,
even for an explicit xa_reserve(). Only the rare, slow path __xas_nomem()
honors the original gfp. E.g.
xa_reserve(..., GFP_KERNEL_ACCOUNT)
|
-> ...
|
-> __xa_cmpxchg_raw()
|
-> xas_store() <== does not take @gfp
|
-> xas_create()
|
-> xas_alloc()
The bug was confirmed by observing that a process in a cgroup limited to
256 MiB grew radix_tree_node slab by ~512 MiB while its memory.current
stayed near 0.
Fixes: 5a475554db1e ("KVM: Introduce per-page memory attributes")
Cc: stable@vger.kernel.org
Assisted-by: Claude-Code:claude-opus-5
Signed-off-by: David Ballesteros <davimaba.v@proton.me>
Link: https://patch.msgid.link/20260915175335.138547-4-davimaba.v@proton.me
[sean: rewrite changelog, tag for stable]
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
virt/kvm/kvm_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/virt/kvm/kvm_main.c
+++ b/virt/kvm/kvm_main.c
@@ -1116,7 +1116,7 @@ static struct kvm *kvm_create_vm(unsigne
rcuwait_init(&kvm->mn_memslots_update_rcuwait);
xa_init(&kvm->vcpu_array);
#ifdef CONFIG_KVM_GENERIC_MEMORY_ATTRIBUTES
- xa_init(&kvm->mem_attr_array);
+ xa_init_flags(&kvm->mem_attr_array, XA_FLAGS_ACCOUNT);
#endif
INIT_LIST_HEAD(&kvm->gpc_list);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 384/457] KVM: Dont treat reserved xarray entries as having memory attributes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 383/457] KVM: Ensure memory attributes xarray nodes are accounted to the callers memcg Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 385/457] KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV Greg Kroah-Hartman
` (83 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Christopherson,
David Ballesteros, Zeng Chi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zeng Chi <zengchi@kylinos.cn>
commit 277d3623d99a4fc2623bfb7d191b649ca380605d upstream.
kvm_vm_set_mem_attributes() reserves an xarray entry for every gfn in
the range before storing the new attributes, so that the store loop
can't fail partway through. If one of the reservations fails, e.g. with
-ENOMEM, the entries that were already reserved are left in the array.
That is harmless as far as xa_reserve() is concerned, as the reserved
entries read back as NULL via xa_load(), but it confuses the "does this
range have no attributes at all" check:
if (!attrs)
return !xas_find(&xas, end - 1);
A reserved entry is XA_ZERO_ENTRY, not NULL, and xas_find() returns it
as present. So a leftover reservation makes KVM report that a fully
shared range has attributes even though kvm_get_memory_attributes()
returns none for every gfn in the range. On x86, the next time
mixed-attribute tracking is recomputed for the range (memslot creation,
or a later attribute change that straddles the 2MiB page),
hugepage_has_attrs() treats a fully shared 2MiB range as mixed and
refuses to map it with a hugepage, until userspace happens to set
attributes on the range again.
Drop the shortcut and handle the !attrs case in the per-index loop,
using xas_next_entry() to find the next non-NULL entry. xas_next_entry()
is essentially an optimized xas_find(), so the effective change is that
the !attrs lookup now goes through xas_retry() like the attrs != 0 case,
i.e. reserved entries are skipped and retry entries restart the walk.
Don't check the index when no entry is found, as the xarray leaves the
xas index in a bogus state in that case; no entry simply means the rest
of the range has no attributes.
KVM never stores a non-NULL entry with a value of zero (clearing stores
NULL), but such an entry would be returned by xas_next_entry() and trip
the index check, so WARN if one is ever seen.
Fixes: 5a475554db1e ("KVM: Introduce per-page memory attributes")
Cc: stable@vger.kernel.org
Suggested-by: Sean Christopherson <seanjc@google.com>
Cc: David Ballesteros <davimaba.v@proton.me>
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
Link: https://patch.msgid.link/20260921102442.1232375-1-zeng_chi911@163.com
[sean: expand comment to elaborate on xarray APIs, split optimization out]
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
virt/kvm/kvm_main.c | 28 +++++++++++++++++++++++++---
1 file changed, 25 insertions(+), 3 deletions(-)
--- a/virt/kvm/kvm_main.c
+++ b/virt/kvm/kvm_main.c
@@ -2446,14 +2446,36 @@ bool kvm_range_has_memory_attributes(str
return (kvm_get_memory_attributes(kvm, start) & mask) == attrs;
guard(rcu)();
- if (!attrs)
- return !xas_find(&xas, end - 1);
+ /*
+ * Lookup the entry for each index instead of iterating over the xarray
+ * as KVM deletes/nullifies entries to represent "no attributes", and
+ * the xas index is effectively invalid when no entry is found. I.e.
+ * matching non-zero attributes for *every* entry effectively requires
+ * a manually lookup for each index.
+ *
+ * Skip pre-allocated, reserved entries, or restart the lookup if the
+ * xarray was concurrently modified, via xas_retry() ("retry" means the
+ * entry holds an internal xarray value, i.e. is either invalid or NULL
+ * from the caller's perspective).
+ *
+ * Use xas_next() when looking for non-zero attributes to optimize for
+ * the case where the start of the range (or the entire range) doesn't
+ * have any attributes, as xas_next() returns literally the next entry,
+ * whereas xas_next_entry() returns the next non-NULL entry (bounded by
+ * a maximum index).
+ */
for (index = start; index < end; index++) {
do {
- entry = xas_next(&xas);
+ entry = attrs ? xas_next(&xas) :
+ xas_next_entry(&xas, end - 1);
} while (xas_retry(&xas, entry));
+ if (!entry)
+ return !attrs;
+
+ WARN_ON_ONCE(!xa_to_value(entry));
+
if (xas.xa_index != index ||
(xa_to_value(entry) & mask) != attrs)
return false;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 385/457] KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 384/457] KVM: Dont treat reserved xarray entries as having memory attributes Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 386/457] KVM: SEV: Do cache maintenance on the source VM during intra-host migration Greg Kroah-Hartman
` (82 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefan Teodorescu,
Sean Christopherson, Paolo Bonzini
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
commit 12c1f6e03f944e399bd2c88441dca5dc702b95a5 upstream.
Unconditionally free SEV's "have run CPUs" cpumask in the VM destroy path,
i.e. even for what appear to be non-SEV VMs, as an SEV VM becomes a non-SEV
VM if its state is intra-host migrated. Alternatively, the mask could be
freed in sev_migrate_from() when "converting" the source VM, but that gets
annoying because ideally KVM would nullify the mask to guard against UAF,
and nullifying the mask would need be conditioned on CPUMASK_OFFSTACK=y.
Freeing the mask during sev_migrate_from() is also not robust against other
KVM bugs, though that's kind of a moot point since any such bugs would show
up even if sev->active is never set. I.e. KVM must get that side of things
correct. But, that's not a great reason to add more code just to make
things marginally less robust.
Fixes: 6f38f8c57464 ("KVM: SVM: Flush cache only on CPUs running SEV guest")
Cc: stable@vger.kernel.org
Reported-by: Stefan Teodorescu <fane@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-ID: <20260923163721.1584779-2-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/svm/sev.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -2981,13 +2981,17 @@ void sev_vm_destroy(struct kvm *kvm)
struct list_head *head = &sev->regions_list;
struct list_head *pos, *q;
+ /*
+ * Free the mask even if the VM is not *currently* an SEV VM, as it may
+ * have been an SEV VM prior to intra-host migration.
+ */
+ free_cpumask_var(sev->have_run_cpus);
+
if (!sev_guest(kvm))
return;
WARN_ON(!list_empty(&sev->mirror_vms));
- free_cpumask_var(sev->have_run_cpus);
-
/*
* If this is a mirror VM, remove it from the owner's list of a mirrors
* and skip ASID cleanup (the ASID is tied to the lifetime of the owner).
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 386/457] KVM: SEV: Do cache maintenance on the source VM during intra-host migration
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 385/457] KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 387/457] KVM: arm64: Dont WARN on an unknown VM ioctl in protected mode Greg Kroah-Hartman
` (81 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stefan Teodorescu,
Sean Christopherson, Paolo Bonzini
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
commit 93de2a6a4b91b72607136dd656edf03fb399d27f upstream.
Manually perform cache maintenance on the source VM during intra-host
migration to ensure no stale data is left in CPU caches after the VM is
destroyed. Because the source VM is "converted" to a non-SEV VM, KVM's
memory reclaim flows won't trigger cache maintenance, e.g. when all guest
memory is reclaimed in response to detaching from the mmu_notifier.
Note, relying on the destination VM to do cache maintenance isn't an option
as KVM doesn't require identical guest memory configurations, i.e. the
source VM may have access to memory that the destination VM does not.
Enforcing equivalent memory configurations is infeasible, as it would
require a *deep* comparison of memslots, e.g. to verify that not only are
the memslot identical, but what the memslots point at is also identical.
Fixes: b56639318bb2 ("KVM: SEV: Add support for SEV intra host migration")
Cc: stable@vger.kernel.org
Reported-by: Stefan Teodorescu <fane@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-ID: <20260923163721.1584779-3-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/svm/sev.c | 10 ++++++++++
1 file changed, 10 insertions(+)
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -2048,6 +2048,12 @@ static void sev_migrate_from(struct kvm
src->pages_locked = 0;
src->es_active = false;
+ /*
+ * Do cache maintenance on the source VM as it is no longer an SEV VM,
+ * i.e. memory reclaim flows won't trigger cache maintenance on the VM.
+ */
+ sev_writeback_caches(src_kvm);
+
list_cut_before(&dst->regions_list, &src->regions_list, &src->regions_list);
mutex_lock(&sev_mirror_lock);
@@ -2187,6 +2193,10 @@ int sev_vm_move_enc_context_from(struct
* the set of CPUs from the source. If a CPU was used to run a vCPU in
* the source VM but is never used for the destination VM, then the CPU
* can only have cached memory that was accessible to the source VM.
+ * Furthermore, KVM *must* perform cache maintenance on the source VM,
+ * as the source VM may have access to memory that the destination VM
+ * does not, i.e. KVM could skip flushes if memory is reclaimed from
+ * the old VM but not the new VM.
*/
if (!zalloc_cpumask_var(&dst_sev->have_run_cpus, GFP_KERNEL_ACCOUNT)) {
ret = -ENOMEM;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 387/457] KVM: arm64: Dont WARN on an unknown VM ioctl in protected mode
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 386/457] KVM: SEV: Do cache maintenance on the source VM during intra-host migration Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 388/457] KVM: arm64: Fix AArch32 DBGBXVR<n> handling Greg Kroah-Hartman
` (80 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Suzuki K Poulose,
Oliver Upton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
commit 49d9d295d69d07e850cae35933ba8519e2915f26 upstream.
kvm_pkvm_ioctl_allowed() WARNs when kvm_get_cap_for_kvm_ioctl() doesn't
find the ioctl number in vm_ioctl_caps[], and kvm_arch_vm_ioctl() calls
it for every number the generic code doesn't handle, so
ioctl(vm_fd, 0xdeadbeef) from userspace taints a pKVM host and panics it
under panic_on_warn. The lookup is fed userspace input: return false,
and userspace gets the -EINVAL kvm_arch_vm_ioctl() returns for that
number on a host without pKVM.
Fixes: b12b3b04f6ba0 ("KVM: arm64: Check whether a VM IOCTL is allowed in pKVM")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://patch.msgid.link/20260914093838.1082637-1-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/kvm_pkvm.h | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/arch/arm64/include/asm/kvm_pkvm.h
+++ b/arch/arm64/include/asm/kvm_pkvm.h
@@ -62,8 +62,7 @@ static inline bool kvm_pkvm_ioctl_allowe
int r;
r = kvm_get_cap_for_kvm_ioctl(ioctl, &ext);
-
- if (WARN_ON_ONCE(r < 0))
+ if (r < 0)
return false;
return kvm_pkvm_ext_allowed(kvm, ext);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 388/457] KVM: arm64: Fix AArch32 DBGBXVR<n> handling
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 387/457] KVM: arm64: Dont WARN on an unknown VM ioctl in protected mode Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 389/457] KVM: arm64: Fix spurious warning for benign stage 2 teardown race Greg Kroah-Hartman
` (79 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Marc Zyngier,
Oliver Upton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 6b1bca1b1ab77f60a62087337bfe6e2f0efb9e6d upstream.
The consolidation of the breakpoint and watchpoint register accessors
switched DBGBXVR<n> from trap_bvr() to trap_dbg_wb_reg(). The latter
selects backing storage with demux_wb_reg(), which only handles Op2 values
4 through 7. Since DBGBXVR<n> uses Op2 1, an AArch32 guest access hits
KVM_BUG_ON() and marks the VM dead.
DBGBXVR<n> aliases DBGBVR<n>_EL1[63:32], and its AA32(HI) descriptor
already selects the upper half. Map Op2 1 to dbg_bvr[] alongside Op2 4,
restoring the pre-regression behavior.
Fixes: 3ce9f3357e9e ("KVM: arm64: Fold DBGxVR/DBGxCR accessors into common set")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260810005616.13227-1-kmehltretter@gmail.com
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/sys_regs.c | 1 +
1 file changed, 1 insertion(+)
--- a/arch/arm64/kvm/sys_regs.c
+++ b/arch/arm64/kvm/sys_regs.c
@@ -889,6 +889,7 @@ static u64 *demux_wb_reg(struct kvm_vcpu
struct kvm_guest_debug_arch *dbg = &vcpu->arch.vcpu_debug_state;
switch (rd->Op2) {
+ case 0b001:
case 0b100:
return &dbg->dbg_bvr[rd->CRm];
case 0b101:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 389/457] KVM: arm64: Fix spurious warning for benign stage 2 teardown race
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 388/457] KVM: arm64: Fix AArch32 DBGBXVR<n> handling Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 390/457] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, " Greg Kroah-Hartman
` (78 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuan Yao, Marc Zyngier,
Lorenzo Stoakes (ARM), Oliver Upton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit 38b70fc453c3112f1a62583b89903ae41116cc27 upstream.
kvmtool was used to establish an L1 guest with 8 CPUs and 8 GiB of RAM, an
L2 guest with 4 CPUs and 4 GiB of RAM and an L3 guest with 2 CPUs and 2 GiB
of RAM, all of which was then exited.
Under memory pressure in the L0 host warnings were observed due to
migration triggered by compaction:
WARNING: arch/arm64/kvm/mmu.c:336 at __unmap_stage2_range+0x64/0x80,
CPU#5: kcompactd0/66
Which was, in turn, triggered by an MMU notifier for the host invalidation:
mmu_notifier_invalidate_range_start()
-> ... -> kvm_mmu_notifier_invalidate_range_start()
-> kvm_mmu_unmap_gfn_range()
-> kvm_unmap_gfn_range()
-> kvm_nested_s2_unmap()
-> kvm_stage2_unmap_range()
-> __unmap_stage2_range()
-> stage2_apply_range()
<- -EINVAL, triggering a WARN_ON()
Racing with L0's teardown of stage 2 page tables:
exit_mm()
-> mmput()
-> __mmput()
-> exit_mmap()
-> mmu_notifier_release()
-> ... -> kvm_mmu_notifier_release()
-> kvm_flush_shadow_all()
-> kvm_arch_flush_shadow_all()
-> kvm_free_stage2_pgd()
-> [ acquire kvm->mmu_lock for write ]
-> mmu->pgt = NULL [ among other tasks ]
-> [ release kvm->mmu_lock for write ]
It turns out there is a benign race resulting in a spurious warning:
Thread A - notify: migration | Thread B - notify: release
-------------------------------|---------------------------------
< kvm->mmu_lock held > |
stage2_apply_range() |
get mmu->pgt, check !NULL |
... | kvm_arch_flush_shadow_all()
cond_resched_rwlock_write(); | < contend, sleep kvm->mmu_lock >
< drop kvm->mmu_lock > | < acquire kvm->mmu_lock>
| ...
| kvm_free_stage2_pgd()
| mmu->pgt = NULL
| < invalidate MMU >
| ...
| < release kvm->mmu_lock >
[ scheduled ] |
stage2_apply_range() |
< loop to next > |
get, mmu->pgt, check !NULL |
is NULL, return -EINVAL |
__unmap_stage2_range() |
WARN_ON(-EINVAL) <--- entirely spurious - the race was handled
correctly.
Fix the spurious warning by updating stage2_apply_range() to no longer
treat concurrent PGT teardown on lock release as an error - whether the
walker is tearing down page tables or doing something else this is a
legitimate reason to abort the operation without error.
This keeps the warning in place for all other circumstances.
In practice only __unmap_stage2_range() actually does anything with the
error so this only impacts that.
Fixes: ec14c272408a ("KVM: arm64: nv: Unmap/flush shadow stage 2 page tables")
Cc: stable@vger.kernel.org
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Link: https://patch.msgid.link/20260901-kvm-arm-nested-virt-fix-v3-1-b154676f7e4c@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/mmu.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
--- a/arch/arm64/kvm/mmu.c
+++ b/arch/arm64/kvm/mmu.c
@@ -59,27 +59,36 @@ static phys_addr_t stage2_range_addr_end
* long will also starve other vCPUs. We have to also make sure that the page
* tables are not freed while we released the lock.
*/
-static int stage2_apply_range(struct kvm_s2_mmu *mmu, phys_addr_t addr,
+static int stage2_apply_range(struct kvm_s2_mmu *mmu, phys_addr_t start,
phys_addr_t end,
int (*fn)(struct kvm_pgtable *, u64, u64),
bool resched)
{
struct kvm *kvm = kvm_s2_mmu_to_kvm(mmu);
+ bool lock_dropped = false;
+ phys_addr_t addr = start;
int ret;
u64 next;
do {
struct kvm_pgtable *pgt = mmu->pgt;
+ /*
+ * We may be raced on PGT teardown when we release the
+ * kvm->mmu_lock. That's fine as the PGT is legitimately no
+ * longer present.
+ */
if (!pgt)
- return -EINVAL;
+ return lock_dropped ? 0 : -EINVAL;
next = stage2_range_addr_end(addr, end);
ret = fn(pgt, addr, next - addr);
if (ret)
break;
- if (resched && next != end)
+ if (resched && next != end) {
cond_resched_rwlock_write(&kvm->mmu_lock);
+ lock_dropped = true;
+ }
} while (addr = next, addr != end);
return ret;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 390/457] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 389/457] KVM: arm64: Fix spurious warning for benign stage 2 teardown race Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 391/457] KVM: arm64: Transfer the hyp stack pages out of the host stage-2 Greg Kroah-Hartman
` (77 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Lorenzo Stoakes (ARM),
Jonathan Davies, Oliver Upton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit 4c74e233cdedd11592775fae2a6243e67ca3f891 upstream.
Commit 7270cc9157f4 ("KVM: arm64: nv: Handle VNCR_EL2 invalidation from MMU
notifiers") introduced VNCR_EL2 invalidation in both kvm_nested_s2_unmap()
and kvm_nested_s2_wp().
However at the point of this being performed concurrent stage 2 teardown of
a nested guest can cause kvm->arch.mmu.pgt to be set to NULL.
This happens in kvm_flush_shadow_all() -> kvm_arch_flush_shadow_all() ->
kvm_free_stage2_pgd() and is performed under the kvm->mmu_lock.
Commit ec14c272408a ("KVM: arm64: nv: Unmap/flush shadow stage 2 page
tables") introduced the teardown of the entire nested MMU range, which then
invokes stage2_apply_range() with resched=true:
mmu_notifier_invalidate_range_start()
-> ... -> kvm_mmu_notifier_invalidate_range_start()
-> kvm_mmu_unmap_gfn_range()
-> kvm_unmap_gfn_range()
-> kvm_nested_s2_unmap()
-> kvm_stage2_unmap_range()
-> __unmap_stage2_range()
-> stage2_apply_range()
This means that stage2_apply_range() can drop the kvm->mmu_lock and thus
concurrent progress can be made in lockstep with
kvm_arch_flush_shadow_all().
If kvm_arch_flush_shadow_all() advances ahead of stage2_apply_range() and
completes its operation it guarantees a NULL pointer deref.
Since kvm_free_stage2_pgd() is performed under the kvm->mmu_lock this will
either be observed NULL or not and serialised against
kvm_free_stage2_pgd().
Resolve the issue by abstracting the invalidation to a new function,
kvm_invalidate_vncr_ipa_all(), and check that the pgt is non-NULL before
dereferencing it.
Fixes: 7270cc9157f4 ("KVM: arm64: nv: Handle VNCR_EL2 invalidation from MMU notifiers")
Cc: stable@vger.kernel.org
Reviewed-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Tested-by: Jonathan Davies <jonathan.davies@nutanix.com>
Link: https://patch.msgid.link/20260901-kvm-arm-nested-virt-fix-v3-2-b154676f7e4c@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/nested.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -1256,6 +1256,17 @@ void kvm_handle_s1e2_tlbi(struct kvm_vcp
invalidate_vncr_va(vcpu->kvm, &scope);
}
+static void kvm_invalidate_vncr_ipa_all(struct kvm *kvm)
+{
+ struct kvm_pgtable *pgt = kvm->arch.mmu.pgt;
+
+ lockdep_assert_held_write(&kvm->mmu_lock);
+
+ /* if the mmu lock was dropped, pgt teardown may have raced. */
+ if (pgt)
+ kvm_invalidate_vncr_ipa(kvm, 0, BIT(pgt->ia_bits));
+}
+
void kvm_nested_s2_wp(struct kvm *kvm)
{
int i;
@@ -1272,7 +1283,7 @@ void kvm_nested_s2_wp(struct kvm *kvm)
kvm_stage2_wp_range(mmu, 0, kvm_phys_size(mmu));
}
- kvm_invalidate_vncr_ipa(kvm, 0, BIT(kvm->arch.mmu.pgt->ia_bits));
+ kvm_invalidate_vncr_ipa_all(kvm);
}
void kvm_nested_s2_unmap(struct kvm *kvm, bool may_block)
@@ -1291,7 +1302,7 @@ void kvm_nested_s2_unmap(struct kvm *kvm
kvm_stage2_unmap_range(mmu, 0, kvm_phys_size(mmu), may_block);
}
- kvm_invalidate_vncr_ipa(kvm, 0, BIT(kvm->arch.mmu.pgt->ia_bits));
+ kvm_invalidate_vncr_ipa_all(kvm);
}
void kvm_nested_s2_flush(struct kvm *kvm)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 391/457] KVM: arm64: Transfer the hyp stack pages out of the host stage-2
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 390/457] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, " Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 392/457] RISC-V: KVM: Serialize IMSIC attributes with vCPU migration Greg Kroah-Hartman
` (76 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hiroyuki Katsura, Fuad Tabba,
Vincent Donnefort, Marc Zyngier, Oliver Upton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fuad Tabba <fuad.tabba@linux.dev>
commit 3a8c562892b96f35bba1e00d5e455a15963bbb92 upstream.
fix_host_ownership() walks only the linear-map alias of each memblock
region, and the per-CPU hyp stack, mapped in the private VA range for
its guard page, has none.
Walk each stack's VA range with the same walker.
Fixes: 1a919b17ef012 ("KVM: arm64: Add guard pages for pKVM (protected nVHE) hypervisor stack")
Reported-by: Hiroyuki Katsura <hk590@cam.ac.uk>
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Vincent Donnefort <vdonnefort@google.com>
Tested-by: Vincent Donnefort <vdonnefort@google.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260908110713.1540304-2-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/hyp/nvhe/setup.c | 10 ++++++++++
1 file changed, 10 insertions(+)
--- a/arch/arm64/kvm/hyp/nvhe/setup.c
+++ b/arch/arm64/kvm/hyp/nvhe/setup.c
@@ -269,6 +269,16 @@ static int fix_host_ownership(void)
return ret;
}
+ /* The stacks sit in the private VA range, not the linear map. */
+ for (i = 0; i < hyp_nr_cpus; i++) {
+ struct kvm_nvhe_init_params *params = per_cpu_ptr(&kvm_init_params, i);
+ u64 start = params->stack_hyp_va - NVHE_STACK_SIZE;
+
+ ret = kvm_pgtable_walk(&pkvm_pgtable, start, NVHE_STACK_SIZE, &walker);
+ if (ret)
+ return ret;
+ }
+
return 0;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 392/457] RISC-V: KVM: Serialize IMSIC attributes with vCPU migration
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 391/457] KVM: arm64: Transfer the hyp stack pages out of the host stage-2 Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 393/457] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
` (75 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xie Bo, Anup Patel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xie Bo <xb@ultrarisc.com>
commit 8ae12ccaec6ec74945d8c1ef39f2c1b8df779abc upstream.
KVM device ioctls are not serialized against KVM_RUN. As a result,
kvm_riscv_aia_imsic_rw_attr() can snapshot the physical CPU and HGEI of
an IMSIC VS-file before a concurrent vCPU migration releases it.
The HGEI can then be allocated to another vCPU before imsic_vsfile_rw()
uses the stale tuple. A GET or SET attribute may consequently access the
new owner's interrupt file.
Serialize the entire IMSIC attribute operation with the target vCPU
mutex. This prevents the VS-file from being migrated and recycled until
the attribute access completes. Acquire the mutex killably so that the
device ioctl remains interruptible while waiting for KVM_RUN to finish.
Fixes: db8b7e97d613 ("RISC-V: KVM: Add in-kernel virtualization of AIA IMSIC")
Cc: stable@vger.kernel.org
Signed-off-by: Xie Bo <xb@ultrarisc.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260810-imsic-attr-race-v2-1-00ed95ad321e@ultrarisc.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/aia_imsic.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
--- a/arch/riscv/kvm/aia_imsic.c
+++ b/arch/riscv/kvm/aia_imsic.c
@@ -969,9 +969,14 @@ int kvm_riscv_aia_imsic_rw_attr(struct k
if (!vcpu)
return -ENODEV;
+ if (mutex_lock_killable(&vcpu->mutex))
+ return -EINTR;
+
imsic = vcpu->arch.aia_context.imsic_state;
- if (!imsic)
- return -ENODEV;
+ if (!imsic) {
+ rc = -ENODEV;
+ goto out_unlock;
+ }
isel = KVM_DEV_RISCV_AIA_IMSIC_GET_ISEL(type);
read_lock_irqsave(&imsic->vsfile_lock, flags);
@@ -995,6 +1000,8 @@ int kvm_riscv_aia_imsic_rw_attr(struct k
rc = imsic_vsfile_rw(vsfile_hgei, vsfile_cpu, imsic->nr_eix,
isel, write, val);
+out_unlock:
+ mutex_unlock(&vcpu->mutex);
return rc;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 393/457] RISC-V: KVM: Synchronize hrtimer callback during teardown
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 392/457] RISC-V: KVM: Serialize IMSIC attributes with vCPU migration Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 394/457] RISC-V: KVM: Release unused page after MMU invalidation Greg Kroah-Hartman
` (74 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Myeonghun Pak, Anup Patel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit aaad136d56d91252517272b68cd533e5714698d5 upstream.
The non-Sstc hrtimer callback clears next_set before its final uses of
the enclosing vCPU. If teardown observes next_set as false while the
callback is still running, kvm_riscv_vcpu_timer_cancel() skips
hrtimer_cancel() and kvm_destroy_vcpus() can free the vCPU before the
callback enters kvm_riscv_vcpu_set_interrupt().
A guest can arm the timer with SBI TIME and request shutdown with SBI
legacy shutdown or SRST. A VMM that honors KVM_EXIT_SYSTEM_EVENT and
destroys the VM supplies the teardown side of the race; no post-launch
host ioctl is needed to arm or request teardown.
On upstream master 62cc90241548, generic KASAN reported:
BUG: KASAN: slab-use-after-free in do_raw_spin_lock
Write of size 4 at addr ff60000005e58898
kvm_riscv_vcpu_set_interrupt
kvm_riscv_vcpu_hrtimer_expired
__hrtimer_run_queues
hrtimer_interrupt
The object was allocated by KVM_CREATE_VCPU and freed concurrently by:
kvm_destroy_vcpus
kvm_arch_destroy_vm
kvm_destroy_vm
__fput
For deterministic validation, I added mdelay(1000) immediately after
the existing next_set = false assignment. This only widens the
existing post-clear callback window. A no-delay trace build naturally
reached the callback-after-teardown-start/before-deinit ordering in 12
of 200 runs, but 1,500 stock-kernel stress iterations did not produce a
KASAN report, so natural reproduction is timing-sensitive.
Always invoke hrtimer_cancel() for an initialized timer. Preserve the
existing -EINVAL result when the timer is no longer set, but only after
synchronizing with a running callback.
With this patch, hrtimer_cancel() blocked for the full widened callback
window before vCPU destruction. KASAN reported no error in 100
fixed-and-widened runs or 200 fix-only timing-sweep runs.
Fixes: 3a9f66cb25e1 ("RISC-V: KVM: Add timer functionality")
Cc: stable@vger.kernel.org
Assisted-by: OpenAI:GPT-5.6
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260731163550.46991-1-mhun512@gmail.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/vcpu_timer.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/arch/riscv/kvm/vcpu_timer.c
+++ b/arch/riscv/kvm/vcpu_timer.c
@@ -61,10 +61,13 @@ static enum hrtimer_restart kvm_riscv_vc
static int kvm_riscv_vcpu_timer_cancel(struct kvm_vcpu_timer *t)
{
- if (!t->init_done || !t->next_set)
+ if (!t->init_done)
return -EINVAL;
hrtimer_cancel(&t->hrt);
+
+ if (!t->next_set)
+ return -EINVAL;
t->next_set = false;
return 0;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 394/457] RISC-V: KVM: Release unused page after MMU invalidation
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 393/457] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 395/457] RISC-V: KVM: Propagate interrupted G-stage faults Greg Kroah-Hartman
` (73 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xie Bo, Anup Patel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xie Bo <xb@ultrarisc.com>
commit ed54fdb460a6e81d5f8f38388d1f10b385dd4a58 upstream.
If an MMU invalidation races with a G-stage fault, the fault handler skips
installing the page but leaves ret set to zero. As a result,
kvm_release_faultin_page() treats the page as used and can unnecessarily
mark it dirty.
Track the invalidation retry separately and release the page as unused,
while preserving the existing return value so that the vCPU retries the
fault.
Fixes: 2ed90cb0938a ("KVM: RISC-V: Retry fault if vma_lookup() results become invalid")
Cc: stable@vger.kernel.org
Signed-off-by: Xie Bo <xb@ultrarisc.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260810051544.3953925-2-xb@ultrarisc.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/mmu.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/arch/riscv/kvm/mmu.c
+++ b/arch/riscv/kvm/mmu.c
@@ -540,6 +540,7 @@ int kvm_riscv_mmu_map(struct kvm_vcpu *v
int ret;
kvm_pfn_t hfn;
bool is_hugetlb;
+ bool unused = false;
bool writable;
short vma_pageshift;
gfn_t gfn = gpa >> PAGE_SHIFT;
@@ -632,8 +633,10 @@ int kvm_riscv_mmu_map(struct kvm_vcpu *v
write_lock(&kvm->mmu_lock);
- if (mmu_invalidate_retry(kvm, mmu_seq))
+ if (mmu_invalidate_retry(kvm, mmu_seq)) {
+ unused = true;
goto out_unlock;
+ }
/*
* Check if we are backed by a THP and thus use block mapping if
@@ -656,7 +659,8 @@ int kvm_riscv_mmu_map(struct kvm_vcpu *v
kvm_err("Failed to map in G-stage\n");
out_unlock:
- kvm_release_faultin_page(kvm, page, ret && ret != -EEXIST, writable);
+ kvm_release_faultin_page(kvm, page,
+ unused || (ret && ret != -EEXIST), writable);
write_unlock(&kvm->mmu_lock);
return ret;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 395/457] RISC-V: KVM: Propagate interrupted G-stage faults
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 394/457] RISC-V: KVM: Release unused page after MMU invalidation Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 396/457] RISC-V: KVM: Fix HSM hart status error propagation Greg Kroah-Hartman
` (72 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xie Bo, Anup Patel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xie Bo <xb@ultrarisc.com>
commit f41fb17143df890855d3de980f8eb92dfd595817 upstream.
__kvm_faultin_pfn() reports an interrupted host page fault with
KVM_PFN_ERR_SIGPENDING. RISC-V currently handles it as a generic
error PFN and returns -EFAULT.
Return -EINTR for the signal-pending sentinel so callers can distinguish
an interrupted fault from an invalid userspace mapping. Do not log the
expected interruption as a vCPU exit error.
Fixes: 9d05c1fee837 ("RISC-V: KVM: Implement stage2 page table programming")
Cc: stable@vger.kernel.org
Signed-off-by: Xie Bo <xb@ultrarisc.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260810051544.3953925-3-xb@ultrarisc.com
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/mmu.c | 2 ++
arch/riscv/kvm/vcpu_exit.c | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
--- a/arch/riscv/kvm/mmu.c
+++ b/arch/riscv/kvm/mmu.c
@@ -621,6 +621,8 @@ int kvm_riscv_mmu_map(struct kvm_vcpu *v
vma_pageshift, current);
return 0;
}
+ if (is_sigpending_pfn(hfn))
+ return -EINTR;
if (is_error_noslot_pfn(hfn))
return -EFAULT;
--- a/arch/riscv/kvm/vcpu_exit.c
+++ b/arch/riscv/kvm/vcpu_exit.c
@@ -267,7 +267,7 @@ int kvm_riscv_vcpu_exit(struct kvm_vcpu
}
/* Print details in-case of error */
- if (ret < 0) {
+ if (ret < 0 && ret != -EINTR) {
kvm_err("VCPU exit error %d\n", ret);
kvm_err("SEPC=0x%lx SSTATUS=0x%lx HSTATUS=0x%lx\n",
vcpu->arch.guest_context.sepc,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 396/457] RISC-V: KVM: Fix HSM hart status error propagation
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 395/457] RISC-V: KVM: Propagate interrupted G-stage faults Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 397/457] sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags Greg Kroah-Hartman
` (71 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tan Chi, Anup Patel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tan Chi <tanchi25@mails.ucas.ac.cn>
commit 41e81f7e3ef96594fb840445343c0ee7723aa550 upstream.
kvm_sbi_hsm_vcpu_get_status() returns SBI_ERR_INVALID_PARAM when
the requested hart does not exist. However, the HART_STATUS case
returns from the SBI handler without storing this error in
retdata->err_val.
As a result, a guest querying the status of a non-existent hart
observes SBI_SUCCESS instead of SBI_ERR_INVALID_PARAM.
Use the common SBI error handling path for HART_STATUS after
saving a valid hart state in retdata->out_val. This preserves
the returned error when kvm_sbi_hsm_vcpu_get_status() fails.
Fixes: bae0dfd74e01 ("RISC-V: KVM: Modify SBI extension handler to return SBI error code")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tan Chi <tanchi25@mails.ucas.ac.cn>
Reviewed-by: Anup Patel <anup@brainfault.org>
Link: https://lore.kernel.org/r/20260914031146.446157-1-tanchi25@mails.ucas.ac.cn
Signed-off-by: Anup Patel <anup@brainfault.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/riscv/kvm/vcpu_sbi_hsm.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/riscv/kvm/vcpu_sbi_hsm.c
+++ b/arch/riscv/kvm/vcpu_sbi_hsm.c
@@ -95,9 +95,9 @@ static int kvm_sbi_ext_hsm_handler(struc
ret = kvm_sbi_hsm_vcpu_get_status(vcpu);
if (ret >= 0) {
retdata->out_val = ret;
- retdata->err_val = 0;
+ ret = 0;
}
- return 0;
+ break;
case SBI_EXT_HSM_HART_SUSPEND:
switch (lower_32_bits(cp->a0)) {
case SBI_HSM_SUSPEND_RET_DEFAULT:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 397/457] sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 396/457] RISC-V: KVM: Fix HSM hart status error propagation Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 398/457] sched/cache: Decouple sched_cache_group from mm to fix UAF Greg Kroah-Hartman
` (70 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Andrea Righi, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tejun Heo <tj@kernel.org>
commit df5cdc2c832ca4e8a6d774596b9005558761a403 upstream.
schedule_deferred_locked() skips scheduling a deferred action while
SCX_RQ_IN_WAKEUP is set and relies on the task_woken_scx() call that follows
a wakeup enqueue to run it. enqueue_task_scx() sets the flag from the merged
enqueue flags, which include the flags stashed for a remote activation.
move_remote_task_to_local_dsq() thus sets SCX_RQ_IN_WAKEUP on the
destination rq when the moved task was woken up, although no
task_woken_scx() follows that activation.
An IMMED insert into a busy destination requests a local reenqueue during
that enqueue. The request gets linked but not scheduled and stays pending
until an unrelated wakeup or preemption on that CPU runs the deferred
actions. The IMMED task sits behind the running task in the meantime. If
nothing runs them before the scheduler is disabled, the request outlives the
scheduler and points into its freed per-cpu area, which the next scheduler
dereferences from run_deferred().
Test the core enqueue flags for the wakeup bit. Only the core's wakeup path
is followed by task_woken_scx().
Fixes: 57ccf5ccdc56 ("sched_ext: Fix enqueue_task_scx() truncation of upper enqueue flags")
Cc: stable@vger.kernel.org # v7.1+
Reported-by: Andrea Righi <arighi@nvidia.com>
Link: https://lore.kernel.org/all/20260916145807.3250167-1-arighi@nvidia.com/
Signed-off-by: Tejun Heo <tj@kernel.org>
Reviewed-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/sched/ext/ext.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/kernel/sched/ext/ext.c
+++ b/kernel/sched/ext/ext.c
@@ -2037,7 +2037,12 @@ static void enqueue_task_scx(struct rq *
int sticky_cpu = p->scx.sticky_cpu;
u64 enq_flags = core_enq_flags | rq->scx.extra_enq_flags;
- if (enq_flags & ENQUEUE_WAKEUP)
+ /*
+ * SCX_RQ_IN_WAKEUP promises a task_woken_scx() call once this enqueue
+ * returns. Only the core's wakeup path delivers one. The flags stashed
+ * for a remote activation may carry the wakeup bit without it.
+ */
+ if (core_enq_flags & ENQUEUE_WAKEUP)
rq->scx.flags |= SCX_RQ_IN_WAKEUP;
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 398/457] sched/cache: Decouple sched_cache_group from mm to fix UAF
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 397/457] sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 399/457] sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug Greg Kroah-Hartman
` (69 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Zenghui Yu (Huawei),
Chen Yu, Tim Chen, Peter Zijlstra (Intel), Ingo Molnar, stable
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tim Chen <tim.c.chen@linux.intel.com>
commit 28f9c0e0a0b94c5d3e1b634db545f6e1f94858c5 upstream.
Currently the sched cache grouping is by mm and the scheduling statistics
sched_cache_stat lives in the mm structure. This ties the life cycle
of scheduling stats with mm.
In account_mm_sched(), the scheduling stats are accessed by
task->mm->sc_stat. However, a task may be switching mm on one CPU when
another CPU is running account_mm_sched(), and possibly accessing the
old mm that was freed. This problem was found when running tests with
KASAN by Hyunwoo:
https://lore.kernel.org/lkml/apPb-Dr4nPYuHQOK@v4bel/
Instead of serializing the mm access by introducing extra acquisition of
rq lock in the mm free path, extract sched_cache_stat from mm_struct,
rename it as sched_cache_group and manage its life cycle apart from
mm_struct with its own ref counting. This allows us in the next patch
access sched_cache_group directly from task, and add a refcount
on sched_cache_group when a task links to it. This prevents the use
after free issue when accessing stale and released old mm and its
sched cache stat a task switches to a new mm while account_mm_sched()
is done elsewhere.
The other benefit of this restructure is in the future, the grouping of
tasks to a LLC would have the flexibility to be associated with a user
defined grouping, or cgroup, cookie group, numa_group or others instead
of just with a single mm address space.
