)]}'
{
  "log": [
    {
      "commit": "8cdeaa50eae8dad34885515f62559ee83e7e8dda",
      "tree": "179809e80b9b152a405a89197c6602fb1e38a439",
      "parents": [
        "f105f3631d51e8d7c49bf18ec21b873e4f38e648"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 14:44:06 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 14:44:06 2026 -1000"
      },
      "message": "Linux 7.2-rc2\n"
    },
    {
      "commit": "f105f3631d51e8d7c49bf18ec21b873e4f38e648",
      "tree": "3eb3ab98204b4fdccae2630e14aca2ebef99e3e4",
      "parents": [
        "c10dc5c03e17a9502325f3f49721a6058d162048",
        "fc16126cc11d9f507130bf84ab137ee0938c900e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:37:46 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:37:46 2026 -1000"
      },
      "message": "Merge tag \u0027x86-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull x86 fix from Ingo Molnar:\n\n - Prevent OOB access in the resctrl code while offlining\n   CPUs when Intel SNC (Sub-NUMA Clustering) is enabled\n   (Reinette Chatre)\n\n* tag \u0027x86-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled\n"
    },
    {
      "commit": "c10dc5c03e17a9502325f3f49721a6058d162048",
      "tree": "e393af5a43ba67fadb80dd24f900d9dd262cf528",
      "parents": [
        "fe5881ed7293813e492ad165292ae652b676ff6c",
        "169328645663bae30e9abad4012d52441e085a71"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:34:43 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:34:43 2026 -1000"
      },
      "message": "Merge tag \u0027perf-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull perf events fixes from Ingo Molnar:\n\n - Fix a perf_event_attr::remove_on_exec bug for group events\n   (Taeyang Lee)\n\n - Fix uprobes CALL emulation interaction with shadow stacks, and\n   add a testcase for this (David Windsor)\n\n - Fix uprobes unregister bug (Jiri Olsa)\n\n* tag \u0027perf-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline\n  selftests/x86: Add shadow stack uprobe CALL test\n  x86/uprobes: Keep shadow stack in sync for emulated CALLs\n  perf/core: Detach event groups during remove_on_exec\n"
    },
    {
      "commit": "fe5881ed7293813e492ad165292ae652b676ff6c",
      "tree": "bdc08c6d0aa58c69e21e7feebb5d86623c07aaab",
      "parents": [
        "610533cb3bd0aba501d14552c3bf1485eb427455",
        "39def6d250d370298f86c116f4ac60093cefadaa"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:31:41 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:31:41 2026 -1000"
      },
      "message": "Merge tag \u0027locking-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull futex fix from Ingo Molnar:\n\n - Fix a futex-requeue deadlock detection regression (Thomas Gleixner)\n\n* tag \u0027locking-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  futex/requeue: Revert \"Prevent NULL pointer dereference in remove_waiter() on self-deadlock\"\"\n"
    },
    {
      "commit": "610533cb3bd0aba501d14552c3bf1485eb427455",
      "tree": "a7dfbaf198d5b15baab206d93dd6a7e97d0a26a9",
      "parents": [
        "216a8b21797ff4ad8622a24a68f851918890e95d",
        "98bf7e54cec07d514b3575c11896a8b12d50ecc4"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:29:41 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:29:41 2026 -1000"
      },
      "message": "Merge tag \u0027irq-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull irq fixes from Ingo Molnar:\n \"Misc irqchip driver fixes:\n\n   - Fix a resource leak in the RISC-V imsic-early driver (Haoxiang Li)\n\n   - Fix an OF node reference leak in the ARM gic-v3-its driver (Yuho\n     Choi)\n\n   - Fix a dangling handler function on module removal bug in the\n     TS-4800 ARM board irqchip driver (Qingshuang Fu)\"\n\n* tag \u0027irq-urgent-2026-07-05\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  irqchip/ts4800: Fix missing chained handler cleanup on remove\n  irqchip/gic-v3-its: Fix OF node reference leak\n  irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure\n"
    },
    {
      "commit": "216a8b21797ff4ad8622a24a68f851918890e95d",
      "tree": "d6ba1dd22f2f6538a1c6c7ae3d9336f93e6a1078",
      "parents": [
        "9c9330c764b01519500a656cf3ffab76ff481878",
        "5720deab6da70d0676cee8a580f6146ef85a3ab9"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:26:45 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:26:45 2026 -1000"
      },
      "message": "Merge tag \u0027sound-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n\nPull sound fixes from Takashi Iwai:\n \"A standard set of driver-specific fixes and quirks accumulated since\n  the merge window:\n\n  ASoC:\n   - SOF: Sanity check to prevent OOB reads\n   - rsnd: Fix clock leak and double-disable issues with PM\n   - tas675x: Misc fixes for register fields, etc\n   - lpass-va-macro: Correct codec version for Qualcomm SC7280\n   - amd-yc: DMIC quirk for Alienware m15 R7 AMD\n\n  Others:\n   - us144mkii: Fix a UAF on disconnect and anchor list corruption\n   - HD-audio: Realtek quirks for HP models\"\n\n* tag \u0027sound-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound:\n  ASoC: rsnd: src: Add missing scu_supply clock to suspend/resume\n  Documentation: sound: tas675x: Fix temperature range and impedance documentation\n  ASoC: codecs: tas675x: Fix CHx temperature range register bit fields\n  ASoC: codecs: tas675x: use READ_ONCE for params to be used concurrently\n  ASoC: rsnd: adg: make rsnd_adg_clk_control() idempotent\n  ASoC: SOF: validate probe info element counts\n  ALSA: usx2y: us144mkii: fix work UAF on disconnect\n  ASoC: amd: yc: Add Alienware m15 R7 AMD to DMIC quirk table\n  ALSA: hda/realtek: Add quirk for HP Victus 16-e0xxx (88EE) to enable mute LED\n  MAINTAINERS: ASoC: SOF: add AMD reviewer for Sound Open Firmware\n  ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280\n  ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission\n"
    },
    {
      "commit": "9c9330c764b01519500a656cf3ffab76ff481878",
      "tree": "ce0bb72e704152e6dfc58c4c38862ab302bea77b",
      "parents": [
        "7404ce51637231382873d0b55edabc2f3b841a9d",
        "7fc2c3dcae28347a30ccd76c8817e5719005f1c3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:24:06 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jul 05 05:24:06 2026 -1000"
      },
      "message": "Merge tag \u0027spi-fix-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi\n\nPull spi fixes from Mark Brown:\n \"A small set of fixes that came in since -rc1, we have one core fix for\n  shutting down target mode properly if the system suspends while it\u0027s\n  running plus a small set of fairly unremarkable device specific fixes.\n  There\u0027s also a couple of pure DT binding changes for Renesas SoCs, the\n  power domains one allows some SoCs to be correctly described with\n  existing code\"\n\n* tag \u0027spi-fix-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:\n  spi: rzv2h-rspi: Fix DMA transfer error handling for signal interruption\n  spi: dt-bindings: snps,dw-apb-ssi: add \u0027power-domains\u0027 property\n  spi: dt-bindings: snps,dw-apb-ssi: drop superfluous RZ/N1 entry\n  spi: dw: use the correct error msg if request_irq() fails\n  spi: dw: fix first spi transfer with dma always fallback to PIO\n  spi: core: Abort active target transfer on controller suspend\n  spi: sh-msiof: abort transfers when reset times out\n"
    },
    {
      "commit": "7404ce51637231382873d0b55edabc2f3b841a9d",
      "tree": "402d966ef2d808c4a3ae5c09bbbd6368c7611b73",
      "parents": [
        "410430b616a739eb395143f4f608d4339a3b0a8f",
        "2995ccec260caa9e85b3301a4aba1e66ed80ad74"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jul 04 06:28:45 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jul 04 06:28:45 2026 -1000"
      },
      "message": "Merge tag \u0027s390-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux\n\nPull s390 fixes from Vasily Gorbik:\n\n - Fix PKEY_VERIFYPROTK ioctl key type handling by removing the generic\n   key-length based type check with its wrong bit-size calculation, and\n   leaving protected key verification to the pkey handler\n\n - Fix monwriter buffer reuse by rejecting records that change the data\n   length, preventing out of bounds user copy into the kernel buffer\n\n* tag \u0027s390-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux:\n  s390/monwriter: Reject buffer reuse with different data length\n  pkey: Move keytype check from pkey api to handler\n"
    },
    {
      "commit": "410430b616a739eb395143f4f608d4339a3b0a8f",
      "tree": "d8adae9cb020ed909ff2402ecd27bfa9df59023d",
      "parents": [
        "1e9cdc2ea15adf4a821eefedabf6c0c8cf0b6a55",
        "0880884b36d1230a80a0322abc9b9c7b26942b65"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jul 04 06:05:28 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jul 04 06:05:28 2026 -1000"
      },
      "message": "Merge tag \u0027mips-fixes_7.2_1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux\n\nPull MIPS fixes from Thomas Bogendoerfer.\n\n* tag \u0027mips-fixes_7.2_1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux:\n  MIPS: configs: Enable the current Ingenic USB PHY symbol\n  MIPS: loongson64: add IRQ work based on self-IPI\n  MIPS: mm: Add check for highmem before removing memory block\n  mips: Add build salt to the vDSO\n  MIPS: DEC: Ensure RTC platform device deregistration upon failure\n"
    },
    {
      "commit": "1e9cdc2ea15adf4a821eefedabf6c0c8cf0b6a55",
      "tree": "c81f3227b4965d9139a1adcb53f1168b7a391315",
      "parents": [
        "dac0b8c58757eba9deb0fdd32d37a85bbb06006d",
        "f363a0fb134a3eb9e47368b1edbd251fd76be84b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 18:55:34 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 18:55:34 2026 -1000"
      },
      "message": "Merge tag \u0027v7.2-rc1-smb3-server-fixes\u0027 of git://git.samba.org/ksmbd\n\nPull smb server fixes from Steve French:\n\n - Fix several use-after-free races in durable handle reconnect,\n   supersede, and oplock handling\n\n - Avoid holding the inode oplock lock while waiting for a lease break\n   acknowledgement. This removes delays of up to 35 seconds when cifs.ko\n   closes a deferred handle in response to a lease break\n\n - Fix malformed security descriptor handling, including an undersized\n   DACL allocation issue and an out-of-bounds ACE SID read\n\n - Fix memory leaks in security descriptor and DOS attribute xattr\n   encoding/decoding error paths\n\n - Fix outstanding SMB2 credit leaks on aborted requests and correct the\n   QUERY_INFO credit charge calculation\n\n - Fix hard-link creation without replacement being incorrectly rejected\n   when the handle lacks DELETE access\n\n - Avoid unnecessary zeroing of large SMB2 read buffers\n\n - Add an oplock list lockdep annotation and update the documented\n   support status for durable handles and SMB3.1.1 compression\n\n - Durable handle fixes to address ownership and lifetime races during\n   reconnect, session teardown, oplock handling, and superseding opens,\n   preventing stale session and file references from being used by\n   concurrent operations\n\n* tag \u0027v7.2-rc1-smb3-server-fixes\u0027 of git://git.samba.org/ksmbd:\n  ksmbd: fix app-instance durable supersede session UAF\n  ksmbd: snapshot previous oplock state before durable checks\n  ksmbd: close superseded durable handles through refcount handoff\n  ksmbd: fix use-after-free of fp-\u003eowner.name in durable handle owner check\n  smb/server: do not require delete access for non-replacing links\n  ksmbd: don\u0027t hold ci-\u003em_lock while waiting for a lease break ack\n  ksmbd: doc: update feature support status for durable handles and compression\n  ksmbd: annotate oplock list traversals under m_lock\n  ksmbd: fix outstanding credit leak on abort and error paths\n  ksmbd: fix credit charge calculation for SMB2 QUERY_INFO\n  ksmbd: avoid zeroing the read buffer in smb2_read()\n  ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl\n  ksmbd: reject undersized DACLs before parsing ACEs\n  ksmbd: fix n.data memory leak in ksmbd_vfs_set_dos_attrib_xattr\n  ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling\n  ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr\n"
    },
    {
      "commit": "dac0b8c58757eba9deb0fdd32d37a85bbb06006d",
      "tree": "03cdd6031497bce9cf63e4e60b408ca1ae1c12c7",
      "parents": [
        "e6174e9b38e766cdfcfed41ffd8be35c504a9963",
        "acd7c71ba8d83808fa8d704196f3d53f7d58cf50"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:42:20 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:42:20 2026 -1000"
      },
      "message": "Merge tag \u0027drm-fixes-2026-07-04\u0027 of https://gitlab.freedesktop.org/drm/kernel\n\nPull drm fixes from Dave Airlie:\n \"Weekly fixes for drm. This is large for rc2 but it\u0027s just a lot of\n  small fixes across a bunch of drivers, xe, amdgpu as usual, plus some\n  sashiko-inspired fixes for panthor, and some dma-fence updates.\n\n  core:\n   - kernel doc fix\n   - include types.h in drm_ras.h\n\n  dma-fence:\n   - fix NULL ptr dereference\n   - use correct callback\n   - make dma_fence_dedup_array more robust\n\n  dp:\n   - handle torn down topology gracefully\n   - fix kernel doc\n\n  i915:\n   - Input validation fixes for BIOS and EDID\n   - Fix HDCP code buffer overflow and seq_num_v monotonic increase check\n   - Fix near-NULL deref in i915_active during GFP_ATOMIC exhaustion\n\n  xe:\n   - Wedge from the timeout handler only after releasing the queue\n   - Fix a NULL pointer dereference\n   - Remove redundant exec_queue_suspended\n   - RTP / OA whitelist fixes\n   - Return error on non-migratable faults requiring devmem\n   - Skip FORCE_WC and vm_bound check for external dma-bufs\n   - Hold notifier lock for write on inject test path\n   - Drop bogus static from finish in force_invalidate\n   - Fix double-free of managed BO in error path\n   - Don\u0027t attempt to process FAST_REQ or EVENT relays\n   - Fix NPD in bo_meminfo\n   - Prevent invalid cursor access for purged BOs\n   - Fix offset alignment for MERT WHITELST_OA_MERT_MMIO_TRG\n\n  amdgpu:\n   - Soc24 aborted suspend fix\n   - Drop unecessary BUG() and BUG_ON() from error paths\n   - SCPM fix\n   - Power reporting fix\n   - DCE HDR fix\n   - UVD boundary checks\n   - VCN boundary checks\n   - VCE boundary checks\n   - DCN 4.2 fixes\n   - Large stack allocation fixes\n   - Fix aperture mapping leak\n   - UserQ fixes\n   - Ignore_damage_clips fix\n   - ACP fixes\n   - DC boundary checks\n   - GPUVM fixes\n   - JPEG idle check fixes\n   - Userptr fix\n   - GC 11.7 updates\n   - Non-4K page fix\n   - SMU 13 fixes\n   - DP alt mode fix\n\n  amdkfd:\n   - Boundary checks\n   - CRIU fixes\n\n  amdxdna:\n   - fix device removal issues\n   - fix use after free in debug BO\n\n  imagination:\n   - fix double call to scheduler fini\n   - fix ioctl return values\n   - fix user array stride\n\n  virtio:\n   - handle EDIDs better\n\n  panthor:\n   - irq safe fence lock fix\n   - reset work fix\n   - fix invalid pointer\n   - fix iomem access in suspended state\n   - sched resume fix\n   - unplug suspend fix\n   - drop needless check\n   - eviction leak fix\n   - bail on group start/resume fix\n   - keep irqs masked\n\n  malidp:\n   - use clock bulk API\n\n  komeda:\n   - clock prepare fixes\"\n\n* tag \u0027drm-fixes-2026-07-04\u0027 of https://gitlab.freedesktop.org/drm/kernel: (105 commits)\n  drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG\n  drm/xe/pt: prevent invalid cursor access for purged BOs\n  drm/xe: fix NPD in bo_meminfo()\n  drm/xe/pf: Don\u0027t attempt to process FAST_REQ or EVENT relays\n  drm/xe/hw_engine: Fix double-free of managed BO in error path\n  drm/xe/userptr: Drop bogus static from finish in force_invalidate\n  drm/xe/userptr: Hold notifier_lock for write on inject test path\n  drm/xe/display: skip FORCE_WC and vm_bound check for external dma-bufs\n  drm/xe: Return error on non-migratable faults requiring devmem\n  drm/xe/rtp: Ensure locking/ref counting for OA whitelists\n  drm/xe/oa: (De-)whitelist OA registers on OA stream open/release\n  drm/xe/rtp: (De-)whitelist OA registers for all hwe\u0027s for a gt\n  drm/xe/rtp: Toggle \u0027deny\u0027 bit to (de-)whitelist OA regs\n  drm/xe/rtp: Save OA nonpriv registers to register save/restore lists\n  drm/xe/rtp: Generalize whitelist_apply_to_hwe\n  drm/xe/rtp: Keep track of non-OA nonpriv slots\n  drm/xe/rtp: Maintain OA whitelists separately\n  drm/xe/rtp: Fix build error with clang \u003c 21 and non-const initializers\n  drm/imagination: Fix user array stride in pvr_set_uobj_array()\n  drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY\n  ...\n"
    },
    {
      "commit": "e6174e9b38e766cdfcfed41ffd8be35c504a9963",
      "tree": "61fe44b6482ff376836d12bb01d99c3452113a3b",
      "parents": [
        "590cae7152cab2dd954b8db20522769e1c62deec",
        "973772c7cf647cf4da6badd86c484f9b350eea18"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:13:50 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:13:50 2026 -1000"
      },
      "message": "Merge tag \u0027acpi-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n\nPull ACPI support fixes from Rafael Wysocki:\n \"These fix a coding mistake in the ACPI TAD (Time and Alarm\n  Device) driver introduced by one of its previous updates and\n  get rid of the ugly #ifdef __KERNEL__ conditional compilation\n  in acpi_ut_safe_strncpy() by redefining that function as an\n  alias for strscpy_pad():\n\n   - Add a missing ACPI_TAD_AC_WAKE capability check omitted by mistake\n     to the ACPI TAD driver (Xu Rao)\n\n   - Define acpi_ut_safe_strncpy() as an alias for strscpy_pad()\n     which is viable because that function is only called from kernel\n     code (Rafael Wysocki)\"\n\n* tag \u0027acpi-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:\n  ACPICA: Define acpi_ut_safe_strncpy() as strscpy_pad() alias\n  ACPI: TAD: Check AC wake capability before enabling wakeup\n"
    },
    {
      "commit": "590cae7152cab2dd954b8db20522769e1c62deec",
      "tree": "a504cadde7504478d5ee801c4c60278c4b88cc21",
      "parents": [
        "6cf48bfec934834ade6e0f5745f9afdbddbe446d",
        "bc7b086a45521a986a49045907f017e3e46c763e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:07:24 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:07:24 2026 -1000"
      },
