Commit graph

978,462 commits

Author SHA1 Message Date
Axel Rasmussen
3325f0ceaf BACKPORT: FROMGIT: userfaultfd/selftests: exercise minor fault handling shmem support
Enable test_uffdio_minor for test_type == TEST_SHMEM, and modify the test
slightly to pass in / check for the right feature flags.

Link: https://lkml.kernel.org/r/20210302000133.272579-6-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Joe Perches <joe@perches.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wang Qing <wangqing@vivo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 01d5af3a0bc027d51d729cefe3105c7054182df7
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388148/

Conflicts: tools/testing/selftests/vm/userfaultfd.c
(Manual rebase)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I545c6b7058f59fe5bc21d2dd37202209253f1a92
2025-05-18 08:08:42 +00:00
Axel Rasmussen
9302deed1a BACKPORT: FROMGIT: userfaultfd/selftests: reinitialize test context in each test
Currently, the context (fds, mmap-ed areas, etc.) are global.  Each test
mutates this state in some way, in some cases really "clobbering it"
(e.g., the events test mremap-ing area_dst over the top of area_src, or
the minor faults tests overwriting the count_verify values in the test
areas).  We run the tests in a particular order, each test is careful to
make the right assumptions about its starting state, etc.

But, this is fragile.  It's better for a test's success or failure to not
depend on what some other prior test case did to the global state.

To that end, clear and reinitialize the test context at the start of each
test case, so whatever prior test cases did doesn't affect future tests.

This is particularly relevant to this series because the events test's
mremap of area_dst screws up assumptions the minor fault test was relying
on.  This wasn't a problem for hugetlb, as we don't mremap in that case.

Link: https://lkml.kernel.org/r/20210302000133.272579-5-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Joe Perches <joe@perches.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wang Qing <wangqing@vivo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 0108aac75e6d6852e8bba20d5b94e29bf8dc9335
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388145/

Conflicts: tools/testing/selftests/vm/userfaultfd.c
(Manual rebase)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Icf57513cad6f6580114bc5452bfadc5e528434ed
2025-05-18 08:08:42 +00:00
Axel Rasmussen
7e738f2d9a FROMGIT: userfaultfd/selftests: create alias mappings in the shmem test
Previously, we just allocated two shm areas: area_src and area_dst.  With
this commit, change this so we also allocate area_src_alias, and
area_dst_alias.

area_*_alias and area_* (respectively) point to the same underlying
physical pages, but are different VMAs.  In a future commit in this
series, we'll leverage this setup to exercise minor fault handling support
for shmem, just like we do in the hugetlb_shared test.

Link: https://lkml.kernel.org/r/20210302000133.272579-4-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Joe Perches <joe@perches.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wang Qing <wangqing@vivo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 8bc5e62208bcb9427ea6eed94ff1b152598da6f8
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388149/

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I1605dba2d5f0e35bfd57bd9110bb54e950faab19
2025-05-18 08:08:42 +00:00
Axel Rasmussen
195eef95ec FROMGIT: userfaultfd/selftests: use memfd_create for shmem test type
This is a preparatory commit.  In the future, we want to be able to setup
alias mappings for area_src and area_dst in the shmem test, like we do in
the hugetlb_shared test.  With a VMA obtained via mmap(MAP_ANONYMOUS |
MAP_SHARED), it isn't clear how to do this.

So, mmap() with an fd, so we can create alias mappings.  Use memfd_create
instead of actually passing in a tmpfs path like hugetlb does, since it's
more convenient / simpler to run, and works just as well.

Future commits will:

1. Setup the alias mappings.
2. Extend our tests to actually take advantage of this, to test new
   userfaultfd behavior being introduced in this series.

Also, a small fix in the area we're changing: when the hugetlb setup fails
in main(), pass in the right argv[] so we actually print out the hugetlb
file path.

Link: https://lkml.kernel.org/r/20210302000133.272579-3-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Joe Perches <joe@perches.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wang Qing <wangqing@vivo.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit de45daecde2d4793e9021b102e168a4cb656dd03
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388147/

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I63ac39245d4090e275238efa75bcdbd40fcc7879
2025-05-18 08:08:42 +00:00
Axel Rasmussen
1999a272c6 BACKPORT: FROMGIT: userfaultfd: support minor fault handling for shmem
Patch series "userfaultfd: support minor fault handling for shmem", v2.

Overview
========

See my original series [1] for a detailed overview of minor fault handling
in general.  The feature in this series works exactly like the hugetblfs
version (from userspace's perspective).

I'm sending this as a separate series because:

- The original minor fault handling series has a full set of R-Bs, and seems
  close to being merged. So, it seems reasonable to start looking at this next
  step, which extends the basic functionality.

- shmem is different enough that this series may require some additional work
  before it's ready, and I don't want to delay the original series
  unnecessarily by bundling them together.

Use Case
========

In some cases it is useful to have VM memory backed by tmpfs instead of
hugetlbfs.  So, this feature will be used to support the same VM live
migration use case described in my original series.

Additionally, Android folks (Lokesh Gidra <lokeshgidra@google.com>) hope
to optimize the Android Runtime garbage collector using this feature:

"The plan is to use userfaultfd for concurrently compacting the heap.
With this feature, the heap can be shared-mapped at another location where
the GC-thread(s) could continue the compaction operation without the need
to invoke userfault ioctl(UFFDIO_COPY) each time.  OTOH, if and when Java
threads get faults on the heap, UFFDIO_CONTINUE can be used to resume
execution.  Furthermore, this feature enables updating references in the
'non-moving' portion of the heap efficiently.  Without this feature,
uneccessary page copying (ioctl(UFFDIO_COPY)) would be required."

[1] https://lore.kernel.org/linux-fsdevel/20210301222728.176417-1-axelrasmussen@google.com/T/#t

This patch (of 5):

Modify the userfaultfd register API to allow registering shmem VMAs in
minor mode.  Modify the shmem mcopy implementation to support
UFFDIO_CONTINUE in order to resolve such faults.

Combine the shmem mcopy handler functions into a single
shmem_mcopy_atomic_pte, which takes a mode parameter.  This matches how
the hugetlbfs implementation is structured, and lets us remove a good
chunk of boilerplate.

Link: https://lkml.kernel.org/r/20210302000133.272579-1-axelrasmussen@google.com
Link: https://lkml.kernel.org/r/20210302000133.272579-2-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Joe Perches <joe@perches.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Wang Qing <wangqing@vivo.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 4cc6e15679966aa49afc5b114c3c83ba0ac39b05
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388146/

Conflicts: include/linux/shmem_fs.h
	mm/shmem.c
	mm/userfaultfd.c
(1. write-protect related conflicts, rebased manually
2. Enclose shmem_mcopy_atomic_pte() with CONFIG_USERFAULTFD to avoid
compile errors when USERFAULTFD is not enabled.)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Idcd822b2a124a089121b9ad8c65061f6979126ec
2025-05-18 08:08:42 +00:00
Axel Rasmussen
05004f0991 BACKPORT: FROMGIT: userfaultfd/selftests: add test exercising minor fault handling
Fix a dormant bug in userfaultfd_events_test(), where we did `return
faulting_process(0)` instead of `exit(faulting_process(0))`.  This caused
the forked process to keep running, trying to execute any further test
cases after the events test in parallel with the "real" process.

Add a simple test case which exercises minor faults. In short, it does
the following:

1. "Sets up" an area (area_dst) and a second shared mapping to the same
   underlying pages (area_dst_alias).

2. Register one of these areas with userfaultfd, in minor fault mode.

3. Start a second thread to handle any minor faults.

4. Populate the underlying pages with the non-UFFD-registered side of
   the mapping. Basically, memset() each page with some arbitrary
   contents.

5. Then, using the UFFD-registered mapping, read all of the page
   contents, asserting that the contents match expectations (we expect
   the minor fault handling thread can modify the page contents before
   resolving the fault).

The minor fault handling thread, upon receiving an event, flips all the
bits (~) in that page, just to prove that it can modify it in some
arbitrary way.  Then it issues a UFFDIO_CONTINUE ioctl, to setup the
mapping and resolve the fault.  The reading thread should wake up and see
this modification.

Currently the minor fault test is only enabled in hugetlb_shared mode, as
this is the only configuration the kernel feature supports.

Link: https://lkml.kernel.org/r/20210301222728.176417-7-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 823e78ae969c4ae9500cac5a84ee5b923634be4d
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388135/

Conflicts: tools/testing/selftests/vm/userfaultfd.c
(Removed write-protect related test and removed uffd_stats usage)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I93a845d45436d835a4fd5de0dfd8a2c54fa15550
2025-05-18 08:08:42 +00:00
Axel Rasmussen
e896f54b5e BACKPORT: FROMGIT: userfaultfd: update documentation to describe minor fault handling
Reword / reorganize things a little bit into "lists", so new features /
modes / ioctls can sort of just be appended.

Describe how UFFDIO_REGISTER_MODE_MINOR and UFFDIO_CONTINUE can be used to
intercept and resolve minor faults.  Make it clear that COPY and ZEROPAGE
are used for MISSING faults, whereas CONTINUE is used for MINOR faults.

Link: https://lkml.kernel.org/r/20210301222728.176417-6-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit d08ba026886f0161e2bdd3dbd75c4da0fc62a284
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388137/

Conflicts: Documentation/admin-guide/mm/userfaultfd.rst
(Manual rebase by removing text related to write-protect feature)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Ib59504247d38034e4c86f692dd63f2b3706fe554
2025-05-18 08:08:42 +00:00
Axel Rasmussen
5d62f07fff BACKPORT: FROMGIT: userfaultfd: add UFFDIO_CONTINUE ioctl
This ioctl is how userspace ought to resolve "minor" userfaults. The
idea is, userspace is notified that a minor fault has occurred. It might
change the contents of the page using its second non-UFFD mapping, or
not. Then, it calls UFFDIO_CONTINUE to tell the kernel "I have ensured
the page contents are correct, carry on setting up the mapping".

Note that it doesn't make much sense to use UFFDIO_{COPY,ZEROPAGE} for
MINOR registered VMAs. ZEROPAGE maps the VMA to the zero page; but in
the minor fault case, we already have some pre-existing underlying page.
Likewise, UFFDIO_COPY isn't useful if we have a second non-UFFD mapping.
We'd just use memcpy() or similar instead.

It turns out hugetlb_mcopy_atomic_pte() already does very close to what
we want, if an existing page is provided via `struct page **pagep`. We
already special-case the behavior a bit for the UFFDIO_ZEROPAGE case, so
just extend that design: add an enum for the three modes of operation,
and make the small adjustments needed for the MCOPY_ATOMIC_CONTINUE
case. (Basically, look up the existing page, and avoid adding the
existing page to the page cache or calling set_page_huge_active() on
it.)

Link: https://lkml.kernel.org/r/20210301222728.176417-5-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 14ea86439abaf3423cd9b6712ed5ce8451d2d181
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388136/

Conflicts: fs/userfaultfd.c
	include/linux/hugetlb.h
	include/linux/userfaultfd_k.h
	include/uapi/linux/userfaultfd.h
	mm/hugetlb.c
	mm/userfaultfd.c
(1. 8f251a3d5ce3bdea73bd045ed35db64f32e0d0d9 is not cherry-picked yet so
    switched SetHPageMigratable() to set_active_huge_page() in
    mm/hugetlb.c,
2. Other files conflicts due to lack of write-protect userfaultfd
support. Manually rebased accordingly
3. Included linux/mm.h in linux/userfaultfd_k.h for definitions of
VM_UFFD_*)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I45b62959dcb1d343154cb831113a26e47e77c8af
2025-05-18 08:08:42 +00:00
Axel Rasmussen
0bea3b8d35 BACKPORT: FROMGIT: userfaultfd: hugetlbfs: only compile UFFD helpers if config enabled
For background, mm/userfaultfd.c provides a general mcopy_atomic
implementation.  But some types of memory (i.e., hugetlb and shmem) need a
slightly different implementation, so they provide their own helpers for
this.  In other words, userfaultfd is the only caller of these functions.

This patch achieves two things:

1. Don't spend time compiling code which will end up never being
   referenced anyway (a small build time optimization).

2. In patches later in this series, we extend the signature of these
   helpers with UFFD-specific state (a mode enumeration).  Once this
   happens, we *have to* either not compile the helpers, or
   unconditionally define the UFFD-only state (which seems messier to me).
   This includes the declarations in the headers, as otherwise they'd
   yield warnings about implicitly defining the type of those arguments.

Link: https://lkml.kernel.org/r/20210301222728.176417-4-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 0e6e243e1d9a252c047c4cb1b032cfb31caf87ea
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388133/

Conflicts: include/linux/hugetlb.h
(Manual rebase, required as 1f9dccb25b8fb48778149a002bb25d4ac2899633
isn't CP'ed)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I765cff74cde5fb4ce8141fb95e41848890ced961
2025-05-18 08:08:42 +00:00
Axel Rasmussen
84c481c854 FROMGIT: userfaultfd: disable huge PMD sharing for MINOR registered VMAs
As the comment says: for the MINOR fault use case, although the page might
be present and populated in the other (non-UFFD-registered) half of the
mapping, it may be out of date, and we explicitly want userspace to get a
minor fault so it can check and potentially update the page's contents.

Huge PMD sharing would prevent these faults from occurring for suitably
aligned areas, so disable it upon UFFD registration.

Link: https://lkml.kernel.org/r/20210301222728.176417-3-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 19fbec4445b6a690253c1785dfd376ede2cdb9d9
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388134/

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I257024f980f43cf8b06b5421ee3278115d1b1540
2025-05-18 08:08:42 +00:00
Axel Rasmussen
59e978522d BACKPORT: FROMGIT: userfaultfd: add minor fault registration mode
Patch series "userfaultfd: add minor fault handling", v9.

Overview
========

This series adds a new userfaultfd feature, UFFD_FEATURE_MINOR_HUGETLBFS.
When enabled (via the UFFDIO_API ioctl), this feature means that any
hugetlbfs VMAs registered with UFFDIO_REGISTER_MODE_MISSING will *also*
get events for "minor" faults.  By "minor" fault, I mean the following
situation:

Let there exist two mappings (i.e., VMAs) to the same page(s) (shared
memory).  One of the mappings is registered with userfaultfd (in minor
mode), and the other is not.  Via the non-UFFD mapping, the underlying
pages have already been allocated & filled with some contents.  The UFFD
mapping has not yet been faulted in; when it is touched for the first
time, this results in what I'm calling a "minor" fault.  As a concrete
example, when working with hugetlbfs, we have huge_pte_none(), but
find_lock_page() finds an existing page.

We also add a new ioctl to resolve such faults: UFFDIO_CONTINUE.  The idea
is, userspace resolves the fault by either a) doing nothing if the
contents are already correct, or b) updating the underlying contents using
the second, non-UFFD mapping (via memcpy/memset or similar, or something
fancier like RDMA, or etc...).  In either case, userspace issues
UFFDIO_CONTINUE to tell the kernel "I have ensured the page contents are
correct, carry on setting up the mapping".

Use Case
========

Consider the use case of VM live migration (e.g. under QEMU/KVM):

1. While a VM is still running, we copy the contents of its memory to a
   target machine. The pages are populated on the target by writing to the
   non-UFFD mapping, using the setup described above. The VM is still running
   (and therefore its memory is likely changing), so this may be repeated
   several times, until we decide the target is "up to date enough".

2. We pause the VM on the source, and start executing on the target machine.
   During this gap, the VM's user(s) will *see* a pause, so it is desirable to
   minimize this window.

3. Between the last time any page was copied from the source to the target, and
   when the VM was paused, the contents of that page may have changed - and
   therefore the copy we have on the target machine is out of date. Although we
   can keep track of which pages are out of date, for VMs with large amounts of
   memory, it is "slow" to transfer this information to the target machine. We
   want to resume execution before such a transfer would complete.

4. So, the guest begins executing on the target machine. The first time it
   touches its memory (via the UFFD-registered mapping), userspace wants to
   intercept this fault. Userspace checks whether or not the page is up to date,
   and if not, copies the updated page from the source machine, via the non-UFFD
   mapping. Finally, whether a copy was performed or not, userspace issues a
   UFFDIO_CONTINUE ioctl to tell the kernel "I have ensured the page contents
   are correct, carry on setting up the mapping".

We don't have to do all of the final updates on-demand. The userfaultfd manager
can, in the background, also copy over updated pages once it receives the map of
which pages are up-to-date or not.

Interaction with Existing APIs
==============================

Because this is a feature, a registered VMA could potentially receive both
missing and minor faults.  I spent some time thinking through how the
existing API interacts with the new feature:

UFFDIO_CONTINUE cannot be used to resolve non-minor faults, as it does not
allocate a new page.  If UFFDIO_CONTINUE is used on a non-minor fault:

- For non-shared memory or shmem, -EINVAL is returned.
- For hugetlb, -EFAULT is returned.

