Linux/linux b88c841 — drivers/input/joystick xpad.c, drivers/input/misc ati_remote2.c

Merge tag 'input-for-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input

Pull input fixes from Dmitry Torokhov:

 - A fix for the ati_remote2 sysfs attributes handling, resolving type
   confusion after conversion to dev_groups

 - Updates to the xpad joystick driver adding support for the Corsair
   Novablade Pro controller (wired and 2.4 GHz wireless) and a newer
   hardware revision of the 8BitDo Pro 2 Wired Controller for Xbox.

* tag 'input-for-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:
  Input: xpad - add support for 8BitDo Pro 2 Wired Controller for Xbox
  Input: xpad - add support for Corsair Novablade Pro
  Input: ati_remote2 - fix type confusion in device attribute handlers
DeltaFile
+4-8drivers/input/misc/ati_remote2.c
+4-0drivers/input/joystick/xpad.c
+8-82 files

Linux/linux a5ebb76 — drivers/edac amd64_edac.c

Merge tag 'edac_urgent_for_v7.3_rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras

Pull EDAC fix from Borislav Petkov:

 - amd64_edac: Shorten the ErrorInformation field read from the MCA_SYND
   MSR to only two bits. It is perfectly fine to do so because no system
   ever supported more than 2 bits of information (the Chip Selects used
   were only 4 maximum) and newer hardware will use only 2 bits anyway

* tag 'edac_urgent_for_v7.3_rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras:
  EDAC/amd64: Mask UMC chip select to the four implemented selects
DeltaFile
+2-2drivers/edac/amd64_edac.c
+2-21 files

Linux/linux bb934c2 — drivers/gpu/drm/amd/amdgpu amdgpu_debugfs.c, drivers/gpu/drm/amd/amdkfd kfd_device_queue_manager.c

Merge tag 'drm-fixes-2026-10-11' of https://gitlab.freedesktop.org/drm/kernel

Pull drm fixes from Dave Ailie:
 "Live from Dublin Airport, it's Saturday Night drm fixes.

  This week has the missing misc fixes from last week which I tracked
  down and seemed to be a race/bug in my lei setup somehow, once I asked
  lei to ignore it's cache I got the missing email. But there are more
  misc fixes this week and amd and intel ones.

  The main ones in this are amdgpu and xe, with vc4, vmwgfx, nouveau and
  imagination in the middle, with a bunch of small single fixes.

  Bit busier than I'd like, but the missing misc might explain it,
  anyways time for me to fly home.

  fb:
   - defer setup when fbdev_probe() fails, not just on -EAGAIN


    [84 lines not shown]
DeltaFile
+105-34drivers/gpu/drm/xe/xe_bo.c
+46-31drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+35-30drivers/gpu/drm/vc4/vc4_v3d.c
+42-0drivers/gpu/drm/amd/display/amdgpu_dm/tests/amdgpu_dm_connector_test.c
+25-13drivers/gpu/drm/xe/xe_lrc.c
+26-6drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+279-11435 files not shown
+461-22841 files

Linux/linux b62f58b — drivers/i2c/busses i2c-qcom-geni.c

Merge tag 'i2c-fixes-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c fix from Andi Shyti:
 "Just one qcom-geni fix for a runtime PM reference leak
  during transfer setup"

* tag 'i2c-fixes-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: qcom-geni: release runtime PM reference when set_rate fails
DeltaFile
+2-1drivers/i2c/busses/i2c-qcom-geni.c
+2-11 files

Linux/linux c61e23e — drivers/gpu/drm/imagination pvr_vm.c pvr_mmu.c, drivers/gpu/drm/nouveau nouveau_abi16.c

Merge tag 'drm-misc-fixes-2026-10-09' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes

A pointer assignment fix for gud, a reference fix and a preallocation
size fix for imagination, a suspend fix and an allocation fix when idle
for vc4, and a hardware variant fix for nouveau.

