Linux/linux 3b7cab6 — block blk-mq.c, drivers/nvme/host nvme.h multipath.c

Merge tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull block fixes from Jens Axboe:

 - NVMe fixes via Keith:
     - Fix an out-of-bounds write in nvmet_auth_challenge(), where
       sizeof() on a void pointer undercounted the challenge header and
       let a short AUTH_RECEIVE buffer pass the check
     - nvme-multipath fixes for an ANA log bounds check underflow, the
       command effects log lifetime for multipath heads, and only
       setting BLK_FEAT_ZONED after the zone info is known.
     - nvmet fixes for ns->enabled teardown ordering, rejecting I/O
       after the percpu ns reference is killed, device path preservation
       on allocation failure, and too-short SGL segments in pci-epf
     - nvme-tcp: revert the per-socket dynamic lockdep keys, and delay
       the socket reclassification
     - A DMA pool alignment quirk for the Micron 4100AT
     - Controller state/reset race fixes, and -Wformat-security
       workarounds

    [34 lines not shown]
DeltaFile
+28-35drivers/nvme/host/core.c
+37-26block/blk-mq.c
+13-26drivers/nvme/host/tcp.c
+21-14drivers/nvme/target/core.c
+8-11drivers/nvme/host/multipath.c
+5-4drivers/nvme/host/nvme.h
+112-11613 files not shown
+140-13119 files

Linux/linux 3f1fe48 — io_uring bpf_filter.c tw.c

Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull io_uring fixes from Jens Axboe:

 - Fix a task_work add use-after-free with SQPOLL.

   The sqpoll thread could pop and complete the last request while
   io_req_normal_work_add() was still looking at them after the mpscq
   push.

   Use the same approach as DEFER_TASKRUN to protect from that, holding
   an RCU read lock across the add, and have exit wait for an RCU grace
   period for SQPOLL rings as well.

 - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
   big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
   rings

 - Mark the source filter table as COW when cloning bpf filters, so

    [18 lines not shown]
DeltaFile
+14-5io_uring/cmd_net.c
+9-7io_uring/io_uring.c
+7-2io_uring/zcrx.c
+5-0io_uring/loop.c
+3-0io_uring/tw.c
+1-0io_uring/bpf_filter.c
+39-146 files

Linux/linux 5d144c2 — drivers/spi spi-cs42l43.c, sound/hda/codecs/realtek alc269.c

Merge tag 'sound-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound

Pull sound fixes from Takashi Iwai:
 "A fair amount of small fixes, which became much larger as a pile of
  pending homework during my vacation in the last weeks.

  The majority of changes are device-specific quirks and ASoC updates,
  along with a few ALSA core fixes and USB-audio hardening as well as a
  few regression fixes.

  ALSA Core:
   - Serialize ALSA sequencer compat port-info ioctls

  HD-audio:
   - Fix ALC235 codec headset handling
   - Fix regression on Tegra194 controller support
   - Quirks / fixes for Lenovo, ASUS, Acer, Dell, Higole, HP, and IPASON
     laptops


    [42 lines not shown]
DeltaFile
+97-0drivers/spi/spi-cs42l43.c
+58-4sound/hda/codecs/realtek/alc269.c
+8-19sound/soc/codecs/rt1017-sdca-sdw.c
+20-0sound/soc/amd/acp/amd-acp70-acpi-match.c
+13-6sound/soc/sdca/sdca_class_function.c
+17-0sound/soc/intel/boards/bytcr_rt5651.c
+213-2925 files not shown
+331-4631 files

Linux/linux ac7445c — arch/x86/entry/vdso/vdso64 Makefile, drivers/virt vmgenid.c

Merge tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random

Pull random number generator fixes from Jason Donenfeld:

 - VMGENID memory needs to be mapped with the decrypted tag, so that
   SEV-SNP machines can boot