UFFDIO_COPY and UFFDIO_ZEROPAGE cannot be used to resolve minor faults.
Without modifications, the existing codepath assumes a new page needs to
be allocated.  This is okay, since userspace must have a second
non-UFFD-registered mapping anyway, thus there isn't much reason to want
to use these in any case (just memcpy or memset or similar).

- If UFFDIO_COPY is used on a minor fault, -EEXIST is returned.
- If UFFDIO_ZEROPAGE is used on a minor fault, -EEXIST is returned (or -EINVAL
  in the case of hugetlb, as UFFDIO_ZEROPAGE is unsupported in any case).
- UFFDIO_WRITEPROTECT simply doesn't work with shared memory, and returns
  -ENOENT in that case (regardless of the kind of fault).

Future Work
===========

This series only supports hugetlbfs.  I have a second series in flight to
support shmem as well, extending the functionality.  This series is more
mature than the shmem support at this point, and the functionality works
fully on hugetlbfs, so this series can be merged first and then shmem
support will follow.

This patch (of 6):

This feature allows userspace to intercept "minor" faults.  By "minor"
faults, I mean the following situation:

Let there exist two mappings (i.e., VMAs) to the same page(s).  One of the
mappings is registered with userfaultfd (in minor mode), and the other is
not.  Via the non-UFFD mapping, the underlying pages have already been
allocated & filled with some contents.  The UFFD mapping has not yet been
faulted in; when it is touched for the first time, this results in what
I'm calling a "minor" fault.  As a concrete example, when working with
hugetlbfs, we have huge_pte_none(), but find_lock_page() finds an existing
page.

This commit adds the new registration mode, and sets the relevant flag on
the VMAs being registered.  In the hugetlb fault path, if we find that we
have huge_pte_none(), but find_lock_page() does indeed find an existing
page, then we have a "minor" fault, and if the VMA has the userfaultfd
registration flag, we call into userfaultfd to handle it.

This is implemented as a new registration mode, instead of an API feature.
This is because the alternative implementation has significant drawbacks
[1].

However, doing it this was requires we allocate a VM_* flag for the new
registration mode.  On 32-bit systems, there are no unused bits, so this
feature is only supported on architectures with
CONFIG_ARCH_USES_HIGH_VMA_FLAGS.  When attempting to register a VMA in
MINOR mode on 32-bit architectures, we return -EINVAL.

[1] https://lore.kernel.org/patchwork/patch/1380226/

Link: https://lkml.kernel.org/r/20210301222728.176417-1-axelrasmussen@google.com
Link: https://lkml.kernel.org/r/20210301222728.176417-2-axelrasmussen@google.com
Signed-off-by: Axel Rasmussen <axelrasmussen@google.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Steven Price <steven.price@arm.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 82a150ec394f6b944e26786b907fc0deab5b2064
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1388132/

Conflicts: arch/x86/Kconfig
	fs/userfaultfd.c
	include/linux/userfaultfd_k.h
	include/uapi/linux/userfaultfd.h
	init/Kconfig
	mm/hugetlb.c
(Lack of userfaultfd write-protect support in 5.4 lead to all conflicts.
Resolved by carefully rebasing such that write-protect related code
doesn't get added)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I43b37272d531341439ceaa03213d0e2415e04688
2025-05-18 08:08:42 +00:00
Peter Xu
5f1b26c2cd BACKPORT: FROMGIT: hugetlb/userfaultfd: unshare all pmds for hugetlbfs when register wp
Huge pmd sharing for hugetlbfs is racy with userfaultfd-wp because
userfaultfd-wp is always based on pgtable entries, so they cannot be
shared.

Walk the hugetlb range and unshare all such mappings if there is, right
before UFFDIO_REGISTER will succeed and return to userspace.

This will pair with want_pmd_share() in hugetlb code so that huge pmd
sharing is completely disabled for userfaultfd-wp registered range.

Link: https://lkml.kernel.org/r/20210218231206.15524-1-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 267bda5c9993856b86f91a998df632b29cf517e2
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1382208/
Conflicts:
	mm/hugetlb.c

(CONFIG_CMA not CP'ed in this kernel. Manual rebase)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I99d541ce45aaf924fa912f00dafa4caefe307755
2025-05-18 08:08:42 +00:00
Peter Xu
abc495fa9d FROMGIT: mm/hugetlb: move flush_hugetlb_tlb_range() into hugetlb.h
Prepare for it to be called outside of mm/hugetlb.c.

Link: https://lkml.kernel.org/r/20210218231204.15474-1-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Reviewed-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 04297c667b3972097535638e3dab5a66f11ca1df
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1382206/

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I9bf21fe479548d44a8b611ed832b2f1af7667f4c
2025-05-18 08:08:42 +00:00
Peter Xu
245a106b01 FROMGIT: mm/hugetlb: fix build with !ARCH_WANT_HUGE_PMD_SHARE
want_pmd_share() is undefined with !ARCH_WANT_HUGE_PMD_SHARE since it's
put by accident into a "#ifdef ARCH_WANT_HUGE_PMD_SHARE" block.  Moving it
out won't work either since vma_shareable() is only defined within the
block.  Define it for !ARCH_WANT_HUGE_PMD_SHARE instead.

Link: https://lkml.kernel.org/r/20210310185359.88297-1-peterx@redhat.com
Fixes: 5b109cc1cdcc ("hugetlb/userfaultfd: forbid huge pmd sharing when uffd enabled")
Signed-off-by: Peter Xu <peterx@redhat.com>
Reported-by: Naresh Kamboju <naresh.kamboju@linaro.org>
Tested-by: Naresh Kamboju <naresh.kamboju@linaro.org>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit 5038f9dd8bbde13ff16435011bb3b0981acc5c1c
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1393174/

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Id716afd43bff303f7eda2c4f70f18d9ea727c698
2025-05-18 08:08:42 +00:00
Peter Xu
a7279b3385 BACKPORT: FROMGIT: hugetlb/userfaultfd: forbid huge pmd sharing when uffd enabled
Huge pmd sharing could bring problem to userfaultfd.  The thing is that
userfaultfd is running its logic based on the special bits on page table
entries, however the huge pmd sharing could potentially share page table
entries for different address ranges.  That could cause issues on either:

  - When sharing huge pmd page tables for an uffd write protected range, the
    newly mapped huge pmd range will also be write protected unexpectedly, or,

  - When we try to write protect a range of huge pmd shared range, we'll first
    do huge_pmd_unshare() in hugetlb_change_protection(), however that also
    means the UFFDIO_WRITEPROTECT could be silently skipped for the shared
    region, which could lead to data loss.

Since at it, a few other things are done altogether:

  - Move want_pmd_share() from mm/hugetlb.c into linux/hugetlb.h, because
    that's definitely something that arch code would like to use too

  - ARM64 currently directly check against CONFIG_ARCH_WANT_HUGE_PMD_SHARE when
    trying to share huge pmd.  Switch to the want_pmd_share() helper.

Since at it, move vma_shareable() from huge_pmd_share() into want_pmd_share().

Link: https://lkml.kernel.org/r/20210218231202.15426-1-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Mike Kravetz <mike.kravetz@oracle.com>
Reviewed-by: Axel Rasmussen <axelrasmussen@google.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit ab6a0d00a63f92f1f0d220274fa989eb75c09f2b
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1382207/
Conflicts:
	include/linux/hugetlb.h
	mm/hugetlb.c

(Manual rebase)

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Ie2dff7ab31600cae78914e3278be61516844394e
2025-05-18 08:08:42 +00:00
Peter Xu
c775249492 BACKPORT: FROMGIT: hugetlb: pass vma into huge_pte_alloc() and huge_pmd_share()
Patch series "hugetlb: Disable huge pmd unshare for uffd-wp", v4.

This series tries to disable huge pmd unshare of hugetlbfs backed memory
for uffd-wp.  Although uffd-wp of hugetlbfs is still during rfc stage, the
idea of this series may be needed for multiple tasks (Axel's uffd minor
fault series, and Mike's soft dirty series), so I picked it out from the
larger series.

This patch (of 4):

It is a preparation work to be able to behave differently in the per
architecture huge_pte_alloc() according to different VMA attributes.

Pass it deeper into huge_pmd_share() so that we can avoid the find_vma() call.

Link: https://lkml.kernel.org/r/20210218230633.15028-1-peterx@redhat.com
Link: https://lkml.kernel.org/r/20210218230633.15028-2-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
Suggested-by: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Adam Ruprecht <ruprecht@google.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Alexey Dobriyan <adobriyan@gmail.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Cc: Cannon Matthews <cannonmatthews@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Chinwen Chang <chinwen.chang@mediatek.com>
Cc: David Rientjes <rientjes@google.com>
Cc: "Dr . David Alan Gilbert" <dgilbert@redhat.com>
Cc: Huang Ying <ying.huang@intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: "Matthew Wilcox (Oracle)" <willy@infradead.org>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: "Michal Koutn" <mkoutny@suse.com>
Cc: Michel Lespinasse <walken@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oliver Upton <oupton@google.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Shawn Anastasio <shawn@anastas.io>
Cc: Steven Price <steven.price@arm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>

(cherry picked from commit b92dc1bfd52ecf338c024815a7c1d44e37a507a1
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git akpm)
Link: https://lore.kernel.org/patchwork/patch/1382205/

Conflicts:
	arch/sparc/mm/hugetlbpage.c
	mm/hugetlb.c
	mm/userfaultfd.c

(1. manual rebase,
 2. c0d0381ade79885c04a04c303284b040616b116e wasn't CP'ed. Rebased by
 appropriately updating huge_pte_alloc(),
 3. manual rebase)

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I50db4e27f2951a5ee01b0dfa22c1ece34e79f881
2025-05-18 08:08:42 +00:00
John Hubbard
346a6836ed UPSTREAM: selftests/vm/.gitignore: add mremap_dontunmap
Add mremap_dontunmap to .gitignore.

Fixes: 0c28759ee3c9 ("selftests: add MREMAP_DONTUNMAP selftest")
Signed-off-by: John Hubbard <jhubbard@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Brian Geffon <bgeffon@google.com>
Link: http://lkml.kernel.org/r/20200517002509.362401-2-jhubbard@nvidia.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

(cherry picked from commit 98097701cc0bec06e4bc183cceaf6dfa06a69e10)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Iadb72ad4ffec5d0203214a632b612ff3266695c0
2025-05-18 08:08:42 +00:00
Brian Geffon
c16d9b8365 FROMLIST: selftests: Add a MREMAP_DONTUNMAP selftest for shmem
This test extends the current mremap tests to validate that
the MREMAP_DONTUNMAP operation can be performed on shmem mappings.

Signed-off-by: Brian Geffon <bgeffon@google.com>

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Link: https://lore.kernel.org/patchwork/patch/1401225/
Bug: 160737021
Bug: 169683130
Change-Id: Ib357e58526af739cf8df49fc9604372996a9a6b3
2025-05-18 08:08:42 +00:00
Brian Geffon
7d28c28500 UPSTREAM: selftests: add MREMAP_DONTUNMAP selftest
Add a few simple self tests for the new flag MREMAP_DONTUNMAP, they are
simple smoke tests which also demonstrate the behavior.

[akpm@linux-foundation.org: convert eight-spaces to hard tabs]
[bgeffon@google.com: v7]
  Link: http://lkml.kernel.org/r/20200221174248.244748-2-bgeffon@google.com
[akpm@linux-foundation.org: coding style fixes]
Signed-off-by: Brian Geffon <bgeffon@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: "Michael S . Tsirkin" <mst@redhat.com>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Will Deacon <will@kernel.org>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Cc: Sonny Rao <sonnyrao@google.com>
Cc: Minchan Kim <minchan@kernel.org>
Cc: Joel Fernandes <joel@joelfernandes.org>
Cc: Yu Zhao <yuzhao@google.com>
Cc: Jesse Barnes <jsbarnes@google.com>
Cc: Nathan Chancellor <natechancellor@gmail.com>
Cc: Florian Weimer <fweimer@redhat.com>
Cc: "Kirill A . Shutemov" <kirill@shutemov.name>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Link: http://lkml.kernel.org/r/20200218173221.237674-2-bgeffon@google.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

(cherry picked from commit 0c28759ee3c91fa8ae14d7672b781b979be274e1)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I3380f66b882cc24b7c4b5b29923f929722e7c22a
2025-05-18 08:08:42 +00:00
Alexander Winkowski
5b40652054
qcedev: Fix excessive logging on DRM playback
Change-Id: Idb0224d5213a57b9f0925fe89a1a5c816e3967b2
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
2025-05-18 11:08:08 +03:00
Shashikala Katthi
20e2af2352
usb: dwc3: gadget: Fix break condition in gadget state
Add break condition in gadget state of dwc3_gadget_run_stop_util.

Change-Id: I644ae558558616819a7369d8163a68a74c2bb3fd
Signed-off-by: Shashikala Katthi <quic_skatthi@quicinc.com>
2025-05-18 11:07:00 +03:00
Alexander Winkowski
9f07178ded
Revert "usb: dwc3: Increase DWC3 controller halt timeout"
This reverts commit 935e842f98.

Reason for revert: dwc3_gadget_run_stop() is called from atomic context,
it's wrong to use usleep_range() there.

Change-Id: I5e25f2c1c9de0bba4b28157b6d42ef62f6706dfc
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
2025-05-18 11:05:37 +03:00
Michael Bestas
6544d65e83
Revert "Revert "Revert "8250: add support for ASIX devices with a FIFO bug"""
This reverts commit eea11c5180.

Reason for revert: Build is broken without it,
we don't care about GKI ABI.

Change-Id: I3d7be0324682d01b14863438d8383df16679ef38
2025-05-18 11:04:18 +03:00
Michael Bestas
bbcf9da13a Merge tag 'ASB-2025-05-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-05-01

