* [PATCH 6.12 000/877] 6.12.112-rc1 review
@ 2026-09-30 15:15 Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 001/877] Revert "hwmon: (emc1403) Drop hysteresis for low limit temperature" Greg Kroah-Hartman
` (884 more replies)
0 siblings, 885 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 6.12.112 release.
There are 877 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri, 02 Oct 2026 15:23:04 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.12.112-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.12.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 6.12.112-rc1
Longlong Xia <xialonglong@kylinos.cn>
mm/hugetlb: keep max_huge_pages when dissolving surplus folios
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Reject key-less BTF for hash maps
Pei Xiao <xiaopei01@kylinos.cn>
usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
Mario Limonciello <mario.limonciello@amd.com>
platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
mtd: rawnand: pl353: Fix debug prints
Steven Rostedt <rostedt@goodmis.org>
tracing: Move d_max_latency out of CONFIG_FSNOTIFY protection
Ben Hutchings <benh@debian.org>
bootconfig: Fix negative seeks on 32-bit with LFS enabled
Christoph Hellwig <hch@lst.de>
nvme: revert the cross-controller atomic write size validation
Lin.Cao <lincao12@amd.com>
drm/amdgpu: fix ring timeout issue in gfx10 sr-iov environment
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: don't free fd-owned sockets when reaping in the heartbeat
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: clear neighbour pointer in rose_kill_by_device()
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: cancel neighbour timers in rose_neigh_put() before freeing
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: drop CALL_REQUEST in loopback timer when device is not running
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: release netdev ref and destroy orphaned incoming sockets
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: fix netdev double-hold in rose_make_new()
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: disconnect orphaned STATE_2 sockets when device is gone
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: set SOCK_DESTROY in rose_kill_by_device() for prompt cleanup
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: fix notifier unregistered too early in rose_exit()
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: fix netdev double-hold in rose_rx_call_request()
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: guard rose_neigh_put() against NULL in timer expiry
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: clear neighbour pointer after rose_neigh_put() in state machines
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: fix race between loopback timer and module removal
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: hold loopback neighbour reference across timer callback
Bernard Pidoux <bernard.f6bvp@gmail.com>
rose: fix dev_put() leak in rose_loopback_timer()
Xie Bo <xb@ultrarisc.com>
RISC-V: KVM: Serialize IMSIC attributes with vCPU migration
Jiakai Xu <jiakaipeanut@gmail.com>
RISC-V: KVM: Fix null pointer dereference in kvm_riscv_aia_imsic_rw_attr()
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Update event constraints and cache_extra_regsfor ADL
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Update event constraints and cache_extra_regsfor LNL
Sean Christopherson <seanjc@google.com>
KVM: SEV: Do cache maintenance on the source VM during intra-host migration
Zheyun Shen <szy0127@sjtu.edu.cn>
KVM: SVM: Flush cache only on CPUs running SEV guest
Guangshuo Li <lgs201920130244@gmail.com>
net: ena: fix MMIO read buffer leak on probe failure
Dr. David Alan Gilbert <linux@treblig.org>
net: ena: Remove autopolling mode
Yuqi Xu <xuyuqiabc@gmail.com>
net: ipconfig: bound DHCP option construction
Thorsten Blum <thorsten.blum@linux.dev>
net: ipconfig: Remove outdated comment and indent code block
Ilya Maximets <i.maximets@ovn.org>
net/sched: act_ct: avoid modifying shared unconfirmed ct entry
Ilya Maximets <i.maximets@ovn.org>
net/sched: act_ct: fix helper UAF due to extensions realloc
Chen Changcheng <chenchangcheng@kylinos.cn>
HID: alps: unregister DualPoint Stick input device on remove
Bastien Nocera <hadess@hadess.net>
HID: hid-alps: Use pm_ptr instead of #ifdef CONFIG_PM
Willem de Bruijn <willemb@google.com>
packet: use ubuf_info completion for TX_RING packets
Liz Fong-Jones <lizf@honeycomb.io>
PCI: Fix BAR resize for devices on a root bus
Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
PCI: Fix Resizable BAR restore order
Christian Brauner <brauner@kernel.org>
super: make iterate_supers_type() deletion-safe
Longlong Xia <xialonglong@kylinos.cn>
mm/hugetlb: do not dissolve gigantic pages without runtime support
Usama Arif <usamaarif642@gmail.com>
mm/hugetlb: create hstate_is_gigantic_no_runtime helper
Jinjiang Tu <tujinjiang@huawei.com>
mm/hugetlb: fix surplus pages in dissolve_free_huge_page()
SJ Park <sj@kernel.org>
mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold()
Matthew Auld <matthew.auld@intel.com>
drm/xe/vm: nuke PTs only after unlinking contested VMAs
Jinjiang Tu <tujinjiang@huawei.com>
mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish
Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
mm/rmap: allocate anon_vma_chain objects unlocked when possible
Imre Deak <imre.deak@intel.com>
drm/i915/dp_mst: Fix configuring FEC for a disconnected stream
Jani Nikula <jani.nikula@intel.com>
drm/i915/mst: add mst sub-struct to struct intel_dp
shechenglong <shechenglong@xfusion.com>
drm/client: fix restore of partially initialized client
Thomas Zimmermann <tzimmermann@suse.de>
drm/client: Pass force parameter to client restore
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc()
Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL
Myeonghun Pak <mhun512@gmail.com>
bna: prevent IOC timer rearm during teardown
Fan Wu <wufan@kernel.org>
ipe: fix use-after-free when auditing a newly loaded policy
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
gpio: cdev: fix kernel stack leak to user-space in error path
Xiang Mei <xmei5@asu.edu>
vlan: require the MAC header to be present in __vlan_insert_inner_tag()
Fuad Tabba <fuad.tabba@linux.dev>
arm64/boot: Disable trapping of PMZR_EL0 writes to EL2
April Cardenas <april.cardenas@canonical.com>
smb/client: send lease break ACKs thru correct session for multiuser mounts
Frank Sorenson <sorenson@redhat.com>
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
Mike Lothian <mike@fireburn.co.uk>
drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
Yunxiang Li <Yunxiang.Li@amd.com>
drm: add drm_memory_stats_is_zero
Frank Sorenson <sorenson@redhat.com>
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
Chengjun Yao <Chengjun.Yao@amd.com>
drm/amdgpu: fix rmmio iounmap skipped on device removal
Christian König <christian.koenig@amd.com>
drm/amdgpu: use GFP_NOWAIT for memory allocations
Saleemkhan Jamadar <saleemkhan.jamadar@amd.com>
drm/amdgpu/umsch: remove vpe test from umsch
Christian König <christian.koenig@amd.com>
drm/amdgpu: set the VM pointer to NULL in amdgpu_job_prepare
Andrew Martin <Andrew.Martin@amd.com>
drm/amdgpu: Failed to check various return code
Joseph Qi <joseph.qi@linux.alibaba.com>
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
Bharath SM <bharathsm@microsoft.com>
smb: mark the new channel addition log as informational log with cifs_info
Devin Wittmayer <lucid_duck@justthetip.ca>
wifi: mac80211: refuse to make a monitor active when it has no queue
Benjamin Berg <benjamin.berg@intel.com>
wifi: mac80211: track MU-MIMO configuration on disabled interfaces
Daehyeon Ko <4ncienth@gmail.com>
wifi: libipw: reject TKIP frames without a full MIC
Saim Shujah <saimzst@gmail.com>
drm/msm/dpu: clear pending peripheral flush state
Yibo Tan <lhfff@tju.edu.cn>
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
Fan Wu <fanwu01@zju.edu.cn>
wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
Runyu Xiao <runyu.xiao@seu.edu.cn>
Input: hp_sdc - shut down kicker timer on module exit
Arun Easi <aeasi@cisco.com>
scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
Liu Zhenlong <dragonliu2018@gmail.com>
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
Jiapeng Chong <jiapeng.chong@linux.alibaba.com>
i2c: qcom-cci: Remove the unused variable cci_clk_rate
Bryan O'Donoghue <bryan.odonoghue@linaro.org>
i2c: qcom-cci: Stop complaining about DT set clock rate
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix LSE operations on {8,16}-bit types
Catalin Marinas <catalin.marinas@arm.com>
arm64: Use load LSE atomics for the non-return per-CPU atomic operations
Hongling Zeng <zenghongling@kylinos.cn>
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
Ahmed Naseef <naseefkm@gmail.com>
net: phy: mediatek: do not report link and per-speed LED rules together
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
swiotlb: use the adjusted address for the highmem page lookup
Xiang Mei <xmei5@asu.edu>
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
Takashi Iwai <tiwai@suse.de>
ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling
Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
David Howells <dhowells@redhat.com>
9p: Fix v9fs_issue_write() to update i_size and remote_i_size
David Howells <dhowells@redhat.com>
cifs: Fix specification of function pointers
Darrick J. Wong <djwong@kernel.org>
xfs: fix backwards mergeability logic in refcount scrubber
Darrick J. Wong <djwong@kernel.org>
xfs: fix under-reservation of blocks when repairing sf directories
Christoph Hellwig <hch@lst.de>
xfs: remove the i_ino field in struct xfs_inode
Darrick J. Wong <djwong@kernel.org>
xfs: strengthen the "is cow staging" helpers in scrub
Darrick J. Wong <djwong@kernel.org>
xfs: fix short ifork reaping computation in xreap_bmapi_binval
Darrick J. Wong <djwong@kernel.org>
xfs: report healthy filesystem events in scrub stats
Bjoern Doebel <doebel@amazon.de>
smb: client: fail DACL rewrite when the new DACL exceeds 64K
Ralph Boehme <slow@samba.org>
smb/client: fix security flag calculation when setting security descriptors
Ralph Boehme <slow@samba.org>
smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl()
Paolo Abeni <pabeni@redhat.com>
mptcp: prevent race between disconnect() and rtx
Paolo Abeni <pabeni@redhat.com>
mptcp: do not reschedule the RTX timer for fallback sockets
Eric Dumazet <edumazet@google.com>
tcp: introduce icsk->icsk_keepalive_timer
Kalpan Jani <kalpan.jani@mpiricsoftware.com>
mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: rename add_entry structure to add_addr
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: use for_each_subflow helper
Matthieu Baerts (NGI0) <matttbe@kernel.org>
mptcp: pm: reset retrans_time when ADD_ADDR entry is reused
Joe Damato <joe@dama.to>
bnxt_en: Don't free the live ring's TPA state on queue restart failure
Will Chen <will.chen.tty@gmail.com>
bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
Pavel Begunkov <asml.silence@gmail.com>
eth: bnxt: store rx buffer size per queue
Michael Chan <michael.chan@broadcom.com>
bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
Qing Luo <luoqing@kylinos.cn>
mptcp: pm: userspace: fix address ID overflow
Geliang Tang <geliang@kernel.org>
mptcp: use sock_kmemdup for address entry
Geliang Tang <geliang@kernel.org>
sock: add sock_kmemdup helper
Geliang Tang <geliang@kernel.org>
mptcp: pm: drop match in userspace_pm_append_new_local_addr
Joe Damato <joe@dama.to>
bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc()
Mina Almasry <almasrymina@google.com>
page_pool: disable sync for cpu for dmabuf memory provider
Mina Almasry <almasrymina@google.com>
net: page_pool: rename page_pool_alloc_netmem to *_netmems
Alexander Lobakin <aleksander.lobakin@intel.com>
netmem: add a couple of page helper wrappers
Norbert Szetei <norbert@doyensec.com>
landlock: Fix use-after-free of the source's parent directory
Günther Noack <gnoack3000@gmail.com>
landlock: Clarify documentation for the IOCTL access right
Zhiling Zou <zhilinz@nebusec.ai>
ipv6: flowlabel: cap duplicate leases per socket
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: Move ipv6_fl_list from ipv6_pinfo to inet_sock.
Eric Dumazet <edumazet@google.com>
ipv6: reorganise struct ipv6_pinfo
Eric Dumazet <edumazet@google.com>
ipv6: make ipv6_pinfo.saddr_cache a boolean
Eric Dumazet <edumazet@google.com>
ipv4: remove fib_info_devhash[]
Eric Dumazet <edumazet@google.com>
ipv4: use rcu in ip_fib_check_default()
Eric Dumazet <edumazet@google.com>
ipv4: remove fib_devindex_hashfn()
Myeonghun Pak <mhun512@gmail.com>
idpf: disable DIM work before freeing q_vectors
Pavan Kumar Linga <pavan.kumar.linga@intel.com>
idpf: introduce idpf_q_vec_rsrc struct and move vector resources to it
Andy Shevchenko <andriy.shevchenko@linux.intel.com>
idpf: Fix kernel-doc descriptions to avoid warnings
Jingbo Xu <jefflexu@linux.alibaba.com>
erofs: add sysfs feature entry for xattr prefixes
Runyu Xiao <runyu.xiao@seu.edu.cn>
net: macb: initialize PTP state before registering clock
Théo Lebrun <theo.lebrun@bootlin.com>
net: macb: unify device pointer naming convention
Kevin Hao <haokexin@gmail.com>
net: macb: Use netif_napi_add_tx() instead of netif_napi_add() for TX NAPI
Kevin Hao <haokexin@gmail.com>
net: macb: Replace open-coded implementation with napi_schedule()
Chengfeng Ye <nicoyip.dev@gmail.com>
netfilter: cttimeout: prevent UAF during module unload
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount
Thomas Hellström <thomas.hellstrom@linux.intel.com>
drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches
Zhiling Zou <zhilinz@nebusec.ai>
net: bridge: use option bits for CFM/MRP frame handlers
Masami Hiramatsu (Google) <mhiramat@kernel.org>
bootconfig: Fix integer overflow in initrd size check
Gabriel Krisman Bertazi <krisman@suse.de>
io_uring/net: don't overconsume buffers when using MSG_TRUNC
Jens Axboe <axboe@kernel.dk>
io_uring/rw: end write accounting from ->ki_complete
Leonardo Costa <leonardo.costa@toradex.com>
drm/bridge: tc358768: Enforce input bus flags via atomic_check
XingWang Xiang <v3rdant.xiang@gmail.com>
genetlink: pin family module during policy dump
Dinh Nguyen <dinguyen@kernel.org>
EDAC/altera: Use parent device for devres in altr_portb_setup()
Rounak Das <rounakdas2025@gmail.com>
EDAC/altera: Use ECC manager compatible to select A10/S10 IRQ layout
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
tracing: Undo the registration when enabling the histogram trigger fails
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
tracing: Take the reference before publishing the named histogram trigger
Steven Rostedt <rostedt@goodmis.org>
tracing: Take trace_array reference when opening a tracer options file
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tools/bootconfig: Fix integer overflow and truncation in size checks
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tools/bootconfig: Cleanup bootconfig footer size calculations
Xiong Weimin <xiongweimin@kylinos.cn>
virtio_mmio: disable IRQ wake before free_irq
Viresh Kumar <viresh.kumar@linaro.org>
virtio-mmio: Remove virtqueue list from mmio device
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
tracing: Set the trace clock before registering the histogram trigger
Steven Rostedt <rostedt@goodmis.org>
tracing: Merge struct event_trigger_ops into struct event_command
Steven Rostedt <rostedt@goodmis.org>
tracing: Remove get_trigger_ops() and add count_func() from trigger ops
Christophe JAILLET <christophe.jaillet@wanadoo.fr>
tracing: Constify struct event_trigger_ops
Vasileios Almpanis <vasilisalmpanis@gmail.com>
configfs: unhash the dentry before dropping the item in rmdir
Cen Zhang (Microsoft) <blbllhy@gmail.com>
reboot: fix cad_pid use-after-free race
Oleg Nesterov <oleg@redhat.com>
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
Zihan Xi <zihanx@nebusec.ai>
ipmr: account multicast table and route memory
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
tracing: Fix memory corruption from a "STACKTRACE" histogram key
Vasileios Almpanis <vasilisalmpanis@gmail.com>
configfs: pin the symlink target's dirent instead of chasing ->ci_dentry
Al Viro <viro@zeniv.linux.org.uk>
configfs:get_target() - release path as soon as we grab configfs_item reference
Shixiong Ou <oushixiong@kylinos.cn>
drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug
Shixiong Ou <oushixiong@kylinos.cn>
drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
Thomas Zimmermann <tzimmermann@suse.de>
drm/sysfb: simpledrm: Improve framebuffer-size validation
Thomas Zimmermann <tzimmermann@suse.de>
firmware: sysfb: Move bpp-depth calculation into screen_info helper
Thomas Zimmermann <tzimmermann@suse.de>
drm/sysfb: simpledrm: Improve stride validation
Thomas Zimmermann <tzimmermann@suse.de>
drm/sysfb: simpledrm: Improve panel-size validation
Roman Li <Roman.Li@amd.com>
drm/amd/display: Set gpuvm min page size to 4K on dcn35/36
Lyude Paul <lyude@redhat.com>
drm/nouveau/disp/r535: Add scanline position support + head state support
Bob Zhou <bobzhou2@amd.com>
drm/amdgpu: avoid force-completing uninitialized UVD rings
Alex Deucher <alexander.deucher@amd.com>
drm/amdgpu: plumb timedout fence through to force completion
Alex Deucher <alexander.deucher@amd.com>
drm/amdgpu: add a helper to calculate ring distance
Srinivasan Shanmugam <srinivasan.shanmugam@amd.com>
drm/amdgpu: Fix missing unwind in amdgpu_ib_schedule() error path
Daeho Jeong <daehojeong@google.com>
f2fs: accurately adjust free_sections during free_segment_range
Chao Yu <chao@kernel.org>
f2fs: fix to clear dirty flag on folio in error path
Matthew Wilcox (Oracle) <willy@infradead.org>
f2fs: Convert clear_node_page_dirty() to clear_node_folio_dirty()
Chao Yu <chao@kernel.org>
f2fs: embed f2fs_gc_kthread in f2fs_sb_info
Guanghui Yang <3497809730@qq.com>
f2fs: fix dentry folio leak in find_in_level
Wenjie Qi <qwjhust@gmail.com>
f2fs: limit recovery filename logging to stored length
Joanne Chang <joannechien@google.com>
f2fs: dirty directory inodes on mtime/ctime update
Chao Yu <chao@kernel.org>
f2fs: fix to avoid potential section-unaligned pinfile
wangzijie <wangzijie1@honor.com>
f2fs: don't allow unaligned truncation to smaller/equal size on pinned file
wangzijie <wangzijie1@honor.com>
f2fs: convert F2FS_I_SB to sbi in f2fs_setattr()
Wenjie Qi <qwjhust@gmail.com>
f2fs: validate MOVE_RANGE destination size
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Clamp max_npiv_vports to VP_CTRL bitmap capacity
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Skip vport under deletion in report ID acquisition
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Fix 64G link speed reporting in get_data_rate
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Use memset_io() to clear QLAFX00 request ring slot
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Use ring-slot helpers in __qla2x00_alloc_iocbs
Jackson Lee <jackson.lee@chipsnmedia.com>
media: chips-media: wave5: Add timeout while stop_streaming
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking
Nilesh Javali <njavali@marvell.com>
scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
Yosry Ahmed <yosry@kernel.org>
KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported
Christian Borntraeger <borntraeger@linux.ibm.com>
KVM: s390: Zero initialize data structures for inject_pfault_token
Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
media: rkvdec: Propagate platform_get_irq() errors
Dave Stevenson <dave.stevenson@raspberrypi.com>
media: imx355: Avoid calling imx355_power_off twice in error path
Laurent Pinchart <laurent.pinchart@ideasonboard.com>
media: i2c: imx355: Replace client->dev usage
Yosry Ahmed <yosry@kernel.org>
KVM: x86: Check EFER validity on KVM_SET_SREGS*
Sean Christopherson <seanjc@google.com>
KVM: x86: Move the bulk of register specific code from x86.c to regs.c
Sean Christopherson <seanjc@google.com>
KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2()
Sean Christopherson <seanjc@google.com>
KVM: x86: Extract REGS and SREGS runtime sync code to helpers
Sean Christopherson <seanjc@google.com>
KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves
Sean Christopherson <seanjc@google.com>
KVM: x86/mmu: Dynamically allocate shadow MMU's hashed page list
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP
Jon Hunter <jonathanh@nvidia.com>
ASoC: tegra: Fix the MIXER enable default value
Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
ASoC: tegra210_mixer: sort the register default table
Imran Shaik <imran.shaik@oss.qualcomm.com>
clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs
Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses
Andrea Scian <andrea.scian@dave.eu>
mtd: rawnand: pl353: Add message about ECC mode
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: refcount requests for token lifetime
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: always wake -ENOSPC waiters
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: stop allocating child flush bio
Li Chen <me@linux.beauty>
nvdimm: pmem: keep PREFLUSH before data writes
Li Chen <me@linux.beauty>
nvdimm: preserve flush callback -ENOMEM
Baolin Wang <baolin.wang@linux.alibaba.com>
mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs
Anthony Krowiak <akrowiak@linux.ibm.com>
s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects
Chao Shi <coshi036@gmail.com>
nvme: skip the zoned limits update if the zone info query failed
Christoph Hellwig <hch@lst.de>
nvme: fix atomic write size validation
Christoph Hellwig <hch@lst.de>
nvme: refactor the atomic write unit detection
Alan Adamson <alan.adamson@oracle.com>
nvme: all namespaces in a subsystem must adhere to a common atomic write size
Tristan Madani <tristan@talencesecurity.com>
nvme: add missing SRCU grace period in error path
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Allow splice reads on static buffers
Steven Rostedt <rostedt@goodmis.org>
ring-buffer: Show persistent buffer dropped events in trace_pipe file
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
Yabin Cui <yabinc@google.com>
perf/aux: Allocate non-contiguous AUX pages by default
Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm
Sebastian Andrzej Siewior <bigeasy@linutronix.de>
futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
Marco Elver <elver@google.com>
compiler_types: Move lock checking attributes to compiler-context-analysis.h
Baineng Shou <shoubaineng@gmail.com>
dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds
Steven Rostedt <rostedt@goodmis.org>
ftrace: Take trace_array reference before accessing its ftrace_ops
Steven Rostedt <rostedt@goodmis.org>
tracing: Take trace_array reference when opening options file
Steven Rostedt <rostedt@goodmis.org>
tracing: Clean up use of trace_create_maxlat_file()
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/secretmem: properly account locked pages
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/probes: Fix BTF kflag check for anonymous struct member access
Steven Rostedt <rostedt@goodmis.org>
Documentation: tracing: Add documentation about eprobes
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member
Muhammad Bilal <meatuni001@gmail.com>
staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit()
Muhammad Bilal <meatuni001@gmail.com>
staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
Vivek BalachandharTN <vivek.balachandhar@gmail.com>
staging: rtl8723bs: fix spacing around operators
Jeffin Philip <jeffinphilip14@gmail.com>
usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
Myeonghun Pak <mhun512@gmail.com>
usb: storage: realtek_cr: fix use-after-free on disconnect
Pawel Laszczak <pawell@cadence.com>
usb: cdnsp: fix wakeup from S3 after controller context loss
Théo Lebrun <theo.lebrun@bootlin.com>
usb: cdns3: rename hibernated argument of role->resume() to lost_power
Mathias Nyman <mathias.nyman@linux.intel.com>
xhci: Cleanup Candence controller PCI device and vendor ID usage
Bryam Vargas <hexlabsecurity@proton.me>
wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
Amit Sunil Dhamne <amitsd@google.com>
usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling
Xu Yang <xu.yang_2@nxp.com>
usb: typec: tcpm: fix debug accessory mode detection for sink ports
Yuhang.chen <yhchen312@gmail.com>
wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
Bitterblue Smith <rtl8821cerfe2@gmail.com>
wifi: rtw89: Hide some errors when the device is unplugged
Zong-Zhe Yang <kevin_yang@realtek.com>
wifi: rtw89: cleanup unused rtwdev::roc_work
Elson Serrao <elson.serrao@oss.qualcomm.com>
usb: dwc3: clear forceRM when issuing EndTransfer
Thinh Nguyen <Thinh.Nguyen@synopsys.com>
usb: dwc3: gadget: Reinitiate stream for all host NoStream behavior
Jan Kara <jack@suse.cz>
udf: Fix data loss when converting inline inodes to out of line
Jan Kara <jack@suse.cz>
udf: Move udf_map_block() up
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Fix use-after-free of master->this
Bryam Vargas <hexlabsecurity@proton.me>
wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
StanleyYP Wang <StanleyYP.Wang@mediatek.com>
wifi: mt76: mt7915: set correct background radar capability
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Do not treat master device as a duplicate target
Can Peng <pengcan@kylinos.cn>
hwrng: stm32 - Fix runtime PM cleanup on registration failure
Uwe Kleine-König <u.kleine-koenig@baylibre.com>
hwrng: drivers - Switch back to struct platform_driver::remove()
Xu Rao <raoxu@uniontech.com>
ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
Glenn Judd <gmj@meta.com>
net/mlx5e: do not HW-GRO coalesce small frames
Dragos Tatulea <dtatulea@nvidia.com>
net/mlx5e: SHAMPO, Always calculate page size
Hidayath Khan <hidayath@linux.ibm.com>
net/smc: stop killed, freed and out_of_sync sharing a byte
Simon Horman <horms@kernel.org>
net/smc: Address spelling errors
Fan Wu <fanwu01@zju.edu.cn>
power: supply: qcom_battmgr: fix use-after-free
Hui Su <sh_def@163.com>
io_uring/waitid: avoid siginfo copy during ring teardown
Jens Axboe <axboe@kernel.dk>
io_uring/waitid: have io_waitid_complete() remove wait queue entry
Mario Limonciello <mario.limonciello@amd.com>
platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
Mario Limonciello <mario.limonciello@amd.com>
platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
Shyam Sundar S K <Shyam-sundar.S-k@amd.com>
platform/x86/amd/pmc: Define enum for S2D/PMC msg_port and add helper function
Shyam Sundar S K <Shyam-sundar.S-k@amd.com>
platform/x86/amd/pmc: Move STB functionality to a new file for better code organization
Shyam Sundar S K <Shyam-sundar.S-k@amd.com>
platform/x86/amd/pmc: Move STB block into amd_pmc_s2d_init()
Abdun Nihaal <nihaal@cse.iitm.ac.in>
platform/x86: int1092: Fix potential memory leak in sar_probe()
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
platform/x86: intel_sar: Check ACPI_HANDLE() against NULL
Thorsten Blum <thorsten.blum@linux.dev>
platform/x86: think-lmi: Fix certificate thumbprint sysfs output
Mark Pearson <mpearson-lenovo@squebb.ca>
platform/x86: think-lmi: improve check if BIOS account security enabled
Thorsten Blum <thorsten.blum@linux.dev>
platform/x86: think-lmi: Fix current password length check
Farhan Ali <alifm@linux.ibm.com>
PCI: Allow per function PCI slots to fix slot reset on s390
Farhan Ali <alifm@linux.ibm.com>
PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value
Fan Wu <fanwu01@zju.edu.cn>
mmc: via-sdmmc: cancel card-detect work on remove
Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
platform/x86: ISST: Validate max level for set feature
Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
platform/x86: ISST: Check for admin capability for write commands
Peiyang He <peiyang_he@smail.nju.edu.cn>
iommufd: Fix UAF in selftest IOPF reporting
Yi Liu <yi.l.liu@intel.com>
iommufd: Pass @pasid through the device attach/replace path
Weimin Xiong <xiongwm2026@163.com>
iommu/msm: Unwind probe state on registration failure
Zhang Heng <zhangheng@kylinos.cn>
iommu/msm: Use helper function devm_clk_get_prepared()
Ali Tariq <alitariq45892@gmail.com>
PCI: starfive: Fix resource leaks on error paths in host_init()
Hal Feng <hal.feng@starfivetech.com>
PCI: starfive: Use regulator APIs to control the 3v3 power supply of PCIe slots
Fan Wu <fanwu01@zju.edu.cn>
power: supply: ab8500_fg: fix use-after-free on remove
Pan Chuang <panchuang@vivo.com>
power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe()
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
remoteproc: pas: Replace metadata context with PAS context structure
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware: qcom_scm: Rename peripheral as pas_id
Oscar Ou <oscarou@synology.com>
lockd: fix swapped arguments in nlmsvc_match_ip()
Ruoyu Wang <ruoyuw560@gmail.com>
i2c: mxs: fix DMA channel leak on probe error
Bence Csókás <csokas.bence@prolan.hu>
dmaengine: Add devm_dma_request_chan()
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>
ASoC: codecs: aw88261: only check PLL and clock state at power-up
Val Packett <val@packett.cool>
ASoC: codecs: aw88261: reduce log spam
Tejun Heo <tj@kernel.org>
sched/core: Make core-sched flips wait for in-flight selections
John Stultz <jstultz@google.com>
sched: Rework prev_balance() to avoid stale prev references
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
Steven Rostedt <rostedt@goodmis.org>
ring-buffer: Add helper functions for allocations
James Clark <james.clark@linaro.org>
perf test: Change all remaining #!/bin/sh to #!/bin/bash
Jakub Kicinski <kuba@kernel.org>
net: tls: fix silent data drop under pipe back-pressure
Darrick J. Wong <djwong@kernel.org>
xfs: fix blockgc group quota scanning when usrquota isn't enforced
Darrick J. Wong <djwong@kernel.org>
xfs: drop dquot flush lock when we can't find a buffer to flush
Darrick J. Wong <djwong@kernel.org>
xfs: check di_forkoff correctly in scrub
Darrick J. Wong <djwong@kernel.org>
xfs: don't call xfs_exchange_range_finish for a dry run
Darrick J. Wong <djwong@kernel.org>
xfs: check padding field in xfs_ioc_commit_range
Darrick J. Wong <djwong@kernel.org>
xfs: use correct jiffies comparison function in xchk_maybe_relax
Darrick J. Wong <djwong@kernel.org>
xfs: release orphanage dir inode if chown fails
Darrick J. Wong <djwong@kernel.org>
xfs: fix attr fork block count checks in xrep_inode_blockcounts
Darrick J. Wong <djwong@kernel.org>
xfs: don't assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption
Zihan Xi <zihanx@nebusec.ai>
smb: client: validate POSIX create context length
Zihan Xi <zihanx@nebusec.ai>
smb: client: clean up failed cached directory opens
Zihan Xi <zihanx@nebusec.ai>
smb: client: fix create context out-of-bounds reads
Hui Peng <benquike@gmail.com>
Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: mgmt: fix race in read_unconf_index_list()
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: L2CAP: validate frame length before control and FCS access
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: ISO: balance the parent hold in hci_bind_bis()
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_sock: reject out-of-range OCF values
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_sock: validate event length before filtering
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Bluetooth: hci_conn: fix CIS hold ownership on reuse
Tan Chi <tanchi25@mails.ucas.ac.cn>
RISC-V: KVM: Fix HSM hart status error propagation
Myeonghun Pak <mhun512@gmail.com>
RISC-V: KVM: Synchronize hrtimer callback during teardown
Lorenzo Stoakes (ARM) <ljs@kernel.org>
KVM: arm64: Fix spurious warning for benign stage 2 teardown race
Zeng Chi <zengchi@kylinos.cn>
KVM: Don't treat reserved xarray entries as having memory attributes
David Ballesteros <davimaba.v@proton.me>
KVM: Ensure memory attributes xarray nodes are accounted to the caller's memcg
Anthony Krowiak <akrowiak@linux.ibm.com>
s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config
Peter Oberparleiter <oberpar@linux.ibm.com>
s390/cmf: Fix virtual vs physical address confusion
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str()
Ilya Titov <ilya.titov@wirenboard.com>
pinctrl: sunxi: keep a shadow copy of the data register output latches
Myeonghun Pak <mhun512@gmail.com>
pinctrl: single: free the IRQ on domain creation failure
Puranjay Mohan <puranjay@kernel.org>
perf/core: Run sched_task() for PMUs with only CPU-wide events
Puranjay Mohan <puranjay@kernel.org>
perf/core: Fix NULL pmu_ctx passed to pmu->sched_task()
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
scsi: libiscsi_tcp: Check the data direction of a Data-In PDU
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: port100: reject frames whose declared length exceeds the received data
Aamir Ahmed <elb12345@hotmail.co.uk>
nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc()
Luxiao Xu <rakukuip@gmail.com>
nfc: fix use-after-free in nfc_get_local_general_bytes
Aohan Mei <henrymei@tencent.com>
netfilter: nf_tables: skip expired catchall elements on insert and delete
Luxiao Xu <rakukuip@gmail.com>
netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read
Weiming Shi <bestswngs@gmail.com>
netfilter: ip6t_rpfilter: reject routes without inet6_dev
Wentao Liang <vulab@iscas.ac.cn>
net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
Ming Wang <wangming01@loongson.cn>
net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist
Fourie Zhang <littleddfu@gmail.com>
net: bridge: mdb: restart port group walk after deletion
Gajdos Tamás <tamas@rimpianto.com>
net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read
Gajdos Tamás <tamas@rimpianto.com>
net: atl1c: fix soft lockup on out-of-range tpd_cons read
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: fix helper UAF due to extensions realloc
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: remove 'add_helper' dead code
Ilya Maximets <i.maximets@ovn.org>
net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry
Wentao Liang <vulab@iscas.ac.cn>
net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy()
Gajdos Tamás <tamas@rimpianto.com>
net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read
Zijie Huang <milkory@outlook.com>
net: arp: terminate device name before lookup
Weiming Shi <bestswngs@gmail.com>
net/sched: reject IDR error pointers when deleting actions
Ralf Lici <ralf@mandelbit.com>
net/mlx5e: advertise MACsec offload only when supported
Wentao Liang <vulab@iscas.ac.cn>
net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()
Wei Jie LAW <98lawweijie@gmail.com>
HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce()
Junjie Cao <junjie.cao@intel.com>
HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard
Chen Changcheng <chenchangcheng@kylinos.cn>
HID: alps: fix use-after-free on input2 registration failure
Angel J <iamanaws@httpd.dev>
PCI: of_property: Omit bus properties without a subordinate bus
Jaewook You <jaewook376@gmail.com>
mm/hugetlb: preserve mremap address delta when skipping page tables
Karl Mehltretter <kmehltretter@gmail.com>
gpio: tps65219: Fix GPIO input value reads
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/virtio: fix NULL pointer dereference on fence allocation failure
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/virtio: fix memory leak of fence event on execbuffer failure
Szymon Acedański <accek@invisiblethingslab.com>
drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau: don't bump pin count on failed re-pin in nouveau_bo_pin_locked()
Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
drm/nouveau: RCU-free the scheduler-containing nouveau_sched
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix runtime PM leak in nouveau_connector_detect()
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix gem reference leak in validate_init()
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau: fix double-free in nvif_vmm_dtor
Wentao Liang <vulab@iscas.ac.cn>
drm/nouveau: Fix bridge reference leak in nv1a_ram_new()
Guangshuo Li <lgs201920130244@gmail.com>
drm/nouveau: fix autosuspend cleanup during teardown
Peiyang He <peiyang_he@smail.nju.edu.cn>
drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init()
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show()
Wentao Liang <vulab@iscas.ac.cn>
drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init()
Ivan Lipski <ivan.lipski@amd.com>
drm/amd/display: Bump frame warning limit for clang builds of dml
Wentao Liang <vulab@iscas.ac.cn>
drm/amd/display: Fix dc stream excess put in dm_update_crtc_state()
Christian König <ckoenig.leichtzumerken@gmail.com>
drm/i915: fix incorrect RCU teardown order
Brajesh Gupta <brajesh.gupta@imgtec.com>
drm/imagination: Fix page count for page table for map() interface
Brajesh Gupta <brajesh.gupta@imgtec.com>
drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl()
Dongliang Qin <cccccccccccc777777@gmail.com>
rds: ib: Clear the sg list when mapping an MR fails
Hui Peng <benquike@gmail.com>
mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag()
Zixuan Chai <petalzu987@gmail.com>
llc: reserve device headroom for allocated frames
Ridham Khurana <khurana.ridham222@gmail.com>
gpio: zynq: fix runtime PM leak on request error path
Wentao Liang <vulab@iscas.ac.cn>
gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out()
Hui Peng <benquike@gmail.com>
ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST
Norbert Szetei <norbert@doyensec.com>
ipv6: do not let ipv6_find_hdr() return an offset past the packet end
Fan Wu <wufan@kernel.org>
ipe: protect the dm-verity root hash with RCU
Wentao Liang <vulab@iscas.ac.cn>
fsl/fman: Fix clk reference leak in read_dts_node()
Josef Bacik <josef@toxicpanda.com>
writeback: report a Tasks-RCU quiescent state per cgwb drain pass
Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
workqueue: Fix NULL current_pwq deref in flush dependency check
Patrick Lu (Anthropic) <perf.patrick.lu@gmail.com>
writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes
Christian Brauner <brauner@kernel.org>
fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbot's "WARNING in do_new_mount" saga
Hui Peng <benquike@gmail.com>
fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT
Guopeng Zhang <zhangguopeng@kylinos.cn>
cgroup/pids: Restore pids.events notifications in local mode
Matthias Goergens <matthias.goergens@gmail.com>
ata: libata-scsi: bound the ATA passthru sense descriptor writes
Dairui Zhang <zhangdairui@gmail.com>
af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
Aohan Mei <henrymei@tencent.com>
sctp: discard the rest of the packet on a stale-cookie error
Willem de Bruijn <willemb@google.com>
tcp: prevent collapsing skbs across boundary in rtx queue
Eric Dumazet <edumazet@google.com>
tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow
Willem de Bruijn <willemb@google.com>
virtio_net: copy zerocopy frags in start_xmit without NAPI
Mario Limonciello <mario.limonciello@amd.com>
x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11
Masami Hiramatsu (Google) <mhiramat@kernel.org>
x86/mce: Fix hardware debug register corruption on task migration
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
Pablo Neira Ayuso <pablo@netfilter.org>
rculist: add list_splice_rcu() for private lists
Mark Amirkan <markdamirkan@gmail.com>
mptcp: return sk_wait_data() errors from recvmsg()
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Don't write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
Sean Christopherson <seanjc@google.com>
perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
Hui Peng <benquike@gmail.com>
autofs: fix sbi->pipe file reference leak in autofs_kill_sb()
Eric Dumazet <edumazet@google.com>
vlan: ensure sufficient headroom in vlan_dev_hard_header()
Eric Dumazet <edumazet@google.com>
net/sched: sch_teql: fix shadowed err in __teql_resolve()
Eric Dumazet <edumazet@google.com>
bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
Eric Dumazet <edumazet@google.com>
llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
Coia Prant <coiaprant@gmail.com>
net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
Ginger Li <ginger.jzllee@gmail.com>
tipc: Fix a data race on mon->peer_cnt in mon_timeout()
Sidraya Jayagond <sidraya@linux.ibm.com>
net/smc: fix UAF on lgr list traversal in smcr_port_err()
Sang-Hoon Choi <csh0052@gmail.com>
nfp: hold IPsec RX state under the XArray lock
Yilin Zhang <yilinzhang@moonshot.ai>
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
Aleksei Sviridkin <f@lex.la>
net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621
Haseeb Malik <haseebulhaq55@gmail.com>
macsec: initialize SecY before registering the netdevice
Sabrina Dubroca <sd@queasysnail.net>
macsec: inherit lower device's TSO limits when offloading
Sabrina Dubroca <sd@queasysnail.net>
macsec: add some of the lower device's features when offloading
David Dai <zdai@linux.ibm.com>
bonding: crypto offload enabled, non-offload slave failover, rekey failed
Pengpeng Hou <hppiscas@163.com>
drm/imagination: clamp freelist reconstruction requests
Norbert Szetei <norbert@doyensec.com>
net: xps: reject an out of range traffic class
Sanghyun Park <sanghyun.park.cnu@gmail.com>
vxlan: use one headroom snapshot for neighbour replies
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
ip_gre: Reject enabling collect metadata through changelink
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: do not skip WoL power up on GENET V1
Doug Berger <opendmb@gmail.com>
net: bcmgenet: allow return of power up status
Doug Berger <opendmb@gmail.com>
net: bcmgenet: move bcmgenet_power_up into resume_noirq
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: initialize u64 stats seq counter for all queues
Florian Fainelli <florian.fainelli@broadcom.com>
net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems
Ivan Delalande <colona@arista.com>
tg3: use random MAC address when tg3_get_device_address fails
Dragan Simic <dsimic@manjaro.org>
driver core: Add device probe log helper dev_warn_probe()
Johan Almbladh <johan.almbladh@anyfinetworks.com>
bpf: Fix BSWAP 32 and 16 on MIPS64
Johan Almbladh <johan.almbladh@anyfinetworks.com>
bpf: Fix immediate JMP JEQ/JNE on MIPS32
Ido Schimmel <idosch@nvidia.com>
vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets
Shihuang Liu <shlomojune6@gmail.com>
net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6()
Jakub Kicinski <kuba@kernel.org>
veth: manage XDP program pointers during channel resize
Victor Nogueira <victor@mojatatu.com>
net/sched: act_gate: budget the per-entry list in get_fill_size
Deepanshu Kartikey <kartikey406@gmail.com>
nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix slab-out-of-bounds reads when logging service names
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap()
Ömer Mete Kaya <omermetekaya0@gmail.com>
nfc: llcp: fix -ENOMEM on connect with zero-length service name
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: st21nfca: validate ISO15693 inventory length
Cong Nguyen <congnt264@gmail.com>
nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure
Chris Gellermann <christian.gellermann@codasip.com>
nfc: virtual_ncidev: Add missing ioctl compat handler
Chris Gellermann <christian.gellermann@codasip.com>
selftests/nci: Fix out-of-bounds store on thread join
Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
selftests: nci: Fix uninitialized family ID on missing attribute
Lee Jones <lee@kernel.org>
nfc: llcp: Fix race condition in accept_queue lifecycle
Lei Zhu <zhulei@kylinos.cn>
selftests: nci: Correct pthread_create return value check
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm()
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: st21nfca: validate received frame size
Pengpeng Hou <pengpeng@iscas.ac.cn>
nfc: nfcmrvl: validate helper command length before pull
Weiming Shi <bestswngs@gmail.com>
bpf: Reject dev-bound-only programs on other devices
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Capture all packets for vlan checks
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Check the dev->features for S-TAG offload testing
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Support running selftests on DSA conduits
Xin Long <lucien.xin@gmail.com>
sctp: hold asoc or transport before mod_timer() in timer handlers
Bernardo Soares <bsoares.it@gmail.com>
net/mlx5: Bridge, don't fail unlink of untracked/unsupported peer ports
Bernardo Soares <bsoares.it@gmail.com>
net/mlx5: Bridge, don't fail switchdev events of sibling eswitch ports
Zhao Gongyi <zhaogongyi@BYTEDANCE.COM>
bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc
Emil Tsalapatis <emil@etsalapatis.com>
bpf: Fix bpf_sock context code generation
Emil Tsalapatis <emil@etsalapatis.com>
bpf: Fix bounds check for skb-backed dynptrs
Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>
thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds
Coia Prant <coiaprant@gmail.com>
net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure
Jakub Kicinski <kuba@kernel.org>
genetlink: report the real command id for dump-only ops in policy dumps
bui duc phuc <phucduc.bui@gmail.com>
net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error
Mikhail Zaslonko <zaslonko@linux.ibm.com>
s390/debug: Fix NULL pointer dereference in debug_info_copy()
Mikhail Zaslonko <zaslonko@linux.ibm.com>
s390/debug: Do not register views for failed static debug areas
Nemesa Garg <nemesa.garg@intel.com>
drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable
Jouni Högander <jouni.hogander@intel.com>
drm/i915/psr: Add new SU area calculation helper to apply workarounds
Myeonghun Pak <mhun512@gmail.com>
tg3: clean up PHYLIB resources on probe failure
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: Fix dst leak for uncached routes.
Pengpeng Hou <hppiscas@163.com>
net: usb: sr9700: include receive overhead in the length check
Ivan Vecera <ivecera@redhat.com>
dpll: use exact lookup for reference sync pin id
Ratheesh Kannoth <rkannoth@marvell.com>
octeontx2-af: Fix memory scaling limitation in SR-IOV mode
Hui Peng <benquike@gmail.com>
Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame()
Ravindra <ravindra@intel.com>
Bluetooth: btintel_pcie: validate device-supplied DMA indices
Hui Peng <benquike@gmail.com>
Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough
Li Youhong <liyouhong@kylinos.cn>
drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: release the GEM object on virtio_gpu_vram_create() errors
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl()
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl()
Junrui Luo <moonafterrain@outlook.com>
drm/virtio: fix object leak when drm_gem_handle_create() fails
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget
Yuqi Xu <xuyuqiabc@gmail.com>
bpf: Check params size before reading reserved fields
Aamir Ahmed <elb12345@hotmail.co.uk>
net: usb: catc: bound the RX packet length in catc_rx_done()
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Bound ownership depth through local kptrs and graph roots
Yiqi Sun <sunyiqixm@gmail.com>
sctp: avoid livelock while updating retransmit path
Alexander Duyck <alexanderduyck@fb.com>
eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox
Björn Töpel <bjorn@kernel.org>
eth: fbnic: Handle maximum standalone channels
Kuniyuki Iwashima <kuniyu@google.com>
ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink().
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
net: gue: reject invalid REMCSUM offsets
Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
net/sched: act_ct: don't WARN on benign flow_offload_alloc() failure
Giuseppe Ranieri <giuseppe@ranieri.dev>
drm/nouveau/disp: don't reject HDMI config on cards without SCDC
Francesco Magazzu <postadelmaga@gmail.com>
drm/nouveau/clk: don't clobber reclock status when restoring volt/fan
Dan Carpenter <error27@gmail.com>
drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
Joseph Qi <joseph.qi@linux.alibaba.com>
ocfs2: make ocfs2_calc_xattr_init() return void
Zeng Heng <zengheng4@huawei.com>
arm64: io: Reject non-user protection in ioremap_prot()
Naman Gulati <namangulati@google.com>
netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name
Julian Anastasov <ja@ssi.bg>
ipvs: revalidate ihl before icmp_send
Karl Mehltretter <kmehltretter@gmail.com>
netfilter: nft_synproxy: use the family-aware checksum helper
Florian Westphal <fw@strlen.de>
netfilter: nfnetlink_queue: hold nfnl mutex in event notifier
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
netfilter: flowtable: publish HW_DEAD after worker is done
Kumar Kartikeya Dwivedi <memxor@gmail.com>
libbpf: Reject truncated ldimm64 CO-RE relocations
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Restrict CO-RE poisoning to relocatable instructions
Shay Drory <shayd@nvidia.com>
net/mlx5: devcom, Base component size on linked devices
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: cls_u32: fix manual hash table handle IDR aliasing
Weiming Shi <bestswngs@gmail.com>
bpf: Skip unsettled links in link iterator
Zhiling Zou <zhilinz@nebusec.ai>
xsk: Use a 32-bit compare in xsk_map_gen_lookup
Julian Sun <sunjunchao@bytedance.com>
fs: avoid repeated scans in evict_inodes()
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Guard PMCW field accesses with dnv check
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points
Vineeth Vijayan <vneethv@linux.ibm.com>
s390/cio: Fix cio_update_schib() to not cache invalid schib
Karl Mehltretter <kmehltretter@gmail.com>
s390/pci/docs: Fix sriov_numvfs attribute name
Niklas Schnelle <schnelle@linux.ibm.com>
docs: s390/pci: Improve and update PCI documentation
Bart Van Assche <bvanassche@acm.org>
scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume()
Eva Kurchatova <eva.kurchatova@virtuozzo.com>
selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode
Sean Christopherson <seanjc@google.com>
cgroup: selftests: Move memcontrol specific helpers out of common cgroup_util.c
Lee Jones <lee@kernel.org>
Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel
Christiano Amora <christiano.amora@gmail.com>
Bluetooth: SMP: reject Security Request over BR/EDR
ZHOU Jiaxiang <me@fxti.xyz>
scsi: sd_zbc: Reject disks with too many zones
Ran Hongyun <ranhongyun1@huawei.com>
squashfs: Add dictionary size range check to prevent shift-out-of-bounds
Mark Brown <broonie@kernel.org>
KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP
Karl Mehltretter <kmehltretter@gmail.com>
KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save
Marc Zyngier <maz@kernel.org>
KVM: arm64: vgic-its: Add stronger type-checking to the ITS entry sizes
Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: vgic-its: Free the caches when GITS_BASER changes
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Fix perf-backed counter accounting across stop and read
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Report snapshot write failure to the guest
SeungJu Cheon <suunj1331@gmail.com>
RISC-V: KVM: Preserve firmware counter value across stop/start
Benjamin Tissoires <bentiss@kernel.org>
HID: bpf: fix __hid_bpf_hw_check_params report length
Slawomir Stepien <sst@poczta.fm>
HID: amd_sfh: Validate PCI BAR size before mapping
Sean Anderson <sanderson@brivo.com>
pinctrl: meson: Fix typo in s4 group name
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
bpf, arm64: set up the frame pointer for the exception callback
Geliang Tang <geliang@kernel.org>
bpf, sockmap: Fix self-redirect copied_seq double-counting
Pu Lehui <pulehui@huawei.com>
bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Register dtor for freeing special fields
Hou Tao <houtao1@huawei.com>
bpf: Factor out htab_elem_value helper()
Hou Tao <houtao1@huawei.com>
bpf: Bail out early in __htab_map_lookup_and_delete_elem()
Hou Tao <houtao1@huawei.com>
bpf: Remove migrate_{disable|enable} in ->map_for_each_callback
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix out-of-bounds read of rtt_min in sock_ops
Jose Fernandez (Anthropic) <jose.fernandez@linux.dev>
bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch()
Jim Mattson <jmattson@google.com>
KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr()
Oscar Priego Verdugo <oscar.priegov@gmail.com>
HID: elecom: fix bus type for M-XGL20DLBK
Jiayuan Chen <jiayuan.chen@linux.dev>
tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf: Fix divide-by-zero in btf_struct_walk()
Sven Schnelle <svens@linux.ibm.com>
selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
Weiming Shi <bestswngs@gmail.com>
bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL
Daniel Borkmann <daniel@iogearbox.net>
bpf: Fix bpf_skb_change_tail wrt csum partial skbs
Claudio Imbrenda <imbrenda@linux.ibm.com>
KVM: s390: Fix IRQ injection with SIGP Stop and Store Status
Mostafa Saleh <smostafa@google.com>
remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage
Zhiling Zou <zhilinz@nebusec.ai>
xfrm: save input state data before secpath resets
Dong Chenchen <dongchenchen2@huawei.com>
xfrm: Fix dev use-after-free in xfrm async resumption
Jianbo Liu <jianbol@nvidia.com>
xfrm: Refactor xfrm_input lock to reduce contention with RSS
Phil Sutter <phil@nwl.cc>
netfilter: nf_tables: Simplify chain netdev notifier
Phil Sutter <phil@nwl.cc>
netfilter: nf_tables: Tolerate chains with no remaining hooks
Sean Rhodes <sean@starlabs.systems>
ALSA: hda/realtek: Add StarFighter HDA SSID
Sean Rhodes <sean@starlabs.systems>
ALSA: hda/realtek: Limit Star Labs internal mic boost
Wenwu Hou <hwenwur@gmail.com>
erofs: fix large folio race in erofs_fscache_req_complete
Darrick J. Wong <djwong@kernel.org>
xfs: don't stash removename operations with unknown ftype
Zizhi Wo <wozizhi@huawei.com>
smb: client: fix busy dentry warning on unmount after DIO
Itai Handler <itai.handler@gmail.com>
spi: spi-zynqmp-gqspi: stop the controller on shutdown
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial normalized name responses
Antheas Kapenekakis <lkml@antheas.dev>
HID: asus: fortify keyboard handshake
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing iov bounds check in parse_posix_sids()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing lower-bound check on DFS referral string offsets
Frank Sorenson <sorenson@redhat.com>
smb: client: fix server->total_read for compound encrypted PDUs
Frank Sorenson <sorenson@redhat.com>
smb: client: fix potential OOB read in smb3_enum_snapshots()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Paulo Alcantara <pc@manguebit.org>
smb: client: fix unaligned access in WSL reparse point parser
Paulo Alcantara <pc@manguebit.org>
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
Frank Sorenson <sorenson@redhat.com>
smb: client: reject short Next offsets in parse_server_interfaces()
Paulo Alcantara <pc@manguebit.org>
smb: client: fix rlist race and missing initialization
Paulo Alcantara <pc@manguebit.org>
smb: client: cancel reconnect work in clean_demultiplex_info()
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/adreno: fix autosuspend cleanup during teardown
Sajal Gupta <sajal2005gupta@gmail.com>
drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
Rik van Riel <riel@surriel.com>
wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
Zhao Li <enderaoelyther@gmail.com>
wifi: mwifiex: validate action frame fixed fields
Linmao Li <lilinmao@kylinos.cn>
wifi: mwifiex: prevent authentication frame length truncation
Pengpeng Hou <pengpeng@iscas.ac.cn>
wifi: mwifiex: validate scan response extents
Doruk Tan Ozturk <doruk@0sec.ai>
wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
Shengzhuo Wei <me@cherr.cc>
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
Shengzhuo Wei <me@cherr.cc>
wifi: p54: validate curve data length in the calibration curve converters
Tianchu Chen <flynnnchen@tencent.com>
wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
Ali Ahmet Memis <ali@iusegentoo.com>
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
Runyu Xiao <runyu.xiao@seu.edu.cn>
wifi: wlcore: release runtime PM ref on regdomain config failure
Tianchu Chen <flynnnchen@tencent.com>
wifi: rsi: fix heap OOB write on key removal
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: libertas_tf: fix UAF in lbtf_free_adapter()
Stanislaw Gruszka <stf_xl@wp.pl>
wifi: iwlegacy: fix broadcast stations deallocation
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: brcmsmac: fix UAF in brcms_free_timer()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: rtd119x: Avoid division by zero
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Propagate error code in resume()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Fix premature reset during timeout update
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: digicolor: Avoid division by zero
Li Jun <lijun01@kylinos.cn>
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83793) release probe data through kref
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
Nuno Sá <nuno.sa@analog.com>
hwmon: (pmbus/core) increase number of phases and add new mask
Muhammad Bilal <meatuni001@gmail.com>
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: zero ff_effect before compat copy in input_ff_effect_from_user
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Raphaël Larocque <rlarocque@disroot.org>
Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - check btns_desc->package.count
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - fix MS Surface Pro 11 probe failure
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
Chris Sommers <chris.sommers@icloud.com>
Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: evdev - zero absinfo before partial copy in EVIOCSABS
Linkai Gong <gonglinkai@kylinos.cn>
Input: cyttsp5 - clamp the HID report size before memcpy
Alexei Turtanov <9alexei9@gmail.com>
Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
Alvin Šipraga <alvin.sipraga@analog.com>
Input: adp5588-keys - cache GPIO state before registering the gpiochip
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Clear ITAPDLY on tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Reset command and data lines on failed tuning
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Move tuning_loop to local variable
Xu Rao <raoxu@uniontech.com>
mmc: spi: reset bytes_xfered before retrying CRC failures
Runyu Xiao <runyu.xiao@seu.edu.cn>
mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
Felix Gu <ustc.gu@gmail.com>
mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Myeonghun Pak <mhun512@gmail.com>
mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
Florian Maillard <florian.maillard@mailoo.org>
mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
Fan Wu <fanwu01@zju.edu.cn>
mmc: mxcmmc: cancel data work and watchdog on remove
Fan Wu <fanwu01@zju.edu.cn>
mmc: mmci: Fix use-after-free in busy-timeout work
Fan Wu <fanwu01@zju.edu.cn>
mmc: hsq: Fix use-after-free in retry work
Zhu Ling <zhuling0805@qq.com>
mmc: core: Fix OF node reference leak on card add failure
Fan Wu <fanwu01@zju.edu.cn>
mmc: core: Cancel SDIO IRQ work before freeing host
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: don't call .post_enable() if pwrseq_unit_enable() failed
Christian Göttsche <cgzones@googlemail.com>
selinux: always fill AVC decision in avc_has_perm_noaudit()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: recheck intermediate backing files on mprotect()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: preserve user SID across nested backing files
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Fix the PIO_CRED credit-return mmap
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Resolve the credit-return buffer through the send context's node
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
IB/mlx4: Fix use-after-free on pkey sysfs registration failure
Guangshuo Li <lgs201920130244@gmail.com>
i2c: imx: disable autosuspend on remove
Shengzhuo Wei <me@cherr.cc>
i2c: imx: release DMA channels on probe error
Linkai Gong <gonglinkai@kylinos.cn>
i2c: atr: fix dangling adapter pointer on add failure
Shengzhuo Wei <me@cherr.cc>
i2c: at91: release DMA channels on remove and probe error
Jarkko Sakkinen <jarkko@kernel.org>
KEYS: trusted: Fix tpm2_load_cmd() boundary check
Maoyi Xie <maoyixie.tju@gmail.com>
keys: translate request_key_auth pid for the reading procfs instance
Cen Zhang <cenzhang@linux.microsoft.com>
KEYS: encrypted: fix integer overflow of datablob_len
Shakeel Butt <shakeel.butt@linux.dev>
mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
Yifei Gao <gyf161023@gmail.com>
memstick: ms_block: destroy io_queue workqueue on removal
Siwei Zhang <fourdizhang@tencent.com>
xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
Chengfeng Ye <nicoyip.dev@gmail.com>
xfrm: serialize state GC with device state flush
Alberto Carboneri <acarboneri@drivesec.com>
scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
Mark Amirkan <markdamirkan@gmail.com>
net/packet: avoid truncating TPACKET_V3 private size
Mark Amirkan <markdamirkan@gmail.com>
net/packet: clear RX owner on VNET header error
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: hhf: cap hh_flows_limit at change time
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
net/sched: act_api: release tail references on DELACTION failure
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
Mark Amirkan <markdamirkan@gmail.com>
net: lan743x: fix RX checksum use-after-free
Zhiling Zou <zhilinz@nebusec.ai>
ipv6: xfrm: use full sockets in local error paths
Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix non-atomic read of DMA position registers
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_sync: Serialize local codec list cleanup
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Bluetooth: hci_codec: validate vendor codec count length
Aamir Ahmed <elb12345@hotmail.co.uk>
Bluetooth: eir: validate service data length before reading UUID
Nicolas Thibert <nithibert@gmail.com>
Bluetooth: btusb: fix NXP IW610 composite device handling
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_and() mask generation
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_write() casting
Koichiro Den <den@valinux.co.jp>
arm64: dts: renesas: r8a779f0: Set UFS lane count
Bradley Morgan <include@grrlz.net>
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
Thomas Huth <thuth@redhat.com>
kselftest/arm64: Fix size of thread_data values for pthread_join()
Benoît Sevens <bsevens@google.com>
HID: logitech-hidpp: fix race condition when accessing stale stack pointer
Wyatt Feng <wf.kernel.dev@gmail.com>
net: xfrm: reject unrepresentable espintcp transport headers
Zhiling Zou <zhilinz@nebusec.ai>
openvswitch: avoid reallocating confirmed conntrack labels
Jeffin Philip <jeffinphilip14@gmail.com>
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
Quanye Yang <quanyeyang@proton.me>
RDMA/ucma: Serialize join and leave on copy_to_user failure
Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
tcp: exclude old ACKs from tcp fast path
Chang S. Bae <chang.seok.bae@intel.com>
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
Aohan Mei <henrymei@tencent.com>
rds: ib: use rds_conn_drop() on protocol version mismatch
Hyunwoo Kim <imv4bel@gmail.com>
exec: Cleanup POSIX timers right after de_thread()
Wentao Liang <vulab@iscas.ac.cn>
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
Wentao Liang <vulab@iscas.ac.cn>
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
Niklas Cassel <cassel@kernel.org>
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
Jiangshan Yi <yijiangshan@kylinos.cn>
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
Yuho Choi <oss.patchbox@gmail.com>
ALSA: virtio: reset device before deleting virtqueues
Takashi Iwai <tiwai@suse.de>
ALSA: core: Fix potential UAF after asynchronous card release
Jeremy Nyberg <slickstretch3.0@gmail.com>
Input: xpad - fix PDP Marvel Xbox 360 controller
Roberts Kursitis <roberts.kursitis@azeron.eu>
Input: xpad - add support for Azeron devices
Erich Sartison <byt.es@mailbox.org>
Input: xpad - add support for Victrix Pro BFG Controller
Bitterblue Smith <rtl8821cerfe2@gmail.com>
wifi: rtw88: Fix the random "error beacon valid" messages for USB
Bitterblue Smith <rtl8821cerfe2@gmail.com>
wifi: rtw88: TX QOS Null data the same way as Null data
Zi Yan <ziy@nvidia.com>
mm/huge_memory: use folio's memcg inside __folio_split()
Matthew Schwartz <matthew.schwartz@linux.dev>
x86/fred: Reconstruct the #GP context for rejected INT instructions
Filipe Manana <fdmanana@suse.com>
btrfs: abort transaction on failure to update inode for hole punching and reflinking
Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
drm/amdgpu: check ras and obj before dereference
Eric Dumazet <edumazet@google.com>
net: skbuff: do not leave stale header offsets after pskb_carve()
Dmitriy Okunev <dokunevdmitriy@gmail.com>
net: mvpp2: prevent buffer overflow in page_pool allocation
James Clark <jjc@jclark.com>
net: macb: fix ordering around PTP timestamp read
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: propagate FPE preemption-class mapping errors
Linus Walleij <linusw@kernel.org>
net: ethernet: cortina: Ack RX overrun interrupt correctly
Eric Dumazet <edumazet@google.com>
net: lock the socket in sock_gettstamp()
Yige Jiang <yigejiang86@gmail.com>
net: netsec: fix device_node reference leak on phy_np
HyeongJun An <sammiee5311@gmail.com>
ASoC: hdmi-codec: Report a change when the channel status moves
Sasha Levin <sashal@kernel.org>
ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
Shivaprasad G Bhat <sbhat@linux.ibm.com>
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: do not overwrite phc_index when no PTP clock is registered
Eric Dumazet <edumazet@google.com>
drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
Eric Dumazet <edumazet@google.com>
drop_monitor: synchronize tracepoint unregistration on error path
Eric Dumazet <edumazet@google.com>
pppoatm: ensure a writable skb header and linear data
Juan Perdomo <jcperdomo100@gmail.com>
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
Tzung-Bi Shih <tzungbi@kernel.org>
Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
Weiming Shi <bestswngs@gmail.com>
Bluetooth: coredump: Quiesce dump work on unregister
ThangNN99 <ngocthang2710.1999@gmail.com>
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: hci_core: Print number of packets in conn->data_q
Baineng Shou <shoubaineng@gmail.com>
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: keep compound responses on query info errors
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial file information responses
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: return buffer overflow for partial filesystem info
Eric Dumazet <edumazet@google.com>
tcp: do not let tcp_rmem be set below 4096
Kuniyuki Iwashima <kuniyu@google.com>
tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
Nikolay Aleksandrov <razor@blackwall.org>
net: bridge: mst: move switchdev call outside rcu
Karl Mehltretter <kmehltretter@gmail.com>
wifi: brcmfmac: fix lost 802.1x TX completion wakeup
Hohyun Sim <tlaghgus0425@korea.ac.kr>
net: fddi: skfp: fix NULL deref when setting the MAC address while down
Dong Chenchen <dongchenchen2@huawei.com>
ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
Andrea Mayer <andrea.mayer@uniroma2.it>
seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
Filipe Manana <fdmanana@suse.com>
btrfs: tree-checker: print dev extent offset in error message
Nicolas Escande <nico.escande@gmail.com>
wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
Slavin Liu <bolin.liu@seu.edu.cn>
ALSA: hda: trace PCM open only after assigning a stream
Karl Mehltretter <kmehltretter@gmail.com>
drm/vc4: Use managed KMS polling to fix UAF on unbind
Zihan Xi <zihanx@nebusec.ai>
wifi: virt_wifi: don't transfer operstate before register
Xiang Mei <xmei5@asu.edu>
ALSA: 6fire: fix OOB write from device-reported iso length
Takashi Iwai <tiwai@suse.de>
ALSA: usb: 6fire: Avoid embedded URBs
Takashi Iwai <tiwai@suse.de>
ALSA: 6fire: Clean ups with guard()
Runyu Xiao <runyu.xiao@seu.edu.cn>
gpio: virtuser: skip free_irq when no IRQ is installed
Karl Mehltretter <kmehltretter@gmail.com>
Input: trackpoint - fix the inertia attribute name in the ABI document
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
ALSA: pcm: set timer->private_data before registering the PCM timer
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
Takashi Iwai <tiwai@suse.de>
ALSA: bcd2000: Fix race between rawmidi and disconnect
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Skip default parms when resumed in neightbl_dump_info().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Add missing RCU annotation for neightbl_dump_info().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Convert RTM_GETNEIGHTBL to RCU.
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Convert RTM_GETNEIGH to RCU.
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Move neigh_find_table() to neigh_get().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Allocate skb in neigh_get().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Move two validations from neigh_get() to neigh_valid_get_req().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Make neigh_valid_get_req() return ndmsg.
Kuniyuki Iwashima <kuniyu@amazon.com>
neighbour: Use rtnl_register_many().
Karl Mehltretter <kmehltretter@gmail.com>
keys: fix lost wakeup when reaping a dead key type
Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
Breno Leitao <leitao@debian.org>
arm64: hibernate: clone only the linear map that exists at runtime
Shouping Wang <allen.wang@hj-micro.com>
perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: flowtable: hold reference on ct until flow is released
Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
netfilter: nft_nat: fully initialise new_addr in netmap setup
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
RDMA/siw: Bound fragmented header copies by the remaining length
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep EQ resources alive while IRQ is registered
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep admin queues alive while IRQ is registered
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
Karl Mehltretter <kmehltretter@gmail.com>
scsi: qla2xxx: Fix the ql2xfc2target parameter description
Meijing Zhao <zhaomeijing@lixiang.com>
mm: memblock: show all region flags in debugfs
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: set up the TX info early to fix failure paths
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: release the channel if start fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: reset the CSA state when leaving
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: add HE 6 GHz capability in the scan elems len
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't access the TSF of a down interface
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't RCU-dereference the mesh CSA settings we just set
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow link changes when iface is down
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: require a peer station for TDLS setup confirm
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow injecting frames wider than the chanctx
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: expose cfg80211_chandef_get_width()
Kavita Kavita <quic_kkavita@quicinc.com>
wifi: cfg80211: skip regulatory for punctured subchannels
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211_hwsim: don't hand frames to mac80211 while stopping
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: unlist vifs when their netdev is unregistered
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset state when starting AP fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: abort chanswitch when leaving a mesh
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: suppress chanctx warning for debugfs reset
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't warn when an IBSS has no channel to scan
Felix Fietkau <nbd@nbd.name>
wifi: mac80211: use vif radio mask to limit ibss scan frequencies
Felix Fietkau <nbd@nbd.name>
wifi: cfg80211: add option for vif allowed radios
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't start a ROC while scanning
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't filter by BSS type when removing stale entries
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: only group hidden BSSes with beacon entries
Shivank Garg <shivankg@amd.com>
dmaengine: wait for RCU readers before releasing dma_device
Shivank Garg <shivankg@amd.com>
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
Shivank Garg <shivankg@amd.com>
dmaengine: Fix device kref underflow in dma_chan_put()
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
dma-coherent: report a failed reserved memory assignment
Chen-Yu Tsai <wenst@chromium.org>
dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask
Orgad Shaneh <orgads@gmail.com>
MIPS: Octeon: apply USB FDT fixups also when USB is modular
Bard Liao <yung-chuan.liao@linux.intel.com>
soundwire: cadence_master: wait and cancel cdns->work before clock stop
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: check IP header size in cfg80211_classify8021d()
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
Carolina Jubran <cjubran@nvidia.com>
IB/IPoIB: Avoid restoring OPER_UP after multicast flush
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short association responses
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short beacon and probe responses
Peng Hao <flyingpenghao@gmail.com>
wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
Mariano Baragiola <mbaragiola@linux.com>
wifi: virt_wifi: free skb when disconnected
Ruoyu Wang <ruoyuw560@gmail.com>
dmaengine: sprd: Fix runtime PM reference leak in probe
Quanye Yang <quanyeyang@proton.me>
RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Enforce local fence for IB_WR_REG_MR
Li RongQing <lirongqing@baidu.com>
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: wait for deferred control PDU completions before releasing the connection
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/iser: reject a remote invalidation of an unregistered direction
Krystian Kaniewski <krystianmkaniewski@gmail.com>
RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
Michael Bommarito <michael.bommarito@gmail.com>
RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
Xixin Liu <liuxixin@kylinos.cn>
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
Xixin Liu <liuxixin@kylinos.cn>
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
Gang Yan <yangang@kylinos.cn>
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
Norbert Szetei <norbert@doyensec.com>
RDMA/rxe: validate access flags before swapping the MR's PD
Guoqing Jiang <guoqing.jiang@linux.dev>
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
Pengpeng Hou <pengpeng@iscas.ac.cn>
ARM: socfpga: select the PL310 erratum 753970 workaround
Maher Azzouzi <maherazz04@gmail.com>
esp: downgrade zerocopy managed frags before mutating skb frags
Eric Dumazet <edumazet@google.com>
xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
Kyle Zeng <kylebot@openai.com>
xfrm: fix compat ALLOCSPI request use-after-free
Sabrina Dubroca <sd@queasysnail.net>
xfrm: avoid RCU warnings around the per-netns netlink socket
Chen Linxuan <me@black-desk.cn>
pidfd: hold exec_update_lock around namespace ioctl
Ido Schimmel <idosch@nvidia.com>
ipv6: Honor oif when choosing nexthop for locally generated traffic
Ido Schimmel <idosch@nvidia.com>
ipv6: Select best matching nexthop object in fib6_table_lookup()
Arash Golgol <arash.golgol@gmail.com>
media: video-i2c: fix buffer queue ordering
Eric Dumazet <edumazet@google.com>
ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: mcast: Don't hold RTNL for MCAST_ socket options.
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: mcast: Don't hold RTNL for IPV6_DROP_MEMBERSHIP and MCAST_LEAVE_GROUP.
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: mcast: Don't hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.
Kuniyuki Iwashima <kuniyu@google.com>
ipv6: mcast: Use in6_dev_get() in ipv6_dev_mc_dec().
