Commit Graph

1165241 Commits

Author SHA1 Message Date
Chenghao Zhao
2cd8ac816d ANDROID: ABI: update symbol list for honor
2 function symbol(s) added
  'int netdev_get_name(struct net*, char*, int)'
  'void tcp_send_active_reset(struct sock*, gfp_t)'

Bug: 334000512
Change-Id: I83507ca33d4547088b61c6f83cfb48cc94474185
Signed-off-by: Chenghao Zhao <zhaochenghao@honor.com>
2024-09-23 20:37:44 +00:00
Dezhi Huang
b5ee53c64e ANDROID: Allow vendor modules perform more operationson on sock.
Export netdev_get_name, tcp_send_active_reset functions, allow vendor
modules perform more operations on socks and improve users' online
experience.When users browse websites or watch videos, we will sense
the bad sock is on which device, so that the sock can be switched to
another good device by us, so that the internet service will no longer
be stuck. In a similar scenario, if the user downloads from multiple
devices and the rate of one device is low,we can reset the TCP stream
with a lower rate and establish it on the device with a higher rate.

Bug: 334000512
Change-Id: I9ed90ea9fe6f3dc9f11ae1661ca9f2f5fdad5820
Signed-off-by: Dezhi Huang <huangdezhi@hihonor.com>
(cherry picked from commit 21614c79408f0342363db9874d315fbb3ff6553b)
2024-09-23 20:37:44 +00:00
Yuxuan Yan
e64a80a096 ANDROID: GKI: update symbol list file for xiaomi
add 3 function:
    android_vh_page_should_be_protected()
    android_vh_page_referenced_check_bypass()
    __page_mapcount()

Bug: 348285765

Change-Id: Idbcdf69693a3f4e83ada35aebf3f138648c73d10
Signed-off-by: Yuxuan Yan <yanyuxuan3@xiaomi.corp-partner.google.com>
2024-09-23 18:25:57 +00:00
Yuxuan Yan
530ff6a3e6 ANDROID: GKI: add vendor hooks android_vh_page_should_be_protected() and
android_vh_modify_scan_control().

add two vendor hooks:
    android_vh_page_should_be_protected():protect pages from memory
reclaim.
    android_vh_page_referenced_check_bypass():bypass rmap in active list
shrink.

The new vendor data field in scan_control are used to track how many
pages are protected in current reclaim and the "protected / scanned"
rate. These parameters are useful for understanding the impact of page
protection operations on LRU and reclaim, helping us make better
decsions.

Bug: 348285765
Change-Id: I49567a4b1f978821a94da0a8339b2b8fdfd52daf
Signed-off-by: Yuxuan Yan <yanyuxuan3@xiaomi.corp-partner.google.com>
2024-09-23 18:25:57 +00:00
Greg Kroah-Hartman
41e1c6f937 Merge tag 'android14-6.1.99_r00' into android14-6.1
This merges up to the 6.1.99 LTS release into android14-6.1.  This
includes the following commits:

*   12f9bcc034 Merge 6.1.99 into android14-6.1-lts
|\
| * cac15753b8 Linux 6.1.99
| * 1f4a10cb82 Revert "usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB"
* | e6e7b1084c Merge 6.1.98 into android14-6.1-lts
|\|
| * 266ee8e06d Linux 6.1.98
| * 86e3ffeab5 nilfs2: fix incorrect inode allocation from reserved inodes
| * a077a6cdb3 null_blk: Do not allow runt zone with zone capacity smaller then zone size
| * 2fed4a94bc spi: cadence: Ensure data lines set to low during dummy-cycle period
| * 41f5e2840c nfc/nci: Add the inconsistency check between the input data length and count
| * 833112b7f1 kbuild: fix short log for AS in link-vmlinux.sh
| * 940a71f08e nvmet: fix a possible leak when destroy a ctrl during qp establishment
| * 273a824a9c platform/x86: touchscreen_dmi: Add info for the EZpad 6s Pro
| * 363585e3fc platform/x86: touchscreen_dmi: Add info for GlobalSpace SolT IVW 11.6" tablet
| * 85646d7796 regmap-i2c: Subtract reg size from max_write
| * 62fc41a69c nvme: adjust multiples of NVME_CTRL_PAGE_SIZE in offset
| * ce39d85705 dma-mapping: benchmark: avoid needless copy_to_user if benchmark fails
| * d62da841bf nvme-multipath: find NUMA path only for online numa-node
| * 154f4ca807 ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897
| * 850ef5d239 fs/ntfs3: Mark volume as dirty if xattr is broken
| * 3d32327f5c i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr
| * 7069aa6d41 clk: mediatek: mt8183: Only enable runtime PM on mt8183-mfgcfg
| * e3e33879d6 clk: mediatek: clk-mtk: Register MFG notifier in mtk_clk_simple_probe()
| * 661baa1711 clk: qcom: gcc-sm6350: Fix gpll6* & gpll7 parents
| * e5411f2653 media: dw2102: fix a potential buffer overflow
| * 9c3906c373 ima: Avoid blocking in RCU read-side critical section
| * ee42c15083 arm64: dts: rockchip: Fix the DCDC_REG2 minimum voltage on Quartz64 Model B
| * 9504a15506 bnx2x: Fix multiple UBSAN array-index-out-of-bounds
| * 1c67f79350 mtd: rawnand: rockchip: ensure NVDDR timings are rejected
| * 670f841c07 mtd: rawnand: Bypass a couple of sanity checks during NAND identification
| * ca0f2e7244 mtd: rawnand: Ensure ECC configuration is propagated to upper layers
| * c550679d60 powerpc/pseries: Fix scv instruction crash with kexec
| * dd4674d016 drm: panel-orientation-quirks: Add quirk for Valve Galileo
| * 742cac675f drm/amdgpu/atomfirmware: silence UBSAN warning
| * 1f32535238 drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
| * cbbe17a324 Revert "mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again"
| * 4e0716110a fsnotify: Do not generate events for O_PATH file descriptors
| * 44aa3e76f4 can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct
| * e6e200b264 Bluetooth: qca: Fix BT enable failure again for QCA6390 after warm reboot
| * c126aff74a scsi: mpi3mr: Use proper format specifier in mpi3mr_sas_port_add()
| * 525ad8dd9a f2fs: Add inline to f2fs_build_fault_attr() stub
| * aa1d8cc0cc btrfs: fix adding block group to a reclaim list and the unused list during reclaim
| * c83ed422c2 mm: avoid overflows in dirty throttling logic
| * d259d0c375 mm: optimize the redundant loop of mm_update_owner_next()
| * 1b7d549ed2 nilfs2: add missing check for inode numbers on directory entries
| * fae1959d6a nilfs2: fix inode number range checks
| * 98c8958980 Revert "igc: fix a log entry using uninitialized netdev"
| * 89a5f0625f platform/x86: toshiba_acpi: Fix quickstart quirk handling
| * ab557f5cd9 mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file
| * d6f487e070 inet_diag: Initialize pad field in struct inet_diag_req_v2
| * 8d9fa5e82e selftests: make order checking verbose in msg_zerocopy selftest
| * fb8fc89b5c selftests: fix OOM in msg_zerocopy selftest
| * c8eb8ab9a4 bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()
| * 4c06c13317 netfilter: nf_tables: unconditionally flush pending work before notifier
| * 653deee48a riscv: kexec: Avoid deadlock in kexec crash path
| * b610a87538 wifi: wilc1000: fix ies_len type in connect path
| * 4b3b6c7efe net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx()
| * 12f6119d86 net: allow skb_datagram_iter to be called from any context
| * b368762d1e e1000e: Fix S0ix residency on corporate systems
| * c159afd3b5 KVM: s390: fix LPSWEY handling
| * 31f03bb041 tcp_metrics: validate source addr length
| * f8b7bd500d net/mlx5e: Add mqprio_rl cleanup and free in mlx5e_priv_cleanup()
| * bc3ff8d3c0 net/mlx5: E-switch, Create ingress ACL when needed
| * 965fbc6d9a UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()
| * a0d1afe8a9 mac802154: fix time calculation in ieee802154_configure_durations()
| * 325d8659b8 tools/power turbostat: Remember global max_die_id
| * 0c97527e91 cdrom: rearrange last_media_change check to avoid unintentional overflow
| * c0d7a3b290 btrfs: scrub: initialize ret in scrub_simple_mirror() to fix compilation warning
| * c51795885c s390/pkey: Wipe sensitive data on failure
| * 751987a5d8 jffs2: Fix potential illegal address access in jffs2_free_inode
| * e1683ff4eb serial: imx: Raise TX trigger level to 8
| * b869ec89d2 scsi: mpi3mr: Sanitise num_phys
| * bc84dd2c33 f2fs: check validation of fault attrs in f2fs_build_fault_attr()
| * a21d76bd0b bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD
| * 2e9d8aa52b igc: fix a log entry using uninitialized netdev
| * ce8d496786 powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
| * ae9edc2b17 kunit: Fix timeout message
| * 74159d409d orangefs: fix out-of-bounds fsid access
| * 9c06fe8cfb powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n
| * d4889c95bc i2c: i801: Annotate apanel_addr as __ro_after_init
| * 1663e2474e media: dvb-frontends: tda10048: Fix integer overflow
| * 1aa04c84a3 media: s2255: Use refcount_t instead of atomic_t for num_channels
| * fa547cdd7b media: dvb-frontends: tda18271c2dd: Remove casting during div
| * aa03f591ef net: dsa: mv88e6xxx: Correct check for empty list
| * 22ea2a7f0b wifi: mt76: replace skb_put with skb_put_zero
| * 948554f1bb usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB
| * 46c82c5e4c Input: ff-core - prefer struct_size over open coded arithmetic
| * d792fc8f7a firmware: dmi: Stop decoding on broken entry
| * f2c9c42f6b sctp: prefer struct_size over open coded arithmetic
| * a010daa33e media: dw2102: Don't translate i2c read into write
| * ee18ed34a2 drm/amdgpu: fix uninitialized scalar variable warning
| * 874261358d drm/amd/display: Skip finding free audio for unknown engine_id
| * d2c3645a4a drm/amd/display: Check pipe offset before setting vblank
| * ae91ffbc8b drm/amd/display: Check index msg_id before read or write
| * bf312c0529 drm/amdgpu: Initialize timestamp for some legacy SOCs
| * 7eb74d14c7 drm/amdgpu: Fix uninitialized variable warnings
| * 28c8d27484 crypto: aead,cipher - zeroize key buffer after use
| * fa49c65a1c scsi: qedf: Make qedf_execute_tmf() non-preemptible
| * 63d202d948 IB/core: Implement a limit on UMAD receive List
| * 95e9377c7c media: dvb-usb: dib0700_devices: Add missing release_firmware()
| * c72990a6a7 media: dvb: as102-fe: Fix as10x_register_addr packing
| * 8d3f83dfb2 powerpc: Avoid nmi_enter/nmi_exit in real mode interrupt.
| * 0a487e977c drm/lima: fix shared irq handling on driver remove
| * eda60520cf crypto: hisilicon/debugfs - Fix debugfs uninit process issue
| * 42d64dbe4b locking/mutex: Introduce devm_mutex_init()
* | e44db5756e ANDROID: db845c symbol list additions
* | ab63f81b3a Revert "mm/page_alloc: Separate THP PCP into movable and non-movable categories"
* | 9a2454ec58 Merge 6.1.97 into android14-6.1-lts
|\|
| * 7753af06ee Linux 6.1.97
| * f19cca5d16 tracing/net_sched: NULL pointer dereference in perf_trace_qdisc_reset()
| * fbfd2c876c serial: 8250_omap: Fix Errata i2310 with RX FIFO level check
| * 1dc9d05040 serial: imx: only set receiver level if it is zero
| * 16d92a6dfa arm64: dts: rockchip: Add sound-dai-cells for RK3368
| * 4e66009d35 arm64: dts: rockchip: fix PMIC interrupt pin on ROCK Pi E
| * 2581e814d7 ARM: dts: rockchip: rk3066a: add #sound-dai-cells to hdmi node
| * bccc0c847f arm64: dts: rockchip: Rename LED related pinctrl nodes on rk3308-rock-pi-s
| * b619f741b6 arm64: dts: rockchip: Fix SD NAND and eMMC init on rk3308-rock-pi-s
| * fcafdf32ac efi/x86: Free EFI memory map only when installing a new one.
| * 01b3cddfa6 efi: xen: Set EFI_PARAVIRT for Xen dom0 boot on all architectures
| * 0d01140e92 efi: memmap: Move manipulation routines into x86 arch tree
| * 7ad4e0a4f6 gfs2: Fix slab-use-after-free in gfs2_qd_dealloc
| * 447434eaaf mm/page_alloc: Separate THP PCP into movable and non-movable categories
| * 978e27ff31 Revert "cpufreq: amd-pstate: Fix the inconsistency in max frequency units"
| * d2b5636883 pwm: stm32: Refuse too small period requests
| * f910aee90b syscalls: fix sys_fanotify_mark prototype
| * e1b88ac1fe syscalls: fix compat_sys_io_pgetevents_time64 usage
| * 5ae6af6841 ftruncate: pass a signed offset
| * 702c1edbaf ata: libata-core: Fix double free on error
| * 5f0d0bf9f5 ata: ahci: Clean up sysfs file on error
| * f926c022eb can: mcp251xfd: fix infinite loop when xmit fails
| * 778a8e67c7 batman-adv: Don't accept TT entries for out-of-spec VIDs
| * c92a15b3b2 drm/amdgpu/atomfirmware: fix parsing of vram_info
| * 30cbf6ffaf drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
| * ca0fabd365 drm/i915/gt: Fix potential UAF by revoke of fence registers
| * 6ce0544cab drm/amdgpu: avoid using null object of framebuffer
| * f95ed0f54b drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
| * 948dc69f4b hexagon: fix fadvise64_64 calling conventions
| * 0f92275527 csky, hexagon: fix broken sys_sync_file_range
| * 87936f517b btrfs: zoned: fix initial free space detection
| * 41dd6b0ec7 sh: rework sync_file_range ABI
| * bf3c44f67c kbuild: Install dtb files as 0644 in Makefile.dtbinst
| * 84394f35b6 irqchip/loongson-liointc: Set different ISRs for different cores
| * 71af0f2f22 cpu/hotplug: Fix dynstate assignment in __cpuhp_setup_state_cpuslocked()
| * e0560219db cpufreq: intel_pstate: Use HWP to initialize ITMT if CPPC is missing
| * 26b18dd30e net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new
| * 4ff6978921 net: can: j1939: recover socket queue on CAN bus error during BAM transmission
| * f97cbce633 net: can: j1939: Initialize unused data in j1939_send_one()
| * a44aedd512 tty: mcf: MCF54418 has 10 UARTS
| * 94307bc31b ALSA: hda/realtek: fix mute/micmute LEDs don't work for EliteBook 645/665 G11.
| * e97ef9a3a3 serial: imx: set receiver level before starting uart
| * 98840e410d serial: 8250_omap: Implementation of Errata i2310
| * a47407ae12 usb: ucsi: stm32: fix command completion handling
| * a11b71624b usb: gadget: aspeed_udc: fix device address configuration
| * d77e2b5104 usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock
| * 5584c776a1 usb: atm: cxacru: fix endpoint checking in cxacru_bind()
| * 7afa50ce46 usb: musb: da8xx: fix a resource leak in probe()
| * e9835f39a8 usb: gadget: printer: fix races against disable
| * e48b92ed16 usb: gadget: printer: SS+ support
| * a59d84377d net: usb: ax88179_178a: improve link status logs
| * d441ad2aa9 iio: chemical: bme680: Fix sensor data read operation
| * ba1bb3e2a3 iio: chemical: bme680: Fix overflows in compensate() functions
| * 94f303ed7b iio: chemical: bme680: Fix calibration data variable
| * 4decfc47a1 iio: chemical: bme680: Fix pressure value output
| * 90d4d02b37 iio: accel: fxls8962af: select IIO_BUFFER & IIO_KFIFO_BUF
| * df188072b5 iio: adc: ad7266: Fix variable checking bug
| * 274239d9f8 i2c: testunit: discard write requests while old command is running
| * 86826b1ffd i2c: testunit: don't erase registers after STOP
| * 8cfb468a67 counter: ti-eqep: enable clock at probe
| * 70516c5ff3 iio: xilinx-ams: Don't include ams_ctrl_channels in scan_mask
| * f8ec1677ce mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
| * 2f3555c20a mmc: sdhci: Do not invert write-protect twice
| * dca15c1861 mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
| * 81027f81c4 mmc: sdhci-brcmstb: check R1_STATUS for erase/trim/discard
| * ea6beb811b nfs: drop the incorrect assertion in nfs_swap_rw()
| * 9ea2d1c678 ocfs2: fix DIO failure due to insufficient transaction credits
| * a4f9251e4b pinctrl: qcom: spmi-gpio: drop broken pm8008 support
| * ceabd79fd4 Revert "MIPS: pci: lantiq: restore reset gpio polarity"
| * 3ae15c0238 parisc: use generic sys_fanotify_mark implementation
| * 161cef8185 x86: stop playing stack games in profile_pc()
| * 7fb374981e ima: Fix use-after-free on a dentry's dname.name
| * b793177141 randomize_kstack: Remove non-functional per-arch entropy filtering
| * 31594c5a42 gpiolib: cdev: Disallow reconfiguration without direction (uAPI v1)
| * c3b425744d riscv: stacktrace: convert arch_stack_walk() to noinstr
| * 09f64e7ad7 drm/amdgpu: Fix pci state save during mode-1 reset
| * 87a2448efc drm/amd/amdgpu: Fix style errors in amdgpu_drv.c & amdgpu_device.c
| * 89d7008af4 gpio: davinci: Validate the obtained number of IRQs
| * c717cef1ff drm/panel: simple: Add missing display timing flags for KOE TX26D202VM0BWA
| * d8e2766655 nvme: fixup comment for nvme RDMA Provider Type
| * b719f2bc76 drm/radeon/radeon_display: Decrease the size of allocated memory
| * 9e424deb9a soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message
| * 06c5331047 media: dvbdev: Initialize sbuf
| * d0ff2443fc ALSA: emux: improve patch ioctl data validation
| * fd7ef32591 crypto: ecdh - explicitly zeroize private_key
| * 48147337d7 net/dpaa2: Avoid explicit cpumask var allocation on stack
| * d85ca8179a net/iucv: Avoid explicit cpumask var allocation on stack
| * 782bdaf9d0 RDMA/restrack: Fix potential invalid address access
| * b30f3197a6 bpf: Mark bpf prog stack with kmsan_unposion_memory in interpreter mode
| * 5bcb9cf62f bpf: Add a check for struct bpf_fib_lookup size
| * cc33a7a2f1 wifi: ieee80211: check for NULL in ieee80211_mle_size_ok()
| * 081938266a mtd: partitions: redboot: Added conversion of operands to a larger type
| * ed1fa6d6af x86/fpu: Fix AMD X86_BUG_FXSAVE_LEAK fixup
| * 7d18ab6e4f vduse: Temporarily fail if control queue feature requested
| * d99a4e147b vduse: validate block features only with block devices
| * 5f41401219 drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
| * e4f602e3ff bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
| * efb27ad059 netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers
| * 736c74dc60 tcp: fix tcp_rcv_fastopen_synack() to enter TCP_CA_Loss for failed TFO
| * 853c0387ac powerpc: restore some missing spu syscalls
| * 2eb9a4bc63 parisc: use correct compat recv/recvfrom syscalls
| * ef03810c9a sparc: fix compat recv/recvfrom syscalls
| * 04c1271243 sparc: fix old compat_sys_select()
| * f75c21bf73 net: dsa: microchip: fix wrong register write when masking interrupt
| * c14f3c3793 Fix race for duplicate reqsk on identical SYN
| * 4e0c539ee2 xdp: Remove WARN() from __xdp_reg_mem_model()
| * 75fabdc911 net: dsa: microchip: use collision based back pressure mode
| * aecaaf8abd net: phy: micrel: add Microchip KSZ 9477 to the device table
| * 5516c9ee2a ibmvnic: Free any outstanding tx skbs during scrq reset
| * d1b9df0435 bpf: Fix overrunning reservations in ringbuf
| * bfa86a9691 mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4 systems
| * 2dfaf2c4b3 net: dsa: microchip: fix initial port flush problem
| * 8faf91e584 ASoC: fsl-asoc-card: set priv->pdev before using it
| * 20f19c91da ASoC: amd: acp: remove i2s configuration check in acp_i2s_probe()
| * d9912994a0 s390/pci: Add missing virt_to_phys() for directed DIBV
| * 87358401ed ASoC: rockchip: i2s-tdm: Fix trcm mode by setting clock on right mclk
| * b45176b869 netfilter: nf_tables: use timestamp to check for set element timeout
| * 7491c3c55c dt-bindings: i2c: atmel,at91sam: correct path to i2c-controller schema
| * 58d65ce94b dt-bindings: i2c: Drop unneeded quotes
| * 777f3c9954 MIPS: pci: lantiq: restore reset gpio polarity
| * ae7b2aa805 pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
| * 8a5859bb14 pinctrl: rockchip: use dedicated pinctrl type for RK3328
| * 6bed115e5e pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
| * 940ce6f283 pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
| * b36efd2e3e pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
| * 4312eace43 Input: ili210x - fix ili251x_read_touch_data() return value
| * b2f1ce6cc9 ACPI: x86: Force StorageD3Enable on more products
| * c538c8861c ACPI: x86: utils: Add Picasso to the list for forcing StorageD3Enable
| * 411e6aa90a usb: typec: ucsi: Ack also failed Get Error commands
| * 8cace39c77 usb: typec: ucsi: Never send a lone connector change ack
* | 47b24bf8ea Revert "net/sched: fix false lockdep warning on qdisc root lock"
* | 0a6ad70f07 Revert "net/sched: unregister lockdep keys in qdisc_create/qdisc_alloc error path"
* | 325f5b8ed9 Revert "tty: add the option to have a tty reject a new ldisc"
* | 7455bf543f Merge 6.1.96 into android14-6.1-lts
|\|
| * 99e6a620de Linux 6.1.96
| * 19526f54ec Revert "mm: mmap: allow for the maximum number of bits for randomizing mmap_base by default"
| * 8a630e8acd hid: asus: asus_report_fixup: fix potential read out of bounds
| * 48d3f91d83 net/sched: unregister lockdep keys in qdisc_create/qdisc_alloc error path
| * d04943bb69 drm/amd/display: revert Exit idle optimizations before HDCP execution
| * 5efe0b5deb kheaders: explicitly define file modes for archived headers
| * f0b5d1d9fe Revert "kheaders: substituting --sort in archive creation"
| * 8ab1361b2e x86/cpu: Fix x86_match_cpu() to match just X86_VENDOR_INTEL
| * b0727ed7ba x86/cpu/vfm: Add new macros to work with (vendor/family/model) values
| * 6efd1d4b1f tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
| * 8d5d123f62 pmdomain: ti-sci: Fix duplicate PD referrals
| * 95881ebdb4 ARM: dts: samsung: smdk4412: fix keypad no-autorepeat
| * 7c1448ea11 ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat
| * 2df48353fa ARM: dts: samsung: smdkv310: fix keypad no-autorepeat
| * 8154edd62a perf script: Show also errors for --insn-trace option
| * 4bd6f883bd perf: script: add raw|disasm arguments to --insn-trace option
| * 520f28926a spi: stm32: qspi: Clamp stm32_qspi_get_mode() output to CCR_BUSWIDTH_4
| * 56de6648a4 arm64: dts: imx8qm-mek: fix gpio number for reg_usdhc2_vmmc
| * 065494adab spi: stm32: qspi: Fix dual flash mode sanity test in stm32_qspi_setup()
| * fd6cfb11d7 dt-bindings: i2c: google,cros-ec-i2c-tunnel: correct path to i2c-controller schema
| * 92278b2dd1 i2c: ocores: set IACK bit after core is enabled
| * 51897f9935 mm/page_table_check: fix crash on ZONE_DEVICE
| * 6f7c39a675 tcp: clear tp->retrans_stamp in tcp_rcv_fastopen_synack()
| * 665e932600 mm: mmap: allow for the maximum number of bits for randomizing mmap_base by default
| * 4cb3b5bc4c kcov: don't lose track of remote references during softirqs
| * 9ad023010e gcov: add support for GCC 14
| * fc5cb952e6 drm/amdgpu: fix UBSAN warning in kv_dpm.c
| * f803532bc3 drm/radeon: fix UBSAN warning in kv_dpm.c
| * 013e8f2371 drm/i915/mso: using joiner is not possible with eDP MSO
| * 661882cfe5 ALSA: hda/realtek: Limit mic boost on N14AP7
| * 72eed766d9 ALSA: hda/realtek: fix mute/micmute LEDs don't work for ProBook 445/465 G11.
| * 9e6e37d9d6 KVM: x86: Always sync PIR to IRR prior to scanning I/O APIC routes
| * 68df4fc449 KVM: arm64: Disassociate vcpus from redistributor region on teardown
| * 92c77807d9 KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
| * b95fce863b cifs: fix typo in module parameter enable_gcm_256
| * 15cb476ceb btrfs: retry block group reclaim without infinite loop
| * 893eeba94c net: do not leave a dangling sk pointer, when socket creation fails
| * 44f521431f net: usb: ax88179_178a: improve reset check
| * dda369a760 net: stmmac: Assign configured channel value to EXTTS event
| * d8abba1e3c MIPS: dts: bcm63268: Add missing properties to the TWD node
| * 2703312590 kbuild: Remove support for Clang's ThinLTO caching
| * 9995864186 RDMA/mlx5: Add check for srq max_sge attribute
| * a331f275cb firmware: psci: Fix return value from psci_system_suspend()
| * ddc1f5f124 ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine."
| * 87d2639f8a arm64: dts: freescale: imx8mm-verdin: enable hysteresis on slow input pin
| * 97af5de2cb arm64: dts: imx93-11x11-evk: Remove the 'no-sdio' property
| * 474a1661f4 regulator: bd71815: fix ramp values
| * 6136f19e52 dmaengine: ioatdma: Fix missing kmem_cache_destroy()
| * 6a104377d4 dmaengine: ioatdma: Fix kmemleak in ioat_pci_probe()
| * 98b35b2b7e dmaengine: ioatdma: Fix error path in ioat3_dma_probe()
| * d7f4e58f1b dmaengine: ioat: use PCI core macros for PCIe Capability
| * 98d79caf37 dmaengine: ioatdma: Fix leaking on version mismatch
| * 95dc59ba94 dmaengine: ioat: Drop redundant pci_enable_pcie_error_reporting()
| * 83163667d8 dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list
| * 1bd1857fed regulator: core: Fix modpost error "regulator_get_regmap" undefined
| * 1803875fef net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings
| * e214f102e0 bnxt_en: Restore PTP tx_avail count in case of skb_pad() error
| * dd37b86999 ice: Fix VSI list rule with ICE_SW_LKUP_LAST type
| * ec4d970b59 seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors
| * 788d585e62 netfilter: ipset: Fix suspicious rcu_dereference_protected()
| * 49780570bf octeontx2-pf: Add error handling to VLAN unoffload handling
| * 04619db397 virtio_net: checksum offloading handling fix
| * 521d42a1c2 net: stmmac: No need to calculate speed divider when offload is disabled
| * d50d62d5e6 ptp: fix integer overflow in max_vclocks_store
| * 2f82f75f84 sched: act_ct: add netns into the key of tcf_ct_flow_table
| * 623c90d86a tipc: force a dst refcount before doing decryption
| * 6fc78d67f5 net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
| * 668be2b635 net/sched: act_api: rely on rcu in tcf_idr_check_alloc
| * 5bd1b7ab6a net: phy: mxl-gpy: Remove interrupt mask clearing from config_init
| * 70993aca4f net: phy: mxl-gpy: enhance delay time required by loopback disable function
| * 7d0606bdd7 net: lan743x: Support WOL at both the PHY and MAC appropriately
| * 2af9aa9ac6 net: lan743x: disable WOL upon resume to restore full data path operation
| * e2ec071727 qca_spi: Make interrupt remembering atomic
| * 1b631bffcb netns: Make get_net_ns() handle zero refcount net
| * 83c02fb2cc xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
| * 51ee2f7c30 ipv6: prevent possible NULL dereference in rt6_probe()
| * 88b9a55e2e ipv6: prevent possible NULL deref in fib6_nh_init()
| * a02fd5d775 netrom: Fix a memory leak in nr_heartbeat_expiry()
| * eb1bde62d6 ALSA: hda/realtek: Enable headset mic on IdeaPad 330-17IKB 81DM
| * dacc15e9cb bpf: Avoid splat in pskb_pull_reason
| * 7dabc4b45b cipso: fix total option length computation
| * 224b69e875 ice: avoid IRQ collision to fix init failure on ACPI S3 resume
| * 531d85b4fb ice: move RDMA init to ice_idc.c
| * 7de448db67 ALSA/hda: intel-dsp-config: Document AVS as dsp_driver option
| * 71b027d3c0 ALSA: hda/realtek: Remove Framework Laptop 16 from quirks
| * 32ef4dc2b1 tracing: Build event generation tests only as modules
| * 6c0f6ccd93 mips: bmips: BCM6358: make sure CBR is correctly set
| * a6061f60e1 MIPS: Routerboard 532: Fix vendor retry check code
| * 3c6332f3bb tty: add the option to have a tty reject a new ldisc
| * 6466b91968 usb: gadget: function: Remove usage of the deprecated ida_simple_xx() API
| * 3b3655a1d3 serial: exar: adding missing CTI and Exar PCI ids
| * 7f9e70c68b serial: imx: Introduce timeout when waiting on transmitter empty
| * d996deb803 MIPS: Octeon: Add PCIe link status check
| * 70196feadb PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
| * 29dfe9e844 udf: udftime: prevent overflow in udf_disk_stamp_to_time()
| * 69170a888e usb: dwc3: pci: Don't set "linux,phy_charger_detect" property on Lenovo Yoga Tab2 1380
| * dd42570018 Avoid hw_desc array overrun in dw-axi-dmac
| * 8fc246a8a4 usb: misc: uss720: check for incompatible versions of the Belkin F5U002
| * a9cea0489c f2fs: remove clear SB_INLINECRYPT flag in default_options
| * 8092775cb6 iommu/arm-smmu-v3: Free MSIs in case of ENOMEM
| * 10c19cf7a1 power: supply: cros_usbpd: provide ID table for avoiding fallback match
| * 5cb3339b6d platform/x86: p2sb: Don't init until unassigned resources have been assigned
| * 7bbcd3b1c2 powerpc/io: Avoid clang null pointer arithmetic warnings
| * 8aa11aa001 powerpc/pseries: Enforce hcall result buffer validity and size
| * cf56640e9a ALSA: hda/realtek: Add quirks for Lenovo 13X
| * 9fd8ddd237 drm/lima: mask irqs in timeout path before hard reset
| * 394d660678 drm/lima: add mask irq callback to gp and pp
| * 4cd1360c63 ASoC: Intel: sof_sdw: add JD2 quirk for HP Omen 14
| * 6239d65b91 platform/x86: toshiba_acpi: Add quirk for buttons on Z830
| * fc1f030978 drm/amd/display: Exit idle optimizations before HDCP execution
| * be4a1fc857 Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
| * aa2fb9c54c HID: asus: fix more n-key report descriptors if n-key quirked
| * 5368c463bc HID: Add quirk for Logitech Casa touchpad
| * 0b81faa05b wifi: mt76: mt7921s: fix potential hung tasks during chip recovery
| * 96826b16ef netpoll: Fix race condition in netpoll_owner_active
| * e8fc7647a8 net: dsa: realtek: keep default LED state in rtl8366rb
| * d927fae287 kselftest: arm64: Add a null pointer check
| * 048b33817a net/sched: fix false lockdep warning on qdisc root lock
| * eaddb86637 scsi: qedi: Fix crash while reading debugfs attribute
| * f251ccef1d drop_monitor: replace spin_lock by raw_spin_lock
| * 63310043ac af_packet: avoid a false positive warning in packet_setsockopt()
| * 2e48d73577 wifi: ath9k: work around memset overflow warning
| * fed7914858 batman-adv: bypass empty buckets in batadv_purge_orig_ref()
| * 63f2d5373d selftests/bpf: Fix flaky test btf_map_in_map/lookup_update
| * fb9088a7a7 selftests/bpf: Prevent client connect before server bind in test_tc_tunnel.sh
| * 61ec76ec93 block/ioctl: prefer different overflow check
| * cf9b1652b4 rcutorture: Fix invalid context warning when enable srcu barrier testing
| * dbd4175e5e rcutorture: Make stall-tasks directly exit when rcutorture tests end
| * 9bc282fb8a rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment
| * 55c22375cb io_uring/sqpoll: work around a potential audit memory leak
| * 7c42ce556f crypto: hisilicon/sec - Fix memory leak for sec resource release
| * 4925da0896 padata: Disable BH when taking works lock on MT path
* | cb7d32c26d Merge aosp/android14-6.1 to aosp/android14-6.1-lts
* | 6f4a686ac9 Revert "i2c: add fwnode APIs"
* | efbc7c7549 Revert "i2c: acpi: Unbind mux adapters before delete"
* | ced5058778 Merge 6.1.95 into android14-6.1-lts
|\|
| * a6398e3730 Linux 6.1.95
| * edd2754a62 zap_pid_ns_processes: clear TIF_NOTIFY_SIGNAL along with TIF_SIGPENDING
| * e44999ec0b i2c: designware: Fix the functionality flags of the slave-only interface
| * 1a0bbb90f3 i2c: at91: Fix the functionality flags of the slave-only interface
| * ea25a4c0de misc: microchip: pci1xxxx: Fix a memory leak in the error handling of gp_aux_bus_probe()
| * e0e2eec769 usb-storage: alauda: Check whether the media is initialized
| * ae917519ba serial: core: Add UPIO_UNKNOWN constant for unknown port type
| * 29d35f0b53 serial: 8250_dw: fall back to poll if there's no interrupt
| * 9a733d69a4 greybus: Fix use-after-free bug in gb_interface_release due to race condition.
| * 12a4a28eae Bluetooth: qca: generalise device address check
| * 47988653a4 Bluetooth: qca: fix wcn3991 device address check
| * 9afc658ce7 cachefiles, erofs: Fix NULL deref in when cachefiles is not doing ondemand-mode
| * 4733dea73c remoteproc: k3-r5: Jump to error handling labels in start/stop errors
| * 04b0c41912 Revert "fork: defer linking file vma until vma is fully initialized"
| * 35e395373e mptcp: pm: update add_addr counters after connect
| * 51861fc086 serial: 8250_pxa: Configure tx_loadsz to match FIFO IRQ level
| * 00b0752c7f mm/memory-failure: fix handling of dissolved but not taken off from buddy pages
| * b2494506f3 mm/huge_memory: don't unpoison huge_zero_folio
| * 2641261b93 tick/nohz_full: Don't abuse smp_call_function_single() in tick_setup_device()
| * 271dcd977c nilfs2: fix potential kernel bug due to lack of writeback flag waiting
| * 1776596470 btrfs: zoned: fix use-after-free due to race with dev replace
| * babfd2d0d5 btrfs: zoned: factor out DUP bg handling from btrfs_load_block_group_zone_info
| * 43a89d48bd btrfs: zoned: factor out single bg handling from btrfs_load_block_group_zone_info
| * 7fd274c062 btrfs: zoned: factor out per-zone logic from btrfs_load_block_group_zone_info
| * c60f0a442d btrfs: zoned: introduce a zone_info struct in btrfs_load_block_group_zone_info
| * d2fa51eb9c intel_th: pci: Add Lunar Lake support
| * 5b64a368e3 intel_th: pci: Add Meteor Lake-S support
| * a1fb1bd6c0 intel_th: pci: Add Sapphire Rapids SOC support
| * b7b6bc60ed intel_th: pci: Add Granite Rapids SOC support
| * bb8b9d91f7 intel_th: pci: Add Granite Rapids support
| * 3272801490 drm/i915/dpt: Make DPT object unshrinkable
| * d205e30216 drm/i915/gt: Disarm breadcrumbs if engines are already idle
| * 919f862609 riscv: rewrite __kernel_map_pages() to fix sleeping in invalid context
| * dd5042eed5 remoteproc: k3-r5: Do not allow core1 to power up before core0 via sysfs
| * 2a1ec20b17 remoteproc: k3-r5: Wait for core0 power-up before powering up core1
| * f6a426a0c4 dmaengine: axi-dmac: fix possible race in remove()
| * eab9d5a846 PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
| * ea042dc2be ocfs2: fix races between hole punching and AIO+DIO
| * a2e8105eb2 ocfs2: use coarse time for new created files
| * a373ad833a fs/proc: fix softlockup in __read_vmcore
| * 06bea44b93 knfsd: LOOKUP can return an illegal error value
| * bbce9fb50c spmi: hisi-spmi-controller: Do not override device identifier
| * 95bac1c8be vmci: prevent speculation leaks by sanitizing event in event_deliver()
| * 5eabdf17fe sock_map: avoid race between sock_map_close and sk_psock_put
| * ae080302bf null_blk: Print correct max open zones limit in null_init_zoned_dev()
| * e2585bc1d8 tracing/selftests: Fix kprobe event name test for .isra. functions
| * 6625417dfe riscv: fix overlap of allocated page and PTR_ERR
| * c81705d66f perf/core: Fix missing wakeup when waiting for context reference
| * 355784a5c0 x86/amd_nb: Check for invalid SMN reads
| * 2458f2362f irqchip/gic-v3-its: Fix potential race condition in its_vlpi_prop_update()
| * 9dc3200a5c mptcp: pm: inc RmAddr MIB counter once per RM_ADDR ID
| * f03c46eabb mptcp: ensure snd_una is properly initialized on connect
| * c3ca24dfe9 drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found
| * dcba6bedb4 drm/exynos/vidi: fix memory leak in .get_modes()
| * 08891eeaa9 drivers: core: synchronize really_probe() and dev_uevent()
| * cc09e1d351 iio: imu: inv_icm42600: delete unneeded update watermark call
| * 1b82cc8664 iio: dac: ad5592r: fix temperature channel scaling value
| * f35eb2c486 iio: adc: ad9467: fix scan type sign
| * b9da7e9653 x86/boot: Don't add the EFI stub to targets, again
| * 34ae447b13 misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe()
| * cde177fa23 bnxt_en: Adjust logging of firmware messages in case of released token in __hwrm_send()
| * e9c6513cff af_unix: Read with MSG_PEEK loops if the first unread byte is OOB
| * 60cd714871 ionic: fix use after netif_napi_del()
| * caaa212978 net: bridge: mst: fix suspicious rcu usage in br_mst_set_state
| * 09f4337c27 net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state
| * cd68f84910 net/ipv6: Fix the RT cache flush via sysctl using a previous delay
| * 5872043bcf nvmet-passthru: propagate status from id override functions
| * a6ea39fd2d net: stmmac: replace priv->speed with the portTransmitRate from the tc-cbs parameters
| * c495ebe90b gve: ignore nonrelevant GSO type bits when processing TSO headers
| * 950217d97c net: pse-pd: Use EOPNOTSUPP error code instead of ENOTSUPP
| * 390b353d1a netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type
| * 4431d37498 Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
| * 0f99dc35cb net/mlx5e: Fix features validation check for tunneled UDP (non-VXLAN) packets
| * 11f1f0c4f7 geneve: Fix incorrect inner network header offset when innerprotoinherit is set
| * 0b160b127c tcp: fix race in tcp_v6_syn_recv_sock()
| * c8879a39c7 drm/bridge/panel: Fix runtime warning on panel bridge release
| * 3b1cf943b0 drm/komeda: check for error-valued pointer
| * f1ab15a094 liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
| * f2583f8172 net: hns3: add cond_resched() to hns3 ring buffer init process
| * 6d0007f7b6 net: hns3: fix kernel crash problem in concurrent scenario
| * 84a0d86853 net: sfp: Always call `sfp_sm_mod_remove()` on remove
| * 2b7be0eb79 drm/vmwgfx: Remove STDU logic from generic mode_valid function
| * b1aae9c5d7 drm/vmwgfx: 3D disabled should not effect STDU memory limits
| * b7479b39b7 drm/vmwgfx: Filter modes which exceed graphics memory
| * 862bd36daf drm/vmwgfx: Refactor drm connector probing for display modes
| * 67adcfae2e drm/vmwgfx: Port the framebuffer code to drm fb helpers
| * 789c99a1d7 HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode()
| * f2af9dbad8 iommu/amd: Fix sysfs leak in iommu init
| * bfd546fc7f HID: core: remove unnecessary WARN_ON() in implement()
| * 2df8c16ea4 gpio: tqmx86: fix broken IRQ_TYPE_EDGE_BOTH interrupt type
| * 4ada932c43 gpio: tqmx86: store IRQ trigger type and unmask status separately
| * 0f6b55f9f7 gpio: tqmx86: Convert to immutable irq_chip
| * 8c2e28a209 gpio: tqmx86: introduce shadow register for GPIO output value
| * a09c3dbe59 gpio: tqmx86: remove unneeded call to platform_set_drvdata()
| * 8200440578 gpio: tqmx86: fix typo in Kconfig label
| * 3150d4e4b9 platform/x86: dell-smbios: Fix wrong token data in sysfs
| * 0abb51acfb NFS: add barriers when testing for NFS_FSDATA_BLOCKED
| * 3cde566d9f SUNRPC: return proper error from gss_wrap_req_priv
| * e6ddef11c0 NFSv4.1 enforce rootpath check in fs_location query
| * 81fce119df clk: sifive: Do not register clkdevs for PRCI clocks
| * fcb4ce61a5 selftests/ftrace: Fix to check required event file
| * 320ba9cbca cachefiles: flush all requests after setting CACHEFILES_DEAD
| * eac51d9daa cachefiles: defer exposing anon_fd until after copy_to_user() succeeds
| * 1fd5f317b5 cachefiles: never get a new anonymous fd if ondemand_id is valid
| * bb00aef6d9 cachefiles: remove err_put_fd label in cachefiles_ondemand_daemon_read()
| * cb55625f8e cachefiles: fix slab-use-after-free in cachefiles_ondemand_daemon_read()
| * 99e9c5bd27 cachefiles: fix slab-use-after-free in cachefiles_ondemand_get_fd()
| * a0cc87f866 cachefiles: add restore command to recover inflight ondemand read requests
| * 5344f2ab31 cachefiles: add spin_lock for cachefiles_ondemand_info
| * f17443d52d cachefiles: resend an open request if the read request's object is closed
| * bb512c8587 cachefiles: extract ondemand info field from cachefiles_object
| * e43fb9a20d cachefiles: introduce object ondemand state
| * 9f13aacdd4 cachefiles: remove requests from xarray during flushing requests
| * dad925266a cachefiles: add output string to cachefiles_obj_[get|put]_ondemand_fd
| * bee55952ff cxl/test: Add missing vmalloc.h for tools/testing/cxl/test/mem.c
| * 6dfa1d80ea Input: try trimming too long modalias strings
| * ce1afd733b powerpc/uaccess: Fix build errors seen with GCC 13/14
| * d221284991 gve: Clear napi->skb before dev_kfree_skb_any()
| * d19254d891 scsi: sd: Use READ(16) when reading block zero on large capacity disks
| * 46bab2bcd7 scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
| * a9624afc91 scsi: mpi3mr: Fix ATA NCQ priority support
| * a136698d1e thunderbolt: debugfs: Fix margin debugfs node creation condition
| * 0daacb57b9 xhci: Apply broken streams quirk to Etron EJ188 xHCI host
| * 633f72cb61 xhci: Handle TD clearing for multiple streams case
| * 0a1c2a581d xhci: Apply reset resume quirk to Etron EJ188 xHCI host
| * f6559d28c0 xhci: Set correct transferred length for cancelled bulk transfers
| * 33aecc5799 jfs: xattr: fix buffer overflow for invalid xattr
| * b6e5e69643 landlock: Fix d_parent walk
| * 03f916e56a tty: n_tty: Fix buffer offsets when lookahead is used
| * 185a1b1fcc mei: me: release irq in mei_me_pci_resume error path
| * 2ad7e02c2e usb: typec: tcpm: Ignore received Hard Reset in TOGGLING state
| * 4053696594 usb: typec: tcpm: fix use-after-free case in tcpm_register_source_caps
| * fb9f366ae6 USB: xen-hcd: Traverse host/ when CONFIG_USB_XEN_HCD is selected
| * 02a4c0499f USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
| * c2844d5e58 io_uring: check for non-NULL file pointer in io_file_can_poll()
| * 129dcd3e7d nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
| * ea2ac9238d nilfs2: return the mapped address from nilfs_get_page()
| * 8b0d6d1879 btrfs: fix leak of qgroup extent records after transaction abort
| * b1a5d3f79b btrfs: make btrfs_destroy_delayed_refs() return void
| * 95e69b16d0 btrfs: remove unnecessary prototype declarations at disk-io.c
| * be70a6c516 wifi: ath10k: fix QCOM_RPROC_COMMON dependency
| * 46a072e050 selftests/mm: compaction_test: fix bogus test success on Aarch64
| * 264b8a7e15 selftests/mm: log a consistent test name for check_compaction
| * 5ba39134b6 selftests/mm: conform test to TAP format output
| * 499fd1db08 selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages
| * 198a80833e mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL
| * fe5c2bdcb1 mm, vmalloc: fix high order __GFP_NOFAIL allocations
| * b1574c8c0a i2c: acpi: Unbind mux adapters before delete
| * ef1e9b624d i2c: add fwnode APIs
| * c0cd2d8800 HID: i2c-hid: elan: fix reset suspend current leakage
| * 274ecd4001 HID: i2c-hid: elan: Add ili9882t timing
| * 0fce1c959a firmware: qcom_scm: disable clocks if qcom_scm_bw_enable() fails
| * 5ee241f72e mmc: davinci: Don't strip remove function when driver is builtin
| * c3d39fdc33 serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler
| * aeb2b22e4f serial: sc16is7xx: replace hardcoded divisor value with BIT() macro
| * c0b8f49183 misc/pvpanic-pci: register attributes via pci_driver
| * 96826e74d7 misc/pvpanic: deduplicate common code
| * 1529c86da6 arm64: dts: qcom: sa8155p-adp: fix SDHC2 CD pin configuration
| * eedbb969a4 arm64: dts: qcom: sm8150: align TLMM pin configuration with DT schema
| * a869a9b604 drm/amd/display: Fix incorrect DSC instance for MST
| * ed82dc58c7 drm/amd/display: drop unnecessary NULL checks in debugfs
| * b6621895b4 xtensa: fix MAKE_PC_FROM_RA second argument
| * eccf114abd xtensa: stacktrace: include <asm/ftrace.h> for prototype
| * 5253a35ea5 iio: accel: mxc4005: Reset chip on probe() and resume()
| * 02db59533b iio: accel: mxc4005: allow module autoloading via OF compatible
| * a0fdccb1c9 usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete
| * b55bc52521 usb: gadget: f_fs: use io_data->status consistently
| * e8b8582355 btrfs: fix wrong block_start calculation for btrfs_drop_extent_map_range()
| * b45cfd9bde Bluetooth: qca: fix invalid device address check
| * 2498960dac ipv6: fix possible race in __fib6_drop_pcpu_from()
| * 6b9ff1620d af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill().
| * 4a967bac16 af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().
| * e3f2599e9a af_unix: Use skb_queue_empty_lockless() in unix_release_sock().
| * 4c64c3e2f5 af_unix: annotate lockless accesses to sk->sk_err
| * f5c4276607 af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().
| * 8b29fcd7f3 af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen.
| * 19425cfe59 af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG.
| * fda68a7da8 af_unix: Annotate data-race of sk->sk_state in unix_stream_read_skb().
| * f53cf0449e af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg().
| * 018fc5d9db af_unix: Annotate data-race of sk->sk_state in unix_stream_connect().
| * 35bdc364e1 af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll().
| * a8814322e5 af_unix: Annotate data-race of sk->sk_state in unix_inq_len().
| * a59dc9cb03 af_unix: Annodate data-races around sk->sk_state for writers.
| * ca32605565 af_unix: Set sk->sk_state under unix_state_lock() for truly disconencted peer.
| * fe394d59cd net: wwan: iosm: Fix tainted pointer delete is case of region creation fail
| * a62c50545b ice: remove af_xdp_zc_qps bitmap
| * 447a5433bd ice: remove null checks before devm_kfree() calls
| * a388961be5 ice: Introduce new parameters in ice_sched_node
| * 17ccdebe5a ice: fix iteration of TLVs in Preserved Fields Area
| * 952557eb6e ptp: Fix error message on failed pin verification
| * 0bf6cc9661 net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
| * 531eab2da2 net/mlx5: Fix tainted pointer delete is case of flow rules creation fail
| * e7d4485d47 net/mlx5: Always stop health timer during driver removal
| * 0819acb87b net/mlx5: Split function_setup() to enable and open functions
| * 0c42eef3f0 net/mlx5: Stop waiting for PCI if pci channel is offline
| * e4df7b53a4 net/mlx5: Stop waiting for PCI up if teardown was triggered
| * a2ab7dae67 tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB
| * a31d0e5deb vxlan: Fix regression when dropping packets due to invalid src addresses
| * 0f208fad86 net: sched: sch_multiq: fix possible OOB write in multiq_tune()
| * 1a0c20c056 net/smc: avoid overwriting when adjusting sock bufsizes
| * 87ef68f3af octeontx2-af: Always allocate PF entries from low prioriy zone
| * 3708b6c254 bpf: Set run context for rawtp test_run callback
| * a170d5a40f ipv6: sr: block BH in seg6_output_core() and seg6_input_core()
| * 9b3d1ba4a4 ipv6: ioam: block BH from ioam6_output()
| * 9bcdfdc6a6 net/ncsi: Fix the multi thread manner of NCSI driver
| * f2cd7e1b48 net/ncsi: Simplify Kconfig/dts control flow
| * e6ad2311e0 ax25: Replace kfree() in ax25_dev_free() with ax25_dev_put()
| * f4df9d6c8d ax25: Fix refcount imbalance on inbound connections
| * bd403f3989 wifi: mac80211: correctly parse Spatial Reuse Parameter Set element
| * a8bc8276af wifi: iwlwifi: mvm: don't read past the mfuart notifcation
| * 9e719ae3ab wifi: iwlwifi: mvm: check n_ssids before accessing the ssids
| * ca4c230788 wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of debugfs ifdef
| * 8014a7dbbf wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
| * a5c20830fb wifi: cfg80211: pmsr: use correct nla_get_uX functions
| * 6d540b0317 wifi: cfg80211: Lock wiphy in cfg80211_get_station
| * 96c950d6b0 wifi: cfg80211: fully move wiphy work to unbound workqueue
| * 9c49b58b9a wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
| * 617dadbfb2 wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
* | c6bbb760e9 ANDROID: ABI fixup for abi break in struct dst_ops
* | 079775fd35 Merge 6.1.94 into android14-6.1-lts
|/
* eb44d83053 Linux 6.1.94
* 6d6fe13cca smp: Provide 'setup_max_cpus' definition on UP too
* b09b556e48 smb: client: fix deadlock in smb2_find_smb_tcon()
* 3174d8b7c9 powerpc/bpf: enforce full ordering for ATOMIC operations with BPF_FETCH
* 1ff2bd566f btrfs: fix crash on racing fsync and size-extending write into prealloc
* e601937b5b NFS: Fix READ_PLUS when server doesn't support OP_READ_PLUS
* a54419e60e nfs: fix undefined behavior in nfs_block_bits()
* 728b663f5e EDAC/igen6: Convert PCIBIOS_* return codes to errnos
* 4e060b308d i3c: master: svc: fix invalidate IBI type and miss call client IBI handler
* 07c8050f8c s390/cpacf: Make use of invalid opcode produce a link error
* 1d39dcff47 s390/cpacf: Split and rework cpacf query functions
* 8c5f5911c1 s390/ap: Fix crash in AP internal function modify_bitmap()
* ff19ea00a5 parisc: Define sigset_t in parisc uapi header
* bca17801fb parisc: Define HAVE_ARCH_HUGETLB_UNMAPPED_AREA
* e941b712e7 ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()
* 16a392f66a ext4: set type of ac_groups_linear_remaining to __u32 to avoid overflow
* d47445b041 sparc: move struct termio to asm/termios.h
* 81dd3c82a4 net: fix __dst_negative_advice() race
* 10938be35e kdb: Use format-specifiers rather than memset() for padding in kdb_read()
* 60e2a14a81 kdb: Merge identical case statements in kdb_read()
* 0ec478e7a1 kdb: Fix console handling when editing and tab-completing commands
* b4e6a259f8 kdb: Use format-strings rather than '\0' injection in kdb_read()
* 33d9c81465 kdb: Fix buffer overflow during tab-complete
* 6da1ffc4bc watchdog: rti_wdt: Set min_hw_heartbeat_ms to accommodate a safety margin
* c7071d3052 mm/hugetlb: pass correct order_per_bit to cma_declare_contiguous_nid
* 04b4278245 mm/cma: drop incorrect alignment check in cma_init_reserved_mem
* 14a339e7d7 sparc64: Fix number of online CPUs
* 3ec82c9a15 intel_th: pci: Add Meteor Lake-S CPU support
* 82590ce3a0 cpufreq: amd-pstate: Fix the inconsistency in max frequency units
* 9ff078f5ba kmsan: do not wipe out origin when doing partial unpoisoning
* ca71f20471 net/9p: fix uninit-value in p9_client_rpc()
* 6684086359 net/ipv6: Fix route deleting failure when metric equals 0
* 65bb86fbc8 scsi: core: Handle devices which return an unusually large VPD page count
* 7a2bc8b34e mm: fix race between __split_huge_pmd_locked() and GUP-fast
* e7428e7e3f crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak
* dd999fdeee crypto: ecrdsa - Fix module auto-load on add_key
* 458458c130 crypto: ecdsa - Fix module auto-load on add-key
* e0032f5c08 KVM: arm64: AArch32: Fix spurious trapping of conditional instructions
* 5b12ce0b6f KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
* 4f902f03ef KVM: arm64: Fix AArch32 register narrowing on userspace write
* 7da44257e6 drm/amd: Fix shutdown (again) on some SMU v13.0.4/11 platforms
* cb299cdba0 9p: add missing locking around taking dentry fid list
* 97820893f2 drm/amdgpu/atomfirmware: add intergrated info v2.3 table
* edaa57480b fbdev: savage: Handle err return when savagefb_check_var failed
* 1a156761fc mmc: sdhci-acpi: Add quirk to enable pull-up on the card-detect GPIO on Asus T100TA
* 4ac34dc6b4 mmc: sdhci-acpi: Disable write protect detection on Toshiba WT10-A
* 21109f137a mmc: sdhci-acpi: Fix Lenovo Yoga Tablet 2 Pro 1380 sdcard slot not working
* c2107d3024 mmc: sdhci-acpi: Sort DMI quirks alphabetically
* 32b76505ba mmc: sdhci: Add support for "Tuning Error" interrupts
* 36a28616d4 mmc: core: Add mmc_gpiod_set_cd_config() function
* 7170d0c0da media: v4l2-core: hold videodev_lock until dev reg, finishes
* 5d931a2694 media: mxl5xx: Move xpt structures off stack
* 9ef7ee4cb6 media: mc: mark the media devnode as registered from the, start
* 788fd0f11e media: mc: Fix graph walk in media_pipeline_start
* 9d180538de arm64: dts: hi3798cv200: fix the size of GICR
* 46fe2af45c wifi: rtlwifi: rtl8192de: Fix endianness issue in RX path
* 6973383af5 wifi: rtlwifi: rtl8192de: Fix low speed with WPA3-SAE
* 83daddb601 wifi: rtlwifi: rtl8192de: Fix 5 GHz TX power
* 2c13c9f6ca wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
* c365394a41 wifi: rtw89: pci: correct TX resource checking for PCI DMA channel of firmware command
* 3f8d5e802d md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING
* 3f09972198 arm64: dts: qcom: qcs404: fix bluetooth device address
* 2eea8b448e arm64: tegra: Correct Tegra132 I2C alias
* ef2f4d60c3 ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
* 3988a2850b soc: qcom: rpmh-rsc: Enhance check for VRM in-flight request
* 560d69c975 thermal/drivers/qcom/lmh: Check for SCM availability at probe
* 5e0d41aa53 ata: pata_legacy: make legacy_exit() work again
* 336b8b2e90 wifi: rtw89: correct aSIFSTime for 6GHz band
* 934e1e4331 bcache: fix variable length array abuse in btree_iter
* 011552f29f drm/amdgpu: add error handle to avoid out-of-bounds
* d082757b83 media: lgdt3306a: Add a check against null-pointer-def
* 8c8aa473fe f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode()
* 376fad5e52 scripts/gdb: fix SB_* constants parsing
* 6bbd9c021c vxlan: Fix regression when dropping packets due to invalid src addresses
* 7a898d5ed4 mptcp: fix full TCP keep-alive support
* dc62d53f01 mptcp: cleanup SOL_TCP handling
* e7d48faa15 mptcp: avoid some duplicate code in socket option handling
* 164320fc22 drm/i915/audio: Fix audio time stamp programming for DP
* 86a30d6302 nilfs2: fix use-after-free of timer for log writer thread
* 79fc40a29d riscv: signal: handle syscall restart before get_signal
* bc20a0a290 afs: Don't cross .backup mountpoint from backup volume
* 265426254d mmc: core: Do not force a retune before RPMB switch
* 883e5d542b maple_tree: fix mas_empty_area_rev() null pointer dereference
* 34f3005303 maple_tree: fix allocation in mas_sparse_area()
* cf0df43520 Bluetooth: btrtl: Add missing MODULE_FIRMWARE declarations
* a17e06d709 drm: Check polling initialized before enabling in drm_helper_probe_single_connector_modes
* 4ad8d57d90 drm: Check output polling initialized before disabling

Change-Id: I849966e53c4a46d2ee81b3b6078f953a08502872
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
2024-09-23 14:23:12 +00:00
Dmitry Skiba
3b95e54867 ANDROID: Update the ABI symbol list
Adding the following symbols:
  - __traceiter_android_rvh_try_to_wake_up_success
  - __traceiter_android_vh_mm_kcompactd_cpu_online
  - __traceiter_android_vh_vmscan_kswapd_done
  - __traceiter_mm_vmscan_kswapd_wake
  - __tracepoint_android_rvh_try_to_wake_up_success
  - __tracepoint_android_vh_mm_kcompactd_cpu_online
  - __tracepoint_android_vh_vmscan_kswapd_done
  - __tracepoint_mm_vmscan_kswapd_wake

Bug: 367400751
Change-Id: I658b4961666d93238feaa8f166012b76a69994eb
Signed-off-by: Dmitry Skiba <dskiba@google.com>
2024-09-20 17:12:39 +00:00
Dmitry Skiba
b3a2458fc6 ANDROID: mm: add vh for kcompactd_cpu_online()
kcompactd_cpu_online() changes kcompactd cpumask, potentially
overwriting any vendor-specific cpumask that was there. This
hook allows vendors to re-set the cpumask.

Bug: 367400751
Change-Id: I45b92bcd16fbf2d5d76474287db659e32af64201
Signed-off-by: Dmitry Skiba <dskiba@google.com>
2024-09-20 16:55:50 +00:00
jiangxinpei
532fad0092 ANDROID: ABI: update symbol list for honor
1 function symbol(s) added
  'int __traceiter_android_vh_should_fault_around(void*, struct vm_fault*, bool*)'

Bug: 362663044
Change-Id: Ie7634bc746e40142455c7bd22d876d519a02e0d5
Signed-off-by: jiangxinpei <jiangxinpei@honor.corp-partner.google.com>
2024-09-20 09:37:56 +00:00
Dezhi Huang
145b08312d ANDROID: vendor_hooks: add hook to perform targeted memory management
Add vendor_hook trace_android_vh_should_fault_around, allow vendor modules
to skip the fault_around processing for less important processes.

Bug: 362663044
Bug: 337547131
Change-Id: I792dca2038f5ad7cba1d212ef95407244958609d
Signed-off-by: Dezhi Huang <huangdezhi@hihonor.com>
(cherry picked from commit 65ebb00fe7977348d5fcfa58985c29181f3ec173)
2024-09-20 09:37:56 +00:00
jiangxinpei
c105083ac6 ANDROID: ABI: update symbol list for honor
3 function symbol(s) added
  'int __traceiter_android_vh_do_read_fault(void*, struct vm_fault*, unsigned long)'
  'int __traceiter_android_vh_filemap_map_pages(void*, struct file*, unsigned long, unsigned long, vm_fault_t)'
  'int __traceiter_android_vh_filemap_read(void*, struct file*, loff_t, size_t)'

Bug: 362665923
Change-Id: I49fa40c65d7d24799c815de0c2c02c12d09e8fd8
Signed-off-by: jiangxinpei <jiangxinpei@honor.corp-partner.google.com>
2024-09-20 09:21:56 +00:00
Sooyong Suk
eda4e9fa64 ANDROID: mm: add vendor hook in fault and read file
Add a vendor hook to notify vendor module fault and read events.

Bug: 362665923
Bug: 351175506
Change-Id: I4c46e9e00aa5f5555fd42a6b0815563497658b34
Signed-off-by: Sooyong Suk <s.suk@samsung.corp-partner.google.com>
(cherry picked from commit a9867d872e24fbe658e05f32b770e4b36c6e3773)
2024-09-20 09:21:56 +00:00
David Chiang
814dd5bfa8 ANDROID: Update the ABI symbol list
Adding the following symbols to abi_gki_aarch64_pixel:
- mbox_request_channel_byname

Bug: 368167673
Change-Id: I031522377372a25bf5f9e97eb4832173463de390
Signed-off-by: David Chiang <davidchiang@google.com>
2024-09-19 06:07:31 +00:00
Greg Kroah-Hartman
e526b12bf9 Linux 6.1.111
Link: https://lore.kernel.org/r/20240916114221.021192667@linuxfoundation.org
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Tested-by: Yann Sionneau<ysionneau@kalrayinc.com>
Tested-by: Mark Brown <broonie@kernel.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Tested-by: Pavel Machek (CIP) <pavel@denx.de>
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
Tested-by: Ron Economos <re@w6rz.net>
Tested-by: Salvatore Bonaccorso <carnil@debian.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Arseniy Krasnov
e1a199ec31 ASoC: meson: axg-card: fix 'use-after-free'
commit 4f9a71435953f941969a4f017e2357db62d85a86 upstream.

