Commit graph

985,442 commits

Author SHA1 Message Date
dianlujitao
2906b38ea7
Revert "disp: msm:: reset the param value to the default value"
This reverts commit 5c202c9614.

Change-Id: Ia6c492d29b47f8d829c38e941fd3a896e8102647
2025-09-06 11:05:34 +03:00
Michael Bestas
b3dd3932b4
Revert "fixup! (CR): disp: msm:: reset the param value to the default value"
This reverts commit b6d3acff9c.

Change-Id: I0fbb96bbb20811f0a7636554ce878804a43747a4
2025-09-06 11:05:34 +03:00
dianlujitao
cbded7bc5c
disp: msm: dsi: invert CABC status code
0: off, 1: ui, 2: movie

Change-Id: Ie8ef4b9fac60fb16e087be3c9f1b97a19a816951
2025-09-06 11:05:34 +03:00
dianlujitao
5f7c152f42
disp: msm: sde: expose panel features to sysfs by wrapping moto utils
Change-Id: Ibb70f479fb8fcfd582d41e47f759327679b40f46
2025-09-06 11:05:33 +03:00
Michael Bestas
aae02053fd
Merge tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display into lineage-22.2
Bangkk push for Android 15

* tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display:
  disp: msm: dsi: add null pointer check in dsi_display_dev_remove
  msm/dsi_display: resend new roi to panel, fix pu dup issue
  disp: msm: sde: clear cached rectangles when PU ROI is set

Change-Id: I2eed4c78f491b527ed088576e799dfb4488e5e97
2025-09-05 16:38:14 +03:00
Michael Bestas
284572d645
Merge tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-devicetree into lineage-22.2
Bangkk push for Android 15

* tag 'MMI-V1TC35H.88-16' of https://github.com/MotorolaMobilityLLC/kernel-devicetree:
  [Fogo5G NA] DCP fallback to 10W

Change-Id: I4251180025c5905372e2dbccfdf9c8db76e060a5
2025-09-05 16:16:16 +03:00
Michael Bestas
273969fc48
Merge branch 'staging/kernel-msm/MMI-V1TC35H.88-16' into lineage-22.2
* staging/kernel-msm/MMI-V1TC35H.88-16:
  bangkk:en62680 PD TEST.PD.PROT.PORT3.02
  bangkk:en62680 PD TEST.PD.VDM.SNK.02&05
  bangkk: en62680 PD test

Change-Id: I2e7de2f0c8bc3fb007c6b0359d7dd44b540a355e
2025-09-05 16:10:19 +03:00
Lei Chen
6a5f80b78d
bangkk:en62680 PD TEST.PD.PROT.PORT3.02
Changes,
Fixe the PD test case TEST.PD.PROT.PORT3.02.

Change-Id: I881b1890f6ad618467c1775e7d93efa93d482ed3
Signed-off-by: Lei Chen <chenlei18@lenovo.com>
Reviewed-on: https://gerrit.mot.com/3137769
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Zonghua Liu <a17671@motorola.com>
Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com>
Submit-Approved: Jira Key
2025-09-05 16:09:23 +03:00
Lei Chen
3feb6cd70d
bangkk:en62680 PD TEST.PD.VDM.SNK.02&05
PROPAGATED_from (CR)

Fix EU common charger failed case
TEST.PD.VDM.SNK.02 Exit Mode without Entering
TEST.PD.VDM.SNK.05 DR Swap in Modal Operation

Change-Id: If642f90442175af9d5ae4b19bb588c45bb2bca88
Signed-off-by: Lei Chen <chenlei18@lenovo.com>
Reviewed-on: https://gerrit.mot.com/3141838
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Zonghua Liu <a17671@motorola.com>
Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com>
Submit-Approved: Jira Key
Reviewed-on: https://gerrit.mot.com/3239425
Reviewed-by: Bruno Oliveira <brunosoe@motorola.com>
Reviewed-by: Deise Alves <deisema@motorola.com>
Submit-Approved: Deise Alves <deisema@motorola.com>
2025-09-05 16:09:21 +03:00
Lei Chen
1c37a3a2d1
bangkk: en62680 PD test
PROPAGATED_from (CR)

main changes:
add several protocol related interface to pass cases
such as
TEST.PD.PROT.ALL.01 Corrupted GoodCRC
TEST.PD.PROT.ALL.04 Reset Signals and MessageID
TEST.PD.PROT.ALL3.08 Get Revision Response
TEST.PD.PROT.PORT3.01 Get_Battery_Status Response
TEST.PD.PROT.PORT3.02 Invalid Battery Status Reference
TEST.PD.PROT.PORT3.03 Get_Battery_Cap Response
TEST.PD.PROT.PORT3.04 Invalid Battery Capabilities Reference
TEST.PD.PROT.SRC.03 SenderResponseTimer Deadline
TEST.PD.PROT.SNK.12 PR_Swap - PSSourceOffTimer Timeout
TEST.PD.PROT.SNK.13 PR_Swap - Request SenderResponseTimer Timeout
TEST.PD.VDM.SRC.01 Discovery Process and Enter Mode
TEST.PD.VDM.SRC.02 Invalid Fields - Discover Identity
TEST.PD.VDM.SNK.06 Structured VDM Revision Number Test
TEST.PD.PS.SRC.01 Multiple Request Load Test
TEST.PD.PS.SNK.03 Multiple Request Load Test Post PR Swap

Change-Id: I0d5df498d1b9d42080eaac9c9b8297c31a120938
Signed-off-by: Lei Chen <chenlei18@lenovo.com>
Reviewed-on: https://gerrit.mot.com/3126980
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Zonghua Liu <a17671@motorola.com>
Reviewed-by: Wei Xu <xuwei9@lenovo.com>
Reviewed-by: Xiangpo Zhao <zhaoxp3@motorola.com>
Submit-Approved: Jira Key
Reviewed-on: https://gerrit.mot.com/3239424
Reviewed-by: Bruno Oliveira <brunosoe@motorola.com>
Reviewed-by: Deise Alves <deisema@motorola.com>
Submit-Approved: Deise Alves <deisema@motorola.com>
2025-09-05 16:09:18 +03:00
AnierinB
1de2e5d505
input: touchscreen: nova_0flash_mmi: Start firmware update immediately
Allows touch to immediately be available in recovery.

Change-Id: I426dc7a42bc6c2692d8a0aa039648178c1d35c51
Signed-off-by: AnierinB <anierin@evolution-x.org>
2025-09-04 12:41:52 +03:00
Raghavendra Ambadas
85ce702b47
disp: msm: dsi: Avoid dynamic mode switch during first commit
Dynamic mode switch (DMS) is not supported for video mode panels
before cont-splash handoff handled for first frame. so avoid
dynamic mode-switch during cont-splash handoff for any DRM mode change.

WA is given by QC for GSI issue, as of observation there are no
side effects

QC SR:05515278
QC CR:NA
QC Change ID:Icd5881af99afb3e398d3bba3746b7a35bcda4491

Change-Id: I97f5712ce5bb8448f1c600ccf306d0dac7fa6eae
Signed-off-by: maheshmk <maheshmk@motorola.com>
Reviewed-on: https://gerrit.mot.com/2113033
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Ashwin Kumar Pathmudi <jfxr63@motorola.com>
Reviewed-by: Shuo Yan <shuoyan@motorola.com>
Reviewed-by: Guobin Zhang <zhanggb@motorola.com>
Submit-Approved: Jira Key
2025-09-04 12:38:45 +03:00
Michael Bestas
ee69f5d73d
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-22.2
* sm8350/lineage-20:
  ANDROID: bpf: do not fail to load if log is full
  ANDROID: fix kernelci compressed kernel linking
  ANDROID: GKI: Update symbol list for Zebra
  UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  Linux 5.4.295
  scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
  arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
  perf: Fix sample vs do_exit()
  s390/pci: Fix __pcilg_mio_inuser() inline assembly
  rtc: test: Fix invalid format specifier.
  jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
  mm/huge_memory: fix dereferencing invalid pmd migration entry
  rtc: Make rtc_time64_to_tm() support dates before 1970
  rtc: Improve performance of rtc_time64_to_tm(). Add tests.
  xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
  posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
  ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
  net: atm: fix /proc/net/atm/lec handling
  ...

Change-Id: Ibdde607f7a4ae5a74994603f513e7f94a9eb04ad
2025-09-02 13:51:29 +03:00
Michael Bestas
2b9e22c70c
Merge tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-08-01

* tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common:
  ANDROID: bpf: do not fail to load if log is full
  ANDROID: fix kernelci compressed kernel linking
  ANDROID: GKI: Update symbol list for Zebra
  UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  Linux 5.4.295
  scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
  arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
  perf: Fix sample vs do_exit()
  s390/pci: Fix __pcilg_mio_inuser() inline assembly
  rtc: test: Fix invalid format specifier.
  jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
  mm/huge_memory: fix dereferencing invalid pmd migration entry
  rtc: Make rtc_time64_to_tm() support dates before 1970
  rtc: Improve performance of rtc_time64_to_tm(). Add tests.
  xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
  posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
  ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
  net: atm: fix /proc/net/atm/lec handling
  net: atm: add lec_mutex
  calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
  tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
  tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
  atm: atmtcp: Free invalid length skb in atmtcp_c_send().
  mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
  wifi: carl9170: do not ping device which has failed to load firmware
  aoe: clean device rq_list in aoedev_downdev()
  hwmon: (occ) fix unaligned accesses
  drm/nouveau/bl: increase buffer size to avoid truncate warning
  erofs: remove unused trace event erofs_destroy_inode
  ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
  ALSA: hda/intel: Add Thinkpad E15 to PM deny list
  Input: sparcspkr - avoid unannotated fall-through
  HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
  atm: Revert atm_account_tx() if copy_from_iter_full() fails.
  selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
  scsi: s390: zfcp: Ensure synchronous unit_add
  scsi: storvsc: Increase the timeouts to storvsc_timeout
  jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
  jffs2: check that raw node were preallocated before writing summary
  drivers/rapidio/rio_cm.c: prevent possible heap overwrite
  Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
  powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
  platform/x86: dell_rbu: Stop overwriting data buffer
  platform: Add Surface platform directory
  Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
  tee: Prevent size calculation wraparound on 32-bit kernels
  ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
  bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
  watchdog: da9052_wdt: respect TWDMIN
  i40e: fix MMIO write access to an invalid page in i40e_clear_hw
  sock: Correct error checking condition for (assign|release)_proto_idx()
  scsi: lpfc: Use memcpy() for BIOS version
  vxlan: Do not treat dst cache initialization errors as fatal
  clk: rockchip: rk3036: mark ddrphy as critical
  wifi: mac80211: do not offer a mesh path if forwarding is disabled
  net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
  pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
  pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
  pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
  pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
  ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
  tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
  tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
  net: dlink: add synchronization for stats update
  sctp: Do not wake readers in __sctp_write_space()
  emulex/benet: correct command version selection in be_cmd_get_stats()
  i2c: designware: Invoke runtime suspend on quick slave re-registration
  net: macb: Check return value of dma_set_mask_and_coherent()
  cpufreq: Force sync policy boost with global boost on sysfs update
  nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
  media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
  media: tc358743: ignore video while HPD is low
  drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
  jfs: Fix null-ptr-deref in jfs_ioc_trim
  drm/amdgpu/gfx9: fix CSIB handling
  drm/amdgpu/gfx8: fix CSIB handling
  jfs: fix array-index-out-of-bounds read in add_missing_indices
  drm/amdgpu/gfx7: fix CSIB handling
  drm/amdgpu/gfx10: fix CSIB handling
  drm/msm/a6xx: Increase HFI response timeout
  drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
  media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
  drm/msm/hdmi: add runtime PM calls to DDC transfer function
  drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
  sunrpc: update nextcheck time when adding new cache entries
  drm/amdgpu/gfx6: fix CSIB handling
  ACPI: battery: negate current when discharging
  PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
  power: supply: bq27xxx: Retrieve again when busy
  ACPICA: fix acpi parse and parseext cache leaks
  ACPICA: Avoid sequence overread in call to strncmp()
  ACPICA: fix acpi operand cache leak in dswstate.c
  iio: adc: ad7606_spi: fix reg write value mask
  PCI: Fix lock symmetry in pci_slot_unlock()
  PCI: Add ACS quirk for Loongson PCIe
  uio_hv_generic: Use correct size for interrupt and monitor pages
  regulator: max14577: Add error check for max14577_read_reg()
  mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
  staging: iio: ad5933: Correct settling cycles encoding per datasheet
  net: ch9200: fix uninitialised access during mii_nway_restart
  ftrace: Fix UAF when lookup kallsym after ftrace disabled
  dm-mirror: fix a tiny race condition
  mtd: nand: sunxi: Add randomizer configuration before randomizer enable
  mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
  mm: fix ratelimit_pages update error in dirty_ratio_handler()
  ipc: fix to protect IPCS lookups using RCU
  parisc: fix building with gcc-15
  vgacon: Add check for vc_origin address range in vgacon_scroll()
  fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
  EDAC/altera: Use correct write width with the INTTEST register
  NFC: nci: uart: Set tty->disc_data only in success path
  f2fs: prevent kernel warning due to negative i_nlink from corrupted image
  Input: ims-pcu - check record size in ims_pcu_flash_firmware()
  ext4: fix calculation of credits for extent tree modification
  ext4: inline: fix len overflow in ext4_prepare_inline_data
  bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
  ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
  ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
  media: v4l2-dev: fix error handling in __video_register_device()
  media: gspca: Add error handling for stv06xx_read_sensor()
  wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
  nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
  wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
  gfs2: move msleep to sleepable context
  configfs: Do not override creating attribute file failure in populate_attrs()
  net: usb: aqc111: debug info before sanitation
  calipso: unlock rcu before returning -EAFNOSUPPORT
  xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
  usb: Flush altsetting 0 endpoints before reinitializating them after reset.
  fs/filesystems: Fix potential unsigned integer underflow in fs_name()
  net/mdiobus: Fix potential out-of-bounds read/write access
  drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
  drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
  MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
  x86/boot/compressed: prefer cc-option for CFLAGS additions
  net: mdio: C22 is now optional, EOPNOTSUPP if not provided
  net_sched: tbf: fix a race in tbf_change()
  net_sched: red: fix a race in __red_change()
  net_sched: prio: fix a race in prio_tune()
  net/mlx5: Fix return value when searching for existing flow group
  net/mlx5: Wait for inactive autogroups
  i40e: retry VFLR handling if there is ongoing VF reset
  i40e: return false from i40e_reset_vf if reset is in progress
  net_sched: sch_sfq: fix a potential crash on gso_skb handling
  scsi: iscsi: Fix incorrect error path labels for flashnode operations
  NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
  NFSD: Fix ia_size underflow
  Input: synaptics-rmi - fix crash with unsupported versions of F34
  Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
  pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
  do_change_type(): refuse to operate on unmounted/not ours mounts
  PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
  ice: create new Tx scheduler nodes for new queues only
  Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
  net/mlx4_en: Prevent potential integer overflow calculating Hz
  vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
  serial: Fix potential null-ptr-deref in mlb_usio_probe()
  usb: renesas_usbhs: Reorder clock handling and power management in probe
  rtc: Fix offset calculation for .start_secs < 0
  rtc: sh: assign correct interrupts with DT
  perf record: Fix incorrect --user-regs comments
  perf tests switch-tracking: Fix timestamp comparison
  mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
  mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
  rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
  perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
  perf ui browser hists: Set actions->thread before calling do_zoom_thread()
  fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
  soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
  soc: aspeed: lpc: Fix impossible judgment condition
  arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
  ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
  bus: fsl-mc: fix double-free on mc_dev
  nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
  nilfs2: add pointer check for nilfs_direct_propagate()
  Squashfs: check return result of sb_min_blocksize
  ARM: dts: at91: at91sam9263: fix NAND chip selects
  ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
  f2fs: fix to correct check conditions in f2fs_cross_rename
  f2fs: use d_inode(dentry) cleanup dentry->d_inode
  calipso: Don't call calipso functions for AF_INET sk.
  net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
  net: usb: aqc111: fix error handling of usbnet read calls
  netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
  wifi: ath9k_htc: Abort software beacon handling if disabled
  bpf: Fix WARN() in get_bpf_raw_tp_regs
  pinctrl: at91: Fix possible out-of-boundary access
  ktls, sockmap: Fix missing uncharge operation
  netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
  f2fs: clean up w/ fscrypt_is_bounce_page()
  RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
  wifi: rtw88: do not ignore hardware read error during DPK
  net: ncsi: Fix GCPS 64-bit member variables
  f2fs: fix to do sanity check on sbi->total_valid_block_count
  drm/tegra: rgb: Fix the unbound reference count
  drm/vkms: Adjust vkms_state->active_planes allocation type
  drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
  selftests/seccomp: fix syscall_restart test for arm compat
  firmware: psci: Fix refcount leak in psci_dt_init
  m68k: mac: Fix macintosh_config for Mac II
  drm/vmwgfx: Add seqno waiter for sync_files
  spi: sh-msiof: Fix maximum DMA transfer size
  ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
  x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
  PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
  EDAC/skx_common: Fix general protection fault
  crypto: marvell/cesa - Avoid empty transfer descriptor
  crypto: marvell/cesa - Handle zero-length skcipher requests
  x86/cpu: Sanitize CPUID(0x80000000) output
  perf/core: Fix broken throttling when max_samples_per_tick=1
  gfs2: gfs2_create_inode error handling fix
  netfilter: nft_socket: fix sk refcount leaks
  thunderbolt: Do not double dequeue a configuration request
  usb: usbtmc: Fix timeout value in get_stb
  usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
  usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
  pinctrl: armada-37xx: set GPIO output value before setting direction
  pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
  tracing: Fix compilation warning on arm32
  BACKPORT: binder: Create safe versions of binder log files
  UPSTREAM: binder: Refactor binder_node print synchronization
  Revert "coredump: hand a pidfd to the usermode coredump helper"
  Linux 5.4.294
  xen/swiotlb: relax alignment requirements
  platform/x86: thinkpad_acpi: Ignore battery threshold change event notification
  platform/x86: fujitsu-laptop: Support Lifebook S2110 hotkeys
  spi: spi-sun4i: fix early activation
  um: let 'make clean' properly clean underlying SUBARCH as well
  platform/x86: thinkpad_acpi: Support also NEC Lavie X1475JAS
  nfs: don't share pNFS DS connections between net namespaces
  HID: quirks: Add ADATA XPG alpha wireless mouse support
  coredump: hand a pidfd to the usermode coredump helper
  fork: use pidfd_prepare()
  pid: add pidfd_prepare()
  pidfd: check pid has attached task in fdinfo
  coredump: fix error handling for replace_fd()
  net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
  smb: client: Reset all search buffer pointers when releasing buffer
  smb: client: Fix use-after-free in cifs_fill_dirent
  drm/i915/gvt: fix unterminated-string-initialization warning
  netfilter: nf_tables: do not defer rule destruction via call_rcu
  netfilter: nf_tables: wait for rcu grace period on net_device removal
  netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx
  kbuild: Disable -Wdefault-const-init-unsafe
  spi: spi-fsl-dspi: restrict register range for regmap access
  mm/page_alloc.c: avoid infinite retries caused by cpuset race
  memcg: always call cond_resched() after fn()
  drm/edid: fixed the bug that hdr metadata was not reset
  llc: fix data loss when reading from a socket in llc_ui_recvmsg()
  ALSA: pcm: Fix race of buffer access at PCM OSS layer
  can: bcm: add missing rcu read protection for procfs content
  can: bcm: add locking for bcm_op runtime updates
  crypto: algif_hash - fix double free in hash_accept
  sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
  net: dwmac-sun8i: Use parsed internal PHY address instead of 1
  bridge: netfilter: Fix forwarding of fragmented packets
  xfrm: Sanitize marks before insert
  __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock
  xenbus: Allow PVH dom0 a non-local xenstore
  btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref
  nvmet-tcp: don't restore null sk_state_change
  ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013
  pinctrl: meson: define the pull up/down resistor value as 60 kOhm
  drm: Add valid clones check
  drm/atomic: clarify the rules around drm_atomic_state->allow_modeset
  regulator: ad5398: Add device tree support
  wifi: rtw88: Don't use static local variable in rtw8822b_set_tx_power_index_by_rate
  bpftool: Fix readlink usage in get_fd_type
  HID: usbkbd: Fix the bit shift number for LED_KANA
  scsi: st: Restore some drive settings after reset
  scsi: lpfc: Handle duplicate D_IDs in ndlp search-by D_ID routine
  rcu: fix header guard for rcu_all_qs()
  rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y
  vxlan: Annotate FDB data races
  hwmon: (xgene-hwmon) use appropriate type for the latency value
  ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure().
  net/mlx5e: reduce rep rxq depth to 256 for ECPF
  net/mlx5e: set the tx_queue_len for pfifo_fast
  net/mlx5: Extend Ethtool loopback selftest to support non-linear SKB
  phy: core: don't require set_mode() callback for phy_get_mode() to work
  net/mlx4_core: Avoid impossible mlx4_db_alloc() order value
  smack: recognize ipv4 CIPSO w/o categories
  pinctrl: devicetree: do not goto err when probing hogs in pinctrl_dt_to_map
  ASoC: ops: Enforce platform maximum on initial value
  net/mlx5: Apply rate-limiting to high temperature warning
  net/mlx5: Modify LSB bitmask in temperature event to include only the first bit
  ACPI: HED: Always initialize before evged
  PCI: Fix old_size lower bound in calculate_iosize() too
  EDAC/ie31200: work around false positive build warning
  net: pktgen: fix access outside of user given buffer in pktgen_thread_write()
  wifi: rtw88: Fix rtw_init_ht_cap() for RTL8814AU
  scsi: mpt3sas: Send a diag reset if target reset fails
  MIPS: pm-cps: Use per-CPU variables as per-CPU, not per-core
  MIPS: Use arch specific syscall name match function
  cpuidle: menu: Avoid discarding useful information
  x86/nmi: Add an emergency handler in nmi_desc & use it in nmi_shootdown_cpus()
  bonding: report duplicate MAC address in all situations
  net: xgene-v2: remove incorrect ACPI_PTR annotation
  drm/amdkfd: KFD release_work possible circular locking
  net/mlx5: Avoid report two health errors on same syndrome
  fpga: altera-cvp: Increase credit timeout
  drm/mediatek: mtk_dpi: Add checks for reg_h_fre_con existence
  hwmon: (gpio-fan) Add missing mutex locks
  x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2
  net: pktgen: fix mpls maximum labels list parsing
  pinctrl: bcm281xx: Use "unsigned int" instead of bare "unsigned"
  media: cx231xx: set device_caps for 417
  orangefs: Do not truncate file size
  dm cache: prevent BUG_ON by blocking retries on failed device resumes
  media: c8sectpfe: Call of_node_put(i2c_bus) only once in c8sectpfe_probe()
  ARM: tegra: Switch DSI-B clock parent to PLLD on Tegra114
  ieee802154: ca8210: Use proper setters and getters for bitwise types
  rtc: ds1307: stop disabling alarms on probe
  powerpc/prom_init: Fixup missing #size-cells on PowerBook6,7
  mmc: sdhci: Disable SD card clock before changing parameters
  netfilter: conntrack: Bound nf_conntrack sysctl writes
  posix-timers: Add cond_resched() to posix_timer_add() search loop
  xen: Add support for XenServer 6.1 platform device
  dm: restrict dm device size to 2^63-512 bytes
  kbuild: fix argument parsing in scripts/config
  scsi: st: ERASE does not change tape location
  scsi: st: Tighten the page format heuristics with MODE SELECT
  ext4: reorder capability check last
  um: Update min_low_pfn to match changes in uml_reserved
  um: Store full CSGSFS and SS register from mcontext
  btrfs: send: return -ENAMETOOLONG when attempting a path that is too long
  btrfs: avoid linker error in btrfs_find_create_tree_block()
  i2c: pxa: fix call balance of i2c->clk handling routines
  mmc: host: Wait for Vdd to settle on card power off
  libnvdimm/labels: Fix divide error in nd_label_data_init()
  pNFS/flexfiles: Report ENETDOWN as a connection error
  tools/build: Don't pass test log files to linker
  dql: Fix dql->limit value when reset.
  SUNRPC: rpc_clnt_set_transport() must not change the autobind setting
  NFSv4: Treat ENETUNREACH errors as fatal for state recovery
  fbdev: core: tileblit: Implement missing margin clearing for tileblit
  fbdev: fsl-diu-fb: add missing device_remove_file()
  mailbox: use error ret code of of_parse_phandle_with_args()
  kconfig: merge_config: use an empty file as initfile
  cgroup: Fix compilation issue due to cgroup_mutex not being exported
  dma-mapping: avoid potential unused data compilation warning
  scsi: target: iscsi: Fix timeout on deleted connection
  openvswitch: Fix unsafe attribute parsing in output_userspace()
  Input: synaptics - enable InterTouch on TUXEDO InfinityBook Pro 14 v5
  Input: synaptics - enable SMBus for HP Elitebook 850 G1
  clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable()
  phy: renesas: rcar-gen3-usb2: Set timing registers only once
  phy: Fix error handling in tegra_xusb_port_init
  ALSA: es1968: Add error handling for snd_pcm_hw_constraint_pow2()
  ACPI: PPTT: Fix processor subtable walk
  dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when interrupted"
  NFSv4/pnfs: Reset the layout state after a layoutreturn
  NFSv4/pnfs: pnfs_set_layout_stateid() should update the layout cred
  qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd()
  ALSA: sh: SND_AICA should depend on SH_DMA_API
  net: dsa: sja1105: discard incoming frames in BR_STATE_LISTENING
  spi: loopback-test: Do not split 1024-byte hexdumps
  nfs: handle failure of nfs_get_lock_context in unlock path
  RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug
  iio: chemical: sps30: use aligned_s64 for timestamp
  iio: adc: ad7768-1: Fix insufficient alignment of timestamp.
  staging: axis-fifo: Correct handling of tx_fifo_depth for size validation
  staging: axis-fifo: avoid parsing ignored device tree properties
  staging: axis-fifo: Remove hardware resets for user errors
  staging: axis-fifo: replace spinlock with mutex
  platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
  do_umount(): add missing barrier before refcount checks in sync case
  nvme: unblock ctrl state transition for firmware update
  MIPS: Fix MAX_REG_OFFSET
  iio: adc: dln2: Use aligned_s64 for timestamp
  types: Complement the aligned types with signed 64-bit one
  usb: usbtmc: Fix erroneous generic_read ioctl return
  usb: usbtmc: Fix erroneous wait_srq ioctl return
  usb: usbtmc: Fix erroneous get_stb ioctl error returns
  USB: usbtmc: use interruptible sleep in usbtmc_read
  usb: typec: ucsi: displayport: Fix NULL pointer access
  usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT transition
  ocfs2: stop quota recovery before disabling quotas
  ocfs2: implement handshaking with ocfs2 recovery thread
  ocfs2: switch osb->disable_recovery to enum
  module: ensure that kobject_put() is safe for module type kobjects
  xenbus: Use kref to track req lifetime
  usb: uhci-platform: Make the clock really optional
  iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo
  iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo
  iio: adis16201: Correct inclinometer channel resolution
  iio: adc: ad7606: fix serial register access
  staging: iio: adc: ad7816: Correct conditional logic for store mode
  Input: synaptics - enable InterTouch on Dell Precision M3800
  Input: synaptics - enable InterTouch on Dynabook Portege X30L-G
  Input: synaptics - enable InterTouch on Dynabook Portege X30-D
  net: dsa: b53: fix learning on VLAN unaware bridges
  netfilter: ipset: fix region locking in hash types
  sch_htb: make htb_deactivate() idempotent
  scsi: target: Fix WRITE_SAME No Data Buffer crash
  dm: fix copying after src array boundaries
  iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid
  arm64: dts: rockchip: fix iface clock-name on px30 iommus
  usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error handling
  usb: chipidea: ci_hdrc_imx: use dev_err_probe()
  usb: chipidea: imx: refine the error handling for hsic
  usb: chipidea: imx: change hsic power regulator as optional
  irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
  irqchip/gic-v2m: Mark a few functions __init
  irqchip/gic-v2m: Add const to of_device_id
  sch_htb: make htb_qlen_notify() idempotent
  of: module: add buffer overflow check in of_modalias()
  PCI: imx6: Skip controller_id generation logic for i.MX7D
  net: fec: ERR007885 Workaround for conventional TX
  net: lan743x: Fix memleak issue when GSO enabled
  lan743x: fix endianness when accessing descriptors
  lan743x: remove redundant initialization of variable current_head_index
  nvme-tcp: fix premature queue removal and I/O failover
  net: dlink: Correct endianness handling of led_mode
  net_sched: qfq: Fix double list add in class with netem as child qdisc
  net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
  net_sched: drr: Fix double list add in class with netem as child qdisc
  net/mlx5: E-Switch, Initialize MAC Address for Default GID
  tracing: Fix oob write in trace_seq_to_buffer()
  dm: always update the array size in realloc_argv on success
  dm-integrity: fix a warning on invalid table line
  wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()
  amd-xgbe: Fix to ensure dependent features are toggled with RX checksum offload
  parisc: Fix double SIGFPE crash
  i2c: imx-lpi2c: Fix clock count when probe defers
  EDAC/altera: Set DDR and SDMMC interrupt mask before registration
  EDAC/altera: Test the correct error reg offset

