Commit graph

920,145 commits

Author SHA1 Message Date
QCTECMDR Service
bb60c83293 Merge "Merge android11-5.4.289(4c8fb32) into msm-5.4" 2025-03-26 22:23:45 -07:00
kamasali Satyanarayan
f2c008f940 Merge android11-5.4.289(4c8fb32) into msm-5.4
* remotes/origin/tmp-4c8fb32:
  ANDROID: GKI: add Trimble symbol list
  UPSTREAM: selinux: ignore unknown extended permissions
  ANDROID: ABI: Update allowed list for galaxy
  Revert "netfilter: Replace zero-length array with flexible-array member"
  Revert "tracing: Constify string literal data member in struct trace_event_call"
  Revert "skb_expand_head() adjust skb->truesize incorrectly"
  Linux 5.4.289
  ftrace: use preempt_enable/disable notrace macros to avoid double fault
  mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()
  drm: adv7511: Drop dsi single lane support
  net/sctp: Prevent autoclose integer overflow in sctp_association_init()
  sky2: Add device ID 11ab:4373 for Marvell 88E8075
  pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking
  RDMA/uverbs: Prevent integer overflow issue
  modpost: fix the missed iteration for the max bit in do_input()
  modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host
  ARC: build: Try to guess GCC variant of cross compiler
  irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base
  net: usb: qmi_wwan: add Telit FE910C04 compositions
  bpf: fix potential error return
  sound: usb: format: don't warn that raw DSD is unsupported
  wifi: mac80211: wake the queues in case of failure in resume
  ila: serialize calls to nf_register_net_hooks()
  af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
  af_packet: fix vlan_get_tci() vs MSG_PEEK
  ALSA: usb-audio: US16x08: Initialize array before use
  net: llc: reset skb->transport_header
  netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext
  netfilter: Replace zero-length array with flexible-array member
  netrom: check buffer length before accessing it
  drm/bridge: adv7511_audio: Update Audio InfoFrame properly
  drm: bridge: adv7511: Enable SPDIF DAI
  RDMA/bnxt_re: Fix max_qp_wrs reported
  RDMA/bnxt_re: Fix reporting hw_ver in query_device
  RDMA/bnxt_re: Add check for path mtu in modify_qp
  RDMA/mlx5: Enforce same type port association for multiport RoCE
  net/mlx5: Make API mlx5_core_is_ecpf accept const pointer
  IB/mlx5: Introduce and use mlx5_core_is_vf()
  Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
  selinux: ignore unknown extended permissions
  ipv6: prevent possible UAF in ip6_xmit()
  skb_expand_head() adjust skb->truesize incorrectly
  btrfs: avoid monopolizing a core when activating a swap file
  tracing: Constify string literal data member in struct trace_event_call
  bpf: fix recursive lock when verdict program return SK_PASS
  ipv6: fix possible UAF in ip6_finish_output2()
  ipv6: use skb_expand_head in ip6_xmit
  ipv6: use skb_expand_head in ip6_finish_output2
  skbuff: introduce skb_expand_head()
  MIPS: Probe toolchain support of -msym32
  epoll: Add synchronous wakeup support for ep_poll_callback
  virtio-blk: don't keep queue frozen during system suspend
  scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver load time
  platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
  regmap: Use correct format specifier for logging range errors
  scsi: megaraid_sas: Fix for a potential deadlock
  scsi: qla1280: Fix hw revision numbering for ISP1020/1040
  tracing/kprobe: Make trace_kprobe's module callback called after jump_label update
  mtd: rawnand: fix double free in atmel_pmecc_create_user()
  dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
  dmaengine: mv_xor: fix child node refcount handling in early exit
  phy: core: Fix that API devm_phy_destroy() fails to destroy the phy
  phy: core: Fix that API devm_phy_put() fails to release the phy
  phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()
  phy: core: Fix an OF node refcount leakage in _of_phy_get()
  mtd: diskonchip: Cast an operand to prevent potential overflow
  nfsd: restore callback functionality for NFSv4.0
  bpf: Check negative offsets in __bpf_skb_min_len()
  media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
  of: Fix refcount leakage for OF node returned by __of_get_dma_parent()
  of: Fix error path in of_parse_phandle_with_args_map()
  udmabuf: also check for F_SEAL_FUTURE_WRITE
  nilfs2: prevent use of deleted inode
  of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one()
  NFS/pnfs: Fix a live lock between recalled layouts and layoutget
  btrfs: tree-checker: reject inline extent items with 0 ref count
  zram: refuse to use zero sized block device as backing device
  sh: clk: Fix clk_enable() to return 0 on NULL clk
  USB: serial: option: add Telit FE910C04 rmnet compositions
  USB: serial: option: add MediaTek T7XX compositions
  USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
  USB: serial: option: add MeiG Smart SLM770A
  USB: serial: option: add TCL IK512 MBIM & ECM
  efivarfs: Fix error on non-existent file
  i2c: riic: Always round-up when calculating bus period
  chelsio/chtls: prevent potential integer overflow on 32bit
  mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk
  netfilter: ipset: Fix for recursive locking warning
  net: ethernet: bgmac-platform: fix an OF node reference leak
  net: hinic: Fix cleanup in create_rxqs/txqs()
  ionic: use ee->offset when returning sprom data
  net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
  erofs: fix incorrect symlink detection in fast symlink
  erofs: fix order >= MAX_ORDER warning due to crafted negative i_size
  drm/i915: Fix memory leak by correcting cache object name in error handler
  i2c: pnx: Fix timeout in wait functions
  PCI: Add ACS quirk for Broadcom BCM5760X NIC
  ALSA: usb: Fix UBSAN warning in parse_audio_unit()
  PCI/AER: Disable AER service on suspend
  usb: dwc2: gadget: Don't write invalid mapped sg entries into dma_desc with iommu enabled
  net: sched: fix ordering of qlen adjustment
  UPSTREAM: ALSA: usb-audio: Fix a DMA to stack memory bug
  Linux 5.4.288
  ALSA: usb-audio: Fix a DMA to stack memory bug
  xen/netfront: fix crash when removing device
  tracing/kprobes: Skip symbol counting logic for module symbols in create_local_trace_kprobe()
  KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status
  blk-iocost: Avoid using clamp() on inuse in __propagate_weights()
  blk-iocost: fix weight updates of inner active iocgs
  blk-iocost: clamp inuse and skip noops in __propagate_weights()
  ACPICA: events/evxfregn: don't release the ContextMutex that was never acquired
  net/sched: netem: account for backlog updates from child qdisc
  qca_spi: Make driver probing reliable
  qca_spi: Fix clock speed for multiple QCA7000
  ACPI: resource: Fix memory resource type union access
  net: lapb: increase LAPB_HEADER_LEN
  tipc: fix NULL deref in cleanup_bearer()
  batman-adv: Do not let TT changes list grows indefinitely
  batman-adv: Remove uninitialized data in full table TT response
  batman-adv: Do not send uninitialized TT changes
  bpf, sockmap: Fix update element with same
  xfs: don't drop errno values when we fail to ficlone the entire range
  usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer
  usb: ehci-hcd: fix call balance of clocks handling routines
  usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature
  ata: sata_highbank: fix OF node reference leak in highbank_initialize_phys()
  usb: host: max3421-hcd: Correctly abort a USB request.
  UPSTREAM: ALSA: usb-audio: Fix out of bounds reads when finding clock sources
  UPSTREAM: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
  Revert "cgroup: Make operations on the cgroup root_list RCU safe"
  Revert "cgroup: Move rcu_head up near the top of cgroup_root"
  Linux 5.4.287
  bpf, xdp: Update devmap comments to reflect napi/rcu usage
  ALSA: usb-audio: Fix out of bounds reads when finding clock sources
  PCI: rockchip-ep: Fix address translation unit programming
  Revert "drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()"
  modpost: Add .irqentry.text to OTHER_SECTIONS
  ocfs2: Revert "ocfs2: fix the la space leak when unmounting an ocfs2 volume"
  jffs2: Fix rtime decompressor
  jffs2: Prevent rtime decompress memory corruption
  KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
  KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
  KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
  perf/x86/intel/pt: Fix buffer full but size is 0 case
  Revert "unicode: Don't special case ignorable code points"
  bpf: fix OOB devmap writes when deleting elements
  xdp: Simplify devmap cleanup
  misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
  powerpc/prom_init: Fixup missing powermac #size-cells
  usb: chipidea: udc: handle USB Error Interrupt if IOC not set
  i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock
  PCI: Add ACS quirk for Wangxun FF5xxx NICs
  PCI: Add 'reset_subordinate' to reset hierarchy below bridge
  f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
  nvdimm: rectify the illogical code within nd_dax_probe()
  pinctrl: qcom-pmic-gpio: add support for PM8937
  scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset
  scsi: st: Don't modify unknown block number in MTIOCGET
  leds: class: Protect brightness_show() with led_cdev->led_access mutex
  tracing: Use atomic64_inc_return() in trace_clock_counter()
  netpoll: Use rcu_access_pointer() in __netpoll_setup
  net/neighbor: clear error in case strict check is not set
  rocker: fix link status detection in rocker_carrier_init()
  ASoC: hdmi-codec: reorder channel allocation list
  Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables
  wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()
  wifi: ipw2x00: libipw_rx_any(): fix bad alignment
  drm/amdgpu: set the right AMDGPU sg segment limitation
  jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
  jfs: fix array-index-out-of-bounds in jfs_readdir
  jfs: fix shift-out-of-bounds in dbSplit
  jfs: array-index-out-of-bounds fix in dtReadFirst
  wifi: ath5k: add PCI ID for Arcadyan devices
  wifi: ath5k: add PCI ID for SX76X
  net: inet6: do not leave a dangling sk pointer in inet6_create()
  net: inet: do not leave a dangling sk pointer in inet_create()
  net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
  net: af_can: do not leave a dangling sk pointer in can_create()
  Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()
  af_packet: avoid erroring out after sock_init_data() in packet_create()
  net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
  net: ethernet: fs_enet: Use %pa to format resource_size_t
  net: fec_mpc52xx_phy: Use %pa to format resource_size_t
  samples/bpf: Fix a resource leak
  drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check()
  drm/mcde: Enable module autoloading
  drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
  media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108
  media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera
  s390/cpum_sf: Handle CPU hotplug remove during sampling
  mmc: core: Further prevent card detect during shutdown
  regmap: detach regmap from dev on regmap_exit
  dma-buf: fix dma_fence_array_signaled v4
  bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again
  nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()
  scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt
  scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
  scsi: qla2xxx: Fix NVMe and NPIV connect issue
  ocfs2: update seq_file index in ocfs2_dlm_seq_next
  tracing: Fix cmp_entries_dup() to respect sort() comparison rules
  HID: wacom: fix when get product name maybe null pointer
  bpf: Fix exact match conditions in trie_get_next_key()
  bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie
  ocfs2: free inode when ocfs2_get_init_inode() fails
  spi: mpc52xx: Add cancel_work_sync before module remove
  tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
  drm/sti: Add __iomem for mixer_dbg_mxn's parameter
  gpio: grgpio: Add NULL check in grgpio_probe
  gpio: grgpio: use a helper variable to store the address of ofdev->dev
  crypto: x86/aegis128 - access 32-bit arguments as 32-bit
  x86/asm: Reorder early variables
  xen: Fix the issue of resource not being properly released in xenbus_dev_probe()
  xen/xenbus: fix locking
  xenbus/backend: Protect xenbus callback with lock
  xenbus/backend: Add memory pressure handler callback
  xen/xenbus: reference count registered modules
  netfilter: nft_set_hash: skip duplicated elements pending gc run
  netfilter: ipset: Hold module reference while requesting a module
  igb: Fix potential invalid memory access in igb_init_module()
  net/qed: allow old cards not supporting "num_images" to work
  tipc: Fix use-after-free of kernel socket in cleanup_bearer().
  tipc: add new AEAD key structure for user API
  tipc: enable creating a "preliminary" node
  tipc: add reference counter to bearer
  dccp: Fix memory leak in dccp_feat_change_recv
  net/ipv6: release expired exception dst cached in socket
  can: j1939: j1939_session_new(): fix skb reference counting
  net/sched: tbf: correct backlog statistic for GSO packets
  netfilter: x_tables: fix LED ID check in led_tg_check()
  ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init()
  can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
  can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL
  watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart()
  iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
  drm/etnaviv: flush shader L1 cache after user commandstream
  nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
  nfsd: make sure exp active before svc_export_show
  dm thin: Add missing destroy_work_on_stack()
  i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()
  util_macros.h: fix/rework find_closest() macros
  ad7780: fix division by zero in ad7780_write_raw()
  clk: qcom: gcc-qcs404: fix initial rate of GPLL3
  ftrace: Fix regression with module command in stack_trace_filter
  ovl: Filter invalid inodes with missing lookup function
  media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()
  media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate()
  media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled
  media: ts2020: fix null-ptr-deref in ts2020_probe()
  media: i2c: tc358743: Fix crash in the probe error path when using polling
  btrfs: ref-verify: fix use-after-free after invalid ref action
  quota: flush quota_release_work upon quota writeback
  ASoC: fsl_micfil: fix the naming style for mask definition
  sh: intc: Fix use-after-free bug in register_intc_controller()
  sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
  SUNRPC: Replace internal use of SOCKWQ_ASYNC_NOSPACE
  SUNRPC: correct error code comment in xs_tcp_setup_socket()
  modpost: remove incorrect code in do_eisa_entry()
  rtc: ab-eoz9: don't fail temperature reads on undervoltage notification
  9p/xen: fix release of IRQ
  9p/xen: fix init sequence
  block: return unsigned int from bdev_io_min
  jffs2: fix use of uninitialized variable
  ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
  ubi: fastmap: Fix duplicate slab cache names while attaching
  ubifs: Correct the total block count by deducting journal reservation
  rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
  rtc: abx80x: Fix WDT bit position of the status register
  rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
  NFSv4.0: Fix a use-after-free problem in the asynchronous open()
  um: Always dump trace for specified task in show_stack
  um: Clean up stacktrace dump
  um: add show_stack_loglvl()
  um/sysrq: remove needless variable sp
  um: Fix the return value of elf_core_copy_task_fpregs
  um: Fix potential integer overflow during physmem setup
  rpmsg: glink: Propagate TX failures in intentless mode as well
  SUNRPC: make sure cache entry active before cache_show
  NFSD: Prevent a potential integer overflow
  lib: string_helpers: silence snprintf() output truncation warning
  usb: dwc3: gadget: Fix checking for number of TRBs left
  ALSA: hda/realtek: Apply quirk for Medion E15433
  ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max
  ALSA: hda/realtek: Set PCBeep to default value for ALC274
  ALSA: hda/realtek: Update ALC225 depop procedure
  media: wl128x: Fix atomicity violation in fmc_send_cmd()
  HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
  block: fix ordering between checking BLK_MQ_S_STOPPED request adding
  arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled
  sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
  um: vector: Do not use drvdata in release
  serial: 8250: omap: Move pm_runtime_get_sync
  um: net: Do not use drvdata in release
  um: ubd: Do not use drvdata in release
  ubi: wl: Put source PEB into correct list if trying locking LEB failed
  spi: Fix acpi deferred irq probe
  netfilter: ipset: add missing range check in bitmap_ip_uadt
  Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon exit"
  serial: sh-sci: Clean sci_ports[0] after at earlycon exit
  Revert "usb: gadget: composite: fix OS descriptors w_value logic"
  Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
  tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
  comedi: Flush partial mappings in error case
  PCI: Fix use-after-free of slot->bus on hot remove
  ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
  jfs: xattr: check invalid xattr size more strictly
  ext4: fix FS_IOC_GETFSMAP handling
  ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
  ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
  soc: qcom: socinfo: fix revision check in qcom_socinfo_probe()
  cgroup: Move rcu_head up near the top of cgroup_root
  cgroup: Make operations on the cgroup root_list RCU safe
  usb: ehci-spear: fix call balance of sehci clk handling routines
  apparmor: fix 'Do simple duplicate message elimination'
  staging: greybus: uart: clean up TIOCGSERIAL
  misc: apds990x: Fix missing pm_runtime_disable()
  USB: chaoskey: Fix possible deadlock chaoskey_list_lock
  USB: chaoskey: fail open after removal
  usb: yurex: make waiting on yurex_write interruptible
  usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
  ipmr: fix tables suspicious RCU usage
  ipmr: convert /proc handlers to rcu_read_lock()
  net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
  marvell: pxa168_eth: fix call balance of pep->clk handling routines
  net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration
  tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
  net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
  power: supply: core: Remove might_sleep() from power_supply_put()
  vfio/pci: Properly hide first-in-list PCIe extended capability
  NFSD: Fix nfsd4_shutdown_copy()
  NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
  NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
  rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
  rpmsg: glink: Fix GLINK command prefix
  rpmsg: glink: Send READ_NOTIFY command in FIFO full case
  rpmsg: glink: Add TX_DATA_CONT command while sending
  perf trace: Avoid garbage when not printing a syscall's arguments
  perf trace: Do not lose last events in a race
  m68k: coldfire/device.c: only build FEC when HW macros are defined
  m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x
  PCI: cpqphp: Fix PCIBIOS_* return value confusion
  PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
  perf probe: Correct demangled symbols in C++ program
  perf cs-etm: Don't flush when packet_queue fills up
  clk: clk-axi-clkgen: make sure to enable the AXI bus clock
  clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand
  dt-bindings: clock: axi-clkgen: include AXI clk
  dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format
  fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
  fbdev/sh7760fb: Alloc DMA memory from hardware device
  powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static
  ocfs2: fix uninitialized value in ocfs2_file_read_iter()
  scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
  scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()
  scsi: fusion: Remove unused variable 'rc'
  scsi: bfa: Fix use-after-free in bfad_im_module_exit()
  mfd: rt5033: Fix missing regmap_del_irq_chip()
  RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
  mtd: rawnand: atmel: Fix possible memory leak
  cpufreq: loongson2: Unregister platform_driver on failure
  mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
  mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
  mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
  mfd: intel_soc_pmic_bxtwc: Use dev_err_probe()
  mfd: da9052-spi: Change read-mask to write-mask
  mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race
  powerpc/vdso: Flag VDSO64 entry points as functions
  trace/trace_event_perf: remove duplicate samples on the first tracepoint event
  netpoll: Use rcu_access_pointer() in netpoll_poll_lock
  ALSA: 6fire: Release resources at card release
  ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
  ALSA: us122l: Use snd_card_free_when_closed() at disconnection
  net: rfkill: gpio: Add check for clk_enable()
  selftests: net: really check for bg process completion
  bpf, sockmap: Fix sk_msg_reset_curr
  bpf, sockmap: Several fixes to bpf_msg_pop_data
  bpf, sockmap: Several fixes to bpf_msg_push_data
  drm/etnaviv: hold GPU lock across perfmon sampling
  drm/etnaviv: fix power register offset on GC300
  drm/etnaviv: dump: fix sparse warnings
  drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
  drm/panfrost: Remove unused id_mask from struct panfrost_model
  wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()
  bpf: Fix the xdp_adjust_tail sample prog issue
  ASoC: fsl_micfil: fix regmap_write_bits usage
  ASoC: fsl_micfil: use GENMASK to define register bit fields
  ASoC: fsl_micfil: do not define SHIFT/MASK for single bits
  ASoC: fsl_micfil: Drop unnecessary register read
  dt-bindings: vendor-prefixes: Add NeoFidelity, Inc
  drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
  wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
  wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq()
  drm/omap: Fix locking in omap_gem_new_dmabuf()
  wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
  drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
  firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
  regmap: irq: Set lockdep class for hierarchical IRQ domains
  ARM: dts: cubieboard4: Fix DCDC5 regulator constraints
  tpm: fix signed/unsigned bug when checking event logs
  efi/tpm: Pass correct address to memblock_reserve
  mmc: mmc_spi: drop buggy snprintf()
  soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
  soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
  time: Fix references to _msecs_to_jiffies() handling of values
  crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
  crypto: bcm - add error check in the ahash_hmac_init function
  crypto: cavium - Fix the if condition to exit loop after timeout
  crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY
  EDAC/fsl_ddr: Fix bad bit shift operations
  EDAC/bluefield: Fix potential integer overflow
  firmware: google: Unregister driver_info on failure
  firmware: google: Unregister driver_info on failure and exit in gsmi
  hfsplus: don't query the device logical block size multiple times
  s390/syscalls: Avoid creation of arch/arch/ directory
  acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()
  m68k: mvme147: Reinstate early console
  m68k: mvme16x: Add and use "mvme16x.h"
  m68k: mvme147: Fix SCSI controller IRQ numbers
  nvme-pci: fix freeing of the HMB descriptor table
  initramfs: avoid filename buffer overrun
  mips: asm: fix warning when disabling MIPS_FP_SUPPORT
  x86/xen/pvh: Annotate indirect branch as safe
  nvme: fix metadata handling in nvme-passthrough
  NFSD: Force all NFSv4.2 COPY requests to be synchronous
  cifs: Fix buffer overflow when parsing NFS reparse points
  ipmr: Fix access to mfc_cache_list without lock held
  proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
  ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div()
  ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate()
  regulator: rk808: Add apply_bit for BUCK3 on RK809
  soc: qcom: Add check devm_kasprintf() returned value
  net: usb: qmi_wwan: add Quectel RG650V
  x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB
  ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
  selftests/watchdog-test: Fix system accidentally reset after watchdog-test
  mac80211: fix user-power when emulating chanctx
  ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet
  mm: revert "mm: shmem: fix data-race in shmem_getattr()"
  kbuild: Use uname for LINUX_COMPILE_HOST detection
  media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set
  Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
  nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
  ocfs2: fix UBSAN warning in ocfs2_verify_volume()
  nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
  KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
  ocfs2: uncache inode which has failed entering the group
  net/mlx5e: kTLS, Fix incorrect page refcounting
  net/mlx5: fs, lock FTE when checking if active
  netlink: terminate outstanding dump on socket close
  Revert "UPSTREAM: unicode: Don't special case ignorable code points"
  Reapply "UPSTREAM: unicode: Don't special case ignorable code points"
  Revert "UPSTREAM: unicode: Don't special case ignorable code points"
  UPSTREAM: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
  ANDROID: add file for recording allowed ABI breaks
  Revert "spi: Fix deadlock when adding SPI controllers on SPI buses"
  Revert "spi: fix use-after-free of the add_lock mutex"
  ANDROID: declare sp_in_global outside of CONFIG_FRAME_POINTER
  BACKPORT: RISC-V: Stop relying on GCC's register allocator's hueristics
  UPSTREAM: x86/percpu: Clean up percpu_add_op()
  UPSTREAM: x86/percpu: Clean up percpu_from_op()
  UPSTREAM: x86/percpu: Clean up percpu_to_op()
  UPSTREAM: x86/percpu: Introduce size abstraction macros
  BACKPORT: FROMGIT: binder: add delivered_freeze to debugfs output
  BACKPORT: FROMGIT: binder: fix memleak of proc->delivered_freeze
  FROMGIT: binder: allow freeze notification for dead nodes
  FROMGIT: binder: fix BINDER_WORK_CLEAR_FREEZE_NOTIFICATION debug logs
  FROMGIT: binder: fix BINDER_WORK_FROZEN_BINDER debug logs
  BACKPORT: FROMGIT: binder: fix freeze UAF in binder_release_work()
  FROMGIT: binder: fix OOB in binder_add_freeze_work()
  FROMGIT: binder: fix node UAF in binder_add_freeze_work()
  Linux 5.4.286
  mm: avoid leaving partial pfn mappings around in error case
  9p: fix slab cache name creation for real
  mm: add remap_pfn_range_notrack
  mm/memory.c: make remap_pfn_range() reject unaligned addr
  mm: fix ambiguous comments for better code readability
  mm: clarify a confusing comment for remap_pfn_range()
  md/raid10: improve code of mrdev in raid10_sync_request
  net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition
  fs: Fix uninitialized value issue in from_kuid and from_kgid
  powerpc/powernv: Free name on error in opal_event_init()
  sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML
  bpf: use kvzmalloc to allocate BPF verifier environment
  HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad
  9p: Avoid creating multiple slab caches with the same name
  ALSA: usb-audio: Add endianness annotations
  vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
  hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
  ftrace: Fix possible use-after-free issue in ftrace_location()
  NFSD: Fix NFSv4's PUTPUBFH operation
  ALSA: usb-audio: Add quirks for Dell WD19 dock
  ALSA: usb-audio: Support jack detection on Dell dock
  ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()
  irqchip/gic-v3: Force propagation of the active state with a read-back
  USB: serial: option: add Quectel RG650V
  USB: serial: option: add Fibocom FG132 0x0112 composition
  USB: serial: qcserial: add support for Sierra Wireless EM86xx
  USB: serial: io_edgeport: fix use after free in debug printk
  usb: musb: sunxi: Fix accessing an released usb phy
  fs/proc: fix compile warning about variable 'vmcore_mmap_ops'
  media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
  net: bridge: xmit: make sure we have at least eth header len bytes
  spi: fix use-after-free of the add_lock mutex
  spi: Fix deadlock when adding SPI controllers on SPI buses
  mtd: rawnand: protect access to rawnand devices while in suspend
  btrfs: reinitialize delayed ref list after deleting it from the list
  nfs: Fix KMSAN warning in decode_getfattr_attrs()
  dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow
  dm cache: fix potential out-of-bounds access on the first resume
  dm cache: optimize dirty bit checking with find_next_bit when resizing
  dm cache: fix out-of-bounds access to the dirty bitset when resizing
