<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-toradex.git, branch master</title>
<subtitle>Linux kernel for Apalis and Colibri modules</subtitle>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/'/>
<entry>
<title>Merge tag 'keys-v7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd</title>
<updated>2026-10-06T02:51:54+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-06T02:51:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=2c3418fffa9d037b2038a6db48be63f9e2291806'/>
<id>2c3418fffa9d037b2038a6db48be63f9e2291806</id>
<content type='text'>
Pull keys fixes from Jarkko Sakkinen:

 - key_get_persistent() created a new persistent keyring if one did not
   exist, but failed to set a timeout on it in an error path, preventing
   GC.

   Call key_set_timeout() regardless of key_link() result if a
   persistent keyring was created.

 - __key_create_or_update() made a copy of keyring-&gt;restrict_link before
   holding keyring-&gt;sem, which could cause add_key() to be executed
   against stale keyring restrictions. Fix it by copying the value only
   after taking keyring-&gt;sem

* tag 'keys-v7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  KEYS: Fix add_key() race with keyring restriction
  keys: finalize persistent keyring timeout after link attempt
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull keys fixes from Jarkko Sakkinen:

 - key_get_persistent() created a new persistent keyring if one did not
   exist, but failed to set a timeout on it in an error path, preventing
   GC.

   Call key_set_timeout() regardless of key_link() result if a
   persistent keyring was created.

 - __key_create_or_update() made a copy of keyring-&gt;restrict_link before
   holding keyring-&gt;sem, which could cause add_key() to be executed
   against stale keyring restrictions. Fix it by copying the value only
   after taking keyring-&gt;sem

* tag 'keys-v7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  KEYS: Fix add_key() race with keyring restriction
  keys: finalize persistent keyring timeout after link attempt
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'selinux-pr-20261005' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux</title>
<updated>2026-10-05T14:36:06+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-05T14:36:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=67f0943b394d920b6c142aad8c6af94340342ae7'/>
<id>67f0943b394d920b6c142aad8c6af94340342ae7</id>
<content type='text'>
Pull selinux fixes from Paul Moore:

 - Preserve SECURITY_LSM_NATIVE_LABELS when reusing superblocks

   Similar to a previous fix (see the commit description of Stephen's
   fix) we need to check to see if we have already mounted/setup the
   superblock passed into the security_sb_set_mnt_opts() LSM hook so we
   don't mistakenly unset SECURITY_LSM_NATIVE_LABELS.

 - Fix a potential AVC sequence number data race

* tag 'selinux-pr-20261005' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: preserve NATIVE_LABELS on already-initialized sb in set_mnt_opts
  selinux: fix data race on AVC latest_notif
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull selinux fixes from Paul Moore:

 - Preserve SECURITY_LSM_NATIVE_LABELS when reusing superblocks

   Similar to a previous fix (see the commit description of Stephen's
   fix) we need to check to see if we have already mounted/setup the
   superblock passed into the security_sb_set_mnt_opts() LSM hook so we
   don't mistakenly unset SECURITY_LSM_NATIVE_LABELS.

 - Fix a potential AVC sequence number data race

* tag 'selinux-pr-20261005' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: preserve NATIVE_LABELS on already-initialized sb in set_mnt_opts
  selinux: fix data race on AVC latest_notif
</pre>
</div>
</content>
</entry>
<entry>
<title>Linux 7.3-rc6</title>
<updated>2026-10-04T20:45:25+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T20:45:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=a90ee4305c4a5df72c11b31dacfdc76e00fcf78a'/>
<id>a90ee4305c4a5df72c11b31dacfdc76e00fcf78a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>KEYS: Fix add_key() race with keyring restriction</title>
<updated>2026-10-04T18:09:32+00:00</updated>
<author>
<name>성병찬</name>
<email>tjdqudcks0424@naver.com</email>
</author>
<published>2026-09-30T04:18:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=dd3ea3fcba7c75493760cdbccd35f029597e8d5e'/>
<id>dd3ea3fcba7c75493760cdbccd35f029597e8d5e</id>
<content type='text'>
__key_create_or_update() snapshots keyring-&gt;restrict_link before taking
the destination keyring's semaphore.  keyring_restrict() installs a
restriction while holding that semaphore.

This allows a writer to observe no restriction, wait for the keyring
owner to install a reject-all restriction and return successfully, and
then link a key using the stale NULL snapshot.  The writer only needs
write permission on the destination keyring.