Rename sched_cache_stat to sched_cache_group and turn it into a refcounted
object allocated from mm_struct. The mm_struct now holds a pointer
(sched_cache_grp) to this object instead of embedding it.
Fixes: df0d98475954 ("sched/cache: Introduce infrastructure for cache-aware load balancing")
Closes: https://lore.kernel.org/lkml/apPb-Dr4nPYuHQOK@v4bel/
Closes: https://lore.kernel.org/all/343a7e07-7fad-4979-9c9b-82ec038c293c@linux.dev/
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Reported-by: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
Co-developed-by: Chen Yu <yu.c.chen@intel.com>
Signed-off-by: Chen Yu <yu.c.chen@intel.com>
Signed-off-by: Tim Chen <tim.c.chen@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: <stable@kernel.org> #7.2.x
Link: https://patch.msgid.link/91fd1e3266707c865bc9abecfb3e17bc676712df.1790035273.git.tim.c.chen@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/mm_types.h | 15 +---
include/linux/sched.h | 6 +
kernel/exit.c | 11 ++
kernel/sched/fair.c | 173 ++++++++++++++++++++++++++++++++++-------------
4 files changed, 144 insertions(+), 61 deletions(-)
--- a/include/linux/mm_types.h
+++ b/include/linux/mm_types.h
@@ -1211,7 +1211,7 @@ struct mm_struct {
struct mm_mm_cid mm_cid;
/* sched_cache related statistics */
- struct sched_cache_stat sc_stat;
+ struct sched_cache_group *sched_cache_grp;
#ifdef CONFIG_MMU
atomic_long_t pgtables_bytes; /* size of all page tables */
#endif
@@ -1609,8 +1609,9 @@ static inline unsigned int mm_cid_size(v
#endif /* CONFIG_SCHED_MM_CID */
#ifdef CONFIG_SCHED_CACHE
-void mm_init_sched(struct mm_struct *mm,
- struct sched_cache_time __percpu *pcpu_sched);
+int mm_init_sched(struct mm_struct *mm,
+ struct sched_cache_time __percpu *pcpu_sched);
+void mm_destroy_sched(struct mm_struct *mm);
static inline int mm_alloc_sched_noprof(struct mm_struct *mm)
{
@@ -1620,17 +1621,11 @@ static inline int mm_alloc_sched_noprof(
if (!pcpu_sched)
return -ENOMEM;
- mm_init_sched(mm, pcpu_sched);
- return 0;
+ return mm_init_sched(mm, pcpu_sched);
}
#define mm_alloc_sched(...) alloc_hooks(mm_alloc_sched_noprof(__VA_ARGS__))
-static inline void mm_destroy_sched(struct mm_struct *mm)
-{
- free_percpu(mm->sc_stat.pcpu_sched);
- mm->sc_stat.pcpu_sched = NULL;
-}
#else /* !CONFIG_SCHED_CACHE */
static inline int mm_alloc_sched(struct mm_struct *mm) { return 0; }
--- a/include/linux/sched.h
+++ b/include/linux/sched.h
@@ -2398,7 +2398,7 @@ struct sched_cache_time {
unsigned long epoch;
};
-struct sched_cache_stat {
+struct sched_cache_group {
struct sched_cache_time __percpu *pcpu_sched;
raw_spinlock_t lock;
unsigned long epoch;
@@ -2406,11 +2406,13 @@ struct sched_cache_stat {
unsigned long next_scan;
unsigned long footprint;
int cpu;
+ refcount_t refcnt;
+ struct rcu_head rcu;
} ____cacheline_aligned_in_smp;
#else
-struct sched_cache_stat { };
+struct sched_cache_group { };
#endif
--- a/kernel/exit.c
+++ b/kernel/exit.c
@@ -559,18 +559,23 @@ void mm_update_next_owner(struct mm_stru
*/
static void exit_mm_sched_cache(struct mm_struct *mm)
{
+ struct sched_cache_group *grp;
unsigned long fp, sub;
if (!current->total_numa_faults)
return;
/*
* No lock protection due to performance considerations.
- * Make sure mm->sc_stat.footprint does not become
+ * Make sure the group footprint does not become
* negative.
*/
- fp = READ_ONCE(mm->sc_stat.footprint);
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp)
+ return;
+
+ fp = READ_ONCE(grp->footprint);
sub = min(fp, current->total_numa_faults);
- WRITE_ONCE(mm->sc_stat.footprint, fp - sub);
+ WRITE_ONCE(grp->footprint, fp - sub);
}
#else
static inline void exit_mm_sched_cache(struct mm_struct *mm)
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -1453,12 +1453,17 @@ static bool exceed_llc_capacity(struct m
return true;
if (static_branch_likely(&sched_numa_balancing)) {
+ struct sched_cache_group *grp = READ_ONCE(mm->sched_cache_grp);
+
+ if (!grp)
+ return true;
+
/*
* TBD: RDT exclusive LLC ways reserved should be
* excluded.
*/
llc = sd->llc_bytes;
- footprint = READ_ONCE(mm->sc_stat.footprint);
+ footprint = READ_ONCE(grp->footprint);
/*
* Scale the LLC size by 256*llc_aggr_tolerance
@@ -1490,6 +1495,7 @@ static bool exceed_llc_capacity(struct m
static bool invalid_llc_nr(struct mm_struct *mm, struct task_struct *p,
int cpu)
{
+ struct sched_cache_group *grp;
int scale;
if (get_nr_threads(p) <= 1)
@@ -1503,7 +1509,11 @@ static bool invalid_llc_nr(struct mm_str
if (scale == INT_MAX)
return false;
- return !fits_capacity((mm->sc_stat.nr_running_avg * cpu_smt_num_threads),
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp)
+ return true;
+
+ return !fits_capacity((READ_ONCE(grp->nr_running_avg) * cpu_smt_num_threads),
(scale * per_cpu(sd_llc_size, cpu)));
}
@@ -1580,12 +1590,20 @@ static void account_llc_dequeue(struct r
}
}
-void mm_init_sched(struct mm_struct *mm,
- struct sched_cache_time __percpu *_pcpu_sched)
+int mm_init_sched(struct mm_struct *mm,
+ struct sched_cache_time __percpu *_pcpu_sched)
{
+ struct sched_cache_group *grp;
unsigned long epoch = 0;
int i;
+ grp = kzalloc_obj(*grp);
+ if (!grp) {
+ free_percpu(_pcpu_sched);
+ mm->sched_cache_grp = NULL;
+ return -ENOMEM;
+ }
+
for_each_possible_cpu(i) {
struct sched_cache_time *pcpu_sched = per_cpu_ptr(_pcpu_sched, i);
struct rq *rq = cpu_rq(i);
@@ -1596,18 +1614,51 @@ void mm_init_sched(struct mm_struct *mm,
epoch = rq->cpu_epoch;
}
- raw_spin_lock_init(&mm->sc_stat.lock);
- mm->sc_stat.epoch = epoch;
- mm->sc_stat.cpu = -1;
- mm->sc_stat.next_scan = jiffies;
- mm->sc_stat.nr_running_avg = 0;
- mm->sc_stat.footprint = 0;
+ raw_spin_lock_init(&grp->lock);
+ grp->epoch = epoch;
+ grp->cpu = -1;
+ grp->next_scan = jiffies;
+ grp->nr_running_avg = 0;
+ grp->footprint = 0;
+ refcount_set(&grp->refcnt, 1);
/*
- * The update to mm->sc_stat should not be reordered
- * before initialization to mm's other fields, in case
+ * The update to grp->pcpu_sched should not be reordered
+ * before initialization to grp's other fields, in case
* the readers may get invalid mm_sched_epoch, etc.
*/
- smp_store_release(&mm->sc_stat.pcpu_sched, _pcpu_sched);
+ smp_store_release(&grp->pcpu_sched, _pcpu_sched);
+ /*
+ * Publish the group last. Not every reader qualifies it by
+ * grp->pcpu_sched - can_migrate_llc_task() only checks that the
+ * pointer is non-NULL before reading grp->footprint and
+ * grp->nr_running_avg - so a reachable group must already be
+ * fully initialized.
+ */
+ smp_store_release(&mm->sched_cache_grp, grp);
+ return 0;
+}
+
+static void sched_cache_group_free_rcu(struct rcu_head *rcu)
+{
+ struct sched_cache_group *grp =
+ container_of(rcu, struct sched_cache_group, rcu);
+
+ free_percpu(grp->pcpu_sched);
+ kfree(grp);
+}
+
+static void sched_cache_group_put(struct sched_cache_group *grp)
+{
+ if (!grp || !refcount_dec_and_test(&grp->refcnt))
+ return;
+
+ call_rcu(&grp->rcu, sched_cache_group_free_rcu);
+}
+
+void mm_destroy_sched(struct mm_struct *mm)
+{
+ sched_cache_group_put(mm->sched_cache_grp);
+ mm->sched_cache_grp = NULL;
}
/* because why would C be fully specified */
@@ -1661,11 +1712,16 @@ static unsigned long fraction_mm_sched(s
static int get_pref_llc(struct task_struct *p, struct mm_struct *mm)
{
int mm_sched_llc = -1, mm_sched_cpu;
+ struct sched_cache_group *grp;
if (!mm)
return -1;
- mm_sched_cpu = READ_ONCE(mm->sc_stat.cpu);
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp)
+ return -1;
+
+ mm_sched_cpu = READ_ONCE(grp->cpu);
if (mm_sched_cpu != -1) {
mm_sched_llc = llc_id(mm_sched_cpu);
@@ -1696,6 +1752,7 @@ static inline
void account_mm_sched(struct rq *rq, struct task_struct *p, s64 delta_exec)
{
struct sched_cache_time *pcpu_sched;
+ struct sched_cache_group *grp;
struct mm_struct *mm = p->mm;
int mm_sched_llc = -1;
unsigned long epoch;
@@ -1709,10 +1766,14 @@ void account_mm_sched(struct rq *rq, str
* init_task, kthreads and user thread created
* by user_mode_thread() don't have mm.
*/
- if (!mm || !mm->sc_stat.pcpu_sched)
+ if (!mm)
+ return;
+
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp || !grp->pcpu_sched)
return;
- pcpu_sched = per_cpu_ptr(mm->sc_stat.pcpu_sched, cpu_of(rq));
+ pcpu_sched = per_cpu_ptr(grp->pcpu_sched, cpu_of(rq));
scoped_guard (raw_spinlock, &rq->cpu_epoch_lock) {
__update_mm_sched(rq, pcpu_sched);
@@ -1725,11 +1786,11 @@ void account_mm_sched(struct rq *rq, str
* If this process hasn't hit task_cache_work() for a while invalidate
* its preferred state.
*/
- if ((long)(epoch - READ_ONCE(mm->sc_stat.epoch)) > llc_epoch_affinity_timeout ||
+ if ((long)(epoch - READ_ONCE(grp->epoch)) > llc_epoch_affinity_timeout ||
invalid_llc_nr(mm, p, cpu_of(rq)) ||
exceed_llc_capacity(mm, cpu_of(rq))) {
- if (READ_ONCE(mm->sc_stat.cpu) != -1)
- WRITE_ONCE(mm->sc_stat.cpu, -1);
+ if (READ_ONCE(grp->cpu) != -1)
+ WRITE_ONCE(grp->cpu, -1);
}
mm_sched_llc = get_pref_llc(p, mm);
@@ -1746,30 +1807,35 @@ void account_mm_sched(struct rq *rq, str
static void task_tick_cache(struct rq *rq, struct task_struct *p)
{
struct callback_head *work = &p->cache_work;
+ struct sched_cache_group *grp;
struct mm_struct *mm = p->mm;
unsigned long epoch;
if (!sched_cache_enabled())
return;
- if (!mm || p->flags & PF_KTHREAD ||
- !mm->sc_stat.pcpu_sched)
+ if (!mm || p->flags & PF_KTHREAD)
+ return;
+
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp || !grp->pcpu_sched)
return;
epoch = rq->cpu_epoch;
/* avoid moving backwards */
- if (time_after_eq(mm->sc_stat.epoch, epoch))
+ if (time_after_eq(grp->epoch, epoch))
return;
- guard(raw_spinlock)(&mm->sc_stat.lock);
+ guard(raw_spinlock)(&grp->lock);
if (work->next == work) {
task_work_add(p, work, TWA_RESUME);
- WRITE_ONCE(mm->sc_stat.epoch, epoch);
+ WRITE_ONCE(grp->epoch, epoch);
}
}
-static void get_scan_cpumasks(cpumask_var_t cpus, struct task_struct *p)
+static void get_scan_cpumasks(cpumask_var_t cpus, struct task_struct *p,
+ struct sched_cache_group *grp)
{
#ifdef CONFIG_NUMA_BALANCING
int cpu, curr_cpu, nid, pref_nid;
@@ -1777,7 +1843,7 @@ static void get_scan_cpumasks(cpumask_va
if (!static_branch_likely(&sched_numa_balancing))
goto out;
- cpu = READ_ONCE(p->mm->sc_stat.cpu);
+ cpu = READ_ONCE(grp->cpu);
if (cpu != -1)
nid = cpu_to_node(cpu);
curr_cpu = task_cpu(p);
@@ -1838,6 +1904,7 @@ static void task_cache_work(struct callb
unsigned long next_scan, now = jiffies;
struct task_struct *p = current, *cur;
unsigned long curr_m_a_occ = 0;
+ struct sched_cache_group *grp;
struct mm_struct *mm = p->mm;
unsigned long m_a_occ = 0;
cpumask_var_t cpus;
@@ -1849,12 +1916,16 @@ static void task_cache_work(struct callb
if (p->flags & PF_EXITING)
return;
- next_scan = READ_ONCE(mm->sc_stat.next_scan);
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp)
+ return;
+
+ next_scan = READ_ONCE(grp->next_scan);
if (time_before(now, next_scan))
return;
/* only 1 thread is allowed to scan */
- if (!try_cmpxchg(&mm->sc_stat.next_scan, &next_scan,
+ if (!try_cmpxchg(&grp->next_scan, &next_scan,
now + max_t(unsigned long,
READ_ONCE(llc_epoch_period), 1)))
return;
@@ -1862,8 +1933,8 @@ static void task_cache_work(struct callb
curr_cpu = task_cpu(p);
if (invalid_llc_nr(mm, p, curr_cpu) ||
exceed_llc_capacity(mm, curr_cpu)) {
- if (READ_ONCE(mm->sc_stat.cpu) != -1)
- WRITE_ONCE(mm->sc_stat.cpu, -1);
+ if (READ_ONCE(grp->cpu) != -1)
+ WRITE_ONCE(grp->cpu, -1);
return;
}
@@ -1874,7 +1945,7 @@ static void task_cache_work(struct callb
scoped_guard (cpus_read_lock) {
guard(rcu)();
- get_scan_cpumasks(cpus, p);
+ get_scan_cpumasks(cpus, p, grp);
for_each_cpu(cpu, cpus) {
/* XXX sched_cluster_active */
@@ -1887,7 +1958,7 @@ static void task_cache_work(struct callb
for_each_cpu(i, sched_domain_span(sd)) {
occ = fraction_mm_sched(cpu_rq(i),
- per_cpu_ptr(mm->sc_stat.pcpu_sched, i));
+ per_cpu_ptr(grp->pcpu_sched, i));
a_occ += occ;
if (occ > m_occ) {
m_occ = occ;
@@ -1920,7 +1991,7 @@ static void task_cache_work(struct callb
m_a_cpu = m_cpu;
}
- if (llc_id(cpu) == llc_id(READ_ONCE(mm->sc_stat.cpu)))
+ if (llc_id(cpu) == llc_id(READ_ONCE(grp->cpu)))
curr_m_a_occ = a_occ;
cpumask_andnot(cpus, cpus, sched_domain_span(sd));
@@ -1929,7 +2000,7 @@ static void task_cache_work(struct callb
if (m_a_occ > (2 * curr_m_a_occ)) {
/*
- * Avoid switching sc_stat.cpu too fast.
+ * Avoid switching sched_cache_grp->cpu too fast.
* The reason to choose 2X is because:
* 1. It is better to keep the preferred LLC stable,
* rather than changing it frequently and cause migrations
@@ -1938,10 +2009,10 @@ static void task_cache_work(struct callb
* 3. 2X is chosen based on test results, as it delivers
* the optimal performance gain so far.
*/
- WRITE_ONCE(mm->sc_stat.cpu, m_a_cpu);
+ WRITE_ONCE(grp->cpu, m_a_cpu);
}
- update_avg_scale(&mm->sc_stat.nr_running_avg, nr_running);
+ update_avg_scale(&grp->nr_running_avg, nr_running);
free_cpumask_var(cpus);
}
@@ -3647,6 +3718,7 @@ static int preferred_group_nid(struct ta
static void task_numa_placement(struct task_struct *p)
__context_unsafe(/* conditional locking */)
{
+ struct sched_cache_group __maybe_unused *grp;
int seq, nid, max_nid = NUMA_NO_NODE;
unsigned long max_faults = 0;
unsigned long fault_types[2] = { 0, 0 };
@@ -3739,19 +3811,23 @@ static void task_numa_placement(struct t
* heuristic and occasional lost updates are tolerable.
*
* If a task exits, its corresponding footprint must
- * be subtracted from the mm->sc_stat.footprint, otherwise
- * the mm->sc_stat.footprint will not converge:
- * the exiting thread's footprint remains unchanged/undecayed
- * in mm->sc_stat.footprint. See exit_mm().
+ * be subtracted from the mm->sched_cache_grp->footprint,
+ * otherwise the mm->sched_cache_grp->footprint will not
+ * converge: the exiting thread's footprint remains
+ * unchanged/undecayed in mm->sched_cache_grp->footprint.
+ * See exit_mm().
*
* Lost updates and unsynchronized subtraction
* in exit_mm() can cause footprint + diff to
* go negative. Clamp to zero to prevent the
* unsigned footprint from wrapping.
*/
- new_fp = (long)READ_ONCE(p->mm->sc_stat.footprint) + diff;
- WRITE_ONCE(p->mm->sc_stat.footprint,
- max(new_fp, 0L));
+ grp = READ_ONCE(p->mm->sched_cache_grp);
+ if (!grp)
+ continue;
+
+ new_fp = (long)READ_ONCE(grp->footprint) + diff;
+ WRITE_ONCE(grp->footprint, max(new_fp, 0L));
#endif
}
@@ -10582,6 +10658,7 @@ static enum llc_mig can_migrate_llc(int
static enum llc_mig can_migrate_llc_task(int src_cpu, int dst_cpu,
struct task_struct *p)
{
+ struct sched_cache_group *grp;
struct mm_struct *mm;
bool to_pref;
int cpu;
@@ -10590,15 +10667,19 @@ static enum llc_mig can_migrate_llc_task
if (!mm)
return mig_unrestricted;
- cpu = READ_ONCE(mm->sc_stat.cpu);
+ grp = READ_ONCE(mm->sched_cache_grp);
+ if (!grp)
+ return mig_unrestricted;
+
+ cpu = READ_ONCE(grp->cpu);
if (cpu < 0 || cpus_share_cache(src_cpu, dst_cpu))
return mig_unrestricted;
/* skip cache aware load balance for too many threads */
if (invalid_llc_nr(mm, p, dst_cpu) ||
exceed_llc_capacity(mm, dst_cpu)) {
- if (READ_ONCE(mm->sc_stat.cpu) != -1)
- WRITE_ONCE(mm->sc_stat.cpu, -1);
+ if (READ_ONCE(grp->cpu) != -1)
+ WRITE_ONCE(grp->cpu, -1);
return mig_unrestricted;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 399/457] sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 398/457] sched/cache: Decouple sched_cache_group from mm to fix UAF Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 400/457] Bluetooth: hci_conn: fix CIS hold ownership on reuse Greg Kroah-Hartman
` (68 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Davi Chaves Azevedo, Tim Chen,
Peter Zijlstra (Intel), Ingo Molnar, Chen Yu, K Prateek Nayak,
stable
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Davi Chaves Azevedo <davichazbh@gmail.com>
commit 3cb0243767fd033bdce95f4f1b5882172a2f8119 upstream.
The scheduler scales LLC capacity by the fraction of cache-sharing CPUs
covered by a domain:
llc_bytes = cache_size * span_weight / shared_weight
During CPU teardown, sched_cpu_deactivate() rebuilds scheduler domains
before cacheinfo_cpu_pre_down() removes the CPU from shared_cpu_map. The
new domains therefore use the old sharing weight. The later call to
sched_update_llc_bytes() looks up the departing CPU's sd_llc, which has
already been detached, and returns without correcting the surviving CPUs.
On a Ryzen 5 7535U with twelve logical CPUs sharing a 16 MiB LLC,
offlining one SMT sibling left the remaining CPUs with:
llc_bytes = floor(16777216 * 11 / 12) = 15379114 bytes
The correct capacity is still 16777216 bytes. On systems with active
cache-aware scheduling, an underestimated capacity can cause
exceed_llc_capacity() to reject aggregation for a process whose footprint
would fit. Unchanged cpuset partitions sharing the physical cache can
also retain stale capacity when a CPU comes online in another partition.
Pass the cache-sharing mask already retained by cacheinfo to the
scheduler update. Refresh every surviving CPU using its own LLC domain
so that each partition receives the correct share. This also preserves
the correction needed as cache-sharing maps grow during boot.
Keep the existing CPU-hotplug and scheduler-domain synchronization. The
update remains on the hotplug path; no steady-state scheduling operation
or persistent allocation is added.
Fixes: 7030513a0877 ("sched/cache: Calculate the LLC size and store it in sched_domain")
Signed-off-by: Davi Chaves Azevedo <davichazbh@gmail.com>
Signed-off-by: Tim Chen <tim.c.chen@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Chen Yu <yu.c.chen@intel.com>
Reviewed-by: Tim Chen <tim.c.chen@linux.intel.com>
Reviewed-by: K Prateek Nayak <kprateek.nayak@amd.com>
Tested-by: Chen Yu <yu.c.chen@intel.com>
Tested-by: K Prateek Nayak <kprateek.nayak@amd.com>
Cc: <stable@kernel.org> # v7.2.x
Link: https://patch.msgid.link/6751d93e15889e624796c74db0bfe66603d60b1b.1790035273.git.tim.c.chen@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/base/cacheinfo.c | 11 ++++++-----
include/linux/sched/topology.h | 4 ++--
kernel/sched/topology.c | 22 +++++++++++++---------
3 files changed, 21 insertions(+), 16 deletions(-)
diff --git a/drivers/base/cacheinfo.c b/drivers/base/cacheinfo.c
index 9f9c72727a05..7a47a392568a 100644
--- a/drivers/base/cacheinfo.c
+++ b/drivers/base/cacheinfo.c
@@ -1040,9 +1040,10 @@ static int cacheinfo_cpu_online(unsigned int cpu)
rc = cache_add_dev(cpu);
if (rc)
goto err;
- if (cpu_map_shared_cache(true, cpu, &cpu_map))
+ if (cpu_map_shared_cache(true, cpu, &cpu_map)) {
update_per_cpu_data_slice_size(true, cpu, cpu_map);
- sched_update_llc_bytes(cpu);
+ sched_update_llc_bytes(cpu_map);
+ }
return 0;
err:
free_cache_attributes(cpu);
@@ -1059,10 +1060,10 @@ static int cacheinfo_cpu_pre_down(unsigned int cpu)
cpu_cache_sysfs_exit(cpu);
free_cache_attributes(cpu);
- if (nr_shared > 1)
+ if (nr_shared > 1) {
update_per_cpu_data_slice_size(false, cpu, cpu_map);
-
- sched_update_llc_bytes(cpu);
+ sched_update_llc_bytes(cpu_map);
+ }
return 0;
}
diff --git a/include/linux/sched/topology.h b/include/linux/sched/topology.h
index b5d9d7c2b8ad..f96812d71c51 100644
--- a/include/linux/sched/topology.h
+++ b/include/linux/sched/topology.h
@@ -281,9 +281,9 @@ static inline int task_node(const struct task_struct *p)
}
#ifdef CONFIG_SCHED_CACHE
-extern void sched_update_llc_bytes(unsigned int cpu);
+extern void sched_update_llc_bytes(const struct cpumask *cpus);
#else
-static inline void sched_update_llc_bytes(unsigned int cpu) { }
+static inline void sched_update_llc_bytes(const struct cpumask *cpus) { }
#endif
#endif /* _LINUX_SCHED_TOPOLOGY_H */
diff --git a/kernel/sched/topology.c b/kernel/sched/topology.c
index 0248227d983a..3dab0253976f 100644
--- a/kernel/sched/topology.c
+++ b/kernel/sched/topology.c
@@ -985,8 +985,8 @@ void sched_cache_active_set(void)
}
/*
- * Update the bottom sched_domain's llc_bytes for @cpu and all its
- * LLC siblings. Called from cacheinfo_cpu_online() or
+ * Update the bottom sched_domain's llc_bytes for @cpus sharing a physical
+ * LLC. Called from cacheinfo_cpu_online() or
* cacheinfo_cpu_pre_down() with cpu hotplug lock held.
*
* Note: get_effective_llc_bytes() returns 0 on PowerPC.
@@ -996,17 +996,13 @@ void sched_cache_active_set(void)
* and does not populates the per-CPU struct cpu_cacheinfo array
* that get_cpu_cacheinfo_llc() reads.
*/
-void sched_update_llc_bytes(unsigned int cpu)
+void sched_update_llc_bytes(const struct cpumask *cpus)
{
struct sched_domain *sd, *sdp;
unsigned int i;
sched_domains_mutex_lock();
- sdp = rcu_dereference_sched_domain(per_cpu(sd_llc, cpu));
- if (!sdp)
- goto unlock;
-
/*
* ci->shared_cpu_map is built incrementally as CPUs come
* online, so the first CPU in an LLC initially sees
@@ -1014,14 +1010,22 @@ void sched_update_llc_bytes(unsigned int cpu)
* get_effective_llc_bytes(). Re-evaluating every LLC
* sibling on each online event corrects this once the full
* shared_cpu_map is known.
+ *
+ * The departing CPU's domains have already been detached when
+ * cacheinfo removes it. Use the surviving cache siblings instead.
+ * They may belong to different cpuset partitions, so use each CPU's
+ * own LLC domain to scale its share of the physical cache.
*/
- for_each_cpu(i, sched_domain_span(sdp)) {
+ for_each_cpu(i, cpus) {
+ sdp = rcu_dereference_sched_domain(per_cpu(sd_llc, i));
+ if (!sdp)
+ continue;
+
sd = rcu_dereference_sched_domain(cpu_rq(i)->sd);
if (sd)
sd->llc_bytes = get_effective_llc_bytes(i, sdp);
}
-unlock:
sched_domains_mutex_unlock();
}
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 400/457] Bluetooth: hci_conn: fix CIS hold ownership on reuse
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 399/457] sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 401/457] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
` (67 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit e06d549fcd4a0ba381ed67ddf1ab3c7a6ca4314c upstream.
Commit 69997d50ec57 ("Bluetooth: ISO: handle bound CIS cleanup via
hci_conn") made hci_bind_cis() and hci_connect_cis() return a
connection with one hold for the ISO layer. hci_bind_cis() currently
takes that hold only after configuring a CIS, so its BT_CONNECTED and
matching BT_BOUND paths return a bare lookup result. Its configuration
failure path can likewise call hci_conn_drop() before taking a hold.
Take the hold before any state-dependent return or configuration error
so every successful return follows the documented ownership contract
and every error drop is balanced.
hci_connect_cis() also assumes hci_conn_link() always takes a new CIS
hold before dropping the one returned by hci_bind_cis(). However, the
helper returns an existing link without taking another hold. In that
case, preserve the CIS hold for the caller and drop the redundant LE
hold because the existing link already owns its parent hold. Returning
early also avoids changing an existing CIS back to BT_CONNECT.
Fixes: 69997d50ec57 ("Bluetooth: ISO: handle bound CIS cleanup via hci_conn")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_conn.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -2079,6 +2079,8 @@ struct hci_conn *hci_bind_cis(struct hci
cis->conn_timeout = timeout;
}
+ hci_conn_hold(cis);
+
if (cis->state == BT_CONNECTED)
return cis;
@@ -2120,7 +2122,6 @@ struct hci_conn *hci_bind_cis(struct hci
return ERR_PTR(-EINVAL);
}
- hci_conn_hold(cis);
cis->state = BT_BOUND;
return cis;
@@ -2496,6 +2497,12 @@ struct hci_conn *hci_connect_cis(struct
hci_conn_drop(le);
return cis;
}
+
+ /* The existing link already owns the hold on its parent. */
+ if (cis->link) {
+ hci_conn_drop(le);
+ return cis;
+ }
link = hci_conn_link(le, cis);
hci_conn_drop(cis);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 401/457] Bluetooth: hci_sock: validate event length before filtering
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 400/457] Bluetooth: hci_conn: fix CIS hold ownership on reuse Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 402/457] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
` (66 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit b0a6cf99afd57a39598b1beca0e86ef5004980de upstream.
is_filtered_packet() reads the event code from skb->data[0] without first
checking that the skb is nonempty. When an opcode filter is configured,
it also reads the command opcode at offsets 3 or 4 without checking that
a Command Complete or Command Status event is long enough.
hci_send_to_sock() invokes the filter before hci_event_packet() validates
the event header. A malformed event supplied by a controller or a vhci
device can therefore cause an out-of-bounds read.
Keep the unmasked event code for the opcode checks. The masked value is
needed for the 64-bit event bitmap, but using it to identify command events
aliases event codes above 0x3f. In particular, Synchronous Train Complete
(0x4f) was treated as Command Status (0x0f) even though its payload has no
opcode.
Reject actual command events that are too short for the field being
inspected. A truncated command event cannot match a configured opcode.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sock.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
--- a/net/bluetooth/hci_sock.c
+++ b/net/bluetooth/hci_sock.c
@@ -164,6 +164,7 @@ static bool is_filtered_packet(struct so
{
struct hci_filter *flt;
int flt_type, flt_event;
+ u8 event;
/* Apply filter */
flt = &hci_pi(sk)->filter;
@@ -177,7 +178,11 @@ static bool is_filtered_packet(struct so
if (hci_skb_pkt_type(skb) != HCI_EVENT_PKT)
return false;
- flt_event = (*(__u8 *)skb->data & HCI_FLT_EVENT_BITS);
+ if (skb->len < 1)
+ return true;
+
+ event = *(__u8 *)skb->data;
+ flt_event = event & HCI_FLT_EVENT_BITS;
if (!hci_test_bit(flt_event, &flt->event_mask))
return true;
@@ -186,11 +191,17 @@ static bool is_filtered_packet(struct so
if (!flt->opcode)
return false;
- if (flt_event == HCI_EV_CMD_COMPLETE &&
+ if (event == HCI_EV_CMD_COMPLETE && skb->len < 5)
+ return true;
+
+ if (event == HCI_EV_CMD_COMPLETE &&
flt->opcode != get_unaligned((__le16 *)(skb->data + 3)))
return true;
- if (flt_event == HCI_EV_CMD_STATUS &&
+ if (event == HCI_EV_CMD_STATUS && skb->len < 6)
+ return true;
+
+ if (event == HCI_EV_CMD_STATUS &&
flt->opcode != get_unaligned((__le16 *)(skb->data + 4)))
return true;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 402/457] Bluetooth: hci_sock: reject out-of-range OCF values
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 401/457] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 403/457] Bluetooth: ISO: balance the parent hold in hci_bind_bis() Greg Kroah-Hartman
` (65 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit e93fad891c72deb84cae49430163b384ebcc92b1 upstream.
The raw HCI socket security filter has 128 OCF bits per supported OGF,
but masks the 10-bit OCF with 127 before looking up the command. An
unprivileged socket can therefore submit a reserved OCF that aliases an
allowlisted command modulo 128.
A conforming controller should reject reserved opcodes. Nevertheless,
the security decision must apply to the opcode that will actually be
sent, especially since controller-specific behavior is outside the host
stack's control.
Reject OCF values that cannot be represented by the security filter
instead of aliasing them onto an unrelated command.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sock.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/bluetooth/hci_sock.c
+++ b/net/bluetooth/hci_sock.c
@@ -1892,7 +1892,8 @@ static int hci_sock_sendmsg(struct socke
u16 ocf = hci_opcode_ocf(opcode);
if (((ogf > HCI_SFLT_MAX_OGF) ||
- !hci_test_bit(ocf & HCI_FLT_OCF_BITS,
+ (ocf > HCI_FLT_OCF_BITS) ||
+ !hci_test_bit(ocf,
&hci_sec_filter.ocf_mask[ogf])) &&
!capable(CAP_NET_RAW)) {
err = -EPERM;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 403/457] Bluetooth: ISO: balance the parent hold in hci_bind_bis()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 402/457] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 404/457] Bluetooth: ISO: release unused CIS holds after channel attach Greg Kroah-Hartman
` (64 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit 4c94557dd02569efa6c1072a0439addaef9a5224 upstream.
hci_conn_link() takes a lifetime reference to its parent with
hci_conn_get(), but only takes an operational hold on the child.
hci_conn_unlink() later balances both a hold and a reference on the
parent.
The SCO and CIS paths pass a parent acquired from a connect helper, so
it already has a hold. For an additional BIS, hci_bind_bis() obtains the
parent from hci_conn_hash_lookup_big(), which returns a bare pointer.
Unlinking the child then drops the parent's existing hold and can
schedule it for disconnection while its socket is still using it.
Take a hold on the parent before linking it and drop that hold if linking
fails. A successful link transfers the hold to hci_conn_unlink().
Fixes: fa224d0c094a ("Bluetooth: ISO: Reassociate a socket with an active BIS")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_conn.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -2375,10 +2375,13 @@ struct hci_conn *hci_bind_bis(struct hci
parent = hci_conn_hash_lookup_big(hdev,
conn->iso_qos.bcast.big);
if (parent && parent != conn) {
+ hci_conn_hold(parent);
link = hci_conn_link(parent, conn);
hci_conn_drop(conn);
- if (!link)
+ if (!link) {
+ hci_conn_drop(parent);
return ERR_PTR(-ENOLINK);
+ }
}
return conn;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 404/457] Bluetooth: ISO: release unused CIS holds after channel attach
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (402 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 403/457] Bluetooth: ISO: balance the parent hold in hci_bind_bis() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 405/457] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
` (63 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit 0fcd4dad555c96e0bd3a1b8c569f989be85c7341 upstream.
hci_bind_cis() and hci_connect_cis() return one hci_conn hold for the
ISO layer. A new channel association consumes that hold, which is
eventually released by iso_conn_free().
There are two cases where iso_chan_add() does not create an association:
it returns success when the socket is already attached to the same
iso_conn, and it returns -EBUSY when another socket is attached. The
hold returned for the current call is unused in both cases. This occurs
when deferred setup calls iso_connect_cis() again for its existing
socket, or when another socket attempts to reuse the CIS.
Detect the idempotent case while the connection is locked and release
the unused hold after iso_chan_add(). Also release it on -EBUSY. Do not
drop it for other errors: a newly allocated iso_conn releases the
transferred hold when its last temporary reference is put.
Fixes: 69997d50ec57 ("Bluetooth: ISO: handle bound CIS cleanup via hci_conn")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/iso.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -496,6 +496,7 @@ static int iso_connect_cis(struct sock *
struct hci_dev *hdev;
bdaddr_t src, dst;
u8 src_type;
+ bool already_attached;
int err;
lock_sock(sk);
@@ -568,8 +569,14 @@ static int iso_connect_cis(struct sock *
goto unlock;
}
+ iso_conn_lock(conn);
+ already_attached = iso_pi(sk)->conn == conn && conn->sk == sk;
+ iso_conn_unlock(conn);
+
err = iso_chan_add(conn, sk, NULL);
iso_conn_put(conn);
+ if (already_attached || err == -EBUSY)
+ hci_conn_drop(hcon);
if (err)
goto unlock;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 405/457] Bluetooth: L2CAP: validate frame length before control and FCS access
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (403 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 404/457] Bluetooth: ISO: release unused CIS holds after channel attach Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 406/457] Bluetooth: mgmt: fix race in read_unconf_index_list() Greg Kroah-Hartman
` (62 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit 6c78a213d9070b610c7f418af2c25b66180b7e37 upstream.
l2cap_data_rcv() unpacks either a two-byte or four-byte control field
without first ensuring that it is present. A short ERTM or streaming-mode
frame can therefore cause an out-of-bounds read.
There is a second short-frame case when CRC16 is enabled. After the
control field is pulled, l2cap_check_fcs() subtracts two from skb->len
without checking it. If fewer than two bytes remain, the subtraction
wraps; skb_trim() leaves the buffer unchanged and the subsequent FCS
load reads past the logical end of the frame.
Validate that the frame contains both its control field and, when
enabled, its FCS before either field is accessed.
Fixes: 1c2acffb76d4 ("Bluetooth: Add initial support for ERTM packets transfers")
Fixes: fcc203c30d72 ("Bluetooth: Add support for FCS option to L2CAP")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/l2cap_core.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -6701,9 +6701,17 @@ static int l2cap_stream_rx(struct l2cap_
static int l2cap_data_rcv(struct l2cap_chan *chan, struct sk_buff *skb)
{
struct l2cap_ctrl *control = &bt_cb(skb)->l2cap;
- u16 len;
+ u16 len, min_len;
u8 event;
+ min_len = test_bit(FLAG_EXT_CTRL, &chan->flags) ?
+ L2CAP_EXT_CTRL_SIZE : L2CAP_ENH_CTRL_SIZE;
+ if (chan->fcs == L2CAP_FCS_CRC16)
+ min_len += L2CAP_FCS_SIZE;
+
+ if (skb->len < min_len)
+ goto drop;
+
__unpack_control(chan, skb);
len = skb->len;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 406/457] Bluetooth: mgmt: fix race in read_unconf_index_list()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (404 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 405/457] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 407/457] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
` (61 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aldo Ariel Panzardo,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
commit b5dbb41b212c50c095a4dbee3017a84fe94f033b upstream.
read_unconf_index_list() counts unconfigured controllers before allocating
its response, then checks the device flags again while filling it.
hci_dev_list_lock stabilizes list membership, but it does not serialize the
per-device flags. During asynchronous controller setup, the worker can set
HCI_UNCONFIGURED and clear HCI_SETUP between the two passes. A controller
omitted from the allocation count can then become eligible for the fill
pass, causing an out-of-bounds write to rp->index[].
Allocate space for every device on hci_dev_list. Since list membership
cannot change while hci_dev_list_lock is held, the response remains large
enough regardless of flag transitions. The reported count and response
length still include only eligible unconfigured controllers.
Fixes: 73d1df2a7a10 ("Bluetooth: Add support for Read Unconfigured Index List command")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/mgmt.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -496,13 +496,9 @@ static int read_unconf_index_list(struct
read_lock(&hci_dev_list_lock);
- count = 0;
- list_for_each_entry(d, &hci_dev_list, list) {
- if (hci_dev_test_flag(d, HCI_UNCONFIGURED))
- count++;
- }
+ count = list_count_nodes(&hci_dev_list);
- rp_len = sizeof(*rp) + (2 * count);
+ rp_len = sizeof(*rp) + (sizeof(__le16) * count);
rp = kmalloc(rp_len, GFP_ATOMIC);
if (!rp) {
read_unlock(&hci_dev_list_lock);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 407/457] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (405 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 406/457] Bluetooth: mgmt: fix race in read_unconf_index_list() Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 408/457] smb: client: fix create context out-of-bounds reads Greg Kroah-Hartman
` (60 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Peng, Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Peng <benquike@gmail.com>
commit 46f8ffd0a1f1eb6cbc94946a92c11ef601e228a1 upstream.