  dm cache: correct the number of origin blocks to match the target length
  drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
  drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()
  pwm: imx-tpm: Use correct MODULO value for EPWM mode
  media: v4l2-tpg: prevent the risk of a division by zero
  media: cx24116: prevent overflows on SNR calculus
  media: s5p-jpeg: prevent buffer overflows
  ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()
  media: adv7604: prevent underflow condition when reporting colorspace
  media: dvb_frontend: don't play tricks with underflow values
  media: dvbdev: prevent the risk of out of memory access
  media: stb0899_algo: initialize cfr before using it
  net: hns3: fix kernel crash when uninstalling driver
  can: c_can: fix {rx,tx}_errors statistics
  sctp: properly validate chunk size in sctp_sf_ootb()
  net: enetc: set MAC address to the VF net_device
  enetc: simplify the return expression of enetc_vf_set_mac_addr()
  security/keys: fix slab-out-of-bounds in key_task_permission
  HID: core: zero-initialize the report buffer
  ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin
  ARM: dts: rockchip: Fix the spi controller on rk3036
  ARM: dts: rockchip: drop grf reference from rk3036 hdmi
  ARM: dts: rockchip: fix rk3036 acodec node
  arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion
  arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards
  arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328
  arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator
  ANDROID: GKI: Enable SERIAL_8250_DW
  UPSTREAM: USB: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
  Revert "genetlink: hold RCU in genlmsg_mcast()"
  Revert "arm64: probes: Fix uprobes for big-endian kernels"
  Revert "arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning"
  Revert "inet: inet_defrag: prevent sk release while still in use"
  Linux 5.4.285
  mm: krealloc: Fix MTE false alarm in __do_krealloc
  mac80211: always have ieee80211_sta_restart()
  vt: prevent kernel-infoleak in con_font_get()
  Revert "drm/mipi-dsi: Set the fwnode for mipi_dsi_device"
  mm: shmem: fix data-race in shmem_getattr()
  nilfs2: fix kernel bug due to missing clearing of checked flag
  ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
  riscv: Remove unused GENERATING_ASM_OFFSETS
  nilfs2: fix potential deadlock with newly created symlinks
  staging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg()
  wifi: iwlegacy: Clear stale interrupts before resuming device
  wifi: ath10k: Fix memory leak in management tx
  wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
  Revert "driver core: Fix uevent_show() vs driver detach race"
  xhci: Fix Link TRB DMA in command ring stopped completion event
  usb: phy: Fix API devm_usb_put_phy() can not release the phy
  usbip: tools: Fix detach_port() invalid port error path
  misc: sgi-gru: Don't disable preemption in GRU driver
  net: amd: mvme147: Fix probe banner message
  firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()
  drivers/misc: ti-st: Remove unneeded variable in st_tty_open
  netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
  net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension
  net: support ip generic csum processing in skb_csum_hwoffload_help
  bpf: Fix out-of-bounds write in trie_get_next_key()
  net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
  gtp: allow -1 to be specified as file description from userspace
  gtp: simplify error handling code in 'gtp_encap_enable()'
  dt-bindings: gpu: Convert Samsung Image Rotator to dt-schema
  ASoC: cs42l51: Fix some error handling paths in cs42l51_probe()
  wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()
  wifi: iwlwifi: mvm: disconnect station vifs if recovery failed
  mac80211: Add support to trigger sta disconnect on hardware restart
  mac80211: do drv_reconfig_complete() before restarting all
  wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
  cgroup: Fix potential overflow issue when checking max_depth
  xfrm: validate new SA's prefixlen using SA family when sel.family is unset
  arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning
  selinux: improve error checking in sel_write_load()
  hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event
  ALSA: hda/realtek: Add subwoofer quirk for Acer Predator G9-593
  nilfs2: fix kernel bug due to missing clearing of buffer delay flag
  ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid detection issue
  ACPI: resource: Add LG 16T90SP to irq1_level_low_skip_override[]
  drm/amd: Guard against bad data for ATIF ACPI method
  ALSA: hda/realtek: Update default depop procedure
  ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()
  posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
  r8169: avoid unsolicited interrupts
  net: sched: fix use-after-free in taprio_change()
  net: usb: usbnet: fix name regression
  be2net: fix potential memory leak in be_xmit()
  net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
  tracing: Consider the NULL character when validating the event length
  jfs: Fix sanity check in dbMount
  udf: fix uninit-value use in udf_get_fileshortad
  drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA
  KVM: s390: gaccess: Check if guest address is in memslot
  KVM: s390: gaccess: Cleanup access to guest pages
  KVM: s390: gaccess: Refactor access address range check
  KVM: s390: gaccess: Refactor gpa and length calculation
  arm64: probes: Fix uprobes for big-endian kernels
  arm64:uprobe fix the uprobe SWBP_INSN in big-endian
  Bluetooth: bnep: fix wild-memory-access in proto_unregister
  usb: typec: altmode should keep reference to parent
  smb: client: fix OOBs when building SMB2_IOCTL request
  genetlink: hold RCU in genlmsg_mcast()
  net: systemport: fix potential memory leak in bcm_sysport_xmit()
  net: ethernet: aeroflex: fix potential memory leak in greth_start_xmit_gbit()
  macsec: don't increment counters for an unrelated SA
  drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation
  RDMA/bnxt_re: Return more meaningful error
  ipv4: give an IPv4 dev to blackhole_netdev
  RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP
  ARM: dts: bcm2837-rpi-cm3-io3: Fix HDMI hpd-gpio pin
  RDMA/bnxt_re: Fix incorrect AVID type in WQE structure
  mac80211: Fix NULL ptr deref for injected rate info
  erofs: fix lz4 inplace decompression
  nilfs2: propagate directory read errors from nilfs_find_entry()
  x86/apic: Always explicitly disarm TSC-deadline timer
  x86/resctrl: Annotate get_mem_config() functions as __init
  parport: Proper fix for array out-of-bounds access
  USB: serial: option: add Telit FN920C04 MBIM compositions
  USB: serial: option: add support for Quectel EG916Q-GL
  xhci: Fix incorrect stream context type macro
  Bluetooth: btusb: Fix regression with fake CSR controllers 0a12:0001
  Bluetooth: Remove debugfs directory on module init failure
  iio: adc: ti-ads124s08: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
  iio: proximity: mb1232: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
  iio: light: opt3001: add missing full-scale range value
  iio: hid-sensors: Fix an error handling path in _hid_sensor_set_report_latency()
  iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig
  iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in Kconfig
  iio: dac: ltc1660: add missing select REGMAP_SPI in Kconfig
  drm/vmwgfx: Handle surface check failure correctly
  blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race
  x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET
  KVM: s390: Change virtual to physical address access in diag 0x258 handler
  s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
  KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
  wifi: mac80211: fix potential key use-after-free
  mm/swapfile: skip HugeTLB pages for unuse_vma
  fat: fix uninitialized variable
  PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
  tracing/kprobes: Fix symbol counting logic by looking at modules as well
  tracing/kprobes: Return EADDRNOTAVAIL when func matches several symbols
  arm64: probes: Fix simulate_ldr*_literal()
  arm64: probes: Remove broken LDR (literal) uprobe support
  posix-clock: Fix missing timespec64 check in pc_clock_settime()
  nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error
  net: Fix an unsafe loop on the list
  hid: intel-ish-hid: Fix uninitialized variable 'rv' in ish_fw_xfer_direct_dma
  usb: storage: ignore bogus device raised by JieLi BR21 USB sound chip
  usb: xhci: Fix problem with xhci resume from suspend
  usb: dwc3: core: Stop processing of pending events if controller is halted
  Revert "usb: yurex: Replace snprintf() with the safer scnprintf() variant"
  HID: plantronics: Workaround for an unexcepted opposite volume key
  CDC-NCM: avoid overflow in sanity checking
  resource: fix region_intersects() vs add_memory_driver_managed()
  lockdep: fix deadlock issue between lockdep and rcu
  locking/lockdep: Avoid potential access of invalid memory in lock_class
  locking/lockdep: Rework lockdep_lock
  locking/lockdep: Fix bad recursion pattern
  slip: make slhc_remember() more robust against malicious packets
  ppp: fix ppp_async_encode() illegal access
  sctp: ensure sk_state is set to CLOSED if hashing fails in sctp_listen_start
  net: annotate lockless accesses to sk->sk_max_ack_backlog
  net: annotate lockless accesses to sk->sk_ack_backlog
  net: ibm: emac: mal: fix wrong goto
  net/sched: accept TCA_STAB only for root qdisc
  igb: Do not bring the device up after non-fatal error
  gpio: aspeed: Use devm_clk api to manage clock source
  gpio: aspeed: Add the flush write to ensure the write complete.
  Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change
  netfilter: br_netfilter: fix panic with metadata_dst skb
  tcp: fix tcp_enter_recovery() to zero retrans_stamp when it's safe
  tcp: fix to allow timestamp undo if no retransmits were sent
  SUNRPC: Fix integer overflow in decode_rc_list()
  ice: fix VLAN replay after reset
  RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
  fbdev: sisfb: Fix strbuf array overflow
  driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute
  tools/iio: Add memory allocation failure check for trigger_name
  virtio_pmem: Check device status before requesting flush
  usb: dwc2: Adjust the timing of USB Driver Interrupt Registration in the Crashkernel Scenario
  usb: chipidea: udc: enable suspend interrupt after usb reset
  media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()
  ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition
  PCI: Mark Creative Labs EMU20k2 INTx masking as broken
  i2c: i801: Use a different adapter-name for IDF adapters
  PCI: Add ACS quirk for Qualcomm SA8775P
  clk: bcm: bcm53573: fix OF node leak in init
  ktest.pl: Avoid false positives with grub2 skip regex
  s390/cpum_sf: Remove WARN_ON_ONCE statements
  ext4: nested locking for xattr inode
  s390/mm: Add cond_resched() to cmm_alloc/free_pages()
  s390/facility: Disable compile time optimization for decompressor code
  bpf: Check percpu map value size first
  Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal
  virtio_console: fix misc probe bugs
  tracing: Have saved_cmdlines arrays all in one allocation
  drm/crtc: fix uninitialized variable use even harder
  tracing: Remove precision vsnprintf() check from print event
  net: ethernet: cortina: Drop TSO support
  unicode: Don't special case ignorable code points
  ext4: fix inode tree inconsistency caused by ENOMEM
  ACPI: battery: Fix possible crash when unregistering a battery hook
  ACPI: battery: Simplify battery hook locking
  r8169: add tally counter fields added with RTL8125
  r8169: Fix spelling mistake: "tx_underun" -> "tx_underrun"
  clk: qcom: clk-rpmh: Fix overflow in BCM vote
  clk: qcom: rpmh: Simplify clk_rpmh_bcm_send_cmd()
  nfsd: fix delegation_blocked() to block correctly for at least 30 seconds
  nfsd: use ktime_get_seconds() for timestamps
  uprobes: fix kernel info leak via "[uprobes]" vma
  arm64: errata: Expand speculative SSBS workaround once more
  arm64: cputype: Add Neoverse-N3 definitions
  arm64: Add Cortex-715 CPU part definition
  i2c: qcom-geni: Use IRQF_NO_AUTOEN flag in request_irq()
  i2c: qcom-geni: Grow a dev pointer to simplify code
  i2c: qcom-geni: Let firmware specify irq trigger flags
  gpio: davinci: fix lazy disable
  btrfs: wait for fixup workers before stopping cleaner kthread during umount
  btrfs: fix a NULL pointer dereference when failed to start a new trasacntion
  ACPI: resource: Add Asus ExpertBook B2502CVA to irq1_level_low_skip_override[]
  ACPI: resource: Add Asus Vivobook X1704VAP to irq1_level_low_skip_override[]
  Input: adp5589-keys - fix adp5589_gpio_get_value()
  rtc: at91sam9: fix OF node leak in probe() error path
  tomoyo: fallback to realpath if symlink's pathname does not exist
  iio: magnetometer: ak8975: Fix reading for ak099xx sensors
  media: venus: fix use after free bug in venus_remove due to race condition
  media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
  media: sun4i_csi: Implement link validate for sun4i_csi subdev
  clk: rockchip: fix error for unknown clocks
  aoe: fix the potential use-after-free problem in more places
  riscv: define ILLEGAL_POINTER_VALUE for 64bit
  ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
  ocfs2: fix null-ptr-deref when journal load failed.
  ocfs2: remove unreasonable unlock in ocfs2_read_blocks
  ocfs2: cancel dqi_sync_work before freeing oinfo
  ocfs2: reserve space for inline xattr before attaching reflink tree
  ocfs2: fix uninit-value in ocfs2_get_block()
  ocfs2: fix the la space leak when unmounting an ocfs2 volume
  mm: krealloc: consider spare memory for __GFP_ZERO
  jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
  drm: omapdrm: Add missing check for alloc_ordered_workqueue
  of/irq: Support #msi-cells=<0> in of_msi_get_domain
  parisc: Fix stack start for ADDR_NO_RANDOMIZE personality
  parisc: Fix 64-bit userspace syscall path
  ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit()
  ext4: fix double brelse() the buffer of the extents path
  ext4: aovid use-after-free in ext4_ext_insert_extent()
  ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space()
  ext4: propagate errors from ext4_find_extent() in ext4_insert_range()
  ext4: no need to continue when the number of entries is 1
  ALSA: core: add isascii() check to card ID generator
  drm: Consistently use struct drm_mode_rect for FB_DAMAGE_CLIPS
  parisc: Fix itlb miss handler for 64-bit programs
  perf/core: Fix small negative period being ignored
  spi: bcm63xx: Fix module autoloading
  firmware: tegra: bpmp: Drop unused mbox_client_to_bpmp()
  i2c: xiic: Wait for TX empty to avoid missed TX NAKs
  i2c: stm32f7: Do not prepare/unprepare clock during runtime suspend/resume
  selftests: vDSO: fix vDSO symbols lookup for powerpc64
  selftests: breakpoints: use remaining time to check if suspend succeed
  spi: s3c64xx: fix timeout counters in flush_fifo
  ext4: fix i_data_sem unlock order in ext4_ind_migrate()
  ext4: ext4_search_dir should return a proper error
  of/irq: Refer to actual buffer size in of_irq_parse_one()
  drm/radeon/r100: Handle unknown family in r100_cp_init_microcode()
  scsi: aacraid: Rearrange order of struct aac_srb_unit
  drm/printer: Allow NULL data in devcoredump printer
  drm/amd/display: Initialize get_bytes_per_element's default to 1
  drm/amd/display: Fix index out of bounds in degamma hardware format translation
  drm/amd/display: Check stream before comparing them
  jfs: Fix uninit-value access of new_ea in ea_buffer
  jfs: check if leafidx greater than num leaves per dmap tree
  jfs: Fix uaf in dbFreeBits
  jfs: UBSAN: shift-out-of-bounds in dbFindBits
  ata: sata_sil: Rename sil_blacklist to sil_quirks
  power: reset: brcmstb: Do not go into infinite loop if reset fails
  fbdev: pxafb: Fix possible use after free in pxafb_task()
  x86/syscall: Avoid memcpy() for ia32 syscall_get_arguments()
  ALSA: hdsp: Break infinite MIDI input flush loop
  ALSA: asihpi: Fix potential OOB array access
  signal: Replace BUG_ON()s
  nfp: Use IRQF_NO_AUTOEN flag in request_irq()
  wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
  proc: add config & param to block forcing mem writes
  ACPICA: iasl: handle empty connection_node
  tcp: avoid reusing FIN_WAIT2 when trying to find port in connect() process
  ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family
  ipv4: Check !in_dev earlier for ioctl(SIOCSIFADDR).
  net: mvpp2: Increase size of queue_name buffer
  tipc: guard against string buffer overrun
  ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
  ACPI: EC: Do not release locks during operation region accesses
  wifi: rtw88: select WANT_DEV_COREDUMP
  net: sched: consistently use rcu_replace_pointer() in taprio_change()
  ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
  ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
  net: hisilicon: hns_mdio: fix OF node leak in probe()
  net: hisilicon: hns_dsaf_mac: fix OF node leak in hns_mac_get_info()
  net: hisilicon: hip04: fix OF node leak in probe()
  ice: Adjust over allocation of memory in ice_sched_add_root_node() and ice_sched_add_node()
  wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
  wifi: ath9k: fix possible integer overflow in ath9k_get_et_stats()
  f2fs: Require FMODE_WRITE for atomic write ioctls
  ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
  ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
  ALSA: hda/realtek: Fix the push button function for the ALC257
  sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start
  ipv4: ip_gre: Fix drops of small packets in ipgre_xmit
  net: add more sanity checks to qdisc_pkt_len_init()
  net: avoid potential underflow in qdisc_pkt_len_init() with UFO
  net: ethernet: lantiq_etop: fix memory disclosure
  Bluetooth: btmrvl: Use IRQF_NO_AUTOEN flag in request_irq()
  Bluetooth: btmrvl_sdio: Refactor irq wakeup
  netfilter: nf_tables: prevent nf_skb_duplicated corruption
  net: ieee802154: mcr20a: Use IRQF_NO_AUTOEN flag in request_irq()
  netfilter: uapi: NFTA_FLOWTABLE_HOOK is NLA_NESTED
  net/mlx5: Added cond_resched() to crdump collection
  ieee802154: Fix build error
  drivers: net: Fix Kconfig indentation, continued
  Minor fixes to the CAIF Transport drivers Kconfig file
  ceph: remove the incorrect Fw reference check when dirtying pages
  mailbox: bcm2835: Fix timeout during suspend mode
  mailbox: rockchip: fix a typo in module autoloading
  usb: yurex: Fix inconsistent locking bug in yurex_read()
  i2c: isch: Add missed 'else'
  i2c: aspeed: Update the stop sw state when the bus recovery occurs
  mm: only enforce minimum stack gap size if it's sensible
  pps: add an error check in parport_attach
  pps: remove usage of the deprecated ida_simple_xx() API
  USB: misc: yurex: fix race between read and write
  usb: yurex: Replace snprintf() with the safer scnprintf() variant
  soc: versatile: realview: fix soc_dev leak during device remove
  soc: versatile: realview: fix memory leak during device remove
  PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler
  PCI: xilinx-nwl: Use irq_data_get_irq_chip_data()
  ASoC: meson: axg-card: fix 'use-after-free'
  ASoC: meson: axg: extract sound card utils
  nfs: fix memory leak in error path of nfs4_do_reclaim
  fs: Fix file_set_fowner LSM hook inconsistencies
  vfs: fix race between evice_inodes() and find_inode()&iput()
  hwrng: mtk - Use devm_pm_runtime_enable
  f2fs: avoid potential int overflow in sanity_check_area_boundary()
  f2fs: prevent possible int overflow in dir_block_index()
  debugobjects: Fix conditions in fill_pool()
  wifi: rtw88: 8822c: Fix reported RX band width
  ACPI: resource: Add another DMI match for the TongFang GMxXGxx
  ACPI: sysfs: validate return type of _STR method
  drbd: Add NULL check for net_conf to prevent dereference in state validation
  drbd: Fix atomicity violation in drbd_uuid_set_bm()
  tty: rp2: Fix reset with non forgiving PCIe host bridges
  firmware_loader: Block path traversal
  USB: class: CDC-ACM: fix race between get_serial and set_serial
  USB: misc: cypress_cy7c63: check for short transfer
  USB: appledisplay: close race between probe and completion handler
  drm/amd/display: Round calculated vtotal
  soc: versatile: integrator: fix OF node leak in probe() error path
  Remove *.orig pattern from .gitignore
  crypto: aead,cipher - zeroize key buffer after use
  netfilter: ctnetlink: compile ctnetlink_label_size with CONFIG_NF_CONNTRACK_EVENTS
  net: qrtr: Update packets cloning when broadcasting
  tcp: check skb is non-NULL in tcp_rto_delta_us()
  net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition
  netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
  coresight: tmc: sg: Do not leak sg_table
  iio: adc: ad7606: fix standby gpio state to match the documentation
  iio: adc: ad7606: fix oversampling gpio array
  f2fs: reduce expensive checkpoint trigger frequency
  f2fs: remove unneeded check condition in __f2fs_setxattr()
  f2fs: fix to update i_ctime in __f2fs_setxattr()
  f2fs: fix typo
  f2fs: enhance to update i_mode and acl atomically in f2fs_setattr()
  nfsd: return -EINVAL when namelen is 0
  nfsd: call cache_put if xdr_reserve_space returns NULL
  ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir()
  RDMA/cxgb4: Added NULL check for lookup_atid
  riscv: Fix fp alignment bug in perf_callchain_user()
  RDMA/hns: Optimize hem allocation performance
  watchdog: imx_sc_wdt: Don't disable WDT in suspend
  pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function
  clk: ti: dra7-atl: Fix leak of of_nodes
  pinctrl: single: fix missing error code in pcs_probe()
  RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
  PCI: xilinx-nwl: Fix register misspelling
  PCI: keystone: Fix if-statement expression in ks_pcie_quirk()
  drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error
  drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error
  clk: rockchip: Set parent rate for DCLK_VOP clock on RK3228
  perf time-utils: Fix 32-bit nsec parsing
  perf sched timehist: Fixed timestamp error when unable to confirm event sched_in time
  perf sched timehist: Fix missing free of session in perf_sched__timehist()
  bpf: Fix bpf_strtol and bpf_strtoul helpers for 32bit
  nilfs2: fix potential oob read in nilfs_btree_check_delete()
  nilfs2: determine empty node blocks as corrupted
  nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
  ext4: avoid OOB when system.data xattr changes underneath the filesystem
  ext4: return error on ext4_find_inline_entry
  ext4: avoid negative min_clusters in find_group_orlov()
  smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipso
  ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard
  jbd2: introduce/export functions jbd2_journal_submit|finish_inode_data_buffers()
  kthread: fix task state in kthread worker if being frozen
  kthread: add kthread_work tracepoints
  xz: cleanup CRC32 edits from 2018
  selftests/bpf: Fix error compiling test_lru_map.c
  selftests/bpf: Fix compiling tcp_rtt.c with musl-libc
  selftests/bpf: Fix compiling flow_dissector.c with musl-libc
  selftests/bpf: Fix compile error from rlim_t in sk_storage_map.c
  tpm: Clean up TPM space after command failure
  xen/swiotlb: add alignment check for dma buffers
  xen: use correct end address of kernel for conflict checking
  drivers:drm:exynos_drm_gsc:Fix wrong assignment in gsc_bind()
  drm/msm: fix %s null argument error
  ipmi: docs: don't advertise deprecated sysfs entries
  drm/msm/a5xx: fix races in preemption evaluation stage
  drm/msm/a5xx: properly clear preemption records on resume
  drm/msm/a5xx: disable preemption in submits by default
  drm/msm: Fix incorrect file name output in adreno_request_fw()
  jfs: fix out-of-bounds in dbNextAG() and diAlloc()
  drm/radeon/evergreen_cs: fix int overflow errors in cs track offsets
  drm/rockchip: dw_hdmi: Fix reading EDID when using a forced mode
  drm/rockchip: vop: Allow 4096px width scaling
  drm/radeon: properly handle vbios fake edid sizing
  drm/radeon: Replace one-element array with flexible-array member
  drm/amdgpu: properly handle vbios fake edid sizing
  drm/amdgpu: Replace one-element array with flexible-array member
  drm/stm: Fix an error handling path in stm_drm_platform_probe()
  mtd: powernv: Add check devm_kasprintf() returned value
  fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
  power: supply: max17042_battery: Fix SOC threshold calc w/ no current sense
  power: supply: axp20x_battery: Remove design from min and max voltage
  power: supply: axp20x_battery: allow disabling battery charging
  hwmon: (ntc_thermistor) fix module autoloading
  mtd: slram: insert break after errors in parsing the map
  hwmon: (max16065) Fix overflows seen when writing limits
  clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()
  reset: berlin: fix OF node leak in probe() error path
  ARM: versatile: fix OF node leak in CPUs prepare
  ARM: dts: imx7d-zii-rmu2: fix Ethernet PHY pinctrl property
  spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
  spi: ppc4xx: handle irq_of_parse_and_map() errors
  block, bfq: don't break merge chain in bfq_split_bfqq()
  block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator()
  block, bfq: fix possible UAF for bfqq->bic with merge chain
  net: tipc: avoid possible garbage value
  Bluetooth: btusb: Fix not handling ZPL/short-transfer
  can: bcm: Clear bo->bcm_proc_read after remove_proc_entry().
  sock_map: Add a cond_resched() in sock_hash_free()
  wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param
  wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()
  mac80211: parse radiotap header when selecting Tx queue
  wifi: cfg80211: fix two more possible UBSAN-detected off-by-one errors
  wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
  netfilter: nf_tables: reject expiration higher than timeout
  netfilter: nf_tables: reject element expiration with no timeout
  netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire
  can: j1939: use correct function name in comment
  mount: handle OOM on mnt_warn_timestamp_expiry
  fs/namespace: fnic: Switch to use %ptTd
  mount: warn only once about timestamp range expiration
  fs: explicitly unregister per-superblock BDIs
  wifi: ath9k: Remove error checks when creating debugfs entries
  wifi: ath9k: fix parameter check in ath9k_init_debug()
  ACPI: PMIC: Remove unneeded check in tps68470_pmic_opregion_probe()
  USB: usbtmc: prevent kernel-usb-infoleak
  USB: serial: pl2303: add device id for Macrosilicon MS3020
  bpf: Fix DEVMAP_HASH overflow check on 32-bit arches
  inet: inet_defrag: prevent sk release while still in use
  gpio: prevent potential speculation leaks in gpio_device_get_desc()
  ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()
  ocfs2: add bounds checking to ocfs2_xattr_find_entry()
  x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides frequency
  spi: bcm63xx: Enable module autoloading
  drm: komeda: Fix an issue related to normalized zpos
  ASoC: tda7419: fix module autoloading
  wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
  wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
  net: ftgmac100: Ensure tx descriptor updates are visible
  microblaze: don't treat zero reserved memory regions as error
  pinctrl: at91: make it work with current gpiolib
  ALSA: hda/realtek - FIxed ALC285 headphone no sound
  ALSA: hda/realtek - Fixed ALC256 headphone no sound
  ASoC: allow module autoloading for table db1200_pids
  selftests: breakpoints: Fix a typo of function name
  soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
  spi: nxp-fspi: fix the KASAN report out-of-bounds bug
  net: dpaa: Pad packets to ETH_ZLEN
  net: ftgmac100: Enable TX interrupt to avoid TX timeout
  net/mlx5e: Add missing link modes to ptys2ethtool_map
  ice: fix accounting for filters shared by multiple VSIs
  arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO hog on RK3399 Puma
  scripts: kconfig: merge_config: config files: add a trailing newline
  net: phy: vitesse: repair vsc73xx autonegotiation
  net: ethernet: use ip_hdrlen() instead of bit shift
  usbnet: ipheth: fix carrier detection in modes 1 and 4
  UPSTREAM: unicode: Don't special case ignorable code points
  ANDROID: 16K: Fixup padding vm_flags bits on VMA splits
  ANDROID: 16K: Introduce pgsize_migration_inline.h
  Revert "clocksource/drivers/timer-of: Remove percpu irq related code"
  Linux 5.4.284
  Revert "parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367"
  cx82310_eth: fix error return code in cx82310_bind()
  net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket
  rtmutex: Drop rt_mutex::wait_lock before scheduling
  drm/i915/fence: Mark debug_fence_free() with __maybe_unused
  drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused
  nvmet-tcp: fix kernel crash if commands allocation fails
  arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry
  arm64: acpi: Move get_cpu_for_acpi_id() to a header