* tag 'ASB-2025-05-05_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: net_sched: Prevent creation of classes with TC_H_ROOT
  Linux 5.4.292
  jfs: add index corruption check to DT_GETPAGE()
  jfs: fix slab-out-of-bounds read in ea_get()
  tracing: Fix use-after-free in print_graph_function_flags during tracer switching
  mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
  ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
  x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
  x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
  ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
  can: flexcan: only change CAN state when link up in system PM
  arcnet: Add NULL check in com20020pci_probe()
  net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
  ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
  vsock: avoid timeout during connect() if the socket is closing
  net_sched: skbprio: Remove overly strict queue assertions
  netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
  ntb: intel: Fix using link status DB's
  ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
  spufs: fix a leak in spufs_create_context()
  spufs: fix a leak on spufs_new_file() failure
  hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
  can: statistics: use atomic access in hot path
  locking/semaphore: Use wake_q to wake up processes outside lock critical section
  sched/deadline: Use online cpus for validating runtime
  affs: don't write overlarge OFS data block size fields
  affs: generate OFS sequence numbers starting at 1
  wifi: iwlwifi: fw: allocate chained SG tables for dump
  sched/smt: Always inline sched_smt_active()
  octeontx2-af: Fix mbox INTR handler when num VFs > 64
  ring-buffer: Fix bytes_dropped calculation issue
  objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
  fs/procfs: fix the comment above proc_pid_wchan()
  perf python: Check if there is space to copy all the event
  perf python: Decrement the refcount of just created event on failure
  perf python: Fixup description of sample.id event member
  ocfs2: validate l_tree_depth to avoid out-of-bounds access
  kexec: initialize ELF lowest address to ULONG_MAX
  perf units: Fix insufficient array space
  iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
  coresight: catu: Fix number of pages while using 64k pages
  isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
  x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
  mfd: sm501: Switch to BIT() to mitigate integer overflows
  RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
  power: supply: max77693: Fix wrong conversion of charge input threshold value
  x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
  clk: amlogic: g12a: fix mmc A peripheral clock
  clk: amlogic: gxbb: drop non existing 32k clock parent
  clk: amlogic: g12b: fix cluster A parent data
  IB/mad: Check available slots before posting receive WRs
  clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent
  pinctrl: renesas: rza2: Fix missing of_node_put() call
  lib: 842: Improve error handling in sw842_compress()
  bpf: Use preempt_count() directly in bpf_send_signal_common()
  clk: amlogic: gxbb: drop incorrect flag on 32k clock
  fbdev: sm501fb: Add some geometry checks.
  mdacon: rework dependency list
  fbdev: au1100fb: Move a variable assignment behind a null pointer check
  PCI: pciehp: Don't enable HPIE when resuming in poll mode
  PCI: Remove stray put_device() in pci_register_host_bridge()
  PCI/portdrv: Only disable pciehp interrupts early when needed
  PCI/ASPM: Fix link state exit during switch upstream function removal
  drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
  ALSA: hda/realtek: Always honor no_shutup_pins
  perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
  lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*()
  PM: sleep: Fix handling devices with direct_complete set on errors
  thermal: int340x: Add NULL check for adev
  EDAC/ie31200: Fix the error path order of ie31200_init()
  EDAC/ie31200: Fix the DIMM size mask for several SoCs
  EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer
  selinux: Chain up tool resolving errors in install_policy.sh
  x86/platform: Only allow CONFIG_EISA for 32-bit
  x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct()
  cpufreq: governor: Fix negative 'idle_time' handling in dbs_update()
  x86/mm/pat: cpa-test: fix length for CPA_ARRAY test
  serial: 8250_dma: terminate correct DMA in tx_dma_flush()
  memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
  net: usb: usbnet: restore usb%d name exception for local mac addresses
  net: usb: qmi_wwan: add Telit Cinterion FE990B composition
  net: usb: qmi_wwan: add Telit Cinterion FN990B composition
  tty: serial: 8250: Add some more device IDs
  counter: stm32-lptimer-cnt: fix error handling when enabling
  netfilter: socket: Lookup orig tuple for IPv6 SNAT
  ARM: Remove address checking for MMUless devices
  ARM: 9351/1: fault: Add "cut here" line for prefetch aborts
  ARM: 9350/1: fault: Implement copy_from_kernel_nofault_allowed()
  atm: Fix NULL pointer dereference
  HID: hid-plantronics: Add mic mute mapping and generalize quirks
  ALSA: usb-audio: Add quirk for Plantronics headsets to fix control names
  drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
  batman-adv: Ignore own maximum aggregation size during RX
  ARM: shmobile: smp: Enforce shmobile_smp_* alignment
  mmc: atmel-mci: Add missing clk_disable_unprepare()
  drm/v3d: Don't run jobs that have errors flagged in its fence
  i2c: omap: fix IRQ storms
  net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
  net: atm: fix use after free in lec_send()
  ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
  ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
  Bluetooth: Fix error code in chan_alloc_skb_cb()
  RDMA/hns: Fix wrong value of max_sge_rd
  RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
  xfrm_output: Force software GSO only in tunnel mode
  firmware: imx-scu: fix OF node leak in .probe()
  i2c: sis630: Fix an error handling path in sis630_probe()
  i2c: ali15x3: Fix an error handling path in ali15x3_probe()
  i2c: ali1535: Fix an error handling path in ali1535_probe()
  ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
  drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
  qlcnic: fix memory leak issues in qlcnic_sriov_common.c
  drm/amd/display: Assign normalized_pix_clk when color depth = 14
  drm/atomic: Filter out redundant DPMS calls
  x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
  USB: serial: option: match on interface class for Telit FN990B
  USB: serial: option: fix Telit Cinterion FE990A name
  USB: serial: option: add Telit Cinterion FE990B compositions
  USB: serial: ftdi_sio: add support for Altera USB Blaster 3
  block: fix 'kmem_cache of name 'bio-108' already exists'
  drm/nouveau: Do not override forced connector status
  x86/irq: Define trace events conditionally
  fuse: don't truncate cached, mutated symlink
  nvme: only allow entering LIVE from CONNECTING state
  sctp: Fix undefined behavior in left shift operation
  nvmet-rdma: recheck queue state is LIVE in state lock in recv done
  ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
  s390/cio: Fix CHPID "configure" attribute caching
  HID: ignore non-functional sensor in HP 5MP Camera
  HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
  ACPI: resource: IRQ override for Eluktronics MECH-17
  scsi: qla1280: Fix kernel oops when debug level > 2
  iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
  powercap: call put_device() on an error path in powercap_register_control_type()
  hrtimers: Mark is_migration_base() with __always_inline
  nvme-fc: go straight to connecting state when initializing
  net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed devices
  netfilter: nft_exthdr: fix offset with ipv4_find_option()
  net_sched: Prevent creation of classes with TC_H_ROOT
  ipvs: prevent integer overflow in do_ip_vs_get_ctl()
  netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
  Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
  drivers/hv: Replace binary semaphore with mutex
  netpoll: hold rcu read lock in __netpoll_send_skb()
  netpoll: netpoll_send_skb() returns transmit status
  netpoll: move netpoll_send_skb() out of line
  netpoll: remove dev argument from netpoll_send_skb_on_dev()
  netpoll: Fix use correct return type for ndo_start_xmit()
  pinctrl: bcm281xx: Fix incorrect regmap max_registers value
  sctp: sysctl: auth_enable: avoid using current->nsproxy
  sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
  Revert "sctp: sysctl: auth_enable: avoid using current->nsproxy"
  Revert "sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy"
  sched/isolation: Prevent boot crash when the boot CPU is nohz_full
  clockevents/drivers/i8253: Fix stop sequence for timer 0
  vlan: fix memory leak in vlan_newlink()
  Revert "tasklet: Introduce new initialization API"
  Revert "net: usb: rtl8150: use new tasklet API"
  Revert "net: usb: rtl8150: enable basic endpoint checking"
  Revert "usb: xhci: Add timeout argument in address_device USB HCD callback"
  Revert "usb: xhci: Fix NULL pointer dereference on certain command aborts"
  Linux 5.4.291
  eeprom: digsy_mtc: Make GPIO lookup table match the device
  slimbus: messaging: Free transaction ID in delayed interrupt scenario
  intel_th: pci: Add Panther Lake-P/U support
  intel_th: pci: Add Panther Lake-H support
  intel_th: pci: Add Arrow Lake support
  Squashfs: check the inode number is not the invalid value of zero
  xhci: pci: Fix indentation in the PCI device ID definitions
  usb: gadget: Check bmAttributes only if configuration is valid
  usb: gadget: Fix setting self-powered state on suspend
  usb: gadget: Set self-powered based on MaxPower and bmAttributes
  usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix functionality
  usb: typec: ucsi: increase timeout for PPM reset operations
  usb: atm: cxacru: fix a flaw in existing endpoint checks
  usb: renesas_usbhs: Flush the notify_hotplug_work
  usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass Storage Card Reader
  usb: renesas_usbhs: Use devm_usb_get_phy()
  usb: renesas_usbhs: Call clk_put()
  Revert "drivers/card_reader/rtsx_usb: Restore interrupt based detection"
  gpio: rcar: Fix missing of_node_put() call
  net: ipv6: fix missing dst ref drop in ila lwtunnel
  net: ipv6: fix dst ref loop in ila lwtunnel
  net-timestamp: support TCP GSO case for a few missing flags
  vlan: enforce underlying device type
  ppp: Fix KMSAN uninit-value warning with bpf
  be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
  drm/sched: Fix preprocessor guard
  hwmon: fix a NULL vs IS_ERR_OR_NULL() check in xgene_hwmon_probe()
  llc: do not use skb_get() before dev_queue_xmit()
  hwmon: (ad7314) Validate leading zero bits and return error
  hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
  hwmon: (pmbus) Initialise page count in pmbus_identify()
  caif_virtio: fix wrong pointer check in cfv_probe()
  net: gso: fix ownership in __udp_gso_segment
  HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
  HID: google: fix unused variable warning under !CONFIG_ACPI
  wifi: iwlwifi: limit printed string from FW file
  mm/page_alloc: fix uninitialized variable
  rapidio: fix an API misues when rio_add_net() fails
  rapidio: add check for rio_add_net() in rio_scan_alloc_net()
  wifi: nl80211: reject cooked mode if it is set along with other flags
  wifi: cfg80211: regulatory: improve invalid hints checking
  x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63
  x86/cpu: Validate CPUID leaf 0x2 EDX output
  x86/cacheinfo: Validate CPUID leaf 0x2 EDX output
  platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad X131e
  drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress 200M
  ALSA: hda/realtek: update ALC222 depop optimize
  ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
  HID: appleir: Fix potential NULL dereference at raw event handle
  Revert "of: reserved-memory: Fix using wrong number of cells to get property 'alignment'"
  drm/amdgpu: disable BAR resize on Dell G5 SE
  drm/amdgpu: Check extended configuration space register when system uses large bar
  drm/amdgpu: skip BAR resizing if the bios already did it
  acct: perform last write from workqueue
  kernel/acct.c: use dedicated helper to access rlimit values
  kernel/acct.c: use #elif instead of #end and #elif
  drop_monitor: fix incorrect initialization order
  pfifo_tail_enqueue: Drop new packet when sch->limit == 0
  sched/core: Prevent rescheduling when interrupts are disabled
  phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL masks in refclk
  phy: tegra: xusb: reset VBUS & ID OVERRIDE
  usbnet: gl620a: fix endpoint checking in genelink_bind()
  perf/core: Fix low freq setting via IOC_PERIOD
  ftrace: Avoid potential division by zero in function_stat_show()
  x86/CPU: Fix warm boot hang regression on AMD SC1100 SoC systems
  net: mvpp2: cls: Fixed Non IP flow, with vlan tag flow defination.
  ipvs: Always clear ipvs_property flag in skb_scrub_packet()
  ASoC: es8328: fix route from DAC to output
  net: cadence: macb: Synchronize stats calculations
  net: loopback: Avoid sending IP packets without an Ethernet header
  sunrpc: suppress warnings for unused procfs functions
  batman-adv: Drop unmanaged ELP metric worker
  batman-adv: Ignore neighbor throughput metrics in error case
  acct: block access to kernel internal filesystems
  ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
  nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
  tee: optee: Fix supplicant wait loop
  power: supply: da9150-fg: fix potential overflow
  flow_dissector: Fix port range key handling in BPF conversion
  flow_dissector: Fix handling of mixed port and port-range keys
  net: extract port range fields from fl_flow_key
  geneve: Suppress list corruption splat in geneve_destroy_tunnels().
  gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
  geneve: Fix use-after-free in geneve_find_dev().
  powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC
  ALSA: hda/realtek: Fixup ALC225 depop procedure
  ALSA: hda/realtek - Add type for ALC287
  powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as static inline
  powerpc/64s/mm: Move __real_pte stubs into hash-4k.h
  USB: gadget: f_midi: f_midi_complete to call queue_work
  usb/gadget: f_midi: Replace tasklet with work
  usb/gadget: f_midi: convert tasklets to use new tasklet_setup() API
  usb: dwc3: Fix timeout issue during controller enter/exit from halt state
  usb: dwc3: Increase DWC3 controller halt timeout
  memcg: fix soft lockup in the OOM process
  mm: update mark_victim tracepoints fields
  crypto: testmgr - some more fixes to RSA test vectors
  crypto: testmgr - populate RSA CRT parameters in RSA test vectors
  crypto: testmgr - fix version number of RSA tests
  crypto: testmgr - Fix wrong test case of RSA
  crypto: testmgr - fix wrong key length for pkcs1pad
  driver core: bus: Fix double free in driver API bus_register()
  scsi: storvsc: Set correct data length for sending SCSI command without payload
  vlan: move dev_put into vlan_dev_uninit
  vlan: introduce vlan_dev_free_egress_priority
  ima: Fix use-after-free on a dentry's dname.name
  pps: Fix a use-after-free
  btrfs: avoid monopolizing a core when activating a swap file
  Revert "btrfs: avoid monopolizing a core when activating a swap file"
  x86/i8253: Disable PIT timer 0 when not in use
  parport_pc: add support for ASIX AX99100
  serial: 8250_pci: add support for ASIX AX99100
  can: ems_pci: move ASIX AX99100 ids to pci_ids.h
  nilfs2: protect access to buffers with no active references
  nilfs2: do not force clear folio if buffer is referenced
  nilfs2: do not output warnings when clearing dirty buffers
  alpha: replace hardcoded stack offsets with autogenerated ones
  ndisc: extend RCU protection in ndisc_send_skb()
  openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
  arp: use RCU protection in arp_xmit()
  neighbour: use RCU protection in __neigh_notify()
  neighbour: delete redundant judgment statements
  ndisc: use RCU protection in ndisc_alloc_skb()
  ipv6: use RCU protection in ip6_default_advmss()
  ipv4: use RCU protection in inet_select_addr()
  ipv4: use RCU protection in rt_is_expired()
  net: add dev_net_rcu() helper
  net: treat possible_net_t net pointer as an RCU one and add read_pnet_rcu()
  regmap-irq: Add missing kfree()
  partitions: mac: fix handling of bogus partition table
  gpio: stmpe: Check return value of stmpe_reg_read in stmpe_gpio_irq_sync_unlock
  alpha: align stack for page fault and user unaligned trap handlers
  serial: 8250: Fix fifo underflow on flush
  alpha: make stack 16-byte aligned (most cases)
  can: j1939: j1939_sk_send_loop(): fix unable to send messages with data length zero
  can: c_can: fix unbalanced runtime PM disable in error path
  USB: serial: option: drop MeiG Smart defines
  USB: serial: option: fix Telit Cinterion FN990A name
  USB: serial: option: add Telit Cinterion FN990B compositions
  USB: serial: option: add MeiG Smart SLM828
  usb: cdc-acm: Fix handling of oversized fragments
  usb: cdc-acm: Check control transfer buffer size before access
  USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
  USB: hub: Ignore non-compliant devices with too many configs or interfaces
  usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
  USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
  USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
  USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
  usb: dwc2: gadget: remove of_node reference upon udc_stop
  usb: gadget: udc: renesas_usb3: Fix compiler warning
  usb: roles: set switch registered flag early on
  batman-adv: fix panic during interface removal
  ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V
  orangefs: fix a oob in orangefs_debug_write
  Grab mm lock before grabbing pt lock
  vfio/pci: Enable iowrite64 and ioread64 for vfio pci
  media: cxd2841er: fix 64-bit division on gcc-9
  x86/xen: allow larger contiguous memory regions in PV guests
  xen: remove a confusing comment on auto-translated guest I/O
  gpio: bcm-kona: Add missing newline to dev_err format string
  gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting IRQ
  gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
  arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
  team: better TEAM_OPTION_TYPE_STRING validation
  vrf: use RCU protection in l3mdev_l3_out()
  ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
  HID: multitouch: Add NULL check in mt_input_configured
  ocfs2: check dir i_size in ocfs2_find_entry
  MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static
  ptp: Ensure info->enable callback is always set
  net/ncsi: wait for the last response to Deselect Package before configuring channel
  misc: fastrpc: Fix registered buffer page address
  mtd: onenand: Fix uninitialized retlen in do_otp_read()
  NFC: nci: Add bounds checking in nci_hci_create_pipe()
  nilfs2: fix possible int overflows in nilfs_fiemap()
  ocfs2: handle a symlink read error correctly
  ocfs2: fix incorrect CPU endianness conversion causing mount failure
  vfio/platform: check the bounds of read/write syscalls
  nvmem: core: improve range check for nvmem_cell_write()
  crypto: qce - unregister previously registered algos in error path
  crypto: qce - fix goto jump in error path
  media: uvcvideo: Remove redundant NULL assignment
  media: uvcvideo: Fix event flags in uvc_ctrl_send_events
  media: ov5640: fix get_light_freq on auto
  soc: qcom: smem_state: fix missing of_node_put in error path
  kbuild: Move -Wenum-enum-conversion to W=2
  powerpc/pseries/eeh: Fix get PE state translation
  serial: sh-sci: Do not probe the serial port if its slot in sci_ports[] is in use
  serial: sh-sci: Drop __initdata macro for port_cfg
  soc: qcom: socinfo: Avoid out of bounds read of serial number
  usb: gadget: f_tcm: Don't prepare BOT write request twice
  usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
  usb: gadget: f_tcm: Decrement command ref count on cleanup
  usb: gadget: f_tcm: Translate error to sense
  wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()
  HID: hid-sensor-hub: don't use stale platform-data on remove
  of: reserved-memory: Fix using wrong number of cells to get property 'alignment'
  of: Fix of_find_node_opts_by_path() handling of alias+path+options
  of: Correct child specifier used as input of the 2nd nexus node
  perf bench: Fix undefined behavior in cmpworker()
  clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
  clk: qcom: clk-alpha-pll: fix alpha mode configuration
  Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
  drm/komeda: Add check for komeda_get_layer_fourcc_list()
  KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
  KVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
  arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma
  binfmt_flat: Fix integer overflow bug on 32 bit systems
  m68k: vga: Fix I/O defines
  s390/futex: Fix FUTEX_OP_ANDN implementation
  leds: lp8860: Write full EEPROM, not only half of it
  cpufreq: s3c64xx: Fix compilation warning
  tun: revert fix group permission check
  netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
  net: rose: lock the socket in rose_bind()
  udp: gso: do not drop small packets when PMTU reduces
  tg3: Disable tg3 PCIe AER on system reboot
  gpu: drm_dp_cec: fix broken CEC adapter properties check
  firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry
  nvme: handle connectivity loss in nvme_set_queue_count
  usb: xhci: Fix NULL pointer dereference on certain command aborts
  usb: xhci: Add timeout argument in address_device USB HCD callback
  net: usb: rtl8150: enable basic endpoint checking
  net: usb: rtl8150: use new tasklet API
  tasklet: Introduce new initialization API
  kbuild: userprogs: use correct lld when linking through clang
  sched: sch_cake: add bounds checks to host bulk flow fairness counts
  media: uvcvideo: Remove dangling pointers
  media: uvcvideo: Only save async fh if success
  nilfs2: handle errors that nilfs_prepare_chunk() may return
  nilfs2: eliminate staggered calls to kunmap in nilfs_rename
  nilfs2: move page release outside of nilfs_delete_entry and nilfs_set_link
  spi-mxs: Fix chipselect glitch
  x86/mm: Don't disable PCID when INVLPG has been fixed by microcode
  APEI: GHES: Have GHES honor the panic= setting
  HID: Wacom: Add PCI Wacom device support
  mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
  tomoyo: don't emit warning in tomoyo_write_control()
  wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()
  mmc: core: Respect quirk_max_rate for non-UHS SDIO card
  tun: fix group permission check
  printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
  x86/amd_nb: Restrict init function to AMD-based systems
  sched: Don't try to catch up excess steal time.
  btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error handling
  btrfs: fix use-after-free when attempting to join an aborted transaction
  btrfs: output the reason for open_ctree() failure
  usb: gadget: f_tcm: Don't free command immediately
  media: uvcvideo: Fix double free in error path
  HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections
  usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to PD_T_SENDER_RESPONSE
  drivers/card_reader/rtsx_usb: Restore interrupt based detection
  ktest.pl: Check kernelrelease return in get_version
  NFSD: Reset cb_seq_status after NFS4ERR_DELAY
  hexagon: Fix unbalanced spinlock in die()
  hexagon: fix using plain integer as NULL pointer warning in cmpxchg
  genksyms: fix memory leak when the same symbol is read from *.symref file
  genksyms: fix memory leak when the same symbol is added from source
  net: sh_eth: Fix missing rtnl lock in suspend/resume path
  vsock: Allow retrying on connect() failure
  perf trace: Fix runtime error of index out of bounds
  net: davicom: fix UAF in dm9000_drv_remove
  net: rose: fix timer races against user threads
  PM: hibernate: Add error handling for syscore_suspend()
  ipmr: do not call mr_mfc_uses_dev() for unres entries
  net: fec: implement TSO descriptor cleanup
  ubifs: skip dumping tnc tree when zroot is null
  rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
  dmaengine: ti: edma: fix OF node reference leaks in edma_driver
  module: Extend the preempt disabled section in dereference_symbol_descriptor().
  ocfs2: mark dquot as inactive if failed to start trans while releasing dquot
  scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
  scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
  staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()
  media: uvcvideo: Propagate buf->error to userspace
  media: camif-core: Add check for clk_enable()
  media: mipi-csis: Add check for clk_enable()
  PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
  media: lmedm04: Handle errors for lme2510_int_read
  media: lmedm04: Use GFP_KERNEL for URB allocation/submission.
  media: rc: iguanair: handle timeouts
  fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()
  ARM: dts: mediatek: mt7623: fix IR nodename
  arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names
  arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property
  rdma/cxgb4: Prevent potential integer overflow on 32bit
  RDMA/mlx4: Avoid false error about access to uninitialized gids array
  bpf: Send signals asynchronously if !preemptible
  perf report: Fix misleading help message about --demangle
  perf top: Don't complain about lack of vmlinux when not resolving some kernel samples
  padata: fix sysfs store callback check
  ktest.pl: Remove unused declarations in run_bisect_test function
  perf header: Fix one memory leakage in process_bpf_prog_info()
  perf header: Fix one memory leakage in process_bpf_btf()
  ASoC: sun4i-spdif: Add clock multiplier settings
  tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind
  net: sched: Disallow replacing of child qdisc from one parent to another
  net/mlxfw: Drop hard coded max FW flash image size
  net: let net.core.dev_weight always be non-zero
  clk: analogbits: Fix incorrect calculation of vco rate delta
  selftests: harness: fix printing of mismatch values in __EXPECT()
  selftests/harness: Display signed values correctly
  wifi: wlcore: fix unbalanced pm_runtime calls
  regulator: of: Implement the unwind path of of_regulator_match()
  team: prevent adding a device which is already a team device lower
  cpupower: fix TSC MHz calculation
  wifi: rtlwifi: pci: wait for firmware loading before releasing memory
  wifi: rtlwifi: fix memory leaks and invalid access at probe error path
  wifi: rtlwifi: remove unused check_buddy_priv
  wifi: rtlwifi: remove unused dualmac control leftovers
  wifi: rtlwifi: remove unused timer and related code
  rtlwifi: replace usage of found with dedicated list iterator variable
  dt-bindings: mmc: controller: clarify the address-cells description
  wifi: rtlwifi: usb: fix workqueue leak when probe fails
  wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last step
  rtlwifi: rtl8192se Rename RT_TRACE to rtl_dbg
  wifi: rtlwifi: do not complete firmware loading needlessly
  ipmi: ipmb: Add check devm_kasprintf() returned value
  drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table
  drm/etnaviv: Fix page property being used for non writecombine buffers
  partitions: ldm: remove the initial kernel-doc notation
  nbd: don't allow reconnect after disconnect
  afs: Fix directory format encoding struct
  overflow: Allow mixed type arguments
  overflow: Correct check_shl_overflow() comment
  overflow: Add __must_check attribute to check_*() helpers
  udf: Fix use of check_add_overflow() with mixed type arguments
  perf cs-etm: Add missing variable in cs_etm__process_queues()

