Commit graph android_kernel_motorola_sm6375/tools/testing
Author SHA1 Message Date
KP Singh
8bcac7418f
BACKPORT: bpf: Renames in preparation for bpf_local_storage
A purely mechanical change to split the renaming from the actual
generalization.

Flags/consts:

  SK_STORAGE_CREATE_FLAG_MASK	BPF_LOCAL_STORAGE_CREATE_FLAG_MASK
  BPF_SK_STORAGE_CACHE_SIZE	BPF_LOCAL_STORAGE_CACHE_SIZE
  MAX_VALUE_SIZE		BPF_LOCAL_STORAGE_MAX_VALUE_SIZE

Structs:

  bucket			bpf_local_storage_map_bucket
  bpf_sk_storage_map		bpf_local_storage_map
  bpf_sk_storage_data		bpf_local_storage_data
  bpf_sk_storage_elem		bpf_local_storage_elem
  bpf_sk_storage		bpf_local_storage

The "sk" member in bpf_local_storage is also updated to "owner"
in preparation for changing the type to void * in a subsequent patch.

Functions:

  selem_linked_to_sk			selem_linked_to_storage
  selem_alloc				bpf_selem_alloc
  __selem_unlink_sk			bpf_selem_unlink_storage_nolock
  __selem_link_sk			bpf_selem_link_storage_nolock
  selem_unlink_sk			__bpf_selem_unlink_storage
  sk_storage_update			bpf_local_storage_update
  __sk_storage_lookup			bpf_local_storage_lookup
  bpf_sk_storage_map_free		bpf_local_storage_map_free
  bpf_sk_storage_map_alloc		bpf_local_storage_map_alloc
  bpf_sk_storage_map_alloc_check	bpf_local_storage_map_alloc_check
  bpf_sk_storage_map_check_btf		bpf_local_storage_map_check_btf

Change-Id: I282ab51390db10efbfccf54cd25896abbd6582cb
Signed-off-by: KP Singh <kpsingh@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200825182919.1118197-2-kpsingh@chromium.org
2026-01-14 18:12:19 -08:00
Andrey Ignatov
d3a41db5ea
UPSTREAM: selftests/bpf: Test access to bpf map pointer
Add selftests to test access to map pointers from bpf program for all
map types except struct_ops (that one would need additional work).

verifier test focuses mostly on scenarios that must be rejected.

prog_tests test focuses on accessing multiple fields both scalar and a
nested struct from bpf program and verifies that those fields have
expected values.

Change-Id: I4b0c119c8d686871551bbc4011e11cc68858f775
Signed-off-by: Andrey Ignatov <rdna@fb.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/139a6a17f8016491e39347849b951525335c6eb4.1592600985.git.rdna@fb.com
2026-01-14 18:12:19 -08:00
Dmitry Yakunin
64e25a5d35
UPSTREAM: bpf: Allow to specify ifindex for skb in bpf_prog_test_run_skb
Now skb->dev is unconditionally set to the loopback device in current net
namespace. But if we want to test bpf program which contains code branch
based on ifindex condition (eg filters out localhost packets) it is useful
to allow specifying of ifindex from userspace. This patch adds such option
through ctx_in (__sk_buff) parameter.

Change-Id: Ia56479984ad24f3e0deb878c30dc42a6377bfb0b
Signed-off-by: Dmitry Yakunin <zeil@yandex-team.ru>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20200803090545.82046-3-zeil@yandex-team.ru
2026-01-14 18:12:12 -08:00
Jesper Dangaard Brouer
6312f5960f
UPSTREAM: bpf: Selftests and tools use struct bpf_devmap_val from uapi
Sync tools uapi bpf.h header file and update selftests that use
struct bpf_devmap_val.

Change-Id: I04bd0cb51e59ec3d23573df3c74f02ffaabe768b
Signed-off-by: Jesper Dangaard Brouer <brouer@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/159170951195.2102545.1833108712124273987.stgit@firesoul
2026-01-14 18:12:03 -08:00
David Ahern
b49eb38074
UPSTREAM: selftest: Add tests for XDP programs in devmap entries
Add tests to verify ability to add an XDP program to a
entry in a DEVMAP.

Add negative tests to show DEVMAP programs can not be
attached to devices as a normal XDP program, and accesses
to egress_ifindex require BPF_XDP_DEVMAP attach type.

Change-Id: Ic91c2835212b87d397dc33161c718619f26a8ac7
Signed-off-by: David Ahern <dsahern@kernel.org>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Link: https://lore.kernel.org/bpf/20200529220716.75383-6-dsahern@kernel.org
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-01-14 18:12:03 -08:00
Andrey Ignatov
db1162f1dd
UPSTREAM: bpf: Support access to bpf map fields
There are multiple use-cases when it's convenient to have access to bpf
map fields, both `struct bpf_map` and map type specific struct-s such as
`struct bpf_array`, `struct bpf_htab`, etc.

For example while working with sock arrays it can be necessary to
calculate the key based on map->max_entries (some_hash % max_entries).
Currently this is solved by communicating max_entries via "out-of-band"
channel, e.g. via additional map with known key to get info about target
map. That works, but is not very convenient and error-prone while
working with many maps.

In other cases necessary data is dynamic (i.e. unknown at loading time)
and it's impossible to get it at all. For example while working with a
hash table it can be convenient to know how much capacity is already
used (bpf_htab.count.counter for BPF_F_NO_PREALLOC case).

At the same time kernel knows this info and can provide it to bpf
program.

Fill this gap by adding support to access bpf map fields from bpf
program for both `struct bpf_map` and map type specific fields.

Support is implemented via btf_struct_access() so that a user can define
their own `struct bpf_map` or map type specific struct in their program
with only necessary fields and preserve_access_index attribute, cast a
map to this struct and use a field.

For example:

	struct bpf_map {
		__u32 max_entries;
	} __attribute__((preserve_access_index));

	struct bpf_array {
		struct bpf_map map;
		__u32 elem_size;
	} __attribute__((preserve_access_index));

	struct {
		__uint(type, BPF_MAP_TYPE_ARRAY);
		__uint(max_entries, 4);
		__type(key, __u32);
		__type(value, __u32);
	} m_array SEC(".maps");

	SEC("cgroup_skb/egress")
	int cg_skb(void *ctx)
	{
		struct bpf_array *array = (struct bpf_array *)&m_array;
		struct bpf_map *map = (struct bpf_map *)&m_array;

		/* .. use map->max_entries or array->map.max_entries .. */
	}

Similarly to other btf_struct_access() use-cases (e.g. struct tcp_sock
in net/ipv4/bpf_tcp_ca.c) the patch allows access to any fields of
corresponding struct. Only reading from map fields is supported.

For btf_struct_access() to work there should be a way to know btf id of
a struct that corresponds to a map type. To get btf id there should be a
way to get a stringified name of map-specific struct, such as
"bpf_array", "bpf_htab", etc for a map type. Two new fields are added to
`struct bpf_map_ops` to handle it:
* .map_btf_name keeps a btf name of a struct returned by map_alloc();
* .map_btf_id is used to cache btf id of that struct.

To make btf ids calculation cheaper they're calculated once while
preparing btf_vmlinux and cached same way as it's done for btf_id field
of `struct bpf_func_proto`

While calculating btf ids, struct names are NOT checked for collision.
Collisions will be checked as a part of the work to prepare btf ids used
in verifier in compile time that should land soon. The only known
collision for `struct bpf_htab` (kernel/bpf/hashtab.c vs
net/core/sock_map.c) was fixed earlier.

Both new fields .map_btf_name and .map_btf_id must be set for a map type
for the feature to work. If neither is set for a map type, verifier will
return ENOTSUPP on a try to access map_ptr of corresponding type. If
just one of them set, it's verifier misconfiguration.

Only `struct bpf_array` for BPF_MAP_TYPE_ARRAY and `struct bpf_htab` for
BPF_MAP_TYPE_HASH are supported by this patch. Other map types will be
supported separately.

The feature is available only for CONFIG_DEBUG_INFO_BTF=y and gated by
perfmon_capable() so that unpriv programs won't have access to bpf map
fields.

Change-Id: Ibd44c4fe4f296e0488dff536e1ec56e90d542f56
Signed-off-by: Andrey Ignatov <rdna@fb.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/6479686a0cd1e9067993df57b4c3eef0e276fec9.1592600985.git.rdna@fb.com
2026-01-14 17:50:46 -08:00
Andrii Nakryiko
84e1e40542
UPSTREAM: bpf: Implement BPF ring buffer and verifier support for it
This commit adds a new MPSC ring buffer implementation into BPF ecosystem,
which allows multiple CPUs to submit data to a single shared ring buffer. On
the consumption side, only single consumer is assumed.

Motivation
----------
There are two distinctive motivators for this work, which are not satisfied by
existing perf buffer, which prompted creation of a new ring buffer
implementation.
  - more efficient memory utilization by sharing ring buffer across CPUs;
  - preserving ordering of events that happen sequentially in time, even
  across multiple CPUs (e.g., fork/exec/exit events for a task).

These two problems are independent, but perf buffer fails to satisfy both.
Both are a result of a choice to have per-CPU perf ring buffer.  Both can be
also solved by having an MPSC implementation of ring buffer. The ordering
problem could technically be solved for perf buffer with some in-kernel
counting, but given the first one requires an MPSC buffer, the same solution
would solve the second problem automatically.

Semantics and APIs
------------------
Single ring buffer is presented to BPF programs as an instance of BPF map of
type BPF_MAP_TYPE_RINGBUF. Two other alternatives considered, but ultimately
rejected.

One way would be to, similar to BPF_MAP_TYPE_PERF_EVENT_ARRAY, make
BPF_MAP_TYPE_RINGBUF could represent an array of ring buffers, but not enforce
"same CPU only" rule. This would be more familiar interface compatible with
existing perf buffer use in BPF, but would fail if application needed more
advanced logic to lookup ring buffer by arbitrary key. HASH_OF_MAPS addresses
this with current approach. Additionally, given the performance of BPF
ringbuf, many use cases would just opt into a simple single ring buffer shared
among all CPUs, for which current approach would be an overkill.

Another approach could introduce a new concept, alongside BPF map, to
represent generic "container" object, which doesn't necessarily have key/value
interface with lookup/update/delete operations. This approach would add a lot
of extra infrastructure that has to be built for observability and verifier
support. It would also add another concept that BPF developers would have to
familiarize themselves with, new syntax in libbpf, etc. But then would really
provide no additional benefits over the approach of using a map.
BPF_MAP_TYPE_RINGBUF doesn't support lookup/update/delete operations, but so
doesn't few other map types (e.g., queue and stack; array doesn't support
delete, etc).

The approach chosen has an advantage of re-using existing BPF map
infrastructure (introspection APIs in kernel, libbpf support, etc), being
familiar concept (no need to teach users a new type of object in BPF program),
and utilizing existing tooling (bpftool). For common scenario of using
a single ring buffer for all CPUs, it's as simple and straightforward, as
would be with a dedicated "container" object. On the other hand, by being
a map, it can be combined with ARRAY_OF_MAPS and HASH_OF_MAPS map-in-maps to
implement a wide variety of topologies, from one ring buffer for each CPU
(e.g., as a replacement for perf buffer use cases), to a complicated
application hashing/sharding of ring buffers (e.g., having a small pool of
ring buffers with hashed task's tgid being a look up key to preserve order,
but reduce contention).

Key and value sizes are enforced to be zero. max_entries is used to specify
the size of ring buffer and has to be a power of 2 value.

There are a bunch of similarities between perf buffer
(BPF_MAP_TYPE_PERF_EVENT_ARRAY) and new BPF ring buffer semantics:
  - variable-length records;
  - if there is no more space left in ring buffer, reservation fails, no
    blocking;
  - memory-mappable data area for user-space applications for ease of
    consumption and high performance;
  - epoll notifications for new incoming data;
  - but still the ability to do busy polling for new data to achieve the
    lowest latency, if necessary.

BPF ringbuf provides two sets of APIs to BPF programs:
  - bpf_ringbuf_output() allows to *copy* data from one place to a ring
    buffer, similarly to bpf_perf_event_output();
  - bpf_ringbuf_reserve()/bpf_ringbuf_commit()/bpf_ringbuf_discard() APIs
    split the whole process into two steps. First, a fixed amount of space is
    reserved. If successful, a pointer to a data inside ring buffer data area
    is returned, which BPF programs can use similarly to a data inside
    array/hash maps. Once ready, this piece of memory is either committed or
    discarded. Discard is similar to commit, but makes consumer ignore the
    record.

bpf_ringbuf_output() has disadvantage of incurring extra memory copy, because
record has to be prepared in some other place first. But it allows to submit
records of the length that's not known to verifier beforehand. It also closely
matches bpf_perf_event_output(), so will simplify migration significantly.

bpf_ringbuf_reserve() avoids the extra copy of memory by providing a memory
pointer directly to ring buffer memory. In a lot of cases records are larger
than BPF stack space allows, so many programs have use extra per-CPU array as
a temporary heap for preparing sample. bpf_ringbuf_reserve() avoid this needs
completely. But in exchange, it only allows a known constant size of memory to
be reserved, such that verifier can verify that BPF program can't access
memory outside its reserved record space. bpf_ringbuf_output(), while slightly
slower due to extra memory copy, covers some use cases that are not suitable
for bpf_ringbuf_reserve().

The difference between commit and discard is very small. Discard just marks
a record as discarded, and such records are supposed to be ignored by consumer
code. Discard is useful for some advanced use-cases, such as ensuring
all-or-nothing multi-record submission, or emulating temporary malloc()/free()
within single BPF program invocation.

Each reserved record is tracked by verifier through existing
reference-tracking logic, similar to socket ref-tracking. It is thus
impossible to reserve a record, but forget to submit (or discard) it.

bpf_ringbuf_query() helper allows to query various properties of ring buffer.
Currently 4 are supported:
  - BPF_RB_AVAIL_DATA returns amount of unconsumed data in ring buffer;
  - BPF_RB_RING_SIZE returns the size of ring buffer;
  - BPF_RB_CONS_POS/BPF_RB_PROD_POS returns current logical possition of
    consumer/producer, respectively.
Returned values are momentarily snapshots of ring buffer state and could be
off by the time helper returns, so this should be used only for
debugging/reporting reasons or for implementing various heuristics, that take
into account highly-changeable nature of some of those characteristics.

One such heuristic might involve more fine-grained control over poll/epoll
notifications about new data availability in ring buffer. Together with
BPF_RB_NO_WAKEUP/BPF_RB_FORCE_WAKEUP flags for output/commit/discard helpers,
it allows BPF program a high degree of control and, e.g., more efficient
batched notifications. Default self-balancing strategy, though, should be
adequate for most applications and will work reliable and efficiently already.

Design and implementation
-------------------------
This reserve/commit schema allows a natural way for multiple producers, either
on different CPUs or even on the same CPU/in the same BPF program, to reserve
independent records and work with them without blocking other producers. This
means that if BPF program was interruped by another BPF program sharing the
same ring buffer, they will both get a record reserved (provided there is
enough space left) and can work with it and submit it independently. This
applies to NMI context as well, except that due to using a spinlock during
reservation, in NMI context, bpf_ringbuf_reserve() might fail to get a lock,
in which case reservation will fail even if ring buffer is not full.

The ring buffer itself internally is implemented as a power-of-2 sized
circular buffer, with two logical and ever-increasing counters (which might
wrap around on 32-bit architectures, that's not a problem):
  - consumer counter shows up to which logical position consumer consumed the
    data;
  - producer counter denotes amount of data reserved by all producers.