 - A fix for an initialization race in VMGENID, followed by a cleanup

 - Trivial kernel doc cleanups in siphash and random.c

 - A fix for a new compilation failure with recent clang on PPC and
   RISC-V, due to generating an out-of-line memset in the vDSO

* tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random:
  random: vDSO: avoid call to memset() when zeroing reserved parameter
  random: fix vgetrandom_opaque_params kernel-doc
  random: vDSO: fix repeated word 'to' in comment
  siphash: clean up kernel-doc comments

    [3 lines not shown]
DeltaFile
+7-4drivers/virt/vmgenid.c
+6-2include/linux/siphash.h
+5-0init/Kconfig
+1-1include/vdso/getrandom.h
+1-1include/uapi/linux/random.h
+1-1arch/x86/entry/vdso/vdso64/Makefile
+21-95 files not shown
+26-1011 files

Linux/linux 4e9a2de — . MAINTAINERS, mm slub.c

Merge tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab

Pull slab fixes from Vlastimil Babka:

 - Stable fix for a potential deadlock in kfree_rcu() when called
   from set_cpus_allowed_force() (Harry Yoo)

 - MAINTAINERS update of the slab.git URL

* tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab:
  mm/slab: do not wake up kswapd in __kfree_rcu_sheaf()
  MAINTAINERS: update slab.git URL
DeltaFile
+4-3mm/slub.c
+1-1MAINTAINERS
+5-42 files

Linux/linux 5e0f839 — drivers/hid hid-ids.h hid-logitech-dj.c, drivers/hid/intel-thc-hid/intel-quicki2c pci-quicki2c.c

Merge tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid

Pull HID fixes from Benjamin Tissoires:

 - Revert of the Bolt integration into hid-logitech-dj (Benjamin
   Tissoires)

 - A couple of buffer overflow in Intel-thc-hid (Even Xu)

 - A couple of Sashiko findings fixes in hid-multitouch and HID-BPF
   (Aldo Ariel Panzardo and Benjamin Tissoires)

* tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid:
  selftest/hid: add test for negative return codes for hid_bpf_hw_request
  HID: bpf: cast size to ssize_t when checking hid_bpf_hw_request
  HID: Intel-thc-hid: Intel-quickspi: Fix buffer overflow
  HID: Intel-thc-hid: Intel-quicki2c: Fix buffer overflow
  HID: universal-pidff: Add support for Turtle Beach VelocityOne Race
  HID: multitouch: stop the release timer from being rearmed on remove
  Revert "HID: logitech: add Bolt receiver support for Logitech HID++ devices"
DeltaFile
+4-47drivers/hid/hid-logitech-hidpp.c
+4-44drivers/hid/hid-logitech-dj.c
+31-0tools/testing/selftests/hid/hid_bpf.c
+4-2drivers/hid/intel-thc-hid/intel-quicki2c/pci-quicki2c.c
+2-1drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
+3-0drivers/hid/hid-ids.h
+48-943 files not shown
+51-969 files

Linux/linux 17a5800 — drivers/char/tpm tpm2-sessions.c tpm-interface.c

Merge tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd

Pull tpm fixes from Jarkko Sakkinen.

 - tpm error handling and buffer size fixes

* tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  tpm: Disable TPM on null key name mismatch
  tpm: fix off-by-four bounds check in tpm2_get_random()
  tpm: Fix auth session leak in tpm2_get_random() error path
  tpm: Fix heap buffer overflow in tpm_transmit_cmd()
DeltaFile
+4-2drivers/char/tpm/tpm2-cmd.c
+1-1drivers/char/tpm/tpm-interface.c
+1-0drivers/char/tpm/tpm2-sessions.c
+6-33 files

Linux/linux b4e7fc3 — arch/mips/configs econet_en751221_defconfig, drivers/phy/renesas phy-rcar-gen3-usb2.c

Merge tag 'asoc-fix-v7.3-rc5' of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus

ASoC: Fixes for v7.3

A bigger collection of fixes than usual due to your vacation but nothing
hugely remarkable here, just fairly standard quirks and driver specific
bugfixes.
DeltaFile
+0-1,029lib/alloc_tag.c
+354-101fs/ntfs/mft.c
+311-0tools/testing/selftests/x86/int_signal.c
+265-45drivers/phy/renesas/phy-rcar-gen3-usb2.c
+264-0arch/mips/configs/econet_en751221_defconfig
+203-56fs/ntfs/attrib.c
+1,397-1,231486 files not shown
+7,382-3,305492 files

Linux/linux eb13a1f — arch/arm64/kernel/vdso Makefile, arch/loongarch/vdso Makefile

random: vDSO: avoid call to memset() when zeroing reserved parameter

After a recent change in LLVM [1], builds with the random vDSO
implementation, such as PowerPC and RISC-V, fail when checking the vDSO:

  arch/powerpc/kernel/vdso/vdso32.so.dbg: dynamic relocations are not supported
  arch/riscv/kernel/vdso/vdso.so.dbg: dynamic relocations are not supported

memset() is now generated when zeroing params->reserved for some builds
because LLVM has an optimization (now run in more instances) that can
recognize at compile time when it is assigning a static value to a
contiguous area of memory and turn that into a call to memset(). Both
clang and GCC assume memset() is always available [2].

Clang has an internal fiddly hook, -max-store-memset, which we can set
to a high number, to disable generating out of line memset calls [3].
Similarly, GCC has -finline-stringops=memset to do the same [4], should
this issue ever hit future version of GCC. While these options wouldn't
make sense for normal kernel code, it is fine for the extremely limited

    [10 lines not shown]
DeltaFile
+5-0init/Kconfig
+1-1arch/x86/entry/vdso/vdso64/Makefile
+1-1arch/arm64/kernel/vdso/Makefile
+1-0arch/riscv/kernel/vdso/Makefile
+1-0arch/powerpc/kernel/vdso/Makefile
+1-0arch/loongarch/vdso/Makefile
+10-21 files not shown
+11-27 files

Linux/linux ce1e022 — drivers/of irq.c base.c

Merge tag 'devicetree-fixes-for-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux

Pull devicetree fixes from Rob Herring:

 - Fix another case of refcount leaks in of_irq_init()

 - Avoid refcount leak in coreboot node check

 - Fix overlay handling of a root node target path

 - Various error path fixes in the overlay code

* tag 'devicetree-fixes-for-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux:
  of/irq: Fix remaining refcount leaks in of_irq_init()
  of: Put coreboot node after compatibility check
  of/overlay: don't create "//" paths for fragments targeting the root
  of/overlay: don't leak fragment references when changeset init fails
  of/overlay: only treat a positive changeset id as registered
  of/overlay: put property on deadprops only after changeset add succeeds
DeltaFile
+13-4drivers/of/overlay.c
+9-1drivers/of/base.c
+2-0drivers/of/irq.c
+24-53 files

Linux/linux 100638f — drivers/cpufreq cpufreq.c intel_pstate.c, include/linux cpufreq.h

Merge tag 'pm-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm

Pull power management fix from Rafael Wysocki:
 "Restore the previous behavior on systems where the cpufreq pressure
  was not visible in the scheduler and is not expected to be visible
  there.

  It became visible after a change made during the 7.2 development cycle
  that had gone too far"

* tag 'pm-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:
  cpufreq: intel_pstate: Fix max_freq fallback in cpufreq_update_pressure()
DeltaFile
+10-0drivers/cpufreq/intel_pstate.c
+2-2drivers/cpufreq/cpufreq.c
+3-0include/linux/cpufreq.h
+15-23 files

Linux/linux bd35955 — arch/x86/crypto aesni-intel_glue.c, crypto aes.c

Merge tag 'libcrypto-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux

Pull crypto library fixes from Eric Biggers:

 - Fix a performance regression in certain AES encryption modes on
   certain architectures, introduced this cycle

 - Fix a small performance regression in the x86_64 optimized AES-GCM
   code, introduced in 6.15

* tag 'libcrypto-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux:
  crypto: aes - Fix undesired override of some optimized AES modes
  crypto: x86/aes-gcm - fix always true check for last AAD segment
DeltaFile
+47-4crypto/aes.c
+1-1arch/x86/crypto/aesni-intel_glue.c
+48-52 files

Linux/linux a940b03 — arch/arm64/kvm mmu.c, arch/x86/kvm/svm svm.c sev.c

Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm

Pull kvm fixes from Paolo Bonzini:
 "The most intrusive change is reverting a commit from 7.3-rc1 that made
  struct kvm a bit too large, and fixing the same issue otherwise.

  There are again a lot of selftests lines; the sheer number of commits
  is not small but I don't expect much more for 7.3 due to people
  travelling to Plumbers next week.

  ARM:

   - Take a reference on the last IRQ loaded into an LR to prevent it
     from being freed while running the guest (Marc Zyngier)

   - Ensure that the ITS MOVALL command only affects LPIs that were
     previously affined to the source redistributor (Marc Zyngier)

   - Fix + test for honoring the host's trap configuration when running

    [55 lines not shown]
DeltaFile
+222-0tools/testing/selftests/kvm/x86/nested_x2apic_test.c
+184-0tools/testing/selftests/kvm/arm64/hidden_features.c
+29-28arch/x86/kvm/svm/sev.c
+6-41arch/arm64/kvm/mmu.c
+20-23arch/x86/kvm/svm/svm.c
+11-24virt/kvm/kvm_main.c
+472-11618 files not shown
+554-16524 files

Linux/linux f9bfc32 — arch/arm64/kvm mmu.c, arch/arm64/kvm/hyp/include/nvhe pkvm.h

Merge tag 'kvmarm-fixes-7.3-2' of https://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm into HEAD

KVM/arm64 fixes for 7.3, round #2

 - Take a reference on the last IRQ loaded into an LR to prevent it
   from being freed while running the guest (Marc Zyngier)

 - Ensure that the ITS MOVALL command only affects LPIs that were
   previously affined to the source redistributor (Marc Zyngier)

 - Fix + test for honoring the host's trap configuration when running
   non-protected VMs while KVM is in protected mode (Fuad Tabba)

 - Use the host stage-1 mapping granularity for VM_PFNMAP mappings at
   stage-2 (Mostafa Saleh)
DeltaFile
+184-0tools/testing/selftests/kvm/arm64/hidden_features.c
+6-41arch/arm64/kvm/mmu.c
+16-9arch/arm64/kvm/hyp/nvhe/pkvm.c
+16-5arch/arm64/kvm/vgic/vgic.c
+8-4arch/arm64/kvm/vgic/vgic-its.c
+9-0arch/arm64/kvm/hyp/include/nvhe/pkvm.h
+239-595 files not shown
+252-6911 files

Linux/linux 71cc2c6 — arch/arm64/kvm mmu.c

KVM: arm64: Use stage-1 leaf size for VM_PFNMAP

When commit 2aa53d68cee6 ("KVM: arm64: Try stage2 block mapping for
host device MMIO") added VM_PFNMAP support to get_vma_page_shift(),
stage-1 page tables did not support huge PFNMAP (as in VFIO-PCI
vfio_pci_mmap_huge_fault()) and transparent_hugepage_adjust() was
unsafe for MMIO as it dereferenced struct page.

Since commit 6011cf68c885 ("KVM: arm64: Walk userspace page tables to
compute the THP mapping size"), transparent_hugepage_adjust() instead
walks the host stage-1 page tables via get_user_mapping_size() without
touching struct page. Meanwhile, commit 3e509c9b03f9 ("mm/arm64:
support large pfn mappings") enabled stage-1 huge PFNMAP.

