<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-toradex.git/include/linux, branch master</title>
<subtitle>Linux kernel for Apalis and Colibri modules</subtitle>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/'/>
<entry>
<title>Merge tag 'net-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net</title>
<updated>2026-10-09T04:40:28+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-09T04:40:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=af32da41b0327b9c6a37856ba82b6760d6c8d10e'/>
<id>af32da41b0327b9c6a37856ba82b6760d6c8d10e</id>
<content type='text'>
Pull networking fixes from Jakub Kicinski:
 "Including fixes from wireless, wireguard, CAN and Bluetooth.
  We have one known regression to wrap up in VLAN handling.

  Current release - regressions:

   - Bluetooth: RFCOMM: fix deadlock on rfcomm_mutex

  Previous releases - regressions:

   - can: fix regression in handling RPS after migrating metadata to skb_ext

   - eth:
      - iavf: fix regressions in reconfig impacting bonding
      - mana: fix packet forwarding performance regression
      - stmmac: remove buggy VLAN acceleration support

  Previous releases - always broken:

   - a few high prio fixes for tun, and af_packet

   - amt: fix a UaF on tunnel teardown

   - eth:
      - bnxt: fix PCIe AER recovery and FLR handling issues
      - macb: don't modify Tx skbs before taking ownership
      - axienet: don't leak Tx skbs on interface stop

   - wifi:
      - nxpwifi: number of LLM-ish fixes
      - assorted mt76 fixes"

* tag 'net-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (128 commits)
  net: macb: copy shared skbs before appending the FCS
  net: macb: check TX ring before modifying skb
  vsock: Fix memory leak in vmci_transport_recv_dgram_cb()
  wireguard: noise: reject response consumption after intermediate initiation
  wireguard: queueing: preserve tstamp_type when encapsulating packet
  net: openvswitch: validate transport header presence in set_ipv6_addr
  net/smc: protect clcsock lifetime in smc_getname
  ipv6: do not warn on route notification size race
  ipv4: do not warn on route notification size race
  ipv4: validate checksum_start before completing checksum
  ptp: ocp: fix PCIe delay estimation calculation
  xen/netfront: don't leak the skb when xennet_fill_frags() fails
  net/packet: call packet_parse_headers after virtio_net_hdr_to_skb
  xen/netfront: drop RX packets with a short Ethernet header
  net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()
  net: sparx5: free the matchall entry on destroy
  selftests: mlxsw: Test port range occupancy on template create
  mlxsw: spectrum_flower: Fix port range register leak in tmplt_create()
  net: dsa: microchip: fix KSZ8765 fiber detection
  net/mlx5e: Order ICOSQ cc update after CQ doorbell
  ...
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull networking fixes from Jakub Kicinski:
 "Including fixes from wireless, wireguard, CAN and Bluetooth.
  We have one known regression to wrap up in VLAN handling.

  Current release - regressions:

   - Bluetooth: RFCOMM: fix deadlock on rfcomm_mutex

  Previous releases - regressions:

   - can: fix regression in handling RPS after migrating metadata to skb_ext

   - eth:
      - iavf: fix regressions in reconfig impacting bonding
      - mana: fix packet forwarding performance regression
      - stmmac: remove buggy VLAN acceleration support

  Previous releases - always broken:

   - a few high prio fixes for tun, and af_packet

   - amt: fix a UaF on tunnel teardown

   - eth:
      - bnxt: fix PCIe AER recovery and FLR handling issues
      - macb: don't modify Tx skbs before taking ownership
      - axienet: don't leak Tx skbs on interface stop

   - wifi:
      - nxpwifi: number of LLM-ish fixes
      - assorted mt76 fixes"

