)]}'
{
  "log": [
    {
      "commit": "5d0b3e418e6ccf8aa6bed726a719ecc971e3a288",
      "tree": "c0445c838a070a0d004c60c8e3ef16c616be544e",
      "parents": [
        "166e7aa93ac158d81585e4212c98191418c7eaa5"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sun Aug 02 10:34:28 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Sep 02 07:14:56 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: mvm: correctly check the API version\n\nThe check for the firmware version for the reset handshake\nwas wrong. mvm-\u003efw-\u003eucode_ver is the major number itself.\nNo need to mask it with IWL_UCODE_MAJOR.\n\nWe could look at the major number from IWL_UCODE_TLV_FW_VERSION\nbut we don\u0027t remember that number and looking at fw-\u003eucode_ver\nis good enough.\n\ntype\u003dbugfix\nticket\u003dnone\nfixes\u003dI21bba9e649f4cd0e35d3ea6cd97a03258be5832f\n\nChange-Id: I8cda260e2ef7aedd790915a17cb6832010f82aa4\nReported-and-tested-by: Chris Bainbridge \u003cchris.bainbridge@gmail.com\u003e\nLink: https://lore.kernel.org/linux-wireless/amzVtgQb2p-_nShU@debian.local/\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/314967\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 2db0925200f79e2ab5822816e4581c415e4bf3e6"
    },
    {
      "commit": "166e7aa93ac158d81585e4212c98191418c7eaa5",
      "tree": "a2678c7a10144199b85c91fffe031a370eec2d65",
      "parents": [
        "4b6a098ddef4d350de3768aaec927e48f4ce5f13"
      ],
      "author": {
        "name": "Avinash Bhatt",
        "email": "avinash.bhatt@intel.com",
        "time": "Sun Aug 23 21:06:40 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Sep 01 08:15:11 2026 +0000"
      },
      "message": "[NOUPSTREAM] wifi: iwlwifi: mld: wonder: implement TX data path\n\nSubmit wonder frames to the firmware via iwl_trans_tx(), translating\nwondertap rate parameters to the firmware rate word and routing each\nframe to the right TX queue.\n\nUnicast frames go to the destination sta\u0027s single TX queue, regardless\nof TID; everything else uses the bcast/mcast stations. Management\nframes use a fixed low legacy rate; data frames use the fixed rate or\nfirmware rate adaptation. TX completion frees wonder frames directly\ninstead of routing them through mac80211.\n\ntype\u003dfeature\nticket\u003dnone\n\nSigned-off-by: Avinash Bhatt \u003cavinash.bhatt@intel.com\u003e\nChange-Id: I849d142b2f67d4712a1b9abdd7f7bd519b773723\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320190\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: e3e1bd1c18ee7c7758835035af78ef1f52c42b6f"
    },
    {
      "commit": "4b6a098ddef4d350de3768aaec927e48f4ce5f13",
      "tree": "d345991de28b30556906ba1da504a9a57323a3a4",
      "parents": [
        "41f6a08db4c24bc2f21844bd899a2a449d8da659"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 20:40:36 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Sep 01 08:15:07 2026 +0000"
      },
      "message": "wifi: iwlwifi: move iwl_force_nmi() to where it belongs\n\niwl_force_nmi() forces a firmware NMI and has nothing to do with the\nregister I/O helpers in iwl-io.c. Move it to iwl-trans.c and rename it\nto iwl_trans_force_nmi() to match the transport API naming.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: Ie0d3ea9b23e35d7ff4b67e129c7b97ccb7c6c453\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319194\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nx-iwlwifi-stack-dev: e7045908e5a1c6854135308b01930712f8e5c136"
    },
    {
      "commit": "41f6a08db4c24bc2f21844bd899a2a449d8da659",
      "tree": "d60e8f4d2241a94ad7cee98cd64f7c893f6eab5c",
      "parents": [
        "04c44d9a428a0e2c31840e0cb491136b446eefd8"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 20:26:30 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Sep 01 08:15:02 2026 +0000"
      },
      "message": "wifi: iwlwifi: open code iwl_trans_sync_nmi_with_addr()\n\niwl_trans_sync_nmi_with_addr() had a single caller,\niwl_trans_pcie_sync_nmi(). There is no reason to keep it as a separate\nexported function in iwl-io.c, so embed its body directly in the caller\nand drop the now-unused declaration.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I23611eb40d875c6a69df0c08add3834f6f7d8528\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319193\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: b5bdc1b1d2b7ed34ab8e3f96e513a52ec9f99701"
    },
    {
      "commit": "04c44d9a428a0e2c31840e0cb491136b446eefd8",
      "tree": "7358a13dd7d15715e9de404c133e0dcd20217c44",
      "parents": [
        "ca6f7db7fcc94a93aa268d1afe41dbbaaeea31da"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 20:18:20 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Sep 01 08:14:58 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: remove iwl_dbgfs_fh_reg_read\n\nThis is no longer needed, and adds lots of parsing code\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I122eaf364743ffc42bd18a84a766d7920ec5700d\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319192\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 5da1eac4c1826b57c0dc88b5ecff3eb688e02016"
    },
    {
      "commit": "ca6f7db7fcc94a93aa268d1afe41dbbaaeea31da",
      "tree": "10f140b2d98febd6ebd867406a84666c8682d7b2",
      "parents": [
        "070e486a6d462c79bf6356832af28e45c1b94519"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Mon Aug 31 15:00:23 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Mon Aug 31 14:54:14 2026 +0000"
      },
      "message": "Merge remote-tracking branch \u0027auto/master\u0027 into merge\n\nMerge tag \u0027v7.3-rc1\u0027\n\nLinux 7.3-rc1\n\nCommits in this merge:\n\nAbhishek Bapat (1):\n      kselftest: alloc_tag: add kselftest for ioctl interface\n\nAdrian Ng Ho Yin (1):\n      MAINTAINERS: replace maintainer for Altera mSGDMA driver\n\nAlexander Usyskin (2):\n      issei: initial driver skeleton\n      issei: add firmware and host clients implementation, finish character device\n\nAlexandre Belloni (2):\n      Merge tag \u0027tegra-for-7.3-arm64-dt\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tegra/linux into soc/dt\n      MAINTAINERS: update rtc subsystem patchwork location\n\nAlice Ryhl (1):\n      rust: net: add rust/kernel/net to NETWORKING [GENERAL]\n\nAlim Akhtar (1):\n      MAINTAINERS: Add entry for Samsung Exynos8855 SoC\n\nAlvin Sun (1):\n      rust: module: update MAINTAINERS to cover module.rs\n\nAlvin Šipraga (1):\n      MAINTAINERS: make Luiz a maintainer and myself reviewer for Realtek DSA\n\nAndreas Hindborg (1):\n      MAINTAINERS: configfs: split configfs entry in C and Rust parts\n\nAndrew Morton (2):\n      Merge branch \u0027mm-hotfixes-stable\u0027 into mm-stable in order to pick up vmscan.c changes which are required by \"memcg: bail out proactive reclaim when memcg is dying\".\n      Merge branch \u0027mm-hotfixes-stable\u0027 into mm-stable to pick up already-upstream changes to memcontrol.c, needed by \"memcg: move mem_cgroup_swappiness and vm_swappiness to mm/swap.h\".\n\nAndrew Pope (1):\n      wifi: mac80211: recalculate TIM when a station enters power save\n\nAndy Chung (1):\n      hwmon: (kb9002) Add driver for Kandou KB9002 retimer\n\nAndy Shevchenko (1):\n      MAINTAINERS: Add Intel LPSS section to follow the changes\n\nAnirudh Srinivasan (1):\n      PCI: Move Spacemit vendor and device IDs to linux/pci_ids.h\n\nAntonio Borneo (1):\n      MAINTAINERS: Update remoteproc repo url for hwspinlock\n\nArend van Spriel (5):\n      wifi: cfg80211: pre-assign cookie for driver callbacks\n      wifi: mac80211: stop using ieee80211_mgmt_tx_cookie()\n      wifi: cfg80211: convert cookie output to input parameter\n      wifi: cfg80211: convert tx_control_port cookie to input parameter\n      wifi: nl80211: send frame tx status event only for non-zero cookie\n\nArnd Bergmann (9):\n      wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack\n      Merge tag \u0027tee-update-for-v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jenswi/linux-tee into arm/fixes\n      Merge tag \u0027samsung-dt64-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/krzk/linux into soc/dt\n      Merge tag \u0027imx-maintainers-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux into arm/fixes\n      Merge tag \u0027aspeed-7.3-maintainers-0\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/bmc/linux into arm/fixes\n      Merge tag \u0027qcom-drivers-for-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/qcom/linux into soc/drivers\n      Merge tag \u0027apple-soc-drivers-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/sven/linux into soc/drivers\n      Merge tag \u0027soc_fsl-7.3-1\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/chleroy/linux into soc/drivers\n      Merge tag \u0027samsung-soc-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/krzk/linux into soc/arm\n\nAvinash Bhatt (1):\n      wifi: iwlwifi: fw: move SAR defines from acpi.h to regulatory.h\n\nAvraham Stern (6):\n      wifi: iwlwifi: mvm: verify scan id reported by firmware\n      wifi: iwlwifi: mld: support aborting an ongoing ftm request\n      wifi: iwlwifi: mei: check SAP message length before reading it\n      wifi: iwlwifi: mei: skip data read if length is too short\n      wifi: iwlwifi: mei: pass correct argument to function\n      wifi: iwlwifi: mvm: copy the correct TK length for ranging\n\nAyala Beker (1):\n      wifi: iwlwifi: mld: drop connection on D3 resume failure\n\nBartosz Golaszewski (8):\n      Merge tag \u0027v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux into gpio/for-next\n      MAINTAINERS: add myself as the maintainer for Qualcomm pin control drivers\n      Merge tag \u0027v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux into gpio/for-next\n      software node: add kunit tests for fw_devlink support\n      MAINTAINERS: add myself as reviewer of software node support\n      Merge tag \u0027swnode-7.3-rc1\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core into gpio/for-next\n      eeprom: move nvmem EEPROM drivers to drivers/nvmem/\n      Merge tag \u0027v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux into gpio/for-next\n\nBasavaraj Natikar (1):\n      Input: misc: Add AMD SFH tablet-mode switch driver\n\nBen Greear (1):\n      wifi: iwlwifi: Clean dangling pointer in tx path\n\nBenjamin Berg (1):\n      wifi: mac80211: copy aggregation information\n\nBenjamin Blume (1):\n      HID: hyperx: add driver for the HyperX QuadCast 2 mute button\n\nBiju Das (1):\n      dt-bindings: clock: renesas,versaclock7: Update maintainer\n\nBilly Tsai (1):\n      MAINTAINERS: add Ryan Chen and Billy Tsai as reviewer for ARM/ASPEED\n\nBjorn Helgaas (3):\n      Merge branch \u0027pci/controller/dwc-qcom\u0027\n      Merge branch \u0027pci/controller/tegra264\u0027\n      Merge branch \u0027pci/controller/vmd\u0027\n\nBrendan Jackman (2):\n      mm: split out internal page_alloc.h\n      MAINTAINERS: update address for Brendan Jackman\n\nBreno Leitao (1):\n      bootconfig: render embedded bootconfig as a kernel cmdline at build time\n\nBrian Masney (1):\n      MAINTAINERS: Add Brian Masney and Jerome Brunet as co-maintainers for clk subsystem\n\nBryam Vargas (1):\n      wifi: mac80211_hwsim: clamp virtio RX length before skb_put\n\nBurak Emir (1):\n      MAINTAINERS: update address for Burak Emir\n\nCen Zhang (5):\n      wifi: cfg80211: cancel sched scan results work on unregister\n      wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n      wifi: cfg80211: use wiphy work for socket owner autodisconnect\n      wifi: mac80211_hwsim: clean up radio rhashtable on free\n      wifi: mac80211_hwsim: avoid NULL skb in stop queue drain\n\nChandrashekar Devegowda (1):\n      Bluetooth: btintel_pcie: Add vendor_reset PCI sysfs for PLDR\n\nChen-Yu Yeh (1):\n      MAINTAINERS: update Traditional Chinese documentation maintainers\n\nChenXiaoSong (1):\n      MAINTAINERS: add myself as KSMBD reviewer\n\nChenghai Huang (1):\n      MAINTAINERS: update hisilicon zip driver maintainer\n\nChristian Marangi (1):\n      MAINTAINERS: add myself as QCA8K maintainer\n\nChristoph Hellwig (2):\n      freevxfs: remove the driver\n      mm/swap: add a new swap_ops.h header to allow for pluggable swap ops\n\nChristophe JAILLET (1):\n      wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()\n\nCiprian Regus (2):\n      net: phy: Add support for the ADIN1140 PHY\n      net: ethernet: adi: Add a driver for the ADIN1140 MACPHY\n\nCristian Ciocaltea (1):\n      MAINTAINERS: Track dw-hdmi-qp under Rockchip DRM drivers\n\nDaniel Borkmann (1):\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.2-rc7\n\nDanilo Krummrich (2):\n      MAINTAINERS: add sys_soc.h to DRIVER CORE\n      Merge tag \u0027v7.2-rc7\u0027 into driver-core-next\n\nDave Airlie (3):\n      Merge tag \u0027drm-misc-next-2026-06-19\u0027 of https://gitlab.freedesktop.org/drm/misc/kernel into drm-next\n      Merge tag \u0027drm-misc-next-2026-07-02\u0027 of https://gitlab.freedesktop.org/drm/misc/kernel into drm-next\n      BackMerge tag \u0027v7.2\u0027 into drm-next\n\nDave Carey (1):\n      platform/x86/lenovo: Add Yoga Book 9 keyboard dock detection driver\n\nDave Hansen (1):\n      MAINTAINERS: Camera sensor and Intel IPU driver changes\n\nDave Penkler (1):\n      MAINTAINERS: Add Greg Kroah-Hartman to GPIB\n\nDavid Christensen (1):\n      ehea: remove the ehea driver\n\nDavid E. Box (1):\n      MAINTAINERS: update Intel PMC Core maintainer contact\n\nDavid Heidelberg (1):\n      MAINTAINERS: Add Matrix channel to the NFC subsystem\n\nDavid Hildenbrand (Arm) (1):\n      mm/bootmem_info: remove CONFIG_HAVE_BOOTMEM_INFO_NODE\n\nDavid Lechner (TI) (2):\n      dt-bindings: iio: adc: add ti,ads112c14\n      iio: adc: add ti-ads112c14 driver\n\nDavid Sterba (1):\n      MAINTAINERS: update btrfs git tree entries\n\nDavid Woodhouse (1):\n      MAINTAINERS: Add Miroslav as timekeeping reviewer\n\nDawei Feng (2):\n      wifi: mac80211: fix memory leak in ieee80211_register_hw()\n      wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()\n\nDeepanshu Kartikey (2):\n      wifi: mac80211: don\u0027t encrypt pre-auth (ETH_P_PREAUTH) frames\n      wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()\n\nDerek J. Clark (1):\n      HID: hid-msi: Add MSI Claw configuration driver\n\nDhanavandhana Kannan (1):\n      wifi: cfg80211: Avoid UNPROT_BEACON on AP interfaces\n\nDimitri Sivanich (2):\n      misc: sgi-xp: Remove SGI XP drivers\n      misc: sgi-gru: Remove SGI GRU driver\n\nDinh Nguyen (1):\n      MAINTAINERS: update entry for socfpga dwmac and gmii/sgmii\n\nDmitry Antipov (1):\n      wifi: mac80211: simplify airtime_flags_write()\n\nDmitry Torokhov (1):\n      mfd: rohm: Factor out power button registration\n\nDongdong Hao (1):\n      scsi: leapraid: Add new SCSI driver\n\nDrew Fustini (1):\n      riscv: Add support for srmcfg CSR from Ssqosid extension\n\nEdelweise Escala (2):\n      dt-bindings: leds: Add LTC3220 18 channel LED Driver\n      leds: ltc3220: Add Support for LTC3220 18 channel LED Driver\n\nEduard Zingerman (1):\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.2-rc5\n\nElizabeth Figura (1):\n      MAINTAINERS: Update wine-devel list address\n\nEmmanuel Grumbach (46):\n      wifi: iwlwifi: mvm: fix an off-by-1 boundary check\n      wifi: iwlwifi: mld: fix an off-by-1 boundary check\n      wifi: iwlwifi: mld: don\u0027t parse a notif before checking its length\n      wifi: iwlwifi: mvm: fix the FCS truncation logic in d3\n      wifi: iwlwifi: mld: validate reorder BAID\n      wifi: iwlwifi: mvm: parse beacon notif per layout\n      wifi: iwlwifi: mvm: validate MCC header before n_channels\n      wifi: iwlwifi: mvm: validate sta_id in TLC notif\n      wifi: iwlwifi: mvm: validate sta_id in BA window status notif\n      wifi: iwlwifi: mvm: validate mac_link_id in session protect notif\n      wifi: iwlwifi: mld: clear tzone on fail\n      wifi: iwlwifi: mvm: fix sched scan IE sizing\n      wifi: iwlwifi: pcie: null RX pointers after free\n      wifi: iwlwifi: mvm: d3: validate D3 resume notification payloads\n      wifi: iwlwifi: mvm: fix the FCS truncation logic in d3\n      wifi: iwlwifi: mld: treat valid BAID without STA as a FW error\n      wifi: iwlwifi: mvm: validate monitor notif link_id\n      wifi: iwlwifi: mld: validate D3_END notif size\n      wifi: iwlwifi: pcie: validate txq_id in txq_enable\n      wifi: iwlwifi: mvm: reset the smart fifo state upon FW stop\n      wifi: iwlwifi: mvm: cleanup the driver state after device_powered_off\n      wifi: iwlwifi: mld: reset the driver state upon firmware recovery\n      wifi: iwlwifi: mld: validate WoWLAN notif header\n      wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs\n      wifi: iwlwifi: mld: fix validation fallback in iwl_mld_notif_is_valid\n      wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser\n      wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments\n      wifi: iwlwifi: mld: validate txq_id in TX response handler\n      wifi: iwlwifi: add support for additional channels in NVM_GET_INFO\n      wifi: iwlwifi: mvm: validate TX_CMD response layout\n      wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list\n      wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn\n      wifi: iwlwifi: mvm: ptp: free response on success path\n      wifi: iwlwifi: pcie: validate FW section counts in iwl_pcie_init_fw_sec\n      wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif\n      wifi: iwlwifi: mvm: add a check on the tid coming from the firmware\n      wifi: iwlwifi: mvm: fix a possible underflow\n      wifi: iwlwifi: adapt ND match notif sizing to fixed matches array\n      wifi: iwlwifi: bound aligned TLV advance in FW parser\n      wifi: iwlwifi: dbg-tlv: bound aligned TLV walk length\n      wifi: iwlwifi: acpi: validate WGDS table revision index\n      wifi: iwlwifi: uefi: bound PPAG revision bitmap shift\n      wifi: iwlwifi: validate SEC_RT TLV minimum size\n      wifi: iwlwifi: mld: validate wake packet crypto overhead\n      wifi: iwlwifi: mld: initialize scan-abort status\n      wifi: iwlwifi: mvm: ignore sync frames when sync is disabled\n\nFelix Fietkau (5):\n      wifi: mac80211: factor out part of ieee80211_calc_expected_tx_airtime\n      wifi: mac80211: estimate expected throughput if not provided by driver/rc\n      wifi: mac80211: add AQL support for multicast packets\n      wifi: mac80211: add ieee80211_txq_aql_pending()\n      wifi: mac80211: skip default WMM setup for AP_VLAN links\n\nFinn Thain (1):\n      scsi: MAINTAINERS: Leave the cumana_1 and oak drivers to the RISCPC maintainers\n\nFrank Li (2):\n      MAINTAINERS: ARM/FREESCALE: merge Layerscape entry into i.MX entry\n      MAINTAINERS: media: nxp: imx8-isi: Add Frank Li as reviewer and i.MX mailing list\n\nFuad Tabba (2):\n      KVM: arm64: Add Fuad Tabba as a reviewer\n      KVM: arm64: Update Fuad Tabba\u0027s email address\n\nGabriel Somlo (1):\n      MAINTAINERS: remove Gabriel from LiteX and fw-cfg drivers\n\nGary Guo (1):\n      rust: driver: remove open-coded matching logic\n\nGary Yang (1):\n      MAINTAINERS: Update maintainer and git tree for CIX SoC\n\nGeorgi Vlaev (1):\n      hwmon: (pmbus/vt7505) Add driver for Analog Devices MAX16545/MAX16550 and Volterra VT7505\n\nGreg Kroah-Hartman (6):\n      MAINTAINERS: USB: add usb.rs to USB subsystem file list\n      Merge 7.2-rc5 into char-misc-next\n      Merge tag \u0027svc_updates_for_v7.3\u0027 of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/dinguyen/linux into char-misc-next\n      Merge tag \u0027mhi-for-v7.3\u0027 of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/mani/mhi into char-misc-next\n      Merge tag \u0027iio-for-7.3a\u0027 of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio into char-misc-next\n      Merge tag \u0027coresight-next-v7.3\u0027 of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/coresight/linux into char-misc-next\n\nGuixin Liu (1):\n      MAINTAINERS: add missing NVMe documentation files\n\nHE WEI (ギカク) (1):\n      wifi: cfg80211: bound element ID read when checking non-inheritance\n\nHaofeng Li (1):\n      wifi: cfg80211: validate EHT MLE before MLD ID read\n\nHaoxiang Li (1):\n      iwlwifi: dvm: add missing cleaup for on error path\n\nHarini T (1):\n      MAINTAINERS: Replace maintainer for Xilinx CAN driver\n\nHeikki Krogerus (1):\n      i2c: designware: Global register definitions\n\nHeiko Carstens (1):\n      MAINTAINERS: Update s390 specific vfio sections\n\nHongbo Li (1):\n      MAINTAINERS: update Hongbo Li\u0027s email address\n\nHongyan Xu (1):\n      misc: hisi_hikey_usb: remove untested role-switch driver\n\nIbrahim Hashimov (1):\n      wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO\n\nIgor Reznichenko (1):\n      drm/panel: Add Ilitek ILI9488 controller driver\n\nIhor Solodrai (1):\n      MAINTAINERS: BPF: Add self as reviewer\n\nIlan Peer (2):\n      wifi: mac80211: Route (Re)association req/response to per-STA queue\n      wifi: iwlwifi: mld: Do not cleanup FW state when the device is dead\n\nIvan Vecera (1):\n      MAINTAINERS: dpll: zl3073x: replace Prathosh Satish with Min Li\n\nJP Kobryn (1):\n      MAINTAINERS, mailmap: update email address for JP Kobryn\n\nJai Luthra (2):\n      dt-bindings: media: i2c: Add Sony IMX678\n      media: i2c: imx678: Add driver for Sony IMX678\n\nJakub Kicinski (12):\n      MAINTAINERS: add nci tests to nfc\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027wireless-2026-07-26\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next\n      Merge tag \u0027wireless-2026-07-29\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027wireless-next-2026-08-06\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next\n      MAINTAINERS: make Tung an official TIPC maintainer\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge branch \u0027200GbE\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tnguy/next-queue\n      Merge tag \u0027nfc-net-next-20260817\u0027 of https://codeberg.org/linux-nfc/linux\n      Merge tag \u0027linux-can-next-for-7.3-20260818\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can-next\n\nJan Kara (2):\n      mm: a second pagecache maintainer\n      fsnotify: Remove Matt Bobrowski as a reviewer\n\nJean-Michel Hautbois (1):\n      power: reset: add MCF5441x RCM power-on reason driver\n\nJeff Chen (1):\n      wifi: nxp: add nxpwifi driver for IW61x\n\nJens Axboe (1):\n      Merge tag \u0027nvme-7.3-2026-08-13\u0027 of git://git.infradead.org/nvme into for-7.3/block\n\nJens Wiklander (1):\n      MAINTAINERS: .mailmap: update Jens Wiklander\u0027s email address\n\nJia Wang (2):\n      dt-bindings: clock: ultrarisc: Add DP1000 