Kevin Hao <haokexin@gmail.com>
net: cpsw: Execute ndo_set_rx_mode callback in a work queue
Kevin Hao <haokexin@gmail.com>
net: cpsw_new: Execute ndo_set_rx_mode callback in a work queue
Jens Axboe <axboe@kernel.dk>
sunvdc: fix -EIO issue due to lack of retries
Günther Noack <gnoack@google.com>
selftests/landlock: Add tests for whiteout object creation
Vasily Gorbik <gor@linux.ibm.com>
s390/boot: Avoid IPL parameter append past command line
Vasily Gorbik <gor@linux.ibm.com>
s390/boot: Add sized_strscpy() to enable strscpy() usage
Mickaël Salaün <mic@digikod.net>
selftests/landlock: Add disconnected leafs and branch test suites
Tingmao Wang <m@maowtm.org>
selftests/landlock: Add tests for access through disconnected paths
Matthieu Buffet <matthieu@buffet.re>
selftests/landlock: Add missing connect(minimal AF_UNSPEC) test
Matthieu Buffet <matthieu@buffet.re>
selftests/landlock: Add test for TCP fast open
Matthieu Buffet <matthieu@buffet.re>
landlock: Fix TCP Fast Open connection bypass
Sasha Levin <sashal@kernel.org>
Revert "hwmon: (emc1403) Rely on subsystem locking"
Sasha Levin <sashal@kernel.org>
Revert "hwmon: (emc1403) Drop hysteresis for low limit temperature"
-------------
Diffstat:
.../ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
Documentation/ABI/testing/sysfs-fs-erofs | 2 +-
Documentation/arch/arm64/booting.rst | 1 +
Documentation/arch/s390/pci.rst | 144 +-
Documentation/hwmon/emc1403.rst | 8 +-
Documentation/networking/ip-sysctl.rst | 2 +
.../net_cachelines/inet_connection_sock.rst | 1 +
.../networking/net_cachelines/inet_sock.rst | 1 +
.../networking/net_cachelines/net_device.rst | 1 +
Documentation/trace/eprobetrace.rst | 269 ++++
Documentation/trace/index.rst | 1 +
Makefile | 4 +-
arch/arm/mach-socfpga/Kconfig | 2 +-
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
arch/arm64/include/asm/el2_setup.h | 8 +-
arch/arm64/include/asm/io.h | 3 +-
arch/arm64/include/asm/percpu.h | 33 +-
arch/arm64/kernel/hibernate-asm.S | 2 +
arch/arm64/kernel/hibernate.c | 4 +-
arch/arm64/kvm/emulate-nested.c | 2 +-
arch/arm64/kvm/hypercalls.c | 3 +-
arch/arm64/kvm/mmu.c | 15 +-
arch/arm64/kvm/vgic/vgic-its.c | 108 +-
arch/arm64/kvm/vgic/vgic.h | 23 -
arch/arm64/net/bpf_jit_comp.c | 2 +
arch/mips/cavium-octeon/octeon-platform.c | 4 +-
arch/mips/net/bpf_jit_comp32.c | 2 +-
arch/mips/net/bpf_jit_comp64.c | 3 +-
arch/powerpc/kernel/iommu.c | 2 +-
arch/powerpc/kvm/book3s_hv_nested.c | 2 +
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 +-
arch/riscv/kvm/aia_imsic.c | 11 +-
arch/riscv/kvm/vcpu_pmu.c | 33 +-
arch/riscv/kvm/vcpu_sbi_hsm.c | 4 +-
arch/riscv/kvm/vcpu_timer.c | 5 +-
arch/s390/boot/ipl_parm.c | 26 +-
arch/s390/boot/string.c | 12 +
arch/s390/include/asm/debug.h | 8 +-
arch/s390/kernel/debug.c | 15 +-
arch/s390/kvm/interrupt.c | 72 +-
arch/s390/kvm/kvm-s390.c | 4 +-
arch/x86/entry/entry_fred.c | 11 +-
arch/x86/events/intel/core.c | 89 +-
arch/x86/events/intel/ds.c | 36 +-
arch/x86/events/intel/pt.c | 2 +
arch/x86/events/perf_event.h | 2 +-
arch/x86/include/asm/kvm_host.h | 4 +-
arch/x86/kernel/cpu/mce/core.c | 27 +-
arch/x86/kernel/cpu/microcode/intel.c | 26 +
arch/x86/kvm/Makefile | 2 +-
arch/x86/kvm/mmu/mmu.c | 60 +-
arch/x86/kvm/pmu.c | 8 -
arch/x86/kvm/regs.c | 872 ++++++++++
arch/x86/kvm/svm/sev.c | 77 +-
arch/x86/kvm/svm/svm.h | 1 +
arch/x86/kvm/vmx/pmu_intel.c | 3 +
arch/x86/kvm/x86.c | 900 +----------
arch/x86/kvm/x86.h | 28 +
arch/x86/pci/fixup.c | 99 ++
drivers/ata/libahci.c | 15 +-
drivers/ata/libahci_platform.c | 2 +-
drivers/ata/libata-scsi.c | 10 +-
drivers/base/core.c | 131 +-
drivers/block/sunvdc.c | 9 +-
drivers/bluetooth/btintel_pcie.c | 18 +-
drivers/bluetooth/btmtk.c | 7 +-
drivers/bluetooth/btmtksdio.c | 4 +-
drivers/bluetooth/btusb.c | 17 +
drivers/char/hw_random/atmel-rng.c | 2 +-
drivers/char/hw_random/cctrng.c | 2 +-
drivers/char/hw_random/exynos-trng.c | 2 +-
drivers/char/hw_random/ingenic-rng.c | 2 +-
drivers/char/hw_random/ks-sa-rng.c | 2 +-
drivers/char/hw_random/mxc-rnga.c | 2 +-
drivers/char/hw_random/n2-drv.c | 2 +-
drivers/char/hw_random/npcm-rng.c | 2 +-
drivers/char/hw_random/omap-rng.c | 2 +-
drivers/char/hw_random/stm32-rng.c | 11 +-
drivers/char/hw_random/timeriomem-rng.c | 2 +-
drivers/char/hw_random/xgene-rng.c | 2 +-
drivers/clk/clk-scpi.c | 2 +-
drivers/clk/qcom/gcc-qcm2290.c | 6 +-
drivers/clk/qcom/gcc-sm6115.c | 6 +-
drivers/dma-buf/dma-heap.c | 80 +-
drivers/dma/dmaengine.c | 40 +-
drivers/dma/mmp_pdma.c | 2 +-
drivers/dma/sprd-dma.c | 3 +-
drivers/dma/sun6i-dma.c | 9 +-
drivers/dma/ti/k3-udma-glue.c | 5 +-
drivers/dma/xilinx/xilinx_dma.c | 26 +-
drivers/dpll/dpll_netlink.c | 3 +-
drivers/edac/altera_edac.c | 115 +-
drivers/edac/altera_edac.h | 1 +
drivers/firmware/arm_scpi.c | 4 +-
drivers/firmware/qcom/qcom_scm.c | 44 +-
drivers/firmware/sysfb_simplefb.c | 31 +-
drivers/gpio/gpio-arizona.c | 8 +-
drivers/gpio/gpio-tps65219.c | 2 +-
drivers/gpio/gpio-virtuser.c | 3 +-
drivers/gpio/gpio-zynq.c | 10 +-
drivers/gpio/gpiolib-cdev.c | 30 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c | 1 +
drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c | 2 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c | 20 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 18 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c | 6 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 11 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 36 +
drivers/gpu/drm/amd/amdgpu/amdgpu_fence.c | 25 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_ib.c | 2 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_ids.c | 11 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_job.c | 9 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c | 4 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_ring.c | 2 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_ring.h | 21 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_sync.c | 11 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_sync.h | 3 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_umsch_mm.c | 459 +-----
drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 3 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c | 1 +
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 4 +-
drivers/gpu/drm/amd/display/dc/dml/Makefile | 6 +-
.../amd/display/dc/dml2/dml2_translation_helper.c | 1 +
drivers/gpu/drm/armada/armada_fbdev.c | 4 +-
drivers/gpu/drm/bridge/samsung-dsim.c | 2 +-
drivers/gpu/drm/bridge/tc358768.c | 15 +-
drivers/gpu/drm/drm_atomic_uapi.c | 13 +-
drivers/gpu/drm/drm_client.c | 4 +-
drivers/gpu/drm/drm_fb_helper.c | 24 +-
drivers/gpu/drm/drm_fbdev_client.c | 14 +-
drivers/gpu/drm/drm_fbdev_dma.c | 4 +-
drivers/gpu/drm/drm_fbdev_shmem.c | 4 +-
drivers/gpu/drm/drm_fbdev_ttm.c | 4 +-
drivers/gpu/drm/drm_file.c | 12 +-
drivers/gpu/drm/exynos/exynos_drm_fbdev.c | 4 +-
drivers/gpu/drm/gma500/fbdev.c | 4 +-
drivers/gpu/drm/gud/gud_pipe.c | 4 +-
drivers/gpu/drm/i915/display/intel_connector.c | 4 +-
drivers/gpu/drm/i915/display/intel_cursor.c | 7 +-
drivers/gpu/drm/i915/display/intel_ddi.c | 4 +-
.../gpu/drm/i915/display/intel_display_debugfs.c | 8 +-
drivers/gpu/drm/i915/display/intel_display_types.h | 20 +-
drivers/gpu/drm/i915/display/intel_dp.c | 36 +-
drivers/gpu/drm/i915/display/intel_dp_hdcp.c | 6 +-
.../gpu/drm/i915/display/intel_dp_link_training.c | 4 +-
drivers/gpu/drm/i915/display/intel_dp_mst.c | 155 +-
drivers/gpu/drm/i915/display/intel_fbdev.c | 8 +-
drivers/gpu/drm/i915/display/intel_hdcp.c | 8 +-
drivers/gpu/drm/i915/display/intel_psr.c | 39 +-
drivers/gpu/drm/i915/display/skl_universal_plane.c | 9 +-
drivers/gpu/drm/i915/gem/i915_gem_object.c | 2 +-
drivers/gpu/drm/imagination/pvr_free_list.c | 15 +-
drivers/gpu/drm/imagination/pvr_mmu.c | 19 +-
drivers/gpu/drm/imagination/pvr_mmu.h | 2 +-
drivers/gpu/drm/imagination/pvr_vm.c | 4 +-
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 +
drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c | 1 +
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 +-
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 +-
drivers/gpu/drm/msm/msm_fbdev.c | 4 +-
drivers/gpu/drm/nouveau/nouveau_bo.c | 3 +-
drivers/gpu/drm/nouveau/nouveau_connector.c | 5 +-
drivers/gpu/drm/nouveau/nouveau_drm.c | 5 +-
drivers/gpu/drm/nouveau/nouveau_gem.c | 2 +
drivers/gpu/drm/nouveau/nouveau_sched.c | 2 +-
drivers/gpu/drm/nouveau/nouveau_sched.h | 1 +
drivers/gpu/drm/nouveau/nouveau_uvmm.c | 13 +-
drivers/gpu/drm/nouveau/nvif/vmm.c | 1 +
drivers/gpu/drm/nouveau/nvkm/engine/disp/gv100.c | 4 +-
drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h | 2 +
drivers/gpu/drm/nouveau/nvkm/engine/disp/r535.c | 8 +-
drivers/gpu/drm/nouveau/nvkm/engine/disp/uoutp.c | 3 +-
drivers/gpu/drm/nouveau/nvkm/subdev/clk/base.c | 23 +-
drivers/gpu/drm/nouveau/nvkm/subdev/fb/ramnv1a.c | 2 +
drivers/gpu/drm/omapdrm/omap_fbdev.c | 4 +-
drivers/gpu/drm/radeon/radeon_fbdev.c | 4 +-
drivers/gpu/drm/tegra/fbdev.c | 4 +-
drivers/gpu/drm/tiny/ofdrm.c | 8 +-
drivers/gpu/drm/tiny/simpledrm.c | 61 +-
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
drivers/gpu/drm/virtio/virtgpu_gem.c | 2 +-
drivers/gpu/drm/virtio/virtgpu_ioctl.c | 6 +-
drivers/gpu/drm/virtio/virtgpu_submit.c | 11 +-
drivers/gpu/drm/virtio/virtgpu_vram.c | 17 +-
drivers/gpu/drm/xe/instructions/xe_gpu_commands.h | 1 +
drivers/gpu/drm/xe/xe_bo.h | 19 +
drivers/gpu/drm/xe/xe_ring_ops.c | 16 +-
drivers/gpu/drm/xe/xe_vm.c | 29 +-
drivers/hid/amd-sfh-hid/amd_sfh_common.h | 4 +
drivers/hid/amd-sfh-hid/amd_sfh_pcie.c | 10 +
drivers/hid/bpf/hid_bpf_dispatch.c | 12 +-
drivers/hid/hid-alps.c | 31 +-
drivers/hid/hid-asus.c | 34 +-
drivers/hid/hid-ids.h | 3 +
drivers/hid/hid-logitech-hidpp.c | 24 +-
drivers/hid/hid-quirks.c | 3 +-
drivers/hid/wacom_sys.c | 5 +-
drivers/hwmon/emc1403.c | 73 +-
drivers/hwmon/hp-wmi-sensors.c | 2 +
drivers/hwmon/pmbus/pmbus.h | 3 +-
drivers/hwmon/pmbus/tps53679.c | 11 +-
drivers/hwmon/pwm-fan.c | 13 +-
drivers/hwmon/w83791d.c | 1 +
drivers/hwmon/w83793.c | 4 +-
drivers/i2c/busses/i2c-at91-core.c | 3 +
drivers/i2c/busses/i2c-at91-master.c | 12 +-
drivers/i2c/busses/i2c-at91.h | 1 +
drivers/i2c/busses/i2c-imx.c | 3 +
drivers/i2c/busses/i2c-mxs.c | 5 +-
drivers/i2c/busses/i2c-qcom-cci.c | 37 +-
drivers/i2c/busses/i2c-qcom-geni.c | 33 +-
drivers/i2c/i2c-atr.c | 1 +
drivers/i3c/master.c | 20 +-
drivers/infiniband/core/iwpm_util.c | 9 +-
drivers/infiniband/core/mad.c | 3 +-
drivers/infiniband/core/ucma.c | 7 +-
drivers/infiniband/core/verbs.c | 12 +-
drivers/infiniband/hw/efa/efa_com.c | 7 +-
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 35 +-
drivers/infiniband/hw/hfi1/file_ops.c | 23 +-
drivers/infiniband/hw/irdma/verbs.c | 2 +-
drivers/infiniband/hw/mlx4/sysfs.c | 4 +
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +-
drivers/infiniband/sw/rxe/rxe_mr.c | 3 +-
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +-
drivers/infiniband/sw/siw/siw_cm.c | 7 +-
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +-
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 +-
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +-
drivers/infiniband/ulp/isert/ib_isert.c | 22 +
drivers/infiniband/ulp/isert/ib_isert.h | 2 +
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 +
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 +
drivers/input/evdev.c | 2 +
drivers/input/input-compat.c | 2 +
drivers/input/joystick/xpad.c | 10 +-
drivers/input/keyboard/adp5588-keys.c | 12 +-
drivers/input/keyboard/atkbd.c | 8 +
drivers/input/misc/soc_button_array.c | 16 +-
drivers/input/mouse/synaptics.c | 8 +
drivers/input/rmi4/rmi_driver.c | 13 +
drivers/input/rmi4/rmi_smbus.c | 10 +-
drivers/input/serio/hp_sdc.c | 2 +-
drivers/input/serio/i8042-acpipnpio.h | 7 +
drivers/input/touchscreen/cyttsp5.c | 1 +
drivers/iommu/iommufd/device.c | 70 +-
drivers/iommu/iommufd/hw_pagetable.c | 13 +-
drivers/iommu/iommufd/iommufd_private.h | 8 +-
drivers/iommu/iommufd/selftest.c | 20 +
drivers/iommu/msm_iommu.c | 55 +-
drivers/media/i2c/imx355.c | 62 +-
drivers/media/i2c/video-i2c.c | 5 +-
.../platform/chips-media/wave5/wave5-vpu-dec.c | 12 +-
.../platform/chips-media/wave5/wave5-vpuconfig.h | 1 +
drivers/memstick/core/ms_block.c | 2 +
drivers/mmc/core/bus.c | 2 +-
drivers/mmc/core/host.c | 1 +
drivers/mmc/core/sdio_uart.c | 3 +
drivers/mmc/host/mmc_hsq.c | 8 +-
drivers/mmc/host/mmc_spi.c | 1 +
drivers/mmc/host/mmci.c | 3 +
drivers/mmc/host/mxcmmc.c | 4 +
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +
drivers/mmc/host/sdhci-of-aspeed.c | 5 +-
drivers/mmc/host/sdhci_am654.c | 43 +-
drivers/mmc/host/sh_mmcif.c | 3 +-
drivers/mmc/host/via-sdmmc.c | 4 +
drivers/mtd/nand/raw/pl35x-nand-controller.c | 10 +-
drivers/net/bonding/bond_main.c | 2 +-
drivers/net/dsa/mt7530-mdio.c | 18 +-
drivers/net/ethernet/amazon/ena/ena_com.c | 25 +-
drivers/net/ethernet/amazon/ena/ena_com.h | 14 -
drivers/net/ethernet/amazon/ena/ena_netdev.c | 1 +
drivers/net/ethernet/atheros/atl1c/atl1c_main.c | 3 +
drivers/net/ethernet/atheros/atl1e/atl1e_main.c | 3 +
drivers/net/ethernet/atheros/atlx/atl1.c | 3 +
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 82 +-
drivers/net/ethernet/broadcom/bnxt/bnxt.h | 2 +
drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c | 6 +-
drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.h | 2 +-
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 63 +-
drivers/net/ethernet/broadcom/genet/bcmgenet.h | 5 +-
drivers/net/ethernet/broadcom/genet/bcmgenet_wol.c | 20 +-
drivers/net/ethernet/broadcom/tg3.c | 15 +-
drivers/net/ethernet/brocade/bna/bnad.c | 16 +-
drivers/net/ethernet/cadence/macb_main.c | 13 +-
drivers/net/ethernet/cadence/macb_ptp.c | 20 +-
.../chelsio/inline_crypto/chtls/chtls_cm.c | 4 +-
drivers/net/ethernet/cortina/gemini.c | 2 +-
drivers/net/ethernet/freescale/fman/fman.c | 1 +
drivers/net/ethernet/hisilicon/hns/hns_dsaf_mac.c | 3 +
drivers/net/ethernet/intel/idpf/idpf.h | 24 +-
drivers/net/ethernet/intel/idpf/idpf_dev.c | 10 +-
drivers/net/ethernet/intel/idpf/idpf_lib.c | 35 +-
drivers/net/ethernet/intel/idpf/idpf_txrx.c | 301 ++--
drivers/net/ethernet/intel/idpf/idpf_txrx.h | 14 +-
drivers/net/ethernet/intel/idpf/idpf_vf_dev.c | 10 +-
drivers/net/ethernet/intel/idpf/idpf_virtchnl.c | 20 +-
drivers/net/ethernet/intel/idpf/idpf_virtchnl.h | 3 +-
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 +-
drivers/net/ethernet/marvell/octeontx2/af/common.h | 45 +-
drivers/net/ethernet/mediatek/mtk_eth_soc.c | 6 +-
.../ethernet/mellanox/mlx5/core/en/rep/bridge.c | 45 +-
drivers/net/ethernet/mellanox/mlx5/core/en/tc_ct.c | 3 +
.../ethernet/mellanox/mlx5/core/en_accel/macsec.c | 2 +
drivers/net/ethernet/mellanox/mlx5/core/en_main.c | 1 -
drivers/net/ethernet/mellanox/mlx5/core/en_rx.c | 39 +-
.../net/ethernet/mellanox/mlx5/core/esw/bridge.c | 15 +-
.../net/ethernet/mellanox/mlx5/core/esw/bridge.h | 2 +
.../net/ethernet/mellanox/mlx5/core/lib/devcom.c | 5 +-
drivers/net/ethernet/meta/fbnic/fbnic_csr.h | 1 +
drivers/net/ethernet/meta/fbnic/fbnic_fw.c | 9 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 2 +-
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
drivers/net/ethernet/netronome/nfp/crypto/ipsec.c | 3 +-
drivers/net/ethernet/socionext/netsec.c | 2 +
drivers/net/ethernet/stmicro/stmmac/dwmac-rk.c | 5 +-
drivers/net/ethernet/stmicro/stmmac/dwmac4_descs.c | 4 +-
drivers/net/ethernet/stmicro/stmmac/hwif.h | 4 +-
drivers/net/ethernet/stmicro/stmmac/ring_mode.c | 4 +-
.../net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 -
.../net/ethernet/stmicro/stmmac/stmmac_selftests.c | 106 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c | 19 +-
drivers/net/ethernet/ti/cpsw.c | 41 +-
drivers/net/ethernet/ti/cpsw_new.c | 35 +-
drivers/net/ethernet/ti/cpsw_priv.h | 1 +
drivers/net/ethernet/ti/netcp_core.c | 2 +-
drivers/net/fddi/skfp/skfddi.c | 3 +-
drivers/net/macsec.c | 123 +-
drivers/net/pcs/pcs-xpcs.c | 4 +-
drivers/net/phy/mediatek/mtk-ge-soc.c | 23 +-
drivers/net/usb/catc.c | 15 +-
drivers/net/usb/cdc_mbim.c | 5 +
drivers/net/usb/lan78xx.c | 2 +
drivers/net/usb/sr9700.c | 3 +-
drivers/net/veth.c | 2 +
drivers/net/virtio_net.c | 9 +
drivers/net/vrf.c | 2 -
drivers/net/vxlan/vxlan_core.c | 6 +-
drivers/net/wireless/ath/ath11k/mac.c | 25 +-
drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +-
.../wireless/broadcom/brcm80211/brcmfmac/core.c | 2 +
.../broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 +
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 6 +
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
drivers/net/wireless/intersil/p54/eeprom.c | 22 +-
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 12 +-
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
drivers/net/wireless/marvell/mwifiex/scan.c | 54 +-
drivers/net/wireless/marvell/mwifiex/util.c | 10 +-
.../net/wireless/mediatek/mt76/mt7915/debugfs.c | 5 +
drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c | 33 +-
drivers/net/wireless/mediatek/mt76/mt7915/eeprom.h | 1 +
drivers/net/wireless/mediatek/mt76/mt7915/init.c | 7 +-
drivers/net/wireless/mediatek/mt76/mt7915/mcu.c | 15 +-
drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h | 3 +-
drivers/net/wireless/mediatek/mt76/mt7996/mcu.c | 8 +-
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 +
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +
drivers/net/wireless/realtek/rtw88/fw.c | 8 +-
drivers/net/wireless/realtek/rtw88/tx.c | 2 +-
drivers/net/wireless/realtek/rtw89/core.h | 3 +-
drivers/net/wireless/realtek/rtw89/mac.c | 13 +-
drivers/net/wireless/realtek/rtw89/mac80211.c | 3 +-
drivers/net/wireless/realtek/rtw89/pci.c | 13 +
drivers/net/wireless/realtek/rtw89/pci.h | 1 +
drivers/net/wireless/realtek/rtw89/phy.c | 3 +-
drivers/net/wireless/realtek/rtw89/rtw8851be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852ae.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852bte.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852ce.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8922ae.c | 1 +
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 -
drivers/net/wireless/ti/wlcore/main.c | 4 +-
drivers/net/wireless/virtual/mac80211_hwsim.c | 39 +-
drivers/net/wireless/virtual/virt_wifi.c | 4 +-
drivers/net/wwan/mhi_wwan_mbim.c | 28 +-
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 +
drivers/nfc/microread/microread.c | 6 +-
drivers/nfc/nfcmrvl/fw_dnld.c | 11 +-
drivers/nfc/pn533/pn533.c | 14 +-
drivers/nfc/pn533/pn533.h | 4 +-
drivers/nfc/pn533/usb.c | 4 +-
drivers/nfc/pn544/pn544.c | 7 +-
drivers/nfc/port100.c | 7 +
drivers/nfc/st21nfca/core.c | 12 +-
drivers/nfc/st21nfca/i2c.c | 29 +-
drivers/nfc/virtual_ncidev.c | 3 +-
drivers/nvdimm/nd_virtio.c | 125 +-
drivers/nvdimm/pmem.c | 15 +-
drivers/nvdimm/region_devs.c | 5 +-
drivers/nvdimm/virtio_pmem.c | 14 +-
drivers/nvdimm/virtio_pmem.h | 6 +
drivers/nvme/host/core.c | 83 +-
drivers/nvme/host/nvme.h | 2 +-
drivers/pci/controller/plda/pcie-starfive.c | 36 +-
drivers/pci/hotplug/pnv_php.c | 2 +-
drivers/pci/hotplug/rpaphp_slot.c | 2 +-
drivers/pci/of_property.c | 11 +-
drivers/pci/pci.c | 5 +-
drivers/pci/rebar.c | 19 +-
drivers/pci/setup-bus.c | 56 +-
drivers/pci/slot.c | 67 +-
drivers/perf/arm-cmn.c | 10 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 4 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 302 +++-
drivers/pinctrl/meson/pinctrl-meson-s4.c | 2 +-
drivers/pinctrl/pinctrl-single.c | 3 +-
drivers/pinctrl/sunxi/pinctrl-sunxi.c | 76 +-
drivers/pinctrl/sunxi/pinctrl-sunxi.h | 7 +
drivers/platform/x86/amd/pmc/Makefile | 2 +-
drivers/platform/x86/amd/pmc/mp1_stb.c | 316 ++++
drivers/platform/x86/amd/pmc/pmc.c | 314 +---
drivers/platform/x86/amd/pmc/pmc.h | 18 +-
drivers/platform/x86/intel/int1092/intel_sar.c | 39 +-
.../x86/intel/speed_select_if/isst_tpmi_core.c | 14 +-
drivers/platform/x86/think-lmi.c | 45 +-
drivers/platform/x86/think-lmi.h | 2 +-
drivers/power/sequencing/core.c | 11 +-
drivers/power/supply/ab8500_fg.c | 32 +-
drivers/power/supply/qcom_battmgr.c | 8 +-
drivers/remoteproc/qcom_q6v5_adsp.c | 8 +-
drivers/remoteproc/qcom_q6v5_pas.c | 93 +-
drivers/rtc/rtc-rzn1.c | 16 +-
drivers/s390/cio/chp.c | 3 +
drivers/s390/cio/cio.c | 11 +-
drivers/s390/cio/cio.h | 5 +-
drivers/s390/cio/cmf.c | 2 +-
drivers/s390/cio/device.c | 9 +-
drivers/s390/cio/device_fsm.c | 3 +
drivers/s390/cio/device_ops.c | 23 +
drivers/s390/cio/vfio_ccw_fsm.c | 2 +-
drivers/s390/crypto/vfio_ap_ops.c | 44 +-
drivers/scsi/fnic/fnic.h | 2 +-
drivers/scsi/fnic/fnic_isr.c | 13 +-
drivers/scsi/fnic/fnic_main.c | 33 +-
drivers/scsi/libiscsi_tcp.c | 3 +
drivers/scsi/megaraid/megaraid_sas_base.c | 4 +-
drivers/scsi/qla2xxx/qla_bsg.c | 47 +-
drivers/scsi/qla2xxx/qla_def.h | 2 +
drivers/scsi/qla2xxx/qla_fw.h | 4 +
drivers/scsi/qla2xxx/qla_init.c | 14 +
drivers/scsi/qla2xxx/qla_iocb.c | 23 +-
drivers/scsi/qla2xxx/qla_isr.c | 33 +-
drivers/scsi/qla2xxx/qla_mbx.c | 6 +-
drivers/scsi/qla2xxx/qla_mid.c | 49 +-
drivers/scsi/qla2xxx/qla_nvme.c | 10 +
drivers/scsi/qla2xxx/qla_os.c | 17 +-
drivers/scsi/scsi.c | 24 +-
drivers/scsi/sd_zbc.c | 8 +-
drivers/soc/qcom/mdt_loader.c | 4 +-
drivers/soundwire/cadence_master.c | 7 +
drivers/spi/spi-zynqmp-gqspi.c | 34 +
drivers/staging/media/rkvdec/rkvdec.c | 4 +-
drivers/staging/rtl8723bs/core/rtw_mlme.c | 5 +-
drivers/staging/sm750fb/sm750.c | 2 +-
drivers/staging/sm750fb/sm750.h | 2 +-
drivers/staging/sm750fb/sm750_accel.c | 6 +-
drivers/staging/sm750fb/sm750_accel.h | 4 +-
drivers/thermal/gov_step_wise.c | 10 +-
drivers/usb/cdns3/cdns3-gadget.c | 4 +-
drivers/usb/cdns3/cdnsp-gadget.c | 112 +-
drivers/usb/cdns3/cdnsp-gadget.h | 1 +
drivers/usb/cdns3/cdnsp-mem.c | 98 +-
drivers/usb/cdns3/core.h | 2 +-
drivers/usb/dwc3/core.h | 3 +-
drivers/usb/dwc3/ep0.c | 2 +-
drivers/usb/dwc3/gadget.c | 129 +-
drivers/usb/gadget/function/f_mass_storage.c | 3 +
drivers/usb/host/xhci-pci.c | 8 +-
drivers/usb/storage/realtek_cr.c | 9 +-
drivers/usb/typec/tcpm/tcpm.c | 39 +-
drivers/video/screen_info_generic.c | 36 +
drivers/virtio/virtio_mmio.c | 66 +-
drivers/watchdog/da9063_wdt.c | 4 +-
drivers/watchdog/digicolor_wdt.c | 13 +-
drivers/watchdog/msc313e_wdt.c | 16 +-
drivers/watchdog/rtd119x_wdt.c | 7 +-
drivers/watchdog/sp5100_tco.c | 6 +-
drivers/watchdog/starfive-wdt.c | 2 +-
fs/9p/vfs_addr.c | 12 +
fs/autofs/inode.c | 4 +
fs/btrfs/dev-replace.c | 1 +
fs/btrfs/file.c | 4 +-
fs/btrfs/tree-checker.c | 2 +-
fs/configfs/dir.c | 13 +-
fs/configfs/symlink.c | 51 +-
fs/erofs/fscache.c | 2 +
fs/erofs/sysfs.c | 2 +
fs/exec.c | 29 +-
fs/f2fs/debug.c | 4 -
fs/f2fs/dir.c | 7 +-
fs/f2fs/f2fs.h | 29 +-
fs/f2fs/file.c | 47 +-
fs/f2fs/gc.c | 51 +-
fs/f2fs/gc.h | 25 -
fs/f2fs/inline.c | 2 +-
fs/f2fs/namei.c | 6 +-
fs/f2fs/node.c | 22 +-
fs/f2fs/recovery.c | 41 +-
fs/f2fs/segment.c | 9 +-
fs/f2fs/super.c | 4 +-
fs/f2fs/sysfs.c | 18 +-
fs/fs-writeback.c | 25 +-
fs/inode.c | 11 +-
fs/kernfs/mount.c | 4 +-
fs/lockd/svcsubs.c | 2 +-
fs/ntfs3/inode.c | 7 +-
fs/ocfs2/namei.c | 9 +-
fs/ocfs2/xattr.c | 13 +-
fs/ocfs2/xattr.h | 8 +-
fs/pidfs.c | 43 +-
fs/smb/client/cached_dir.c | 32 +-
fs/smb/client/cifs_fs_sb.h | 1 +
fs/smb/client/cifsacl.c | 69 +-
fs/smb/client/cifsfs.c | 12 +
fs/smb/client/cifsglob.h | 12 +-
fs/smb/client/cifsproto.h | 8 +-
fs/smb/client/cifssmb.c | 2 +-
fs/smb/client/connect.c | 10 +
fs/smb/client/file.c | 11 +-
fs/smb/client/misc.c | 12 +-
fs/smb/client/reparse.c | 4 +-
fs/smb/client/reparse.h | 7 +-
fs/smb/client/sess.c | 106 +-
fs/smb/client/smb2inode.c | 11 +
fs/smb/client/smb2ops.c | 78 +-
fs/smb/client/smb2pdu.c | 64 +-
fs/smb/client/transport.c | 4 +-
fs/smb/server/smb2pdu.c | 89 +-
fs/smb/server/smb2pdu.h | 1 +
fs/squashfs/xz_wrapper.c | 6 +-
fs/super.c | 43 +-
fs/udf/inode.c | 129 +-
fs/xfs/libxfs/xfs_da_btree.c | 2 +-
fs/xfs/libxfs/xfs_da_btree.h | 2 +
fs/xfs/scrub/attr_repair.c | 4 +-
fs/xfs/scrub/dir_repair.c | 23 +-
fs/xfs/scrub/health.c | 6 +-
fs/xfs/scrub/inode.c | 2 +-
fs/xfs/scrub/inode_repair.c | 2 +-
fs/xfs/scrub/orphanage.c | 6 +-
fs/xfs/scrub/reap.c | 2 +-
fs/xfs/scrub/refcount.c | 8 +-
fs/xfs/scrub/scrub.h | 2 +-
fs/xfs/scrub/stats.c | 1 +
fs/xfs/scrub/tempfile.c | 29 +-
fs/xfs/xfs_exchrange.c | 13 +-
fs/xfs/xfs_icache.c | 2 +-
fs/xfs/xfs_inode.h | 3 +
fs/xfs/xfs_qm.c | 10 +-
include/drm/drm_client.h | 10 +-
include/drm/drm_fb_helper.h | 11 +-
include/drm/drm_file.h | 1 +
include/keys/request_key_auth-type.h | 2 +-
include/linux/bpf_mem_alloc.h | 6 +
include/linux/compiler-context-analysis.h | 32 +
include/linux/compiler_types.h | 18 +-
include/linux/dev_printk.h | 1 +
include/linux/dmaengine.h | 7 +
include/linux/firmware/qcom/qcom_scm.h | 20 +-
include/linux/ftrace.h | 5 +-
include/linux/if_vlan.h | 3 +
include/linux/ipv6.h | 40 +-
include/linux/libnvdimm.h | 9 +
include/linux/lockd/lockd.h | 2 +-
include/linux/netdevice.h | 3 +
include/linux/pci.h | 14 +-
include/linux/perf_event.h | 1 +
include/linux/rculist.h | 29 +
include/linux/sched.h | 16 +-
include/linux/sched/rt.h | 2 +
include/linux/sched/signal.h | 5 +-
include/linux/sched/user.h | 3 +-
include/linux/screen_info.h | 2 +
include/linux/skbuff.h | 24 +-
include/linux/soc/qcom/mdt_loader.h | 6 +-
include/linux/virtio.h | 2 +-
include/net/bluetooth/coredump.h | 2 +
include/net/cfg80211.h | 25 +
include/net/gue.h | 19 +-
include/net/if_inet6.h | 2 -
include/net/inet_connection_sock.h | 11 +-
include/net/inet_sock.h | 1 +
include/net/ip6_route.h | 8 +-
include/net/mac80211.h | 5 +-
include/net/netfilter/nf_conntrack.h | 5 +
include/net/netfilter/nf_conntrack_timeout.h | 27 +-
include/net/netfilter/nf_tables.h | 2 -
include/net/netmem.h | 78 +-
include/net/netns/xfrm.h | 2 +-
include/net/nfc/hci.h | 2 +-
include/net/nfc/nfc.h | 3 +-
include/net/page_pool/helpers.h | 35 +-
include/net/page_pool/types.h | 5 +-
include/net/rose.h | 12 +
include/net/sock.h | 8 +-
include/net/tcp.h | 4 +-
include/sound/soc.h | 3 +-
include/uapi/linux/landlock.h | 37 +-
include/uapi/linux/nl80211.h | 5 +
init/main.c | 27 +-
io_uring/net.c | 41 +-
io_uring/rw.c | 32 +-
io_uring/waitid.c | 44 +-
kernel/bpf/arraymap.c | 6 +-
kernel/bpf/btf.c | 140 +-
kernel/bpf/crypto.c | 5 +-
kernel/bpf/hashtab.c | 236 ++-
kernel/bpf/memalloc.c | 106 +-
kernel/bpf/offload.c | 2 +
kernel/bpf/syscall.c | 5 +-
kernel/cgroup/pids.c | 5 +
kernel/dma/coherent.c | 13 +-
kernel/dma/swiotlb.c | 4 +-
kernel/events/core.c | 15 +-
kernel/events/ring_buffer.c | 29 +-
kernel/futex/pi.c | 10 -
kernel/locking/rtmutex_api.c | 2 +
kernel/reboot.c | 55 +-
kernel/sched/core.c | 77 +-
kernel/sched/sched.h | 9 +-
kernel/signal.c | 24 +-
kernel/sysctl.c | 31 -
kernel/trace/ftrace.c | 57 +-
kernel/trace/ring_buffer.c | 135 +-
kernel/trace/trace.c | 155 +-
kernel/trace/trace.h | 131 +-
kernel/trace/trace_btf.c | 31 +-
kernel/trace/trace_btf.h | 3 +-
kernel/trace/trace_eprobe.c | 19 +-
kernel/trace/trace_events_hist.c | 167 +-
kernel/trace/trace_events_trigger.c | 344 ++--
kernel/trace/trace_functions.c | 2 +-
kernel/trace/trace_probe.c | 5 +-
kernel/trace/trace_stack.c | 2 +-
kernel/workqueue.c | 2 +-
mm/backing-dev.c | 5 +-
mm/damon/vaddr.c | 1 +
mm/huge_memory.c | 10 +
mm/hugetlb.c | 55 +-
mm/khugepaged.c | 6 -
mm/madvise.c | 8 +
mm/memblock.c | 18 +-
mm/mlock.c | 2 +-
mm/mremap.c | 12 +-
mm/rmap.c | 23 +-
mm/secretmem.c | 117 +-
mm/vma.c | 8 +
net/8021q/vlan_dev.c | 5 +
net/atm/pppoatm.c | 42 +-
net/bluetooth/bnep/core.c | 17 +-
net/bluetooth/bnep/netdev.c | 8 +-
net/bluetooth/coredump.c | 65 +-
net/bluetooth/eir.c | 10 +-
net/bluetooth/hci_codec.c | 36 +-
net/bluetooth/hci_conn.c | 14 +-
net/bluetooth/hci_core.c | 26 +-
net/bluetooth/hci_sock.c | 20 +-
net/bluetooth/hci_sync.c | 2 +
net/bluetooth/iso.c | 53 +-
net/bluetooth/l2cap_core.c | 10 +-
net/bluetooth/mgmt.c | 27 +-
net/bluetooth/rfcomm/core.c | 3 +-
net/bluetooth/rfcomm/sock.c | 19 +-
net/bluetooth/smp.c | 17 +
net/bridge/br_cfm.c | 11 +-
net/bridge/br_device.c | 1 -
net/bridge/br_input.c | 35 +-
net/bridge/br_mdb.c | 2 +
net/bridge/br_mrp.c | 13 +-
net/bridge/br_mst.c | 20 +-
net/bridge/br_private.h | 26 +-
net/bridge/br_stp_bpdu.c | 5 +-
net/core/dev.c | 2 +-
net/core/devmem.c | 1 +
net/core/drop_monitor.c | 4 +-
net/core/filter.c | 46 +-
net/core/neighbour.c | 241 ++-
net/core/page_pool.c | 9 +-
net/core/skbuff.c | 41 +-
net/core/skmsg.c | 4 +
net/core/sock.c | 25 +-
net/core/sock_map.c | 1 +
net/dccp/ipv6.c | 4 +-
net/dccp/timer.c | 4 +-
net/ipv4/arp.c | 1 +
net/ipv4/esp4.c | 6 +
net/ipv4/fib_semantics.c | 59 +-
net/ipv4/fou_core.c | 4 +
net/ipv4/icmp.c | 17 +-
net/ipv4/inet_connection_sock.c | 13 +-
net/ipv4/inet_diag.c | 4 +-
net/ipv4/ip_gre.c | 12 +
net/ipv4/ipconfig.c | 90 +-
net/ipv4/ipmr.c | 3 +-
net/ipv4/ipmr_base.c | 2 +-
net/ipv4/sysctl_net_ipv4.c | 4 +-
net/ipv4/tcp_input.c | 3 +-
net/ipv4/tcp_ipv4.c | 4 +-
net/ipv4/tcp_output.c | 3 +
net/ipv4/tcp_timer.c | 5 +-
net/ipv4/xfrm4_input.c | 2 -
net/ipv6/addrconf.c | 3 +-
net/ipv6/af_inet6.c | 2 +-
net/ipv6/esp6.c | 6 +
net/ipv6/exthdrs_core.c | 3 +
net/ipv6/inet6_connection_sock.c | 2 +-
net/ipv6/ip6_flowlabel.c | 67 +-
net/ipv6/ip6_gre.c | 2 +-
net/ipv6/ip6_output.c | 3 +-
net/ipv6/ip6mr.c | 2 +-
net/ipv6/ipv6_sockglue.c | 9 -
net/ipv6/mcast.c | 253 +--
net/ipv6/netfilter/ip6t_rpfilter.c | 2 +-
net/ipv6/netfilter/ip6t_rt.c | 11 +-
net/ipv6/route.c | 33 +-
net/ipv6/seg6.c | 4 +-
net/ipv6/seg6_local.c | 3 +
net/ipv6/tcp_ipv6.c | 21 +-
net/ipv6/xfrm6_input.c | 2 -
net/ipv6/xfrm6_output.c | 10 +-
net/llc/llc_c_ac.c | 2 +-
net/llc/llc_s_ac.c | 4 +
net/llc/llc_sap.c | 8 +-
net/mac80211/cfg.c | 55 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/debugfs_netdev.c | 9 +
net/mac80211/ieee80211_i.h | 5 +-
net/mac80211/iface.c | 76 +-
net/mac80211/main.c | 4 +
net/mac80211/mesh.c | 34 +-
net/mac80211/offchannel.c | 7 +
net/mac80211/pm.c | 8 +-
net/mac80211/scan.c | 24 +-
net/mac80211/tdls.c | 19 +-
net/mac80211/tx.c | 66 +-
net/mac80211/util.c | 3 +-
net/mctp/route.c | 2 +-
net/mptcp/Makefile | 2 +-
net/mptcp/ctrl.c | 4 +-
net/mptcp/mib.c | 5 +
net/mptcp/mib.h | 5 +
net/mptcp/options.c | 6 +-
net/mptcp/{pm_netlink.c => pm_kernel.c} | 71 +-
net/mptcp/pm_userspace.c | 32 +-
net/mptcp/protocol.c | 95 +-
net/mptcp/protocol.h | 36 +-
net/mptcp/subflow.c | 10 +-
net/netfilter/ipvs/ip_vs_core.c | 6 +
net/netfilter/nf_conntrack_core.c | 6 +-
net/netfilter/nf_conntrack_netlink.c | 3 +-
net/netfilter/nf_conntrack_timeout.c | 27 +-
net/netfilter/nf_flow_table_core.c | 12 +-
net/netfilter/nf_flow_table_offload.c | 7 +-
net/netfilter/nf_tables_api.c | 59 +-
net/netfilter/nfnetlink_cttimeout.c | 114 +-
net/netfilter/nfnetlink_queue.c | 8 +-
net/netfilter/nft_chain_filter.c | 50 +-
net/netfilter/nft_ct.c | 7 +-
net/netfilter/nft_nat.c | 2 +-
net/netfilter/nft_synproxy.c | 3 +-
net/netfilter/xt_CT.c | 2 +-
net/netlink/genetlink.c | 29 +-
net/nfc/core.c | 15 +-
net/nfc/digital_dep.c | 8 +-
net/nfc/llcp.h | 1 +
net/nfc/llcp_commands.c | 2 +-
net/nfc/llcp_core.c | 173 +-
net/nfc/llcp_sock.c | 67 +-
net/nfc/nci/core.c | 10 +-
net/nfc/netlink.c | 7 +-
net/nfc/nfc.h | 3 +-
net/openvswitch/conntrack.c | 39 +-
net/packet/af_packet.c | 108 +-
net/packet/internal.h | 2 +-
net/rds/ib_cm.c | 2 +-
net/rds/ib_frmr.c | 11 +-
net/rose/af_rose.c | 49 +-
net/rose/rose_in.c | 6 +
net/rose/rose_loopback.c | 61 +-
net/rose/rose_timer.c | 87 +-
net/sched/act_api.c | 13 +-
net/sched/act_ct.c | 41 +-
net/sched/act_gate.c | 30 +-
net/sched/cls_u32.c | 12 +-
net/sched/sch_hfsc.c | 22 +
net/sched/sch_hhf.c | 9 +-
net/sched/sch_teql.c | 7 +-
net/sctp/associola.c | 15 +-
net/sctp/input.c | 7 +-
net/sctp/ipv6.c | 8 +-
net/sctp/sm_sideeffect.c | 37 +-
net/sctp/sm_statefuns.c | 2 +
net/smc/smc.h | 6 +-
net/smc/smc_clc.h | 2 +-
net/smc/smc_core.c | 4 +-
net/smc/smc_core.h | 4 +-
net/smc/smc_ib.c | 10 +-
net/tipc/group.c | 4 +-
net/tipc/monitor.c | 3 +-
net/tls/tls_sw.c | 6 +-
net/wireless/chan.c | 389 ++---
net/wireless/core.c | 2 +
net/wireless/lib80211_crypt_tkip.c | 13 +-
net/wireless/nl80211.c | 60 +-
net/wireless/scan.c | 22 +-
net/wireless/util.c | 68 +-
net/xdp/xskmap.c | 2 +-
net/xfrm/espintcp.c | 6 +-
net/xfrm/xfrm_input.c | 63 +-
net/xfrm/xfrm_state.c | 9 +-
net/xfrm/xfrm_user.c | 37 +-
security/ipe/eval.c | 12 +-
security/ipe/eval.h | 2 +-
security/ipe/fs.c | 4 -
security/ipe/hooks.c | 22 +-
security/ipe/policy_fs.c | 4 +
security/keys/encrypted-keys/encrypted.c | 20 +-
security/keys/gc.c | 4 +-
security/keys/request_key_auth.c | 12 +-
security/keys/trusted-keys/trusted_tpm2.c | 12 +-
security/landlock/fs.c | 18 +-
security/landlock/net.c | 14 +
security/selinux/avc.c | 5 +-
security/selinux/hooks.c | 158 +-
security/selinux/include/objsec.h | 10 +-
sound/core/init.c | 3 +-
sound/core/pcm_timer.c | 7 +-
sound/hda/ext/hdac_ext_stream.c | 4 +-
sound/pci/hda/hda_controller.c | 2 +-
sound/pci/hda/patch_realtek.c | 9 +
sound/soc/codecs/aw88261.c | 30 +-
sound/soc/codecs/aw88261.h | 6 -
sound/soc/codecs/hdmi-codec.c | 6 +-
sound/soc/codecs/rt712-sdca-dmic.c | 14 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
sound/soc/soc-pcm.c | 18 +-
sound/soc/tegra/tegra210_mixer.c | 10 +-
sound/soc/ux500/ux500_msp_i2s.h | 4 +-
sound/usb/6fire/chip.c | 40 +-
sound/usb/6fire/comm.c | 42 +-
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 64 +-
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 221 +--
sound/usb/6fire/pcm.h | 5 +-
sound/usb/bcd2000/bcd2000.c | 33 +-
sound/usb/card.h | 3 +-
sound/usb/endpoint.c | 16 +-
sound/virtio/virtio_card.c | 4 +-
tools/bootconfig/main.c | 32 +-
tools/lib/bpf/libbpf.c | 7 +
tools/lib/bpf/relo_core.c | 58 +-
tools/perf/tests/shell/stat_bpf_counters.sh | 2 +-
.../selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
.../testing/selftests/bpf/prog_tests/linked_list.c | 4 +-
tools/testing/selftests/bpf/progs/bpf_iter_tcp4.c | 4 +-
tools/testing/selftests/bpf/progs/bpf_iter_tcp6.c | 4 +-
tools/testing/selftests/cgroup/cgroup_util.c | 82 +-
tools/testing/selftests/cgroup/cgroup_util.h | 8 +-
tools/testing/selftests/cgroup/test_memcontrol.c | 78 +
.../ftrace/test.d/kprobe/kprobe_non_uniq_symbol.tc | 2 +-
tools/testing/selftests/landlock/fs_test.c | 1679 +++++++++++++++++++-
tools/testing/selftests/landlock/net_test.c | 169 +-
tools/testing/selftests/mm/memfd_secret.c | 30 +-
tools/testing/selftests/nci/nci_dev.c | 45 +-
virt/kvm/kvm_main.c | 30 +-
875 files changed, 14469 insertions(+), 7651 deletions(-)
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 001/877] Revert "hwmon: (emc1403) Drop hysteresis for low limit temperature"
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 002/877] Revert "hwmon: (emc1403) Rely on subsystem locking" Greg Kroah-Hartman
` (883 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 5cc075ffa1c986474c1f56ba6f869dcc41a363d4.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/hwmon/emc1403.rst | 8 ++++----
drivers/hwmon/emc1403.c | 27 ++++++++++++++++-----------
2 files changed, 20 insertions(+), 15 deletions(-)
diff --git a/Documentation/hwmon/emc1403.rst b/Documentation/hwmon/emc1403.rst
index ebf2435a76a62..57f833b1a800e 100644
--- a/Documentation/hwmon/emc1403.rst
+++ b/Documentation/hwmon/emc1403.rst
@@ -71,10 +71,10 @@ and EMC14x8 support eight sensors (one internal, seven external).
The chips implement three limits for each sensor: low (tempX_min), high
(tempX_max) and critical (tempX_crit.) The chips also implement an
-hysteresis mechanism which applies to high and critical limits. The relative
-difference is stored in a single register on the chip, which means that the
-relative difference between the limit and its hysteresis is always the same
-for high and critical limits.
+hysteresis mechanism which applies to all limits. The relative difference
+is stored in a single register on the chip, which means that the relative
+difference between the limit and its hysteresis is always the same for
+all three limits.
This implementation detail implies the following:
diff --git a/drivers/hwmon/emc1403.c b/drivers/hwmon/emc1403.c
index 39f69adb88c25..ccce948a4306e 100644
--- a/drivers/hwmon/emc1403.c
+++ b/drivers/hwmon/emc1403.c
@@ -305,9 +305,10 @@ static int emc1403_get_hyst(struct thermal_data *data, int channel,
ret = regmap_read(data->regmap, 0x21, &hyst);
if (ret < 0)
return ret;
-
- *val = limit - hyst * 1000;
-
+ if (map == temp_min)
+ *val = limit + hyst * 1000;
+ else
+ *val = limit - hyst * 1000;
return 0;
}
@@ -323,6 +324,9 @@ static int emc1403_temp_read(struct thermal_data *data, u32 attr, int channel, l
case hwmon_temp_input:
ret = emc1403_get_temp(data, channel, ema1403_temp_map[attr], val);
break;
+ case hwmon_temp_min_hyst:
+ ret = emc1403_get_hyst(data, channel, temp_min, val);
+ break;
case hwmon_temp_max_hyst:
ret = emc1403_get_hyst(data, channel, temp_max, val);
break;
@@ -544,6 +548,7 @@ static umode_t emc1403_temp_is_visible(const void *_data, u32 attr, int channel)
case hwmon_temp_max_alarm:
case hwmon_temp_crit_alarm:
case hwmon_temp_fault:
+ case hwmon_temp_min_hyst:
case hwmon_temp_max_hyst:
return 0444;
case hwmon_temp_min:
@@ -586,35 +591,35 @@ static const struct hwmon_channel_info * const emc1403_info[] = {
HWMON_CHANNEL_INFO(chip, HWMON_C_UPDATE_INTERVAL),
HWMON_CHANNEL_INFO(temp,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT,
HWMON_T_INPUT | HWMON_T_MIN | HWMON_T_MAX |
- HWMON_T_CRIT | HWMON_T_MAX_HYST |
+ HWMON_T_CRIT | HWMON_T_MIN_HYST | HWMON_T_MAX_HYST |
HWMON_T_CRIT_HYST | HWMON_T_MIN_ALARM |
HWMON_T_MAX_ALARM | HWMON_T_CRIT_ALARM | HWMON_T_FAULT
),
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 002/877] Revert "hwmon: (emc1403) Rely on subsystem locking"
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 001/877] Revert "hwmon: (emc1403) Drop hysteresis for low limit temperature" Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 003/877] landlock: Fix TCP Fast Open connection bypass Greg Kroah-Hartman
` (882 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit 52dfb8be29d9918c40b512f3d65529f88304afe4.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/emc1403.c | 46 ++++++++++++++++++++++++++++++++---------
1 file changed, 36 insertions(+), 10 deletions(-)
diff --git a/drivers/hwmon/emc1403.c b/drivers/hwmon/emc1403.c
index ccce948a4306e..eca33220d34a0 100644
--- a/drivers/hwmon/emc1403.c
+++ b/drivers/hwmon/emc1403.c
@@ -17,6 +17,7 @@
#include <linux/hwmon-sysfs.h>
#include <linux/err.h>
#include <linux/sysfs.h>
+#include <linux/mutex.h>
#include <linux/regmap.h>
#include <linux/util_macros.h>
@@ -29,6 +30,7 @@ enum emc1403_chip { emc1402, emc1403, emc1404, emc1428 };
struct thermal_data {
enum emc1403_chip chip;
struct regmap *regmap;
+ struct mutex mutex;
};
static ssize_t power_state_show(struct device *dev, struct device_attribute *attr, char *buf)
@@ -266,8 +268,8 @@ static s8 emc1403_temp_regs_low[][4] = {
},
};
-static int emc1403_get_temp(struct thermal_data *data, int channel,
- enum emc1403_reg_map map, long *val)
+static int __emc1403_get_temp(struct thermal_data *data, int channel,
+ enum emc1403_reg_map map, long *val)
{
unsigned int regvalh;
unsigned int regvall = 0;
@@ -293,23 +295,38 @@ static int emc1403_get_temp(struct thermal_data *data, int channel,
return 0;
}
+static int emc1403_get_temp(struct thermal_data *data, int channel,
+ enum emc1403_reg_map map, long *val)
+{
+ int ret;
+
+ mutex_lock(&data->mutex);
+ ret = __emc1403_get_temp(data, channel, map, val);
+ mutex_unlock(&data->mutex);
+
+ return ret;
+}
+
static int emc1403_get_hyst(struct thermal_data *data, int channel,
enum emc1403_reg_map map, long *val)
{
int hyst, ret;
long limit;
- ret = emc1403_get_temp(data, channel, map, &limit);
+ mutex_lock(&data->mutex);
+ ret = __emc1403_get_temp(data, channel, map, &limit);
if (ret < 0)
- return ret;
+ goto unlock;
ret = regmap_read(data->regmap, 0x21, &hyst);
if (ret < 0)
- return ret;
+ goto unlock;
if (map == temp_min)
*val = limit + hyst * 1000;
else
*val = limit - hyst * 1000;
- return 0;
+unlock:
+ mutex_unlock(&data->mutex);
+ return ret;
}
static int emc1403_temp_read(struct thermal_data *data, u32 attr, int channel, long *val)
@@ -434,16 +451,20 @@ static int emc1403_set_hyst(struct thermal_data *data, long val)
else
val = clamp_val(val, 0, 255000);
- ret = emc1403_get_temp(data, 0, temp_crit, &limit);
+ mutex_lock(&data->mutex);
+ ret = __emc1403_get_temp(data, 0, temp_crit, &limit);
if (ret < 0)
- return ret;
+ goto unlock;
hyst = limit - val;
if (data->chip == emc1428)
hyst = clamp_val(DIV_ROUND_CLOSEST(hyst, 1000), 0, 127);
else
hyst = clamp_val(DIV_ROUND_CLOSEST(hyst, 1000), 0, 255);
- return regmap_write(data->regmap, 0x21, hyst);
+ ret = regmap_write(data->regmap, 0x21, hyst);
+unlock:
+ mutex_unlock(&data->mutex);
+ return ret;
}
static int emc1403_set_temp(struct thermal_data *data, int channel,
@@ -457,6 +478,7 @@ static int emc1403_set_temp(struct thermal_data *data, int channel,
regh = emc1403_temp_regs[channel][map];
regl = emc1403_temp_regs_low[channel][map];
+ mutex_lock(&data->mutex);
if (regl >= 0) {
if (data->chip == emc1428)
val = clamp_val(val, -128000, 127875);
@@ -465,7 +487,7 @@ static int emc1403_set_temp(struct thermal_data *data, int channel,
regval = DIV_ROUND_CLOSEST(val, 125);
ret = regmap_write(data->regmap, regh, (regval >> 3) & 0xff);
if (ret < 0)
- return ret;
+ goto unlock;
ret = regmap_write(data->regmap, regl, (regval & 0x07) << 5);
} else {
if (data->chip == emc1428)
@@ -475,6 +497,8 @@ static int emc1403_set_temp(struct thermal_data *data, int channel,
regval = DIV_ROUND_CLOSEST(val, 1000);
ret = regmap_write(data->regmap, regh, regval);
}
+unlock:
+ mutex_unlock(&data->mutex);
return ret;
}
@@ -671,6 +695,8 @@ static int emc1403_probe(struct i2c_client *client)
if (IS_ERR(data->regmap))
return PTR_ERR(data->regmap);
+ mutex_init(&data->mutex);
+
hwmon_dev = devm_hwmon_device_register_with_info(&client->dev,
client->name, data,
&emc1403_chip_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 003/877] landlock: Fix TCP Fast Open connection bypass
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 001/877] Revert "hwmon: (emc1403) Drop hysteresis for low limit temperature" Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 002/877] Revert "hwmon: (emc1403) Rely on subsystem locking" Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 004/877] selftests/landlock: Add test for TCP fast open Greg Kroah-Hartman
` (881 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit 33cb713db0161b54f04fe830e062c9e102c29a04 ]
The documentation of the socket_connect() LSM hook states that it
controls connecting a socket to a remote address. It has not been the
case since the addition of TCP Fast Open (RFC 7413) support, which
allows opening a TCP connection (thus, setting a socket's destination
address) via the MSG_FASTOPEN flag passed to
sendto()/sendmsg()/sendmmsg(). The problem then got duplicated into
MPTCP.
Landlock did not take it into account when its TCP support was added,
leaving a bypass of TCP connect policy.
Ideally a call to the LSM hook would be added in the fastopen code path,
in order to fix this generically. But connect() hooks are designed to
run with the socket locked, unlike sendmsg() hooks.
Closes: https://github.com/landlock-lsm/linux/issues/41
Fixes: fff69fb03dde ("landlock: Support network rules with TCP bind and connect")
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://patch.msgid.link/20260701214628.33319-1-matthieu@buffet.re
Cc: stable@vger.kernel.org
[mic: Wrap commit message]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the TCP Fast Open check to the TCP-only network
hooks]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/landlock/net.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/security/landlock/net.c b/security/landlock/net.c
index 9c9608924fbdb..c5c26e9029924 100644
--- a/security/landlock/net.c
+++ b/security/landlock/net.c
@@ -193,9 +193,23 @@ static int hook_socket_connect(struct socket *const sock,
LANDLOCK_ACCESS_NET_CONNECT_TCP);
}
+static int hook_socket_sendmsg(struct socket *const sock,
+ struct msghdr *const msg, const int size)
+{
+ struct sockaddr *const address = msg->msg_name;
+
+ if ((msg->msg_flags & MSG_FASTOPEN) && address)
+ return current_check_access_socket(
+ sock, address, msg->msg_namelen,
+ LANDLOCK_ACCESS_NET_CONNECT_TCP);
+
+ return 0;
+}
+
static struct security_hook_list landlock_hooks[] __ro_after_init = {
LSM_HOOK_INIT(socket_bind, hook_socket_bind),
LSM_HOOK_INIT(socket_connect, hook_socket_connect),
+ LSM_HOOK_INIT(socket_sendmsg, hook_socket_sendmsg),
};
__init void landlock_add_net_hooks(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 004/877] selftests/landlock: Add test for TCP fast open
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 003/877] landlock: Fix TCP Fast Open connection bypass Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 005/877] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test Greg Kroah-Hartman
` (880 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit f4b30e0b1d488e7ffd8ea28d1365b9ba8e551edb ]
Enforce that TCP Fast Open is controlled by
LANDLOCK_ACCESS_NET_CONNECT_TCP. Semantics of connect() and
sendmsg(MSG_FASTOPEN) should be identical from Landlock's perspective.
Also enforce error code consistency, since UDP sockets ignore the
MSG_FASTOPEN flag while Unix sockets reject it.
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://patch.msgid.link/20260701214628.33319-2-matthieu@buffet.re
Cc: stable@vger.kernel.org
[mic: Fix formatting]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the test to the older network fixture and add the
required send helper]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/net_test.c | 155 ++++++++++++++++++++
1 file changed, 155 insertions(+)
diff --git a/tools/testing/selftests/landlock/net_test.c b/tools/testing/selftests/landlock/net_test.c
index 897131bc8a13b..63b1e655afb25 100644
--- a/tools/testing/selftests/landlock/net_test.c
+++ b/tools/testing/selftests/landlock/net_test.c
@@ -257,6 +257,64 @@ static int connect_variant(const int sock_fd,
return connect_variant_addrlen(sock_fd, srv, get_addrlen(srv, false));
}
+static int sendto_variant_addrlen(const int sock_fd,
+ const struct service_fixture *const srv,
+ const socklen_t addrlen, void *buf,
+ size_t len, size_t flags)
+{
+ const struct sockaddr *dst = NULL;
+ ssize_t ret;
+
+ /*
+ * We never want our processes to be killed by SIGPIPE: we check return
+ * codes and errno, so that we have actual error messages.
+ */
+ flags |= MSG_NOSIGNAL;
+
+ if (srv != NULL) {
+ switch (srv->protocol.domain) {
+ case AF_UNSPEC:
+ case AF_INET:
+ dst = (const struct sockaddr *)&srv->ipv4_addr;
+ break;
+
+ case AF_INET6:
+ dst = (const struct sockaddr *)&srv->ipv6_addr;
+ break;
+
+ case AF_UNIX:
+ dst = (const struct sockaddr *)&srv->unix_addr;
+ break;
+
+ default:
+ errno = EAFNOSUPPORT;
+ return -errno;
+ }
+ }
+
+ ret = sendto(sock_fd, buf, len, flags, dst, addrlen);
+ if (ret < 0)
+ return -errno;
+
+ /* errno is not set in cases of partial writes. */
+ if (ret != len)
+ return -EINTR;
+
+ return 0;
+}
+
+static int sendto_variant(const int sock_fd,
+ const struct service_fixture *const srv, void *buf,
+ size_t len, size_t flags)
+{
+ socklen_t addrlen = 0;
+
+ if (srv != NULL)
+ addrlen = get_addrlen(srv, false);
+
+ return sendto_variant_addrlen(sock_fd, srv, addrlen, buf, len, flags);
+}
+
FIXTURE(protocol)
{
struct service_fixture srv0, srv1, srv2, unspec_any0, unspec_srv0;
@@ -937,6 +995,103 @@ TEST_F(protocol, connect_unspec)
EXPECT_EQ(0, close(bind_fd));
}
+TEST_F(protocol, tcp_fastopen)
+{
+ const bool restricted = variant->sandbox == TCP_SANDBOX &&
+ variant->prot.type == SOCK_STREAM &&
+ (variant->prot.protocol == IPPROTO_TCP ||
+ variant->prot.protocol == IPPROTO_IP) &&
+ (variant->prot.domain == AF_INET ||
+ variant->prot.domain == AF_INET6);
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_net = LANDLOCK_ACCESS_NET_CONNECT_TCP,
+ };
+ int bind_fd, client_fd, status;
+ char buf;
+ pid_t child;
+
+ bind_fd = socket_variant(&self->srv0);
+ ASSERT_LE(0, bind_fd);
+ EXPECT_EQ(0, bind_variant(bind_fd, &self->srv0));
+ if (self->srv0.protocol.type == SOCK_STREAM)
+ EXPECT_EQ(0, listen(bind_fd, backlog));
+
+ child = fork();
+ ASSERT_LE(0, child);
+ if (child == 0) {
+ int connect_fd, ret;
+
+ /* Closes listening socket for the child. */
+ EXPECT_EQ(0, close(bind_fd));
+
+ connect_fd = socket_variant(&self->srv0);
+ ASSERT_LE(0, connect_fd);
+
+ if (variant->sandbox == TCP_SANDBOX) {
+ const int ruleset_fd = landlock_create_ruleset(
+ &ruleset_attr, sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+ }
+
+ /* Fast Open with no address. */
+ ret = sendto_variant(connect_fd, NULL, NULL, 0, MSG_FASTOPEN);
+ if (self->srv0.protocol.domain == AF_UNIX) {
+ EXPECT_EQ(-ENOTCONN, ret);
+ } else if (self->srv0.protocol.type == SOCK_DGRAM) {
+ EXPECT_EQ(-EDESTADDRREQ, ret);
+ } else {
+ EXPECT_EQ(-EINVAL, ret);
+ }
+
+ /* Fast Open to a denied address. */
+ ret = sendto_variant(connect_fd, &self->srv0, "A", 1,
+ MSG_FASTOPEN);
+ if (restricted) {
+ EXPECT_EQ(-EACCES, ret);
+ } else if (self->srv0.protocol.domain == AF_UNIX &&
+ self->srv0.protocol.type == SOCK_STREAM) {
+ EXPECT_EQ(-EOPNOTSUPP, ret);
+ } else {
+ EXPECT_EQ(0, ret);
+ }
+
+ EXPECT_EQ(0, close(connect_fd));
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ client_fd = bind_fd;
+ if (!restricted && self->srv0.protocol.type == SOCK_STREAM &&
+ self->srv0.protocol.domain != AF_UNIX) {
+ client_fd = accept(bind_fd, NULL, 0);
+ ASSERT_LE(0, client_fd);
+ }
+
+ if (restricted) {
+ EXPECT_EQ(-1, read(client_fd, &buf, 1));
+ EXPECT_EQ(ENOTCONN, errno);
+ } else if (self->srv0.protocol.domain == AF_UNIX &&
+ self->srv0.protocol.type == SOCK_STREAM) {
+ EXPECT_EQ(-1, read(client_fd, &buf, 1));
+ EXPECT_EQ(EINVAL, errno);
+ } else {
+ EXPECT_EQ(1, read(client_fd, &buf, 1));
+ EXPECT_EQ('A', buf);
+ }
+
+ EXPECT_EQ(child, waitpid(child, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ if (client_fd != bind_fd)
+ EXPECT_LE(0, close(client_fd));
+
+ EXPECT_EQ(0, close(bind_fd));
+}
+
FIXTURE(ipv4)
{
struct service_fixture srv0, srv1;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 005/877] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 004/877] selftests/landlock: Add test for TCP fast open Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 006/877] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
` (879 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit 6685201ebfacff0c889bcd569181fa6e8af5575e ]
connect_variant(unspec_any0) is called twice. Both calls end
up in connect_variant_addrlen() with an address length of
get_addrlen(minimal=false).
However, the connect() syscall and its variants (e.g.
iouring/compat) accept much shorter addresses of 4 bytes
and that behaviour was not tested.
Replace one of these calls with one using a minimal address
length (just a bare sa_family=AF_UNSPEC field with no actual
address). Also add a call using a truncated address for good
measure.
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://lore.kernel.org/r/20251027190726.626244-3-matthieu@buffet.re
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/net_test.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/landlock/net_test.c b/tools/testing/selftests/landlock/net_test.c
index 63b1e655afb25..0be69fcc4efbe 100644
--- a/tools/testing/selftests/landlock/net_test.c
+++ b/tools/testing/selftests/landlock/net_test.c
@@ -963,7 +963,19 @@ TEST_F(protocol, connect_unspec)
EXPECT_EQ(0, close(ruleset_fd));
}
- ret = connect_variant(connect_fd, &self->unspec_any0);
+ /* Try to re-disconnect with a truncated address struct. */
+ EXPECT_EQ(-EINVAL,
+ connect_variant_addrlen(
+ connect_fd, &self->unspec_any0,
+ get_addrlen(&self->unspec_any0, true) - 1));
+
+ /*
+ * Re-disconnect, with a minimal sockaddr struct (just a
+ * bare af_family=AF_UNSPEC field).
+ */
+ ret = connect_variant_addrlen(connect_fd, &self->unspec_any0,
+ get_addrlen(&self->unspec_any0,
+ true));
if (self->srv0.protocol.domain == AF_UNIX &&
self->srv0.protocol.type == SOCK_STREAM) {
EXPECT_EQ(-EINVAL, ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 006/877] selftests/landlock: Add tests for access through disconnected paths
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 005/877] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 007/877] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
` (878 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tingmao Wang <m@maowtm.org>
[ Upstream commit a18ee3f31fd714173a62515d049d77e76ab55649 ]
This adds tests for the edge case discussed in [1], with specific ones
for rename and link operations when the operands are through
disconnected paths, as that go through a separate code path in Landlock.
This has resulted in a warning, due to collect_domain_accesses() not
expecting to reach a different root from path->mnt:
# RUN layout1_bind.path_disconnected ...
# OK layout1_bind.path_disconnected
ok 96 layout1_bind.path_disconnected
# RUN layout1_bind.path_disconnected_rename ...
[..] ------------[ cut here ]------------
[..] WARNING: CPU: 3 PID: 385 at security/landlock/fs.c:1065 collect_domain_accesses
[..] ...
[..] RIP: 0010:collect_domain_accesses (security/landlock/fs.c:1065 (discriminator 2) security/landlock/fs.c:1031 (discriminator 2))
[..] current_check_refer_path (security/landlock/fs.c:1205)
[..] ...
[..] hook_path_rename (security/landlock/fs.c:1526)
[..] security_path_rename (security/security.c:2026 (discriminator 1))
[..] do_renameat2 (fs/namei.c:5264)
# OK layout1_bind.path_disconnected_rename
ok 97 layout1_bind.path_disconnected_rename
Move the const char definitions a bit above so that we can use the path
for s4d1 in cleanup code.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Link: https://lore.kernel.org/r/027d5190-b37a-40a8-84e9-4ccbc352bcdf@maowtm.org [1]
Signed-off-by: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-4-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 423 ++++++++++++++++++++-
1 file changed, 415 insertions(+), 8 deletions(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index c781014e6a5c6..1109d0e932336 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -4363,6 +4363,18 @@ TEST_F_FORK(ioctl, handle_file_access_file)
FIXTURE(layout1_bind) {};
/* clang-format on */
+static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
+static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
+
+/* Move targets for disconnected path tests. */
+static const char dir_s4d1[] = TMP_DIR "/s4d1";
+static const char file1_s4d1[] = TMP_DIR "/s4d1/f1";
+static const char file2_s4d1[] = TMP_DIR "/s4d1/f2";
+static const char dir_s4d2[] = TMP_DIR "/s4d1/s4d2";
+static const char file1_s4d2[] = TMP_DIR "/s4d1/s4d2/f1";
+static const char file1_name[] = "f1";
+static const char file2_name[] = "f2";
+
FIXTURE_SETUP(layout1_bind)
{
prepare_layout(_metadata);
@@ -4378,14 +4390,14 @@ FIXTURE_TEARDOWN_PARENT(layout1_bind)
{
/* umount(dir_s2d2)) is handled by namespace lifetime. */
+ remove_path(file1_s4d1);
+ remove_path(file2_s4d1);
+
remove_layout1(_metadata);
cleanup_layout(_metadata);
}
-static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
-static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
-
/*
* layout1_bind hierarchy:
*
@@ -4396,20 +4408,25 @@ static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
* │ └── s1d2
* │ ├── f1
* │ ├── f2
- * │ └── s1d3
+ * │ └── s1d3 [disconnected by path_disconnected]
* │ ├── f1
* │ └── f2
* ├── s2d1
* │ ├── f1
- * │ └── s2d2
+ * │ └── s2d2 [bind mount from s1d2]
* │ ├── f1
* │ ├── f2
* │ └── s1d3
* │ ├── f1
* │ └── f2
- * └── s3d1
- * └── s3d2
- * └── s3d3
+ * ├── s3d1
+ * │ └── s3d2
+ * │ └── s3d3
+ * └── s4d1 [renamed from s1d3 by path_disconnected]
+ * ├── f1
+ * ├── f2
+ * └── s4d2
+ * └── f1
*/
TEST_F_FORK(layout1_bind, no_restriction)
@@ -4608,6 +4625,396 @@ TEST_F_FORK(layout1_bind, reparent_cross_mount)
ASSERT_EQ(0, rename(bind_file1_s1d3, file1_s2d2));
}
+/*
+ * Make sure access to file through a disconnected path works as expected.
+ * This test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected)
+{
+ const struct rule layer1_allow_all[] = {
+ {
+ .path = TMP_DIR,
+ .access = ACCESS_ALL,
+ },
+ {},
+ };
+ const struct rule layer2_allow_just_f1[] = {
+ {
+ .path = file1_s1d3,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ const struct rule layer3_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+
+ /* Landlock should not deny access just because it is disconnected. */
+ int ruleset_fd_l1 =
+ create_ruleset(_metadata, ACCESS_ALL, layer1_allow_all);
+
+ /* Creates the new ruleset now before we move the dir containing the file. */
+ int ruleset_fd_l2 =
+ create_ruleset(_metadata, ACCESS_RW, layer2_allow_just_f1);
+ int ruleset_fd_l3 =
+ create_ruleset(_metadata, ACCESS_RW, layer3_only_s1d2);
+ int bind_s1d3_fd;
+
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+ ASSERT_LE(0, ruleset_fd_l3);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+
+ /* Tests access is possible before we move. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* Makes it disconnected. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Tests that access is still possible. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ /*
+ * Tests that ".." is not possible (not because of Landlock, but just
+ * because it's disconnected).
+ */
+ EXPECT_EQ(ENOENT,
+ test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* This should still work with a narrower rule. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to this file, even if it is no longer visible in
+ * its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ enforce_ruleset(_metadata, ruleset_fd_l3);
+ EXPECT_EQ(0, close(ruleset_fd_l3));
+
+ EXPECT_EQ(EACCES, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to the original mount point, even if it is no
+ * longer visible in its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+}
+
+/*
+ * Test that renameat with disconnected paths works under Landlock. This test
+ * moves s1d3 to s4d2, so that we can have a rule allowing refers on the move
+ * target's immediate parent.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_rename)
+{
+ const struct rule layer1[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {}
+ };
+
+ /* This layer only handles LANDLOCK_ACCESS_FS_READ_FILE. */
+ const struct rule layer2_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ int ruleset_fd_l1, ruleset_fd_l2;
+ pid_t child_pid;
+ int bind_s1d3_fd, status;
+
+ ASSERT_EQ(0, mkdir(dir_s4d1, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d1, strerror(errno));
+ }
+ ruleset_fd_l1 = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ruleset_fd_l2 = create_ruleset(_metadata, LANDLOCK_ACCESS_FS_READ_FILE,
+ layer2_only_s1d2);
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Tests ENOENT priority over EACCES for disconnected directory. */
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(ENOENT, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+
+ /*
+ * The file is no longer under s1d2 but we should still be able to access it
+ * with layer 2 because its mount point is evaluated as the first valid
+ * directory because it was initially a parent. Do a fork to test this so
+ * we don't prevent ourselves from renaming it back later.
+ */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open(file1_s4d2, O_RDONLY));
+
+ /*
+ * Tests that access widening checks indeed prevents us from renaming it
+ * back.
+ */
+ EXPECT_EQ(-1, rename(dir_s4d2, dir_s1d3));
+ EXPECT_EQ(EXDEV, errno);
+
+ /*
+ * Including through the now disconnected fd (but it should return
+ * EXDEV).
+ */
+ EXPECT_EQ(-1, renameat(bind_s1d3_fd, file1_name, AT_FDCWD,
+ file1_s2d2));
+ EXPECT_EQ(EXDEV, errno);
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d1, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Now checks that we can access it under l2. */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ /*
+ * Also test that we can rename via a disconnected path. We move the
+ * dir back to the disconnected place first, then we rename file1 to
+ * file2 through our dir fd.
+ */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ ASSERT_EQ(0,
+ renameat(bind_s1d3_fd, file1_name, bind_s1d3_fd, file2_name))
+ {
+ TH_LOG("Failed to rename %s to %s within disconnected %s: %s",
+ file1_name, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ ASSERT_EQ(0, renameat(bind_s1d3_fd, file2_name, AT_FDCWD, file1_s2d2))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file2_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d2, O_RDONLY));
+
+ /* Move it back using the disconnected path as the target. */
+ ASSERT_EQ(0, renameat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file1_name))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file1_s1d2, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Now make it connected again. */
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d2, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Checks again that we can access it under l2. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+}
+
+/*
+ * Test that linkat(2) with disconnected paths works under Landlock. This
+ * test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_link)
+{
+ /* Ruleset to be applied after renaming s1d3 to s4d1. */
+ const struct rule layer1[] = {
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {
+ .path = dir_s2d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {}
+ };
+ int ruleset_fd, bind_s1d3_fd;
+
+ /* Removes unneeded files created by layout1, otherwise it will EEXIST. */
+ ASSERT_EQ(0, unlink(file1_s1d2));
+ ASSERT_EQ(0, unlink(file2_s1d3));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Disconnects bind_s1d3_fd. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Need this later to test different parent link. */
+ ASSERT_EQ(0, mkdir(dir_s4d2, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d2, strerror(errno));
+ }
+
+ ruleset_fd = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ASSERT_LE(0, ruleset_fd);
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ /* From disconnected to connected. */
+ ASSERT_EQ(0, linkat(bind_s1d3_fd, file1_name, AT_FDCWD, file1_s2d2, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Tests that we can access via the new link... */
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s2d2,
+ strerror(errno));
+ }
+
+ /* ...as well as the old one. */
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open original %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+
+ /* From connected to disconnected. */
+ ASSERT_EQ(0, unlink(file1_s4d1));
+ ASSERT_EQ(0, linkat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file2_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_s2d2, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file2_s4d1, O_RDONLY));
+ ASSERT_EQ(0, unlink(file1_s2d2));
+
+ /* From disconnected to disconnected (same parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file2_name, bind_s1d3_fd, file1_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file2_name, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through newly created link under disconnected path: %s",
+ file1_name, strerror(errno));
+ }
+ ASSERT_EQ(0, unlink(file2_s4d1));
+
+ /* From disconnected to disconnected (different parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file1_name, bind_s1d3_fd, "s4d2/f1", 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file1_name, "s4d2/f1", bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s after link: %s", file1_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "s4d2/f1", O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through disconnected path after link: %s",
+ "s4d2/f1", strerror(errno));
+ }
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 007/877] selftests/landlock: Add disconnected leafs and branch test suites
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 006/877] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 008/877] s390/boot: Add sized_strscpy() to enable strscpy() usage Greg Kroah-Hartman
` (877 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 54f9baf537b0a091adad860ec92e3e18e0a0754c ]
Test disconnected directories with two test suites
(layout4_disconnected_leafs and layout5_disconnected_branch) and 43
variants to cover the main corner cases.
These tests are complementary to the previous commit.
Add test_renameat() and test_exchangeat() helpers.
Test coverage for security/landlock is 92.1% of 1927 lines according to
LLVM 20.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Cc: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-5-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 1051 ++++++++++++++++++++
1 file changed, 1051 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 1109d0e932336..732ba5a92df56 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -2109,6 +2109,22 @@ static int test_exchange(const char *const oldpath, const char *const newpath)
return 0;
}
+static int test_renameat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, 0))
+ return errno;
+ return 0;
+}
+
+static int test_exchangeat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, RENAME_EXCHANGE))
+ return errno;
+ return 0;
+}
+
TEST_F_FORK(layout1, rename_file)
{
const struct rule rules[] = {
@@ -5015,6 +5031,1041 @@ TEST_F_FORK(layout1_bind, path_disconnected_link)
}
}
+/*
+ * layout4_disconnected_leafs with bind mount and renames:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the bind mount]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [bind mount of s1d2]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [opened FD, now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [opened FD, now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s1d41 [renamed here]
+ * │ ├── f1
+ * │ └── f2
+ * └── s4d1
+ * └── s1d42 [renamed here]
+ * ├── f3
+ * └── f4
+ */
+/* clang-format off */
+FIXTURE(layout4_disconnected_leafs) {
+ int s2d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout4_disconnected_leafs)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2");
+ create_directory(_metadata, TMP_DIR "/s3d1");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d2_fd =
+ open(TMP_DIR "/s2d1/s2d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2", NULL,
+ MS_BIND, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN_PARENT(layout4_disconnected_leafs)
+{
+ /* umount(TMP_DIR "/s2d1") is handled by namespace lifetime. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s3d1/s1d41/f1");
+ remove_path(TMP_DIR "/s3d1/s1d41/f2");
+ remove_path(TMP_DIR "/s4d1/s1d42/f1");
+ remove_path(TMP_DIR "/s4d1/s1d42/f3");
+ remove_path(TMP_DIR "/s4d1/s1d42/f4");
+ remove_path(TMP_DIR "/s4d1/s1d42/f5");
+
+ cleanup_layout(_metadata);
+}
+
+FIXTURE_VARIANT(layout4_disconnected_leafs)
+{
+ /*
+ * Parent of the bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ /*
+ * Source of bind mount (to s2d2). It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d2;
+ /*
+ * Original parent of s1d41. It should always be ignored when testing
+ * against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d31;
+ /*
+ * Original parent of s1d42. It should always be ignored when testing
+ * against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d32;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d41;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d42;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f1;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f2;
+ /*
+ * File in the s1d42 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_f3;
+ /*
+ * Parent of the bind mount destination. It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d1;
+ /*
+ * Directory covered by the bind mount. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d2;
+ /*
+ * New parent of the renamed s1d41. It should always be ignored when
+ * testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s3d1;
+ /*
+ * New parent of the renamed s1d42. It should always be ignored when
+ * testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d41]/f1, O_RDONLY). */
+ const int expected_read_result;
+ /* Expected result of the call to renameat([fd:s1d41]/f1, [fd:s1d42]/f1). */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d41]/f2, [fd:s1d42]/f3,
+ * RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /* Expected result of the call to renameat([fd:s1d42]/f4, [fd:s1d42]/f5). */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d1_mount_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d31_s1d32_old_parent) {
+ /* clang-format on */
+ .allowed_s1d31 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d32 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_refer) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_create) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_even) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_mini) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d2_covered_by_mount) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* Tests collect_domain_accesses(). */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs,
+ s3d1_s4d1_disconnected_rename_even){
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, f1_f2_f3) {
+ /* clang-format on */
+ .allowed_f1 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f2 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f3 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+TEST_F_FORK(layout4_disconnected_leafs, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31",
+ .access = variant->allowed_s1d31,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32",
+ .access = variant->allowed_s1d32,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ .access = variant->allowed_s1d41,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ .access = variant->allowed_s1d42,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1",
+ .access = variant->allowed_f1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2",
+ .access = variant->allowed_f2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3",
+ .access = variant->allowed_f3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ /* s2d2_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d41_bind_fd, s1d42_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rule for the covered directory. */
+ if (variant->allowed_s2d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d2_fd,
+ .allowed_access =
+ variant->allowed_s2d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d2_fd));
+
+ s1d41_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d31/s1d41",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d41_bind_fd);
+ s1d42_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d32/s1d42",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d42_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ AT_FDCWD, TMP_DIR "/s3d1/s1d41"));
+ /* Renames to make it accessible through s4d1/s1d42 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ AT_FDCWD, TMP_DIR "/s4d1/s1d42"));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d41_bind_fd, "f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d41_bind_fd, "f1", s1d42_bind_fd, "f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d41_bind_fd, "f2", s1d42_bind_fd, "f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d42_bind_fd, "f4", s1d42_bind_fd, "f5"));
+}
+
+/*
+ * layout5_disconnected_branch before rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * └── s4d1
+ *
+ * After rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * └── s4d1
+ * └── s2d3 [renamed here]
+ * └── s2d4 [first s1d2 bind mount]
+ * └── s1d3
+ * ├── s1d41
+ * │ ├── f1
+ * │ └── f2
+ * └── s1d42
+ * ├── f3
+ * └── f4
+ *
+ * Decision path for access from the s3d1/s3d2/s2d3/s2d4/s1d3 file descriptor:
+ * 1. first bind mount: s1d3 -> s1d2
+ * 2. second bind mount: s2d3
+ * 3. tmp mount: s4d1 -> tmp [disconnected branch]
+ * 4. second bind mount: s2d2
+ * 5. tmp mount: s3d1 -> tmp
+ * 6. parent mounts: [...] -> /
+ *
+ * The s4d1 directory is evaluated even if it is not in the s2d2 mount.