Each time a record is reserved, producer that "owns" the record will
successfully advance producer counter. At that point, data is still not yet
ready to be consumed, though. Each record has 8 byte header, which contains
the length of reserved record, as well as two extra bits: busy bit to denote
that record is still being worked on, and discard bit, which might be set at
commit time if record is discarded. In the latter case, consumer is supposed
to skip the record and move on to the next one. Record header also encodes
record's relative offset from the beginning of ring buffer data area (in
pages). This allows bpf_ringbuf_commit()/bpf_ringbuf_discard() to accept only
the pointer to the record itself, without requiring also the pointer to ring
buffer itself. Ring buffer memory location will be restored from record
metadata header. This significantly simplifies verifier, as well as improving
API usability.

Producer counter increments are serialized under spinlock, so there is
a strict ordering between reservations. Commits, on the other hand, are
completely lockless and independent. All records become available to consumer
in the order of reservations, but only after all previous records where
already committed. It is thus possible for slow producers to temporarily hold
off submitted records, that were reserved later.

Reservation/commit/consumer protocol is verified by litmus tests in
Documentation/litmus-test/bpf-rb.

One interesting implementation bit, that significantly simplifies (and thus
speeds up as well) implementation of both producers and consumers is how data
area is mapped twice contiguously back-to-back in the virtual memory. This
allows to not take any special measures for samples that have to wrap around
at the end of the circular buffer data area, because the next page after the
last data page would be first data page again, and thus the sample will still
appear completely contiguous in virtual memory. See comment and a simple ASCII
diagram showing this visually in bpf_ringbuf_area_alloc().

Another feature that distinguishes BPF ringbuf from perf ring buffer is
a self-pacing notifications of new data being availability.
bpf_ringbuf_commit() implementation will send a notification of new record
being available after commit only if consumer has already caught up right up
to the record being committed. If not, consumer still has to catch up and thus
will see new data anyways without needing an extra poll notification.
Benchmarks (see tools/testing/selftests/bpf/benchs/bench_ringbuf.c) show that
this allows to achieve a very high throughput without having to resort to
tricks like "notify only every Nth sample", which are necessary with perf
buffer. For extreme cases, when BPF program wants more manual control of
notifications, commit/discard/output helpers accept BPF_RB_NO_WAKEUP and
BPF_RB_FORCE_WAKEUP flags, which give full control over notifications of data
availability, but require extra caution and diligence in using this API.

Comparison to alternatives
--------------------------
Before considering implementing BPF ring buffer from scratch existing
alternatives in kernel were evaluated, but didn't seem to meet the needs. They
largely fell into few categores:
  - per-CPU buffers (perf, ftrace, etc), which don't satisfy two motivations
    outlined above (ordering and memory consumption);
  - linked list-based implementations; while some were multi-producer designs,
    consuming these from user-space would be very complicated and most
    probably not performant; memory-mapping contiguous piece of memory is
    simpler and more performant for user-space consumers;
  - io_uring is SPSC, but also requires fixed-sized elements. Naively turning
    SPSC queue into MPSC w/ lock would have subpar performance compared to
    locked reserve + lockless commit, as with BPF ring buffer. Fixed sized
    elements would be too limiting for BPF programs, given existing BPF
    programs heavily rely on variable-sized perf buffer already;
  - specialized implementations (like a new printk ring buffer, [0]) with lots
    of printk-specific limitations and implications, that didn't seem to fit
    well for intended use with BPF programs.

  [0] https://lwn.net/Articles/779550/

Change-Id: I0da8e403a2ccc0d786a38da207557060300ab1b2
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20200529075424.3139988-2-andriin@fb.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-01-14 17:48:05 -08:00
Stanislav Fomichev
bf3c1fa865
UPSTREAM: bpf: Allow any port in bpf_bind helper
We want to have a tighter control on what ports we bind to in
the BPF_CGROUP_INET{4,6}_CONNECT hooks even if it means
connect() becomes slightly more expensive. The expensive part
comes from the fact that we now need to call inet_csk_get_port()
that verifies that the port is not used and allocates an entry
in the hash table for it.

Since we can't rely on "snum || !bind_address_no_port" to prevent
us from calling POST_BIND hook anymore, let's add another bind flag
to indicate that the call site is BPF program.

v5:
* fix wrong AF_INET (should be AF_INET6) in the bpf program for v6

v3:
* More bpf_bind documentation refinements (Martin KaFai Lau)
* Add UDP tests as well (Martin KaFai Lau)
* Don't start the thread, just do socket+bind+listen (Martin KaFai Lau)

v2:
* Update documentation (Andrey Ignatov)
* Pass BIND_FORCE_ADDRESS_NO_PORT conditionally (Andrey Ignatov)

Change-Id: Ia0d7052ae78cb82da3a0a7eea21afef9b174d26e
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Andrey Ignatov <rdna@fb.com>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200508174611.228805-5-sdf@google.com
2025-12-23 13:36:18 -08:00
Stanislav Fomichev
54af4e8275
BACKPORT: bpf: Bpf_{g,s}etsockopt for struct bpf_sock_addr
Currently, bpf_getsockopt and bpf_setsockopt helpers operate on the
'struct bpf_sock_ops' context in BPF_PROG_TYPE_SOCK_OPS program.
Let's generalize them and make them available for 'struct bpf_sock_addr'.
That way, in the future, we can allow those helpers in more places.

As an example, let's expose those 'struct bpf_sock_addr' based helpers to
BPF_CGROUP_INET{4,6}_CONNECT hooks. That way we can override CC before the
connection is made.

v3:
* Expose custom helpers for bpf_sock_addr context instead of doing
  generic bpf_sock argument (as suggested by Daniel). Even with
  try_socket_lock that doesn't sleep we have a problem where context sk
  is already locked and socket lock is non-nestable.

v2:
* s/BPF_PROG_TYPE_CGROUP_SOCKOPT/BPF_PROG_TYPE_SOCK_OPS/

Change-Id: Ic1ec1a886b1c822be6652075f0f85549a0594266
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Link: https://lore.kernel.org/bpf/20200430233152.199403-1-sdf@google.com
2025-12-23 13:36:17 -08:00
KP Singh
2aa7df3130
UPSTREAM: bpf: lsm: Add selftests for BPF_PROG_TYPE_LSM
* Load/attach a BPF program that hooks to file_mprotect (int)
  and bprm_committed_creds (void).
* Perform an action that triggers the hook.
* Verify if the audit event was received using the shared global
  variables for the process executed.
* Verify if the mprotect returns a -EPERM.

Change-Id: I0e041365f359a29ffb2d68b178ed090af54fc6f7
Signed-off-by: KP Singh <kpsingh@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Brendan Jackman <jackmanb@google.com>
Reviewed-by: Florent Revest <revest@google.com>
Reviewed-by: Thomas Garnier <thgarnie@google.com>
Reviewed-by: James Morris <jamorris@linux.microsoft.com>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/bpf/20200329004356.27286-8-kpsingh@chromium.org
2025-12-23 13:36:17 -08:00
Andrii Nakryiko
16652c0b17
UPSTREAM: bpf: Make verifier log more relevant by default
To make BPF verifier verbose log more releavant and easier to use to debug
verification failures, "pop" parts of log that were successfully verified.
This has effect of leaving only verifier logs that correspond to code branches
that lead to verification failure, which in practice should result in much
shorter and more relevant verifier log dumps. This behavior is made the
default behavior and can be overriden to do exhaustive logging by specifying
BPF_LOG_LEVEL2 log level.

Using BPF_LOG_LEVEL2 to disable this behavior is not ideal, because in some
cases it's good to have BPF_LOG_LEVEL2 per-instruction register dump
verbosity, but still have only relevant verifier branches logged. But for this
patch, I didn't want to add any new flags. It might be worth-while to just
rethink how BPF verifier logging is performed and requested and streamline it
a bit. But this trimming of successfully verified branches seems to be useful
and a good default behavior.

To test this, I modified runqslower slightly to introduce read of
uninitialized stack variable. Log (**truncated in the middle** to save many
lines out of this commit message) BEFORE this change:

; int handle__sched_switch(u64 *ctx)
0: (bf) r6 = r1
; struct task_struct *prev = (struct task_struct *)ctx[1];
1: (79) r1 = *(u64 *)(r6 +8)
func 'sched_switch' arg1 has btf_id 151 type STRUCT 'task_struct'
2: (b7) r2 = 0
; struct event event = {};
3: (7b) *(u64 *)(r10 -24) = r2
last_idx 3 first_idx 0
regs=4 stack=0 before 2: (b7) r2 = 0
4: (7b) *(u64 *)(r10 -32) = r2
5: (7b) *(u64 *)(r10 -40) = r2
6: (7b) *(u64 *)(r10 -48) = r2
; if (prev->state == TASK_RUNNING)

[ ... instruction dump from insn #7 through #50 are cut out ... ]

51: (b7) r2 = 16
52: (85) call bpf_get_current_comm#16
last_idx 52 first_idx 42
regs=4 stack=0 before 51: (b7) r2 = 16
; bpf_perf_event_output(ctx, &events, BPF_F_CURRENT_CPU,
53: (bf) r1 = r6
54: (18) r2 = 0xffff8881f3868800
56: (18) r3 = 0xffffffff
58: (bf) r4 = r7
59: (b7) r5 = 32
60: (85) call bpf_perf_event_output#25
last_idx 60 first_idx 53
regs=20 stack=0 before 59: (b7) r5 = 32
61: (bf) r2 = r10
; event.pid = pid;
62: (07) r2 += -16
; bpf_map_delete_elem(&start, &pid);
63: (18) r1 = 0xffff8881f3868000
65: (85) call bpf_map_delete_elem#3
; }
66: (b7) r0 = 0
67: (95) exit

from 44 to 66: safe

from 34 to 66: safe

from 11 to 28: R1_w=inv0 R2_w=inv0 R6_w=ctx(id=0,off=0,imm=0) R10=fp0 fp-8=mmmm???? fp-24_w=00000000 fp-32_w=00000000 fp-40_w=00000000 fp-48_w=00000000
; bpf_map_update_elem(&start, &pid, &ts, 0);
28: (bf) r2 = r10
;
29: (07) r2 += -16
; tsp = bpf_map_lookup_elem(&start, &pid);
30: (18) r1 = 0xffff8881f3868000
32: (85) call bpf_map_lookup_elem#1
invalid indirect read from stack off -16+0 size 4
processed 65 insns (limit 1000000) max_states_per_insn 1 total_states 5 peak_states 5 mark_read 4

Notice how there is a successful code path from instruction 0 through 67, few
successfully verified jumps (44->66, 34->66), and only after that 11->28 jump
plus error on instruction #32.

AFTER this change (full verifier log, **no truncation**):

; int handle__sched_switch(u64 *ctx)
0: (bf) r6 = r1
; struct task_struct *prev = (struct task_struct *)ctx[1];
1: (79) r1 = *(u64 *)(r6 +8)
func 'sched_switch' arg1 has btf_id 151 type STRUCT 'task_struct'
2: (b7) r2 = 0
; struct event event = {};
3: (7b) *(u64 *)(r10 -24) = r2
last_idx 3 first_idx 0
regs=4 stack=0 before 2: (b7) r2 = 0
4: (7b) *(u64 *)(r10 -32) = r2
5: (7b) *(u64 *)(r10 -40) = r2
6: (7b) *(u64 *)(r10 -48) = r2
; if (prev->state == TASK_RUNNING)
7: (79) r2 = *(u64 *)(r1 +16)
; if (prev->state == TASK_RUNNING)
8: (55) if r2 != 0x0 goto pc+19
 R1_w=ptr_task_struct(id=0,off=0,imm=0) R2_w=inv0 R6_w=ctx(id=0,off=0,imm=0) R10=fp0 fp-24_w=00000000 fp-32_w=00000000 fp-40_w=00000000 fp-48_w=00000000
; trace_enqueue(prev->tgid, prev->pid);
9: (61) r1 = *(u32 *)(r1 +1184)
10: (63) *(u32 *)(r10 -4) = r1
; if (!pid || (targ_pid && targ_pid != pid))
11: (15) if r1 == 0x0 goto pc+16

from 11 to 28: R1_w=inv0 R2_w=inv0 R6_w=ctx(id=0,off=0,imm=0) R10=fp0 fp-8=mmmm???? fp-24_w=00000000 fp-32_w=00000000 fp-40_w=00000000 fp-48_w=00000000
; bpf_map_update_elem(&start, &pid, &ts, 0);
28: (bf) r2 = r10
;
29: (07) r2 += -16
; tsp = bpf_map_lookup_elem(&start, &pid);
30: (18) r1 = 0xffff8881db3ce800
32: (85) call bpf_map_lookup_elem#1
invalid indirect read from stack off -16+0 size 4
processed 65 insns (limit 1000000) max_states_per_insn 1 total_states 5 peak_states 5 mark_read 4

Notice how in this case, there are 0-11 instructions + jump from 11 to
28 is recorded + 28-32 instructions with error on insn #32.

test_verifier test runner was updated to specify BPF_LOG_LEVEL2 for
VERBOSE_ACCEPT expected result due to potentially "incomplete" success verbose
log at BPF_LOG_LEVEL1.

On success, verbose log will only have a summary of number of processed
instructions, etc, but no branch tracing log. Having just a last succesful
branch tracing seemed weird and confusing. Having small and clean summary log
in success case seems quite logical and nice, though.

Change-Id: I3666f731c62f71ceb6baa6f758aaed3a30f8825c
Signed-off-by: Andrii Nakryiko <andriin@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200423195850.1259827-1-andriin@fb.com
2025-12-23 13:36:15 -08:00
Stanislav Fomichev
dc7229f6a3
UPSTREAM: bpf: Enable more helpers for BPF_PROG_TYPE_CGROUP_{DEVICE,SYSCTL,SOCKOPT}
Currently the following prog types don't fall back to bpf_base_func_proto()
(instead they have cgroup_base_func_proto which has a limited set of
helpers from bpf_base_func_proto):
* BPF_PROG_TYPE_CGROUP_DEVICE
* BPF_PROG_TYPE_CGROUP_SYSCTL
* BPF_PROG_TYPE_CGROUP_SOCKOPT

I don't see any specific reason why we shouldn't use bpf_base_func_proto(),
every other type of program (except bpf-lirc and, understandably, tracing)
use it, so let's fall back to bpf_base_func_proto for those prog types
as well.

This basically boils down to adding access to the following helpers:
* BPF_FUNC_get_prandom_u32
* BPF_FUNC_get_smp_processor_id
* BPF_FUNC_get_numa_node_id
* BPF_FUNC_tail_call
* BPF_FUNC_ktime_get_ns
* BPF_FUNC_spin_lock (CAP_SYS_ADMIN)
* BPF_FUNC_spin_unlock (CAP_SYS_ADMIN)
* BPF_FUNC_jiffies64 (CAP_SYS_ADMIN)

I've also added bpf_perf_event_output() because it's really handy for
logging and debugging.

Change-Id: I1d1bb9f918ac89ac20a045e7428e01b676d989a5
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200420174610.77494-1-sdf@google.com
2025-12-23 13:36:14 -08:00
Eelco Chaudron
cc217594c6
BACKPORT: bpf: Add bpf_xdp_output() helper
Introduce new helper that reuses existing xdp perf_event output
implementation, but can be called from raw_tracepoint programs
that receive 'struct xdp_buff *' as a tracepoint argument.

Change-Id: I418e7a0142b7f7e9f44febf5b1d6bdd5519ef5ca
Signed-off-by: Eelco Chaudron <echaudro@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Link: https://lore.kernel.org/bpf/158348514556.2239.11050972434793741444.stgit@xdp-tutorial
2025-12-23 13:36:05 -08:00
Eelco Chaudron
fe3fbc1044
UPSTREAM: selftests/bpf: Update xdp_bpf2bpf test to use new set_attach_target API
Use the new bpf_program__set_attach_target() API in the xdp_bpf2bpf
selftest so it can be referenced as an example on how to use it.

