Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
712 commits
Select commit Hold shift + click to select a range
407b22f
ocfs2: validate rl_used against rl_count in refcount block validator
Jul 9, 2026
6070ea4
ocfs2: validate directory-index entry counts when reading metadata
peaktwilight Jul 13, 2026
aa56c8e
ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_regi…
josephhz Jul 22, 2026
985efe3
ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from …
josephhz Jul 22, 2026
5f07f3c
ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
josephhz Jul 22, 2026
69f8e4e
ocfs2: fix cached cluster count after suballocator reclaim
matthiasgoergens Aug 5, 2026
4658ca9
ocfs2: fix readdir position truncation on 32-bit kernels
zhanxusheng1024-os Aug 6, 2026
3904620
openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
lrfe Aug 21, 2026
38a149e
openvswitch: Fix CT limit teardown use-after-free
xuyq19 Aug 21, 2026
ced7f7d
openvswitch: only skb_tx_error() a packet we are about to drop
nszetei Aug 22, 2026
6890bc0
ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
sammiee5311 Aug 8, 2026
1d7d43b
arm64: compat: Fix decrementing LDM/STM alignment emulation
kmehltretter82 Aug 19, 2026
7621d12
arm64: proton-pack: Restore the nospectre_bhb command-line option
kmehltretter82 Jul 26, 2026
e1715f1
ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
cjtlabs Aug 23, 2026
894a941
ASoC: codecs: aw88261: only check PLL and clock state at power-up
The-Mighty-Cat Jul 4, 2026
a87179d
dma-contiguous: fix truncation of numa_cma / cma_pernuma sizes >= 2G
agraf Aug 21, 2026
ba1d33e
hwmon: (max6621) fix negative temperature offset and crit readings
Congnt264 Aug 10, 2026
d56efdc
hwmon: (max6621) fix temperature clamp range
Congnt264 Aug 10, 2026
e27d7e1
i2c: mxs: fix DMA channel leak on probe error
Ryuwang3 Aug 15, 2026
ad3a54e
ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
bhcsayx Aug 25, 2026
7cf01a9
lockd: pin next file across nlm_inspect_file lock-drop
mjbommar May 24, 2026
f0e057b
lockd: fix NLMv4 GRANTED_MSG handling
Jun 25, 2026
6f3cd72
lockd: fix NULL dereference on lockowner allocation failure
shuangpeng-kernel Jul 17, 2026
1f3c76e
lockd: fix swapped arguments in nlmsvc_match_ip()
OscarOu0421 Jun 17, 2026
3cb027a
nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in er…
May 13, 2026
a49b87c
nvme: zero the discard fallback page
Jul 30, 2026
55462b0
nvme-pci: disable controller on admin queue IRQ setup failure
testacegi Jul 15, 2026
3783201
nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
Aug 1, 2026
c740553
nvme-tcp: fix host memory disclosure on R2T for a read command
Jul 29, 2026
ec43354
nvme-tcp: reject a read that transferred too few bytes
Aug 1, 2026
b127c02
sctp: stop processing a packet once its association is deleted
V4bel Aug 14, 2026
d4e4c33
sctp: drop a chunk if its transport was removed
V4bel Aug 19, 2026
abefc09
sctp: fix NULL deref on untransmitted RECONF completion
winmin Aug 23, 2026
40d68d8
sctp: distinguish sequence zero from wildcard in reconf lookup
Aug 24, 2026
a673197
sctp: fix stream->outcnt underflow on duplicate RECONF responses
Aug 24, 2026
2a83fb8
power: supply: bq24257: fix use-after-free on remove
Aug 1, 2026
cc81f35
power: supply: bq256xx: drain usb_work before freeing the charger
Aug 4, 2026
2d143de
power: supply: bq25890: Fix power_supply reference leak
Jul 22, 2026
cadcf69
power: supply: charger-manager: register regulators before exposing s…
Jul 28, 2026
b34243a
power: supply: cros_usbpd-charger: bound the EC-reported port count
bryamzxz Jun 17, 2026
7db6585
power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
jthiesatgoogle Jul 22, 2026
209dd52
power: supply: lp8727: fix use-after-free in lp8727_release_irq()
Aug 7, 2026
2ab59d0
power: supply: lp8788-charger: fix use-after-free on remove
Aug 2, 2026
b05cf48
power: supply: pf1550: enable charging when battery profile exists
Jul 24, 2026
552e30b
power: supply: qcom_battmgr: fix use-after-free
Aug 1, 2026
dc39a5f
power: supply: qcom_battmgr: terminate the strings from firmware
sammiee5311 Jul 27, 2026
a137009
power: supply: rt9455: quiesce delayed work before teardown
Jul 23, 2026
84ba637
power: supply: twl4030_charger: cancel workers via devm
maoyixie Jul 25, 2026
6c6e463
power: supply: ucs1002: fix use-after-free on remove
Aug 2, 2026
e9ee9c6
power: supply: max17040: propagate register read errors