  ACPI: processor: Fix memory leaks in error paths of processor_add()
  ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()
  nilfs2: protect references to superblock parameters exposed in sysfs
  nilfs2: replace snprintf in show functions with sysfs_emit
  tracing: Avoid possible softlockup in tracing_iter_reset()
  ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()
  uprobes: Use kzalloc to allocate xol area
  clocksource/drivers/timer-of: Remove percpu irq related code
  clocksource/drivers/imx-tpm: Fix next event not taking effect sometime
  clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX
  VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
  Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
  uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
  nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc
  binder: fix UAF caused by offsets overwrite
  iio: fix scale application in iio_convert_raw_to_processed_unlocked
  iio: buffer-dmaengine: fix releasing dma channel on error
  staging: iio: frequency: ad9834: Validate frequency parameter value
  NFSv4: Add missing rescheduling points in nfs_client_return_marked_delegations
  ata: pata_macio: Use WARN instead of BUG
  lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
  of/irq: Prevent device address out-of-bounds read in interrupt map walk
  Squashfs: sanity check symbolic link size
  usbnet: ipheth: race between ipheth_close and error handling
  Input: uinput - reject requests with unreasonable number of slots
  HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
  btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()
  PCI: Add missing bridge lock to pci_bus_lock()
  btrfs: clean up our handling of refs == 0 in snapshot delete
  btrfs: replace BUG_ON with ASSERT in walk_down_proc()
  smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
  wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
  libbpf: Add NULL checks to bpf_object__{prev_map,next_map}
  hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
  hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
  hwmon: (lm95234) Fix underflows seen when writing limit attributes
  hwmon: (adc128d818) Fix underflows seen when writing limit attributes
  pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
  devres: Initialize an uninitialized struct member
  um: line: always fill *error_out in setup_one_line()
  cgroup: Protect css->cgroup write under css_set_lock
  iommu/vt-d: Handle volatile descriptor status read
  dm init: Handle minors larger than 255
  ASoC: topology: Properly initialize soc_enum values
  net: dsa: vsc73xx: fix possible subblocks range of CAPT block
  net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN
  net: bridge: fdb: convert added_by_external_learn to use bitops
  net: bridge: fdb: convert added_by_user to bitops
  net: bridge: fdb: convert is_sticky to bitops
  net: bridge: fdb: convert is_static to bitops
  net: bridge: fdb: convert is_local to bitops
  usbnet: modern method to get random MAC
  net: usb: don't write directly to netdev->dev_addr
  drivers/net/usb: Remove all strcpy() uses
  cx82310_eth: re-enable ethernet mode after router reboot
  tcp_bpf: fix return value of tcp_bpf_sendmsg()
  platform/x86: dell-smbios: Fix error path in dell_smbios_init()
  igb: Fix not clearing TimeSync interrupts for 82580
  can: bcm: Remove proc entry when dev is unregistered.
  pcmcia: Use resource_size function on resource object
  media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
  PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
  usb: uas: set host status byte on data completion error
  wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
  udf: Avoid excessive partition lengths
  netfilter: nf_conncount: fix wrong variable type
  af_unix: Remove put_pid()/put_cred() in copy_peercred().
  irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1
  smack: unix sockets: fix accept()ed socket label
  ALSA: hda: Add input value sanity checks to HDMI channel map controls
  nilfs2: fix state management in error path of log writing function
  nilfs2: fix missing cleanup on rollforward recovery error
  sched: sch_cake: fix bulk flow accounting logic for host fairness
  ila: call nf_unregister_net_hooks() sooner
  clk: qcom: clk-alpha-pll: Fix the trion pll postdiv set rate API
  clk: qcom: clk-alpha-pll: Fix the pll post div mask
  clk: hi6220: use CLK_OF_DECLARE_DRIVER
  reset: hi6220: Add support for AO reset controller
  fuse: use unsigned type for getxattr/listxattr size truncation
  fuse: update stats for pages in dropped aux writeback list
  mmc: sdhci-of-aspeed: fix module autoloading
  mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
  irqchip/gic-v2m: Fix refcount leak in gicv2m_of_init()
  ata: libata: Fix memory leak for error path in ata_host_alloc()
  ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices
  ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
  sch/netem: fix use after free in netem_dequeue
  i2c: Use IS_REACHABLE() for substituting empty ACPI functions
  udf: Limit file size to 4TB
  virtio_net: Fix napi_skb_cache_put warning
  net: set SOCK_RCU_FREE before inserting socket into hashtable
  block: initialize integrity buffer to zero before writing it to media
  media: uvcvideo: Enforce alignment of frame and interval
  drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
  wifi: cfg80211: make hash table duplicates more survivable
  smack: tcp: ipv4, fix incorrect labeling
  usb: typec: ucsi: Fix null pointer dereference in trace
  usbip: Don't submit special requests twice
  ionic: fix potential irq name truncation
  apparmor: fix possible NULL pointer dereference
  drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device
  drm/amdgpu: fix mc_data out-of-bounds read warning
  drm/amdgpu: fix ucode out-of-bounds read warning
  drm/amd/display: Fix Coverity INTEGER_OVERFLOW within dal_gpio_service_create
  drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]
  drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
  drm/amd/display: Check gpio_id before used as array index
  drm/amdgpu: fix overflowed array index read warning
  drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr
  net: usb: qmi_wwan: add MeiG Smart SRM825L
  i2c: Fix conditional for substituting empty ACPI functions
  drm: panel-orientation-quirks: Add quirk for OrangePi Neo
  Linux 5.4.283
  scsi: aacraid: Fix double-free on probe failure
  net: dsa: mv8e6xxx: Fix stub function parameters
  usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in remove_power_attributes()
  usb: dwc3: st: add missing depopulate in probe error path
  usb: dwc3: st: fix probed platform device ref count on probe error path
  usb: dwc3: core: Prevent USB core invalid event buffer address access
  usb: dwc3: omap: add missing depopulate in probe error path
  USB: serial: option: add MeiG Smart SRM825L
  cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
  soc: qcom: cmd-db: Map shared memory as WC, not WB
  nfc: pn533: Add poll mod list filling check
  nfc: pn533: Add autopoll capability
  nfc: pn533: Add dev_up/dev_down hooks to phy_ops
  net: busy-poll: use ktime_get_ns() instead of local_clock()
  gtp: fix a potential NULL pointer dereference
  ethtool: check device is present when getting link settings
  r8152: Factor out OOB link list waits
  soundwire: stream: fix programming slave ports for non-continous port maps
  net:rds: Fix possible deadlock in rds_message_put
  cgroup/cpuset: Prevent UAF in proc_cpuset_show()
  ata: libata-core: Fix null pointer dereference on error
  media: uvcvideo: Fix integer overflow calculating timestamp
  filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
  drm/amdkfd: don't allow mapping the MMIO HDP page with large pages
  ipc: replace costly bailout check in sysvipc_find_ipc()
  wifi: mwifiex: duplicate static structs used in driver instances
  pinctrl: single: fix potential NULL dereference in pcs_get_function()
  drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
  tools: move alignment-related macros to new <linux/align.h>
  Input: MT - limit max slots
  Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
  ALSA: timer: Relax start tick time check for slave timer elements
  mmc: dw_mmc: allow biu and ciu clocks to defer
  cxgb4: add forgotten u64 ivlan cast before shift
  HID: microsoft: Add rumble support to latest xbox controllers
  HID: wacom: Defer calculation of resolution until resolution_code is known
  Bluetooth: MGMT: Add error handling to pair_device()
  mmc: mmc_test: Fix NULL dereference on allocation failure
  drm/msm/dpu: don't play tricks with debug macros
  drm/msm: use drm_debug_enabled() to check for debug categories
  net: xilinx: axienet: Fix dangling multicast addresses
  net: xilinx: axienet: Always disable promiscuous mode
  ipv6: prevent UAF in ip6_send_skb()
  netem: fix return value if duplicate enqueue fails
  net: dsa: mv88e6xxx: Fix out-of-bound access
  net: dsa: mv88e6xxx: replace ATU violation prints with trace points
  net: dsa: mv88e6xxx: read FID when handling ATU violations
  net: dsa: mv88e6xxx: global1_atu: Add helper for get next
  net: dsa: mv88e6xxx: global2: Expose ATU stats register
  netfilter: nft_counter: Synchronize nft_counter_reset() against reader.
  kcm: Serialise kcm_sendmsg() for the same socket.
  tc-testing: don't access non-existent variable on exception
  Bluetooth: hci_core: Fix LE quote calculation
  Bluetooth: hci_core: Fix not handling link timeouts propertly
  Bluetooth: Make use of __check_timeout on hci_sched_le
  dm suspend: return -ERESTARTSYS instead of -EINTR
  dm: do not use waitqueue for request-based DM
  dm mpath: pass IO start time to path selector
  media: solo6x10: replace max(a, min(b, c)) by clamp(b, a, c)
  block: use "unsigned long" for blk_validate_block_size().
  gtp: pull network headers in gtp_dev_xmit()
  hrtimer: Prevent queuing of hrtimer without a function callback
  nvmet-rdma: fix possible bad dereference when freeing rsps
  ext4: set the type of max_zeroout to unsigned int to avoid overflow
  irqchip/gic-v3-its: Remove BUG_ON in its_vpe_irq_domain_alloc
  usb: dwc3: core: Skip setting event buffers for host only controllers
  s390/iucv: fix receive buffer virtual vs physical address confusion
  openrisc: Call setup_memory() earlier in the init sequence
  NFS: avoid infinite loop in pnfs_update_layout.
  nvmet-tcp: do not continue for invalid icreq
  Bluetooth: bnep: Fix out-of-bound access
  nvme: clear caller pointer on identify failure
  usb: gadget: fsl: Increase size of name buffer for endpoints
  f2fs: fix to do sanity check in update_sit_entry
  btrfs: delete pointless BUG_ON check on quota root in btrfs_qgroup_account_extent()
  btrfs: send: handle unexpected data in header buffer in begin_cmd()
  btrfs: handle invalid root reference found in may_destroy_subvol()
  btrfs: change BUG_ON to assertion when checking for delayed_node root
  powerpc/boot: Only free if realloc() succeeds
  powerpc/boot: Handle allocation failure in simple_realloc()
  parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367
  x86: Increase brk randomness entropy for 64-bit systems
  md: clean up invalid BUG_ON in md_ioctl
  virtiofs: forbid newlines in tags
  drm/lima: set gp bus_stop bit before hard reset
  net/sun3_82586: Avoid reading past buffer in debug output
  scsi: lpfc: Initialize status local variable in lpfc_sli4_repost_sgl_list()
  fs: binfmt_elf_efpic: don't use missing interpreter's properties
  media: pci: cx23885: check cx23885_vdev_init() return
  quota: Remove BUG_ON from dqget()
  ext4: do not trim the group with corrupted block bitmap
  nvmet-trace: avoid dereferencing pointer too early
  powerpc/xics: Check return value of kasprintf in icp_native_map_one_cpu
  IB/hfi1: Fix potential deadlock on &irq_src_lock and &dd->uctxt_lock
  wifi: iwlwifi: abort scan when rfkill on but device enabled
  gfs2: setattr_chown: Add missing initialization
  scsi: spi: Fix sshdr use
  binfmt_misc: cleanup on filesystem umount
  staging: ks7010: disable bh on tx_dev_lock
  media: radio-isa: use dev_name to fill in bus_info
  i2c: riic: avoid potential division by zero
  wifi: cw1200: Avoid processing an invalid TIM IE
  ssb: Fix division by zero issue in ssb_calc_clock_rate
  ALSA: hda/realtek: Fix noise from speakers on Lenovo IdeaPad 3 15IAU7
  net: hns3: fix a deadlock problem when config TC during resetting
  net: dsa: vsc73xx: pass value in phy_write operation
  net: axienet: Fix register defines comment description
  net: axienet: Autodetect 64-bit DMA capability
  net: axienet: Upgrade descriptors to hold 64-bit addresses
  net: axienet: Wrap DMA pointer writes to prepare for 64 bit
  net: axienet: Drop MDIO interrupt registers from ethtools dump
  net: axienet: Check for DMA mapping errors
  net: axienet: Factor out TX descriptor chain cleanup
  net: axienet: Improve DMA error handling
  net: axienet: Fix DMA descriptor cleanup path
  atm: idt77252: prevent use after free in dequeue_rx()
  net/mlx5e: Correctly report errors for ethtool rx flows
  s390/uv: Panic for set and remove shared access UVC errors
  btrfs: rename bitmap_set_bits() -> btrfs_bitmap_set_bits()
  s390/cio: rename bitmap_size() -> idset_bitmap_size()
  overflow: Implement size_t saturating arithmetic helpers
  overflow.h: Add flex_array_size() helper
  memcg_write_event_control(): fix a user-triggerable oops
  drm/amdgpu: Actually check flags for all context ops.
  selinux: fix potential counting error in avc_add_xperms_decision()
  fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
  bitmap: introduce generic optimized bitmap_size()
  vfs: Don't evict inode under the inode lru traversing context
  dm persistent data: fix memory allocation failure
  dm resume: don't return EINVAL when signalled
  arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to NUMA_NO_NODE
  s390/dasd: fix error recovery leading to data corruption on ESE devices
  xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration
  ALSA: usb-audio: Support Yamaha P-125 quirk entry
  fuse: Initialize beyond-EOF page contents before setting uptodate
  Revert "genirq: Allow the PM device to originate from irq domain"
  Revert "genirq: Allow irq_chip registration functions to take a const irq_chip"
  Revert "irqchip/imx-irqsteer: Constify irq_chip struct"
  Revert "irqchip/imx-irqsteer: Add runtime PM support"
  Revert "irqchip/imx-irqsteer: Handle runtime power management correctly"
  Linux 5.4.282
  media: Revert "media: dvb-usb: Fix unexpected infinite loop in dvb_usb_read_remote_control()"
  ARM: dts: imx6qdl-kontron-samx6i: fix phy-mode
  nvme/pci: Add APST quirk for Lenovo N60z laptop
  exec: Fix ToCToU between perm check and set-uid/gid usage
  media: uvcvideo: Use entity get_cur in uvc_ctrl_set
  arm64: cpufeature: Fix the visibility of compat hwcaps
  drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
  netfilter: nf_tables: prefer nft_chain_validate
  netfilter: nf_tables: use timestamp to check for set element timeout
  netfilter: nf_tables: set element extended ACK reporting support
  kbuild: Fix '-S -c' in x86 stack protector scripts
  Fix gcc 4.9 build issue in 5.4.y
  drm/mgag200: Set DDC timeout in milliseconds
  drm/bridge: analogix_dp: properly handle zero sized AUX transactions
  x86/mtrr: Check if fixed MTRRs exist before saving them
  tracing: Fix overflow in get_free_elt()
  power: supply: axp288_charger: Round constant_charge_voltage writes down
  power: supply: axp288_charger: Fix constant_charge_voltage writes
  genirq/irqdesc: Honor caller provided affinity in alloc_desc()
  serial: core: check uartclk for zero to avoid divide by zero
  scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES
  scsi: mpt3sas: Remove scsi_dma_map() error messages
  ntp: Safeguard against time_constant overflow
  driver core: Fix uevent_show() vs driver detach race
  ntp: Clamp maxerror and esterror to operating range
  tick/broadcast: Move per CPU pointer access into the atomic section
  scsi: ufs: core: Fix hba->last_dme_cmd_tstamp timestamp updating logic
  usb: gadget: core: Check for unset descriptor
  USB: serial: debug: do not echo input by default
  usb: vhci-hcd: Do not drop references before new references are gained
  ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
  ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
  ALSA: line6: Fix racy access to midibuf
  drm/client: fix null pointer dereference in drm_client_modeset_probe
  spi: spi-fsl-lpspi: Fix scldiv calculation
  spi: fsl-lpspi: remove unneeded array
  bpf: kprobe: remove unused declaring of bpf_kprobe_override
  i2c: smbus: Send alert notifications to all devices if source not found
  i2c: smbus: Improve handling of stuck alerts
  i2c: smbus: Don't filter out duplicate alerts
  arm64: errata: Expand speculative SSBS workaround (again)
  arm64: cputype: Add Cortex-A725 definitions
  arm64: cputype: Add Cortex-X1C definitions
  arm64: errata: Expand speculative SSBS workaround
  arm64: errata: Unify speculative SSBS errata logic
  arm64: cputype: Add Cortex-X925 definitions
  arm64: cputype: Add Cortex-A720 definitions
  arm64: cputype: Add Cortex-X3 definitions
  arm64: errata: Add workaround for Arm errata 3194386 and 3312417
  arm64: cputype: Add Neoverse-V3 definitions
  arm64: cputype: Add Cortex-X4 definitions
  arm64: Add Neoverse-V2 part
  arm64: cpufeature: Force HWCAP to be based on the sysreg visible to user-space
  ext4: fix wrong unit use in ext4_mb_find_by_goal
  SUNRPC: Fix a race to wake a sync task
  s390/sclp: Prevent release of buffer in I/O
  jbd2: avoid memleak in jbd2_journal_write_metadata_buffer
  media: uvcvideo: Fix the bandwdith quirk on USB 3.x
  media: uvcvideo: Ignore empty TS packets
  drm/amdgpu: Fix the null pointer dereference to ras_manager
  btrfs: fix bitmap leak when loading free space cache on duplicate entry
  wifi: nl80211: don't give key data to userspace
  udf: prevent integer overflow in udf_bitmap_free_blocks()
  PCI: Add Edimax Vendor ID to pci_ids.h
  selftests/bpf: Fix send_signal test with nested CONFIG_PARAVIRT
  ACPI: SBS: manage alarm sysfs attribute through psy core
  ACPI: battery: create alarm sysfs attribute atomically
  clocksource/drivers/sh_cmt: Address race condition for clock events
  md/raid5: avoid BUG_ON() while continue reshape after reassembling
  net: fec: Stop PPS on driver remove
  Bluetooth: l2cap: always unlock channel in l2cap_conless_channel()
  net: linkwatch: use system_unbound_wq
  net: usb: qmi_wwan: fix memory leak for not ip packets
  sctp: Fix null-ptr-deref in reuseport_add_sock().
  sctp: move hlist_node and hashent out of sctp_ep_common
  x86/mm: Fix pti_clone_pgtable() alignment assumption
  irqchip/mbigen: Fix mbigen node address layout
  genirq: Allow irq_chip registration functions to take a const irq_chip
  netfilter: ipset: Add list flush to cancel_gc
  net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
  ALSA: usb-audio: Correct surround channels in UAC1 channel map
  protect the fetch of ->fd[fd] in do_dup2() from mispredictions
  HID: wacom: Modify pen IDs
  ipv6: fix ndisc_is_useropt() handling for PIO
  net/mlx5e: Add a check for the return value from mlx5_port_set_eth_ptys
  net/iucv: fix use after free in iucv_sock_close()
  drm/vmwgfx: Fix overlay when using Screen Targets
  drm/nouveau: prime: fix refcount underflow
  remoteproc: imx_rproc: Skip over memory region when node value is NULL
  remoteproc: imx_rproc: Fix ignoring mapping vdev regions
  remoteproc: imx_rproc: ignore mapping vdev regions
  irqchip/imx-irqsteer: Handle runtime power management correctly
  irqchip/imx-irqsteer: Add runtime PM support
  irqchip/imx-irqsteer: Constify irq_chip struct
  genirq: Allow the PM device to originate from irq domain
  devres: Fix memory leakage caused by driver API devm_free_percpu()
  driver core: Cast to (void *) with __force for __percpu pointer
  dev/parport: fix the array out-of-bounds risk
  parport: Standardize use of printmode
  parport: Convert printk(KERN_<LEVEL> to pr_<level>(
  PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
  PCI: rockchip: Make 'ep-gpios' DT property optional
  mm: avoid overflows in dirty throttling logic
  nvme-pci: add missing condition check for existence of mapped data
  ASoC: Intel: use soc_intel_is_byt_cr() only when IOSF_MBI is reachable
  ASoC: Intel: Move soc_intel_is_foo() helpers to a generic header
  ASoC: Intel: Convert to new X86 CPU match macros
  powerpc: fix a file leak in kvm_vcpu_ioctl_enable_cap()
  apparmor: Fix null pointer deref when receiving skb during sock creation
  mISDN: Fix a use after free in hfcmulti_tx()
  bpf: Fix a segment issue when downgrading gso_size
  net: nexthop: Initialize all fields in dumped nexthops
  tipc: Return non-zero value from tipc_udp_addr2str() on error
  net: bonding: correctly annotate RCU in bond_should_notify_peers()
  ipv4: Fix incorrect source address in Record Route option
  MIPS: SMP-CPS: Fix address for GCR_ACCESS register for CM3 and later
  dma: fix call order in dmam_free_coherent
  libbpf: Fix no-args func prototype BTF dumping syntax
  um: time-travel: fix time-travel-start option
  jfs: Fix array-index-out-of-bounds in diFree
  kdb: Use the passed prompt in kdb_position_cursor()
  kdb: address -Wformat-security warnings
  nilfs2: handle inconsistent state in nilfs_btnode_create_block()
  Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x13d3:0x3591
  Bluetooth: btusb: Add RTL8852BE device 0489:e125 to device tables
  rbd: don't assume RBD_LOCK_STATE_LOCKED for exclusive mappings
  rbd: rename RBD_LOCK_STATE_RELEASING and releasing_wait
  drm/panfrost: Mark simple_ondemand governor as softdep
  rbd: don't assume rbd_is_lock_owner() for exclusive mappings
  selftests/sigaltstack: Fix ppc64 GCC build
  RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
  platform: mips: cpu_hwmon: Disable driver on unsupported hardware
  watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
  rtc: isl1208: Fix return value of nvmem callbacks
  perf/x86/intel/pt: Fix a topa_entry base address calculation
  perf/x86/intel/pt: Fix topa_entry base length
  scsi: qla2xxx: validate nvme_local_port correctly
  scsi: qla2xxx: Complete command early within lock
  scsi: qla2xxx: Fix for possible memory corruption
  scsi: qla2xxx: During vport delete send async logout explicitly
  rtc: cmos: Fix return value of nvmem callbacks
  kobject_uevent: Fix OOB access within zap_modalias_env()
  decompress_bunzip2: fix rare decompression failure
  ubi: eba: properly rollback inside self_check_eba
  clk: davinci: da8xx-cfgchip: Initialize clk_init_data before use
  f2fs: fix to don't dirty inode for readonly filesystem
  scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for ELS cmds
  binder: fix hang of unregistered readers
  PCI: hv: Return zero, not garbage, when reading PCI_INTERRUPT_PIN
  hwrng: amd - Convert PCIBIOS_* return codes to errnos
  tools/memory-model: Fix bug in lock.cat
  leds: ss4200: Convert PCIBIOS_* return codes to errnos
  wifi: mwifiex: Fix interface type change
  ext4: make sure the first directory block is not a hole
  ext4: check dot and dotdot of dx_root before making dir indexed
  m68k: amiga: Turn off Warp1260 interrupts during boot
  udf: Avoid using corrupted block bitmap buffer
  drm/amd/display: Check for NULL pointer
  drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
  drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
  hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
  media: venus: fix use after free in vdec_close
  char: tpm: Fix possible memory leak in tpm_bios_measurements_open()
  ipv6: take care of scope when choosing the src addr
  af_packet: Handle outgoing VLAN packets without hardware offloading
  net: netconsole: Disable target before netpoll cleanup
  tick/broadcast: Make takeover of broadcast hrtimer reliable
  rtc: interface: Add RTC offset to alarm after fix-up
  nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
  fs/nilfs2: remove some unused macros to tame gcc
  pinctrl: freescale: mxs: Fix refcount of child
  pinctrl: ti: ti-iodelay: fix possible memory leak when pinctrl_enable() fails
  pinctrl: ti: ti-iodelay: Drop if block with always false condition
  pinctrl: single: fix possible memory leak when pinctrl_enable() fails
  pinctrl: core: fix possible memory leak when pinctrl_enable() fails
  netfilter: ctnetlink: use helper function to calculate expect ID
  bnxt_re: Fix imm_data endianness
  macintosh/therm_windtunnel: fix module unload.
  powerpc/xmon: Fix disassembly CPU feature checks
  MIPS: Octeron: remove source file executable bit
  Input: elan_i2c - do not leave interrupt disabled on suspend failure
  RDMA/device: Return error earlier if port in not valid
  mtd: make mtd_test.c a separate module
  ASoC: max98088: Check for clk_prepare_enable() error
  RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs
  RDMA/mlx4: Fix truncated output warning in alias_GUID.c
  RDMA/mlx4: Fix truncated output warning in mad.c
  Input: qt1050 - handle CHIP_ID reading error
  PCI: Fix resource double counting on remove & rescan
  SUNRPC: Fixup gss_status tracepoint error output
  sparc64: Fix incorrect function signature and add prototype for prom_cif_init
  ext4: avoid writing unitialized memory to disk in EA inodes
  SUNRPC: avoid soft lockup when transmitting UDP to reachable server.
  mfd: omap-usb-tll: Use struct_size to allocate tll
  drm/qxl: Add check for drm_cvt_mode
  drm/etnaviv: fix DMA direction handling for cached RW buffers
  perf report: Fix condition in sort__sym_cmp()
  leds: trigger: Unregister sysfs attributes before calling deactivate()
  media: renesas: vsp1: Store RPF partition configuration per RPF instance
  media: renesas: vsp1: Fix _irqsave and _irq mix
  media: uvcvideo: Override default flags
  media: uvcvideo: Allow entity-defined get_info and get_cur
  saa7134: Unchecked i2c_transfer function result fixed
  media: imon: Fix race getting ictx->lock
  media: dvb-usb: Fix unexpected infinite loop in dvb_usb_read_remote_control()
  USB: move snd_usb_pipe_sanity_check into the USB core
  selftests: forwarding: devlink_lib: Wait for udev events after reloading
  bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
  wifi: virt_wifi: don't use strlen() in const context
  gss_krb5: Fix the error handling path for crypto_sync_skcipher_setkey
  wifi: virt_wifi: avoid reporting connection success with wrong SSID
  qed: Improve the stack space of filter_config()
  perf: Prevent passing zero nr_pages to rb_alloc_aux()
  perf: Fix perf_aux_size() for greater-than 32-bit size
  perf/x86/intel/pt: Fix pt_topa_entry_for_page() address calculation
  netfilter: nf_tables: rise cap on SELinux secmark context
  ipvs: Avoid unnecessary calls to skb_is_gso_sctp
  net: fec: Fix FEC_ECR_EN1588 being cleared on link-down
  net: fec: Refactor: #define magic constants
  wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()
  wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
  mlxsw: spectrum_acl_erp: Fix object nesting warning
  lib: objagg: Fix general protection fault
  selftests/bpf: Check length of recv in test_sockmap
  net/smc: set rmb's SG_MAX_SINGLE_ALLOC limitation only when CONFIG_ARCH_NO_SG_CHAIN is defined
  net/smc: Allow SMC-D 1MB DMB allocations
  wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
  firmware: turris-mox-rwtm: Initialize completion before mailbox
  firmware: turris-mox-rwtm: Fix checking return value of wait_for_completion_timeout()
  m68k: cmpxchg: Fix return value for default case in __arch_xchg()
  x86/xen: Convert comma to semicolon
  m68k: atari: Fix TT bootup freeze / unexpected (SCU) interrupt messages
  arm64: dts: amlogic: gx: correct hdmi clocks
  arm64: dts: mediatek: mt7622: fix "emmc" pinctrl mux
  ARM: dts: imx6qdl-kontron-samx6i: fix PCIe reset polarity
  ARM: dts: imx6qdl-kontron-samx6i: fix board reset
  ARM: dts: imx6qdl-kontron-samx6i: fix PHY reset
  ARM: dts: imx6qdl-kontron-samx6i: move phy reset into phy-node
  arm64: dts: rockchip: Increase VOP clk rate on RK3328
  arm64: dts: qcom: msm8996: specify UFS core_clk frequencies
  arm64: dts: qcom: sdm845: add power-domain to UFS PHY
  hwmon: (max6697) Fix swapped temp{1,8} critical alarms
  hwmon: (max6697) Fix underflow when writing limit attributes
  pwm: stm32: Always do lazy disabling
  hwmon: (adt7475) Fix default duty on fan is disabled
  x86/platform/iosf_mbi: Convert PCIBIOS_* return codes to errnos
  x86/pci/xen: Fix PCIBIOS_* return code handling
  x86/pci/intel_mid_pci: Fix PCIBIOS_* return code handling
  x86/of: Return consistent error type from x86_of_pci_irq_enable()
  hfsplus: fix to avoid false alarm of circular locking
  platform/chrome: cros_ec_debugfs: fix wrong EC message version
  EDAC, i10nm: make skx_common.o a separate module
  EDAC/skx_common: Add new ADXL components for 2-level memory
  EDAC, skx: Retrieve and print retry_rd_err_log registers
  EDAC, skx_common: Refactor so that we initialize "dev" in result of adxl decode.