Change-Id: I21e608200f21a01a504b4b40cf24f5461161989f
Signed-off-by: Eelco Chaudron <echaudro@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/bpf/158220520562.127661.14289388017034825841.stgit@xdp-tutorial
2025-12-23 13:36:04 -08:00
Eelco Chaudron
48a618172e
UPSTREAM: selftests/bpf: Add a test for attaching a bpf fentry/fexit trace to an XDP program
Add a test that will attach a FENTRY and FEXIT program to the XDP test
program. It will also verify data from the XDP context on FENTRY and
verifies the return code on exit.

Change-Id: If0116a206c1776fef4094acbad42784b0b5a1f03
Signed-off-by: Eelco Chaudron <echaudro@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/bpf/157909410480.47481.11202505690938004673.stgit@xdp-tutorial
2025-12-23 13:36:04 -08:00
Jakub Sitnicki
ecc2370505
UPSTREAM: bpf, sockmap: Allow inserting listening TCP sockets into sockmap
In order for sockmap/sockhash types to become generic collections for
storing TCP sockets we need to loosen the checks during map update, while
tightening the checks in redirect helpers.

Currently sock{map,hash} require the TCP socket to be in established state,
which prevents inserting listening sockets.

Change the update pre-checks so the socket can also be in listening state.

Since it doesn't make sense to redirect with sock{map,hash} to listening
sockets, add appropriate socket state checks to BPF redirect helpers too.

Change-Id: I3a1bf4a5cda6f09c023d24a1c8653a4aa4e5a5c8
Signed-off-by: Jakub Sitnicki <jakub@cloudflare.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Link: https://lore.kernel.org/bpf/20200218171023.844439-5-jakub@cloudflare.com
2025-12-23 13:36:02 -08:00
KP Singh
3ae796205a
UPSTREAM: bpf: Add selftests for BPF_MODIFY_RETURN
Test for two scenarios:

  * When the fmod_ret program returns 0, the original function should
    be called along with fentry and fexit programs.
  * When the fmod_ret program returns a non-zero value, the original
    function should not be called, no side effect should be observed and
    fentry and fexit programs should be called.

The result from the kernel function call and whether a side-effect is
observed is returned via the retval attr of the BPF_PROG_TEST_RUN (bpf)
syscall.

Change-Id: Ifd5cfbe80986c6650cf7cc95e8ef190fb01ed04a
Signed-off-by: KP Singh <kpsingh@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20200304191853.1529-8-kpsingh@chromium.org
2025-12-23 13:36:02 -08:00
Daniel Xu
f06d60517f
BACKPORT: selftests/bpf: Add bpf_read_branch_records() selftest
Add a selftest to test:

* default bpf_read_branch_records() behavior
* BPF_F_GET_BRANCH_RECORDS_SIZE flag behavior
* error path on non branch record perf events
* using helper to write to stack
* using helper to write to global

On host with hardware counter support:

    # ./test_progs -t perf_branches
    #27/1 perf_branches_hw:OK
    #27/2 perf_branches_no_hw:OK
    #27 perf_branches:OK
    Summary: 1/2 PASSED, 0 SKIPPED, 0 FAILED

On host without hardware counter support (VM):

    # ./test_progs -t perf_branches
    #27/1 perf_branches_hw:OK
    #27/2 perf_branches_no_hw:OK
    #27 perf_branches:OK
    Summary: 1/2 PASSED, 1 SKIPPED, 0 FAILED

Also sync tools/include/uapi/linux/bpf.h.

Change-Id: Ie3abbdb66decaf913824d87d2f0feebb506d7062
Signed-off-by: Daniel Xu <dxu@dxuuu.xyz>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/bpf/20200218030432.4600-3-dxu@dxuuu.xyz
2025-12-23 13:36:00 -08:00
Nikita V. Shirokov
b8909f104c
UPSTREAM: bpf: Allow to change skb mark in test_run
allow to pass skb's mark field into bpf_prog_test_run ctx
for BPF_PROG_TYPE_SCHED_CLS prog type. that would allow
to test bpf programs which are doing decision based on this
field

Change-Id: Id05ce69ad66d1635c4c839e28d389d7c80b38a02
Signed-off-by: Nikita V. Shirokov <tehnerd@tehnerd.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2025-12-23 13:35:48 -08:00
Stanislav Fomichev
374bd6ee99
UPSTREAM: selftests/bpf: Test wire_len/gso_segs in BPF_PROG_TEST_RUN
Make sure we can pass arbitrary data in wire_len/gso_segs.

Change-Id: I67098cd27a7b31a86c175ba42a79fd5e26dd5ef7
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20191213223028.161282-2-sdf@google.com
2025-12-23 13:35:48 -08:00
Stanislav Fomichev
7c95600b09
UPSTREAM: selftests: bpf: Add selftest for __sk_buff tstamp
Make sure BPF_PROG_TEST_RUN accepts tstamp and exports any
modifications that BPF program does.

Change-Id: Ib03df9539df637f1dc2595798e96aff87e04b695
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20191015183125.124413-2-sdf@google.com
2025-12-23 13:35:47 -08:00
basamaryan
9181ada660
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
* 'android11-5.4-lts' of https://android.googlesource.com/kernel/common:
  Linux 5.4.302
  Input: pegasus-notetaker - fix potential out-of-bounds access
  Input: remove third argument of usb_maxpacket()
  usb: deprecate the third argument of usb_maxpacket()
  ata: libata-scsi: Fix system suspend for a security locked drive
  fs/proc: fix uaf in proc_readdir_de()
  pmdomain: imx: Fix reference count leak in imx_gpc_remove
  pmdomain: arm: scmi: Fix genpd leak on provider registration failure
  net: netpoll: fix incorrect refcount handling causing incorrect cleanup
  net: qede: Initialize qede_ll_ops with designated initializer
  uio_hv_generic: Set event for all channels on the device
  net: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on error
  ALSA: usb-audio: fix uac2 clock source at terminal parser
  mm/page_alloc: fix hash table order logging in alloc_large_system_hash()
  kconfig/nconf: Initialize the default locale at startup
  kconfig/mconf: Initialize the default locale at startup
  vsock: Ignore signal/timeout on connect() if already established
  s390/ctcm: Fix double-kfree
  net: openvswitch: remove never-working support for setting nsh fields
  mlxsw: spectrum: Fix memory leak in mlxsw_sp_flower_stats()
  MIPS: Malta: Fix !EVA SOC-it PCI MMIO
  scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
  scsi: sg: Do not sleep in atomic context
  Input: cros_ec_keyb - fix an invalid memory access
  be2net: pass wrb_params in case of OS2BMC
  HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
  isdn: mISDN: hfcsusb: fix memory leak in hfcsusb_probe()
  EDAC/altera: Use INTTEST register for Ethernet and USB SBE injection
  EDAC/altera: Handle OCRAM ECC enable after warm reset
  spi: Try to get ACPI GPIO IRQ earlier
  ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
  strparser: Fix signed/unsigned mismatch bug
  gcov: add support for GCC 15
  mm/ksm: fix flag-dropping behavior in ksm_madvise
  ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
  drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
  ASoC: cs4271: Fix regulator leak on probe failure
  regulator: fixed: fix GPIO descriptor leak on register failure
  regulator: fixed: use dev_err_probe for register
  Bluetooth: L2CAP: export l2cap_chan_hold for modules
  net_sched: limit try_bulk_dequeue_skb() batches
  net_sched: remove need_resched() from qdisc_run()
  net/mlx5e: Fix wraparound in rate limiting for values above 255 Gbps
  net/mlx5e: Fix maxrate wraparound in threshold between units
  net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
  wifi: mac80211: skip rate verification for not captured PSDUs
  net: mdio: fix resource leak in mdiobus_register_device()
  tipc: Fix use-after-free in tipc_mon_reinit_self().
  tipc: simplify the finalize work queue
  sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
  sctp: get netns from asoc and ep base
  Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
  Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion
  Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
  Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
  net: fec: correct rx_bytes statistic for the case SHIFT16 is set
  ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
  HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
  NFS4: Fix state renewals missing after boot
  compiler_types: Move unused static inline functions warning to W=2
  extcon: adc-jack: Cleanup wakeup source only if it was enabled
  tracing: Fix memory leaks in create_field_var()
  net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
  sctp: Prevent TOCTOU out-of-bounds write
  sctp: Hold RCU read lock while iterating over address list
  net: dsa: b53: stop reading ARL entries if search is done
  net: dsa: b53: fix enabling ip multicast
  net: dsa: b53: fix resetting speed and pause on forced link
  net: dsa: b53: prevent GMII_PORT_OVERRIDE_CTRL access on BCM5325
  net: dsa/b53: change b53_force_port_config() pause argument
  net: vlan: sync VLAN features with lower device
  ceph: add checking of wait_for_completion_killable() return value
  fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
  ACPI: property: Return present device nodes only on fwnode interface
  9p: sysfs_init: don't hardcode error to ENOMEM
  9p: fix /sys/fs/9p/caches overwriting itself
  fs/hpfs: Fix error code for new_inode() failure in mkdir/create/mknod/symlink
  ACPICA: Update dsmethod.c to get rid of unused variable warning
  orangefs: fix xattr related buffer overflow...
  page_pool: Clamp pool size to max 16K pages
  Bluetooth: bcsp: receive data only if registered
  Bluetooth: SCO: Fix UAF on sco_conn_free
  net: macb: avoid dealing with endianness in macb_set_hwaddr()
  nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
  NFSv4.1: fix mount hang after CREATE_SESSION failure
  NFSv4: handle ERR_GRACE on delegation recalls
  remoteproc: qcom: q6v5: Avoid handling handover twice
  sparc/module: Add R_SPARC_UA64 relocation handling
  net: intel: fm10k: Fix parameter idx set but not used
  jfs: fix uninitialized waitqueue in transaction manager
  jfs: Verify inode mode when loading from disk
  ipv6: np->rxpmtu race annotation
  usb: xhci: plat: Facilitate using autosuspend for xhci plat devices
  usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs
  allow finish_no_open(file, ERR_PTR(-E...))
  scsi: lpfc: Define size of debugfs entry for xri rebalancing
  scsi: lpfc: Check return status of lpfc_reset_flush_io_context during TGT_RESET
  selftests/Makefile: include $(INSTALL_DEP_TARGETS) in clean target to clean net/lib dependency
  net/cls_cgroup: Fix task_get_classid() during qdisc run
  selftests: Replace sleep with slowwait
  selftests: Disable dad for ipv6 in fcnal-test.sh
  media: redrat3: use int type to store negative error codes
  net: sh_eth: Disable WoL if system can not suspend
  phy: cadence: cdns-dphy: Enable lower resolutions in dphy
  usb: gadget: f_hid: Fix zero length packet transfer
  net: call cond_resched() less often in __release_sock()
  ALSA: usb-audio: apply quirk for MOONDROP Quark2
  net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms
  dmaengine: dw-edma: Set status for callback_result
  dmaengine: mv_xor: match alloc_wc and free_wc
  dmaengine: sh: setup_xref error handling
  scsi: pm8001: Use int instead of u32 to store error codes
  mips: lantiq: xway: sysctrl: rename stp clock
  mips: lantiq: danube: add missing device_type in pci node
  mips: lantiq: danube: add missing properties to cpu node
  media: fix uninitialized symbol warnings
  drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption
  extcon: adc-jack: Fix wakeup source leaks on device unbind
  rds: Fix endianness annotation for RDS_MPATH_HASH
  PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call
  net: Call trace_sock_exceed_buf_limit() for memcg failure with SK_MEM_RECV.
  net: When removing nexthops, don't call synchronize_net if it is not necessary
  char: misc: Does not request module for miscdevice with dynamic minor
  usb: gadget: f_ncm: Fix MAC assignment NCM ethernet
  iio: adc: spear_adc: mask SPEAR_ADC_STATUS channel and avg sample before setting register
  media: imon: make send_packet() more robust
  net: ipv6: fix field-spanning memcpy warning in AH output
  bridge: Redirect to backup port when port is administratively down
  powerpc/eeh: Use result of error_detected() in uevent
  x86/vsyscall: Do not require X86_PF_INSTR to emulate vsyscall
  media: pci: ivtv: Don't create fake v4l2_fh
  drm/amdkfd: return -ENOTTY for unsupported IOCTLs
  selftests/net: Ensure assert() triggers in psock_tpacket.c
  selftests/net: Replace non-standard __WORDSIZE with sizeof(long) * 8
  PCI: Disable MSI on RDC PCI to PCIe bridges
  drm/nouveau: replace snprintf() with scnprintf() in nvkm_snprintbf()
  mfd: madera: Work around false-positive -Wininitialized warning
  mfd: stmpe-i2c: Add missing MODULE_LICENSE
  mfd: stmpe: Remove IRQ domain upon removal
  tools/power x86_energy_perf_policy: Prefer driver HWP limits
  tools/power x86_energy_perf_policy: Enhance HWP enable
  tools/cpupower: Fix incorrect size in cpuidle_state_disable()
  hwmon: (dell-smm) Add support for Dell OptiPlex 7040
  uprobe: Do not emulate/sstep original instruction when ip is changed
  clocksource/drivers/vf-pit: Replace raw_readl/writel to readl/writel
  video: backlight: lp855x_bl: Set correct EPROM start for LP8556
  tee: allow a driver to allocate a tee_device without a pool
  ACPICA: dispatcher: Use acpi_ds_clear_operands() in acpi_ds_call_control_method()
  mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card
  irqchip/gic-v2m: Handle Multiple MSI base IRQ Alignment
  arc: Fix __fls() const-foldability via __builtin_clzl()
  cpufreq/longhaul: handle NULL policy in longhaul_exit
  selftests/bpf: Fix bpf_prog_detach2 usage in test_lirc_mode2
  ACPI: video: force native for Lenovo 82K8
  memstick: Add timeout to prevent indefinite waiting
  mmc: host: renesas_sdhi: Fix the actual clock
  bpf: Don't use %pK through printk
  spi: loopback-test: Don't use %pK through printk
  soc: qcom: smem: Fix endian-unaware access of num_entries
  usb: gadget: f_fs: Fix epfile null pointer access after ep enable.
  serial: 8250_dw: handle reset control deassert error
  serial: 8250_dw: Use devm_add_action_or_reset()
  serial: 8250_dw: Use devm_clk_get_optional() to get the input clock
  can: gs_usb: increase max interface to U8_MAX
  devcoredump: Fix circular locking dependency with devcd->mutex.
  net: ravb: Enforce descriptor type ordering
  x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID
  wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode
  net: phy: dp83867: Disable EEE support as not implemented
  regmap: slimbus: fix bus_context pointer in regmap init calls
  drm/etnaviv: fix flush sequence logic
  usbnet: Prevents free active kevent
  wifi: ath10k: Fix memory leak on unsupported WMI command
  ASoC: qdsp6: q6asm: do not sleep while atomic
  fbdev: valkyriefb: Fix reference count leak in valkyriefb_init
  fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS
  fbdev: bitblit: bound-check glyph index in bit_putcs*
  ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
  fbdev: atyfb: Check if pll_ops->init_pll failed
  net: usb: asix_devices: Check return value of usbnet_get_endpoints
  btrfs: use smp_mb__after_atomic() when forcing COW in create_pending_snapshot()
  x86/bugs: Fix reporting of LFENCE retpoline
  net/sched: sch_qfq: Fix null-deref in agg_dequeue

 Conflicts:
	drivers/mmc/host/sdhci-msm.c
	drivers/usb/host/xhci-plat.c

Change-Id: I30739fea8840ace3825ea8955598d9efa687bb27
2025-12-11 01:41:51 -08:00
Michael Bestas
350c4ccfe1
Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-12-01
CVE-2025-48623
CVE-2025-48624
CVE-2025-48637
CVE-2025-48638
CVE-2024-35970
CVE-2025-38236
CVE-2025-38349
CVE-2025-48610
CVE-2025-38500

* tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: crypto: essiv - Check ssize for decryption and in-place encryption
  ANDROID: GKI: fix up build break where timer_delete_sync() was used
  Revert "net: rtnetlink: remove redundant assignment to variable err"
  Revert "net: rtnetlink: add msg kind names"
  Revert "net: rtnetlink: add helper to extract msg type's kind"
  Revert "net: rtnetlink: use BIT for flag values"
  Revert "net: netlink: add NLM_F_BULK delete request modifier"
  Revert "net: rtnetlink: add bulk delete support flag"
  Revert "net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg"
  Revert "net: add ndo_fdb_del_bulk"
  Revert "net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del"
  Revert "rtnetlink: Allow deleting FDB entries in user namespace"
  Linux 5.4.301
  net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
  media: s5p-mfc: remove an unused/uninitialized variable
  NFSD: Fix last write offset handling in layoutcommit
  NFSD: Minor cleanup in layoutcommit processing
  padata: Reset next CPU when reorder sequence wraps around
  KEYS: trusted_tpm1: Compare HMAC values in constant time
  NFSD: Define a proc_layoutcommit for the FlexFiles layout type
  vfs: Don't leak disconnected dentries on umount
  jbd2: ensure that all ongoing I/O complete before freeing blocks
  ext4: detect invalid INLINE_DATA + EXTENTS flag combination
  drm/amdgpu: use atomic functions with memory barriers for vm fault info
  ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
  spi: cadence-quadspi: Flush posted register writes before DAC access
  spi: cadence-quadspi: Flush posted register writes before INDAC access
  memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
  memory: samsung: exynos-srom: Correct alignment
  arm64: errata: Apply workarounds for Neoverse-V3AE
  arm64: cputype: Add Neoverse-V3AE definitions
  comedi: fix divide-by-zero in comedi_buf_munge()
  binder: remove "invalid inc weak" check
  xhci: dbc: enable back DbC in resume if it was enabled before suspend
  usb/core/quirks: Add Huawei ME906S to wakeup quirk
  USB: serial: option: add Telit FN920C04 ECM compositions
  USB: serial: option: add Quectel RG255C
  USB: serial: option: add UNISOC UIS7720
  net: ravb: Ensure memory write completes before ringing TX doorbell
  net: usb: rtl8150: Fix frame padding
  ocfs2: clear extent cache after moving/defragmenting extents
  MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
  Revert "cpuidle: menu: Avoid discarding useful information"
  net: bonding: fix possible peer notify event loss or dup issue
  sctp: avoid NULL dereference when chunk data buffer is missing
  arm64, mm: avoid always making PTE dirty in pte_mkwrite()
  net: enetc: correct the value of ENETC_RXB_TRUESIZE
  rtnetlink: Allow deleting FDB entries in user namespace
  net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del
  net: add ndo_fdb_del_bulk
  net: rtnetlink: add bulk delete support flag
  net: netlink: add NLM_F_BULK delete request modifier
  net: rtnetlink: use BIT for flag values
  net: rtnetlink: add helper to extract msg type's kind
  net: rtnetlink: add msg kind names
  net: rtnetlink: remove redundant assignment to variable err
  m68k: bitops: Fix find_*_bit() signatures
  hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super()
  hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
  dlm: check for defined force value in dlm_lockspace_release
  hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
  hfs: validate record offset in hfsplus_bmap_alloc
  hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
  hfs: make proper initalization of struct hfs_find_data
  hfs: clear offset and space out of valid records in b-tree node
  exec: Fix incorrect type for ret
  hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
  ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
  sched/fair: Fix pelt lost idle time detection
  sched/balancing: Rename newidle_balance() => sched_balance_newidle()
  sched/fair: Trivial correction of the newidle_balance() comment
  sched: Make newidle_balance() static again
  tls: don't rely on tx_work during send()
  tls: always set record_type in tls_process_cmsg
  tg3: prevent use of uninitialized remote_adv and local_adv variables
  tcp: fix tcp_tso_should_defer() vs large RTT
  amd-xgbe: Avoid spurious link down messages during interface toggle
  net/ip6_tunnel: Prevent perpetual tunnel growth
  net: dlink: handle dma_map_single() failure properly
  net: dl2k: switch from 'pci_' to 'dma_' API
  media: pci: ivtv: Add missing check after DMA map
  media: pci/ivtv: switch from 'pci_' to 'dma_' API
  xen/events: Update virq_to_irq on migration
  media: lirc: Fix error handling in lirc_register()
  media: rc: Directly use ida_free()
  drm/exynos: exynos7_drm_decon: remove ctx->suspended
  btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
  pwm: berlin: Fix wrong register in suspend/resume
  media: cx18: Add missing check after DMA map
  xen/events: Cleanup find_virq() return codes
  cramfs: Verify inode mode when loading from disk
  fs: Add 'initramfs_options' to set initramfs mount options
  pid: Add a judgment for ns null in pid_nr_ns
  minixfs: Verify inode mode when loading from disk
  tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
  dm: fix NULL pointer dereference in __dm_suspend()
  mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag
  mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type
  mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value
  Squashfs: reject negative file sizes in squashfs_read_inode()
  Squashfs: add additional inode sanity checking
  media: mc: Clear minor number before put device
  mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data()
  fs: udf: fix OOB read in lengthAllocDescs handling
  KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
  net/9p: fix double req put in p9_fd_cancelled
  ext4: guard against EA inode refcount underflow in xattr update
  ext4: correctly handle queries for metadata mappings
  ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch()
  nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
  x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases)
  x86/umip: Check that the instruction opcode is at least two bytes
  PCI: keystone: Use devm_request_irq() to free "ks-pcie-error-irq" on exit
  PCI/AER: Fix missing uevent on recovery when a reset is requested
  PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
  rseq/selftests: Use weak symbol reference, not definition, to link with glibc
  rtc: interface: Fix long-standing race when setting alarm
  rtc: interface: Ensure alarm irq is enabled when UIE is enabled
  mmc: core: SPI mode remove cmd7
  mtd: rawnand: fsmc: Default to autodetect buswidth
  sparc: fix error handling in scan_one_device()
  sparc64: fix hugetlb for sun4u
  sctp: Fix MAC comparison to be constant-time
  scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl()
  parisc: don't reference obsolete termio struct for TC* constants
  lib/genalloc: fix device leak in of_gen_pool_get()
  iio: frequency: adf4350: Fix prescaler usage.
  iio: dac: ad5421: use int type to store negative error codes
  iio: dac: ad5360: use int type to store negative error codes
  crypto: atmel - Fix dma_unmap_sg() direction
  cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
  drm/nouveau: fix bad ret code in nouveau_bo_move_prep
  media: i2c: mt9v111: fix incorrect type for ret
  firmware: meson_sm: fix device leak at probe
  xen/manage: Fix suspend error path
  arm64: dts: qcom: msm8916: Add missing MDSS reset
  ACPI: debug: fix signedness issues in read/write helpers
  ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
  tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
  tpm, tpm_tis: Claim locality before writing interrupt registers
  crypto: essiv - Check ssize for decryption and in-place encryption
  mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes
  mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call
  tools build: Align warning options with perf
  net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe
  tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
  net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
  drm/vmwgfx: Fix Use-after-free in validation
  net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter()
  scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
  scsi: mvsas: Use sas_task_find_rq() for tagging
  scsi: mvsas: Delete mvs_tag_init()
  scsi: libsas: Add sas_task_find_rq()
  clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
  clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
  perf session: Fix handling when buffer exceeds 2 GiB
  rtc: x1205: Fix Xicor X1205 vendor prefix
  perf util: Fix compression checks returning -1 as bool
  iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
  clocksource/drivers/clps711x: Fix resource leaks in error paths
  pinctrl: check the return value of pinmux_ops::get_function_name()
  Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
  mm: hugetlb: avoid soft lockup when mprotect to large memory area
  uio_hv_generic: Let userspace take care of interrupt mask
  Squashfs: fix uninit-value in squashfs_get_parent
  Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
  net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable
  nfp: fix RSS hash key size when RSS is not supported
  drivers/base/node: fix double free in register_one_node()
  ocfs2: fix double free in user_cluster_connect()
  net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
  RDMA/siw: Always report immediate post SQ errors
  usb: vhci-hcd: Prevent suspending virtually attached devices
  scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
  ipvs: Defer ip_vs_ftp unregister during netns cleanup
  NFSv4.1: fix backchannel max_resp_sz verification check
  remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice
  sparc: fix accurate exception reporting in copy_{from,to}_user for M7
  sparc: fix accurate exception reporting in copy_to_user for Niagara 4
  sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
  sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
  sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC
  IB/sa: Fix sa_local_svc_timeout_ms read race
  RDMA/core: Resolve MAC of next-hop device without ARP support
  wifi: mt76: fix potential memory leak in mt76_wmac_probe()
  drivers/base/node: handle error properly in register_one_node()
  watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog
  netfilter: ipset: Remove unused htable_bits in macro ahash_region
  iio: consumers: Fix offset handling in iio_convert_raw_to_processed()
  ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
  ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
  ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
  pps: fix warning in pps_register_cdev when register device fail
  misc: genwqe: Fix incorrect cmd field being reported in error
  usb: gadget: configfs: Correctly set use_os_string at bind
  usb: phy: twl6030: Fix incorrect type for ret
  tcp: fix __tcp_close() to only send RST when required
  PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation
  wifi: mwifiex: send world regulatory domain to driver
  ALSA: lx_core: use int type to store negative error codes
  media: rj54n1cb0c: Fix memleak in rj54n1_probe()
  scsi: myrs: Fix dma_alloc_coherent() error check
  scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
  serial: max310x: Add error checking in probe()
  usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
  drm/radeon/r600_cs: clean up of dead code in r600_cs
  i2c: designware: Add disabling clocks when probe fails
  i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
  bpf: Explicitly check accesses to bpf_sock_addr
  selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
  pwm: tiehrpwm: Fix corner case in clock divisor calculation
  block: use int to store blk_stack_limits() return value
  blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
  pinctrl: meson-gxl: add missing i2c_d pinmux
  soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
  ACPI: processor: idle: Fix memory leak when register cpuidle device failed
  regmap: Remove superfluous check for !config in __regmap_init()
  x86/vdso: Fix output operand size of RDPID
  perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
  driver core/PM: Set power.no_callbacks along with power.no_pm
  staging: axis-fifo: flush RX FIFO on read errors
  staging: axis-fifo: fix maximum TX packet length check
  perf subcmd: avoid crash in exclude_cmds when excludes is empty
  dm-integrity: limit MAX_TAG_SIZE to 255
  wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
  USB: serial: option: add SIMCom 8230C compositions
  media: rc: fix races with imon_disconnect()
  media: imon: grab lock earlier in imon_ir_change_protocol()
  media: imon: reorganize serialization
  media: rc: Add support for another iMON 0xffdc device
  media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
  media: tuner: xc5000: Fix use-after-free in xc5000_release
  media: tunner: xc5000: Refactor firmware load
  udp: Fix memory accounting leak.
  media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
  scsi: target: target_core_configfs: Add length check to avoid buffer overflow

 Conflicts:
	drivers/soc/qcom/rpmh-rsc.c
	kernel/sched/fair.c

Change-Id: I58ab24a3db8be4c698c41fd47daeb1f1fb7884ee
2025-12-04 19:21:35 +02:00
Greg Kroah-Hartman
ca00e0f525 This is the 5.4.302 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmkwI4sACgkQONu9yGCS
 aT46Mg//f9a0IiDkO2ybqt7JAStVCkQ5MM2CgPjlgHGyns6hWyxUES5twrVrTO0v
 mdYmeXLztyFSArUHMnoWcUK1O4IVUVK32SX3eEMFy81ojX+LpYm/m5TZg3tU1rvq
 jaTE0i6ihmwG48ciB63i28TxQfhY8QuVJTEV400Ro+ILY2hs1l6c6DYf9i0S/v4g
 gKDQpzuwR0AnGNFI+D6D6D0D8jbLVcBYnAndyvDrLYTIILczf7nJ66ZePYTBvlg3
 rIiIMjG0BX0V2ctPmez3mz0BDTpnZY4pwIwIG8K/bX4UZrgOKJPSZWh1SzbASaGN
 vTJQwRs9nGHvM/kK9CUUsi1+hhaAl7UmQEiRJ06BkXlR7chFCcL/fI/VEQjf12wL
 dyw6/RR/rXPxLbLxCYk+9C9ANTE/ByirLKSeJkNT/yoeiCSpaFuKxtoYkNslBK/B
 i0/Qweez0IzJuVUtUp/2/PrkNKyCaEbbqhDerbnLhU/0lcnT0fkFlFoLLLNzxNdt
 hj6RRJrcpoQB+Qrkf0+5Sxx6W1feP5clZJ2nRSL+rtUNEzCWk7HVh4GprCyvDn6i
 xjINN9Yh40suJkuKaE0+IrPF1tcL3/128OaT3e0VlL57wK5M4YmJTwrb7g4mlR2/
 31Z4bL1IFYju9WYPW2fWHrdrZUH4h22vLcpW6Q/VFdG0wTC6wVc=
 =Wt2i
 -----END PGP SIGNATURE-----

