Commit graph

980,349 commits

Author SHA1 Message Date
Michael Bestas
350c4ccfe1
Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-12-01
CVE-2025-48623
CVE-2025-48624
CVE-2025-48637
CVE-2025-48638
CVE-2024-35970
CVE-2025-38236
CVE-2025-38349
CVE-2025-48610
CVE-2025-38500

* tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: crypto: essiv - Check ssize for decryption and in-place encryption
  ANDROID: GKI: fix up build break where timer_delete_sync() was used
  Revert "net: rtnetlink: remove redundant assignment to variable err"
  Revert "net: rtnetlink: add msg kind names"
  Revert "net: rtnetlink: add helper to extract msg type's kind"
  Revert "net: rtnetlink: use BIT for flag values"
  Revert "net: netlink: add NLM_F_BULK delete request modifier"
  Revert "net: rtnetlink: add bulk delete support flag"
  Revert "net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg"
  Revert "net: add ndo_fdb_del_bulk"
  Revert "net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del"
  Revert "rtnetlink: Allow deleting FDB entries in user namespace"
  Linux 5.4.301
  net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
  media: s5p-mfc: remove an unused/uninitialized variable
  NFSD: Fix last write offset handling in layoutcommit
  NFSD: Minor cleanup in layoutcommit processing
  padata: Reset next CPU when reorder sequence wraps around
  KEYS: trusted_tpm1: Compare HMAC values in constant time
  NFSD: Define a proc_layoutcommit for the FlexFiles layout type
  vfs: Don't leak disconnected dentries on umount
  jbd2: ensure that all ongoing I/O complete before freeing blocks
  ext4: detect invalid INLINE_DATA + EXTENTS flag combination
  drm/amdgpu: use atomic functions with memory barriers for vm fault info
  ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
  spi: cadence-quadspi: Flush posted register writes before DAC access
  spi: cadence-quadspi: Flush posted register writes before INDAC access
  memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
  memory: samsung: exynos-srom: Correct alignment
  arm64: errata: Apply workarounds for Neoverse-V3AE
  arm64: cputype: Add Neoverse-V3AE definitions
  comedi: fix divide-by-zero in comedi_buf_munge()
  binder: remove "invalid inc weak" check
  xhci: dbc: enable back DbC in resume if it was enabled before suspend
  usb/core/quirks: Add Huawei ME906S to wakeup quirk
  USB: serial: option: add Telit FN920C04 ECM compositions
  USB: serial: option: add Quectel RG255C
  USB: serial: option: add UNISOC UIS7720
  net: ravb: Ensure memory write completes before ringing TX doorbell
  net: usb: rtl8150: Fix frame padding
  ocfs2: clear extent cache after moving/defragmenting extents
  MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
  Revert "cpuidle: menu: Avoid discarding useful information"
  net: bonding: fix possible peer notify event loss or dup issue
  sctp: avoid NULL dereference when chunk data buffer is missing
  arm64, mm: avoid always making PTE dirty in pte_mkwrite()
  net: enetc: correct the value of ENETC_RXB_TRUESIZE
  rtnetlink: Allow deleting FDB entries in user namespace
  net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del
  net: add ndo_fdb_del_bulk
  net: rtnetlink: add bulk delete support flag
  net: netlink: add NLM_F_BULK delete request modifier
  net: rtnetlink: use BIT for flag values
  net: rtnetlink: add helper to extract msg type's kind
  net: rtnetlink: add msg kind names
  net: rtnetlink: remove redundant assignment to variable err
  m68k: bitops: Fix find_*_bit() signatures
  hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super()
  hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
  dlm: check for defined force value in dlm_lockspace_release
  hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
  hfs: validate record offset in hfsplus_bmap_alloc
  hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
  hfs: make proper initalization of struct hfs_find_data
  hfs: clear offset and space out of valid records in b-tree node
  exec: Fix incorrect type for ret
  hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
  ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
  sched/fair: Fix pelt lost idle time detection
  sched/balancing: Rename newidle_balance() => sched_balance_newidle()
  sched/fair: Trivial correction of the newidle_balance() comment
  sched: Make newidle_balance() static again
  tls: don't rely on tx_work during send()
  tls: always set record_type in tls_process_cmsg
  tg3: prevent use of uninitialized remote_adv and local_adv variables
  tcp: fix tcp_tso_should_defer() vs large RTT
  amd-xgbe: Avoid spurious link down messages during interface toggle
  net/ip6_tunnel: Prevent perpetual tunnel growth
  net: dlink: handle dma_map_single() failure properly
  net: dl2k: switch from 'pci_' to 'dma_' API
  media: pci: ivtv: Add missing check after DMA map
  media: pci/ivtv: switch from 'pci_' to 'dma_' API
  xen/events: Update virq_to_irq on migration
  media: lirc: Fix error handling in lirc_register()
  media: rc: Directly use ida_free()
  drm/exynos: exynos7_drm_decon: remove ctx->suspended
  btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
  pwm: berlin: Fix wrong register in suspend/resume
  media: cx18: Add missing check after DMA map
  xen/events: Cleanup find_virq() return codes
  cramfs: Verify inode mode when loading from disk
  fs: Add 'initramfs_options' to set initramfs mount options
  pid: Add a judgment for ns null in pid_nr_ns
  minixfs: Verify inode mode when loading from disk
  tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
  dm: fix NULL pointer dereference in __dm_suspend()
  mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag
  mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type
  mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value
  Squashfs: reject negative file sizes in squashfs_read_inode()
  Squashfs: add additional inode sanity checking
  media: mc: Clear minor number before put device
  mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data()
  fs: udf: fix OOB read in lengthAllocDescs handling
  KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
  net/9p: fix double req put in p9_fd_cancelled
  ext4: guard against EA inode refcount underflow in xattr update
  ext4: correctly handle queries for metadata mappings
  ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch()
  nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
  x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases)
  x86/umip: Check that the instruction opcode is at least two bytes
  PCI: keystone: Use devm_request_irq() to free "ks-pcie-error-irq" on exit
  PCI/AER: Fix missing uevent on recovery when a reset is requested
  PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
  rseq/selftests: Use weak symbol reference, not definition, to link with glibc
  rtc: interface: Fix long-standing race when setting alarm
  rtc: interface: Ensure alarm irq is enabled when UIE is enabled
  mmc: core: SPI mode remove cmd7
  mtd: rawnand: fsmc: Default to autodetect buswidth
  sparc: fix error handling in scan_one_device()
  sparc64: fix hugetlb for sun4u
  sctp: Fix MAC comparison to be constant-time
  scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl()
  parisc: don't reference obsolete termio struct for TC* constants
  lib/genalloc: fix device leak in of_gen_pool_get()
  iio: frequency: adf4350: Fix prescaler usage.
  iio: dac: ad5421: use int type to store negative error codes
  iio: dac: ad5360: use int type to store negative error codes
  crypto: atmel - Fix dma_unmap_sg() direction
  cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
  drm/nouveau: fix bad ret code in nouveau_bo_move_prep
  media: i2c: mt9v111: fix incorrect type for ret
  firmware: meson_sm: fix device leak at probe
  xen/manage: Fix suspend error path
  arm64: dts: qcom: msm8916: Add missing MDSS reset
  ACPI: debug: fix signedness issues in read/write helpers
  ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
  tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
  tpm, tpm_tis: Claim locality before writing interrupt registers
  crypto: essiv - Check ssize for decryption and in-place encryption
  mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes
  mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call
  tools build: Align warning options with perf
  net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe
  tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
  net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
  drm/vmwgfx: Fix Use-after-free in validation
  net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter()
  scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
  scsi: mvsas: Use sas_task_find_rq() for tagging
  scsi: mvsas: Delete mvs_tag_init()
  scsi: libsas: Add sas_task_find_rq()
  clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
  clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
  perf session: Fix handling when buffer exceeds 2 GiB
  rtc: x1205: Fix Xicor X1205 vendor prefix
  perf util: Fix compression checks returning -1 as bool
  iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
  clocksource/drivers/clps711x: Fix resource leaks in error paths
  pinctrl: check the return value of pinmux_ops::get_function_name()
  Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
  mm: hugetlb: avoid soft lockup when mprotect to large memory area
  uio_hv_generic: Let userspace take care of interrupt mask
  Squashfs: fix uninit-value in squashfs_get_parent
  Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
  net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable
  nfp: fix RSS hash key size when RSS is not supported
  drivers/base/node: fix double free in register_one_node()
  ocfs2: fix double free in user_cluster_connect()
  net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
  RDMA/siw: Always report immediate post SQ errors
  usb: vhci-hcd: Prevent suspending virtually attached devices
  scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
  ipvs: Defer ip_vs_ftp unregister during netns cleanup
  NFSv4.1: fix backchannel max_resp_sz verification check
  remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice
  sparc: fix accurate exception reporting in copy_{from,to}_user for M7
  sparc: fix accurate exception reporting in copy_to_user for Niagara 4
  sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
  sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
  sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC
  IB/sa: Fix sa_local_svc_timeout_ms read race
  RDMA/core: Resolve MAC of next-hop device without ARP support
  wifi: mt76: fix potential memory leak in mt76_wmac_probe()
  drivers/base/node: handle error properly in register_one_node()
  watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog
  netfilter: ipset: Remove unused htable_bits in macro ahash_region
  iio: consumers: Fix offset handling in iio_convert_raw_to_processed()
  ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
  ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
  ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
  pps: fix warning in pps_register_cdev when register device fail
  misc: genwqe: Fix incorrect cmd field being reported in error
  usb: gadget: configfs: Correctly set use_os_string at bind
  usb: phy: twl6030: Fix incorrect type for ret
  tcp: fix __tcp_close() to only send RST when required
  PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation
  wifi: mwifiex: send world regulatory domain to driver
  ALSA: lx_core: use int type to store negative error codes
  media: rj54n1cb0c: Fix memleak in rj54n1_probe()
  scsi: myrs: Fix dma_alloc_coherent() error check
  scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
  serial: max310x: Add error checking in probe()
  usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
  drm/radeon/r600_cs: clean up of dead code in r600_cs
  i2c: designware: Add disabling clocks when probe fails
  i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
  bpf: Explicitly check accesses to bpf_sock_addr
  selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
  pwm: tiehrpwm: Fix corner case in clock divisor calculation
  block: use int to store blk_stack_limits() return value
  blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
  pinctrl: meson-gxl: add missing i2c_d pinmux
  soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
  ACPI: processor: idle: Fix memory leak when register cpuidle device failed
  regmap: Remove superfluous check for !config in __regmap_init()
  x86/vdso: Fix output operand size of RDPID
  perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
  driver core/PM: Set power.no_callbacks along with power.no_pm
  staging: axis-fifo: flush RX FIFO on read errors
  staging: axis-fifo: fix maximum TX packet length check
  perf subcmd: avoid crash in exclude_cmds when excludes is empty
  dm-integrity: limit MAX_TAG_SIZE to 255
  wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
  USB: serial: option: add SIMCom 8230C compositions
  media: rc: fix races with imon_disconnect()
  media: imon: grab lock earlier in imon_ir_change_protocol()
  media: imon: reorganize serialization
  media: rc: Add support for another iMON 0xffdc device
  media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
  media: tuner: xc5000: Fix use-after-free in xc5000_release
  media: tunner: xc5000: Refactor firmware load
  udp: Fix memory accounting leak.
  media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
  scsi: target: target_core_configfs: Add length check to avoid buffer overflow