Signed-off-by: Dave Airlie <airlied at redhat.com>

From: Maxime Ripard <self at mripard.dev>
Link: https://patch.msgid.link/asjkbknTHg2t8JGy@houat
DeltaFile
+27-30drivers/gpu/drm/vc4/vc4_v3d.c
+12-13drivers/gpu/drm/imagination/pvr_mmu.c
+8-16drivers/gpu/drm/vc4/vc4_irq.c
+4-4drivers/gpu/drm/imagination/pvr_vm.c
+7-1drivers/gpu/drm/vc4/vc4_gem.c
+1-1drivers/gpu/drm/nouveau/nouveau_abi16.c
+59-653 files not shown
+62-679 files

Linux/linux 492c4de — drivers/gpu/drm/amd/amdgpu amdgpu_gmc.c amdgpu_debugfs.c, drivers/gpu/drm/amd/amdkfd kfd_device_queue_manager.c

Merge tag 'amd-drm-fixes-7.3-2026-10-08' of https://gitlab.freedesktop.org/drm/amdgpu/kernel into drm-fixes

amd-drm-fixes-7.3-2026-10-08:

amdgpu:
- Fix direct scanout alpha on some DRM_FORMATs
- UserQ fixes
- Fix tearing flips with PSR
- GPU reset vblank fix
- Debugfs register interface fix
- Fix display mode patching
- Expand Mac reserved memory workaround

amdkfd:
- SDMA doorbell fix
- Fix dma-buf reference leak in error path

Signed-off-by: Dave Airlie <airlied at redhat.com>


    [2 lines not shown]
DeltaFile
+46-31drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c
+42-0drivers/gpu/drm/amd/display/amdgpu_dm/tests/amdgpu_dm_connector_test.c
+26-6drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+1-19drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_plane.c
+19-0drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+7-10drivers/gpu/drm/amd/amdgpu/amdgpu_gmc.c
+141-666 files not shown
+180-7612 files

Linux/linux a8013cb — drivers/gpu/drm/xe xe_mmio.c xe_i2c.c, drivers/gpu/drm/xe/display xe_fb_pin.c

Merge tag 'drm-xe-fixes-2026-10-08' of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes

Fixes on:
 - i2c removal (Fan)
 - system Controller Maibox header handling (Mallesh)
 - two bo pin/unpin accounting bugs (Thomas)
 - not emitting a w/a twice (Tvrtko)
 - xe_mmio_wait32() to honor delay/sleep maximums (Alan)

Signed-off-by: Dave Airlie <airlied at redhat.com>

From: Rodrigo Vivi <rodrigo.vivi at intel.com>
Link: https://patch.msgid.link/asfEfgbIjs0GJ-RF@intel.com
DeltaFile
+105-34drivers/gpu/drm/xe/xe_bo.c
+25-13drivers/gpu/drm/xe/xe_lrc.c
+8-8drivers/gpu/drm/xe/xe_sysctrl_mailbox.c
+3-3drivers/gpu/drm/xe/display/xe_fb_pin.c
+3-2drivers/gpu/drm/xe/xe_mmio.c
+4-1drivers/gpu/drm/xe/xe_i2c.c
+148-611 files not shown
+150-617 files

Linux/linux 3857c2f — drivers/pci/pcie aer.c

Merge tag 'pci-v7.3-fixes-4' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci

Pull PCI fix from Bjorn Helgaas:
 "This fixes some GPU initialization regressions caused by eddba19b8b5f
  ("PCI/AER: Support Advisory Non-Fatal Errors"), which appeared in
  v7.3-rc1.

  That commit also caused a MacBookPro16,1 spontaneous power-off
  regression; I expect a fix for that next week"

* tag 'pci-v7.3-fixes-4' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
  PCI/AER: Skip error recovery on false alarms
DeltaFile
+16-6drivers/pci/pcie/aer.c
+16-61 files

Linux/linux b71ccf6 — drivers/memstick/core memstick.c, drivers/memstick/host rtsx_usb_ms.c

Merge tag 'mmc-v7.3-rc1-2' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc

Pull MMC/MEMSTICK fixes from Ulf Hansson:
 "MMC host:
   - cavium-octeon|thunderx: Destroy slot platform devices on remove
   - mtk-sd: Cancel request timeout work on remove
   - sdhci-sprd: Disable runtime PM on remove

  MEMSTICK:
   - Wait for request completion before freeing card
   - rtsx_usb_ms: Complete requests after eject instead of dropping
     them"

