Merge tag 'clk-fixes-for-linus-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux
Pull clk fixes from Brian Masney:
"Two small clk driver fixes:
- spacemit: k3: Fix an issue that will trigger a system hang due to
unavailable frequency
- ti: composite: Reverts a commit that breaks OMAP3"
* tag 'clk-fixes-for-linus-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux:
clk: spacemit: k3: add CPU PLL rate tables
clk: ti: composite: resolve parent clocks by name again
Merge tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc
Pull char/misc/IIO fixes from Greg KH:
"Here is a set of char/misc/iio and other small driver subsystem fixes
for 7.3-rc6 that resolve a number of reported issues. Included in here
are:
- lots of small iio driver fixes for reported problems
- interconnect driver revert to resolve a regression
- nitro_enclaves driver fix for a use-after-free
- binder driver fixes for reported problems (in both the rust and C
versions)
All of these have been in linux-next with no reported issues"
* tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (63 commits)
[21 lines not shown]
Merge tag 'tty-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty
Pull tty/serial fixes from Greg KH:
"Here are some small tty/serial driver fixes for 7.3-rc6. Nothing major
here, just lots of small fixes for reported issues, some of them very
long-standing:
- tty hangup fixes that have been there since the BKL days and kept
tripping people up over time.
- vt selection bugfix
- other vt bugfixes (memory leaks and screen update fixes)
- n_gsm bugfix
- qcom-geni serial driver bugfix
- 8250 serial driver bugfixes
[29 lines not shown]
Merge tag 'usb-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb
Pull USB/Thunderbolt fixes from Greg KH:
"Here is a big set of USB and Thunderbolt driver fixes for 7.3-rc6.
They were delayed on my side due to conference travel, not the fault
of the submitters at all. Included in here are:
- lots of small thunderbolt fixes for reported issues due to more
testing and devices and a few reverts as well based on that work
- more usb-serial device ids added
- usb-serial and cdc-acm driver hangup and other fixes
- dwc3 driver fixes for reported problems
- lots of usb gadget driver fixes as people again fuzz these drivers
and send in fixes, which is nice to finally see
[32 lines not shown]
Merge tag 'input-for-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input
Pull input fixes from Dmitry Torokhov:
- A fix for the Samsung S6SY761 touchscreen driver to power on the
controller before unmasking interrupts during resume and to re-enable
touch sensing when the device is open
- Updates to the Synaptics touchpad driver to enable SMBus/RMI4 mode on
Lenovo ThinkPad T490 and restrict the ThinkPad T440p InterTouch
disable quirk to LEN0036 so that ThinkPad L440 retains SMBus support
- A quirk for the AT keyboard driver (atkbd) to skip keyboard
deactivation on Lenovo IdeaPad Slim 3 15IWC11 so the internal
keyboard functions properly
- A DMI quirk for the i8042 controller to disable active multiplexing
on Fujitsu LIFEBOOK U7410, preventing the internal keyboard and
touchpad from dying shortly after boot.
[7 lines not shown]
Merge tag 'drm-fixes-2026-10-03' of https://gitlab.freedesktop.org/drm/kernel
Pull drm fixes from Dave Airlie:
"Live from Brisbane airport, it's Saturday Night drm fixes.
The misc fixes tree didn't get a PR this week, so I'll probably have
that to you when I see it, there were a few patches in there.
Otherwise amdgpu is the main act, mediatek has a guest spot, and
xe/i915 bring in a fix each.
xe:
- keep VF LMEM bar size low if no VFs enabled
i915:
- Disable VRR DC balance by default to fix timing issues
mediatek:
- Add missing IS_ERR check for ovl_adaptor platform device
[54 lines not shown]
Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux
Pull arm64 fixes from Will Deacon:
"Half of this is broken hardware (AMU counters and TLB invalidation)
and the other half is broken software (frequency scaling and signals).
So it seems as though we're all as bad as each other.
The AMU workaround is a little noisy, as it refactors an existing
workaround so that it can more easily be applied to additional CPUs.