+ */
+
+/* clang-format off */
+FIXTURE(layout5_disconnected_branch) {
+ int s2d4_fd, s3d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout5_disconnected_branch)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2/s2d3/s2d4");
+ create_directory(_metadata, TMP_DIR "/s3d1/s3d2");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d4_fd = open(TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d4_fd);
+
+ self->s3d2_fd =
+ open(TMP_DIR "/s3d1/s3d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s3d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ NULL, MS_BIND, NULL));
+ ASSERT_EQ(0, mount(TMP_DIR "/s2d1/s2d2", TMP_DIR "/s3d1/s3d2", NULL,
+ MS_BIND | MS_REC, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN_PARENT(layout5_disconnected_branch)
+{
+ /* Bind mounts are handled by namespace lifetime. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f5");
+
+ cleanup_layout(_metadata);
+}
+
+FIXTURE_VARIANT(layout5_disconnected_branch)
+{
+ /*
+ * Parent of all files. It should always be enforced when testing against
+ * files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_base;
+ /*
+ * Parent of the first bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ const __u64 allowed_s1d2;
+ const __u64 allowed_s1d3;
+ const __u64 allowed_s2d1;
+ const __u64 allowed_s2d2;
+ const __u64 allowed_s2d3;
+ const __u64 allowed_s2d4;
+ const __u64 allowed_s3d1;
+ const __u64 allowed_s3d2;
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d3]/s1d41/f1, O_RDONLY). */
+ const int expected_read_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f1,
+ * [fd:s1d3]/s1d42/f1).
+ */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f2,
+ * [fd:s1d3]/s1d42/f3, RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d42/f4,
+ * [fd:s1d3]/s1d42/f5).
+ */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d1_mount1_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_refer) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_create) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_rename) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_full) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d1_mount2_src_parent) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_refer) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_create) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_rename) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d4_mount1_dst) {
+ /* clang-format on */
+ .allowed_s2d4 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d2_mount1_dst) {
+ /* clang-format on */
+ .allowed_s3d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_refer) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_create) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_rename) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+TEST_F_FORK(layout5_disconnected_branch, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d3",
+ .access = variant->allowed_s1d3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2",
+ .access = variant->allowed_s2d2,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2/s2d3",
+ .access = variant->allowed_s2d3,
+ },
+ /* s2d4_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ /* s3d2_fd */
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d3_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rules for the covered directories. */
+ if (variant->allowed_s2d4) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d4_fd,
+ .allowed_access =
+ variant->allowed_s2d4,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d4_fd));
+
+ if (variant->allowed_s3d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s3d2_fd,
+ .allowed_access =
+ variant->allowed_s3d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s3d2_fd));
+
+ s1d3_bind_fd = open(TMP_DIR "/s3d1/s3d2/s2d3/s2d4/s1d3",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d3_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s2d1/s2d2/s2d3",
+ AT_FDCWD, TMP_DIR "/s4d1/s2d3"));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d3_bind_fd, "s1d41/f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d41/f1", s1d3_bind_fd,
+ "s1d42/f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d3_bind_fd, "s1d41/f2", s1d3_bind_fd,
+ "s1d42/f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d42/f4", s1d3_bind_fd,
+ "s1d42/f5"));
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 008/877] s390/boot: Add sized_strscpy() to enable strscpy() usage
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 007/877] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 009/877] s390/boot: Avoid IPL parameter append past command line Greg Kroah-Hartman
` (876 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vasily Gorbik, Heiko Carstens,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vasily Gorbik <gor@linux.ibm.com>
[ Upstream commit f271df9d41c216f6189c40fa1cb83839a6117c3e ]
Add a simple sized_strscpy() implementation to allow the use of strscpy()
in the decompressor.
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/boot/string.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/arch/s390/boot/string.c b/arch/s390/boot/string.c
index f6b9b1df48a82..bd68161434a60 100644
--- a/arch/s390/boot/string.c
+++ b/arch/s390/boot/string.c
@@ -29,6 +29,18 @@ int strncmp(const char *cs, const char *ct, size_t count)
return 0;
}
+ssize_t sized_strscpy(char *dst, const char *src, size_t count)
+{
+ size_t len;
+
+ if (count == 0)
+ return -E2BIG;
+ len = strnlen(src, count - 1);
+ memcpy(dst, src, len);
+ dst[len] = '\0';
+ return src[len] ? -E2BIG : len;
+}
+
void *memset64(uint64_t *s, uint64_t v, size_t count)
{
uint64_t *xs = s;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 009/877] s390/boot: Avoid IPL parameter append past command line
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 008/877] s390/boot: Add sized_strscpy() to enable strscpy() usage Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 010/877] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
` (875 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Heiko Carstens, Vasily Gorbik,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vasily Gorbik <gor@linux.ibm.com>
[ Upstream commit d76181dfabdaa720703167393704efacba343442 ]
A command line may occupy all but the terminating byte of
COMMAND_LINE_SIZE. In that case append_ipl_block_parm() passes a zero size
to the IPL parameter conversion helpers and points the destination one
byte past early_command_line. The helpers subtract one from the unsigned
size and write the converted parameter outside the command line buffer.
Convert the IPL parameter in the command line parsing buffer first. A
parameter beginning with '=' can then replace the existing command line
regardless of its length, while other parameters are appended only when
space remains.
Fixes: 5ecb2da660ab ("s390: support command lines longer than 896 bytes")
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/boot/ipl_parm.c | 26 ++++++++++++--------------
1 file changed, 12 insertions(+), 14 deletions(-)
diff --git a/arch/s390/boot/ipl_parm.c b/arch/s390/boot/ipl_parm.c
index 557462e62cd73..6c77afb3b8a11 100644
--- a/arch/s390/boot/ipl_parm.c
+++ b/arch/s390/boot/ipl_parm.c
@@ -21,6 +21,7 @@ struct parmarea parmarea __section(".parmarea") = {
};
char __bootdata(early_command_line)[COMMAND_LINE_SIZE];
+static char command_line_buf[COMMAND_LINE_SIZE];
unsigned int __bootdata_preserved(zlib_dfltcc_support) = ZLIB_DFLTCC_FULL;
struct ipl_parameter_block __bootdata_preserved(ipl_block);
@@ -148,31 +149,29 @@ static size_t ipl_block_get_ascii_scpdata(char *dest, size_t size,
static void append_ipl_block_parm(void)
{
- char *parm, *delim;
- size_t len, rc = 0;
+ size_t len, extra = 0;
+ char *delim;
len = strlen(early_command_line);
-
- delim = early_command_line + len; /* '\0' character position */
- parm = early_command_line + len + 1; /* append right after '\0' */
+ delim = early_command_line + len; /* '\0' character position */
switch (ipl_block.pb0_hdr.pbt) {
case IPL_PBT_CCW:
- rc = ipl_block_get_ascii_vmparm(
- parm, COMMAND_LINE_SIZE - len - 1, &ipl_block);
+ extra = ipl_block_get_ascii_vmparm(command_line_buf, sizeof(command_line_buf), &ipl_block);
break;
case IPL_PBT_FCP:
case IPL_PBT_NVME:
case IPL_PBT_ECKD:
- rc = ipl_block_get_ascii_scpdata(
- parm, COMMAND_LINE_SIZE - len - 1, &ipl_block);
+ extra = ipl_block_get_ascii_scpdata(command_line_buf, sizeof(command_line_buf), &ipl_block);
break;
}
- if (rc) {
- if (*parm == '=')
- memmove(early_command_line, parm + 1, rc);
- else
+ if (extra) {
+ if (command_line_buf[0] == '=') {
+ memmove(early_command_line, command_line_buf + 1, extra);
+ } else if (len < COMMAND_LINE_SIZE - 2) {
*delim = ' '; /* replace '\0' with space */
+ sized_strscpy(delim + 1, command_line_buf, COMMAND_LINE_SIZE - len - 1);
+ }
}
}
@@ -258,7 +257,6 @@ static void modify_fac_list(char *str)
check_cleared_facilities();
}
-static char command_line_buf[COMMAND_LINE_SIZE];
void parse_boot_command_line(void)
{
char *param, *val;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 010/877] selftests/landlock: Add tests for whiteout object creation
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 009/877] s390/boot: Avoid IPL parameter append past command line Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 011/877] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
` (874 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit ee890889b30b22f9a21636061def7a04e4f89380 ]
Add tests to check that whiteout object creation is guarded by
LANDLOCK_ACCESS_FS_MAKE_REG, in the cases where these are created from
userspace:
* Conventional creation with mknod()
* Linking or renaming an existing whiteout object
* renameat2() with RENAME_WHITEOUT,
which creates a new whiteout object in the source location
* renameat2() with RENAME_EXCHANGE,
with one of the renamed objects being a whiteout object
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-4-gnoack@google.com
[mic: Update commit message as requested]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the tests to the older filesystem fixture and
ruleset helper]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 205 ++++++++++++++++++++-
1 file changed, 203 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 732ba5a92df56..ae96637ad40e9 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -85,6 +85,8 @@ static const char file1_s3d1[] = TMP_DIR "/s3d1/f1";
/* dir_s3d2 is a mount point. */
static const char dir_s3d2[] = TMP_DIR "/s3d1/s3d2";
static const char dir_s3d3[] = TMP_DIR "/s3d1/s3d2/s3d3";
+static const char file1_s3d3[] = TMP_DIR "/s3d1/s3d2/s3d3/f1";
+static const char file1_s3d4[] = TMP_DIR "/s3d1/s3d2/s3d4/f1";
/*
* layout1 hierarchy:
@@ -358,7 +360,8 @@ static void create_layout1(struct __test_metadata *const _metadata)
ASSERT_EQ(0, mount_opt(&mnt_tmp, dir_s3d2));
clear_cap(_metadata, CAP_SYS_ADMIN);
- ASSERT_EQ(0, mkdir(dir_s3d3, 0700));
+ create_file(_metadata, file1_s3d3);
+ create_file(_metadata, file1_s3d4);
}
static void remove_layout1(struct __test_metadata *const _metadata)
@@ -378,7 +381,8 @@ static void remove_layout1(struct __test_metadata *const _metadata)
EXPECT_EQ(0, remove_path(dir_s2d2));
EXPECT_EQ(0, remove_path(file1_s3d1));
- EXPECT_EQ(0, remove_path(dir_s3d3));
+ EXPECT_EQ(0, remove_path(file1_s3d3));
+ EXPECT_EQ(0, remove_path(file1_s3d4));
set_cap(_metadata, CAP_SYS_ADMIN);
umount(dir_s3d2);
clear_cap(_metadata, CAP_SYS_ADMIN);
@@ -772,6 +776,27 @@ static int create_ruleset(struct __test_metadata *const _metadata,
return ruleset_fd;
}
+static void enforce_fs(struct __test_metadata *const _metadata,
+ const __u64 access_fs, const struct rule rules[])
+{
+ int ruleset_fd;
+
+ if (rules) {
+ ruleset_fd = create_ruleset(_metadata, access_fs, rules);
+ } else {
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_fs = access_fs,
+ };
+
+ ruleset_fd = landlock_create_ruleset(&ruleset_attr,
+ sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+ }
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+}
+
TEST_F_FORK(layout0, proc_nsfs)
{
const struct rule rules[] = {
@@ -2207,6 +2232,170 @@ TEST_F_FORK(layout1, rename_file)
RENAME_EXCHANGE));
}
+TEST_F_FORK(layout1, rename_whiteout_denied)
+{
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Deny MAKE_REG, but allow MAKE_FIFO. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, NULL);
+
+ /*
+ * Try to rename a file with RENAME_WHITEOUT.
+ * file1_s3d3 is in dir_s3d2 (tmpfs), so it supports RENAME_WHITEOUT.
+ * Denied, because whiteout creation is guarded with MAKE_REG.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+}
+
+static bool is_whiteout(const char *const path)
+{
+ struct stat st;
+
+ if (stat(path, &st) == -1)
+ return false;
+
+ return S_ISCHR(st.st_mode) && st.st_rdev == makedev(0, 0);
+}
+
+static bool is_fifo(const char *const path)
+{
+ struct stat st;
+
+ return stat(path, &st) == 0 && S_ISFIFO(st.st_mode);
+}
+
+TEST_F_FORK(layout1, rename_whiteout_allowed)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Allow MAKE_REG below dir_s3d3. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, rules);
+
+ /*
+ * Rename a file with RENAME_WHITEOUT within the same directory.
+ * Allowed, because MAKE_REG is granted for the whiteout object which
+ * gets created in the source location.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d3/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_reparenting)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The moved files are FIFOs. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * The whiteout object is created in the source directory: Moving the
+ * FIFO out of dir_s3d4 is denied because MAKE_REG is not granted
+ * there, even though it is granted in the destination directory
+ * dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Moving the FIFO out of dir_s3d3 is allowed, because MAKE_REG is
+ * granted there for the created whiteout object.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d4/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d4/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_exchange)
+{
+ const char *const whiteout_s3d3 = TMP_DIR "/s3d1/s3d2/s3d3/f2";
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The exchanged files are FIFOs and an existing whiteout object. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, mknod(whiteout_s3d3, S_IFCHR | 0600, makedev(0, 0)));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * With RENAME_EXCHANGE, the whiteout object moves into the source
+ * directory of the rename: Exchanging the FIFO in dir_s3d4 with the
+ * whiteout object is denied because MAKE_REG is not granted in
+ * dir_s3d4, even though it is granted in the whiteout object's own
+ * directory dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Exchanging the FIFO in dir_s3d3 with the whiteout object is
+ * allowed, because MAKE_REG is granted in the directory into which
+ * the whiteout object moves.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+
+ /* The FIFO and the whiteout object swapped places. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(whiteout_s3d3));
+}
+
TEST_F_FORK(layout1, rename_dir)
{
const struct rule rules[] = {
@@ -3260,6 +3449,18 @@ TEST_F_FORK(layout1, make_char)
makedev(1, 3));
}
+TEST_F_FORK(layout1, make_whiteout)
+{
+ /*
+ * Creates a whiteout object (creation guarded by MAKE_REG).
+ *
+ * Contrary to the other character devices, this does not require
+ * CAP_MKNOD, cf. vfs_mknod().
+ */
+ test_make_file(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, S_IFCHR,
+ makedev(0, 0));
+}
+
TEST_F_FORK(layout1, make_block)
{
/* Creates a /dev/loop0 device. */
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 011/877] sunvdc: fix -EIO issue due to lack of retries
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 010/877] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 012/877] net: cpsw_new: Execute ndo_set_rx_mode callback in a work queue Greg Kroah-Hartman
` (873 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Stian Halseth, Jens Axboe, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit 5067d4ba713961d8ccea1e06cd4c453793f3121e ]
John reports that since commit:
a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN")
users of Linux inside Solaris ldom see occasional -EIO errors because
the request send loop now times out. The current loop does 10 retries,
and inside vio_ldc_send() a further 1000 1usec retries are done as well.
Even with 10.5 msec of busy loop retries that's apparently not enough to
always succeed.
Rather than introduce continued busy looping, requeue the request and
have the delayed queue kicking retry the request after another 10ms.
This obviously isn't ideal, but there's seemingly no way to wait for
this type of event. And if 10ms of busy looping was not enough to make
progress, then presumably this is an edge condition and we just need to
guarantee to make forward progress at some later point in time. That's
more suitably done through letting the CPU tend to other work, rather
than sitting in a tight loop retrying.
[stian: rebased on top of the cookie-unmap fix, without which every
requeued attempt leaks LDC map table entries; tested on an
UltraSPARC T4 LDOM where the vdc_tx_trigger failure condition was
reproduced and absorbed by the requeue with no I/O error]
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/all/20251006100226.4246-2-glaubitz@physik.fu-berlin.de/
Link: https://lore.kernel.org/all/418310b3-2b77-4534-b2fd-27dcc11e333c@kernel.dk/
Signed-off-by: Stian Halseth <stian@itx.no>
Link: https://patch.msgid.link/20260901173947.3292110-3-stian@itx.no
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/sunvdc.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/block/sunvdc.c b/drivers/block/sunvdc.c
index 97fe566465d79..16953341e5013 100644
--- a/drivers/block/sunvdc.c
+++ b/drivers/block/sunvdc.c
@@ -557,6 +557,7 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
struct vdc_port *port = hctx->queue->queuedata;
struct vio_dring_state *dr;
unsigned long flags;
+ int ret;
dr = &port->vio.drings[VIO_DRIVER_TX_RING];
@@ -578,7 +579,13 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
return BLK_STS_DEV_RESOURCE;
}
- if (__send_request(bd->rq) < 0) {
+ ret = __send_request(bd->rq);
+ if (ret == -EAGAIN) {
+ spin_unlock_irqrestore(&port->vio.lock, flags);
+ /* already spun for 10msec, defer 10msec and retry */
+ blk_mq_delay_kick_requeue_list(hctx->queue, 10);
+ return BLK_STS_DEV_RESOURCE;
+ } else if (ret < 0) {
spin_unlock_irqrestore(&port->vio.lock, flags);
return BLK_STS_IOERR;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 012/877] net: cpsw_new: Execute ndo_set_rx_mode callback in a work queue
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 011/877] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 013/877] net: cpsw: " Greg Kroah-Hartman
` (872 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kevin Hao, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kevin Hao <haokexin@gmail.com>
commit c0b5dc73a38f954e780f93a549b8fe225235c07a upstream.
Commit 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for
IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.") removed the RTNL lock for
IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP operations. However, this
change triggered the following call trace on my BeagleBone Black board:
WARNING: net/8021q/vlan_core.c:236 at vlan_for_each+0x120/0x124, CPU#0: rpcbind/496
RTNL: assertion failed at net/8021q/vlan_core.c (236)
Modules linked in:
CPU: 0 UID: 997 PID: 496 Comm: rpcbind Not tainted 6.19.0-rc6-next-20260122-yocto-standard+ #8 PREEMPT
Hardware name: Generic AM33XX (Flattened Device Tree)
Call trace:
unwind_backtrace from show_stack+0x28/0x2c
show_stack from dump_stack_lvl+0x30/0x38
dump_stack_lvl from __warn+0xb8/0x11c
__warn from warn_slowpath_fmt+0x130/0x194
warn_slowpath_fmt from vlan_for_each+0x120/0x124
vlan_for_each from cpsw_add_mc_addr+0x54/0xd8
cpsw_add_mc_addr from __hw_addr_ref_sync_dev+0xc4/0xec
__hw_addr_ref_sync_dev from __dev_mc_add+0x78/0x88
__dev_mc_add from igmp6_group_added+0x84/0xec
igmp6_group_added from __ipv6_dev_mc_inc+0x1fc/0x2f0
__ipv6_dev_mc_inc from __ipv6_sock_mc_join+0x124/0x1b4
__ipv6_sock_mc_join from do_ipv6_setsockopt+0x84c/0x1168
do_ipv6_setsockopt from ipv6_setsockopt+0x88/0xc8
ipv6_setsockopt from do_sock_setsockopt+0xe8/0x19c
do_sock_setsockopt from __sys_setsockopt+0x84/0xac
__sys_setsockopt from ret_fast_syscall+0x0/0x5
This trace occurs because vlan_for_each() is called within
cpsw_ndo_set_rx_mode(), which expects the RTNL lock to be held.
Since modifying vlan_for_each() to operate without the RTNL lock is not
straightforward, and because ndo_set_rx_mode() is invoked both with and
without the RTNL lock across different code paths, simply adding
rtnl_lock() in cpsw_ndo_set_rx_mode() is not a viable solution.
To resolve this issue, we opt to execute the actual processing within
a work queue, following the approach used by the icssg-prueth driver.
Fixes: 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.")
Signed-off-by: Kevin Hao <haokexin@gmail.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260203-bbb-v5-1-ea0ea217a85c@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ti/cpsw_new.c | 35 ++++++++++++++++++++++++-----
drivers/net/ethernet/ti/cpsw_priv.h | 1 +
2 files changed, 30 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/ti/cpsw_new.c b/drivers/net/ethernet/ti/cpsw_new.c
index 468eaa6f785e6..c2041e46b83d6 100644
--- a/drivers/net/ethernet/ti/cpsw_new.c
+++ b/drivers/net/ethernet/ti/cpsw_new.c
@@ -248,16 +248,22 @@ static int cpsw_purge_all_mc(struct net_device *ndev, const u8 *addr, int num)
return 0;
}
-static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
+static void cpsw_ndo_set_rx_mode_work(struct work_struct *work)
{
- struct cpsw_priv *priv = netdev_priv(ndev);
+ struct cpsw_priv *priv = container_of(work, struct cpsw_priv, rx_mode_work);
struct cpsw_common *cpsw = priv->cpsw;
+ struct net_device *ndev = priv->ndev;
+
+ rtnl_lock();
+ if (!netif_running(ndev))
+ goto unlock_rtnl;
+ netif_addr_lock_bh(ndev);
if (ndev->flags & IFF_PROMISC) {
/* Enable promiscuous mode */
cpsw_set_promiscious(ndev, true);
cpsw_ale_set_allmulti(cpsw->ale, IFF_ALLMULTI, priv->emac_port);
- return;
+ goto unlock_addr;
}
/* Disable promiscuous mode */
@@ -270,6 +276,18 @@ static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
/* add/remove mcast address either for real netdev or for vlan */
__hw_addr_ref_sync_dev(&ndev->mc, ndev, cpsw_add_mc_addr,
cpsw_del_mc_addr);
+
+unlock_addr:
+ netif_addr_unlock_bh(ndev);
+unlock_rtnl:
+ rtnl_unlock();
+}
+
+static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
+{
+ struct cpsw_priv *priv = netdev_priv(ndev);
+
+ schedule_work(&priv->rx_mode_work);
}
static unsigned int cpsw_rxbuf_total_len(unsigned int len)
@@ -1391,6 +1409,7 @@ static int cpsw_create_ports(struct cpsw_common *cpsw)
priv->msg_enable = netif_msg_init(debug_level, CPSW_DEBUG);
priv->emac_port = i + 1;
priv->tx_packet_min = CPSW_MIN_PACKET_SIZE;
+ INIT_WORK(&priv->rx_mode_work, cpsw_ndo_set_rx_mode_work);
if (is_valid_ether_addr(slave_data->mac_addr)) {
ether_addr_copy(priv->mac_addr, slave_data->mac_addr);
@@ -1440,14 +1459,18 @@ static int cpsw_create_ports(struct cpsw_common *cpsw)
static void cpsw_unregister_ports(struct cpsw_common *cpsw)
{
+ struct net_device *ndev;
+ struct cpsw_priv *priv;
int i = 0;
for (i = 0; i < cpsw->data.slaves; i++) {
- if (!cpsw->slaves[i].ndev ||
- cpsw->slaves[i].ndev->reg_state != NETREG_REGISTERED)
+ ndev = cpsw->slaves[i].ndev;
+ if (!ndev || ndev->reg_state != NETREG_REGISTERED)
continue;
- unregister_netdev(cpsw->slaves[i].ndev);
+ priv = netdev_priv(ndev);
+ unregister_netdev(ndev);
+ disable_work_sync(&priv->rx_mode_work);
}
}
diff --git a/drivers/net/ethernet/ti/cpsw_priv.h b/drivers/net/ethernet/ti/cpsw_priv.h
index 1f448290b9f4b..bacaa855e6148 100644
--- a/drivers/net/ethernet/ti/cpsw_priv.h
+++ b/drivers/net/ethernet/ti/cpsw_priv.h
@@ -391,6 +391,7 @@ struct cpsw_priv {
u32 tx_packet_min;
struct cpsw_ale_ratelimit ale_bc_ratelimit;
struct cpsw_ale_ratelimit ale_mc_ratelimit;
+ struct work_struct rx_mode_work;
};
#define ndev_to_cpsw(ndev) (((struct cpsw_priv *)netdev_priv(ndev))->cpsw)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 013/877] net: cpsw: Execute ndo_set_rx_mode callback in a work queue
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 012/877] net: cpsw_new: Execute ndo_set_rx_mode callback in a work queue Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 014/877] ipv6: mcast: Use in6_dev_get() in ipv6_dev_mc_dec() Greg Kroah-Hartman
` (871 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kevin Hao, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kevin Hao <haokexin@gmail.com>
commit 0b8c878d117319f2be34c8391a77e0f4d5c94d79 upstream.
Commit 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for
IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.") removed the RTNL lock for
IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP operations. However, this
change triggered the following call trace on my BeagleBone Black board:
WARNING: net/8021q/vlan_core.c:236 at vlan_for_each+0x120/0x124, CPU#0: rpcbind/481
RTNL: assertion failed at net/8021q/vlan_core.c (236)
Modules linked in:
CPU: 0 UID: 997 PID: 481 Comm: rpcbind Not tainted 6.19.0-rc7-next-20260130-yocto-standard+ #35 PREEMPT
Hardware name: Generic AM33XX (Flattened Device Tree)
Call trace:
unwind_backtrace from show_stack+0x28/0x2c
show_stack from dump_stack_lvl+0x30/0x38
dump_stack_lvl from __warn+0xb8/0x11c
__warn from warn_slowpath_fmt+0x130/0x194
warn_slowpath_fmt from vlan_for_each+0x120/0x124
vlan_for_each from cpsw_add_mc_addr+0x54/0x98
cpsw_add_mc_addr from __hw_addr_ref_sync_dev+0xc4/0xec
__hw_addr_ref_sync_dev from __dev_mc_add+0x78/0x88
__dev_mc_add from igmp6_group_added+0x84/0xec
igmp6_group_added from __ipv6_dev_mc_inc+0x1fc/0x2f0
__ipv6_dev_mc_inc from __ipv6_sock_mc_join+0x124/0x1b4
__ipv6_sock_mc_join from do_ipv6_setsockopt+0x84c/0x1168
do_ipv6_setsockopt from ipv6_setsockopt+0x88/0xc8
ipv6_setsockopt from do_sock_setsockopt+0xe8/0x19c
do_sock_setsockopt from __sys_setsockopt+0x84/0xac
__sys_setsockopt from ret_fast_syscall+0x0/0x54
This trace occurs because vlan_for_each() is called within
cpsw_ndo_set_rx_mode(), which expects the RTNL lock to be held.
Since modifying vlan_for_each() to operate without the RTNL lock is not
straightforward, and because ndo_set_rx_mode() is invoked both with and
without the RTNL lock across different code paths, simply adding
rtnl_lock() in cpsw_ndo_set_rx_mode() is not a viable solution.
To resolve this issue, we opt to execute the actual processing within
a work queue, following the approach used by the icssg-prueth driver.
Please note: To reproduce this issue, I manually reverted the changes to
am335x-bone-common.dtsi from commit c477358e66a3 ("ARM: dts: am335x-bone:
switch to new cpsw switch drv") in order to revert to the legacy cpsw
driver.
Fixes: 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.")
Signed-off-by: Kevin Hao <haokexin@gmail.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260203-bbb-v5-2-ea0ea217a85c@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/ti/cpsw.c | 41 +++++++++++++++++++++++++++++-----
1 file changed, 35 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index c0a5abd8d9a8e..2968b5fbe428c 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -305,12 +305,19 @@ static int cpsw_purge_all_mc(struct net_device *ndev, const u8 *addr, int num)
return 0;
}
-static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
+static void cpsw_ndo_set_rx_mode_work(struct work_struct *work)
{
- struct cpsw_priv *priv = netdev_priv(ndev);
+ struct cpsw_priv *priv = container_of(work, struct cpsw_priv, rx_mode_work);
struct cpsw_common *cpsw = priv->cpsw;
+ struct net_device *ndev = priv->ndev;
int slave_port = -1;
+ rtnl_lock();
+ if (!netif_running(ndev))
+ goto unlock_rtnl;
+
+ netif_addr_lock_bh(ndev);
+
if (cpsw->data.dual_emac)
slave_port = priv->emac_port + 1;
@@ -318,7 +325,7 @@ static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
/* Enable promiscuous mode */
cpsw_set_promiscious(ndev, true);
cpsw_ale_set_allmulti(cpsw->ale, IFF_ALLMULTI, slave_port);
- return;
+ goto unlock_addr;
} else {
/* Disable promiscuous mode */
cpsw_set_promiscious(ndev, false);
@@ -331,6 +338,18 @@ static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
/* add/remove mcast address either for real netdev or for vlan */
__hw_addr_ref_sync_dev(&ndev->mc, ndev, cpsw_add_mc_addr,
cpsw_del_mc_addr);
+
+unlock_addr:
+ netif_addr_unlock_bh(ndev);
+unlock_rtnl:
+ rtnl_unlock();
+}
+
+static void cpsw_ndo_set_rx_mode(struct net_device *ndev)
+{
+ struct cpsw_priv *priv = netdev_priv(ndev);
+
+ schedule_work(&priv->rx_mode_work);
}
static unsigned int cpsw_rxbuf_total_len(unsigned int len)
@@ -1444,6 +1463,7 @@ static int cpsw_probe_dual_emac(struct cpsw_priv *priv)
priv_sl2->ndev = ndev;
priv_sl2->dev = &ndev->dev;
priv_sl2->msg_enable = netif_msg_init(debug_level, CPSW_DEBUG);
+ INIT_WORK(&priv_sl2->rx_mode_work, cpsw_ndo_set_rx_mode_work);
if (is_valid_ether_addr(data->slave_data[1].mac_addr)) {
memcpy(priv_sl2->mac_addr, data->slave_data[1].mac_addr,
@@ -1625,6 +1645,7 @@ static int cpsw_probe(struct platform_device *pdev)
priv->dev = dev;
priv->msg_enable = netif_msg_init(debug_level, CPSW_DEBUG);
priv->emac_port = 0;
+ INIT_WORK(&priv->rx_mode_work, cpsw_ndo_set_rx_mode_work);
if (is_valid_ether_addr(data->slave_data[0].mac_addr)) {
memcpy(priv->mac_addr, data->slave_data[0].mac_addr, ETH_ALEN);
@@ -1727,6 +1748,8 @@ static int cpsw_probe(struct platform_device *pdev)
static void cpsw_remove(struct platform_device *pdev)
{
struct cpsw_common *cpsw = platform_get_drvdata(pdev);
+ struct net_device *ndev;
+ struct cpsw_priv *priv;
int i, ret;
ret = pm_runtime_resume_and_get(&pdev->dev);
@@ -1739,9 +1762,15 @@ static void cpsw_remove(struct platform_device *pdev)
return;
}
- for (i = 0; i < cpsw->data.slaves; i++)
- if (cpsw->slaves[i].ndev)
- unregister_netdev(cpsw->slaves[i].ndev);
+ for (i = 0; i < cpsw->data.slaves; i++) {
+ ndev = cpsw->slaves[i].ndev;
+ if (!ndev)
+ continue;
+
+ priv = netdev_priv(ndev);
+ unregister_netdev(ndev);
+ disable_work_sync(&priv->rx_mode_work);
+ }
cpts_release(cpsw->cpts);
cpdma_ctlr_destroy(cpsw->dma);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 014/877] ipv6: mcast: Use in6_dev_get() in ipv6_dev_mc_dec().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 013/877] net: cpsw: " Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 015/877] ipv6: mcast: Dont hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP Greg Kroah-Hartman
` (870 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit e01b193e0b50ae849bf60067e111446f19ee2f20 ]
As well as __ipv6_dev_mc_inc(), all code in __ipv6_dev_mc_dec() are
protected by inet6_dev->mc_lock, and RTNL is not needed.
Let's use in6_dev_get() in ipv6_dev_mc_dec() and remove ASSERT_RTNL()
in __ipv6_dev_mc_dec().
Now, we can remove the RTNL comment above addrconf_leave_solict() too.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20250702230210.3115355-6-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/addrconf.c | 3 +--
net/ipv6/mcast.c | 14 ++++++--------
2 files changed, 7 insertions(+), 10 deletions(-)
diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index ef938fb1d7549..fb239e8f83593 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -2255,12 +2255,11 @@ void addrconf_join_solict(struct net_device *dev, const struct in6_addr *addr)
ipv6_dev_mc_inc(dev, &maddr);
}
-/* caller must hold RTNL */
void addrconf_leave_solict(struct inet6_dev *idev, const struct in6_addr *addr)
{
struct in6_addr maddr;
- if (idev->dev->flags&(IFF_LOOPBACK|IFF_NOARP))
+ if (READ_ONCE(idev->dev->flags) & (IFF_LOOPBACK | IFF_NOARP))
return;
addrconf_addr_solict_mult(addr, &maddr);
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index c060954c52757..212c2d8efe0f5 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -972,9 +972,8 @@ int __ipv6_dev_mc_dec(struct inet6_dev *idev, const struct in6_addr *addr)
{
struct ifmcaddr6 *ma, __rcu **map;
- ASSERT_RTNL();
-
mutex_lock(&idev->mc_lock);
+
for (map = &idev->mc_list;
(ma = mc_dereference(*map, idev));
map = &ma->next) {
@@ -1003,13 +1002,12 @@ int ipv6_dev_mc_dec(struct net_device *dev, const struct in6_addr *addr)
struct inet6_dev *idev;
int err;
- ASSERT_RTNL();
-
- idev = __in6_dev_get(dev);
+ idev = in6_dev_get(dev);
if (!idev)
- err = -ENODEV;
- else
- err = __ipv6_dev_mc_dec(idev, addr);
+ return -ENODEV;
+
+ err = __ipv6_dev_mc_dec(idev, addr);
+ in6_dev_put(idev);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 015/877] ipv6: mcast: Dont hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 014/877] ipv6: mcast: Use in6_dev_get() in ipv6_dev_mc_dec() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 016/877] ipv6: mcast: Dont hold RTNL for IPV6_DROP_MEMBERSHIP and MCAST_LEAVE_GROUP Greg Kroah-Hartman
` (869 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 1767bb2d47b715a106287a8f963d9ec6cbab4e69 ]
In __ipv6_sock_mc_join(), per-socket mld data is protected by lock_sock(),
and only __dev_get_by_index() requires RTNL.
Let's use dev_get_by_index() and drop RTNL for IPV6_ADD_MEMBERSHIP and
MCAST_JOIN_GROUP.
Note that we must call rt6_lookup() and dev_hold() under RCU.
If rt6_lookup() returns an entry from the exception table, dst_dev_put()
could change rt->dev.dst to loopback concurrently, and the original device
could lose the refcount before dev_hold() and unblock device registration.
dst_dev_put() is called from NETDEV_UNREGISTER and synchronize_net() follows
it, so as long as rt6_lookup() and dev_hold() are called within the same
RCU critical section, the dev is alive.
Even if the race happens, they are synchronised by idev->dead and mcast
addresses are cleaned up.
For the racy access to rt->dst.dev, we use dst_dev().
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20250702230210.3115355-7-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ipv6_sockglue.c | 2 --
net/ipv6/mcast.c | 24 +++++++++++++-----------
2 files changed, 13 insertions(+), 13 deletions(-)
diff --git a/net/ipv6/ipv6_sockglue.c b/net/ipv6/ipv6_sockglue.c
index c2ea92c0f9166..385321a43a19b 100644
--- a/net/ipv6/ipv6_sockglue.c
+++ b/net/ipv6/ipv6_sockglue.c
@@ -121,11 +121,9 @@ static bool setsockopt_needs_rtnl(int optname)
{
switch (optname) {
case IPV6_ADDRFORM:
- case IPV6_ADD_MEMBERSHIP:
case IPV6_DROP_MEMBERSHIP:
case IPV6_JOIN_ANYCAST:
case IPV6_LEAVE_ANYCAST:
- case MCAST_JOIN_GROUP:
case MCAST_LEAVE_GROUP:
case MCAST_JOIN_SOURCE_GROUP:
case MCAST_LEAVE_SOURCE_GROUP:
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 212c2d8efe0f5..61046543302d4 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -172,14 +172,12 @@ static int unsolicited_report_interval(struct inet6_dev *idev)
static int __ipv6_sock_mc_join(struct sock *sk, int ifindex,
const struct in6_addr *addr, unsigned int mode)
{
- struct net_device *dev = NULL;
- struct ipv6_mc_socklist *mc_lst;
struct ipv6_pinfo *np = inet6_sk(sk);
+ struct ipv6_mc_socklist *mc_lst;
struct net *net = sock_net(sk);
+ struct net_device *dev = NULL;
int err;
- ASSERT_RTNL();
-
if (!ipv6_addr_is_multicast(addr))
return -EINVAL;
@@ -199,13 +197,18 @@ static int __ipv6_sock_mc_join(struct sock *sk, int ifindex,
if (ifindex == 0) {
struct rt6_info *rt;
+
+ rcu_read_lock();
rt = rt6_lookup(net, addr, NULL, 0, NULL, 0);
if (rt) {
- dev = rt->dst.dev;
+ dev = dst_dev(&rt->dst);
+ dev_hold(dev);
ip6_rt_put(rt);
}
- } else
- dev = __dev_get_by_index(net, ifindex);
+ rcu_read_unlock();
+ } else {
+ dev = dev_get_by_index(net, ifindex);
+ }
if (!dev) {
sock_kfree_s(sk, mc_lst, sizeof(*mc_lst));
@@ -216,12 +219,11 @@ static int __ipv6_sock_mc_join(struct sock *sk, int ifindex,
mc_lst->sfmode = mode;
RCU_INIT_POINTER(mc_lst->sflist, NULL);
- /*
- * now add/increase the group membership on the device
- */
-
+ /* now add/increase the group membership on the device */
err = __ipv6_dev_mc_inc(dev, addr, mode);
+ dev_put(dev);
+
if (err) {
sock_kfree_s(sk, mc_lst, sizeof(*mc_lst));
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 016/877] ipv6: mcast: Dont hold RTNL for IPV6_DROP_MEMBERSHIP and MCAST_LEAVE_GROUP.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 015/877] ipv6: mcast: Dont hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 017/877] ipv6: mcast: Dont hold RTNL for MCAST_ socket options Greg Kroah-Hartman
` (868 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 2ceb71ce7d34e751f91bbca9da3513a2bc29089c ]
In __ipv6_sock_mc_drop(), per-socket mld data is protected by lock_sock(),
and only __dev_get_by_index() and __in6_dev_get() require RTNL.
Let's use dev_get_by_index() and in6_dev_get() and drop RTNL for
IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.
Note that __ipv6_sock_mc_drop() is factorised to reuse in the next patch.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20250702230210.3115355-8-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ipv6_sockglue.c | 2 --
net/ipv6/mcast.c | 47 +++++++++++++++++++++++-----------------
2 files changed, 27 insertions(+), 22 deletions(-)
diff --git a/net/ipv6/ipv6_sockglue.c b/net/ipv6/ipv6_sockglue.c
index 385321a43a19b..ab6987e72e3a7 100644
--- a/net/ipv6/ipv6_sockglue.c
+++ b/net/ipv6/ipv6_sockglue.c
@@ -121,10 +121,8 @@ static bool setsockopt_needs_rtnl(int optname)
{
switch (optname) {
case IPV6_ADDRFORM:
- case IPV6_DROP_MEMBERSHIP:
case IPV6_JOIN_ANYCAST:
case IPV6_LEAVE_ANYCAST:
- case MCAST_LEAVE_GROUP:
case MCAST_JOIN_SOURCE_GROUP:
case MCAST_LEAVE_SOURCE_GROUP:
case MCAST_BLOCK_SOURCE:
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 61046543302d4..2f485e58a7d49 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -250,14 +250,36 @@ int ipv6_sock_mc_join_ssm(struct sock *sk, int ifindex,
/*
* socket leave on multicast group
*/
+static void __ipv6_sock_mc_drop(struct sock *sk, struct ipv6_mc_socklist *mc_lst)
+{
+ struct net *net = sock_net(sk);
+ struct net_device *dev;
+
+ dev = dev_get_by_index(net, mc_lst->ifindex);
+ if (dev) {
+ struct inet6_dev *idev = in6_dev_get(dev);
+
+ ip6_mc_leave_src(sk, mc_lst, idev);
+
+ if (idev) {
+ __ipv6_dev_mc_dec(idev, &mc_lst->addr);
+ in6_dev_put(idev);
+ }
+
+ dev_put(dev);
+ } else {
+ ip6_mc_leave_src(sk, mc_lst, NULL);
+ }
+
+ atomic_sub(sizeof(*mc_lst), &sk->sk_omem_alloc);
+ kfree_rcu(mc_lst, rcu);
+}
+
int ipv6_sock_mc_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
{
struct ipv6_pinfo *np = inet6_sk(sk);
- struct ipv6_mc_socklist *mc_lst;
struct ipv6_mc_socklist __rcu **lnk;
- struct net *net = sock_net(sk);
-
- ASSERT_RTNL();
+ struct ipv6_mc_socklist *mc_lst;
if (!ipv6_addr_is_multicast(addr))
return -EINVAL;
@@ -267,23 +289,8 @@ int ipv6_sock_mc_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
lnk = &mc_lst->next) {
if ((ifindex == 0 || mc_lst->ifindex == ifindex) &&
ipv6_addr_equal(&mc_lst->addr, addr)) {
- struct net_device *dev;
-
*lnk = mc_lst->next;
-
- dev = __dev_get_by_index(net, mc_lst->ifindex);
- if (dev) {
- struct inet6_dev *idev = __in6_dev_get(dev);
-
- ip6_mc_leave_src(sk, mc_lst, idev);
- if (idev)
- __ipv6_dev_mc_dec(idev, &mc_lst->addr);
- } else {
- ip6_mc_leave_src(sk, mc_lst, NULL);
- }
-
- atomic_sub(sizeof(*mc_lst), &sk->sk_omem_alloc);
- kfree_rcu(mc_lst, rcu);
+ __ipv6_sock_mc_drop(sk, mc_lst);
return 0;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 017/877] ipv6: mcast: Dont hold RTNL for MCAST_ socket options.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 016/877] ipv6: mcast: Dont hold RTNL for IPV6_DROP_MEMBERSHIP and MCAST_LEAVE_GROUP Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 018/877] ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() Greg Kroah-Hartman
` (867 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit e6e14d582dd2cbee362c48a1865f8d03ca0a5611 ]
In ip6_mc_source() and ip6_mc_msfilter(), per-socket mld data is
protected by lock_sock() and inet6_dev->mc_lock is also held for
some per-interface functions.
ip6_mc_find_dev_rtnl() only depends on RTNL. If we want to remove
it, we need to check inet6_dev->dead under mc_lock to close the race
with addrconf_ifdown(), as mentioned earlier.
Let's do that and drop RTNL for the rest of MCAST_ socket options.
Note that ip6_mc_msfilter() has unnecessary lock dances and they
are integrated into one to avoid the last-minute error and simplify
the error handling.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20250702230210.3115355-10-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/ipv6_sockglue.c | 5 ---
net/ipv6/mcast.c | 74 ++++++++++++++++++++++++----------------
2 files changed, 45 insertions(+), 34 deletions(-)
diff --git a/net/ipv6/ipv6_sockglue.c b/net/ipv6/ipv6_sockglue.c
index ab6987e72e3a7..0f1242138d176 100644
--- a/net/ipv6/ipv6_sockglue.c
+++ b/net/ipv6/ipv6_sockglue.c
@@ -123,11 +123,6 @@ static bool setsockopt_needs_rtnl(int optname)
case IPV6_ADDRFORM:
case IPV6_JOIN_ANYCAST:
case IPV6_LEAVE_ANYCAST:
- case MCAST_JOIN_SOURCE_GROUP:
- case MCAST_LEAVE_SOURCE_GROUP:
- case MCAST_BLOCK_SOURCE:
- case MCAST_UNBLOCK_SOURCE:
- case MCAST_MSFILTER:
return true;
}
return false;
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 2f485e58a7d49..02919944d5570 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -299,31 +299,36 @@ int ipv6_sock_mc_drop(struct sock *sk, int ifindex, const struct in6_addr *addr)
}
EXPORT_SYMBOL(ipv6_sock_mc_drop);
-static struct inet6_dev *ip6_mc_find_dev_rtnl(struct net *net,
- const struct in6_addr *group,
- int ifindex)
+static struct inet6_dev *ip6_mc_find_dev(struct net *net,
+ const struct in6_addr *group,
+ int ifindex)
{
struct net_device *dev = NULL;
- struct inet6_dev *idev = NULL;
+ struct inet6_dev *idev;
if (ifindex == 0) {
- struct rt6_info *rt = rt6_lookup(net, group, NULL, 0, NULL, 0);
+ struct rt6_info *rt;
+ rcu_read_lock();
+ rt = rt6_lookup(net, group, NULL, 0, NULL, 0);
if (rt) {
- dev = rt->dst.dev;
+ dev = dst_dev(&rt->dst);
+ dev_hold(dev);
ip6_rt_put(rt);
}
+ rcu_read_unlock();
} else {
- dev = __dev_get_by_index(net, ifindex);
+ dev = dev_get_by_index(net, ifindex);
}
-
if (!dev)
return NULL;
- idev = __in6_dev_get(dev);
+
+ idev = in6_dev_get(dev);
+ dev_put(dev);
+
if (!idev)
return NULL;
- if (idev->dead)
- return NULL;
+
return idev;
}
@@ -371,16 +376,16 @@ void ipv6_sock_mc_close(struct sock *sk)
}
int ip6_mc_source(int add, int omode, struct sock *sk,
- struct group_source_req *pgsr)
+ struct group_source_req *pgsr)
{
+ struct ipv6_pinfo *inet6 = inet6_sk(sk);
struct in6_addr *source, *group;
+ struct net *net = sock_net(sk);
struct ipv6_mc_socklist *pmc;
- struct inet6_dev *idev;
- struct ipv6_pinfo *inet6 = inet6_sk(sk);
struct ip6_sf_socklist *psl;
- struct net *net = sock_net(sk);
- int i, j, rv;
+ struct inet6_dev *idev;
int leavegroup = 0;
+ int i, j, rv;
int err;
source = &((struct sockaddr_in6 *)&pgsr->gsr_source)->sin6_addr;
@@ -389,13 +394,19 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
if (!ipv6_addr_is_multicast(group))
return -EINVAL;
- idev = ip6_mc_find_dev_rtnl(net, group, pgsr->gsr_interface);
+ idev = ip6_mc_find_dev(net, group, pgsr->gsr_interface);
if (!idev)
return -ENODEV;
+ mutex_lock(&idev->mc_lock);
+
+ if (idev->dead) {
+ err = -ENODEV;
+ goto done;
+ }
+
err = -EADDRNOTAVAIL;
- mutex_lock(&idev->mc_lock);
for_each_pmc_socklock(inet6, sk, pmc) {
if (pgsr->gsr_interface && pmc->ifindex != pgsr->gsr_interface)
continue;
@@ -492,6 +503,7 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
ip6_mc_add_src(idev, group, omode, 1, source, 1);
done:
mutex_unlock(&idev->mc_lock);
+ in6_dev_put(idev);
if (leavegroup)
err = ipv6_sock_mc_drop(sk, pgsr->gsr_interface, group);
return err;
@@ -500,12 +512,12 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
int ip6_mc_msfilter(struct sock *sk, struct group_filter *gsf,
struct sockaddr_storage *list)
{
- const struct in6_addr *group;
- struct ipv6_mc_socklist *pmc;
- struct inet6_dev *idev;
struct ipv6_pinfo *inet6 = inet6_sk(sk);
struct ip6_sf_socklist *newpsl, *psl;
struct net *net = sock_net(sk);
+ const struct in6_addr *group;
+ struct ipv6_mc_socklist *pmc;
+ struct inet6_dev *idev;
int leavegroup = 0;
int i, err;
@@ -517,10 +529,17 @@ int ip6_mc_msfilter(struct sock *sk, struct group_filter *gsf,
gsf->gf_fmode != MCAST_EXCLUDE)
return -EINVAL;
- idev = ip6_mc_find_dev_rtnl(net, group, gsf->gf_interface);
+ idev = ip6_mc_find_dev(net, group, gsf->gf_interface);
if (!idev)
return -ENODEV;
+ mutex_lock(&idev->mc_lock);
+
+ if (idev->dead) {
+ err = -ENODEV;
+ goto done;
+ }
+
err = 0;
if (gsf->gf_fmode == MCAST_INCLUDE && gsf->gf_numsrc == 0) {
@@ -553,24 +572,19 @@ int ip6_mc_msfilter(struct sock *sk, struct group_filter *gsf,
psin6 = (struct sockaddr_in6 *)list;
newpsl->sl_addr[i] = psin6->sin6_addr;
}
- mutex_lock(&idev->mc_lock);
+
err = ip6_mc_add_src(idev, group, gsf->gf_fmode,
newpsl->sl_count, newpsl->sl_addr, 0);
if (err) {
- mutex_unlock(&idev->mc_lock);
sock_kfree_s(sk, newpsl, struct_size(newpsl, sl_addr,
newpsl->sl_max));
goto done;
}
- mutex_unlock(&idev->mc_lock);
} else {
newpsl = NULL;
- mutex_lock(&idev->mc_lock);
ip6_mc_add_src(idev, group, gsf->gf_fmode, 0, NULL, 0);
- mutex_unlock(&idev->mc_lock);
}
- mutex_lock(&idev->mc_lock);
psl = sock_dereference(pmc->sflist, sk);
if (psl) {
ip6_mc_del_src(idev, group, pmc->sfmode,
@@ -580,12 +594,14 @@ int ip6_mc_msfilter(struct sock *sk, struct group_filter *gsf,
} else {
ip6_mc_del_src(idev, group, pmc->sfmode, 0, NULL, 0);
}
+
rcu_assign_pointer(pmc->sflist, newpsl);
- mutex_unlock(&idev->mc_lock);
kfree_rcu(psl, rcu);
pmc->sfmode = gsf->gf_fmode;
err = 0;
done:
+ mutex_unlock(&idev->mc_lock);
+ in6_dev_put(idev);
if (leavegroup)
err = ipv6_sock_mc_drop(sk, gsf->gf_interface, group);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 018/877] ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 017/877] ipv6: mcast: Dont hold RTNL for MCAST_ socket options Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 019/877] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
` (866 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Taehee Yoo,
Ido Schimmel, Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit c073d1b070f171d206b19c98d71739a97f15b3f1 ]
pmc->sflist is read locklessly under rcu_read_lock() by
inet6_mc_check() during packet reception in the UDP and RAW
multicast receive paths.
ip6_mc_source() mutated psl->sl_addr and psl->sl_count in-place
when adding or removing a source filter. Additionally, when expanding
the filter buffer, newpsl was published via rcu_assign_pointer()
before writing the new source into the array.
Because 16-byte struct in6_addr writes are not atomic and array
shifting is not synchronized with RCU readers, concurrent readers in
inet6_mc_check() could read torn IPv6 addresses or observe
duplicated/missed source entries.
Fix this by switching ip6_mc_source() to copy-on-write RCU updates:
allocate and fully populate newpsl before publishing it via
rcu_assign_pointer(), and reclaim the old filter via kfree_rcu(),
matching ip6_mc_msfilter().
Also remove the now unused IP6_SFBLOCK macro.
Fixes: 882ba1f73c06 ("mld: convert ipv6_mc_socklist->sflist to RCU")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Taehee Yoo <ap420073@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260828084531.1826790-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/if_inet6.h | 2 -
net/ipv6/mcast.c | 98 ++++++++++++++++++++++++------------------
2 files changed, 56 insertions(+), 44 deletions(-)
diff --git a/include/net/if_inet6.h b/include/net/if_inet6.h
index 238ad3349456a..795fb41b45f5d 100644
--- a/include/net/if_inet6.h
+++ b/include/net/if_inet6.h
@@ -88,8 +88,6 @@ struct ip6_sf_socklist {
struct in6_addr sl_addr[] __counted_by(sl_max);
};
-#define IP6_SFBLOCK 10 /* allocate this many at once */
-
struct ipv6_mc_socklist {
struct in6_addr addr;
int ifindex;
diff --git a/net/ipv6/mcast.c b/net/ipv6/mcast.c
index 02919944d5570..d0eefadea5c33 100644
--- a/net/ipv6/mcast.c
+++ b/net/ipv6/mcast.c
@@ -380,12 +380,12 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
{
struct ipv6_pinfo *inet6 = inet6_sk(sk);
struct in6_addr *source, *group;
+ struct ip6_sf_socklist *newpsl, *psl;
struct net *net = sock_net(sk);
struct ipv6_mc_socklist *pmc;
- struct ip6_sf_socklist *psl;
struct inet6_dev *idev;
int leavegroup = 0;
- int i, j, rv;
+ int i, j;
int err;
source = &((struct sockaddr_in6 *)&pgsr->gsr_source)->sin6_addr;
@@ -434,13 +434,11 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
if (!add) {
if (!psl)
goto done; /* err = -EADDRNOTAVAIL */
- rv = !0;
for (i = 0; i < psl->sl_count; i++) {
- rv = !ipv6_addr_equal(&psl->sl_addr[i], source);
- if (rv == 0)
+ if (ipv6_addr_equal(&psl->sl_addr[i], source))
break;
}
- if (rv) /* source not found */
+ if (i == psl->sl_count) /* source not found */
goto done; /* err = -EADDRNOTAVAIL */
/* special case - (INCLUDE, empty) == LEAVE_GROUP */
@@ -449,58 +447,74 @@ int ip6_mc_source(int add, int omode, struct sock *sk,
goto done;
}
+ atomic_sub(struct_size(psl, sl_addr, psl->sl_max),
+ &sk->sk_omem_alloc);
+
+ if (psl->sl_count == 1) {
+ newpsl = NULL;
+ } else {
+ newpsl = sock_kmalloc(sk, struct_size(newpsl, sl_addr,
+ psl->sl_count - 1),
+ GFP_KERNEL);
+ if (!newpsl) {
+ atomic_add(struct_size(psl, sl_addr, psl->sl_max),
+ &sk->sk_omem_alloc);
+ err = -ENOBUFS;
+ goto done;
+ }
+ newpsl->sl_max = psl->sl_count - 1;
+ newpsl->sl_count = psl->sl_count - 1;
+ for (j = 0; j < i; j++)
+ newpsl->sl_addr[j] = psl->sl_addr[j];
+ for (j = i + 1; j < psl->sl_count; j++)
+ newpsl->sl_addr[j - 1] = psl->sl_addr[j];
+ }
+
/* update the interface filter */
ip6_mc_del_src(idev, group, omode, 1, source, 1);
- for (j = i+1; j < psl->sl_count; j++)
- psl->sl_addr[j-1] = psl->sl_addr[j];
- psl->sl_count--;
+ rcu_assign_pointer(pmc->sflist, newpsl);
+ kfree_rcu(psl, rcu);
err = 0;
goto done;
}
/* else, add a new source to the filter */
- if (psl && psl->sl_count >= sysctl_mld_max_msf) {
+ if (psl && psl->sl_count >= READ_ONCE(sysctl_mld_max_msf)) {
err = -ENOBUFS;
goto done;
}
- if (!psl || psl->sl_count == psl->sl_max) {
- struct ip6_sf_socklist *newpsl;
- int count = IP6_SFBLOCK;
-
- if (psl)
- count += psl->sl_max;
- newpsl = sock_kmalloc(sk, struct_size(newpsl, sl_addr, count),
- GFP_KERNEL);
- if (!newpsl) {
- err = -ENOBUFS;
- goto done;
- }
- newpsl->sl_max = count;
- newpsl->sl_count = count - IP6_SFBLOCK;
- if (psl) {
- for (i = 0; i < psl->sl_count; i++)
- newpsl->sl_addr[i] = psl->sl_addr[i];
- atomic_sub(struct_size(psl, sl_addr, psl->sl_max),
- &sk->sk_omem_alloc);
+ if (psl) {
+ for (i = 0; i < psl->sl_count; i++) {
+ if (ipv6_addr_equal(&psl->sl_addr[i], source))
+ goto done; /* err = -EADDRNOTAVAIL */
}
- rcu_assign_pointer(pmc->sflist, newpsl);
- kfree_rcu(psl, rcu);
- psl = newpsl;
}
- rv = 1; /* > 0 for insert logic below if sl_count is 0 */
- for (i = 0; i < psl->sl_count; i++) {
- rv = !ipv6_addr_equal(&psl->sl_addr[i], source);
- if (rv == 0) /* There is an error in the address. */
- goto done;
+
+ i = psl ? psl->sl_count + 1 : 1;
+ newpsl = sock_kmalloc(sk, struct_size(newpsl, sl_addr, i),
+ GFP_KERNEL);
+ if (!newpsl) {
+ err = -ENOBUFS;
+ goto done;
}
- for (j = psl->sl_count-1; j >= i; j--)
- psl->sl_addr[j+1] = psl->sl_addr[j];
- psl->sl_addr[i] = *source;
- psl->sl_count++;
- err = 0;
+ newpsl->sl_max = i;
+ newpsl->sl_count = i;
+ if (psl) {
+ for (j = 0; j < psl->sl_count; j++)
+ newpsl->sl_addr[j] = psl->sl_addr[j];
+ }
+ newpsl->sl_addr[i - 1] = *source;
+
/* update the interface list */
ip6_mc_add_src(idev, group, omode, 1, source, 1);
+
+ if (psl)
+ atomic_sub(struct_size(psl, sl_addr, psl->sl_max),
+ &sk->sk_omem_alloc);
+ rcu_assign_pointer(pmc->sflist, newpsl);
+ kfree_rcu(psl, rcu);
+ err = 0;
done:
mutex_unlock(&idev->mc_lock);
in6_dev_put(idev);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 019/877] media: video-i2c: fix buffer queue ordering
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 018/877] ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 020/877] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
` (865 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arash Golgol, Hans Verkuil,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arash Golgol <arash.golgol@gmail.com>
[ Upstream commit bc4574c265ed738849e46d942617100580fcedd2 ]
Queued buffers are added to the tail of vid_cap_active in
buffer_queue(), but the capture kthread also retrieves buffers from
the tail of the list.
This makes the queue behave as LIFO instead of FIFO when multiple
buffers are queued.
Fix this by retrieving buffers from the head of the list.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/i2c/video-i2c.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/media/i2c/video-i2c.c b/drivers/media/i2c/video-i2c.c
index a091fd6d3e607..a4ddc10c5f22e 100644
--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -465,8 +465,9 @@ static int video_i2c_thread_vid_cap(void *priv)
spin_lock(&data->slock);
if (!list_empty(&data->vid_cap_active)) {
- vid_cap_buf = list_last_entry(&data->vid_cap_active,
- struct video_i2c_buffer, list);
+ vid_cap_buf = list_first_entry(&data->vid_cap_active,
+ struct video_i2c_buffer,
+ list);
list_del(&vid_cap_buf->list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 020/877] ipv6: Select best matching nexthop object in fib6_table_lookup()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 019/877] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 021/877] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
` (864 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, David Ahern,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit 484bb9d164df397a53e0f533b262b27b1590efcb ]
Currently, when using multipath routes without nexthop objects,
fib6_table_lookup() selects the nexthop with the highest score. This
means that when both a source address and an oif are specified, the
nexthop that is chosen is the one that matches in terms of oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip address add 2001:db8:2::1/64 dev lo
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
When using nexthop objects, fib6_table_lookup() selects the first
matching nexthop and not necessarily the one with the highest score:
# ip nexthop add id 1 via fe80::1 dev dummy1
# ip nexthop add id 2 via fe80::2 dev dummy2
# ip nexthop add id 3 group 1/2
# ip route add 2001:db8:20::/64 nhid 3
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
This is not very significant right now because the nexthop is later
overwritten during path selection in fib6_select_path(). However, the
next patch is going to skip path selection when we have an oif match
during output route lookup.
As a preparation for this change, align the nexthop object behavior with
the legacy one and make sure that fib6_table_lookup() always selects the
best matching nexthop. Do that by always returning 0 from
rt6_nh_find_match() in order not to terminate the loop in
nexthop_for_each_fib6_nh() and storing in arg->nh the best matching
nexthop so far.
Behavior after the change:
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260611154605.992528-2-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index 19c970978e863..b30cb180009b1 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -820,9 +820,11 @@ static int rt6_nh_find_match(struct fib6_nh *nh, void *_arg)
{
struct fib6_nh_frl_arg *arg = _arg;
- arg->nh = nh;
- return find_match(nh, arg->flags, arg->oif, arg->strict,
- arg->mpri, arg->do_rr);
+ if (find_match(nh, arg->flags, arg->oif, arg->strict, arg->mpri,
+ arg->do_rr))
+ arg->nh = nh;
+
+ return 0;
}
static void __find_rr_leaf(struct fib6_info *f6i_start,
@@ -862,11 +864,10 @@ static void __find_rr_leaf(struct fib6_info *f6i_start,
res->nh = nexthop_fib6_nh(f6i->nh);
return;
}
- if (nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
- &arg)) {
- matched = true;
- nh = arg.nh;
- }
+ nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
+ &arg);
+ matched = !!arg.nh;
+ nh = arg.nh;
} else {
nh = f6i->fib6_nh;
if (find_match(nh, f6i->fib6_flags, oif, strict,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 021/877] ipv6: Honor oif when choosing nexthop for locally generated traffic
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 020/877] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 022/877] pidfd: hold exec_update_lock around namespace ioctl Greg Kroah-Hartman
` (863 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Ahern, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit d25e7e9d8a6c1e2afb854613e417c6aa1a28ce6f ]
Commit 741a11d9e410 ("net: ipv6: Add RT6_LOOKUP_F_IFACE flag if oif is
set") made the kernel honor the oif parameter when specified as part of
output route lookup:
# ip route add 2001:db8:1::/64 dev dummy1
# ip route add ::/0 dev dummy2
# ip route get 2001:db8:1::1 oif dummy2 fibmatch
default dev dummy2 metric 1024 pref medium
Due to regression reports, the behavior was partially reverted in commit
d46a9d678e4c ("net: ipv6: Dont add RT6_LOOKUP_F_IFACE flag if saddr
set") to only honor the oif if source address is not specified:
# ip route get 2001:db8:1::1 from 2001:db8:2::1 oif dummy2 fibmatch
2001:db8:1::/64 dev dummy1 metric 1024 pref medium
That is, when source address is specified, the kernel will choose the
most specific route even if its nexthop device does not match the
specified oif.
This creates a problem for multipath routes. After looking up a route,
when source address is not specified, the kernel will choose a nexthop
whose nexthop device matches the specified oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But will disregard the oif when source address is specified despite the
fact that a matching nexthop exists:
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
53 dummy1
47 dummy2
This behavior differs from IPv4:
# ip address add 192.0.2.1/32 dev lo
# ip route add 198.51.100.0/24 nexthop via inet6 fe80::1 dev dummy1 nexthop via inet6 fe80::2 dev dummy2
# for i in {1..100}; do ip route get 198.51.100.${i} from 192.0.2.1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
What happens is that fib6_table_lookup() returns a route with a matching
nexthop device (assuming it exists):
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But it is later overwritten during path selection in fib6_select_path()
which instead chooses a nexthop according to the calculated hash.
Solve this by telling fib6_select_path() to skip path selection if we
have an oif match during output route lookup (iif being
LOOPBACK_IFINDEX).
Behavior after the change:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Note that enabling forwarding is only needed because we did not add
neighbor entries for the gateway addresses. When forwarding is disabled
and CONFIG_IPV6_ROUTER_PREF is not enabled in kernel config, the kernel
will treat non-existing neighbor entries as errors and perform
round-robin between the nexthops:
# sysctl -wq net.ipv6.conf.all.forwarding=0
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
50 dummy1
50 dummy2
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260611154605.992528-3-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index b30cb180009b1..15f02882be040 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -2269,6 +2269,7 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
{
struct fib6_result res = {};
struct rt6_info *rt = NULL;
+ bool have_oif_match;
int strict = 0;
WARN_ON_ONCE((flags & RT6_LOOKUP_F_DST_NOREF) &&
@@ -2285,7 +2286,9 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
if (res.f6i == net->ipv6.fib6_null_entry)
goto out;
- fib6_select_path(net, &res, fl6, oif, false, skb, strict);
+ have_oif_match = fl6->flowi6_iif == LOOPBACK_IFINDEX &&
+ oif == res.nh->fib_nh_dev->ifindex;
+ fib6_select_path(net, &res, fl6, oif, have_oif_match, skb, strict);
/*Search through exception table */
rt = rt6_find_cached_rt(&res, &fl6->daddr, &fl6->saddr);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 022/877] pidfd: hold exec_update_lock around namespace ioctl
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 021/877] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 023/877] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
` (862 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen Linxuan,
Christian Brauner (Amutable), Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Linxuan <me@black-desk.cn>
[ Upstream commit 9688a46802939da28f00cb40e8129615d5d4af39 ]
The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem
credentials ptrace access check before handing out a namespace file
descriptor. The accompanying comment states that the code "mirrors nsfs
behavior", but, unlike the corresponding procfs paths, it does so without
holding the target task's exec_update_lock.
proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for
reading around the ptrace check and the namespace lookup, so that the
credentials used for the access decision match those of the task when its
namespace is read. Without it, a caller can pass the check against the
target's old credentials and then read the namespace after the target has
execve()'d a setuid binary and committed new credentials -- accessing
namespace information it should have been denied.
Hold exec_update_lock for reading around the ptrace check and the
namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment
already claims. open_namespace() itself runs outside the lock: once a
namespace reference is obtained it carries its own refcount and is opened
with the caller's own credentials, so a concurrent execve() on the target
can no longer affect the outcome.
Fixes: 5b08bd408534 ("pidfs: allow retrieval of namespace file descriptors")
Cc: stable@vger.kernel.org
Signed-off-by: Chen Linxuan <me@black-desk.cn>
Link: https://patch.msgid.link/20260731-pidfd-exec-update-lock-v1-1-b388f2f3a8b0@black-desk.cn
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/pidfs.c | 43 +++++++++++++++++++++++++++++++------------
1 file changed, 31 insertions(+), 12 deletions(-)
diff --git a/fs/pidfs.c b/fs/pidfs.c
index 5a8d8eb8df23b..b2dc613a64f6f 100644
--- a/fs/pidfs.c
+++ b/fs/pidfs.c
@@ -122,6 +122,7 @@ static long pidfd_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
struct pid *pid = pidfd_pid(file);
struct ns_common *ns_common = NULL;
struct pid_namespace *pid_ns;
+ int error;
if (arg)
return -EINVAL;
@@ -130,20 +131,33 @@ static long pidfd_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
if (!task)
return -ESRCH;
+ /*
+ * We're trying to open a file descriptor to the namespace so perform a
+ * filesystem cred ptrace check. Hold @task's exec_update_lock for the
+ * duration of the ptrace check and the namespace lookup so that the
+ * credentials used for the access decision match those of @task at the
+ * time its namespace is read, preventing a concurrent execve() from
+ * swapping the task's credentials in between the check and the use. We
+ * mirror nsfs behavior.
+ */
+ error = down_read_killable(&task->signal->exec_update_lock);
+ if (error)
+ return error;
+
+ if (!ptrace_may_access(task, PTRACE_MODE_READ_FSCREDS)) {
+ error = -EACCES;
+ goto out_unlock;
+ }
+
scoped_guard(task_lock, task) {
nsp = task->nsproxy;
if (nsp)
get_nsproxy(nsp);
}
- if (!nsp)
- return -ESRCH; /* just pretend it didn't exist */
-
- /*
- * We're trying to open a file descriptor to the namespace so perform a
- * filesystem cred ptrace check. Also, we mirror nsfs behavior.
- */
- if (!ptrace_may_access(task, PTRACE_MODE_READ_FSCREDS))
- return -EACCES;
+ if (!nsp) {
+ error = -ESRCH; /* just pretend it didn't exist */
+ goto out_unlock;
+ }
switch (cmd) {
/* Namespaces that hang of nsproxy. */
@@ -211,11 +225,16 @@ static long pidfd_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
}
break;
default:
- return -ENOIOCTLCMD;
+ error = -ENOIOCTLCMD;
}
- if (!ns_common)
- return -EOPNOTSUPP;
+ if (!error && !ns_common)
+ error = -EOPNOTSUPP;
+
+out_unlock:
+ up_read(&task->signal->exec_update_lock);
+ if (error)
+ return error;
/* open_namespace() unconditionally consumes the reference */
return open_namespace(ns_common);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 023/877] xfrm: avoid RCU warnings around the per-netns netlink socket
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 022/877] pidfd: hold exec_update_lock around namespace ioctl Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 024/877] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
` (861 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sabrina Dubroca, Simon Horman,
Steffen Klassert, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sabrina Dubroca <sd@queasysnail.net>
[ Upstream commit d87f8bc47fbf012a7f115e311d0603d97e47c34c ]
net->xfrm.nlsk is used in 2 types of contexts:
- fully under RCU, with rcu_read_lock + rcu_dereference and a NULL check
- in the netlink handlers, with requests coming from a userspace socket
In the 2nd case, net->xfrm.nlsk is guaranteed to stay non-NULL and the
object is alive, since we can't enter the netns destruction path while
the user socket holds a reference on the netns.
After adding the __rcu annotation to netns_xfrm.nlsk (which silences
sparse warnings in the RCU users and __net_init code), we need to tell
sparse that the 2nd case is safe. Add a helper for that.
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Stable-dep-of: d1ebd9081879 ("xfrm: fix compat ALLOCSPI request use-after-free")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/netns/xfrm.h | 2 +-
net/xfrm/xfrm_user.c | 25 +++++++++++++++++--------
2 files changed, 18 insertions(+), 9 deletions(-)
diff --git a/include/net/netns/xfrm.h b/include/net/netns/xfrm.h
index 23dd647fe0248..b73983a17e088 100644
--- a/include/net/netns/xfrm.h
+++ b/include/net/netns/xfrm.h
@@ -59,7 +59,7 @@ struct netns_xfrm {
struct list_head inexact_bins;
- struct sock *nlsk;
+ struct sock __rcu *nlsk;
struct sock *nlsk_stash;
u32 sysctl_aevent_etime;
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 904c9328852f0..c37f8e518f1e3 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -35,6 +35,15 @@
#endif
#include <linux/unaligned.h>
+static struct sock *xfrm_net_nlsk(const struct net *net, const struct sk_buff *skb)
+{
+ /* get the source of this request, see netlink_unicast_kernel */
+ const struct sock *sk = NETLINK_CB(skb).sk;
+
+ /* sk is refcounted, the netns stays alive and nlsk with it */
+ return rcu_dereference_protected(net->xfrm.nlsk, sk->sk_net_refcnt);
+}
+
static int verify_one_alg(struct nlattr **attrs, enum xfrm_attr_type_t type,
struct netlink_ext_ack *extack)
{
@@ -1662,7 +1671,7 @@ static int xfrm_get_spdinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_spdinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static inline unsigned int xfrm_sadinfo_msgsize(void)
@@ -1722,7 +1731,7 @@ static int xfrm_get_sadinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_sadinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -1742,7 +1751,7 @@ static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
}
xfrm_state_put(x);
out_noput:
@@ -1833,7 +1842,7 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
}
}
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
xfrm_state_put(x);
@@ -2476,7 +2485,7 @@ static int xfrm_get_default(struct sk_buff *skb, struct nlmsghdr *nlh,
r_up->out = READ_ONCE(net->xfrm.policy_default[XFRM_POLICY_OUT]);
nlmsg_end(r_skb, r_nlh);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, portid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, portid);
}
static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -2542,7 +2551,7 @@ static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb,
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb,
NETLINK_CB(skb).portid);
}
} else {
@@ -2721,7 +2730,7 @@ static int xfrm_get_ae(struct sk_buff *skb, struct nlmsghdr *nlh,
return err;
}
- err = nlmsg_unicast(net->xfrm.nlsk, r_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, NETLINK_CB(skb).portid);
spin_unlock_bh(&x->lock);
xfrm_state_put(x);
return err;
@@ -3393,7 +3402,7 @@ static int xfrm_user_rcv_msg(struct sk_buff *skb, struct nlmsghdr *nlh,
goto err;
}
- err = netlink_dump_start(net->xfrm.nlsk, skb, nlh, &c);
+ err = netlink_dump_start(xfrm_net_nlsk(net, skb), skb, nlh, &c);
goto err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 024/877] xfrm: fix compat ALLOCSPI request use-after-free
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 023/877] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 025/877] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
` (860 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, David Lee,
Steffen Klassert, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 ]
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Co-developed-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_user.c | 12 ------------
1 file changed, 12 deletions(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index c37f8e518f1e3..c1e753d554e75 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -1765,7 +1765,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
struct net *net = sock_net(skb->sk);
struct xfrm_state *x;
struct xfrm_userspi_info *p;
- struct xfrm_translator *xtr;
struct sk_buff *resp_skb;
xfrm_address_t *daddr;
int family;
@@ -1831,17 +1830,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
goto out;
}
- xtr = xfrm_get_translator();
- if (xtr) {
- err = xtr->alloc_compat(skb, nlmsg_hdr(skb));
-
- xfrm_put_translator(xtr);
- if (err) {
- kfree_skb(resp_skb);
- goto out;
- }
- }
-
err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 025/877] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 024/877] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 026/877] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
` (859 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot, Eric Dumazet,
Steffen Klassert, Liu Jian, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 ]
syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():
WARNING: suspicious RCU usage in ip6_pkt_drop
include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!
Call Trace:
__in6_dev_get_safely include/net/addrconf.h:389 [inline]
ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through
workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue,
the reinjection loop ceased running in softirq context. Workqueue workers
run in process context where local_bh_disable() does not enter an RCU
read-side critical section under CONFIG_PREEMPT_RCU.
Because finish callbacks (such as ip6_rcv_finish) expect to run under an
RCU read lock (performing route lookups, l3mdev lookups, and accessing
RCU-protected data structures), invoking them in workqueue context without
rcu_read_lock() triggers RCU lockdep warnings.
Furthermore, packets queued to the workqueue via xfrm_trans_queue_net()
may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).
Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev
with blackhole_netdev, so dst entries do not keep skb->dev alive while
queued in the workqueue.
Fix these issues by:
1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the
caller's RCU section to ensure dst is reference-counted before queuing.
2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue
deferral so skb->dev remains valid during finish() callback processing.
3. Acquiring rcu_read_lock() around the finish callback invocation loop in
xfrm_trans_reinject().
Fixes: 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Cc: Liu Jian <liujian56@huawei.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_input.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/xfrm/xfrm_input.c b/net/xfrm/xfrm_input.c
index 5d3633ce6ba32..1be187b980461 100644
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -778,12 +778,17 @@ static void xfrm_trans_reinject(struct work_struct *work)
spin_unlock_bh(&trans->queue_lock);
local_bh_disable();
+ rcu_read_lock();
while ((skb = __skb_dequeue(&queue))) {
struct net *net = XFRM_TRANS_SKB_CB(skb)->net;
+ struct net_device *dev = skb->dev;
XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
+ if (dev)
+ dev_put(dev);
put_net(net);
}
+ rcu_read_unlock();
local_bh_enable();
}
@@ -799,12 +804,18 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
if (skb_queue_len(&trans->queue) >= READ_ONCE(net_hotdata.max_backlog))
return -ENOBUFS;
+ if (skb_dst(skb) && !skb_dst_force(skb))
+ return -EHOSTUNREACH;
+
BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));
hold_net = maybe_get_net(net);
if (!hold_net)
return -ENODEV;
+ if (skb->dev)
+ dev_hold(skb->dev);
+
XFRM_TRANS_SKB_CB(skb)->finish = finish;
XFRM_TRANS_SKB_CB(skb)->net = hold_net;
spin_lock_bh(&trans->queue_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 026/877] esp: downgrade zerocopy managed frags before mutating skb frags
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 025/877] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 027/877] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
` (858 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maher Azzouzi, Steffen Klassert,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maher Azzouzi <maherazz04@gmail.com>
[ Upstream commit f89416eb3db151170a6f3c6dfc5239d26cdce4d2 ]
On the out-of-place output path (esp->inplace == false) ESP rewrites the
skb frag array: esp_output_head() appends a trailer frag and
esp_output_tail() replaces the frags with a destination page, both
referenced with get_page().
When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the
payload frags are owned by the ubuf and must not be referenced or
unreferenced individually, but ESP mutates the frag array without ever
downgrading the skb. This breaks the managed-frag invariant two ways:
- esp_ssg_unref() walks the source scatterlist and drops a page
reference for every frag, including the ubuf-owned payload frags,
pushing their refcount below the GUP pin bias while the pages are
still pinned, i.e. a use-after-free of the zerocopy pages;
- esp_output_tail() installs its destination page as frag 0 with
get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so
skb_release_data() takes the skip_unref branch and never drops that
reference, leaking the x->xfrag page at packet rate.
Fix this the way every other frag-mutating site does (__ip_append_data(),
__ip6_append_data(), tcp_sendmsg_locked()) and call
skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes
a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,
so the per-frag unref in esp_ssg_unref() and the frag release in
skb_release_data() are both balanced and no mixed-ownership frag array is
left behind.
Fixes: 753f1ca4e1e5 ("net: introduce managed frags infrastructure")
Signed-off-by: Maher Azzouzi <maherazz04@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/esp4.c | 6 ++++++
net/ipv6/esp6.c | 6 ++++++
2 files changed, 12 insertions(+)
diff --git a/net/ipv4/esp4.c b/net/ipv4/esp4.c
index 6c8c789ded0e4..fb78dc6b7e148 100644
--- a/net/ipv4/esp4.c
+++ b/net/ipv4/esp4.c
@@ -438,6 +438,12 @@ int esp_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info *
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
diff --git a/net/ipv6/esp6.c b/net/ipv6/esp6.c
index 80981596236ab..7411aac0707b2 100644
--- a/net/ipv6/esp6.c
+++ b/net/ipv6/esp6.c
@@ -467,6 +467,12 @@ int esp6_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 027/877] ARM: socfpga: select the PL310 erratum 753970 workaround
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 026/877] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 028/877] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
` (857 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Dinh Nguyen,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit cfc1e9a543e3589ba200795b6e7fd8ef4314efdf ]
ARCH_INTEL_SOCFPGA selects CACHE_L2X0 and several PL310 erratum
workarounds. The 753970 workaround is still conditioned on PL310, but that
Kconfig symbol no longer exists, so this one selection is always disabled.