* tag 'net-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (128 commits)
  net: macb: copy shared skbs before appending the FCS
  net: macb: check TX ring before modifying skb
  vsock: Fix memory leak in vmci_transport_recv_dgram_cb()
  wireguard: noise: reject response consumption after intermediate initiation
  wireguard: queueing: preserve tstamp_type when encapsulating packet
  net: openvswitch: validate transport header presence in set_ipv6_addr
  net/smc: protect clcsock lifetime in smc_getname
  ipv6: do not warn on route notification size race
  ipv4: do not warn on route notification size race
  ipv4: validate checksum_start before completing checksum
  ptp: ocp: fix PCIe delay estimation calculation
  xen/netfront: don't leak the skb when xennet_fill_frags() fails
  net/packet: call packet_parse_headers after virtio_net_hdr_to_skb
  xen/netfront: drop RX packets with a short Ethernet header
  net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()
  net: sparx5: free the matchall entry on destroy
  selftests: mlxsw: Test port range occupancy on template create
  mlxsw: spectrum_flower: Fix port range register leak in tmplt_create()
  net: dsa: microchip: fix KSZ8765 fiber detection
  net/mlx5e: Order ICOSQ cc update after CQ doorbell
  ...
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'linux-can-fixes-for-7.3-20261001' of git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can</title>
<updated>2026-10-07T01:11:19+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-10-07T01:11:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=c8a900ded7759ca982910d3fb4a56f11529079b4'/>
<id>c8a900ded7759ca982910d3fb4a56f11529079b4</id>
<content type='text'>
Marc Kleine-Budde says:

====================
pull-request: can 2026-10-01

The first patch is by zjamg and restores the skb header initialization
lost during the v7.0 release cycle.

Oliver Hartkopp contributes a patch for the CAN net layer to fix the
unique skb identifier regression under RPS, introduced in the v7.0
release cycle, which causes lost packets.

The last patch is by Ji-Ze Hong and fixes a struct size mismatch in
the f81604 CAN driver, which results in a TX starvation.

* tag 'linux-can-fixes-for-7.3-20261001' of git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can:
  usb: f81604: fix struct f81604_int_data size mismatch
  can: fix unique skb identifier regression under RPS
  can: dev: init_can_skb(): restore skb header initialization
====================

Link: https://patch.msgid.link/20261001151905.1556270-1-mkl@pengutronix.de
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Marc Kleine-Budde says:

====================
pull-request: can 2026-10-01

The first patch is by zjamg and restores the skb header initialization
lost during the v7.0 release cycle.

Oliver Hartkopp contributes a patch for the CAN net layer to fix the
unique skb identifier regression under RPS, introduced in the v7.0
release cycle, which causes lost packets.

The last patch is by Ji-Ze Hong and fixes a struct size mismatch in
the f81604 CAN driver, which results in a TX starvation.

* tag 'linux-can-fixes-for-7.3-20261001' of git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can:
  usb: f81604: fix struct f81604_int_data size mismatch
  can: fix unique skb identifier regression under RPS
  can: dev: init_can_skb(): restore skb header initialization
====================

Link: https://patch.msgid.link/20261001151905.1556270-1-mkl@pengutronix.de
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'sched_ext-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext</title>
<updated>2026-10-07T00:03:46+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-07T00:03:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=762122d75e50e4919ef77afc2dffdc4931c5be87'/>
<id>762122d75e50e4919ef77afc2dffdc4931c5be87</id>
<content type='text'>
Pull sched_ext fixes from Tejun Heo:

 - Taking a CPU offline could hang, or stall until the watchdog ejected
   the BPF scheduler, when tasks on the dying CPU were still held by the
   scheduler or sitting on a user dispatch queue. Re-enqueue them onto
   the local queue when the runqueue goes offline so that the CPU pushes
   them off like the other sched classes.

 - The sequence number guarding against stale dispatches was per
   runqueue, so a task re-enqueued on another CPU could get the same
   number and a dispatch meant for its earlier instance was applied to
   the new one. Use a per-task counter.

 - A task dispatched to another CPU's local queue got its ops.dequeue()
   only when picked to run and flagged as a core-sched pick. Call it at
   insertion like for same-CPU dispatches.

* tag 'sched_ext-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext:
  sched_ext: Generate qseq from a per-task counter
  selftests/sched_ext: Add a test for ops.dequeue() on remote local DSQ moves
  sched_ext: Call ops.dequeue() when a task arrives on a remote local DSQ
  sched_ext: Fix CPU hotplug hang when a dying CPU's tasks sit in the BPF scheduler
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull sched_ext fixes from Tejun Heo:

 - Taking a CPU offline could hang, or stall until the watchdog ejected
   the BPF scheduler, when tasks on the dying CPU were still held by the
   scheduler or sitting on a user dispatch queue. Re-enqueue them onto
   the local queue when the runqueue goes offline so that the CPU pushes
   them off like the other sched classes.