Clock Controller\n      clk: ultrarisc: Add DP1000 clock driver\n\nJiajia Liu (1):\n      wifi: cfg80211: reg: add a newline in DFS debug message\n\nJianyue Wu (1):\n      mm: rename swap.c to folio.c\n\nJijie Shao (1):\n      MAINTAINERS: add myself as a maintainer for Hisilicon Network Subsystem\n\nJiri Kosina (3):\n      Merge branch \u0027for-7.3/msi\u0027 into for-linus\n      Merge branch \u0027for-7.3/hyperx\u0027 into for-linus\n      Merge branch \u0027for-7.3/amd-sfh\u0027 into for-linus\n\nJiri Pirko (1):\n      MAINTAINERS: add Ivan Vecera as DPLL reviewer\n\nJohannes Berg (23):\n      wifi: radiotap: add definitions for the new UHR TLVs\n      wifi: nl80211: clarify NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA content\n      wifi: cfg80211: remove WIPHY_FLAG_DISABLE_WEXT\n      wifi: iwlwifi: mvm: remove iwl_mvm_recalc_tcm()\n      wifi: iwlwifi: claim UHR DBE capability for UHR devices\n      wifi: iwlwifi: mvm/mld: fix PPE threshold debug print loop\n      Merge tag \u0027iwlwifi-fixes-2026-07-21\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/iwlwifi/iwlwifi-next\n      Merge tag \u0027mm81x-driver-08-07-2026\u0027 of https://github.com/MorseMicro/linux\n      wifi: mac80211: always send regulatory connectivity element\n      wifi: use UHR operation field presence bits\n      wifi: cfg80211: improve multi-BSSID profile continuation parser\n      wifi: cfg80211: clarify and tighten key checks\n      wifi: mac80211: fix monitor min_def bandwidth\n      wifi: mac80211: refactor multi-link assoc response parsing\n      wifi: mac80211: parse enhanced critical updates field\n      Merge tag \u0027nxpwifi-2026-07-15\u0027 of https://github.com/jeffchen71/nxpwifi\n      Merge tag \u0027ath-next-20260722\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ath/ath\n      Merge tag \u0027iwlwifi-next-2026-07-23\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/iwlwifi/iwlwifi-next\n      Revert \"wifi: mac80211: don\u0027t encrypt pre-auth (ETH_P_PREAUTH) frames\"\n      wifi: mac80211: fix RCU dereference in throughput estimate\n      wifi: mac80211: fix RCU usage in peer probing\n      Merge tag \u0027rtw-next-2026-08-02\u0027 of https://github.com/pkshih/rtw\n      wifi: mac80211: disconnect on CSA to channel 0\n\nJonas Jelonek (1):\n      net: pse-pd: add Realtek PSE MCU core\n\nJonathan Cameron (2):\n      Merge tag \u0027v7.2-rc2\u0027 into togreg\n      MAINTAINERS: Update HiSilicon PCI Trace and Tune maintainer\n\nJorijn van der Graaf (2):\n      dt-bindings: iio: magnetometer: add QST QMC6308\n      iio: magnetometer: add support for QST QMC6308\n\nJoshua Crofts (2):\n      dt-bindings: iio: dac: add support for mcp47a1\n      iio: dac: mcp47a1: add support for new device\n\nJudith Mendez (1):\n      MAINTAINERS: Add myself to maintain TI AM654 SDHCI host drver\n\nJulian Braha (1):\n      MAINTAINERS: add Julian Braha as Kconfig reviewer\n\nJunjie Cao (1):\n      MAINTAINERS: Update my email address for the AW99706 backlight driver\n\nJunyang Han (1):\n      dinghai: add ZTE network driver support\n\nKai Mäkisara (1):\n      scsi: MAINTAINERS: Orphan the SCSI tape driver\n\nKate Hsuan (1):\n      media: i2c: imx471: Add Sony IMX471 image sensor driver\n\nKiryl Shutsemau (Meta) (1):\n      drivers/firmware: add SDEI cross-CPU NMI service for arm64\n\nKrzysztof Kozlowski (2):\n      MAINTAINERS: Drop redundant lists from various Samsung entries\n      docs: dt: maintainer: Add Devicetree and OF maintainer profile document\n\nLachlan Hodges (4):\n      wifi: cfg80211: introduce helper to get S1G primary width\n      wifi: ieee80211: introduce generic KHZ_TO_HZ helper\n      wifi: mm81x: add mm81x Wi-Fi HaLow driver\n      wifi: cfg80211: include cf1 offset when sending chandef\n\nLance Yang (1):\n      MAINTAINERS: add Usama as a THP reviewer\n\nLars Randers (1):\n      hwmon: Driver for the temp/voltage sensor on PolarFire SoC\n\nLee Jones (1):\n      MAINTAINERS: Add a mailing list entry to MFD\n\nLinus Torvalds (87):\n      Merge tag \u0027mm-hotfixes-stable-2026-07-06-17-49\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027usb-7.2-rc3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb\n      Merge tag \u0027sound-7.2-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n      Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/virt/kvm/kvm\n      Merge tag \u0027soc-fixes-7.2-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n      Merge tag \u0027net-7.2-rc4\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027mm-hotfixes-stable-2026-07-20-11-37\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027net-7.2-rc5\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027v7.2-rc4-smb3-client-fixes\u0027 of git://git.samba.org/sfrench/cifs-2.6\n      Merge tag \u0027block-7.2-20260724\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n      Merge tag \u0027char-misc-7.2-rc5\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc\n      Merge tag \u0027erofs-for-7.2-rc6-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/xiang/erofs\n      Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/virt/kvm/kvm\n      Merge tag \u0027powerpc-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux\n      Merge tag \u0027net-7.2-rc6\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027mm-hotfixes-stable-2026-07-30-19-30\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027pci-v7.2-fixes-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci\n      Merge tag \u0027soc-fixes-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n      Merge tag \u0027net-7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027mm-hotfixes-stable-2026-08-06-18-44\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027sound-7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n      Merge tag \u0027char-misc-7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc\n      Merge tags \u0027vfs-7.3-rc1.efs\u0027 and \u0027vfs-7.3-rc1.freevxfs\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs\n      Merge tag \u0027libcrypto-updates-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux\n      Merge tag \u0027kbuild-7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux\n      Merge tag \u0027rust-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux\n      Merge tag \u0027arm64-upstream\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux\n      Merge tag \u0027irq-core-2026-08-17\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n      Merge tag \u0027timers-core-2026-08-17\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n      Merge tag \u0027soc-dt-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n      Merge tag \u0027soc-drivers-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n      Merge tag \u0027soc-arm-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n      Merge tag \u0027gpio-updates-for-v7.3-rc1-v2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n      Merge tag \u0027hwmon-for-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging\n      Merge tag \u0027hid-for-linus-2026081901\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/hid/hid\n      Merge tag \u0027media/v7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media\n      Merge tag \u0027devicetree-for-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux\n      Merge tag \u0027driver-core-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/driver-core/driver-core\n      Merge tag \u0027for-linus-fwctl\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/fwctl/fwctl\n      Merge tag \u0027v7.3-p1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6\n      Merge tag \u0027bpf-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next\n      Merge tag \u0027net-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next\n      Merge tag \u0027docs-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/docs/linux\n      Merge tag \u0027bitmap-for-7.3\u0027 of https://github.com/norov/linux\n      Merge tag \u0027fsnotify_for_v7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jack/linux-fs\n      Merge tag \u0027for-7.3/block-20260819\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n      Merge tag \u0027riscv-for-linus-7.3-mw1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux\n      Merge tag \u0027for_linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mst/vhost\n      Merge tag \u0027mm-stable-2026-08-18-18-39\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027mm-hotfixes-stable-2026-08-19-21-33\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027drm-next-2026-08-20\u0027 of https://gitlab.freedesktop.org/drm/kernel\n      Merge tag \u0027scsi-misc\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi\n      Merge tag \u0027mmc-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc\n      Merge tag \u0027for-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/sre/linux-power-supply\n      Merge tag \u0027cifs-maintainer-switch-7.3-rc1\u0027 of https://git.manguebit.org/linux\n      Merge tag \u0027landlock-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux\n      Merge tag \u0027exfat-for-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/exfat\n      Merge tag \u0027mm-nonmm-stable-2026-08-22-16-57\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027ksmbd-for-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb\n      Merge tag \u0027liveupdate-v7.3-rc1-20260823\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/liveupdate/linux\n      Merge tag \u0027s390-7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/s390/linux\n      Merge tag \u0027pci-v7.3-changes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci\n      Merge tag \u0027i3c/for-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/i3c/linux\n      Merge tag \u0027rcu.2026.08.18a\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rcu/linux\n      Merge tag \u0027pinctrl-v7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/linusw/linux-pinctrl\n      Merge tag \u0027mailbox-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jassibrar/mailbox\n      Merge tag \u0027platform-drivers-x86-v7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/pdx86/platform-drivers-x86\n      Merge tag \u0027configfs-for-v7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/a.hindborg/linux\n      Merge tags \u0027dma-mapping-7.3-2026-08-24\u0027 and \u0027dma-mapping-7.3-2026-08-24-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux\n      Merge tag \u0027phy-for-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/phy/linux-phy\n      Merge tag \u0027dmaengine-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vkoul/dmaengine\n      Merge tag \u0027ntfs-for-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs\n      Merge tag \u0027bootconfig-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n      Merge tag \u0027char-misc-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc\n      Merge tag \u0027tty-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty\n      Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/virt/kvm/kvm\n      Merge tag \u0027rproc-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux\n      Merge tag \u0027hwlock-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux\n      Merge tag \u0027clk-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux\n      Merge tag \u0027acpi-7.3-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n      Merge tag \u0027mm-stable-2026-08-26-15-22\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n      Merge tag \u0027mfd-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd\n      Merge tag \u0027leds-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/leds\n      Merge tag \u0027backlight-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/backlight\n      Merge tag \u0027rtc-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/abelloni/linux\n      Merge tag \u0027drm-next-2026-08-29\u0027 of https://gitlab.freedesktop.org/drm/kernel\n      Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi\n\nLorenzo Stoakes (3):\n      MAINTAINERS: add Lance as an rmap reviewer\n      mm: move alloc tag to mm\n      MAINTAINERS: move mm/interval_tree.c to rmap section\n\nLorenzo Stoakes (ARM) (1):\n      MAINTAINERS: add drivers/char/mem.c to mm misc, memory mapping sections\n\nLouis Kotze (2):\n      wifi: cfg80211: say why the auth/assoc BSS lookup failed\n      wifi: cfg80211: tests: check BSS lookup failure reasons\n\nManikanta Guntupalli (1):\n      i3c: master: Add driver for AMD AXI I3C master controller\n\nManivannan Sadhasivam (4):\n      MAINTAINERS: Drop Karthikeyan Mitran from Mobiveil PCIe entry\n      MAINTAINERS: Add Jeff Hugo as the Reviewer of MHI bus\n      MAINTAINERS: Add Manivannan Sadhasivam as the Reviewer for Generic PHY Framework\n      Documentation: PCI: Document how to write PCI Host Controller drivers\n\nMaoyi Xie (1):\n      wifi: mac80211: defer link RX stats percpu free to RCU\n\nMarcelo Schmitt (2):\n      dt-bindings: iio: adc: Add ltc2378\n      iio: adc: ltc2378: Add support for LTC2378-20 and similar ADCs\n\nMarek Szyprowski (1):\n      MAINTAINERS: update tree for DMA MAPPING HELPERS\n\nMark Brown (1):\n      ASoC: cs35l41/cs35l45/cs4265: sort the reg_defaults tables\n\nMarkus Probst (3):\n      rust: add basic serial device bus abstractions\n      samples: rust: add Rust serial device bus sample device driver\n      MAINTAINERS: serdev: Add self for serdev\n\nMartin K. Petersen (Oracle) (2):\n      Merge patch series \"scsi: Add LeapRAID driver support\"\n      scsi: MAINTAINERS: Update my email address\n\nMathieu Dubois-Briand (1):\n      nvmem: layouts: Add fixed-layout driver\n\nMatt Bobrowski (1):\n      bpf: update BPF LSM maintainer list\n\nMatt Coster (3):\n      MAINTAINERS: Update imagination details\n      MAINTAINERS: Update imagination maintainers\n      MAINTAINERS, mailmap: Update address for Matt Coster\n\nMatthew Leung (1):\n      dt-bindings: PCI: qcom: Document Hawi and Maili PCIe Controllers\n\nMatthew Wilcox (Oracle) (1):\n      efs: Remove EFS\n\nMaxime Chevallier (1):\n      MAINTAINERS: Add myself for stmmac ethernet driver maintainance\n\nMaxwell Doose (1):\n      iio: Update email for Maxwell Doose\n\nMete Durlu (1):\n      s390/idle: Introduce cpuidle for s390\n\nMichael Ellerman (1):\n      MAINTAINERS: Demote myself to reviewer\n\nMickaël Salaün (3):\n      landlock: Consolidate access-right and scope names in a shared header\n      landlock: Add create_ruleset and free_ruleset tracepoints\n      landlock: Document tracepoints\n\nMike Rapoport (Microsoft) (5):\n      Merge branch \u0027mm-stable-6d098029de09\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm into kho-scratch\n      mm: split out mm_init and memblock declarations from internal.h\n      mm: split out sparse declarations from internal.h\n      mm: split out vmalloc declarations from internal.h\n      drivers/base, mm: move arch_numa.c to mm/\n\nMikhail Lukianchikov (1):\n      dt-bindings: net: microchip,lan78xx: convert to DT schema\n\nMiri Korenblit (6):\n      wifi: iwlwifi: add a compile time check for too long hcmds\n      wifi: iwlwifi: support TTL platform device ID\n      wifi: iwlwifi: mld: cancel wiphy work before freeing wiphy\n      wifi: iwlwifi: mld: add PNVM_INIT_COMPLETE_NTFY to the hcmd names\n      wifi: iwlwifi: mld: move BIOS reading code to where it belongs\n      wifi: iwlwifi: bump core version for BZ/SC/DR\n\nMukesh Ojha (1):\n      MAINTAINERS: add rsc_table.h to remoteproc entry\n\nNamjae Jeon (3):\n      MAINTAINERS: update mailing list address for exfat\n      MAINTAINERS: update mailing list address for ntfs\n      MAINTAINERS: update ksmbd repository URL\n\nNatalie Vock (1):\n      MAINTAINERS: Update Natalie Vock\u0027s email\n\nNick Desaulniers (1):\n      MAINTAINERS: update ndesaulniers\n\nNico Pache (Red Hat) (1):\n      MAINTAINERS: update Nico Pache\u0027s email address\n\nNicolai Buchwitz (1):\n      MAINTAINERS: remove Rengarajan Sundararajan from LAN78XX\n\nNiklas Söderlund (1):\n      media: rppx1: Add framework to support Dreamchip RPPX1 ISP\n\nNirmal Patel (1):\n      PCI: vmd: Add feature to scan BIOS-enumerated devices\n\nOnur Özkan (1):\n      MAINTAINERS: add Rust SRCU files to SRCU entry\n\nP Praneesh (5):\n      wifi: cfg80211: Drop unused link stats handling in nl80211_send_station()\n      wifi: cfg80211: Add helper to pack station-level STA_INFO\n      wifi: cfg80211: Refactor nl80211_dump_station() to prepare for per-link stats\n      wifi: cfg80211: Fragment per-link station stats in nl80211_dump_station()\n      wifi: cfg80211: support MAC address filtering in station dump for link stats\n\nPagadala Yesu Anjaneyulu (10):\n      wifi: mac80211: ibss: wait for in-flight TX on disconnect\n      wifi: iwlwifi: ignore raw-DSM TLV for LARI cmd version 13 and above\n      wifi: iwlwifi: regulatory: add LARI_CONFIG_CHANGE command v14 support\n      wifi: iwlwifi: mld: honor FW puncturing capability in MCC response\n      wifi: iwlwifi: mvm: add LARI_CONFIG_EXTENSION command\n      wifi: iwlwifi: mvm: validate SAR GEO response payload size\n      wifi: iwlwifi: mld: support update_mcc notification v2\n      wifi: iwlwifi: mld: add debug log after AP type command\n      wifi: mac80211: notify driver before destroying assoc link\n      wifi: iwlwifi: regulatory: add LARI v15 DSM support bitmap\n\nPaolo Abeni (4):\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n      Merge tag \u0027wireless-2026-07-09\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless\n      Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPaolo Bonzini (5):\n      Merge tag \u0027kvmarm-fixes-7.2-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm into HEAD\n      Merge tag \u0027kvmarm-fixes-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm into HEAD\n      Merge tag \u0027kvm-s390-next-7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kvms390/linux into HEAD\n      Merge tag \u0027kvm-x86-maintainers-7.3\u0027 of https://github.com/kvm-x86/linux into HEAD\n      Merge tag \u0027loongarch-kvm-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson into HEAD\n\nPaulo Alcantara (1):\n      MAINTAINERS: Replace Steve French as CIFS maintainer\n\nPeddolla Harshavardhan Reddy (1):\n      wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nPengpeng Hou (2):\n      wifi: iwlwifi: validate PNVM SKU TLV length\n      wifi: iwlwifi: validate UEFI reduced-power SKU TLV length\n\nPetr Vorel (1):\n      MAINTAINERS: add IRC and patchwork for LTP\n\nPhillip Lougher (1):\n      MAINTAINERS: remove git URL for Squashfs\n\nPratyush Yadav (Google) (1):\n      x86/setup: do not include kexec_handover.h from asm/setup.h\n\nPraveen Rajendran (1):\n      wifi: iwlwifi: fw: Fix spelling typo in error-dump.h\n\nPriyansha Tiwari (4):\n      wifi: nl80211/cfg80211: rename probe_client to probe_peer\n      wifi: cfg80211/nl80211: add STA-mode peer probing\n      wifi: mac80211: implement STA-mode peer probing\n      wifi: mac80211_hwsim: report TX status link_id\n\nQingfang Deng (1):\n      tty: remove the ipwireless driver\n\nRadhey Shyam Pandey (1):\n      MAINTAINERS: Add Radhey Shyam Pandey as ZynqMP PHY maintainer\n\nRafael J. Wysocki (1):\n      ACPI: Update MAINTAINERS entry for ACPICA\n\nRandy Dunlap (1):\n      MAINTAINERS: docs: add reviewer\n\nRichard Fitzgerald (1):\n      ALSA: hda: MAINTAINERS: Fix missing cirrus* file reference\n\nRodrigo Alencar (3):\n      dt-bindings: iio: frequency: add adf41513\n      iio: frequency: adf41513: driver implementation\n      docs: iio: add documentation for adf41513 driver\n\nRoger Pau Monne (1):\n      MAINTAINERS: update my email address\n\nRoman Vivchar (2):\n      dt-bindings: iio: adc: mediatek,mt6359-auxadc: add mt6323 PMIC AUXADC\n      iio: adc: mt6323-auxadc: add mt6323 PMIC AUXADC driver\n\nRoy Pledge (1):\n      MAINTAINERS: Update drivers/soc/fsl/dpio maintainer\n\nSJ Park (1):\n      MAINTAINERS: s/SeongJae/SJ/\n\nSai Krishna Potthuri (1):\n      MAINTAINERS: Update Xilinx AMS driver maintainers\n\nSakari Ailus (1):\n      MAINTAINERS: Merge int3472 driver patches via the media tree by default\n\nSalih Erim (1):\n      iio: adc: add Versal SysMon driver\n\nSasha Finkelstein (1):\n      dt-bindings: soc: apple: Add Apple PMGR misc controls\n\nSean Christopherson (4):\n      MAINTAINERS: Add kvm-x86 tree to KVM x86 entries\n      MAINTAINERS: Add an entry for KVM\u0027s guest_memfd\n      MAINTAINERS: Add David H. as a KVM guest_memfd reviewer\n      MAINTAINERS: Add myself (Sean) as a reviewer in the main KVM entry\n\nShahar Tzarfati (5):\n      wifi: mac80211: recalculate rx_nss on IBSS peer capability update\n      wifi: iwlwifi: mld: fix read in wake packet notification handler\n      wifi: iwlwifi: fw: validate SMEM response size\n      wifi: iwlwifi: mvm: fix read in wake packet notification handler\n      wifi: mac80211: ibss: read deauth reason_code after frame length check\n\nShyam Sundar S K (1):\n      Documentation/ABI: add testing entry for AMD PMF character device interface\n\nSiratul Islam (3):\n      dt-bindings: iio: magnetometer: add QST QMC5883L Sensor\n      iio: magnetometer: add driver for QST QMC5883L Sensor\n      iio: update email for Siratul Islam\n\nSrinivas Achary (1):\n      wifi: cfg80211: change mesh_setup::ie_len to size_t\n\nSrinivas Kandagatla (1):\n      MAINTAINERS: fastrpc: remove inactive maintainer and add reviewer\n\nSteffen Eiden (1):\n      KVM: s390: Move s390 kvm code into a subdirectory\n\nStephen Boyd (5):\n      Merge tag \u0027renesas-clk-for-v7.3-tag1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-drivers into clk-renesas\n      Merge tag \u0027clk-microchip-7.3\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/at91/linux into clk-microchip\n      Merge tag \u0027clk-misc-for-v7.3\u0027 of ssh://github.com/masneyb/linux into clk-pile\n      Merge tag \u0027clk-misc-round-two-for-v7.3\u0027 of ssh://github.com/masneyb/linux into clk-pile\n      Merge branches \u0027clk-pile\u0027 and \u0027clk-microchip\u0027 into clk-next\n\nSteve French (1):\n      Add missing git branch info for cifs and ksmbd to MAINTAINERS file\n\nSumit Garg (1):\n      MAINTAINERS: Add maintainer entry for Qualcomm PAS TZ service\n\nSuren Baghdasaryan (2):\n      MAINTAINERS: move inactive maintainer to CREDITS\n      alloc_tag: add ioctl to /proc/allocinfo\n\nSwark Yang (2):\n      dt-bindings: mailbox: add Axiado AX3005 mailbox\n      mailbox: add Axiado AX3005 mailbox driver\n\nThierry Reding (1):\n      PCI: tegra264: Add Tegra264 support\n\nThomas Gleixner (1):\n      MAINTAINERS: Add Radu Rendec