Select PL310_ERRATA_753970 directly, consistently with the other PL310
workarounds required by the platform.
Fixes: fbc125afdc50 ("ARM: socfpga: Turn on ARM errata for L2 cache")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-socfpga/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-socfpga/Kconfig b/arch/arm/mach-socfpga/Kconfig
index eb72c240c2486..528c5c1368c37 100644
--- a/arch/arm/mach-socfpga/Kconfig
+++ b/arch/arm/mach-socfpga/Kconfig
@@ -16,7 +16,7 @@ menuconfig ARCH_INTEL_SOCFPGA
select ARM_ERRATA_775420
select PL310_ERRATA_588369
select PL310_ERRATA_727915
- select PL310_ERRATA_753970 if PL310
+ select PL310_ERRATA_753970
select PL310_ERRATA_769419
select RESET_CONTROLLER
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 028/877] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 027/877] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 029/877] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
` (856 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Guoqing Jiang,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit 32cd87f54dd1070020e664ccb0312a9f0fea79b4 ]
We need to clear cep before release state_lock as siw_qp_llp_close and
siw_qp_modify->siw_qp_llp_close did.
Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock
is released before the error path cleanup. A concurrent ibv_modify_qp()
transitioning the QP to ERROR can race in this window:
siw_accept() ibv_modify_qp(ERROR)
---------------------- ----------------------
siw_qp_modify() fails
up_write(&qp->state_lock)
down_write(&qp->state_lock)
nextstate_from_idle():
if (qp->cep)
siw_cep_put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw_cep_get(),
all under the write lock held from the initial down_write(&qp->state_lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw_accept() is done with it.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://lore.kernel.org/linux-rdma/d6fbe475-a5c2-f975-99b0-a0bd6b6d10e8@linux.dev/T/#m5876c1ff2de8686a9a1173b8f1aa0ff5363a785c
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://patch.msgid.link/20260827125553.12831-1-guoqing.jiang@linux.dev
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index bb7d909639071..04fabab440581 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1669,9 +1669,12 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
SIW_QP_ATTR_STATE | SIW_QP_ATTR_LLP_HANDLE |
SIW_QP_ATTR_ORD | SIW_QP_ATTR_IRD |
SIW_QP_ATTR_MPA);
+ if (rv) {
+ qp->cep = NULL;
+ siw_cep_put(cep);
+ goto error_unlock;
+ }
up_write(&qp->state_lock);
- if (rv)
- goto error;
siw_dbg_cep(cep, "[QP %u]: send mpa reply, %d byte pdata\n",
qp_id(qp), params->private_data_len);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 029/877] RDMA/rxe: validate access flags before swapping the MRs PD
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 028/877] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 030/877] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
` (855 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
[ Upstream commit ae36a5b609ae79f4de966328b78d2584be9719a4 ]
rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then
validates the IB_MR_REREG_ACCESS argument:
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
if (flags & IB_MR_REREG_ACCESS) {
if (access & ~RXE_ACCESS_SUPPORTED_MR)
return ERR_PTR(-EOPNOTSUPP);
mr->access = access;
}
Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is
IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error
without undoing the reassignment, so mr->pd == new_pd while the usecnts
still charge the MR to orig_pd. ib_dereg_mr_user() then decrements
new_pd, whose count can reach zero while a memory window still references
it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup()
writes to freed memory:
BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0
Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591
__rxe_put+0x31/0xa0
rxe_mw_cleanup+0x42/0x200
__rxe_cleanup+0x115/0x370
rxe_dealloc_mw+0x4c/0x80
Allocated by task 591:
ib_uverbs_alloc_pd+0x258/0x540
Freed by task 591:
ib_dealloc_pd_user+0x174/0x210
uverbs_free_pd+0x8d/0xc0
ib_uverbs_dealloc_pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Fixes: 544c7f62cf32 ("RDMA/rxe: Implement rereg_user_mr")
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/46E1D5C0-24BE-4D01-BDB3-634FE09B22C5@doyensec.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_verbs.c b/drivers/infiniband/sw/rxe/rxe_verbs.c
index 9466fed6726b4..da3bad301efab 100644
--- a/drivers/infiniband/sw/rxe/rxe_verbs.c
+++ b/drivers/infiniband/sw/rxe/rxe_verbs.c
@@ -1326,19 +1326,20 @@ static struct ib_mr *rxe_rereg_user_mr(struct ib_mr *ibmr, int flags,
if (err)
return ERR_PTR(err);
+ if ((flags & IB_MR_REREG_ACCESS) &&
+ (access & ~RXE_ACCESS_SUPPORTED_MR)) {
+ rxe_err_mr(mr, "access = %#x not supported\n", access);
+ return ERR_PTR(-EOPNOTSUPP);
+ }
+
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
- if (flags & IB_MR_REREG_ACCESS) {
- if (access & ~RXE_ACCESS_SUPPORTED_MR) {
- rxe_err_mr(mr, "access = %#x not supported\n", access);
- return ERR_PTR(-EOPNOTSUPP);
- }
+ if (flags & IB_MR_REREG_ACCESS)
mr->access = access;
- }
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 030/877] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 029/877] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 031/877] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
` (854 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gang Yan, Zhu Yanjun, Shukai Ni,
Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gang Yan <yangang@kylinos.cn>
[ Upstream commit d10e2a08799e858d3e71ea4169bcd018f216d444 ]
mr_check_range() validates that [iova, iova+length) falls within the
registered MR range using wraparound-prone arithmetic:
if (iova < mr->ibmr.iova ||
iova + length > mr->ibmr.iova + mr->ibmr.length)
A remote peer can craft an RDMA-Write/Read RETH so that iova + length
wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the
check. rxe_mr_iova_to_index() then computes a huge index (int idx, only
guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences
mr->page_info[huge], causing an out-of-bounds read/write and a kernel
oops that is triggerable by an unauthenticated remote peer.
Rewrite the check in overflow-safe form; the first two clauses guarantee
that the subsequent subtractions do not underflow:
if (iova < mr->ibmr.iova ||
length > mr->ibmr.length ||
iova - mr->ibmr.iova > mr->ibmr.length - length)
With the fix, mr_check_range() returns -EINVAL for the crafted iova and
the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Signed-off-by: Gang Yan <yangang@kylinos.cn>
Link: https://patch.msgid.link/20260814093740.292954-1-gang.yan@linux.dev
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Reviewed-by: Shukai Ni <shukai.ni@kuleuven.be>
Tested-by: Shukai Ni <shukai.ni@kuleuven.be>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mr.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mr.c b/drivers/infiniband/sw/rxe/rxe_mr.c
index da3dee520876a..83e325b76f67d 100644
--- a/drivers/infiniband/sw/rxe/rxe_mr.c
+++ b/drivers/infiniband/sw/rxe/rxe_mr.c
@@ -33,7 +33,8 @@ int mr_check_range(struct rxe_mr *mr, u64 iova, size_t length)
case IB_MR_TYPE_USER:
case IB_MR_TYPE_MEM_REG:
if (iova < mr->ibmr.iova ||
- iova + length > mr->ibmr.iova + mr->ibmr.length) {
+ length > mr->ibmr.length ||
+ iova - mr->ibmr.iova > mr->ibmr.length - length) {
rxe_dbg_mr(mr, "iova/length out of range\n");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 031/877] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 030/877] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 032/877] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
` (853 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 32471d84a487c7fd74532bc96be56f8028cf4a3f ]
scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted
any larger value from the SCP firmware. The shared-memory reply only holds
MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array
and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB).
The missing upper bound dates back to the original SCPI DVFS support.
Reject zero and out-of-range counts in one check and return -EINVAL.
Fixes: 8cb7cf56c9fe ("firmware: add support for ARM System Control and Power Interface(SCPI) protocol")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/022802f0b38f.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scpi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scpi.c b/drivers/firmware/arm_scpi.c
index 2d33771917bb4..ec6f3d0cdd6a1 100644
--- a/drivers/firmware/arm_scpi.c
+++ b/drivers/firmware/arm_scpi.c
@@ -631,8 +631,8 @@ static struct scpi_dvfs_info *scpi_dvfs_get_info(u8 domain)
if (ret)
return ERR_PTR(ret);
- if (!buf.opp_count)
- return ERR_PTR(-ENOENT);
+ if (!buf.opp_count || buf.opp_count > MAX_DVFS_OPPS)
+ return ERR_PTR(-EINVAL);
info = kmalloc(sizeof(*info), GFP_KERNEL);
if (!info)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 032/877] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 031/877] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 033/877] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
` (852 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 70f4b78d560e592cbf3325b162424737d032fc1d ]
dvfs_get_idx() may return an out-of-range index if the SCP firmware is
buggy or returns a stale value. Only negative indexes were rejected, so a
large index walked past info->opps and could treat garbage as a clock rate
(KASAN OOB / wrong frequency to consumers). The missing upper bound dates
back to the original SCPI clock driver.
Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by SCP(System Control Processor)")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/04f9ab766e07.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-scpi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index 50ac1cd255785..598dc1fd99ade 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -85,7 +85,7 @@ static unsigned long scpi_dvfs_recalc_rate(struct clk_hw *hw,
int idx = clk->scpi_ops->dvfs_get_idx(clk->id);
const struct scpi_opp *opp;
- if (idx < 0)
+ if (idx < 0 || idx >= clk->info->count)
return 0;
opp = clk->info->opps + idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 033/877] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 032/877] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 034/877] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
` (851 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 1caceeb2d74bbe88223aea55eb8626b4c5f076fd ]
rxe_get_mcg() publishes a newly allocated multicast group in
rxe->mcg_tree before programming the backing Ethernet multicast address
with rxe_mcast_add(), which runs outside mcg_lock. A local userspace
RDMA client reaches this path with ATTACH_MCAST on a UD QP; if
rxe_mcast_add() then returns an error (for example -ENODEV when the
backing netdev has been removed, or a propagated dev_mc_add() error),
the unwind frees the published group without removing it from the tree.
A later lookup of the same MGID dereferences the freed struct rxe_mcg
from __rxe_lookup_mcg().
Fix this by keeping the new mcg private until rxe_mcast_add() succeeds.
Split the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()
before taking the tree reference, and free the still-private mcg on
failure. Because the group is never visible in mcg_tree until the
multicast address is programmed, no concurrent caller can look it up or
attach a QP to a group that is about to be torn down, so the error path
needs no conditional unwind. If another caller publishes the same MGID
while the address is being programmed, the post-add re-check under
mcg_lock finds the winner; this caller then drops its private object and
balances its own rxe_mcast_add() with rxe_mcast_del() before returning
the winner.
Reproduced by forcing the rxe_mcast_add() error return under KASAN:
without the change the next attach to the same MGID reports a
slab-use-after-free in __rxe_lookup_mcg(); with it the forced failure
returns cleanly. A no-injection attach/detach regression, including a
two-QP shared join/leave and re-attach, stays KASAN- and leak-clean.
Fixes: a926a903b7dc ("RDMA/rxe: Do not call dev_mc_add/del() under a spinlock")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260617022728.2770116-1-michael.bommarito@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +++++++++++++++++++--------
1 file changed, 36 insertions(+), 14 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mcast.c b/drivers/infiniband/sw/rxe/rxe_mcast.c
index 07ff47bae31df..c14680c9a5362 100644
--- a/drivers/infiniband/sw/rxe/rxe_mcast.c
+++ b/drivers/infiniband/sw/rxe/rxe_mcast.c
@@ -175,7 +175,9 @@ struct rxe_mcg *rxe_lookup_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
* @mgid: multicast address as a gid
* @mcg: new mcg object
*
- * Context: caller should hold rxe->mcg lock
+ * Initializes the mcg fields. The mcg is private and not yet visible in
+ * mcg_tree, so this may run without rxe->mcg_lock; __rxe_publish_mcg()
+ * makes it visible under the lock once it is ready.
*/
static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
struct rxe_mcg *mcg)
@@ -184,13 +186,22 @@ static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
memcpy(&mcg->mgid, mgid, sizeof(mcg->mgid));
INIT_LIST_HEAD(&mcg->qp_list);
mcg->rxe = rxe;
+}
- /* caller holds a ref on mcg but that will be
- * dropped when mcg goes out of scope. We need to take a ref
- * on the pointer that will be saved in the red-black tree
- * by __rxe_insert_mcg and used to lookup mcg from mgid later.
- * Inserting mcg makes it visible to outside so this should
- * be done last after the object is ready.
+/**
+ * __rxe_publish_mcg - make a fully initialized mcg visible in mcg_tree
+ * @mcg: the mcg object
+ *
+ * Context: caller must hold rxe->mcg_lock and a reference on mcg
+ */
+static void __rxe_publish_mcg(struct rxe_mcg *mcg)
+{
+ /* caller holds a ref on mcg but that will be dropped when mcg goes
+ * out of scope. We need to take a ref on the pointer that will be
+ * saved in the red-black tree by __rxe_insert_mcg and used to lookup
+ * mcg from mgid later. Inserting mcg makes it visible to outside so
+ * this is done last after the object is ready and the multicast
+ * address has been programmed.
*/
kref_get(&mcg->ref_cnt);
__rxe_insert_mcg(mcg);
@@ -228,26 +239,37 @@ static struct rxe_mcg *rxe_get_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
err = -ENOMEM;
goto err_dec;
}
+ __rxe_init_mcg(rxe, mgid, mcg);
+
+ /* program the multicast address while mcg is still private, before
+ * it is inserted into mcg_tree. dev_mc_add() may sleep so this must
+ * run outside mcg_lock. On failure mcg was never published, so a
+ * plain free is correct and the tree is untouched.
+ */
+ err = rxe_mcast_add(rxe, mgid);
+ if (err) {
+ kfree(mcg);
+ goto err_dec;
+ }
spin_lock_bh(&rxe->mcg_lock);
- /* re-check to see if someone else just added it */
+ /* re-check to see if someone else just added it while we were adding
+ * the multicast address; if so use theirs and drop ours
+ */
tmp = __rxe_lookup_mcg(rxe, mgid);
if (tmp) {
spin_unlock_bh(&rxe->mcg_lock);
+ rxe_mcast_del(rxe, mgid);
atomic_dec(&rxe->mcg_num);
kfree(mcg);
return tmp;
}
- __rxe_init_mcg(rxe, mgid, mcg);
+ __rxe_publish_mcg(mcg);
spin_unlock_bh(&rxe->mcg_lock);
- /* add mcast address outside of lock */
- err = rxe_mcast_add(rxe, mgid);
- if (!err)
- return mcg;
+ return mcg;
- kfree(mcg);
err_dec:
atomic_dec(&rxe->mcg_num);
return ERR_PTR(err);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 034/877] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 033/877] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 035/877] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
` (850 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5fe14f2ff4ccbace9a26,
Krystian Kaniewski, Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krystian Kaniewski <krystianmkaniewski@gmail.com>
[ Upstream commit ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 ]
ib_device_get_netdev() intentionally returns a referenced net_device even
when it is unregistering, so matching and cleanup callers can still find
the association. The reference keeps struct net_device allocated, but does
not guarantee that the device remains operational.
ib_get_eth_speed() uses the returned device operationally by invoking its
ethtool callback. Although that call is made under RTNL, the function does
not verify the registration state first. An asynchronous RDMA port query
can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit
have completed.
Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a
device which is being unregistered. Keeping RTNL across the check and the
ethtool operation prevents unregister from starting between them.
Keep the speed fallback and warning under RTNL as well, so the warning can
safely read netdev->name. Drop the netdev reference before releasing RTNL
once all accesses to the device are complete.
Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed from netdev")
Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5fe14f2ff4ccbace9a26
Signed-off-by: Krystian Kaniewski <krystianmkaniewski@gmail.com>
Link: https://patch.msgid.link/20260812081708.32468-1-krystianmkaniewski@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index d0bd57ac7c6aa..d6fd7db5cbbd7 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -2000,11 +2000,13 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
return -ENODEV;
rtnl_lock();
- rc = __ethtool_get_link_ksettings(netdev, &lksettings);
- rtnl_unlock();
-
- dev_put(netdev);
+ if (READ_ONCE(netdev->reg_state) != NETREG_REGISTERED) {
+ dev_put(netdev);
+ rtnl_unlock();
+ return -ENODEV;
+ }
+ rc = __ethtool_get_link_ksettings(netdev, &lksettings);
if (!rc && lksettings.base.speed != (u32)SPEED_UNKNOWN) {
netdev_speed = lksettings.base.speed;
} else {
@@ -2013,6 +2015,8 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
pr_warn("%s speed is unknown, defaulting to %u\n",
netdev->name, netdev_speed);
}
+ dev_put(netdev);
+ rtnl_unlock();
ib_get_width_and_speed(netdev_speed, lksettings.lanes,
speed, width);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 035/877] IB/iser: reject a remote invalidation of an unregistered direction
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 034/877] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 036/877] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
` (849 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Max Gurtovoy,
Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit d85f0f0a7c85756fc992c70d869706f19dac9259 ]
A write command whose data is sent entirely as immediate data is not
registered. iser_reg_mem_fastreg() takes the DMA key path and leaves
rdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has
already set dir[ISER_DIR_OUT].
iser_check_remote_inv() looks at dir[] alone and hands the descriptor to
iser_inv_desc(), which reads desc->sig_protected. A target that answers
such a command with IB_WR_SEND_WITH_INV faults the initiator.
Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends
a remote invalidation the initiator did not ask for. A target that
invalidates a direction that was never registered is in the same class,
so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: rxe_wq do_work
RIP: 0010:iser_task_rsp+0x6d6/0xec0
Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
<IRQ>
__ib_process_cq+0xe1/0x390
ib_poll_handler+0x6e/0x200
irq_poll_softirq+0x1df/0x480
? clockevents_program_event+0x2ba/0x860
? __pfx_irq_poll_softirq+0x10/0x10
handle_softirqs+0x18e/0x590
? __pfx_handle_softirqs+0x10/0x10
? __hrtimer_rearm_deferred+0x156/0x450
do_softirq+0x3b/0x60
</IRQ>
<TASK>
__local_bh_enable_ip+0x61/0x70
__alloc_skb+0x732/0x890
? _raw_spin_lock_irqsave+0x85/0xe0
? __pfx___alloc_skb+0x10/0x10
? _raw_read_unlock_irqrestore+0x16/0x50
rxe_init_packet+0x16b/0x4f0
prepare_ack_packet+0xb8/0x830
rxe_receiver+0x499/0x9980
? __pfx_rxe_receiver+0x10/0x10
? rxe_completer+0x29e5/0x38c0
? hrtimer_start_range_ns_common+0x75f/0x1730
? hrtimer_start_range_ns+0xa6/0x2c0
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? __pfx_rxe_receiver+0x10/0x10
do_work+0x144/0x470
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
Fixes: 59caaed7a72a ("IB/iser: Support the remote invalidation exception")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260819010804.641772-1-yhlee@isslab.korea.ac.kr
Reviewed-by: Max Gurtovoy <mgurtovoy@nvidia.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/ulp/iser/iser_initiator.c b/drivers/infiniband/ulp/iser/iser_initiator.c
index f5f090dc4f1eb..cf234ddbaaad5 100644
--- a/drivers/infiniband/ulp/iser/iser_initiator.c
+++ b/drivers/infiniband/ulp/iser/iser_initiator.c
@@ -599,11 +599,8 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
iser_dbg("conn %p: remote invalidation for rkey %#x\n",
iser_conn, rkey);
- if (unlikely(!iser_conn->snd_w_inv)) {
- iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
- iser_conn);
- return -EPROTO;
- }
+ if (unlikely(!iser_conn->snd_w_inv))
+ goto bad_inv;
task = iscsi_itt_to_ctask(iser_conn->iscsi_conn, hdr->itt);
if (likely(task)) {
@@ -612,12 +609,16 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
if (iser_task->dir[ISER_DIR_IN]) {
desc = iser_task->rdma_reg[ISER_DIR_IN].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
if (iser_task->dir[ISER_DIR_OUT]) {
desc = iser_task->rdma_reg[ISER_DIR_OUT].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
@@ -628,6 +629,11 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
}
return 0;
+
+bad_inv:
+ iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
+ iser_conn);
+ return -EPROTO;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 036/877] IB/isert: wait for deferred control PDU completions before releasing the connection
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 035/877] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 037/877] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
` (848 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f ]
isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and
ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work
item then runs isert_completion_put() -> isert_put_cmd(), which reads
isert_conn->conn and takes conn->cmd_lock.
Nothing orders that work item against teardown. isert_wait_conn() queues
isert_release_work, which frees isert_conn, and iscsit_close_connection()
frees the iscsit_conn right after it returns, so the queued work can run
against freed memory.
Count the deferred control PDU completions per connection and let
isert_wait_conn() wait for them before the release work is queued.
ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs
iscsit_logout_post_handler(), which ends up waiting for
conn->conn_wait_comp, and that completion is only sent by
iscsit_close_connection() after it has called iscsit_wait_conn().
Waiting for it here would deadlock. Its wait stays the existing
isert_wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert_do_control_comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620
Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
Tainted: [B]=BAD_PAGE
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: isert_comp_wq isert_do_control_comp
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? _raw_spin_unlock_irqrestore+0x3e/0x70
? isert_put_cmd+0x53d/0x620
kasan_report+0xce/0x100
? isert_put_cmd+0x53d/0x620
isert_put_cmd+0x53d/0x620
? isert_completion_put+0x305/0x330
? isert_do_control_comp+0x2ef/0x310
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 48:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x158/0x370
isert_cma_handler+0x1e3/0x2ae0
cma_cm_event_handler+0x3e/0x240
cma_ib_req_handler+0x17d9/0x4490
cm_process_work+0x41/0x330
cm_work_handler+0x5727/0xc160
process_one_work+0x633/0x1030
worker_thread+0x45b/0xd10
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Freed by task 184:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x121/0x380
iscsit_close_connection+0x7cf/0x1e60
iscsit_take_action_for_connection_exit+0x1b6/0x360
iscsi_target_tx_thread+0x472/0x690
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260821080620.1694119-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 22 ++++++++++++++++++++++
drivers/infiniband/ulp/isert/ib_isert.h | 2 ++
2 files changed, 24 insertions(+)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 6483a55170cd1..b3fc753982a38 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -21,6 +21,7 @@
#include <target/target_core_fabric.h>
#include <target/iscsi/iscsi_transport.h>
#include <linux/semaphore.h>
+#include <linux/wait_bit.h>
#include "ib_isert.h"
@@ -311,6 +312,7 @@ isert_init_conn(struct isert_conn *isert_conn)
init_completion(&isert_conn->login_req_comp);
init_waitqueue_head(&isert_conn->rem_wait);
kref_init(&isert_conn->kref);
+ atomic_set(&isert_conn->ctrl_comp_cnt, 0);
mutex_init(&isert_conn->mutex);
INIT_WORK(&isert_conn->release_work, isert_release_work);
}
@@ -1697,6 +1699,8 @@ isert_do_control_comp(struct work_struct *work)
struct isert_conn *isert_conn = isert_cmd->conn;
struct ib_device *ib_dev = isert_conn->cm_id->device;
struct iscsit_cmd *cmd = isert_cmd->iscsit_cmd;
+ /* The switch below may free isert_cmd. */
+ bool counted = isert_cmd->ctrl_counted;
isert_dbg("Cmd %p i_state %d\n", isert_cmd, cmd->i_state);
@@ -1718,6 +1722,14 @@ isert_do_control_comp(struct work_struct *work)
dump_stack();
break;
}
+
+ /*
+ * The count is what keeps isert_conn alive, so drop it last. The wait
+ * queue lives in the global hash table, not in isert_conn, so this is
+ * safe even if the waiter has already freed the connection.
+ */
+ if (counted && atomic_dec_and_test(&isert_conn->ctrl_comp_cnt))
+ wake_up_var(&isert_conn->ctrl_comp_cnt);
}
static void
@@ -1761,6 +1773,12 @@ isert_send_done(struct ib_cq *cq, struct ib_wc *wc)
case ISTATE_SEND_TEXTRSP:
isert_unmap_tx_desc(tx_desc, ib_dev);
+ /* Paired with the wait in isert_wait_conn(). */
+ isert_cmd->ctrl_counted =
+ isert_cmd->iscsit_cmd->i_state != ISTATE_SEND_LOGOUTRSP;
+ if (isert_cmd->ctrl_counted)
+ atomic_inc(&isert_conn->ctrl_comp_cnt);
+
INIT_WORK(&isert_cmd->comp_work, isert_do_control_comp);
queue_work(isert_comp_wq, &isert_cmd->comp_work);
return;
@@ -2605,6 +2623,10 @@ static void isert_wait_conn(struct iscsit_conn *conn)
isert_wait4cmds(conn);
isert_wait4logout(isert_conn);
+ /* Paired with the count taken in isert_send_done(). */
+ wait_var_event(&isert_conn->ctrl_comp_cnt,
+ !atomic_read(&isert_conn->ctrl_comp_cnt));
+
queue_work(isert_release_wq, &isert_conn->release_work);
}
diff --git a/drivers/infiniband/ulp/isert/ib_isert.h b/drivers/infiniband/ulp/isert/ib_isert.h
index 0bac5aa66c802..519b17e54bd34 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.h
+++ b/drivers/infiniband/ulp/isert/ib_isert.h
@@ -153,6 +153,7 @@ struct isert_cmd {
struct work_struct comp_work;
struct scatterlist sg;
bool ctx_init_done;
+ bool ctrl_counted;
};
static inline struct isert_cmd *tx_desc_to_cmd(struct iser_tx_desc *desc)
@@ -187,6 +188,7 @@ struct isert_conn {
struct mutex mutex;
struct kref kref;
struct work_struct release_work;
+ atomic_t ctrl_comp_cnt;
bool logout_posted;
bool snd_w_inv;
wait_queue_head_t rem_wait;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 037/877] RDMA/mad: Fix receive buffer leak when PKey enforcement fails
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 036/877] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 038/877] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
` (847 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Leon Romanovsky,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 3476c28c9addfa253f505e6bd87f1f5598b961d0 ]
ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs
ib_mad_enforce_security() before linking recv_buf onto that list. On
failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees
the ib_mad_private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL
right after ib_mad_complete_recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv_buf onto rmpp_list right after the list is initialized, so the
error path has something to free.
Fixes: 47a2b338fe63 ("IB/core: Enforce security on management datagrams")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Link: https://patch.msgid.link/20260826073216.2367-1-lirongqing@baidu.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/mad.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/mad.c b/drivers/infiniband/core/mad.c
index 96c1fd8039fb5..21f482e0243f2 100644
--- a/drivers/infiniband/core/mad.c
+++ b/drivers/infiniband/core/mad.c
@@ -1805,6 +1805,8 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
int ret;
INIT_LIST_HEAD(&mad_recv_wc->rmpp_list);
+ list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
+
ret = ib_mad_enforce_security(mad_agent_priv,
mad_recv_wc->wc->pkey_index);
if (ret) {
@@ -1813,7 +1815,6 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
return;
}
- list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
if (is_kernel_rmpp_data_response(mad_agent_priv, mad_recv_wc)) {
spin_lock_irqsave(&mad_agent_priv->lock, flags);
mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 038/877] RDMA/irdma: Enforce local fence for IB_WR_REG_MR
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 037/877] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 039/877] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
` (846 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 3fb905f07ea45b31c8f67ba6e4668de46f527e65 ]
Enforce local fence for IB_WR_REG_MR to avoid spurious
FASTREG_VALID_MKEY async events during heavy invalidation
and registration activity.
Commit 69e8e429bca2 ("RDMA/irdma: Enforce local fence for LOCAL_INV WRs")
was very similar, but was not sufficient to prevent all occurrences
of these async events.
Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260901160014.2026285-1-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index d8e101fc74ff7..97fa345635524 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -3571,7 +3571,7 @@ static int irdma_post_send(struct ib_qp *ibqp,
stag_info.total_len = iwmr->ibmr.length;
stag_info.reg_addr_pa = *palloc->level1.addr;
stag_info.first_pm_pbl_index = palloc->level1.idx;
- stag_info.local_fence = ib_wr->send_flags & IB_SEND_FENCE;
+ stag_info.local_fence = true;
if (iwmr->npages > IRDMA_MIN_PAGES_PER_FMR)
stag_info.chunk_size = 1;
err = irdma_sc_mr_fast_register(&iwqp->sc_qp, &stag_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 039/877] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 038/877] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 040/877] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
` (845 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+d396918a29afb8543e1c,
Quanye Yang, Jack Wang, Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
[ Upstream commit 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda ]
The client borrows shared CQ credits in the ADDR_RESOLVED handler via
ib_cq_pool_get(), before the peer is connected. create_cm() can return
-ERESTARTSYS from wait_event_interruptible_timeout() without destroying
the CM ID. The init_conns() and stop-and-destroy paths then call
destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards
rdma_destroy_id().
CMA serializes the handler against rdma_destroy_id() with handler_mutex,
but that does not order the GET against destroy_con_cq_qp(). If
ADDR_RESOLVED has already passed the DESTROYING check, it can take
con_mutex, GET credits, and then lose the con to kfree. Device
unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().
Set a per-connection flag under con_mutex before CQ/QP teardown so a
racing ADDR_RESOLVED cannot borrow credits after teardown has begun.
Reported-by: syzbot+d396918a29afb8543e1c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d396918a29afb8543e1c
Fixes: 3b89e92c2a95 ("RDMA/rtrs: Use new shared CQ mechanism")
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260830-rdma-rtrs-clt-cq-pool-leak-v1-1-b169434fd3df@proton.me
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 ++++++++
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 ++
2 files changed, 10 insertions(+)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index 8fa1d72bd20a4..fea3b17611c50 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -1738,6 +1738,8 @@ static void destroy_con_cq_qp(struct rtrs_clt_con *con)
/*
* Be careful here: destroy_con_cq_qp() can be called even
* create_con_cq_qp() failed, see comments there.
+ * Caller must set con->destroyed under this lock first so a
+ * racing ADDR_RESOLVED cannot ib_cq_pool_get() after we PUT/SKIP.
*/
lockdep_assert_held(&con->con_mutex);
rtrs_cq_qp_destroy(&con->c);
@@ -1772,6 +1774,10 @@ static int rtrs_rdma_addr_resolved(struct rtrs_clt_con *con)
int err;
mutex_lock(&con->con_mutex);
+ if (con->destroyed) {
+ mutex_unlock(&con->con_mutex);
+ return -ECONNABORTED;
+ }
err = create_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
if (err) {
@@ -2202,6 +2208,7 @@ static void rtrs_clt_stop_and_destroy_conns(struct rtrs_clt_path *clt_path)
break;
con = to_clt_con(clt_path->s.con[cid]);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
@@ -2368,6 +2375,7 @@ static int init_conns(struct rtrs_clt_path *clt_path)
if (con->c.cm_id) {
stop_cm(con);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.h b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
index 0f57759b3080f..e1e7c7adc9470 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
@@ -75,6 +75,8 @@ struct rtrs_clt_con {
unsigned int cpu;
struct mutex con_mutex;
int cm_err;
+ /* Set under con_mutex before CQ/QP teardown. */
+ bool destroyed;
};
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 040/877] dmaengine: sprd: Fix runtime PM reference leak in probe
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 039/877] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 041/877] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
` (844 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Frank Li, Baolin Wang,
Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit a7df136ec529ee49a789c5029bc37b98b0d4bedd ]
pm_runtime_get_sync() increments a device's usage counter even when it
fails. sprd_dma_probe() currently jumps directly to controller clock
cleanup on that error, bypassing both pm_runtime_put_noidle() and
pm_runtime_disable(). This can happen if the preceding unchecked
pm_runtime_set_active() fails and the following runtime-resume attempt
also returns an error.
Enter the existing runtime-PM unwind path instead. This drops the
reference without idling the partially initialized device, disables
runtime PM, and then releases the controller clocks. The success path
and propagated error code are unchanged.
This issue was found by a static analysis checker and confirmed by manual
source review.
Fixes: 9b3b8171f7f4 ("dmaengine: sprd: Add Spreadtrum DMA driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Link: https://patch.msgid.link/20260813153149.3953497-1-ruoyuw560@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/sprd-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dma/sprd-dma.c b/drivers/dma/sprd-dma.c
index 3f54ff37c5e05..f000d5a5add52 100644
--- a/drivers/dma/sprd-dma.c
+++ b/drivers/dma/sprd-dma.c
@@ -1212,7 +1212,7 @@ static int sprd_dma_probe(struct platform_device *pdev)
ret = pm_runtime_get_sync(&pdev->dev);
if (ret < 0)
- goto err_rpm;
+ goto err_register;
ret = dma_async_device_register(&sdev->dma_dev);
if (ret < 0) {
@@ -1234,7 +1234,6 @@ static int sprd_dma_probe(struct platform_device *pdev)
err_register:
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
-err_rpm:
sprd_dma_disable(sdev);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 041/877] wifi: virt_wifi: free skb when disconnected
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 040/877] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 042/877] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
` (843 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mariano Baragiola, Johannes Berg,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mariano Baragiola <mbaragiola@linux.com>
[ Upstream commit f9edf7cf63b96d2b776fca8d258d3c5256e40c8e ]
When the simulated link is disconnected, virt_wifi_start_xmit() returns
NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this
return value as consumed, so every packet sent while disconnected leaks its
skb.
Free the skb before returning the drop status.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Signed-off-by: Mariano Baragiola <mbaragiola@linux.com>
Link: https://patch.msgid.link/20260809124947.3590270-1-mbaragiola@linux.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index 976edacb689de..056d375e3f41f 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -432,6 +432,7 @@ static netdev_tx_t virt_wifi_start_xmit(struct sk_buff *skb,
priv->tx_packets++;
if (!priv->is_connected) {
priv->tx_failed++;
+ dev_kfree_skb_any(skb);
return NET_XMIT_DROP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 042/877] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 041/877] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 043/877] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
` (842 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Hao, Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Hao <flyingpenghao@gmail.com>
[ Upstream commit a3d722190cdef18da4878b5efc27c3c386dda248 ]
mwifiex_pcie_request_irq() registers each MSI-X vector with a per-index
dev_id (&card->msix_ctx[i]). On a request_irq() failure the cleanup loop
"for (j = 0; j < i; j++)" frees msix_entries[j].vector but passes the
failed index's &card->msix_ctx[i] as the dev_id. free_irq() matches on
(irq, dev_id), so it fails to find the action registered with
&card->msix_ctx[j]: the already-requested IRQ j is not freed (leaked) and
free_irq() warns about freeing a non-existent IRQ. Use &card->msix_ctx[j].
Fixes: 99074fc1e67b ("mwifiex: enable pcie MSIx interrupt mode support")
Signed-off-by: Peng Hao <flyingpeng@tencent.com>
Link: https://patch.msgid.link/20260828111531.56723-1-flyingpeng@tencent.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/pcie.c b/drivers/net/wireless/marvell/mwifiex/pcie.c
index 5f997becdbaa2..d36d431f53679 100644
--- a/drivers/net/wireless/marvell/mwifiex/pcie.c
+++ b/drivers/net/wireless/marvell/mwifiex/pcie.c
@@ -3068,7 +3068,7 @@ static int mwifiex_pcie_request_irq(struct mwifiex_adapter *adapter)
ret);
for (j = 0; j < i; j++)
free_irq(card->msix_entries[j].vector,
- &card->msix_ctx[i]);
+ &card->msix_ctx[j]);
pci_disable_msix(pdev);
} else {
mwifiex_dbg(adapter, MSG, "MSIx enabled!");
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 043/877] wifi: libipw: reject too-short beacon and probe responses
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 042/877] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 044/877] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
` (841 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b ]
libipw_process_probe_response() and the libipw_network_init() call it
makes assume the frame contains the full 36-byte beacon and probe
response prefix, but the ipw2100 and ipw2200 receive paths only
establish that a management frame carries the generic 24-byte
three-address header.
libipw_network_init() then computes the information element length as
stats->len - sizeof(*beacon)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() yields
65524 for a 24-byte beacon, and the parser then walks the receive
buffer as if it held almost 64 KiB of information elements, reading
past the allocation.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-2-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 2220a9814c8a6..33f5dbe274c74 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1514,6 +1514,9 @@ static void libipw_process_probe_response(struct libipw_device
#endif
unsigned long flags;
+ if (stats->len < sizeof(*beacon))
+ return;
+
LIBIPW_DEBUG_SCAN("'%*pE' (%pM): %c%c%c%c %c%c%c%c-%c%c%c%c %c%c%c%c\n",
info_element->len, info_element->data,
beacon->header.addr3,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 044/877] wifi: libipw: reject too-short association responses
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 043/877] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 045/877] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
` (840 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit adb7118b7d2cfd7e8213c17d7d2829f353017754 ]
libipw_handle_assoc_resp() reads the capability, status and aid fields
of the 30-byte association response prefix and then computes the
information element length as
stats->len - sizeof(*frame)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() turns a
frame shorter than the fixed fields into a length near 64 KiB, and the
parser then reads past the receive buffer.
Both the ipw2100 and ipw2200 management receive paths reach this
function having established only that the frame carries the generic
24-byte three-address header.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: 9e8571affd1c ("[PATCH] ieee80211: Add QoS (WME) support to the ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-3-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 33f5dbe274c74..762ed2704bf65 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1302,6 +1302,9 @@ static int libipw_handle_assoc_resp(struct libipw_device *ieee, struct libipw_as
struct libipw_network *network = &network_resp;
struct net_device *dev = ieee->dev;
+ if (stats->len < sizeof(*frame))
+ return 1;
+
network->flags = 0;
network->qos_data.active = 0;
network->qos_data.supported = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 045/877] IB/IPoIB: Avoid restoring OPER_UP after multicast flush
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 044/877] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 046/877] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
` (839 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ben Davies, Carolina Jubran,
Cosmin Ratiu, Edward Srouji, Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit 9a141d3dc869d18b2eab35e999f4790a9b84e40f ]
ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to
prevent multicast joins while ipoib_mcast_dev_flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib_ib_dev_down(). If the interface is brought
down while the flush is in progress, ipoib_ib_dev_down() clears
IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race
aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP
being cleared to terminate its rtnl_trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while
holding RTNL.
Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins
during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag.
Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
Fixes: 344bacca8cd8 ("IB/ipoib: Don't allow MC joins during light MC flush")
Reported-by: Ben Davies <ben.davies@gresearch.co.uk>
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260902-avoid-rest-oper-up-v1-1-04fcd4916cae@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +++++++
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +++++++-----
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 ++++++++--------
3 files changed, 22 insertions(+), 13 deletions(-)
diff --git a/drivers/infiniband/ulp/ipoib/ipoib.h b/drivers/infiniband/ulp/ipoib/ipoib.h
index abe0522b7df46..ee23b8d37b977 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib.h
+++ b/drivers/infiniband/ulp/ipoib/ipoib.h
@@ -87,6 +87,7 @@ enum {
IPOIB_FLAG_INITIALIZED = 1,
IPOIB_FLAG_ADMIN_UP = 2,
IPOIB_PKEY_ASSIGNED = 3,
+ IPOIB_FLAG_MCAST_FLUSH = 4,
IPOIB_FLAG_SUBINTERFACE = 5,
IPOIB_STOP_REAPER = 7,
IPOIB_FLAG_ADMIN_CM = 9,
@@ -419,6 +420,12 @@ struct ipoib_dev_priv {
const struct net_device_ops *rn_ops;
};
+static inline bool ipoib_mcast_allowed(struct ipoib_dev_priv *priv)
+{
+ return test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) &&
+ !test_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
+}
+
struct ipoib_ah {
struct net_device *dev;
struct ib_ah *ah;
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_ib.c b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
index 5cde275daa941..76850a7d300bb 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_ib.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
@@ -1235,17 +1235,19 @@ static void __ipoib_ib_dev_flush(struct ipoib_dev_priv *priv,
}
if (level == IPOIB_FLUSH_LIGHT) {
- int oper_up;
ipoib_mark_paths_invalid(dev);
- /* Set IPoIB operation as down to prevent races between:
+ /* Set MCAST_FLUSH to prevent races between:
* the flush flow which leaves MCG and on the fly joins
* which can happen during that time. mcast restart task
* should deal with join requests we missed.
+ *
+ * Do not clear OPER_UP for this; restoring it races with
+ * ipoib_ib_dev_down() and can leave OPER_UP set after the
+ * device is down.
*/
- oper_up = test_and_clear_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ set_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_mcast_dev_flush(dev);
- if (oper_up)
- set_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ clear_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_reap_dead_ahs(priv);
}
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
index 8a4ab9ff0a681..4f7639bbc7dc5 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
@@ -74,7 +74,7 @@ static void __ipoib_mcast_schedule_join_thread(struct ipoib_dev_priv *priv,
struct ipoib_mcast *mcast,
bool delay)
{
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
/*
@@ -469,7 +469,7 @@ static int ipoib_mcast_join(struct net_device *dev, struct ipoib_mcast *mcast)
int ret = 0;
if (!priv->broadcast ||
- !test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ !ipoib_mcast_allowed(priv))
return -EINVAL;
init_completion(&mcast->done);
@@ -555,7 +555,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
unsigned long delay_until = 0;
struct ipoib_mcast *mcast = NULL;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
if (ib_query_port(priv->ca, priv->port, &port_attr)) {
@@ -577,7 +577,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
netif_addr_unlock_bh(dev);
spin_lock_irq(&priv->lock);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
goto out;
if (!priv->broadcast) {
@@ -749,7 +749,7 @@ void ipoib_mcast_send(struct net_device *dev, u8 *daddr, struct sk_buff *skb)
spin_lock_irqsave(&priv->lock, flags);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) ||
+ if (!ipoib_mcast_allowed(priv) ||
!priv->broadcast ||
!test_bit(IPOIB_MCAST_FLAG_ATTACHED, &priv->broadcast->flags)) {
++dev->stats.tx_dropped;
@@ -871,7 +871,7 @@ void ipoib_mcast_restart_task(struct work_struct *work)
LIST_HEAD(remove_list);
struct ib_sa_mcmember_rec rec;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
/*
* shortcut...on shutdown flush is called next, just
* let it do all the work
@@ -965,9 +965,9 @@ void ipoib_mcast_restart_task(struct work_struct *work)
ipoib_mcast_remove_list(&remove_list);
/*
- * Double check that we are still up
+ * Double check that we are still up and not flushing
*/
- if (test_bit(IPOIB_FLAG_OPER_UP, &priv->flags)) {
+ if (ipoib_mcast_allowed(priv)) {
spin_lock_irq(&priv->lock);
__ipoib_mcast_schedule_join_thread(priv, NULL, 0);
spin_unlock_irq(&priv->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 046/877] wifi: cfg80211: dont get the radio mask for netdev-less wdevs
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 045/877] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 047/877] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
` (838 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+abff43d2d045e37c0bb2,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7783e585360ee05dfe21d3173dbbe985c94f29e ]
cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with
wdev->netdev, which can be NULL and then crashes in mac80211.
To avoid that, invert the order of checks since wdev->netdev
is always valid for beaconing interfaces.
Assisted-by: LLM
Fixes: abb4cfe3661a ("wifi: cfg80211: extend interface combination check for multi-radio")
Reported-by: syzbot+abff43d2d045e37c0bb2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=abff43d2d045e37c0bb2
Link: https://patch.msgid.link/20260904165614.2056a8b7dc91.I7412c5062d8166ad6c81ee7252cec49dea19a60f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 8478f3a0e9402..f565fb5ddd44a 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -2355,16 +2355,15 @@ static void cfg80211_calculate_bi_data(struct wiphy *wiphy, u32 new_beacon_int,
if (wdev->valid_links)
continue;
+ wdev_bi = cfg80211_wdev_bi(wdev);
+ if (!wdev_bi)
+ continue;
+
/* skip wdevs not active on the given wiphy radio */
if (radio_idx >= 0 &&
!(rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx)))
continue;
- wdev_bi = cfg80211_wdev_bi(wdev);
-
- if (!wdev_bi)
- continue;
-
if (!*beacon_int_gcd) {
*beacon_int_gcd = wdev_bi;
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 047/877] wifi: cfg80211: check IP header size in cfg80211_classify8021d()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 046/877] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:15 ` [PATCH 6.12 048/877] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
` (837 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+878ddc3962f792e9af59,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 48b2c5c628b09cf36cbeca53e0432fc2a7518be7 ]
A frame that looks like IP can be transmitted, but be too short, so
the DS field is read incorrectly:
BUG: KMSAN: uninit-value in cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
ieee80211_select_queue+0x37a/0x9e0 net/mac80211/wme.c:180
__ieee80211_subif_start_xmit+0x60f/0x1d90 net/mac80211/tx.c:4304
ieee80211_subif_start_xmit+0xa8/0x6d0 net/mac80211/tx.c:4538
...
packet_sendmsg+0x9173/0xa2a0 net/packet/af_packet.c:3108
Use skb_header_pointer() like the MPLS case.
Assisted-by: LLM
Fixes: e31a16d6f64e ("wireless: move some utility functions from mac80211 to cfg80211")
Reported-by: syzbot+878ddc3962f792e9af59@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=878ddc3962f792e9af59
Link: https://patch.msgid.link/20260904165614.5e61a4c80b92.I37d68d3f406cb3b90b32e6943418d66070b65197@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 26 ++++++++++++++++++++++----
1 file changed, 22 insertions(+), 4 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index f565fb5ddd44a..f9e0ec311982e 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -989,12 +989,30 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb,
}
switch (skb->protocol) {
- case htons(ETH_P_IP):
- dscp = ipv4_get_dsfield(ip_hdr(skb)) & 0xfc;
+ case htons(ETH_P_IP): {
+ const struct iphdr *iph;
+ struct iphdr _iph;
+
+ iph = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*iph), &_iph);
+ if (!iph)
+ return 0;
+
+ dscp = ipv4_get_dsfield(iph) & 0xfc;
break;
- case htons(ETH_P_IPV6):
- dscp = ipv6_get_dsfield(ipv6_hdr(skb)) & 0xfc;
+ }
+ case htons(ETH_P_IPV6): {
+ const struct ipv6hdr *ip6h;
+ struct ipv6hdr _ip6h;
+
+ ip6h = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*ip6h), &_ip6h);
+ if (!ip6h)
+ return 0;
+
+ dscp = ipv6_get_dsfield(ip6h) & 0xfc;
break;
+ }
case htons(ETH_P_MPLS_UC):
case htons(ETH_P_MPLS_MC): {
struct mpls_label mpls_tmp, *mpls;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 048/877] soundwire: cadence_master: wait and cancel cdns->work before clock stop
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 047/877] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
@ 2026-09-30 15:15 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 049/877] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
` (836 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:15 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, David Lin, Shuming Fan,
Pierre-Louis Bossart, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
[ Upstream commit aba7b41faeecb7692458095ce6fafc341fe0b80e ]
A peripheral event could happen during the clock stop process. We need
to wait for the event be handled before stopping the bus clock.
Otherwise, we will get the IO transfer timed out issue.
Fixes: af4cc917826f ("soundwire: cadence: mask Slave interrupt before stopping clock")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: David Lin <david.lin@intel.com>
Reviewed-by: Shuming Fan <shumingf@realtek.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260901031019.233254-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/cadence_master.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/soundwire/cadence_master.c b/drivers/soundwire/cadence_master.c
index a503ef606a62c..1557d6b044491 100644
--- a/drivers/soundwire/cadence_master.c
+++ b/drivers/soundwire/cadence_master.c
@@ -1670,6 +1670,13 @@ int sdw_cdns_clock_stop(struct sdw_cdns *cdns, bool block_wake)
return 0;
}
+ /*
+ * wait for any in-flight peripheral event handling to complete before stopping the clock.
+ * No need to disable peripheral interrupts before canceling the work, as the peripheral
+ * interrupts are already masked before the work is scheduled.
+ */
+ cancel_work_sync(&cdns->work);
+
/*
* Before entering clock stop we mask the Slave
* interrupts. This helps avoid having to deal with e.g. a
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 049/877] MIPS: Octeon: apply USB FDT fixups also when USB is modular
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-30 15:15 ` [PATCH 6.12 048/877] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 050/877] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask Greg Kroah-Hartman
` (835 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Orgad Shaneh, Thomas Bogendoerfer,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Orgad Shaneh <orgads@gmail.com>
[ Upstream commit 126f16e0a1b353c2ba5c7e2c8626cfa865934f9f ]
The uctl/usbn device-tree fixups in octeon_prune_device_tree() - which
set the board's USB reference-clock frequency and type from
__cvmx_helper_board_usb_get_clock_type() - are guarded by
"#ifdef CONFIG_USB", which is false when USB is built as a module. The
fixups then silently disappear and octeon-hcd sees whatever default the
DTS carries (12MHz crystal in octeon_3xxx.dts), leaving the PHY dead or
the bus erroring on boards with a different reference clock.
Use IS_ENABLED() so USB=m gets the same fixups as USB=y.
Fixes: 7fd57ab9d9cf ("MIPS: Octeon: Fix compile error when USB is not enabled.")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Orgad Shaneh <orgads@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/cavium-octeon/octeon-platform.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/mips/cavium-octeon/octeon-platform.c b/arch/mips/cavium-octeon/octeon-platform.c
index 5e1dd4e6e82fb..4b5c99e6f5bcc 100644
--- a/arch/mips/cavium-octeon/octeon-platform.c
+++ b/arch/mips/cavium-octeon/octeon-platform.c
@@ -17,7 +17,7 @@
#include <asm/octeon/octeon.h>
#include <asm/octeon/cvmx-helper-board.h>
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
#include <linux/usb/ehci_def.h>
#include <linux/usb/ehci_pdriver.h>
#include <linux/usb/ohci_pdriver.h>
@@ -1080,7 +1080,7 @@ int __init octeon_prune_device_tree(void)
;
}
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
/* OHCI/UHCI USB */
alias_prop = fdt_getprop(initial_boot_params, aliases,
"uctl", NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 050/877] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 049/877] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 051/877] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
` (834 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai, Marek Szyprowski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen-Yu Tsai <wenst@chromium.org>
[ Upstream commit 89461db349cc00816c01d55507d511466b3b7151 ]
When a reserved memory region described in the device tree is attached
to a device, it is expected that the device's limitations are correctly
included in that description.
However, if the device driver failed to implement DMA address masking
or addressing beyond the default 32 bits (on arm64), then bad things
could happen because the DMA address was truncated, such as playing
back audio with no actual audio coming out, or DMA overwriting random
blocks of kernel memory.
Check against the coherent DMA mask when the memory regions are attached
to the device. Give a warning when the memory region can not be covered
by the mask.
A warning instead of a hard error was chosen, because it is possible
that existing drivers could be working fine even if they forgot to
extend the coherent DMA mask.
Signed-off-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/r/20250421083930.374173-1-wenst@chromium.org
Stable-dep-of: 504981db4f69 ("dma-coherent: report a failed reserved memory assignment")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index 3b2bdca9f1d4b..77c8d9487a9ab 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -336,16 +336,22 @@ static phys_addr_t dma_reserved_default_memory_size __initdata;
static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
{
- if (!rmem->priv) {
- struct dma_coherent_mem *mem;
+ struct dma_coherent_mem *mem = rmem->priv;
+ if (!mem) {
mem = dma_init_coherent_memory(rmem->base, rmem->base,
rmem->size, true);
if (IS_ERR(mem))
return PTR_ERR(mem);
rmem->priv = mem;
}
- dma_assign_coherent_memory(dev, rmem->priv);
+
+ /* Warn if the device potentially can't use the reserved memory */
+ if (mem->device_base + rmem->size - 1 >
+ min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
+ dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
+
+ dma_assign_coherent_memory(dev, mem);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 051/877] dma-coherent: report a failed reserved memory assignment
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 050/877] dma-coherent: Warn if OF reserved memory is beyond current coherent DMA mask Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 052/877] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
` (833 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Marek Szyprowski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit 504981db4f69bdd28054fb98c96a3a67f7248dde ]
rmem_dma_device_init() drops the return value of
dma_assign_coherent_memory() and always reports success. That call fails
with -EBUSY when the device already has a coherent pool, and the file
allows only "*one* such region of memory" per device.
of_reserved_mem_device_init_by_idx() reads the zero as success. It logs
"assigned reserved memory node" for a region that was not assigned and
records the pairing, so of_reserved_mem_device_release() later runs
rmem_dma_device_release() for it. That clears dev->dma_mem without
looking at which region it was called for, dropping the pool the device
did get and leaving it on ordinary memory.
dma_declare_coherent_memory() checks the same call and releases the
memory on failure, and rmem_swiotlb_device_init() propagates its own
errors. Return the error here as well, so a device tree that assigns two
pools to one device fails the probe instead of half working.
Fixes: 7bfa5ab6fa1b ("drivers: dma-coherent: add initialization from device tree")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260905074727.108029-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index 77c8d9487a9ab..87f2f02e921a6 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -351,8 +351,7 @@ static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
- dma_assign_coherent_memory(dev, mem);
- return 0;
+ return dma_assign_coherent_memory(dev, mem);
}
static void rmem_dma_device_release(struct reserved_mem *rmem,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 052/877] dmaengine: Fix device kref underflow in dma_chan_put()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 051/877] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 053/877] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
` (832 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit 44dab659064eb5c10adb0306510eebe848ed592d ]
dma_chan_get() takes chan->device->ref only on the slow path:
/* no kref on fast path */
if (chan->client_count) {
__module_get(owner);
chan->client_count++;
return 0;
}
if (!try_module_get(owner))
return -ENODEV;
if (!dma_device_get(chan->device)) { // calls kref_get_unless_zero()
dma_chan_put() drops the ref unconditionally, so every fast-path
get/put pair drops one extra device reference.
The bug fires when two conditions hold together: a non-private
provider has a persistent client holding chan->client_count > 0
and another client cycles dmaengine_get()/dmaengine_put().
When the kref hits zero, the subsequent dma_find_channel() returns
NULL even though the provider module is still loaded.
Fix this by dropping device->ref only on the last put, matching the
single slow-path get.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-2-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index e241b7b01233e..ea3ed830061dc 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -513,7 +513,9 @@ static void dma_chan_put(struct dma_chan *chan)
chan->route_data = NULL;
}
- dma_device_put(chan->device);
+ /* This channel is not in use anymore, drop the device ref */
+ if (!chan->client_count)
+ dma_device_put(chan->device);
module_put(dma_chan_to_owner(chan));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 053/877] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 052/877] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 054/877] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
` (831 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit e873c74132f0c5f1452816cd9bb26208f0bba1e1 ]
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-3-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index ea3ed830061dc..d6a4e914018da 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -493,10 +493,13 @@ static int dma_chan_get(struct dma_chan *chan)
*/
static void dma_chan_put(struct dma_chan *chan)
{
+ struct module *owner;
+
/* This channel is not in use, bail out */
if (!chan->client_count)
return;
+ owner = dma_chan_to_owner(chan);
chan->client_count--;
/* This channel is not in use anymore, free it */
@@ -516,7 +519,7 @@ static void dma_chan_put(struct dma_chan *chan)
/* This channel is not in use anymore, drop the device ref */
if (!chan->client_count)
dma_device_put(chan->device);
- module_put(dma_chan_to_owner(chan));
+ module_put(owner);
}
enum dma_status dma_sync_wait(struct dma_chan *chan, dma_cookie_t cookie)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 054/877] dmaengine: wait for RCU readers before releasing dma_device
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 053/877] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 055/877] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
` (830 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit dc750422170a563c7a81f6e49d36bb02c62ae37f ]
dma_issue_pending_all() walks the dma_device_list with
list_for_each_entry_rcu() under rcu_read_lock(). dma_device_release()
unlinks the device with list_del_rcu() and then calls
device->device_release() (which in many drivers, such as plx_dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma_issue_pending_all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma_device struct") decoupled the dma_device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize_rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device_release() free the device themselves once
dma_async_device_unregister() returns. This call will delay for a grace
period with dma_list_mutex held, which is safe and only teardown path is
delayed.
Fixes: 2ba05622b8b1 ("dmaengine: provide a common 'issue_pending_all' implementation")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-4-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index d6a4e914018da..9a591bc15a36b 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -426,6 +426,7 @@ static void dma_device_release(struct kref *ref)
list_del_rcu(&device->global_node);
dma_channel_rebalance();
+ synchronize_rcu();
if (device->device_release)
device->device_release(device);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 055/877] wifi: cfg80211: only group hidden BSSes with beacon entries
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 054/877] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 056/877] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
` (829 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1a797e1c81be78a2ace7,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 068843ed0902c552a13860c5ec6b2ca65b57a065 ]
When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.
But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there's a group without beacon elements.
If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its
WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
WARN_ON_ONCE(!list_empty(&bss->hidden_list))
which are there because an entry without beacon elements is not supposed
to be part of a group yet.
Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.
Assisted-by: LLM
Fixes: 4593c4cbe1c9 ("cfg80211: fix BSS list hidden SSID lookup")
Reported-by: syzbot+1a797e1c81be78a2ace7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a797e1c81be78a2ace7
Link: https://patch.msgid.link/20260904165614.bcfa64715745.Iad740347c86de56d4ff4f96a95f3c3afc47c42de@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 3c439841578c4..f3b9e7a519ff9 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1960,6 +1960,13 @@ __cfg80211_bss_update(struct cfg80211_registered_device *rdev,
if (!hidden)
hidden = rb_find_bss(rdev, tmp,
BSS_CMP_HIDE_NUL);
+ /*
+ * Only group with an entry with beacon data, otherwise
+ * beacon data can never be filled/updated.
+ */
+ if (hidden &&
+ !rcu_access_pointer(hidden->pub.beacon_ies))
+ hidden = NULL;
if (hidden) {
new->pub.hidden_beacon_bss = &hidden->pub;
list_add(&new->hidden_list,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 056/877] wifi: cfg80211: dont filter by BSS type when removing stale entries
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 055/877] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 057/877] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
` (828 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+dc6f4dce0d707900cdea,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b377e1000d963e7182a987082b4b06580bd7ac84 ]
When an assoc AP switches to a channel that already has a BSS entry,
cfg80211_update_assoc_bss_entry() removes that entry before rehashing
the real one, since the two would otherwise collide in the BSS rbtree.
The lookup for that entry also required it to match the connection's BSS
type, so an entry advertising e.g. the IBSS capability bit was left in
place, and the following cfg80211_rehash_bss() then ran into it:
WARN_ON(!cmp)
Changing the type shouldn't really happen, but can be triggered by a
rogue AP/device, so drop the check and remove any entries matching
the comparison.
Assisted-by: LLM
Fixes: 0afd425b1b64 ("cfg80211: fix duplicated scan entries after channel switch")
Reported-by: syzbot+dc6f4dce0d707900cdea@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dc6f4dce0d707900cdea
Link: https://patch.msgid.link/20260904165614.1f05dae1c546.Ib52d57b57caa912efee020f9d4a033a5160617ce@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index f3b9e7a519ff9..9d21667641a50 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -3398,11 +3398,6 @@ void cfg80211_update_assoc_bss_entry(struct wireless_dev *wdev,
cbss->pub.channel = chan;
list_for_each_entry(bss, &rdev->bss_list, list) {
- if (!cfg80211_bss_type_match(bss->pub.capability,
- bss->pub.channel->band,
- wdev->conn_bss_type))
- continue;
-
if (bss == cbss)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 057/877] wifi: mac80211: dont start a ROC while scanning
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 056/877] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 058/877] wifi: cfg80211: add option for vif allowed radios Greg Kroah-Hartman
` (827 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c3a167b5615df4ccd7fb,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 733f0fde95392ed5f61a4e36aee661ea8d0e8581 ]
The ROC work can be pending when a scan starts (which requires
ROC list to be empty, but that's possible), and then a new ROC
can be added to the list and the work will pick it up.
Avoid starting that ROC if a scan made it between things, as
otherwise we'll hit a warning later:
WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0
Workqueue: events_unbound cfg80211_wiphy_work
Call Trace:
__ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537
ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513
Assisted-by: LLM
Fixes: aaa016ccd5df ("mac80211: rewrite remain-on-channel logic")
Reported-by: syzbot+c3a167b5615df4ccd7fb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c3a167b5615df4ccd7fb
Link: https://patch.msgid.link/20260904165722.f9d5b150edd8.I61bc9de8c8d089096ad695213b9c85c7df38c3bd@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/offchannel.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/mac80211/offchannel.c b/net/mac80211/offchannel.c
index 29fab7ae47b4c..0d9807526ecbd 100644
--- a/net/mac80211/offchannel.c
+++ b/net/mac80211/offchannel.c
@@ -462,6 +462,13 @@ static void __ieee80211_roc_work(struct ieee80211_local *local)
return;
if (!roc->started) {
+ /*
+ * The work can be started by a previous ROC work, but a scan
+ * can get between things; scan finish will retrigger us.
+ */
+ if (local->scanning)
+ return;
+
WARN_ON(!local->emulate_chanctx);
_ieee80211_start_next_roc(local);
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 058/877] wifi: cfg80211: add option for vif allowed radios
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 057/877] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 059/877] wifi: mac80211: use vif radio mask to limit ibss scan frequencies Greg Kroah-Hartman
` (826 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Johannes Berg,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 3607798ad9bdef35ad08489a8239390fccaac6b5 ]
This allows users to prevent a vif from affecting radios other than the
configured ones. This can be useful in cases where e.g. an AP is running
on one radio, and triggering a scan on another radio should not disturb it.
Changing the allowed radios list for a vif is supported, but only while
it is down.
While it is possible to achieve the same by always explicitly specifying
a frequency list for scan requests and ensuring that the wrong channel/band
is never accidentally set on an unrelated interface, this change makes
multi-radio wiphy setups a lot easier to deal with for CLI users.
By itself, this patch only enforces the radio mask for scanning requests
and remain-on-channel. Follow-up changes build on this to limit configured
frequencies.
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Link: https://patch.msgid.link/eefcb218780f71a1549875d149f1196486762756.1728462320.git-series.nbd@nbd.name
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: a7491b7efbd9 ("wifi: mac80211: don't warn when an IBSS has no channel to scan")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 14 +++++++++
include/uapi/linux/nl80211.h | 5 +++
net/wireless/core.c | 2 ++
net/wireless/nl80211.c | 60 +++++++++++++++++++++++++++++++-----
net/wireless/scan.c | 10 ++++--
net/wireless/util.c | 29 +++++++++++++++++
6 files changed, 109 insertions(+), 11 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index fcc5934a20c0f..f3915118c15d7 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -6353,6 +6353,7 @@ enum ieee80211_ap_reg_power {
* entered.
* @links.cac_time_ms: CAC time in ms
* @valid_links: bitmap describing what elements of @links are valid
+ * @radio_mask: Bitmask of radios that this interface is allowed to operate on.
*/
struct wireless_dev {
struct wiphy *wiphy;
@@ -6465,6 +6466,8 @@ struct wireless_dev {
unsigned int cac_time_ms;
} links[IEEE80211_MLD_MAX_NUM_LINKS];
u16 valid_links;
+
+ u32 radio_mask;
};
static inline const u8 *wdev_address(struct wireless_dev *wdev)
@@ -6650,6 +6653,17 @@ static inline bool cfg80211_channel_is_psc(struct ieee80211_channel *chan)
bool cfg80211_radio_chandef_valid(const struct wiphy_radio *radio,
const struct cfg80211_chan_def *chandef);
+/**
+ * cfg80211_wdev_channel_allowed - Check if the wdev may use the channel
+ *
+ * @wdev: the wireless device
+ * @chan: channel to check
+ *
+ * Return: whether or not the wdev may use the channel
+ */
+bool cfg80211_wdev_channel_allowed(struct wireless_dev *wdev,
+ struct ieee80211_channel *chan);
+
/**
* ieee80211_get_response_rate - get basic rate for a given rate
*
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index c2d7faf8d87fa..8ce0c143e9fde 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -2868,6 +2868,9 @@ enum nl80211_commands {
* nested item, it contains attributes defined in
* &enum nl80211_if_combination_attrs.
*
+ * @NL80211_ATTR_VIF_RADIO_MASK: Bitmask of allowed radios (u32).
+ * A value of 0 means all radios.
+ *
* @NUM_NL80211_ATTR: total number of nl80211_attrs available
* @NL80211_ATTR_MAX: highest attribute number currently defined
* @__NL80211_ATTR_AFTER_LAST: internal use
@@ -3416,6 +3419,8 @@ enum nl80211_attrs {
NL80211_ATTR_WIPHY_RADIOS,
NL80211_ATTR_WIPHY_INTERFACE_COMBINATIONS,
+ NL80211_ATTR_VIF_RADIO_MASK,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 8f7f84c5f440b..7c278b8694393 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -1456,6 +1456,8 @@ void cfg80211_init_wdev(struct wireless_dev *wdev)
/* allow mac80211 to determine the timeout */
wdev->ps_timeout = -1;
+ wdev->radio_mask = BIT(wdev->wiphy->n_radio) - 1;
+
if ((wdev->iftype == NL80211_IFTYPE_STATION ||
wdev->iftype == NL80211_IFTYPE_P2P_CLIENT ||
wdev->iftype == NL80211_IFTYPE_ADHOC) && !wdev->use_4addr)
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index b302caafd4d31..6261befa1e949 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -834,6 +834,7 @@ static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
[NL80211_ATTR_MLO_TTLM_DLINK] = NLA_POLICY_EXACT_LEN(sizeof(u16) * 8),
[NL80211_ATTR_MLO_TTLM_ULINK] = NLA_POLICY_EXACT_LEN(sizeof(u16) * 8),
[NL80211_ATTR_ASSOC_SPP_AMSDU] = { .type = NLA_FLAG },
+ [NL80211_ATTR_VIF_RADIO_MASK] = { .type = NLA_U32 },
};
/* policy for the key attributes */
@@ -3975,7 +3976,8 @@ static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flag
nla_put_u32(msg, NL80211_ATTR_GENERATION,
rdev->devlist_generation ^
(cfg80211_rdev_list_generation << 2)) ||
- nla_put_u8(msg, NL80211_ATTR_4ADDR, wdev->use_4addr))
+ nla_put_u8(msg, NL80211_ATTR_4ADDR, wdev->use_4addr) ||
+ nla_put_u32(msg, NL80211_ATTR_VIF_RADIO_MASK, wdev->radio_mask))
goto nla_put_failure;
if (rdev->ops->get_channel && !wdev->valid_links) {
@@ -4296,6 +4298,29 @@ static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
return -EOPNOTSUPP;
}
+static int nl80211_parse_vif_radio_mask(struct genl_info *info,
+ u32 *radio_mask)
+{
+ struct cfg80211_registered_device *rdev = info->user_ptr[0];
+ struct nlattr *attr = info->attrs[NL80211_ATTR_VIF_RADIO_MASK];
+ u32 mask, allowed;
+
+ if (!attr) {
+ *radio_mask = 0;
+ return 0;
+ }
+
+ allowed = BIT(rdev->wiphy.n_radio) - 1;
+ mask = nla_get_u32(attr);
+ if (mask & ~allowed)
+ return -EINVAL;
+ if (!mask)
+ mask = allowed;
+ *radio_mask = mask;
+
+ return 1;
+}
+
static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
{
struct cfg80211_registered_device *rdev = info->user_ptr[0];
@@ -4303,6 +4328,8 @@ static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
int err;
enum nl80211_iftype otype, ntype;
struct net_device *dev = info->user_ptr[1];
+ struct wireless_dev *wdev = dev->ieee80211_ptr;
+ u32 radio_mask = 0;
bool change = false;
memset(¶ms, 0, sizeof(params));
@@ -4316,8 +4343,6 @@ static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
}
if (info->attrs[NL80211_ATTR_MESH_ID]) {
- struct wireless_dev *wdev = dev->ieee80211_ptr;
-
if (ntype != NL80211_IFTYPE_MESH_POINT)
return -EINVAL;
if (otype != NL80211_IFTYPE_MESH_POINT)
@@ -4348,6 +4373,12 @@ static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
if (err > 0)
change = true;
+ err = nl80211_parse_vif_radio_mask(info, &radio_mask);
+ if (err < 0)
+ return err;
+ if (err && netif_running(dev))
+ return -EBUSY;
+
if (change)
err = cfg80211_change_iface(rdev, dev, ntype, ¶ms);
else
@@ -4356,11 +4387,11 @@ static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
if (!err && params.use_4addr != -1)
dev->ieee80211_ptr->use_4addr = params.use_4addr;
- if (change && !err) {
- struct wireless_dev *wdev = dev->ieee80211_ptr;
+ if (radio_mask)
+ wdev->radio_mask = radio_mask;
+ if (change && !err)
nl80211_notify_iface(rdev, wdev, NL80211_CMD_SET_INTERFACE);
- }
return err;
}
@@ -4371,6 +4402,7 @@ static int _nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
struct vif_params params;
struct wireless_dev *wdev;
struct sk_buff *msg;
+ u32 radio_mask;
int err;
enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
@@ -4408,6 +4440,10 @@ static int _nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
if (err < 0)
return err;
+ err = nl80211_parse_vif_radio_mask(info, &radio_mask);
+ if (err < 0)
+ return err;
+
msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
if (!msg)
return -ENOMEM;
@@ -4449,6 +4485,9 @@ static int _nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
break;
}
+ if (radio_mask)
+ wdev->radio_mask = radio_mask;
+
if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
nlmsg_free(msg);
@@ -9178,6 +9217,9 @@ static bool cfg80211_off_channel_oper_allowed(struct wireless_dev *wdev,
lockdep_assert_wiphy(wdev->wiphy);
+ if (!cfg80211_wdev_channel_allowed(wdev, chan))
+ return false;
+
if (!cfg80211_beaconing_iface_active(wdev))
return true;
@@ -9390,7 +9432,8 @@ static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
}
/* ignore disabled channels */
- if (chan->flags & IEEE80211_CHAN_DISABLED)
+ if (chan->flags & IEEE80211_CHAN_DISABLED ||
+ !cfg80211_wdev_channel_allowed(wdev, chan))
continue;
request->channels[i] = chan;
@@ -9410,7 +9453,8 @@ static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
chan = &wiphy->bands[band]->channels[j];
- if (chan->flags & IEEE80211_CHAN_DISABLED)
+ if (chan->flags & IEEE80211_CHAN_DISABLED ||
+ !cfg80211_wdev_channel_allowed(wdev, chan))
continue;
request->channels[i] = chan;
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 9d21667641a50..a7d704d0a282a 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -953,7 +953,8 @@ static int cfg80211_scan_6ghz(struct cfg80211_registered_device *rdev)
struct ieee80211_channel *chan =
ieee80211_get_channel(&rdev->wiphy, ap->center_freq);
- if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
+ if (!chan || chan->flags & IEEE80211_CHAN_DISABLED ||
+ !cfg80211_wdev_channel_allowed(rdev_req->wdev, chan))
continue;
for (i = 0; i < rdev_req->n_channels; i++) {
@@ -3519,9 +3520,12 @@ int cfg80211_wext_siwscan(struct net_device *dev,
continue;
for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
+ struct ieee80211_channel *chan;
+
/* ignore disabled channels */
- if (wiphy->bands[band]->channels[j].flags &
- IEEE80211_CHAN_DISABLED)
+ chan = &wiphy->bands[band]->channels[j];
+ if (chan->flags & IEEE80211_CHAN_DISABLED ||
+ !cfg80211_wdev_channel_allowed(creq->wdev, chan))
continue;
/* If we have a wireless request structure and the
diff --git a/net/wireless/util.c b/net/wireless/util.c
index f9e0ec311982e..8cc205b9f105c 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -2965,3 +2965,32 @@ bool cfg80211_radio_chandef_valid(const struct wiphy_radio *radio,
return true;
}
EXPORT_SYMBOL(cfg80211_radio_chandef_valid);
+
+bool cfg80211_wdev_channel_allowed(struct wireless_dev *wdev,
+ struct ieee80211_channel *chan)
+{
+ struct wiphy *wiphy = wdev->wiphy;
+ const struct wiphy_radio *radio;
+ struct cfg80211_chan_def chandef;
+ u32 radio_mask;
+ int i;
+
+ radio_mask = wdev->radio_mask;
+ if (!wiphy->n_radio || radio_mask == BIT(wiphy->n_radio) - 1)
+ return true;
+
+ cfg80211_chandef_create(&chandef, chan, NL80211_CHAN_HT20);
+ for (i = 0; i < wiphy->n_radio; i++) {
+ if (!(radio_mask & BIT(i)))
+ continue;
+
+ radio = &wiphy->radio[i];
+ if (!cfg80211_radio_chandef_valid(radio, &chandef))
+ continue;
+
+ return true;
+ }
+
+ return false;
+}
+EXPORT_SYMBOL(cfg80211_wdev_channel_allowed);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 059/877] wifi: mac80211: use vif radio mask to limit ibss scan frequencies
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 058/877] wifi: cfg80211: add option for vif allowed radios Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 060/877] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
` (825 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Johannes Berg,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 32ee616a7f8c36fa3ab00985ebd038c3487e721f ]
Reject frequencies not supported by any radio that the vif is allowed to
use.
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Link: https://patch.msgid.link/9d5c0b6b00a7ecef6a0ac6de765c0af00c8bb0e1.1728462320.git-series.nbd@nbd.name
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: a7491b7efbd9 ("wifi: mac80211: don't warn when an IBSS has no channel to scan")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/scan.c | 22 ++++++++++++----------
1 file changed, 12 insertions(+), 10 deletions(-)
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
index 8675d2e99c564..07ce9cd35dab2 100644
--- a/net/mac80211/scan.c
+++ b/net/mac80211/scan.c
@@ -1180,14 +1180,14 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
unsigned int n_channels)
{
struct ieee80211_local *local = sdata->local;
- int ret = -EBUSY, i, n_ch = 0;
+ int i, n_ch = 0;
enum nl80211_band band;
lockdep_assert_wiphy(local->hw.wiphy);
/* busy scanning */
if (local->scan_req)
- goto unlock;
+ return -EBUSY;
/* fill internal scan request */
if (!channels) {
@@ -1204,7 +1204,9 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
&local->hw.wiphy->bands[band]->channels[i];
if (tmp_ch->flags & (IEEE80211_CHAN_NO_IR |
- IEEE80211_CHAN_DISABLED))
+ IEEE80211_CHAN_DISABLED) ||
+ !cfg80211_wdev_channel_allowed(&sdata->wdev,
+ tmp_ch))
continue;
local->int_scan_req->channels[n_ch] = tmp_ch;
@@ -1213,21 +1215,23 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
}
if (WARN_ON_ONCE(n_ch == 0))
- goto unlock;
+ return -EINVAL;
local->int_scan_req->n_channels = n_ch;
} else {
for (i = 0; i < n_channels; i++) {
if (channels[i]->flags & (IEEE80211_CHAN_NO_IR |
- IEEE80211_CHAN_DISABLED))
+ IEEE80211_CHAN_DISABLED) ||
+ !cfg80211_wdev_channel_allowed(&sdata->wdev,
+ channels[i]))
continue;
local->int_scan_req->channels[n_ch] = channels[i];
n_ch++;
}
- if (WARN_ON_ONCE(n_ch == 0))
- goto unlock;
+ if (n_ch == 0)
+ return -EINVAL;
local->int_scan_req->n_channels = n_ch;
}
@@ -1237,9 +1241,7 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
memcpy(local->int_scan_req->ssids[0].ssid, ssid, IEEE80211_MAX_SSID_LEN);
local->int_scan_req->ssids[0].ssid_len = ssid_len;
- ret = __ieee80211_start_scan(sdata, sdata->local->int_scan_req);
- unlock:
- return ret;
+ return __ieee80211_start_scan(sdata, sdata->local->int_scan_req);
}
void ieee80211_scan_cancel(struct ieee80211_local *local)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 060/877] wifi: mac80211: dont warn when an IBSS has no channel to scan
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 059/877] wifi: mac80211: use vif radio mask to limit ibss scan frequencies Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 061/877] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
` (824 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1634c5399e29d8b66789,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7491b7efbd9136b120a12ed72af9c12121dd134 ]
ieee80211_request_ibss_scan() warns when regulatory leaves no
allowed channel, but that can happen as the regdomain can change
while IBSS is operating, and it can continue to operate briefly
during the 60s grace period until it's shut down.
Just remove the warning in this case.
Assisted-by: LLM
Fixes: 34bcf7150241 ("mac80211: fix ibss scanning")
Reported-by: syzbot+1634c5399e29d8b66789@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1634c5399e29d8b66789
Link: https://patch.msgid.link/20260904165722.fe380c27fef4.I0e8bee2e12a40d240851a4bc724d47753af46159@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/scan.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
index 07ce9cd35dab2..19e374fa00795 100644
--- a/net/mac80211/scan.c
+++ b/net/mac80211/scan.c
@@ -1214,7 +1214,7 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
}
}
- if (WARN_ON_ONCE(n_ch == 0))
+ if (n_ch == 0)
return -EINVAL;
local->int_scan_req->n_channels = n_ch;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 061/877] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 060/877] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 062/877] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
` (823 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f1ba58d6b55abd13239e,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 362bd5bce29ed0f6fd3d39a7065567777d70606e ]
AP_VLAN interfaces are purely virtual, so don't try to offload
TC setup to drivers. We can't really use the AP interface either
since we may not know it all the time, and it could technically
even change.
Just reject the TC offload so things get done in software.
