<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/include, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/include?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/include?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-10-04T15:39:26Z</updated>
<entry>
<title>Merge tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:39:26Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:39:26Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=942e4a0e46bfd0efd3f87f70bf186c54aaaeb138'/>
<id>urn:sha1:942e4a0e46bfd0efd3f87f70bf186c54aaaeb138</id>
<content type='text'>
Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
</content>
</entry>
<entry>
<title>Merge tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:35:29Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:35:29Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=a27611f8994c9a4772156432badb533af33fd32d'/>
<id>urn:sha1:a27611f8994c9a4772156432badb533af33fd32d</id>
<content type='text'>
Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
</content>
</entry>
<entry>
<title>Merge tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty</title>
<updated>2026-10-03T15:59:37Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-03T15:59:37Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=9a32e0754d637c1d386a533ae36e41c8f4be8b10'/>
<id>urn:sha1:9a32e0754d637c1d386a533ae36e41c8f4be8b10</id>
<content type='text'>
Pull tty/serial fixes from Greg KH:
 "Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major
  here, just lots of small fixes for reported issues, some of them very
  long-standing:

   - tty hangup fixes that have been there since the BKL days and kept
     tripping people up over time.

   - vt selection bugfix

   - other vt bugfixes (memory leaks and screen update fixes)

   - n_gsm bugfix

   - qcom-geni serial driver bugfix

   - 8250 serial driver bugfixes

   - other tiny serial driver fixes

  All of these have been in linux-next, the last few only a few days but
  testing here seems solid (this pull request was generated on that
  tree)"

* tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (37 commits)
  tty: add missing driver flag kernel-doc colon
  vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()
  vt: skip screen update for DEC alignment test on backgroup consoles
  vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF
  serial: sc16is7xx: reduce TX refill rate with half-FIFO trigger
  serial: sc16is7xx: refill TX FIFO below trigger using fresh TXLVL
  serial: tegra: don't clear the Tx FIFO on an Rx-only reset
  serial: sc16is7xx: fix TX gap caused by kfifo circular buffer wrap-around
  tty: fix saved termios reset race
  tty: serial: mpc52xx_uart: move static declarations up.
  tty: serial: max3100: shut down timer before freeing port
  tty: add break_wait kernel-doc
  serial: qcom-geni: keep registered console runtime active
  serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend
  serial: qcom-geni: avoid unused-function warning
  tty: serial: qcom_geni_serial: Keep console RX functional after deep idle
  soc: qcom: geni-se: Correct QUP Core ICC vote constants
  serial: 8250_bcm7271: fix use-after-free in brcmuart_remove()
  serial: vt8500: Fix clock reference leak in vt8500_serial_probe()
  kgdboc: Fix tty driver reference leak in configure_kgdboc()
  ...
</content>
</entry>
<entry>
<title>Merge tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb</title>
<updated>2026-10-03T15:42:54Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-03T15:42:54Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=903e23eda5af2a5491e698838645f84a8f90379b'/>
<id>urn:sha1:903e23eda5af2a5491e698838645f84a8f90379b</id>
<content type='text'>
Pull USB/Thunderbolt fixes from Greg KH:
 "Here is a big set of USB and Thunderbolt driver fixes for 7.3-rc6.
  They were delayed on my side due to conference travel, not the fault
  of the submitters at all. Included in here are:

   - lots of small thunderbolt fixes for reported issues due to more
     testing and devices and a few reverts as well based on that work

   - more usb-serial device ids added

   - usb-serial and cdc-acm driver hangup and other fixes

   - dwc3 driver fixes for reported problems

   - lots of usb gadget driver fixes as people again fuzz these drivers
     and send in fixes, which is nice to finally see

   - typec driver fixes for reported problems

   - octeon-hcd driver fixes for reported problems

   - more usb-storage quirks added

   - other small USB driver bugs resolved for reported problems

  All of these have been in linux-next without any reported issues"

* tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: (63 commits)
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  Revert "usb: dwc3: gadget: fix IRQ storm on invalid event buffer count"
  USB: gadget: dummy-hcd: Fix wait for outstanding request completions
  usb: typec: port-mapper: Only match USB4 port if host interface is available
  usb: cdns3: Fix NULL pointer dereference in cdns3_pci_probe
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  usb: typec: ucsi: Get the connector fwnode based on reg value
  usb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmd
  usb: core: clear both ep_in and ep_out for non-ep0 control endpoints
  USB: cdc-acm: skip URB restart in port_shutdown if disconnected
  usb: gadget: f_fs: Fix NULL pointer dereference in FUNCTIONFS_ENDPOINT_DESC
  usb: gadget: aspeed-vhub: cancel wake work on device removal
  thunderbolt: Disable CL states for the Anker Prime TB5 dock
  thunderbolt: stream: Announce support for FMODE_NOWAIT
  usb: typec: ucsi: displayport: Current CAM OOB index fixup
  usb: ohci-st: disable controller wakeup on removal
  usb: ohci-spear: disable controller wakeup on removal
  usb: ohci-s3c2410: disable controller wakeup on removal
  usb: ohci-da8xx: disable controller wakeup on cleanup
  usb: cdns3: fix use-after-free in cdns3_gadget_exit()
  ...
</content>
</entry>
<entry>
<title>Merge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux</title>
<updated>2026-10-02T21:04:11Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T21:04:11Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=ff47652a4b66c067c765a7ad464d930b5a9367cc'/>
<id>urn:sha1:ff47652a4b66c067c765a7ad464d930b5a9367cc</id>
<content type='text'>
Pull smb client fixes from Paulo Alcantara:
 "Fix a series of data corruption and I/O error bugs found by running
  generic/363 (fsx) in a loop against Windows Server 2022 and Samba.

   - Stop data dirtied past EOF through an mmap from reappearing as file
     content once the file is extended by a write, truncate, zero range,
     copy range or clone range

   - Flush dirty data and drain in-flight I/O before operations that
     assume the pagecache and the server agree on the file: querying
     allocated ranges, the O_TRUNC open, interior zero range, and
     server-side copy/clone

   - Stop a genuine size-extending zero range or preallocate from being
     refused with -EOPNOTSUPP when the inode is not read caching, by
     querying the server's authoritative EOF instead of trusting a stale
     cached i_size

   - Zero the untransferred tail of a short read, both in the netfs
     read-gaps path (where stale folio content could otherwise be
     written back to the server) and in the DIO/unbuffered read
     collector, and tell a real EOF apart from a stale cached
     remote_i_size after a lease downgrade

   - Require stable pages on signed connections so a buffered write
     can't modify a folio whose signature has already been computed and
     is in flight, which the server rejected with STATUS_ACCESS_DENIED
     and the client surfaced as -EIO

   - Split several cifsFileInfo flags out of a shared bitfield byte so
     concurrent updates taken under different locks no longer clobber
     each other through a byte-level RMW"

* tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux:
  smb: client: split cifsFileInfo bitfields to avoid shared-byte RMW races
  smb: client: require stable pages for signed connections
  smb: client: distinguish real EOF from a stale remote_i_size on read
  netfs: zero the tail of a short DIO/unbuffered read
  smb: client: only require read lease for size-extending preallocate
  netfs: zero gaps in read-gaps folio to avoid writing back stale data
  smb: client: only require read lease for size-extending zero range
  smb: client: drain and invalidate before server-side copy/clone
  smb: client: flush dirty data before zeroing a range
  smb: client: drain outstanding I/O before truncating on O_TRUNC open
  smb: client: flush and commit data before querying allocated ranges
  smb: client: discard post-EOF pagecache when extending a file via clone range
  smb: client: discard post-EOF pagecache when extending a file via copy range
  smb: client: discard post-EOF pagecache when extending a file via zero range
  smb: client: clear post-EOF pagecache when extending a file via truncate
  netfs: clear post-EOF pagecache when extending a file via write
</content>
</entry>
<entry>
<title>Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf</title>
<updated>2026-10-02T19:59:32Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T19:59:32Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=8f150ccedfbd610aa25509ff42365d70fb20478f'/>
<id>urn:sha1:8f150ccedfbd610aa25509ff42365d70fb20478f</id>
<content type='text'>
Pull bpf fixes from Alexei Starovoitov:

 - Fix overflow of backward jump offset in constant blinding
   (Alexei Starovoitov)

 - Fix packet range of packet pointers sharing an id when var_off
   tightens umax of one pointer and not the other (Alexei Starovoitov)