 Conflicts:
	drivers/soc/qcom/rpmh-rsc.c
	kernel/sched/fair.c

Change-Id: I58ab24a3db8be4c698c41fd47daeb1f1fb7884ee
2025-12-04 19:21:35 +02:00
Greg Kroah-Hartman
d13b9b5a0a Merge tag 'android11-5.4.301_r00' into android11-5.4
This merges the android11-5.4.301_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

* 6c4d697461 ANDROID: GKI: fix up build break where timer_delete_sync() was used
* d9d086d36e Revert "net: rtnetlink: remove redundant assignment to variable err"
* 85c7d734c7 Revert "net: rtnetlink: add msg kind names"
* 3f77162543 Revert "net: rtnetlink: add helper to extract msg type's kind"
* 2c1c741fc7 Revert "net: rtnetlink: use BIT for flag values"
* 11a4078a8a Revert "net: netlink: add NLM_F_BULK delete request modifier"
* fc27935e9f Revert "net: rtnetlink: add bulk delete support flag"
* 49a5ba893c Revert "net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg"
* 2a0670011e Revert "net: add ndo_fdb_del_bulk"
* af72578d25 Revert "net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del"
* 13a2c8a68f Revert "rtnetlink: Allow deleting FDB entries in user namespace"
*   f6520a7c91 Merge 5.4.301 into android11-5.4-lts
|\
| * 2e58fc1413 Linux 5.4.301
| * 283ee8ce3b net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
| * 7d993371c1 media: s5p-mfc: remove an unused/uninitialized variable
| * 61e8a8c424 NFSD: Fix last write offset handling in layoutcommit
| * 702d8d6e7e NFSD: Minor cleanup in layoutcommit processing
| * a39ae0d8f8 padata: Reset next CPU when reorder sequence wraps around
| * 07861d6371 KEYS: trusted_tpm1: Compare HMAC values in constant time
| * a75994dd87 NFSD: Define a proc_layoutcommit for the FlexFiles layout type
| * b5abafd0aa vfs: Don't leak disconnected dentries on umount
| * 71cdb58dc7 jbd2: ensure that all ongoing I/O complete before freeing blocks
| * 4954d297c9 ext4: detect invalid INLINE_DATA + EXTENTS flag combination
| * 301c668d5e drm/amdgpu: use atomic functions with memory barriers for vm fault info
| * 7bf46ff83a ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
| * 05eb29effe spi: cadence-quadspi: Flush posted register writes before DAC access
| * 4612070e4c spi: cadence-quadspi: Flush posted register writes before INDAC access
| * 5879837bfe memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
| * a8e7fc99d4 memory: samsung: exynos-srom: Correct alignment
| * 133bb61caf arm64: errata: Apply workarounds for Neoverse-V3AE
| * 0db16ce5e5 arm64: cputype: Add Neoverse-V3AE definitions
| * 4ffea48c69 comedi: fix divide-by-zero in comedi_buf_munge()
| * 9d053f9856 binder: remove "invalid inc weak" check
| * 428c804752 xhci: dbc: enable back DbC in resume if it was enabled before suspend
| * 02a089cf40 usb/core/quirks: Add Huawei ME906S to wakeup quirk
| * 2b24cd3ab1 USB: serial: option: add Telit FN920C04 ECM compositions
| * e9639d4237 USB: serial: option: add Quectel RG255C
| * 84c73088ec USB: serial: option: add UNISOC UIS7720
| * 14b68ab4f6 net: ravb: Ensure memory write completes before ringing TX doorbell
| * a8749742e6 net: usb: rtl8150: Fix frame padding
| * 93166bc53c ocfs2: clear extent cache after moving/defragmenting extents
| * d7fb245842 MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
| * 5568efa5bd Revert "cpuidle: menu: Avoid discarding useful information"
| * 839028e70a net: bonding: fix possible peer notify event loss or dup issue
| * 61cda2777b sctp: avoid NULL dereference when chunk data buffer is missing
| * b735a3e81b arm64, mm: avoid always making PTE dirty in pte_mkwrite()
| * 5f192fdc26 net: enetc: correct the value of ENETC_RXB_TRUESIZE
| * 509da3463f rtnetlink: Allow deleting FDB entries in user namespace
| * 4b7140925d net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del
| * 7111cc9552 net: add ndo_fdb_del_bulk
| * 2b0d1dc340 net: rtnetlink: add bulk delete support flag
| * 6dea96a841 net: netlink: add NLM_F_BULK delete request modifier
| * b3eed4bf84 net: rtnetlink: use BIT for flag values
| * 85c154222d net: rtnetlink: add helper to extract msg type's kind
| * a8b1eeb931 net: rtnetlink: add msg kind names
| * c49d31809a net: rtnetlink: remove redundant assignment to variable err
| * fdc8217820 m68k: bitops: Fix find_*_bit() signatures
| * 7e173b4ee1 hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super()
| * fc56548fca hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
| * 1b87b8f872 dlm: check for defined force value in dlm_lockspace_release
| * a2bee43b45 hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
| * f7d9f600c7 hfs: validate record offset in hfsplus_bmap_alloc
| * c1ec90bed5 hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
| * f823d27308 hfs: make proper initalization of struct hfs_find_data
| * 257271282a hfs: clear offset and space out of valid records in b-tree node
| * 577b13e5b2 exec: Fix incorrect type for ret
| * 603158d4ef hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
| * 7196826274 ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
| * d0936c8b07 sched/fair: Fix pelt lost idle time detection
| * ca51183ed9 sched/balancing: Rename newidle_balance() => sched_balance_newidle()
| * 7335a5a006 sched/fair: Trivial correction of the newidle_balance() comment
| * d8dd04003c sched: Make newidle_balance() static again
| * 3477af7026 tls: don't rely on tx_work during send()
| * 12027b0990 tls: always set record_type in tls_process_cmsg
| * e06a8f2ff7 tg3: prevent use of uninitialized remote_adv and local_adv variables
| * 8b7ac7af3a tcp: fix tcp_tso_should_defer() vs large RTT
| * 96fac1bbd2 amd-xgbe: Avoid spurious link down messages during interface toggle
| * 566f8d5c8a net/ip6_tunnel: Prevent perpetual tunnel growth
| * eb8be540b5 net: dlink: handle dma_map_single() failure properly
| * 75ca4fd107 net: dl2k: switch from 'pci_' to 'dma_' API
| * 6c397c1b33 media: pci: ivtv: Add missing check after DMA map
| * 1b00b73350 media: pci/ivtv: switch from 'pci_' to 'dma_' API
| * 979dca8d24 xen/events: Update virq_to_irq on migration
| * 83fc1f68fb media: lirc: Fix error handling in lirc_register()
| * bc35a8cc8a media: rc: Directly use ida_free()
| * e73416a108 drm/exynos: exynos7_drm_decon: remove ctx->suspended
| * 60de2f55d2 btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
| * da3cadb8b0 pwm: berlin: Fix wrong register in suspend/resume
| * 18b7e4b960 media: cx18: Add missing check after DMA map
| * 0aa9e273ac xen/events: Cleanup find_virq() return codes
| * 68151c7120 cramfs: Verify inode mode when loading from disk
| * 6ad65ae94d fs: Add 'initramfs_options' to set initramfs mount options
| * 75dbc029c5 pid: Add a judgment for ns null in pid_nr_ns
| * 6b9f2563bd minixfs: Verify inode mode when loading from disk
| * 07926ce598 tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
| * 9dc43ea6a2 dm: fix NULL pointer dereference in __dm_suspend()
| * 642ff39838 mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag
| * 09fa52968a mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type
| * b8a2083822 mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value
| * 54170057a5 Squashfs: reject negative file sizes in squashfs_read_inode()
| * 5b5cd739c5 Squashfs: add additional inode sanity checking
| * dd156f44ea media: mc: Clear minor number before put device
| * 38bdc302c5 mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data()
| * 14496175b2 fs: udf: fix OOB read in lengthAllocDescs handling
| * a908eca437 KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
| * a5901a0dfb net/9p: fix double req put in p9_fd_cancelled
| * ea39e712c2 ext4: guard against EA inode refcount underflow in xattr update
| * 7a1286e5a8 ext4: correctly handle queries for metadata mappings
| * a87def3f44 ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch()
| * 16013e03e4 nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
| * 1c572370fd x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases)
| * ad5c71fa9b x86/umip: Check that the instruction opcode is at least two bytes
| * e1bfc50444 PCI: keystone: Use devm_request_irq() to free "ks-pcie-error-irq" on exit
| * 43a7d0beff PCI/AER: Fix missing uevent on recovery when a reset is requested
| * 5c1cd7d405 PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
| * 9f363bf6f9 rseq/selftests: Use weak symbol reference, not definition, to link with glibc
| * 524e37f785 rtc: interface: Fix long-standing race when setting alarm
| * 755e5a8ffb rtc: interface: Ensure alarm irq is enabled when UIE is enabled
| * 8613c9fb1c mmc: core: SPI mode remove cmd7
| * d70c726547 mtd: rawnand: fsmc: Default to autodetect buswidth
| * bf70d603af sparc: fix error handling in scan_one_device()
| * bbb085bc0a sparc64: fix hugetlb for sun4u
| * b93fa8dc52 sctp: Fix MAC comparison to be constant-time
| * 76307bb571 scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl()
| * 9cad93c788 parisc: don't reference obsolete termio struct for TC* constants
| * 41e5d9cef3 lib/genalloc: fix device leak in of_gen_pool_get()
| * e19da48937 iio: frequency: adf4350: Fix prescaler usage.
| * ae75b83897 iio: dac: ad5421: use int type to store negative error codes
| * d0bdae59b2 iio: dac: ad5360: use int type to store negative error codes
| * 4819f5f864 crypto: atmel - Fix dma_unmap_sg() direction
| * 15ac9579eb cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
| * 868ce19497 drm/nouveau: fix bad ret code in nouveau_bo_move_prep
| * 9dc4dc99f9 media: i2c: mt9v111: fix incorrect type for ret
| * f08cbec8ce firmware: meson_sm: fix device leak at probe
| * aa35033261 xen/manage: Fix suspend error path
| * fe9f84cc90 arm64: dts: qcom: msm8916: Add missing MDSS reset
| * 6beaa602f6 ACPI: debug: fix signedness issues in read/write helpers
| * e2512755bc ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
| * 41d73f8054 tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
| * dae78a1d64 tpm, tpm_tis: Claim locality before writing interrupt registers
| * 29294dd6f1 crypto: essiv - Check ssize for decryption and in-place encryption
| * 4e5a929f5c mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes
| * 5906eede6f mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call
| * aeb1fe8a52 tools build: Align warning options with perf
| * 7a12f1a184 net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe
| * e359b742ea tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
| * 1014b83778 net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
| * 1822e5287b drm/vmwgfx: Fix Use-after-free in validation
| * 2357cf8954 net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter()
| * a6f68f219d scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
| * 87e2fc78aa scsi: mvsas: Use sas_task_find_rq() for tagging
| * 3a635fab5c scsi: mvsas: Delete mvs_tag_init()
| * c51f9de091 scsi: libsas: Add sas_task_find_rq()
| * 0cbbf2741f clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
| * 5bc41ef2e7 clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
| * 681e7a933f perf session: Fix handling when buffer exceeds 2 GiB
| * c8a20c9ef7 rtc: x1205: Fix Xicor X1205 vendor prefix
| * bc4eb7e7df perf util: Fix compression checks returning -1 as bool
| * 662995895f iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
| * 20fd916244 clocksource/drivers/clps711x: Fix resource leaks in error paths
| * 1a7fc8fed2 pinctrl: check the return value of pinmux_ops::get_function_name()
| * 1b31779601 Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
| * 30498c44c2 mm: hugetlb: avoid soft lockup when mprotect to large memory area
| * 540aac117e uio_hv_generic: Let userspace take care of interrupt mask
| * f81a5bc9e9 Squashfs: fix uninit-value in squashfs_get_parent
| * d8e8528007 Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
| * 49f9f4c5cb net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable
| * 21f7d60a89 nfp: fix RSS hash key size when RSS is not supported
| * ef442edff2 drivers/base/node: fix double free in register_one_node()
| * 283333079d ocfs2: fix double free in user_cluster_connect()
| * cce3c0e21c net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
| * 18b8163807 RDMA/siw: Always report immediate post SQ errors
| * 0ba8541351 usb: vhci-hcd: Prevent suspending virtually attached devices
| * b3a6d15386 scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
| * 8a6ecab384 ipvs: Defer ip_vs_ftp unregister during netns cleanup
| * 5e4b916024 NFSv4.1: fix backchannel max_resp_sz verification check
| * f29579803b remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice
| * 03db640a5c sparc: fix accurate exception reporting in copy_{from,to}_user for M7
| * c171f8e02a sparc: fix accurate exception reporting in copy_to_user for Niagara 4
| * 05440320ea sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
| * fdd43fe6d2 sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
| * 0bf3dc3a21 sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC
| * b81739e033 IB/sa: Fix sa_local_svc_timeout_ms read race
| * bd1aaea359 RDMA/core: Resolve MAC of next-hop device without ARP support
| * c24a1f683b wifi: mt76: fix potential memory leak in mt76_wmac_probe()
| * 9f4ef845d2 drivers/base/node: handle error properly in register_one_node()
| * 7b323e67d2 watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog
| * e16592112d netfilter: ipset: Remove unused htable_bits in macro ahash_region
| * e7c31aac98 iio: consumers: Fix offset handling in iio_convert_raw_to_processed()
| * bff827b0d5 ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
| * 2c27e047bd ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
| * ef7028c957 ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
| * 38c7bb10aa pps: fix warning in pps_register_cdev when register device fail
| * 3564c62d10 misc: genwqe: Fix incorrect cmd field being reported in error
| * b86de42c42 usb: gadget: configfs: Correctly set use_os_string at bind
| * a88df38970 usb: phy: twl6030: Fix incorrect type for ret
| * 4f88c5c187 tcp: fix __tcp_close() to only send RST when required
| * c523bdc6ae PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation
| * 58ce953c01 wifi: mwifiex: send world regulatory domain to driver
| * 534b6c26d1 ALSA: lx_core: use int type to store negative error codes
| * a05e38d179 media: rj54n1cb0c: Fix memleak in rj54n1_probe()
| * d186a8200b scsi: myrs: Fix dma_alloc_coherent() error check
| * d94be0a6ae scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
| * 148aba0be5 serial: max310x: Add error checking in probe()
| * 89838fe5c6 usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
| * 3e992a82d5 drm/radeon/r600_cs: clean up of dead code in r600_cs
| * 46b35621d6 i2c: designware: Add disabling clocks when probe fails
| * 7dc48c447a i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
| * de44cdc50d bpf: Explicitly check accesses to bpf_sock_addr
| * 93818c7ce4 selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
| * abf7cf212a pwm: tiehrpwm: Fix corner case in clock divisor calculation
| * 48d6e1424c block: use int to store blk_stack_limits() return value
| * a8c53553f1 blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
| * 6d39bc327c pinctrl: meson-gxl: add missing i2c_d pinmux
| * cdf96ac33a soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
| * 7c4d9b3177 ACPI: processor: idle: Fix memory leak when register cpuidle device failed
| * 4b48bfa2e5 regmap: Remove superfluous check for !config in __regmap_init()
| * dfd57c6210 x86/vdso: Fix output operand size of RDPID
| * 656e9a5d69 perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
| * a9f8f33f5d driver core/PM: Set power.no_callbacks along with power.no_pm
| * 86bdd3deca staging: axis-fifo: flush RX FIFO on read errors
| * 5873888534 staging: axis-fifo: fix maximum TX packet length check
| * e58778d9c8 perf subcmd: avoid crash in exclude_cmds when excludes is empty
| * cbffccccc8 dm-integrity: limit MAX_TAG_SIZE to 255
| * 463222f233 wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
| * a1f24c2e91 USB: serial: option: add SIMCom 8230C compositions
| * 9348976003 media: rc: fix races with imon_disconnect()
| * e1b1ba1864 media: imon: grab lock earlier in imon_ir_change_protocol()
| * ab5d16511e media: imon: reorganize serialization
| * f61cad824f media: rc: Add support for another iMON 0xffdc device
| * 9205fb6e61 media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
| * bc4ffd962c media: tuner: xc5000: Fix use-after-free in xc5000_release
| * 0006640fb7 media: tunner: xc5000: Refactor firmware load
| * 1355027317 udp: Fix memory accounting leak.
| * 607010d07b media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
| * e6eeee5dc0 scsi: target: target_core_configfs: Add length check to avoid buffer overflow
* cdb7045549 Merge android11-5.4 into android11-5.4-lts