Assisted-by: LLM
Fixes: 61587f1556fe ("wifi: mac80211: add support for letting drivers register tc offload support")
Reported-by: syzbot+f1ba58d6b55abd13239e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f1ba58d6b55abd13239e
Link: https://patch.msgid.link/20260904165722.726cc076cecb.Iccfd88b13635425e850ce031376eb60a4ce5f4f8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 7a79b40d23b36..98bc924d74fa6 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -873,6 +873,9 @@ static int ieee80211_netdev_setup_tc(struct net_device *dev,
struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
struct ieee80211_local *local = sdata->local;
+ if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
+ return -EOPNOTSUPP;
+
return drv_net_setup_tc(local, sdata, dev, type, type_data);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 062/877] wifi: mac80211: suppress chanctx warning for debugfs reset
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 061/877] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 063/877] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
` (822 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+56a1a45a9a2c04d425ff,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit bf29d085e0eba92388518719d044f4702a8c6644 ]
Before suspend all the channel contexts should removed, so the
warning makes sense and should be there, but during reset the
same code is called without first removing. Limit the check to
the real suspend case.
Assisted-by: LLM
Fixes: 12e7f517029d ("mac80211: cleanup generic suspend/resume procedures")
Reported-by: syzbot+56a1a45a9a2c04d425ff@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=56a1a45a9a2c04d425ff
Link: https://patch.msgid.link/20260904165722.fe46395e310b.Ic4aaa95bd9d0ceb6a3cd7d84c425afee7d7d3dd7@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 2 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/ieee80211_i.h | 2 +-
net/mac80211/pm.c | 8 +++++---
4 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index f6c5de994898c..73d7183c1ce59 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -2844,7 +2844,7 @@ static int ieee80211_set_txq_params(struct wiphy *wiphy,
static int ieee80211_suspend(struct wiphy *wiphy,
struct cfg80211_wowlan *wowlan)
{
- return __ieee80211_suspend(wiphy_priv(wiphy), wowlan);
+ return __ieee80211_suspend(wiphy_priv(wiphy), wowlan, false);
}
static int ieee80211_resume(struct wiphy *wiphy)
diff --git a/net/mac80211/debugfs.c b/net/mac80211/debugfs.c
index e9b3b2c7b6faa..28b1355cc062f 100644
--- a/net/mac80211/debugfs.c
+++ b/net/mac80211/debugfs.c
@@ -418,7 +418,7 @@ static ssize_t reset_write(struct file *file, const char __user *user_buf,
rtnl_lock();
wiphy_lock(local->hw.wiphy);
- __ieee80211_suspend(&local->hw, NULL);
+ __ieee80211_suspend(&local->hw, NULL, true);
ret = __ieee80211_resume(&local->hw);
wiphy_unlock(local->hw.wiphy);
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index 3b00b3f9f17dd..24edf2d4eb4f5 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2287,7 +2287,7 @@ int ieee80211_reconfig(struct ieee80211_local *local);
void ieee80211_stop_device(struct ieee80211_local *local, bool suspend);
int __ieee80211_suspend(struct ieee80211_hw *hw,
- struct cfg80211_wowlan *wowlan);
+ struct cfg80211_wowlan *wowlan, bool reset);
static inline int __ieee80211_resume(struct ieee80211_hw *hw)
{
diff --git a/net/mac80211/pm.c b/net/mac80211/pm.c
index 7be52345f218c..56c222bdd4905 100644
--- a/net/mac80211/pm.c
+++ b/net/mac80211/pm.c
@@ -18,7 +18,8 @@ static void ieee80211_sched_scan_cancel(struct ieee80211_local *local)
cfg80211_sched_scan_stopped_locked(local->hw.wiphy, 0);
}
-int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
+int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan,
+ bool reset)
{
struct ieee80211_local *local = hw_to_local(hw);
struct ieee80211_sub_if_data *sdata;
@@ -166,9 +167,10 @@ int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
/*
* We disconnected on all interfaces before suspend, all channel
- * contexts should be released.
+ * contexts should be released, but on 'reset' debugfs that's
+ * not true so don't check there.
*/
- WARN_ON(!list_empty(&local->chanctx_list));
+ WARN_ON(!reset && !list_empty(&local->chanctx_list));
/* stop hardware - this must stop RX */
ieee80211_stop_device(local, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 063/877] wifi: mac80211: abort chanswitch when leaving a mesh
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 062/877] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 064/877] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
` (821 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+81cd9dc1596563141d19,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ac7472a24bd433b81c06582835dd1d5547c10da9 ]
The code in ieee80211_stop_mesh() leaves CSA active, but leaving
the mesh released the channel context, so the CSA finalize work
crashes:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000003
KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
RIP: 0010:ieee80211_put_srates_elem+0x42/0x640 net/mac80211/util.c:3272
Call Trace:
ieee80211_mesh_build_beacon+0xa83/0x1b50 net/mac80211/mesh.c:1093
ieee80211_mesh_rebuild_beacon+0xc7/0x170 net/mac80211/mesh.c:1147
ieee80211_mesh_finish_csa+0x131/0x210 net/mac80211/mesh.c:1542
ieee80211_set_after_csa_beacon net/mac80211/cfg.c:4085 [inline]
__ieee80211_csa_finalize net/mac80211/cfg.c:4133 [inline]
ieee80211_csa_finalize+0x633/0x1150 net/mac80211/cfg.c:4155
cfg80211_wiphy_work+0x2ab/0x450 net/wireless/core.c:438
Abort the channel switch properly.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+81cd9dc1596563141d19@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=81cd9dc1596563141d19
Link: https://patch.msgid.link/20260904165722.d0b87eee08aa.I80550d6127e0bb26efb49a5fbe95be1aef1cd0cb@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 253f4b0642842..57cf3f90f7fbe 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1225,6 +1225,10 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
netif_carrier_off(sdata->dev);
+ /* abort any running channel switch */
+ sdata->vif.bss_conf.csa_active = false;
+ ieee80211_vif_unblock_queues_csa(sdata);
+
/* flush STAs and mpaths on this iface */
sta_info_flush(sdata, -1);
ieee80211_free_keys(sdata, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 064/877] wifi: mac80211: reset state when starting AP fails
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 063/877] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 065/877] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
` (820 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+ca7a2759caaa6cd4e3db,
syzbot+c4686c3eb8b64032618f, Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 3f28551d0241254a75626d868041c6340285088b ]
ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail
later, leaving it set forever. Scanning can then attempt to restore
beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00
Call Trace:
drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160
__ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519
ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type,
and the off-channel path getgs confused about beaconing as well,
leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122
ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]
__ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Assisted-by: LLM
Fixes: d6a83228823f ("mac80211: track enable_beacon explicitly")
Reported-by: syzbot+ca7a2759caaa6cd4e3db@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ca7a2759caaa6cd4e3db
Reported-by: syzbot+c4686c3eb8b64032618f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c4686c3eb8b64032618f
Link: https://patch.msgid.link/20260904165722.9629429a5221.I7f599412bfe12a09d41ea4901be9ad165d07d133@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 73d7183c1ce59..71310d708dbc4 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -1514,6 +1514,9 @@ static int ieee80211_start_ap(struct wiphy *wiphy, struct net_device *dev,
return 0;
error:
+ link_conf->enable_beacon = false;
+ link_conf->beacon_int = prev_beacon_int;
+ sdata->vif.cfg.ssid_len = 0;
ieee80211_link_release_channel(link);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 065/877] wifi: mac80211: unlist vifs when their netdev is unregistered
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 064/877] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 066/877] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
` (819 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eee2efd82867b623982ac51925b5a1812a74c50d ]
mac80211 only removes vifs from the local->interfaces list when
an interface is removed via ieee80211_if_remove(), before it
unregisters the netdev. However, it's possible for a netdev to
be unregistered without going through that: When the netns that
holds the wiphy is destroyed, the wiphy is supposed to move to
the init_ns, but that can run into allocation failures.
Then, mac80211 has an interface listed that doesn't exist, and
will eventually hit
BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!
...
_cfg80211_unregister_wdev+0x24/0x36a [cfg80211]
cfg80211_unregister_wdev+0x15/0x1d [cfg80211]
ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]
ieee80211_unregister_hw+0x73/0x1d1 [mac80211]
mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]
Remove the interface from the list in ->ndo_uninit if it's still
around to avoid this.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.038ad73e6c04.I990abca78483e058746b6f42b4796717c3028164@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 98bc924d74fa6..ac0a7374d721a 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -862,9 +862,33 @@ static void ieee80211_teardown_sdata(struct ieee80211_sub_if_data *sdata)
ieee80211_link_stop(&sdata->deflink);
}
+/*
+ * The netdev can be unregistered without mac80211 doing it, e.g. by the netdev
+ * core when cfg80211 couldn't move it out of a network namespace that's being
+ * destroyed. Drop it from the interface list either way.
+ */
+static void ieee80211_unlist_sdata(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_local *local = sdata->local;
+ struct ieee80211_sub_if_data *iter;
+
+ ASSERT_RTNL();
+
+ list_for_each_entry(iter, &local->interfaces, list) {
+ if (iter != sdata)
+ continue;
+ guard(mutex)(&local->iflist_mtx);
+ list_del_rcu(&sdata->list);
+ return;
+ }
+}
+
static void ieee80211_uninit(struct net_device *dev)
{
- ieee80211_teardown_sdata(IEEE80211_DEV_TO_SUB_IF(dev));
+ struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
+
+ ieee80211_unlist_sdata(sdata);
+ ieee80211_teardown_sdata(sdata);
}
static int ieee80211_netdev_setup_tc(struct net_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 066/877] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 065/877] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 067/877] wifi: cfg80211: skip regulatory for punctured subchannels Greg Kroah-Hartman
` (818 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b4aa2b672b18f1d4dc5f,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 87840d4a3a21b1c19b867a80e16ba69dff284de2 ]
The code checks ->started for frames coming from wmediumd, but the
radio can be stopped after the check and before frame delivery,
causing mac80211 to hit the WARN_ON(!local->started).
Expand the mutex for this case and synchronise against it when the
radio is stopped to avoid being able to hit the warning with hwsim.
Drop the error print that would've complicated the error path, it
only triggers for allocation failures (already noisy) and malformed
frames anyway.
Assisted-by: LLM
Fixes: 7882513bacb1 ("mac80211_hwsim driver support userspace frame tx/rx")
Reported-by: syzbot+b4aa2b672b18f1d4dc5f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b4aa2b672b18f1d4dc5f
Link: https://patch.msgid.link/20260904170140.5f69a10d606b.I4a7921d00643f69e439c7a3b221d104f66a3dcdc@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/mac80211_hwsim.c | 39 ++++++++++++-------
1 file changed, 24 insertions(+), 15 deletions(-)
diff --git a/drivers/net/wireless/virtual/mac80211_hwsim.c b/drivers/net/wireless/virtual/mac80211_hwsim.c
index 9410059e97f01..f1b96cd1198c5 100644
--- a/drivers/net/wireless/virtual/mac80211_hwsim.c
+++ b/drivers/net/wireless/virtual/mac80211_hwsim.c
@@ -2120,7 +2120,12 @@ static void mac80211_hwsim_stop(struct ieee80211_hw *hw, bool suspend)
struct sk_buff *skb;
int i;
- data->started = false;
+ /*
+ * Serialise against wmediumd userspace, so no more frames
+ * can be handed to mac80211 after this returns.
+ */
+ scoped_guard(mutex, &data->mutex)
+ data->started = false;
for (i = 0; i < ARRAY_SIZE(data->link_data); i++)
hrtimer_cancel(&data->link_data[i].beacon_timer);
@@ -5851,12 +5856,12 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
if (frame_data_len < sizeof(struct ieee80211_hdr_3addr) ||
frame_data_len > IEEE80211_MAX_DATA_LEN)
- goto err;
+ goto out;
/* Allocate new skb here */
skb = alloc_skb(frame_data_len, GFP_KERNEL);
if (skb == NULL)
- goto err;
+ goto out;
/* Copy the data */
skb_put_data(skb, frame_data, frame_data_len);
@@ -5881,10 +5886,17 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
goto out;
}
+ /*
+ * Serialise against mac80211_hwsim_stop() - mac80211 doesn't allow
+ * frames reported while the HW is down, hence the ->started check
+ * must be under mutex.
+ */
+ mutex_lock(&data2->mutex);
+
/* check if radio is configured properly */
if ((data2->idle && !data2->tmp_chan) || !data2->started)
- goto out;
+ goto out_unlock;
/* A frame is received from user space */
memset(&rx_status, 0, sizeof(rx_status));
@@ -5900,22 +5912,18 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
iter_data.channel = ieee80211_get_channel(data2->hw->wiphy,
rx_status.freq);
if (!iter_data.channel)
- goto out;
+ goto out_unlock;
rx_status.band = iter_data.channel->band;
- mutex_lock(&data2->mutex);
if (!hwsim_chans_compat(iter_data.channel, channel)) {
ieee80211_iterate_active_interfaces_atomic(
data2->hw, IEEE80211_IFACE_ITER_NORMAL,
mac80211_hwsim_tx_iter, &iter_data);
- if (!iter_data.receive) {
- mutex_unlock(&data2->mutex);
- goto out;
- }
+ if (!iter_data.receive)
+ goto out_unlock;
}
- mutex_unlock(&data2->mutex);
} else if (!channel) {
- goto out;
+ goto out_unlock;
} else {
rx_status.freq = channel->center_freq;
rx_status.band = channel->band;
@@ -5923,7 +5931,7 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.rate_idx = nla_get_u32(info->attrs[HWSIM_ATTR_RX_RATE]);
if (rx_status.rate_idx >= data2->hw->wiphy->bands[rx_status.band]->n_bitrates)
- goto out;
+ goto out_unlock;
rx_status.signal = nla_get_u32(info->attrs[HWSIM_ATTR_SIGNAL]);
hdr = (void *)skb->data;
@@ -5933,10 +5941,11 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.boottime_ns = ktime_get_boottime_ns();
mac80211_hwsim_rx(data2, &rx_status, skb);
+ mutex_unlock(&data2->mutex);
return 0;
-err:
- pr_debug("mac80211_hwsim: error occurred in %s\n", __func__);
+out_unlock:
+ mutex_unlock(&data2->mutex);
out:
dev_kfree_skb(skb);
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 067/877] wifi: cfg80211: skip regulatory for punctured subchannels
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 066/877] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 068/877] wifi: cfg80211: expose cfg80211_chandef_get_width() Greg Kroah-Hartman
` (817 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manaswini Paluri, Kavita Kavita,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kavita Kavita <quic_kkavita@quicinc.com>
[ Upstream commit 9add053591ed9d126b6f071236e33e762c439fa8 ]
The kernel performs several regulatory checks for AP mode in
nl80211/cfg80211. These checks include radar detection,
verification of whether the sub-channel is disabled, and
an examination to determine if the channel is a DFS channel
(both DFS usable and DFS available). These checks are
performed across a frequency range, examining each sub-channel.
However, these checks are also performed on subchannels that
have been punctured which should not be examined as they are
not in use.
This leads to the issue where the AP stops because one of
the 20 MHz sub-channels is disabled or radar detected on
the channel, even when the sub-channel is punctured.
To address this issue, add a condition check wherever
regulatory checks exist for AP mode in nl80211/cfg80211.
This check identifies punctured channels and, upon finding
them, skips the regulatory checks for those channels.
Co-developed-by: Manaswini Paluri <quic_mpaluri@quicinc.com>
Signed-off-by: Manaswini Paluri <quic_mpaluri@quicinc.com>
Signed-off-by: Kavita Kavita <quic_kkavita@quicinc.com>
Link: https://patch.msgid.link/20250109050409.25351-1-quic_kkavita@quicinc.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: e14bf37bb2b3 ("wifi: mac80211: don't allow injecting frames wider than the chanctx")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/chan.c | 370 +++++++++++++++-----------------------------
1 file changed, 123 insertions(+), 247 deletions(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 515d40c09e788..b1a8d17baa62a 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -55,6 +55,56 @@ void cfg80211_chandef_create(struct cfg80211_chan_def *chandef,
}
EXPORT_SYMBOL(cfg80211_chandef_create);
+static int cfg80211_chandef_get_width(const struct cfg80211_chan_def *c)
+{
+ return nl80211_chan_width_to_mhz(c->width);
+}
+
+static u32 cfg80211_get_start_freq(const struct cfg80211_chan_def *chandef,
+ u32 cf)
+{
+ u32 start_freq, center_freq, bandwidth;
+
+ center_freq = MHZ_TO_KHZ((cf == 1) ?
+ chandef->center_freq1 : chandef->center_freq2);
+ bandwidth = MHZ_TO_KHZ(cfg80211_chandef_get_width(chandef));
+
+ if (bandwidth <= MHZ_TO_KHZ(20))
+ start_freq = center_freq;
+ else
+ start_freq = center_freq - bandwidth / 2 + MHZ_TO_KHZ(10);
+
+ return start_freq;
+}
+
+static u32 cfg80211_get_end_freq(const struct cfg80211_chan_def *chandef,
+ u32 cf)
+{
+ u32 end_freq, center_freq, bandwidth;
+
+ center_freq = MHZ_TO_KHZ((cf == 1) ?
+ chandef->center_freq1 : chandef->center_freq2);
+ bandwidth = MHZ_TO_KHZ(cfg80211_chandef_get_width(chandef));
+
+ if (bandwidth <= MHZ_TO_KHZ(20))
+ end_freq = center_freq;
+ else
+ end_freq = center_freq + bandwidth / 2 - MHZ_TO_KHZ(10);
+
+ return end_freq;
+}
+
+#define for_each_subchan(chandef, freq, cf) \
+ for (u32 punctured = chandef->punctured, \
+ cf = 1, freq = cfg80211_get_start_freq(chandef, cf); \
+ freq <= cfg80211_get_end_freq(chandef, cf); \
+ freq += MHZ_TO_KHZ(20), \
+ ((cf == 1 && chandef->center_freq2 != 0 && \
+ freq > cfg80211_get_end_freq(chandef, cf)) ? \
+ (cf++, freq = cfg80211_get_start_freq(chandef, cf), \
+ punctured = 0) : (punctured >>= 1))) \
+ if (!(punctured & 1))
+
struct cfg80211_per_bw_puncturing_values {
u8 len;
const u16 *valid_values;
@@ -258,11 +308,6 @@ int nl80211_chan_width_to_mhz(enum nl80211_chan_width chan_width)
}
EXPORT_SYMBOL(nl80211_chan_width_to_mhz);
-static int cfg80211_chandef_get_width(const struct cfg80211_chan_def *c)
-{
- return nl80211_chan_width_to_mhz(c->width);
-}
-
static bool cfg80211_valid_center_freq(u32 center,
enum nl80211_chan_width width)
{
@@ -582,29 +627,11 @@ cfg80211_chandef_compatible(const struct cfg80211_chan_def *c1,
}
EXPORT_SYMBOL(cfg80211_chandef_compatible);
-static void cfg80211_set_chans_dfs_state(struct wiphy *wiphy, u32 center_freq,
- u32 bandwidth,
- enum nl80211_dfs_state dfs_state)
-{
- struct ieee80211_channel *c;
- u32 freq;
-
- for (freq = center_freq - bandwidth/2 + 10;
- freq <= center_freq + bandwidth/2 - 10;
- freq += 20) {
- c = ieee80211_get_channel(wiphy, freq);
- if (!c || !(c->flags & IEEE80211_CHAN_RADAR))
- continue;
-
- c->dfs_state = dfs_state;
- c->dfs_state_entered = jiffies;
- }
-}
-
void cfg80211_set_dfs_state(struct wiphy *wiphy,
const struct cfg80211_chan_def *chandef,
enum nl80211_dfs_state dfs_state)
{
+ struct ieee80211_channel *c;
int width;
if (WARN_ON(!cfg80211_chandef_valid(chandef)))
@@ -614,41 +641,14 @@ void cfg80211_set_dfs_state(struct wiphy *wiphy,
if (width < 0)
return;
- cfg80211_set_chans_dfs_state(wiphy, chandef->center_freq1,
- width, dfs_state);
-
- if (!chandef->center_freq2)
- return;
- cfg80211_set_chans_dfs_state(wiphy, chandef->center_freq2,
- width, dfs_state);
-}
-
-static u32 cfg80211_get_start_freq(u32 center_freq,
- u32 bandwidth)
-{
- u32 start_freq;
-
- bandwidth = MHZ_TO_KHZ(bandwidth);
- if (bandwidth <= MHZ_TO_KHZ(20))
- start_freq = center_freq;
- else
- start_freq = center_freq - bandwidth / 2 + MHZ_TO_KHZ(10);
-
- return start_freq;
-}
-
-static u32 cfg80211_get_end_freq(u32 center_freq,
- u32 bandwidth)
-{
- u32 end_freq;
-
- bandwidth = MHZ_TO_KHZ(bandwidth);
- if (bandwidth <= MHZ_TO_KHZ(20))
- end_freq = center_freq;
- else
- end_freq = center_freq + bandwidth / 2 - MHZ_TO_KHZ(10);
+ for_each_subchan(chandef, freq, cf) {
+ c = ieee80211_get_channel_khz(wiphy, freq);
+ if (!c || !(c->flags & IEEE80211_CHAN_RADAR))
+ continue;
- return end_freq;
+ c->dfs_state = dfs_state;
+ c->dfs_state_entered = jiffies;
+ }
}
static bool
@@ -725,17 +725,12 @@ static bool cfg80211_dfs_permissive_chan(struct wiphy *wiphy,
}
static int cfg80211_get_chans_dfs_required(struct wiphy *wiphy,
- u32 center_freq,
- u32 bandwidth,
- enum nl80211_iftype iftype)
+ const struct cfg80211_chan_def *chandef,
+ enum nl80211_iftype iftype)
{
struct ieee80211_channel *c;
- u32 freq, start_freq, end_freq;
-
- start_freq = cfg80211_get_start_freq(center_freq, bandwidth);
- end_freq = cfg80211_get_end_freq(center_freq, bandwidth);
- for (freq = start_freq; freq <= end_freq; freq += MHZ_TO_KHZ(20)) {
+ for_each_subchan(chandef, freq, cf) {
c = ieee80211_get_channel_khz(wiphy, freq);
if (!c)
return -EINVAL;
@@ -768,25 +763,9 @@ int cfg80211_chandef_dfs_required(struct wiphy *wiphy,
if (width < 0)
return -EINVAL;
- ret = cfg80211_get_chans_dfs_required(wiphy,
- ieee80211_chandef_to_khz(chandef),
- width, iftype);
- if (ret < 0)
- return ret;
- else if (ret > 0)
- return BIT(chandef->width);
-
- if (!chandef->center_freq2)
- return 0;
-
- ret = cfg80211_get_chans_dfs_required(wiphy,
- MHZ_TO_KHZ(chandef->center_freq2),
- width, iftype);
- if (ret < 0)
- return ret;
- else if (ret > 0)
- return BIT(chandef->width);
+ ret = cfg80211_get_chans_dfs_required(wiphy, chandef, iftype);
+ return (ret > 0) ? BIT(chandef->width) : ret;
break;
case NL80211_IFTYPE_STATION:
case NL80211_IFTYPE_OCB:
@@ -806,16 +785,18 @@ int cfg80211_chandef_dfs_required(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_chandef_dfs_required);
-static int cfg80211_get_chans_dfs_usable(struct wiphy *wiphy,
- u32 center_freq,
- u32 bandwidth)
+bool cfg80211_chandef_dfs_usable(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef)
{
struct ieee80211_channel *c;
- u32 freq, start_freq, end_freq;
- int count = 0;
+ int width, count = 0;
- start_freq = cfg80211_get_start_freq(center_freq, bandwidth);
- end_freq = cfg80211_get_end_freq(center_freq, bandwidth);
+ if (WARN_ON(!cfg80211_chandef_valid(chandef)))
+ return false;
+
+ width = cfg80211_chandef_get_width(chandef);
+ if (width < 0)
+ return false;
/*
* Check entire range of channels for the bandwidth.
@@ -823,61 +804,24 @@ static int cfg80211_get_chans_dfs_usable(struct wiphy *wiphy,
* DFS_AVAILABLE). Return number of usable channels
* (require CAC). Allow DFS and non-DFS channel mix.
*/
- for (freq = start_freq; freq <= end_freq; freq += MHZ_TO_KHZ(20)) {
+ for_each_subchan(chandef, freq, cf) {
c = ieee80211_get_channel_khz(wiphy, freq);
if (!c)
- return -EINVAL;
+ return false;
if (c->flags & IEEE80211_CHAN_DISABLED)
- return -EINVAL;
+ return false;
if (c->flags & IEEE80211_CHAN_RADAR) {
if (c->dfs_state == NL80211_DFS_UNAVAILABLE)
- return -EINVAL;
+ return false;
if (c->dfs_state == NL80211_DFS_USABLE)
count++;
}
}
- return count;
-}
-
-bool cfg80211_chandef_dfs_usable(struct wiphy *wiphy,
- const struct cfg80211_chan_def *chandef)
-{
- int width;
- int r1, r2 = 0;
-
- if (WARN_ON(!cfg80211_chandef_valid(chandef)))
- return false;
-
- width = cfg80211_chandef_get_width(chandef);
- if (width < 0)
- return false;
-
- r1 = cfg80211_get_chans_dfs_usable(wiphy,
- MHZ_TO_KHZ(chandef->center_freq1),
- width);
-
- if (r1 < 0)
- return false;
-
- switch (chandef->width) {
- case NL80211_CHAN_WIDTH_80P80:
- WARN_ON(!chandef->center_freq2);
- r2 = cfg80211_get_chans_dfs_usable(wiphy,
- MHZ_TO_KHZ(chandef->center_freq2),
- width);
- if (r2 < 0)
- return false;
- break;
- default:
- WARN_ON(chandef->center_freq2);
- break;
- }
-
- return (r1 + r2 > 0);
+ return count > 0;
}
EXPORT_SYMBOL(cfg80211_chandef_dfs_usable);
@@ -1051,26 +995,29 @@ bool cfg80211_any_wiphy_oper_chan(struct wiphy *wiphy,
return false;
}
-static bool cfg80211_get_chans_dfs_available(struct wiphy *wiphy,
- u32 center_freq,
- u32 bandwidth)
+static bool cfg80211_chandef_dfs_available(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef)
{
struct ieee80211_channel *c;
- u32 freq, start_freq, end_freq;
+ int width;
bool dfs_offload;
+ if (WARN_ON(!cfg80211_chandef_valid(chandef)))
+ return false;
+
+ width = cfg80211_chandef_get_width(chandef);
+ if (width < 0)
+ return false;
+
dfs_offload = wiphy_ext_feature_isset(wiphy,
NL80211_EXT_FEATURE_DFS_OFFLOAD);
- start_freq = cfg80211_get_start_freq(center_freq, bandwidth);
- end_freq = cfg80211_get_end_freq(center_freq, bandwidth);
-
/*
* Check entire range of channels for the bandwidth.
* If any channel in between is disabled or has not
* had gone through CAC return false
*/
- for (freq = start_freq; freq <= end_freq; freq += MHZ_TO_KHZ(20)) {
+ for_each_subchan(chandef, freq, cf) {
c = ieee80211_get_channel_khz(wiphy, freq);
if (!c)
return false;
@@ -1087,124 +1034,54 @@ static bool cfg80211_get_chans_dfs_available(struct wiphy *wiphy,
return true;
}
-static bool cfg80211_chandef_dfs_available(struct wiphy *wiphy,
- const struct cfg80211_chan_def *chandef)
+unsigned int
+cfg80211_chandef_dfs_cac_time(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef)
{
+ struct ieee80211_channel *c;
int width;
- int r;
+ unsigned int t1 = 0, t2 = 0;
if (WARN_ON(!cfg80211_chandef_valid(chandef)))
- return false;
+ return 0;
width = cfg80211_chandef_get_width(chandef);
if (width < 0)
- return false;
-
- r = cfg80211_get_chans_dfs_available(wiphy,
- MHZ_TO_KHZ(chandef->center_freq1),
- width);
-
- /* If any of channels unavailable for cf1 just return */
- if (!r)
- return r;
-
- switch (chandef->width) {
- case NL80211_CHAN_WIDTH_80P80:
- WARN_ON(!chandef->center_freq2);
- r = cfg80211_get_chans_dfs_available(wiphy,
- MHZ_TO_KHZ(chandef->center_freq2),
- width);
- break;
- default:
- WARN_ON(chandef->center_freq2);
- break;
- }
-
- return r;
-}
-
-static unsigned int cfg80211_get_chans_dfs_cac_time(struct wiphy *wiphy,
- u32 center_freq,
- u32 bandwidth)
-{
- struct ieee80211_channel *c;
- u32 start_freq, end_freq, freq;
- unsigned int dfs_cac_ms = 0;
-
- start_freq = cfg80211_get_start_freq(center_freq, bandwidth);
- end_freq = cfg80211_get_end_freq(center_freq, bandwidth);
+ return 0;
- for (freq = start_freq; freq <= end_freq; freq += MHZ_TO_KHZ(20)) {
+ for_each_subchan(chandef, freq, cf) {
c = ieee80211_get_channel_khz(wiphy, freq);
- if (!c)
- return 0;
-
- if (c->flags & IEEE80211_CHAN_DISABLED)
- return 0;
+ if (!c || (c->flags & IEEE80211_CHAN_DISABLED)) {
+ if (cf == 1)
+ t1 = INT_MAX;
+ else
+ t2 = INT_MAX;
+ continue;
+ }
if (!(c->flags & IEEE80211_CHAN_RADAR))
continue;
- if (c->dfs_cac_ms > dfs_cac_ms)
- dfs_cac_ms = c->dfs_cac_ms;
- }
-
- return dfs_cac_ms;
-}
-
-unsigned int
-cfg80211_chandef_dfs_cac_time(struct wiphy *wiphy,
- const struct cfg80211_chan_def *chandef)
-{
- int width;
- unsigned int t1 = 0, t2 = 0;
+ if (cf == 1 && c->dfs_cac_ms > t1)
+ t1 = c->dfs_cac_ms;
- if (WARN_ON(!cfg80211_chandef_valid(chandef)))
- return 0;
+ if (cf == 2 && c->dfs_cac_ms > t2)
+ t2 = c->dfs_cac_ms;
+ }
- width = cfg80211_chandef_get_width(chandef);
- if (width < 0)
+ if (t1 == INT_MAX && t2 == INT_MAX)
return 0;
- t1 = cfg80211_get_chans_dfs_cac_time(wiphy,
- MHZ_TO_KHZ(chandef->center_freq1),
- width);
+ if (t1 == INT_MAX)
+ return t2;
- if (!chandef->center_freq2)
+ if (t2 == INT_MAX)
return t1;
- t2 = cfg80211_get_chans_dfs_cac_time(wiphy,
- MHZ_TO_KHZ(chandef->center_freq2),
- width);
-
return max(t1, t2);
}
EXPORT_SYMBOL(cfg80211_chandef_dfs_cac_time);
-static bool cfg80211_secondary_chans_ok(struct wiphy *wiphy,
- u32 center_freq, u32 bandwidth,
- u32 prohibited_flags,
- u32 permitting_flags)
-{
- struct ieee80211_channel *c;
- u32 freq, start_freq, end_freq;
-
- start_freq = cfg80211_get_start_freq(center_freq, bandwidth);
- end_freq = cfg80211_get_end_freq(center_freq, bandwidth);
-
- for (freq = start_freq; freq <= end_freq; freq += MHZ_TO_KHZ(20)) {
- c = ieee80211_get_channel_khz(wiphy, freq);
- if (!c)
- return false;
- if (c->flags & permitting_flags)
- continue;
- if (c->flags & prohibited_flags)
- return false;
- }
-
- return true;
-}
-
/* check if the operating channels are valid and supported */
static bool cfg80211_edmg_usable(struct wiphy *wiphy, u8 edmg_channels,
enum ieee80211_edmg_bw_config edmg_bw_config,
@@ -1270,6 +1147,7 @@ bool _cfg80211_chandef_usable(struct wiphy *wiphy,
bool ext_nss_cap, support_80_80 = false, support_320 = false;
const struct ieee80211_sband_iftype_data *iftd;
struct ieee80211_supported_band *sband;
+ struct ieee80211_channel *c;
int i;
if (WARN_ON(!cfg80211_chandef_valid(chandef)))
@@ -1420,19 +1298,17 @@ bool _cfg80211_chandef_usable(struct wiphy *wiphy,
if (width < 20)
prohibited_flags |= IEEE80211_CHAN_NO_OFDM;
+ for_each_subchan(chandef, freq, cf) {
+ c = ieee80211_get_channel_khz(wiphy, freq);
+ if (!c)
+ return false;
+ if (c->flags & permitting_flags)
+ continue;
+ if (c->flags & prohibited_flags)
+ return false;
+ }
- if (!cfg80211_secondary_chans_ok(wiphy,
- ieee80211_chandef_to_khz(chandef),
- width, prohibited_flags,
- permitting_flags))
- return false;
-
- if (!chandef->center_freq2)
- return true;
- return cfg80211_secondary_chans_ok(wiphy,
- MHZ_TO_KHZ(chandef->center_freq2),
- width, prohibited_flags,
- permitting_flags);
+ return true;
}
bool cfg80211_chandef_usable(struct wiphy *wiphy,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 068/877] wifi: cfg80211: expose cfg80211_chandef_get_width()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 067/877] wifi: cfg80211: skip regulatory for punctured subchannels Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 069/877] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
` (816 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Miriam Rachel Korenblit,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b5c1622762f0937a66b69b7f15466c28fe85dcf1 ]
This can be just a trivial inline, to simplify some code.
Expose it, and also use it in util.c where it wasn't
previously available.
Reviewed-by: Miriam Rachel Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20250311122534.c5c3b4af9a74.Ib25cf60f634dc359961182113214e5cdc3504e9c@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: e14bf37bb2b3 ("wifi: mac80211: don't allow injecting frames wider than the chanctx")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 11 +++++++++++
net/wireless/chan.c | 5 -----
net/wireless/util.c | 4 ++--
3 files changed, 13 insertions(+), 7 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index f3915118c15d7..ede91e4709ee5 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -1008,6 +1008,17 @@ cfg80211_chandef_compatible(const struct cfg80211_chan_def *chandef1,
*/
int nl80211_chan_width_to_mhz(enum nl80211_chan_width chan_width);
+/**
+ * cfg80211_chandef_get_width - return chandef width in MHz
+ * @c: chandef to return bandwidth for
+ * Return: channel width in MHz for the given chandef; note that it returns
+ * 80 for 80+80 configurations
+ */
+static inline int cfg80211_chandef_get_width(const struct cfg80211_chan_def *c)
+{
+ return nl80211_chan_width_to_mhz(c->width);
+}
+
/**
* cfg80211_chandef_valid - check if a channel definition is valid
* @chandef: the channel definition to check
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index b1a8d17baa62a..6f4b4770bf50b 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -55,11 +55,6 @@ void cfg80211_chandef_create(struct cfg80211_chan_def *chandef,
}
EXPORT_SYMBOL(cfg80211_chandef_create);
-static int cfg80211_chandef_get_width(const struct cfg80211_chan_def *c)
-{
- return nl80211_chan_width_to_mhz(c->width);
-}
-
static u32 cfg80211_get_start_freq(const struct cfg80211_chan_def *chandef,
u32 cf)
{
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 8cc205b9f105c..66f95044adb2a 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -5,7 +5,7 @@
* Copyright 2007-2009 Johannes Berg <johannes@sipsolutions.net>
* Copyright 2013-2014 Intel Mobile Communications GmbH
* Copyright 2017 Intel Deutschland GmbH
- * Copyright (C) 2018-2023 Intel Corporation
+ * Copyright (C) 2018-2023, 2025 Intel Corporation
*/
#include <linux/export.h>
#include <linux/bitops.h>
@@ -2954,7 +2954,7 @@ bool cfg80211_radio_chandef_valid(const struct wiphy_radio *radio,
u32 freq, width;
freq = ieee80211_chandef_to_khz(chandef);
- width = nl80211_chan_width_to_mhz(chandef->width);
+ width = cfg80211_chandef_get_width(chandef);
if (!ieee80211_radio_freq_range_valid(radio, freq, width))
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 069/877] wifi: mac80211: dont allow injecting frames wider than the chanctx
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 068/877] wifi: cfg80211: expose cfg80211_chandef_get_width() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 070/877] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
` (815 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+435fdb053cf98bfa5778,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit e14bf37bb2b3853012ff160131d1c6233f7a9cc9 ]
Frames injected on a monitor interface can carry a radiotap
field requesting a bandwidth, which mac80211 passes down to
the driver regardless of the the actual operational bandwidth.
If the bandwidth requested is too wide, that triggers a warning
in hwsim:
WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))
Drop such frames entirely instead since they cannot be sent.
Assisted-by: LLM
Fixes: 646e76bb5daf ("mac80211: parse VHT info in injected frames")
Reported-by: syzbot+435fdb053cf98bfa5778@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=435fdb053cf98bfa5778
Link: https://patch.msgid.link/20260908122838.201719-13-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/mac80211.h | 5 ++++-
net/mac80211/iface.c | 2 +-
net/mac80211/tx.c | 28 ++++++++++++++++++++++++++--
3 files changed, 31 insertions(+), 4 deletions(-)
diff --git a/include/net/mac80211.h b/include/net/mac80211.h
index 7d71a4149cdf9..41ae682015fc0 100644
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -7228,11 +7228,14 @@ bool ieee80211_tx_prepare_skb(struct ieee80211_hw *hw,
*
* @skb: packet injected by userspace
* @dev: the &struct device of this 802.11 device
+ * @chandef: the channel definition the frame will be transmitted on, or
+ * %NULL to skip the bandwidth checks
*
* Return: %true if the radiotap header was parsed, %false otherwise
*/
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev);
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef);
/**
* struct ieee80211_noa_data - holds temporary data for tracking P2P NoA state
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index ac0a7374d721a..3726dded1959a 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -929,7 +929,7 @@ static u16 ieee80211_monitor_select_queue(struct net_device *dev,
/* reset flags and info before parsing radiotap header */
memset(info, 0, sizeof(*info));
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, NULL))
return 0; /* doesn't matter, frame will be dropped */
len_rthdr = ieee80211_get_radiotap_len(skb->data);
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index 9bc1a80e80570..e78e71cb92f7f 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2084,8 +2084,29 @@ static bool ieee80211_validate_radiotap_len(struct sk_buff *skb)
return true;
}
+static bool ieee80211_rate_bw_usable(u16 rate_flags,
+ const struct cfg80211_chan_def *chandef)
+{
+ int width;
+
+ if (!chandef)
+ return true;
+
+ if (rate_flags & IEEE80211_TX_RC_160_MHZ_WIDTH)
+ width = 160;
+ else if (rate_flags & IEEE80211_TX_RC_80_MHZ_WIDTH)
+ width = 80;
+ else if (rate_flags & IEEE80211_TX_RC_40_MHZ_WIDTH)
+ width = 40;
+ else
+ return true;
+
+ return width <= cfg80211_chandef_get_width(chandef);
+}
+
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev)
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef)
{
struct ieee80211_local *local = wdev_priv(dev->ieee80211_ptr);
struct ieee80211_radiotap_iterator iterator;
@@ -2259,6 +2280,9 @@ bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
struct ieee80211_supported_band *sband =
local->hw.wiphy->bands[info->band];
+ if (!ieee80211_rate_bw_usable(rate_flags, chandef))
+ return false;
+
info->control.flags |= IEEE80211_TX_CTRL_RATE_INJECT;
for (i = 0; i < IEEE80211_TX_MAX_RATES; i++) {
@@ -2448,7 +2472,7 @@ netdev_tx_t ieee80211_monitor_start_xmit(struct sk_buff *skb,
* selected chandef above to accurately set injection rates and
* retransmissions.
*/
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, chandef))
goto fail_rcu;
/* remove the injection radiotap header */
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 070/877] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 069/877] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 071/877] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
` (814 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+de3ee5362db09487ea37,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4504f3960dc4501c73be9f99eabda2e26e9db41e ]
On ifup, AP_VLAN interfaces get crypto_tx_tailroom_needed_cnt from
the AP interface, but it's never decremented again unless the AP is
also brought down. Thus, bringing the same AP_VLAN up again will
increment the counter again and eventually hit the sanity check:
WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt !=
master->crypto_tx_tailroom_needed_cnt);
Reset it on ifdown to avoid that.
Assisted-by: LLM
Fixes: f9dca80b98ca ("mac80211: fix AP_VLAN crypto tailroom calculation")
Reported-by: syzbot+de3ee5362db09487ea37@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de3ee5362db09487ea37
Link: https://patch.msgid.link/20260908122838.201719-14-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 3726dded1959a..14a80583956c1 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -618,6 +618,8 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
RCU_INIT_POINTER(sdata->vif.bss_conf.chanctx_conf, NULL);
/* see comment in the default case below */
ieee80211_free_keys(sdata, true);
+ /* increased by AP value on ifup, so reset on ifdown */
+ sdata->crypto_tx_tailroom_needed_cnt = 0;
/* no need to tell driver */
break;
case NL80211_IFTYPE_MONITOR:
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 071/877] wifi: mac80211: require a peer station for TDLS setup confirm
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 070/877] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 072/877] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
` (813 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+e55106f8389651870be0,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 038e1d126304fd25d507fd4e671232df57bd1799 ]
It's nonsense for the setup confirm to go to station that
doesn't even exist, and it hits a warning when building
the frame:
WARN_ON_ONCE(!sta || !ap_sta)
Only accept WLAN_TDLS_SETUP_CONFIRM when the station is
already there as a TDLS station. Need to copy the call
to ieee80211_tdls_prep_mgmt_packet() since the existing
WLAN_TDLS_DISCOVERY_REQUEST already falls through to it.
Assisted-by: LLM
Fixes: 6f7eaa47e1de ("mac80211: add TDLS QoS param IE on setup-confirm")
Reported-by: syzbot+e55106f8389651870be0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e55106f8389651870be0
Link: https://patch.msgid.link/20260908122838.201719-15-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 19 ++++++++++++++++++-
1 file changed, 18 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 92ab7be3d4824..b4bedf0b2b552 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1285,6 +1285,24 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
peer_capability, initiator,
extra_ies, extra_ies_len);
break;
+ case WLAN_TDLS_SETUP_CONFIRM: {
+ struct sta_info *sta;
+
+ sta = sta_info_get(sdata, peer);
+ if (!sta || !sta->sta.tdls) {
+ ret = -ENOLINK;
+ break;
+ }
+
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
+ dialog_token,
+ status_code,
+ peer_capability,
+ initiator, extra_ies,
+ extra_ies_len, 0, NULL);
+ break;
+ }
case WLAN_TDLS_DISCOVERY_REQUEST:
/*
* Protect the discovery so we can hear the TDLS discovery
@@ -1293,7 +1311,6 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
*/
drv_mgd_protect_tdls_discover(sdata->local, sdata, link_id);
fallthrough;
- case WLAN_TDLS_SETUP_CONFIRM:
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
/* no special handling */
ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 072/877] wifi: mac80211: dont allow link changes when iface is down
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 071/877] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 073/877] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
` (812 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+582469b3a9ef5f13606b,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 370872d30349d81dec519e15ea2949fd63511cf7 ]
ieee80211_set_active_links() only checks that the interface is running in
the inner __ieee80211_set_active_links(), after drv_can_activate_links()
was already called, so using active_links on an interface that's down
triggers the check-sdata-in-driver warning.
Add the missing check in the debugfs file.
Assisted-by: LLM
Fixes: 3d9011029227 ("wifi: mac80211: implement link switching")
Reported-by: syzbot+582469b3a9ef5f13606b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=582469b3a9ef5f13606b
Link: https://patch.msgid.link/20260908122838.201719-16-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index d0b145888e139..bb5812925d82e 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -731,6 +731,9 @@ static ssize_t ieee80211_if_parse_active_links(struct ieee80211_sub_if_data *sda
if (kstrtou16(buf, 0, &active_links) || !active_links)
return -EINVAL;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
return ieee80211_set_active_links(&sdata->vif, active_links) ?: buflen;
}
IEEE80211_IF_FILE_RW(active_links);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 073/877] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 072/877] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 074/877] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
` (811 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b59873f5699e941717ca,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b481e64e4498e2c053d5954f546ee02338f6ab63 ]
In the error path of ieee80211_mesh_csa_beacon() the settings that were
just assigned are read back with rcu_dereference(), which lockdep then
complains about.
There's no need to read the pointer at all, tmp_csa_settings still is
the right value anyway.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+b59873f5699e941717ca@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b59873f5699e941717ca
Link: https://patch.msgid.link/20260908122838.201719-17-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 57cf3f90f7fbe..4c601b9cb3bb2 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1577,7 +1577,6 @@ int ieee80211_mesh_csa_beacon(struct ieee80211_sub_if_data *sdata,
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret) {
- tmp_csa_settings = rcu_dereference(ifmsh->csa);
RCU_INIT_POINTER(ifmsh->csa, NULL);
kfree_rcu(tmp_csa_settings, rcu_head);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 074/877] wifi: mac80211: dont access the TSF of a down interface
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 073/877] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 075/877] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
` (810 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1c8c45017f784e646b47,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 0b1de9feeb8651f7a3bb53ed7c9006e3b5298c01 ]
The tsf debugfs files call the driver even if the interface
isn't up, tgriggering check-sdata-in-driver warnings.
Reject the access in that case.
Assisted-by: LLM
Fixes: 37a41b4affa3 ("mac80211: add ieee80211_vif param to tsf functions")
Reported-by: syzbot+1c8c45017f784e646b47@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1c8c45017f784e646b47
Link: https://patch.msgid.link/20260908122838.201719-18-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index bb5812925d82e..d3519bbc4285f 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -659,6 +659,9 @@ static ssize_t ieee80211_if_fmt_tsf(
struct ieee80211_local *local = sdata->local;
u64 tsf;
+ if (!ieee80211_sdata_running((struct ieee80211_sub_if_data *)sdata))
+ return -ENETDOWN;
+
tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
return scnprintf(buf, buflen, "0x%016llx\n", (unsigned long long) tsf);
@@ -672,6 +675,9 @@ static ssize_t ieee80211_if_parse_tsf(
int ret;
int tsf_is_delta = 0;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
if (strncmp(buf, "reset", 5) == 0) {
if (local->ops->reset_tsf) {
drv_reset_tsf(local, sdata);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 075/877] wifi: mac80211: add HE 6 GHz capability in the scan elems len
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 074/877] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 076/877] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
` (809 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f961b9f94edbc266f1f8,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit cd54bf333f5631d3630bab0a832e9ae648f73515 ]
The HE 6 GHz Band Capability element is in the probe request for
every band if 6 GHz is supported, so add the size to scan_ies_len.
Otherwise, building probe request elements can fail, triggering the
WARN_ON in __ieee80211_start_scan().
Assisted-by: LLM
Fixes: 2ad2274c58ee ("mac80211: Add HE 6GHz capabilities element to probe request")
Reported-by: syzbot+f961b9f94edbc266f1f8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f961b9f94edbc266f1f8
Link: https://patch.msgid.link/20260908122838.201719-19-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
index 84cc2a21a9a59..a65d49e4402ad 100644
--- a/net/mac80211/main.c
+++ b/net/mac80211/main.c
@@ -1424,6 +1424,10 @@ int ieee80211_register_hw(struct ieee80211_hw *hw)
sizeof(struct ieee80211_he_mcs_nss_supp) +
IEEE80211_HE_PPE_THRES_MAX_LEN;
+ if (local->hw.wiphy->bands[NL80211_BAND_6GHZ])
+ local->scan_ies_len +=
+ 3 + sizeof(struct ieee80211_he_6ghz_capa);
+
if (supp_eht)
local->scan_ies_len +=
3 + sizeof(struct ieee80211_eht_cap_elem) +
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 076/877] wifi: mac80211: mesh: reset the CSA state when leaving
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 075/877] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 077/877] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
` (808 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f5752cd6b94fe38be666,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 860134b3af77970e006feab7e5decb8c84771c7f ]
ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.
Leaving the mesh while a switch is still pending therefore leaks it.
Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak
in this case, so things can get mixed up in addition to the memory
leak.
Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.
Assisted-by: LLM
Reported-by: syzbot+f5752cd6b94fe38be666@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f5752cd6b94fe38be666
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Link: https://patch.msgid.link/20260908122838.201719-20-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 29 ++++++++++++++++++-----------
1 file changed, 18 insertions(+), 11 deletions(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 4c601b9cb3bb2..258c865921784 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1217,6 +1217,21 @@ int ieee80211_start_mesh(struct ieee80211_sub_if_data *sdata)
return 0;
}
+static void ieee80211_mesh_reset_csa(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
+ struct mesh_csa_settings *csa;
+
+ /* Reset the TTL value and Initiator flag */
+ ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
+ ifmsh->chsw_ttl = 0;
+
+ /* Remove the CSA and MCSP elements from the beacon */
+ csa = sdata_dereference(ifmsh->csa, sdata);
+ RCU_INIT_POINTER(ifmsh->csa, NULL);
+ kfree_rcu(csa, rcu_head);
+}
+
void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
{
struct ieee80211_local *local = sdata->local;
@@ -1227,6 +1242,7 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
/* abort any running channel switch */
sdata->vif.bss_conf.csa_active = false;
+ ieee80211_mesh_reset_csa(sdata);
ieee80211_vif_unblock_queues_csa(sdata);
/* flush STAs and mpaths on this iface */
@@ -1531,19 +1547,10 @@ static void ieee80211_mesh_rx_bcn_presp(struct ieee80211_sub_if_data *sdata,
int ieee80211_mesh_finish_csa(struct ieee80211_sub_if_data *sdata, u64 *changed)
{
- struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
- struct mesh_csa_settings *tmp_csa_settings;
- int ret = 0;
+ int ret;
- /* Reset the TTL value and Initiator flag */
- ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
- ifmsh->chsw_ttl = 0;
+ ieee80211_mesh_reset_csa(sdata);
- /* Remove the CSA and MCSP elements from the beacon */
- tmp_csa_settings = sdata_dereference(ifmsh->csa, sdata);
- RCU_INIT_POINTER(ifmsh->csa, NULL);
- if (tmp_csa_settings)
- kfree_rcu(tmp_csa_settings, rcu_head);
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 077/877] wifi: mac80211: mesh: release the channel if start fails
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 076/877] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 078/877] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
` (807 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+63a84ea9c0f57d6133fa,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ae97fff6495a8764bc0ef281cfe5444f701e527f ]
ieee80211_join_mesh() acquires a channel context and then calls
ieee80211_start_mesh(), which can fail. In that case, the chanctx
isn't released then interface removal will attempt to unassign it
after it's removed from the driver, hitting:
wlan0: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx
ieee80211_assign_link_chanctx
__ieee80211_link_release_channel
ieee80211_link_release_channel
ieee80211_teardown_sdata
unregister_netdevice_many_notify
_cfg80211_unregister_wdev
ieee80211_remove_interfaces
ieee80211_unregister_hw
mac80211_hwsim_del_radio
hwsim_exit_net
Correctly release the channel on start failures.
Assisted-by: LLM
Reported-by: syzbot+63a84ea9c0f57d6133fa@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=63a84ea9c0f57d6133fa
Fixes: 2b5e19677592 ("mac80211: cache mesh beacon")
Link: https://patch.msgid.link/20260908122838.201719-21-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 71310d708dbc4..73f56e4143f66 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -2691,7 +2691,11 @@ static int ieee80211_join_mesh(struct wiphy *wiphy, struct net_device *dev,
if (err)
return err;
- return ieee80211_start_mesh(sdata);
+ err = ieee80211_start_mesh(sdata);
+ if (err)
+ ieee80211_link_release_channel(&sdata->deflink);
+
+ return err;
}
static int ieee80211_leave_mesh(struct wiphy *wiphy, struct net_device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 078/877] wifi: mac80211: set up the TX info early to fix failure paths
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 077/877] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 079/877] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
` (806 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 50d3d79dc0743b616afb00d01a626c76758721f7 ]
The previous commit 2c51457d930f ("wifi: mac80211: free ack status
frame on TX header build failure") cleaned up the leak, but still
left the code a bit messy and the failed SKB didn't get reported
to userspace.
Fix this up by initialising skb->cb[] earlier, which allows using
ieee80211_free_txskb() and therefore reports it for the failure
in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize()
failure path with it.
Assisted-by: LLM
Fixes: c3e7724b6bc2 ("mac80211: use ieee80211_free_txskb to fix possible skb leaks")
Link: https://patch.msgid.link/20260908122838.201719-22-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 38 ++++++++++++++++++++------------------
1 file changed, 20 insertions(+), 18 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index e78e71cb92f7f..228c717ea314b 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2927,10 +2927,23 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
*/
skb = skb_share_check(skb, GFP_ATOMIC);
if (unlikely(!skb)) {
- ret = -ENOMEM;
- goto free;
+ /* skb_share_check() already freed the skb */
+ if (info_id)
+ ieee80211_remove_ack_skb(local, info_id);
+ return ERR_PTR(-ENOMEM);
}
+ /* set this up so failure paths can clean up ack skb */
+ info = IEEE80211_SKB_CB(skb);
+ memset(info, 0, sizeof(*info));
+
+ info->flags = info_flags;
+ if (info_id) {
+ info->status_data = info_id;
+ info->status_data_idr = 1;
+ }
+ info->band = band;
+
hdr.frame_control = fc;
hdr.duration_id = 0;
hdr.seq_ctrl = 0;
@@ -2969,10 +2982,8 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
head_need += local->tx_headroom;
head_need = max_t(int, 0, head_need);
if (ieee80211_skb_resize(sdata, skb, head_need, ENCRYPT_DATA)) {
- ieee80211_free_txskb(&local->hw, skb);
- skb = NULL;
ret = -ENOMEM;
- goto free;
+ goto free_txskb;
}
}
@@ -2999,16 +3010,6 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
skb_reset_mac_header(skb);
- info = IEEE80211_SKB_CB(skb);
- memset(info, 0, sizeof(*info));
-
- info->flags = info_flags;
- if (info_id) {
- info->status_data = info_id;
- info->status_data_idr = 1;
- }
- info->band = band;
-
if (likely(!cookie)) {
ctrl_flags |= u32_encode_bits(link_id,
IEEE80211_TX_CTRL_MLO_LINK);
@@ -3032,16 +3033,17 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
pre_conf_link_id, link_id);
#endif
ret = -EINVAL;
- goto free;
+ goto free_txskb;
}
}
info->control.flags = ctrl_flags;
return skb;
+ free_txskb:
+ ieee80211_free_txskb(&local->hw, skb);
+ return ERR_PTR(ret);
free:
- if (info_id)
- ieee80211_remove_ack_skb(local, info_id);
kfree_skb(skb);
return ERR_PTR(ret);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 079/877] mm: memblock: show all region flags in debugfs
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 078/877] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 080/877] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
` (805 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Meijing Zhao,
Mike Rapoport (Microsoft), Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Meijing Zhao <zhaomeijing@lixiang.com>
[ Upstream commit e2d5b01f878d76bd1142e512a0b979a1d3cd0abf ]
Commit 493f349e38d0 ("memblock: Add flags and nid info in memblock
debugfs") made memblock_debug_show() stop after finding the first set
flag. A memblock region can carry multiple flags, so the remaining flags
are hidden from debugfs.
Walk all bits in the region flags and print every set flag separated by
"|". Keep walking beyond flagname[] so that a set flag without a known
name is reported as UNKNOWN rather than silently ignored.
Fixes: 493f349e38d0 ("memblock: Add flags and nid info in memblock debugfs")
Signed-off-by: Meijing Zhao <zhaomeijing@lixiang.com>
Link: https://patch.msgid.link/20260902075944.3742866-1-zhaomeijing100@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/memblock.c | 18 +++++++++++-------
1 file changed, 11 insertions(+), 7 deletions(-)
diff --git a/mm/memblock.c b/mm/memblock.c
index 3d7b0114442c4..00ef6bea6fe8c 100644
--- a/mm/memblock.c
+++ b/mm/memblock.c
@@ -2416,14 +2416,18 @@ static int memblock_debug_show(struct seq_file *m, void *private)
else
seq_printf(m, "%4c ", 'x');
if (reg->flags) {
- for (j = 0; j < count; j++) {
- if (reg->flags & (1U << j)) {
- seq_printf(m, "%s\n", flagname[j]);
- break;
- }
+ unsigned int flags = reg->flags;
+ bool first = true;
+
+ for (j = 0; flags; j++, flags >>= 1) {
+ if (!(flags & 1))
+ continue;
+ if (!first)
+ seq_putc(m, '|');
+ seq_puts(m, j < count ? flagname[j] : "UNKNOWN");
+ first = false;
}
- if (j == count)
- seq_printf(m, "%s\n", "UNKNOWN");
+ seq_putc(m, '\n');
} else {
seq_printf(m, "%s\n", "NONE");
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 080/877] scsi: qla2xxx: Fix the ql2xfc2target parameter description
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 079/877] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 081/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
` (804 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Martin K. Petersen (Oracle), Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 779f202a92ef10a426efc07d0f4267918cb07ca3 ]
The module parameter is ql2xfc2target, but its MODULE_PARM_DESC() names
qla2xfc2target, so modinfo describes a parameter that does not exist and
shows no description for the real one.
Use the parameter name in the description.
Fixes: 877b03795fcf ("scsi: qla2xxx: Add option to disable FC2 Target support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260906171009.2560-1-kmehltretter@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_os.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c
index 7a78cff128cfa..e2c0c99a5b052 100644
--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -363,7 +363,7 @@ MODULE_PARM_DESC(ql2xnvme_queues,
int ql2xfc2target = 1;
module_param(ql2xfc2target, int, 0444);
-MODULE_PARM_DESC(qla2xfc2target,
+MODULE_PARM_DESC(ql2xfc2target,
"Enables FC2 Target support. "
"0 - FC2 Target support is disabled. "
"1 - FC2 Target support is enabled (default).");
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 081/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 080/877] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 082/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
` (803 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit cee9c863ee68cb27d66745eb03f60e357f4f8ad2 ]
xilinx_dma_alloc_chan_resources() builds a static ring of hardware
buffer descriptors once and the driver uses this ring throughout the
lifetime of a channel. This requires the allocation order of hardware
buffer descriptors from chan->free_seg_list to stay in sync with the
hardware buffer descriptor ring built at channel allocation time by
returning oldest descriptors to chan->free_seg_list first.
When chan->pending_list is not empty e.g. during
xilinx_dma_terminate_all() the chan->free_seg_list and the order of the
static hardware buffer descriptor ring get out of sync. Descriptors age
in this order: pending -> active -> done. So freeing pending_list first
returns the newest buffer descriptors to the chan->free_seg_list first
and thus breaks the order required by the static hardware buffer
descriptor ring. Then when the channel is reused, after a wrap around of
the free_seg_list the DMA will find a hardware buffer descriptor with a
length field that is still zeroed and stop with something like this:
xilinx-vdma 86000000.dma: Channel 000000003a21d7b8 has errors 10, cdr 6de4c000 tdr 6de4c000
After this no more descriptors are completed and a consumer potentially
blocks and waits forever. The only way to get out of this error state is
to rebuild the static hardware buffer descriptor ring and the
free_seg_list by releasing and re-acquiring the channel.
Fix the order in which hardware buffer descriptors are returned to
free_seg_list to ensure the mentioned requirement holds.
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-reuse-v1-1-d79827a844c7@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index bea55dc99673b..29ff6c8082fb1 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -917,9 +917,9 @@ static void xilinx_dma_free_descriptors(struct xilinx_dma_chan *chan)
spin_lock_irqsave(&chan->lock, flags);
- xilinx_dma_free_desc_list(chan, &chan->pending_list);
xilinx_dma_free_desc_list(chan, &chan->done_list);
xilinx_dma_free_desc_list(chan, &chan->active_list);
+ xilinx_dma_free_desc_list(chan, &chan->pending_list);
spin_unlock_irqrestore(&chan->lock, flags);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 082/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 081/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 083/877] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
` (802 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit 7ed1e3070c9b4bbd67d5519e14711038dd53ab13 ]
Using the DMA in cyclic mode modifies the hardware buffer descriptor
chain in xilinx_dma_prep_dma_cyclic so that the last descriptor used by
the cyclic transfer points back to the first descriptor, but it never
restores the original descriptor ring. This breaks using non-cyclic mode
after cyclic mode with an error like:
xilinx-vdma 86000000.dma: Channel 00000000354d5c8d has errors 100, cdr 6de40000 tdr 6de40400
The only way to get out of this error state is to rebuild the hardware
buffer descriptor ring by releasing and re-acquiring the channel.
Fix using non-cyclic mode after cyclic mode by always restoring the
original buffer descriptor ring in the same manner as it is set up by
xilinx_dma_alloc_chan_resources().
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-after-cyclic-mode-v1-1-1fe47e701d6c@bereza.email
Link: https://patch.msgid.link/20260818-fix-hw-buf-desc-after-cyclic-mode-v2-1-530ff44c6a81@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 29ff6c8082fb1..4a89ad8c90a34 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -753,15 +753,25 @@ xilinx_aximcdma_alloc_tx_segment(struct xilinx_dma_chan *chan)
return segment;
}
-static void xilinx_dma_clean_hw_desc(struct xilinx_axidma_desc_hw *hw)
+static void xilinx_dma_clean_hw_desc(struct xilinx_dma_chan *chan,
+ struct xilinx_axidma_tx_segment *segment)
{
- u32 next_desc = hw->next_desc;
- u32 next_desc_msb = hw->next_desc_msb;
+ dma_addr_t next;
+ u32 i;
- memset(hw, 0, sizeof(struct xilinx_axidma_desc_hw));
+ /*
+ * Restore the buffer descriptor's next descriptor pointer to the value
+ * set up in xilinx_dma_alloc_chan_resources(). Otherwise using the DMA
+ * in cyclic mode leaves the next descriptor pointer altered and
+ * prevents subsequent non-cyclic transfers.
+ */
+ i = segment - chan->seg_v;
+ next = chan->seg_p +
+ sizeof(*chan->seg_v) * ((i + 1) % XILINX_DMA_NUM_DESCS);
- hw->next_desc = next_desc;
- hw->next_desc_msb = next_desc_msb;
+ memset(&segment->hw, 0, sizeof(segment->hw));
+ segment->hw.next_desc = lower_32_bits(next);
+ segment->hw.next_desc_msb = upper_32_bits(next);
}
static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
@@ -783,7 +793,7 @@ static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
static void xilinx_dma_free_tx_segment(struct xilinx_dma_chan *chan,
struct xilinx_axidma_tx_segment *segment)
{
- xilinx_dma_clean_hw_desc(&segment->hw);
+ xilinx_dma_clean_hw_desc(chan, segment);
list_add_tail(&segment->node, &chan->free_seg_list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 083/877] RDMA/efa: Keep admin queues alive while IRQ is registered
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 082/877] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 084/877] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
` (801 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e08aca85c02ff290f785f07acae758f0daf5f49e ]
The management IRQ handler accesses both the admin completion queue and the
async event queue. The driver registered the IRQ before constructing these
queues and destroyed them before freeing the IRQ, so the handler's lifetime
was not contained by the resources it accesses.
Initialize the queues with interrupts masked, request the IRQ, and then
switch to interrupt mode. On removal, reset the device and free the IRQ
before destroying the queues. Also reset the device before destroying the
queues if IRQ registration fails, because the device already has their DMA
addresses.
Fixes: b7f5e880f377 ("RDMA/efa: Add the efa module")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-1-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 4 +---
drivers/infiniband/hw/efa/efa_main.c | 15 +++++++++------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index bafd210dd43e8..d6fb2edc96891 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -743,7 +743,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
aq->dmadev = edev->dmadev;
aq->efa_dev = edev->efa_dev;
- set_bit(EFA_AQ_STATE_POLLING_BIT, &aq->state);
+ efa_com_set_admin_polling_mode(edev, true);
sema_init(&aq->avail_cmds, aq->depth);
@@ -761,8 +761,6 @@ int efa_com_admin_init(struct efa_com_dev *edev,
if (err)
goto err_destroy_sq;
- efa_com_set_admin_polling_mode(edev, false);
-
err = efa_com_admin_init_aenq(edev, aenq_handlers);
if (err)
goto err_destroy_cq;
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 45a4564c670c0..83323a7ad7120 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -615,18 +615,21 @@ static struct efa_dev *efa_probe_device(struct pci_dev *pdev)
edev->aq.msix_vector_idx = dev->admin_msix_vector_idx;
edev->aenq.msix_vector_idx = dev->admin_msix_vector_idx;
- err = efa_set_mgmnt_irq(dev);
+ err = efa_com_admin_init(edev, &aenq_handlers);
if (err)
goto err_disable_msix;
- err = efa_com_admin_init(edev, &aenq_handlers);
+ err = efa_set_mgmnt_irq(dev);
if (err)
- goto err_free_mgmnt_irq;
+ goto err_destroy_admin;
+
+ efa_com_set_admin_polling_mode(edev, false);
return dev;
-err_free_mgmnt_irq:
- efa_free_irq(dev, &dev->admin_irq);
+err_destroy_admin:
+ efa_com_dev_reset(edev, EFA_REGS_RESET_INIT_ERR);
+ efa_com_admin_destroy(edev);
err_disable_msix:
efa_disable_msix(dev);
err_reg_read_destroy:
@@ -650,8 +653,8 @@ static void efa_remove_device(struct pci_dev *pdev,
edev = &dev->edev;
efa_com_dev_reset(edev, reset_reason);
- efa_com_admin_destroy(edev);
efa_free_irq(dev, &dev->admin_irq);
+ efa_com_admin_destroy(edev);
efa_disable_msix(dev);
efa_com_mmio_reg_read_destroy(edev);
devm_iounmap(&pdev->dev, edev->reg_bar);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 084/877] RDMA/efa: Keep EQ resources alive while IRQ is registered
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 083/877] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 085/877] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
` (800 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e22a3627b7151754f07f90ea3d1ab6e85f5d93f4 ]
The completion IRQ handler accesses the EQ state and DMA buffer. Its IRQ was
registered before that state was initialized, while teardown released the
buffer before free_irq() synchronized the handler.
Initialize the EQ without arming it, register the IRQ, and then arm it.
Reverse the resource order during teardown by freeing the IRQ before
destroying the EQ.
Fixes: 2a152512a155 ("RDMA/efa: CQ notifications")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-2-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 3 +--
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 18 ++++++++++--------
3 files changed, 12 insertions(+), 10 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index d6fb2edc96891..00e339abc2c13 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -1149,7 +1149,7 @@ static void efa_com_destroy_eq(struct efa_com_dev *edev,
err);
}
-static void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
{
u32 val = 0;
@@ -1238,7 +1238,6 @@ int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
eeq->phase = 1;
eeq->depth = params.depth;
eeq->cb = cb;
- efa_com_arm_eq(edev, eeq);
return 0;
diff --git a/drivers/infiniband/hw/efa/efa_com.h b/drivers/infiniband/hw/efa/efa_com.h
index 77282234ce686..29a9d087db5d9 100644
--- a/drivers/infiniband/hw/efa/efa_com.h
+++ b/drivers/infiniband/hw/efa/efa_com.h
@@ -157,6 +157,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
void efa_com_admin_destroy(struct efa_com_dev *edev);
int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
efa_eqe_handler cb, u16 depth, u8 msix_vec);
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq);
void efa_com_eq_destroy(struct efa_com_dev *edev, struct efa_com_eq *eeq);
int efa_com_dev_reset(struct efa_com_dev *edev,
enum efa_regs_reset_reason_types reset_reason);
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 83323a7ad7120..30cefd0bb4f56 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -301,28 +301,30 @@ static void efa_set_host_info(struct efa_dev *dev)
static void efa_destroy_eq(struct efa_dev *dev, struct efa_eq *eq)
{
- efa_com_eq_destroy(&dev->edev, &eq->eeq);
efa_free_irq(dev, &eq->irq);
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
}
static int efa_create_eq(struct efa_dev *dev, struct efa_eq *eq, u8 msix_vec)
{
int err;
- efa_setup_comp_irq(dev, eq, msix_vec);
- err = efa_request_irq(dev, &eq->irq);
+ err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
+ dev->dev_attr.max_eq_depth, msix_vec);
if (err)
return err;
- err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
- dev->dev_attr.max_eq_depth, msix_vec);
+ efa_setup_comp_irq(dev, eq, msix_vec);
+ err = efa_request_irq(dev, &eq->irq);
if (err)
- goto err_free_comp_irq;
+ goto err_destroy_eq;
+
+ efa_com_arm_eq(&dev->edev, &eq->eeq);
return 0;
-err_free_comp_irq:
- efa_free_irq(dev, &eq->irq);
+err_destroy_eq:
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 085/877] RDMA/siw: Bound fragmented header copies by the remaining length
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 084/877] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 086/877] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
` (799 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 9ff797e516dbc1ecb73701ec4c24055712d44411 ]
siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the
next copy length.
Fixes: 754209850df8 ("RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260908085520.1746329-1-Jeremy.Jean@oss.cyber.gouv.fr
Assisted-by: Codex:gpt-6
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_rx.c b/drivers/infiniband/sw/siw/siw_qp_rx.c
index ad281da44cb49..4db245748af0b 100644
--- a/drivers/infiniband/sw/siw/siw_qp_rx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_rx.c
@@ -1079,7 +1079,7 @@ static int siw_get_hdr(struct siw_rx_stream *srx)
if (iwarp_pktinfo[opcode].hdr_len > sizeof(struct iwarp_ctrl_tagged)) {
int hdrlen = iwarp_pktinfo[opcode].hdr_len;
- bytes = min_t(int, hdrlen - MIN_DDP_HDR, srx->skb_new);
+ bytes = min_t(int, hdrlen - srx->fpdu_part_rcvd, srx->skb_new);
skb_copy_bits(skb, srx->skb_offset,
(char *)c_hdr + srx->fpdu_part_rcvd, bytes);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 086/877] netfilter: nft_nat: fully initialise new_addr in netmap setup
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 085/877] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 087/877] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
` (798 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Theodor Arsenij Larionov Trichkine,
Pablo Neira Ayuso, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
[ Upstream commit d313499df66159b4b7971d760d16729598ab7e5a ]
nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.
KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.
Zero-initialise new_addr.
Fixes: 3ff7ddb1353d ("netfilter: nft_nat: add netmap support")
Signed-off-by: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_nat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nft_nat.c b/net/netfilter/nft_nat.c
index e32cd9fbc7c2e..cdbd800cac969 100644
--- a/net/netfilter/nft_nat.c
+++ b/net/netfilter/nft_nat.c
@@ -64,8 +64,8 @@ static void nft_nat_setup_netmap(struct nf_nat_range2 *range,
const struct nft_pktinfo *pkt,
const struct nft_nat *priv)
{
+ union nf_inet_addr new_addr = {};
struct sk_buff *skb = pkt->skb;
- union nf_inet_addr new_addr;
__be32 netmask;
int i, len = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 087/877] netfilter: flowtable: hold reference on ct until flow is released
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 086/877] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 088/877] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
` (797 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d ]
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Fixes: 0ff90b6c2034 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_core.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index b9e3ac950894f..b00f1c68a8e76 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -205,6 +205,14 @@ static void flow_offload_route_release(struct flow_offload *flow)
nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY);
}
+static void flow_offload_free_rcu(struct rcu_head *rcu_head)
+{
+ struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head);
+
+ nf_ct_put(flow->ct);
+ kfree(flow);
+}
+
void flow_offload_free(struct flow_offload *flow)
{
switch (flow->type) {
@@ -214,8 +222,7 @@ void flow_offload_free(struct flow_offload *flow)
default:
break;
}
- nf_ct_put(flow->ct);
- kfree_rcu(flow, rcu_head);
+ call_rcu(&flow->rcu_head, flow_offload_free_rcu);
}
EXPORT_SYMBOL_GPL(flow_offload_free);
@@ -686,6 +693,7 @@ static int __init nf_flow_table_module_init(void)
static void __exit nf_flow_table_module_exit(void)
{
+ rcu_barrier();
nf_flow_table_offload_exit();
unregister_pernet_subsys(&nf_flow_table_net_ops);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 088/877] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 087/877] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 089/877] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
` (796 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shouping Wang, Robin Murphy,
Will Deacon, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shouping Wang <allen.wang@hj-micro.com>
[ Upstream commit 49daa3d668b69a5454b5aba0078848a479f79f1c ]
When MXP_MULTIPLE_DTM_EN is TRUE, each DTM will monitor at most
two device ports. In this case, {wp_dev_sel2, wp_dev_sel} will
only use values 2'b00 and 2'b01 per DTM.
Previously the setting allowed values beyond the supported range
per DTM, which could cause each DTM to select invalid ports when
MXP_MULTIPLE_DTM_EN is TRUE.
Fix this by only setting CMN_DTM_WPn_CONFIG_WP_DEV_SEL2 when
!multi_dtm.
Fixes: 60d1504070c2 ("perf/arm-cmn: Support new IP features")
Signed-off-by: Shouping Wang <allen.wang@hj-micro.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm-cmn.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/perf/arm-cmn.c b/drivers/perf/arm-cmn.c
index 892bc6b5875a7..3a4541c51863b 100644
--- a/drivers/perf/arm-cmn.c
+++ b/drivers/perf/arm-cmn.c
@@ -1395,13 +1395,14 @@ static void arm_cmn_claim_wp_idx(struct arm_cmn_dtm *dtm,
static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
{
+ struct arm_cmn *cmn = to_cmn(event->pmu);
u32 config;
u32 dev = CMN_EVENT_WP_DEV_SEL(event);
u32 chn = CMN_EVENT_WP_CHN_SEL(event);
u32 grp = CMN_EVENT_WP_GRP(event);
u32 exc = CMN_EVENT_WP_EXCLUSIVE(event);
u32 combine = CMN_EVENT_WP_COMBINE(event);
- bool is_cmn600 = to_cmn(event->pmu)->part == PART_CMN600;
+ bool is_cmn600 = cmn->part == PART_CMN600;
/* CMN-600 supports only primary and secondary matching groups */
if (is_cmn600)
@@ -1409,8 +1410,11 @@ static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
config = FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL, dev) |
FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_CHN_SEL, chn) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+ FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp);
+
+ if (!cmn->multi_dtm)
+ config |= FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+
if (exc)
config |= is_cmn600 ? CMN600_WPn_CONFIG_WP_EXCLUSIVE :
CMN_DTM_WPn_CONFIG_WP_EXCLUSIVE;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 089/877] arm64: hibernate: clone only the linear map that exists at runtime
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 088/877] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 090/877] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
` (795 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Ard Biesheuvel,
Will Deacon, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit e4a6f57d22e079e23fafac51057fad534160b269 ]
This is similar to commit 1537e55728ec2 ("arm64: trans_pgd: clone only
the linear map that exists at runtime"), but in a different place.
swsusp_arch_resume() clones the kernel linear map with
trans_pgd_create_copy(..., PAGE_OFFSET, PAGE_END). PAGE_OFFSET comes
from the compile-time VA_BITS, so a CONFIG_ARM64_VA_BITS_52 kernel
booting on hardware without LPA2 -- vabits_actual is 48 and the fifth
level is folded -- hands the walk a 3.9PB window while its linear map
only spans the top 128TB.
On a VA_BITS_52 4k kernel with CONFIG_KASAN_GENERIC in a 4GB VM, I see:
swapper/0: page allocation failure: order:0, mode:0x920(GFP_ATOMIC|__GFP_ZERO)
hibernate_page_alloc+0x10/0x1c
swsusp_arch_resume+0x70/0x320
hibernation_restore+0xa4/0x138
software_resume+0x15c/0x270
PM: hibernation: Failed to load image, recovering.
PM: hibernation: resume failed (-12)
Fix it by copying the linear map that is the actual one, not the
compiled one.
Fixes: a6bbf5d4d9d1 ("arm64: mm: Add definitions to support 5 levels of paging")
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/hibernate.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 44d31b019efd5..b883f6d833b6b 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -417,8 +417,8 @@ int __nocfi swsusp_arch_resume(void)
* Create a second copy of just the linear map, and use this when
* restoring.
*/
- rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir, PAGE_OFFSET,
- PAGE_END);
+ rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir,
+ _PAGE_OFFSET(vabits_actual), PAGE_END);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 090/877] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 089/877] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 091/877] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
` (794 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Thadeu Lima de Souza Cascardo, Melissa Wen, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
[ Upstream commit 9eb1a393c89a79c4210230d23e7d88d239c61d7b ]
When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().
Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260727-drm_crtc_atomic_commit_leak-v1-1-23d9948a9d7c@igalia.com?part=1
Fixes: 92c715fca907 ("drm/atomic: Fix double free in drm_atomic_state_default_clear")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Signed-off-by: Melissa Wen <mwen@igalia.com>
Link: https://patch.msgid.link/20260826-drm_pending_vblank_event_leak-v4-1-f8de8b996b9d@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_atomic_uapi.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_atomic_uapi.c b/drivers/gpu/drm/drm_atomic_uapi.c
index fc20b039bed40..02255296cc576 100644
--- a/drivers/gpu/drm/drm_atomic_uapi.c
+++ b/drivers/gpu/drm/drm_atomic_uapi.c
@@ -1225,10 +1225,12 @@ static int prepare_signaling(struct drm_device *dev,
struct dma_fence *fence;
struct drm_out_fence_state *f;
+ ret = -ENOMEM;
+
f = krealloc(*fence_state, sizeof(**fence_state) *
(*num_fences + 1), GFP_KERNEL);
if (!f)
- return -ENOMEM;
+ goto err_free_event;
memset(&f[*num_fences], 0, sizeof(*f));
@@ -1237,12 +1239,12 @@ static int prepare_signaling(struct drm_device *dev,
fence = drm_crtc_create_fence(crtc);
if (!fence)
- return -ENOMEM;
+ goto err_free_event;
ret = setup_out_fence(&f[(*num_fences)++], fence);
if (ret) {
dma_fence_put(fence);
- return ret;
+ goto err_free_event;
}
crtc_state->event->base.fence = fence;
@@ -1298,6 +1300,11 @@ static int prepare_signaling(struct drm_device *dev,
}
return 0;
+
+err_free_event:
+ drm_event_cancel_free(dev, &crtc_state->event->base);
+ crtc_state->event = NULL;
+ return ret;
}
static void complete_signaling(struct drm_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 091/877] keys: fix lost wakeup when reaping a dead key type
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 090/877] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 092/877] neighbour: Use rtnl_register_many() Greg Kroah-Hartman
` (793 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jarkko Sakkinen,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 2725ab3f5ad1c5f375c7c9fee4af02a9b138f701 ]
clear_bit() is atomic with respect to the word it modifies, but it is
an unordered operation: it implies no memory barrier on either side
(Documentation/atomic_bitops.txt).
key_garbage_collector() clears KEY_GC_REAPING_KEYTYPE with clear_bit()
and calls wake_up_bit() after reaping a dead key type. wake_up_bit()
uses a lockless waitqueue check and requires a full barrier after the
clear.
