Linux/linux e767a4e — kernel kprobes.c, kernel/trace fprobe.c

Merge tag 'probes-fixes-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace

Pull probes fixes from Masami Hiramatsu:

 - fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()

   Exit handlers early if !rcu_is_watching() to prevent potential
   use-after-free during unregistration in idle/quiescent states. Switch
   to guard(rcu_sched_notrace) to avoid fast-path lockdep overhead and
   recursion while ensuring safe grace period synchronization.

 - kprobes: Skip disarmed probes when checking optkprobe overlap

   Continue past disarmed or unprepared probes in get_optimized_kprobe()
   to find active optimized probes. This avoids overwriting active jump
   displacements which can lead to panic.

* tag 'probes-fixes-v7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
  kprobes: Skip disarmed probes when checking optkprobe overlap
  fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()
DeltaFile
+16-10kernel/trace/fprobe.c
+5-3kernel/kprobes.c
+21-132 files

Linux/linux ff47652 — Documentation/filesystems netfs_library.rst, fs/netfs read_collect.c misc.c

Merge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux

Pull smb client fixes from Paulo Alcantara:
 "Fix a series of data corruption and I/O error bugs found by running
  generic/363 (fsx) in a loop against Windows Server 2022 and Samba.

   - Stop data dirtied past EOF through an mmap from reappearing as file
     content once the file is extended by a write, truncate, zero range,
     copy range or clone range

   - Flush dirty data and drain in-flight I/O before operations that
     assume the pagecache and the server agree on the file: querying
     allocated ranges, the O_TRUNC open, interior zero range, and
     server-side copy/clone

   - Stop a genuine size-extending zero range or preallocate from being
     refused with -EOPNOTSUPP when the inode is not read caching, by
     querying the server's authoritative EOF instead of trusting a stale
     cached i_size

    [33 lines not shown]
DeltaFile
+97-33fs/smb/client/smb2ops.c
+99-0fs/netfs/misc.c
+36-5fs/smb/client/cifsfs.c
+26-0Documentation/filesystems/netfs_library.rst
+16-8fs/smb/client/inode.c
+24-0fs/netfs/read_collect.c
+298-469 files not shown
+347-5615 files

Linux/linux 8f150cc — arch/loongarch/net bpf_jit.c, kernel/bpf memalloc.c trampoline.c

Merge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf

Pull bpf fixes from Alexei Starovoitov:

 - Fix overflow of backward jump offset in constant blinding
   (Alexei Starovoitov)

 - Fix packet range of packet pointers sharing an id when var_off
   tightens umax of one pointer and not the other (Alexei Starovoitov)

 - Fix objects stuck in free_by_rcu_ttrace list of bpf memalloc
   (Alexei Starovoitov)

 - Fix use-after-free of progs detached from busy trampolines: wait for
   an RCU tasks grace period before freeing trampoline progs, and patch
   detached progs out of trampoline images that are still in use
   (Florent Revest)

 - Hold map BTF for the memory allocator destructor record to fix UAF in

    [17 lines not shown]
DeltaFile
+188-0tools/testing/selftests/bpf/prog_tests/tramp_prog_detach.c
+178-0tools/testing/selftests/bpf/progs/verifier_direct_packet_access.c
+68-17kernel/bpf/trampoline.c
+40-20arch/loongarch/net/bpf_jit.c
+60-0tools/testing/selftests/bpf/prog_tests/bpf_ma_ttrace.c
+47-10kernel/bpf/memalloc.c
+581-4717 files not shown
+975-17223 files

Linux/linux d2dbe50 — drivers/pci pci.c

Merge tag 'pci-v7.3-fixes-3' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci

Pull PCI fix from Bjorn Helgaas:

 - Allow driver to use AtomicOps if already enabled by hypervisor; fixes
   regression when Root Port is not visible in a guest (Nikola Prica)