as reviewer for the interrupt subsystem\n\nThomas Huth (1):\n      mac80211: fils_aead: Use __cleanup() instead of memzero_explicit()\n\nThomas Zimmermann (2):\n      Merge drm/drm-next into drm-misc-next\n      Merge drm/drm-next into drm-misc-next\n\nTomasz Duszynski (1):\n      iio: chemical: scd30: update email for Tomasz Duszynski\n\nTroy Mitchell (1):\n      MAINTAINERS: add SpacemiT K1/K3 I2S entry\n\nTze Yee Ng (1):\n      hwmon: add Altera SoC FPGA hardware monitoring driver\n\nUwe Kleine-König (1):\n      Drop Michael Turquette\u0027s clk maintainer entry\n\nVicki Pfau (1):\n      HID: steam: Update documentation\n\nVictor Raj (1):\n      virtchnl: move virtchnl and virtchnl2 headers to \u0027include/linux/net/intel\u0027\n\nVincent Jardin (1):\n      hwmon: (pmbus) Add MPQ8646 driver\n\nWadim Mueller (2):\n      dt-bindings: iio: flow: add Sensirion SLF3S liquid flow sensor\n      iio: flow: add Sensirion SLF3S liquid flow sensor driver\n\nWenjia Zhang (1):\n      MAINTAINERS: Update SHARED MEMORY COMMUNICATIONS (SMC) maintainer entries\n\nWensheng Wang (1):\n      hwmon: (pmbus) Add MPQ82D00 driver\n\nWill Deacon (3):\n      MAINTAINERS: arm64: Add Mark Rutland as an official Reviewer\n      Merge branch \u0027for-next/perf\u0027 into for-next/core\n      Merge branch \u0027for-next/sdei\u0027 into for-next/core\n\nXiang Mei (3):\n      wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n      wifi: mac80211: fix fils_discovery double free on alloc failure\n      wifi: mac80211: tear down new links on vif update error path\n\nXiang-Bin Shi (1):\n      atm: remove unused exported helpers\n\nXuyang Dong (1):\n      dt-bindings: clock: Add ESWIN eic7700 HSP clock and reset generator\n\nYicong Yang (1):\n      perf/dwc_pcie: Add support for Picoheart vendor devices\n\nYihang Li (1):\n      scsi: MAINTAINERS: Update HiSilicon hisi_sas driver maintainer to Xingui Yang\n\nYixun Lan (1):\n      MAINTAINERS: Update SpacemiT SoC git tree repository\n\nYo-Jung Leo Lin (AMD) (1):\n      platform/x86/amd: Introduce Halo Box RGB LED driver\n\nYousef Alhouseen (1):\n      wifi: mac80211_hwsim: avoid treating MCS as legacy rate index\n\nYury Norov (1):\n      lib: test bitmap vs IDA vs Maple Tree performance for region allocations\n\nYuyang Huang (1):\n      wifi: mac80211: use ifa_dev from event argument\n\nZenghui Yu (Huawei) (1):\n      MAINTAINERS: add ABI docs and selftests to ZRAM entry\n\nZhao Li (25):\n      wifi: nl80211: free RNR data on MBSSID mismatch\n      wifi: mac80211: validate extension-frame layout before RX\n      wifi: cfg80211: derive S1G beacon TSF from S1G fields\n      wifi: ieee80211: validate MLE common info length\n      wifi: nl80211: validate nested MBSSID IE blobs\n      wifi: nl80211: constrain MBSSID TX link ID range\n      wifi: cfg80211: validate PMSR measurement type data\n      wifi: cfg80211: validate PMSR FTM preamble range\n      wifi: cfg80211: reject unsupported PMSR FTM location requests\n      wifi: cfg80211: reject empty PMSR peer lists\n      wifi: mac80211: avoid non-S1G AID fallback for S1G assoc\n      wifi: mac80211: validate deauth frame length before reason access\n      wifi: cfg80211: validate rx/tx MLME callback frame lengths before access\n      wifi: cfg80211: validate assoc response length before status and IE access\n      wifi: cfg80211: guard optional PMSR nominal time\n      wifi: mac80211_hwsim: authenticate PMSR report senders\n      wifi: mac80211_hwsim: clear PMSR request state on abort\n      wifi: mac80211: fix tid_tx use-after-free on BA session stop\n      wifi: cfg80211: publish PMSR request before starting the driver\n      wifi: mac80211: validate individual TWT params before driver setup\n      wifi: mac80211: fix per-STA profile length in cross-link CSA parsing\n      wifi: mac80211: send TWT teardown to peer after setup TX failure\n      wifi: nl80211: clean up color-change beacon data on errors\n      wifi: mac80211: skip unused probe response countdown offsets\n      wifi: cfg80211: stop PMSR before P2P and NAN teardown\n\nZhi Wang (1):\n      rust: introduce abstractions for fwctl\n\nZhiling Zou (1):\n      wifi: mac80211: free ack status frame on TX header build failure\n\nx-git-tracker-backport: 8a64838b9aa234164cde19e4566f962a118e5fa9\nx-git-tracker-iwlwifi: 05ffb9a625ef6e33bb7bacaa0dfa40214790acc6\nChange-Id: I131d3b1408144aa034b184a3e1e12c0da9942681\nx-iwlwifi-stack-dev: 638c3812a4003a0dcc520e39c792edd7ce2a0bd3"
    },
    {
      "commit": "070e486a6d462c79bf6356832af28e45c1b94519",
      "tree": "adb44f272b98153e49c396fa05f29a8d66a41cc8",
      "parents": [
        "1fcd9d619e6bc455ed618b3054889452e48c7916"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Aug 26 13:01:50 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 30 03:31:35 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: honor the per-channel 320 MHz regulatory flag\n\nWhen support for the MCC update response version 8 was added, the API\nchange was implemented only partially. That version introduced two new\npieces of information about 320 MHz: the global capability\nREG_CAPA_V5_320MHZ_ALLOWED and a per-channel bit, BIT(12), in the\nchannel flags carried by the response. Only the former was picked up.\nBIT(12) kept its previous meaning in the driver, NVM_CHANNEL_DC_HIGH,\na leftover from old devices that nothing used, so the new bit was\nsilently dropped.\n\nThe two are not equivalent, the per-channel bit can be more restrictive\nthan the global capability. When that happens, cfg80211 is told that\n320 MHz is allowed, mac80211 builds a 320 MHz channel context, and the\nfirmware rejects the resulting PHY_CONTEXT_CMD and asserts with\n0x200014FC.\n\nRename the bit to NVM_CHANNEL_320MHZ and set NL80211_RRF_NO_320MHZ for\nthe channels that don\u0027t have it, so that we cap the bandwidth at\n160 MHz instead of asserting the firmware. The bit is checked in every\nband, so that a future band that supports 320 MHz is covered as well.\n\ntype\u003dbugfix\nticket\u003djira:WIFI-909622\nfixes\u003dIbddcb9fbfa74895f742c0ac20968720691c94853\n\nChange-Id: Ic0a4bf544fd6ebaf1fc62b40bf463bd289e58cf0\nAssisted-by: GitHub-Copilot:claude-opus-5\nCloses: https://bugzilla.kernel.org/show_bug.cgi?id\u003d221675\nFixes: b2d2ad72e06e (\"wifi: iwlwifi: update response for mcc_update command\")\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/321007\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: e558ef10bad3e8af6d275cc9406a0583bb9e5c87"
    },
    {
      "commit": "1fcd9d619e6bc455ed618b3054889452e48c7916",
      "tree": "845829e82c494626790a7f67f173d8325e700fbe",
      "parents": [
        "0a5135849b464fa19bcaf9df81838d5ffcfc72af"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Fri Aug 21 09:00:41 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 08:58:39 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: pcie: order RX reads after the write pointer\n\niwl_pcie_rx_handle() reads the last closed RB index from rb_stts and\nthen reads the completion descriptor and the RB contents that this\nindex makes visible. Nothing orders those two reads: there is no\nbarrier, the descriptor address derives from rxq-\u003eread rather than\nfrom the index just read, so there is no address dependency, and the\n\"while (i !\u003d r)\" test is only a control dependency, which does not\norder loads on arm64.\n\nThe CPU can therefore speculate past the loop test, perform the\ncompletion descriptor load early and sample the value from before\nthe device\u0027s DMA, then resolve the rb_stts load to the value from\nafter it. On arm64 (Jetson AGX Orin) this showed up as recurring\n\"Invalid rxb from HW \u003cvid\u003e\" naming an in-range rbid the driver still\nowned, and \"frame on invalid queue\" for an RB tagged with the queue\nthat used it before the wrap. Both force an NMI and a firmware\nrestart. x86 never shows it because loads are not reordered with\nloads there.\n\nAdd a dma_rmb() after reading the write pointer, as other NIC drivers\ndo when consuming a DMA descriptor ring. It is a no-op on x86 and a\ndmb on arm64. Verified to stop the warnings on Orin.\n\ntype\u003dbugfix\nticket\u003dnone\nfixes\u003dunknown\n\nChange-Id: I24dec81516e37a33674e87ed3359c41e59d12e5e\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nAssisted-by: GitHub-Copilot:claude-opus-5\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320351\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 942392bec1fb81f9acb46869452d2fd29d99af7f"
    },
    {
      "commit": "0a5135849b464fa19bcaf9df81838d5ffcfc72af",
      "tree": "c525f1d009cb18a105d46ae6e10181b943e87d89",
      "parents": [
        "e6389b39bcb35d8e8ee384c9ddcb527818c52a4f"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Fri Aug 21 12:26:41 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 05:33:54 2026 +0000"
      },
      "message": "wifi: iwlwifi: fw: add Samsung to TAS and PPAG allow lists\n\nAllow platforms reporting the exact manufacturer string\n\"Samsung\" to use TAS and PPAG, while retaining the existing\nSamsung Electronics entry.\n\ntype\u003dfeature\nticket\u003djira:WIFI-945102\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nChange-Id: I18a7292b5a8bd878d074b114b45ce99e1309897e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319899\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 5d2aae30bdacde2f0d9b748fd810709214dec9ec"
    },
    {
      "commit": "e6389b39bcb35d8e8ee384c9ddcb527818c52a4f",
      "tree": "7db2c390ea42cc407ffb44a3f5022d0f9d566ae3",
      "parents": [
        "8461b199230d971167f05b1e24e408e5382baf99"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Mon Jul 27 08:35:02 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 05:33:15 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: fw: harden UEFI reduced-power TLV parsing\n\nUEFI reduced-power parsing advanced by ALIGN(tlv_len, 4) but\nvalidated only tlv_len. When remaining bytes were between these\nvalues, len could underflow and parsing could continue past the\nbuffer boundary.\n\nValidate remaining bytes against the aligned length before\nadvancing in both TLV walkers. Also reject short PNVM_SKU TLVs\nbefore reading sku_id fields.\n\ntype\u003dbugfix\nticket\u003djira:WIFI-920950\nfixes\u003dI81bf1bdee64ae7e3f8b6c1a049b0adea6605d105\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nChange-Id: I570750f27d9530d4c76922d2699a272d9c60a0ab\nAssisted-by: GitHubCopilot:GPT-5.3-Codex\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/313183\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 2bd4f3c9a6a9b491c001d29e3ffea9a753cb0b51"
    },
    {
      "commit": "8461b199230d971167f05b1e24e408e5382baf99",
      "tree": "6a158998ebafd00adba104e85fe5f8e7337cfd2e",
      "parents": [
        "cf9bfbbc73a215c4e157933378e135b5717ae656"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Wed Aug 19 07:33:34 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 05:24:51 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: uefi: Fix SAR enable check to use mode parameter correctly\n\nThe iwl_uefi_set_sar_profile() function was receiving a bool parameter,\nwhich would treat any non-zero value as enabled. This is incorrect because\nthe SAR mode value contains additional bits beyond the enable flag.\n\nChange the parameter from bool enabled to u32 mode and properly extract\nthe enable bit using IWL_SAR_ENABLE_MSK bitmask. This ensures that only\nthe designated enable bit determines whether SAR is enabled, not arbitrary\nnon-zero values.\n\ntype\u003dbugfix\nfixes\u003dunknown\nticket\u003dnone\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nChange-Id: Ib184c201e677cb6d95f64e725a1e39148234fa41\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319060\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 282d6f9f69d12b6241b39f1d9cb29738a76d4166"
    },
    {
      "commit": "cf9bfbbc73a215c4e157933378e135b5717ae656",
      "tree": "677b4ba8fbbefd7224c61a24ee8e096aa2c8e625",
      "parents": [
        "d54013b30253f33f75fd840191d2ec8cb7d38e74"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Tue Aug 18 13:08:24 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 05:24:47 2026 +0000"
      },
      "message": "wifi: iwlwifi: send standalone SAR to firmware\n\nPlumb the standalone WRSS/EWSS SAR data and\nsend the standalone profile to firmware.\n\nAdd REDUCE_TX_POWER_CMD version 12 support with the\nIWL_TX_POWER_MODE_SET_STANDALONE_CHAINS set_mode, and rename\niwl_dev_tx_power_cmd_v11 to iwl_dev_tx_power_cmd_v12 to match the\nupdated command layout.\n\nThis enables higher transmit power limits for standalone firmware\noperation while preserving the existing concurrent SAR handling.\n\ntype\u003dfeature\nticket\u003djira:WIFI-909609\nticket\u003djira:WIFI-917994\n\nChange-Id: Ic02190e91e795dcfe660710721b47de71f2b2c86\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319061\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 2e03ce83acb6dea4572c4b0114a30c8570a305dd"
    },
    {
      "commit": "d54013b30253f33f75fd840191d2ec8cb7d38e74",
      "tree": "f1c917af61bebcde4734bedc444cf095bd5a26c7",
      "parents": [
        "04574cb03e404171005b045cb0edb63242cf3a4b"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Tue Aug 18 13:08:08 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Wed Aug 26 05:24:43 2026 +0000"
      },
      "message": "wifi: iwlwifi: add standalone WRSS/EWSS BIOS table loading\n\nAdd support for reading WRSS and EWSS standalone SAR tables\nfrom the BIOS in the ACPI and UEFI paths.\n\nWRDS/EWRD tables describe SAR limits for concurrent Wi-Fi\nand Bluetooth operation. When Bluetooth is not active,\nthose limits can unnecessarily restrict Wi-Fi transmit power.\nWRSS/EWSS provide separate standalone SAR profiles for Wi-Fi-only\noperation, allowing the firmware to select the appropriate\nhigher-power limits while still respecting the platform-specific\nregulatory constraints.\n\ntype\u003dfeature\nticket\u003djira:WIFI-909609\nticket\u003djira:WIFI-917994\n\nChange-Id: Id79836e772136e1e38f107b578007faf39b13b4e\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/308221\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: e23b761f41bdc8f94bd93a3cd624a6f3dd0d9b3e"
    },
    {
      "commit": "04574cb03e404171005b045cb0edb63242cf3a4b",
      "tree": "79fdc8e57d3730e5f83f64762a2431e6f923d07d",
      "parents": [
        "93211037f4bc736917a6e03ed3653c3bdde5d051"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Sun Aug 23 18:15:17 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 20:49:10 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: mvm: validate BAID from FW\n\nThe BAID from the ADD_STA response is used to access mvm-\u003ebaid_map[]\nwithout an upper bound check.\nCheck and reject an invalid value.\n\ntype\u003dbugfix\nticket\u003djira:WIFI-920968\nfixes\u003dunknown\n\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nChange-Id: I9a99a140ab72cb1790a03a130ae7c8aa93cfac01\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320180\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: b13c85a178c3768ac8eb6f797ad8eb5b8af6e5e5"
    },
    {
      "commit": "93211037f4bc736917a6e03ed3653c3bdde5d051",
      "tree": "080377e3642d9b0d8d6348cea782143a583cee0a",
      "parents": [
        "b313b4869031cfbf0f77c66c885ab4cb6c2c74c9"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 25 08:35:28 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 19:21:20 2026 +0000"
      },
      "message": "wifi: iwlwifi: support for another device ID\n\nAdd support of another flavor of AX231.\n\ntype\u003dfeature\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I1fd3aa97da28065966952c36edcdb99acd5313cb\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320591\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 07c7b8d15c3f1e7787fd66a08e2630db5686c5e7"
    },
    {
      "commit": "b313b4869031cfbf0f77c66c885ab4cb6c2c74c9",
      "tree": "a7d490caf3c8d73729fe1b3ffb25be1dc50e0c0f",
      "parents": [
        "57fc4b6d162b294eda8de3bdeed9004be32c0726"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Fri Aug 21 14:17:36 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 17:35:05 2026 +0000"
      },
      "message": "[NOUPSTREAM] wifi: iwlwifi: mld: honor FW ack of Fatal Error Test Mode\n\nWhen FATAL_ERROR_TEST_MODE is enabled the transport already stops acting\non HW RF-Kill and relies on the FW to raise a fatal error instead. That\nis only safe if the FW actually supports the mode; otherwise HW RF-Kill\nwould be silently ignored with nothing taking over.\n\nThe FW reports whether it accepted the mode in its alive notification.\nCheck that on alive and, if the FW did not ack it, clear\nFATAL_ERROR_TEST_MODE so the driver falls back to the normal RF-Kill\nhandling on the next evaluation.\n\ntype\u003dfeature\nticket\u003djira:WIFI-876942\n\nChange-Id: Ib2e049b40e1c2987b840b135ca5914027eefba34\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nAssisted-by: GitHub-Copilot:claude-opus-4-8\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320154\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 5503690aae9a1b618427c0364811c443a6040a1a"
    },
    {
      "commit": "57fc4b6d162b294eda8de3bdeed9004be32c0726",
      "tree": "f3bc96ee8df9634df374a29c4e8c1b21434bfdf1",
      "parents": [
        "fa39573bbf674735403ddb690b74dc36fa6c2668"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Fri Aug 21 14:13:24 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 17:35:00 2026 +0000"
      },
      "message": "[NOUPSTREAM] wifi: iwlwifi: pcie: add Fatal Error Test Mode INI knob\n\nFor validation of the fatal error dump path we need a way to make the\nFW convert a HW RF-Kill event into a fatal error instead of running the\nnormal RF-Kill flow. Expose this as a debug-only FATAL_ERROR_TEST_MODE\nknob in the iwl-dbg-cfg.ini config.\n\nTwo things are required for this to work. First, the FW has to be told\nto enable the mode, so when the knob is set the corresponding request\nbit is added to the context info built for the next FW load. Second, the\ndriver must not act on HW RF-Kill itself. So while the knob is set the\ntransport treats HW RF-Kill as off and leaves the handling to the FW.\n\ntype\u003dfeature\nticket\u003djira:WIFI-876942\n\nChange-Id: Ie3d372453549a2735f923566294db518dd8ddf8e\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nAssisted-by: GitHub-Copilot:claude-opus-4-8\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320153\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 5df780355a2930d837b7c188dfe88cc260edd9f6"
    },
    {
      "commit": "fa39573bbf674735403ddb690b74dc36fa6c2668",
      "tree": "b55bd902a7a4db2f9b2280b1ca00473b3bd38d5f",
      "parents": [
        "212d97916863b19fbd765e4fa9cc5067882b9f4d"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Mon Aug 24 22:09:47 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 06:21:57 2026 +0000"
      },
      "message": "[BUGFIX][NOUPSTREAM] wifi: iwlwifi: mld: fix the Rx nss\u003d0 firmware check\n\nThe nss\u003d0 check was added under CPTCFG_IWLWIFI_SUPPORT_DEBUG_OVERRIDE,\nbut the Kconfig symbol is CPTCFG_IWLWIFI_SUPPORT_DEBUG_OVERRIDES. Since\nthe singular spelling exists nowhere else in the tree, both checks were\nsilently compiled out and mac80211 was the only one to complain about\nRx with nss\u003d0.\n\nWhile at it, only check nss for VHT and later: iwl_mld_set_rx_rate()\nleaves nss at 0 for CCK, legacy OFDM and HT, so the check would have\nfired on nearly every frame in a sniffer capture and hidden the real\noccurrences. mac80211 doesn\u0027t validate nss for those encodings either.\n\ntype\u003dbugfix\nticket\u003djira:WIFI-929828\nfixes\u003dI5af924946b95da27dd6d49b6cb1d3c19c3e3a961\n\nChange-Id: I038ecb539263e234a8d874658f6c599ee3c0f4ef\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320463\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 3393341ef7d7ca6fbf63835d7e353f841b47d96d"
    },
    {
      "commit": "212d97916863b19fbd765e4fa9cc5067882b9f4d",
      "tree": "25057a7c03a951ef27acfb5dbcd406f0b789326c",
      "parents": [
        "bbc75803262a909c2b8beed54a9511ffe82821e6"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Mon Aug 24 23:13:35 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 25 05:15:13 2026 +0000"
      },
      "message": "[NOUPSTREAM] backport: define EFI_ACCESS_DENIED for older kernels\n\nAdd the missing EFI_ACCESS_DENIED status definition to the EFI\ncompatibility wrapper for kernels predating v6.8.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nChange-Id: I3a9fe477f3edce796d40866422f85a9888007756\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/320468\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 89cac5ad142947f510aeeba2071e7fe7db2ca0df"
    },
    {
      "commit": "bbc75803262a909c2b8beed54a9511ffe82821e6",
      "tree": "da8903cd76b0a64b750eb4493fcd58ee32d3520c",
      "parents": [
        "5eae07c3759c4e4221f7581b1c6e036f7d8180f3"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Sun Aug 23 10:07:54 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 23 17:14:36 2026 +0000"
      },
      "message": "wifi: iwlwifi: regulatory: use GLUI as root-of-trust for connectivity variables\n\nThe BIOS tables can be sourced from either UEFI or ACPI. The UEFI\ncopies are writable, so they may be trusted only when the platform\nattests they are locked. Resolve this trust from a single source,\npreferring the UEFI GUID Lock Indicator (GLUI) and consulting the ACPI\nGLAI whenever GLUI does not attest the tables as locked or in test mode.\n\nAdd iwl_bios_get_guid_lock_status() as that entry point and have the\nmvm and mld op-modes use it instead of the ACPI-only helper, so trust is\nresolved consistently regardless of whether a platform ships GLUI or\nGLAI.\n\ntype\u003dfeature\nticket\u003djira:WIFI-879636\n\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nChange-Id: I46f8c4d55bd22d98a7200cce8f528c5e182f443c\nAssisted-by: GitHub-Copilot:claude-opus-4-8\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/311861\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: bcd7e5c30102c3cb29b325a7ec5ef5e478987598"
    },
    {
      "commit": "5eae07c3759c4e4221f7581b1c6e036f7d8180f3",
      "tree": "8af5aeefd35097fc2d0a772846048c91d73c8ef8",
      "parents": [
        "d3ffeed72fd7304b0bf750873fa88571019130e1"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Mon Aug 17 10:13:10 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 23 17:14:32 2026 +0000"
      },