The existing smp_mb() is before clear_bit(), so nothing orders the clear
against that check. The GC can see an empty waitqueue while
unregister_key_type() still sees the bit set. The final wakeup is then
lost, leaving module unload stuck in wait_on_bit().
Use clear_and_wake_up_bit(). Its clear_bit_unlock() has RELEASE
semantics, so the completed GC work stays ordered before the clear, and
its smp_mb__after_atomic() orders the clear before the waitqueue check.
Fixes: 0c061b5707ab ("KEYS: Correctly destroy key payloads when their keytype is removed")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://lore.kernel.org/r/20260821025327.61488-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/gc.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/security/keys/gc.c b/security/keys/gc.c
index f27223ea4578f..cf71b26c0c008 100644
--- a/security/keys/gc.c
+++ b/security/keys/gc.c
@@ -318,9 +318,7 @@ static void key_garbage_collector(struct work_struct *work)
if (unlikely(gc_state & KEY_GC_REAPING_DEAD_3)) {
kdebug("dead wake");
- smp_mb();
- clear_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
- wake_up_bit(&key_gc_flags, KEY_GC_REAPING_KEYTYPE);
+ clear_and_wake_up_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
}
if (gc_state & KEY_GC_REAP_AGAIN)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 092/877] neighbour: Use rtnl_register_many().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 091/877] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-10-01 19:19 ` Harshit Mogalapalli
2026-09-30 15:16 ` [PATCH 6.12 093/877] neighbour: Make neigh_valid_get_req() return ndmsg Greg Kroah-Hartman
` (792 subsequent siblings)
884 siblings, 1 reply; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@amazon.com>
[ Upstream commit d0d14aef50a6184426c5a05b9815fb2697d6d42c ]
We will remove rtnl_register() in favour of rtnl_register_many().
When it succeeds, rtnl_register_many() guarantees all rtnetlink types
in the passed array are supported, and there is no chance that a part
of message types is not supported.
Let's use rtnl_register_many() instead.
Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20241014201828.91221-4-kuniyu@amazon.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 19 ++++++++++---------
1 file changed, 10 insertions(+), 9 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index bf07438d6dfa5..1dd9f85b74997 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -3898,17 +3898,18 @@ EXPORT_SYMBOL(neigh_sysctl_unregister);
#endif /* CONFIG_SYSCTL */
+static const struct rtnl_msg_handler neigh_rtnl_msg_handlers[] __initconst = {
+ {.msgtype = RTM_NEWNEIGH, .doit = neigh_add},
+ {.msgtype = RTM_DELNEIGH, .doit = neigh_delete},
+ {.msgtype = RTM_GETNEIGH, .doit = neigh_get, .dumpit = neigh_dump_info,
+ .flags = RTNL_FLAG_DUMP_UNLOCKED},
+ {.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info},
+ {.msgtype = RTM_SETNEIGHTBL, .doit = neightbl_set},
+};
+
static int __init neigh_init(void)
{
- rtnl_register(PF_UNSPEC, RTM_NEWNEIGH, neigh_add, NULL, 0);
- rtnl_register(PF_UNSPEC, RTM_DELNEIGH, neigh_delete, NULL, 0);
- rtnl_register(PF_UNSPEC, RTM_GETNEIGH, neigh_get, neigh_dump_info,
- RTNL_FLAG_DUMP_UNLOCKED);
-
- rtnl_register(PF_UNSPEC, RTM_GETNEIGHTBL, NULL, neightbl_dump_info,
- 0);
- rtnl_register(PF_UNSPEC, RTM_SETNEIGHTBL, neightbl_set, NULL, 0);
-
+ rtnl_register_many(neigh_rtnl_msg_handlers);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 093/877] neighbour: Make neigh_valid_get_req() return ndmsg.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 092/877] neighbour: Use rtnl_register_many() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 094/877] neighbour: Move two validations from neigh_get() to neigh_valid_get_req() Greg Kroah-Hartman
` (791 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit caf0a753a8eb7ca2b035e199b71a3dabb853a18a ]
neigh_get() passes 4 local variable pointers to neigh_valid_get_req().
If it returns a pointer of struct ndmsg, we do not need to pass two
of them.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250716221221.442239-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 43 +++++++++++++++++++------------------------
1 file changed, 19 insertions(+), 24 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 1dd9f85b74997..fe921f8cc81c1 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2911,10 +2911,9 @@ static int neigh_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
return err;
}
-static int neigh_valid_get_req(const struct nlmsghdr *nlh,
- struct neigh_table **tbl,
- void **dst, int *dev_idx, u8 *ndm_flags,
- struct netlink_ext_ack *extack)
+static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
+ struct neigh_table **tbl, void **dst,
+ struct netlink_ext_ack *extack)
{
struct nlattr *tb[NDA_MAX + 1];
struct ndmsg *ndm;
@@ -2922,32 +2921,30 @@ static int neigh_valid_get_req(const struct nlmsghdr *nlh,
if (nlh->nlmsg_len < nlmsg_msg_size(sizeof(*ndm))) {
NL_SET_ERR_MSG(extack, "Invalid header for neighbor get request");
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
}
ndm = nlmsg_data(nlh);
if (ndm->ndm_pad1 || ndm->ndm_pad2 || ndm->ndm_state ||
ndm->ndm_type) {
NL_SET_ERR_MSG(extack, "Invalid values in header for neighbor get request");
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
}
if (ndm->ndm_flags & ~NTF_PROXY) {
NL_SET_ERR_MSG(extack, "Invalid flags in header for neighbor get request");
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
}
err = nlmsg_parse_deprecated_strict(nlh, sizeof(struct ndmsg), tb,
NDA_MAX, nda_policy, extack);
if (err < 0)
- return err;
+ return ERR_PTR(err);
- *ndm_flags = ndm->ndm_flags;
- *dev_idx = ndm->ndm_ifindex;
*tbl = neigh_find_table(ndm->ndm_family);
- if (*tbl == NULL) {
+ if (!*tbl) {
NL_SET_ERR_MSG(extack, "Unsupported family in header for neighbor get request");
- return -EAFNOSUPPORT;
+ return ERR_PTR(-EAFNOSUPPORT);
}
for (i = 0; i <= NDA_MAX; ++i) {
@@ -2958,17 +2955,17 @@ static int neigh_valid_get_req(const struct nlmsghdr *nlh,
case NDA_DST:
if (nla_len(tb[i]) != (int)(*tbl)->key_len) {
NL_SET_ERR_MSG(extack, "Invalid network address in neighbor get request");
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
}
*dst = nla_data(tb[i]);
break;
default:
NL_SET_ERR_MSG(extack, "Unsupported attribute in neighbor get request");
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
}
}
- return 0;
+ return ndm;
}
static inline size_t neigh_nlmsg_size(void)
@@ -3039,18 +3036,16 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
struct net_device *dev = NULL;
struct neigh_table *tbl = NULL;
struct neighbour *neigh;
+ struct ndmsg *ndm;
void *dst = NULL;
- u8 ndm_flags = 0;
- int dev_idx = 0;
int err;
- err = neigh_valid_get_req(nlh, &tbl, &dst, &dev_idx, &ndm_flags,
- extack);
- if (err < 0)
- return err;
+ ndm = neigh_valid_get_req(nlh, &tbl, &dst, extack);
+ if (IS_ERR(ndm))
+ return PTR_ERR(ndm);
- if (dev_idx) {
- dev = __dev_get_by_index(net, dev_idx);
+ if (ndm->ndm_ifindex) {
+ dev = __dev_get_by_index(net, ndm->ndm_ifindex);
if (!dev) {
NL_SET_ERR_MSG(extack, "Unknown device ifindex");
return -ENODEV;
@@ -3062,7 +3057,7 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
return -EINVAL;
}
- if (ndm_flags & NTF_PROXY) {
+ if (ndm->ndm_flags & NTF_PROXY) {
struct pneigh_entry *pn;
pn = pneigh_lookup(tbl, net, dst, dev, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 094/877] neighbour: Move two validations from neigh_get() to neigh_valid_get_req().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 093/877] neighbour: Make neigh_valid_get_req() return ndmsg Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 095/877] neighbour: Allocate skb in neigh_get() Greg Kroah-Hartman
` (790 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit f5046fbc1b6d8c5168d47a617f368f9d4a025e34 ]
We will remove RTNL for neigh_get() and run it under RCU instead.
neigh_get() returns -EINVAL in the following cases:
* NDA_DST is not specified
* Both ndm->ndm_ifindex and NTF_PROXY are not specified
These validations do not require RCU.
Let's move them to neigh_valid_get_req().
While at it, the extack string for the first case is replaced with
NL_SET_ERR_ATTR_MISS().
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250716221221.442239-3-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 26 +++++++++++++-------------
1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index fe921f8cc81c1..ecfa1cc2f85f2 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2936,6 +2936,11 @@ static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
return ERR_PTR(-EINVAL);
}
+ if (!(ndm->ndm_flags & NTF_PROXY) && !ndm->ndm_ifindex) {
+ NL_SET_ERR_MSG(extack, "No device specified");
+ return ERR_PTR(-EINVAL);
+ }
+
err = nlmsg_parse_deprecated_strict(nlh, sizeof(struct ndmsg), tb,
NDA_MAX, nda_policy, extack);
if (err < 0)
@@ -2948,11 +2953,13 @@ static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
}
for (i = 0; i <= NDA_MAX; ++i) {
- if (!tb[i])
- continue;
-
switch (i) {
case NDA_DST:
+ if (!tb[i]) {
+ NL_SET_ERR_ATTR_MISS(extack, NULL, NDA_DST);
+ return ERR_PTR(-EINVAL);
+ }
+
if (nla_len(tb[i]) != (int)(*tbl)->key_len) {
NL_SET_ERR_MSG(extack, "Invalid network address in neighbor get request");
return ERR_PTR(-EINVAL);
@@ -2960,6 +2967,9 @@ static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
*dst = nla_data(tb[i]);
break;
default:
+ if (!tb[i])
+ continue;
+
NL_SET_ERR_MSG(extack, "Unsupported attribute in neighbor get request");
return ERR_PTR(-EINVAL);
}
@@ -3052,11 +3062,6 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
}
}
- if (!dst) {
- NL_SET_ERR_MSG(extack, "Network address not specified");
- return -EINVAL;
- }
-
if (ndm->ndm_flags & NTF_PROXY) {
struct pneigh_entry *pn;
@@ -3069,11 +3074,6 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
nlh->nlmsg_seq, tbl);
}
- if (!dev) {
- NL_SET_ERR_MSG(extack, "No device specified");
- return -EINVAL;
- }
-
neigh = neigh_lookup(tbl, dst, dev);
if (!neigh) {
NL_SET_ERR_MSG(extack, "Neighbour entry not found");
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 095/877] neighbour: Allocate skb in neigh_get().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 094/877] neighbour: Move two validations from neigh_get() to neigh_valid_get_req() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 096/877] neighbour: Move neigh_find_table() to neigh_get() Greg Kroah-Hartman
` (789 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 3dfe0b57dcda070d9f1ed2bfb3a9bf0ec8632e08 ]
We will remove RTNL for neigh_get() and run it under RCU instead.
neigh_get_reply() and pneigh_get_reply() allocate skb with GFP_KERNEL.
Let's move the allocation before __dev_get_by_index() in neigh_get().
Now, neigh_get_reply() and pneigh_get_reply() are inlined and
rtnl_unicast() is factorised.
We will convert pneigh_lookup() to __pneigh_lookup() later.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250716221221.442239-4-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 88 ++++++++++++++++----------------------------
1 file changed, 32 insertions(+), 56 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index ecfa1cc2f85f2..b57d5810fa0d8 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2989,27 +2989,6 @@ static inline size_t neigh_nlmsg_size(void)
+ nla_total_size(1); /* NDA_PROTOCOL */
}
-static int neigh_get_reply(struct net *net, struct neighbour *neigh,
- u32 pid, u32 seq)
-{
- struct sk_buff *skb;
- int err = 0;
-
- skb = nlmsg_new(neigh_nlmsg_size(), GFP_KERNEL);
- if (!skb)
- return -ENOBUFS;
-
- err = neigh_fill_info(skb, neigh, pid, seq, RTM_NEWNEIGH, 0);
- if (err) {
- kfree_skb(skb);
- goto errout;
- }
-
- err = rtnl_unicast(skb, net, pid);
-errout:
- return err;
-}
-
static inline size_t pneigh_nlmsg_size(void)
{
return NLMSG_ALIGN(sizeof(struct ndmsg))
@@ -3018,34 +2997,16 @@ static inline size_t pneigh_nlmsg_size(void)
+ nla_total_size(1); /* NDA_PROTOCOL */
}
-static int pneigh_get_reply(struct net *net, struct pneigh_entry *neigh,
- u32 pid, u32 seq, struct neigh_table *tbl)
-{
- struct sk_buff *skb;
- int err = 0;
-
- skb = nlmsg_new(pneigh_nlmsg_size(), GFP_KERNEL);
- if (!skb)
- return -ENOBUFS;
-
- err = pneigh_fill_info(skb, neigh, pid, seq, RTM_NEWNEIGH, 0, tbl);
- if (err) {
- kfree_skb(skb);
- goto errout;
- }
-
- err = rtnl_unicast(skb, net, pid);
-errout:
- return err;
-}
-
static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
struct netlink_ext_ack *extack)
{
struct net *net = sock_net(in_skb->sk);
+ u32 pid = NETLINK_CB(in_skb).portid;
struct net_device *dev = NULL;
struct neigh_table *tbl = NULL;
+ u32 seq = nlh->nlmsg_seq;
struct neighbour *neigh;
+ struct sk_buff *skb;
struct ndmsg *ndm;
void *dst = NULL;
int err;
@@ -3054,11 +3015,19 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
if (IS_ERR(ndm))
return PTR_ERR(ndm);
+ if (ndm->ndm_flags & NTF_PROXY)
+ skb = nlmsg_new(neigh_nlmsg_size(), GFP_KERNEL);
+ else
+ skb = nlmsg_new(pneigh_nlmsg_size(), GFP_KERNEL);
+ if (!skb)
+ return -ENOBUFS;
+
if (ndm->ndm_ifindex) {
dev = __dev_get_by_index(net, ndm->ndm_ifindex);
if (!dev) {
NL_SET_ERR_MSG(extack, "Unknown device ifindex");
- return -ENODEV;
+ err = -ENODEV;
+ goto err_free_skb;
}
}
@@ -3068,23 +3037,30 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
pn = pneigh_lookup(tbl, net, dst, dev, 0);
if (!pn) {
NL_SET_ERR_MSG(extack, "Proxy neighbour entry not found");
- return -ENOENT;
+ err = -ENOENT;
+ goto err_free_skb;
}
- return pneigh_get_reply(net, pn, NETLINK_CB(in_skb).portid,
- nlh->nlmsg_seq, tbl);
- }
-
- neigh = neigh_lookup(tbl, dst, dev);
- if (!neigh) {
- NL_SET_ERR_MSG(extack, "Neighbour entry not found");
- return -ENOENT;
- }
- err = neigh_get_reply(net, neigh, NETLINK_CB(in_skb).portid,
- nlh->nlmsg_seq);
+ err = pneigh_fill_info(skb, pn, pid, seq, RTM_NEWNEIGH, 0, tbl);
+ if (err)
+ goto err_free_skb;
+ } else {
+ neigh = neigh_lookup(tbl, dst, dev);
+ if (!neigh) {
+ NL_SET_ERR_MSG(extack, "Neighbour entry not found");
+ err = -ENOENT;
+ goto err_free_skb;
+ }
- neigh_release(neigh);
+ err = neigh_fill_info(skb, neigh, pid, seq, RTM_NEWNEIGH, 0);
+ neigh_release(neigh);
+ if (err)
+ goto err_free_skb;
+ }
+ return rtnl_unicast(skb, net, pid);
+err_free_skb:
+ kfree_skb(skb);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 096/877] neighbour: Move neigh_find_table() to neigh_get().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 095/877] neighbour: Allocate skb in neigh_get() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 097/877] neighbour: Convert RTM_GETNEIGH to RCU Greg Kroah-Hartman
` (788 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 0e5ac19c78654abbf43dc4ffdae290c8cb81c59c ]
neigh_valid_get_req() calls neigh_find_table() to fetch neigh_tables[].
neigh_find_table() uses rcu_dereference_rtnl(), but RTNL actually does
not protect it at all; neigh_table_clear() can be called without RTNL
and only waits for RCU readers by synchronize_rcu().
Fortunately, there is no bug because IPv4 is built-in, IPv6 cannot be
unloaded, and DECNET was removed.
To fetch neigh_tables[] by rcu_dereference() later, let's move
neigh_find_table() from neigh_valid_get_req() to neigh_get().
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250716221221.442239-5-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 37 ++++++++++++++++++++-----------------
1 file changed, 20 insertions(+), 17 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index b57d5810fa0d8..0dc0ba5cf7443 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2912,10 +2912,9 @@ static int neigh_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
}
static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
- struct neigh_table **tbl, void **dst,
+ struct nlattr **tb,
struct netlink_ext_ack *extack)
{
- struct nlattr *tb[NDA_MAX + 1];
struct ndmsg *ndm;
int err, i;
@@ -2946,12 +2945,6 @@ static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
if (err < 0)
return ERR_PTR(err);
- *tbl = neigh_find_table(ndm->ndm_family);
- if (!*tbl) {
- NL_SET_ERR_MSG(extack, "Unsupported family in header for neighbor get request");
- return ERR_PTR(-EAFNOSUPPORT);
- }
-
for (i = 0; i <= NDA_MAX; ++i) {
switch (i) {
case NDA_DST:
@@ -2959,12 +2952,6 @@ static struct ndmsg *neigh_valid_get_req(const struct nlmsghdr *nlh,
NL_SET_ERR_ATTR_MISS(extack, NULL, NDA_DST);
return ERR_PTR(-EINVAL);
}
-
- if (nla_len(tb[i]) != (int)(*tbl)->key_len) {
- NL_SET_ERR_MSG(extack, "Invalid network address in neighbor get request");
- return ERR_PTR(-EINVAL);
- }
- *dst = nla_data(tb[i]);
break;
default:
if (!tb[i])
@@ -3002,16 +2989,17 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
{
struct net *net = sock_net(in_skb->sk);
u32 pid = NETLINK_CB(in_skb).portid;
+ struct nlattr *tb[NDA_MAX + 1];
struct net_device *dev = NULL;
- struct neigh_table *tbl = NULL;
u32 seq = nlh->nlmsg_seq;
+ struct neigh_table *tbl;
struct neighbour *neigh;
struct sk_buff *skb;
struct ndmsg *ndm;
- void *dst = NULL;
+ void *dst;
int err;
- ndm = neigh_valid_get_req(nlh, &tbl, &dst, extack);
+ ndm = neigh_valid_get_req(nlh, tb, extack);
if (IS_ERR(ndm))
return PTR_ERR(ndm);
@@ -3022,6 +3010,21 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
if (!skb)
return -ENOBUFS;
+ tbl = neigh_find_table(ndm->ndm_family);
+ if (!tbl) {
+ NL_SET_ERR_MSG(extack, "Unsupported family in header for neighbor get request");
+ err = -EAFNOSUPPORT;
+ goto err_free_skb;
+ }
+
+ if (nla_len(tb[NDA_DST]) != (int)tbl->key_len) {
+ NL_SET_ERR_MSG(extack, "Invalid network address in neighbor get request");
+ err = -EINVAL;
+ goto err_free_skb;
+ }
+
+ dst = nla_data(tb[NDA_DST]);
+
if (ndm->ndm_ifindex) {
dev = __dev_get_by_index(net, ndm->ndm_ifindex);
if (!dev) {
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 097/877] neighbour: Convert RTM_GETNEIGH to RCU.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 096/877] neighbour: Move neigh_find_table() to neigh_get() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 098/877] neighbour: Convert RTM_GETNEIGHTBL " Greg Kroah-Hartman
` (787 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit ed6e380d2d419a3e8ca73de7b4c7ccb522835f1e ]
Only __dev_get_by_index() is the RTNL dependant in neigh_get().
Let's replace it with dev_get_by_index_rcu() and convert RTM_GETNEIGH
to RCU.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250716221221.442239-10-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 25 +++++++++++++++----------
1 file changed, 15 insertions(+), 10 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 0dc0ba5cf7443..50a18ae55409e 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -3010,27 +3010,29 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
if (!skb)
return -ENOBUFS;
+ rcu_read_lock();
+
tbl = neigh_find_table(ndm->ndm_family);
if (!tbl) {
NL_SET_ERR_MSG(extack, "Unsupported family in header for neighbor get request");
err = -EAFNOSUPPORT;
- goto err_free_skb;
+ goto err_unlock;
}
if (nla_len(tb[NDA_DST]) != (int)tbl->key_len) {
NL_SET_ERR_MSG(extack, "Invalid network address in neighbor get request");
err = -EINVAL;
- goto err_free_skb;
+ goto err_unlock;
}
dst = nla_data(tb[NDA_DST]);
if (ndm->ndm_ifindex) {
- dev = __dev_get_by_index(net, ndm->ndm_ifindex);
+ dev = dev_get_by_index_rcu(net, ndm->ndm_ifindex);
if (!dev) {
NL_SET_ERR_MSG(extack, "Unknown device ifindex");
err = -ENODEV;
- goto err_free_skb;
+ goto err_unlock;
}
}
@@ -3041,28 +3043,31 @@ static int neigh_get(struct sk_buff *in_skb, struct nlmsghdr *nlh,
if (!pn) {
NL_SET_ERR_MSG(extack, "Proxy neighbour entry not found");
err = -ENOENT;
- goto err_free_skb;
+ goto err_unlock;
}
err = pneigh_fill_info(skb, pn, pid, seq, RTM_NEWNEIGH, 0, tbl);
if (err)
- goto err_free_skb;
+ goto err_unlock;
} else {
neigh = neigh_lookup(tbl, dst, dev);
if (!neigh) {
NL_SET_ERR_MSG(extack, "Neighbour entry not found");
err = -ENOENT;
- goto err_free_skb;
+ goto err_unlock;
}
err = neigh_fill_info(skb, neigh, pid, seq, RTM_NEWNEIGH, 0);
neigh_release(neigh);
if (err)
- goto err_free_skb;
+ goto err_unlock;
}
+ rcu_read_unlock();
+
return rtnl_unicast(skb, net, pid);
-err_free_skb:
+err_unlock:
+ rcu_read_unlock();
kfree_skb(skb);
return err;
}
@@ -3876,7 +3881,7 @@ static const struct rtnl_msg_handler neigh_rtnl_msg_handlers[] __initconst = {
{.msgtype = RTM_NEWNEIGH, .doit = neigh_add},
{.msgtype = RTM_DELNEIGH, .doit = neigh_delete},
{.msgtype = RTM_GETNEIGH, .doit = neigh_get, .dumpit = neigh_dump_info,
- .flags = RTNL_FLAG_DUMP_UNLOCKED},
+ .flags = RTNL_FLAG_DOIT_UNLOCKED | RTNL_FLAG_DUMP_UNLOCKED},
{.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info},
{.msgtype = RTM_SETNEIGHTBL, .doit = neightbl_set},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 098/877] neighbour: Convert RTM_GETNEIGHTBL to RCU.
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 097/877] neighbour: Convert RTM_GETNEIGH to RCU Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-10-01 19:34 ` Harshit Mogalapalli
2026-09-30 15:16 ` [PATCH 6.12 099/877] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
` (786 subsequent siblings)
884 siblings, 1 reply; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 4ae34be500649ec452ac1fc2748958683ad9b55d ]
neightbl_dump_info() calls these functions for each neigh_tables[]
entry:
1. neightbl_fill_info() for tbl->parms
2. neightbl_fill_param_info() for tbl->parms_list (except tbl->parms)
Both functions rely on the table lock (read_lock_bh(&tbl->lock))
and RTNL is not needed.
Let's fetch the table under RCU and convert RTM_GETNEIGHTBL to RCU.
Note that the first entry of tbl->parms_list is tbl->parms.list and
embedded in neigh_table, so list_next_entry() is safe.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251022054004.2514876-4-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 23 +++++++++--------------
1 file changed, 9 insertions(+), 14 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 50a18ae55409e..d38c309e7fa61 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2131,7 +2131,7 @@ static int neightbl_fill_parms(struct sk_buff *skb, struct neigh_parms *parms)
return -ENOBUFS;
if ((parms->dev &&
- nla_put_u32(skb, NDTPA_IFINDEX, parms->dev->ifindex)) ||
+ nla_put_u32(skb, NDTPA_IFINDEX, READ_ONCE(parms->dev->ifindex))) ||
nla_put_u32(skb, NDTPA_REFCNT, refcount_read(&parms->refcnt)) ||
nla_put_u32(skb, NDTPA_QUEUE_LENBYTES,
NEIGH_VAR(parms, QUEUE_LEN_BYTES)) ||
@@ -2183,8 +2183,6 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
return -EMSGSIZE;
ndtmsg = nlmsg_data(nlh);
-
- read_lock_bh(&tbl->lock);
ndtmsg->ndtm_family = tbl->family;
ndtmsg->ndtm_pad1 = 0;
ndtmsg->ndtm_pad2 = 0;
@@ -2210,11 +2208,9 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
.ndtc_proxy_qlen = READ_ONCE(tbl->proxy_queue.qlen),
};
- rcu_read_lock();
nht = rcu_dereference(tbl->nht);
ndc.ndtc_hash_rnd = nht->hash_rnd[0];
ndc.ndtc_hash_mask = ((1 << nht->hash_shift) - 1);
- rcu_read_unlock();
if (nla_put(skb, NDTA_CONFIG, sizeof(ndc), &ndc))
goto nla_put_failure;
@@ -2252,12 +2248,10 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
if (neightbl_fill_parms(skb, &tbl->parms) < 0)
goto nla_put_failure;
- read_unlock_bh(&tbl->lock);
nlmsg_end(skb, nlh);
return 0;
nla_put_failure:
- read_unlock_bh(&tbl->lock);
nlmsg_cancel(skb, nlh);
return -EMSGSIZE;
}
@@ -2276,8 +2270,6 @@ static int neightbl_fill_param_info(struct sk_buff *skb,
return -EMSGSIZE;
ndtmsg = nlmsg_data(nlh);
-
- read_lock_bh(&tbl->lock);
ndtmsg->ndtm_family = tbl->family;
ndtmsg->ndtm_pad1 = 0;
ndtmsg->ndtm_pad2 = 0;
@@ -2286,11 +2278,9 @@ static int neightbl_fill_param_info(struct sk_buff *skb,
neightbl_fill_parms(skb, parms) < 0)
goto errout;
- read_unlock_bh(&tbl->lock);
nlmsg_end(skb, nlh);
return 0;
errout:
- read_unlock_bh(&tbl->lock);
nlmsg_cancel(skb, nlh);
return -EMSGSIZE;
}
@@ -2531,10 +2521,12 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
family = ((struct rtgenmsg *)nlmsg_data(nlh))->rtgen_family;
+ rcu_read_lock();
+
for (tidx = 0; tidx < NEIGH_NR_TABLES; tidx++) {
struct neigh_parms *p;
- tbl = rcu_dereference_rtnl(neigh_tables[tidx]);
+ tbl = rcu_dereference(neigh_tables[tidx]);
if (!tbl)
continue;
@@ -2548,7 +2540,7 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
nidx = 0;
p = list_next_entry(&tbl->parms, list);
- list_for_each_entry_from(p, &tbl->parms_list, list) {
+ list_for_each_entry_from_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
continue;
@@ -2568,6 +2560,8 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
neigh_skip = 0;
}
out:
+ rcu_read_unlock();
+
cb->args[0] = tidx;
cb->args[1] = nidx;
@@ -3882,7 +3876,8 @@ static const struct rtnl_msg_handler neigh_rtnl_msg_handlers[] __initconst = {
{.msgtype = RTM_DELNEIGH, .doit = neigh_delete},
{.msgtype = RTM_GETNEIGH, .doit = neigh_get, .dumpit = neigh_dump_info,
.flags = RTNL_FLAG_DOIT_UNLOCKED | RTNL_FLAG_DUMP_UNLOCKED},
- {.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info},
+ {.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info,
+ .flags = RTNL_FLAG_DUMP_UNLOCKED},
{.msgtype = RTM_SETNEIGHTBL, .doit = neightbl_set},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 099/877] neighbour: Add missing RCU annotation for neightbl_dump_info().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 098/877] neighbour: Convert RTM_GETNEIGHTBL " Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 100/877] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
` (785 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 764dcebb033764633700a036c7351a7c6350eec6 ]
neightbl_dump_info() fetches the first non-default neigh_parms
with list_next_entry(&tbl->parms, ...) and iterates through the
list with list_for_each_entry_from_rcu().
However, list_next_entry() does not use RCU helper.
Let's use list_for_each_entry_rcu() and skip the default parms.
Fixes: 4ae34be50064 ("neighbour: Convert RTM_GETNEIGHTBL to RCU.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index d38c309e7fa61..c9d848085dad3 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2539,11 +2539,14 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
break;
nidx = 0;
- p = list_next_entry(&tbl->parms, list);
- list_for_each_entry_from_rcu(p, &tbl->parms_list, list) {
+
+ list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
continue;
+ if (!p->dev)
+ continue;
+
if (nidx < neigh_skip)
goto next;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 100/877] neighbour: Skip default parms when resumed in neightbl_dump_info().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 099/877] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 101/877] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
` (784 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 979aabdad8dd03394467ee484a1a70f3d40b19ba ]
neightbl_dump_info() calls neightbl_fill_info() in each loop
to render the default parms.
If there are many devices and neightbl_fill_param_info() failed,
neightbl_fill_info() is called again when the dump resumes:
# ynl --family rt-neigh --dump getneightbl --output-json |
jq '.[] | {name: .name, ifindex: .parms.ifindex}'
...
{
"name": "ndisc_cache",
"ifindex": null
}
...
{
"name": "ndisc_cache",
"ifindex": 6
}
{
"name": "ndisc_cache",
"ifindex": null
}
{
"name": "ndisc_cache",
"ifindex": 5
}
Let's skip neightbl_fill_info() if it is already called in
neightbl_dump_info().
Note that we cannot use !neigh_skip instead of !default_skip
because default_skip == 1 && neigh_skip == 0 could be true
if the first neightbl_fill_param_info() fails.
Also, nidx must be cleared at the end of each table loop;
otherwise, if neightbl_fill_info() for a subsequent table
fails, the leftover nidx from the previous table would be
saved in cb->args[1], resulting in erroneously skipping parms
of the subsequent table in the next dump.
Fixes: c7fb64db001f ("[NETLINK]: Neighbour table configuration and statistics via rtnetlink")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-5-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index c9d848085dad3..99822878262c7 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2507,9 +2507,10 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
{
const struct nlmsghdr *nlh = cb->nlh;
struct net *net = sock_net(skb->sk);
+ int default_skip = cb->args[2];
+ int neigh_skip = cb->args[1];
int family, tidx, nidx = 0;
int tbl_skip = cb->args[0];
- int neigh_skip = cb->args[1];
struct neigh_table *tbl;
if (cb->strict_check) {
@@ -2533,12 +2534,13 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
if (tidx < tbl_skip || (family && tbl->family != family))
continue;
- if (neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
+ if (!default_skip &&
+ neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
nlh->nlmsg_seq, RTM_NEWNEIGHTBL,
NLM_F_MULTI) < 0)
break;
- nidx = 0;
+ default_skip = 1;
list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
@@ -2561,12 +2563,15 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
}
neigh_skip = 0;
+ nidx = 0;
+ default_skip = 0;
}
out:
rcu_read_unlock();
cb->args[0] = tidx;
cb->args[1] = nidx;
+ cb->args[2] = default_skip;
return skb->len;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 101/877] ALSA: bcd2000: Fix race between rawmidi and disconnect
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 100/877] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 102/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
` (783 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 221253723dc58bb901c3f27a7659823e63fc598c ]
Although we tried to fix the potential UAF issues at USB disconnect on
bcd2000 driver, there is still an overlooked case -- namely, when a
rawmidi trigger callback has been already running at USB disconnect
handling, the in-flight function (e.g. bcd2000_midi_send()) could
still access the URB, because the previous URB NULL-check & clearance
was considered only for the URB complete callbacks, but not about the
parallel rawmidi operations.
For addressing the race, this patch introduced a new spinlock that
covers each rawmidi operation as well as the rawmidi handling in the
complete callback. The URB is cleared with the lock, so it guarantees
that the pending rawmidi task already finished or a NULL check is
effective.
Fixes: 459d3a64766f ("ALSA: bcd2000: clear the URB pointers on disconnect")
Link: https://patch.msgid.link/20260910155227.996210-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/bcd2000/bcd2000.c | 33 ++++++++++++++++++++++++++-------
1 file changed, 26 insertions(+), 7 deletions(-)
diff --git a/sound/usb/bcd2000/bcd2000.c b/sound/usb/bcd2000/bcd2000.c
index c7e7149c6dabd..dce6d1f611f94 100644
--- a/sound/usb/bcd2000/bcd2000.c
+++ b/sound/usb/bcd2000/bcd2000.c
@@ -43,6 +43,7 @@ struct bcd2000 {
struct usb_interface *intf;
int card_index;
+ spinlock_t midi_lock;
int midi_out_active;
struct snd_rawmidi *rmidi;
struct snd_rawmidi_substream *midi_receive_substream;
@@ -90,6 +91,8 @@ static void bcd2000_midi_input_trigger(struct snd_rawmidi_substream *substream,
int up)
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2k->midi_receive_substream = up ? substream : NULL;
}
@@ -195,6 +198,8 @@ static void bcd2000_midi_output_trigger(struct snd_rawmidi_substream *substream,
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (up) {
bcd2k->midi_out_substream = substream;
/* check if there is data userspace wants to send */
@@ -219,6 +224,7 @@ static void bcd2000_output_complete(struct urb *urb)
return;
/* check if there is more data userspace wants to send */
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2000_midi_send(bcd2k);
}
@@ -234,6 +240,8 @@ static void bcd2000_input_complete(struct urb *urb)
if (!bcd2k || urb->status == -ESHUTDOWN)
return;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (urb->actual_length > 0)
bcd2000_midi_handle_input(bcd2k, urb->transfer_buffer,
urb->actual_length);
@@ -348,16 +356,26 @@ static int bcd2000_init_midi(struct bcd2000 *bcd2k)
return 0;
}
+static void bcd2000_midi_free(struct bcd2000 *bcd2k,
+ struct urb **urb_p)
+{
+ struct urb *urb = *urb_p;
+
+ if (!urb)
+ return;
+
+ usb_poison_urb(urb);
+ scoped_guard(spinlock_irq, &bcd2k->midi_lock)
+ *urb_p = NULL;
+
+ usb_free_urb(urb);
+}
+
static void bcd2000_free_usb_related_resources(struct bcd2000 *bcd2k,
struct usb_interface *interface)
{
- usb_poison_urb(bcd2k->midi_out_urb);
- usb_poison_urb(bcd2k->midi_in_urb);
-
- usb_free_urb(bcd2k->midi_out_urb);
- usb_free_urb(bcd2k->midi_in_urb);
- bcd2k->midi_out_urb = NULL;
- bcd2k->midi_in_urb = NULL;
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_out_urb);
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_in_urb);
if (bcd2k->intf) {
usb_set_intfdata(bcd2k->intf, NULL);
@@ -397,6 +415,7 @@ static int bcd2000_probe(struct usb_interface *interface,
bcd2k->card = card;
bcd2k->card_index = card_index;
bcd2k->intf = interface;
+ spin_lock_init(&bcd2k->midi_lock);
snd_card_set_dev(card, &interface->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 102/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 101/877] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 103/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
` (782 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit de7f29a1fe1dc2864d8a47f8c39d508442cae167 ]
When trying to calculate a PLL rate for target display resolutions
above 2560x1440, 24bpp, 30Hz, the pixel clock value will be more
than 32-bits long but the division to finally calculate the digital
clock divider is being done with div_u64(), which expects a 32bit
unsigned divisor.
Fix the overflow by using div64_u64() instead.
Fixes: 9d9ff3d2a4a5 ("phy: mediatek: hdmi: mt8195: fix wrong pll calculus")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-2-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index bbfe11d6a69d7..80600b2b6b38d 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -288,7 +288,7 @@ static int mtk_hdmi_pll_calc(struct mtk_hdmi_phy *hdmi_phy, struct clk_hw *hw,
posdiv2 = 1;
/* Digital clk divider, max /32 */
- digital_div = div_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
+ digital_div = div64_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
if (!(digital_div <= 32 && digital_div >= 1))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 103/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 102/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 104/877] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
` (781 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit 486a70ef848264dcf9a57f0bb0452848db9537de ]
The comment in the mtk_phy_tmds_clk_ratio() function clearly and
correctly explains that the TMDS ratio has to be 1/10 for data
rates under 3.4Gbps, and 1/40 over that.
Unfortunately though, the TXC_DIV register setting was wrong, as
in value 3 means to divide by 8 and, in order to achieve the in
spec 1/40 (tmds) data rate, this has to divide by 4 instead!
Add definitions for the TXC_DIV register values clearly explaining
the meanings (DIV2, DIV4, DIV8), and program the correct, DIV 4,
value to the register in mtk_phy_tmds_clk_ratio().
This fixes out of spec clocking and, with this change, SoCs using
the MT8195 class HDMI PHYs can now successfully be configured to
output 3840x2160@60Hz over HDMI.
Fixes: 45810d486bb4 ("phy: mediatek: add support for phy-mtk-hdmi-mt8195")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-3-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +++
2 files changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index 80600b2b6b38d..9f2c4db843479 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -34,7 +34,7 @@ mtk_phy_tmds_clk_ratio(struct mtk_hdmi_phy *hdmi_phy, bool enable)
* clock bit ratio 1:40, under 3.4Gbps, clock bit ratio 1:10
*/
if (enable)
- mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, 3);
+ mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, VAL_TXC_DIV4);
else
mtk_phy_clear_bits(regs + HDMI20_CLK_CFG, REG_TXC_DIV);
}
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
index 22a68dc9550ca..8e118a10ffbf2 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
@@ -17,6 +17,9 @@
#define HDMI20_CLK_CFG 0x70
#define REG_TXC_DIV GENMASK(31, 30)
+#define VAL_TXC_DIV2 1
+#define VAL_TXC_DIV4 2
+#define VAL_TXC_DIV8 3
#define HDMI_1_CFG_0 0x00
#define RG_HDMITX21_DRV_IBIAS_CLK GENMASK(10, 5)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 104/877] ALSA: pcm: set timer->private_data before registering the PCM timer
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 103/877] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 105/877] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
` (780 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+19da64013c46df87f971,
Nguyen Ngoc Thang, Takashi Iwai, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 1e713f9bb2ac583521f06b0eb4e22440b1e3d078 ]
snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.
Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private_data;
return substream->runtime ? ... // substream is NULL
Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Reported-by: syzbot+19da64013c46df87f971@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=19da64013c46df87f971
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Link: https://patch.msgid.link/20260913134446.114724-1-ngocthang2710.1999@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/pcm_timer.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/sound/core/pcm_timer.c b/sound/core/pcm_timer.c
index ab0e5bd70f8fa..18bedd66435dc 100644
--- a/sound/core/pcm_timer.c
+++ b/sound/core/pcm_timer.c
@@ -111,12 +111,15 @@ void snd_pcm_timer_init(struct snd_pcm_substream *substream)
snd_pcm_direction_name(substream->stream),
tid.card, tid.device, tid.subdevice);
timer->hw = snd_pcm_timer;
+ /* Set before registering: a concurrent reader can invoke our hw
+ * callbacks as soon as the timer is on the global list.
+ */
+ timer->private_data = substream;
+ timer->private_free = snd_pcm_timer_free;
if (snd_device_register(timer->card, timer) < 0) {
snd_device_free(timer->card, timer);
return;
}
- timer->private_data = substream;
- timer->private_free = snd_pcm_timer_free;
substream->timer = timer;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 105/877] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 104/877] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 106/877] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
` (779 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 4d855d747521505b54457c96bc73577bf74b2374 ]
Rename the ch_mask member of snd_soc_dai_link_ch_map to cpu_ch_mask,
as that is what it is used for.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU. So it's quite normal
that the channel mask at the CPU end is different for each codec, but
the codec channel masks are the same for each codec.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-2-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 2 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
sound/soc/soc-pcm.c | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index cd467f8babdb6..87e50c8cdda31 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -717,7 +717,7 @@ struct snd_soc_dai_link_component {
struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
- unsigned int ch_mask;
+ unsigned int cpu_ch_mask;
};
struct snd_soc_dai_link {
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index e6ac5c0fd3bec..70a7abede618f 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -795,7 +795,7 @@ int asoc_sdw_hw_params(struct snd_pcm_substream *substream,
* ASoC will set the corresponding channel numbers for each cpu dai.
*/
for_each_link_ch_maps(rtd->dai_link, i, ch_maps)
- ch_maps->ch_mask = ch_mask << (i * step);
+ ch_maps->cpu_ch_mask = ch_mask << (i * step);
return 0;
}
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index 628322790c878..440acec700a56 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1180,7 +1180,7 @@ static int __soc_pcm_hw_params(struct snd_soc_pcm_runtime *rtd,
*/
for_each_rtd_ch_maps(rtd, j, ch_maps)
if (ch_maps->cpu == i)
- ch_mask |= ch_maps->ch_mask;
+ ch_mask |= ch_maps->cpu_ch_mask;
/* fixup cpu channel number */
if (ch_mask)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 106/877] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 105/877] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:16 ` [PATCH 6.12 107/877] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
` (778 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 88b14c0d0bab5c0f3e7c641f274e3c70210c0e36 ]
Add a codec_ch_mask member to snd_soc_dai_link_ch_map.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU.
It is also possible for one TX channel to map to multiple RX channels.
So it isn't _always_ safe to assume that the total number of set bits
in the CPU ch_mask is the same as the total number of enabled channels
on the codec.
For example consider this mapping on a capture stream:
CPU0 CODEC0 cpu_ch_mask = 0x03
CPU1 CODEC0 cpu_ch_mask = 0x03
This could be either four TX channels on the codec split across two
receiving CPUs, or two TX channels on the codec duplicated to two CPUs.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-3-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 87e50c8cdda31..a5f8e83e6ced4 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -718,6 +718,7 @@ struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
unsigned int cpu_ch_mask;
+ unsigned int codec_ch_mask;
};
struct snd_soc_dai_link {
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 107/877] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 106/877] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-10-01 20:39 ` Harshit Mogalapalli
2026-09-30 15:16 ` [PATCH 6.12 108/877] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
` (777 subsequent siblings)
884 siblings, 1 reply; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 6b382bdfe26a2232091bf743e454e6794295783e ]
In __soc_pcm_hw_params() if there is a snd_soc_dai_link_ch_map with
non-zero codec_ch_mask, use that channel mask to restrict which channels
are enabled on the codec. But only if there isn't a TDM mask.
It is possible that a snd_soc_dai_link_ch_map could include the same codec
multiple times on different CPUs so the for_each_rtd_ch_maps() loop
accumulates the channel masks for all entries of that codec.
If a TDM mask was also set, it takes priority and is used instead of any
possible snd_soc_dai_link_ch_map entries. (They cannot be ANDed together
because the bit positions are indicating different things: TDM is a bit
for each TDM slot, codec_ch_mask is a bit for each codec channel.)
This fixes a problem of incorrect TX channels enabled on the codec when
multiple codecs are aggregated on a single capture link. For example:
- Two CPUs with six 4-channel codecs.
- The machine driver chooses to assign one channel from each codec to
one channel on the CPU
- But the codec hw_params() would be passed a channel count of 6, which
(a) is more channels than the codec has and (b) allows enabling channels
that should not be driving the audio bus.
Fixes: ac950278b087 ("ASoC: add N cpus to M codecs dai link support")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-4-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/soc-pcm.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index 440acec700a56..d52771a4a723b 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1122,7 +1122,9 @@ static int __soc_pcm_hw_params(struct snd_soc_pcm_runtime *rtd,
goto out;
for_each_rtd_codec_dais(rtd, i, codec_dai) {
- unsigned int tdm_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ unsigned int ch_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ struct snd_soc_dai_link_ch_map *ch_maps;
+ int j;
/*
* Skip CODECs which don't support the current stream type,
@@ -1144,9 +1146,15 @@ static int __soc_pcm_hw_params(struct snd_soc_pcm_runtime *rtd,
/* copy params for each codec */
tmp_params = *params;
- /* fixup params based on TDM slot masks */
- if (tdm_mask)
- soc_pcm_codec_params_fixup(&tmp_params, tdm_mask);
+ /* fixup params based on TDM or ch_map masks */
+ if (!ch_mask) {
+ for_each_rtd_ch_maps(rtd, j, ch_maps)
+ if (ch_maps->codec == i)
+ ch_mask |= ch_maps->codec_ch_mask;
+ }
+
+ if (ch_mask)
+ soc_pcm_codec_params_fixup(&tmp_params, ch_mask);
ret = snd_soc_dai_hw_params(codec_dai, substream,
&tmp_params);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 108/877] Input: trackpoint - fix the inertia attribute name in the ABI document
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 107/877] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
@ 2026-09-30 15:16 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 109/877] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
` (776 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:16 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Dmitry Torokhov,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 45b0037899704caf9078be2be4de69361ca7d933 ]
The attribute is created as "inertia" (TRACKPOINT_INT_ATTR(inertia, ...)
in drivers/input/mouse/trackpoint.c); the ABI file spells the path
"intertia". The description below it already says inertia.
Fix the spelling.
Fixes: aebb47d4e7a9 ("Input: trackpoint: document sysfs interface")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260905102038.42882-1-kmehltretter@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
index df11901a6b3df..7954434b0434a 100644
--- a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
+++ b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
@@ -5,7 +5,7 @@ Contact: linux-input@vger.kernel.org
Description:
(RW) Trackpoint sensitivity.
-What: /sys/devices/platform/i8042/.../intertia
+What: /sys/devices/platform/i8042/.../inertia
Date: Aug, 2005
KernelVersion: 2.6.14
Contact: linux-input@vger.kernel.org
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 109/877] gpio: virtuser: skip free_irq when no IRQ is installed
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-30 15:16 ` [PATCH 6.12 108/877] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 110/877] ALSA: 6fire: Clean ups with guard() Greg Kroah-Hartman
` (775 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Linus Walleij,
Bartosz Golaszewski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
[ Upstream commit 50fd0ada8d37587223001600933270b59cb30e19 ]
Disabling interrupt monitoring uses atomic_xchg() to clear the stored IRQ.
When monitoring is already disabled, atomic_xchg() returns 0. It must not
be passed to free_irq().
The bug is reproducible on an x86_64 QEMU guest with
CONFIG_GPIO_VIRTUSER=y and CONFIG_GPIO_SIM=y. Configure a live
gpio-virtuser device through configfs. Its input lookup must refer to a
live gpio-sim bank, such as key gpio-sim-test with offset 0. The
consumer's dev_name attribute is shown as <dev> below; then run:
echo 0 > /sys/kernel/debug/gpio-virtuser/<dev>/gpiod:input:0/interrupts
On an unpatched kernel, this reaches gpio_virtuser_interrupts_set() with
ld->irq still at its initial value 0, and free_irq() reports:
Trying to free already-free IRQ 0
The same reproducer completes without the warning on the patched kernel.
Fixes: 91581c4b3f29 ("gpio: virtuser: new virtual testing driver for the GPIO API")
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914051537.15320-1-runyu.xiao@seu.edu.cn
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-virtuser.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-virtuser.c b/drivers/gpio/gpio-virtuser.c
index ff1977b269914..5de9cee51fd08 100644
--- a/drivers/gpio/gpio-virtuser.c
+++ b/drivers/gpio/gpio-virtuser.c
@@ -698,7 +698,8 @@ static int gpio_virtuser_interrupts_set(void *data, u64 val)
atomic_set(&ld->irq, irq);
} else {
irq = atomic_xchg(&ld->irq, 0);
- free_irq(irq, ld);
+ if (irq)
+ free_irq(irq, ld);
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 110/877] ALSA: 6fire: Clean ups with guard()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 109/877] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 111/877] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
` (774 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 6ff0d95774f0c728f96b8f78367318e95e09ee64 ]
Simple code cleanups with the guard() for spinlock and mutex.
No functional changes.
Link: https://patch.msgid.link/20250811082231.31498-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/chip.c | 40 ++++++++++----------
sound/usb/6fire/midi.c | 21 +++--------
sound/usb/6fire/pcm.c | 83 ++++++++++++++++++------------------------
3 files changed, 59 insertions(+), 85 deletions(-)
diff --git a/sound/usb/6fire/chip.c b/sound/usb/6fire/chip.c
index e5916c6b75aea..30b240e06a8c8 100644
--- a/sound/usb/6fire/chip.c
+++ b/sound/usb/6fire/chip.c
@@ -83,24 +83,22 @@ static int usb6fire_chip_probe(struct usb_interface *intf,
struct snd_card *card = NULL;
/* look if we already serve this card and return if so */
- mutex_lock(®ister_mutex);
- for (i = 0; i < SNDRV_CARDS; i++) {
- if (devices[i] == device) {
- if (chips[i])
- chips[i]->intf_count++;
- usb_set_intfdata(intf, chips[i]);
- mutex_unlock(®ister_mutex);
- return 0;
- } else if (!devices[i] && regidx < 0)
- regidx = i;
- }
- if (regidx < 0) {
- mutex_unlock(®ister_mutex);
- dev_err(&intf->dev, "too many cards registered.\n");
- return -ENODEV;
+ scoped_guard(mutex, ®ister_mutex) {
+ for (i = 0; i < SNDRV_CARDS; i++) {
+ if (devices[i] == device) {
+ if (chips[i])
+ chips[i]->intf_count++;
+ usb_set_intfdata(intf, chips[i]);
+ return 0;
+ } else if (!devices[i] && regidx < 0)
+ regidx = i;
+ }
+ if (regidx < 0) {
+ dev_err(&intf->dev, "too many cards registered.\n");
+ return -ENODEV;
+ }
+ devices[regidx] = device;
}
- devices[regidx] = device;
- mutex_unlock(®ister_mutex);
/* check, if firmware is present on device, upload it if not */
ret = usb6fire_fw_init(intf);
@@ -175,10 +173,10 @@ static void usb6fire_chip_disconnect(struct usb_interface *intf)
if (chip) { /* if !chip, fw upload has been performed */
chip->intf_count--;
if (!chip->intf_count) {
- mutex_lock(®ister_mutex);
- devices[chip->regidx] = NULL;
- chips[chip->regidx] = NULL;
- mutex_unlock(®ister_mutex);
+ scoped_guard(mutex, ®ister_mutex) {
+ devices[chip->regidx] = NULL;
+ chips[chip->regidx] = NULL;
+ }
/*
* Save card pointer before teardown.
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index de2691d58de6e..6c6bccc0c410d 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -23,9 +23,8 @@ static void usb6fire_midi_out_handler(struct urb *urb)
{
struct midi_runtime *rt = urb->context;
int ret;
- unsigned long flags;
- spin_lock_irqsave(&rt->out_lock, flags);
+ guard(spinlock_irqsave)(&rt->out_lock);
if (rt->out) {
ret = snd_rawmidi_transmit(rt->out, rt->out_buffer + 4,
@@ -43,18 +42,14 @@ static void usb6fire_midi_out_handler(struct urb *urb)
} else /* no more data to transmit */
rt->out = NULL;
}
- spin_unlock_irqrestore(&rt->out_lock, flags);
}
static void usb6fire_midi_in_received(
struct midi_runtime *rt, u8 *data, int length)
{
- unsigned long flags;
-
- spin_lock_irqsave(&rt->in_lock, flags);
+ guard(spinlock_irqsave)(&rt->in_lock);
if (rt->in)
snd_rawmidi_receive(rt->in, data, length);
- spin_unlock_irqrestore(&rt->in_lock, flags);
}
static int usb6fire_midi_out_open(struct snd_rawmidi_substream *alsa_sub)
@@ -73,14 +68,11 @@ static void usb6fire_midi_out_trigger(
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
struct urb *urb = &rt->out_urb;
__s8 ret;
- unsigned long flags;
- spin_lock_irqsave(&rt->out_lock, flags);
+ guard(spinlock_irqsave)(&rt->out_lock);
if (up) { /* start transfer */
- if (rt->out) { /* we are already transmitting so just return */
- spin_unlock_irqrestore(&rt->out_lock, flags);
+ if (rt->out) /* we are already transmitting so just return */
return;
- }
ret = snd_rawmidi_transmit(alsa_sub, rt->out_buffer + 4,
MIDI_BUFSIZE - 4);
@@ -99,7 +91,6 @@ static void usb6fire_midi_out_trigger(
}
} else if (rt->out == alsa_sub)
rt->out = NULL;
- spin_unlock_irqrestore(&rt->out_lock, flags);
}
static void usb6fire_midi_out_drain(struct snd_rawmidi_substream *alsa_sub)
@@ -125,14 +116,12 @@ static void usb6fire_midi_in_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- unsigned long flags;
- spin_lock_irqsave(&rt->in_lock, flags);
+ guard(spinlock_irqsave)(&rt->in_lock);
if (up)
rt->in = alsa_sub;
else
rt->in = NULL;
- spin_unlock_irqrestore(&rt->in_lock, flags);
}
static const struct snd_rawmidi_ops out_ops = {
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 32c39d8bd2e55..14d23e3103989 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -289,7 +289,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
- unsigned long flags;
+ bool period_elapsed;
int total_length = 0;
int frame_count;
int frame;
@@ -313,17 +313,18 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* receive our capture data */
sub = &rt->capture;
- spin_lock_irqsave(&sub->lock, flags);
- if (sub->active) {
- usb6fire_pcm_capture(sub, in_urb);
- if (sub->period_off >= sub->instance->runtime->period_size) {
- sub->period_off %= sub->instance->runtime->period_size;
- spin_unlock_irqrestore(&sub->lock, flags);
- snd_pcm_period_elapsed(sub->instance);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
+ period_elapsed = false;
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ if (sub->active) {
+ usb6fire_pcm_capture(sub, in_urb);
+ if (sub->period_off >= sub->instance->runtime->period_size) {
+ sub->period_off %= sub->instance->runtime->period_size;
+ period_elapsed = true;
+ }
+ }
+ }
+ if (period_elapsed)
+ snd_pcm_period_elapsed(sub->instance);
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
@@ -338,17 +339,18 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* now send our playback data (if a free out urb was found) */
sub = &rt->playback;
- spin_lock_irqsave(&sub->lock, flags);
- if (sub->active) {
- usb6fire_pcm_playback(sub, out_urb);
- if (sub->period_off >= sub->instance->runtime->period_size) {
- sub->period_off %= sub->instance->runtime->period_size;
- spin_unlock_irqrestore(&sub->lock, flags);
- snd_pcm_period_elapsed(sub->instance);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
- } else
- spin_unlock_irqrestore(&sub->lock, flags);
+ period_elapsed = false;
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ if (sub->active) {
+ usb6fire_pcm_playback(sub, out_urb);
+ if (sub->period_off >= sub->instance->runtime->period_size) {
+ sub->period_off %= sub->instance->runtime->period_size;
+ period_elapsed = true;
+ }
+ }
+ }
+ if (period_elapsed)
+ snd_pcm_period_elapsed(sub->instance);
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
@@ -392,7 +394,7 @@ static int usb6fire_pcm_open(struct snd_pcm_substream *alsa_sub)
if (rt->panic)
return -EPIPE;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
alsa_rt->hw = pcm_hw;
if (alsa_sub->stream == SNDRV_PCM_STREAM_PLAYBACK) {
@@ -408,14 +410,12 @@ static int usb6fire_pcm_open(struct snd_pcm_substream *alsa_sub)
}
if (!sub) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev, "invalid stream type.\n");
return -EINVAL;
}
sub->instance = alsa_sub;
sub->active = false;
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -423,18 +423,17 @@ static int usb6fire_pcm_close(struct snd_pcm_substream *alsa_sub)
{
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
- unsigned long flags;
if (rt->panic)
return 0;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
if (sub) {
/* deactivate substream */
- spin_lock_irqsave(&sub->lock, flags);
- sub->instance = NULL;
- sub->active = false;
- spin_unlock_irqrestore(&sub->lock, flags);
+ scoped_guard(spinlock_irqsave, &sub->lock) {
+ sub->instance = NULL;
+ sub->active = false;
+ }
/* all substreams closed? if so, stop streaming */
if (!rt->playback.instance && !rt->capture.instance) {
@@ -442,7 +441,6 @@ static int usb6fire_pcm_close(struct snd_pcm_substream *alsa_sub)
rt->rate = ARRAY_SIZE(rates);
}
}
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -458,7 +456,7 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
if (!sub)
return -ENODEV;
- mutex_lock(&rt->stream_mutex);
+ guard(mutex)(&rt->stream_mutex);
sub->dma_off = 0;
sub->period_off = 0;
@@ -467,7 +465,6 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
if (alsa_rt->rate == rates[rt->rate])
break;
if (rt->rate == ARRAY_SIZE(rates)) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev,
"invalid rate %d in prepare.\n",
alsa_rt->rate);
@@ -475,19 +472,15 @@ static int usb6fire_pcm_prepare(struct snd_pcm_substream *alsa_sub)
}
ret = usb6fire_pcm_set_rate(rt);
- if (ret) {
- mutex_unlock(&rt->stream_mutex);
+ if (ret)
return ret;
- }
ret = usb6fire_pcm_stream_start(rt);
if (ret) {
- mutex_unlock(&rt->stream_mutex);
dev_err(&rt->chip->dev->dev,
"could not start pcm stream.\n");
return ret;
}
}
- mutex_unlock(&rt->stream_mutex);
return 0;
}
@@ -495,26 +488,22 @@ static int usb6fire_pcm_trigger(struct snd_pcm_substream *alsa_sub, int cmd)
{
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
- unsigned long flags;
if (rt->panic)
return -EPIPE;
if (!sub)
return -ENODEV;
+ guard(spinlock_irqsave)(&sub->lock);
switch (cmd) {
case SNDRV_PCM_TRIGGER_START:
case SNDRV_PCM_TRIGGER_PAUSE_RELEASE:
- spin_lock_irqsave(&sub->lock, flags);
sub->active = true;
- spin_unlock_irqrestore(&sub->lock, flags);
return 0;
case SNDRV_PCM_TRIGGER_STOP:
case SNDRV_PCM_TRIGGER_PAUSE_PUSH:
- spin_lock_irqsave(&sub->lock, flags);
sub->active = false;
- spin_unlock_irqrestore(&sub->lock, flags);
return 0;
default:
@@ -527,15 +516,13 @@ static snd_pcm_uframes_t usb6fire_pcm_pointer(
{
struct pcm_substream *sub = usb6fire_pcm_get_substream(alsa_sub);
struct pcm_runtime *rt = snd_pcm_substream_chip(alsa_sub);
- unsigned long flags;
snd_pcm_uframes_t ret;
if (rt->panic || !sub)
return SNDRV_PCM_POS_XRUN;
- spin_lock_irqsave(&sub->lock, flags);
+ guard(spinlock_irqsave)(&sub->lock);
ret = sub->dma_off;
- spin_unlock_irqrestore(&sub->lock, flags);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 111/877] ALSA: usb: 6fire: Avoid embedded URBs
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 110/877] ALSA: 6fire: Clean ups with guard() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 112/877] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
` (773 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 9fe49dbc023e82dfaee7b245997d820d01742a9a ]
The USB 6fire driver uses URBs embedded in different structs for PCM,
MIDI and communication, and this is basically a buggy implementation
nowadays; since a URB is managed with a refcount, this may lead to a
UAF when the URB is released asynchronously.
For addressing the problem, this patch converts those embedded URBs to
ones that are properly allocated via usb_alloc_urb(). The
pcm_urb.packets[] is gone, as it's allocated by usb_alloc_urb(), hence
it's found in urb.iso_frame_desc[] instead.
The conversions are rather straightforward; each embedded struct urb
is changed to a pointer, and its callers are updated accordingly.
The resource for those structs are released in the common destructor
functions (usb6fire_comm_free(), etc), which are called at both the
init error path and the disconnect.
No functional changes, only compile-tested.
Link: https://lore.kernel.org/20260903130757.0668310a.michal.pecio@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260903160458.1938392-4-tiwai@suse.de
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/comm.c | 42 +++++++++-----
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +++++++++-----
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 128 ++++++++++++++++++++++++-----------------
sound/usb/6fire/pcm.h | 5 +-
6 files changed, 136 insertions(+), 86 deletions(-)
diff --git a/sound/usb/6fire/comm.c b/sound/usb/6fire/comm.c
index bcfb34db37d95..cfaaad9d24028 100644
--- a/sound/usb/6fire/comm.c
+++ b/sound/usb/6fire/comm.c
@@ -21,7 +21,6 @@ enum {
static void usb6fire_comm_init_urb(struct comm_runtime *rt, struct urb *urb,
u8 *buffer, void *context, void(*handler)(struct urb *urb))
{
- usb_init_urb(urb);
urb->transfer_buffer = buffer;
urb->pipe = usb_sndintpipe(rt->chip->dev, COMM_EP);
urb->complete = handler;
@@ -142,6 +141,19 @@ static int usb6fire_comm_write16(struct comm_runtime *rt, u8 request,
return ret;
}
+static void usb6fire_comm_free(struct comm_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->comm = NULL;
+
+ usb_free_urb(rt->receiver);
+ kfree(rt->receiver_buffer);
+ kfree(rt);
+}
+
int usb6fire_comm_init(struct sfire_chip *chip)
{
struct comm_runtime *rt = kzalloc(sizeof(struct comm_runtime),
@@ -154,14 +166,18 @@ int usb6fire_comm_init(struct sfire_chip *chip)
rt->receiver_buffer = kzalloc(COMM_RECEIVER_BUFSIZE, GFP_KERNEL);
if (!rt->receiver_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
}
- urb = &rt->receiver;
+ urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!urb) {
+ ret = -ENOMEM;
+ goto error;
+ }
+ rt->receiver = urb;
rt->serial = 1;
rt->chip = chip;
- usb_init_urb(urb);
rt->init_urb = usb6fire_comm_init_urb;
rt->write8 = usb6fire_comm_write8;
rt->write16 = usb6fire_comm_write16;
@@ -176,13 +192,15 @@ int usb6fire_comm_init(struct sfire_chip *chip)
urb->interval = 1;
ret = usb_submit_urb(urb, GFP_KERNEL);
if (ret < 0) {
- kfree(rt->receiver_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create comm data receiver.");
- return ret;
+ goto error;
}
chip->comm = rt;
return 0;
+
+ error:
+ usb6fire_comm_free(rt);
+ return ret;
}
void usb6fire_comm_abort(struct sfire_chip *chip)
@@ -190,14 +208,10 @@ void usb6fire_comm_abort(struct sfire_chip *chip)
struct comm_runtime *rt = chip->comm;
if (rt)
- usb_poison_urb(&rt->receiver);
+ usb_poison_urb(rt->receiver);
}
void usb6fire_comm_destroy(struct sfire_chip *chip)
{
- struct comm_runtime *rt = chip->comm;
-
- kfree(rt->receiver_buffer);
- kfree(rt);
- chip->comm = NULL;
+ usb6fire_comm_free(chip->comm);
}
diff --git a/sound/usb/6fire/comm.h b/sound/usb/6fire/comm.h
index 2447d7ecf1798..89976f510f6c2 100644
--- a/sound/usb/6fire/comm.h
+++ b/sound/usb/6fire/comm.h
@@ -19,7 +19,7 @@ enum /* settings for comm */
struct comm_runtime {
struct sfire_chip *chip;
- struct urb receiver;
+ struct urb *receiver;
u8 *receiver_buffer;
u8 serial; /* urb serial */
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index 6c6bccc0c410d..9a1dd5b6557c7 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -66,7 +66,7 @@ static void usb6fire_midi_out_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- struct urb *urb = &rt->out_urb;
+ struct urb *urb = rt->out_urb;
__s8 ret;
guard(spinlock_irqsave)(&rt->out_lock);
@@ -137,6 +137,19 @@ static const struct snd_rawmidi_ops in_ops = {
.trigger = usb6fire_midi_in_trigger
};
+static void usb6fire_midi_free(struct midi_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->midi = NULL;
+
+ usb_free_urb(rt->out_urb);
+ kfree(rt->out_buffer);
+ kfree(rt);
+}
+
int usb6fire_midi_init(struct sfire_chip *chip)
{
int ret;
@@ -149,8 +162,14 @@ int usb6fire_midi_init(struct sfire_chip *chip)
rt->out_buffer = kzalloc(MIDI_BUFSIZE, GFP_KERNEL);
if (!rt->out_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
+ }
+
+ rt->out_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!rt->out_urb) {
+ ret = -ENOMEM;
+ goto error;
}
rt->chip = chip;
@@ -161,15 +180,13 @@ int usb6fire_midi_init(struct sfire_chip *chip)
spin_lock_init(&rt->in_lock);
spin_lock_init(&rt->out_lock);
- comm_rt->init_urb(comm_rt, &rt->out_urb, rt->out_buffer, rt,
+ comm_rt->init_urb(comm_rt, rt->out_urb, rt->out_buffer, rt,
usb6fire_midi_out_handler);
ret = snd_rawmidi_new(chip->card, "6FireUSB", 0, 1, 1, &rt->instance);
if (ret < 0) {
- kfree(rt->out_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "unable to create midi.\n");
- return ret;
+ goto error;
}
rt->instance->private_data = rt;
strcpy(rt->instance->name, "DMX6FireUSB MIDI");
@@ -183,6 +200,10 @@ int usb6fire_midi_init(struct sfire_chip *chip)
chip->midi = rt;
return 0;
+
+ error:
+ usb6fire_midi_free(rt);
+ return ret;
}
void usb6fire_midi_abort(struct sfire_chip *chip)
@@ -190,14 +211,10 @@ void usb6fire_midi_abort(struct sfire_chip *chip)
struct midi_runtime *rt = chip->midi;
if (rt)
- usb_poison_urb(&rt->out_urb);
+ usb_poison_urb(rt->out_urb);
}
void usb6fire_midi_destroy(struct sfire_chip *chip)
{
- struct midi_runtime *rt = chip->midi;
-
- kfree(rt->out_buffer);
- kfree(rt);
- chip->midi = NULL;
+ usb6fire_midi_free(chip->midi);
}
diff --git a/sound/usb/6fire/midi.h b/sound/usb/6fire/midi.h
index 47640c845903b..8716ab8a863ae 100644
--- a/sound/usb/6fire/midi.h
+++ b/sound/usb/6fire/midi.h
@@ -22,7 +22,7 @@ struct midi_runtime {
spinlock_t in_lock;
spinlock_t out_lock;
struct snd_rawmidi_substream *out;
- struct urb out_urb;
+ struct urb *out_urb;
u8 out_serial; /* serial number of out packet */
u8 *out_buffer;
int buffer_offset;
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 14d23e3103989..9e8f4371e89ff 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -138,8 +138,8 @@ static void usb6fire_pcm_stream_stop(struct pcm_runtime *rt)
rt->stream_state = STREAM_STOPPING;
for (i = 0; i < PCM_N_URBS; i++) {
- usb_kill_urb(&rt->in_urbs[i].instance);
- usb_kill_urb(&rt->out_urbs[i].instance);
+ usb_kill_urb(rt->in_urbs[i].instance);
+ usb_kill_urb(rt->out_urbs[i].instance);
}
ctrl_rt->usb_streaming = false;
ctrl_rt->update_streaming(ctrl_rt);
@@ -161,13 +161,13 @@ static int usb6fire_pcm_stream_start(struct pcm_runtime *rt)
rt->stream_state = STREAM_STARTING;
for (i = 0; i < PCM_N_URBS; i++) {
for (k = 0; k < PCM_N_PACKETS_PER_URB; k++) {
- packet = &rt->in_urbs[i].packets[k];
+ packet = &rt->in_urbs[i].instance->iso_frame_desc[k];
packet->offset = k * rt->in_packet_size;
packet->length = rt->in_packet_size;
packet->actual_length = 0;
packet->status = 0;
}
- ret = usb_submit_urb(&rt->in_urbs[i].instance,
+ ret = usb_submit_urb(rt->in_urbs[i].instance,
GFP_ATOMIC);
if (ret) {
usb6fire_pcm_stream_stop(rt);
@@ -197,6 +197,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
unsigned int total_length = 0;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = NULL;
u32 *dest = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
@@ -207,8 +208,9 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].actual_length > 4)
- frame_count = (urb->packets[i].actual_length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->actual_length > 4)
+ frame_count = (isoc->actual_length - 4)
/ (rt->in_n_analog << 2);
else
frame_count = 0;
@@ -220,7 +222,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
else
return;
src++; /* skip leading 4 bytes of every packet */
- total_length += urb->packets[i].length;
+ total_length += isoc->length;
for (frame = 0; frame < frame_count; frame++) {
memcpy(dest, src, bytes_per_frame);
dest += alsa_rt->channels;
@@ -244,6 +246,7 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
int frame_count;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
u32 *src_end = (u32 *) (alsa_rt->dma_area + alsa_rt->buffer_size
@@ -263,8 +266,9 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].length > 4)
- frame_count = (urb->packets[i].length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->length > 4)
+ frame_count = (isoc->length - 4)
/ (rt->out_n_analog << 2);
else
frame_count = 0;
@@ -289,6 +293,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
+ struct usb_iso_packet_descriptor *isoc_out, *isoc_in;
bool period_elapsed;
int total_length = 0;
int frame_count;
@@ -299,11 +304,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
if (usb_urb->status || rt->panic || rt->stream_state == STREAM_STOPPING)
return;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (in_urb->packets[i].status) {
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->status) {
rt->panic = true;
return;
}
+ }
if (rt->stream_state == STREAM_DISABLED) {
dev_err(&rt->chip->dev->dev,
@@ -328,12 +335,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
- out_urb->packets[i].offset = total_length;
- out_urb->packets[i].length = (in_urb->packets[i].actual_length
- - 4) / (rt->in_n_analog << 2)
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ isoc_out->offset = total_length;
+ isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
* (rt->out_n_analog << 2) + 4;
- out_urb->packets[i].status = 0;
- total_length += out_urb->packets[i].length;
+ isoc_out->status = 0;
+ total_length += isoc_out->length;
}
memset(out_urb->buffer, 0, total_length);
@@ -354,9 +362,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (out_urb->packets[i].length >= 4) {
- frame_count = (out_urb->packets[i].length - 4)
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ if (isoc_out->length >= 4) {
+ frame_count = (isoc_out->length - 4)
/ (rt->out_n_analog << 2);
*(dest++) = 0xaa;
*(dest++) = 0xaa;
@@ -370,8 +379,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
*(dest++) = 0x40;
}
}
- usb_submit_urb(&out_urb->instance, GFP_ATOMIC);
- usb_submit_urb(&in_urb->instance, GFP_ATOMIC);
+ }
+
+ usb_submit_urb(out_urb->instance, GFP_ATOMIC);
+ usb_submit_urb(in_urb->instance, GFP_ATOMIC);
}
static void usb6fire_pcm_out_urb_handler(struct urb *usb_urb)
@@ -534,22 +545,25 @@ static const struct snd_pcm_ops pcm_ops = {
.pointer = usb6fire_pcm_pointer,
};
-static void usb6fire_pcm_init_urb(struct pcm_urb *urb,
- struct sfire_chip *chip, bool in, int ep,
- void (*handler)(struct urb *))
+static int usb6fire_pcm_init_urb(struct pcm_urb *urb,
+ struct sfire_chip *chip, bool in, int ep,
+ void (*handler)(struct urb *))
{
urb->chip = chip;
- usb_init_urb(&urb->instance);
- urb->instance.transfer_buffer = urb->buffer;
- urb->instance.transfer_buffer_length =
+ urb->instance = usb_alloc_urb(PCM_N_PACKETS_PER_URB, GFP_KERNEL);
+ if (!urb->instance)
+ return -ENOMEM;
+ urb->instance->transfer_buffer = urb->buffer;
+ urb->instance->transfer_buffer_length =
PCM_N_PACKETS_PER_URB * PCM_MAX_PACKET_SIZE;
- urb->instance.dev = chip->dev;
- urb->instance.pipe = in ? usb_rcvisocpipe(chip->dev, ep)
+ urb->instance->dev = chip->dev;
+ urb->instance->pipe = in ? usb_rcvisocpipe(chip->dev, ep)
: usb_sndisocpipe(chip->dev, ep);
- urb->instance.interval = 1;
- urb->instance.complete = handler;
- urb->instance.context = urb;
- urb->instance.number_of_packets = PCM_N_PACKETS_PER_URB;
+ urb->instance->interval = 1;
+ urb->instance->complete = handler;
+ urb->instance->context = urb;
+ urb->instance->number_of_packets = PCM_N_PACKETS_PER_URB;
+ return 0;
}
static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
@@ -571,14 +585,23 @@ static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
return 0;
}
-static void usb6fire_pcm_buffers_destroy(struct pcm_runtime *rt)
+static void usb6fire_pcm_free(struct pcm_runtime *rt)
{
int i;
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->pcm = NULL;
+
for (i = 0; i < PCM_N_URBS; i++) {
+ usb_free_urb(rt->out_urbs[i].instance);
kfree(rt->out_urbs[i].buffer);
+ usb_free_urb(rt->in_urbs[i].instance);
kfree(rt->in_urbs[i].buffer);
}
+ kfree(rt);
}
int usb6fire_pcm_init(struct sfire_chip *chip)
@@ -593,11 +616,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
return -ENOMEM;
ret = usb6fire_pcm_buffers_init(rt);
- if (ret) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- return ret;
- }
+ if (ret)
+ goto error;
rt->chip = chip;
rt->stream_state = STREAM_DISABLED;
@@ -609,10 +629,14 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
spin_lock_init(&rt->capture.lock);
for (i = 0; i < PCM_N_URBS; i++) {
- usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
- usb6fire_pcm_in_urb_handler);
- usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
- usb6fire_pcm_out_urb_handler);
+ ret = usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
+ usb6fire_pcm_in_urb_handler);
+ if (ret < 0)
+ goto error;
+ ret = usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
+ usb6fire_pcm_out_urb_handler);
+ if (ret < 0)
+ goto error;
rt->in_urbs[i].peer = &rt->out_urbs[i];
rt->out_urbs[i].peer = &rt->in_urbs[i];
@@ -620,10 +644,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
ret = snd_pcm_new(chip->card, "DMX6FireUSB", 0, 1, 1, &pcm);
if (ret < 0) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create pcm instance.\n");
- return ret;
+ goto error;
}
pcm->private_data = rt;
@@ -636,6 +658,10 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
chip->pcm = rt;
return 0;
+
+ error:
+ usb6fire_pcm_free(rt);
+ return ret;
}
void usb6fire_pcm_abort(struct sfire_chip *chip)
@@ -653,8 +679,8 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
snd_pcm_stop_xrun(rt->capture.instance);
for (i = 0; i < PCM_N_URBS; i++) {
- usb_poison_urb(&rt->in_urbs[i].instance);
- usb_poison_urb(&rt->out_urbs[i].instance);
+ usb_poison_urb(rt->in_urbs[i].instance);
+ usb_poison_urb(rt->out_urbs[i].instance);
}
}
@@ -662,9 +688,5 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
void usb6fire_pcm_destroy(struct sfire_chip *chip)
{
- struct pcm_runtime *rt = chip->pcm;
-
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- chip->pcm = NULL;
+ usb6fire_pcm_free(chip->pcm);
}
diff --git a/sound/usb/6fire/pcm.h b/sound/usb/6fire/pcm.h
index 5a092dfd69f5a..b586fe220fd11 100644
--- a/sound/usb/6fire/pcm.h
+++ b/sound/usb/6fire/pcm.h
@@ -24,10 +24,7 @@ enum /* settings for pcm */
struct pcm_urb {
struct sfire_chip *chip;
- /* BEGIN DO NOT SEPARATE */
- struct urb instance;
- struct usb_iso_packet_descriptor packets[PCM_N_PACKETS_PER_URB];
- /* END DO NOT SEPARATE */
+ struct urb *instance;
u8 *buffer;
struct pcm_urb *peer;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 112/877] ALSA: 6fire: fix OOB write from device-reported iso length
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 111/877] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 113/877] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
` (772 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+855929c2df672879, Xiang Mei,
Takashi Iwai, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 1589afe2d099d3e817873bc474676968d7080410 ]
usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as
(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where
actual_length is the unsigned length the device reported for the matching
IN packet. A packet completed with status 0 and actual_length < 4 wraps
the subtraction to 0x7fffffec; a zero-length isochronous packet is legal
on the bus, and the preceding loop rejects only non-zero status. The sum
reaches memset() on out_urb->buffer, a 4832-byte object from
kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
Even without the wrap the result is out of bounds: at 88.2/96 kHz the
4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight
packets span 5024 bytes of that buffer. usb_submit_urb() rejects an
over-long descriptor only after the memset() and the
usb6fire_pcm_playback() copy of user PCM data have run.