Move the restrict_link read after __key_link_lock() and
__key_link_begin().  The read and the subsequent restriction check are
then serialized with restriction installation by keyring-&gt;sem.

The race was reproduced on v7.2.8 in 19 executions where restriction
installation returned before the link completed.  All 19 linked the key
despite the reject-all restriction.  With this change, 312 executions
reached the same ordering and every add_key() call failed with -EPERM.

The issue was found by manual concurrency analysis assisted by AI-based
analysis and independently verified with a QEMU reproducer and kernel
instrumentation.

Fixes: 5ac7eace2d00 ("KEYS: Add a facility to restrict new links into a keyring")
Cc: stable@vger.kernel.org
Signed-off-by: 성병찬 &lt;tjdqudcks0424@naver.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
Link: https://lore.kernel.org/r/20260930041802.6114-1-tjdqudcks0424@naver.com
Signed-off-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
__key_create_or_update() snapshots keyring-&gt;restrict_link before taking
the destination keyring's semaphore.  keyring_restrict() installs a
restriction while holding that semaphore.

This allows a writer to observe no restriction, wait for the keyring
owner to install a reject-all restriction and return successfully, and
then link a key using the stale NULL snapshot.  The writer only needs
write permission on the destination keyring.

Move the restrict_link read after __key_link_lock() and
__key_link_begin().  The read and the subsequent restriction check are
then serialized with restriction installation by keyring-&gt;sem.

The race was reproduced on v7.2.8 in 19 executions where restriction
installation returned before the link completed.  All 19 linked the key
despite the reject-all restriction.  With this change, 312 executions
reached the same ordering and every add_key() call failed with -EPERM.

The issue was found by manual concurrency analysis assisted by AI-based
analysis and independently verified with a QEMU reproducer and kernel
instrumentation.

Fixes: 5ac7eace2d00 ("KEYS: Add a facility to restrict new links into a keyring")
Cc: stable@vger.kernel.org
Signed-off-by: 성병찬 &lt;tjdqudcks0424@naver.com&gt;
Reviewed-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
Link: https://lore.kernel.org/r/20260930041802.6114-1-tjdqudcks0424@naver.com
Signed-off-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>keys: finalize persistent keyring timeout after link attempt</title>
<updated>2026-10-04T18:09:32+00:00</updated>
<author>
<name>Karl Mehltretter</name>
<email>kmehltretter@gmail.com</email>
</author>
<published>2026-09-12T09:54:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=25bf14f817168079f731975b8998fc2af380f29e'/>
<id>25bf14f817168079f731975b8998fc2af380f29e</id>
<content type='text'>
When no keyring exists for the requested UID, KEYCTL_GET_PERSISTENT
creates and registers one before linking it to the requested destination.
The configured timeout is set only after the destination link succeeds.

A destination restricted with KEYCTL_RESTRICT_KEYRING makes that link fail
with -EPERM. With persistent_keyring_expiry set to 60 seconds, /proc/keys
still reports the registered keyring's expiry as "perm".
The failed call therefore leaves a quota-exempt keyring in the namespace's
hidden register, where it may remain until namespace teardown.

Rename the write-locked helper to key_get_or_create_persistent() and return
the key reference through a result parameter. Return 0 when it creates a
keyring and 1 when the retry finds an existing one. Return a negative error
on failure. Another caller may create the keyring between the initial
read-locked lookup and the retry under the write lock.

Set the timeout after permission checking and linking. Do this on success,
or on failure if the call allocated the keyring. This leaves a new keyring
collectible after failure without starting its timeout while linking is
still in progress.

Cc: stable@vger.kernel.org # v5.10+
Fixes: f36f8c75ae2e ("KEYS: Add per-user_namespace registers for persistent per-UID kerberos caches")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter &lt;kmehltretter@gmail.com&gt;
Link: https://lore.kernel.org/r/20260912095440.79864-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
Signed-off-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
When no keyring exists for the requested UID, KEYCTL_GET_PERSISTENT
creates and registers one before linking it to the requested destination.
The configured timeout is set only after the destination link succeeds.

A destination restricted with KEYCTL_RESTRICT_KEYRING makes that link fail
with -EPERM. With persistent_keyring_expiry set to 60 seconds, /proc/keys
still reports the registered keyring's expiry as "perm".
The failed call therefore leaves a quota-exempt keyring in the namespace's
hidden register, where it may remain until namespace teardown.

