Commit graph

979,361 commits

Author SHA1 Message Date
Ard Biesheuvel
52aff5473d
UPSTREAM: crypto: arm/chacha - remove dependency on generic ChaCha driver
Instead of falling back to the generic ChaCha skcipher driver for
non-SIMD cases, use a fast scalar implementation for ARM authored
by Eric Biggers. This removes the module dependency on chacha-generic
altogether, which also simplifies things when we expose the ChaCha
library interface from this module.

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit b36d8c09e710c71f6a9690b6586fea2d1c9e1e27)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ia90b283b3fa6e4102aeb20a29f5729a4a1583c18
2025-09-24 12:16:30 +02:00
Ard Biesheuvel
591b5cba81
UPSTREAM: crypto: arm/chacha - import Eric Biggers's scalar accelerated ChaCha code
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 29621d099f9c642b22a69dc8e7e20c108473a392)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I1444e8306896318f6f84a7291ff9c5784da57e3a
2025-09-24 12:16:30 +02:00
Ard Biesheuvel
56cc9b4c68
UPSTREAM: crypto: arm64/chacha - expose arm64 ChaCha routine as library function
Expose the accelerated NEON ChaCha routine directly as a symbol
export so that users of the ChaCha library API can use it directly.

Given that calls into the library API will always go through the
routines in this module if it is enabled, switch to static keys
to select the optimal implementation available (which may be none
at all, in which case we defer to the generic implementation for
all invocations).

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit b3aad5bad26a01a4bd8c49a5c5f52aec665f3b7c)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: Ifcc07348894e098d926c115de1f372cd74f6b397
2025-09-24 12:16:29 +02:00
Ard Biesheuvel
389b966414
UPSTREAM: crypto: arm64/chacha - depend on generic chacha library instead of crypto driver
Depend on the generic ChaCha library routines instead of pulling in the
generic ChaCha skcipher driver, which is more than we need, and makes
managing the dependencies between the generic library, generic driver,
accelerated library and driver more complicated.

While at it, drop the logic to prefer the scalar code on short inputs.
Turning the NEON on and off is cheap these days, and one major use case
for ChaCha20 is ChaCha20-Poly1305, which is guaranteed to hit the scalar
path upon every invocation  (when doing the Poly1305 nonce generation)

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit c77da4867cbb7841177275dbb250f5c09679fae4)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I1d964629bcd87c84c086c17b7a081bb01013a7cf
2025-09-24 12:16:29 +02:00
Ard Biesheuvel
ddb77ae428
UPSTREAM: crypto: x86/chacha - expose SIMD ChaCha routine as library function
Wire the existing x86 SIMD ChaCha code into the new ChaCha library
interface, so that users of the library interface will get the
accelerated version when available.

Given that calls into the library API will always go through the
routines in this module if it is enabled, switch to static keys
to select the optimal implementation available (which may be none
at all, in which case we defer to the generic implementation for
all invocations).

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 84e03fa39fbe95a5567d43bff458c6d3b3a23ad1)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I6053c5023c6fd9f914b9ebdbf04683c20c8675d0
2025-09-24 12:16:29 +02:00
Ard Biesheuvel
20630d0203
UPSTREAM: crypto: x86/chacha - depend on generic chacha library instead of crypto driver
In preparation of extending the x86 ChaCha driver to also expose the ChaCha
library interface, drop the dependency on the chacha_generic crypto driver
as a non-SIMD fallback, and depend on the generic ChaCha library directly.
This way, we only pull in the code we actually need, without registering
a set of ChaCha skciphers that we will never use.

Since turning the FPU on and off is cheap these days, simplify the SIMD
routine by dropping the per-page yield, which makes for a cleaner switch
to the library API as well. This also allows use to invoke the skcipher
walk routines in non-atomic mode.

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 28e8d89b1ce8d2e7badfb5f69971dd635acb8863)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I83c0e6f69000d43ecf2da9f3b8bc543bdaa8d954
2025-09-24 12:16:29 +02:00
Ard Biesheuvel
7dfbe55359
UPSTREAM: crypto: chacha - move existing library code into lib/crypto
Currently, our generic ChaCha implementation consists of a permute
function in lib/chacha.c that operates on the 64-byte ChaCha state
directly [and which is always included into the core kernel since it
is used by the /dev/random driver], and the crypto API plumbing to
expose it as a skcipher.

In order to support in-kernel users that need the ChaCha streamcipher
but have no need [or tolerance] for going through the abstractions of
the crypto API, let's expose the streamcipher bits via a library API
as well, in a way that permits the implementation to be superseded by
an architecture specific one if provided.

So move the streamcipher code into a separate module in lib/crypto,
and expose the init() and crypt() routines to users of the library.

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit 5fb8ef25803ef33e2eb60b626435828b937bed75)
Bug: 152722841
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I15a2ab1be696f3c37ae6483348c840fdb1d05117
2025-09-24 12:16:29 +02:00
Alexander Martinz
fa5e8001f7
Revert "BACKPORT: crypto: arch - conditionalize crypto api in arch glue for lib code"
This reverts commit 47c8de47e1.

This will be reapplied later.

Change-Id: I2181874ef8de0e64007c2daf8a6f480cdeca97ac
Signed-off-by: Alexander Martinz <amartinz@shiftphones.com>
2025-09-24 12:16:26 +02:00
Michael Bestas
dae3d3ea9f
Merge tag 'ASB-2025-09-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-09-01
CVE-2025-21755
CVE-2025-38352
CVE-2025-021701

* tag 'ASB-2025-09-05_11-5.4' of https://android.googlesource.com/kernel/common:
  UPSTREAM: perf/core: Fix potential NULL deref
  UPSTREAM: net/packet: fix a race in packet_set_ring() and packet_notifier()
  ANDROID: 16K: Allocate pad vma on the stack
  ANDROID: 16K: Don't copy data vma for maps/smaps output
  ANDROID: GKI: update Trimble symbol list
  UPSTREAM: net/sched: Always pass notifications when child class becomes empty
  Revert "drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling"
  Linux 5.4.296
  net: ipv6: Discard next-hop MTU less than minimum link MTU
  x86/mm: Disable hugetlb page table sharing on 32-bit
  Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID
  HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
  HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY
  vt: add missing notification when switching back to text mode
  net: usb: qmi_wwan: add SIMCom 8230C composition
  atm: idt77252: Add missing `dma_map_error()`
  bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
  bnxt_en: Fix DCB ETS validation
  can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level
  net: phy: microchip: limit 100M workaround to link-down events on LAN88xx
  net: appletalk: Fix device refcount leak in atrtr_create()
  md/raid1: Fix stack memory use after return in raid1_reshape
  wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
  dma-buf: fix timeout handling in dma_resv_wait_timeout v2
  Input: xpad - support Acer NGR 200 Controller
  Input: xpad - add VID for Turtle Beach controllers
  Input: xpad - add support for Amazon Game Controller
  NFSv4/flexfiles: Fix handling of NFS level errors in I/O
  flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes
  RDMA/mlx5: Fix vport loopback for MPV device
  netlink: Fix rmem check in netlink_broadcast_deliver().
  netlink: make sure we allow at least one dump skb
  pwm: mediatek: Ensure to disable clocks in error path
  Revert "ACPI: battery: negate current when discharging"
  usb: gadget: u_serial: Fix race condition in TTY wakeup
  drm/sched: Increment job count before swapping tail spsc queue
  pinctrl: qcom: msm: mark certain pins as invalid for interrupts
  x86/mce: Make sure CMCI banks are cleared during shutdown on Intel
  x86/mce: Don't remove sysfs if thresholding sysfs init fails
  x86/mce/amd: Fix threshold limit reset
  rxrpc: Fix oops due to non-existence of prealloc backlog struct
  net/sched: Abort __tc_modify_qdisc if parent class does not exist
  atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
  atm: clip: Fix infinite recursive call of clip_push().
  atm: clip: Fix memory leak of struct clip_vcc.
  atm: clip: Fix potential null-ptr-deref in to_atmarpd().
  tipc: Fix use-after-free in tipc_conn_close().
  netlink: Fix wraparounds of sk->sk_rmem_alloc.
  fix proc_sys_compare() handling of in-lookup dentries
  proc: Clear the pieces of proc_inode that proc_evict_inode cares about
  drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
  staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher()
  media: uvcvideo: Rollback non processed entities on error
  media: uvcvideo: Send control events for partial succeeds
  media: uvcvideo: Return the number of processed controls
  ACPI: PAD: fix crash in exit_round_robin()
  usb: typec: displayport: Fix potential deadlock
  Logitech C-270 even more broken
  rose: fix dangling neighbour pointers in rose_rt_device_down()
  net: rose: Fix fall-through warnings for Clang
  drm/i915/gt: Fix timeline left held on VMA alloc error
  drm/i915/selftests: Change mock_request() to return error pointers
  spi: spi-fsl-dspi: Clear completion counter before initiating transfer
  spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path
  spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write
  dpaa2-eth: fix xdp_rxq_info leak
  ethernet: atl1: Add missing DMA mapping error checks and count errors
  btrfs: use btrfs_record_snapshot_destroy() during rmdir
  btrfs: propagate last_unlink_trans earlier when doing a rmdir
  RDMA/mlx5: Fix CC counters query for MPV
  RDMA/core: Create and destroy counters in the ib_core
  scsi: ufs: core: Fix spelling of a sysfs attribute name
  drm/v3d: Disable interrupts before resetting the GPU
  mtk-sd: reset host->mrq on prepare_data() error
  mtk-sd: Prevent memory corruption from DMA map failure
  mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data()
  regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
  regulator: gpio: Add input_supply support in gpio_regulator_config
  ACPICA: Refuse to evaluate a method if arguments are missing
  wifi: ath6kl: remove WARN on bad firmware input
  wifi: mac80211: drop invalid source address OCB frames
  powerpc: Fix struct termio related ioctl macros
  ata: pata_cs5536: fix build on 32-bit UML
  ALSA: sb: Force to disable DMAs once when DMA mode is changed
  net/sched: Always pass notifications when child class becomes empty
  nui: Fix dma_mapping_error() check
  enic: fix incorrect MTU comparison in enic_change_mtu()
  amd-xgbe: align CL37 AN sequence as per databook
  lib: test_objagg: Set error message in check_expect_hints_stats()
  drm/exynos: fimd: Guard display clock control with runtime PM calls
  btrfs: fix missing error handling when searching for inode refs during log replay
  scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu()
  nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails.
  RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert
  platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
  mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
  usb: typec: altmodes/displayport: do not index invalid pin_assignments
  Revert "mmc: sdhci: Disable SD card clock before changing parameters"
  mmc: sdhci: Add a helper function for dump register in dynamic debug mode
  vsock/vmci: Clear the vmci transport packet properly when initializing it
  btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
  arm64: Restrict pagetable teardown to avoid false warning
  s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
  drm/bridge: cdns-dsi: Check return value when getting default PHY config
  drm/bridge: cdns-dsi: Fix connecting to next bridge
  drm/bridge: cdns-dsi: Fix the clock variable for mode_valid()
  drm/tegra: Assign plane type before registration
  HID: wacom: fix kobject reference count leak
  HID: wacom: fix memory leak on sysfs attribute creation failure
  HID: wacom: fix memory leak on kobject creation failure
  dm-raid: fix variable in journal device check
  Bluetooth: L2CAP: Fix L2CAP MTU negotiation
  atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
  net: enetc: Correct endianness handling in _enetc_rd_reg64
  um: ubd: Add missing error check in start_io_thread()
  vsock/uapi: fix linux/vm_sockets.h userspace compilation errors
  wifi: mac80211: fix beacon interval calculation overflow
  attach_recursive_mnt(): do not lock the covering tree when sliding something under it
  ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
  i2c: robotfuzz-osif: disable zero-length read messages
  i2c: tiny-usb: disable zero-length read messages
  RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
  RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private
  media: vivid: Change the siize of the composing
  media: omap3isp: use sgtable-based scatterlist wrappers
  media: cxusb: no longer judge rbuf when the write fails
  media: cxusb: use dev_dbg() rather than hand-rolled debug
  jfs: validate AG parameters in dbMount() to prevent crashes
  fs/jfs: consolidate sanity checking in dbMount
  ASoC: meson: meson-card-utils: use of_property_present() for DT parsing
  of: Add of_property_present() helper
  of: property: define of_property_read_u{8,16,32,64}_array() unconditionally
  kbuild: hdrcheck: fix cross build with clang
  kbuild: add --target to correctly cross-compile UAPI headers with Clang
  bpfilter: match bit size of bpfilter_umh to that of the kernel
  kbuild: use -MMD instead of -MD to exclude system headers from dependency
  VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
  VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF
  ovl: Check for NULL d_inode() in ovl_dentry_upper()
  ceph: fix possible integer overflow in ceph_zero_objects()
  ALSA: hda: Ignore unsol events for cards being shut down
  usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode
  usb: cdc-wdm: avoid setting WDM_READ for ZLP-s
  usb: Add checks for snprintf() calls in usb_alloc_dev()
  tty: serial: uartlite: register uart driver in init
  usb: potential integer overflow in usbg_make_tpg()
  iio: pressure: zpa2326: Use aligned_s64 for the timestamp
  md/md-bitmap: fix dm-raid max_write_behind setting
  dmaengine: xilinx_dma: Set dma_device directions
  mfd: max14577: Fix wakeup source leaks on device unbind
  mailbox: Not protect module_put with spin_lock_irqsave
  cifs: Fix cifs_query_path_info() for Windows NT servers

 Conflicts:
	drivers/hid/hid-ids.h
	drivers/pinctrl/qcom/pinctrl-msm.c

Change-Id: Ifd5acd2c013f9985e02b866e3f9383383077e3f0
2025-09-12 18:48:05 +03:00
Peter Zijlstra
dd8b17eff1 UPSTREAM: perf/core: Fix potential NULL deref
commit a71ef31485bb51b846e8db8b3a35e432cc15afb5 upstream.

Smatch is awesome.