 Conflicts:
	Documentation/devicetree/bindings
	Documentation/devicetree/bindings/vendor-prefixes.yaml
	drivers/clk/qcom/clk-rpmh.c
	drivers/rpmsg/qcom_glink_native.c
	drivers/soc/qcom/socinfo.c
	drivers/usb/dwc3/core.c
	fs/userfaultfd.c
	mm/madvise.c
	net/qrtr/qrtr.c

Change-Id: I5064cb8c11d2c104b445035a948867f10c88da1b
Signed-off-by: kamasali Satyanarayan <quic_kamasali@quicinc.com>
2025-03-26 11:56:22 +05:30
Subramanian Ananthanarayanan
487f688a87 msm: mhi_dev: Avoid BME check while sending ready
On some x86 based Root complex devices we observe that BME gets set
during PBL initialization sequence and gets cleared if the BAR
configuration is yet to be complete. So depending on the timing of
AMSS boot duration, when we read the PCIE20_COMMAND_STATUS register
bit(5) during BME IRQ, three scenarios can happen.

1. AMSS boots quicker: The BME bit is set, we set dev->enumerated flag
and indicate EP_PCIE_LINK_ENABLED and initiate MHI which in turn
continues to do MMIO initialization sequence. This sequence involves
call to mhi_dev_sm_set_ready() and mhi_dev_sm_init() APIs which check
for ep_pcie_get_linkstatus() API which might end up failing thus
preventing MHI from moving to ready state.
2. The BME bit is already cleared and set again before the first BME
IRQ. So there is no disruption in the code flow.
3. The BME bit is cleared and hence we do not set dev->enumerated. The
normal code flow happens as part of 2nd BME IRQ.