Change-Id: If506ff4ca59154a08ec491ff09df49463e952cb7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-11-24 09:59:06 +00:00
Herbert Xu
0a4bf073fa UPSTREAM: crypto: essiv - Check ssize for decryption and in-place encryption
[ Upstream commit 6bb73db6948c2de23e407fe1b7ef94bf02b7529f ]

Move the ssize check to the start in essiv_aead_crypt so that
it's also checked for decryption and in-place encryption.

Bug: 451939108
Reported-by: Muhammad Alifa Ramdhan <ramdhan@starlabs.sg>
Fixes: be1eb7f78a ("crypto: essiv - create wrapper template for ESSIV generation")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit dc4c854a5e7453c465fa73b153eba4ef2a240abe)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I675993b4640189861f0fe8a3f61a89c2f3821f19
2025-11-17 14:17:53 +00:00
Michael Bestas
92d61f8f0f
Merge tag 'LA.UM.9.14.r1-26500-LAHAINA.QSSI16.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
LA.UM.9.14.r1-26500-LAHAINA.QSSI16.0

* tag 'LA.UM.9.14.r1-26500-LAHAINA.QSSI16.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  msm: mhi_dev: Avoid BME check while sending ready
  FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
  FROMGIT: media: venus: hfi: add check to handle incorrect queue size
  FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
  FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
  defconfig: Enable RTL8152 ETH-USB driver
  msm: Add Kconfig for RTL8152 driver
  defconfig: Disable upstream RTL8152 ETH-USB driver
  qseecom: Remove virtual address print

 Conflicts:
	arch/arm64/boot/dts/vendor/bindings/clock/adi,axi-clkgen.yaml
	arch/arm64/boot/dts/vendor/bindings/gpu/samsung-rotator.yaml
	arch/arm64/boot/dts/vendor/bindings/vendor-prefixes.yaml
	drivers/clk/qcom/clk-rpmh.c
	drivers/rpmsg/qcom_glink_native.c
	drivers/soc/qcom/smcinvoke.c
	drivers/soc/qcom/socinfo.c
	drivers/usb/dwc3/core.c
	fs/userfaultfd.c
	mm/madvise.c

Change-Id: I76d04fb5422490ff302dad1460426db1b573f4c9
2025-11-08 16:13:44 +02:00
Michael Bestas
50786b5180
Merge tag 'ASB-2025-11-03_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-11-01

* tag 'ASB-2025-11-03_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: soc: qcom: mdt_loader: Deal with zero e_shentsize

Change-Id: I2c07f1f7b154c228f3174807fe686e7660f45590
2025-11-08 15:59:31 +02:00
Greg Kroah-Hartman
6c4d697461 ANDROID: GKI: fix up build break where timer_delete_sync() was used
We reverted the commit that renamed del_timer_sync() to
timer_delete_sync() a long while back, but that breaks the build when
new users of the call get merged into LTS releases.  Fix the tc358743
driver by using the "old" name of the function.

