)]}'
{
  "log": [
    {
      "commit": "4a2610a5a9fcf77eaad82bb030ec77ec5e381db8",
      "tree": "5cbb5cc5a739e1b7185ee34627419586e025e715",
      "parents": [
        "01f41f5fd823fb70a2f28ea87f6cf85a268ef8b9"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 23 14:23:37 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 23 20:26:32 2026 +0300"
      },
      "message": "wifi: iwlwifi: bump core version for BZ/SC/DR\n\nStart supporting Core 107 FW on these devices.\n\nLink: https://patch.msgid.link/20260723142324.ed92b1d7f927.I6dd10d2f9a04a36751aea9e238fecfa62fe280a6@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "01f41f5fd823fb70a2f28ea87f6cf85a268ef8b9",
      "tree": "775229b510df3cf4a7d3be9e0488b44613fa00c4",
      "parents": [
        "a47ab1b9c0827f5bd6717abb3f9e3f4f6eb5e00c"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Thu Jul 23 14:23:36 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 23 20:26:32 2026 +0300"
      },
      "message": "wifi: iwlwifi: regulatory: add LARI v15 DSM support bitmap\n\nFirmware API v15 extends LARI config with the DSM function-0 support\nbitmap, and host must provide this information for regulatory handling.\nWithout this, FW cannot use BIOS-reported DSM capability bits.\n\nAdd oem_supported_dsm_bitmap to the host LARI config command\ndefinition and wire it into regulatory command construction.\nPopulate it from DSM query data and keep backward compatibility by\nusing the pre-v15 command size for command version 14.\n\nBehavior change:\nWhen DSM function-0 data is available, host includes it in the LARI\nconfig command sent to FW; older command versions remain compatible.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nLink: https://patch.msgid.link/20260723142324.c576a8c7560b.I5cc1277d0ef31409f6a3364342a3f35cd9318ceb@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "a47ab1b9c0827f5bd6717abb3f9e3f4f6eb5e00c",
      "tree": "b86e340c8327e3cc2a220fffd7539cfbb992f2be",
      "parents": [
        "ac8227e35ff7c8953a7d8adf7f5230127ad97aae"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Fri Jul 17 17:31:12 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:31 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: move BIOS reading code to where it belongs\n\nWe have a dedicated function to fetch all the BIOS tables when the opmode\nstarts, and yet we read a couple of tables directly from\niwl_op_mode_mld_start, which is already a large function that does\nmultiple things.\nMove the reading of the sgom, puncturing, and RFI enablement to the\ndedicated iwl_mld_get_bios_tables.\n\nLink: https://patch.msgid.link/20260717172958.b19a33e0b507.I73f6b5e6a81d0f411f12589ceb30afa655c0a16b@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "ac8227e35ff7c8953a7d8adf7f5230127ad97aae",
      "tree": "a973303f7005800f73a343f8eb70c0214b863bbb",
      "parents": [
        "340eafb30b35a600a66da333bb0c119a880b7062"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Fri Jul 17 17:31:11 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:31 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: add debug log after AP type command\n\nAdd a radio debug trace when MCC_ALLOWED_AP_TYPE_CMD is sent\nsuccessfully during AP type table initialization.\nThis improves bring-up visibility without changing runtime behavior.\nFailures are still reported through the existing error log path.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.18e1fc5ec109.I76dd832f62d00a8f358f8e4a705f25184ac53da2@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "340eafb30b35a600a66da333bb0c119a880b7062",
      "tree": "b38f311349085632edc7b2b6971ae5e6b9a94c7c",
      "parents": [
        "7e1d5ccac87ec618f393ec137743207282ef1af5"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Fri Jul 17 17:31:10 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:31 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: support update_mcc notification v2\n\nNew firmware will support version 2 of the update_mcc notification. The\nextra field is used for a new feature, but we does not support it.\n\nKeep the existing payload definition compatible with both versions and\nregister version 2 in the MLD notification version table so the driver\naccepts the newer notification without changing the behavior.\n\nThis preserves version 1 support and adds compatibility with firmware\nthat sends version 2.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.9c5a940d37dc.I955800c2377b802ffb99003349552cc4036ca4bd@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "7e1d5ccac87ec618f393ec137743207282ef1af5",
      "tree": "5b5ef93907b33ea5d503ad54987448751ba2da4e",
      "parents": [
        "4f5384b58b483e4aec576ce461dec45b41df18db"
      ],
      "author": {
        "name": "Avinash Bhatt",
        "email": "avinash.bhatt@intel.com",
        "time": "Fri Jul 17 17:31:09 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:30 2026 +0300"
      },
      "message": "wifi: iwlwifi: fw: move SAR defines from acpi.h to regulatory.h\n\nIWL_SAR_ENABLE_MSK and IWL_REDUCE_POWER_FLAGS_POS describe the layout\nof the shared WRDS/SAR table format. They are not ACPI-specific: the\nsame bit positions are used regardless of whether the data originates\nfrom ACPI, UEFI, or another BIOS source.\n\nIWL_SAR_ENABLE_MSK was already duplicated in regulatory.h; remove it\nfrom acpi.h to eliminate the duplication.\n\nMove IWL_REDUCE_POWER_FLAGS_POS to regulatory.h alongside\nIWL_SAR_ENABLE_MSK so that both SAR field descriptors live in the\nshared regulatory header, accessible to all BIOS configuration sources.\n\nNo functional change.\n\nSigned-off-by: Avinash Bhatt \u003cavinash.bhatt@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.32e5dcde4b90.I420c58b05ab6ab011c4c771ca9e4eb62740de549@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "4f5384b58b483e4aec576ce461dec45b41df18db",
      "tree": "28f44062e6b1c16db67bdc3e6652e0b3a4a061da",
      "parents": [
        "a790f60cc4d7dc64a2d7cadb94a3d9f60392bed4"
      ],
      "author": {
        "name": "Ayala Beker",
        "email": "ayala.beker@intel.com",
        "time": "Fri Jul 17 17:31:08 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:30 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: drop connection on D3 resume failure\n\nWhen FW crashes on D3 exit, iwl_mld_nic_error() sets\nSTATUS_RESET_PENDING and queues restart wk, but mac80211\u0027s resume\ncallback synchronously calls iwl_trans_stop_device() which clears\nthe flag. As a result restart wk skips sw_reset, and the FW error\nrecovery buffer is never read.\n\nThe new FW boots with empty BA state and initial sequence numbers,\nwhile the AP still holds its A-MPDU RX reorder window.\nThis causes MPDUs to be dropped as IWL_RX_MPDU_REORDER_BA_OLD_SN until\nADDBA is renegotiated.\n\nWe don\u0027t know how long the firmware has been in an error state\nor whether the AP still considers us associated, so keeping the\nconnection alive is not worth it.\nCall ieee80211_resume_disconnect() when iwl_mld_wait_d3_notif() fails,\nand let userspace reassociate.\n\nSigned-off-by: Ayala Beker \u003cayala.beker@intel.com\u003e\nReviewed-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.3e10c8498f53.Icf5644b42d79e984ecc16abfa873bd37f611e778@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "a790f60cc4d7dc64a2d7cadb94a3d9f60392bed4",
      "tree": "65542e8e6033e5618e34c8e0a11f2fcac75f166d",
      "parents": [
        "6aa811062cd78ad961410a64db55694ff609da57"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Fri Jul 17 17:31:07 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:30 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: ignore sync frames when sync is disabled\n\nGate time-sync frame interception on the active flag so frames are not\nqueued after time-sync teardown.\n\nAssisted-by: GitHubCopilot:GPT-5.3-Codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.ac73ee199a25.Ic1489244f9b02da93060f0a0e5b300a73527f265@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "6aa811062cd78ad961410a64db55694ff609da57",
      "tree": "335375b3583f8f5b86a5da4fdd5c25e57a7eec58",
      "parents": [
        "c5cb9dd220ba9fdcf4ba485ce3d1d36ca32ac00b"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Fri Jul 17 17:31:06 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:30 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: initialize scan-abort status\n\nInitialize abort status before issuing the abort command so debug\nlogging never reads an uninitialized value on error paths.\n\nAssisted-by: GitHubCopilot:GPT-5.3-Codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.9d804f466534.I4e10270bd1dde4a80940a47ef5d383729cc66cb1@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "c5cb9dd220ba9fdcf4ba485ce3d1d36ca32ac00b",
      "tree": "ffaa16ee91f4f63fe72784bb57bdb3a96eeccee5",
      "parents": [
        "905f57aefde4f4092a411c8a55856182fb1c7598"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Fri Jul 17 17:31:05 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Sat Jul 18 22:39:30 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: validate wake packet crypto overhead\n\nWake packet parsing only accounted for FCS and missed per-key\nIV/ICV overhead for protected data frames.\n\nPrevent size underflow and bad packet trimming when\nnotifications are malformed or truncated.\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260717172958.e06595623533.Ie09494b7e34e5872b750fd90e325648ee469d0da@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "905f57aefde4f4092a411c8a55856182fb1c7598",
      "tree": "622634eca53476f876940b1bb014bb2a3c57213f",
      "parents": [
        "1c031ac5a39ebcc3269eace8b606043adc398bfa"
      ],
      "author": {
        "name": "Avraham Stern",
        "email": "avraham.stern@intel.com",
        "time": "Wed Jul 15 22:04:31 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mei: pass correct argument to function\n\nThe first argument to iwl_mei_write_cyclic_buf() should be the cldev\nbut the q_head pointer is passed instead. Fix it.\n\nFixes: 652291601459 (\"iwlwifi: mei: don\u0027t rely on the size from the shared area\")\nSigned-off-by: Avraham Stern \u003cavraham.stern@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.24cea60c6428.I42301010c31487b1458faa967b22c8320b0cfd23@changeid\n"
    },
    {
      "commit": "1c031ac5a39ebcc3269eace8b606043adc398bfa",
      "tree": "22eb681449ae912843b3c79e549d2ef5abaae972",
      "parents": [
        "9318bc0c41b24705690cf80d1596cf6b711e7027"
      ],
      "author": {
        "name": "Ilan Peer",
        "email": "ilan.peer@intel.com",
        "time": "Wed Jul 15 22:04:30 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: Do not cleanup FW state when the device is dead\n\nWhen a channel context is unassigned, there is a path to cleanup the FW\nstate in case of NON MLO connection: remove the link and add it again.\nHowever, when the transport is dead, e.g., during device removal etc.,\nthis flow will fail and as a result the mld_vif-\u003elink[0] would be set to\nNULL. Later, when the interface is removed, iwl_mld_remove_link() would\nwarn as the link is NULL.\n\nFix this by not doing the cleanup when the device is dead.\n\nSigned-off-by: Ilan Peer \u003cilan.peer@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.89a0c44a72a3.I45cca8b84a25943d5771199af6b0155dbac77b58@changeid\n"
    },
    {
      "commit": "9318bc0c41b24705690cf80d1596cf6b711e7027",
      "tree": "13c7cd173ae0833f1b067197004f2ceb1f5c9903",
      "parents": [
        "c00a5d65b7ada536eb488280fae53fcf1724a7c3"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Jul 15 22:04:29 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments\n\nMake sure we don\u0027t end-up with a num_frags \u003d 0 situation.\nFor that, check that the required size is not 0 and put a checker on\nnum_frags as well.\n\nFixes: 14124b25780d (\"iwlwifi: dbg_ini: implement monitor allocation flow\")\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.60121deecf2c.Iebc891c95a7bd1b2a093b0bb88532db446a758ee@changeid\n"
    },
    {
      "commit": "c00a5d65b7ada536eb488280fae53fcf1724a7c3",
      "tree": "1fa043a7f344e86684720d76d3a2f6cda5eb65ae",
      "parents": [
        "7d8cc301bcba233f31b589a45f4c1c97f2bb90d6"
      ],
      "author": {
        "name": "Avraham Stern",
        "email": "avraham.stern@intel.com",
        "time": "Wed Jul 15 22:04:28 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mei: skip data read if length is too short\n\nWhen calculating the SAP data length, the code subtracts\nsizeof(*ethhdr) from len. If the SAP data header indicates a length\nthat is shorter than ethernet header length, this will result in an\nunsigned underflow which will lead to a kernel panic when trying to\nput the data into the SKB. Fix it by skipping a message if the\nindicated length is too short.\nIn addition, if the message type is not SAP_MSG_DATA_PACKET or skb\nallocation fails, the loop skips to the next message but without\nreading the message payload. This may result in reading the payload\nas the next message header, which will lead to errors in parsing the\nnext messages. Fix it by skipping the message payload as well.\n\nSigned-off-by: Avraham Stern \u003cavraham.stern@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.f66b10736047.I4a1dde517c36561d41358dd82a5cec8b6c886c14@changeid\n"
    },
    {
      "commit": "7d8cc301bcba233f31b589a45f4c1c97f2bb90d6",
      "tree": "c6c1f35c7a24e6ba819462333ea7a076e4305a5a",
      "parents": [
        "c5aeb11489150be84d3a700711abffd98969d2d5"
      ],
      "author": {
        "name": "Avraham Stern",
        "email": "avraham.stern@intel.com",
        "time": "Wed Jul 15 22:04:27 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mei: check SAP message length before reading it\n\nVerify the SAP message size is not larger than the local buffer before\nreading the message to avoid buffer overflow.\n\nFixes: bcd68b3dbe78 (\"wifi: iwlwifi: mei: fix tx DHCP packet for devices with new Tx API\")\nSigned-off-by: Avraham Stern \u003cavraham.stern@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.f0026ce26218.I00a856d3aacae1caac605c708f7362689b734234@changeid\n"
