)]}'
{
  "log": [
    {
      "commit": "5dd1818b15d98d4a20806cd00b1b40320b06004f",
      "tree": "691abe8db32739093fdbcd0fa054776a3b55a257",
      "parents": [
        "b5a051f6b840d48f159166ef073d3021989bfb50",
        "8697c431e297eb0d0ab13dda6bc172b48a34f05c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 16:53:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 16:53:26 2026 -0700"
      },
      "message": "Merge tag \u0027for-next-keys-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd\n\nPull key fixes from Jarkko Sakkinen.\n\n* tag \u0027for-next-keys-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:\n  KEYS: encrypted: fix integer overflow of datablob_len\n  KEYS: trusted: Fix tpm2_load_cmd() boundary check\n  keys: translate request_key_auth pid for the reading procfs instance\n  keys: fix lost wakeup when reaping a dead key type\n"
    },
    {
      "commit": "b5a051f6b840d48f159166ef073d3021989bfb50",
      "tree": "229bce3a2790a4729d84907859da1b888a695c99",
      "parents": [
        "4982d3552a3bf94de503acf93433277d08421de6",
        "3b95a04eb5f95bf6a016a1bb9ff37d3eee48de63"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 10:40:48 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 10:40:48 2026 -0700"
      },
      "message": "Merge tag \u0027net-7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Paolo Abeni:\n \"Including fixes from Netfilter, Bluetooth, IPSec and WiFi.\n\n  Previous releases - regressions:\n\n   - netfilter: hold reference on ct until flow is released\n\n   - bridge:\n      - move switchdev call outside rcu\n      - vlan: fix bugs caused by switchdev deletion errors\n\n   - wifi:\n      - mac80211: reset state when starting AP fails\n      - cfg80211: don\u0027t free driver-owned scan requests\n\n   - tcp: don\u0027t call skb_clone_and_charge_r() for close()d listener in\n     tcp_v6_do_rcv()\n\n   - mptcp: return sk_wait_data() errors from recvmsg()\n\n   - xfrm: serialize state GC with device state flush\n\n   - drop_monitor: synchronize tracepoint unregistration on error path\n\n   - bluetooth:\n      - eir: validate service data length before reading UUID\n      - hci_sync: serialize local codec list cleanup\n      - RFCOMM: avoid socket lock inversion in listener cleanup\n\n   - eth:\n      - lan743x: fix RX checksum use-after-free\n      - mvpp2: prevent buffer overflow in page_pool allocation\n\n  Previous releases - always broken:\n\n   - core: lock the socket in sock_gettstamp()\n\n   - neighbour: enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.\n\n   - sched: codel: bound the dropping loop per dequeue call\n\n   - wifi: mac80211: include TIM bitmap control for buffered S1G mcast\n     traffic\n\n   - psp: avoid conflicts with skb-\u003edecrypted and sk_validate_xmit_skb()\n\n   - xfrm: fix stack OOB read in iptfs_skb_reset_frag_walk()\n\n   - bluetooth: hci_qca: do not write to the serial port after it is\n     closed\n\n   - dsa: mxl862xx: disable the stats poll on teardown\n\n   - eth:\n      - stmmac: fix TSO header length truncation\n      - ip_tunnel: initialize `options_len` before referencing options\"\n\n* tag \u0027net-7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (159 commits)\n  mptcp: fix bad accounting in __mptcp_subflow_push_pending()\n  mptcp: close race between scheduler and state change\n  mptcp: avoid unneeded actions on subflow reset\n  net: skbuff: do not leave stale header offsets after pskb_carve()\n  selftests: net: packetdrill: test exclusion of old ACK from TCP fast path\n  tcp: exclude old ACKs from tcp fast path\n  dpll: reject a reference sync pin which is not on the pin\u0027s dpll\n  net: mvpp2: prevent buffer overflow in page_pool allocation\n  net: macb: fix ordering around PTP timestamp read\n  selftests: drv-net: psp: test PSP and TCP ULP mutual exclusion\n  net: psp: avoid conflicts with skb-\u003edecrypted and sk_validate_xmit_skb()\n  net: stmmac: preserve real_num_tx_queues on mqprio setup failure\n  net: stmmac: propagate FPE preemption-class mapping errors\n  net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()\n  net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value\n  net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain\n  net: ethernet: cortina: Ack RX overrun interrupt correctly\n  net: lock the socket in sock_gettstamp()\n  eth: fbnic: ring the doorbell if a burst ends in a drop\n  net: netsec: fix device_node reference leak on phy_np\n  ...\n"
    },
    {
      "commit": "4982d3552a3bf94de503acf93433277d08421de6",
      "tree": "94956c7fb806cee3dd376119b19f0df2fa5be69f",
      "parents": [
        "f143ea21cf834b4d57d70b47b99e582461f2dfaf",
        "546b928da0427b0d6c663cbb992bd7bfa9ac7971"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:57:09 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:57:09 2026 -0700"
      },
      "message": "Merge tag \u0027sound-7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n\nPull sound fixes from Takashi Iwai:\n \"A collection of small fixes. Most of them are device-specific fixes\n  while there are a few core fixes. The continued flux, but not too\n  scaring yet. Some highlights below.\n\n  ALSA Core:\n   - Fix potential UAF after asynchronous card release\n   - Fix a race condition in PCM timer initialization order\n\n  USB-Audio:\n   - Hardening fixes for issues reported by fuzzer for 6fire, bcd2000,\n     and implicit FB packets\n   - Fix double list addition in implicit FB handling\n   - Quirks for AVerMedia GC553Pro and Behringer FCA1616\n\n  HD-Audio:\n   - Quirks / fixes for HP OmniBook 7, OMEN 15, and Victus 15 laptops\n\n  ASoC:\n   - Support for DAI link codec channel mask to avoid mismatches\n   - Fix HDMI-codec channel status change report\n   - Fixes for various codecs and platforms: Realtek rt712/rt721\n     (calibration, reset fixes), Cirrus Logic (empty EFI variable\n     validation, capture channel fixup), AMD ACP SoundWire (bounds\n     checks, refactorings), ADAU1977 (OF match table support, SPI\n     cleanups), ES8336 (Huawei Matebook B3-420 quirk), UX500 (macro\n     fix)\"\n\n* tag \u0027sound-7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound: (33 commits)\n  ASoC: adau1977-i2c: add OF match table for I2C\n  ASoC: adau1977-spi: drop __maybe_unused and of_match_ptr()\n  ASoC: adau1977: make the Kconfig symbols user selectable\n  ASoC: amd: acp: fix card name length warning in SOF SoundWire machine driver\n  ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID\n  ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver\n  ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers\n  ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length\n  ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config-\u003etype\n  ASoC: hdmi-codec: Report a change when the channel status moves\n  ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments\n  ASoC: rt721: Reset codec to fix abnormal sound\n  ALSA: usb-audio: fix list_add double-add in push_back_to_ready_list\n  ALSA: hda: trace PCM open only after assigning a stream\n  ALSA: usb-audio: skip the broken mute control on AVerMedia GC553Pro\n  ALSA: hda/realtek: Enable mute LEDs on HP OmniBook 7 17-dc0xxx\n  ALSA: 6fire: fix OOB write from device-reported iso length\n  ALSA: usb-audio: Add capture quirk for Behringer FCA1616\n  ALSA: hda/realtek: Add mute LED quirk for HP OMEN 15-ax\n  ASoC: Intel: sof_es8336: Add a quirk for Huawei Matebook B3-420\n  ...\n"
    },
    {
      "commit": "f143ea21cf834b4d57d70b47b99e582461f2dfaf",
      "tree": "f1920242738109f1ae5b52f770ca3d07430bbb27",
      "parents": [
        "61cc777ca7a4280568ec3a8f730651d482f46e55",
        "242da4318d97380741516b595af3920207b2f0f1"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:40:25 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:40:25 2026 -0700"
      },
      "message": "Merge tag \u0027pwrseq-fixes-for-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull power sequencing fixes from Bartosz Golaszewski:\n\n - fix kconfig issue in pwrseq-thread-gpu\n\n - fix error path logic in pwrseq_unit_enable()\n\n - fix two NULL-pointer dereference bugs in power sequencing core\n\n* tag \u0027pwrseq-fixes-for-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()\n  power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()\n  power: sequencing: don\u0027t call .post_enable() if pwrseq_unit_enable() failed\n  power: sequencing: Fix build issue with COMPILE_TEST\n"
    },
    {
      "commit": "61cc777ca7a4280568ec3a8f730651d482f46e55",
      "tree": "6d956ff214f9ffe0fba921ad3c6f726d3c99e461",
      "parents": [
        "4aec9ad1c668755b253bff4d95a9d82a17d2d434",
        "50fd0ada8d37587223001600933270b59cb30e19"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:08:20 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 09:08:20 2026 -0700"
      },
      "message": "Merge tag \u0027gpio-fixes-for-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull gpio fixes from Bartosz Golaszewski:\n\n - fix fwnode reference leak on failure in shared GPIO handling\n\n - fix regression in OF_POPULATED logic after the unification of GPIO\n   hog handling between OF, ACPI and machine variants\n\n - don\u0027t call free_irq() if no IRQ is installed in gpio-virtuser\n\n* tag \u0027gpio-fixes-for-v7.3-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  gpio: virtuser: skip free_irq when no IRQ is installed\n  gpiolib: of: don\u0027t mark hog nodes OF_POPULATED before a chip is found\n  gpiolib: Put fwnode reference on failure\n"
    },
    {
      "commit": "3b95a04eb5f95bf6a016a1bb9ff37d3eee48de63",
      "tree": "f8d6e1cf388a6f343cb8e15fabb51541c8461e9e",
      "parents": [
        "a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309",
        "f3ef03357396d4b147d8e76c75fb612c2f264ffc"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Sep 17 08:14:38 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Sep 17 08:14:39 2026 -0700"
      },
      "message": "Merge branch \u0027mptcp-misc-fixes-for-v7-3-rc4\u0027\n\nMatthieu Baerts says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nmptcp: misc fixes for v7.3-rc4\n\nHere are two unrelated fixes:\n\n- Patch 1: avoid unneeded actions on subflow reset. A fix for another\n  fix introduced in v6.12 and targeting a commit from v5.7.\n\n- Patch 2: close a possible race when scheduling a closing path. A fix\n  for another fix introduced in v6.0 and targeting v5.10.\n\n- Patch 3: fix bad accounting when __subflow_push_pending returns an\n  error. A fix for v6.6.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-0-0cf5c72667c8@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f3ef03357396d4b147d8e76c75fb612c2f264ffc",
      "tree": "f8d6e1cf388a6f343cb8e15fabb51541c8461e9e",
      "parents": [
        "42064de57fb83231fcc89663a94885f228a1ee53"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:05:59 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Sep 17 08:14:33 2026 -0700"
      },
      "message": "mptcp: fix bad accounting in __mptcp_subflow_push_pending()\n\nIf __subflow_push_pending() errors out we should avoid updating the\ncopied byte counters, to avoid mismatch push call later on.\n\nFixes: 0fa1b3783a17 (\"mptcp: use get_send wrapper\")\nCc: stable@vger.kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-3-0cf5c72667c8@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "42064de57fb83231fcc89663a94885f228a1ee53",
      "tree": "e77e8ff6293e74412dcedba4d8d99576ecde65b9",
      "parents": [
        "2b0f561f21b27c40c91ea4975268a06092bd7e9c"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:05:58 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Sep 17 08:14:33 2026 -0700"
      },
      "message": "mptcp: close race between scheduler and state change\n\nThe mptcp scheduler may race with subflow sockets state change: data\ntransmission on the selected socket may fail and a later release could\ntry to use mss_now reset to 0 for a divide operation.\n\nAddress the issue by explicitly checking for the critical scenario.\n\nFixes: c886d70286bf (\"mptcp: do not queue data on closed subflows\")\nCc: stable@vger.kernel.org\nReported-by: Shardul Bankar \u003cshardul.b@mpiricsoftware.com\u003e\nReported-by: Xinyang Ge \u003cxinyang@anthropic.com\u003e\nCloses: https://lore.kernel.org/20260525194828.1137119-1-shardul.b@mpiricsoftware.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-2-0cf5c72667c8@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2b0f561f21b27c40c91ea4975268a06092bd7e9c",
      "tree": "c88af0230d14081ad30a6a3dcb886d3e5cb95633",
      "parents": [
        "a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:05:57 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Sep 17 08:14:33 2026 -0700"
      },
      "message": "mptcp: avoid unneeded actions on subflow reset\n\nOnce in a blue moon, the mptcp receive path can recursively call\nmptcp_data_ready() via state change under unlucky error conditions, and\nthen try to hold the data lock again.\n\nBreak the recursion loop explicitly checking for the exceptional\ncondition.\n\nAdd a new flag instead of using an existing one like \u0027closing\u0027, to exit\nearly in subflow_state_change(), and explicitly flush the RX queue at\nreset time.\n\nThis avoids unneeded processing to check for available data -- calling\nget_mapping_status() and more on a dying subflow -- but also in error\nreporting and worker scheduling.\n\nNote that we must consume the currently peeked skb before invoking\nmptcp_dss_corruption to avoid consuming it again after the eventual\nreset has freed it.\n\nFixes: e32d262c89e2 (\"mptcp: handle consistently DSS corruption\")\nCc: stable@vger.kernel.org\nReported-by: Xinyang Ge \u003cxinyang@anthropic.com\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260917-net-mptcp-misc-fixes-7-3-rc4-v2-1-0cf5c72667c8@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4aec9ad1c668755b253bff4d95a9d82a17d2d434",
      "tree": "d3e2b627494ec7645f85d7877eb977ad40eaef9d",
      "parents": [
        "238650ef6c7c7cca08e032527329424c9fbd70e5",
        "55a8e1451869233db837a97e8f3cbf9983bc8678"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 08:03:37 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Sep 17 08:03:37 2026 -0700"
      },
      "message": "Merge tag \u0027dma-mapping-7.3-2026-09-17\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux\n\nPull dma-mapping fixes from Marek Szyprowski:\n \"A few fixes for the DMA-mapping code:\n\n   - resolved regression in accessing encrypted memory by IOMMU-backed\n     devices (Aneesh Kumar K.V)\n\n   - improved failure handling and removed rare bug in swiotlb/highmem\n     (Donggeun Yoo)\"\n\n* tag \u0027dma-mapping-7.3-2026-09-17\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux:\n  x86/mm: Don\u0027t force unencrypted DMA for IOMMU-backed devices\n  dma-mapping: don\u0027t trace the DMA address when the allocation fails\n  swiotlb: use the adjusted address for the highmem page lookup\n  dma-coherent: report a failed reserved memory assignment\n"
    },
    {
      "commit": "a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309",
      "tree": "79e4a5a1c8e35269d9d4525598af02d2b169ad99",
      "parents": [
        "ad9c65b8f948f9ca00d065114d6cd7d281f53ec9"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Sep 15 13:04:23 2026 +0000"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 16:05:02 2026 +0200"
      },
      "message": "net: skbuff: do not leave stale header offsets after pskb_carve()\n\npskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove\nthe first bytes of a packet and reallocate skb-\u003ehead.\n\nAll the headers that were present before the operation are gone,\nbut both functions call skb_headers_offset_update(skb, 0), which\nis a no-op : skb-\u003emac_header, skb-\u003enetwork_header,\nskb-\u003etransport_header and skb-\u003ecsum_start keep their old values and\nnow describe bytes which are no longer there.\n\nBoth helpers size the new head from the old skb_end_offset(), so the\nstale offsets still land inside the new allocation. They point past\nskb_tail_pointer() though, to bytes that were never initialized.\n\npskb_carve_inside_nonlinear() is the worst case, because it leaves a\nzombie skb with an empty linear part (skb-\u003edata \u003d\u003d\nskb_tail_pointer(skb), skb_headlen(skb) \u003d\u003d 0), while\nskb_mac_header_was_set() is still true and skb-\u003emac_header is way\nahead of skb-\u003edata.\n\nThe only user of pskb_extract() is rds_tcp_data_recv(), and the\ncarved skb is queued on tinc-\u003eti_skb_list. When the RDS incoming\nmessage is released, rds_tcp_inc_free() calls skb_queue_purge(),\nwhich frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is\nvisible from drop_monitor, which then tries to pull back to the\n(bogus) mac header :\n\nskbuff: __skb_pull(len\u003d234)\nskb len\u003d6968 data_len\u003d6968 headroom\u003d0 headlen\u003d0 tailroom\u003d0\nend-tail\u003d384 mac\u003d(234,14) mac_len\u003d14 net\u003d(248,40) trans\u003d288\nshinfo(txflags\u003d0 nr_frags\u003d1 gso(size\u003d1428 type\u003d16 segs\u003d5))\ncsum(0x100120 start\u003d288 offset\u003d16 ip_summed\u003d3 complete_sw\u003d0 valid\u003d1 level\u003d0)\nhash(0x7b446c6c sw\u003d0 l4\u003d1) proto\u003d0x86dd pkttype\u003d0 iif\u003d60\nkernel BUG at ./include/linux/skbuff.h:2847!\n\nAdd skb_carve_reset_headers() to mark the mac and transport headers\nas not set, reset the network header, clear skb-\u003emac_len, and drop\na now meaningless CHECKSUM_PARTIAL (csum_start no longer describes\nanything).\n\nInvalidate the inner offsets as well. Unlike mac_header and\ntransport_header they have no \"unset\" sentinel, so a leftover\nnon-zero value still looks like a real header. Zero\nskb-\u003einner_mac_header, skb-\u003einner_network_header,\nskb-\u003einner_transport_header, skb-\u003einner_protocol and\nskb-\u003eencapsulation, so that all the header state is invalidated in\none place.\n\nv2: fixed an inaccurate changelog. The stale offsets stay inside the\n    new skb-\u003ehead, which is never smaller than the old one, they\n    simply point past skb_tail_pointer() to bytes that are gone.\n    Thanks to Xuanqiang Luo for insisting on this.\n    Also invalidate the inner header state, as suggested by the\n    netdev AI review :\n    https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com\n\nFixes: 6fa01ccd8830 (\"skbuff: Add pskb_extract() helper function\")\nReported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/\nCc: Xuanqiang Luo \u003cxuanqiang.luo@linux.dev\u003e\nCc: Allison Henderson \u003cachender@kernel.org\u003e\nCc: rds-devel@oss.oracle.com\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260915130423.3956471-1-edumazet@google.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "ad9c65b8f948f9ca00d065114d6cd7d281f53ec9",
      "tree": "24460f2d4896308f91e3bb5f6c294f056f2f4aaa",
      "parents": [
        "d798162eb364df2e77a56fdbe5bae54440152d3b",
        "d841cd7513f3d48018175ecb1fb972cfd3c3c10b"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:18:10 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:18:49 2026 +0200"
      },
      "message": "Merge branch \u0027tcp-exclude-old-acks-from-fast-path\u0027\n\nInbal Schussheim says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\ntcp: exclude old ACKs from fast path\n\nExclude ACKs outside [SND.UNA, SND.NXT] from TCP header prediction so\nthat they fall through to the slow path, where ACK\nvalidation is applied.\n\nAdd a packetdrill test for a data segment carrying an\nexcessively old ACK. The test fails on the unpatched kernel and passes\nwith the fix.\n\nv2: https://lore.kernel.org/netdev/20260909075644.1408171-1-inbal.lipshtat@mail.huji.ac.il/\nv1: https://lore.kernel.org/netdev/20260906123151.1391349-1-inbal.lipshtat@mail.huji.ac.il/T/#u\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260914090408.1435080-1-inbal.lipshtat@mail.huji.ac.il\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "d841cd7513f3d48018175ecb1fb972cfd3c3c10b",
      "tree": "24460f2d4896308f91e3bb5f6c294f056f2f4aaa",
      "parents": [
        "f81e6c3fb06327bc49cdd6e559845293ba06a704"
      ],
      "author": {
        "name": "Inbal Schussheim",
        "email": "inbal.lipshtat@mail.huji.ac.il",
        "time": "Mon Sep 14 12:04:08 2026 +0300"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:17:58 2026 +0200"
      },