Fixes: 9205fb6e61 ("media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe")
Change-Id: I56b1a69965937b3187978d0ae04d8c483916290f
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 08:05:55 +00:00
Greg Kroah-Hartman
d9d086d36e Revert "net: rtnetlink: remove redundant assignment to variable err"
This reverts commit c49d31809a which is
commit 7d3118016787b5c05da94b3bcdb96c9d6ff82c44 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I29e9d676be00412288460401a10b4c456aa90f99
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:59:01 +00:00
Greg Kroah-Hartman
85c7d734c7 Revert "net: rtnetlink: add msg kind names"
This reverts commit a8b1eeb931 which is
commit 12dc5c2cb7b269c5a1c6d02844f40bfce942a7a6 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I780457e01724f9a48db68aefe4cd71a6628174e0
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:56 +00:00
Greg Kroah-Hartman
3f77162543 Revert "net: rtnetlink: add helper to extract msg type's kind"
This reverts commit 85c154222d which is
commit 2e9ea3e30f696fd438319c07836422bb0bbb4608 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I8cde97f239eaf15d952948581987bfa4f1bcb28b
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:52 +00:00
Greg Kroah-Hartman
2c1c741fc7 Revert "net: rtnetlink: use BIT for flag values"
This reverts commit b3eed4bf84 which is
commit 0569e31f1bc2f50613ba4c219f3ecc0d1174d841 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Idf0c4ae34007eabf54c7269dfb5bd6ec5aca6b9f
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:48 +00:00
Greg Kroah-Hartman
11a4078a8a Revert "net: netlink: add NLM_F_BULK delete request modifier"
This reverts commit 6dea96a841 which is
commit 545528d788556c724eeb5400757f828ef27782a8 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I8481c837c6822c562f748152030b18b2bf780dfe
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:44 +00:00
Greg Kroah-Hartman
fc27935e9f Revert "net: rtnetlink: add bulk delete support flag"
This reverts commit 2b0d1dc340 which is
commit a6cec0bcd34264be8887791594be793b3f12719f upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I8cc1e6be45fdc9d34a8cd5972d5e3a16a94a9825
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:37 +00:00
Greg Kroah-Hartman
49a5ba893c Revert "net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg"
This reverts commit 283ee8ce3b which is
commit 5b22f62724a0a09e00d301abf5b57b0c12be8a16 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Id94f628d7244f7360069b2f03e192007b5eb1c9c
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:58:01 +00:00
Greg Kroah-Hartman
2a0670011e Revert "net: add ndo_fdb_del_bulk"
This reverts commit 7111cc9552 which is
commit 1306d5362a591493a2d07f685ed2cc480dcda320 upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I148a599c2a5b94238b0bfacd354e670dbb03f710
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:56:01 +00:00
Greg Kroah-Hartman
af72578d25 Revert "net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del"
This reverts commit 4b7140925d which is
commit 9e83425993f38bb89e0ea07849ba0039a748e85b upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I065c84bd7cc13eb97aacf866af01a8b5c93d3d64
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:55:57 +00:00
Greg Kroah-Hartman
13a2c8a68f Revert "rtnetlink: Allow deleting FDB entries in user namespace"
This reverts commit 509da3463f which is
commit bf29555f5bdc017bac22ca66fcb6c9f46ec8788f upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Id85d10ca56c12b015364a2440c540f6d89203366
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-31 07:55:53 +00:00
Greg Kroah-Hartman
f6520a7c91 This is the 5.4.301 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmkCD9kACgkQONu9yGCS
 aT756BAAwEcL3lKO/0QKjMUrvgv7FRoRm9TH9Usq7Nswmiax6YKI3oPgZKfZZL6u
 yLGSnYqV8f+Jo8kALMJAybu+Oc3Z8WbBZJG/dvlAkvR7iN19ZCuKa2NwWmh8BTGd
 5ZP4/nyXlNlg0/IIZ8xJa3067U895y9IhgMDmSvOZoUFGFecqUmJNBoj8bHgJaPL
 /MENYb7D0CcKWbgCwzsqN0EEm9UKb7xgtaaC52sfZD+GHUPF/RLq9QNyUGtyL0m8
 y20HG6zXmBiVP+zdtYpTaaEP6OSNOCmiOweSZOFafnatd2XO1hRdnAoEk7+t2Lj+
 Xa5GowVUuglmBd8bPbeY8cwVihMxr81DxMns+OpQJTiDD8Q6Whcxbaqwv+tVe7z4
 cVDh1xlKG4U2rsDTeiGhbZVNb6gqqy3LnVFqImQE+dcZqlwC0pbqwO2lLdHMa8NF
 f+l1U3ab0k9qYx8HQegYDTufW5Eb0Rki/3YyHk8o3alOYd2Oc3r16lw9rpSw2Nq3
 Rku+VMSy6z8uvmIP7Ywobla6j73SGFrDc61F0nsU1x+Gd/dMIgkn36dfxciBCgPa
 /AmkK1Psx04s7dIPMowx/nXy5Jk8J4k3JlVMeBnMCuFVUNCNp3qzq5WXdeL1G5f5
 GFPJPblaZrfKQNSSlpUAmstl8v5t8aJcjxobmHn28fVliFAJdDI=
 =XPvH
 -----END PGP SIGNATURE-----