      "message": "wifi: iwlwifi: uefi: add a way to probe connectivity UEFI variables\n\nThe connectivity UEFI variables are only trusted when the platform\nattests they are locked. When the lock status is unknown, the trust of\neach variable has to be discovered on its own by checking whether it is\nwrite protected. Probing depends on trying to rewrite UEFI variables and\nit is only attempted on non-x86 platforms. If the write is rejected the\nvariable is considered locked and therefore trusted, otherwise it is\ntreated as not trusted.\n\nSeparate reading such a variable into two steps:\niwl_uefi_get_variable_guid() only fetches and validates the variable,\nwhile iwl_uefi_get_verified_variable_guid() layers the trust decision on\ntop of it. The latter now takes an iwl_fw_runtime so it can consult the\nlock status. Rename its WiFi-GUID wrapper from\niwl_uefi_get_verified_variable() to iwl_uefi_get_verified_wifi_var().\n\nWith the trust check now performed by every iwl_uefi_get_*() reached\nthrough the GET_BIOS_TABLE() macro, the per-table lock-status gate in\nthat macro is redundant, so drop it here.\n\nThis move, and the new unknown-status handling, affect only the tables\nreached through GET_BIOS_TABLE(), i.e. those that have both a UEFI and\nan ACPI source.\n\ntype\u003dfeature\nticket\u003djira:WIFI-879636\n\nAssisted-by: GitHub-Copilot:claude-opus-4-8\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nChange-Id: I877c0d6ab5126edb3e4f1f187ca1e20e563b2ec4\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/311832\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 579e5081e70e5ad6f764bb9253b2fd10fcb53519"
    },
    {
      "commit": "d3ffeed72fd7304b0bf750873fa88571019130e1",
      "tree": "1bdf6d3515f88d1436dba5b3cf77a30d5d683d99",
      "parents": [
        "69b67f99ab0db5cf2f0677ded3a960ba43912131"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Mon Aug 17 09:42:40 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 23 17:14:27 2026 +0000"
      },
      "message": "wifi: iwlwifi: uefi: add UEFI GUID Lock Indicator (GLUI) definitions\n\nThe platform provides a root-of-trust mechanism for connectivity UEFI\nvariables via a dedicated UEFI GUID Lock Indicator (GLUI) variable. The\nGLUI may remain locked in both production and testing modes. A UEFI\nindicator is used rather than relying on the ACPI GLAI alone, so the\nmechanism also works on platforms that do not expose ACPI.\n\nAdd the building blocks for consuming this variable and\niwl_uefi_get_guid_lock_status() to read its value and store it, so the\ndriver can use its lock state to decide whether the connectivity UEFI\nvariables are trusted.\n\ntype\u003dfeature\nticket\u003djira:WIFI-879636\n\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nChange-Id: If4c9949de70fe78951464b983caf2c9d974061b3\nAssisted-by: GitHub-Copilot:claude-opus-4-8\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/302067\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: c85407fef21070e012ae6cd08bf099aadfb56ecf"
    },
    {
      "commit": "69b67f99ab0db5cf2f0677ded3a960ba43912131",
      "tree": "685c4ac5131f84a1a1b9a18dcc943f80c1c3afb1",
      "parents": [
        "50f353f48c9513940d88a26bdd29d3fe1c4e0d25"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 19:46:37 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:47 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: drop gen1_2 prefix from alloc/free_tx_cmd\n\nThe gen1_2 PCIe transport helpers for allocating and freeing a device\ntx command were named iwl_pcie_gen1_2_alloc_tx_cmd() and\niwl_pcie_gen1_2_free_tx_cmd() to distinguish them from planned gen3\ntwins. The gen3 transport was removed, so the qualifier is no longer\nmeaningful. Rename them to iwl_pcie_alloc_tx_cmd() and\niwl_pcie_free_tx_cmd(). No functional change.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I6c7646ecdad1408b36b2a183ed8deb753511df3a\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319191\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 079baf7c4713ebb8b06f2a08801dccac3dda5998"
    },
    {
      "commit": "50f353f48c9513940d88a26bdd29d3fe1c4e0d25",
      "tree": "1032b3331fded92eea28a8973c5b296559d68338",
      "parents": [
        "f67b2724d48da6fcb1114410809d55632ae5d89d"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 18:26:42 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:43 2026 +0000"
      },
      "message": "wifi: iwlwifi: Revert \"wifi: iwlwifi: pcie: move generation specific files to a folder\"\n\nThis reverts commit a6fafaedb5d6 (\"wifi: iwlwifi: pcie: move generation\nspecific files to a folder\").\n\nThe pcie/gen1_2/ subfolder was introduced to separate the gen1_2 and\ngen3 transport sources. The gen3 transport was removed, so move rx.c,\ntx.c, trans.c, trans-gen2.c, tx-gen2.c and internal.h back to pcie/,\nrestore the flat object list in the Makefile and the corresponding\ninclude paths and publishable-files entries. The later-added pcie/utils.o\nis kept. No functional change.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I25521996309a25ac779cb31f2c93477b25be9ac3\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319162\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: f19d0e21b0552ab1627e95ed9ba8ed45903acfad"
    },
    {
      "commit": "f67b2724d48da6fcb1114410809d55632ae5d89d",
      "tree": "5c693e252fa7c8ecd4694f358ee9533587c5fcf9",
      "parents": [
        "11f2ad56845076bd952e9b4bd61e2b8cf200f905"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Aug 20 20:57:11 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:39 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: remove gen1_2 prefix from probe\n\nThere won\u0027t be gen3 at the end, so we don\u0027t this prefix to\ndifferentiate. Remove it.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I1174e7ee1b3d0a85601861286424bed01ff25aca\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319796\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 1efeb6aad083eb7f00edb2d94292b55b99e07c78"
    },
    {
      "commit": "11f2ad56845076bd952e9b4bd61e2b8cf200f905",
      "tree": "cb574c2a646a14d870c9a1df21d8e008127a6442",
      "parents": [
        "e32471a37ee0d46ba1221b1f34665e85e0d25285"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 17:25:09 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:35 2026 +0000"
      },
      "message": "wifi: iwlwifi: Revert \"wifi: iwlwifi: gen1_2: rename iwl_trans_pcie_op_mode_enter\"\n\nThis reverts commit 3a7ad289f83d (\"wifi: iwlwifi: gen1_2: rename\niwl_trans_pcie_op_mode_enter\").\n\nThe op_mode_enter callback was renamed to iwl_pcie_gen1_2_op_mode_enter()\nonly to distinguish it from a planned gen3 version. The gen3 transport\nwas removed, so restore the original iwl_trans_pcie_op_mode_enter() name.\nNo functional change.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I8d1efe0f717a772ab47bd03794d0870a1a273792\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319158\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: affff45a064487e36f1099862c14d2bce11dbdce"
    },
    {
      "commit": "e32471a37ee0d46ba1221b1f34665e85e0d25285",
      "tree": "c3b73911d4e5a437242e09fb2ab6c1f76fbc6de3",
      "parents": [
        "4d237b4fb75f1928c17c5fd34e5bdb7880485483"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 17:24:19 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:31 2026 +0000"
      },
      "message": "wifi: iwlwifi: Revert \"wifi: iwlwifi: gen1_2: move gen specific code to a function\"\n\nThis reverts commit b5b4a44a53f0 (\"wifi: iwlwifi: gen1_2: move gen\nspecific code to a function\").\n\nThe remove flow body was factored out into iwl_pcie_gen1_2_remove() only\nso a separate gen3 remove path could share iwl_pci_remove(). The gen3\ntransport was removed, so inline the code back into iwl_pci_remove() and\ndrop the now-unused helper. No functional change.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: Ic19d96486253518e2107d91e512654596689a426\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319157\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 237e962687925bf0b22d0e04c3606f1709394161"
    },
    {
      "commit": "4d237b4fb75f1928c17c5fd34e5bdb7880485483",
      "tree": "545bfa78fdb7a41de1d381dd1bf0d4332ec419cf",
      "parents": [
        "c9e4b8ede713c2d8af1dab2fd7b988857eabcd97"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 17:21:14 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:24 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: drop gen1_2 prefix from activate_nic\n\nThe finish_nic_init logic was relocated into the gen1_2 transport and\nlater renamed to iwl_pcie_gen1_2_activate_nic(), the gen1_2 qualifier\nbeing there to distinguish it from a planned gen3 twin. The gen3\ntransport was removed, so the qualifier is no longer meaningful. Rename\nit to iwl_pcie_activate_nic(). No functional change.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: Ie98e2ec5268ae138e8ec8e46a4c0262d549a61c1\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319155\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 7d19af522cda413d5b0891bf97314bc90c64dfa5"
    },
    {
      "commit": "c9e4b8ede713c2d8af1dab2fd7b988857eabcd97",
      "tree": "2d64331dbf5441e57b17ec7b95077be3575fa9ff",
      "parents": [
        "b99b156d6ac80c4534fd922bed725058d522957b"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 17:20:21 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:20 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: drop gen1_2 prefix from is_ltr_enabled\n\nThe gen1_2 PCIe transport helper for reading the LTR state was named\niwl_pcie_gen1_2_is_ltr_enabled() to distinguish it from a planned gen3\ntwin. The gen3 transport was removed, so the qualifier is no longer\nmeaningful. Rename it to iwl_pcie_is_ltr_enabled(). No functional\nchange.\n\ntype\u003dcleanup\nticket\u003dnone\n\nChange-Id: I20e77f228e1536c6eb327dc077b030dbea889ac2\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319154\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 7526ccec5fcdeae50a2a1c42ec90e61c27a40aca"
    },
    {
      "commit": "b99b156d6ac80c4534fd922bed725058d522957b",
      "tree": "0273d671387aafa228730fa5f20baa9ae0c7ff8e",
      "parents": [
        "efae819acc966b95ead23eb352380b28809843c2"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 15:07:16 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Fri Aug 21 13:12:15 2026 +0000"
      },
      "message": "wifi: iwlwifi: pcie: remove the gen3 transport\n\nThe gen3 PCIe transport (for future devices) was only partially\nimplemented, and the project has been cancelled. Remove it entirely:\nthe pcie/gen3/ directory, the gen3 indicator in struct iwl_mac_cfg,\nand all the gen3 dispatch branches in the transport layer.\n\nThe gen3 bit was never set by any device configuration, so all the\nremoved branches were dead code and this does not change any runtime\nbehavior.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: Iab370b9c6b0f46928c0986455e0a77164d919e16\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319153\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: 80bf4903488431a424073f4d59c3652946cdbd1f"
    },
    {
      "commit": "efae819acc966b95ead23eb352380b28809843c2",
      "tree": "9f21d754b2694a1ad4d439bd749364d63d095bcb",
      "parents": [
        "e1158d47405361ac3333382bba8582c663b65f15"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Aug 18 15:16:54 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Tue Aug 18 20:08:29 2026 +0000"
      },
      "message": "[NOUPSTREAM] wifi: iwlwifi: remove iwlprod\n\nThis project was cancelled. Remove the code.\n\ntype\u003dcleanup\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I0b7f2f57d1b75575ee08bbd8a46f05eb840a3503\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/319093\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Daniel Gabay \u003cdaniel.gabay@intel.com\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nx-iwlwifi-stack-dev: cf59126c9ef5b6f441d0e85b08b4ed3be482df9e"
    },
    {
      "commit": "e1158d47405361ac3333382bba8582c663b65f15",
      "tree": "4dd221e7b203c6291b83b165bc091c3cf3e80af9",
      "parents": [
        "a5b302a42029d8da93a4a2f577af0629adacf29f"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 09 13:34:21 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Mon Aug 17 12:32:49 2026 +0000"
      },
      "message": "[BUGFIX] wifi: iwlwifi: mvm: validate mpdu len before relying on it\n\niwl_mvm_rx_mpdu_mq path only checks that the mpdu_len fits into the pkt\nlen, but it doesn\u0027t validate len itself before dereferencing parts of\nthe mpdu: the header, the padding, and the mic_crc_len.\n\nCheck that the mpdu len covers the hdrlen, the padding (if exists) and\nthe mic_crc_len.\n\ntype\u003dbugfix\nticket\u003dnone\nfixes\u003dunknown\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I4bb0dbd739ff1ddf969e51bbd68c42ca9e4e0634\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/307927\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nx-iwlwifi-stack-dev: a0fa569c45159cd002e245ed34a730b283c8d562"
    },
    {
      "commit": "a5b302a42029d8da93a4a2f577af0629adacf29f",
      "tree": "df46d350dbf56c57f9046e4f13f16184f2bd1aeb",
      "parents": [
        "9b8f7f4c1e7e638686de6e189f59b96c2ec3f6df"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 09 12:39:41 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Mon Aug 17 12:32:45 2026 +0000"
      },
      "message": "wifi: iwlwifi: mvm: Revert \"[BUGFIX] wifi: iwlwifi: mvm: guard padded MPDU length\"\n\nThis reverts commit e1f0db56993aff5277adb3733f9df7d93c0eff43.\nThis fix is only avoiding the underflow. But there are more issues here:\n- If we have len \u003c 2, we will crash earlier, when trying to get the hdr\n  (without checking if it fits)\n- If we want to check that the padding exists, we need to check that\n  len \u003e hdr_len + 2, because the padding is after the hdr.\n\nRevert this fix, it will be implemented properly in a separate commit.\n\ntype\u003dfeature\nticket\u003dnone\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: I1fd57d190617ad025c820a608f13dee4c82ad080\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/307926\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nx-iwlwifi-stack-dev: 35b9d4319eedc3c778b5e8f254b46dc482e0b08c"
    },
    {
      "commit": "9b8f7f4c1e7e638686de6e189f59b96c2ec3f6df",
      "tree": "948adf4c3309442820fedc8cbe09ca53e21dbc3b",
      "parents": [
        "8853af62b0b3e2a0fd8263881f17538a55cec7e2"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Tue Jul 07 22:25:42 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Mon Aug 17 08:20:48 2026 +0000"
      },
      "message": "wifi: mac80211: allow advertising 20 MHz-only non-AP STA\n\n802.11 Clause 27 (HE) already defined a 20 MHz-only non-AP\nHE STA in the 5 GHz band, where VHT is required, although\nVHT in Clause 21 requires 20, 40 and 80 MHz support. The\nVHT requirement is implemented in mac80211, but the later\nallowance for 20 MHz-only since HE wasn\u0027t.\n\nAllow a device to be a 20 MHz-only non-AP STA and require\nthat it support VHT, but not that it has 80 MHz support,\nif it\u0027s HE as well.\n\ntype\u003dfeature\nticket\u003dnone\n\nChange-Id: I628aed79ec7f9bf2f8e770b4866ed98cf1ddbe60\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/307235\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nAI-Code-Review: Miriam Rachel Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nx-iwlwifi-stack-dev: 0807cd0dbc4ee3c371f992019a877fc92ec8a949"
    },
    {
      "commit": "8853af62b0b3e2a0fd8263881f17538a55cec7e2",
      "tree": "f8c42da9dbfdeab2ddaf16240841015603de0c05",
      "parents": [
        "240ae744342c56e3be61564e6f139552f6c615e1"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@nbd.name",
        "time": "Tue Aug 04 08:26:08 2026 +0000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:44:09 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: skip default WMM setup for AP_VLAN links\n\nAP_VLAN interfaces are never passed to the driver, so setting default WMM\nparameters on their links trips the check-sdata-in-driver warning in\ndrv_conf_tx(), as well as in the BSS_CHANGED_QOS link info notification.\nSkip it, matching the existing AP_VLAN handling in this function.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 2259d14499d1 (\"wifi: mac80211: set default WMM parameters on all links\")\nSigned-off-by: Felix Fietkau \u003cnbd@nbd.name\u003e\nLink: https://patch.msgid.link/20260804082608.2011433-1-nbd@nbd.name\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I21121da48860072200f24eafe9777e2e7759f2ae\nx-iwlwifi-stack-dev: aebd5142ea77b17ccbfc73e52367e6b208fb36ae"
    },
    {
      "commit": "240ae744342c56e3be61564e6f139552f6c615e1",
      "tree": "5244bd63bb626ab3803d8b6359f8bd0b6c2f2692",
      "parents": [
        "e7db67874da3a397c4bb9d3772383345edd18696"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jul 31 15:11:03 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:44:04 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: stop PMSR before P2P and NAN teardown\n\nPMSR request teardown must abort active measurements while the\nwireless_dev is still present in the driver. cfg80211_leave_locked() and\ncfg80211_stop_pd() already do this before invoking the driver\u0027s stop\ncallback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not.\n\nThose helpers are also called directly by nl80211, rfkill shutdown, and\nwireless_dev unregister paths. If one of these paths stops a P2P device\nor NAN interface with a pending request, it removes the mac80211\nsubinterface from the driver first. Subsequent request cleanup cannot\nreach the lower driver\u0027s abort callback, but cfg80211 frees the request\nregardless. Driver state can then retain a stale request and use it when\nit later reports a result.\n\nCall cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN\ninterface. This keeps lower-driver request state and cfg80211 request\nownership in sync for all of the helpers\u0027 callers.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 9bb7e0f24e7e (\"cfg80211: add peer measurement with FTM initiator API\")\nAssisted-by: Codex:gpt-5.6-sol\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260731071103.73563-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I41ff866f03deec52e14ced5c7002b9cca3129f9d\nx-iwlwifi-stack-dev: fe210d9b861207270ad77f1c8c457eda74c12f04"
    },
    {
      "commit": "e7db67874da3a397c4bb9d3772383345edd18696",
      "tree": "67a9b6338ab55cdec53121787e4c8a64d5fec758",
      "parents": [
        "fb33e27b787f2162d21f1bb04cd3039fa83811a2"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Sun Aug 02 10:40:10 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:44:00 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix RCU usage in peer probing\n\nConverting the station and chanctx lookups to wiphy_dereference()\nwas correct for the function itself but removed the rcu_read_lock()\nfor the later transmit, which requires it, as well. Fix that.\n\nFound with the ap_open_poll_sta hwsim test, which reports\n\n  net/mac80211/tx.c:608 suspicious rcu_dereference_check() usage!\n\n(and four more like it).\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 1c3f880ed00e (\"wifi: mac80211: implement STA-mode peer probing\")\nLink: https://patch.msgid.link/20260802104010.6c09477032c4.If024b480b96bf9fe7baa821ed48b80be322d1e44@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id273a06e282cc65fd011eb22ab80056e162a3169\nx-iwlwifi-stack-dev: b6fa840c3ca8e1ba8bd65d4a6b3bfd150f0474d7"
    },
    {
      "commit": "fb33e27b787f2162d21f1bb04cd3039fa83811a2",
      "tree": "211cde3bb9ed48303d4d1cfd02a088a46080881f",
      "parents": [
        "3e1b071602014ec175c17418e4bfc27580904d0f"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Sun Aug 02 10:40:09 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:55 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix RCU dereference in throughput estimate\n\nThis is invoked with the wiphy mutex held, not in an RCU\ncritical section, fix the dereference accordingly.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 2f925427e27a (\"wifi: mac80211: estimate expected throughput if not provided by driver/rc\")\nLink: https://patch.msgid.link/20260802104010.94bf0862c329.I0a05bf8ab999cb737c487d79082425257e10132a@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ibb838983c307c2ef7bf4f67d860052ee5a85472e\nx-iwlwifi-stack-dev: a280442c8e52d98c16d438fd6f64788ea1552af6"
    },
    {
      "commit": "3e1b071602014ec175c17418e4bfc27580904d0f",
      "tree": "b730cb604de8a796f7d25314f64bb96db7943e27",
      "parents": [
        "cbeb37e254e453c6d974f8ab8d703a34d2caa65a"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Thu Jul 23 09:10:01 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:52 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: skip unused probe response countdown offsets\n\nmac80211 copies cfg80211\u0027s variable-length countdown offset list into a\nzero-initialized fixed-size array, leaving unused entries at zero. The\nbeacon branch already skips those zero entries, but the AP probe-response\nbranch writes through them unconditionally.\n\nWhen a probe-response template has no countdown offset, the write through\nan unused zero entry overwrites resp-\u003edata[0], corrupting the first byte of\nthe template. cfg80211 already bounds explicitly supplied non-zero offsets\nin nl80211_parse_counter_offsets(), so this is a zero-sentinel bug, not an\nout-of-bounds write.\n\nSkip zero probe-response offsets, matching the beacon path.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: af296bdb8da4 (\"mac80211: move csa counters from sdata to beacon/presp\")\nLink: https://lore.kernel.org/all/20260708195911.84365-6-enderaoelyther@gmail.com/\nAssisted-by: Codex:gpt-5\nAssisted-by: Claude:opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260723011001.76851-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Icfc097074da7fc1ab59c32508ac8e9c62a7bfb9c\nx-iwlwifi-stack-dev: dab46fd701cb37d07eb2b989a15cab3b82d1849f"
    },
    {
      "commit": "cbeb37e254e453c6d974f8ab8d703a34d2caa65a",
      "tree": "2bd8955659f43be2169dd17b4eae46381d3b3b8d",
      "parents": [
        "cb3b80da126ea8b366681191dee0935cfb78a8ee"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jul 31 12:02:44 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:47 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: clean up color-change beacon data on errors\n\nnl80211_color_change() calls nl80211_parse_beacon() for the beacon_next\ntemplate, which can allocate params.beacon_next.mbssid_ies and .rnr_ies.\nA parsing failure returned directly instead of using the out: cleanup,\nleaking any allocations completed before the error.\n\nAllocate the nested attribute table before parsing beacon_next. Its\nallocation failure can then return before beacon data exists, while a\nlater parsing failure uses out: to release the parsed data.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: dc1e3cb8da8b (\"nl80211: MBSSID and EMA support in AP mode\")\nAssisted-by: Codex:gpt-5\nAssisted-by: Claude:opus-4.8\nAssisted-by: Kimi:K3\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260731120244.82628-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I92470981ec5037fbb22a0864f2c78e61d2f196bc\nx-iwlwifi-stack-dev: 72c06d2bd1e014ad47fc0d2bc2c78444eaf1f220"
    },
    {
      "commit": "cb3b80da126ea8b366681191dee0935cfb78a8ee",
      "tree": "f5bbf1b68a553558bf840c02cdf931c8487fe93c",
      "parents": [
        "a623cd83fa83e91134071f595782e43951bee53a"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Thu Jul 30 01:36:07 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:43 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: send TWT teardown to peer after setup TX failure\n\nWhen an AP\u0027s TWT Setup response is not acknowledged,\nieee80211_s1g_tx_twt_setup_fail() asks the driver to tear down the local\nagreement and sends a TWT teardown action as the peer notification. It\nuses the response SA as the destination, but\nieee80211_s1g_send_twt_setup() built that response with SA set to the\nAP\u0027s address. The teardown is therefore queued with DA, SA and BSSID all\nset to the AP address and never reaches the station.\n\nThe in-tree driver callbacks update local hardware state and emit no\naction frame. The station receives no notification that mac80211 asked\nthe driver to remove the agreement and can keep following the TWT\nschedule, leaving the peers\u0027 power-save state desynchronized.\n\nAddress the teardown to the response DA, the station to which the failed\nresponse was sent. This also matches the station lookup the transmit\nstatus path already performs on the same frame.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: f5a4c24e689f (\"mac80211: introduce individual TWT support in AP mode\")\nAssisted-by: Codex:gpt-5.6-sol\nAssisted-by: Kimi:K3\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260729173607.13340-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ia6290b0181c5f7370f21550deefedacbd2071734\nx-iwlwifi-stack-dev: d0250bfeba5bcd4534e086aa7a6a1f27340a7034"
    },
    {
      "commit": "a623cd83fa83e91134071f595782e43951bee53a",
      "tree": "6cd53e4c6117bf45d1f2f3ddcf920d1b786e35a7",
      "parents": [
        "39bd2ef3efd04f93c59cae8e075e22061f3239a1"
      ],
      "author": {
        "name": "Arend van Spriel",
        "email": "arend.vanspriel@broadcom.com",
        "time": "Fri Jul 31 14:35:09 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:39 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: send frame tx status event only for non-zero cookie\n\nThe cookie value assigned by cfg80211_assign_cookie() is guaranteed to be\nnon-zero. So the zero cookie value has special use in tx_control_port where\nuserspace can indicate dont_wait_for_ack, ie. not interested in status. The\nwil6210 driver also uses the zero cookie when wil_cfg80211_mgmt_tx() is\ninvoked from debugfs api the driver provides so the event is also redundant\nin that scenario.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Arend van Spriel \u003carend.vanspriel@broadcom.com\u003e\nLink: https://patch.msgid.link/20260731123509.1975281-14-arend.vanspriel@broadcom.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ie0a59d9c3947d83713d31ac196a353ccffb24193\nx-iwlwifi-stack-dev: a89fec75d094b134e9e34d9e9825ddd68c869873"
    },
    {
      "commit": "39bd2ef3efd04f93c59cae8e075e22061f3239a1",
      "tree": "d11dfc1fce4ff4902901a5e9f7d8d7265b456426",
      "parents": [
        "cbb41b72a7b3efa0fa1a7df882cfd6d9a37971df"
      ],
      "author": {
        "name": "Arend van Spriel",
        "email": "arend.vanspriel@broadcom.com",
        "time": "Fri Jul 31 14:35:08 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:35 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: convert tx_control_port cookie to input parameter\n\nThe tx_control_port op was excluded from the previous commit because\na NULL cookie was affecting different behavior, ie. signalling that\nno TX status is wanted.\n\nSince cfg80211_assign_cookie() guarantees a non-zero value, cookie value\n0 can be used instead. So pass 0 when dont_wait_for_ack is set, otherwise\npass value returned from cfg80211_assign_cookie() call.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Claude:claude-sonnet-4-6\nSigned-off-by: Arend van Spriel \u003carend.vanspriel@broadcom.com\u003e\nLink: https://patch.msgid.link/20260731123509.1975281-13-arend.vanspriel@broadcom.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ibe749b03e5b691fa215d394bdd181992dc8e2ba0\nx-iwlwifi-stack-dev: 1d10733139c21e5dc9b8bb474783a63efba50508"
    },
    {
      "commit": "cbb41b72a7b3efa0fa1a7df882cfd6d9a37971df",
      "tree": "283bdf59f70a216237a03302d0a023f23b045b1b",
      "parents": [
        "ee9bd45b3a79d29e9e59290a5fcec009973581a7"
      ],
      "author": {
        "name": "Arend van Spriel",
        "email": "arend.vanspriel@broadcom.com",
        "time": "Fri Jul 31 14:35:07 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:30 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: convert cookie output to input parameter\n\nThe remain_on_channel, mgmt_tx, and probe_peer ops previously used\na u64 *cookie output parameter. Now that cfg80211 pre-assigns the\ncookie value before invoking drivers, the parameter conveys a value\nfrom caller to driver, not the other way around. Convert it to a\nplain u64 input parameter across the ops struct (cfg80211.h),\nrdev-ops.h wrappers, nl80211.c/mlme.c call sites, mac80211, and\nall driver implementations.\n\nThe tx_control_port op is excluded: its cookie pointer is nullable\n(passed as NULL when dont_wait_for_ack is set), so the nullable\npointer semantics are still required.\n\nInternal mac80211 helpers ieee80211_start_roc_work() and\nieee80211_attach_ack_skb() still take u64 *cookie because they\nassign to the pointee; their callers now pass \u0026cookie to take the\naddress of the local value parameter.\n\nwil6210\u0027s internal wil_p2p_listen() is also updated to take u64\ncookie since it is called directly from the remain_on_channel\ncallback.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Claude:claude-sonnet-4-6\nSigned-off-by: Arend van Spriel \u003carend.vanspriel@broadcom.com\u003e\nLink: https://patch.msgid.link/20260731123509.1975281-12-arend.vanspriel@broadcom.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I00f755f0f7dba98d47a03a4be094fff14f47b003\nx-iwlwifi-stack-dev: b668e028752e07a07dc8c6821a21d259ce7beb11"
    },
    {
      "commit": "ee9bd45b3a79d29e9e59290a5fcec009973581a7",
      "tree": "4760c0bc8d98edc6eb9d8d16baf45953f3afb495",
      "parents": [
        "50ac6d6dc50daee09243713f6101bd88bdea4e7c"
      ],
      "author": {
        "name": "Arend van Spriel",
        "email": "arend.vanspriel@broadcom.com",
        "time": "Fri Jul 31 14:34:58 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:26 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: stop using ieee80211_mgmt_tx_cookie()\n\nNow that cfg80211 pre-assigns the cookie before calling into mac80211,\nstop calling ieee80211_mgmt_tx_cookie() in all affected paths:\n\n- ieee80211_start_roc_work(): for normal ROC use the pre-assigned value\n  directly instead of generating a new one.\n- ieee80211_attach_ack_skb(): the cookie is already set by the caller;\n  remove the ieee80211_mgmt_tx_cookie() call and store it in the ack\n  SKB as-is. This covers both mgmt_tx and probe_peer since both call\n  ieee80211_attach_ack_skb().\n- ieee80211_mgmt_tx(): the dummy 0xffffffff assignment for the\n  dont_wait_for_ack case is no longer needed; cfg80211_assign_cookie()\n  guarantees a non-zero value which is sufficient for the internal\n  ROC vs mgmt-tx distinction.\n- ieee80211_store_ack_skb(): same fix for the tx_control_port path.\n\nWith no remaining callers, remove ieee80211_mgmt_tx_cookie() and the\nroc_cookie_counter field from struct ieee80211_local.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Claude:claude-sonnet-4-6\nSigned-off-by: Arend van Spriel \u003carend.vanspriel@broadcom.com\u003e\nLink: https://patch.msgid.link/20260731123509.1975281-3-arend.vanspriel@broadcom.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Idbe71388ed32487e99d6fea2da62cd5661a12d4b\nx-iwlwifi-stack-dev: 850de36d003d73cad4b9a2b83b4954fa3e951fca"
    },
    {
      "commit": "50ac6d6dc50daee09243713f6101bd88bdea4e7c",
      "tree": "00b5145a91f1de9d46978bc34ba6310a89569fc5",
      "parents": [
        "8b6d7cc05ae9ccb783aae3649eee71dbf45a209e"
      ],
      "author": {
        "name": "Arend van Spriel",
        "email": "arend.vanspriel@broadcom.com",
        "time": "Fri Jul 31 14:34:57 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:22 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: pre-assign cookie for driver callbacks\n\nHaving a single place for cookie assignment and keeping that\nresponsibility in the cfg80211 subsystem is a logical choice as it\nhandles the userspace nl80211 API. add_nan_func already does this:\ncfg80211 calls cfg80211_assign_cookie() before invoking the driver.\nApply the same pattern to remain_on_channel, mgmt_tx, probe_peer and\ntx_control_port by pre-assigning the cookie in the nl80211 command\nhandlers before the rdev_* call. For tx_control_port the cookie is\nonly pre-assigned when the caller requests an ack (cookie pointer\nnon-NULL).\n\nDrivers may still overwrite the value for now; subsequent patches will\nremove per-driver cookie generation.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Claude:claude-sonnet-4-6\nSigned-off-by: Arend van Spriel \u003carend.vanspriel@broadcom.com\u003e\nLink: https://patch.msgid.link/20260731123509.1975281-2-arend.vanspriel@broadcom.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I61373524c0022b02e46f1324801778a091e3bfbe\nx-iwlwifi-stack-dev: 6992a2341d50e3328078901b66ab80fc09323757"
    },
    {
      "commit": "8b6d7cc05ae9ccb783aae3649eee71dbf45a209e",
      "tree": "4f27fc4ce81350a01ea6e8dfa0d49c825f433f98",
      "parents": [
        "78d4706568e128c2fdf20fb9e82cd0a7c2aba30a"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Sun Aug 02 17:33:39 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:18 2026 +0000"
      },
      "message": "[FROMGIT] Revert \"wifi: mac80211: don\u0027t encrypt pre-auth (ETH_P_PREAUTH) frames\"\n\nThis reverts commit dd406779999fa2065ec6b7c4f80906b727041d2c.\n\nNever encrypting the frames broke a number of tests that do\nadditional pre-authentication while already connected, and\nthen the frames didn\u0027t go out correctly. Whatever this was\nintended to fix, this wasn\u0027t the right fix.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: dd406779999f (\"wifi: mac80211: don\u0027t encrypt pre-auth (ETH_P_PREAUTH) frames\")\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I04ae697a946a1ac1a48326c4b26d8a00b396f4af\nx-iwlwifi-stack-dev: 5673ce2d5f22ec11c3c654f16ccdb13aa75bccee"
    },
    {
      "commit": "78d4706568e128c2fdf20fb9e82cd0a7c2aba30a",
      "tree": "6ee501c3b156f4b8a3baa77b2a010eff953c97ee",
      "parents": [
        "9fa5a13f1f48c0a20eef79766bcf49a5c78769b1"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Tue Jul 28 19:13:26 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:14 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix per-STA profile length in cross-link CSA parsing\n\nieee80211_mgd_check_cross_link_csa() starts parsing elements after the\nfixed per-STA profile header and the STA Info field, but subtracts only\nthe STA Info length from the profile length. As a result,\nieee802_11_parse_elems() is given sizeof(*prof) \u003d\u003d 3 bytes beyond the\ncurrent profile\u0027s element area, and data following the profile may be\ninterpreted as belonging to it.\n\nSubtract the fixed profile header as well. The preceding\nieee80211_mle_basic_sta_prof_size_ok() check guarantees that the\ncorrected calculation cannot underflow, and\nieee80211_rx_uhr_link_reconfig_req() uses the same calculation.\n\nThe call site currently states that cross-link CSA parsing has no effect\nbecause the broader parsing is still incorrect. This patch does not\naddress that broader problem; it only makes the per-STA profile parser\nstop at the end of that profile. No production allocation over-read or\nuser-visible failure has been demonstrated.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 7ef8f6821d16 (\"wifi: mac80211: mlme: handle cross-link CSA\")\nAssisted-by: Codex:gpt-5.6-sol\nAssisted-by: Kimi:K3\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260728111326.63087-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I18cddb70f6381b679e47c2e17f31a9a30cc79ce8\nx-iwlwifi-stack-dev: e86fec3a1864d8412a7772127b3640519ca29f30"
    },
    {
      "commit": "9fa5a13f1f48c0a20eef79766bcf49a5c78769b1",
      "tree": "2a0a3d9ecc2d131dbc875503daadd11d5120cabc",
      "parents": [
        "83f5518f7808c56b55208f21643f1c8717eb1685"
      ],
      "author": {
        "name": "Dmitry Antipov",
        "email": "dmantipov@yandex.ru",
        "time": "Mon Jul 27 12:57:14 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:10 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: simplify airtime_flags_write()\n\nUse \u0027kstrtou16_from_user()\u0027 to simplify \u0027airtime_flags_write()\u0027.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Dmitry Antipov \u003cdmantipov@yandex.ru\u003e\nLink: https://patch.msgid.link/20260727095714.347039-1-dmantipov@yandex.ru\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ief8608ec27c8e8d2b637058ef1af273b88fbb559\nx-iwlwifi-stack-dev: 3fb0bcaf12522960551b82afc288f03b61d18ed4"
    },
    {
      "commit": "83f5518f7808c56b55208f21643f1c8717eb1685",
      "tree": "65d7fbe77f510eec0f3144eff64273f35c4d5a34",
      "parents": [
        "4e22903db8ae758b90322b099c939f7e847490bf"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@nbd.name",
        "time": "Fri Jul 24 11:54:29 2026 +0000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:04 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: add ieee80211_txq_aql_pending()\n\nAdd a function to allow drivers to query the pending AQL airtime\nfor a given txq, for both unicast and broadcast.\nThis will be used for mt76 to limit buffering in AP mode for power-save\nstations.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Felix Fietkau \u003cnbd@nbd.name\u003e\nLink: https://patch.msgid.link/20260724115429.3921457-4-nbd@nbd.name\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I9a027af7f2f403fbec404dc71143b1cea4cb4e3b\nx-iwlwifi-stack-dev: 9787c4783d621001e5a498f6ccb7babe563e9a89"
    },
    {
      "commit": "4e22903db8ae758b90322b099c939f7e847490bf",
      "tree": "cec998edb1a97d6cb78462423c7aed6bf58b3722",
      "parents": [
        "1a73dce82ce9f518048b1e336e604771b4398a45"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@nbd.name",
        "time": "Fri Jul 24 11:54:28 2026 +0000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:43:00 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: add AQL support for multicast packets\n\nExcessive multicast traffic with little competing unicast traffic can easily\nflood hardware queues, leading to throughput issues. Additionally, filling\nthe hardware queues with too many packets breaks FQ for multicast data.\nFix this by enabling AQL for multicast packets.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Felix Fietkau \u003cnbd@nbd.name\u003e\nLink: https://patch.msgid.link/20260724115429.3921457-3-nbd@nbd.name\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I6223071d77e02edf1f546857cee8d5f7c9a76219\nx-iwlwifi-stack-dev: 83cd37790767a9ce4d4f2b21c6f1e0a1d8772351"
    },
    {
      "commit": "1a73dce82ce9f518048b1e336e604771b4398a45",
      "tree": "8ec60a7e7e664fef2082d50fe3213b9a011a80c3",
      "parents": [
        "19150aea10ab7b95ee8418883c96b47fc54a7a09"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@nbd.name",
        "time": "Fri Jul 24 11:54:27 2026 +0000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:55 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: estimate expected throughput if not provided by driver/rc\n\nEstimate the tx throughput based on the expected per-packet tx time.\nThis is useful for mesh implementations that rely on expected throughput,\ne.g. 802.11s or batman-adv.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Felix Fietkau \u003cnbd@nbd.name\u003e\nLink: https://patch.msgid.link/20260724115429.3921457-2-nbd@nbd.name\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id86e833eda1368a99277229835b9f2cc3df8444a\nx-iwlwifi-stack-dev: 50ab350dd31c697b2bfe2a78ed7e7de154530335"
    },
    {
      "commit": "19150aea10ab7b95ee8418883c96b47fc54a7a09",
      "tree": "01970d29f3f7ed574b06524c6ce60c56e2242e30",
      "parents": [
        "3ab42a394d4cc20f49225aaab9b12869e8280e86"
      ],
      "author": {
        "name": "Felix Fietkau",
        "email": "nbd@nbd.name",
        "time": "Fri Jul 24 11:54:26 2026 +0000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:50 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: factor out part of ieee80211_calc_expected_tx_airtime\n\nCreate ieee80211_rate_expected_tx_airtime helper function, which returns\nthe expected tx airtime for a given rate and packet length in units of\n1/1024 usec, for more accuracy.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Felix Fietkau \u003cnbd@nbd.name\u003e\nLink: https://patch.msgid.link/20260724115429.3921457-1-nbd@nbd.name\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ieb3a96a8999b881af4131211ce854e244853e338\nx-iwlwifi-stack-dev: 2eada94b8fc89d2ef01d6d7378a4e2fe04be7143"
    },
    {
      "commit": "3ab42a394d4cc20f49225aaab9b12869e8280e86",
      "tree": "084f93b0887d992d089485f145e4d125caa2097a",
      "parents": [
        "12e0b060e4c8959208219f3e1610a982dca57935"
      ],
      "author": {
        "name": "Srinivas Achary",
        "email": "srinivas@aerlync.com",
        "time": "Thu Jul 23 19:15:50 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:45 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: change mesh_setup::ie_len to size_t\n\nThe ie_len field in struct mesh_setup stores the length of the\ninformation elements (IEs) buffer. It is currently defined as u8,\nwhich limits the maximum supported length to 255 bytes.\n\nThe IE length is derived from memory buffers whose size is naturally\nrepresented by size_t. Using u8 may truncate larger values and can\nresult in incorrect length handling.\n\nChange ie_len to size_t so it can represent the full buffer length and\nmatch the type commonly used for memory sizes throughout the kernel.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Ramakrishnan Rathinasamy \u003cramakrishnan@aerlync.com\u003e\nSigned-off-by: Srinivas Achary \u003csrinivas@aerlync.com\u003e\nLink: https://patch.msgid.link/20260723134550.35167-1-srinivas@aerlync.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ibc7f0a5aaac2498c6ad352f4ab44867c8a0faa7b\nx-iwlwifi-stack-dev: 44783c0f46dd41f25e5790a037a1f428423fbea7"
    },
    {
      "commit": "12e0b060e4c8959208219f3e1610a982dca57935",
      "tree": "9ab8dce2d9575d70254ec76bfdc5f9075a7f5cd1",
      "parents": [
        "7a1d5e02b367bc20a85c4a8b1685dec0b453fca2"
      ],
      "author": {
        "name": "Jiajia Liu",
        "email": "liujiajia@kylinos.cn",
        "time": "Wed Jul 22 15:18:19 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:40 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: reg: add a newline in DFS debug message\n\nAdd a missing newline in the debug message in print_regdomain.\n\nSigned-off-by: Jiajia Liu \u003cliujiajia@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260722071819.22465-1-liujiajia@kylinos.cn\n[break long line]\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id40f62c6f927becbea8777419f4794005ed5701c\nx-iwlwifi-stack-dev: e50e88ae84c82e0a98f49b4430f5546d3458a18f"
    },
    {
      "commit": "7a1d5e02b367bc20a85c4a8b1685dec0b453fca2",
      "tree": "34dc3b88b4a91be3bb3acf95aabee2441996f53d",
      "parents": [
        "b16923f06285093ba0445c2b65c66d1bc8e946a3"
      ],
      "author": {
        "name": "Louis Kotze",
        "email": "loukot@gmail.com",
        "time": "Wed Jul 22 09:07:34 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:36 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: tests: check BSS lookup failure reasons\n\nAdd a KUnit test for the extack failure reasons that\n__cfg80211_get_bss() now reports: no matching scan entry at all, a\nmatching entry that is expired, and a matching entry whose use_for\nflags do not allow the requested use. Also cover the cases that must\nnot report a failure (a fresh entry, and an expired-but-held entry),\nan entry that is both expired and unusable, and the combined message\nwhen one matching entry is expired while another is current but\nunusable.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Louis Kotze \u003cloukot@gmail.com\u003e\nLink: https://patch.msgid.link/20260722070734.3612581-3-loukot@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Iba9122e1c45638314738ed8fc0e2c851d01ceff1\nx-iwlwifi-stack-dev: 5564f9bbb26e2a0d4f3a0eba24250d9af1c47abf"
    },
    {
      "commit": "b16923f06285093ba0445c2b65c66d1bc8e946a3",
      "tree": "7c99ba0a687908f26eb288df0119b9512b97ca4f",
      "parents": [
        "9c5983ad8ee65d114bfaf80943fac039a9c2ca84"
      ],
      "author": {
        "name": "Louis Kotze",
        "email": "loukot@gmail.com",
