summaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)Author
5 daysLinux 7.3-rc6HEADv7.3-rc6masterLinus Torvalds
6 daysMerge tag 'i2c-fixes-7.3-rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux Pull i2c fixes from Andi Shyti: "Three patches in xiic for fixing the block reads and a single cleanup in the at91 error path: - at91: also release DMA channels when deferring probe - xiic: fix SMBus block reads with PEC" * tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux: i2c: at91: release DMA channels when probe defers i2c: xiic: don't clobber msg->len to signal block-read completion i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO i2c: xiic: preserve PEC byte length in SMBus block read setup
6 daysMerge tag 'x86-urgent-2026-10-04' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull x86 fixes from Ingo Molnar: - Don't apply va_align to hugetlb mappings on AMD F15h systems that have custom va_align.bits values (Laurent Wandrebeck) - Fix PMD teardown handling regression flagged by lockdep (Mikhail Gavrilov) - Hide ptrace header register offset macros behind __ASSEMBLER__ or __FRAME_OFFSETS, to fix user-space build errors that may trigger if they happen to shadow these short and generic macro names (Nick Desaulniers) * tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: {x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS x86/mm: Drop unnecessary PMD page copy when freeing x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h
6 daysMerge tag 'timers-urgent-2026-10-04' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull timer fix from Ingo Molnar: - Fix task work flags management regression in the hrtimer rearming code that can leave task work items unprocessed (Karl Mehltretter) * tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
6 daysMerge tag 'perf-urgent-2026-10-04' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull perf events fixes from Ingo Molnar: - Fix race between perf_event_exit_task() and perf_pending_task() (Luo Gengkun) - Fix perf header output management regressions (Ian Rogers) - Require kernel access for text poke events (Zhengchuan Liang) * tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: perf: Require kernel access for text poke events perf: Replace perf_event_header__init_id with full header init perf: Fix race between perf_event_exit_task() and perf_pending_task()
6 daysMerge tag 'locking-urgent-2026-10-04' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip Pull locking fixes from Ingo Molnar: - Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS (Kuan-Wei Chiu) - Fix futex private hash use-after-free on resize (Chris Mason) * tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: futex: Fix private hash use-after-free on resize irq: Make refcount_interrupt kunit test selectable
6 daysMerge tag 'edac_urgent_for_v7.3_rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras Pull EDAC fixes from Borislav Petkov: "This is more of the new normal of LLM-induced fixes of error paths. Oh well, they should be done eventually and hopefully we'll be back to normal soon-ish... one would hope... :-P AMD Versal NET: - Properly release a remote processor reference which was acquired at probe time, on memory controller instance remove A handful of Altera EDAC driver fixes: - Fix device node reference leaks covering both the success path and the various error paths, and route the single-bit setup function through the common exit label - Fix a use-after-free by releasing the devres group before freeing the control info structure in the error paths, since managed IRQ handlers could reference the freed dci struct if they fire at just the right time - Fix a memory leak by freeing the allocated control info structure when the devres group open fails in the Altera SDMMC setup path - Remove the __init marking from the Altera Arria10 setup paths and their helpers so they remain safely callable at runtime, including after deferred or re-triggered probing - Prevent the Altera driver from being unbound by removing their ->remove callbacks and marking them to suppress bind/unbind sysfs attributes, since unbinding could erase active system memory" * tag 'edac_urgent_for_v7.3_rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras: EDAC/versalnet: Drop remote processor handle refcount on driver removal EDAC/altera: Fix device node reference leaks in the SDMMC ECC setup EDAC/altera: Fix use-after-free in error paths EDAC/altera: Fix memory leak on dci allocation failure EDAC/altera: Drop __init from ECC setup paths for re-probe safety EDAC/altera: Do not allow driver unbinding
6 daysMerge tag 'clk-fixes-for-linus-v7.3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux Pull clk fixes from Brian Masney: "Two small clk driver fixes: - spacemit: k3: Fix an issue that will trigger a system hang due to unavailable frequency - ti: composite: Reverts a commit that breaks OMAP3" * tag 'clk-fixes-for-linus-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux: clk: spacemit: k3: add CPU PLL rate tables clk: ti: composite: resolve parent clocks by name again
7 daysMerge tag 'char-misc-7.3-rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc Pull char/misc/IIO fixes from Greg KH: "Here is a set of char/misc/iio and other small driver subsystem fixes for 7.3-rc6 that resolve a number of reported issues. Included in here are: - lots of small iio driver fixes for reported problems - interconnect driver revert to resolve a regression - nitro_enclaves driver fix for a use-after-free - binder driver fixes for reported problems (in both the rust and C versions) All of these have been in linux-next with no reported issues" * tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (63 commits) iio: adc: ad_sigma_delta: fix use-after-free on unbind iio: accel: kxcjk-1013: reject duplicate event disable iio: buffer: serialize buffer teardown with mode claims iio: cdc: ad7150: fix OF matching and publish module aliases iio: adc: ade9000: fix NULL pointer dereference in clkout registration iio: adc: ad4030: fix invalid oversampling_ratio validation iio: adc: ad7173: Fix digital filter configuration iio: adc: stm32-adc: fix possible division by zero in processed channel iio: adc: stm32-adc: fix check on internal channel availability iio: proximity: isl29501: Fix return type of isl29501_register_write iio: imu: inv_icm42607: restore runtime PM on system resume errors iio: imu: inv_icm42607: propagate runtime suspend errors iio: adc: pac1934: check ACPI label duplication rust_binderfs: add transaction_report feature entry rust_binder: reschedule node refcount update on thread exit rust_binder: cancel deferred work items in thread exit binderfs: fix UAF write in binder_add_device binder: fix is_failure flag for superseded transaction cleanup binder: fix leaked fd fixups on TF_UPDATE_TXN supersede Revert "interconnect: qcom: x1e80100: enable QoS configuration" ...
7 daysMerge tag 'tty-7.3-rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty Pull tty/serial fixes from Greg KH: "Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major here, just lots of small fixes for reported issues, some of them very long-standing: - tty hangup fixes that have been there since the BKL days and kept tripping people up over time. - vt selection bugfix - other vt bugfixes (memory leaks and screen update fixes) - n_gsm bugfix - qcom-geni serial driver bugfix - 8250 serial driver bugfixes - other tiny serial driver fixes All of these have been in linux-next, the last few only a few days but testing here seems solid (this pull request was generated on that tree)" * tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (37 commits) tty: add missing driver flag kernel-doc colon vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection() vt: skip screen update for DEC alignment test on backgroup consoles vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF serial: sc16is7xx: reduce TX refill rate with half-FIFO trigger serial: sc16is7xx: refill TX FIFO below trigger using fresh TXLVL serial: tegra: don't clear the Tx FIFO on an Rx-only reset serial: sc16is7xx: fix TX gap caused by kfifo circular buffer wrap-around tty: fix saved termios reset race tty: serial: mpc52xx_uart: move static declarations up. tty: serial: max3100: shut down timer before freeing port tty: add break_wait kernel-doc serial: qcom-geni: keep registered console runtime active serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend serial: qcom-geni: avoid unused-function warning tty: serial: qcom_geni_serial: Keep console RX functional after deep idle soc: qcom: geni-se: Correct QUP Core ICC vote constants serial: 8250_bcm7271: fix use-after-free in brcmuart_remove() serial: vt8500: Fix clock reference leak in vt8500_serial_probe() kgdboc: Fix tty driver reference leak in configure_kgdboc() ...
