Linux/linux 7b63ef2 — fs/btrfs transaction.c scrub.c

Merge tag 'for-7.3-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux

Pull btrfs fixes from David Sterba:

 - fix command queuing and cleanup in encoded read/write ioctls

 - fix root and transaction association to avoid unnecessary lock
   contention and transaction start

 - properly handle replacing multiple xattrs in the same item

 - in scrub, fix root reference leak after reporting an unresolved file
   path

* tag 'for-7.3-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
  btrfs: fix lost error return value in btrfs_listxattr()
  btrfs: fix xattr replace when multiple xattrs are packed in the same item
  btrfs: don't stash io_uring encoded data across -EAGAIN
  btrfs: unlock inode and extent in caller when io_uring read extent fails

    [4 lines not shown]
DeltaFile
+16-15fs/btrfs/ioctl.c
+11-4fs/btrfs/xattr.c
+3-4fs/btrfs/inode.c
+3-1fs/btrfs/scrub.c
+1-0fs/btrfs/transaction.c
+34-245 files

Linux/linux 0f27326 — drivers/md dm-crypt.c dm-ioctl.c

Merge tag 'for-7.3/dm-fixes-2' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm

Pull device mapper fixes from Mikulas Patocka:
 "dm-integrity:
   - validate the superblock after re-reading it
   - fix buffer overflow if tag size > 64

  dm:
   - fix reading up to 7 bytes beyond the end of block in dm-ioctl
   - fix reading free memory if the ioctls are called concurrently

  dm-crypt:
   - fix a crash on invalid table line

  dm-snap:
   - fix a crash on invalid table line"

* tag 'for-7.3/dm-fixes-2' of git://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm:
  dm-integrity: validate the superblock on resume

    [5 lines not shown]
DeltaFile
+52-2drivers/md/dm-integrity.c
+11-3drivers/md/dm-ioctl.c
+14-0drivers/md/dm-snap.c
+6-1drivers/md/dm-crypt.c
+83-64 files

Linux/linux 602042b — kernel workqueue.c

Merge tag 'wq-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/wq

Pull workqueue fixes from Tejun Heo:

 - Fix a NULL dereference in the chained work check when a kworker
   queues work on a draining or destroying workqueue outside work item
   execution.

* tag 'wq-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/wq:
  workqueue: Fix NULL current_pwq deref in chained work check
DeltaFile
+1-1kernel/workqueue.c
+1-11 files

Linux/linux 0d32b3e — kernel/cgroup cpuset.c

Merge tag 'cgroup-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup

Pull cgroup fixes from Tejun Heo:

 - During CPU offline, the active mask drops the CPU before cpuset
   updates the effective CPUs, so a task placement in that window could
   find no active CPU in the top cpuset and dereference NULL. Restore
   the NULL check.

 - The cpuset v2-mode test read the subsystem's root pointer, which is
   stale during a cgroup filesystem rebind, and the hotplug handler
   evaluated it before taking the cpuset mutex. Record the mode in a
   flag and test it under the mutex.

* tag 'cgroup-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup:
  cgroup/cpuset: Call is_in_v2_mode() after acquiring cpuset_mutex in cpuset_handle_hotplug()
  cgroup/cpuset: Handle cpu hotplug race in guarantee_active_cpus()
  cgroup/cpuset: Don't access cpuset_cgrp_subsys.root in is_in_v2_mode()
DeltaFile
+32-8kernel/cgroup/cpuset.c
+32-81 files

Linux/linux 762122d — kernel/sched sched.h, kernel/sched/ext internal.h inlines.h

Merge tag 'sched_ext-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext

Pull sched_ext fixes from Tejun Heo:

 - Taking a CPU offline could hang, or stall until the watchdog ejected
   the BPF scheduler, when tasks on the dying CPU were still held by the
   scheduler or sitting on a user dispatch queue. Re-enqueue them onto
   the local queue when the runqueue goes offline so that the CPU pushes
   them off like the other sched classes.

 - The sequence number guarding against stale dispatches was per
   runqueue, so a task re-enqueued on another CPU could get the same
   number and a dispatch meant for its earlier instance was applied to
   the new one. Use a per-task counter.

 - A task dispatched to another CPU's local queue got its ops.dequeue()
   only when picked to run and flagged as a core-sched pick. Call it at
   insertion like for same-CPU dispatches.