      "message": "Merge tag \u0027riscv-for-linus-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux\n\nPull RISC-V fixes from Paul Walmsley:\n\n - Fix a crash when a kretprobe reads from the stack\n\n - Fix an issue with the build-time mcount sorter that broke ftrace\n\n - Fix the rv32 IRQ stack frame padding to match the ABI\n\n - Only defer IOMMU configuration during initialization. This avoids an\n   issue where IOMMU configuration could be indefinitely deferred\n\n - Add the missing build salt to the vDSO\n\n - Now that RISC-V systems with higher numbers of cores are starting to\n   become available, raise NR_CPUS for RISC-V to 256\n\n - Clean up some warnings from sparse caused by the RISC-V-optimized\n   RAID6 code\n\n - Clean up our __cpu_up() code with a few minor fixes\n\n* tag \u0027riscv-for-linus-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux:\n  riscv: probes: save original sp in rethook trampoline\n  riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI\n  scripts/sorttable: Handle RISC-V patchable ftrace entries\n  riscv: smp: use secs_to_jiffies in __cpu_up\n  ACPI: RIMT: Only defer the IOMMU configuration in init stage\n  riscv: Add build salt to the vDSO\n  raid6: fix raid6_recov_rvv symbol undeclared warning\n  raid6: fix riscv symbol undeclared warnigns\n  riscv: Raise default NR_CPUS for 64BIT to 256\n"
    },
    {
      "commit": "6cf48bfec934834ade6e0f5745f9afdbddbe446d",
      "tree": "238e0d5573efdf137468ce28beb23e8bda9188e2",
      "parents": [
        "71dfdfb0209b43dfd6f494f84f5548e4cfd18cb5",
        "c16b8c4cfb4fe2244cc33e469a93c1ab8684146b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:01:33 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 15:01:33 2026 -1000"
      },
      "message": "Merge tag \u0027v7.2-rc1-smb3-client-fixes\u0027 of git://git.samba.org/sfrench/cifs-2.6\n\nPull smb client fixes from Steve French:\n\n - Credit fix\n\n - Fix alignment issue in parse_posix_ctxt\n\n - SID parsing fix\n\n* tag \u0027v7.2-rc1-smb3-client-fixes\u0027 of git://git.samba.org/sfrench/cifs-2.6:\n  cifs: Fix missing credit release on failure in cifs_issue_read()\n  cifs: update internal module version number\n  smb: client: use unaligned reads in parse_posix_ctxt()\n  smb: client: harden POSIX SID length parsing\n"
    },
    {
      "commit": "973772c7cf647cf4da6badd86c484f9b350eea18",
      "tree": "1189820bec0019f64c1ea58b976909d840aa8af2",
      "parents": [
        "9825cf2cb59fac7480e7fac9eee13ab9af3f1ea8",
        "8522d806d84e2c3816c275ae6dd79e124c1b3dac"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jul 03 20:28:08 2026 +0200"
      },
      "committer": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jul 03 20:28:08 2026 +0200"
      },
      "message": "Merge branch \u0027acpi-tad\u0027\n\nMerge an ACPI TAD (Time and Alarm Device) driver fix for 7.2-rc2.\n\n* acpi-tad:\n  ACPI: TAD: Check AC wake capability before enabling wakeup\n"
    },
    {
      "commit": "71dfdfb0209b43dfd6f494f84f5548e4cfd18cb5",
      "tree": "cfe70d8de248fc18924b14f05d6315282d6febc7",
      "parents": [
        "025d0d6221d9b060bce251427c671cd0080d9dae",
        "5c6ce05e406520290c1d89da97fb3cd70c09137d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:48:05 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:48:05 2026 -1000"
      },
      "message": "Merge tag \u0027vfs-7.2-rc2.fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs\n\nPull vfs fixes from Christian Brauner:\n\n - netfs:\n\n    - fix the decision when to disallow write-streaming with fscache in\n      use, handling of asynchronous cache object creation, a double fput\n      in cachefiles, clearing S_KERNEL_FILE without the inode lock held,\n      page extraction bugs in the iov_iter helpers (a potential\n      underflow, a missing allocation failure check, a memory leak, and\n      a folio offset miscalculation), writeback error and ENOMEM\n      handling, DIO write retry for filesystems without a\n      -\u003eprepare_write() method, and the replacement of the wb_lock mutex\n      with a bit lock plus writethrough collection offload so that\n      multiple asynchronous writebacks don\u0027t interfere with each other.\n\n    - Fix the barriering when walking the netfs subrequest list during\n      retries as it was possible to see a subrequest that was just added\n      by the application thread.\n\n - iomap:\n\n    - Change iomap to submit read bios after each extent instead of\n      building them up across extents. The old behavior was considered\n      problematic for a while and now caused an actual erofs bug.\n\n    - Guard the ioend io_size EOF trim in iomap against underflow when a\n      concurrent truncate moves EOF below the start of the ioend,\n      wrapping io_size to a huge value.\n\n - overlayfs\n\n    - Fix a stale overlayfs comment about the locking order.\n\n    - Store the linked-in upper dentry instead of the disconnected\n      O_TMPFILE dentry during overlayfs tmpfile copy-up. With a FUSE or\n      virtiofs upper layer -\u003ed_revalidate() would try to look up \"/\" in\n      the workdir and fail, causing persistent ESTALE errors that broke\n      dpkg and apt.\n\n - vfs-bpf:\n\n   Have the bpf_real_data_inode() kfunc take a struct file instead of a\n   dentry so it is usable from the bprm_check_security, mmap_file, and\n   file_mprotect hooks, and rename it from bpf_real_inode() to make the\n   data-inode semantics explicit. The kfunc landed this cycle so the\n   change is safe.\n\n - afs:\n\n   NULL pointer dereferences in the callback service and in\n   afs_get_tree(), several memory and refcount leaks, missing locking\n   around the dynamic root inode numbers and premature cell exposure\n   through /afs, a netns destruction hang caused by a misplaced\n   increment of net-\u003ecells_outstanding, a bulk lookup malfunction caused\n   by the dir_emit() API change, inode (re)initialisation issues, and\n   assorted smaller fixes to error codes, seqlock handling, and debug\n   output.\n\n - vfs:\n\n   Refuse O_TMPFILE creation with an unmapped fsuid or fsgid and add a\n   selftest for it.\n\n - vboxsf:\n\n   Add Jori Koolstra as vboxsf maintainer, taking over from Hans de\n   Goede.\n\n - dio:\n\n   Release the pages attached to a short atomic dio bio; the REQ_ATOMIC\n   size check error path leaked them.\n\n - procfs:\n\n   Only bump the parent directory link count when registering\n   directories in procfs. Registering regular files inflated the count\n   and leaked a link on every create and remove cycle.\n\n - minix:\n\n   Avoid an unsigned overflow in the minix bitmap block count\n   calculation that let crafted images with huge inode or zone counts\n   pass superblock validation and crash the kernel during mount.\n\n - cachefiles:\n\n   Fix a double unlock in the cachefiles nomem_d_alloc error path left\n   over from the start_creating() conversion.\n\n - fat:\n\n   Stop fat from reading directory entries past the 0x00\n   end-of-directory marker. If the trailing on-disk slots aren\u0027t\n   zero-filled the driver surfaced arbitrary garbage as directory\n   entries.\n\n - freexvfs:\n\n   Don\u0027t BUG() on unknown typed-extent types in freevxfs, reachable via\n   ioctl(FIBMAP) on a crafted image; fail with an I/O error instead.\n\n - orangefs:\n\n   Keep the readdir entry size 64-bit in orangefs fill_from_part().\n   Truncating it to __u32 bypassed the bounds check and led to\n   out-of-bounds reads triggerable by the userspace client.\n\n - xfs:\n\n   Fix the error unwind in xfs_open_devices() which released the rt\n   device file twice and left dangling buftarg pointers behind that were\n   freed again when the failed mount was torn down.\n\n - exec:\n\n   Fix an off-by-one in the comment documenting the maximum binfmt\n   rewrite depth in exec_binprm(). The code allows five rewrites, not\n   four; restricting the code would break userspace so the comment is\n   fixed instead.\n\n - file handles:\n\n   Reject detached mounts in capable_wrt_mount(). A detached mount can\n   be dissolved concurrently, leaving a NULL mount namespace that\n   open_by_handle_at() would dereference.\n\n* tag \u0027vfs-7.2-rc2.fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs: (57 commits)\n  netfs: Fix barriering when walking subrequest list\n  iomap: submit read bio after each extent\n  fuse: call fuse_send_readpages explicitly from fuse_readahead\n  iomap: consolidate bio submission\n  fhandle: reject detached mounts in capable_wrt_mount()\n  netfs: Fix DIO write retry for filesystems without a -\u003eprepare_write()\n  netfs: Fix folio state after ENOMEM whilst under writeback iteration\n  netfs: Fix writeback error handling\n  netfs: Fix writethrough to use collection offload\n  netfs: Replace wb_lock with a bit lock for asynchronicity\n  netfs: Fix kdoc warning\n  scatterlist: Fix offset in folio calc in extract_xarray_to_sg()\n  iov_iter: Remove unused variable in kunit_iov_iter.c\n  iov_iter: Fix a memory leak in iov_iter_extract_user_pages()\n  iov_iter: Fix missing alloc fail check in iov_iter_extract_bvec_pages()\n  iov_iter: Fix potential underflow in iov_iter_extract_xarray_pages()\n  cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE\n  cachefiles: Fix double fput\n  netfs: Fix netfs_create_write_req() to handle async cache object creation\n  netfs: Fix decision whether to disallow write-streaming due to fscache use\n  ...\n"
    },
    {
      "commit": "025d0d6221d9b060bce251427c671cd0080d9dae",
      "tree": "73437f1b164beaca429ebe1dbe510dd34064f65e",
      "parents": [
        "4dbc94bcc2df0c3bba40318c0751a8f487486783",
        "e4281086ae6caf006b6ef0670479eb5f96880fb9"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:44:56 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:44:56 2026 -1000"
      },
      "message": "Merge tag \u0027xfs-fixes-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux\n\nPull xfs fixes from Carlos Maiolino:\n \"A collection of bugfixes and some small code refactoring\"\n\n* tag \u0027xfs-fixes-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux:\n  xfs: simplify __xfs_buf_ioend\n  xfs: fix handling of synchronous errors in xfs_buf_submit\n  xfs: remove xfs_buf_ioend\n  xfs: improve the xfs_buf_ioend_fail calling convention\n  xfs: use null daddr for unset first bad log block\n  xfs: fix memory leak in xfs_dqinode_metadir_create()\n  xfs: release dquot buffer after dqflush failure\n  xfs: also mark the buffer stale on verifier failure in xfs_buf_submit\n  xfs: open code xfs_buf_ioend_fail in xfs_buf_submit\n  xfs: fix AGFL extent count calculation in xrep_agfl_fill\n  xfs: simplify the failure path in xfs_buf_alloc_vmalloc\n  xfs: fix incorrect use of gfp flags in xfs_buf_alloc_backing_mem\n  xfs: lift setting __GFP_NOFAIL from xfs_buf_alloc_kmem to the caller\n  xfs: split up xfs_buf_alloc_backing_mem\n"
    },
    {
      "commit": "4dbc94bcc2df0c3bba40318c0751a8f487486783",
      "tree": "ae7ef52224c58b9cf2366ef5534ca2bf1ade019b",
      "parents": [
        "2916bfc6baf7e1215b00169d285b88321299b629",
        "fcd245ea7528d50fddffc0fd1308941a9180f5b3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:40:58 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:40:58 2026 -1000"
      },
      "message": "Merge tag \u0027for-linus-7.2a-rc2-tag\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/xen/tip\n\nPull xen fixes from Juergen Gross:\n\n - rename function parameters and a comment related to\n   xen_exchange_memory() (Jan Beulich)\n\n - replace __ASSEMBLY__ with __ASSEMBLER__ (Thomas Huth)\n\n - add some sanity checking to the Xen pvcalls frontend driver (Michael\n   Bommarito)\n\n - fix error handling in the Xen gntdev driver (Wentao Liang)\n\n - fix several minor bugs in Xen related drivers (Yousef Alhouseen)\n\n* tag \u0027for-linus-7.2a-rc2-tag\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/xen/tip:\n  x86/Xen: correct commentary and parameter naming of xen_exchange_memory()\n  xenbus: reject unterminated directory replies\n  xen/gntalloc: validate grant count before allocation\n  xen/gntalloc: make grant counters unsigned\n  xen/front-pgdir-shbuf: free grant reference head on errors\n  xen/gntdev: fix error handling in ioctl\n  xen: Replace __ASSEMBLY__ with __ASSEMBLER__ in header files\n  xen/pvcalls: bound backend response req_id before indexing rsp[]\n"
    },
    {
      "commit": "2916bfc6baf7e1215b00169d285b88321299b629",
      "tree": "43a52eae72147759d5d398ac44dd4a8effa05dca",
      "parents": [
        "d2c9a99135da931377240942d44f3dea104cedb8",
        "9777530157e7b82fd994327ff878c4245dadc931"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:38:12 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jul 03 05:38:12 2026 -1000"
      },
      "message": "Merge tag \u0027gpio-fixes-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull gpio fixes from Bartosz Golaszewski:\n\n - check the return value of gpiochip_add_data() in gpio-mvebu and\n   gpio-htc-egpio\n\n - avoid locking context issues with GPIO drivers using the shared GPIO\n   proxy by only allowing sleeping operations (atomic GPIO ops don\u0027t\n   really make sense in shared context anyway)\n\n - with the above: restore non-sleeping GPIO access in pinctrl-meson\n\n - fix return value on OOM in gpio-timberdale\n\n - fix interrupt handling in gpio-mt7621\n\n - support both A and B variants of NCT6126D in gpio-f7188x\n\n* tag \u0027gpio-fixes-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  pinctrl: meson: restore non-sleeping GPIO access\n  gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe\n  gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips\n  gpio: mt7621: more robust management of IRQ domain teardown\n  gpio: mt7621: avoid corruption of shared interrupt trigger state\n  gpio: shared-proxy: always serialize with a sleeping mutex\n  gpio-f7188x: Add support for NCT6126D version B\n  gpio: htc-egpio: use managed gpiochip registration\n  gpio: mvebu: fail probe if gpiochip registration fails\n"
    },
    {
      "commit": "5c6ce05e406520290c1d89da97fb3cd70c09137d",
      "tree": "a8d156448b9d572cd8f6b031b4b1a54c47bfd317",
      "parents": [
        "24dddc384fb9aec2d7eea5463ca6dac98a3b3854"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Thu Jul 02 09:23:02 2026 +0100"
      },
      "committer": {
        "name": "Christian Brauner",
        "email": "brauner@kernel.org",
        "time": "Fri Jul 03 11:52:41 2026 +0200"
      },
      "message": "netfs: Fix barriering when walking subrequest list\n\nFix the barriering used when walking the subrequest list in retry as\nthere\u0027s a possibility of seeing a subreq that\u0027s just been added by the\napplication thread.\n\nFixes: ee4cdf7ba857 (\"netfs: Speed up buffered reading\")\nFixes: 288ace2f57c9 (\"netfs: New writeback implementation\")\nLink: https://sashiko.dev/#/patchset/20260608145432.681865-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nLink: https://patch.msgid.link/138807.1782980582@warthog.procyon.org.uk\nReviewed-by: Paulo Alcantara (Red Hat) \u003cpc@manguebit.org\u003e\ncc: Paulo Alcantara \u003cpc@manguebit.org\u003e\ncc: netfs@lists.linux.dev\ncc: linux-fsdevel@vger.kernel.org\nSigned-off-by: Christian Brauner (Amutable) \u003cbrauner@kernel.org\u003e\n"
    },
    {
      "commit": "5720deab6da70d0676cee8a580f6146ef85a3ab9",
      "tree": "eebb82e1aee7e9185bf6bd4dae1a0e9fb67b08c1",
      "parents": [
        "147996e7e7c9e8339c0e04f6fa7ccb3e4d448ff7",
        "83245e7a436c04e511378af14dd81fd188b41541"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jul 03 09:30:30 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jul 03 09:30:30 2026 +0200"
      },
      "message": "Merge tag \u0027asoc-fix-v7.2-rc1\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus\n\nASoC: Fixes for v7.2\n\nA fairly standard set of driver specific fixes and quirks that have come\nin since the merge window, plus a MAINTAINERS update.  The tas675x\nREAD_ONCE change is probably not actually fixing issues properly but we\nneed a whole new approach to concurrency there and it came along with\nsome good fixes.\n"
    },
    {
      "commit": "d2c9a99135da931377240942d44f3dea104cedb8",
      "tree": "2030fc72fd9abbf784155bb8b50efa0d906aa957",
      "parents": [
        "c85167c926e0b1a9213ecc9040eb355f90426832",
        "995832b2cebe6969d1b42635db698803ee31294d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 20:54:26 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 20:54:26 2026 -1000"
      },
      "message": "Merge tag \u0027device-id-rework\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux\n\nPull mod_devicetable.h header split from Uwe Kleine-König:\n \"Split \u003clinux/mod_devicetable.h\u003e in per subsystem headers\n\n  \u003clinux/mod_devicetable.h\u003e is included transitively in nearly every\n  driver in an x86_64 allmodconfig build of v7.1:\n\n      $ find drivers -name \\*.o -not -name \\*.mod.o | wc -l\n      21330\n      $ find drivers -name \\*.o.cmd -not -name \\*.mod.o.cmd | xargs grep -l mod_devicetable.h | wc -l\n      17038\n\n  The result of this mixture of different and unrelated subsystem\n  details is that even when touching an obscure device id struct most of\n  the kernel needs to be recompiled. Given that each driver typically\n  only needs one or two of these structures, splitting into per\n  subsystem headers and only including what is really needed reduces the\n  amount of needed recompilation.\n\n  This split is implemented in the first commit and then after some\n  preparatory work in the following commits, the last two replace\n  includes of \u003clinux/mod_devicetable.h\u003e by the actually needed more\n  specific headers.\n\n  There are still a few instances left, but the ones with high impact\n  (that is in headers that are used a lot) and the easy ones (.c files)\n  are handled. These remaining includes will be addressed during the\n  next merge window\"\n\n* tag \u0027device-id-rework\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux:\n  Replace \u003clinux/mod_devicetable.h\u003e by more specific \u003clinux/device-id/*.h\u003e (c files)\n  Replace \u003clinux/mod_devicetable.h\u003e by more specific \u003clinux/device-id/*.h\u003e (headers)\n  parisc: #include \u003clinux/compiler.h\u003e for unlikely() in \u003casm/ptrace.h\u003e\n  media: em28xx: Add include for struct usb_device_id\n  LoongArch: KVM: Add include defining struct cpu_feature\n  ALSA: hda/core: Add include defining struct hda_device_id\n  usb: dwc2: Add include defining struct pci_device_id\n  platform/x86: int3472: Add include defining struct dmi_system_id\n  platform/x86: x86-android-tablets: Add include defining struct dmi_system_id\n  i2c: Let i2c-core.h include \u003clinux/i2c.h\u003e\n  of: Explicitly include \u003clinux/types.h\u003e and \u003clinux/err.h\u003e\n  platform/x86: msi-ec: Ensure dmi_system_id is defined\n  usb: serial: Include \u003clinux/usb.h\u003e in \u003clinux/usb/serial.h\u003e\n  driver core: platform: Include header for struct platform_device_id\n  driver: core: Include headers for acpi_device_id and of_device_id for struct device_driver\n  media: ti: vpe: #include \u003clinux/platform_device.h\u003e explicitly\n  mod_devicetable.h: Split into per subsystem headers\n"