 - The sequence number guarding against stale dispatches was per
   runqueue, so a task re-enqueued on another CPU could get the same
   number and a dispatch meant for its earlier instance was applied to
   the new one. Use a per-task counter.

 - A task dispatched to another CPU's local queue got its ops.dequeue()
   only when picked to run and flagged as a core-sched pick. Call it at
   insertion like for same-CPU dispatches.

* tag 'sched_ext-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext:
  sched_ext: Generate qseq from a per-task counter
  selftests/sched_ext: Add a test for ops.dequeue() on remote local DSQ moves
  sched_ext: Call ops.dequeue() when a task arrives on a remote local DSQ
  sched_ext: Fix CPU hotplug hang when a dying CPU's tasks sit in the BPF scheduler
</pre>
</div>
</content>
</entry>
<entry>
<title>net: always dissect GSO packets in __virtio_net_hdr_to_skb()</title>
<updated>2026-10-06T22:35:40+00:00</updated>
<author>
<name>Eric Dumazet</name>
<email>edumazet@kernel.org</email>
</author>
<published>2026-10-01T19:11:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=44378d02c5aaae24b60a75fbbb539b4aa4db503d'/>
<id>44378d02c5aaae24b60a75fbbb539b4aa4db503d</id>
<content type='text'>
Commit 9e8db5913264 ("net: avoid false positives in untrusted gso
validation") added a '&amp;&amp; skb-&gt;network_header' check before flow-dissecting
GSO packets without VIRTIO_NET_HDR_F_NEEDS_CSUM in
__virtio_net_hdr_to_skb(), because some callers (such as tun_get_user(),
tun_xdp_one(), virtnet_receive_done(), and raw_verify_header()) called
virtio_net_hdr_*_to_skb() before initializing skb-&gt;network_header and
skb-&gt;dev.

Because __alloc_skb() and __build_skb_around() zero-initialize
skb-&gt;network_header to 0 (unlike mac_header and transport_header which
are initialized to ~0U), those four callers always had
skb-&gt;network_header == 0 and bypassed flow dissection in
__virtio_net_hdr_to_skb(). More generally, skb-&gt;network_header is an
offset from skb-&gt;head (where 0 is also a valid offset whenever
skb_headroom(skb) is 0), not a boolean flag.

Whenever the 'if (gso_type &amp;&amp; skb-&gt;network_header)' branch was skipped,
the fallback 'else if (gso_type)' only pulled nh_min_len + thlen (40 bytes
for TCPv4) without dissecting the packet, without validating ip_proto or
n_proto, and without setting skb-&gt;transport_header.

If the packet has a malformed network header, it is not rejected and a
subsequent skb_probe_transport_header() also fails, leaving
skb-&gt;transport_header at ~0U (0xffff). Similarly, if an IPv4 packet
carries IP options (ihl &gt; 5) or an IPv6 packet carries extension headers,
pulling only nh_min_len + thlen can leave the TCP header outside
skb-&gt;head. In both cases, tcp_hdrlen(skb) in skb_gso_transport_seglen()
reads out-of-bounds:

  BUG: KASAN: slab-out-of-bounds in skb_gso_transport_seglen
  Read of size 2 by task poc/133
  skb_gso_transport_seglen (net/core/gso.c:155)
  skb_gso_validate_mac_len (net/core/gso.c:270)
  tbf_enqueue (net/sched/sch_tbf.c:260)
  dev_qdisc_enqueue (net/core/dev.c:4227)
  __dev_queue_xmit (net/core/dev.c:4884)

In addition, checking virtio_net_hdr_match_proto() only inside
'if (!skb-&gt;protocol)' before flow dissection both skipped validation when
skb-&gt;protocol was pre-set by the caller and rejected VLAN-tagged frames
whose outer L2 protocol is ETH_P_8021Q or ETH_P_8021AD.