    },
    {
      "commit": "c5aeb11489150be84d3a700711abffd98969d2d5",
      "tree": "bdfbb8d5f3ac3ef2e9665b909798cf89cc6db719",
      "parents": [
        "51c45bb2c884e0e2f56d6770011994d653371702"
      ],
      "author": {
        "name": "Shahar Tzarfati",
        "email": "shahar.tzarfati@intel.com",
        "time": "Wed Jul 15 22:04:26 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: fix read in wake packet notification handler\n\nIn iwl_mld_handle_wake_pkt_notif(), expected_size was initialized from\nnotif-\u003ewake_packet_length before the IWL_FW_CHECK that validates the\npayload covers sizeof(*notif).\n\nMove the assignment of expected_size to after the size check so that\nnotif-\u003ewake_packet_length is only accessed once the payload length has\nbeen validated.\n\nSigned-off-by: Shahar Tzarfati \u003cshahar.tzarfati@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.94c526d2c66e.I065a19a9dcc7f45a7457667c0f625fcd2c7bf6b6@changeid\n"
    },
    {
      "commit": "51c45bb2c884e0e2f56d6770011994d653371702",
      "tree": "8d29938fc374beb1914d88279cf933814cd1cf1f",
      "parents": [
        "ebc246e1d5a3e4502dba60cf9e9644de0fc5a8b6"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 22:04:25 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: add PNVM_INIT_COMPLETE_NTFY to the hcmd names\n\nAdd it to the array of host command name so it will be printed with\niwl_get_cmd_string\n\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.e8da467f1883.I75ab56a022f31365042d29aff5484e4329b0f6ce@changeid\n"
    },
    {
      "commit": "ebc246e1d5a3e4502dba60cf9e9644de0fc5a8b6",
      "tree": "8173ed343db2c8273606c575c73d5345b7050bc6",
      "parents": [
        "ad13072308f82a9aa2e68a135e70672454367d92"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Wed Jul 15 22:04:24 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: add LARI_CONFIG_EXTENSION command\n\nThere is a new UHB extension bitmap that is part of the LARI\nconfiguration, which needs to be sent to the FW - also frozen ones.\nBut in frozen FWs we cannot increase the version of an API, since the\ndriver assumes a specific version, depending on the core number.\nIn case of a (new) FW that expects the new version and a (old) driver\nthat doesn\u0027t support that new version, the driver will send a default\nold version, causing a fw assert about its bad size.\n\nTo mitigate this, there is a special command which will be supported\nonly on those frozen FWs. Old drivers will simply not support/send it,\nand new driver will send it if supported by fw.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.551f40ee2de3.I3e32a5d5c9aa13cbb0e599bef630cdb8e3b031c4@changeid\n"
    },
    {
      "commit": "ad13072308f82a9aa2e68a135e70672454367d92",
      "tree": "8df5df64ba50865bb1c92951b22bf9c7cb71f586",
      "parents": [
        "f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Wed Jul 15 22:04:23 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: honor FW puncturing capability in MCC response\n\nNew MCC response versions expose puncturing support directly in the\nregulatory capability flags. Propagate that information from NVM MCC\nparsing to MLD MCC handling and fall back to legacy FM/WH MCC-specific\npolicy when puncturing status is unknown.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.47d1389fa134.I5c7921d6e3c065e3962c5927991498c2d277fd8f@changeid\n"
    },
    {
      "commit": "f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab",
      "tree": "49a0fb03576e3ad44717090bce7e928fe67ca763",
      "parents": [
        "405ff50b72db1dfb86d7502c3c84208779809ab2"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Jul 15 22:04:22 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser\n\niwl_mvm_frob_txf_key_iter() tracks the last matched byte position\nin loop variable \u0027i\u0027. When a full key match is found (match \u003d\u003d\nkeylen), \u0027i\u0027 points at the last byte of the matched key. The\nmemset start offset should therefore be i + 1 - keylen, not\ni - keylen; the current code zeroes one byte before the match\nand leaves the final key byte un-sanitised.\n\nFixes: 12d60c1efc29 (\"iwlwifi: mvm: scrub key material in firmware dumps\")\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.355998ec4fbe.I40f3427657b897e911bdf4ebf8e494745508d126@changeid\n"
    },
    {
      "commit": "405ff50b72db1dfb86d7502c3c84208779809ab2",
      "tree": "6b83c69e43514d6e59ee2bda2257df4286aadc98",
      "parents": [
        "71e67b4b59337b2f9f4fef976a27de2dad7aabf2"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Jul 15 22:04:21 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: fix validation fallback in iwl_mld_notif_is_valid\n\nWhen a firmware notification version is not in the handler\u0027s\nsize table, iwl_mld_notif_is_valid() falls back to comparing\nagainst the last known structure size but the comparison is\nwrong: \u0027return size \u003c last_known_size\u0027 returns true (accept)\nfor undersized payloads and false (reject) for payloads that\nare large enough.\n\nInstead of trying to accept notifications that are large enough,\njust refuse the notification. We shouldn\u0027t ever get a\nnotification that is longer than what we expect.\n\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.e0b91efe689d.I7d7604be6819da263e9091370892e6b6f4c57913@changeid\n"
    },
    {
      "commit": "71e67b4b59337b2f9f4fef976a27de2dad7aabf2",
      "tree": "8a6e92be99217998dee8e7bae3d1937377a8b0f2",
      "parents": [
        "bbe2d2fa8780a04dac8de0ecaa3895d3f3bc093e"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Jul 15 22:04:20 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs\n\nThe loop counter \u0027count\u0027 was declared as u8 while num_pc is u32.\nIf firmware advertises more than 255 PC entries the counter wraps\nback to zero and the loop never terminates potentially causing an\ninfinite loop or reading past the allocated pc_data array.\n\nChange the declaration to u32 to match num_pc.\n\nFixes: 2b69d242e29b (\"wifi: iwlwifi: fw: print PC register value instead of address\")\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.a61c65f34e87.Ie5f1a7ca43e0cc5a0ddc8305b0448ddffc09cd18@changeid\n"
    },
    {
      "commit": "bbe2d2fa8780a04dac8de0ecaa3895d3f3bc093e",
      "tree": "12986ebc253c447fb6c779b0f8ea5b9b2ddd6de3",
      "parents": [
        "7e16dad5d47e29338db9effbeb26b4e8bcfbc2c0"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Wed Jul 15 22:04:19 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm/mld: fix PPE threshold debug print loop\n\nThe loop should print all bandwidths, the extra * results in\ncalculating the wrong ARRAY_SIZE() here (of the array inside\nthe per-bandwidth, not the per-bandwidth array.) Fix that,\nand also clarify the array variable assignment.\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.5e1d3448bfca.I6919627382d46605b41b0c6a6f34deedfd45523c@changeid\n"
    },
    {
      "commit": "7e16dad5d47e29338db9effbeb26b4e8bcfbc2c0",
      "tree": "6723abc66e550667984d67294b480234c2de2160",
      "parents": [
        "ef704fc32ae1a519801ac4a06aa290fece5f403c"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Wed Jul 15 22:04:18 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: validate WoWLAN notif header\n\nValidate fixed wowlan_info_notif header size first.\nOnly then read num_mlo_link_keys from pkt-\u003edata.\nApply this to v5 and v6 parsing paths.\n\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.9c33c20194ad.I691d019927cc56898f2516fcf5795c8b1fae362c@changeid\n"
    },
    {
      "commit": "ef704fc32ae1a519801ac4a06aa290fece5f403c",
      "tree": "74be700b900015726c12c1ab1b8946fe16b3e2ba",
      "parents": [
        "71ac392d8b5c23c45c66f30eff1c319580ada4da"
      ],
      "author": {
        "name": "Avraham Stern",
        "email": "avraham.stern@intel.com",
        "time": "Wed Jul 15 22:04:17 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Thu Jul 16 21:10:48 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: support aborting an ongoing ftm request\n\nAdd support for aborting an ongoing FTM request.\n\nSigned-off-by: Avraham Stern \u003cavraham.stern@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260715220243.340040bdc6a3.Ifbbf70021e42bf1d59db6ec45a73f1806a1c2289@changeid\n"
    },
    {
      "commit": "71ac392d8b5c23c45c66f30eff1c319580ada4da",
      "tree": "bb9044e63cd3186df5b1da7d38862fa463f9f4da",
      "parents": [
        "0a00c3ec2db7674483dece4863f105b18a966202"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:18 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:46 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: reset the driver state upon firmware recovery\n\nJust like we did in iwlmvm, we also need to clear the mld state when the\nfirmware was killed because of the device being powered off during\nsuspend.\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.ff1c9e05e0a9.I8df8d4a0384065fd2a32cf258339be77084c55bd@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "0a00c3ec2db7674483dece4863f105b18a966202",
      "tree": "2dd6c84da03aa826b3bbdfbda22b3e033122a7f3",
      "parents": [
        "a51cc8131214870af92abbceab64877b27e690c2"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:17 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:46 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: cleanup the driver state after device_powered_off\n\nIf the device was powered off during suspend, we need to reload the\nfirmware in resume which also means that we need to reconfigure it.\n\nIt could be tempting to just set IWL_MVM_STATUS_HW_RESTART_REQUESTED\nbut that would leave IWL_MVM_STATUS_IN_HW_RESTART set forever since that\nrecovery is not managed by mac80211.\n\nJust call iwl_mvm_restart_cleanup() from device_powered_off().\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.dc33533ac962.I6d7cca9c4e5643a477eae1d0a4f5fc83a10d0ee7@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "a51cc8131214870af92abbceab64877b27e690c2",
      "tree": "919d30903c939c937a1e2128338d5e17274c73a5",
      "parents": [
        "974cbad4c86d6442d9e08710322b924e4ae79023"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:16 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:45 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: reset the smart fifo state upon FW stop\n\nThe smart fifo is a feature in the firmware configured by the driver.\nThe driver keeps a state to remember what was the last configuration\nsent to the firmware. Obviously, if the firmware stops, we need to\nreconfigure the smart fifo. Since we didn\u0027t reset that state upon\nfirmware stop, we thought the firmware is already properly\nconfigured and we didn\u0027t send the smart fifo configuration command\nas part of the init sequence.\n\nReset the smart fifo state in iwl_mvm_stop_device() so that we\nwill properly send the command during the init that will come\nlater.\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.7d3c5efe2d1a.I16b23c328a677257257f695fa6f439e41fbcd081@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "974cbad4c86d6442d9e08710322b924e4ae79023",
      "tree": "ba67dde2569a7b3c633521b37a041a5d01b74cfa",
      "parents": [
        "678148622fa8e5a118784fa3fcb9bd1876b8322a"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Tue Jul 14 17:02:15 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:45 2026 +0300"
      },
      "message": "wifi: iwlwifi: regulatory: add LARI_CONFIG_CHANGE command v14 support\n\nAdd support for LARI_CONFIG_CHANGE version 14 and populate\nthe newly added BIOS-related fields in the command payload.\n\nExtend the version 14 command layout with UHB extension, puncturing and\nWBEM metadata fields, update command-size handling for version negotiation,\nand wire the new data into the LARI configuration flow. Track WBEM and\npuncturing source/revision in fw runtime, set them when loading ACPI or\nUEFI tables, and pass the headers to firmware. Update send conditions,\ndebug traces, and related documentation/comments to match the new format.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.c73d2fbebbfe.I93af7c456f04ef10d03646a43aaeb1858ecdc36d@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "678148622fa8e5a118784fa3fcb9bd1876b8322a",
      "tree": "3f8e148adbf37ac88d839b48f60396506eb745dd",
      "parents": [
        "5826799a26fd1c7dd954f6386a49e9fad747f21f"
      ],
      "author": {
        "name": "Pagadala Yesu Anjaneyulu",
        "email": "pagadala.yesu.anjaneyulu@intel.com",
        "time": "Tue Jul 14 17:02:14 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:45 2026 +0300"
      },
      "message": "wifi: iwlwifi: ignore raw-DSM TLV for LARI cmd version 13 and above\n\nLARI_CONFIG_CHANGE command version 13 and above accepts raw DSM\nvalues by default in firmware, so FW_ACCEPTS_RAW_DSM_TABLE should\nnot gate DSM bitmap handling for these versions.\n\nSet has_raw_dsm_capa based on command version (version 13 and above\nis true) with TLV fallback for older command versions. Also update TLV\nkernel-doc to mark this capability obsolete for LARI command\nversion 13 and above.\n\nSigned-off-by: Pagadala Yesu Anjaneyulu \u003cpagadala.yesu.anjaneyulu@intel.com\u003e\nReviewed-by: Avinash Bhatt \u003cavinash.bhatt@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.12c8b407e115.I6809041f1eb52b7fafe9172ca3e47323d43cc30a@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "5826799a26fd1c7dd954f6386a49e9fad747f21f",
      "tree": "7747008ab06d014c6d4524664ec00625d02b90d5",
      "parents": [
        "4e777dcdfe70d9b3ddf38cb49de9e30306889b18"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:13 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:45 2026 +0300"
      },
      "message": "wifi: iwlwifi: pcie: validate txq_id in txq_enable\n\nAvoid indexing txq arrays and queue-used bitmaps with an\ninvalid queue ID by adding an early bounds check in\niwl_trans_pcie_txq_enable().\n\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.273be072f5ff.I0d6c36a4c06bdbb4655164c7792da32b6143731e@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "4e777dcdfe70d9b3ddf38cb49de9e30306889b18",