Guard the subtraction as the sibling usb6fire_pcm_capture() already does,
and limit the frame count to what fits in rt->out_packet_size, the OUT
endpoint's wMaxPacketSize. This bounds total_length by the buffer size
while keeping each packet length aligned to a whole output frame.
BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018
Call Trace:
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
__asan_memset (mm/kasan/shadow.c:84)
usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Allocated by task 10:
__kmalloc_cache_noprof (mm/slub.c:5563)
usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)
usb6fire_chip_probe (sound/usb/6fire/chip.c:133)
usb_probe_interface (drivers/usb/core/driver.c:399)
The buggy address belongs to the object at ffff88802a3d0000
which belongs to the cache kmalloc-8k of size 8192
The buggy address is located 0 bytes inside of
4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: c6d43ba816d1 ("ALSA: usb/6fire - Driver for TerraTec DMX 6Fire USB")
Reported-by: co+855929c2df672879@bugs.sh
Closes: https://lore.kernel.org/all/gisnub8aWGLbyZLcDCSc7zWsHonMWGcyRgt5%40bugs.sh/
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260914074324.3590843-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/pcm.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 9e8f4371e89ff..5f6a63f79990b 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -335,11 +335,19 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ unsigned int frames = 0;
+
isoc_out = &out_urb->instance->iso_frame_desc[i];
isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->actual_length > 4)
+ frames = (isoc_in->actual_length - 4)
+ / (rt->in_n_analog << 2);
+ frames = min_t(unsigned int, frames,
+ (rt->out_packet_size - 4)
+ / (rt->out_n_analog << 2));
+
isoc_out->offset = total_length;
- isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
- * (rt->out_n_analog << 2) + 4;
+ isoc_out->length = frames * (rt->out_n_analog << 2) + 4;
isoc_out->status = 0;
total_length += isoc_out->length;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 113/877] wifi: virt_wifi: dont transfer operstate before register
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 112/877] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 114/877] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
` (771 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
[ Upstream commit e5c8d7acd31b27057ea42cd405d0b3ece097bc89 ]
virt_wifi_newlink() calls netif_stacked_transfer_operstate() before
register_netdevice(). If the lower device is dormant, that queues the
new netdev on lweventlist while it is still uninitialized. If
registration fails after that, for example because of an invalid name
such as "bad/name", free_netdev() immediately frees the object. A
later linkwatch_fire_event() then use-after-frees the list entry.
Move the transfer to after netdev_upper_dev_link(), as macvlan and
ipvlan already do.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Link: https://patch.msgid.link/f5a832fb0ab228ce6e2b5a91fba4ca8b79198a2f.1788948455.git.zihanx@nebusec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index 056d375e3f41f..4d36c15c1118e 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -554,7 +554,6 @@ static int virt_wifi_newlink(struct net *src_net, struct net_device *dev,
}
eth_hw_addr_inherit(dev, priv->lowerdev);
- netif_stacked_transfer_operstate(priv->lowerdev, dev);
dev->ieee80211_ptr = kzalloc(sizeof(*dev->ieee80211_ptr), GFP_KERNEL);
@@ -580,6 +579,8 @@ static int virt_wifi_newlink(struct net *src_net, struct net_device *dev,
goto unregister_netdev;
}
+ netif_stacked_transfer_operstate(priv->lowerdev, dev);
+
dev->priv_destructor = virt_wifi_net_device_destructor;
priv->being_deleted = false;
priv->is_connected = false;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 114/877] drm/vc4: Use managed KMS polling to fix UAF on unbind
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 113/877] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 115/877] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
` (770 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Maíra Canal,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 073a30d75f309812ed61af134f24ffef4107b13a ]
vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
no matching drm_kms_helper_poll_fini(). The output poll work stays
scheduled after unbind and runs on the freed drm_device:
# modprobe vc4; rmmod vc4; sleep 10
BUG: KASAN: slab-use-after-free in delayed_work_timer_fn
BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]
Workqueue: events output_poll_execute [drm_kms_helper]
Allocated by task 171: __devm_drm_dev_alloc
Freed by task 262 (rmmod): drm_dev_put / component_del
Use drmm_kms_helper_poll_init() so polling is finalized with the device,
as other drivers do.
Fixes: c8b75bca92cb ("drm/vc4: Add KMS support for Raspberry Pi.")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260822143110.68594-1-kmehltretter@gmail.com
Reviewed-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/vc4/vc4_kms.c b/drivers/gpu/drm/vc4/vc4_kms.c
index bddfcad109501..c5e28ff3931a7 100644
--- a/drivers/gpu/drm/vc4/vc4_kms.c
+++ b/drivers/gpu/drm/vc4/vc4_kms.c
@@ -1084,7 +1084,7 @@ int vc4_kms_load(struct drm_device *dev)
drm_mode_config_reset(dev);
- drm_kms_helper_poll_init(dev);
+ drmm_kms_helper_poll_init(dev);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 115/877] ALSA: hda: trace PCM open only after assigning a stream
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 114/877] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 116/877] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
` (769 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Slavin Liu, Takashi Iwai,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slavin Liu <bolin.liu@seu.edu.cn>
[ Upstream commit c9e6e5f38bf75276605f1952b22285f5f3abcaff ]
Stream assignment can fail when hardware streams are exhausted.
Move the tracepoint after the NULL check because its payload accesses
the assigned stream tag.
Detected by static analysis and reviewed with AI-assisted source auditing.
Fixes: 184865085b88 ("ALSA: hda - rename hda_intel_trace.h to hda_controller_trace.h")
Assisted-by: LLM
Signed-off-by: Slavin Liu <bolin.liu@seu.edu.cn>
Link: https://patch.msgid.link/20260913125154.109944-1-bolin.liu@seu.edu.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/hda/hda_controller.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/pci/hda/hda_controller.c b/sound/pci/hda/hda_controller.c
index bd13ea0c9352e..7c0574eb54c61 100644
--- a/sound/pci/hda/hda_controller.c
+++ b/sound/pci/hda/hda_controller.c
@@ -593,11 +593,11 @@ static int azx_pcm_open(struct snd_pcm_substream *substream)
snd_hda_codec_pcm_get(apcm->info);
mutex_lock(&chip->open_mutex);
azx_dev = azx_assign_device(chip, substream);
- trace_azx_pcm_open(chip, azx_dev);
if (azx_dev == NULL) {
err = -EBUSY;
goto unlock;
}
+ trace_azx_pcm_open(chip, azx_dev);
runtime->private_data = azx_dev;
runtime->hw = azx_pcm_hw;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 116/877] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 115/877] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 117/877] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
` (768 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolas Escande,
Rameshkumar Sundaram, Baochen Qiang, Jeff Johnson, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Escande <nico.escande@gmail.com>
[ Upstream commit 820b8cff81c796ba20573e04722ab62500713f97 ]
When mac80211 removes a sta, it calls .sta_state() which in turn calls
ath11k_mac_station_remove(). In that function we clean up both peers &
arsta related resources.
But when the firmware crashes, ath11k calls ieee80211_restart_hw(), which
assumes that all driver related resources are cleaned up beforehand. This
cleanup is supposedly done by ath11k_mac_peer_cleanup_all() but does not
in fact free arsta->rx_stats / tx_stats.
Extract the arsta cleanup from ath11k_mac_station_remove() into a
new ath11k_mac_station_cleanup() and call it from both there and
ath11k_mac_peer_cleanup_all().
This should handle kmemleaks reports like:
unreferenced object 0xffffff801ae66400 (size 1024):
comm "hostapd", pid 1306, jiffies 4295011565
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc d61c08ec):
kmemleak_alloc+0x3c/0x50
__kmalloc_cache_noprof+0x2b0/0x3e0
ath11k_mac_op_sta_state+0x1dc/0xb10
drv_sta_state+0xac/0x6f8
sta_info_insert_rcu+0x314/0x5e0
sta_info_insert+0x14/0x38
ieee80211_add_station+0x10c/0x1a0
nl80211_new_station+0x3e8/0x680
genl_family_rcv_msg_doit+0xc0/0x120
genl_rcv_msg+0x1b4/0x258
netlink_rcv_skb+0x4c/0x108
genl_rcv+0x38/0x60
netlink_unicast+0x190/0x278
netlink_sendmsg+0x15c/0x370
____sys_sendmsg+0x120/0x290
___sys_sendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Signed-off-by: Nicolas Escande <nico.escande@gmail.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260731145830.769811-1-nico.escande@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/mac.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/mac.c b/drivers/net/wireless/ath/ath11k/mac.c
index c4856480fffe7..53bc1b90bab3c 100644
--- a/drivers/net/wireless/ath/ath11k/mac.c
+++ b/drivers/net/wireless/ath/ath11k/mac.c
@@ -873,6 +873,22 @@ static int ath11k_mac_set_kickout(struct ath11k_vif *arvif)
return 0;
}
+static void ath11k_mac_station_cleanup(struct ieee80211_sta *sta)
+{
+ struct ath11k_sta *arsta;
+
+ if (!sta)
+ return;
+
+ arsta = ath11k_sta_to_arsta(sta);
+
+ kfree(arsta->tx_stats);
+ arsta->tx_stats = NULL;
+
+ kfree(arsta->rx_stats);
+ arsta->rx_stats = NULL;
+}
+
void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
{
struct ath11k_peer *peer, *tmp;
@@ -885,6 +901,7 @@ void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
list_for_each_entry_safe(peer, tmp, &ab->peers, list) {
ath11k_peer_rx_tid_cleanup(ar, peer);
ath11k_peer_rhash_delete(ab, peer);
+ ath11k_mac_station_cleanup(peer->sta);
list_del(&peer->list);
kfree(peer);
}
@@ -9759,7 +9776,6 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
{
struct ath11k_base *ab = ar->ab;
struct ath11k_vif *arvif = ath11k_vif_to_arvif(vif);
- struct ath11k_sta *arsta = ath11k_sta_to_arsta(sta);
int ret;
if (ab->hw_params.vdev_start_delay &&
@@ -9783,12 +9799,7 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
sta->addr, arvif->vdev_id);
ath11k_mac_dec_num_stations(arvif, sta);
-
- kfree(arsta->tx_stats);
- arsta->tx_stats = NULL;
-
- kfree(arsta->rx_stats);
- arsta->rx_stats = NULL;
+ ath11k_mac_station_cleanup(sta);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 117/877] btrfs: tree-checker: print dev extent offset in error message
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 116/877] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 118/877] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
` (767 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit a1167d9420474ab9ed9efca99d86aeb6217c0265 ]
If a dev extent's offset is not sector size aligned, the error message is
printing the dev extent's objectid instead of the offset. This is a copy
paste error, as before this check we check the objectid field.
Fixes: 008e2512dc56 ("btrfs: tree-checker: add dev extent item checks")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/tree-checker.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 92a2df6dd3a4e..6b68d87cbf446 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -1914,7 +1914,7 @@ static int check_dev_extent_item(const struct extent_buffer *leaf,
sectorsize))) {
generic_err(leaf, slot,
"invalid dev extent chunk offset, has %llu not aligned to %u",
- btrfs_dev_extent_chunk_objectid(leaf, de),
+ btrfs_dev_extent_chunk_offset(leaf, de),
sectorsize);
return -EUCLEAN;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 118/877] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 117/877] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 119/877] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
` (766 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abel Vesa, Krzysztof Kozlowski,
Dmitry Baryshkov, Konrad Dybcio, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 2028280686f4fa78e2f1f6dede4b6c1fd782b9e3 ]
DSI 6G v2.9 hosts (SM8650, SM8750, Kaanapali, etc.) reparent the byte and
pixel RCGs to the DSI PHY PLL at runtime from
dsi_link_clk_set_rate_6g_v2_9(), after the PHY has been enabled. However
dsi_calc_clk_rate_6g() runs earlier, in order to compute the bit clock
request for the PHY. At that point the byte RCG still has its reset
parent (XO), so clk_round_rate() returns a bogus rate, which then ends up
in the PHY bit clock request and the PLL gets programmed to a wrong
frequency, breaking the panel.
Move the rounding to dsi_link_clk_set_rate_6g(), which is called after
the RCGs have been reparented to the PLL. Storing the rounded rate at
this point still makes later link_clk_set_rate() calls no-ops in the
CCF. Derive the byte interface clock rate from the rounded byte clock
rate, otherwise it would keep requesting the idealized rate and
retrigger the PLL on every transfer.
Reported-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reported-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Fixes: 6cd33b6f4155 ("drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value")
Assisted-by: LLM
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> # SM6115P J606F
Tested-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/750496/
Link: https://lore.kernel.org/r/20260903-fix-eliza-dsi-v1-1-3474a6c9f2e0@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 ++++++++++++++++--------------
1 file changed, 19 insertions(+), 17 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 77173183509f1..cd605c75cef8e 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -120,7 +120,7 @@ struct msm_dsi_host {
struct clk *byte_intf_clk;
unsigned long byte_clk_rate;
- unsigned long byte_intf_clk_rate;
+ bool byte_intf_clk_div_2;
unsigned long pixel_clk_rate;
unsigned long esc_clk_rate;
@@ -350,8 +350,20 @@ int msm_dsi_runtime_resume(struct device *dev)
int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
{
+ unsigned long byte_intf_clk_rate;
+ long rounded_byte_clk_rate;
int ret;
+ rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
+ msm_host->byte_clk_rate);
+ if (rounded_byte_clk_rate < 0) {
+ pr_err("%s: failed to round byte clock rate, %ld\n",
+ __func__, rounded_byte_clk_rate);
+ return rounded_byte_clk_rate;
+ }
+
+ msm_host->byte_clk_rate = rounded_byte_clk_rate;
+
DBG("Set clk rates: pclk=%lu, byteclk=%lu",
msm_host->pixel_clk_rate, msm_host->byte_clk_rate);
@@ -369,7 +381,11 @@ int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
}
if (msm_host->byte_intf_clk) {
- ret = clk_set_rate(msm_host->byte_intf_clk, msm_host->byte_intf_clk_rate);
+ byte_intf_clk_rate = msm_host->byte_clk_rate;
+ if (msm_host->byte_intf_clk_div_2)
+ byte_intf_clk_rate /= 2;
+
+ ret = clk_set_rate(msm_host->byte_intf_clk, byte_intf_clk_rate);
if (ret) {
pr_err("%s: Failed to set rate byte intf clk, %d\n",
__func__, ret);
@@ -619,24 +635,12 @@ static void dsi_calc_pclk(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
int dsi_calc_clk_rate_6g(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
{
- long rounded_byte_clk_rate;
-
if (!msm_host->mode) {
pr_err("%s: mode not set\n", __func__);
return -EINVAL;
}
dsi_calc_pclk(msm_host, is_bonded_dsi);
-
- rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
- msm_host->byte_clk_rate);
- if (rounded_byte_clk_rate < 0) {
- pr_err("%s: failed to round byte clock rate, %ld\n",
- __func__, rounded_byte_clk_rate);
- return rounded_byte_clk_rate;
- }
-
- msm_host->byte_clk_rate = rounded_byte_clk_rate;
msm_host->esc_clk_rate = clk_get_rate(msm_host->esc_clk);
return 0;
}
@@ -2419,9 +2423,7 @@ int msm_dsi_host_power_on(struct mipi_dsi_host *host,
goto unlock_ret;
}
- msm_host->byte_intf_clk_rate = msm_host->byte_clk_rate;
- if (phy_shared_timings->byte_intf_clk_div_2)
- msm_host->byte_intf_clk_rate /= 2;
+ msm_host->byte_intf_clk_div_2 = phy_shared_timings->byte_intf_clk_div_2;
msm_dsi_sfpb_config(msm_host, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 119/877] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 118/877] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 120/877] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
` (765 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Mayer, David Ahern,
Hangbin Liu, Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Mayer <andrea.mayer@uniroma2.it>
[ Upstream commit 7616242a2b37883f7322aaa1d2bd6cd0fed28315 ]
When an SRv6 packet arrives on an interface enslaved to a VRF,
vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
a reassembled outer packet could even set it, with no VRF involved.
Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
decapsulation") then made the unreliable bit reliably clear.
The effect of the missing flag is visible with End.DX4 when a
delivery to a local address of the node reaches the socket lookup.
For example, a UDP socket bound to the enslaved ingress interface
does not receive any of the decapsulated packets, while an unbound
socket outside the VRF does.
This contradicts Documentation/networking/vrf.rst: by default the
scope of an unbound UDP or TCP socket is limited to the default VRF.
Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
the same for IPv6. The socket lookup then matches the decapsulated
packet like any other packet received on that enslaved interface. Such
a packet matches an unbound UDP or TCP socket only when
udp_l3mdev_accept or tcp_l3mdev_accept is set.
Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260913194421.31-1-andrea.mayer@uniroma2.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/seg6_local.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c
index 10f29bb8e608f..191b99b073b06 100644
--- a/net/ipv6/seg6_local.c
+++ b/net/ipv6/seg6_local.c
@@ -257,10 +257,13 @@ static bool decap_and_validate(struct sk_buff *skb, int proto)
return false;
if (proto == IPPROTO_IPIP) {
+ bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
IPCB(skb)->iif = iif;
+ if (l3slave)
+ IPCB(skb)->flags |= IPSKB_L3SLAVE;
} else if (proto == IPPROTO_IPV6) {
bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 120/877] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 119/877] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 121/877] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
` (764 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Jiayuan Chen,
Dong Chenchen, Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dong Chenchen <dongchenchen2@huawei.com>
[ Upstream commit 2998147b59c9df0a51477c7a6b3d1f0ba3127dd4 ]
When the forward output route cannot be used in icmp_route_lookup(),
it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr,
the original packet's source address.
ip_route_input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip_rt_bug(). The existing check only rejects
RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN_ON_ONCE()
in ip_rt_bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20
RIP: 0010:ip_rt_bug+0x14/0x20
Call Trace:
ip_push_pending_frames+0xfa/0x100
__icmp_send+0x905/0xf10
ip_options_compile+0xc0/0xd0
ip_rcv_finish_core+0x321/0xae0
ip_rcv+0x1de/0x260
__netif_receive_skb_one_core+0x11a/0x130
netif_receive_skb+0x7b/0x260
tun_get_user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN_UNREACHABLE to fix it. The net warning
is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of
a race condition.
Fixes: 8b7817f3a959 ("[IPSEC]: Add ICMP host relookup support")
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com>
Link: https://patch.msgid.link/20260910140042.1880242-1-dongchenchen2@huawei.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/icmp.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index 7e391c2bc5bc0..3b0475f658105 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -573,16 +573,19 @@ static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
skb_dstref_restore(skb_in, orefdst);
/*
- * At this point, fl4_dec.daddr should NOT be local (we
- * checked fl4_dec.saddr above). However, a race condition
- * may occur if the address is added to the interface
- * concurrently. In that case, ip_route_input() returns a
- * LOCAL route with dst.output=ip_rt_bug, which must not
- * be used for output.
+ * fl4_dec.daddr is not expected to be local here, but it can be
+ * added to an interface concurrently, in which case
+ * ip_route_input() returns a LOCAL route. It can also fail to
+ * build a forwarding route towards fl4_dec.daddr, for example,
+ * when forwarding is disabled, and return an UNREACHABLE route.
+ * Both cases will result in a route with dst.output=ip_rt_bug,
+ * which must not be used for output.
*/
- if (!err && rt2 && rt2->rt_type == RTN_LOCAL) {
+ if (!err && rt2 && rt2->rt_type == RTN_LOCAL)
net_warn_ratelimited("detected local route for %pI4 during ICMP sending, src %pI4\n",
&fl4_dec.daddr, &fl4_dec.saddr);
+ if (!err && rt2 &&
+ (rt2->rt_type == RTN_LOCAL || rt2->rt_type == RTN_UNREACHABLE)) {
dst_release(&rt2->dst);
err = -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 121/877] net: fddi: skfp: fix NULL deref when setting the MAC address while down
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 120/877] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 122/877] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
` (763 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hohyun Sim, Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hohyun Sim <tlaghgus0425@korea.ac.kr>
[ Upstream commit 7c8810c2e69c3d9ca6df870b40ae9218e50b4fb1 ]
skfp_ctl_set_mac_address() calls ResetAdapter() unconditionally, without
checking netif_running(). ResetAdapter() first calls card_stop(), which
sets smc->hw.hw_state to STOPPED, and then mac_drv_clear_tx_queue(),
which walks the two transmit queues:
for (i = QUEUE_S; i <= QUEUE_A0; i++) {
queue = smc->hw.fp.tx[i] ;
...
t = queue->tx_curr_get ;
smc->hw.fp.tx[] is only populated by init_tx(), which is reached from
skfp_open() through init_smt() -> init_fddi_driver() -> init_fplus() ->
init_mac() -> init_tx(). The private area is allocated and zeroed by
alloc_fddidev(), so on an interface that has never been brought up both
queue pointers are still NULL. The hw_state test at the top of
mac_drv_clear_tx_queue() does not catch this, because card_stop() has
just set STOPPED; the function proceeds into the loop and dereferences
NULL. ResetAdapter() does call init_smt() itself, but only after the
queues have been cleared.
Setting the MAC address on a down interface therefore oopses:
ip link set dev fddi0 address 02:00:00:00:00:01
BUG: KASAN: null-ptr-deref in mac_drv_clear_tx_queue+0x68/0x2c0 [skfp]
Read of size 8 at addr 0000000000000010 by task ip/302
Call Trace:
<TASK>
mac_drv_clear_tx_queue+0x68/0x2c0 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
ResetAdapter+0x29/0x100 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
skfp_ctl_set_mac_address+0x57/0x80 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
netif_set_mac_address+0x1e4/0x2c0
do_setlink+0x684/0x2680
</TASK>
Address 0x10 is the offset of tx_curr_get, the third pointer in
struct s_smt_tx_queue, on 64-bit. mac_drv_clear_rx_queue(), which
ResetAdapter() calls immediately afterwards, dereferences
smc->hw.fp.rx[QUEUE_R1] in the same way behind the same ineffective
hw_state test; the transmit queue merely crashes first. Both are
covered by the guard below.
Skip the adapter reset when the interface is down. dev_addr_set() is
left unconditional, so the new address is still recorded in
dev->dev_addr. Nothing is lost by not resetting the adapter here:
skfp_open() deliberately re-reads the factory address on every open,
read_address(smc, NULL);
eth_hw_addr_set(dev, smc->hw.fddi_canon_addr.a);
and the comment above it states this is done to discard exactly such an
address override across a close/open cycle. An address set while the
interface is down could not have survived the following open even
before this change, so the guard removes no working behaviour. Guarding
the hardware side of ndo_set_mac_address() with netif_running() is
established practice; skge_set_mac_address() has done so since commit
2eb3e621c4e0 ("skge: set mac address bonding fix").
Guarding the reset as a whole, rather than NULL-checking the queues, is
also what the rest of the driver expects. After a previous open/close
the queue pointers are stale but non-NULL, so there is no crash, yet
ResetAdapter() goes on to call smt_online() and STI_FBI() ("Enable
Board Interrupts") while skfp_close() has already called free_irq() -
the adapter would be brought back online with no handler installed. The
only other ResetAdapter() caller is skfp_interrupt(), which by
construction runs only while the device is open.
Found by automated driver testing against an emulated SysKonnect FDDI
adapter under a KASAN-enabled 7.0.0 kernel. Triggering it requires
CAP_NET_ADMIN.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM KASAN
Signed-off-by: Hohyun Sim <tlaghgus0425@korea.ac.kr>
Link: https://patch.msgid.link/20260910063743.110747-1-tlaghgus0425@korea.ac.kr
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/fddi/skfp/skfddi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/fddi/skfp/skfddi.c b/drivers/net/fddi/skfp/skfddi.c
index a273362c9e703..feea7baa48168 100644
--- a/drivers/net/fddi/skfp/skfddi.c
+++ b/drivers/net/fddi/skfp/skfddi.c
@@ -928,7 +928,8 @@ static int skfp_ctl_set_mac_address(struct net_device *dev, void *addr)
dev_addr_set(dev, p_sockaddr->sa_data);
spin_lock_irqsave(&bp->DriverLock, Flags);
- ResetAdapter(smc);
+ if (netif_running(dev))
+ ResetAdapter(smc);
spin_unlock_irqrestore(&bp->DriverLock, Flags);
return 0; /* always return zero */
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 122/877] wifi: brcmfmac: fix lost 802.1x TX completion wakeup
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 121/877] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 123/877] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
` (762 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Arend van Spriel,
Johannes Berg, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 621d90169cef6c8da5b6134db5c0c4e23cdd09ce ]
brcmf_txfinalize() decrements pend_8021x_cnt before a lockless
waitqueue_active() check. atomic_dec() does not order the decrement
against the check.
The waiter can therefore observe a nonzero count while the waker observes
an empty queue, losing the final wakeup and delaying key installation
until the 950 ms timeout.
Add smp_mb__after_atomic() to order the decrement before the queue
check. wait_event_timeout() provides the matching barrier. LKMM confirms
that this forbids the lost-wakeup outcome.
Fixes: 21fff75d2fb6 ("brcmfmac: use wait_event_timeout for 8021x pending count")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260811082702.44521-1-kmehltretter@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
index 58eaf08a147b6..f99accc34a36e 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
@@ -550,6 +550,8 @@ void brcmf_txfinalize(struct brcmf_if *ifp, struct sk_buff *txp, bool success)
if (type == ETH_P_PAE) {
atomic_dec(&ifp->pend_8021x_cnt);
+ /* Order the decrement before waitqueue_active() */
+ smp_mb__after_atomic();
if (waitqueue_active(&ifp->pend_8021x_wait))
wake_up(&ifp->pend_8021x_wait);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 123/877] net: bridge: mst: move switchdev call outside rcu
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 122/877] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 124/877] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
` (761 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Aleksandrov <razor@blackwall.org>
[ Upstream commit 18a6fe05fb6e18de29fa90d388bb34044114b3d8 ]
This is a follow-up of one of sashiko's pre-existing bug reports.
br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
while holding rcu_read_lock() which invokes the blocking switchdev
notifier chain and may sleep. Nonzero MSTI changes come from netlink
with rtnl held. Move the switchdev call before entering the rcu section and
assert that rtnl is held.
The call cannot be deferred because netlink needs its error and extack.
Also DSA reads the old bridge MST state during the callback and checks it.
A deferred callback will be late and will see the updated state.
Fixes: 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260911105021.1385934-1-razor@blackwall.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_mst.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c
index 43a300ae6bfaf..1654efd3045b0 100644
--- a/net/bridge/br_mst.c
+++ b/net/bridge/br_mst.c
@@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
struct net_bridge_vlan *v;
int err = 0;
- rcu_read_lock();
- vg = nbp_vlan_group_rcu(p);
- if (!vg)
- goto out;
-
/* MSTI 0 (CST) state changes are notified via the regular
- * SWITCHDEV_ATTR_ID_PORT_STP_STATE.
+ * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via
+ * netlink with RTNL held
*/
if (msti) {
+ ASSERT_RTNL();
+
err = switchdev_port_attr_set(p->dev, &attr, extack);
if (err && err != -EOPNOTSUPP)
goto out;
+ err = 0;
}
- err = 0;
+ rcu_read_lock();
+ vg = nbp_vlan_group_rcu(p);
+ if (!vg)
+ goto out_rcu_unlock;
+
list_for_each_entry_rcu(v, &vg->vlan_list, vlist) {
if (v->brvlan->msti != msti)
continue;
@@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
br_mst_vlan_set_state(vg, v, state);
}
-out:
+out_rcu_unlock:
rcu_read_unlock();
+out:
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 124/877] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 123/877] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 125/877] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
` (760 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taras Madan, Kuniyuki Iwashima,
Xuanqiang Luo, Eric Dumazet, Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 8e759cd1f6444a946bd1fd2b2b29eea582eea1d5 ]
tcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for
TCP_LISTEN since commit 073d89808c06 ("net: fix data-races around
sk->sk_forward_alloc").
However, there is still a small race window between tcp_v6_rcv()
and tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN
to TCP_CLOSE, causing skb_clone_and_charge_r() to be called
locklessly and resulting in the splat below. [0]
Let's avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.
This is fine for non-listeners because tcp_rcv_state_process()
drops skb for TCP_CLOSE and opt_skb was freed immediately anyway.
[0]:
sk->sk_forward_alloc
WARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28
Modules linked in:
CPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
RIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162
Code: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 <0f> 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff
RSP: 0018:ffffc90000677bb8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41
RDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005
RBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000
R10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003
FS: 0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__sk_destruct+0x82/0xae0 net/core/sock.c:2356
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897
handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622
run_ksoftirqd kernel/softirq.c:1076 [inline]
run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068
smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160
kthread+0x396/0x4a0 kernel/kthread.c:436
ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Fixes: e994b2f0fb92 ("tcp: do not lock listener to process SYN packets")
Reported-by: Taras Madan <tarasmadan@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914011420.115556-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/tcp_ipv6.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index 533943a7127dc..e5f632b683c5d 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1605,7 +1605,8 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
by tcp. Feel free to propose better solution.
--ANK (980728)
*/
- if (np->rxopt.all && sk->sk_state != TCP_LISTEN)
+ if (np->rxopt.all &&
+ !((1 << sk->sk_state) & (TCPF_LISTEN | TCPF_CLOSE)))
opt_skb = skb_clone_and_charge_r(skb, sk);
if (sk->sk_state == TCP_ESTABLISHED) { /* Fast path */
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 125/877] tcp: do not let tcp_rmem be set below 4096
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 124/877] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 126/877] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
` (759 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 83a945a529d6e002dd7339c532288a931f463dba ]
We can hit a division by zero crash in tcp_rcvbuf_grow()
and tcp_rcv_space_adjust():
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq_space.space as divisor.
When tp->rcvq_space.space is zero, this leads to a divide-by-zero
exception.
tp->rcvq_space.space is initialized in tcp_init_buffer_space():
tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
(u32)TCP_INIT_CWND * tp->advmss);
If tcp_rmem[1] is configured to very small values (such as 1),
sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which
computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.
This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and
tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,
tcp_rcvbuf_grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem_default and
net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,
SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).
However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing
arbitrarily small values.
Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere
and matches the documented 4K default.
Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912144848.3448026-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/networking/ip-sysctl.rst | 2 ++
net/ipv4/sysctl_net_ipv4.c | 4 +++-
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index dcbb6f6caf6de..eb2c136be63da 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -735,6 +735,8 @@ tcp_rmem - vector of 3 INTEGERs: min, default, max
case this value is ignored.
Default: between 131072 and 6MB, depending on RAM size.
+ Each of the three values cannot be set below 4096.
+
tcp_sack - BOOLEAN
Enable select acknowledgments (SACKS).
diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
index 63625a5038af4..00d3be968a53d 100644
--- a/net/ipv4/sysctl_net_ipv4.c
+++ b/net/ipv4/sysctl_net_ipv4.c
@@ -46,6 +46,8 @@ static unsigned int udp_child_hash_entries_max = UDP_HTABLE_SIZE_MAX;
static int tcp_plb_max_rounds = 31;
static int tcp_plb_max_cong_thresh = 256;
+static int tcp_min_rcvbuf = 4096;
+
/* obsolete */
static int sysctl_tcp_low_latency __read_mostly;
@@ -1405,7 +1407,7 @@ static struct ctl_table ipv4_net_table[] = {
.maxlen = sizeof(init_net.ipv4.sysctl_tcp_rmem),
.mode = 0644,
.proc_handler = proc_dointvec_minmax,
- .extra1 = SYSCTL_ONE,
+ .extra1 = &tcp_min_rcvbuf,
},
{
.procname = "tcp_comp_sack_delay_ns",
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 126/877] ksmbd: return buffer overflow for partial filesystem info
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 125/877] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 127/877] ksmbd: fix partial file information responses Greg Kroah-Hartman
` (758 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 0ecd35fac4b4f2828490689b46039744d201dcb0 ]
The query-info buffer check returns STATUS_INFO_LENGTH_MISMATCH for
every output buffer smaller than the complete response. Variable-length
filesystem information instead requires STATUS_BUFFER_OVERFLOW when the
fixed portion fits but the complete data does not.
Pass the fixed size for each filesystem information class to the buffer
checker. Keep INFO_LENGTH_MISMATCH for buffers below that size, and
return BUFFER_OVERFLOW with a response truncated to the requested length
for larger partial buffers.
This fixes smb2.getinfo.qfs_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 37d8db4bbbaec..b12dad36bb574 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -4648,21 +4648,30 @@ int smb2_query_dir(struct ksmbd_work *work)
/**
* buffer_check_err() - helper function to check buffer errors
* @reqOutputBufferLength: max buffer length expected in command response
+ * @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
* @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
+ unsigned int fixed_len,
struct smb2_query_info_rsp *rsp,
void *rsp_org)
{
- if (reqOutputBufferLength < le32_to_cpu(rsp->OutputBufferLength)) {
+ unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
+
+ if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
*(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
+
+ if (reqOutputBufferLength < output_len) {
+ rsp->hdr.Status = STATUS_BUFFER_OVERFLOW;
+ rsp->OutputBufferLength = cpu_to_le32(reqOutputBufferLength);
+ }
return 0;
}
@@ -4725,11 +4734,13 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
case FILE_STANDARD_INFORMATION:
get_standard_info_pipe(rsp, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
case FILE_INTERNAL_INFORMATION:
get_internal_info_pipe(rsp, id, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
default:
@@ -5523,6 +5534,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
if (!rc)
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
ksmbd_fd_put(work, fp);
@@ -5544,6 +5556,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
struct kstatfs stfs;
struct path path;
int rc = 0, len;
+ unsigned int fixed_len = 0;
if (!share->path)
return -EIO;
@@ -5578,6 +5591,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DeviceCharacteristics |=
cpu_to_le32(FILE_READ_ONLY_DEVICE);
rsp->OutputBufferLength = cpu_to_le32(8);
+ fixed_len = 8;
break;
}
case FS_ATTRIBUTE_INFORMATION:
@@ -5606,6 +5620,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->FileSystemNameLen = cpu_to_le32(len);
sz = sizeof(struct filesystem_attribute_info) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 16;
break;
}
case FS_VOLUME_INFORMATION:
@@ -5632,6 +5647,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->Reserved = 0;
sz = sizeof(struct filesystem_vol_info) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 24;
break;
}
case FS_SIZE_INFORMATION:
@@ -5644,6 +5660,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(24);
+ fixed_len = 24;
break;
}
case FS_FULL_SIZE_INFORMATION:
@@ -5659,6 +5676,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(32);
+ fixed_len = 32;
break;
}
case FS_OBJECT_ID_INFORMATION:
@@ -5679,6 +5697,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->extended_info.rel_date = 0;
memcpy(info->extended_info.version_string, "1.1.0", strlen("1.1.0"));
rsp->OutputBufferLength = cpu_to_le32(64);
+ fixed_len = 64;
break;
}
case FS_SECTOR_SIZE_INFORMATION:
@@ -5700,6 +5719,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->ByteOffsetForSectorAlignment = 0;
info->ByteOffsetForPartitionAlignment = 0;
rsp->OutputBufferLength = cpu_to_le32(28);
+ fixed_len = 28;
break;
}
case FS_CONTROL_INFORMATION:
@@ -5720,6 +5740,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DefaultQuotaLimit = cpu_to_le64(SMB2_NO_FID);
info->Padding = 0;
rsp->OutputBufferLength = cpu_to_le32(48);
+ fixed_len = 48;
break;
}
case FS_POSIX_INFORMATION:
@@ -5740,6 +5761,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->TotalFileNodes = cpu_to_le64(stfs.f_files);
info->FreeFileNodes = cpu_to_le64(stfs.f_ffree);
rsp->OutputBufferLength = cpu_to_le32(56);
+ fixed_len = 56;
}
break;
}
@@ -5748,6 +5770,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
return -EOPNOTSUPP;
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
path_put(&path);
@@ -5862,6 +5885,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
iov_pin:
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 127/877] ksmbd: fix partial file information responses
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 126/877] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 128/877] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
` (757 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 6b8b79226bc3e0ac3fdd4e91836241af712e8cd1 ]
Variable-length file information handlers use the client output length
while constructing the response. FILE_ALL_INFORMATION can consequently
return -EINVAL before the common buffer check, while stream information
can stop building the complete result too early.
Build the complete response within the available server response buffer
and apply the client output length only when selecting the final status
and transmitted length. Use the protocol-defined fixed sizes for all,
alternate-name, and stream information to distinguish
STATUS_INFO_LENGTH_MISMATCH from STATUS_BUFFER_OVERFLOW.
This fixes smb2.getinfo.qfile_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++++++++++-----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index b12dad36bb574..af3178031c1ee 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5019,7 +5019,6 @@ static int get_file_all_info(struct ksmbd_work *work,
char *filename;
u64 time;
int ret, buf_free_len, filename_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) {
ksmbd_debug(SMB, "no right to read the attributes : 0x%x\n",
@@ -5032,10 +5031,9 @@ static int get_file_all_info(struct ksmbd_work *work,
return PTR_ERR(filename);
filename_len = strlen(filename);
- buf_free_len = smb2_calc_max_out_buf_len(work,
+ buf_free_len = smb2_resp_buf_len(work,
offsetof(struct smb2_query_info_rsp, Buffer) +
- offsetof(struct smb2_file_all_info, FileName),
- le32_to_cpu(req->OutputBufferLength));
+ offsetof(struct smb2_file_all_info, FileName));
if (buf_free_len < (filename_len + 1) * 2) {
kfree(filename);
return -EINVAL;
@@ -5120,7 +5118,6 @@ static int get_file_stream_info(struct ksmbd_work *work,
ssize_t xattr_list_len;
int nbytes = 0, streamlen, stream_name_len, next, idx = 0;
int buf_free_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
int ret;
ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS,
@@ -5130,10 +5127,8 @@ static int get_file_stream_info(struct ksmbd_work *work,
file_info = (struct smb2_file_stream_info *)rsp->Buffer;
- buf_free_len =
- smb2_calc_max_out_buf_len(work,
- offsetof(struct smb2_query_info_rsp, Buffer),
- le32_to_cpu(req->OutputBufferLength));
+ buf_free_len = smb2_resp_buf_len(work,
+ offsetof(struct smb2_query_info_rsp, Buffer));
if (buf_free_len < 0)
goto out;
@@ -5429,6 +5424,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
struct ksmbd_file *fp;
int fileinfoclass = 0;
int rc = 0;
+ unsigned int fixed_len;
unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID;
if (test_share_config_flag(work->tcon->share_conf,
@@ -5532,10 +5528,23 @@ static int smb2_get_info_file(struct ksmbd_work *work,
fileinfoclass);
rc = -EOPNOTSUPP;
}
- if (!rc)
+ if (!rc) {
+ fixed_len = le32_to_cpu(rsp->OutputBufferLength);
+ switch (fileinfoclass) {
+ case FILE_ALL_INFORMATION:
+ fixed_len = FILE_ALL_INFORMATION_SIZE;
+ break;
+ case FILE_ALTERNATE_NAME_INFORMATION:
+ fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
+ break;
+ case FILE_STREAM_INFORMATION:
+ fixed_len = FILE_STREAM_INFORMATION_SIZE;
+ break;
+ }
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
- le32_to_cpu(rsp->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
+ }
ksmbd_fd_put(work, fp);
iov_pin_out:
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 128/877] ksmbd: keep compound responses on query info errors
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 127/877] ksmbd: fix partial file information responses Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 129/877] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
` (756 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, ChenXiaoSong,
Namjae Jeon, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 9fa26285ae70ac2d3d1b47459a6b4463ab053e1c ]
Do not reset the RFC1002 length of the complete response when a query
info buffer is too small. The current command will add its error response
through ksmbd_iov_pin_rsp(), while resetting the base length can truncate
earlier responses in a compound request.
This lets ksmbd return the earlier responses and the query-info error
response together. Remove the now-unused rsp_org parameter from the pipe
query-info helpers.
Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++-------------------
1 file changed, 12 insertions(+), 19 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index af3178031c1ee..283160908218e 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -4650,21 +4650,18 @@ int smb2_query_dir(struct ksmbd_work *work)
* @reqOutputBufferLength: max buffer length expected in command response
* @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
- * @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
unsigned int fixed_len,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
- *(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
@@ -4675,8 +4672,7 @@ static int buffer_check_err(int reqOutputBufferLength,
return 0;
}
-static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp)
{
struct smb2_file_standard_info *sinfo;
@@ -4691,8 +4687,7 @@ static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
cpu_to_le32(sizeof(struct smb2_file_standard_info));
}
-static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
- void *rsp_org)
+static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num)
{
struct smb2_file_internal_info *file_info;
@@ -4706,8 +4701,7 @@ static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
struct smb2_query_info_req *req,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
u64 id;
int rc;
@@ -4732,16 +4726,16 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
switch (req->FileInfoClass) {
case FILE_STANDARD_INFORMATION:
- get_standard_info_pipe(rsp, rsp_org);
+ get_standard_info_pipe(rsp);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
case FILE_INTERNAL_INFORMATION:
- get_internal_info_pipe(rsp, id, rsp_org);
+ get_internal_info_pipe(rsp, id);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
default:
ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n",
@@ -5430,8 +5424,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
if (test_share_config_flag(work->tcon->share_conf,
KSMBD_SHARE_FLAG_PIPE)) {
/* smb2 info file called for pipe */
- rc = smb2_get_info_file_pipe(work->sess, req, rsp,
- work->response_buf);
+ rc = smb2_get_info_file_pipe(work->sess, req, rsp);
goto iov_pin_out;
}
@@ -5543,7 +5536,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
}
ksmbd_fd_put(work, fp);
@@ -5780,7 +5773,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
path_put(&path);
if (!rc)
@@ -5895,7 +5888,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, work->response_buf);
+ rsp);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 129/877] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 128/877] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 130/877] Bluetooth: hci_core: Print number of packets in conn->data_q Greg Kroah-Hartman
` (755 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baineng Shou, Frank Li, Vinod Koul,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit 075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 ]
In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist
putting each entry into 'sg', but the entry length is read from 'sgl'
(the list head) instead of 'sg' (the current entry):
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
avail = sg_dma_len(sgl); /* should be 'sg' */
Consequently 'avail' is always the length of the first entry. For
multi-sg lists this causes out-of-bounds reads when a later entry is
shorter than the first, and silent data loss when it is longer.
Single-sg or uniformly-sized lists happen to mask the issue.
Fixes: c8acd6aa6bed3 ("dmaengine: mmp-pdma support")
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260910021652.1296640-1-shoubaineng@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mmp_pdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/mmp_pdma.c b/drivers/dma/mmp_pdma.c
index 852e6714d9f28..59227fbed9045 100644
--- a/drivers/dma/mmp_pdma.c
+++ b/drivers/dma/mmp_pdma.c
@@ -541,7 +541,7 @@ mmp_pdma_prep_slave_sg(struct dma_chan *dchan, struct scatterlist *sgl,
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
- avail = sg_dma_len(sgl);
+ avail = sg_dma_len(sg);
do {
len = min_t(size_t, avail, PDMA_MAX_DESC_BYTES);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 130/877] Bluetooth: hci_core: Print number of packets in conn->data_q
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 129/877] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 131/877] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
` (754 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 3c34d6428740e47b29ae3afd85d6f9eb656a3ea3 ]
This attempts to print the number of packets pending to be transmitted
in the conn->data_q.
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 6610c6fe4b89 ("Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_core.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index f68238406ad2e..24f2119c7abfa 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -3273,6 +3273,8 @@ static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
spin_unlock_bh(&queue->lock);
}
+
+ bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue));
}
void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
@@ -3304,6 +3306,10 @@ void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
hci_skb_pkt_type(skb) = HCI_SCODATA_PKT;
skb_queue_tail(&conn->data_q, skb);
+
+ bt_dev_dbg(hdev, "hcon %p queued %d", conn,
+ skb_queue_len(&conn->data_q));
+
queue_work(hdev->workqueue, &hdev->tx_work);
}
@@ -3363,6 +3369,8 @@ static void hci_queue_iso(struct hci_conn *conn, struct sk_buff_head *queue,
__skb_queue_tail(queue, skb);
} while (list);
}
+
+ bt_dev_dbg(hdev, "hcon %p queued %d", conn, skb_queue_len(queue));
}
void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 131/877] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 130/877] Bluetooth: hci_core: Print number of packets in conn->data_q Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 132/877] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
` (753 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b6919040d9958e2fc1ae,
ThangNN99, Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: ThangNN99 <ngocthang2710.1999@gmail.com>
[ Upstream commit 6610c6fe4b8936c232048e6049bf77c70a6f759c ]
hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work
unconditionally. They can run from the L2CAP/SCO/ISO socket send path
while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN
racing with a socket write). Since that queue_work() is not chained
work from the tx_work worker itself, __queue_work() sees the queue
marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops
the work:
WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
Call Trace:
queue_work_on
l2cap_chan_send
l2cap_sock_sendmsg
...
hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before
draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()
check it before queuing. Route the tx_work producers through the
same guard via a shared hci_sched_tx() helper.
Fixes: 525daaea459f ("Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close")
Reported-by: syzbot+b6919040d9958e2fc1ae@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b6919040d9958e2fc1ae
Signed-off-by: ThangNN99 <ngocthang2710.1999@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_core.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 24f2119c7abfa..85aecd4c5b9b2 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -3277,6 +3277,17 @@ static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue));
}
+/* Queue hdev->tx_work, unless hdev->workqueue is being drained by
+ * hci_dev_close_sync(), which would otherwise WARN and drop the work.
+ */
+static void hci_sched_tx(struct hci_dev *hdev)
+{
+ rcu_read_lock();
+ if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
+ queue_work(hdev->workqueue, &hdev->tx_work);
+ rcu_read_unlock();
+}
+
void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
{
struct hci_dev *hdev = chan->conn->hdev;
@@ -3285,7 +3296,7 @@ void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
hci_queue_acl(chan, &chan->data_q, skb, flags);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send SCO data */
@@ -3310,7 +3321,7 @@ void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
bt_dev_dbg(hdev, "hcon %p queued %d", conn,
skb_queue_len(&conn->data_q));
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send ISO data */
@@ -3381,7 +3392,7 @@ void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb)
hci_queue_iso(conn, &conn->data_q, skb);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* ---- HCI TX task (outgoing data) ---- */
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 132/877] Bluetooth: coredump: Quiesce dump work on unregister
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 131/877] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 133/877] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
` (752 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b170dbf55520ebf5969a,
Aby Sam Ross, Tristan Madani, Xiang Mei, Weiming Shi,
Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit d236517c264e41dc09833c708ef23bccb7a91219 ]
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.
Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump")
Reported-by: syzbot+b170dbf55520ebf5969a@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b170dbf55520ebf5969a
Reported-by: Aby Sam Ross <abysamross@gmail.com>
Link: https://lore.kernel.org/r/20260322210849.68743-1-abysamross@gmail.com
Suggested-by: Aby Sam Ross <abysamross@gmail.com>
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://lore.kernel.org/r/20260814231248.3096377-1-tristmd@gmail.com
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: OpenAI Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/bluetooth/coredump.h | 2 +
net/bluetooth/coredump.c | 65 +++++++++++++++++++++-----------
net/bluetooth/hci_core.c | 1 +
3 files changed, 47 insertions(+), 21 deletions(-)
diff --git a/include/net/bluetooth/coredump.h b/include/net/bluetooth/coredump.h
index 72f51b587a046..00c12c7ac042f 100644
--- a/include/net/bluetooth/coredump.h
+++ b/include/net/bluetooth/coredump.h
@@ -61,6 +61,7 @@ struct hci_devcoredump {
#ifdef CONFIG_DEV_COREDUMP
void hci_devcd_reset(struct hci_dev *hdev);
+void hci_devcd_shutdown(struct hci_dev *hdev);
void hci_devcd_rx(struct work_struct *work);
void hci_devcd_timeout(struct work_struct *work);
@@ -75,6 +76,7 @@ int hci_devcd_abort(struct hci_dev *hdev);
#else
static inline void hci_devcd_reset(struct hci_dev *hdev) {}
+static inline void hci_devcd_shutdown(struct hci_dev *hdev) {}
static inline void hci_devcd_rx(struct work_struct *work) {}
static inline void hci_devcd_timeout(struct work_struct *work) {}
diff --git a/net/bluetooth/coredump.c b/net/bluetooth/coredump.c
index c18df3a086075..517a61234ef43 100644
--- a/net/bluetooth/coredump.c
+++ b/net/bluetooth/coredump.c
@@ -105,6 +105,22 @@ static void hci_devcd_free(struct hci_dev *hdev)
hci_devcd_reset(hdev);
}
+void hci_devcd_shutdown(struct hci_dev *hdev)
+{
+ unsigned long flags;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ hdev->dump.supported = false;
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ disable_work_sync(&hdev->dump.dump_rx);
+ disable_delayed_work_sync(&hdev->dump.dump_timeout);
+
+ hci_dev_lock(hdev);
+ hci_devcd_free(hdev);
+ hci_dev_unlock(hdev);
+}
+
/* Call with hci_dev_lock only. */
static int hci_devcd_alloc(struct hci_dev *hdev, u32 size)
{
@@ -426,7 +442,29 @@ EXPORT_SYMBOL(hci_devcd_register);
static inline bool hci_devcd_enabled(struct hci_dev *hdev)
{
- return hdev->dump.supported;
+ return READ_ONCE(hdev->dump.supported);
+}
+
+static int hci_devcd_queue(struct hci_dev *hdev, struct sk_buff *skb)
+{
+ unsigned long flags;
+ int err = 0;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ if (!hdev->dump.supported)
+ err = -EOPNOTSUPP;
+ else
+ __skb_queue_tail(&hdev->dump.dump_q, skb);
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ if (err) {
+ kfree_skb(skb);
+ return err;
+ }
+
+ queue_work(hdev->workqueue, &hdev->dump.dump_rx);
+
+ return 0;
}
int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
@@ -443,10 +481,7 @@ int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_INIT;
put_unaligned_le32(dump_size, skb_put(skb, 4));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_init);
@@ -462,10 +497,7 @@ int hci_devcd_append(struct hci_dev *hdev, struct sk_buff *skb)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_SKB;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append);
@@ -487,10 +519,7 @@ int hci_devcd_append_pattern(struct hci_dev *hdev, u8 pattern, u32 len)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_PATTERN;
skb_put_data(skb, &p, sizeof(p));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append_pattern);
@@ -507,10 +536,7 @@ int hci_devcd_complete(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_COMPLETE;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_complete);
@@ -527,9 +553,6 @@ int hci_devcd_abort(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_ABORT;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_abort);
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 85aecd4c5b9b2..a85c77ed4a13e 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -2731,6 +2731,7 @@ void hci_unregister_dev(struct hci_dev *hdev)
disable_work_sync(&hdev->error_reset);
disable_delayed_work_sync(&hdev->cmd_timer);
disable_delayed_work_sync(&hdev->ncmd_timer);
+ hci_devcd_shutdown(hdev);
hci_cmd_sync_clear(hdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 133/877] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 132/877] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 134/877] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
` (751 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit ca18ee413a7cb6f09885778039225e58bae0d607 ]
iso_get_sock() returns the parent socket with a reference held, which is
dropped by sock_put() once the child socket has been set up. The error
path taken when iso_sock_alloc() fails only calls release_sock() and
returns, leaking the reference and thus the parent socket itself.
Drop the reference on that path as well.
Fixes: fa224d0c094a ("Bluetooth: ISO: Reassociate a socket with an active BIS")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 6e1fac4b1cf63..8cdfe3b6e1235 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -2013,6 +2013,7 @@ static void iso_conn_ready(struct iso_conn *conn)
BTPROTO_ISO, GFP_ATOMIC, 0);
if (!sk) {
release_sock(parent);
+ sock_put(parent);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 134/877] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 133/877] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 135/877] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
` (750 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 296e7f3c5071cc02dc22e1566e759179fa1792ae ]
A BIS connection is matched to its parent socket by looking for a
socket in BT_LISTEN state with the same BIG handle:
iso_conn_ready()
if (test_bit(HCI_CONN_BIG_SYNC, &hcon->flags))
parent = iso_get_sock(hdev, &hcon->src, &hcon->dst,
BT_LISTEN, iso_match_big_hcon, hcon);
The socket was only moved to BT_LISTEN after iso_conn_big_sync()
returned, while the LE BIG Create Sync command has already been queued
by then. If the BIG sync is established before the state is updated,
which is easy to hit with an emulated controller as the command may
complete in a few hundred microseconds, no parent is found and the BIS
connections are never notified to the listening socket.
The user space is then left waiting for connections that never arrive,
e.g. bluetoothd never completes a MediaTransport1.Acquire of a
Broadcast Sink transport.
Move the socket to BT_LISTEN before requesting the BIG sync, so the
state is visible by the time the command is queued, and restore the
previous state if the request could not be started. Since the socket is
briefly visible as a listening socket, child sockets may have been
queued in the meantime, so drain the accept queue before restoring the
state: the cleanup paths of BT_CONNECT2/BT_CONNECTED don't do it and the
children would be left with a dangling parent pointer.
Fixes: fbdc4bc47268 ("Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 52 +++++++++++++++++++++++++++++++++++----------
1 file changed, 41 insertions(+), 11 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 8cdfe3b6e1235..3cf4ef291bf54 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -738,19 +738,24 @@ static void iso_sock_destruct(struct sock *sk)
skb_queue_purge(&sk->sk_write_queue);
}
-static void iso_sock_cleanup_listen(struct sock *parent)
+/* Close not yet accepted channels */
+static void iso_sock_flush_accept_q(struct sock *parent)
{
struct sock *sk;
- BT_DBG("parent %p", parent);
-
- /* Close not yet accepted channels */
while ((sk = bt_accept_dequeue(parent, NULL))) {
iso_sock_close(sk);
iso_sock_kill(sk);
/* Drop the reference handed back by bt_accept_dequeue(). */
sock_put(sk);
}
+}
+
+static void iso_sock_cleanup_listen(struct sock *parent)
+{
+ BT_DBG("parent %p", parent);
+
+ iso_sock_flush_accept_q(parent);
/* If listening socket has a hcon, properly disconnect it */
if (iso_pi(parent)->conn && iso_pi(parent)->conn->hcon) {
@@ -1524,6 +1529,13 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
switch (sk->sk_state) {
case BT_CONNECT2:
if (test_bit(BT_SK_PA_SYNC, &pi->flags)) {
+ /* Move to BT_LISTEN before requesting the BIG
+ * sync: the BIS connections are matched to a
+ * parent socket in BT_LISTEN state, and they
+ * may be notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
@@ -1532,12 +1544,20 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
* connection may have been torn down
* meanwhile and iso_chan_del() may have
* already moved the socket to BT_CLOSED.
- * Only move on to BT_LISTEN if the BIG sync
- * was actually started and nothing else has
- * changed the state.
+ * Only move back if the BIG sync could not be
+ * started and nothing else has changed the
+ * state.
*/
- if (!err && sk->sk_state == BT_CONNECT2)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* Discard any child socket that may
+ * have been queued while the socket
+ * was in BT_LISTEN, as the cleanup of
+ * BT_CONNECT2 doesn't drain the
+ * accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECT2;
+ }
} else {
iso_conn_defer_accept(pi->conn->hcon);
sk->sk_state = BT_CONFIG;
@@ -1547,12 +1567,22 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
break;
case BT_CONNECTED:
if (test_bit(BT_SK_PA_SYNC, &iso_pi(sk)->flags)) {
+ /* As above, the BIS connections may be
+ * notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
- if (!err && sk->sk_state == BT_CONNECTED)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* As above, don't leave any child
+ * socket behind in the accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECTED;
+ }
early_ret = true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 135/877] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 134/877] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 136/877] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
` (749 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Lu, Luiz Augusto von Dentz,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Lu <chris.lu@mediatek.com>
[ Upstream commit 78b6abd6c7a7591aacdae657f813214dae4fcd3b ]
A too-short BTMTK_WMT_FUNC_CTRL event (WMT header only, no trailing
2-byte status word) is always treated as BTMTK_WMT_ON_UNDONE. This
short form is how firmware acks a plain enable/disable request, and
the actual result is carried in the header's own flag byte (0 =
success), not a separate status word. Decode it from there instead of
assuming failure.
Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.
Fixes: e3ac0d9f1a20 ("Bluetooth: btmtk: accept too short WMT FUNC_CTRL events")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Chris Lu <chris.lu@mediatek.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtk.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btmtk.c b/drivers/bluetooth/btmtk.c
index eb42b694da7f2..33e0e3eb65159 100644
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -709,7 +709,12 @@ static int btmtk_usb_hci_wmt_sync(struct hci_dev *hdev,
case BTMTK_WMT_FUNC_CTRL:
if (!skb_pull_data(data->evt_skb,
sizeof(wmt_evt_funcc->status))) {
- status = BTMTK_WMT_ON_UNDONE;
+ /* A plain enable/disable request is acked with just
+ * the WMT header and no trailing status word; the
+ * result is carried in the header's own flag byte.
+ */
+ status = wmt_evt->whdr.flag ? BTMTK_WMT_ON_UNDONE :
+ BTMTK_WMT_ON_DONE;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 136/877] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 135/877] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 137/877] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
` (748 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih,
Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 7b60ee5f46f2ee329de661f7c68b6818d8136220 ]
In btmtksdio_shutdown(), pm_runtime_get_sync() is called at the
beginning of the function. However, if sending the WMT function
control command fails later, the driver returns early.
It bypasses the corresponding pm_runtime_put_noidle() and
pm_runtime_disable() calls, leaking the PM usage counter and leaving PM
runtime enabled indefinitely.
Fall through to execute the PM runtime cleanup block even if WMT errors.
Fixes: 7f3c563c575e ("Bluetooth: btmtksdio: Add runtime PM support to SDIO based Bluetooth")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtksdio.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/bluetooth/btmtksdio.c b/drivers/bluetooth/btmtksdio.c
index 0e8fb01981432..575bac139715b 100644
--- a/drivers/bluetooth/btmtksdio.c
+++ b/drivers/bluetooth/btmtksdio.c
@@ -1245,10 +1245,8 @@ static int btmtksdio_shutdown(struct hci_dev *hdev)
wmt_params.status = NULL;
err = mtk_hci_wmt_sync(hdev, &wmt_params);
- if (err < 0) {
+ if (err < 0)
bt_dev_err(hdev, "Failed to send wmt func ctrl (%d)", err);
- return err;
- }
ignore_wmt_cmd:
pm_runtime_put_noidle(bdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 137/877] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 136/877] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 138/877] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
` (747 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sai Teja Aluvala,
Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
[ Upstream commit 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765 ]
btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the
FRBD array access, allowing frbd_index == rxq->count to pass through
and index one element past the end of the array. Change the check to
>= rxq->count so every out-of-range index is rejected.
This issue was reported by Claude Mythos.
Fixes: c2b636b3f788 (Bluetooth: btintel_pcie: Add support for PCIe transport)
Signed-off-by: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 8ebdfd9744ca0..bc87ebc46f4db 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -210,7 +210,7 @@ static int btintel_pcie_submit_rx(struct btintel_pcie_data *data)
frbd_index = data->ia.tr_hia[BTINTEL_PCIE_RXQ_NUM];
- if (frbd_index > rxq->count)
+ if (frbd_index >= rxq->count)
return -ERANGE;
/* Prepare for RX submit. It updates the FRBD with the address of DMA
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 138/877] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 137/877] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 139/877] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
` (746 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0cece8fa7d83523f47a3,
Juan Perdomo, Luiz Augusto von Dentz, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Juan Perdomo <jcperdomo100@gmail.com>
[ Upstream commit 801fb950cae7048eb7d83b18857d1ca37b8cd5a4 ]
rfcomm_sock_cleanup_listen() closes unaccepted child sockets through
rfcomm_sock_close(), which takes the child socket lock before
rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt_accept_dequeue() locks the child
while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent
rfcomm_connect_ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT_CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm_connect_ind() then rejects new children once cleanup starts.
Reported-by: syzbot+0cece8fa7d83523f47a3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0cece8fa7d83523f47a3
Fixes: b7ce436a5d79 ("Bluetooth: switch to lock_sock in RFCOMM")
Signed-off-by: Juan Perdomo <jcperdomo100@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/sock.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/rfcomm/sock.c b/net/bluetooth/rfcomm/sock.c
index 2286efef62f5b..037a7fcab3023 100644
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -243,9 +243,7 @@ static void __rfcomm_sock_close(struct sock *sk)
*/
static void rfcomm_sock_close(struct sock *sk)
{
- lock_sock(sk);
__rfcomm_sock_close(sk);
- release_sock(sk);
}
static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
@@ -902,6 +900,7 @@ static int rfcomm_sock_compat_ioctl(struct socket *sock, unsigned int cmd, unsig
static int rfcomm_sock_shutdown(struct socket *sock, int how)
{
struct sock *sk = sock->sk;
+ bool cleanup_listen = false;
int err = 0;
BT_DBG("sock %p, sk %p", sock, sk);
@@ -912,9 +911,17 @@ static int rfcomm_sock_shutdown(struct socket *sock, int how)
lock_sock(sk);
if (!sk->sk_shutdown) {
sk->sk_shutdown = SHUTDOWN_MASK;
+ if (sk->sk_state == BT_LISTEN) {
+ /* Block new children before cleaning up without sk lock. */
+ sk->sk_state = BT_CLOSED;
+ cleanup_listen = true;
+ }
release_sock(sk);
- __rfcomm_sock_close(sk);
+ if (cleanup_listen)
+ rfcomm_sock_cleanup_listen(sk);
+ else
+ __rfcomm_sock_close(sk);
lock_sock(sk);
if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime &&
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 139/877] pppoatm: ensure a writable skb header and linear data
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 138/877] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 140/877] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
` (745 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ecc7253683a3c55caa868ce0ee530fcb0044bd3c ]
In pppoatm_send(), LLC encapsulation checks whether there is sufficient
headroom for the 4-byte LLC header, but does not ensure that the skb header
is writable.
Normal transmit packets passing through ppp_start_xmit() have their header
unshared via skb_cow_head(). However, packets can also reach pppoatm_send()
via PPP channel bridging (PPPIOCBRIDGECHAN) without going through
ppp_start_xmit().
Use skb_cow_head() to ensure both sufficient headroom and a writable
header before pushing the LLC header.
While at it:
- Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent
out-of-bounds reads on zero-length or non-linear frames (e.g. from
bridging).
- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()
succeeds. This eliminates the temporary skb allocation on admission failure
and completely removes the fragile "undo" heuristic at the nospace label,
avoiding any risk of reading uninitialized headroom or performing an
unbalanced skb_push().
Fixes: 4cf476ced45d ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912233048.3977192-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/atm/pppoatm.c | 42 +++++++++++++++++-------------------------
1 file changed, 17 insertions(+), 25 deletions(-)
diff --git a/net/atm/pppoatm.c b/net/atm/pppoatm.c
index 3e4f17d335feb..b668a30b67a8d 100644
--- a/net/atm/pppoatm.c
+++ b/net/atm/pppoatm.c
@@ -292,10 +292,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
struct atm_vcc *vcc;
int ret;
+ if (!pskb_may_pull(skb, 1)) {
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+
ATM_SKB(skb)->vcc = pvcc->atmvcc;
pr_debug("(skb=0x%p, vcc=0x%p)\n", skb, pvcc->atmvcc);
- if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
- (void) skb_pull(skb, 1);
vcc = ATM_SKB(skb)->vcc;
bh_lock_sock(sk_atm(vcc));
@@ -318,23 +321,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
switch (pvcc->encaps) { /* LLC encapsulation needed */
case e_llc:
- if (skb_headroom(skb) < LLC_LEN) {
- struct sk_buff *n;
- n = skb_realloc_headroom(skb, LLC_LEN);
- if (n != NULL &&
- !pppoatm_may_send(pvcc, n->truesize)) {
- kfree_skb(n);
- goto nospace;
- }
- consume_skb(skb);
- skb = n;
- if (skb == NULL) {
- bh_unlock_sock(sk_atm(vcc));
- return DROP_PACKET;
- }
- } else if (!pppoatm_may_send(pvcc, skb->truesize))
+ if (skb_cow_head(skb, LLC_LEN)) {
+ bh_unlock_sock(sk_atm(vcc));
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+ if (!pppoatm_may_send(pvcc, skb->truesize))
goto nospace;
- memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
break;
case e_vc:
if (!pppoatm_may_send(pvcc, skb->truesize))
@@ -347,6 +340,12 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return 1;
}
+ if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
+ skb_pull(skb, 1);
+
+ if (pvcc->encaps == e_llc)
+ memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
+
atm_account_tx(vcc, skb);
pr_debug("atm_skb(%p)->vcc(%p)->dev(%p)\n",
skb, ATM_SKB(skb)->vcc, ATM_SKB(skb)->vcc->dev);
@@ -356,13 +355,6 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return ret;
nospace:
bh_unlock_sock(sk_atm(vcc));
- /*
- * We don't have space to send this SKB now, but we might have
- * already applied SC_COMP_PROT compression, so may need to undo
- */
- if ((pvcc->flags & SC_COMP_PROT) && skb_headroom(skb) > 0 &&
- skb->data[-1] == '\0')
- (void) skb_push(skb, 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 140/877] drop_monitor: synchronize tracepoint unregistration on error path
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 139/877] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 141/877] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
` (744 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6a038ef2b57922b6d9ca98ddac0df0681849b704 ]
If register_trace_napi_poll() fails in net_dm_trace_on_set(),
unregister_trace_kfree_skb() is called to roll back the kfree_skb
tracepoint registration.
However, tracepoint_synchronize_unregister() is omitted before calling
cancel_work_sync() and module_put(). An in-flight probe executing
concurrently on another CPU could call schedule_work() after
cancel_work_sync() has already returned, leaving a pending work item
scheduled after the module reference is dropped. If the module is then
unloaded, executing the work item triggers a kernel panic.
Add tracepoint_synchronize_unregister() after unregister_trace_kfree_skb()
in the error path, matching net_dm_trace_off_set() and
net_dm_hw_probe_unregister().
Fixes: 7c747838a558 ("drop_monitor: Split tracing enable / disable to different functions")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 308e0fa8f723f..a9c604ef2c826 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1174,6 +1174,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
err_unregister_trace:
unregister_trace_kfree_skb(ops->kfree_skb_probe, NULL);
+ tracepoint_synchronize_unregister();
err_module_put:
for_each_possible_cpu(cpu) {
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 141/877] drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 140/877] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 142/877] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
` (743 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ]
In reset_per_cpu_data(), al is computed as:
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
al += sizeof(struct nlattr);
skb = genlmsg_new(al, GFP_KERNEL);
...
nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));
...
msg = nla_data(nla);
memset(msg, 0, al);
Because al includes sizeof(struct nlattr) (the 4-byte attribute header),
genlmsg_new() allocates al bytes of tailroom starting at nla.
However, msg points to nla_data(nla), which is located
sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al)
therefore writes al bytes starting from msg, exceeding the allocated
buffer by sizeof(struct nlattr) (4 bytes) and corrupting
skb_shared_info.
Fix this by letting al represent only the payload length, allocating
the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing
al bytes from msg.
Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index a9c604ef2c826..1ba281bef21e3 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -141,9 +141,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data)
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
- al += sizeof(struct nlattr);
- skb = genlmsg_new(al, GFP_KERNEL);
+ skb = genlmsg_new(nla_total_size(al), GFP_KERNEL);
if (!skb)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 142/877] net: stmmac: do not overwrite phc_index when no PTP clock is registered
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 141/877] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 143/877] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
` (742 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Rahul Rameshbabu,
Lorenzo Bianconi, Gal Pressman, Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit f0ef4b1eaed000a304726a43091588e8426ba08a ]
stmmac_get_ts_info() reports phc_index as 0 when hardware timestamping
is supported but no PTP clock has been registered yet (e.g. while the
interface is down). Zero is a valid PHC index and would make userspace
resolve the wrong clock; the absence of a clock should be reported as
-1.
The ethtool core already initializes phc_index to -1 before invoking
the get_ts_info callback (ethtool_init_tsinfo()), so just drop the
erroneous assignment.
Fixes: 9364fa7fcf12 ("net: stmmac: Remove setting of RX software timestamp")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Rahul Rameshbabu <rrameshbabu@nvidia.com>
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Gal Pressman <gal@nvidia.com>
Link: https://patch.msgid.link/20260914-stmmac-fix-phc_index-v2-1-bf3d90373fe4@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
index 2a37592a62810..ca8712a573ea0 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
@@ -1206,8 +1206,6 @@ static int stmmac_get_ts_info(struct net_device *dev,
if (priv->ptp_clock)
info->phc_index = ptp_clock_index(priv->ptp_clock);
- else
- info->phc_index = 0;
info->tx_types = (1 << HWTSTAMP_TX_OFF) | (1 << HWTSTAMP_TX_ON);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 143/877] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 142/877] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 144/877] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
` (741 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 51938dfa8a51a4f85328413fca9b6e21f9d2d088 ]
kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops
mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a
reference on the kvm_nested_guest pointer obtained from the IDR. A
concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race
through kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove /
--refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving
the iterating vCPU with a dangling pointer. The subsequent
mutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable,
gp->shadow_lpid and gp->l1_host all touch freed memory. The free path
is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping
mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the
reference with kvmhv_put_nested() after the per-guest work completes.
This is the same get/put discipline already used at every other
call site that drops mmu_lock while holding a nested-guest pointer.
Fixes: e3b6b4661527 ("KVM: PPC: Book3S HV: Implement H_TLB_INVALIDATE hcall")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_nested.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/kvm/book3s_hv_nested.c b/arch/powerpc/kvm/book3s_hv_nested.c
index 125440a606ee3..a4dd8d983ec76 100644
--- a/arch/powerpc/kvm/book3s_hv_nested.c
+++ b/arch/powerpc/kvm/book3s_hv_nested.c
@@ -1202,8 +1202,10 @@ static void kvmhv_emulate_tlbie_all_lpid(struct kvm_vcpu *vcpu, int ric)
spin_lock(&kvm->mmu_lock);
idr_for_each_entry(&kvm->arch.kvm_nested_guest_idr, gp, lpid) {
+ ++gp->refcnt;
spin_unlock(&kvm->mmu_lock);
kvmhv_emulate_tlbie_lpid(vcpu, gp, ric);
+ kvmhv_put_nested(gp);
spin_lock(&kvm->mmu_lock);
}
spin_unlock(&kvm->mmu_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 144/877] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 143/877] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 145/877] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
` (740 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 0a416ee20bcccddf91ca5b63696a23b9d11d73aa ]
In kvmppc_svm_page_in(), if uv_page_in() fails after
kvmppc_uvmem_get_page() has succeeded, the secure device page is never
released. kvmppc_uvmem_get_page() sets a bit in kvmppc_uvmem_bitmap,
allocates a kvmppc_uvmem_page_pvt struct, marks the GFN as
KVMPPC_GFN_UVMEM_PFN, and calls zone_device_page_init() which sets
refcount=1 and locks the page. The subsequent goto out_finalize skips
the *mig.dst assignment, so migrate_vma_finalize() is a no-op for the
page, and none of those resources are ever reclaimed.
Each occurrence permanently consumes one entry from the firmware-bounded
secure memory pool (kvmppc_uvmem_bitmap), leaks pvt, and leaves the GFN
marked as secure — making it unusable for the lifetime of the VM.
The twin __kvmppc_svm_page_out() already handles the analogous uv_page_out()
failure correctly with unlock_page(dpage); __free_page(dpage). Apply
the same pattern here: unlock_page() followed by put_page(), which
chains through free_zone_device_folio() into kvmppc_uvmem_folio_free()
to clear the bitmap bit, free pvt, and reset the GFN state.
Reachable whenever uv_page_in() returns an error (e.g. UV pool
exhaustion) on any POWER9/10 + Ultravisor/PEF system.
Fixes: ca9f4942670c ("KVM: PPC: Book3S HV: Support for running secure guests")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kvm/book3s_hv_uvmem.c b/arch/powerpc/kvm/book3s_hv_uvmem.c
index 92f33115144b2..7ea0c58622274 100644
--- a/arch/powerpc/kvm/book3s_hv_uvmem.c
+++ b/arch/powerpc/kvm/book3s_hv_uvmem.c
@@ -779,8 +779,11 @@ static int kvmppc_svm_page_in(struct vm_area_struct *vma,
if (spage) {
ret = uv_page_in(kvm->arch.lpid, pfn << page_shift,
gpa, 0, page_shift);
- if (ret)
+ if (ret) {
+ unlock_page(dpage);
+ put_page(dpage);
goto out_finalize;
+ }
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 145/877] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 144/877] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 146/877] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
` (739 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Shivaprasad G Bhat, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivaprasad G Bhat <sbhat@linux.ibm.com>
[ Upstream commit 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 ]
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
Fixes: b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/iommu.c b/arch/powerpc/kernel/iommu.c
index 0ebae6e4c19dd..50c180cd1fa31 100644
--- a/arch/powerpc/kernel/iommu.c
+++ b/arch/powerpc/kernel/iommu.c
@@ -1074,7 +1074,7 @@ int iommu_tce_check_ioba(unsigned long page_shift,
if (ioba < offset)
return -EINVAL;
- if ((ioba + 1) > (offset + size))
+ if ((ioba + npages < ioba) || (ioba - offset + npages > size))
return -EINVAL;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 146/877] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 145/877] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 147/877] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
` (738 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Sasha Levin,
Linus Walleij, Mark Brown
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
[ Upstream commit 11fc0048a6930f4fca44fe3bd16a0023e78846a2 ]
arm allmodconfig fails to build with gcc:
In file included from sound/soc/ux500/ux500_msp_i2s.c:20:
sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses
around arithmetic in operand of '^' [-Werror=parentheses]
sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro
'MSP_TX_CLKPOL_BIT'
cc1: all warnings being treated as errors
The macros never parenthesized their argument:
#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
That went unnoticed while every caller passed a plain variable, but
configure_protocol() now passes an XOR expression, which binds as
"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly
complains.
No functional change: tx_clk_pol and rx_clk_pol only ever hold
MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a
bool, so masking before or after the XOR gives the same 0/1 result.
Parenthesize the argument anyway - it fixes the build and stops the
macros from silently mis-evaluating a future composite argument.
Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609051547.G9SJp8UQ-lkp@intel.com/
Assisted-by: LLM
Signed-off-by: Sasha Levin <sashal@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260913173132.1172003-1-sashal@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 2bf2699bdc49f..c66ef455e1380 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -147,8 +147,8 @@ enum msp_direction {
#define RCKPOL_MASK BIT(0)
#define TCKPOL_MASK BIT(0)
#define SPICKM_MASK (BIT(1) | BIT(0))
-#define MSP_RX_CLKPOL_BIT(n) ((n & RCKPOL_MASK) << RCKPOL_SHIFT)
-#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
+#define MSP_RX_CLKPOL_BIT(n) (((n) & RCKPOL_MASK) << RCKPOL_SHIFT)
+#define MSP_TX_CLKPOL_BIT(n) (((n) & TCKPOL_MASK) << TCKPOL_SHIFT)
#define P1ELEN_SHIFT 0
#define P1FLEN_SHIFT 3
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 147/877] ASoC: hdmi-codec: Report a change when the channel status moves
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 146/877] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 148/877] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
` (737 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit c17ae8c26eac16ad244daef44044d714f68a2ddc ]
The put() callback of "IEC958 Playback Default" stores all 24 channel
status bytes and then returns 0. The core notifies userspace only on a
positive return, so a write that changes what the get() callback hands
back is never announced, and a mixer holding the control open keeps
showing the old value.
Compare the stored bytes and return 1 when they move, the way
snd_hda_spdif_default_put() does.
The same shape is in img-spdif-out and uniperif_player.
No board with this codec was to hand. The change is a comparison of
driver state with no hardware behaviour in it, and mixer-test counts the
missing notification as event_missing.
Fixes: 7a8e1d44211e ("ASoC: hdmi-codec: Add iec958 controls")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260915092515.2638542-1-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/hdmi-codec.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/hdmi-codec.c b/sound/soc/codecs/hdmi-codec.c
index d9df29a26f4f2..0ffc649c6ad21 100644
--- a/sound/soc/codecs/hdmi-codec.c
+++ b/sound/soc/codecs/hdmi-codec.c
@@ -423,10 +423,14 @@ static int hdmi_codec_iec958_default_put(struct snd_kcontrol *kcontrol,
struct snd_soc_component *component = snd_kcontrol_chip(kcontrol);
struct hdmi_codec_priv *hcp = snd_soc_component_get_drvdata(component);
+ if (!memcmp(hcp->iec_status, ucontrol->value.iec958.status,
+ sizeof(hcp->iec_status)))
+ return 0;
+
memcpy(hcp->iec_status, ucontrol->value.iec958.status,
sizeof(hcp->iec_status));
- return 0;
+ return 1;
}
static int hdmi_codec_iec958_mask_get(struct snd_kcontrol *kcontrol,
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 148/877] net: netsec: fix device_node reference leak on phy_np
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 147/877] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 149/877] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
` (736 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yige Jiang, Simon Horman,
Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yige Jiang <yigejiang86@gmail.com>
[ Upstream commit 5ae916fabca141b79b32e2e57f3c915c0f1e1b2e ]
netsec_of_probe() takes a reference on the PHY device_node with
of_parse_phandle() and stores it in priv->phy_np, but the driver never
drops it. One device_node reference is leaked per probe, on the success
path as well as on every error path reached after netsec_of_probe().