      "message": "selftests: net: packetdrill: test exclusion of old ACK from TCP fast path\n\nAdd a packetdrill test for an in-sequence data segment carrying an\nexcessively old ACK.\n\nVerify that the segment falls through from the TCP fast path to the slow\npath, where the existing ACK validation rejects it and sends a challenge\nACK. The payload is not accepted and RCV.NXT remains unchanged.\n\nBased on the reproducer from Commit 3d501dd326fb\n(\"tcp: do not accept ACK of bytes we never sent\").\n\nSigned-off-by: Inbal Schussheim \u003cinbal.lipshtat@mail.huji.ac.il\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260914090408.1435080-3-inbal.lipshtat@mail.huji.ac.il\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f81e6c3fb06327bc49cdd6e559845293ba06a704",
      "tree": "d0bab714377f843fe238b2adbeadb088e3822ae6",
      "parents": [
        "d798162eb364df2e77a56fdbe5bae54440152d3b"
      ],
      "author": {
        "name": "Inbal Schussheim",
        "email": "inbal.lipshtat@mail.huji.ac.il",
        "time": "Mon Sep 14 12:04:07 2026 +0300"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 15:17:58 2026 +0200"
      },
      "message": "tcp: exclude old ACKs from tcp fast path\n\nExclude old ACKs before SND.UNA from the tcp fast path\nas well as ACKs after SND.NXT.\n\nSuch ACKs will fall through to the slow path, where tcp_ack()\nperforms the appropriate validation and challenge ACK handling\naccording to RFC5961 and Commit 3d501dd326fb1c7 (\"tcp: do not\naccept ACK of bytes we never sent\").\n\nThis prevents old ACKs from being accepted\nor modifying connection state as part of the fast path before\nappropriate ACK validation is applied.\nIn particular, this prevents payload carried by a segment with\nan excessively old ACK from advancing RCV.NXT before the ACK\nis rejected.\n\nFixes: 31770e34e43d (\"tcp: Revert \"tcp: remove header prediction\"\")\nReported-by: Amit Klein \u003camit.klein@mail.huji.ac.il\u003e\nReported-by: Tamir Shahar \u003ctamir.shahar1@mail.huji.ac.il\u003e\nReported-by: Inbal Schussheim \u003cinbal.lipshtat@mail.huji.ac.il\u003e\nSuggested-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: stable@vger.kernel.org\nSigned-off-by: Inbal Schussheim \u003cinbal.lipshtat@mail.huji.ac.il\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260914090408.1435080-2-inbal.lipshtat@mail.huji.ac.il\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "d798162eb364df2e77a56fdbe5bae54440152d3b",
      "tree": "0c2d1a28f23a2a58d824a90d75533fb1055a07ea",
      "parents": [
        "14cb1e7702e5cb3c58888f6aed498381a73927d2"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 14:30:47 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 14:51:23 2026 +0200"
      },
      "message": "dpll: reject a reference sync pin which is not on the pin\u0027s dpll\n\ndpll_pin_ref_sync_state_set() resolves the partner\u0027s driver private data\nwith dpll_pin_on_dpll_priv() and passes the result to ref_sync_get() and\nref_sync_set() without looking at it. The helper returns NULL when the\npartner holds no ref on that dpll. Of the two drivers implementing the\nfeature only zl3073x dereferences the pointer (sync_pin-\u003eid); ice ignores\nit, so ice cannot fault here.\n\nThe NULL is a teardown race, not a steady state - zl3073x registers every\ninput pin with every channel, so the partner is normally present on the\ndpll the base pin resolves to. zl3073x_dev_stop() unregisters pins one at\na time, taking and dropping dpll_lock for each, and between the partner\u0027s\nturn and the base pin\u0027s the partner is out of that dpll\u0027s pin_refs while\nstill registered with the channels not yet torn down, so\ndpll_pin_available() keeps passing. That path is not only driver removal:\ndevlink reload and devlink dev flash both run zl3073x_dev_stop().\n\nReproduced by holding that state open with a mock dpll device, which is\nwhere the frame name comes from:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n Oops: Oops: 0000 [#1] SMP NOPTI\n RIP: 0010:mock_ref_sync_get+0x5/0x30\n Call Trace:\n  \u003cTASK\u003e\n  dpll_pin_ref_sync_set+0x19f/0x4a0\n  dpll_nl_pin_set_doit+0x17d/0x840\n  genl_family_rcv_msg_doit+0xd6/0x130\n  genl_rcv_msg+0x181/0x2b0\n  netlink_rcv_skb+0x55/0x100\n  genl_rcv+0x23/0x30\n  netlink_unicast+0x24d/0x370\n  netlink_sendmsg+0x1e2/0x420\n  __sys_sendto+0x1db/0x1f0\n  __x64_sys_sendto+0x1f/0x30\n  do_syscall_64+0xe1/0x490\n\nCommit d2e914a4a0d0 (\"dpll: fix NULL pointer dereference in\ndpll_msg_add_pin_ref_sync()\") added the same guard to the read side, which\nthe kernel walks into by itself because the delete notification is emitted\nfrom inside the unregister; the write side needs a pin-set to land in the\nwindow and was left alone. Test the priv rather than look up pin_refs\ndirectly, so that the two halves key off the same condition.\n\nFixes: 58256a26bfb3 (\"dpll: add reference sync get/set\")\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nReviewed-by: Ivan Vecera \u003civecera@redhat.com\u003e\nLink: https://patch.msgid.link/20260915213047.1352286-1-kuba@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "14cb1e7702e5cb3c58888f6aed498381a73927d2",
      "tree": "8dc204235313dd83a6f1bf390efe087be5320e9b",
      "parents": [
        "9ca4ba24259183ce15665be86b2956cd896c4687"
      ],
      "author": {
        "name": "Dmitriy Okunev",
        "email": "dokunevdmitriy@gmail.com",
        "time": "Mon Sep 14 12:15:57 2026 +0300"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 14:43:29 2026 +0200"
      },
      "message": "net: mvpp2: prevent buffer overflow in page_pool allocation\n\nThe per‑processor buffering scheme is supported only if the\nnumber of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).\nThis is already checked in mvpp2_probe() during the initial\nactivation of percpu_pools.\n\nHowever, mvpp2_change_mtu() may later call\nmvpp2_bm_switch_buffers(priv, true) without this check, which can\nlead to an out-of-bounds access in the priv-\u003epage_pool array in\nmvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ\nentries, and mvpp2_get_nrxqs() may return exactly that value. The\nper-CPU scheme then doubles it to nrxqs * 2, exceeding the array\nbounds.\n\nCheck that the hardware version is MVPP22 or newer and that the\nnumber of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS\nbefore switching to per-CPU mode.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\nFixes: 7d04b0b13b11 (\"mvpp2: percpu buffers\")\nSigned-off-by: Dmitriy Okunev \u003cdokunevdmitriy@gmail.com\u003e\nLink: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "9ca4ba24259183ce15665be86b2956cd896c4687",
      "tree": "7204238fdde71195b0135aedf3bb6020e5f20486",
      "parents": [
        "c9151088f1674fd29ff26a20f5fc687acf53a2f0"
      ],
      "author": {
        "name": "James Clark",
        "email": "jjc@jclark.com",
        "time": "Tue Sep 15 11:58:17 2026 +0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Sep 17 14:25:52 2026 +0200"
      },
      "message": "net: macb: fix ordering around PTP timestamp read\n\nPTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly\nbracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the\nreturned interval can be as short as 37 ns, while an ordered register\nread takes approximately 1 us. This biases the midpoint used by phc2sys,\ncausing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized\nto the PHC.\n\ngem_tsu_get_time() reads the nanoseconds register using the driver\u0027s\nrelaxed MMIO accessor. On weakly ordered systems, the subsequent system\ntimestamp can be taken before the register read completes. The internal\nsmp_rmb() in the pre-timestamp path also does not guarantee ordering\nagainst the subsequent MMIO read.\n\nAdd rmb() before and after the bracketed nanoseconds read in both the\nnormal and seconds rollover paths so the system timestamps bracket the\nPHC read. Adding the post-read barrier increases the minimum interval on\nthe same Raspberry Pi 5 to approximately 1 us.\n\nFixes: e51bb5c2784c (\"net: macb: ptp: Switch to gettimex64() interface\")\nTested-by: Nicolai Buchwitz \u003cnb@tipi-net.de\u003e # Raspberry Pi CM5, min bracket 37 ns -\u003e 981 ns\nReviewed-by: Nicolai Buchwitz \u003cnb@tipi-net.de\u003e\nReviewed-by: Théo Lebrun \u003ctheo.lebrun@bootlin.com\u003e\nAssisted-by: LLM\nSigned-off-by: James Clark \u003cjjc@jclark.com\u003e\nLink: https://patch.msgid.link/20260915045823.76100-1-jjc@jclark.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "546b928da0427b0d6c663cbb992bd7bfa9ac7971",
      "tree": "8af139c814686116b55ab46ad130804f5da46a57",
      "parents": [
        "dbd9d1cbf9700528c8595ab1fa7ef832e79821fe",
        "940e8fe8535d22ce67dd2fb9588e6c55a31d7d03"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Sep 17 08:15:32 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Sep 17 08:15:32 2026 +0200"
      },
      "message": "Merge tag \u0027asoc-fix-v7.3-rc3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus\n\nASoC: Fixes for v7.3\n\nA relatively large pile of fixes here, a lot of driver specific stuff\nthat\u0027s broadly unremarkable plus a few core fixes from Richard that fix\nissues where SoundWire systems with multiple CODECs on the same link\nwould configure the CODECs to use the same bus slots leading to broken\naudio.\n"
    },
    {
      "commit": "c9151088f1674fd29ff26a20f5fc687acf53a2f0",
      "tree": "5d219670a0f060605a7692b25678446a3d1e29b2",
      "parents": [
        "dd56c0bc4836fa705acb2f6a8a44af669d30fa3a",
        "b4288c59bda883b0e5cd95099dc3b0b7b7fc50f6"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:18:26 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:18:26 2026 -0700"
      },
      "message": "Merge branch \u0027net-psp-avoid-conflicts-with-skb-decrypted-and-sk_validate_xmit_skb\u0027\n\nDaniel Zahka says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: psp: avoid conflicts with skb-\u003edecrypted and sk_validate_xmit_skb()\n\nSashiko\u0027s review of commit da630d1da2b1 (\"netdevsim: psp: drop tx key\nops\") [1] showed that there is a hazard between PSP and offloaded TLS,\nwhere both can clobber what the other set in the sk_validate_xmit_skb\ncallback.\n\nIt was discussed further on the mailing list [2], and it was pointed out\nthat there are conflicts with PSP and TLS ULP both using the\nskb-\u003edecrypted bit.\n\nThe simplest fix is to make psp and tls mutually exclusive. This series\ngoes a bit further and makes psp exclusive with all TCP ULPs. The PSP\nimplementation that we have is not designed to be used with any TCP ULP,\nso don\u0027t allow a socket to have state for both.\n\nI will send a subsequent series to net-next which will remove the\nability to perform the rx-assoc and tx-assoc psp netlink calls on\nsockets that are not in the TCP_ESTABLISHED state. This will close the\nremaining quirk that a sk_clone() on a listen socket with psp tx-assoc\nstate will leave a stale sk-\u003esk_validate_xmit_skb call back on a new,\nnon-psp socket. I do not believe that change needs to be regarded as a\nfix, because it only stands to add unecessary validation code in the tx\npath.\n\n[1]: https://sashiko.dev/#/patchset/20260903-psp-prep-v1-0-d47e9c4c375d%40gmail.com\n[2]: https://lore.kernel.org/netdev/20260903-psp-prep-v1-0-d47e9c4c375d@gmail.com/\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260915-psp-ktls-fix-v2-0-0eedc3b148ec@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b4288c59bda883b0e5cd95099dc3b0b7b7fc50f6",
      "tree": "5d219670a0f060605a7692b25678446a3d1e29b2",
      "parents": [
        "a41f24c612c3f5139a3143307eb85bbcf1bd4d07"
      ],
      "author": {
        "name": "Daniel Zahka",
        "email": "daniel.zahka@gmail.com",
        "time": "Tue Sep 15 16:11:38 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:18:24 2026 -0700"
      },
      "message": "selftests: drv-net: psp: test PSP and TCP ULP mutual exclusion\n\nTest both setting PSP after TLS ULP, and TLS ULP after PSP.\n\nAdd CONFIG_TLS\u003dy to the drivers/net/config.\n\nSigned-off-by: Daniel Zahka \u003cdaniel.zahka@gmail.com\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260915-psp-ktls-fix-v2-2-0eedc3b148ec@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a41f24c612c3f5139a3143307eb85bbcf1bd4d07",
      "tree": "22b3d797f7db3ae3178d621d07d4b12faac0ffea",
      "parents": [
        "dd56c0bc4836fa705acb2f6a8a44af669d30fa3a"
      ],
      "author": {
        "name": "Daniel Zahka",
        "email": "daniel.zahka@gmail.com",
        "time": "Tue Sep 15 16:11:37 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:18:24 2026 -0700"
      },
      "message": "net: psp: avoid conflicts with skb-\u003edecrypted and sk_validate_xmit_skb()\n\nPSP conflicts with TLS ULP in its usage of both skb-\u003edecrypted and\nsk-\u003esk_validate_xmit_skb().\n\nMake PSP mutually exclusive with TLS ULP, the only other user of either\nof these. As other users of skb-\u003edecrypted come along, they can be added\nto sk_has_decrypt_user(). It would make sense to also assert that\nsk-\u003esk_validate_xmit_skb() is also NULL in both of these setup paths for\nsimilar future proofing, but the PSP listener/sk_clone() path is still\nbroken and it could be seen as a regression to not allow rx assoc to run\non a child of a listener socket with PSP tx assoc state.\n\nInclude all TCP ULPs in the sk_has_decrypt_user() check, even though TLS\nis the only one that conflicts with PSP via the decrypted bit. This is\nintentional because PSP was not designed to be used with ULPs. It is\nbest to close off surface area that may make bugs reachable, until\nsomeone wishes to design and test an actual user of PSP with ULPs.\n\nFixes: 6b46ca260e22 (\"net: psp: add socket security association code\")\nSigned-off-by: Daniel Zahka \u003cdaniel.zahka@gmail.com\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260915-psp-ktls-fix-v2-1-0eedc3b148ec@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "dd56c0bc4836fa705acb2f6a8a44af669d30fa3a",
      "tree": "8739d044c65312677c3c76fb5457247d54d9e9e6",
      "parents": [
        "c7ead9704249d57d4693a04697e3bbd285138fa9",
        "02fffd1939f6b45892f61822459953ce95e42948"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:07:16 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:07:17 2026 -0700"
      },
      "message": "Merge branch \u0027net-stmmac-restore-previous-state-if-tc_setup_dwmac510_mqprio-fails\u0027\n\nLorenzo Bianconi says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: stmmac: restore previous state if tc_setup_dwmac510_mqprio() fails\n\nRestore previous mqprio qdisc configuration if\ntc_setup_dwmac510_mqprio() fails running the following configuration:\n\n  $tc qdisc add dev eth0 root handle 1: mqprio queues 2@0 2@2\n  $tc qdisc replace dev eth0 root handle 2: mqprio queues 2@0 2@2 fp E P\n\nPropagate FPE preemption-class mapping errors in\ntc_setup_dwmac510_mqprio() and tc_taprio_configure().\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-0-a76b1e2547c1@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "02fffd1939f6b45892f61822459953ce95e42948",
      "tree": "8739d044c65312677c3c76fb5457247d54d9e9e6",
      "parents": [
        "90e4b849dfa6fc8e6c050bcfe1b331b69c015d28"
      ],
      "author": {
        "name": "Lorenzo Bianconi",
        "email": "lorenzo.bianconi@oss.qualcomm.com",
        "time": "Fri Sep 11 10:58:30 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:07:13 2026 -0700"
      },
      "message": "net: stmmac: preserve real_num_tx_queues on mqprio setup failure\n\nWith the FPE preemption-class mapping error now propagated from\nstmmac_fpe_map_preemption_class(), tc_setup_dwmac510_mqprio() can fail\non the mapping step. The error path used to call stmmac_reset_tc_mqprio(),\nwhich resets the number of real TX queues to priv-\u003eplat-\u003etx_queues_to_use\n(the platform maximum), overwriting the value that was active before the\noffload was attempted (for example a lower count left over from a previous\nmqprio configuration).\n\nThe issue can be triggered using the following configuration:\n\n  # First mqprio config lowers the hw queue count below the platform\n  # default (e.g. 8 TX queues).\n  $tc qdisc add dev eth0 root handle 1: mqprio queues 2@0 2@2\n\n  # Replace mqprio configuration with a second one that fails FPE\n  # preemption-class mapping. stmmac driver resets the real_num_tx_queues\n  # to the platform maximum, losing the previous configuration.\n  $tc qdisc replace dev eth0 root handle 2: mqprio queues 2@0 2@2 fp E P\n\nSave ndev-\u003ereal_num_tx_queues before lowering it and restore it,\ntogether with the TC-to-queue and priority-to-TC mappings, when the FPE\npreemption-class mapping fails, instead of resetting the queue count to\nthe platform maximum.\n\nNote that a failed setup makes the qdisc layer run mqprio_destroy() on\nthe new qdisc. Because priv-\u003ehw_offload is only assigned after\nndo_setup_tc() succeeds, mqprio_destroy() calls netdev_set_num_tc(dev, 0),\nso dev-\u003enum_tc ends up 0 regardless of the driver-side restore and the\nprevious qdisc is not reactivated. The restore is still needed to keep\nreal_num_tx_queues and to avoid leaving the failed configuration\u0027s\nTC-to-queue and priority-to-TC mappings in place.\n\nFixes: 195e4f409a40 (\"net: stmmac: support fp parameter of tc-mqprio\")\nSigned-off-by: Lorenzo Bianconi \u003clorenzo.bianconi@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-2-a76b1e2547c1@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "90e4b849dfa6fc8e6c050bcfe1b331b69c015d28",
      "tree": "025cabcbcf5c45d659cceeeb60db45cf0a8d7307",
      "parents": [
        "c7ead9704249d57d4693a04697e3bbd285138fa9"
      ],
      "author": {
        "name": "Lorenzo Bianconi",
        "email": "lorenzo.bianconi@oss.qualcomm.com",
        "time": "Fri Sep 11 10:58:29 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 19:07:13 2026 -0700"
      },
      "message": "net: stmmac: propagate FPE preemption-class mapping errors\n\nstmmac_fpe_map_preemption_class() dispatches through the\nstmmac_do_void_callback() helper, which forces the callback\u0027s return\nvalue to 0 whenever the op pointer is populated. As a result the\n-EINVAL returned by dwmac5_fpe_map_preemption_class() (e.g. when a\npreemptible TC owns more than one TXQ under SP scheduling) is silently\nswallowed by every caller.\n\nSwitch the dispatch macro to stmmac_do_callback() so the callback\u0027s real\nresult is propagated, and honour it in the taprio and mqprio qdisc\noffload.\n\nNote that the taprio \"if (ret)\" check in tc_taprio_configure() used to\nbe dead code and now becomes live: a preemptible TC spanning more than\none TXQ under SP scheduling cannot be programmed in hardware, so a\ntaprio or mqprio configuration that previously returned success while\nleaving the preemption-class register unprogrammed now fails with\n-EINVAL. For taprio, the failure also runs the disable path, tearing\ndown the schedule that was just installed; this is the intended\nbehaviour.\n\nFixes: 195e4f409a40 (\"net: stmmac: support fp parameter of tc-mqprio\")\nSigned-off-by: Lorenzo Bianconi \u003clorenzo.bianconi@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-1-a76b1e2547c1@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c7ead9704249d57d4693a04697e3bbd285138fa9",
      "tree": "f538181ad1f21091e6c20044be43271b5e26376d",
      "parents": [
        "31550d585589fde1ae95bf7f7a8188b2d2fdf1c7"
      ],
      "author": {
        "name": "Guanglei Zhu",
        "email": "zhugl3@xiaopeng.com",
        "time": "Fri Sep 11 10:17:34 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 18:58:45 2026 -0700"
      },
      "message": "net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()\n\nThe netif index carried in the DPMAIF PIT header is five bits wide,\nbut ccmni_inst[] only has room for NIC_DEV_MAX (21) entries.\nt7xx_ccmni_recv_skb() indexes the array without a bounds check, so\nindexes 21 to 31 read past it.  The out-of-bounds value lands in the\ncallback table that follows the array, which is never NULL, so the\nexisting !ccmni check does not catch it and the driver dereferences\nwhatever sits there as a struct t7xx_ccmni.\n\nDrop the skb when the index is out of range.\n\nFixes: 05d19bf500f8 (\"net: wwan: t7xx: Add WWAN network interface\")\nCc: stable@vger.kernel.org\nSigned-off-by: Guanglei Zhu \u003czhugl3@xiaopeng.com\u003e\n\nVerified in a QEMU guest with a fault injector setting the netif\nindex to 25: the unpatched driver reads a value past ccmni_inst[],\nwhich lands in the callback table, and dereferences it far enough to\nqueue the skb.  With this check the packet is dropped.  Well-formed\ntraffic on index 0 is unaffected.\n\nChanges in v2: none.\n\nLink: https://patch.msgid.link/20260911021734.1396599-3-zhugl3@xiaopeng.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "31550d585589fde1ae95bf7f7a8188b2d2fdf1c7",
      "tree": "525662aacb0d71e4caaa2c2baeabb32d0def6304",
      "parents": [
        "5d063822ac5184939c1ed377a339a01d8ae814e8"
      ],
      "author": {
        "name": "Guanglei Zhu",
        "email": "zhugl3@xiaopeng.com",
        "time": "Fri Sep 11 10:17:33 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 18:58:45 2026 -0700"
      },
      "message": "net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value\n\nmhi_mbim_rx() ignores the return value of skb_copy_bits() when it\ncopies each datagram out of the NTB.  The datagram offset and length\ncome from the DPE, which is only checked to lie within the NTB\nitself, so a modem can point a datagram outside the received skb.\nThe copy then fails and the freshly allocated skbn is passed to\nnetif_rx() with its uninitialized contents still in place, leaking\nkernel heap memory into the network stack.\n\nFree the skb and account an error when the copy fails.\n\nFixes: aa730a9905b7 (\"net: wwan: Add MHI MBIM network driver\")\nCc: stable@vger.kernel.org\nSuggested-by: Loic Poulain \u003cloic.poulain@oss.qualcomm.com\u003e\nSigned-off-by: Guanglei Zhu \u003czhugl3@xiaopeng.com\u003e\n\nVerified in a QEMU guest with a fault injector pointing a DPE\noutside the received NTB: the copy fails, and the unpatched driver\nhands the uninitialized skbn to the network stack (observed as\n\"unknown protocol\" on bytes that were never written).  With this\ncheck the failed datagram is dropped and counted as an rx error.\n\nChanges in v2: factor the free-and-count sequence out into\nmhi_mbim_rx_drop(), shared with the unknown-protocol path, as\nsuggested by Loic Poulain.\n\nLink: https://patch.msgid.link/20260911021734.1396599-2-zhugl3@xiaopeng.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5d063822ac5184939c1ed377a339a01d8ae814e8",
      "tree": "dc1e4b225ebf452ca0e1df1851c763a099fed31a",
      "parents": [
        "1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e"
      ],
      "author": {
        "name": "Guanglei Zhu",
        "email": "zhugl3@xiaopeng.com",
        "time": "Fri Sep 11 10:17:32 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 18:58:45 2026 -0700"
      },
      "message": "net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain\n\nThe NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is\nzero.  Nothing requires the offsets to advance, so a modem that\npoints an NDP at itself, or at an earlier NDP, keeps the loop\nspinning forever on one CPU.\n\nBreak out when the next NDP offset is not larger than the current\none.\n\nFixes: aa730a9905b7 (\"net: wwan: Add MHI MBIM network driver\")\nCc: stable@vger.kernel.org\nSuggested-by: Loic Poulain \u003cloic.poulain@oss.qualcomm.com\u003e\nSigned-off-by: Guanglei Zhu \u003czhugl3@xiaopeng.com\u003e\n\nVerified in a QEMU guest with a fault injector feeding the driver\u0027s\nreceive callback an NTB whose single NDP points at itself: the\nunpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%\nand the thread never returns.  With this check the loop terminates\nwithin one iteration.\n\nChanges in v2: move the non-increasing check to the wNextNdpIndex\nretrieval site, as suggested by Loic Poulain, instead of tracking\nthe previous offset in a separate variable.\n\nLink: https://patch.msgid.link/20260911021734.1396599-1-zhugl3@xiaopeng.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e",
      "tree": "847466aa49afd77852fc130f4552a1a063793cc7",
      "parents": [
        "9ed55f3dbef4f4adfe65eb03b0c35c53229a8490"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Mon Sep 14 23:26:41 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:44:40 2026 -0700"
      },
      "message": "net: ethernet: cortina: Ack RX overrun interrupt correctly\n\nThe RX overrun interrupt is reported in interrupt status register 4, but\ngmac_irq() acknowledges it using the RX descriptor error bit from status\nregister 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1\nthe shift leaves no bit in the 32-bit register.\n\nAcknowledge the same per-port RX overrun bit that was detected.\n\nFixes: 4d5ae32f5e1e (\"net: ethernet: Add a driver for Gemini gigabit ethernet\")\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260914-b4-gemini-ethernet-fixes-2-v2-1-5ab39a047b90@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9ed55f3dbef4f4adfe65eb03b0c35c53229a8490",
      "tree": "5abd684d4d5ac2ca313f03418ea785f002abc211",
      "parents": [
        "490599ab23134962a6d18a024e84541d77bdb999"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Sep 15 04:30:54 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:34:56 2026 -0700"
      },
      "message": "net: lock the socket in sock_gettstamp()\n\nsk-\u003esk_flags must only be changed while holding the socket lock,\nbecause sock_set_flag() and sock_reset_flag() use non atomic\noperations (__set_bit() and __clear_bit()).\n\nsock_gettstamp() is one of the last places where a bit of sk-\u003esk_flags\nis changed from a syscall without owning the socket lock, through\nsock_enable_timestamp(sk, SOCK_TIMESTAMP).\n\nsk_set_memalloc() and sk_clear_memalloc() also change sk-\u003esk_flags\nwithout the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,\nsunrpc, wireguard) need a careful audit, this will be addressed in a\nseparate patch.\n\nJungwoo Lee and Wongi Lee reported an UDP socket use-after-free\ncaused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()\ncan cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,\nbecause both threads perform a read-modify-write on the same word.\n\n  CPU 0 (bind)                        CPU 1 (SIOCGSTAMPNS_NEW)\n  --------------------------------    ----------------------------\n  read sk_flags \u003d F                   read sk_flags \u003d F\n  compute F | BIT(SOCK_RCU_FREE)      compute F | BIT(SOCK_TIMESTAMP)\n  store F | BIT(SOCK_RCU_FREE)\n  sk_add_node_rcu(sk, ...)\n                                      store F | BIT(SOCK_TIMESTAMP)\n\nAfter the lost update, SOCK_RCU_FREE is clear while the socket is\nvisible to lockless UDP receive lookups. sk_destruct() then frees\nthe socket immediately instead of waiting for a RCU grace period,\nwhile the receive path still holds a reference-less pointer to it:\n\n BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410\n Read of size 8 at addr ffff888008806610 by task exploit/207\n CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1\n  ipv4_pktinfo_prepare+0x30/0x410\n  udp_queue_rcv_one_skb+0x51c/0x1180\n  udp_unicast_rcv_skb+0x109/0x350\n  ip_protocol_deliver_rcu+0x14b/0x310\n  ip_local_deliver_finish+0x29d/0x390\n  ip_local_deliver+0x24d/0x2a0\n\nOnly grab the socket lock when SOCK_TIMESTAMP has to be set,\nto keep the common case lockless.\n\nFixes: 1da177e4c3f4 (\"Linux-2.6.12-rc2\")\nReported-by: Jungwoo Lee \u003cjwlee2217@gmail.com\u003e\nReported-by: Wongi Lee \u003cqw3rtyp0@gmail.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "490599ab23134962a6d18a024e84541d77bdb999",
      "tree": "48122edd4e0f470ecaf9d9d1a1fe46023aadd0e3",
      "parents": [
        "5ae916fabca141b79b32e2e57f3c915c0f1e1b2e"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Mon Sep 14 19:23:27 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:33:06 2026 -0700"
      },
      "message": "eth: fbnic: ring the doorbell if a burst ends in a drop\n\nfbnic_tx_map() skips the doorbell write, and the completion request,\nfor every packet handed to it with xmit_more set, counting on the\npacket which ends the burst to publish them all. When that packet is\ndropped instead - skb_put_padto(), skb_cow_head() or a DMA mapping\nfailure - nothing rings. The descriptors of the preceding packets stay\ninvisible to the HW until the next transmit on that queue, which for a\nburst-then-idle workload may never come.\n\nRemember the meta descriptor of the last packet left without a doorbell\nand flush it from the error paths. The completion request has to be set\non that descriptor rather than simply writing the tail, otherwise the HW\nwould transmit the packets but never report a head, and the ring would\nfill up and stall for good.\n\nThis is very similar to Joe\u0027s recent series of fixes for bnxt.\nNot seen in real life, reproduced under QEMU with failure injection.\n\nFixes: 9a57bacd574b (\"eth: fbnic: Add basic Tx handling\")\nReviewed-by: Alexander Duyck \u003calexanderduyck@fb.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260915022327.913218-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5ae916fabca141b79b32e2e57f3c915c0f1e1b2e",
      "tree": "01a097b8505d85f37b10961979429e526053d28c",
      "parents": [
        "150dba2c69e93302af24a0c868eebe4871e2e107"
      ],
      "author": {
        "name": "Yige Jiang",
        "email": "yigejiang86@gmail.com",
        "time": "Sun Sep 13 14:41:02 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:32:15 2026 -0700"
      },
      "message": "net: netsec: fix device_node reference leak on phy_np\n\nnetsec_of_probe() takes a reference on the PHY device_node with\nof_parse_phandle() and stores it in priv-\u003ephy_np, but the driver never\ndrops it.  One device_node reference is leaked per probe, on the success\npath as well as on every error path reached after netsec_of_probe().\n\nNeither consumer takes ownership.  of_mdio_parse_addr() is a static\ninline taking a const struct device_node * that only reads the \"reg\"\nproperty.  of_phy_connect() borrows as well: of_phy_get_and_connect() in\ndrivers/net/mdio/of_mdio.c brackets its own call with of_node_get() at\n:364 and of_node_put() at :373, which would be a double put if\nof_phy_connect() consumed the reference.\n\nThe node is still in use at netsec_netdev_open() time, where it is\npassed to of_phy_connect(), so it has device lifetime.  Release it at\nthe probe error label, which every failure path after the acquire\nfunnels through, and in netsec_remove().  Both releases precede\nfree_netdev(), since priv is netdev_priv(ndev).  The ACPI probe path\nleaves priv-\u003ephy_np NULL and of_node_put(NULL) is a no-op.\n\nThere is no end-user visible symptom on currently supported platforms:\na device_node is only freed once OF_DYNAMIC is enabled and the node has\nbeen detached, so on a static device tree the imbalance is inert.  It is\nobservable as a refcount that grows across bind/unbind cycles, and would\nmatter under device tree overlays.\n\nFound by static analysis of reference acquire/release pairing rather\nthan from a runtime report.  No reproducer was produced and the change\nhas not been runtime tested; it is compile-tested only (arm64,\nCONFIG_SNI_NETSEC\u003dm via COMPILE_TEST).\n\nFixes: 533dd11a12f6 (\"net: socionext: Add Synquacer NetSec driver\")\nSigned-off-by: Yige Jiang \u003cyigejiang86@gmail.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260913064102.37452-1-yigejiang86@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "150dba2c69e93302af24a0c868eebe4871e2e107",
      "tree": "63edd38ac7e786d73401e68ae890bd51ab058395",
      "parents": [
        "37213e61120297920ae4c937fcb326a360da5084"
      ],
      "author": {
        "name": "Farhad Alemi",
        "email": "farhad.alemi@berkeley.edu",
        "time": "Sat Sep 12 07:40:09 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:30:23 2026 -0700"
      },
      "message": "net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check\n\nipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the\nroute to the tunnel\u0027s remote endpoint and set ctx-\u003edev to its device,\nwhich is the tunnel itself when that route resolves back to the tunnel.\ndev_fill_forward_path() then makes no progress and trips\nWARN_ON_ONCE(last_dev \u003d\u003d ctx-\u003edev) as soon as a flowtable tries to\noffload a flow through the tunnel. That routing loop is a configuration\nany CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and\nip6_tnl_xmit() already treat it as a tx error, so remove the warning and\njust fail the walk, as commit 008e7a7c293b (\"net: remove WARN_ON_ONCE\nwhen accessing forward path array\") did for the path stack overflow.\n\nFixes: ab427db17885 (\"netfilter: flowtable: Add IPIP rx sw acceleration\")\nFixes: d98103575dcd (\"netfilter: flowtable: Add IP6IP6 rx sw acceleration\")\nCloses: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/\nSuggested-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\nSigned-off-by: Farhad Alemi \u003cfarhad.alemi@berkeley.edu\u003e\nReviewed-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "37213e61120297920ae4c937fcb326a360da5084",
      "tree": "3efe062c0655d0528447eba053a4c354b16baf39",
      "parents": [
        "60404266ef3e0a1cd8f7a164060e0c83efb72f4b"
      ],
      "author": {
        "name": "Mark Amirkan",
        "email": "markdamirkan@gmail.com",
        "time": "Sun Sep 13 10:31:08 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:29:11 2026 -0700"
      },
      "message": "net/packet: avoid truncating TPACKET_V3 private size\n\ntpacket_req3.tp_sizeof_priv is an unsigned int, and packet_set_ring()\nvalidates the full value against the block size.  init_prb_bdqc() then\nstores it in the unsigned short blk_sizeof_priv field.\n\nCommit 2b6867c2ce76 (\"net/packet: fix overflow in check for priv area\nsize\") fixed the validation arithmetic, but an accepted value above\nUSHRT_MAX still narrows when it is stored.\n\nFor a 131072-byte block, tp_sizeof_priv\u003d65536 is valid.  The narrowing\nmakes offset_to_first_pkt 48 instead of 65584, so packet records can be\nplaced in the private area that userspace asked the kernel to preserve.\n\nblk_sizeof_priv is internal state, so widen it to hold the validated\nUAPI value.\n\nFixes: f6fb8f100b80 (\"af-packet: TPACKET_V3 flexible buffer implementation.\")\nCc: stable@vger.kernel.org\nSigned-off-by: Mark Amirkan \u003cmarkdamirkan@gmail.com\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260913-b4-send-packet-private-v1-1-925eab2cd388@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "60404266ef3e0a1cd8f7a164060e0c83efb72f4b",
      "tree": "763559180bd2da2ba3c93ffd0ce6d5716b512aa4",
      "parents": [
        "33ff111d7ba3beb86e28938d6382bb5beabd865a"
      ],
      "author": {
        "name": "Mark Amirkan",
        "email": "markdamirkan@gmail.com",
        "time": "Sun Sep 13 10:30:05 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:28:06 2026 -0700"
      },
      "message": "mptcp: return sk_wait_data() errors from recvmsg()\n\nCommit 581302298524 (\"mptcp: error out earlier on disconnect\") made\nmptcp_recvmsg() stop when sk_wait_data() returns an error.  The error is\nstored in err, but the function then jumps to a path which returns\ncopied.  When no data was copied, recvmsg() therefore returns zero and\nreports a false EOF.\n\nStore the result in copied, which is the value returned by the function.\nThis also keeps the usual partial-read result when data was copied before\nthe error.\n\nA recvmsg() blocked in one thread reproduces the issue when another\nthread disconnects the same MPTCP socket with connect(AF_UNSPEC).\nBefore this change recvmsg() returns zero; afterwards it returns -EPIPE.\n\nFixes: 581302298524 (\"mptcp: error out earlier on disconnect\")\nCc: stable@vger.kernel.org\nSigned-off-by: Mark Amirkan \u003cmarkdamirkan@gmail.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260913-b4-send-mptcp-recv-error-v1-1-4eaa3684a8b8@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "33ff111d7ba3beb86e28938d6382bb5beabd865a",
      "tree": "342556a876bed47596f98fbf9ee0a4ec3045a2ca",
      "parents": [
        "a9ce4053dc945c5372dedba5017ee675b30dc0c5"
      ],
      "author": {
        "name": "Mark Amirkan",
        "email": "markdamirkan@gmail.com",
        "time": "Sun Sep 13 10:28:08 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:27:35 2026 -0700"
      },
      "message": "net/packet: clear RX owner on VNET header error\n\nCommit 61fad6816fc1 (\"net/packet: tpacket_rcv: avoid a producer race\ncondition\") added rx_owner_map and made tpacket_rcv() claim a V1 or V2\nring slot before converting the virtio-net header.  If the conversion\nfails, the drop path leaves the slot claimed.\n\nWith a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves\nthe only slot unavailable, so the ring also drops the next valid packet.\n\nClear the ownership bit on this error path.  TPACKET_V3 already clears\nits block state here.\n\nFixes: 61fad6816fc1 (\"net/packet: tpacket_rcv: avoid a producer race condition\")\nCc: stable@vger.kernel.org\nSigned-off-by: Mark Amirkan \u003cmarkdamirkan@gmail.com\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260913-b4-send-packet-vnet-v1-1-5545ffb528ae@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a9ce4053dc945c5372dedba5017ee675b30dc0c5",
      "tree": "fc018e933608c0e7689f4aabfd134b99060fcfab",
      "parents": [
        "f6fb2ac5e19ae4b66112a698050db80e51f841c3"
      ],
      "author": {
        "name": "Mark Amirkan",
        "email": "markdamirkan@gmail.com",
        "time": "Sun Sep 13 17:14:09 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:26:40 2026 -0700"
      },
      "message": "net: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb\u0027s frag_list.  On the last descriptor, lan743x_rx_trim_skb()\nlinearizes the head and frees the fragment skb metadata.\n\nThe checksum-success path then writes ip_summed through the local skb\npointer, which still points to the final fragment.  This causes a\nuse-after-free write when a packet spans more than one receive buffer.\n\nSet ip_summed on the surviving head skb instead.  Multi-buffer receive\ncan occur after a live MTU increase because existing ring entries keep\ntheir old buffer size until they are replenished.\n\nA KUnit test invoking lan743x_rx_process_buffer() with a two-buffer\npacket produced a one-byte KASAN use-after-free write before this change.\nThe same test passed after the change.  The driver object also builds\nwith W\u003d1.  This was not tested on physical LAN743x hardware.\n\nFixes: cd6910501cfd (\"net: lan743x: Add support for Rx IP \u0026 TCP checksum offload\")\nCc: stable@vger.kernel.org\nSigned-off-by: Mark Amirkan \u003cmarkdamirkan@gmail.com\u003e\nReviewed-by: Chenguang Zhao \u003czhaochenguang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260913-b4-send-lan743x-uaf-v1-1-73d563d08ba9@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f6fb2ac5e19ae4b66112a698050db80e51f841c3",
      "tree": "8a3f252868296ab450688f151a6ef5fb091fc6c6",
      "parents": [
        "7f4a5ec6258fd7c92633ec4b0493fc51166d9398"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Sat Sep 12 14:08:31 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:15:29 2026 -0700"
      },
      "message": "selftests/tc-testing: add codel/fq_codel interval boundary cases\n\nAdd tdc cases locking the codel/fq_codel small-interval uAPI after\nthe dropping-loop bound (previous patch): sub-tick and two-tick\nintervals are ACCEPTED (the loop bound makes them safe), the\n1024us boundary is accepted, and a sub-tick target sojourn delay is\naccepted (it does not participate in the control law):\n\n  codel:     6e44/a8c3/a695/9793 - interval 1us/3us/1024us and\n             target 1us accepted (rendered 0us/2us/1.02ms/0us by tc)\n  fq_codel:  1b4d/3540/49c5/3e0f - interval 1us/3us/1024us and\n             target 1us accepted\n\nThe positive cases match the full rendered qdisc line (tc renders\ninterval 1us as 0us, 3us as 2us, 1024us as 1.02ms), mirroring the\nexisting tests in these files.\n\nThese cases do not test the dropping-loop bound itself: tdc cannot\nobserve per-dequeue drop counts. c797 (fq_codel target 1 interval 1)\npasses unmodified on the patched kernel, which is the uAPI evidence\nfor the previous patch.\n\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nLink: https://patch.msgid.link/QDISC-1L5H.v1.20260912080102@mojatatu.com.2\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "7f4a5ec6258fd7c92633ec4b0493fc51166d9398",
      "tree": "52a0b76cbaeddf0ba5c57a62d90177c4dc4d4335",
      "parents": [
        "fefaac1176bf3cf002a8dc83339d6ed6a369941a"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Sat Sep 12 14:08:30 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 17:15:29 2026 -0700"
      },
      "message": "net/sched: codel: bound the dropping loop per dequeue call\n\nThe CoDel control law schedules the next drop one interval/sqrt(count)\nafter the previous drop, using the configured interval\n(codel_params.interval). For very small intervals the scheduled step\nrounds down to zero, so the dropping loop in codel_dequeue() never\nadvances and drains the entire backlog under the qdisc lock in one\ncall - an unprivileged user can trigger a soft lockup this way.\n\nFix in the shared codel code used by both codel and fq_codel:\n\n1. Make the control-law step at least 1 tick so the dropping loop\n   always moves forward.\n\n2. Cap the dropping loop at CODEL_MAX_DROPS_PER_DEQUEUE (256) drops\n   per codel_dequeue() call, resyncing drop_next to now when the cap\n   is hit: the catch-up owed to the loop grows with the idle gap and\n   the backlog, which no interval threshold can bound. This is a\n   deliberate behaviour change after long idle gaps.\n\nThe cap applies to fq_codel (4b549a2ef4be) and the mac80211 TXQ path\n(fixed interval, cap only).\n\nThe target sojourn delay (codel_params.target) is not validated: it\ndoes not feed the control law, so a sub-tick value is aggressive\nrather than deadlock-prone.\n\nConditions to recreate the bug:\n  - tc qdisc add dev lo root handle 1: tbf rate 1kbit burst 2kb limit 1000000\n  - tc qdisc add dev lo parent 1:1 handle 10: codel interval 2us target 1ms noecn limit 1000000 (same for fq_codel)\n  - unpatched kernel: tc accepts it; a UDP flood under the 1kbit tbf\n    soft-lockups (watchdog: BUG: soft lockup) while one\n    codel_dequeue() call drops the backlog under the qdisc lock\n  - patched kernel: same setup, at most 256 drops per dequeue call,\n    no soft lockup\n\nTesting: claim reproducer and interval 2us/3us variants run clean;\ntdc qdisc category passes (see the selftests patch).\n\nFixes: 76e3cc126bb2 (\"codel: Controlled Delay AQM\")\nReported-by: Vega \u003cvega@nebusec.ai\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nTested-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nReviewed-by: Toke Høiland-Jørgensen \u003ctoke@toke.dk\u003e\nLink: https://patch.msgid.link/QDISC-1L5H.v1.20260912080102@mojatatu.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "fefaac1176bf3cf002a8dc83339d6ed6a369941a",
      "tree": "ab8893c9e199bb9f981ab9fbc8840a3c5a6d28b5",
      "parents": [
        "7c7d5e9d7e3942ba5aec9847f61a6e76d7773191",
        "1eeca1d5e0920fbdad6449768fd2d4364e714180"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 15:54:55 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 15:54:56 2026 -0700"
      },
      "message": "Merge tag \u0027wireless-2026-09-16\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless\n\nJohannes Berg says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nMany fixes:\n - mac80211: S1G TIM bitmap fix\n - ath12k: remove undocumented DT ABI implementation\n - various firmware API and over-the-air hardening changes\n - fixes for most cfg80211/mac80211 syzbot reports\n\n* tag \u0027wireless-2026-09-16\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless: (67 commits)\n  wifi: brcmsmac: fix UAF in brcms_free_timer()\n  wifi: brcmfmac: fix lost 802.1x TX completion wakeup\n  wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()\n  wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown\n  wifi: ath12k: ahb: Revert undocumented ABI and dead code\n  wifi: mac80211: refuse to make a monitor active when it has no queue\n  wifi: libipw: reject TKIP frames without a full MIC\n  wifi: virt_wifi: don\u0027t transfer operstate before register\n  wifi: cfg80211: check if AP has been started or joined a mesh before adding new station\n  wifi: cfg80211: move link_id validation earlier in nl80211_new_station()\n  wifi: cfg80211: do not support direct add of station to AP_VLAN interfaces\n  wifi: cfg80211: verify if AP_VLAN belongs to the correct AP\n  wifi: mac80211: set up the TX info early to fix failure paths\n  wifi: mac80211: mesh: release the channel if start fails\n  wifi: mac80211: mesh: reset the CSA state when leaving\n  wifi: mac80211: add HE 6 GHz capability in the scan elems len\n  wifi: mac80211: don\u0027t access the TSF of a down interface\n  wifi: mac80211: don\u0027t RCU-dereference the mesh CSA settings we just set\n  wifi: mac80211: don\u0027t allow link changes when iface is down\n  wifi: mac80211: require a peer station for TDLS setup confirm\n  ...\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260916083642.110609-3-johannes@sipsolutions.net\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "7c7d5e9d7e3942ba5aec9847f61a6e76d7773191",
      "tree": "9ee39b8e1c9e91cd37d5e84778cd1cb1fe19ca71",
      "parents": [
        "ceac0de741bfb47ca255eee075257b3bb31f0651",
        "96f01b53c2d05e003b040892256de54a586e8529"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 15:54:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Sep 16 15:54:19 2026 -0700"
      },
      "message": "Merge tag \u0027ipsec-2026-09-16\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec\n\nSteffen Klassert says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\npull request (net): ipsec 2026-09-16\n\n1) xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()\n   Add the up-front nr_frags guard iptfs_skb_add_frags() already has,\n   so an out-of-range offset can\u0027t walk past the on-stack frags[] array.\n\n2) xfrm: serialize state GC with device state flush\n   Serialize xfrm_state destruction against the deferred-device pass\n   with a dedicated mutex, since the device GC list doesn\u0027t hold a state\n   reference and the two paths could free the same state.\n\n3) xfrm: add missing RCU read lock in xfrm_send_migrate_state()\n   Hold the RCU read lock around xfrm_nlmsg_multicast() so the\n   rcu_dereference() of net-\u003exfrm.nlsk doesn\u0027t warn.\n\n4) xfrm: iptfs: fix runt reassembly panic from short inner tot_len\n   Require the runt length to cover at least the minimum IP header,\n   so a tot_len in [6, 19] (IPv4) can\u0027t write past the declared length\n   and trip skb_over_panic().\n\n5) ipv6: xfrm: use full sockets in local error paths\n   Use skb_to_full_sk() in xfrm6_local_rxpmtu() and xfrm6_local_error()\n   and bail out without a full socket, so a TCP_NEW_SYN_RECV request_sock\n   isn\u0027t miscast as a full inet/IPv6 socket.\n\n6) xfrm: fix compat ALLOCSPI request use-after-free\n   Drop the redundant alloc_compat() in xfrm_alloc_userspi() so the\n   compat translator no longer reads past the payload and publishes a\n   child a multicast clone can still see after xfrm_user_rcv_msg() frees.\n\n7) xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n   Force the dst before queuing, hold dev across the workqueue deferral,\n   and take rcu_read_lock() around the finish() loop, so transport-mode\n   reinjection doesn\u0027t deref non-refcounted dst/dev under workqueue.\n\n8) xfrm: use hlist_del_init_rcu for state_cache and state_cache_input\n   Switch to hlist_del_init_rcu() so a second __xfrm_state_delete() is\n   a no-op instead of writing through LIST_POISON2, closing the UAFs.\n\n9) esp: downgrade zerocopy managed frags before mutating skb frags\n   Call skb_zcopy_downgrade_managed() before ESP rewrites the skb frag\n   array, so per-frag unrefs in esp_ssg_unref() and skb_release_data()\n   stay balanced for ubuf-owned managed frags.\n\n10) xfrm: hold net_device reference under RCU in bundle creation\n    Read dst-\u003edev via dst_dev_rcu() and keep RCU active through\n    xfrm_fill_dst(), so a concurrent RTM_DELLINK can\u0027t free dev\n    under bundle creation.\n\n11) xfrm: save input state data before secpath resets\n    Save the state protocol on the stack while it\u0027s still valid and\n    use the saved address family for transport_finish(), so post-reset\n    dereferences (VTI, XFRM if, MAX_DEPTH error) can\u0027t UAF the state.\n\n12) net: xfrm: reject unrepresentable espintcp transport headers\n    Use the careful transport-header helper and drop the skb through\n    the XFRM error path when the offset can\u0027t be represented, instead\n    of silently truncating it.\n\n* tag \u0027ipsec-2026-09-16\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec:\n  net: xfrm: reject unrepresentable espintcp transport headers\n  xfrm: save input state data before secpath resets\n  xfrm: hold net_device reference under RCU in bundle creation\n  esp: downgrade zerocopy managed frags before mutating skb frags\n  xfrm: use hlist_del_init_rcu for state_cache and state_cache_input\n  xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n  xfrm: fix compat ALLOCSPI request use-after-free\n  ipv6: xfrm: use full sockets in local error paths\n  xfrm: iptfs: fix runt reassembly panic from short inner tot_len\n  xfrm: add missing RCU read lock in xfrm_send_migrate_state()\n  xfrm: serialize state GC with device state flush\n  xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260916101938.118628-1-steffen.klassert@secunet.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "940e8fe8535d22ce67dd2fb9588e6c55a31d7d03",
      "tree": "c8cf4fa8d07d573dae55e04781793d348c6fdfb9",
      "parents": [
        "fa899ba9b1bfa0481a477c7a05a1a5d484285e7f",
        "76a8fe25b97881223976363044924d5cf0511749"
      ],
      "author": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:09:57 2026 +0100"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:09:57 2026 +0100"
      },
      "message": "ASoC: adau1977: small fixes to make the driver more usable\n\nAlvin Šipraga \u003calvin.sipraga@analog.com\u003e says:\n\nHere\u0027s a few fixes I encountered were needed in order to use this driver\nas a module together with the simple audio card.\n\nLink: https://patch.msgid.link/20260914-asoc-adau1977-fixes-v1-0-aa2f0cabd728@analog.com\n"
    },
    {
      "commit": "76a8fe25b97881223976363044924d5cf0511749",
      "tree": "23fb8c17c173b0b879f8ff93fd3962e276e67e35",
      "parents": [
        "528a0da3e55b24d1113b3658e94cf432e0020913"
      ],
      "author": {
        "name": "Alvin Šipraga",
        "email": "alvin.sipraga@analog.com",
        "time": "Mon Sep 14 12:12:37 2026 +0200"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:09:56 2026 +0100"
      },
      "message": "ASoC: adau1977-i2c: add OF match table for I2C\n\nLike for SPI, the I2C driver needs an OF match table for the kernel to\nbe able to automatically load the driver when built as a module. Add\none.\n\nSigned-off-by: Alvin Šipraga \u003calvin.sipraga@analog.com\u003e\nReviewed-by: Nuno Sá \u003cnuno.sa@analog.com\u003e\nLink: https://patch.msgid.link/20260914-asoc-adau1977-fixes-v1-3-aa2f0cabd728@analog.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "528a0da3e55b24d1113b3658e94cf432e0020913",
      "tree": "9ef146ea3e132437b64b5d81580213d0367894cd",
      "parents": [
        "0030f62683d5061d43b80577b7ab27196f1adb4c"
      ],
      "author": {
        "name": "Alvin Šipraga",
        "email": "alvin.sipraga@analog.com",
        "time": "Mon Sep 14 12:12:36 2026 +0200"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:09:55 2026 +0100"
      },
      "message": "ASoC: adau1977-spi: drop __maybe_unused and of_match_ptr()\n\nSince commit 5ab23c7923a1 (\"modpost: Create modalias for builtin\nmodules\") MODULE_DEVICE_TABLE() is enough to reference a match table and\nthe data isn\u0027t discarded by the linker even when the driver is built-in\nand CONFIG_OF is disabled. Drop the of_match_ptr() wrapping so that OF\nmatching keeps working regardless of CONFIG_OF. This also means we can\ndrop __maybe_unused since it\u0027s always used.\n\nThe entries in adau1977_spi_of_match were also erroneously indented with\nspaces - replace the indentation with tabs to conform with coding style.\n\nSigned-off-by: Alvin Šipraga \u003calvin.sipraga@analog.com\u003e\nReviewed-by: Nuno Sá \u003cnuno.sa@analog.com\u003e\nLink: https://patch.msgid.link/20260914-asoc-adau1977-fixes-v1-2-aa2f0cabd728@analog.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "0030f62683d5061d43b80577b7ab27196f1adb4c",
      "tree": "59fe9edda4830ed250313f4ee84160794896d163",
      "parents": [
        "fd73f4a6659897191fa0d40695fe370925dd3780"
      ],
      "author": {
        "name": "Alvin Šipraga",
        "email": "alvin.sipraga@analog.com",
        "time": "Mon Sep 14 12:12:35 2026 +0200"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:09:54 2026 +0100"
      },
      "message": "ASoC: adau1977: make the Kconfig symbols user selectable\n\nSND_SOC_ADAU1977_{SPI,I2C} are missing Kconfig text, so they don\u0027t show\nup in menuconfig and can\u0027t be selected by a user - only by another\nsymbol such as a machine driver. Add the text to make these symbols\nselectable and usable with generic machine drivers like the simple audio\ncard.\n\nSigned-off-by: Alvin Šipraga \u003calvin.sipraga@analog.com\u003e\nReviewed-by: Nuno Sá \u003cnuno.sa@analog.com\u003e\nLink: https://patch.msgid.link/20260914-asoc-adau1977-fixes-v1-1-aa2f0cabd728@analog.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "fa899ba9b1bfa0481a477c7a05a1a5d484285e7f",
      "tree": "af07c26b0b3c084d4af35aa197188dabbd1052db",
      "parents": [
        "3482062c786ce4233f8ed3224d824184f53ec154",
        "d57616f8be5601d210bbb0f677b9cb88a5186c3c"
      ],
      "author": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:20 2026 +0100"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:20 2026 +0100"
      },
      "message": "ASoC: amd: acp: SoundWire machine driver fixes\n\nVijendar Mukunda \u003cVijendar.Mukunda@amd.com\u003e says:\n\nThis series fixes four defects in the AMD ACP SoundWire machine drivers\n(acp-sdw-legacy-mach.c and acp-sdw-sof-mach.c).\n\nA bounds check is added to validate the SoundWire link ID before it is\nused as an array index in create_sdw_dailink(), preventing out-of-bounds\naccess when an unexpected link_mask value is encountered. The codec\nconfig count in the SOF machine driver is refactored to use a dedicated\nvariable rather than reusing the endpoint-count variable for two\npurposes, making the intent clearer and avoiding a stale value being\npassed to the codec config array. An operator-precedence bug in the\nffs(link_mask - 1) expression is corrected to ffs(link_mask) - 1,\nensuring the link ID is derived from the correct bit position. Finally,\nthe SOF machine driver card name is shortened to fit within the 16-byte\nsnd_card driver[] field and eliminate a compile-time warning.\n\nLink: https://patch.msgid.link/20260910161728.1452808-1-Vijendar.Mukunda@amd.com\n"
    },
    {
      "commit": "d57616f8be5601d210bbb0f677b9cb88a5186c3c",
      "tree": "6b2a7fd863739180b570801c575c54215608b26a",
      "parents": [
        "27098aaf28b96ab4e6891709062c343566d4882b"
      ],
      "author": {
        "name": "Vijendar Mukunda",
        "email": "Vijendar.Mukunda@amd.com",
        "time": "Thu Sep 10 21:46:49 2026 +0530"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:19 2026 +0100"
      },
      "message": "ASoC: amd: acp: fix card name length warning in SOF SoundWire machine driver\n\nThe ALSA snd_card driver[] field is 16 bytes (including the NUL\nterminator), leaving 15 usable characters. The SOF framework\nprepends a \"sof-\" prefix when registering the card, so\ncard-\u003ename \u003d \"amd-soundwire\" becomes driver name \"sof-amd-soundwire\"\nwhich is 17 characters and overflows the driver[16] buffer, triggering\na kernel warning.\n\nFix by shortening the card name to \"amd-sdw\"; the resulting driver\nname \"sof-amd-sdw\" fits within the 15-character limit.\n\nSigned-off-by: Vijendar Mukunda \u003cVijendar.Mukunda@amd.com\u003e\nReviewed-by: Mario Limonciello (AMD) \u003csuperm1@kernel.org\u003e\nLink: https://patch.msgid.link/20260910161728.1452808-5-Vijendar.Mukunda@amd.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "27098aaf28b96ab4e6891709062c343566d4882b",
      "tree": "a0542c1074ea36f6634ebb6c62caeb974a66b1e0",
      "parents": [
        "0b7d55d3a91200f2b1ed710f525a944b0a7d6369"
      ],
      "author": {
        "name": "Vijendar Mukunda",
        "email": "Vijendar.Mukunda@amd.com",
        "time": "Thu Sep 10 21:46:48 2026 +0530"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:18 2026 +0100"
      },
      "message": "ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID\n\nffs(link_mask - 1) computes ffs on (link_mask - 1) instead of\nsubtracting 1 from the result of ffs(link_mask). For a typical\npower-of-2 link_mask this returns the wrong link ID, causing cpu_pin_id\nlookup to select the incorrect SoundWire manager.\n\nFix the operator precedence to ffs(link_mask) - 1 in both\nacp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.\n\nFixes: 6d8348ddc56e (\"ASoC: amd: acp: refactor SoundWire machine driver code\")\nSigned-off-by: Vijendar Mukunda \u003cVijendar.Mukunda@amd.com\u003e\nReviewed-by: Mario Limonciello (AMD) \u003csuperm1@kernel.org\u003e\nLink: https://patch.msgid.link/20260910161728.1452808-4-Vijendar.Mukunda@amd.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "0b7d55d3a91200f2b1ed710f525a944b0a7d6369",
      "tree": "32b6e02076a9068875cb111fa45d222faa9aaedc",
      "parents": [
        "29218a4d11a31a8157389bc2b9e62dd768d7ea42"
      ],
      "author": {
        "name": "Vijendar Mukunda",
        "email": "Vijendar.Mukunda@amd.com",
        "time": "Thu Sep 10 21:46:47 2026 +0530"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:17 2026 +0100"
      },
      "message": "ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver\n\nnum_devs was used both as the endpoint count and as the output for\nasoc_sdw_parse_sdw_endpoints(), which overwrites it with the codec\nconfiguration count. Introduce a separate num_confs variable to hold\nthe codec conf count so the two values remain distinct across\ncodec_conf allocation and card-\u003enum_configs assignment.\n\nFixes: 6d8348ddc56e (\"ASoC: amd: acp: refactor SoundWire machine driver code\")\nSigned-off-by: Vijendar Mukunda \u003cVijendar.Mukunda@amd.com\u003e\nReviewed-by: Mario Limonciello (AMD) \u003csuperm1@kernel.org\u003e\nLink: https://patch.msgid.link/20260910161728.1452808-3-Vijendar.Mukunda@amd.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "29218a4d11a31a8157389bc2b9e62dd768d7ea42",
      "tree": "07d249d8d954c89c54ec8248ec719ed266b3c67f",
      "parents": [
        "fd73f4a6659897191fa0d40695fe370925dd3780"
      ],
      "author": {
        "name": "Vijendar Mukunda",
        "email": "Vijendar.Mukunda@amd.com",
        "time": "Thu Sep 10 21:46:46 2026 +0530"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:08:16 2026 +0100"
      },
      "message": "ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers\n\nAdd a bounds check in create_sdw_dailink() to validate that the\nSoundWire link ID derived from link_mask does not exceed the maximum\nsupported by the platform. If the link ID is out of range or link_mask\nis zero, log an error and return -EINVAL to prevent accessing invalid\nCPU pin ID tables.\n\nApplied to both acp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.\n\nFixes: 6d8348ddc56e (\"ASoC: amd: acp: refactor SoundWire machine driver code\")\nSigned-off-by: Vijendar Mukunda \u003cVijendar.Mukunda@amd.com\u003e\nReviewed-by: Mario Limonciello (AMD) \u003csuperm1@kernel.org\u003e\nLink: https://patch.msgid.link/20260910161728.1452808-2-Vijendar.Mukunda@amd.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "3482062c786ce4233f8ed3224d824184f53ec154",
      "tree": "7ef50b2df8c4ddc9163e42cda57eda4dd055f786",
      "parents": [
        "03a5699a0a04309c597683967aaaf25d1e555ea2"
      ],
      "author": {
        "name": "Richard Fitzgerald",
        "email": "rf@opensource.cirrus.com",
        "time": "Mon Sep 14 13:26:11 2026 +0100"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:07:19 2026 +0100"
      },
      "message": "ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length\n\nIn cs_amp_alloc_get_efi_variable() the first call to\ncs_amp_get_efi_variable() might return EFI_SUCCESS if the variable\nexists with zero length. Trap this and return -ENOENT to prevent\nreturning an unexpected NULL pointer.\n\nThe first cs_amp_get_efi_variable() call was assumed to return\nEFI_BUFFER_TOO_SMALL if the variable existed, but if instead it\nreturned EFI_SUCCESS this would be converted to 0 by\ncs_amp_convert_efi_status() and then be returned as a NULL pointer.\n\nFixes: 00fd40bc7acec (\"ASoC: cs-amp-lib: Support Dell SSIDExV2 UEFI variable\")\nSigned-off-by: Richard Fitzgerald \u003crf@opensource.cirrus.com\u003e\nLink: https://patch.msgid.link/20260914122611.2783563-1-rf@opensource.cirrus.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "03a5699a0a04309c597683967aaaf25d1e555ea2",
      "tree": "fb50beceaed2c222c6f14f64ab122e138b1eb8e9",
      "parents": [
        "c17ae8c26eac16ad244daef44044d714f68a2ddc"
      ],
      "author": {
        "name": "Jiangshan Yi",
        "email": "yijiangshan@kylinos.cn",
        "time": "Mon Sep 14 18:47:12 2026 +0800"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:06:17 2026 +0100"
      },
      "message": "ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config-\u003etype\n\nstream_config is not initialized before being passed to\nsdw_stream_add_slave().  The type field may contain garbage and is\nlater copied to stream-\u003etype by sdw_config_stream().\n\nZero-initialize stream_config so type defaults to SDW_STREAM_PCM.\n\nWhile at it, use snd_sdw_params_to_config() helper instead of\nopen-coding the same logic.\n\nFixes: 63a511284c9e (\"ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology\")\nCc: stable@vger.kernel.org\nSigned-off-by: Jiangshan Yi \u003cyijiangshan@kylinos.cn\u003e\nReviewed-by: Pierre-Louis Bossart \u003cpierre-louis.bossart@linux.dev\u003e\nLink: https://patch.msgid.link/20260914104712.379574-1-yijiangshan@kylinos.cn\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "c17ae8c26eac16ad244daef44044d714f68a2ddc",
      "tree": "c18d223c6e071bac5c0ba6c307c52a1ff7c3e33b",
      "parents": [
        "11fc0048a6930f4fca44fe3bd16a0023e78846a2"
      ],
      "author": {
        "name": "HyeongJun An",
        "email": "sammiee5311@gmail.com",
        "time": "Tue Sep 15 18:25:15 2026 +0900"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:05:19 2026 +0100"
      },
      "message": "ASoC: hdmi-codec: Report a change when the channel status moves\n\nThe put() callback of \"IEC958 Playback Default\" stores all 24 channel\nstatus bytes and then returns 0. The core notifies userspace only on a\npositive return, so a write that changes what the get() callback hands\nback is never announced, and a mixer holding the control open keeps\nshowing the old value.\n\nCompare the stored bytes and return 1 when they move, the way\nsnd_hda_spdif_default_put() does.\n\nThe same shape is in img-spdif-out and uniperif_player.\n\nNo board with this codec was to hand. The change is a comparison of\ndriver state with no hardware behaviour in it, and mixer-test counts the\nmissing notification as event_missing.\n\nFixes: 7a8e1d44211e (\"ASoC: hdmi-codec: Add iec958 controls\")\nSigned-off-by: HyeongJun An \u003csammiee5311@gmail.com\u003e\nAssisted-by: Claude:claude-opus-5\nLink: https://patch.msgid.link/20260915092515.2638542-1-sammiee5311@gmail.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "11fc0048a6930f4fca44fe3bd16a0023e78846a2",
      "tree": "9714b8a6ec2364541f88a23141ed662714195be2",
      "parents": [
        "a5e22cba3549b3b9ca592a6bc62329c9b85ce285"
      ],
      "author": {
        "name": "Sasha Levin",
        "email": "sashal@kernel.org",
        "time": "Sun Sep 13 13:31:32 2026 -0400"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:04:26 2026 +0100"
      },
      "message": "ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments\n\narm allmodconfig fails to build with gcc:\n\n  In file included from sound/soc/ux500/ux500_msp_i2s.c:20:\n  sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses\n  around arithmetic in operand of \u0027^\u0027 [-Werror\u003dparentheses]\n  sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro\n  \u0027MSP_TX_CLKPOL_BIT\u0027\n  cc1: all warnings being treated as errors\n\nThe macros never parenthesized their argument:\n\n  #define MSP_TX_CLKPOL_BIT(n)  ((n \u0026 TCKPOL_MASK) \u003c\u003c TCKPOL_SHIFT)\n\nThat went unnoticed while every caller passed a plain variable, but\nconfigure_protocol() now passes an XOR expression, which binds as\n\"a ^ (b \u0026 MASK)\" rather than \"(a ^ b) \u0026 MASK\", and gcc rightly\ncomplains.\n\nNo functional change: tx_clk_pol and rx_clk_pol only ever hold\nMSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a\nbool, so masking before or after the XOR gives the same 0/1 result.\nParenthesize the argument anyway - it fixes the build and stops the\nmacros from silently mis-evaluating a future composite argument.\n\nFixes: 9ccbacf5a012 (\"ASoC: ux500: Validate MSP DAI configuration\")\nReported-by: kernel test robot \u003clkp@intel.com\u003e\nCloses: https://lore.kernel.org/oe-kbuild-all/202609051547.G9SJp8UQ-lkp@intel.com/\nAssisted-by: LLM\nSigned-off-by: Sasha Levin \u003csashal@kernel.org\u003e\nReviewed-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260913173132.1172003-1-sashal@kernel.org\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "a5e22cba3549b3b9ca592a6bc62329c9b85ce285",
      "tree": "134db56784273d300253af6e1b344532c62a8f13",
      "parents": [
        "576725ded009f09a28da19852f7edf62dbc5f94c"
      ],
      "author": {
        "name": "Oder Chiou",
        "email": "oder_chiou@realtek.com",
        "time": "Wed Sep 16 18:18:03 2026 +0800"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Sep 16 20:03:38 2026 +0100"
      },
      "message": "ASoC: rt721: Reset codec to fix abnormal sound\n\nThe audio output may become abnormal after a warm reboot from Windows.\nReset the codec once during hardware initialization to restore it to a\nknown state and prevent the issue.\n\nSigned-off-by: Oder Chiou \u003coder_chiou@realtek.com\u003e\nLink: https://patch.msgid.link/20260916101803.2301508-1-oder_chiou@realtek.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "238650ef6c7c7cca08e032527329424c9fbd70e5",
      "tree": "ada4d56578c713c59de798ed5b892f337afdf919",
      "parents": [
        "9b87fdc9af2fbfcdb5c24a64139685ef80f6573f",
        "0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Sep 16 09:29:25 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Sep 16 09:29:25 2026 -0700"
      },
      "message": "Merge tag \u0027powerpc-7.3-4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux\n\nPull powerpc fixes from Madhavan Srinivasan:\n \"KVM:\n    - fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n    - fix secure device page leak on uv_page_in() failure\n\n  iommu:\n    - Fix the overflow validation in iommu_tce_check_ioba\n\n  Thanks to Amit Machhiwal, Gautam Menghani, Ritesh Harjani (IBM), R\n  Nageswara Sastry, and Shivaprasad G Bhat\"\n\n* tag \u0027powerpc-7.3-4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux:\n  powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba\n  KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure\n  KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n"
    },
    {
      "commit": "0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71",
      "tree": "affdb13250d05eff52a66920b8040368647797a2",
      "parents": [
        "0a416ee20bcccddf91ca5b63696a23b9d11d73aa"
      ],
      "author": {
        "name": "Shivaprasad G Bhat",
        "email": "sbhat@linux.ibm.com",
        "time": "Tue Sep 15 22:04:17 2026 +0530"
      },
      "committer": {
        "name": "Madhavan Srinivasan",
        "email": "maddy@linux.ibm.com",
        "time": "Wed Sep 16 13:43:58 2026 +0530"
      },
      "message": "powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba\n\nThe commit b1af23d836f8 (\"KVM: PPC: iommu: Unify TCE checking\") unified\nIOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().\nWhile doing so, the passed in argument npages is ignored and constant\nvalue \u00271\u0027 is used leaving out a possible overflow as the callers can\nlegitimately be using npages \u003e 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT\ncases.\n\nFix this by accounting for \u0027npages\u0027, checking for arithmetic overflow,\nand verifying that the entire requested range (ioba - offset + npages)\ndoes not exceed the table capacity \u0027size\u0027.\n\nFixes: b1af23d836f8 (\"KVM: PPC: iommu: Unify TCE checking\")\nReviewed-by: Ritesh Harjani (IBM) \u003critesh.list@gmail.com\u003e\nTested-by: R Nageswara Sastry \u003crnsastry@linux.ibm.com\u003e\nSigned-off-by: Shivaprasad G Bhat \u003csbhat@linux.ibm.com\u003e\nSigned-off-by: Gautam Menghani \u003cgautam@linux.ibm.com\u003e\nSigned-off-by: Madhavan Srinivasan \u003cmaddy@linux.ibm.com\u003e\n"
    },
    {
      "commit": "0a416ee20bcccddf91ca5b63696a23b9d11d73aa",
      "tree": "05a32516a3ebb46fbdb1cc87f824f1ec99ba6658",
      "parents": [
        "51938dfa8a51a4f85328413fca9b6e21f9d2d088"
      ],
      "author": {
        "name": "Amit Machhiwal",
        "email": "amachhiw@linux.ibm.com",
        "time": "Tue Sep 15 22:04:16 2026 +0530"
      },
      "committer": {
        "name": "Madhavan Srinivasan",
        "email": "maddy@linux.ibm.com",
        "time": "Wed Sep 16 13:43:54 2026 +0530"
      },
      "message": "KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure\n\nIn kvmppc_svm_page_in(), if uv_page_in() fails after\nkvmppc_uvmem_get_page() has succeeded, the secure device page is never\nreleased.  kvmppc_uvmem_get_page() sets a bit in kvmppc_uvmem_bitmap,\nallocates a kvmppc_uvmem_page_pvt struct, marks the GFN as\nKVMPPC_GFN_UVMEM_PFN, and calls zone_device_page_init() which sets\nrefcount\u003d1 and locks the page.  The subsequent goto out_finalize skips\nthe *mig.dst assignment, so migrate_vma_finalize() is a no-op for the\npage, and none of those resources are ever reclaimed.\n\nEach occurrence permanently consumes one entry from the firmware-bounded\nsecure memory pool (kvmppc_uvmem_bitmap), leaks pvt, and leaves the GFN\nmarked as secure — making it unusable for the lifetime of the VM.\n\nThe twin __kvmppc_svm_page_out() already handles the analogous uv_page_out()\nfailure correctly with unlock_page(dpage); __free_page(dpage).  Apply\nthe same pattern here: unlock_page() followed by put_page(), which\nchains through free_zone_device_folio() into kvmppc_uvmem_folio_free()\nto clear the bitmap bit, free pvt, and reset the GFN state.\n\nReachable whenever uv_page_in() returns an error (e.g. UV pool\nexhaustion) on any POWER9/10 + Ultravisor/PEF system.\n\nFixes: ca9f4942670c (\"KVM: PPC: Book3S HV: Support for running secure guests\")\nReviewed-by: Ritesh Harjani (IBM) \u003critesh.list@gmail.com\u003e\nTested-by: R Nageswara Sastry \u003crnsastry@linux.ibm.com\u003e\nSigned-off-by: Amit Machhiwal \u003camachhiw@linux.ibm.com\u003e\nSigned-off-by: Gautam Menghani \u003cgautam@linux.ibm.com\u003e\nSigned-off-by: Madhavan Srinivasan \u003cmaddy@linux.ibm.com\u003e\n"
    },
    {
      "commit": "51938dfa8a51a4f85328413fca9b6e21f9d2d088",
      "tree": "eda67c64d35759c0bb9814f3dd1ba7264ce4fa81",
      "parents": [
        "fd73f4a6659897191fa0d40695fe370925dd3780"
      ],
      "author": {
        "name": "Amit Machhiwal",
        "email": "amachhiw@linux.ibm.com",
        "time": "Tue Sep 15 22:04:15 2026 +0530"
      },
      "committer": {
        "name": "Madhavan Srinivasan",
        "email": "maddy@linux.ibm.com",
        "time": "Wed Sep 16 13:43:50 2026 +0530"
      },
      "message": "KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n\nkvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops\nmmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a\nreference on the kvm_nested_guest pointer obtained from the IDR.  A\nconcurrent vCPU issuing a single-LPID tlbie (is\u003d2, ric\u003d2) can race\nthrough kvmhv_flush_nested() -\u003e kvmhv_remove_nested() -\u003e idr_remove /\n--refcnt -\u003e kvmhv_release_nested() -\u003e kfree(gp) in that window, leaving\nthe iterating vCPU with a dangling pointer.  The subsequent\nmutex_lock(\u0026gp-\u003etlb_lock) and accesses to gp-\u003eshadow_pgtable,\ngp-\u003eshadow_lpid and gp-\u003el1_host all touch freed memory.  The free path\nis fully L1-controlled.\n\nFix this by incrementing gp-\u003erefcnt inside the loop before dropping\nmmu_lock, mirroring what kvmhv_get_nested() does, and releasing the\nreference with kvmhv_put_nested() after the per-guest work completes.\nThis is the same get/put discipline already used at every other\ncall site that drops mmu_lock while holding a nested-guest pointer.\n\nFixes: e3b6b4661527 (\"KVM: PPC: Book3S HV: Implement H_TLB_INVALIDATE hcall\")\nReviewed-by: Ritesh Harjani (IBM) \u003critesh.list@gmail.com\u003e\nTested-by: R Nageswara Sastry \u003crnsastry@linux.ibm.com\u003e\nSigned-off-by: Amit Machhiwal \u003camachhiw@linux.ibm.com\u003e\nSigned-off-by: Gautam Menghani \u003cgautam@linux.ibm.com\u003e\nSigned-off-by: Madhavan Srinivasan \u003cmaddy@linux.ibm.com\u003e\n"
    },
    {
      "commit": "dbd9d1cbf9700528c8595ab1fa7ef832e79821fe",
      "tree": "1ad52517857e32af01527bc26f435574dd484450",
      "parents": [
        "c9e6e5f38bf75276605f1952b22285f5f3abcaff"
      ],
      "author": {
        "name": "Nguyen Ngoc Thang",
        "email": "ngocthang2710.1999@gmail.com",
        "time": "Tue Sep 15 23:31:10 2026 +0700"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Wed Sep 16 09:30:17 2026 +0200"
      },
      "message": "ALSA: usb-audio: fix list_add double-add in push_back_to_ready_list\n\nstop_urbs() clears ep-\u003eready_playback_urbs with a bare INIT_LIST_HEAD()\ninstead of unlinking each queued snd_urb_ctx. If a URB survives past\nwait_clear_urbs()\u0027s forced STOPPING-\u003eSTOPPED timeout, its ctx is left\nlooking \"linked\" (stale next/prev) even though the list head has\nforgotten it. When the endpoint later restarts and re-queues that same\nctx onto the (now real) ready list, and the old URB\u0027s completion\nhandler then calls push_back_to_ready_list() for it a second time, the\nctx is still the list\u0027s own tail and list_add\u0027s double-add check trips:\n\n  kernel BUG at lib/list_debug.c:35 (list_add double add)\n\nGuard push_back_to_ready_list() with a list_empty() check so a\nstill-linked ctx isn\u0027t re-added, and make stop_urbs() actually unlink\neach ctx via list_del_init() instead of only resetting the head, so a\ndropped ctx doesn\u0027t keep looking linked to that guard.\n\nReported-by: syzbot+9fe3b8d9f5c64ff410a7@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d9fe3b8d9f5c64ff410a7\nSigned-off-by: Nguyen Ngoc Thang \u003cngocthang2710.1999@gmail.com\u003e\nLink: https://patch.msgid.link/20260915163110.58124-1-ngocthang2710.1999@gmail.com\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\n"
    },
    {
      "commit": "ceac0de741bfb47ca255eee075257b3bb31f0651",
      "tree": "5f3a412a5da309ca190ee87af037f44955ea17bb",
      "parents": [
        "2842ce397dd09882530b42f7fdb0c855767eb24e"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Fri Sep 11 16:08:04 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 18:44:02 2026 -0700"
      },
      "message": "netlink: do not free nlk-\u003egroups while lockless readers can use it\n\nnetlink_realloc_groups() uses krealloc() under netlink_table_grab().\nWhenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old\nbitmap is freed immediately.\n\nTwo readers of nlk-\u003egroups / nlk-\u003engroups do not hold the netlink\ntable lock:\n\n1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the\n   rhashtable walk in __netlink_diag_dump(), which only holds RCU.\n   Only the mc_list part of the dump takes nl_table_lock.\n\n2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been\n   lockless since commit 21e4902aea80 (\"netlink: Lockless lookup with\n   RCU grace period in socket release\").\n\nBoth can read a freed buffer, and sk_diag_dump_groups() can also read\npast the end of the old (smaller) buffer if it happens to load the old\n@groups pointer together with the new @ngroups value, copying the\nresult into a NETLINK_DIAG_GROUPS attribute.\n\nThis is the same class of bug that commit f773608026ee (\"netlink:\naccess nlk groups safely in netlink bind and getname\") fixed for bind()\nand getname(); these two readers were missed. Simply grabbing the table\nlock in sk_diag_dump_groups() is not an option, because it is also\ncalled with nl_table_lock already held from the mc_list section of the\ndump.\n\nMake the lockless readers safe instead:\n\n- Allocate a new bitmap and free the old one after an RCU grace period,\n  instead of relying on the implicit kfree() done by krealloc().\n\n- Publish @groups before @ngroups, both with release semantics, and have\n  the lockless readers load @ngroups first. A reader can then never pair\n  the new (bigger) size with the old (smaller) buffer, and a reader\n  picking up the new pointer while still seeing the old size is\n  guaranteed to see the initialized bitmap.\n\nnetlink_realloc_groups() is called from process context (bind() and\nsetsockopt()), so kfree_rcu_mightsleep() can be used, once the table\nhas been released.\n\nFixes: 21e4902aea80 (\"netlink: Lockless lookup with RCU grace period in socket release\")\nFixes: ad202074320c (\"netlink: Use rhashtable walk interface in diag dump\")\nReported-by: James Burton \u003cjamesburton@meta.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260911160804.917099-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2842ce397dd09882530b42f7fdb0c855767eb24e",
      "tree": "75078af382d48e3dfd8d383a4ce85ee9346cdf7e",
      "parents": [
        "f0ef4b1eaed000a304726a43091588e8426ba08a"
      ],
      "author": {
        "name": "Nikolay Aleksandrov",
        "email": "razor@blackwall.org",
        "time": "Mon Sep 14 13:52:58 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 18:31:57 2026 -0700"
      },
      "message": "net: bridge: vlan: fix bugs caused by switchdev deletion errors\n\nAllowing switchdev to prevent vlan deletion and error out in __vlan_del\ncould cause multiple different issues - inconsistent state, memory leaks\nwhen flushing, NULL pointer dereference on bridge error when flushing.\nIt doesn\u0027t make sense to allow it to stop __vlan_del, so log the error\nand continue with software vlan deletion. This is also consistent with\n8021q behaviour.\n\nSuggested-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nFixes: bf361ad38165 (\"net: bridge: check __vlan_vid_del for error\")\nFixes: 5454f5c28eca (\"net: bridge: vlan: check for errors from __vlan_del in __vlan_flush\")\nFixes: 2594e9064a57 (\"bridge: vlan: add per-vlan struct and move to rhashtables\")\nFixes: 9c86ce2c1ae3 (\"net: bridge: Notify about bridge VLANs\")\nSigned-off-by: Nikolay Aleksandrov \u003crazor@blackwall.org\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260914105258.3436918-1-razor@blackwall.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f0ef4b1eaed000a304726a43091588e8426ba08a",
      "tree": "bb18ce1c7c5cdfd5df81f015f083943028d32719",
      "parents": [
        "3f118c8217c109fd13ca61caa301d72c483897ef"
      ],
      "author": {
        "name": "Lorenzo Bianconi",
        "email": "lorenzo.bianconi@oss.qualcomm.com",
        "time": "Mon Sep 14 09:41:07 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 18:25:06 2026 -0700"
      },
      "message": "net: stmmac: do not overwrite phc_index when no PTP clock is registered\n\nstmmac_get_ts_info() reports phc_index as 0 when hardware timestamping\nis supported but no PTP clock has been registered yet (e.g. while the\ninterface is down). Zero is a valid PHC index and would make userspace\nresolve the wrong clock; the absence of a clock should be reported as\n-1.\n\nThe ethtool core already initializes phc_index to -1 before invoking\nthe get_ts_info callback (ethtool_init_tsinfo()), so just drop the\nerroneous assignment.\n\nFixes: 9364fa7fcf12 (\"net: stmmac: Remove setting of RX software timestamp\")\nReviewed-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Rahul Rameshbabu \u003crrameshbabu@nvidia.com\u003e\nSigned-off-by: Lorenzo Bianconi \u003clorenzo.bianconi@oss.qualcomm.com\u003e\nReviewed-by: Gal Pressman \u003cgal@nvidia.com\u003e\nLink: https://patch.msgid.link/20260914-stmmac-fix-phc_index-v2-1-bf3d90373fe4@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3f118c8217c109fd13ca61caa301d72c483897ef",
      "tree": "14b6e2f1319792916760ca4d8d06dbb1a80f6b43",
      "parents": [
        "ad77dba64dc1a522014b2cd7376a67004140375b"
      ],
      "author": {
        "name": "Zhiling Zou",
        "email": "zhilinz@nebusec.ai",
        "time": "Sat Sep 12 21:22:43 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 18:00:46 2026 -0700"
      },
      "message": "openvswitch: avoid reallocating confirmed conntrack labels\n\novs_ct_get_conn_labels() adds the labels extension when a conntrack\nentry does not have one.  Confirmed conntracks can be read locklessly,\nso adding an extension may reallocate and free the extension block\nwhile another CPU accesses it.\n\nOnly add the extension for unconfirmed conntracks.  A confirmed\nconntrack without labels now fails the caller\u0027s label operation instead\nof reallocating its extension storage.\n\nFixes: c2ac66735870 (\"openvswitch: Allow matching on conntrack label\")\nCc: stable@vger.kernel.org\nReported-by: Vega \u003cvega@nebusec.ai\u003e\nSigned-off-by: Zhiling Zou \u003czhilinz@nebusec.ai\u003e\nReviewed-by: Ilya Maximets \u003ci.maximets@ovn.org\u003e\nReviewed-by: Aaron Conole \u003caconole@redhat.com\u003e\nLink: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ad77dba64dc1a522014b2cd7376a67004140375b",
      "tree": "e1fd5a411c7bb76507456946395b90d730ebf81e",
      "parents": [
        "455ebeadf714f51e1dbbd6a022c74c9215b1cd76",
        "439f392084f8f7f59ab9d47a9579185accefe1d8"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:36 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:37 2026 -0700"
      },
      "message": "Merge branch \u0027net-drop_monitor-fix-concurrency-issues-preemption-warning-and-buffer-overrun\u0027\n\nEric Dumazet says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: drop_monitor: fix concurrency issues, preemption warning, and buffer overrun\n\nThis series addresses several issues discovered in the drop_monitor subsystem:\n\nPatch 1 adds missing tracepoint unregistration synchronization to the\nnet_dm_trace_on_set() error unwind path, preventing in-flight probes\nfrom scheduling work after the module reference has been dropped.\n\nPatch 2 resolves a race condition during monitoring teardown where per-CPU\ntimers can be re-armed after deletion if a concurrent worker encounters a\nmemory allocation failure, switching to timer_shutdown_sync().\n\nPatch 3 fixes a CONFIG_DEBUG_PREEMPT warning reported by syzbot when\nkfree_skb() is invoked from preemptible process context, using raw_cpu_ptr()\nsince each per-CPU queue is safely protected by its own spinlock.\n\nPatch 4 fixes an out-of-bounds write in reset_per_cpu_data() where memset()\noverwrote the allocated SKB tailroom by sizeof(struct nlattr) bytes.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260910204612.3762015-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "439f392084f8f7f59ab9d47a9579185accefe1d8",
      "tree": "e1fd5a411c7bb76507456946395b90d730ebf81e",
      "parents": [
        "c19b7d35086b7d240f1ca3088b0079d2bd39ffb9"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Sep 10 20:46:12 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:35 2026 -0700"
      },
      "message": "drop_monitor: fix out-of-bounds write in reset_per_cpu_data()\n\nIn reset_per_cpu_data(), al is computed as:\n\n    al \u003d sizeof(struct net_dm_alert_msg);\n    al +\u003d dm_hit_limit * sizeof(struct net_dm_drop_point);\n    al +\u003d sizeof(struct nlattr);\n\n    skb \u003d genlmsg_new(al, GFP_KERNEL);\n    ...\n    nla \u003d nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));\n    ...\n    msg \u003d nla_data(nla);\n    memset(msg, 0, al);\n\nBecause al includes sizeof(struct nlattr) (the 4-byte attribute header),\ngenlmsg_new() allocates al bytes of tailroom starting at nla.\nHowever, msg points to nla_data(nla), which is located\nsizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al)\ntherefore writes al bytes starting from msg, exceeding the allocated\nbuffer by sizeof(struct nlattr) (4 bytes) and corrupting\nskb_shared_info.\n\nFix this by letting al represent only the payload length, allocating\nthe skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing\nal bytes from msg.\n\nFixes: 683703a26e46 (\"drop_monitor: Update netlink protocol to include netlink attribute header in alert message\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Hangbin Liu \u003cliuhangbin@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c19b7d35086b7d240f1ca3088b0079d2bd39ffb9",
      "tree": "8c32548ae448d6b4d4ecabc26f05b56da2f6df41",
      "parents": [
        "c391a40f71886b28c082b47270f0e856fa3e1150"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Sep 10 20:46:11 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:35 2026 -0700"
      },
      "message": "drop_monitor: use raw_cpu_ptr() in tracepoint probes\n\nsyzbot reported a preemption warning in sk_skb_reason_drop():\n\n BUG: using smp_processor_id() in preemptible [00000000] code: syz.0.17/5917\n caller is net_dm_packet_trace_kfree_skb_hit+0x119/0x350 net/core/drop_monitor.c:519\n\nIn net_dm_packet_trace_kfree_skb_hit(), data \u003d this_cpu_ptr(\u0026dm_cpu_data)\nis evaluated before spin_lock_irqsave(\u0026data-\u003edrop_queue.lock, flags).\nWhen kfree_skb() is called from preemptible context (e.g. process context\nduring close() on /dev/net/tun), preemption is enabled, triggering the\nCONFIG_DEBUG_PREEMPT warning in smp_processor_id().\n\nThe same pattern exists in net_dm_hw_trap_summary_probe() and\nnet_dm_hw_trap_packet_probe() for dm_hw_cpu_data.\n\nThis is a false positive because each per-cpu structure is protected\nby its own spinlock. If the task migrates to another CPU right after\nreading the per-cpu pointer, the lock still safely synchronizes\naccess to that queue.\n\nUse raw_cpu_ptr() instead of this_cpu_ptr() to silence\nCONFIG_DEBUG_PREEMPT without disturbing interrupt state or breaking\nPREEMPT_RT locking semantics.\n\nFixes: ca30707dee2b (\"drop_monitor: Add packet alert mode\")\nFixes: 5855357cd40e (\"drop_monitor: Prepare probe functions for devlink tracepoint\")\nReported-by: syzbot+dc57fd6722deb17e92af@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6aa316b2.f81106d8.2ab401.0014.GAE@google.com/\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260910204612.3762015-4-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c391a40f71886b28c082b47270f0e856fa3e1150",
      "tree": "dfd445c49c587198606e64c1b321cb18f1ab3ec1",
      "parents": [
        "6a038ef2b57922b6d9ca98ddac0df0681849b704"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Sep 10 20:46:10 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:34 2026 -0700"
      },
      "message": "drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown\n\nIn drop_monitor teardown paths (net_dm_trace_off_set(),\nnet_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set()\nand net_dm_hw_monitor_start()), per-CPU timers are stopped using\ntimer_delete_sync() followed by cancel_work_sync().\n\nHowever, there is a circular dependency between send_timer and\ndm_alert_work:\n1) sched_send_work() (timer callback) schedules dm_alert_work.\n2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data()\n   or net_dm_hw_reset_per_cpu_data().\n3) If memory allocation fails under memory pressure in the reset\n   function, it re-arms the timer via mod_timer(\u0026data-\u003esend_timer, ...).\n\nIf dm_alert_work is running concurrently while timer_delete_sync()\nexecutes on another CPU, an allocation failure in the worker will\nre-arm the timer after timer_delete_sync() has already returned.\nOnce cancel_work_sync() completes and module_put() is called, the timer\nremains active in the timer wheel. If the module is then unloaded, the\ntimer will fire and execute sched_send_work() in freed memory,\ntriggering a kernel panic / use-after-free.\n\nSwitch from timer_delete_sync() to timer_shutdown_sync(). This guarantees\nthat any in-flight timer handler has finished and prevents subsequent\nre-arming attempts from running workers from succeeding. When monitoring\nis restarted later, timer_setup() is invoked, which cleanly\nre-initializes the timer.\n\nFixes: 9398e9c0b1d4 (\"drop_monitor: Perform cleanup upon probe registration failure\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260910204612.3762015-3-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6a038ef2b57922b6d9ca98ddac0df0681849b704",
      "tree": "d4763fcf151755b5f9b9db41d2ebb3ef15d285d3",
      "parents": [
        "455ebeadf714f51e1dbbd6a022c74c9215b1cd76"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Sep 10 20:46:09 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:58:34 2026 -0700"
      },
      "message": "drop_monitor: synchronize tracepoint unregistration on error path\n\nIf register_trace_napi_poll() fails in net_dm_trace_on_set(),\nunregister_trace_kfree_skb() is called to roll back the kfree_skb\ntracepoint registration.\n\nHowever, tracepoint_synchronize_unregister() is omitted before calling\ncancel_work_sync() and module_put(). An in-flight probe executing\nconcurrently on another CPU could call schedule_work() after\ncancel_work_sync() has already returned, leaving a pending work item\nscheduled after the module reference is dropped. If the module is then\nunloaded, executing the work item triggers a kernel panic.\n\nAdd tracepoint_synchronize_unregister() after unregister_trace_kfree_skb()\nin the error path, matching net_dm_trace_off_set() and\nnet_dm_hw_probe_unregister().\n\nFixes: 7c747838a558 (\"drop_monitor: Split tracing enable / disable to different functions\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Hangbin Liu \u003cliuhangbin@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260910204612.3762015-2-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "455ebeadf714f51e1dbbd6a022c74c9215b1cd76",
      "tree": "cb775d963a4823472e940bce94ae8b8f01bfb63c",
      "parents": [
        "ecc7253683a3c55caa868ce0ee530fcb0044bd3c"
      ],
      "author": {
        "name": "Gris Ge",
        "email": "cnfourt@gmail.com",
        "time": "Sun Sep 13 17:08:50 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:34:31 2026 -0700"
      },
      "message": "net: ip_tunnel: initialize `options_len` before referencing options\n\nThe following command triggers a kernel panic:\n\n  ip link add d0 type dummy; ip link set d0 up\n  ip route add 10.30.0.0/16 \\\n    encap ip id 300 geneve_opts 4660:66:11223344 dev d0\n\n  memcpy: detected buffer overflow: 4 byte write of buffer size 0\n  kernel BUG at lib/string_helpers.c:1044!\n  ...\n  ip_tun_parse_opts.part.0.cold+0x10/0x10\n  ip_tun_build_state+0x116/0x2a0\n\nOn kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified\n`memcpy()` got 0 sized destination with request of 4 bytes length:\n\n  static int ip_tun_parse_opts_geneve(...)\n  {\n      ...\n      attr \u003d tb[LWTUNNEL_IP_OPT_GENEVE_DATA];\n      data_len \u003d nla_len(attr); /* \u003d\u003d 4 */\n\n      struct geneve_opt *opt \u003d ip_tunnel_info_opts(info) + opts_len;\n      memcpy(opt-\u003eopt_data, nla_data(attr), data_len);\n      /*     ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */\n\nFixed by initializing the counter before the options are referenced.\nMatching what `tunnel_key_opts_set()` already does.\n\nFixes: bb5e62f2d547 (\"net: Add options as a flexible array to struct ip_tunnel_info\")\nCc: stable@vger.kernel.org\nSigned-off-by: Gris Ge \u003ccnfourt@gmail.com\u003e\nReviewed-by: Hangbin Liu \u003cliuhangbin@kylinos.cn\u003e\nReviewed-by: Gustavo A. R. Silva \u003cgustavoars@kernel.org\u003e\nLink: https://patch.msgid.link/20260913090851.468216-1-cnfourt@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ecc7253683a3c55caa868ce0ee530fcb0044bd3c",
      "tree": "6a2a6bb79488c0c17ed3a8d4551382fd5dc21711",
      "parents": [
        "562219874cba1be6b708fb29a89fe8f54544b022"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Sat Sep 12 23:30:48 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:07:01 2026 -0700"
      },
      "message": "pppoatm: ensure a writable skb header and linear data\n\nIn pppoatm_send(), LLC encapsulation checks whether there is sufficient\nheadroom for the 4-byte LLC header, but does not ensure that the skb header\nis writable.\n\nNormal transmit packets passing through ppp_start_xmit() have their header\nunshared via skb_cow_head(). However, packets can also reach pppoatm_send()\nvia PPP channel bridging (PPPIOCBRIDGECHAN) without going through\nppp_start_xmit().\n\nUse skb_cow_head() to ensure both sufficient headroom and a writable\nheader before pushing the LLC header.\n\nWhile at it:\n- Call pskb_may_pull(skb, 1) before inspecting skb-\u003edata[0] to prevent\n  out-of-bounds reads on zero-length or non-linear frames (e.g. from\n  bridging).\n- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()\n  succeeds. This eliminates the temporary skb allocation on admission failure\n  and completely removes the fragile \"undo\" heuristic at the nospace label,\n  avoiding any risk of reading uninitialized headroom or performing an\n  unbalanced skb_push().\n\nFixes: 4cf476ced45d (\"ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260912233048.3977192-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "562219874cba1be6b708fb29a89fe8f54544b022",
      "tree": "f08c58d1dc0b2d1353b85ca1920a92e9ae42463b",
      "parents": [
        "15989abd74f16f44bf953d056b95f1d2fda9b0cd",
        "14c5eb685cdefbd32e73d2723071ecbd8effbce9"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:03:13 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:03:14 2026 -0700"
      },
      "message": "Merge branch \u0027net-sched-fix-action-batch-deletion-cleanup\u0027\n\nXuanqiang Luo says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet/sched: fix action batch deletion cleanup\n\nBatched RTM_DELACTION requests can leak references to unprocessed actions\nwhen deletion stops at a filter-bound action.\n\nPatch 1 fixes the failure cleanup.\n\nPatch 2 adds tc-testing regression coverage.\n\nFailure reproduction (key output excerpts):\n\n  python3 tdc.py -f /root/tc-testing/batch-delete.json\n\nnot ok 1 d710 - Release tail references after first action deletion fails\n\tCould not match regex pattern. Verify command output:\n[...]\n\t index 2 ref 2 bind 0\n[...]\n\t index 3 ref 2 bind 0\n\nnot ok 2 d711 - Release tail references after middle action deletion fails\n\tCould not match regex pattern. Verify command output:\n[...]\n\t index 3 ref 2 bind 0\n\nnot ok 3 d713 - Delete a tail action once after a failed batch\n\tCould not match regex pattern. Verify command output:\ntotal acts 2\n[...]\n\t index 2 ref 1 bind 0\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260910093413.34509-1-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "14c5eb685cdefbd32e73d2723071ecbd8effbce9",
      "tree": "f08c58d1dc0b2d1353b85ca1920a92e9ae42463b",
      "parents": [
        "6e05e46fa821a5c1b281355f1f622ac76cb6080a"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Thu Sep 10 17:34:13 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:03:09 2026 -0700"
      },
      "message": "selftests: tc-testing: test action batch deletion failure cleanup\n\nAdd tests for cleanup after a batched RTM_DELACTION request fails at\na gact action bound to a filter. Check that subsequent actions retain\ntheir original reference counts and that earlier successful deletions\nare preserved.\n\nCover failures at the first and middle entries. Verify that a remaining\nunbound action can be removed with one subsequent delete.\n\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260910093413.34509-3-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6e05e46fa821a5c1b281355f1f622ac76cb6080a",
      "tree": "defe45ca6b54051500dd6cbf6facb4bfa1063ca4",
      "parents": [
        "15989abd74f16f44bf953d056b95f1d2fda9b0cd"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Thu Sep 10 17:34:12 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 17:03:09 2026 -0700"
      },
      "message": "net/sched: act_api: release tail references on DELACTION failure\n\nA batched RTM_DELACTION request takes a temporary reference on each\naction before attempting any deletion. tcf_action_delete() clears\neach processed slot and drops its temporary reference before attempting\nthe deletion. If deletion fails, tca_action_gd() calls\ntcf_action_put_many() to release the remaining references, but its\ntcf_act_for_each_action() iterator stops at the first NULL slot.\n\nWhen a batch stops at an action bound to a filter, this leaks a\nreference on each subsequent action. A later delete of an unbound\naction can then return success without removing it from the IDR.\n\nWalk the full array in tcf_action_put_many() and skip NULL slots to\nrelease the references held on the unprocessed actions.\n\nFixes: a0e947c9ccff (\"net/sched: act_api: avoid non-contiguous action array\")\nCc: stable@vger.kernel.org\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260910093413.34509-2-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "15989abd74f16f44bf953d056b95f1d2fda9b0cd",
      "tree": "716bc8eaa6d036d009f63857d0e52de9ed54b931",
      "parents": [
        "433cfc302561bc7e23b1305e1779e0d83156cb61"
      ],
      "author": {
        "name": "Lorenzo Bianconi",
        "email": "lorenzo.bianconi@oss.qualcomm.com",
        "time": "Fri Sep 11 11:20:15 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:55:52 2026 -0700"
      },
      "message": "net: stmmac: fix TSO header length truncation\n\nstmmac_tso_xmit() stores the protocol header length returned by\nstmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits\nheaders up to 1023 bytes, so a header longer than 255 bytes wraps modulo\n256 (486 becomes 230, 256 becomes 0).\n\nA TCP over IPv6 socket carrying a few hundred bytes of sticky\ndestination/hop-by-hop options makes skb_tcp_all_headers() exceed 255\nwhile staying below the 1023-byte limit, so such an skb reaches\nstmmac_tso_xmit().\n\nWiden proto_hdr_len to unsigned int, which is sufficient since the value\nis bounded by the hardware limit, and adjust the debug print specifier\naccordingly.\n\nFixes: 9edfa7dab811 (\"net: stmmac: enable TSO for IPv6\")\nSigned-off-by: Lorenzo Bianconi \u003clorenzo.bianconi@oss.qualcomm.com\u003e\nReviewed-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nLink: https://patch.msgid.link/20260911-stmmac-fix-header-length-v1-1-8fc103334327@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "433cfc302561bc7e23b1305e1779e0d83156cb61",
      "tree": "c1d65f519aad9bd62decab7b83ab7187507e4aad",
      "parents": [
        "c5e367a8a3f939e9935369a38ea7e0f872f594b5",
        "b645ccd410547d0e0e4a9543f828119e24dc7635"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:45:06 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:45:07 2026 -0700"
      },
      "message": "Merge branch \u0027af_unix-fix-inconsistent-scc_index\u0027\n\nKuniyuki Iwashima says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\naf_unix: Fix inconsistent scc_index.\n\nJames Burton reported that a single SCC could have multiple\nscc_index and unix_vertex_dead() fails to detect a dead SCC.\n\nPatch 1 fixes it and Patch 2 adds a test case.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260912030852.1467872-1-kuniyu@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b645ccd410547d0e0e4a9543f828119e24dc7635",
      "tree": "c1d65f519aad9bd62decab7b83ab7187507e4aad",
      "parents": [
        "4a4263dfeabad72f95e8ab6e15146861fa4144dd"
      ],
      "author": {
        "name": "Kuniyuki Iwashima",
        "email": "kuniyu@google.com",
        "time": "Sat Sep 12 03:07:52 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:45:05 2026 -0700"
      },
      "message": "selftest: af_unix: Add test case with mixed lowpoint in scm_rights.c.\n\nThe new test case creates two SCCs so that each of them\nhas multiple scc_index.\n\nWithout patch, GC cannot free the sockets and the test fails.\n\n  #  RUN           scm_rights.dgram.mixed_lowpoints ...\n  # scm_rights.c:176:mixed_lowpoints:Expected 0 (0) \u003d\u003d ret (12)\n  # mixed_lowpoints: Test terminated by assertion\n  #          FAIL  scm_rights.dgram.mixed_lowpoints\n  not ok 5 scm_rights.dgram.mixed_lowpoints\n  ...\n  # FAILED: 45 / 50 tests passed.\n  # Totals: pass:45 fail:5 xfail:0 xpass:0 skip:0 error:0\n\nWith the patch, all tests pass.\n\n  # PASSED: 50 / 50 tests passed.\n  # Totals: pass:50 fail:0 xfail:0 xpass:0 skip:0 error:0\n\nSigned-off-by: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260912030852.1467872-3-kuniyu@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4a4263dfeabad72f95e8ab6e15146861fa4144dd",
      "tree": "5599fb84af489e861679958a2539006ca62ba0f6",
      "parents": [
        "c5e367a8a3f939e9935369a38ea7e0f872f594b5"
      ],
      "author": {
        "name": "Kuniyuki Iwashima",
        "email": "kuniyu@google.com",
        "time": "Sat Sep 12 03:07:51 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:45:05 2026 -0700"
      },
      "message": "af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().\n\nCommit bfdb01283ee8 (\"af_unix: Assign a unique index to SCC.\")\nchanged Tarjan\u0027s algorithm to update lowlink with lowlink,\nwhich is called lowpoint (unix_vertex.scc_index).\n\nunix_vertex_dead() assumes all vertices in an SCC share the same\nlowpoint, but this is not always true if an SCC has two or more\nback edges, depending on the order of DFS.\n\nFor example, the graph below has two back edges from B to A\nand from C to B.\n\n  A --\u003e B --\u003e C\n  ^    | ^    |\n  `----\u0027 `----\u0027\n\nIf DFS walks through A -\u003e B -\u003e C -\u003e B (-\u003e C -\u003e B) -\u003e A (-\u003e B -\u003e A),\neach index and scc_index will be updated as follows.\n\n  A --\u003e B --\u003e C    C \u003d (3, 3)  (index, scc_index)\n                   B \u003d (2, 2)\n                   A \u003d (1, 1)\n\n  A ... B ... C    C \u003d (3, 2)\u003c-.\n         ^    |    B \u003d (2, 2) -\u0027\n         `----\u0027    A \u003d (1, 1)\n\n  A ... B ... C    C \u003d (3, 2)\n  ^    | .    .    B \u003d (2, 1)\u003c-.\n  `----\u0027  ....     A \u003d (1, 1) -\u0027\n\nThen, unix_vertex_dead() thinks that B is passed to another\nSCC with scc_index 2, and the SCC is not garbage-collected.\n\nThis does not happen if DFS walks in a different order below\nor starts from B.\n\n    1      3\n  A --\u003e B --\u003e C\n  ^    | ^    |\n  `----\u0027 `----\u0027\n     2      4\n\nLet\u0027s unify scc_index across the SCC when finalising it.\n\nNote that updating v-\u003eindex was previously done in unix_scc_dead(),\nwhen called from __unix_walk_scc(), just to save one loop.  Since\n__unix_walk_scc() now iterates over the SCC anyway, the update is\nmoved back to __unix_walk_scc() and \u0027fast\u0027 argument is dropped.\n\nFixes: 4090fa373f0e (\"af_unix: Replace garbage collection algorithm.\")\nReported-by: James Burton \u003cjamesburton@meta.com\u003e\nSigned-off-by: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260912030852.1467872-2-kuniyu@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c5e367a8a3f939e9935369a38ea7e0f872f594b5",