Merge 5.4.302 into android11-5.4-lts

Changes in 5.4.302
	net/sched: sch_qfq: Fix null-deref in agg_dequeue
	x86/bugs: Fix reporting of LFENCE retpoline
	btrfs: use smp_mb__after_atomic() when forcing COW in create_pending_snapshot()
	net: usb: asix_devices: Check return value of usbnet_get_endpoints
	fbdev: atyfb: Check if pll_ops->init_pll failed
	ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
	fbdev: bitblit: bound-check glyph index in bit_putcs*
	fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS
	fbdev: valkyriefb: Fix reference count leak in valkyriefb_init
	ASoC: qdsp6: q6asm: do not sleep while atomic
	wifi: ath10k: Fix memory leak on unsupported WMI command
	usbnet: Prevents free active kevent
	drm/etnaviv: fix flush sequence logic
	regmap: slimbus: fix bus_context pointer in regmap init calls
	net: phy: dp83867: Disable EEE support as not implemented
	wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode
	x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID
	net: ravb: Enforce descriptor type ordering
	devcoredump: Fix circular locking dependency with devcd->mutex.
	can: gs_usb: increase max interface to U8_MAX
	serial: 8250_dw: Use devm_clk_get_optional() to get the input clock
	serial: 8250_dw: Use devm_add_action_or_reset()
	serial: 8250_dw: handle reset control deassert error
	usb: gadget: f_fs: Fix epfile null pointer access after ep enable.
	soc: qcom: smem: Fix endian-unaware access of num_entries
	spi: loopback-test: Don't use %pK through printk
	bpf: Don't use %pK through printk
	mmc: host: renesas_sdhi: Fix the actual clock
	memstick: Add timeout to prevent indefinite waiting
	ACPI: video: force native for Lenovo 82K8
	selftests/bpf: Fix bpf_prog_detach2 usage in test_lirc_mode2
	cpufreq/longhaul: handle NULL policy in longhaul_exit
	arc: Fix __fls() const-foldability via __builtin_clzl()
	irqchip/gic-v2m: Handle Multiple MSI base IRQ Alignment
	mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card
	ACPICA: dispatcher: Use acpi_ds_clear_operands() in acpi_ds_call_control_method()
	tee: allow a driver to allocate a tee_device without a pool
	video: backlight: lp855x_bl: Set correct EPROM start for LP8556
	clocksource/drivers/vf-pit: Replace raw_readl/writel to readl/writel
	uprobe: Do not emulate/sstep original instruction when ip is changed
	hwmon: (dell-smm) Add support for Dell OptiPlex 7040
	tools/cpupower: Fix incorrect size in cpuidle_state_disable()
	tools/power x86_energy_perf_policy: Enhance HWP enable
	tools/power x86_energy_perf_policy: Prefer driver HWP limits
	mfd: stmpe: Remove IRQ domain upon removal
	mfd: stmpe-i2c: Add missing MODULE_LICENSE
	mfd: madera: Work around false-positive -Wininitialized warning
	drm/nouveau: replace snprintf() with scnprintf() in nvkm_snprintbf()
	PCI: Disable MSI on RDC PCI to PCIe bridges
	selftests/net: Replace non-standard __WORDSIZE with sizeof(long) * 8
	selftests/net: Ensure assert() triggers in psock_tpacket.c
	drm/amdkfd: return -ENOTTY for unsupported IOCTLs
	media: pci: ivtv: Don't create fake v4l2_fh
	x86/vsyscall: Do not require X86_PF_INSTR to emulate vsyscall
	powerpc/eeh: Use result of error_detected() in uevent
	bridge: Redirect to backup port when port is administratively down
	net: ipv6: fix field-spanning memcpy warning in AH output
	media: imon: make send_packet() more robust
	iio: adc: spear_adc: mask SPEAR_ADC_STATUS channel and avg sample before setting register
	usb: gadget: f_ncm: Fix MAC assignment NCM ethernet
	char: misc: Does not request module for miscdevice with dynamic minor
	net: When removing nexthops, don't call synchronize_net if it is not necessary
	net: Call trace_sock_exceed_buf_limit() for memcg failure with SK_MEM_RECV.
	PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call
	rds: Fix endianness annotation for RDS_MPATH_HASH
	extcon: adc-jack: Fix wakeup source leaks on device unbind
	drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption
	media: fix uninitialized symbol warnings
	mips: lantiq: danube: add missing properties to cpu node
	mips: lantiq: danube: add missing device_type in pci node
	mips: lantiq: xway: sysctrl: rename stp clock
	scsi: pm8001: Use int instead of u32 to store error codes
	dmaengine: sh: setup_xref error handling
	dmaengine: mv_xor: match alloc_wc and free_wc
	dmaengine: dw-edma: Set status for callback_result
	net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms
	ALSA: usb-audio: apply quirk for MOONDROP Quark2
	net: call cond_resched() less often in __release_sock()
	usb: gadget: f_hid: Fix zero length packet transfer
	phy: cadence: cdns-dphy: Enable lower resolutions in dphy
	net: sh_eth: Disable WoL if system can not suspend
	media: redrat3: use int type to store negative error codes
	selftests: Disable dad for ipv6 in fcnal-test.sh
	selftests: Replace sleep with slowwait
	net/cls_cgroup: Fix task_get_classid() during qdisc run
	selftests/Makefile: include $(INSTALL_DEP_TARGETS) in clean target to clean net/lib dependency
	scsi: lpfc: Check return status of lpfc_reset_flush_io_context during TGT_RESET
	scsi: lpfc: Define size of debugfs entry for xri rebalancing
	allow finish_no_open(file, ERR_PTR(-E...))
	usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs
	usb: xhci: plat: Facilitate using autosuspend for xhci plat devices
	ipv6: np->rxpmtu race annotation
	jfs: Verify inode mode when loading from disk
	jfs: fix uninitialized waitqueue in transaction manager
	net: intel: fm10k: Fix parameter idx set but not used
	sparc/module: Add R_SPARC_UA64 relocation handling
	remoteproc: qcom: q6v5: Avoid handling handover twice
	NFSv4: handle ERR_GRACE on delegation recalls
	NFSv4.1: fix mount hang after CREATE_SESSION failure
	nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
	net: macb: avoid dealing with endianness in macb_set_hwaddr()
	Bluetooth: SCO: Fix UAF on sco_conn_free
	Bluetooth: bcsp: receive data only if registered
	page_pool: Clamp pool size to max 16K pages
	orangefs: fix xattr related buffer overflow...
	ACPICA: Update dsmethod.c to get rid of unused variable warning
	fs/hpfs: Fix error code for new_inode() failure in mkdir/create/mknod/symlink
	9p: fix /sys/fs/9p/caches overwriting itself
	9p: sysfs_init: don't hardcode error to ENOMEM
	ACPI: property: Return present device nodes only on fwnode interface
	fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
	ceph: add checking of wait_for_completion_killable() return value
	net: vlan: sync VLAN features with lower device
	net: dsa/b53: change b53_force_port_config() pause argument
	net: dsa: b53: prevent GMII_PORT_OVERRIDE_CTRL access on BCM5325
	net: dsa: b53: fix resetting speed and pause on forced link
	net: dsa: b53: fix enabling ip multicast
	net: dsa: b53: stop reading ARL entries if search is done
	sctp: Hold RCU read lock while iterating over address list
	sctp: Prevent TOCTOU out-of-bounds write
	net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
	tracing: Fix memory leaks in create_field_var()
	extcon: adc-jack: Cleanup wakeup source only if it was enabled
	compiler_types: Move unused static inline functions warning to W=2
	NFS4: Fix state renewals missing after boot
	HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
	ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
	net: fec: correct rx_bytes statistic for the case SHIFT16 is set
	Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
	Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
	Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion
	Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
	sctp: get netns from asoc and ep base
	sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
	tipc: simplify the finalize work queue
	tipc: Fix use-after-free in tipc_mon_reinit_self().
	net: mdio: fix resource leak in mdiobus_register_device()
	wifi: mac80211: skip rate verification for not captured PSDUs
	net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
	net/mlx5e: Fix maxrate wraparound in threshold between units
	net/mlx5e: Fix wraparound in rate limiting for values above 255 Gbps
	net_sched: remove need_resched() from qdisc_run()
	net_sched: limit try_bulk_dequeue_skb() batches
	Bluetooth: L2CAP: export l2cap_chan_hold for modules
	regulator: fixed: use dev_err_probe for register
	regulator: fixed: fix GPIO descriptor leak on register failure
	ASoC: cs4271: Fix regulator leak on probe failure
	drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
	ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
	mm/ksm: fix flag-dropping behavior in ksm_madvise
	gcov: add support for GCC 15
	strparser: Fix signed/unsigned mismatch bug
	ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
	spi: Try to get ACPI GPIO IRQ earlier
	EDAC/altera: Handle OCRAM ECC enable after warm reset
	EDAC/altera: Use INTTEST register for Ethernet and USB SBE injection
	isdn: mISDN: hfcsusb: fix memory leak in hfcsusb_probe()
	HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
	be2net: pass wrb_params in case of OS2BMC
	Input: cros_ec_keyb - fix an invalid memory access
	scsi: sg: Do not sleep in atomic context
	scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
	MIPS: Malta: Fix !EVA SOC-it PCI MMIO
	mlxsw: spectrum: Fix memory leak in mlxsw_sp_flower_stats()
	net: openvswitch: remove never-working support for setting nsh fields
	s390/ctcm: Fix double-kfree
	vsock: Ignore signal/timeout on connect() if already established
	kconfig/mconf: Initialize the default locale at startup
	kconfig/nconf: Initialize the default locale at startup
	mm/page_alloc: fix hash table order logging in alloc_large_system_hash()
	ALSA: usb-audio: fix uac2 clock source at terminal parser
	net: ethernet: ti: netcp: Standardize knav_dma_open_channel to return NULL on error
	uio_hv_generic: Set event for all channels on the device
	net: qede: Initialize qede_ll_ops with designated initializer
	net: netpoll: fix incorrect refcount handling causing incorrect cleanup
	pmdomain: arm: scmi: Fix genpd leak on provider registration failure
	pmdomain: imx: Fix reference count leak in imx_gpc_remove
	fs/proc: fix uaf in proc_readdir_de()
	ata: libata-scsi: Fix system suspend for a security locked drive
	usb: deprecate the third argument of usb_maxpacket()
	Input: remove third argument of usb_maxpacket()
	Input: pegasus-notetaker - fix potential out-of-bounds access
	Linux 5.4.302

Change-Id: I7291d845c3cfde8a154957356156fadcc4b96b80
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-12-03 14:36:44 +00:00
Nai-Chen Cheng
0dc59e2673 selftests/Makefile: include $(INSTALL_DEP_TARGETS) in clean target to clean net/lib dependency
[ Upstream commit d3f7457da7b9527a06dbcbfaf666aa51ac2eeb53 ]

The selftests 'make clean' does not clean the net/lib because it only
processes $(TARGETS) and ignores $(INSTALL_DEP_TARGETS). This leaves
compiled objects in net/lib after cleaning, requiring manual cleanup.

Include $(INSTALL_DEP_TARGETS) in clean target to ensure net/lib
dependency is properly cleaned.

Signed-off-by: Nai-Chen Cheng <bleach1827@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Tested-by: Simon Horman <horms@kernel.org> # build-tested
Acked-by: Shuah Khan <skhan@linuxfoundation.org>
Link: https://patch.msgid.link/20250910-selftests-makefile-clean-v1-1-29e7f496cd87@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:12 +01:00
David Ahern
9cfaa6b715 selftests: Replace sleep with slowwait
[ Upstream commit 2f186dd5585c3afb415df80e52f71af16c9d3655 ]

Replace the sleep in kill_procs with slowwait.

Signed-off-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250910025828.38900-2-dsahern@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:12 +01:00
David Ahern
731088e8cb selftests: Disable dad for ipv6 in fcnal-test.sh
[ Upstream commit 53d591730ea34f97a82f7ec6e7c987ca6e34dc21 ]

Constrained test environment; duplicate address detection is not needed
and causes races so disable it.

Signed-off-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250910025828.38900-1-dsahern@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:12 +01:00
Wake Liu
0f2fce4b19 selftests/net: Ensure assert() triggers in psock_tpacket.c
[ Upstream commit bc4c0a48bdad7f225740b8e750fdc1da6d85e1eb ]

The get_next_frame() function in psock_tpacket.c was missing a return
statement in its default switch case, leading to a compiler warning.

This was caused by a `bug_on(1)` call, which is defined as an
`assert()`, being compiled out because NDEBUG is defined during the
build.

Instead of adding a `return NULL;` which would silently hide the error
and could lead to crashes later, this change restores the original
author's intent. By adding `#undef NDEBUG` before including <assert.h>,
we ensure the assertion is active and will cause the test to abort if
this unreachable code is ever executed.

Signed-off-by: Wake Liu <wakel@google.com>
Link: https://patch.msgid.link/20250809062013.2407822-1-wakel@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:09 +01:00
Wake Liu
00e6691f6c selftests/net: Replace non-standard __WORDSIZE with sizeof(long) * 8
[ Upstream commit c36748e8733ef9c5f4cd1d7c4327994e5b88b8df ]

The `__WORDSIZE` macro, defined in the non-standard `<bits/wordsize.h>`
header, is a GNU extension and not universally available with all
toolchains, such as Clang when used with musl libc.

This can lead to build failures in environments where this header is
missing.

The intention of the code is to determine the bit width of a C `long`.
Replace the non-portable `__WORDSIZE` with the standard and portable
`sizeof(long) * 8` expression to achieve the same result.

This change also removes the inclusion of the now-unused
`<bits/wordsize.h>` header.

Signed-off-by: Wake Liu <wakel@google.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:09 +01:00
Ricardo B. Marlière
b5d562b4d4 selftests/bpf: Fix bpf_prog_detach2 usage in test_lirc_mode2
[ Upstream commit 98857d111c53954aa038fcbc4cf48873e4240f7c ]

Commit e9fc3ce99b34 ("libbpf: Streamline error reporting for high-level
APIs") redefined the way that bpf_prog_detach2() returns. Therefore, adapt
the usage in test_lirc_mode2_user.c.

Signed-off-by: Ricardo B. Marlière <rbm@suse.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20250828-selftests-bpf-v1-1-c7811cd8b98c@suse.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:07 +01:00
Greg Kroah-Hartman
f6520a7c91 This is the 5.4.301 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmkCD9kACgkQONu9yGCS
 aT756BAAwEcL3lKO/0QKjMUrvgv7FRoRm9TH9Usq7Nswmiax6YKI3oPgZKfZZL6u
 yLGSnYqV8f+Jo8kALMJAybu+Oc3Z8WbBZJG/dvlAkvR7iN19ZCuKa2NwWmh8BTGd
 5ZP4/nyXlNlg0/IIZ8xJa3067U895y9IhgMDmSvOZoUFGFecqUmJNBoj8bHgJaPL
 /MENYb7D0CcKWbgCwzsqN0EEm9UKb7xgtaaC52sfZD+GHUPF/RLq9QNyUGtyL0m8
 y20HG6zXmBiVP+zdtYpTaaEP6OSNOCmiOweSZOFafnatd2XO1hRdnAoEk7+t2Lj+
 Xa5GowVUuglmBd8bPbeY8cwVihMxr81DxMns+OpQJTiDD8Q6Whcxbaqwv+tVe7z4
 cVDh1xlKG4U2rsDTeiGhbZVNb6gqqy3LnVFqImQE+dcZqlwC0pbqwO2lLdHMa8NF
 f+l1U3ab0k9qYx8HQegYDTufW5Eb0Rki/3YyHk8o3alOYd2Oc3r16lw9rpSw2Nq3
 Rku+VMSy6z8uvmIP7Ywobla6j73SGFrDc61F0nsU1x+Gd/dMIgkn36dfxciBCgPa
 /AmkK1Psx04s7dIPMowx/nXy5Jk8J4k3JlVMeBnMCuFVUNCNp3qzq5WXdeL1G5f5
 GFPJPblaZrfKQNSSlpUAmstl8v5t8aJcjxobmHn28fVliFAJdDI=
 =XPvH
 -----END PGP SIGNATURE-----