Buffer 'card->dai_link' is reallocated in 'meson_card_reallocate_links()',
so move 'pad' pointer initialization after this function when memory is
already reallocated.

Kasan bug report:

==================================================================
BUG: KASAN: slab-use-after-free in axg_card_add_link+0x76c/0x9bc
Read of size 8 at addr ffff000000e8b260 by task modprobe/356

CPU: 0 PID: 356 Comm: modprobe Tainted: G O 6.9.12-sdkernel #1
Call trace:
 dump_backtrace+0x94/0xec
 show_stack+0x18/0x24
 dump_stack_lvl+0x78/0x90
 print_report+0xfc/0x5c0
 kasan_report+0xb8/0xfc
 __asan_load8+0x9c/0xb8
 axg_card_add_link+0x76c/0x9bc [snd_soc_meson_axg_sound_card]
 meson_card_probe+0x344/0x3b8 [snd_soc_meson_card_utils]
 platform_probe+0x8c/0xf4
 really_probe+0x110/0x39c
 __driver_probe_device+0xb8/0x18c
 driver_probe_device+0x108/0x1d8
 __driver_attach+0xd0/0x25c
 bus_for_each_dev+0xe0/0x154
 driver_attach+0x34/0x44
 bus_add_driver+0x134/0x294
 driver_register+0xa8/0x1e8
 __platform_driver_register+0x44/0x54
 axg_card_pdrv_init+0x20/0x1000 [snd_soc_meson_axg_sound_card]
 do_one_initcall+0xdc/0x25c
 do_init_module+0x10c/0x334
 load_module+0x24c4/0x26cc
 init_module_from_file+0xd4/0x128
 __arm64_sys_finit_module+0x1f4/0x41c
 invoke_syscall+0x60/0x188
 el0_svc_common.constprop.0+0x78/0x13c
 do_el0_svc+0x30/0x40
 el0_svc+0x38/0x78
 el0t_64_sync_handler+0x100/0x12c
 el0t_64_sync+0x190/0x194

Fixes: 7864a79f37 ("ASoC: meson: add axg sound card support")
Cc: Stable@vger.kernel.org
Signed-off-by: Arseniy Krasnov <avkrasnov@salutedevices.com>
Reviewed-by: Jerome Brunet <jbrunet@baylibre.com>
Link: https://patch.msgid.link/20240911142425.598631-1-avkrasnov@salutedevices.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Mika Westerberg
3d792c6a85 pinctrl: meteorlake: Add Arrow Lake-H/U ACPI ID
commit a366e46da10d7bfa1a52c3bd31f342a3d0e8e7fe upstream.

Intel Arrow Lake-H/U has the same GPIO hardware than Meteor Lake-P but
the ACPI ID is different. Add this new ACPI ID to the list of supported
devices.

Cc: stable@vger.kernel.org
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Nikita Zhandarovich
57da7d15e5 drm/i915/guc: prevent a possible int overflow in wq offsets
[ Upstream commit d3d37f74683e2f16f2635ee265884f7ca69350ae ]

It may be possible for the sum of the values derived from
i915_ggtt_offset() and __get_parent_scratch_offset()/
i915_ggtt_offset() to go over the u32 limit before being assigned
to wq offsets of u64 type.

Mitigate these issues by expanding one of the right operands
to u64 to avoid any overflow issues just in case.

Found by Linux Verification Center (linuxtesting.org) with static
analysis tool SVACE.

Fixes: c2aa552ff0 ("drm/i915/guc: Add multi-lrc context registration")
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: John Harrison <John.C.Harrison@Intel.com>
Signed-off-by: Nikita Zhandarovich <n.zhandarovich@fintech.ru>
Link: https://patchwork.freedesktop.org/patch/msgid/20240725155925.14707-1-n.zhandarovich@fintech.ru
Reviewed-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
(cherry picked from commit 1f1c1bd56620b80ae407c5790743e17caad69cec)
Signed-off-by: Tvrtko Ursulin <tursulin@ursulin.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Jinjie Ruan
29aa222920 spi: geni-qcom: Fix incorrect free_irq() sequence
[ Upstream commit b787a33864121a565aeb0e88561bf6062a19f99c ]

In spi_geni_remove(), the free_irq() sequence is different from that
on the probe error path. And the IRQ will still remain and it's interrupt
handler may use the dma channel after release dma channel and before free
irq, which is not secure, fix it.

Fixes: b59c122484 ("spi: spi-geni-qcom: Add support for GPI dma")
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Link: https://patch.msgid.link/20240909073141.951494-3-ruanjinjie@huawei.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Jinjie Ruan
d66fbca6c1 spi: geni-qcom: Undo runtime PM changes at driver exit time
[ Upstream commit 89e362c883c65ff94b76b9862285f63545fb5274 ]

It's important to undo pm_runtime_use_autosuspend() with
pm_runtime_dont_use_autosuspend() at driver exit time unless driver
initially enabled pm_runtime with devm_pm_runtime_enable()
(which handles it for you).

Hence, switch to devm_pm_runtime_enable() to fix it, so the
pm_runtime_disable() in probe error path and remove function
can be removed.

Fixes: cfdab2cd85 ("spi: spi-geni-qcom: Set an autosuspend delay of 250 ms")
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Suggested-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Link: https://patch.msgid.link/20240909073141.951494-2-ruanjinjie@huawei.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Uwe Kleine-König
433ece380b spi: geni-qcom: Convert to platform remove callback returning void
[ Upstream commit d0b52f6539 ]

The .remove() callback for a platform driver returns an int which makes
many driver authors wrongly assume it's possible to do error handling by
returning an error code. However the value returned is (mostly) ignored
and this typically results in resource leaks. To improve here there is a
quest to make the remove callback return void. In the first step of this
quest all drivers are converted to .remove_new() which already returns
void.

Trivially convert this driver from always returning zero in the remove
callback to the void returning variant.

Signed-off-by: Uwe Kleine-König <u.kleine-koenig@pengutronix.de>
Link: https://lore.kernel.org/r/20230303172041.2103336-30-u.kleine-koenig@pengutronix.de
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 89e362c883c6 ("spi: geni-qcom: Undo runtime PM changes at driver exit time")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Alex Deucher
bd1f7cc3be drm/amdgpu/atomfirmware: Silence UBSAN warning
commit 17ea4383649fdeaff3181ddcf1ff03350d42e591 upstream.

Per the comments, these are variable sized arrays.

Closes: https://gitlab.freedesktop.org/drm/amd/-/issues/3613
Reviewed-by: Harry Wentland <harry.wentland@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 81f7804ba84ee617ed594de934ed87bcc4f83531)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
T.J. Mercier
84175dc5b2 dma-buf: heaps: Fix off-by-one in CMA heap fault handler
commit ea5ff5d351b520524019f7ff7f9ce418de2dad87 upstream.

Until VM_DONTEXPAND was added in commit 1c1914d6e8c6 ("dma-buf: heaps:
Don't track CMA dma-buf pages under RssFile") it was possible to obtain
a mapping larger than the buffer size via mremap and bypass the overflow
check in dma_buf_mmap_internal. When using such a mapping to attempt to
fault past the end of the buffer, the CMA heap fault handler also checks
the fault offset against the buffer size, but gets the boundary wrong by
1. Fix the boundary check so that we don't read off the end of the pages
array and insert an arbitrary page in the mapping.

Reported-by: Xingyu Jin <xingyuj@google.com>
Fixes: a5d2d29e24 ("dma-buf: heaps: Move heap-helper logic into the cma_heap implementation")
Cc: stable@vger.kernel.org # Applicable >= 5.10. Needs adjustments only for 5.10.
Signed-off-by: T.J. Mercier <tjmercier@google.com>
Acked-by: John Stultz <jstultz@google.com>
Signed-off-by: Sumit Semwal <sumit.semwal@linaro.org>
Link: https://patchwork.freedesktop.org/patch/msgid/20240830192627.2546033-1-tjmercier@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Krzysztof Kozlowski
94c705fb4d soundwire: stream: Revert "soundwire: stream: fix programming slave ports for non-continous port maps"
commit 233a95fd574fde1c375c486540a90304a2d2d49f upstream.

This reverts commit ab8d66d132bc8f1992d3eb6cab8d32dda6733c84 because it
breaks codecs using non-continuous masks in source and sink ports.  The
commit missed the point that port numbers are not used as indices for
iterating over prop.sink_ports or prop.source_ports.

Soundwire core and existing codecs expect that the array passed as
prop.sink_ports and prop.source_ports is continuous.  The port mask still
might be non-continuous, but that's unrelated.

Reported-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Closes: https://lore.kernel.org/all/b6c75eee-761d-44c8-8413-2a5b34ee2f98@linux.intel.com/
Fixes: ab8d66d132bc ("soundwire: stream: fix programming slave ports for non-continous port maps")
Acked-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Cc: stable@vger.kernel.org
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Tested-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://lore.kernel.org/r/20240909164746.136629-1-krzysztof.kozlowski@linaro.org
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Han Xu
09af8b0ba7 spi: nxp-fspi: fix the KASAN report out-of-bounds bug
commit 2a8787c1cdc7be24fdd8953ecd1a8743a1006235 upstream.

Change the memcpy length to fix the out-of-bounds issue when writing the
data that is not 4 byte aligned to TX FIFO.

To reproduce the issue, write 3 bytes data to NOR chip.

dd if=3b of=/dev/mtd0
[   36.926103] ==================================================================
[   36.933409] BUG: KASAN: slab-out-of-bounds in nxp_fspi_exec_op+0x26ec/0x2838
[   36.940514] Read of size 4 at addr ffff00081037c2a0 by task dd/455
[   36.946721]
[   36.948235] CPU: 3 UID: 0 PID: 455 Comm: dd Not tainted 6.11.0-rc5-gc7b0e37c8434 #1070
[   36.956185] Hardware name: Freescale i.MX8QM MEK (DT)
[   36.961260] Call trace:
[   36.963723]  dump_backtrace+0x90/0xe8
[   36.967414]  show_stack+0x18/0x24
[   36.970749]  dump_stack_lvl+0x78/0x90
[   36.974451]  print_report+0x114/0x5cc
[   36.978151]  kasan_report+0xa4/0xf0
[   36.981670]  __asan_report_load_n_noabort+0x1c/0x28
[   36.986587]  nxp_fspi_exec_op+0x26ec/0x2838
[   36.990800]  spi_mem_exec_op+0x8ec/0xd30
[   36.994762]  spi_mem_no_dirmap_read+0x190/0x1e0
[   36.999323]  spi_mem_dirmap_write+0x238/0x32c
[   37.003710]  spi_nor_write_data+0x220/0x374
[   37.007932]  spi_nor_write+0x110/0x2e8
[   37.011711]  mtd_write_oob_std+0x154/0x1f0
[   37.015838]  mtd_write_oob+0x104/0x1d0
[   37.019617]  mtd_write+0xb8/0x12c
[   37.022953]  mtdchar_write+0x224/0x47c
[   37.026732]  vfs_write+0x1e4/0x8c8
[   37.030163]  ksys_write+0xec/0x1d0
[   37.033586]  __arm64_sys_write+0x6c/0x9c
[   37.037539]  invoke_syscall+0x6c/0x258
[   37.041327]  el0_svc_common.constprop.0+0x160/0x22c
[   37.046244]  do_el0_svc+0x44/0x5c
[   37.049589]  el0_svc+0x38/0x78
[   37.052681]  el0t_64_sync_handler+0x13c/0x158
[   37.057077]  el0t_64_sync+0x190/0x194
[   37.060775]
[   37.062274] Allocated by task 455:
[   37.065701]  kasan_save_stack+0x2c/0x54
[   37.069570]  kasan_save_track+0x20/0x3c
[   37.073438]  kasan_save_alloc_info+0x40/0x54
[   37.077736]  __kasan_kmalloc+0xa0/0xb8
[   37.081515]  __kmalloc_noprof+0x158/0x2f8
[   37.085563]  mtd_kmalloc_up_to+0x120/0x154
[   37.089690]  mtdchar_write+0x130/0x47c
[   37.093469]  vfs_write+0x1e4/0x8c8
[   37.096901]  ksys_write+0xec/0x1d0
[   37.100332]  __arm64_sys_write+0x6c/0x9c
[   37.104287]  invoke_syscall+0x6c/0x258
[   37.108064]  el0_svc_common.constprop.0+0x160/0x22c
[   37.112972]  do_el0_svc+0x44/0x5c
[   37.116319]  el0_svc+0x38/0x78
[   37.119401]  el0t_64_sync_handler+0x13c/0x158
[   37.123788]  el0t_64_sync+0x190/0x194
[   37.127474]
[   37.128977] The buggy address belongs to the object at ffff00081037c2a0
[   37.128977]  which belongs to the cache kmalloc-8 of size 8
[   37.141177] The buggy address is located 0 bytes inside of
[   37.141177]  allocated 3-byte region [ffff00081037c2a0, ffff00081037c2a3)
[   37.153465]
[   37.154971] The buggy address belongs to the physical page:
[   37.160559] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x89037c
[   37.168596] flags: 0xbfffe0000000000(node=0|zone=2|lastcpupid=0x1ffff)
[   37.175149] page_type: 0xfdffffff(slab)
[   37.179021] raw: 0bfffe0000000000 ffff000800002500 dead000000000122 0000000000000000
[   37.186788] raw: 0000000000000000 0000000080800080 00000001fdffffff 0000000000000000
[   37.194553] page dumped because: kasan: bad access detected
[   37.200144]
[   37.201647] Memory state around the buggy address:
[   37.206460]  ffff00081037c180: fa fc fc fc fa fc fc fc fa fc fc fc fa fc fc fc
[   37.213701]  ffff00081037c200: fa fc fc fc 05 fc fc fc 03 fc fc fc 02 fc fc fc
[   37.220946] >ffff00081037c280: 06 fc fc fc 03 fc fc fc fc fc fc fc fc fc fc fc
[   37.228186]                                ^
[   37.232473]  ffff00081037c300: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   37.239718]  ffff00081037c380: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc
[   37.246962] ==================================================================
[   37.254394] Disabling lock debugging due to kernel taint
0+1 records in
0+1 records out
3 bytes copied, 0.335911 s, 0.0 kB/s