 Conflicts:
	Documentation/devicetree/bindings/mmc/mmc-controller.yaml
	Documentation/devicetree/bindings~HEAD
	drivers/clk/qcom/clk-alpha-pll.c
	drivers/soc/qcom/socinfo.c
	drivers/usb/dwc3/gadget.c
	mm/oom_kill.c
	scripts/Makefile.extrawarn

Change-Id: I599df88164649e325b40d25cb1a8e64e5fd27cf0
2025-05-18 08:00:20 +00:00
lixiong
1f82cea219
arm64: dts: qcom: Fix missing thermal cooling device thermal-cpufreq-0
Description: lack thermal cooling device thermal-cpufreq-0, and small cpu
core is limited to 576M during running ES.

Change-Id: Ib8b19c22ca569b5f35700e6c65913100b96a13ea
Reviewed-on: https://gerrit.mot.com/3205502
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Wei Wei <weiweij@motorola.com>
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Reviewed-by: <zzy103@motorola.com>
Submit-Approved: Jira Key
2025-05-05 10:06:09 +03:00
Hardik Gajjar
0db4cc475d
usb: gadget: f_ncm: Always set current gadget in ncm_bind()
[ Upstream commit a04224da1f3424b2c607b12a3bd1f0e302fb8231 ]

Previously, gadget assignment to the net device occurred exclusively
during the initial binding attempt.

Nevertheless, the gadget pointer could change during bind/unbind
cycles due to various conditions, including the unloading/loading
of the UDC device driver or the detachment/reconnection of an
OTG-capable USB hub device.

This patch relocates the gether_set_gadget() function out from
ncm_opts->bound condition check, ensuring that the correct gadget
is assigned during each bind request.

The provided logs demonstrate the consistency of ncm_opts throughout
the power cycle, while the gadget may change.

* OTG hub connected during boot up and assignment of gadget and
  ncm_opts pointer

[    2.366301] usb 2-1.5: New USB device found, idVendor=2996, idProduct=0105
[    2.366304] usb 2-1.5: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[    2.366306] usb 2-1.5: Product: H2H Bridge
[    2.366308] usb 2-1.5: Manufacturer: Aptiv
[    2.366309] usb 2-1.5: SerialNumber: 13FEB2021
[    2.427989] usb 2-1.5: New USB device found, VID=2996, PID=0105
[    2.428959] dabridge 2-1.5:1.0: dabridge 2-4 total endpoints=5, 0000000093a8d681
[    2.429710] dabridge 2-1.5:1.0: P(0105) D(22.06.22) F(17.3.16) H(1.1) high-speed
[    2.429714] dabridge 2-1.5:1.0: Hub 2-2 P(0151) V(06.87)
[    2.429956] dabridge 2-1.5:1.0: All downstream ports in host mode

[    2.430093] gadget 000000003c414d59 ------> gadget pointer

* NCM opts and associated gadget pointer during First ncm_bind

[   34.763929] NCM opts 00000000aa304ac9
[   34.763930] NCM gadget 000000003c414d59

* OTG capable hub disconnecte or assume driver unload.

[   97.203114] usb 2-1: USB disconnect, device number 2
[   97.203118] usb 2-1.1: USB disconnect, device number 3
[   97.209217] usb 2-1.5: USB disconnect, device number 4
[   97.230990] dabr_udc deleted

* Reconnect the OTG hub or load driver assaign new gadget pointer.

[  111.534035] usb 2-1.1: New USB device found, idVendor=2996, idProduct=0120, bcdDevice= 6.87
[  111.534038] usb 2-1.1: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[  111.534040] usb 2-1.1: Product: Vendor
[  111.534041] usb 2-1.1: Manufacturer: Aptiv
[  111.534042] usb 2-1.1: SerialNumber: Superior
[  111.535175] usb 2-1.1: New USB device found, VID=2996, PID=0120
[  111.610995] usb 2-1.5: new high-speed USB device number 8 using xhci-hcd
[  111.630052] usb 2-1.5: New USB device found, idVendor=2996, idProduct=0105, bcdDevice=21.02
[  111.630055] usb 2-1.5: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[  111.630057] usb 2-1.5: Product: H2H Bridge
[  111.630058] usb 2-1.5: Manufacturer: Aptiv
[  111.630059] usb 2-1.5: SerialNumber: 13FEB2021
[  111.687464] usb 2-1.5: New USB device found, VID=2996, PID=0105
[  111.690375] dabridge 2-1.5:1.0: dabridge 2-8 total endpoints=5, 000000000d87c961
[  111.691172] dabridge 2-1.5:1.0: P(0105) D(22.06.22) F(17.3.16) H(1.1) high-speed
[  111.691176] dabridge 2-1.5:1.0: Hub 2-6 P(0151) V(06.87)
[  111.691646] dabridge 2-1.5:1.0: All downstream ports in host mode

[  111.692298] gadget 00000000dc72f7a9 --------> new gadget ptr on connect

* NCM opts and associated gadget pointer during second ncm_bind

[  113.271786] NCM opts 00000000aa304ac9 -----> same opts ptr used during first bind
[  113.271788] NCM gadget 00000000dc72f7a9 ----> however new gaget ptr, that will not set
                                                 in net_device due to ncm_opts->bound = true

Change-Id: I803f892ccd2a0f9558d4f32d8a3104aba78353ff
Signed-off-by: Hardik Gajjar <hgajjar@de.adit-jv.com>
Link: https://lore.kernel.org/r/20231020153324.82794-1-hgajjar@de.adit-jv.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-04-26 21:17:22 +03:00
Lorenzo Colitti
305e9e4cf9
FROMGIT: usb: gadget: u_ether: support configuring interface names.
This patch allows the administrator to configure the interface
name of a function using u_ether (e.g., eem, ncm, rndis).

Currently, all such interfaces, regardless of function type, are
always called usb0, usb1, etc. This makes it very cumbersome to
use more than one such type at a time, because userspace cannnot
easily tell the interfaces apart and apply the right
configuration to each one. Interface renaming in userspace based
on driver doesn't help, because the interfaces all have the same
driver. Without this patch, doing this require hacks/workarounds
such as setting fixed MAC addresses on the functions, and then
renaming by MAC address, or scraping configfs after each
interface is created to find out what it is.

Setting the interface name is done by writing to the same
"ifname" configfs attribute that reports the interface name after
the function is bound. The write must contain an interface
pattern such as "usb%d" (which will cause the net core to pick
the next available interface name starting with "usb").
This patch does not allow writing an exact interface name (as
opposed to a pattern) because if the interface already exists at
bind time, the bind will fail and the whole gadget will fail to
activate. This could be allowed in a future patch.

For compatibility with current userspace, when reading an ifname
that has not currently been set, the result is still "(unnamed
net_device)". Once a write to ifname happens, then reading ifname
will return whatever was last written.

Tested by configuring an rndis function and an ncm function on
the same gadget, and writing "rndis%d" to ifname on the rndis
function and "ncm%d" to ifname on the ncm function. When the
gadget was bound, the rndis interface was rndis0 and the ncm
interface was ncm0.

Signed-off-by: Lorenzo Colitti <lorenzo@google.com>
(cherry picked from commit 63d152149b2d0860ccf8c4e6596b6175b2b7ace6
 https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-next)
Link: https://lore.kernel.org/r/20210113234222.3272933-1-lorenzo@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lorenzo Colitti <lorenzo@google.com>
Change-Id: I04deb6cc1d8a5b8ee82404940de2a79c06fbafe7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-04-26 21:17:22 +03:00
Jack Pham
3e79ef2602
usb: gadget: f_ncm: Revert to upstream
Revert the following changes to restore to upstream version:

commit 006d8adf55 ("usb: gadget: f_ncm: allocate/free net device upon driver bind/unbind")
commit ad2d551ece ("usb: gadget: Add check gadget function bind or not")

Reason for revert: Causes gether_set_ifname() support to kernel panic.

Change-Id: I51064467cad63e47a4a9734f18f1a5b95fa8db86
2025-04-26 21:17:21 +03:00
Sevenrock
365ffb9892
mm: page_owner: Fix -Wstrlcpy-strlcat-size
mm/page_owner.c:944:39: error:
 size argument in 'strlcpy' call appears to be size of the source;
 expected the size of the destination [-Werror,-Wstrlcpy-strlcat-size]
  944 |         strlcpy(call_site->name, buf, strlen(buf));
      |                                       ~~~~~~~^~~~
mm/page_owner.c:944:32: note:
 change size argument to be the size of the destination
  944 |         strlcpy(call_site->name, buf, strlen(buf));
      |                                       ^~~~~~~~~~~
      |                                       sizeof(call_site->name)

https://github.com/LineageOS/android_kernel_qcom_sm8450/blob/lineage-20/drivers/soc/qcom/minidump_memory.c#L692
contains the same code.

Change-Id: Id06f67fe18f2e00dd180afaf99c7577787198cc3
Signed-off-by: Sevenrock <sevenrock@hotmail.de>
2025-04-26 21:17:21 +03:00
LuK1337
20d7404d1e
Revert "hrtimers: Handle CPU state correctly on hotplug"
Causes sleep of death.

This reverts commit 95e4f62df2.

Change-Id: Id3e5f5a71b7d2d57aaa1b9bba7b4ef02221bdba7
2025-04-26 12:28:45 +02:00
Greg Kroah-Hartman
1aec9e76fe Merge tag 'android11-5.4.292_r00' into android11-5.4
This merges the android11-5.4.292_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

