)]}'
{
  "log": [
    {
      "commit": "e6a5d573d24cd375e09d24f136523cb3cc85c9d3",
      "tree": "0a45c214c1ba842741f45d57d9c71a3b17b62888",
      "parents": [
        "9958e69b98930834a576e156f6458166d1db1c02"
      ],
      "author": {
        "name": "Kai Kuang",
        "email": "kuangkai@kylinos.cn",
        "time": "Wed Aug 12 14:06:44 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Fri Aug 14 13:57:27 2026 -0700"
      },
      "message": "net: dsa: drop explicit NULL comparisons\n\nReplace explicit NULL comparisons with the boolean form to follow\nthe kernel coding style:\n\n  dev-\u003eclass !\u003d NULL  -\u003e dev-\u003eclass\n  user_dev \u003d\u003d NULL    -\u003e !user_dev\n\nNo functional changes intended.\n\nSigned-off-by: Kai Kuang \u003ckuangkai@kylinos.cn\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nReviewed-by: Joe Damato \u003cjoe@dama.to\u003e\nLink: https://patch.msgid.link/20260812060644.210997-1-kuangkai@kylinos.cn\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9958e69b98930834a576e156f6458166d1db1c02",
      "tree": "d1965bf93cbc63c5cf61a09c7e6251a8e9d66308",
      "parents": [
        "486e5419b7ec357da8f287efef7ccc1ebc1421e9"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Wed Aug 12 14:22:57 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Fri Aug 14 12:57:44 2026 -0700"
      },
      "message": "gre: fix ERSPAN o_flags race/corruption in xmit and fill_info\n\nFor IPv4 ERSPAN:\nIn erspan_xmit(), the driver clears IP_TUNNEL_SEQ_BIT (for version 0)\nand IP_TUNNEL_KEY_BIT directly in the shared tunnel-\u003eparms.o_flags\nstructure. Since transmit paths can run locklessly and concurrently,\nthis leads to a data race.\n\nFurthermore, modifying tunnel-\u003eparms.o_flags permanently alters the\ntunnel configuration. To work around this, erspan_fill_info() (which\nreports config to userspace) was setting IP_TUNNEL_KEY_BIT back. If\nerspan_fill_info (running under RTNL) and erspan_xmit (running locklessly)\nrace, erspan_xmit might see IP_TUNNEL_KEY_BIT set when it shouldn\u0027t,\nleading to GRE header corruption (injecting a key field into the ERSPAN\nGRE header).\n\nFix this by:\n1) Passing flags as an argument to __gre_xmit().\n2) Using local stack flags in ipgre_xmit(), gre_tap_xmit(), and erspan_xmit()\n   to prevent TOCTOU data races with concurrent configuration updates,\n   and passing them to __gre_xmit().\n3) Removing the racy modification of t-\u003eparms.o_flags in erspan_fill_info().\n4) Forcing IP_TUNNEL_KEY_BIT in the reported flags for ERSPAN locally\n   in ipgre_fill_info().\n\nFor IPv6 ERSPAN:\nip6erspan_tunnel_xmit() was locklessly clearing IP_TUNNEL_KEY_BIT in\nt-\u003eparms.o_flags even though it does not use these flags for building\nthe GRE header (it uses local flags). This permanently corrupts the\nconfiguration and races with ip6gre_fill_info() which reads it.\n\nRemove the redundant and racy modification.\nThis should remove false sharing in a fast path.\n\nAdd const qualifiers in ipgre_fill_info(), erspan_fill_info()\nand ip6gre_fill_info() to clarify that these methods are not\nsupposed to write any live parameters.\n\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260812142257.21283-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "486e5419b7ec357da8f287efef7ccc1ebc1421e9",
      "tree": "8397ce2f0c32de481b4108a8af2143b1a06e75f9",
      "parents": [
        "4cc4f59258a99f43713e7d9a5042c56350b4eeaf"
      ],
      "author": {
        "name": "Shay Drory",
        "email": "shayd@nvidia.com",
        "time": "Mon Aug 10 12:30:37 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Fri Aug 14 12:27:12 2026 -0700"
      },
      "message": "net/mlx5: SD, prefer sd_group_size from vport context\n\nNewer FW reports the SD group size directly in the NIC vport context\nvia the sd_group_size field, gated by the sd_group_size capability.\nSwitch sd_init() to source the group size from there and fall back to\nthe MPIR-based host_buses query only when the cap is absent.\nsd_group_size might return 1 in some FW configuration. Add explicit\ncheck to disable SD creation in this case.\n\nWhile here, rename host_buses to group_size throughout sd.c to follow\nthe new name on capable FW.\n\nSigned-off-by: Shay Drory \u003cshayd@nvidia.com\u003e\nReviewed-by: Moshe Shemesh \u003cmoshe@nvidia.com\u003e\nSigned-off-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260810093037.3138197-1-tariqt@nvidia.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4cc4f59258a99f43713e7d9a5042c56350b4eeaf",
      "tree": "257379ecce59e94813d183765299b3aa35a2b3c6",
      "parents": [
        "4f93b12cf7b25fbf8e73d222722805b049f0a6d3",
        "736fb8632217bd27da6b2e3f1f8cbbe3193fc2d8"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Fri Aug 14 12:23:11 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Fri Aug 14 12:23:12 2026 -0700"
      },
      "message": "Merge tag \u0027nf-next-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next\n\nPablo Neira Ayuso says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nNetfilter updates for net\n\nThis includes an enhancement to detect ct memleaks easier via\nDEBUG_NET and flowtable preparation patches for IPv4 over IPV6\nand vice-versa. This also includes a fix for the nft_ct custom\nexpectation support.\n\n1) Add DEBUG_NET_WARN_ON_ONCE to nf_ct_set() to spot ct memleaks.\n\n2) Pass struct net_device_path_ctx to dev_fill_forward_path() to\n   make it easier to pass more parameters to this function.\n   From Lorenzo Bianconi.\n\n3) Add ether_type field to net_device_path context structucture.\n\n4) Rename tun.l3_proto field to tun.inner_proto.\n\n5) Rename ctx.tun.proto to ctx.tun.inner_proto.\n\n6) Store ether_type in flowtable context.\n\n7) Move IPv4 and IPv6 xmit path to a helper function.\n\n8) Move encapsulation header parser out of the flowtable lookup\n   function.\n\n9) Rework nft_ct custom expectation support to address a possible\n   reallocation of ct extension area while expectation list also\n   contains expectations. Move datapath to a ct helper to fix it.\n\n10) Ensure timeout is always lowered for the non-closing RST case\n    in the TCP connection tracking.\n\n11) Bail out when inserting already dead expectation, this should\n    not ever happen, hence report it via DEBUG_NET.\n\n12) Comestic updates for improving the conntrack selftest dump and\n    flush userspace program, from Qingshuang Fu.\n\n* tag \u0027nf-next-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next:\n  selftests: netfilter: conntrack_dump_flush: remove unused variables and fix typo\n  netfilter: nf_conntrack_expect: bail out on insert dead expectations\n  netfilter: conntrack: always lower timeout for non-closing RST packets\n  netfilter: nft_ct: move custom expectation support to helper\n  netfilter: flowtable: detach layer 2 encapsulation parser from lookup\n  netfilter: flowtable: move ipv4 and ipv6 xmit path to function\n  netfilter: flowtable: store ethertype in flowtable context\n  netfilter: flowtable: rename ctx.tun.proto to ctx.tun.inner_proto\n  netfilter: flowtable: rename tun.l3_proto to tun.inner_proto\n  net: netfilter: add ether_type to net_device_path_ctx and use it\n  net: pass net_device_path_ctx to dev_fill_forward_path()\n  netfilter: add DEBUG_NET_WARN_ON_ONCE to skb_set_nfct()\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260810194015.932627-1-pablo@netfilter.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4f93b12cf7b25fbf8e73d222722805b049f0a6d3",
      "tree": "0cc922bcb5f22aa48f2bb886342c0fd3880d9f43",
      "parents": [
        "9702af05a007e9dffbdbf566e8afdd70b89f82da"
      ],
      "author": {
        "name": "Xu Rao",
        "email": "raoxu@uniontech.com",
        "time": "Mon Aug 10 16:44:35 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 18:55:35 2026 -0700"
      },
      "message": "net: usb: lg-vl600: fix Ethernet header on fragmented RX packets\n\nThe LG VL600 RX path can assemble one device frame from multiple USB RX\nURBs.  In the single-URB case, the input skb passed by usbnet is also the\nbuffer being parsed, so @skb and @buf point to the same skb.\n\nWhen a frame is completed from current_rx_buf, however, @buf points to\nthe assembled skb while @skb still points to the last URB fragment.\nvl600_rx_fixup() returns @buf to the network stack in that path, but it\ncurrently obtains the Ethernet header from @skb.\n\nAs a result, the source/destination address fixups and the IPv6 ethertype\nfixup can be applied to the final fragment instead of the assembled skb\nthat is actually delivered.  Use @buf for the Ethernet header so the\nfixups are applied to the packet being parsed and returned.\n\nThis has likely gone unnoticed because the common single-URB path has\n@skb \u003d\u003d @buf and therefore behaves correctly.\n\nCc: stable+noautosel@kernel.org # untested fix to unlikely driver error path\nSigned-off-by: Xu Rao \u003craoxu@uniontech.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/30CC616506DE5BC4+20260810084435.2099229-1-raoxu@uniontech.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9702af05a007e9dffbdbf566e8afdd70b89f82da",
      "tree": "d1523e32a0d4bf455589016b041d04872beec75a",
      "parents": [
        "07a9e3975039c099c71f9bc5ceab39c1cd949234"
      ],
      "author": {
        "name": "Ilya Maximets",
        "email": "i.maximets@ovn.org",
        "time": "Wed Aug 12 14:20:06 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 18:33:35 2026 -0700"
      },
      "message": "net: openvswitch: unexport ovs_vport_alloc/free\n\nSince removal of the legacy tunnel port types, there are no more\nusers for these functions outside the main openvswitch module.\nFunctions to register vport_ops are also not exported.  Allocating\nvports without operations doesn\u0027t make a lot of sense.\n\nHighlighted by Sashiko as a follow up to the removal of the module\ninfrastructure.\n\nSigned-off-by: Ilya Maximets \u003ci.maximets@ovn.org\u003e\nReviewed-by: Aaron Conole \u003caconole@redhat.com\u003e\nLink: https://patch.msgid.link/20260812122007.457136-1-i.maximets@ovn.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "07a9e3975039c099c71f9bc5ceab39c1cd949234",
      "tree": "6f3368367a8d6c58fca3a81e5b8c041a6a309b2e",
      "parents": [
        "5ba017f9efef3cf65cc60005aae4cbbf70b9b2b8"
      ],
      "author": {
        "name": "Minxi Hou",
        "email": "houminxi@gmail.com",
        "time": "Tue Aug 11 14:16:45 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 18:30:53 2026 -0700"
      },
      "message": "selftests/net/openvswitch: add SCTP flow key support and test\n\nThe ovskey flow-string parser has no OVS_KEY_ATTR_SCTP entry, so a\nflow string containing sctp(src\u003d.../dst\u003d...) parses without error but\nsilently drops the L4 key. The resulting flow carries only\nipv4(proto\u003d132), and the kernel rejects it: match_validate() in\nflow_netlink.c requires OVS_KEY_ATTR_SCTP when the IP protocol is\nIPPROTO_SCTP and returns -EINVAL for the missing key.\n\nRegister OVS_KEY_ATTR_SCTP in the parse table and add a matching\nselftest that verifies SCTP flow key matching (sctp src/dst port).\n\nOne listener serves the whole test. socat\u0027s fork option handles each\nassociation in a child, so the flow rules are the only thing that\nchanges between the three phases and the listener is never restarted\nunderneath them. -t 1 bounds how long a forked child lingers after\nits association closes, and the existing kill -TERM of the captured\npid on teardown removes the listener itself.\n\nAlso enable CONFIG_IP_SCTP in the selftest kernel config. The config\nchecker strips underscores before comparing keys, so the entry sorts\nbefore CONFIG_IPV6 rather than after it.\n\nSigned-off-by: Minxi Hou \u003chouminxi@gmail.com\u003e\nReviewed-by: Aaron Conole \u003caconole@redhat.com\u003e\nLink: https://patch.msgid.link/20260811181645.1918420-1-houminxi@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5ba017f9efef3cf65cc60005aae4cbbf70b9b2b8",
      "tree": "4a6cbb1b5a21931701c1a1aa228c4fcc90437d6d",
      "parents": [
        "77e80af7d2d4dc223716c90e9fc043bc66a8335f"
      ],
      "author": {
        "name": "Sandeep Sondagar",
        "email": "sandeepsondagar@gmail.com",
        "time": "Sun Aug 09 21:31:41 2026 +0530"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 18:21:31 2026 -0700"
      },
      "message": "net: phylink: treat PSGMII as an inband capable interface\n\nPSGMII (the Qualcomm 5-port SGMII) conveys the link negotiation result\nfrom the PHY back to the MAC through per-channel in-band SGMII words,\nexactly like SGMII and QSGMII.\n\nHowever, PHY_INTERFACE_MODE_PSGMII is missing from\nphylink_get_inband_type(), so phylink reports INBAND_NONE for it and\nphylink_pcs_neg_mode() falls back to PHYLINK_PCS_NEG_NONE. The PCS is\nthen programmed in force mode and its control-register speed bits (which\ndefault to 1000base) are used, so a slower copper link - e.g. 100base-T\n- is reported as 1Gbps and cannot pass traffic.\n\nClassify PSGMII alongside SGMII and QSGMII as INBAND_CISCO_SGMII so the\nPCS negotiates in-band and the resolved link speed comes from the PHY\nin-band word.\n\nAlso add PSGMII to the generic clause 22 PCS helper functions which\nhandle the SGMII in-band word. Without this, a PCS using these helpers\nwould still fall through to the default handling and force the link\nstate to false in phylink_mii_c22_pcs_decode_state(), fail to encode\nthe SGMII advertisement, and get rejected by phylink_get_link_timer_ns().\n\nSigned-off-by: Sandeep Sondagar \u003csandeepsondagar@gmail.com\u003e\nReviewed-by: Nicolai Buchwitz \u003cnb@tipi-net.de\u003e\nLink: https://patch.msgid.link/20260809-phylink-psgmii-v3-1-908dcd3a9e3d@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "77e80af7d2d4dc223716c90e9fc043bc66a8335f",
      "tree": "12776391d429fbe7f318a8d5852152f6c24bd9f3",
      "parents": [
        "a7c44619c6977fd64da99a6d1c2b73e2ad9af873"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 09:22:30 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:44:54 2026 -0700"
      },