Jul 27, 2026
4eba333
power: supply: max17040: drop incorrect I2C functionality check
Jul 31, 2026
d1e7c7c
power: supply: max17040: synchronize work cancellation on suspend
Aug 10, 2026
9cdbc8f
s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
Aug 11, 2026
a52b196
s390/percpu: Fix MVIY_PERCPU() with older binutils
kmehltretter82 Aug 12, 2026
94dd7a5
s390/dasd: Do not complete a failed ESE read as successful
Aug 5, 2026
3a1bdce
s390/dasd: Guard sysfs discipline callbacks against unallocated priva…
Aug 5, 2026
855d18e
s390/dasd: Propagate partial completion length across ERP recovery
Aug 5, 2026
dd51018
PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
Aug 10, 2026
ee1ec8f
PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
raiz-deen Jul 23, 2026
bd058bc
PCI: meson: Fix GPIO state while requesting PERST#
rclaveau-tech Jun 16, 2026
3af8fa9
PCI: starfive: Fix resource leaks on error paths in host_init()
alitariq4589-2 Jul 16, 2026
41f771b
PCI: plda: Fix use-after-free of event IRQs during teardown
alitariq4589-2 Jul 23, 2026
1177190
PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_inter…
alitariq4589-2 Jul 23, 2026
c8b2291
PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
Gateworks Jul 20, 2026
2f7d28d
PCI/sysfs: Fix read byte order in pci_read_legacy_io()
kwilczynski Jun 16, 2026
5ea064e
PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
kwilczynski Jul 20, 2026
23c59ee
PCI/AER: Emit TLP Log only for unmasked errors
l1k Jul 24, 2026
8c4bda0
PCI/AER: Fix mapping of errors to agent & layer
l1k Jul 24, 2026
aa7110d
PCI/ASPM: Avoid L0s for Realtek RTS525A
chochien Jul 7, 2026
d9c65f2
PCI/MSI: Enable memory decoding before restoring MSI-X messages
Aug 5, 2026
57b9bb0
PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
kwilczynski Jul 29, 2026
51aa1e4
PCI/proc: Use file_ns_capable() when checking config space read access
kwilczynski Jul 20, 2026
27e27bb
PCI/proc: Warn on writes to kernel-exclusive config space regions
kwilczynski Jul 29, 2026
7c4c7aa
iommu/amd: Put PCI device after handling PPR faults
axiqia Jul 27, 2026
54c120a
iommu/msm: Unwind probe state on registration failure
Jul 16, 2026
514dcef
iommu/sva: Set handle->dev before the SVA handle is visible
axiqia Jul 26, 2026
c0e5488
iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
nicolinc Jul 14, 2026
f756440
iommu/arm-smmu-v3: Add HAFT support for SVA
rmurphy-arm Jul 27, 2026
4300dcd
iommu/arm-smmu-v3: Manage teardown with devm
Jun 29, 2026
44a8000
iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_…
BaldDemian Jul 11, 2026
f62943a
iommu/vt-d: Fix no_iommu to disable platform opt-in
ktian1 Aug 4, 2026
06ce2e3
iommu/vt-d: Force requesting ACS when tboot is enabled
ktian1 Aug 4, 2026
cfb6c3c
iommupt: Return zero for invalid iova_to_phys() ranges
axiqia Jul 26, 2026
a1fe11a
iommufd: Avoid locking internal accesses during unmap
axiqia Jul 26, 2026
fe45fca
iommufd: Release current IOAS on xa_store() failure
axiqia Jul 26, 2026
17c317f
iommufd: Fix UAF in selftest IOPF reporting
BaldDemian Aug 11, 2026
ef100de
platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
sammiee5311 Jun 14, 2026
1081f9f
platform/x86: ISST: Validate level in perf mask ioctls
sammiee5311 Aug 7, 2026
9b9d1e0
platform/x86: ISST: Validate socket ID in clos_assoc ioctl
sammiee5311 Aug 7, 2026
75e468f
mmc: via-sdmmc: cancel card-detect work on remove
Jul 23, 2026
8cc5266
mmc: via-sdmmc: stop card-detect handling on probe failure
Jul 23, 2026
a0c7b68
platform/x86: ISST: Add a NULL check for sst_inst[]
spandruvada Aug 11, 2026
976dc14
platform/x86: ISST: Just allow 2 bits for SST feature enable
spandruvada Aug 11, 2026
34465c0
platform/x86: ISST: Use PP level enable mask
spandruvada Aug 11, 2026
e40e90a
platform/x86: ISST: Validate logical CPU id and clos id
spandruvada Aug 11, 2026
fafa347
platform/x86: ISST: Validate max level for set feature
spandruvada Aug 11, 2026
fb735f9
platform/x86: ISST: Validate parameter for core power state
spandruvada Aug 11, 2026
cf254ee
platform/x86: ISST: Validate parameter for frequency and priority
spandruvada Aug 11, 2026
af57013
platform/x86: ISST: Return error during profile addition
spandruvada Aug 11, 2026
54364de
platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
VulnX Jun 23, 2026
6cefc25
platform/x86: int1092: Fix potential memory leak in sar_probe()