* tag 'mmc-v7.3-rc1-2' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc:
  memstick: rtsx_usb_ms: complete requests after eject instead of dropping them
  memstick: core: wait for request completion before freeing card
  mmc: cavium-thunderx: destroy slot platform devices on remove
  mmc: cavium-octeon: destroy slot platform devices on remove
  mmc: sdhci-sprd: disable runtime PM on remove
  mmc: mtk-sd: Cancel request timeout work on remove
DeltaFile
+11-20drivers/memstick/host/rtsx_usb_ms.c
+2-6drivers/memstick/core/memstick.c
+4-1drivers/mmc/host/cavium-thunderx.c
+4-1drivers/mmc/host/cavium-octeon.c
+4-0drivers/mmc/host/sdhci-sprd.c
+1-0drivers/mmc/host/mtk-sd.c
+26-286 files

Linux/linux f7bec60 — drivers/media/usb/em28xx em28xx-video.c

Merge tag 'media/v7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media

Pull media fix from Mauro Carvalho Chehab:
 "A fix for em28xx unregister code affecting devices with FM radio
  support"

* tag 'media/v7.3-3' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media:
  media: em28xx: use video_unregister_device for radio_dev
DeltaFile
+2-2drivers/media/usb/em28xx/em28xx-video.c
+2-21 files

Linux/linux 5f6ee18 — sound/hda/codecs/side-codecs tas2781_hda.c, sound/soc/amd/acp amd-acp70-acpi-match.c

Merge tag 'sound-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound

Pull sound fixes from Takashi Iwai:
 "A dozen of small fixes. All device-specific quirks or fixes, and
  nothing exciting is expected.

   - USB-audio and HD-audio quirks

   - HD-audio TAS2781 codec fix

   - ctxfi driver memory leak fix

   - ASoC AMD quirks

   - ASoC cs35l56 and adau1372 codec fixes"

* tag 'sound-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound:
  ASoC: amd: acp: Add more ACP7.0 match entries for Cirrus Logic parts
  ASoC: amd: acp: Add DMI override for ASUS EXPERTBOOK AM7406CKA

    [11 lines not shown]
DeltaFile
+54-0sound/soc/codecs/cs35l56.c
+35-0sound/soc/amd/acp/amd-acp70-acpi-match.c
+14-4sound/soc/codecs/adau1372.c
+15-3sound/hda/codecs/side-codecs/tas2781_hda.c
+7-2sound/soc/codecs/cs35l56-sdw.c
+8-0sound/soc/samsung/i2s.c
+133-97 files not shown
+161-1413 files

Linux/linux 9a06d4b — drivers/pmdomain/imx imx8m-blk-ctrl.c, drivers/pmdomain/rockchip pm-domains.c

Merge tag 'pmdomain-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm

Pull pmdomain provider fixes from Ulf Hansson:

 - imx: Serialize power on/off across sibling domains for imx8m-blk-ctrl

 - rockchip: Fix a couple of errors during probe

* tag 'pmdomain-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm:
  pmdomain: rockchip: don't ignore clock lookup errors on attach
  pmdomain: rockchip: fix clock leak on domain probe failure
  pmdomain: rockchip: propagate subdomain add errors
  pmdomain: imx8m-blk-ctrl: Serialize power on/off across sibling domains
DeltaFile
+17-3drivers/pmdomain/rockchip/pm-domains.c
+15-0drivers/pmdomain/imx/imx8m-blk-ctrl.c
+32-32 files

Linux/linux c8d4256 — drivers/iommu dma-iommu.c, kernel/dma swiotlb.c

Merge tag 'dma-mapping-7.3-2026-10-09' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux

Pull dma-mapping fixes from Marek Szyprowski:
 "Two more fixes for the corner cases in the DMA-mapping SWIOTLB code
  (Peng Fan and Marek Szyprowski)"

* tag 'dma-mapping-7.3-2026-10-09' of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux:
  swiotlb: fix default_swiotlb_limit() for non-growable default pool
  iommu/dma: skip swiotlb bounce for DMA_ATTR_MMIO in iommu_dma_map_phys
DeltaFile
+3-3kernel/dma/swiotlb.c
+2-2drivers/iommu/dma-iommu.c
+5-52 files

Linux/linux fc1c250 — fs/verity open.c fsverity_private.h

Merge tag 'fsverity-for-linus' of git://git.kernel.org/pub/scm/fs/fsverity/linux

Pull fsverity fix from Eric Biggers:
 "Fix a regression from commit f77f281b6118 ("fsverity: use a hashtable
  to find the fsverity_info")"