      "message": "ethtool: tsconfig: reject zero-valued tx_type and rx_filter bitsets\n\nThe ffs()/fls() guard in ethnl_set_tsconfig() was meant to enforce\nthat the user selects exactly one tx_type (and one rx_filter)\nat a time (off / none are explicit types with non-zero values).\nHowever, both ffs(0) and fls(0) return 0, so the guard passes\na zero-valued bitset through.\n\nThe subsequent ffs(req_tx_type) - 1 would produce -1, if user selected\nno bit. net_hwtstamp_validate() catches the invalid -1 downstream,\nbut returns a generic error (-ERANGE) without telling the user\nwhat went wrong. Return -EINVAL + extack instead.\n\nReplace the ffs()/fls() comparison with a hweight32() \u003d\u003d 1 check.\n\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nReviewed-by: Joe Damato \u003cjoe@dama.to\u003e\nReviewed-by: Vadim Fedorenko \u003cvadim.fedorenko@linux.dev\u003e\nLink: https://patch.msgid.link/20260812162230.1837788-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a7c44619c6977fd64da99a6d1c2b73e2ad9af873",
      "tree": "b65149f0e39dc1df7865c225d229e19979b2399a",
      "parents": [
        "b3217bdb0091e52887e23896cd82483f7808914a"
      ],
      "author": {
        "name": "Florian Bezdeka",
        "email": "florian.bezdeka@siemens.com",
        "time": "Mon Aug 10 15:19:17 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:40:49 2026 -0700"
      },
      "message": "net: stmmac: intel: Add missing pci_free_irq_vectors() calls\n\nThe IRQ vectors allocated in stmmac_config_multi_msi() or\nstmmac_config_single_msi() where never explicitly cleaned up. As\npcim_enable_device() is used, all sorts of other functions are switched\nto managed mode. The missing cleanup here isn\u0027t actually missing, it\u0027s\nburied in the depths of PCI code.\n\nBut: There are some ongoing activities to remove that cleanup magic.\nSee the linked discussions below.\n\nThis patch prepares the dwmac-intel code for the removal.\n\nLink: https://lore.kernel.org/netdev/27fec7d0ed633218a7787be3edce63c3038c63e2.camel@mailbox.org/\nLink: https://lore.kernel.org/netdev/7e024db2557a4d5822a0dd409ae678d10d815d9c.camel@mailbox.org/\nSigned-off-by: Florian Bezdeka \u003cflorian.bezdeka@siemens.com\u003e\nLink: https://patch.msgid.link/20260810-flo-net-stmmac-default-affinity-core-v2-1-d2105780b8ca@siemens.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b3217bdb0091e52887e23896cd82483f7808914a",
      "tree": "126ff434d690dffd6bc4e5a7a2b53af80c36ea09",
      "parents": [
        "ed267f783c0c283171e132bb660f8753b40a2660"
      ],
      "author": {
        "name": "Slawomir Stepien",
        "email": "sst@poczta.fm",
        "time": "Mon Aug 10 10:57:17 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:38:05 2026 -0700"
      },
      "message": "netdevsim: drop the ability to change max_vfs via debugfs\n\nThis debugfs file isn\u0027t used by kernel\u0027s selftests, so drop it.\n\nReported-by: syzbot+3147c5de186107ffc7a1@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d3147c5de186107ffc7a1\nSuggested-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nSigned-off-by: Slawomir Stepien \u003csst@poczta.fm\u003e\nLink: https://patch.msgid.link/20260810085717.570382-1-sst@poczta.fm\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ed267f783c0c283171e132bb660f8753b40a2660",
      "tree": "1916925b1778ebe53b177e35b19c8c907e4882b7",
      "parents": [
        "a1ca9d0abea8a2374435021aea4267f49ef4904c"
      ],
      "author": {
        "name": "Maoyi Xie",
        "email": "maoyixie.tju@gmail.com",
        "time": "Sun Aug 09 17:42:52 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:33:31 2026 -0700"
      },
      "message": "l2tp: send netlink notifications in the tunnel\u0027s net namespace\n\nl2tp_tunnel_notify() and l2tp_session_notify() use\ngenlmsg_multicast_allns(), which delivers to listeners in every network\nnamespace. l2tp is per-namespace, and a tunnel records the namespace it\nbelongs to in tunnel-\u003el2tp_net. Each event concerns one namespace, yet\nevery namespace is told about it. A tunnel event carries the tunnel and\npeer tunnel ids, plus the socket\u0027s addresses with both ports for a UDP\ntunnel. A session event carries the session and peer session ids, the\ninterface name, plus the L2TP cookies where those are set. A listener\nneeds no privilege for any of this, because l2tp_multicast_group[]\ncarries no flags and genl_bind() asks for no capability.\n\nThe fix is to send to the tunnel\u0027s namespace with\ngenlmsg_multicast_netns(). Commit 134e63756d5f (\"genetlink: make netns\naware\") added both helpers and drew the line between them. The netns\nvariant is for an object that lives in a namespace.\n\nI found this by auditing the tree\u0027s six genlmsg_multicast_allns() call\nsites for objects that live in a network namespace. Only the two l2tp\nones do.\n\nI reproduced it on net at dd057113ac7b, in a virtual machine, with no\nreal hardware involved. A process in the initial namespace, running as\nan ordinary user with an empty capability set, receives the create and\ndelete events of a tunnel. The tunnel was set up inside an unprivileged\nuser and network namespace. tools/testing/selftests/net/l2tp.sh passes\nbefore and after.\n\nOn a container host, any local user and every other tenant can read a\ntenant\u0027s tunnel parameters.\n\nCc: stable+noautosel@kernel.org # high regression risk\nSigned-off-by: Maoyi Xie \u003cmaoyixie.tju@gmail.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260809094252.2107242-1-maoyixie.tju@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a1ca9d0abea8a2374435021aea4267f49ef4904c",
      "tree": "db182849dfc6e58b243d4cb01a63c3376a3c6ebb",
      "parents": [
        "3da8c3c8b8fa99505624b65ef590482f48e766b6",
        "854ac5fde2215a3cb06f6d05b744869a31889064"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:30:22 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:30:23 2026 -0700"
      },
      "message": "Merge branch \u0027net-phy-dp83640-fix-shared-clock-lifetime-and-probe-error-cleanup\u0027\n\nXuanqiang Luo says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: phy: dp83640: fix shared clock lifetime and probe error cleanup\n\nThe DP83640 driver shares one PTP clock between all PHYs on the same MII\nbus.\n\nIts driver-local clock lookup and removal scheme can leak the shared clock\non probe failure or free it while another probe is acquiring it.\n\nThis series moves the shared clock to the PHY package infrastructure.\n\nPatch 1 adds PHY package locking helpers.\n\nPatch 2 embeds the pin configuration in the shared clock.\n\nPatch 3 clears per-PHY state when PTP clock registration fails.\n\nPatch 4 fixes the shared clock lifetime using the PHY package\ninfrastructure.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260811151345.73582-1-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "854ac5fde2215a3cb06f6d05b744869a31889064",
      "tree": "db182849dfc6e58b243d4cb01a63c3376a3c6ebb",
      "parents": [
        "e8b166c1f0a53312bd50355ea4db77b2a6728e0f"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Tue Aug 11 23:13:45 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:30:15 2026 -0700"
      },
      "message": "net: phy: dp83640: fix per-bus clock lifetime\n\nCommit 42e2a9e11a1d (\"net: phy: dp83640: improve phydev and driver\nremoval handling\") moved per-bus clock cleanup from module exit to the\nremove path. This leaves two lifetime problems.\n\ndp83640_clock_get_bus() publishes a newly allocated clock before the\ndriver allocates its per-PHY data and registers the PTP clock. If either\noperation fails, no PHY is bound and the remove callback cannot release\nthe clock, leaking the clock and the MII bus device reference.\n\nThe remove path can also free a clock after dropping clock_lock. A\nconcurrent probe may already have found the clock under\nphyter_clocks_lock and be waiting for clock_lock, allowing it to acquire\na freed mutex and access the freed clock.\n\nUse the PHY package infrastructure for the per-bus clock. PHY packages\nare tracked per MII bus, and the driver uses BROADCAST_ADDR as the\npackage key so the DP83640 PHYs on the same bus share the same clock\nstorage. Call phy_package_join() during probe and phy_package_leave() on\nprobe errors and in remove.\n\nSerialize the one-time clock initialization with the package lock because\nphy_package_probe_once() elects an initializer but does not wait for\ninitialization to finish.\n\nCc: stable+noautosel@kernel.org # untested fix to a driver init path\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260811151345.73582-5-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e8b166c1f0a53312bd50355ea4db77b2a6728e0f",
      "tree": "1bc5f5ff6d326012c2fdc7bb8dd5ee61c47edbed",
      "parents": [
        "20663d78f1a1c242ad865967a31ee716dd1e52a1"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Tue Aug 11 23:13:44 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:29:56 2026 -0700"
      },
      "message": "net: phy: dp83640: clear state after PTP registration failure\n\ndp83640_probe() publishes its per-PHY state through phydev before\nregistering the PTP clock. If registration fails, the private data is\nfreed while phydev-\u003emii_ts and phydev-\u003epriv still point to it, and\ndefault_timestamp remains set.\n\nClear the published PHY state and reset the PTP clock pointer before\nfreeing the private data.\n\nCc: stable+noautosel@kernel.org # untested fix to a driver init path\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260811151345.73582-4-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "20663d78f1a1c242ad865967a31ee716dd1e52a1",
      "tree": "f8a95249e5c1c093cffd71c72bbaf55e14a923c5",
      "parents": [
        "ebb16fca011ce08fa710cec42ee43a33bf331893"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Tue Aug 11 23:13:43 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:29:55 2026 -0700"
      },
      "message": "net: phy: dp83640: embed pin configuration in clock\n\nThe DP83640 has a fixed number of PTP pins, and its pin configuration\nhas the same lifetime as the per-bus clock. Allocating the configuration\nseparately adds an allocation failure path and requires a separate free.\n\nEmbed the pin configuration in struct dp83640_clock and point the PTP\nclock information at the embedded array. This changes only the storage;\nthe pin functions remain configurable at runtime. It also allows all\nper-bus clock storage to be managed as one allocation.\n\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260811151345.73582-3-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ebb16fca011ce08fa710cec42ee43a33bf331893",
      "tree": "36d4d49698ec358a78ef5a140c43d782af593113",
      "parents": [
        "3da8c3c8b8fa99505624b65ef590482f48e766b6"
      ],
      "author": {
        "name": "Xuanqiang Luo",
        "email": "luoxuanqiang@kylinos.cn",
        "time": "Tue Aug 11 23:13:42 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 17:29:53 2026 -0700"
      },
      "message": "net: phy: add PHY package locking helpers\n\nThe PHY package API provides private data shared by all PHYs in a\npackage. Drivers are responsible for synchronizing access to this data,\nbut the API does not provide a lock for that purpose.\n\nAdd phy_package_lock() and phy_package_unlock() for drivers to serialize\naccess to package-private data, including its initialization.\n\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nSigned-off-by: Xuanqiang Luo \u003cluoxuanqiang@kylinos.cn\u003e\nLink: https://patch.msgid.link/20260811151345.73582-2-xuanqiang.luo@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3da8c3c8b8fa99505624b65ef590482f48e766b6",
      "tree": "a4e8435b0e16ba34a7fe90a6b7e355390cc33fb4",
      "parents": [
        "3205699d79f262412c1be7fc1c04066610d3cd52",
        "3aa1dcaa4f6f5ae08936491e08bd456f331f2d40"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 06 11:51:42 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 13 11:00:14 2026 -0700"
      },
      "message": "Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nCross-merge networking fixes after downstream PR (net-7.2-rc8).\n\nNo conflicts.\n\nAdjacent changes:\n\ndrivers/net/ethernet/wangxun/ngbe/ngbe_main.c\n  5f3a13e0bb5e (\"net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling\")\n  d661abdc30c2 (\"net: ngbe: correct misleading interrupt comment\")\n\ndrivers/net/ipvlan/ipvlan_main.c\n  e16e960d55a4 (\"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev\")\n  00a40d809207 (\"ipvlan: Support per-netns netdev unregistration.\")\n\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3aa1dcaa4f6f5ae08936491e08bd456f331f2d40",
      "tree": "a54e92e33ab75e5545796457447ad8b9a5231107",
      "parents": [
        "e14aacefb78d942d2308d9821fe52d75d21a824e"
      ],
      "author": {
        "name": "Mikhail Gavrilov",
        "email": "mikhail.v.gavrilov@gmail.com",
        "time": "Tue Aug 04 17:00:04 2026 +0500"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 09:00:55 2026 -0700"
      },