    },
    {
      "commit": "c85167c926e0b1a9213ecc9040eb355f90426832",
      "tree": "6782d8e4aafad82e17f06555adb6e1cb935d3fe6",
      "parents": [
        "51512e22efe813d8223de27f6fd02a8a48ea2323",
        "cd64be0ecd399fa2b1ab60b3aaf2b2b744243467"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 20:05:43 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 20:05:43 2026 -1000"
      },
      "message": "Merge tag \u0027ata-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux\n\nPull ata fixes from Damien Le Moal:\n\n - Quirk the Phison PS3111-S11 SSD with NOLPM due to its defective\n   link power management (Bryam)\n\n - Strengthen checks on a device concurrent positioning range\n   information to make sure to reject any invalid report (Bryam)\n\n - Fix probe error handling in the pata_pxa and sata_gemini\n   drivers (Myeonghun, Wentao)\n\n - Limit buffer size of replies from translated commands to what\n   libata actually generated (Karuna)\n\n* tag \u0027ata-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:\n  ata: libata-scsi: limit simulated SCSI command copy to response length\n  ata: pata_pxa: Fix DMA channel leak on probe error\n  ata: sata_gemini: unwind clocks on IDE pinctrl errors\n  ata: libata-core: Reject an invalid concurrent positioning ranges count\n  ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD\n"
    },
    {
      "commit": "995832b2cebe6969d1b42635db698803ee31294d",
      "tree": "a94fcfdcd2e78f1210d5c7a520e2c5e82ee4b066",
      "parents": [
        "ecca1d63c1eadbbb38ceab82de0f7adfbc2b465d"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:36 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:17 2026 +0200"
      },
      "message": "Replace \u003clinux/mod_devicetable.h\u003e by more specific \u003clinux/device-id/*.h\u003e (c files)\n\nReplace the #include of \u003clinux/mod_devicetable.h\u003e by the more specific\n\u003clinux/device-id/*.h\u003e where applicable. For most cases the include\ncan be dropped completely, only a few drivers need one or two headers\nadded.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nAcked-by: Bjorn Helgaas \u003cbhelgaas@google.com\u003e\nLink: https://patch.msgid.link/1a3f2007c5c5dcf555c09a4035ce3ae8ef1b6c49.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "ecca1d63c1eadbbb38ceab82de0f7adfbc2b465d",
      "tree": "d0201da24e0ceaafac066fb3c079f3438b1b1b2d",
      "parents": [
        "a7e8cae4c60e693fffa493c7e3088cd03ee66232"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:35 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:16 2026 +0200"
      },
      "message": "Replace \u003clinux/mod_devicetable.h\u003e by more specific \u003clinux/device-id/*.h\u003e (headers)\n\n\u003clinux/mod_devicetable.h\u003e is included in a many files:\n\n\t$ git grep \u0027\u003clinux/mod_devicetable.h\u003e\u0027 ef0c9f75a195 | wc -l\n\t1598\n\n; some of them are widely used headers. To stop mixing up different and\nunrelated driver( type)s let the subsystem headers only use the subset\nof the recently split \u003clinux/mod_devicetable.h\u003e that are relevant for\nthem.\n\nThe fallout (I hope) is addressed in the previous commits that handle\nsources relying on e.g. \u003clinux/i2c.h\u003e pulling in the full legacy header\nand thus providing pci_device_id.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/199fe46b624ba07fb9bd3e0cd6ff13757932cb5f.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "a7e8cae4c60e693fffa493c7e3088cd03ee66232",
      "tree": "06b25e128e3a36160f3b0176149504549314c8d1",
      "parents": [
        "c19f08f796cbc169307a275d24a6a0e41d9bbd64"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:34 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:16 2026 +0200"
      },
      "message": "parisc: #include \u003clinux/compiler.h\u003e for unlikely() in \u003casm/ptrace.h\u003e\n\nCurrently \u003clinux/compiler.h\u003e isn\u0027t included at all (not even\ntransitively) in \u003casm/ptrace.h\u003e.\narch/parisc/kernel/asm-offsets.c just happens to include the following\nchain of includes before \u003casm/ptrace.h\u003e:\n\n\t\u003clinux/sched.h\u003e\n\t-\u003e \u003casm/processor.h\u003e\n\t-\u003e \u003casm/hardware.h\u003e\n\t-\u003e \u003clinux/mod_devicetable.h\u003e\n\t-\u003e \u003clinux/uuid.h\u003e\n\t-\u003e \u003clinux/string.h\u003e\n\t-\u003e \u003clinux/compiler.h\u003e\n\n. That chain will be broken, because in one of the next commits\n\u003casm/hardware.h\u003e is changed to only include \u003clinux/device-id/parisc.h\u003e\ninstead of \u003clinux/mod_devicetable.h\u003e. So to ensure\narch/parisc/kernel/asm-offsets.c knows about unlikely() even after that\nchange, #include \u003clinux/compiler.h\u003e explicitly.\n\nLink: https://patch.msgid.link/0574a2b73363c3cbf21c55c27455c3cecfb33583.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "c19f08f796cbc169307a275d24a6a0e41d9bbd64",
      "tree": "4692318c451b8e4fa4e9e292925e227fafc6cc04",
      "parents": [
        "a59fbb8ceff625a4841c1d010bd9b6a53dcfd190"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:33 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:16 2026 +0200"
      },
      "message": "media: em28xx: Add include for struct usb_device_id\n\nTraditionally \u003clinux/mod_devicetable.h\u003e was a header defining a plethora\nof structs, among them struct usb_device_id. This was split now with the\nobjective that only the relevant bits are included.\n\nCurrently \u003clinux/mod_devicetable.h\u003e is transitively included in\ndrivers/media/usb/em28xx/em28xx.h via:\n\n\tdrivers/media/usb/em28xx/em28xx.h -\u003e\n\t\u003clinux/i2c.h\u003e -\u003e\n\t\u003clinux/acpi.h\u003e -\u003e\n\t\u003clinux/device.h\u003e -\u003e\n\t\u003clinux/device/driver.h\u003e -\u003e\n\t\u003clinux/mod_devicetable.h\n\nTo keep struct usb_device_id available once \u003clinux/device/driver.h\u003e\nstops including \u003clinux/mod_devicetable.h\u003e, include it the header\nproviding that struct explictly.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/e72de5b4b9f1aa77a3c19a5e698a195dfd81ae0b.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "a59fbb8ceff625a4841c1d010bd9b6a53dcfd190",
      "tree": "d3a4ef6887f35bcc2ed3600fc38c436bfc64cc32",
      "parents": [
        "4e38ddd96b528a35477a9dfd5e6748d3961c85ab"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:32 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:16 2026 +0200"
      },
      "message": "LoongArch: KVM: Add include defining struct cpu_feature\n\nTraditionally \u003clinux/mod_devicetable.h\u003e was a header defining a plethora\nof structs, among them struct cpu_features. This was split now with the\nobjective that only the relevant bits are included.\n\nCurrently \u003clinux/mod_devicetable.h\u003e is transitively included in\narch/loongarch/kvm/main.c via:\n\n\tarch/loongarch/kvm/main.c -\u003e\n\t\u003clinux/kvm_host.h\u003e -\u003e\n\t\u003clinux/entry-virt.h\u003e -\u003e\n\t\u003clinux/resume_user_mode.h\u003e -\u003e\n\t\u003clinux/memcontrol.h\u003e -\u003e\n\t\u003clinux/cgroup.h\u003e -\u003e\n\t\u003clinux/kernel_stat.h\u003e -\u003e\n\t\u003clinux/interrupt.h\u003e -\u003e\n\t\u003clinux/hardirq\u003e -\u003e\n\t\u003casm/hardirq.h\u003e -\u003e\n\t\u003clinux/irq.h\u003e -\u003e\n\t\u003casm/irq.h\u003e -\u003e\n\t\u003clinux/irqdomain.h\u003e -\u003e\n\t\u003clinux/of.h\u003e -\u003e\n\t\u003clinux/mod_devicetable.h\u003e\n\nTo keep struct cpu_features available once \u003clinux/of.h\u003e stops including\n\u003clinux/mod_devicetable.h\u003e, include it here explicitly.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/052feec0e04ea8f5b2706a19a5b236679eed0aba.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "4e38ddd96b528a35477a9dfd5e6748d3961c85ab",
      "tree": "4b9a63015df05a0bd8b005368f7999b651dc519c",
      "parents": [
        "e3cda6938ab3027266bcbf92063075c9c495ddc2"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:31 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "ALSA: hda/core: Add include defining struct hda_device_id\n\nTraditionally all *_device_id were defined in a single header\n\u003clinux/mod_devicetable.h\u003e. This was split now with the objective that\nonly the relevant bits are included. So including \u003clinux/pci.h\u003e won\u0027t be\nenough to get a definition of (the unrelated to pci) struct\nhda_device_id.\n\nAdd an explicit include for the header defining struct hda_device_id to\nkeep working when \u003clinux/pci.h\u003e stops providing this defintion.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nReviewed-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nLink: https://patch.msgid.link/376883bc5889d5cca01efb6f8d4e07a20158f2b8.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "e3cda6938ab3027266bcbf92063075c9c495ddc2",
      "tree": "1bdc17844cc6706d2d45502a450414ab99ad6c5b",
      "parents": [
        "a66f9107a8ff8881f98bcbf4a271eac591f11e26"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:30 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "usb: dwc2: Add include defining struct pci_device_id\n\nUp to now \u003clinux/acpi.h\u003e includes \u003clinux/mod_devicetable.h\u003e that\nprovides struct pci_device_id. However \u003clinux/mod_devicetable.h\u003e was\nsplit into per bus headers and \u003clinux/acpi.h\u003e will only include the acpi\nrelated one (and similar for other bus headers).\n\nAs struct pci_device_id is used in drivers/usb/dwc2/core.h, add an\ninclude to ensure it\u0027s defined also after the includes in \u003clinux/acpi.h\u003e\nare tightened.\n\nAcked-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/bddfcdfaf36d735c244e03efada6083ef98ebd51.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "a66f9107a8ff8881f98bcbf4a271eac591f11e26",
      "tree": "f68fee9afa9592e4c86882d289e235f57fe56b70",
      "parents": [
        "5e4cc258b35cf1cca2248d370bfe75a67f51527b"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:29 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "platform/x86: int3472: Add include defining struct dmi_system_id\n\nCurrently \u003clinux/mod_devicetable.h\u003e is included transitively in\nint3472.h via\n\n\t\u003clinux/clk-provider.h\u003e -\u003e\n\t\u003clinux/of.h\u003e -\u003e\n\t\u003clinux/mod_devicetable.h\u003e\n\nHowever these includes will be tightend such that only the bits relevant\nfor of will be provided by \u003clinux/of.h\u003e. To ensure that dmi_system_id\nstays around, include the respective header explicitly.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Ilpo Järvinen \u003cilpo.jarvinen@linux.intel.com\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nAcked-by: Sakari Ailus \u003csakari.ailus@linux.intel.com\u003e\nLink: https://patch.msgid.link/0ba52730f67dc995d9d896b81fa6a7320bf8cb4b.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "5e4cc258b35cf1cca2248d370bfe75a67f51527b",
      "tree": "0fc16cd55e43381e96937d75276fedecf719a904",
      "parents": [
        "6d924c42e0ada2a9938b2a9c0b9bbc406c6282ce"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:28 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "platform/x86: x86-android-tablets: Add include defining struct dmi_system_id\n\nCurrently \u003clinux/i2c.h\u003e includes \u003clinux/mod_devicetable.h\u003e transitively\nwhich ensures that struct dmi_system_id is defined in\ndrivers/platform/x86/x86-android-tablets/x86-android-tablets.h. However\nthis include in \u003clinux/i2c.h\u003e will be replaced by one for i2c_device_id\nonly. To ensure that dmi_system_id is available add the include for that\nexplicitly.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Ilpo Järvinen \u003cilpo.jarvinen@linux.intel.com\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/32928d9ee47cefc7dfc4c385c06bd5e598b0fca1.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "6d924c42e0ada2a9938b2a9c0b9bbc406c6282ce",
      "tree": "30635c46249938690a3d9de6d130318542d854b8",
      "parents": [
        "2fb03de5256989d603f68dc07f06b6dbd72a9d92"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:27 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "i2c: Let i2c-core.h include \u003clinux/i2c.h\u003e\n\nThe subsystem private header i2c-core.h uses several symbols defined in\n\u003clinux/i2c.h\u003e, e.g. struct i2c_board_info and i2c_lock_bus()). This\ndoesn\u0027t pose a problem in practise because all files including\n\"i2c-core.h\" also include \u003clinux/i2c.h\u003e.\n\nTo make this more robust add an include statement for \u003clinux/i2c.h\u003e\nmaking the header self-contained.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nReviewed-by: Wolfram Sang \u003cwsa+renesas@sang-engineering.com\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/46aa85ab3dc4e63bfb5bd8ff1fd212a3d0e31f58.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "2fb03de5256989d603f68dc07f06b6dbd72a9d92",
      "tree": "aeb1e4fc3f958cc7ca5e0414bad3d8ac2b3dd70b",
      "parents": [
        "4c8f323b9e1517ea97bfdb2bc6f3c246f7d43eac"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:26 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "of: Explicitly include \u003clinux/types.h\u003e and \u003clinux/err.h\u003e\n\n\u003clinux/of_platform.h\u003e uses resource_size_t and relies on the transitive\ninclude \u003clinux/mod_devicetable.h\u003e -\u003e \u003clinux/types.h\u003e. It also uses error\nconstants and thus relying on the include chain\n\u003clinux/mod_devicetable.h\u003e -\u003e \u003clinux/uuid.h\u003e -\u003e \u003clinux/string.h\u003e -\u003e\n\u003clinux/err.h\u003e.\n\nWith the plan to split \u003clinux/mod_devicetable.h\u003e per subsystem and then\nonly letting of_platform.h include the of-specific bits (which don\u0027t\nrequire these two headers), add the needed includes explicitly to keep\nthe header self-contained.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/a730991bc8813cf70c2445064ea425291538f709.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "4c8f323b9e1517ea97bfdb2bc6f3c246f7d43eac",
      "tree": "0cf9dc1e1e8eb980df9f59a48d88a2bade651249",
      "parents": [
        "b14f81978d7ab6f28381f7cc0be7e65f244a083b"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:25 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:15 2026 +0200"
      },
      "message": "platform/x86: msi-ec: Ensure dmi_system_id is defined\n\nCurrently \u003clinux/acpi.h\u003e includes \u003clinux/mod_devicetable.h\u003e and thus\ndmi_system_id is available for the driver. To disentangle includes\n\u003clinux/acpi.h\u003e will be changed to only include the header for\nacpi_device_id instead of the full \u003clinux/mod_devicetable.h\u003e. To prepare\nfor that include the dedicated header for struct dmi_device_id.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Ilpo Järvinen \u003cilpo.jarvinen@linux.intel.com\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/600c7ab3263dcb8cee39b43dbd313eba8abef376.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "b14f81978d7ab6f28381f7cc0be7e65f244a083b",
      "tree": "9253c0fd60f2571d9a6869c88297e6d1b8049bd2",
      "parents": [
        "00cd8fc630e06e15a46200ce941d7fe98fea1e9d"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:24 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:14 2026 +0200"
      },
      "message": "usb: serial: Include \u003clinux/usb.h\u003e in \u003clinux/usb/serial.h\u003e\n\nAll consumers of the latter also include the former, but without that\nstruct usb_driver and struct usb_device_id (and maybe more) are not\ndefined. Add an include for \u003clinux/usb.h\u003e to make the header\nself-contained.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/82219ab65d16ee5bfe5a35d11bc938baac3fd3bc.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "00cd8fc630e06e15a46200ce941d7fe98fea1e9d",
      "tree": "57fed814aa6c1b8bee55f5098ec7954e656397c9",
      "parents": [
        "e1da37efb51b46870f7e50ae5e8a03293335bce5"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:23 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:14 2026 +0200"
      },
      "message": "driver core: platform: Include header for struct platform_device_id\n\nPlatform drivers can define an array containing the supported device\nvariants to be assigned to the struct platform_driver\u0027s .id_table.\n\nWhile a forward declaration of struct platform_device_id is technically\nenough to make the driver self-contained, it\u0027s reasonable to provide the\n(very lightweight) data type definition for that array in\n\u003clinux/platform_device.h\u003e to not add that burden to all platform drivers\nwith an id-table.\n\nNote that currently \u003clinux/device.h\u003e transitively includes\n\u003clinux/mod_devicetable.h\u003e that provides struct platform_device_id. But\nthat include is planned to be replaced by a tighter set of includes that\nonly define the structures relevant for the stuff in \u003clinux/device.h\u003e.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/4ca29592c9d1c6d528a65e05b80af7355f3c79c5.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "e1da37efb51b46870f7e50ae5e8a03293335bce5",
      "tree": "5b48eb40533ac1038cf703565c9443fb9f9e4e68",
      "parents": [
        "1b44cfa834e12aac55d2f071cabedc3aaa6fd19c"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:22 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:14 2026 +0200"
      },