      "tree": "83e0068403f80d23183e9b077e7c9756effb0456",
      "parents": [
        "c99bc4d4e0ba6f4661b2b914c96a597d26e7cc05"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:12 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:44 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: validate D3_END notif size\n\nCheck D3_END_NOTIFICATION payload length before reading notif-\u003eflags.\nOn short payloads, mark notif handling as failed.\nAvoid out-of-bounds reads from malformed notifications.\n\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.db2df8b6b6bb.I6163bbdf433379bf1dbf9eb46fb9562892217bd7@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "c99bc4d4e0ba6f4661b2b914c96a597d26e7cc05",
      "tree": "dccd8cf924b904c6545b1d984e56b671ff6e3ef1",
      "parents": [
        "21b3263b90e8006d488894e8a71c8debf45f6b88"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 17:02:11 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:44 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: cancel wiphy work before freeing wiphy\n\nWhen we fail to load the fw during op-mode start, we purge the list\nof the async handlers but we don\u0027t cancel the work.\nSame when we stop the op-mode.\n\nBefore freeing wiphy, we need to cancel/flush any pending wiphy work,\notherwise the work will fire with a freed memory.\ncfg80211 will do it anyway, but it will warn.\n\nCancel the work in those cases.\n\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.07aa49f755a2.I734a27b1b0eeb5b0e821aee3318fee8dc0a6bc03@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "21b3263b90e8006d488894e8a71c8debf45f6b88",
      "tree": "425185eba8ad684fba676918c7ac4239e98a7585",
      "parents": [
        "68f7d05494403ce89eba2b5476b2cd9ac03041db"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:10 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:44 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: validate monitor notif link_id\n\nMONITOR_NOTIF link_id is firmware-provided. Validate link_id range\nwith IWL_FW_CHECK before vif lookup. Payload length is already\nchecked by RX_HANDLER.\nUse iwl_mvm_rcu_dereference_vif_id which does all we need which allows\nus to drop iwl_mvm_get_vif_by_macid.\n\nAssisted-by: GitHubCopilot:gpt-5.3-codex\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.7601d05649a4.I237f58a007af761468057c9c09039953a3bb37da@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "68f7d05494403ce89eba2b5476b2cd9ac03041db",
      "tree": "42c3804f65a51d3704d4db7fcf3cd576fc48a5d7",
      "parents": [
        "9119aeeddc210cdfce0537de3ea3bab9316b2589"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:09 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:43 2026 +0300"
      },
      "message": "wifi: iwlwifi: mld: treat valid BAID without STA as a FW error\n\nSomehow, the firmware sometimes seems to have a valid BAID even if the\nieee80211_sta was not found. This happens in sniffer mode.\nTreat those as a firmware error.\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.4902f73de145.I2cec7133f2a2ec8c39dcfb36938aba2ea3d6be24@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "9119aeeddc210cdfce0537de3ea3bab9316b2589",
      "tree": "196bc5d9d830dd7142e0185384180b5816f66b9e",
      "parents": [
        "3bff0d12c36247073fca976498b58a940fca72dc"
      ],
      "author": {
        "name": "Emmanuel Grumbach",
        "email": "emmanuel.grumbach@intel.com",
        "time": "Tue Jul 14 17:02:08 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:43 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: fix the FCS truncation logic in d3\n\nFix a harmless mistake in the wake packet management code in the d3\nwakeup flow. If the FCS is truncated, we want to detect it, but we\ncleared the icvlen before updating the truncated variable that holds the\nnumber of bytes having been truncated.\nFix that.\n\nSigned-off-by: Emmanuel Grumbach \u003cemmanuel.grumbach@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.a7d094168ed3.I1a4d13f276c7e75514ab2032ae387873337470b8@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "3bff0d12c36247073fca976498b58a940fca72dc",
      "tree": "44d7df1bcebf2e5652850bf97d67c193054378b3",
      "parents": [
        "6800559a1042bfef9985b400f9dd971650d122f4"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 17:02:07 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:43 2026 +0300"
      },
      "message": "wifi: iwlwifi: support TTL platform device ID\n\nAdd support for a new device ID that we will have on TTL (sc2).\n\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.46183446954f.Icc260831e530c1c92c9be615a7077768b1b9ae30@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "6800559a1042bfef9985b400f9dd971650d122f4",
      "tree": "34014f76ca3bc3f1b3422cc2e7eaa4949a2aecfd",
      "parents": [
        "1e749bd58e556f69a0251cfc8cd110b986f641f0"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Tue Jul 14 17:02:06 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:42 2026 +0300"
      },
      "message": "wifi: iwlwifi: claim UHR DBE capability for UHR devices\n\nWhen an Intel device supports UHR it also supports DBE\n(dynamic bandwidth extension) since that\u0027s handled in\nmac80211. Claim support for it for client mode.\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.435828046f11.I538b2d90a4c282118ca2e56292cf5615d477a44c@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "1e749bd58e556f69a0251cfc8cd110b986f641f0",
      "tree": "28ea79998251a5cae8db51e4217ad34558ad64c5",
      "parents": [
        "478cad8bba59e8ee0e08d49edabf14bf1fbde5e4"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes@sipsolutions.net",
        "time": "Tue Jul 14 17:02:05 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:42 2026 +0300"
      },
      "message": "wifi: iwlwifi: mvm: remove iwl_mvm_recalc_tcm()\n\nThis function is only called in the worker, so it doesn\u0027t\nneed to exist at all, simply move the code there.\n\nSigned-off-by: Johannes Berg \u003cjohannes@sipsolutions.net\u003e\nLink: https://patch.msgid.link/20260714165826.dd9f49714128.I65fbe6890d67ec424d333c362aa7041a117aed44@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "478cad8bba59e8ee0e08d49edabf14bf1fbde5e4",
      "tree": "f78846afdb320dececb52f1b04b44890b8d0f88c",
      "parents": [
        "f051995c539582b05276abda4c5874fd4cafd2a5"
      ],
      "author": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 17:02:04 2026 +0300"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:52:42 2026 +0300"
      },
      "message": "wifi: iwlwifi: add a compile time check for too long hcmds\n\nA host command that is bigger than the allowed payload length should be\nsent with the NOCOPY flag. If it is sent without, we will get a warning.\n\nWe do know at compile time what is the maximum size of a hcmd payload that\nthe transport supports, so in order to catch bugs early,\nadd a compile time check to iwl_*_send_cmd_pdu to catch that.\n\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nLink: https://patch.msgid.link/20260714165826.a549b9499e3e.Id1a95bbbf92b5862862becaf57419bb9fe1385e5@changeid\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "f051995c539582b05276abda4c5874fd4cafd2a5",
      "tree": "12b6f3fc9c87c4f34ed32618657e6edde1a9d97b",
      "parents": [
        "7410e4548a17bd868dfc60b48f2e78eacde3ad78"
      ],
      "author": {
        "name": "Pengpeng Hou",
        "email": "pengpeng@iscas.ac.cn",
        "time": "Wed Jul 15 21:57:50 2026 +0800"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:51:44 2026 +0300"
      },
      "message": "wifi: iwlwifi: validate UEFI reduced-power SKU TLV length\n\niwl_uefi_reduce_power_parse() reads an iwl_sku_id from an\nIWL_UCODE_TLV_PNVM_SKU payload after only checking that the generic TLV\npayload is present.\n\nA short type-specific payload can therefore make the three data[] reads\nextend beyond the TLV. Reject SKU TLVs shorter than the structure before\naccessing it.\n\nSigned-off-by: Pengpeng Hou \u003cpengpeng@iscas.ac.cn\u003e\nLink: https://patch.msgid.link/20260715135916.24417-2-pengpeng@iscas.ac.cn\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "7410e4548a17bd868dfc60b48f2e78eacde3ad78",
      "tree": "6873b7ac6db00589cdd723d3cea44c7f6c103e6d",
      "parents": [
        "94280e6e0c69a5327e377803732f494d8b5a74cd"
      ],
      "author": {
        "name": "Pengpeng Hou",
        "email": "pengpeng@iscas.ac.cn",
        "time": "Wed Jul 15 21:57:50 2026 +0800"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Wed Jul 15 20:51:28 2026 +0300"
      },
      "message": "wifi: iwlwifi: validate PNVM SKU TLV length\n\niwl_pnvm_parse() reads an iwl_sku_id from an\nIWL_UCODE_TLV_PNVM_SKU payload after only checking that the generic TLV\npayload is present.\n\nA short type-specific payload can therefore make the three data[] reads\nextend beyond the TLV. Reject SKU TLVs shorter than the structure before\naccessing it.\n\nSigned-off-by: Pengpeng Hou \u003cpengpeng@iscas.ac.cn\u003e\nLink: https://patch.msgid.link/20260715135916.24417-1-pengpeng@iscas.ac.cn\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "94280e6e0c69a5327e377803732f494d8b5a74cd",
      "tree": "8ca876a8b2aa73b474263c3626dcb6d6fd94eb07",
      "parents": [
        "67105abd6195a685a84dcb8a5daf54a1f4bfdb60"
      ],
      "author": {
        "name": "Haoxiang Li",
        "email": "lihaoxiang@isrc.iscas.ac.cn",
        "time": "Wed Apr 01 11:05:55 2026 +0800"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 21:29:29 2026 +0300"
      },
      "message": "iwlwifi: dvm: add missing cleaup for on error path\n\nIn iwlagn_tx_agg_start(), call iwlagn_dealloc_agg_txq()\nto clear bit on error path.\n\nSigned-off-by: Haoxiang Li \u003clihaoxiang@isrc.iscas.ac.cn\u003e\nLink: https://patch.msgid.link/20260401030555.541685-1-lihaoxiang@isrc.iscas.ac.cn\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "67105abd6195a685a84dcb8a5daf54a1f4bfdb60",
      "tree": "a70eda99cbd38db71f961dd85a52067df88725bc",
      "parents": [
        "d6061f5f1318a0fc116fa442bea299095d211ad4"
      ],
      "author": {
        "name": "Dawei Feng",
        "email": "dawei.feng@seu.edu.cn",
        "time": "Wed Jun 24 16:44:04 2026 +0800"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 21:13:13 2026 +0300"
      },
      "message": "wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()\n\nIn iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses\nthe out_free_eeprom_blob label. Consequently, error paths triggered after\nsuccessfully parsing the EEPROM free priv-\u003envm_data but leak\npriv-\u003eeeprom_blob.\n\nFix this memory leak by reordering the error handling labels so\nthat out_free_eeprom falls through to out_free_eeprom_blob.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc6.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\nsupported Intel DVM wireless hardware and firmware to test with, no\nruntime testing was able to be performed.\n\nCc: stable@vger.kernel.org\nSigned-off-by: Dawei Feng \u003cdawei.feng@seu.edu.cn\u003e\nLink: https://patch.msgid.link/20260624084404.570703-1-dawei.feng@seu.edu.cn\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "d6061f5f1318a0fc116fa442bea299095d211ad4",
      "tree": "fecfee66e9618d1f36b7f03782051363fafe79b8",
      "parents": [
        "0ba1b366185b770440bf4eee3c4a929bc3cfc0e9"
      ],
      "author": {
        "name": "Praveen Rajendran",
        "email": "praveenrajendran2009@gmail.com",
        "time": "Fri Jul 03 19:37:57 2026 +0530"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 21:04:12 2026 +0300"
      },
      "message": "wifi: iwlwifi: fw: Fix spelling typo in error-dump.h\n\nCorrect a minor grammatical error inside the kernel-doc comments\nof error-dump.h where \"configuration\" was misspelled as \"configuraiton\".\n\nSigned-off-by: Praveen Rajendran \u003cpraveenrajendran2009@gmail.com\u003e\nLink: https://patch.msgid.link/20260703140757.3372-1-praveenrajendran2009@gmail.com\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "0ba1b366185b770440bf4eee3c4a929bc3cfc0e9",
      "tree": "6bef52ac06a4164d348f7d9c28155531257cf08d",
      "parents": [
        "ac798f757d6475dc6fee2ec899980d6740714596"
      ],
      "author": {
        "name": "Ben Greear",
        "email": "greearb@candelatech.com",
        "time": "Sat Feb 14 11:05:09 2026 -0800"
      },
      "committer": {
        "name": "Miri Korenblit",
        "email": "miriam.rachel.korenblit@intel.com",
        "time": "Tue Jul 14 20:49:35 2026 +0300"
      },
      "message": "wifi: iwlwifi: Clean dangling pointer in tx path\n\nIf iwl_txq_gen2_build_tfd fails, we return -1, which will cause calling\ncode to dispose of the skb one way or another.  Remove any reference to\nthat skb from the txq entries so that nothing will try to access it\nlater.\n\nSigned-off-by: Ben Greear \u003cgreearb@candelatech.com\u003e\nLink: https://patch.msgid.link/20260214190509.2098565-1-greearb@candelatech.com\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\n"
    },
    {
      "commit": "ac798f757d6475dc6fee2ec899980d6740714596",
      "tree": "d87fb20b7704d165c83234e518f966b46d8b5ca6",
      "parents": [
        "158438cd6ad69d6dd7d871582c38baf22169fede"
      ],
      "author": {
        "name": "Ilan Peer",
        "email": "ilan.peer@intel.com",
        "time": "Mon Jul 06 22:29:31 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Tue Jul 07 10:16:31 2026 +0200"
      },
      "message": "wifi: mac80211: Route (Re)association req/response to per-STA queue\n\nAn association request or response frame is generally delivered to the\ndriver without a TX queue object. However, with drivers that do encryption\noffload and couple the key with a transmit queue, this means that the\nframes are not being encrypted.\n\nFix this by routing the association frames to the management TXQ.\nThis will allow the driver to set up the required resources before\ntransmitting the association frame, e.g., set up keys etc.\n\nSigned-off-by: Ilan Peer \u003cilan.peer@intel.com\u003e\nReviewed-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260706222925.febcc62f485c.Iff932880e4b98232cbf6ba405fbb90d650a85381@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "158438cd6ad69d6dd7d871582c38baf22169fede",