Jul 23, 2026
700b665
platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe e…
Jun 24, 2026
cd48a1b
platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch que…
realRobotix Jun 14, 2026
6785c67
platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]
hmontelo Aug 13, 2026
33c8818
platform/x86: think-lmi: Fix certificate thumbprint sysfs output
toblux Aug 10, 2026
af73fbd
platform/x86: think-lmi: Free system certificate signatures
toblux Aug 10, 2026
f224776
platform/x86: think-lmi: Fix current password length check
toblux Aug 18, 2026
2b9d5be
platform/chrome: sensorhub: Bound the EC-reported sensor number
bryamzxz Jun 18, 2026
4ba0b56
platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
superm1 Jul 21, 2026
ef736eb
platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
superm1 Jul 21, 2026
ad027e5
platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
superm1 Jul 21, 2026
fe26edc
platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_ope…
superm1 Jul 21, 2026
0064610
platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP …
Jul 9, 2026
3d53381
platform/x86: hp-bioscfg: advance elem past consumed array elements
Aug 12, 2026
a5a9eb8
platform/x86: hp-bioscfg: bound ordered-list parsing by the package c…
Jul 9, 2026
d5ae5b7
platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_sto…
Aug 12, 2026
991dd2c
platform/x86: hp-bioscfg: fix heap OOB read on empty password write
Aug 12, 2026
e1b58b9
platform/x86: hp-bioscfg: fix new_password_store() overwriting curren…
Aug 12, 2026
0d0675c
platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_…
Aug 12, 2026
b66058a
platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
Aug 12, 2026
1362f3e
platform/x86: hp-bioscfg: pass validated element count to package par…
Jul 9, 2026
5e764ba
platform/x86: hp-bioscfg: warn on element type mismatch instead of fa…
Jul 9, 2026
e2e2b56
io_uring/waitid: honor task_work cancellation
liulangrenaaa Aug 18, 2026
8661c06
io_uring/waitid: avoid siginfo copy during ring teardown
liulangrenaaa Aug 18, 2026
4010a89
io_uring/query: cap user size passed to copy_struct_to_user
laxmanacharya8 Aug 21, 2026
0d381ea
interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
visitorckw Apr 16, 2026
c0a3353
ipmi: ipmb: validate write message length
Yousef13710 Jun 24, 2026
2773163
ipmi: Remove all sysfs files on registration failure
Uuuuuuho Aug 3, 2026
b2a4e29
ipmi: si: Fix NULL pointer dereference after failed registration
Seiji-Nishikawa Jun 30, 2026
e24221f
ipmi:msghandler: Cancel work cleanly on an error
cminyard Aug 18, 2026
8621915
net/iucv: filter frames in afiucv_hs_rcv() by ingress device
SandyWinter Aug 21, 2026
3412910
xdp: fix zero-copy frame layout
winmin Aug 18, 2026
f0e5554
slip: fix use-after-free in sl_sync()
Aug 24, 2026
02c1374
net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
fabio-porcedda Aug 12, 2026
40c78d4
net: tun: bound receive headroom
manizada Aug 12, 2026
ada8767
net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
a3f Aug 14, 2026
586e4b9
net: bnxt: ring the doorbell when SW USO exits early
Aug 19, 2026
e1d2d02
net: ibm: emac: mal: fix NAPI locking
Aug 11, 2026
097424d
net: ipa: fix stalled modem TX queue after runtime resume
The-Mighty-Cat Aug 15, 2026
5a4724e
net: l2tp: do not propagate multicast notification errors
Aug 20, 2026
f7f9269
net: mctp: hold a reference to the route device in mctp_route_lookup()
AldoAriel12 Aug 13, 2026
d066675
net: openvswitch: fix flow mask use-after-free on flow deletion
igsilya Aug 15, 2026
9ee36e6
net: openvswitch: fix nf_connlabels leak in ovs_ct_init
Ryuwang3 Aug 15, 2026
a7cb227
net: phylink: correctly validate returned PCS in phylink_inband_caps
Ansuel Aug 17, 2026
a395156
net: ravb: avoid dereferencing an invalid PTP clock
Aug 11, 2026
bbdfa55
net: ravb: serialize PTP clock teardown
Aug 11, 2026
fe77d61
net: thunderbolt: Release the Rx HopID that was handed out on mismatch
faliye Aug 11, 2026
eb65977
net: thunderbolt: Mark the connection down when bringing it up fails
faliye Aug 11, 2026
026ec32
NTB: ntb_transport: Recycle TX entries before client callbacks
lkpdn Aug 17, 2026
b001efd
NTB: ntb_transport: Fail TX enqueue when the QP link is down
lkpdn Aug 17, 2026
de4b2a6
NTB: ntb_transport: Reject oversized TX buffers
lkpdn Aug 17, 2026
9f1d0dc
net: ntb_netdev: Fix TX busy and drop handling