    [5 lines not shown]
DeltaFile
+270-0tools/testing/selftests/sched_ext/dequeue_remote.bpf.c
+204-0tools/testing/selftests/sched_ext/dequeue_remote.c
+37-9kernel/sched/ext/ext.c
+7-1kernel/sched/ext/inlines.h
+3-3kernel/sched/sched.h
+5-0kernel/sched/ext/internal.h
+526-133 files not shown
+528-179 files

Linux/linux b8eb5fd — kernel/cgroup cpuset.c

cgroup/cpuset: Call is_in_v2_mode() after acquiring cpuset_mutex in cpuset_handle_hotplug()

It is reported by sashiko that calling is_in_v2_mode() outside of
cpuset_mutex critical section in cpuset_handle_hotplug() can introduce
a TOCTOU race where cgroup hierarchy may have changed from v1 to v2 or
vice versa after is_in_v2_mode() is called leading to erroneously skip
the allocation of tmpmasks or incorrectly modify cpus_allowed masks,
resulting in cpuset state corruption. Fix that by calling is_in_v2_mode()
after acquiring the cpuset_mutex.

Fixes: b8d1b8ee93df ("cpuset: Allow v2 behavior in v1 cgroup")
Signed-off-by: Waiman Long <longman at redhat.com>
Signed-off-by: Tejun Heo <tj at kernel.org>
DeltaFile
+5-4kernel/cgroup/cpuset.c
+5-41 files

Linux/linux 69f80fe — drivers/ata libata-scsi.c

Merge tag 'ata-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux

Pull ata fix from Niklas Cassel:

 - Set CHECK CONDITION for failed ATAPI commands.

   Since commit 2e1d2e65e773 ("ata: libata-scsi: terminate deferred
   commands on time out") failed ATAPI commands incorrectly stopped
   having CHECK CONDITION set for commands that had a SCSI midlayer
   byte set by scsi_check_sense(). SG_IO users therefore saw failed
   ATAPI commands as successful (Hengyu)

* tag 'ata-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
  ata: libata-scsi: do not lose CHECK CONDITION for failed ATAPI commands
DeltaFile
+9-4drivers/ata/libata-scsi.c
+9-41 files

Linux/linux 22430ae — drivers/accessibility/braille braille_console.c, drivers/tty/serial imx.c amba-pl011.c

Merge tag 'printk-for-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux

Pull printk fix from Petr Mladek:

 - Allow using Braille console with a serial console driver converted
   to NBCON API

* tag 'printk-for-7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux:
  braille: nbcon: Allow to use a serial console with NBCON API as Braille console
DeltaFile
+79-0kernel/printk/nbcon.c
+55-2drivers/accessibility/braille/braille_console.c
+15-0include/linux/console.h
+4-1drivers/tty/serial/8250/8250_port.c
+1-1drivers/tty/serial/imx.c
+1-1drivers/tty/serial/amba-pl011.c
+155-51 files not shown
+156-67 files

Linux/linux 2c3418f — security/keys key.c persistent.c

Merge tag 'keys-v7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd

Pull keys fixes from Jarkko Sakkinen:

 - key_get_persistent() created a new persistent keyring if one did not
   exist, but failed to set a timeout on it in an error path, preventing
   GC.

   Call key_set_timeout() regardless of key_link() result if a
   persistent keyring was created.

 - __key_create_or_update() made a copy of keyring->restrict_link before
   holding keyring->sem, which could cause add_key() to be executed
   against stale keyring restrictions. Fix it by copying the value only
   after taking keyring->sem

* tag 'keys-v7.3-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
  KEYS: Fix add_key() race with keyring restriction
  keys: finalize persistent keyring timeout after link attempt
DeltaFile
+32-23security/keys/persistent.c
+3-3security/keys/key.c
+35-262 files

Linux/linux 67f0943 — security/selinux avc.c hooks.c

Merge tag 'selinux-pr-20261005' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fixes from Paul Moore:

 - Preserve SECURITY_LSM_NATIVE_LABELS when reusing superblocks

   Similar to a previous fix (see the commit description of Stephen's
   fix) we need to check to see if we have already mounted/setup the
   superblock passed into the security_sb_set_mnt_opts() LSM hook so we
   don't mistakenly unset SECURITY_LSM_NATIVE_LABELS.