* tag 'pci-v7.3-fixes-3' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
  PCI: Accept AtomicOps already enabled by the hypervisor
DeltaFile
+14-1drivers/pci/pci.c
+14-11 files

Linux/linux 3b7cab6 — block blk-mq.c, drivers/nvme/host nvme.h multipath.c

Merge tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull block fixes from Jens Axboe:

 - NVMe fixes via Keith:
     - Fix an out-of-bounds write in nvmet_auth_challenge(), where
       sizeof() on a void pointer undercounted the challenge header and
       let a short AUTH_RECEIVE buffer pass the check
     - nvme-multipath fixes for an ANA log bounds check underflow, the
       command effects log lifetime for multipath heads, and only
       setting BLK_FEAT_ZONED after the zone info is known.
     - nvmet fixes for ns->enabled teardown ordering, rejecting I/O
       after the percpu ns reference is killed, device path preservation
       on allocation failure, and too-short SGL segments in pci-epf
     - nvme-tcp: revert the per-socket dynamic lockdep keys, and delay
       the socket reclassification
     - A DMA pool alignment quirk for the Micron 4100AT
     - Controller state/reset race fixes, and -Wformat-security
       workarounds

    [34 lines not shown]
DeltaFile
+28-35drivers/nvme/host/core.c
+37-26block/blk-mq.c
+13-26drivers/nvme/host/tcp.c
+21-14drivers/nvme/target/core.c
+8-11drivers/nvme/host/multipath.c
+5-4drivers/nvme/host/nvme.h
+112-11613 files not shown
+140-13119 files

Linux/linux 3f1fe48 — io_uring bpf_filter.c tw.c

Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull io_uring fixes from Jens Axboe:

 - Fix a task_work add use-after-free with SQPOLL.

   The sqpoll thread could pop and complete the last request while
   io_req_normal_work_add() was still looking at them after the mpscq
   push.

   Use the same approach as DEFER_TASKRUN to protect from that, holding
   an RCU read lock across the add, and have exit wait for an RCU grace
   period for SQPOLL rings as well.

 - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
   big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
   rings

 - Mark the source filter table as COW when cloning bpf filters, so

    [18 lines not shown]
DeltaFile
+14-5io_uring/cmd_net.c
+9-7io_uring/io_uring.c
+7-2io_uring/zcrx.c
+5-0io_uring/loop.c
+3-0io_uring/tw.c
+1-0io_uring/bpf_filter.c
+39-146 files

Linux/linux 5d144c2 — drivers/spi spi-cs42l43.c, sound/hda/codecs/realtek alc269.c

Merge tag 'sound-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound

Pull sound fixes from Takashi Iwai:
 "A fair amount of small fixes, which became much larger as a pile of
  pending homework during my vacation in the last weeks.

  The majority of changes are device-specific quirks and ASoC updates,
  along with a few ALSA core fixes and USB-audio hardening as well as a
  few regression fixes.

  ALSA Core:
   - Serialize ALSA sequencer compat port-info ioctls

  HD-audio:
   - Fix ALC235 codec headset handling
   - Fix regression on Tegra194 controller support
   - Quirks / fixes for Lenovo, ASUS, Acer, Dell, Higole, HP, and IPASON
     laptops


    [42 lines not shown]
DeltaFile
+97-0drivers/spi/spi-cs42l43.c
+58-4sound/hda/codecs/realtek/alc269.c
+8-19sound/soc/codecs/rt1017-sdca-sdw.c
+20-0sound/soc/amd/acp/amd-acp70-acpi-match.c
+13-6sound/soc/sdca/sdca_class_function.c
+17-0sound/soc/intel/boards/bytcr_rt5651.c
+213-2925 files not shown
+331-4631 files

Linux/linux ac7445c — arch/x86/entry/vdso/vdso64 Makefile, drivers/virt vmgenid.c

Merge tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random

Pull random number generator fixes from Jason Donenfeld:

 - VMGENID memory needs to be mapped with the decrypted tag, so that
   SEV-SNP machines can boot