*   9b78f083cb Merge 5.4.292 into android11-5.4-lts
|\
| * 1b01d9c341 Linux 5.4.292
| * 2809029821 jfs: add index corruption check to DT_GETPAGE()
| * 3d6fd5b9c6 jfs: fix slab-out-of-bounds read in ea_get()
| * 42561fe62c tracing: Fix use-after-free in print_graph_function_flags during tracer switching
| * 922a70031c mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
| * a7d0f84a31 ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
| * 618d5612ec x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
| * c0189c02b5 x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
| * 2414095a8c ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
| * a1ef4447b8 can: flexcan: only change CAN state when link up in system PM
| * 661cf5d102 arcnet: Add NULL check in com20020pci_probe()
| * 5309432c67 net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
| * 87c53a1c65 ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
| * 42df95e5ea vsock: avoid timeout during connect() if the socket is closing
| * 7abc8318ce net_sched: skbprio: Remove overly strict queue assertions
| * 1ad9166cab netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
| * b9f2980327 ntb: intel: Fix using link status DB's
| * f56951f211 ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
| * 829bd61399 spufs: fix a leak in spufs_create_context()
| * b1eef06d10 spufs: fix a leak on spufs_new_file() failure
| * 5214156633 hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
| * 12d344d74c can: statistics: use atomic access in hot path
| * d6ae75c3ba locking/semaphore: Use wake_q to wake up processes outside lock critical section
| * 0ab44f03c5 sched/deadline: Use online cpus for validating runtime
| * 04039a3806 affs: don't write overlarge OFS data block size fields
| * 739499e146 affs: generate OFS sequence numbers starting at 1
| * f5302f6786 wifi: iwlwifi: fw: allocate chained SG tables for dump
| * 99bd64445f sched/smt: Always inline sched_smt_active()
| * da3b90f71b octeontx2-af: Fix mbox INTR handler when num VFs > 64
| * 4a760b682e ring-buffer: Fix bytes_dropped calculation issue
| * 536f7f3595 objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
| * 6601c04a87 fs/procfs: fix the comment above proc_pid_wchan()
| * 38dffe995b perf python: Check if there is space to copy all the event
| * 213ee3d738 perf python: Decrement the refcount of just created event on failure
| * 58edf5e6a3 perf python: Fixup description of sample.id event member
| * ef34840bda ocfs2: validate l_tree_depth to avoid out-of-bounds access
| * 8a3ebead12 kexec: initialize ELF lowest address to ULONG_MAX
| * 466806997a perf units: Fix insufficient array space
| * d1696caf8b iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
| * 61c6dc3b55 coresight: catu: Fix number of pages while using 64k pages
| * 99c737ec34 isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
| * 85a17b9ab3 x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
| * 2bf98cc76b mfd: sm501: Switch to BIT() to mitigate integer overflows
| * 3b97d77049 RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
| * a4be0b575a power: supply: max77693: Fix wrong conversion of charge input threshold value
| * b26152f504 x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
| * 62ae4a1b29 clk: amlogic: g12a: fix mmc A peripheral clock
| * 450a1d9eac clk: amlogic: gxbb: drop non existing 32k clock parent
| * d15e95d7b8 clk: amlogic: g12b: fix cluster A parent data
| * 0c23a6f147 IB/mad: Check available slots before posting receive WRs
| * 64f805c30c clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent
| * f53c2937ab pinctrl: renesas: rza2: Fix missing of_node_put() call
| * 37e63b0af9 lib: 842: Improve error handling in sw842_compress()
| * 794d6b4b4e bpf: Use preempt_count() directly in bpf_send_signal_common()
| * 671760004d clk: amlogic: gxbb: drop incorrect flag on 32k clock
| * 90ab169fb9 fbdev: sm501fb: Add some geometry checks.
| * 38b9a21a75 mdacon: rework dependency list
| * ab846209f4 fbdev: au1100fb: Move a variable assignment behind a null pointer check
| * ed8bf338d7 PCI: pciehp: Don't enable HPIE when resuming in poll mode
| * 70a83ba1df PCI: Remove stray put_device() in pci_register_host_bridge()
| * c6f9613a22 PCI/portdrv: Only disable pciehp interrupts early when needed
| * 0a0f9aecf6 PCI/ASPM: Fix link state exit during switch upstream function removal
| * 6038b90cdf drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
| * b66baefc08 ALSA: hda/realtek: Always honor no_shutup_pins
| * fc50ed312c perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
| * c6d87a552c lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*()
| * 41b5a58878 PM: sleep: Fix handling devices with direct_complete set on errors
| * d0d21c8e44 thermal: int340x: Add NULL check for adev
| * cc4b161029 EDAC/ie31200: Fix the error path order of ie31200_init()
| * 563493f22c EDAC/ie31200: Fix the DIMM size mask for several SoCs
| * eb96456b70 EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer
| * 095a5cba17 selinux: Chain up tool resolving errors in install_policy.sh
| * e6748cbbbd x86/platform: Only allow CONFIG_EISA for 32-bit
| * 3b2e1ce751 x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct()
| * 73cee9b56a cpufreq: governor: Fix negative 'idle_time' handling in dbs_update()
| * c918f836a4 x86/mm/pat: cpa-test: fix length for CPA_ARRAY test
| * 0d510e175b serial: 8250_dma: terminate correct DMA in tx_dma_flush()
| * 914c5e5bfc memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
| * e206041b55 net: usb: usbnet: restore usb%d name exception for local mac addresses
| * 52ea3f5803 net: usb: qmi_wwan: add Telit Cinterion FE990B composition
| * c960ab007a net: usb: qmi_wwan: add Telit Cinterion FN990B composition
| * 16eed55a08 tty: serial: 8250: Add some more device IDs
| * b7e4d3d707 counter: stm32-lptimer-cnt: fix error handling when enabling
| * 6488b96a79 netfilter: socket: Lookup orig tuple for IPv6 SNAT
| * 0387a57cc9 ARM: Remove address checking for MMUless devices
| * 1c078dadb4 ARM: 9351/1: fault: Add "cut here" line for prefetch aborts
| * 11bb05969b ARM: 9350/1: fault: Implement copy_from_kernel_nofault_allowed()
| * ab92f51c7f atm: Fix NULL pointer dereference
| * b93e9fd3ee HID: hid-plantronics: Add mic mute mapping and generalize quirks
| * ece47d9213 ALSA: usb-audio: Add quirk for Plantronics headsets to fix control names
| * 0effb378eb drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
| * 9bd50100ee batman-adv: Ignore own maximum aggregation size during RX
| * 8310e6a1c9 ARM: shmobile: smp: Enforce shmobile_smp_* alignment
| * 450cd5f5fe mmc: atmel-mci: Add missing clk_disable_unprepare()
| * a354b8bbdf drm/v3d: Don't run jobs that have errors flagged in its fence
| * d3e4439a79 i2c: omap: fix IRQ storms
| * 9dcf9db183 net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
| * 50e288097c net: atm: fix use after free in lec_send()
| * f400408c5e ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
| * 16267a5036 ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
| * b3d607e36f Bluetooth: Fix error code in chan_alloc_skb_cb()
| * 2cf5228644 RDMA/hns: Fix wrong value of max_sge_rd
| * 7cfd80fa58 RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
| * 4f0f83799a xfrm_output: Force software GSO only in tunnel mode
| * d541325120 firmware: imx-scu: fix OF node leak in .probe()
| * c9e2b3b231 i2c: sis630: Fix an error handling path in sis630_probe()
| * 20521ee78c i2c: ali15x3: Fix an error handling path in ali15x3_probe()
| * 75148adf8c i2c: ali1535: Fix an error handling path in ali1535_probe()
| * f26d827172 ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
| * 5d45755de5 drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
| * 880295b68a qlcnic: fix memory leak issues in qlcnic_sriov_common.c
| * cca3ab74f9 drm/amd/display: Assign normalized_pix_clk when color depth = 14
| * 31ed3586f4 drm/atomic: Filter out redundant DPMS calls
| * d509c47310 x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
| * 2175d3c126 USB: serial: option: match on interface class for Telit FN990B
| * f26a86f829 USB: serial: option: fix Telit Cinterion FE990A name
| * 57f6ae8b88 USB: serial: option: add Telit Cinterion FE990B compositions
| * abb9f684f8 USB: serial: ftdi_sio: add support for Altera USB Blaster 3
| * 8d8e2c9961 block: fix 'kmem_cache of name 'bio-108' already exists'
| * f6e43f6aea drm/nouveau: Do not override forced connector status
| * f8e635b762 x86/irq: Define trace events conditionally
| * 34468b2e39 fuse: don't truncate cached, mutated symlink
| * e7fa90c0cb nvme: only allow entering LIVE from CONNECTING state
| * 36256b2447 sctp: Fix undefined behavior in left shift operation
| * 72f676364d nvmet-rdma: recheck queue state is LIVE in state lock in recv done
| * 3dbbc37db8 ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
| * 8b3c9b69fa s390/cio: Fix CHPID "configure" attribute caching
| * 9af297aea8 HID: ignore non-functional sensor in HP 5MP Camera
| * bfa6d90db3 HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
| * cc4d9d3a1e ACPI: resource: IRQ override for Eluktronics MECH-17
| * afa27b7c17 scsi: qla1280: Fix kernel oops when debug level > 2
| * a858cd58de iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
| * 6752747a11 powercap: call put_device() on an error path in powercap_register_control_type()
| * 66beda69bb hrtimers: Mark is_migration_base() with __always_inline
| * 27b2f3dc04 nvme-fc: go straight to connecting state when initializing
| * bb728b5521 net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed devices
| * aaeefb9868 netfilter: nft_exthdr: fix offset with ipv4_find_option()
| * e05d9938b1 net_sched: Prevent creation of classes with TC_H_ROOT
| * ab45c0ee54 ipvs: prevent integer overflow in do_ip_vs_get_ctl()
| * f522229c55 netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
| * ca61dc0c2f Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
| * 1485aaf8d7 drivers/hv: Replace binary semaphore with mutex
| * 6a3c34e875 netpoll: hold rcu read lock in __netpoll_send_skb()
| * 413691c54e netpoll: netpoll_send_skb() returns transmit status
| * e3235e0486 netpoll: move netpoll_send_skb() out of line
| * ddf5458095 netpoll: remove dev argument from netpoll_send_skb_on_dev()
| * 0945ed0e62 netpoll: Fix use correct return type for ndo_start_xmit()
| * 9cc1b39f5a pinctrl: bcm281xx: Fix incorrect regmap max_registers value
| * cf387cdebf sctp: sysctl: auth_enable: avoid using current->nsproxy
| * 5599b212d2 sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
| * 19573dcddb Revert "sctp: sysctl: auth_enable: avoid using current->nsproxy"
| * 2ced96df87 Revert "sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy"
| * 769f2099d9 sched/isolation: Prevent boot crash when the boot CPU is nohz_full
| * 9f89d4ad21 clockevents/drivers/i8253: Fix stop sequence for timer 0
| * 549de58dba vlan: fix memory leak in vlan_newlink()
* | 51aa3bfef8 Revert "tasklet: Introduce new initialization API"
* | fa82985d52 Revert "net: usb: rtl8150: use new tasklet API"
* | 2461d9a37e Revert "net: usb: rtl8150: enable basic endpoint checking"
* | eb00272aa5 Revert "usb: xhci: Add timeout argument in address_device USB HCD callback"
* | 4364e0f8cf Revert "usb: xhci: Fix NULL pointer dereference on certain command aborts"
* | d6a7c6fab0 Merge 5.4.291 into android11-5.4-lts
|\|
| * 52bcf31d8e Linux 5.4.291
| * 7f24cff72a eeprom: digsy_mtc: Make GPIO lookup table match the device
| * cec8c0ac17 slimbus: messaging: Free transaction ID in delayed interrupt scenario
| * 5619084876 intel_th: pci: Add Panther Lake-P/U support
| * 3940fe7d0c intel_th: pci: Add Panther Lake-H support
| * 8740a9ddc4 intel_th: pci: Add Arrow Lake support
| * 32c114a582 Squashfs: check the inode number is not the invalid value of zero
| * e722515dab xhci: pci: Fix indentation in the PCI device ID definitions
| * 19b3918840 usb: gadget: Check bmAttributes only if configuration is valid
| * 9af1d5c4d5 usb: gadget: Fix setting self-powered state on suspend
| * 7367e87b6e usb: gadget: Set self-powered based on MaxPower and bmAttributes
| * 094b49dec3 usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix functionality
| * b654e4c757 usb: typec: ucsi: increase timeout for PPM reset operations
| * dcd592ab9d usb: atm: cxacru: fix a flaw in existing endpoint checks
| * 4cd847a7b6 usb: renesas_usbhs: Flush the notify_hotplug_work
| * a5c8be5903 usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass Storage Card Reader
| * 97f8c81570 usb: renesas_usbhs: Use devm_usb_get_phy()
| * d1968edada usb: renesas_usbhs: Call clk_put()
| * 0971d857c2 Revert "drivers/card_reader/rtsx_usb: Restore interrupt based detection"
| * efbddfb96c gpio: rcar: Fix missing of_node_put() call
| * a3895a367f net: ipv6: fix missing dst ref drop in ila lwtunnel
| * c2fb9104b3 net: ipv6: fix dst ref loop in ila lwtunnel
| * 4ca4dce141 net-timestamp: support TCP GSO case for a few missing flags
| * 7f1564b2b2 vlan: enforce underlying device type
| * d685096c81 ppp: Fix KMSAN uninit-value warning with bpf
| * 797bb9439c be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
| * f5a7fa426a drm/sched: Fix preprocessor guard
| * 7a115f431b hwmon: fix a NULL vs IS_ERR_OR_NULL() check in xgene_hwmon_probe()
| * cd1c44327b llc: do not use skb_get() before dev_queue_xmit()
| * b205ac53a6 hwmon: (ad7314) Validate leading zero bits and return error
| * 90b2aee418 hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
| * d51369e720 hwmon: (pmbus) Initialise page count in pmbus_identify()
| * 990fff6980 caif_virtio: fix wrong pointer check in cfv_probe()
| * 9f28205ddb net: gso: fix ownership in __udp_gso_segment
| * 0c1fb475ef HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
| * 8ecee2b056 HID: google: fix unused variable warning under !CONFIG_ACPI
| * 38f0d398b6 wifi: iwlwifi: limit printed string from FW file
| * b7f3090f19 mm/page_alloc: fix uninitialized variable
| * d4ec862ce8 rapidio: fix an API misues when rio_add_net() fails
| * 6d22953c4a rapidio: add check for rio_add_net() in rio_scan_alloc_net()
| * 5ea856d937 wifi: nl80211: reject cooked mode if it is set along with other flags
| * 62b1a9bbfe wifi: cfg80211: regulatory: improve invalid hints checking
| * 62c602f3c7 x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63
| * c67b103a8d x86/cpu: Validate CPUID leaf 0x2 EDX output
| * 0d1275424f x86/cacheinfo: Validate CPUID leaf 0x2 EDX output
| * 9616539e62 platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad X131e
| * 1f75482717 drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress 200M
| * 19abf50b6c ALSA: hda/realtek: update ALC222 depop optimize
| * 07bc341d61 ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
| * 6db423b009 HID: appleir: Fix potential NULL dereference at raw event handle
| * 38807477c1 Revert "of: reserved-memory: Fix using wrong number of cells to get property 'alignment'"
| * f1f5e41577 drm/amdgpu: disable BAR resize on Dell G5 SE
| * d6566c66c2 drm/amdgpu: Check extended configuration space register when system uses large bar
| * fa996df875 drm/amdgpu: skip BAR resizing if the bios already did it
| * 8acbf4a88c acct: perform last write from workqueue
| * 8d30d9dde5 kernel/acct.c: use dedicated helper to access rlimit values
| * 1b18a0118c kernel/acct.c: use #elif instead of #end and #elif
| * 6e9e0f224f drop_monitor: fix incorrect initialization order
| * 78285b5326 pfifo_tail_enqueue: Drop new packet when sch->limit == 0
| * 321794b75a sched/core: Prevent rescheduling when interrupts are disabled
| * 4af1aff347 phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL masks in refclk
| * 074f4e6284 phy: tegra: xusb: reset VBUS & ID OVERRIDE
| * 5f2dbabbce usbnet: gl620a: fix endpoint checking in genelink_bind()
| * 813822972e perf/core: Fix low freq setting via IOC_PERIOD
| * 5b3d32f607 ftrace: Avoid potential division by zero in function_stat_show()
| * 58446f9868 x86/CPU: Fix warm boot hang regression on AMD SC1100 SoC systems
| * 7ff67d1967 net: mvpp2: cls: Fixed Non IP flow, with vlan tag flow defination.
| * 747010edd6 ipvs: Always clear ipvs_property flag in skb_scrub_packet()
| * aa91462f1f ASoC: es8328: fix route from DAC to output
| * a15efcf84f net: cadence: macb: Synchronize stats calculations
| * c75c6e6e4f net: loopback: Avoid sending IP packets without an Ethernet header
| * a049c2d86c sunrpc: suppress warnings for unused procfs functions
| * 1c33462917 batman-adv: Drop unmanaged ELP metric worker
| * 77bff7bb11 batman-adv: Ignore neighbor throughput metrics in error case
| * fe7343b8a3 acct: block access to kernel internal filesystems
| * 521ad61fc4 ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
| * d64c6ca420 nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
| * 3eb4911364 tee: optee: Fix supplicant wait loop
| * 3c6e8129a4 power: supply: da9150-fg: fix potential overflow
| * 607b0b1c83 flow_dissector: Fix port range key handling in BPF conversion
| * c67e23568e flow_dissector: Fix handling of mixed port and port-range keys
| * 895d04846e net: extract port range fields from fl_flow_key
| * d37e36db58 geneve: Suppress list corruption splat in geneve_destroy_tunnels().
| * 7f86fb07db gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
| * d5e86e27de geneve: Fix use-after-free in geneve_find_dev().
| * 97de585205 powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC
| * 206c9a8f57 ALSA: hda/realtek: Fixup ALC225 depop procedure
| * 85d63c559b ALSA: hda/realtek - Add type for ALC287
| * 2ecb663224 powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as static inline
| * fc4f8ac3b9 powerpc/64s/mm: Move __real_pte stubs into hash-4k.h
| * 727dee0857 USB: gadget: f_midi: f_midi_complete to call queue_work
| * 89019ab7a6 usb/gadget: f_midi: Replace tasklet with work
| * ec42b4a0eb usb/gadget: f_midi: convert tasklets to use new tasklet_setup() API
| * 19aad69c2b usb: dwc3: Fix timeout issue during controller enter/exit from halt state
| * 935e842f98 usb: dwc3: Increase DWC3 controller halt timeout
| * 72f2c0b7c1 memcg: fix soft lockup in the OOM process
| * de3f6e7a84 mm: update mark_victim tracepoints fields
| * 3758d1ed60 crypto: testmgr - some more fixes to RSA test vectors
| * 5ecee5d5ee crypto: testmgr - populate RSA CRT parameters in RSA test vectors
| * 3a2f1eb708 crypto: testmgr - fix version number of RSA tests
| * 1bd5831c65 crypto: testmgr - Fix wrong test case of RSA
| * 321cc1d830 crypto: testmgr - fix wrong key length for pkcs1pad
| * 87bc3cb23c driver core: bus: Fix double free in driver API bus_register()
| * 0196802993 scsi: storvsc: Set correct data length for sending SCSI command without payload
| * eab83178ee vlan: move dev_put into vlan_dev_uninit
| * b195d229de vlan: introduce vlan_dev_free_egress_priority
| * 480afcbeb7 ima: Fix use-after-free on a dentry's dname.name
| * 785c78ed0d pps: Fix a use-after-free
| * 41d3c605bf btrfs: avoid monopolizing a core when activating a swap file
| * ed0c0c7de0 Revert "btrfs: avoid monopolizing a core when activating a swap file"
| * 67f70e61b8 x86/i8253: Disable PIT timer 0 when not in use
| * 81b605bbcd parport_pc: add support for ASIX AX99100
| * 14ffcc4571 serial: 8250_pci: add support for ASIX AX99100
| * 753ad96cdd can: ems_pci: move ASIX AX99100 ids to pci_ids.h
| * e1fc4a90a9 nilfs2: protect access to buffers with no active references
| * 7d0544bacc nilfs2: do not force clear folio if buffer is referenced
| * 1ca6d471f8 nilfs2: do not output warnings when clearing dirty buffers
| * 24d59c41e2 alpha: replace hardcoded stack offsets with autogenerated ones
| * 10a1f3fece ndisc: extend RCU protection in ndisc_send_skb()
| * e85a25d1a9 openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
| * 10f555e3f5 arp: use RCU protection in arp_xmit()
| * e1aed6be38 neighbour: use RCU protection in __neigh_notify()
| * c5d53d3ad4 neighbour: delete redundant judgment statements
| * 96fc896d0e ndisc: use RCU protection in ndisc_alloc_skb()
| * 78ad057472 ipv6: use RCU protection in ip6_default_advmss()
| * 8cc8e1285a ipv4: use RCU protection in inet_select_addr()
| * 155298112a ipv4: use RCU protection in rt_is_expired()
| * 7f86ac1f40 net: add dev_net_rcu() helper
| * fde36de3b4 net: treat possible_net_t net pointer as an RCU one and add read_pnet_rcu()
| * ef539316c5 regmap-irq: Add missing kfree()
| * a3e77da9f8 partitions: mac: fix handling of bogus partition table
| * 9cb4edb23c gpio: stmpe: Check return value of stmpe_reg_read in stmpe_gpio_irq_sync_unlock
| * 7ec1e5e9f2 alpha: align stack for page fault and user unaligned trap handlers
| * bbec5998d7 serial: 8250: Fix fifo underflow on flush
| * ab4f7b1d95 alpha: make stack 16-byte aligned (most cases)
| * 1abecca55d can: j1939: j1939_sk_send_loop(): fix unable to send messages with data length zero
| * 85069553d1 can: c_can: fix unbalanced runtime PM disable in error path
| * 039cc7d94d USB: serial: option: drop MeiG Smart defines
| * 6621ddcdda USB: serial: option: fix Telit Cinterion FN990A name
| * b95bd1248b USB: serial: option: add Telit Cinterion FN990B compositions
| * 2b03876842 USB: serial: option: add MeiG Smart SLM828
| * 7cfb70e97f usb: cdc-acm: Fix handling of oversized fragments
| * a4e1ae5c05 usb: cdc-acm: Check control transfer buffer size before access
| * 42b3050171 USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
| * 49f077106f USB: hub: Ignore non-compliant devices with too many configs or interfaces
| * 3a983390d1 usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
| * a0a18484ce USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
| * a120aad69e USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
| * 2b8a7cfefd USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
| * 1c231617ac usb: dwc2: gadget: remove of_node reference upon udc_stop
| * 3d921d29d4 usb: gadget: udc: renesas_usb3: Fix compiler warning
| * 27a15815af usb: roles: set switch registered flag early on
| * 167422a070 batman-adv: fix panic during interface removal
| * c4edbd5429 ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V
| * 18b7f84110 orangefs: fix a oob in orangefs_debug_write
| * c0c082fef5 Grab mm lock before grabbing pt lock
| * d85ab22daa vfio/pci: Enable iowrite64 and ioread64 for vfio pci
| * dde407d931 media: cxd2841er: fix 64-bit division on gcc-9
| * e9d30ea730 x86/xen: allow larger contiguous memory regions in PV guests
| * 386c8657fe xen: remove a confusing comment on auto-translated guest I/O
| * 69c84cf3b1 gpio: bcm-kona: Add missing newline to dev_err format string
| * f40d5f0169 gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting IRQ
| * 9b4d03e5c0 gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
| * 4371ac7b49 arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
| * 7c30483d0f team: better TEAM_OPTION_TYPE_STRING validation
| * 6ccaa5797f vrf: use RCU protection in l3mdev_l3_out()
| * a4b3863fe7 ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
| * a04d96ef67 HID: multitouch: Add NULL check in mt_input_configured
| * 3cb901b8a9 ocfs2: check dir i_size in ocfs2_find_entry
| * 16e8693eb2 MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static
| * fdc1e72487 ptp: Ensure info->enable callback is always set
| * 70dc66d0cb net/ncsi: wait for the last response to Deselect Package before configuring channel
| * b04fd7cdd8 misc: fastrpc: Fix registered buffer page address
| * 2535f15d31 mtd: onenand: Fix uninitialized retlen in do_otp_read()
| * bd249109d2 NFC: nci: Add bounds checking in nci_hci_create_pipe()
| * 7649937987 nilfs2: fix possible int overflows in nilfs_fiemap()
| * cd3e22b206 ocfs2: handle a symlink read error correctly
| * 970ef46c6d ocfs2: fix incorrect CPU endianness conversion causing mount failure
| * 9377cdc118 vfio/platform: check the bounds of read/write syscalls
| * 406c63ceea nvmem: core: improve range check for nvmem_cell_write()
| * 8c735ef894 crypto: qce - unregister previously registered algos in error path
| * f933d3b26a crypto: qce - fix goto jump in error path
| * d7b11ef0c3 media: uvcvideo: Remove redundant NULL assignment
| * 4823ab3781 media: uvcvideo: Fix event flags in uvc_ctrl_send_events
| * 85b3a78845 media: ov5640: fix get_light_freq on auto
| * 5d50d51d50 soc: qcom: smem_state: fix missing of_node_put in error path
| * 6e3e74dd04 kbuild: Move -Wenum-enum-conversion to W=2
| * 1130e26e3e powerpc/pseries/eeh: Fix get PE state translation
| * 0367db43eb serial: sh-sci: Do not probe the serial port if its slot in sci_ports[] is in use
| * 8119f3afb6 serial: sh-sci: Drop __initdata macro for port_cfg
| * 7445fa0531 soc: qcom: socinfo: Avoid out of bounds read of serial number
| * cc4e1d76a1 usb: gadget: f_tcm: Don't prepare BOT write request twice
| * 54e7215ed1 usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
| * 6e10b792fb usb: gadget: f_tcm: Decrement command ref count on cleanup
| * 5e051636b4 usb: gadget: f_tcm: Translate error to sense
| * 2326e19190 wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize()
| * b64e9092ab HID: hid-sensor-hub: don't use stale platform-data on remove
| * 4aac5315dc of: reserved-memory: Fix using wrong number of cells to get property 'alignment'
| * 8c4178d2d0 of: Fix of_find_node_opts_by_path() handling of alias+path+options
| * b3f14fccde of: Correct child specifier used as input of the 2nd nexus node
| * 7cd71d7574 perf bench: Fix undefined behavior in cmpworker()
| * 523003eb6c clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
| * 5d549136fa clk: qcom: clk-alpha-pll: fix alpha mode configuration
| * a9a7672fc1 Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
| * 737c74bc17 drm/komeda: Add check for komeda_get_layer_fourcc_list()
| * a5ddf2626d KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
| * 5cce2ed69b KVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
| * db9088f402 arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma
| * 0b6be54d73 binfmt_flat: Fix integer overflow bug on 32 bit systems
| * 15e94cfebc m68k: vga: Fix I/O defines
| * c763d34193 s390/futex: Fix FUTEX_OP_ANDN implementation
| * 2f50af0ca0 leds: lp8860: Write full EEPROM, not only half of it
| * 619708ef44 cpufreq: s3c64xx: Fix compilation warning
| * a2bfaf4ce2 tun: revert fix group permission check
| * e395fec75a netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
| * b8bf5c3fb7 net: rose: lock the socket in rose_bind()
| * 4fae092c3c udp: gso: do not drop small packets when PMTU reduces
| * 558d3acef0 tg3: Disable tg3 PCIe AER on system reboot
| * fe8b241e5e gpu: drm_dp_cec: fix broken CEC adapter properties check
| * 309b493990 firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry
| * 3a1aeef304 nvme: handle connectivity loss in nvme_set_queue_count
| * fd8bfaeba4 usb: xhci: Fix NULL pointer dereference on certain command aborts
| * 7032df572e usb: xhci: Add timeout argument in address_device USB HCD callback
| * 431be4f782 net: usb: rtl8150: enable basic endpoint checking
| * 88892dabac net: usb: rtl8150: use new tasklet API
| * 21dc5a1de2 tasklet: Introduce new initialization API
| * 579fac0e5c kbuild: userprogs: use correct lld when linking through clang
| * 44fe1efb49 sched: sch_cake: add bounds checks to host bulk flow fairness counts
| * 2a29413ace media: uvcvideo: Remove dangling pointers
| * 1df994d852 media: uvcvideo: Only save async fh if success
| * b38c6c260c nilfs2: handle errors that nilfs_prepare_chunk() may return
| * 620e036978 nilfs2: eliminate staggered calls to kunmap in nilfs_rename
| * 49d80141af nilfs2: move page release outside of nilfs_delete_entry and nilfs_set_link
| * dff1553c27 spi-mxs: Fix chipselect glitch
| * 7220b2446e x86/mm: Don't disable PCID when INVLPG has been fixed by microcode
| * 96c2ddba89 APEI: GHES: Have GHES honor the panic= setting
| * 8bec50f4c3 HID: Wacom: Add PCI Wacom device support
| * 7283aa9700 mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
| * c67efabddc tomoyo: don't emit warning in tomoyo_write_control()
| * 0a457223cb wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()
| * ea7e57d54b mmc: core: Respect quirk_max_rate for non-UHS SDIO card
| * 369c063e35 tun: fix group permission check
| * 54c14022fa printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
| * 9bc723d82e x86/amd_nb: Restrict init function to AMD-based systems
| * 7c4d23b6c5 sched: Don't try to catch up excess steal time.
| * 49c8a023ed btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error handling
| * cee55b1219 btrfs: fix use-after-free when attempting to join an aborted transaction
| * ab476f0a45 btrfs: output the reason for open_ctree() failure
| * 7cb72dc08e usb: gadget: f_tcm: Don't free command immediately
| * d6e5ba2516 media: uvcvideo: Fix double free in error path
| * 3a002e4029 HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections
| * 3b269db6fe usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to PD_T_SENDER_RESPONSE
| * 0692c81957 drivers/card_reader/rtsx_usb: Restore interrupt based detection
| * 270c48e652 ktest.pl: Check kernelrelease return in get_version
| * d763fa3b65 NFSD: Reset cb_seq_status after NFS4ERR_DELAY
| * 2ac1d4705b hexagon: Fix unbalanced spinlock in die()
| * bfac520978 hexagon: fix using plain integer as NULL pointer warning in cmpxchg
| * 884385cb4f genksyms: fix memory leak when the same symbol is read from *.symref file
| * a149fe312e genksyms: fix memory leak when the same symbol is added from source
| * a78fbf9765 net: sh_eth: Fix missing rtnl lock in suspend/resume path
| * 64cd120639 vsock: Allow retrying on connect() failure
| * 093c20a38c perf trace: Fix runtime error of index out of bounds
| * db79e982c5 net: davicom: fix UAF in dm9000_drv_remove
| * 52f5aff33c net: rose: fix timer races against user threads
| * a51dedd586 PM: hibernate: Add error handling for syscore_suspend()
| * 71a0fcb68c ipmr: do not call mr_mfc_uses_dev() for unres entries
| * 6ffa190852 net: fec: implement TSO descriptor cleanup
| * 428aff8f7c ubifs: skip dumping tnc tree when zroot is null
| * 21cd59fcb9 rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
| * 5057f4d0cf dmaengine: ti: edma: fix OF node reference leaks in edma_driver
| * 9fdcd0038b module: Extend the preempt disabled section in dereference_symbol_descriptor().
| * ab3e71ae07 ocfs2: mark dquot as inactive if failed to start trans while releasing dquot
| * b4beb4a96e scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
| * 9274ff6854 scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
| * 01ace0742c staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()
| * 7c22a9c3ee media: uvcvideo: Propagate buf->error to userspace
| * 12a73f441b media: camif-core: Add check for clk_enable()
| * 35654e1cb2 media: mipi-csis: Add check for clk_enable()
| * a0a943700f PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
| * 406429d873 media: lmedm04: Handle errors for lme2510_int_read
| * a6a31b4cfd media: lmedm04: Use GFP_KERNEL for URB allocation/submission.
| * 82e6f01637 media: rc: iguanair: handle timeouts
| * 9b9a7e6641 fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()
| * e87fee8392 ARM: dts: mediatek: mt7623: fix IR nodename
| * f3606e14e1 arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names
| * 9cd56af0c6 arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property
| * 2b759f78b8 rdma/cxgb4: Prevent potential integer overflow on 32bit
| * c4e639acdf RDMA/mlx4: Avoid false error about access to uninitialized gids array
| * feba1308bc bpf: Send signals asynchronously if !preemptible
| * 66ad33b350 perf report: Fix misleading help message about --demangle
| * 819d7f3832 perf top: Don't complain about lack of vmlinux when not resolving some kernel samples
| * 8899c5146d padata: fix sysfs store callback check
| * 4bd8444adb ktest.pl: Remove unused declarations in run_bisect_test function
| * 3d13beb404 perf header: Fix one memory leakage in process_bpf_prog_info()
| * 7789f9f790 perf header: Fix one memory leakage in process_bpf_btf()
| * 3b22b8a1d2 ASoC: sun4i-spdif: Add clock multiplier settings
| * 0b920758f5 tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind
| * cd796e2691 net: sched: Disallow replacing of child qdisc from one parent to another
| * cb53e470d3 net/mlxfw: Drop hard coded max FW flash image size
| * d0e0f9c821 net: let net.core.dev_weight always be non-zero
| * a24287200b clk: analogbits: Fix incorrect calculation of vco rate delta
| * 39f5d44f0a selftests: harness: fix printing of mismatch values in __EXPECT()
| * 822a5a0521 selftests/harness: Display signed values correctly
| * a84063de83 wifi: wlcore: fix unbalanced pm_runtime calls
| * d0c5fd206e regulator: of: Implement the unwind path of of_regulator_match()
| * 0a7794b9ca team: prevent adding a device which is already a team device lower
| * 6f4354ca0c cpupower: fix TSC MHz calculation
| * 167483d91a wifi: rtlwifi: pci: wait for firmware loading before releasing memory
| * 85b67b4c4a wifi: rtlwifi: fix memory leaks and invalid access at probe error path
| * f801e754ef wifi: rtlwifi: remove unused check_buddy_priv
| * 4f6d6cbf3f wifi: rtlwifi: remove unused dualmac control leftovers
| * bbac1dd053 wifi: rtlwifi: remove unused timer and related code
| * 0f02775e11 rtlwifi: replace usage of found with dedicated list iterator variable
| * 088e47ef06 dt-bindings: mmc: controller: clarify the address-cells description
| * 88f04590cd wifi: rtlwifi: usb: fix workqueue leak when probe fails
| * 1faa2647a0 wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last step
| * f5dad52e01 rtlwifi: rtl8192se Rename RT_TRACE to rtl_dbg
| * ee74aec777 wifi: rtlwifi: do not complete firmware loading needlessly
| * 1a8a17c5ce ipmi: ipmb: Add check devm_kasprintf() returned value
| * a713ba7167 drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table
| * b4a95da4c7 drm/etnaviv: Fix page property being used for non writecombine buffers
| * 092bb58ec7 partitions: ldm: remove the initial kernel-doc notation
| * e70a578487 nbd: don't allow reconnect after disconnect
| * f84e024057 afs: Fix directory format encoding struct
| * ed6c8c1fe6 overflow: Allow mixed type arguments
| * 0f6dd56712 overflow: Correct check_shl_overflow() comment
| * dbf89a4db3 overflow: Add __must_check attribute to check_*() helpers
| * 08c32d6729 udf: Fix use of check_add_overflow() with mixed type arguments
| * a4c54df0ad perf cs-etm: Add missing variable in cs_etm__process_queues()
* 6e905d8b5a Merge branch 'android11-5.4' into android11-5.4-lts