Fixes: 32671e3799ca ("perf: Disallow mis-matched inherited group reads")
Reported-by: Dan Carpenter <dan.carpenter@linaro.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 511f3e9bbb)
Change-Id: I6d2005d6c186cfc7ff41ed2615e37ee9f01da6a5
Bug: 442358987
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-09-02 06:54:39 +00:00
Quang Le
b7a9bb0844 UPSTREAM: net/packet: fix a race in packet_set_ring() and packet_notifier()
commit 01d3c8417b9c1b884a8a981a3b886da556512f36 upstream.

When packet_set_ring() releases po->bind_lock, another thread can
run packet_notifier() and process an NETDEV_UP event.

This race and the fix are both similar to that of commit 15fe076ede
("net/packet: fix a race in packet_bind() and packet_notifier()").

There too the packet_notifier NETDEV_UP event managed to run while a
po->bind_lock critical section had to be temporarily released. And
the fix was similarly to temporarily set po->num to zero to keep
the socket unhooked until the lock is retaken.

The po->bind_lock in packet_set_ring and packet_notifier precede the
introduction of git history.

Bug: 438674212
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Quang Le <quanglex97@gmail.com>
Signed-off-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20250801175423.2970334-1-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit f2e8fcfd2b1bc754920108b7f2cd75082c5a18df)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: Ibcc94a6f951a94a6b1a82ebb199b355a1c39a5e1
2025-09-01 18:08:07 +01:00
Michael Bestas
2b9e22c70c
Merge tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
https://source.android.com/docs/security/bulletin/2025-08-01

* tag 'ASB-2025-08-05_11-5.4' of https://android.googlesource.com/kernel/common:
  ANDROID: bpf: do not fail to load if log is full
  ANDROID: fix kernelci compressed kernel linking
  ANDROID: GKI: Update symbol list for Zebra
  UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  Linux 5.4.295
  scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
  arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
  perf: Fix sample vs do_exit()
  s390/pci: Fix __pcilg_mio_inuser() inline assembly
  rtc: test: Fix invalid format specifier.
  jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
  mm/huge_memory: fix dereferencing invalid pmd migration entry
  rtc: Make rtc_time64_to_tm() support dates before 1970
  rtc: Improve performance of rtc_time64_to_tm(). Add tests.
  xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
  posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
  ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
  ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
  net: atm: fix /proc/net/atm/lec handling
  net: atm: add lec_mutex
  calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
  tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
  tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
  atm: atmtcp: Free invalid length skb in atmtcp_c_send().
  mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
  wifi: carl9170: do not ping device which has failed to load firmware
  aoe: clean device rq_list in aoedev_downdev()
  hwmon: (occ) fix unaligned accesses
  drm/nouveau/bl: increase buffer size to avoid truncate warning
  erofs: remove unused trace event erofs_destroy_inode
  ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
  ALSA: hda/intel: Add Thinkpad E15 to PM deny list
  Input: sparcspkr - avoid unannotated fall-through
  HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
  atm: Revert atm_account_tx() if copy_from_iter_full() fails.
  selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
  scsi: s390: zfcp: Ensure synchronous unit_add
  scsi: storvsc: Increase the timeouts to storvsc_timeout
  jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
  jffs2: check that raw node were preallocated before writing summary
  drivers/rapidio/rio_cm.c: prevent possible heap overwrite
  Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
  powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
  platform/x86: dell_rbu: Stop overwriting data buffer
  platform: Add Surface platform directory
  Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
  tee: Prevent size calculation wraparound on 32-bit kernels
  ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
  bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
  watchdog: da9052_wdt: respect TWDMIN
  i40e: fix MMIO write access to an invalid page in i40e_clear_hw
  sock: Correct error checking condition for (assign|release)_proto_idx()
  scsi: lpfc: Use memcpy() for BIOS version
  vxlan: Do not treat dst cache initialization errors as fatal
  clk: rockchip: rk3036: mark ddrphy as critical
  wifi: mac80211: do not offer a mesh path if forwarding is disabled
  net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
  pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
  pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
  pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
  pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
  ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
  tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
  tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
  net: dlink: add synchronization for stats update
  sctp: Do not wake readers in __sctp_write_space()
  emulex/benet: correct command version selection in be_cmd_get_stats()
  i2c: designware: Invoke runtime suspend on quick slave re-registration
  net: macb: Check return value of dma_set_mask_and_coherent()
  cpufreq: Force sync policy boost with global boost on sysfs update
  nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
  media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
  media: tc358743: ignore video while HPD is low
  drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
  jfs: Fix null-ptr-deref in jfs_ioc_trim
  drm/amdgpu/gfx9: fix CSIB handling
  drm/amdgpu/gfx8: fix CSIB handling
  jfs: fix array-index-out-of-bounds read in add_missing_indices
  drm/amdgpu/gfx7: fix CSIB handling
  drm/amdgpu/gfx10: fix CSIB handling
  drm/msm/a6xx: Increase HFI response timeout
  drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
  media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
  drm/msm/hdmi: add runtime PM calls to DDC transfer function
  drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
  sunrpc: update nextcheck time when adding new cache entries
  drm/amdgpu/gfx6: fix CSIB handling
  ACPI: battery: negate current when discharging
  PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
  power: supply: bq27xxx: Retrieve again when busy
  ACPICA: fix acpi parse and parseext cache leaks
  ACPICA: Avoid sequence overread in call to strncmp()
  ACPICA: fix acpi operand cache leak in dswstate.c
  iio: adc: ad7606_spi: fix reg write value mask
  PCI: Fix lock symmetry in pci_slot_unlock()
  PCI: Add ACS quirk for Loongson PCIe
  uio_hv_generic: Use correct size for interrupt and monitor pages
  regulator: max14577: Add error check for max14577_read_reg()
  mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
  staging: iio: ad5933: Correct settling cycles encoding per datasheet
  net: ch9200: fix uninitialised access during mii_nway_restart
  ftrace: Fix UAF when lookup kallsym after ftrace disabled
  dm-mirror: fix a tiny race condition
  mtd: nand: sunxi: Add randomizer configuration before randomizer enable
  mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
  mm: fix ratelimit_pages update error in dirty_ratio_handler()
  ipc: fix to protect IPCS lookups using RCU
  parisc: fix building with gcc-15
  vgacon: Add check for vc_origin address range in vgacon_scroll()
  fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
  EDAC/altera: Use correct write width with the INTTEST register
  NFC: nci: uart: Set tty->disc_data only in success path
  f2fs: prevent kernel warning due to negative i_nlink from corrupted image
  Input: ims-pcu - check record size in ims_pcu_flash_firmware()
  ext4: fix calculation of credits for extent tree modification
  ext4: inline: fix len overflow in ext4_prepare_inline_data
  bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
  ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
  ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
  media: v4l2-dev: fix error handling in __video_register_device()
  media: gspca: Add error handling for stv06xx_read_sensor()
  wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
  nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
  wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
  gfs2: move msleep to sleepable context
  configfs: Do not override creating attribute file failure in populate_attrs()
  net: usb: aqc111: debug info before sanitation
  calipso: unlock rcu before returning -EAFNOSUPPORT
  xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
  usb: Flush altsetting 0 endpoints before reinitializating them after reset.
  fs/filesystems: Fix potential unsigned integer underflow in fs_name()
  net/mdiobus: Fix potential out-of-bounds read/write access
  drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
  drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
  MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
  x86/boot/compressed: prefer cc-option for CFLAGS additions
  net: mdio: C22 is now optional, EOPNOTSUPP if not provided
  net_sched: tbf: fix a race in tbf_change()
  net_sched: red: fix a race in __red_change()
  net_sched: prio: fix a race in prio_tune()
  net/mlx5: Fix return value when searching for existing flow group
  net/mlx5: Wait for inactive autogroups
  i40e: retry VFLR handling if there is ongoing VF reset
  i40e: return false from i40e_reset_vf if reset is in progress
  net_sched: sch_sfq: fix a potential crash on gso_skb handling
  scsi: iscsi: Fix incorrect error path labels for flashnode operations
  NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
  NFSD: Fix ia_size underflow
  Input: synaptics-rmi - fix crash with unsupported versions of F34
  Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
  pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
  do_change_type(): refuse to operate on unmounted/not ours mounts
  PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
  ice: create new Tx scheduler nodes for new queues only
  Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
  net/mlx4_en: Prevent potential integer overflow calculating Hz
  vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
  serial: Fix potential null-ptr-deref in mlb_usio_probe()
  usb: renesas_usbhs: Reorder clock handling and power management in probe
  rtc: Fix offset calculation for .start_secs < 0
  rtc: sh: assign correct interrupts with DT
  perf record: Fix incorrect --user-regs comments
  perf tests switch-tracking: Fix timestamp comparison
  mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
  mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
  rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
  perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
  perf ui browser hists: Set actions->thread before calling do_zoom_thread()
  fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
  soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
  soc: aspeed: lpc: Fix impossible judgment condition
  arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
  ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
  bus: fsl-mc: fix double-free on mc_dev
  nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
  nilfs2: add pointer check for nilfs_direct_propagate()
  Squashfs: check return result of sb_min_blocksize
  ARM: dts: at91: at91sam9263: fix NAND chip selects
  ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
  f2fs: fix to correct check conditions in f2fs_cross_rename
  f2fs: use d_inode(dentry) cleanup dentry->d_inode
  calipso: Don't call calipso functions for AF_INET sk.
  net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
  net: usb: aqc111: fix error handling of usbnet read calls
  netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
  wifi: ath9k_htc: Abort software beacon handling if disabled
  bpf: Fix WARN() in get_bpf_raw_tp_regs
  pinctrl: at91: Fix possible out-of-boundary access
  ktls, sockmap: Fix missing uncharge operation
  netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
  f2fs: clean up w/ fscrypt_is_bounce_page()
  RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
  wifi: rtw88: do not ignore hardware read error during DPK
  net: ncsi: Fix GCPS 64-bit member variables
  f2fs: fix to do sanity check on sbi->total_valid_block_count
  drm/tegra: rgb: Fix the unbound reference count
  drm/vkms: Adjust vkms_state->active_planes allocation type
  drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
  selftests/seccomp: fix syscall_restart test for arm compat
  firmware: psci: Fix refcount leak in psci_dt_init
  m68k: mac: Fix macintosh_config for Mac II