Rename the write-locked helper to key_get_or_create_persistent() and return
the key reference through a result parameter. Return 0 when it creates a
keyring and 1 when the retry finds an existing one. Return a negative error
on failure. Another caller may create the keyring between the initial
read-locked lookup and the retry under the write lock.

Set the timeout after permission checking and linking. Do this on success,
or on failure if the call allocated the keyring. This leaves a new keyring
collectible after failure without starting its timeout while linking is
still in progress.

Cc: stable@vger.kernel.org # v5.10+
Fixes: f36f8c75ae2e ("KEYS: Add per-user_namespace registers for persistent per-UID kerberos caches")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter &lt;kmehltretter@gmail.com&gt;
Link: https://lore.kernel.org/r/20260912095440.79864-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
Signed-off-by: Jarkko Sakkinen &lt;jarkko@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux</title>
<updated>2026-10-04T16:38:11+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T16:38:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=7704c4c5bb127673b4f0ead839919db573559e38'/>
<id>7704c4c5bb127673b4f0ead839919db573559e38</id>
<content type='text'>
Pull i2c fixes from Andi Shyti:
 "Three patches in xiic for fixing the block reads and a single cleanup
  in the at91 error path:

   - at91: also release DMA channels when deferring probe

   - xiic: fix SMBus block reads with PEC"

* tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: at91: release DMA channels when probe defers
  i2c: xiic: don't clobber msg-&gt;len to signal block-read completion
  i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO
  i2c: xiic: preserve PEC byte length in SMBus block read setup
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull i2c fixes from Andi Shyti:
 "Three patches in xiic for fixing the block reads and a single cleanup
  in the at91 error path:

   - at91: also release DMA channels when deferring probe

   - xiic: fix SMBus block reads with PEC"

* tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: at91: release DMA channels when probe defers
  i2c: xiic: don't clobber msg-&gt;len to signal block-read completion
  i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO
  i2c: xiic: preserve PEC byte length in SMBus block read setup
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:59:22+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:59:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=06ac073129191a01d77933ed381f89c67674db6f'/>
<id>06ac073129191a01d77933ed381f89c67674db6f</id>
<content type='text'>
Pull x86 fixes from Ingo Molnar:

 - Don't apply va_align to hugetlb mappings on AMD F15h systems
   that have custom va_align.bits values (Laurent Wandrebeck)

 - Fix PMD teardown handling regression flagged by lockdep
   (Mikhail Gavrilov)

 - Hide ptrace header register offset macros behind __ASSEMBLER__ or
   __FRAME_OFFSETS, to fix user-space build errors that may trigger
   if they happen to shadow these short and generic macro names
   (Nick Desaulniers)

* tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  {x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS
  x86/mm: Drop unnecessary PMD page copy when freeing
  x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull x86 fixes from Ingo Molnar:

 - Don't apply va_align to hugetlb mappings on AMD F15h systems
   that have custom va_align.bits values (Laurent Wandrebeck)

 - Fix PMD teardown handling regression flagged by lockdep
   (Mikhail Gavrilov)

 - Hide ptrace header register offset macros behind __ASSEMBLER__ or
   __FRAME_OFFSETS, to fix user-space build errors that may trigger
   if they happen to shadow these short and generic macro names
   (Nick Desaulniers)

* tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  {x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS
  x86/mm: Drop unnecessary PMD page copy when freeing
  x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:39:26+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:39:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=942e4a0e46bfd0efd3f87f70bf186c54aaaeb138'/>
<id>942e4a0e46bfd0efd3f87f70bf186c54aaaeb138</id>
<content type='text'>
Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:35:29+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:35:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=a27611f8994c9a4772156432badb533af33fd32d'/>
<id>a27611f8994c9a4772156432badb533af33fd32d</id>
<content type='text'>
Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:29:27+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:29:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=1c915d6007fab5b87a8c2516dfd37dd614875f9c'/>
<id>1c915d6007fab5b87a8c2516dfd37dd614875f9c</id>
<content type='text'>
Pull locking fixes from Ingo Molnar:

 - Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS
   (Kuan-Wei Chiu)

 - Fix futex private hash use-after-free on resize (Chris Mason)

* tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Fix private hash use-after-free on resize
  irq: Make refcount_interrupt kunit test selectable
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull locking fixes from Ingo Molnar:

 - Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS
   (Kuan-Wei Chiu)

 - Fix futex private hash use-after-free on resize (Chris Mason)

* tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Fix private hash use-after-free on resize
  irq: Make refcount_interrupt kunit test selectable
</pre>
</div>
</content>
</entry>
</feed>