Change-Id: I83d45c04bbee6185721829195b1bf0ddbd437f16
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-04-26 01:33:15 -07:00
Michael Bestas
ef174b952e
Merge tag 'ASB-2025-04-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-04-01
CVE-2024-50264
CVE-2024-53197
CVE-2024-56556
CVE-2024-53150

* tag 'ASB-2025-04-05_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: net: sched: Disallow replacing of child qdisc from one parent to another
  UPSTREAM: pfifo_tail_enqueue: Drop new packet when sch->limit == 0
  UPSTREAM: f2fs: compress: don't allow unaligned truncation on released compress inode
  UPSTREAM: net: core: reject skb_copy(_expand) for fraglist GSO skbs
  UPSTREAM: udp: prevent local UDP tunnel packets from being GROed
  UPSTREAM: udp: do not transition UDP GRO fraglist partial checksums to unnecessary
  UPSTREAM: udp: do not accept non-tunnel GSO skbs landing in a tunnel
  UPSTREAM: binder: Return EFAULT if we fail BINDER_ENABLE_ONEWAY_SPAM_DETECTION

Change-Id: If91ea6f68126e13b4dfc08471e94ced6d2d68ae9
2025-04-23 17:49:35 +03:00
Cong Wang
eb15b7766c UPSTREAM: net_sched: Prevent creation of classes with TC_H_ROOT
[ Upstream commit 0c3057a5a04d07120b3d0ec9c79568fceb9c921e ]

The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination
condition when traversing up the qdisc tree to update parent backlog
counters. However, if a class is created with classid TC_H_ROOT, the
traversal terminates prematurely at this class instead of reaching the
actual root qdisc, causing parent statistics to be incorrectly maintained.
In case of DRR, this could lead to a crash as reported by Mingi Cho.