Summary:
- Fix handling of CPU erratum #2645198 when batching pte updates
- Fix truncation of CPU frequency calculation by using 64-bit
arithmetic in arch_freq_get_on_cpu()
- Work around AMU erratum #3821522 on Cortex-A725
[9 lines not shown]
Input: atkbd - skip deactivate for Lenovo IdeaPad Slim 3 15IWC11
The internal keyboard on the Lenovo IdeaPad Slim 3 15IWC11 (83RR)
does not work correctly with the default i8042 settings. Using
i8042.nopnp=1 and i8042.dumbkbd=1 restores keyboard input, but prevents
the Caps Lock LED from working. Using i8042.nopnp=1 alone does not fix
the keyboard.
The laptop works correctly when atkbd_deactivate_fixup is used instead.
Add a DMI quirk for the 83RR to enable it.
This was tested without any i8042 command-line parameters. Keyboard
input and the Caps Lock LED work correctly, including after suspend
and resume and after a cold boot.
Link: https://lore.kernel.org/all/4f43465f-98ba-4722-8e29-03df20315369@kernel.org/
Signed-off-by: Martino Papero <martino.papero at lcb.to.it>
Reviewed-by: Hans de Goede <johannes.goede at oss.qualcomm.com>
Link: https://patch.msgid.link/c0b597b8-e7ad-4fba-a2bb-5d252e3dfbd3@lcb.to.it
[2 lines not shown]
Merge tag 'probes-fixes-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace
Pull probes fixes from Masami Hiramatsu:
- fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()
Exit handlers early if !rcu_is_watching() to prevent potential
use-after-free during unregistration in idle/quiescent states. Switch
to guard(rcu_sched_notrace) to avoid fast-path lockdep overhead and
recursion while ensuring safe grace period synchronization.
- kprobes: Skip disarmed probes when checking optkprobe overlap
Continue past disarmed or unprepared probes in get_optimized_kprobe()
to find active optimized probes. This avoids overwriting active jump
displacements which can lead to panic.
* tag 'probes-fixes-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
kprobes: Skip disarmed probes when checking optkprobe overlap
fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()
Merge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux
Pull smb client fixes from Paulo Alcantara:
"Fix a series of data corruption and I/O error bugs found by running
generic/363 (fsx) in a loop against Windows Server 2022 and Samba.
- Stop data dirtied past EOF through an mmap from reappearing as file
content once the file is extended by a write, truncate, zero range,
copy range or clone range
- Flush dirty data and drain in-flight I/O before operations that
assume the pagecache and the server agree on the file: querying
allocated ranges, the O_TRUNC open, interior zero range, and
server-side copy/clone
- Stop a genuine size-extending zero range or preallocate from being
refused with -EOPNOTSUPP when the inode is not read caching, by
querying the server's authoritative EOF instead of trusting a stale
cached i_size
[33 lines not shown]
Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf
Pull bpf fixes from Alexei Starovoitov:
- Fix overflow of backward jump offset in constant blinding
(Alexei Starovoitov)
- Fix packet range of packet pointers sharing an id when var_off
tightens umax of one pointer and not the other (Alexei Starovoitov)
- Fix objects stuck in free_by_rcu_ttrace list of bpf memalloc
(Alexei Starovoitov)
- Fix use-after-free of progs detached from busy trampolines: wait for
an RCU tasks grace period before freeing trampoline progs, and patch
detached progs out of trampoline images that are still in use
(Florent Revest)
- Hold map BTF for the memory allocator destructor record to fix UAF in
[17 lines not shown]
Merge tag 'pci-v7.3-fixes-3' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci
Pull PCI fix from Bjorn Helgaas:
- Allow driver to use AtomicOps if already enabled by hypervisor; fixes
regression when Root Port is not visible in a guest (Nikola Prica)
* tag 'pci-v7.3-fixes-3' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
PCI: Accept AtomicOps already enabled by the hypervisor
Merge tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux
Pull block fixes from Jens Axboe:
- NVMe fixes via Keith:
- Fix an out-of-bounds write in nvmet_auth_challenge(), where
sizeof() on a void pointer undercounted the challenge header and
let a short AUTH_RECEIVE buffer pass the check
- nvme-multipath fixes for an ANA log bounds check underflow, the
command effects log lifetime for multipath heads, and only
setting BLK_FEAT_ZONED after the zone info is known.