        "time": "Wed Jul 22 09:07:33 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:32 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: say why the auth/assoc BSS lookup failed\n\nThe BSS lookup for an authentication or association request can fail\nfor three distinct reasons: cfg80211 has no scan entry at all for the\nBSSID/channel, an entry exists but is older than\nIEEE80211_SCAN_RESULT_EXPIRE (and not held), or a fresh entry exists\nbut its use_for flags do not allow this use. All three currently\nsurface as the same generic extack message \"Error fetching BSS for\nlink\" on the MLO association path, and as a bare -ENOENT with no\nmessage at all on the authentication and non-MLO association paths.\n\nSince wpa_supplicant logs the extack message verbatim (\"nl80211:\nkernel reports: ...\"), that message is often the only diagnostic a\nuser sees when an MLO association degrades to fewer links, and it\ndoes not say whether a fresh scan could have helped. In practice the\nexpired case is common for MLO partner links: 6 GHz is passive-scan\nin many regulatory domains, so the partner-link entry is routinely\nstale by the time userspace requests the association even though the\nlink is perfectly usable.\n\nLet __cfg80211_get_bss() take an optional extack and record, during\nthe same bss_lock walk that fails the lookup, whether any matching\nentry was rejected for being expired or for not being usable for the\nrequested use, and set a distinct message for each case (and a\ncombined one when different entries were rejected for different\nreasons). Reorder the checks in the walk so that an entry\u0027s identity\n(type, privacy, channel, BSSID/SSID) is established before the\nusability checks; this doesn\u0027t change which entry is returned since\nan entry is only used when all checks pass.\n\nAlso give the -EINVAL paths in nl80211_assoc_bss() proper messages\nwhile at it, and keep pointing the bad_attr at the failing link on\nthe MLO path there; the message for that case is already set by the\nlookup itself.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Louis Kotze \u003cloukot@gmail.com\u003e\nLink: https://patch.msgid.link/20260722070734.3612581-2-loukot@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id0c06d2118ffb8063668a0f59b920edfe8a88e7f\nx-iwlwifi-stack-dev: 04f5938fcf4464d5599249b2fa7cbfaaff04fb04"
    },
    {
      "commit": "9c5983ad8ee65d114bfaf80943fac039a9c2ca84",
      "tree": "9366021ff5cffbdc2edc2f32a23da175953e3caf",
      "parents": [
        "81ced32280898a1e770eac87d920dc34083cad50"
      ],
      "author": {
        "name": "Priyansha Tiwari",
        "email": "priyansha.tiwari@oss.qualcomm.com",
        "time": "Thu Jul 09 17:12:27 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:28 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: implement STA-mode peer probing\n\nAdd STA/P2P-client support to ieee80211_probe_peer(): when called\nfor a station interface, send a null-data frame (TODS) to the\nassociated AP and report the ACK via cfg80211_probe_status().\n\nFor MLO connections the driver/firmware selects the link\n(IEEE80211_LINK_UNSPECIFIED); for non-MLO the single link is used.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Priyansha Tiwari \u003cpriyansha.tiwari@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260709114228.672317-2-pritiwa@qti.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I641ae5f0a49ea159c6419d3a9cc9284d563e34e7\nx-iwlwifi-stack-dev: 54d2ed61d96fa791ef0737196cfd6aa09843843c"
    },
    {
      "commit": "81ced32280898a1e770eac87d920dc34083cad50",
      "tree": "1d853d3d4352ba3640287ca3a8db368ad9fd41a8",
      "parents": [
        "203e7e6a5102fb9ad5144b377f768b1fbb0cd4eb"
      ],
      "author": {
        "name": "Lachlan Hodges",
        "email": "lachlan.hodges@morsemicro.com",
        "time": "Tue Jul 21 15:39:58 2026 +1000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:24 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: include cf1 offset when sending chandef\n\nThe cf1 offset is not included when sending the chandef leading\nto incorrect channel resolution in usermode. Include it.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260721053958.227853-1-lachlan.hodges@morsemicro.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I4def11c14de71aadfaa743928677eca0b206fd5d\nx-iwlwifi-stack-dev: 5cd03bbf37f28e28c5efedde772092591baa5d53"
    },
    {
      "commit": "203e7e6a5102fb9ad5144b377f768b1fbb0cd4eb",
      "tree": "ed853fd469286fdf3b925fd048385a78bb9ae6ef",
      "parents": [
        "f35fcbbff40c11ce382d161c1aae365b287ae7bc"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "yuyanghuang@google.com",
        "time": "Sat Jul 11 09:54:03 2026 +0900"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:20 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: use ifa_dev from event argument\n\nDuring address teardown, the netdevice\u0027s ip_ptr might be cleared before\nthe inetaddr notifier is called. In this case, __in_dev_get_rtnl()\nreturns NULL, causing the notifier to abort early and fail to update\nthe ARP filter.\n\nFix this by using the in_device pointer from the event argument\n(ifa-\u003eifa_dev) which is guaranteed to be valid.\n\ntype\u003dmaint\nticket\u003dnone\n\nCc: Ido Schimmel \u003cidosch@nvidia.com\u003e\nCc: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nSigned-off-by: Yuyang Huang \u003cyuyanghuang@google.com\u003e\nLink: https://patch.msgid.link/20260711005405.2861680-3-yuyanghuang@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nChange-Id: Iaad1095b9c1033b331568c78fdb064d87850ebd5\nx-iwlwifi-stack-dev: feac2c99b833fd01e95a683b4b22b4a55c16ebbf"
    },
    {
      "commit": "f35fcbbff40c11ce382d161c1aae365b287ae7bc",
      "tree": "44f32c966dcbd2bfd56bf5737ce5c63224ba2047",
      "parents": [
        "be20e3ad87be30cc94e5f793ada301ff83aace19"
      ],
      "author": {
        "name": "Deepanshu Kartikey",
        "email": "kartikey406@gmail.com",
        "time": "Mon Jul 13 07:29:46 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:16 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: don\u0027t encrypt pre-auth (ETH_P_PREAUTH) frames\n\nPre-authentication frames (ETH_P_PREAUTH, 0x88C7) are sent before\nthe authentication handshake completes with the target AP, so no\nencryption key exists for them yet. Unlike normal EAPOL frames\n(ETH_P_8021X, 0x888E) which are registered as the control port\nprotocol, pre-auth frames are not recognized as control port frames,\ncausing the kernel to incorrectly assign the current AP\u0027s key and\nattempt encryption, resulting in a WARN_ON in ieee80211_encrypt_tx_skb\nwhen the cipher is not handled.\n\nFix this by setting IEEE80211_TX_INTFL_DONT_ENCRYPT for pre-auth\nframes in ieee80211_tx_h_check_control_port_protocol(), so that\nkey selection skips them and they are sent unencrypted as intended.\n\nNote that the only driver hitting this path is hwsim.\n\nReported-by: syzbot+b6ce23950fd636e6efb6@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003db6ce23950fd636e6efb6\nSigned-off-by: Deepanshu Kartikey \u003ckartikey406@gmail.com\u003e\nLink: https://patch.msgid.link/20260713015946.44636-1-kartikey406@gmail.com\n[add note about hwsim, fix subject]\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I14ff40b2013f6311fe791180b46f2713ebbe9a35\nx-iwlwifi-stack-dev: 07b83dd9ec3a508abbff60975e6ba3c93e7bc82a"
    },
    {
      "commit": "be20e3ad87be30cc94e5f793ada301ff83aace19",
      "tree": "4bbf5ffc15105e0d4b62645a41b69cb50fbb632c",
      "parents": [
        "77d9ec6ad2ec1ddc5568f248eb6611f16a471448"
      ],
      "author": {
        "name": "Andrew Pope",
        "email": "andrew.pope@morsemicro.com",
        "time": "Fri Jul 17 11:17:51 2026 +1000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:12 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: recalculate TIM when a station enters power save\n\nWhen an AP buffers frames for a station on its per-station TXQs and the\nstation subsequently enters power save, sta_ps_start() records the\nbuffered TIDs in txq_buffered_tids but does not update the TIM. The\nstation\u0027s TIM bit is only ever set when a further frame is buffered\nwhile the station is already asleep\n(ieee80211_tx_h_unicast_ps_buf() -\u003e sta_info_recalc_tim()).\n\nIf no further downlink frame arrives for that station the beacon\nTIM never advertises the buffered traffic. A station relying on the\nTIM then remains in doze indefinitely on top of a non-empty queue. Its\nTXQs were removed from the scheduler\u0027s active list at PS entry, nothing\npages it, and the flow deadlocks until an unrelated event wakes the\nstation.\n\nRecalculate the TIM at the end of sta_ps_start(), so traffic\nalready buffered at PS entry is advertised immediately.\nsta_info_recalc_tim() already consults txq_buffered_tids, which is\nupdated above, and is safe in this context (it is already called\nfrom equivalent paths such as the tx handlers and\nieee80211_handle_filtered_frame()).\n\nFixes: ba8c3d6f16a1 (\"mac80211: add an intermediate software queue implementation\")\nSigned-off-by: Andrew Pope \u003candrew.pope@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260717011751.79524-1-andrew.pope@morsemicro.com\n[add wifi: subject prefix]\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I951430972c96b311a224650bb6cd24eed26e95de\nx-iwlwifi-stack-dev: e21fc55404e951d2d392d6d31b9f61c26a697c55"
    },
    {
      "commit": "77d9ec6ad2ec1ddc5568f248eb6611f16a471448",
      "tree": "75fb56199c57ddb8a29d169c3f6b54bf0e4b8179",
      "parents": [
        "087f0f7a71f2639f2045c2fefcd168eb216a4682"
      ],
      "author": {
        "name": "Xiang Mei",
        "email": "xmei5@asu.edu",
        "time": "Sat Jul 11 14:03:02 2026 -0700"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:08 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file-\u003eprivate_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to \u0027free\u0027, which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file-\u003eprivate_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link\u0027s keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links \u003d\u003d 0) but left the newly-added links\u0027 teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links\u0027 debugfs entries and stop them before freeing.\n\n  BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Read of size 8 at addr ffff888011290000 by task exploit/145\n  Call Trace:\n   ...\n   ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n   short_proxy_read (fs/debugfs/file.c:373)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  ...\n  Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n  RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Kernel panic - not syncing: Fatal exception\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 170cd6a66d9a (\"wifi: mac80211: add netdev per-link debugfs data and driver hook\")\nReported-by: Weiming Shi \u003cbestswngs@gmail.com\u003e\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Xiang Mei \u003cxmei5@asu.edu\u003e\nLink: https://patch.msgid.link/20260711210302.2098404-1-xmei5@asu.edu\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id01429572995691ab208dd9a9311b6a6eb47a6f9\nx-iwlwifi-stack-dev: 452357c36e18b27b87c4dcbc55b4f1943bf04aef"
    },
    {
      "commit": "087f0f7a71f2639f2045c2fefcd168eb216a4682",
      "tree": "580d8d2f6932f5294ebc32f6ebeef0d1f59b1ec7",
      "parents": [
        "8e1340ddc3d90d183b0c3dc5e2b9848973bc6e60"
      ],
      "author": {
        "name": "HE WEI (ギカク)",
        "email": "skyexpoc@gmail.com",
        "time": "Tue Jul 07 18:48:28 2026 +0900"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:42:03 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: bound element ID read when checking non-inheritance\n\ncfg80211_is_element_inherited() reads the first data octet of the\ncandidate element (id \u003d elem-\u003edata[0]) to look it up in an extension\nnon-inheritance list. It does so after testing elem-\u003eid, but without\nverifying that the element actually has a data octet. A zero-length\nextension element (WLAN_EID_EXTENSION with length 0) therefore makes it\nread one octet past the end of the element.\n\n_ieee802_11_parse_elems_full() runs this check for every element of a\nframe once a non-inheritance context exists -- e.g. while parsing a\nper-STA profile of a Multi-Link element in a (re)association response,\nor a non-transmitted BSS profile -- so a crafted frame from an AP can\ntrigger a one-octet slab-out-of-bounds read during element parsing:\n\n  BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited\n  Read of size 1 ... in net/wireless/scan.c\n\nReturn early (treat the element as inherited) when an extension element\ncarries no data, mirroring the existing handling of empty ID lists.\n\nThe bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: f7dacfb11475 (\"cfg80211: support non-inheritance element\")\nSigned-off-by: HE WEI (ギカク) \u003cskyexpoc@gmail.com\u003e\nLink: https://patch.msgid.link/20260707094828.16465-1-skyexpoc@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id30a91a64e74710f5a757810946db8d4377c66f3\nx-iwlwifi-stack-dev: 508b0f4bcf94b9fbf1dc76e6c15f9aa9df803242"
    },
    {
      "commit": "8e1340ddc3d90d183b0c3dc5e2b9848973bc6e60",
      "tree": "03264ef2989b186ae107dbc49539037218d201fb",
      "parents": [
        "8634e124015c0de64da54649af102611a609a1fe"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Tue Jul 07 10:53:35 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:59 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: validate assoc response length before status and IE access\n\ncfg80211_rx_assoc_resp() initialises the status and response-IE fields\nof cfg80211_connect_resp_params from the management frame before\nproving that the frame is long enough for those offsets. S1G and\nregular association responses also have different IE offsets, but the\nS1G path only patched resp_ie after the unsafe initialiser had already\nrun.\n\nDefer resp_ie, resp_ie_len, and status to after the link-iteration\nloop. Use a bool to remember whether the frame is S1G, then validate\nthe appropriate minimum length and set all three fields in a single\nif/else block. Funnel short-frame and SME-reject cleanup through a\nshared free_bss label for the abandon paths.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260707025336.22557-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I95ed8aaeaa905957cc151644c815c718529619ad\nx-iwlwifi-stack-dev: d55c25403b0fd9fafdf3813dc5b4a4ee216d64fd"
    },
    {
      "commit": "8634e124015c0de64da54649af102611a609a1fe",
      "tree": "3c74aaece26ea399a2791f6c8007b94764e7711f",
      "parents": [
        "47a45a4c25048012d1505c6b0d2f30831edc1f09"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Tue Jul 07 10:53:34 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:55 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: validate rx/tx MLME callback frame lengths before access\n\ncfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() call tracepoints\nbefore rejecting frames shorter than the frame-control field. After\nthat, they only require len \u003e\u003d 2 before dispatching into subtype\nhandlers that assume their fixed fields are present.\n\nThe frames that trip this are not shorter than 2 bytes; they are short\nrelative to their subtype. mwifiex is a concrete in-tree example on the\nlength side: mwifiex_process_mgmt_packet() only requires a 4-address\nieee80211_hdr plus the 2-byte firmware length prefix before handing the\nframe to cfg80211_rx_mlme_mgmt(). After stripping the length prefix and\nremoving addr4, pkt_len can be exactly 24: a bare 3-address management\nheader with no reason-code body. The existing WARN_ON(len \u003c 2) does not\nfire on such a frame, and cfg80211_process_deauth() then reads\nu.deauth.reason_code as a two-byte access starting at offset 24,\nimmediately past the 24-byte buffer.\n\nAdd a frame-control length gate, then validate each subtype\u0027s minimum\nframe size in an if/else-if chain that mirrors the dispatch logic. Trace\nonly after the frame is known to be well-formed.\n\nSide effects of this change:\n - The WARN_ON(len \u003c 2) is dropped. It only guarded the frame_control\n   read, never the subtype fixed fields, and it does not fire on the\n   frames that actually trigger the out-of-bounds read (which are \u003e\u003d 2).\n   The len \u003e\u003d 2 check is kept as the guard before dereferencing\n   frame_control, but without the warning: these are exported callbacks\n   and a malformed frame from a driver should be dropped silently rather\n   than backtraced.\n - cfg80211_tx_mlme_mgmt() previously routed every non-deauth subtype\n   through disassociation handling; it now silently ignores unrecognised\n   subtypes.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260707025336.22557-1-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ic5eb37ea8f75c2b4adb79da10537e38789014e69\nx-iwlwifi-stack-dev: 9e59a38871c893db6aa253b1b5dceffdf1eab12b"
    },
    {
      "commit": "47a45a4c25048012d1505c6b0d2f30831edc1f09",
      "tree": "e6932cbeb7a20120d05411572cd5972a00d3dbf5",
      "parents": [
        "1578f45165f30336e551d9389032e9ab07a72289"
      ],
      "author": {
        "name": "Cen Zhang",
        "email": "zzzccc427@gmail.com",
        "time": "Mon Jul 06 23:24:18 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:51 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: use wiphy work for socket owner autodisconnect\n\nnl80211_netlink_notify() walks the cfg80211 wireless device list when a\nNETLINK_GENERIC socket is released. If the socket owns a connection, the\nnotifier queues the embedded wdev-\u003edisconnect_wk work item.\n\nThat work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a\nNETLINK_URELEASE notifier that already observed conn_owner_nlportid can\nqueue it after that cancel returns. _cfg80211_unregister_wdev() then\nremoves the wdev from the list and waits for RCU readers, but\nsynchronize_net() does not drain work queued by such a reader.\n\nMake the autodisconnect work a wiphy_work instead. The callback already\nneeds the wiphy mutex, and wiphy_work runs under that mutex. This lets\nteardown cancel pending autodisconnect work while holding the mutex,\nwithout a cancel_work_sync() vs. worker locking concern.\n\nAlso cancel the wiphy work after list_del_rcu() and synchronize_net(). Any\nNETLINK_URELEASE notifier that had already reached the wdev list has then\neither queued the work and it is removed, or can no longer find the wdev.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: bd2522b16884 (\"cfg80211: NL80211_ATTR_SOCKET_OWNER support for CMD_CONNECT\")\nSuggested-by: Johannes Berg \u003cjohannes@sipsolutions.net\u003e\nAssisted-by: Codex:gpt-5.5\nSigned-off-by: Cen Zhang \u003czzzccc427@gmail.com\u003e\nLink: https://patch.msgid.link/20260706152418.779226-1-zzzccc427@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id15c62e474017ec14f3008236930798d67d6814a\nx-iwlwifi-stack-dev: 2ba426c021e66b196f86d5d271ad69ae8e298078"
    },
    {
      "commit": "1578f45165f30336e551d9389032e9ab07a72289",
      "tree": "6ef2c24db751e51ca9038c8199ea3c9b8424380c",
      "parents": [
        "bf4e88afd5c7fef1ece43ff0321e1616063d742e"
      ],
      "author": {
        "name": "Dawei Feng",
        "email": "dawei.feng@seu.edu.cn",
        "time": "Mon Jul 06 22:35:07 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:47 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix memory leak in ieee80211_register_hw()\n\nIf kmemdup() fails while copying supported band structures, the error\npath jumps to fail_rate. This skips rate_control_deinitialize() and\nleaks the initialized local-\u003erate_ctrl.\n\nFix this by adding a fail_band label that shares the rate-control cleanup\npath before falling through to the remaining teardown.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc7.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nsuitable mac80211 device/driver combination to test with, no runtime\ntesting was able to be performed.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 09b4a4faf9d0 (\"mac80211: introduce capability flags for VHT EXT NSS support\")\nCc: stable@vger.kernel.org\nReviewed-by: Zilin Guan \u003czilin@seu.edu.cn\u003e\nSigned-off-by: Dawei Feng \u003cdawei.feng@seu.edu.cn\u003e\nLink: https://patch.msgid.link/20260706143507.146131-1-dawei.feng@seu.edu.cn\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: If7a214913ae315c50e78e874ea2f5c130eedf878\nx-iwlwifi-stack-dev: 043dae43c784ca4c518580fb7a101af5de952803"
    },
    {
      "commit": "bf4e88afd5c7fef1ece43ff0321e1616063d742e",
      "tree": "8afe8d880108598fddfcbf32248c6a9f4516abaf",
      "parents": [
        "b4f015a07b6112d06cc18b6283a272f69c535c04"
      ],
      "author": {
        "name": "Cen Zhang",
        "email": "zzzccc427@gmail.com",
        "time": "Mon Jul 06 22:08:41 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:42 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps-\u003ebc_buf while holding ps-\u003ebc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX:             AP_VLAN stop:\n1. attach ACK-status state         1. clear the running state\n2. queue a multicast SKB on        2. take ps-\u003ebc_buf.lock with IRQs\n   parent ps-\u003ebc_buf                  disabled\n                                   3. unlink the AP_VLAN SKB\n                                   4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps-\u003ebc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\ntype\u003dmaint\nticket\u003dnone\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip\nFixes: 397a7a24ef8c (\"mac80211: free ps-\u003ebc_buf skbs on vlan device stop\")\nAssisted-by: Codex:gpt-5.5\nSigned-off-by: Cen Zhang \u003czzzccc427@gmail.com\u003e\nLink: https://patch.msgid.link/20260706140841.581566-1-zzzccc427@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I22c83946da6ea831cc90a0e08fa3c93630bdc9c7\nx-iwlwifi-stack-dev: d2208a543af7259bc9bd5a2e248a58c3ec50bce0"
    },
    {
      "commit": "b4f015a07b6112d06cc18b6283a272f69c535c04",
      "tree": "f693da2b3e8361e73492ecaf3a8f250c8b0a5cd9",
      "parents": [
        "2b1ec88a8db899486de68d2dee43955a6d1cf99f"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:35 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:38 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: support MAC address filtering in station dump for link stats\n\nCurrently, when userspace requests station information with\nlink statistics using NL80211_CMD_GET_STATION with the\nNL80211_ATTR_STA_DUMP_LINK_STATS flag, the kernel uses the .doit callback\n(nl80211_get_station) which sends a single netlink message. For MLO\nstations with multiple links, the link statistics can be large and may\nexceed the maximum netlink message size, causing the operation to fail\nwith -EMSGSIZE.\n\nThe .dumpit callback (nl80211_dump_station) already supports\nfragmentation across multiple netlink messages, making it suitable\nfor handling large link statistics. However, it currently iterates over\nall stations on the interface, which is inefficient when userspace only\nwants information about a specific station.\n\nAdd support for MAC address filtering in nl80211_dump_station to allow\nuserspace to request fragmented link statistics for a specific station.\nWhen NL80211_ATTR_MAC is present in a dump request, cache the MAC address\nin the dump context and use rdev_get_station() to retrieve information for\nonly that station, instead of iterating over all stations with\nrdev_dump_station().\n\nThis allows userspace tools (like iw) to use NL80211_CMD_GET_STATION with\nNLM_F_DUMP flag to retrieve complete link statistics for a specific\nstation across multiple netlink messages, avoiding the message size\nlimitation.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-6-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ib57d95b182ae53680756821710321420e3efbe9c\nx-iwlwifi-stack-dev: 843a9895f2dd82b0ce87e354bc6d93e945955a1c"
    },
    {
      "commit": "2b1ec88a8db899486de68d2dee43955a6d1cf99f",
      "tree": "7c6ffb06b343add4c614ba1b129c817c7d16ee16",
      "parents": [
        "229be2f88d894cf3dbaba507021f08f98f648016"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:34 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:33 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Fragment per-link station stats in nl80211_dump_station()\n\nIn MLO scenarios, stations may have multiple links, each with distinct\nstatistics. When userspace tools like iw or hostapd request station dumps,\nattempting to pack all per-link stats into a single netlink message can\neasily exceed the default 4KB buffer limit, especially when more than two\nlinks are active. This results in -EMSGSIZE errors and incomplete data\ndelivery.\n\nTo address this, fragment per-link station statistics across multiple\nnetlink messages to ensure reliable delivery of complete MLO station\ninformation. Extend the stateful context with a two-phase dump mechanism:\nphase 0 (AGGREGATED) sends combined MLO-level statistics and phase 1\n(PER_LINK) sends individual per-link statistics for each active link.\n\nThe dump loop is structured to produce exactly one netlink message per\niteration, with a common header (ifindex, wdev, mac, generation) built\nonce and phase-specific payload added via a switch statement. This keeps\nheader construction in one place and makes the EMSGSIZE bail-out uniform.\n\nAdd a new request flag attribute, NL80211_ATTR_STA_DUMP_LINK_STATS\n(NLA_FLAG), for NL80211_CMD_GET_STATION dump. Userspace can set this\nflag to request per-link station statistics for MLO stations.\n\nExtract this flag during the first dump invocation by passing an attrbuf\nto nl80211_prepare_wdev_dump(); use __free(kfree) to avoid scattered\nmanual kfree() calls. Cache the boolean in the dump context to avoid\nrepeated parsing on subsequent invocations.\n\nPer-link messages carry a single NL80211_ATTR_MLO_LINKS nest with the\nlink ID, link-specific MAC, and per-link NL80211_ATTR_STA_INFO payload.\nThe link-specific validity (is_valid_ether_addr) and null pointer guard\nare checked in nl80211_put_link_station_payload() before any message\nconstruction begins.\n\nAlso fix all nla_nest_start_noflag() calls in nl80211_fill_link_station()\nfor nested attribute types (STA_INFO, BSS_PARAM, TID_STATS, per-tid) to\nuse nla_nest_start() so the NLA_F_NESTED flag is set correctly.\n\nPropagate the actual return value from nl80211_put_sta_info_common() in\nthe AGGREGATED phase rather than returning skb-\u003elen. Returning skb-\u003elen\nsignals netlink to re-invoke the dump with the same sta_idx, causing an\ninfinite loop when the aggregated payload is too large to fit; returning\nthe real error code (-EMSGSIZE or otherwise) terminates the dump cleanly.\n\nBackward compatibility is seamlessly preserved for non-MLO stations.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-5-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I100685ba7aa7ba2b60c3fd9e5d9ea1f09ca129e2\nx-iwlwifi-stack-dev: ae23bb80f2b1bdaf7579e9878f02b7fdce069d56"
    },
    {
      "commit": "229be2f88d894cf3dbaba507021f08f98f648016",
      "tree": "563d8cfb339d2e6a95322e347b21ec01f62f290a",
      "parents": [
        "d69d6d6f87f06912d33a4dab2300d625bf9e2bca"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:33 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:29 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Refactor nl80211_dump_station() to prepare for per-link stats\n\nCurrently, nl80211_dump_station() relies on the netlink callback\u0027s generic\nargs array (cb-\u003eargs[2]) to track the station index during dumps. It also\nprocesses the entire sinfo structure and transmits it to userspace\nimmediately in a single pass.\n\nThis approach creates a bottleneck for MLO. When an MLD station has\nmultiple active links, the aggregated station information, combined\nwith the individual per-link statistics, can easily exceed the\nmaximum netlink message size limits. The current monolithic dump\niteration cannot pause and resume mid-station to fragment these large\nper-link statistics across multiple netlink messages.\n\nIntroduce a stateful context structure (struct nl80211_dump_station_ctx)\nallocated during the dump to track the iteration state. Store the context\npointer directly at cb-\u003eargs[2], following the same pattern as\nnl80211_dump_wiphy which stores its state pointer at cb-\u003eargs[0].\n\nMove the station index (sta_idx) tracking and the sinfo payload into this\ncontext. The per-station netlink message is built inline in the loop:\ncommon header attributes are assembled directly, then\nnl80211_put_sta_info_common() adds the STA_INFO payload.\n\nFurthermore, move the NL80211_CMD_GET_STATION command definition from\ngenl_small_ops to genl_ops to natively support the .done callback.\nImplement nl80211_dump_station_done() to ensure the newly allocated state\ncontext and its deeply allocated sinfo payload are safely freed when the\ndump concludes or is aborted prematurely by userspace.\n\nNote that the previous dump path used nl80211_send_station(), which\nincluded NL80211_ATTR_IE and NL80211_ATTR_RESP_IE. These attributes are\nnot carried forward in this implementation. As documented, association\nresponse IEs (assoc_resp_ies) are only relevant at station creation time\n(e.g. via cfg80211_new_sta()) to notify userspace about association\ndetails, and are not expected to be part of get_station()/dump_station()\ncallbacks. Aligning with this expectation, these IEs are intentionally\nomitted here.\n\nThis refactoring maintains the existing netlink batching performance while\nlaying the stateful foundation required for per-link statistics\nfragmentation in subsequent patches.\n\nAt out_err_release, cfg80211_sinfo_release_content() frees any\ndynamically allocated sub-fields inside ctx-\u003esinfo (including per-link\npointers in sinfo.links[]). Without the subsequent memset, those\npointers remain non-NULL in the embedded sinfo. When the dump concludes\nor is aborted, nl80211_dump_station_done() calls\ncfg80211_sinfo_release_content() a second time on the same ctx-\u003esinfo,\nwhich would free the already-released link memory. The\nmemset(\u0026ctx-\u003esinfo, 0, sizeof(ctx-\u003esinfo)) zeroes all pointers so the\nsecond release call hits kfree(NULL), which is a harmless no-op.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-4-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Icb3a951a09fef49c3aa1d906027feb89ad131af6\nx-iwlwifi-stack-dev: 2e241285183147056fa94caace41101b5e5c7c7c"
    },
    {
      "commit": "d69d6d6f87f06912d33a4dab2300d625bf9e2bca",
      "tree": "0d0f1ee507f716d98b36557a25783f3ab6bc3da1",
      "parents": [
        "37c9057e42a5d9b7f4983c2aa53db26fa94f8fa9"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:32 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:25 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Add helper to pack station-level STA_INFO\n\nAdd a helper function nl80211_put_sta_info_common() to pack the\nstation-level (aggregated) STA information into a netlink message.\nThis prepares the code for future enhancements such as supporting\nfragmented link statistics in nl80211_dump_station.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-3-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I27a1c2fe26b8d5e842567bdbf62ffd4e51229a92\nx-iwlwifi-stack-dev: 6c340e60fe5052e3d48c66c392ab4b1e86292c9b"
    },
    {
      "commit": "37c9057e42a5d9b7f4983c2aa53db26fa94f8fa9",
      "tree": "d8a4a6dc2735633cd3b67c1447d10d14b1185b0b",
      "parents": [
        "e310c9f8f6a5a39f6c5ccd57dd89b445eb72054a"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:31 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:20 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Drop unused link stats handling in nl80211_send_station()\n\nRemove the link level statistics handling from\nnl80211_send_station() and drop the unused link_stats parameter\nfrom its signature and callers. The removed code iterated over\neach MLO link and attempted to send link specific station data\nthrough NL80211_ATTR_MLO_LINKS, but this logic was never used\nbecause link_stats was always false.\n\nThis logic was introduced during early work on link level station\nstatistics with the intention of reporting information for each\nlink. Due to message size concerns when a station has multiple\nlinks, the feature was disabled behind the link_stats flag and\nremained unused.\n\nThe link level reporting block in nl80211_send_station() is dead\ncode and cannot support larger messages, so remove it. This\ncleanup also prepares for proper link level statistics reporting\nin nl80211_dump_station() in a later patch, where fragmentation\nallows safe transmission of multi link data.\n\nAlso fix label indentation: the nla_put_failure label had an\nerroneous leading space.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-2-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I4c4bca15f1bc469b779fec594893d70a525f5907\nx-iwlwifi-stack-dev: ec9aa1826f581153fc11a30f89e261fee2eb6a9f"
    },
    {
      "commit": "e310c9f8f6a5a39f6c5ccd57dd89b445eb72054a",
      "tree": "a13da004db7e651d73b0e90ec2fcd1941afb566c",
      "parents": [
        "30a4dde8404c8e2f5bee575f6e52587d8e30875c"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Sat Jun 13 02:50:45 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:16 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: validate deauth frame length before reason access\n\nieee80211_rx_mgmt_deauth() reads the deauth reason code before checking\nthat the fixed field is actually present in the received frame.\n\nValidate the deauth frame length first and only then read the reason\ncode.\n\ntype\u003dmaint\nticket\u003dnone\n\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612185042.66260-6-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ic451958e6db9f9d1ae2a38c5c1ecb3b552824f36\nx-iwlwifi-stack-dev: 853cf8df73f678af8c185f047262fd5f4c05c47d"
    },
    {
      "commit": "30a4dde8404c8e2f5bee575f6e52587d8e30875c",
      "tree": "5fa721bd08a80336e6bb10093b74893c98cc35c3",
      "parents": [
        "42d218cee7bdae58f12cff74a7f84ed47fdc1a22"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 23:24:41 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:11 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: avoid non-S1G AID fallback for S1G assoc\n\nWhen assoc_data-\u003es1g is set and no AID Response element is present,\nfalling back to mgmt-\u003eu.assoc_resp.aid reads the non-S1G\nassociation-response layout.\n\nKeep the fallback for non-S1G only. If a successful S1G association\nresponse omits the AID Response element, abandon the association\ninstead of proceeding with AID 0. Initialize aid to 0 for other S1G\nresponses so the later mask and logging flow keeps a defined value\nwithout reading the non-S1G layout.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 2a8a6b7c4cb0 (\"wifi: mac80211: handle station association response with S1G\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612152440.25955-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I1c1123413256e616e5ebb653a6d6ace4c080e416\nx-iwlwifi-stack-dev: 36d4770e4d1cf76ca7878a97647073d1c7c318b0"
    },
    {
      "commit": "42d218cee7bdae58f12cff74a7f84ed47fdc1a22",
      "tree": "0a86de7fea55e30fc32d5ab4f355a76d3c874272",
      "parents": [
        "d1ccee5c2305e091caedb720db17987d86218502"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:37:18 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:06 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: reject empty PMSR peer lists\n\nA PMSR request with an empty peers array is not a useful request and\nweakens the cfg80211-to-driver contract by allowing start_pmsr() with\nno target peer.\n\nReject empty peer lists before allocating the request object or calling\ninto the driver.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 9bb7e0f24e7e7 (\"cfg80211: add peer measurement with FTM initiator API\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612133717.93783-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: If524b21e72c0eacd0d6188c6080fbafe4fc7ced1\nx-iwlwifi-stack-dev: 355ad0a2e635a359507495e0291af7990e2a91bf"
    },
    {
      "commit": "d1ccee5c2305e091caedb720db17987d86218502",
      "tree": "d265f816f2d40090dad533b5f52b92795992d52c",
      "parents": [
        "7bfae654b48aa1dc53c5c61e237107aa8a00dd21"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:37:11 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:41:01 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: reject unsupported PMSR FTM location requests\n\nPMSR FTM location request flags are syntactically valid, but they must\nbe rejected when the device capability does not advertise support for\nthem.\n\nReturn an error immediately after rejecting unsupported LCI or civic\nlocation request bits so the request cannot reach the driver.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 9bb7e0f24e7e7 (\"cfg80211: add peer measurement with FTM initiator API\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612133710.93544-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ic12c7de12017e2d9ec405602d11aab8137b0fa17\nx-iwlwifi-stack-dev: b3c8e9b0816aea4d70724ad85938698df51d4954"
    },
    {
      "commit": "7bfae654b48aa1dc53c5c61e237107aa8a00dd21",
      "tree": "daa43e2956dfe28bf7e85a5caa39514a6167fbf8",
      "parents": [
        "f0d44f0ed27312abd55a5195f91ddd2457c4d008"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:37:04 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:57 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: validate PMSR FTM preamble range\n\nPMSR FTM request parsing accepts preamble values outside the\nenumerated nl80211 preamble range.\n\nReject out-of-range values before using them in the parser capability\nbit test using the policy.\n\nFixes: 9bb7e0f24e7e7 (\"cfg80211: add peer measurement with FTM initiator API\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612133703.93274-2-enderaoelyther@gmail.com\n[drop unnecessary check]\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I5dbf15fa0335d0aabfe7fa60d84d5dbb8e9c14cb\nx-iwlwifi-stack-dev: a0eca2b0f53469da04e243df2d992739f28e1d21"
    },
    {
      "commit": "f0d44f0ed27312abd55a5195f91ddd2457c4d008",
      "tree": "fe6cac74b2b2761e9cfea980555cd579a9c64246",
      "parents": [
        "e6f5d570594f611346ef483f406a8cf4f46d0580"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:36:57 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:53 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: validate PMSR measurement type data\n\nPMSR request parsing accepts missing or duplicated measurement type\nentries in NL80211_PMSR_REQ_ATTR_DATA.\n\nTrack whether one measurement type was already provided, reject a\nsecond one immediately, and return an error if the request data block\ncontains no measurement type at all.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 9bb7e0f24e7e7 (\"cfg80211: add peer measurement with FTM initiator API\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612133656.92900-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I5ed80a42daa29916931b0526ced5bef0dfce7b4e\nx-iwlwifi-stack-dev: f0b0832c9e7d0f45ac2df4418a7bc68ff42e4a69"
    },
    {
      "commit": "e6f5d570594f611346ef483f406a8cf4f46d0580",
      "tree": "204c942b4e3bee9d49f7883a8835d0cffae4c415",
      "parents": [
        "6705bf7b276cb4df987fb3b11539af7cb8d77a51"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:18:56 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:48 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: constrain MBSSID TX link ID range\n\nMBSSID transmitted-profile link IDs are valid only in the range\n0..IEEE80211_MLD_MAX_NUM_LINKS - 1. Constrain the nl80211 policy to\nreject out-of-range values during attribute validation.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 37523c3c47b3 (\"wifi: nl80211: add link id of transmitted profile for MLO MBSSID\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612131854.43575-4-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ib0a2fe4def5fa321ba5f82f72dab53dfb730e058\nx-iwlwifi-stack-dev: 110af65740cd512e8a3a875568244d26f2f4b443"
    },
    {
      "commit": "6705bf7b276cb4df987fb3b11539af7cb8d77a51",
      "tree": "733714fe318e4f2692ca7f06645d006def4d2558",
      "parents": [
        "ada486f923c6b435408a1490722bd4f2416c0384"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 21:18:55 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:43 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: validate nested MBSSID IE blobs\n\nValidate each nested NL80211_ATTR_MBSSID_ELEMS entry as a well-formed\ninformation-element stream before storing it for beacon construction.\n\nRNR parsing already validates each nested blob with validate_ie_attr()\nbefore storing it. Apply the same syntactic IE validation to MBSSID\nentries before counting and copying their data and length pointers.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: dc1e3cb8da8b (\"nl80211: MBSSID and EMA support in AP mode\")\nAssisted-by: Codex:gpt-5.5\nAssisted-by: Claude:claude-opus-4.8\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260612131854.43575-3-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Iff94b67e28556a52b87d3a0749eac574fc87bf55\nx-iwlwifi-stack-dev: bd490e5c45789ade731c229cdc987e9b103da97b"
    },
    {
      "commit": "ada486f923c6b435408a1490722bd4f2416c0384",
      "tree": "a973add6fb177974e4ef1a99be513631d0e6417a",
      "parents": [
        "4be9fb7ae4c0d43d97db83949a918e24858b99f9"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 01:35:07 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:39 2026 +0000"
      },
      "message": "[FROMGIT] wifi: ieee80211: validate MLE common info length\n\nieee80211_mle_common_size() uses the first common-info octet as the\ncommon information length for all known MLE types. However,\nieee80211_mle_size_ok() only validates that octet for Basic, Probe\nRequest, and TDLS MLEs.\n\nReconfiguration MLEs also skipped the length octet when calculating the\nminimum common size, and Priority Access MLEs skipped validation of the\nadvertised common information length.\n\nAccount for the Reconfiguration common-info length octet and validate\nthe advertised common information length for all known MLE types. Keep\nunknown-type handling unchanged.\n\nFixes: 0f48b8b88aa9 (\"wifi: ieee80211: add definitions for multi-link element\")\nCc: stable@vger.kernel.org\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260611173506.36838-2-enderaoelyther@gmail.com\n[remove now misleading comment]\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ia45298add4497d9cec9b930b158536a8c964e22c\nx-iwlwifi-stack-dev: 49277c6423830f3af6c0e78380abc8f77ca9adfe"
    },
    {
      "commit": "4be9fb7ae4c0d43d97db83949a918e24858b99f9",
      "tree": "7e11cc0c2e8ccd229a78bfd9bd049545d679314b",
      "parents": [
        "cf55885f7e3048446e01cad3c6fd3336a0f31d43"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 00:19:46 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:35 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: derive S1G beacon TSF from S1G fields\n\ncfg80211_inform_bss_frame_data() parses S1G beacons with the extension\nframe layout, but still reads the TSF from the regular probe response\nlayout after the S1G branch. For S1G beacons that reads bytes at the\nregular management-frame timestamp offset instead of the S1G timestamp.\n\nUse the 32-bit S1G beacon timestamp and the S1G Beacon Compatibility\nelement\u0027s TSF completion field when informing an S1G BSS. Keep the\nregular management-frame timestamp read in the non-S1G branch.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 9eaffe5078ca (\"cfg80211: convert S1G beacon to scan results\")\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nTested-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nReviewed-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260611161943.91069-6-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I472ebf6db486c2c276b5e2fa8b5d0453bc59d4f3\nx-iwlwifi-stack-dev: e5be2ae260235b5e5478aab15328bd0dd255fa81"
    },
    {
      "commit": "cf55885f7e3048446e01cad3c6fd3336a0f31d43",
      "tree": "d877ea37936046a662bce684b4550c01c809ac64",
      "parents": [
        "4bb98706eba1aa66e2739ad6b2dc609aeb7e4782"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Fri Jun 12 00:19:45 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:31 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: validate extension-frame layout before RX\n\nExtension frames only have the extension header at the regular 802.11\nheader offset. The generic RX path can still reach helpers and interface\ndispatch code that read regular header address fields before unsupported\nextension subtypes are dropped.\n\nmac80211 currently only handles S1G beacon extension frames. Drop other\nextension subtypes before they can reach regular-header RX processing.\nFor S1G beacons, linearize the SKB with the management-frame path and\nrequire the fixed S1G beacon header, including optional fixed fields\nindicated by frame control, before generic RX dispatch.\n\nRoute S1G beacons through the station/default-link RX path without\nregular-header station lookup. Avoid regular-header address reads in the\nmac80211 RX paths that process S1G extension beacons, including\naccept-frame, duplicate-detection, address-copy, and MLO\naddress-translation paths.\n\nAlso make ieee80211_get_bssid() length-safe before returning the S1G\nsource-address pointer.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 09a740ce352e (\"mac80211: receive and process S1G beacons\")\nCc: stable@vger.kernel.org\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260611161943.91069-5-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ic0f6d8dc51a40ba5f9334cd5a418fe374a45ac22\nx-iwlwifi-stack-dev: f975f70eaacf7b468ea8d2f8e2c0fd6bd86e0dc0"