The RFCOMM_CONNINFO getsockopt handler accepts a socket that is not
connected as long as deferred setup is enabled:
if (sk->sk_state != BT_CONNECTED &&
!rfcomm_pi(sk)->dlc->defer_setup) {
err = -ENOTCONN;
break;
}
l2cap_sk = rfcomm_pi(sk)->dlc->session->sock->sk;
dlc->defer_setup is set in rfcomm_sock_init() when rfcomm_connect_ind()
creates a child socket for an incoming connection on a listening socket
that has BT_DEFER_SETUP enabled. It is never cleared afterwards. The
session, however, can go away underneath it.
rfcomm_recv_disc() forces the dlc state before tearing it down:
d->state = BT_CLOSED;
__rfcomm_dlc_close(d, err);
The RFCOMM_DEFER_SETUP early return in __rfcomm_dlc_close() only covers
BT_CONNECT, BT_CONFIG, BT_OPEN and BT_CONNECT2, so with the state
already BT_CLOSED that switch does not match and the function falls
through to rfcomm_dlc_unlink(), which sets d->session = NULL, while
d->defer_setup stays 1.
A getsockopt(SOL_RFCOMM, RFCOMM_CONNINFO) on the accepted socket after
that point therefore skips the -ENOTCONN path -- sk->sk_state is
BT_CLOSED, but dlc->defer_setup is still set -- and dereferences the
NULL session. No race is needed: once the DISC has been processed, the
dereference is unconditional.
Reproduced on a KASAN kernel under QEMU with a BR/EDR peer emulated over
/dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM
PSM, starts a session and sends SABM for a channel bound with
BT_DEFER_SETUP, and sends DISC for that dlci after the socket has been
accepted. getsockopt(SOL_RFCOMM, RFCOMM_CONNINFO) on the accepted
socket then hits:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000002: 0000 [#1] SMP KASAN PTI
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
CPU: 1 UID: 0 PID: 150 Comm: init Tainted: G B 7.3.0-rc3-g5dd1818b15d9
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
RIP: 0010:rfcomm_sock_getsockopt+0x529/0x780
Call Trace:
<TASK>
do_sock_getsockopt+0x3ad/0x7d0
__sys_getsockopt+0x10e/0x1b0
__x64_sys_getsockopt+0xc2/0x160
do_syscall_64+0xda/0x4b0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
0x10 is the offset of sock in struct rfcomm_session;
rfcomm_sock_getsockopt_old() is inlined into rfcomm_sock_getsockopt().
Commit 43a556b2fd43 ("Bluetooth: RFCOMM: take rfcomm_mutex for the
deferred setup accept") fixed the same "a remote DISC clears the session
while deferred setup is still flagged" problem in rfcomm_dlc_accept();
this is the remaining instance of it, in the getsockopt path.
Deferred setup only leaves a socket usable here once it has reached
BT_CONNECT2, so restrict the exception to that state and check that a
session is actually present before following it.
Fixes: bb23c0ab8246 ("Bluetooth: Add support for deferring RFCOMM connection setup")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/rfcomm/sock.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -785,8 +785,10 @@ static int rfcomm_sock_getsockopt_old(st
break;
case RFCOMM_CONNINFO:
- if (sk->sk_state != BT_CONNECTED &&
- !rfcomm_pi(sk)->dlc->defer_setup) {
+ if ((sk->sk_state != BT_CONNECTED &&
+ !(sk->sk_state == BT_CONNECT2 &&
+ rfcomm_pi(sk)->dlc->defer_setup)) ||
+ !rfcomm_pi(sk)->dlc->session) {
err = -ENOTCONN;
break;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 408/457] smb: client: fix create context out-of-bounds reads
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (406 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 407/457] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 409/457] smb: client: close handle after create-context parsing failure Greg Kroah-Hartman
` (59 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 67f4c1c6a1b51e203d986779299824d1c2c590a6 upstream.
smb2_parse_contexts() validates the complete create-context area but
does not limit each record to its Next field before dispatching it. A
malformed chain can therefore expose bytes beyond the current context to
a handler. The QFid handler also used a full response-structure cast
although it only reads DiskFileId.
The SMB2/SMB3 lease parsers made the same layout assumption: they read
LeaseState and LeaseFlags at canonical offsets rather than at
DataOffset. A valid non-canonical DataOffset could therefore yield
unrelated in-bounds data, while a short DataLength was still accepted.
Limit each context to its Next value, reject offsets before the context
header, and reject malformed chains. Bound the name range by the current
context and do not dispatch a known handler when DataLength is zero. Read
the QFid DiskFileId only when the context data covers that field. Parse the
lease context from DataOffset and require DataLength to match the v1 or v2
lease_context size used by ksmbd. A size mismatch skips lease parsing
without failing the open.
Fixes: b8c32dbb0deb ("CIFS: Request SMB2.1 leases")
Fixes: f047390a097e ("CIFS: Add create lease v2 context for SMB3")
Fixes: 89a5bfa350fa ("smb3: optimize open to not send query file internal info")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 28 ++++++++++++++++++++--------
fs/smb/client/smb2pdu.c | 44 ++++++++++++++++++++++++++++++++++----------
2 files changed, 54 insertions(+), 18 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -4569,25 +4569,37 @@ smb3_create_lease_buf(u8 *lease_key, u8
static __u8
smb2_parse_lease_buf(void *buf, __u16 *epoch, char *lease_key)
{
- struct create_lease *lc = (struct create_lease *)buf;
+ struct create_context *cc = buf;
+ struct lease_context lc;
*epoch = 0; /* not used */
- if (lc->lcontext.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE)
+ if (le32_to_cpu(cc->DataLength) != sizeof(lc))
+ return 0;
+
+ memcpy(&lc, (u8 *)cc + le16_to_cpu(cc->DataOffset), sizeof(lc));
+ if (lc.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE)
return SMB2_OPLOCK_LEVEL_NOCHANGE;
- return le32_to_cpu(lc->lcontext.LeaseState);
+ return le32_to_cpu(lc.LeaseState);
}
static __u8
smb3_parse_lease_buf(void *buf, __u16 *epoch, char *lease_key)
{
- struct create_lease_v2 *lc = (struct create_lease_v2 *)buf;
+ struct create_context *cc = buf;
+ struct lease_context_v2 lc;
+
+ if (le32_to_cpu(cc->DataLength) != sizeof(lc)) {
+ *epoch = 0;
+ return 0;
+ }
- *epoch = le16_to_cpu(lc->lcontext.Epoch);
- if (lc->lcontext.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE)
+ memcpy(&lc, (u8 *)cc + le16_to_cpu(cc->DataOffset), sizeof(lc));
+ *epoch = le16_to_cpu(lc.Epoch);
+ if (lc.LeaseFlags & SMB2_LEASE_FLAG_BREAK_IN_PROGRESS_LE)
return SMB2_OPLOCK_LEVEL_NOCHANGE;
if (lease_key)
- memcpy(lease_key, &lc->lcontext.LeaseKey, SMB2_LEASE_KEY_SIZE);
- return le32_to_cpu(lc->lcontext.LeaseState);
+ memcpy(lease_key, lc.LeaseKey, SMB2_LEASE_KEY_SIZE);
+ return le32_to_cpu(lc.LeaseState);
}
static unsigned int
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -2379,11 +2379,17 @@ create_reconnect_durable_buf(struct cifs
static void
parse_query_id_ctxt(struct create_context *cc, struct smb2_file_all_info *buf)
{
- struct create_disk_id_rsp *pdisk_id = (struct create_disk_id_rsp *)cc;
+ u16 doff = le16_to_cpu(cc->DataOffset);
+ u32 dlen = le32_to_cpu(cc->DataLength);
+ u8 *beg;
- cifs_dbg(FYI, "parse query id context 0x%llx 0x%llx\n",
- pdisk_id->DiskFileId, pdisk_id->VolumeId);
- buf->IndexNumber = pdisk_id->DiskFileId;
+ if (dlen < sizeof(__le64))
+ return;
+
+ beg = (u8 *)cc + doff;
+ memcpy(&buf->IndexNumber, beg, sizeof(__le64));
+ cifs_dbg(FYI, "parse query id context 0x%llx\n",
+ le64_to_cpu(buf->IndexNumber));
}
static void
@@ -2431,6 +2437,7 @@ int smb2_parse_contexts(struct TCP_Serve
struct smb2_create_rsp *rsp = rsp_iov->iov_base;
struct create_context *cc;
size_t rem, off, len;
+ size_t cc_len;
size_t doff, dlen;
size_t noff, nlen;
char *name;
@@ -2453,29 +2460,41 @@ int smb2_parse_contexts(struct TCP_Serve
buf->IndexNumber = 0;
while (rem >= sizeof(*cc)) {
+ off = le32_to_cpu(cc->Next);
+ if (off) {
+ if ((off & 0x7) || off >= rem || off < sizeof(*cc))
+ return -EINVAL;
+ cc_len = off;
+ } else {
+ cc_len = rem;
+ }
+
doff = le16_to_cpu(cc->DataOffset);
dlen = le32_to_cpu(cc->DataLength);
- if (check_add_overflow(doff, dlen, &len) || len > rem)
+ if (doff < sizeof(*cc) ||
+ check_add_overflow(doff, dlen, &len) || len > cc_len)
return -EINVAL;
noff = le16_to_cpu(cc->NameOffset);
nlen = le16_to_cpu(cc->NameLength);
- if (noff + nlen > doff)
+ if (noff < sizeof(*cc) ||
+ check_add_overflow(noff, nlen, &len) || len > cc_len ||
+ (dlen && len > doff))
return -EINVAL;
name = (char *)cc + noff;
switch (nlen) {
case 4:
- if (!strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) {
+ if (dlen && !strncmp(name, SMB2_CREATE_REQUEST_LEASE, 4)) {
*oplock = server->ops->parse_lease_buf(cc, epoch,
lease_key);
- } else if (buf &&
+ } else if (dlen && buf &&
!strncmp(name, SMB2_CREATE_QUERY_ON_DISK_ID, 4)) {
parse_query_id_ctxt(cc, buf);
}
break;
case 16:
- if (posix && !memcmp(name, smb3_create_tag_posix, 16))
+ if (dlen && posix && !memcmp(name, smb3_create_tag_posix, 16))
parse_posix_ctxt(cc, buf, posix);
break;
default:
@@ -2487,13 +2506,18 @@ int smb2_parse_contexts(struct TCP_Serve
}
off = le32_to_cpu(cc->Next);
- if (!off)
+ if (!off) {
+ rem = 0;
break;
+ }
if (check_sub_overflow(rem, off, &rem))
return -EINVAL;
cc = (struct create_context *)((u8 *)cc + off);
}
+ if (rem)
+ return -EINVAL;
+
if (rsp->OplockLevel != SMB2_OPLOCK_LEVEL_LEASE)
*oplock = rsp->OplockLevel;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 409/457] smb: client: close handle after create-context parsing failure
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (407 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 408/457] smb: client: fix create context out-of-bounds reads Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 410/457] smb: client: clean up failed cached directory opens Greg Kroah-Hartman
` (58 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 566820af017e81497fb5e9d3ad6e7ffe2828bc8b upstream.
SMB2_open() accounts a successful CREATE response as a remote open before
parsing its create contexts. If smb2_parse_contexts() rejects malformed
context data, SMB2_open() returns without closing the handle, leaving the
server-side handle open and num_remote_opens elevated.
Close the handle after a post-CREATE context parsing failure so the error
path releases the remote resource and balances the open count.
Fixes: af1689a9b770 ("smb: client: fix potential OOBs in smb2_parse_contexts()")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 3 +++
1 file changed, 3 insertions(+)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -3413,6 +3413,9 @@ replay_again:
rc = smb2_parse_contexts(server, &rsp_iov, &oparms->fid->epoch,
oparms->fid->lease_key, oplock, file_info, posix);
+ if (rc)
+ SMB2_close(xid, tcon, oparms->fid->persistent_fid,
+ oparms->fid->volatile_fid);
trace_smb3_open_done(xid, rsp->PersistentFileId, tcon->tid, ses->Suid,
oparms->create_options, oparms->desired_access,
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 410/457] smb: client: clean up failed cached directory opens
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (408 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 409/457] smb: client: close handle after create-context parsing failure Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 411/457] smb: client: preserve create-context parsing errors Greg Kroah-Hartman
` (57 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit d2ff5fb93ea83034025850266b5eed391f96b825 upstream.
open_cached_dir() sends CREATE and QUERY_INFO as a compound request. If
the CREATE succeeds but a later command returns an error, the function
must retain the CREATE FID so common cleanup can issue SMB2_close(). It
also must not treat a response error as a valid CREATE.
Validate the CREATE response before using its fields, record the FIDs, and
mark the handle open before handling errors from later compound commands.
Move the -EREMCHG reconnect handling before response validation so a
missing response does not hide the reconnect request. Count the handle
when it is marked open; confirmed close responses decrement the counter,
while existing close retry behavior remains best effort on transport
failures.
Fixes: b0f6df737a1c ("cifs: cache FILE_ALL_INFO for the shared root handle")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cached_dir.c | 32 ++++++++++++++++++++++----------
1 file changed, 22 insertions(+), 10 deletions(-)
--- a/fs/smb/client/cached_dir.c
+++ b/fs/smb/client/cached_dir.c
@@ -8,6 +8,7 @@
#include <linux/namei.h>
#include "cifsglob.h"
#include "cifsproto.h"
+#include "../common/smb2status.h"
#include "cifs_debug.h"
#include "smb2proto.h"
#include "cached_dir.h"
@@ -323,25 +324,37 @@ replay_again:
rc = compound_send_recv(xid, ses, server,
flags, 2, rqst,
resp_buftype, rsp_iov);
- if (rc) {
- if (rc == -EREMCHG) {
- tcon->need_reconnect = true;
- pr_warn_once("server share %s deleted\n",
- tcon->tree_name);
- }
- goto oshr_free;
+ if (rc == -EREMCHG) {
+ tcon->need_reconnect = true;
+ pr_warn_once("server share %s deleted\n",
+ tcon->tree_name);
}
- cfid->is_open = true;
- spin_lock(&cfids->cfid_list_lock);
+ if (!rsp_iov[0].iov_base || rsp_iov[0].iov_len < sizeof(*o_rsp)) {
+ if (!rc)
+ rc = -EIO;
+ goto oshr_free;
+ }
o_rsp = (struct smb2_create_rsp *)rsp_iov[0].iov_base;
+ if (o_rsp->hdr.Status != STATUS_SUCCESS) {
+ if (!rc)
+ rc = -EIO;
+ goto oshr_free;
+ }
+
oparms.fid->persistent_fid = o_rsp->PersistentFileId;
oparms.fid->volatile_fid = o_rsp->VolatileFileId;
#ifdef CONFIG_CIFS_DEBUG2
oparms.fid->mid = le64_to_cpu(o_rsp->hdr.MessageId);
#endif /* CIFS_DEBUG2 */
+ cfid->is_open = true;
+ atomic_inc(&tcon->num_remote_opens);
+ if (rc)
+ goto oshr_free;
+
+ spin_lock(&cfids->cfid_list_lock);
if (o_rsp->OplockLevel != SMB2_OPLOCK_LEVEL_LEASE) {
spin_unlock(&cfids->cfid_list_lock);
@@ -408,7 +421,6 @@ out:
close_cached_dir(cfid);
} else {
*ret_cfid = cfid;
- atomic_inc(&tcon->num_remote_opens);
}
kfree(utf16_path);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 411/457] smb: client: preserve create-context parsing errors
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (409 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 410/457] smb: client: clean up failed cached directory opens Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 412/457] smb: client: use finish_no_open() for non-regular inodes Greg Kroah-Hartman
` (56 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 2e828035d5d736d904c238ae7ec3f77c0d6270bf upstream.
smb2_compound_op() saves the result from compound_send_recv() in
tmp_rc. For SMB2_OP_OPEN_QUERY it then parses the CREATE contexts, but
the final assignment of rc from tmp_rc discards a parsing error. A
malformed create-context response can therefore be reported as
successful to smb2_query_path_info().
Keep a create-context parsing error in tmp_rc so it survives per-command
response processing and is returned to the caller.
Fixes: b07687edee99 ("cifs: Improve SMB2+ stat() to work also without FILE_READ_ATTRIBUTES")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2inode.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2inode.c
+++ b/fs/smb/client/smb2inode.c
@@ -596,8 +596,10 @@ finished:
/* smb2_parse_contexts() fills idata->fi.IndexNumber */
rc = smb2_parse_contexts(server, &rsp_iov[0], &oparms->fid->epoch,
oparms->fid->lease_key, &oplock, &idata->fi, NULL);
- if (rc)
+ if (rc) {
cifs_dbg(VFS, "rc: %d parsing context of compound op\n", rc);
+ tmp_rc = rc;
+ }
}
for (i = 0; i < num_cmds; i++) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 412/457] smb: client: use finish_no_open() for non-regular inodes
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (410 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 411/457] smb: client: preserve create-context parsing errors Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 413/457] smb: client: validate POSIX create context length Greg Kroah-Hartman
` (55 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
commit e66cf1625ec4a3fe68346119f371def713fd0a4d upstream.
An O_CREAT open can find an existing symlink or another non-regular
inode. cifs_atomic_open() calls finish_open() on it and attaches a
cifsFileInfo. Symlink inodes have no CIFS release operation, so the
dentry reference held by cifsFileInfo is leaked. FMODE_OPENED also
prevents the VFS from following the symlink.
Track whether cifs_do_create() returned an open server handle. For
non-regular inodes, close the handle if present, remove the pending
open, and call finish_no_open() so the VFS can continue the lookup.
Do not set FMODE_CREATED unless a regular file was opened. For
O_NOFOLLOW with __O_REGULAR, return -ELOOP before the VFS's
-EFTYPE check.
Defer closing a legacy POSIX handle on a non-regular inode until
after inode lookup. This avoids closing it again if lookup fails.
Fixes: d2c127197dfc ("cifs: implement i_op->atomic_open()")
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/dir.c | 52 +++++++++++++++++++++++++++++++++++++++-------------
1 file changed, 39 insertions(+), 13 deletions(-)
--- a/fs/smb/client/dir.c
+++ b/fs/smb/client/dir.c
@@ -203,7 +203,7 @@ static int __cifs_do_create(struct inode
struct tcon_link *tlink, unsigned int oflags,
umode_t mode, __u32 *oplock, struct cifs_fid *fid,
struct cifs_open_info_data *buf,
- struct inode **inode)
+ struct inode **inode, bool *opened)
{
int rc = -ENOENT;
int create_options = CREATE_NOT_DIR;
@@ -220,6 +220,7 @@ static int __cifs_do_create(struct inode
__le32 lease_flags = 0;
*inode = NULL;
+ *opened = false;
*oplock = 0;
if (tcon->ses->server->oplocks)
*oplock = REQ_OPLOCK;
@@ -236,6 +237,7 @@ static int __cifs_do_create(struct inode
oflags, oplock, &fid->netfid, xid);
switch (rc) {
case 0:
+ *opened = true;
if (newinode == NULL) {
/* query inode info */
goto cifs_create_get_file_info;
@@ -257,11 +259,9 @@ static int __cifs_do_create(struct inode
/*
* The server may allow us to open things like
* FIFOs, but the client isn't set up to deal
- * with that. If it's not a regular file, just
- * close it and proceed as if it were a normal
- * lookup.
+ * with that. Keep the handle until the caller
+ * can finish the lookup.
*/
- CIFSSMBClose(xid, tcon, fid->netfid);
goto cifs_create_get_file_info;
}
/* success, no need to query */
@@ -388,6 +388,7 @@ retry_open:
}
return rc;
}
+ *opened = true;
if (rdwr_for_fscache == 2)
cifs_invalidate_cache(dir, FSCACHE_INVAL_DIO_WRITE);
@@ -479,7 +480,7 @@ cifs_create_set_dentry:
return rc;
out_err:
- if (server->ops->close)
+ if (*opened && server->ops->close)
server->ops->close(xid, tcon, fid);
if (newinode)
iput(newinode);
@@ -491,7 +492,7 @@ static int cifs_do_create(struct inode *
unsigned int oflags, umode_t mode,
__u32 *oplock, struct cifs_fid *fid,
struct cifs_open_info_data *buf,
- struct inode **inode)
+ struct inode **inode, bool *opened)
{
void *page = alloc_dentry_path();
const char *full_path;
@@ -500,10 +501,11 @@ static int cifs_do_create(struct inode *
full_path = build_path_from_dentry(direntry, page);
if (IS_ERR(full_path)) {
rc = PTR_ERR(full_path);
+ *opened = false;
} else {
rc = __cifs_do_create(dir, direntry, full_path, xid,
tlink, oflags, mode, oplock,
- fid, buf, inode);
+ fid, buf, inode, opened);
}
free_dentry_path(page);
return rc;
@@ -533,6 +535,8 @@ int cifs_atomic_open(struct inode *dir,
struct inode *inode;
unsigned int xid;
__u32 oplock;
+ bool is_regular;
+ bool opened;
int rc;
if (unlikely(cifs_forced_shutdown(cifs_sb)))
@@ -585,12 +589,26 @@ int cifs_atomic_open(struct inode *dir,
cifs_add_pending_open(&fid, tlink, &open);
rc = cifs_do_create(dir, direntry, xid, tlink, oflags, mode,
- &oplock, &fid, &buf, &inode);
+ &oplock, &fid, &buf, &inode, &opened);
if (rc) {
cifs_del_pending_open(&open);
goto out;
}
+ is_regular = S_ISREG(inode->i_mode);
+ if (!is_regular || !opened) {
+ if (opened && server->ops->close)
+ server->ops->close(xid, tcon, &fid);
+ cifs_del_pending_open(&open);
+ if (S_ISLNK(inode->i_mode) &&
+ (oflags & (O_NOFOLLOW | __O_REGULAR)) ==
+ (O_NOFOLLOW | __O_REGULAR) && !(oflags & O_EXCL)) {
+ iput(inode);
+ rc = -ELOOP;
+ goto out;
+ }
+ }
+
if (d_in_lookup(direntry)) {
alias = d_splice_alias(inode, direntry);
if (!IS_ERR_OR_NULL(alias))
@@ -599,9 +617,15 @@ int cifs_atomic_open(struct inode *dir,
d_instantiate(direntry, inode);
}
- if ((oflags & (O_CREAT | O_EXCL)) == (O_CREAT | O_EXCL))
+ if (is_regular && opened &&
+ (oflags & (O_CREAT | O_EXCL)) == (O_CREAT | O_EXCL))
file->f_mode |= FMODE_CREATED;
+ if (!is_regular || !opened) {
+ rc = finish_no_open(file, NULL);
+ goto out;
+ }
+
rc = finish_open(file, direntry, generic_file_open);
if (rc) {
if (server->ops->close)
@@ -664,6 +688,7 @@ int cifs_create(struct mnt_idmap *idmap,
struct inode *inode;
struct cifs_fid fid;
__u32 oplock;
+ bool opened;
struct cifs_open_info_data buf = {};
cifs_dbg(FYI, "cifs_create parent inode = 0x%p name is: %pd and dentry = 0x%p\n",
@@ -686,10 +711,10 @@ int cifs_create(struct mnt_idmap *idmap,
server->ops->new_lease_key(&fid);
rc = cifs_do_create(dir, direntry, xid, tlink, oflags,
- mode, &oplock, &fid, &buf, &inode);
+ mode, &oplock, &fid, &buf, &inode, &opened);
if (!rc) {
d_instantiate(direntry, inode);
- if (server->ops->close)
+ if (opened && server->ops->close)
server->ops->close(xid, tcon, &fid);
}
@@ -1082,6 +1107,7 @@ int cifs_tmpfile(struct mnt_idmap *idmap
struct inode *inode;
unsigned int xid;
__u32 oplock;
+ bool opened;
int namelen;
int rc;
@@ -1120,7 +1146,7 @@ int cifs_tmpfile(struct mnt_idmap *idmap
namelen = scnprintf(name, namesize, CIFS_TMPNAME_PREFIX "%x",
atomic_inc_return(&cifs_tmpcounter));
rc = __cifs_do_create(dir, dentry, path, xid, tlink, oflags,
- mode, &oplock, &fid, NULL, &inode);
+ mode, &oplock, &fid, NULL, &inode, &opened);
if (!rc) {
rc = d_mark_tmpfile_name(file, &QSTR_LEN(name, namelen));
if (rc) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 413/457] smb: client: validate POSIX create context length
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (411 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 412/457] smb: client: use finish_no_open() for non-regular inodes Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 414/457] smb: client: close completed creates on compound wait errors Greg Kroah-Hartman
` (54 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit fa2e9900dd2a3f5a1e7ef5a8c5e8d435feedbfcc upstream.
parse_posix_ctxt() reads the fixed nlink, reparse_tag, and mode fields
before checking that the POSIX create context contains them. A short
context can pass the generic checks and still make these fixed-width
reads run past its declared data.
The current in-tree smb2_open_file() path passes a NULL posix pointer,
so this handler is not reached on the ordinary open path. Still require
the POSIX data to cover all three fields before reading them because the
helper performs those unguarded reads. Keep the existing soft-failure
behavior so malformed optional metadata does not fail the open.
Fixes: 69dda3059e7a ("cifs: add SMB2_open() arg to return POSIX data")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -2396,12 +2396,15 @@ static void
parse_posix_ctxt(struct create_context *cc, struct smb2_file_all_info *info,
struct create_posix_rsp *posix)
{
- int sid_len;
u8 *beg = (u8 *)cc + le16_to_cpu(cc->DataOffset);
- u8 *end = beg + le32_to_cpu(cc->DataLength);
+ u32 dlen = le32_to_cpu(cc->DataLength);
+ u8 *end = beg + dlen;
+ int sid_len;
u8 *sid;
memset(posix, 0, sizeof(*posix));
+ if (dlen < 3 * sizeof(__le32))
+ return;
posix->nlink = get_unaligned_le32(beg);
posix->reparse_tag = get_unaligned_le32(beg + 4);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 414/457] smb: client: close completed creates on compound wait errors
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (412 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 413/457] smb: client: validate POSIX create context length Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 415/457] smb: client: delete compound mids on send failure before unlock Greg Kroah-Hartman
` (53 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Frank Sorenson, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
commit 6c5c547f037bc18f0b8d0b5db5a648f8f630ce85 upstream.
compound_send_recv() waits for responses in order. If a later wait is
interrupted, or if a later MID fails during response synchronization, an
earlier CREATE may already have opened a remote handle. The earlier mid
is then released without invoking handle_cancelled_mid(), leaving the
remote handle open because no FID was copied to the caller.
Mark completed earlier mids as cancelled when a compound wait or MID
synchronization aborts. Keep their response buffers attached while the
MIDs are synchronized, and transfer them only after synchronization of
the processed responses, so the release path can inspect successful
CREATE responses and queue SMB2_close() after a later failure. Account for
a remote open only after the close work is allocated and before it is
queued, since the caller has not yet updated num_remote_opens. Mark the
create+close compound used by smb2_unlink() so it is not closed again.
Non-CREATE responses and compounds that already include a close keep their
existing behavior.
Fixes: e0bba0b85481 ("cifs: add compound_send_recv()")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Tested-by: Frank Sorenson <sorenson@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2inode.c | 2 -
fs/smb/client/smb2misc.c | 9 ++++--
fs/smb/client/transport.c | 67 +++++++++++++++++++++++++++++++++++++---------
3 files changed, 61 insertions(+), 17 deletions(-)
--- a/fs/smb/client/smb2inode.c
+++ b/fs/smb/client/smb2inode.c
@@ -1120,7 +1120,7 @@ smb2_unlink(const unsigned int xid, stru
struct kvec close_iov;
int resp_buftype[2];
struct cifs_fid fid;
- int flags = 0;
+ int flags = CIFS_CP_CREATE_CLOSE_OP;
__u8 oplock;
int rc;
--- a/fs/smb/client/smb2misc.c
+++ b/fs/smb/client/smb2misc.c
@@ -821,7 +821,8 @@ smb2_cancelled_close_fid(struct work_str
*/
static int
__smb2_handle_cancelled_cmd(struct cifs_tcon *tcon, __u16 cmd, __u64 mid,
- __u64 persistent_fid, __u64 volatile_fid)
+ __u64 persistent_fid, __u64 volatile_fid,
+ bool account_remote_open)
{
struct close_cancelled_open *cancelled;
@@ -835,6 +836,8 @@ __smb2_handle_cancelled_cmd(struct cifs_
cancelled->cmd = cmd;
cancelled->mid = mid;
INIT_WORK(&cancelled->work, smb2_cancelled_close_fid);
+ if (account_remote_open)
+ atomic_inc(&tcon->num_remote_opens);
WARN_ON(queue_work(cifsiod_wq, &cancelled->work) == false);
return 0;
@@ -871,7 +874,7 @@ smb2_handle_cancelled_close(struct cifs_
spin_unlock(&tcon->tc_lock);
rc = __smb2_handle_cancelled_cmd(tcon, SMB2_CLOSE_HE, 0,
- persistent_fid, volatile_fid);
+ persistent_fid, volatile_fid, false);
if (rc)
cifs_put_tcon(tcon, netfs_trace_tcon_ref_put_cancelled_close);
@@ -899,7 +902,7 @@ smb2_handle_cancelled_mid(struct mid_q_e
le16_to_cpu(hdr->Command),
le64_to_cpu(hdr->MessageId),
rsp->PersistentFileId,
- rsp->VolatileFileId);
+ rsp->VolatileFileId, true);
if (rc)
cifs_put_tcon(tcon, netfs_trace_tcon_ref_put_cancelled_mid);
--- a/fs/smb/client/transport.c
+++ b/fs/smb/client/transport.c
@@ -805,6 +805,18 @@ cifs_cancelled_callback(struct TCP_Serve
release_mid(server, mid);
}
+static void
+cifs_mark_compound_mids_cancelled(struct mid_q_entry **mid, int count)
+{
+ int i;
+
+ for (i = 0; i < count; i++) {
+ spin_lock(&mid[i]->mid_lock);
+ mid[i]->wait_cancelled = true;
+ spin_unlock(&mid[i]->mid_lock);
+ }
+}
+
/*
* cifs_pick_channel - pick an eligible channel for network operations
*
@@ -865,6 +877,7 @@ compound_send_recv(const unsigned int xi
int *resp_buf_type, struct kvec *resp_iov)
{
int i, j, optype, rc = 0;
+ int num_processed = 0;
struct mid_q_entry *mid[MAX_COMPOUND];
bool cancelled_mid[MAX_COMPOUND] = {false};
struct cifs_credits credits[MAX_COMPOUND] = {
@@ -1011,6 +1024,14 @@ compound_send_recv(const unsigned int xi
break;
}
if (rc != 0) {
+ /*
+ * A completed CREATE earlier in the compound chain may have
+ * opened a remote handle even though a later wait was
+ * interrupted. Mark it cancelled so __release_mid() invokes
+ * the existing unmatched-open cleanup.
+ */
+ cifs_mark_compound_mids_cancelled(mid, i);
+
for (; i < num_rqst; i++) {
cifs_server_dbg(FYI, "Cancelling wait for mid %llu cmd: %d\n",
mid[i]->mid, le16_to_cpu(mid[i]->command));
@@ -1033,6 +1054,14 @@ compound_send_recv(const unsigned int xi
rc = cifs_sync_mid_result(mid[i], server);
if (rc != 0) {
+ /*
+ * A previous CREATE may have completed before this
+ * response failed. Mark it cancelled so its remote
+ * handle is closed when the mid is released.
+ */
+ cifs_mark_compound_mids_cancelled(mid, i);
+ /* Keep their response buffers for cancelled-mid cleanup. */
+ num_processed = 0;
/* mark this mid as cancelled to not free it below */
cancelled_mid[i] = true;
goto out;
@@ -1042,13 +1071,24 @@ compound_send_recv(const unsigned int xi
mid[i]->mid_state != MID_RESPONSE_READY) {
rc = smb_EIO1(smb_eio_trace_rx_mid_unready, mid[i]->mid_state);
cifs_dbg(FYI, "Bad MID state?\n");
+ cifs_mark_compound_mids_cancelled(mid, i);
+ num_processed = 0;
goto out;
}
rc = server->ops->check_receive(mid[i], server,
flags & CIFS_LOG_ERROR);
+ num_processed = i + 1;
+ }
- if (resp_iov) {
+out:
+ /*
+ * Delay moving response buffers out of their mids until response
+ * synchronization completes. This lets cancelled-mid cleanup inspect
+ * an earlier CREATE response if a later MID fails.
+ */
+ if (resp_iov) {
+ for (i = 0; i < num_processed; i++) {
buf = (char *)mid[i]->resp_buf;
resp_iov[i].iov_base = buf;
resp_iov[i].iov_len = mid[i]->resp_buf_size;
@@ -1067,21 +1107,22 @@ compound_send_recv(const unsigned int xi
/*
* Compounding is never used during session establish.
*/
- spin_lock(&ses->ses_lock);
- if ((ses->ses_status == SES_NEW) || (optype & CIFS_NEG_OP) || (optype & CIFS_SESS_OP)) {
- struct kvec iov = {
- .iov_base = resp_iov[0].iov_base,
- .iov_len = resp_iov[0].iov_len
- };
- spin_unlock(&ses->ses_lock);
- cifs_server_lock(server);
- smb311_update_preauth_hash(ses, server, &iov, 1);
- cifs_server_unlock(server);
+ if (num_processed == num_rqst) {
spin_lock(&ses->ses_lock);
+ if ((ses->ses_status == SES_NEW) || (optype & CIFS_NEG_OP) || (optype & CIFS_SESS_OP)) {
+ struct kvec iov = {
+ .iov_base = resp_iov[0].iov_base,
+ .iov_len = resp_iov[0].iov_len
+ };
+ spin_unlock(&ses->ses_lock);
+ cifs_server_lock(server);
+ smb311_update_preauth_hash(ses, server, &iov, 1);
+ cifs_server_unlock(server);
+ spin_lock(&ses->ses_lock);
+ }
+ spin_unlock(&ses->ses_lock);
}
- spin_unlock(&ses->ses_lock);
-out:
/*
* This will dequeue all mids. After this it is important that the
* demultiplex_thread will not process any of these mids any further.
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 415/457] smb: client: delete compound mids on send failure before unlock
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (413 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 414/457] smb: client: close completed creates on compound wait errors Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 416/457] xfs: dont assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption Greg Kroah-Hartman
` (52 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+eeb58d2197d88720a228,
Adarsh Das, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adarsh Das <adarshdas950@gmail.com>
commit 8f6f8a48399f82f4a83f7b9f25b9707e0062a4f9 upstream.
When sending a compound request fails, smb_send_rqst() kicks off a
reconnect. compound_send_recv() still has those mids on pending_mid_q,
but it unlocks the server without removing them first.
During reconnect, cifs_abort_connection() walks pending_mid_q and runs
each mid callback. With no response yet, those callbacks return credits
and drop in_flight. Then compound_send_recv()'s send-error path returns
the same credits again. in_flight ends up decremented twice and
smb2_add_credits() WARNs.
syzbot hits this during SMB2_negotiate when the socket send fails.
cifs_call_async() already calls delete_mid() before unlock on send
failure. Do the same for compound chains and set cancelled_mid[] so the
out: path does not delete them again.
Fixes: ee258d79159a ("CIFS: Move credit processing to mid callbacks for SMB3")
Reported-by: syzbot+eeb58d2197d88720a228@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/r/6a727d22.40259c87.584f4.04ce.GAE@google.com
Tested-by: syzbot+eeb58d2197d88720a228@syzkaller.appspotmail.com
Assisted-by: LLM
Cc: stable@vger.kernel.org
Signed-off-by: Adarsh Das <adarshdas950@gmail.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/transport.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/fs/smb/client/transport.c
+++ b/fs/smb/client/transport.c
@@ -978,6 +978,10 @@ compound_send_recv(const unsigned int xi
if (rc < 0) {
revert_current_mid(server, num_rqst);
server->sequence_number -= 2;
+ for (i = 0; i < num_rqst; i++) {
+ delete_mid(server, mid[i]);
+ cancelled_mid[i] = true;
+ }
}
cifs_server_unlock(server);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 416/457] xfs: dont assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (414 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 415/457] smb: client: delete compound mids on send failure before unlock Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 417/457] xfs: fix attr fork block count checks in xrep_inode_blockcounts Greg Kroah-Hartman
` (51 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit afbccf99f7f82117cba9ad4b0b006692030f49e8 upstream.
XFS_SCRUB_TYPE_HEALTHY is a synthentic scrub type so that xfs_scrub can
tell the kernel "Hey, I finished a scan and saw no problems" and have
the kernel forget that it saw indirect evidence of corruption.
Unfortunately, as LOLLM points out, it's possible for the health system
to record a new corruption just before xfs_scrub gets to
XFS_SCRUB_TYPE_HEALTHY. In this case, the existing logic doesn't return
early and instead wanders into unknown regions of type_to_health_flag
and trips the assert because HEALTHY doesn't have a group assignment.
Fix the logic so that we always return early for a HEALTHY scrub type,
even if we decide not to call xchk_mark_all_healthy.
Cc: stable@vger.kernel.org # v6.9
Fixes: a1f3e0cca41036 ("xfs: update health status if we get a clean bill of health")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/health.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/fs/xfs/scrub/health.c
+++ b/fs/xfs/scrub/health.c
@@ -202,9 +202,9 @@ xchk_update_health(
* there's no sick flag defined for it, so we branch here ahead of the
* mask check.
*/
- if (sc->sm->sm_type == XFS_SCRUB_TYPE_HEALTHY &&
- !(sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)) {
- xchk_mark_all_healthy(sc->mp);
+ if (sc->sm->sm_type == XFS_SCRUB_TYPE_HEALTHY) {
+ if (!(sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT))
+ xchk_mark_all_healthy(sc->mp);
return;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 417/457] xfs: fix attr fork block count checks in xrep_inode_blockcounts
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (415 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 416/457] xfs: dont assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 418/457] xfs: release orphanage dir inode if chown fails Greg Kroah-Hartman
` (50 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit bb991b7f79dd34cc5f24db0f736bf75630c970e7 upstream.
LOLLM points out that a file has an attr fork, it will call
xchk_inode_count_blocks to set @ablocks to the number of fsblocks mapped
by the attr fork; but then it'll compare @blocks (aka the count of
fsblocks mapped by the data fork). We already checked that and we never
do anything with @acount, so I think this is clearly a bug. Fix the
comparison.
Cc: stable@vger.kernel.org # v6.8
Fixes: 2d295fe65776d1 ("xfs: repair inode records")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/inode_repair.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/scrub/inode_repair.c
+++ b/fs/xfs/scrub/inode_repair.c
@@ -1702,7 +1702,7 @@ xrep_inode_blockcounts(
&acount);
if (error)
return error;
- if (count >= sc->mp->m_sb.sb_dblocks)
+ if (acount >= sc->mp->m_sb.sb_dblocks)
return -EFSCORRUPTED;
error = xrep_ino_ensure_extent_count(sc, XFS_ATTR_FORK,
nextents);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 418/457] xfs: release orphanage dir inode if chown fails
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (416 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 417/457] xfs: fix attr fork block count checks in xrep_inode_blockcounts Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 419/457] xfs: use correct jiffies comparison function in xchk_maybe_relax Greg Kroah-Hartman
` (49 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 1c32cdc986467eaffeedb6c5334852809555b82d upstream.
LOLLM points out that we leak the igrab'd reference to the orphanage
directory inode if chowning it fails. Fix that.