- nvmet fixes for ns->enabled teardown ordering, rejecting I/O
after the percpu ns reference is killed, device path preservation
on allocation failure, and too-short SGL segments in pci-epf
- nvme-tcp: revert the per-socket dynamic lockdep keys, and delay
the socket reclassification
- A DMA pool alignment quirk for the Micron 4100AT
- Controller state/reset race fixes, and -Wformat-security
workarounds
[34 lines not shown]
Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux
Pull io_uring fixes from Jens Axboe:
- Fix a task_work add use-after-free with SQPOLL.
The sqpoll thread could pop and complete the last request while
io_req_normal_work_add() was still looking at them after the mpscq
push.
Use the same approach as DEFER_TASKRUN to protect from that, holding
an RCU read lock across the add, and have exit wait for an RCU grace
period for SQPOLL rings as well.
- CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
rings
- Mark the source filter table as COW when cloning bpf filters, so
[18 lines not shown]
Merge tag 'sound-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound
Pull sound fixes from Takashi Iwai:
"A fair amount of small fixes, which became much larger as a pile of
pending homework during my vacation in the last weeks.
The majority of changes are device-specific quirks and ASoC updates,
along with a few ALSA core fixes and USB-audio hardening as well as a
few regression fixes.
ALSA Core:
- Serialize ALSA sequencer compat port-info ioctls
HD-audio:
- Fix ALC235 codec headset handling
- Fix regression on Tegra194 controller support
- Quirks / fixes for Lenovo, ASUS, Acer, Dell, Higole, HP, and IPASON
laptops
[42 lines not shown]
Merge tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random
Pull random number generator fixes from Jason Donenfeld:
- VMGENID memory needs to be mapped with the decrypted tag, so that
SEV-SNP machines can boot
- A fix for an initialization race in VMGENID, followed by a cleanup
- Trivial kernel doc cleanups in siphash and random.c
- A fix for a new compilation failure with recent clang on PPC and
RISC-V, due to generating an out-of-line memset in the vDSO
* tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random:
random: vDSO: avoid call to memset() when zeroing reserved parameter
random: fix vgetrandom_opaque_params kernel-doc
random: vDSO: fix repeated word 'to' in comment
siphash: clean up kernel-doc comments
[3 lines not shown]
Merge tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab
Pull slab fixes from Vlastimil Babka:
- Stable fix for a potential deadlock in kfree_rcu() when called
from set_cpus_allowed_force() (Harry Yoo)
- MAINTAINERS update of the slab.git URL
* tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab:
mm/slab: do not wake up kswapd in __kfree_rcu_sheaf()
MAINTAINERS: update slab.git URL
Merge tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid
Pull HID fixes from Benjamin Tissoires:
- Revert of the Bolt integration into hid-logitech-dj (Benjamin
Tissoires)
- A couple of buffer overflow in Intel-thc-hid (Even Xu)
- A couple of Sashiko findings fixes in hid-multitouch and HID-BPF
(Aldo Ariel Panzardo and Benjamin Tissoires)
* tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid:
selftest/hid: add test for negative return codes for hid_bpf_hw_request
HID: bpf: cast size to ssize_t when checking hid_bpf_hw_request
HID: Intel-thc-hid: Intel-quickspi: Fix buffer overflow
HID: Intel-thc-hid: Intel-quicki2c: Fix buffer overflow
HID: universal-pidff: Add support for Turtle Beach VelocityOne Race
HID: multitouch: stop the release timer from being rearmed on remove
Revert "HID: logitech: add Bolt receiver support for Logitech HID++ devices"
PCI: Accept AtomicOps already enabled by the hypervisor
pci_enable_atomic_ops_to_root() currently fails when no Root Port is
visible. That is common in passthrough guests (ESXi, Hyper-V): the Endpoint
is assigned to the VM, but the Root Port above it is not visible in the
guest topology.
In those setups the hypervisor may already have enabled AtomicOp Requester
Enable on the device. If PCI_EXP_DEVCTL2_ATOMIC_REQ is set, treat AtomicOps
as already enabled and return success instead of failing the Root Port
walk.
After 1ae8c4ce1570 ("PCI: Enable AtomicOps only if Root Port supports
them"), pci_enable_atomic_ops_to_root() always returns failure if the Root
Port is not visible, so drivers don't use atomics when they could. On
systems where the Root Port is not visible but *does* support AtomicOps,
this is a regression: prior to 1ae8c4ce1570, it enabled AtomicOps in the
endpoint and returned success.