 - Fix a potential AVC sequence number data race

* tag 'selinux-pr-20261005' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: preserve NATIVE_LABELS on already-initialized sb in set_mnt_opts
  selinux: fix data race on AVC latest_notif
DeltaFile
+8-1security/selinux/hooks.c
+3-2security/selinux/avc.c
+11-32 files

Linux/linux 41c8899 — fs/btrfs xattr.c

btrfs: fix lost error return value in btrfs_listxattr()

If the input buffer does not have enough space to store the current xattr,
we set 'iter_ret' to -ERANGE and then do "break", but that only exits the
while loop over the xattrs in the current btrfs_dir_item, and then we
continue the btrfs_for_each_slot() iteration, which overwrites the value
of 'iter_ret' causing us to lose the error return value and proceed as if
the buffer has enough space.

Fix this by returning -ERANGE directly (the path is automatically freed)
instead of breaking from the while loop.

Fixes: 184b3d190087 ("btrfs: use btrfs_for_each_slot in btrfs_listxattr")
Assisted-by: LLM (found the bug)
Reviewed-by: Qu Wenruo <wqu at suse.com>
Signed-off-by: Filipe Manana <fdmanana at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+2-4fs/btrfs/xattr.c
+2-41 files

Linux/linux a8ea928 — fs/btrfs ioctl.c

btrfs: free iov when btrfs_uring_read_extent() fails

After btrfs_uring_read_extent(), the caller always jumped to out_acct.
That skips kfree(data->iov), which is only correct for -EIOCBQUEUED
where the deferred path owns the iov. On failure, fall through to
out_free instead.

Fixes: 34310c442e17 ("btrfs: add io_uring command for encoded reads (ENCODED_READ ioctl)")
Signed-off-by: Yang Xiuwei <yangxiuwei at kylinos.cn>
Reviewed-by: David Sterba <dsterba at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+2-2fs/btrfs/ioctl.c
+2-21 files

Linux/linux 1fd742c — fs/btrfs scrub.c

btrfs: scrub: fix local_root reference leak in scrub_print_warning_inode()

When paths_from_inode() fails, scrub_print_warning_inode() jumps to err
without dropping the reference taken by btrfs_get_fs_root(), leaking a
reference to the root every time path resolution fails while printing
scrub warnings.  Every other error and success path of the function
drops the reference.

Drop the reference on the paths_from_inode() failure path too.

Fixes: 558540c17771 ("btrfs scrub: print paths of corrupted files")
CC: stable at vger.kernel.org
Reviewed-by: Qu Wenruo <wqu at suse.com>
Signed-off-by: Wentao Liang <vulab at iscas.ac.cn>
Reviewed-by: David Sterba <dsterba at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+3-1fs/btrfs/scrub.c
+3-11 files

Linux/linux 858bee1 — fs/btrfs xattr.c

btrfs: fix xattr replace when multiple xattrs are packed in the same item

If we have a btrfs_dir_item item that packs multiple xattrs and then we
replace the value of one of them (with the setxattr(2) family of syscalls)
with another value of a different size, we end up not having a fully
initialized btrfs_dir_item, resulting in a corruption that the tree
checker will detect at extent buffer writeback time.

This is because in btrfs_setxattr() when we find a btrfs_dir_item with
multiple xattrs (due to the crc32c hash of their name being the same)
we delete one of the xattr items (btrfs_dir_item) and then insert a new
one, but the deletion and insertion results in shifting existing data in
the leaf and therefore when the new value of a xattr has a different size,
the new btrfs_dir_item is placed in a leaf section that was not
initialized and we only copy the value's data and set the value's length
in the new btrfs_dir_item, without setting the name, the name's length,
the key (which must be all zeroes for xattrs), flags (BTRFS_FT_XATTR) and
transaction ID.


    [187 lines not shown]
DeltaFile
+9-0fs/btrfs/xattr.c
+9-01 files

Linux/linux 80a8dbb — fs/btrfs inode.c

btrfs: always return -EIOCBQUEUED after btrfs_uring_read_extent_endio

If all bios finish before btrfs_encoded_read_regular_fill_pages()
returns, it calls btrfs_uring_read_extent_endio() and previously
returned the I/O status.  A negative errno then made
btrfs_uring_read_extent() unlock and free while
btrfs_uring_read_finished() did the same again.

Return -EIOCBQUEUED so only the deferred path cleans up.