  drm/vmwgfx: Add seqno waiter for sync_files
  spi: sh-msiof: Fix maximum DMA transfer size
  ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
  x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
  PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
  EDAC/skx_common: Fix general protection fault
  crypto: marvell/cesa - Avoid empty transfer descriptor
  crypto: marvell/cesa - Handle zero-length skcipher requests
  x86/cpu: Sanitize CPUID(0x80000000) output
  perf/core: Fix broken throttling when max_samples_per_tick=1
  gfs2: gfs2_create_inode error handling fix
  netfilter: nft_socket: fix sk refcount leaks
  thunderbolt: Do not double dequeue a configuration request
  usb: usbtmc: Fix timeout value in get_stb
  usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
  usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
  pinctrl: armada-37xx: set GPIO output value before setting direction
  pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
  tracing: Fix compilation warning on arm32
  BACKPORT: binder: Create safe versions of binder log files
  UPSTREAM: binder: Refactor binder_node print synchronization
  Revert "coredump: hand a pidfd to the usermode coredump helper"
  Linux 5.4.294
  xen/swiotlb: relax alignment requirements
  platform/x86: thinkpad_acpi: Ignore battery threshold change event notification
  platform/x86: fujitsu-laptop: Support Lifebook S2110 hotkeys
  spi: spi-sun4i: fix early activation
  um: let 'make clean' properly clean underlying SUBARCH as well
  platform/x86: thinkpad_acpi: Support also NEC Lavie X1475JAS
  nfs: don't share pNFS DS connections between net namespaces
  HID: quirks: Add ADATA XPG alpha wireless mouse support
  coredump: hand a pidfd to the usermode coredump helper
  fork: use pidfd_prepare()
  pid: add pidfd_prepare()
  pidfd: check pid has attached task in fdinfo
  coredump: fix error handling for replace_fd()
  net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
  smb: client: Reset all search buffer pointers when releasing buffer
  smb: client: Fix use-after-free in cifs_fill_dirent
  drm/i915/gvt: fix unterminated-string-initialization warning
  netfilter: nf_tables: do not defer rule destruction via call_rcu
  netfilter: nf_tables: wait for rcu grace period on net_device removal
  netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx
  kbuild: Disable -Wdefault-const-init-unsafe
  spi: spi-fsl-dspi: restrict register range for regmap access
  mm/page_alloc.c: avoid infinite retries caused by cpuset race
  memcg: always call cond_resched() after fn()
  drm/edid: fixed the bug that hdr metadata was not reset
  llc: fix data loss when reading from a socket in llc_ui_recvmsg()
  ALSA: pcm: Fix race of buffer access at PCM OSS layer
  can: bcm: add missing rcu read protection for procfs content
  can: bcm: add locking for bcm_op runtime updates
  crypto: algif_hash - fix double free in hash_accept
  sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
  net: dwmac-sun8i: Use parsed internal PHY address instead of 1
  bridge: netfilter: Fix forwarding of fragmented packets
  xfrm: Sanitize marks before insert
  __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock
  xenbus: Allow PVH dom0 a non-local xenstore
  btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref
  nvmet-tcp: don't restore null sk_state_change
  ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013
  pinctrl: meson: define the pull up/down resistor value as 60 kOhm
  drm: Add valid clones check
  drm/atomic: clarify the rules around drm_atomic_state->allow_modeset
  regulator: ad5398: Add device tree support
  wifi: rtw88: Don't use static local variable in rtw8822b_set_tx_power_index_by_rate
  bpftool: Fix readlink usage in get_fd_type
  HID: usbkbd: Fix the bit shift number for LED_KANA
  scsi: st: Restore some drive settings after reset
  scsi: lpfc: Handle duplicate D_IDs in ndlp search-by D_ID routine
  rcu: fix header guard for rcu_all_qs()
  rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y
  vxlan: Annotate FDB data races
  hwmon: (xgene-hwmon) use appropriate type for the latency value
  ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure().
  net/mlx5e: reduce rep rxq depth to 256 for ECPF
  net/mlx5e: set the tx_queue_len for pfifo_fast
  net/mlx5: Extend Ethtool loopback selftest to support non-linear SKB
  phy: core: don't require set_mode() callback for phy_get_mode() to work
  net/mlx4_core: Avoid impossible mlx4_db_alloc() order value
  smack: recognize ipv4 CIPSO w/o categories
  pinctrl: devicetree: do not goto err when probing hogs in pinctrl_dt_to_map
  ASoC: ops: Enforce platform maximum on initial value
  net/mlx5: Apply rate-limiting to high temperature warning
  net/mlx5: Modify LSB bitmask in temperature event to include only the first bit
  ACPI: HED: Always initialize before evged
  PCI: Fix old_size lower bound in calculate_iosize() too
  EDAC/ie31200: work around false positive build warning
  net: pktgen: fix access outside of user given buffer in pktgen_thread_write()
  wifi: rtw88: Fix rtw_init_ht_cap() for RTL8814AU
  scsi: mpt3sas: Send a diag reset if target reset fails
  MIPS: pm-cps: Use per-CPU variables as per-CPU, not per-core
  MIPS: Use arch specific syscall name match function
  cpuidle: menu: Avoid discarding useful information
  x86/nmi: Add an emergency handler in nmi_desc & use it in nmi_shootdown_cpus()
  bonding: report duplicate MAC address in all situations
  net: xgene-v2: remove incorrect ACPI_PTR annotation
  drm/amdkfd: KFD release_work possible circular locking
  net/mlx5: Avoid report two health errors on same syndrome
  fpga: altera-cvp: Increase credit timeout
  drm/mediatek: mtk_dpi: Add checks for reg_h_fre_con existence
  hwmon: (gpio-fan) Add missing mutex locks
  x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2
  net: pktgen: fix mpls maximum labels list parsing
  pinctrl: bcm281xx: Use "unsigned int" instead of bare "unsigned"
  media: cx231xx: set device_caps for 417
  orangefs: Do not truncate file size
  dm cache: prevent BUG_ON by blocking retries on failed device resumes
  media: c8sectpfe: Call of_node_put(i2c_bus) only once in c8sectpfe_probe()
  ARM: tegra: Switch DSI-B clock parent to PLLD on Tegra114
  ieee802154: ca8210: Use proper setters and getters for bitwise types
  rtc: ds1307: stop disabling alarms on probe
  powerpc/prom_init: Fixup missing #size-cells on PowerBook6,7
  mmc: sdhci: Disable SD card clock before changing parameters
  netfilter: conntrack: Bound nf_conntrack sysctl writes
  posix-timers: Add cond_resched() to posix_timer_add() search loop
  xen: Add support for XenServer 6.1 platform device
  dm: restrict dm device size to 2^63-512 bytes
  kbuild: fix argument parsing in scripts/config
  scsi: st: ERASE does not change tape location
  scsi: st: Tighten the page format heuristics with MODE SELECT
  ext4: reorder capability check last
  um: Update min_low_pfn to match changes in uml_reserved
  um: Store full CSGSFS and SS register from mcontext
  btrfs: send: return -ENAMETOOLONG when attempting a path that is too long
  btrfs: avoid linker error in btrfs_find_create_tree_block()
  i2c: pxa: fix call balance of i2c->clk handling routines
  mmc: host: Wait for Vdd to settle on card power off
  libnvdimm/labels: Fix divide error in nd_label_data_init()
  pNFS/flexfiles: Report ENETDOWN as a connection error
  tools/build: Don't pass test log files to linker
  dql: Fix dql->limit value when reset.
  SUNRPC: rpc_clnt_set_transport() must not change the autobind setting
  NFSv4: Treat ENETUNREACH errors as fatal for state recovery
  fbdev: core: tileblit: Implement missing margin clearing for tileblit
  fbdev: fsl-diu-fb: add missing device_remove_file()
  mailbox: use error ret code of of_parse_phandle_with_args()
  kconfig: merge_config: use an empty file as initfile
  cgroup: Fix compilation issue due to cgroup_mutex not being exported
  dma-mapping: avoid potential unused data compilation warning
  scsi: target: iscsi: Fix timeout on deleted connection
  openvswitch: Fix unsafe attribute parsing in output_userspace()
  Input: synaptics - enable InterTouch on TUXEDO InfinityBook Pro 14 v5
  Input: synaptics - enable SMBus for HP Elitebook 850 G1
  clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable()
  phy: renesas: rcar-gen3-usb2: Set timing registers only once
  phy: Fix error handling in tegra_xusb_port_init
  ALSA: es1968: Add error handling for snd_pcm_hw_constraint_pow2()
  ACPI: PPTT: Fix processor subtable walk
  dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting less when interrupted"
  NFSv4/pnfs: Reset the layout state after a layoutreturn
  NFSv4/pnfs: pnfs_set_layout_stateid() should update the layout cred
  qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd()
  ALSA: sh: SND_AICA should depend on SH_DMA_API
  net: dsa: sja1105: discard incoming frames in BR_STATE_LISTENING
  spi: loopback-test: Do not split 1024-byte hexdumps
  nfs: handle failure of nfs_get_lock_context in unlock path
  RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug
  iio: chemical: sps30: use aligned_s64 for timestamp
  iio: adc: ad7768-1: Fix insufficient alignment of timestamp.
  staging: axis-fifo: Correct handling of tx_fifo_depth for size validation
  staging: axis-fifo: avoid parsing ignored device tree properties
  staging: axis-fifo: Remove hardware resets for user errors
  staging: axis-fifo: replace spinlock with mutex
  platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
  do_umount(): add missing barrier before refcount checks in sync case
  nvme: unblock ctrl state transition for firmware update
  MIPS: Fix MAX_REG_OFFSET
  iio: adc: dln2: Use aligned_s64 for timestamp
  types: Complement the aligned types with signed 64-bit one
  usb: usbtmc: Fix erroneous generic_read ioctl return
  usb: usbtmc: Fix erroneous wait_srq ioctl return
  usb: usbtmc: Fix erroneous get_stb ioctl error returns
  USB: usbtmc: use interruptible sleep in usbtmc_read
  usb: typec: ucsi: displayport: Fix NULL pointer access
  usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT transition
  ocfs2: stop quota recovery before disabling quotas
  ocfs2: implement handshaking with ocfs2 recovery thread
  ocfs2: switch osb->disable_recovery to enum
  module: ensure that kobject_put() is safe for module type kobjects
  xenbus: Use kref to track req lifetime
  usb: uhci-platform: Make the clock really optional
  iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo
  iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo
  iio: adis16201: Correct inclinometer channel resolution
  iio: adc: ad7606: fix serial register access
  staging: iio: adc: ad7816: Correct conditional logic for store mode
  Input: synaptics - enable InterTouch on Dell Precision M3800
  Input: synaptics - enable InterTouch on Dynabook Portege X30L-G
  Input: synaptics - enable InterTouch on Dynabook Portege X30-D
  net: dsa: b53: fix learning on VLAN unaware bridges
  netfilter: ipset: fix region locking in hash types
  sch_htb: make htb_deactivate() idempotent
  scsi: target: Fix WRITE_SAME No Data Buffer crash
  dm: fix copying after src array boundaries
  iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid
  arm64: dts: rockchip: fix iface clock-name on px30 iommus
  usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error handling
  usb: chipidea: ci_hdrc_imx: use dev_err_probe()
  usb: chipidea: imx: refine the error handling for hsic
  usb: chipidea: imx: change hsic power regulator as optional
  irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
  irqchip/gic-v2m: Mark a few functions __init
  irqchip/gic-v2m: Add const to of_device_id
  sch_htb: make htb_qlen_notify() idempotent
  of: module: add buffer overflow check in of_modalias()
  PCI: imx6: Skip controller_id generation logic for i.MX7D
  net: fec: ERR007885 Workaround for conventional TX
  net: lan743x: Fix memleak issue when GSO enabled
  lan743x: fix endianness when accessing descriptors
  lan743x: remove redundant initialization of variable current_head_index
  nvme-tcp: fix premature queue removal and I/O failover
  net: dlink: Correct endianness handling of led_mode
  net_sched: qfq: Fix double list add in class with netem as child qdisc
  net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
  net_sched: drr: Fix double list add in class with netem as child qdisc
  net/mlx5: E-Switch, Initialize MAC Address for Default GID
  tracing: Fix oob write in trace_seq_to_buffer()
  dm: always update the array size in realloc_argv on success
  dm-integrity: fix a warning on invalid table line
  wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()
  amd-xgbe: Fix to ensure dependent features are toggled with RX checksum offload
  parisc: Fix double SIGFPE crash
  i2c: imx-lpi2c: Fix clock count when probe defers
  EDAC/altera: Set DDR and SDMMC interrupt mask before registration
  EDAC/altera: Test the correct error reg offset