lkpdn Aug 17, 2026
1ebb8da
net: ntb_netdev: Avoid double-accounting netif_rx() drops
lkpdn Aug 19, 2026
b5c128e
net: ntb_netdev: Count packets dropped on RX refill failure
lkpdn Aug 19, 2026
b370d9f
net/mlx5e: do not HW-GRO coalesce small frames
Aug 16, 2026
86c4daa
net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
Aug 19, 2026
4e5adfe
net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
Aug 19, 2026
8e9cc90
net/smc: do not dereference an unset send buffer on the SMC-D teardow…
bryamzxz Aug 8, 2026
27df4f7
net/smc: fix socket refcount leak in smc_switch_conns()
Aug 20, 2026
dbae6ba
net/smc: fix use-after-free in smc_rx_pipe_buf_release()
Aug 20, 2026
f2b9966
net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
Aug 19, 2026
13ae059
net/smc: stop killed, freed and out_of_sync sharing a byte
Aug 20, 2026
880416d
net/smc: unregister the connection before draining the rx tasklet
bryamzxz Aug 8, 2026
75208de
net: cap advertised IP tunnel headroom
Aug 12, 2026
19026b9
net: fix spurious TX timeout after dev_activate()
leitao Aug 25, 2026
2afc7cb
net: skbuff: don't touch shared zerocopy state in skb_tx_error()
nszetei Aug 22, 2026
caedecf
seg6: reset IP6CB after IPv6 decapsulation
Aug 22, 2026
ee63772
hwrng: stm32 - Fix runtime PM cleanup on registration failure
Jul 18, 2026
2caa5f0
mfd: cgbc: Fix teardown ordering in cgbc_remove()
thom24 Jul 13, 2026
cc8bbe3
mfd: qnap-mcu: keep the reply buffer alive past a command timeout
lrfe Aug 2, 2026
3ce6861
mfd: sm501: Fix potential memory leaks during remove
Jul 20, 2026
5816b7e
ALSA: 6fire: bound the MIDI event length from the device
baul1337 Aug 5, 2026
e2f7a99
ALSA: aloop: Check card index validity at probe
tiwai Aug 6, 2026
5c5d15c
ALSA: bcd2000: clear the URB pointers on disconnect
baul1337 Aug 5, 2026
66a8e7e
ALSA: FCP: do not copy out an uninitialised init response
baul1337 Aug 5, 2026
afa4957
ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
Aug 13, 2026
50ec986
ALSA: mpu401: Check card index validity at probe
tiwai Aug 6, 2026
dc3840b
ALSA: mts64: Check card index validity at probe
tiwai Aug 6, 2026
fdc721b
ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
Aug 18, 2026
319330e
ALSA: portman2x4: Check card index validity at probe
tiwai Aug 6, 2026
cc31636
ALSA: serial-u16550: Check card index validity at probe
tiwai Aug 6, 2026
7344042
ALSA: virmidi: Check card index validity at probe
tiwai Aug 6, 2026
935da3d
ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
Emohr-Tuxedo Aug 21, 2026
7fea5da
ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
rautyrauty Aug 8, 2026
9f871c5
ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q…
ii343hbka Aug 10, 2026
7a762b2
ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
Aug 17, 2026
39c6de0
rust: num: reject Bounded::shr overshifts at build time
Sep 3, 2026
12b6720
arch_numa: avoid false positive fortify warning in setup_node_to_cpum…
nathanchance Aug 14, 2026
ce02fa9
dm-stats: fix a crash if allocation of per-cpu data fails
Aug 3, 2026
87c98d9
dm-switch: use WRITE_ONCE() in switch_region_table_write()
ISCAS-Vulab Jul 11, 2026
40dbb03
dm-pcache: validate geometry fields from on-disk cache_info
bryamzxz Jul 17, 2026
bb5f850
dm-pcache: validate kset key_num and intra-segment bounds
bryamzxz Jul 17, 2026
ef0dc53
dm-pcache: validate on-media seg_num against the cache device size
bryamzxz Jul 17, 2026
56acaf9
dm-pcache: bound the persisted tail-position offset
bryamzxz Jul 17, 2026
8c3c1ad
dm-pcache: clamp the tail kset read to the segment data region
bryamzxz Jul 17, 2026
ebde18e
dm-pcache: detect a cycle in the last-kset chain during replay
bryamzxz Jul 17, 2026
a11febe
dm-pcache: only hand out initialized cache segments
bryamzxz Jul 17, 2026
339abff
dm-pcache: fix implicit u8 truncation of gc_percent in message handler
Jul 20, 2026
eb947f1
dm-pcache: fix use-after-free and invalid seg operations in kset_repl…
Jul 20, 2026
5908c67
i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supporte…
ahunter6 Aug 7, 2026
8a47f1b
i3c: master: adi: initialize the lock before enabling interrupts
Jun 17, 2026
ba59ced
i3c: master: Fix info leak and UAF in device unregister path
ahunter6 Jul 23, 2026
9a5972f
i3c: master: svc: bound IBI payload to the requested max_payload_len
maoyixie Jun 24, 2026
9f45b22
i3c: renesas: Check that the transfer is valid before accessing it