Cc: stable@vger.kernel.org # v6.10
Fixes: 1e58a8ccf2597c ("xfs: move orphan files to the orphanage")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/orphanage.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/fs/xfs/scrub/orphanage.c
+++ b/fs/xfs/scrub/orphanage.c
@@ -192,12 +192,16 @@ xrep_orphanage_create(
/* Make sure the orphanage is owned by root. */
error = xrep_chown_orphanage(sc, XFS_I(orphanage_inode));
if (error)
- goto out_dput_orphanage;
+ goto out_rele_orphanage;
/* Stash the reference for later and bail out. */
sc->orphanage = XFS_I(orphanage_inode);
sc->orphanage_ilock_flags = 0;
+ orphanage_inode = NULL;
+out_rele_orphanage:
+ if (orphanage_inode)
+ xchk_irele(sc, XFS_I(orphanage_inode));
out_dput_orphanage:
end_creating(orphanage_dentry);
out_dput_root:
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 419/457] xfs: use correct jiffies comparison function in xchk_maybe_relax
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (417 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 418/457] xfs: release orphanage dir inode if chown fails Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 420/457] xfs: check padding field in xfs_ioc_commit_range Greg Kroah-Hartman
` (48 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 984aab2d905a8557fafb27cd9e8713d6d12b3437 upstream.
LOLLM points out that we're supposed to use time_after_eq, not a raw >=
operation here, or else jiffies wraps can go unnoticed. Fix this.
Cc: stable@vger.kernel.org # v6.10
Fixes: 271557de7cbfde ("xfs: reduce the rate of cond_resched calls inside scrub")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/scrub.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/scrub/scrub.h
+++ b/fs/xfs/scrub/scrub.h
@@ -40,7 +40,7 @@ static inline int xchk_maybe_relax(struc
return 0;
widget->resched_nr = 0;
- if (unlikely(widget->next_resched <= jiffies)) {
+ if (unlikely(time_after_eq(jiffies, widget->next_resched))) {
cond_resched();
widget->next_resched = XCHK_RELAX_NEXT;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 420/457] xfs: check padding field in xfs_ioc_commit_range
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (418 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 419/457] xfs: use correct jiffies comparison function in xchk_maybe_relax Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 421/457] xfs: dont call xfs_exchange_range_finish for a dry run Greg Kroah-Hartman
` (47 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 3083ba8dde765a9ab2337f3db68d00724a6b1202 upstream.
LOLLM points out that we don't check the ioctl padding field here, so
let's do that. I don't think there are many users yet since exchrange
requires a new feature flag, so it's a good time to try to plug this
hole.
Cc: stable@vger.kernel.org # v6.12
Fixes: 398597c3ef7fb1 ("xfs: introduce new file range commit ioctls")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_exchrange.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/xfs_exchrange.c
+++ b/fs/xfs/xfs_exchrange.c
@@ -902,7 +902,7 @@ xfs_ioc_commit_range(
if (copy_from_user(&args, argp, sizeof(args)))
return -EFAULT;
- if (args.flags & ~XFS_EXCHANGE_RANGE_ALL_FLAGS)
+ if (args.pad || (args.flags & ~XFS_EXCHANGE_RANGE_ALL_FLAGS))
return -EINVAL;
if (kern_f->magic != XCR_FRESH_MAGIC)
return -EBUSY;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 421/457] xfs: dont call xfs_exchange_range_finish for a dry run
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (419 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 420/457] xfs: check padding field in xfs_ioc_commit_range Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 422/457] xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks Greg Kroah-Hartman
` (46 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 8fc18580ec17f90beac4c933fbe4c74dcd3b7f36 upstream.
LOLLM noticed that we strip file privileges and whatnot even for a dry
run. We also shouldn't flush dirty data to disk or trim COW staging
events for a dry run. Neither of those behaviors are allowed by the
manpage, so fix that by exiting early on DRY_RUN in various functions.
Cc: stable@vger.kernel.org # v6.10
Fixes: 42672471f938cd ("xfs: bind together the front and back ends of the file range exchange code")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_exchrange.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/fs/xfs/xfs_exchrange.c
+++ b/fs/xfs/xfs_exchrange.c
@@ -633,6 +633,9 @@ xfs_exchrange_prep(
if (error)
return error;
+ if (fxr->flags & XFS_EXCHANGE_RANGE_DRY_RUN)
+ return 0;
+
trace_xfs_exchrange_flush(fxr, ip1, ip2);
/* Flush the relevant ranges of both files. */
@@ -709,9 +712,11 @@ xfs_exchrange_contents(
* other file write would do. This may involve turning on support for
* logged xattrs if either file has security capabilities.
*/
- error = xfs_exchange_range_finish(fxr);
- if (error)
- goto out_unlock;
+ if (!(fxr->flags & XFS_EXCHANGE_RANGE_DRY_RUN)) {
+ error = xfs_exchange_range_finish(fxr);
+ if (error)
+ goto out_unlock;
+ }
out_unlock:
xfs_iunlock2_io_mmap(ip1, ip2);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 422/457] xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (420 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 421/457] xfs: dont call xfs_exchange_range_finish for a dry run Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 423/457] xfs: use the correct reservations for rtrmap/refcount recovery Greg Kroah-Hartman
` (45 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit c54110d814c3e8ed6bbbb5e02874994ed9f668ac upstream.
LOLLM complains that xchk_directory_data_bestfree can be passed a
directory block that is either in "block" or "data" format, but the
check here unconditionally treats the dir3_block and dir3_data blocks as
if they have the same header format (they don't). Consequently, we can
incorrectly set the preen state on dir3_block blocks, which of course
we can't preen away because dir3_block blocks do not have a padding
field. Fix this.
Cc: stable@vger.kernel.org # v7.1-rc4
Fixes: 939919ccddfcc3 ("xfs: check directory data block header padding in scrub")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/dir.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/xfs/scrub/dir.c b/fs/xfs/scrub/dir.c
index 2a037aae904d..19d974c7e2b7 100644
--- a/fs/xfs/scrub/dir.c
+++ b/fs/xfs/scrub/dir.c
@@ -492,7 +492,7 @@ xchk_directory_data_bestfree(
goto out;
xchk_buffer_recheck(sc, bp);
- if (xfs_has_crc(sc->mp)) {
+ if (!is_block && xfs_has_crc(sc->mp)) {
struct xfs_dir3_data_hdr *hdr3 = bp->b_addr;
if (hdr3->pad)
--
2.55.0
^ permalink raw reply related [flat|nested] 469+ messages in thread
* [PATCH 7.2 423/457] xfs: use the correct reservations for rtrmap/refcount recovery
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (421 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 422/457] xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 424/457] xfs: check di_forkoff correctly in scrub Greg Kroah-Hartman
` (44 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 471e0b6e2ddac9e16b8dc2153d6e5575fefb8a2f upstream.
LOLLM noticed that we might reserve the wrong number of blocks for
recovering rtrmap and rtrefcount updates after a crash. Fix that.
Cc: stable@vger.kernel.org # v6.14
Fixes: 5e0679d1c62f25 ("xfs: support recovering rmap intent items targetting realtime extents")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_refcount_item.c | 8 ++++++--
fs/xfs/xfs_rmap_item.c | 8 ++++++--
2 files changed, 12 insertions(+), 4 deletions(-)
--- a/fs/xfs/xfs_refcount_item.c
+++ b/fs/xfs/xfs_refcount_item.c
@@ -508,6 +508,7 @@ xfs_refcount_recover_work(
struct xfs_cui_log_item *cuip = CUI_ITEM(lip);
struct xfs_trans *tp;
struct xfs_mount *mp = lip->li_log->l_mp;
+ unsigned int dblocks;
bool isrt = xfs_cui_item_isrt(lip);
int i;
int error = 0;
@@ -543,8 +544,11 @@ xfs_refcount_recover_work(
* full btree split on either end of the refcount range.
*/
resv = xlog_recover_resv(&M_RES(mp)->tr_itruncate);
- error = xfs_trans_alloc(mp, &resv, mp->m_refc_maxlevels * 2, 0,
- XFS_TRANS_RESERVE, &tp);
+ if (isrt)
+ dblocks = mp->m_rtrefc_maxlevels * 2;
+ else
+ dblocks = mp->m_refc_maxlevels * 2;
+ error = xfs_trans_alloc(mp, &resv, dblocks, 0, XFS_TRANS_RESERVE, &tp);
if (error)
return error;
--- a/fs/xfs/xfs_rmap_item.c
+++ b/fs/xfs/xfs_rmap_item.c
@@ -573,6 +573,7 @@ xfs_rmap_recover_work(
struct xfs_rui_log_item *ruip = RUI_ITEM(lip);
struct xfs_trans *tp;
struct xfs_mount *mp = lip->li_log->l_mp;
+ unsigned int dblocks;
bool isrt = xfs_rui_item_isrt(lip);
int i;
int error = 0;
@@ -596,8 +597,11 @@ xfs_rmap_recover_work(
}
resv = xlog_recover_resv(&M_RES(mp)->tr_itruncate);
- error = xfs_trans_alloc(mp, &resv, mp->m_rmap_maxlevels, 0,
- XFS_TRANS_RESERVE, &tp);
+ if (isrt)
+ dblocks = mp->m_rtrmap_maxlevels;
+ else
+ dblocks = mp->m_rmap_maxlevels;
+ error = xfs_trans_alloc(mp, &resv, dblocks, 0, XFS_TRANS_RESERVE, &tp);
if (error)
return error;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 424/457] xfs: check di_forkoff correctly in scrub
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (422 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 423/457] xfs: use the correct reservations for rtrmap/refcount recovery Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 425/457] xfs: fix rtgroup repair estimations Greg Kroah-Hartman
` (43 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit e9193f2f1ce32d02b9230094ffdbfab715ab6137 upstream.
The di_forkoff check in xchk_dinode is incorrect, according to LOLLM.
XFS_DFORK_BOFF returns a byte count relative to the start of the literal
area, not the start of the inode. Therefore, this check won't flag
di_forkoff values that are larger than the literal area but not the
inode size itself. Fix this check; sadly the old APTR code was correct.
Cc: stable@vger.kernel.org # v6.8
Fixes: 6b5d917780219d ("xfs: dont cast to char * for XFS_DFORK_*PTR macros")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/scrub/inode.c
+++ b/fs/xfs/scrub/inode.c
@@ -607,7 +607,7 @@ xchk_dinode(
}
/* di_forkoff */
- if (XFS_DFORK_BOFF(dip) >= mp->m_sb.sb_inodesize)
+ if (dip->di_forkoff >= (XFS_LITINO(mp) >> 3))
xchk_ino_set_corrupt(sc, ino);
if (naextents != 0 && dip->di_forkoff == 0)
xchk_ino_set_corrupt(sc, ino);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 425/457] xfs: fix rtgroup repair estimations
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (423 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 424/457] xfs: check di_forkoff correctly in scrub Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 426/457] xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots Greg Kroah-Hartman
` (42 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 41c4c41cf6c44f98db2916e1781f537d9ba6461a upstream.
When I added online fsck for realtime reflink, I forgot to update
xrep_calc_rtgroup_resblks to factor in the size of the refcount btree
when it guesses how much space we need to start a repair. This hasn't
been a huge problem in practice because there are few filesystems with
(a) realtime, (b) rtgroups, (c) reflink, and (d) no rmap. But let's fix
this before someone stumbles upon it, especially since LOLLM flagged
this for me.
Cc: stable@vger.kernel.org # v6.14
Fixes: 83ccffc489975d ("xfs: online repair of the realtime refcount btree")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/repair.c | 19 +++++++++++++++++--
fs/xfs/scrub/trace.h | 12 ++++++++----
2 files changed, 25 insertions(+), 6 deletions(-)
--- a/fs/xfs/scrub/repair.c
+++ b/fs/xfs/scrub/repair.c
@@ -399,6 +399,7 @@ xrep_calc_rtgroup_resblks(
struct xfs_mount *mp = sc->mp;
struct xfs_scrub_metadata *sm = sc->sm;
uint64_t usedlen;
+ xfs_extlen_t refcbt_sz = 0;
xfs_extlen_t rmapbt_sz = 0;
if (!(sm->sm_flags & XFS_SCRUB_IFLAG_REPAIR))
@@ -411,13 +412,27 @@ xrep_calc_rtgroup_resblks(
usedlen = xfs_rtbxlen_to_blen(mp, xfs_rtgroup_extents(mp, sm->sm_agno));
ASSERT(usedlen <= XFS_MAX_RGBLOCKS);
+ if (xfs_has_reflink(mp))
+ refcbt_sz = xfs_rtrefcountbt_calc_size(mp, usedlen);
+
if (xfs_has_rmapbt(mp))
rmapbt_sz = xfs_rtrmapbt_calc_size(mp, usedlen);
+ /*
+ * Guess how many blocks we need to rebuild the rmapbt. For
+ * non-reflink filesystems we can't have more records than used blocks.
+ * However, with reflink it's possible to have more than one rmap
+ * record per rtgroup block. We don't know how many rmaps there could
+ * be in the rtgroup, so we start off with what we hope is an generous
+ * over-estimation.
+ */
+ if (refcbt_sz > 0 && rmapbt_sz > 0)
+ rmapbt_sz *= 2;
+
trace_xrep_calc_rtgroup_resblks_btsize(mp, sm->sm_agno, usedlen,
- rmapbt_sz);
+ rmapbt_sz, refcbt_sz);
- return rmapbt_sz;
+ return max(rmapbt_sz, refcbt_sz);
}
#endif /* CONFIG_XFS_RT */
--- a/fs/xfs/scrub/trace.h
+++ b/fs/xfs/scrub/trace.h
@@ -2376,25 +2376,29 @@ TRACE_EVENT(xrep_calc_ag_resblks_btsize,
#ifdef CONFIG_XFS_RT
TRACE_EVENT(xrep_calc_rtgroup_resblks_btsize,
TP_PROTO(struct xfs_mount *mp, xfs_rgnumber_t rgno,
- xfs_rgblock_t usedlen, xfs_rgblock_t rmapbt_sz),
- TP_ARGS(mp, rgno, usedlen, rmapbt_sz),
+ xfs_rgblock_t usedlen, xfs_rgblock_t rmapbt_sz,
+ xfs_rgblock_t refcbt_sz),
+ TP_ARGS(mp, rgno, usedlen, rmapbt_sz, refcbt_sz),
TP_STRUCT__entry(
__field(dev_t, dev)
__field(xfs_rgnumber_t, rgno)
__field(xfs_rgblock_t, usedlen)
__field(xfs_rgblock_t, rmapbt_sz)
+ __field(xfs_rgblock_t, refcbt_sz)
),
TP_fast_assign(
__entry->dev = mp->m_super->s_dev;
__entry->rgno = rgno;
__entry->usedlen = usedlen;
__entry->rmapbt_sz = rmapbt_sz;
+ __entry->refcbt_sz = refcbt_sz;
),
- TP_printk("dev %d:%d rgno 0x%x usedlen %u rmapbt %u",
+ TP_printk("dev %d:%d rgno 0x%x usedlen %u rmapbt %u refcountbt %u",
MAJOR(__entry->dev), MINOR(__entry->dev),
__entry->rgno,
__entry->usedlen,
- __entry->rmapbt_sz)
+ __entry->rmapbt_sz,
+ __entry->refcbt_sz)
);
#endif /* CONFIG_XFS_RT */
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 426/457] xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (424 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 425/457] xfs: fix rtgroup repair estimations Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 427/457] xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits Greg Kroah-Hartman
` (41 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit fe2f9135df43db849e74f03956d322ac20b59af7 upstream.
LOLLM noticed that the inode btree root formatting methods copy too many
bytes -- there's only one set of keys in node blocks, not two. This
causes memory corruption of whatever's beyond the buffers.
Cc: stable@vger.kernel.org # v6.14
Fixes: f0415af60f482a ("xfs: wire up a new metafile type for the realtime refcount")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_rtrefcount_btree.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/fs/xfs/libxfs/xfs_rtrefcount_btree.c
+++ b/fs/xfs/libxfs/xfs_rtrefcount_btree.c
@@ -617,7 +617,7 @@ xfs_rtrefcountbt_from_disk(
fpp = xfs_rtrefcount_droot_ptr_addr(dblock, 1, maxrecs);
tpp = xfs_rtrefcount_broot_ptr_addr(mp, rblock, 1, rblocklen);
numrecs = be16_to_cpu(dblock->bb_numrecs);
- memcpy(tkp, fkp, 2 * sizeof(*fkp) * numrecs);
+ memcpy(tkp, fkp, sizeof(*fkp) * numrecs);
memcpy(tpp, fpp, sizeof(*fpp) * numrecs);
} else {
frp = xfs_rtrefcount_droot_rec_addr(dblock, 1);
@@ -703,7 +703,7 @@ xfs_rtrefcountbt_to_disk(
fpp = xfs_rtrefcount_broot_ptr_addr(mp, rblock, 1, rblocklen);
tpp = xfs_rtrefcount_droot_ptr_addr(dblock, 1, maxrecs);
numrecs = be16_to_cpu(rblock->bb_numrecs);
- memcpy(tkp, fkp, 2 * sizeof(*fkp) * numrecs);
+ memcpy(tkp, fkp, sizeof(*fkp) * numrecs);
memcpy(tpp, fpp, sizeof(*fpp) * numrecs);
} else {
frp = xfs_rtrefcount_rec_addr(rblock, 1);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 427/457] xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (425 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 426/457] xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 428/457] xfs: dont let hidden_space go negative in xfs_metafile_resv_init Greg Kroah-Hartman
` (40 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 065f3ce5936e68da75f3dc18201d290073d78f3c upstream.
Now that we have quotas for the realtime volume, we also have
precomputed watermark limits for the realtime block counts. These
precomputations should be done any time we change the rtb limits, which
means that xfs_qm_adjust_dqlimits needs to ensure that if we installed
a default rtb limit.
Cc: stable@vger.kernel.org # v6.13
Fixes: 5dd70852b03901 ("xfs: create quota preallocation watermarks for realtime quota")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_dquot.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/fs/xfs/xfs_dquot.c
+++ b/fs/xfs/xfs_dquot.c
@@ -139,10 +139,14 @@ xfs_qm_adjust_dqlimits(
dq->q_ino.softlimit = defq->ino.soft;
if (!dq->q_ino.hardlimit)
dq->q_ino.hardlimit = defq->ino.hard;
- if (!dq->q_rtb.softlimit)
+ if (!dq->q_rtb.softlimit) {
dq->q_rtb.softlimit = defq->rtb.soft;
- if (!dq->q_rtb.hardlimit)
+ prealloc = 1;
+ }
+ if (!dq->q_rtb.hardlimit) {
dq->q_rtb.hardlimit = defq->rtb.hard;
+ prealloc = 1;
+ }
if (prealloc)
xfs_dquot_set_prealloc_limits(dq);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 428/457] xfs: dont let hidden_space go negative in xfs_metafile_resv_init
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (426 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 427/457] xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 429/457] xfs: dont let memory failures leak blocks and kill repairs Greg Kroah-Hartman
` (39 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 476582d754cdc5110f806001417fea6c77824c13 upstream.
LOLLM points out that if the amount of fdblocks that we can reserve for
a metadata btree file goes below the space already used by that file,
then the hidden_space subtraction can underflow, causing
xfs_dec_fdblocks to subtract a huge amount of space. We never want the
target to be less than the used sapce, so fix the logic that adjusts
dblocks_avail downwards.
Also fix an error in the adjacent comment.
Cc: stable@vger.kernel.org # v6.15
Fixes: 1df8d75030b787 ("xfs: make metabtree reservations global")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_metafile.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/fs/xfs/libxfs/xfs_metafile.c
+++ b/fs/xfs/libxfs/xfs_metafile.c
@@ -297,14 +297,14 @@ xfs_metafile_resv_init(
goto out_unlock;
/*
- * Space taken by the per-AG metadata btrees are accounted on-disk as
- * used space. We therefore only hide the space that is reserved but
- * not used by the trees.
+ * Space taken by metadata btrees are accounted on-disk as used space.
+ * We therefore only hide the space that is reserved but not used by
+ * the trees.
*/
if (used > target)
target = used;
else if (target > dblocks_avail)
- target = dblocks_avail;
+ target = max(dblocks_avail, used);
hidden_space = target - used;
error = xfs_dec_fdblocks(mp, hidden_space, true);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 429/457] xfs: dont let memory failures leak blocks and kill repairs
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (427 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 428/457] xfs: dont let hidden_space go negative in xfs_metafile_resv_init Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 430/457] xfs: dont merge different file IO error types Greg Kroah-Hartman
` (38 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit ab1c416d2377cdc16123ef521aac4da1c468c3d4 upstream.
LOLLM complains that a memory allocation failure in
xrep_newbt_add_blocks results in online repair leaking blocks that were
previously allocated to write a new btree, but the problem is worse than
that -- a limitation of the codebase is that the callers cannot undo the
transaction /and/ return the error -- either you undo all changes and
commit the transaction, or you error out and the filesystem goes down.
However, the new btree space reservation object isn't that big (~48
bytes). Let's just do a NOFAIL allocation and the problem goes away.
Cc: stable@vger.kernel.org # v6.8
Fixes: be408417630427 ("xfs: implement block reservation accounting for btrees we're staging")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/newbt.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
--- a/fs/xfs/scrub/newbt.c
+++ b/fs/xfs/scrub/newbt.c
@@ -193,9 +193,11 @@ xrep_newbt_add_blocks(
struct xrep_newbt_resv *resv;
int error;
- resv = kmalloc_obj(struct xrep_newbt_resv, XCHK_GFP_FLAGS);
- if (!resv)
- return -ENOMEM;
+ /*
+ * We have no way to clean up the allocated space *and* return an
+ * ENOMEM if we fail to allocate this control structure.
+ */
+ resv = kmalloc_obj(struct xrep_newbt_resv, GFP_KERNEL | __GFP_NOFAIL);
INIT_LIST_HEAD(&resv->list);
resv->agbno = XFS_FSB_TO_AGBNO(mp, args->fsbno);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 430/457] xfs: dont merge different file IO error types
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (428 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 429/457] xfs: dont let memory failures leak blocks and kill repairs Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 431/457] xfs: drop dquot flush lock when we cant find a buffer to flush Greg Kroah-Hartman
` (37 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit d80993655f7be2a461c0a63e2022da5757f47dac upstream.
LOLLM noticed that we can accidentally merge file range health
monitoring events even if they have different errors. We shouldn't do
that.
Cc: stable@vger.kernel.org # v7.0
Fixes: dfa8bad3a8796c ("xfs: convey file I/O errors to the health monitor")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_healthmon.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/fs/xfs/xfs_healthmon.c
+++ b/fs/xfs/xfs_healthmon.c
@@ -245,7 +245,9 @@ xfs_healthmon_merge_events(
case XFS_HEALTHMON_DIOWRITE:
case XFS_HEALTHMON_DATALOST:
/* logically adjacent file ranges can merge */
- if (existing->fino != new->fino || existing->fgen != new->fgen)
+ if (existing->fino != new->fino ||
+ existing->fgen != new->fgen ||
+ existing->error != new->error)
return false;
if (existing->fpos + existing->flen == new->fpos) {
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 431/457] xfs: drop dquot flush lock when we cant find a buffer to flush
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (429 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 430/457] xfs: dont merge different file IO error types Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 432/457] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
` (36 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit ffb48dccce1960a9ea24463a2f3c21d124d6b672 upstream.
LOLLM noticed that xfs_qm_flush_one fails to drop the dquot flush lock
if it can't grab the buffer associated with the dquot. Since there's no
buffer, nobody else is going to drop the dqflock, so we need to do it
ourselves.
Cc: stable@vger.kernel.org # v6.13
Fixes: ca378189fdfa89 ("xfs: convert quotacheck to attach dquot buffers")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_qm.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/fs/xfs/xfs_qm.c
+++ b/fs/xfs/xfs_qm.c
@@ -1432,16 +1432,22 @@ xfs_qm_flush_one(
error = xfs_dquot_use_attached_buf(dqp, &bp);
if (error)
- goto out_unlock;
+ goto out_dqflock;
if (!bp) {
error = -EFSCORRUPTED;
- goto out_unlock;
+ goto out_dqflock;
}
error = xfs_qm_dqflush(dqp, bp);
if (!error)
xfs_buf_delwri_queue(bp, buffer_list);
xfs_buf_relse(bp);
+ mutex_unlock(&dqp->q_qlock);
+ xfs_qm_dqrele(dqp);
+ return error;
+
+out_dqflock:
+ xfs_dqfunlock(dqp);
out_unlock:
mutex_unlock(&dqp->q_qlock);
xfs_qm_dqrele(dqp);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 432/457] xfs: fix blockgc group quota scanning when usrquota isnt enforced
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (430 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 431/457] xfs: drop dquot flush lock when we cant find a buffer to flush Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 433/457] xfs: fix cursor and pointer handling when recovering iunlink buckets Greg Kroah-Hartman
` (35 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit f8f6382ff13109e19d0fc1d0224ff7d29641e56a upstream.
LOLLM noticed the copy-paste error here -- if user quotas aren't
enforced but we're near the group quota limit, we fail to set FLAG_GID
and hence we might not actually free any preallocations, causing
unnecessary EDQUOT. Fix that.
Cc: stable@vger.kernel.org # v5.12
Fixes: c237dd7c709432 ("xfs: flush eof/cowblocks if we can't reserve quota for inode creation")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_icache.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/xfs/xfs_icache.c
+++ b/fs/xfs/xfs_icache.c
@@ -1656,7 +1656,7 @@ xfs_blockgc_free_dquots(
do_work = true;
}
- if (XFS_IS_UQUOTA_ENFORCED(mp) && gdqp && xfs_dquot_lowsp(gdqp)) {
+ if (XFS_IS_GQUOTA_ENFORCED(mp) && gdqp && xfs_dquot_lowsp(gdqp)) {
icw.icw_gid = make_kgid(mp->m_super->s_user_ns, gdqp->q_id);
icw.icw_flags |= XFS_ICWALK_FLAG_GID;
do_work = true;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 433/457] xfs: fix cursor and pointer handling when recovering iunlink buckets
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (431 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 432/457] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 434/457] drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms Greg Kroah-Hartman
` (34 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Darrick J. Wong, Christoph Hellwig,
Carlos Maiolino
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Darrick J. Wong <djwong@kernel.org>
commit 65f39d09d73718611cee40399179323b5d4ead00 upstream.
LOLLM pointed out a bug in xlog_recover_iunlink_bucket:
1. We don't null out prev_ip after releasing it, which can lead to UAF
problems if the inodegc flush call in the loop fails.
at which point I noticed even more bugs:
2. If the inodegc flush inside the loop fails, we also leak @ip.
3. We set prev_agino to agino having already advanced agino, which
results in inodes with i_prev_unlinked set to itself.
4. If we exit the bottom of the loop with prev_ip set, then prev_ip
aliases ip and we also set its i_prev_unlinked to itself.
Bugs 3 and 4 introduce loops into the unlinked list, though these loops
don't surface because we immediately flush each unlinked inode after
loading it.
Fix all of these issues.
Cc: stable@vger.kernel.org # v6.0
Fixes: 04755d2e5821b3 ("xfs: refactor xlog_recover_process_iunlinks()")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Assisted-by: LOLLM # finding obvious bugs
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/xfs_log_recover.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
--- a/fs/xfs/xfs_log_recover.c
+++ b/fs/xfs/xfs_log_recover.c
@@ -2736,12 +2736,13 @@ xlog_recover_iunlink_bucket(
{
struct xfs_mount *mp = pag_mount(pag);
struct xfs_inode *prev_ip = NULL;
- struct xfs_inode *ip;
xfs_agino_t prev_agino, agino;
int error = 0;
agino = be32_to_cpu(agi->agi_unlinked[bucket]);
while (agino != NULLAGINO) {
+ struct xfs_inode *ip;
+
error = xfs_iget(mp, NULL, xfs_agino_to_ino(pag, agino), 0, 0,
&ip);
if (error)
@@ -2750,11 +2751,11 @@ xlog_recover_iunlink_bucket(
ASSERT(VFS_I(ip)->i_nlink == 0);
ASSERT(VFS_I(ip)->i_mode != 0);
xfs_iflags_clear(ip, XFS_IRECOVERY);
- agino = ip->i_next_unlinked;
if (prev_ip) {
ip->i_prev_unlinked = prev_agino;
xfs_irele(prev_ip);
+ prev_ip = NULL;
/*
* Ensure the inode is removed from the unlinked list
@@ -2766,18 +2767,20 @@ xlog_recover_iunlink_bucket(
* complete.
*/
error = xfs_inodegc_flush(mp);
- if (error)
- break;
+ if (error) {
+ xfs_irele(ip);
+ return error;
+ }
}
prev_agino = agino;
+ agino = ip->i_next_unlinked;
prev_ip = ip;
}
if (prev_ip) {
int error2;
- ip->i_prev_unlinked = prev_agino;
xfs_irele(prev_ip);
error2 = xfs_inodegc_flush(mp);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 434/457] drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (432 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 433/457] xfs: fix cursor and pointer handling when recovering iunlink buckets Greg Kroah-Hartman
@ 2026-09-30 15:28 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 435/457] landlock: Work around gcc-16 -Wuninitialized warning Greg Kroah-Hartman
` (33 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:28 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tangudu Tilak Tirumalesh,
Vinay Belgaumkar, Matt Roper, Rodrigo Vivi, Thomas Hellström
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
commit cc319238e3f6668f867beb381ce93727c69b7317 upstream.
Avoid programming the IDLEDLY timer to less than 5 microseconds.
Apply wa_14025941587 to Graphics Versions 20.01 to 35.11
and Media Versions 13.01 to 35.03
v2: Use xe_rtp_match_not_sriov_vf, move to local variable
Remove warn and other knits - Matt R
v3: Add verbose comment - Tejas
v4: Restore IDLE_DLY register on engine reset.
Add it to GUC save-restore list. -Vivek
v5: Extend WA to Media Versions 13.01 to 35.03 - Vinay
v6: Avoid clearing inhibit switch - Bala
Refactor code accordingly by adding idle_reg_val.
v7: Rebased with the divide-by-zero/overflow guards living in
a separate hardening patch.
v8: Preserve the Wa_16023105232 floor (DIV_ROUND_DOWN_ULL) and the
maxcnt == 0 guard from the hardening patch. Round up
(DIV_ROUND_UP_ULL) the Wa_14025941587 minimum conversion instead,
so the tick-quantized delay cannot round back below 5 us.
v9: Evaluate the Wa_16023105232 xe_gt_WARN_ON() against the value
read from hardware instead of the Wa_14025941587-bumped value,
so it no longer fires on the driver's own floor. Re-check the
rounded-up tick value against maxcnt and floor it if tick
quantization pushed it back to/above maxcnt, logging via
xe_gt_dbg since this is the driver's own value, not a hardware
anomaly.
Assisted-by: GitHub_Copilot:claude-opus-4.8
Signed-off-by: Tangudu Tilak Tirumalesh <tilak.tirumalesh.tangudu@intel.com>
Reviewed-by: Vinay Belgaumkar <vinay.belgaumkar@intel.com>
Link: https://patch.msgid.link/20260916100545.779894-3-tilak.tirumalesh.tangudu@intel.com
Signed-off-by: Matt Roper <matthew.d.roper@intel.com>
(cherry picked from commit 9453c528fc909076468ff10df1c2e334ca5a9b00)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
---
drivers/gpu/drm/xe/xe_guc_ads.c | 2
drivers/gpu/drm/xe/xe_hw_engine.c | 93 ++++++++++++++++++++++++++++++-------
drivers/gpu/drm/xe/xe_wa_oob.rules | 2
3 files changed, 79 insertions(+), 18 deletions(-)
--- a/drivers/gpu/drm/xe/xe_guc_ads.c
+++ b/drivers/gpu/drm/xe/xe_guc_ads.c
@@ -791,7 +791,7 @@ static unsigned int guc_mmio_regset_writ
}
}
- if (XE_GT_WA(hwe->gt, 16023105232))
+ if (XE_GT_WA(hwe->gt, 16023105232) || XE_GT_WA(hwe->gt, 14025941587))
guc_mmio_regset_write_one(ads, regset_map,
RING_IDLEDLY(hwe->mmio_base),
count++);
--- a/drivers/gpu/drm/xe/xe_hw_engine.c
+++ b/drivers/gpu/drm/xe/xe_hw_engine.c
@@ -577,44 +577,103 @@ static void hw_engine_init_early(struct
xe_reg_whitelist_process_engine(hwe);
}
+static u32 idledly_floor_ticks(u32 idledly_ns, u32 idledly_units_ps)
+{
+ return DIV_ROUND_DOWN_ULL((u64)idledly_ns * 1000, idledly_units_ps);
+}
+
static void adjust_idledly(struct xe_hw_engine *hwe)
{
struct xe_gt *gt = hwe->gt;
- u32 idledly, maxcnt;
+ u32 idledly, idledly_hw, idledly_reg_val, maxcnt;
u32 idledly_units_ps = 8 * gt->info.timestamp_base;
u32 maxcnt_units_ns = 640;
- bool inhibit_switch = 0;
+ bool inhibit_switch = false;
bool wa_applied = false;
+ bool clamped_below_maxcnt = false;
+
+ if ((!IS_SRIOV_VF(gt_to_xe(gt)) && XE_GT_WA(gt, 16023105232)) ||
+ XE_GT_WA(gt, 14025941587)) {
+ u32 mincnt_idledly_ns = 5000;
- if (!IS_SRIOV_VF(gt_to_xe(gt)) && XE_GT_WA(gt, 16023105232)) {
/* xe_gt_clock_init() warns and zeroes timestamp_base on unknown crystal clock. */
if (!idledly_units_ps)
return;
- idledly = xe_mmio_read32(>->mmio, RING_IDLEDLY(hwe->mmio_base));
+ idledly_reg_val = xe_mmio_read32(>->mmio, RING_IDLEDLY(hwe->mmio_base));
maxcnt = xe_mmio_read32(>->mmio, RING_PWRCTX_MAXCNT(hwe->mmio_base));
- inhibit_switch = idledly & INHIBIT_SWITCH_UNTIL_PREEMPTED;
- idledly = REG_FIELD_GET(IDLE_DELAY, idledly);
+ inhibit_switch = idledly_reg_val & INHIBIT_SWITCH_UNTIL_PREEMPTED;
+ idledly = REG_FIELD_GET(IDLE_DELAY, idledly_reg_val);
idledly = DIV_ROUND_CLOSEST_ULL((u64)idledly * idledly_units_ps, 1000);
+ idledly_hw = idledly;
maxcnt = REG_FIELD_GET(IDLE_WAIT_TIME, maxcnt);
maxcnt *= maxcnt_units_ns;
- /* Clear the inhibit switch without disturbing a valid delay. */
- if (inhibit_switch)
+ /*
+ * Wa_14025941587 is applied before Wa_16023105232, which takes
+ * priority if the two ever conflict (not expected in practice).
+ */
+ if (XE_GT_WA(gt, 14025941587) &&
+ idledly < mincnt_idledly_ns) {
+ idledly = mincnt_idledly_ns;
wa_applied = true;
+ }
- if (xe_gt_WARN_ON(gt, idledly >= maxcnt)) {
- /* Floor below maxcnt; write 0 to still clear the inhibit bit. */
- idledly = maxcnt ?
- DIV_ROUND_DOWN_ULL((u64)(maxcnt - 1) * 1000,
- idledly_units_ps) : 0;
- wa_applied = true;
+ if (XE_GT_WA(gt, 16023105232)) {
+ /* Clear the inhibit switch without disturbing a valid delay. */
+ if (inhibit_switch) {
+ idledly_reg_val &= ~INHIBIT_SWITCH_UNTIL_PREEMPTED;
+ wa_applied = true;
+ }
+
+ /* Warn only on the value read from hardware. */
+ xe_gt_WARN_ON(gt, idledly_hw >= maxcnt);
+
+ if (idledly >= maxcnt) {
+ /* maxcnt may be 0 if IDLE_WAIT_TIME is unprogrammed. */
+ idledly = maxcnt ? maxcnt - 1 : 0;
+ clamped_below_maxcnt = true;
+ wa_applied = true;
+ }
}
- if (wa_applied)
- xe_mmio_write32(>->mmio, RING_IDLEDLY(hwe->mmio_base),
- REG_FIELD_PREP(IDLE_DELAY, idledly));
+ if (wa_applied) {
+ u32 idledly_ticks;
+
+ /*
+ * Wa_16023105232 requires idledly < maxcnt, so floor
+ * that clamp; otherwise round up to guarantee the
+ * Wa_14025941587 minimum survives tick quantization.
+ */
+ if (clamped_below_maxcnt)
+ idledly_ticks = idledly_floor_ticks(idledly, idledly_units_ps);
+ else
+ idledly_ticks = DIV_ROUND_UP_ULL((u64)idledly * 1000,
+ idledly_units_ps);
+
+ /*
+ * Tick quantization can still push the rounded-up value
+ * to/above maxcnt; re-floor here so Wa_16023105232 keeps
+ * priority even in that case.
+ */
+ if (!clamped_below_maxcnt && XE_GT_WA(gt, 16023105232) &&
+ (u64)idledly_ticks * idledly_units_ps >= (u64)maxcnt * 1000) {
+ xe_gt_dbg(gt, "idledly %s: %u ticks would exceed maxcnt=%u, so flooring\n",
+ hwe->name, idledly_ticks, maxcnt);
+ idledly = maxcnt ? maxcnt - 1 : 0;
+ idledly_ticks = idledly_floor_ticks(idledly, idledly_units_ps);
+ }
+
+ idledly_reg_val &= ~IDLE_DELAY;
+ idledly_reg_val |= REG_FIELD_PREP(IDLE_DELAY, idledly_ticks);
+ xe_gt_dbg(gt, "idledly %s: set %u max=%u inh=%u ts=%u\n",
+ hwe->name, idledly, maxcnt,
+ !!inhibit_switch, gt->info.timestamp_base);
+ xe_mmio_write32(>->mmio,
+ RING_IDLEDLY(hwe->mmio_base),
+ idledly_reg_val);
+ }
}
}
--- a/drivers/gpu/drm/xe/xe_wa_oob.rules
+++ b/drivers/gpu/drm/xe/xe_wa_oob.rules
@@ -65,3 +65,5 @@
14025883347 MEDIA_VERSION_RANGE(1301, 3500)
GRAPHICS_VERSION_RANGE(2004, 3005)
+14025941587 GRAPHICS_VERSION_RANGE(2001, 3511), FUNC(xe_rtp_match_not_sriov_vf)
+ MEDIA_VERSION_RANGE(1301, 3503), FUNC(xe_rtp_match_not_sriov_vf)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 435/457] landlock: Work around gcc-16 -Wuninitialized warning
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (433 preceding siblings ...)
2026-09-30 15:28 ` [PATCH 7.2 434/457] drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 436/457] accel/ivpu: Use threaded IRQ for IPC callback processing Greg Kroah-Hartman
` (32 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arnd Bergmann,
Mickaël Salaün
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
commit c4e941bb7654bcbdfb0b6f3341dc2acfdf235c8d upstream.
gcc has a bug with -ftrivial-auto-var-init=pattern that produces a
warning for correct code that uses sparse bitfields:
security/landlock/fs.c: In function 'is_access_to_paths_allowed.isra':
security/landlock/fs.c:767:28: error: '_layer_masks_child1' is used uninitialized [-Werror=uninitialized]
767 | struct layer_masks _layer_masks_child1, _layer_masks_child2;
| ^~~~~~~~~~~~~~~~~~~
security/landlock/fs.c:767:28: note: '_layer_masks_child1' declared here
767 | struct layer_masks _layer_masks_child1, _layer_masks_child2;
| ^~~~~~~~~~~~~~~~~~~
security/landlock/fs.c: In function 'hook_unix_find':
security/landlock/fs.c:1649:28: error: 'layer_masks' is used uninitialized [-Werror=uninitialized]
1649 | struct layer_masks layer_masks;
| ^~~~~~~~~~~
security/landlock/fs.c:1649:28: note: 'layer_masks' declared here
1649 | struct layer_masks layer_masks;
| ^~~~~~~~~~~
To work around this, change the definition of struct layer_mask to
use an explictit padding field.
Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=110743
Link: https://lore.kernel.org/all/20260619082133.3504146-1-arnd@kernel.org/
Fixes: a260c0055665 ("landlock: Add a place for flags to layer rules")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260915201036.3527935-1-arnd@kernel.org
[mic: Use BITS_PER_TYPE(), fix kdoc warnings, fix commit message
according to v2 changes]
Cc: stable@vger.kernel.org
[mic: Backport: use CONFIG_AUDIT to calculate the padding width]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/landlock/access.h | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/security/landlock/access.h
+++ b/security/landlock/access.h
@@ -61,6 +61,10 @@ union access_masks_all {
static_assert(sizeof(typeof_member(union access_masks_all, masks)) ==
sizeof(typeof_member(union access_masks_all, all)));
+#define _LANDLOCK_LAYER_MASK_PADDING \
+ (BITS_PER_TYPE(access_mask_t) - LANDLOCK_NUM_ACCESS_MAX - \
+ IS_ENABLED(CONFIG_AUDIT))
+
/**
* struct layer_mask - The access rights and rule flags for a layer.
*
@@ -81,6 +85,10 @@ struct layer_mask {
*/
access_mask_t quiet : 1;
#endif /* CONFIG_AUDIT */
+ /**
+ * @__pad: Padding for the compiler's bitfield initialization.
+ */
+ access_mask_t __pad : _LANDLOCK_LAYER_MASK_PADDING;
} __packed __aligned(sizeof(access_mask_t));
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 436/457] accel/ivpu: Use threaded IRQ for IPC callback processing
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (434 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 435/457] landlock: Work around gcc-16 -Wuninitialized warning Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 437/457] accel/ivpu: Use separate flag for job timeout Greg Kroah-Hartman
` (31 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrzej Kacprowski, Karol Wachowski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karol Wachowski <karol.wachowski@linux.intel.com>
[ Upstream commit 85c9cc2d25f80534c1623621264018a655869cb2 ]
Dispatching IPC callbacks from system_percpu_wq adds scheduling latency
that is neither bounded nor predictable, which hurts job completion
turnaround. Handle them from a threaded IRQ instead: the hard-IRQ
handler drains the IPC FIFO and wakes the thread, which runs the
callback consumers such as job-done processing.
Job resource teardown can trigger IOMMU unmapping and context teardown,
which is too slow to run from the IRQ thread. Defer it to a dedicated
WQ_UNBOUND | WQ_MEM_RECLAIM workqueue via a per-device lockless list.
UNBOUND keeps the long-running cleanup off the percpu workers and
MEM_RECLAIM guarantees forward progress because the work frees buffer
objects. The runtime PM reference taken at submission is released only
after cleanup completes, otherwise runtime suspend could race the
pending work and deadlock.
Because cleanup is now asynchronous, userspace that rapidly recycles
file descriptors or command queues can momentarily observe stale
per-context resources and fail with -EMFILE or -EBUSY. Flush the
cleanup work once and retry before giving up.
Reviewed-by: Andrzej Kacprowski <andrzej.kacprowski@linux.intel.com>
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
Link: https://patch.msgid.link/20260611055201.948726-1-karol.wachowski@linux.intel.com
Stable-dep-of: 72b782097e53 ("accel/ivpu: Use separate flag for job timeout")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/accel/ivpu/ivpu_drv.c | 28 +++++++++++++++++--
drivers/accel/ivpu/ivpu_drv.h | 5 ++-
drivers/accel/ivpu/ivpu_hw.c | 4 ++
drivers/accel/ivpu/ivpu_ipc.c | 8 ++---
drivers/accel/ivpu/ivpu_ipc.h | 2 -
drivers/accel/ivpu/ivpu_job.c | 59 +++++++++++++++++++++++++++++++++++++-----
drivers/accel/ivpu/ivpu_job.h | 7 ++++
7 files changed, 96 insertions(+), 17 deletions(-)
--- a/drivers/accel/ivpu/ivpu_drv.c
+++ b/drivers/accel/ivpu/ivpu_drv.c
@@ -307,6 +307,11 @@ static int ivpu_open(struct drm_device *
return -ENODEV;
limits = ivpu_user_limits_get(vdev);
+ if (IS_ERR(limits) && PTR_ERR(limits) == -EMFILE) {
+ /* Context limit may be held by jobs pending deferred cleanup */
+ flush_work(&vdev->job_destroy_work);
+ limits = ivpu_user_limits_get(vdev);
+ }
if (IS_ERR(limits)) {
ret = PTR_ERR(limits);
goto err_dev_exit;
@@ -510,9 +515,9 @@ void ivpu_prepare_for_reset(struct ivpu_
{
ivpu_hw_irq_disable(vdev);
disable_irq(vdev->irq);
- flush_work(&vdev->irq_ipc_work);
flush_work(&vdev->irq_dct_work);
flush_work(&vdev->context_abort_work);
+ flush_work(&vdev->job_destroy_work);
ivpu_ipc_disable(vdev);
ivpu_mmu_disable(vdev);
}
@@ -584,6 +589,11 @@ static const struct drm_driver driver =
.major = 1,
};
+static void ivpu_destroy_workqueue(void *wq)
+{
+ destroy_workqueue(wq);
+}
+
static int ivpu_irq_init(struct ivpu_device *vdev)
{
struct pci_dev *pdev = to_pci_dev(vdev->drm.dev);
@@ -595,16 +605,26 @@ static int ivpu_irq_init(struct ivpu_dev
return ret;
}
- INIT_WORK(&vdev->irq_ipc_work, ivpu_ipc_irq_work_fn);
INIT_WORK(&vdev->irq_dct_work, ivpu_pm_irq_dct_work_fn);
INIT_WORK(&vdev->context_abort_work, ivpu_context_abort_work_fn);
+ init_llist_head(&vdev->job_destroy_list);
+ INIT_WORK(&vdev->job_destroy_work, ivpu_job_destroy_work_fn);
+
+ vdev->job_destroy_wq = alloc_workqueue("ivpu_job_destroy", WQ_UNBOUND | WQ_MEM_RECLAIM, 0);
+ if (!vdev->job_destroy_wq)
+ return -ENOMEM;
+
+ ret = devm_add_action_or_reset(vdev->drm.dev, ivpu_destroy_workqueue, vdev->job_destroy_wq);
+ if (ret)
+ return ret;
ivpu_irq_handlers_init(vdev);
vdev->irq = pci_irq_vector(pdev, 0);
- ret = devm_request_irq(vdev->drm.dev, vdev->irq, ivpu_hw_irq_handler,
- IRQF_NO_AUTOEN, DRIVER_NAME, vdev);
+ ret = devm_request_threaded_irq(vdev->drm.dev, vdev->irq, ivpu_hw_irq_handler,
+ ivpu_ipc_irq_thread_handler, IRQF_NO_AUTOEN | IRQF_ONESHOT,
+ DRIVER_NAME, vdev);
if (ret)
ivpu_err(vdev, "Failed to request an IRQ %d\n", ret);
--- a/drivers/accel/ivpu/ivpu_drv.h
+++ b/drivers/accel/ivpu/ivpu_drv.h
@@ -13,6 +13,7 @@
#include <drm/drm_print.h>
#include <linux/hashtable.h>
+#include <linux/llist.h>
#include <linux/pci.h>
#include <linux/xarray.h>
#include <uapi/drm/ivpu_accel.h>
@@ -157,9 +158,11 @@ struct ivpu_device {
struct xa_limit db_limit;
u32 db_next;
- struct work_struct irq_ipc_work;
struct work_struct irq_dct_work;
struct work_struct context_abort_work;
+ struct llist_head job_destroy_list;
+ struct work_struct job_destroy_work;
+ struct workqueue_struct *job_destroy_wq;
struct mutex bo_list_lock; /* Protects bo_list */
struct list_head bo_list;
--- a/drivers/accel/ivpu/ivpu_hw.c
+++ b/drivers/accel/ivpu/ivpu_hw.c
@@ -399,6 +399,10 @@ irqreturn_t ivpu_hw_irq_handler(int irq,
return IRQ_NONE;
pm_runtime_mark_last_busy(vdev->drm.dev);
+
+ if (ip_handled)
+ return IRQ_WAKE_THREAD;
+
return IRQ_HANDLED;
}
--- a/drivers/accel/ivpu/ivpu_ipc.c
+++ b/drivers/accel/ivpu/ivpu_ipc.c
@@ -463,13 +463,11 @@ void ivpu_ipc_irq_handler(struct ivpu_de
ivpu_ipc_rx_mark_free(vdev, ipc_hdr, jsm_msg);
}
}
-
- queue_work(system_percpu_wq, &vdev->irq_ipc_work);
}
-void ivpu_ipc_irq_work_fn(struct work_struct *work)
+irqreturn_t ivpu_ipc_irq_thread_handler(int irq, void *ptr)
{
- struct ivpu_device *vdev = container_of(work, struct ivpu_device, irq_ipc_work);
+ struct ivpu_device *vdev = ptr;
struct ivpu_ipc_info *ipc = vdev->ipc;
struct ivpu_ipc_rx_msg *rx_msg, *r;
struct list_head cb_msg_list;
@@ -484,6 +482,8 @@ void ivpu_ipc_irq_work_fn(struct work_st
rx_msg->callback(vdev, rx_msg->ipc_hdr, rx_msg->jsm_msg);
ivpu_ipc_rx_msg_del(vdev, rx_msg);
}
+
+ return IRQ_HANDLED;
}
int ivpu_ipc_init(struct ivpu_device *vdev)
--- a/drivers/accel/ivpu/ivpu_ipc.h
+++ b/drivers/accel/ivpu/ivpu_ipc.h
@@ -90,7 +90,7 @@ void ivpu_ipc_disable(struct ivpu_device
void ivpu_ipc_reset(struct ivpu_device *vdev);
void ivpu_ipc_irq_handler(struct ivpu_device *vdev);
-void ivpu_ipc_irq_work_fn(struct work_struct *work);
+irqreturn_t ivpu_ipc_irq_thread_handler(int irq, void *ptr);
void ivpu_ipc_consumer_add(struct ivpu_device *vdev, struct ivpu_ipc_consumer *cons,
u32 channel, ivpu_ipc_rx_callback_t callback);
--- a/drivers/accel/ivpu/ivpu_job.c
+++ b/drivers/accel/ivpu/ivpu_job.c
@@ -535,6 +535,20 @@ static void ivpu_job_destroy(struct ivpu
kfree(job);
}
+void ivpu_job_destroy_work_fn(struct work_struct *work)
+{
+ struct ivpu_device *vdev = container_of(work, struct ivpu_device, job_destroy_work);
+ struct ivpu_job *job, *tmp;
+ struct llist_node *list;
+
+ list = llist_del_all(&vdev->job_destroy_list);
+
+ llist_for_each_entry_safe(job, tmp, list, destroy_node) {
+ ivpu_job_destroy(job);
+ ivpu_rpm_put(vdev);
+ }
+}
+
static struct ivpu_job *
ivpu_job_create(struct ivpu_file_priv *file_priv, u32 engine_idx, u32 bo_count)
{
@@ -619,7 +633,7 @@ bool ivpu_job_handle_engine_error(struct
return false;
}
-static int ivpu_job_signal_and_destroy(struct ivpu_device *vdev, u32 job_id, u32 job_status)
+static struct ivpu_job *ivpu_job_signal(struct ivpu_device *vdev, u32 job_id, u32 job_status)
{
struct ivpu_job *job;
@@ -627,7 +641,7 @@ static int ivpu_job_signal_and_destroy(s
job = xa_load(&vdev->submitted_jobs_xa, job_id);
if (!job)
- return -ENOENT;
+ return NULL;
ivpu_job_remove_from_submitted_jobs(vdev, job_id);
@@ -646,14 +660,37 @@ static int ivpu_job_signal_and_destroy(s
job->job_id, job->file_priv->ctx.id, job->cmdq_id, job->engine_idx,
job->job_status);
- ivpu_job_destroy(job);
ivpu_stop_job_timeout_detection(vdev);
- ivpu_rpm_put(vdev);
-
if (!xa_empty(&vdev->submitted_jobs_xa))
ivpu_start_job_timeout_detection(vdev);
+ return job;
+}
+
+static int ivpu_job_signal_and_destroy(struct ivpu_device *vdev, u32 job_id, u32 job_status)
+{
+ struct ivpu_job *job = ivpu_job_signal(vdev, job_id, job_status);
+
+ if (!job)
+ return -ENOENT;
+
+ ivpu_job_destroy(job);
+ ivpu_rpm_put(vdev);
+
+ return 0;
+}
+
+static int ivpu_job_signal_and_defer_destroy(struct ivpu_device *vdev, u32 job_id, u32 job_status)
+{
+ struct ivpu_job *job = ivpu_job_signal(vdev, job_id, job_status);
+
+ if (!job)
+ return -ENOENT;
+
+ llist_add(&job->destroy_node, &vdev->job_destroy_list);
+ queue_work(vdev->job_destroy_wq, &vdev->job_destroy_work);
+
return 0;
}
@@ -689,6 +726,7 @@ static int ivpu_job_submit(struct ivpu_j
struct ivpu_file_priv *file_priv = job->file_priv;
struct ivpu_device *vdev = job->vdev;
struct ivpu_cmdq *cmdq;
+ bool flushed = false;
bool is_first_job;
int ret;
@@ -696,6 +734,7 @@ static int ivpu_job_submit(struct ivpu_j
if (ret < 0)
return ret;
+retry:
mutex_lock(&vdev->submitted_jobs_lock);
mutex_lock(&file_priv->lock);
@@ -709,6 +748,14 @@ static int ivpu_job_submit(struct ivpu_j
}
ret = ivpu_cmdq_register(file_priv, cmdq);
+ if (ret == -EBUSY && !flushed) {
+ /* Doorbell may be held by jobs pending deferred cleanup */
+ mutex_unlock(&file_priv->lock);
+ mutex_unlock(&vdev->submitted_jobs_lock);
+ flush_work(&vdev->job_destroy_work);
+ flushed = true;
+ goto retry;
+ }
if (ret) {
ivpu_err(vdev, "Failed to register command queue: %d\n", ret);
goto err_unlock;
@@ -1101,7 +1148,7 @@ ivpu_job_done_callback(struct ivpu_devic
mutex_lock(&vdev->submitted_jobs_lock);
if (!ivpu_job_handle_engine_error(vdev, payload->job_id, payload->job_status))
/* No engine error, complete the job normally */
- ivpu_job_signal_and_destroy(vdev, payload->job_id, payload->job_status);
+ ivpu_job_signal_and_defer_destroy(vdev, payload->job_id, payload->job_status);
mutex_unlock(&vdev->submitted_jobs_lock);
}
--- a/drivers/accel/ivpu/ivpu_job.h
+++ b/drivers/accel/ivpu/ivpu_job.h
@@ -6,8 +6,10 @@
#ifndef __IVPU_JOB_H__
#define __IVPU_JOB_H__
-#include <linux/kref.h>
#include <linux/idr.h>
+#include <linux/kref.h>
+#include <linux/llist.h>
+#include <linux/workqueue.h>
#include "ivpu_gem.h"
@@ -47,6 +49,7 @@ struct ivpu_cmdq {
* @vdev: Pointer to the VPU device
* @file_priv: The client context that submitted this job
* @done_fence: Fence signaled when job completes
+ * @destroy_node: List node for deferred resource cleanup after job completion
* @cmd_buf_vpu_addr: VPU address of the command buffer for this job
* @cmdq_id: Command queue ID used for submission
* @job_id: Unique job ID for tracking and status reporting
@@ -61,6 +64,7 @@ struct ivpu_job {
struct ivpu_device *vdev;
struct ivpu_file_priv *file_priv;
struct dma_fence *done_fence;
+ struct llist_node destroy_node;
u64 cmd_buf_vpu_addr;
u32 cmdq_id;
u32 job_id;
@@ -87,6 +91,7 @@ void ivpu_job_done_consumer_init(struct
void ivpu_job_done_consumer_fini(struct ivpu_device *vdev);
bool ivpu_job_handle_engine_error(struct ivpu_device *vdev, u32 job_id, u32 job_status);
void ivpu_context_abort_work_fn(struct work_struct *work);
+void ivpu_job_destroy_work_fn(struct work_struct *work);
void ivpu_jobs_abort_all(struct ivpu_device *vdev);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 437/457] accel/ivpu: Use separate flag for job timeout
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (435 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 436/457] accel/ivpu: Use threaded IRQ for IPC callback processing Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 438/457] i2c: qcom-geni: Isolate serial engine setup Greg Kroah-Hartman
` (30 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Pawlak, Dawid Osuchowski,
Karol Wachowski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Pawlak <jakub.pawlak@intel.com>
[ Upstream commit 72b782097e534ab48152dd25aaba40dda5f25f9e ]
Use separate flag to mark a job timeout as a reason
of starting context_abort_work. This allows to distinguish
engine reset reason and clearly adjust reset procedure flow.
The flag is cleared in ivpu_prepare_for_reset(), which every
recovery and suspend path already funnels through, so that the
state is clean after recovery.
Cc: stable@vger.kernel.org # v7.1+
Fixes: ade00a6c903f ("accel/ivpu: Perform engine reset instead of device recovery on TDR")
Signed-off-by: Jakub Pawlak <jakub.pawlak@intel.com>
Reviewed-by: Dawid Osuchowski <dawid.osuchowski@linux.intel.com>
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
Link: https://patch.msgid.link/20260914084301.894028-1-karol.wachowski@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/accel/ivpu/ivpu_drv.c | 3 ++-
drivers/accel/ivpu/ivpu_drv.h | 2 +-
drivers/accel/ivpu/ivpu_job.c | 7 +++----
drivers/accel/ivpu/ivpu_mmu.c | 1 -
drivers/accel/ivpu/ivpu_pm.c | 1 +
5 files changed, 7 insertions(+), 7 deletions(-)
--- a/drivers/accel/ivpu/ivpu_drv.c
+++ b/drivers/accel/ivpu/ivpu_drv.c
@@ -515,6 +515,7 @@ void ivpu_prepare_for_reset(struct ivpu_
{
ivpu_hw_irq_disable(vdev);
disable_irq(vdev->irq);
+ atomic_set(&vdev->job_timeout_detected, 0);
flush_work(&vdev->irq_dct_work);
flush_work(&vdev->context_abort_work);
flush_work(&vdev->job_destroy_work);
@@ -710,7 +711,7 @@ static int ivpu_dev_init(struct ivpu_dev
vdev->context_xa_limit.max = IVPU_USER_CONTEXT_MAX_SSID;
atomic64_set(&vdev->unique_id_counter, 0);
atomic_set(&vdev->job_timeout_counter, 0);
- atomic_set(&vdev->faults_detected, 0);
+ atomic_set(&vdev->job_timeout_detected, 0);
xa_init_flags(&vdev->context_xa, XA_FLAGS_ALLOC | XA_FLAGS_LOCK_IRQ);
xa_init_flags(&vdev->submitted_jobs_xa, XA_FLAGS_ALLOC1);
xa_init_flags(&vdev->db_xa, XA_FLAGS_ALLOC1);
--- a/drivers/accel/ivpu/ivpu_drv.h
+++ b/drivers/accel/ivpu/ivpu_drv.h
@@ -171,7 +171,7 @@ struct ivpu_device {
struct xarray submitted_jobs_xa;
struct ivpu_ipc_consumer job_done_consumer;
atomic_t job_timeout_counter;
- atomic_t faults_detected;
+ atomic_t job_timeout_detected;
atomic64_t unique_id_counter;
--- a/drivers/accel/ivpu/ivpu_job.c
+++ b/drivers/accel/ivpu/ivpu_job.c
@@ -621,7 +621,6 @@ bool ivpu_job_handle_engine_error(struct
* status and ensure both are handled in the same way
*/
job->file_priv->has_mmu_faults = true;
- atomic_set(&vdev->faults_detected, 1);
queue_work(system_percpu_wq, &vdev->context_abort_work);
return true;
}
@@ -1175,10 +1174,10 @@ static int reset_engine_and_mark_faulty_
return ret;
/*
- * If faults are detected, ignore guilty contexts from engine reset as NPU may not be stuck
- * and could return currently running good context and faulty contexts are already marked
+ * If job timeout is detected, read guilty context from engine reset, for other reasons
+ * faulty context is already known
*/
- if (atomic_cmpxchg(&vdev->faults_detected, 1, 0) == 1)
+ if (atomic_cmpxchg(&vdev->job_timeout_detected, 1, 0) == 0)
return 0;
num_impacted_contexts = resp.payload.engine_reset_done.num_impacted_contexts;
--- a/drivers/accel/ivpu/ivpu_mmu.c
+++ b/drivers/accel/ivpu/ivpu_mmu.c
@@ -964,7 +964,6 @@ void ivpu_mmu_irq_evtq_handler(struct iv
file_priv = xa_load(&vdev->context_xa, ssid);
if (file_priv) {
if (!READ_ONCE(file_priv->has_mmu_faults)) {
- atomic_set(&vdev->faults_detected, 1);
ivpu_mmu_dump_event(vdev, event);
WRITE_ONCE(file_priv->has_mmu_faults, true);
}
--- a/drivers/accel/ivpu/ivpu_pm.c
+++ b/drivers/accel/ivpu/ivpu_pm.c
@@ -229,6 +229,7 @@ abort:
ivpu_jsm_state_dump(vdev);
ivpu_dev_coredump(vdev);
+ atomic_set(&vdev->job_timeout_detected, 1);
queue_work(system_percpu_wq, &vdev->context_abort_work);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 438/457] i2c: qcom-geni: Isolate serial engine setup
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (436 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 437/457] accel/ivpu: Use separate flag for job timeout Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 439/457] i2c: qcom-geni: Move resource initialization to separate function Greg Kroah-Hartman
` (29 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Praveen Talari, Viken Dadhaniya,
Konrad Dybcio, Mukesh Kumar Savaliya, Mattijs Korpershoek,
Andi Shyti, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit d8d3bb127ad119853ddcf5da8f546cf37c3cc346 ]
Moving the serial engine setup to geni_i2c_init() API for a cleaner
probe function and utilizes the PM runtime API to control resources
instead of direct clock-related APIs for better resource management.
Enables reusability of the serial engine initialization like
hibernation and deep sleep features where hardware context is lost.
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Acked-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Tested-by: Mattijs Korpershoek <mkorpershoek@kernel.org>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260617-enable-i2c-on-sa8255p-v7-2-ad736dbeab57@oss.qualcomm.com
Stable-dep-of: cb97bf3d4f91 ("i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-geni.c | 158 +++++++++++++++++--------------------
1 file changed, 75 insertions(+), 83 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -990,10 +990,77 @@ err_tx:
return ret;
}
+static int geni_i2c_init(struct geni_i2c_dev *gi2c)
+{
+ const struct geni_i2c_desc *desc = NULL;
+ u32 proto, tx_depth;
+ bool fifo_disable;
+ int ret;
+
+ ret = pm_runtime_resume_and_get(gi2c->se.dev);
+ if (ret < 0) {
+ dev_err(gi2c->se.dev, "error turning on device :%d\n", ret);
+ return ret;
+ }
+
+ proto = geni_se_read_proto(&gi2c->se);
+ if (proto == GENI_SE_INVALID_PROTO) {
+ ret = geni_load_se_firmware(&gi2c->se, GENI_SE_I2C);
+ if (ret) {
+ dev_err_probe(gi2c->se.dev, ret, "i2c firmware load failed ret: %d\n", ret);
+ goto err;
+ }
+ } else if (proto != GENI_SE_I2C) {
+ ret = dev_err_probe(gi2c->se.dev, -ENXIO, "Invalid proto %d\n", proto);
+ goto err;
+ }
+
+ desc = device_get_match_data(gi2c->se.dev);
+ if (desc && desc->no_dma_support) {
+ fifo_disable = false;
+ gi2c->no_dma = true;
+ } else {
+ fifo_disable = readl_relaxed(gi2c->se.base + GENI_IF_DISABLE_RO) & FIFO_IF_DISABLE;
+ }
+
+ if (fifo_disable) {
+ /* FIFO is disabled, so we can only use GPI DMA */
+ gi2c->gpi_mode = true;
+ ret = setup_gpi_dma(gi2c);
+ if (ret)
+ goto err;
+
+ dev_dbg(gi2c->se.dev, "Using GPI DMA mode for I2C\n");
+ } else {
+ gi2c->gpi_mode = false;
+ tx_depth = geni_se_get_tx_fifo_depth(&gi2c->se);
+
+ /* I2C Master Hub Serial Elements doesn't have the HW_PARAM_0 register */
+ if (!tx_depth && desc)
+ tx_depth = desc->tx_fifo_depth;
+
+ if (!tx_depth) {
+ ret = dev_err_probe(gi2c->se.dev, -EINVAL,
+ "Invalid TX FIFO depth\n");
+ goto err;
+ }
+
+ gi2c->tx_wm = tx_depth - 1;
+ geni_se_init(&gi2c->se, gi2c->tx_wm, tx_depth);
+ geni_se_config_packing(&gi2c->se, BITS_PER_BYTE,
+ PACKING_BYTES_PW, true, true, true);
+
+ dev_dbg(gi2c->se.dev, "i2c fifo/se-dma mode. fifo depth:%d\n", tx_depth);
+ }
+
+err:
+ pm_runtime_put(gi2c->se.dev);
+ return ret;
+}
+
static int geni_i2c_probe(struct platform_device *pdev)
{
struct geni_i2c_dev *gi2c;
- u32 proto, tx_depth, fifo_disable;
int ret;
struct device *dev = &pdev->dev;
const struct geni_i2c_desc *desc = NULL;
@@ -1073,102 +1140,27 @@ static int geni_i2c_probe(struct platfor
if (ret)
return ret;
- ret = clk_prepare_enable(gi2c->core_clk);
- if (ret)
- return ret;
-
- ret = geni_se_resources_on(&gi2c->se);
- if (ret) {
- dev_err_probe(dev, ret, "Error turning on resources\n");
- goto err_clk;
- }
- proto = geni_se_read_proto(&gi2c->se);
- if (proto == GENI_SE_INVALID_PROTO) {
- ret = geni_load_se_firmware(&gi2c->se, GENI_SE_I2C);
- if (ret) {
- dev_err_probe(dev, ret, "i2c firmware load failed ret: %d\n", ret);
- goto err_resources;
- }
- } else if (proto != GENI_SE_I2C) {
- ret = dev_err_probe(dev, -ENXIO, "Invalid proto %d\n", proto);
- goto err_resources;
- }
-
- if (desc && desc->no_dma_support) {
- fifo_disable = false;
- gi2c->no_dma = true;
- } else {
- fifo_disable = readl_relaxed(gi2c->se.base + GENI_IF_DISABLE_RO) & FIFO_IF_DISABLE;
- }
-
- if (fifo_disable) {
- /* FIFO is disabled, so we can only use GPI DMA */
- gi2c->gpi_mode = true;
- ret = setup_gpi_dma(gi2c);
- if (ret)
- goto err_resources;
-
- dev_dbg(dev, "Using GPI DMA mode for I2C\n");
- } else {
- gi2c->gpi_mode = false;
- tx_depth = geni_se_get_tx_fifo_depth(&gi2c->se);
-
- /* I2C Master Hub Serial Elements doesn't have the HW_PARAM_0 register */
- if (!tx_depth && desc)
- tx_depth = desc->tx_fifo_depth;
-
- if (!tx_depth) {
- ret = dev_err_probe(dev, -EINVAL,
- "Invalid TX FIFO depth\n");
- goto err_resources;
- }
-
- gi2c->tx_wm = tx_depth - 1;
- geni_se_init(&gi2c->se, gi2c->tx_wm, tx_depth);
- geni_se_config_packing(&gi2c->se, BITS_PER_BYTE,
- PACKING_BYTES_PW, true, true, true);
-
- dev_dbg(dev, "i2c fifo/se-dma mode. fifo depth:%d\n", tx_depth);
- }
-
- clk_disable_unprepare(gi2c->core_clk);
- ret = geni_se_resources_off(&gi2c->se);
- if (ret) {
- dev_err_probe(dev, ret, "Error turning off resources\n");
- goto err_dma;
- }
-
- ret = geni_icc_disable(&gi2c->se);
- if (ret)
- goto err_dma;
-
pm_runtime_set_suspended(gi2c->se.dev);
pm_runtime_set_autosuspend_delay(gi2c->se.dev, I2C_AUTO_SUSPEND_DELAY);
pm_runtime_use_autosuspend(gi2c->se.dev);
pm_runtime_enable(gi2c->se.dev);
+ ret = geni_i2c_init(gi2c);
+ if (ret < 0) {
+ pm_runtime_disable(gi2c->se.dev);
+ return ret;
+ }
+
ret = i2c_add_adapter(&gi2c->adap);
if (ret) {
dev_err_probe(dev, ret, "Error adding i2c adapter\n");
pm_runtime_disable(gi2c->se.dev);
- goto err_dma;
+ return ret;
}
dev_dbg(dev, "Geni-I2C adaptor successfully added\n");
return ret;
-
-err_resources:
- geni_se_resources_off(&gi2c->se);
-err_clk:
- clk_disable_unprepare(gi2c->core_clk);
-
- return ret;
-
-err_dma:
- release_gpi_dma(gi2c);
-
- return ret;
}
static void geni_i2c_remove(struct platform_device *pdev)
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 439/457] i2c: qcom-geni: Move resource initialization to separate function
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (437 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 438/457] i2c: qcom-geni: Isolate serial engine setup Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 440/457] i2c: qcom-geni: Store of_device_id data in driver private struct Greg Kroah-Hartman
` (28 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Praveen Talari, Viken Dadhaniya,
Konrad Dybcio, Mattijs Korpershoek, Andi Shyti, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit ed4b34033db25a0f35bb84289377e1916ffe2329 ]
Refactor the resource initialization in geni_i2c_probe() by introducing
a new geni_i2c_resources_init() function and utilizing the common
geni_se_resources_init() framework and clock frequency mapping, making the
probe function cleaner.
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Acked-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Mattijs Korpershoek <mkorpershoek@kernel.org>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260617-enable-i2c-on-sa8255p-v7-3-ad736dbeab57@oss.qualcomm.com
Stable-dep-of: cb97bf3d4f91 ("i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-geni.c | 64 +++++++++++++------------------------
1 file changed, 24 insertions(+), 40 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -107,7 +107,6 @@ struct geni_i2c_dev {
int cur_wr;
int cur_rd;
spinlock_t lock;
- struct clk *core_clk;
u32 clk_freq_out;
const struct geni_i2c_clk_fld *clk_fld;
void *dma_buf;
@@ -124,8 +123,6 @@ struct geni_i2c_dev {
};
struct geni_i2c_desc {
- bool has_core_clk;
- char *icc_ddr;
bool no_dma_support;
unsigned int tx_fifo_depth;
};
@@ -1058,6 +1055,23 @@ err:
return ret;
}
+static int geni_i2c_resources_init(struct geni_i2c_dev *gi2c)
+{
+ int ret;
+
+ ret = geni_se_resources_init(&gi2c->se);
+ if (ret)
+ return ret;
+
+ ret = geni_i2c_clk_map_idx(gi2c);
+ if (ret)
+ return dev_err_probe(gi2c->se.dev, ret, "Invalid clk frequency %d Hz\n",
+ gi2c->clk_freq_out);
+
+ return geni_icc_set_bw_ab(&gi2c->se, GENI_DEFAULT_BW, GENI_DEFAULT_BW,
+ Bps_to_icc(gi2c->clk_freq_out));
+}
+
static int geni_i2c_probe(struct platform_device *pdev)
{
struct geni_i2c_dev *gi2c;
@@ -1077,16 +1091,6 @@ static int geni_i2c_probe(struct platfor
desc = device_get_match_data(&pdev->dev);
- if (desc && desc->has_core_clk) {
- gi2c->core_clk = devm_clk_get(dev, "core");
- if (IS_ERR(gi2c->core_clk))
- return PTR_ERR(gi2c->core_clk);
- }
-
- gi2c->se.clk = devm_clk_get(dev, "se");
- if (IS_ERR(gi2c->se.clk) && !has_acpi_companion(dev))
- return PTR_ERR(gi2c->se.clk);
-
ret = device_property_read_u32(dev, "clock-frequency",
&gi2c->clk_freq_out);
if (ret) {
@@ -1101,16 +1105,15 @@ static int geni_i2c_probe(struct platfor
if (gi2c->irq < 0)
return gi2c->irq;
- ret = geni_i2c_clk_map_idx(gi2c);
- if (ret)
- return dev_err_probe(dev, ret, "Invalid clk frequency %d Hz\n",
- gi2c->clk_freq_out);
-
gi2c->adap.algo = &geni_i2c_algo;
init_completion(&gi2c->done);
spin_lock_init(&gi2c->lock);
platform_set_drvdata(pdev, gi2c);
+ ret = geni_i2c_resources_init(gi2c);
+ if (ret)
+ return ret;
+
/* Keep interrupts disabled initially to allow for low-power modes */
ret = devm_request_irq(dev, gi2c->irq, geni_i2c_irq, IRQF_NO_AUTOEN,
dev_name(dev), gi2c);
@@ -1123,23 +1126,6 @@ static int geni_i2c_probe(struct platfor
gi2c->adap.dev.of_node = dev->of_node;
strscpy(gi2c->adap.name, "Geni-I2C", sizeof(gi2c->adap.name));
- ret = geni_icc_get(&gi2c->se, desc ? desc->icc_ddr : "qup-memory");
- if (ret)
- return ret;
- /*
- * Set the bus quota for core and cpu to a reasonable value for
- * register access.
- * Set quota for DDR based on bus speed.
- */
- gi2c->se.icc_paths[GENI_TO_CORE].avg_bw = GENI_DEFAULT_BW;
- gi2c->se.icc_paths[CPU_TO_GENI].avg_bw = GENI_DEFAULT_BW;
- if (!desc || desc->icc_ddr)
- gi2c->se.icc_paths[GENI_TO_DDR].avg_bw = Bps_to_icc(gi2c->clk_freq_out);
-
- ret = geni_icc_set_bw(&gi2c->se);
- if (ret)
- return ret;
-
pm_runtime_set_suspended(gi2c->se.dev);
pm_runtime_set_autosuspend_delay(gi2c->se.dev, I2C_AUTO_SUSPEND_DELAY);
pm_runtime_use_autosuspend(gi2c->se.dev);
@@ -1192,7 +1178,7 @@ static int __maybe_unused geni_i2c_runti
return ret;
}
- clk_disable_unprepare(gi2c->core_clk);
+ clk_disable_unprepare(gi2c->se.core_clk);
return geni_icc_disable(&gi2c->se);
}
@@ -1206,7 +1192,7 @@ static int __maybe_unused geni_i2c_runti
if (ret)
return ret;
- ret = clk_prepare_enable(gi2c->core_clk);
+ ret = clk_prepare_enable(gi2c->se.core_clk);
if (ret)
goto out_icc_disable;
@@ -1219,7 +1205,7 @@ static int __maybe_unused geni_i2c_runti
return 0;
out_clk_disable:
- clk_disable_unprepare(gi2c->core_clk);
+ clk_disable_unprepare(gi2c->se.core_clk);
out_icc_disable:
geni_icc_disable(&gi2c->se);
@@ -1260,8 +1246,6 @@ static const struct dev_pm_ops geni_i2c_
};
static const struct geni_i2c_desc i2c_master_hub = {
- .has_core_clk = true,
- .icc_ddr = NULL,
.no_dma_support = true,
.tx_fifo_depth = 16,
};
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 440/457] i2c: qcom-geni: Store of_device_id data in driver private struct
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (438 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 439/457] i2c: qcom-geni: Move resource initialization to separate function Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 441/457] i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL Greg Kroah-Hartman
` (27 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Praveen Talari, Viken Dadhaniya,
Konrad Dybcio, Mattijs Korpershoek, Andi Shyti, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit 692e0c84db5fdd88c242eadc873d498787c94e3e ]
To avoid repeatedly fetching and checking platform data across various
functions, store the struct of_device_id data directly in the i2c
private structure. This change enhances code maintainability and reduces
redundancy.
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Acked-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Mattijs Korpershoek <mkorpershoek@kernel.org>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260617-enable-i2c-on-sa8255p-v7-5-ad736dbeab57@oss.qualcomm.com
Stable-dep-of: cb97bf3d4f91 ("i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-geni.c | 46 +++++++++++++++++++------------------
1 file changed, 24 insertions(+), 22 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -77,6 +77,11 @@ enum geni_i2c_err_code {
#define XFER_TIMEOUT HZ
#define RST_TIMEOUT HZ
+struct geni_i2c_desc {
+ bool no_dma_support;
+ unsigned int tx_fifo_depth;
+};
+
#define QCOM_I2C_MIN_NUM_OF_MSGS_MULTI_DESC 2
/**
@@ -120,11 +125,7 @@ struct geni_i2c_dev {
bool is_tx_multi_desc_xfer;
u32 num_msgs;
struct geni_i2c_gpi_multi_desc_xfer i2c_multi_desc_config;
-};
-
-struct geni_i2c_desc {
- bool no_dma_support;
- unsigned int tx_fifo_depth;
+ const struct geni_i2c_desc *dev_data;
};
struct geni_i2c_err_log {
@@ -941,15 +942,6 @@ static const struct i2c_algorithm geni_i
.functionality = geni_i2c_func,
};
-#ifdef CONFIG_ACPI
-static const struct acpi_device_id geni_i2c_acpi_match[] = {
- { "QCOM0220"},
- { "QCOM0411" },
- { }
-};
-MODULE_DEVICE_TABLE(acpi, geni_i2c_acpi_match);
-#endif
-
static void release_gpi_dma(struct geni_i2c_dev *gi2c)
{
if (gi2c->rx_c)
@@ -989,7 +981,6 @@ err_tx:
static int geni_i2c_init(struct geni_i2c_dev *gi2c)
{
- const struct geni_i2c_desc *desc = NULL;
u32 proto, tx_depth;
bool fifo_disable;
int ret;
@@ -1012,8 +1003,7 @@ static int geni_i2c_init(struct geni_i2c
goto err;
}
- desc = device_get_match_data(gi2c->se.dev);
- if (desc && desc->no_dma_support) {
+ if (gi2c->dev_data->no_dma_support) {
fifo_disable = false;
gi2c->no_dma = true;
} else {
@@ -1033,8 +1023,8 @@ static int geni_i2c_init(struct geni_i2c
tx_depth = geni_se_get_tx_fifo_depth(&gi2c->se);
/* I2C Master Hub Serial Elements doesn't have the HW_PARAM_0 register */
- if (!tx_depth && desc)
- tx_depth = desc->tx_fifo_depth;
+ if (!tx_depth && gi2c->se.core_clk)
+ tx_depth = gi2c->dev_data->tx_fifo_depth;
if (!tx_depth) {
ret = dev_err_probe(gi2c->se.dev, -EINVAL,
@@ -1077,7 +1067,6 @@ static int geni_i2c_probe(struct platfor
struct geni_i2c_dev *gi2c;
int ret;
struct device *dev = &pdev->dev;
- const struct geni_i2c_desc *desc = NULL;
gi2c = devm_kzalloc(dev, sizeof(*gi2c), GFP_KERNEL);
if (!gi2c)
@@ -1089,7 +1078,9 @@ static int geni_i2c_probe(struct platfor
if (IS_ERR(gi2c->se.base))
return PTR_ERR(gi2c->se.base);
- desc = device_get_match_data(&pdev->dev);
+ gi2c->dev_data = device_get_match_data(&pdev->dev);
+ if (!gi2c->dev_data)
+ return -EINVAL;
ret = device_property_read_u32(dev, "clock-frequency",
&gi2c->clk_freq_out);
@@ -1245,13 +1236,24 @@ static const struct dev_pm_ops geni_i2c_
NULL)
};
+static const struct geni_i2c_desc geni_i2c = {};
+
static const struct geni_i2c_desc i2c_master_hub = {
.no_dma_support = true,
.tx_fifo_depth = 16,
};
+#ifdef CONFIG_ACPI
+static const struct acpi_device_id geni_i2c_acpi_match[] = {
+ { "QCOM0220", (kernel_ulong_t)&geni_i2c},
+ { "QCOM0411", (kernel_ulong_t)&geni_i2c},
+ { }
+};
+MODULE_DEVICE_TABLE(acpi, geni_i2c_acpi_match);
+#endif
+
static const struct of_device_id geni_i2c_dt_match[] = {
- { .compatible = "qcom,geni-i2c" },
+ { .compatible = "qcom,geni-i2c", .data = &geni_i2c },
{ .compatible = "qcom,geni-i2c-master-hub", .data = &i2c_master_hub },
{}
};
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 441/457] i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (439 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 440/457] i2c: qcom-geni: Store of_device_id data in driver private struct Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 442/457] super: convert s_count to refcount_t s_passive Greg Kroah-Hartman
` (26 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Viken Dadhaniya,
Mukesh Kumar Savaliya, Andi Shyti, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
[ Upstream commit cb97bf3d4f91453b881acaf8e9f0cc47bb40b604 ]
qcom_geni_i2c_conf() writes a hardcoded 0 to SE_GENI_CLK_SEL, which
selects an index from the hardware clock performance table. This always
picks the first table entry regardless of the actual source clock
configuration. On platforms where the matching entry is not at index 0,
the wrong source clock divider is active and the I2C bus runs at an
incorrect frequency.