 - A fix for an initialization race in VMGENID, followed by a cleanup

 - Trivial kernel doc cleanups in siphash and random.c

 - A fix for a new compilation failure with recent clang on PPC and
   RISC-V, due to generating an out-of-line memset in the vDSO

* tag 'random-7.3-rc6-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/crng/random:
  random: vDSO: avoid call to memset() when zeroing reserved parameter
  random: fix vgetrandom_opaque_params kernel-doc
  random: vDSO: fix repeated word 'to' in comment
  siphash: clean up kernel-doc comments

    [3 lines not shown]
DeltaFile
+7-4drivers/virt/vmgenid.c
+6-2include/linux/siphash.h
+5-0init/Kconfig
+1-1include/vdso/getrandom.h
+1-1include/uapi/linux/random.h
+1-1arch/x86/entry/vdso/vdso64/Makefile
+21-95 files not shown
+26-1011 files

Linux/linux 4e9a2de — . MAINTAINERS, mm slub.c

Merge tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab

Pull slab fixes from Vlastimil Babka:

 - Stable fix for a potential deadlock in kfree_rcu() when called
   from set_cpus_allowed_force() (Harry Yoo)

 - MAINTAINERS update of the slab.git URL

* tag 'slab-for-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mm/slab:
  mm/slab: do not wake up kswapd in __kfree_rcu_sheaf()
  MAINTAINERS: update slab.git URL
DeltaFile
+4-3mm/slub.c
+1-1MAINTAINERS
+5-42 files

Linux/linux 5e0f839 — drivers/hid hid-ids.h hid-logitech-dj.c, drivers/hid/intel-thc-hid/intel-quicki2c pci-quicki2c.c

Merge tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid

Pull HID fixes from Benjamin Tissoires:

 - Revert of the Bolt integration into hid-logitech-dj (Benjamin
   Tissoires)

 - A couple of buffer overflow in Intel-thc-hid (Even Xu)

 - A couple of Sashiko findings fixes in hid-multitouch and HID-BPF
   (Aldo Ariel Panzardo and Benjamin Tissoires)

* tag 'hid-for-linus-2026100201' of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid:
  selftest/hid: add test for negative return codes for hid_bpf_hw_request
  HID: bpf: cast size to ssize_t when checking hid_bpf_hw_request
  HID: Intel-thc-hid: Intel-quickspi: Fix buffer overflow
  HID: Intel-thc-hid: Intel-quicki2c: Fix buffer overflow
  HID: universal-pidff: Add support for Turtle Beach VelocityOne Race
  HID: multitouch: stop the release timer from being rearmed on remove
  Revert "HID: logitech: add Bolt receiver support for Logitech HID++ devices"
DeltaFile
+4-47drivers/hid/hid-logitech-hidpp.c
+4-44drivers/hid/hid-logitech-dj.c
+31-0tools/testing/selftests/hid/hid_bpf.c
+4-2drivers/hid/intel-thc-hid/intel-quicki2c/pci-quicki2c.c
+2-1drivers/hid/intel-thc-hid/intel-quickspi/pci-quickspi.c
+3-0drivers/hid/hid-ids.h
+48-943 files not shown
+51-969 files

Linux/linux 40cce45 — drivers/pci pci.c

PCI: Accept AtomicOps already enabled by the hypervisor

pci_enable_atomic_ops_to_root() currently fails when no Root Port is
visible. That is common in passthrough guests (ESXi, Hyper-V): the Endpoint
is assigned to the VM, but the Root Port above it is not visible in the
guest topology.

In those setups the hypervisor may already have enabled AtomicOp Requester
Enable on the device. If PCI_EXP_DEVCTL2_ATOMIC_REQ is set, treat AtomicOps
as already enabled and return success instead of failing the Root Port
walk.