      "tree": "d25a7acb74eee5b49f7db2718cecd366fae2e8ad",
      "parents": [
        "cffd0d2ed5f2603ef147fc8b625ca84b4041f5bf"
      ],
      "author": {
        "name": "Cen Zhang",
        "email": "zzzccc427@gmail.com",
        "time": "Tue Jul 07 00:18:22 2026 +0800"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Tue Jul 07 10:16:20 2026 +0200"
      },
      "message": "wifi: mac80211_hwsim: avoid NULL skb in stop queue drain\n\nmac80211_hwsim_stop() drops any frames left in data-\u003epending. The loop\ncurrently checks skb_queue_empty() and then dequeues separately.\n\nThat split is racy with TX status handling, which can remove a pending\nframe under the queue lock. If the last entry is removed after the empty\ncheck, skb_dequeue() returns NULL and the stop path passes that NULL skb\nto ieee80211_free_txskb().\n\nUse skb_dequeue() as the loop condition instead. The dequeue result is the\nobject that stop owns and frees, and a concurrent status completion that\nempties the queue simply makes the loop terminate.\n\nFixes: bd18de517923 (\"mac80211_hwsim: drop pending frames on stop\")\nAssisted-by: Codex:gpt-5.5\nSigned-off-by: Cen Zhang \u003czzzccc427@gmail.com\u003e\nLink: https://patch.msgid.link/20260706161822.921039-1-zzzccc427@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "cffd0d2ed5f2603ef147fc8b625ca84b4041f5bf",
      "tree": "b8e0b48c04f23b9b9844e897baba0a57f86b4888",
      "parents": [
        "f9202a374ec34e767185cf44f44ed2fbdf6bf053"
      ],
      "author": {
        "name": "Cen Zhang",
        "email": "zzzccc427@gmail.com",
        "time": "Mon Jul 06 20:37:56 2026 +0800"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Tue Jul 07 10:16:11 2026 +0200"
      },
      "message": "wifi: mac80211_hwsim: clean up radio rhashtable on free\n\nmac80211_hwsim_free() removes each radio from hwsim_radios before calling\nmac80211_hwsim_del_radio(), but leaves the matching hwsim_radios_rht entry\nin place until the whole table is destroyed.\n\nOther radio removal paths remove both the list entry and data-\u003erht while\nholding hwsim_radio_lock, before dropping the lock and deleting the radio.\nDo the same here so the all-radio cleanup path follows the same object\nvisibility ordering.\n\nThis helper is used while all radios are being torn down, either after\ncallback users have already been unregistered or while module init is\nunwinding, so no hwsim_radios_generation update is needed.\n\nAssisted-by: Codex:gpt-5.5\nSigned-off-by: Cen Zhang \u003czzzccc427@gmail.com\u003e\nLink: https://patch.msgid.link/20260706123756.343818-1-zzzccc427@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "f9202a374ec34e767185cf44f44ed2fbdf6bf053",
      "tree": "aaae8854a1e1666f1d7f8f5674d83b51c625a7ad",
      "parents": [
        "dd21d1844aa096216e1be551d1ae5e57c27c837c"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:35 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 16:51:45 2026 +0200"
      },
      "message": "wifi: cfg80211: support MAC address filtering in station dump for link stats\n\nCurrently, when userspace requests station information with\nlink statistics using NL80211_CMD_GET_STATION with the\nNL80211_ATTR_STA_DUMP_LINK_STATS flag, the kernel uses the .doit callback\n(nl80211_get_station) which sends a single netlink message. For MLO\nstations with multiple links, the link statistics can be large and may\nexceed the maximum netlink message size, causing the operation to fail\nwith -EMSGSIZE.\n\nThe .dumpit callback (nl80211_dump_station) already supports\nfragmentation across multiple netlink messages, making it suitable\nfor handling large link statistics. However, it currently iterates over\nall stations on the interface, which is inefficient when userspace only\nwants information about a specific station.\n\nAdd support for MAC address filtering in nl80211_dump_station to allow\nuserspace to request fragmented link statistics for a specific station.\nWhen NL80211_ATTR_MAC is present in a dump request, cache the MAC address\nin the dump context and use rdev_get_station() to retrieve information for\nonly that station, instead of iterating over all stations with\nrdev_dump_station().\n\nThis allows userspace tools (like iw) to use NL80211_CMD_GET_STATION with\nNLM_F_DUMP flag to retrieve complete link statistics for a specific\nstation across multiple netlink messages, avoiding the message size\nlimitation.\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-6-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "dd21d1844aa096216e1be551d1ae5e57c27c837c",
      "tree": "e25181df3e173172f9a9aa0a6ab82382bbc17e4c",
      "parents": [
        "727afb05ef6322c5a430d971301adad90eb040b0"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:34 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 16:51:44 2026 +0200"
      },
      "message": "wifi: cfg80211: Fragment per-link station stats in nl80211_dump_station()\n\nIn MLO scenarios, stations may have multiple links, each with distinct\nstatistics. When userspace tools like iw or hostapd request station dumps,\nattempting to pack all per-link stats into a single netlink message can\neasily exceed the default 4KB buffer limit, especially when more than two\nlinks are active. This results in -EMSGSIZE errors and incomplete data\ndelivery.\n\nTo address this, fragment per-link station statistics across multiple\nnetlink messages to ensure reliable delivery of complete MLO station\ninformation. Extend the stateful context with a two-phase dump mechanism:\nphase 0 (AGGREGATED) sends combined MLO-level statistics and phase 1\n(PER_LINK) sends individual per-link statistics for each active link.\n\nThe dump loop is structured to produce exactly one netlink message per\niteration, with a common header (ifindex, wdev, mac, generation) built\nonce and phase-specific payload added via a switch statement. This keeps\nheader construction in one place and makes the EMSGSIZE bail-out uniform.\n\nAdd a new request flag attribute, NL80211_ATTR_STA_DUMP_LINK_STATS\n(NLA_FLAG), for NL80211_CMD_GET_STATION dump. Userspace can set this\nflag to request per-link station statistics for MLO stations.\n\nExtract this flag during the first dump invocation by passing an attrbuf\nto nl80211_prepare_wdev_dump(); use __free(kfree) to avoid scattered\nmanual kfree() calls. Cache the boolean in the dump context to avoid\nrepeated parsing on subsequent invocations.\n\nPer-link messages carry a single NL80211_ATTR_MLO_LINKS nest with the\nlink ID, link-specific MAC, and per-link NL80211_ATTR_STA_INFO payload.\nThe link-specific validity (is_valid_ether_addr) and null pointer guard\nare checked in nl80211_put_link_station_payload() before any message\nconstruction begins.\n\nAlso fix all nla_nest_start_noflag() calls in nl80211_fill_link_station()\nfor nested attribute types (STA_INFO, BSS_PARAM, TID_STATS, per-tid) to\nuse nla_nest_start() so the NLA_F_NESTED flag is set correctly.\n\nPropagate the actual return value from nl80211_put_sta_info_common() in\nthe AGGREGATED phase rather than returning skb-\u003elen. Returning skb-\u003elen\nsignals netlink to re-invoke the dump with the same sta_idx, causing an\ninfinite loop when the aggregated payload is too large to fit; returning\nthe real error code (-EMSGSIZE or otherwise) terminates the dump cleanly.\n\nBackward compatibility is seamlessly preserved for non-MLO stations.\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-5-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "727afb05ef6322c5a430d971301adad90eb040b0",
      "tree": "716aed401d0dfd2e192fe32bbc3d2ce9761a552f",
      "parents": [
        "4b40378ac20384e58b9b6f2c4b800966ec14c137"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:33 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 16:51:44 2026 +0200"
      },
      "message": "wifi: cfg80211: Refactor nl80211_dump_station() to prepare for per-link stats\n\nCurrently, nl80211_dump_station() relies on the netlink callback\u0027s generic\nargs array (cb-\u003eargs[2]) to track the station index during dumps. It also\nprocesses the entire sinfo structure and transmits it to userspace\nimmediately in a single pass.\n\nThis approach creates a bottleneck for MLO. When an MLD station has\nmultiple active links, the aggregated station information, combined\nwith the individual per-link statistics, can easily exceed the\nmaximum netlink message size limits. The current monolithic dump\niteration cannot pause and resume mid-station to fragment these large\nper-link statistics across multiple netlink messages.\n\nIntroduce a stateful context structure (struct nl80211_dump_station_ctx)\nallocated during the dump to track the iteration state. Store the context\npointer directly at cb-\u003eargs[2], following the same pattern as\nnl80211_dump_wiphy which stores its state pointer at cb-\u003eargs[0].\n\nMove the station index (sta_idx) tracking and the sinfo payload into this\ncontext. The per-station netlink message is built inline in the loop:\ncommon header attributes are assembled directly, then\nnl80211_put_sta_info_common() adds the STA_INFO payload.\n\nFurthermore, move the NL80211_CMD_GET_STATION command definition from\ngenl_small_ops to genl_ops to natively support the .done callback.\nImplement nl80211_dump_station_done() to ensure the newly allocated state\ncontext and its deeply allocated sinfo payload are safely freed when the\ndump concludes or is aborted prematurely by userspace.\n\nNote that the previous dump path used nl80211_send_station(), which\nincluded NL80211_ATTR_IE and NL80211_ATTR_RESP_IE. These attributes are\nnot carried forward in this implementation. As documented, association\nresponse IEs (assoc_resp_ies) are only relevant at station creation time\n(e.g. via cfg80211_new_sta()) to notify userspace about association\ndetails, and are not expected to be part of get_station()/dump_station()\ncallbacks. Aligning with this expectation, these IEs are intentionally\nomitted here.\n\nThis refactoring maintains the existing netlink batching performance while\nlaying the stateful foundation required for per-link statistics\nfragmentation in subsequent patches.\n\nAt out_err_release, cfg80211_sinfo_release_content() frees any\ndynamically allocated sub-fields inside ctx-\u003esinfo (including per-link\npointers in sinfo.links[]). Without the subsequent memset, those\npointers remain non-NULL in the embedded sinfo. When the dump concludes\nor is aborted, nl80211_dump_station_done() calls\ncfg80211_sinfo_release_content() a second time on the same ctx-\u003esinfo,\nwhich would free the already-released link memory. The\nmemset(\u0026ctx-\u003esinfo, 0, sizeof(ctx-\u003esinfo)) zeroes all pointers so the\nsecond release call hits kfree(NULL), which is a harmless no-op.\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-4-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "4b40378ac20384e58b9b6f2c4b800966ec14c137",
      "tree": "e9a1367c1d443dad571ef0c18614545eb188eda8",
      "parents": [
        "5c660b243435d74d17a6721cd90e9d188b231cc8"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:32 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 16:51:44 2026 +0200"
      },
      "message": "wifi: cfg80211: Add helper to pack station-level STA_INFO\n\nAdd a helper function nl80211_put_sta_info_common() to pack the\nstation-level (aggregated) STA information into a netlink message.\nThis prepares the code for future enhancements such as supporting\nfragmented link statistics in nl80211_dump_station.\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-3-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "5c660b243435d74d17a6721cd90e9d188b231cc8",
      "tree": "3be19ff40cae0a9028ad1c58c43e4b3515150c9f",
      "parents": [
        "ddd23927462f34d4a32e4fab086637d400e2b777"
      ],
      "author": {
        "name": "P Praneesh",
        "email": "praneesh.p@oss.qualcomm.com",
        "time": "Sun Jun 14 10:47:31 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 16:51:44 2026 +0200"
      },
      "message": "wifi: cfg80211: Drop unused link stats handling in nl80211_send_station()\n\nRemove the link level statistics handling from\nnl80211_send_station() and drop the unused link_stats parameter\nfrom its signature and callers. The removed code iterated over\neach MLO link and attempted to send link specific station data\nthrough NL80211_ATTR_MLO_LINKS, but this logic was never used\nbecause link_stats was always false.\n\nThis logic was introduced during early work on link level station\nstatistics with the intention of reporting information for each\nlink. Due to message size concerns when a station has multiple\nlinks, the feature was disabled behind the link_stats flag and\nremained unused.\n\nThe link level reporting block in nl80211_send_station() is dead\ncode and cannot support larger messages, so remove it. This\ncleanup also prepares for proper link level statistics reporting\nin nl80211_dump_station() in a later patch, where fragmentation\nallows safe transmission of multi link data.\n\nAlso fix label indentation: the nla_put_failure label had an\nerroneous leading space.\n\nSigned-off-by: P Praneesh \u003cpraneesh.p@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260614051739.3979947-2-praneesh.p@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "ddd23927462f34d4a32e4fab086637d400e2b777",
      "tree": "156cd6adacf37ac0fef121fff2a2ffc5d9173367",
      "parents": [
        "72cdb89a4349daf94b1360abff1b27dc42e33380"
      ],
      "author": {
        "name": "Anas Khan",
        "email": "anxkhn28@gmail.com",
        "time": "Thu Jul 02 15:53:25 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:59:05 2026 +0200"
      },