[8 lines not shown]
Merge tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd
Pull tpm fixes from Jarkko Sakkinen.
- tpm error handling and buffer size fixes
* tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
tpm: Disable TPM on null key name mismatch
tpm: fix off-by-four bounds check in tpm2_get_random()
tpm: Fix auth session leak in tpm2_get_random() error path
tpm: Fix heap buffer overflow in tpm_transmit_cmd()
Merge tag 'asoc-fix-v7.3-rc5' of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus
ASoC: Fixes for v7.3
A bigger collection of fixes than usual due to your vacation but nothing
hugely remarkable here, just fairly standard quirks and driver specific
bugfixes.
bpf: Fix missing migration protection in __rhtab_map_lookup_and_delete_batch()
bpf_mem_cache_free_rcu() uses this_cpu_ptr() which requires migration
to be disabled. All callers of rhtab_delete_elem() disable migration
except __rhtab_map_lookup_and_delete_batch(), which calls it under
rcu_read_lock() only.
On CONFIG_PREEMPT_RCU, rcu_read_lock() does not disable preemption or
migration, so the task can migrate between CPUs during the delete loop,
causing this_cpu_ptr() to trigger:
BUG: using smp_processor_id() in preemptible [00000000] code
Fix by wrapping the delete loop in migrate_disable()/migrate_enable()
in __rhtab_map_lookup_and_delete_batch(), matching the migration
protection that the other callers already provide.
Fixes: 818e00848227 ("bpf: Implement iteration ops for resizable hashtab")
Reported-by: syzbot+fd7e415d891073b83e1f at syzkaller.appspotmail.com
[5 lines not shown]
random: vDSO: avoid call to memset() when zeroing reserved parameter
After a recent change in LLVM [1], builds with the random vDSO
implementation, such as PowerPC and RISC-V, fail when checking the vDSO:
arch/powerpc/kernel/vdso/vdso32.so.dbg: dynamic relocations are not supported
arch/riscv/kernel/vdso/vdso.so.dbg: dynamic relocations are not supported
memset() is now generated when zeroing params->reserved for some builds
because LLVM has an optimization (now run in more instances) that can
recognize at compile time when it is assigning a static value to a
contiguous area of memory and turn that into a call to memset(). Both
clang and GCC assume memset() is always available [2].
Clang has an internal fiddly hook, -max-store-memset, which we can set
to a high number, to disable generating out of line memset calls [3].
Similarly, GCC has -finline-stringops=memset to do the same [4], should
this issue ever hit future version of GCC. While these options wouldn't
make sense for normal kernel code, it is fine for the extremely limited
[10 lines not shown]
kprobes: Skip disarmed probes when checking optkprobe overlap
On x86, an optkprobe at A replaces five bytes with a jump. If a disabled
probe B is at A+2, get_optimized_kprobe() stops at B when arming a new
probe C at A+4. It leaves A optimized:
A A+1 A+2 A+3 A+4
A's jump | e9 | d0 | d1 | d2 | d3 |
after C | e9 | d0 | d1 | d2 | cc |
The INT3 for C overwrites the last byte of A's jump displacement, so
execution can jump to the wrong address. B can have prepared optinsns
while disarmed, but has no jump to unoptimize.
Continue past disarmed and unprepared probes to find the active optimized
probe before arming a probe in its jump.
Link: https://lore.kernel.org/all/20260930053618.104498-1-leon.hwang@linux.dev/
[4 lines not shown]
drm/mediatek: Fix ovl adaptor platform device leak
mtk_drm_probe() creates an OVL adaptor platform device with
platform_device_register_data() when the display pipeline requires the
OVL adaptor.
If a later initialization step fails, the probe error path releases
the DRM resources without unregistering the already registered OVL
adaptor device. The normal remove path likewise leaves the device
registered after the DRM driver is unbound.
Keep track of whether the OVL adaptor was successfully registered and
unregister it on probe failure. Also recover the platform device from
the stored DDP component device and unregister it during normal
removal.
The issue was identified by a static analysis tool I developed and
confirmed by manual review.
[5 lines not shown]