7 daysMerge tag 'usb-7.3-rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb Pull USB/Thunderbolt fixes from Greg KH: "Here is a big set of USB and Thunderbolt driver fixes for 7.3-rc6. They were delayed on my side due to conference travel, not the fault of the submitters at all. Included in here are: - lots of small thunderbolt fixes for reported issues due to more testing and devices and a few reverts as well based on that work - more usb-serial device ids added - usb-serial and cdc-acm driver hangup and other fixes - dwc3 driver fixes for reported problems - lots of usb gadget driver fixes as people again fuzz these drivers and send in fixes, which is nice to finally see - typec driver fixes for reported problems - octeon-hcd driver fixes for reported problems - more usb-storage quirks added - other small USB driver bugs resolved for reported problems All of these have been in linux-next without any reported issues" * tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: (63 commits) usb: dwc3: gadget: fix IRQ storm on invalid event buffer count Revert "usb: dwc3: gadget: fix IRQ storm on invalid event buffer count" USB: gadget: dummy-hcd: Fix wait for outstanding request completions usb: typec: port-mapper: Only match USB4 port if host interface is available usb: cdns3: Fix NULL pointer dereference in cdns3_pci_probe usb: dwc3: gadget: fix IRQ storm on invalid event buffer count usb: typec: ucsi: Get the connector fwnode based on reg value usb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmd usb: core: clear both ep_in and ep_out for non-ep0 control endpoints USB: cdc-acm: skip URB restart in port_shutdown if disconnected usb: gadget: f_fs: Fix NULL pointer dereference in FUNCTIONFS_ENDPOINT_DESC usb: gadget: aspeed-vhub: cancel wake work on device removal thunderbolt: Disable CL states for the Anker Prime TB5 dock thunderbolt: stream: Announce support for FMODE_NOWAIT usb: typec: ucsi: displayport: Current CAM OOB index fixup usb: ohci-st: disable controller wakeup on removal usb: ohci-spear: disable controller wakeup on removal usb: ohci-s3c2410: disable controller wakeup on removal usb: ohci-da8xx: disable controller wakeup on cleanup usb: cdns3: fix use-after-free in cdns3_gadget_exit() ...
7 daysMerge tag 'input-for-v7.3-rc5' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input fixes from Dmitry Torokhov: - A fix for the Samsung S6SY761 touchscreen driver to power on the controller before unmasking interrupts during resume and to re-enable touch sensing when the device is open - Updates to the Synaptics touchpad driver to enable SMBus/RMI4 mode on Lenovo ThinkPad T490 and restrict the ThinkPad T440p InterTouch disable quirk to LEN0036 so that ThinkPad L440 retains SMBus support - A quirk for the AT keyboard driver (atkbd) to skip keyboard deactivation on Lenovo IdeaPad Slim 3 15IWC11 so the internal keyboard functions properly - A DMI quirk for the i8042 controller to disable active multiplexing on Fujitsu LIFEBOOK U7410, preventing the internal keyboard and touchpad from dying shortly after boot. * tag 'input-for-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: atkbd - skip deactivate for Lenovo IdeaPad Slim 3 15IWC11 Input: s6sy761 - fix resume ordering and restore sensing Input: synaptics - limit T440p InterTouch quirk to LEN0036 Input: i8042 - add nomux quirk for Fujitsu LIFEBOOK U7410 Input: synaptics - add LEN205b entry to smbus_pnp_ids for ThinkPad T490
7 daysMerge tag 'drm-fixes-2026-10-03' of https://gitlab.freedesktop.org/drm/kernelLinus Torvalds
Pull drm fixes from Dave Airlie: "Live from Brisbane airport, it's Saturday Night drm fixes. The misc fixes tree didn't get a PR this week, so I'll probably have that to you when I see it, there were a few patches in there. Otherwise amdgpu is the main act, mediatek has a guest spot, and xe/i915 bring in a fix each. xe: - keep VF LMEM bar size low if no VFs enabled i915: - Disable VRR DC balance by default to fix timing issues mediatek: - Add missing IS_ERR check for ovl_adaptor platform device - Fix VID_DOWNSAMPLE_CONFIG register offset - Fix pdev reference leak in mtk_drm_bind() - Fix runtime PM leak in mtk_hdmi_ddc_v2_probe() - Fix ovl adaptor platform device leak amdgpu: - dc_state_create_copy() fix - HDMI RGB limited range fix - eDP ASSR fix - DCE 6 fixes - DCE 8.1 fix - SI DPM fixes - Reset fixes - Workaround for multiple SDMA entities with DCC - PWM backlight fix - GPUVM fixes - Switcheroo fix - Error handling leak fixes - GC 6 unload FW leak fix - SDMA 7.1 fix - DML frame size limit fix - RGB vs YCbCr 4:4:4 fix - DP MST fix - DC Power module fixes - MacBookPro14,3 fix amdkfd: - SVM fix radeon: - sparc64 fix" * tag 'drm-fixes-2026-10-03' of https://gitlab.freedesktop.org/drm/kernel: (36 commits) drm/mediatek: Fix ovl adaptor platform device leak drm/mediatek: Fix runtime PM leak in mtk_hdmi_ddc_v2_probe() drm/mediatek: Fix pdev reference leak in mtk_drm_bind() drm/amdgpu: reset VI ASIC on MacBookPro14,3 drm/amd/pm/si: Fix updating clock limits on AC/DC drm/amd/display: Fix stale replay_events after mod_power stream removal drm/radeon: Read the VRAM VBIOS signature with readb() drm/amd/display: guard dc_sink dereferences in MST mode validation drm/amd/display: Try RGB before YCbCr 4:4:4 in stream validation drm/amd/display: Fix sanitizer check for the DML frame size limit drm/amdgpu/gmc12.1: properly pass flush_type to gmc_v12_1_flush_vm_hub() drm/amdgpu: drop userq callback assignment for sdma 7.1 drm/amdgpu/gfx6: fix firmware leak on teardown drm/amdgpu: fix ACP MFD device leak on init failure drm/amdgpu: fix IP instance memory leak on kobject add failure drm/amdgpu: skip the noirq suspend reset for a switcheroo-parked GPU drm/amdgpu/gmc12: properly pass flush_type to gmc_v12_0_flush_vm_hub() drm/amd/display: map PWM brightness through custom backlight curve drm/amdgpu: implement workaround for sdma dcc corruption drm/amdkfd: Fix always mapped range mapping to all ACCESS GPUs ...