Use geni_se_clk_freq_match() in geni_i2c_clk_map_idx() to find the
performance table index for the source clock (32 MHz or 19.2 MHz). Store
the resolved index in a new clk_idx field in geni_i2c_dev and write it
to SE_GENI_CLK_SEL instead of the hardcoded 0.
Fixes: 37692de5d523 ("i2c: i2c-qcom-geni: Add bus driver for the Qualcomm GENI I2C controller")
Signed-off-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Cc: <stable@vger.kernel.org> # v4.19+
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260921-i2c-fix-se-clk-conf-v2-1-8b5537ceff2d@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-geni.c | 38 ++++++++++++++++++++++++++++++++-----
1 file changed, 33 insertions(+), 5 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -77,6 +77,9 @@ enum geni_i2c_err_code {
#define XFER_TIMEOUT HZ
#define RST_TIMEOUT HZ
+#define GENI_SE_CLK_32MHZ (32 * HZ_PER_MHZ)
+#define GENI_SE_CLK_19P2MHZ 19200000UL
+
struct geni_i2c_desc {
bool no_dma_support;
unsigned int tx_fifo_depth;
@@ -114,6 +117,7 @@ struct geni_i2c_dev {
spinlock_t lock;
u32 clk_freq_out;
const struct geni_i2c_clk_fld *clk_fld;
+ u32 clk_idx;
void *dma_buf;
size_t xfer_len;
dma_addr_t dma_addr;
@@ -184,19 +188,44 @@ static const struct geni_i2c_clk_fld gen
static int geni_i2c_clk_map_idx(struct geni_i2c_dev *gi2c)
{
const struct geni_i2c_clk_fld *itr;
+ unsigned long res_freq;
- if (clk_get_rate(gi2c->se.clk) == 32 * HZ_PER_MHZ)
+ /*
+ * Frequency counter tables are calibrated for a specific source
+ * clock frequency and are not valid for any multiple of it
+ * (e.g. 64 MHz, 128 MHz).
+ * Use exact=true and verify res_freq matches req_freq literally
+ * to reject harmonics: a 64 MHz clock that divides evenly to
+ * 32 MHz would pass exact matching but produce double the intended
+ * I2C frequency with these counter values.
+ */
+ if (!geni_se_clk_freq_match(&gi2c->se, GENI_SE_CLK_32MHZ,
+ &gi2c->clk_idx, &res_freq, true) &&
+ res_freq == GENI_SE_CLK_32MHZ) {
itr = geni_i2c_clk_map_32mhz;
- else
+ } else if (!geni_se_clk_freq_match(&gi2c->se, GENI_SE_CLK_19P2MHZ,
+ &gi2c->clk_idx, &res_freq, true) &&
+ res_freq == GENI_SE_CLK_19P2MHZ) {
itr = geni_i2c_clk_map_19p2mhz;
+ } else {
+ dev_err(gi2c->se.dev,
+ "Unsupported SE source clock: must be exactly 32 MHz or 19.2 MHz\n");
+ return -EINVAL;
+ }
while (itr->clk_freq_out != 0) {
if (itr->clk_freq_out == gi2c->clk_freq_out) {
gi2c->clk_fld = itr;
+ dev_dbg(gi2c->se.dev,
+ "I2C clk selected: freq: %u Hz, clk_idx: %u\n",
+ gi2c->clk_freq_out, gi2c->clk_idx);
return 0;
}
itr++;
}
+
+ dev_err(gi2c->se.dev, "Unsupported I2C output frequency %u Hz\n", gi2c->clk_freq_out);
+
return -EINVAL;
}
@@ -205,7 +234,7 @@ static void qcom_geni_i2c_conf(struct ge
const struct geni_i2c_clk_fld *itr = gi2c->clk_fld;
u32 val;
- writel_relaxed(0, gi2c->se.base + SE_GENI_CLK_SEL);
+ writel_relaxed(gi2c->clk_idx, gi2c->se.base + SE_GENI_CLK_SEL);
val = (itr->clk_div << CLK_DIV_SHFT) | SER_CLK_EN;
writel_relaxed(val, gi2c->se.base + GENI_SER_M_CLK_CFG);
@@ -1055,8 +1084,7 @@ static int geni_i2c_resources_init(struc
ret = geni_i2c_clk_map_idx(gi2c);
if (ret)
- return dev_err_probe(gi2c->se.dev, ret, "Invalid clk frequency %d Hz\n",
- gi2c->clk_freq_out);
+ return ret;
return geni_icc_set_bw_ab(&gi2c->se, GENI_DEFAULT_BW, GENI_DEFAULT_BW,
Bps_to_icc(gi2c->clk_freq_out));
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 442/457] super: convert s_count to refcount_t s_passive
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (440 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 441/457] i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 443/457] super: take lock after last reference count Greg Kroah-Hartman
` (25 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Kara,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
[ Upstream commit 3ec9800c2d33c783dd3b27d4cc3bb22b9385f828 ]
The superblock carries two counters: s_active, the active reference
count that keeps the filesystem usable, and s_count, the passive
reference count that merely keeps the structure itself alive. Turn the
passive count into a refcount_t and rename it to s_passive to make the
pairing with s_active obvious.
Everything is still serialized by sb_lock, so there is no functional
change; the conversion buys the usual refcount_t saturation and
underflow checking. The following patches start dropping passive
references without holding sb_lock and make the device-to-superblock
table hold one passive reference per registered entry, which a plain
integer cannot support.
Link: https://patch.msgid.link/20260616-work-super-bdev_holder_global-v2-2-7df6b864028e@kernel.org
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Stable-dep-of: 2d2a2d7aa987 ("super: make iterate_supers_type() deletion-safe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/super.c | 18 +++++++++---------
include/linux/fs/super_types.h | 2 +-
2 files changed, 10 insertions(+), 10 deletions(-)
--- a/fs/super.c
+++ b/fs/super.c
@@ -103,7 +103,7 @@ static bool super_flags(const struct sup
* creation will succeed and SB_BORN is set by vfs_get_tree() or we're
* woken and we'll see SB_DYING.
*
- * The caller must have acquired a temporary reference on @sb->s_count.
+ * The caller must have acquired a temporary reference on @sb->s_passive.
*
* Return: The function returns true if SB_BORN was set and with
* s_umount held. The function returns false if SB_DYING was
@@ -368,7 +368,7 @@ static struct super_block *alloc_super(s
spin_lock_init(&s->s_inode_wblist_lock);
fserror_mount(s);
- s->s_count = 1;
+ refcount_set(&s->s_passive, 1);
atomic_set(&s->s_active, 1);
mutex_init(&s->s_vfs_rename_mutex);
lockdep_set_class(&s->s_vfs_rename_mutex, &type->s_vfs_rename_key);
@@ -408,7 +408,7 @@ fail:
*/
static void __put_super(struct super_block *s)
{
- if (!--s->s_count) {
+ if (refcount_dec_and_test(&s->s_passive)) {
list_del_init(&s->s_list);
WARN_ON(s->s_dentry_lru.node);
WARN_ON(s->s_inode_lru.node);
@@ -530,7 +530,7 @@ static bool grab_super(struct super_bloc
{
bool locked;
- sb->s_count++;
+ refcount_inc(&sb->s_passive);
spin_unlock(&sb_lock);
locked = super_lock_excl(sb);
if (locked) {
@@ -557,7 +557,7 @@ static bool grab_super(struct super_bloc
* lock held in read mode in case of success. On successful return,
* the caller must drop the s_umount lock when done.
*
- * Note that unlike get_super() et.al. this one does *not* bump ->s_count.
+ * Note that unlike get_super() et.al. this one does *not* bump ->s_passive.
* The reason why it's safe is that we are OK with doing trylock instead
* of down_read(). There's a couple of places that are OK with that, but
* it's very much not a general-purpose interface.
@@ -859,7 +859,7 @@ static void __iterate_supers(void (*f)(s
sb = next_super(sb, flags)) {
if (super_flags(sb, SB_DYING))
continue;
- sb->s_count++;
+ refcount_inc(&sb->s_passive);
spin_unlock(&sb_lock);
if (flags & SUPER_ITER_UNLOCKED) {
@@ -904,7 +904,7 @@ void iterate_supers_type(struct file_sys
if (super_flags(sb, SB_DYING))
continue;
- sb->s_count++;
+ refcount_inc(&sb->s_passive);
spin_unlock(&sb_lock);
locked = super_lock_shared(sb);
@@ -936,7 +936,7 @@ struct super_block *user_get_super(dev_t
if (sb->s_dev != dev)
continue;
- sb->s_count++;
+ refcount_inc(&sb->s_passive);
spin_unlock(&sb_lock);
locked = super_lock(sb, excl);
@@ -1376,7 +1376,7 @@ static struct super_block *bdev_super_lo
/* Make sure sb doesn't go away from under us */
spin_lock(&sb_lock);
- sb->s_count++;
+ refcount_inc(&sb->s_passive);
spin_unlock(&sb_lock);
mutex_unlock(&bdev->bd_holder_lock);
--- a/include/linux/fs/super_types.h
+++ b/include/linux/fs/super_types.h
@@ -145,7 +145,7 @@ struct super_block {
unsigned long s_magic;
struct dentry *s_root;
struct rw_semaphore s_umount;
- int s_count;
+ refcount_t s_passive;
atomic_t s_active;
#ifdef CONFIG_SECURITY
void *s_security;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 443/457] super: take lock after last reference count
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (441 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 442/457] super: convert s_count to refcount_t s_passive Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 444/457] super: make iterate_supers_type() deletion-safe Greg Kroah-Hartman
` (24 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jan Kara,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
[ Upstream commit 9c486f28994fdfc1a83f5f60129402cf4379957b ]
__put_super() required the caller to hold sb_lock, so put_super()
wrapped it. The per-device superblock table introduced later drops its
passive references from contexts that do not hold sb_lock, so make
put_super() self-locking: drop the count first and take sb_lock only for
the final list_del.
With the count now dropped outside sb_lock a superblock can briefly sit
on @super_blocks with s_passive == 0 before it is unlinked, so the list
walkers (__iterate_supers(), iterate_supers_type(), user_get_super())
switch to refcount_inc_not_zero() and skip it.
Link: https://patch.msgid.link/20260616-work-super-bdev_holder_global-v2-3-7df6b864028e@kernel.org
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Stable-dep-of: 2d2a2d7aa987 ("super: make iterate_supers_type() deletion-safe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/super.c | 63 +++++++++++++++++++++++++++----------------------------------
1 file changed, 28 insertions(+), 35 deletions(-)
--- a/fs/super.c
+++ b/fs/super.c
@@ -404,12 +404,17 @@ fail:
/* Superblock refcounting */
/*
- * Drop a superblock's refcount. The caller must hold sb_lock.
+ * Drop a superblock's passive reference. Must be called WITHOUT sb_lock held;
+ * put_super() acquires sb_lock itself when the final reference is dropped.
*/
-static void __put_super(struct super_block *s)
+void put_super(struct super_block *s)
{
if (refcount_dec_and_test(&s->s_passive)) {
+
+ spin_lock(&sb_lock);
list_del_init(&s->s_list);
+ spin_unlock(&sb_lock);
+
WARN_ON(s->s_dentry_lru.node);
WARN_ON(s->s_inode_lru.node);
WARN_ON(s->s_mounts);
@@ -417,20 +422,6 @@ static void __put_super(struct super_blo
}
}
-/**
- * put_super - drop a temporary reference to superblock
- * @sb: superblock in question
- *
- * Drops a temporary reference, frees superblock if there's no
- * references left.
- */
-void put_super(struct super_block *sb)
-{
- spin_lock(&sb_lock);
- __put_super(sb);
- spin_unlock(&sb_lock);
-}
-
static void kill_super_notify(struct super_block *sb)
{
lockdep_assert_not_held(&sb->s_umount);
@@ -479,11 +470,7 @@ void deactivate_locked_super(struct supe
kill_super_notify(s);
- /*
- * Since list_lru_destroy() may sleep, we cannot call it from
- * put_super(), where we hold the sb_lock. Therefore we destroy
- * the lru lists right now.
- */
+ /* list_lru_destroy() may sleep; put_super() callers may not. */
list_lru_destroy(&s->s_dentry_lru);
list_lru_destroy(&s->s_inode_lru);
@@ -852,14 +839,17 @@ static void __iterate_supers(void (*f)(s
struct super_block *sb, *p = NULL;
bool excl = flags & SUPER_ITER_EXCL;
- guard(spinlock)(&sb_lock);
+ spin_lock(&sb_lock);
for (sb = first_super(flags);
!list_entry_is_head(sb, &super_blocks, s_list);
sb = next_super(sb, flags)) {
if (super_flags(sb, SB_DYING))
continue;
- refcount_inc(&sb->s_passive);
+
+ if (!refcount_inc_not_zero(&sb->s_passive))
+ continue;
+
spin_unlock(&sb_lock);
if (flags & SUPER_ITER_UNLOCKED) {
@@ -869,13 +859,14 @@ static void __iterate_supers(void (*f)(s
super_unlock(sb, excl);
}
- spin_lock(&sb_lock);
if (p)
- __put_super(p);
+ put_super(p);
p = sb;
+ spin_lock(&sb_lock);
}
+ spin_unlock(&sb_lock);
if (p)
- __put_super(p);
+ put_super(p);
}
void iterate_supers(void (*f)(struct super_block *, void *), void *arg)
@@ -904,7 +895,9 @@ void iterate_supers_type(struct file_sys
if (super_flags(sb, SB_DYING))
continue;
- refcount_inc(&sb->s_passive);
+ if (!refcount_inc_not_zero(&sb->s_passive))
+ continue;
+
spin_unlock(&sb_lock);
locked = super_lock_shared(sb);
@@ -913,14 +906,14 @@ void iterate_supers_type(struct file_sys
super_unlock_shared(sb);
}
- spin_lock(&sb_lock);
if (p)
- __put_super(p);
+ put_super(p);
p = sb;
+ spin_lock(&sb_lock);
}
- if (p)
- __put_super(p);
spin_unlock(&sb_lock);
+ if (p)
+ put_super(p);
}
EXPORT_SYMBOL(iterate_supers_type);
@@ -936,15 +929,17 @@ struct super_block *user_get_super(dev_t
if (sb->s_dev != dev)
continue;
- refcount_inc(&sb->s_passive);
+ if (!refcount_inc_not_zero(&sb->s_passive))
+ continue;
+
spin_unlock(&sb_lock);
locked = super_lock(sb, excl);
if (locked)
return sb;
+ put_super(sb);
spin_lock(&sb_lock);
- __put_super(sb);
break;
}
spin_unlock(&sb_lock);
@@ -1375,9 +1370,7 @@ static struct super_block *bdev_super_lo
lockdep_assert_not_held(&bdev->bd_disk->open_mutex);
/* Make sure sb doesn't go away from under us */
- spin_lock(&sb_lock);
refcount_inc(&sb->s_passive);
- spin_unlock(&sb_lock);
mutex_unlock(&bdev->bd_holder_lock);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 444/457] super: make iterate_supers_type() deletion-safe
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (442 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 443/457] super: take lock after last reference count Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 445/457] drm/amd/display: Relax DML frame limit with UBSAN Greg Kroah-Hartman
` (23 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jan Kara,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Brauner <brauner@kernel.org>
[ Upstream commit 2d2a2d7aa98741b58f54cacc99b52024e4d865f9 ]
iterate_supers_type() drops sb_lock while invoking the callback and keeps
only a passive reference to the current superblock. That reference keeps
the object allocated, but does not keep its s_instances node linked.
After the iterator releases s_umount, final teardown can unlink the current
s_instances node. The iterator then advances through a reinitialized node.
With the current hlist it stops without visiting the remaining superblocks.
The unlink moved from generic_shutdown_super() to kill_super_notify(), but
the cursor lifetime has been unsafe since the helper was introduced.
The CIFS DFS lookup can consequently miss a matching superblock and return
-EINVAL.
Move removal from fs_supers to put_super(), alongside removal from
super_blocks, so a passive reference keeps both list nodes linked. Keep
the filesystem module reference until then, since unlinking s_instances
may touch type->fs_supers.
Make sget_fc() skip SB_DEAD superblocks before invoking test(), and set
SB_DEAD under sb_lock to serialize with those callbacks. This allows
kernfs to free its private information after kill_anon_super() returns.
Keep matching SB_DYING superblocks until SB_DEAD is set so concurrent
mounts still wait for teardown before retrying.
Fixes: 43e15cdbefea ("new helper: iterate_supers_type()")
Reported-by: Karl Mehltretter <kmehltretter@gmail.com>
Closes: https://lore.kernel.org/r/20260903013336.92081-1-kmehltretter@gmail.com
Suggested-by: Jan Kara <jack@suse.cz>
Cc: stable@vger.kernel.org
Tested-by: Karl Mehltretter <kmehltretter@gmail.com>
[kmehltretter: supplied the commit message]
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260909193034.7467-1-kmehltretter@gmail.com
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
[ adjusted kill_super_notify() context for missing device-to-superblock table cleanup. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/kernfs/mount.c | 4 ++--
fs/super.c | 39 +++++++++++++++++++--------------------
2 files changed, 21 insertions(+), 22 deletions(-)
--- a/fs/kernfs/mount.c
+++ b/fs/kernfs/mount.c
@@ -434,8 +434,8 @@ void kernfs_kill_sb(struct super_block *
up_write(&root->kernfs_supers_rwsem);
/*
- * Remove the superblock from fs_supers/s_instances
- * so we can't find it, before freeing kernfs_super_info.
+ * Mark the superblock dead so sget_fc() can't find it,
+ * before freeing kernfs_super_info.
*/
kill_anon_super(sb);
kfree(info);
--- a/fs/super.c
+++ b/fs/super.c
@@ -410,15 +410,19 @@ fail:
void put_super(struct super_block *s)
{
if (refcount_dec_and_test(&s->s_passive)) {
+ struct file_system_type *type = s->s_type;
spin_lock(&sb_lock);
list_del_init(&s->s_list);
+ hlist_del_init(&s->s_instances);
spin_unlock(&sb_lock);
WARN_ON(s->s_dentry_lru.node);
WARN_ON(s->s_inode_lru.node);
WARN_ON(s->s_mounts);
call_rcu(&s->rcu, destroy_super_rcu);
+ /* The unlink above may touch type->fs_supers, so drop it last. */
+ put_filesystem(type);
}
}
@@ -431,23 +435,16 @@ static void kill_super_notify(struct sup
return;
/*
- * Remove it from @fs_supers so it isn't found by new
- * sget_fc() walkers anymore. Any concurrent mounter still
- * managing to grab a temporary reference is guaranteed to
- * already see SB_DYING and will wait until we notify them about
- * SB_DEAD.
- */
- spin_lock(&sb_lock);
- hlist_del_init(&sb->s_instances);
- spin_unlock(&sb_lock);
-
- /*
* Let concurrent mounts know that this thing is really dead.
- * We don't need @sb->s_umount here as every concurrent caller
- * will see SB_DYING and either discard the superblock or wait
- * for SB_DEAD.
+ * sget_fc() skips SB_DEAD superblocks and calls test() under
+ * sb_lock, so set it under sb_lock: once we return no test()
+ * runs on this superblock anymore and none will start. Everyone
+ * else already saw SB_DYING and either discarded the superblock
+ * or waits for SB_DEAD.
*/
+ spin_lock(&sb_lock);
super_wake(sb, SB_DEAD);
+ spin_unlock(&sb_lock);
}
/**
@@ -474,7 +471,6 @@ void deactivate_locked_super(struct supe
list_lru_destroy(&s->s_dentry_lru);
list_lru_destroy(&s->s_inode_lru);
- put_filesystem(fs);
put_super(s);
} else {
super_unlock_excl(s);
@@ -661,12 +657,12 @@ void generic_shutdown_super(struct super
}
/*
* Broadcast to everyone that grabbed a temporary reference to this
- * superblock before we removed it from @fs_supers that the superblock
- * is dying. Every walker of @fs_supers outside of sget_fc() will now
- * discard this superblock and treat it as dead.
+ * superblock that it is dying. Every walker of @fs_supers outside
+ * of sget_fc() will now discard this superblock and treat it as
+ * dead.
*
- * We leave the superblock on @fs_supers so it can be found by
- * sget_fc() until we passed sb->kill_sb().
+ * sget_fc() keeps finding the superblock until SB_DEAD is set, so
+ * a concurrent mounter waits until we passed sb->kill_sb().
*/
super_wake(sb, SB_DYING);
super_unlock_excl(sb);
@@ -745,6 +741,9 @@ retry:
spin_lock(&sb_lock);
if (test) {
hlist_for_each_entry(old, &fc->fs_type->fs_supers, s_instances) {
+ /* Only unlinked at the last passive reference. */
+ if (super_flags(old, SB_DEAD))
+ continue;
if (test(old, fc))
goto share_extant_sb;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 445/457] drm/amd/display: Relax DML frame limit with UBSAN
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (443 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 444/457] super: make iterate_supers_type() deletion-safe Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 446/457] net/sched: act_ct: fix helper UAF due to extensions realloc Greg Kroah-Hartman
` (22 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leo Li, Alex Hung, Alex Deucher,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Hung <alex.hung@amd.com>
[ Upstream commit 0fd5e9ddf362b1253b3c94b858371f90400e5c4a ]
[WHY]
UBSAN instrumentation adds checks and handler calls and increases
stack usage in the large DML calculation functions, similar to
KASAN and KCSAN. With UBSAN enabled these files exceed the default
-Wframe-larger-than limit and fail to build when -Werror is in effect.
Reproduced with LLVM (make LLVM=1, clang 19.1.1), CONFIG_UBSAN=y,
CONFIG_GCOV_PROFILE_ALL=y and CONFIG_DRM_AMDGPU_WERROR=y on x86_64.
[HOW]
Include CONFIG_UBSAN in the sanitizer check that selects the
higher per-file frame warning limit in the dml and dml2_0
Makefiles.
Suggested-by: Leo Li <sunpeng.li@amd.com>
Assisted-by: Copilot:Claude-Opus-5.5
Signed-off-by: Alex Hung <alex.hung@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit ebf8b0fd8508b744f85a8eee82b745b1d3502dd0)
Cc: stable@vger.kernel.org
[ Changed sanitizer checks to test for a nonempty filter result over space-separated configuration values. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/display/dc/dml/Makefile | 2 +-
drivers/gpu/drm/amd/display/dc/dml2_0/Makefile | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/amd/display/dc/dml/Makefile
+++ b/drivers/gpu/drm/amd/display/dc/dml/Makefile
@@ -29,7 +29,7 @@ dml_ccflags := $(CC_FLAGS_FPU)
dml_rcflags := $(CC_FLAGS_NO_FPU)
ifneq ($(CONFIG_FRAME_WARN),0)
- ifeq ($(filter y,$(CONFIG_KASAN)$(CONFIG_KCSAN)),y)
+ ifneq ($(filter y,$(CONFIG_KASAN) $(CONFIG_KCSAN) $(CONFIG_UBSAN)),)
ifeq ($(CONFIG_CC_IS_CLANG)$(CONFIG_COMPILE_TEST),yy)
frame_warn_limit := 4096
else
--- a/drivers/gpu/drm/amd/display/dc/dml2_0/Makefile
+++ b/drivers/gpu/drm/amd/display/dc/dml2_0/Makefile
@@ -28,7 +28,7 @@ dml2_ccflags := $(CC_FLAGS_FPU)
dml2_rcflags := $(CC_FLAGS_NO_FPU)
ifneq ($(CONFIG_FRAME_WARN),0)
- ifeq ($(filter y,$(CONFIG_KASAN)$(CONFIG_KCSAN)),y)
+ ifneq ($(filter y,$(CONFIG_KASAN) $(CONFIG_KCSAN) $(CONFIG_UBSAN)),)
ifeq ($(CONFIG_CC_IS_CLANG)$(CONFIG_COMPILE_TEST),yy)
frame_warn_limit := 4096
else
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 446/457] net/sched: act_ct: fix helper UAF due to extensions realloc
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (444 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 445/457] drm/amd/display: Relax DML frame limit with UBSAN Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 447/457] net/sched: act_ct: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
` (21 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Axel Mierczuk, Ilya Maximets,
Xin Long, Jamal Hadi Salim, Aaron Conole, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
[ Upstream commit dad19b59da050cb60d3f7023dac2a042a84bf0bd ]
While calling the helpers, a raw pointer to the extensions area is
wired into expectations list:
-> nf_ct_helper()
-> helper->help()
-> nf_ct_expect_related_report()
-> nf_ct_expect_insert()
-> hlist_add_head_rcu(&exp->lnode, &master_help->expectations)
In case the connection is not confirmed yet, more extensions can be
added afterwards with *_ext_add() calls reallocating the extension
space and leaving the now invalid pointer in the expectations list
that is later accessed while removing the expectation.
Make sure that helpers are called at the end after all the other
extensions are already added.
Note that the helper rejection now leaves the mark and labels set,
but that's not different from how the NAT was handled before or how
the mark and the labels were handled on confirmation failure. And
there are no atomicity guarantees provided by the API anyway.
Fixes: a21b06e73191 ("net: sched: add helper support in act_ct")
Cc: stable@vger.kernel.org
Reported-by: Axel Mierczuk <axel.mierczuk@1password.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Xin Long <lucien.xin@gmail.com>
Reviewed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260921145655.3167436-7-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Preserved the existing add_helper condition that upstream had removed. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_ct.c | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -1089,19 +1089,25 @@ do_nat:
}
}
- if (nf_ct_is_confirmed(ct) ? ((!cached && !skip_add) || add_helper) : commit) {
- err = nf_ct_helper(skb, ct, ctinfo, family);
- if (err != NF_ACCEPT)
- goto nf_error;
- }
-
if (commit) {
tcf_ct_act_set_mark(ct, p->mark, p->mark_mask);
tcf_ct_act_set_labels(ct, p->labels, p->labels_mask);
if (!nf_ct_is_confirmed(ct))
nf_conn_act_ct_ext_add(skb, ct, ctinfo);
+ }
+ /* Run helpers for the connection if nf_conntrack_in() was executed
+ * or if we're about to commit. This has to be done after all the
+ * extensions are already added.
+ */
+ if (nf_ct_is_confirmed(ct) ? ((!cached && !skip_add) || add_helper) : commit) {
+ err = nf_ct_helper(skb, ct, ctinfo, family);
+ if (err != NF_ACCEPT)
+ goto nf_error;
+ }
+
+ if (commit) {
/* This will take care of sending queued events
* even if the connection is already confirmed.
*/
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 447/457] net/sched: act_ct: avoid modifying shared unconfirmed ct entry
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (445 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 446/457] net/sched: act_ct: fix helper UAF due to extensions realloc Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 448/457] KVM: arm64: nv: Fix life cycle of the nested_mmus array Greg Kroah-Hartman
` (20 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Axel Mierczuk, Ilya Maximets,
Aaron Conole, Xin Long, Jamal Hadi Salim, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilya Maximets <i.maximets@ovn.org>
[ Upstream commit f85009dfcd65e5969526b0db7a49b5413746e630 ]
In a case where skb with an unconfirmed ct entry gets cloned, we may
end up processing both again but with different sets of extensions.
The series of events:
1. The first clone wants to commit and runs the helpers wiring up
the extension pointer into the expectation list.
2. Then it looses the confirmation keeping the entry unconfirmed.
3. Second clone now wants to commit labels or run NAT and adds the
new extension for that breaking the pointer in the expectation
list causing UAF on the destruction path later.
While this is possible to trigger, there should be no practical
network pipeline where we need to process both clones without
modifications in the same zone. So, let's just reset the entry in
case for some reason we got an skb with a shared one. This doesn't
affect any known use cases, but avoids any potential problems with
sharing and modification of the unconfirmed ct entry.
Unlike openvswitch module, act_ct allows for NAT without commit.
Changing that would be a uAPI break. So, act_ct needs to reset on NAT
regardless of the commit flag to avoid reallocation of the extension
space. This, however, doesn't really change the picture for sensible
networking cases as there should be no need to run the same packet
twice (before and after the clone) through conntrack without packet
header or zone changes and without commit.
The fixes tag points to the introduction of helpers, since that's the
main UAF trigger for the sharing.
Fixes: a21b06e73191 ("net: sched: add helper support in act_ct")
Cc: stable@vger.kernel.org
Reported-by: Axel Mierczuk <axel.mierczuk@1password.com>
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Reviewed-by: Xin Long <lucien.xin@gmail.com>
Reviewed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/20260921145655.3167436-5-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_ct.c | 18 ++++++++++++++++--
1 file changed, 16 insertions(+), 2 deletions(-)
--- a/net/sched/act_ct.c
+++ b/net/sched/act_ct.c
@@ -979,11 +979,11 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct
struct tcf_result *res)
{
struct net *net = dev_net(skb->dev);
+ bool cached, commit, clear, nat;
enum ip_conntrack_info ctinfo;
struct tcf_ct *c = to_ct(a);
struct nf_conn *tmpl = NULL;
struct nf_hook_state state;
- bool cached, commit, clear;
int nh_ofs, err, retval;
struct tcf_ct_params *p;
bool add_helper = false;
@@ -998,6 +998,7 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct
retval = p->action;
commit = p->ct_action & TCA_CT_ACT_COMMIT;
clear = p->ct_action & TCA_CT_ACT_CLEAR;
+ nat = p->ct_action & TCA_CT_ACT_NAT;
tmpl = p->tmpl;
tcf_lastuse_update(&c->tcf_tm);
@@ -1046,6 +1047,19 @@ TC_INDIRECT_SCOPE int tcf_ct_act(struct
* different zone.
*/
cached = tcf_ct_skb_nfct_cached(net, skb, p);
+
+ /* If the ct entry is not confirmed and shared with some other skb,
+ * e.g., a cloned one, we can't just modify it with a commit or nat
+ * as we must not modify the extension set. Reset.
+ */
+ if (cached && (commit || nat)) {
+ ct = nf_ct_get(skb, &ctinfo);
+ if (ct && !nf_ct_is_confirmed(ct) && nf_ct_shared(ct)) {
+ nf_reset_ct(skb);
+ cached = false;
+ }
+ }
+
if (!cached) {
if (tcf_ct_flow_table_lookup(p, skb, family)) {
skip_add = true;
@@ -1083,7 +1097,7 @@ do_nat:
if (err)
goto drop;
add_helper = true;
- if (p->ct_action & TCA_CT_ACT_NAT && !nfct_seqadj(ct)) {
+ if (nat && !nfct_seqadj(ct)) {
if (!nfct_seqadj_ext_add(ct))
goto drop;
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 448/457] KVM: arm64: nv: Fix life cycle of the nested_mmus array
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (446 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 447/457] net/sched: act_ct: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 449/457] KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction Greg Kroah-Hartman
` (19 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shen Yongchao, Karl Mehltretter,
Lorenzo Stoakes (ARM), Marc Zyngier, Wei-Lin Chang, Oliver Upton,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Zyngier <maz@kernel.org>
[ Upstream commit 33346f8960c7bb6a3b4e273b5cfe25c5a8be349f ]
The nested_mmus array holds the shadow page tables that are used when
a guest is running a nested context. These structures are allocated on
VCPU_INIT for whole guest, which implies that they may have to be
relocated as the array grows.
Should a VCPU_INIT occur whilst a vcpu is actively running an L2 and
that the allocation requires relocation, that vcpu will still be
running with a pointer to the previous structure, which will have been
freed.
Fix this by turning the array of structures to an array of pointers,
which is now allocated at VM creation, sized to the absolute maximum
that KVM can handle.
In turn, each VCPU_INIT contributes S2_MMU_PER_VCPU to the pool. No
reallocation is ever performed, and the life cycle of each object is
much clearer:
- the nested_mmus array is allocated in kvm_init_nested(), and freed
in kvm_arch_destroy_vm()
- s2_mmu structures are allocated in kvm_vcpu_init_nested(), and freed
on kvm_arch_flush_shadow_all()
Finally, the freeing of vcpu->arch.vncr_array is made consistent
rather than being done on some failure paths, but not others.
Fixes: 4f128f8e1aaa ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
Reported-by: Shen Yongchao <grayhat@foxmail.com>
Reported-by: Karl Mehltretter <kmehltretter@gmail.com>
Suggested-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Link: https://lore.kernel.org/r/20260803224405.41468-1-kmehltretter@gmail.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Reviewed-by: Wei-Lin Chang <weilin.chang@arm.com>
Link: https://patch.msgid.link/20260911162203.1919330-2-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
[ Backport to 7.2: omit vncr_tlb_count initialization because this tree
removed the counter in 87c2bbf189829 and does not have the subsequent
VNCR TLB tracking reintroduction. Retain kvcalloc() for the per-vCPU
MMU block, with the new fixed S2_MMU_PER_VCPU allocation size, because
this call site has not undergone the upstream allocator conversion.
Preserve the pointer-array lifetime changes required by e5843f4effaa2
("KVM: arm64: nv: Delay freeing of shadow S2 structures until VM
destruction"). No functions are added. ]
Stable-dep-of: e5843f4effaa ("KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/kvm_host.h | 2
arch/arm64/include/asm/kvm_nested.h | 2
arch/arm64/kvm/arm.c | 8 ++-
arch/arm64/kvm/nested.c | 89 ++++++++++++++++--------------------
4 files changed, 49 insertions(+), 52 deletions(-)
--- a/arch/arm64/include/asm/kvm_host.h
+++ b/arch/arm64/include/asm/kvm_host.h
@@ -322,7 +322,7 @@ struct kvm_arch {
* Stage 2 paging state for VMs with nested S2 using a virtual
* VMID.
*/
- struct kvm_s2_mmu *nested_mmus;
+ struct kvm_s2_mmu **nested_mmus;
size_t nested_mmus_size;
int nested_mmus_next;
--- a/arch/arm64/include/asm/kvm_nested.h
+++ b/arch/arm64/include/asm/kvm_nested.h
@@ -66,7 +66,7 @@ static inline u64 translate_ttbr0_el2_to
extern bool forward_smc_trap(struct kvm_vcpu *vcpu);
extern bool forward_debug_exception(struct kvm_vcpu *vcpu);
-extern void kvm_init_nested(struct kvm *kvm);
+extern int kvm_init_nested(struct kvm *kvm);
extern int kvm_vcpu_init_nested(struct kvm_vcpu *vcpu);
extern void kvm_init_nested_s2_mmu(struct kvm_s2_mmu *mmu);
extern struct kvm_s2_mmu *lookup_s2_mmu(struct kvm_vcpu *vcpu);
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -236,8 +236,6 @@ int kvm_arch_init_vm(struct kvm *kvm, un
mutex_unlock(&kvm->lock);
#endif
- kvm_init_nested(kvm);
-
ret = kvm_share_hyp(kvm, kvm + 1);
if (ret)
return ret;
@@ -252,6 +250,10 @@ int kvm_arch_init_vm(struct kvm *kvm, un
if (ret)
goto err_free_cpumask;
+ ret = kvm_init_nested(kvm);
+ if (ret)
+ goto err_uninit_mmu;
+
if (is_protected_kvm_enabled()) {
/*
* If any failures occur after this is successful, make sure to
@@ -280,6 +282,7 @@ int kvm_arch_init_vm(struct kvm *kvm, un
err_uninit_mmu:
kvm_uninit_stage2_mmu(kvm);
+ kvfree(kvm->arch.nested_mmus);
err_free_cpumask:
free_cpumask_var(kvm->arch.supported_cpus);
err_unshare_kvm:
@@ -337,6 +340,7 @@ void kvm_arch_destroy_vm(struct kvm *kvm
kvm_unshare_hyp(kvm, kvm + 1);
+ kvfree(kvm->arch.nested_mmus);
kvm_arm_teardown_hypercalls(kvm);
}
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -44,10 +44,14 @@ struct vncr_tlb {
*/
#define S2_MMU_PER_VCPU 2
-void kvm_init_nested(struct kvm *kvm)
+int kvm_init_nested(struct kvm *kvm)
{
- kvm->arch.nested_mmus = NULL;
+ kvm->arch.nested_mmus = kvmalloc_objs(struct kvm_s2_mmu *,
+ KVM_MAX_VCPUS * S2_MMU_PER_VCPU,
+ GFP_KERNEL_ACCOUNT);
kvm->arch.nested_mmus_size = 0;
+
+ return kvm->arch.nested_mmus ? 0 : -ENOMEM;
}
static int init_nested_s2_mmu(struct kvm *kvm, struct kvm_s2_mmu *mmu)
@@ -68,8 +72,9 @@ static int init_nested_s2_mmu(struct kvm
int kvm_vcpu_init_nested(struct kvm_vcpu *vcpu)
{
struct kvm *kvm = vcpu->kvm;
- struct kvm_s2_mmu *tmp;
- int num_mmus, ret = 0;
+ int num_mmus;
+
+ lockdep_assert_held(&kvm->arch.config_lock);
if (test_bit(KVM_ARM_VCPU_HAS_EL2_E2H0, kvm->arch.vcpu_features) &&
!cpus_have_final_cap(ARM64_HAS_HCR_NV1))
@@ -82,51 +87,40 @@ int kvm_vcpu_init_nested(struct kvm_vcpu
if (!vcpu->arch.ctxt.vncr_array)
return -ENOMEM;
- /*
- * Let's treat memory allocation failures as benign: If we fail to
- * allocate anything, return an error and keep the allocated array
- * alive. Userspace may try to recover by initializing the vcpu
- * again, and there is no reason to affect the whole VM for this.