 Conflicts:
	Makefile
	drivers/platform/Kconfig
	drivers/platform/Makefile
	include/linux/pid.h

Change-Id: Iab0fd96a23cfe218e945cbf71eef0e87dce204db
2025-09-01 13:17:46 +03:00
Greg Kroah-Hartman
4d9a721965 Merge tag 'android11-5.4.296_r00' into android11-5.4
This merges the android11-5.4.296_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

* 4b4c88cf07 Merge android11-5.4 into android11-5.4-lts
* 76f454157d Revert "drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling"
* 02f0aeffc1 Merge 5.4.296 into android11-5.4-lts
* 04b7726c3c Linux 5.4.296
* ecdb232730 net: ipv6: Discard next-hop MTU less than minimum link MTU
* b2fdd7f1b6 x86/mm: Disable hugetlb page table sharing on 32-bit
* e690296886 Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID
* 35f1a5360a HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
* 99599f9989 HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY
* 7549410b27 vt: add missing notification when switching back to text mode
* 1987e681ea net: usb: qmi_wwan: add SIMCom 8230C composition
* 553017c66e atm: idt77252: Add missing `dma_map_error()`
* e260f4d493 bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
* 2da77aa6a5 bnxt_en: Fix DCB ETS validation
* 6807ef101b can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level
* 7c0beeab3a net: phy: microchip: limit 100M workaround to link-down events on LAN88xx
* b92bedf71f net: appletalk: Fix device refcount leak in atrtr_create()
* d8a6853d00 md/raid1: Fix stack memory use after return in raid1_reshape
* c1958270de wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
* b96d700a2a dma-buf: fix timeout handling in dma_resv_wait_timeout v2
* 221244b0bd Input: xpad - support Acer NGR 200 Controller
* 6edf13f159 Input: xpad - add VID for Turtle Beach controllers
* f01afc1e46 Input: xpad - add support for Amazon Game Controller
* 5f5239363c NFSv4/flexfiles: Fix handling of NFS level errors in I/O
* 9b6f73ae10 flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes
* c60a54b3b4 RDMA/mlx5: Fix vport loopback for MPV device
* 07100f3ba5 netlink: Fix rmem check in netlink_broadcast_deliver().
* 23791e9242 netlink: make sure we allow at least one dump skb
* 2a668b1707 pwm: mediatek: Ensure to disable clocks in error path
* e0098a1193 Revert "ACPI: battery: negate current when discharging"
* 18d58a467c usb: gadget: u_serial: Fix race condition in TTY wakeup
* 549a9c78c3 drm/sched: Increment job count before swapping tail spsc queue
* 6a89563ccf pinctrl: qcom: msm: mark certain pins as invalid for interrupts
* 7c2bc303a0 x86/mce: Make sure CMCI banks are cleared during shutdown on Intel
* d6720de3bd x86/mce: Don't remove sysfs if thresholding sysfs init fails
* a3e80b2fcc x86/mce/amd: Fix threshold limit reset
* bf0ca6a1bc rxrpc: Fix oops due to non-existence of prealloc backlog struct
* 923a276c74 net/sched: Abort __tc_modify_qdisc if parent class does not exist
* 9ec7e943ae atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
* f493f31a63 atm: clip: Fix infinite recursive call of clip_push().
* 2fb37ab322 atm: clip: Fix memory leak of struct clip_vcc.
* a4c5785feb atm: clip: Fix potential null-ptr-deref in to_atmarpd().
* 03dcdd2558 tipc: Fix use-after-free in tipc_conn_close().
* 9da025150b netlink: Fix wraparounds of sk->sk_rmem_alloc.
* 16a58e9a17 fix proc_sys_compare() handling of in-lookup dentries
* 42e9cf27c0 proc: Clear the pieces of proc_inode that proc_evict_inode cares about
* b4e72c0bf8 drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
* a801f7b08b staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher()
* e9bd89e6e7 media: uvcvideo: Rollback non processed entities on error
* daf9c48d79 media: uvcvideo: Send control events for partial succeeds
* a99f3157a7 media: uvcvideo: Return the number of processed controls
* 82191a21a0 ACPI: PAD: fix crash in exit_round_robin()
* 749d907673 usb: typec: displayport: Fix potential deadlock
* 0722035aef Logitech C-270 even more broken
* 94e0918e39 rose: fix dangling neighbour pointers in rose_rt_device_down()
* 9de013fa77 net: rose: Fix fall-through warnings for Clang
* 60b7577308 drm/i915/gt: Fix timeline left held on VMA alloc error
* 6d2d741052 drm/i915/selftests: Change mock_request() to return error pointers
* fb6c27aaf3 spi: spi-fsl-dspi: Clear completion counter before initiating transfer
* 50a387e1f7 spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path
* 3f6491c3bc spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write
* 3cef0d2afb dpaa2-eth: fix xdp_rxq_info leak
* 568a6afd1d ethernet: atl1: Add missing DMA mapping error checks and count errors
* e2dec6cdb6 btrfs: use btrfs_record_snapshot_destroy() during rmdir
* ef761ccefc btrfs: propagate last_unlink_trans earlier when doing a rmdir
* c6f8ded6a6 RDMA/mlx5: Fix CC counters query for MPV
* 40af2a153d RDMA/core: Create and destroy counters in the ib_core
* eaf0a33edf scsi: ufs: core: Fix spelling of a sysfs attribute name
* b9c403d123 drm/v3d: Disable interrupts before resetting the GPU
* ea4664dff8 mtk-sd: reset host->mrq on prepare_data() error
* 5ac9e9e2e9 mtk-sd: Prevent memory corruption from DMA map failure
* 0f495797f5 mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data()
* a3cd5ae7be regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
* 285e4fb525 regulator: gpio: Add input_supply support in gpio_regulator_config
* b49d224d18 ACPICA: Refuse to evaluate a method if arguments are missing
* 7a2afdc5af wifi: ath6kl: remove WARN on bad firmware input
* 48293b9cde wifi: mac80211: drop invalid source address OCB frames
* f2aec1069f powerpc: Fix struct termio related ioctl macros
* 2b61eebbd0 ata: pata_cs5536: fix build on 32-bit UML
* 78c0ba1d1c ALSA: sb: Force to disable DMAs once when DMA mode is changed
* 3b290923ad net/sched: Always pass notifications when child class becomes empty
* 73c38e679a nui: Fix dma_mapping_error() check
* 32bc854b8f enic: fix incorrect MTU comparison in enic_change_mtu()
* 0247896973 amd-xgbe: align CL37 AN sequence as per databook
* 80e9028f5c lib: test_objagg: Set error message in check_expect_hints_stats()
* 71ac65ebd9 drm/exynos: fimd: Guard display clock control with runtime PM calls
* 9b506d95bb btrfs: fix missing error handling when searching for inode refs during log replay
* 5e6d24e635 scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu()
* 8785701fd7 nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails.
* 716b555fc0 RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert
* 7121f483bd platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
* 35fcc9ea84 mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
* c93bc95978 usb: typec: altmodes/displayport: do not index invalid pin_assignments
* e7e914942b Revert "mmc: sdhci: Disable SD card clock before changing parameters"
* 8e56691a97 mmc: sdhci: Add a helper function for dump register in dynamic debug mode
* 19c2cc01ff vsock/vmci: Clear the vmci transport packet properly when initializing it
* c069415640 btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
* a7ae98c219 arm64: Restrict pagetable teardown to avoid false warning
* 88e47ded17 s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
* c1a4677f7c drm/bridge: cdns-dsi: Check return value when getting default PHY config
* 7aa42abc8d drm/bridge: cdns-dsi: Fix connecting to next bridge
* 0ad3721400 drm/bridge: cdns-dsi: Fix the clock variable for mode_valid()
* e52589c016 drm/tegra: Assign plane type before registration
* 57b0ad4f5c HID: wacom: fix kobject reference count leak
* ee49c0e99a HID: wacom: fix memory leak on sysfs attribute creation failure
* e0d646954b HID: wacom: fix memory leak on kobject creation failure
* a30260dcf2 dm-raid: fix variable in journal device check
* 397df6d957 Bluetooth: L2CAP: Fix L2CAP MTU negotiation
* 2a8dcee649 atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
* a434395b00 net: enetc: Correct endianness handling in _enetc_rd_reg64
* a304adc2c7 um: ubd: Add missing error check in start_io_thread()
* 04ec06adf8 vsock/uapi: fix linux/vm_sockets.h userspace compilation errors
* 14f42b7be2 wifi: mac80211: fix beacon interval calculation overflow
* 5925f9f229 attach_recursive_mnt(): do not lock the covering tree when sliding something under it
* 24ff7d465c ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
* 585be561e5 i2c: robotfuzz-osif: disable zero-length read messages
* e34167aee4 i2c: tiny-usb: disable zero-length read messages
* 013dcdf6f0 RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
* 33e120ff07 RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private
* 57597d8db5 media: vivid: Change the siize of the composing
* 725a7c2a73 media: omap3isp: use sgtable-based scatterlist wrappers
* 77829a5f5a media: cxusb: no longer judge rbuf when the write fails
* 1301d405cd media: cxusb: use dev_dbg() rather than hand-rolled debug
* 95ae5ee606 jfs: validate AG parameters in dbMount() to prevent crashes
* 7d17153a85 fs/jfs: consolidate sanity checking in dbMount
* 80efe2d9ce ASoC: meson: meson-card-utils: use of_property_present() for DT parsing
* f1195eb224 of: Add of_property_present() helper
* 9c4736267c of: property: define of_property_read_u{8,16,32,64}_array() unconditionally
* 20fa617fe4 kbuild: hdrcheck: fix cross build with clang
* 25661f954b kbuild: add --target to correctly cross-compile UAPI headers with Clang
* 223f497f05 bpfilter: match bit size of bpfilter_umh to that of the kernel
* 4451642747 kbuild: use -MMD instead of -MD to exclude system headers from dependency
* 74095bbbb1 VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
* b4239bfb26 VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF
* 094353c10f ovl: Check for NULL d_inode() in ovl_dentry_upper()
* 6fd52bfecd ceph: fix possible integer overflow in ceph_zero_objects()
* 471722bb5b ALSA: hda: Ignore unsol events for cards being shut down
* e0359c66c1 usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode
* df6701168a usb: cdc-wdm: avoid setting WDM_READ for ZLP-s
* 13d8f52c88 usb: Add checks for snprintf() calls in usb_alloc_dev()
* 5015eed450 tty: serial: uartlite: register uart driver in init
* 0861b9cb2f usb: potential integer overflow in usbg_make_tpg()
* 70ee697bf1 iio: pressure: zpa2326: Use aligned_s64 for the timestamp
* 6b23e4e713 md/md-bitmap: fix dm-raid max_write_behind setting
* fce4e6a548 dmaengine: xilinx_dma: Set dma_device directions
* 2ad0c96d44 mfd: max14577: Fix wakeup source leaks on device unbind
* 48f8227a65 mailbox: Not protect module_put with spin_lock_irqsave
* 8161046920 cifs: Fix cifs_query_path_info() for Windows NT servers

Change-Id: I846696f18af0af53cdc74e698d6a529ad06d7c12
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-09-01 02:53:46 -07:00
Kalesh Singh
e4601d0bb2 ANDROID: 16K: Allocate pad vma on the stack
Now that the padding VMA is only used in show_map_pad_vma(),
initialize the padding VMA struct on the stack.

This is a nice clean up and avoid having to deal with dynamic
allocation failure.

Bug: 440210631
Bug: 432564748
Change-Id: I168cda6cdb98423a40bb691b687c0f99bd160db6
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2025-08-22 07:07:13 -07:00
Kalesh Singh
2f1e2df209 ANDROID: 16K: Don't copy data vma for maps/smaps output
Remove get_data_vma() which made a copy of the original VMA containing
padding and modified vm_end to exclude the trailing padding (if any).

Avoid this copy to avoid races due to stale data relating to
vma->vm_file.

Instead use VMA_PAD_START(vma) directly to get the correct end excluding
padding if any.

Add additional check to verify the padding VMA is as expected and also
check for allocation failure of the pad VMA.

ELFs with padding can be loaded from tmpfs. For simplicity swapped out
shmem accounting in smaps, skips the fast path for read only files and
walks the page table with the range adjusted for padding.

Example output:

===== Maps =====

7ff6306c2000-7ff6306c3000 r--p 00000000 fe:09 1912                       /system/lib64/bootstrap/libdl.so
7ff6306c3000-7ff6306c6000 ---p 00000000 00:00 0                          [page size compat]
7ff6306c6000-7ff6306c7000 r-xp 00004000 fe:09 1912                       /system/lib64/bootstrap/libdl.so
7ff6306c7000-7ff6306ca000 ---p 00000000 00:00 0                          [page size compat]
7ff6306ca000-7ff6306cb000 r--p 00008000 fe:09 1912                       /system/lib64/bootstrap/libdl.so

===== Smaps =====

7ff6306c2000-7ff6306c3000 r--p 00000000 fe:09 1912                       /system/lib64/bootstrap/libdl.so
Size:                  4 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:                   4 kB
Pss:                   0 kB
Pss_Dirty:             0 kB
Shared_Clean:          4 kB
Shared_Dirty:          0 kB
Private_Clean:         0 kB
Private_Dirty:         0 kB
Referenced:            4 kB
Anonymous:             0 kB
KSM:                   0 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
FilePmdMapped:         0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB
THPeligible:           0
VmFlags: rd mr mw me ??
7ff6306c3000-7ff6306c6000 ---p 00000000 00:00 0                          [page size compat]
Size:                 12 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:                   0 kB
Pss:                   0 kB
Pss_Dirty:             0 kB
Shared_Clean:          0 kB
Shared_Dirty:          0 kB
Private_Clean:         0 kB
Private_Dirty:         0 kB
Referenced:            0 kB
Anonymous:             0 kB
KSM:                   0 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
FilePmdMapped:         0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB
THPeligible:           0
VmFlags: mr mw me
7ff6306c6000-7ff6306c7000 r-xp 00004000 fe:09 1912                       /system/lib64/bootstrap/libdl.so
Size:                  4 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:                   4 kB
Pss:                   0 kB
Pss_Dirty:             0 kB
Shared_Clean:          4 kB
Shared_Dirty:          0 kB
Private_Clean:         0 kB
Private_Dirty:         0 kB
Referenced:            4 kB
Anonymous:             0 kB
KSM:                   0 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
FilePmdMapped:         0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB
THPeligible:           0
VmFlags: rd ex mr mw me ??
7ff6306c7000-7ff6306ca000 ---p 00000000 00:00 0                          [page size compat]
Size:                 12 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:                   0 kB
Pss:                   0 kB
Pss_Dirty:             0 kB
Shared_Clean:          0 kB
Shared_Dirty:          0 kB
Private_Clean:         0 kB
Private_Dirty:         0 kB
Referenced:            0 kB
Anonymous:             0 kB
KSM:                   0 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
FilePmdMapped:         0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB
THPeligible:           0
VmFlags: mr mw me
7ff6306ca000-7ff6306cb000 r--p 00008000 fe:09 1912                       /system/lib64/bootstrap/libdl.so
Size:                  4 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:                   4 kB
Pss:                   4 kB
Pss_Dirty:             4 kB
Shared_Clean:          0 kB
Shared_Dirty:          0 kB
Private_Clean:         0 kB
Private_Dirty:         4 kB
Referenced:            4 kB
Anonymous:             4 kB
KSM:                   0 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
FilePmdMapped:         0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB
THPeligible:           0
VmFlags: rd mr mw me ac

Bug: 427145188
Bug: 409239984
Change-Id: Ic54e89571276db62ffc01681e7ca8986bb1ca7c4
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
2025-08-22 07:06:50 -07:00
Joann Liu
7802e7ac16 ANDROID: GKI: update Trimble symbol list
Update symbol for cdc_mbim and qcserial

Leaf changes summary: 8 artifacts changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 8 Added functions
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

8 Added functions:

  [A] 'function int cdc_ncm_bind_common(usbnet*, usb_interface*, u8, int)'
  [A] 'function int cdc_ncm_change_mtu(net_device*, int)'
  [A] 'function sk_buff* cdc_ncm_fill_tx_frame(usbnet*, sk_buff*, __le32)'
  [A] 'function int cdc_ncm_rx_verify_ndp16(sk_buff*, int)'
  [A] 'function int cdc_ncm_rx_verify_nth16(cdc_ncm_ctx*, sk_buff*)'
  [A] 'function u8 cdc_ncm_select_altsetting(usb_interface*)'
  [A] 'function void cdc_ncm_unbind(usbnet*, usb_interface*)'
  [A] 'function void usb_disable_autosuspend(usb_device*)'

Bug: 437733089
Change-Id: I8b5b287ffdd4bfd914cff1308487c10556a28433
Signed-off-by: Joann Liu <joann_liu@pegatroncorp.com>
2025-08-12 16:58:01 +08:00
Lion Ackermann
1e81917710 UPSTREAM: net/sched: Always pass notifications when child class becomes empty
[ Upstream commit 103406b38c600fec1fe375a77b27d87e314aea09 ]

Certain classful qdiscs may invoke their classes' dequeue handler on an
enqueue operation. This may unexpectedly empty the child qdisc and thus
make an in-flight class passive via qlen_notify(). Most qdiscs do not
expect such behaviour at this point in time and may re-activate the
class eventually anyways which will lead to a use-after-free.

The referenced fix commit attempted to fix this behavior for the HFSC
case by moving the backlog accounting around, though this turned out to
be incomplete since the parent's parent may run into the issue too.
The following reproducer demonstrates this use-after-free:

    tc qdisc add dev lo root handle 1: drr
    tc filter add dev lo parent 1: basic classid 1:1
    tc class add dev lo parent 1: classid 1:1 drr
    tc qdisc add dev lo parent 1:1 handle 2: hfsc def 1
    tc class add dev lo parent 2: classid 2:1 hfsc rt m1 8 d 1 m2 0
    tc qdisc add dev lo parent 2:1 handle 3: netem
    tc qdisc add dev lo parent 3:1 handle 4: blackhole

    echo 1 | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888
    tc class delete dev lo classid 1:1
    echo 1 | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888

Since backlog accounting issues leading to a use-after-frees on stale
class pointers is a recurring pattern at this point, this patch takes
a different approach. Instead of trying to fix the accounting, the patch
ensures that qdisc_tree_reduce_backlog always calls qlen_notify when
the child qdisc is empty. This solves the problem because deletion of
qdiscs always involves a call to qdisc_reset() and / or
qdisc_purge_queue() which ultimately resets its qlen to 0 thus causing
the following qdisc_tree_reduce_backlog() to report to the parent. Note
that this may call qlen_notify on passive classes multiple times. This
is not a problem after the recent patch series that made all the
classful qdiscs qlen_notify() handlers idempotent.