Prevent the creation of any Qdisc class with classid TC_H_ROOT
(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.

Bug: 403920173
Reported-by: Mingi Cho <mincho@theori.io>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Fixes: 066a3b5b23 ("[NET_SCHED] sch_api: fix qdisc_tree_decrease_qlen() loop")
Link: https://patch.msgid.link/20250306232355.93864-2-xiyou.wangcong@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 78533c4a29ac3aeddce4b481770beaaa4f3bfb67)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ieac912ddc0bc44e999fe0d29ddf3a3842abdfa14
2025-04-22 12:46:48 +01:00
Tommy Webb
91ab127ff9 Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/display-drivers into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# By Jayasri Sampath Kumaran
# Via Karthik Veeranki (1) and Linux Build Service Account (1)
* tag 'clo/display-drivers/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
  disp: msm: sde: fix kms NULL pointer access in encoder IRQ control

Change-Id: I52a1f3a27d8eed895e1db8a48f15c225d1c1c3ea
2025-04-12 09:35:58 +00:00
Tommy Webb
dd43b3c449 Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom/opensource/datarmnet into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# Via Linux Build Service Account
* tag 'clo/datarmnet/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':

Change-Id: I5a76d0990d5bc7655a0c66fc2f39a02f900cdd43
2025-04-12 09:35:26 +00:00
Tommy Webb
b483dce61a Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# By Ratna Deepthi Kudaravalli
# Via Linux Build Service Account (1) and Ratna Deepthi Kudaravalli (1)
* tag 'clo/audio-kernel/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
  audio-kernel: avoid out of bound read while checking a bit

Change-Id: I70a5aa2eb95361d9181d5e93a2bbbcce590ce7db
2025-04-12 09:34:41 +00:00
Tommy Webb
200ca5e738 Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0 into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# By Krupali Dhanvijay (1) and Ravindra Konda (1)
# Via Linux Build Service Account (1) and Ravindra Konda (1)
* tag 'clo/qcacld-3.0/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
  Release 2.0.8.34Z
  qcacld-3.0: Update key management in original auth mode for WAPI

Change-Id: Idc372a690bf0f5d77ce26e64c7d5fbc5d6aa95c2
2025-04-12 09:33:37 +00:00
Tommy Webb
358dd08568 Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# By spuligil
# Via Linux Build Service Account (1) and Ravindra Konda (1)
* tag 'clo/fw-api/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
  fw-api: CL 28563606 - update fw common interface files
  fw-api: CL 28550964 - update fw common interface files
  fw-api: CL 28541501 - update fw common interface files
  fw-api: CL 28534399 - update fw common interface files
  fw-api: CL 28532052 - update fw common interface files
  fw-api: CL 28539558 - update fw common interface files
  fw-api: CL 28524940 - update fw common interface files
  fw-api: CL 28481760 - update fw common interface files
  fw-api: CL 28447311 - update fw common interface files
  fw-api: CL 28444600 - update fw common interface files
  fw-api: CL 28429679 - update fw common interface files
  fw-api: CL 28361807 - update fw common interface files
  fw-api: CL 28373291 - update fw common interface files
  fw-api: CL 28388903 - update fw common interface files
  fw-api: CL 28373275 - update fw common interface files
  fw-api: CL 28354118 - update fw common interface files
  fw-api: CL 28343275 - update fw common interface files
  fw-api: CL 28339144 - update fw common interface files
  fw-api: CL 28338484 - update fw common interface files

Change-Id: I2f78979704898e0da3b4dded68fd2714e315365a
2025-04-12 09:33:04 +00:00
Tommy Webb
626f66b50c Merge tag 'LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0

# By Prashanth K (6) and others
# Via Gerrit - the friendly Code Review server (5) and others
* tag 'clo/msm-5.4/LA.UM.9.14.r1-26000-LAHAINA.QSSI15.0':
  FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
  FROMGIT: media: venus: hfi: add check to handle incorrect queue size
  FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
  FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
  UPSTREAM: usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK
  UPSTREAM: usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK
  UPSTREAM: usb: xhci: Add error handling in xhci_map_urb_for_dma
  UPSTREAM: usb: xhci: Use temporary buffer to consolidate SG
  UPSTREAM: usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK
  defconfig: Enable RTL8152 ETH-USB driver
  msm: mhi_dev: Breaking memory for event request in smaller chunks
  msm: eva: Validating the SFR buffer size before accessing
  msm: eva: Copy back the validated size to avoid security issue

Change-Id: Ibd883e18a8a410fb23eb3cda97e88b77c34cdbd7
2025-04-12 09:31:55 +00:00
Tommy Webb
3b5fdef6b4 Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-03-01
CVE-2024-46852
CVE-2024-50302
CVE-2025-22413

# By Greg Kroah-Hartman (7) and others
# Via Greg Kroah-Hartman (3) and Terence Tritton (xWF) (1)
* tag 'ASB-2025-03-05_11-5.4':
  ANDROID: ABI: Cuttlefish Symbol update
  Revert "net: net_namespace: Optimize the code"
  Revert "net: add exit_batch_rtnl() method"
  Revert "gtp: use exit_batch_rtnl() method"
  Revert "gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp()."
  Revert "gtp: Destroy device along with udp socket's netns dismantle."
  Linux 5.4.290
  Partial revert of xhci: use pm_ptr() instead #ifdef for CONFIG_PM conditionals
  xhci: use pm_ptr() instead of #ifdef for CONFIG_PM conditionals
  drm/v3d: Assign job pointer to NULL before signaling the fence
  Input: xpad - add support for wooting two he (arm)
  Input: xpad - add unofficial Xbox 360 wireless receiver clone
  Input: atkbd - map F23 key to support default copilot shortcut
  Revert "usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null"
  USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()
  ext4: fix slab-use-after-free in ext4_split_extent_at()
  ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path
  vfio/platform: check the bounds of read/write syscalls
  net/xen-netback: prevent UAF in xenvif_flush_hash()
  net: xen-netback: hash.c: Use built-in RCU list checking
  signal/m68k: Use force_sigsegv(SIGSEGV) in fpsp040_die
  m68k: Add missing mmap_read_lock() to sys_cacheflush()
  m68k: Update ->thread.esp0 before calling syscall_trace() in ret_from_signal
  gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
  irqchip/sunxi-nmi: Add missing SKIP_WAKE flag
  scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request
  ASoC: wm8994: Add depends on MFD core
  net: fix data-races around sk->sk_forward_alloc
  scsi: sg: Fix slab-use-after-free read in sg_release()
  ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev()
  hrtimers: Handle CPU state correctly on hotplug
  irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly
  fs/proc: fix softlockup in __read_vmcore (part 2)
  net: ethernet: xgbe: re-add aneg to supported features in PHY quirks
  nvmet: propagate npwg topology
  poll_wait: add mb() to fix theoretical race between waitqueue_active() and .poll()
  kheaders: Ignore silly-rename files
  hfs: Sanity check the root record
  mac802154: check local interfaces before deleting sdata list
  i2c: mux: demux-pinctrl: check initial mux selection, too
  drm/v3d: Ensure job pointer is set to NULL after job completion
  nfp: bpf: prevent integer overflow in nfp_bpf_event_output()
  gtp: Destroy device along with udp socket's netns dismantle.
  gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp().
  gtp: use exit_batch_rtnl() method
  net: add exit_batch_rtnl() method
  net: net_namespace: Optimize the code
  net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field()
  sctp: sysctl: rto_min/max: avoid using current->nsproxy
  ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
  ocfs2: correct return value of ocfs2_local_free_info()
  phy: core: Fix that API devm_of_phy_provider_unregister() fails to unregister the phy provider
  phy: core: fix code style in devm_of_phy_provider_unregister
  arm64: dts: rockchip: add hevc power domain clock to rk3328
  arm64: dts: rockchip: add #power-domain-cells to power domain nodes
  arm64: dts: rockchip: fix pd_tcpc0 and pd_tcpc1 node position on rk3399
  arm64: dts: rockchip: fix defines in pd_vio node for rk3399
  iio: inkern: call iio_device_put() only on mapped devices
  iio: adc: at91: call input_free_device() on allocated iio_dev
  iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()
  iio: gyro: fxas21002c: Fix missing data update in trigger handler
  iio: adc: ti-ads8688: fix information leak in triggered buffer
  iio: imu: kmx61: fix information leak in triggered buffer
  iio: light: vcnl4035: fix information leak in triggered buffer
  iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer
  iio: pressure: zpa2326: fix information leak in triggered buffer
  usb: gadget: f_fs: Remove WARN_ON in functionfs_bind
  usb: fix reference leak in usb_new_device()
  USB: core: Disable LPM only for non-suspended ports
  USB: usblp: return error when setting unsupported protocol
  usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null
  USB: serial: cp210x: add Phoenix Contact UPS Device
  usb-storage: Add max sectors quirk for Nokia 208
  staging: iio: ad9832: Correct phase range check
  staging: iio: ad9834: Correct phase range check
  USB: serial: option: add Neoway N723-EA support
  USB: serial: option: add MeiG Smart SRM815
  drm/amd/display: increase MAX_SURFACES to the value supported by hw
  ACPI: resource: Add Asus Vivobook X1504VAP to irq1_level_low_skip_override[]
  ACPI: resource: Add TongFang GM5HG0A to irq1_edge_low_force_override[]
  drm/amd/display: Add check for granularity in dml ceil/floor helpers
  sctp: sysctl: auth_enable: avoid using current->nsproxy
  sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
  dm thin: make get_first_thin use rcu-safe list first function
  tls: Fix tls_sw_sendmsg error handling
  net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
  tcp/dccp: allow a connection when sk_max_ack_backlog is zero
  tcp/dccp: complete lockless accesses to sk->sk_max_ack_backlog
  net: 802: LLC+SNAP OID:PID lookup on start of skb data
  ieee802154: ca8210: Add missing check for kfifo_alloc() in ca8210_probe()
  dm array: fix cursor index when skipping across block boundaries
  dm array: fix unreleased btree blocks on closing a faulty array cursor
  dm array: fix releasing a faulty array block twice in dm_array_cursor_end
  jbd2: flush filesystem device before updating tail sequence

Change-Id: I83cf20e29c63126cd17dfa393dca0ce7dfa47a76
2025-04-12 09:31:28 +00:00
Greg Kroah-Hartman
9b78f083cb This is the 5.4.292 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmf3uc8ACgkQONu9yGCS
 aT7cOA/+IMZpVcP8BeutEqLl9O0SXf4QS9LT8u/eQKy3b26p8otQXOkElhGmchBv
 cvb7+ZuJQGUcjfhW0CsHGx/vKfDz3qbbLaXH/F0sRvZxkYApX35pkSDOtcE3jAHn
 klQejHzoFlom8d951VUpQukwGXPoVfPExdXMWNg4RCrn1pcDnb3JjmEyhDRu5Sna
 fA1JeQ54UReNPUnXOHyixy+xoOLGBdikqVzV8SIqKNuzBloXIbSA831BGocFffrW
 xng8XIemuCEuK552/Ex8AJfUiY/q6XGH2OYy46g4oEG85xoyseGlQJqsnziOxDGX
 VYbdYGmtTZB7Tv2fwjpKsyluexoQEXmxVbu8CuGn/X0B1d48tRl40ROBMoAnOOhZ
 j7gjZG9TK9G7+fQSEpS8bLwknRndQWlbxSRMVEGAqIDcxF09+Hkkycu82siCtKz2
 JYQnKsv7We/m7EI+3uAh50zZrLU6NL+wVnkGlQy17RTQYYshZpSs6GYvB4OjJ5vx
 OXovZA2IKDnWA336viL265etHsUf2agNIyWiMr/5Tp4RgirN2WSQubZjNhp/FdjR
 e3MxVPrUxBD/QyGs2KuZo/rA/SuYDtMxdoogrYQO1cbpvBCcsyYvnczhAUcjVgKq
 C+iGTOAs+EEHWYol/CWuOJAkG/0O7Uj2U+cDdQQgeKD9SCSzohA=
 =wRcs
 -----END PGP SIGNATURE-----

