summaryrefslogtreecommitdiff
path: root/Documentation
AgeCommit message (Collapse)Author
111 min.Merge tag 'vfs-7.3-rc7.fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs Pull vfs fixes from Christian Brauner: "This contains fixes for the current development cycle. All of them came out of a review of the mount code that started with a bug report. The review modeled the corner cases of mount propagation, unmounting and mount reference counting and turned up a lot of bugs. Most of them years old. Most fixes come with a selftest. - Rework connected mounts. A mount that is unmounted together with its parent can stay attached to the parent to keep its mountpoint covered. That happens when the mountpoint is removed with rmdir(), unlink() or rename(), when a detached tree is dissolved, and for locked mounts in any umount that isn't synchronous, including the teardown of their mount namespace. The parent then owns the child and drops it on its own final mntput(). So any reference from the child's superblock back to one of its ancestors becomes a cycle that is never freed. A loop device backed by an image on a tmpfs and mounted on that same tmpfs is enough. Remove the directory the tmpfs is mounted on from the host, let the container's mount namespace exit, and the loop device, the tmpfs and the filesystem on the loop device are leaked for good. The same works with autofs, zram, ecryptfs, binfmt_misc, fuse passthrough, zloop, a mass storage gadget and md, and the selftests have reproducers for them. This has been possible since v4.1. It is also why "put_mnt_ns(): leave mounts connected" was reverted in -rc5. Keeping every mount of a dying mount namespace connected made these cycles trivial to create. Every unmounted mount is now detached from its parent. Where the mountpoint has to stay covered the mount leaves a cover on the parent instead, allocated together with the mount. A lookup on the unmounted parent that hits a cover finds an empty immutable directory or file on the private nullfs instance. Nothing leads from a cover to another mount, so no unmounted mount owns another one and no cycle can form. This is visible to userspace. A formerly connected mount can no longer be reached through its unmounted parent and ".." inside it leads nowhere, as for every other lazily unmounted mount. With that the private nullfs instance becomes reachable from userspace, so it now refuses mounts on top, is mounted read-only, and refuses fsnotify marks and file locks. Its inodes are shared by every holder and a watch or a lock would otherwise reach across users. may_decode_fh() now also decides its subtree check under a single mount_lock hold, as a racing umount could otherwise let it decode into what a locked child covered. - umount: * Don't silently unmount busy mounts. Since v4.13 propagate_umount() takes down propagated copies of the victim with children as long as each child is an overmount or another copy of the victim, but propagate_mount_busy() only ever checked copies without children or with just an overmount. A container that moved a tree beneath its copy of a host mount lost that tree from under its open file descriptor to a plain umount() on the host. propagate_mount_busy() now applies the same rules, walking each chain of copies once. * Don't let a migrating task hide its reference from umount(). mnt_get_count() sums the per-cpu counters under mount_lock but the mntget() and mntput() fast paths don't take it. A task that takes a reference on a cpu the sum has already passed and drops it after migrating to one the sum hasn't reached yet hides the reference it held to begin with, and umount() succeeds with the file still open. Gets and puts now live in separate per-cpu counters and all puts are summed before all gets with a full barrier in between, the way srcu_readers_active_idx_check() does it. mntget() is unchanged and mntput() gains an smp_wmb(). * Check each submount for references right before unmounting it. shrink_submounts() and mark_mounts_for_expiry() checked all their victims up front. Unmounting the first could move a busy overmount to where the next victim's propagated copy is looked up and it was then unmounted without a check. * Never expire a locked mount. A shrinkable mount moved beneath a locked mount with MOVE_MOUNT_BENEATH takes over the lock, and umount() of an unlocked ancestor expired it and revealed what it covered. That umount() now fails with EBUSY as it does for any other locked child. A lazy umount still takes the whole tree. - Overmounts and locked mounts: * Unhash a dentry before detaching the mounts on it. unlink(), rmdir() and rename() detach the mounts on the victim but only d_delete() it once its inode is unlocked, a window that includes an expedited RCU grace period. In between, a lookup from a mount namespace in which the dentry is a mountpoint found it hashed, positive and uncovered. Drop the dentry first, as d_invalidate() already does. * Don't reveal overmounted entries in refwalk. A refwalk that had grabbed the dentry before the unlink never rechecked it the way rcuwalk does with d_seq and mount_lock. Without any artificial widening three walkers read the covered file 27 times in a minute. step_into() now fails an unhashed dentry marked DCACHE_CANT_MOUNT with -ESTALE and the walk is retried. * Keep covered mounts covered in OPEN_TREE_NAMESPACE. Creating such a mount namespace only takes a user namespace and the copy followed bind mount rules: no children without AT_RECURSIVE and no unbindable mounts with it. An unprivileged user could see what mounts covered in the source, such as the parts of /proc and /sys that container runtimes mask. If the caller doesn't own the source mount namespace a non-recursive copy of a mount with something mounted below the requested directory is now refused and a recursive copy includes unbindable mounts, the way unshare() copies. * Keep the lock on a mount that a propagated copy is moved beneath. MNT_LOCKED moved to any mount that ended up beneath a locked mount, propagated copies included. A host mount and umount on a directory covered by a locked mount in a less privileged mount namespace left that cover unlocked for the namespace's owner to remove. Only mounts the caller places beneath take over the lock now. * Handle mount locking for automounts correctly. Which copies to lock was decided by the mount namespace of the task that triggered the automount. A task in a user namespace that triggered one on a host mount through a file descriptor got the host's own automount locked while its own copy stayed unlocked and could have nosuid, nodev and noexec cleared. Use the owner of the mount namespace the mount lands in. - Use-after-free and crashes: * Refuse an automount below a mount that is in no namespace. The private clones overlayfs uses for its layers have the MNT_NS_INTERNAL error pointer as their namespace, which finish_automount() let through and count_mounts() dereferenced. A fanotify filesystem mark on an overlayfs lower layer hands out file descriptors on such a clone. With debugfs as the lower layer opening "tracing" oopses with namespace_sem held for writing and every mount operation on the system blocks from then on. * Reset the old parent's ->overmount in mnt_change_mountpoint(). When propagate_umount() moved an overmount off a mount that a file descriptor kept alive, MOVE_MOUNT_BENEATH through that descriptor later followed the stale pointer into the freed overmount. * statmount() with STATMOUNT_BY_FD and pivot_root() read the parent of a mount that may be unmounted and only held by a file descriptor, while the parent's final mntput() can free it. statmount() now reads it under mount_lock and pivot_root() first checks that both mounts are in the caller's mount namespace. * Queue a mount only once for mount notifications. A mount reparented by one umount_tree() and taken down by the next under the same namespace_sem hold, as in shrink_submounts(), was queued twice. That cut the mounts queued in between out of notify_list while it still pointed at them, and once they were freed every later mount operation walked freed memory. * Don't let a pseudo dentry become the root of a mount. A bind mount of a bpf token file did that with a DCACHE_NORCU dentry, which is freed without an RCU grace period while lockless path walks may still look at it. Refuse to clone such a mount. * Don't inherit MNT_UMOUNT in clone_mnt(). A bind mount of a lazily unmounted nsfs or pidfs mount through its file descriptor started out flagged as unmounted. Among other things __detach_mounts() then dropped the namespace's reference on it, the mount outlived its namespace and mount_setattr() through the descriptor read the freed namespace. A recursive bind mount of such a mount also copied the unmounted stack still attached to it. That now fails with EINVAL, copying the mount itself still works. * Remove the fsnotify marks of a mount namespace in free_mnt_ns() instead of the RCU callback that frees the namespace, where taking the group mutexes meant sleeping in softirq context. - Propagation and copies: * Keep a copied mount unbindable. Since v6.17 clone_mnt() didn't copy the unbindable flag, so every mount namespace created with CLONE_NEWNS had bindable copies of all unbindable mounts. This had been fixed once before. * Refuse MOVE_MOUNT_SET_GROUP on an unbindable mount. It made the mount an unbindable slave, a state nothing else can produce, or silently dropped the unbindable flag. CRIU applies MS_UNBINDABLE after restoring sharing and isn't affected. * Check a recursive bind mount for mount namespace loops. Recursively bind mounting a tree from another mount namespace could put a mount of a namespace's file inside that same namespace, which then pins itself and all its mounts. Repeating it leaks without limit, the reproducer took Shmem from 380 kB to 65916 kB. The copy is now checked with check_for_nsfs_mounts() before it is grafted, as move_mount() does. * Look at the topmost mount for a mount namespace file. attach_recursive_mnt() never looked at the topmost mount of the source's chain of overmounts. If that was the chain's only mount namespace file an existing mount at a propagated destination got buried below the root of the nsfs file where no path walk reaches it. * Don't put a mountpoint on a dentry that's being removed. attach_recursive_mnt() makes a mountpoint of the source's root without its inode lock, so a racing rmdir() of that directory could leave a mount on it that nothing ever detaches. d_set_mounted() now checks cant_mount() as well. - nullfs: * Take no inode lock for readdir of an immutable directory. The root of every empty mount namespace is the same nullfs directory and iterate_dir() held its i_rwsem across ->iterate_shared(). A reader whose buffer faults on a FUSE mount of its own holds it for as long as its server wants, and with an exclusive locker queued behind it every lookup that misses the dcache, every create and every mount in that directory waits. One user of an empty mount namespace stalls all others. Directories with the new FOP_IMMUTABLE flag skip the lock. * Refuse to reconfigure internal superblocks through fspick(), MS_REMOUNT or the read-only remount that a synchronous umount() of the root does. For nullfs only root in the initial user namespace could do it, but the superblock is shared by every mount namespace and the flags showed up in statfs() for all of them. * Don't update the access time on nullfs and refuse F_SET_RW_HINT on an immutable inode. - unshare: Free an nsproxy that was never installed with nsproxy_free() when set_cred_ucounts() fails. put_nsproxy() dropped active references that were never taken, which triggered a warning and hid the caller's own namespaces from listns(). - Smaller changes: mount_setattr() checks the target before it walks the tree to allocate peer group ids, unshare() puts the old fs_struct before the old namespaces, dissolve_on_fput() drops the file's reference to the tree itself, disconnect_mount() is simplified and the documentation of the propagated unmount rule is brought up to date" * tag 'vfs-7.3-rc7.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs: (58 commits) namespace: simplify disconnect_mount() selftests/filesystems: test covered mounts namespace: rework connected mounts nullfs: add an empty immutable regular file selftests/filesystems: check that reading the root of an empty mount namespace stalls nobody selftests/filesystems: add a helper that holds a readdir in a page fault readdir: take no inode lock on an immutable directory nullfs: refuse file locks fsnotify: let a filesystem refuse marks on its objects namespace: nothing is mounted on or written through knullfs namespace: keep the private nullfs instance in knullfs fhandle: decide the subtree check under mount_lock selftests/filesystems: check that an automount below an overlay layer is refused selftests/filesystems: check the atime of the empty mount namespace root selftests/filesystems: check that a lock lands on the right mount and stays namespace: keep the lock on a mount that a propagated copy is moved beneath namespace: never expire a locked mount nullfs: don't update the access time namespace: handle mount locking for automounts correctly namespace: refuse an automount below a mount that is in no namespace ...