Bug: 431676976
Fixes: 3f981138109f ("sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()")
Signed-off-by: Lion Ackermann <nnamrec@gmail.com>
Reviewed-by: Jamal Hadi Salim <jhs@mojatatu.com>
Acked-by: Cong Wang <xiyou.wangcong@gmail.com>
Acked-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/d912cbd7-193b-4269-9857-525bee8bbb6a@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit e9921b57dca05ac5f4fa1fa8e993d4f0ee52e2b7)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2eb242c0279efc5c5e31e63f7fb12a3f4d5f3e1d
2025-08-05 16:23:04 +01:00
Neill Kapron
387dbb9a99 ANDROID: bpf: do not fail to load if log is full
Upstream commit 973c7a0d8a38 ("bpf: fix precision backtracking
instruction iteration") slightly changes the logic in the verifier which
results in the verifier log growing. This results in the log being too
small when loading the filterPowerSupplyEvents BPF program in Android,
and therefore causing the program loading to fail. Because this
program is labeled 'critical', a load failure forces a boot loop.

This BPF program exists on the vendor partition, and therefore we must
maintain the GRF/ treble boundary and modify the kernel logic.

The kernel's bpf log logic is refactored in the 6.4 kernel and
acknowledges the shortcomings of the existing approach which causes the
program load to fail. Instead of backporting the significant changes,
this change simply ignores the fact that the log is full.

For more information see commit 121664093803 ("bpf: Switch BPF verifier
log to be a rotating log by default")

Bug: 432207940
Bug: 433641053
Test: verify pixel 6 boots on a 5.10 kernel including commit 973c7a0d8a38
Change-Id: I35c3d2074dd9b39e44bfdbaf66fa56ec917df0a6
Signed-off-by: Neill Kapron <nkapron@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-29 07:38:45 +00:00
Greg Kroah-Hartman
4b4c88cf07 Merge android11-5.4 into android11-5.4-lts
This merges the android11-5.4 branch into the -lts branch, catching
it up with the latest changes in there.

It contains the following commits:

* 21224f4b67 Merge tag 'android11-5.4.295_r00' into android11-5.4
* 5287b166b7 ANDROID: fix kernelci compressed kernel linking
* d72ce6ed64 ANDROID: GKI: Update symbol list for Zebra
* a4761d1472 UPSTREAM: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

Change-Id: Icfb6f14de98e8e0974621c528941d6bed6555e2a
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-26 10:57:02 +00:00
Greg Kroah-Hartman
21224f4b67 Merge tag 'android11-5.4.295_r00' into android11-5.4
This merges the android11-5.4.295_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

*   978aeb58ff Merge 5.4.295 into android11-5.4-lts
|\
| * 39ed7800f9 Linux 5.4.295
| * 5d84869995 scsi: qedf: Use designated initializer for struct qed_fcoe_cb_ops
| * 64773b3ea0 arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
| * 7b8f3c7217 perf: Fix sample vs do_exit()
| * cc2f923e92 s390/pci: Fix __pcilg_mio_inuser() inline assembly
| * b9dc8b84b9 rtc: test: Fix invalid format specifier.
| * 5c1a34ff5b jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata()
| * 753f142f7f mm/huge_memory: fix dereferencing invalid pmd migration entry
| * afef20f488 rtc: Make rtc_time64_to_tm() support dates before 1970
| * 31d87dda79 rtc: Improve performance of rtc_time64_to_tm(). Add tests.
| * 59892d18dd xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
| * 78a4b8e379 posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
| * 0fee1b2b48 ARM: dts: am335x-bone-common: Increase MDIO reset deassert delay to 50ms
| * b9ffe75f36 ARM: dts: am335x-bone-common: Increase MDIO reset deassert time
| * 6a4c1721a7 ARM: dts: am335x-bone-common: Add GPIO PHY reset on revision C3 board
| * fcfccf56f4 net: atm: fix /proc/net/atm/lec handling
| * e91274cc7e net: atm: add lec_mutex
| * 956f149941 calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
| * 3998283e4c tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
| * 4918865254 tcp: fix tcp_packet_delayed() for tcp_is_non_sack_preventing_reopen() behavior
| * c19c094342 atm: atmtcp: Free invalid length skb in atmtcp_c_send().
| * 2919297b18 mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
| * 0140d3d37f wifi: carl9170: do not ping device which has failed to load firmware
| * ed52e9652b aoe: clean device rq_list in aoedev_downdev()
| * c14c02a712 hwmon: (occ) fix unaligned accesses
| * 738066cdd0 drm/nouveau/bl: increase buffer size to avoid truncate warning
| * 2b9109de64 erofs: remove unused trace event erofs_destroy_inode
| * de2b7d137b ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
| * 6357f20e00 ALSA: hda/intel: Add Thinkpad E15 to PM deny list
| * 82ff0cc5f5 Input: sparcspkr - avoid unannotated fall-through
| * 7a6d6b68db HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
| * 5e0d009921 atm: Revert atm_account_tx() if copy_from_iter_full() fails.
| * a21966e594 selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
| * 48222a330d scsi: s390: zfcp: Ensure synchronous unit_add
| * 8bc89302f3 scsi: storvsc: Increase the timeouts to storvsc_timeout
| * 7e860296d7 jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
| * 337f80f3d5 jffs2: check that raw node were preallocated before writing summary
| * a8b5ea2e30 drivers/rapidio/rio_cm.c: prevent possible heap overwrite
| * a8b7347f5e Revert "x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2" on v6.6 and older
| * ba649593f3 powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO EEH recovery
| * 65594ec9d2 platform/x86: dell_rbu: Stop overwriting data buffer
| * e6ff2952c3 platform: Add Surface platform directory
| * 882ff6d324 Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
| * 77a06908a3 tee: Prevent size calculation wraparound on 32-bit kernels
| * 54edad2d2c ARM: OMAP2+: Fix l4ls clk domain handling in STANDBY
| * 41a4c323cc bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
| * df5bd72949 watchdog: da9052_wdt: respect TWDMIN
| * 872607632c i40e: fix MMIO write access to an invalid page in i40e_clear_hw
| * 7e372262cd sock: Correct error checking condition for (assign|release)_proto_idx()
| * ac7bfaa099 scsi: lpfc: Use memcpy() for BIOS version
| * 4f10da4e82 vxlan: Do not treat dst cache initialization errors as fatal
| * 90cba782f8 clk: rockchip: rk3036: mark ddrphy as critical
| * 7c24ad36d5 wifi: mac80211: do not offer a mesh path if forwarding is disabled
| * db876c0a05 net: mlx4: add SOF_TIMESTAMPING_TX_SOFTWARE flag when getting ts info
| * 7db634f5f6 pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get()
| * e29b3da920 pinctrl: armada-37xx: propagate error from armada_37xx_pmx_gpio_set_direction()
| * 3168358647 pinctrl: armada-37xx: propagate error from armada_37xx_gpio_get_direction()
| * ecbd6b4d83 pinctrl: armada-37xx: propagate error from armada_37xx_pmx_set_by_name()
| * de9b7586f9 ipv4/route: Use this_cpu_inc() for stats on PREEMPT_RT
| * bcaf3c2f06 tcp: fix initial tp->rcvq_space.space value for passive TS enabled flows
| * 17c42ca3d1 tcp: always seek for minimal rtt in tcp_rcv_rtt_update()
| * 17813543a3 net: dlink: add synchronization for stats update
| * 8094640cdf sctp: Do not wake readers in __sctp_write_space()
| * c5ea7c6d0a emulex/benet: correct command version selection in be_cmd_get_stats()
| * aa588740e3 i2c: designware: Invoke runtime suspend on quick slave re-registration
| * 9a9fd4025b net: macb: Check return value of dma_set_mask_and_coherent()
| * 7f33b484bb cpufreq: Force sync policy boost with global boost on sysfs update
| * d4292853f7 nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults
| * b0d92b9427 media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()
| * 45f5a37b58 media: tc358743: ignore video while HPD is low
| * 8a8b77335f drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB
| * 0d50231d47 jfs: Fix null-ptr-deref in jfs_ioc_trim
| * c17707f2e7 drm/amdgpu/gfx9: fix CSIB handling
| * 3ba40789f5 drm/amdgpu/gfx8: fix CSIB handling
| * 81af4b34fd jfs: fix array-index-out-of-bounds read in add_missing_indices
| * 9a3b711f78 drm/amdgpu/gfx7: fix CSIB handling
| * d7f3ca1c09 drm/amdgpu/gfx10: fix CSIB handling
| * 8c49859140 drm/msm/a6xx: Increase HFI response timeout
| * 63074eed66 drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit()
| * ceb810de2d media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
| * 9c60c173ab drm/msm/hdmi: add runtime PM calls to DDC transfer function
| * 08493880ff drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq()
| * 88dec58190 sunrpc: update nextcheck time when adding new cache entries
| * 255959104f drm/amdgpu/gfx6: fix CSIB handling
| * 081558451e ACPI: battery: negate current when discharging
| * 44050a6c1a PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn()
| * a9f710fc7a power: supply: bq27xxx: Retrieve again when busy
| * 1e0e629e88 ACPICA: fix acpi parse and parseext cache leaks
| * 2ca55d221b ACPICA: Avoid sequence overread in call to strncmp()
| * 4fa430a8bc ACPICA: fix acpi operand cache leak in dswstate.c
| * 0068025928 iio: adc: ad7606_spi: fix reg write value mask
| * acf5c9d8b3 PCI: Fix lock symmetry in pci_slot_unlock()
| * 300f543231 PCI: Add ACS quirk for Loongson PCIe
| * 0ac228f76f uio_hv_generic: Use correct size for interrupt and monitor pages
| * e66a241cb7 regulator: max14577: Add error check for max14577_read_reg()
| * 39fe75f00f mips: Add -std= flag specified in KBUILD_CFLAGS to vdso CFLAGS
| * 34d5ea7ee0 staging: iio: ad5933: Correct settling cycles encoding per datasheet
| * 119766de49 net: ch9200: fix uninitialised access during mii_nway_restart
| * d064c68781 ftrace: Fix UAF when lookup kallsym after ftrace disabled
| * 92311f8dfd dm-mirror: fix a tiny race condition
| * 3b443407da mtd: nand: sunxi: Add randomizer configuration before randomizer enable
| * b1f30e7c7d mtd: rawnand: sunxi: Add randomizer configuration in sunxi_nfc_hw_ecc_write_chunk
| * b36ad2ddc2 mm: fix ratelimit_pages update error in dirty_ratio_handler()
| * 5f1e1573bf ipc: fix to protect IPCS lookups using RCU
| * 6a5cda7fd5 parisc: fix building with gcc-15
| * e44532b1c3 vgacon: Add check for vc_origin address range in vgacon_scroll()
| * ee20216f12 fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
| * 0d02410db5 EDAC/altera: Use correct write width with the INTTEST register
| * a514fca2b8 NFC: nci: uart: Set tty->disc_data only in success path
| * d9a55869d8 f2fs: prevent kernel warning due to negative i_nlink from corrupted image
| * c1b9d140b0 Input: ims-pcu - check record size in ims_pcu_flash_firmware()
| * 922200f03b ext4: fix calculation of credits for extent tree modification
| * d3dfc60efd ext4: inline: fix len overflow in ext4_prepare_inline_data
| * e5d5647b7b bus: fsl-mc: do not add a device-link for the UAPI used DPMCP device
| * 67d66a5e45 ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
| * 175925abd5 ARM: 9447/1: arm/memremap: fix arch_memremap_can_ram_remap()
| * ee141706e7 media: v4l2-dev: fix error handling in __video_register_device()
| * 658029a3c8 media: gspca: Add error handling for stv06xx_read_sensor()
| * b51ce65c44 wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID 11ad:1723
| * bf78a2706c nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
| * 12134f79e5 wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
| * aad09bbe46 gfs2: move msleep to sleepable context
| * 64d0e07a9b configfs: Do not override creating attribute file failure in populate_attrs()
| * c50b9bb30c net: usb: aqc111: debug info before sanitation
| * 2186f01c75 calipso: unlock rcu before returning -EAFNOSUPPORT
| * bddb807958 xen/arm: call uaccess_ttbr0_enable for dm_op hypercall
| * b2ce37d86d usb: Flush altsetting 0 endpoints before reinitializating them after reset.
| * ae57ce58ac fs/filesystems: Fix potential unsigned integer underflow in fs_name()
| * ff70bd8ff4 net/mdiobus: Fix potential out-of-bounds read/write access
| * f4c6337da9 drm/amd/display: Do not add '-mhard-float' to dcn2{1,0}_resource.o for clang
| * d3e3345645 drm/amd/display: Do not add '-mhard-float' to dml_ccflags for clang
| * 92b7545695 MIPS: Move '-Wa,-msoft-float' check from as-option to cc-option
| * c33417f3b8 x86/boot/compressed: prefer cc-option for CFLAGS additions
| * 38c9d4f8e6 net: mdio: C22 is now optional, EOPNOTSUPP if not provided
| * da1f38bc18 net_sched: tbf: fix a race in tbf_change()
| * 2790c4ec48 net_sched: red: fix a race in __red_change()
| * 53d11560e9 net_sched: prio: fix a race in prio_tune()
| * 21498209cb net/mlx5: Fix return value when searching for existing flow group
| * 2fa390ee36 net/mlx5: Wait for inactive autogroups
| * 6ab93dcedc i40e: retry VFLR handling if there is ongoing VF reset
| * 4b4c8fd192 i40e: return false from i40e_reset_vf if reset is in progress
| * c337efb20d net_sched: sch_sfq: fix a potential crash on gso_skb handling
| * b076002838 scsi: iscsi: Fix incorrect error path labels for flashnode operations
| * 72c14aed68 NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
| * d2211e6e34 NFSD: Fix ia_size underflow
| * 69aff1b73c Input: synaptics-rmi - fix crash with unsupported versions of F34
| * b475d189f4 Input: synaptics-rmi4 - convert to use sysfs_emit() APIs
| * eab11dcd6a pmdomain: core: Fix error checking in genpd_dev_pm_attach_by_id()
| * 787937c4e3 do_change_type(): refuse to operate on unmounted/not ours mounts
| * 36d91620a6 PM: sleep: Fix power.is_suspended cleanup for direct-complete devices
| * b0122774ab ice: create new Tx scheduler nodes for new queues only
| * 737f13ac66 Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
| * 589c0971af net/mlx4_en: Prevent potential integer overflow calculating Hz
| * 85ae8372cd vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
| * a05ebe384c serial: Fix potential null-ptr-deref in mlb_usio_probe()
| * 095cc0b588 usb: renesas_usbhs: Reorder clock handling and power management in probe
| * 55d4b2734f rtc: Fix offset calculation for .start_secs < 0
| * 5023b76466 rtc: sh: assign correct interrupts with DT
| * a972ec94c3 perf record: Fix incorrect --user-regs comments
| * eed18824a1 perf tests switch-tracking: Fix timestamp comparison
| * 49d0662fea mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
| * 24358eb471 mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice in exynos_lpass_remove()
| * 7b44dbda2e rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
| * 0ea2f7e9e3 perf scripts python: exported-sql-viewer.py: Fix pattern matching with Python 3
| * 43fe88b963 perf ui browser hists: Set actions->thread before calling do_zoom_thread()
| * 9027ce4c03 fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
| * 2beee9cf83 soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
| * c07c8b4e33 soc: aspeed: lpc: Fix impossible judgment condition
| * 81e5357d47 arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou
| * 4e4c974ab4 ARM: dts: qcom: apq8064 merge hw splinlock into corresponding syscon device
| * 12e4431e50 bus: fsl-mc: fix double-free on mc_dev
| * 2f11add2ff nilfs2: do not propagate ENOENT error from nilfs_btree_propagate()
| * 67d596979f nilfs2: add pointer check for nilfs_direct_propagate()
| * db7096ea16 Squashfs: check return result of sb_min_blocksize
| * 21bcf72e97 ARM: dts: at91: at91sam9263: fix NAND chip selects
| * d5373a0af2 ARM: dts: at91: usb_a9263: fix GPIO for Dataflash chip select
| * ce87f4c192 f2fs: fix to correct check conditions in f2fs_cross_rename
| * ab752ebd97 f2fs: use d_inode(dentry) cleanup dentry->d_inode
| * fc2da88411 calipso: Don't call calipso functions for AF_INET sk.
| * 961ad55974 net: lan743x: rename lan743x_reset_phy to lan743x_hw_reset_phy
| * 8c97655275 net: usb: aqc111: fix error handling of usbnet read calls
| * 48af842f4e netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy
| * e5ce9df1d6 wifi: ath9k_htc: Abort software beacon handling if disabled
| * 44ebe361ab bpf: Fix WARN() in get_bpf_raw_tp_regs
| * 264a5cf0c4 pinctrl: at91: Fix possible out-of-boundary access
| * ac7fca667b ktls, sockmap: Fix missing uncharge operation
| * 6d1ab8bf2e netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
| * 879d3e0d54 f2fs: clean up w/ fscrypt_is_bounce_page()
| * ceb20ec671 RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h
| * a052c91a7d wifi: rtw88: do not ignore hardware read error during DPK
| * 64f82c02df net: ncsi: Fix GCPS 64-bit member variables
| * 49bc7bf38e f2fs: fix to do sanity check on sbi->total_valid_block_count
| * 6a2be4740d drm/tegra: rgb: Fix the unbound reference count
| * 833d0acee9 drm/vkms: Adjust vkms_state->active_planes allocation type
| * e443e547a5 drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
| * 593f0060fb selftests/seccomp: fix syscall_restart test for arm compat
| * 5c1d85c971 firmware: psci: Fix refcount leak in psci_dt_init
| * 629a2417ea m68k: mac: Fix macintosh_config for Mac II
| * dc796cdae6 drm/vmwgfx: Add seqno waiter for sync_files
| * 5571f36f21 spi: sh-msiof: Fix maximum DMA transfer size
| * d79fee3bc1 ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
| * a3c189e7c1 x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges()
| * 8eb5b081bc PM: wakeup: Delete space in the end of string shown by pm_show_wakelocks()
| * 80bf28fd62 EDAC/skx_common: Fix general protection fault
| * 8517d3af60 crypto: marvell/cesa - Avoid empty transfer descriptor
| * 32d3e8049a crypto: marvell/cesa - Handle zero-length skcipher requests
| * b48773f888 x86/cpu: Sanitize CPUID(0x80000000) output
| * 5b4da569a2 perf/core: Fix broken throttling when max_samples_per_tick=1
| * 7bf56bd74a gfs2: gfs2_create_inode error handling fix
| * 076d281e90 netfilter: nft_socket: fix sk refcount leaks
| * e49e994cd8 thunderbolt: Do not double dequeue a configuration request
| * 768668e159 usb: usbtmc: Fix timeout value in get_stb
| * 90da5d9876 usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage device
| * 5db9d2c508 usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
| * 0ce2e102ea pinctrl: armada-37xx: set GPIO output value before setting direction
| * 33b1b38acf pinctrl: armada-37xx: use correct OUTPUT_VAL register for GPIOs > 31
| * 26fd2dbc65 tracing: Fix compilation warning on arm32
* b3fbf76488 Merge android11-5.4 into android11-5.4-lts