After 1ae8c4ce1570 ("PCI: Enable AtomicOps only if Root Port supports
them"), pci_enable_atomic_ops_to_root() always returns failure if the Root
Port is not visible, so drivers don't use atomics when they could.  On
systems where the Root Port is not visible but *does* support AtomicOps,
this is a regression: prior to 1ae8c4ce1570, it enabled AtomicOps in the
endpoint and returned success.


    [8 lines not shown]
DeltaFile
+14-1drivers/pci/pci.c
+14-11 files

Linux/linux 17a5800 — drivers/char/tpm tpm2-sessions.c tpm-interface.c

Merge tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd

Pull tpm fixes from Jarkko Sakkinen.

 - tpm error handling and buffer size fixes

* tag 'for-next-tpm-v7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  tpm: Disable TPM on null key name mismatch
  tpm: fix off-by-four bounds check in tpm2_get_random()
  tpm: Fix auth session leak in tpm2_get_random() error path
  tpm: Fix heap buffer overflow in tpm_transmit_cmd()
DeltaFile
+4-2drivers/char/tpm/tpm2-cmd.c
+1-1drivers/char/tpm/tpm-interface.c
+1-0drivers/char/tpm/tpm2-sessions.c
+6-33 files

Linux/linux b4e7fc3 — arch/mips/configs econet_en751221_defconfig, drivers/phy/renesas phy-rcar-gen3-usb2.c

Merge tag 'asoc-fix-v7.3-rc5' of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus

ASoC: Fixes for v7.3

A bigger collection of fixes than usual due to your vacation but nothing
hugely remarkable here, just fairly standard quirks and driver specific
bugfixes.
DeltaFile
+0-1,029lib/alloc_tag.c
+354-101fs/ntfs/mft.c
+311-0tools/testing/selftests/x86/int_signal.c
+265-45drivers/phy/renesas/phy-rcar-gen3-usb2.c
+264-0arch/mips/configs/econet_en751221_defconfig
+203-56fs/ntfs/attrib.c
+1,397-1,231486 files not shown
+7,382-3,305492 files

Linux/linux de020dc — kernel/bpf hashtab.c

bpf: Fix missing migration protection in __rhtab_map_lookup_and_delete_batch()

bpf_mem_cache_free_rcu() uses this_cpu_ptr() which requires migration
to be disabled. All callers of rhtab_delete_elem() disable migration
except __rhtab_map_lookup_and_delete_batch(), which calls it under
rcu_read_lock() only.

On CONFIG_PREEMPT_RCU, rcu_read_lock() does not disable preemption or
migration, so the task can migrate between CPUs during the delete loop,
causing this_cpu_ptr() to trigger:

  BUG: using smp_processor_id() in preemptible [00000000] code

Fix by wrapping the delete loop in migrate_disable()/migrate_enable()
in __rhtab_map_lookup_and_delete_batch(), matching the migration
protection that the other callers already provide.

Fixes: 818e00848227 ("bpf: Implement iteration ops for resizable hashtab")
Reported-by: syzbot+fd7e415d891073b83e1f at syzkaller.appspotmail.com

    [5 lines not shown]
DeltaFile
+2-0kernel/bpf/hashtab.c
+2-01 files

Linux/linux eb13a1f — arch/arm64/kernel/vdso Makefile, arch/loongarch/vdso Makefile

random: vDSO: avoid call to memset() when zeroing reserved parameter

After a recent change in LLVM [1], builds with the random vDSO
implementation, such as PowerPC and RISC-V, fail when checking the vDSO:

  arch/powerpc/kernel/vdso/vdso32.so.dbg: dynamic relocations are not supported
  arch/riscv/kernel/vdso/vdso.so.dbg: dynamic relocations are not supported

memset() is now generated when zeroing params->reserved for some builds
because LLVM has an optimization (now run in more instances) that can
recognize at compile time when it is assigning a static value to a
contiguous area of memory and turn that into a call to memset(). Both
clang and GCC assume memset() is always available [2].