So. we can drop the VMA-based VM_PFNMAP size calculation in
get_vma_page_shift() and let transparent_hugepage_adjust() derive
the stage-2 mapping size directly from the populated stage-1 leaf
for non-cacheable mappings as well.


    [6 lines not shown]
DeltaFile
+6-41arch/arm64/kvm/mmu.c
+6-411 files

Linux/linux cad16d8 — drivers/spi spi-cs42l43.c

spi: cs42l43: Workaround for wrong speaker ID on Dell XPS 13 DX13260

On Dell XPS 13 DX13260 create an acpi_gpio_mapping with exactly two
GPIO entries to point at the two pins in the GpioIo(). Use this to
read the speaker ID GPIOs.

This fixes problems on Dell XPS 13 DX13260:

- No speaker audio
- The wrong firmware was loaded so the speaker protection did not match
  the speaker characteristics.

The Dell XPS 13 DX13260 has two speaker ID GPIOs, to form a 2-bit ID. The
ACPI GpioIo() has both pins but the Linux-specific spk-id-gpios property
only has a mapping to the first pin. This meant that the speaker ID was
wrong in most cases, and that would lead to the codec driver loading the
wrong amp firmware, or not finding a firmware (as 0 is not a valid ID on
this laptop).


    [9 lines not shown]
DeltaFile
+97-0drivers/spi/spi-cs42l43.c
+97-01 files

Linux/linux f1d565d — include/sound core.h

ALSA: core: Define auto-cleanup for snd_card_free()

For the errors at the probe time, we'd need to call rather
snd_card_free() instead of the snd_card_unref() -- the former calls
explicitly snd_card_disconnect() that cleans up the registered
devices, etc, while the latter may leak in corner cases.

For convenience, define a new auto-clean with snd_card_free.

Link: https://patch.msgid.link/20261001151039.592033-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai at suse.de>
DeltaFile
+9-0include/sound/core.h
+9-01 files

Linux/linux e6229c0 — sound/pci/ice1712 ice1712.c

ALSA: ice1712: Fix the error handling via auto-cleanup at probe

We used the auto-cleanup via snd_card_unref() for errors at probe of
ice1712 driver, but this may be problematic in a subtle way when an
error happens at snd_card_register(); since snd_card_unref() skips the
snd_card_disconnect() call, it may miss some resource clearance.

For fixing the issue, use the new __free(snd_card_free) instead, which
does call snd_card_free() explicitly at errors for avoiding such a
pitfall.

Fixes: d736eba9c453 ("ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup")
Link: https://patch.msgid.link/20261001151039.592033-2-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai at suse.de>
DeltaFile
+1-1sound/pci/ice1712/ice1712.c
+1-11 files

Linux/linux d24e8ac — drivers/net/ethernet/stmicro/stmmac stmmac_main.c, net/core dev.c

Merge tag 'net-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net

Pull networking fixes from Paolo Abeni:
 "Including fixes from Bluetooth, WiFi and netfilter.

  We are actively retargeting several non-urgent fixes towards next,
  but the traffic on the ML looks ever-increasing, and propagating the
  push-back towards subsystems is not immediate.

  No known outstanding regressions.

  Current release - regressions:

   - netfilter: nft_set_rbtree: skip transaction elements during GC

  Previous releases - regressions:

   - sched: cls_api: reclaim an empty proto on the error path


    [59 lines not shown]
DeltaFile
+378-0tools/testing/selftests/net/udp_splice_checksum.c
+117-23net/ipv6/seg6_local.c
+81-8net/mac80211/rc80211_minstrel_ht.c
+49-34drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+55-23net/core/dev.c
+70-0net/mac80211/status.c
+750-88105 files not shown
+1,442-345111 files

Linux/linux 703033e — kernel sysctl.c, kernel/time jiffies.c

Merge tag 'sysctl-7.03-fixes-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl

Pull sysctl fixes from Joel Granados:
 "Fix sysctl jiffies conversions errors introduced in 2dc164a48e6f
  ("sysctl: Create converter functions with two new macros")

   - Ensure that mult_hz does *not* wrap

   - Ensure we pass just the magnitude for the negative branch in
     proc_int_k2u_conv_kop"

* tag 'sysctl-7.03-fixes-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl:
  time/jiffies: Saturate in mult_hz() instead of wrapping
  sysctl: Negate before converting in the int read path
DeltaFile
+1-1kernel/sysctl.c
+2-0kernel/time/jiffies.c
+3-12 files

Linux/linux e23a64e — net/mac80211 iface.c, net/netfilter nf_nat_core.c nft_flow_offload.c

Merge tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf

Pablo Neira Ayuso says:

====================
Netfilter/IPVS fixes for net

The following batch contains Netfilter fixes for net. This batch
fixes crashes as recent feature regression, one of the due to a
dependency that has been pulled into -stable:

1) Expand existing ipset fix for bitmap sets to disallow comments
   updates from kernel-side adds, from Florian Westphal.

2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise
   flowtable cannot ever be removed, from Aohan Mei.

3) nft_rbtree GC should collect end elements that contained in
   this transaction batch, new or deleted elements are never

    [44 lines not shown]
DeltaFile
+30-3net/netfilter/ipvs/ip_vs_sync.c
+5-9net/netfilter/nf_flow_table_offload.c
+6-1net/netfilter/nft_flow_offload.c
+6-1net/netfilter/nf_flow_table_core.c
+7-0net/mac80211/iface.c
+3-2net/netfilter/nf_nat_core.c
+57-1610 files not shown
+81-1916 files

Linux/linux 6e0022b — drivers/net/phy/aquantia aquantia_main.c

net: phy: aquantia: fix system interface type not updated in forced mode

aqr_gen1_read_status() decodes the MDIO_PHYXS_VEND_IF_STATUS register
to determine which SerDes interface the PHY is currently using on its
system side and stores the result in phydev->interface. phylink relies
on this value to configure the MAC.

The autoneg == AUTONEG_DISABLE check is not correct:
MDIO_PHYXS_VEND_IF_STATUS is set by the PHY firmware based on the
negotiated link speed, not based on whether autoneg was used to reach
it. When the link comes up at 1G in forced mode, the register correctly
reads SGMII, but the early return prevents phydev->interface from being
updated. It stays at whatever value it held before (typically 2500BASE-X
from the initial autoneg run), so phylink configures the MAC for the
wrong interface and the link cannot come up.

Remove the autoneg guard so that the system interface type is always
decoded when the link is up.


    [5 lines not shown]
DeltaFile
+4-1drivers/net/phy/aquantia/aquantia_main.c
+4-11 files

Linux/linux 9ee4266 — sound/hda/codecs/realtek realtek.c

ALSA: hda/realtek: Add ALC235 support for headset mode

The ALC235 (0x10ec0235) is registered as the ALC255 codec variant in
patch_alc269(), but the headset mode functions were missing a case
for it, so the CTIA/OMTP jack type detection and routing never ran
on this codec. As a result, a plugged-in headset is detected (jack
presence works) but the microphone signal is never routed, leaving
the capture stream permanently silent.

Verified on an ASUS M5451GA laptop (HDA:10ec0235,10431814): with the
ALC255 coef sequence applied, the headset microphone works correctly.

Signed-off-by: Zeyu Li <13776528859 at 163.com>
Link: https://patch.msgid.link/20260926140336.27896-1-13776528859@163.com
Signed-off-by: Takashi Iwai <tiwai at suse.de>
DeltaFile
+6-0sound/hda/codecs/realtek/realtek.c
+6-01 files

Linux/linux 5cd9813 — kernel audit_tree.c

Merge tag 'audit-pr-20260930' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit

Pull audit fix from Paul Moore:
 "A single audit fix for a potential UAF error in some audit filter
  configurations"

* tag 'audit-pr-20260930' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit:
  audit: fix exe mark UAF in kill_rules()
DeltaFile
+26-10kernel/audit_tree.c
+26-101 files

Linux/linux 7375d38 — drivers/net/usb qmi_wwan.c

net: usb: qmi_wwan: add Rolling Wireless RN947R

Add Rolling Wireless RN947R 0x9300 composition:

DIAG + ADB + NMEA + MODEM + RMNET + QDSS + ADPL

T:  Bus=01 Lev=01 Prnt=01 Port=02 Cnt=02 Dev#=  6 Spd=480  MxCh= 0
D:  Ver= 2.10 Cls=ef(misc ) Sub=02 Prot=01 MxPS=64 #Cfgs=  1
P:  Vendor=33f8 ProdID=9300 Rev= 0.00
S:  Manufacturer=Rolling Wireless
S:  Product=RN947R
S:  SerialNumber=xxxxxxxxxxx
C:* #Ifs= 7 Cfg#= 1 Atr=a0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=42 Prot=01 Driver=usbfs
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=82(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

    [20 lines not shown]
DeltaFile
+1-0drivers/net/usb/qmi_wwan.c
+1-01 files

Linux/linux 8f1c2a1 — drivers/net/ethernet/marvell mvneta.c, include/net xdp.h

net: mvneta: clear XDP pfmemalloc flag between frames

mvneta_swbm_add_rx_fragment() sets XDP_FLAGS_FRAGS_PF_MEMALLOC on the
xdp_buff when a fragment page is a pfmemalloc one (page under memory
pressure). The xdp_buff is reused for the next frame, but only the
XDP_FLAGS_HAS_FRAGS bit was cleared at frame start, so the pfmemalloc
bit leaked from one frame into the following ones. mvneta_swbm_build_skb()
propagates the flag to skb->pfmemalloc through xdp_update_skb_frags_info(),
so the skb of a subsequent fragmented frame could be wrongly marked as
pfmemalloc even if none of its pages are under pressure.

Clear all the xdp_buff flags in mvneta_swbm_rx_frame(), which is invoked
for each new frame, instead of just the XDP_FLAGS_HAS_FRAGS bit.

Fixes: ed7a58cb40bd ("net: marvell: rely on xdp_update_skb_shared_info utility routine")
Reviewed-by: Simon Horman <horms at kernel.org>
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi at oss.qualcomm.com>
Reviewed-by: Toke Høiland-Jørgensen <toke at redhat.com>
Link: https://patch.msgid.link/20260929-mvneta-xdp-clear-frag-fix-v4-1-1e63b25eeed8@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
DeltaFile
+5-0include/net/xdp.h
+1-1drivers/net/ethernet/marvell/mvneta.c
+6-12 files

Linux/linux 8ec454d — net/ipv6 seg6_iptunnel.c

ipv6: sr: use skb_get_hash_net() in seg6_make_flowlabel()

Since commit d58e468b1112 ("flow_dissector: implements flow dissector
BPF hook") __skb_flow_dissect() needs a net pointer, either from
skb->dev, skb->sk, or since commit 3cbf4ffba5ee ("net: plumb network
namespace into __skb_flow_dissect") a caller provided pointer.

syzbot was able to reach seg6_make_flowlabel() with an skb having
neither skb->dev nor skb->sk set: a TIPC UDP bearer sends a discovery
message through an IPv4 route using seg6 encap, while
net.ipv6.seg6_flowlabel is set to 1.

seg6_make_flowlabel() already has a net pointer, use skb_get_hash_net().