7 daysMerge tag 'arm64-fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux Pull arm64 fixes from Will Deacon: "Half of this is broken hardware (AMU counters and TLB invalidation) and the other half is broken software (frequency scaling and signals). So it seems as though we're all as bad as each other. The AMU workaround is a little noisy, as it refactors an existing workaround so that it can more easily be applied to additional CPUs. Summary: - Fix handling of CPU erratum #2645198 when batching pte updates - Fix truncation of CPU frequency calculation by using 64-bit arithmetic in arch_freq_get_on_cpu() - Work around AMU erratum #3821522 on Cortex-A725 - Fix panic when trying to restore an SVE sigframe on a CPU that only supports SME" * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux: arm64/fpsimd: signal: Forbid non-streaming SVE payload on SME-only systems arm64: errata: Add Cortex-A725 erratum 3821522 workaround arm64: errata: Factor out broken AMU const counter cap arm64: topology: fix arch_freq_get_on_cpu() overflow above 4.19 GHz arm64: mm: Fix the break-before-make flush range for erratum 2645198
7 daysInput: atkbd - skip deactivate for Lenovo IdeaPad Slim 3 15IWC11Martino Papero
The internal keyboard on the Lenovo IdeaPad Slim 3 15IWC11 (83RR) does not work correctly with the default i8042 settings. Using i8042.nopnp=1 and i8042.dumbkbd=1 restores keyboard input, but prevents the Caps Lock LED from working. Using i8042.nopnp=1 alone does not fix the keyboard. The laptop works correctly when atkbd_deactivate_fixup is used instead. Add a DMI quirk for the 83RR to enable it. This was tested without any i8042 command-line parameters. Keyboard input and the Caps Lock LED work correctly, including after suspend and resume and after a cold boot. Link: https://lore.kernel.org/all/4f43465f-98ba-4722-8e29-03df20315369@kernel.org/ Signed-off-by: Martino Papero <martino.papero@lcb.to.it> Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com> Link: https://patch.msgid.link/c0b597b8-e7ad-4fba-a2bb-5d252e3dfbd3@lcb.to.it Cc: stable@vger.kernel.org Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
7 daysMerge tag 'probes-fixes-v7.3-rc5' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace Pull probes fixes from Masami Hiramatsu: - fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching() Exit handlers early if !rcu_is_watching() to prevent potential use-after-free during unregistration in idle/quiescent states. Switch to guard(rcu_sched_notrace) to avoid fast-path lockdep overhead and recursion while ensuring safe grace period synchronization. - kprobes: Skip disarmed probes when checking optkprobe overlap Continue past disarmed or unprepared probes in get_optimized_kprobe() to find active optimized probes. This avoids overwriting active jump displacements which can lead to panic. * tag 'probes-fixes-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: kprobes: Skip disarmed probes when checking optkprobe overlap fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()
7 daysMerge tag 'amd-drm-fixes-7.3-2026-10-01' of ↵Dave Airlie
https://gitlab.freedesktop.org/drm/amdgpu/kernel into drm-fixes amd-drm-fixes-7.3-2026-10-01: amdgpu: - dc_state_create_copy() fix - HDMI RGB limited range fix - eDP ASSR fix - DCE 6 fixes - DCE 8.1 fix - SI DPM fixes - Reset fixes - Workaround for multiple SDMA entities with DCC - PWM backlight fix - GPUVM fixes - Switcheroo fix - Error handling leak fixes - GC 6 unload FW leak fix - SDMA 7.1 fix - DML frame size limit fix - RGB vs YCbCr 4:4:4 fix - DP MST fix - DC Power module fixes - MacBookPro14,3 fix amdkfd: - SVM fix radeon: - Sparc64 fix Signed-off-by: Dave Airlie <airlied@redhat.com> From: Alex Deucher <alexander.deucher@amd.com> Link: https://patch.msgid.link/20261001230115.1319089-1-alexander.deucher@amd.com
7 daysMerge tag 'mediatek-drm-fixes-20261002' of ↵Dave Airlie
https://git.kernel.org/pub/scm/linux/kernel/git/chunkuang.hu/linux into drm-fixes Mediatek DRM Fixes - 20261002 1. Add missing IS_ERR check for ovl_adaptor platform device 2. Fix VID_DOWNSAMPLE_CONFIG register offset 3. Fix pdev reference leak in mtk_drm_bind() 4. Fix runtime PM leak in mtk_hdmi_ddc_v2_probe() 5. Fix ovl adaptor platform device leak Signed-off-by: Dave Airlie <airlied@redhat.com> From: Chun-Kuang Hu <chunkuang.hu@kernel.org> Link: https://patch.msgid.link/20261001234906.14940-1-chunkuang.hu@kernel.org
7 daysMerge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linuxLinus Torvalds
Pull smb client fixes from Paulo Alcantara: "Fix a series of data corruption and I/O error bugs found by running generic/363 (fsx) in a loop against Windows Server 2022 and Samba. - Stop data dirtied past EOF through an mmap from reappearing as file content once the file is extended by a write, truncate, zero range, copy range or clone range - Flush dirty data and drain in-flight I/O before operations that assume the pagecache and the server agree on the file: querying allocated ranges, the O_TRUNC open, interior zero range, and server-side copy/clone - Stop a genuine size-extending zero range or preallocate from being refused with -EOPNOTSUPP when the inode is not read caching, by querying the server's authoritative EOF instead of trusting a stale cached i_size - Zero the untransferred tail of a short read, both in the netfs read-gaps path (where stale folio content could otherwise be written back to the server) and in the DIO/unbuffered read collector, and tell a real EOF apart from a stale cached remote_i_size after a lease downgrade - Require stable pages on signed connections so a buffered write can't modify a folio whose signature has already been computed and is in flight, which the server rejected with STATUS_ACCESS_DENIED and the client surfaced as -EIO - Split several cifsFileInfo flags out of a shared bitfield byte so concurrent updates taken under different locks no longer clobber each other through a byte-level RMW" * tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux: smb: client: split cifsFileInfo bitfields to avoid shared-byte RMW races smb: client: require stable pages for signed connections smb: client: distinguish real EOF from a stale remote_i_size on read netfs: zero the tail of a short DIO/unbuffered read smb: client: only require read lease for size-extending preallocate netfs: zero gaps in read-gaps folio to avoid writing back stale data smb: client: only require read lease for size-extending zero range smb: client: drain and invalidate before server-side copy/clone smb: client: flush dirty data before zeroing a range smb: client: drain outstanding I/O before truncating on O_TRUNC open smb: client: flush and commit data before querying allocated ranges smb: client: discard post-EOF pagecache when extending a file via clone range smb: client: discard post-EOF pagecache when extending a file via copy range smb: client: discard post-EOF pagecache when extending a file via zero range smb: client: clear post-EOF pagecache when extending a file via truncate netfs: clear post-EOF pagecache when extending a file via write
7 daysMerge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpfLinus Torvalds