Fixes: a5356aef6a ("spi: spi-mem: Add driver for NXP FlexSPI controller")
Cc: stable@kernel.org
Signed-off-by: Han Xu <han.xu@nxp.com>
Link: https://patch.msgid.link/20240911211146.3337068-1-han.xu@nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:06 +02:00
Sean Anderson
f43190e332 net: dpaa: Pad packets to ETH_ZLEN
[ Upstream commit cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0 ]

When sending packets under 60 bytes, up to three bytes of the buffer
following the data may be leaked. Avoid this by extending all packets to
ETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be
reproduced by running

	$ ping -s 11 destination

Fixes: 9ad1a37493 ("dpaa_eth: add support for DPAA Ethernet")
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Sean Anderson <sean.anderson@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20240910143144.1439910-1-sean.anderson@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Florian Westphal
33c2258bf8 netfilter: nft_socket: fix sk refcount leaks
[ Upstream commit 8b26ff7af8c32cb4148b3e147c52f9e4c695209c ]

We must put 'sk' reference before returning.

Fixes: 039b1f4f24 ("netfilter: nft_socket: fix erroneous socket assignment")
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:06 +02:00
Jacky Chou
bb8cb61543 net: ftgmac100: Enable TX interrupt to avoid TX timeout
[ Upstream commit fef2843bb49f414d1523ca007d088071dee0e055 ]

Currently, the driver only enables RX interrupt to handle RX
packets and TX resources. Sometimes there is not RX traffic,
so the TX resource needs to wait for RX interrupt to free.
This situation will toggle the TX timeout watchdog when the MAC
TX ring has no more resources to transmit packets.
Therefore, enable TX interrupt to release TX resources at any time.

When I am verifying iperf3 over UDP, the network hangs.
Like the log below.

root# iperf3 -c 192.168.100.100 -i1 -t10 -u -b0
Connecting to host 192.168.100.100, port 5201
[  4] local 192.168.100.101 port 35773 connected to 192.168.100.100 port 5201
[ ID] Interval           Transfer     Bandwidth       Total Datagrams
[  4]   0.00-20.42  sec   160 KBytes  64.2 Kbits/sec  20
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
[  4]  20.42-20.42  sec  0.00 Bytes  0.00 bits/sec  0
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval          Transfer    Bandwidth      Jitter   Lost/Total Datagrams
[  4]   0.00-20.42  sec  160 KBytes 64.2 Kbits/sec 0.000 ms 0/20 (0%)
[  4] Sent 20 datagrams
iperf3: error - the server has terminated

The network topology is FTGMAC connects directly to a PC.
UDP does not need to wait for ACK, unlike TCP.
Therefore, FTGMAC needs to enable TX interrupt to release TX resources instead
of waiting for the RX interrupt.

Fixes: 10cbd64076 ("ftgmac100: Rework NAPI & interrupts handling")
Signed-off-by: Jacky Chou <jacky_chou@aspeedtech.com>
Link: https://patch.msgid.link/20240906062831.2243399-1-jacky_chou@aspeedtech.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Naveen Mamindlapalli
8b220251e1 octeontx2-af: Modify SMQ flush sequence to drop packets
[ Upstream commit 019aba04f08c2102b35ce7fee9d4628d349f56c0 ]

The current implementation of SMQ flush sequence waits for the packets
in the TM pipeline to be transmitted out of the link. This sequence
doesn't succeed in HW when there is any issue with link such as lack of
link credits, link down or any other traffic that is fully occupying the
link bandwidth (QoS). This patch modifies the SMQ flush sequence to
drop the packets after TL1 level (SQM) instead of polling for the packets
to be sent out of RPM/CGX link.

Fixes: 5d9b976d44 ("octeontx2-af: Support fixed transmit scheduler topology")
Signed-off-by: Naveen Mamindlapalli <naveenm@marvell.com>
Reviewed-by: Sunil Kovvuri Goutham <sgoutham@marvell.com>
Link: https://patch.msgid.link/20240906045838.1620308-1-naveenm@marvell.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Naveen Mamindlapalli
22246e9757 octeontx2-af: Set XOFF on other child transmit schedulers during SMQ flush
[ Upstream commit e18aab0470 ]

When multiple transmit scheduler queues feed a TL1 transmit link, the
SMQ flush initiated on a low priority queue might get stuck when a high
priority queue fully subscribes the transmit link. This inturn effects
interface teardown. To avoid this, temporarily XOFF all TL1's other
immediate child transmit scheduler queues and also clear any rate limit
configuration on all the scheduler queues in SMQ(flush) hierarchy.

Signed-off-by: Naveen Mamindlapalli <naveenm@marvell.com>
Signed-off-by: Sunil Goutham <sgoutham@marvell.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Stable-dep-of: 019aba04f08c ("octeontx2-af: Modify SMQ flush sequence to drop packets")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Muhammad Usama Anjum
5d537b8d90 fou: fix initialization of grc
[ Upstream commit 4c8002277167125078e6b9b90137bdf443ebaa08 ]

The grc must be initialize first. There can be a condition where if
fou is NULL, goto out will be executed and grc would be used
uninitialized.

Fixes: 7e4196935069 ("fou: Fix null-ptr-deref in GRO.")
Signed-off-by: Muhammad Usama Anjum <usama.anjum@collabora.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20240906102839.202798-1-usama.anjum@collabora.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Benjamin Poirier
52c4beb79e net/mlx5: Fix bridge mode operations when there are no VFs
[ Upstream commit b1d305abef4640af1b4f1b4774d513cd81b10cfc ]

Currently, trying to set the bridge mode attribute when numvfs=0 leads to a
crash:

bridge link set dev eth2 hwmode vepa

[  168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
[  168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]
[...]
[  168.976037] Call Trace:
[  168.976188]  <TASK>
[  168.978620]  _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]
[  168.979074]  mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]
[  168.979471]  rtnl_bridge_setlink+0xe9/0x1f0
[  168.979714]  rtnetlink_rcv_msg+0x159/0x400
[  168.980451]  netlink_rcv_skb+0x54/0x100
[  168.980675]  netlink_unicast+0x241/0x360
[  168.980918]  netlink_sendmsg+0x1f6/0x430
[  168.981162]  ____sys_sendmsg+0x3bb/0x3f0
[  168.982155]  ___sys_sendmsg+0x88/0xd0
[  168.985036]  __sys_sendmsg+0x59/0xa0
[  168.985477]  do_syscall_64+0x79/0x150
[  168.987273]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  168.987773] RIP: 0033:0x7f8f7950f917

(esw->fdb_table.legacy.vepa_fdb is null)

The bridge mode is only relevant when there are multiple functions per
port. Therefore, prevent setting and getting this setting when there are no
VFs.

Note that after this change, there are no settings to change on the PF
interface using `bridge link` when there are no VFs, so the interface no
longer appears in the `bridge link` output.

Fixes: 4b89251de0 ("net/mlx5: Support ndo bridge_setlink and getlink")
Signed-off-by: Benjamin Poirier <bpoirier@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Carolina Jubran
c06402e3e4 net/mlx5: Verify support for scheduling element and TSAR type
[ Upstream commit 861cd9b9cb62feb244b8d77e68fd6ddedbbf66e9 ]

Before creating a scheduling element in a NIC or E-Switch scheduler,
ensure that the requested element type is supported. If the element is
of type Transmit Scheduling Arbiter (TSAR), also verify that the
specific TSAR type is supported.

Fixes: 214baf2287 ("net/mlx5e: Support HTB offload")
Fixes: 85c5f7c920 ("net/mlx5: E-switch, Create QoS on demand")
Fixes: 0fe132eac3 ("net/mlx5: E-switch, Allow to add vports to rate groups")
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Cosmin Ratiu
bfc611c8f3 net/mlx5: Correct TASR typo into TSAR
[ Upstream commit e575d3a6dd22123888defb622b1742aa2d45b942 ]

TSAR is the correct spelling (Transmit Scheduling ARbiter).

Signed-off-by: Cosmin Ratiu <cratiu@nvidia.com>
Reviewed-by: Gal Pressman <gal@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://lore.kernel.org/r/20240613210036.1125203-2-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 861cd9b9cb62 ("net/mlx5: Verify support for scheduling element and TSAR type")
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Carolina Jubran
cb7cea22d2 net/mlx5: Add missing masks and QoS bit masks for scheduling elements
[ Upstream commit 452ef7f86036392005940de54228d42ca0044192 ]

Add the missing masks for supported element types and Transmit
Scheduling Arbiter (TSAR) types in scheduling elements.

Also, add the corresponding bit masks for these types in the QoS
capabilities of a NIC scheduler.

Fixes: 214baf2287 ("net/mlx5e: Support HTB offload")
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Carolina Jubran
5b3cbf4fbf net/mlx5: Explicitly set scheduling element and TSAR type
[ Upstream commit c88146abe4d0f8cf659b2b8883fdc33936d2e3b8 ]

Ensure the scheduling element type and TSAR type are explicitly
initialized in the QoS rate group creation.

This prevents potential issues due to default values.

Fixes: 1ae258f8b3 ("net/mlx5: E-switch, Introduce rate limiting groups API")
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Shahar Shitrit
f062f17f0b net/mlx5e: Add missing link modes to ptys2ethtool_map
[ Upstream commit 7617d62cba4a8a3ff3ed3fda0171c43f135c142e ]

Add MLX5E_1000BASE_T and MLX5E_100BASE_TX to the legacy
modes in ptys2legacy_ethtool_table, since they were missing.

Fixes: 665bc53969 ("net/mlx5e: Use new ethtool get/set link ksettings API")
Signed-off-by: Shahar Shitrit <shshitrit@nvidia.com>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Reviewed-by: Carolina Jubran <cjubran@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Maher Sanalla
7d32d2d350 net/mlx5: Update the list of the PCI supported devices
[ Upstream commit 7472d157cb8014103105433bcc0705af2e6f7184 ]

Add the upcoming ConnectX-9 device ID to the table of supported
PCI device IDs.

Fixes: f908a35b22 ("net/mlx5: Update the list of the PCI supported devices")
Signed-off-by: Maher Sanalla <msanalla@nvidia.com>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Sriram Yagnaraman
b01930b75f igb: Always call igb_xdp_ring_update_tail() under Tx lock
[ Upstream commit 27717f8b17c098c4373ddb8fe89e1a1899c7779d ]

Always call igb_xdp_ring_update_tail() under __netif_tx_lock, add a comment
and lockdep assert to indicate that. This is needed to share the same TX
ring between XDP, XSK and slow paths. Furthermore, the current XDP
implementation is racy on tail updates.