* tag 'fsverity-for-linus' of git://git.kernel.org/pub/scm/fs/fsverity/linux:
  fsverity: RCU-delay the freeing of struct fsverity_info
DeltaFile
+14-1fs/verity/fsverity_private.h
+12-1fs/verity/open.c
+26-22 files

Linux/linux f99005f — fs namespace.c, tools/testing/selftests/filesystems/mount_cycle locked_handle_test.c unmounted_tree_test.c

Merge tag 'vfs-7.3-rc7.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs

Pull vfs fixes from Christian Brauner:
 "This contains fixes for the current development cycle.

  All of them came out of a review of the mount code that started with a
  bug report. The review modeled the corner cases of mount propagation,
  unmounting and mount reference counting and turned up a lot of bugs.
  Most of them years old. Most fixes come with a selftest.

   - Rework connected mounts.

     A mount that is unmounted together with its parent can stay
     attached to the parent to keep its mountpoint covered. That happens
     when the mountpoint is removed with rmdir(), unlink() or rename(),
     when a detached tree is dissolved, and for locked mounts in any
     umount that isn't synchronous, including the teardown of their
     mount namespace. The parent then owns the child and drops it on its
     own final mntput(). So any reference from the child's superblock

    [264 lines not shown]
DeltaFile
+1,542-0tools/testing/selftests/filesystems/mount_cycle/loop_cycle_test.c
+579-0tools/testing/selftests/filesystems/mount_cycle/mount_cover_test.c
+484-0tools/testing/selftests/filesystems/mount_cycle/unmounted_tree_test.c
+327-134fs/namespace.c
+432-0tools/testing/selftests/filesystems/umount_propagation/locked_mount_test.c
+377-0tools/testing/selftests/filesystems/mount_cycle/locked_handle_test.c
+3,741-13447 files not shown
+6,462-19553 files

Linux/linux 9515f63 — arch/arm64/include/asm el2_setup.h, arch/arm64/kernel Makefile

Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux

Pull arm64 fixes from Will Deacon:
 "It finally seems to have calmed down on the arm64 fixes front, so
  please pull these two straightforward fixes for -rc7. One fixes the
  EL2 trap configuration for implementation-defined CPU PMU hardware
  during boot and the other fixes a kcov selftest failure by excluding
  our softirq early entry code:

   - Fix PMU EL2 trap configuration for CPUs with an IMPDEF PMU

   - Fix kcov boot selftest failure by excluding our early IRQ entry
     code"

* tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:
  arm64: irq: exclude the softirq stack switch from KCOV
  arm64/boot: Don't set PMUv3p9 FGT2 bits without PMUv3
DeltaFile
+3-2arch/arm64/include/asm/el2_setup.h
+3-0arch/arm64/kernel/Makefile
+6-22 files

Linux/linux 41363c2 — drivers/input/joystick xpad.c

Input: xpad - add support for 8BitDo Pro 2 Wired Controller for Xbox

The 8BitDo Pro 2 Wired Controller for Xbox is already matched by the
vendor-wide XPAD_XBOXONE_VENDOR(0x2dc8) entry, but a later hardware
revision reports product ID 0x201e, which has no entry in the
xpad_device table. The device therefore binds and functions but is
exposed to userspace as "Generic X-Box pad".

Add the VID/PID pair so the controller is named correctly, and set
MAP_SHARE_BUTTON to expose the share button as KEY_RECORD.

Signed-off-by: Bihaan Sen <stevewholikesthings at gmail.com>
Link: https://patch.msgid.link/20260925114459.110253-1-stevewholikesthings@gmail.com
Cc: stable at vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov at gmail.com>
DeltaFile
+1-0drivers/input/joystick/xpad.c
+1-01 files

Linux/linux f9282b8 — drivers/input/joystick xpad.c

Input: xpad - add support for Corsair Novablade Pro

Add device IDs for the Corsair Novablade Pro leverless fight controller
in both wired (0x2b1f) and 2.4 GHz receiver (0x2b2b) modes, and add
Corsair's vendor ID to the Xbox 360 vendor match list.

Outside of its PS4/PS5 modes the controller uses the Xbox 360 protocol
(vendor-specific class, subclass 93, protocol 1) on interface 0, which
xpad does not currently bind, so no gamepad device is created. The
PS4/PS5 modes present a standard HID gamepad and already work with
hid-generic.