Pull bpf fixes from Alexei Starovoitov: - Fix overflow of backward jump offset in constant blinding (Alexei Starovoitov) - Fix packet range of packet pointers sharing an id when var_off tightens umax of one pointer and not the other (Alexei Starovoitov) - Fix objects stuck in free_by_rcu_ttrace list of bpf memalloc (Alexei Starovoitov) - Fix use-after-free of progs detached from busy trampolines: wait for an RCU tasks grace period before freeing trampoline progs, and patch detached progs out of trampoline images that are still in use (Florent Revest) - Hold map BTF for the memory allocator destructor record to fix UAF in deferred bpf_mem_alloc destruction (Kumar Kartikeya Dwivedi) - Fix missing migration protection in resizable hashtab lookup_and_delete batch operation (Ömer Mete Kaya) * tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf: bpf: Fix missing migration protection in __rhtab_map_lookup_and_delete_batch() selftests/bpf: Add a test for objects stuck in free_by_rcu_ttrace bpf: Fix objects stuck in free_by_rcu_ttrace bpf: Factor out __do_call_rcu_ttrace() selftests/bpf: Test packet range of pointers sharing an id bpf: Fix packet range of pointers sharing an id selftests/bpf: Detach a trampoline prog while a task sleeps before it bpf: Skip detached progs in trampoline images that are still in use bpf: Wait for an RCU tasks grace period before freeing trampoline progs bpf: Hold map BTF for the memory allocator destructor record bpf: Fix overflow of jump offset in constant blinding
7 daysMerge tag 'pci-v7.3-fixes-3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci Pull PCI fix from Bjorn Helgaas: - Allow driver to use AtomicOps if already enabled by hypervisor; fixes regression when Root Port is not visible in a guest (Nikola Prica) * tag 'pci-v7.3-fixes-3' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci: PCI: Accept AtomicOps already enabled by the hypervisor
7 daysMerge tag 'block-7.3-20261002' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull block fixes from Jens Axboe: - NVMe fixes via Keith: - Fix an out-of-bounds write in nvmet_auth_challenge(), where sizeof() on a void pointer undercounted the challenge header and let a short AUTH_RECEIVE buffer pass the check - nvme-multipath fixes for an ANA log bounds check underflow, the command effects log lifetime for multipath heads, and only setting BLK_FEAT_ZONED after the zone info is known. - nvmet fixes for ns->enabled teardown ordering, rejecting I/O after the percpu ns reference is killed, device path preservation on allocation failure, and too-short SGL segments in pci-epf - nvme-tcp: revert the per-socket dynamic lockdep keys, and delay the socket reclassification - A DMA pool alignment quirk for the Micron 4100AT - Controller state/reset race fixes, and -Wformat-security workarounds - blk-mq: set RQF_USE_SCHED when the operation is known, and allow cached requests to be used for flush operations - Reject polled dio with user integrity metadata - Save the IRQ state in blkg_tryget_closest() - Set the zone write granularity in virtio_blk - ublk selftest fixes * tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: (23 commits) virtio_blk: set the zone write granularity nvme-multipath: set BLK_FEAT_ZONED only after the zone info is known nvme: fix command effects log lifetime for multipath heads nvmet: don't allow I/O admission after percpu ns reference is killed nvmet: defer setting ns->enabled to false in nvmet_ns_disable() nvmet: copy the hostid into the ctrl before creating PR pc_refs nvmet-auth: fix out-of-bounds write in nvmet_auth_challenge() nvmet: pci-epf: reject too-short SGL segments nvme-multipath: fix underflow in ANA log bounds checks nvme: work around all -Wformat-security warnings nvme: work around -Wformat-security warning nvme: do not reset controllers in NVME_CTRL_NEW state nvme-tcp: delay nvme_tcp_reclassify_socket() Revert "nvme-tcp: lockdep: use dynamic lockdep keys per socket instance" drbd: remove unused drbd_nl_mcgrps[] array blk-mq: allow cached requests to be used for flush operations blk-mq: set RQF_USE_SCHED when the operation is known block: reject polled dio with user integrity metadata selftests: ublk: fix unused_result error blk-cgroup: save IRQ state in blkg_tryget_closest() ...
7 daysMerge tag 'io_uring-7.3-20261002' of ↵graftedLinus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux Pull io_uring fixes from Jens Axboe: - Fix a task_work add use-after-free with SQPOLL. The sqpoll thread could pop and complete the last request while io_req_normal_work_add() was still looking at them after the mpscq push. Use the same approach as DEFER_TASKRUN to protect from that, holding an RCU read lock across the add, and have exit wait for an RCU grace period for SQPOLL rings as well. - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED rings - Mark the source filter table as COW when cloning bpf filters, so registering another filter on the source doesn't modify the shared table in place - Initialize the task context before running the BPF loop - Requeue zcrx multishot receives stopped by a local resource - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit) * tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: io_uring: fix task_work add use-after-free with SQPOLL io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full io_uring/zcrx: requeue multishot receives stopped by a local resource io_uring: initialize task context before running the BPF loop io_uring: zero big_cqe for aux CQEs on CQE32 rings io_uring: fix free entry check for 32b CQEs on CQE32 rings io_uring: only post the dummy skip CQE on CQE_MIXED rings io_uring/bpf_filter: mark source as COW when cloning filters
8 daysPCI: Accept AtomicOps already enabled by the hypervisorNikola Prica
pci_enable_atomic_ops_to_root() currently fails when no Root Port is visible. That is common in passthrough guests (ESXi, Hyper-V): the Endpoint is assigned to the VM, but the Root Port above it is not visible in the guest topology. In those setups the hypervisor may already have enabled AtomicOp Requester Enable on the device. If PCI_EXP_DEVCTL2_ATOMIC_REQ is set, treat AtomicOps as already enabled and return success instead of failing the Root Port walk. After 1ae8c4ce1570 ("PCI: Enable AtomicOps only if Root Port supports them"), pci_enable_atomic_ops_to_root() always returns failure if the Root Port is not visible, so drivers don't use atomics when they could. On systems where the Root Port is not visible but *does* support AtomicOps, this is a regression: prior to 1ae8c4ce1570, it enabled AtomicOps in the endpoint and returned success. Fixes: 1ae8c4ce1570 ("PCI: Enable AtomicOps only if Root Port supports them") Signed-off-by: Nikola Prica <nikola.prica@amd.com> [bhelgaas: commit log, code comment] Signed-off-by: Bjorn Helgaas <bhelgaas@google.com> Tested-by: Gerd Bayer <gbayer@linux.ibm.com> Reviewed-by: Christian König <christian.koenig@amd.com> Reviewed-by: Gerd Bayer <gbayer@linux.ibm.com> Link: https://patch.msgid.link/20260921111903.978687-1-nikprica@amd.com
8 daysbpf: Fix missing migration protection in __rhtab_map_lookup_and_delete_batch()Ömer Mete Kaya
bpf_mem_cache_free_rcu() uses this_cpu_ptr() which requires migration to be disabled. All callers of rhtab_delete_elem() disable migration except __rhtab_map_lookup_and_delete_batch(), which calls it under rcu_read_lock() only. On CONFIG_PREEMPT_RCU, rcu_read_lock() does not disable preemption or migration, so the task can migrate between CPUs during the delete loop, causing this_cpu_ptr() to trigger: BUG: using smp_processor_id() in preemptible [00000000] code Fix by wrapping the delete loop in migrate_disable()/migrate_enable() in __rhtab_map_lookup_and_delete_batch(), matching the migration protection that the other callers already provide. Fixes: 818e00848227 ("bpf: Implement iteration ops for resizable hashtab") Reported-by: syzbot+fd7e415d891073b83e1f@syzkaller.appspotmail.com Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Acked-by: Mykyta Yatsenko <yatsenko@meta.com> Link: https://patch.msgid.link/20260929081609.557899-1-omermetekaya0@gmail.com Closes: https://syzkaller.appspot.com/bug?extid=fd7e415d891073b83e1f