      "message": "driver: core: Include headers for acpi_device_id and of_device_id for struct device_driver\n\nstruct device_driver contains pointers of type struct of_device_id* and\nstruct acpi_device_id* but doesn\u0027t ensure these are defined. To make the\nheader self-contained add the (very lightweight) includes that contain\nthe respective definitions.\n\nAcked-by: Greg Kroah-Hartman \u003cgregkh@linuxfoundation.org\u003e\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Rafael J. Wysocki (Intel) \u003crafael@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/199ba71b4ac73f4b4d9f5d2be635c96eec73c70e.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "1b44cfa834e12aac55d2f071cabedc3aaa6fd19c",
      "tree": "642a5b9e41efaf21343b1e4ab1c9a9d2a5cc32e1",
      "parents": [
        "ad428f5811bd7fb3d91fa002174de533f9da94d7"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:21 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:38:14 2026 +0200"
      },
      "message": "media: ti: vpe: #include \u003clinux/platform_device.h\u003e explicitly\n\nThe driver uses several symbols and structs defined in that header. The\nheader is currently included transitively via\n\n\t\"vip.h\" -\u003e\n\t\u003cmedia/v4l2-ctrls.h\u003e -\u003e\n\t\u003cmedia/media-request.h\u003e -\u003e\n\t\u003cmedia/media-device.h\u003e -\u003e\n\t\u003clinux/platform_device.h\u003e\n\nwhich seems to be on the lower end of the scale between random and\nreliable.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nReviewed-by: Yemike Abhilash Chandra \u003cy-abhilashchandra@ti.com\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nLink: https://patch.msgid.link/9f2e0e001eec087f00ac2c5af2de2e8f6d0978c1.1782808461.git.u.kleine-koenig@baylibre.com\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "ad428f5811bd7fb3d91fa002174de533f9da94d7",
      "tree": "aee60b8200d3570af5afa3a007a27cbd0e92e5d8",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Tue Jun 30 11:24:20 2026 +0200"
      },
      "committer": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Fri Jul 03 07:37:43 2026 +0200"
      },
      "message": "mod_devicetable.h: Split into per subsystem headers\n\n\u003clinux/mod_devicetable.h\u003e is included transitively in nearly every\ndriver in an x86_64 allmodconfig build of v7.1:\n\n\t$ find drivers -name \\*.o -not -name \\*.mod.o | wc -l\n\t21330\n\t$ find drivers -name \\*.o.cmd -not -name \\*.mod.o.cmd | xargs grep -l mod_devicetable.h | wc -l\n\t17038\n\nThe result is that even when touching an obscure device id struct most\nof the kernel needs to be recompiled. Given that each driver typically\nonly needs one or two of these structures, splitting into per subsystem\nheaders and only including what is really needed reduces the amount of\nneeded recompilation.\n\nImplement the first step and define each device id struct in a separate\nheader (together with its associated #defines).\n\n\u003clinux/mod_devicetable.h\u003e is modified to include all the new headers to\ncontinue to provide the same symbols.\n\nSeveral headers currently include \u003clinux/mod_devicetable.h\u003e, those that\nare most lukrative to include only their subsystem headers only are:\n\n\t$ git -C source grep -l mod_devicetable.h include/linux | while read h; do echo -n \"$h:\"; find drivers -name \\*.o.cmd -not -name \\*.mod.o.cmd | xargs grep -l $h | wc -l; done | sort -t: -k2 -n -r | head\n\tinclude/linux/of.h:10897\n\tinclude/linux/pci.h:7920\n\tinclude/linux/acpi.h:7097\n\tinclude/linux/i2c.h:5402\n\tinclude/linux/spi/spi.h:1897\n\tinclude/linux/dmi.h:1643\n\tinclude/linux/usb.h:1222\n\tinclude/linux/input.h:1205\n\tinclude/linux/mdio.h:835\n\tinclude/linux/phy.h:733\n\nstruct cpu_feature isn\u0027t really a device_id struct. That is kept in\n\u003clinux/mod_devicetable.h\u003e for now.\n\nAcked-by: Danilo Krummrich \u003cdakr@kernel.org\u003e\nAcked-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\nAcked-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e # zorro\nLink: https://patch.msgid.link/41400e323be8640702b906d04327e833c5bdaf4a.1782808461.git.u.kleine-koenig@baylibre.com\n[Drop \"MOD\" from the header guards]\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\n"
    },
    {
      "commit": "cd64be0ecd399fa2b1ab60b3aaf2b2b744243467",
      "tree": "6782d8e4aafad82e17f06555adb6e1cb935d3fe6",
      "parents": [
        "fcaf242e7fc406e78f444a35441e3b58f5e28781"
      ],
      "author": {
        "name": "Karuna Ramkumar",
        "email": "rkaruna@google.com",
        "time": "Thu Jul 02 02:01:42 2026 +0000"
      },
      "committer": {
        "name": "Damien Le Moal",
        "email": "dlemoal@kernel.org",
        "time": "Fri Jul 03 13:44:18 2026 +0900"
      },
      "message": "ata: libata-scsi: limit simulated SCSI command copy to response length\n\nThe function ata_scsi_rbuf_fill() is used to copy the response of\nemulated SCSI commands from ata_scsi_rbuf to the SCSI command\u0027s\nscatterlist.\n\nCurrently, sg_copy_from_buffer() is called with the size argument\nset to ATA_SCSI_RBUF_SIZE (2048 bytes). Since ata_scsi_rbuf is\nzeroed out before the simulation actor is invoked, copying the\nfull buffer size causes the remainder of the SCSI command\u0027s\ntransfer buffer (beyond the actual response length \u0027len\u0027) to be\noverwritten with zeroes. This clobbers any pre-existing sentinel\nvalues or data in the caller\u0027s buffer tail, even though the\ncorrect residual count is reported via scsi_set_resid().\n\nFix this by passing the actual response length \u0027len\u0027 as the copy\nsize to sg_copy_from_buffer(), ensuring that the tail of the\ncaller\u0027s buffer remains untouched. Also, add a defensive check\nto ensure that the actor does not return a length exceeding the\nstatic buffer capacity. If this occurs, trigger a WARN_ON(),\nfail the command with an aborted command error, and return\nimmediately without copying any data.\n\nThe fix was tested by invoking an SCSI SG_IO INQUIRY on\nan ATA disk on vanilla build, and build with the fix. Confirmed\nthat the input buffer\u0027s tail end remains unmodified with the fix.\n\nFixes: 5251ae224d8d (\"ata: libata-scsi: Return residual for emulated SCSI commands\")\nAssisted-by: Antigravity:gemini-3.5-flash\nSigned-off-by: Karuna Ramkumar \u003crkaruna@google.com\u003e\nSigned-off-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\n"
    },
    {
      "commit": "fcaf242e7fc406e78f444a35441e3b58f5e28781",
      "tree": "19b068e81cecb92eac0b1f3cbb83e0bf4da41a65",
      "parents": [
        "c0ace4130e813acbabdfaa28d4e94a849c2ffdd7"
      ],
      "author": {
        "name": "Wentao Liang",
        "email": "vulab@iscas.ac.cn",
        "time": "Thu Jun 25 22:18:37 2026 +0800"
      },
      "committer": {
        "name": "Damien Le Moal",
        "email": "dlemoal@kernel.org",
        "time": "Fri Jul 03 13:44:18 2026 +0900"
      },
      "message": "ata: pata_pxa: Fix DMA channel leak on probe error\n\nWhen dmaengine_slave_config() fails, the DMA channel acquired by\ndma_request_chan() is not released before returning the error,\nleaking the channel reference.\n\nFix by adding dma_release_channel() in the error path.\n\nThe ata_host_activate() error path already correctly releases the\nDMA channel.\n\nCc: stable@vger.kernel.org\nFixes: 88622d80af82 (\"ata: pata_pxa: dmaengine conversion\")\nSigned-off-by: Wentao Liang \u003cvulab@iscas.ac.cn\u003e\nReviewed-by: Niklas Cassel \u003ccassel@kernel.org\u003e\nSigned-off-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\n"
    },
    {
      "commit": "c0ace4130e813acbabdfaa28d4e94a849c2ffdd7",
      "tree": "4a43080d4ebd575d7e22a7f4eddaa41c0f1fa2c4",
      "parents": [
        "533a0b940f901c15e5cbbd4b5d66e871c209e8ce"
      ],
      "author": {
        "name": "Myeonghun Pak",
        "email": "mhun512@gmail.com",
        "time": "Fri Jun 26 17:58:37 2026 +0900"
      },
      "committer": {
        "name": "Damien Le Moal",
        "email": "dlemoal@kernel.org",
        "time": "Fri Jul 03 13:44:18 2026 +0900"
      },
      "message": "ata: sata_gemini: unwind clocks on IDE pinctrl errors\n\ngemini_sata_bridge_init() prepares and enables both SATA PCLKs, then\ndisables them again while keeping the clocks prepared for later bridge\nstart and stop operations. If gemini_setup_ide_pins() fails after that,\ngemini_sata_probe() returns directly and skips the existing\nout_unprep_clk unwind path.\n\nRoute the IDE pinctrl failure through out_unprep_clk so the clocks\nprepared by gemini_sata_bridge_init() are unprepared before probe\nfails.\n\nFixes: d872ced29d5f (\"ata: sata_gemini: Introduce explicit IDE pin control\")\nCo-developed-by: Ijae Kim \u003cae878000@gmail.com\u003e\nSigned-off-by: Ijae Kim \u003cae878000@gmail.com\u003e\nSigned-off-by: Myeonghun Pak \u003cmhun512@gmail.com\u003e\nReviewed-by: Niklas Cassel \u003ccassel@kernel.org\u003e\nReviewed-by: Linus Walleij \u003clinusw@kernel.org\u003e\nSigned-off-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\n"
    },
    {
      "commit": "533a0b940f901c15e5cbbd4b5d66e871c209e8ce",
      "tree": "ed19ca4c626d9496522c7ac3a6aac68e0fa08a31",
      "parents": [
        "462775c620197adaabc983ce847e5b9878ff4cb0"
      ],
      "author": {
        "name": "Bryam Vargas",
        "email": "hexlabsecurity@proton.me",
        "time": "Mon Jun 22 22:23:45 2026 -0500"
      },
      "committer": {
        "name": "Damien Le Moal",
        "email": "dlemoal@kernel.org",
        "time": "Fri Jul 03 13:44:18 2026 +0900"
      },
      "message": "ata: libata-core: Reject an invalid concurrent positioning ranges count\n\nata_dev_config_cpr() takes the number of range descriptors from buf[0]\nof the concurrent positioning ranges log (up to 255), which the device\nreports independently of the log size in the GPL directory. The count is\nthen walked at a fixed 32-byte stride in two places with no bound: the\nlog read here, and the INQUIRY VPD page B9h emitter, which writes one\ndescriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device\nreporting a count larger than its own log overflows the read buffer (up\nto 7704 bytes past a 512-byte slab), and a count above 62 overflows the\nresponse buffer on the emit side.\n\nBound the count once, on probe, against both the log the device returned\nand the number of descriptors the VPD B9h response buffer can hold\n(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range\ncount with a warning; this keeps the emitter in bounds with no separate\nchange there.\n\nSuggested-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\nFixes: fe22e1c2f705 (\"libata: support concurrent positioning ranges log\")\nFixes: c745dfc541e7 (\"libata: fix reading concurrent positioning ranges log\")\nCc: stable@vger.kernel.org\nSigned-off-by: Bryam Vargas \u003chexlabsecurity@proton.me\u003e\nReviewed-by: Niklas Cassel \u003ccassel@kernel.org\u003e\nSigned-off-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\n"
    },
    {
      "commit": "462775c620197adaabc983ce847e5b9878ff4cb0",
      "tree": "cffac51490a122edbed561737571a05c268f4811",
      "parents": [
        "51512e22efe813d8223de27f6fd02a8a48ea2323"
      ],
      "author": {
        "name": "Bryam Vargas",
        "email": "hexlabsecurity@proton.me",
        "time": "Fri Jun 19 21:54:02 2026 -0500"
      },
      "committer": {
        "name": "Damien Le Moal",
        "email": "dlemoal@kernel.org",
        "time": "Fri Jul 03 13:44:18 2026 +0900"
      },
      "message": "ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD\n\nThe PNY CS900 1TB SSD (Phison PS3111-S11, DRAM-less) drops off the bus\nafter entering Device-Initiated Slumber during idle. With the default\nmed_power_with_dipm policy the link goes down (SStatus 1 SControl 300)\nand does not recover, forcing the filesystem read-only. Forcing\nmax_performance keeps the link stable across prolonged idle.\n\nAdd a NOLPM quirk so link power management is disabled for this drive\nspecifically, leaving it intact for other devices on the host.\n\nCc: stable@vger.kernel.org\nSigned-off-by: Bryam Vargas \u003chexlabsecurity@proton.me\u003e\nReviewed-by: Niklas Cassel \u003ccassel@kernel.org\u003e\nSigned-off-by: Damien Le Moal \u003cdlemoal@kernel.org\u003e\n"
    },
    {
      "commit": "51512e22efe813d8223de27f6fd02a8a48ea2323",
      "tree": "71652a4126cce9f0529d265519df11fb118af40b",
      "parents": [
        "826eec5b5efd785dc87638a54d5ecc9f88e5afce",
        "b72e29e0f7ee329d89f86db8700c8ea99b4a370a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 16:39:28 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 16:39:28 2026 -1000"
      },
      "message": "Merge tag \u0027bpf-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf\n\nPull BPF fixes from Daniel Borkmann:\n\n - Initialize task local storage before fork bails out to free the task\n   (Jann Horn)\n\n - Fix insn_aux_data leak on verifier error path (KaFai Wan)\n\n - Reject BPF inode storage map creation when BPF LSM is uninitialized\n   (Matt Bobrowski)\n\n - Mask pseudo pointer values in verifier logs when pointer leaks are\n   not allowed (Nuoqi Gui)\n\n - Harden BPF JIT against spraying via IBPB flush (Pawan Gupta)\n\n - Reject a skb-modifying SK_SKB stream parser since the latter is only\n   meant to measure the next message (Sechang Lim)\n\n - Fix bpf_refcount_acquire to reject refcounted allocation arguments\n   with a non-zero fixed offset (Yiyang Chen)\n\n* tag \u0027bpf-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf:\n  bpf: Prefer dirty packs for eBPF allocations\n  bpf: Prefer packs that won\u0027t trigger an IBPB flush on allocation\n  bpf: Skip redundant IBPB in pack allocator\n  bpf: Restrict JIT predictor flush to cBPF\n  x86/bugs: Enable IBPB flush on BPF JIT allocation\n  bpf: Support for hardening against JIT spraying\n  bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized\n  bpf,fork: wipe -\u003ebpf_storage before bailouts that access it\n  bpf: Fix insn_aux_data leak on verifier err_free_env path\n  selftests/bpf: Cover pseudo-BTF ksym log masking\n  bpf: Mask pseudo pointer values in verifier logs\n  selftests/bpf: Cover refcount acquire node offsets\n  bpf: Reject offset refcount acquire arguments\n  selftests/bpf: test rejection of a packet-modifying SK_SKB stream parser\n  bpf, sockmap: reject a packet-modifying SK_SKB stream parser\n  selftests/bpf: don\u0027t modify the skb in the strparser parser prog\n"
    },
    {
      "commit": "826eec5b5efd785dc87638a54d5ecc9f88e5afce",
      "tree": "506372685f6c9b913607a7545e7e9d7ff9b650e8",
      "parents": [
        "87320be9f0d24fce67631b7eef919f0b79c3e45c",
        "e242e974e812e7a47e3088860c80d9492fac314f"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 15:25:54 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 15:25:54 2026 -1000"
      },
      "message": "Merge tag \u0027vfio-v7.2-rc2\u0027 of https://github.com/awilliam/linux-vfio\n\nPull VFIO fixes from Alex Williamson:\n \"Mostly straightforward fixes here, inconsistent runtime PM handling\n  due to global device policies, bitfield races, unwind path gaps,\n  teardown ordering, and a misplaced library flag.\n\n   - Fix racy bitfield updates in vfio-pci-core and the mlx5 vfio-pci\n     variant driver with a binary split between setup/release and\n     runtime modified flags. These were noted across several Sashiko\n     reviews as pre-existing issues (Alex Williamson)\n\n   - Fix runtime PM inconsistency where the vfio-pci driver module_init\n     could modify the idle PM policy of existing devices through globals\n     managed in vfio-pci-core, leading to unbalanced runtime PM\n     operations (Alex Williamson)\n\n   - Restore mutability of writable vfio-pci module options by further\n     pulling policy globals out of vfio-pci-core, to instead be latched\n     per device at device init. Provide visibility of the per device\n     latched values through debugfs (Alex Williamson)\n\n   - Fix missing VGA arbiter uninit callback in unwind path (Alex\n     Williamson)\n\n   - Reorder device debugfs removal before device_del() to avoid gap\n     where debugfs is available with stale devres pointers (Alex\n     Williamson)\n\n   - Move UUID library linking flag from vfio selftest Makefile into\n     libvfio.mk to avoid exposing such dependencies when linking with\n     KVM selftests (Sean Christopherson)\"\n\n* tag \u0027vfio-v7.2-rc2\u0027 of https://github.com/awilliam/linux-vfio:\n  vfio: selftests: Add luuid to libvfio.mk\u0027s list of libraries, not to the Makefile\n  vfio/pci: Expose latched module parameter policy in debugfs\n  vfio: Remove device debugfs before releasing devres\n  vfio/pci: Latch all module parameters per device\n  vfio/mlx5: Fix racy bitfields and tighten struct layout\n  vfio/pci: Fix racy bitfields and tighten struct layout\n  vfio/pci: Release the VGA arbiter client on register_device() failure\n  vfio/pci: Latch disable_idle_d3 per device\n"
    },
    {
      "commit": "acd7c71ba8d83808fa8d704196f3d53f7d58cf50",
      "tree": "71a2359940de6c869f2f19b7297711cae3327903",
      "parents": [
        "23e98bbd534d0cfb9aa2cef69224a66e6b8453e9",
        "8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:53:09 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:53:15 2026 +1000"
      },
      "message": "Merge tag \u0027drm-misc-fixes-2026-07-02\u0027 of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes\n\ndrm-misc-fixes for v7.2-rc2:\n- Fix potential null pointer dereference in dma-buf.\n- Handle 0 in dma_fence_dedup_array.\n- Use the correct callback in dma_fence_timeline_name.\n- Fix device removal handling in amdxdna.\n- kernel-doc fixes.\n- Include header fix for drm_ras.h\n- Handle edids better in virtio.\n- Use the clk_bulk api for error handling in malidp.\n- More clk handling fixes for komeda.\n- panthor scheduler block fallout fixes.\n- panthor unplug fixes.\n- other panthor fixes.\n- Fix unnecessary WARN_ON in topology probe after teardown.\n- Add refcount to amdxdna job to fix use-after free.\n- Fix increasing args-\u003esize in ioctl\u0027s of drm/imagination.\n- Handle stride correctly in pvr_set_uobj_array.\n- Only call imagination\u0027s drm_sched_entity_fini once.\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Maarten Lankhorst \u003cmaarten.lankhorst@linux.intel.com\u003e\nLink: https://patch.msgid.link/786bdc92-0ce3-4c0f-9668-b0fa8a0047ea@linux.intel.com\n"
    },
    {
      "commit": "23e98bbd534d0cfb9aa2cef69224a66e6b8453e9",
      "tree": "3ff95e7b2d91e868fa8f8806efcc4b66ce6491f7",
      "parents": [
        "7e21dc06c7270496b020c5fd44b9fa08b568e9b4",
        "959b5016e4646b55fd2fd0438932e4c4e9ce171f"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:43:58 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:44:46 2026 +1000"