 Conflicts:
	Makefile
	drivers/platform/Kconfig
	drivers/platform/Makefile
	include/linux/pid.h

Change-Id: Iab0fd96a23cfe218e945cbf71eef0e87dce204db
2025-09-01 13:17:46 +03:00
Vivekachooz
6c9dd323b9
arm64: configs: denver: Disable CAMERA_CCI_MASTER_CHANGE
Change-Id: I9014c3a95ecffe8fc31d6d1d4a4d1c5090d43517
2025-09-01 09:40:26 +05:30
electimon
67cfbd9fb2
techpack: camera: Add guarding for header struct changes
* We don't build the Camera HAL from source
  so userspace does not need access to
  cam_sensor.h, move it and implement guarding
  for breaking changes for devices with older
  Camera Blobs.

Change-Id: I5a45b83e01ad85752e99035805ee2a6d1f8dfa93
Signed-off-by: electimon <electimon@gmail.com>
2025-09-01 09:40:26 +05:30
Vivekachooz
e7e3836bc3
drivers: power: Guard SMB5_QG_SOH function
* Fixes battery detection for denver

Change-Id: I16087f472b8f06002486141dec23e4a2ef3f9688
2025-09-01 09:40:26 +05:30
Vivekachooz
6be9fdc19a
arm64: configs: denver: Build moto kernel modules
Change-Id: Ia5c0b280ba99999f8713f3192ccead1157183421
2025-09-01 09:40:26 +05:30
Vivekachooz
24599b086c
treewide: Setup inline build for denver modules
Change-Id: Ia804acc4af1e5424aabaf062d8ac897dc214b04d
2025-08-23 09:06:04 +03:00
AnierinB
5bf63f8060 drivers: misc: pen: Send key events on removed/inserted
So that we can wire it up with KeyHandler.

Change-Id: I8ec75d2bddb4864eed2806a84794c59e1ead3b20
Signed-off-by: AnierinB <anierin@evolution-x.org>
2025-08-22 15:47:27 +00:00
AnierinB
e0e2ad134a arm64: configs: milanf: Build moto kernel modules
Change-Id: I63f601c9fba15bbcc415f40c5c49e197d034e4a1
Signed-off-by: AnierinB <anierin@evolution-x.org>
2025-08-22 14:59:56 +00:00
AnierinB
839c9fd502 treewide: Setup inline build for milanf modules
Change-Id: Ie9eab43384d353290b6b8d967af2e87a64a537da
Signed-off-by: AnierinB <anierin@evolution-x.org>
2025-08-22 14:59:34 +00:00
Vitor Hugo Vasconcelos de Oliveira
eabd61eded [Fogo5G NA] DCP fallback to 10W
Ported from (CR) to fogo

According to the conclusion of the D-team,
DCP fallback to 10W

Change-Id: I21fecd38d23e80dd419f72d7fb7483f5493f544c
Reviewed-on: https://gerrit.mot.com/3246149
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Bruno Dias <brunorcd@motorola.com>
Reviewed-by: Andrea dos Santos <andreads@motorola.com>
Submit-Approved: Jira Key
Submit-Approved: Andrea dos Santos <andreads@motorola.com>
2025-08-20 13:34:51 -05:00
Neill Kapron
387dbb9a99 ANDROID: bpf: do not fail to load if log is full
Upstream commit 973c7a0d8a38 ("bpf: fix precision backtracking
instruction iteration") slightly changes the logic in the verifier which
results in the verifier log growing. This results in the log being too
small when loading the filterPowerSupplyEvents BPF program in Android,
and therefore causing the program loading to fail. Because this
program is labeled 'critical', a load failure forces a boot loop.

This BPF program exists on the vendor partition, and therefore we must
maintain the GRF/ treble boundary and modify the kernel logic.

The kernel's bpf log logic is refactored in the 6.4 kernel and
acknowledges the shortcomings of the existing approach which causes the
program load to fail. Instead of backporting the significant changes,
this change simply ignores the fact that the log is full.

For more information see commit 121664093803 ("bpf: Switch BPF verifier
log to be a rotating log by default")

Bug: 432207940
Bug: 433641053
Test: verify pixel 6 boots on a 5.10 kernel including commit 973c7a0d8a38
Change-Id: I35c3d2074dd9b39e44bfdbaf66fa56ec917df0a6
Signed-off-by: Neill Kapron <nkapron@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-29 07:38:45 +00:00
Greg Kroah-Hartman
21224f4b67 Merge tag 'android11-5.4.295_r00' into android11-5.4
This merges the android11-5.4.295_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

*   978aeb58ff Merge 5.4.295 into android11-5.4-lts
|\
| * 39ed7800f9 Linux 5.4.295
| * 5d84869995 scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
| * 64773b3ea0 arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
| * 7b8f3c7217 perf: Fix sample vs do_exit()
| * cc2f923e92 s390/pci: Fix __pcilg_mio_inuser() inline assembly
| * b9dc8b84b9 rtc: test: Fix invalid format specifier.
| * 5c1a34ff5b jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
| * 753f142f7f mm/huge_memory: fix dereferencing invalid pmd migration entry
| * afef20f488 rtc: Make rtc_time64_to_tm() support dates before 1970
| * 31d87dda79 rtc: Improve performance of rtc_time64_to_tm(). Add tests.
| * 59892d18dd xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
| * 78a4b8e379 posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
| * 0fee1b2b48 ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
| * b9ffe75f36 ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
| * 6a4c1721a7 ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
| * fcfccf56f4 net: atm: fix /proc/net/atm/lec handling
| * e91274cc7e net: atm: add lec_mutex
| * 956f149941 calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
| * 3998283e4c tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
| * 4918865254 tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
| * c19c094342 atm: atmtcp: Free invalid length skb in atmtcp_c_send().
| * 2919297b18 mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
| * 0140d3d37f wifi: carl9170: do not ping device which has failed to load firmware
| * ed52e9652b aoe: clean device rq_list in aoedev_downdev()
| * c14c02a712 hwmon: (occ) fix unaligned accesses
| * 738066cdd0 drm/nouveau/bl: increase buffer size to avoid truncate warning
| * 2b9109de64 erofs: remove unused trace event erofs_destroy_inode
| * de2b7d137b ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
| * 6357f20e00 ALSA: hda/intel: Add Thinkpad E15 to PM deny list
| * 82ff0cc5f5 Input: sparcspkr - avoid unannotated fall-through
| * 7a6d6b68db HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
| * 5e0d009921 atm: Revert atm_account_tx() if copy_from_iter_full() fails.
| * a21966e594 selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
| * 48222a330d scsi: s390: zfcp: Ensure synchronous unit_add
| * 8bc89302f3 scsi: storvsc: Increase the timeouts to storvsc_timeout
| * 7e860296d7 jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
| * 337f80f3d5 jffs2: check that raw node were preallocated before writing summary
| * a8b5ea2e30 drivers/rapidio/rio_cm.c: prevent possible heap overwrite
| * a8b7347f5e Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
| * ba649593f3 powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
| * 65594ec9d2 platform/x86: dell_rbu: Stop overwriting data buffer
| * e6ff2952c3 platform: Add Surface platform directory
| * 882ff6d324 Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
| * 77a06908a3 tee: Prevent size calculation wraparound on 32-bit kernels
| * 54edad2d2c ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
| * 41a4c323cc bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
| * df5bd72949 watchdog: da9052_wdt: respect TWDMIN
| * 872607632c i40e: fix MMIO write access to an invalid page in i40e_clear_hw
| * 7e372262cd sock: Correct error checking condition for (assign|release)_proto_idx()
| * ac7bfaa099 scsi: lpfc: Use memcpy() for BIOS version
| * 4f10da4e82 vxlan: Do not treat dst cache initialization errors as fatal
| * 90cba782f8 clk: rockchip: rk3036: mark ddrphy as critical
| * 7c24ad36d5 wifi: mac80211: do not offer a mesh path if forwarding is disabled
| * db876c0a05 net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
| * 7db634f5f6 pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
| * e29b3da920 pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
| * 3168358647 pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
| * ecbd6b4d83 pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
| * de9b7586f9 ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
| * bcaf3c2f06 tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
| * 17c42ca3d1 tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
| * 17813543a3 net: dlink: add synchronization for stats update
| * 8094640cdf sctp: Do not wake readers in __sctp_write_space()
| * c5ea7c6d0a emulex/benet: correct command version selection in be_cmd_get_stats()
| * aa588740e3 i2c: designware: Invoke runtime suspend on quick slave re-registration
| * 9a9fd4025b net: macb: Check return value of dma_set_mask_and_coherent()
| * 7f33b484bb cpufreq: Force sync policy boost with global boost on sysfs update
| * d4292853f7 nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
| * b0d92b9427 media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
| * 45f5a37b58 media: tc358743: ignore video while HPD is low
| * 8a8b77335f drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
| * 0d50231d47 jfs: Fix null-ptr-deref in jfs_ioc_trim
| * c17707f2e7 drm/amdgpu/gfx9: fix CSIB handling
| * 3ba40789f5 drm/amdgpu/gfx8: fix CSIB handling
| * 81af4b34fd jfs: fix array-index-out-of-bounds read in add_missing_indices
| * 9a3b711f78 drm/amdgpu/gfx7: fix CSIB handling
| * d7f3ca1c09 drm/amdgpu/gfx10: fix CSIB handling
| * 8c49859140 drm/msm/a6xx: Increase HFI response timeout
| * 63074eed66 drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
| * ceb810de2d media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
| * 9c60c173ab drm/msm/hdmi: add runtime PM calls to DDC transfer function
| * 08493880ff drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
| * 88dec58190 sunrpc: update nextcheck time when adding new cache entries
| * 255959104f drm/amdgpu/gfx6: fix CSIB handling
| * 081558451e ACPI: battery: negate current when discharging
| * 44050a6c1a PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
| * a9f710fc7a power: supply: bq27xxx: Retrieve again when busy
| * 1e0e629e88 ACPICA: fix acpi parse and parseext cache leaks
| * 2ca55d221b ACPICA: Avoid sequence overread in call to strncmp()
| * 4fa430a8bc ACPICA: fix acpi operand cache leak in dswstate.c
| * 0068025928 iio: adc: ad7606_spi: fix reg write value mask
| * acf5c9d8b3 PCI: Fix lock symmetry in pci_slot_unlock()
| * 300f543231 PCI: Add ACS quirk for Loongson PCIe
| * 0ac228f76f uio_hv_generic: Use correct size for interrupt and monitor pages
| * e66a241cb7 regulator: max14577: Add error check for max14577_read_reg()
| * 39fe75f00f mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
| * 34d5ea7ee0 staging: iio: ad5933: Correct settling cycles encoding per datasheet
| * 119766de49 net: ch9200: fix uninitialised access during mii_nway_restart
| * d064c68781 ftrace: Fix UAF when lookup kallsym after ftrace disabled
| * 92311f8dfd dm-mirror: fix a tiny race condition
| * 3b443407da mtd: nand: sunxi: Add randomizer configuration before randomizer enable
| * b1f30e7c7d mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
| * b36ad2ddc2 mm: fix ratelimit_pages update error in dirty_ratio_handler()
| * 5f1e1573bf ipc: fix to protect IPCS lookups using RCU
| * 6a5cda7fd5 parisc: fix building with gcc-15
| * e44532b1c3 vgacon: Add check for vc_origin address range in vgacon_scroll()
| * ee20216f12 fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
| * 0d02410db5 EDAC/altera: Use correct write width with the INTTEST register
| * a514fca2b8 NFC: nci: uart: Set tty->disc_data only in success path
| * d9a55869d8 f2fs: prevent kernel warning due to negative i_nlink from corrupted image
| * c1b9d140b0 Input: ims-pcu - check record size in ims_pcu_flash_firmware()
| * 922200f03b ext4: fix calculation of credits for extent tree modification
| * d3dfc60efd ext4: inline: fix len overflow in ext4_prepare_inline_data
| * e5d5647b7b bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
| * 67d66a5e45 ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
| * 175925abd5 ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
| * ee141706e7 media: v4l2-dev: fix error handling in __video_register_device()
| * 658029a3c8 media: gspca: Add error handling for stv06xx_read_sensor()
| * b51ce65c44 wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
| * bf78a2706c nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
| * 12134f79e5 wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
| * aad09bbe46 gfs2: move msleep to sleepable context
| * 64d0e07a9b configfs: Do not override creating attribute file failure in populate_attrs()
| * c50b9bb30c net: usb: aqc111: debug info before sanitation
| * 2186f01c75 calipso: unlock rcu before returning -EAFNOSUPPORT
| * bddb807958 xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
| * b2ce37d86d usb: Flush altsetting 0 endpoints before reinitializating them after reset.
| * ae57ce58ac fs/filesystems: Fix potential unsigned integer underflow in fs_name()
| * ff70bd8ff4 net/mdiobus: Fix potential out-of-bounds read/write access
| * f4c6337da9 drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
| * d3e3345645 drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
| * 92b7545695 MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
| * c33417f3b8 x86/boot/compressed: prefer cc-option for CFLAGS additions
| * 38c9d4f8e6 net: mdio: C22 is now optional, EOPNOTSUPP if not provided
| * da1f38bc18 net_sched: tbf: fix a race in tbf_change()
| * 2790c4ec48 net_sched: red: fix a race in __red_change()
| * 53d11560e9 net_sched: prio: fix a race in prio_tune()
| * 21498209cb net/mlx5: Fix return value when searching for existing flow group
| * 2fa390ee36 net/mlx5: Wait for inactive autogroups
| * 6ab93dcedc i40e: retry VFLR handling if there is ongoing VF reset
| * 4b4c8fd192 i40e: return false from i40e_reset_vf if reset is in progress
| * c337efb20d net_sched: sch_sfq: fix a potential crash on gso_skb handling
| * b076002838 scsi: iscsi: Fix incorrect error path labels for flashnode operations
| * 72c14aed68 NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
| * d2211e6e34 NFSD: Fix ia_size underflow
| * 69aff1b73c Input: synaptics-rmi - fix crash with unsupported versions of F34
| * b475d189f4 Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
| * eab11dcd6a pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
| * 787937c4e3 do_change_type(): refuse to operate on unmounted/not ours mounts
| * 36d91620a6 PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
| * b0122774ab ice: create new Tx scheduler nodes for new queues only
| * 737f13ac66 Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
| * 589c0971af net/mlx4_en: Prevent potential integer overflow calculating Hz
| * 85ae8372cd vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
| * a05ebe384c serial: Fix potential null-ptr-deref in mlb_usio_probe()
| * 095cc0b588 usb: renesas_usbhs: Reorder clock handling and power management in probe
| * 55d4b2734f rtc: Fix offset calculation for .start_secs < 0
| * 5023b76466 rtc: sh: assign correct interrupts with DT
| * a972ec94c3 perf record: Fix incorrect --user-regs comments
| * eed18824a1 perf tests switch-tracking: Fix timestamp comparison
| * 49d0662fea mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
| * 24358eb471 mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
| * 7b44dbda2e rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
| * 0ea2f7e9e3 perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
| * 43fe88b963 perf ui browser hists: Set actions->thread before calling do_zoom_thread()
| * 9027ce4c03 fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
| * 2beee9cf83 soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
| * c07c8b4e33 soc: aspeed: lpc: Fix impossible judgment condition
| * 81e5357d47 arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
| * 4e4c974ab4 ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
| * 12e4431e50 bus: fsl-mc: fix double-free on mc_dev
| * 2f11add2ff nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
| * 67d596979f nilfs2: add pointer check for nilfs_direct_propagate()
| * db7096ea16 Squashfs: check return result of sb_min_blocksize
| * 21bcf72e97 ARM: dts: at91: at91sam9263: fix NAND chip selects
| * d5373a0af2 ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
| * ce87f4c192 f2fs: fix to correct check conditions in f2fs_cross_rename
| * ab752ebd97 f2fs: use d_inode(dentry) cleanup dentry->d_inode
| * fc2da88411 calipso: Don't call calipso functions for AF_INET sk.
| * 961ad55974 net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
| * 8c97655275 net: usb: aqc111: fix error handling of usbnet read calls
| * 48af842f4e netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
| * e5ce9df1d6 wifi: ath9k_htc: Abort software beacon handling if disabled
| * 44ebe361ab bpf: Fix WARN() in get_bpf_raw_tp_regs
| * 264a5cf0c4 pinctrl: at91: Fix possible out-of-boundary access
| * ac7fca667b ktls, sockmap: Fix missing uncharge operation
| * 6d1ab8bf2e netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
| * 879d3e0d54 f2fs: clean up w/ fscrypt_is_bounce_page()
| * ceb20ec671 RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
| * a052c91a7d wifi: rtw88: do not ignore hardware read error during DPK
| * 64f82c02df net: ncsi: Fix GCPS 64-bit member variables
| * 49bc7bf38e f2fs: fix to do sanity check on sbi->total_valid_block_count
| * 6a2be4740d drm/tegra: rgb: Fix the unbound reference count
| * 833d0acee9 drm/vkms: Adjust vkms_state->active_planes allocation type
| * e443e547a5 drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
| * 593f0060fb selftests/seccomp: fix syscall_restart test for arm compat
| * 5c1d85c971 firmware: psci: Fix refcount leak in psci_dt_init
| * 629a2417ea m68k: mac: Fix macintosh_config for Mac II
| * dc796cdae6 drm/vmwgfx: Add seqno waiter for sync_files
| * 5571f36f21 spi: sh-msiof: Fix maximum DMA transfer size
| * d79fee3bc1 ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
| * a3c189e7c1 x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
| * 8eb5b081bc PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
| * 80bf28fd62 EDAC/skx_common: Fix general protection fault
| * 8517d3af60 crypto: marvell/cesa - Avoid empty transfer descriptor
| * 32d3e8049a crypto: marvell/cesa - Handle zero-length skcipher requests
| * b48773f888 x86/cpu: Sanitize CPUID(0x80000000) output
| * 5b4da569a2 perf/core: Fix broken throttling when max_samples_per_tick=1
| * 7bf56bd74a gfs2: gfs2_create_inode error handling fix
| * 076d281e90 netfilter: nft_socket: fix sk refcount leaks
| * e49e994cd8 thunderbolt: Do not double dequeue a configuration request
| * 768668e159 usb: usbtmc: Fix timeout value in get_stb
| * 90da5d9876 usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
| * 5db9d2c508 usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
| * 0ce2e102ea pinctrl: armada-37xx: set GPIO output value before setting direction
| * 33b1b38acf pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
| * 26fd2dbc65 tracing: Fix compilation warning on arm32
* b3fbf76488 Merge android11-5.4 into android11-5.4-lts