In (2) and (3) there are no issues, but in (1) during
mhi_dev_resume_mmio_mhi_init() we call ep_pcie_register_event() which
will overwrite the previous EP_PCIE_EVENT_LINKUP registration. So
during the 2nd BME IRQ that gets fired, EP PCIE driver does not give
a callback to MHI as EP_PCIE_EVENT_LINKUP is not registered by MHI
anymore.

In current implementation, APIs mhi_dev_sm_set_ready() or
mhi_dev_sm_init() fail as BME is deasserted. This results in MHI host
driver not getting ready state. mhi_dev_resume_mmio_mhi_init() is called
only if BME is set, mhi_dev_sm_set_ready() and mhi_dev_sm_init() APIs
are called as part of this. As these APIs are called only if BME is set,
BME check inside these APIs is not really needed.

To avoid the issue of not sending ready state, removing checks for BME
in mhi_dev_sm_set_ready() and mhi_dev_sm_init() APIs, so that ready
state is sent to host and M0 is received after this. Added a warning log
before polling for M0 to know if BME is not set again by host.

Change-Id: I211e9e20e05211d2a0c6f0972e1468a4d452ff5d
Signed-off-by: Subramanian Ananthanarayanan <skananth@codeaurora.org>
Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
2025-03-25 18:21:30 +05:30
QCTECMDR Service
9cc9e1aef9 Merge "qseecom: Remove virtual address print" 2025-03-24 00:28:41 -07:00
QCTECMDR Service
cdc0c3e081 Merge "FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region" 2025-03-17 11:14:35 -07:00
QCTECMDR Service
ea14e82ebf Merge "FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic" 2025-03-16 23:50:11 -07:00
Vikash Garodia
56820042f9 FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
sfr->buf_size is in shared memory and can be modified by malicious user.
OOB write is possible when the size is made higher than actual sfr data
buffer. Cap the size to allocated size for such cases.

Cc: stable@vger.kernel.org
Fixes: d96d3f30c0 ("[media] media: venus: hfi: add Venus HFI files")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
CRs-Fixed: 3947576
Change-Id: I483a5feff3dfa35dae8f444e57601d2d1d85246f
Git-commit: f4b211714bcc70effa60c34d9fa613d182e3ef1e
Git-repo: https://gitlab.freedesktop.org/linux-media/media-committers.git
Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com>
2025-03-13 23:23:50 +05:30
Vikash Garodia
11f9d2350e FROMGIT: media: venus: hfi: add check to handle incorrect queue size
qsize represents size of shared queued between driver and video
firmware. Firmware can modify this value to an invalid large value. In
such situation, empty_space will be bigger than the space actually
available. Since new_wr_idx is not checked, so the following code will
result in an OOB write.
...
qsize = qhdr->q_size

if (wr_idx >= rd_idx)
 empty_space = qsize - (wr_idx - rd_idx)
....
if (new_wr_idx < qsize) {
 memcpy(wr_ptr, packet, dwords << 2) --> OOB write

Add check to ensure qsize is within the allocated size while
reading and writing packets into the queue.

Cc: stable@vger.kernel.org
Fixes: d96d3f30c0 ("[media] media: venus: hfi: add Venus HFI files")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
CRs-Fixed: 3935673
Change-Id: Ifb907d4a4c82f853081492e06e68180476367ed5
Git-commit: 69baf245b23e20efda0079238b27fc63ecf13de1
Git-repo: https://gitlab.freedesktop.org/linux-media/media-committers.git
Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com>
2025-03-13 23:23:41 +05:30
Vikash Garodia
fd9b658c8a FROMGIT: media: venus: hfi_parser: refactor hfi packet parsing logic
words_count denotes the number of words in total payload, while data
points to payload of various property within it. When words_count
reaches last word, data can access memory beyond the total payload. This
can lead to OOB access. With this patch, the utility api for handling
individual properties now returns the size of data consumed. Accordingly
remaining bytes are calculated before parsing the payload, thereby
eliminates the OOB access possibilities.

Cc: stable@vger.kernel.org
Fixes: 1a73374a04 ("media: venus: hfi_parser: add common capability parser")
CRs-Fixed: 3935669
Change-Id: I692e4a8dea110f0650fe26e07207408087a4d19b
Git-commit: 9edaaa8e3e15aab1ca413ab50556de1975bcb329
Git-repo: https://gitlab.freedesktop.org/linux-media/media-committers.git
Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com>
2025-03-13 23:23:38 +05:30
Vikash Garodia
91f42e0f9c FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
There is a possibility that init_codecs is invoked multiple times during
manipulated payload from video firmware. In such case, if codecs_count
can get incremented to value more than MAX_CODEC_NUM, there can be OOB
access. Reset the count so that it always starts from beginning.

Cc: stable@vger.kernel.org
Fixes: 1a73374a04 ("media: venus: hfi_parser: add common capability parser")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
CRs-Fixed: 3935643
Change-Id: I6216e773af65082e4775b415789ffd549e0bed2d
Git-commit: 172bf5a9ef70a399bb227809db78442dc01d9e48
Git-repo: https://gitlab.freedesktop.org/linux-media/media-committers.git
Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com>
2025-03-13 23:22:48 +05:30
Arun Khanna
e9f5566e7e defconfig: Enable RTL8152 ETH-USB driver
Enable RTL815x Ethernet dongle support for sdxlemur.

Change-Id: I4e7f0c825ede875df28e29972827f451b04898b5
Signed-off-by: Arun Khanna <quic_arkhanna@quicinc.com>
2025-03-12 11:51:31 -07:00
Mohd Ayaan Anwar
f7f8e585ba msm: Add Kconfig for RTL8152 driver
Add a Kernel configuration option for the RTL8152 USB-to-ethernet
adapter driver.

Change-Id: If41cb9d5142acb2fc3036370c40625db9e3b51f6
Signed-off-by: Mohd Ayaan Anwar <quic_mohdayaa@quicinc.com>
2025-03-12 11:51:02 -07:00
Arun Khanna
ab7a25805b defconfig: Disable upstream RTL8152 ETH-USB driver
Disable upstream RTL815x Ethernet dongle support for sdxlemur.

Change-Id: I07115ba5127921396644952c81d1652d06df1995
Signed-off-by: Arun Khanna <quic_arkhanna@quicinc.com>
2025-03-11 11:13:24 +05:30
Kuldeep Singh
4e22be36ab qseecom: Remove virtual address print
Printing virtual address can leak kernel addresses.So remove vaddr print
to not leak kernel pointers to unprivileged users.

Change-Id: I1823573a35fb16195a20a8362a4648dc12694271
Signed-off-by: Kuldeep Singh <quic_kuldsing@quicinc.com>
2025-03-03 10:45:42 +05:30
Prashanth K
95c448e702 UPSTREAM: usb: dwc3: host: Set XHCI_SG_TRB_CACHE_SIZE_QUIRK
Upstream commit bac1ec551434 ("usb: xhci: Set quirk for
XHCI_SG_TRB_CACHE_SIZE_QUIRK") introduced a new quirk in XHCI
which fixes XHC timeout, which was seen on synopsys XHCs while
using SG buffers. But the support for this quirk isn't present
in the DWC3 layer.

We will encounter this XHCI timeout/hung issue if we run iperf
loopback tests using RTL8156 ethernet adaptor on DWC3 targets
with scatter-gather enabled. This gets resolved after enabling
the XHCI_SG_TRB_CACHE_SIZE_QUIRK. This patch enables it using
the xhci device property since its needed for DWC3 controller.

In Synopsys DWC3 databook,
Table 9-3: xHCI Debug Capability Limitations
Chained TRBs greater than TRB cache size: The debug capability
driver must not create a multi-TRB TD that describes smaller
than a 1K packet that spreads across 8 or more TRBs on either
the IN TR or the OUT TR.

Change-Id: I51c065d76939b6fc34e80dc970568ba5c9d40567
Cc: stable@vger.kernel.org #5.11
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
Acked-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Link: https://lore.kernel.org/r/20240116055816.1169821-2-quic_prashk@quicinc.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:03:30 +05:30
Prashanth K
4f6f18aa00 UPSTREAM: usb: host: xhci-plat: Add support for XHCI_SG_TRB_CACHE_SIZE_QUIRK
Upstream commit bac1ec551434 ("usb: xhci: Set quirk for
XHCI_SG_TRB_CACHE_SIZE_QUIRK") introduced a new quirk in XHCI
which fixes XHC timeout, which was seen on synopsys XHCs while
using SG buffers. Currently this quirk can only be set using
xhci private data. But there are some drivers like dwc3/host.c
which adds adds quirks using software node for xhci device.
Hence set this xhci quirk by iterating over device properties.

Change-Id: I29c31b05727851fd7c22809febc64589113bc1b9
Cc: stable@vger.kernel.org # 5.11
Fixes: bac1ec551434 ("usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK")
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
Link: https://lore.kernel.org/r/20240116055816.1169821-3-quic_prashk@quicinc.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:03:22 +05:30
Prashanth K
43e62e158f UPSTREAM: usb: xhci: Add error handling in xhci_map_urb_for_dma
Currently xhci_map_urb_for_dma() creates a temporary buffer and copies
the SG list to the new linear buffer. But if the kzalloc_node() fails,
then the following sg_pcopy_to_buffer() can lead to crash since it
tries to memcpy to NULL pointer.

So return -ENOMEM if kzalloc returns null pointer.

Change-Id: I5a2d953f8e9b2f2488f5daafdfbc7084db0ceb61
Cc: stable@vger.kernel.org # 5.11
Fixes: 2017a1e58472 ("usb: xhci: Use temporary buffer to consolidate SG")
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://lore.kernel.org/r/20240229141438.619372-10-mathias.nyman@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:03:14 +05:30
Prashanth K
ea48826815 UPSTREAM: usb: xhci: Use temporary buffer to consolidate SG
The Synopsys xHC has an internal TRB cache of size TRB_CACHE_SIZE for
each endpoint. The default value for TRB_CACHE_SIZE is 16 for SS and 8
for HS. The controller loads and updates the TRB cache from the transfer
ring in system memory whenever the driver issues a start transfer or
update transfer command.

For chained TRBs, the Synopsys xHC requires that the total amount of
bytes for all TRBs loaded in the TRB cache be greater than or equal to 1
MPS. Or the chain ends within the TRB cache (with a last TRB).

If this requirement is not met, the controller will not be able to send
or receive a packet and it will hang causing a driver timeout and error.

This can be a problem if a class driver queues SG requests with many
small-buffer entries. The XHCI driver will create a chained TRB for each
entry which may trigger this issue.

This patch adds logic to the XHCI driver to detect and prevent this from
happening.

For every (TRB_CACHE_SIZE - 2), we check the total buffer size of
the SG list and if the last window of (TRB_CACHE_SIZE - 2) SG list length
and we don't make up at least 1 MPS, we create a temporary buffer to
consolidate full SG list into the buffer.

We check at (TRB_CACHE_SIZE - 2) window because it is possible that there
would be a link and/or event data TRB that take up to 2 of the cache
entries.

We discovered this issue with devices on other platforms but have not
yet come across any device that triggers this on Linux. But it could be
a real problem now or in the future. All it takes is N number of small
chained TRBs. And other instances of the Synopsys IP may have smaller
values for the TRB_CACHE_SIZE which would exacerbate the problem.

Change-Id: I6d34805c32756c48b07be2ffa9aad72ab5af2bbe
Signed-off-by: Tejas Joglekar <joglekar@synopsys.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://lore.kernel.org/r/20201208092912.1773650-3-mathias.nyman@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:03:07 +05:30
Prashanth K
2a4f06f92c UPSTREAM: usb: xhci: Set quirk for XHCI_SG_TRB_CACHE_SIZE_QUIRK
This commit uses the private data passed by parent device
to set the quirk for Synopsys xHC. This patch fixes the
SNPS xHC hang issue when the data is scattered across
small buffers which does not make atleast MPS size for
given TRB cache size of SNPS xHC.

Change-Id: I1eb96096cfb7500b5ef4eb866170642bff0b2133
Signed-off-by: Tejas Joglekar <joglekar@synopsys.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://lore.kernel.org/r/20201208092912.1773650-2-mathias.nyman@linux.intel.com
Cc: stable <stable@vger.kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:02:57 +05:30
Prashanth K
cc93684364 defconfig: Enable RTL8152 ETH-USB driver
Enable RTL815x Ethernet dongle support for sdxlemur.

Change-Id: Ida1265bd8642af0b9211dea5cf6330d8487274b0
Signed-off-by: Prashanth K <quic_prashk@quicinc.com>
2025-02-28 10:02:54 +05:30
QCTECMDR Service
305e323055 Merge "msm: mhi_dev: Breaking memory for event request in smaller chunks" 2025-02-26 01:13:23 -08:00
Pallavi Singh
b824744c4a msm: mhi_dev: Breaking memory for event request in smaller chunks
Optimizing event buffer allocation to avoid memory allocation failure
on 512MB targets for sdx72 M.2 devices.

Change-Id: Ia2b381e71aff72fc4f5c379f7226cf0e91f069a3
Signed-off-by: Pallavi Singh <quic_pallsing@quicinc.com>
2025-02-09 22:58:05 -08:00
QCTECMDR Service
eeafe4140a Merge "msm: eva: Validating the SFR buffer size before accessing" 2025-01-22 03:41:08 -08:00
Pulkit Singh Tak
8ee6cd6bef msm: eva: Validating the SFR buffer size before accessing
To avoid any OOB write or other security issues, it's good to
validate the buffer size before accessing it.

Change-Id: Ibfdef21293c9385119cfb6338ef36e20c0fc1f2f
Signed-off-by: Pulkit Singh Tak <quic_ptak@quicinc.com>
2025-01-22 10:57:18 +05:30
Madhu Ananthula
bb8a45801d msm: eva: Copy back the validated size to avoid security issue
As we are reading the packet from a shared queue, there is a
possibility to corrupt the packet->size data of shared queue by
malicious FW after validating it in the kernel driver.

Change-Id: I9bff8f2daa64054eada37de54fe3fa837d57b22a
Signed-off-by: Aniruddh Sharma <quic_anirshar@quicinc.com>
Signed-off-by: Madhu Ananthula <quic_mananthu@quicinc.com>
2025-01-20 03:01:54 -08:00
Greg Kroah-Hartman
4c8fb32758 Merge tag 'android11-5.4.289_r00' into android11-5.4
This merges the android11-5.4.289_r00 tag into the android11-5.4 branch,
catching it up with the latest LTS releases.

It contains the following commits:

* b9aba1f4e2 Revert "netfilter: Replace zero-length array with flexible-array member"
* 196c9546b3 Revert "tracing: Constify string literal data member in struct trace_event_call"
* c32bcb5cc0 Revert "skb_expand_head() adjust skb->truesize incorrectly"
*   a85d92d704 Merge 5.4.289 into android11-5.4-lts
|\
| * 7f0e075be1 Linux 5.4.289
| * 177516053e ftrace: use preempt_enable/disable notrace macros to avoid double fault
| * 66cd37660e mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()
| * bad27f62d8 drm: adv7511: Drop dsi single lane support
| * 94b7ed0a48 net/sctp: Prevent autoclose integer overflow in sctp_association_init()
| * 9efc2a85ed sky2: Add device ID 11ab:4373 for Marvell 88E8075
| * 788d9e9a41 pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking
| * c57721b24b RDMA/uverbs: Prevent integer overflow issue
| * 213305a1cb modpost: fix the missed iteration for the max bit in do_input()
| * f072e43697 modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host
| * 6103478629 ARC: build: Try to guess GCC variant of cross compiler
| * 512929f115 irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base
| * 520e02b7fe net: usb: qmi_wwan: add Telit FE910C04 compositions
| * f960a6b5d9 bpf: fix potential error return
| * 8929492594 sound: usb: format: don't warn that raw DSD is unsupported
| * 155f6a7e0a wifi: mac80211: wake the queues in case of failure in resume
| * 1638f430f8 ila: serialize calls to nf_register_net_hooks()
| * 560cbdd26b af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
| * 66ffb0cf21 af_packet: fix vlan_get_tci() vs MSG_PEEK
| * 7b91cd2a43 ALSA: usb-audio: US16x08: Initialize array before use
| * 6889d622b1 net: llc: reset skb->transport_header
| * 352f8eaaab netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext
| * 9857e028d4 netfilter: Replace zero-length array with flexible-array member
| * 64e9f54a14 netrom: check buffer length before accessing it
| * 53425075fb drm/bridge: adv7511_audio: Update Audio InfoFrame properly
| * 6ffd9a346f drm: bridge: adv7511: Enable SPDIF DAI
| * eea3fbfcbd RDMA/bnxt_re: Fix max_qp_wrs reported
| * cddb0c59fc RDMA/bnxt_re: Fix reporting hw_ver in query_device
| * 1dcf5cb17d RDMA/bnxt_re: Add check for path mtu in modify_qp
| * 4e726e6b5f RDMA/mlx5: Enforce same type port association for multiport RoCE
| * 63e7bc7261 net/mlx5: Make API mlx5_core_is_ecpf accept const pointer
| * bb92b36156 IB/mlx5: Introduce and use mlx5_core_is_vf()
| * f091a224a2 Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
| * f45a77dd24 selinux: ignore unknown extended permissions
| * b3a3d5333c ipv6: prevent possible UAF in ip6_xmit()
| * 43e7958cf7 skb_expand_head() adjust skb->truesize incorrectly
| * 3d770d44dd btrfs: avoid monopolizing a core when activating a swap file
| * 30080cdde6 tracing: Constify string literal data member in struct trace_event_call
| * 078f7e1521 bpf: fix recursive lock when verdict program return SK_PASS
| * ae8512e93f ipv6: fix possible UAF in ip6_finish_output2()
| * 81d626b00b ipv6: use skb_expand_head in ip6_xmit
| * 1598154fd2 ipv6: use skb_expand_head in ip6_finish_output2
| * 7e13e59bf6 skbuff: introduce skb_expand_head()
| * 0d1a6cd2d7 MIPS: Probe toolchain support of -msym32
| * 59a9c2a351 epoll: Add synchronous wakeup support for ep_poll_callback
| * d738f3215b virtio-blk: don't keep queue frozen during system suspend
| * 4ed6d56e85 scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver load time
| * 436df0cfe8 platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
| * c2dae50ddb regmap: Use correct format specifier for logging range errors
| * 78afb9bfad scsi: megaraid_sas: Fix for a potential deadlock
| * de349d2382 scsi: qla1280: Fix hw revision numbering for ISP1020/1040
| * 0146a07f95 tracing/kprobe: Make trace_kprobe's module callback called after jump_label update
| * ca9818554b mtd: rawnand: fix double free in atmel_pmecc_create_user()
| * 3d229600c5 dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
| * 3e351d0279 dmaengine: mv_xor: fix child node refcount handling in early exit
| * 677e77d2b5 phy: core: Fix that API devm_phy_destroy() fails to destroy the phy
| * ce14e466d5 phy: core: Fix that API devm_phy_put() fails to release the phy
| * 696bb5ec8e phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()
| * 99ac4a47a0 phy: core: Fix an OF node refcount leakage in _of_phy_get()
| * 63055e47cf mtd: diskonchip: Cast an operand to prevent potential overflow
| * aa577b51d5 nfsd: restore callback functionality for NFSv4.0
| * 06f6b1717c bpf: Check negative offsets in __bpf_skb_min_len()
| * 035772fcd6 media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
| * f15dec32fb of: Fix refcount leakage for OF node returned by __of_get_dma_parent()
| * 24937f999b of: Fix error path in of_parse_phandle_with_args_map()
| * cb70f37c10 udmabuf: also check for F_SEAL_FUTURE_WRITE
| * 55e4baa0d3 nilfs2: prevent use of deleted inode
| * 353e49dd5d of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one()
| * 40c6a6b6bd NFS/pnfs: Fix a live lock between recalled layouts and layoutget
| * 703388839b btrfs: tree-checker: reject inline extent items with 0 ref count
| * 9202cc7852 zram: refuse to use zero sized block device as backing device
| * fa6f0fbb1c sh: clk: Fix clk_enable() to return 0 on NULL clk
| * a36572118c USB: serial: option: add Telit FE910C04 rmnet compositions
| * dfe21fb44e USB: serial: option: add MediaTek T7XX compositions
| * e3374308d2 USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
| * dafbc0d826 USB: serial: option: add MeiG Smart SLM770A
| * a678147a6b USB: serial: option: add TCL IK512 MBIM & ECM
| * dbb8df1d30 efivarfs: Fix error on non-existent file
| * e062021441 i2c: riic: Always round-up when calculating bus period
| * 8e9f1f405a chelsio/chtls: prevent potential integer overflow on 32bit
| * 4b794b6e59 mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk
| * f89fae2cd2 netfilter: ipset: Fix for recursive locking warning
| * cb743fe159 net: ethernet: bgmac-platform: fix an OF node reference leak
| * 5fcc7e6643 net: hinic: Fix cleanup in create_rxqs/txqs()
| * fe65c3e36a ionic: use ee->offset when returning sprom data
| * c9d5f2776c net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
| * 70a727901d erofs: fix incorrect symlink detection in fast symlink
| * 17a0cdbd7b erofs: fix order >= MAX_ORDER warning due to crafted negative i_size
| * 0430f13291 drm/i915: Fix memory leak by correcting cache object name in error handler
| * e00e6283e9 i2c: pnx: Fix timeout in wait functions
| * 7d7fed7f2a PCI: Add ACS quirk for Broadcom BCM5760X NIC
| * 8f9e9c8d08 ALSA: usb: Fix UBSAN warning in parse_audio_unit()
| * d41fcaa12a PCI/AER: Disable AER service on suspend
| * f413230a1f usb: dwc2: gadget: Don't write invalid mapped sg entries into dma_desc with iommu enabled
| * 44782565e1 net: sched: fix ordering of qlen adjustment
* | 4d8aad9b5e Merge 5.4.288 into android11-5.4-lts
|\|
| * e0646975af Linux 5.4.288
| * 1102fb2aa4 ALSA: usb-audio: Fix a DMA to stack memory bug
| * 20f7f0cf7a xen/netfront: fix crash when removing device
| * 20df02cb98 tracing/kprobes: Skip symbol counting logic for module symbols in create_local_trace_kprobe()
| * fb5b4d675d KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status
| * 2870cd0286 blk-iocost: Avoid using clamp() on inuse in __propagate_weights()
| * a3b64f8ac1 blk-iocost: fix weight updates of inner active iocgs
| * 24075e3895 blk-iocost: clamp inuse and skip noops in __propagate_weights()
| * 8c29e7ece6 ACPICA: events/evxfregn: don't release the ContextMutex that was never acquired
| * 83c6ab12f0 net/sched: netem: account for backlog updates from child qdisc
| * 26a5f515ef qca_spi: Make driver probing reliable
| * f07818a854 qca_spi: Fix clock speed for multiple QCA7000
| * 0e7585572a ACPI: resource: Fix memory resource type union access
| * 3aa2ef7ffd net: lapb: increase LAPB_HEADER_LEN
| * d1d4dfb189 tipc: fix NULL deref in cleanup_bearer()
| * 89d94cf7a7 batman-adv: Do not let TT changes list grows indefinitely
| * 0d2fbae5f5 batman-adv: Remove uninitialized data in full table TT response
| * 860e733982 batman-adv: Do not send uninitialized TT changes
| * 1b0d7e51ac bpf, sockmap: Fix update element with same
| * 0520483177 xfs: don't drop errno values when we fail to ficlone the entire range
| * 4efdfdc32d usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer
| * 357219c16f usb: ehci-hcd: fix call balance of clocks handling routines
| * 2da6e4d35d usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature
| * efd985332e ata: sata_highbank: fix OF node reference leak in highbank_initialize_phys()
| * d4b2afe2fa usb: host: max3421-hcd: Correctly abort a USB request.
* | d93411f753 Revert "cgroup: Make operations on the cgroup root_list RCU safe"
* | 0f76afd374 Revert "cgroup: Move rcu_head up near the top of cgroup_root"
* | ad8d63bdc6 Merge 5.4.287 into android11-5.4-lts
|\|
| * 6708005a36 Linux 5.4.287
| * 7eb794e1a9 bpf, xdp: Update devmap comments to reflect napi/rcu usage
| * a632bdcb35 ALSA: usb-audio: Fix out of bounds reads when finding clock sources
| * 4fed24bf45 PCI: rockchip-ep: Fix address translation unit programming
| * e0e1cde240 Revert "drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()"
| * 42c5ed5252 modpost: Add .irqentry.text to OTHER_SECTIONS
| * 89236868a1 ocfs2: Revert "ocfs2: fix the la space leak when unmounting an ocfs2 volume"
| * 54832216f1 jffs2: Fix rtime decompressor
| * 421f9e9f0f jffs2: Prevent rtime decompress memory corruption
| * 4098c94097 KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
| * 0ba044be2b KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
| * 3c6c631f28 KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
| * c0978ecb28 perf/x86/intel/pt: Fix buffer full but size is 0 case
| * 119f470a31 Revert "unicode: Don't special case ignorable code points"
| * 0f170e91d3 bpf: fix OOB devmap writes when deleting elements
| * 8b69c887f1 xdp: Simplify devmap cleanup
| * 9ab3a1aaa5 misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
| * 0b94d83801 powerpc/prom_init: Fixup missing powermac #size-cells
| * e99a36ed0c usb: chipidea: udc: handle USB Error Interrupt if IOC not set
| * 9a2173660e i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock
| * 44c73d8f4f PCI: Add ACS quirk for Wangxun FF5xxx NICs
| * 88da5d46b6 PCI: Add 'reset_subordinate' to reset hierarchy below bridge
| * ac8aaf78bd f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
| * 77ae53c490 nvdimm: rectify the illogical code within nd_dax_probe()
| * 61b32d4af7 pinctrl: qcom-pmic-gpio: add support for PM8937
| * 631c1e6b68 scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset
| * e6e6045f86 scsi: st: Don't modify unknown block number in MTIOCGET
| * 84b42d5b5f leds: class: Protect brightness_show() with led_cdev->led_access mutex
| * c67aeff289 tracing: Use atomic64_inc_return() in trace_clock_counter()
| * 383833f04c netpoll: Use rcu_access_pointer() in __netpoll_setup
| * 6978e400bf net/neighbor: clear error in case strict check is not set
| * cf0d36cf00 rocker: fix link status detection in rocker_carrier_init()
| * 97ecf3dbdd ASoC: hdmi-codec: reorder channel allocation list
| * 802216bc7b Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables
| * 342f87d263 wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()
| * d336bf8680 wifi: ipw2x00: libipw_rx_any(): fix bad alignment
| * b5807a0895 drm/amdgpu: set the right AMDGPU sg segment limitation
| * b15000bcbe jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
| * b62f41aeec jfs: fix array-index-out-of-bounds in jfs_readdir
| * bbb24ce7f0 jfs: fix shift-out-of-bounds in dbSplit
| * 25f1e673ef jfs: array-index-out-of-bounds fix in dtReadFirst
| * 685ee05004 wifi: ath5k: add PCI ID for Arcadyan devices
| * b10be84272 wifi: ath5k: add PCI ID for SX76X
| * f2709d1271 net: inet6: do not leave a dangling sk pointer in inet6_create()
| * f8a3f255f7 net: inet: do not leave a dangling sk pointer in inet_create()
| * 1d5fe782c0 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
| * 884ae8bcee net: af_can: do not leave a dangling sk pointer in can_create()
| * f6ad641646 Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()
| * 71b22837a5 af_packet: avoid erroring out after sock_init_data() in packet_create()
| * 4803d81373 net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
| * fb5b3a35c6 net: ethernet: fs_enet: Use %pa to format resource_size_t
| * e0e2dabcf0 net: fec_mpc52xx_phy: Use %pa to format resource_size_t
| * c2c01ee592 samples/bpf: Fix a resource leak
| * cb8ae56d73 drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check()
| * 4c245d6d19 drm/mcde: Enable module autoloading
| * 920c9149bd drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
| * 30af4d9845 media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108
| * a6ba781b0b media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera
| * 238e3af849 s390/cpum_sf: Handle CPU hotplug remove during sampling
| * 4eb49404de mmc: core: Further prevent card detect during shutdown
| * f44895aa11 regmap: detach regmap from dev on regmap_exit
| * 83df6a591a dma-buf: fix dma_fence_array_signaled v4
| * 4379c58284 bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again
| * 09d6d05579 nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()
| * 0bdf3905cd scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt
| * ad7556f1b8 scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
| * 541236f95a scsi: qla2xxx: Fix NVMe and NPIV connect issue
| * 4f394bf499 ocfs2: update seq_file index in ocfs2_dlm_seq_next
| * a1c78bcc70 tracing: Fix cmp_entries_dup() to respect sort() comparison rules
| * d031eef3cc HID: wacom: fix when get product name maybe null pointer
| * f247471e3a bpf: Fix exact match conditions in trie_get_next_key()
| * 50e06cbb60 bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie
| * 911fcc95b5 ocfs2: free inode when ocfs2_get_init_inode() fails
| * d0cde3911c spi: mpc52xx: Add cancel_work_sync before module remove
| * 905d82e6e7 tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
| * 079484a928 drm/sti: Add __iomem for mixer_dbg_mxn's parameter
| * 53ff0caa6a gpio: grgpio: Add NULL check in grgpio_probe
| * c2d1bc4163 gpio: grgpio: use a helper variable to store the address of ofdev->dev
| * eb30e6b51a crypto: x86/aegis128 - access 32-bit arguments as 32-bit
| * 7475e47200 x86/asm: Reorder early variables
| * 87106169b4 xen: Fix the issue of resource not being properly released in xenbus_dev_probe()
| * 1c264dd643 xen/xenbus: fix locking
| * 7c138d1284 xenbus/backend: Protect xenbus callback with lock
| * bae18180aa xenbus/backend: Add memory pressure handler callback
| * 892ad83f20 xen/xenbus: reference count registered modules
| * 98d62cf0e2 netfilter: nft_set_hash: skip duplicated elements pending gc run
| * e5e2d30247 netfilter: ipset: Hold module reference while requesting a module
| * 4458046617 igb: Fix potential invalid memory access in igb_init_module()
| * 5cabe42ead net/qed: allow old cards not supporting "num_images" to work
| * 4e69457f9d tipc: Fix use-after-free of kernel socket in cleanup_bearer().
| * bd09e2482d tipc: add new AEAD key structure for user API
| * 0b8f0026bb tipc: enable creating a "preliminary" node
| * 6b7fbc30ec tipc: add reference counter to bearer
| * 623be080ab dccp: Fix memory leak in dccp_feat_change_recv
| * a95808252e net/ipv6: release expired exception dst cached in socket
| * 224e606a8d can: j1939: j1939_session_new(): fix skb reference counting
| * dfc2e58028 net/sched: tbf: correct backlog statistic for GSO packets
| * 147a42bb02 netfilter: x_tables: fix LED ID check in led_tg_check()
| * 31d1ddc1ce ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init()
| * 9c6c2d0d43 can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
| * f8138cba7b can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL
| * 5ba0a19a6f watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart()
| * b467087053 iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
| * f145c9924c drm/etnaviv: flush shader L1 cache after user commandstream
| * a85364f0d3 nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
| * e2fa0d0e32 nfsd: make sure exp active before svc_export_show
| * c470d6194f dm thin: Add missing destroy_work_on_stack()
| * c2f0ce2411 i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()
| * 7cd787499d util_macros.h: fix/rework find_closest() macros
| * 18fb33df1d ad7780: fix division by zero in ad7780_write_raw()
| * a42d050d07 clk: qcom: gcc-qcs404: fix initial rate of GPLL3
| * 43ca32ce12 ftrace: Fix regression with module command in stack_trace_filter
| * f9248e2f73 ovl: Filter invalid inodes with missing lookup function
| * cf642904be media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()
| * 6ef14ba50a media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate()
| * 214db0ab96 media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled
| * ced1c04e82 media: ts2020: fix null-ptr-deref in ts2020_probe()
| * 13193a97dd media: i2c: tc358743: Fix crash in the probe error path when using polling
| * dfb9fe7de6 btrfs: ref-verify: fix use-after-free after invalid ref action
| * a5abba5e0e quota: flush quota_release_work upon quota writeback
| * 21fd6b2f0e ASoC: fsl_micfil: fix the naming style for mask definition
| * d8de818df1 sh: intc: Fix use-after-free bug in register_intc_controller()
| * cc91d59d34 sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
| * e89ac70361 SUNRPC: Replace internal use of SOCKWQ_ASYNC_NOSPACE
| * 768df674c5 SUNRPC: correct error code comment in xs_tcp_setup_socket()
| * 3c5c4d1216 modpost: remove incorrect code in do_eisa_entry()
| * 4c54ffc23b rtc: ab-eoz9: don't fail temperature reads on undervoltage notification
| * d74b4b2970 9p/xen: fix release of IRQ
| * be216f99df 9p/xen: fix init sequence
| * 847d94e60e block: return unsigned int from bdev_io_min
| * f4f31bd51e jffs2: fix use of uninitialized variable
| * daac4aa182 ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
| * 871c148f8e ubi: fastmap: Fix duplicate slab cache names while attaching
| * f1f685b3dd ubifs: Correct the total block count by deducting journal reservation
| * 44b3257ff7 rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
| * 1a7d4c093b rtc: abx80x: Fix WDT bit position of the status register
| * 0bce88e065 rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
| * 7bf6bf130a NFSv4.0: Fix a use-after-free problem in the asynchronous open()
| * 9e497ef3a6 um: Always dump trace for specified task in show_stack
| * 115e3e51b1 um: Clean up stacktrace dump
| * abf08999d9 um: add show_stack_loglvl()
| * 3103837c50 um/sysrq: remove needless variable sp
| * ea8b2f3718 um: Fix the return value of elf_core_copy_task_fpregs
| * 5c710f4581 um: Fix potential integer overflow during physmem setup
| * 5398de330c rpmsg: glink: Propagate TX failures in intentless mode as well
| * e9be26735d SUNRPC: make sure cache entry active before cache_show
| * 90adbae9dd NFSD: Prevent a potential integer overflow
| * af1db93c94 lib: string_helpers: silence snprintf() output truncation warning
| * a70316b52e usb: dwc3: gadget: Fix checking for number of TRBs left
| * 2a9cbaeb4c ALSA: hda/realtek: Apply quirk for Medion E15433
| * 7f57353abc ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max
| * 937a94c977 ALSA: hda/realtek: Set PCBeep to default value for ALC274
| * 2be4e4fe88 ALSA: hda/realtek: Update ALC225 depop procedure
| * 3c818ad07e media: wl128x: Fix atomicity violation in fmc_send_cmd()
| * c8e5e170d9 HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
| * 383455a9aa block: fix ordering between checking BLK_MQ_S_STOPPED request adding
| * 25ace006e9 arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled
| * f8f26cf690 sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK
| * 376c7f0beb um: vector: Do not use drvdata in release
| * 7b5e40abd1 serial: 8250: omap: Move pm_runtime_get_sync
| * 8d9d174d3f um: net: Do not use drvdata in release
| * 300e277e46 um: ubd: Do not use drvdata in release
| * 7cf819ea37 ubi: wl: Put source PEB into correct list if trying locking LEB failed
| * 2afe950e49 spi: Fix acpi deferred irq probe
| * 78b0f2028f netfilter: ipset: add missing range check in bitmap_ip_uadt
| * 2d64a005ba Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon exit"
| * 0fd14b63fa serial: sh-sci: Clean sci_ports[0] after at earlycon exit
| * eff104b29c Revert "usb: gadget: composite: fix OS descriptors w_value logic"
| * 37fb0fd3fb Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
| * 1ebbcaf0d5 tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
| * 57f048c2d2 comedi: Flush partial mappings in error case
| * d0ddd2c92b PCI: Fix use-after-free of slot->bus on hot remove
| * 02ca7b6027 ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
| * 6e39b681d1 jfs: xattr: check invalid xattr size more strictly
| * dc331ed4cc ext4: fix FS_IOC_GETFSMAP handling
| * 56b8416193 ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
| * 9b8460a2a7 ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
| * f7b0952a70 soc: qcom: socinfo: fix revision check in qcom_socinfo_probe()
| * 047f0ee8b5 cgroup: Move rcu_head up near the top of cgroup_root
| * 92f6ebead8 cgroup: Make operations on the cgroup root_list RCU safe
| * a35767ab80 usb: ehci-spear: fix call balance of sehci clk handling routines
| * 2c312ab8f2 apparmor: fix 'Do simple duplicate message elimination'
| * d6de1aaa0f staging: greybus: uart: clean up TIOCGSERIAL
| * aabb00874a misc: apds990x: Fix missing pm_runtime_disable()
| * 7aacc23608 USB: chaoskey: Fix possible deadlock chaoskey_list_lock
| * a6b88ed51e USB: chaoskey: fail open after removal
| * bcb28ed2e1 usb: yurex: make waiting on yurex_write interruptible
| * 516e667442 usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
| * b4ccc582ef ipmr: fix tables suspicious RCU usage
| * 59be0c8afc ipmr: convert /proc handlers to rcu_read_lock()
| * 5743a2db46 net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
| * 9be33a1eb0 marvell: pxa168_eth: fix call balance of pep->clk handling routines
| * d720e8ccc2 net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration
| * 1604c6d440 tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
| * 7b99620a9f net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
| * c423afa170 power: supply: core: Remove might_sleep() from power_supply_put()
| * 7d121f66b6 vfio/pci: Properly hide first-in-list PCIe extended capability
| * d68d5f63b6 NFSD: Fix nfsd4_shutdown_copy()
| * c6dc01d04c NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
| * cac1405e3f NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
| * 68c3b7cdef rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
| * 83f8eb3280 rpmsg: glink: Fix GLINK command prefix
| * 6094d8c3d2 rpmsg: glink: Send READ_NOTIFY command in FIFO full case
| * 4e318b935d rpmsg: glink: Add TX_DATA_CONT command while sending
| * 82137bab80 perf trace: Avoid garbage when not printing a syscall's arguments
| * e2956feece perf trace: Do not lose last events in a race
| * 7a78e2865a m68k: coldfire/device.c: only build FEC when HW macros are defined
| * 32d587a538 m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x
| * 5ad6ca7662 PCI: cpqphp: Fix PCIBIOS_* return value confusion
| * d8392686ad PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
| * 25b338db0c perf probe: Correct demangled symbols in C++ program
| * 1ed167325c perf cs-etm: Don't flush when packet_queue fills up
| * b106f718fc clk: clk-axi-clkgen: make sure to enable the AXI bus clock
| * 31fe8bc84b clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand
| * 17aad93e2b dt-bindings: clock: axi-clkgen: include AXI clk
| * 80d2319709 dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format
| * d48cbfa90d fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
| * dd3a6d5441 fbdev/sh7760fb: Alloc DMA memory from hardware device
| * 1403e7b10c powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static
| * f4078ef38d ocfs2: fix uninitialized value in ocfs2_file_read_iter()
| * eaf92fad1f scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
| * 97384449dd scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()
| * c7da99b2d4 scsi: fusion: Remove unused variable 'rc'
| * 3932c753f8 scsi: bfa: Fix use-after-free in bfad_im_module_exit()
| * 5ea4b832b5 mfd: rt5033: Fix missing regmap_del_irq_chip()
| * 171bb5aefc RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
| * 22fbbc37ed mtd: rawnand: atmel: Fix possible memory leak
| * b3617ac6aa cpufreq: loongson2: Unregister platform_driver on failure
| * 6ea17c03ed mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
| * b7c7c400de mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
| * 0997e77c51 mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
| * 851f94e403 mfd: intel_soc_pmic_bxtwc: Use dev_err_probe()
| * a4eb13644d mfd: da9052-spi: Change read-mask to write-mask
| * 321d24f9a5 mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race
| * 7022d187cb powerpc/vdso: Flag VDSO64 entry points as functions
| * 598b156722 trace/trace_event_perf: remove duplicate samples on the first tracepoint event
| * 85cf038c39 netpoll: Use rcu_access_pointer() in netpoll_poll_lock
| * 273eec2346 ALSA: 6fire: Release resources at card release
| * ebad462eec ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
| * 75f418b249 ALSA: us122l: Use snd_card_free_when_closed() at disconnection
| * 71d55e19fe net: rfkill: gpio: Add check for clk_enable()
| * cb158d79b1 selftests: net: really check for bg process completion
| * 3d106b2f9f bpf, sockmap: Fix sk_msg_reset_curr
| * d3f5763b30 bpf, sockmap: Several fixes to bpf_msg_pop_data
| * 962932ee62 bpf, sockmap: Several fixes to bpf_msg_push_data
| * 2cc97daab5 drm/etnaviv: hold GPU lock across perfmon sampling
| * b8132704a6 drm/etnaviv: fix power register offset on GC300
| * b8777d076e drm/etnaviv: dump: fix sparse warnings
| * 41c7200d66 drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
| * 8b49ea3418 drm/panfrost: Remove unused id_mask from struct panfrost_model
| * 1de0ca1d73 wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()
| * de94dc8a1f bpf: Fix the xdp_adjust_tail sample prog issue
| * 7913bf6f8c ASoC: fsl_micfil: fix regmap_write_bits usage
| * c5cde68215 ASoC: fsl_micfil: use GENMASK to define register bit fields
| * d7b49f67c7 ASoC: fsl_micfil: do not define SHIFT/MASK for single bits
| * f8fe5b13ab ASoC: fsl_micfil: Drop unnecessary register read
| * 50383e18bf dt-bindings: vendor-prefixes: Add NeoFidelity, Inc
| * 22e700ee09 drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
| * d766e4dfae wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
| * 0e720766e0 wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq()
| * 6dfbea145a drm/omap: Fix locking in omap_gem_new_dmabuf()
| * cb480ae80f wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
| * 5665bb4371 drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
| * 8be4e51f3e firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
| * 3491404405 regmap: irq: Set lockdep class for hierarchical IRQ domains
| * a6e1387e9f ARM: dts: cubieboard4: Fix DCDC5 regulator constraints
| * 6f0093c15f tpm: fix signed/unsigned bug when checking event logs
| * 2fc27a7fc5 efi/tpm: Pass correct address to memblock_reserve
| * 5ad7dc9748 mmc: mmc_spi: drop buggy snprintf()
| * 7a3465b79e soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
| * 6ebcbacbcf soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
| * 054de36e91 time: Fix references to _msecs_to_jiffies() handling of values
| * 3428cc5047 crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
| * 75e1e38e5d crypto: bcm - add error check in the ahash_hmac_init function
| * 2d721b961d crypto: cavium - Fix the if condition to exit loop after timeout
| * fca8aed122 crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY
| * adadb7167a EDAC/fsl_ddr: Fix bad bit shift operations
| * 8cc31cfa36 EDAC/bluefield: Fix potential integer overflow
| * de5d5b84a6 firmware: google: Unregister driver_info on failure
| * 659e78fe61 firmware: google: Unregister driver_info on failure and exit in gsmi
| * f57725bcc5 hfsplus: don't query the device logical block size multiple times
| * b76579701b s390/syscalls: Avoid creation of arch/arch/ directory
| * 52a1c2242e acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()
| * b3b2838426 m68k: mvme147: Reinstate early console
| * 83ba8219bf m68k: mvme16x: Add and use "mvme16x.h"
| * f1441a0dce m68k: mvme147: Fix SCSI controller IRQ numbers
| * ac22240540 nvme-pci: fix freeing of the HMB descriptor table
| * c509b1acbd initramfs: avoid filename buffer overrun
| * 30608827e8 mips: asm: fix warning when disabling MIPS_FP_SUPPORT
| * b214a6dd48 x86/xen/pvh: Annotate indirect branch as safe
| * 7f591ed125 nvme: fix metadata handling in nvme-passthrough
| * ab64809049 NFSD: Force all NFSv4.2 COPY requests to be synchronous
| * 7b222d6cb8 cifs: Fix buffer overflow when parsing NFS reparse points
| * bdd8bfe75d ipmr: Fix access to mfc_cache_list without lock held
| * bff0f725c7 proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
| * 1c3c3d8177 ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div()
| * 05fc0c3d6f ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate()
| * 43cec71ce2 regulator: rk808: Add apply_bit for BUCK3 on RK809
| * e5137997b8 soc: qcom: Add check devm_kasprintf() returned value
| * 3b084fe40c net: usb: qmi_wwan: add Quectel RG650V
| * ffa5b6230a x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB
| * cb3309b9ae ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
| * 50c946b263 selftests/watchdog-test: Fix system accidentally reset after watchdog-test
| * a862a826cb mac80211: fix user-power when emulating chanctx
| * ab38b9267f ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet
| * a3c65022d8 mm: revert "mm: shmem: fix data-race in shmem_getattr()"
| * b8a78600ce kbuild: Use uname for LINUX_COMPILE_HOST detection
| * e3439cc573 media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set
| * 47693ba35b Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
| * 0ce59fb1c7 nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
| * a3abb97830 ocfs2: fix UBSAN warning in ocfs2_verify_volume()
| * 6438f3f42c nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
| * c3742319d0 KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
| * 5ae8cc0b0c ocfs2: uncache inode which has failed entering the group
| * a0ddb20a74 net/mlx5e: kTLS, Fix incorrect page refcounting
| * 0d568258f9 net/mlx5: fs, lock FTE when checking if active
| * 598c956b62 netlink: terminate outstanding dump on socket close
* 4ed1e6725b Merge branch 'android11-5.4' into android11-5.4-lts