    },
    {
      "commit": "4bb98706eba1aa66e2739ad6b2dc609aeb7e4782",
      "tree": "f1ecf7379116665472c8947e2e42d2064107751a",
      "parents": [
        "5981194b0b431ed1fb320191593208dd308362ff"
      ],
      "author": {
        "name": "Zhao Li",
        "email": "enderaoelyther@gmail.com",
        "time": "Wed Jun 10 19:22:09 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:27 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: free RNR data on MBSSID mismatch\n\nnl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR\nentries than MBSSID entries.\n\nThe rejected RNR allocation has not been attached to the beacon data yet,\nso free it before returning the error.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: dbbb27e183b1 (\"cfg80211: support RNR for EMA AP\")\nSigned-off-by: Zhao Li \u003cenderaoelyther@gmail.com\u003e\nLink: https://patch.msgid.link/20260610112208.1308-2-enderaoelyther@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ia7d6f4a66b624fef1689b08672a0e3a50e055bad\nx-iwlwifi-stack-dev: bccf55766183d58aefddeeb0bcccb0d2026a6bab"
    },
    {
      "commit": "5981194b0b431ed1fb320191593208dd308362ff",
      "tree": "5b6feb94a8ca43d15e34ba7ab2a623767c9767a4",
      "parents": [
        "20388cc5d19c137840d695bf3bda45ed1d1036ec"
      ],
      "author": {
        "name": "Peddolla Harshavardhan Reddy",
        "email": "peddolla.reddy@oss.qualcomm.com",
        "time": "Fri Jul 03 13:55:23 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:23 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nWhen a netlink socket that owns a PMSR session is closed,\ncfg80211_release_pmsr() clears the request\u0027s nl_portid and queues\npmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.\n\nIf the interface tears down concurrently, cfg80211_pmsr_wdev_down()\nis called under wiphy_lock and calls cancel_work_sync(\u0026pmsr_free_wk)\nto wait for any running work. The work function acquires wiphy_lock\nvia guard(wiphy) before calling process_abort.\n\nThis is a deadlock: wdev_down holds wiphy_lock and blocks inside\ncancel_work_sync(); pmsr_free_wk blocks trying to acquire that same\nwiphy_lock. Neither thread can proceed.\n\nThe same deadlock is reachable from cfg80211_leave_locked(), which\ncalls cfg80211_pmsr_wdev_down() for all interface types under\nwiphy_lock.\n\nFix this by converting pmsr_free_wk from a plain work_struct to a\nwiphy_work. The wiphy_work dispatcher holds wiphy_lock when running\nwork items, so the explicit guard(wiphy) in the work function is no\nlonger needed. wiphy_work_cancel() can be called safely while holding\nwiphy_lock - since wiphy_lock prevents the work from running\nconcurrently, wiphy_work_cancel() never blocks, eliminating the\ndeadlock.\n\nRemove the cancel_work_sync() for pmsr_free_wk from the\nNETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally\njust before it, already cancels any pending work under wiphy_lock\nvia wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 6dccbc9f3e1d (\"wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down\")\nSigned-off-by: Peddolla Harshavardhan Reddy \u003cpeddolla.reddy@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260703082523.2629324-1-peddolla.reddy@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I236ec7d35554524fdd4c0a080532208a9ead8549\nx-iwlwifi-stack-dev: 1b4590d41a60ed724b3cb46802de29d0e7bb9312"
    },
    {
      "commit": "20388cc5d19c137840d695bf3bda45ed1d1036ec",
      "tree": "d910cedcc6ecdeac55bea589ddbb4aee9f801c5c",
      "parents": [
        "18177785aeee5ca2dbad34467cd518492dc759e2"
      ],
      "author": {
        "name": "Haofeng Li",
        "email": "lihaofeng@kylinos.cn",
        "time": "Wed Jul 01 17:33:27 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:19 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: validate EHT MLE before MLD ID read\n\ncfg80211_gen_new_ie() copies ML probe response elements from\nthe parent frame when the parent EHT multi-link element has an\nMLD ID matching the nontransmitted BSSID index.\n\nThe code only checked that the extension element had more than\none byte before calling ieee80211_mle_get_mld_id(). That helper\nassumes a BASIC MLE with enough common info and documents that\ncallers must first use ieee80211_mle_type_ok().\n\nAttack chain:\nmalicious AP sends a short EHT MLE in an MBSSID beacon.\ncfg80211_inform_bss_frame_data() stores the copied IE buffer.\ncfg80211_parse_mbssid_data() builds the nontransmitted BSS IE.\ncfg80211_gen_new_ie() sees the EHT MLE in the parent frame.\nieee80211_mle_get_mld_id() then reads past the IE boundary.\n\nValidate the MLE type and size before reading the MLD ID. This\nmatches the contract required by the MLE helper and rejects the\nshort element before any internal MLE fields are accessed.\n\ntype\u003dmaint\nticket\u003dnone\n\nCc: stable@vger.kernel.org\nFixes: 61dcfa8c2a8f (\"wifi: cfg80211: copy multi-link element from the multi-link probe request\u0027s frame body to the generated elements\")\nSigned-off-by: Haofeng Li \u003clihaofeng@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260701093327.2680709-1-lihaofeng@kylinos.cn\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ib89eeaecd90991785c26dfbb9008077a40c44bdc\nx-iwlwifi-stack-dev: a5e2064f7b610ab90ebc0d002e01319910b9e120"
    },
    {
      "commit": "18177785aeee5ca2dbad34467cd518492dc759e2",
      "tree": "f032cafbc4d12d1ef5843c7acefc568138d5a184",
      "parents": [
        "05ecc7d180ef1bbcf5139463a8aee733567d5036"
      ],
      "author": {
        "name": "Maoyi Xie",
        "email": "maoyixie.tju@gmail.com",
        "time": "Sat Jun 27 16:30:28 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:15 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: defer link RX stats percpu free to RCU\n\nsta_remove_link() frees a removed MLO link\u0027s RX stats percpu buffer right\naway, but defers only the link container to RCU:\n\n\tsta_info_free_link(\u0026alloc-\u003einfo);\n\tkfree_rcu(alloc, rcu_head);\n\nThe RX fast path reads link_sta under rcu_read_lock and writes the percpu\nstats. A reader that resolved link_sta before the removal keeps the\npointer. The container stays alive from the kfree_rcu, so the read still\nworks. But the percpu block it points to is already freed. This needs\nuses_rss. That is when pcpu_rx_stats exists.\n\nThe full STA teardown frees the deflink stats only after\nsynchronize_net(). The link removal path had no such barrier. The race is\nhard to win in practice, but the free should still wait for RCU.\n\nFree the link together with its data from a single RCU callback, so the\npercpu block is reclaimed only after readers drain.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: c71420db653a (\"wifi: mac80211: RCU-ify link STA pointers\")\nLink: https://lore.kernel.org/r/20260626080158.3589711-1-maoyixie.tju@gmail.com\nSuggested-by: Johannes Berg \u003cjohannes@sipsolutions.net\u003e\nCo-developed-by: Kaixuan Li \u003ckaixuan.li@ntu.edu.sg\u003e\nSigned-off-by: Kaixuan Li \u003ckaixuan.li@ntu.edu.sg\u003e\nSigned-off-by: Maoyi Xie \u003cmaoyixie.tju@gmail.com\u003e\nLink: https://patch.msgid.link/20260627083028.3826810-1-maoyixie.tju@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I0315ffd43e1b0bb2b769b05d8fecf9bb913bab88\nx-iwlwifi-stack-dev: a1ba15c19b029463e1a22d58886ff28a362ed6b8"
    },
    {
      "commit": "05ecc7d180ef1bbcf5139463a8aee733567d5036",
      "tree": "639c14d9ea84f7f11cc8c9f8b99b6d1635d7e388",
      "parents": [
        "d57f08f5ea017e991605036d7de09f17bf7298c3"
      ],
      "author": {
        "name": "Zhiling Zou",
        "email": "roxy520tt@gmail.com",
        "time": "Sat Jun 27 00:58:30 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:11 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: free ack status frame on TX header build failure\n\nieee80211_build_hdr() stores an ACK status frame before it has\nfinished all validation and header construction. If a later error path\nis taken, the transmit skb is freed but the stored ACK status frame\nremains in local-\u003eack_status_frames.\n\nThis can happen for control port frames when the requested MLO link ID\ndoes not match the link selected for a non-MLO station. Repeated\nfailures can fill the ACK status IDR and leave pending ACK frames until\nhardware teardown.\n\nRemove any stored ACK status frame before returning an error after it\nhas been inserted into the IDR.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: a729cff8ad51 (\"mac80211: implement wifi TX status\")\nCc: stable@vger.kernel.org\nReported-by: Yuan Tan \u003cyuantan098@gmail.com\u003e\nReported-by: Yifan Wu \u003cyifanwucs@gmail.com\u003e\nReported-by: Juefei Pu \u003ctomapufckgml@gmail.com\u003e\nReported-by: Xin Liu \u003cbird@lzu.edu.cn\u003e\nAssisted-by: Codex:gpt-5.4\nSigned-off-by: Zhiling Zou \u003croxy520tt@gmail.com\u003e\nSigned-off-by: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\nLink: https://patch.msgid.link/9de0423da840e92084915b8f92e66a421245c4b8.1782462409.git.roxy520tt@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I51313719177f39944d43aac5de99133cb46f0f13\nx-iwlwifi-stack-dev: d54a9955f976c2621d829f52866417e0cbab62ff"
    },
    {
      "commit": "d57f08f5ea017e991605036d7de09f17bf7298c3",
      "tree": "9e0539b3b6b74869df39a9430716af7303418feb",
      "parents": [
        "83111a659969245f7ec3184f2d9c2c9ad1661c1d"
      ],
      "author": {
        "name": "Xiang Mei",
        "email": "xmei5@asu.edu",
        "time": "Sun Jun 21 02:35:32 2026 -0700"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:07 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link-\u003eu.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800c065280 by task swapper/0/0\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 3b1c256eb4ae (\"wifi: mac80211: fixes in FILS discovery updates\")\nReported-by: Weiming Shi \u003cbestswngs@gmail.com\u003e\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Xiang Mei \u003cxmei5@asu.edu\u003e\nLink: https://patch.msgid.link/20260621093532.884188-2-xmei5@asu.edu\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I8ea767dd6a2374afea13fab66a2dcfebf438ee18\nx-iwlwifi-stack-dev: 8b1eaa50062582166d4841307cd2aedb8dd7f21a"
    },
    {
      "commit": "83111a659969245f7ec3184f2d9c2c9ad1661c1d",
      "tree": "90969ea18dc4bec021b4d9a5b8e9fd8cbc279583",
      "parents": [
        "2f2a8cb8a96f37a60cffd0cd7f148de947090c5e"
      ],
      "author": {
        "name": "Xiang Mei",
        "email": "xmei5@asu.edu",
        "time": "Sun Jun 21 02:35:31 2026 -0700"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:40:02 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link-\u003eu.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800d06f300 by task exploit/145\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 3b1c256eb4ae (\"wifi: mac80211: fixes in FILS discovery updates\")\nReported-by: Weiming Shi \u003cbestswngs@gmail.com\u003e\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Xiang Mei \u003cxmei5@asu.edu\u003e\nLink: https://patch.msgid.link/20260621093532.884188-1-xmei5@asu.edu\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Ic611fa3eb136e8fac41114add3d59987f6def8bd\nx-iwlwifi-stack-dev: 747d50d6a1e8f1e6717a2b6bad470e8f45facf2b"
    },
    {
      "commit": "2f2a8cb8a96f37a60cffd0cd7f148de947090c5e",
      "tree": "62dad33b48019823f6d7f838a2cb8b2ed14b8572",
      "parents": [
        "6f301466c975800bcc116f76d405b957cc77c56c"
      ],
      "author": {
        "name": "Christophe JAILLET",
        "email": "christophe.jaillet@wanadoo.fr",
        "time": "Sat Jun 20 21:48:56 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:58 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()\n\nIf the test against IEEE80211_MAX_SSID_LEN fails, then \u0027creq\u0027 leaks.\nUse the existing error handling path to fix it.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 2a5193119269 (\"cfg80211/nl80211: scanning (and mac80211 update to use it)\")\nSigned-off-by: Christophe JAILLET \u003cchristophe.jaillet@wanadoo.fr\u003e\nLink: https://patch.msgid.link/a1be7eea4da0da18f90589af252bb76a18a61978.1781984889.git.christophe.jaillet@wanadoo.fr\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I9c759e6b3e4c933a41b1deb090203ca2537f15cd\nx-iwlwifi-stack-dev: 3e0990a79fd40089b02d27475f775bd175f9b65a"
    },
    {
      "commit": "6f301466c975800bcc116f76d405b957cc77c56c",
      "tree": "678e7eb8428b820d66fa1e9a36f838b5d457dcde",
      "parents": [
        "ed641f75e9f5147078a772db6cd4ad016f93ab36"
      ],
      "author": {
        "name": "Cen Zhang",
        "email": "zzzccc427@gmail.com",
        "time": "Sat Jun 20 00:25:42 2026 +0800"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:54 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: cancel sched scan results work on unregister\n\ncfg80211_sched_scan_results() can queue rdev-\u003esched_scan_res_wk from a\ndriver result notification while a scheduled scan request is present. The\nwork callback recovers the containing cfg80211_registered_device and then\nlocks the wiphy and walks the scheduled-scan request list.\n\nwiphy_unregister() already makes the wiphy unreachable and drains rdev work\nitems before cfg80211_dev_free() can release the object, but it does not\ndrain sched_scan_res_wk. A queued or running result work item can therefore\ncross the unregister/free boundary and access freed rdev state.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nscheduled-scan result path:        unregister/free path:\n1. cfg80211_sched_scan_results()   1. interface teardown stops and\n   queues rdev-\u003esched_scan_res_wk.    removes the scheduled scan request.\n2. cfg80211_wq starts the work     2. wiphy_unregister() drains other\n   item and recovers rdev.            rdev work items.\n3. The worker locks rdev-\u003ewiphy    3. cfg80211_dev_free() destroys and\n   and walks rdev state.              frees rdev.\n\nCancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev\nwork items. cancel_work_sync() removes a pending result notification and\nwaits for an already running callback, so cfg80211_dev_free() cannot free\nrdev while this work item is still active.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530\nWorkqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  cfg80211_sched_scan_results_wk+0x4a6/0x530\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x224/0x430\n  kasan_report+0xac/0xe0\n  lockdep_hardirqs_on_prepare+0xea/0x1a0\n  process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)\n  lock_is_held_type+0x8f/0x100\n  worker_thread+0x5ad/0xfd0\n  __kthread_parkme+0xc6/0x200\n  kthread+0x31e/0x410\n  trace_hardirqs_on+0x1a/0x170\n  ret_from_fork+0x576/0x810\n  __switch_to+0x57e/0xe20\n  __switch_to_asm+0x33/0x70\n  ret_from_fork_asm+0x1a/0x30\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 807f8a8c3004 (\"cfg80211/nl80211: add support for scheduled scans\")\nAssisted-by: Codex:gpt-5.5\nSigned-off-by: Cen Zhang \u003czzzccc427@gmail.com\u003e\nLink: https://patch.msgid.link/20260619162542.3878296-1-zzzccc427@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: Id37946b3db6c6727dc3b9561212d7f2e58a51de3\nx-iwlwifi-stack-dev: 85a3c612b953deeaa939c56bf26692bceafb8564"
    },
    {
      "commit": "ed641f75e9f5147078a772db6cd4ad016f93ab36",
      "tree": "a7e69f2d7ed48b7fe6ae9f08aead48c900c2b637",
      "parents": [
        "0da4e7ece235d2474eb4ecb08d3cd4868c12438c"
      ],
      "author": {
        "name": "Lachlan Hodges",
        "email": "lachlan.hodges@morsemicro.com",
        "time": "Fri Jun 26 16:28:58 2026 +1000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:50 2026 +0000"
      },
      "message": "[FROMGIT] wifi: ieee80211: introduce generic KHZ_TO_HZ helper\n\nUseful for S1G drivers due to the increased required granularity,\nbut may be useful for others so include it as a generic helper.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260626063014.1275235-3-lachlan.hodges@morsemicro.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I693f93ee32793610930b3c22e2ddb1dd42c2eb30\nx-iwlwifi-stack-dev: 425e88e69302612db9a78e0ca7f42c21cfe8a2a0"
    },
    {
      "commit": "0da4e7ece235d2474eb4ecb08d3cd4868c12438c",
      "tree": "f591bd1054f89c8eb1c93b669284c5cac50d017f",
      "parents": [
        "bc65f3feb7006d14372bab1c60440ef770457e63"
      ],
      "author": {
        "name": "Lachlan Hodges",
        "email": "lachlan.hodges@morsemicro.com",
        "time": "Fri Jun 26 16:28:57 2026 +1000"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:46 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: introduce helper to get S1G primary width\n\nThis is needed for drivers and will be needed for mac80211/cfg80211\nin the future so introduce a generic accessor to retrieve the\nchandefs S1G primary channel width.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260626063014.1275235-2-lachlan.hodges@morsemicro.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I0452295c37f85ba8b7bcfde24fb6a194ed717193\nx-iwlwifi-stack-dev: f2d20ab2ec4fe1df089381ae8480a5a22256e5fc"
    },
    {
      "commit": "bc65f3feb7006d14372bab1c60440ef770457e63",
      "tree": "e5b6ae699996e173ddc0900e7bc4835cab7b09df",
      "parents": [
        "057f113dfd91408dcbf477d3b3059975ec77afce"
      ],
      "author": {
        "name": "Dhanavandhana Kannan",
        "email": "dhanavandhana.kannan@oss.qualcomm.com",
        "time": "Tue Jun 23 16:04:12 2026 +0530"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:41 2026 +0000"
      },
      "message": "[FROMGIT] wifi: cfg80211: Avoid UNPROT_BEACON on AP interfaces\n\nCurrently, an AP may receive unprotected beacons from neighbouring\nBSSes, which cfg80211_rx_unprot_mlme_mgmt() forwards to userspace via\nNL80211_CMD_UNPROT_BEACON regardless of interface type.\n\nWhile the kernel rate-limits these events to once per 10 seconds per\nwdev, in multi-BSS scenarios each AP interface maintains its own\nrate-limit state, increasing the number of reported events.\nIn AP mode, hostapd has no handler for NL80211_CMD_UNPROT_BEACON and\nlogs an unhandled event message for each occurrence, leading to excessive\nlog noise and making it harder to identify real issues.\n\nSince an AP does not need to act on unprotected beacons from neighbouring\nBSSes, skip reporting this event when operating in AP mode.\n\ntype\u003dmaint\nticket\u003dnone\n\nSigned-off-by: Dhanavandhana Kannan \u003cdhanavandhana.kannan@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260623103412.1578812-1-dhanavandhana.kannan@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I82986484dc2444ffaccf16118fd25ce4177f6813\nx-iwlwifi-stack-dev: 28dd9994a72c864222ed7d2caa77576e5320fbfc"
    },
    {
      "commit": "057f113dfd91408dcbf477d3b3059975ec77afce",
      "tree": "d5a6a445ff3c151532e661e33018f986b1978daa",
      "parents": [
        "e2331bbf39b16879af33cd54b1348c9176b97293"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jun 15 09:39:48 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:37 2026 +0000"
      },
      "message": "[FROMGIT] wifi: nl80211: clarify NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA content\n\nThis is currently __le16, but really the whole content of the\ncorresponding 802.11 element, which is even extensible and\ncould, in theory, be increased in size. Clarify the docs.\n\ntype\u003dmaint\nticket\u003dnone\n\nLink: https://patch.msgid.link/20260615093948.0f730833a6d5.I1c8c5c09dfe16b0b1dcb10d54fc030f6b1d4fc8c@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: If899acb65855eb56d486b4b6c4c55924d18f20b5\nx-iwlwifi-stack-dev: 46ca0ef13f77b6b116c6655975e8a6d7d1d555f5"
    },
    {
      "commit": "e2331bbf39b16879af33cd54b1348c9176b97293",
      "tree": "576e554e4fd41e6dd4917d3133ff7c133c8e6f72",
      "parents": [
        "373fc0441cf5ef2b237e2663037551de5176fc3a"
      ],
      "author": {
        "name": "Arnd Bergmann",
        "email": "arnd@arndb.de",
        "time": "Thu Jun 11 15:00:54 2026 +0200"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Sun Aug 16 16:39:33 2026 +0000"
      },
      "message": "[FROMGIT] wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack\n\nThe ieee80211_nan_sched_cfg structure is too large to keep on the\nper thread stack:\n\nnet/mac80211/nan.c:251:5: error: stack frame size (1560) exceeds limit (1536) in \u0027ieee80211_nan_set_local_sched\u0027 [-Werror,-Wframe-larger-than]\n  251 | int ieee80211_nan_set_local_sched(struct ieee80211_sub_if_data *sdata,\n\nAllocate this dynamically using kmalloc_obj() to reduce the stack\nusage of this function to a manageable 344 bytes for the same\nconfiguration.\n\ntype\u003dmaint\nticket\u003dnone\n\nFixes: 589c06e8fdee (\"wifi: mac80211: add NAN local schedule support\")\nSigned-off-by: Arnd Bergmann \u003carnd@arndb.de\u003e\nLink: https://patch.msgid.link/20260611130100.3387714-1-arnd@kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nChange-Id: I44e9ddf9e94588c7804ed8ae54d9a20f4210f881\nx-iwlwifi-stack-dev: 19433c8b9e97d752370ca99dd86543e281c370e2"
    },
    {
      "commit": "373fc0441cf5ef2b237e2663037551de5176fc3a",
      "tree": "fc2f4d42b5d6b2bea052185ffe72d9519e32f840",
      "parents": [
        "0812c8fc42b09fce390c77f138b2f87943df9202"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Aug 13 11:15:06 2026 +0300"
      },
      "committer": {
        "name": "iwlwifi publisher",
        "email": "",
        "time": "Thu Aug 13 20:46:45 2026 +0000"
      },
      "message": "wifi: iwlwifi: BZ/FM is frozen on Core107\n\nThe BZ/FM combination is frozen on Core107 (while each of BZ, FM is not\nyet frozen and is still supported in other combinations).\nIndicate this in the relevant FW file mames, for modinfo.\nWhile at it, remove names that are no longer needed.\n\ntype\u003dfeature\nticket\u003dnone\nfixes\u003dI0e2918e21f8a20d200d371c1861ed2c5deac829d\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nChange-Id: Ie582bfb7d07a9d2e21c69d0468e0f51447e8f628\nReviewed-on: https://gerritwcs.ir.intel.com/c/iwlwifi-stack-dev/+/317974\nautomatic-review: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\ntested: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nTested-by: iil_jenkins iil_jenkins \u003cEC.GER.UNIX.IIL.JENKINS@INTEL.COM\u003e\nReviewed-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nx-iwlwifi-stack-dev: f3110430f0a0fa18b72425e496a8af8ce76ac58b"
    }
  ],
  "next": "0812c8fc42b09fce390c77f138b2f87943df9202"
}