Change-Id: I5dc61fb04bfb3b890a77c22b1f6312ada2cc46df
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-26 00:43:02 -07:00
Tiffany Yang
5287b166b7 ANDROID: fix kernelci compressed kernel linking
Kernel versions 5.4 and below have several bogus relocations defined in
arch/x86/boot/compressed/head_32.S that cause build errors like the
following when linked with the llvm toolchain:

ld.lld: error: relocation R_386_32 cannot be used against symbol '_bss';
recompile with -fPIC

These errors only show up when linking with LLD because BFD allows
relocations in read-only sections by default. Add "-z notext" to
KBUILD_LDFLAGS to replicate that behavior with ld.lld and unblock
kernelci builds for 5.4 branches.

Bug: 430124841

Change-Id: I393174e264fbc0181abb5ecfd518055a7cb14162
Signed-off-by: Tiffany Yang <ynaffit@google.com>
2025-07-18 11:40:41 -07:00
Greg Kroah-Hartman
76f454157d Revert "drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling"
This reverts commit b4e72c0bf8 which is
commit b846350aa272de99bf6fecfa6b08e64ebfb13173 upstream.

It breaks the Android kernel build and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I5036544ff96d39426f2c09cb10a68422d61cb98d
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-18 11:31:28 +00:00
Greg Kroah-Hartman
02f0aeffc1 This is the 5.4.296 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmh5JDkACgkQONu9yGCS
 aT5nfg//evp7vYDG9XXjBxzgNBJu1kP+N/yNxjM9ATgiEW4/gbhLASWZcMrdhiQl
 bvvEFad055VyjEnhK1OrCkAE/YivuJjnCvAhW4FA2V5sFTh2efYmGEOvgZBnHYsa
 txUYM/1NTlKZYPwM+YBX+9ImPDV84RX2Ryjx9ZKIZoCRsEAuH5rDbuNelgxHkmWe
 7NfscD2Fz5If2DCA7SLAwsL4KTdTfMKuOJThy0/LxAiV0ephZwgYtDB5Do56woqU
 rrV+k4dfKmGz02nOz5AJAP5fjZ0nzC27Ztwahxpey/X/Q2O3qAb9hpC1ELOC88Qv
 /yd5SqnsW4RWW2mrHumu5wngMgz2lXvjR+WOWox0BxHH2BlkkbEDJJRN74Ji7Fyu
 n0uGhRPfP9B0Qm9owTav3SJwD0fvJ1IEuOZ8H7XMONA6Zpv1Xhntqh2hGy0IwXaZ
 1lf9a0p0r9N6bbwLpOQXdDJXGh/nhmYVeTlbhkHdaZDtPpkpA28e3/bJJg15K9ap
 55t4+Xc4yU1qAP3M1GdmygRONCHKt9CpLadVBJ3EG9E6N3xFN1Y6oHAvczmoPTco
 8OITQWn1EBpg9ygLWWeof1COUZITPLsmqt6Yt3307UPqfPK+xjWiz39VNisFfuHB
 4W1lKHa7616bSrQtlc9uvBUO+jhppFtqz9EsrqOEr9epH6jiHJE=
 =LIf5
 -----END PGP SIGNATURE-----

Merge 5.4.296 into android11-5.4-lts

Changes in 5.4.296
	cifs: Fix cifs_query_path_info() for Windows NT servers
	mailbox: Not protect module_put with spin_lock_irqsave
	mfd: max14577: Fix wakeup source leaks on device unbind
	dmaengine: xilinx_dma: Set dma_device directions
	md/md-bitmap: fix dm-raid max_write_behind setting
	iio: pressure: zpa2326: Use aligned_s64 for the timestamp
	usb: potential integer overflow in usbg_make_tpg()
	tty: serial: uartlite: register uart driver in init
	usb: Add checks for snprintf() calls in usb_alloc_dev()
	usb: cdc-wdm: avoid setting WDM_READ for ZLP-s
	usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode
	ALSA: hda: Ignore unsol events for cards being shut down
	ceph: fix possible integer overflow in ceph_zero_objects()
	ovl: Check for NULL d_inode() in ovl_dentry_upper()
	VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF
	VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
	kbuild: use -MMD instead of -MD to exclude system headers from dependency
	bpfilter: match bit size of bpfilter_umh to that of the kernel
	kbuild: add --target to correctly cross-compile UAPI headers with Clang
	kbuild: hdrcheck: fix cross build with clang
	of: property: define of_property_read_u{8,16,32,64}_array() unconditionally
	of: Add of_property_present() helper
	ASoC: meson: meson-card-utils: use of_property_present() for DT parsing
	fs/jfs: consolidate sanity checking in dbMount
	jfs: validate AG parameters in dbMount() to prevent crashes
	media: cxusb: use dev_dbg() rather than hand-rolled debug
	media: cxusb: no longer judge rbuf when the write fails
	media: omap3isp: use sgtable-based scatterlist wrappers
	media: vivid: Change the siize of the composing
	RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private
	RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
	i2c: tiny-usb: disable zero-length read messages
	i2c: robotfuzz-osif: disable zero-length read messages
	ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
	attach_recursive_mnt(): do not lock the covering tree when sliding something under it
	wifi: mac80211: fix beacon interval calculation overflow
	vsock/uapi: fix linux/vm_sockets.h userspace compilation errors
	um: ubd: Add missing error check in start_io_thread()
	net: enetc: Correct endianness handling in _enetc_rd_reg64
	atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
	Bluetooth: L2CAP: Fix L2CAP MTU negotiation
	dm-raid: fix variable in journal device check
	HID: wacom: fix memory leak on kobject creation failure
	HID: wacom: fix memory leak on sysfs attribute creation failure
	HID: wacom: fix kobject reference count leak
	drm/tegra: Assign plane type before registration
	drm/bridge: cdns-dsi: Fix the clock variable for mode_valid()
	drm/bridge: cdns-dsi: Fix connecting to next bridge
	drm/bridge: cdns-dsi: Check return value when getting default PHY config
	s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
	arm64: Restrict pagetable teardown to avoid false warning
	btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
	vsock/vmci: Clear the vmci transport packet properly when initializing it
	mmc: sdhci: Add a helper function for dump register in dynamic debug mode
	Revert "mmc: sdhci: Disable SD card clock before changing parameters"
	usb: typec: altmodes/displayport: do not index invalid pin_assignments
	mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
	platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
	RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert
	nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails.
	scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu()
	btrfs: fix missing error handling when searching for inode refs during log replay
	drm/exynos: fimd: Guard display clock control with runtime PM calls
	lib: test_objagg: Set error message in check_expect_hints_stats()
	amd-xgbe: align CL37 AN sequence as per databook
	enic: fix incorrect MTU comparison in enic_change_mtu()
	nui: Fix dma_mapping_error() check
	net/sched: Always pass notifications when child class becomes empty
	ALSA: sb: Force to disable DMAs once when DMA mode is changed
	ata: pata_cs5536: fix build on 32-bit UML
	powerpc: Fix struct termio related ioctl macros
	wifi: mac80211: drop invalid source address OCB frames
	wifi: ath6kl: remove WARN on bad firmware input
	ACPICA: Refuse to evaluate a method if arguments are missing
	regulator: gpio: Add input_supply support in gpio_regulator_config
	regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
	mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data()
	mtk-sd: Prevent memory corruption from DMA map failure
	mtk-sd: reset host->mrq on prepare_data() error
	drm/v3d: Disable interrupts before resetting the GPU
	scsi: ufs: core: Fix spelling of a sysfs attribute name
	RDMA/core: Create and destroy counters in the ib_core
	RDMA/mlx5: Fix CC counters query for MPV
	btrfs: propagate last_unlink_trans earlier when doing a rmdir
	btrfs: use btrfs_record_snapshot_destroy() during rmdir
	ethernet: atl1: Add missing DMA mapping error checks and count errors
	dpaa2-eth: fix xdp_rxq_info leak
	spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write
	spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path
	spi: spi-fsl-dspi: Clear completion counter before initiating transfer
	drm/i915/selftests: Change mock_request() to return error pointers
	drm/i915/gt: Fix timeline left held on VMA alloc error
	net: rose: Fix fall-through warnings for Clang
	rose: fix dangling neighbour pointers in rose_rt_device_down()
	Logitech C-270 even more broken
	usb: typec: displayport: Fix potential deadlock
	ACPI: PAD: fix crash in exit_round_robin()
	media: uvcvideo: Return the number of processed controls
	media: uvcvideo: Send control events for partial succeeds
	media: uvcvideo: Rollback non processed entities on error
	staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher()
	drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
	proc: Clear the pieces of proc_inode that proc_evict_inode cares about
	fix proc_sys_compare() handling of in-lookup dentries
	netlink: Fix wraparounds of sk->sk_rmem_alloc.
	tipc: Fix use-after-free in tipc_conn_close().
	atm: clip: Fix potential null-ptr-deref in to_atmarpd().
	atm: clip: Fix memory leak of struct clip_vcc.
	atm: clip: Fix infinite recursive call of clip_push().
	atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
	net/sched: Abort __tc_modify_qdisc if parent class does not exist
	rxrpc: Fix oops due to non-existence of prealloc backlog struct
	x86/mce/amd: Fix threshold limit reset
	x86/mce: Don't remove sysfs if thresholding sysfs init fails
	x86/mce: Make sure CMCI banks are cleared during shutdown on Intel
	pinctrl: qcom: msm: mark certain pins as invalid for interrupts
	drm/sched: Increment job count before swapping tail spsc queue
	usb: gadget: u_serial: Fix race condition in TTY wakeup
	Revert "ACPI: battery: negate current when discharging"
	pwm: mediatek: Ensure to disable clocks in error path
	netlink: make sure we allow at least one dump skb
	netlink: Fix rmem check in netlink_broadcast_deliver().
	RDMA/mlx5: Fix vport loopback for MPV device
	flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes
	NFSv4/flexfiles: Fix handling of NFS level errors in I/O
	Input: xpad - add support for Amazon Game Controller
	Input: xpad - add VID for Turtle Beach controllers
	Input: xpad - support Acer NGR 200 Controller
	dma-buf: fix timeout handling in dma_resv_wait_timeout v2
	wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
	md/raid1: Fix stack memory use after return in raid1_reshape
	net: appletalk: Fix device refcount leak in atrtr_create()
	net: phy: microchip: limit 100M workaround to link-down events on LAN88xx
	can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level
	bnxt_en: Fix DCB ETS validation
	bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
	atm: idt77252: Add missing `dma_map_error()`
	net: usb: qmi_wwan: add SIMCom 8230C composition
	vt: add missing notification when switching back to text mode
	HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY
	HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
	Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID
	x86/mm: Disable hugetlb page table sharing on 32-bit
	net: ipv6: Discard next-hop MTU less than minimum link MTU
	Linux 5.4.296