      },
      "message": "Merge tag \u0027drm-xe-fixes-2026-07-02\u0027 of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes\n\nDriver Changes:\n- Wedge from the timeout handler only after releasing the queue (Rodrigo)\n- Fix a NULL pointer dereference (Francois)\n- Remove redundant exec_queue_suspended (Lu)\n- RTP / OA whitelist fixes (Ashutosh, Gustavo, Thomas)\n- Return error on non-migratable faults requiring devmem (Matt Brost)\n- Skip FORCE_WC and vm_bound check for external dma-bufs (Matt Auld)\n- Hold notifier lock for write on inject test path (Shuicheng)\n- Drop bogus static from finish in force_invalidate (Shuicheng)\n- Fix double-free of managed BO in error path (Shuicheng)\n- Don\u0027t attempt to process FAST_REQ or EVENT relays (Michal)\n- Fix NPD in bo_meminfo (Matthew Auld)\n- Prevent invalid cursor access for purged BOs (Matthew Auld)\n- Fix offset alignment for MERT WHITELST_OA_MERT_MMIO_TRG (Ashutosh)\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Thomas Hellstrom \u003cthomas.hellstrom@linux.intel.com\u003e\nLink: https://patch.msgid.link/akZ_UbrL94G4F2iA@fedora\n"
    },
    {
      "commit": "7e21dc06c7270496b020c5fd44b9fa08b568e9b4",
      "tree": "70b7629fa5032b0daabb9e0ab03109c5d05eb5d9",
      "parents": [
        "46d67197521e41fc0077ce3efe459dce82622631",
        "c44af3810fc8b3adf6910a332038aa566560c8fa"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:10:18 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:10:55 2026 +1000"
      },
      "message": "Merge tag \u0027amd-drm-fixes-7.2-2026-07-02\u0027 of https://gitlab.freedesktop.org/agd5f/linux into drm-fixes\n\namd-drm-fixes-7.2-2026-07-02:\n\namdgpu:\n- Soc24 aborted suspend fix\n- Drop unecessary BUG() and BUG_ON() from error paths\n- SCPM fix\n- Power reporting fix\n- DCE HDR fix\n- UVD boundary checks\n- VCN boundary checks\n- VCE boundary checks\n- DCN 4.2 fixes\n- Large stack allocation fixes\n- Fix aperture mapping leak\n- UserQ fixes\n- Ignore_damage_clips fix\n- ACP fixes\n- DC boundary checks\n- GPUVM fixes\n- JPEG idle check fixes\n- Userptr fix\n- GC 11.7 updates\n- Non-4K page fix\n- SMU 13 fixes\n- DP alt mode fix\n\namdkfd:\n- Boundary checks\n- CRIU fixes\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Alex Deucher \u003calexander.deucher@amd.com\u003e\nLink: https://patch.msgid.link/20260702143138.68463-1-alexander.deucher@amd.com\n"
    },
    {
      "commit": "46d67197521e41fc0077ce3efe459dce82622631",
      "tree": "ea0c4e665925575bbfe5c1af3e7975be63899c0b",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482",
        "2084503f2d087bf956198e7f6eb25b03a7049cb2"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:04:12 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jul 03 08:04:12 2026 +1000"
      },
      "message": "Merge tag \u0027drm-intel-fixes-2026-07-02\u0027 of https://gitlab.freedesktop.org/drm/i915/kernel into drm-fixes\n\n- Input validation fixes for BIOS and EDID (Jani)\n- Fix HDCP code buffer overflow and seq_num_v monotonic increase check (Jani)\n- Fix near-NULL deref in i915_active during GFP_ATOMIC exhaustion (Joonas)\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\nFrom: Joonas Lahtinen \u003cjoonas.lahtinen@linux.intel.com\u003e\nLink: https://patch.msgid.link/akYLxDea3kEyHqJA@jlahtine-mobl\n"
    },
    {
      "commit": "39def6d250d370298f86c116f4ac60093cefadaa",
      "tree": "15c127d32c09f9099a5b1d8f01ff4ba317297e75",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Sebastian Andrzej Siewior",
        "email": "bigeasy@linutronix.de",
        "time": "Wed Jul 01 15:11:50 2026 +0200"
      },
      "committer": {
        "name": "Thomas Gleixner",
        "email": "tglx@kernel.org",
        "time": "Thu Jul 02 22:14:08 2026 +0200"
      },
      "message": "futex/requeue: Revert \"Prevent NULL pointer dereference in remove_waiter() on self-deadlock\"\"\n\nThe commit cited below should not have been merged. It attemted to fix an\nexisting problem ansd thereby introduced new problems by keeping the\npi_state in state Q_REQUEUE_PI_IN_PROGRESS and leaking it.\n\nBased on the commit description the intention was to handle the case\nwhen task_blocks_on_rt_mutex() returns -EDEADLK and the following\nremove_waiter() dereferences the NULL pointer in waiter-\u003etask.\n\nThat is already handled by Davidlohr in commit 40a25d59e85b3\n(\"locking/rtmutex: Skip remove_waiter() when waiter is not enqueued\") and\nrequires no further acting.\n\nRevert the commit breaking the \"waiter \u003d\u003d owner\" case again.\n\nFixes: 74e144274af39 (\"futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock\")\nReported-by: Michael Bommarito \u003cmichael.bommarito@gmail.com\u003e\nSigned-off-by: Sebastian Andrzej Siewior \u003cbigeasy@linutronix.de\u003e\nSigned-off-by: Thomas Gleixner \u003ctglx@kernel.org\u003e\nCc: stable@vger.kernel.org\nLink: https://patch.msgid.link/20260701131150.0Ijhq4Dw@linutronix.de\nCloses: https://lore.kernel.org/all/20260629020049.2082397-1-michael.bommarito@gmail.com\n"
    },
    {
      "commit": "83245e7a436c04e511378af14dd81fd188b41541",
      "tree": "c3f2ecb273b4299de5f976c13688e109125c06c2",
      "parents": [
        "bf93bd42068b0b1dad84eb9375b8337bc05ef55d"
      ],
      "author": {
        "name": "John Madieu",
        "email": "john.madieu.xa@bp.renesas.com",
        "time": "Tue Jun 30 17:53:29 2026 +0000"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Thu Jul 02 18:56:38 2026 +0100"
      },
      "message": "ASoC: rsnd: src: Add missing scu_supply clock to suspend/resume\n\nscu_supply is enabled alongside scu and scu_x2 during normal SRC\noperation, but rsnd_src_suspend() and rsnd_src_resume() only disable\nand re-enable scu and scu_x2. The supply clock is left enabled across\na system suspend and its prepare/enable refcount becomes unbalanced\nafter a suspend/resume cycle.\n\nDisable scu_supply in rsnd_src_suspend() and re-enable it in\nrsnd_src_resume() so the SRC clocks are managed consistently across\nsystem PM transitions.\n\nFixes: ef19ecf042b4 (\"ASoC: rsnd: Add system suspend/resume support\")\nSigned-off-by: John Madieu \u003cjohn.madieu.xa@bp.renesas.com\u003e\nAcked-by: Kuninori Morimoto \u003ckuninori.morimoto.gx@renesas.com\u003e\nLink: https://patch.msgid.link/20260630175329.4145703-1-john.madieu.xa@bp.renesas.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "87320be9f0d24fce67631b7eef919f0b79c3e45c",
      "tree": "acea3ad5a6bc1c5fd1a5fc8fd2a29184802c88d5",
      "parents": [
        "a9d4dd742466cab468a950441447c614a3920aad",
        "d8e8b85a85fe21954d303db68034aac4639df88d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 06:01:12 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 06:01:12 2026 -1000"
      },
      "message": "Merge tag \u0027net-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Paolo Abeni:\n \"Including fixes from netfilter and batman-adv.\n\n  Current release - new code bugs:\n\n   - netfilter: cthelper: cap to maximum number of expectation per master\n\n  Previous releases - regressions:\n\n   - netpoll: fix a use-after-free on shutdown path\n\n   - tcp: restore RCU grace period in tcp_ao_destroy_sock\n\n   - ipv6: fix NULL deref in fib6_walk_continiue() on multi-batch dump\n\n   - batman-adv: dat: ensure accessible eth_hdr proto field\n\n   - eth:\n      - virtio_net: disable cb when NAPI is busy-polled\n      - lan743x: Initialize eth_syslock spinlock before use\n\n  Previous releases - always broken:\n\n   - netfilter:\n      - nft_set_pipapo: don\u0027t leak bad clone into future transaction\n\n   - sched:\n      - sch_teql: Introduce slaves_lock to avoid race condition and UAF\n      - replace direct dequeue call with peek and qdisc_dequeue_peeked\n\n   - sctp: add INIT verification after cookie unpacking\n\n   - tipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\n   - seg6: validate SRH length before reading fixed fields\n\n   - eth:\n      - mlx5e: fix use-after-free of metadata_dst on RX SC delete\n      - enetc: check the number of BDs needed for xdp_frame\n      - fbnic: don\u0027t cache shinfo across skb realloc\"\n\n* tag \u0027net-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (58 commits)\n  net/mlx5: HWS, fix matcher leak on resize target setup failure\n  net/sched: hhf: clear heavy-hitter state on reset\n  net/sched: dualpi2: clear stale classification on filter miss\n  net/sched: act_bpf: use rcu_dereference_bh() to read the filter\n  selftests: drv-net: tso: don\u0027t touch dangerous feature bits\n  cxgb4: Fix decode strings dump for T6 adapters\n  virtio_net: disable cb when NAPI is busy-polled\n  sctp: fix addr_wq_timer race in sctp_free_addr_wq()\n  selftests: net: bump default cmd() timeout to 20 seconds\n  bridge: stp: Fix a potential use-after-free when deleting a bridge\n  net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF\n  net: gianfar: dispose irq mappings on probe failure and device removal\n  net: lan743x: Initialize eth_syslock spinlock before use\n  net: libwx: fix VMDQ mask for 1-queue mode\n  net: airoha: fix max receive size configuration\n  fsl/fman: Free init resources on KeyGen failure in fman_init()\n  netfilter: nftables: restrict checkum update offset\n  netfilter: nftables: restrict linklayer and network header writes\n  netfilter: nfnetlink_queue: restrict writes to network header\n  netfilter: nft_fib: reject fib expression on the netdev egress hook\n  ...\n"
    },
    {
      "commit": "a9d4dd742466cab468a950441447c614a3920aad",
      "tree": "7636eb983dfd189e951ec8972be483b3d9b55f35",
      "parents": [
        "db78c0db411b111b438f00a1ba418e995b5bd246",
        "fe87b8dc67f1b2c64e76a66e78468c533d3c44ca"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:58:35 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:58:35 2026 -1000"
      },
      "message": "Merge tag \u0027hwmon-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging\n\nPull hwmon fixes from Guenter Roeck:\n\n - adm1275: Detect coefficient overflow, and prevent reading\n   uninitialized stack\n\n - aspeed-g6-pwm-tach: Guard fan RPM calculation against divide-by-zero\n\n - asus_atk0110: Check package count before accessing element\n\n - ltc4283: fix malformed table docs build error\n\n - occ: Unregister sysfs devices outside occ lock to avoid lockdep\n   warning\n\n - pmbus core: Fix passing events to regulator core, and honor\n   vrm_version in pmbus_data2reg_vid()\n\n - w83627hf: Remove VID sysfs files on error and remove\n\n - w83793: remove vrm sysfs file on probe failure\n\n - Various: Add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n\n* tag \u0027hwmon-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:\n  hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero\n  hwmon: (pmbus) Fix passing events to regulator core\n  hwmon: adm1275: Detect coefficient overflow\n  hwmon: adm1275: Prevent reading uninitialized stack\n  hwmon: (max6697) add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n  hwmon: (ltc2992) add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n  hwmon: (max1619) add missing \u0027select REGMAP\u0027 to Kconfig\n  hwmon: (w83627hf) remove VID sysfs files on error and remove\n  hwmon: (w83793) remove vrm sysfs file on probe failure\n  hwmon: (asus_atk0110) Check package count before accessing element\n  docs: hwmon: ltc4283: fix malformed table docs build error\n  hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()\n  hwmon: (occ) unregister sysfs devices outside occ lock\n"
    },
    {
      "commit": "db78c0db411b111b438f00a1ba418e995b5bd246",
      "tree": "0595366a5ac26c2d8c8062f38adba58dc67435c2",
      "parents": [
        "4a50a141f05a8d1737661b19ee22ff8455b94409",
        "d5d2d7a8d8be18681a0864f58e3875f1c639e11c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:56:44 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:56:44 2026 -1000"
      },
      "message": "Merge tag \u0027mfd-fixes-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd\n\nPull MFD fix from Lee Jones:\n\n - Add MFD mailing list to MAINTAINERS\n\n* tag \u0027mfd-fixes-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd:\n  MAINTAINERS: Add a mailing list entry to MFD\n"
    },
    {
      "commit": "2995ccec260caa9e85b3301a4aba1e66ed80ad74",
      "tree": "582428b3465626f8e8b84d6749441175681feb94",
      "parents": [
        "754e9e49b76fd5be339172aa98544182ed3ca75e"
      ],
      "author": {
        "name": "Gerald Schaefer",
        "email": "gerald.schaefer@linux.ibm.com",
        "time": "Tue Jun 23 19:44:06 2026 +0200"
      },
      "committer": {
        "name": "Vasily Gorbik",
        "email": "gor@linux.ibm.com",
        "time": "Thu Jul 02 16:51:06 2026 +0200"
      },
      "message": "s390/monwriter: Reject buffer reuse with different data length\n\nWhen data buffers are reused, e.g. for interval sample records, the\nfirst record determines the data length, and the size of the buffer for\nuser copy. Current monwriter code does not check if the data length was\nchanged for subsequent records, which also would never happen for valid\nuser programs.\n\nHowever, a malicious user could change the data length, resulting in out\nof bounds user copy to the kernel buffer, and memory corruption. By\ndefault, the monwriter misc device is created with root-only permissions,\nso practical impact is typically low.\n\nFix this by checking for changed data length and rejecting such records.\n\nCc: stable@vger.kernel.org\nSigned-off-by: Gerald Schaefer \u003cgerald.schaefer@linux.ibm.com\u003e\nReviewed-by: Christian Borntraeger \u003cborntraeger@linux.ibm.com\u003e\nSigned-off-by: Vasily Gorbik \u003cgor@linux.ibm.com\u003e\n"
    },
    {
      "commit": "c16b8c4cfb4fe2244cc33e469a93c1ab8684146b",
      "tree": "384ac536492623d31a77aa97caf68082614929d9",
      "parents": [
        "1b7a6da1d617876fbccd98da9bf1c2368e4f9424"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Thu Jul 02 09:25:00 2026 +0100"
      },
      "committer": {
        "name": "Steve French",
        "email": "stfrench@microsoft.com",
        "time": "Thu Jul 02 09:16:03 2026 -0500"
      },
      "message": "cifs: Fix missing credit release on failure in cifs_issue_read()\n\nFix missing release of credits in the failure path in cifs_issue_read()\nlest retrying the subreq just overwrites the credits value.\n\nFixes: 69c3c023af25 (\"cifs: Implement netfslib hooks\")\nLink: https://sashiko.dev/#/patchset/20260608145432.681865-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nAcked-by: Paulo Alcantara (Red Hat) \u003cpc@manguebit.org\u003e\ncc: linux-cifs@vger.kernel.org\ncc: netfs@lists.linux.dev\ncc: linux-fsdevel@vger.kernel.org\nSigned-off-by: Steve French \u003cstfrench@microsoft.com\u003e\n"
    },
    {
      "commit": "169328645663bae30e9abad4012d52441e085a71",
      "tree": "8bf2698e6b195d79e3fcfcd0abaf4dc9dcd6b48c",
      "parents": [
        "5166973b20784b4627c7a657d546963d8c6e9b5a"
      ],
      "author": {
        "name": "Jiri Olsa",
        "email": "jolsa@kernel.org",
        "time": "Wed Jul 01 13:13:25 2026 +0200"
      },
      "committer": {
        "name": "Peter Zijlstra",
        "email": "peterz@infradead.org",
        "time": "Thu Jul 02 13:21:49 2026 +0200"
      },
      "message": "uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline\n\nIn the unregister path we use __in_uprobe_trampoline check with\ncurrent-\u003emm for the VMA lookup, which is wrong, because we are\nin the tracer context, not the traced process.\n\nAdd mm_struct pointer argument to __in_uprobe_trampoline and\nchanging related callers to pass proper mm_struct pointer.\n\nFixes: ba2bfc97b462 (\"uprobes/x86: Add support to optimize uprobes\")\nReported-by: syzbot+61ce80689253f42e6d80@syzkaller.appspotmail.com\nSigned-off-by: Jiri Olsa \u003cjolsa@kernel.org\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\nReviewed-by: Oleg Nesterov \u003coleg@redhat.com\u003e\nAcked-by: Andrii Nakryiko \u003candrii@kernel.org\u003e\nTested-by: syzbot+61ce80689253f42e6d80@syzkaller.appspotmail.com\nLink: https://patch.msgid.link/20260701111337.53943-2-jolsa@kernel.org\n"
    },
    {
      "commit": "5166973b20784b4627c7a657d546963d8c6e9b5a",
      "tree": "82c6389a5272d78b05bc604c597b5be5a09e2b44",
      "parents": [
        "abf08854d224085e2ebb3ba660e7995909f47d6a"
      ],
      "author": {
        "name": "David Windsor",
        "email": "dwindsor@gmail.com",
        "time": "Mon Jun 29 20:13:34 2026 -0400"
      },
      "committer": {
        "name": "Peter Zijlstra",
        "email": "peterz@infradead.org",
        "time": "Thu Jul 02 13:21:49 2026 +0200"
      },
      "message": "selftests/x86: Add shadow stack uprobe CALL test\n\nAdd coverage for entry uprobes installed on CALL instructions while user\nshadow stack is enabled. The test puts an entry uprobe on a helper whose\nfirst instruction is a relative CALL, then verifies that the call/return\nsequence completes without SIGSEGV.\n\nThis catches regressions where x86 uprobe CALL emulation updates the\nregular user stack but leaves the CET shadow stack stale.\n\nSigned-off-by: David Windsor \u003cdwindsor@gmail.com\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\nLink: https://patch.msgid.link/b957039191118c5eba97d01d80c494b859f115a6.1782777969.git.dwindsor@gmail.com\n"
    },
    {
      "commit": "abf08854d224085e2ebb3ba660e7995909f47d6a",
      "tree": "f48461ec6a6eae8d75f739a4689cefb4200ce24b",
      "parents": [
        "037a3c43edfb597665dd34457cd22b14692f2ba3"
      ],
      "author": {
        "name": "David Windsor",
        "email": "dwindsor@gmail.com",
        "time": "Mon Jun 29 20:13:33 2026 -0400"
      },
      "committer": {
        "name": "Peter Zijlstra",
        "email": "peterz@infradead.org",
        "time": "Thu Jul 02 13:21:49 2026 +0200"
      },
      "message": "x86/uprobes: Keep shadow stack in sync for emulated CALLs\n\nUprobe CALL emulation updates the normal user stack, but not the CET user\nshadow stack. The subsequent RET then sees a stale shadow stack entry and\nraises #CP.\n\nUpdate the relative CALL emulation and XOL CALL fixup paths to keep the\nshadow stack in sync.\n\nFixes: 488af8ea7131 (\"x86/shstk: Wire in shadow stack interface\")\nSigned-off-by: David Windsor \u003cdwindsor@gmail.com\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\nAcked-by: Oleg Nesterov \u003coleg@redhat.com\u003e\nAcked-by: Jiri Olsa \u003cjolsa@kernel.org\u003e\nTested-by: Jiri Olsa \u003cjolsa@kernel.org\u003e\nLink: https://patch.msgid.link/8b5b1c7407b98f31664ad7b6a6faf20d2d4a6cad.1782777969.git.dwindsor@gmail.com\n"