8 daysfutex: Fix private hash use-after-free on resizeChris Mason
poll_state_synchronize_rcu(mm->futex.phash.batches) is used by futex_ref_drop() to check that a grace period has passed since the current hash was published. This relies on batches referencing a grace period which started after the hash pointer was assigned. __futex_pivot_hash() sets mmph->batches before it replaces mmph->hash: scoped_guard(rcu) { mmph->batches = get_state_synchronize_rcu(); rcu_assign_pointer(mmph->hash, new); } The scoped_guard(rcu) doesn't stop new grace periods from starting, and if one starts between those two assignments, futex_ref_drop() can move forward while a reader still holds a pointer to the old hash. Fix things by setting mmph->batches after assigning mmph->hash. The scoped_guard(rcu) isn't needed, so let's drop that as well. Fixes: 56180dd20c19 ("futex: Use RCU-based per-CPU reference counting instead of rcuref_t") Assisted-by: kres Signed-off-by: Chris Mason <mason@kernel.org> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Reviewed-by: Paul E. McKenney <paulmck@kernel.org> Link: https://patch.msgid.link/20261001135022.2220288-1-mason@kernel.org
8 daysirq: Make refcount_interrupt kunit test selectableKuan-Wei Chiu
Currently, refcount_interrupt_test is built unconditionally when CONFIG_KUNIT is enabled, causing it to run unexpectedly during boot. Fix this by introducing CONFIG_REFCOUNT_INTERRUPT_KUNIT_TEST so the test can be configured independently, following standard kunit practices. Fixes: 07a88e2bcd5b ("irq: Add KUnit test for refcounted interrupt enable/disable") Signed-off-by: Kuan-Wei Chiu <visitorckw@gmail.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Reviewed-by: Lyude Paul <lyude@redhat.com> Reviewed-by: Radu Rendec <radu@rendec.net> Reviewed-by: Boqun Feng <boqun@kernel.org> Link: https://patch.msgid.link/20261001082519.16195-2-boqun@kernel.org
8 daystty: add missing driver flag kernel-doc colonJohan Hovold
A recent change adding a new TTY driver flag left out a colon required for well-formed kernel-doc. Fixes: 8df07fe93573 ("tty: fix saved termios reset race") Reported-by: Randy Dunlap <rdunlap@infradead.org> Link: https://lore.kernel.org/ec3a09d6-4ba4-41b8-abb1-b59e265f4532@infradead.org Signed-off-by: Johan Hovold <johan@kernel.org> Link: https://patch.msgid.link/20261002072736.2063004-1-johan@kernel.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
8 dayskprobes: Skip disarmed probes when checking optkprobe overlapLeon Hwang
On x86, an optkprobe at A replaces five bytes with a jump. If a disabled probe B is at A+2, get_optimized_kprobe() stops at B when arming a new probe C at A+4. It leaves A optimized: A A+1 A+2 A+3 A+4 A's jump | e9 | d0 | d1 | d2 | d3 | after C | e9 | d0 | d1 | d2 | cc | The INT3 for C overwrites the last byte of A's jump displacement, so execution can jump to the wrong address. B can have prepared optinsns while disarmed, but has no jump to unoptimize. Continue past disarmed and unprepared probes to find the active optimized probe before arming a probe in its jump. Link: https://lore.kernel.org/all/20260930053618.104498-1-leon.hwang@linux.dev/ Fixes: afd66255b9a4 ("kprobes: Introduce kprobes jump optimization") Cc: stable@vger.kernel.org Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
8 daysMerge tag 'drm-intel-fixes-2026-10-01' of ↵Dave Airlie
https://gitlab.freedesktop.org/drm/i915/kernel into drm-fixes drm/i915 fixes for v7.3-rc6: - Disable VRR DC balance by default to fix timing issues Signed-off-by: Dave Airlie <airlied@redhat.com> From: Jani Nikula <jani.nikula@intel.com> Link: https://patch.msgid.link/5a9a11777f605b59550783923add4568e974a6ea@intel.com
8 daysMerge tag 'drm-xe-fixes-2026-10-01' of ↵Dave Airlie
https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes Only 1 fix to Keep VF LMEM BAR size low if no VFs enabled from Marcin and a preparation patch for that. Signed-off-by: Dave Airlie <airlied@redhat.com> From: Rodrigo Vivi <rodrigo.vivi@intel.com> Link: https://patch.msgid.link/ar5qJ-OV2gNI1TwN@intel.com
8 daysdrm/mediatek: Fix ovl adaptor platform device leakGuangshuo Li
mtk_drm_probe() creates an OVL adaptor platform device with platform_device_register_data() when the display pipeline requires the OVL adaptor. If a later initialization step fails, the probe error path releases the DRM resources without unregistering the already registered OVL adaptor device. The normal remove path likewise leaves the device registered after the DRM driver is unbound. Keep track of whether the OVL adaptor was successfully registered and unregister it on probe failure. Also recover the platform device from the stored DDP component device and unregister it during normal removal. The issue was identified by a static analysis tool I developed and confirmed by manual review. Fixes: 0d9eee9118b7 ("drm/mediatek: Add drm ovl_adaptor sub driver for MT8195") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com> Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260921131156.403652-1-lgs201920130244@gmail.com/ Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
8 daysdrm/mediatek: Fix runtime PM leak in mtk_hdmi_ddc_v2_probe()Wentao Liang
pm_runtime_get_sync() unconditionally bumps the usage counter, but nothing puts it back when devm_i2c_add_adapter() fails, leaving the DDC runtime-resumed after a failed probe. Drop the reference on that error path. Fixes: 8d0f79886273 ("drm/mediatek: Introduce HDMI/DDC v2 for MT8195/MT8188") Signed-off-by: Wentao Liang <vulab@iscas.ac.cn> Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260916174229.2088824-1-vulab@iscas.ac.cn/ Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
8 daysdrm/mediatek: Fix pdev reference leak in mtk_drm_bind()Wentao Liang
When the device is not the mmsys master, mtk_drm_bind() returns early after taking a reference on the disp-mutex device via of_find_device_by_node(), without ever dropping it: mtk_drm_unbind() only puts mutex_dev for the master. Drop the reference before returning from the non-master path. Fixes: 1ef7ed48356c ("drm/mediatek: Modify mediatek-drm for mt8195 multi mmsys support") Cc: stable@vger.kernel.org Signed-off-by: Wentao Liang <vulab@iscas.ac.cn> Link: https://patchwork.kernel.org/project/linux-mediatek/patch/20260916174058.2088709-1-vulab@iscas.ac.cn/ Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
8 daysdrm/amdgpu: reset VI ASIC on MacBookPro14,3Francisco Beltrán Millalén