Change-Id: I5dc61fb04bfb3b890a77c22b1f6312ada2cc46df
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-26 00:43:02 -07:00
Tiffany Yang
5287b166b7 ANDROID: fix kernelci compressed kernel linking
Kernel versions 5.4 and below have several bogus relocations defined in
arch/x86/boot/compressed/head_32.S that cause build errors like the
following when linked with the llvm toolchain:

ld.lld: error: relocation R_386_32 cannot be used against symbol '_bss';
recompile with -fPIC

These errors only show up when linking with LLD because BFD allows
relocations in read-only sections by default. Add "-z notext" to
KBUILD_LDFLAGS to replicate that behavior with ld.lld and unblock
kernelci builds for 5.4 branches.

Bug: 430124841

Change-Id: I393174e264fbc0181abb5ecfd518055a7cb14162
Signed-off-by: Tiffany Yang <ynaffit@google.com>
2025-07-18 11:40:41 -07:00
Michael Bestas
c88830fe05
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-22.2
* sm8350/lineage-20:
  sched/headers: Move 'struct sched_param' out of uapi, to work around glibc/musl breakage
  ANDROID: binder: fix minimum node priority comparison
  ANDROID: 16K: Remove ELF padding entry from map_file ranges
  Linux 5.4.293
  MIPS: cm: Fix warning if MIPS_CM is disabled
  crypto: atmel-sha204a - Set hwrng quality to lowest possible
  comedi: jr3_pci: Fix synchronous deletion of timer
  md/raid1: Add check for missing source disk in process_checks()
  scsi: pm80xx: Set phy_attached to zero when device is gone
  x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline
  ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls
  selftests: ublk: fix test_stripe_04
  udmabuf: fix a buf size overflow issue during udmabuf creation
  KVM: s390: Don't use %pK through tracepoints
  sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP
  ntb: reduce stack usage in idt_scan_mws
  qibfs: fix _another_ leak
  usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()
  dmaengine: dmatest: Fix dmatest waiting less when interrupted
  usb: host: max3421-hcd: Add missing spi_device_id table
  ...

Change-Id: Ic9ed345187af7171604f364f2abc621d180b26a9
2025-06-30 18:20:58 +03:00
Akshay M Joshi
d72ce6ed64 ANDROID: GKI: Update symbol list for Zebra
3 function symbol(s) added
  'void drm_client_dev_hotplug(struct drm_device*)'
  'int drm_edid_to_sad(struct edid*, struct cea_sad**)'
  'int drm_edid_to_speaker_allocation(struct edid*, u8**)'

Bug: 427631467
Change-Id: I0e0dbe03e7d3deaa5bf0b7f42d4cdc3b48577973
Signed-off-by: Akshay M Joshi <aakshayjoshi892@gmail.com>
2025-06-30 05:23:36 -07:00
Kir Kolyshkin
9be1f8739c
sched/headers: Move 'struct sched_param' out of uapi, to work around glibc/musl breakage
Both glibc and musl define 'struct sched_param' in sched.h, while kernel
has it in uapi/linux/sched/types.h, making it cumbersome to use
sched_getattr(2) or sched_setattr(2) from userspace.

For example, something like this:

	#include <sched.h>
	#include <linux/sched/types.h>

	struct sched_attr sa;

will result in "error: redefinition of ‘struct sched_param’" (note the
code doesn't need sched_param at all -- it needs struct sched_attr
plus some stuff from sched.h).

The situation is, glibc is not going to provide a wrapper for
sched_{get,set}attr, thus the need to include linux/sched_types.h
directly, which leads to the above problem.

Thus, the userspace is left with a few sub-par choices when it wants to
use e.g. sched_setattr(2), such as maintaining a copy of struct
sched_attr definition, or using some other ugly tricks.

OTOH, 'struct sched_param' is well known, defined in POSIX, and it won't
be ever changed (as that would break backward compatibility).

So, while 'struct sched_param' is indeed part of the kernel uapi,
exposing it the way it's done now creates an issue, and hiding it
(like this patch does) fixes that issue, hopefully without creating
another one: common userspace software rely on libc headers, and as
for "special" software (like libc), it looks like glibc and musl
do not rely on kernel headers for 'struct sched_param' definition
(but let's Cc their mailing lists in case it's otherwise).

The alternative to this patch would be to move struct sched_attr to,
say, linux/sched.h, or linux/sched/attr.h (the new file).

Oh, and here is the previous attempt to fix the issue:

  https://lore.kernel.org/all/20200528135552.GA87103@google.com/

While I support Linus arguments, the issue is still here
and needs to be fixed.

[ mingo: Linus is right, this shouldn't be needed - but on the other
         hand I agree that this header is not really helpful to
	 user-space as-is. So let's pretend that
	 <uapi/linux/sched/types.h> is only about sched_attr, and
	 call this commit a workaround for user-space breakage
	 that it in reality is ... Also, remove the Fixes tag. ]

Change-Id: I3943f8f4a11a9007ccc392de3ece9e62841e8fcb
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Link: https://lore.kernel.org/r/20230808030357.1213829-1-kolyshkin@gmail.com
2025-06-30 14:38:08 +03:00
Oleg Nesterov
a4761d1472 UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
commit f90fff1e152dedf52b932240ebbd670d83330eca upstream.

If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().

If a concurrent posix_cpu_timer_del() runs at that moment, it won't be
able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or
lock_task_sighand() will fail.

Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.

This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because
exit_task_work() is called before exit_notify(). But the check still
makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail
anyway in this case.