claudiubeznea Jul 13, 2026
bbb85fe
i3c: renesas: Clean DATBAS register on detach
claudiubeznea Jul 13, 2026
60ba556
i3c: renesas: Follow the reset deassert order used in probe
claudiubeznea Jul 13, 2026
f4281b7
i3c: renesas: Reconfigure the DATBAS register on re-attach
claudiubeznea Jul 13, 2026
c834cb5
i3c: renesas: Reset the controller on resume
claudiubeznea Jul 13, 2026
c3a88f1
i3c: renesas: Restore STDBR and EXTBR registers on resume
claudiubeznea Jul 13, 2026
04568e6
i3c: renesas: Perform Dynamic Address Assignment on resume
claudiubeznea Jul 13, 2026
48c03f9
wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
Aug 3, 2026
792bd51
wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
Jun 24, 2026
403b5f1
wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
Jun 30, 2026
07679c2
fuse: decouple fuse_ring creation from ent registration
joannekoong Aug 31, 2026
d4ab9bb
fuse: copy request headers via a stack buffer for io-uring
n132 Aug 31, 2026
a394160
crypto: iaa - unmap dst before software fallback on decompress
vcgomes Sep 1, 2026
ec9a16c
crypto: atmel-ecc - clean up and improve ECDH comments
toblux Sep 1, 2026
d8fa818
crypto: atmel-ecc - avoid stale fallback key after set_secret failure
toblux Sep 1, 2026
e1ccede
mm/kmemleak: stop the task stack scan early when interrupted
leitao Sep 3, 2026
565e912
mm/kmemleak: report RCU-tasks quiescent states during the scan
leitao Sep 3, 2026
17e4fe6
wifi: mwifiex: Detach sync cmd buffer on interrupted wait
Jul 24, 2026
7f8094f
wifi: rtl818x: initialize eeprom_93cx6 struct to zero
sgruszka Jul 23, 2026
eb228dd
wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
Jun 20, 2026
bce7cd8
wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw…
Jul 23, 2026
323fc35
wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
Jul 27, 2026
4a8fea9
wifi: rtw88: pci: fix resource leak on failed NAPI setup
Jun 17, 2026
a57ec04
wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on re…
Jul 29, 2026
977d96b
wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
Jun 12, 2026
b6bb442
wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE …
bryamzxz Jun 25, 2026
400628e
wifi: mt76: mt7925: cancel mlo_pm_work on stop
Lucid-Duck Jun 27, 2026
269735b
wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE …
bryamzxz Jun 25, 2026
8308383
wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
nbd168 Jul 22, 2026
4ba11bd
wifi: mt76: mt7996: validate default EEPROM firmware size
laxmanacharya8 Jul 13, 2026
b1c9be5
vsock/virtio: flush works in dependency order
Ychame Aug 22, 2026
73069ee
w1: ds28e17: reject an oversize length on an I2C block read
maoyixie Jun 29, 2026
84f2e24
xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
x-y-z Aug 4, 2026
8d35b91
zloop: truncate finished zones to zone capacity
Aug 4, 2026
dfdad4f
tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
testacegi Jun 26, 2026
2e1caef
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
oleg-nesterov Jul 20, 2026
0b0f138
sticon/parisc: Detect default STI graphics card for console output
hdeller Aug 6, 2026
ce8c703
signal: avoid shared siginfo namespace rewrites
Jun 22, 2026
791cc49
smack: fix cred UAF in smack_file_send_sigiotask()
thejh Aug 6, 2026
c96b7c0
taskstats: fix cpumask parsing cutting off the last character
Jul 23, 2026
0eede6a
timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtim…
t-8ch Jul 31, 2026
99ed7ba
timer: Keep debugobjects state consistent in migrate_timer_list()
Aug 17, 2026
c25c313
udf: Fix i_lenExtents truncation on 32-bit kernels
zhanxusheng1024-os Jul 22, 2026
bd78ff0
selftests/mm: fix on-fault-limit false failure under sudo-rs
injaeryou Jul 13, 2026
b530b88
ACPI: scan: Do not combine resources that overlap completely
rafaeljw Aug 20, 2026
1d224da
platform/chrome: sensorhub: Fix dropped timestamp events and log spam
Jul 15, 2026
ba8af06
Linux 7.2.4
gregkh Sep 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion Documentation/ABI/testing/sysfs-bus-nvdimm
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,8 @@ What: /sys/bus/nd/devices/nmemX/cxl/id
Date: November 2022
KernelVersion: 6.2
Contact: Dave Jiang <dave.jiang@intel.com>
Description: (RO) Show the id (serial) of the device. This is CXL specific.
Description: (RO) Show the id (serial) of the device, formatted as an
unsigned 64-bit decimal value. This is CXL specific.

What: /sys/bus/nd/devices/nmemX/cxl/provider
Date: November 2022
Expand Down
9 changes: 4 additions & 5 deletions Documentation/admin-guide/blockdev/zoned_loop.rst
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,10 @@ indicates the position of the write pointer of the zone.

When resetting a sequential zone, its backing file size is truncated to zero.
Conversely, for a zone finish operation, the backing file is truncated to the
zone size. With this, the maximum capacity of a zloop zoned block device created
can be larger configured to be larger than the storage space available on the
backing file system. Of course, for such configuration, writing more data than
the storage space available on the backing file system will result in write
errors.
zone capacity. With this, a zloop zoned block device can be configured with a
larger capacity than the storage space available on the backing file system. Of
course, for such configuration, writing more data than the storage space
available on the backing file system will result in write errors.

The zoned loop block device driver implements a complete zone transition state
machine. That is, zones can be empty, implicitly opened, explicitly opened,
Expand Down
15 changes: 13 additions & 2 deletions Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 7
PATCHLEVEL = 2
SUBLEVEL = 3
SUBLEVEL = 4
EXTRAVERSION =
NAME = Baby Opossum Posse

Expand Down Expand Up @@ -1087,6 +1087,16 @@ endif
export CC_FLAGS_SCS
endif

ifdef CONFIG_RUST_INLINE_HELPERS
# `rustc` normally emits traps for unreachable paths during code generation.
# With inline helpers, Clang performs code generation from the linked bitcode
# instead, so request the same behavior explicitly. Otherwise `objtool` may
# follow an impossible Rust path into the next function.
CC_FLAGS_RUST_INLINE_HELPERS := -mllvm -trap-unreachable \
-mllvm -no-trap-after-noreturn
export CC_FLAGS_RUST_INLINE_HELPERS
endif

ifdef CONFIG_LTO_CLANG
ifdef CONFIG_LTO_CLANG_FULL
CC_FLAGS_LTO := -flto
Expand Down Expand Up @@ -1122,7 +1132,8 @@ endif
ifdef CONFIG_RUST
# Always pass -Zsanitizer-cfi-normalize-integers as CONFIG_RUST selects
# CONFIG_CFI_ICALL_NORMALIZE_INTEGERS.
RUSTC_FLAGS_CFI := -Zsanitizer=kcfi -Zsanitizer-cfi-normalize-integers
# Disable function merging as LLVM incorrectly merges functions with different KCFI types.
RUSTC_FLAGS_CFI := -Zsanitizer=kcfi -Zsanitizer-cfi-normalize-integers -Zmerge-functions=disabled
KBUILD_RUSTFLAGS += $(RUSTC_FLAGS_CFI)
export RUSTC_FLAGS_CFI
endif
Expand Down
8 changes: 6 additions & 2 deletions arch/alpha/include/uapi/asm/fpu.h
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,12 @@ ieee_swcr_to_fpcr(unsigned long sw)
| IEEE_TRAP_ENABLE_OVF)) << 48;
fp |= (~sw & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE)) << 57;
fp |= (sw & IEEE_MAP_UMZ ? FPCR_UNDZ | FPCR_UNFD : 0);
fp |= (~sw & IEEE_TRAP_ENABLE_DNO) << 41;
/*
* Disable denormal operand traps only when denormal inputs are to be
* flushed to zero. Otherwise they must keep trapping, so that /S
* instructions reach the kernel emulation handler.
*/
fp |= (sw & IEEE_MAP_DMZ ? FPCR_DNOD : 0);
return fp;
}

Expand All @@ -116,7 +121,6 @@ ieee_fpcr_to_swcr(unsigned long fp)
| IEEE_TRAP_ENABLE_OVF);
sw |= (~fp >> 57) & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE);
sw |= (fp >> 47) & IEEE_MAP_UMZ;
sw |= (~fp >> 41) & IEEE_TRAP_ENABLE_DNO;
return sw;
}

Expand Down
6 changes: 3 additions & 3 deletions arch/alpha/kernel/pci-sysfs.c
Original file line number Diff line number Diff line change
Expand Up @@ -224,17 +224,17 @@ int pci_legacy_write(struct pci_bus *bus, loff_t port, u32 val, size_t size)

switch(size) {
case 1:
outb(port, val);
outb(val, port);
return 1;
case 2:
if (port & 1)
return -EINVAL;
outw(port, val);
outw(val, port);
return 2;
case 4:
if (port & 3)
return -EINVAL;
outl(port, val);
outl(val, port);
return 4;
}
return -EINVAL;
Expand Down
25 changes: 12 additions & 13 deletions arch/alpha/kernel/sys_marvel.c
Original file line number Diff line number Diff line change
Expand Up @@ -263,6 +263,18 @@ init_io7_irqs(struct io7 *io7,
*/
printk(" Interrupts reported to CPU at PE %u\n", boot_cpuid);

/* Set up the lsi irqs. */
for (i = 0; i < 128; ++i) {
irq_set_chip_and_handler(base + i, lsi_ops, handle_level_irq);
irq_set_status_flags(base + i, IRQ_LEVEL);
}

/* Set up the msi irqs. */
for (i = 128; i < (128 + 512); ++i) {
irq_set_chip_and_handler(base + i, msi_ops, handle_level_irq);
irq_set_status_flags(base + i, IRQ_LEVEL);
}

raw_spin_lock(&io7->irq_lock);

/* set up the error irqs */
Expand All @@ -272,26 +284,13 @@ init_io7_irqs(struct io7 *io7,
io7_redirect_irq(io7, &io7->csrs->STV_CTL.csr, boot_cpuid);
io7_redirect_irq(io7, &io7->csrs->HEI_CTL.csr, boot_cpuid);