19 hoursMerge tag 'net-7.3-rc7' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net Pull networking fixes from Jakub Kicinski: "Including fixes from wireless, wireguard, CAN and Bluetooth. We have one known regression to wrap up in VLAN handling. Current release - regressions: - Bluetooth: RFCOMM: fix deadlock on rfcomm_mutex Previous releases - regressions: - can: fix regression in handling RPS after migrating metadata to skb_ext - eth: - iavf: fix regressions in reconfig impacting bonding - mana: fix packet forwarding performance regression - stmmac: remove buggy VLAN acceleration support Previous releases - always broken: - a few high prio fixes for tun, and af_packet - amt: fix a UaF on tunnel teardown - eth: - bnxt: fix PCIe AER recovery and FLR handling issues - macb: don't modify Tx skbs before taking ownership - axienet: don't leak Tx skbs on interface stop - wifi: - nxpwifi: number of LLM-ish fixes - assorted mt76 fixes" * tag 'net-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (128 commits) net: macb: copy shared skbs before appending the FCS net: macb: check TX ring before modifying skb vsock: Fix memory leak in vmci_transport_recv_dgram_cb() wireguard: noise: reject response consumption after intermediate initiation wireguard: queueing: preserve tstamp_type when encapsulating packet net: openvswitch: validate transport header presence in set_ipv6_addr net/smc: protect clcsock lifetime in smc_getname ipv6: do not warn on route notification size race ipv4: do not warn on route notification size race ipv4: validate checksum_start before completing checksum ptp: ocp: fix PCIe delay estimation calculation xen/netfront: don't leak the skb when xennet_fill_frags() fails net/packet: call packet_parse_headers after virtio_net_hdr_to_skb xen/netfront: drop RX packets with a short Ethernet header net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits() net: sparx5: free the matchall entry on destroy selftests: mlxsw: Test port range occupancy on template create mlxsw: spectrum_flower: Fix port range register leak in tmplt_create() net: dsa: microchip: fix KSZ8765 fiber detection net/mlx5e: Order ICOSQ cc update after CQ doorbell ...
32 hoursMerge tag 'ext4_for_linus-7.3-rc7' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4 Pull ext4 fixes from Ted Ts'o: "Mark the ext4 data=journal feature as being deprecated and will be removed in 2028. Also designate the primary branch that Sashiko and other tools use to find the primary development branch in the ext4 tree" * tag 'ext4_for_linus-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4: ext4: mark data=journal as deprecated and will be removed in January 2028. MAINTAINERS: name the ext4 dev branch
32 hoursext4: mark data=journal as deprecated and will be removed in January 2028.Theodore Ts'o
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
3 daysstrparser: make sure __strp_recv isn't running before tearing down the parserSabrina Dubroca
The comment above strp_done() claims that if strp is stopped, strp_recv will no longer be called. That's only true if the caller has a mechanism (eg locking) to guarantee that strp_recv() calls that started before strp_stop() have completed by the time we call strp_done(). This adds a dummy lock_sock/release_sock pair to guarantee that any in-flight strp_recv() (which runs under either bh_lock_sock or lock_sock, depending if it's called from ->sk_data_ready or strp_work) has completed. Only espintcp can be affected by this race condition, but this patch makes sure no future user of strp can have the bug. This could crash on strp->sk ("general mode" of strp), but this mode has been here for 9 years and has never been used. It'll be gone soon, no point worrying about it. Switch the stopped/paused/etc bits to u8's to avoid races between strp_stop() and strp_pause/unpause(). A reproducer has been published and turns the possible UAF into an exploit [1]. Reported-by: Hyunwoo Kim <imv4bel@gmail.com> Link: https://lore.kernel.org/all/aZLn2Faeg1FB7XOf@v4bel/ Link: https://lore.kernel.org/all/aZgpkyTDU3aXe_V0@v4bel/ Link: https://github.com/m0x41nos/RustyTux [1] Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)") Cc: stable@vger.kernel.org Signed-off-by: Sabrina Dubroca <sd@queasysnail.net> Reviewed-by: Hyunwoo Kim <imv4bel@gmail.com> Link: https://patch.msgid.link/425d9d926709b542ed5331110c19fee4aee1f28d.1791206940.git.sd@queasysnail.net Signed-off-by: Jakub Kicinski <kuba@kernel.org>
3 daysnamespace: rework connected mountsChristian Brauner
UMOUNT_CONNECTED as implemented allows for the creation of reference count cycles. Here's a simple example mkdir /x; mkfifo /ready /go unshare -m sh -c 'mount -t tmpfs tmpfs /x truncate -s 8M /x/img; mkfs.ext4 -q /x/img dev=$(losetup -f --show /x/img) mkdir /x/mp; mount $dev /x/mp echo $dev > /ready; read r < /go' & read dev < /ready rmdir /x echo > /go wait losetup -d $dev losetup -a Take a directory /x on the host, create a new mount namespace, mount a tmpfs on /x, use a file on that tmpfs as the backing file for a loop device, mount that loop device on that tmpfs. Now rmdir /x on the host. This will lazily unmount the mount on top of /x in the container with UMOUNT_CONNECTED. Once the namespace exits nothing references the mount anymore. Now the tmpfs is pinned by the backing file of the loop device and the loop mount is owned by the tmpfs superblock. Fun fact, such cycles can be formed by at least the following subsystems and I have added reproducers for all of them: (1) a loop mount P from an image on a tmpfs next to it, so that P's death shows as the loop device giving up its backing file (2) autofs with a FIFO on P as its pipe, zram with a device node on P as its writeback device, both on a minix image since vfat has neither (3) ecryptfs with its lower directory on P, under a passphrase token added to the session keyring (4) binfmt_misc in a new user namespace with an 'F' interpreter on P (5) a fuse server that answers FUSE_INIT with passthrough on and registers a file on P as a backing file (6) zloop with its zone files in a directory on P (7) a mass storage gadget on the dummy UDC with its LUN file on P, mounted from the SCSI disk the gadget shows up as (8) md with a RAID1 of one loop device and its bitmap file on P, which skips while SET_BITMAP_FILE has no way to succeed (9) rmdir of P's mountpoint from the parent, then the child exits, then the device must be free and LOOP_CLR_FD must release the file The underlying mechanism is UMOUNT_CONNECTED (MNT_LOCKED falls into the same class). With UMOUNT_CONNECTED an unmounted mount stays attached to its parent. This is used to protect revealing the underlying mount and is a non-negotiable security mechanism. So now the parent owns that mount and is put on the parent's final mntput(). That moves it to mnt_stuck_children and ultimately it's cleaned up by cleanup_mnt(). The fact that ownership of the child mount gets transferred to the parent turns every reference from a child's superblock back to one of its ancestors into a cycle. Don't keep the child attached at all. What the parent needs is that a lookup at the child's mountpoint keeps finding some mount, not the child itself and it's not a guarantee we have given really. When an unmounted mount would have stayed attached to its unmounted parent disconnect it like every other unmounted mount and leave a marker behind. A lookup on the parent that misses the mount hash and hits a marker finds knullfs. Either a file or a directory. Nothing leads from a marker to any other mount. The marker is owned by the parent and dropped by the parent's final mntput() or by __detach_mounts() when the mountpoint is deleted from under it. It is allocated together with the mount. With that every unmounted mount is a root and holds only its own reference which namespace_unlock() drops. No unmounted mount owns another one. A superblock that pins an ancestor can't form a cycle. It has a visible change. Mounts left connected (rmdir etc.) used to stay traversable through the parent for as long as something held the parent. Now it is detached with the umount. It lives as long as something references it but it isn't reachable through the parent anymore and ".." inside it leads nowhere which is the same as for every other lazily unmounted mount. Link: https://gist.github.com/mvo5/63ef46482349f3b1c3957d463a0c9c6f Link: https://patch.msgid.link/20261002-work-mount-cover-v1-2-232a8f52b43c@kernel.org Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
6 daysMerge tag 'char-misc-7.3-rc6' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc Pull char/misc/IIO fixes from Greg KH: "Here is a set of char/misc/iio and other small driver subsystem fixes for 7.3-rc6 that resolve a number of reported issues. Included in here are: - lots of small iio driver fixes for reported problems - interconnect driver revert to resolve a regression - nitro_enclaves driver fix for a use-after-free - binder driver fixes for reported problems (in both the rust and C versions) All of these have been in linux-next with no reported issues" * tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (63 commits) iio: adc: ad_sigma_delta: fix use-after-free on unbind iio: accel: kxcjk-1013: reject duplicate event disable iio: buffer: serialize buffer teardown with mode claims iio: cdc: ad7150: fix OF matching and publish module aliases iio: adc: ade9000: fix NULL pointer dereference in clkout registration iio: adc: ad4030: fix invalid oversampling_ratio validation iio: adc: ad7173: Fix digital filter configuration iio: adc: stm32-adc: fix possible division by zero in processed channel iio: adc: stm32-adc: fix check on internal channel availability iio: proximity: isl29501: Fix return type of isl29501_register_write iio: imu: inv_icm42607: restore runtime PM on system resume errors iio: imu: inv_icm42607: propagate runtime suspend errors iio: adc: pac1934: check ACPI label duplication rust_binderfs: add transaction_report feature entry rust_binder: reschedule node refcount update on thread exit rust_binder: cancel deferred work items in thread exit binderfs: fix UAF write in binder_add_device binder: fix is_failure flag for superseded transaction cleanup binder: fix leaked fd fixups on TF_UPDATE_TXN supersede Revert "interconnect: qcom: x1e80100: enable QoS configuration" ...