Fix this by:
1. Initializing skb-&gt;dev and skb-&gt;network_header (plus skb-&gt;protocol for
   IFF_TUN) before virtio_net_hdr_*_to_skb() in tun_get_user(),
   tun_xdp_one(), virtnet_receive_done(), and raw_verify_header(). In
   tun_get_user(), drop the redundant skb_reset_mac_header(skb) in the
   IFF_TUN case since __virtio_net_hdr_to_skb() unconditionally resets
   mac_header.
2. Removing '&amp;&amp; skb-&gt;network_header' and the unvalidated
   'else if (gso_type)' fallback in __virtio_net_hdr_to_skb() so all GSO
   packets without VIRTIO_NET_HDR_F_NEEDS_CSUM are flow-dissected, have
   their transport header pulled into linear data, and have
   skb-&gt;transport_header set.
3. Moving the virtio_net_hdr_match_proto() check to after
   skb_flow_dissect_flow_keys_basic(), validating keys.basic.n_proto
   against hdr_gso_type.

Fixes: 9e8db5913264 ("net: avoid false positives in untrusted gso validation")
Fixes: d5be7f632bad ("net: validate untrusted gso packets without csum offload")
Fixes: 924a9bc362a5 ("net: check if protocol extracted by virtio_net_hdr_set_proto is correct")
Reported-by: Weiming Shi &lt;bestswngs@gmail.com&gt;
Closes: https://lore.kernel.org/netdev/20260927163117.746432-2-bestswngs@gmail.com/
Signed-off-by: Eric Dumazet &lt;edumazet@kernel.org&gt;
Reviewed-by: Willem de Bruijn &lt;willemb@google.com&gt;
Cc: Michael S. Tsirkin &lt;mst@redhat.com&gt;
Link: https://patch.msgid.link/20261001191140.2818991-3-edumazet@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Commit 9e8db5913264 ("net: avoid false positives in untrusted gso
validation") added a '&amp;&amp; skb-&gt;network_header' check before flow-dissecting
GSO packets without VIRTIO_NET_HDR_F_NEEDS_CSUM in
__virtio_net_hdr_to_skb(), because some callers (such as tun_get_user(),
tun_xdp_one(), virtnet_receive_done(), and raw_verify_header()) called
virtio_net_hdr_*_to_skb() before initializing skb-&gt;network_header and
skb-&gt;dev.

Because __alloc_skb() and __build_skb_around() zero-initialize
skb-&gt;network_header to 0 (unlike mac_header and transport_header which
are initialized to ~0U), those four callers always had
skb-&gt;network_header == 0 and bypassed flow dissection in
__virtio_net_hdr_to_skb(). More generally, skb-&gt;network_header is an
offset from skb-&gt;head (where 0 is also a valid offset whenever
skb_headroom(skb) is 0), not a boolean flag.

Whenever the 'if (gso_type &amp;&amp; skb-&gt;network_header)' branch was skipped,
the fallback 'else if (gso_type)' only pulled nh_min_len + thlen (40 bytes
for TCPv4) without dissecting the packet, without validating ip_proto or
n_proto, and without setting skb-&gt;transport_header.

If the packet has a malformed network header, it is not rejected and a
subsequent skb_probe_transport_header() also fails, leaving
skb-&gt;transport_header at ~0U (0xffff). Similarly, if an IPv4 packet
carries IP options (ihl &gt; 5) or an IPv6 packet carries extension headers,
pulling only nh_min_len + thlen can leave the TCP header outside
skb-&gt;head. In both cases, tcp_hdrlen(skb) in skb_gso_transport_seglen()
reads out-of-bounds:

  BUG: KASAN: slab-out-of-bounds in skb_gso_transport_seglen
  Read of size 2 by task poc/133
  skb_gso_transport_seglen (net/core/gso.c:155)
  skb_gso_validate_mac_len (net/core/gso.c:270)
  tbf_enqueue (net/sched/sch_tbf.c:260)
  dev_qdisc_enqueue (net/core/dev.c:4227)
  __dev_queue_xmit (net/core/dev.c:4884)

In addition, checking virtio_net_hdr_match_proto() only inside
'if (!skb-&gt;protocol)' before flow dissection both skipped validation when
skb-&gt;protocol was pre-set by the caller and rejected VLAN-tagged frames
whose outer L2 protocol is ETH_P_8021Q or ETH_P_8021AD.