Clang has an internal fiddly hook, -max-store-memset, which we can set
to a high number, to disable generating out of line memset calls [3].
Similarly, GCC has -finline-stringops=memset to do the same [4], should
this issue ever hit future version of GCC. While these options wouldn't
make sense for normal kernel code, it is fine for the extremely limited

    [10 lines not shown]
DeltaFile
+5-0init/Kconfig
+1-1arch/x86/entry/vdso/vdso64/Makefile
+1-1arch/arm64/kernel/vdso/Makefile
+1-0arch/riscv/kernel/vdso/Makefile
+1-0arch/powerpc/kernel/vdso/Makefile
+1-0arch/loongarch/vdso/Makefile
+10-21 files not shown
+11-27 files

Linux/linux 7a39c73 — kernel kprobes.c

kprobes: Skip disarmed probes when checking optkprobe overlap

On x86, an optkprobe at A replaces five bytes with a jump. If a disabled
probe B is at A+2, get_optimized_kprobe() stops at B when arming a new
probe C at A+4. It leaves A optimized:

              A    A+1  A+2  A+3  A+4
  A's jump  | e9 | d0 | d1 | d2 | d3 |
  after C   | e9 | d0 | d1 | d2 | cc |

The INT3 for C overwrites the last byte of A's jump displacement, so
execution can jump to the wrong address. B can have prepared optinsns
while disarmed, but has no jump to unoptimize.

Continue past disarmed and unprepared probes to find the active optimized
probe before arming a probe in its jump.

Link: https://lore.kernel.org/all/20260930053618.104498-1-leon.hwang@linux.dev/


    [4 lines not shown]
DeltaFile
+5-3kernel/kprobes.c
+5-31 files

Linux/linux ce1e022 — drivers/of irq.c base.c

Merge tag 'devicetree-fixes-for-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux

Pull devicetree fixes from Rob Herring:

 - Fix another case of refcount leaks in of_irq_init()

 - Avoid refcount leak in coreboot node check

 - Fix overlay handling of a root node target path

 - Various error path fixes in the overlay code

* tag 'devicetree-fixes-for-7.3-2' of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux:
  of/irq: Fix remaining refcount leaks in of_irq_init()
  of: Put coreboot node after compatibility check
  of/overlay: don't create "//" paths for fragments targeting the root
  of/overlay: don't leak fragment references when changeset init fails
  of/overlay: only treat a positive changeset id as registered
  of/overlay: put property on deadprops only after changeset add succeeds
DeltaFile
+13-4drivers/of/overlay.c
+9-1drivers/of/base.c
+2-0drivers/of/irq.c
+24-53 files

Linux/linux 100638f — drivers/cpufreq cpufreq.c intel_pstate.c, include/linux cpufreq.h

Merge tag 'pm-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm

Pull power management fix from Rafael Wysocki:
 "Restore the previous behavior on systems where the cpufreq pressure
  was not visible in the scheduler and is not expected to be visible
  there.

  It became visible after a change made during the 7.2 development cycle
  that had gone too far"

* tag 'pm-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:
  cpufreq: intel_pstate: Fix max_freq fallback in cpufreq_update_pressure()
DeltaFile
+10-0drivers/cpufreq/intel_pstate.c
+2-2drivers/cpufreq/cpufreq.c
+3-0include/linux/cpufreq.h
+15-23 files

Linux/linux bd35955 — arch/x86/crypto aesni-intel_glue.c, crypto aes.c

Merge tag 'libcrypto-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux

Pull crypto library fixes from Eric Biggers:

 - Fix a performance regression in certain AES encryption modes on
   certain architectures, introduced this cycle

 - Fix a small performance regression in the x86_64 optimized AES-GCM
   code, introduced in 6.15

* tag 'libcrypto-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux:
  crypto: aes - Fix undesired override of some optimized AES modes
  crypto: x86/aes-gcm - fix always true check for last AAD segment
DeltaFile
+47-4crypto/aes.c
+1-1arch/x86/crypto/aesni-intel_glue.c
+48-52 files

Linux/linux a940b03 — arch/arm64/kvm mmu.c, arch/x86/kvm/svm svm.c sev.c

Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm

Pull kvm fixes from Paolo Bonzini:
 "The most intrusive change is reverting a commit from 7.3-rc1 that made
  struct kvm a bit too large, and fixing the same issue otherwise.