      "message": "wifi: p54: update stale wireless wiki URLs\n\nThe p54 wireless wiki links (wireless.wiki.kernel.org) return 404; the\ncontent moved to the Sphinx documentation site. Point them at the\ncurrent wireless.docs.kernel.org pages.\n\nSigned-off-by: Anas Khan \u003canxkhn28@gmail.com\u003e\nAcked-by: Christian Lamparter \u003cchunkeey@gmail.com\u003e\nLink: https://patch.msgid.link/20260702102325.63955-1-anxkhn28@gmail.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "72cdb89a4349daf94b1360abff1b27dc42e33380",
      "tree": "2cca4753f5bc095794e015c9851b6e33b0c029b3",
      "parents": [
        "93e60f96b76fa9108bfc47ee420a6db6f36f19a2"
      ],
      "author": {
        "name": "Mike Rapoport (Microsoft)",
        "email": "rppt@kernel.org",
        "time": "Wed Jul 01 16:59:13 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:58:21 2026 +0200"
      },
      "message": "wifi: wlcore: allocate aggregation and firmware log buffers with kzalloc()\n\nwlcore_alloc_hw() uses __get_free_pages() to  allocate TX aggregation\nand firmware log buffers used for software data staging.\n\nThese buffer can be allocated with kmalloc() as there\u0027s nothing special\nabout them to go directly to the page allocator.\n\nkmalloc() provides a better API that does not require ugly casts and\nkfree() does not need to know the size of the freed object.\n\nPerformance difference between kmalloc() and __get_free_pages() is not\nmeasurable as both allocators take an object/page from a per-CPU list for\nfast path allocations.\n\nFor the slow path the performance is anyway determined by the amount of\nreclaim involved rather than by what allocator is used.\n\nReplace use of __get_free_pages() with kzalloc() and free_pages() with\nkfree().\n\nLink: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com\nSigned-off-by: Mike Rapoport (Microsoft) \u003crppt@kernel.org\u003e\nLink: https://patch.msgid.link/20260701-b4-drivers-wireless-v1-4-60264cdf2efe@kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "93e60f96b76fa9108bfc47ee420a6db6f36f19a2",
      "tree": "d9b5eaaaa0668293df679d265382faf78f252813",
      "parents": [
        "535fd0a64f94f4a6d93e2fd1daf829663eb17e06"
      ],
      "author": {
        "name": "Mike Rapoport (Microsoft)",
        "email": "rppt@kernel.org",
        "time": "Wed Jul 01 16:59:12 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:58:19 2026 +0200"
      },
      "message": "wifi: mwifiex: debugfs: use kzalloc() to allocate formatting buffers\n\nmwifiex debugfs functions allocate buffers for formatting debug output\ntext using get_zeroed_page().\n\nThese buffers can be allocated with kmalloc() as there\u0027s nothing special\nabout them to go directly to the page allocator.\n\nkmalloc() provides a better API that does not require ugly casts and\nkfree() does not need to know the size of the freed object.\n\nPerformance difference between kmalloc() and __get_free_pages() is not\nmeasurable as both allocators take an object/page from a per-CPU list for\nfast path allocations.\n\nFor the slow path the performance is anyway determined by the amount of\nreclaim involved rather than by what allocator is used.\n\nReplace use of get_zeroed_page() with kzalloc() and free_page() with\nkfree().\n\nLink: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com\nSigned-off-by: Mike Rapoport (Microsoft) \u003crppt@kernel.org\u003e\nReviewed-by: Francesco Dolcini \u003cfrancesco.dolcini@toradex.com\u003e\nLink: https://patch.msgid.link/20260701-b4-drivers-wireless-v1-3-60264cdf2efe@kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "535fd0a64f94f4a6d93e2fd1daf829663eb17e06",
      "tree": "d517622470715ba805b55e818a4a4d867c48c1ac",
      "parents": [
        "1cb971bb9741d2358fc422f6603b68dfaf424335"
      ],
      "author": {
        "name": "Mike Rapoport (Microsoft)",
        "email": "rppt@kernel.org",
        "time": "Wed Jul 01 16:59:11 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:58:16 2026 +0200"
      },
      "message": "wifi: libertas: debugfs: use kzalloc() to allocate formatting buffers\n\nlibertas debugfs functions allocate buffers for formatting debug\noutput text using get_zeroed_page().\n\nThese buffers can be allocated with kmalloc() as there\u0027s nothing special\nabout them to go directly to the page allocator.\n\nkmalloc() provides a better API that does not require ugly casts and\nkfree() does not need to know the size of the freed object.\n\nPerformance difference between kmalloc() and __get_free_pages() is not\nmeasurable as both allocators take an object/page from a per-CPU list for\nfast path allocations.\n\nFor the slow path the performance is anyway determined by the amount of\nreclaim involved rather than by what allocator is used.\n\nReplace use of get_zeroed_page() with kzalloc() and free_page() with\nkfree().\n\nLink: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com\nSigned-off-by: Mike Rapoport (Microsoft) \u003crppt@kernel.org\u003e\nLink: https://patch.msgid.link/20260701-b4-drivers-wireless-v1-2-60264cdf2efe@kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "1cb971bb9741d2358fc422f6603b68dfaf424335",
      "tree": "a3ec767bf1888bf6263161849af92edf5e09f0ad",
      "parents": [
        "cc61825060b01077da2b9796dc1047ec383e53c0"
      ],
      "author": {
        "name": "Mike Rapoport (Microsoft)",
        "email": "rppt@kernel.org",
        "time": "Wed Jul 01 16:59:10 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:58:07 2026 +0200"
      },
      "message": "wifi: b43, b43legacy: debugfs: use kzalloc() to allocate formatting buffers\n\nb43* debugfs functions allocate 16 KiB buffers for formatting debug output\ntext using __get_free_pages().\n\nkzalloc() provides a better API that does not require ugly casts and\nkfree() does not need to know the size of the freed object and for 16 Kib\nallocation kzalloc() will anyway delegate it to buddy.\n\nReplace use of __get_free_pages() with kzalloc().\n\nLink: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com\nSigned-off-by: Mike Rapoport (Microsoft) \u003crppt@kernel.org\u003e\nLink: https://patch.msgid.link/20260701-b4-drivers-wireless-v1-1-60264cdf2efe@kernel.org\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "cc61825060b01077da2b9796dc1047ec383e53c0",
      "tree": "be322794991f4d5f228e4e9cac284f9dedef0296",
      "parents": [
        "1c29c67bc7a9962e2ef91e8c65b7fc4fa227eded"
      ],
      "author": {
        "name": "Lachlan Hodges",
        "email": "lachlan.hodges@morsemicro.com",
        "time": "Fri Jun 26 16:28:58 2026 +1000"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:56:34 2026 +0200"
      },
      "message": "wifi: ieee80211: introduce generic KHZ_TO_HZ helper\n\nUseful for S1G drivers due to the increased required granularity,\nbut may be useful for others so include it as a generic helper.\n\nSigned-off-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260626063014.1275235-3-lachlan.hodges@morsemicro.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "1c29c67bc7a9962e2ef91e8c65b7fc4fa227eded",
      "tree": "fef7c71f75ccc8b01b2ab9acb9a6806e2c7dc6e0",
      "parents": [
        "5e20d72350df589478691310f0e1c427f35ee4aa"
      ],
      "author": {
        "name": "Lachlan Hodges",
        "email": "lachlan.hodges@morsemicro.com",
        "time": "Fri Jun 26 16:28:57 2026 +1000"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:56:07 2026 +0200"
      },
      "message": "wifi: cfg80211: introduce helper to get S1G primary width\n\nThis is needed for drivers and will be needed for mac80211/cfg80211\nin the future so introduce a generic accessor to retrieve the\nchandefs S1G primary channel width.\n\nSigned-off-by: Lachlan Hodges \u003clachlan.hodges@morsemicro.com\u003e\nLink: https://patch.msgid.link/20260626063014.1275235-2-lachlan.hodges@morsemicro.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "5e20d72350df589478691310f0e1c427f35ee4aa",
      "tree": "1957f18d52904ea0309928638a13ee7f8fbf8eb6",
      "parents": [
        "84442442e04be58a8977fb10debcbbfc1649d962"
      ],
      "author": {
        "name": "Dhanavandhana Kannan",
        "email": "dhanavandhana.kannan@oss.qualcomm.com",
        "time": "Tue Jun 23 16:04:12 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:55:46 2026 +0200"
      },
      "message": "wifi: cfg80211: Avoid UNPROT_BEACON on AP interfaces\n\nCurrently, an AP may receive unprotected beacons from neighbouring\nBSSes, which cfg80211_rx_unprot_mlme_mgmt() forwards to userspace via\nNL80211_CMD_UNPROT_BEACON regardless of interface type.\n\nWhile the kernel rate-limits these events to once per 10 seconds per\nwdev, in multi-BSS scenarios each AP interface maintains its own\nrate-limit state, increasing the number of reported events.\nIn AP mode, hostapd has no handler for NL80211_CMD_UNPROT_BEACON and\nlogs an unhandled event message for each occurrence, leading to excessive\nlog noise and making it harder to identify real issues.\n\nSince an AP does not need to act on unprotected beacons from neighbouring\nBSSes, skip reporting this event when operating in AP mode.\n\nSigned-off-by: Dhanavandhana Kannan \u003cdhanavandhana.kannan@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260623103412.1578812-1-dhanavandhana.kannan@oss.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "84442442e04be58a8977fb10debcbbfc1649d962",
      "tree": "598e304ddf882cfa877cee87255fd24814874cb8",
      "parents": [
        "f83378e6ce497eda7e9a7490de4e1a46459febb2"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Fri Jun 19 14:21:07 2026 +0200"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:55:29 2026 +0200"
      },
      "message": "wifi: cfg80211: remove WIPHY_FLAG_DISABLE_WEXT\n\nThere are only two drivers left setting it, but they\u0027re\nboth also setting WIPHY_FLAG_SUPPORTS_MLO for the relevant\ndevices, so we can now remove WIPHY_FLAG_DISABLE_WEXT.\n\nLink: https://patch.msgid.link/20260619142107.150f1bbe3b83.I9ff3d419bad54313c76fa4c3485148c122e67fb3@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "f83378e6ce497eda7e9a7490de4e1a46459febb2",
      "tree": "4a4d1d37884cc34adc2ac09d0b2236f1fb0b6d4a",
      "parents": [
        "010e955c203e435d5bdba228fdc1556297d3d7ff"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jun 15 09:39:48 2026 +0200"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:55:20 2026 +0200"
      },
      "message": "wifi: nl80211: clarify NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA content\n\nThis is currently __le16, but really the whole content of the\ncorresponding 802.11 element, which is even extensible and\ncould, in theory, be increased in size. Clarify the docs.\n\nLink: https://patch.msgid.link/20260615093948.0f730833a6d5.I1c8c5c09dfe16b0b1dcb10d54fc030f6b1d4fc8c@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "010e955c203e435d5bdba228fdc1556297d3d7ff",
      "tree": "5b39f653be0889adb0f6bae3c5b21a7b318543d7",
      "parents": [
        "4ab9b637b94a3821acfcd6d6037dffe33669245a"
      ],
      "author": {
        "name": "Priyansha Tiwari",
        "email": "priyansha.tiwari@oss.qualcomm.com",
        "time": "Thu Jun 11 11:52:23 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:45:19 2026 +0200"
      },
      "message": "wifi: cfg80211/nl80211: add STA-mode peer probing\n\nAdd NL80211_EXT_FEATURE_PROBE_AP to allow drivers to advertise\nsupport for probing the associated AP from STA/P2P-client mode.\n\nExtend nl80211_probe_peer() to accept STA/P2P-client interfaces\nwhen the driver advertises NL80211_EXT_FEATURE_PROBE_AP; in that\ncase the MAC attribute must be omitted (the peer is implied by\nthe association).\n\nUpdate cfg80211_probe_status() to accept an optional peer address\nand a link_id parameter (-1 for non-MLO), and include\nNL80211_ATTR_MLO_LINK_ID in the event when link_id \u003e\u003d 0.\nUpdate all callers.\n\nSigned-off-by: Priyansha Tiwari \u003cpriyansha.tiwari@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260611062225.2144241-3-pritiwa@qti.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "4ab9b637b94a3821acfcd6d6037dffe33669245a",
      "tree": "ba2f62318476b55d7d074077aaf7ba59ecf73134",
      "parents": [
        "25bc29ba671d0496b599149a0823b5dbb5409f94"
      ],
      "author": {
        "name": "Priyansha Tiwari",
        "email": "priyansha.tiwari@oss.qualcomm.com",
        "time": "Thu Jun 11 11:52:22 2026 +0530"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:45:19 2026 +0200"
      },
      "message": "wifi: nl80211/cfg80211: rename probe_client to probe_peer\n\nRename NL80211_CMD_PROBE_CLIENT to NL80211_CMD_PROBE_PEER in the UAPI\nenum and retain NL80211_CMD_PROBE_CLIENT as a compatibility alias.\n\nRename the .probe_client cfg80211_ops callback to .probe_peer and\nupdate all in-tree users (wil6210, mwifiex) and mac80211 so the\ntree continues to build after this change.\n\nSigned-off-by: Priyansha Tiwari \u003cpriyansha.tiwari@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260611062225.2144241-2-pritiwa@qti.qualcomm.com\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "25bc29ba671d0496b599149a0823b5dbb5409f94",
      "tree": "29fab990d19f9744ce99de245531c1b0f0a58f81",
      "parents": [
        "2bb62a85aff6d4c14a62a476dfabaada3c1cc014"
      ],
      "author": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Sun Apr 12 15:26:09 2026 +0300"
      },
      "committer": {
        "name": "Johannes Berg",
        "email": "johannes.berg@intel.com",
        "time": "Mon Jul 06 12:41:44 2026 +0200"
      },
      "message": "wifi: radiotap: add definitions for the new UHR TLVs\n\nAdd the necessary definitions to create radiotap UHR TLVs\nfor UHR sniffers.\n\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\nSigned-off-by: Miri Korenblit \u003cmiriam.rachel.korenblit@intel.com\u003e\nLink: https://patch.msgid.link/20260412152605.73e682d0c8c3.I5a0c858467c852b7a2a00f580bd073af29c37705@changeid\nSigned-off-by: Johannes Berg \u003cjohannes.berg@intel.com\u003e\n"
    },
    {
      "commit": "2bb62a85aff6d4c14a62a476dfabaada3c1cc014",
      "tree": "89fe2bb7d5d671e24077d57a276c08c48561ab27",
      "parents": [
        "08bc5b2636afcbadc31bb17243eec094e048bd79",