6 daysMerge tag 'arm64-fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux Pull arm64 fixes from Will Deacon: "Half of this is broken hardware (AMU counters and TLB invalidation) and the other half is broken software (frequency scaling and signals). So it seems as though we're all as bad as each other. The AMU workaround is a little noisy, as it refactors an existing workaround so that it can more easily be applied to additional CPUs. Summary: - Fix handling of CPU erratum #2645198 when batching pte updates - Fix truncation of CPU frequency calculation by using 64-bit arithmetic in arch_freq_get_on_cpu() - Work around AMU erratum #3821522 on Cortex-A725 - Fix panic when trying to restore an SVE sigframe on a CPU that only supports SME" * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux: arm64/fpsimd: signal: Forbid non-streaming SVE payload on SME-only systems arm64: errata: Add Cortex-A725 erratum 3821522 workaround arm64: errata: Factor out broken AMU const counter cap arm64: topology: fix arch_freq_get_on_cpu() overflow above 4.19 GHz arm64: mm: Fix the break-before-make flush range for erratum 2645198
7 daysMerge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linuxLinus Torvalds
Pull smb client fixes from Paulo Alcantara: "Fix a series of data corruption and I/O error bugs found by running generic/363 (fsx) in a loop against Windows Server 2022 and Samba. - Stop data dirtied past EOF through an mmap from reappearing as file content once the file is extended by a write, truncate, zero range, copy range or clone range - Flush dirty data and drain in-flight I/O before operations that assume the pagecache and the server agree on the file: querying allocated ranges, the O_TRUNC open, interior zero range, and server-side copy/clone - Stop a genuine size-extending zero range or preallocate from being refused with -EOPNOTSUPP when the inode is not read caching, by querying the server's authoritative EOF instead of trusting a stale cached i_size - Zero the untransferred tail of a short read, both in the netfs read-gaps path (where stale folio content could otherwise be written back to the server) and in the DIO/unbuffered read collector, and tell a real EOF apart from a stale cached remote_i_size after a lease downgrade - Require stable pages on signed connections so a buffered write can't modify a folio whose signature has already been computed and is in flight, which the server rejected with STATUS_ACCESS_DENIED and the client surfaced as -EIO - Split several cifsFileInfo flags out of a shared bitfield byte so concurrent updates taken under different locks no longer clobber each other through a byte-level RMW" * tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux: smb: client: split cifsFileInfo bitfields to avoid shared-byte RMW races smb: client: require stable pages for signed connections smb: client: distinguish real EOF from a stale remote_i_size on read netfs: zero the tail of a short DIO/unbuffered read smb: client: only require read lease for size-extending preallocate netfs: zero gaps in read-gaps folio to avoid writing back stale data smb: client: only require read lease for size-extending zero range smb: client: drain and invalidate before server-side copy/clone smb: client: flush dirty data before zeroing a range smb: client: drain outstanding I/O before truncating on O_TRUNC open smb: client: flush and commit data before querying allocated ranges smb: client: discard post-EOF pagecache when extending a file via clone range smb: client: discard post-EOF pagecache when extending a file via copy range smb: client: discard post-EOF pagecache when extending a file via zero range smb: client: clear post-EOF pagecache when extending a file via truncate netfs: clear post-EOF pagecache when extending a file via write
8 daysarm64: errata: Add Cortex-A725 erratum 3821522 workaroundBeata Michalska
Cortex-A725 erratum 3821522 affects the CNT_CYCLES event, which can incur a significant increment error when a CPU enters and subsequently exits WFE or WFI, and may no longer track the system counter frequency. The AMEVCNTR01_EL0 counter is used as the AMU constant counter for frequency invariance and CPPC FFH feedback counters. Wire the affected Cortex-A725 range into the shared broken AMU constant-counter capability so the affected counter is treated as unavailable by returning zero in the AMU counter paths. This prevents the broken counter from being used as a reference source. The erratum can also affect PMUv3 users of the CNT_CYCLES event, but this workaround intentionally does not change PMU event handling. Hiding or rejecting the PMU event from the erratum code would change the perf-visible PMU event interface, including raw event selection, and would need a separate PMU-specific approach rather than being folded into the AMU reference-counter workaround. Cc: stable@vger.kernel.org Signed-off-by: Beata Michalska <beata.michalska@arm.com> Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com> Signed-off-by: Will Deacon <will@kernel.org>
9 daysnetfs: clear post-EOF pagecache when extending a file via writePaulo Alcantara
Fix netfs to erase the contents of a hole created after the EOF by an ordinary write if dirty data has been previously left there by writes through an mmapped region. Neither the buffered nor the unbuffered/DIO write path clears that stale pagecache. Zero the tail of the folio straddling the EOF before an extending write. That is the only folio that can hold data written past the EOF through an mmap, as pages wholly beyond the EOF can't be faulted in. The folio is zeroed rather than dropped so a concurrent extending write can't lose data. Both write paths downgrade the i_rwsem to shared, so extending writes can run concurrently and the i_size read by the caller may be stale by the time the folio is locked. Re-read i_size under the folio lock and clamp the zeroed range up to it, so a racing write that already put data into the folio isn't clobbered. Wait for any writeback on the folio to finish before zeroing it so that the pagecache isn't modified while it may still be read by the transport during transmission. Honour IOCB_NOWAIT by returning -EAGAIN rather than blocking on the folio lock, on writeback, or in folio_mkclean()'s rmap walk when the folio is mapped. truncate_pagecache() can't be used here: it must be called with the i_rwsem held exclusively, but these write paths only hold it shared, and it would block unconditionally, breaking IOCB_NOWAIT. Callers that hold i_rwsem exclusively for the whole resize (truncate, setattr, fallocate, clone) exclude any genuine concurrent buffered writer, so staleness can instead be decided from the folio's dirty state, as pagecache_isize_extended() already does for filesystems that serialise writes against truncate/setattr via a single i_rwsem. Export netfs_clear_stale_post_isize() helper to handle such case. The helper is required by the CIFS client to fix generic/363. Closes: https://sashiko.dev/#/patchset/20260921230755.1133425-1-pc%40manguebit.org Fixes: 938e13a73b24 ("netfs: Implement buffered write API") Fixes: 153a9961b551 ("netfs: Implement unbuffered/DIO write support") Reviewed-by: David Howells <dhowells@redhat.com> Reviewed-by: Namjae Jeon <linkinjeon@kernel.org> Signed-off-by: Paulo Alcantara <pc@manguebit.org> Cc: Christian Brauner <brauner@kernel.org> Cc: Matthew Wilcox <willy@infradead.org> Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com> Cc: Shyam Prasad N <sprasad@microsoft.com> Cc: Tom Talpey <tom@talpey.com> Cc: Bharath SM <bharathsm@microsoft.com> Cc: stable@vger.kernel.org
13 daysMerge tag 'ata-7.3-rc5' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux Pull ata fixes from Niklas Cassel: - Extend the quirk "no LPM on ATI" quirk, that is currently only applied for Samsung drives, to include AMD controllers as well. The AMD AHCI controllers are newer versions of the ATI AHCI controllers, and these controllers still have LPM issues with Samsung drives - LPM works with drives from other vendors (me) - Fix errors in the libata.force parameter documentation (me) - Verify the sense data descriptor lengths for ATA PASS-THROUGH command, so that a malicious device cannot write past the buffer length (Matthias) - Mention the libata for-next branch in MAINTAINERS such that the git ls-remote command done by get_maintainer.pl --self-test=scm can verify it (Matthias) * tag 'ata-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux: MAINTAINERS: name the libata/linux for-next branch ata: libata-scsi: bound the ATA passthru sense descriptor writes ata: libata: Correct libata.force parameter documentation ata: libata-core: Extend Samsung LPM quirk to AMD controllers
2026-09-25Merge tag 's390-7.3-4' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux Pull s390 fixes from Heiko Carstens: - Fix several bugs in PCI error recovery SCLP reporting: don't report success on skipped recovery, report errors when no pdev is associated, add missing device lock, and fix struct pci_dev reference leak in zpci_report_status() - Fix several bugs in CIO code: fix use of invalid SCHIB data, guard PMCW field accesses, check device number valid bit in PMWC before accessing other fields, and fix NULL pointer dereference in ccw_device_get_util_str() - Fix virtual vs physical address confusion in channel measurement facility code on kernels with CONFIG_RANDOMIZE_IDENTITY_BASE=y - Fix couple of bugs in s390dbf: fix copy of failed static debug areas, skip view registration on failure, and reject NULL pointer in debug_dump() - Fix sriov_numvfs attribute name in zPCI documentation - Fix typos in comments * tag 's390-7.3-4' of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux: s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() s390/debug: Fix NULL pointer dereference in debug_info_copy() s390/debug: Do not register views for failed static debug areas s390/debug: Reject NULL debug info in debug_dump() s390/cmf: Fix virtual vs physical address confusion s390/pci: Don't report recovery success on skipped recovery s390/pci: Report SCLP status on error events when no pdev is associated s390/pci: Fix missing device lock in zpci_report_status() s390/pci: Fix leak of struct pci_dev reference in zpci_report_status() s390/cio: Guard PMCW field accesses with dnv check s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points s390/cio: Fix cio_update_schib() to not cache invalid schib s390/pci/docs: Fix sriov_numvfs attribute name s390: Fix typos in comments
2026-09-25docs: update the unmount propagation ruleChristian Brauner
Section 5f still describes the rule propagate_umount() used before commit f0d0ba19985d ("Rewrite of propagate_umount()"). It states that a mount that receives the unmount by propagation is left alone as soon as it has any submount. That's not true anymore. A propagated unmount unmounts a mount with sub-mounts as long as every sub-mount gets unmounted together with it. This is the case when the sub-mounts are unmounted by the same propagation. Only a sub-mount that cannot be unmounted keeps its parent mounted. The section also only describes a single mount without sub-mounts. But lazy unmounts take a tree and every mount of the tree propagates its unmount from its parent mount. Link: https://patch.msgid.link/20260923-work-mount-fixes-v1-8-f424cf8d3242@kernel.org Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
2026-09-24Merge tag 'net-7.3-rc5' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net Pull networking fixes from Jakub Kicinski: "Including fixes from Bluetooth, NFC and Netfilter. Every week in this release is record-setting for number of posted patches. It doesn't seem like we're creating any regressions with all these fixes, three 'Fixes' tags here point to 7.2 commits but none are true regression fixes. We're trying to keep the count down, nonetheless. Previous releases - regressions: - net: don't require the hwtstamp NDOs when a PHY provides timestamping - ipv6: fix dst leak for uncached routes - vrf: stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Previous releases - always broken: - packet: use ubuf_info completion for TX_RING packets - arp: terminate device name before lookup - ipv6: do not let ipv6_find_hdr() return an offset past the packet end - udp: remove a disconnected socket from the 4-tuple hash table - sctp: discard the rest of the packet on a stale-cookie error - eth: mlx5: Bridge, fix remaining switchdev ownership gaps on merged eswitch" [ And lots of other random network driver fixes ] * tag 'net-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (189 commits) tcp: prevent collapsing skbs across boundary in rtx queue vlan: ensure sufficient headroom in vlan_dev_hard_header() net/sched: sch_teql: fix shadowed err in __teql_resolve() bridge: check llc_mac_hdr_init() return value in br_send_bpdu() llc: fix skb UAF and leaks on llc_mac_hdr_init() failure llc: reserve device headroom for allocated frames gve: DQO: reject TSO packets with an out of range MSS gve: fix TX drop when GSO MSS is too small for hw gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO net: flush skb_defer_nodes in dev_cpu_dead() net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails af_packet: fix integer overflow in prb_calc_retire_blk_tmo() tipc: Fix a data race on mon->peer_cnt in mon_timeout() net: phy: intel-xway: workaround 100BASE-TX Link-Up issue net/smc: fix UAF on lgr list traversal in smcr_port_err() net/rds: size a connection's path set by the transport it ends up with nfp: hold IPsec RX state under the XArray lock net: ena: fix MMIO read buffer leak on probe failure net: ena: fix PHC cleanup on probe failure net/sched: act_ct: fix helper UAF due to extensions realloc ...
2026-09-24Merge tag 'landlock-7.3-rc5' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux Pull Landlock fixes from Mickaël Salaün: "This mainly fixes the Landlock tracepoint support merged this cycle so that denial and rule events report the intended policy context, whether through tracefs or BTF-visible callbacks. The size of this all is mainly from propagating the corrected contract through event definitions and producers, adding new tests for the reported context, and updating the documentation. Also improve annotation and fix a GCC 16 build warning" * tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux: landlock: Widen ruleset versions to 64 bits landlock: Add counted_by in landlock_domain landlock: Fix tracepoint contract documentation selftests/landlock: Test network denial context selftests/landlock: Test filesystem denial blockers landlock: Report the effective signal number landlock: Report the actual ptrace tracer landlock: Fix network denial trace context landlock: Fix rule tracepoint context landlock: Fix filesystem denial blocker reporting landlock: Fix tracepoint fixed-width type names landlock: Work around gcc-16 -Wuninitialized warning
2026-09-24Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpfLinus Torvalds
Pull bpf fixes from Alexei Starovoitov: - Fix bpf_skb_change_tail() to drop the checksum offload instead of rejecting the trim of CHECKSUM_PARTIAL skbs (Daniel Borkmann) - Add KF_PERFMON kfunc flag and require CAP_PERFMON for kfuncs that read arbitrary memory and for untrusted read-only memory reads (Daniel Borkmann) - Clear scalar delta on narrowing stack spill (Daniel Borkmann) - Set up the frame pointer for the exception callback in arm64 JIT, and zero-fill other CPUs when BPF_F_CPU update creates a per-cpu hash element (Donggeun Yoo) - Various fixes (Emil Tsalapatis): - Fix bounds check underflow for skb-backed dynptrs - Fix rx_queue_mapping context access code generation in bpf_sock - Reject packet pointer arguments to subprogs that may mutate the packet - Reject ALU instructions that see arena and non-arena operands on different code paths - Fix copied_seq double-counting on sockmap self-redirect (Geliang Tang) - Fix divide-by-zero in btf_struct_walk() on a flexible array of zero-sized elements, fix out-of-bounds read of rtt_min in sock_ops (Jiayuan Chen) - Fix bpf_sock_destroy() out-of-bounds read of sk_protocol on TIME_WAIT and request socks, and sleeping under RCU when destroying a listener with pending children (Jiayuan Chen) - Fix JEQ/JNE with immediate operand in MIPS32 JIT and missing zero extension of BSWAP 16/32 in MIPS64 JIT (Johan Almbladh) - Avoid soft lockup in htab lookup[_and_delete] batch operations on large maps (Jose Fernandez) - Various fixes (Kumar Kartikeya Dwivedi): - Verify global subprogs in each sleepability context they are called from - Make post-verification instruction rewrites killable - Preserve packet pointer displacement in regsafe() - Apply CO-RE relocations before subprogram validation, restrict CO-RE poisoning to relocatable instructions, and reject truncated ldimm64 CO-RE relocations in libbpf - Assign lock identity to callback map values - Compare stack frames in regs_exact() - Bound ownership depth through local kptrs and graph roots - Fix u32 overflow in map batch operations when the map size exceeds 4GB (Masoud Aghasi) - Fix UAF in bpf memalloc due to concurrent consumption of ttrace lists in alloc_bulk() (Pu Lehui) - Allow gotox as the terminal instruction of a program or a subprogram (Siddharth Chintamaneni) - Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL, skip unsettled links in link iterator, and reject dev-bound-only programs on other devices (Weiming Shi) - Reject non-negative stack offsets in stack_slot_obj_get_spi() (Xu Yunxiang) - Check params size before reading reserved fields in bpf_crypto_ctx_create() (Yuqi Xu) - Reject max_entries > INT_MAX in sock_map_alloc() (Zhao Gongyi) - Use a 32-bit compare in xsk_map_gen_lookup() (Zhiling Zou) - Use kvfree() in xdp_test_run_teardown() (Zhixing Chen) * tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf: (58 commits) selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element bpf: Fix BSWAP 32 and 16 on MIPS64 bpf: Fix immediate JMP JEQ/JNE on MIPS32 bpf: Reject dev-bound-only programs on other devices bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc selftests/bpf: Test for mixed arena/nonarena code paths bpf: Prevent variable arena/non-arena register contents selftests/bpf: Test rejection of pkt args to mutating subprogs bpf: Reject pkt arguments in mutating subprogs selftests/bpf: Add selftests for rx_queue_mapping context access bpf: Fix bpf_sock context code generation selftests/bpf: Test dynptr slices past end of skb bpf: Fix bounds check for skb-backed dynptrs selftests/bpf: Reject iterator destruction through fp+0 bpf: Reject non-negative offsets in stack_slot_obj_get_spi() bpf: Check params size before reading reserved fields selftests/bpf: Check local object ownership depth bpf: Bound ownership depth through local kptrs and graph roots selftests/bpf: Cover frame changes in bounded loops ...