  There are again a lot of selftests lines; the sheer number of commits
  is not small but I don't expect much more for 7.3 due to people
  travelling to Plumbers next week.

  ARM:

   - Take a reference on the last IRQ loaded into an LR to prevent it
     from being freed while running the guest (Marc Zyngier)

   - Ensure that the ITS MOVALL command only affects LPIs that were
     previously affined to the source redistributor (Marc Zyngier)

   - Fix + test for honoring the host's trap configuration when running

    [55 lines not shown]
DeltaFile
+222-0tools/testing/selftests/kvm/x86/nested_x2apic_test.c
+184-0tools/testing/selftests/kvm/arm64/hidden_features.c
+29-28arch/x86/kvm/svm/sev.c
+6-41arch/arm64/kvm/mmu.c
+20-23arch/x86/kvm/svm/svm.c
+11-24virt/kvm/kvm_main.c
+472-11618 files not shown
+554-16524 files

Linux/linux f9bfc32 — arch/arm64/kvm mmu.c, arch/arm64/kvm/hyp/include/nvhe pkvm.h

Merge tag 'kvmarm-fixes-7.3-2' of https://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm into HEAD

KVM/arm64 fixes for 7.3, round #2

 - Take a reference on the last IRQ loaded into an LR to prevent it
   from being freed while running the guest (Marc Zyngier)

 - Ensure that the ITS MOVALL command only affects LPIs that were
   previously affined to the source redistributor (Marc Zyngier)

 - Fix + test for honoring the host's trap configuration when running
   non-protected VMs while KVM is in protected mode (Fuad Tabba)

 - Use the host stage-1 mapping granularity for VM_PFNMAP mappings at
   stage-2 (Mostafa Saleh)
DeltaFile
+184-0tools/testing/selftests/kvm/arm64/hidden_features.c
+6-41arch/arm64/kvm/mmu.c
+16-9arch/arm64/kvm/hyp/nvhe/pkvm.c
+16-5arch/arm64/kvm/vgic/vgic.c
+8-4arch/arm64/kvm/vgic/vgic-its.c
+9-0arch/arm64/kvm/hyp/include/nvhe/pkvm.h
+239-595 files not shown
+252-6911 files

Linux/linux 7b12c53 — kernel/bpf memalloc.c, tools/testing/selftests/bpf/prog_tests bpf_ma_ttrace.c

Merge branch 'bpf-fix-objects-stuck-in-free_by_rcu_ttrace'

Alexei Starovoitov says:

====================
bpf: Fix objects stuck in free_by_rcu_ttrace

From: Alexei Starovoitov <ast at kernel.org>

The objects that bpf_mem_alloc frees while RCU tasks trace GP is in flight
stay in free_by_rcu_ttrace list until the same bpf_mem_cache frees or
allocates in bulk again.

Patch 1 - refactoring. No functional change.
Patch 2 - the fix.
Patch 3 - selftest.

Signed-off-by: Alexei Starovoitov <ast at kernel.org>
====================

    [3 lines not shown]
DeltaFile
+60-0tools/testing/selftests/bpf/prog_tests/bpf_ma_ttrace.c
+47-10kernel/bpf/memalloc.c
+50-0tools/testing/selftests/bpf/progs/bpf_ma_ttrace.c
+157-103 files

Linux/linux aeb709c — tools/testing/selftests/bpf/prog_tests bpf_ma_ttrace.c, tools/testing/selftests/bpf/progs bpf_ma_ttrace.c

selftests/bpf: Add a test for objects stuck in free_by_rcu_ttrace

Delete all elements of BPF_F_NO_PREALLOC hash map in one batch. The first
free_bulk() starts RCU tasks trace GP and the rest of the elements are
freed while it's in flight. Wait for call_rcu_ttrace_in_progress to clear
in bpf_mem_cache of every cpu and check that free_by_rcu_ttrace and
waiting_for_gp_ttrace lists are empty.