Fixes: 9cbc948b5a ("igb: add XDP support")
Signed-off-by: Sriram Yagnaraman <sriram.yagnaraman@est.tech>
[Kurt: Add lockdep assert and fixes tag]
Signed-off-by: Kurt Kanzenbach <kurt@linutronix.de>
Acked-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Tested-by: George Kuruvinakunnel <george.kuruvinakunnel@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Jacob Keller
231442c47c ice: fix accounting for filters shared by multiple VSIs
[ Upstream commit e843cf7b34fe2e0c1afc55e1f3057375c9b77a14 ]

When adding a switch filter (such as a MAC or VLAN filter), it is expected
that the driver will detect the case where the filter already exists, and
return -EEXIST. This is used by calling code such as ice_vc_add_mac_addr,
and ice_vsi_add_vlan to avoid incrementing the accounting fields such as
vsi->num_vlan or vf->num_mac.

This logic works correctly for the case where only a single VSI has added a
given switch filter.

When a second VSI adds the same switch filter, the driver converts the
existing filter from an ICE_FWD_TO_VSI filter into an ICE_FWD_TO_VSI_LIST
filter. This saves switch resources, by ensuring that multiple VSIs can
re-use the same filter.

The ice_add_update_vsi_list() function is responsible for doing this
conversion. When first converting a filter from the FWD_TO_VSI into
FWD_TO_VSI_LIST, it checks if the VSI being added is the same as the
existing rule's VSI. In such a case it returns -EEXIST.

However, when the switch rule has already been converted to a
FWD_TO_VSI_LIST, the logic is different. Adding a new VSI in this case just
requires extending the VSI list entry. The logic for checking if the rule
already exists in this case returns 0 instead of -EEXIST.

This breaks the accounting logic mentioned above, so the counters for how
many MAC and VLAN filters exist for a given VF or VSI no longer accurately
reflect the actual count. This breaks other code which relies on these
counts.

In typical usage this primarily affects such filters generally shared by
multiple VSIs such as VLAN 0, or broadcast and multicast MAC addresses.

Fix this by correctly reporting -EEXIST in the case of adding the same VSI
to a switch rule already converted to ICE_FWD_TO_VSI_LIST.

Fixes: 9daf8208dd ("ice: Add support for switch filter programming")
Signed-off-by: Jacob Keller <jacob.e.keller@intel.com>
Tested-by: Rafal Romanowski <rafal.romanowski@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:05 +02:00
Patryk Biel
b0df43e22d hwmon: (pmbus) Conditionally clear individual status bits for pmbus rev >= 1.2
[ Upstream commit 20471071f198c8626dbe3951ac9834055b387844 ]

The current implementation of pmbus_show_boolean assumes that all devices
support write-back operation of status register to clear pending warnings
or faults. Since clearing individual bits in the status registers was only
introduced in PMBus specification 1.2, this operation may not be supported
by some older devices. This can result in an error while reading boolean
attributes such as temp1_max_alarm.

Fetch PMBus revision supported by the device and modify pmbus_show_boolean
so that it only tries to clear individual status bits if the device is
compliant with PMBus specs >= 1.2. Otherwise clear all fault indicators
on the current page after a fault status was reported.

Fixes: 35f165f089 ("hwmon: (pmbus) Clear pmbus fault/warning bits after read")
Signed-off-by: Patryk Biel <pbiel7@gmail.com>
Message-ID: <20240909-pmbus-status-reg-clearing-v1-1-f1c0d68c6408@gmail.com>
[groeck:
 Rewrote description
 Moved revision detection code ahead of clear faults command
 Assigned revision if return value from PMBUS_REVISION command is 0
 Improved return value check from calling _pmbus_write_byte_data()]
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:04 +02:00
Michal Luczaj
a4a1de084d selftests/bpf: Support SOCK_STREAM in unix_inet_redir_to_connected()
[ Upstream commit 1b0ad43177c097d38b967b99c2b71d8be28b0223 ]

Function ignores the AF_UNIX socket type argument, SOCK_DGRAM is hardcoded.
Fix to respect the argument provided.

Fixes: 75e0e27db6 ("selftest/bpf: Change udp to inet in some function names")
Suggested-by: Jakub Sitnicki <jakub@cloudflare.com>
Signed-off-by: Michal Luczaj <mhal@rbox.co>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Tested-by: Jakub Sitnicki <jakub@cloudflare.com>
Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com>
Link: https://lore.kernel.org/bpf/20240713200218.2140950-3-mhal@rbox.co
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:04 +02:00
peng guo
c6c16fd016 cxl/core: Fix incorrect vendor debug UUID define
[ Upstream commit 8ecef8e01a08c7e3e4ffc8f08d9f9663984f334b ]

When user send a mbox command whose opcode is CXL_MBOX_OP_CLEAR_LOG and
the in_payload is normal vendor debug log UUID according to
the CXL specification cxl_payload_from_user_allowed() will return
false unexpectedly, Sending mbox cmd operation fails and the kernel
log will print:
Clear Log: input payload not allowed.

All CXL devices that support a debug log shall support the Vendor Debug
Log to allow the log to be accessed through a common host driver, for any
device, all versions of the CXL specification define the same value with
Log Identifier of: 5e1819d9-11a9-400c-811f-d60719403d86

Refer to CXL spec r3.1 Table 8-71

Fix the definition value of DEFINE_CXL_VENDOR_DEBUG_UUID to match the
CXL specification.

Fixes: 472b1ce6e9 ("cxl/mem: Enable commands via CEL")
Signed-off-by: peng guo <engguopeng@buaa.edu.cn>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20240710023112.8063-1-engguopeng@buaa.edu.cn
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:04 +02:00
Andy Shevchenko
4b3c279f30 eeprom: digsy_mtc: Fix 93xx46 driver probe failure
[ Upstream commit 2b82641ad0620b2d71dc05024b20f82db7e1c0b6 ]

The update to support other (bigger) types of EEPROMs broke
the driver loading due to removal of the default size.

Fix this by adding the respective (new) flag to the platform data.

Fixes: 14374fbb3f ("misc: eeprom_93xx46: Add new 93c56 and 93c66 compatible strings")
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://lore.kernel.org/r/20240508184905.2102633-3-andriy.shevchenko@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:04 +02:00
FUKAUMI Naoki
7029e9c7f5 arm64: dts: rockchip: fix PMIC interrupt pin in pinctrl for ROCK Pi E
[ Upstream commit c623e9daf60a0275d623ce054601550e54987f5b ]

use GPIO0_A2 as PMIC interrupt pin in pinctrl.
(I forgot to fix this part in previous commit.)

Fixes: 02afd3d5b9fa ("arm64: dts: rockchip: fix PMIC interrupt pin on ROCK Pi E")
Signed-off-by: FUKAUMI Naoki <naoki@radxa.com>
Link: https://lore.kernel.org/r/20240722095216.1656081-1-naoki@radxa.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-09-18 19:23:04 +02:00
Konstantin Komarov
742dcbc47a fs/ntfs3: Use kvfree to free memory allocated by kvmalloc
commit ddb17dc880eeaac37b5a6e984de07b882de7d78d upstream.

Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Kunwu Chan
bc08f5ab11 pmdomain: ti: Add a null pointer check to the omap_prm_domain_init
commit 5d7f58ee08434a33340f75ac7ac5071eea9673b3 upstream.

devm_kasprintf() returns a pointer to dynamically allocated memory
which can be NULL upon failure. Ensure the allocation was successful
by checking the pointer validity.

Signed-off-by: Kunwu Chan <chentao@kylinos.cn>
Link: https://lore.kernel.org/r/20240118054257.200814-1-chentao@kylinos.cn
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
[Xiangyu: Modified to apply on 6.1.y]
Signed-off-by: Xiangyu Chen <xiangyu.chen@windriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Sean Anderson
530698ea6b net: xilinx: axienet: Fix race in axienet_stop
commit 858430db28a5f5a11f8faa3a6fa805438e6f0851 upstream.

axienet_dma_err_handler can race with axienet_stop in the following
manner:

CPU 1                       CPU 2
======================      ==================
axienet_stop()
    napi_disable()
    axienet_dma_stop()
                            axienet_dma_err_handler()
                                napi_disable()
                                axienet_dma_stop()
                                axienet_dma_start()
                                napi_enable()
    cancel_work_sync()
    free_irq()

Fix this by setting a flag in axienet_stop telling
axienet_dma_err_handler not to bother doing anything. I chose not to use
disable_work_sync to allow for easier backporting.

Signed-off-by: Sean Anderson <sean.anderson@linux.dev>
Fixes: 8a3b7a252d ("drivers/net/ethernet/xilinx: added Xilinx AXI Ethernet driver")
Link: https://patch.msgid.link/20240903175141.4132898-1-sean.anderson@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Adjusted to apply before dmaengine support ]
Signed-off-by: Sean Anderson <sean.anderson@linux.dev>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Linus Torvalds
65d0db500d mm: avoid leaving partial pfn mappings around in error case
commit 79a61cc3fc0466ad2b7b89618a6157785f0293b3 upstream.

As Jann points out, PFN mappings are special, because unlike normal
memory mappings, there is no lifetime information associated with the
mapping - it is just a raw mapping of PFNs with no reference counting of
a 'struct page'.

That's all very much intentional, but it does mean that it's easy to
mess up the cleanup in case of errors.  Yes, a failed mmap() will always
eventually clean up any partial mappings, but without any explicit
lifetime in the page table mapping itself, it's very easy to do the
error handling in the wrong order.

In particular, it's easy to mistakenly free the physical backing store
before the page tables are actually cleaned up and (temporarily) have
stale dangling PTE entries.

To make this situation less error-prone, just make sure that any partial
pfn mapping is torn down early, before any other error handling.

Reported-and-tested-by: Jann Horn <jannh@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Simona Vetter <simona.vetter@ffwll.ch>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Mikulas Patocka
d3fccbfaca dm-integrity: fix a race condition when accessing recalc_sector
commit f8e1ca92e35e9041cc0a1bc226ef07a853a22de4 upstream.

There's a race condition when accessing the variable
ic->sb->recalc_sector. The function integrity_recalc writes to this
variable when it makes some progress and the function
dm_integrity_map_continue may read this variable concurrently.

One problem is that on 32-bit architectures the 64-bit variable is not
read and written atomically - it may be possible to read garbage if read
races with write.

Another problem is that memory accesses to this variable are not guarded
with memory barriers.

This commit fixes the race - it moves reading ic->sb->recalc_sector to an
earlier place where we hold &ic->endio_wait.lock.

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Willem de Bruijn
34aaedb052 net: tighten bad gso csum offset check in virtio_net_hdr
commit 6513eb3d3191574b58859ef2d6dc26c0277c6f81 upstream.

The referenced commit drops bad input, but has false positives.
Tighten the check to avoid these.

The check detects illegal checksum offload requests, which produce
csum_start/csum_off beyond end of packet after segmentation.

But it is based on two incorrect assumptions:

1. virtio_net_hdr_to_skb with VIRTIO_NET_HDR_GSO_TCP[46] implies GSO.
True in callers that inject into the tx path, such as tap.
But false in callers that inject into rx, like virtio-net.
Here, the flags indicate GRO, and CHECKSUM_UNNECESSARY or
CHECKSUM_NONE without VIRTIO_NET_HDR_F_NEEDS_CSUM is normal.

2. TSO requires checksum offload, i.e., ip_summed == CHECKSUM_PARTIAL.
False, as tcp[46]_gso_segment will fix up csum_start and offset for
all other ip_summed by calling __tcp_v4_send_check.

Because of 2, we can limit the scope of the fix to virtio_net_hdr
that do try to set these fields, with a bogus value.

Link: https://lore.kernel.org/netdev/20240909094527.GA3048202@port70.net/
Fixes: 89add40066f9 ("net: drop bad gso csum_start and offset in virtio_net_hdr")
Signed-off-by: Willem de Bruijn <willemb@google.com>
Acked-by: Jason Wang <jasowang@redhat.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20240910213553.839926-1-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00
Lorenzo Stoakes
12cfb869e1 minmax: reduce min/max macro expansion in atomisp driver
commit 7c6a3a65ace70f12b27b1a27c9a69cb791dc6e91 upstream.

Avoid unnecessary nested min()/max() which results in egregious macro
expansion.

Use clamp_t() as this introduces the least possible expansion, and turn
the {s,u}DIGIT_FITTING() macros into inline functions to avoid the
nested expansion.

This resolves an issue with slackware 15.0 32-bit compilation as
reported by Richard Narron.

Presumably the min/max fixups would be difficult to backport, this patch
should be easier and fix's Richard's problem in 5.15.

Reported-by: Richard Narron <richard@aaazen.com>
Reviewed-by: Hans de Goede <hdegoede@redhat.com>
Closes: https://lore.kernel.org/all/4a5321bd-b1f-1832-f0c-cea8694dc5aa@aaazen.com/
Fixes: 867046cc7027 ("minmax: relax check to allow comparison between unsigned arguments and signed constants")
Cc: stable@vger.kernel.org
Signed-off-by: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-09-18 19:23:04 +02:00