        "87320be9f0d24fce67631b7eef919f0b79c3e45c"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Jul 03 07:42:04 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Jul 03 07:46:27 2026 +0200"
      },
      "message": "Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nCross-merge networking fixes after downstream PR (net-7.2-rc2).\n\nNo conflicts.\n\nAdjacent changes:\n\nMAINTAINERS:\n  56114690ff3c (\"MAINTAINERS: Update Marvell octeontx2 driver maintainers\")\n  eb56577ae9a5 (\"ehea: remove the ehea driver\")\n\nnet/core/netpoll.c:\n  45f1458a8501 (\"netpoll: fix a use-after-free on shutdown path\")\n  84c0ff1efb62 (\"netpoll: do not warn when the best-effort pool refill fails\")\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "87320be9f0d24fce67631b7eef919f0b79c3e45c",
      "tree": "acea3ad5a6bc1c5fd1a5fc8fd2a29184802c88d5",
      "parents": [
        "a9d4dd742466cab468a950441447c614a3920aad",
        "d8e8b85a85fe21954d303db68034aac4639df88d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 06:01:12 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 06:01:12 2026 -1000"
      },
      "message": "Merge tag \u0027net-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Paolo Abeni:\n \"Including fixes from netfilter and batman-adv.\n\n  Current release - new code bugs:\n\n   - netfilter: cthelper: cap to maximum number of expectation per master\n\n  Previous releases - regressions:\n\n   - netpoll: fix a use-after-free on shutdown path\n\n   - tcp: restore RCU grace period in tcp_ao_destroy_sock\n\n   - ipv6: fix NULL deref in fib6_walk_continiue() on multi-batch dump\n\n   - batman-adv: dat: ensure accessible eth_hdr proto field\n\n   - eth:\n      - virtio_net: disable cb when NAPI is busy-polled\n      - lan743x: Initialize eth_syslock spinlock before use\n\n  Previous releases - always broken:\n\n   - netfilter:\n      - nft_set_pipapo: don\u0027t leak bad clone into future transaction\n\n   - sched:\n      - sch_teql: Introduce slaves_lock to avoid race condition and UAF\n      - replace direct dequeue call with peek and qdisc_dequeue_peeked\n\n   - sctp: add INIT verification after cookie unpacking\n\n   - tipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\n   - seg6: validate SRH length before reading fixed fields\n\n   - eth:\n      - mlx5e: fix use-after-free of metadata_dst on RX SC delete\n      - enetc: check the number of BDs needed for xdp_frame\n      - fbnic: don\u0027t cache shinfo across skb realloc\"\n\n* tag \u0027net-7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (58 commits)\n  net/mlx5: HWS, fix matcher leak on resize target setup failure\n  net/sched: hhf: clear heavy-hitter state on reset\n  net/sched: dualpi2: clear stale classification on filter miss\n  net/sched: act_bpf: use rcu_dereference_bh() to read the filter\n  selftests: drv-net: tso: don\u0027t touch dangerous feature bits\n  cxgb4: Fix decode strings dump for T6 adapters\n  virtio_net: disable cb when NAPI is busy-polled\n  sctp: fix addr_wq_timer race in sctp_free_addr_wq()\n  selftests: net: bump default cmd() timeout to 20 seconds\n  bridge: stp: Fix a potential use-after-free when deleting a bridge\n  net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF\n  net: gianfar: dispose irq mappings on probe failure and device removal\n  net: lan743x: Initialize eth_syslock spinlock before use\n  net: libwx: fix VMDQ mask for 1-queue mode\n  net: airoha: fix max receive size configuration\n  fsl/fman: Free init resources on KeyGen failure in fman_init()\n  netfilter: nftables: restrict checkum update offset\n  netfilter: nftables: restrict linklayer and network header writes\n  netfilter: nfnetlink_queue: restrict writes to network header\n  netfilter: nft_fib: reject fib expression on the netdev egress hook\n  ...\n"
    },
    {
      "commit": "a9d4dd742466cab468a950441447c614a3920aad",
      "tree": "7636eb983dfd189e951ec8972be483b3d9b55f35",
      "parents": [
        "db78c0db411b111b438f00a1ba418e995b5bd246",
        "fe87b8dc67f1b2c64e76a66e78468c533d3c44ca"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:58:35 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:58:35 2026 -1000"
      },
      "message": "Merge tag \u0027hwmon-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging\n\nPull hwmon fixes from Guenter Roeck:\n\n - adm1275: Detect coefficient overflow, and prevent reading\n   uninitialized stack\n\n - aspeed-g6-pwm-tach: Guard fan RPM calculation against divide-by-zero\n\n - asus_atk0110: Check package count before accessing element\n\n - ltc4283: fix malformed table docs build error\n\n - occ: Unregister sysfs devices outside occ lock to avoid lockdep\n   warning\n\n - pmbus core: Fix passing events to regulator core, and honor\n   vrm_version in pmbus_data2reg_vid()\n\n - w83627hf: Remove VID sysfs files on error and remove\n\n - w83793: remove vrm sysfs file on probe failure\n\n - Various: Add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n\n* tag \u0027hwmon-for-v7.2-rc2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:\n  hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero\n  hwmon: (pmbus) Fix passing events to regulator core\n  hwmon: adm1275: Detect coefficient overflow\n  hwmon: adm1275: Prevent reading uninitialized stack\n  hwmon: (max6697) add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n  hwmon: (ltc2992) add missing \u0027select REGMAP_I2C\u0027 to Kconfig\n  hwmon: (max1619) add missing \u0027select REGMAP\u0027 to Kconfig\n  hwmon: (w83627hf) remove VID sysfs files on error and remove\n  hwmon: (w83793) remove vrm sysfs file on probe failure\n  hwmon: (asus_atk0110) Check package count before accessing element\n  docs: hwmon: ltc4283: fix malformed table docs build error\n  hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()\n  hwmon: (occ) unregister sysfs devices outside occ lock\n"
    },
    {
      "commit": "db78c0db411b111b438f00a1ba418e995b5bd246",
      "tree": "0595366a5ac26c2d8c8062f38adba58dc67435c2",
      "parents": [
        "4a50a141f05a8d1737661b19ee22ff8455b94409",
        "d5d2d7a8d8be18681a0864f58e3875f1c639e11c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:56:44 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jul 02 05:56:44 2026 -1000"
      },
      "message": "Merge tag \u0027mfd-fixes-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd\n\nPull MFD fix from Lee Jones:\n\n - Add MFD mailing list to MAINTAINERS\n\n* tag \u0027mfd-fixes-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd:\n  MAINTAINERS: Add a mailing list entry to MFD\n"
    },
    {
      "commit": "08bc5b2636afcbadc31bb17243eec094e048bd79",
      "tree": "bb4cc590cdae92d18a1df0b29bc1cad8f78c4ca0",
      "parents": [
        "140be217df577961bea1ca36240439a463026cbd",
        "961db18e28d0ab6a684292e0efc99ba24377d394"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 15:11:38 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 15:11:38 2026 +0200"
      },
      "message": "Merge branch \u0027octeontx2-af-npc-parser-and-rss-improvements\u0027\n\nKiran Kumar says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nocteontx2-af: NPC parser and RSS improvements\n\nThis series extends the Marvell OcteonTX2 admin-function driver with two\nimprovements to the NPC (Network Parser CAM) block. The NPC parses packets\nreceived by or transmitted from the NIX, and its matching CAM (MCAM)\nselects which VFs, queues, or output ports handle each packet.\n\nPatch 1 reserves a new range of PKINDs (46-53) to support configurable\nL2 skip-size parsing. Packets arriving with variable length L2 headers\nor a CPT (Cryptographic Accelerator Unit) pre-header can be steered\nto one of four skip-size PKINDs so the NPC advances past the right number\nof bytes before starting protocol classification. The mbox interface is\nextended with a skip_size field so PF/VF drivers can program the desired\nL2 offset at run time without rebuilding firmware.\n\nPatch 2 adds a NIX_FLOW_KEY_TYPE_ROCEV2 flow-key type so the RSS engine\ncan distribute RoCEv2 traffic across receive queues using the destination\nQueue Pair (QP) field. Without this, all RoCEv2 flows hash the same\nway and land on a single queue.\n\nBoth changes target the admin-function driver to improve overall hardware\nparsing infrastructure.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260630062145.2533816-1-nshettyj@marvell.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "961db18e28d0ab6a684292e0efc99ba24377d394",
      "tree": "bb4cc590cdae92d18a1df0b29bc1cad8f78c4ca0",
      "parents": [
        "5ba5611ef946fc43d7e74cd050f334a9420de136"
      ],
      "author": {
        "name": "Kiran Kumar K",
        "email": "kirankumark@marvell.com",
        "time": "Tue Jun 30 11:51:45 2026 +0530"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 15:11:31 2026 +0200"
      },
      "message": "octeontx2-af: Add RSS hashing support based on RoCEv2 header\n\nAdd NIX_FLOW_KEY_TYPE_ROCEV2 flow key type to support RSS hashing on\nthe RoCEv2 destination Queue Pair (QP) field, allowing RoCEv2 traffic\nto be distributed across receive queues.\n\nSigned-off-by: Kiran Kumar K \u003ckirankumark@marvell.com\u003e\nSigned-off-by: Nitin Shetty J \u003cnshettyj@marvell.com\u003e\nLink: https://patch.msgid.link/20260630062145.2533816-3-nshettyj@marvell.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "5ba5611ef946fc43d7e74cd050f334a9420de136",
      "tree": "f0d5e2f84a89a207dbfb0890d6a64a87fd3922d4",
      "parents": [
        "140be217df577961bea1ca36240439a463026cbd"
      ],
      "author": {
        "name": "Kiran Kumar K",
        "email": "kirankumark@marvell.com",
        "time": "Tue Jun 30 11:51:44 2026 +0530"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 15:11:31 2026 +0200"
      },
      "message": "octeontx2-af: reserve 4 PKINDs for skip-size custom use\n\nThe NPC block uses PKINDs to determine how incoming packets are\nparsed. Reserve PKINDs 46-49 (NPC_RX_SKIP_SIZE_PKIND) for\nconfigurable L2 skip-size use in the first pass, and PKINDs 50-53\n(NPC_RX_CPT_SKIP_SIZE_PKIND) for the second pass where packets\ncarry a CPT (Cryptographic Accelerator Unit) header.\n\nAdd npc_set_skip_size_pkind() to program NPC_AF_PKINDX_ACTION0\nfor these reserved PKINDs with a user-supplied ptr_advance value\nrepresenting the L2 size to skip. For the corresponding CPT PKINDs\n(pkind + 4), additionally configure the var_len_offset, var_len_mask,\nvar_len_shift, and var_len_right fields so the NPC can extract the\ninner payload length from the CPT header.\n\nUpdate rvu_npc_set_parse_mode() to accept a new skip_size argument\nand dispatch to npc_set_skip_size_pkind() when the requested PKIND\nfalls in the newly reserved range. Extend the npc_set_pkind mbox\nmessage struct with a skip_size field so PF/VF drivers can supply\nthis value at run time.\n\nAdvance NPC_UNRESERVED_PKIND_COUNT to NPC_RX_SKIP_SIZE_PKIND to\nreflect the updated reservation boundary.\n\nSigned-off-by: Kiran Kumar K \u003ckirankumark@marvell.com\u003e\nSigned-off-by: Nitin Shetty J \u003cnshettyj@marvell.com\u003e\nLink: https://patch.msgid.link/20260630062145.2533816-2-nshettyj@marvell.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "140be217df577961bea1ca36240439a463026cbd",
      "tree": "debb05f1937ba9d405bb191b4e9485e50b0a6900",
      "parents": [
        "15fede6ca522fe192191df48856004497475b6a0"
      ],
      "author": {
        "name": "Yun Zhou",
        "email": "yun.zhou@windriver.com",
        "time": "Tue Jun 30 14:03:11 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 15:00:54 2026 +0200"
      },
      "message": "net: mvneta_bm: add suspend/resume support to prevent crash after resume\n\nThe mvneta driver uses the hardware Buffer Manager (BM) for RX buffer\nallocation. During suspend, mvneta disables its clock, causing BM to\nlose all buffer address state. On resume, mvneta_bm_port_init() re-\nattaches the BM pool to the NIC, but BM hardware returns stale/garbage\nbuffer addresses. When NAPI poll processes these buffers, DMA cache\nsync hits an invalid virtual address causing a kernel panic:\n\n Unable to handle kernel paging request at virtual address b0000080\n PC is at v7_dma_inv_range\n Call trace:\n  v7_dma_inv_range from arch_sync_dma_for_cpu+0x94/0x158\n  arch_sync_dma_for_cpu from __dma_sync_single_for_cpu+0xc4/0x15c\n  __dma_sync_single_for_cpu from mvneta_rx_swbm+0x6c8/0xf48\n  mvneta_rx_swbm from mvneta_poll+0x6fc/0x70c\n  mvneta_poll from __napi_poll.constprop.0+0x2c/0x1e0\n  __napi_poll.constprop.0 from net_rx_action+0x160/0x2c4\n  net_rx_action from handle_softirqs+0xd8/0x2b8\n  handle_softirqs from run_ksoftirqd+0x30/0x94\n  run_ksoftirqd from smpboot_thread_fn+0x100/0x204\n  smpboot_thread_fn from kthread+0xf4/0x110\n  kthread from ret_from_fork+0x14/0x28\n\nFix by adding suspend/resume callbacks to the BM driver:\n\n- suspend: drain all buffers (with DMA unmapping), free the BPPE\n  regions, and reset pool state to FREE before stopping BM and gating\n  the clock.\n\n- resume: enable the clock, reinitialize BM defaults, and restore pool\n  read/write pointers and size registers. Pool allocation and buffer\n  refill are handled by mvneta_resume() through the normal\n  mvneta_bm_port_init() path, which sees pools as FREE and performs\n  full initialization identical to probe.\n\nAdd a device_link (DL_FLAG_AUTOREMOVE_CONSUMER) in mvneta_probe to\nguarantee BM resumes before mvneta and suspends after mvneta. If the\nlink cannot be created, fall back to SW buffer management to avoid a\npotential crash on resume due to unordered PM transitions.\n\nSigned-off-by: Yun Zhou \u003cyun.zhou@windriver.com\u003e\nLink: https://patch.msgid.link/20260630060311.4072140-1-yun.zhou@windriver.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "15fede6ca522fe192191df48856004497475b6a0",
      "tree": "51d8c66e4742fbfec0b49cb6299d362815658a87",
      "parents": [
        "b8ea7da314c2efcb9c2f559ed65b7a36c869d68e",
        "f4d5e3a5c7bc3d789b5138ef127ab27e0128e2da"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:08 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:08 2026 +0200"
      },
      "message": "Merge branch \u0027net-convert-udp-getsockopt-to-sockopt_t\u0027\n\nBreno Leitao says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: convert UDP getsockopt to sockopt_t\n\nThe leaf proto_ops getsockopt callbacks have been moving to the new\ngetsockopt_iter()/sockopt_t interface.\n\nI was trying to get SMC into getsockop and retire .getsockopt, but,\nI found the best approach is to keep converting other protocols.\n\nThis series starts the same conversion one layer down, at the struct proto\ngetsockopt path, beginning with UDP.\n\nExample of the current code.\n\n\tstatic int udp_getsockopt(struct sock *sk, int level, int optname,\n\t\t\t\tchar __user *optval, int __user *optlen)\n\t{\n\t\tif (level \u003d\u003d SOL_UDP)\n\t\t\treturn udp_lib_getsockopt(sk, level, optname, optval, optlen);\n\t\treturn ip_getsockopt(sk, level, optname, optval, optlen);\n\t}\n\nWe want udp_getsockopt to go to .getsockopt_iter, and there are two\napproaches in this case:\n\n1) Create a patchset that moves both of them to getsockopt_iter, which\n   is will be a huge change (ip_getsockopt() is used in many places)\n\n2) Break this down, and transform from bottoms up. First\n   udp_lib_getsockopt() up to the point we can easily convert\n   others, such as ip_getsockopt().\n\nI am taking the approach 2), so, the intermediate code will be something\nlike:\n\nstatic int udp_getsockopt(struct sock *sk, int level, int optname,\n                          char __user *optval, int __user *optlen)\n{\n        sockopt_t opt;\n        int err;\n\n        if (level !\u003d SOL_UDP)\n                return ip_getsockopt(sk, level, optname, optval, optlen);\n\n\t// Convert optlen/optval in sockopt // (first patch)\n\n        err \u003d udp_lib_getsockopt(sk, level, optname, \u0026opt);\n}\n\nThe work is bottom-up and mergeable in small steps: a protocol\u0027s inner\ngetsockopt helper is switched to sockopt_t behind its existing thin\n__user wrapper, one patch at a time.\n\nOnce every inner helper speaks sockopt_t, a later series flips the shared\nstruct proto.getsockopt and inet_connection_sock_af_ops.getsockopt signatures\nand drops the transitional wrappers.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260630-getsockopt_phase2-v2-0-193335f3d4d1@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f4d5e3a5c7bc3d789b5138ef127ab27e0128e2da",
      "tree": "51d8c66e4742fbfec0b49cb6299d362815658a87",
      "parents": [
        "9588d5da17ce1d52ab8356ea2d7231988d1e11fa"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Tue Jun 30 07:01:29 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:06 2026 +0200"
      },
      "message": "selftests: net: getsockopt_iter: add raw ICMP_FILTER coverage\n\nExercise the raw getsockopt path now backed by sockopt_t. ICMP_FILTER\nreturns a fixed-size struct and, unlike the int/u64 options already\ncovered, clamps the length down to the user buffer on a short read\ninstead of failing, so check that semantic explicitly along with the\nexact and oversized cases, the -EOPNOTSUPP path on a non-ICMP raw\nsocket, and an unknown optname.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260630-getsockopt_phase2-v2-4-193335f3d4d1@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "9588d5da17ce1d52ab8356ea2d7231988d1e11fa",
      "tree": "e733bcf5a82d055d8dc84b955aa72394ad1603eb",
      "parents": [
        "f99d7065a4d45529ccfdc630c1f278da805cf59f"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Tue Jun 30 07:01:28 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:06 2026 +0200"
      },
      "message": "ipv4: raw: convert do_raw_getsockopt to sockopt_t\n\nContinue converting the proto-layer getsockopt callbacks to the sockopt_t\ninterface, switching do_raw_getsockopt() and its raw_geticmpfilter()\nhelper to take a sockopt_t.\n\nThe thin raw_getsockopt() wrapper keeps its __user signature for now: it\nbuilds a user-backed sockopt_t with sockopt_init_user(), calls the helper,\nand writes the returned length back to optlen. The helper uses\ncopy_to_iter() instead of copy_to_user(). No functional change.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nAcked-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260630-getsockopt_phase2-v2-3-193335f3d4d1@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f99d7065a4d45529ccfdc630c1f278da805cf59f",
      "tree": "0af47b13ef822f27419746d1f74bf3c1eb22111b",
      "parents": [
        "b5997f911eec53790d56ca438c8ad61e872d795b"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Tue Jun 30 07:01:27 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:06 2026 +0200"
      },
      "message": "udp: convert udp_lib_getsockopt to sockopt_t\n\nIn preparation for converting the proto-layer getsockopt callbacks to the\nsockopt_t interface, switch udp_lib_getsockopt() to take a sockopt_t.\n\nThe thin udp_getsockopt()/udpv6_getsockopt() wrappers keep their __user\nsignature for now: they build a user-backed sockopt_t with\nsockopt_init_user(), call the helper, and write the returned length back\nto optlen. The helper uses copy_to_iter() instead of copy_to_user().\nNo functional change.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nAcked-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260630-getsockopt_phase2-v2-2-193335f3d4d1@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b5997f911eec53790d56ca438c8ad61e872d795b",
      "tree": "d1a6cd558712e6c5af1ffa4f5b1ba23eac5236ae",
      "parents": [
        "b8ea7da314c2efcb9c2f559ed65b7a36c869d68e"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Tue Jun 30 07:01:26 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 12:29:06 2026 +0200"
      },
      "message": "net: add sockopt_init_user() for getsockopt conversion\n\nAdd a helper that initializes a user-backed sockopt_t from the (optval,\noptlen) __user pair passed to a getsockopt() callback.\n\nIt is used by transitional __user getsockopt wrappers while the\nproto-layer getsockopt callbacks are converted to take a sockopt_t, and\nis removed once the conversion is complete.\n\nThe goal is to help to convert leafs. Example:\n\n sock_common_getsockopt(... char __user *optval, int __user *optlen)\n      → udp_getsockopt(sk, level, optname, optval__user, optlen__user)\n               → udp_lib_getsockopt(sk, level, optname, \u0026opt)   /* needs a sockopt_t */\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nAcked-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260630-getsockopt_phase2-v2-1-193335f3d4d1@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b8ea7da314c2efcb9c2f559ed65b7a36c869d68e",
      "tree": "7fd671ff0fb1fa350b63aaf7a22c046a5a061e75",
      "parents": [
        "49c5ad3cd51885fe9883cc641a0b5a5c3a99dbbe"
      ],
      "author": {
        "name": "Rosen Penev",
        "email": "rosenp@gmail.com",
        "time": "Mon Jun 29 18:51:37 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:48:25 2026 +0200"
      },
      "message": "net: dsa: qca8k: fall back to ethernet-ports node name for LEDs\n\nThe device tree binding allows both \"ports\" and \"ethernet-ports\" as\nthe container node name.  Try \"ethernet-ports\" when \"ports\" is absent\nso that newer DTBs with the preferred name work.\n\nThis matches the handling already present in qca8k-8xxx.c\n\nAssisted-by: opencode:big-pickle\nSigned-off-by: Rosen Penev \u003crosenp@gmail.com\u003e\nLink: https://patch.msgid.link/20260630015137.1591152-1-rosenp@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "49c5ad3cd51885fe9883cc641a0b5a5c3a99dbbe",
      "tree": "80ac7dc3fba2568a6d715eeb5f200a558a074187",
      "parents": [
        "ff052cfcf8cd52e2fccd1f94b2db41e6f85c663c"
      ],
      "author": {
        "name": "Ratheesh Kannoth",
        "email": "rkannoth@marvell.com",
        "time": "Tue Jun 30 07:08:14 2026 +0530"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:45:15 2026 +0200"
      },
      "message": "octeontx2-pf: link RQ page pools to netdev for Netlink stats\n\npage_pool_create() only registers pools with the netdev Netlink\ninterface when pp_params.netdev is set. Set netdev in page pool\nparams.\n\nSigned-off-by: Ratheesh Kannoth \u003crkannoth@marvell.com\u003e\nLink: https://patch.msgid.link/20260630013814.3657831-1-rkannoth@marvell.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "ff052cfcf8cd52e2fccd1f94b2db41e6f85c663c",
      "tree": "ac990835e57a2a401ab0e3ff2fb8ce35afe053ba",
      "parents": [
        "09cfee6a80047850581ad373cffac6034fedf0be",
        "b269a05961913b81753dc2f9ae87469a6815a534"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:20 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:21 2026 +0200"
      },
      "message": "Merge branch \u0027net-dsa-realtek-rtl8366rb-use-generic-rtl83xx-code\u0027\n\nLinus Walleij says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: dsa: realtek: rtl8366rb: Use generic RTL83xx code\n\nAs a follow-up to Luiz\u0027s and Alvin\u0027s series improvining the\ngeneric handling of the Realtek DSA switches, this small\nseries brings the RTL8366RB closer to the way things are done\nin the RTL8365MB driver.\n\nThis patch series switches over to using the generic helpers\nfor:\n\n- Bridge joining and leaving (isolation)\n- STP handling\n- Learning enable/disable\n\nIt would be appreciated if this doesn\u0027t lead to AI-automated\nrequest to fix the entire universe (hi Sashiko, I\u0027m looking\nat you but I bet you will do you compulsive C3P0-style review\nanyway) since I\u0027m just moving code around so some helper\nfunctions come before their new users. The code itself is\npretty straight-forward.\n\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-0-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b269a05961913b81753dc2f9ae87469a6815a534",
      "tree": "ac990835e57a2a401ab0e3ff2fb8ce35afe053ba",
      "parents": [
        "e058ab0c46168d5acb5ce59dbc28b62507b8e426"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Tue Jun 30 13:19:45 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:19 2026 +0200"
      },
      "message": "net: dsa: realtek: rtl8366rb: Switch to generic learning enablement\n\nInstead of just writing the learning disablement register in setup\nand a custom handling of BR_LEARNING, implement the generic RTL83xx\n.port_set_learning() callback for setting learning on a port, and\ncall this in the per-port loop in .setup().\n\nInstead of the custom rtl83366rb_port_bridge_flags() function for\nsetting learning mode on each port, use the RTL83xx generic\nrtl83xx_port_bridge_flags() callback.\n\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-5-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "e058ab0c46168d5acb5ce59dbc28b62507b8e426",
      "tree": "da78a76119a202931f3bfcdbe1eba889a6c30dfe",
      "parents": [
        "cc61d5d7c205502d87f720ef86de9a6819f913e7"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Tue Jun 30 13:19:44 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:19 2026 +0200"
      },
      "message": "net: dsa: realtek: rtl8366rb: Disable STP learning on all ports in setup\n\nWhen we loop over all ports in the switch .setup() callback,\nmake sure to disable learning on all user ports. This is what\nis normally expected and what the RTL8365MB is doing.\n\nMove the code around to accommodate for the new call.\n\nReviewed-by: Luiz Angelo Daros de Luca \u003cluizluca@gmail.com\u003e\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-4-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "cc61d5d7c205502d87f720ef86de9a6819f913e7",
      "tree": "a8eb1805ca4f7cfdda10d770d5ff55ce454b2b65",
      "parents": [
        "82ddf181448ba93b12f8d2e2b6ba7ab38e66c8b9"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Tue Jun 30 13:19:43 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:19 2026 +0200"
      },
      "message": "net: dsa: realtek: rtl8366rb: Use DSA port iterators\n\nInstead of custom loops for intializing the ports (including the\nCPU port) use the DSA helpers dsa_switch_for_each_port() and\ndsa_switch_for_each_cpu_port() following the pattern in RTL8365MB by\naccumulatong masks for the upstream and downstream ports.\n\nThis gives us similar enough code to the RTL8365MB that we\ncan start using more generic rtl83xx helpers.\n\nReviewed-by: Luiz Angelo Daros de Luca \u003cluizluca@gmail.com\u003e\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-3-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "82ddf181448ba93b12f8d2e2b6ba7ab38e66c8b9",
      "tree": "28f39f918ee6db8168afa92665c6c5f663a75262",
      "parents": [
        "69bf497cfa799f80cade1ce5e663fb3c58da7b85"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Tue Jun 30 13:19:42 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:19 2026 +0200"
      },
      "message": "net: dsa: realtek: rtl8366rb: Switch to generic port_bridge* handlers\n\nThe RTL8366RB is using its own sub-standard port isolation code.\n\nImplement the required isolation helpers, use these directly in\nthe port setup callback, and switch over to the standard port\nisolation code.\n\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-2-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "69bf497cfa799f80cade1ce5e663fb3c58da7b85",
      "tree": "374e616b06a6d9862a00073a79ee4fdd8f91a4ad",
      "parents": [
        "09cfee6a80047850581ad373cffac6034fedf0be"
      ],
      "author": {
        "name": "Linus Walleij",
        "email": "linusw@kernel.org",
        "time": "Tue Jun 30 13:19:41 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:32:19 2026 +0200"
      },
      "message": "net: dsa: realtek: rtl83xx: Make learning optional in join/leave\n\nMostly to make it possible to add rtl83xx support piece by piece,\nmake the port learning callback optional in rtl83xx_port_bridge_join()\nand rtl83xx_port_bridge_leave().\n\nSigned-off-by: Linus Walleij \u003clinusw@kernel.org\u003e\nLink: https://patch.msgid.link/20260630-rtl8366rb-improvements-v2-1-05eb9d6a37f5@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "09cfee6a80047850581ad373cffac6034fedf0be",
      "tree": "0f226da1bc2f6af72e80733f482995c47bccb9d5",
      "parents": [
        "8c9c5b9a689612dcb92a04a4218c975cd19f19d8"