Reported-by: Yue Sun <samsun1006219 at gmail.com>
Closes: https://lore.kernel.org/linux-btrfs/20260630091609.3414-1-samsun1006219@gmail.com/
Suggested-by: Jens Axboe <axboe at kernel.dk>
Fixes: 34310c442e17 ("btrfs: add io_uring command for encoded reads (ENCODED_READ ioctl)")
Signed-off-by: Yang Xiuwei <yangxiuwei at kylinos.cn>
Reviewed-by: David Sterba <dsterba at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+3-4fs/btrfs/inode.c
+3-41 files

Linux/linux b6e8add — fs/btrfs ioctl.c

btrfs: unlock inode and extent in caller when io_uring read extent fails

btrfs_uring_read_extent() runs only after btrfs_encoded_read() has taken
the inode shared lock and the extent lock.  On failure it used to unlock
in out_fail, and a pages-array allocation failure returned -ENOMEM
without unlocking at all.

Unlock in the caller instead on all failure returns, matching the
copy_to_user() error path.  The deferred -EIOCBQUEUED path still unlocks
in btrfs_uring_read_finished().

Fixes: 34310c442e17 ("btrfs: add io_uring command for encoded reads (ENCODED_READ ioctl)")
Suggested-by: Qu Wenruo <quwenruo.btrfs at gmx.com>
Reviewed-by: Qu Wenruo <wqu at suse.com>
Signed-off-by: Yang Xiuwei <yangxiuwei at kylinos.cn>
Reviewed-by: David Sterba <dsterba at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+3-4fs/btrfs/ioctl.c
+3-41 files

Linux/linux 51562a8 — fs/btrfs ioctl.c

btrfs: don't stash io_uring encoded data across -EAGAIN

Returning -EAGAIN while leaving btrfs_uring_encoded_data in the cmd PDU
leaks if the request is cancelled or the ring exits before reissue.
io_uring does not free driver PDU allocations on cleanup.

Write: io_queue_sqe() always issues with IO_URING_F_NONBLOCK first, so
return -EAGAIN before allocating and free data on every exit.

Read: free on nowait -EAGAIN too; only -EIOCBQUEUED keeps the allocation
for btrfs_uring_read_finished().

Fixes: 34310c442e17 ("btrfs: add io_uring command for encoded reads (ENCODED_READ ioctl)")
Fixes: e32dcdb0af9f ("btrfs: add io_uring interface for encoded writes")
Signed-off-by: Yang Xiuwei <yangxiuwei at kylinos.cn>
Reviewed-by: David Sterba <dsterba at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+11-9fs/btrfs/ioctl.c
+11-91 files

Linux/linux 3e6ff34 — fs/btrfs transaction.c

btrfs: clear BTRFS_ROOT_IN_TRANS_SETUP on early exit from record_root_in_trans()

If we exit early because the transaction that last used the root already
matches the current transaction, we leave the BTRFS_ROOT_IN_TRANS_SETUP
bit set in the root (which we just set right before the exit). While this
does not cause any functional issue, it makes callers of
btrfs_record_root_in_trans() lock fs_info->reloc_mutex and call
record_root_in_trans() for nothing, causing unnecessary lock contention,
until one of them clears the bit in record_root_in_trans().
One caller of btrfs_record_root_in_trans() is start_transaction(), used to
start new transaction or joining an existing one, which is a hot path.

So clear BTRFS_ROOT_IN_TRANS_SETUP on early exit.

Assisted-by: LLM
Reviewed-by: Boris Burkov <boris at bur.io>
Reviewed-by: Qu Wenruo <wqu at suse.com>
Signed-off-by: Filipe Manana <fdmanana at suse.com>
Signed-off-by: David Sterba <dsterba at suse.com>
DeltaFile
+1-0fs/btrfs/transaction.c
+1-01 files

Linux/linux a90ee43 — . Makefile

Linux 7.3-rc6
DeltaFile
+1-1Makefile
+1-11 files

Linux/linux dd3ea3f — security/keys key.c

KEYS: Fix add_key() race with keyring restriction

__key_create_or_update() snapshots keyring->restrict_link before taking
the destination keyring's semaphore.  keyring_restrict() installs a
restriction while holding that semaphore.

This allows a writer to observe no restriction, wait for the keyring
owner to install a reject-all restriction and return successfully, and
then link a key using the stale NULL snapshot.  The writer only needs
write permission on the destination keyring.

Move the restrict_link read after __key_link_lock() and
__key_link_begin().  The read and the subsequent restriction check are
then serialized with restriction installation by keyring->sem.

The race was reproduced on v7.2.8 in 19 executions where restriction
installation returned before the link completed.  All 19 linked the key
despite the reject-all restriction.  With this change, 312 executions
reached the same ordering and every add_key() call failed with -EPERM.