Tested on 7.2.5 with the 2.4 GHz receiver and wired.

Assisted-by: Claude Opus 5.5
Signed-off-by: Krzysztof Furman <krisfur at proton.me>
Link: https://patch.msgid.link/20261009-xpad-corsair-novablade-v1-1-e58746bef99f@proton.me
Cc: stable at vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov at gmail.com>
DeltaFile
+3-0drivers/input/joystick/xpad.c
+3-01 files

Linux/linux f321cc4 — drivers/input/misc ati_remote2.c

Input: ati_remote2 - fix type confusion in device attribute handlers

Previously, the channel_mask and mode_mask attributes were registered on
the parent usb_device via sysfs_create_group(). When commit b20d6bf8014b
("Input: ati-remote2 - use driver core to instantiate device
attributes") converted the driver to let the driver core manage them via
dev_groups in struct usb_driver, the attributes moved to the bound
usb_interface devices, but the show and store callbacks were not updated
accordingly.

As a result, the callbacks still invoked to_usb_device() on a device
pointer belonging to a struct usb_interface, producing an invalid
usb_device pointer.

Use to_usb_interface() directly in the attribute handlers to obtain the
interface and its driver data.

Fixes: b20d6bf8014b ("Input: ati-remote2 - use driver core to instantiate device attributes")
Assisted-by: DeepSeek-V4.1-Flash

    [4 lines not shown]
DeltaFile
+4-8drivers/input/misc/ati_remote2.c
+4-81 files

Linux/linux af32da4 — drivers/net/ethernet/broadcom/bnxt bnxt.c, drivers/net/ethernet/intel/iavf iavf_virtchnl.c

Merge tag 'net-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net

Pull networking fixes from Jakub Kicinski:
 "Including fixes from wireless, wireguard, CAN and Bluetooth.
  We have one known regression to wrap up in VLAN handling.

  Current release - regressions:

   - Bluetooth: RFCOMM: fix deadlock on rfcomm_mutex

  Previous releases - regressions:

   - can: fix regression in handling RPS after migrating metadata to skb_ext

   - eth:
      - iavf: fix regressions in reconfig impacting bonding
      - mana: fix packet forwarding performance regression
      - stmmac: remove buggy VLAN acceleration support


    [37 lines not shown]
DeltaFile
+125-74drivers/net/ethernet/broadcom/bnxt/bnxt.c
+136-0tools/testing/selftests/net/tun.c
+88-46drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
+95-39net/bluetooth/rfcomm/core.c
+126-0lib/dim/dim_kunit.c
+89-10drivers/net/ethernet/intel/iavf/iavf_virtchnl.c
+659-169143 files not shown
+2,074-824149 files

Linux/linux 6ccf996 — drivers/gpu/drm/nouveau nouveau_abi16.c

drm/nouveau: Skip the Turing CE workaround object for non-GR channels

This workaround is here for the old Gallium driver and predate async CE
and NVDEC.  Instead of only skipping it for NVDEC, let's only apply it
in case of GR channels.

This should make async CE work properly on Turing by stopping the assign
of a GRCE. (here CE0)

Signed-off-by: Mary Guillemard <mary at mary.zone>
Reviewed-by: Lyude Paul <lyude at redhat.com>
Reviewed-by: Daniel Almeida <daniel.almeida at collabora.com>
Signed-off-by: Lyude Paul <lyude at redhat.com>
Link: https://patch.msgid.link/20261007-turing-async-ce-fix-v1-1-12ee6ccd1a3c@mary.zone
DeltaFile
+1-1drivers/gpu/drm/nouveau/nouveau_abi16.c
+1-11 files

Linux/linux 79c168e — drivers/pci/pcie aer.c

PCI/AER: Skip error recovery on false alarms

Alex is seeing a probe failure of the amdgpu driver after the Root Port
above an AMD Navi10 GPU has been reset.  The reset was performed to recover
from a Firmware First reported Fatal Error.

However all status registers in the Root Port's AER Extended Capability are
blank, so apparently the platform firmware raised a false alarm.

The issue is only occurring since commit eddba19b8b5f ("PCI/AER: Support
Advisory Non-Fatal Errors").  It looks like enabling Advisory Non-Fatal
Errors causes code paths to be exercised in platform firmware which were
never validated before.