      "message": "Revert \"wifi: mt76: Disable napi when removing device\"\n\nThis reverts commit 13b7e6a96a005c656d38f3da51581deaf9866375.\n\nThat commit made mt76_dma_cleanup() disable every RX NAPI instance before\ndeleting it, to silence WARNs in __netif_napi_del_locked() and\npage_pool_disable_direct_recycling() seen when unloading mt7915e with an\nMT7916.\n\nOn mt7921e and mt7925e the same instances are already disabled earlier,\nin mt7921e_unregister_device() and mt7925e_unregister_device(), which\nonly afterwards call mt792x_dma_cleanup() -\u003e mt76_dma_cleanup().  Each\ninstance is therefore disabled twice, and napi_disable() is not\nidempotent: on return it leaves NAPIF_STATE_SCHED and NAPIF_STATE_NPSVC\nset, so the second call spins in usleep_range() forever, waiting for bits\nthat nobody will clear.\n\nmt7921_pci_shutdown() and mt7925_pci_shutdown() reuse the remove path, so\nthis is hit on every reboot, poweroff and module unload.  It is silent:\nthe stuck task keeps sleeping and rescheduling, so neither the hung task\ndetector nor the lockup detectors fire, and the last line on the console\nis \"systemd-shutdown[1]: Rebooting.\"\n\n  task:modprobe        state:D stack:25720 pid:7954  tgid:7954\n  Call Trace:\n   \u003cTASK\u003e\n   __schedule+0x11b8/0x26d0\n   schedule+0xe7/0x2f0\n   schedule_hrtimeout_range_clock+0x218/0x330\n   usleep_range_state+0x133/0x1b0\n   napi_disable_locked+0x37d/0x5f0\n   napi_disable+0x43/0x80\n   mt76_dma_cleanup+0x2b4/0x860 [mt76]\n   mt7921_pci_remove+0x17f/0x350 [mt7921e]\n   pci_device_remove+0xb6/0x1e0\n   device_release_driver_internal+0x38d/0x540\n   driver_detach+0xd0/0x1b0\n   bus_remove_driver+0x127/0x2d0\n   pci_unregister_driver+0x2a/0x280\n   __do_sys_delete_module+0x36a/0x5b0\n   do_syscall_64+0x11c/0x6d0\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   \u003c/TASK\u003e\n\nDropping the two driver-side loops instead was tried and rejected: with\nthem gone, the RX poll can reach mt76_token_release() via\nPKT_TYPE_TXRX_NOTIFY and mt7921_mac_tx_free() while\nmt76_connac2_tx_token_put() is running idr_destroy(\u0026dev-\u003etoken) outside\ntoken_lock, which is a use-after-free rather than a hang [1].\n\nRevert for now, so that reboot, poweroff and module unload work again.\nThe WARNs on mt7915e are a less severe problem than an unbootable\nmachine, and fixing them belongs in the drivers that delete the NAPI\ninstances, where each one can pick a point that is safe for its own\nteardown order, rather than in the shared mt76_dma_cleanup().\n\n[ This is the \"landing soonish\" known regression fix mentioned in the\n  previous networking merge commit       - Linus ]\n\nReported-by: Bert Karwatzki \u003cspasswolf@web.de\u003e\nCloses: https://lore.kernel.org/all/20260724151419.26014-1-spasswolf@web.de/\nCloses: https://bugzilla.kernel.org/show_bug.cgi?id\u003d221818\nLink: https://lore.kernel.org/all/20260730050428.GA73812@sol/ [1]\nSigned-off-by: Mikhail Gavrilov \u003cmikhail.v.gavrilov@gmail.com\u003e\nAcked-by: Nicolas Cavallari \u003cnicolas.cavallari@green-communications.fr\u003e\nFixes: 13b7e6a96a00 (\"wifi: mt76: Disable napi when removing device\")\nTested-by: Devin Wittmayer \u003clucid_duck@justthetip.ca\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "e14aacefb78d942d2308d9821fe52d75d21a824e",
      "tree": "1bad843db01ff93e3951865d1fdb7080e6ac2493",
      "parents": [
        "83a4f90e9835d3d61fe3dd39ffbbcac752467d09",
        "9006c116dd111d457bf5d074990210f70a4ad2c8"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 08:37:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 08:37:26 2026 -0700"
      },
      "message": "Merge tag \u0027net-7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Paolo Abeni:\n \"Including fixes from netfilter.\n\n  There is a known WiFi/mt76 regression, waiting for a complete fix that\n  should land soonish.\n\n  Previous releases - regressions:\n\n   - tcp: fix icsk_ack.ato bitfield overflow\n\n   - af_unix: Unlink scc_entry in unix_del_edge()\n\n   - ipv4: fix use-after-free in fib_nhc_update_mtu()\n\n   - netfilter:\n      - ipset: fix refcount race between list:set GC and swap\n      - nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort\n        path\n\n   - sched: act_ct: fix sk_buff leak when the header checks reject a\n     packet\n\n   - sctp: clear new_transport when removing a peer\n\n   - dibs: correct freeing of dmb_clientid_arr\n\n   - ovpn: fix NULL dereference when killing missing key\n\n   - eth:\n      - veth: fix queue index used to wake the peer txq in veth_poll\n      - ngbe: fix NULL pointer dereference in non-MSI-X interrupt\n        enabling\n      - gve: fix zero-length skb frag with header-split\n\n  Previous releases - always broken:\n\n   - core: fix skb length accounting after generic XDP frag adjustment\n\n   - af_packet: don\u0027t send zero-byte data in tpacket_snd().\n\n   - eth:\n      - bnxt: avoid deadlock when canceling IRQ affinity notifier\n      - ipvlan: inherit needed_headroom and needed_tailroom from\n        phy_dev\"\n\n* tag \u0027net-7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (55 commits)\n  l2tp: fix tunnel and session refcount leak on seq_file release\n  net/sched: cls_bpf: reject dev-bound programs bound to a different device\n  sctp: fix use-after-free of cached ASCONF chunk\n  net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n  sctp: clear new_transport when removing a peer\n  net/dibs: Correct freeing of dmb_clientid_arr\n  net/sched: cls_u32: skip hash tables in u32_bind_class()\n  gve: fix NULL dereference due to missing ptp adjfine\n  gve: fix zero-length skb frag with header-split\n  net/sched: act_api: fix TOCTOU NULL deref on a-\u003egoto_chain\n  af_packet: Don\u0027t send zero-byte data in tpacket_snd().\n  tipc: read le-\u003elink under the node lock in tipc_node_link_down()\n  selftests: tls: cover splice after a failed decrypt\n  net/tls: Fail tls_sw_splice_read() after a failed async decrypt\n  net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling\n  net: tap: fix wrong transport_header when sending VLAN-tagged frame\n  net: packet: fix wrong transport_header when sending VLAN-tagged frame\n  vxlan: do not arm the ageing timer on a device that is down\n  ipv4: fix use-after-free in fib_nhc_update_mtu()\n  NTB: ntb_netdev: Preserve RX queue depth on allocation failure\n  ...\n"
    },
    {
      "commit": "83a4f90e9835d3d61fe3dd39ffbbcac752467d09",
      "tree": "3bab72e9ae6a57ae6f25d92e518bae40cc8ef974",
      "parents": [
        "b4f5144d37403d529334573ef2a1bb6ca4a2c553",
        "42d217add8d80d6e7d9f58f80d11ea9b07ea113e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:31:21 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:31:21 2026 -0700"
      },
      "message": "Merge tag \u0027firewire-fixes-7.2-final\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394\n\nPull firewire fix from Takashi Sakamoto:\n \"Fix a NULL pointer dereference in 1394 OHCI PCI driver when probe()\n  returns early with an error, as detected by Syzkaller\"\n\n* tag \u0027firewire-fixes-7.2-final\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394:\n  firewire: ohci: fix NULL pointer dereference in ar_context_release\n"
    },
    {
      "commit": "b4f5144d37403d529334573ef2a1bb6ca4a2c553",
      "tree": "e5c97704314f918a7b782392804f0f2ca801bf39",
      "parents": [
        "64dc3ba55effbf8afcc0099162dfb4138009ad48",
        "44f3468a0aef1aabdad551898ab7cfa2a9d20e99"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:16:58 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:16:58 2026 -0700"
      },
      "message": "Merge tag \u0027gpio-fixes-for-v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull gpio fixes from Bartosz Golaszewski:\n\n - use raw_spinlock_t in gpio-ml-ioh to avoid locking context issues\n\n - fix a race condition in gpio-ml-ioh by sharing the register locks\n   across channels\n\n - fix a use-after-free bug in unbind path in gpio-sloppy-logic-analyzer\n\n* tag \u0027gpio-fixes-for-v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind\n  gpio: ml-ioh: share the register lock across channels\n  gpio: ml-ioh: use raw_spinlock_t for the register lock\n  gpiolib: Check gc-\u003eget_direction() before calling gpiod_get_direction()\n"
    },
    {
      "commit": "64dc3ba55effbf8afcc0099162dfb4138009ad48",
      "tree": "80336659e12bde884a59cd016a889c2eb653e75d",
      "parents": [
        "3d6d817622b0a9721e3cc404df3469171582be13",
        "1fd495ef09eef96169a379a749c24b5e69974bb8"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:00:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:00:26 2026 -0700"
      },
      "message": "Merge tag \u0027m68k-for-v7.2-tag2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/geert/linux-m68k\n\nPull m68k fix from Geert Uytterhoeven:\n \"Define NR_CPUS to 1.\n\n  This fixes a long-standing but never critical before oddity on m68k,\n  that turned into a serious configuration issue after a recent erofs\n  change\"\n\n* tag \u0027m68k-for-v7.2-tag2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/geert/linux-m68k:\n  m68k: Define NR_CPUS to 1\n"
    },
    {
      "commit": "3205699d79f262412c1be7fc1c04066610d3cd52",
      "tree": "a1e0487449723c29c85b7be98410cffa6a2fc0f4",
      "parents": [
        "885a48b521b40aa515ad47f5581535b5763d105c",
        "3d2452c2fb2fe37d8b1eb5b814561e71eb8652f3"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 15:05:04 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 15:05:05 2026 +0200"
      },
      "message": "Merge branch \u0027netconsole-replace-target_list_lock-by-rcu-on-userdata-hot-path\u0027\n\nBreno Leitao says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnetconsole: replace target_list_lock by RCU on userdata hot path\n\nI would like to move netconsole to use RCU on the hot path for\na while instead of target_list_lock. My goal is to have no lock on the\ntx side at all and eventually drop CON_NBCON_ATOMIC_UNSAFE, if that is\npossible [1].\n\nStart removing target_list_lock on certain parts of the code. This patch\ntransforms the userdata array into a RCU-protected pointer, and uses the\ndynamic mutex as the write lock.\n\nAdded a selftest, given we didn\u0027t have any netconsole selftest for\nuserdata operations. Feel free to drop it if this is not useful, dear\nmaintainers.\n\nLink: https://lore.kernel.org/all/20251121-nbcon-v1-0-503d17b2b4af@debian.org/[1]\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260810-netcons-userdata-rcu-v3-0-f65557f769ce@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "3d2452c2fb2fe37d8b1eb5b814561e71eb8652f3",
      "tree": "a1e0487449723c29c85b7be98410cffa6a2fc0f4",
      "parents": [
        "a9560343d4e9da962616110140afed20249f81c2"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Mon Aug 10 02:36:12 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 15:04:40 2026 +0200"
      },
      "message": "selftests: netconsole: add a userdata torture test\n\nThe userdata payload is rebuilt and republished on every configfs write,\nincluding while the target is enabled and messages are being sent.\n\nAdd netcons_userdata.sh that runs random tests with userdata.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nReviewed-by: Gustavo Luiz Duarte \u003cgustavold@gmail.com\u003e\nLink: https://patch.msgid.link/20260810-netcons-userdata-rcu-v3-2-f65557f769ce@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "a9560343d4e9da962616110140afed20249f81c2",
      "tree": "ba63f5db01202435bf18d3ef41c318139e362ca7",
      "parents": [
        "885a48b521b40aa515ad47f5581535b5763d105c"
      ],
      "author": {
        "name": "Breno Leitao",
        "email": "leitao@debian.org",
        "time": "Mon Aug 10 02:36:11 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 15:04:40 2026 +0200"
      },
      "message": "netconsole: publish the userdata payload with RCU\n\nupdate_userdata() takes target_list_lock to swap nt-\u003euserdata and\nnt-\u003euserdata_length, then frees the old buffer. Since commit\n7eab73b18630 (\"netconsole: convert to NBCON console infrastructure\")\nthat lock is also the console\u0027s device_lock, so writing a userdata value\nfrom configfs serialises against the printk core emitting messages.\n\nThe buffer is immutable once published, which is what RCU is for. Move\nthe string and its length into a single netcons_userdata object and\npublish it with rcu_replace_pointer(), freeing the old one with\nkfree_rcu().\n\nNew userdata design:\n\n0) Unify the userdata fields into a struct netcons_userdata\n1) update_userdata() no longer needs target_list_lock.\n2) writers stay serialised by dynamic_netconsole_mutex.\n3) reading userdata needs an RCU read lock.\n\nNo functional change intended.\n\nSigned-off-by: Breno Leitao \u003cleitao@debian.org\u003e\nReviewed-by: Gustavo Luiz Duarte \u003cgustavold@gmail.com\u003e\nLink: https://patch.msgid.link/20260810-netcons-userdata-rcu-v3-1-f65557f769ce@debian.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "42d217add8d80d6e7d9f58f80d11ea9b07ea113e",
      "tree": "154a9a3ebe93079eeb0d24087892a6f6264ad37d",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Aleksandr Nogikh",
        "email": "nogikh@google.com",
        "time": "Fri Aug 07 14:25:26 2026 +0000"
      },
      "committer": {
        "name": "Takashi Sakamoto",
        "email": "o-takashi@sakamocchi.jp",
        "time": "Thu Aug 13 21:02:23 2026 +0900"
      },
      "message": "firewire: ohci: fix NULL pointer dereference in ar_context_release\n\nDuring the error handling path of the driver\u0027s probe function, a NULL\npointer dereference can occur in ar_context_release().\n\nWhen pci_probe() fails early (e.g., if pcim_enable_device() or MMIO mapping\nfails), the devres cleanup mechanism invokes release_ohci(). This function\nunconditionally calls ar_context_release() to clean up the asynchronous\nreceive contexts. However, if ar_context_init() was not yet called,\nctx-\u003eohci remains NULL (as the fw_ohci structure is zero-initialized by\ndevres_alloc()).\n\nar_context_release() immediately dereferences ctx-\u003eohci to get the dev\npointer before checking if the context was actually initialized, leading to\na crash:\n\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nRIP: 0010:ar_context_release+0x3f/0x380 drivers/firewire/ohci.c:543\nCall Trace:\n release_ohci+0x3f/0x60 drivers/firewire/ohci.c:3567\n release_nodes drivers/base/devres.c:546 [inline]\n devres_release_all+0x1a8/0x260 drivers/base/devres.c:576\n device_unbind_cleanup drivers/base/dd.c:597 [inline]\n really_probe+0x451/0xae0 drivers/base/dd.c:772\n\nTo fix this, move the assignment of the dev pointer after the !ctx-\u003ebuffer\ncheck. If ctx-\u003ebuffer is NULL, it indicates that the context was never\nsuccessfully initialized and there is nothing to release, safely avoiding\nthe dereference of the uninitialized ctx-\u003eohci pointer.\n\nFixes: 5716e58aecdd (\"firewire: ohci: release buffer for AR req/resp contexts when managed resource is released\")\nAssisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot\nReported-by: syzbot+d30aad27833a559defab@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003dd30aad27833a559defab\nLink: https://syzkaller.appspot.com/ai_job?id\u003d10a18617-7893-42dd-bf1c-cd49e19e95d9\nSigned-off-by: Aleksandr Nogikh \u003cnogikh@google.com\u003e\nLink: https://lore.kernel.org/r/90c5db71-dd1f-4d46-b9d3-2f1046cbd5ea@mail.kernel.org\nSigned-off-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\n"