    [11 lines not shown]
DeltaFile
+3-3security/keys/key.c
+3-31 files

Linux/linux 25bf14f — security/keys persistent.c

keys: finalize persistent keyring timeout after link attempt

When no keyring exists for the requested UID, KEYCTL_GET_PERSISTENT
creates and registers one before linking it to the requested destination.
The configured timeout is set only after the destination link succeeds.

A destination restricted with KEYCTL_RESTRICT_KEYRING makes that link fail
with -EPERM. With persistent_keyring_expiry set to 60 seconds, /proc/keys
still reports the registered keyring's expiry as "perm".
The failed call therefore leaves a quota-exempt keyring in the namespace's
hidden register, where it may remain until namespace teardown.

Rename the write-locked helper to key_get_or_create_persistent() and return
the key reference through a result parameter. Return 0 when it creates a
keyring and 1 when the retry finds an existing one. Return a negative error
on failure. Another caller may create the keyring between the initial
read-locked lookup and the retry under the write lock.

Set the timeout after permission checking and linking. Do this on success,

    [11 lines not shown]
DeltaFile
+32-23security/keys/persistent.c
+32-231 files

Linux/linux 7704c4c — drivers/i2c/busses i2c-at91-master.c i2c-xiic.c

Merge tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux

Pull i2c fixes from Andi Shyti:
 "Three patches in xiic for fixing the block reads and a single cleanup
  in the at91 error path:

   - at91: also release DMA channels when deferring probe

   - xiic: fix SMBus block reads with PEC"

* tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:
  i2c: at91: release DMA channels when probe defers
  i2c: xiic: don't clobber msg->len to signal block-read completion
  i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO
  i2c: xiic: preserve PEC byte length in SMBus block read setup
DeltaFile
+46-15drivers/i2c/busses/i2c-xiic.c
+7-1drivers/i2c/busses/i2c-at91-master.c
+53-162 files

Linux/linux 06ac073 — arch/x86/include/uapi/asm ptrace-abi.h, arch/x86/kernel sys_x86_64.c

Merge tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fixes from Ingo Molnar:

 - Don't apply va_align to hugetlb mappings on AMD F15h systems
   that have custom va_align.bits values (Laurent Wandrebeck)

 - Fix PMD teardown handling regression flagged by lockdep
   (Mikhail Gavrilov)

 - Hide ptrace header register offset macros behind __ASSEMBLER__ or
   __FRAME_OFFSETS, to fix user-space build errors that may trigger
   if they happen to shadow these short and generic macro names
   (Nick Desaulniers)

* tag 'x86-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  {x86,um}/uapi/ptrace: Guard register offset macros with __ASSEMBLER__ or __FRAME_OFFSETS
  x86/mm: Drop unnecessary PMD page copy when freeing
  x86/mm: Don't apply va_align to hugetlb mappings on AMD F15h
DeltaFile
+14-24arch/x86/mm/pgtable.c
+11-4arch/x86/kernel/sys_x86_64.c
+1-3arch/x86/um/asm/ptrace.h
+2-2arch/x86/include/uapi/asm/ptrace-abi.h
+1-0arch/x86/um/ptrace_32.c
+29-335 files

Linux/linux 942e4a0 — include/linux hrtimer_rearm.h

Merge tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull timer fix from Ingo Molnar:

 - Fix task work flags management regression in the hrtimer
   rearming code that can leave task work items unprocessed
   (Karl Mehltretter)

* tag 'timers-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
DeltaFile
+1-1include/linux/hrtimer_rearm.h
+1-11 files

Linux/linux a27611f — arch/powerpc/perf imc-pmu.c, include/linux perf_event.h

Merge tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull perf events fixes from Ingo Molnar:

 - Fix race between perf_event_exit_task() and perf_pending_task()
   (Luo Gengkun)

 - Fix perf header output management regressions (Ian Rogers)

 - Require kernel access for text poke events (Zhengchuan Liang)

* tag 'perf-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf: Require kernel access for text poke events
  perf: Replace perf_event_header__init_id with full header init
  perf: Fix race between perf_event_exit_task() and perf_pending_task()
DeltaFile
+132-179kernel/events/core.c
+12-11arch/powerpc/perf/imc-pmu.c
+3-4kernel/events/ring_buffer.c
+4-3include/linux/perf_event.h
+151-1974 files