Merge 5.4.301 into android11-5.4-lts

Changes in 5.4.301
	scsi: target: target_core_configfs: Add length check to avoid buffer overflow
	media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
	udp: Fix memory accounting leak.
	media: tunner: xc5000: Refactor firmware load
	media: tuner: xc5000: Fix use-after-free in xc5000_release
	media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
	media: rc: Add support for another iMON 0xffdc device
	media: imon: reorganize serialization
	media: imon: grab lock earlier in imon_ir_change_protocol()
	media: rc: fix races with imon_disconnect()
	USB: serial: option: add SIMCom 8230C compositions
	wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
	dm-integrity: limit MAX_TAG_SIZE to 255
	perf subcmd: avoid crash in exclude_cmds when excludes is empty
	staging: axis-fifo: fix maximum TX packet length check
	staging: axis-fifo: flush RX FIFO on read errors
	driver core/PM: Set power.no_callbacks along with power.no_pm
	perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
	x86/vdso: Fix output operand size of RDPID
	regmap: Remove superfluous check for !config in __regmap_init()
	ACPI: processor: idle: Fix memory leak when register cpuidle device failed
	soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
	pinctrl: meson-gxl: add missing i2c_d pinmux
	blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
	block: use int to store blk_stack_limits() return value
	pwm: tiehrpwm: Fix corner case in clock divisor calculation
	selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported
	bpf: Explicitly check accesses to bpf_sock_addr
	i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
	i2c: designware: Add disabling clocks when probe fails
	drm/radeon/r600_cs: clean up of dead code in r600_cs
	usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup
	serial: max310x: Add error checking in probe()
	scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
	scsi: myrs: Fix dma_alloc_coherent() error check
	media: rj54n1cb0c: Fix memleak in rj54n1_probe()
	ALSA: lx_core: use int type to store negative error codes
	wifi: mwifiex: send world regulatory domain to driver
	PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation
	tcp: fix __tcp_close() to only send RST when required
	usb: phy: twl6030: Fix incorrect type for ret
	usb: gadget: configfs: Correctly set use_os_string at bind
	misc: genwqe: Fix incorrect cmd field being reported in error
	pps: fix warning in pps_register_cdev when register device fail
	ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
	ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
	ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
	iio: consumers: Fix offset handling in iio_convert_raw_to_processed()
	netfilter: ipset: Remove unused htable_bits in macro ahash_region
	watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog
	drivers/base/node: handle error properly in register_one_node()
	wifi: mt76: fix potential memory leak in mt76_wmac_probe()
	RDMA/core: Resolve MAC of next-hop device without ARP support
	IB/sa: Fix sa_local_svc_timeout_ms read race
	sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC
	sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III
	sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara
	sparc: fix accurate exception reporting in copy_to_user for Niagara 4
	sparc: fix accurate exception reporting in copy_{from,to}_user for M7
	remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice
	NFSv4.1: fix backchannel max_resp_sz verification check
	ipvs: Defer ip_vs_ftp unregister during netns cleanup
	scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
	usb: vhci-hcd: Prevent suspending virtually attached devices
	RDMA/siw: Always report immediate post SQ errors
	net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
	ocfs2: fix double free in user_cluster_connect()
	drivers/base/node: fix double free in register_one_node()
	nfp: fix RSS hash key size when RSS is not supported
	net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable
	Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
	Squashfs: fix uninit-value in squashfs_get_parent
	uio_hv_generic: Let userspace take care of interrupt mask
	mm: hugetlb: avoid soft lockup when mprotect to large memory area
	Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
	pinctrl: check the return value of pinmux_ops::get_function_name()
	clocksource/drivers/clps711x: Fix resource leaks in error paths
	iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
	perf util: Fix compression checks returning -1 as bool
	rtc: x1205: Fix Xicor X1205 vendor prefix
	perf session: Fix handling when buffer exceeds 2 GiB
	clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate()
	clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
	scsi: libsas: Add sas_task_find_rq()
	scsi: mvsas: Delete mvs_tag_init()
	scsi: mvsas: Use sas_task_find_rq() for tagging
	scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
	net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter()
	drm/vmwgfx: Fix Use-after-free in validation
	net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
	tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
	net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe
	tools build: Align warning options with perf
	mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call
	mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes
	crypto: essiv - Check ssize for decryption and in-place encryption
	tpm, tpm_tis: Claim locality before writing interrupt registers
	tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
	ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
	ACPI: debug: fix signedness issues in read/write helpers
	arm64: dts: qcom: msm8916: Add missing MDSS reset
	xen/manage: Fix suspend error path
	firmware: meson_sm: fix device leak at probe
	media: i2c: mt9v111: fix incorrect type for ret
	drm/nouveau: fix bad ret code in nouveau_bo_move_prep
	cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
	crypto: atmel - Fix dma_unmap_sg() direction
	iio: dac: ad5360: use int type to store negative error codes
	iio: dac: ad5421: use int type to store negative error codes
	iio: frequency: adf4350: Fix prescaler usage.
	lib/genalloc: fix device leak in of_gen_pool_get()
	parisc: don't reference obsolete termio struct for TC* constants
	scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl()
	sctp: Fix MAC comparison to be constant-time
	sparc64: fix hugetlb for sun4u
	sparc: fix error handling in scan_one_device()
	mtd: rawnand: fsmc: Default to autodetect buswidth
	mmc: core: SPI mode remove cmd7
	rtc: interface: Ensure alarm irq is enabled when UIE is enabled
	rtc: interface: Fix long-standing race when setting alarm
	rseq/selftests: Use weak symbol reference, not definition, to link with glibc
	PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
	PCI/AER: Fix missing uevent on recovery when a reset is requested
	PCI: keystone: Use devm_request_irq() to free "ks-pcie-error-irq" on exit
	x86/umip: Check that the instruction opcode is at least two bytes
	x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases)
	nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
	ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch()
	ext4: correctly handle queries for metadata mappings
	ext4: guard against EA inode refcount underflow in xattr update
	net/9p: fix double req put in p9_fd_cancelled
	KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
	fs: udf: fix OOB read in lengthAllocDescs handling
	mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data()
	media: mc: Clear minor number before put device
	Squashfs: add additional inode sanity checking
	Squashfs: reject negative file sizes in squashfs_read_inode()
	mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value
	mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type
	mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag
	dm: fix NULL pointer dereference in __dm_suspend()
	tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
	minixfs: Verify inode mode when loading from disk
	pid: Add a judgment for ns null in pid_nr_ns
	fs: Add 'initramfs_options' to set initramfs mount options
	cramfs: Verify inode mode when loading from disk
	xen/events: Cleanup find_virq() return codes
	media: cx18: Add missing check after DMA map
	pwm: berlin: Fix wrong register in suspend/resume
	btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
	drm/exynos: exynos7_drm_decon: remove ctx->suspended
	media: rc: Directly use ida_free()
	media: lirc: Fix error handling in lirc_register()
	xen/events: Update virq_to_irq on migration
	media: pci/ivtv: switch from 'pci_' to 'dma_' API
	media: pci: ivtv: Add missing check after DMA map
	net: dl2k: switch from 'pci_' to 'dma_' API
	net: dlink: handle dma_map_single() failure properly
	net/ip6_tunnel: Prevent perpetual tunnel growth
	amd-xgbe: Avoid spurious link down messages during interface toggle
	tcp: fix tcp_tso_should_defer() vs large RTT
	tg3: prevent use of uninitialized remote_adv and local_adv variables
	tls: always set record_type in tls_process_cmsg
	tls: don't rely on tx_work during send()
	sched: Make newidle_balance() static again
	sched/fair: Trivial correction of the newidle_balance() comment
	sched/balancing: Rename newidle_balance() => sched_balance_newidle()
	sched/fair: Fix pelt lost idle time detection
	ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
	hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp()
	exec: Fix incorrect type for ret
	hfs: clear offset and space out of valid records in b-tree node
	hfs: make proper initalization of struct hfs_find_data
	hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
	hfs: validate record offset in hfsplus_bmap_alloc
	hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat()
	dlm: check for defined force value in dlm_lockspace_release
	hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
	hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super()
	m68k: bitops: Fix find_*_bit() signatures
	net: rtnetlink: remove redundant assignment to variable err
	net: rtnetlink: add msg kind names
	net: rtnetlink: add helper to extract msg type's kind
	net: rtnetlink: use BIT for flag values
	net: netlink: add NLM_F_BULK delete request modifier
	net: rtnetlink: add bulk delete support flag
	net: add ndo_fdb_del_bulk
	net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del
	rtnetlink: Allow deleting FDB entries in user namespace
	net: enetc: correct the value of ENETC_RXB_TRUESIZE
	arm64, mm: avoid always making PTE dirty in pte_mkwrite()
	sctp: avoid NULL dereference when chunk data buffer is missing
	net: bonding: fix possible peer notify event loss or dup issue
	Revert "cpuidle: menu: Avoid discarding useful information"
	MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
	ocfs2: clear extent cache after moving/defragmenting extents
	net: usb: rtl8150: Fix frame padding
	net: ravb: Ensure memory write completes before ringing TX doorbell
	USB: serial: option: add UNISOC UIS7720
	USB: serial: option: add Quectel RG255C
	USB: serial: option: add Telit FN920C04 ECM compositions
	usb/core/quirks: Add Huawei ME906S to wakeup quirk
	xhci: dbc: enable back DbC in resume if it was enabled before suspend
	binder: remove "invalid inc weak" check
	comedi: fix divide-by-zero in comedi_buf_munge()
	arm64: cputype: Add Neoverse-V3AE definitions
	arm64: errata: Apply workarounds for Neoverse-V3AE
	memory: samsung: exynos-srom: Correct alignment
	memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
	spi: cadence-quadspi: Flush posted register writes before INDAC access
	spi: cadence-quadspi: Flush posted register writes before DAC access
	ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
	drm/amdgpu: use atomic functions with memory barriers for vm fault info
	ext4: detect invalid INLINE_DATA + EXTENTS flag combination
	jbd2: ensure that all ongoing I/O complete before freeing blocks
	vfs: Don't leak disconnected dentries on umount
	NFSD: Define a proc_layoutcommit for the FlexFiles layout type
	KEYS: trusted_tpm1: Compare HMAC values in constant time
	padata: Reset next CPU when reorder sequence wraps around
	NFSD: Minor cleanup in layoutcommit processing
	NFSD: Fix last write offset handling in layoutcommit
	media: s5p-mfc: remove an unused/uninitialized variable
	net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
	Linux 5.4.301

Change-Id: Ie2685625a0f630cb01ac8d8c9ddcd68c64ea6ed7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-10-30 07:52:10 +00:00
Greg Kroah-Hartman
2e58fc1413 Linux 5.4.301
Link: https://lore.kernel.org/r/20251027183508.963233542@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Pavel Machek (CIP) <pavel@denx.de>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Brett A C Sheffield <bacs@librecast.net>
Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:02 +01:00
Zhengchao Shao
283ee8ce3b net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg
commit 5b22f62724a0a09e00d301abf5b57b0c12be8a16 upstream.

When bulk delete command is received in the rtnetlink_rcv_msg function,
if bulk delete is not supported, module_put is not called to release
the reference counting. As a result, module reference count is leaked.

Fixes: a6cec0bcd342 ("net: rtnetlink: add bulk delete support flag")
Signed-off-by: Zhengchao Shao <shaozhengchao@huawei.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://lore.kernel.org/r/20220815024629.240367-1-shaozhengchao@huawei.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Arnd Bergmann
7d993371c1 media: s5p-mfc: remove an unused/uninitialized variable
[ Upstream commit 7fa37ba25a1dfc084e24ea9acc14bf1fad8af14c ]

The s5p_mfc_cmd_args structure in the v6 driver is never used, not
initialized to anything other than zero, but as of clang-21 this
causes a warning:

drivers/media/platform/samsung/s5p-mfc/s5p_mfc_cmd_v6.c:45:7: error: variable 'h2r_args' is uninitialized when passed as a const pointer argument here [-Werror,-Wuninitialized-const-pointer]
   45 |                                         &h2r_args);
      |                                          ^~~~~~~~

Just remove this for simplicity. Since the function is also called
through a callback, this does require adding a trivial wrapper with
the correct prototype.

Fixes: f96f3cfa0b ("[media] s5p-mfc: Update MFC v4l2 driver to support MFC6.x")
Cc: stable@vger.kernel.org
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
[ Adjust context ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Sergey Bashirov
61e8a8c424 NFSD: Fix last write offset handling in layoutcommit
[ Upstream commit d68886bae76a4b9b3484d23e5b7df086f940fa38 ]

The data type of loca_last_write_offset is newoffset4 and is switched
on a boolean value, no_newoffset, that indicates if a previous write
occurred or not. If no_newoffset is FALSE, an offset is not given.
This means that client does not try to update the file size. Thus,
server should not try to calculate new file size and check if it fits
into the segment range. See RFC 8881, section 12.5.4.2.

Sometimes the current incorrect logic may cause clients to hang when
trying to sync an inode. If layoutcommit fails, the client marks the
inode as dirty again.

Fixes: 9cf514ccfa ("nfsd: implement pNFS operations")
Cc: stable@vger.kernel.org
Co-developed-by: Konstantin Evtushenko <koevtushenko@yandex.com>
Signed-off-by: Konstantin Evtushenko <koevtushenko@yandex.com>
Signed-off-by: Sergey Bashirov <sergeybashirov@gmail.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
[ replaced inode_get_mtime() with inode->i_mtime and removed rqstp parameter from proc_layoutcommit() ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Sergey Bashirov
702d8d6e7e NFSD: Minor cleanup in layoutcommit processing
[ Upstream commit 274365a51d88658fb51cca637ba579034e90a799 ]

Remove dprintk in nfsd4_layoutcommit. These are not needed
in day to day usage, and the information is also available
in Wireshark when capturing NFS traffic.

Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Sergey Bashirov <sergeybashirov@gmail.com>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Stable-dep-of: d68886bae76a ("NFSD: Fix last write offset handling in layoutcommit")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Xiao Liang
a39ae0d8f8 padata: Reset next CPU when reorder sequence wraps around
[ Upstream commit 501302d5cee0d8e8ec2c4a5919c37e0df9abc99b ]

When seq_nr wraps around, the next reorder job with seq 0 is hashed to
the first CPU in padata_do_serial(). Correspondingly, need reset pd->cpu
to the first one when pd->processed wraps around. Otherwise, if the
number of used CPUs is not a power of 2, padata_find_next() will be
checking a wrong list, hence deadlock.