    },
    {
      "commit": "037a3c43edfb597665dd34457cd22b14692f2ba3",
      "tree": "4b16db771e0d0b2447d031fba360db123c88f991",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Taeyang Lee",
        "email": "0wn@theori.io",
        "time": "Sun Jun 14 23:22:18 2026 +0900"
      },
      "committer": {
        "name": "Peter Zijlstra",
        "email": "peterz@infradead.org",
        "time": "Thu Jul 02 13:21:48 2026 +0200"
      },
      "message": "perf/core: Detach event groups during remove_on_exec\n\nperf_event_remove_on_exec() removes events by calling\nperf_event_exit_event(). For top-level events, this removes the event from\nthe context with DETACH_EXIT only.\n\nThis can leave inconsistent group state when a removed event is a group\nleader and the group contains siblings without remove_on_exec. If the group\nwas active, the surviving siblings can remain active and attached to the\nremoved leader\u0027s sibling list, but are no longer represented by a valid\ngroup leader on the PMU context active lists.\n\nA later close of the removed leader uses DETACH_GROUP and can promote the\nstill-active siblings from this stale group state. The next schedule-in can\nthen add an already-linked active_list entry again, corrupting the PMU\ncontext active list.\n\nWith DEBUG_LIST enabled, this is caught as a list_add double-add in\nmerge_sched_in().\n\nFix this by detaching group relationships when remove_on_exec removes an\nevent. This preserves the existing task-exit and revoke behavior, while\nensuring surviving siblings are ungrouped before the removed event leaves\nthe context.\n\nFixes: 2e498d0a74e5 (\"perf: Add support for event removal on exec\")\nSigned-off-by: Taeyang Lee \u003c0wn@theori.io\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\nLink: https://patch.msgid.link/ai65GgZcC0LAlWLG@Taeyangs-MacBook-Pro.local\n"
    },
    {
      "commit": "959b5016e4646b55fd2fd0438932e4c4e9ce171f",
      "tree": "c8b5495556aa8a85b042dae5694270a53334c037",
      "parents": [
        "8a0fb57675be578c4db19deb4298ed08a70f0f1a"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 29 10:26:34 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:44 2026 +0200"
      },
      "message": "drm/xe/oa: Fix offset alignment for MERT WHITELIST_OA_MERT_MMIO_TRG\n\n\u0027head\u0027 argument for WHITELIST_OA_MERT_MMIO_TRG was previously wrong (not\nmultiple of 16). Fix this.\n\nFixes: ec02e49f21bc (\"drm/xe/rtp: Whitelist OAMERT MMIO trigger registers\")\nCc: stable@vger.kernel.org\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nLink: https://patch.msgid.link/20260629172634.1100983-1-ashutosh.dixit@intel.com\n(cherry picked from commit f6c23e4589bdc69a5d2f79aed5c5bddd5d406cbe)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "8a0fb57675be578c4db19deb4298ed08a70f0f1a",
      "tree": "7964a4ed9e3a347dbc8c3b1fc7a7539ab633dde4",
      "parents": [
        "b5c55015d4164a0f206bcdcf2985da948b3c7837"
      ],
      "author": {
        "name": "Matthew Auld",
        "email": "matthew.auld@intel.com",
        "time": "Thu Jun 25 16:20:58 2026 +0100"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/pt: prevent invalid cursor access for purged BOs\n\nDuring a page table walk for binding, xe_pt_stage_bind() explicitly\nskips initializing the xe_res_cursor for purged BOs, treating them\nsimilarly to NULL VMAs by only setting the cursor size.\n\nHowever, xe_pt_hugepte_possible() and xe_pt_scan_64K() did not check\nif the BO was purged before attempting to walk the cursor using\nxe_res_dma() and xe_res_next(). Because the cursor was left\nuninitialized for purged BOs, this falls through and triggers\nwarnings like:\n\n  WARNING: drivers/gpu/drm/xe/xe_res_cursor.h:274 at xe_res_next\n\nFix this by explicitly checking if the BO is purged in both\nxe_pt_hugepte_possible() and xe_pt_scan_64K(), returning early just\nas we do for NULL VMAs, avoiding the invalid cursor accesses entirely.\n\nAs a precaution, also zero-initialize the cursor in xe_pt_stage_bind()\nto ensure we don\u0027t pass garbage data into the page table walkers\nif we ever hit a similar edge case in the future.\n\nCloses: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8418\nFixes: ad9843aac91a (\"drm/xe/madvise: Implement purgeable buffer object support\")\nAssisted-by: Copilot:gemini-3.1-pro-preview\nReported-by: Matthew Schwartz \u003cmatthew.schwartz@linux.dev\u003e\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nCc: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nCc: Arvind Yadav \u003carvind.yadav@intel.com\u003e\nReviewed-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nTested-by: Matthew Schwartz \u003cmatthew.schwartz@linux.dev\u003e\nLink: https://patch.msgid.link/20260625152054.450125-8-matthew.auld@intel.com\n(cherry picked from commit 4c7b9c6ece32440e5a435a92076d049450cd2d2e)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "b5c55015d4164a0f206bcdcf2985da948b3c7837",
      "tree": "bdec1aff493f6002a3e785a91d90bc21d9c7eefd",
      "parents": [
        "ed8b0d731892c68b41ecbd27c952af284816dec1"
      ],
      "author": {
        "name": "Matthew Auld",
        "email": "matthew.auld@intel.com",
        "time": "Thu Jun 25 16:20:56 2026 +0100"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe: fix NPD in bo_meminfo()\n\nWhen a buffer object is purged, its ttm.resource is set to NULL via the\nTTM pipeline gutting flow. However, the BO remains in the client\u0027s\nobject list until userspace explicitly closes the GEM handle. If memory\nstats are queried during this time, accessing bo-\u003ettm.resource-\u003emem_type\nwill result in a NULL pointer dereference.\n\nFix this by safely skipping purged BOs in bo_meminfo, as they no longer\nconsume any memory.\n\nUser is getting NPD on device resume, and possible theory is that in\nbo_move(), if we need to evict something to SYSTEM to save the CCS state,\nbut the BO is marked as dontneed, this won\u0027t trigger a move but will\nnuke the pages, leaving us with a NULL bo resource. And the meminfo()\ndoesn\u0027t look ready to handle a NULL resource.\n\nv2 (Sashiko):\n - There could potentially be other cases where we might end up with a\n   NULL resource, so make this a general NULL check for now.\n\nCloses: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8419\nFixes: ad9843aac91a (\"drm/xe/madvise: Implement purgeable buffer object support\")\nAssisted-by: Copilot:gemini-3.1-pro-preview\nReported-by: Matthew Schwartz \u003cmatthew.schwartz@linux.dev\u003e\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nCc: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nCc: Arvind Yadav \u003carvind.yadav@intel.com\u003e\nReviewed-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nTested-by: Matthew Schwartz \u003cmatthew.schwartz@linux.dev\u003e\nLink: https://patch.msgid.link/20260625152054.450125-6-matthew.auld@intel.com\n(cherry picked from commit c9a8e7daa0afe3161111e27fd92176e608c7f186)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "ed8b0d731892c68b41ecbd27c952af284816dec1",
      "tree": "c48004244d474f2fc9034205f0be8c663822881d",
      "parents": [
        "7ac3cae7a251d28e9079de07a991bd4eb2bb7fd8"
      ],
      "author": {
        "name": "Michal Wajdeczko",
        "email": "michal.wajdeczko@intel.com",
        "time": "Wed May 27 20:37:35 2026 +0200"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/pf: Don\u0027t attempt to process FAST_REQ or EVENT relays\n\nCurrently defined VF/PF relay actions use regular REQUEST messages\nonly and the PF shouldn\u0027t attempt to handle FAST_REQUEST nor EVENT\nmessages as this would result in breaking the VFPF ABI protocol\nand also might trigger an assert on the PF side.\n\nFixes: 98e62805921c (\"drm/xe/pf: Add SR-IOV GuC Relay PF services\")\nSigned-off-by: Michal Wajdeczko \u003cmichal.wajdeczko@intel.com\u003e\nReviewed-by: Michał Winiarski \u003cmichal.winiarski@intel.com\u003e\nLink: https://patch.msgid.link/20260527183735.22616-1-michal.wajdeczko@intel.com\n(cherry picked from commit 1714d360fc5ae2e0886a69e979095d9c7ff3568a)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "7ac3cae7a251d28e9079de07a991bd4eb2bb7fd8",
      "tree": "6e56d95c2a4984cfab98d5fd1caeb32cb6137ef7",
      "parents": [
        "0c56ea482aab1470b96a525ef53fa3eb8704f9a6"
      ],
      "author": {
        "name": "Shuicheng Lin",
        "email": "shuicheng.lin@intel.com",
        "time": "Fri Jun 26 21:06:31 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/hw_engine: Fix double-free of managed BO in error path\n\nThe error path in hw_engine_init() explicitly frees a BO allocated\nwith xe_managed_bo_create_pin_map() via xe_bo_unpin_map_no_vm().\nSince the managed BO already has a devm cleanup action registered,\nthis causes a double-free when devm unwinds during probe failure.\n\nRemove the explicit free and let devm handle it, consistent with\nall other xe_managed_bo_create_pin_map() callers.\n\nFixes: 0e1a47fcabc8 (\"drm/xe: Add a helper for DRM device-lifetime BO create\")\nAssisted-by: Claude:claude-opus-4.6\nReviewed-by: Zongyao Bai \u003czongyao.bai@intel.com\u003e\nLink: https://patch.msgid.link/20260626210631.3887291-1-shuicheng.lin@intel.com\nSigned-off-by: Shuicheng Lin \u003cshuicheng.lin@intel.com\u003e\n(cherry picked from commit e459a3bdeb117be496d7f229e2ea1f6c9fe4080b)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "0c56ea482aab1470b96a525ef53fa3eb8704f9a6",
      "tree": "77e4c5e89a24c6f0eba61674cea2f1b7e3742d90",
      "parents": [
        "dca6e08c923a44d2d66b955e03dd57a3a38c2b94"
      ],
      "author": {
        "name": "Shuicheng Lin",
        "email": "shuicheng.lin@intel.com",
        "time": "Thu Jun 25 22:44:52 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/userptr: Drop bogus static from finish in force_invalidate\n\nThe local \"finish\" pointer in xe_vma_userptr_force_invalidate() is\nunconditionally written before each read, so the static storage class\nserves no purpose. Worse, it makes the variable a process-wide shared\nslot: the function\u0027s per-VM asserts do not exclude concurrent callers\non different VMs, so two such callers can race on the slot and take\nthe wrong if (finish) branch.\n\nThe function is gated by CONFIG_DRM_XE_USERPTR_INVAL_INJECT\n(developer/test option, default n), so production builds are\nunaffected.\n\nDrop the static.\n\nFixes: 18c4e536959e (\"drm/xe/userptr: Convert invalidation to two-pass MMU notifier\")\nAssisted-by: Claude:claude-opus-4.7\nCc: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nCc: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nReviewed-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nReviewed-by: Zongyao Bai \u003czongyao.bai@intel.com\u003e\nLink: https://patch.msgid.link/20260625224452.3243231-1-shuicheng.lin@intel.com\nSigned-off-by: Shuicheng Lin \u003cshuicheng.lin@intel.com\u003e\n(cherry picked from commit ed382e3b07fae51a09d7290485bff0592f6b168b)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "dca6e08c923a44d2d66b955e03dd57a3a38c2b94",
      "tree": "04ca6a7a107c31f431b76dfb18bbb96e213a8010",
      "parents": [
        "d472497265374e895e31cf2af8a2c5f650019889"
      ],
      "author": {
        "name": "Shuicheng Lin",
        "email": "shuicheng.lin@intel.com",
        "time": "Thu Jun 25 21:56:15 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/userptr: Hold notifier_lock for write on inject test path\n\nWhen CONFIG_DRM_XE_USERPTR_INVAL_INJECT\u003dy, xe_pt_svm_userptr_pre_commit()\nruns vma_check_userptr() with the svm notifier_lock taken for read. The\ntest injection causes vma_check_userptr() to call\nxe_vma_userptr_force_invalidate(), which feeds into\nxe_vma_userptr_do_inval() with drm_gpusvm_ctx.in_notifier\u003dtrue. That\nflag tells drm_gpusvm_unmap_pages() the caller already holds\nnotifier_lock for write and only asserts the mode. Because the caller\nactually holds it for read, the assertion fires:\n\n  WARNING: drivers/gpu/drm/drm_gpusvm.c:1669 at \\\n           drm_gpusvm_unmap_pages+0xd4/0x130 [drm_gpusvm_helper]\n  Call Trace:\n   xe_vma_userptr_do_inval+0x40d/0xfd0 [xe]\n   xe_vma_userptr_invalidate_pass1+0x3e6/0x8d0 [xe]\n   xe_vma_userptr_force_invalidate+0xde/0x290 [xe]\n   vma_check_userptr.constprop.0+0x1c6/0x220 [xe]\n   xe_pt_svm_userptr_pre_commit+0x6a3/0xc60 [xe]\n   ...\n   xe_vm_bind_ioctl+0x3a0a/0x4480 [xe]\n\nAcquire notifier_lock for write in pre-commit when the inject Kconfig\nis enabled, via new helpers xe_pt_svm_userptr_notifier_lock()/_unlock().\nRename xe_svm_assert_held_read() to\nxe_svm_assert_held_read_or_inject_write() so it asserts the correct\nmode under each build configuration. Production builds\n(CONFIG_DRM_XE_USERPTR_INVAL_INJECT\u003dn) keep the existing read-mode\nbehavior bit-for-bit.\n\nFixes: 9e9787414882 (\"drm/xe/userptr: replace xe_hmm with gpusvm\")\nAssisted-by: Claude:claude-opus-4.7\nCc: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: Zongyao Bai \u003czongyao.bai@intel.com\u003e\nReviewed-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nLink: https://patch.msgid.link/20260625215615.3016892-1-shuicheng.lin@intel.com\nSigned-off-by: Shuicheng Lin \u003cshuicheng.lin@intel.com\u003e\n(cherry picked from commit 80ccbd97ffee8ad2e73167d826fe7be548364365)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "d472497265374e895e31cf2af8a2c5f650019889",
      "tree": "94f5eb52547c7981efcd265766ae740d1c6c5d45",
      "parents": [
        "136fb61ba8571076dc5d49350a0e6d002d740b74"
      ],
      "author": {
        "name": "Matthew Auld",
        "email": "matthew.auld@intel.com",
        "time": "Fri Jun 12 18:05:02 2026 +0100"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/display: skip FORCE_WC and vm_bound check for external dma-bufs\n\nCurrently, xe_display_bo_framebuffer_init() unconditionally attempts to\napply XE_BO_FLAG_FORCE_WC to the buffer and rejects the FB creation with\n-EINVAL if the BO is already VM_BINDed.\n\nHowever, for imported dma-bufs (ttm_bo_type_sg), this check doesn\u0027t seem\nto make much sense since CPU caching policy is entirely controlled by\nthe exporter. Plus there is no place to set this flag, in the first\nplace. Also this is not rejected if not yet vm_binded, but that seems\narbitrary since setting or not setting FORCE_WC should a noop either\nway, at this stage, and whether it is currently VM_BINDed makes no\ndifference.\n\nCurrently if we run an app and offload rendering to an external dGPU,\nlike NV or another xe device, the dma-buf passed back to the compositor\n(igpu) will be an actual external import from xe pov, and it will be\nmissing FORCE_WC, and if the compositor side did a VM_BIND before\nturning into it into an fb the whole thing gets rejected.\n\nSo it looks like we either need to reject outright, no matter what, or\nthis usecase is valid and we need to loosen the restriction for sg\nbuffers.  Proposing here to loosen the restriction.\n\nAssisted-by: Gemini:gemini-3.1-pro-preview\nLink: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/7919\nFixes: 44e694958b95 (\"drm/xe/display: Implement display support\")\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nCc: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nCc: Maarten Lankhorst \u003cdev@lankhorst.se\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.12+\nReviewed-by: Maarten Lankhorst \u003cdev@lankhorst.se\u003e\nLink: https://patch.msgid.link/20260612170501.550816-2-matthew.auld@intel.com\n(cherry picked from commit 3e493f88c84088ccd7b53cdd23ac5c875c9a60dd)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "136fb61ba8571076dc5d49350a0e6d002d740b74",
      "tree": "a15a345bd4ffc5fa7a5f192e4b7b940e00713ecb",
      "parents": [
        "ef78e2a22f72c892fd6663f0760abd208d49a3e2"
      ],
      "author": {
        "name": "Matthew Brost",
        "email": "matthew.brost@intel.com",
        "time": "Wed Jun 17 06:51:01 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe: Return error on non-migratable faults requiring devmem\n\nNon-migratable faults that require devmem incorrectly jump to the \u0027out\u0027\nlabel, which squashes the error code intended to be returned to the\nupper layers. Fix this by returning -EACCES instead.\n\nReported-by: Sashiko \u003csashiko-bot@kernel.org\u003e\nFixes: 4208fac3dce5 (\"drm/xe: Add more SVM GT stats\")\nCc: stable@vger.kernel.org\nSigned-off-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nReviewed-by: Francois Dugast \u003cfrancois.dugast@intel.com\u003e\nLink: https://patch.msgid.link/20260617135101.1245574-1-matthew.brost@intel.com\n(cherry picked from commit c4508edb2c723de93717272488ea65b165637eac)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "ef78e2a22f72c892fd6663f0760abd208d49a3e2",
      "tree": "8099e095ac24fb5eba2f5e31a5a1e449704f1c05",
      "parents": [
        "63ddb3ad08ff4e89c108499dfec5e9be5ddc25c9"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:27 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/rtp: Ensure locking/ref counting for OA whitelists\n\nSince multiple OA streams might be open in parallel on a gt, ensure that\nproper locking is in place. Also ensure that OA registers are whitelisted\nwhen the first OA stream is open and de-whitelisted after the last OA\nstream is closed.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-10-ashutosh.dixit@intel.com\n(cherry picked from commit 645f1a2589bd4782e25490e5ecc05b7043c36cbf)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "63ddb3ad08ff4e89c108499dfec5e9be5ddc25c9",
      "tree": "f1840e6148c61128ebc756b52552acbca4cc746b",
      "parents": [
        "ebba7ce65252a4ab0e3794ff14854df2afca5c08"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:26 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/oa: (De-)whitelist OA registers on OA stream open/release\n\nWhitelist OA registers on stream open and de-whitelist on stream\nclose/release. Whitelisting is only done when \u0027stream-\u003esample\u0027 is\ntrue. \u0027stream-\u003esample\u0027 is only true when (a) xe_observation_paranoid is set\nto false by system admin, or (b) the process is perfmon_capable(). This\ntherefore enforces the OA register whitelisting security requirements.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-9-ashutosh.dixit@intel.com\n(cherry picked from commit f8e6874f46f19a6a2a0f24a81689f90641bb402a)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "ebba7ce65252a4ab0e3794ff14854df2afca5c08",