Fix this by:
1. Initializing skb-&gt;dev and skb-&gt;network_header (plus skb-&gt;protocol for
   IFF_TUN) before virtio_net_hdr_*_to_skb() in tun_get_user(),
   tun_xdp_one(), virtnet_receive_done(), and raw_verify_header(). In
   tun_get_user(), drop the redundant skb_reset_mac_header(skb) in the
   IFF_TUN case since __virtio_net_hdr_to_skb() unconditionally resets
   mac_header.
2. Removing '&amp;&amp; skb-&gt;network_header' and the unvalidated
   'else if (gso_type)' fallback in __virtio_net_hdr_to_skb() so all GSO
   packets without VIRTIO_NET_HDR_F_NEEDS_CSUM are flow-dissected, have
   their transport header pulled into linear data, and have
   skb-&gt;transport_header set.
3. Moving the virtio_net_hdr_match_proto() check to after
   skb_flow_dissect_flow_keys_basic(), validating keys.basic.n_proto
   against hdr_gso_type.

Fixes: 9e8db5913264 ("net: avoid false positives in untrusted gso validation")
Fixes: d5be7f632bad ("net: validate untrusted gso packets without csum offload")
Fixes: 924a9bc362a5 ("net: check if protocol extracted by virtio_net_hdr_set_proto is correct")
Reported-by: Weiming Shi &lt;bestswngs@gmail.com&gt;
Closes: https://lore.kernel.org/netdev/20260927163117.746432-2-bestswngs@gmail.com/
Signed-off-by: Eric Dumazet &lt;edumazet@kernel.org&gt;
Reviewed-by: Willem de Bruijn &lt;willemb@google.com&gt;
Cc: Michael S. Tsirkin &lt;mst@redhat.com&gt;
Link: https://patch.msgid.link/20261001191140.2818991-3-edumazet@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'printk-for-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux</title>
<updated>2026-10-06T09:32:54+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-06T09:32:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=22430ae5d90ab288b0ee2ad99ae941f4a666b694'/>
<id>22430ae5d90ab288b0ee2ad99ae941f4a666b694</id>
<content type='text'>
Pull printk fix from Petr Mladek:

 - Allow using Braille console with a serial console driver converted
   to NBCON API

* tag 'printk-for-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux:
  braille: nbcon: Allow to use a serial console with NBCON API as Braille console
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull printk fix from Petr Mladek:

 - Allow using Braille console with a serial console driver converted
   to NBCON API

* tag 'printk-for-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux:
  braille: nbcon: Allow to use a serial console with NBCON API as Braille console
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:39:26+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:39:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=942e4a0e46bfd0efd3f87f70bf186c54aaaeb138'/>
<id>942e4a0e46bfd0efd3f87f70bf186c54aaaeb138</id>
<content type='text'>
Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-10-04T15:35:29+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-04T15:35:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=a27611f8994c9a4772156432badb533af33fd32d'/>
<id>a27611f8994c9a4772156432badb533af33fd32d</id>
<content type='text'>
Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
</pre>
</div>
</content>
</entry>
<entry>
<title>sched_ext: Generate qseq from a per-task counter</title>
<updated>2026-10-03T23:23:31+00:00</updated>
<author>
<name>Kuba Piecuch</name>
<email>jpiecuch@google.com</email>
</author>
<published>2026-10-03T11:53:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=e6ac89b8b1c12e9104df45a14a26e2dfa96ded06'/>
<id>e6ac89b8b1c12e9104df45a14a26e2dfa96ded06</id>
<content type='text'>
finish_dispatch() uses the qseq embedded in p-&gt;scx.ops_state to tell
whether the QUEUED instance of a task it's about to claim is the one
scx_bpf_dsq_insert() saw. qseq is generated from rq-&gt;scx.ops_qseq, but
the counters of different rqs are independent, so if a task is dequeued
and re-enqueued on a different rq between scx_bpf_dsq_insert() and
finish_dispatch(), the new QUEUED instance can end up with the same
qseq as the old one:

  CPU X                          CPU Z
  -----                          -----
                                 enqueue p on rq A, qseq = N
  ops.dispatch()
    scx_bpf_dsq_insert(p)
      records qseq N
                                 sched_setaffinity(p)
                                   dequeue p from rq A
                                   enqueue p on rq B, qseq = N
  finish_dispatch(p, N)
    qseq matches, p is claimed

The claim itself is still atomic so the core stays consistent, but an
insert issued for a previous QUEUED instance gets applied to a new one
which the BPF scheduler has just received through ops.enqueue(). This
breaks the guarantee that dispatches targeting a stale instance are
ignored.