Change-Id: I6fbef186b3de42a158c8ad0e8a06de08f08e6509
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-01-17 09:32:49 +00:00
joann_liu
bf5b85fe24 ANDROID: GKI: add Trimble symbol list
Add symbol list for cdc_mbim.ko and qmi_wwan.ko

Leaf changes summary: 3 artifacts changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 3 Added functions
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

3 Added functions:

  [A] 'function void in6_dev_finish_destroy(inet6_dev*)'
  [A] 'function void netdev_stats_to_stats64(rtnl_link_stats64*, const net_device_stats*)'
  [A] 'function net_device* netdev_upper_get_next_dev_rcu(net_device*, list_head**)'

Bug: 390219540
Change-Id: I9ea4615f36b1e9ec89d2f8247eafae6f0fdb0778
Signed-off-by: joann_liu <joann_liu@pegatroncorp.com>
2025-01-16 06:41:15 -08:00
Thiébaud Weksteen
4cd26955b0 UPSTREAM: selinux: ignore unknown extended permissions
commit 900f83cf376bdaf798b6f5dcb2eae0c822e908b6 upstream.

When evaluating extended permissions, ignore unknown permissions instead
of calling BUG(). This commit ensures that future permissions can be
added without interfering with older kernels.

Cc: stable@vger.kernel.org
Fixes: fa1aa143ac ("selinux: extended permissions for ioctls")
Signed-off-by: Thiébaud Weksteen <tweek@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Acked-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Thiébaud Weksteen <tweek@google.com>
Change-Id: I1689d8c5084a24c1a34ef3d15d71f8cfa4122447
2025-01-16 00:50:13 -08:00
Heegon Lee
1194f08d5c ANDROID: ABI: Update allowed list for galaxy
Leaf changes summary: 1 artifact changed
Changed leaf types summary: 0 leaf type changed
Removed/Changed/Added functions summary: 0 Removed, 0 Changed, 1 Added function
Removed/Changed/Added variables summary: 0 Removed, 0 Changed, 0 Added variable

1 Added function:

  [A] 'function int usb_driver_set_configuration(usb_device*, int)'

Bug: 390078050
Change-Id: I2c3b389c4b0032b877f1c6112695eff296b6a68e
Signed-off-by: Heegon Lee <heegon.lee@samsung.com>
2025-01-15 17:23:38 +09:00
Greg Kroah-Hartman
b9aba1f4e2 Revert "netfilter: Replace zero-length array with flexible-array member"
This reverts commit 9857e028d4 which is
commit 6daf14140129d30207ed6a0a69851fa6a3636bda upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I72ea16907de19ad38a993363ae45bab25f67d57a
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-01-14 17:17:17 +00:00
Greg Kroah-Hartman
196c9546b3 Revert "tracing: Constify string literal data member in struct trace_event_call"
This reverts commit 30080cdde6 which is
commit 452f4b31e3f70a52b97890888eeb9eaa9a87139a upstream.

It breaks the Android kernel abi and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: Ib63a284c6a02575a89f533f77da910de420989a7
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-01-13 09:47:29 +00:00
Greg Kroah-Hartman
c32bcb5cc0 Revert "skb_expand_head() adjust skb->truesize incorrectly"
This reverts commit 43e7958cf7 which is
commit 7f678def99d29c520418607509bb19c7fc96a6db upstream.

It breaks the Android kernel build and can be brought back in the future
in an abi-safe way if it is really needed.

Bug: 161946584
Change-Id: I21417bd6cf13432836618e2c0be84c79a9998b60
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-01-10 09:20:55 +00:00
Greg Kroah-Hartman
a85d92d704 This is the 5.4.289 stable release
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmd/v80ACgkQONu9yGCS
 aT6efw//UHOD4GORAmNhbC5i1A7+anJJpafHEDDb3f7yYpPsAeZMo3wS1zXesoIl
 1x3aSBAUW6651gpO7FMQx16VMl9gtF2LRYtQomVvyqIi53a2XvZUGdmhnZBaXfNz
 F7EX4bn3/wKtYfEC0buDCBzFZUzsLLnkwpiIwzMWymZsHS/lMvu9F+Ap240gy3MG
 60ikjLpWbkrmfgJVHHKn+xeTUp8ikqDsx9JW+VYAqBENUr6+ZKZxKgo8SNh+Z+3n
 xk39Rq/hzXyMtsQR7s8+3QSCJoh6VYhl7l6yvGYZ+BW8BKpqDl4lcKxiNUPUFjXL
 mSk9AISKMUnBiPKQmhK0Yewns8aX0qIdLpZiUoSg+Ul+hlBf1bD//0AvJZ7A8kT0
 I7s8OiemcrVMTW0m9HzY6XAgXhF9TutbrHTBn8IjDunQGz6Rz1pBsk7ka6boHf9K
 6Cxb/VcsB3OsZGzVc7wULCVki5PWSRbQ4AklmCSlLnbMC8saVTkvH5cd0b6CeCB9
 HJzZC4N77nUHUpRLz9ybu+bZFlJAwsXLrz84c50oU8RYSOPwIWOYsJgOmEpy1gbx
 THGLBhs6xCdzOUB4deRS9MXcVDzLvVo5qcT7XAnVABz2XULfEPN1aD2ZbBsxQoxU
 KIkmryxsohsLkomIxzSZHRTHptHCL+qtAPkDb0OgRkINlBb3Gbw=
 =5mLz
 -----END PGP SIGNATURE-----

Merge 5.4.289 into android11-5.4-lts

Changes in 5.4.289
	net: sched: fix ordering of qlen adjustment
	usb: dwc2: gadget: Don't write invalid mapped sg entries into dma_desc with iommu enabled
	PCI/AER: Disable AER service on suspend
	ALSA: usb: Fix UBSAN warning in parse_audio_unit()
	PCI: Add ACS quirk for Broadcom BCM5760X NIC
	i2c: pnx: Fix timeout in wait functions
	drm/i915: Fix memory leak by correcting cache object name in error handler
	erofs: fix order >= MAX_ORDER warning due to crafted negative i_size
	erofs: fix incorrect symlink detection in fast symlink
	net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
	ionic: use ee->offset when returning sprom data
	net: hinic: Fix cleanup in create_rxqs/txqs()
	net: ethernet: bgmac-platform: fix an OF node reference leak
	netfilter: ipset: Fix for recursive locking warning
	mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk
	chelsio/chtls: prevent potential integer overflow on 32bit
	i2c: riic: Always round-up when calculating bus period
	efivarfs: Fix error on non-existent file
	USB: serial: option: add TCL IK512 MBIM & ECM
	USB: serial: option: add MeiG Smart SLM770A
	USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
	USB: serial: option: add MediaTek T7XX compositions
	USB: serial: option: add Telit FE910C04 rmnet compositions
	sh: clk: Fix clk_enable() to return 0 on NULL clk
	zram: refuse to use zero sized block device as backing device
	btrfs: tree-checker: reject inline extent items with 0 ref count
	NFS/pnfs: Fix a live lock between recalled layouts and layoutget
	of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one()
	nilfs2: prevent use of deleted inode
	udmabuf: also check for F_SEAL_FUTURE_WRITE
	of: Fix error path in of_parse_phandle_with_args_map()
	of: Fix refcount leakage for OF node returned by __of_get_dma_parent()
	media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
	bpf: Check negative offsets in __bpf_skb_min_len()
	nfsd: restore callback functionality for NFSv4.0
	mtd: diskonchip: Cast an operand to prevent potential overflow
	phy: core: Fix an OF node refcount leakage in _of_phy_get()
	phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()
	phy: core: Fix that API devm_phy_put() fails to release the phy
	phy: core: Fix that API devm_phy_destroy() fails to destroy the phy
	dmaengine: mv_xor: fix child node refcount handling in early exit
	dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
	mtd: rawnand: fix double free in atmel_pmecc_create_user()
	tracing/kprobe: Make trace_kprobe's module callback called after jump_label update
	scsi: qla1280: Fix hw revision numbering for ISP1020/1040
	scsi: megaraid_sas: Fix for a potential deadlock
	regmap: Use correct format specifier for logging range errors
	platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
	scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver load time
	virtio-blk: don't keep queue frozen during system suspend
	epoll: Add synchronous wakeup support for ep_poll_callback
	MIPS: Probe toolchain support of -msym32
	skbuff: introduce skb_expand_head()
	ipv6: use skb_expand_head in ip6_finish_output2
	ipv6: use skb_expand_head in ip6_xmit
	ipv6: fix possible UAF in ip6_finish_output2()
	bpf: fix recursive lock when verdict program return SK_PASS
	tracing: Constify string literal data member in struct trace_event_call
	btrfs: avoid monopolizing a core when activating a swap file
	skb_expand_head() adjust skb->truesize incorrectly
	ipv6: prevent possible UAF in ip6_xmit()
	selinux: ignore unknown extended permissions
	Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
	IB/mlx5: Introduce and use mlx5_core_is_vf()
	net/mlx5: Make API mlx5_core_is_ecpf accept const pointer
	RDMA/mlx5: Enforce same type port association for multiport RoCE
	RDMA/bnxt_re: Add check for path mtu in modify_qp
	RDMA/bnxt_re: Fix reporting hw_ver in query_device
	RDMA/bnxt_re: Fix max_qp_wrs reported
	drm: bridge: adv7511: Enable SPDIF DAI
	drm/bridge: adv7511_audio: Update Audio InfoFrame properly
	netrom: check buffer length before accessing it
	netfilter: Replace zero-length array with flexible-array member
	netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext
	net: llc: reset skb->transport_header
	ALSA: usb-audio: US16x08: Initialize array before use
	af_packet: fix vlan_get_tci() vs MSG_PEEK
	af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
	ila: serialize calls to nf_register_net_hooks()
	wifi: mac80211: wake the queues in case of failure in resume
	sound: usb: format: don't warn that raw DSD is unsupported
	bpf: fix potential error return
	net: usb: qmi_wwan: add Telit FE910C04 compositions
	irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base
	ARC: build: Try to guess GCC variant of cross compiler
	modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host
	modpost: fix the missed iteration for the max bit in do_input()
	RDMA/uverbs: Prevent integer overflow issue
	pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking
	sky2: Add device ID 11ab:4373 for Marvell 88E8075
	net/sctp: Prevent autoclose integer overflow in sctp_association_init()
	drm: adv7511: Drop dsi single lane support
	mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()
	ftrace: use preempt_enable/disable notrace macros to avoid double fault
	Linux 5.4.289

Change-Id: I2fe8ada5386224ce16b22d4e1eff016656be40f3
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2025-01-10 07:30:07 +00:00
Greg Kroah-Hartman
7f0e075be1 Linux 5.4.289
Link: https://lore.kernel.org/r/20250106151128.686130933@linuxfoundation.org
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Linux Kernel Functional Testing <lkft@linaro.org>
Tested-by: Shuah Khan <skhan@linuxfoundation.org>
Tested-by: kernelci.org bot <bot@kernelci.org>
Tested-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Koichiro Den
177516053e ftrace: use preempt_enable/disable notrace macros to avoid double fault
Since the backport commit eea46baf14 ("ftrace: Fix possible
use-after-free issue in ftrace_location()") on linux-5.4.y branch, the
old ftrace_int3_handler()->ftrace_location() path has included
rcu_read_lock(), which has mcount location inside and leads to potential
double fault.

Replace rcu_read_lock/unlock with preempt_enable/disable notrace macros
so that the mcount location does not appear on the int3 handler path.

This fix is specific to linux-5.4.y branch, the only branch still using
ftrace_int3_handler with commit e60b613df8b6 ("ftrace: Fix possible
use-after-free issue in ftrace_location()") backported. It also avoids
the need to backport the code conversion to text_poke() on this branch.

Reported-by: Koichiro Den <koichiro.den@canonical.com>
Closes: https://lore.kernel.org/all/74gjhwxupvozwop7ndhrh7t5qeckomt7yqvkkbm5j2tlx6dkfk@rgv7sijvry2k
Fixes: eea46baf14 ("ftrace: Fix possible use-after-free issue in ftrace_location()") # linux-5.4.y
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Koichiro Den <koichiro.den@canonical.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Seiji Nishikawa
66cd37660e mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()
commit 6aaced5abd32e2a57cd94fd64f824514d0361da8 upstream.

The task sometimes continues looping in throttle_direct_reclaim() because
allow_direct_reclaim(pgdat) keeps returning false.

 #0 [ffff80002cb6f8d0] __switch_to at ffff8000080095ac
 #1 [ffff80002cb6f900] __schedule at ffff800008abbd1c
 #2 [ffff80002cb6f990] schedule at ffff800008abc50c
 #3 [ffff80002cb6f9b0] throttle_direct_reclaim at ffff800008273550
 #4 [ffff80002cb6fa20] try_to_free_pages at ffff800008277b68
 #5 [ffff80002cb6fae0] __alloc_pages_nodemask at ffff8000082c4660
 #6 [ffff80002cb6fc50] alloc_pages_vma at ffff8000082e4a98
 #7 [ffff80002cb6fca0] do_anonymous_page at ffff80000829f5a8
 #8 [ffff80002cb6fce0] __handle_mm_fault at ffff8000082a5974
 #9 [ffff80002cb6fd90] handle_mm_fault at ffff8000082a5bd4

At this point, the pgdat contains the following two zones:

        NODE: 4  ZONE: 0  ADDR: ffff00817fffe540  NAME: "DMA32"
          SIZE: 20480  MIN/LOW/HIGH: 11/28/45
          VM_STAT:
                NR_FREE_PAGES: 359
        NR_ZONE_INACTIVE_ANON: 18813
          NR_ZONE_ACTIVE_ANON: 0
        NR_ZONE_INACTIVE_FILE: 50
          NR_ZONE_ACTIVE_FILE: 0
          NR_ZONE_UNEVICTABLE: 0
        NR_ZONE_WRITE_PENDING: 0
                     NR_MLOCK: 0
                    NR_BOUNCE: 0
                   NR_ZSPAGES: 0
            NR_FREE_CMA_PAGES: 0

        NODE: 4  ZONE: 1  ADDR: ffff00817fffec00  NAME: "Normal"
          SIZE: 8454144  PRESENT: 98304  MIN/LOW/HIGH: 68/166/264
          VM_STAT:
                NR_FREE_PAGES: 146
        NR_ZONE_INACTIVE_ANON: 94668
          NR_ZONE_ACTIVE_ANON: 3
        NR_ZONE_INACTIVE_FILE: 735
          NR_ZONE_ACTIVE_FILE: 78
          NR_ZONE_UNEVICTABLE: 0
        NR_ZONE_WRITE_PENDING: 0
                     NR_MLOCK: 0
                    NR_BOUNCE: 0
                   NR_ZSPAGES: 0
            NR_FREE_CMA_PAGES: 0

In allow_direct_reclaim(), while processing ZONE_DMA32, the sum of
inactive/active file-backed pages calculated in zone_reclaimable_pages()
based on the result of zone_page_state_snapshot() is zero.

Additionally, since this system lacks swap, the calculation of inactive/
active anonymous pages is skipped.

        crash> p nr_swap_pages
        nr_swap_pages = $1937 = {
          counter = 0
        }

As a result, ZONE_DMA32 is deemed unreclaimable and skipped, moving on to
the processing of the next zone, ZONE_NORMAL, despite ZONE_DMA32 having
free pages significantly exceeding the high watermark.

The problem is that the pgdat->kswapd_failures hasn't been incremented.

        crash> px ((struct pglist_data *) 0xffff00817fffe540)->kswapd_failures
        $1935 = 0x0

This is because the node deemed balanced.  The node balancing logic in
balance_pgdat() evaluates all zones collectively.  If one or more zones
(e.g., ZONE_DMA32) have enough free pages to meet their watermarks, the
entire node is deemed balanced.  This causes balance_pgdat() to exit early
before incrementing the kswapd_failures, as it considers the overall
memory state acceptable, even though some zones (like ZONE_NORMAL) remain
under significant pressure.


The patch ensures that zone_reclaimable_pages() includes free pages
(NR_FREE_PAGES) in its calculation when no other reclaimable pages are
available (e.g., file-backed or anonymous pages).  This change prevents
zones like ZONE_DMA32, which have sufficient free pages, from being
mistakenly deemed unreclaimable.  By doing so, the patch ensures proper
node balancing, avoids masking pressure on other zones like ZONE_NORMAL,
and prevents infinite loops in throttle_direct_reclaim() caused by
allow_direct_reclaim(pgdat) repeatedly returning false.


The kernel hangs due to a task stuck in throttle_direct_reclaim(), caused
by a node being incorrectly deemed balanced despite pressure in certain
zones, such as ZONE_NORMAL.  This issue arises from
zone_reclaimable_pages() returning 0 for zones without reclaimable file-
backed or anonymous pages, causing zones like ZONE_DMA32 with sufficient
free pages to be skipped.