      "tree": "09cdc4e5240c43d61cfe67bdf0ac78181edbfb9a",
      "parents": [
        "b422babd77fac2c96b92db484050e460899bddaf"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:25 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:43 2026 +0200"
      },
      "message": "drm/xe/rtp: (De-)whitelist OA registers for all hwe\u0027s for a gt\n\nWhitelist or de-whitelist OA registers for all hwe\u0027s on the gt on which the\nOA stream is opened. This simplifies the case where an oa unit has 0\nattached hwe\u0027s (but which monitors OA events on the associated GT).\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-8-ashutosh.dixit@intel.com\n(cherry picked from commit 6f73bf8fffa728aa5d5ee143ba318fa0744113a2)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "b422babd77fac2c96b92db484050e460899bddaf",
      "tree": "31ed01318ebf4525ebca6764548b4fde5fbeea91",
      "parents": [
        "a19a83721a28ccaddace846da70da5c53d7dd052"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:24 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:42 2026 +0200"
      },
      "message": "drm/xe/rtp: Toggle \u0027deny\u0027 bit to (de-)whitelist OA regs\n\nWhitelist or de-whitelist OA registers by setting or resetting the \u0027deny\u0027\nbit in OA nonpriv registers and writing new register values to HW.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-7-ashutosh.dixit@intel.com\n(cherry picked from commit aeaa7d2bb017272ab9e18759fe00bf758cd3299f)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "a19a83721a28ccaddace846da70da5c53d7dd052",
      "tree": "f1c6a7ca7be4c30cd77a95e53c0b5028158a1bf5",
      "parents": [
        "4fe2844b0f0c7cdc45ca4c4c62ca56b7f26c514c"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:23 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:42 2026 +0200"
      },
      "message": "drm/xe/rtp: Save OA nonpriv registers to register save/restore lists\n\nNow we can save OA whitelisting nonpriv registers to register save/restore\nlists. OA nonpriv registers are saved to both hwe-\u003eoa_sr as well as\nhwe-\u003ereg_sr.\n\nDuring probe, resume and gt-reset flows KMD will apply hwe-\u003ereg_sr,\nensuring OA registers are de-whitelisted after these events. For\nengine-reset, hwe-\u003ereg_sr is registered with GuC and GuC will apply these\nregisters, ensuring OA registers are de-whitelisted after engine resets.\n\nhwe-\u003eoa_sr is used for whitelisting or de-whitelisting OA registers during\nOA operation, by toggling the \u0027deny\u0027 bit on oa stream open/close.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-6-ashutosh.dixit@intel.com\n(cherry picked from commit 3a3c3e56db2923daaf1a5353cd6463a4cdaf4ffa)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "4fe2844b0f0c7cdc45ca4c4c62ca56b7f26c514c",
      "tree": "9cc925659b718b008e78df13b7fff61524239d9f",
      "parents": [
        "60d49ea28bb190a640bd8dc3f4c946e0811a948c"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:22 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:42 2026 +0200"
      },
      "message": "drm/xe/rtp: Generalize whitelist_apply_to_hwe\n\nGeneralize whitelist_apply_to_hwe to construct both non-OA and OA\nwhitelist nonpriv registers.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-5-ashutosh.dixit@intel.com\n(cherry picked from commit c3ff77d7235ccef7a0883c2fd981f70ef3aafd21)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "60d49ea28bb190a640bd8dc3f4c946e0811a948c",
      "tree": "b05a96840b0f5567aa1c17f4dddd38ed6f0011c6",
      "parents": [
        "31e2437561621b4867c08efc890bf629d017df03"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:21 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:42 2026 +0200"
      },
      "message": "drm/xe/rtp: Keep track of non-OA nonpriv slots\n\nIn order to dynamically whitelist/dewhitelist OA registers on OA stream\nopen/close, we need to keep track of nonpriv slots occupied by non-OA\nregister whitelists.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-4-ashutosh.dixit@intel.com\n(cherry picked from commit 15739920b71ef3c56868973b4e7e3164a793d09d)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "31e2437561621b4867c08efc890bf629d017df03",
      "tree": "38c03203224d57b5da4c375d2fbdd979039288b7",
      "parents": [
        "61596826b89af9dc20a53bae79b2b41e2bdc1fb5"
      ],
      "author": {
        "name": "Ashutosh Dixit",
        "email": "ashutosh.dixit@intel.com",
        "time": "Mon Jun 15 15:42:20 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:29:42 2026 +0200"
      },
      "message": "drm/xe/rtp: Maintain OA whitelists separately\n\nOA registers are dynamically whitelisted (and again dewhitelisted) on OA\nstream open/close. Maintaining OA whitelists separately from non-OA\nregister whitlists simplifies this management of OA register\nwhitelisting/dewhitelisting.\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260615224227.34880-3-ashutosh.dixit@intel.com\n(cherry picked from commit c478244a9e2d14b3f1f92e8bd293919e554622a5)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "61596826b89af9dc20a53bae79b2b41e2bdc1fb5",
      "tree": "81b5253b7eb581575731136eb8322623543c1c4f",
      "parents": [
        "e23fafb8594ea886ee03e005cc32dfda24f417cf"
      ],
      "author": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Fri Jun 05 11:33:05 2026 +0200"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Jul 02 12:28:02 2026 +0200"
      },
      "message": "drm/xe/rtp: Fix build error with clang \u003c 21 and non-const initializers\n\nClang \u003c 21 treats const-qualified compound literals at function scope as\nhaving static storage duration, which requires all initializer elements\nto be compile-time constants.  When xe_hw_engine.c initializes a local\nstruct xe_rtp_table_sr using XE_RTP_TABLE_SR(), the compound literals in\nXE_RTP_TABLE_SR end up containing runtime values (e.g. blit_cctl_val\nderived from gt-\u003emocs.uc_index), triggering:\n\n  xe_hw_engine.c:361: error: initializer element is not a compile-time constant\n  xe_hw_engine.c:416: error: initializer element is not a compile-time constant\n\nARRAY_SIZE() cannot be used as a replacement because it expands through\n__must_be_array() -\u003e __BUILD_BUG_ON_ZERO_MSG() -\u003e _Static_assert inside\nsizeof(struct{}), which clang \u003c 21 also rejects in the same context.\n\nReplace ARRAY_SIZE() with an open-coded sizeof(arr)/sizeof(elem) in\nXE_RTP_TABLE_SR and XE_RTP_TABLE to avoid both issues.\n\nFixes: e23fafb8594e (\"drm/xe/rtp: Add struct types for RTP tables\")\nCc: Matt Roper \u003cmatthew.d.roper@intel.com\u003e\nCc: Gustavo Sousa \u003cgustavo.sousa@intel.com\u003e\nCc: Violet Monti \u003cviolet.monti@intel.com\u003e\nCc: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nCc: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nCc: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nCc: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nCc: intel-xe@lists.freedesktop.org\nReported-by: Mark Brown \u003cbroonie@kernel.org\u003e\nCloses: https://lore.kernel.org/intel-xe/bfb0dee8-b243-47ba-a89d-71472b0d51c5@sirena.org.uk/\nAssisted-by: GitHub_Copilot:claude-sonnet-4.6\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\nReviewed-by: Gustavo Sousa \u003cgustavo.sousa@intel.com\u003e\nLink: https://patch.msgid.link/20260605093305.110598-1-thomas.hellstrom@linux.intel.com\n(cherry picked from commit a57011eff45e7265dc42a7adad68b84605d8f828)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "8dc8f3f4c2382fb7d1b1986ba8f33a2466cd3d7a",
      "tree": "b82bcb724d667b75f8122351e7506a3a9f39828a",
      "parents": [
        "d431b4012fd22920523dbd2806da663c1048e386"
      ],
      "author": {
        "name": "Shuvam Pandey",
        "email": "shuvampandey1@gmail.com",
        "time": "Wed Jul 01 11:44:34 2026 -0700"
      },
      "committer": {
        "name": "Alessio Belle",
        "email": "alessio.belle@imgtec.com",
        "time": "Thu Jul 02 11:16:18 2026 +0100"
      },
      "message": "drm/imagination: Fix user array stride in pvr_set_uobj_array()\n\npvr_set_uobj_array() copies an array of kernel objects to a userspace\narray whose element size is described by out-\u003estride. When out-\u003estride\nis different from the kernel object size, the slow path advances the\nuserspace pointer by the kernel object size and the kernel pointer by the\nuserspace stride.\n\nThis reverses the intended layout. For larger userspace strides, later\ncopies read from the wrong kernel addresses. For smaller userspace\nstrides, later copies are written at the wrong userspace offsets. The\npadding clear is also done only for the first element instead of the\npadding area for each element.\n\nAdvance the userspace pointer by out-\u003estride and the kernel pointer by\nobj_size, and clear per-element padding while the current userspace\npointer is still available.\n\nFixes: f99f5f3ea7ef (\"drm/imagination: Add GPU ID parsing and firmware loading\")\nCc: stable@vger.kernel.org # v6.8+\nReviewed-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\nSigned-off-by: Shuvam Pandey \u003cshuvampandey1@gmail.com\u003e\nLink: https://patch.msgid.link/6a456012.eb165e5c.113c2a.b71d@mx.google.com\nSigned-off-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\n"
    },
    {
      "commit": "d431b4012fd22920523dbd2806da663c1048e386",
      "tree": "e9dffe2d1781199c79a3f27109e1065c702e8838",
      "parents": [
        "4af24c27a39ba147a613a09e10b9e0f7294524c0"
      ],
      "author": {
        "name": "Brajesh Gupta",
        "email": "brajesh.gupta@imgtec.com",
        "time": "Wed Jul 01 10:49:30 2026 +0530"
      },
      "committer": {
        "name": "Alessio Belle",
        "email": "alessio.belle@imgtec.com",
        "time": "Thu Jul 02 11:15:59 2026 +0100"
      },
      "message": "drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY\n\nFor a few subtypes of DRM_IOCTL_PVR_DEV_QUERY, driver was overriding\nthe returned size unconditionally. This would have resulted in\nincrease of reported size beyond the amount of data returned to\nuserspace when args-\u003esize \u003c size of query structure.\n\nUpdated behaviour matches with the description of\ndrm_pvr_ioctl_dev_query_args.size and written byte length.\nNone of the structures of DRM_IOCTL_PVR_DEV_QUERY changed after addition,\nso change will not break any compatibility with earlier version.\n\nFixes: f99f5f3ea7ef (\"drm/imagination: Add GPU ID parsing and firmware loading\")\nFixes: ff5f643de0bf (\"drm/imagination: Add GEM and VM related code\")\nSigned-off-by: Brajesh Gupta \u003cbrajesh.gupta@imgtec.com\u003e\nReviewed-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\nLink: https://patch.msgid.link/20260701-b4-b4-query-v2-1-a1b491387875@imgtec.com\nSigned-off-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\n"
    },
    {
      "commit": "4af24c27a39ba147a613a09e10b9e0f7294524c0",
      "tree": "9cb8d579939c5c5a16422cac5b7ce866a13cf1d6",
      "parents": [
        "ec3304ddfd99adf531244be3a35c77b52583d5d3"
      ],
      "author": {
        "name": "Brajesh Gupta",
        "email": "brajesh.gupta@imgtec.com",
        "time": "Tue Jun 30 21:10:07 2026 +0530"
      },
      "committer": {
        "name": "Alessio Belle",
        "email": "alessio.belle@imgtec.com",
        "time": "Thu Jul 02 11:15:35 2026 +0100"
      },
      "message": "drm/imagination: Fix double call to drm_sched_entity_fini()\n\nCall sequence of double call:\npvr_context_destroy\n  pvr_context_kill_queues\n    pvr_queue_kill\n      drm_sched_entity_destroy\n        drm_sched_entity_fini // here\n  pvr_context_put\n    kref_put(..., pvr_context_release)\n      pvr_context_destroy_queues\n        pvr_queue_destroy\n          drm_sched_entity_fini // here\n\nCall to drm_sched_entity_destroy() from pvr_context_kill_queues() calls\ndrm_sched_entity_flush() + drm_sched_entity_fini().\ndrm_sched_entity_flush() ensures all pending jobs are completed and\ndrm_sched_entity_fini() ensures no further submission is allowed as\nper expectation from pvr_context_kill_queues(). Double call to\ndrm_sched_entity_fini() is misuse of the API so keep call only in\npvr_context_create() failure path.\n\nStack trace for issue with addition of refcounting for DRM entity\nstats in commit fd177135f0e6 (\"drm/sched: Account entity GPU time\"):\n\n[  789.490527] ------------[ cut here ]------------\n[  789.490559] refcount_t: underflow; use-after-free.\n[  789.490657] WARNING: lib/refcount.c:28 at refcount_warn_saturate+0xf4/0x144, CPU#0: kworker/u16:1/440\n[  789.490695] Modules linked in: powervr drm_gpuvm drm_exec gpu_sched drm_shmem_helper xhci_plat_hcd xhci_hcd dwc3 usbcore usb_common snd_soc_simple_card snd_soc_simple_card_utils sa2ul sha512 sha256 dwc3_am62 sha1 authenc rti_wdt libsha512 at24 sch_fq_codel fuse dm_mod ipv6\n[  789.490798] CPU: 0 UID: 0 PID: 440 Comm: kworker/u16:1 Not tainted 7.0.0-rc7-02049-g5e2c0700091b #22 PREEMPT\n[  789.490809] Hardware name: Texas Instruments AM625 SK (DT)\n[  789.490815] Workqueue: powervr-sched pvr_queue_fence_release_work [powervr]\n[  789.490868] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE\u003d--)\n[  789.490876] pc : refcount_warn_saturate+0xf4/0x144\n[  789.490884] lr : refcount_warn_saturate+0xf4/0x144\n[  789.490892] sp : ffff8000822cbcc0\n[  789.490895] x29: ffff8000822cbcc0 x28: 0000000000000000 x27: 0000000000000000\n[  789.490909] x26: 0000000000000000 x25: ffff800081b1e338 x24: ffff000004541405\n[  789.490922] x23: ffff000004bea950 x22: ffff00000042e400 x21: ffff000007123e30\n[  789.490935] x20: ffff000007123000 x19: ffff000007a80d50 x18: fffffffffffe7768\n[  789.490948] x17: 74736574202c6e6f x16: 697461746e656d65 x15: ffff800081b269f0\n[  789.490962] x14: 0000000000000030 x13: ffff800081b26a70 x12: 0000000000000211\n[  789.490975] x11: 00000000000000c0 x10: 0000000000000b50 x9 : ffff8000822cbb30\n[  789.490988] x8 : ffff0000014e7bb0 x7 : ffff00007725e780 x6 : 0000000372a05f49\n[  789.491001] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000010\n[  789.491013] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000014e7000\n[  789.491027] Call trace:\n[  789.491032]  refcount_warn_saturate+0xf4/0x144 (P)\n[  789.491043]  drm_sched_entity_fini+0x164/0x18c [gpu_sched]\n[  789.491081]  pvr_queue_destroy+0x64/0x134 [powervr]\n[  789.491110]  pvr_context_destroy_queues+0x34/0x64 [powervr]\n[  789.491138]  pvr_context_release+0x70/0xac [powervr]\n[  789.491166]  pvr_context_put.part.0+0x5c/0x7c [powervr]\n[  789.491193]  pvr_context_put+0x14/0x24 [powervr]\n[  789.491221]  pvr_queue_fence_release_work+0x20/0x38 [powervr]\n[  789.491249]  process_one_work+0x160/0x4c4\n[  789.491264]  worker_thread+0x188/0x310\n[  789.491276]  kthread+0x130/0x13c\n[  789.491287]  ret_from_fork+0x10/0x20\n[  789.491300] ---[ end trace 0000000000000000 ]---\n\nFixes: eaf01ee5ba28 (\"drm/imagination: Implement job submission and scheduling\")\nCc: stable@vger.kernel.org\nSigned-off-by: Brajesh Gupta \u003cbrajesh.gupta@imgtec.com\u003e\nReviewed-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\nLink: https://patch.msgid.link/20260630-b4-sched_fix-v7-1-71aa39c62627@imgtec.com\nSigned-off-by: Alessio Belle \u003calessio.belle@imgtec.com\u003e\n"
    },
    {
      "commit": "d8e8b85a85fe21954d303db68034aac4639df88d",
      "tree": "d4d398dbf1006a4f7001656feebe82a5cb04faab",
      "parents": [
        "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
        "26560c4a03dc4d607331600c187f59ab2df5f341"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:34:05 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:34:06 2026 +0200"
      },
      "message": "Merge tag \u0027batadv-net-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv\n\nSimon Wunderlich says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nHere are some batman-adv bugfix, all by Sven Eckelmann:\n\n - fix pointers after potential skb reallocs (5 patches)\n\n - dat: ensure accessible eth_hdr proto field\n\n* tag \u0027batadv-net-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv:\n  batman-adv: dat: ensure accessible eth_hdr proto field\n  batman-adv: bla: reacquire gw address after skb realloc\n  batman-adv: dat: acquire ARP hw source only after skb realloc\n  batman-adv: gw: acquire ethernet header only after skb realloc\n  batman-adv: access unicast_ttvn skb-\u003edata only after skb realloc\n  batman-adv: retrieve ethhdr after potential skb realloc on RX\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260630134430.85786-1-sw@simonwunderlich.de\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "d5d2d7a8d8be18681a0864f58e3875f1c639e11c",
      "tree": "00a8c1a1e2117f6718c306e2d0e91837ced89d37",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Lee Jones",
        "email": "lee@kernel.org",
        "time": "Fri Jun 19 09:07:14 2026 +0100"
      },
      "committer": {
        "name": "Lee Jones",
        "email": "lee@kernel.org",
        "time": "Thu Jul 02 09:07:03 2026 +0100"
      },
      "message": "MAINTAINERS: Add a mailing list entry to MFD\n\nThis is to be included by all contributors and will be leaned on for\nSashiko\u0027s \"reply to author\" support.\n\nSigned-off-by: Lee Jones \u003clee@kernel.org\u003e\n"
    },
    {
      "commit": "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
      "tree": "6e328b19cc29c5d3518103dea429ec6624cc27dd",
      "parents": [
        "0469d460a598d03fc85ebd97f99640e6c579e2a2"
      ],
      "author": {
        "name": "Dawei Feng",
        "email": "dawei.feng@seu.edu.cn",
        "time": "Mon Jun 29 14:40:49 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 09:27:26 2026 +0200"
      },
      "message": "net/mlx5: HWS, fix matcher leak on resize target setup failure\n\nhws_bwc_matcher_move() allocates a replacement matcher before setting it\nas the resize target. If mlx5hws_matcher_resize_set_target() fails, the\nreplacement matcher is not attached anywhere and is leaked.\n\nFix the leak by destroying the replacement matcher before returning from\nthe resize-target failure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nmlx5 HWS-capable device to test with, no runtime testing was able to be\nperformed.\n\nFixes: 2111bb970c78 (\"net/mlx5: HWS, added backward-compatible API handling\")\nCc: stable@vger.kernel.org\nSigned-off-by: Dawei Feng \u003cdawei.feng@seu.edu.cn\u003e\nReviewed-by: Yevgeny Kliteynik \u003ckliteyn@nvidia.com\u003e\nAcked-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nLink: https://patch.msgid.link/20260629064049.3852759-1-dawei.feng@seu.edu.cn\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "fcd245ea7528d50fddffc0fd1308941a9180f5b3",