- */
num_mmus = atomic_read(&kvm->online_vcpus) * S2_MMU_PER_VCPU;
if (num_mmus > kvm->arch.nested_mmus_size) {
- tmp = kvcalloc(num_mmus, sizeof(*tmp), GFP_KERNEL_ACCOUNT);
- if (!tmp)
- return -ENOMEM;
+ struct kvm_s2_mmu *tmp;
+ int i, ret = 0;
- write_lock(&kvm->mmu_lock);
-
- if (kvm->arch.nested_mmus_size) {
- memcpy(tmp, kvm->arch.nested_mmus,
- size_mul(sizeof(*tmp), kvm->arch.nested_mmus_size));
+ tmp = kvcalloc(S2_MMU_PER_VCPU, sizeof(*tmp), GFP_KERNEL_ACCOUNT);
+ if (!tmp)
+ ret = -ENOMEM;
- for (int i = 0; i < kvm->arch.nested_mmus_size; i++)
- tmp[i].pgt->mmu = &tmp[i];
+ for (i = 0; !ret && i < S2_MMU_PER_VCPU; i++) {
+ ret = init_nested_s2_mmu(kvm, &tmp[i]);
+ if (ret)
+ break;
}
- swap(kvm->arch.nested_mmus, tmp);
-
- write_unlock(&kvm->mmu_lock);
-
- kvfree(tmp);
- }
+ if (ret) {
+ while (--i >= 0)
+ kvm_free_stage2_pgd(&tmp[i]);
- for (int i = kvm->arch.nested_mmus_size; !ret && i < num_mmus; i++)
- ret = init_nested_s2_mmu(kvm, &kvm->arch.nested_mmus[i]);
+ kvfree(tmp);
+ free_page((unsigned long)vcpu->arch.ctxt.vncr_array);
+ vcpu->arch.ctxt.vncr_array = NULL;
+ return ret;
+ }
- if (ret) {
- for (int i = kvm->arch.nested_mmus_size; i < num_mmus; i++)
- kvm_free_stage2_pgd(&kvm->arch.nested_mmus[i]);
+ guard(write_lock)(&kvm->mmu_lock);
- free_page((unsigned long)vcpu->arch.ctxt.vncr_array);
- vcpu->arch.ctxt.vncr_array = NULL;
+ for (i = 0; i < S2_MMU_PER_VCPU; i++)
+ kvm->arch.nested_mmus[i + kvm->arch.nested_mmus_size] = &tmp[i];
- return ret;
+ kvm->arch.nested_mmus_size += S2_MMU_PER_VCPU;
}
- kvm->arch.nested_mmus_size = num_mmus;
-
return 0;
}
@@ -740,7 +734,7 @@ void kvm_s2_mmu_iterate_by_vmid(struct k
write_lock(&kvm->mmu_lock);
for (int i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (!kvm_s2_mmu_valid(mmu))
continue;
@@ -782,7 +776,7 @@ struct kvm_s2_mmu *lookup_s2_mmu(struct
* if S2 translation is disabled.
*/
for (int i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (!kvm_s2_mmu_valid(mmu))
continue;
@@ -821,7 +815,7 @@ static struct kvm_s2_mmu *get_s2_mmu_nes
for (i = kvm->arch.nested_mmus_next;
i < (kvm->arch.nested_mmus_size + kvm->arch.nested_mmus_next);
i++) {
- s2_mmu = &kvm->arch.nested_mmus[i % kvm->arch.nested_mmus_size];
+ s2_mmu = kvm->arch.nested_mmus[i % kvm->arch.nested_mmus_size];
if (atomic_read(&s2_mmu->refcnt) == 0)
break;
@@ -1277,7 +1271,7 @@ void kvm_nested_s2_wp(struct kvm *kvm)
return;
for (i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (kvm_s2_mmu_valid(mmu))
kvm_stage2_wp_range(mmu, 0, kvm_phys_size(mmu));
@@ -1296,7 +1290,7 @@ void kvm_nested_s2_unmap(struct kvm *kvm
return;
for (i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (kvm_s2_mmu_valid(mmu))
kvm_stage2_unmap_range(mmu, 0, kvm_phys_size(mmu), may_block);
@@ -1315,7 +1309,7 @@ void kvm_nested_s2_flush(struct kvm *kvm
return;
for (i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (kvm_s2_mmu_valid(mmu))
kvm_stage2_flush_range(mmu, 0, kvm_phys_size(mmu));
@@ -1324,16 +1318,15 @@ void kvm_nested_s2_flush(struct kvm *kvm
void kvm_arch_flush_shadow_all(struct kvm *kvm)
{
- int i;
-
- for (i = 0; i < kvm->arch.nested_mmus_size; i++) {
- struct kvm_s2_mmu *mmu = &kvm->arch.nested_mmus[i];
+ for (int i = kvm->arch.nested_mmus_size - 1; i >= 0; i--) {
+ struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (!WARN_ON(atomic_read(&mmu->refcnt)))
kvm_free_stage2_pgd(mmu);
+
+ if ((i % S2_MMU_PER_VCPU) == 0)
+ kvfree(mmu);
}
- kvfree(kvm->arch.nested_mmus);
- kvm->arch.nested_mmus = NULL;
kvm->arch.nested_mmus_size = 0;
kvm_uninit_stage2_mmu(kvm);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 449/457] KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (447 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 448/457] KVM: arm64: nv: Fix life cycle of the nested_mmus array Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 450/457] KVM: x86: Move IRQ-related helper declarations from kvm_host.h => irq.h Greg Kroah-Hartman
` (18 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Marc Zyngier,
Wei-Lin Chang, Oliver Upton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Zyngier <maz@kernel.org>
[ Upstream commit e5843f4effaa2ffac3e789ecd4456403564961d4 ]
We free the shadow S2 structures from kvm_arch_flush_shadow_all(), which
is a Bad Idea(tm). Freeing the page tables is fair game (this is what
this callback is for), but freeing the container that could still be
referenced by another part of the system is not great.
Instead, grow separate destructors that gets called when we tear the VM
down for good. From there, we can nuke both the individual MMUs as well
as the global array that points to them, safe in the knowledge that the
vcpus themselves have been destroyed already.
Fixes: 4f128f8e1aaac ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Reviewed-by: Wei-Lin Chang <weilin.chang@arm.com>
Link: https://patch.msgid.link/20260911162203.1919330-3-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/kvm_nested.h | 1 +
arch/arm64/kvm/arm.c | 4 ++--
arch/arm64/kvm/nested.c | 15 ++++++++++-----
3 files changed, 13 insertions(+), 7 deletions(-)
--- a/arch/arm64/include/asm/kvm_nested.h
+++ b/arch/arm64/include/asm/kvm_nested.h
@@ -67,6 +67,7 @@ static inline u64 translate_ttbr0_el2_to
extern bool forward_smc_trap(struct kvm_vcpu *vcpu);
extern bool forward_debug_exception(struct kvm_vcpu *vcpu);
extern int kvm_init_nested(struct kvm *kvm);
+extern void kvm_destroy_nested(struct kvm *kvm);
extern int kvm_vcpu_init_nested(struct kvm_vcpu *vcpu);
extern void kvm_init_nested_s2_mmu(struct kvm_s2_mmu *mmu);
extern struct kvm_s2_mmu *lookup_s2_mmu(struct kvm_vcpu *vcpu);
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -282,7 +282,7 @@ int kvm_arch_init_vm(struct kvm *kvm, un
err_uninit_mmu:
kvm_uninit_stage2_mmu(kvm);
- kvfree(kvm->arch.nested_mmus);
+ kvm_destroy_nested(kvm);
err_free_cpumask:
free_cpumask_var(kvm->arch.supported_cpus);
err_unshare_kvm:
@@ -340,7 +340,7 @@ void kvm_arch_destroy_vm(struct kvm *kvm
kvm_unshare_hyp(kvm, kvm + 1);
- kvfree(kvm->arch.nested_mmus);
+ kvm_destroy_nested(kvm);
kvm_arm_teardown_hypercalls(kvm);
}
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -54,6 +54,15 @@ int kvm_init_nested(struct kvm *kvm)
return kvm->arch.nested_mmus ? 0 : -ENOMEM;
}
+void kvm_destroy_nested(struct kvm *kvm)
+{
+ for (int i = 0; i < kvm->arch.nested_mmus_size; i+= S2_MMU_PER_VCPU)
+ kvfree(kvm->arch.nested_mmus[i]);
+
+ kvm->arch.nested_mmus_size = 0;
+ kvfree(kvm->arch.nested_mmus);
+}
+
static int init_nested_s2_mmu(struct kvm *kvm, struct kvm_s2_mmu *mmu)
{
/*
@@ -1318,16 +1327,12 @@ void kvm_nested_s2_flush(struct kvm *kvm
void kvm_arch_flush_shadow_all(struct kvm *kvm)
{
- for (int i = kvm->arch.nested_mmus_size - 1; i >= 0; i--) {
+ for (int i = 0; i < kvm->arch.nested_mmus_size; i++) {
struct kvm_s2_mmu *mmu = kvm->arch.nested_mmus[i];
if (!WARN_ON(atomic_read(&mmu->refcnt)))
kvm_free_stage2_pgd(mmu);
-
- if ((i % S2_MMU_PER_VCPU) == 0)
- kvfree(mmu);
}
- kvm->arch.nested_mmus_size = 0;
kvm_uninit_stage2_mmu(kvm);
}
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 450/457] KVM: x86: Move IRQ-related helper declarations from kvm_host.h => irq.h
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (448 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 449/457] KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 451/457] KVM: x86/mmu: Move kvm_arch_async_page_ready() below kvm_tdp_page_fault() Greg Kroah-Hartman
` (17 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Kai Huang, Binbin Wu, Paolo Bonzini, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 0bdd2d6d7328a7debcf138a7d6ef95d01a26b1b8 ]
Move the function declaration for APIs to get/query pending IRQs from
kvm_host.h to irq.h, as the APIs are only used by KVM x86 code.
No functional change intended.
Reviewed-by: Yosry Ahmed <yosry@kernel.org>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Message-ID: <20260613000329.732085-25-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/include/asm/kvm_host.h | 5 -----
arch/x86/kvm/irq.h | 6 ++++++
arch/x86/kvm/svm/nested.c | 1 +
arch/x86/kvm/vmx/nested.c | 1 +
4 files changed, 8 insertions(+), 5 deletions(-)
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -2462,12 +2462,7 @@ enum {
# define kvm_memslots_for_spte_role(kvm, role) __kvm_memslots(kvm, 0)
#endif
-int kvm_cpu_has_injectable_intr(struct kvm_vcpu *v);
-int kvm_cpu_has_interrupt(struct kvm_vcpu *vcpu);
-int kvm_cpu_has_extint(struct kvm_vcpu *v);
int kvm_arch_interrupt_allowed(struct kvm_vcpu *vcpu);
-int kvm_cpu_get_extint(struct kvm_vcpu *v);
-int kvm_cpu_get_interrupt(struct kvm_vcpu *v);
void kvm_vcpu_reset(struct kvm_vcpu *vcpu, bool init_event);
int kvm_pv_send_ipi(struct kvm *kvm, unsigned long ipi_bitmap_low,
--- a/arch/x86/kvm/irq.h
+++ b/arch/x86/kvm/irq.h
@@ -112,6 +112,12 @@ static inline int irqchip_in_kernel(stru
return mode != KVM_IRQCHIP_NONE;
}
+int kvm_cpu_has_injectable_intr(struct kvm_vcpu *v);
+int kvm_cpu_has_interrupt(struct kvm_vcpu *vcpu);
+int kvm_cpu_has_extint(struct kvm_vcpu *v);
+int kvm_cpu_get_extint(struct kvm_vcpu *v);
+int kvm_cpu_get_interrupt(struct kvm_vcpu *v);
+
void kvm_inject_pending_timer_irqs(struct kvm_vcpu *vcpu);
void kvm_inject_apic_timer_irqs(struct kvm_vcpu *vcpu);
void kvm_apic_nmi_wd_deliver(struct kvm_vcpu *vcpu);
--- a/arch/x86/kvm/svm/nested.c
+++ b/arch/x86/kvm/svm/nested.c
@@ -23,6 +23,7 @@
#include "kvm_emulate.h"
#include "trace.h"
+#include "irq.h"
#include "mmu.h"
#include "x86.h"
#include "smm.h"
--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -11,6 +11,7 @@
#include "x86.h"
#include "cpuid.h"
#include "hyperv.h"
+#include "irq.h"
#include "mmu.h"
#include "nested.h"
#include "pmu.h"
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 451/457] KVM: x86/mmu: Move kvm_arch_async_page_ready() below kvm_tdp_page_fault()
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (449 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 450/457] KVM: x86: Move IRQ-related helper declarations from kvm_host.h => irq.h Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 452/457] KVM: x86/mmu: Move kvm_mmu_do_page_fault() from mmu_internal.h => mmu.c Greg Kroah-Hartman
` (16 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Kai Huang,
Sean Christopherson, Binbin Wu, Paolo Bonzini, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 31a2cf735cc00c01526bcb676f111d5c0b711d17 ]
Move the implementation of kvm_arch_async_page_ready() "down" in mmu.c so
that it lives below kvm_tdp_page_fault(). This will allow moving
kvm_mmu_do_page_fault() into mmu.c without needing a forward declaration.
No functional change intended.
Reviewed-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Message-ID: <20260613000329.732085-29-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/mmu/mmu.c | 62 ++++++++++++++++++++++++-------------------------
1 file changed, 31 insertions(+), 31 deletions(-)
--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -4600,37 +4600,6 @@ static bool kvm_arch_setup_async_pf(stru
kvm_vcpu_gfn_to_hva(vcpu, fault->gfn), &arch);
}
-void kvm_arch_async_page_ready(struct kvm_vcpu *vcpu, struct kvm_async_pf *work)
-{
- int r;
-
- if (WARN_ON_ONCE(work->arch.error_code & PFERR_PRIVATE_ACCESS))
- return;
-
- if ((vcpu->arch.mmu->root_role.direct != work->arch.direct_map) ||
- work->wakeup_all)
- return;
-
- r = kvm_mmu_reload(vcpu);
- if (unlikely(r))
- return;
-
- if (!vcpu->arch.mmu->root_role.direct &&
- work->arch.cr3 != kvm_mmu_get_guest_pgd(vcpu, vcpu->arch.mmu))
- return;
-
- r = kvm_mmu_do_page_fault(vcpu, work->cr2_or_gpa, work->arch.error_code,
- true, NULL, NULL);
-
- /*
- * Account fixed page faults, otherwise they'll never be counted, but
- * ignore stats for all other return times. Page-ready "faults" aren't
- * truly spurious and never trigger emulation
- */
- if (r == RET_PF_FIXED)
- vcpu->stat.pf_fixed++;
-}
-
static void kvm_mmu_finish_page_fault(struct kvm_vcpu *vcpu,
struct kvm_page_fault *fault, int r)
{
@@ -5088,6 +5057,37 @@ long kvm_arch_vcpu_pre_fault_memory(stru
return min(range->size, end - range->gpa);
}
+void kvm_arch_async_page_ready(struct kvm_vcpu *vcpu, struct kvm_async_pf *work)
+{
+ int r;
+
+ if (WARN_ON_ONCE(work->arch.error_code & PFERR_PRIVATE_ACCESS))
+ return;
+
+ if ((vcpu->arch.mmu->root_role.direct != work->arch.direct_map) ||
+ work->wakeup_all)
+ return;
+
+ r = kvm_mmu_reload(vcpu);
+ if (unlikely(r))
+ return;
+
+ if (!vcpu->arch.mmu->root_role.direct &&
+ work->arch.cr3 != kvm_mmu_get_guest_pgd(vcpu, vcpu->arch.mmu))
+ return;
+
+ r = kvm_mmu_do_page_fault(vcpu, work->cr2_or_gpa, work->arch.error_code,
+ true, NULL, NULL);
+
+ /*
+ * Account fixed page faults, otherwise they'll never be counted, but
+ * ignore stats for all other return times. Page-ready "faults" aren't
+ * truly spurious and never trigger emulation
+ */
+ if (r == RET_PF_FIXED)
+ vcpu->stat.pf_fixed++;
+}
+
#ifdef CONFIG_KVM_GUEST_MEMFD
static void kvm_assert_gmem_invalidate_lock_held(struct kvm_memory_slot *slot)
{
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 452/457] KVM: x86/mmu: Move kvm_mmu_do_page_fault() from mmu_internal.h => mmu.c
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (450 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 451/457] KVM: x86/mmu: Move kvm_arch_async_page_ready() below kvm_tdp_page_fault() Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 453/457] KVM: move TSS constants from kvm_host.h to tss.h Greg Kroah-Hartman
` (15 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Kai Huang,
Sean Christopherson, Binbin Wu, Paolo Bonzini, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 20fe9252460524f9028b515f0f672442ffe6779b ]
Move kvm_mmu_do_page_fault() into mmu.c, as there are no users outside of
mmu.c, and the function typically isn't inlined by the compiler anyways.
This will allow moving the EMULTYPE_xxx definitions into x86.h without
having to include x86.h in mmu_internal.h, i.e. will help preserve the
goal of making x86.h KVM x86's "top-level" include.
No functional change intended.
Reviewed-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Message-ID: <20260613000329.732085-30-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/mmu/mmu.c | 67 +++++++++++++++++++++++++++++++++++++++-
arch/x86/kvm/mmu/mmu_internal.h | 66 ---------------------------------------
2 files changed, 66 insertions(+), 67 deletions(-)
--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -4957,7 +4957,7 @@ out_unlock:
}
#endif
-int kvm_tdp_page_fault(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
+static int kvm_tdp_page_fault(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault)
{
#ifdef CONFIG_X86_64
if (tdp_mmu_enabled)
@@ -4967,6 +4967,71 @@ int kvm_tdp_page_fault(struct kvm_vcpu *
return direct_page_fault(vcpu, fault);
}
+static int kvm_mmu_do_page_fault(struct kvm_vcpu *vcpu, gpa_t cr2_or_gpa,
+ u64 err, bool prefetch, int *emulation_type,
+ u8 *level)
+{
+ struct kvm_page_fault fault = {
+ .addr = cr2_or_gpa,
+ .error_code = err,
+ .exec = err & PFERR_FETCH_MASK,
+ .write = err & PFERR_WRITE_MASK,
+ .present = err & PFERR_PRESENT_MASK,
+ .rsvd = err & PFERR_RSVD_MASK,
+ .user = err & PFERR_USER_MASK,
+ .prefetch = prefetch,
+ .is_tdp = likely(vcpu->arch.mmu->page_fault == kvm_tdp_page_fault),
+ .nx_huge_page_workaround_enabled =
+ is_nx_huge_page_enabled(vcpu->kvm),
+
+ .max_level = KVM_MAX_HUGEPAGE_LEVEL,
+ .req_level = PG_LEVEL_4K,
+ .goal_level = PG_LEVEL_4K,
+ .is_private = err & PFERR_PRIVATE_ACCESS,
+
+ .pfn = KVM_PFN_ERR_FAULT,
+ };
+ int r;
+
+ if (vcpu->arch.mmu->root_role.direct) {
+ /*
+ * Things like memslots don't understand the concept of a shared
+ * bit. Strip it so that the GFN can be used like normal, and the
+ * fault.addr can be used when the shared bit is needed.
+ */
+ fault.gfn = gpa_to_gfn(fault.addr) & ~kvm_gfn_direct_bits(vcpu->kvm);
+ fault.slot = kvm_vcpu_gfn_to_memslot(vcpu, fault.gfn);
+ }
+
+ /*
+ * With retpoline being active an indirect call is rather expensive,
+ * so do a direct call in the most common case.
+ */
+ if (IS_ENABLED(CONFIG_MITIGATION_RETPOLINE) && fault.is_tdp)
+ r = kvm_tdp_page_fault(vcpu, &fault);
+ else
+ r = vcpu->arch.mmu->page_fault(vcpu, &fault);
+
+ /*
+ * Not sure what's happening, but punt to userspace and hope that
+ * they can fix it by changing memory to shared, or they can
+ * provide a better error.
+ */
+ if (r == RET_PF_EMULATE && fault.is_private) {
+ pr_warn_ratelimited("kvm: unexpected emulation request on private memory\n");
+ kvm_mmu_prepare_memory_fault_exit(vcpu, &fault);
+ return -EFAULT;
+ }
+
+ if (fault.write_fault_to_shadow_pgtable && emulation_type)
+ *emulation_type |= EMULTYPE_WRITE_PF_TO_SP;
+ if (level)
+ *level = fault.goal_level;
+
+ return r;
+}
+
+
static int kvm_tdp_page_prefault(struct kvm_vcpu *vcpu, gpa_t gpa,
u64 error_code, u8 *level)
{
--- a/arch/x86/kvm/mmu/mmu_internal.h
+++ b/arch/x86/kvm/mmu/mmu_internal.h
@@ -290,8 +290,6 @@ struct kvm_page_fault {
bool write_fault_to_shadow_pgtable;
};
-int kvm_tdp_page_fault(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault);
-
/*
* Return values of handle_mmio_page_fault(), mmu.page_fault(), fast_page_fault(),
* and of course kvm_mmu_do_page_fault().
@@ -337,70 +335,6 @@ static inline void kvm_mmu_prepare_memor
fault->is_private);
}
-static inline int kvm_mmu_do_page_fault(struct kvm_vcpu *vcpu, gpa_t cr2_or_gpa,
- u64 err, bool prefetch,
- int *emulation_type, u8 *level)
-{
- struct kvm_page_fault fault = {
- .addr = cr2_or_gpa,
- .error_code = err,
- .exec = err & PFERR_FETCH_MASK,
- .write = err & PFERR_WRITE_MASK,
- .present = err & PFERR_PRESENT_MASK,
- .rsvd = err & PFERR_RSVD_MASK,
- .user = err & PFERR_USER_MASK,
- .prefetch = prefetch,
- .is_tdp = likely(vcpu->arch.mmu->page_fault == kvm_tdp_page_fault),
- .nx_huge_page_workaround_enabled =
- is_nx_huge_page_enabled(vcpu->kvm),
-
- .max_level = KVM_MAX_HUGEPAGE_LEVEL,
- .req_level = PG_LEVEL_4K,
- .goal_level = PG_LEVEL_4K,
- .is_private = err & PFERR_PRIVATE_ACCESS,
-
- .pfn = KVM_PFN_ERR_FAULT,
- };
- int r;
-
- if (vcpu->arch.mmu->root_role.direct) {
- /*
- * Things like memslots don't understand the concept of a shared
- * bit. Strip it so that the GFN can be used like normal, and the
- * fault.addr can be used when the shared bit is needed.
- */
- fault.gfn = gpa_to_gfn(fault.addr) & ~kvm_gfn_direct_bits(vcpu->kvm);
- fault.slot = kvm_vcpu_gfn_to_memslot(vcpu, fault.gfn);
- }
-
- /*
- * With retpoline being active an indirect call is rather expensive,
- * so do a direct call in the most common case.
- */
- if (IS_ENABLED(CONFIG_MITIGATION_RETPOLINE) && fault.is_tdp)
- r = kvm_tdp_page_fault(vcpu, &fault);
- else
- r = vcpu->arch.mmu->page_fault(vcpu, &fault);
-
- /*
- * Not sure what's happening, but punt to userspace and hope that
- * they can fix it by changing memory to shared, or they can
- * provide a better error.
- */
- if (r == RET_PF_EMULATE && fault.is_private) {
- pr_warn_ratelimited("kvm: unexpected emulation request on private memory\n");
- kvm_mmu_prepare_memory_fault_exit(vcpu, &fault);
- return -EFAULT;
- }
-
- if (fault.write_fault_to_shadow_pgtable && emulation_type)
- *emulation_type |= EMULTYPE_WRITE_PF_TO_SP;
- if (level)
- *level = fault.goal_level;
-
- return r;
-}
-
int kvm_mmu_max_mapping_level(struct kvm *kvm, struct kvm_page_fault *fault,
const struct kvm_memory_slot *slot, gfn_t gfn);
void kvm_mmu_hugepage_adjust(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 453/457] KVM: move TSS constants from kvm_host.h to tss.h
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (451 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 452/457] KVM: x86/mmu: Move kvm_mmu_do_page_fault() from mmu_internal.h => mmu.c Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 454/457] KVM: x86: Reject nested CAP enablement if nested virtualization is disabled Greg Kroah-Hartman
` (14 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kai Huang, Paolo Bonzini,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paolo Bonzini <pbonzini@redhat.com>
[ Upstream commit 35fdfa632e7cf8271189c7ae6f97e7c4b55f7f80 ]
Suggested-by: Kai Huang <kai.huang@intel.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/include/asm/kvm_host.h | 7 -------
arch/x86/kvm/tss.h | 7 +++++++
arch/x86/kvm/vmx/vmx.c | 1 +
3 files changed, 8 insertions(+), 7 deletions(-)
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -2433,13 +2433,6 @@ static inline void kvm_inject_gp(struct
kvm_queue_exception_e(vcpu, GP_VECTOR, error_code);
}
-#define TSS_IOPB_BASE_OFFSET 0x66
-#define TSS_BASE_SIZE 0x68
-#define TSS_IOPB_SIZE (65536 / 8)
-#define TSS_REDIRECTION_SIZE (256 / 8)
-#define RMODE_TSS_SIZE \
- (TSS_BASE_SIZE + TSS_REDIRECTION_SIZE + TSS_IOPB_SIZE + 1)
-
enum {
TASK_SWITCH_CALL = 0,
TASK_SWITCH_IRET = 1,
--- a/arch/x86/kvm/tss.h
+++ b/arch/x86/kvm/tss.h
@@ -57,4 +57,11 @@ struct tss_segment_16 {
u16 ldt;
};
+#define TSS_IOPB_BASE_OFFSET 0x66
+#define TSS_BASE_SIZE 0x68
+#define TSS_IOPB_SIZE (65536 / 8)
+#define TSS_REDIRECTION_SIZE (256 / 8)
+#define RMODE_TSS_SIZE \
+ (TSS_BASE_SIZE + TSS_REDIRECTION_SIZE + TSS_IOPB_SIZE + 1)
+
#endif
--- a/arch/x86/kvm/vmx/vmx.c
+++ b/arch/x86/kvm/vmx/vmx.c
@@ -72,6 +72,7 @@
#include "x86.h"
#include "x86_ops.h"
#include "smm.h"
+#include "tss.h"
#include "vmx_onhyperv.h"
#include "vmenter.h"
#include "posted_intr.h"
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 454/457] KVM: x86: Reject nested CAP enablement if nested virtualization is disabled
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (452 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 453/457] KVM: move TSS constants from kvm_host.h to tss.h Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 455/457] KVM: x86: Add static calls for nested virtualization ops Greg Kroah-Hartman
` (13 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vitaly Kuznetsov,
Sean Christopherson, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit b65699be2c606d2687593516d93e66d16a713b61 ]
Add a flag to explicitly track if nested virtualization is enabled, and use
it enumerate that various nested CAPs are unsupported, and to reject
enablement of said CAPs. When the nested ops hooks were moved to their
own structure, KVM's NULL-by-default behavior was deliberately dropped,
with the changelog asserting that all was well. That wasn't quite true;
there is no danger to KVM, but now KVM is over-reporting support for
KVM_CAP_NESTED_STATE and KVM_CAP_HYPERV_ENLIGHTENED_VMCS.
Fixes: 33b22172452f ("KVM: x86: move nested-related kvm_x86_ops to a separate struct")
Reviewed-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Link: https://patch.msgid.link/20260630202828.440724-2-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/include/asm/kvm_host.h | 2 ++
arch/x86/kvm/hyperv.c | 3 ++-
arch/x86/kvm/svm/svm.c | 1 +
arch/x86/kvm/vmx/vmx.c | 1 +
arch/x86/kvm/x86.c | 12 +++++++-----
5 files changed, 13 insertions(+), 6 deletions(-)
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -2019,6 +2019,8 @@ struct kvm_x86_ops {
};
struct kvm_x86_nested_ops {
+ bool enabled;
+
void (*leave_nested)(struct kvm_vcpu *vcpu);
bool (*is_exception_vmexit)(struct kvm_vcpu *vcpu, u8 vector,
u32 error_code);
--- a/arch/x86/kvm/hyperv.c
+++ b/arch/x86/kvm/hyperv.c
@@ -2800,7 +2800,8 @@ int kvm_get_hv_cpuid(struct kvm_vcpu *vc
};
int i, nent = ARRAY_SIZE(cpuid_entries);
- if (kvm_x86_ops.nested_ops->get_evmcs_version)
+ if (kvm_x86_ops.nested_ops->enabled &&
+ kvm_x86_ops.nested_ops->get_evmcs_version)
evmcs_ver = kvm_x86_ops.nested_ops->get_evmcs_version(vcpu);
if (cpuid->nent < nent)
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -5662,6 +5662,7 @@ static __init int svm_hardware_setup(voi
if (r)
return r;
}
+ svm_nested_ops.enabled = nested;
/*
* KVM's MMU doesn't support using 2-level paging for itself, and thus
--- a/arch/x86/kvm/vmx/vmx.c
+++ b/arch/x86/kvm/vmx/vmx.c
@@ -8771,6 +8771,7 @@ __init int vmx_hardware_setup(void)
if (r)
return r;
}
+ vmx_nested_ops.enabled = nested;
kvm_set_posted_intr_wakeup_handler(pi_wakeup_handler);
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -4517,7 +4517,7 @@ int kvm_vm_ioctl_check_extension(struct
r &= ~KVM_X2APIC_ENABLE_SUPPRESS_EOI_BROADCAST;
break;
case KVM_CAP_NESTED_STATE:
- r = kvm_x86_ops.nested_ops->get_state ?
+ r = kvm_x86_ops.nested_ops->enabled ?
kvm_x86_ops.nested_ops->get_state(NULL, NULL, 0) : 0;
break;
#ifdef CONFIG_KVM_HYPERV
@@ -4525,7 +4525,8 @@ int kvm_vm_ioctl_check_extension(struct
r = kvm_x86_ops.enable_l2_tlb_flush != NULL;
break;
case KVM_CAP_HYPERV_ENLIGHTENED_VMCS:
- r = kvm_x86_ops.nested_ops->enable_evmcs != NULL;
+ r = kvm_x86_ops.nested_ops->enabled &&
+ kvm_x86_ops.nested_ops->enable_evmcs != NULL;
break;
#endif
case KVM_CAP_SMALLER_MAXPHYADDR:
@@ -5567,7 +5568,8 @@ static int kvm_vcpu_ioctl_enable_cap(str
uint16_t vmcs_version;
void __user *user_ptr;
- if (!kvm_x86_ops.nested_ops->enable_evmcs)
+ if (!kvm_x86_ops.nested_ops->enabled ||
+ !kvm_x86_ops.nested_ops->enable_evmcs)
return -ENOTTY;
r = kvm_x86_ops.nested_ops->enable_evmcs(vcpu, &vmcs_version);
if (!r) {
@@ -6067,7 +6069,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
u32 user_data_size;
r = -EINVAL;
- if (!kvm_x86_ops.nested_ops->get_state)
+ if (!kvm_x86_ops.nested_ops->enabled)
break;
BUILD_BUG_ON(sizeof(user_data_size) != sizeof(user_kvm_nested_state->size));
@@ -6097,7 +6099,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
int idx;
r = -EINVAL;
- if (!kvm_x86_ops.nested_ops->set_state)
+ if (!kvm_x86_ops.nested_ops->enabled)
break;
r = -EFAULT;
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 455/457] KVM: x86: Add static calls for nested virtualization ops
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (453 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 454/457] KVM: x86: Reject nested CAP enablement if nested virtualization is disabled Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 456/457] accel/ivpu: Drop IRQF_ONESHOT to allow IPC IRQ threading on PREEMPT_RT Greg Kroah-Hartman
` (12 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 4b9819a50674dd40d176033f9ea2e23a70889dc6 ]
Use static calls to invoke nested virtualization ops, as many of the calls
are in relatively hot paths when L2 is active, e.g. checking for events,
and because there's no reason not use static calls these days.
Opportunistically use a RET0 static call for get_evmcs_version() instead
of manually checking for a non-NULL vendor hook.
Link: https://patch.msgid.link/20260630202828.440724-3-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Backport notes:
Preserve the stable tree's kvm_x86_vendor_init()/exit() declarations and
ignore_msrs/report_ignored_msrs module parameters at the conflicting
insertion points. Initialize nested static calls in the existing
kvm_ops_update() instead of adding kvm_nested_ops_update(), preserving the
same mandatory, optional, and return-zero hook behavior without adding a
function. Keep the get_nested_state_pages call conversion so target
10180a277549339020b08000206092c07e0bff5a applies unchanged.
Stable-dep-of: 10180a277549 ("KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/include/asm/kvm-x86-nested-ops.h | 36 +++++++++++++++++++++
arch/x86/include/asm/kvm_host.h | 8 ++++
arch/x86/kvm/hyperv.c | 7 +---
arch/x86/kvm/mmu.h | 5 +--
arch/x86/kvm/mmu/paging_tmpl.h | 2 -
arch/x86/kvm/x86.c | 50 +++++++++++++++++++-----------
arch/x86/kvm/x86.h | 2 -
7 files changed, 83 insertions(+), 27 deletions(-)
create mode 100644 arch/x86/include/asm/kvm-x86-nested-ops.h
--- /dev/null
+++ b/arch/x86/include/asm/kvm-x86-nested-ops.h
@@ -0,0 +1,36 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#if !defined(KVM_X86_NESTED_OP) || \
+ !defined(KVM_X86_NESTED_OP_OPTIONAL) || \
+ !defined(KVM_X86_NESTED_OP_OPTIONAL_RET0)
+#error Missing one or more KVM_X86_NESTED_OP #defines
+#else
+/*
+ * KVM_X86_NESTED_OP() and KVM_X86_NESTED_OP_OPTIONAL() are used to help
+ * generate both DECLARE/DEFINE_STATIC_CALL() invocations and
+ * "static_call_update()" calls.
+ *
+ * KVM_X86_NESTED_OP_OPTIONAL() can be used for those functions that can have
+ * a NULL definition. KVM_X86_NESTED_OP_OPTIONAL_RET0() can be used likewise
+ * to make a definition optional, but in this case the default will
+ * be __static_call_return0.
+ */
+KVM_X86_NESTED_OP(leave_nested)
+KVM_X86_NESTED_OP(is_exception_vmexit)
+KVM_X86_NESTED_OP(check_events)
+KVM_X86_NESTED_OP_OPTIONAL_RET0(has_events)
+KVM_X86_NESTED_OP(triple_fault)
+KVM_X86_NESTED_OP(get_state)
+KVM_X86_NESTED_OP(set_state)
+KVM_X86_NESTED_OP(get_nested_state_pages)
+KVM_X86_NESTED_OP_OPTIONAL_RET0(write_log_dirty)
+KVM_X86_NESTED_OP(translate_nested_gpa)
+#ifdef CONFIG_KVM_HYPERV
+KVM_X86_NESTED_OP_OPTIONAL(enable_evmcs)
+KVM_X86_NESTED_OP_OPTIONAL_RET0(get_evmcs_version)
+KVM_X86_NESTED_OP(hv_inject_synthetic_vmexit_post_tlb_flush)
+#endif
+#endif
+
+#undef KVM_X86_NESTED_OP
+#undef KVM_X86_NESTED_OP_OPTIONAL
+#undef KVM_X86_NESTED_OP_OPTIONAL_RET0
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -2077,6 +2077,14 @@ extern struct kvm_x86_ops kvm_x86_ops;
#define KVM_X86_OP_OPTIONAL_RET0 KVM_X86_OP
#include <asm/kvm-x86-ops.h>
+#define kvm_nested_call(func) static_call(kvm_x86_nested_##func)
+
+#define KVM_X86_NESTED_OP(func) \
+ DECLARE_STATIC_CALL(kvm_x86_nested_##func, *(((struct kvm_x86_nested_ops *)0)->func));
+#define KVM_X86_NESTED_OP_OPTIONAL KVM_X86_NESTED_OP
+#define KVM_X86_NESTED_OP_OPTIONAL_RET0 KVM_X86_NESTED_OP
+#include <asm/kvm-x86-nested-ops.h>
+
int kvm_x86_vendor_init(struct kvm_x86_init_ops *ops);
void kvm_x86_vendor_exit(void);
--- a/arch/x86/kvm/hyperv.c
+++ b/arch/x86/kvm/hyperv.c
@@ -2419,7 +2419,7 @@ static int kvm_hv_hypercall_complete(str
ret = kvm_skip_emulated_instruction(vcpu);
if (tlb_lock_count)
- kvm_x86_ops.nested_ops->hv_inject_synthetic_vmexit_post_tlb_flush(vcpu);
+ kvm_nested_call(hv_inject_synthetic_vmexit_post_tlb_flush)(vcpu);
return ret;
}
@@ -2800,9 +2800,8 @@ int kvm_get_hv_cpuid(struct kvm_vcpu *vc
};
int i, nent = ARRAY_SIZE(cpuid_entries);
- if (kvm_x86_ops.nested_ops->enabled &&
- kvm_x86_ops.nested_ops->get_evmcs_version)
- evmcs_ver = kvm_x86_ops.nested_ops->get_evmcs_version(vcpu);
+ if (kvm_x86_ops.nested_ops->enabled)
+ evmcs_ver = kvm_nested_call(get_evmcs_version)(vcpu);
if (cpuid->nent < nent)
return -E2BIG;
--- a/arch/x86/kvm/mmu.h
+++ b/arch/x86/kvm/mmu.h
@@ -308,9 +308,8 @@ static inline gpa_t kvm_translate_gpa(st
{
if (mmu != &vcpu->arch.nested_mmu)
return gpa;
- return kvm_x86_ops.nested_ops->translate_nested_gpa(vcpu, gpa, access,
- exception,
- pte_access);
+ return kvm_nested_call(translate_nested_gpa)(vcpu, gpa, access,
+ exception, pte_access);
}
static inline bool kvm_has_mirrored_tdp(const struct kvm *kvm)
--- a/arch/x86/kvm/mmu/paging_tmpl.h
+++ b/arch/x86/kvm/mmu/paging_tmpl.h
@@ -233,7 +233,7 @@ static int FNAME(update_accessed_dirty_b
!(pte & PT_GUEST_DIRTY_MASK)) {
trace_kvm_mmu_set_dirty_bit(table_gfn, index, sizeof(pte));
#if PTTYPE == PTTYPE_EPT
- if (kvm_x86_ops.nested_ops->write_log_dirty(vcpu, addr))
+ if (kvm_nested_call(write_log_dirty)(vcpu, addr))
return -EINVAL;
#endif
pte |= PT_GUEST_DIRTY_MASK;
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -148,6 +148,13 @@ EXPORT_STATIC_CALL_GPL(kvm_x86_get_cs_db
EXPORT_STATIC_CALL_GPL(kvm_x86_cache_reg);
EXPORT_STATIC_CALL_GPL(kvm_x86_get_cpl);
+#define KVM_X86_NESTED_OP(func) \
+ DEFINE_STATIC_CALL_NULL(kvm_x86_nested_##func, \
+ *(((struct kvm_x86_nested_ops *)0)->func));
+#define KVM_X86_NESTED_OP_OPTIONAL KVM_X86_NESTED_OP
+#define KVM_X86_NESTED_OP_OPTIONAL_RET0 KVM_X86_NESTED_OP
+#include <asm/kvm-x86-nested-ops.h>
+
static bool __read_mostly ignore_msrs = 0;
module_param(ignore_msrs, bool, 0644);
@@ -833,7 +840,7 @@ static void kvm_multiple_exception(struc
* wants to intercept the exception.
*/
if (is_guest_mode(vcpu) &&
- kvm_x86_ops.nested_ops->is_exception_vmexit(vcpu, nr, error_code)) {
+ kvm_nested_call(is_exception_vmexit)(vcpu, nr, error_code)) {
kvm_queue_exception_vmexit(vcpu, nr, has_error, error_code,
has_payload, payload);
return;
@@ -4518,7 +4525,7 @@ int kvm_vm_ioctl_check_extension(struct
break;
case KVM_CAP_NESTED_STATE:
r = kvm_x86_ops.nested_ops->enabled ?