Merge 5.4.292 into android11-5.4-lts

Changes in 5.4.292
	vlan: fix memory leak in vlan_newlink()
	clockevents/drivers/i8253: Fix stop sequence for timer 0
	sched/isolation: Prevent boot crash when the boot CPU is nohz_full
	Revert "sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy"
	Revert "sctp: sysctl: auth_enable: avoid using current->nsproxy"
	sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy
	sctp: sysctl: auth_enable: avoid using current->nsproxy
	pinctrl: bcm281xx: Fix incorrect regmap max_registers value
	netpoll: Fix use correct return type for ndo_start_xmit()
	netpoll: remove dev argument from netpoll_send_skb_on_dev()
	netpoll: move netpoll_send_skb() out of line
	netpoll: netpoll_send_skb() returns transmit status
	netpoll: hold rcu read lock in __netpoll_send_skb()
	drivers/hv: Replace binary semaphore with mutex
	Drivers: hv: vmbus: Don't release fb_mmio resource in vmbus_free_mmio()
	netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
	ipvs: prevent integer overflow in do_ip_vs_get_ctl()
	net_sched: Prevent creation of classes with TC_H_ROOT
	netfilter: nft_exthdr: fix offset with ipv4_find_option()
	net/mlx5e: Prevent bridge link show failure for non-eswitch-allowed devices
	nvme-fc: go straight to connecting state when initializing
	hrtimers: Mark is_migration_base() with __always_inline
	powercap: call put_device() on an error path in powercap_register_control_type()
	iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
	scsi: qla1280: Fix kernel oops when debug level > 2
	ACPI: resource: IRQ override for Eluktronics MECH-17
	HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in doorbell
	HID: ignore non-functional sensor in HP 5MP Camera
	s390/cio: Fix CHPID "configure" attribute caching
	ASoC: rsnd: don't indicate warning on rsnd_kctrl_accept_runtime()
	nvmet-rdma: recheck queue state is LIVE in state lock in recv done
	sctp: Fix undefined behavior in left shift operation
	nvme: only allow entering LIVE from CONNECTING state
	fuse: don't truncate cached, mutated symlink
	x86/irq: Define trace events conditionally
	drm/nouveau: Do not override forced connector status
	block: fix 'kmem_cache of name 'bio-108' already exists'
	USB: serial: ftdi_sio: add support for Altera USB Blaster 3
	USB: serial: option: add Telit Cinterion FE990B compositions
	USB: serial: option: fix Telit Cinterion FE990A name
	USB: serial: option: match on interface class for Telit FN990B
	x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes
	drm/atomic: Filter out redundant DPMS calls
	drm/amd/display: Assign normalized_pix_clk when color depth = 14
	qlcnic: fix memory leak issues in qlcnic_sriov_common.c
	drm/gma500: Add NULL check for pci_gfx_root in mid_get_vbt_data()
	ASoC: codecs: wm0010: Fix error handling path in wm0010_spi_probe()
	i2c: ali1535: Fix an error handling path in ali1535_probe()
	i2c: ali15x3: Fix an error handling path in ali15x3_probe()
	i2c: sis630: Fix an error handling path in sis630_probe()
	firmware: imx-scu: fix OF node leak in .probe()
	xfrm_output: Force software GSO only in tunnel mode
	RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path
	RDMA/hns: Fix wrong value of max_sge_rd
	Bluetooth: Fix error code in chan_alloc_skb_cb()
	ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
	ipv6: Set errno after ip_fib_metrics_init() in ip6_route_info_create().
	net: atm: fix use after free in lec_send()
	net/neighbor: add missing policy for NDTPA_QUEUE_LENBYTES
	i2c: omap: fix IRQ storms
	drm/v3d: Don't run jobs that have errors flagged in its fence
	mmc: atmel-mci: Add missing clk_disable_unprepare()
	ARM: shmobile: smp: Enforce shmobile_smp_* alignment
	batman-adv: Ignore own maximum aggregation size during RX
	drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
	ALSA: usb-audio: Add quirk for Plantronics headsets to fix control names
	HID: hid-plantronics: Add mic mute mapping and generalize quirks
	atm: Fix NULL pointer dereference
	ARM: 9350/1: fault: Implement copy_from_kernel_nofault_allowed()
	ARM: 9351/1: fault: Add "cut here" line for prefetch aborts
	ARM: Remove address checking for MMUless devices
	netfilter: socket: Lookup orig tuple for IPv6 SNAT
	counter: stm32-lptimer-cnt: fix error handling when enabling
	tty: serial: 8250: Add some more device IDs
	net: usb: qmi_wwan: add Telit Cinterion FN990B composition
	net: usb: qmi_wwan: add Telit Cinterion FE990B composition
	net: usb: usbnet: restore usb%d name exception for local mac addresses
	memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
	serial: 8250_dma: terminate correct DMA in tx_dma_flush()
	x86/mm/pat: cpa-test: fix length for CPA_ARRAY test
	cpufreq: governor: Fix negative 'idle_time' handling in dbs_update()
	x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct()
	x86/platform: Only allow CONFIG_EISA for 32-bit
	selinux: Chain up tool resolving errors in install_policy.sh
	EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer
	EDAC/ie31200: Fix the DIMM size mask for several SoCs
	EDAC/ie31200: Fix the error path order of ie31200_init()
	thermal: int340x: Add NULL check for adev
	PM: sleep: Fix handling devices with direct_complete set on errors
	lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*()
	perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
	ALSA: hda/realtek: Always honor no_shutup_pins
	drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
	PCI/ASPM: Fix link state exit during switch upstream function removal
	PCI/portdrv: Only disable pciehp interrupts early when needed
	PCI: Remove stray put_device() in pci_register_host_bridge()
	PCI: pciehp: Don't enable HPIE when resuming in poll mode
	fbdev: au1100fb: Move a variable assignment behind a null pointer check
	mdacon: rework dependency list
	fbdev: sm501fb: Add some geometry checks.
	clk: amlogic: gxbb: drop incorrect flag on 32k clock
	bpf: Use preempt_count() directly in bpf_send_signal_common()
	lib: 842: Improve error handling in sw842_compress()
	pinctrl: renesas: rza2: Fix missing of_node_put() call
	clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent
	IB/mad: Check available slots before posting receive WRs
	clk: amlogic: g12b: fix cluster A parent data
	clk: amlogic: gxbb: drop non existing 32k clock parent
	clk: amlogic: g12a: fix mmc A peripheral clock
	x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1
	power: supply: max77693: Fix wrong conversion of charge input threshold value
	RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
	mfd: sm501: Switch to BIT() to mitigate integer overflows
	x86/dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment
	isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
	coresight: catu: Fix number of pages while using 64k pages
	iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio
	perf units: Fix insufficient array space
	kexec: initialize ELF lowest address to ULONG_MAX
	ocfs2: validate l_tree_depth to avoid out-of-bounds access
	perf python: Fixup description of sample.id event member
	perf python: Decrement the refcount of just created event on failure
	perf python: Check if there is space to copy all the event
	fs/procfs: fix the comment above proc_pid_wchan()
	objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
	ring-buffer: Fix bytes_dropped calculation issue
	octeontx2-af: Fix mbox INTR handler when num VFs > 64
	sched/smt: Always inline sched_smt_active()
	wifi: iwlwifi: fw: allocate chained SG tables for dump
	affs: generate OFS sequence numbers starting at 1
	affs: don't write overlarge OFS data block size fields
	sched/deadline: Use online cpus for validating runtime
	locking/semaphore: Use wake_q to wake up processes outside lock critical section
	can: statistics: use atomic access in hot path
	hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
	spufs: fix a leak on spufs_new_file() failure
	spufs: fix a leak in spufs_create_context()
	ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans
	ntb: intel: Fix using link status DB's
	netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
	net_sched: skbprio: Remove overly strict queue assertions
	vsock: avoid timeout during connect() if the socket is closing
	ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS
	net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy
	arcnet: Add NULL check in com20020pci_probe()
	can: flexcan: only change CAN state when link up in system PM
	ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
	x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
	x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
	ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
	mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
	tracing: Fix use-after-free in print_graph_function_flags during tracer switching
	jfs: fix slab-out-of-bounds read in ea_get()
	jfs: add index corruption check to DT_GETPAGE()
	Linux 5.4.292

Change-Id: I9386a675acdf4384f0d612b6fc80c59bd6bb739f
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-04-11 08:16:05 +00:00
Greg Kroah-Hartman
1b01d9c341 Linux 5.4.292
Link: https://lore.kernel.org/r/20250408104815.295196624@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Roman Smirnov
2809029821 jfs: add index corruption check to DT_GETPAGE()
commit a8dfb2168906944ea61acfc87846b816eeab882d upstream.

If the file system is corrupted, the header.stblindex variable
may become greater than 127. Because of this, an array access out
of bounds may occur:

------------[ cut here ]------------
UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dtree.c:3096:10
index 237 is out of range for type 'struct dtslot[128]'
CPU: 0 UID: 0 PID: 5822 Comm: syz-executor740 Not tainted 6.13.0-rc4-syzkaller-00110-g4099a71718b0 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
 ubsan_epilogue lib/ubsan.c:231 [inline]
 __ubsan_handle_out_of_bounds+0x121/0x150 lib/ubsan.c:429
 dtReadFirst+0x622/0xc50 fs/jfs/jfs_dtree.c:3096
 dtReadNext fs/jfs/jfs_dtree.c:3147 [inline]
 jfs_readdir+0x9aa/0x3c50 fs/jfs/jfs_dtree.c:2862
 wrap_directory_iterator+0x91/0xd0 fs/readdir.c:65
 iterate_dir+0x571/0x800 fs/readdir.c:108
 __do_sys_getdents64 fs/readdir.c:403 [inline]
 __se_sys_getdents64+0x1e2/0x4b0 fs/readdir.c:389
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
 </TASK>
---[ end trace ]---

Add a stblindex check for corruption.

Reported-by: syzbot <syzbot+9120834fc227768625ba@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=9120834fc227768625ba
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Roman Smirnov <r.smirnov@omp.ru>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Qasim Ijaz
3d6fd5b9c6 jfs: fix slab-out-of-bounds read in ea_get()
commit fdf480da5837c23b146c4743c18de97202fcab37 upstream.

During the "size_check" label in ea_get(), the code checks if the extended
attribute list (xattr) size matches ea_size. If not, it logs
"ea_get: invalid extended attribute" and calls print_hex_dump().

Here, EALIST_SIZE(ea_buf->xattr) returns 4110417968, which exceeds
INT_MAX (2,147,483,647). Then ea_size is clamped:

	int size = clamp_t(int, ea_size, 0, EALIST_SIZE(ea_buf->xattr));

Although clamp_t aims to bound ea_size between 0 and 4110417968, the upper
limit is treated as an int, causing an overflow above 2^31 - 1. This leads
"size" to wrap around and become negative (-184549328).

The "size" is then passed to print_hex_dump() (called "len" in
print_hex_dump()), it is passed as type size_t (an unsigned
type), this is then stored inside a variable called
"int remaining", which is then assigned to "int linelen" which
is then passed to hex_dump_to_buffer(). In print_hex_dump()
the for loop, iterates through 0 to len-1, where len is
18446744073525002176, calling hex_dump_to_buffer()
on each iteration:

	for (i = 0; i < len; i += rowsize) {
		linelen = min(remaining, rowsize);
		remaining -= rowsize;

		hex_dump_to_buffer(ptr + i, linelen, rowsize, groupsize,
				   linebuf, sizeof(linebuf), ascii);

		...
	}

The expected stopping condition (i < len) is effectively broken
since len is corrupted and very large. This eventually leads to
the "ptr+i" being passed to hex_dump_to_buffer() to get closer
to the end of the actual bounds of "ptr", eventually an out of
bounds access is done in hex_dump_to_buffer() in the following
for loop:

	for (j = 0; j < len; j++) {
			if (linebuflen < lx + 2)
				goto overflow2;
			ch = ptr[j];
		...
	}

To fix this we should validate "EALIST_SIZE(ea_buf->xattr)"
before it is utilised.

Reported-by: syzbot <syzbot+4e6e7e4279d046613bc5@syzkaller.appspotmail.com>
Tested-by: syzbot <syzbot+4e6e7e4279d046613bc5@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=4e6e7e4279d046613bc5
Fixes: d9f9d96136cb ("jfs: xattr: check invalid xattr size more strictly")
Cc: stable@vger.kernel.org
Signed-off-by: Qasim Ijaz <qasdev00@gmail.com>
Signed-off-by: Dave Kleikamp <dave.kleikamp@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Tengda Wu
42561fe62c tracing: Fix use-after-free in print_graph_function_flags during tracer switching
commit 7f81f27b1093e4895e87b74143c59c055c3b1906 upstream.

Kairui reported a UAF issue in print_graph_function_flags() during
ftrace stress testing [1]. This issue can be reproduced if puting a
'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(),
and executing the following script:

  $ echo function_graph > current_tracer
  $ cat trace > /dev/null &
  $ sleep 5  # Ensure the 'cat' reaches the 'mdelay(10)' point
  $ echo timerlat > current_tracer

The root cause lies in the two calls to print_graph_function_flags
within print_trace_line during each s_show():

  * One through 'iter->trace->print_line()';
  * Another through 'event->funcs->trace()', which is hidden in
    print_trace_fmt() before print_trace_line returns.

Tracer switching only updates the former, while the latter continues
to use the print_line function of the old tracer, which in the script
above is print_graph_function_flags.

Moreover, when switching from the 'function_graph' tracer to the
'timerlat' tracer, s_start only calls graph_trace_close of the
'function_graph' tracer to free 'iter->private', but does not set
it to NULL. This provides an opportunity for 'event->funcs->trace()'
to use an invalid 'iter->private'.

To fix this issue, set 'iter->private' to NULL immediately after
freeing it in graph_trace_close(), ensuring that an invalid pointer
is not passed to other tracers. Additionally, clean up the unnecessary
'iter->private = NULL' during each 'cat trace' when using wakeup and
irqsoff tracers.

 [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/

Cc: stable@vger.kernel.org
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Zheng Yejian <zhengyejian1@huawei.com>
Link: https://lore.kernel.org/20250320122137.23635-1-wutengda@huaweicloud.com
Fixes: eecb91b9f98d ("tracing: Fix memleak due to race between current_tracer and trace")
Closes: https://lore.kernel.org/all/CAMgjq7BW79KDSCyp+tZHjShSzHsScSiJxn5ffskp-QzVM06fxw@mail.gmail.com/
Reported-by: Kairui Song <kasong@tencent.com>
Signed-off-by: Tengda Wu <wutengda@huaweicloud.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Karel Balej
922a70031c mmc: sdhci-pxav3: set NEED_RSP_BUSY capability
commit a41fcca4b342811b473bbaa4b44f1d34d87fcce6 upstream.

Set the MMC_CAP_NEED_RSP_BUSY capability for the sdhci-pxav3 host to
prevent conversion of R1B responses to R1. Without this, the eMMC card
in the samsung,coreprimevelte smartphone using the Marvell PXA1908 SoC
with this mmc host doesn't probe with the ETIMEDOUT error originating in
__mmc_poll_for_busy.

Note that the other issues reported for this phone and host, namely
floods of "Tuning failed, falling back to fixed sampling clock" dmesg
messages for the eMMC and unstable SDIO are not mitigated by this
change.

Link: https://lore.kernel.org/r/20200310153340.5593-1-ulf.hansson@linaro.org/
Link: https://lore.kernel.org/r/D7204PWIGQGI.1FRFQPPIEE2P9@matfyz.cz/
Link: https://lore.kernel.org/r/20250115-pxa1908-lkml-v14-0-847d24f3665a@skole.hr/
Cc: stable@vger.kernel.org
Signed-off-by: Karel Balej <balejk@matfyz.cz>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Tested-by: Duje Mihanović <duje.mihanovic@skole.hr>
Link: https://lore.kernel.org/r/20250310140707.23459-1-balejk@matfyz.cz
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Paul Menzel
a7d0f84a31 ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
commit 2da31ea2a085cd189857f2db0f7b78d0162db87a upstream.

Like the ASUS Vivobook X1504VAP and Vivobook X1704VAP, the ASUS Vivobook 14
X1404VAP has its keyboard IRQ (1) described as ActiveLow in the DSDT, which
the kernel overrides to EdgeHigh breaking the keyboard.

    $ sudo dmidecode
    […]
    System Information
            Manufacturer: ASUSTeK COMPUTER INC.
            Product Name: ASUS Vivobook 14 X1404VAP_X1404VA
    […]
    $ grep -A 30 PS2K dsdt.dsl | grep IRQ -A 1
                 IRQ (Level, ActiveLow, Exclusive, )
                     {1}

Add the X1404VAP to the irq1_level_low_skip_override[] quirk table to fix
this.

Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219224
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Paul Menzel <pmenzel@molgen.mpg.de>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Tested-by: Anton Shyndin <mrcold.il@gmail.com>
Link: https://patch.msgid.link/20250318160903.77107-1-pmenzel@molgen.mpg.de
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Jann Horn
618d5612ec x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
commit 3ef938c3503563bfc2ac15083557f880d29c2e64 upstream.

On the following path, flush_tlb_range() can be used for zapping normal
PMD entries (PMD entries that point to page tables) together with the PTE
entries in the pointed-to page table:

    collapse_pte_mapped_thp
      pmdp_collapse_flush
        flush_tlb_range

The arm64 version of flush_tlb_range() has a comment describing that it can
be used for page table removal, and does not use any last-level
invalidation optimizations. Fix the X86 version by making it behave the
same way.

Currently, X86 only uses this information for the following two purposes,
which I think means the issue doesn't have much impact:

 - In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be
   IPI'd to avoid issues with speculative page table walks.
 - In Hyper-V TLB paravirtualization, again for lazy TLB stuff.

The patch "x86/mm: only invalidate final translations with INVLPGB" which
is currently under review (see
<https://lore.kernel.org/all/20241230175550.4046587-13-riel@surriel.com/>)
would probably be making the impact of this a lot worse.

Fixes: 016c4d92cd ("x86/mm/tlb: Add freed_tables argument to flush_tlb_mm_range")
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Link: https://lkml.kernel.org/r/20250103-x86-collapse-flush-fix-v1-1-3c521856cfa6@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Guilherme G. Piccoli
c0189c02b5 x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
commit d90c9de9de2f1712df56de6e4f7d6982d358cabe upstream.

TSC could be reset in deep ACPI sleep states, even with invariant TSC.

That's the reason we have sched_clock() save/restore functions, to deal
with this situation. But what happens is that such functions are guarded
with a check for the stability of sched_clock - if not considered stable,
the save/restore routines aren't executed.

On top of that, we have a clear comment in native_sched_clock() saying
that *even* with TSC unstable, we continue using TSC for sched_clock due
to its speed.

In other words, if we have a situation of TSC getting detected as unstable,
it marks the sched_clock as unstable as well, so subsequent S3 sleep cycles
could bring bogus sched_clock values due to the lack of the save/restore
mechanism, causing warnings like this:

  [22.954918] ------------[ cut here ]------------
  [22.954923] Delta way too big! 18446743750843854390 ts=18446744072977390405 before=322133536015 after=322133536015 write stamp=18446744072977390405
  [22.954923] If you just came from a suspend/resume,
  [22.954923] please switch to the trace global clock:
  [22.954923]   echo global > /sys/kernel/tracing/trace_clock
  [22.954923] or add trace_clock=global to the kernel command line
  [22.954937] WARNING: CPU: 2 PID: 5728 at kernel/trace/ring_buffer.c:2890 rb_add_timestamp+0x193/0x1c0

Notice that the above was reproduced even with "trace_clock=global".

The fix for that is to _always_ save/restore the sched_clock on suspend
cycle _if TSC is used_ as sched_clock - only if we fallback to jiffies
the sched_clock_stable() check becomes relevant to save/restore the
sched_clock.

Debugged-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Signed-off-by: Guilherme G. Piccoli <gpiccoli@igalia.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Cc: stable@vger.kernel.org
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Link: https://lore.kernel.org/r/20250215210314.351480-1-gpiccoli@igalia.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
Markus Elfring
2414095a8c ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk()
commit 4279e72cab31dd3eb8c89591eb9d2affa90ab6aa upstream.

The function call “dmaengine_unmap_put(unmap)” was used in an if branch.
The same call was immediately triggered by a subsequent goto statement.
Thus avoid such a call repetition.

This issue was detected by using the Coccinelle software.

Fixes: 5648e56d03 ("NTB: ntb_perf: Add full multi-port NTB API support")
Cc: stable@vger.kernel.org
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
Signed-off-by: Jon Mason <jdmason@kudzu.us>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00