Signed-off-by: Alexei Starovoitov <ast at kernel.org>
Link: https://lore.kernel.org/bpf/20260930095920.601738-4-alexei.starovoitov@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor at gmail.com>
DeltaFile
+60-0tools/testing/selftests/bpf/prog_tests/bpf_ma_ttrace.c
+50-0tools/testing/selftests/bpf/progs/bpf_ma_ttrace.c
+110-02 files

Linux/linux fbd97dd — kernel/bpf memalloc.c

bpf: Fix objects stuck in free_by_rcu_ttrace

do_call_rcu_ttrace() returns early when call_rcu_ttrace_in_progress is set
and leaves the objects in free_by_rcu_ttrace. __free_rcu() frees
waiting_for_gp_ttrace only and clears the flag. Hence the objects that
free_bulk() or __free_by_rcu() added while RCU tasks trace GP was in flight
stay in free_by_rcu_ttrace until free_bulk() or alloc_bulk() is called for
the same bpf_mem_cache again, which may never happen. The number of such
objects is not bounded.

Turn call_rcu_ttrace_in_progress into three states:
0 - idle
1 - __free_rcu() is queued
2 - __free_rcu() is queued and free_by_rcu_ttrace got more objects since

do_call_rcu_ttrace() sets 2. __free_rcu() does cmpxchg(1 -> 0) and starts
the next GP when it fails. It cannot clear the flag first and check
free_by_rcu_ttrace later, since bpf_mem_alloc_destroy() frees bpf_mem_cache
without waiting for RCU callbacks when the flag is zero.

    [12 lines not shown]
DeltaFile
+32-2kernel/bpf/memalloc.c
+32-21 files

Linux/linux 47f4f69 — kernel/bpf memalloc.c

bpf: Factor out __do_call_rcu_ttrace()

Move the part of do_call_rcu_ttrace() that runs after
call_rcu_ttrace_in_progress is set into __do_call_rcu_ttrace().
The next patch will call it from __free_rcu().
No functional change.

Signed-off-by: Alexei Starovoitov <ast at kernel.org>
Link: https://lore.kernel.org/bpf/20260930095920.601738-2-alexei.starovoitov@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor at gmail.com>
DeltaFile
+17-10kernel/bpf/memalloc.c
+17-101 files

Linux/linux b88822d — kernel/bpf verifier.c, tools/testing/selftests/bpf/progs verifier_align.c

bpf: Fix packet range of pointers sharing an id

Since commit 022ac0750883 ("bpf: use reg->var_off instead of reg->off
for pointers"), find_good_pkt_pointers() sets the range of all packet
pointers sharing an id from the umax of the compared pointer, and
check_packet_access() requires umax + off + size <= range.  That assumes
the umax of two such pointers differ by exactly their constant distance.
reg_bounds_sync() breaks it when var_off tightens one umax and not the
other:

        r4 &= 0x38
        if r4 > 50 goto exit     ; umax 50, var_off (0x0; 0x38)
        r5 = pkt + r4            ; umax 50
        r6 = r5
        r6 += 8                  ; umax 56, not 58

Comparing r6 with pkt_end sets the range to 56, and the valid 8-byte
load at r5 is rejected (50 + 8 > 56).  Comparing r5 sets it to 50, and
the out-of-bounds 1-byte load at r6 - 7, i.e. r5 + 1, is accepted

    [20 lines not shown]
DeltaFile
+9-1kernel/bpf/verifier.c
+3-3tools/testing/selftests/bpf/progs/verifier_align.c
+12-42 files

Linux/linux 33a154a — tools/testing/selftests/bpf/progs verifier_meta_access.c verifier_direct_packet_access.c

selftests/bpf: Test packet range of pointers sharing an id

Add tests where two packet pointers share an id and tightening one
pointer's umax from its var_off would put it less than their constant
distance from the other's umax: with an index & 0x38 capped at 50, the
base pointer keeps umax 50, so the pointer 8 bytes further on must keep
umax 58, even though its known bits allow at most 56.