- kvm_x86_ops.nested_ops->get_state(NULL, NULL, 0) : 0;
+ kvm_nested_call(get_state)(NULL, NULL, 0) : 0;
break;
#ifdef CONFIG_KVM_HYPERV
case KVM_CAP_HYPERV_DIRECT_TLBFLUSH:
@@ -5571,7 +5578,7 @@ static int kvm_vcpu_ioctl_enable_cap(str
if (!kvm_x86_ops.nested_ops->enabled ||
!kvm_x86_ops.nested_ops->enable_evmcs)
return -ENOTTY;
- r = kvm_x86_ops.nested_ops->enable_evmcs(vcpu, &vmcs_version);
+ r = kvm_nested_call(enable_evmcs)(vcpu, &vmcs_version);
if (!r) {
user_ptr = (void __user *)(uintptr_t)cap->args[0];
if (copy_to_user(user_ptr, &vmcs_version,
@@ -6077,8 +6084,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
if (get_user(user_data_size, &user_kvm_nested_state->size))
break;
- r = kvm_x86_ops.nested_ops->get_state(vcpu, user_kvm_nested_state,
- user_data_size);
+ r = kvm_nested_call(get_state)(vcpu, user_kvm_nested_state, user_data_size);
if (r < 0)
break;
@@ -6122,7 +6128,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
break;
idx = srcu_read_lock(&vcpu->kvm->srcu);
- r = kvm_x86_ops.nested_ops->set_state(vcpu, user_kvm_nested_state, &kvm_state);
+ r = kvm_nested_call(set_state)(vcpu, user_kvm_nested_state, &kvm_state);
srcu_read_unlock(&vcpu->kvm->srcu, idx);
break;
}
@@ -9560,6 +9566,8 @@ static void kvm_setup_efer_caps(void)
static inline void kvm_ops_update(struct kvm_x86_init_ops *ops)
{
+ const struct kvm_x86_nested_ops *nested_ops = ops->runtime_ops->nested_ops;
+
memcpy(&kvm_x86_ops, ops->runtime_ops, sizeof(kvm_x86_ops));
#define __KVM_X86_OP(func) \
@@ -9573,6 +9581,17 @@ static inline void kvm_ops_update(struct
#include <asm/kvm-x86-ops.h>
#undef __KVM_X86_OP
+#define __KVM_X86_NESTED_OP(func) \
+ static_call_update(kvm_x86_nested_##func, nested_ops->func);
+#define KVM_X86_NESTED_OP(func) \
+ WARN_ON(!nested_ops->func); __KVM_X86_NESTED_OP(func)
+#define KVM_X86_NESTED_OP_OPTIONAL __KVM_X86_NESTED_OP
+#define KVM_X86_NESTED_OP_OPTIONAL_RET0(func) \
+ static_call_update(kvm_x86_nested_##func, (void *)nested_ops->func ? : \
+ (void *)__static_call_return0);
+#include <asm/kvm-x86-nested-ops.h>
+#undef __KVM_X86_NESTED_OP
+
kvm_pmu_ops_update(ops->pmu_ops);
}
@@ -10109,11 +10128,11 @@ static void post_kvm_run_save(struct kvm
int kvm_check_nested_events(struct kvm_vcpu *vcpu)
{
if (kvm_test_request(KVM_REQ_TRIPLE_FAULT, vcpu)) {
- kvm_x86_ops.nested_ops->triple_fault(vcpu);
+ kvm_nested_call(triple_fault)(vcpu);
return 1;
}
- return kvm_x86_ops.nested_ops->check_events(vcpu);
+ return kvm_nested_call(check_events)(vcpu);
}
static void kvm_inject_exception(struct kvm_vcpu *vcpu)
@@ -10351,9 +10370,7 @@ static int kvm_check_and_inject_events(s
kvm_x86_call(enable_irq_window)(vcpu);
}
- if (is_guest_mode(vcpu) &&
- kvm_x86_ops.nested_ops->has_events &&
- kvm_x86_ops.nested_ops->has_events(vcpu, true))
+ if (is_guest_mode(vcpu) && kvm_nested_call(has_events)(vcpu, true))
*req_immediate_exit = true;
/*
@@ -10676,7 +10693,7 @@ static int vcpu_enter_guest(struct kvm_v
}
if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) {
- if (unlikely(!kvm_x86_ops.nested_ops->get_nested_state_pages(vcpu))) {
+ if (unlikely(!kvm_nested_call(get_nested_state_pages)(vcpu))) {
r = 0;
goto out;
}
@@ -10728,7 +10745,7 @@ static int vcpu_enter_guest(struct kvm_v
}
if (kvm_test_request(KVM_REQ_TRIPLE_FAULT, vcpu)) {
if (is_guest_mode(vcpu))
- kvm_x86_ops.nested_ops->triple_fault(vcpu);
+ kvm_nested_call(triple_fault)(vcpu);
if (kvm_check_request(KVM_REQ_TRIPLE_FAULT, vcpu)) {
vcpu->run->exit_reason = KVM_EXIT_SHUTDOWN;
@@ -11148,9 +11165,7 @@ bool kvm_vcpu_has_events(struct kvm_vcpu
if (kvm_hv_has_stimer_pending(vcpu))
return true;
- if (is_guest_mode(vcpu) &&
- kvm_x86_ops.nested_ops->has_events &&
- kvm_x86_ops.nested_ops->has_events(vcpu, false))
+ if (is_guest_mode(vcpu) && kvm_nested_call(has_events)(vcpu, false))
return true;
if (kvm_xen_has_pending_events(vcpu))
@@ -11575,8 +11590,7 @@ int kvm_arch_vcpu_ioctl_run(struct kvm_v
* a pending VM-Exit if L1 wants to intercept the exception.
*/
if (vcpu->arch.exception_from_userspace && is_guest_mode(vcpu) &&
- kvm_x86_ops.nested_ops->is_exception_vmexit(vcpu, ex->vector,
- ex->error_code)) {
+ kvm_nested_call(is_exception_vmexit)(vcpu, ex->vector, ex->error_code)) {
kvm_queue_exception_vmexit(vcpu, ex->vector,
ex->has_error_code, ex->error_code,
ex->has_payload, ex->payload);
--- a/arch/x86/kvm/x86.h
+++ b/arch/x86/kvm/x86.h
@@ -151,7 +151,7 @@ int kvm_check_nested_events(struct kvm_v
/* Forcibly leave the nested mode in cases like a vCPU reset */
static inline void kvm_leave_nested(struct kvm_vcpu *vcpu)
{
- kvm_x86_ops.nested_ops->leave_nested(vcpu);
+ kvm_nested_call(leave_nested)(vcpu);
}
/*
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 456/457] accel/ivpu: Drop IRQF_ONESHOT to allow IPC IRQ threading on PREEMPT_RT
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (454 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 455/457] KVM: x86: Add static calls for nested virtualization ops Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 457/457] i2c: qcom-geni: release DMA channels on probe error Greg Kroah-Hartman
` (11 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrzej Kacprowski, Karol Wachowski,
dri-devel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karol Wachowski <karol.wachowski@linux.intel.com>
commit 799c8f0b9f3fd728b32594aed3852044703b7e5b upstream.
The IPC RX hardirq handler matches consumers under a spinlock and
allocates rx_msg buffers. On PREEMPT_RT these spinlocks become sleeping
locks and the allocation may sleep, neither of which is allowed in true
hardirq context, resulting in "sleeping function called from invalid
context" splats.
IRQF_ONESHOT makes genirq keep the primary handler in hardirq even when
forced threading is enabled, so on PREEMPT_RT the handler cannot be
threaded. Drop the flag so the primary handler is threaded on PREEMPT_RT
and the IPC RX path runs in a context where sleeping is allowed. On the
MSI interrupt chip (IRQCHIP_ONESHOT_SAFE) the flag was stripped anyway,
so non-RT behaviour is unchanged.
Fixes: 85c9cc2d25f8 ("accel/ivpu: Use threaded IRQ for IPC callback processing")
Cc: Andrzej Kacprowski <andrzej.kacprowski@linux.intel.com>
Cc: Karol Wachowski <karol.wachowski@linux.intel.com>
Cc: dri-devel@lists.freedesktop.org
Reviewed-by: Andrzej Kacprowski <andrzej.kacprowski@linux.intel.com>
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
Link: https://patch.msgid.link/20260617092031.3016582-1-karol.wachowski@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/accel/ivpu/ivpu_drv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/accel/ivpu/ivpu_drv.c
+++ b/drivers/accel/ivpu/ivpu_drv.c
@@ -624,7 +624,7 @@ static int ivpu_irq_init(struct ivpu_dev
vdev->irq = pci_irq_vector(pdev, 0);
ret = devm_request_threaded_irq(vdev->drm.dev, vdev->irq, ivpu_hw_irq_handler,
- ivpu_ipc_irq_thread_handler, IRQF_NO_AUTOEN | IRQF_ONESHOT,
+ ivpu_ipc_irq_thread_handler, IRQF_NO_AUTOEN,
DRIVER_NAME, vdev);
if (ret)
ivpu_err(vdev, "Failed to request an IRQ %d\n", ret);
^ permalink raw reply [flat|nested] 469+ messages in thread
* [PATCH 7.2 457/457] i2c: qcom-geni: release DMA channels on probe error
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (455 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 456/457] accel/ivpu: Drop IRQF_ONESHOT to allow IPC IRQ threading on PREEMPT_RT Greg Kroah-Hartman
@ 2026-09-30 15:29 ` Greg Kroah-Hartman
2026-09-30 17:10 ` [PATCH 7.2 000/457] 7.2.9-rc1 review Ronald Warsow
` (10 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:29 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Konrad Dybcio,
Mukesh Kumar Savaliya, Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit 268aacb2e2a5c94d08e23194961234d0710c8407 upstream.
geni_i2c_init() grabs exclusive GPI tx/rx DMA channels when the serial
engine runs in GPI mode. If i2c_add_adapter() subsequently fails, probe
returns without releasing the channels, because the remove callback is
not invoked after a failed probe.
The adapter-registration failure path used to release the channels via
its err_dma label; that release was dropped when the probe tail was
restructured into geni_i2c_init().
Release the channels on the adapter-registration failure path, mirroring
geni_i2c_remove().
Fixes: d8d3bb127ad1 ("i2c: qcom-geni: Isolate serial engine setup")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-3-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-geni.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -1158,6 +1158,7 @@ static int geni_i2c_probe(struct platfor
ret = i2c_add_adapter(&gi2c->adap);
if (ret) {
+ release_gpi_dma(gi2c);
dev_err_probe(dev, ret, "Error adding i2c adapter\n");
pm_runtime_disable(gi2c->se.dev);
return ret;
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (456 preceding siblings ...)
2026-09-30 15:29 ` [PATCH 7.2 457/457] i2c: qcom-geni: release DMA channels on probe error Greg Kroah-Hartman
@ 2026-09-30 17:10 ` Ronald Warsow
2026-09-30 22:56 ` Peter Schneider
` (9 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Ronald Warsow @ 2026-09-30 17:10 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
conor, hargar, broonie, achill, sr
Hi
kernel build / boot test on x86_64 (Intel).
No regressions here.
Thanks
Tested-by: Ronald Warsow <rwarsow@gmx.de>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (457 preceding siblings ...)
2026-09-30 17:10 ` [PATCH 7.2 000/457] 7.2.9-rc1 review Ronald Warsow
@ 2026-09-30 22:56 ` Peter Schneider
2026-10-01 6:18 ` Benjamin Boortz
` (8 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Peter Schneider @ 2026-09-30 22:56 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
Am 30.09.2026 um 17:21 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697v2 server. No dmesg oddities or regressions found.
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Beste Grüße,
Peter Schneider
--
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you. -- David McCullough Jr.
OpenPGP: 0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (458 preceding siblings ...)
2026-09-30 22:56 ` Peter Schneider
@ 2026-10-01 6:18 ` Benjamin Boortz
2026-10-01 9:19 ` Pavel Machek
` (7 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Benjamin Boortz @ 2026-10-01 6:18 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Wed, Sep 30, 2026 at 05:21:45PM +0200, Greg Kroah-Hartman wrote:
>This is the start of the stable review cycle for the 7.2.9 release.
>There are 457 patches in this series, all will be posted as a response
>to this one. If anyone has any issues with these being applied, please
>let me know.
Build and boot tested with QEMU for x86_64, i386, arm64, and riscv
across multiple configurations, and boots on AMD Ryzen 7 5800H.
No regressions observed.
Tested-by: Benjamin Boortz <bennib@mailbox.org>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (459 preceding siblings ...)
2026-10-01 6:18 ` Benjamin Boortz
@ 2026-10-01 9:19 ` Pavel Machek
2026-10-01 9:54 ` Ron Economos
` (6 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Pavel Machek @ 2026-10-01 9:19 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
[-- Attachment #1: Type: text/plain, Size: 501 bytes --]
Hi!
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
CIP testing did not find any problems here:
https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-7.2.y
Tested-by: Pavel Machek (CIP) <pavel@nabladev.com>
Best regards,
Pavel
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (460 preceding siblings ...)
2026-10-01 9:19 ` Pavel Machek
@ 2026-10-01 9:54 ` Ron Economos
2026-10-01 12:22 ` Takeshi Ogasawara
` (5 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Ron Economos @ 2026-10-01 9:54 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/30/26 08:21, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Built and booted successfully on RISC-V RV64 (HiFive Unmatched).
Tested-by: Ron Economos <re@w6rz.net>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (461 preceding siblings ...)
2026-10-01 9:54 ` Ron Economos
@ 2026-10-01 12:22 ` Takeshi Ogasawara
2026-10-01 13:11 ` Miguel Ojeda
` (4 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Takeshi Ogasawara @ 2026-10-01 12:22 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
Hi Greg
On Thu, Oct 1, 2026 at 3:18 AM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
>
Linux version 7.2.9-rc1 tested.
Build successfully completed.
Boot successfully completed.
No dmesg regressions.
Video output normal.
Sound output normal.
Lenovo ThinkPad X1 Carbon Gen10(Intel i7-1260P(x86_64) arch linux)
[ 0.000000] Linux version 7.2.9-rc1rv-g815c1e68a78f
(takeshi@ThinkPadX1Gen10J0764) (gcc (GCC) 16.2.1 20260810, GNU ld (GNU
Binutils) 2.47) #1 SMP PREEMPT_DYNAMIC Thu Oct 1 19:40:07 JST 2026
Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (462 preceding siblings ...)
2026-10-01 12:22 ` Takeshi Ogasawara
@ 2026-10-01 13:11 ` Miguel Ojeda
2026-10-01 16:44 ` Brett A C Sheffield
` (3 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Miguel Ojeda @ 2026-10-01 13:11 UTC (permalink / raw)
To: gregkh
Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
linux-kernel, linux, lkft-triage, patches, patches, pavel,
rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
Miguel Ojeda
On Wed, 30 Sep 2026 17:21:45 +0200 Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
Boot-tested under QEMU for Rust x86_64, arm64 and riscv64; built-tested
for loongarch64 and arm32:
Tested-by: Miguel Ojeda <ojeda@kernel.org>
Thanks!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (463 preceding siblings ...)
2026-10-01 13:11 ` Miguel Ojeda
@ 2026-10-01 16:44 ` Brett A C Sheffield
2026-10-02 7:44 ` Barry K. Nathan
` (2 subsequent siblings)
467 siblings, 0 replies; 469+ messages in thread
From: Brett A C Sheffield @ 2026-10-01 16:44 UTC (permalink / raw)
To: gregkh
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
Brett A C Sheffield
# Librecast Test Results
044/044 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast
CPU/kernel: Linux auntie 7.2.9-rc1-g815c1e68a78f #2 SMP PREEMPT_DYNAMIC Thu Oct 1 15:15:39 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux
Tested-by: Brett A C Sheffield <bacs@librecast.net>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (464 preceding siblings ...)
2026-10-01 16:44 ` Brett A C Sheffield
@ 2026-10-02 7:44 ` Barry K. Nathan
2026-10-02 13:50 ` Justin Forbes
2026-10-02 17:11 ` Florian Fainelli
467 siblings, 0 replies; 469+ messages in thread
From: Barry K. Nathan @ 2026-10-02 7:44 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/30/26 8:21 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested on an amd64 laptop (Lenovo ThinkPad T14 Gen 1) and an arm64
virtual machine. Working well, no regressions observed.
Tested-by: Barry K. Nathan <barryn@pobox.com>
--
-Barry K. Nathan <barryn@pobox.com>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (465 preceding siblings ...)
2026-10-02 7:44 ` Barry K. Nathan
@ 2026-10-02 13:50 ` Justin Forbes
2026-10-02 17:11 ` Florian Fainelli
467 siblings, 0 replies; 469+ messages in thread
From: Justin Forbes @ 2026-10-02 13:50 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Wed, Sep 30, 2026 at 05:21:45PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested rc1 against the Fedora build system (aarch64, ppc64le, s390x,
x86_64), and boot tested x86_64. No regressions noted.
Tested-by: Justin M. Forbes <jforbes@fedoraproject.org>
^ permalink raw reply [flat|nested] 469+ messages in thread
* Re: [PATCH 7.2 000/457] 7.2.9-rc1 review
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
` (466 preceding siblings ...)
2026-10-02 13:50 ` Justin Forbes
@ 2026-10-02 17:11 ` Florian Fainelli
467 siblings, 0 replies; 469+ messages in thread
From: Florian Fainelli @ 2026-10-02 17:11 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, sudipm.mukherjee, rwarsow, conor,
hargar, broonie, achill, sr
On 9/30/2026 8:21 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.9 release.
> There are 457 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.9-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On ARCH_BRCMSTB using 32-bit and 64-bit ARM kernels, build tested on
BMIPS_GENERIC:
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
--
Florian
^ permalink raw reply [flat|nested] 469+ messages in thread
end of thread, other threads:[~2026-10-02 17:11 UTC | newest]
Thread overview: 469+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 15:21 [PATCH 7.2 000/457] 7.2.9-rc1 review Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 001/457] drm/amd/display: Atomize IRQ register read/modify/write ops Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 002/457] ALSA: hda/realtek: Limit Star Labs internal mic boost Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 003/457] ALSA: hda/realtek: Add StarFighter HDA SSID Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 004/457] drm/amd/display: Remove sink usage from DPMS Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 005/457] remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 006/457] KVM: s390: Fix dirty marking in adapter_indicators_set*() Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 007/457] KVM: s390: Fix _gaccess_shadow_fault() Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 008/457] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 009/457] KVM: s390: Add missing srcu in kvm_s390_set_irq_state() Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 010/457] KVM: s390: Properly handle NULL pointer in dat_cond_set_storage_key() Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 011/457] KVM: s390: Fix potential races in dat skey functions Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 012/457] KVM: s390: Fix race in _destroy_pages_crste() Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 013/457] s390/uv: Fix loop condition in uv_find_secrets Greg Kroah-Hartman
2026-09-30 15:21 ` [PATCH 7.2 014/457] s390/uv: Prevent potential out-of-bounds read Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 015/457] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 016/457] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 017/457] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 018/457] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 019/457] bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 020/457] tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 021/457] HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 022/457] HID: winwing: fix use-after-free in force feedback teardown Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 023/457] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 024/457] KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 025/457] bpf: Allow terminal gotox instructions Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 026/457] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 027/457] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 028/457] bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 029/457] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 030/457] bpf: Fix u32 overflow issue in map batch operations Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 031/457] bpf, arm64: set up the frame pointer for the exception callback Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 032/457] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 033/457] pinctrl: generic: serialise pinctrl_generic_dt_node_to_map() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 034/457] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 035/457] HID: bpf: fix __hid_bpf_hw_check_params report length Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 036/457] RISC-V: KVM: Fix the conversion between vsip and hvip Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 037/457] KVM: riscv: Fix NACL hfence entry update order Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 038/457] RISC-V: KVM: Preserve firmware counter value across stop/start Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 039/457] RISC-V: KVM: Report snapshot write failure to the guest Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 040/457] RISC-V: KVM: Fix perf-backed counter accounting across stop and read Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 041/457] KVM: arm64: vgic-its: Free the caches when GITS_BASER changes Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 042/457] KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 043/457] KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 044/457] KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 045/457] KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2 Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 046/457] KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0 Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 047/457] KVM: arm64: Match hyp text by physical address in fix_host_ownership() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 048/457] KVM: selftests: fix steal_time for arm64 with host page size > 4K Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 049/457] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 050/457] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 051/457] scsi: block: Fix zones_cond out-of-bounds write on zone report Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 052/457] scsi: sd_zbc: Reject disks with too many zones Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 053/457] pinctrl: sunxi: A523: fix voltage withstand encoding Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 054/457] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 055/457] Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 056/457] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 057/457] selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 058/457] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 059/457] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 060/457] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 061/457] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 062/457] s390/cio: Guard PMCW field accesses with dnv check Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 063/457] netfs: Fix netfs_read_gaps() to use separate sink folios Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 064/457] netfs, afs: Fix symlink reading Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 065/457] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 066/457] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 067/457] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 068/457] eth: fbnic: Fix payload page pool error cleanup Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 069/457] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 070/457] net: pcs: rzn1-miic: Fix config array initialization Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 071/457] octeontx2-af: use seq_file for rsrc_alloc debugfs Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 072/457] net/mlx5: devcom, Base component size on linked devices Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 073/457] net/mlx5: SD, unload reps on shared FDB create error path Greg Kroah-Hartman
2026-09-30 15:22 ` [PATCH 7.2 074/457] net/mlx5: LAG, reload IB reps of LAG master before the rest Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 075/457] bpf: Make post-verification instruction rewrites killable Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 076/457] bpf: Preserve packet pointer class displacement in regsafe() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 077/457] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 078/457] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 079/457] ipv4: fib: fix data-race and stale genid check around nh->nh_saddr Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 080/457] gpiolib: use of_node_name if line-name is missing Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 081/457] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 082/457] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 083/457] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 084/457] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 085/457] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 086/457] arm64: io: Reject non-user protection in ioremap_prot() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 087/457] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 088/457] pinctrl: qcom: ipq5210: Publish the OF module alias Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 089/457] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 090/457] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 091/457] drm/nouveau/disp: dont reject HDMI config on cards without SCDC Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 092/457] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 093/457] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 094/457] net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 095/457] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 096/457] net: ethtool: keep rtnl_lock for the ioctl self test Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 097/457] eth: fbnic: Handle maximum standalone channels Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 098/457] eth: fbnic: use the Rx queue napi pointer to find the napi vector Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 099/457] eth: fbnic: reset num_napi when the napi vectors are freed Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 100/457] eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 101/457] eth: fbnic: Handle FW mailbox completions flagged with an error Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 102/457] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 103/457] net: allow IFLA_INET_CONF messages when NLA_F_NESTED unset Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 104/457] bpf: Bound ownership depth through local kptrs and graph roots Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 105/457] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 106/457] bpf: Check params size before reading reserved fields Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 107/457] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 108/457] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 109/457] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 110/457] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 111/457] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 112/457] Revert "drm/virtio: Allow importing prime buffers when 3D is enabled" Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 113/457] drm/virtio: sync shmem backing on guest-bound transfers Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 114/457] pinctrl: tegra238: Fix register bank for AON pin groups Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 115/457] drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 116/457] ovpn: preserve IPv6 scope id for netlink peer endpoints Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 117/457] ovpn: skip UDP source validation for unspecified addresses Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 118/457] ovpn: track UDP socket route key for peer dst cache Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 119/457] ovpn: validate peer state before caching UDP dst Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 120/457] ovpn: replace bind when learning local endpoint Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 121/457] ovpn: replace bind when clearing stale local source Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 122/457] ovpn: always unhash old VPN addresses before rehashing Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 123/457] ovpn: reject duplicate peer VPN addresses Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 124/457] ovpn: reject multipeer peers without " Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 125/457] ovpn: reject invalid peer " Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 126/457] drm/xe/gt_throttle: Report power brake as a throttle reason on CRI Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 127/457] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 128/457] Bluetooth: btintel_pcie: validate device-supplied DMA indices Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 129/457] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 130/457] bpf: Reject non-negative offsets in stack_slot_obj_get_spi() Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 131/457] octeontx2-af: Fix memory scaling limitation in SR-IOV mode Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 132/457] ipv6: Prevent rt6_insert_exception() for dying fib6_info Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 133/457] net: dont require the hwtstamp NDOs when a PHY provides timestamping Greg Kroah-Hartman
2026-09-30 15:23 ` [PATCH 7.2 134/457] dpll: use exact lookup for reference sync pin id Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 135/457] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 136/457] ipv6: Fix dst leak for uncached routes Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 137/457] udp: relocate a connected socket in the 4-tuple hash table on re-connect Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 138/457] udp: remove a disconnected socket from the 4-tuple hash table Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 139/457] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 140/457] drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 141/457] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 142/457] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 143/457] net: spacemit: clear TX descriptor on fragment mapping failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 144/457] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 145/457] genetlink: report the real command id for dump-only ops in policy dumps Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 146/457] net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 147/457] PM: hibernate: Freeze kernel threads after image preallocation Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 148/457] thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 149/457] bpf: Fix bounds check for skb-backed dynptrs Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 150/457] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 151/457] bpf: Reject pkt arguments in mutating subprogs Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 152/457] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 153/457] firewire: cdev: fix back-transition for iso_resource_auto client resource Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 154/457] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 155/457] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 156/457] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 157/457] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 158/457] net: stmmac: selftests: Validate EEE based on the actual LPI timer value Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 159/457] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 160/457] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 161/457] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 162/457] net: stmmac: size the RX buffers from the frame length, not the MTU Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 163/457] net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 164/457] eth: fbnic: Avoid rounding zero ring sizes Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 165/457] net/sched: fix potential stack infoleak in em_text_dump() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 166/457] bpf: Reject dev-bound-only programs on other devices Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 167/457] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 168/457] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 169/457] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 170/457] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 171/457] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 172/457] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 173/457] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 174/457] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 175/457] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 176/457] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 177/457] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 178/457] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 179/457] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 180/457] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 181/457] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 182/457] net: bcmgenet: stop Tx NAPI before disabling the queues Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 183/457] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 184/457] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 185/457] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 186/457] net: dsa: mv88e6xxx: 88E6191X and 88E6193X have no PTP Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 187/457] net: mdio: realtek-rtl9300: fix RTL931x C22 extended page selection Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 188/457] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 189/457] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 190/457] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 191/457] net: stmmac: clear stale buf->page after recycling on skb build failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 192/457] net: ipv6: keep room for the mac header in dst_dev_overhead() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 193/457] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 7.2 194/457] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 195/457] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 196/457] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 197/457] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 198/457] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 199/457] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 200/457] net: xps: reject an out of range traffic class Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 201/457] drm/imagination: clamp freelist reconstruction requests Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 202/457] bonding: crypto offload enabled, non-offload slave failover, rekey failed Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 203/457] macsec: initialize SecY before registering the netdevice Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 204/457] net/sched: act_ife: validate metadata length before decoding Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 205/457] net: emac: move setting of netops to fix crash Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 206/457] bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 207/457] net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 208/457] net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 209/457] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 210/457] net: phylink: record the PHY only once bringup cannot fail Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 211/457] net: wangxun: implement soft quiesce for PCIe error recovery Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 212/457] net: libwx: fix races in Tx timestamp handling Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 213/457] nfp: hold IPsec RX state under the XArray lock Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 214/457] net/rds: size a connections path set by the transport it ends up with Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 215/457] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 216/457] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 217/457] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 218/457] net: flush skb_defer_nodes in dev_cpu_dead() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 219/457] gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 220/457] gve: fix TX drop when GSO MSS is too small for hw Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 221/457] gve: DQO: reject TSO packets with an out of range MSS Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 222/457] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 223/457] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 224/457] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 225/457] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 226/457] ovl: fix UAF in ovl_do_mkdir() debug print Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 227/457] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 228/457] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 229/457] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 230/457] perf/x86/intel: Dont pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 231/457] perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 232/457] perf/x86/intel: Delete dead NVL PEBS data-source initcall Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 233/457] perf/core: Fix a refcount leak in attach_perf_ctx_data() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 234/457] perf/core: Fill branch entries with a single assignment Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 235/457] sched/core: Account PSI IRQ time to the execution context, not the scheduling context Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 236/457] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 237/457] drm/pagemap: dma-unmap pages before handling migration errors Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 238/457] vlan: require the MAC header to be present in __vlan_insert_inner_tag() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 239/457] x86/mce: Fix hardware debug register corruption on task migration Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 240/457] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 241/457] x86/sev: Make vTPM SVSM calls preemption-safe Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 242/457] vsock: ignore empty child namespace mode writes Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 243/457] virtio_net: copy zerocopy frags in start_xmit without NAPI Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 244/457] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 245/457] tcp: prevent collapsing skbs across boundary in rtx queue Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 246/457] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 247/457] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 248/457] arm64/boot: Disable trapping of PMZR_EL0 writes to EL2 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 249/457] arm64: errata: match the target implementation CPUs own MIDR Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 250/457] ata: libata-scsi: bound the ATA passthru sense descriptor writes Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 251/457] bna: prevent IOC timer rearm during teardown Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 252/457] bpf: fs/xattr: dont assume the inode is locked in path_unlink/path_rmdir Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 253/457] crypto: s390/hmac - Generate intermediate CV for API partial block handling Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 7.2 254/457] cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 255/457] cgroup/pids: Restore pids.events notifications in local mode Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 256/457] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 257/457] fprobe: Terminate the fgraph_data list when the reservation is not filled Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 258/457] fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbots "WARNING in do_new_mount" saga Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 259/457] netfs: Fix missing alloc tagging of direct mempool allocations Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 260/457] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 261/457] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 262/457] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 263/457] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 264/457] ipe: fix use-after-free when auditing a newly loaded policy Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 265/457] ipe: protect the dm-verity root hash with RCU Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 266/457] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 267/457] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 268/457] kprobes: Fix permanent hang when flushing the kprobe optimizer Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 269/457] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 270/457] gpio: cdev: fix kernel stack leak to user-space in error path Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 271/457] gpio: zynq: fix runtime PM leak on request " Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 272/457] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 273/457] mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 274/457] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 275/457] drm/client: fix restore of partially initialized client Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 276/457] drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 277/457] drm/imagination: Fix page count for page table for map() interface Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 278/457] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 279/457] drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1 Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 280/457] drm/i915/dp_mst: Fix configuring FEC for a disconnected stream Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 281/457] drm/i915/dp_mst: Fix configuring TUs " Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 282/457] drm/amdkfd: fix use-after-free and multi-container gap in kfd_dev_mapping Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 283/457] drm/amd/display: Fix dc stream excess put in dm_update_crtc_state() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 284/457] drm/amd/display: Bump frame warning limit for clang builds of dml Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 285/457] drm/amdgpu/userq: fix double jiffies conversion in hang detect timeout Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 286/457] drm/amdgpu/vcn4.0.3: fix video_timeout unit mismatch in jpeg reset wait Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 287/457] drm/amdgpu/vcn5.0.1: " Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 288/457] drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 289/457] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 290/457] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 291/457] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 292/457] drm/amdgpu: move userq fence wait out of signalling section Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 293/457] drm/nouveau/dmem: pin VRAM for the whole registered range Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 294/457] drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 295/457] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 296/457] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 297/457] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 298/457] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 299/457] drm/nouveau: Fix runtime PM leak in nouveau_connector_detect() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 300/457] drm/nouveau: RCU-free the scheduler-containing nouveau_sched Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 301/457] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 302/457] drm/xe/vm: nuke PTs only after unlinking contested VMAs Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 303/457] drm/xe: harden adjust_idledly() against divide-by-zero and overflow Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 304/457] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 305/457] drm/xe: Keep walking on SVM eviction failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 306/457] drm/virtio: fix memory leak of fence event on execbuffer failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 307/457] drm/virtio: fix NULL pointer dereference on fence allocation failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 308/457] gpio: tps65219: Fix GPIO input value reads Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 309/457] gpio: tps65219: Use the variant-specific direction callback Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 310/457] gpio: tps65219: Fix TPS65214 GPIO direction programming Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 311/457] mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 312/457] mm/hugetlb: do not dissolve gigantic pages without runtime support Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 313/457] mm/hugetlb: preserve mremap address delta when skipping page tables Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 7.2 314/457] mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 315/457] mm/damon/ops-common: use a page-aligned address in damon_ptep_mkold() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 316/457] mm/damon/core: fix unconditionally skip last region Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 317/457] mm/damon/core: allow esz to be set to zero Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 318/457] mm/damon/core: reset invalid quota->charge_target_from Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 319/457] PCI: Fix BAR resize for devices on a root bus Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 320/457] PCI: of_property: Omit bus properties without a subordinate bus Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 321/457] packet: use ubuf_info completion for TX_RING packets Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 322/457] HID: alps: unregister DualPoint Stick input device on remove Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 323/457] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 324/457] HID: hid-oxp: use cancel_delayed_work_sync() in remove Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 325/457] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 326/457] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 327/457] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 328/457] net/mlx5e: advertise MACsec offload only when supported Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 329/457] net/mlx5e: fix swapped IPv6 IPsec policy masks Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 330/457] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 331/457] net: airoha: npu: cancel wdt_work after releasing the WDT IRQ Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 332/457] net: arp: terminate device name before lookup Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 333/457] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 334/457] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 335/457] net: ipconfig: bound DHCP option construction Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 336/457] net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 337/457] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 338/457] net: openvswitch: conntrack: remove add_helper dead code Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 339/457] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 340/457] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 341/457] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 342/457] net: bridge: mdb: restart port group walk after deletion Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 343/457] net: ena: fix PHC cleanup on probe failure Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 344/457] net: ena: fix MMIO read buffer leak " Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 345/457] net: phy: intel-xway: workaround 100BASE-TX Link-Up issue Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 346/457] net: phy: micrel: Advance register data pointer in write loop Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 347/457] net: txgbe: fix FDIR filter restore for VF rules Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 348/457] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 349/457] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 350/457] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 351/457] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 352/457] netfilter: nf_tables: skip expired catchall elements on insert and delete Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 353/457] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 354/457] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 355/457] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 356/457] nfc: trf7970a: power down on startup RX gain failure Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 357/457] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 358/457] scsi: ufs: core: Keep internal commands dispatchable during error handling Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 359/457] scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 360/457] parisc: Increase kernel stack size to 32kb Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 361/457] parisc: parse early parameters in setup_arch() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 362/457] perf/core: Fix NULL pmu_ctx passed to pmu->sched_task() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 363/457] perf/core: Run sched_task() for PMUs with only CPU-wide events Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 364/457] perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 365/457] perf/x86/intel: Fix GRT " Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 366/457] perf/x86/intel: Fix DKT " Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 367/457] perf/x86/intel: Fix Panther Cove PEBS data-source snoop states Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 368/457] perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 369/457] perf/x86/intel: Remove incorrect Panther Cove " Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 370/457] perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 371/457] pinctrl: mpfs-mssio: fix width of unused bank voltage setting Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 372/457] pinctrl: mpfs-mssio: use correct regmap function to set bank voltage Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 373/457] pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 7.2 374/457] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 375/457] pinctrl: sunxi: keep a shadow copy of the data register output latches Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 376/457] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 377/457] s390/cmf: Fix virtual vs physical address confusion Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 378/457] s390/pci: Fix leak of struct pci_dev reference in zpci_report_status() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 379/457] s390/pci: Fix missing device lock " Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 380/457] s390/pci: Report SCLP status on error events when no pdev is associated Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 381/457] s390/pci: Dont report recovery success on skipped recovery Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 382/457] s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 383/457] KVM: Ensure memory attributes xarray nodes are accounted to the callers memcg Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 384/457] KVM: Dont treat reserved xarray entries as having memory attributes Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 385/457] KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 386/457] KVM: SEV: Do cache maintenance on the source VM during intra-host migration Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 387/457] KVM: arm64: Dont WARN on an unknown VM ioctl in protected mode Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 388/457] KVM: arm64: Fix AArch32 DBGBXVR<n> handling Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 389/457] KVM: arm64: Fix spurious warning for benign stage 2 teardown race Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 390/457] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, " Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 391/457] KVM: arm64: Transfer the hyp stack pages out of the host stage-2 Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 392/457] RISC-V: KVM: Serialize IMSIC attributes with vCPU migration Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 393/457] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 394/457] RISC-V: KVM: Release unused page after MMU invalidation Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 395/457] RISC-V: KVM: Propagate interrupted G-stage faults Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 396/457] RISC-V: KVM: Fix HSM hart status error propagation Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 397/457] sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 398/457] sched/cache: Decouple sched_cache_group from mm to fix UAF Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 399/457] sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 400/457] Bluetooth: hci_conn: fix CIS hold ownership on reuse Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 401/457] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 402/457] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 403/457] Bluetooth: ISO: balance the parent hold in hci_bind_bis() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 404/457] Bluetooth: ISO: release unused CIS holds after channel attach Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 405/457] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 406/457] Bluetooth: mgmt: fix race in read_unconf_index_list() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 407/457] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 408/457] smb: client: fix create context out-of-bounds reads Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 409/457] smb: client: close handle after create-context parsing failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 410/457] smb: client: clean up failed cached directory opens Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 411/457] smb: client: preserve create-context parsing errors Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 412/457] smb: client: use finish_no_open() for non-regular inodes Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 413/457] smb: client: validate POSIX create context length Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 414/457] smb: client: close completed creates on compound wait errors Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 415/457] smb: client: delete compound mids on send failure before unlock Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 416/457] xfs: dont assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 417/457] xfs: fix attr fork block count checks in xrep_inode_blockcounts Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 418/457] xfs: release orphanage dir inode if chown fails Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 419/457] xfs: use correct jiffies comparison function in xchk_maybe_relax Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 420/457] xfs: check padding field in xfs_ioc_commit_range Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 421/457] xfs: dont call xfs_exchange_range_finish for a dry run Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 422/457] xfs: only flag zero padding for dir3 data blocks, not dir3 block blocks Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 423/457] xfs: use the correct reservations for rtrmap/refcount recovery Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 424/457] xfs: check di_forkoff correctly in scrub Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 425/457] xfs: fix rtgroup repair estimations Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 426/457] xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 427/457] xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 428/457] xfs: dont let hidden_space go negative in xfs_metafile_resv_init Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 429/457] xfs: dont let memory failures leak blocks and kill repairs Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 430/457] xfs: dont merge different file IO error types Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 431/457] xfs: drop dquot flush lock when we cant find a buffer to flush Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 432/457] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 433/457] xfs: fix cursor and pointer handling when recovering iunlink buckets Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 7.2 434/457] drm/xe: Add wa_14025941587 to xe2, xe3 and xe3p platforms Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 435/457] landlock: Work around gcc-16 -Wuninitialized warning Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 436/457] accel/ivpu: Use threaded IRQ for IPC callback processing Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 437/457] accel/ivpu: Use separate flag for job timeout Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 438/457] i2c: qcom-geni: Isolate serial engine setup Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 439/457] i2c: qcom-geni: Move resource initialization to separate function Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 440/457] i2c: qcom-geni: Store of_device_id data in driver private struct Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 441/457] i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 442/457] super: convert s_count to refcount_t s_passive Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 443/457] super: take lock after last reference count Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 444/457] super: make iterate_supers_type() deletion-safe Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 445/457] drm/amd/display: Relax DML frame limit with UBSAN Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 446/457] net/sched: act_ct: fix helper UAF due to extensions realloc Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 447/457] net/sched: act_ct: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 448/457] KVM: arm64: nv: Fix life cycle of the nested_mmus array Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 449/457] KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 450/457] KVM: x86: Move IRQ-related helper declarations from kvm_host.h => irq.h Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 451/457] KVM: x86/mmu: Move kvm_arch_async_page_ready() below kvm_tdp_page_fault() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 452/457] KVM: x86/mmu: Move kvm_mmu_do_page_fault() from mmu_internal.h => mmu.c Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 453/457] KVM: move TSS constants from kvm_host.h to tss.h Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 454/457] KVM: x86: Reject nested CAP enablement if nested virtualization is disabled Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 455/457] KVM: x86: Add static calls for nested virtualization ops Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 456/457] accel/ivpu: Drop IRQF_ONESHOT to allow IPC IRQ threading on PREEMPT_RT Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 7.2 457/457] i2c: qcom-geni: release DMA channels on probe error Greg Kroah-Hartman
2026-09-30 17:10 ` [PATCH 7.2 000/457] 7.2.9-rc1 review Ronald Warsow
2026-09-30 22:56 ` Peter Schneider
2026-10-01 6:18 ` Benjamin Boortz
2026-10-01 9:19 ` Pavel Machek
2026-10-01 9:54 ` Ron Economos
2026-10-01 12:22 ` Takeshi Ogasawara
2026-10-01 13:11 ` Miguel Ojeda
2026-10-01 16:44 ` Brett A C Sheffield
2026-10-02 7:44 ` Barry K. Nathan
2026-10-02 13:50 ` Justin Forbes
2026-10-02 17:11 ` Florian Fainelli
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox