Merge tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

Pull block fixes from Jens Axboe:

 - NVMe fixes via Keith:
     - Fix an out-of-bounds write in nvmet_auth_challenge(), where
       sizeof() on a void pointer undercounted the challenge header and
       let a short AUTH_RECEIVE buffer pass the check
     - nvme-multipath fixes for an ANA log bounds check underflow, the
       command effects log lifetime for multipath heads, and only
       setting BLK_FEAT_ZONED after the zone info is known.
     - nvmet fixes for ns->enabled teardown ordering, rejecting I/O
       after the percpu ns reference is killed, device path preservation
       on allocation failure, and too-short SGL segments in pci-epf
     - nvme-tcp: revert the per-socket dynamic lockdep keys, and delay
       the socket reclassification
     - A DMA pool alignment quirk for the Micron 4100AT
     - Controller state/reset race fixes, and -Wformat-security
       workarounds

 - blk-mq: set RQF_USE_SCHED when the operation is known, and allow
   cached requests to be used for flush operations

 - Reject polled dio with user integrity metadata

 - Save the IRQ state in blkg_tryget_closest()

 - Set the zone write granularity in virtio_blk

 - ublk selftest fixes

* tag 'block-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: (23 commits)
  virtio_blk: set the zone write granularity
  nvme-multipath: set BLK_FEAT_ZONED only after the zone info is known
  nvme: fix command effects log lifetime for multipath heads
  nvmet: don't allow I/O admission after percpu ns reference is killed
  nvmet: defer setting ns->enabled to false in nvmet_ns_disable()
  nvmet: copy the hostid into the ctrl before creating PR pc_refs
  nvmet-auth: fix out-of-bounds write in nvmet_auth_challenge()
  nvmet: pci-epf: reject too-short SGL segments
  nvme-multipath: fix underflow in ANA log bounds checks
  nvme: work around all -Wformat-security warnings
  nvme: work around -Wformat-security warning
  nvme: do not reset controllers in NVME_CTRL_NEW state
  nvme-tcp: delay nvme_tcp_reclassify_socket()
  Revert "nvme-tcp: lockdep: use dynamic lockdep keys per socket instance"
  drbd: remove unused drbd_nl_mcgrps[] array
  blk-mq: allow cached requests to be used for flush operations
  blk-mq: set RQF_USE_SCHED when the operation is known
  block: reject polled dio with user integrity metadata
  selftests: ublk: fix unused_result error
  blk-cgroup: save IRQ state in blkg_tryget_closest()
  ...