These refused a valid program or accepted an out-of-bounds access before
the fix:

- check the advanced copy, load through the base: valid, was refused;
- check the base, load the byte at base + 1 through a copy advanced by
  8: was accepted;
- check base + 4, load 4 bytes at base + 2 through base + 8: reads two
  bytes past the checked range, was accepted;
- the same as the second with data_meta pointers checked against data:
  was accepted.


    [13 lines not shown]
DeltaFile
+178-0tools/testing/selftests/bpf/progs/verifier_direct_packet_access.c
+30-0tools/testing/selftests/bpf/progs/verifier_meta_access.c
+208-02 files

Linux/linux 71cc2c6 — arch/arm64/kvm mmu.c

KVM: arm64: Use stage-1 leaf size for VM_PFNMAP

When commit 2aa53d68cee6 ("KVM: arm64: Try stage2 block mapping for
host device MMIO") added VM_PFNMAP support to get_vma_page_shift(),
stage-1 page tables did not support huge PFNMAP (as in VFIO-PCI
vfio_pci_mmap_huge_fault()) and transparent_hugepage_adjust() was
unsafe for MMIO as it dereferenced struct page.

Since commit 6011cf68c885 ("KVM: arm64: Walk userspace page tables to
compute the THP mapping size"), transparent_hugepage_adjust() instead
walks the host stage-1 page tables via get_user_mapping_size() without
touching struct page. Meanwhile, commit 3e509c9b03f9 ("mm/arm64:
support large pfn mappings") enabled stage-1 huge PFNMAP.

So. we can drop the VMA-based VM_PFNMAP size calculation in
get_vma_page_shift() and let transparent_hugepage_adjust() derive
the stage-2 mapping size directly from the populated stage-1 leaf
for non-cacheable mappings as well.


    [6 lines not shown]
DeltaFile
+6-41arch/arm64/kvm/mmu.c
+6-411 files

Linux/linux cad16d8 — drivers/spi spi-cs42l43.c

spi: cs42l43: Workaround for wrong speaker ID on Dell XPS 13 DX13260

On Dell XPS 13 DX13260 create an acpi_gpio_mapping with exactly two
GPIO entries to point at the two pins in the GpioIo(). Use this to
read the speaker ID GPIOs.

This fixes problems on Dell XPS 13 DX13260:

- No speaker audio
- The wrong firmware was loaded so the speaker protection did not match
  the speaker characteristics.

The Dell XPS 13 DX13260 has two speaker ID GPIOs, to form a 2-bit ID. The
ACPI GpioIo() has both pins but the Linux-specific spk-id-gpios property
only has a mapping to the first pin. This meant that the speaker ID was
wrong in most cases, and that would lead to the codec driver loading the
wrong amp firmware, or not finding a firmware (as 0 is not a valid ID on
this laptop).


    [9 lines not shown]
DeltaFile
+97-0drivers/spi/spi-cs42l43.c
+97-01 files

Linux/linux f1d565d — include/sound core.h

ALSA: core: Define auto-cleanup for snd_card_free()

For the errors at the probe time, we'd need to call rather
snd_card_free() instead of the snd_card_unref() -- the former calls
explicitly snd_card_disconnect() that cleans up the registered
devices, etc, while the latter may leak in corner cases.

For convenience, define a new auto-clean with snd_card_free.

Link: https://patch.msgid.link/20261001151039.592033-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai at suse.de>
DeltaFile
+9-0include/sound/core.h
+9-01 files