Fixes: 6fc4dbcf02 ("padata: Replace delayed timer with immediate workqueue in padata_reorder")
Cc: <stable@vger.kernel.org>
Signed-off-by: Xiao Liang <shaw.leon@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
[ moved from padata_reorder() to padata_find_next() function ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Eric Biggers
07861d6371 KEYS: trusted_tpm1: Compare HMAC values in constant time
[ Upstream commit eed0e3d305530066b4fc5370107cff8ef1a0d229 ]

To prevent timing attacks, HMAC value comparison needs to be constant
time.  Replace the memcmp() with the correct function, crypto_memneq().

[For the Fixes commit I used the commit that introduced the memcmp().
It predates the introduction of crypto_memneq(), but it was still a bug
at the time even though a helper function didn't exist yet.]

Fixes: d00a1c72f7 ("keys: add new trusted key-type")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
[ changed include from crypto/utils.h to crypto/algapi.h ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Chuck Lever
a75994dd87 NFSD: Define a proc_layoutcommit for the FlexFiles layout type
[ Upstream commit 4b47a8601b71ad98833b447d465592d847b4dc77 ]

Avoid a crash if a pNFS client should happen to send a LAYOUTCOMMIT
operation on a FlexFiles layout.

Reported-by: Robert Morris <rtm@csail.mit.edu>
Closes: https://lore.kernel.org/linux-nfs/152f99b2-ba35-4dec-93a9-4690e625dccd@oracle.com/T/#t
Cc: Thomas Haynes <loghyr@hammerspace.com>
Cc: stable@vger.kernel.org
Fixes: 9b9960a0ca ("nfsd: Add a super simple flex file server")
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
[ removed struct svc_rqst parameter from nfsd4_ff_proc_layoutcommit ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Jan Kara
b5abafd0aa vfs: Don't leak disconnected dentries on umount
[ Upstream commit 56094ad3eaa21e6621396cc33811d8f72847a834 ]

When user calls open_by_handle_at() on some inode that is not cached, we
will create disconnected dentry for it. If such dentry is a directory,
exportfs_decode_fh_raw() will then try to connect this dentry to the
dentry tree through reconnect_path(). It may happen for various reasons
(such as corrupted fs or race with rename) that the call to
lookup_one_unlocked() in reconnect_one() will fail to find the dentry we
are trying to reconnect and instead create a new dentry under the
parent. Now this dentry will not be marked as disconnected although the
parent still may well be disconnected (at least in case this
inconsistency happened because the fs is corrupted and .. doesn't point
to the real parent directory). This creates inconsistency in
disconnected flags but AFAICS it was mostly harmless. At least until
commit f1ee616214 ("VFS: don't keep disconnected dentries on d_anon")
which removed adding of most disconnected dentries to sb->s_anon list.
Thus after this commit cleanup of disconnected dentries implicitely
relies on the fact that dput() will immediately reclaim such dentries.
However when some leaf dentry isn't marked as disconnected, as in the
scenario described above, the reclaim doesn't happen and the dentries
are "leaked". Memory reclaim can eventually reclaim them but otherwise
they stay in memory and if umount comes first, we hit infamous "Busy
inodes after unmount" bug. Make sure all dentries created under a
disconnected parent are marked as disconnected as well.

Reported-by: syzbot+1d79ebe5383fc016cf07@syzkaller.appspotmail.com
Fixes: f1ee616214 ("VFS: don't keep disconnected dentries on d_anon")
CC: stable@vger.kernel.org
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Christian Brauner <brauner@kernel.org>
[ relocated DCACHE_DISCONNECTED propagation from d_alloc_parallel() to d_alloc() ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Zhang Yi
71cdb58dc7 jbd2: ensure that all ongoing I/O complete before freeing blocks
[ Upstream commit 3c652c3a71de1d30d72dc82c3bead8deb48eb749 ]

When releasing file system metadata blocks in jbd2_journal_forget(), if
this buffer has not yet been checkpointed, it may have already been
written back, currently be in the process of being written back, or has
not yet written back.  jbd2_journal_forget() calls
jbd2_journal_try_remove_checkpoint() to check the buffer's status and
add it to the current transaction if it has not been written back. This
buffer can only be reallocated after the transaction is committed.

jbd2_journal_try_remove_checkpoint() attempts to lock the buffer and
check its dirty status while holding the buffer lock. If the buffer has
already been written back, everything proceeds normally. However, there
are two issues. First, the function returns immediately if the buffer is
locked by the write-back process. It does not wait for the write-back to
complete. Consequently, until the current transaction is committed and
the block is reallocated, there is no guarantee that the I/O will
complete. This means that ongoing I/O could write stale metadata to the
newly allocated block, potentially corrupting data. Second, the function
unlocks the buffer as soon as it detects that the buffer is still dirty.
If a concurrent write-back occurs immediately after this unlocking and
before clear_buffer_dirty() is called in jbd2_journal_forget(), data
corruption can theoretically still occur.

Although these two issues are unlikely to occur in practice since the
undergoing metadata writeback I/O does not take this long to complete,
it's better to explicitly ensure that all ongoing I/O operations are
completed.

Fixes: 597599268e ("jbd2: discard dirty data when forgetting an un-journalled buffer")
Cc: stable@kernel.org
Suggested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Message-ID: <20250916093337.3161016-2-yi.zhang@huaweicloud.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
[ Adjust context ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Deepanshu Kartikey
4954d297c9 ext4: detect invalid INLINE_DATA + EXTENTS flag combination
[ Upstream commit 1d3ad183943b38eec2acf72a0ae98e635dc8456b ]

syzbot reported a BUG_ON in ext4_es_cache_extent() when opening a verity
file on a corrupted ext4 filesystem mounted without a journal.

The issue is that the filesystem has an inode with both the INLINE_DATA
and EXTENTS flags set:

    EXT4-fs error (device loop0): ext4_cache_extents:545: inode #15:
    comm syz.0.17: corrupted extent tree: lblk 0 < prev 66

Investigation revealed that the inode has both flags set:
    DEBUG: inode 15 - flag=1, i_inline_off=164, has_inline=1, extents_flag=1

This is an invalid combination since an inode should have either:
- INLINE_DATA: data stored directly in the inode
- EXTENTS: data stored in extent-mapped blocks

Having both flags causes ext4_has_inline_data() to return true, skipping
extent tree validation in __ext4_iget(). The unvalidated out-of-order
extents then trigger a BUG_ON in ext4_es_cache_extent() due to integer
underflow when calculating hole sizes.

Fix this by detecting this invalid flag combination early in ext4_iget()
and rejecting the corrupted inode.

Cc: stable@kernel.org
Reported-and-tested-by: syzbot+038b7bf43423e132b308@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=038b7bf43423e132b308
Suggested-by: Zhang Yi <yi.zhang@huawei.com>
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Message-ID: <20250930112810.315095-1-kartikey406@gmail.com>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
[ Adjust context ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Gui-Dong Han
301c668d5e drm/amdgpu: use atomic functions with memory barriers for vm fault info
[ Upstream commit 6df8e84aa6b5b1812cc2cacd6b3f5ccbb18cda2b ]

The atomic variable vm_fault_info_updated is used to synchronize access to
adev->gmc.vm_fault_info between the interrupt handler and
get_vm_fault_info().

The default atomic functions like atomic_set() and atomic_read() do not
provide memory barriers. This allows for CPU instruction reordering,
meaning the memory accesses to vm_fault_info and the vm_fault_info_updated
flag are not guaranteed to occur in the intended order. This creates a
race condition that can lead to inconsistent or stale data being used.

The previous implementation, which used an explicit mb(), was incomplete
and inefficient. It failed to account for all potential CPU reorderings,
such as the access of vm_fault_info being reordered before the atomic_read
of the flag. This approach is also more verbose and less performant than
using the proper atomic functions with acquire/release semantics.

Fix this by switching to atomic_set_release() and atomic_read_acquire().
These functions provide the necessary acquire and release semantics,
which act as memory barriers to ensure the correct order of operations.
It is also more efficient and idiomatic than using explicit full memory
barriers.

Fixes: b97dfa27ef ("drm/amdgpu: save vm fault information for amdkfd")
Cc: stable@vger.kernel.org
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Signed-off-by: Felix Kuehling <felix.kuehling@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
[ kept kgd_dev parameter and adev cast in amdgpu_amdkfd_gpuvm_get_vm_fault_info ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Theodore Ts'o
7bf46ff83a ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
[ Upstream commit 8ecb790ea8c3fc69e77bace57f14cf0d7c177bd8 ]

Unlike other strings in the ext4 superblock, we rely on tune2fs to
make sure s_mount_opts is NUL terminated.  Harden
parse_apply_sb_mount_options() by treating s_mount_opts as a potential
__nonstring.

Cc: stable@vger.kernel.org
Fixes: 8b67f04ab9 ("ext4: Add mount options in superblock")
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Message-ID: <20250916-tune2fs-v2-1-d594dc7486f0@mit.edu>
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
[ applied to ext4_fill_super() instead of parse_apply_sb_mount_options() ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:01 +01:00
Pratyush Yadav
05eb29effe spi: cadence-quadspi: Flush posted register writes before DAC access
[ Upstream commit 1ad55767e77a853c98752ed1e33b68049a243bd7 ]

cqspi_read_setup() and cqspi_write_setup() program the address width as
the last step in the setup. This is likely to be immediately followed by
a DAC region read/write. On TI K3 SoCs the DAC region is on a different
endpoint from the register region. This means that the order of the two
operations is not guaranteed, and they might be reordered at the
interconnect level. It is possible that the DAC read/write goes through
before the address width update goes through. In this situation if the
previous command used a different address width the OSPI command is sent
with the wrong number of address bytes, resulting in an invalid command
and undefined behavior.

Read back the size register to make sure the write gets flushed before
accessing the DAC region.

Fixes: 1406234105 ("mtd: spi-nor: Add driver for Cadence Quad SPI Flash Controller")
CC: stable@vger.kernel.org
Reviewed-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Santhosh Kumar K <s-k6@ti.com>
Message-ID: <20250905185958.3575037-3-s-k6@ti.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
[ backported to drivers/mtd/spi-nor ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Pratyush Yadav
4612070e4c spi: cadence-quadspi: Flush posted register writes before INDAC access
[ Upstream commit 29e0b471ccbd674d20d4bbddea1a51e7105212c5 ]

cqspi_indirect_read_execute() and cqspi_indirect_write_execute() first
set the enable bit on APB region and then start reading/writing to the
AHB region. On TI K3 SoCs these regions lie on different endpoints. This
means that the order of the two operations is not guaranteed, and they
might be reordered at the interconnect level.