2026-09-24Merge tag 'pinctrl-v7.3-2' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl Pull pin control fixes from Linus Walleij: - Serialize the calls to pinctrl_generic_dt_nod_to_map() - Fix a typo in S4 group in the Meson driver - Fix bank width and regmap usage in the MPFS-SSIO driver - Data register output latch behavior and voltage encoding fixes in the Sunxi driver - Free the IRQ domain on the error path in the single driver - Fix some QUP1 SE2/SE3 groups and a missing OF module alias in the Qualcomm drivers - Fix up the register banks for AON (I guess always-on) pins in the Tegra238 driver * tag 'pinctrl-v7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl: pinctrl: tegra238: Fix register bank for AON pin groups pinctrl: qcom: ipq5210: Publish the OF module alias pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functions pinctrl: single: free the IRQ on domain creation failure pinctrl: sunxi: A523: fix voltage withstand encoding pinctrl: sunxi: keep a shadow copy of the data register output latches pinctrl: mpfs-mssio: use correct regmap function to set bank voltage pinctrl: mpfs-mssio: fix width of unused bank voltage setting pinctrl: generic: serialise pinctrl_generic_dt_node_to_map() pinctrl: meson: Fix typo in s4 group name
2026-09-24Merge tag 'arm64-fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux Pull arm64 fixes from Will Deacon: - Fix the recently merged user ABI for the Arm CMN PMU driver filtering logic so that the ordering matches the hardware spec - Fix spurious warning when attempting to read PROT_NONE mappings of /dev/mem - Allow WFxT to be disabled on the command line, which is necessary for some configurations of recent Apple SoCs - Fix EL2 fine-grained trap configuration for the CPU PMU - Fix MIDR matching when applying CPU errata workarounds in a VM * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux: arm64/boot: Disable trapping of PMZR_EL0 writes to EL2 arm64: errata: match the target implementation CPU's own MIDR arm64: Add override for WFxT arm64: io: Reject non-user protection in ioremap_prot() perf/arm-cmn: Fix multi-filter encoding
2026-09-23arm64/boot: Disable trapping of PMZR_EL0 writes to EL2Fuad Tabba
__init_el2_fgt2() writes one mask to both HDFGRTR2_EL2 and HDFGWTR2_EL2. PMZR_EL0 is write-only, so its trap bit, nPMZR_EL0, exists only in HDFGWTR2_EL2 and is therefore never set: a PMZR_EL0 write from the host traps to EL2, where the nVHE hypervisor has no handler and BUG()s. The kernel never writes PMZR_EL0, but kernel.perf_user_access=1 has the PMU driver set PMUSERENR_EL0.UEN for a task with a user-read event, so a write from EL0 reaches the trap and takes the host down without a panic message. Accumulate the HDFGWTR2_EL2 bits separately, as __init_el2_fgt() already does for HDFGWTR_EL2, and set nPMZR_EL0 with the other FEAT_PMUv3p9 bits. Fixes: 858c7bfcb35e1 ("arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9") Cc: stable@vger.kernel.org Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev> Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com> Reviewed-by: Oliver Upton <oupton@kernel.org> Signed-off-by: Will Deacon <will@kernel.org>
2026-09-22net: devmem: document that bind-tx is unprivileged by designMina Almasry
Unlike bind-rx, which configures shared NIC RX queues to steer incoming traffic into the caller's dmabuf and requires CAP_NET_ADMIN (uns-admin-perm), bind-tx only DMA-maps the caller's dmabuf so the caller can transmit from it on their own sockets without affecting other traffic or device configuration. Add a comment in netdev.yaml and above netdev_nl_bind_tx_doit() to make it explicit that NETDEV_CMD_BIND_TX is unprivileged by design. Signed-off-by: Mina Almasry <almasrymina@google.com> Acked-by: Stanislav Fomichev <sdf@fomichev.me> Acked-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://patch.msgid.link/20260921195545.493253-1-almasrymina@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-21ata: libata: Correct libata.force parameter documentationNiklas Cassel
Align the documented libata.force options with their implementation. The force table accepts PIO modes 0 through 6, not mode 7, and ncqati controls NCQ generally rather than only queued TRIM. The max_sec_1024 and max_sec_lba48 options only set transfer size limits. Remove the misleading claim that they can also clear them. Reviewed-by: Damien Le Moal <dlemoal@kernel.org> Link: https://lore.kernel.org/r/20260918124030.1962773-6-cassel@kernel.org Signed-off-by: Niklas Cassel <cassel@kernel.org>
2026-09-20Merge tag 'input-for-v7.3-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input Pull input fixes from Dmitry Torokhov: - Fixes for evdev and input compat handling to zero-initialize on-stack absinfo and force-feedback effect structures before partial or compat copies from userspace, preventing kernel stack memory disclosure - Fixes for the Synaptics RMI4 driver to prevent an out-of-bounds read when writing multi-chunk blocks over SMBus and to avoid a NULL pointer dereference during suspend/resume when the RMI device is unbound - Fixes for the soc_button_array driver to propagate -EPROBE_DEFER on non-Bay Trail/Cherry Trail platforms (fixing broken power and volume buttons on the Microsoft Surface Pro 11) and to validate the ACPI package element count before dereferencing - A fix for the adp5588-keys driver to cache the initial GPIO hardware state before registering the gpiochip so pre-configured pin states are not clobbered by GPIO hogs during registration - A fix for the cyttsp5 touchscreen driver to clamp the device-supplied HID report size before copying into the response buffer, preventing a buffer overflow - A fix for the HP SDC serio driver to use timer_shutdown_sync() on module exit so the periodic kicker timer cannot rearm itself during teardown - A fix for the eeti_ts touchscreen driver to export its OF module alias so the module autoloads on Device Tree platforms - Updates to the xpad joystick driver adding support for the Victrix Pro BFG controller and Azeron devices, and fixing the device type classification for the PDP Marvel Xbox 360 controller - Quirks for the i8042 and atkbd drivers to keep the built-in keyboards functional on the Acer Aspire Go 15 AG15-42P and Xiaomi Redmi Book Pro 16 2026 - A quirk for the Synaptics PS/2 touchpad driver disabling SMBus InterTouch on the Lenovo ThinkPad T440p (board ID 2722) so the touchpad and TrackPoint respond immediately at boot - Other minor updates and documentation fixes, including reading the "ti,poll-period" property as u32 in tsc2007, adding the mt6572 compatible to the MediaTek keypad Device Tree binding, fixing an attribute name typo in the trackpoint sysfs ABI documentation, and documenting that no new LED codes should be added to the input subsystem * tag 'input-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input: Input: hp_sdc - shut down kicker timer on module exit Input: xpad - add support for Victrix Pro BFG Controller Input: tsc2007 - read "ti,poll-period" as u32 Input: trackpoint - fix the inertia attribute name in the ABI document Input: eeti_ts - publish the OF module alias Input: xpad - add support for Azeron devices Input: xpad - fix PDP Marvel Xbox 360 controller Input: document that no new LED codes should be added Input: soc_button_array - check btns_desc->package.count Input: soc_button_array - fix MS Surface Pro 11 probe failure Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Input: cyttsp5 - clamp the HID report size before memcpy Input: zero ff_effect before compat copy in input_ff_effect_from_user Input: evdev - zero absinfo before partial copy in EVIOCSABS Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 dt-bindings: input: mediatek,mt6779-keypad: add mt6572 Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-20landlock: Fix tracepoint contract documentationMickaël Salaün
The tracepoint documentation claims that denial and lifecycle events expose every input needed to reproduce a verdict. Instead document how denial, ruleset, and domain events identify the denying policy, checked operation and object, and reason for denial. Direct consumers to generic tracepoints for additional operational context. State the reconstruction limits: IDs are boot-local, rule checks have no request ID, and exported records may be lost or cross-CPU reordered. Also replace the incorrect BPF_RAW_TRACEPOINT guidance with libbpf SEC("tp_btf/...") attachment and refer consumers to the event prototypes for callback argument layouts. Cc: Günther Noack <gnoack@google.com> Cc: Steven Rostedt <rostedt@goodmis.org> Link: https://patch.msgid.link/20260918185036.608651-10-mic@digikod.net Signed-off-by: Mickaël Salaün <mic@digikod.net>
2026-09-20landlock: Fix rule tracepoint contextMickaël Salaün
Name each event after the identity it reports. Add-rule events describe UAPI rule insertion, so rename them after LANDLOCK_RULE_PATH_BENEATH and LANDLOCK_RULE_NET_PORT. Check-rule events describe matches in internal rule trees, so rename them after LANDLOCK_KEY_INODE and LANDLOCK_KEY_NET_PORT. This remains accurate if multiple UAPI rule types share one lookup and stored rule. Keep denial event names based on filesystem and network families because they describe final access decisions. Use u64 for growable access masks passed by value to add-rule and check-rule typed BTF callbacks. CO-RE can relocate pointer-reached fields, but it cannot widen a scalar callback slot declared by a BPF program. Keep native access_mask_t for internal state and trace records. For add-rule callbacks, report the normalized per-call contribution passed to landlock_insert_rule() and expose the complete validated flags value. Put the ruleset and flags first as a common invocation prefix. This distinguishes duplicate and effective-zero additions without recovering arguments from saved syscall registers. Cc: Günther Noack <gnoack@google.com> Cc: Steven Rostedt <rostedt@goodmis.org> Fixes: 63747c94774d ("landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints") Fixes: 3f1f106e4c14 ("landlock: Add tracepoints for rule checking") Link: https://patch.msgid.link/20260918185036.608651-4-mic@digikod.net Signed-off-by: Mickaël Salaün <mic@digikod.net>
2026-09-18Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernelLinus Torvalds
Pull drm fixes from Dave Airlie: "Things have picked back up a bit this week, mostly amdgpu, xe and msm this time. There are a bunch of scattered changes across the rest of drivers and core stuff, nouveau, i915. core: - fix vblank pending event leak ttm: - swapout fixes dma-buf: - scattergather fixes - enable dma-buf debug on debug kernels dma-fence: - fix signaling bit checks sched: - fix virtual runtime race msm: - DT: - Corrected indentation - Core: - Marked fbdev as system memory - GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups - DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state - DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks - HDMI: - Fixed runtime PM cleanup on probe failure xe: - shrinker related fixes - xe_mmio_gem fault handler and destroy fixes - xe disable i2c irq on unbind i915: - Revert a commit touching registers that don't necessarily exist - Check for negative numbers before passing to BIT() amdgpu: - SMU 14.x fix - DC IRQ fix - Runtime PM fix for P2P - RAS fix - PCIe reporting fix - DCN 6 fix - Device removal fix - DC MALL fix amdkfd: - GC 12.x fixes - Boundary checks - Mapping clear fix nouveau: - suspend/resume fixes gud: - out of bounds access fix - ignore damage clips in full update vc4: - use-after-free fix versilicon: - plane format fix longsoon: - blend mode property fix" * tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel: (59 commits) drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates drm/amdgpu: fix rmmio iounmap skipped on device removal drm/amdgpu: Skip KFD mapping clear before initialization drm/amd/display: Fix NULL dereference in dcn50/dcn60 init_hw drm/amdkfd: Avoid integer underflow in EOP ring size calculation. drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc drm/amdgpu: Fix GPU PCIe link capability reporting drm/amdgpu: check ras and obj before dereference drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 drm/amd/display: Atomize IRQ register read/modify/write ops drm/amd/pm: report energy accumulator for smu 14.0.3 drm/loongson: Create blend mode property for cursor plane drm/xe/i2c: Disable IRQ on unbind Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" drm/verisilicon: remove ARGB formats from primary plane drm/verisilicon: add primary modifier for format tables drm/verisilicon: set blend mode for the cursor plane drm/sched: Fix virtual runtime race drm/i915/display: check configuration index before shifting ...