On a MacBookPro14,3 with a Radeon Pro 555 (Polaris11), the framebuffer is at MC address 0 when amdgpu loads after a cold boot, as the firmware leaves it (MC_VM_FB_LOCATION = 0x007f0000), while the VBIOS ASIC_Init table places it at 0xF4_0000_0000 (0xf47ff400). amdgpu reads the location once, at init, so after a re-POST (S3 resume or GPU reset) the framebuffer has moved and the driver keeps programming the old one: the SMU is handed a table that was never written and the GPU does not come back, which leaves the internal panel black. Resetting the ASIC on load makes ASIC_Init run before the driver reads the location, so the driver uses the VBIOS placement from the start and every later re-POST puts the framebuffer back where it already is. Add the Radeon Pro 555 used in this machine to the existing VI reset quirk table. Tested on a MacBookPro14,3 on 6.18.49 with the quirk table backported (the kernel also carries unrelated local PCI and ACPI patches for this machine). The framebuffer is at 0x000000F400000000 after both cold and warm boot, and the GPU survived 9 S3 cycles (lid close and rtcwake, one of them with the lid closed for about 7.5 minutes and a USB-C disk attached), each followed by a few minutes of 3D load; no ring timeouts or VM faults were reported. The reset adds about 0.23 s to amdgpu init. Suggested-by: Christian König <christian.koenig@amd.com> Suggested-by: Alex Deucher <alexander.deucher@amd.com> Link: https://lore.kernel.org/all/20260924132952.25054-1-fbeltranmillalen@gmail.com/ Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Francisco Beltrán Millalén <fbeltranmillalen@gmail.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit b6b1d97218518003107d4446fac278fa3e0a19a0) Cc: stable@vger.kernel.org
8 daysdrm/amd/pm/si: Fix updating clock limits on AC/DCTimur Kristóf
Assume that the AC limits are the maximum of all power states, and the DC limits are the maximum of battery power states. This shouldn't make any difference in practice, but is cleaner and more robust against bogus information in the VBIOS. Fixes: e6c5d36756e7 ("drm/amd/pm/si: Fix updating clock limits from power states") Signed-off-by: Timur Kristóf <timur.kristof@gmail.com> Reviewed-by: Mario Limonciello <mario.limonciello@amd.com> Link: https://patch.msgid.link/20260923120354.1027996-2-timur.kristof@gmail.com Signed-off-by: Mario Limonciello <mario.limonciello@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit ef8cb9dcc7db7b7abcbdbe870a080cc81e4f0bf3) Cc: stable@vger.kernel.org
8 daysdrm/amd/display: Fix stale replay_events after mod_power stream removalSimon Polack
[Why] mod_power_remove_stream() shifts the remaining power_entity slots down but does not move replay_events, and mod_power_add_stream() does not initialize it. replay_events therefore stay bound to the map slot instead of the stream. When several streams are disabled in one atomic commit, amdgpu_dm_mod_power_update_streams() removes them one after another. The eDP stream can then be looked up in a slot whose stale replay_events already have replay_event_hw_programming set, so amdgpu_dm_replay_set_event() returns early ("already in desired state") without calling mod_power_set_replay_event(). Replay is not disabled before the eDP panel is powered off. After DPMS on, the sink reports neither replay state nor frame lock (DPCD 0x378 = 0x00, no error bits), so the HPD IRQ recovery does not trigger and the panel stays black until a full modeset. Seen with an eDP panel using FreeSync Replay plus two DP-MST displays: DPMS off/on of all outputs leaves eDP black, while DPMS of eDP alone works. Doing an eDP-only DPMS first makes the next all-output DPMS fail reliably. [How] Shift replay_events together with the PSR cached fields in mod_power_remove_stream() and initialize it to replay_event_vsync in mod_power_add_stream(), matching the psr_event_vsync initial value used for PSR (both vsync events are driven together by amdgpu_dm_crtc_set_static_screen_optimze()). Tested on 7.3.0-rc3 (238650ef6c7c): the reproducer above now recovers reliably, and Replay still engages when the screen is idle. The issue was debugged with help from an AI assistant (Claude), which analysed ftrace/kprobe traces and the driver source, pointed to the missing replay_events handling and suggested this change. I collected the traces and built and tested the fix on the affected hardware. Fixes: 4cef2ac4c795 ("drm/amd/display: Introduce power module on Linux") Assisted-by: Claude:claude-opus-5 Signed-off-by: Simon Polack <spolack+git@mailbox.org> Reviewed-by: Ray Wu <ray.wu@amd.com> Tested-by: Daniel Wheeler <daniel.wheeler@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit 3d47e38e271195435e125527b224d11cfdb777b1) Cc: stable@vger.kernel.org
8 daysdrm/radeon: Read the VRAM VBIOS signature with readb()Imre Kaloz
igp_read_bios_from_vram() checked bios[0]/bios[1] with a plain __iomem load, which faults on sparc64 before the copy runs at all. radeon_read_bios() already reads its two signature bytes with readb() ahead of its own copy; use the same accessor here, keeping the check before the allocation. Fixes: b442962a9e82 ("drm/radeon/kms: add support for "Surround View"") Signed-off-by: Imre Kaloz <kaloz@kernel.org> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit 09155b8932e5013dbce0f5cdff7d75264a279ee5) Cc: stable@vger.kernel.org
8 daysdrm/amd/display: guard dc_sink dereferences in MST mode validationHari Mishal
dm_dp_mst_is_port_support_mode() reads aconnector->dc_sink->dsc_caps... for the DSC branch-throughput check, and get_conv_frl_bw()'s HDMI-PCON FRL-bandwidth path reads aconnector->dc_sink->edid_caps.max_frl_rate, both without a NULL check. dc_sink is cleared asynchronously on MST unplug, and both functions run from paths that the driver's own comments document as racing that teardown: the connector probe worker's ->mode_valid callback and a compositor's atomic check, neither of which holds the MST manager lock that the teardown path uses. The former does have an existing dsc_aux NULL check, but dsc_aux isn't reliably cleared in every path that clears dc_sink, so it doesn't cover this. Fail the port-support check and skip the FRL conversion path when the sink is already gone. Fixes: f04d275d94e1 ("drm/amd/display: add mst port output bw check") Fixes: 5c9b8b27a883 ("drm/amd/display: Tie FRL support into amdgpu_dm") Assisted-by: gkh_clanker_t1000 Signed-off-by: Hari Mishal <harimishal1@gmail.com> Reviewed-by: Fangzhi Zuo <jerry.zuo@amd.com> Tested-by: Daniel Wheeler <daniel.wheeler@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit 7c3db8da4e039698ae198c870712428644e965c7) Cc: stable@vger.kernel.org
8 daysdrm/amd/display: Try RGB before YCbCr 4:4:4 in stream validationgraftedAdrian Betschart
amdgpu_dm_create_validate_stream_for_sink() walks encoding_order[] and uses the first encoding that validates. YCbCr 4:4:4 is listed before RGB, so an HDMI sink that advertises 4:4:4 gets YCbCr 4:4:4 whenever the "color format" property is left at AUTO, even though RGB fits the same link. That contradicts the documented AUTO behaviour for HDMI in enum drm_connector_color_format (RGB, falling back to YCbCr 4:2:0 only when the bandwidth is not available or the mode is 4:2:0-only), which the amdgpu implementation of the property also describes. It also leaves the "Broadcast RGB" property without effect on such sinks, since the quantization range it selects only applies to RGB output. Try RGB first. The mask still holds every encoding the sink supports, so a mode that cannot carry RGB falls back exactly as before. For reference, v7.2 picked RGB here unless YCbCr 4:4:4 was forced through debugfs, while earlier kernels picked YCbCr 4:4:4 for any HDMI sink that advertised it. Fixes: 0b0ff65d3ca1 ("drm/amd/display: Refactor stream validation") Suggested-by: Adolfo Rodrigues <adolfotregosa@gmail.com> Assisted-by: Claude Code:claude-fable-5-1 Signed-off-by: Adrian Betschart <adrian.betschart@cinemaone.ch> Reviewed-by: Fangzhi Zuo <jerry.zuo@amd.com> Tested-by: Adolfo Rodrigues <adolfotregosa@gmail.com> Tested-by: Daniel Wheeler <daniel.wheeler@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit 7de432bc753133764dc40d37f9388da56de251e7)