 - Fix objects stuck in free_by_rcu_ttrace list of bpf memalloc
   (Alexei Starovoitov)

 - Fix use-after-free of progs detached from busy trampolines: wait for
   an RCU tasks grace period before freeing trampoline progs, and patch
   detached progs out of trampoline images that are still in use
   (Florent Revest)

 - Hold map BTF for the memory allocator destructor record to fix UAF in
   deferred bpf_mem_alloc destruction (Kumar Kartikeya Dwivedi)

 - Fix missing migration protection in resizable hashtab
   lookup_and_delete batch operation (Ömer Mete Kaya)

* tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf:
  bpf: Fix missing migration protection in __rhtab_map_lookup_and_delete_batch()
  selftests/bpf: Add a test for objects stuck in free_by_rcu_ttrace
  bpf: Fix objects stuck in free_by_rcu_ttrace
  bpf: Factor out __do_call_rcu_ttrace()
  selftests/bpf: Test packet range of pointers sharing an id
  bpf: Fix packet range of pointers sharing an id
  selftests/bpf: Detach a trampoline prog while a task sleeps before it
  bpf: Skip detached progs in trampoline images that are still in use
  bpf: Wait for an RCU tasks grace period before freeing trampoline progs
  bpf: Hold map BTF for the memory allocator destructor record
  bpf: Fix overflow of jump offset in constant blinding
</content>
</entry>
<entry>
<title>Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux</title>
<updated>2026-10-02T19:17:24Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T19:17:24Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=3f1fe48a36b0b6722dc3fd421d93512bac138e9a'/>
<id>urn:sha1:3f1fe48a36b0b6722dc3fd421d93512bac138e9a</id>
<content type='text'>
Pull io_uring fixes from Jens Axboe:

 - Fix a task_work add use-after-free with SQPOLL.

   The sqpoll thread could pop and complete the last request while
   io_req_normal_work_add() was still looking at them after the mpscq
   push.

   Use the same approach as DEFER_TASKRUN to protect from that, holding
   an RCU read lock across the add, and have exit wait for an RCU grace
   period for SQPOLL rings as well.

 - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
   big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
   rings

 - Mark the source filter table as COW when cloning bpf filters, so
   registering another filter on the source doesn't modify the shared
   table in place

 - Initialize the task context before running the BPF loop

 - Requeue zcrx multishot receives stopped by a local resource

 - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit)

* tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
  io_uring: fix task_work add use-after-free with SQPOLL
  io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full
  io_uring/zcrx: requeue multishot receives stopped by a local resource
  io_uring: initialize task context before running the BPF loop
  io_uring: zero big_cqe for aux CQEs on CQE32 rings
  io_uring: fix free entry check for 32b CQEs on CQE32 rings
  io_uring: only post the dummy skip CQE on CQE_MIXED rings
  io_uring/bpf_filter: mark source as COW when cloning filters
</content>
</entry>
<entry>
<title>tty: add missing driver flag kernel-doc colon</title>
<updated>2026-10-02T09:15:22Z</updated>
<author>
<name>Johan Hovold</name>
<email>johan@kernel.org</email>
</author>
<published>2026-10-02T07:27:36Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=6c95ca52f27855dd2fb74131c8d4e8325d2af7de'/>
<id>urn:sha1:6c95ca52f27855dd2fb74131c8d4e8325d2af7de</id>
<content type='text'>
A recent change adding a new TTY driver flag left out a colon required
for well-formed kernel-doc.

Fixes: 8df07fe93573 ("tty: fix saved termios reset race")
Reported-by: Randy Dunlap &lt;rdunlap@infradead.org&gt;
Link: https://lore.kernel.org/ec3a09d6-4ba4-41b8-abb1-b59e265f4532@infradead.org
Signed-off-by: Johan Hovold &lt;johan@kernel.org&gt;
Link: https://patch.msgid.link/20261002072736.2063004-1-johan@kernel.org
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>selftests/bpf: Test packet range of pointers sharing an id</title>
<updated>2026-10-01T16:39:27Z</updated>
<author>
<name>Alexei Starovoitov</name>
<email>ast@kernel.org</email>
</author>
<published>2026-10-01T14:52:55Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=33a154a96e71a34a1bcca9f40da343dbbf7b38b4'/>
<id>urn:sha1:33a154a96e71a34a1bcca9f40da343dbbf7b38b4</id>
<content type='text'>
Add tests where two packet pointers share an id and tightening one
pointer's umax from its var_off would put it less than their constant
distance from the other's umax: with an index &amp; 0x38 capped at 50, the
base pointer keeps umax 50, so the pointer 8 bytes further on must keep
umax 58, even though its known bits allow at most 56.