    },
    {
      "commit": "885a48b521b40aa515ad47f5581535b5763d105c",
      "tree": "a91df54b31dc49bc9d158dcb838daaa60f882d07",
      "parents": [
        "03a105c83243a8c9cc147a44a7ec7bfd4c10ee8c",
        "23adfc77c22cb959ac84e08dc8a77bac656f1caa"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:42:50 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:42:50 2026 +0200"
      },
      "message": "Merge branch \u0027net-mana-avoid-dma-queue-allocation-failure-under-memory-fragmentation\u0027\n\nAditya Garg says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: mana: Avoid DMA queue allocation failure under memory fragmentation\n\nThe MANA driver can fail to bring up its queues on systems with high\nmemory utilization because every GDMA queue ring is allocated as a\nsingle dma_alloc_coherent() of the whole power-of-2 ring size. Under\nmemory fragmentation these high-order allocations may fail, preventing\nthe driver from creating queues when opening the interface, after a VF\nreset, or when reconfiguring channels, ring parameters or MTU.\n\nPer-queue sizes that are problematic, with depth and size given as\n(default, max) over the ethtool ring settings:\n\n  ring                  entry  depth          size\n  ------------------------------------------------------------\n  TX completion queue   64 B   (256, 16384)   (16 KB, 1024 KB)\n  TX send queue         32 B   (256, 16384)   ( 8 KB,  512 KB)\n  RX completion queue   64 B   (1024, 8192)   (64 KB,  512 KB)\n  RX receive queue      32 B   (1024, 8192)   (32 KB,  256 KB)\n  event queue           16 B   2048 (fixed)   32 KB\n\nThis series addresses the issue by:\n  1. Routing all CPU-side ring access through mana_gd_ring_ptr() and\n     mana_gd_ring_contig_avail(). On a contiguous ring these reduce to\n     simple arithmetic, so this patch is a pure refactor.\n  2. Falling back in mana_gd_alloc_memory() to a vector of scattered\n     order-0 coherent pages when the contiguous allocation fails. The\n     device sees the same page-list format either way, as\n     mana_gd_create_dma_region() already describes a ring as a list of\n     MANA_PAGE_SIZE addresses. The HW channel stays contiguous, as\n     advertising a scattered page list needs the HW channel itself.\n\nThroughput testing confirms no regression. Since the fallback only\ntriggers under memory fragmentation, the scattered-page path was enabled\nunconditionally for all eligible GDMA queue rings during testing (iperf3,\nGbit/s):\n\n                 Baseline    Patched     Patched\n  Connections   Contiguous  Contiguous  Scattered\n  -----------------------------------------------\n  1                  46.1        46.2       46.1\n  16                 182         182        182\n  32                 182         182        182\n  64                 182         182        182\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807210002.1695263-1-gargaditya@linux.microsoft.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "23adfc77c22cb959ac84e08dc8a77bac656f1caa",
      "tree": "a91df54b31dc49bc9d158dcb838daaa60f882d07",
      "parents": [
        "1da1a037bc60c3744a6cdcb7610917a20ba1a318"
      ],
      "author": {
        "name": "Aditya Garg",
        "email": "gargaditya@linux.microsoft.com",
        "time": "Fri Aug 07 13:56:36 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:42:48 2026 +0200"
      },
      "message": "net: mana: Fall back to scattered pages for GDMA queues\n\nEach GDMA queue ring is one dma_alloc_coherent() of the whole ring size.\nSuch high-order allocations fail first under memory fragmentation, so\nqueue setup can fail with memory still free.\n\nThe hardware does not need the ring physically contiguous:\nmana_gd_create_dma_region() already maps it as a list of MANA_PAGE_SIZE\n(4K) device addresses. Only the driver\u0027s linear CPU view needs\ncontiguity, and it goes through mana_gd_ring_ptr() and\nmana_gd_ring_contig_avail(); change both to map offsets onto\nscattered pages.\n\nAdd a fallback in mana_gd_alloc_memory(): data-path queues pass\nallow_scatter\u003dtrue, so when the contiguous allocation fails the ring is\nbacked by a vector of scattered PAGE_SIZE (order-0) coherent pages,\npresenting the same DMA page-list layout to the device. The HW channel\nbootstrap keeps allow_scatter\u003dfalse, and the debugfs ring dumper reads\nscattered rings through the same helpers.\n\nSigned-off-by: Aditya Garg \u003cgargaditya@linux.microsoft.com\u003e\nLink: https://patch.msgid.link/20260807210002.1695263-3-gargaditya@linux.microsoft.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "1da1a037bc60c3744a6cdcb7610917a20ba1a318",
      "tree": "36be7d78156b0aff05a62a618babf0a46df448a6",
      "parents": [
        "03a105c83243a8c9cc147a44a7ec7bfd4c10ee8c"
      ],
      "author": {
        "name": "Aditya Garg",
        "email": "gargaditya@linux.microsoft.com",
        "time": "Fri Aug 07 13:56:35 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:42:48 2026 +0200"
      },
      "message": "net: mana: Route ring-buffer access through offset-based helpers\n\nIn preparation for backing GDMA queue memory with a vector of\nnon-contiguous order-0 coherent pages, route CPU access to a queue\u0027s\nring buffer through two new helpers: mana_gd_ring_ptr() returns the CPU\naddress of a byte offset into the ring, and mana_gd_ring_contig_avail()\nthe number of bytes left before the ring wraps, so a WQ write that runs\npast the end of the ring can be split at that point.\n\nConvert the EQ, CQ and work-request paths to use them.\nmana_gd_write_sgl() now takes a byte offset rather than a raw pointer,\nso mana_gd_post_work_request() derives the SGL position arithmetically.\n\nWhile queue memory is contiguous both helpers are simple arithmetic on\nthe ring base and size, so there is no functional change.\n\nSigned-off-by: Aditya Garg \u003cgargaditya@linux.microsoft.com\u003e\nLink: https://patch.msgid.link/20260807210002.1695263-2-gargaditya@linux.microsoft.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "03a105c83243a8c9cc147a44a7ec7bfd4c10ee8c",
      "tree": "3359112e0cadf291a6cf46f75d66e8a53c2dc31e",
      "parents": [
        "379122479ba7b30daa6c858a254316f2bcd13240"
      ],
      "author": {
        "name": "Michael Guralnik",
        "email": "michaelgur@nvidia.com",
        "time": "Tue Aug 11 09:16:37 2026 +0300"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:34:37 2026 +0200"
      },
      "message": "net/mlx5: rsc_dump and hv_vhca return NULL on create error\n\nAll callers of these create functions treat NULL and ERR_PTR as\nequivalent error cases. Align the return convention to NULL-on-failure\nto simplify the checks at usage sites.\n\nSince its return value is never checked and failure is non-fatal, change\nhv_vhca init function to return void.\n\nSigned-off-by: Michael Guralnik \u003cmichaelgur@nvidia.com\u003e\nReviewed-by: Shay Drori \u003cshayd@nvidia.com\u003e\nSigned-off-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260811061637.3195320-1-tariqt@nvidia.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "379122479ba7b30daa6c858a254316f2bcd13240",
      "tree": "9f6fa99a0667a33fbb6d1c951c88bf243ea7e3a4",
      "parents": [
        "68b3d4dbaf20539fc3268a2def90aa5e3b79bcb9",
        "0abc76bc20826e2582c4589e43b7fb8f3612911c"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:12:24 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:12:25 2026 +0200"
      },
      "message": "Merge branch \u0027net-sysctl-const-qualify-sysctl-ctl_table-arrays\u0027\n\nJoel Granados says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: sysctl: Const Qualify sysctl ctl_table arrays\n\nWhat?\n\u003d\u003d\u003d\u003d\u003d\nWe do two things:\n1. Reject netns-unsafe: Replace warning and file permission change with\n   an error (reject registration) when an \"unsafe\" net sysctl\n   registration is detected.\n2. Const qualify: Const qualify network templated ctl_table arrays and\n   unconditional kmemdup\u0027ed ctl_table arrays.\n\nWhy?\n\u003d\u003d\u003d\u003d\nThe main motivation for this is to continue with the const qualification\nof the ctl_table arrays [1]. The permission change inside\nensure_safe_net_sysctl disallows cons qualifiaction as it basically\nmodifies the entries before running the sysctl registration.\n\n      ent-\u003emode \u0026\u003d ~0222;\n\nOn reject netns-unsafe?\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n* I believe that there is currently now way that the permission change\n  gets executed [2]\n* I found one case where the warning message was posted to lore\n  (vsock_sysctl_register) [3], but it made its to mainline as part of\n  the second case in [2].\n* We should error anyway because writing to the global sysctl value\n  through a child netns is indicative of a bug [4].\n\nOn Const qualification?\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nWe can separate the places where network registers sysctl tables into\nthree groups:\n1. Static global: The unchanged global static arrays are passed along to\n   sysctl register.\n2. Always kmemdup: The global static arrays are always kmemdup\u0027ed before\n   passing them along to sysctl register.\n3. Dynamic global: The global static array is changed in place before\n   passing it along to sysctl register.\n\nThis series handles case 1 and 2. It leaves 3 for a later point as\nconst qualifying those global ctl_tables is more involved.\n\nI would be very thankful if you point me to anything that I have missed\nin my analysis that shows that this cannot/shouldn\u0027t be done.\n\n[1]\n  https://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl.git/commit/?h\u003dconstfy-sysctl-6.14-rc1\u0026id\u003d1751f872cc97f992ed5c4c72c55588db1f0021e1\n\n[2]\n  I have identified 4 contexts relevant to the ensure_safe_net_sysctl call\n  inside the network sysctl registration.\n\n  1. When the (struct net) \u003d\u003d \u0026init_net (like in iw_cm_init): In this case\n     ensure_safe_net_sysctl is not executed and permission modification\n     never happens.\n\n  2. When the ctl_table data (-\u003edata) gets \"manually\" assigned to\n     something other init_net (like in vsock_sysctl_register): In this\n     case ensure_safe_net_sysctl *is* executed but the data that is passed\n     is neither a module address (!is_module_address) nor a kernel core\n     address (!is_kernel_core_data); so the permission modification never\n     happens.\n\n  3. When the permissions are explicitly changed on a kmemdup\u0027ed ctl_table\n     array (like in sysctl_core_net_init): in this case\n     ensure_safe_net_sysctl *is* executed but the permission modification\n     never happens as the mode is not writable.\n\n  4. When ctl have custom proc_handlers (like in nf_lwtunnel_net_init): In\n     this case -\u003edata is NULL so it is not a module address\n     (!is_module_address) nor a kernel core address\n     (!is_kernel_core_data), so permission modification never happens.\n\n  It seems like there is no way of executing the permission change in\n  ensure_safe_net_sysctl. Please correct me if this is inaccurate and help\n  me find the case that I missed.\n\n[3]\n  https://lore.kernel.org/all/20260302194926.90378-1-graf@amazon.com/\n\n[4]\n  The ensure_safe_net_sysctl function was introduced in Commit:\n  31c4d2f160eb7b17cbead24dc6efed06505a3fee (\"net: Ensure net namespace\n  isolation of sysctls\") which states that it is trying to prevent a\n  leak (indicative of a bug).\n\n[5]\n  https://patchwork.kernel.org/project/netdevbpf/patch/20260713-jag-net_const_qualify-v3-1-7289fe9eaea6@kernel.org/\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260810-jag-net_const_qualify-v4-0-77e888237c69@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "0abc76bc20826e2582c4589e43b7fb8f3612911c",
      "tree": "9f6fa99a0667a33fbb6d1c951c88bf243ea7e3a4",
      "parents": [
        "09190c59cd101e0bf87a1c5a32ebae25c91e6d81"
      ],
      "author": {
        "name": "Joel Granados",
        "email": "joel.granados@kernel.org",
        "time": "Mon Aug 10 15:01:04 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:12:24 2026 +0200"
      },
      "message": "net: Const qualify network templated ctl_tables Arrays\n\nAdd duplication helpers in the cases where the ctl_table array elements\nare modified after duplication. Helpers return a ctl_table as const\npointer allowing the const qualification of the static global ctl_table\narray.\n\nSigned-off-by: Joel Granados \u003cjoel.granados@kernel.org\u003e\nLink: https://patch.msgid.link/20260810-jag-net_const_qualify-v4-3-77e888237c69@kernel.org\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "09190c59cd101e0bf87a1c5a32ebae25c91e6d81",
      "tree": "9425d8880a7c77a172f103c7693169fded00d39f",
      "parents": [
        "ef6cb145e216b0378686bce356f3317284d54231"
      ],
      "author": {
        "name": "Joel Granados",
        "email": "joel.granados@kernel.org",
        "time": "Mon Aug 10 15:01:03 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:12:24 2026 +0200"
      },
      "message": "net: Const qualify ctl_tables that kmemdup unconditionally\n\nConst qualify clt_table arrays in the net directory that always pass a\nmemory duplicate to sysctl register. The template would then be in\n.rodata and the kmemdup\u0027ed array would be outside.\n\nSigned-off-by: Joel Granados \u003cjoel.granados@kernel.org\u003e\nLink: https://patch.msgid.link/20260810-jag-net_const_qualify-v4-2-77e888237c69@kernel.org\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "ef6cb145e216b0378686bce356f3317284d54231",
      "tree": "ec58eb5ebb5d26b311f0d781a6b5f7bd3bb4035b",
      "parents": [
        "68b3d4dbaf20539fc3268a2def90aa5e3b79bcb9"
      ],
      "author": {
        "name": "Joel Granados",
        "email": "joel.granados@kernel.org",
        "time": "Mon Aug 10 15:01:02 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 13:12:21 2026 +0200"
      },