Bug: 425282960
Cc: stable@vger.kernel.org
Reported-by: Benoît Sevens <bsevens@google.com>
Fixes: 0bdd2ed413 ("sched: run_posix_cpu_timers: Don't check ->exit_state, use lock_task_sighand()")
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 78a4b8e379)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2a9b8114abf2647c346e763edee1d424a07e86fe
2025-06-30 11:40:28 +01:00
Greg Kroah-Hartman
978aeb58ff This is the 5.4.295 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmhebGEACgkQONu9yGCS
 aT67mBAAqkBCrkNSqHHQpsl/YybmfDgGonfHeLkNOYp4G44Axp/oytb1bAEhg65A
 oqfTSF67Hr3xjBVEvFMHMnuFO1+xHxkKIy3LUr9o9gjS+6+rEn7U5cYkaHYPNef5
 hN/tPUwf90d2ivpAsTueUu4PegJUJTaux0VqW6PsECKJ/fRF2sdAW7NpGps4zwaw
 +gnxZ7fhWnMLDeSH4d6HAFsVB10AH4sC/WzVMGlXpiS7V8vzM7QjAj3S7NWkOjaX
 fUWmKLecRT6388V+PBH6tr7vwsbFAv83gKVENgFMPKnsfPLTKd3d81TJvWqbU5Dn
 Y+KxG1NWmIUkhlMeqDld51JJCP2JpLxSchqHvJ2TiFJs3gRdkYeQxiDfXHzRsZ+v
 8beqQufcmQFxOyUkWQLGlMR9ACva1IA7hQ4HdTqygDqcQjKcvIYGcy+29PpTBVjj
 +BNs6F8ttK6jQ19IqwhP2AeIObq/DQCtn0xRaOkfAwyODhi2nD7F191ZtmrRwAq7
 ax+hXzNIWkLhvsuG+YLuNXczYbOGKZ56mg8XI+3DQ0KNRUieznsgeXXsjkGbzivn
 uDPWkRtqO48RnZHzlLUzT0Zv7pNCWXscnHEa1LfQ7Effj3G0C74TJWLDRcfSgf0i
 +cdXwJhnHc1ztExtmuNvfk7SHEFRNhjB8Zmdd8weK6SUzH0knPE=
 =jzgM
 -----END PGP SIGNATURE-----

Merge 5.4.295 into android11-5.4-lts

Changes in 5.4.295
	tracing: Fix compilation warning on arm32
	pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
	pinctrl: armada-37xx: set GPIO output value before setting direction
	usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
	usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
	usb: usbtmc: Fix timeout value in get_stb
	thunderbolt: Do not double dequeue a configuration request
	netfilter: nft_socket: fix sk refcount leaks
	gfs2: gfs2_create_inode error handling fix
	perf/core: Fix broken throttling when max_samples_per_tick=1
	x86/cpu: Sanitize CPUID(0x80000000) output
	crypto: marvell/cesa - Handle zero-length skcipher requests
	crypto: marvell/cesa - Avoid empty transfer descriptor
	EDAC/skx_common: Fix general protection fault
	PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
	x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
	ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
	spi: sh-msiof: Fix maximum DMA transfer size
	drm/vmwgfx: Add seqno waiter for sync_files
	m68k: mac: Fix macintosh_config for Mac II
	firmware: psci: Fix refcount leak in psci_dt_init
	selftests/seccomp: fix syscall_restart test for arm compat
	drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
	drm/vkms: Adjust vkms_state->active_planes allocation type
	drm/tegra: rgb: Fix the unbound reference count
	f2fs: fix to do sanity check on sbi->total_valid_block_count
	net: ncsi: Fix GCPS 64-bit member variables
	wifi: rtw88: do not ignore hardware read error during DPK
	RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
	f2fs: clean up w/ fscrypt_is_bounce_page()
	netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
	ktls, sockmap: Fix missing uncharge operation
	pinctrl: at91: Fix possible out-of-boundary access
	bpf: Fix WARN() in get_bpf_raw_tp_regs
	wifi: ath9k_htc: Abort software beacon handling if disabled
	netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
	net: usb: aqc111: fix error handling of usbnet read calls
	net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
	calipso: Don't call calipso functions for AF_INET sk.
	f2fs: use d_inode(dentry) cleanup dentry->d_inode
	f2fs: fix to correct check conditions in f2fs_cross_rename
	ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
	ARM: dts: at91: at91sam9263: fix NAND chip selects
	Squashfs: check return result of sb_min_blocksize
	nilfs2: add pointer check for nilfs_direct_propagate()
	nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
	bus: fsl-mc: fix double-free on mc_dev
	ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
	arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
	soc: aspeed: lpc: Fix impossible judgment condition
	soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
	fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
	perf ui browser hists: Set actions->thread before calling do_zoom_thread()
	perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
	rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
	mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
	mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
	perf tests switch-tracking: Fix timestamp comparison
	perf record: Fix incorrect --user-regs comments
	rtc: sh: assign correct interrupts with DT
	rtc: Fix offset calculation for .start_secs < 0
	usb: renesas_usbhs: Reorder clock handling and power management in probe
	serial: Fix potential null-ptr-deref in mlb_usio_probe()
	vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
	net/mlx4_en: Prevent potential integer overflow calculating Hz
	Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
	ice: create new Tx scheduler nodes for new queues only
	PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
	do_change_type(): refuse to operate on unmounted/not ours mounts
	pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
	Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
	Input: synaptics-rmi - fix crash with unsupported versions of F34
	NFSD: Fix ia_size underflow
	NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
	scsi: iscsi: Fix incorrect error path labels for flashnode operations
	net_sched: sch_sfq: fix a potential crash on gso_skb handling
	i40e: return false from i40e_reset_vf if reset is in progress
	i40e: retry VFLR handling if there is ongoing VF reset
	net/mlx5: Wait for inactive autogroups
	net/mlx5: Fix return value when searching for existing flow group
	net_sched: prio: fix a race in prio_tune()
	net_sched: red: fix a race in __red_change()
	net_sched: tbf: fix a race in tbf_change()
	net: mdio: C22 is now optional, EOPNOTSUPP if not provided
	x86/boot/compressed: prefer cc-option for CFLAGS additions
	MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
	drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
	drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
	net/mdiobus: Fix potential out-of-bounds read/write access
	fs/filesystems: Fix potential unsigned integer underflow in fs_name()
	usb: Flush altsetting 0 endpoints before reinitializating them after reset.
	xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
	calipso: unlock rcu before returning -EAFNOSUPPORT
	net: usb: aqc111: debug info before sanitation
	configfs: Do not override creating attribute file failure in populate_attrs()
	gfs2: move msleep to sleepable context
	wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
	nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
	wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
	media: gspca: Add error handling for stv06xx_read_sensor()
	media: v4l2-dev: fix error handling in __video_register_device()
	ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
	ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
	bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
	ext4: inline: fix len overflow in ext4_prepare_inline_data
	ext4: fix calculation of credits for extent tree modification
	Input: ims-pcu - check record size in ims_pcu_flash_firmware()
	f2fs: prevent kernel warning due to negative i_nlink from corrupted image
	NFC: nci: uart: Set tty->disc_data only in success path
	EDAC/altera: Use correct write width with the INTTEST register
	fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
	vgacon: Add check for vc_origin address range in vgacon_scroll()
	parisc: fix building with gcc-15
	ipc: fix to protect IPCS lookups using RCU
	mm: fix ratelimit_pages update error in dirty_ratio_handler()
	mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
	mtd: nand: sunxi: Add randomizer configuration before randomizer enable
	dm-mirror: fix a tiny race condition
	ftrace: Fix UAF when lookup kallsym after ftrace disabled
	net: ch9200: fix uninitialised access during mii_nway_restart
	staging: iio: ad5933: Correct settling cycles encoding per datasheet
	mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
	regulator: max14577: Add error check for max14577_read_reg()
	uio_hv_generic: Use correct size for interrupt and monitor pages
	PCI: Add ACS quirk for Loongson PCIe
	PCI: Fix lock symmetry in pci_slot_unlock()
	iio: adc: ad7606_spi: fix reg write value mask
	ACPICA: fix acpi operand cache leak in dswstate.c
	ACPICA: Avoid sequence overread in call to strncmp()
	ACPICA: fix acpi parse and parseext cache leaks
	power: supply: bq27xxx: Retrieve again when busy
	PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
	ACPI: battery: negate current when discharging
	drm/amdgpu/gfx6: fix CSIB handling
	sunrpc: update nextcheck time when adding new cache entries
	drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
	drm/msm/hdmi: add runtime PM calls to DDC transfer function
	media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
	drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
	drm/msm/a6xx: Increase HFI response timeout
	drm/amdgpu/gfx10: fix CSIB handling
	drm/amdgpu/gfx7: fix CSIB handling
	jfs: fix array-index-out-of-bounds read in add_missing_indices
	drm/amdgpu/gfx8: fix CSIB handling
	drm/amdgpu/gfx9: fix CSIB handling
	jfs: Fix null-ptr-deref in jfs_ioc_trim
	drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
	media: tc358743: ignore video while HPD is low
	media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
	nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
	cpufreq: Force sync policy boost with global boost on sysfs update
	net: macb: Check return value of dma_set_mask_and_coherent()
	i2c: designware: Invoke runtime suspend on quick slave re-registration
	emulex/benet: correct command version selection in be_cmd_get_stats()
	sctp: Do not wake readers in __sctp_write_space()
	net: dlink: add synchronization for stats update
	tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
	tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
	ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
	pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
	pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
	pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
	pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
	net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
	wifi: mac80211: do not offer a mesh path if forwarding is disabled
	clk: rockchip: rk3036: mark ddrphy as critical
	vxlan: Do not treat dst cache initialization errors as fatal
	scsi: lpfc: Use memcpy() for BIOS version
	sock: Correct error checking condition for (assign|release)_proto_idx()
	i40e: fix MMIO write access to an invalid page in i40e_clear_hw
	watchdog: da9052_wdt: respect TWDMIN
	bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
	ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
	tee: Prevent size calculation wraparound on 32-bit kernels
	Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
	platform: Add Surface platform directory
	platform/x86: dell_rbu: Stop overwriting data buffer
	powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
	Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
	drivers/rapidio/rio_cm.c: prevent possible heap overwrite
	jffs2: check that raw node were preallocated before writing summary
	jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
	scsi: storvsc: Increase the timeouts to storvsc_timeout
	scsi: s390: zfcp: Ensure synchronous unit_add
	selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
	atm: Revert atm_account_tx() if copy_from_iter_full() fails.
	HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
	Input: sparcspkr - avoid unannotated fall-through
	ALSA: hda/intel: Add Thinkpad E15 to PM deny list
	ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
	erofs: remove unused trace event erofs_destroy_inode
	drm/nouveau/bl: increase buffer size to avoid truncate warning
	hwmon: (occ) fix unaligned accesses
	aoe: clean device rq_list in aoedev_downdev()
	wifi: carl9170: do not ping device which has failed to load firmware
	mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
	atm: atmtcp: Free invalid length skb in atmtcp_c_send().
	tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
	tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
	calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
	net: atm: add lec_mutex
	net: atm: fix /proc/net/atm/lec handling
	ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
	ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
	ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
	posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
	xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
	rtc: Improve performance of rtc_time64_to_tm(). Add tests.
	rtc: Make rtc_time64_to_tm() support dates before 1970
	mm/huge_memory: fix dereferencing invalid pmd migration entry
	jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
	rtc: test: Fix invalid format specifier.
	s390/pci: Fix __pcilg_mio_inuser() inline assembly
	perf: Fix sample vs do_exit()
	arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
	scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
	Linux 5.4.295

Change-Id: I44ee88afdff6b4865efac55635f7529a2d9715e8
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-06-30 08:05:33 +00:00
Michael Bestas
691948d565
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-06-01

* tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common:
  ANDROID: binder: fix minimum node priority comparison
  ANDROID: 16K: Remove ELF padding entry from map_file ranges
  Linux 5.4.293
  MIPS: cm: Fix warning if MIPS_CM is disabled
  crypto: atmel-sha204a - Set hwrng quality to lowest possible
  comedi: jr3_pci: Fix synchronous deletion of timer
  md/raid1: Add check for missing source disk in process_checks()
  scsi: pm80xx: Set phy_attached to zero when device is gone
  x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline
  ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls
  selftests: ublk: fix test_stripe_04
  udmabuf: fix a buf size overflow issue during udmabuf creation
  KVM: s390: Don't use %pK through tracepoints
  sched/isolation: Make CONFIG_CPU_ISOLATION depend on CONFIG_SMP
  ntb: reduce stack usage in idt_scan_mws
  qibfs: fix _another_ leak
  usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev()
  dmaengine: dmatest: Fix dmatest waiting less when interrupted
  usb: host: max3421-hcd: Add missing spi_device_id table
  parisc: PDT: Fix missing prototype warning
  clk: check for disabled clock-provider in of_clk_get_hw_from_clkspec()
  crypto: null - Use spin lock instead of mutex
  MIPS: cm: Detect CM quirks from device tree
  USB: VLI disk crashes if LPM is used
  usb: quirks: Add delay init quirk for SanDisk 3.2Gen1 Flash Drive
  usb: quirks: add DELAY_INIT quirk for Silicon Motion Flash Drive
  usb: dwc3: gadget: check that event count does not exceed event buffer length
  USB: OHCI: Add quirk for LS7A OHCI controller (rev 0x02)
  usb: cdns3: Fix deadlock when using NCM gadget
  USB: serial: simple: add OWON HDS200 series oscilloscope support
  USB: serial: option: add Sierra Wireless EM9291
  USB: serial: ftdi_sio: add support for Abacus Electrics Optical Probe
  serial: sifive: lock port in startup()/shutdown() callbacks
  USB: storage: quirk for ADATA Portable HDD CH94
  mcb: fix a double free bug in chameleon_parse_gdd()
  virtio_console: fix missing byte order handling for cols and rows
  net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
  net_sched: hfsc: Fix a UAF vulnerability in class handling
  tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
  net: phy: leds: fix memory leak
  cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
  drm/amd/pm: Prevent division by zero
  misc: pci_endpoint_test: Fix displaying 'irq_type' after 'request_irq' error
  misc: pci_endpoint_test: Use INTX instead of LEGACY
  PCI: Rename PCI_IRQ_LEGACY to PCI_IRQ_INTX
  iio: adc: ad7768-1: Fix conversion result sign
  iio: adc: ad7768-1: Move setting of val a bit later to avoid unnecessary return value check
  net: dsa: mv88e6xxx: fix VTU methods for 6320 family
  media: vim2m: print device name after registering device
  ext4: fix OOB read when checking dotdot dir
  ext4: optimize __ext4_check_dir_entry()
  ext4: don't over-report free space or inodes in statvfs
  ext4: code cleanup for ext4_statfs_project()
  ext4: simplify checking quota limits in ext4_statfs()
  platform/x86: ISST: Correct command storage data length
  MIPS: ds1287: Match ds1287_set_base_clock() function types
  MIPS: cevt-ds1287: Add missing ds1287.h include
  MIPS: dec: Declare which_prom() as static
  virtio-net: Add validation for used length
  RDMA/srpt: Support specifying the srpt_service_guid parameter
  openvswitch: fix lockup on tx to unregistering netdev with carrier
  net: openvswitch: fix race on port output
  mmc: cqhci: Fix checking of CQHCI_HALT state
  nvmet-fc: Remove unused functions
  usb: dwc3: support continuous runtime PM with dual role
  misc: pci_endpoint_test: Fix 'irq_type' to convey the correct type
  misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error
  tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().
  powerpc/prom_init: Use -ffreestanding to avoid a reference to bcmp
  kbuild: Add '-fno-builtin-wcslen'
  cpufreq: Reference count policy in cpufreq_update_limits()
  drm/sti: remove duplicate object names
  drm/nouveau: prime: fix ttm_bo_delayed_delete oops
  drm/repaper: fix integer overflows in repeat functions
  module: sign with sha512 instead of sha1 by default
  perf/x86/intel/uncore: Fix the scale of IIO free running counters on SNR
  perf/x86/intel: Allow to update user space GPRs from PEBS records
  virtiofs: add filesystem context source name check
  riscv: Avoid fortify warning in syscall_get_arguments()
  isofs: Prevent the use of too small fid
  i2c: cros-ec-tunnel: defer probe if parent EC is not present
  hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key
  btrfs: correctly escape subvol in btrfs_show_options()
  nfs: add missing selections of CONFIG_CRC32
  nfs: move nfs_fhandle_hash to common include file
  NFSD: Constify @fh argument of knfsd_fh_hash()
  asus-laptop: Fix an uninitialized variable
  writeback: fix false warning in inode_to_wb()
  net: b53: enable BPDU reception for management port
  net: openvswitch: fix nested key length validation in the set() action
  Revert "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()"
  Bluetooth: btrtl: Prevent potential NULL dereference
  Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for invalid address
  RDMA/usnic: Fix passing zero to PTR_ERR in usnic_ib_pci_probe()
  scsi: iscsi: Fix missing scsi_host_put() in error path
  wifi: wl1251: fix memory leak in wl1251_tx_work
  wifi: mac80211: Purge vif txq in ieee80211_do_stop()
  wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()
  wifi: at76c50x: fix use after free access in at76_disconnect
  HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition
  pwm: mediatek: always use bus clock for PWM on MT7622
  Bluetooth: hci_uart: Fix another race during initialization
  x86/e820: Fix handling of subpage regions when calculating nosave ranges in e820__register_nosave_regions()
  PCI: Fix reference leak in pci_alloc_child_bus()
  of/irq: Fix device node refcount leakages in of_irq_init()
  of/irq: Fix device node refcount leakage in API irq_of_parse_and_map()
  of/irq: Fix device node refcount leakages in of_irq_count()
  ntb: use 64-bit arithmetic for the MSI doorbell mask
  gpio: zynq: Fix wakeup source leaks on device unbind
  ftrace: Add cond_resched() to ftrace_graph_set_hash()
  dm-integrity: set ti->error on memory allocation failure
  crypto: ccp - Fix check for the primary ASP device
  thermal/drivers/rockchip: Add missing rk3328 mapping entry
  sctp: detect and prevent references to a freed transport in sendmsg
  mm: add missing release barrier on PGDAT_RECLAIM_LOCKED unlock
  sparc/mm: disable preemption in lazy mmu mode
  arm64: dts: mediatek: mt8173: Fix disp-pwm compatible string
  mtd: rawnand: Add status chack in r852_ready()
  mtd: inftlcore: Add error check for inftl_read_oob()
  lib: scatterlist: fix sg_split_phys to preserve original scatterlist offsets
  locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class()
  jbd2: remove wrong sb->s_sequence check
  i3c: Add NULL pointer check in i3c_master_queue_ibi()
  ext4: fix off-by-one error in do_split
  wifi: mac80211: fix integer overflow in hwmp_route_info_get()
  net: dsa: mv88e6xxx: workaround RGMII transmit delay erratum for 6320 family
  media: venus: hfi_parser: add check to avoid out of bound access
  media: i2c: ov7251: Introduce 1 ms delay between regulators and en GPIO
  media: i2c: ov7251: Set enable GPIO low in probe
  media: v4l2-dv-timings: prevent possible overflow in v4l2_detect_gtf()
  media: streamzap: prevent processing IR data on URB failure
  mtd: rawnand: brcmnand: fix PM resume warning
  arm64: cputype: Add MIDR_CORTEX_A76AE
  xenfs/xensyms: respect hypervisor's "next" indication
  media: siano: Fix error handling in smsdvb_module_init()
  media: venus: hfi: add check to handle incorrect queue size
  media: venus: hfi: add a check to handle OOB in sfr region
  media: i2c: adv748x: Fix test pattern selection mask
  ext4: don't treat fhandle lookup of ea_inode as FS corruption
  ext4: reject casefold inode flag without casefold feature
  bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags
  bpf: Add endian modifiers to fix endian warnings
  pwm: fsl-ftm: Handle clk_get_rate() returning 0
  pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config()
  pwm: mediatek: Always use bus clock
  fbdev: omapfb: Add 'plane' value check
  drm/mediatek: mtk_dpi: Explicitly manage TVD clock in power on/off
  drm/amdkfd: Fix pqm_destroy_queue race with GPU reset
  drm/amdkfd: clamp queue size to minimum
  drm: panel-orientation-quirks: Add new quirk for GPD Win 2
  drm: panel-orientation-quirks: Add support for AYANEO 2S
  drm: allow encoder mode_set even when connectors change for crtc
  Bluetooth: hci_uart: fix race during initialization
  tracing: fix return value in __ftrace_event_enable_disable for TRACE_REG_UNREGISTER
  net: vlan: don't propagate flags on open
  wifi: mt76: mt76x2u: add TP-Link TL-WDN6200 ID to device table
  scsi: st: Fix array overflow in st_setup()
  ext4: ignore xattrs past end
  ext4: protect ext4_release_dquot against freezing
  ahci: add PCI ID for Marvell 88SE9215 SATA Controller
  ata: libata-eh: Do not use ATAPI DMA for a device limited to PIO mode
  jfs: add sanity check for agwidth in dbMount
  jfs: Prevent copying of nlink with value 0 from disk inode
  fs/jfs: Prevent integer overflow in AG size calculation
  fs/jfs: cast inactags to s64 to prevent potential overflow
  page_pool: avoid infinite loop to schedule delayed worker
  ALSA: usb-audio: Fix CME quirk for UF series keyboards
  ALSA: hda: intel: Fix Optimus when GPU has no sound
  HID: pidff: Fix null pointer dereference in pidff_find_fields
  HID: pidff: Do not send effect envelope if it's empty
  HID: pidff: Convert infinite length from Linux API to PID standard
  xen/mcelog: Add __nonstring annotations for unterminated strings
  perf: arm_pmu: Don't disable counter in armpmu_add()
  x86/cpu: Don't clear X86_FEATURE_LAHF_LM flag in init_amd_k8() on AMD when running in a virtual machine
  pm: cpupower: bench: Prevent NULL dereference on malloc failure
  net: ppp: Add bound checking for skb data on ppp_sync_txmung
  ata: sata_sx4: Add error handling in pdc20621_i2c_read()
  ata: sata_sx4: Drop pointless VPRINTK() calls and convert the remaining ones
  tipc: fix memory leak in tipc_link_xmit
  ata: pata_pxa: Fix potential NULL pointer dereference in pxa_ata_probe()

 Conflicts:
	arch/arm64/include/asm/cputype.h
	drivers/usb/core/quirks.c
	drivers/usb/dwc3/gadget.c

Change-Id: Ie734fa9555f5cdd3575d8b29f71ab946102b5f84
2025-06-30 10:49:17 +03:00
Greg Kroah-Hartman
39ed7800f9 Linux 5.4.295
Link: https://lore.kernel.org/r/20250623130611.896514667@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Link: https://lore.kernel.org/r/20250625085227.279764371@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Kees Cook
5d84869995 scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
commit d8720235d5b5cad86c1f07f65117ef2a96f8bec7 upstream.

Recent fixes to the randstruct GCC plugin allowed it to notice
that this structure is entirely function pointers and is therefore
subject to randomization, but doing so requires that it always use
designated initializers. Explicitly specify the "common" member as being
initialized. Silences:

drivers/scsi/qedf/qedf_main.c:702:9: error: positional initialization of field in 'struct' declared with 'designated_init' attribute [-Werror=designated-init]
  702 |         {
      |         ^

Fixes: 035f7f87b729 ("randstruct: Enable Clang support")
Link: https://lore.kernel.org/r/20250502224156.work.617-kees@kernel.org
Signed-off-by: Kees Cook <kees@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Tengda Wu
64773b3ea0 arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
[ Upstream commit 39dfc971e42d886e7df01371cd1bef505076d84c ]

KASAN reports a stack-out-of-bounds read in regs_get_kernel_stack_nth().

Call Trace:
[   97.283505] BUG: KASAN: stack-out-of-bounds in regs_get_kernel_stack_nth+0xa8/0xc8
[   97.284677] Read of size 8 at addr ffff800089277c10 by task 1.sh/2550
[   97.285732]
[   97.286067] CPU: 7 PID: 2550 Comm: 1.sh Not tainted 6.6.0+ #11
[   97.287032] Hardware name: linux,dummy-virt (DT)
[   97.287815] Call trace:
[   97.288279]  dump_backtrace+0xa0/0x128
[   97.288946]  show_stack+0x20/0x38
[   97.289551]  dump_stack_lvl+0x78/0xc8
[   97.290203]  print_address_description.constprop.0+0x84/0x3c8
[   97.291159]  print_report+0xb0/0x280
[   97.291792]  kasan_report+0x84/0xd0
[   97.292421]  __asan_load8+0x9c/0xc0
[   97.293042]  regs_get_kernel_stack_nth+0xa8/0xc8
[   97.293835]  process_fetch_insn+0x770/0xa30
[   97.294562]  kprobe_trace_func+0x254/0x3b0
[   97.295271]  kprobe_dispatcher+0x98/0xe0
[   97.295955]  kprobe_breakpoint_handler+0x1b0/0x210
[   97.296774]  call_break_hook+0xc4/0x100
[   97.297451]  brk_handler+0x24/0x78
[   97.298073]  do_debug_exception+0xac/0x178
[   97.298785]  el1_dbg+0x70/0x90
[   97.299344]  el1h_64_sync_handler+0xcc/0xe8
[   97.300066]  el1h_64_sync+0x78/0x80
[   97.300699]  kernel_clone+0x0/0x500
[   97.301331]  __arm64_sys_clone+0x70/0x90
[   97.302084]  invoke_syscall+0x68/0x198
[   97.302746]  el0_svc_common.constprop.0+0x11c/0x150
[   97.303569]  do_el0_svc+0x38/0x50
[   97.304164]  el0_svc+0x44/0x1d8
[   97.304749]  el0t_64_sync_handler+0x100/0x130
[   97.305500]  el0t_64_sync+0x188/0x190
[   97.306151]
[   97.306475] The buggy address belongs to stack of task 1.sh/2550
[   97.307461]  and is located at offset 0 in frame:
[   97.308257]  __se_sys_clone+0x0/0x138
[   97.308910]
[   97.309241] This frame has 1 object:
[   97.309873]  [48, 184) 'args'
[   97.309876]
[   97.310749] The buggy address belongs to the virtual mapping at
[   97.310749]  [ffff800089270000, ffff800089279000) created by:
[   97.310749]  dup_task_struct+0xc0/0x2e8
[   97.313347]
[   97.313674] The buggy address belongs to the physical page:
[   97.314604] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x14f69a
[   97.315885] flags: 0x15ffffe00000000(node=1|zone=2|lastcpupid=0xfffff)
[   97.316957] raw: 015ffffe00000000 0000000000000000 dead000000000122 0000000000000000
[   97.318207] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000
[   97.319445] page dumped because: kasan: bad access detected
[   97.320371]
[   97.320694] Memory state around the buggy address:
[   97.321511]  ffff800089277b00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   97.322681]  ffff800089277b80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[   97.323846] >ffff800089277c00: 00 00 f1 f1 f1 f1 f1 f1 00 00 00 00 00 00 00 00
[   97.325023]                          ^
[   97.325683]  ffff800089277c80: 00 00 00 00 00 00 00 00 00 f3 f3 f3 f3 f3 f3 f3
[   97.326856]  ffff800089277d00: f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 00 00

This issue seems to be related to the behavior of some gcc compilers and
was also fixed on the s390 architecture before:

 commit d93a855c31b7 ("s390/ptrace: Avoid KASAN false positives in regs_get_kernel_stack_nth()")

As described in that commit, regs_get_kernel_stack_nth() has confirmed that
`addr` is on the stack, so reading the value at `*addr` should be allowed.
Use READ_ONCE_NOCHECK() helper to silence the KASAN check for this case.

Fixes: 0a8ea52c3e ("arm64: Add HAVE_REGS_AND_STACK_ACCESS_API feature")
Signed-off-by: Tengda Wu <wutengda@huaweicloud.com>
Link: https://lore.kernel.org/r/20250604005533.1278992-1-wutengda@huaweicloud.com
[will: Use '*addr' as the argument to READ_ONCE_NOCHECK()]
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:58 +01:00
Peter Zijlstra
7b8f3c7217 perf: Fix sample vs do_exit()
[ Upstream commit 4f6fc782128355931527cefe3eb45338abd8ab39 ]

Baisheng Gao reported an ARM64 crash, which Mark decoded as being a
synchronous external abort -- most likely due to trying to access
MMIO in bad ways.

The crash further shows perf trying to do a user stack sample while in
exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address
space it is trying to access.

It turns out that we stop perf after we tear down the userspace mm; a
receipie for disaster, since perf likes to access userspace for
various reasons.

Flip this order by moving up where we stop perf in do_exit().

Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER
to abort when the current task does not have an mm (exit_mm() makes
sure to set current->mm = NULL; before commencing with the actual
teardown). Such that CPU wide events don't trip on this same problem.