2026-09-18Merge tag 'hwmon-for-v7.3-rc4' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull hwmon fixes from Guenter Roeck: - Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon) - Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible interrupt storm (gpioufan) - Improve raw WMI string handling, and fix UaF in show function (hp-wmi-sensors) - Fix k10temp model id range of Zen5 Turin to stop reporting temperature data for non-existing CCDs - pmbus: - Increase number of phases to fix UaF problems - Fix TPS53676 phase page decoding, and select page 0 for single-page applications - Stop pwm-fan RPM timer before freeing tach data to fix UaF - Release w83793 probe data through kref to fix UaF - Remove w83791d fan/pwm 4-5 sysfs group on remove to fix UaF * tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: hwmon: (hp-wmi-sensors) Improve raw WMI string handling hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() hwmon: (w83793) release probe data through kref hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler hwmon: (pmbus/core) increase number of phases and add new mask hwmon: (cgbc-hwmon) Add missing sensors hwmon: (cgbc-hwmon) Fix current sensors ID lookup hwmon: (pwm-fan) Stop RPM timer before freeing tach data hwmon: (k10temp) Fix model id range of Zen5 Turin
2026-09-18pinctrl: qcom: nord: Split QUP1 SE2/SE3 into lane-pair functionsShawn Guo
QUP1 SE2 and SE3 pack all four of their lanes pair-wise onto only two pins each: lanes 0/1 (I2C SDA/SCL) at mux value 2 and lanes 2/3 (UART TX/RX) at mux value 1, on gpio127/gpio128 and gpio129/gpio130 respectively. Both mux values were named "qup1_se2" (respectively "qup1_se3"), so the two distinct lane pairs became indistinguishable. msm_pinmux_set_mux() stops at the first entry matching the requested function, which means mux value 1 was always selected and the I2C lanes could never be muxed out. In practice i2c9 and i2c10 got the UART lanes and did not work, while uart9 and uart10 happened to be muxed correctly. Give each lane pair its own function, following the _01/_23 naming already used for the same hardware arrangement by the shikra, eliza, hawi and maili TLMM drivers. Both functions still cover the full pin pair, so a single pinctrl state per protocol remains sufficient. Drop gpio129/gpio130 from the SE2 group list, since those pins belong to SE3 and were never reachable through the SE2 function. Also rename QUP1 SE2/SE3 functions in the binding doc accordingly. While at it, add missing "gpio", "qup3_se0_mira" and "qup3_se0_mirb" to the binding function enum to get the list complete. Fixes: c24dd0826f06 ("pinctrl: qcom: add the TLMM driver for the Nord platforms") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com> Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> Link: https://patch.msgid.link/20260830030201.135637-1-shengchao.guo@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Signed-off-by: Linus Walleij <linusw@kernel.org>
2026-09-18Merge tag 'arm64-fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux Pull arm64 fixes from Will Deacon: "In this batch we've got a couple of hibernation fixes, a couple of minor MTE fixes, some per-cpu codegen fixes (which were found as part of Mark's series adding preemptible this_cpu_*() operations) and a fix for the Arm CMN PMU driver. Summary: - Fix hypercall arguments when resetting EL2 vectors during hibernation - Fix hibernation with 52-bit capable kernels on machines without 52-bit addressing, similarly to the recent kexec fix - Fix a bunch of clumsy codegen issues with our per-cpu accessors - Fix MTE ptrace documentation to reflect the de-facto ABI behaviour - Fix pthread_join() usage in MTE selftest - Fix port selection in the Arm CMN PMU driver" * tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux: arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation kselftest/arm64: Fix size of thread_data values for pthread_join() arm64: percpu: Fix LSE operations on {8,16}-bit types arm64: percpu: Fix this_cpu_and() mask generation arm64: percpu: Fix this_cpu_write() casting arm64: hibernate: clone only the linear map that exists at runtime perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-18arm64: Add override for WFxTYureka Lilian
Add an override for WFxT support within ID_AA64ISAR2_EL1 to allow it to be disabled using the new arm64.nowfxt command line parameter. This accompanies the idle=nop param introduced in a previous patch series [1] in dealing with misbehaving WFI and WFIT instructions on Apple Silicon SoCs, and eases debugging of other quirky WFxT implementations. Link[1]: https://lore.kernel.org/all/20260804-arm64-idle-param-v3-1-d10f8159062b@cyberchaos.dev/ Suggested-by: Will Deacon <will@kernel.org> Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev> Signed-off-by: Will Deacon <will@kernel.org>
2026-09-17Merge tag 'net-7.3-rc4' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net Pull networking fixes from Paolo Abeni: "Including fixes from Netfilter, Bluetooth, IPSec and WiFi. Previous releases - regressions: - netfilter: hold reference on ct until flow is released - bridge: - move switchdev call outside rcu - vlan: fix bugs caused by switchdev deletion errors - wifi: - mac80211: reset state when starting AP fails - cfg80211: don't free driver-owned scan requests - tcp: don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() - mptcp: return sk_wait_data() errors from recvmsg() - xfrm: serialize state GC with device state flush - drop_monitor: synchronize tracepoint unregistration on error path - bluetooth: - eir: validate service data length before reading UUID - hci_sync: serialize local codec list cleanup - RFCOMM: avoid socket lock inversion in listener cleanup - eth: - lan743x: fix RX checksum use-after-free - mvpp2: prevent buffer overflow in page_pool allocation Previous releases - always broken: - core: lock the socket in sock_gettstamp() - neighbour: enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS. - sched: codel: bound the dropping loop per dequeue call - wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic - psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() - xfrm: fix stack OOB read in iptfs_skb_reset_frag_walk() - bluetooth: hci_qca: do not write to the serial port after it is closed - dsa: mxl862xx: disable the stats poll on teardown - eth: - stmmac: fix TSO header length truncation - ip_tunnel: initialize `options_len` before referencing options" * tag 'net-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (159 commits) mptcp: fix bad accounting in __mptcp_subflow_push_pending() mptcp: close race between scheduler and state change mptcp: avoid unneeded actions on subflow reset net: skbuff: do not leave stale header offsets after pskb_carve() selftests: net: packetdrill: test exclusion of old ACK from TCP fast path tcp: exclude old ACKs from tcp fast path dpll: reject a reference sync pin which is not on the pin's dpll net: mvpp2: prevent buffer overflow in page_pool allocation net: macb: fix ordering around PTP timestamp read selftests: drv-net: psp: test PSP and TCP ULP mutual exclusion net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() net: stmmac: preserve real_num_tx_queues on mqprio setup failure net: stmmac: propagate FPE preemption-class mapping errors net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain net: ethernet: cortina: Ack RX overrun interrupt correctly net: lock the socket in sock_gettstamp() eth: fbnic: ring the doorbell if a burst ends in a drop net: netsec: fix device_node reference leak on phy_np ...
2026-09-17Merge tag 'drm-msm-fixes-2026-09-16' of ↵Dave Airlie
https://gitlab.freedesktop.org/drm/msm into drm-fixes Fixes for v7.3-rc4: DT: - Corrected indentation Core: - Marked fbdev as system memory GPU: - Fixed autosuspend cleanup on teardown - a750: fix timestamps - Increase GMU fw init timeout - Misc fixes/cleanups DPU: - Fixed clock rounding, unbreaking newest platforms - Cleared pending flush state DP: - Skip PUSH_IDLE when link was never enabled - Fixed bandwidth checks HDMI: - Fixed runtime PM cleanup on probe failure Signed-off-by: Dave Airlie <airlied@redhat.com> From: Rob Clark <rob.clark@oss.qualcomm.com> Link: https://patch.msgid.link/CACSVV021rZsjmiPEyR_LR7L=k7=DRV0QdsA50BF_Gd0s2DXaCw@mail.gmail.com
2026-09-17s390/pci/docs: Fix sriov_numvfs attribute nameKarl Mehltretter
The attribute is sriov_numvfs (drivers/pci/iov.c); the document names it sriov_numvf, which does not exist. Use sriov_numvfs. Fixes: de267a7c71ba ("s390/pci: Documentation for zPCI") Assisted-by: LLM Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com> Reviewed-by: Randy Dunlap <rdunlap@infradead.org> Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
2026-09-15tcp: do not let tcp_rmem be set below 4096Eric Dumazet
We can hit a division by zero crash in tcp_rcvbuf_grow() and tcp_rcv_space_adjust(): divide error: 0000 [#1] PREEMPT SMP RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939 ... grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval); The division uses oldval = tp->rcvq_space.space as divisor. When tp->rcvq_space.space is zero, this leads to a divide-by-zero exception. tp->rcvq_space.space is initialized in tcp_init_buffer_space(): tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd, (u32)TCP_INIT_CWND * tp->advmss); If tcp_rmem[1] is configured to very small values (such as 1), sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0. This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked, tcp_rcvbuf_grow() divides by oldval == 0. Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF and RCVBUF for min length") ensured that net.core.rmem_default and net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly, SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF). However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing arbitrarily small values. Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline alignment, its value varies across architectures and configuration options. Using a fixed constant of 4096 ensures a predictable, architecture- independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere and matches the documented 4K default. Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Eric Dumazet <edumazet@google.com> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20260912144848.3448026-1-edumazet@google.com Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2026-09-15dt-bindings: display/msm: Use consistent indentation in the exampleKrzysztof Kozlowski