      "message": "net: enforce net sysctl registration\n\nReplace the warning and file permission change with an error when an\n\"unsafe\" net sysctl registration is detected.\n\nOne of the barriers preventing the const qualification of the ctl_tables\nin the net directory is the permission (-\u003emode) change in\nensure_safe_net_sysctl. This prep commit removes that barrier and\nensures that the received ctl_table pointer to the net ctl_table\nregister function is const.\n\nSigned-off-by: Joel Granados \u003cjoel.granados@kernel.org\u003e\nLink: https://patch.msgid.link/20260810-jag-net_const_qualify-v4-1-77e888237c69@kernel.org\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "68b3d4dbaf20539fc3268a2def90aa5e3b79bcb9",
      "tree": "114fdaeacbb8e816c5642a117065f0de890cbe3b",
      "parents": [
        "782de55a8f6b907cf72a4f36ec3933d6b095f56c"
      ],
      "author": {
        "name": "Allison Henderson",
        "email": "achender@kernel.org",
        "time": "Sun Aug 09 22:56:31 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:53:14 2026 +0200"
      },
      "message": "net/rds: clear i_rx_lat_trace in rds_inc_path_init()\n\nThe commit that introduced the receive-path latency trace added the\nclearing of inc-\u003ei_rx_lat_trace[] to rds_inc_init() only;\nrds_inc_path_init() never got it.\n\nThat asymmetry matters for the one caller that reuses memory:\nrds_tcp_data_recv() carves its rds_tcp_incoming out of a kmem_cache\nwith no zeroing and no constructor, so after rds_inc_path_init() the\narray still holds the timestamps of whatever message previously\noccupied that slab object.  No stale value is user-visible today -\nevery message that reaches the socket happens to overwrite all four\nslots (RX_HDR at allocation, RX_START when the header completes,\nRX_END at delivery, RX_CMSG at recvmsg time) before\nRDS_CMSG_RXPATH_LATENCY reads them back as deltas - but that is a\nproperty of the current writers, not of the init contract, and a\nfuture trace point or an early-exit path would expose another\nmessage\u0027s timestamps to userspace.\n\nClear the array in rds_inc_path_init() too, so both init helpers\nleave the inc fully initialized.  memset is the form the clearing\nalready takes on the rds_inc_init() side since commit 1635bb548f84\n(\"net: rds: use memset to optimize the recv\").  Hardening only; no\nuser-visible bug in the current code.\n\nAssisted-by: Claude-Code:claude-fable-5\nSigned-off-by: Allison Henderson \u003cachender@kernel.org\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260810055631.299558-1-achender@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "782de55a8f6b907cf72a4f36ec3933d6b095f56c",
      "tree": "2534b99de1a1d17844a71358f7f8cc37b8f161a5",
      "parents": [
        "2f886609bd9a9084d66315a8b9967c6c8da8dc5e",
        "ff8376b2458d9026a51c615075e2d77e79757f31"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:52:31 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:52:31 2026 +0200"
      },
      "message": "Merge branch \u0027net-rds-bug-fix-ports-part-2\u0027\n\nAllison Henderson says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet/rds: Bug fix ports, part 2\n\nThis is the next batch of net/rds fixes ported from the Oracle UEK\nkernel, following up on the first set now in net-next [1].\n\nThis is v2 of patches 1 and 2 of \"net/rds: Bug fix ports, part 2\"\n[2], which contained two initialization-hardening ports.  While\nre-reviewing v1\u0027s patches 3 and 4 (the fastpath-lock teardown changes)\nI found their locking needs more rework than a respin should carry, so\nthey are split out and will return as their own series together with\ntwo companion fixes.  The two patches here are independent of them.\n\n[PATCH net 1/2] net/rds: reinitialize to_be_dropped on rds_send_xmit() restart\n  Port commit 7f52b9968d79 (\"net/rds: rds_send_xmit should INIT_LIST_HEAD (\u0026to_be_dropped) on restart\")\n  https://github.com/oracle/linux-uek/commit/7f52b9968d79\n\n[PATCH net 2/2] net/rds: initialize i_conn_path in rds_inc_init()\n  Port commit 0ec6a520da4f (\"rds: rds_inc_init() should initialize the inc-\u003ei_conn_path field\")\n  https://github.com/oracle/linux-uek/commit/0ec6a520da4f\n\nQuestions and comments appreciated!\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260809005103.82371-1-achender@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "ff8376b2458d9026a51c615075e2d77e79757f31",
      "tree": "2534b99de1a1d17844a71358f7f8cc37b8f161a5",
      "parents": [
        "a364a7c168d0a0b9fccee01669ceb9bb7b844056"
      ],
      "author": {
        "name": "William Kucharski",
        "email": "william.kucharski@oracle.com",
        "time": "Sat Aug 08 17:51:03 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:52:29 2026 +0200"
      },
      "message": "net/rds: initialize i_conn_path in rds_inc_init()\n\nrds_inc_init() initializes every field of the embedded rds_incoming\nexcept i_conn_path, and incomings are not zero-allocated (IB carves\nthem out of a slab cache).  The field therefore holds stale garbage\nfor incs created by rds_ib.\n\nThe loopback transport is different: rds_loop_xmit() re-runs\nrds_inc_init() on the message\u0027s embedded inc after\nrds_send_queue_rm() has already stored the connection path in it, so\nthere the field holds a live value rather than garbage, and a NULL\nstore would discard it.  Switch rds_loop_xmit() to\nrds_inc_path_init() with the connection\u0027s single path, which is\nexactly the value readers of the field reconstruct for a\nnon-multipath transport.\n\nWith loopback preserving the field, initialize it to NULL in\nrds_inc_init() so that any future reader trips over a clean NULL\npointer instead of a stale one, and so the two init helpers\n(rds_inc_init/rds_inc_path_init) leave the structure in an\nequivalent, fully-initialized state.  Hardening only; no reader\ndereferences i_conn_path for a non-multipath transport today.\n\nThis mirrors Oracle UEK commit \"rds: rds_inc_init() should initialize\nthe inc-\u003ei_conn_path field\".\n\nSigned-off-by: William Kucharski \u003cwilliam.kucharski@oracle.com\u003e\n[achender: port to net-next; keep loopback\u0027s i_conn_path valid by\n switching rds_loop_xmit() to rds_inc_path_init(); update commit\n message]\nAssisted-by: Claude-Code:claude-fable-5\nSigned-off-by: Allison Henderson \u003cachender@kernel.org\u003e\nLink: https://patch.msgid.link/20260809005103.82371-3-achender@kernel.org\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "a364a7c168d0a0b9fccee01669ceb9bb7b844056",
      "tree": "0514d1e0f2437ca78fabfa4168b8997308d5faf3",
      "parents": [
        "2f886609bd9a9084d66315a8b9967c6c8da8dc5e"
      ],
      "author": {
        "name": "Sharath Srinivasan",
        "email": "sharath.srinivasan@oracle.com",
        "time": "Sat Aug 08 17:51:02 2026 -0700"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:52:29 2026 +0200"
      },
      "message": "net/rds: reinitialize to_be_dropped on rds_send_xmit() restart\n\nThe to_be_dropped list is declared once at the top of rds_send_xmit()\nbut the function can loop via \"goto restart\" after each batch.  The\ncode currently relies on rds_send_remove_from_sock() having emptied\nthe list entry by entry (via list_del_init()) at the end of the\nprevious batch; nothing in rds_send_xmit() itself guarantees the list\nhead is empty when a new batch starts.\n\nRe-initialize the list on every restart, and warn once if it is ever\nfound non-empty there: entries left on the list at that point would\nkeep their message reference, their RDS_MSG_ON_SOCK accounting and\ntheir pending RDS_RDMA_DROPPED notification, so a silent re-init\nwould orphan them.  This is hardening: no user-visible bug is known\nin the current code.\n\nThis mirrors Oracle UEK commit \"net/rds: rds_send_xmit should\nINIT_LIST_HEAD(\u0026to_be_dropped) on restart\".\n\nSigned-off-by: Gerd Rausch \u003cgerd.rausch@oracle.com\u003e\nSigned-off-by: Sharath Srinivasan \u003csharath.srinivasan@oracle.com\u003e\n[achender: port to net-next (keep the existing LIST_HEAD declaration and\n add only the restart re-init); warn if the restart invariant is\n violated; update commit message]\nAssisted-by: Claude-Code:claude-fable-5\nSigned-off-by: Allison Henderson \u003cachender@kernel.org\u003e\nLink: https://patch.msgid.link/20260809005103.82371-2-achender@kernel.org\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "2f886609bd9a9084d66315a8b9967c6c8da8dc5e",
      "tree": "86b1e9606e8871d184c580c88101b19b9b7285f3",
      "parents": [
        "f6057f06ef7afa9893ed33603f7917fa39d237b5",
        "046d883265068cac3a5122335cd4abf1b9be38c1"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:29 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:30 2026 +0200"
      },
      "message": "Merge branch \u0027ipv6-report-why-a-route-was-deleted-in-rtm_delroute\u0027\n\nYuyang Huang says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nipv6: report why a route was deleted in RTM_DELROUTE\n\nWhen the kernel deletes an IPv6 route on its own, the RTM_DELROUTE\nnotification does not say why. User space cannot tell a route that\nexpired from one the router explicitly withdrew, yet the two call for\ndifferent reactions: an expired RA route means the router failed to\nrefresh it in time, which points at a misconfigured or unreliable\nrouter and may warrant action such as disabling IPv6 on that network,\nwhile a zero-lifetime withdrawal is normal, RFC-compliant operation.\n\nThis is a general problem for any consumer device running Linux,\nespecially on Wi-Fi networks, where multicast delivery is not\nguaranteed (e.g. frames can be lost around DTIM for clients in power\nsave mode). The motivating case is Android: the userspace NetworkStack\nprocess listens on RTMGRP_IPV6_ROUTE and today treats any loss of the\nIPv6 default route as \"router lost\". To avoid the device repeatedly\ngaining and losing IPv6 connectivity on a badly configured network,\nwhen it detects the device is on a dual-stack network with working\nIPv4 connectivity, it defensively clears accept_ra_defrtr and restarts\nIPv6, so user space apps stop using broken global IPv6 connectivity\nwhile link-local IPv6 keeps working. That reaction is wrong if the\nroute was withdrawn by a zero-lifetime RA (some ISPs do this\nintentionally for reconfiguration) - with accept_ra_defrtr off, IPv6\nnever recovers once the router advertises again. It is the right\nreaction if the route genuinely expired, since the router failed to\nrefresh it in time.\n\nFixing this in user space is not practical: RTM_NEWROUTE carries the\ninitial route lifetime (in rta_cacheinfo), but the kernel does not\nresend it when a later RA refreshes the lifetime. So distinguishing\nthe cause of an RTM_DELROUTE from user space would mean opening a raw\nsocket, listening to RAs, and tracking lifetimes independently,\nduplicating logic the kernel already has. Sending RTM_NEWROUTE on\nevery RA lifetime refresh was also considered, but that would be\nspammy and is technically wrong, since a lifetime update does not add\na new route.\n\nThis series proposes RTA_DEL_REASON instead: it tells user space why\nthe route was deleted so it can react accordingly. In the Android\ncase, NetworkStack would defensively disable global IPv6 only on\nRT_DEL_REASON_EXPIRED, and take no action on\nRT_DEL_REASON_RA_WITHDRAWN, since that is RFC-compliant behavior.\n\nPatches 1 to 6 add RTA_DEL_REASON and enum rt_del_reason to the\nrtnetlink uAPI, thread the reason from the kernel-initiated IPv6\ndeletion paths down to the RTM_DELROUTE notification, and record the\ncause: RT_DEL_REASON_EXPIRED for routes garbage collected after their\nRTF_EXPIRES lifetime ran out, and RT_DEL_REASON_RA_WITHDRAWN for\ndefault routes, prefix routes and RFC 4191 route information routes\nwithdrawn by Router Advertisements. Patches 1 to 5 are no-ops on the\nwire; the attribute first appears in patch 6. The route addition path\nis not touched.\n\nPatches 7 to 9 extend the rt-route Netlink spec with the route\nnotifications and their multicast groups, split the newroute and\ndelroute request attribute lists out of the shared getroute reply\nlist, and add the new attribute and its enum.\n\nOnly kernel-initiated deletions that user space cannot otherwise\nexplain are attributed. User-requested deletions are self-explanatory\nto the requester, so they carry no reason; the UAPI documents that\nabsence and RT_DEL_REASON_UNSPEC must be treated identically, which\nkeeps the door open for attributing more paths (nexthop removal\ncascades, device removal) later.\n\nPatch 10 adds selftests covering all three producer paths: a\nGC-expired route, and a default route + PIO prefix route + RIO route\nadvertised and then withdrawn by hand-crafted RAs over a raw ICMPv6\nsocket (no external RA tool needed), plus a check that user-requested\ndeletions carry no attribute. The notifications are decoded with YNL,\nwhich also exercises the rt-route spec additions.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260808005642.26901-1-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "046d883265068cac3a5122335cd4abf1b9be38c1",
      "tree": "86b1e9606e8871d184c580c88101b19b9b7285f3",
      "parents": [
        "b13ba4e82bfd5ab8318ae75d545cf3c23abf7a6b"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:42 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:28 2026 +0200"
      },
      "message": "selftests: net: verify RTA_DEL_REASON on route deletion\n\nExtend rtnetlink.py to check the reason reported in RTM_DELROUTE:\n\n- expired: route with a 2s lifetime collected by the fib6 GC\n  (gc_interval lowered like fib_tests.sh fib6_gc_test does);\n- ra-withdrawn: a single RA advertises a default route (router\n  lifetime), an on-link prefix route (RFC 4861 prefix information\n  option) and a route information option route (RFC 4191), then a\n  second RA withdraws all three with zero lifetimes; the RAs are\n  crafted over a raw ICMPv6 socket so the test does not depend on an\n  external RA tool;\n- absence: a userspace deletion request records no cause and must not\n  carry the attribute at all.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-11-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b13ba4e82bfd5ab8318ae75d545cf3c23abf7a6b",
      "tree": "775212976fafb6c5498417eaee19813b5ce06d54",
      "parents": [