Fixes: c5ebcedb56 ("perf: Add ability to attach user stack dump to sample")
Reported-by: Baisheng Gao <baisheng.gao@unisoc.com>
Suggested-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lkml.kernel.org/r/20250605110815.GQ39944@noisy.programming.kicks-ass.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:58 +01:00
Heiko Carstens
cc2f923e92 s390/pci: Fix __pcilg_mio_inuser() inline assembly
commit c4abe6234246c75cdc43326415d9cff88b7cf06c upstream.

Use "a" constraint for the shift operand of the __pcilg_mio_inuser() inline
assembly. The used "d" constraint allows the compiler to use any general
purpose register for the shift operand, including register zero.

If register zero is used this my result in incorrect code generation:

 8f6:   a7 0a ff f8             ahi     %r0,-8
 8fa:   eb 32 00 00 00 0c       srlg    %r3,%r2,0  <----

If register zero is selected to contain the shift value, the srlg
instruction ignores the contents of the register and always shifts zero
bits. Therefore use the "a" constraint which does not permit to select
register zero.

Fixes: f058599e22d5 ("s390/pci: Fix s390_mmio_read/write with MIO")
Cc: stable@vger.kernel.org
Reported-by: Niklas Schnelle <schnelle@linux.ibm.com>
Reviewed-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
David Gow
b9dc8b84b9 rtc: test: Fix invalid format specifier.
commit 8a904a3caa88118744062e872ae90f37748a8fd8 upstream.

'days' is a s64 (from div_s64), and so should use a %lld specifier.

This was found by extending KUnit's assertion macros to use gcc's
__printf attribute.

Fixes: 1d1bb12a8b18 ("rtc: Improve performance of rtc_time64_to_tm(). Add tests.")
Signed-off-by: David Gow <davidgow@google.com>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Reviewed-by: Justin Stitt <justinstitt@google.com>
Acked-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Jeongjun Park
5c1a34ff5b jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
commit af98b0157adf6504fade79b3e6cb260c4ff68e37 upstream.

Since handle->h_transaction may be a NULL pointer, so we should change it
to call is_handle_aborted(handle) first before dereferencing it.

And the following data-race was reported in my fuzzer:

==================================================================
BUG: KCSAN: data-race in jbd2_journal_dirty_metadata / jbd2_journal_dirty_metadata

write to 0xffff888011024104 of 4 bytes by task 10881 on cpu 1:
 jbd2_journal_dirty_metadata+0x2a5/0x770 fs/jbd2/transaction.c:1556
 __ext4_handle_dirty_metadata+0xe7/0x4b0 fs/ext4/ext4_jbd2.c:358
 ext4_do_update_inode fs/ext4/inode.c:5220 [inline]
 ext4_mark_iloc_dirty+0x32c/0xd50 fs/ext4/inode.c:5869
 __ext4_mark_inode_dirty+0xe1/0x450 fs/ext4/inode.c:6074
 ext4_dirty_inode+0x98/0xc0 fs/ext4/inode.c:6103
....

read to 0xffff888011024104 of 4 bytes by task 10880 on cpu 0:
 jbd2_journal_dirty_metadata+0xf2/0x770 fs/jbd2/transaction.c:1512
 __ext4_handle_dirty_metadata+0xe7/0x4b0 fs/ext4/ext4_jbd2.c:358
 ext4_do_update_inode fs/ext4/inode.c:5220 [inline]
 ext4_mark_iloc_dirty+0x32c/0xd50 fs/ext4/inode.c:5869
 __ext4_mark_inode_dirty+0xe1/0x450 fs/ext4/inode.c:6074
 ext4_dirty_inode+0x98/0xc0 fs/ext4/inode.c:6103
....

value changed: 0x00000000 -> 0x00000001
==================================================================

This issue is caused by missing data-race annotation for jh->b_modified.
Therefore, the missing annotation needs to be added.

Reported-by: syzbot+de24c3fe3c4091051710@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de24c3fe3c4091051710
Fixes: 6e06ae88ed ("jbd2: speedup jbd2_journal_dirty_metadata()")
Signed-off-by: Jeongjun Park <aha310510@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20250514130855.99010-1-aha310510@gmail.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Cc: stable@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Gavin Guo
753f142f7f mm/huge_memory: fix dereferencing invalid pmd migration entry
commit be6e843fc51a584672dfd9c4a6a24c8cb81d5fb7 upstream.

When migrating a THP, concurrent access to the PMD migration entry during
a deferred split scan can lead to an invalid address access, as
illustrated below.  To prevent this invalid access, it is necessary to
check the PMD migration entry and return early.  In this context, there is
no need to use pmd_to_swp_entry and pfn_swap_entry_to_page to verify the
equality of the target folio.  Since the PMD migration entry is locked, it
cannot be served as the target.

Mailing list discussion and explanation from Hugh Dickins: "An anon_vma
lookup points to a location which may contain the folio of interest, but
might instead contain another folio: and weeding out those other folios is
precisely what the "folio != pmd_folio((*pmd)" check (and the "risk of
replacing the wrong folio" comment a few lines above it) is for."

BUG: unable to handle page fault for address: ffffea60001db008
CPU: 0 UID: 0 PID: 2199114 Comm: tee Not tainted 6.14.0+ #4 NONE
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:split_huge_pmd_locked+0x3b5/0x2b60
Call Trace:
<TASK>
try_to_migrate_one+0x28c/0x3730
rmap_walk_anon+0x4f6/0x770
unmap_folio+0x196/0x1f0
split_huge_page_to_list_to_order+0x9f6/0x1560
deferred_split_scan+0xac5/0x12a0
shrinker_debugfs_scan_write+0x376/0x470
full_proxy_write+0x15c/0x220
vfs_write+0x2fc/0xcb0
ksys_write+0x146/0x250
do_syscall_64+0x6a/0x120
entry_SYSCALL_64_after_hwframe+0x76/0x7e

The bug is found by syzkaller on an internal kernel, then confirmed on
upstream.

Link: https://lkml.kernel.org/r/20250421113536.3682201-1-gavinguo@igalia.com
Link: https://lore.kernel.org/all/20250414072737.1698513-1-gavinguo@igalia.com/
Link: https://lore.kernel.org/all/20250418085802.2973519-1-gavinguo@igalia.com/
Fixes: 84c3fc4e9c ("mm: thp: check pmd migration entry in common path")
Signed-off-by: Gavin Guo <gavinguo@igalia.com>
Acked-by: David Hildenbrand <david@redhat.com>
Acked-by: Hugh Dickins <hughd@google.com>
Acked-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Cc: Florent Revest <revest@google.com>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Miaohe Lin <linmiaohe@huawei.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
[gavin: backport the migration checking logic to __split_huge_pmd]
Signed-off-by: Gavin Guo <gavinguo@igalia.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Alexandre Mergnat
afef20f488 rtc: Make rtc_time64_to_tm() support dates before 1970
commit 7df4cfef8b351fec3156160bedfc7d6d29de4cce upstream.

Conversion of dates before 1970 is still relevant today because these
dates are reused on some hardwares to store dates bigger than the
maximal date that is representable in the device's native format.
This prominently and very soon affects the hardware covered by the
rtc-mt6397 driver that can only natively store dates in the interval
1900-01-01 up to 2027-12-31. So to store the date 2028-01-01 00:00:00
to such a device, rtc_time64_to_tm() must do the right thing for
time=-2208988800.

Signed-off-by: Alexandre Mergnat <amergnat@baylibre.com>
Reviewed-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Link: https://lore.kernel.org/r/20250428-enable-rtc-v4-1-2b2f7e3f9349@baylibre.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Cassio Neri
31d87dda79 rtc: Improve performance of rtc_time64_to_tm(). Add tests.
commit 1d1bb12a8b1805ddeef9793ebeb920179fb0fa38 upstream.

The current implementation of rtc_time64_to_tm() contains unnecessary
loops, branches and look-up tables. The new one uses an arithmetic-based
algorithm appeared in [1] and is approximately 4.3 times faster (YMMV).

The drawback is that the new code isn't intuitive and contains many 'magic
numbers' (not unusual for this type of algorithm). However, [1] justifies
all those numbers and, given this function's history, the code is unlikely
to need much maintenance, if any at all.

Add a KUnit test case that checks every day in a 160,000 years interval
starting on 1970-01-01 against the expected result. Add a new config
RTC_LIB_KUNIT_TEST symbol to give the option to run this test suite.

[1] Neri, Schneider, "Euclidean Affine Functions and Applications to
Calendar Algorithms". https://arxiv.org/abs/2102.06959

Signed-off-by: Cassio Neri <cassio.neri@gmail.com>
Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Link: https://lore.kernel.org/r/20210624201343.85441-1-cassio.neri@gmail.com
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:58 +01:00
Dan Aloni
59892d18dd xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
commit a9c10b5b3b67b3750a10c8b089b2e05f5e176e33 upstream.

If there are failures then we must not leave the non-NULL pointers with
the error value, otherwise `rpcrdma_ep_destroy` gets confused and tries
free them, resulting in an Oops.

Signed-off-by: Dan Aloni <dan.aloni@vastdata.com>
Acked-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com>
[ Larry: backport to 5.4.y. Minor conflict resolved due to missing commit 93aa8e0a9de80
  xprtrdma: Merge struct rpcrdma_ia into struct rpcrdma_ep ]
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Larry Bassel <larry.bassel@oracle.com>
2025-06-27 11:02:58 +01:00
Oleg Nesterov
78a4b8e379 posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
commit f90fff1e152dedf52b932240ebbd670d83330eca upstream.

If an exiting non-autoreaping task has already passed exit_notify() and
calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent
or debugger right after unlock_task_sighand().

If a concurrent posix_cpu_timer_del() runs at that moment, it won't be
able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or
lock_task_sighand() will fail.

Add the tsk->exit_state check into run_posix_cpu_timers() to fix this.

This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because
exit_task_work() is called before exit_notify(). But the check still
makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail
anyway in this case.

Cc: stable@vger.kernel.org
Reported-by: Benoît Sevens <bsevens@google.com>
Fixes: 0bdd2ed413 ("sched: run_posix_cpu_timers: Don't check ->exit_state, use lock_task_sighand()")
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:57 +01:00
Geert Uytterhoeven
0fee1b2b48 ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
commit 929d8490f8790164f5f63671c1c58d6c50411cb2 upstream.

Commit b9bf5612610aa7e3 ("ARM: dts: am335x-bone-common: Increase MDIO
reset deassert time") already increased the MDIO reset deassert delay
from 6.5 to 13 ms, but this may still cause Ethernet PHY probe failures:

    SMSC LAN8710/LAN8720 4a101000.mdio:00: probe with driver SMSC LAN8710/LAN8720 failed with error -5

On BeagleBone Black Rev. C3, ETH_RESETn is controlled by an open-drain
AND gate.  It is pulled high by a 10K resistor, and has a 4.7µF
capacitor to ground, giving an RC time constant of 47ms.  As it takes
0.7RC to charge the capacitor above the threshold voltage of a CMOS
input (VDD/2), the delay should be at least 33ms.  Considering the
typical tolerance of 20% on capacitors, 40ms would be safer.  Add an
additional safety margin and settle for 50ms.

Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Roger Quadros <rogerq@kernel.org>
Link: https://lore.kernel.org/r/9002a58daa1b2983f39815b748ee9d2f8dcc4829.1730366936.git.geert+renesas@glider.be
Signed-off-by: Kevin Hilman <khilman@baylibre.com>
Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:57 +01:00
Colin Foster
b9ffe75f36 ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
commit b9bf5612610aa7e38d58fee16f489814db251c01 upstream.

Prior to commit df16c1c51d81 ("net: phy: mdio_device: Reset device only
when necessary") MDIO reset deasserts were performed twice during boot.
Now that the second deassert is no longer performed, device probe
failures happen due to the change in timing with the following error
message:

SMSC LAN8710/LAN8720: probe of 4a101000.mdio:00 failed with error -5

Restore the original effective timing, which resolves the probe
failures.

Signed-off-by: Colin Foster <colin.foster@in-advantage.com>
Link: https://lore.kernel.org/r/20240531183817.2698445-1-colin.foster@in-advantage.com
Signed-off-by: Kevin Hilman <khilman@baylibre.com>
Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:57 +01:00
Shengyu Qu
6a4c1721a7 ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
commit 623cef652768860bd5f205fb7b741be278585fba upstream.

This patch adds ethernet PHY reset GPIO config for Beaglebone Black
series boards with revision C3. This fixes a random phy startup failure
bug discussed at [1]. The GPIO pin used for reset is not used on older
revisions, so it is ok to apply to all board revisions. The reset timing
was discussed and tested at [2].

[1] https://forum.digikey.com/t/ethernet-device-is-not-detecting-on-ubuntu-20-04-lts-on-bbg/19948
[2] https://forum.beagleboard.org/t/recognizing-a-beaglebone-black-rev-c3-board/31249/

Signed-off-by: Robert Nelson <robertcnelson@gmail.com>
Signed-off-by: Shengyu Qu <wiagn233@outlook.com>
Message-ID: <TY3P286MB26113797A3B2EC7E0348BBB2980FA@TY3P286MB2611.JPNP286.PROD.OUTLOOK.COM>
Signed-off-by: Tony Lindgren <tony@atomide.com>
Signed-off-by: Nobuhiro Iwamatsu (CIP) <nobuhiro1.iwamatsu@toshiba.co.jp>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-06-27 11:02:57 +01:00
Eric Dumazet
fcfccf56f4 net: atm: fix /proc/net/atm/lec handling
[ Upstream commit d03b79f459c7935cff830d98373474f440bd03ae ]

/proc/net/atm/lec must ensure safety against dev_lec[] changes.