/* Set up the lsi irqs. */
for (i = 0; i < 128; ++i) {
irq_set_chip_and_handler(base + i, lsi_ops, handle_level_irq);
irq_set_status_flags(i, IRQ_LEVEL);
}

/* Disable the implemented irqs in hardware. */
for (i = 0; i < 0x60; ++i)
init_one_io7_lsi(io7, i, boot_cpuid);

init_one_io7_lsi(io7, 0x74, boot_cpuid);
init_one_io7_lsi(io7, 0x75, boot_cpuid);


/* Set up the msi irqs. */
for (i = 128; i < (128 + 512); ++i) {
irq_set_chip_and_handler(base + i, msi_ops, handle_level_irq);
irq_set_status_flags(i, IRQ_LEVEL);
}

for (i = 0; i < 16; ++i)
init_one_io7_msi(io7, i, boot_cpuid);

Expand Down
6 changes: 3 additions & 3 deletions arch/alpha/kernel/traps.c
Original file line number Diff line number Diff line change
Expand Up @@ -166,12 +166,12 @@ static long dummy_emul(void) { return 0; }
long (*alpha_fp_emul_imprecise)(struct pt_regs *regs, unsigned long writemask)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul_imprecise);
long (*alpha_fp_emul) (unsigned long pc)
long (*alpha_fp_emul) (unsigned long pc, unsigned long summary)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul);
#else
long alpha_fp_emul_imprecise(struct pt_regs *regs, unsigned long writemask);
long alpha_fp_emul (unsigned long pc);
long alpha_fp_emul (unsigned long pc, unsigned long summary);
#endif

asmlinkage void
Expand All @@ -185,7 +185,7 @@ do_entArith(unsigned long summary, unsigned long write_mask,
emulate the instruction. If the processor supports
precise exceptions, we don't have to search. */
if (!amask(AMASK_PRECISE_TRAP))
si_code = alpha_fp_emul(regs->pc - 4);
si_code = alpha_fp_emul(regs->pc - 4, summary);
else
si_code = alpha_fp_emul_imprecise(regs, write_mask);
if (si_code == 0)
Expand Down
88 changes: 77 additions & 11 deletions arch/alpha/math-emu/math.c
Original file line number Diff line number Diff line change
Expand Up @@ -52,13 +52,13 @@ MODULE_DESCRIPTION("FP Software completion module");
MODULE_LICENSE("GPL v2");

extern long (*alpha_fp_emul_imprecise)(struct pt_regs *, unsigned long);
extern long (*alpha_fp_emul) (unsigned long pc);
extern long (*alpha_fp_emul) (unsigned long pc, unsigned long summary);

static long (*save_emul_imprecise)(struct pt_regs *, unsigned long);
static long (*save_emul) (unsigned long pc);
static long (*save_emul) (unsigned long pc, unsigned long summary);

long do_alpha_fp_emul_imprecise(struct pt_regs *, unsigned long);
long do_alpha_fp_emul(unsigned long);
long do_alpha_fp_emul(unsigned long, unsigned long);

static int alpha_fp_emul_init_module(void)
{
Expand Down Expand Up @@ -86,7 +86,22 @@ module_exit(alpha_fp_emul_cleanup_module);


/*
* Emulate the floating point instruction at address PC. Returns -1 if the
* Exception bits of the exception summary register (EXC_SUM). Bit 0 is the
* software completion bit; bits 1 through 5 report the exceptions the
* hardware attributed to the trapping instruction, and lie at the same
* positions as the corresponding IEEE_TRAP_ENABLE_* bits.
*/
#define EXC_SUM_INV (1UL << 1)
#define EXC_SUM_DZE (1UL << 2)
#define EXC_SUM_OVF (1UL << 3)
#define EXC_SUM_UNF (1UL << 4)
#define EXC_SUM_INE (1UL << 5)
#define EXC_SUM_MASK (EXC_SUM_INV | EXC_SUM_DZE | EXC_SUM_OVF \
| EXC_SUM_UNF | EXC_SUM_INE)

/*
* Emulate the floating point instruction at address PC. SUMMARY is the
* exception summary register the trap was delivered with. Returns -1 if the
* instruction to be emulated is illegal (such as with the opDEC trap), else
* the SI_CODE for a SIGFPE signal, else 0 if everything's ok.
*
Expand All @@ -95,7 +110,7 @@ module_exit(alpha_fp_emul_cleanup_module);
* stick the result of the operation into the appropriate register.
*/
long
alpha_fp_emul (unsigned long pc)
alpha_fp_emul (unsigned long pc, unsigned long summary)
{
FP_DECL_EX;
FP_DECL_S(SA); FP_DECL_S(SB); FP_DECL_S(SR);
Expand Down Expand Up @@ -300,12 +315,56 @@ alpha_fp_emul (unsigned long pc)
swcr |= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
current_thread_info()->ieee_state
|= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
}