        "8621a7ed80f00f83a6741ad8bd1e1c500d2c5b74"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:41 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "netlink: specs: rt-route: add the route deletion reason\n\nAdd the del-reason attribute and its enum to the route attribute set,\nand to the getroute reply, which the route notifications reuse.\n\nThe attribute is absent from the newroute and delroute request lists.\nRTA_DEL_REASON is above strict_start_type in rtm_ipv6_policy, so\nencoding it in a request is rejected with -EINVAL.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-10-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "8621a7ed80f00f83a6741ad8bd1e1c500d2c5b74",
      "tree": "9b83c23b02d3ee6cd818459dadba15698d2739f8",
      "parents": [
        "bf517422fb26d36f0bdcc4a8e38837b4de675535"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:40 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "netlink: specs: rt-route: split out the request attribute list\n\nThe newroute and delroute requests alias the same attribute list as the\ngetroute reply, but requests and replies do not carry the same\nattributes. Give the requests their own list.\n\nThe two lists are identical today, so the generated code does not\nchange.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-9-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "bf517422fb26d36f0bdcc4a8e38837b4de675535",
      "tree": "5b5b7b7cd66b1ec3a7c405195e01e8d1269c5514",
      "parents": [
        "09f19ce3de67deb859cd95315d55a69a6ca45b40"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:39 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "netlink: specs: rt-route: add route notifications\n\nDeclare the RTM_NEWROUTE and RTM_DELROUTE notifications and the route\nmulticast groups, so that generated clients can subscribe to route\nchanges. Both notifications reuse the getroute reply attributes.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-8-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "09f19ce3de67deb859cd95315d55a69a6ca45b40",
      "tree": "fdd1d31480a70a82970db94838e5ceb820127b63",
      "parents": [
        "1e6a83af59141b9caabb86a9d7d069ab696101e2"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:38 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: add inet6_rt_del_notify()\n\nMove the body of inet6_rt_notify() to __inet6_rt_notify() and give it\nthe deletion reason. inet6_rt_notify() keeps its prototype, so the\nroute addition path does not change.\n\nAdd inet6_rt_del_notify() and call it from fib6_del_route().\nRTA_DEL_REASON now reaches user space on RTM_DELROUTE for routes the\nkernel deleted on its own.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-7-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "1e6a83af59141b9caabb86a9d7d069ab696101e2",
      "tree": "be3b204cb60cdbbc67d243a1e05df4a438620e76",
      "parents": [
        "b0215102356bef144e1375aeb1633b37ec7999ad"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:37 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: expose the route deletion reason in RTM_DELROUTE\n\nEmit RTA_DEL_REASON from rt6_fill_node() when the deletion reason is\nnot RT_DEL_REASON_UNSPEC, and reserve room for it in\nrt6_nlmsg_size().\n\nEvery caller still passes RT_DEL_REASON_UNSPEC.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-6-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b0215102356bef144e1375aeb1633b37ec7999ad",
      "tree": "ee66311fc4bdff007d836b87ca629cc8ddde676e",
      "parents": [
        "e8636445b771c0936cf3c2fe3bbdb281b4cf6acf"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:36 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: add a deletion reason argument to rt6_fill_node()\n\nAdd the deletion reason to rt6_fill_node() so that it can report it to\nuser space. All callers pass RT_DEL_REASON_UNSPEC for now.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-5-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "e8636445b771c0936cf3c2fe3bbdb281b4cf6acf",
      "tree": "d91e41e20de17d97bbe128d261fbffcfad656981",
      "parents": [
        "352c6732ffb2c5a45a10096bfef13c343484c22f"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:35 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: record the reason for kernel-initiated route deletions\n\nRecord why the kernel deletes an IPv6 route on its own:\n\n- RT_DEL_REASON_EXPIRED for routes reaped by the FIB6 garbage\n  collector after their RTF_EXPIRES lifetime ran out.\n- RT_DEL_REASON_RA_WITHDRAWN for default routes, prefix routes and\n  RFC 4191 route information routes withdrawn by a zero-lifetime\n  Router Advertisement.\n\nDeleting a default route because its metric changed is not a\nwithdrawal, so it keeps RT_DEL_REASON_UNSPEC.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-4-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "352c6732ffb2c5a45a10096bfef13c343484c22f",
      "tree": "76e6a147c2e8090cfd342e4e7f7860258d746844",
      "parents": [
        "cc17e386f8a5fc23a3bf49a45d17cd45b49fbb01"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:34 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: propagate the route deletion reason to fib6_del_route()\n\nPass the deletion reason from ip6_del_rt_reason() down through\n__ip6_del_rt(), fib6_del() and into fib6_del_route(). All existing\ncallers pass RT_DEL_REASON_UNSPEC.\n\nfib6_del_route() ignores the reason until the notification path learns\nto report it.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-3-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "cc17e386f8a5fc23a3bf49a45d17cd45b49fbb01",
      "tree": "784d555f69554b7105316f8d6ff62accd137d80a",
      "parents": [
        "f6057f06ef7afa9893ed33603f7917fa39d237b5"
      ],
      "author": {
        "name": "Yuyang Huang",
        "email": "sigefriedhyy@gmail.com",
        "time": "Sat Aug 08 09:56:33 2026 +0900"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 12:30:27 2026 +0200"
      },
      "message": "ipv6: add ip6_del_rt_reason()\n\nAdd RTA_DEL_REASON and enum rt_del_reason to the rtnetlink uAPI, and\nadd ip6_del_rt_reason(), which takes the reason a route is being\ndeleted. It has no skip_notify argument: a caller that records a\ndeletion reason wants the notification that carries it.\n\nThe reason is unused for now. Subsequent patches propagate it to the\ndeletion path and report it on RTM_DELROUTE.\n\nSigned-off-by: Yuyang Huang \u003csigefriedhyy@gmail.com\u003e\nReviewed-by: Ido Schimmel \u003cidosch@nvidia.com\u003e\nLink: https://patch.msgid.link/20260808005642.26901-2-sigefriedhyy@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "9006c116dd111d457bf5d074990210f70a4ad2c8",
      "tree": "1e3e52af0001c78554a494b98e1a7e5fe62058c6",
      "parents": [
        "120977e2c096deea4e866e4273be9220b957c29e"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Aug 11 14:46:51 2026 +0000"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 11:49:31 2026 +0200"
      },
      "message": "l2tp: fix tunnel and session refcount leak on seq_file release\n\nIn pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state\n(pd-\u003etunnel and pd-\u003esession) is kept in seq_file private data to allow\niteration across multiple read() system calls.\n\nHowever, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels\nbefore reading to end-of-file (EOF), any tunnel or session reference stored in\npd-\u003etunnel / pd-\u003esession is left un-dropped when seq_file private data is freed.\n\nFix this by dropping any remaining pd-\u003etunnel and pd-\u003esession references in\npppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.\n\nFixes: 0e0c3fee3a59 (\"l2tp: hold reference on tunnels printed in pppol2tp proc file\")\nFixes: f726214d9b23 (\"l2tp: hold reference on tunnels printed in l2tp/tunnels debugfs file\")\nReported-by: syzbot+d6fa74e3f19d6ee01e3a@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6a760f32.01d0871a.3a0d52.004f.GAE@google.com/T/#u\nAssisted-by: Jetski:Gemini-3.1-Pro\nCc: James Chapman \u003cjchapman@katalix.com\u003e\nCc: Guillaume Nault \u003cgnault@redhat.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260811144651.2733424-1-edumazet@google.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "120977e2c096deea4e866e4273be9220b957c29e",
      "tree": "1a03859632a8800e49de9bbecf819e36b636bc4e",
      "parents": [
        "2bb155e92167cd5ad6aae312e83291da2454f8b0"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Sun Aug 09 05:44:18 2026 -0400"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 11:08:39 2026 +0200"
      },
      "message": "net/sched: cls_bpf: reject dev-bound programs bound to a different device\n\ncls_bpf_prog_from_efd() obtained a SCHED_CLS program via\nbpf_prog_get_type_dev() but never verified that a device-bound (offloaded)\nprogram\u0027s bound netdev matches the TC netdev the classifier is being\nattached to. This let a program loaded with prog_ifindex for device A be\nattached via cls_bpf + skip_sw to device B; deleting device A then\ndestroyed the program\u0027s offload state while it was still attached to\ndevice B, triggering a netdevsim WARN (panic with panic_on_warn\u003d1).\n\nMirror the XDP attach path (net/core/dev.c) and reject the attach with\n-EINVAL when a dev-bound program\u0027s bound device does not match the\ntarget device.\n\nFixes: 2b3486bc2d23 (\"bpf: Introduce device-bound XDP programs\")\nReported-by: vega@nebusec.ai\nTested-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nAcked-by: Daniel Borkmann \u003cdaniel@iogearbox.net\u003e\nLink: https://patch.msgid.link/20260809094418.901607-1-jhs@mojatatu.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f6057f06ef7afa9893ed33603f7917fa39d237b5",
      "tree": "9c4ac3cd2a8be11c39991d4be7db119ed7c96593",
      "parents": [
        "9b20885f147287bc13deef55effe7a400a9561aa",
        "02aee8ebea3a714d92b27da9a9d8791d8c8c9a4f"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:51:40 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:51:41 2026 -0700"
      },
      "message": "Merge tag \u0027batadv-next-pullrequest-20260805\u0027 of https://git.open-mesh.org/batadv\n\nSimon Wunderlich says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nThis cleanup patchset includes the following patches:\n\n - dat: drop non-4addr backwards compatibility, by Sven Eckelmann\n\n - tvlv: handle negative tvlv processing return codes,\n   by Sven Eckelmann\n\n - improve kernel-doc, add comments and warnings,\n   by Sven Eckelmann (3 patches)\n\n - coding style: split declarations, reverse x-mas tree,\n   by Sven Eckelmann (2 patches)\n\n - handle errors in batadv_init(), by Minhong He\n\n - correct NET_RX_* NET_XMIT_* confusion, by Sven Eckelmann\n\n - remove negative returns for batadv_send_skb_unicast,\n   by Sven Eckelmann\n\n* tag \u0027batadv-next-pullrequest-20260805\u0027 of https://git.open-mesh.org/batadv:\n  batman-adv: remove negative returns for batadv_send_skb_unicast\n  batman-adv: correct NET_RX_* NET_XMIT_* confusion\n  batman-adv: handle errors in batadv_init()\n  batman-adv: switch var declarations to reverse x-mas tree order\n  batman-adv: split multiple declarations per line\n  batman-adv: annotate functions which may reallocate the skbuff\n  batman-adv: fix kernel-doc for functions holding skb ownership\n  batman-adv: add missing kernel-doc comments\n  batman-adv: tvlv: handle negative tvlv processing return codes\n  batman-adv: dat: drop non-4addr backwards compatibility\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260805143200.722098-1-sw@simonwunderlich.de\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9b20885f147287bc13deef55effe7a400a9561aa",
      "tree": "7bfc3c1df865c56d1315f863ef06df13faad83b1",
      "parents": [
        "d77f3f01682688ff5db18f027f66c34b4b39e1ac"
      ],
      "author": {
        "name": "Ziran Zhang",
        "email": "zhangcoder@yeah.net",
        "time": "Wed Aug 05 21:19:27 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:24:31 2026 -0700"
      },
      "message": "tcp: clarify comment for mdev_us in struct tcp_sock\n\nThe existing comment for mdev_us says \"medium deviation\", but this\nterm is inaccurate. The field stores the \"mean deviation\" of RTT,\nas originally defined in Van Jacobson\u0027s paper \"Congestion\nAvoidance and Control\", and it is scaled by 4 (\u003c\u003c 2) in the Linux\nimplementation.\n\nUpdate the comment to reflect the correct terminology and storage\nformat.\n\nSigned-off-by: Ziran Zhang \u003czhangcoder@yeah.net\u003e\nReviewed-by: Fernando Fernandez Mancera \u003cfmancera@suse.de\u003e\nLink: https://patch.msgid.link/20260805131927.27661-1-zhangcoder@yeah.net\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2bb155e92167cd5ad6aae312e83291da2454f8b0",
      "tree": "bd07c87070eb72f83f62a12942f451b0215ba99a",
      "parents": [
        "8c283e7b56adce00193837f3311b06662466fb21",
        "2da3dfa1ddfe55a065f484750c83660e3bd4ac00"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:09:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:09:18 2026 -0700"
      },
      "message": "Merge tag \u0027ovpn-net-20260809\u0027 of https://github.com/OpenVPN/ovpn-net-next\n\nAntonio Quartulli says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nIncluded fixes:\n\n* release key slot crypto transforms from a workqueue rather than an RCU\n  callback, because crypto_free_aead() may sleep with async or hardware\n  implementations\n* run all deferred ovpn work on a module-owned workqueue and drain it on\n  module exit, so no work item can still be executing module text after\n  the module is unloaded\n* finish crypto callback cleanup (key slot release and leftover skb)\n  before dropping the peer reference that gates netdev unregistration\n  and module removal\n* avoid dereferencing a NULL key slot when userspace asks to kill a key\n  that is not installed on the peer\n\n* tag \u0027ovpn-net-20260809\u0027 of https://github.com/OpenVPN/ovpn-net-next:\n  ovpn: defer key slot crypto freeing to workqueue\n  ovpn: run deferred work on a module-owned workqueue\n  ovpn: finish crypto callback cleanup before peer release\n  ovpn: fix NULL dereference when killing missing key\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260809212142.2249027-1-antonio@openvpn.net\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "8c283e7b56adce00193837f3311b06662466fb21",