Change-Id: Ida23d7bc57d7a55921aa3db936a175607d7859b8
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-07-18 10:57:54 +00:00
Greg Kroah-Hartman
04b7726c3c Linux 5.4.296
Link: https://lore.kernel.org/r/20250715130800.293690950@linuxfoundation.org
Tested-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Link: https://lore.kernel.org/r/20250716141302.507854168@linuxfoundation.org
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:06 +02:00
Georg Kohmann
ecdb232730 net: ipv6: Discard next-hop MTU less than minimum link MTU
commit 4a65dff81a04f874fa6915c7f069b4dc2c4010e4 upstream.

When a ICMPV6_PKT_TOOBIG report a next-hop MTU that is less than the IPv6
minimum link MTU, the estimated path MTU is reduced to the minimum link
MTU. This behaviour breaks TAHI IPv6 Core Conformance Test v6LC4.1.6:
Packet Too Big Less than IPv6 MTU.

Referring to RFC 8201 section 4: "If a node receives a Packet Too Big
message reporting a next-hop MTU that is less than the IPv6 minimum link
MTU, it must discard it. A node must not reduce its estimate of the Path
MTU below the IPv6 minimum link MTU on receipt of a Packet Too Big
message."

Drop the path MTU update if reported MTU is less than the minimum link MTU.

Signed-off-by: Georg Kohmann <geokohma@cisco.com>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: WangYuli <wangyuli@uniontech.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:06 +02:00
Jann Horn
b2fdd7f1b6 x86/mm: Disable hugetlb page table sharing on 32-bit
commit 76303ee8d54bff6d9a6d55997acd88a6c2ba63cf upstream.

Only select ARCH_WANT_HUGE_PMD_SHARE on 64-bit x86.
Page table sharing requires at least three levels because it involves
shared references to PMD tables; 32-bit x86 has either two-level paging
(without PAE) or three-level paging (with PAE), but even with
three-level paging, having a dedicated PGD entry for hugetlb is only
barely possible (because the PGD only has four entries), and it seems
unlikely anyone's actually using PMD sharing on 32-bit.

Having ARCH_WANT_HUGE_PMD_SHARE enabled on non-PAE 32-bit X86 (which
has 2-level paging) became particularly problematic after commit
59d9094df3d7 ("mm: hugetlb: independent PMD page table shared count"),
since that changes `struct ptdesc` such that the `pt_mm` (for PGDs) and
the `pt_share_count` (for PMDs) share the same union storage - and with
2-level paging, PMDs are PGDs.

(For comparison, arm64 also gates ARCH_WANT_HUGE_PMD_SHARE on the
configuration of page tables such that it is never enabled with 2-level
paging.)

Closes: https://lore.kernel.org/r/srhpjxlqfna67blvma5frmy3aa@altlinux.org
Fixes: cfe28c5d63 ("x86: mm: Remove x86 version of huge_pmd_share.")
Reported-by: Vitaly Chikunov <vt@altlinux.org>
Suggested-by: Dave Hansen <dave.hansen@intel.com>
Signed-off-by: Jann Horn <jannh@google.com>
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: Oscar Salvador <osalvador@suse.de>
Acked-by: David Hildenbrand <david@redhat.com>
Tested-by: Vitaly Chikunov <vt@altlinux.org>
Cc:stable@vger.kernel.org
Link: https://lore.kernel.org/all/20250702-x86-2level-hugetlb-v2-1-1a98096edf92%40google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:06 +02:00
Hans de Goede
e690296886 Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID
commit 9cf6e24c9fbf17e52de9fff07f12be7565ea6d61 upstream.

After commit 936e4d49ecbc ("Input: atkbd - skip ATKBD_CMD_GETID in
translated mode") not only the getid command is skipped, but also
the de-activating of the keyboard at the end of atkbd_probe(), potentially
re-introducing the problem fixed by commit be2d7e4233 ("Input: atkbd -
fix multi-byte scancode handling on reconnect").

Make sure multi-byte scancode handling on reconnect is still handled
correctly by not skipping the atkbd_deactivate() call.

Fixes: 936e4d49ecbc ("Input: atkbd - skip ATKBD_CMD_GETID in translated mode")
Tested-by: Paul Menzel <pmenzel@molgen.mpg.de>
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
Link: https://lore.kernel.org/r/20240126160724.13278-3-hdegoede@redhat.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Wang Hai <wanghai38@huawei.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:06 +02:00
Chia-Lin Kao (AceLan)
35f1a5360a HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
[ Upstream commit 54bae4c17c11688339eb73a04fd24203bb6e7494 ]

The Chicony Electronics HP 5MP Cameras (USB ID 04F2:B824 & 04F2:B82C)
report a HID sensor interface that is not actually implemented.
Attempting to access this non-functional sensor via iio_info causes
system hangs as runtime PM tries to wake up an unresponsive sensor.

Add these 2 devices to the HID ignore list since the sensor interface is
non-functional by design and should not be exposed to userspace.

Signed-off-by: Chia-Lin Kao (AceLan) <acelan.kao@canonical.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Zhang Heng
99599f9989 HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY
[ Upstream commit 1a8953f4f7746c6a515989774fe03047c522c613 ]

MARTLINKTECHNOLOGY is a microphone device, when the HID interface in an
audio device is requested to get specific report id, the following error
may occur.

[  562.939373] usb 1-1.4.1.2: new full-speed USB device number 21 using xhci_hcd
[  563.104908] usb 1-1.4.1.2: New USB device found, idVendor=4c4a, idProduct=4155, bcdDevice= 1.00
[  563.104910] usb 1-1.4.1.2: New USB device strings: Mfr=1, Product=2, SerialNumber=3
[  563.104911] usb 1-1.4.1.2: Product: USB Composite Device
[  563.104912] usb 1-1.4.1.2: Manufacturer: SmartlinkTechnology
[  563.104913] usb 1-1.4.1.2: SerialNumber: 20201111000001
[  563.229499] input: SmartlinkTechnology USB Composite Device as /devices/pci0000:00/0000:00:07.1/0000:04:00.3/usb1/1-1/1-1.4/1-1.4.1/1-1.4.1.2/1-1.4.1.2:1.2/0003:4C4A:4155.000F/input/input35
[  563.291505] hid-generic 0003:4C4A:4155.000F: input,hidraw2: USB HID v2.01 Keyboard [SmartlinkTechnology USB Composite Device] on usb-0000:04:00.3-1.4.1.2/input2
[  563.291557] usbhid 1-1.4.1.2:1.3: couldn't find an input interrupt endpoint
[  568.506654] usb 1-1.4.1.2: 1:1: usb_set_interface failed (-110)
[  573.626656] usb 1-1.4.1.2: 1:1: usb_set_interface failed (-110)
[  578.746657] usb 1-1.4.1.2: 1:1: usb_set_interface failed (-110)
[  583.866655] usb 1-1.4.1.2: 1:1: usb_set_interface failed (-110)
[  588.986657] usb 1-1.4.1.2: 1:1: usb_set_interface failed (-110)

Ignore HID interface. The device is working properly.

Signed-off-by: Zhang Heng <zhangheng@kylinos.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Nicolas Pitre
7549410b27 vt: add missing notification when switching back to text mode
[ Upstream commit ff78538e07fa284ce08cbbcb0730daa91ed16722 ]

Programs using poll() on /dev/vcsa to be notified when VT changes occur
were missing one case: the switch from gfx to text mode.

Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Link: https://lore.kernel.org/r/9o5ro928-0pp4-05rq-70p4-ro385n21n723@onlyvoer.pbz
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Xiaowei Li
1987e681ea net: usb: qmi_wwan: add SIMCom 8230C composition
[ Upstream commit 0b39b055b5b48cbbdf5746a1ca6e3f6b0221e537 ]

Add support for SIMCom 8230C which is based on Qualcomm SDX35 chip.
0x9071: tty (DM) + tty (NMEA) + tty (AT) + rmnet
T:  Bus=01 Lev=01 Prnt=01 Port=05 Cnt=02 Dev#=  8 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1e0e ProdID=9071 Rev= 5.15
S:  Manufacturer=SIMCOM
S:  Product=SDXBAAGHA-IDP _SN:D744C4C5
S:  SerialNumber=0123456789ABCDEF
C:* #Ifs= 5 Cfg#= 1 Atr=a0 MxPwr=500mA
I:* If#= 0 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 1 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=00 Prot=00 Driver=option
E:  Ad=82(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 3 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=86(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:* If#= 4 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=42 Prot=01 Driver=none
E:  Ad=05(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

Signed-off-by: Xiaowei Li <xiaowei.li@simcom.com>
Acked-by: Bjørn Mork <bjorn@mork.no>
Link: https://patch.msgid.link/tencent_21D781FAA4969FEACA6ABB460362B52C9409@qq.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Thomas Fourier
553017c66e atm: idt77252: Add missing dma_map_error()
[ Upstream commit c4890963350dcf4e9a909bae23665921fba4ad27 ]

The DMA map functions can fail and should be tested for errors.

Signed-off-by: Thomas Fourier <fourier.thomas@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250624064148.12815-3-fourier.thomas@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Somnath Kotur
e260f4d493 bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
[ Upstream commit 3cdf199d4755d477972ee87110b2aebc88b3cfad ]

When transmitting an XDP_REDIRECT packet, call dma_unmap_len_set()
with the proper length instead of 0.  This bug triggers this warning
on a system with IOMMU enabled:

WARNING: CPU: 36 PID: 0 at drivers/iommu/dma-iommu.c:842 __iommu_dma_unmap+0x159/0x170
RIP: 0010:__iommu_dma_unmap+0x159/0x170
Code: a8 00 00 00 00 48 c7 45 b0 00 00 00 00 48 c7 45 c8 00 00 00 00 48 c7 45 a0 ff ff ff ff 4c 89 45
b8 4c 89 45 c0 e9 77 ff ff ff <0f> 0b e9 60 ff ff ff e8 8b bf 6a 00 66 66 2e 0f 1f 84 00 00 00 00
RSP: 0018:ff22d31181150c88 EFLAGS: 00010206
RAX: 0000000000002000 RBX: 00000000e13a0000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: ff22d31181150cf0 R08: ff22d31181150ca8 R09: 0000000000000000
R10: 0000000000000000 R11: ff22d311d36c9d80 R12: 0000000000001000
R13: ff13544d10645010 R14: ff22d31181150c90 R15: ff13544d0b2bac00
FS: 0000000000000000(0000) GS:ff13550908a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005be909dacff8 CR3: 0008000173408003 CR4: 0000000000f71ef0
PKRU: 55555554
Call Trace:
<IRQ>
? show_regs+0x6d/0x80
? __warn+0x89/0x160
? __iommu_dma_unmap+0x159/0x170
? report_bug+0x17e/0x1b0
? handle_bug+0x46/0x90
? exc_invalid_op+0x18/0x80
? asm_exc_invalid_op+0x1b/0x20
? __iommu_dma_unmap+0x159/0x170
? __iommu_dma_unmap+0xb3/0x170
iommu_dma_unmap_page+0x4f/0x100
dma_unmap_page_attrs+0x52/0x220
? srso_alias_return_thunk+0x5/0xfbef5
? xdp_return_frame+0x2e/0xd0
bnxt_tx_int_xdp+0xdf/0x440 [bnxt_en]
__bnxt_poll_work_done+0x81/0x1e0 [bnxt_en]
bnxt_poll+0xd3/0x1e0 [bnxt_en]

Fixes: f18c2b77b2 ("bnxt_en: optimized XDP_REDIRECT support")
Signed-off-by: Somnath Kotur <somnath.kotur@broadcom.com>
Signed-off-by: Michael Chan <michael.chan@broadcom.com>
Link: https://patch.msgid.link/20250710213938.1959625-4-michael.chan@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Shravya KN
2da77aa6a5 bnxt_en: Fix DCB ETS validation
[ Upstream commit b74c2a2e9cc471e847abd87e50a2354c07e02040 ]

In bnxt_ets_validate(), the code incorrectly loops over all possible
traffic classes to check and add the ETS settings.  Fix it to loop
over the configured traffic classes only.

The unconfigured traffic classes will default to TSA_ETS with 0
bandwidth.  Looping over these unconfigured traffic classes may
cause the validation to fail and trigger this error message:

"rejecting ETS config starving a TC\n"

The .ieee_setets() will then fail.