It is possible for the AHB write to be executed before the APB write to
enable the indirect controller, causing the transaction to be invalid
and the write erroring out. Read back the APB region write before
accessing the AHB region to make sure the write got flushed and the race
condition is eliminated.

Fixes: 1406234105 ("mtd: spi-nor: Add driver for Cadence Quad SPI Flash Controller")
CC: stable@vger.kernel.org
Reviewed-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Pratyush Yadav <pratyush@kernel.org>
Signed-off-by: Santhosh Kumar K <s-k6@ti.com>
Message-ID: <20250905185958.3575037-2-s-k6@ti.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
[ applied changes to drivers/mtd/spi-nor/cadence-quadspi.c instead of drivers/spi/spi-cadence-quadspi.c ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Zhen Ni
5879837bfe memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe
[ Upstream commit 6744085079e785dae5f7a2239456135407c58b25 ]

The of_platform_populate() call at the end of the function has a
possible failure path, causing a resource leak.

Replace of_iomap() with devm_platform_ioremap_resource() to ensure
automatic cleanup of srom->reg_base.

This issue was detected by smatch static analysis:
drivers/memory/samsung/exynos-srom.c:155 exynos_srom_probe()warn:
'srom->reg_base' from of_iomap() not released on lines: 155.

Fixes: 8ac2266d88 ("memory: samsung: exynos-srom: Add support for bank configuration")
Cc: stable@vger.kernel.org
Signed-off-by: Zhen Ni <zhen.ni@easystack.cn>
Link: https://lore.kernel.org/r/20250806025538.306593-1-zhen.ni@easystack.cn
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Krzysztof Kozlowski
a8e7fc99d4 memory: samsung: exynos-srom: Correct alignment
[ Upstream commit 90de1c75d8acd83e9a699b93153307a1e411ef3a ]

Align indentation with open parenthesis (or fix existing alignment).

Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Stable-dep-of: 6744085079e7 ("memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Mark Rutland
133bb61caf arm64: errata: Apply workarounds for Neoverse-V3AE
commit 0c33aa1804d101c11ba1992504f17a42233f0e11 upstream.

Neoverse-V3AE is also affected by erratum #3312417, as described in its
Software Developer Errata Notice (SDEN) document:

  Neoverse V3AE (MP172) SDEN v9.0, erratum 3312417
  https://developer.arm.com/documentation/SDEN-2615521/9-0/

Enable the workaround for Neoverse-V3AE, and document this.

Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Ryan Roberts <ryan.roberts@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
[ Ryan: Trivial backport ]
Signed-off-by: Ryan Roberts <ryan.roberts@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Mark Rutland
0db16ce5e5 arm64: cputype: Add Neoverse-V3AE definitions
commit 3bbf004c4808e2c3241e5c1ad6cc102f38a03c39 upstream.

Add cputype definitions for Neoverse-V3AE. These will be used for errata
detection in subsequent patches.

These values can be found in the Neoverse-V3AE TRM:

  https://developer.arm.com/documentation/SDEN-2615521/9-0/

... in section A.6.1 ("MIDR_EL1, Main ID Register").

Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Ryan Roberts <ryan.roberts@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
[ Ryan: Trivial backport ]
Signed-off-by: Ryan Roberts <ryan.roberts@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Deepanshu Kartikey
4ffea48c69 comedi: fix divide-by-zero in comedi_buf_munge()
commit 87b318ba81dda2ee7b603f4f6c55e78ec3e95974 upstream.

The comedi_buf_munge() function performs a modulo operation
`async->munge_chan %= async->cmd.chanlist_len` without first
checking if chanlist_len is zero. If a user program submits a command with
chanlist_len set to zero, this causes a divide-by-zero error when the device
processes data in the interrupt handler path.

Add a check for zero chanlist_len at the beginning of the
function, similar to the existing checks for !map and
CMDF_RAWDATA flag. When chanlist_len is zero, update
munge_count and return early, indicating the data was
handled without munging.

This prevents potential kernel panics from malformed user commands.

Reported-by: syzbot+f6c3c066162d2c43a66c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f6c3c066162d2c43a66c
Cc: stable@vger.kernel.org
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Reviewed-by: Ian Abbott <abbotti@mev.co.uk>
Link: https://patch.msgid.link/20250924102639.1256191-1-kartikey406@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Alice Ryhl
9d053f9856 binder: remove "invalid inc weak" check
commit d90eeb8ecd227c204ab6c34a17b372bd950b7aa2 upstream.

There are no scenarios where a weak increment is invalid on binder_node.
The only possible case where it could be invalid is if the kernel
delivers BR_DECREFS to the process that owns the node, and then
increments the weak refcount again, effectively "reviving" a dead node.

However, that is not possible: when the BR_DECREFS command is delivered,
the kernel removes and frees the binder_node. The fact that you were
able to call binder_inc_node_nilocked() implies that the node is not yet
destroyed, which implies that BR_DECREFS has not been delivered to
userspace, so incrementing the weak refcount is valid.

Note that it's currently possible to trigger this condition if the owner
calls BINDER_THREAD_EXIT while node->has_weak_ref is true. This causes
BC_INCREFS on binder_ref instances to fail when they should not.

Cc: stable@vger.kernel.org
Fixes: 457b9a6f09 ("Staging: android: add binder driver")
Reported-by: Yu-Ting Tseng <yutingtseng@google.com>
Signed-off-by: Alice Ryhl <aliceryhl@google.com>
Link: https://patch.msgid.link/20251015-binder-weak-inc-v1-1-7914b092c371@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Mathias Nyman
428c804752 xhci: dbc: enable back DbC in resume if it was enabled before suspend
commit 2bbd38fcd29670e46c0fdb9cd0e90507a8a1bf6a upstream.

DbC is currently only enabled back if it's in configured state during
suspend.

If system is suspended after DbC is enabled, but before the device is
properly enumerated by the host, then DbC would not be enabled back in
resume.

Always enable DbC back in resume if it's suspended in enabled,
connected, or configured state

Cc: stable <stable@kernel.org>
Fixes: dfba2174dc ("usb: xhci: Add DbC support in xHCI driver")
Tested-by: Łukasz Bartosik <ukaszb@chromium.org>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Tim Guttzeit
02a089cf40 usb/core/quirks: Add Huawei ME906S to wakeup quirk
commit dfc2cf4dcaa03601cd4ca0f7def88b2630fca6ab upstream.

The list of Huawei LTE modules needing the quirk fixing spurious wakeups
was missing the IDs of the Huawei ME906S module, therefore suspend did not
work.

Cc: stable <stable@kernel.org>
Signed-off-by: Tim Guttzeit <t.guttzeit@tuxedocomputers.com>
Signed-off-by: Werner Sembach <wse@tuxedocomputers.com>
Link: https://patch.msgid.link/20251020134304.35079-1-wse@tuxedocomputers.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
LI Qingwu
2b24cd3ab1 USB: serial: option: add Telit FN920C04 ECM compositions
commit 622865c73ae30f254abdf182f4b66cccbe3e0f10 upstream.

Add support for the Telit Cinterion FN920C04 module when operating in
ECM (Ethernet Control Model) mode. The following USB product IDs are
used by the module when AT#USBCFG is set to 3 or 7.

0x10A3: ECM + tty (NMEA) + tty (DUN) [+ tty (DIAG)]
T:  Bus=01 Lev=02 Prnt=02 Port=00 Cnt=01 Dev#=  3 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1bc7 ProdID=10a3 Rev= 5.15
S:  Manufacturer=Telit Cinterion
S:  Product=FN920
S:  SerialNumber=76e7cb38
C:* #Ifs= 5 Cfg#= 1 Atr=e0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 1 Cls=02(comm.) Sub=06 Prot=00 Driver=cdc_ether
E:  Ad=82(I) Atr=03(Int.) MxPS=  16 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 0 Cls=0a(data ) Sub=00 Prot=00 Driver=cdc_ether
I:* If#= 1 Alt= 1 #EPs= 2 Cls=0a(data ) Sub=00 Prot=00 Driver=cdc_ether
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=60 Driver=option
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=86(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 4 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

0x10A8: ECM + tty (DUN) + tty (AUX) [+ tty (DIAG)]
T:  Bus=03 Lev=02 Prnt=02 Port=00 Cnt=01 Dev#=  3 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1bc7 ProdID=10a8 Rev= 5.15
S:  Manufacturer=Telit Cinterion
S:  Product=FN920
S:  SerialNumber=76e7cb38
C:* #Ifs= 5 Cfg#= 1 Atr=e0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 1 Cls=02(comm.) Sub=06 Prot=00 Driver=cdc_ether
E:  Ad=82(I) Atr=03(Int.) MxPS=  16 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 0 Cls=0a(data ) Sub=00 Prot=00 Driver=cdc_ether
I:* If#= 1 Alt= 1 #EPs= 2 Cls=0a(data ) Sub=00 Prot=00 Driver=cdc_ether
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=86(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 4 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

Adding these IDs allows the option driver to automatically create the
corresponding /dev/ttyUSB* ports under ECM mode.

Tested with FN920C04 under ECM configuration (USBCFG=3 and 7).

Signed-off-by: LI Qingwu <Qing-wu.Li@leica-geosystems.com.cn>
Cc: stable@vger.kernel.org
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Reinhard Speyerer
e9639d4237 USB: serial: option: add Quectel RG255C
commit 89205c60c0fc96b73567a2e9fe27ee3f59d01193 upstream.

Add support for Quectel RG255C devices to complement commit 5c964c8a97c1
("net: usb: qmi_wwan: add Quectel RG255C").
The composition is DM / NMEA / AT / QMI.

T:  Bus=01 Lev=02 Prnt=99 Port=01 Cnt=02 Dev#=110 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=2c7c ProdID=0316 Rev= 5.15
S:  Manufacturer=Quectel
S:  Product=RG255C-GL
S:  SerialNumber=xxxxxxxx
C:* #Ifs= 4 Cfg#= 1 Atr=a0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=82(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=86(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms

Signed-off-by: Reinhard Speyerer <rspmn@arcor.de>
Cc: stable@vger.kernel.org
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Renjun Wang
84c73088ec USB: serial: option: add UNISOC UIS7720
commit 71c07570b918f000de5d0f7f1bf17a2887e303b5 upstream.