Neither consumer takes ownership. of_mdio_parse_addr() is a static
inline taking a const struct device_node * that only reads the "reg"
property. of_phy_connect() borrows as well: of_phy_get_and_connect() in
drivers/net/mdio/of_mdio.c brackets its own call with of_node_get() at
:364 and of_node_put() at :373, which would be a double put if
of_phy_connect() consumed the reference.
The node is still in use at netsec_netdev_open() time, where it is
passed to of_phy_connect(), so it has device lifetime. Release it at
the probe error label, which every failure path after the acquire
funnels through, and in netsec_remove(). Both releases precede
free_netdev(), since priv is netdev_priv(ndev). The ACPI probe path
leaves priv->phy_np NULL and of_node_put(NULL) is a no-op.
There is no end-user visible symptom on currently supported platforms:
a device_node is only freed once OF_DYNAMIC is enabled and the node has
been detached, so on a static device tree the imbalance is inert. It is
observable as a refcount that grows across bind/unbind cycles, and would
matter under device tree overlays.
Found by static analysis of reference acquire/release pairing rather
than from a runtime report. No reproducer was produced and the change
has not been runtime tested; it is compile-tested only (arm64,
CONFIG_SNI_NETSEC=m via COMPILE_TEST).
Fixes: 533dd11a12f6 ("net: socionext: Add Synquacer NetSec driver")
Signed-off-by: Yige Jiang <yigejiang86@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260913064102.37452-1-yigejiang86@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/socionext/netsec.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/socionext/netsec.c b/drivers/net/ethernet/socionext/netsec.c
index 5ab8b81b84e6f..e96e22dd30808 100644
--- a/drivers/net/ethernet/socionext/netsec.c
+++ b/drivers/net/ethernet/socionext/netsec.c
@@ -2146,6 +2146,7 @@ static int netsec_probe(struct platform_device *pdev)
pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
free_ndev:
+ of_node_put(priv->phy_np);
free_netdev(ndev);
dev_err(&pdev->dev, "init failed\n");
@@ -2163,6 +2164,7 @@ static void netsec_remove(struct platform_device *pdev)
netif_napi_del(&priv->napi);
pm_runtime_disable(&pdev->dev);
+ of_node_put(priv->phy_np);
free_netdev(priv->ndev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 149/877] net: lock the socket in sock_gettstamp()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 148/877] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 150/877] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
` (735 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jungwoo Lee, Wongi Lee, Eric Dumazet,
Simon Horman, Jakub Kicinski, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 9ed55f3dbef4f4adfe65eb03b0c35c53229a8490 ]
sk->sk_flags must only be changed while holding the socket lock,
because sock_set_flag() and sock_reset_flag() use non atomic
operations (__set_bit() and __clear_bit()).
sock_gettstamp() is one of the last places where a bit of sk->sk_flags
is changed from a syscall without owning the socket lock, through
sock_enable_timestamp(sk, SOCK_TIMESTAMP).
sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags
without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()
can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,
because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS_NEW)
-------------------------------- ----------------------------
read sk_flags = F read sk_flags = F
compute F | BIT(SOCK_RCU_FREE) compute F | BIT(SOCK_TIMESTAMP)
store F | BIT(SOCK_RCU_FREE)
sk_add_node_rcu(sk, ...)
store F | BIT(SOCK_TIMESTAMP)
After the lost update, SOCK_RCU_FREE is clear while the socket is
visible to lockless UDP receive lookups. sk_destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410
Read of size 8 at addr ffff888008806610 by task exploit/207
CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
ipv4_pktinfo_prepare+0x30/0x410
udp_queue_rcv_one_skb+0x51c/0x1180
udp_unicast_rcv_skb+0x109/0x350
ip_protocol_deliver_rcu+0x14b/0x310
ip_local_deliver_finish+0x29d/0x390
ip_local_deliver+0x24d/0x2a0
Only grab the socket lock when SOCK_TIMESTAMP has to be set,
to keep the common case lockless.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Jungwoo Lee <jwlee2217@gmail.com>
Reported-by: Wongi Lee <qw3rtyp0@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/net/core/sock.c b/net/core/sock.c
index e8b03cf3a428c..08b3569ac7a18 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -3724,7 +3724,14 @@ int sock_gettstamp(struct socket *sock, void __user *userstamp,
struct sock *sk = sock->sk;
struct timespec64 ts;
- sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ /* sk->sk_flags must only be changed under the socket lock,
+ * because sock_set_flag() uses non atomic operations.
+ */
+ if (!sock_flag(sk, SOCK_TIMESTAMP)) {
+ lock_sock(sk);
+ sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ release_sock(sk);
+ }
ts = ktime_to_timespec64(sock_read_timestamp(sk));
if (ts.tv_sec == -1)
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 150/877] net: ethernet: cortina: Ack RX overrun interrupt correctly
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 149/877] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 151/877] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
` (734 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linus Walleij, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e ]
The RX overrun interrupt is reported in interrupt status register 4, but
gmac_irq() acknowledges it using the RX descriptor error bit from status
register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1
the shift leaves no bit in the 32-bit register.
Acknowledge the same per-port RX overrun bit that was detected.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914-b4-gemini-ethernet-fixes-2-v2-1-5ab39a047b90@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 96fd27545b29b..1b81798914acc 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1798,7 +1798,7 @@ static irqreturn_t gmac_irq(int irq, void *data)
if (val & (GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8))) {
spin_lock(&geth->irq_lock);
- writel(GMAC0_RXDERR_INT_BIT << (netdev->dev_id * 8),
+ writel(GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8),
geth->base + GLOBAL_INTERRUPT_STATUS_4_REG);
u64_stats_update_begin(&port->ir_stats_syncp);
++port->stats.rx_fifo_errors;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 151/877] net: stmmac: propagate FPE preemption-class mapping errors
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 150/877] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 152/877] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
` (733 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Jakub Kicinski,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 90e4b849dfa6fc8e6c050bcfe1b331b69c015d28 ]
stmmac_fpe_map_preemption_class() dispatches through the
stmmac_do_void_callback() helper, which forces the callback's return
value to 0 whenever the op pointer is populated. As a result the
-EINVAL returned by dwmac5_fpe_map_preemption_class() (e.g. when a
preemptible TC owns more than one TXQ under SP scheduling) is silently
swallowed by every caller.
Switch the dispatch macro to stmmac_do_callback() so the callback's real
result is propagated, and honour it in the taprio and mqprio qdisc
offload.
Note that the taprio "if (ret)" check in tc_taprio_configure() used to
be dead code and now becomes live: a preemptible TC spanning more than
one TXQ under SP scheduling cannot be programmed in hardware, so a
taprio or mqprio configuration that previously returned success while
leaving the preemption-class register unprogrammed now fails with
-EINVAL. For taprio, the failure also runs the disable path, tearing
down the schedule that was just installed; this is the intended
behaviour.
Fixes: 195e4f409a40 ("net: stmmac: support fp parameter of tc-mqprio")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-1-a76b1e2547c1@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
.../net/ethernet/stmicro/stmmac/stmmac_tc.c | 19 +++++++++----------
2 files changed, 10 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/hwif.h b/drivers/net/ethernet/stmicro/stmmac/hwif.h
index d5a9f01ecac53..31d7f9375d747 100644
--- a/drivers/net/ethernet/stmicro/stmmac/hwif.h
+++ b/drivers/net/ethernet/stmicro/stmmac/hwif.h
@@ -541,7 +541,7 @@ struct stmmac_ops {
#define stmmac_fpe_set_add_frag_size(__priv, __args...) \
stmmac_do_void_callback(__priv, mac, fpe_set_add_frag_size, __args)
#define stmmac_fpe_map_preemption_class(__priv, __args...) \
- stmmac_do_void_callback(__priv, mac, fpe_map_preemption_class, __args)
+ stmmac_do_callback(__priv, mac, fpe_map_preemption_class, __args)
/* PTP and HW Timer helpers */
struct stmmac_hwtimestamp {
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
index 49f133dec810d..65085f9c9290e 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
@@ -970,7 +970,7 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
struct netlink_ext_ack *extack = qopt->mqprio.extack;
struct timespec64 time, current_time, qopt_time;
ktime_t current_time_ns;
- int i, ret = 0;
+ int err, i, ret = 0;
u64 ctr;
if (qopt->base_time < 0)
@@ -1119,9 +1119,9 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
mutex_unlock(&priv->est_lock);
}
- stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
+ err = stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
- return ret;
+ return qopt->cmd == TAPRIO_CMD_DESTROY ? err : ret;
}
static void tc_taprio_stats(struct stmmac_priv *priv,
@@ -1234,14 +1234,15 @@ static int tc_query_caps(struct stmmac_priv *priv,
}
}
-static void stmmac_reset_tc_mqprio(struct net_device *ndev,
- struct netlink_ext_ack *extack)
+static int stmmac_reset_tc_mqprio(struct net_device *ndev,
+ struct netlink_ext_ack *extack)
{
struct stmmac_priv *priv = netdev_priv(ndev);
netdev_reset_tc(ndev);
netif_set_real_num_tx_queues(ndev, priv->plat->tx_queues_to_use);
- stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
+
+ return stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
}
static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
@@ -1254,10 +1255,8 @@ static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
u32 num_tc = qopt->num_tc;
int err;
- if (!num_tc) {
- stmmac_reset_tc_mqprio(ndev, extack);
- return 0;
- }
+ if (!num_tc)
+ return stmmac_reset_tc_mqprio(ndev, extack);
err = netdev_set_num_tc(ndev, num_tc);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 152/877] net: macb: fix ordering around PTP timestamp read
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 151/877] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 153/877] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
` (732 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Théo Lebrun,
James Clark, Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <jjc@jclark.com>
[ Upstream commit 9ca4ba24259183ce15665be86b2956cd896c4687 ]
PTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly
bracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the
returned interval can be as short as 37 ns, while an ordered register
read takes approximately 1 us. This biases the midpoint used by phc2sys,
causing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized
to the PHC.
gem_tsu_get_time() reads the nanoseconds register using the driver's
relaxed MMIO accessor. On weakly ordered systems, the subsequent system
timestamp can be taken before the register read completes. The internal
smp_rmb() in the pre-timestamp path also does not guarantee ordering
against the subsequent MMIO read.
Add rmb() before and after the bracketed nanoseconds read in both the
normal and seconds rollover paths so the system timestamps bracket the
PHC read. Adding the post-read barrier increases the minimum interval on
the same Raspberry Pi 5 to approximately 1 us.
Fixes: e51bb5c2784c ("net: macb: ptp: Switch to gettimex64() interface")
Tested-by: Nicolai Buchwitz <nb@tipi-net.de> # Raspberry Pi CM5, min bracket 37 ns -> 981 ns
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Théo Lebrun <theo.lebrun@bootlin.com>
Assisted-by: LLM
Signed-off-by: James Clark <jjc@jclark.com>
Link: https://patch.msgid.link/20260915045823.76100-1-jjc@jclark.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_ptp.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/net/ethernet/cadence/macb_ptp.c b/drivers/net/ethernet/cadence/macb_ptp.c
index f2b09100f710e..004c0b3b9181c 100644
--- a/drivers/net/ethernet/cadence/macb_ptp.c
+++ b/drivers/net/ethernet/cadence/macb_ptp.c
@@ -48,7 +48,12 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
spin_lock_irqsave(&bp->tsu_clk_lock, flags);
ptp_read_system_prets(sts);
+ /* explicit barriers are needed because gem_readl() is relaxed */
+ if (sts)
+ rmb();
first = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
@@ -60,7 +65,11 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
* (assume all done within 1s)
*/
ptp_read_system_prets(sts);
+ if (sts)
+ rmb();
ts->tv_nsec = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 153/877] net: mvpp2: prevent buffer overflow in page_pool allocation
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 152/877] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 154/877] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
` (731 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitriy Okunev, Paolo Abeni,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Okunev <dokunevdmitriy@gmail.com>
[ Upstream commit 14cb1e7702e5cb3c58888f6aed498381a73927d2 ]
The per‑processor buffering scheme is supported only if the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).
This is already checked in mvpp2_probe() during the initial
activation of percpu_pools.
However, mvpp2_change_mtu() may later call
mvpp2_bm_switch_buffers(priv, true) without this check, which can
lead to an out-of-bounds access in the priv->page_pool array in
mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ
entries, and mvpp2_get_nrxqs() may return exactly that value. The
per-CPU scheme then doubles it to nrxqs * 2, exceeding the array
bounds.
Check that the hardware version is MVPP22 or newer and that the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS
before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7d04b0b13b11 ("mvpp2: percpu buffers")
Signed-off-by: Dmitriy Okunev <dokunevdmitriy@gmail.com>
Link: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
index 325a3a657249d..8096b46b654fd 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
@@ -5099,7 +5099,8 @@ static int mvpp2_change_mtu(struct net_device *dev, int mtu)
netdev_warn(dev, "mtu %d too high, switching to shared buffers", mtu);
mvpp2_bm_switch_buffers(priv, false);
}
- } else {
+ } else if (priv->hw_version >= MVPP22 &&
+ mvpp2_get_nrxqs(priv) * 2 <= MVPP2_BM_MAX_POOLS) {
bool jumbo = false;
int i;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 154/877] net: skbuff: do not leave stale header offsets after pskb_carve()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 153/877] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 155/877] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
` (730 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+586af68eb819833c2d91,
Xuanqiang Luo, Allison Henderson, rds-devel, Eric Dumazet,
Xuanqiang Luo, Paolo Abeni, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309 ]
pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone,
but both functions call skb_headers_offset_update(skb, 0), which
is a no-op : skb->mac_header, skb->network_header,
skb->transport_header and skb->csum_start keep their old values and
now describe bytes which are no longer there.
Both helpers size the new head from the old skb_end_offset(), so the
stale offsets still land inside the new allocation. They point past
skb_tail_pointer() though, to bytes that were never initialized.
pskb_carve_inside_nonlinear() is the worst case, because it leaves a
zombie skb with an empty linear part (skb->data ==
skb_tail_pointer(skb), skb_headlen(skb) == 0), while
skb_mac_header_was_set() is still true and skb->mac_header is way
ahead of skb->data.
The only user of pskb_extract() is rds_tcp_data_recv(), and the
carved skb is queued on tinc->ti_skb_list. When the RDS incoming
message is released, rds_tcp_inc_free() calls skb_queue_purge(),
which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
visible from drop_monitor, which then tries to pull back to the
(bogus) mac header :
skbuff: __skb_pull(len=234)
skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
kernel BUG at ./include/linux/skbuff.h:2847!
Add skb_carve_reset_headers() to mark the mac and transport headers
as not set, reset the network header, clear skb->mac_len, and drop
a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
anything).
Invalidate the inner offsets as well. Unlike mac_header and
transport_header they have no "unset" sentinel, so a leftover
non-zero value still looks like a real header. Zero
skb->inner_mac_header, skb->inner_network_header,
skb->inner_transport_header, skb->inner_protocol and
skb->encapsulation, so that all the header state is invalidated in
one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the
new skb->head, which is never smaller than the old one, they
simply point past skb_tail_pointer() to bytes that are gone.
Thanks to Xuanqiang Luo for insisting on this.
Also invalidate the inner header state, as suggested by the
netdev AI review :
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Fixes: 6fa01ccd8830 ("skbuff: Add pskb_extract() helper function")
Reported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/
Cc: Xuanqiang Luo <xuanqiang.luo@linux.dev>
Cc: Allison Henderson <achender@kernel.org>
Cc: rds-devel@oss.oracle.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260915130423.3956471-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skbuff.c | 32 ++++++++++++++++++++++++++++++--
1 file changed, 30 insertions(+), 2 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 449c84fa73539..1e4f7b8e952cc 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6696,6 +6696,34 @@ struct sk_buff *alloc_skb_with_frags(unsigned long header_len,
}
EXPORT_SYMBOL(alloc_skb_with_frags);
+/* pskb_carve_inside_header() and pskb_carve_inside_nonlinear()
+ * remove the first bytes of a packet and reallocate skb->head.
+ *
+ * Whatever headers were present before the operation are gone,
+ * we must not leave stale offsets, otherwise users of this skb
+ * (skb_dump(), drop_monitor, taps, ...) would read or pull garbage.
+ */
+static void skb_carve_reset_headers(struct sk_buff *skb)
+{
+ skb_unset_mac_header(skb);
+ skb_unset_transport_header(skb);
+ skb_reset_network_header(skb);
+ skb->mac_len = 0;
+
+ /* Inner offsets have no "unset" marker, zero them so that
+ * skb_inner_network_header_was_set() becomes false and no
+ * consumer mistakes them for a real (and long gone) header.
+ */
+ skb->inner_mac_header = 0;
+ skb->inner_network_header = 0;
+ skb->inner_transport_header = 0;
+ skb->inner_protocol = 0;
+ skb->encapsulation = 0;
+
+ if (skb->ip_summed == CHECKSUM_PARTIAL)
+ skb->ip_summed = CHECKSUM_NONE;
+}
+
/* carve out the first off bytes from skb when off < headlen */
static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
const int headlen, gfp_t gfp_mask)
@@ -6751,7 +6779,7 @@ static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
skb->head_frag = 0;
skb_set_end_offset(skb, size);
skb_set_tail_pointer(skb, skb_headlen(skb));
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
@@ -6892,7 +6920,7 @@ static int pskb_carve_inside_nonlinear(struct sk_buff *skb, const u32 off,
skb->data = data;
skb_set_end_offset(skb, size);
skb_reset_tail_pointer(skb);
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 155/877] drm/amdgpu: check ras and obj before dereference
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 154/877] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 156/877] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
` (729 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Zhou, Dmitriy Chumachenko,
Alex Deucher, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
[ Upstream commit 723d4dc628d764b19cf9efca14b82cca5ff020c9 ]
nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj
without checking either for NULL. Both amdgpu_ras_get_context() and
amdgpu_ras_find_obj() can return NULL, e.g. during the window between
adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to
enable the fatal-error interrupt as soon as possible) and the PCIE_BIF
ras object actually being created in RAS late_init. Any interrupt in that
window crashes in hard-IRQ context.
This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning
dereferencing obj for nbio_v7_4"), which fixed the same issue in the
nbio_v7_4 handler.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7692e1ee2446 ("drm/amdgpu: add RAS fatal error handler for NBIO v7.9")
Reviewed-by: Tao Zhou <tao.zhou1@amd.com>
Signed-off-by: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
index 8e401f8b2a054..2b3a1b9f8efc0 100644
--- a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
+++ b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
@@ -518,7 +518,7 @@ static void nbio_v7_9_handle_ras_controller_intr_no_bifring(struct amdgpu_device
RAS_CNTLR_INTERRUPT_CLEAR, 1);
WREG32_SOC15(NBIO, 0, regBIF_BX0_BIF_DOORBELL_INT_CNTL, bif_doorbell_intr_cntl);
- if (!ras->disable_ras_err_cnt_harvest) {
+ if (ras && !ras->disable_ras_err_cnt_harvest && obj) {
/*
* clear error status after ras_controller_intr
* according to hw team and count ue number
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 156/877] btrfs: abort transaction on failure to update inode for hole punching and reflinking
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 155/877] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 157/877] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
` (728 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit 97fcd34aa9fd73cefe3120ac9a82ca9d7763922f ]
If we fail to update the inode we error out without aborting the
transaction, which can result in a persistent inconsistency if after
the failure the transaction is committed, as we have dropped file
extent items from a range and either punched a hole or insert a new file
extent item for that range (for reflinks).
So add the missing transaction abort.
Fixes: 2aaa66558172 ("Btrfs: add hole punching")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/file.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/file.c b/fs/btrfs/file.c
index 9c3b5ecb0b01e..5627e2f7dd64a 100644
--- a/fs/btrfs/file.c
+++ b/fs/btrfs/file.c
@@ -2545,8 +2545,10 @@ int btrfs_replace_file_extents(struct btrfs_inode *inode,
inode_set_ctime_current(&inode->vfs_inode));
ret = btrfs_update_inode(trans, inode);
- if (ret)
+ if (unlikely(ret)) {
+ btrfs_abort_transaction(trans, ret);
break;
+ }
btrfs_end_transaction(trans);
btrfs_btree_balance_dirty(fs_info);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 157/877] x86/fred: Reconstruct the #GP context for rejected INT instructions
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 156/877] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 158/877] mm/huge_memory: use folios memcg inside __folio_split() Greg Kroah-Hartman
` (727 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Gofman, Matthew Schwartz,
Peter Zijlstra (Intel), H. Peter Anvin, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Schwartz <matthew.schwartz@linux.dev>
[ Upstream commit 93f53499d0b945e8ae447f497faf743d60069f61 ]
FRED event delivery does not use the IDT, so the gate DPL check that
rejects a user INT n falls to software (Intel FRED specification [1],
section 8.3). fred_intx() rejects the same vectors as IDT delivery, but
reports a zero error code and the IP after the INT. This breaks the
signal ABI. Wine uses the error code to recognize INT 0x2d, so the
changed context turns a handled breakpoint into an access violation in
Elden Ring.
Rewind IP using the instruction length in the augmented SS and
synthesize the IDT selector error code, (vector << 3) | 2. Set RF in the
saved flags, as the CPU does for a #GP fault. Section 5.2.1 defines the
saved vector, instruction length and RF state. The supplied length
handles prefixes without reading user memory. Limit the changes to
already-rejected software interrupts, preserving the accepted INT3, INT4
and enabled INT80 paths and hardware exceptions. With IA32 emulation
disabled, INT 0x80 now reports the same #GP as the DPL 0 gate IDT
installs there. The rewound IP also stops fixup_iopl_exception() from
inspecting the byte after the INT.
Also clear the software event flag. Section 6.2.3 specifies that ERETU
with this flag and TF set traps before executing any user instruction. A
tracer that suppresses SIGSEGV and resumes with TF set expects the next
instruction to run first, as after IRET. The sigreturn path clears the
same flag for this reason in prevent_single_step_upon_eretu().
[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), sections 5.2.1, 6.2.3 and 8.3.
Fixes: 14619d912b65 ("x86/fred: FRED entry/exit and dispatch code")
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/15745
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/16132
Reported-by: Paul Gofman <pgofman@codeweavers.com>
Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: H. Peter Anvin <hpa@zytor.com>
Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1]
Link: https://patch.msgid.link/20260917230907.2080792-2-matthew.schwartz@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/entry/entry_fred.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/arch/x86/entry/entry_fred.c b/arch/x86/entry/entry_fred.c
index 9f50f0c1c00f5..c43c750fa26dc 100644
--- a/arch/x86/entry/entry_fred.c
+++ b/arch/x86/entry/entry_fred.c
@@ -10,6 +10,7 @@
#include <asm/desc.h>
#include <asm/fred.h>
#include <asm/idtentry.h>
+#include <asm/processor-flags.h>
#include <asm/syscall.h>
#include <asm/trapnr.h>
#include <asm/traps.h>
@@ -71,7 +72,15 @@ static noinstr void fred_intx(struct pt_regs *regs)
#endif
default:
- return exc_general_protection(regs, 0);
+ /*
+ * Reconstruct the #GP fault state that IDT delivery would produce.
+ * Clear the software event flag so ERETU with TF set does not trap
+ * before the resumed instruction. See prevent_single_step_upon_eretu().
+ */
+ regs->ip -= regs->fred_ss.insnlen;
+ regs->flags |= X86_EFLAGS_RF;
+ regs->fred_ss.swevent = 0;
+ return exc_general_protection(regs, (regs->fred_ss.vector << 3) | 2);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 158/877] mm/huge_memory: use folios memcg inside __folio_split()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 157/877] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 159/877] wifi: rtw88: TX QOS Null data the same way as Null data Greg Kroah-Hartman
` (726 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zi Yan, Johannes Weiner, Baolin Wang,
Lorenzo Stoakes (ARM), Barry Song, David Hildenbrand, Dev Jain,
Lance Yang, Liam R. Howlett, Matthew Wilcox (Oracle),
Ryan Roberts, William Kucharski, Andrew Morton, Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zi Yan <ziy@nvidia.com>
commit c299a2285d9d8bda4da024455de65e3d00de6f17 upstream.
Patch series "Honor XA_FLAGS_ACCOUNT in xas_split_alloc() and charge to
folio's memcg", v3.
__GFP_ACCOUNT is needed for xarray node allocation accounting when
XA_FLAGS_ACCOUNT is set. Commit 7b785645e8f13 ("mm: fix page cache
convergence regression") fixed a workingset regression with it.
xas_split_alloc() does not have it and needs to be fixed.
In addition, based on Sashiko's review[1] and Johannes' confirmation[2], to
charge the right memcg, folio's memcg needs to be active during folio
split. Add that before adding __GFP_ACCOUNT.
There is no workingset convergence regression related to missing
__GFP_ACCOUNT in xas_split_alloc() and the impact to userspace should be
minor.
This patch (of 2):
During a pagecache folio split, an xarray node allocation can happen and
needs to charge at folio's memcg instead of folio split invoker's memcg,
because for example folio split can happen during reclaim and reclaim's
active memcg might not be folio's memcg. Switch to folio's memcg at the
beginning and switch back afterwards.
Link: https://lore.kernel.org/20260804-add-gfp_account-to-xas_split_alloc-v3-0-38cb3ff325c5@nvidia.com
Link: https://lore.kernel.org/20260804-add-gfp_account-to-xas_split_alloc-v3-1-38cb3ff325c5@nvidia.com
Link: https://sashiko.dev/#/patchset/20260727-add-gfp_account-to-xas_split_alloc-v1-1-9fae6bf64838%40nvidia.com?part=1 [1]
Link: https://lore.kernel.org/all/amtcBZ-_QVRgCd6b@cmpxchg.org/ [2]
Fixes: 6b24ca4a1a8d ("mm: Use multi-index entries in the page cache")
Signed-off-by: Zi Yan <ziy@nvidia.com>
Suggested-by: Johannes Weiner <hannes@cmpxchg.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Lance Yang <lance.yang@linux.dev>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: William Kucharski <william.kucharski@oracle.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
(cherry picked from commit c299a2285d9d8bda4da024455de65e3d00de6f17)
Signed-off-by: Zi Yan <ziy@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/huge_memory.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/mm/huge_memory.c b/mm/huge_memory.c
index 6fc4e1fb88ae6..1a76a21724d40 100644
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -3420,6 +3420,7 @@ int split_huge_page_to_list_to_order(struct page *page, struct list_head *list,
/* reset xarray order to new order after split */
XA_STATE_ORDER(xas, &folio->mapping->i_pages, folio->index, new_order);
bool is_anon = folio_test_anon(folio);
+ struct mem_cgroup *memcg, *old_memcg;
struct address_space *mapping = NULL;
struct anon_vma *anon_vma = NULL;
int order = folio_order(folio);
@@ -3483,6 +3484,13 @@ int split_huge_page_to_list_to_order(struct page *page, struct list_head *list,
if (folio_test_writeback(folio))
return -EBUSY;
+ /*
+ * switch to folio's memcg as xarray node allocation can happen and
+ * needs to charge to it.
+ */
+ memcg = folio_memcg(folio);
+ old_memcg = set_active_memcg(memcg);
+
if (is_anon) {
/*
* The caller does not necessarily hold an mmap_lock that would
@@ -3629,6 +3637,8 @@ int split_huge_page_to_list_to_order(struct page *page, struct list_head *list,
if (mapping)
i_mmap_unlock_read(mapping);
out:
+ /* restore to caller's old_memcg */
+ set_active_memcg(old_memcg);
xas_destroy(&xas);
if (order == HPAGE_PMD_ORDER)
count_vm_event(!ret ? THP_SPLIT_PAGE : THP_SPLIT_PAGE_FAILED);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 159/877] wifi: rtw88: TX QOS Null data the same way as Null data
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 158/877] mm/huge_memory: use folios memcg inside __folio_split() Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 160/877] wifi: rtw88: Fix the random "error beacon valid" messages for USB Greg Kroah-Hartman
` (725 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bitterblue Smith, Ping-Ke Shih,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bitterblue Smith <rtl8821cerfe2@gmail.com>
[ Upstream commit 737e980e12983bb7420a2c00b981a1e607079a84 ]
When filling out the TX descriptor, Null data frames are treated like
management frames, but QOS Null data frames are treated like normal
data frames. Somehow this causes a problem for the firmware.
When connected to a network in the 2.4 GHz band, wpa_supplicant (or
NetworkManager?) triggers a scan every five minutes. During these scans
mac80211 transmits many QOS Null frames in quick succession. Because
these frames are marked with IEEE80211_TX_CTL_REQ_TX_STATUS, rtw88
asks the firmware to report the TX ACK status for each of these frames.
Sometimes the firmware can't process the TX status requests quickly
enough, they add up, it only processes some of them, and then marks
every subsequent TX status report with the wrong number.
The symptom is that after a while the warning "failed to get tx report
from firmware" appears every five minutes.
This problem apparently happens only with the older RTL8723D, RTL8821A,
RTL8812A, and probably RTL8703B chips.
Treat QOS Null data frames the same way as Null data frames. This seems
to avoid the problem.
Tested with RTL8821AU, RTL8723DU, RTL8811CU, and RTL8812BU.
Signed-off-by: Bitterblue Smith <rtl8821cerfe2@gmail.com>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/2b53fb0d-b1ed-47b6-8caa-2bb9ae2acb80@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw88/tx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw88/tx.c b/drivers/net/wireless/realtek/rtw88/tx.c
index 662fb27224f3d..0c8817bf46c74 100644
--- a/drivers/net/wireless/realtek/rtw88/tx.c
+++ b/drivers/net/wireless/realtek/rtw88/tx.c
@@ -421,7 +421,7 @@ void rtw_tx_pkt_info_update(struct rtw_dev *rtwdev,
pkt_info->mac_id = rtwvif->mac_id;
}
- if (ieee80211_is_mgmt(fc) || ieee80211_is_nullfunc(fc))
+ if (ieee80211_is_mgmt(fc) || ieee80211_is_any_nullfunc(fc))
rtw_tx_mgmt_pkt_info_update(rtwdev, pkt_info, sta, skb);
else if (ieee80211_is_data(fc))
rtw_tx_data_pkt_info_update(rtwdev, pkt_info, sta, skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 160/877] wifi: rtw88: Fix the random "error beacon valid" messages for USB
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 159/877] wifi: rtw88: TX QOS Null data the same way as Null data Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 161/877] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
` (724 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bitterblue Smith, Ping-Ke Shih,
Sasha Levin
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bitterblue Smith <rtl8821cerfe2@gmail.com>
[ Upstream commit f24d0d8c3cd7e4237f802c4d2f3bd4ac04572948 ]
All the USB devices have a problem in AP mode: uploading the updated
beacon to the chip's reserved page can randomly fail:
[34996.474304] rtw88_8723du 1-2:1.2: error beacon valid
[34996.474788] rtw88_8723du 1-2:1.2: failed to download drv rsvd page
[34999.956369] rtw88_8723du 1-2:1.2: error beacon valid
[34999.956846] rtw88_8723du 1-2:1.2: failed to download drv rsvd page
[34999.956855] rtw88_8723du 1-2:1.2: failed to download beacon
[35017.978296] rtw88_8723du 1-2:1.2: error beacon valid
[35017.978805] rtw88_8723du 1-2:1.2: failed to download drv rsvd page
[35017.978823] rtw88_8723du 1-2:1.2: failed to download beacon
[35023.200395] rtw88_8723du 1-2:1.2: error beacon valid
[35023.200869] rtw88_8723du 1-2:1.2: failed to download drv rsvd page
[35023.200875] rtw88_8723du 1-2:1.2: failed to download beacon
[35478.680547] rtw88_8723du 1-2:1.2: error beacon valid
[35478.681023] rtw88_8723du 1-2:1.2: failed to download drv rsvd page
Disable some beacon-related hardware functions before uploading the
beacon and enable them again after.
Tested with RTL8723DU, RTL8812BU, RTL8822CE.
Signed-off-by: Bitterblue Smith <rtl8821cerfe2@gmail.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/c248c40a-d432-47ed-90e0-d81ee6c32464@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw88/fw.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw88/fw.c b/drivers/net/wireless/realtek/rtw88/fw.c
index 43e3df6a48369..fd3bcb4466209 100644
--- a/drivers/net/wireless/realtek/rtw88/fw.c
+++ b/drivers/net/wireless/realtek/rtw88/fw.c
@@ -1446,7 +1446,7 @@ void rtw_add_rsvd_page_sta(struct rtw_dev *rtwdev,
int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
u8 *buf, u32 size)
{
- u8 bckp[2];
+ u8 bckp[3];
u8 val;
u16 rsvd_pg_head;
u32 bcn_valid_addr;
@@ -1458,6 +1458,8 @@ int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
if (!size)
return -EINVAL;
+ bckp[2] = rtw_read8(rtwdev, REG_BCN_CTRL);
+
if (rtw_chip_wcpu_11n(rtwdev)) {
rtw_write32_set(rtwdev, REG_DWBCN0_CTRL, BIT_BCN_VALID);
} else {
@@ -1471,6 +1473,9 @@ int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
val |= BIT_ENSWBCN >> 8;
rtw_write8(rtwdev, REG_CR + 1, val);
+ rtw_write8(rtwdev, REG_BCN_CTRL,
+ (bckp[2] & ~BIT_EN_BCN_FUNCTION) | BIT_DIS_TSF_UDT);
+
if (rtw_hci_type(rtwdev) == RTW_HCI_TYPE_PCIE) {
val = rtw_read8(rtwdev, REG_FWHW_TXQ_CTRL + 2);
bckp[1] = val;
@@ -1501,6 +1506,7 @@ int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
rsvd_pg_head = rtwdev->fifo.rsvd_boundary;
rtw_write16(rtwdev, REG_FIFOPAGE_CTRL_2,
rsvd_pg_head | BIT_BCN_VALID_V1);
+ rtw_write8(rtwdev, REG_BCN_CTRL, bckp[2]);
if (rtw_hci_type(rtwdev) == RTW_HCI_TYPE_PCIE)
rtw_write8(rtwdev, REG_FWHW_TXQ_CTRL + 2, bckp[1]);
rtw_write8(rtwdev, REG_CR + 1, bckp[0]);
--
2.53.0
^ permalink raw reply related [flat|nested] 922+ messages in thread
* [PATCH 6.12 161/877] Input: xpad - add support for Victrix Pro BFG Controller
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 160/877] wifi: rtw88: Fix the random "error beacon valid" messages for USB Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 162/877] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
` (723 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Erich Sartison, Dmitry Torokhov
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Erich Sartison <byt.es@mailbox.org>
commit 971fa7ea8621e123feb9c8d7dc61be1c656bd945 upstream.
The controller doesn't currently work via USB-cable.
Signed-off-by: Erich Sartison <byt.es@mailbox.org>
Link: https://patch.msgid.link/20260903103137.630170-1-byt.es@mailbox.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -256,6 +256,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0213, "Afterglow Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x021f, "Rock Candy Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x0246, "Rock Candy Gamepad for Xbox One 2015", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x024c, "PDP Victrix Pro BFG Wired Controller for Xbox", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a0, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a1, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a2, "PDP Wired Controller for Xbox One - Crimson Red", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 162/877] Input: xpad - add support for Azeron devices
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 161/877] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 163/877] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
` (722 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Roberts Kursitis, Dmitry Torokhov
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roberts Kursitis <roberts.kursitis@azeron.eu>
commit cba76c0f47af1a389d718c5bb69e75cbd67bba98 upstream.
Azeron controllers (Cyro, Cyborg, Classic/Compact, Cyro Lefty,
Cyborg II and Keyzen) present a standard Xbox 360 controller
interface, so they work with the existing xpad driver once their
USB IDs are added.
The 0x16d0 vendor ID is a shared block, but this is safe because
xpad only binds interfaces that match the Xbox 360 signature.
Tested with an Azeron Keyzen.
Signed-off-by: Roberts Kursitis <roberts.kursitis@azeron.eu>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906143040.162418-1-roberts.kursitis@azeron.eu
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -321,6 +321,12 @@ static const struct xpad_device {
{ 0x1689, 0xfd00, "Razer Onza Tournament Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfd01, "Razer Onza Classic Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfe00, "Razer Sabertooth", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1103, "Azeron Cyro", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x113c, "Azeron Cyborg", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1192, "Azeron Classic/Compact", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1212, "Azeron Cyro Lefty", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x12f7, "Azeron Cyborg II", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x13ea, "Azeron Keyzen", 0, XTYPE_XBOX360 },
{ 0x17ef, 0x6182, "Lenovo Legion Controller for Windows", 0, XTYPE_XBOX360 },
{ 0x1949, 0x041a, "Amazon Game Controller", 0, XTYPE_XBOX360 },
{ 0x1a86, 0xe310, "Legion Go S", 0, XTYPE_XBOX360 },
@@ -555,6 +561,7 @@ static const struct usb_device_id xpad_t
XPAD_XBOX360_VENDOR(0x15e4), /* Numark Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x162e), /* Joytech Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x1689), /* Razer Onza */
+ XPAD_XBOX360_VENDOR(0x16d0), /* Azeron controllers */
XPAD_XBOX360_VENDOR(0x17ef), /* Lenovo */
XPAD_XBOX360_VENDOR(0x1949), /* Amazon controllers */
XPAD_XBOX360_VENDOR(0x1a86), /* Nanjing Qinheng Microelectronics (WCH) */
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 163/877] Input: xpad - fix PDP Marvel Xbox 360 controller
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 162/877] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 164/877] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
` (721 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jeremy Nyberg, Dmitry Torokhov
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeremy Nyberg <slickstretch3.0@gmail.com>
commit 7bc369cb3d3f3656eb77285628ee264264d28ad4 upstream.
The PDP Marvel Xbox 360 controller with USB ID 0e6f:0147 is
incorrectly classified as an Xbox One controller.
With the current XTYPE_XBOXONE classification, the controller is
detected but produces no input, while its four player LEDs continue
blinking indefinitely.
Classify USB ID 0e6f:0147 as an Xbox 360 controller instead.
Tested on a PDP Marvel Xbox 360 controller with USB ID 0e6f:0147.
All inputs register correctly and the player LED indicates the
current player.
Fixes: c225370e01b8 ("Input: xpad - sync supported devices with 360Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Jeremy Nyberg <SlickStretch3.0@gmail.com>
Link: https://patch.msgid.link/20260910071627.236014-1-SlickStretch3.0@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -244,7 +244,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0139, "Afterglow Prismatic Wired Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x013a, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0146, "Rock Candy Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
- { 0x0e6f, 0x0147, "PDP Marvel Xbox One Controller", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x0147, "PDP Marvel Xbox 360 Controller", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x015c, "PDP Xbox One Arcade Stick", MAP_TRIGGERS_TO_BUTTONS, XTYPE_XBOXONE },
{ 0x0e6f, 0x015d, "PDP Mirror's Edge Official Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0161, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 164/877] ALSA: core: Fix potential UAF after asynchronous card release
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 163/877] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 165/877] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
` (720 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Farhad Alemi, Takashi Iwai
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit fd95e68df6fe66344161a1329cbe5e5805e7b704 upstream.
Usually a sound driver releases the resources assigned to the card via
snd_card_free(), and it synchronizes with the whole release procedure.
However, when the card is released asynchronously via
snd_card_free_when_closed() like USB-audio driver, the situation is
slightly different; although the snd_card_disconnect() call at the
disconnection guarantees that any newer accesses will be gated, the
in-flight tasks might be still accessing to the underlying card->dev
device even after the disconnection, which would cause a
use-after-free in the end, as reported by fuzzers.
For addressing the bug above, this patch takes the refcount of
card->dev at initialization of the card object, and releases at its
destructor. This assures the availability of the card->dev in its
whole lifecycle.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/CA+0ovChexj4TrZL_2iG_P0WBEbZc5+73GfB3DkciQi=R8pZOnA@mail.gmail.com
Closes: https://lore.kernel.org/CA+0ovCgQUQNN=Z1tJTouiCsDaXR5M-3-SQEGk-cpPXQkM5Xh+w@mail.gmail.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260912162150.455144-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/init.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/sound/core/init.c
+++ b/sound/core/init.c
@@ -309,7 +309,7 @@ static int snd_card_init(struct snd_card
kfree(card); /* manually free here, as no destructor called */
return err;
}
- card->dev = parent;
+ card->dev = get_device(parent);
card->number = idx;
WARN_ON(IS_MODULE(CONFIG_SND) && !module);
card->module = module;
@@ -593,6 +593,7 @@ static int snd_card_do_free(struct snd_c
dev_warn(card->dev, "unable to free card info\n");
/* Not fatal error */
}
+ put_device(card->dev);
if (card->release_completion)
complete(card->release_completion);
if (!managed)
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 165/877] ALSA: virtio: reset device before deleting virtqueues
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 164/877] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 166/877] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
` (719 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Takashi Iwai
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <oss.patchbox@gmail.com>
commit 6c05d00af307560e6a9f1631d6270d3df5aa2272 upstream.
virtsnd_remove() and virtsnd_freeze() delete the virtqueues before
resetting the device. del_vqs() frees the vring backing, but does not
provide a generic device quiesce operation. In particular, modern
virtio-pci keeps enabled queues active until the device is reset.
Reset the device before deleting the virtqueues so it can no longer
access the vring memory when that memory is released. This also covers
probe failures after DRIVER_OK, which unwind through virtsnd_remove().
Fixes: de3a9980d8c3 ("ALSA: virtio: add virtio sound driver")
Fixes: 575483e90a32 ("ALSA: virtio: introduce device suspend/resume support")
Cc: stable@vger.kernel.org
Signed-off-by: Yuho Choi <oss.patchbox@gmail.com>
Link: https://patch.msgid.link/20260911031121.1542502-1-oss.patchbox@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/virtio/virtio_card.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/sound/virtio/virtio_card.c
+++ b/sound/virtio/virtio_card.c
@@ -359,8 +359,8 @@ static void virtsnd_remove(struct virtio
if (snd->card)
snd_card_free(snd->card);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; snd->substreams && i < snd->nsubstreams; ++i) {
struct virtio_pcm_substream *vss = &snd->substreams[i];
@@ -388,8 +388,8 @@ static int virtsnd_freeze(struct virtio_
virtsnd_disable_event_vq(snd);
virtsnd_ctl_msg_cancel_all(snd);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; i < snd->nsubstreams; ++i)
cancel_work_sync(&snd->substreams[i].elapsed_period);
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 166/877] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 165/877] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 167/877] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
` (718 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Pierre-Louis Bossart,
Mark Brown
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 03a5699a0a04309c597683967aaaf25d1e555ea2 upstream.
stream_config is not initialized before being passed to
sdw_stream_add_slave(). The type field may contain garbage and is
later copied to stream->type by sdw_config_stream().
Zero-initialize stream_config so type defaults to SDW_STREAM_PCM.
While at it, use snd_sdw_params_to_config() helper instead of
open-coding the same logic.
Fixes: 63a511284c9e ("ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260914104712.379574-1-yijiangshan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/codecs/rt712-sdca-dmic.c | 14 +++++---------
1 file changed, 5 insertions(+), 9 deletions(-)
--- a/sound/soc/codecs/rt712-sdca-dmic.c
+++ b/sound/soc/codecs/rt712-sdca-dmic.c
@@ -14,6 +14,7 @@
#include <sound/core.h>
#include <sound/pcm.h>
#include <sound/pcm_params.h>
+#include <sound/sdw.h>
#include <sound/tlv.h>
#include "rt712-sdca.h"
#include "rt712-sdca-dmic.h"
@@ -641,10 +642,10 @@ static int rt712_sdca_dmic_hw_params(str
{
struct snd_soc_component *component = dai->component;
struct rt712_sdca_dmic_priv *rt712 = snd_soc_component_get_drvdata(component);
- struct sdw_stream_config stream_config;
+ struct sdw_stream_config stream_config = {0};
struct sdw_port_config port_config;
struct sdw_stream_runtime *sdw_stream;
- int retval, num_channels;
+ int retval;
unsigned int sampling_rate;
dev_dbg(dai->dev, "%s %s", __func__, dai->name);
@@ -656,13 +657,8 @@ static int rt712_sdca_dmic_hw_params(str
if (!rt712->slave)
return -EINVAL;
- stream_config.frame_rate = params_rate(params);
- stream_config.ch_count = params_channels(params);
- stream_config.bps = snd_pcm_format_width(params_format(params));
- stream_config.direction = SDW_DATA_DIR_TX;
-
- num_channels = params_channels(params);
- port_config.ch_mask = GENMASK(num_channels - 1, 0);
+ /* SoundWire specific configuration */
+ snd_sdw_params_to_config(substream, params, &stream_config, &port_config);
port_config.num = 2;
retval = sdw_stream_add_slave(rt712->slave, &stream_config,
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 167/877] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 166/877] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:17 ` [PATCH 6.12 168/877] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
` (717 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roland Waltersson, Damien Le Moal,
Niklas Cassel
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
commit 82e47533221d4746947b74d2e79a478c36c6433a upstream.
A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for
JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board.
The failure is seen as soon as the ahci driver is probed, and booting with
iommu=off does not solve the problem.
Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0'
for HBAs that do not support 64-bit addressing.
For HBAs that do support 64-bit addressing, the registers are read write,
with a reset value that is Implementation Specific.
When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit
addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64.
Thus, in this case, we need to explicitly clear the registers to 0.
Fixes: 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585")
Fixes: c7a42156d99b ("ahci: disable 64bit dma on sb600")
Cc: stable@vger.kernel.org
Reported-by: Roland Waltersson <roland.waltersson@netinsight.net>
Closes: https://lore.kernel.org/linux-ide/IA0PR17MB668730A4ECCD65F7A1DC3EDC9EB62@IA0PR17MB6687.namprd17.prod.outlook.com/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260904134310.1465051-2-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- a/drivers/ata/libahci.c
+++ b/drivers/ata/libahci.c
@@ -748,15 +748,28 @@ void ahci_start_fis_rx(struct ata_port *
struct ahci_port_priv *pp = ap->private_data;
u32 tmp;
- /* set FIS registers */
+ /*
+ * On HBAs that only support 32-bit addressing PxCLBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxCLBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->cmd_slot_dma >> 16) >> 16,
port_mmio + PORT_LST_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_LST_ADDR_HI);
writel(pp->cmd_slot_dma & 0xffffffff, port_mmio + PORT_LST_ADDR);
+ /*
+ * On HBAs that only support 32-bit addressing PxFBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxFBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->rx_fis_dma >> 16) >> 16,
port_mmio + PORT_FIS_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_FIS_ADDR_HI);
writel(pp->rx_fis_dma & 0xffffffff, port_mmio + PORT_FIS_ADDR);
/* enable FIS reception */
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 168/877] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 167/877] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
@ 2026-09-30 15:17 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 169/877] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
` (716 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:17 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Damien Le Moal,
Niklas Cassel
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 0d1cb83337f13af082afb68b28d3fdfe29cde7fb upstream.
of_find_device_by_node() takes a reference on the port platform device,
which is only used to look up its port regulator and is never released,
neither on success nor on the error paths. Drop the reference with
put_device() once the regulator has been obtained, which covers both the
success and error paths.
Fixes: c7d7ddee7e24 ("ata: libahci: Allow using multiple regulators")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://lore.kernel.org/r/20260915065933.1733061-1-vulab@iscas.ac.cn
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci_platform.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/ata/libahci_platform.c
+++ b/drivers/ata/libahci_platform.c
@@ -623,10 +623,10 @@ struct ahci_host_priv *ahci_platform_get
of_platform_device_create(child, NULL, NULL);
port_dev = of_find_device_by_node(child);
-
if (port_dev) {
rc = ahci_platform_get_regulator(hpriv, port,
&port_dev->dev);
+ put_device(&port_dev->dev);
if (rc == -EPROBE_DEFER)
goto err_out;
}
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 169/877] cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-30 15:17 ` [PATCH 6.12 168/877] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 170/877] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
` (715 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Paulo Alcantara
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 717e0a25036b6c92cecace30913b2d874a4c22b8 upstream.
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes: f591062bdbf4 ("cifs: handle servers that still advertise multichannel after disabling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -188,18 +188,19 @@ cifs_chan_skip_or_disable(struct cifs_se
spin_unlock(&ses->chan_lock);
/*
- * the above reference of server by channel
- * needs to be dropped without holding chan_lock
- * as cifs_put_tcp_session takes a higher lock
- * i.e. cifs_tcp_ses_lock
+ * signal the channel and its primary server to
+ * reconnect before dropping the above reference of
+ * server by channel, which is done without holding
+ * chan_lock as cifs_put_tcp_session takes a higher
+ * lock i.e. cifs_tcp_ses_lock
*/
- cifs_put_tcp_session(server, from_reconnect);
-
cifs_signal_cifsd_for_reconnect(server, false);
/* mark primary server as needing reconnect */
pserver = server->primary_server;
cifs_signal_cifsd_for_reconnect(pserver, false);
+
+ cifs_put_tcp_session(server, from_reconnect);
skip_terminate:
return -EHOSTDOWN;
}
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 170/877] exec: Cleanup POSIX timers right after de_thread()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 169/877] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 171/877] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
` (714 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Thomas Gleixner,
Kijo Park, Oleg Nesterov, Frederic Weisbecker
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hyunwoo Kim <imv4bel@gmail.com>
commit acb03d3881818581052924a9bbbe92b8741ed448 upstream.
A per-thread CPU timer holds a reference to the PID of the thread it is
attached to and, while it is armed, its node is queued in that thread's
posix_cputimers. The task is looked up by that PID.
When a non-leader thread exec()s, de_thread() changes which task owns
that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL,
but the node is still queued on tsk, which is alive. timer_lock_sighand()
takes a failed lookup to mean that the node is already dequeued, so it
has nothing to undo.
begin_new_exec() calls posix_cpu_timers_exit(me) right after
exec_task_namespaces() and that removes the leftover node, so the state
normally stays invisible. But bprm->point_of_no_return is set before
de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or
exec_task_namespaces() fails, the task dies before it gets there.
exit_itimers() then frees the k_itimer while its node is still queued,
and reaping tsk later erases that freed node from the rbtree.
In short:
the non-leader thread B the parent
timer_create(CLOCK_THREAD_CPUTIME_ID)
timer_settime()
arm_timer() // the node is queued on B
execve()
de_thread(B)
exchange_tids(B, leader) // B's PID now belongs to the leader
release_task(leader)
__exit_signal(leader)
posix_cpu_timers_exit(leader) // cleans leader's queue, not B's
__unhash_process(leader) // that PID has no task anymore
exec_mmap()
mmap_read_lock_killable(old_mm)
kill(B, SIGKILL)
// -EINTR
get_signal()
do_exit()
exit_itimers()
posix_timer_delete()
posix_cpu_timer_del()
posix_timer_unhash_and_free() // freed while still queued
wait4()
release_task(B)
posix_cpu_timers_exit(B)
cleanup_timerqueue()
timerqueue_del() // use-after-free
Move the POSIX timer cleanup right after de_thread() before any of the
later failure conditions brings the task into do_exit().
[ tglx: Move the cleanup right after de_thread() ]
Fixes: 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to a pid not a task")
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/ao7Q8miiuLAPVnWv@v4bel
Link: https://patch.msgid.link/20260911090541.627712075@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/exec.c | 29 +++++++++++++++++++++--------
1 file changed, 21 insertions(+), 8 deletions(-)
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1217,6 +1217,17 @@ void __set_task_comm(struct task_struct
perf_event_comm(tsk, exec);
}
+static void posixtimer_exec(struct task_struct *me)
+{
+#ifdef CONFIG_POSIX_TIMERS
+ spin_lock_irq(&me->sighand->siglock);
+ posix_cpu_timers_exit(me);
+ spin_unlock_irq(&me->sighand->siglock);
+ exit_itimers(me);
+ flush_itimer_signals();
+#endif
+}
+
/*
* Calling this is the point of no return. None of the failures will be
* seen by userspace since either the process is already taking a fatal
@@ -1250,6 +1261,16 @@ int begin_new_exec(struct linux_binprm *
retval = de_thread(me);
if (retval)
goto out;
+
+ /*
+ * This must be done here to ensure that POSIX CPU timers which were
+ * armed on the current task are dequeued from me::posix_cputimers.
+ * Otherwise in case of a TID switch the deletion of the related POSIX
+ * timer would not remove an enqueued timer because the TID lookup
+ * of the old TID fails.
+ */
+ posixtimer_exec(me);
+
/* see the comment in check_unsafe_exec() */
current->fs->in_exec = 0;
/*
@@ -1304,14 +1325,6 @@ int begin_new_exec(struct linux_binprm *
if (retval)
goto out_unlock;
-#ifdef CONFIG_POSIX_TIMERS
- spin_lock_irq(&me->sighand->siglock);
- posix_cpu_timers_exit(me);
- spin_unlock_irq(&me->sighand->siglock);
- exit_itimers(me);
- flush_itimer_signals();
-#endif
-
/*
* Make the signal table private.
*/
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 171/877] rds: ib: use rds_conn_drop() on protocol version mismatch
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 170/877] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 172/877] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
` (713 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI,
Allison Henderson, Aohan Mei, Jakub Kicinski
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit f97d8c7bab7843631206a114986c9059da03efeb upstream.
rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with
conn->c_cm_lock held. When the peer negotiates a protocol version
older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls
rds_conn_destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush_work()es the
shutdown work cp_down_w.
That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,
DISCONNECTED) use rds_conn_drop(), which marks the connection
RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Fixes: f147dd9ecabf ("RDS/IB: Disallow connections less than RDS 3.1")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Reviewed-by: Allison Henderson <achender@kernel.org>
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Link: https://patch.msgid.link/20260911073436.3542080-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_cm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -115,7 +115,7 @@ void rds_ib_cm_connect_complete(struct r
&conn->c_laddr, &conn->c_faddr,
RDS_PROTOCOL_MAJOR(conn->c_version),
RDS_PROTOCOL_MINOR(conn->c_version));
- rds_conn_destroy(conn);
+ rds_conn_drop(conn);
return;
}
}
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 172/877] x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 171/877] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 173/877] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
` (712 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chang S. Bae, Borislav Petkov (AMD),
Dave Hansen
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chang S. Bae <chang.seok.bae@intel.com>
commit e7d3e2f46dd5a69046e6d95a0f189155a5516b93 upstream.
Microcode updates can usually jump revisions. However, there is an erratum on
Granite Rapids systems. If they "jump over" revision 0x1000405, they result in
an #MC. Avoid it.
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916225939.1144524-1-chang.seok.bae@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kernel/cpu/microcode/intel.c | 26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
--- a/arch/x86/kernel/cpu/microcode/intel.c
+++ b/arch/x86/kernel/cpu/microcode/intel.c
@@ -257,6 +257,26 @@ static void save_microcode_patch(struct
pr_err("Unable to allocate microcode memory size: %u\n", size);
}
+static bool revision_is_safe(struct cpu_signature *sig, u32 rev)
+{
+ u32 vfm = IFM(x86_family(sig->sig), x86_model(sig->sig));
+
+ /*
+ * Erratum GNR98 can cause #MCs if "jumping over" revision 0x1000405.
+ * Avoid the jumps.
+ */
+ if (vfm == INTEL_GRANITERAPIDS_X &&
+ x86_stepping(sig->sig) == 1 &&
+ sig->pf & 0x95 &&
+ sig->rev < 0x1000405 &&
+ rev > 0x1000405) {
+ pr_err_once("Erratum GNR98: skipping revision 0x%x.\n", rev);
+ return false;
+ }
+
+ return true;
+}
+
/* Scan blob for microcode matching the boot CPUs family, model, stepping */
static __init struct microcode_intel *scan_microcode(void *data, size_t size,
struct ucode_cpu_info *uci,
@@ -278,6 +298,9 @@ static __init struct microcode_intel *sc
if (!intel_find_matching_signature(data, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header->rev))
+ continue;
+
/*
* For saving the early microcode, find the matching revision which
* was loaded on the BSP.
@@ -540,6 +563,9 @@ static enum ucode_state parse_microcode_
if (!intel_find_matching_signature(mc, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header.rev))
+ continue;
+
is_safe = ucode_validate_minrev(&mc_header);
if (force_minrev && !is_safe)
continue;
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 173/877] tcp: exclude old ACKs from tcp fast path
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 172/877] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 174/877] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
` (711 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amit Klein, Tamir Shahar,
Inbal Schussheim, Eric Dumazet, Paolo Abeni
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
commit f81e6c3fb06327bc49cdd6e559845293ba06a704 upstream.
Exclude old ACKs before SND.UNA from the tcp fast path
as well as ACKs after SND.NXT.
Such ACKs will fall through to the slow path, where tcp_ack()
performs the appropriate validation and challenge ACK handling
according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not
accept ACK of bytes we never sent").
This prevents old ACKs from being accepted
or modifying connection state as part of the fast path before
appropriate ACK validation is applied.
In particular, this prevents payload carried by a segment with
an excessively old ACK from advancing RCV.NXT before the ACK
is rejected.
Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"")
Reported-by: Amit Klein <amit.klein@mail.huji.ac.il>
Reported-by: Tamir Shahar <tamir.shahar1@mail.huji.ac.il>
Reported-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914090408.1435080-2-inbal.lipshtat@mail.huji.ac.il
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/tcp_input.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -6138,6 +6138,7 @@ reset:
* or pure receivers (this means either the sequence number or the ack
* value must stay constant)
* - Unexpected TCP option.
+ * - ACK sequence number is outside [SND.UNA, SND.NXT].
*
* When these conditions are not satisfied it drops into a standard
* receive procedure patterned after RFC793 to handle all cases.
@@ -6186,7 +6187,7 @@ void tcp_rcv_established(struct sock *sk
if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags &&
TCP_SKB_CB(skb)->seq == tp->rcv_nxt &&
- !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) {
+ between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) {
int tcp_header_len = tp->tcp_header_len;
/* Timestamp header prediction: tcp_header_len
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 174/877] RDMA/ucma: Serialize join and leave on copy_to_user failure
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 173/877] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 175/877] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
` (710 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+a6ffe86390c8a6afc818,
Quanye Yang, Leon Romanovsky
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
commit 662ade4de9ff5eceb0820a9f8e9fac70ba6a815b upstream.
rdma_join_multicast() queues RoCE work that later reads the ucma_multicast
through event->param.ud.private_data, then list_add()s the CMA multicast
at the head of id_priv->mc_list. rdma_leave_multicast() matches only by
sockaddr and destroys the first hit.
ucma_process_join() used to drop ctx->mutex after a successful join and
retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls
with the same address can therefore insert a second CMA entry before the
first thread's leave. leave then cancels the newer work and the older
worker still dereferences the ucma_multicast that the first thread frees.
Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and,
on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.
Do not leave if join itself failed: that path never published this address
on mc_list, and a leave-by-addr would destroy an earlier successful join.
Reported-by: syzbot+a6ffe86390c8a6afc818@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a6ffe86390c8a6afc818
Fixes: fe454dc31e84 ("RDMA/ucma: Fix use-after-free bug in ucma_create_uevent")
Cc: stable@vger.kernel.org
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260831-rdma-ucma-mc-uaf-v1-1-b8eeb7046aff@proton.me
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/ucma.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/drivers/infiniband/core/ucma.c
+++ b/drivers/infiniband/core/ucma.c
@@ -1487,9 +1487,10 @@ static ssize_t ucma_process_join(struct
mutex_lock(&ctx->mutex);
ret = rdma_join_multicast(ctx->cm_id, (struct sockaddr *)&mc->addr,
join_state, mc);
- mutex_unlock(&ctx->mutex);
- if (ret)
+ if (ret) {
+ mutex_unlock(&ctx->mutex);
goto err_xa_erase;
+ }
resp.id = mc->id;
if (copy_to_user(u64_to_user_ptr(cmd->response),
@@ -1497,6 +1498,7 @@ static ssize_t ucma_process_join(struct
ret = -EFAULT;
goto err_leave_multicast;
}
+ mutex_unlock(&ctx->mutex);
xa_store(&multicast_table, mc->id, mc, 0);
@@ -1504,7 +1506,6 @@ static ssize_t ucma_process_join(struct
return 0;
err_leave_multicast:
- mutex_lock(&ctx->mutex);
rdma_leave_multicast(ctx->cm_id, (struct sockaddr *) &mc->addr);
mutex_unlock(&ctx->mutex);
ucma_cleanup_mc_events(mc);
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 175/877] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 174/877] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 176/877] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
` (709 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+bd317784d628820741b5,
Jeffin Philip, Leon Romanovsky
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeffin Philip <jeffinphilip14@gmail.com>
commit 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 upstream.
iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
making it accessible to global list where another CPU can kref_get()
on nlmsg_request causing a refcount "addition on 0" bug. Fix this
by initializing kref _before_ list_add_tail() so refcount for
nlmsg_request can be incremented/decremented normally. In addition,
also initialize every field before list_add_tail().
Reported-by: syzbot+bd317784d628820741b5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bd317784d628820741b5
Fixes: 30dc5e63d6a5 ("RDMA/core: Add support for iWARP Port Mapper user space service")
Cc: stable@vger.kernel.org
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Link: https://patch.msgid.link/20260904131437.12917-1-jeffinphilip14@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/iwpm_util.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/core/iwpm_util.c
+++ b/drivers/infiniband/core/iwpm_util.c
@@ -314,10 +314,6 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
if (!nlmsg_request)
return NULL;
- spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
- list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
- spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
-
kref_init(&nlmsg_request->kref);
kref_get(&nlmsg_request->kref);
nlmsg_request->nlmsg_seq = nlmsg_seq;
@@ -326,6 +322,11 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
nlmsg_request->err_code = 0;
sema_init(&nlmsg_request->sem, 1);
down(&nlmsg_request->sem);
+
+ spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
+ list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
+ spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
+
return nlmsg_request;
}
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 176/877] openvswitch: avoid reallocating confirmed conntrack labels
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 175/877] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 177/877] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
` (708 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ilya Maximets,
Aaron Conole, Jakub Kicinski
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream.
ovs_ct_get_conn_labels() adds the labels extension when a conntrack
entry does not have one. Confirmed conntracks can be read locklessly,
so adding an extension may reallocate and free the extension block
while another CPU accesses it.
Only add the extension for unconfirmed conntracks. A confirmed
conntrack without labels now fails the caller's label operation instead
of reallocating its extension storage.
Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -366,7 +366,7 @@ static struct nf_conn_labels *ovs_ct_get
struct nf_conn_labels *cl;
cl = nf_ct_labels_find(ct);
- if (!cl) {
+ if (!cl && !nf_ct_is_confirmed(ct)) {
nf_ct_labels_ext_add(ct);
cl = nf_ct_labels_find(ct);
}
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 177/877] net: xfrm: reject unrepresentable espintcp transport headers
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 176/877] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 178/877] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
` (707 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Wyatt Feng, Ren Wei,
Steffen Klassert
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wyatt Feng <wf.kernel.dev@gmail.com>
commit 96f01b53c2d05e003b040892256de54a586e8529 upstream.
ESP-in-TCP can hand xfrm packets whose transport header offset no longer
fits after the stream parser trims the TCP envelope. The plain transport
header reset truncates that offset and triggers the skb warning path.
Use the careful transport-header helper and drop the skb through the
existing XFRM error path when the offset cannot be represented.
Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:GPT-5.4
Signed-off-by: Wyatt Feng <wf.kernel.dev@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/espintcp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/net/xfrm/espintcp.c
+++ b/net/xfrm/espintcp.c
@@ -33,7 +33,11 @@ static void handle_esp(struct sk_buff *s
{
struct tcp_skb_cb *tcp_cb = (struct tcp_skb_cb *)skb->cb;
- skb_reset_transport_header(skb);
+ if (!skb_reset_transport_header_careful(skb)) {
+ XFRM_INC_STATS(sock_net(sk), LINUX_MIB_XFRMINERROR);
+ kfree_skb(skb);
+ return;
+ }
/* restore IP CB, we need at least IP6CB->nhoff */
memmove(skb->cb, &tcp_cb->header, sizeof(tcp_cb->header));
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 178/877] HID: logitech-hidpp: fix race condition when accessing stale stack pointer
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 177/877] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 179/877] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
` (706 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benoît Sevens, Jiri Kosina,
Lee Jones
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benoît Sevens <bsevens@google.com>
commit e2aaf2d3ad92ac4a8afa6b69ad4c38e7747d3d6e upstream.
The driver uses hidpp->send_receive_buf to point to a stack-allocated
buffer in the synchronous command path (__do_hidpp_send_message_sync).
However, this pointer is not cleared when the function returns.
If an event is processed (e.g. by a different thread) while the
send_mutex is held by a new command, but before that command has
updated send_receive_buf, the handler (hidpp_raw_hidpp_event) will
observe that the mutex is locked and dereference the stale pointer.
This results in an out-of-bounds access on a different thread's kernel
stack (or a NULL pointer dereference on the very first command).
Fix this by:
1. Clearing hidpp->send_receive_buf to NULL before releasing the mutex
in the synchronous command path.
2. Moving the assignment of the local 'question' and 'answer' pointers
inside the mutex_is_locked() block in the handler, and adding
a NULL check before dereferencing.
Signed-off-by: Benoît Sevens <bsevens@google.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Cc: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-logitech-hidpp.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
--- a/drivers/hid/hid-logitech-hidpp.c
+++ b/drivers/hid/hid-logitech-hidpp.c
@@ -305,21 +305,22 @@ static int __do_hidpp_send_message_sync(
if (ret) {
dbg_hid("__hidpp_send_report returned err: %d\n", ret);
memset(response, 0, sizeof(struct hidpp_report));
- return ret;
+ goto out;
}
if (!wait_event_timeout(hidpp->wait, hidpp->answer_available,
5*HZ)) {
dbg_hid("%s:timeout waiting for response\n", __func__);
memset(response, 0, sizeof(struct hidpp_report));
- return -ETIMEDOUT;
+ ret = -ETIMEDOUT;
+ goto out;
}
if (response->report_id == REPORT_ID_HIDPP_SHORT &&
response->rap.sub_id == HIDPP_ERROR) {
ret = response->rap.params[1];
dbg_hid("%s:got hidpp error %02X\n", __func__, ret);
- return ret;
+ goto out;
}
if ((response->report_id == REPORT_ID_HIDPP_LONG ||
@@ -327,10 +328,14 @@ static int __do_hidpp_send_message_sync(
response->fap.feature_index == HIDPP20_ERROR) {
ret = response->fap.params[1];
dbg_hid("%s:got hidpp 2.0 error %02X\n", __func__, ret);
- return ret;
+ goto out;
}
- return 0;
+ ret = 0;
+
+out:
+ hidpp->send_receive_buf = NULL;
+ return ret;
}
/*
@@ -3866,8 +3871,7 @@ static int hidpp_input_configured(struct
static int hidpp_raw_hidpp_event(struct hidpp_device *hidpp, u8 *data,
int size)
{
- struct hidpp_report *question = hidpp->send_receive_buf;
- struct hidpp_report *answer = hidpp->send_receive_buf;
+ struct hidpp_report *question, *answer;
struct hidpp_report *report = (struct hidpp_report *)data;
int ret;
int last_online;
@@ -3877,6 +3881,12 @@ static int hidpp_raw_hidpp_event(struct
* previously sent command.
*/
if (unlikely(mutex_is_locked(&hidpp->send_mutex))) {
+ question = hidpp->send_receive_buf;
+ answer = hidpp->send_receive_buf;
+
+ if (!question)
+ return 0;
+
/*
* Check for a correct hidpp20 answer or the corresponding
* error
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 179/877] kselftest/arm64: Fix size of thread_data values for pthread_join()
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 178/877] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 180/877] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
` (705 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thomas Huth, Will Deacon
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Huth <thuth@redhat.com>
commit 3d1ba5cbfb622025690c218d8f20da92a9ecb383 upstream.
pthread_join() stores the thread's return value (a "void *", i.e.
8 bytes on 64 bit computers) into the address that is passed as second
parameter. However, the entries of thread_data are only normal "int"s,
i.e. only 4 bytes. The additional 4 bytes of the return value clobber
whatever is adjacent on the stack, i.e. other members of the thread_data
array (which will be re-written in the next iteration of the for-loop,
so that nobody noticed this problem), or another other local variable
on the stack for the last iteration. Use "intptr_t" to declare the
thread_data array entries with the correct size.
Fixes: 29f080881601c ("kselftest/arm64: check GCR_EL1 after context switch")
Cc: stable@vger.kernel.org
Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
+++ b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
@@ -69,7 +69,7 @@ fail:
int execute_test(pid_t pid)
{
pthread_t thread_id[MAX_THREADS];
- int thread_data[MAX_THREADS];
+ intptr_t thread_data[MAX_THREADS];
for (int i = 0; i < MAX_THREADS; i++)
pthread_create(&thread_id[i], NULL,
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 180/877] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 179/877] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 181/877] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
` (704 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bradley Morgan, Vladimir Murzin,
Mark Rutland, Will Deacon
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bradley Morgan <include@grrlz.net>
commit 955d86e5f3b95b731991fdb84966c50b16314629 upstream.
swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub
vectors with an hvc, but never passes the arguments. x0 is not set to
HVC_SET_VECTORS and x1 is not set to the vector address, so the stub
dispatch falls through and returns without writing vbar_el2. EL2 is
left pointing at the trans_pgd copy of the vectors, a page that
swsusp_free() releases right after resume.
Set the arguments up the same way __hyp_set_vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from
hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
Fixes: 788bfdd97434 ("arm64: trans_pgd: hibernate: Add trans_pgd_copy_el2_vectors")
Cc: stable@vger.kernel.org
Signed-off-by: Bradley Morgan <include@grrlz.net>
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Tested-by: Vladimir Murzin <vladimir.murzin@arm.com>
Acked-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kernel/hibernate-asm.S | 2 ++
1 file changed, 2 insertions(+)
--- a/arch/arm64/kernel/hibernate-asm.S
+++ b/arch/arm64/kernel/hibernate-asm.S
@@ -89,6 +89,8 @@ alternative_insn "dc cvau, x4", "dc civ
isb
cbz x24, 3f /* Do we need to re-initialise EL2? */
+ mov x1, x24
+ mov x0, #HVC_SET_VECTORS
hvc #0
3: ret
SYM_CODE_END(swsusp_arch_suspend_exit)
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 181/877] arm64: dts: renesas: r8a779f0: Set UFS lane count
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 180/877] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 182/877] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
` (703 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Koichiro Den, Geert Uytterhoeven
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
commit 8dc2615d5702059b2b71fca6f93c0d7d10ae54cb upstream.
Since commit e72323f3b09f ("scsi: ufs: core: Configure only active lanes
during link"), the following error is observed on R-Car S4:
ufshcd-renesas e6860000.ufs: Tx lane mismatch [config,reported] [2,1]
ufshcd-renesas e6860000.ufs: link startup failed -67
ufshcd-renesas e6860000.ufs: error -ENOLINK: Initialization failed with error -67
ufshcd-renesas e6860000.ufs: probe with driver ufshcd-renesas failed with error -67
R-Car S4 has one UFS lane per direction, as described in section 152.1
of its hardware manual. Without lanes-per-direction, the UFS platform
driver defaults to two lanes.
Previously, the core used PA_CONNECTEDRXDATALANES and
PA_CONNECTEDTXDATALANES to configure the link without checking them
against lanes-per-direction, so the missing property did not prevent
initialization.
Explicitly set lanes-per-direction to 1, now that the validation is in
place.
Fixes: 5235d551779d ("arm64: dts: renesas: r8a779f0: Add UFS node")
Cc: stable@vger.kernel.org # 7.2+
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260911073058.253000-1-den@valinux.co.jp
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
1 file changed, 1 insertion(+)
--- a/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
+++ b/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
@@ -876,6 +876,7 @@
clocks = <&cpg CPG_MOD 1514>, <&ufs30_clk>;
clock-names = "fck", "ref_clk";
freq-table-hz = <200000000 200000000>, <38400000 38400000>;
+ lanes-per-direction = <1>;
power-domains = <&sysc R8A779F0_PD_ALWAYS_ON>;
resets = <&cpg 1514>;
status = "disabled";
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 182/877] arm64: percpu: Fix this_cpu_write() casting
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 181/877] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 183/877] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
` (702 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Laight, Mark Rutland,
Jinjie Ruan, Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi, Lorenzo Stoakes (ARM)
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 885bff055a0f251a51a0d4fd4f0a7b525582a3de upstream.
The arm64 implementation of this_cpu_write() casts 'val' to unsigned
long. This is necessary to handle cases where 'val' is a pointer type,
and to avoid spurious compiler warnings for the (unreachable!) cases
where the pointer type would be cast to a smaller integer type.
Unfortunately, the cast is applied to 'val' rather than '(val)', which
won't always generate the expected value when 'val' is an expression.
For example, for this_cpu_write(pcp, zero - 1), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* 'zero - 1' ===> (u32) 0xffffffff
* '(unsigned long)zero - 1' ===> (u64) 0xffffffffffffffff
* '(unsigned long)(zero - 1)' ===> (u64) 0x00000000ffffffff
Fix this by adding brackets around 'val'.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Reported-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: David Laight <david.laight.linux@gmail.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -172,13 +172,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_read_64, pcp)
#define this_cpu_write_1(pcp, val) \
- _pcp_protect(__percpu_write_8, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_8, pcp, (unsigned long)(val))
#define this_cpu_write_2(pcp, val) \
- _pcp_protect(__percpu_write_16, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_16, pcp, (unsigned long)(val))
#define this_cpu_write_4(pcp, val) \
- _pcp_protect(__percpu_write_32, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_32, pcp, (unsigned long)(val))
#define this_cpu_write_8(pcp, val) \
- _pcp_protect(__percpu_write_64, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_64, pcp, (unsigned long)(val))
#define this_cpu_add_1(pcp, val) \
_pcp_protect(__percpu_add_case_8, pcp, val)
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 183/877] arm64: percpu: Fix this_cpu_and() mask generation
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 182/877] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 184/877] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
` (701 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 44274c657256b4911de82f8104e9e22f054cf742 upstream.
The arm64 implementation of this_cpu_and(pcp, val) is built in terms of
ANDNOT operations, which requires the 'val' argument to be bitwise
negated. The bitwise negation is not implemented correctly, with two
bugs described below.
(1) The bitwise negation is performed as '~val' rather than '~(val)'.
This won't always generate the expected value when 'val' is an
expression.
For example, for this_cpu_and(pcp, 1 - 1):
* 'val' is '1 - 1' ===> (int) 0x00000000
* '~val' is '~1 - 1' ===> (int) 0xfffffffd
* '~(val)' is '~(1 - 1)' ===> (int) 0xffffffff
... and thus bit[1] of 'pcp' would be preserved unexpectedly by the
ANDNOT operation.
(2) The bitwise negation is performed on 'val' before it has been cast
to (at least) the width of 'pcp'. This won't always generate the
expected value for the upper bits.
For example, for this_cpu_and(pcp, zero), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* '~(zero)' ===> (u32) 0xffffffff
* '(u64)~(zero)' ===> (u64) 0x00000000ffffffff
* '~((u64)(zero))' ===> (u64) 0xffffffffffffffff
... and thus bits[63:32] of 'pcp' would be preserved unexpectedly by
the ANDNOT operation.
Fix these issues by adding brackets around 'val', and by casting 'val'
to an appropriately-sized type before bitwise negation.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -199,13 +199,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_add_return_case_64, pcp, val)
#define this_cpu_and_1(pcp, val) \
- _pcp_protect(__percpu_andnot_case_8, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_8, pcp, ~(u8)(val))
#define this_cpu_and_2(pcp, val) \
- _pcp_protect(__percpu_andnot_case_16, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_16, pcp, ~(u16)(val))
#define this_cpu_and_4(pcp, val) \
- _pcp_protect(__percpu_andnot_case_32, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_32, pcp, ~(u32)(val))
#define this_cpu_and_8(pcp, val) \
- _pcp_protect(__percpu_andnot_case_64, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_64, pcp, ~(u64)(val))
#define this_cpu_or_1(pcp, val) \
_pcp_protect(__percpu_or_case_8, pcp, val)
^ permalink raw reply [flat|nested] 922+ messages in thread
* [PATCH 6.12 184/877] Bluetooth: btusb: fix NXP IW610 composite device handling
2026-09-30 15:15 [PATCH 6.12 000/877] 6.12.112-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-30 15:18 ` [PATCH 6.12 183/877] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
@ 2026-09-30 15:18 ` Greg Kroah-Hartman
2026-09-30 15:18 ` [PATCH 6.12 185/877] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
` (700 subsequent siblings)
884 siblings, 0 replies; 922+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 15:18 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolas Thibert,
Luiz Augusto von Dentz
6.12-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Thibert <nithibert@gmail.com>
commit 2b50adefed9808a56d84d1de803cad882cc787fa upstream.
The NXP IW610 module exposes itself as a composite USB device
(0471:0215) with three interfaces: two real Bluetooth HCI interfaces
(class 0xe0) and one vendor-specific WiFi interface (class 0xff) used
by mwifiex-nxp.
The composite device's whole USB descriptor reports class 0xe0/01/01
(Bluetooth), so btusb_table's generic USB_DEVICE_INFO(0xe0, 0x01, 0x01)
entry matches every interface, not just the t