9 daysMerge branch 'bpf-fix-objects-stuck-in-free_by_rcu_ttrace'Kumar Kartikeya Dwivedi
Alexei Starovoitov says: ==================== bpf: Fix objects stuck in free_by_rcu_ttrace From: Alexei Starovoitov <ast@kernel.org> The objects that bpf_mem_alloc frees while RCU tasks trace GP is in flight stay in free_by_rcu_ttrace list until the same bpf_mem_cache frees or allocates in bulk again. Patch 1 - refactoring. No functional change. Patch 2 - the fix. Patch 3 - selftest. Signed-off-by: Alexei Starovoitov <ast@kernel.org> ==================== Link: https://patch.msgid.link/20260930095920.601738-1-alexei.starovoitov@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
9 daysselftests/bpf: Add a test for objects stuck in free_by_rcu_ttracegraftedAlexei Starovoitov
Delete all elements of BPF_F_NO_PREALLOC hash map in one batch. The first free_bulk() starts RCU tasks trace GP and the rest of the elements are freed while it's in flight. Wait for call_rcu_ttrace_in_progress to clear in bpf_mem_cache of every cpu and check that free_by_rcu_ttrace and waiting_for_gp_ttrace lists are empty. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://lore.kernel.org/bpf/20260930095920.601738-4-alexei.starovoitov@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
9 daysselftests/bpf: Test packet range of pointers sharing an idgraftedAlexei Starovoitov
Add tests where two packet pointers share an id and tightening one pointer's umax from its var_off would put it less than their constant distance from the other's umax: with an index & 0x38 capped at 50, the base pointer keeps umax 50, so the pointer 8 bytes further on must keep umax 58, even though its known bits allow at most 56. These refused a valid program or accepted an out-of-bounds access before the fix: - check the advanced copy, load through the base: valid, was refused; - check the base, load the byte at base + 1 through a copy advanced by 8: was accepted; - check base + 4, load 4 bytes at base + 2 through base + 8: reads two bytes past the checked range, was accepted; - the same as the second with data_meta pointers checked against data: was accepted. These pass with and without the fix and cover nearby paths: - subtract an unknown scalar from a checked pointer and load below it (the range is kept across a new id); - reach a load through two paths whose checks cover 8 and 7 bytes after the loaded pointer; the second path must not be pruned by the first; - spill a copy of a pointer, check the pointer, fill the copy and load one byte past the checked range: the load is refused, and the copy has the range of the check. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://lore.kernel.org/bpf/20261001145255.855630-2-alexei.starovoitov@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
9 daysarm64/fpsimd: signal: Forbid non-streaming SVE payload on SME-only systemsMark Rutland
When system_supports_sme() is true but system_supports_sve() is false, restoring a specifically crafted SVE signal context can result in the task erroneously having non-streaming SVE state. Subsequent attempts to manipulate the task's FPSIMD/SVE/SME state can result in a variety of problems, including fatal EL1 UNDEFs. In such configurations, the kernel always creates an SVE signal context when delivering a signal, and this can only be in one of two states: (1) SVE_SIG_FLAG_SM is set, and an SVE payload is present containing streaming mode SVE state. The recorded VL is the task's live streaming VL. (2) SVE_SIG_FLAG_SM is clear, and an SVE payload is not present. The FPSIMD context contains the non-streaming mode FPSIMD state. The recorded VL is 0. Currently restore_sve_fpsimd_context() correctly rejects cases where SVE_SIG_FLAG_SM is set and an SVE payload is not present, but fails to reject cases where SVE_SIG_FLAG_SM is clear and an SVE payload is present. Consequently, restore_sve_fpsimd_context() can place the task in a state where it has non-streaming SVE state even when this is not supported by HW. For example, this can cause a later EL1 UNDEF when the kernel attempts to restore the task's ZCR_EL1 value: | # ./sme-sigcontext-to-sve | Internal error: Oops - Undefined instruction: 0000000002000000 [#1] SMP | Modules linked in: | CPU: 0 UID: 0 PID: 131 Comm: sme-sigcontext- Not tainted 7.3.0-rc1 #1 PREEMPT | Hardware name: linux,dummy-virt (DT) | pstate: 61402009 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) | pc : fpsimd_restore_current_state+0x258/0x458 | lr : exit_to_user_mode_loop+0xb8/0x188 | sp : ffff80008056be40 | x29: ffff80008056be40 x28: fff00000c1670000 x27: 0000000000000000 | x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000 | x23: ffff80008056bec0 x22: 0000000000000008 x21: 0000000000000040 | x20: 0000000000000081 x19: 0000000008800010 x18: 0000000000000000 | x17: 0000fffffd412570 x16: 0000000000001000 x15: 0000fffffd4123b0 | x14: 0000fffffd412780 x13: 0000fffffd412be8 x12: 0000000047435300 | x11: 0000fffffd412570 x10: 0000000000000000 x9 : 0000000045585401 | x8 : fff00000c18a6c44 x7 : 0000000000000000 x6 : 0000000000000002 | x5 : 0000000000000002 x4 : ffff800080568000 x3 : 0000000000000001 | x2 : 0000000008800010 x1 : fff00000c1670000 x0 : 0000000008800000 | Call trace: | fpsimd_restore_current_state+0x258/0x458 (P) | exit_to_user_mode_loop+0xb8/0x188 | el0_svc+0x1cc/0x1d0 | el0t_64_sync_handler+0xa0/0xe4 | el0t_64_sync+0x198/0x19c | Code: d5384101 f9400020 53175c03 36b80de0 (d5381202) | ---[ end trace 0000000000000000 ]--- | Kernel panic - not syncing: Oops - Undefined instruction: Fatal exception in interrupt | Kernel Offset: 0x291fb1000000 from 0xffff800080000000 | PHYS_OFFSET: 0x40000000 | CPU features: 0x0,00000000,0052802f,ffb88f43,3afcf73f | Memory Limit: none Rework restore_sve_fpsimd_context() to reject cases where SVE_SIG_FLAG_SM is clear and an SVE payload is not present. As parse_user_sigframe() rejects SVE signal frames when neither SVE nor SME are supported, it isn't necessary for restore_sve_fpsimd_context() to handle the case where neither are supported. Fixes: 7dde62f0687c ("arm64/signal: Always accept SVE signal frames on SME only systems") Signed-off-by: Mark Rutland <mark.rutland@arm.com> Reviewed-by: Mark Brown <broonie@kernel.org> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Will Deacon <will@kernel.org> Cc: stable@vger.kernel.org Signed-off-by: Will Deacon <will@kernel.org>
9 daysMerge tag 'iio-fixes-late-7.3' of ↵Greg Kroah-Hartman
ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio into char-misc-linus Jonathan writes: IIO: Fixes for 7.3, or 7.4 merge window. Nothing here strikes me as particularly urgent. The core buffer one has been there a long time and is a race only seen during driver removal. core - Ensure buffer teardown on remove occurs under same locks as in other paths, preventing races around access to active_scan_mask. adi,ad-sigma-delta - Fix a use-after-free in driver unbind path by just always allocating a buffer that is large enough rather than trying to resize at runtime. adi,ad4030 - Fix validation of oversampling_ratio to check if value is in range before using it. adi,ad7173 - Fix swapped masks for filter fields being written. adi,ad9000 - Fix a potential NULL dereference. kionix,kxcfjk-1013 - Reject disable of disabled event with underflows on runtime PM. inv,icm42607 - Don't eat runtime suspend errors. - Make sure to put runtime PM back on errors in system resume. isil,isl29501 - Fix a wrong return type for register_write function so it can return error codes. st,stm32-adc - Fix checking for whether a channel actually exists. - Avoid a possible division by zero. ti,pac1934 - Fix missing memory allocation check. * tag 'iio-fixes-late-7.3' of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio: iio: adc: ad_sigma_delta: fix use-after-free on unbind iio: accel: kxcjk-1013: reject duplicate event disable iio: buffer: serialize buffer teardown with mode claims iio: cdc: ad7150: fix OF matching and publish module aliases iio: adc: ade9000: fix NULL pointer dereference in clkout registration iio: adc: ad4030: fix invalid oversampling_ratio validation iio: adc: ad7173: Fix digital filter configuration iio: adc: stm32-adc: fix possible division by zero in processed channel iio: adc: stm32-adc: fix check on internal channel availability iio: proximity: isl29501: Fix return type of isl29501_register_write iio: imu: inv_icm42607: restore runtime PM on system resume errors iio: imu: inv_icm42607: propagate runtime suspend errors iio: adc: pac1934: check ACPI label duplication
9 daysarm64: errata: Add Cortex-A725 erratum 3821522 workaroundBeata Michalska
Cortex-A725 erratum 3821522 affects the CNT_CYCLES event, which can incur a significant increment error when a CPU enters and subsequently exits WFE or WFI, and may no longer track the system counter frequency. The AMEVCNTR01_EL0 counter is used as the AMU constant counter for frequency invariance and CPPC FFH feedback counters. Wire the affected Cortex-A725 range into the shared broken AMU constant-counter capability so the affected counter is treated as unavailable by returning zero in the AMU counter paths. This prevents the broken counter from being used as a reference source. The erratum can also affect PMUv3 users of the CNT_CYCLES event, but this workaround intentionally does not change PMU event handling. Hiding or rejecting the PMU event from the erratum code would change the perf-visible PMU event interface, including raw event selection, and would need a separate PMU-specific approach rather than being folded into the AMU reference-counter workaround. Cc: stable@vger.kernel.org Signed-off-by: Beata Michalska <beata.michalska@arm.com> Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com> Signed-off-by: Will Deacon <will@kernel.org>
9 daysarm64: errata: Factor out broken AMU const counter capBeata Michalska
Move the workaround from the erratum 2457168-specific cpucap to a generic broken AMU constant-counter one. This keeps the existing Cortex-A510 handling unchanged while allowing other errata with similar AMU constant counter issue to share the capability bit and call sites. Signed-off-by: Beata Michalska <beata.michalska@arm.com> Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com> Signed-off-by: Will Deacon <will@kernel.org>
9 daysperf: Require kernel access for text poke eventsZhengchuan Liang
Perf events with exclude_kernel=1 can be opened without kernel perf access. However, exclude_kernel does not suppress text-poke sideband records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL and contains a raw kernel instruction address. An unprivileged task can therefore open and mmap a task-local software event with text_poke=1. Both opening a count-only tracepoint event and configuring UDP GRO for ESP-in-UDP cause updates to inline static calls; the observer receives the relocated addresses of the modified instructions. For a known kernel image, any such address reveals the runtime kernel text base despite KASLR. Call perf_allow_kernel() whenever attr.text_poke is set, regardless of exclude_kernel. Events that neither monitor kernel execution nor request text-poke records retain their existing permissions. Fixes: e17d43b93e54 ("perf: Add perf text poke event") Assisted-by: LLM Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Cc: stable@vger.kernel.org Link: https://patch.msgid.link/99131354c41e23188f778b92f90363775b482395.1790573390.git.zcliangcn@gmail.com
9 daysperf: Replace perf_event_header__init_id with full header initIan Rogers
perf_iterate_sb() invokes its callback for each matching perf_event on the CPU and task context, passing a shared caller-allocated event structure. perf_event_header__init_id() mutated header->size in place by adding event->id_header_size, requiring sideband output callbacks to save and restore header fields across iterations. Three sideband callbacks failed to save and restore header.size around perf_event_header__init_id(): - perf_event_ksymbol_output() - perf_event_bpf_output() - perf_event_text_poke_output() When multiple events with attr.ksymbol, attr.bpf_event, or attr.text_poke and sample_id_all are active on the same CPU, each subsequent event receives a record whose header.size is inflated by all preceding events' id_header_size values while only a single id_sample is written, leaving uninitialized ring-buffer bytes at the end of the record and causing userspace perf to fail with -EFAULT ("Bad address") when parsing the sample_id trailer. Similarly, perf_event_mmap_output() set PERF_RECORD_MISC_MMAP_BUILD_ID in mmap_event->event_id.header.misc when event->attr.build_id was enabled, but only saved and restored header.size and header.type. If an event with attr.build_id was followed by an event with attr.mmap2 and !attr.build_id, the second event received PERF_RECORD_MISC_MMAP_BUILD_ID in header.misc while its payload contained maj/min/ino/ino_generation instead of a build ID. Rather than splitting header initialization between callers and output callbacks and saving/restoring mutated header fields, replace perf_event_header__init_id() with perf_event_header__init(), which initializes header->type, header->misc, and header->size alongside the sample_id fields on each invocation. Fixes: 76193a94522f ("perf, bpf: Introduce PERF_RECORD_KSYMBOL") Fixes: 6ee52e2a3fe4 ("perf, bpf: Introduce PERF_RECORD_BPF_EVENT") Fixes: e17d43b93e54 ("perf: Add perf text poke event") Fixes: 88a16a130933 ("perf: Add build id data in mmap2 event") Assisted-by: Antigravity:gemini-3.1-pro Signed-off-by: Ian Rogers <irogers@google.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://patch.msgid.link/20260929222332.973435-1-irogers@google.com Cc: stable@vger.kernel.org
9 daysperf: Fix race between perf_event_exit_task() and perf_pending_task()Luo Gengkun
A race condition exists between perf_event_exit_task() and perf_pending_task() during begin_new_exec(). During begin_new_exec(), perf_event_exit_task() may be called, and the PF_EXITING flag is not set on task. So perf_sigtrap() continues to execute and triggers WARN_ON_ONCE(event->ctx->task != current). Since both task exit and exec paths can call perf_event_exit_task() which sets ctx->task to TASK_TOMBSTONE, fix this by explicitly checking if event->ctx->task equals TASK_TOMBSTONE and dropping the redundant PF_EXITING check. Fixes: 97ba62b27867 ("perf: Add support for SIGTRAP on perf events") Signed-off-by: Luo Gengkun <luogengkun2@huawei.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://patch.msgid.link/20260920075026.990582-1-luogengkun2@huawei.com