Merge 5.4.301 into android11-5.4-lts

Changes in 5.4.301
	scsi: target: target_core_configfs: Add length check to avoid buffer overflow
	media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
	udp: Fix memory accounting leak.
	media: tunner: xc5000: Refactor firmware load
	media: tuner: xc5000: Fix use-after-free in xc5000_release
	media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
	media: rc: Add support for another iMON 0xffdc device
	media: imon: reorganize serialization
	media: imon: grab lock earlier in imon_ir_change_protocol()
	media: rc: fix races with imon_disconnect()
	USB: serial: option: add SIMCom 8230C compositions
	wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
	dm-integrity: limit MAX_TAG_SIZE to 255
	perf subcmd: avoid crash in exclude_cmds when excludes is empty
	staging: axis-fifo: fix maximum TX packet length check
	staging: axis-fifo: flush RX FIFO on read errors
	driver core/PM: Set power.no_callbacks along with power.no_pm
	perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
	x86/vdso: Fix output operand size of RDPID
	regmap: Remove superfluous check for !config in __regmap_init()
	ACPI: processor: idle: Fix memory leak when register cpuidle device failed
	soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
	pinctrl: meson-gxl: add missing i2c_d pinmux
	blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
	block: use int to store blk_stack_limits() return value
	pwm: tiehrpwm: Fix corner case in clock divisor calculation
	selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
	bpf: Explicitly check accesses to bpf_sock_addr
	i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
	i2c: designware: Add disabling clocks when probe fails
	drm/radeon/r600_cs: clean up of dead code in r600_cs
	usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
	serial: max310x: Add error checking in probe()
	scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
	scsi: myrs: Fix dma_alloc_coherent() error check
	media: rj54n1cb0c: Fix memleak in rj54n1_probe()
	ALSA: lx_core: use int type to store negative error codes
	wifi: mwifiex: send world regulatory domain to driver
	PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation
	tcp: fix __tcp_close() to only send RST when required
	usb: phy: twl6030: Fix incorrect type for ret
	usb: gadget: configfs: Correctly set use_os_string at bind
	misc: genwqe: Fix incorrect cmd field being reported in error
	pps: fix warning in pps_register_cdev when register device fail
	ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
	ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
	ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
	iio: consumers: Fix offset handling in iio_convert_raw_to_processed()
	netfilter: ipset: Remove unused htable_bits in macro ahash_region
	watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog
	drivers/base/node: handle error properly in register_one_node()
	wifi: mt76: fix potential memory leak in mt76_wmac_probe()
	RDMA/core: Resolve MAC of next-hop device without ARP support
	IB/sa: Fix sa_local_svc_timeout_ms read race
	sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC
	sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
	sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
	sparc: fix accurate exception reporting in copy_to_user for Niagara 4
	sparc: fix accurate exception reporting in copy_{from,to}_user for M7
	remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice
	NFSv4.1: fix backchannel max_resp_sz verification check
	ipvs: Defer ip_vs_ftp unregister during netns cleanup
	scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
	usb: vhci-hcd: Prevent suspending virtually attached devices
	RDMA/siw: Always report immediate post SQ errors
	net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
	ocfs2: fix double free in user_cluster_connect()
	drivers/base/node: fix double free in register_one_node()
	nfp: fix RSS hash key size when RSS is not supported
	net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable
	Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
	Squashfs: fix uninit-value in squashfs_get_parent
	uio_hv_generic: Let userspace take care of interrupt mask
	mm: hugetlb: avoid soft lockup when mprotect to large memory area
	Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
	pinctrl: check the return value of pinmux_ops::get_function_name()
	clocksource/drivers/clps711x: Fix resource leaks in error paths
	iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
	perf util: Fix compression checks returning -1 as bool
	rtc: x1205: Fix Xicor X1205 vendor prefix
	perf session: Fix handling when buffer exceeds 2 GiB
	clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
	clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
	scsi: libsas: Add sas_task_find_rq()
	scsi: mvsas: Delete mvs_tag_init()
	scsi: mvsas: Use sas_task_find_rq() for tagging
	scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
	net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter()
	drm/vmwgfx: Fix Use-after-free in validation
	net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
	tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
	net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe
	tools build: Align warning options with perf
	mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call
	mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes
	crypto: essiv - Check ssize for decryption and in-place encryption
	tpm, tpm_tis: Claim locality before writing interrupt registers
	tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
	ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
	ACPI: debug: fix signedness issues in read/write helpers
	arm64: dts: qcom: msm8916: Add missing MDSS reset
	xen/manage: Fix suspend error path
	firmware: meson_sm: fix device leak at probe
	media: i2c: mt9v111: fix incorrect type for ret
	drm/nouveau: fix bad ret code in nouveau_bo_move_prep
	cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
	crypto: atmel - Fix dma_unmap_sg() direction
	iio: dac: ad5360: use int type to store negative error codes
	iio: dac: ad5421: use int type to store negative error codes
	iio: frequency: adf4350: Fix prescaler usage.
	lib/genalloc: fix device leak in of_gen_pool_get()
	parisc: don't reference obsolete termio struct for TC* constants
	scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl()
	sctp: Fix MAC comparison to be constant-time
	sparc64: fix hugetlb for sun4u
	sparc: fix error handling in scan_one_device()
	mtd: rawnand: fsmc: Default to autodetect buswidth
	mmc: core: SPI mode remove cmd7
	rtc: interface: Ensure alarm irq is enabled when UIE is enabled
	rtc: interface: Fix long-standing race when setting alarm
	rseq/selftests: Use weak symbol reference, not definition, to link with glibc
	PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
	PCI/AER: Fix missing uevent on recovery when a reset is requested
	PCI: keystone: Use devm_request_irq() to free "ks-pcie-error-irq" on exit
	x86/umip: Check that the instruction opcode is at least two bytes
	x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases)
	nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
	ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch()
	ext4: correctly handle queries for metadata mappings
	ext4: guard against EA inode refcount underflow in xattr update
	net/9p: fix double req put in p9_fd_cancelled
	KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
	fs: udf: fix OOB read in lengthAllocDescs handling
	mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data()
	media: mc: Clear minor number before put device
	Squashfs: add additional inode sanity checking
	Squashfs: reject negative file sizes in squashfs_read_inode()
	mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value
	mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type
	mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag
	dm: fix NULL pointer dereference in __dm_suspend()
	tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
	minixfs: Verify inode mode when loading from disk
	pid: Add a judgment for ns null in pid_nr_ns
	fs: Add 'initramfs_options' to set initramfs mount options
	cramfs: Verify inode mode when loading from disk
	xen/events: Cleanup find_virq() return codes
	media: cx18: Add missing check after DMA map
	pwm: berlin: Fix wrong register in suspend/resume
	btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
	drm/exynos: exynos7_drm_decon: remove ctx->suspended
	media: rc: Directly use ida_free()
	media: lirc: Fix error handling in lirc_register()
	xen/events: Update virq_to_irq on migration
	media: pci/ivtv: switch from 'pci_' to 'dma_' API
	media: pci: ivtv: Add missing check after DMA map
	net: dl2k: switch from 'pci_' to 'dma_' API
	net: dlink: handle dma_map_single() failure properly
	net/ip6_tunnel: Prevent perpetual tunnel growth
	amd-xgbe: Avoid spurious link down messages during interface toggle
	tcp: fix tcp_tso_should_defer() vs large RTT
	tg3: prevent use of uninitialized remote_adv and local_adv variables
	tls: always set record_type in tls_process_cmsg
	tls: don't rely on tx_work during send()
	sched: Make newidle_balance() static again
	sched/fair: Trivial correction of the newidle_balance() comment
	sched/balancing: Rename newidle_balance() => sched_balance_newidle()
	sched/fair: Fix pelt lost idle time detection
	ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
	hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
	exec: Fix incorrect type for ret
	hfs: clear offset and space out of valid records in b-tree node
	hfs: make proper initalization of struct hfs_find_data
	hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
	hfs: validate record offset in hfsplus_bmap_alloc
	hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
	dlm: check for defined force value in dlm_lockspace_release
	hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
	hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super()
	m68k: bitops: Fix find_*_bit() signatures
	net: rtnetlink: remove redundant assignment to variable err
	net: rtnetlink: add msg kind names
	net: rtnetlink: add helper to extract msg type's kind
	net: rtnetlink: use BIT for flag values
	net: netlink: add NLM_F_BULK delete request modifier
	net: rtnetlink: add bulk delete support flag
	net: add ndo_fdb_del_bulk
	net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del
	rtnetlink: Allow deleting FDB entries in user namespace
	net: enetc: correct the value of ENETC_RXB_TRUESIZE
	arm64, mm: avoid always making PTE dirty in pte_mkwrite()
	sctp: avoid NULL dereference when chunk data buffer is missing
	net: bonding: fix possible peer notify event loss or dup issue
	Revert "cpuidle: menu: Avoid discarding useful information"
	MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
	ocfs2: clear extent cache after moving/defragmenting extents
	net: usb: rtl8150: Fix frame padding
	net: ravb: Ensure memory write completes before ringing TX doorbell
	USB: serial: option: add UNISOC UIS7720
	USB: serial: option: add Quectel RG255C
	USB: serial: option: add Telit FN920C04 ECM compositions
	usb/core/quirks: Add Huawei ME906S to wakeup quirk
	xhci: dbc: enable back DbC in resume if it was enabled before suspend
	binder: remove "invalid inc weak" check
	comedi: fix divide-by-zero in comedi_buf_munge()
	arm64: cputype: Add Neoverse-V3AE definitions
	arm64: errata: Apply workarounds for Neoverse-V3AE
	memory: samsung: exynos-srom: Correct alignment
	memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
	spi: cadence-quadspi: Flush posted register writes before INDAC access
	spi: cadence-quadspi: Flush posted register writes before DAC access
	ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
	drm/amdgpu: use atomic functions with memory barriers for vm fault info
	ext4: detect invalid INLINE_DATA + EXTENTS flag combination
	jbd2: ensure that all ongoing I/O complete before freeing blocks
	vfs: Don't leak disconnected dentries on umount
	NFSD: Define a proc_layoutcommit for the FlexFiles layout type
	KEYS: trusted_tpm1: Compare HMAC values in constant time
	padata: Reset next CPU when reorder sequence wraps around
	NFSD: Minor cleanup in layoutcommit processing
	NFSD: Fix last write offset handling in layoutcommit
	media: s5p-mfc: remove an unused/uninitialized variable
	net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
	Linux 5.4.301

Change-Id: Ie2685625a0f630cb01ac8d8c9ddcd68c64ea6ed7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-30 07:52:10 +00:00
Sean Christopherson
9f363bf6f9 rseq/selftests: Use weak symbol reference, not definition, to link with glibc
commit a001cd248ab244633c5fabe4f7c707e13fc1d1cc upstream.

Add "extern" to the glibc-defined weak rseq symbols to convert the rseq
selftest's usage from weak symbol definitions to weak symbol _references_.
Effectively re-defining the glibc symbols wreaks havoc when building with
-fno-common, e.g. generates segfaults when running multi-threaded programs,
as dynamically linked applications end up with multiple versions of the
symbols.

Building with -fcommon, which until recently has the been the default for
GCC and clang, papers over the bug by allowing the linker to resolve the
weak/tentative definition to glibc's "real" definition.

Note, the symbol itself (or rather its address), not the value of the
symbol, is set to 0/NULL for unresolved weak symbol references, as the
symbol doesn't exist and thus can't have a value.  Check for a NULL rseq
size pointer to handle the scenario where the test is statically linked
against a libc that doesn't support rseq in any capacity.

Fixes: 3bcbc20942db ("selftests/rseq: Play nice with binaries statically linked against glibc 2.35+")
Reported-by: Thomas Gleixner <tglx@linutronix.de>
Suggested-by: Florian Weimer <fweimer@redhat.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/87frdoybk4.ffs@tglx
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:54 +01:00
Akhilesh Patil
93818c7ce4 selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
[ Upstream commit e8cfc524eaf3c0ed88106177edb6961e202e6716 ]

Check if watchdog device supports WDIOF_KEEPALIVEPING option before
entering keep_alive() ping test loop. Fix watchdog-test silently looping
if ioctl based ping is not supported by the device. Exit from test in
such case instead of getting stuck in loop executing failing keep_alive()

watchdog_info:
 identity:              m41t93 rtc Watchdog
 firmware_version:      0
Support/Status: Set timeout (in seconds)
Support/Status: Watchdog triggers a management or other external alarm not a reboot

Watchdog card disabled.
Watchdog timeout set to 5 seconds.
Watchdog ping rate set to 2 seconds.
Watchdog card enabled.
WDIOC_KEEPALIVE not supported by this device

without this change
Watchdog card disabled.
Watchdog timeout set to 5 seconds.
Watchdog ping rate set to 2 seconds.
Watchdog card enabled.
Watchdog Ticking Away!
(Where test stuck here forver silently)

Updated change log at commit time:
Shuah Khan <skhan@linuxfoundation.org>

Link: https://lore.kernel.org/r/20250914152840.GA3047348@bhairav-test.ee.iitb.ac.in
Fixes: d89d08ffd2 ("selftests: watchdog: Fix ioctl SET* error paths to take oneshot exit path")
Signed-off-by: Akhilesh Patil <akhilesh@ee.iitb.ac.in>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-29 13:59:46 +01:00
Michael Bestas
b31d93f6d6
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-10-01

* tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: vsock: Do not allow binding to VMADDR_PORT_ANY
  Linux 5.4.299
  dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status()
  cifs: fix integer overflow in match_server()
  spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort
  spi: spi-fsl-lpspi: Set correct chip-select polarity bit
  spi: spi-fsl-lpspi: Fix transmissions when using CONT
  pcmcia: Add error handling for add_interval() in do_validate_mem()
  ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model
  randstruct: gcc-plugin: Fix attribute addition
  randstruct: gcc-plugin: Remove bogus void member
  vmxnet3: update MTU after device quiesce
  net: dsa: microchip: linearize skb for tail-tagging switches
  net: dsa: microchip: update tag_ksz masks for KSZ9477 family
  dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status()
  ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup
  gpio: pca953x: fix IRQ storm on system wake up
  iio: light: opt3001: fix deadlock due to concurrent flag access
  iio: chemical: pms7003: use aligned_s64 for timestamp
  KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer
  cpufreq/sched: Explicitly synchronize limits_changed flag handling
  mm/slub: avoid accessing metadata when pointer is invalid in object_err()
  scsi: lpfc: Fix buffer free/clear order in deferred receive path
  mm/khugepaged: fix ->anon_vma race
  e1000e: fix heap overflow in e1000_set_eeprom
  batman-adv: fix OOB read/write in network-coding decode
  drm/amdgpu: drop hw access in non-DC audio fini
  wifi: mwifiex: Initialize the chan_stats array to zero
  pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()
  ALSA: usb-audio: Add mute TLV for playback volumes on some devices
  ppp: fix memory leak in pad_compress_skb
  net: atm: fix memory leak in atm_register_sysfs when device_register fail
  ax25: properly unshare skbs in ax25_kiss_rcv()
  ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init()
  net: thunder_bgx: decrement cleanup index before use
  net: thunder_bgx: add a missing of_node_put
  wifi: libertas: cap SSID len in lbs_associate()
  wifi: cw1200: cap SSID length in cw1200_do_join()
  net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets
  i40e: Fix potential invalid access when MAC list is empty
  icmp: fix icmp_ndo_send address translation for reply direction
  mISDN: Fix memory leak in dsp_hwec_enable()
  xirc2ps_cs: fix register access when enabling FullDuplex
  Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
  netfilter: conntrack: helper: Replace -EEXIST by -EBUSY
  wifi: cfg80211: fix use-after-free in cmp_bss()
  powerpc: boot: Remove leading zero in label in udelay()
  Linux 5.4.298
  Revert "drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS"
  net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions
  Revert "drm/amdgpu: fix incorrect vm flags to map bo"
  HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()
  HID: wacom: Add a new Art Pen 2
  HID: asus: fix UAF via HID_CLAIMED_INPUT validation
  KVM: x86: use array_index_nospec with indices that come from guest
  efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
  sctp: initialize more fields in sctp_v6_from_sk()
  net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts
  net/mlx5e: Set local Xoff after FW update
  net/mlx5e: Update and set Xon/Xoff upon port speed set
  net/mlx5e: Update and set Xon/Xoff upon MTU set
  net: dlink: fix multicast stats being counted incorrectly
  atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
  net/atm: remove the atmdev_ops {get, set}sockopt methods
  Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced
  powerpc/kvm: Fix ifdef to remove build warning
  net: ipv4: fix regression in local-broadcast routes
  vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put()
  scsi: core: sysfs: Correct sysfs attributes access rights
  ftrace: Fix potential warning in trace_printk_seq during ftrace_dump
  pinctrl: STMFX: add missing HAS_IOMEM dependency
  Revert "PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports"
  Revert "PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit()"
  Linux 5.4.297
  alloc_fdtable(): change calling conventions.
  s390/hypfs: Enable limited access during lockdown
  s390/hypfs: Avoid unnecessary ioctl registration in debugfs
  ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation
  net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate
  net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
  ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc
  ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add
  ALSA: usb-audio: Fix size validation in convert_chmap_v3()
  scsi: qla4xxx: Prevent a potential error pointer dereference
  usb: xhci: Fix slot_id resource race conflict
  nfs: fix UAF in direct writes
  NFS: Fix up commit deadlocks
  cifs: Fix UAF in cifs_demultiplex_thread()
  Bluetooth: fix use-after-free in device_for_each_child()
  act_mirred: use the backlog for nested calls to mirred ingress
  net/sched: act_mirred: better wording on protection against excessive stack growth
  net/sched: act_mirred: refactor the handle of xmit
  selftests: forwarding: tc_actions.sh: add matchall mirror test
  net: sched: don't expose action qstats to skb_tc_reinsert()
  net: sched: extract qstats update code into functions
  net: sched: extract bstats update code into function
  net: sched: extract common action counters update code into function
  mm: perform the mapping_map_writable() check after call_mmap()
  mm: update memfd seal write check to include F_SEAL_WRITE
  mm: drop the assumption that VM_SHARED always implies writable
  codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
  sch_qfq: make qfq_qlen_notify() idempotent
  sch_hfsc: make hfsc_qlen_notify() idempotent
  sch_drr: make drr_qlen_notify() idempotent
  btrfs: populate otime when logging an inode item
  media: venus: hfi: explicitly release IRQ during teardown
  f2fs: fix to avoid out-of-boundary access in dnode page
  media: venus: protect against spurious interrupts during probe
  media: qcom: camss: cleanup media device allocated resource on error path
  media: venus: vdec: Clamp param smaller than 1fps and bigger than 240.
  drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS
  pwm: mediatek: Fix duty and period setting
  pwm: mediatek: Handle hardware enable and clock enable separately
  pwm: mediatek: Implement .apply() callback
  media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
  media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free()
  media: v4l2-ctrls: always copy the controls on completion
  ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig
  soc: qcom: mdt_loader: Ensure we don't read past the ELF header
  rtc: ds1307: handle oscillator stop flag (OSF) for ds1341
  usb: musb: omap2430: fix device leak at unbind
  NFS: Fix the setting of capabilities when automounting a new filesystem
  NFS: Fix up handling of outstanding layoutcommit in nfs_update_inode()
  NFSv4: Fix nfs4_bitmap_copy_adjust()
  usb: typec: fusb302: cache PD RX state
  cdc-acm: fix race between initial clearing halt and open
  USB: cdc-acm: do not log successful probe on later errors
  mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock
  mm/kmemleak: turn kmemleak_lock and object->lock to raw_spinlock_t
  ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx()
  x86/fpu: Delay instruction pointer fixup until after warning
  mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery
  nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
  pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov
  tracing: Add down_write(trace_event_sem) when adding trace event
  usb: hub: Don't try to recover devices lost during warm reset.
  usb: hub: avoid warm port reset during USB3 disconnect
  x86/mce/amd: Add default names for MCA banks and blocks
  iio: hid-sensor-prox: Fix incorrect OFFSET calculation
  f2fs: fix to do sanity check on ino and xnid
  mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n
  mm/zsmalloc.c: convert to use kmem_cache_zalloc in cache_alloc_zspage()
  drm/sched: Remove optimization that causes hang when killing dependent jobs
  ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
  net: usbnet: Fix the wrong netif_carrier_on() call
  net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
  PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports
  ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value
  comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
  comedi: Fix initialization of data for instructions that write to subdevice
  kbuild: Add KBUILD_CPPFLAGS to as-option invocation
  kbuild: add $(CLANG_FLAGS) to KBUILD_CPPFLAGS
  kbuild: Add CLANG_FLAGS to as-instr
  mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation
  kbuild: Update assembler calls to use proper flags and language target
  ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS
  usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
  USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles
  usb: storage: realtek_cr: Use correct byte order for bcs->Residue
  USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera
  usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive
  iio: proximity: isl29501: fix buffered read on big-endian systems
  ftrace: Also allocate and copy hash for reading of filter files
  fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable()
  use uniform permission checks for all mount propagation changes
  move_mount: allow to add a mount into an existing group
  fs/buffer: fix use-after-free when call bh_read() helper
  drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs
  drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3
  squashfs: fix memory leak in squashfs_fill_super
  memstick: Fix deadlock by moving removing flag earlier
  media: venus: Add a check for packet size after reading from shared memory
  media: ov2659: Fix memory leaks in ov2659_probe()
  media: usbtv: Lock resolution while streaming
  media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init()
  media: gspca: Add bounds checking to firmware parser
  soc/tegra: pmc: Ensure power-domains are in a known state
  jbd2: prevent softlockup in jbd2_log_do_checkpoint()
  PCI: endpoint: Fix configfs group removal on driver teardown
  PCI: endpoint: Fix configfs group list head handling
  mtd: rawnand: fsmc: Add missing check after DMA map
  pwm: imx-tpm: Reset counter if CMOD is 0
  wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table()
  zynq_fpga: use sgtable-based scatterlist wrappers
  ata: libata-scsi: Fix ata_to_sense_error() status handling
  ext4: fix reserved gdt blocks handling in fsmap
  ext4: fix fsmap end of range reporting with bigalloc
  ext4: check fast symlink for ea_inode correctly
  Revert "vgacon: Add check for vc_origin address range in vgacon_scroll()"
  vt: defkeymap: Map keycodes above 127 to K_HOLE
  vt: keyboard: Don't process Unicode characters in K_OFF mode
  usb: dwc3: meson-g12a: fix device leaks at unbind
  usb: gadget: udc: renesas_usb3: fix device leak at unbind
  usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init()
  m68k: Fix lost column on framebuffer debug console
  cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table()
  serial: 8250: fix panic due to PSLVERR
  media: uvcvideo: Do not mark valid metadata as invalid
  media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
  mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup()
  parisc: Makefile: fix a typo in palo.conf
  btrfs: fix log tree replay failure due to file with 0 links and extents
  thunderbolt: Fix copy+paste error in match_service_id()
  comedi: fix race between polling and detaching
  misc: rtsx: usb: Ensure mmc child device is active when card is present
  drm/amdgpu: fix incorrect vm flags to map bo
  scsi: lpfc: Remove redundant assignment to avoid memory leak
  rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe
  pNFS: Fix uninited ptr deref in block/scsi layout
  pNFS: Handle RPC size limit for layoutcommits
  pNFS: Fix disk addr range check in block/scsi layout
  pNFS: Fix stripe mapping in block/scsi layout
  net: phy: smsc: add proper reset flags for LAN8710A
  ipmi: Fix strcpy source and destination the same
  kconfig: lxdialog: fix 'space' to (de)select options
  kconfig: gconf: fix potential memory leak in renderer_edited()
  kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed()
  ipmi: Use dev_warn_ratelimited() for incorrect message warnings
  scsi: aacraid: Stop using PCI_IRQ_AFFINITY
  scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans
  kconfig: nconf: Ensure null termination where strncpy is used
  kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c
  i3c: don't fail if GETHDRCAP is unsupported
  PCI: pnv_php: Work around switches with broken presence detection
  i3c: add missing include to internal header
  media: uvcvideo: Fix bandwidth issue for Alcor camera
  media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
  media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb()
  media: usb: hdpvr: disable zero-length read messages
  media: tc358743: Increase FIFO trigger level to 374
  media: tc358743: Return an appropriate colorspace from tc358743_set_fmt
  media: tc358743: Check I2C succeeded during probe
  pinctrl: stm32: Manage irq affinity settings
  scsi: mpt3sas: Correctly handle ATA device errors
  scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
  RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
  MIPS: Don't crash in stack_top() for tasks without ABI or vDSO
  jfs: upper bound check of tree index in dbAllocAG
  jfs: Regular file corruption check
  jfs: truncate good inode pages when hard link is 0
  scsi: bfa: Double-free fix
  MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free}
  watchdog: dw_wdt: Fix default timeout
  fs/orangefs: use snprintf() instead of sprintf()
  scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
  ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
  cifs: Fix calling CIFSFindFirst() for root path without msearch
  vhost: fail early when __vhost_add_used() fails
  net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325
  uapi: in6: restore visibility of most IPv6 socket options
  net: ncsi: Fix buffer overflow in fetching version id
  net: dsa: b53: prevent SWITCH_CTRL access on BCM5325
  net: dsa: b53: fix b53_imp_vlan_setup for BCM5325
  net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs
  wifi: iwlegacy: Check rate_idx range after addition
  netmem: fix skb_frag_address_safe with unreadable skbs
  wifi: rtlwifi: fix possible skb memory leak in `_rtl_pci_rx_interrupt()`.
  wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect
  wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd()
  net: fec: allow disable coalescing
  (powerpc/512) Fix possible `dma_unmap_single()` on uninitialized pointer
  s390/stp: Remove udelay from stp_sync_clock()
  wifi: iwlwifi: mvm: fix scan request validation
  net: thunderx: Fix format-truncation warning in bgx_acpi_match_id()
  net: ipv4: fix incorrect MTU in broadcast routes
  wifi: cfg80211: Fix interface type validation
  rcu: Protect ->defer_qs_iw_pending from data race
  net: ag71xx: Add missing check after DMA map
  et131x: Add missing check after DMA map
  be2net: Use correct byte order and format string for TCP seq and ack_seq
  s390/time: Use monotonic clock in get_cycles()
  wifi: cfg80211: reject HTC bit for management frames
  ktest.pl: Prevent recursion of default variable options
  ASoC: codecs: rt5640: Retry DEVICE_ID verification
  ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros
  ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
  platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches
  pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop()
  usb: core: usb_submit_urb: downgrade type check
  ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4
  ASoC: hdac_hdmi: Rate limit logging on connection and disconnection
  mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode()
  ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path
  ACPI: processor: fix acpi_object initialization
  PM: sleep: console: Fix the black screen issue
  thermal: sysfs: Return ENODATA instead of EAGAIN for reads
  PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit()
  selftests: tracing: Use mutex_unlock for testing glob filter
  ARM: tegra: Use I/O memcpy to write to IRAM
  gpio: tps65912: check the return value of regmap_update_bits()
  ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed
  ARM: rockchip: fix kernel hang during smp initialization
  cpufreq: Exit governor when failed to start old governor
  usb: xhci: Avoid showing errors during surprise removal
  usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command
  usb: xhci: Avoid showing warnings for dying controller
  selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t
  usb: xhci: print xhci->xhc_state when queue_command failed
  securityfs: don't pin dentries twice, once is enough...
  hfs: fix not erasing deleted b-tree node issue
  drbd: add missing kref_get in handle_write_conflicts
  udf: Verify partition map count
  arm64: Handle KCOV __init vs inline mismatches
  hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file()
  hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
  hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
  hfs: fix slab-out-of-bounds in hfs_bnode_read()
  sctp: linearize cloned gso packets in sctp_rcv
  netfilter: ctnetlink: fix refcount leak on table dump
  udp: also consider secpath when evaluating ipsec use for checksumming
  ACPI: processor: perflib: Move problematic pr->performance check
  ACPI: processor: perflib: Fix initial _PPC limit application
  Documentation: ACPI: Fix parent device references
  fs: Prevent file descriptor table allocations exceeding INT_MAX
  sunvdc: Balance device refcount in vdc_port_mpgroup_check
  NFSD: detect mismatch of file handle and delegation stateid in OPEN op
  net: dpaa: fix device leak when querying time stamp info
  net: gianfar: fix device leak when querying time stamp info
  netlink: avoid infinite retry looping in netlink_unicast()
  ALSA: usb-audio: Validate UAC3 cluster segment descriptors
  ALSA: usb-audio: Validate UAC3 power domain descriptors, too
  io_uring: don't use int for ABI
  usb: gadget : fix use-after-free in composite_dev_cleanup()
  MIPS: mm: tlb-r4k: Uniquify TLB entries on init
  USB: serial: option: add Foxconn T99W709
  vsock: Do not allow binding to VMADDR_PORT_ANY
  net/packet: fix a race in packet_set_ring() and packet_notifier()
  perf/core: Prevent VMA split of buffer mappings
  perf/core: Exit early on perf_mmap() fail
  perf/core: Don't leak AUX buffer refcount on allocation failure
  pptp: fix pptp_xmit() error path
  smb: client: let recv_done() cleanup before notifying the callers.
  benet: fix BUG when creating VFs
  net: drop UFO packets in udp_rcv_segment()
  ipv6: reject malicious packets in ipv6_gso_segment()
  pptp: ensure minimal skb length in pptp_xmit()
  netpoll: prevent hanging NAPI when netcons gets enabled
  NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
  pci/hotplug/pnv-php: Wrap warnings in macro
  pci/hotplug/pnv-php: Improve error msg on power state change failure
  usb: chipidea: udc: fix sleeping function called from invalid context
  f2fs: fix to avoid out-of-boundary access in devs.path
  f2fs: fix to avoid panic in f2fs_evict_inode
  f2fs: fix to avoid UAF in f2fs_sync_inode_meta()
  rtc: pcf8563: fix incorrect maximum clock rate handling
  rtc: hym8563: fix incorrect maximum clock rate handling
  rtc: ds1307: fix incorrect maximum clock rate handling
  module: Restore the moduleparam prefix length check
  bpf: Check flow_dissector ctx accesses are aligned
  mtd: rawnand: atmel: set pmecc data setup time
  mtd: rawnand: atmel: Fix dma_mapping_error() address
  jfs: fix metapage reference count leak in dbAllocCtl
  fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
  crypto: qat - fix seq_file position update in adf_ring_next()
  dmaengine: nbpfaxi: Add missing check after DMA map
  dmaengine: mv_xor: Fix missing check after DMA map and missing unmap
  fs/orangefs: Allow 2 more characters in do_c_string()
  soundwire: stream: restore params when prepare ports fail
  crypto: img-hash - Fix dma_unmap_sg() nents value
  hwrng: mtk - handle devm_pm_runtime_enable errors
  watchdog: ziirave_wdt: check record length in ziirave_firm_verify()
  scsi: isci: Fix dma_unmap_sg() nents value
  scsi: mvsas: Fix dma_unmap_sg() nents value
  scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value
  clk: sunxi-ng: v3s: Fix de clock definition
  perf tests bp_account: Fix leaked file descriptor
  crypto: ccp - Fix crash when rebind ccp device for ccp.ko
  pinctrl: sunxi: Fix memory leak on krealloc failure
  power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set
  clk: davinci: Add NULL check in davinci_lpsc_clk_register()
  mtd: fix possible integer overflow in erase_xfer()
  crypto: marvell/cesa - Fix engine load inaccuracy
  PCI: rockchip-host: Fix "Unexpected Completion" log message
  vrf: Drop existing dst reference in vrf_ip6_input_dst
  selftests: rtnetlink.sh: remove esp4_offload after test
  netfilter: xt_nfacct: don't assume acct name is null-terminated
  can: kvaser_usb: Assign netdev.dev_port based on device channel index
  can: kvaser_pciefd: Store device channel index
  wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE
  Reapply "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()"
  mwl8k: Add missing check after DMA map
  wifi: rtl8xxxu: Fix RX skb size for aggregation disabled
  net/sched: Restrict conditions for adding duplicating netems to qdisc tree
  arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX
  netfilter: nf_tables: adjust lockdep assertions handling
  drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value
  m68k: Don't unregister boot console needlessly
  tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range
  iwlwifi: Add missing check for alloc_ordered_workqueue
  wifi: iwlwifi: Fix memory leak in iwl_mvm_init()
  wifi: rtl818x: Kill URBs before clearing tx status queue
  caif: reduce stack size, again
  bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure
  bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
  staging: nvec: Fix incorrect null termination of battery manufacturer
  samples: mei: Fix building on musl libc
  cpufreq: Init policy->rwsem before it may be possibly used
  ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface
  usb: early: xhci-dbc: Fix early_ioremap leak
  Revert "vmci: Prevent the dispatching of uninitialized payloads"
  pps: fix poll support
  vmci: Prevent the dispatching of uninitialized payloads
  staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()
  ARM: dts: vfxxx: Correctly use two tuples for timer address
  ASoC: ops: dynamically allocate struct snd_ctl_elem_value
  hfsplus: remove mutex_lock check in hfsplus_free_extents
  ASoC: Intel: fix SND_SOC_SOF dependencies
  ethernet: intel: fix building with large NR_CPUS
  usb: phy: mxs: disconnect line when USB charger is attached
  usb: chipidea: add USB PHY event
  usb: chipidea: introduce CI_HDRC_CONTROLLER_VBUS_EVENT glue layer use
  usb: chipidea: udc: protect usb interrupt enable
  usb: chipidea: udc: add new API ci_hdrc_gadget_connect
  ALSA: hda: Add missing NVIDIA HDA codec IDs
  comedi: comedi_test: Fix possible deletion of uninitialized timers
  nilfs2: reject invalid file types when reading inodes
  i2c: qup: jump out of the loop in case of timeout
  net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class
  net: appletalk: Fix use-after-free in AARP proxy probe
  net: appletalk: fix kerneldoc warnings
  RDMA/core: Rate limit GID cache warning messages
  regulator: core: fix NULL dereference on unbind due to stale coupling data
  usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm
  usb: hub: fix detection of high tier USB3 devices behind suspended hubs
  net_sched: sch_sfq: reject invalid perturb period
  net_sched: sch_sfq: move the limit validation
  net_sched: sch_sfq: use a temporary work area for validating configuration
  net_sched: sch_sfq: don't allow 1 packet limit
  net_sched: sch_sfq: handle bigger packets
  net_sched: sch_sfq: annotate data-races around q->perturb_period
  power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition
  power: supply: bq24190_charger: using pm_runtime_resume_and_get instead of pm_runtime_get_sync
  power: supply: bq24190_charger: Fix runtime PM imbalance on error
  xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS
  virtio-net: ensure the received length does not exceed allocated size
  ASoC: fsl_sai: Force a software reset when starting in consumer mode
  usb: dwc3: qcom: Don't leave BCR asserted
  usb: musb: fix gadget state on disconnect
  net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree
  net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime
  Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
  Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
  Bluetooth: SMP: If an unallowed command is received consider it a failure
  Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
  usb: net: sierra: check for no status endpoint
  net/sched: sch_qfq: Fix race condition on qfq_aggregate
  net: emaclite: Fix missing pointer increment in aligned_read()
  comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
  comedi: Fix some signed shift left operations
  comedi: das6402: Fix bit shift out of bounds
  comedi: das16m1: Fix bit shift out of bounds
  comedi: aio_iiro_16: Fix bit shift out of bounds
  comedi: pcl812: Fix bit shift out of bounds
  iio: adc: stm32-adc: Fix race in installing chained IRQ handler
  iio: adc: max1363: Reorder mode_list[] entries
  iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
  soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled
  soc: aspeed: lpc-snoop: Cleanup resources in stack-order
  mmc: sdhci_am654: Workaround for Errata i2312
  mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models
  mmc: bcm2835: Fix dma_unmap_sg() nents value
  memstick: core: Zero initialize id_reg in h_memstick_read_dev_id()
  isofs: Verify inode mode when loading from disk
  dmaengine: nbpfaxi: Fix memory corruption in probe()
  af_packet: fix soft lockup issue caused by tpacket_snd()
  af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd()
  phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept()
  HID: core: do not bypass hid_hw_raw_request
  HID: core: ensure __hid_request reserves the report ID as the first byte
  HID: core: ensure the allocated report buffer can contain the reserved report ID
  pch_uart: Fix dma_sync_sg_for_device() nents value
  Input: xpad - set correct controller type for Acer NGR200
  i2c: stm32: fix the device used for the DMA map
  usb: gadget: configfs: Fix OOB read on empty string write
  USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
  USB: serial: option: add Foxconn T99W640
  USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition

 Conflicts:
	drivers/soc/qcom/mdt_loader.c
	drivers/usb/dwc3/dwc3-qcom.c
	drivers/usb/host/xhci-plat.c
	mm/slub.c
	mm/zsmalloc.c

Change-Id: I83183b507249a323eba0ecec4c7b4b04d76cc7f6
2025-10-08 15:17:54 +03:00
Jason A. Donenfeld
bf427f63a5
UPSTREAM: wireguard: netlink: send staged packets when setting initial private key
Packets bound for peers can queue up prior to the device private key
being set. For example, if persistent keepalive is set, a packet is
queued up to be sent as soon as the device comes up. However, if the
private key hasn't been set yet, the handshake message never sends, and
no timer is armed to retry, since that would be pointless.

But, if a user later sets a private key, the expectation is that those
queued packets, such as a persistent keepalive, are actually sent. So
adjust the configuration logic to account for this edge case, and add a
test case to make sure this works.

Maxim noticed this with a wg-quick(8) config to the tune of:

    [Interface]
    PostUp = wg set %i private-key somefile

    [Peer]
    PublicKey = ...
    Endpoint = ...
    PersistentKeepalive = 25

Here, the private key gets set after the device comes up using a PostUp
script, triggering the bug.

Bug: 254441685
Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Cc: stable@vger.kernel.org
Reported-by: Maxim Cournoyer <maxim.cournoyer@gmail.com>
Tested-by: Maxim Cournoyer <maxim.cournoyer@gmail.com>
Link: https://lore.kernel.org/wireguard/87fs7xtqrv.fsf@gmail.com/
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit f58d0a9b4c6a7a5199c3af967e43cc8b654604d4)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I0b43d5059dca597b637ede74b73338e01c444eef
2025-09-24 12:16:41 +02:00
Jason A. Donenfeld
d418d61ae0
UPSTREAM: wireguard: device: reset peer src endpoint when netns exits
Each peer's endpoint contains a dst_cache entry that takes a reference
to another netdev. When the containing namespace exits, we take down the
socket and prevent future sockets from being created (by setting
creating_net to NULL), which removes that potential reference on the
netns. However, it doesn't release references to the netns that a netdev
cached in dst_cache might be taking, so the netns still might fail to
exit. Since the socket is gimped anyway, we can simply clear all the
dst_caches (by way of clearing the endpoint src), which will release all
references.

However, the current dst_cache_reset function only releases those
references lazily. But it turns out that all of our usages of
wg_socket_clear_peer_endpoint_src are called from contexts that are not
exactly high-speed or bottle-necked. For example, when there's
connection difficulty, or when userspace is reconfiguring the interface.
And in particular for this patch, when the netns is exiting. So for
those cases, it makes more sense to call dst_release immediately. For
that, we add a small helper function to dst_cache.

This patch also adds a test to netns.sh from Hangbin Liu to ensure this
doesn't regress.

Tested-by: Hangbin Liu <liuhangbin@gmail.com>
Reported-by: Xiumei Mu <xmu@redhat.com>
Cc: Toke Høiland-Jørgensen <toke@redhat.com>
Cc: Paolo Abeni <pabeni@redhat.com>
Fixes: 900575aa33a3 ("wireguard: device: avoid circular netns references")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 20ae1d6aa159eb91a9bf09ff92ccaa94dbea92c2)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I8238af8e27da0f33797e7a3120a714f3902335f0
2025-09-24 12:16:39 +02:00
Jason A. Donenfeld
2621d5f5b0
UPSTREAM: wireguard: selftests: actually test for routing loops
We previously removed the restriction on looping to self, and then added
a test to make sure the kernel didn't blow up during a routing loop. The
kernel didn't blow up, thankfully, but on certain architectures where
skb fragmentation is easier, such as ppc64, the skbs weren't actually
being discarded after a few rounds through. But the test wasn't catching
this. So actually test explicitly for massive increases in tx to see if
we have a routing loop. Note that the actual loop problem will need to
be addressed in a different commit.

Fixes: b673e24aad36 ("wireguard: socket: remove errant restriction on looping to self")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 782c72af567fc2ef09bd7615d0307f24de72c7e0)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Ib9bf6aaaf90bde45351c283a31d9e2262ee9c94f
2025-09-24 12:16:39 +02:00
Jason A. Donenfeld
cf1e18aa7a
UPSTREAM: wireguard: selftests: increase default dmesg log size
The selftests currently parse the kernel log at the end to track
potential memory leaks. With these tests now reading off the end of the
buffer, due to recent optimizations, some creation messages were lost,
making the tests think that there was a free without an alloc. Fix this
by increasing the kernel log size.

Fixes: 24b70eeeb4f4 ("wireguard: use synchronize_net rather than synchronize_rcu")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 03ff1b1def73f817e196bf96ab36ac259490bd7c)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: Ie31acfba310512065c468382eee1ac66db0494fb
2025-09-24 12:16:39 +02:00
Jason A. Donenfeld
2cc91ec432
UPSTREAM: wireguard: selftests: test multiple parallel streams
In order to test ndo_start_xmit being called in parallel, explicitly add
separate tests, which should all run on different cores. This should
help tease out bugs associated with queueing up packets from different
cores in parallel. Currently, it hasn't found those types of bugs, but
given future planned work, this is a useful regression to avoid.

Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit d5a49aa6c3e264a93a7d08485d66e346be0969dd)
Bug: 187129171
Signed-off-by: Connor O'Brien <connoro@google.com>
Change-Id: I8415093012d1bb31f87fdcd6ce1c800fbc115cba
2025-09-24 12:16:38 +02:00
Jason A. Donenfeld
6e373c367e
UPSTREAM: wireguard: selftests: remove old conntrack kconfig value
On recent kernels, this config symbol is no longer used.

Reported-by: Rui Salvaterra <rsalvaterra@gmail.com>
Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Cc: stable@vger.kernel.org
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit acf2492b51c9a3c4dfb947f4d3477a86d315150f)
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Iba547203fa30e343a1ed6f46faaae5b9b114b0c1
2025-09-24 12:16:38 +02:00
Jason A. Donenfeld
d84c54b365
UPSTREAM: wireguard: selftests: make sure rp_filter is disabled on vethc
Some distros may enable strict rp_filter by default, which will prevent
vethc from receiving the packets with an unrouteable reverse path address.

Reported-by: Hangbin Liu <liuhangbin@gmail.com>
Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Cc: stable@vger.kernel.org
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit f8873d11d4121aad35024f9379e431e0c83abead)
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I624cc4a1adbf9f9e42ec4c311636341222d7a7f9
2025-09-24 12:16:38 +02:00
Jason A. Donenfeld
441367e097
UPSTREAM: wireguard: device: avoid circular netns references
Before, we took a reference to the creating netns if the new netns was
different. This caused issues with circular references, with two
wireguard interfaces swapping namespaces. The solution is to rather not
take any extra references at all, but instead simply invalidate the
creating netns pointer when that netns is deleted.

In order to prevent this from happening again, this commit improves the
rough object leak tracking by allowing it to account for created and
destroyed interfaces, aside from just peers and keys. That then makes it
possible to check for the object leak when having two interfaces take a
reference to each others' namespaces.

Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 900575aa33a3eaaef802b31de187a85c4a4b4bd0)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I2bf474bc6b687afef14caffae5be5bfe31a554d0
2025-09-24 12:16:36 +02:00
Jason A. Donenfeld
337cac5d57
UPSTREAM: wireguard: selftests: use newer iproute2 for gcc-10
gcc-10 switched to defaulting to -fno-common, which broke iproute2-5.4.
This was fixed in iproute-5.6, so switch to that. Because we're after a
stable testing surface, we generally don't like to bump these
unnecessarily, but in this case, being able to actually build is a basic
necessity.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit ee3c1aa3f34b7842c1557cfe5d8c3f7b8c692de8)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I69ac0a1595d07344dc2e2085395273424df5e0f0
2025-09-24 12:16:36 +02:00
Jason A. Donenfeld
1956371316
UPSTREAM: wireguard: socket: remove errant restriction on looping to self
It's already possible to create two different interfaces and loop
packets between them. This has always been possible with tunnels in the
kernel, and isn't specific to wireguard. Therefore, the networking stack
already needs to deal with that. At the very least, the packet winds up
exceeding the MTU and is discarded at that point. So, since this is
already something that happens, there's no need to forbid the not very
exceptional case of routing a packet back to the same interface; this
loop is no different than others, and we shouldn't special case it, but
rather rely on generic handling of loops in general. This also makes it
easier to do interesting things with wireguard such as onion routing.

At the same time, we add a selftest for this, ensuring that both onion
routing works and infinite routing loops do not crash the kernel. We
also add a test case for wireguard interfaces nesting packets and
sending traffic between each other, as well as the loop in this case
too. We make sure to send some throughput-heavy traffic for this use
case, to stress out any possible recursion issues with the locks around
workqueues.

Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit b673e24aad36981f327a6570412ffa7754de8911)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ib29e0fd0fbae6aff509041f5fbcf046e7248e12b
2025-09-24 12:16:36 +02:00
Jason A. Donenfeld
62e2513fd6
UPSTREAM: wireguard: selftests: use normal kernel stack size on ppc64
While at some point it might have made sense to be running these tests
on ppc64 with 4k stacks, the kernel hasn't actually used 4k stacks on
64-bit powerpc in a long time, and more interesting things that we test
don't really work when we deviate from the default (16k). So, we stop
pushing our luck in this commit, and return to the default instead of
the minimum.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit a0fd7cc87a018df1a17f9d3f0bd994c1f22c6b34)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I1342060abe8f8432b6e26f5926cc5543653512ac
2025-09-24 12:16:36 +02:00
Jason A. Donenfeld
d58b60a549
UPSTREAM: wireguard: noise: error out precomputed DH during handshake rather than config
We precompute the static-static ECDH during configuration time, in order
to save an expensive computation later when receiving network packets.
However, not all ECDH computations yield a contributory result. Prior,
we were just not letting those peers be added to the interface. However,
this creates a strange inconsistency, since it was still possible to add
other weird points, like a valid public key plus a low-order point, and,
like points that result in zeros, a handshake would not complete. In
order to make the behavior more uniform and less surprising, simply
allow all peers to be added. Then, we'll error out later when doing the
crypto if there's an issue. This also adds more separation between the
crypto layer and the configuration layer.

Discussed-with: Mathias Hall-Andersen <mathias@hall-andersen.dk>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 11a7686aa99c7fe4b3f80f6dcccd54129817984d)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I669c4b5365dc4f2e776e76d1916ed70c7cc77c5e
2025-09-24 12:16:35 +02:00
YueHaibing
8bc8826243
UPSTREAM: wireguard: selftests: remove duplicated include <sys/types.h>
This commit removes a duplicated include.

Signed-off-by: YueHaibing <yuehaibing@huawei.com>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 166391159c5deb84795d2ff46e95f276177fa5fb)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I7d144c4f3c9560ecdfdba6d95d7bbcc59fff360a
2025-09-24 12:16:35 +02:00
Jason A. Donenfeld
e30a3bfdda
UPSTREAM: wireguard: selftests: reduce complexity and fix make races
This gives us fewer dependencies and shortens build time, fixes up some
hash checking race conditions, and also fixes missing directory creation
that caused issues on massively parallel builds.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 04ddf1208f03e1dbc39a4619c40eba640051b950)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I2f29c36bb6be7b70e90544629a36cb01e6fc43b5
2025-09-24 12:16:35 +02:00
Jason A. Donenfeld
1063c836fe
UPSTREAM: wireguard: device: use icmp_ndo_send helper
Because wireguard is calling icmp from network device context, it should
use the ndo helper so that the rate limiting applies correctly.  This
commit adds a small test to the wireguard test suite to ensure that the
new functions continue doing the right thing in the context of
wireguard. It does this by setting up a condition that will definately
evoke an icmp error message from the driver, but along a nat'd path.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit a12d7f3cbdc72c7625881c8dc2660fc2c979fdf2)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Iaa18f5c38ff6d5616e5480a9dea5a80ca2980a46
2025-09-24 12:16:35 +02:00
Jason A. Donenfeld
4f1be8308f
UPSTREAM: wireguard: selftests: tie socket waiting to target pid
Without this, we wind up proceeding too early sometimes when the
previous process has just used the same listening port. So, we tie the
listening socket query to the specific pid we're interested in.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 88f404a9b1d75388225b1c67b6dd327cb2182777)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ic222cb4ebfd65d94a1c4d21320dc4ada5335a997
2025-09-24 12:16:35 +02:00