Linux/linux 1c915d6 — kernel/futex core.c, kernel/irq Makefile Kconfig

Merge tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull locking fixes from Ingo Molnar:

 - Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS
   (Kuan-Wei Chiu)

 - Fix futex private hash use-after-free on resize (Chris Mason)

* tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  futex: Fix private hash use-after-free on resize
  irq: Make refcount_interrupt kunit test selectable
DeltaFile
+12-0kernel/irq/Kconfig
+6-4kernel/futex/core.c
+1-1kernel/irq/Makefile
+19-53 files

Linux/linux 6addb4f — drivers/edac versalnet_edac.c altera_edac.c

Merge tag 'edac_urgent_for_v7.3_rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/ras/ras

Pull EDAC fixes from Borislav Petkov:
 "This is more of the new normal of LLM-induced fixes of error paths. Oh
  well, they should be done eventually and hopefully we'll be back to
  normal soon-ish... one would hope... :-P

  AMD Versal NET:

   - Properly release a remote processor reference which was acquired at
     probe time, on memory controller instance remove

  A handful of Altera EDAC driver fixes:

   - Fix device node reference leaks covering both the success path and
     the various error paths, and route the single-bit setup function
     through the common exit label

   - Fix a use-after-free by releasing the devres group before freeing

    [22 lines not shown]
DeltaFile
+35-32drivers/edac/altera_edac.c
+1-0drivers/edac/versalnet_edac.c
+36-322 files

Linux/linux e6ac89b — include/linux/sched ext.h, kernel/sched sched.h

sched_ext: Generate qseq from a per-task counter

finish_dispatch() uses the qseq embedded in p->scx.ops_state to tell
whether the QUEUED instance of a task it's about to claim is the one
scx_bpf_dsq_insert() saw. qseq is generated from rq->scx.ops_qseq, but
the counters of different rqs are independent, so if a task is dequeued
and re-enqueued on a different rq between scx_bpf_dsq_insert() and
finish_dispatch(), the new QUEUED instance can end up with the same
qseq as the old one:

  CPU X                          CPU Z
  -----                          -----
                                 enqueue p on rq A, qseq = N
  ops.dispatch()
    scx_bpf_dsq_insert(p)
      records qseq N
                                 sched_setaffinity(p)
                                   dequeue p from rq A
                                   enqueue p on rq B, qseq = N

    [28 lines not shown]
DeltaFile
+10-4kernel/sched/ext/ext.c
+5-0kernel/sched/ext/internal.h
+0-1kernel/sched/sched.h
+1-0include/linux/sched/ext.h
+16-54 files

Linux/linux a74306e — drivers/clk/spacemit ccu-k3.c, drivers/clk/ti composite.c

Merge tag 'clk-fixes-for-linus-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux

Pull clk fixes from Brian Masney:
 "Two small clk driver fixes:

   - spacemit: k3: Fix an issue that will trigger a system hang due to
     unavailable frequency

   - ti: composite: Reverts a commit that breaks OMAP3"

* tag 'clk-fixes-for-linus-v7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux:
  clk: spacemit: k3: add CPU PLL rate tables
  clk: ti: composite: resolve parent clocks by name again
DeltaFile
+92-0drivers/clk/spacemit/ccu-k3.c
+12-14drivers/clk/ti/composite.c
+104-142 files

Linux/linux 25d576e — drivers/android/binder/node wrapper.rs, drivers/iio/adc ade9000.c stm32-adc.c

Merge tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc

Pull char/misc/IIO fixes from Greg KH:
 "Here is a set of char/misc/iio and other small driver subsystem fixes
  for 7.3-rc6 that resolve a number of reported issues. Included in here
  are:

   - lots of small iio driver fixes for reported problems

   - interconnect driver revert to resolve a regression

   - nitro_enclaves driver fix for a use-after-free

   - binder driver fixes for reported problems (in both the rust and C
     versions)

  All of these have been in linux-next with no reported issues"

* tag 'char-misc-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (63 commits)

    [21 lines not shown]
DeltaFile
+0-485drivers/interconnect/qcom/x1e80100.c
+37-25drivers/iio/light/rohm-bu27034.c
+28-19drivers/iio/adc/stm32-adc.c
+29-9drivers/iio/imu/inv_icm42607/inv_icm42607_core.c
+19-17drivers/iio/adc/ade9000.c
+33-1drivers/android/binder/node/wrapper.rs
+146-55643 files not shown
+407-65849 files