      "tree": "342de931e60235a1f5c5be678e5c7c4b2c1f7db8",
      "parents": [
        "36a05d2820077bb3955acb8111e1041d39148037"
      ],
      "author": {
        "name": "Yuxiang Yang",
        "email": "yangyx22@mails.tsinghua.edu.cn",
        "time": "Sun Aug 09 12:38:06 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:54:42 2026 -0700"
      },
      "message": "sctp: fix use-after-free of cached ASCONF chunk\n\naddip_last_asconf caches the outstanding outbound ASCONF chunk. The normal\nASCONF-ACK completion path releases the chunk and clears the pointer.\n\nHowever, sctp_asconf_queue_teardown() releases the cached chunk without\nclearing addip_last_asconf. During peer restart handling,\nsctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes\nsctp_asconf_queue_teardown() while the association remains alive and leaves\nthe pointer dangling.\n\nA delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),\nwhich accesses the stale chunk and passes it to sctp_process_asconf_ack(),\ncausing a use-after-free and a second release.\n\nClearing the pointer exposes a race with T4 expiry. Peer restart handling\nqueues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses\ntimer_delete(), which does not wait for a callback already running on\nanother CPU. Such a callback can reach sctp_sf_t4_timer_expire() after\nthe purge and dereference NULL.\n\nClear addip_last_asconf after releasing the cached chunk, and make\nsctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding\nASCONF remains.\n\nFixes: a000c01e60e4 (\"sctp: stop pending timers and purge queues when peer restart asoc\")\nCc: stable@vger.kernel.org\nSuggested-by: Xin Long \u003clucien.xin@gmail.com\u003e\nSigned-off-by: Yuxiang Yang \u003cyangyx22@mails.tsinghua.edu.cn\u003e\nAcked-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260809043806.2768302-1-yangyx22@mails.tsinghua.edu.cn\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "d77f3f01682688ff5db18f027f66c34b4b39e1ac",
      "tree": "cbf1ff9f27da5983d6d21b40dd4a3b236b2683d9",
      "parents": [
        "dbf34acdfb29781dd4a8a86f7111d99c016fc7e8"
      ],
      "author": {
        "name": "Karl Mehltretter",
        "email": "kmehltretter@gmail.com",
        "time": "Sat Aug 08 12:19:41 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:51:37 2026 -0700"
      },
      "message": "r8169: give RTL_GIGA_MAC_VER_EXTENDED a distinct value\n\nRTL_GIGA_MAC_VER_EXTENDED implicitly follows\nRTL_GIGA_MAC_VER_LAST \u003d RTL_GIGA_MAC_NONE - 1, so it has the same value\nas RTL_GIGA_MAC_NONE.\n\nrtl_init_one() therefore sends unknown chips through extended detection.\nIf TX_CONFIG_V2 reads as zero, they are misidentified as RTL9151AS\ninstead of being rejected.\n\nGive RTL_GIGA_MAC_VER_EXTENDED a distinct value. It is only a detection\nmarker and is never stored in tp-\u003emac_version.\n\nFound by Clang\u0027s -Wduplicate-enum and verified with a QEMU stub.\n\nCc: stable+noautosel@kernel.org # untested fix to unlikely driver error path\nSigned-off-by: Karl Mehltretter \u003ckmehltretter@gmail.com\u003e\nLink: https://patch.msgid.link/20260808101941.57666-1-kmehltretter@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "36a05d2820077bb3955acb8111e1041d39148037",
      "tree": "b5a34b99f6eab19cb5371c702adc3772300d5ff7",
      "parents": [
        "beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3"
      ],
      "author": {
        "name": "Siddharth Vadapalli",
        "email": "s-vadapalli@ti.com",
        "time": "Fri Aug 07 16:47:37 2026 +0530"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:36:19 2026 -0700"
      },
      "message": "net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n\nOn the packet reception path, the ID of the MAC Port on which the packet\nwas received, is embedded in the RX DMA Descriptor\u0027s metadata. The ID is\nextracted using the helper function cppi5_desc_get_tags_ids() which fills\nin the 16-bit Source Tag into the \u0027port_id\u0027 variable. However, it is only\nthe lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,\nwhile the upper 8-bits are Hardware-Reserved and carry an arbitrary value.\nWith the existing logic, sporadic kernel crash is observed due to the\nsubsequent driver code accessing out-of-bound memory because of an invalid\nport_id.\n\nHence, fix the port_id extraction logic to use only the lower 8-bits of the\nSource Tag as the MAC Port ID.\n\nFixes: 93a76530316a (\"net: ethernet: ti: introduce am65x/j721e gigabit eth subsystem driver\")\nSigned-off-by: Siddharth Vadapalli \u003cs-vadapalli@ti.com\u003e\nReviewed-by: Chintan Vankar \u003cc-vankar@ti.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260807111738.2055900-1-s-vadapalli@ti.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3",
      "tree": "32fbbeb4bde8d572cf3f1aa2b6a9ae2b1129046a",
      "parents": [
        "9e6869be49064915edb6c8776b27c376cfdb0df5"
      ],
      "author": {
        "name": "Qing Ming",
        "email": "a0yami@mailbox.org",
        "time": "Tue Aug 11 23:28:03 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:21:37 2026 -0700"
      },
      "message": "sctp: clear new_transport when removing a peer\n\nsctp_process_asconf_param() stores a newly added peer transport in\nasoc-\u003enew_transport. After all parameters in the ASCONF chunk have been\nprocessed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the\nnew transport.\n\nAn authenticated ASCONF from a remote SCTP peer can add a transport and\nremove it again with a wildcard DEL-IP parameter in the same chunk. The\nwildcard deletion preserves the transport on which the ASCONF arrived, but\nremoves the newly added transport through\nsctp_assoc_del_nonprimary_peers(). The removal does not clear\nasoc-\u003enew_transport, leaving it pointing to the removed transport.\n\nsctp_sf_do_asconf() then creates a HEARTBEAT whose chunk-\u003etransport points\nto the removed transport without holding a transport reference. During\nlocal address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on\ncontrol_chunk_list. After the transport is freed by RCU, a successful\nASCONF_ACK for the replacement address releases the queued HEARTBEAT and\nsctp_outq_select_transport() reads the freed transport\u0027s state.\n\nThe issue was found during a static audit of SCTP objects. With an\nauthenticated peer, the reproducer triggered the same KASAN report in 2\nof 2 unpatched runs on a KASAN-enabled netdev/main kernel:\n\n  BUG: KASAN: slab-use-after-free in sctp_outq_select_transport\n  Read of size 4 at addr ffff88800b9bd95c by task python3/197\n\n  Call Trace:\n   sctp_outq_select_transport+0x549/0x8b0 [sctp]\n   sctp_outq_flush+0x306/0x2c60 [sctp]\n   sctp_transport_immediate_rtx+0xaf/0x260 [sctp]\n   sctp_process_asconf_ack+0xa48/0xf70 [sctp]\n\n  Allocated by task 197:\n   sctp_transport_new+0x68/0x650 [sctp]\n   sctp_assoc_add_peer+0x258/0x12a0 [sctp]\n   sctp_process_asconf+0x5e9/0x1090 [sctp]\n\n  Last potentially related work creation:\n   __call_rcu_common.constprop.0+0x77/0xb70\n   sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]\n   sctp_process_asconf+0xd9c/0x1090 [sctp]\n\nThe first invalid access was a four-byte read of transport-\u003estate at\nnet/sctp/outqueue.c:833. The same reproducer completed the full\nauthenticated ASCONF and local-address replacement sequence with this\nchange without a KASAN report or oops.\n\nClear new_transport when its peer is removed, before it can be used to\ncreate the HEARTBEAT.\n\nFixes: 6af29ccc223b (\"sctp: Bundle HEAERTBEAT into ASCONF_ACK\")\nCc: stable@vger.kernel.org\nSigned-off-by: Qing Ming \u003ca0yami@mailbox.org\u003e\nAcked-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260811152803.5629-1-a0yami@mailbox.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "dbf34acdfb29781dd4a8a86f7111d99c016fc7e8",
      "tree": "f75716d7fcc6924dc551eec9726277e4fe670ffc",
      "parents": [
        "a0d6255b4adcd5b903c289921284c3c362fc1fd6"
      ],
      "author": {
        "name": "Willem de Bruijn",
        "email": "willemb@google.com",
        "time": "Tue Aug 11 14:26:50 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:20:07 2026 -0700"
      },
      "message": "selftests: drv-net: so_txtime: fix qdisc replace with handle\n\nThe blamed commit updated a tc replace command by adding a handle.\n\n  -    tc(f\"qdisc replace dev {ifname} root {qdisc} {optargs}\")\n  +    tc(f\"qdisc replace dev {ifname} root handle 1: {qdisc} {optargs}\")\n\nThis breaks the test if the root qdisc already has that handle and is of\ndifferent kind, with\n\n  \"Invalid qdisc name: must match existing qdisc.\"\n\nIf no handle is asked, or the kind differs, tc replace removes the old\nqdisc and grafts a new one.\n\nIf a handle is asked and exists, tc replace tries to change the qdisc\nin place, for which the kind must be the same.\n\nIt does not trigger in all setups, like netdevsim or debian 13, which\ndo not have root handle 1:. But it is a common root handle.\n\nSolve the bug by first deleting the existing root qdisc if one exists.\n\nWrap that command in a try block, because it will fail for default\nqdiscs with handle 0: with\n\n  \"Error: Cannot delete qdisc with handle of zero.\"\n\nReported-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nCloses: https://lore.kernel.org/netdev/20260810183118.32d5c06a@kernel.org/\nFixes: ef3d6cca02c8 (\"selftests: drv-net: so_txtime: only send test traffic to sch_etf\")\nSigned-off-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nLink: https://patch.msgid.link/20260811182856.2702163-1-willemdebruijn.kernel@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a0d6255b4adcd5b903c289921284c3c362fc1fd6",
      "tree": "98de1ff2988403a30e56b96004343826b8e2c27c",
      "parents": [
        "095887cb96a36b917dbdf163c165e2f294d8eefa"
      ],
      "author": {
        "name": "Qingfang Deng",
        "email": "qingfang.deng@linux.dev",
        "time": "Tue Aug 11 15:49:47 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:17:53 2026 -0700"
      },
      "message": "pptp: drop packets received before connect\n\npptp_bind() publishes the socket by its local call ID before it is\nconnected, so GRE packets can reach pptp_rcv_core() while\nPPPOX_CONNECTED is clear.\n\nSuch packets are queued on sk_receive_queue, but PPTP provides no recvmsg\noperation and never drains the queue after connect. The packets therefore\nremain there until socket destruction.\n\nDrop such packets immediately instead. Since PPTP no longer queues packets\non sk_receive_queue, remove the corresponding destructor purge.\n\nSigned-off-by: Qingfang Deng \u003cqingfang.deng@linux.dev\u003e\nLink: https://patch.msgid.link/20260811074948.345834-1-qingfang.deng@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "095887cb96a36b917dbdf163c165e2f294d8eefa",
      "tree": "6082d493020e35f31a208872d13726066e2fa016",
      "parents": [
        "ac155a26750a595703e7dadff84735456d75a479"
      ],
      "author": {
        "name": "Qingfang Deng",
        "email": "qingfang.deng@linux.dev",
        "time": "Tue Aug 11 14:02:29 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:14:20 2026 -0700"
      },
      "message": "ppp: annotate lockless queue empty check\n\nppp_poll() checks whether pf-\u003erq contains a packet without holding the\nqueue lock. skb_peek() requires appropriate locking or a private queue,\nneither of which applies because ppp_input() can enqueue concurrently.\n\nOnly queue emptiness is needed, so use skb_queue_empty_lockless()\ninstead.\n\nCc: stable+noautosel@kernel.org # race annotation\nSigned-off-by: Qingfang Deng \u003cqingfang.deng@linux.dev\u003e\nReviewed-by: Breno Leitao \u003cleitao@debian.org.\nLink: https://patch.msgid.link/20260811060236.322284-1-qingfang.deng@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9e6869be49064915edb6c8776b27c376cfdb0df5",
      "tree": "0fcb511f2a853639e6f0e19a6d727503d09e2946",
      "parents": [
        "7b53449540502cb21b32bca62a6258e22cd97bbe"
      ],
      "author": {
        "name": "Alexandra Winter",
        "email": "wintera@linux.ibm.com",
        "time": "Mon Aug 10 13:14:32 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:08:05 2026 -0700"
      },
      "message": "net/dibs: Correct freeing of dmb_clientid_arr\n\nA dibs device interrupt handler can be active after dibs_dev_del() and\nmay still access dmb_clientid_arr. (UAF)\n\nIn case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe()\ndmb_clientid_arr is freed twice (double free).\n\nFree dmb_clientid_arr in dibs_dev_release() after last reference is gone.\nNote that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok\nfor now, because no dmbs can be registered before dibs_dev_add().\n\nFixes: cc21191b584c (\"dibs: Move data path to dibs layer\")\nCc: stable@vger.kernel.org\nCo-developed-by: Hidayath Khan \u003chidayath@linux.ibm.com\u003e\nSigned-off-by: Hidayath Khan \u003chidayath@linux.ibm.com\u003e\nSigned-off-by: Alexandra Winter \u003cwintera@linux.ibm.com\u003e\nReviewed-by: Dust Li \u003cdust.li@linux.alibaba.com\u003e\nLink: https://patch.msgid.link/20260810111432.2334900-1-wintera@linux.ibm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3d6d817622b0a9721e3cc404df3469171582be13",
      "tree": "8a171c5e234e3c8232d6d35fb6b1a7144658af19",
      "parents": [
        "f5bbbfec59b4e2fb7520a91de3df8a6174325d6a",
        "c4f6916a99cf105c3ff340b6210fcbba3fa66b35"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Aug 12 08:03:31 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Aug 12 08:03:31 2026 -0700"
      },
      "message": "Merge tag \u0027scsi-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi\n\nPull SCSI fixes from James Bottomley:\n \"Two minor core fixes: one for power management issues in error\n  handling and the other to fix a deadlock in door locking of SCSI\n  devices with removable media; and a minor bug fix for the debug\n  driver\"\n\n* tag \u0027scsi-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:\n  scsi: scsi_debug: Negate wrapped memcmp() result\n  scsi: core: Do not block on tag allocation in scsi_eh_lock_door()\n  scsi: core: pair EH runtime PM get and put\n"
    },
    {
      "commit": "1fd495ef09eef96169a379a749c24b5e69974bb8",
      "tree": "70f1f59796463e84056b08d90aff4f46ad1ca7e3",