Fixes: 7df4ae9fe8 ("bnxt_en: Implement DCBNL to support host-based DCBX.")
Reviewed-by: Sreekanth Reddy <sreekanth.reddy@broadcom.com>
Signed-off-by: Shravya KN <shravya.k-n@broadcom.com>
Signed-off-by: Michael Chan <michael.chan@broadcom.com>
Link: https://patch.msgid.link/20250710213938.1959625-2-michael.chan@broadcom.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Sean Nyekjaer
6807ef101b can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level
[ Upstream commit 58805e9cbc6f6a28f35d90e740956e983a0e036e ]

Downgrade the "msg lost in rx" message to debug level, to prevent
flooding the kernel log with error messages.

Fixes: e0d1f4816f ("can: m_can: add Bosch M_CAN controller support")
Reviewed-by: Vincent Mailhol <mailhol.vincent@wanadoo.fr>
Signed-off-by: Sean Nyekjaer <sean@geanix.com>
Link: https://patch.msgid.link/20250711-mcan_ratelimit-v3-1-7413e8e21b84@geanix.com
[mkl: enhance commit message]
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:05 +02:00
Oleksij Rempel
7c0beeab3a net: phy: microchip: limit 100M workaround to link-down events on LAN88xx
[ Upstream commit dd4360c0e8504f2f7639c7f5d07c93cfd6a98333 ]

Restrict the 100Mbit forced-mode workaround to link-down transitions
only, to prevent repeated link reset cycles in certain configurations.

The workaround was originally introduced to improve signal reliability
when switching cables between long and short distances. It temporarily
forces the PHY into 10 Mbps before returning to 100 Mbps.

However, when used with autonegotiating link partners (e.g., Intel i350),
executing this workaround on every link change can confuse the partner
and cause constant renegotiation loops. This results in repeated link
down/up transitions and the PHY never reaching a stable state.

Limit the workaround to only run during the PHY_NOLINK state. This ensures
it is triggered only once per link drop, avoiding disruptive toggling
while still preserving its intended effect.

Note: I am not able to reproduce the original issue that this workaround
addresses. I can only confirm that 100 Mbit mode works correctly in my
test setup. Based on code inspection, I assume the workaround aims to
reset some internal state machine or signal block by toggling speeds.
However, a PHY reset is already performed earlier in the function via
phy_init_hw(), which may achieve a similar effect. Without a reproducer,
I conservatively keep the workaround but restrict its conditions.

Fixes: e57cf3639c32 ("net: lan78xx: fix accessing the LAN7800's internal phy specific registers from the MAC driver")
Signed-off-by: Oleksij Rempel <o.rempel@pengutronix.de>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20250709130753.3994461-3-o.rempel@pengutronix.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Kito Xu
b92bedf71f net: appletalk: Fix device refcount leak in atrtr_create()
[ Upstream commit 711c80f7d8b163d3ecd463cd96f07230f488e750 ]

When updating an existing route entry in atrtr_create(), the old device
reference was not being released before assigning the new device,
leading to a device refcount leak. Fix this by calling dev_put() to
release the old device reference before holding the new one.

Fixes: c7f905f0f6 ("[ATALK]: Add missing dev_hold() to atrtr_create().")
Signed-off-by: Kito Xu <veritas501@foxmail.com>
Link: https://patch.msgid.link/tencent_E1A26771CDAB389A0396D1681A90A49E5D09@qq.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Wang Jinchao
d8a6853d00 md/raid1: Fix stack memory use after return in raid1_reshape
[ Upstream commit d67ed2ccd2d1dcfda9292c0ea8697a9d0f2f0d98 ]

In the raid1_reshape function, newpool is
allocated on the stack and assigned to conf->r1bio_pool.
This results in conf->r1bio_pool.wait.head pointing
to a stack address.
Accessing this address later can lead to a kernel panic.

Example access path:

raid1_reshape()
{
	// newpool is on the stack
	mempool_t newpool, oldpool;
	// initialize newpool.wait.head to stack address
	mempool_init(&newpool, ...);
	conf->r1bio_pool = newpool;
}

raid1_read_request() or raid1_write_request()
{
	alloc_r1bio()
	{
		mempool_alloc()
		{
			// if pool->alloc fails
			remove_element()
			{
				--pool->curr_nr;
			}
		}
	}
}

mempool_free()
{
	if (pool->curr_nr < pool->min_nr) {
		// pool->wait.head is a stack address
		// wake_up() will try to access this invalid address
		// which leads to a kernel panic
		return;
		wake_up(&pool->wait);
	}
}

Fix:
reinit conf->r1bio_pool.wait after assigning newpool.

Fixes: afeee514ce ("md: convert to bioset_init()/mempool_init()")
Signed-off-by: Wang Jinchao <wangjinchao600@gmail.com>
Reviewed-by: Yu Kuai <yukuai3@huawei.com>
Link: https://lore.kernel.org/linux-raid/20250612112901.3023950-1-wangjinchao600@gmail.com
Signed-off-by: Yu Kuai <yukuai3@huawei.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Daniil Dulov
c1958270de wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
[ Upstream commit 74b1ec9f5d627d2bdd5e5b6f3f81c23317657023 ]

There is a potential NULL pointer dereference in zd_mac_tx_to_dev(). For
example, the following is possible:

    	T0			    		T1
zd_mac_tx_to_dev()
  /* len == skb_queue_len(q) */
  while (len > ZD_MAC_MAX_ACK_WAITERS) {

					  filter_ack()
					    spin_lock_irqsave(&q->lock, flags);
					    /* position == skb_queue_len(q) */
					    for (i=1; i<position; i++)
				    	      skb = __skb_dequeue(q)

					    if (mac->type == NL80211_IFTYPE_AP)
					      skb = __skb_dequeue(q);
					    spin_unlock_irqrestore(&q->lock, flags);

    skb_dequeue() -> NULL

Since there is a small gap between checking skb queue length and skb being
unconditionally dequeued in zd_mac_tx_to_dev(), skb_dequeue() can return NULL.
Then the pointer is passed to zd_mac_tx_status() where it is dereferenced.

In order to avoid potential NULL pointer dereference due to situations like
above, check if skb is not NULL before passing it to zd_mac_tx_status().

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 459c51ad6e ("zd1211rw: port to mac80211")
Signed-off-by: Daniil Dulov <d.dulov@aladdin.ru>
Link: https://patch.msgid.link/20250626114619.172631-1-d.dulov@aladdin.ru
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Christian König
b96d700a2a dma-buf: fix timeout handling in dma_resv_wait_timeout v2
[ Upstream commit 2b95a7db6e0f75587bffddbb490399cbb87e4985 ]

Even the kerneldoc says that with a zero timeout the function should not
wait for anything, but still return 1 to indicate that the fences are
signaled now.

Unfortunately that isn't what was implemented, instead of only returning
1 we also waited for at least one jiffies.

Fix that by adjusting the handling to what the function is actually
documented to do.

v2: improve code readability

Reported-by: Marek Olšák <marek.olsak@amd.com>
Reported-by: Lucas Stach <l.stach@pengutronix.de>
Signed-off-by: Christian König <christian.koenig@amd.com>
Reviewed-by: Lucas Stach <l.stach@pengutronix.de>
Cc: <stable@vger.kernel.org>
Link: https://lore.kernel.org/r/20250129105841.1806-1-christian.koenig@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Nilton Perim Neto
221244b0bd Input: xpad - support Acer NGR 200 Controller
[ Upstream commit 22c69d786ef8fb789c61ca75492a272774221324 ]

Add the NGR 200 Xbox 360 to the list of recognized controllers.

Signed-off-by: Nilton Perim Neto <niltonperimneto@gmail.com>
Link: https://lore.kernel.org/r/20250608060517.14967-1-niltonperimneto@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Vicki Pfau
6edf13f159 Input: xpad - add VID for Turtle Beach controllers
[ Upstream commit 1999a6b12a3b5c8953fc9ec74863ebc75a1b851d ]

This adds support for the Turtle Beach REACT-R and Recon Xbox controllers

Signed-off-by: Vicki Pfau <vi@endrift.com>
Link: https://lore.kernel.org/r/20230225012147.276489-4-vi@endrift.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Stable-dep-of: 22c69d786ef8 ("Input: xpad - support Acer NGR 200 Controller")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Matt Reynolds
f01afc1e46 Input: xpad - add support for Amazon Game Controller
[ Upstream commit 05665cef4b745cb46b1d1b8e96deaa25464092d3 ]

The Amazon Luna controller (product name "Amazon Game Controller") behaves
like an Xbox 360 controller when connected over USB.

Signed-off-by: Matt Reynolds <mattreynolds@chromium.org>
Reviewed-by: Harry Cutts <hcutts@chromium.org>
Link: https://lore.kernel.org/r/20210429103548.1.If5f9a44cb81e25b9350f7c6c0b3c88b4ecd81166@changeid
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Stable-dep-of: 22c69d786ef8 ("Input: xpad - support Acer NGR 200 Controller")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Trond Myklebust
5f5239363c NFSv4/flexfiles: Fix handling of NFS level errors in I/O
[ Upstream commit 38074de35b015df5623f524d6f2b49a0cd395c40 ]

Allow the flexfiles error handling to recognise NFS level errors (as
opposed to RPC level errors) and handle them separately. The main
motivator is the NFSERR_PERM errors that get returned if the NFS client
connects to the data server through a port number that is lower than
1024. In that case, the client should disconnect and retry a READ on a
different data server, or it should retry a WRITE after reconnecting.

Reviewed-by: Tigran Mkrtchyan <tigran.mkrtchyan@desy.de>
Fixes: d67ae825a5 ("pnfs/flexfiles: Add the FlexFile Layout Driver")
Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
Signed-off-by: Anna Schumaker <anna.schumaker@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:04 +02:00
Tigran Mkrtchyan
9b6f73ae10 flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes
[ Upstream commit e3e3775392f3f0f3e3044f8c162bf47858e01759 ]

On NFS4ERR_DELAY nfs slient updates its stats, but misses for
flexfiles v4.1 DSes.

Signed-off-by: Tigran Mkrtchyan <tigran.mkrtchyan@desy.de>
Signed-off-by: Anna Schumaker <anna.schumaker@oracle.com>
Stable-dep-of: 38074de35b01 ("NFSv4/flexfiles: Fix handling of NFS level errors in I/O")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:03 +02:00
Patrisious Haddad
c60a54b3b4 RDMA/mlx5: Fix vport loopback for MPV device
[ Upstream commit a9a9e68954f29b1e197663f76289db4879fd51bb ]

Always enable vport loopback for both MPV devices on driver start.

Previously in some cases related to MPV RoCE, packets weren't correctly
executing loopback check at vport in FW, since it was disabled.
Due to complexity of identifying such cases for MPV always enable vport
loopback for both GVMIs when binding the slave to the master port.

Fixes: 0042f9e458 ("RDMA/mlx5: Enable vport loopback when user context or QP mandate")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Mark Bloch <mbloch@nvidia.com>
Link: https://patch.msgid.link/d4298f5ebb2197459e9e7221c51ecd6a34699847.1750064969.git.leon@kernel.org
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-07-17 18:25:03 +02:00
Kuniyuki Iwashima
07100f3ba5 netlink: Fix rmem check in netlink_broadcast_deliver().
commit a3c4a125ec725cefb40047eb05ff9eafd57830b4 upstream.

We need to allow queuing at least one skb even when skb is
larger than sk->sk_rcvbuf.

The cited commit made a mistake while converting a condition
in netlink_broadcast_deliver().

Let's correct the rmem check for the allow-one-skb rule.

Fixes: ae8f160e7eb24 ("netlink: Fix wraparounds of sk->sk_rmem_alloc.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250711053208.2965945-1-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:03 +02:00
Jakub Kicinski
23791e9242 netlink: make sure we allow at least one dump skb
commit a215b5723922f8099078478122f02100e489cb80 upstream.

Commit under Fixes tightened up the memory accounting for Netlink
sockets. Looks like the accounting is too strict for some existing
use cases, Marek reported issues with nl80211 / WiFi iw CLI.

To reduce number of iterations Netlink dumps try to allocate
messages based on the size of the buffer passed to previous
recvmsg() calls. If user space uses a larger buffer in recvmsg()
than sk_rcvbuf we will allocate an skb we won't be able to queue.

Make sure we always allow at least one skb to be queued.
Same workaround is already present in netlink_attachskb().
Alternative would be to cap the allocation size to
  rcvbuf - rmem_alloc
but as I said, the workaround is already present in other places.

Reported-by: Marek Szyprowski <m.szyprowski@samsung.com>
Link: https://lore.kernel.org/9794af18-4905-46c6-b12c-365ea2f05858@samsung.com
Fixes: ae8f160e7eb2 ("netlink: Fix wraparounds of sk->sk_rmem_alloc.")
Tested-by: Marek Szyprowski <m.szyprowski@samsung.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20250711001121.3649033-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:03 +02:00
Uwe Kleine-König
2a668b1707 pwm: mediatek: Ensure to disable clocks in error path
commit 505b730ede7f5c4083ff212aa955155b5b92e574 upstream.

After enabling the clocks each error path must disable the clocks again.
One of them failed to do so. Unify the error paths to use goto to make it
harder for future changes to add a similar bug.

Fixes: 7ca59947b5fc ("pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config()")
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Link: https://lore.kernel.org/r/20250704172728.626815-2-u.kleine-koenig@baylibre.com
Cc: stable@vger.kernel.org
[ukleinek: backported to 5.15.y]
Signed-off-by: Uwe Kleine-König <ukleinek@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:03 +02:00
Rafael J. Wysocki
e0098a1193 Revert "ACPI: battery: negate current when discharging"
commit de1675de39aa945bad5937d1fde4df3682670639 upstream.

Revert commit 234f71555019 ("ACPI: battery: negate current when
discharging") breaks not one but several userspace implementations
of battery monitoring: Steam and MangoHud. Perhaps it breaks more,
but those are the two that have been tested.

Reported-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Closes: https://lore.kernel.org/linux-acpi/87C1B2AF-D430-4568-B620-14B941A8ABA4@linux.dev/
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-07-17 18:25:03 +02:00