      "tree": "8d2780c739c3ddc9422303e688f41791f6f1dc2c",
      "parents": [
        "83a945a529d6e002dd7339c532288a931f463dba",
        "801fb950cae7048eb7d83b18857d1ca37b8cd5a4"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:40:55 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Sep 15 16:40:55 2026 -0700"
      },
      "message": "Merge tag \u0027for-net-2026-09-15\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth\n\nLuiz Augusto von Dentz says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nbluetooth pull request for net:\n\nCore:\n\n - hci: put the peer\u0027s on-air address on air when we cannot resolve\n - hci: keep dst_type with dst when reusing an LE connection\n - hci_core: Fix queuing tx_work after workqueue is drained\n - hci_sync: Serialize local codec list cleanup\n - hci_codec: validate vendor codec count length\n - eir: validate service data length before reading UUID\n - RFCOMM: avoid socket lock inversion in listener cleanup\n - ISO: Fix parent socket leak in iso_conn_ready()\n - ISO: set BT_LISTEN before requesting a BIG sync\n - coredump: Quiesce dump work on unregister\n\nDrivers:\n\n - btintel_pcie: validate TX skb length in send_sync\n - btmtk: fix wrong status for short WMT FUNC_CTRL events\n - btmtksdio, btmtkuart: validate WMT event length before struct access\n - hci_qca: Do not write to the serial port after it is closed\n - btusb: fix NXP IW610 composite device handling\n - btintel_pcie: fix off-by-one bounds check in RX submit\n - btmtksdio: Fix PM runtime reference leak in shutdown\n\n* tag \u0027for-net-2026-09-15\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth:\n  Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n  Bluetooth: keep dst_type with dst when reusing an LE connection\n  Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit\n  Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown\n  Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access\n  Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events\n  Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync\n  Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()\n  Bluetooth: hci_sync: Serialize local codec list cleanup\n  Bluetooth: hci_qca: Do not write to the serial port after it is closed\n  Bluetooth: hci_codec: validate vendor codec count length\n  Bluetooth: put the peer\u0027s on-air address on air when we cannot resolve\n  Bluetooth: coredump: Quiesce dump work on unregister\n  Bluetooth: btintel_pcie: validate TX skb length in send_sync\n  Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained\n  Bluetooth: eir: validate service data length before reading UUID\n  Bluetooth: btusb: fix NXP IW610 composite device handling\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260915192441.1130583-1-luiz.dentz@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9b87fdc9af2fbfcdb5c24a64139685ef80f6573f",
      "tree": "02d84ef44728f925cb130f487e55dbca8141de7e",
      "parents": [
        "6fb20c02710dabc2f63aa21cb23a154d76ef9921",
        "a9e3760b0838299649c0d57cca44daaf40ba3c33"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 11:57:51 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 11:57:51 2026 -0700"
      },
      "message": "Merge tag \u0027sched_ext-for-7.3-rc3-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext\n\nPull sched_ext fixes from Tejun Heo:\n\n - An error raised by a BPF program before the scheduler finished\n   enabling was consumed by the disable path\u0027s pre-enable shortcut,\n   leaving a running scheduler that couldn\u0027t be disabled and was later\n   freed while in use.\n\n - Two compat kfuncs dereferenced a NULL scheduler when handed an exited\n   or idle task, oopsing the kernel.\n\n - Keep-running decisions in the dispatch path used the root scheduler\u0027s\n   flags for tasks belonging to a sub-scheduler, causing warnings and\n   stalls.\n\n - Schedulers with their own CPU ID mapping had no way to learn which\n   IDs are online. Add a kernel-maintained online mask to plug the hole.\n\n - Cgroup idle state: the initial cpu.idle state wasn\u0027t passed on cgroup\n   init and same-value rewrites delivered spurious callbacks.\n\n - Example scheduler fixes for a reenqueue loop on attach, placements on\n   CPUs without effective grants, stalled partition work and stale idle\n   tracking.\n\n* tag \u0027sched_ext-for-7.3-rc3-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext:\n  sched_ext: Maintain an online cid mask in the scheduler arena\n  sched_ext: scx_qmap: Restore unused idle claims from ops.dispatch()\n  sched_ext: Close the pre-enable ops error claim window\n  sched_ext: scx_qmap: Fix pending partition work handoff\n  sched_ext: scx_qmap: Place only on cids whose caps are in effect\n  sched_ext: scx_qmap: Do not add IMMED to rescue inserts\n  sched_ext: Use @prev\u0027s scheduler for the keep decisions in dispatch_one()\n  sched_ext: Rename sch to root_sch in dispatch_one()\n  sched_ext: Fix NULL sched deref in kfunc sub-sched error paths\n  sched_ext: Don\u0027t deliver duplicate ops.cgroup_set_idle() for same value\n  sched_ext: Pass the initial cpu.idle state in scx_cgroup_init_args\n"
    },
    {
      "commit": "801fb950cae7048eb7d83b18857d1ca37b8cd5a4",
      "tree": "8d2780c739c3ddc9422303e688f41791f6f1dc2c",
      "parents": [
        "555cd2bd860e7c4bdc3f4e4405b05515b0d9bc87"
      ],
      "author": {
        "name": "Juan Perdomo",
        "email": "jcperdomo100@gmail.com",
        "time": "Sat Sep 12 23:09:45 2026 -0400"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:55:41 2026 -0400"
      },
      "message": "Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup\n\nrfcomm_sock_cleanup_listen() closes unaccepted child sockets through\nrfcomm_sock_close(), which takes the child socket lock before\nrfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these\nlocks in reverse order while handling connections and DLC state changes,\nso lockdep reports a possible deadlock.\n\nClose dequeued children without taking their socket lock. The accept queue\nowns a reference to each child, and bt_accept_dequeue() locks the child\nwhile unlinking it and clearing its parent pointer.\n\nDropping the child lock makes it important to prevent a concurrent\nrfcomm_connect_ind() from enqueueing a new child after cleanup observes an\nempty queue. Set a listening socket to BT_CLOSED while its lock is still\nheld, before dropping the lock and draining the queue. The state check in\nrfcomm_connect_ind() then rejects new children once cleanup starts.\n\nReported-by: syzbot+0cece8fa7d83523f47a3@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d0cece8fa7d83523f47a3\nFixes: b7ce436a5d79 (\"Bluetooth: switch to lock_sock in RFCOMM\")\nSigned-off-by: Juan Perdomo \u003cjcperdomo100@gmail.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "555cd2bd860e7c4bdc3f4e4405b05515b0d9bc87",
      "tree": "6a77620419e8930b0061034d2bca3a8ae9ddaafc",
      "parents": [
        "2ea5a87a5a7ae58cb2662b8a7d06f209383e1765"
      ],
      "author": {
        "name": "Radek Podgorny",
        "email": "radek@podgorny.cz",
        "time": "Sun Sep 13 22:28:02 2026 +0200"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:55:32 2026 -0400"
      },
      "message": "Bluetooth: keep dst_type with dst when reusing an LE connection\n\nhci_connect_le() swaps the caller\u0027s identity address for the peer\u0027s\ncached RPA when one is known, and stamps the matching\nADDR_LE_DEV_RANDOM on the local dst_type. On the conn-reuse path only\nthe address is copied into the connection:\n\n  if (conn) {\n          bacpy(\u0026conn-\u003edst, dst);\n\nso conn-\u003edst ends up holding an RPA while conn-\u003edst_type still names the\nidentity it was resolved from, and hci_le_create_conn_sync() puts that\npair on air unchanged. An RPA declared as a public address is not\nsomething any peer can answer.\n\nMeasured on a CYW43438 against a peer advertising an RPA the host holds\nthe IRK for, connecting to the identity address over a raw L2CAP socket.\nThe first attempt creates the connection, the second takes the reuse\npath:\n\n  LE Create Connection  3C:78:95:78:37:C3  type public\n  LE Create Connection  5B:75:A2:26:D6:18  type public\n  LE Connection Complete: Unknown Connection Identifier (0x02)\n\nThe second address is the peer\u0027s RPA. btmon annotates it with an OUI\nlookup rather than \"(Resolvable)\" precisely because the command declares\nit public; the same bit pattern annotates as resolvable once the type is\nright.\n\nThe mistyped pair is also why nothing downstream repairs it.\nhci_bdaddr_is_rpa() tests the type before the address, so an RPA carrying\na public type is not recognised as one, and hci_find_irk_by_addr() then\nsearches for an identity address that does not match it either.\n\nCopy the type along with the address.\n\nThe assignment used to be unconditional just below this block and covered\nboth paths; it moved into hci_conn_add_unset(), which the reuse path does\nnot go through.\n\nCc: stable@vger.kernel.org\nFixes: 14b06c3a88f7 (\"Bluetooth: HCI: Always use the identity address when initializing a connection\")\nAssisted-by: Claude:claude-opus-5\nSigned-off-by: Radek Podgorny \u003cradek@podgorny.cz\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "2ea5a87a5a7ae58cb2662b8a7d06f209383e1765",
      "tree": "a638c3e1b1c57dee1188e045a8cdc77d4fde9277",
      "parents": [
        "7b60ee5f46f2ee329de661f7c68b6818d8136220"
      ],
      "author": {
        "name": "Sai Teja Aluvala",
        "email": "aluvala.sai.teja@intel.com",
        "time": "Fri Sep 11 17:22:22 2026 +0530"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:55:27 2026 -0400"
      },
      "message": "Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit\n\nbtintel_pcie_submit_rx() used frbd_index \u003e rxq-\u003ecount to guard the\nFRBD array access, allowing frbd_index \u003d\u003d rxq-\u003ecount to pass through\nand index one element past the end of the array. Change the check to\n\u003e\u003d rxq-\u003ecount so every out-of-range index is rejected.\n\nThis issue was reported by Claude Mythos.\n\nFixes: c2b636b3f788 (Bluetooth: btintel_pcie: Add support for PCIe transport)\nSigned-off-by: Sai Teja Aluvala \u003caluvala.sai.teja@intel.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "7b60ee5f46f2ee329de661f7c68b6818d8136220",
      "tree": "af651194003a76d73145f923ed48d7dffe79835c",
      "parents": [
        "8879e3e0a84a86954c855caceead4867e74a9a27"
      ],
      "author": {
        "name": "Tzung-Bi Shih",
        "email": "tzungbi@kernel.org",
        "time": "Mon Sep 14 09:47:29 2026 +0000"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:55:01 2026 -0400"
      },
      "message": "Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown\n\nIn btmtksdio_shutdown(), pm_runtime_get_sync() is called at the\nbeginning of the function.  However, if sending the WMT function\ncontrol command fails later, the driver returns early.\n\nIt bypasses the corresponding pm_runtime_put_noidle() and\npm_runtime_disable() calls, leaking the PM usage counter and leaving PM\nruntime enabled indefinitely.\n\nFall through to execute the PM runtime cleanup block even if WMT errors.\n\nFixes: 7f3c563c575e (\"Bluetooth: btmtksdio: Add runtime PM support to SDIO based Bluetooth\")\nSigned-off-by: Tzung-Bi Shih \u003ctzungbi@kernel.org\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "8879e3e0a84a86954c855caceead4867e74a9a27",
      "tree": "312c2730fcbee27cd2a6685502fa05f8e03cb1c6",
      "parents": [
        "78b6abd6c7a7591aacdae657f813214dae4fcd3b"
      ],
      "author": {
        "name": "Chris Lu",
        "email": "chris.lu@mediatek.com",
        "time": "Mon Sep 14 14:56:54 2026 +0800"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:54:54 2026 -0400"
      },
      "message": "Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access\n\nbtmtksdio.c and btmtkuart.c cast a received WMT event straight to\nstruct btmtk_hci_wmt_evt and read its op/flag fields without checking\nthe event is long enough to contain them, unlike btmtk.c. The\nFUNC_CTRL case then further casts to struct btmtk_hci_wmt_evt_funcc\nand reads its 2-byte status field, again without a length check.\nFirmware that sends a short or malformed WMT event makes both drivers\nread past the end of the received SKB.\n\nMirror btmtk.c: validate the base WMT header with skb_pull_data()\nbefore touching any of its fields, and when a FUNC_CTRL event turns\nout to be the short, header-only form (a plain enable/disable ack\nwith no status word), decode the result from the header\u0027s own flag\nbyte instead (0 \u003d success, otherwise failure).\n\nVerified setup on MT7920, MT7921, MT7922 and MT7925: no regression.\n\nFixes: 9aebfd4a2200 (\"Bluetooth: mediatek: add support for MediaTek MT7663S and MT7668S SDIO devices\")\nFixes: e0b67035a90b (\"Bluetooth: mediatek: update the common setup between MT7622 and other devices\")\nAssisted-by: Claude:claude-opus-5\nSigned-off-by: Chris Lu \u003cchris.lu@mediatek.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "78b6abd6c7a7591aacdae657f813214dae4fcd3b",
      "tree": "04241e2a356b779b94ff49e4acfc5ac8e816eb90",
      "parents": [
        "296e7f3c5071cc02dc22e1566e759179fa1792ae"
      ],
      "author": {
        "name": "Chris Lu",
        "email": "chris.lu@mediatek.com",
        "time": "Mon Sep 14 14:56:53 2026 +0800"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:54:48 2026 -0400"
      },
      "message": "Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events\n\nA too-short BTMTK_WMT_FUNC_CTRL event (WMT header only, no trailing\n2-byte status word) is always treated as BTMTK_WMT_ON_UNDONE. This\nshort form is how firmware acks a plain enable/disable request, and\nthe actual result is carried in the header\u0027s own flag byte (0 \u003d\nsuccess), not a separate status word. Decode it from there instead of\nassuming failure.\n\nVerified setup on MT7920, MT7921, MT7922 and MT7925: no regression.\n\nFixes: e3ac0d9f1a20 (\"Bluetooth: btmtk: accept too short WMT FUNC_CTRL events\")\nAssisted-by: Claude:claude-opus-5\nSigned-off-by: Chris Lu \u003cchris.lu@mediatek.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "296e7f3c5071cc02dc22e1566e759179fa1792ae",
      "tree": "3849b9b2e79d0a09da2d237fc933427e39668efb",
      "parents": [
        "ca18ee413a7cb6f09885778039225e58bae0d607"
      ],
      "author": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Thu Sep 10 14:07:24 2026 -0400"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:53:12 2026 -0400"
      },
      "message": "Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync\n\nA BIS connection is matched to its parent socket by looking for a\nsocket in BT_LISTEN state with the same BIG handle:\n\n  iso_conn_ready()\n    if (test_bit(HCI_CONN_BIG_SYNC, \u0026hcon-\u003eflags))\n            parent \u003d iso_get_sock(hdev, \u0026hcon-\u003esrc, \u0026hcon-\u003edst,\n                                  BT_LISTEN, iso_match_big_hcon, hcon);\n\nThe socket was only moved to BT_LISTEN after iso_conn_big_sync()\nreturned, while the LE BIG Create Sync command has already been queued\nby then. If the BIG sync is established before the state is updated,\nwhich is easy to hit with an emulated controller as the command may\ncomplete in a few hundred microseconds, no parent is found and the BIS\nconnections are never notified to the listening socket.\n\nThe user space is then left waiting for connections that never arrive,\ne.g. bluetoothd never completes a MediaTransport1.Acquire of a\nBroadcast Sink transport.\n\nMove the socket to BT_LISTEN before requesting the BIG sync, so the\nstate is visible by the time the command is queued, and restore the\nprevious state if the request could not be started. Since the socket is\nbriefly visible as a listening socket, child sockets may have been\nqueued in the meantime, so drain the accept queue before restoring the\nstate: the cleanup paths of BT_CONNECT2/BT_CONNECTED don\u0027t do it and the\nchildren would be left with a dangling parent pointer.\n\nFixes: fbdc4bc47268 (\"Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync\")\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "ca18ee413a7cb6f09885778039225e58bae0d607",
      "tree": "69f4e5cd70061b214b05e35e9fe0168de92a8c4f",
      "parents": [
        "9a10987a2f160a44a638c9a35994ca6e3089696e"
      ],
      "author": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Thu Sep 10 14:06:27 2026 -0400"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:53:03 2026 -0400"
      },
      "message": "Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()\n\niso_get_sock() returns the parent socket with a reference held, which is\ndropped by sock_put() once the child socket has been set up. The error\npath taken when iso_sock_alloc() fails only calls release_sock() and\nreturns, leaking the reference and thus the parent socket itself.\n\nDrop the reference on that path as well.\n\nFixes: fa224d0c094a (\"Bluetooth: ISO: Reassociate a socket with an active BIS\")\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "9a10987a2f160a44a638c9a35994ca6e3089696e",
      "tree": "a51b2e71ef528643cf3c8cedfef5a46062b4897b",
      "parents": [
        "4e93c65f87825e1e012bce56615320aeb123815d"
      ],
      "author": {
        "name": "Chengfeng Ye",
        "email": "nicoyip.dev@gmail.com",
        "time": "Sat Aug 22 01:43:50 2026 +0800"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:52:31 2026 -0400"
      },
      "message": "Bluetooth: hci_sync: Serialize local codec list cleanup\n\nhci_dev_close_sync() clears hdev-\u003elocal_codecs after releasing hdev-\u003elock.\nCodec list additions and both traversals in sco_sock_getsockopt() use that\nlock, but the close path does not. A close and BT_CODEC query can therefore\ninterleave as follows:\n\n  hci_dev_close_sync()          sco_sock_getsockopt()\n                                hci_dev_lock()\n                                fetch codec entry\n  hci_codec_list_clear()\n    kfree(entry)\n                                read entry-\u003eid\n\nThe reader then accesses an entry which the close path has freed. KASAN\nreported:\n\n  BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0\n  Read of size 1 at addr ffff8881001c3450\n  Call Trace:\n   sco_sock_getsockopt+0xfa0/0xfe0\n   do_sock_getsockopt+0x537/0x7b0\n   __sys_getsockopt+0xf2/0x170\n  Allocated by task 92:\n   hci_codec_list_add.isra.0+0x2c/0x440\n   hci_read_codec_capabilities+0x224/0x590\n   hci_read_supported_codecs+0x2c2/0x640\n  Freed by task 92:\n   kfree+0x131/0x3c0\n   hci_codec_list_clear+0xd8/0x160\n   hci_dev_close_sync+0x92a/0xfa0\n\nTake hdev-\u003elock around the clear operation at its existing point in the\nclose path. This makes the clear wait for active readers and prevents a new\ntraversal until the list is empty without changing teardown ordering.\n\nFixes: b938790e7054 (\"Bluetooth: hci_codec: Fix leaking content of local_codecs\")\nCc: stable@vger.kernel.org\nSigned-off-by: Chengfeng Ye \u003cnicoyip.dev@gmail.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "4e93c65f87825e1e012bce56615320aeb123815d",
      "tree": "4b875025e0f0be221f0dbc9b80a58ca36f34e6e4",
      "parents": [
        "d0795cfd6f655f4de84868a4f4bb41a03f037b3d"
      ],
      "author": {
        "name": "Ibrahim Abdelkader",
        "email": "iabdelka@qti.qualcomm.com",
        "time": "Wed Aug 19 14:54:25 2026 +0200"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:52:19 2026 -0400"
      },