Generate qseq from a per-task counter, p-&gt;scx.ops_qseq, instead so that
consecutive QUEUED instances of a task never share a qseq regardless of
which rq they're on. The counter is only updated in
scx_do_enqueue_task() with the task's rq locked, so no additional
synchronization is needed, and it fits in an existing hole in struct
sched_ext_entity on 64bit. Remove the now unused rq-&gt;scx.ops_qseq.

Never generate qseq 0. NONE and DISPATCHING don't carry a qseq, so
scx_bpf_dsq_insert() on a task in either state records 0. With a
per-task counter, every task's first QUEUED instance would otherwise get
qseq 0 and could be claimed by such an insert. Wrap the counter where
the QSEQ field wraps so that it can't reach a value that shifts to 0 on
32bit either.

Fixes: f0e1a0643a59 ("sched_ext: Implement BPF extensible scheduler class")
Cc: stable@vger.kernel.org # v6.12+
Assisted-by: Claude:claude-opus-5.5
Signed-off-by: Kuba Piecuch &lt;jpiecuch@google.com&gt;
Signed-off-by: Tejun Heo &lt;tj@kernel.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
finish_dispatch() uses the qseq embedded in p-&gt;scx.ops_state to tell
whether the QUEUED instance of a task it's about to claim is the one
scx_bpf_dsq_insert() saw. qseq is generated from rq-&gt;scx.ops_qseq, but
the counters of different rqs are independent, so if a task is dequeued
and re-enqueued on a different rq between scx_bpf_dsq_insert() and
finish_dispatch(), the new QUEUED instance can end up with the same
qseq as the old one:

  CPU X                          CPU Z
  -----                          -----
                                 enqueue p on rq A, qseq = N
  ops.dispatch()
    scx_bpf_dsq_insert(p)
      records qseq N
                                 sched_setaffinity(p)
                                   dequeue p from rq A
                                   enqueue p on rq B, qseq = N
  finish_dispatch(p, N)
    qseq matches, p is claimed

The claim itself is still atomic so the core stays consistent, but an
insert issued for a previous QUEUED instance gets applied to a new one
which the BPF scheduler has just received through ops.enqueue(). This
breaks the guarantee that dispatches targeting a stale instance are
ignored.

Generate qseq from a per-task counter, p-&gt;scx.ops_qseq, instead so that
consecutive QUEUED instances of a task never share a qseq regardless of
which rq they're on. The counter is only updated in
scx_do_enqueue_task() with the task's rq locked, so no additional
synchronization is needed, and it fits in an existing hole in struct
sched_ext_entity on 64bit. Remove the now unused rq-&gt;scx.ops_qseq.

Never generate qseq 0. NONE and DISPATCHING don't carry a qseq, so
scx_bpf_dsq_insert() on a task in either state records 0. With a
per-task counter, every task's first QUEUED instance would otherwise get
qseq 0 and could be claimed by such an insert. Wrap the counter where
the QSEQ field wraps so that it can't reach a value that shifts to 0 on
32bit either.

Fixes: f0e1a0643a59 ("sched_ext: Implement BPF extensible scheduler class")
Cc: stable@vger.kernel.org # v6.12+
Assisted-by: Claude:claude-opus-5.5
Signed-off-by: Kuba Piecuch &lt;jpiecuch@google.com&gt;
Signed-off-by: Tejun Heo &lt;tj@kernel.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty</title>
<updated>2026-10-03T15:59:37+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-03T15:59:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=9a32e0754d637c1d386a533ae36e41c8f4be8b10'/>
<id>9a32e0754d637c1d386a533ae36e41c8f4be8b10</id>
<content type='text'>
Pull tty/serial fixes from Greg KH:
 "Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major
  here, just lots of small fixes for reported issues, some of them very
  long-standing:

   - tty hangup fixes that have been there since the BKL days and kept
     tripping people up over time.