The lack of swap or reclaimable pages results in ZONE_DMA32 being ignored
during reclaim, masking pressure in other zones.  Consequently,
pgdat->kswapd_failures remains 0 in balance_pgdat(), preventing fallback
mechanisms in allow_direct_reclaim() from being triggered, leading to an
infinite loop in throttle_direct_reclaim().

This patch modifies zone_reclaimable_pages() to account for free pages
(NR_FREE_PAGES) when no other reclaimable pages exist.  This ensures zones
with sufficient free pages are not skipped, enabling proper balancing and
reclaim behavior.

[akpm@linux-foundation.org: coding-style cleanups]
Link: https://lkml.kernel.org/r/20241130164346.436469-1-snishika@redhat.com
Link: https://lkml.kernel.org/r/20241130161236.433747-2-snishika@redhat.com
Fixes: 5a1c84b404 ("mm: remove reclaim and compaction retry approximations")
Signed-off-by: Seiji Nishikawa <snishika@redhat.com>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Biju Das
bad27f62d8 drm: adv7511: Drop dsi single lane support
commit 79d67c499c3f886202a40c5cb27e747e4fa4d738 upstream.

As per [1] and [2], ADV7535/7533 supports only 2-, 3-, or 4-lane. Drop
unsupported 1-lane.

[1] https://www.analog.com/media/en/technical-documentation/data-sheets/ADV7535.pdf
[2] https://www.analog.com/media/en/technical-documentation/data-sheets/ADV7533.pdf

Fixes: 1e4d58cd7f ("drm/bridge: adv7533: Create a MIPI DSI device")
Reported-by: Hien Huynh <hien.huynh.px@renesas.com>
Cc: stable@vger.kernel.org
Reviewed-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
Reviewed-by: Adam Ford <aford173@gmail.com>
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20241119192040.152657-4-biju.das.jz@bp.renesas.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Nikolay Kuratov
94b7ed0a48 net/sctp: Prevent autoclose integer overflow in sctp_association_init()
commit 4e86729d1ff329815a6e8a920cb554a1d4cb5b8d upstream.

While by default max_autoclose equals to INT_MAX / HZ, one may set
net.sctp.max_autoclose to UINT_MAX. There is code in
sctp_association_init() that can consequently trigger overflow.

Cc: stable@vger.kernel.org
Fixes: 9f70f46bd4 ("sctp: properly latch and use autoclose value from sock to association")
Signed-off-by: Nikolay Kuratov <kniv@yandex-team.ru>
Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20241219162114.2863827-1-kniv@yandex-team.ru
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Pascal Hambourg
9efc2a85ed sky2: Add device ID 11ab:4373 for Marvell 88E8075
commit 03c8d0af2e409e15c16130b185e12b5efba0a6b9 upstream.

A Marvell 88E8075 ethernet controller has this device ID instead of
11ab:4370 and works fine with the sky2 driver.

Signed-off-by: Pascal Hambourg <pascal@plouf.fr.eu.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/10165a62-99fb-4be6-8c64-84afd6234085@plouf.fr.eu.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Evgenii Shatokhin
788d9e9a41 pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking
commit a37eecb705f33726f1fb7cd2a67e514a15dfe693 upstream.

If a device uses MCP23xxx IO expander to receive IRQs, the following
bug can happen:

  BUG: sleeping function called from invalid context
    at kernel/locking/mutex.c:283
  in_atomic(): 1, irqs_disabled(): 1, non_block: 0, ...
  preempt_count: 1, expected: 0
  ...
  Call Trace:
  ...
  __might_resched+0x104/0x10e
  __might_sleep+0x3e/0x62
  mutex_lock+0x20/0x4c
  regmap_lock_mutex+0x10/0x18
  regmap_update_bits_base+0x2c/0x66
  mcp23s08_irq_set_type+0x1ae/0x1d6
  __irq_set_trigger+0x56/0x172
  __setup_irq+0x1e6/0x646
  request_threaded_irq+0xb6/0x160
  ...

We observed the problem while experimenting with a touchscreen driver which
used MCP23017 IO expander (I2C).

The regmap in the pinctrl-mcp23s08 driver uses a mutex for protection from
concurrent accesses, which is the default for regmaps without .fast_io,
.disable_locking, etc.

mcp23s08_irq_set_type() calls regmap_update_bits_base(), and the latter
locks the mutex.

However, __setup_irq() locks desc->lock spinlock before calling these
functions. As a result, the system tries to lock the mutex whole holding
the spinlock.

It seems, the internal regmap locks are not needed in this driver at all.
mcp->lock seems to protect the regmap from concurrent accesses already,
except, probably, in mcp_pinconf_get/set.

mcp23s08_irq_set_type() and mcp23s08_irq_mask/unmask() are called under
chip_bus_lock(), which calls mcp23s08_irq_bus_lock(). The latter takes
mcp->lock and enables regmap caching, so that the potentially slow I2C
accesses are deferred until chip_bus_unlock().

The accesses to the regmap from mcp23s08_probe_one() do not need additional
locking.

In all remaining places where the regmap is accessed, except
mcp_pinconf_get/set(), the driver already takes mcp->lock.

This patch adds locking in mcp_pinconf_get/set() and disables internal
locking in the regmap config. Among other things, it fixes the sleeping
in atomic context described above.

Fixes: 8f38910ba4 ("pinctrl: mcp23s08: switch to regmap caching")
Cc: stable@vger.kernel.org
Signed-off-by: Evgenii Shatokhin <e.shatokhin@yadro.com>
Link: https://lore.kernel.org/20241209074659.1442898-1-e.shatokhin@yadro.com
Signed-off-by: Linus Walleij <linus.walleij@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:37 +01:00
Dan Carpenter
c57721b24b RDMA/uverbs: Prevent integer overflow issue
commit d0257e089d1bbd35c69b6c97ff73e3690ab149a9 upstream.

In the expression "cmd.wqe_size * cmd.wr_count", both variables are u32
values that come from the user so the multiplication can lead to integer
wrapping.  Then we pass the result to uverbs_request_next_ptr() which also
could potentially wrap.  The "cmd.sge_count * sizeof(struct ib_uverbs_sge)"
multiplication can also overflow on 32bit systems although it's fine on
64bit systems.

This patch does two things.  First, I've re-arranged the condition in
uverbs_request_next_ptr() so that the use controlled variable "len" is on
one side of the comparison by itself without any math.  Then I've modified
all the callers to use size_mul() for the multiplications.

Fixes: 67cdb40ca4 ("[IB] uverbs: Implement more commands")
Cc: stable@vger.kernel.org
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://patch.msgid.link/b8765ab3-c2da-4611-aae0-ddd6ba173d23@stanley.mountain
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:23:36 +01:00
Masahiro Yamada
213305a1cb modpost: fix the missed iteration for the max bit in do_input()
[ Upstream commit bf36b4bf1b9a7a0015610e2f038ee84ddb085de2 ]

This loop should iterate over the range from 'min' to 'max' inclusively.
The last interation is missed.

Fixes: 1d8f430c15 ("[PATCH] Input: add modalias support")
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Tested-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Masahiro Yamada
f072e43697 modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host
[ Upstream commit 77dc55a978e69625f9718460012e5ef0172dc4de ]

When building a 64-bit kernel on a 32-bit build host, incorrect
input MODULE_ALIAS() entries may be generated.

For example, when compiling a 64-bit kernel with CONFIG_INPUT_MOUSEDEV=m
on a 64-bit build machine, you will get the correct output:

  $ grep MODULE_ALIAS drivers/input/mousedev.mod.c
  MODULE_ALIAS("input:b*v*p*e*-e*1,*2,*k*110,*r*0,*1,*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*2,*k*r*8,*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*14A,*r*a*0,*1,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*145,*r*a*0,*1,*18,*1C,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*110,*r*a*0,*1,*m*l*s*f*w*");

However, building the same kernel on a 32-bit machine results in
incorrect output:

  $ grep MODULE_ALIAS drivers/input/mousedev.mod.c
  MODULE_ALIAS("input:b*v*p*e*-e*1,*2,*k*110,*130,*r*0,*1,*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*2,*k*r*8,*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*14A,*16A,*r*a*0,*1,*20,*21,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*145,*165,*r*a*0,*1,*18,*1C,*20,*21,*38,*3C,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*3,*k*110,*130,*r*a*0,*1,*20,*21,*m*l*s*f*w*");

A similar issue occurs with CONFIG_INPUT_JOYDEV=m. On a 64-bit build
machine, the output is:

  $ grep MODULE_ALIAS drivers/input/joydev.mod.c
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*0,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*2,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*8,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*6,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*120,*r*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*130,*r*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*2C0,*r*a*m*l*s*f*w*");

However, on a 32-bit machine, the output is incorrect:

  $ grep MODULE_ALIAS drivers/input/joydev.mod.c
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*0,*20,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*2,*22,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*8,*28,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*3,*k*r*a*6,*26,*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*11F,*13F,*r*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*11F,*13F,*r*a*m*l*s*f*w*");
  MODULE_ALIAS("input:b*v*p*e*-e*1,*k*2C0,*2E0,*r*a*m*l*s*f*w*");

When building a 64-bit kernel, BITS_PER_LONG is defined as 64. However,
on a 32-bit build machine, the constant 1L is a signed 32-bit value.
Left-shifting it beyond 32 bits causes wraparound, and shifting by 31
or 63 bits makes it a negative value.

The fix in commit e0e9263271 ("[PATCH] PATCH: 1 line 2.6.18 bugfix:
modpost-64bit-fix.patch") is incorrect; it only addresses cases where
a 64-bit kernel is built on a 64-bit build machine, overlooking cases
on a 32-bit build machine.

Using 1ULL ensures a 64-bit width on both 32-bit and 64-bit machines,
avoiding the wraparound issue.

Fixes: e0e9263271 ("[PATCH] PATCH: 1 line 2.6.18 bugfix: modpost-64bit-fix.patch")
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Stable-dep-of: bf36b4bf1b9a ("modpost: fix the missed iteration for the max bit in do_input()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Leon Romanovsky
6103478629 ARC: build: Try to guess GCC variant of cross compiler
[ Upstream commit 824927e88456331c7a999fdf5d9d27923b619590 ]

ARC GCC compiler is packaged starting from Fedora 39i and the GCC
variant of cross compile tools has arc-linux-gnu- prefix and not
arc-linux-. This is causing that CROSS_COMPILE variable is left unset.

This change allows builds without need to supply CROSS_COMPILE argument
if distro package is used.

Before this change:
$ make -j 128 ARCH=arc W=1 drivers/infiniband/hw/mlx4/
  gcc: warning: ‘-mcpu=’ is deprecated; use ‘-mtune=’ or ‘-march=’ instead
  gcc: error: unrecognized command-line option ‘-mmedium-calls’
  gcc: error: unrecognized command-line option ‘-mlock’
  gcc: error: unrecognized command-line option ‘-munaligned-access’

[1] https://packages.fedoraproject.org/pkgs/cross-gcc/gcc-arc-linux-gnu/index.html
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Vineet Gupta <vgupta@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Uros Bizjak
512929f115 irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base
[ Upstream commit a1855f1b7c33642c9f7a01991fb763342a312e9b ]

percpu_base is used in various percpu functions that expect variable in
__percpu address space. Correct the declaration of percpu_base to

void __iomem * __percpu *percpu_base;

to declare the variable as __percpu pointer.

The patch fixes several sparse warnings:

irq-gic.c:1172:44: warning: incorrect type in assignment (different address spaces)
irq-gic.c:1172:44:    expected void [noderef] __percpu *[noderef] __iomem *percpu_base
irq-gic.c:1172:44:    got void [noderef] __iomem *[noderef] __percpu *
...
irq-gic.c:1231:43: warning: incorrect type in argument 1 (different address spaces)
irq-gic.c:1231:43:    expected void [noderef] __percpu *__pdata
irq-gic.c:1231:43:    got void [noderef] __percpu *[noderef] __iomem *percpu_base

There were no changes in the resulting object files.

Signed-off-by: Uros Bizjak <ubizjak@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Marc Zyngier <maz@kernel.org>
Link: https://lore.kernel.org/all/20241213145809.2918-2-ubizjak@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Daniele Palmas
520e02b7fe net: usb: qmi_wwan: add Telit FE910C04 compositions
[ Upstream commit 3b58b53a26598209a7ad8259a5114ce71f7c3d64 ]

Add the following Telit FE910C04 compositions:

0x10c0: rmnet + tty (AT/NMEA) + tty (AT) + tty (diag)
T:  Bus=02 Lev=01 Prnt=03 Port=06 Cnt=01 Dev#= 13 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1bc7 ProdID=10c0 Rev=05.15
S:  Manufacturer=Telit Cinterion
S:  Product=FE910
S:  SerialNumber=f71b8b32
C:  #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=82(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=60 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
I:  If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=86(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
I:  If#= 3 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

0x10c4: rmnet + tty (AT) + tty (AT) + tty (diag)
T:  Bus=02 Lev=01 Prnt=03 Port=06 Cnt=01 Dev#= 14 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1bc7 ProdID=10c4 Rev=05.15
S:  Manufacturer=Telit Cinterion
S:  Product=FE910
S:  SerialNumber=f71b8b32
C:  #Ifs= 4 Cfg#= 1 Atr=e0 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=82(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
I:  If#= 2 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=86(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
I:  If#= 3 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

0x10c8: rmnet + tty (AT) + tty (diag) + DPL (data packet logging) + adb
T:  Bus=02 Lev=01 Prnt=03 Port=06 Cnt=01 Dev#= 17 Spd=480  MxCh= 0
D:  Ver= 2.00 Cls=00(>ifc ) Sub=00 Prot=00 MxPS=64 #Cfgs=  1
P:  Vendor=1bc7 ProdID=10c8 Rev=05.15
S:  Manufacturer=Telit Cinterion
S:  Product=FE910
S:  SerialNumber=f71b8b32
C:  #Ifs= 5 Cfg#= 1 Atr=e0 MxPwr=500mA
I:  If#= 0 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=50 Driver=qmi_wwan
E:  Ad=01(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=81(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=82(I) Atr=03(Int.) MxPS=   8 Ivl=32ms
I:  If#= 1 Alt= 0 #EPs= 3 Cls=ff(vend.) Sub=ff Prot=40 Driver=option
E:  Ad=02(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=83(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=84(I) Atr=03(Int.) MxPS=  10 Ivl=32ms
I:  If#= 2 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=ff Prot=30 Driver=option
E:  Ad=03(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=85(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 3 Alt= 0 #EPs= 1 Cls=ff(vend.) Sub=ff Prot=80 Driver=(none)
E:  Ad=86(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms
I:  If#= 4 Alt= 0 #EPs= 2 Cls=ff(vend.) Sub=42 Prot=01 Driver=(none)
E:  Ad=04(O) Atr=02(Bulk) MxPS= 512 Ivl=0ms
E:  Ad=87(I) Atr=02(Bulk) MxPS= 512 Ivl=0ms

Signed-off-by: Daniele Palmas <dnlplm@gmail.com>
Link: https://patch.msgid.link/20241209151821.3688829-1-dnlplm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Anton Protopopov
f960a6b5d9 bpf: fix potential error return
[ Upstream commit c4441ca86afe4814039ee1b32c39d833c1a16bbc ]

The bpf_remove_insns() function returns WARN_ON_ONCE(error), where
error is a result of bpf_adj_branches(), and thus should be always 0
However, if for any reason it is not 0, then it will be converted to
boolean by WARN_ON_ONCE and returned to user space as 1, not an actual
error value. Fix this by returning the original err after the WARN check.

Signed-off-by: Anton Protopopov <aspsk@isovalent.com>
Acked-by: Jiri Olsa <jolsa@kernel.org>
Acked-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/r/20241210114245.836164-1-aspsk@isovalent.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Adrian Ratiu
8929492594 sound: usb: format: don't warn that raw DSD is unsupported
[ Upstream commit b50a3e98442b8d72f061617c7f7a71f7dba19484 ]

UAC 2 & 3 DAC's set bit 31 of the format to signal support for a
RAW_DATA type, typically used for DSD playback.

This is correctly tested by (format & UAC*_FORMAT_TYPE_I_RAW_DATA),
fp->dsd_raw = true; and call snd_usb_interface_dsd_format_quirks(),
however a confusing and unnecessary message gets printed because
the bit is not properly tested in the last "unsupported" if test:
if (format & ~0x3F) { ... }

For example the output:

usb 7-1: new high-speed USB device number 5 using xhci_hcd
usb 7-1: New USB device found, idVendor=262a, idProduct=9302, bcdDevice=0.01
usb 7-1: New USB device strings: Mfr=1, Product=2, SerialNumber=6
usb 7-1: Product: TC44C
usb 7-1: Manufacturer: TC44C
usb 7-1: SerialNumber: 5000000001
hid-generic 0003:262A:9302.001E: No inputs registered, leaving
hid-generic 0003:262A:9302.001E: hidraw6: USB HID v1.00 Device [DDHIFI TC44C] on usb-0000:08:00.3-1/input0
usb 7-1: 2:4 : unsupported format bits 0x100000000

This last "unsupported format" is actually wrong: we know the
format is a RAW_DATA which we assume is DSD, so there is no need
to print the confusing message.

This we unset bit 31 of the format after recognizing it, to avoid
the message.

Suggested-by: Takashi Iwai <tiwai@suse.com>
Signed-off-by: Adrian Ratiu <adrian.ratiu@collabora.com>
Link: https://patch.msgid.link/20241209090529.16134-2-adrian.ratiu@collabora.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:36 +01:00
Emmanuel Grumbach
155f6a7e0a wifi: mac80211: wake the queues in case of failure in resume
[ Upstream commit 220bf000530f9b1114fa2a1022a871c7ce8a0b38 ]

In case we fail to resume, we'll WARN with
"Hardware became unavailable during restart." and we'll wait until user
space does something. It'll typically bring the interface down and up to
recover. This won't work though because the queues are still stopped on
IEEE80211_QUEUE_STOP_REASON_SUSPEND reason.
Make sure we clear that reason so that we give a chance to the recovery
to succeed.

Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219447
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20241119173108.cd628f560f97.I76a15fdb92de450e5329940125f3c58916be3942@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:35 +01:00
Eric Dumazet
1638f430f8 ila: serialize calls to nf_register_net_hooks()
[ Upstream commit 260466b576bca0081a7d4acecc8e93687aa22d0e ]

syzbot found a race in ila_add_mapping() [1]

commit 031ae72825ce ("ila: call nf_unregister_net_hooks() sooner")
attempted to fix a similar issue.

Looking at the syzbot repro, we have concurrent ILA_CMD_ADD commands.

Add a mutex to make sure at most one thread is calling nf_register_net_hooks().

[1]
 BUG: KASAN: slab-use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]
 BUG: KASAN: slab-use-after-free in __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604
Read of size 4 at addr ffff888028f40008 by task dhcpcd/5501

CPU: 1 UID: 0 PID: 5501 Comm: dhcpcd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Call Trace:
 <IRQ>
  __dump_stack lib/dump_stack.c:94 [inline]
  dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
  print_address_description mm/kasan/report.c:378 [inline]
  print_report+0xc3/0x620 mm/kasan/report.c:489
  kasan_report+0xd9/0x110 mm/kasan/report.c:602
  rht_key_hashfn include/linux/rhashtable.h:159 [inline]
  __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604
  rhashtable_lookup include/linux/rhashtable.h:646 [inline]
  rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]
  ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:127 [inline]
  ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]
  ila_nf_input+0x1ee/0x620 net/ipv6/ila/ila_xlat.c:185
  nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]
  nf_hook_slow+0xbb/0x200 net/netfilter/core.c:626
  nf_hook.constprop.0+0x42e/0x750 include/linux/netfilter.h:269
  NF_HOOK include/linux/netfilter.h:312 [inline]
  ipv6_rcv+0xa4/0x680 net/ipv6/ip6_input.c:309
  __netif_receive_skb_one_core+0x12e/0x1e0 net/core/dev.c:5672
  __netif_receive_skb+0x1d/0x160 net/core/dev.c:5785
  process_backlog+0x443/0x15f0 net/core/dev.c:6117
  __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6883
  napi_poll net/core/dev.c:6952 [inline]
  net_rx_action+0xa94/0x1010 net/core/dev.c:7074
  handle_softirqs+0x213/0x8f0 kernel/softirq.c:561
  __do_softirq kernel/softirq.c:595 [inline]
  invoke_softirq kernel/softirq.c:435 [inline]
  __irq_exit_rcu+0x109/0x170 kernel/softirq.c:662
  irq_exit_rcu+0x9/0x30 kernel/softirq.c:678
  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]
  sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049

Fixes: 7f00feaf10 ("ila: Add generic ILA translation facility")
Reported-by: syzbot+47e761d22ecf745f72b9@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6772c9ae.050a0220.2f3838.04c7.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Florian Westphal <fw@strlen.de>
Cc: Tom Herbert <tom@herbertland.com>
Link: https://patch.msgid.link/20241230162849.2795486-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:23:35 +01:00