      "message": "Bluetooth: hci_qca: Do not write to the serial port after it is closed\n\nhci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP\nis set (for example, for the WCN399x family). A failed hci_dev_open_sync()\nfollowing a successful qca_setup() calls hdev-\u003eclose() but not\nhdev-\u003eshutdown(), so the port is closed while power-\u003evregs_on is left true.\nqca_serdev_remove() then passes its power-\u003evregs_on test and calls\nqca_power_off(), which writes to the closed port unconditionally.\n\nSeen on a WCN3988 by unbinding the driver after a controller failure. The\ntrace below is from a 7.0.0 based kernel, where qca_power_off() was still\nnamed qca_power_shutdown():\n\n  Unable to handle kernel NULL pointer dereference at virtual address\n  0000000000000038\n  Call trace:\n   tty_set_termios+0x50/0x238 (P)\n   ttyport_set_baudrate+0x84/0xc0\n   serdev_device_set_baudrate+0x24/0x40\n   qca_power_shutdown+0x158/0x1fc [hci_uart]\n   qca_serdev_remove+0x54/0x68 [hci_uart]\n   serdev_drv_remove+0x1c/0x2c\n   device_remove+0x4c/0x80\n   device_release_driver_internal+0x1cc/0x224\n   device_driver_detach+0x18/0x24\n   unbind_store+0xb4/0xc0\n\nCheck HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place\nit closes the port, before writing to it. The regulator disable is left\nunconditional so the controller is still powered down.\n\nThe dangling serport-\u003etty that turns this into a use-after-free is\naddressed in a separate patch.\n\nFixes: fa9ad876b8e0 (\"Bluetooth: hci_qca: Add support for Qualcomm Bluetooth chip wcn3990\")\nSigned-off-by: Ibrahim Abdelkader \u003ciabdelka@qti.qualcomm.com\u003e\nReviewed-by: Hans de Goede \u003cjohannes.goede@oss.qualcomm.com\u003e\nSigned-off-by: Hans de Goede \u003cjohannes.goede@oss.qualcomm.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "d0795cfd6f655f4de84868a4f4bb41a03f037b3d",
      "tree": "c9f512b876be54e1ce317c33b114cdfad08946ad",
      "parents": [
        "4914c499896121ae8b9d5b90f0abc5c8287ff396"
      ],
      "author": {
        "name": "Laxman Acharya Padhya",
        "email": "acharyalaxman8848@gmail.com",
        "time": "Mon Aug 24 21:42:36 2026 +0545"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:52:12 2026 -0400"
      },
      "message": "Bluetooth: hci_codec: validate vendor codec count length\n\nThe Read Local Supported Codecs parsers consume the variable-sized\nstandard codec array before parsing the vendor codec count.  Although the\ninitial reply-size check includes a vendor count byte in the fixed layout,\nit does not guarantee that the byte remains after the standard codec array.\n\nIf a controller reply ends immediately after that array, calculating the\nvendor codec array size reads vnd_codecs-\u003enum beyond the skb data.  Use\nskb_pull_data() to validate and consume each codec header before using its\ncount in both command variants.\n\nFixes: 8961987f3f5f (\"Bluetooth: Enumerate local supported codec and cache details\")\nFixes: 9ae664028a9e (\"Bluetooth: Add support for Read Local Supported Codecs V2\")\nCc: stable@vger.kernel.org\nSuggested-by: Luiz Augusto von Dentz \u003cluiz.dentz@gmail.com\u003e\nSigned-off-by: Laxman Acharya Padhya \u003cacharyalaxman8848@gmail.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "4914c499896121ae8b9d5b90f0abc5c8287ff396",
      "tree": "59e093b0ce32670b16621685c1e27e155f2bae24",
      "parents": [
        "d236517c264e41dc09833c708ef23bccb7a91219"
      ],
      "author": {
        "name": "Radek Podgorny",
        "email": "radek@podgorny.cz",
        "time": "Wed Sep 09 00:29:37 2026 +0200"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:50:25 2026 -0400"
      },
      "message": "Bluetooth: put the peer\u0027s on-air address on air when we cannot resolve\n\nAn identity address only reaches a peer that is advertising an RPA if the\ncontroller resolves it on our behalf. Where it cannot, the host has to put\nthe peer\u0027s on-air address on air itself.\n\nhci_connect_le() still swaps the caller\u0027s identity address for the peer\u0027s\ncached RPA before creating the connection, but __hci_conn_add() resolves\nthe RPA back to the identity address when it stores it, so the identity is\nwhat goes out. Storing the identity is right when the controller\ntranslates it on the way to the radio; without LL Privacy, or with this\npeer absent from the resolving list, nothing does.\n\nA peer advertising an RPA cannot answer its identity address, so the\nattempt burns a full create-connection timeout. That is not merely a slow\nconnect: a controller without extended scanning cannot scan while it is\ninitiating, so every dead attempt also takes the scanner off the air for\nthe whole timeout.\n\nMeasured on a CYW43438, which reports neither LL Privacy nor extended\nadvertising (LE features 3f 00 00 08 00 00 00 00), against a peer\nadvertising a resolvable private address the host holds the IRK for, with\nthe connection requested on the peer\u0027s identity address:\n\n  before: LE Create Connection to the identity address, public type\n          1.61s -\u003e 22.07s, then LE Create Connection Cancel\n          LE Connection Complete: Unknown Connection Identifier (0x02)\n  after:  LE Create Connection to the peer\u0027s RPA, random type\n          LE Connection Complete: Success\n\nAdvertising reports reaching the host per second, same window, same five\nunrelated devices on the adapter:\n\n  before   1s:2   [nothing from 2s through 21s]   22s:5  23s:3\n  after    0s:11 1s:5 2s:2 3s:5 4s:3 5s:4 ... 21s:2 22s:1 23s:2\n\nOne dead connect costs twenty seconds of scanning for every device on the\nadapter, not just the one being dialled.\n\nKeep the RPA in conn-\u003edst unless the controller will translate the\nidentity address: address resolution enabled and the peer\u0027s identity\nactually programmed into the resolving list. Testing ll_privacy_capable()\nalone would not be enough: it reports the feature bit, not whether\nresolution is switched on and not whether this peer is in the list.\nResolution is cleared with the other volatile flags on power-off and\nswitched off again while suspend pauses scanning, and a peer\u0027s IRK is only\nprogrammed along the accept list path, so a direct-connect target, a peer\nwithout HCI_CONN_FLAG_ADDRESS_RESOLUTION, and one that did not fit in a\nfull list are all absent from it.\n\nWith the peer programmed, the identity address stays in conn-\u003edst and the\ncontroller translates it: measured on an Intel controller, the host dials\nthe identity and LE Enhanced Connection Complete reports Resolved Public\nwith the peer\u0027s RPA in the separate peer resolvable private address field.\nWith the peer absent from the list the same setup dials the RPA itself.\n\nEverything downstream already copes with an RPA in conn-\u003edst: it is what\nevery outgoing LE connection stored before 14b06c3a88f7, the connection\ncomplete event names the address that was dialled, and\nle_conn_complete_evt() resolves it back to the identity once the link is\nup. ISO links keep the unconditional conversion: they are created from an\nexisting ACL or a periodic sync and never dial this address themselves.\n\nKeeping the RPA is only right while the peer is still using it, which is\nwhy the preceding patch drops the cached RPA as soon as the peer is seen\nadvertising its identity address. Without that, a peer that turns privacy\noff would be dialled on the address it abandoned rather than the one it\nis answering on.\n\nFixes: 14b06c3a88f7 (\"Bluetooth: HCI: Always use the identity address when initializing a connection\")\nAssisted-by: Claude:claude-opus-5\nAssisted-by: Claude:claude-fable-5\nSigned-off-by: Radek Podgorny \u003cradek@podgorny.cz\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "d236517c264e41dc09833c708ef23bccb7a91219",
      "tree": "42d30ac66bd9864333ff5af6d009b297f1d82ce8",
      "parents": [
        "4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9"
      ],
      "author": {
        "name": "Weiming Shi",
        "email": "bestswngs@gmail.com",
        "time": "Sun Sep 06 23:43:32 2026 +0800"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:49:41 2026 -0400"
      },
      "message": "Bluetooth: coredump: Quiesce dump work on unregister\n\nhci_devcd_handle_pkt_init() arms dump_timeout and coredump producers\nqueue dump_rx without holding an hdev reference. Unregister leaves both\nworks live, so disconnecting during an active dump lets them access hdev\nafter hci_release_dev() frees it.\n\nShut down coredump processing during unregister. Close the producer gate\nunder dump_q.lock before disabling both works, then free the active buffer\nand queued packets under hci_dev_lock. Serializing the gate with enqueue\nprevents controller-specific workers from adding packets after the final\npurge.\n\nFixes: 9695ef876fd1 (\"Bluetooth: Add support for hci devcoredump\")\nReported-by: syzbot+b170dbf55520ebf5969a@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003db170dbf55520ebf5969a\nReported-by: Aby Sam Ross \u003cabysamross@gmail.com\u003e\nLink: https://lore.kernel.org/r/20260322210849.68743-1-abysamross@gmail.com\nSuggested-by: Aby Sam Ross \u003cabysamross@gmail.com\u003e\nReported-by: Tristan Madani \u003ctristan@talencesecurity.com\u003e\nLink: https://lore.kernel.org/r/20260814231248.3096377-1-tristmd@gmail.com\nReported-by: Xiang Mei \u003cxmei5@asu.edu\u003e\nAssisted-by: OpenAI Codex:gpt-5\nSigned-off-by: Weiming Shi \u003cbestswngs@gmail.com\u003e\nReported-by: Xiang Mei \u003cxmei5@asu.edu\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9",
      "tree": "29a3afd91dcfe11acc1a589d2e3224e9a33e2cee",
      "parents": [
        "6610c6fe4b8936c232048e6049bf77c70a6f759c"
      ],
      "author": {
        "name": "Chandrashekar Devegowda",
        "email": "chandrashekar.devegowda@intel.com",
        "time": "Tue Sep 08 15:26:58 2026 +0530"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:49:34 2026 -0400"
      },
      "message": "Bluetooth: btintel_pcie: validate TX skb length in send_sync\n\nbtintel_pcie_prepare_tx() copies skb-\u003elen bytes into a fixed\nBTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy.\nOversized packets are currently rejected only in\nbtintel_pcie_send_frame(); any future caller of\nbtintel_pcie_send_sync() would silently overflow the DMA buffer.\n\nAdd the bounds check in btintel_pcie_send_sync() itself, right\nbefore skb_push() and the DMA copy.\n\nAssisted-by: Copilot:claude-sonnet-5 code-review code-generation\nFixes: 6e65a09f9275 (\"Bluetooth: btintel_pcie: Add *setup* function to download firmware\")\nSigned-off-by: Chandrashekar Devegowda \u003cchandrashekar.devegowda@intel.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "6610c6fe4b8936c232048e6049bf77c70a6f759c",
      "tree": "673a56885b94d4d1f6c279b998b65f86da4f5407",
      "parents": [
        "e8241766794cf551d787fa3a77c0d54bbea6f6aa"
      ],
      "author": {
        "name": "ThangNN99",
        "email": "ngocthang2710.1999@gmail.com",
        "time": "Sun Sep 06 22:21:27 2026 +0700"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:48:44 2026 -0400"
      },
      "message": "Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained\n\nhci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev-\u003etx_work\nunconditionally. They can run from the L2CAP/SCO/ISO socket send path\nwhile hci_dev_close_sync() is draining hdev-\u003eworkqueue (HCIDEVDOWN\nracing with a socket write). Since that queue_work() is not chained\nwork from the tx_work worker itself, __queue_work() sees the queue\nmarked __WQ_DRAINING, warns \"cannot queue %ps on wq %s\", and drops\nthe work:\n\n  WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work\n  Call Trace:\n   queue_work_on\n   l2cap_chan_send\n   l2cap_sock_sendmsg\n   ...\n\nhci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before\ndraining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()\ncheck it before queuing. Route the tx_work producers through the\nsame guard via a shared hci_sched_tx() helper.\n\nFixes: 525daaea459f (\"Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close\")\nReported-by: syzbot+b6919040d9958e2fc1ae@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003db6919040d9958e2fc1ae\nSigned-off-by: ThangNN99 \u003cngocthang2710.1999@gmail.com\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "6fb20c02710dabc2f63aa21cb23a154d76ef9921",
      "tree": "e76741241f710ec122bbf9c78e5dd76c64c9ee65",
      "parents": [
        "f6e7b42bf05b2427fb8a7a1d1c387a86638bb413",
        "057dac23d329d5c5ed62352f2659a39fd46c6d4a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 11:40:30 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 11:40:30 2026 -0700"
      },
      "message": "Merge tag \u0027cgroup-for-7.3-rc3-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup\n\nPull cgroup fix from Tejun Heo:\n\n - The task iterator could pick up a dying task whose refcount had\n   already dropped to zero and resurrect it, leading to a use-after-free\n   when reading cgroup.procs. Skip such tasks.\n\n* tag \u0027cgroup-for-7.3-rc3-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup:\n  cgroup: Avoid iteration of dying tasks with zero refcount\n"
    },
    {
      "commit": "e8241766794cf551d787fa3a77c0d54bbea6f6aa",
      "tree": "9922ad8b294f98836987474477c9025f0738e201",
      "parents": [
        "2b50adefed9808a56d84d1de803cad882cc787fa"
      ],
      "author": {
        "name": "Aamir Ahmed",
        "email": "elb12345@hotmail.co.uk",
        "time": "Mon Sep 07 00:37:43 2026 +0100"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:30:14 2026 -0400"
      },
      "message": "Bluetooth: eir: validate service data length before reading UUID\n\neir_get_service_data() reads a 16-bit UUID from the service data using\nget_unaligned_le16() without first checking that the data is long enough\nto hold a UUID16 (2 bytes). If a malformed EIR entry has a service data\nfield with only 1 byte of payload (field_len\u003d2), eir_get_data() returns\ndlen\u003d1. The subsequent get_unaligned_le16() then reads 1 byte past the\nfield boundary.\n\nAdditionally, if the corrupted UUID happens to match, the length\ncalculation \"dlen - 2\" underflows to SIZE_MAX since dlen is size_t.\nCurrent callers either pass NULL for the length parameter or bounds-check\nthe returned length, but future callers may not.\n\nAdd a check that dlen \u003e\u003d sizeof(u16) and skip fields that are too short\nto contain a valid UUID16.\n\nFixes: 8f9ae5b3ae80 (\"Bluetooth: eir: Add helpers for managing service data\")\nCc: stable@vger.kernel.org\nSigned-off-by: Aamir Ahmed \u003celb12345@hotmail.co.uk\u003e\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "2b50adefed9808a56d84d1de803cad882cc787fa",
      "tree": "b38428b8beaa65c81f07d7718b67364f3adbbb62",
      "parents": [
        "83a945a529d6e002dd7339c532288a931f463dba"
      ],
      "author": {
        "name": "Nicolas Thibert",
        "email": "nithibert@gmail.com",
        "time": "Tue Sep 08 10:01:08 2026 +0200"
      },
      "committer": {
        "name": "Luiz Augusto von Dentz",
        "email": "luiz.von.dentz@intel.com",
        "time": "Tue Sep 15 14:26:10 2026 -0400"
      },
      "message": "Bluetooth: btusb: fix NXP IW610 composite device handling\n\nThe NXP IW610 module exposes itself as a composite USB device\n(0471:0215) with three interfaces: two real Bluetooth HCI interfaces\n(class 0xe0) and one vendor-specific WiFi interface (class 0xff) used\nby mwifiex-nxp.\n\nThe composite device\u0027s whole USB descriptor reports class 0xe0/01/01\n(Bluetooth), so btusb_table\u0027s generic USB_DEVICE_INFO(0xe0, 0x01, 0x01)\nentry matches every interface, not just the two real HCI ones -- btusb\nends up binding the WiFi interface too, and mwifiex-nxp never gets it.\n\nFix:\n1. In btusb_table (the table the USB core actually matches against),\n   explicitly ignore the WiFi interface via BTUSB_IGNORE, ahead of the\n   generic entry.\n2. In quirks_table, scope the existing BTUSB_MARVELL entry to the BT\n   interface class instead of matching the whole device by VID/PID\n   (harmless either way since quirks_table isn\u0027t consulted for initial\n   binding, but keep it correct).\n\nNot upstream anywhere: checked NXP\u0027s own i.MX kernel fork\n(nxp-imx/linux-imx), no IW610 references in btusb.c on any branch --\ntheir reference designs wire this chip differently (WiFi over SDIO\nper their release notes), so they never hit this.\n\nSigned-off-by: Nicolas Thibert \u003cnithibert@gmail.com\u003e\nCc: stable@vger.kernel.org\nAssisted-by: LLM (Claude Sonnet 5, Anthropic)\nSigned-off-by: Luiz Augusto von Dentz \u003cluiz.von.dentz@intel.com\u003e\n"
    },
    {
      "commit": "a9e3760b0838299649c0d57cca44daaf40ba3c33",
      "tree": "95807ff0e511c05602ef34808cfc660303309057",
      "parents": [
        "9a0b159ff18c8f6fcf982bb81e15a9ceb14db43a"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Mon Sep 14 22:12:34 2026 -1000"
      },
      "committer": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Tue Sep 15 06:57:20 2026 -1000"
      },
      "message": "sched_ext: Maintain an online cid mask in the scheduler arena\n\nSchedulers on the default cid mapping treat [0, nr_online_cids) as the\nonline set and restart on hotplug. Schedulers that install their own mapping\nwith scx_bpf_cid_override() have no way to learn which cids are online: the\ncount no longer identifies members and the CPU-form cpumask is unusable from\ncid programs. This is an obvious hole in the cid API.\n\nAdd scx_bpf_online_cmask(), a kernel-maintained cmask in the scheduler\u0027s\narena, allocated alongside the per-CPU scratch masks and populated after the\ncid mapping is finalized and before ops.init(), for child schedulers too.\nThe pointer stays valid through ops.exit() with no reference to take. It is\nthe arena offset as a void pointer, the same form struct_ops arena arguments\narrive in. The verifier types the void return as a scalar for the program\u0027s\narena cast.\n\nThe mask follows the SCX hotplug notifications: seeded from cpu_active_mask\nand updated before ops.cid_online/offline() runs, so it lags cpu_online_mask\nonly inside a hotplug transition. Updates walk the scheduler list under the\nlock that also serializes unlinking. Reads are live, not atomic snapshots.\nRoot initialization excludes hotplug.\n\nv2: Reworded the getter kerneldoc (Andrea Righi).\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nReviewed-by: Andrea Righi \u003carighi@nvidia.com\u003e\n"
    },
    {
      "commit": "9a0b159ff18c8f6fcf982bb81e15a9ceb14db43a",
      "tree": "227dcf1362145ed7fb4c37d3915afc446ec525fe",
      "parents": [
        "c7a1c6e8004ab12a9c9bfdcb603f60f9bf4a3cee"
      ],
      "author": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Mon Sep 14 22:12:34 2026 -1000"
      },
      "committer": {
        "name": "Tejun Heo",
        "email": "tj@kernel.org",
        "time": "Tue Sep 15 06:57:19 2026 -1000"
      },
      "message": "sched_ext: scx_qmap: Restore unused idle claims from ops.dispatch()\n\nscx_qmap tracks idle cids itself. pick_direct_dispatch_cid() claims a cid by\nclearing its bit and the task is inserted into that cid\u0027s local DSQ, which\nkicks the CPU. When the task does not arrive, for example because the insert\nfell back to the global DSQ after an affinity change, the CPU wakes, finds\nnothing and picks idle again. That is not an idle transition, so\nops.update_idle() is not called and the cid stays marked busy until an\nunrelated task runs on it.\n\nRestore the claim from ops.dispatch(). The kick guarantees a dispatch on the\nkicked CPU, and when it finds nothing to run with a NULL @prev, the CPU is\ngoing back to idle. Document the pattern in ops.update_idle(), which reports\nonly actual transitions.\n\nSigned-off-by: Tejun Heo \u003ctj@kernel.org\u003e\nReviewed-by: Andrea Righi \u003carighi@nvidia.com\u003e\nCc: Andrea Righi \u003carighi@nvidia.com\u003e\n"
    },
    {
      "commit": "f6e7b42bf05b2427fb8a7a1d1c387a86638bb413",
      "tree": "9a0f43558466de114b05420028fd9f001c999d86",
      "parents": [
        "587858367581b9c55c3690f4e63382ad622719d4",
        "afdf35cfae0d039a4a6c907fa5d8391f1ef0a0aa"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 09:43:15 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Sep 15 09:43:15 2026 -0700"
      },
      "message": "Merge tag \u0027sysctl-7.03-fixes-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl\n\nPull sysctl fixes from Joel Granados:\n\n - Re-add the range check for millisecond to jiffy conversion in sysctl\n\n   They where removed in d174174c6776 (\"sysctl: replace\n   SYSCTL_INT_CONV_CUSTOM macro with functions\") and b96b5c6708ea\n   (\"sysctl: Replace do_proc_do{int,ulong,uint}vec with do_proc_vec\")\n\n - Fix type truncation in sysctl_msec_to_jiffies\n\n   Previously truncated millisecond values now get converted into\n   MAX_JIFFY_OFFSET\n\n* tag \u0027sysctl-7.03-fixes-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl:\n  sysctl: Fix type truncation in sysctl_msec_to_jiffies\n  sysctl: Check range in do_proc_ulong_conv_ms_jiffies\n  sysctl: Check range in  proc_dointvec_ms_jiffies_minmax\n"
    }
  ],
  "next": "83a945a529d6e002dd7339c532288a931f463dba"
}