Add support for UNISOC (Spreadtrum) UIS7720 (A7720) module.

T:  Bus=05 Lev=01 Prnt=01 Port=00 Cnt=01 Dev#=  5 Spd=480 MxCh= 0
D:  Ver= 2.10 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1782 ProdID=4064 Rev=04.04
S:  Manufacturer=Unisoc-phone
S:  Product=Unisoc-phone
S:  SerialNumber=0123456789ABCDEF
C:  #Ifs= 9 Cfg#= 1 Atr=c0 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 1 Cls=e0(wlcon) Sub=01 Prot=03 Driver=rndis_host
E:  Ad=82(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 2 Cls=0a(data ) Sub=00 Prot=00 Driver=rndis_host
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 3 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=84(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 4 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 5 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=05(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=86(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 6 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=06(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 7 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=07(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=88(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 8 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=42 Prot=01 Driver=(none)
E:  Ad=08(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=89(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

0&1: RNDIS, 2: LOG, 3: DIAG, 4&5: AT Ports, 6&7: AT2 Ports, 8: ADB

Signed-off-by: Renjun Wang <renjunw0@foxmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 14:00:00 +01:00
Lad Prabhakar
14b68ab4f6 net: ravb: Ensure memory write completes before ringing TX doorbell
commit 706136c5723626fcde8dd8f598a4dcd251e24927 upstream.

Add a final dma_wmb() barrier before triggering the transmit request
(TCCR_TSRQ) to ensure all descriptor and buffer writes are visible to
the DMA engine.

According to the hardware manual, a read-back operation is required
before writing to the doorbell register to guarantee completion of
previous writes. Instead of performing a dummy read, a dma_wmb() is
used to both enforce the same ordering semantics on the CPU side and
also to ensure completion of writes.

Fixes: c156633f13 ("Renesas Ethernet AVB driver proper")
Cc: stable@vger.kernel.org
Co-developed-by: Fabrizio Castro <fabrizio.castro.jz@renesas.com>
Signed-off-by: Fabrizio Castro <fabrizio.castro.jz@renesas.com>
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Niklas Söderlund <niklas.soderlund+renesas@ragnatech.se>
Link: https://patch.msgid.link/20251017151830.171062-5-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Michal Pecio
a8749742e6 net: usb: rtl8150: Fix frame padding
commit 75cea9860aa6b2350d90a8d78fed114d27c7eca2 upstream.

TX frames aren't padded and unknown memory is sent into the ether.

Theoretically, it isn't even guaranteed that the extra memory exists
and can be sent out, which could cause further problems. In practice,
I found that plenty of tailroom exists in the skb itself (in my test
with ping at least) and skb_padto() easily succeeds, so use it here.

In the event of -ENOMEM drop the frame like other drivers do.

The use of one more padding byte instead of a USB zero-length packet
is retained to avoid regression. I have a dodgy Etron xHCI controller
which doesn't seem to support sending ZLPs at all.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Michal Pecio <michal.pecio@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20251014203528.3f9783c4.michal.pecio@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Deepanshu Kartikey
93166bc53c ocfs2: clear extent cache after moving/defragmenting extents
commit 78a63493f8e352296dbc7cb7b3f4973105e8679e upstream.

The extent map cache can become stale when extents are moved or
defragmented, causing subsequent operations to see outdated extent flags.
This triggers a BUG_ON in ocfs2_refcount_cal_cow_clusters().

The problem occurs when:
1. copy_file_range() creates a reflinked extent with OCFS2_EXT_REFCOUNTED
2. ioctl(FITRIM) triggers ocfs2_move_extents()
3. __ocfs2_move_extents_range() reads and caches the extent (flags=0x2)
4. ocfs2_move_extent()/ocfs2_defrag_extent() calls __ocfs2_move_extent()
   which clears OCFS2_EXT_REFCOUNTED flag on disk (flags=0x0)
5. The extent map cache is not invalidated after the move
6. Later write() operations read stale cached flags (0x2) but disk has
   updated flags (0x0), causing a mismatch
7. BUG_ON(!(rec->e_flags & OCFS2_EXT_REFCOUNTED)) triggers

Fix by clearing the extent map cache after each extent move/defrag
operation in __ocfs2_move_extents_range().  This ensures subsequent
operations read fresh extent data from disk.

Link: https://lore.kernel.org/all/20251009142917.517229-1-kartikey406@gmail.com/T/
Link: https://lkml.kernel.org/r/20251009154903.522339-1-kartikey406@gmail.com
Fixes: 53069d4e76 ("Ocfs2/move_extents: move/defrag extents within a certain range.")
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Reported-by: syzbot+6fdd8fa3380730a4b22c@syzkaller.appspotmail.com
Tested-by: syzbot+6fdd8fa3380730a4b22c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?id=2959889e1f6e216585ce522f7e8bc002b46ad9e7
Reviewed-by: Mark Fasheh <mark@fasheh.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Maciej W. Rozycki
d7fb245842 MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering
commit bf5570590a981d0659d0808d2d4bcda21b27a2a5 upstream.

MIPS Malta platform code registers the PCI southbridge legacy port I/O
PS/2 keyboard range as a standard resource marked as busy.  It prevents
the i8042 driver from registering as it fails to claim the resource in
a call to i8042_platform_init().  Consequently PS/2 keyboard and mouse
devices cannot be used with this platform.

Fix the issue by removing the busy marker from the standard reservation,
making the driver register successfully:

  serio: i8042 KBD port at 0x60,0x64 irq 1
  serio: i8042 AUX port at 0x60,0x64 irq 12

and the resource show up as expected among the legacy devices:

  00000000-00ffffff : MSC PCI I/O
    00000000-0000001f : dma1
    00000020-00000021 : pic1
    00000040-0000005f : timer
    00000060-0000006f : keyboard
      00000060-0000006f : i8042
    00000070-00000077 : rtc0
    00000080-0000008f : dma page reg
    000000a0-000000a1 : pic2
    000000c0-000000df : dma2
    [...]

If the i8042 driver has not been configured, then the standard resource
will remain there preventing any conflicting dynamic assignment of this
PCI port I/O address range.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Maciej W. Rozycki <macro@orcam.me.uk>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Acked-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/alpine.DEB.2.21.2510211919240.8377@angie.orcam.me.uk
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Rafael J. Wysocki
5568efa5bd Revert "cpuidle: menu: Avoid discarding useful information"
commit 10fad4012234a7dea621ae17c0c9486824f645a0 upstream.

It is reported that commit 85975daeaa4d ("cpuidle: menu: Avoid discarding
useful information") led to a performance regression on Intel Jasper Lake
systems because it reduced the time spent by CPUs in idle state C7 which
is correlated to the maximum frequency the CPUs can get to because of an
average running power limit [1].

Before that commit, get_typical_interval() would have returned UINT_MAX
whenever it had been unable to make a high-confidence prediction which
had led to selecting the deepest available idle state too often and
both power and performance had been inadequate as a result of that on
some systems.  However, this had not been a problem on systems with
relatively aggressive average running power limits, like the Jasper Lake
systems in question, because on those systems it was compensated by the
ability to run CPUs faster.

It was addressed by causing get_typical_interval() to return a number
based on the recent idle duration information available to it even if it
could not make a high-confidence prediction, but that clearly did not
take the possible correlation between idle power and available CPU
capacity into account.

For this reason, revert most of the changes made by commit 85975daeaa4d,
except for one cosmetic cleanup, and add a comment explaining the
rationale for returning UINT_MAX from get_typical_interval() when it
is unable to make a high-confidence prediction.

Fixes: 85975daeaa4d ("cpuidle: menu: Avoid discarding useful information")
Closes: https://lore.kernel.org/linux-pm/36iykr223vmcfsoysexug6s274nq2oimcu55ybn6ww4il3g3cv@cohflgdbpnq7/ [1]
Reported-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Cc: All applicable <stable@vger.kernel.org>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3663603.iIbC2pHGDl@rafael.j.wysocki
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Tonghao Zhang
839028e70a net: bonding: fix possible peer notify event loss or dup issue
commit 10843e1492e474c02b91314963161731fa92af91 upstream.

If the send_peer_notif counter and the peer event notify are not synchronized.
It may cause problems such as the loss or dup of peer notify event.

Before this patch:
- If should_notify_peers is true and the lock for send_peer_notif-- fails, peer
  event may be sent again in next mii_monitor loop, because should_notify_peers
  is still true.
- If should_notify_peers is true and the lock for send_peer_notif-- succeeded,
  but the lock for peer event fails, the peer event will be lost.

This patch locks the RTNL for send_peer_notif, events, and commit simultaneously.

Fixes: 07a4ddec3c ("bonding: add an option to specify a delay between peer notifications")
Cc: Jay Vosburgh <jv@jvosburgh.net>
Cc: Andrew Lunn <andrew+netdev@lunn.ch>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Hangbin Liu <liuhangbin@gmail.com>
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Cc: Vincent Bernat <vincent@bernat.ch>
Cc: <stable@vger.kernel.org>
Signed-off-by: Tonghao Zhang <tonghao@bamaicloud.com>
Acked-by: Jay Vosburgh <jv@jvosburgh.net>
Link: https://patch.msgid.link/20251021050933.46412-1-tonghao@bamaicloud.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:59 +01:00
Alexey Simakov
61cda2777b sctp: avoid NULL dereference when chunk data buffer is missing
[ Upstream commit 441f0647f7673e0e64d4910ef61a5fb8f16bfb82 ]

chunk->skb pointer is dereferenced in the if-block where it's supposed
to be NULL only.

chunk->skb can only be NULL if chunk->head_skb is not. Check for frag_list
instead and do it just before replacing chunk->skb. We're sure that
otherwise chunk->skb is non-NULL because of outer if() condition.

Fixes: 90017accff ("sctp: Add GSO support")
Signed-off-by: Alexey Simakov <bigalex934@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Link: https://patch.msgid.link/20251021130034.6333-1-bigalex934@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-29 13:59:59 +01:00