It appears it had dev_put() calls without prior dev_hold(),
leading to imbalance and UAF.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Francois Romieu <romieu@fr.zoreil.com> # Minor atm contributor
Link: https://patch.msgid.link/20250618140844.1686882-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:57 +01:00
Eric Dumazet
e91274cc7e net: atm: add lec_mutex
[ Upstream commit d13a3824bfd2b4774b671a75cf766a16637a0e67 ]

syzbot found its way in net/atm/lec.c, and found an error path
in lecd_attach() could leave a dangling pointer in dev_lec[].

Add a mutex to protect dev_lecp[] uses from lecd_attach(),
lec_vcc_attach() and lec_mcast_attach().

Following patch will use this mutex for /proc/net/atm/lec.

BUG: KASAN: slab-use-after-free in lecd_attach net/atm/lec.c:751 [inline]
BUG: KASAN: slab-use-after-free in lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008
Read of size 8 at addr ffff88807c7b8e68 by task syz.1.17/6142

CPU: 1 UID: 0 PID: 6142 Comm: syz.1.17 Not tainted 6.16.0-rc1-syzkaller-00239-g08215f5486ec #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call Trace:
 <TASK>
  __dump_stack lib/dump_stack.c:94 [inline]
  dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
  print_address_description mm/kasan/report.c:408 [inline]
  print_report+0xcd/0x680 mm/kasan/report.c:521
  kasan_report+0xe0/0x110 mm/kasan/report.c:634
  lecd_attach net/atm/lec.c:751 [inline]
  lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008
  do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
  sock_do_ioctl+0x118/0x280 net/socket.c:1190
  sock_ioctl+0x227/0x6b0 net/socket.c:1311
  vfs_ioctl fs/ioctl.c:51 [inline]
  __do_sys_ioctl fs/ioctl.c:907 [inline]
  __se_sys_ioctl fs/ioctl.c:893 [inline]
  __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893
  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
  do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
 </TASK>

Allocated by task 6132:
  kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
  kasan_save_track+0x14/0x30 mm/kasan/common.c:68
  poison_kmalloc_redzone mm/kasan/common.c:377 [inline]
  __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394
  kasan_kmalloc include/linux/kasan.h:260 [inline]
  __do_kmalloc_node mm/slub.c:4328 [inline]
  __kvmalloc_node_noprof+0x27b/0x620 mm/slub.c:5015
  alloc_netdev_mqs+0xd2/0x1570 net/core/dev.c:11711
  lecd_attach net/atm/lec.c:737 [inline]
  lane_ioctl+0x17db/0x23e0 net/atm/lec.c:1008
  do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
  sock_do_ioctl+0x118/0x280 net/socket.c:1190
  sock_ioctl+0x227/0x6b0 net/socket.c:1311
  vfs_ioctl fs/ioctl.c:51 [inline]
  __do_sys_ioctl fs/ioctl.c:907 [inline]
  __se_sys_ioctl fs/ioctl.c:893 [inline]
  __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893
  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
  do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Freed by task 6132:
  kasan_save_stack+0x33/0x60 mm/kasan/common.c:47
  kasan_save_track+0x14/0x30 mm/kasan/common.c:68
  kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:576
  poison_slab_object mm/kasan/common.c:247 [inline]
  __kasan_slab_free+0x51/0x70 mm/kasan/common.c:264
  kasan_slab_free include/linux/kasan.h:233 [inline]
  slab_free_hook mm/slub.c:2381 [inline]
  slab_free mm/slub.c:4643 [inline]
  kfree+0x2b4/0x4d0 mm/slub.c:4842
  free_netdev+0x6c5/0x910 net/core/dev.c:11892
  lecd_attach net/atm/lec.c:744 [inline]
  lane_ioctl+0x1ce8/0x23e0 net/atm/lec.c:1008
  do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159
  sock_do_ioctl+0x118/0x280 net/socket.c:1190
  sock_ioctl+0x227/0x6b0 net/socket.c:1311
  vfs_ioctl fs/ioctl.c:51 [inline]
  __do_sys_ioctl fs/ioctl.c:907 [inline]
  __se_sys_ioctl fs/ioctl.c:893 [inline]
  __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Reported-by: syzbot+8b64dec3affaed7b3af5@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6852c6f6.050a0220.216029.0018.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20250618140844.1686882-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:57 +01:00
Kuniyuki Iwashima
956f149941 calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
[ Upstream commit 10876da918fa1aec0227fb4c67647513447f53a9 ]

syzkaller reported a null-ptr-deref in sock_omalloc() while allocating
a CALIPSO option.  [0]

The NULL is of struct sock, which was fetched by sk_to_full_sk() in
calipso_req_setattr().

Since commit a1a5344ddb ("tcp: avoid two atomic ops for syncookies"),
reqsk->rsk_listener could be NULL when SYN Cookie is returned to its
client, as hinted by the leading SYN Cookie log.

Here are 3 options to fix the bug:

  1) Return 0 in calipso_req_setattr()
  2) Return an error in calipso_req_setattr()
  3) Alaways set rsk_listener

1) is no go as it bypasses LSM, but 2) effectively disables SYN Cookie
for CALIPSO.  3) is also no go as there have been many efforts to reduce
atomic ops and make TCP robust against DDoS.  See also commit 3b24d854cb
("tcp/dccp: do not touch listener sk_refcnt under synflood").

As of the blamed commit, SYN Cookie already did not need refcounting,
and no one has stumbled on the bug for 9 years, so no CALIPSO user will
care about SYN Cookie.

Let's return an error in calipso_req_setattr() and calipso_req_delattr()
in the SYN Cookie case.

This can be reproduced by [1] on Fedora and now connect() of nc times out.

[0]:
TCP: request_sock_TCPv6: Possible SYN flooding on port [::]:20002. Sending cookies.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] PREEMPT SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037]
CPU: 3 UID: 0 PID: 12262 Comm: syz.1.2611 Not tainted 6.14.0 #2
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014
RIP: 0010:read_pnet include/net/net_namespace.h:406 [inline]
RIP: 0010:sock_net include/net/sock.h:655 [inline]
RIP: 0010:sock_kmalloc+0x35/0x170 net/core/sock.c:2806
Code: 89 d5 41 54 55 89 f5 53 48 89 fb e8 25 e3 c6 fd e8 f0 91 e3 00 48 8d 7b 30 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 26 01 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b
RSP: 0018:ffff88811af89038 EFLAGS: 00010216
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffff888105266400
RDX: 0000000000000006 RSI: ffff88800c890000 RDI: 0000000000000030
RBP: 0000000000000050 R08: 0000000000000000 R09: ffff88810526640e
R10: ffffed1020a4cc81 R11: ffff88810526640f R12: 0000000000000000
R13: 0000000000000820 R14: ffff888105266400 R15: 0000000000000050
FS:  00007f0653a07640(0000) GS:ffff88811af80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f863ba096f4 CR3: 00000000163c0005 CR4: 0000000000770ef0
PKRU: 80000000
Call Trace:
 <IRQ>
 ipv6_renew_options+0x279/0x950 net/ipv6/exthdrs.c:1288
 calipso_req_setattr+0x181/0x340 net/ipv6/calipso.c:1204
 calipso_req_setattr+0x56/0x80 net/netlabel/netlabel_calipso.c:597
 netlbl_req_setattr+0x18a/0x440 net/netlabel/netlabel_kapi.c:1249
 selinux_netlbl_inet_conn_request+0x1fb/0x320 security/selinux/netlabel.c:342
 selinux_inet_conn_request+0x1eb/0x2c0 security/selinux/hooks.c:5551
 security_inet_conn_request+0x50/0xa0 security/security.c:4945
 tcp_v6_route_req+0x22c/0x550 net/ipv6/tcp_ipv6.c:825
 tcp_conn_request+0xec8/0x2b70 net/ipv4/tcp_input.c:7275
 tcp_v6_conn_request+0x1e3/0x440 net/ipv6/tcp_ipv6.c:1328
 tcp_rcv_state_process+0xafa/0x52b0 net/ipv4/tcp_input.c:6781
 tcp_v6_do_rcv+0x8a6/0x1a40 net/ipv6/tcp_ipv6.c:1667
 tcp_v6_rcv+0x505e/0x5b50 net/ipv6/tcp_ipv6.c:1904
 ip6_protocol_deliver_rcu+0x17c/0x1da0 net/ipv6/ip6_input.c:436
 ip6_input_finish+0x103/0x180 net/ipv6/ip6_input.c:480
 NF_HOOK include/linux/netfilter.h:314 [inline]
 NF_HOOK include/linux/netfilter.h:308 [inline]
 ip6_input+0x13c/0x6b0 net/ipv6/ip6_input.c:491
 dst_input include/net/dst.h:469 [inline]
 ip6_rcv_finish net/ipv6/ip6_input.c:79 [inline]
 ip6_rcv_finish+0xb6/0x490 net/ipv6/ip6_input.c:69
 NF_HOOK include/linux/netfilter.h:314 [inline]
 NF_HOOK include/linux/netfilter.h:308 [inline]
 ipv6_rcv+0xf9/0x490 net/ipv6/ip6_input.c:309
 __netif_receive_skb_one_core+0x12e/0x1f0 net/core/dev.c:5896
 __netif_receive_skb+0x1d/0x170 net/core/dev.c:6009
 process_backlog+0x41e/0x13b0 net/core/dev.c:6357
 __napi_poll+0xbd/0x710 net/core/dev.c:7191
 napi_poll net/core/dev.c:7260 [inline]
 net_rx_action+0x9de/0xde0 net/core/dev.c:7382
 handle_softirqs+0x19a/0x770 kernel/softirq.c:561
 do_softirq.part.0+0x36/0x70 kernel/softirq.c:462
 </IRQ>
 <TASK>
 do_softirq arch/x86/include/asm/preempt.h:26 [inline]
 __local_bh_enable_ip+0xf1/0x110 kernel/softirq.c:389
 local_bh_enable include/linux/bottom_half.h:33 [inline]
 rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline]
 __dev_queue_xmit+0xc2a/0x3c40 net/core/dev.c:4679
 dev_queue_xmit include/linux/netdevice.h:3313 [inline]
 neigh_hh_output include/net/neighbour.h:523 [inline]
 neigh_output include/net/neighbour.h:537 [inline]
 ip6_finish_output2+0xd69/0x1f80 net/ipv6/ip6_output.c:141
 __ip6_finish_output net/ipv6/ip6_output.c:215 [inline]
 ip6_finish_output+0x5dc/0xd60 net/ipv6/ip6_output.c:226
 NF_HOOK_COND include/linux/netfilter.h:303 [inline]
 ip6_output+0x24b/0x8d0 net/ipv6/ip6_output.c:247
 dst_output include/net/dst.h:459 [inline]
 NF_HOOK include/linux/netfilter.h:314 [inline]
 NF_HOOK include/linux/netfilter.h:308 [inline]
 ip6_xmit+0xbbc/0x20d0 net/ipv6/ip6_output.c:366
 inet6_csk_xmit+0x39a/0x720 net/ipv6/inet6_connection_sock.c:135
 __tcp_transmit_skb+0x1a7b/0x3b40 net/ipv4/tcp_output.c:1471
 tcp_transmit_skb net/ipv4/tcp_output.c:1489 [inline]
 tcp_send_syn_data net/ipv4/tcp_output.c:4059 [inline]
 tcp_connect+0x1c0c/0x4510 net/ipv4/tcp_output.c:4148
 tcp_v6_connect+0x156c/0x2080 net/ipv6/tcp_ipv6.c:333
 __inet_stream_connect+0x3a7/0xed0 net/ipv4/af_inet.c:677
 tcp_sendmsg_fastopen+0x3e2/0x710 net/ipv4/tcp.c:1039
 tcp_sendmsg_locked+0x1e82/0x3570 net/ipv4/tcp.c:1091
 tcp_sendmsg+0x2f/0x50 net/ipv4/tcp.c:1358
 inet6_sendmsg+0xb9/0x150 net/ipv6/af_inet6.c:659
 sock_sendmsg_nosec net/socket.c:718 [inline]
 __sock_sendmsg+0xf4/0x2a0 net/socket.c:733
 __sys_sendto+0x29a/0x390 net/socket.c:2187
 __do_sys_sendto net/socket.c:2194 [inline]
 __se_sys_sendto net/socket.c:2190 [inline]
 __x64_sys_sendto+0xe1/0x1c0 net/socket.c:2190
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xc3/0x1d0 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f06553c47ed
Code: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f0653a06fc8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c
RAX: ffffffffffffffda RBX: 00007f0655605fa0 RCX: 00007f06553c47ed
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 000000000000000b
RBP: 00007f065545db38 R08: 0000200000000140 R09: 000000000000001c
R10: f7384d4ea84b01bd R11: 0000000000000246 R12: 0000000000000000
R13: 00007f0655605fac R14: 00007f0655606038 R15: 00007f06539e7000
 </TASK>
Modules linked in:

[1]:
dnf install -y selinux-policy-targeted policycoreutils netlabel_tools procps-ng nmap-ncat
mount -t selinuxfs none /sys/fs/selinux
load_policy
netlabelctl calipso add pass doi:1
netlabelctl map del default
netlabelctl map add default address:::1 protocol:calipso,1
sysctl net.ipv4.tcp_syncookies=2
nc -l ::1 80 &
nc ::1 80

Fixes: e1adea9270 ("calipso: Allow request sockets to be relabelled by the lsm.")
Reported-by: syzkaller <syzkaller@googlegroups.com>
Reported-by: John Cheung <john.cs.hey@gmail.com>
Closes: https://lore.kernel.org/netdev/CAP=Rh=MvfhrGADy+-WJiftV2_WzMH4VEhEFmeT28qY+4yxNu4w@mail.gmail.com/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Acked-by: Paul Moore <paul@paul-moore.com>
Link: https://patch.msgid.link/20250617224125.17299-1-kuni1840@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-06-27 11:02:57 +01:00