      ],
      "author": {
        "name": "Lei Zhu",
        "email": "zhulei@kylinos.cn",
        "time": "Tue Jun 30 14:54:57 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 11:13:05 2026 +0200"
      },
      "message": "ionic: Change list definition method\n\nThe LIST_HEAD macro can both define a linked list and initialize\nit in one step. To simplify code, we replace the separate operations\nof linked list definition and manual initialization with the LIST_HEAD\nmacro.\n\nSigned-off-by: Lei Zhu \u003czhulei@kylinos.cn\u003e\nReviewed-by: Brett Creeley \u003cbrett.creeley@amd.com\u003e\nLink: https://patch.msgid.link/20260630065457.160081-1-zhulei_szu@163.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "8c9c5b9a689612dcb92a04a4218c975cd19f19d8",
      "tree": "cd452a3b6e8e951cf159938af42c4d89ddfc2eeb",
      "parents": [
        "f5afff65a7743af1d68c338e358ae3f4936d3a7f"
      ],
      "author": {
        "name": "Yousef Alhouseen",
        "email": "alhouseenyousef@gmail.com",
        "time": "Tue Jun 30 12:12:16 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:57:48 2026 +0200"
      },
      "message": "net: usb: rtl8150: handle link status read failures\n\nset_carrier() ignores the result of the USB control transfer and tests\nthe stack variable supplied as its receive buffer. If the device rejects\nor aborts the request, that variable remains uninitialized and the driver\nchooses an arbitrary carrier state.\n\nLeave the existing carrier state unchanged when the link status cannot be\nread. A transient USB error should not be treated as link loss.\n\nReported-by: syzbot+9db6c624635564ad813c@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d9db6c624635564ad813c\nSuggested-by: Petko Manolov \u003cpetkan@nucleusys.com\u003e\nSigned-off-by: Yousef Alhouseen \u003calhouseenyousef@gmail.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260630101216.10365-1-alhouseenyousef@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f5afff65a7743af1d68c338e358ae3f4936d3a7f",
      "tree": "8ff4426b88a14df7f7788055fd24df34c5687d8b",
      "parents": [
        "f07f1e3dedb20077a401193c9b65fe37e7d38046",
        "4bbb6f5940708649b8f51ab22692c467a766518f"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:43:26 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:43:27 2026 +0200"
      },
      "message": "Merge branch \u0027net-remove-the-orphaned-ibm-ehea-driver\u0027\n\nDavid Christensen says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: remove the orphaned IBM eHEA driver\n\nThe IBM eHEA (Ethernet Host Ethernet Adapter) driver has been orphaned\nsince April 2024 with no active maintainer stepping forward. This series\nremoves the driver and associated references from the kernel tree.\n\nThe driver was marked as an Orphan on April 18, 2024:\n\ncommit 97ec32b583bb (\"MAINTAINERS: eth: mark IBM eHEA as an Orphan\")\n\nIn the 13 months since, no maintainer has stepped forward to take\nownership.\n\nThe hardware was last supported on IBM POWER7 systems, which reached\nend-of-support in December 2020. The driver has received no functional\nupdates since October 2022:\n\ncommit 0e7ce23a917a (\"net: ehea: fix possible memory leak in ehea_register_port()\")\n\nAnd has only received mechanical API migrations affecting the entire kernel\ntree since that time.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260629211343.3712775-1-drc@linux.ibm.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "4bbb6f5940708649b8f51ab22692c467a766518f",
      "tree": "8ff4426b88a14df7f7788055fd24df34c5687d8b",
      "parents": [
        "eb56577ae9a5aad5c15725a4121f9e560842bd79"
      ],
      "author": {
        "name": "David Christensen",
        "email": "drc@linux.ibm.com",
        "time": "Mon Jun 29 16:13:43 2026 -0500"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:43:24 2026 +0200"
      },
      "message": "powerpc: remove ehea driver references\n\nFollow-on cleanup after the removal of the IBM eHEA driver in commit\nf721e8ffa92a (\"ehea: remove the ehea driver\").\n\nRemove the CONFIG_IBM_EHEA entry from ppc64_defconfig and the\nEXPORT_SYMBOL_GPL(walk_system_ram_range) export from arch/powerpc/mm/mem.c\nthat was only needed by the ehea driver.\n\nSigned-off-by: David Christensen \u003cdrc@linux.ibm.com\u003e\nReviewed-by: Christophe Leroy (CS GROUP) \u003cchleroy@kernel.org\u003e\nLink: https://patch.msgid.link/20260629211343.3712775-3-drc@linux.ibm.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "eb56577ae9a5aad5c15725a4121f9e560842bd79",
      "tree": "bfd4ed9c69579687682b984add266cdb4712f39c",
      "parents": [
        "f07f1e3dedb20077a401193c9b65fe37e7d38046"
      ],
      "author": {
        "name": "David Christensen",
        "email": "drc@linux.ibm.com",
        "time": "Mon Jun 29 16:13:42 2026 -0500"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:43:24 2026 +0200"
      },
      "message": "ehea: remove the ehea driver\n\nThe IBM eHEA (Ethernet Host Ethernet Adapter) driver has been orphaned\nsince April 2024 with no active maintainer. The hardware was last\nsupported on IBM POWER7 systems which reached end-of-support in\nDecember 2020. The driver has received no functional updates since\nOctober 2022, with all subsequent changes being mechanical API\nmigrations affecting the entire kernel tree.\n\nA search of lore.kernel.org for the last 24 months reveals no user\nreports, no objections to the orphan status, and no maintenance\ndiscussions indicating active hardware deployment.\n\nThe code is preserved in git history and can be restored if a\nmaintainer steps forward to take ownership.\n\nSigned-off-by: David Christensen \u003cdrc@linux.ibm.com\u003e\nReviewed-by: Christophe Leroy (CS GROUP) \u003cchleroy@kernel.org\u003e\nLink: https://patch.msgid.link/20260629211343.3712775-2-drc@linux.ibm.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "d8e8b85a85fe21954d303db68034aac4639df88d",
      "tree": "d4d398dbf1006a4f7001656feebe82a5cb04faab",
      "parents": [
        "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
        "26560c4a03dc4d607331600c187f59ab2df5f341"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:34:05 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:34:06 2026 +0200"
      },
      "message": "Merge tag \u0027batadv-net-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv\n\nSimon Wunderlich says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nHere are some batman-adv bugfix, all by Sven Eckelmann:\n\n - fix pointers after potential skb reallocs (5 patches)\n\n - dat: ensure accessible eth_hdr proto field\n\n* tag \u0027batadv-net-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv:\n  batman-adv: dat: ensure accessible eth_hdr proto field\n  batman-adv: bla: reacquire gw address after skb realloc\n  batman-adv: dat: acquire ARP hw source only after skb realloc\n  batman-adv: gw: acquire ethernet header only after skb realloc\n  batman-adv: access unicast_ttvn skb-\u003edata only after skb realloc\n  batman-adv: retrieve ethhdr after potential skb realloc on RX\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260630134430.85786-1-sw@simonwunderlich.de\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f07f1e3dedb20077a401193c9b65fe37e7d38046",
      "tree": "968b1d6d16becfb26a69180ec6ac3c839bc12423",
      "parents": [
        "07d3aaa046ceffb2ed72010d88cb6071717c4906",
        "247691642fd4de7a029de253e47dba936542ce9f"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:30:26 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:30:27 2026 +0200"
      },
      "message": "Merge tag \u0027batadv-next-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv\n\nSimon Wunderlich says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nThis cleanup patchset includes the following patches:\n\n - drop hardif global list, by Nora Schiffer (2 patches)\n\n - make hard_iface-\u003emesh_iface immutable, by Sven Eckelmann\n\n - further post-hardif global list cleanups,\n   by Nora Schiffer (3 patches)\n\n - cleanups and simplifications depending on the hardif-\u003emesh_iface\n   immutability guarantee, by Sven Eckelmann (3 patches)\n\n - tvlv: extract tvlv header iterator, by Sven Eckelmann\n\n - tp_meter: improve unacked list handling,\n   by Sven Eckelmann (5 patches)\n\n* tag \u0027batadv-next-pullrequest-20260630\u0027 of https://git.open-mesh.org/batadv:\n  batman-adv: tp_meter: delay allocation of unacked entry\n  batman-adv: tp_meter: adjust name of receiver lock\n  batman-adv: tp_meter: keep unacked list for receivers\n  batman-adv: tp_meter: combine adjacent/overlapping unacked entries\n  batman-adv: tp_meter: simplify unordered ack calculation\n  batman-adv: tvlv: extract tvlv header iterator\n  batman-adv: iv: drop migration check for batadv_hard_iface\n  Revert \"batman-adv: v: stop OGMv2 on disabled interface\"\n  batman-adv: drop NULL check for immutable hardif-\u003emesh_iface\n  batman-adv: drop unneeded goto and initialization from batadv_hardif_disable_interface()\n  batman-adv: move hardif generation counter into batadv_priv\n  batman-adv: remove BATADV_IF_NOT_IN_USE hardif state\n  batman-adv: make hard_iface-\u003emesh_iface immutable\n  batman-adv: remove global hardif list\n  batman-adv: create hardif only for netdevs that are part of a mesh\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "07d3aaa046ceffb2ed72010d88cb6071717c4906",
      "tree": "0e68062f38487f1381dbd5d094e3de6483806b04",
      "parents": [
        "7693eadcbb8cc32e7cde77ff2cdac67ac026a920"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Mon Jun 29 16:43:53 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:20:45 2026 +0200"
      },
      "message": "selftests: drv-net: toeplitz: cap the Rx queue count\n\nThe RPS test needs a free CPU within the first RPS_MAX_CPUS (16)\ncores. This is easily violated if the NIC or env allocates the\nIRQs to cores linearly.\n\nCap the Rx queues at 8, we don\u0027t need more. This makes the test\npass on CX7 in NIPA.\n\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260629234354.2154541-1-kuba@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "7693eadcbb8cc32e7cde77ff2cdac67ac026a920",
      "tree": "c42709a022e2d970dcf444080a35a59b6bf2b235",
      "parents": [
        "d6e81529749190123aa0040626c7e5dbc20fdc9a"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Tue Jun 30 10:37:00 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 10:14:35 2026 +0200"
      },
      "message": "net: phylink: Drop references to the .validate() method in comments\n\nThe phylink_mac_ops \u0027.validate()\u0027 has been removed in:\n\ncommit da5f6b80ad64 (\"net: phylink: remove .validate() method\")\n\nThere are still a few comments around in phylink that references that,\nrelated to the ports fields as well as the Pause configuration. Let\u0027s\ndrop these references and update the comments related to Pause handling.\n\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260630083700.2041915-1-maxime.chevallier@bootlin.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "d5d2d7a8d8be18681a0864f58e3875f1c639e11c",
      "tree": "00a8c1a1e2117f6718c306e2d0e91837ced89d37",
      "parents": [
        "dc59e4fea9d83f03bad6bddf3fa2e52491777482"
      ],
      "author": {
        "name": "Lee Jones",
        "email": "lee@kernel.org",
        "time": "Fri Jun 19 09:07:14 2026 +0100"
      },
      "committer": {
        "name": "Lee Jones",
        "email": "lee@kernel.org",
        "time": "Thu Jul 02 09:07:03 2026 +0100"
      },
      "message": "MAINTAINERS: Add a mailing list entry to MFD\n\nThis is to be included by all contributors and will be leaned on for\nSashiko\u0027s \"reply to author\" support.\n\nSigned-off-by: Lee Jones \u003clee@kernel.org\u003e\n"
    },
    {
      "commit": "bb09d0e64ecaa0aa0f7d1133a1696ed74dead295",
      "tree": "6e328b19cc29c5d3518103dea429ec6624cc27dd",
      "parents": [
        "0469d460a598d03fc85ebd97f99640e6c579e2a2"
      ],
      "author": {
        "name": "Dawei Feng",
        "email": "dawei.feng@seu.edu.cn",
        "time": "Mon Jun 29 14:40:49 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Jul 02 09:27:26 2026 +0200"
      },
      "message": "net/mlx5: HWS, fix matcher leak on resize target setup failure\n\nhws_bwc_matcher_move() allocates a replacement matcher before setting it\nas the resize target. If mlx5hws_matcher_resize_set_target() fails, the\nreplacement matcher is not attached anywhere and is leaked.\n\nFix the leak by destroying the replacement matcher before returning from\nthe resize-target failure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nmlx5 HWS-capable device to test with, no runtime testing was able to be\nperformed.\n\nFixes: 2111bb970c78 (\"net/mlx5: HWS, added backward-compatible API handling\")\nCc: stable@vger.kernel.org\nSigned-off-by: Dawei Feng \u003cdawei.feng@seu.edu.cn\u003e\nReviewed-by: Yevgeny Kliteynik \u003ckliteyn@nvidia.com\u003e\nAcked-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nLink: https://patch.msgid.link/20260629064049.3852759-1-dawei.feng@seu.edu.cn\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "4a50a141f05a8d1737661b19ee22ff8455b94409",
      "tree": "e9e87e24e0f18c0084916092e4246fe70b1d66bc",
      "parents": [
        "665159e246749578d4e4bfe106ee3b74edcdab18",
        "dec4d8118c179b3d12bca7e609054c6011c4f2ce"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Jul 01 14:21:03 2026 -1000"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Jul 01 14:21:03 2026 -1000"
      },
      "message": "Merge tag \u0027bootconfig-fixes-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull bootconfig fix from Masami Hiramatsu:\n\n - bootconfig: Fix NULL-pointer arithmetic\n\n   Fix undefined pointer arithmetic in xbc_snprint_cmdline() when\n   probing the buffer length with NULL and size 0. Track the written\n   length as a size_t instead to prevent build-time UBSan/FORTIFY_SOURCE\n   failures.\n\n* tag \u0027bootconfig-fixes-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()\n"
    }
  ],
  "next": "0469d460a598d03fc85ebd97f99640e6c579e2a2"
}