      "tree": "cb9b3b5837e376bbddb23932ee4be7481c15f638",
      "parents": [
        "cbbef43bdc083892a2d4787245c249502c215bb8"
      ],
      "author": {
        "name": "Jan Beulich",
        "email": "jbeulich@suse.com",
        "time": "Thu Jul 02 08:11:22 2026 +0200"
      },
      "committer": {
        "name": "Juergen Gross",
        "email": "jgross@suse.com",
        "time": "Thu Jul 02 08:14:47 2026 +0200"
      },
      "message": "x86/Xen: correct commentary and parameter naming of xen_exchange_memory()\n\nAs documented in comments in struct xen_memory_exchange, the input to the\nhypercall is a set of MFNs which are to be removed from the domain, plus a\nset of PFNs where the newly allocated MFNs are to appear. Present comment\nand parameter naming don\u0027t correctly reflect that.\n\nSigned-off-by: Jan Beulich \u003cjbeulich@suse.com\u003e\nReviewed-by: Juergen Gross \u003cjgross@suse.com\u003e\nSigned-off-by: Juergen Gross \u003cjgross@suse.com\u003e\nMessage-ID: \u003c7e0c8795-cc60-4b78-8601-6a999739467a@suse.com\u003e\n"
    },
    {
      "commit": "1b7a6da1d617876fbccd98da9bf1c2368e4f9424",
      "tree": "1861589f92615d79548d3ea481781af59ab75ccf",
      "parents": [
        "b86467cd2691192ad4809a5a6e922fc24b8e9839"
      ],
      "author": {
        "name": "Steve French",
        "email": "stfrench@microsoft.com",
        "time": "Thu Jun 18 21:23:06 2026 -0500"
      },
      "committer": {
        "name": "Steve French",
        "email": "stfrench@microsoft.com",
        "time": "Wed Jul 01 20:19:21 2026 -0500"
      },
      "message": "cifs: update internal module version number\n\n   to 2.60\n\nSigned-off-by: Steve French \u003cstfrench@microsoft.com\u003e\n"
    },
    {
      "commit": "b86467cd2691192ad4809a5a6e922fc24b8e9839",
      "tree": "475c76becb4f8aadac695438652ad7dda39efe1e",
      "parents": [
        "7ad2bcf2441430bb2e918fb3ef9a90d775a6e422"
      ],
      "author": {
        "name": "Zihan Xi",
        "email": "xizh2024@lzu.edu.cn",
        "time": "Wed Jul 01 18:23:21 2026 +0800"
      },
      "committer": {
        "name": "Steve French",
        "email": "stfrench@microsoft.com",
        "time": "Wed Jul 01 20:19:18 2026 -0500"
      },
      "message": "smb: client: use unaligned reads in parse_posix_ctxt()\n\nThe server controls create-context DataOffset, so the POSIX context data\npointer may be misaligned on strict-alignment architectures. Use\nget_unaligned_le32() when reading nlink, reparse_tag, and mode.\n\nFixes: 69dda3059e7a (\"cifs: add SMB2_open() arg to return POSIX data\")\nCc: stable@vger.kernel.org\nSigned-off-by: Zihan Xi \u003cxizh2024@lzu.edu.cn\u003e\nSigned-off-by: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\nSigned-off-by: Steve French \u003cstfrench@microsoft.com\u003e\n"
    },
    {
      "commit": "7ad2bcf2441430bb2e918fb3ef9a90d775a6e422",
      "tree": "a4c9a6f6974b22a8c5febb2384120b3cb8af2ce3",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Zihan Xi",
        "email": "xizh2024@lzu.edu.cn",
        "time": "Sun Jun 28 17:19:24 2026 +0800"
      },
      "committer": {
        "name": "Steve French",
        "email": "stfrench@microsoft.com",
        "time": "Wed Jul 01 20:19:15 2026 -0500"
      },
      "message": "smb: client: harden POSIX SID length parsing\n\nposix_info_sid_size() reads sid[1] to obtain the subauthority count,\nbut its existing boundary check still accepts buffers with only one\nremaining byte. Require two bytes before reading sid[1] so all client\npaths that reuse the helper reject truncated POSIX SIDs safely.\n\nFixes: 349e13ad30b4 (\"cifs: add smb2 POSIX info level\")\nCc: stable@vger.kernel.org\nReported-by: Yuan Tan \u003cyuantan098@gmail.com\u003e\nReported-by: Yifan Wu \u003cyifanwucs@gmail.com\u003e\nReported-by: Juefei Pu \u003ctomapufckgml@gmail.com\u003e\nReported-by: Xin Liu \u003cbird@lzu.edu.cn\u003e\nAssisted-by: Codex:gpt-5.4\nSigned-off-by: Zihan Xi \u003cxizh2024@lzu.edu.cn\u003e\nSigned-off-by: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\nSigned-off-by: Steve French \u003cstfrench@microsoft.com\u003e\n"
    },
    {
      "commit": "4a50a141f05a8d1737661b19ee22ff8455b94409",
      "tree": "e9e87e24e0f18c0084916092e4246fe70b1d66bc",
      "parents": [
        "665159e246749578d4e4bfe106ee3b74edcdab18",
        "dec4d8118c179b3d12bca7e609054c6011c4f2ce"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Jul 01 14:21:03 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Jul 01 14:21:03 2026 -1000"
      },
      "message": "Merge tag \u0027bootconfig-fixes-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull bootconfig fix from Masami Hiramatsu:\n\n - bootconfig: Fix NULL-pointer arithmetic\n\n   Fix undefined pointer arithmetic in xbc_snprint_cmdline() when\n   probing the buffer length with NULL and size 0. Track the written\n   length as a size_t instead to prevent build-time UBSan/FORTIFY_SOURCE\n   failures.\n\n* tag \u0027bootconfig-fixes-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()\n"
    },
    {
      "commit": "ec3304ddfd99adf531244be3a35c77b52583d5d3",
      "tree": "78b32794f087789874465c81ab7f61e6b6979051",
      "parents": [
        "613059875958e7b217b250ed14c3b189f9488421"
      ],
      "author": {
        "name": "Lizhi Hou",
        "email": "lizhi.hou@amd.com",
        "time": "Wed Jul 01 08:55:56 2026 -0700"
      },
      "committer": {
        "name": "Lizhi Hou",
        "email": "lizhi.hou@amd.com",
        "time": "Wed Jul 01 14:57:45 2026 -0700"
      },
      "message": "accel/amdxdna: Fix use-after-free in debug BO command handling\n\nWhen a debug BO command completes, job-\u003edrv_cmd may already have been\nfreed. Accessing it from aie2_sched_drvcmd_resp_handler() can result in\na use-after-free and memory corruption.\n\nFix this by introducing reference counting for drv_cmd objects and\ntransferring ownership to the job while it is in flight. This ensures\nthat the command remains valid until the completion handler finishes\nprocessing it.\n\nFixes: 7ea046838021 (\"accel/amdxdna: Support firmware debug buffer\")\nReviewed-by: Mario Limonciello (AMD) \u003csuperm1@kernel.org\u003e\nSigned-off-by: Lizhi Hou \u003clizhi.hou@amd.com\u003e\nLink: https://patch.msgid.link/20260701155556.663541-1-lizhi.hou@amd.com\n"
    },
    {
      "commit": "fc16126cc11d9f507130bf84ab137ee0938c900e",
      "tree": "cb71a93c0504afcc9a62691e9b7f41db89c787c0",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Reinette Chatre",
        "email": "reinette.chatre@intel.com",
        "time": "Tue Jun 09 14:02:27 2026 -0700"
      },
      "committer": {
        "name": "Borislav Petkov (AMD)",
        "email": "bp@alien8.de",
        "time": "Wed Jul 01 13:15:02 2026 -0700"
      },
      "message": "x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled\n\nThe architecture updates the cpu_mask in a domain\u0027s header to track which\nonline CPUs are associated with the domain. When this mask becomes empty\nthe architecture initiates offline of the domain that includes calling\non resctrl fs to offline the domain. If it is a monitoring domain in\nwhich LLC occupancy is tracked resctrl fs forces the limbo handler to\nclear all busy RMID state associated with the domain.\n\nThe limbo handler always reads the current event value associated with a\nbusy RMID irrespective of it being checked as part of regular \"is it still\nbusy\" check or whether it will be forced released anyway. When reading an\nRMID on a system with SNC enabled the \"logical RMID\" is converted to the\n\"physical RMID\" and this conversion requires the NUMA node ID of the\nresctrl monitoring domain that is in turn determined by querying the NUMA\nnode ID of any CPU belonging to the monitoring domain.\n\nWhen the monitoring domain is going offline its cpu_mask is empty causing\nthe NUMA node ID query via cpu_to_node() to be done with \"nr_cpu_ids\" as\nargument resulting in an out-of-bounds access.\n\nRefactor the limbo handler to skip reading the RMID when the RMID will\njust be forced to no longer be dirty in the domain anyway. Add a safety\ncheck to the architecture\u0027s RMID reader to protect against this scenario.\n\nFixes: e13db55b5a0d (\"x86/resctrl: Introduce snc_nodes_per_l3_cache\")\nCloses: https://sashiko.dev/#/patchset/cover.1780456704.git.reinette.chatre%40intel.com?part\u003d9\nReported-by: Sashiko \u003csashiko-bot@kernel.org\u003e\nSigned-off-by: Reinette Chatre \u003creinette.chatre@intel.com\u003e\nSigned-off-by: Borislav Petkov (AMD) \u003cbp@alien8.de\u003e\nCc: \u003cstable@kernel.org\u003e\nLink: https://patch.msgid.link/16137433df42f85013b2f7a53626795cbd6637b9.1781029125.git.reinette.chatre@intel.com\n"
    },
    {
      "commit": "e23fafb8594ea886ee03e005cc32dfda24f417cf",
      "tree": "91d583423b678bf9e5169b0c491ecfeb684f4b1b",
      "parents": [
        "e70086a3a06d276b4a5d9a2c51c9330c6cf72780"
      ],
      "author": {
        "name": "Gustavo Sousa",
        "email": "gustavo.sousa@intel.com",
        "time": "Mon Jun 01 13:09:47 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Wed Jul 01 21:48:36 2026 +0200"
      },
      "message": "drm/xe/rtp: Add struct types for RTP tables\n\nWe currently have a mixture of styles for our RTP tables with respect of\nhow we define the number of entries:\n\n  * xe_rtp_process_to_sr() expects to receive the number of entries as\n    arguments;\n  * xe_rtp_process() expects the array to have a sentinel at the end of\n    the array;\n  * in xe_rtp_test.c, even though xe_rtp_process_to_sr() does not\n    require a sentinel value, we need to rely on that technique to be\n    able to count xe_rtp_entry_sr entries because simply using\n    ARRAY_SIZE() is not possible.\n\nThe style used by xe_rtp_process_to_sr() makes it hard to share the\ntables with other compilation units (e.g. kunit tests), since the number\nof entries is calculated with ARRAY_SIZE(), which is done at compile\ntime.\n\nSince we use the size of the tables to create some bitmasks, using a\nsentinel style doesn\u0027t seem great either.\n\nA way to reconcile things into a single style is to have a struct type\nthat would hold the entries array and the number of entries.  Since we\nhave xe_rtp_entry and xe_rtp_entry_sr, we would have one type for each.\n\nThe advantage of the proposed approach is that now we have a nice way to\nshare the tables directly to kunit tests with information about their\nsize.\n\nv6:\n    - Removed sentinels that are not needed\n\nv5:\n    - Removed added code from conflict resolution issues\n\nv4:\n    - Removed conflicts with main branch\n\nv3:\n    - No changes\n\nv2:\n    - Add compatibility with new xe_rtp_table_sr format for\n      \"bad-mcr-reg-forced-to-regular\" and\n      \"bad-regular-reg-forced-to-mcr\"\n\nFixes: 828a8eaf37c3 (\"drm/xe/oa: Add MMIO trigger support\")\nCc: stable@vger.kernel.org # v6.12+\nReviewed-by: Matt Roper \u003cmatthew.d.roper@intel.com\u003e\nSigned-off-by: Gustavo Sousa \u003cgustavo.sousa@intel.com\u003e\nSigned-off-by: Violet Monti \u003cviolet.monti@intel.com\u003e\nLink: https://patch.msgid.link/20260601200947.2032784-7-violet.monti@intel.com\nSigned-off-by: Matt Roper \u003cmatthew.d.roper@intel.com\u003e\n(cherry picked from commit 5ff004fdc7377905f2fe5264b8829d35e14608b8)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "bf93bd42068b0b1dad84eb9375b8337bc05ef55d",
      "tree": "1b4f9efae8a09b42b2549cdf1d2258c786147ccd",
      "parents": [
        "ed0abc8be27e23aa65716bcaab8976ada2503cab",
        "c34a4be8b846c7a220fe56442ecca27f6ab91943"
      ],
      "author": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Jul 01 19:52:46 2026 +0100"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Jul 01 19:52:46 2026 +0100"
      },
      "message": "ASoC: codecs: tas675x: misc bugfixes and minor changes\n\nSen Wang \u003csen@ti.com\u003e says:\n\nFew miscellaneous bug fixes after the initial merge of TAS675x driver, of\nwhich includes:\n\n- Adding READ_ONCE for all concurrent read params\n- Corrected kcontrol bits for temperature range\n- Corrected conversion notes in the driver documentation\n\nLink: https://patch.msgid.link/20260630183126.2588322-1-sen@ti.com\n"
    },
    {
      "commit": "c34a4be8b846c7a220fe56442ecca27f6ab91943",
      "tree": "25960a20cbb745e2349ba9baa464c24d59dd3e9c",
      "parents": [
        "a044f99d000dca7e1d3e8fc847d9ad60467b6793"
      ],
      "author": {
        "name": "Sen Wang",
        "email": "sen@ti.com",
        "time": "Tue Jun 30 13:31:22 2026 -0500"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Jul 01 19:52:38 2026 +0100"
      },
      "message": "Documentation: sound: tas675x: Fix temperature range and impedance documentation\n\nTwo corrections against the TRM (SLOU589A):\n- Corrected channel temperature range\n- Corrected conversion formula for global temperature\n\nFixes: ba46edca354e (\"Documentation: sound: Add TAS675x codec mixer controls documentation\")\nSigned-off-by: Sen Wang \u003csen@ti.com\u003e\nLink: https://patch.msgid.link/20260630183126.2588322-4-sen@ti.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "a044f99d000dca7e1d3e8fc847d9ad60467b6793",
      "tree": "173c187f6a3d8e25f7a9654d4693d65c8133b59d",
      "parents": [
        "12272cb1b23e3032e5c627fb52f183a61913a88b"
      ],
      "author": {
        "name": "Sen Wang",
        "email": "sen@ti.com",
        "time": "Tue Jun 30 13:31:21 2026 -0500"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Jul 01 19:52:37 2026 +0100"
      },
      "message": "ASoC: codecs: tas675x: Fix CHx temperature range register bit fields\n\nThe initial merged patch mixed up the bits for temp reg with LDG report,\nnow fixing to the right bits according to TRM (SLOU589A).\n\nFixes: 133c81f84471 (\"ASoC: codecs: Add TAS67524 quad-channel audio amplifier driver\")\nSigned-off-by: Sen Wang \u003csen@ti.com\u003e\nLink: https://patch.msgid.link/20260630183126.2588322-3-sen@ti.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "12272cb1b23e3032e5c627fb52f183a61913a88b",
      "tree": "9c7aeca47a6b5fe60739edd4b64ee36c4a8a5ab1",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Sen Wang",
        "email": "sen@ti.com",
        "time": "Tue Jun 30 13:31:20 2026 -0500"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Jul 01 19:52:36 2026 +0100"
      },
      "message": "ASoC: codecs: tas675x: use READ_ONCE for params to be used concurrently\n\nactive_playback_dais and active_capture_dais are written atomically via\nset_bit()/clear_bit() and can be read concurrently from the\nfault_check_work delayed work handler.\n\nfault_check_work already uses READ_ONCE; extend the same guard to all other\nreads in tas675x_hw_params() and tas675x_mute_stream().\n\nFixes: 133c81f84471 (\"ASoC: codecs: Add TAS67524 quad-channel audio amplifier driver\")\nSigned-off-by: Sen Wang \u003csen@ti.com\u003e\nLink: https://patch.msgid.link/20260630183126.2588322-2-sen@ti.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "c44af3810fc8b3adf6910a332038aa566560c8fa",
      "tree": "f7eb937cbbc3552891144f02668ae909ec070a37",
      "parents": [
        "a279bd143b3c184358b658e43a057e31ee8c4de5"
      ],
      "author": {
        "name": "Boyuan Zhang",
        "email": "boyuan.zhang@amd.com",
        "time": "Fri Jun 26 10:39:26 2026 -0400"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Jul 01 13:02:53 2026 -0400"
      },
      "message": "drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection\n\njpeg_v4_0_3_is_idle() initializes ret to false and then accumulates ring\nidle status using \u0026\u003d. Since false \u0026 condition always remains false, the\nfunction can never report the JPEG block as idle.\n\nInitialize ret to true so the function returns true only when all JPEG\nrings report RB_JOB_DONE.\n\nSigned-off-by: Boyuan Zhang \u003cboyuan.zhang@amd.com\u003e\nReviewed-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit e9df8e9d04e0593d17ddb069f3b7958991cd18c9)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "a279bd143b3c184358b658e43a057e31ee8c4de5",
      "tree": "f01d5603d5b1bc31867abf2b0369b6bb852f97bc",
      "parents": [
        "a6e14b976be48eebd8769cb5b883a6af7fc5ade1"
      ],
      "author": {
        "name": "Harish Kasiviswanathan",
        "email": "Harish.Kasiviswanathan@amd.com",
        "time": "Fri Jun 26 12:21:54 2026 -0400"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Jul 01 13:02:32 2026 -0400"
      },
      "message": "drm/amdgpu: Fix kernel panic during driver load failure\n\nAvoid kernel panic if MES init fails during driver load. The KIQ ring is\nfalsely marked as ready as ASICs that use MES, KIQ is owned by MES.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:gfx_v12_1_wait_reg_mem+0x5a/0x1f0 [amdgpu]\nCall Trace:\n gfx_v12_1_ring_emit_reg_write_reg_wait+0x1f/0x30 [amdgpu]\n amdgpu_gmc_fw_reg_write_reg_wait+0xb2/0x190 [amdgpu]\n amdgpu_gmc_flush_gpu_tlb+0x1cc/0x230 [amdgpu]\n amdgpu_gart_invalidate_tlb+0x81/0xa0 [amdgpu]\n amdgpu_gart_unbind+0x72/0x90 [amdgpu]\n amdgpu_ttm_backend_unbind+0xa4/0xb0 [amdgpu]\n amdgpu_ttm_tt_unpopulate+0x13/0xd0 [amdgpu]\n amdttm_tt_unpopulate+0x29/0x70 [amdttm]\n ttm_bo_put+0x1eb/0x360 [amdttm]\n amdgpu_bo_free_kernel+0xf9/0x1f0 [amdgpu]\n amdgpu_ih_ring_fini+0x5a/0x90 [amdgpu]\n amdgpu_irq_fini_hw+0x58/0x80 [amdgpu]\n amdgpu_device_fini_hw+0x4e0/0x5b0 [amdgpu]\n amdgpu_driver_load_kms+0x60/0xa0 [amdgpu]\n amdgpu_pci_probe+0x28e/0x6d0 [amdgpu]\n pci_device_probe+0x19f/0x220\n really_probe+0x1ed/0x340\n driver_probe_device+0x1e/0x80\n __driver_attach+0xd3/0x1a0\n bus_for_each_dev+0x68/0xa0\n bus_add_driver+0x19f/0x270\n driver_register+0x5d/0xf0\n do_one_initcall+0xac/0x200\n do_init_module+0x1ec/0x280\n __se_sys_finit_module+0x2de/0x310\n do_syscall_64+0x6a/0x250\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nSigned-off-by: Harish Kasiviswanathan \u003cHarish.Kasiviswanathan@amd.com\u003e\nReviewed-by: Kent Russell \u003ckent.russell@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 4623b958dd6da0f4c3026afdf330626a09ecb0f0)\nCc: stable@vger.kernel.org\n"
    }
  ],
  "next": "a6e14b976be48eebd8769cb5b883a6af7fc5ade1"
}