WARNING: net/core/flow_dissector.c:1131 at __skb_flow_dissect+0x910/0x5368 net/core/flow_dissector.c:1126, CPU#0: syz.0.17/4930
Call trace:
  __skb_flow_dissect+0x910/0x5368 net/core/flow_dissector.c:1126 (P)
  __skb_get_hash_net+0xe0/0x29c net/core/flow_dissector.c:1903
  skb_get_hash include/linux/skbuff.h:1663 [inline]

    [26 lines not shown]
DeltaFile
+1-1net/ipv6/seg6_iptunnel.c
+1-11 files

Linux/linux 7b97273 — drivers/net/ethernet/mellanox/mlx5/core/en xdp.c

net/mlx5e: Fix AF_XDP TX timestamp teardown NULL dereference

During XSK TX queue teardown, outstanding descriptors are completed
without a CQE. If one requested a TX timestamp, the completion path
passes that NULL CQE to mlx5e_xsk_fill_timestamp(), which dereferences
it.

Return zero when no CQE is available, indicating that teardown did not
produce a TX timestamp.

Fixes: ec706a860eba ("net/mlx5e: Implement AF_XDP TX timestamp and checksum offload")
Signed-off-by: Prathamesh Deshpande <prathameshdeshpande7 at gmail.com>
Reviewed-by: Tariq Toukan <tariqt at nvidia.com>
Link: https://patch.msgid.link/20260926165402.5902-1-prathameshdeshpande7@gmail.com
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
DeltaFile
+3-0drivers/net/ethernet/mellanox/mlx5/core/en/xdp.c
+3-01 files

Linux/linux 3cdeaef — drivers/net/ethernet/realtek r8169_main.c

r8169: disable EEE on RTL8168h/8111h

Force EEE off on the RTL8168h/8111h (RTL_GIGA_MAC_VER_46) at PHY connect
with phy_disable_eee().

Commit 202fef9bbbf5 ("net: phy: realtek: fix EEE advertisement write on
the internal PHY MMD path") made EEE actually advertise on the generic
Realtek PHY; the write had been a no-op before. On the RTL8168h that
un-masks a latent defect: once EEE negotiates, RX silently stalls after
~7-20 minutes. The carrier stays up, no counter or dmesg moves, and only
"ip link set down/up" recovers it; disabling EEE keeps the link stable.

Root-causing the RTL8168h LPI/RX path needs hardware not available now, so
disable EEE for this version. Use phy_disable_eee() rather than dropping
the version from rtl_supports_eee(): the latter also skips
rtl_enable_tx_lpi(), whose disable branch clears the MAC TX-LPI bits (ERI
0x1b0[1:0]) on link up. rtl_hw_start_8168h_1() does not clear them (the
RTL8402/RTL8106e init does), so a warm reboot from an EEE-active state
could otherwise leave TX-LPI asserted while the PHY no longer negotiates

    [10 lines not shown]
DeltaFile
+6-0drivers/net/ethernet/realtek/r8169_main.c
+6-01 files

Linux/linux 9e79290 — drivers/net/ethernet/marvell/octeontx2/nic otx2_common.c

octeontx2-pf: Fix RSS indirection table size

The conversion to the dedicated RSS context operations replaced the
pointer to struct otx2_rss_ctx with an inline u32 ind_tbl[] array.
However, otx2_rss_init() still uses sizeof(*rss->ind_tbl) to set rss_size.
This now yields the size of one u32 (4), rather than the 256 entries in
the indirection table.

The RSS initialization and hardware programming loops use rss_size,
so only four entries are initialized and programmed despite the NIX LF
being allocated a 256-entry table. On an OCTEON CN102 with eight RX
queues, the table contained 0, 1, 2, 3 followed by zeros. Traffic was
concentrated on queue 0 and ethtool -X equal 8 did not correct the table.

Use ARRAY_SIZE() to count the indirection table entries. On the same
hardware, this restores the full table repeating queue numbers 0 through
7, and bidirectional multi-flow traffic increments multiple RX queues.

Runtime testing on an Asterfusion ET2500 (OCTEON CN102 A0).

    [8 lines not shown]
DeltaFile
+1-1drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c
+1-11 files