   - vt selection bugfix

   - other vt bugfixes (memory leaks and screen update fixes)

   - n_gsm bugfix

   - qcom-geni serial driver bugfix

   - 8250 serial driver bugfixes

   - other tiny serial driver fixes

  All of these have been in linux-next, the last few only a few days but
  testing here seems solid (this pull request was generated on that
  tree)"

* tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (37 commits)
  tty: add missing driver flag kernel-doc colon
  vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()
  vt: skip screen update for DEC alignment test on backgroup consoles
  vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF
  serial: sc16is7xx: reduce TX refill rate with half-FIFO trigger
  serial: sc16is7xx: refill TX FIFO below trigger using fresh TXLVL
  serial: tegra: don't clear the Tx FIFO on an Rx-only reset
  serial: sc16is7xx: fix TX gap caused by kfifo circular buffer wrap-around
  tty: fix saved termios reset race
  tty: serial: mpc52xx_uart: move static declarations up.
  tty: serial: max3100: shut down timer before freeing port
  tty: add break_wait kernel-doc
  serial: qcom-geni: keep registered console runtime active
  serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend
  serial: qcom-geni: avoid unused-function warning
  tty: serial: qcom_geni_serial: Keep console RX functional after deep idle
  soc: qcom: geni-se: Correct QUP Core ICC vote constants
  serial: 8250_bcm7271: fix use-after-free in brcmuart_remove()
  serial: vt8500: Fix clock reference leak in vt8500_serial_probe()
  kgdboc: Fix tty driver reference leak in configure_kgdboc()
  ...
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull tty/serial fixes from Greg KH:
 "Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major
  here, just lots of small fixes for reported issues, some of them very
  long-standing:

   - tty hangup fixes that have been there since the BKL days and kept
     tripping people up over time.

   - vt selection bugfix

   - other vt bugfixes (memory leaks and screen update fixes)

   - n_gsm bugfix

   - qcom-geni serial driver bugfix

   - 8250 serial driver bugfixes

   - other tiny serial driver fixes

  All of these have been in linux-next, the last few only a few days but
  testing here seems solid (this pull request was generated on that
  tree)"

* tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty: (37 commits)
  tty: add missing driver flag kernel-doc colon
  vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()
  vt: skip screen update for DEC alignment test on backgroup consoles
  vc_screen: reload vc pointer before if (ret) in vcs_write() to avoid UAF
  serial: sc16is7xx: reduce TX refill rate with half-FIFO trigger
  serial: sc16is7xx: refill TX FIFO below trigger using fresh TXLVL
  serial: tegra: don't clear the Tx FIFO on an Rx-only reset
  serial: sc16is7xx: fix TX gap caused by kfifo circular buffer wrap-around
  tty: fix saved termios reset race
  tty: serial: mpc52xx_uart: move static declarations up.
  tty: serial: max3100: shut down timer before freeing port
  tty: add break_wait kernel-doc
  serial: qcom-geni: keep registered console runtime active
  serial: qcom-geni: Fix unbalanced runtime PM resume for no_console_suspend
  serial: qcom-geni: avoid unused-function warning
  tty: serial: qcom_geni_serial: Keep console RX functional after deep idle
  soc: qcom: geni-se: Correct QUP Core ICC vote constants
  serial: 8250_bcm7271: fix use-after-free in brcmuart_remove()
  serial: vt8500: Fix clock reference leak in vt8500_serial_probe()
  kgdboc: Fix tty driver reference leak in configure_kgdboc()
  ...
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb</title>
<updated>2026-10-03T15:42:54+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-03T15:42:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=903e23eda5af2a5491e698838645f84a8f90379b'/>
<id>903e23eda5af2a5491e698838645f84a8f90379b</id>
<content type='text'>
Pull USB/Thunderbolt fixes from Greg KH:
 "Here is a big set of USB and Thunderbolt driver fixes for 7.3-rc6.
  They were delayed on my side due to conference travel, not the fault
  of the submitters at all. Included in here are:

   - lots of small thunderbolt fixes for reported issues due to more
     testing and devices and a few reverts as well based on that work

   - more usb-serial device ids added

   - usb-serial and cdc-acm driver hangup and other fixes

   - dwc3 driver fixes for reported problems

   - lots of usb gadget driver fixes as people again fuzz these drivers
     and send in fixes, which is nice to finally see

   - typec driver fixes for reported problems

   - octeon-hcd driver fixes for reported problems

   - more usb-storage quirks added

   - other small USB driver bugs resolved for reported problems

  All of these have been in linux-next without any reported issues"

* tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: (63 commits)
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  Revert "usb: dwc3: gadget: fix IRQ storm on invalid event buffer count"
  USB: gadget: dummy-hcd: Fix wait for outstanding request completions
  usb: typec: port-mapper: Only match USB4 port if host interface is available
  usb: cdns3: Fix NULL pointer dereference in cdns3_pci_probe
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  usb: typec: ucsi: Get the connector fwnode based on reg value
  usb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmd
  usb: core: clear both ep_in and ep_out for non-ep0 control endpoints
  USB: cdc-acm: skip URB restart in port_shutdown if disconnected
  usb: gadget: f_fs: Fix NULL pointer dereference in FUNCTIONFS_ENDPOINT_DESC
  usb: gadget: aspeed-vhub: cancel wake work on device removal
  thunderbolt: Disable CL states for the Anker Prime TB5 dock
  thunderbolt: stream: Announce support for FMODE_NOWAIT
  usb: typec: ucsi: displayport: Current CAM OOB index fixup
  usb: ohci-st: disable controller wakeup on removal
  usb: ohci-spear: disable controller wakeup on removal
  usb: ohci-s3c2410: disable controller wakeup on removal
  usb: ohci-da8xx: disable controller wakeup on cleanup
  usb: cdns3: fix use-after-free in cdns3_gadget_exit()
  ...
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Pull USB/Thunderbolt fixes from Greg KH:
 "Here is a big set of USB and Thunderbolt driver fixes for 7.3-rc6.
  They were delayed on my side due to conference travel, not the fault
  of the submitters at all. Included in here are:

   - lots of small thunderbolt fixes for reported issues due to more
     testing and devices and a few reverts as well based on that work

   - more usb-serial device ids added

   - usb-serial and cdc-acm driver hangup and other fixes

   - dwc3 driver fixes for reported problems

   - lots of usb gadget driver fixes as people again fuzz these drivers
     and send in fixes, which is nice to finally see

   - typec driver fixes for reported problems

   - octeon-hcd driver fixes for reported problems

   - more usb-storage quirks added

   - other small USB driver bugs resolved for reported problems

  All of these have been in linux-next without any reported issues"

* tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb: (63 commits)
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  Revert "usb: dwc3: gadget: fix IRQ storm on invalid event buffer count"
  USB: gadget: dummy-hcd: Fix wait for outstanding request completions
  usb: typec: port-mapper: Only match USB4 port if host interface is available
  usb: cdns3: Fix NULL pointer dereference in cdns3_pci_probe
  usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
  usb: typec: ucsi: Get the connector fwnode based on reg value
  usb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmd
  usb: core: clear both ep_in and ep_out for non-ep0 control endpoints
  USB: cdc-acm: skip URB restart in port_shutdown if disconnected
  usb: gadget: f_fs: Fix NULL pointer dereference in FUNCTIONFS_ENDPOINT_DESC
  usb: gadget: aspeed-vhub: cancel wake work on device removal
  thunderbolt: Disable CL states for the Anker Prime TB5 dock
  thunderbolt: stream: Announce support for FMODE_NOWAIT
  usb: typec: ucsi: displayport: Current CAM OOB index fixup
  usb: ohci-st: disable controller wakeup on removal
  usb: ohci-spear: disable controller wakeup on removal
  usb: ohci-s3c2410: disable controller wakeup on removal
  usb: ohci-da8xx: disable controller wakeup on cleanup
  usb: cdns3: fix use-after-free in cdns3_gadget_exit()
  ...
</pre>
</div>
</content>
</entry>
</feed>