Skip error recovery on false alarms, i.e. if no unmasked errors were
actually signaled.

Note that this will also skip recovery if both the Status and Mask
registers are "all ones", as would be the case for inaccessible devices.

    [12 lines not shown]
DeltaFile
+16-6drivers/pci/pcie/aer.c
+16-61 files

Linux/linux cca0123 — drivers/gpu/drm/vc4 vc4_validate.c vc4_drv.h

drm/vc4: Fix binner slot allocation failing on an idle GPU

A job's binner slots are returned to bin_alloc_used by vc4_complete_exec(),
which runs from the job_done workqueue, but the seqno
vc4_v3d_get_bin_slot() waits on is incremented earlier, in the function
vc4_irq_finish_render_job(). Therefore, a waiter can wake, retry, and still
find the pool full because the worker has not run. By then, the job might
have left the render_job_list, so no seqno remains to wait on and the
allocation fails returning -ENOMEM.

This scenario can be reproduced on a Raspberry Pi 3 by using a burst of
small jobs (e.g. Piglit's `quick_gl` suite), with userspace seeing a
rejected submit for a pool about to become free.

Note that the slots are held from validation until the render completes,
so the pool can also be exhausted by jobs still queued on bin_job_list,
leaving render_job_list empty and nothing to wait on.

Release the slots from the FRDONE handler and wait on the pool instead of

    [19 lines not shown]
DeltaFile
+20-24drivers/gpu/drm/vc4/vc4_v3d.c
+7-1drivers/gpu/drm/vc4/vc4_gem.c
+5-1drivers/gpu/drm/vc4/vc4_irq.c
+1-1drivers/gpu/drm/vc4/vc4_validate.c
+1-1drivers/gpu/drm/vc4/vc4_drv.h
+34-285 files

Linux/linux 6abc8e4 — drivers/gpu/drm/vc4 vc4_v3d.c vc4_irq.c

drm/vc4: Disable the V3D interrupt across runtime suspend

vc4_irq_disable() masks the V3D interrupt sources and then calls
synchronize_irq() before the V3D is powered down. However, by itself,
this is not enough to quiesce the interrupt handler.

synchronize_irq() waits for handlers that have already set
IRQD_IRQ_INPROGRESS, and for irqchips reporting IRQCHIP_STATE_ACTIVE.
A GIC interrupt chip is able to mark an interrupt active as soon as a
CPU acknowledges it, so there these checks cover the whole dispatch path.
On RPi 0-3, however, the interrupt controller is ARMCTRL, which has no
active state. A CPU that has read the hwirq out of the pending register
but has not yet reached handle_level_irq() stays invisible to
synchronize_irq().

During a power transition, vc4_irq() may therefore run after the power
domain is off, where every V3D register read will return 0xdeadbeef.
0xdeadbeef has FLDONE, FRDONE and OUTOMEM set. This problem doesn't
trigger NULL pointer dereference issues only because the functions

    [13 lines not shown]
DeltaFile
+3-15drivers/gpu/drm/vc4/vc4_irq.c
+7-6drivers/gpu/drm/vc4/vc4_v3d.c
+10-212 files

Linux/linux 37f1244 — drivers/net/ethernet/cadence macb_main.c

Merge branch 'net-macb-fix-software-fcs-handling-of-shared-and-requeued-skbs'

Nicolai Buchwitz says:

====================
net: macb: fix software FCS handling of shared and requeued skbs

While testing the genet MTU series I used a Raspberry Pi CM5 (RP1 GEM)
as pktgen source for the CM4. With clone_skb the CM5 rebooted after a
few seconds. Further investigation showed that macb_pad_and_fcs()
appends the FCS in place, so the shared skb grows with every transmit
until BQL completes more than was queued and dql_completed() hits its
BUG_ON.

The same code also modifies the skb before the TX ring check, so a
NETDEV_TX_BUSY retry gets an skb that was already replaced or grown.

Patch 1 checks the ring first, patch 2 copies shared skbs.


    [6 lines not shown]
DeltaFile
+49-31drivers/net/ethernet/cadence/macb_main.c
+49-311 files

Linux/linux 6b48ed8 — drivers/net/ethernet/cadence macb_main.c

net: macb: check TX ring before modifying skb

macb_pad_and_fcs() replaces or extends the skb before the ring space
check. On NETDEV_TX_BUSY the stack requeues an skb that is already freed
or grown.