These refused a valid program or accepted an out-of-bounds access before
the fix:

- check the advanced copy, load through the base: valid, was refused;
- check the base, load the byte at base + 1 through a copy advanced by
  8: was accepted;
- check base + 4, load 4 bytes at base + 2 through base + 8: reads two
  bytes past the checked range, was accepted;
- the same as the second with data_meta pointers checked against data:
  was accepted.

These pass with and without the fix and cover nearby paths:

- subtract an unknown scalar from a checked pointer and load below it
  (the range is kept across a new id);
- reach a load through two paths whose checks cover 8 and 7 bytes after
  the loaded pointer; the second path must not be pruned by the first;
- spill a copy of a pointer, check the pointer, fill the copy and load
  one byte past the checked range: the load is refused, and the copy
  has the range of the check.

Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Link: https://lore.kernel.org/bpf/20261001145255.855630-2-alexei.starovoitov@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi &lt;memxor@gmail.com&gt;
</content>
</entry>
<entry>
<title>perf: Replace perf_event_header__init_id with full header init</title>
<updated>2026-10-01T12:02:06Z</updated>
<author>
<name>Ian Rogers</name>
<email>irogers@google.com</email>
</author>
<published>2026-09-29T22:23:32Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=b9d1fdc6f4ac1b6e49f9deafaf137da1407d9af1'/>
<id>urn:sha1:b9d1fdc6f4ac1b6e49f9deafaf137da1407d9af1</id>
<content type='text'>
perf_iterate_sb() invokes its callback for each matching perf_event on
the CPU and task context, passing a shared caller-allocated event
structure.

perf_event_header__init_id() mutated header-&gt;size in place by adding
event-&gt;id_header_size, requiring sideband output callbacks to save and
restore header fields across iterations. Three sideband callbacks failed
to save and restore header.size around perf_event_header__init_id():
 - perf_event_ksymbol_output()
 - perf_event_bpf_output()
 - perf_event_text_poke_output()

When multiple events with attr.ksymbol, attr.bpf_event, or
attr.text_poke and sample_id_all are active on the same CPU, each
subsequent event receives a record whose header.size is inflated by all
preceding events' id_header_size values while only a single id_sample is
written, leaving uninitialized ring-buffer bytes at the end of the
record and causing userspace perf to fail with -EFAULT ("Bad address")
when parsing the sample_id trailer.

Similarly, perf_event_mmap_output() set PERF_RECORD_MISC_MMAP_BUILD_ID
in mmap_event-&gt;event_id.header.misc when event-&gt;attr.build_id was
enabled, but only saved and restored header.size and header.type. If an
event with attr.build_id was followed by an event with attr.mmap2 and
!attr.build_id, the second event received PERF_RECORD_MISC_MMAP_BUILD_ID
in header.misc while its payload contained maj/min/ino/ino_generation
instead of a build ID.

Rather than splitting header initialization between callers and output
callbacks and saving/restoring mutated header fields, replace
perf_event_header__init_id() with perf_event_header__init(), which
initializes header-&gt;type, header-&gt;misc, and header-&gt;size alongside the
sample_id fields on each invocation.

Fixes: 76193a94522f ("perf, bpf: Introduce PERF_RECORD_KSYMBOL")
Fixes: 6ee52e2a3fe4 ("perf, bpf: Introduce PERF_RECORD_BPF_EVENT")
Fixes: e17d43b93e54 ("perf: Add perf text poke event")
Fixes: 88a16a130933 ("perf: Add build id data in mmap2 event")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers &lt;irogers@google.com&gt;
Signed-off-by: Peter Zijlstra (Intel) &lt;peterz@infradead.org&gt;
Link: https://patch.msgid.link/20260929222332.973435-1-irogers@google.com
Cc: stable@vger.kernel.org
</content>
</entry>
</feed>