Correct indentation in the examples to consistent 2- or 4-spaces indentation to fix dt-check-style warnings ("example 0 [indent-consistent] indent mismatch ..."). Preferred is 4-spaces, but re-indenting entire example just for that is too much churn. Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com> Patchwork: https://patchwork.freedesktop.org/patch/753054/ Link: https://lore.kernel.org/r/20260913123331.100293-4-krzysztof.kozlowski@oss.qualcomm.com Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
2026-09-13hwmon: (cgbc-hwmon) Add missing sensorsThomas Richard (congatec GmbH)
Add the following sensors: - Alternate Board Temperature (temp11_input) - Top DIMM 1-7 Temperature (temp12_input to temp18_input) - Bottom DIMM 1 Temperature (temp19_input) - 12V Standby Voltage (in14_input) This fixes the following warning on conga-SA7: Board Controller returned an unknown sensor (bc_type=1, bc_id=11), ignore it Also update existing labels to match Congatec documentation. Cc: stable@kernel.org Fixes: 08ebc9def79f ("hwmon: Add Congatec Board Controller monitoring driver") Signed-off-by: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com> Link: https://patch.msgid.link/20260911-cgbc-hwmon-fix-and-new-sensors-v2-2-0c6bf078d173@bootlin.com Signed-off-by: Guenter Roeck <linux@roeck-us.net>
2026-09-13Input: trackpoint - fix the inertia attribute name in the ABI documentKarl Mehltretter
The attribute is created as "inertia" (TRACKPOINT_INT_ATTR(inertia, ...) in drivers/input/mouse/trackpoint.c); the ABI file spells the path "intertia". The description below it already says inertia. Fix the spelling. Fixes: aebb47d4e7a9 ("Input: trackpoint: document sysfs interface") Assisted-by: LLM Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com> Link: https://patch.msgid.link/20260905102038.42882-1-kmehltretter@gmail.com Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
2026-09-12Merge tag 'erofs-for-7.3-rc3-fixes' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs Pull erofs updates from Gao Xiang: "The most impactful fix here is to disable LZ4 rolling decompression for now. AWS folks recently found their systems could get corrupted data with some rare, specific LZ4 datasets, and after a deeper analysis, I found the root cause is that there could be uncontrolled backward memory copies in the current LZ4 implementation and it breaks the assumption of the rolling decompression optimization, since the kernel LZ4 codebase is out of our control and it needs more time to plan how to do next, so disable LZ4 rolling decompression for now to ensure data correctness for real production on these rare cases first. The technical details also see the corresponding commit. Other changes are random minor fixes. Summary: - Disable LZ4 rolling decompression for now due to the uncontrolled LZ4 implementation - Fix missing sysfs feature entry for xattr prefixes - Fix invalid LZMA decoders on resize failure - Rearrange the inode_share cache key to avoid potential collisions - Fix erofs_bread() when fsoffset is used on sub-page-block EROFS filesystems" * tag 'erofs-for-7.3-rc3-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs: erofs: add missing buf->off in erofs_bread() erofs: delimit inode_share cache key components erofs: disable LZ4 rolling decompression for now erofs: preserve LZMA decoders on resize failure erofs: add sysfs feature entry for xattr prefixes
2026-09-11neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.Kuniyuki Iwashima
NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses .validation_type, so no validation is applied: # ynl --family rt-neigh --do setneightbl \ --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}' # ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arp_cache" and has("config")) | .parms["interval-probe-time-ms"]' 0 Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is silently cast to u32, so a larger value can bypass the min check: e.g. 4294967296 == 0x100000000 # ynl --family rt-neigh --do setneightbl \ --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}' # ynl --family rt-neigh --dump getneightbl --output-json | \ jq '.[] | select(.name == "arp_cache" and has("config")) | .parms["interval-probe-time-ms"]' 0 msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR() when HZ > 1000 (Alpha, MIPS), and passing a negative integer to queue_delayed_work(unsigned long delay) causes sign extension, which wraps around the expiry time to the past, resulting in it being handled as 0 delay in the timer wheel. Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day. The same max check is applied to sysctl as well. Note that this controls the probe interval for NTF_MANAGED entries, so the max of 1 day is unlikely to break any deployments. Fixes: 211da42eaa45 ("net, neigh: introduce interval_probe_time_ms for periodic probe") Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com> Reviewed-by: Ido Schimmel <idosch@nvidia.com> Link: https://patch.msgid.link/20260909233143.2401847-3-kuniyu@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-11Merge tag 'regulator-fix-v7.3-rc2' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator Pull regulator fixes from Mark Brown: "One fix for pf1550 which checked for errors on multiple regulators but always notified via one of them regardless of which one had the problem, plus one device ID addition in the fan53555 DT bindings" * tag 'regulator-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator: regulator: pf1550: fix which regulator is notified regulator: dt-bindings: fan53555: add tcs,tcs4526
2026-09-11Merge tag 'spi-fix-v7.3-rc2' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi Pull spi fix from Mark Brown: "New device ID for v7.3: update the DesignWare DT binding to say how to describe the UltraRISC DP1000 instance of the controller" * tag 'spi-fix-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi: spi: dt-bindings: snps,dw-apb-ssi: Add compatible for UltraRISC DP1000 SoC
2026-09-11Merge tag 'riscv-for-linus-7.3-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux Pull RISC-V fixes from Paul Walmsley: "From a RISC-V point of view, there's one notable fix here, reverting an earlier bogus fix to the pointer masking code. Fortunately the practical impact appears to be small. - Revert a bad fix, likely LLM-generated, in the pointer masking code that confused the RISC-V hardware pointer masking implementation with the Linux kernel tagged address feature - Fix unexpected faults caused by kprobe instruction slot writes when !CONFIG_STRICT_MODULE_RWX - Fix unexpected faults on minimal configurations during runtime code patching on !CONFIG_STRICT_MODULE_RWX systems - Fix a misplaced variable clear causing incorrect reuse of previous values in the RISC-V hardware feature probing code - Fix two bugs in the PMU SBI perf code on rv32: use BIT_ULL rather than BIT on 64-bit masks; and use a bitmap rather than an unsigned long on a quantity that can exceed 32 bits And a few miscellaneous cleanups: - Avoid a potential dereference-before-NULL-pointer-check bug in the PMU SBI perf driver - Use CONFIG_GENERIC_BUG_RELATIVE_POINTERS to simplify the rv32 bug table code (like x86 and PPC) - Report the RISC-V standard ISA extensions Z[v]fhmin when support is claimed for the superset RISC-V standard ISA extensions Z[v]fh; and simplify our FPU test code to only check for the presence of the D extension - Use an existing kernel string helper in place of some open-coded code in kernel/usercfi.c - Fix some yamllint issues in the RISC-V DT bindings for CPUs - Convert one use of __ASSEMBLY__ to __ASSEMBLER__ that snuck into the RISC-V CFI selftest code - Update the translation for the simplified Chinese translation of the RISC-V kernel patch acceptance policy" * tag 'riscv-for-linus-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux: riscv: skip software algning code for HAVE_EFFICIENT_UNALIGNED_ACCESS kselftest/riscv: Replace __ASSEMBLY__ with __ASSEMBLER__ docs/zh_CN: Update arch/riscv/patch-acceptance.rst translation dt-bindings: riscv: cpus: Fix yamllint style issues riscv: hwprobe: simplify has_fpu() to check D extension only perf: RISC-V: check cpu_hw_evt before dereference in overflow IRQ riscv: report Zfhmin/Zvfhmin when Zfh/Zvfh are present perf: RISC-V: store available counter mask as bitmap perf: RISC-V: use BIT_ULL for u64 overflow masks riscv: bug: Make RV32 use GENERIC_BUG_RELATIVE_POINTERS riscv: hwprobe: initialize pair->value in hwprobe_one_pair() riscv: use string helper in setup_global_riscv_enable() Revert "riscv: Reset pmm when PR_TAGGED_ADDR_ENABLE is not set" riscv: patch: skip fixmap mapping when kernel text is already writable riscv: mm: make EXECMEM_KPROBES writable without CONFIG_STRICT_MODULE_RWX
2026-09-11Merge tag 'ata-7.3-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux Pull ata fix from Niklas Cassel: - Drop documentation for no longer existing pata_legacy kernel parameters (Ethan) * tag 'ata-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux: ata: pata_legacy: remove documentation for removed module parameters
2026-09-11arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentationCatalin Marinas
PTRACE_{PEEK,POKE}MTETAGS return -EIO rather than -EOPNOTSUPP (as documented) when no tags are copied from/to a mapping without PROT_MTE. This has been the behaviour since the interface was introduced, though the original intent was to distinguish between address not being accessible and mapped as untagged. Update the documentation to match the implementation (de-facto ABI). Since -EOPNOTSUPP was never returned, change the error assignment to -EIO as well to avoid confusion. Fixes: df9d7a22dd21 ("arm64: mte: Add Memory Tagging Extension documentation") Fixes: 18ddbaa02b7a ("arm64: mte: ptrace: Add PTRACE_{PEEK,POKE}MTETAGS support") Reported-by: Yury Khrustalev <yury.khrustalev@arm.com> Cc: Will Deacon <will@kernel.org> Cc: Mark Rutland <mark.rutland@arm.com> Signed-off-by: Catalin Marinas <catalin.marinas@arm.com> Signed-off-by: Will Deacon <will@kernel.org>
2026-09-11Merge tag 'iio-fixes-for-7.3a' of ↵Greg Kroah-Hartman
ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio into char-misc-linus Jonathan writes: IIO: 1st set of fixes for the 7.3 cycle. A couple of core fixes, the rest usual mix of driver issues that surfaced from merge window until now. core - buffer: Ensure that when using the iio_push_to_buffers_with_ts_unaligned() that the full buffer is zeroed. - trigger: Cancel reenable_work() before freeing the trigger that might be re-enabled. dma-buffer - Fix wrong sizing for a mapped sg_list. If an IOMMU was using a fused entry the mapping might walk off the end. adi,ade9000 - Wait for power up before requesting interrupts. - Fix overlap in scan index for current and voltage channels. - Ensure Phase C dip event included in IRQ1 handler. adi,adf4377 - Initialize all of a clk_init_data. adi,adis* - Ensure debugfs reads are finished before unbind. adi,axi-adc - Initialize mutex. adi,admv1013 - Ensure mutex is intialized before notifier that might use it is registered. - Fix wrong channel field used for read_raw. allwinner,sun4i - Drop a pm_runtime_put() when there was no get. - Ensure correct cleanup on driver probe fail due to any issues with the thermal zone. aspeed,adc, - Don't eat reset deassert errors. awinic,aw96103 - Make sure firmware length is validated rather than blindly trusting it. bosch,bmp280 - Fix out of bounds lookup of sampling frequency due to indexing based on elements in matrix rather than just the correct dimension. invensense,timestamp library - Ensure time estimate doesn't invert wrt to current time in a corner case occasionally seen. kionix,kx022a - Off by one in array boundary check. - Close a memory leak and state corruption in error path. maxim,max1363 - Sign extend bipolar values to ensure correct reporting to userspace. maxim,max30102 - Fix NULL dereference by checking there is data in the FIFO before trying to do anything with it. microchip,mcp47a1 - Ensure highest possible value actually settable. pulsed-light,lidar-lite - Don't leak the IIO device registration if runtime pm setup fails particularly as it was being freed. rockchip,saradc - Fix wrong fallback compatible for rv1106 that lead to trying to use too many channels (correct support will follow next merge window) rohm,bd79124 - Correct limit used for rising alarms. - Fix which registers related to limits are used in initialization. - Apply GPIO mask to allow subset of GPIOs to be toggled. - Add missing regmap error handling in a few places. - Ensures scale is read only. rohm,bm1390 - Don't silently eat a data read error. rohm,bu27034 - Don't silently eat error when reading gain. - Ensure we infinite delay doesn't happen on error. semtech,sx9324 - Fix wrong proximity channel resolution. sharp,gp2ap020a00f - Make sure to drain irq_work in remove path. st,vl5310x - Ensure direct mode is claimed for read_raw avoiding corruption of buffered accesses. vishay,vcnl3020 - Use write bits for ISR mask and ensure right event reported. vti,sca3000 - Fix up a condition check for the frequency divider. xilinx,xadc - Swap registration of cleanup of work with that of irq to ensure that no irqs can cause work that has been freed to be queued. x-powers,axp288 - Add bias override quirk for Haier HV103H. Fix because we used to always override then moved to trusting the firmware setup - which fixed some boards, but broke others. * tag 'iio-fixes-for-7.3a' of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio: (42 commits) iio: proximity: vcnl3020: fix ISR bitmask check in IRQ handler iio: proximity: vl53l0x-i2c: claim direct mode for raw reads iio: dac: mcp47a1: Allow full-scale output iio: accel: kionix-kx022a: Prevent memory leak and fix state iio: light: rohm-bu27034: Fix infinite delay on error iio: adc: sun4i-gpadc-iio: clean up on thermal zone registration failure iio: adc: sun4i-gpadc-iio: drop underflowing pm_runtime_put() calls iio: adc: axp288: Add TS bias override for Haier HV103H dt-bindings: iio: adc: rockchip-saradc: Fix RV1106 compatible dt-bindings: iio: adc: rockchip-saradc: Group single-entries into an enum list iio: inv_sensors: fix estimated value larger than interrupt timestamp iio: adc: aspeed: propagate reset deassert errors iio: buffer-dmaengine: fix sg entry iteration when building dma_vecs iio: proximity: pulsedlight: fix iio_device left registered on PM setup failure iio: trigger: cancel reenable_work before freeing trigger iio: frequency: admv1013: fix wrong channel field used in admv1013_read_raw() iio: accel: sca3000: fix frequency divider condition check iio: admv1013: initialize callback mutex before registering notifier iio: gyro: adis16136: fix unprotected debugfs reads iio: imu: adis16400: fix unprotected debugfs reads ...
2026-09-10bpf: Add KF_PERFMON kfunc flagDaniel Borkmann
Tracing related BPF helpers e.g. under bpf_base_func_proto() are gated behind CAP_PERFMON. However, the same is currently not true for kfuncs and they are accessible via plain CAP_BPF. Add a new KF_PERFMON flag which can be used such that check_kfunc_call() ensures env->allow_ptr_leaks is permitted. This follows similar pattern to existing KF_DESTRUCTIVE flag. The rejection returns -EPERM to match the other CAP_PERFMON gates in the verifier, that is, check_ptr_to_btf_access() and check_ptr_to_map_access(), which report the very same policy to user space. Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://lore.kernel.org/r/20260910213510.49358-1-daniel@iogearbox.net Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-10Merge tag 'hwmon-for-v7.3-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging Pull hwmon fixes from Guenter Roeck: - Core - Fix potential UAF in pec_store - Ensure that 'dev' passed to hwmon_notify_event() is a hwmon device - Document hwmon_notify_event() - applesmc: Fix key backlight workqueue leak on register failure - aspeed-pwm-tacho: Propagate reset deassert errors - asus_rog_ryujin: HID report fixes - chipcap2: Fix channels in humidity alarm notifications - corsair-cpro: debugfs fixes - gpd-fan: Documentation: replace full-width colon by a standard ASCII colon - gpio-fan: Take fan_data->lock in gpio_fan_shutdown(), and fix use-after-free in alarm work - ina2xx: Fix in0 and curr1 alarm handling, and acquire hwmon_lock in shunt_resistor_show() - ltc4282: Fully initializeclk_init_data - mcp9982: Propagate one-shot polling errors - nct6694: Do not expose enable on DTIN temperature channels - PMBus core: Clear generic status alarms with CLEAR_FAULTS - sht4x: Fix return value from heater_enable_store(), and add missing locks * tag 'hwmon-for-v7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging: (24 commits) hwmon: (nct6694) do not expose enable on DTIN temperature channels hwmon: (asus_rog_ryujin) Synchronize HID command and report handling hwmon: (asus_rog_ryujin) Validate HID report lengths hwmon: (corsair-cpro) Remove debugfs entries when probe fails hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() hwmon: (corsair-cpro) Create debugfs entries after hwmon registration hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS hwmon: (chipcap2) fix channels in humidity alarm notifications hwmon: (applesmc) fix key backlight workqueue leak on register failure hwmon: (sht4x) Fix return value from heater_enable_store() hwmon: (sht4x) Add missing locks hwmon: (yogafan) fix non-kernel-doc comment Documentation: hwmon: replace full-width colon by a standard ASCII colon hwmon: (ina2xx) Decouple in0 and curr1 alarms hwmon: (ina2xx) Replace masks with enum in alert functions hwmon: (ina2xx) Parameterize ina2xx_data in ina226_alert_read() hwmon: Ensure that 'dev' passed to hwmon_notify_event() is a hwmon device hwmon: (ina2xx) Acquire hwmon_lock in shunt_resistor_show() hwmon: Fix potential UAF in pec_store ...
2026-09-10Merge tag 'net-7.3-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net Pull networking fixes from Jakub Kicinski: "Nothing too exciting, usual stream of fixes. Including fixes from Netfilter, Bluetooth and WPAN. Current release - new code bugs: - Bluetooth: hci_sync: fix not setting CE length properly - eth: enic: match mailbox replies to request numbers Previous releases - regressions: - tunnels: drop stale dst when building an ICMP error for PMTUD - ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() (bug in the rtnl_lock -> RCU conversion) - eth: bnxt_en: - fix crashes on Thor2 due to OOB coalescing buffer accesses - prevent queue stop with deferred completions Previous releases - always broken: - eth: - ice: don't dereference pointers from TP_printk() - fix OOB writes on ethtool flow rule dump in 3 drivers - mlx5: fix FEC configuration with RS_544_514_INTERLEAVED_QUAD - dsa: tag_brcm: legacy FCS: request needed tailroom Misc: - net: cap tx_queue_len at S16_MAX to prevent oversized ring alloc - ipv6: flowlabel: cap duplicate leases per socket" * tag 'net-7.3-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (164 commits) selftests: tc-testing: test action batch failure cleanup net/sched: act_api: release all action references on NEWACTION failure openvswitch: fix wrong flag value in get_ipv6_ext_hdrs() ipmr: account multicast table and route memory net: phy: dp83td510: handle the active-high LED polarity mode net: macb: initialize PTP state before registering clock net: hsr: enable promiscuous mode on interlink port with fwd offload ipv6: fix fib6 walker UAF on seq stop net: stmmac: fix TX descriptor availability check for TSO traffic net/rds: fix tcp stream corruption with large pages net: mana: restore the XDP program pointer when pre-allocation fails net: phy: dp83867: handle the active-high LED polarity mode octeontx2-af: fix PF/CGX debugfs PCI bus lookup net: net_failover: Fix the deadlock in net_failover_slave_name_change() net: phy: mediatek-ge: disable EEE on the MT7530 PHY tcp: reject non zerocopy devmem tx net: ethernet: mtk_eth_soc: populate lpi_interfaces to fix EEE support net: dsa: mt7530: populate lpi_interfaces to fix EEE support net: hinic: fix mailbox segment buffer overflow net: sun4i-emac: fix missing of_node_put() for phy_node ...
2026-09-10ata: pata_legacy: remove documentation for removed module parametersEthan Nelson-Moore
Commit 3c4d783f6922 ("ata: pata_legacy: remove VLB support") removed several module parameters from the pata_legacy driver, but neglected to remove their documentation. Remove it. Fixes: 3c4d783f6922 ("ata: pata_legacy: remove VLB support") Cc: stable@vger.kernel.org # 7.0+ Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com> Reviewed-by: Karl Mehltretter <kmehltretter@gmail.com> Reviewed-by: Damien Le Moal <dlemoal@kernel.org> Reviewed-by: Randy Dunlap <rdunlap@infradead.org> Link: https://lore.kernel.org/r/20260607064053.195166-1-enelsonmoore@gmail.com Signed-off-by: Niklas Cassel <cassel@kernel.org>
2026-09-08spi: dt-bindings: snps,dw-apb-ssi: Add compatible for UltraRISC DP1000 SoCJia Wang
Add the SoC-specific compatible string and use the generic one as fallback for the UltraRISC DP1000 SPI controller. The DP1000 integrates two SPI controllers. SPI0 supports standard, dual and quad transfers with three native chip-select signals. SPI1 supports standard transfers with four native chip-select signals. Both controllers have one register range and separate reference and APB interface clocks. Signed-off-by: Jia Wang <wangjia@ultrarisc.com> Acked-by: Conor Dooley <conor.dooley@microchip.com> Link: https://patch.msgid.link/20260907-ultrarisc-dts-v2-5-5eb4c97477c5@ultrarisc.com Signed-off-by: Mark Brown <broonie@kernel.org>