Check the ring first, using the padded length for the descriptor count.
Nonlinear skbs always take the copy path so the count can assume a
linear skb.

Fixes: 653e92a9175e ("net: macb: add support for padding and fcs computation")
Signed-off-by: Nicolai Buchwitz <nb at tipi-net.de>
Link: https://patch.msgid.link/20261006-nb-macb-shared-skb-net-v1-1-a80641479041@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
DeltaFile
+46-30drivers/net/ethernet/cadence/macb_main.c
+46-301 files

Linux/linux 9151d6c — drivers/net/ethernet/cadence macb_main.c

net: macb: copy shared skbs before appending the FCS

macb_pad_and_fcs() appends the FCS in place when the skb has tailroom.
A shared skb, as pktgen sends in clone_skb mode, grows by one FCS per
transmit. BQL then completes more bytes than were queued and
dql_completed() hits its BUG_ON.

On a Raspberry Pi CM5 (RP1 GEM) pktgen with clone_skb 1000 burst 32 at
60 bytes kills the box within seconds.

Copy shared skbs before appending the FCS. Clearing IFF_TX_SKB_SHARING
would also fix it but makes pktgen refuse clone_skb on macb.

Fixes: 653e92a9175e ("net: macb: add support for padding and fcs computation")
Signed-off-by: Nicolai Buchwitz <nb at tipi-net.de>
Link: https://patch.msgid.link/20261006-nb-macb-shared-skb-net-v1-2-a80641479041@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
DeltaFile
+4-2drivers/net/ethernet/cadence/macb_main.c
+4-21 files

Linux/linux 7c24a4e — net/vmw_vsock af_vsock.c

vsock: Fix memory leak in vmci_transport_recv_dgram_cb()

During the closure of a datagram socket, the vmci_transport_recv_dgram_cb()
function may be called, which will add the packets
to the socket's backlog; then, after the receive queue is cleared,
the __release_sock() function will move the packet back from the socket's
backlog to the receive queue, which will lead to a memory leak.

sock_close
  __sock_release
    __vsock_release
      // take ownership by user-space
      lock_sock_nested
      sock_set_flag(sk, SOCK_DEAD)
      vmci_transport_release
                                      vmci_dispatch_dgs
                                        vmci_datagram_invoke_guest_handler
                                          vmci_transport_recv_dgram_cb
                                            sk_receive_skb

    [49 lines not shown]
DeltaFile
+2-0net/vmw_vsock/af_vsock.c
+2-01 files

Linux/linux fe4167b — drivers/net/wireguard queueing.h noise.c

Merge branch 'wireguard-fixes-for-7-3-rc7'

Jason A. Donenfeld says:

====================
WireGuard fixes for 7.3-rc7

This series contains two important WireGuard fixes

1) Stop zeroing out skb->tstamp_type when encapsulating packets, so that
   fq behaves correctly, from Ramses de Norre.

2) Make sure handshake state isn't swapped out while locks are
   released, reported by Jérémy Jean.
====================

Link: https://patch.msgid.link/20261008130124.724119-1-Jason@zx2c4.com
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
DeltaFile
+4-3drivers/net/wireguard/noise.c
+2-0drivers/net/wireguard/queueing.h
+6-32 files

Linux/linux 65ab9de — drivers/net/wireguard queueing.h

wireguard: queueing: preserve tstamp_type when encapsulating packet

Sending traffic through a wireguard tunnel on a host using the fq
qdisc fills the log with:

  fq: likely mono tstamp with tstamp_type 0

An skb carries a timestamp in skb->tstamp and, separately, a
skb->tstamp_type field recording which clock that timestamp came from.
The two have to agree.

When wireguard encapsulates a packet it calls wg_reset_packet(), which
clears the fields that must not leak from the inner packet into the
tunnel packet. It does so in two steps:

  skb_scrub_packet(skb, true);
  memset(&skb->headers, 0, sizeof(skb->headers));

skb_scrub_packet() deliberately keeps skb->tstamp when it holds a

    [25 lines not shown]
DeltaFile
+2-0drivers/net/wireguard/queueing.h
+2-01 files