/* Update hardware control register. */
fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
fpcr |= ieee_swcr_to_fpcr(swcr);
wrfpcr(fpcr);
/*
* EV6 records exception status bits in the FPCR before delivering the
* software completion trap, and swcr_update_status() above merged them
* into SWCR. Some can be wrong for the instruction we just emulated:
* a CVTTS of a value exactly representable as a subnormal sets FPCR_UNF
* even though the result is exact. Clear the exceptions the trap
* reported but that soft-fp did not raise.
*/
if (implver() == IMPLVER_EV6) {
unsigned long spurious = summary & EXC_SUM_MASK;

if (spurious & (EXC_SUM_UNF | EXC_SUM_OVF)) {
/*
* EXC_SUM reports only the underflow or overflow,
* but the hardware sets INE alongside it in the FPCR.
*/
spurious |= EXC_SUM_INE;
} else if (!spurious) {
/*
* No exception reported, so this was a denormal
* operand trap, for which INE and UNF can be
* fabricated as well.
*/
spurious = EXC_SUM_INE | EXC_SUM_UNF;
}

/*
* Never clear an exception software has confirmed. Every
* instruction that genuinely raises one traps for software
* completion and is recorded in ieee_state above, so a bit
* found there -- including one just set from _fex -- belongs
* to this or an earlier instruction and must survive.
*/
spurious &= ~(current_thread_info()->ieee_state
>> IEEE_STATUS_TO_EXCSUM_SHIFT);

swcr &= ~(spurious << IEEE_STATUS_TO_EXCSUM_SHIFT);
}

/*
* Update hardware control register. This has to happen even when
* soft-fp raised nothing, to clear any fabricated bits.
*/
fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
fpcr |= ieee_swcr_to_fpcr(swcr);
wrfpcr(fpcr);

if (_fex) {
/* Do we generate a signal? */
_fex = _fex & swcr & IEEE_TRAP_ENABLE_MASK;
si_code = 0;
Expand Down Expand Up @@ -387,9 +446,16 @@ alpha_fp_emul_imprecise (struct pt_regs *regs, unsigned long write_mask)
break;
}
if (!write_mask) {
/* Re-execute insns in the trap-shadow. */
/*
* Re-execute insns in the trap-shadow. Pass no
* exception summary: it describes the trap, which
* was taken anywhere in the shadow, and so is not
* attribution for this instruction. Nothing is
* lost, since only EV6 -- which traps precisely and
* never comes this way -- needs it.
*/
regs->pc = trigger_pc + 4;
si_code = alpha_fp_emul(trigger_pc);
si_code = alpha_fp_emul(trigger_pc, 0);
goto egress;
}
trigger_pc -= 4;
Expand Down
2 changes: 1 addition & 1 deletion arch/arm/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ config ARM
select HAVE_ARCH_TRACEHOOK
select HAVE_ARCH_TRANSPARENT_HUGEPAGE if ARM_LPAE
select HAVE_ARM_SMCCC if CPU_V7
select HAVE_EBPF_JIT if !CPU_ENDIAN_BE32
select HAVE_EBPF_JIT if !CPU_ENDIAN_BE32 && !CPU_32v3
select HAVE_CONTEXT_TRACKING_USER
select HAVE_C_RECORDMCOUNT
select HAVE_BUILDTIME_MCOUNT_SORT
Expand Down
9 changes: 6 additions & 3 deletions arch/arm64/boot/dts/qcom/kodiak.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -191,9 +191,12 @@
qcom,vmid = <QCOM_SCM_VMID_MSS_MSA>;
};

adsp_rpc_remote_heap_mem: adsp-rpc-remote-heap@9cb80000 {
reg = <0x0 0x9cb80000 0x0 0x800000>;
no-map;
adsp_rpc_remote_heap_mem: adsp-rpc-remote-heap {
compatible = "shared-dma-pool";
alloc-ranges = <0x0 0x80000000 0x0 0x80000000>;
reusable;
alignment = <0x0 0x400000>;
size = <0x0 0x800000>;
};
};

Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/qcom/sm6115-fxtec-pro1x.dts
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@

interrupts-extended = <&tlmm 80 IRQ_TYPE_LEVEL_LOW>;

irq-gpios = <&tlmm 80 IRQ_TYPE_LEVEL_LOW>;
irq-gpios = <&tlmm 80 GPIO_ACTIVE_LOW>;
reset-gpios = <&tlmm 71 GPIO_ACTIVE_HIGH>;
AVDD28-supply = <&ts_vdd_supply>;
VDDIO-supply = <&ts_vddio_supply>;
Expand Down
2 changes: 2 additions & 0 deletions arch/arm64/boot/dts/qcom/x1-dell-thena.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -589,6 +589,7 @@
regulator-min-microvolt = <1200000>;
regulator-max-microvolt = <1200000>;
regulator-initial-mode = <RPMH_REGULATOR_MODE_HPM>;
regulator-always-on;
};

vreg_l13b_3p0: ldo13 {
Expand All @@ -610,6 +611,7 @@
regulator-min-microvolt = <1800000>;
regulator-max-microvolt = <1800000>;
regulator-initial-mode = <RPMH_REGULATOR_MODE_HPM>;
regulator-always-on;
};
};

Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-cobra.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

gpio-leds {
Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-pp1516.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

gpio-leds {
Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

leds {
Expand Down
Loading
Loading