      "parents": [
        "075b74841bd0065a3bda3440873c747938e69b68"
      ],
      "author": {
        "name": "Uwe Kleine-König",
        "email": "ukleinek@kernel.org",
        "time": "Fri Jul 31 11:49:49 2026 +0200"
      },
      "committer": {
        "name": "Geert Uytterhoeven",
        "email": "geert@linux-m68k.org",
        "time": "Wed Aug 12 13:53:44 2026 +0200"
      },
      "message": "m68k: Define NR_CPUS to 1\n\nThis fixes a Kconfig warning\n\n\tfs/erofs/Kconfig:137:warning: range is invalid\n\nwhich originates from EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS using\nNR_CPUS which up to now didn\u0027t exist for ARCH\u003dm68k.  All other\narchitectures define this symbol, so fix the outlier.\n\n[geert] This also fixes:\n  - CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS being set to the\n    literal NR_CPUS instead of a number by automatic configs like\n    \"make allmodconfig\" or \"make olddefconfig\",\n  - An infinite loop in manual configs like \"make oldconfig\" when\n    CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS is not present or\n    has an invalid value in your existing .config.\n\nFixes: c9b47e6b2311 (\"erofs: cap LZMA stream pool size\")\nSigned-off-by: Uwe Kleine-König \u003cukleinek@kernel.org\u003e\nReviewed-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\nLink: https://patch.msgid.link/20260731094950.1988084-2-ukleinek@kernel.org\nSigned-off-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\n"
    },
    {
      "commit": "ac155a26750a595703e7dadff84735456d75a479",
      "tree": "6e168617e16010e7d642d07f343f8c52e274cca8",
      "parents": [
        "878b56de01e255172745775cd8afcec2bd80268a",
        "e468d371180d3c5b3333660bd742103b88703adf"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:41 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:41 2026 -0700"
      },
      "message": "Merge branch \u0027mptcp-out-of-order-queue-pruning\u0027\n\nMatthieu Baerts says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nmptcp: out-of-order queue pruning\n\nUnder memory pressure, a pruning of the MPTCP-level OoO queue might be\nrequired as last resort, to avoid too long recoveries, or even stalls.\nGeliang and Gang managed to reproduce this behaviour, and Paolo\nimproved the situation thanks to the following patches:\n\n- Patches 1-3: improve the MPTCP-level retransmission schema to make\n  recoveries from memory pressure/after MPTCP-level drop significantly\n  faster.\n\n- Patches 4-5: make the admission check way stricter for incoming\n  packets exceeding the memory limits, with some exceptions for fallback\n  sockets.\n\n- Patches 6-7: implement OoO queue pruning for MPTCP.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-0-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e468d371180d3c5b3333660bd742103b88703adf",
      "tree": "6e168617e16010e7d642d07f343f8c52e274cca8",
      "parents": [
        "996643574cc8fc05ee70f78081f5c2af3601ecf5"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:07 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:38 2026 -0700"
      },
      "message": "mptcp: implemented OoO queue pruning\n\nWhen moving incoming skbs in the msk receive queue and the latter\nis above limits, prune it as needed quite alike what TCP is doing\nat the subflow level. The main difference relies in the stop condition:\nsince MPTCP does not perform collapsing, it\u0027s better off dropping the\nbare minimum to fit the (newer) incoming packet.\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nTested-by: Gang Yan \u003cyangang@kylinos.cn\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-7-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "996643574cc8fc05ee70f78081f5c2af3601ecf5",
      "tree": "0ac508aba56a82d62d52ad2bfb054bcbd487e556",
      "parents": [
        "b1224c4b40f6dfc10fa5654e8f0b690b83bb2905"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:06 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:38 2026 -0700"
      },
      "message": "mptcp: avoid code duplication in __mptcp_move_skb()\n\nAlike TCP, MPTCP handles in-sequence packets and partially overlapping\nones in a very similar way: we can use the same path to handle both,\navoiding some code duplication.\n\nThis will also make the next patch simpler.\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-6-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b1224c4b40f6dfc10fa5654e8f0b690b83bb2905",
      "tree": "01e8bfc6d47a3f9822985bddff24086a75b7d2c5",
      "parents": [
        "e0e4d56b050597a690b4dd1c281af532469b0636"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:05 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:37 2026 -0700"
      },
      "message": "mptcp: enforce hard limit on backlog flushing\n\nCurrently a wild producer could keep the backlog flushing operation\nspinning for an unbound time.\n\nSince the previous patch, the amount of data present in the backlog is\nhard-limited. Move the backlog len update at the end of the flush loop to\nprevent it spinning forever.\n\nAlso, no need to splice back the remaining skbs list into the backlog, as\nsuch list is always empty after each backlog processing loop.\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-5-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e0e4d56b050597a690b4dd1c281af532469b0636",
      "tree": "320c9332ded1563e539f7eea89472a32e761ee97",
      "parents": [
        "96d846e3e2a7ea01ff8a584a0b5e2a42fa9ccc1e"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:04 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:37 2026 -0700"
      },
      "message": "mptcp: explicitly drop over memory limits\n\nCurrently the enforcement of the rcvbuf constraint is implemented\nwhen moving the skbs into the msk receive or OoO queue, keeping the\nincoming skbs in the subflow queue when over limits.\n\nUnder significant memory pressure the above can cause permanent data\ntransfer stalls, as the skb needed to make forward progress can be\nstuck in a subflow queue.\n\nOver memory limits, drop the incoming skb, relying on MPTCP-level\nretransmissions.\n\nNote that fallback socket must perform the limit before the skb reaches\nthe subflow-level queue, as dropping an in-sequence already acked skb\nwould break the stream.\n\nThis is not a complete fix for the stall issue, as the drop strategy\nneeds refinements that will come in the next patches.\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-4-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "96d846e3e2a7ea01ff8a584a0b5e2a42fa9ccc1e",
      "tree": "1e6da81b1a31e57a3505781e16a25bf774325b79",
      "parents": [
        "6cafe51e0f98fe60a106783d30b2f4c4b6039f4c"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:03 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:37 2026 -0700"
      },
      "message": "mptcp: let the retrans scheduler do its job\n\nCurrently the MPTCP core enforces that when MPTCP-level retrans timer\nfires, at most a single dfrag is retransmitted. In some corner-cases, it\nmay be necessary to retransmit multiple dfrags, and the MPTCP socket\nwill need to wait multiple retrans timeout to accomplish that.\n\nRemove the mentioned constraint, allowing to transmit multiple dfrags\nper retrans period, as long as the scheduler keeps selecting subflows\nfor retransmissions and pending data is available in the rtx queue.\nThe default scheduler will transmit a dfrag per available subflow.\n\nTested-by: Gang Yan \u003cyangang@kylinos.cn\u003e\nTested-by: Geliang Tang \u003cgeliang@kernel.org\u003e\nAcked-by: Geliang Tang \u003cgeliang@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-3-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6cafe51e0f98fe60a106783d30b2f4c4b6039f4c",
      "tree": "c66aeb72d1dcc4ad06c61235d58ffe58efca32ab",
      "parents": [
        "789e6a844b51bf6362a7e7f551553ba988f3dc92"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:02 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:37 2026 -0700"
      },
      "message": "mptcp: move the stale logic out of retrans scheduler\n\nThis allow separating the stale logic invocation and the retrans\nscheduler, and will simplify the next patch.\n\nIt\u0027s also a cleaner design as the retrans scheduler has currently\ntoo many side effects. As a possible downside, the retrans work will\nnow traverse the subflows list additional times; that does not matter\nmuch, as this is slowpath.\n\nWhile at it, pick more accurate names for the involved helpers and\nexplicitly note that the per subflow stale data is under msk socket\nlock protection.\n\nThe scheduler and the stale logic may observe different subflow\nstatues, as no subflow lock is acquired. This is intentional and not\nharmful, worst case leading to slower retransmissions.\n\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-2-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "789e6a844b51bf6362a7e7f551553ba988f3dc92",
      "tree": "9842b55714609dcf23916ff17d3748c276be7247",
      "parents": [
        "878b56de01e255172745775cd8afcec2bd80268a"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Fri Aug 07 15:49:01 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:35:37 2026 -0700"
      },
      "message": "mptcp: move the retrans loop to a separate helper\n\nThis is a cleanup in order to make the next patch simpler.\n\nNo functional change intended.\n\nTested-by: Gang Yan \u003cyangang@kylinos.cn\u003e\nTested-by: Geliang Tang \u003cgeliang@kernel.org\u003e\nAcked-by: Geliang Tang \u003cgeliang@kernel.org\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nSigned-off-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260807-net-next-mptcp-oooq-pruning-v3-1-dbc1eb853cc3@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "7b53449540502cb21b32bca62a6258e22cd97bbe",
      "tree": "e2917044e8bbf1eabe743db9d0a60b9adb99f32d",
      "parents": [
        "6d3724e616faf952c3adcf8414fc21a828ef3709",
        "490937b88cb592cc0c5367758edd700fd5abd15c"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:32:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:32:18 2026 -0700"
      },
      "message": "Merge tag \u0027nf-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf\n\nPablo Neira Ayuso says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nNetfilter/IPVS fixes for net\n\nThe following patchset contains Netfilter/IPVS fixes for net. Still\nlarge batch for this late -rc cycle but at least half of these fixes\nin this batch have been cooking for several weeks before:\n\n1) Fix race between ipset list:set GC and swap, use write_lock instead\n   of rcu read lock section when accessing the index to ensure\n   interference with ip_set_swap(), from Xiang Mei.\n\n2) Release template conntrack in bridge conntrack when packet is\n   neither IPv4 nor IPv6 before setting skb as untracked.\n   From Zhiling Zou.\n\n3) A series of 3 patches for IPVS to address sashiko reports:\n   Schedulers read destination overload state while connection\n   accounting and destination configuration can update it concurrently.\n   The first patch adds a single total connection counter. The second\n   patch uses it to identify threshold crossings precisely, and updates\n   OVERLOAD at the crossings and on a threshold edit under dst_lock.\n   The third patch moves configuration-controlled AVAILABLE to a\n   separate cflags word, so it cannot clobber OVERLOAD through an\n   unrelated read-modify-write update.\n\n4) Log invalid packets in TCP and SCTP connection tracking to address\n   a deadlock when nfnetlink_log is used as logging backend and the\n   nfnetlink_log conntrack glue support is used. From Zihan Xi.\n\n5) Wait for rcu grace period before releasing pernet state in\n   nfnetlink_log, otherwise packets can end up access already released\n   memory, triggering UaF. From Florian Westphal.\n\n6) IPVS needs to reset IP information in control buffer in skbuff when\n   encapsulating IP packets in ICMP, from Kyle Zeng.\n\n7) IPVS needs to validate ihl field of inner headers in when handling\n   ICMP response, from Julian Anastasov.\n\n8) Remove a WARN_ON_ONCE reachable from the nf_tables hardware offload\n   when triggering ENOMEM on GFP_KERNEL allocation,\n   from Alexey Velichayshiy.\n\n9) Publish reply tuple into the flowtable hashtable first, otherwise\n   GC might walk over a released tuple when insertion of the original\n   tuple fail. From Jeremy Jean.\n\n10) Elide counter increment when replacing an ipset element,\n    from Florian Westphal.\n\n11) Remove unneeded ipset accounting resets on destruction/flush,\n    from Florian Westphal.\n\n* tag \u0027nf-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:\n  netfilter: ipset: let destroy callbacks adjust ext mem size\n  netfilter: ipset: fix list type element drift bug\n  netfilter: flowtable: publish GC-visible tuple last\n  netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path\n  ipvs: revalidate ihl to prevent out-of-bounds access\n  ipvs: clear IPv4 options after rebasing tunnel ICMP errors\n  netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state\n  netfilter: nf_conntrack: defer invalid log until after unlock\n  ipvs: separate destination availability state\n  ipvs: properly update the overload flag on dest edit\n  ipvs: add totalconns for dest\n  netfilter: bridge: release template ct on non-IP path\n  netfilter: ipset: fix refcount race between list:set GC and swap\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260810190621.894119-1-pablo@netfilter.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "878b56de01e255172745775cd8afcec2bd80268a",
      "tree": "8e465f2fe07ee186af0aad14f52954119b4bdc34",
      "parents": [
        "5838193edccab7810d5dc51c165a316089272dc6"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Mon Aug 10 17:46:45 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:31:19 2026 -0700"
      },
      "message": "selftests: drv-net: hide the devlink port_split test\n\nThe devlink port_split test has limited applicability.\nNICs (as opposed to switches) require at least a re-probe\nto apply the split configuration.\n\nOn top of that the test is not compatible with our driver env,\nit just splits all ports on the system, not only what NETIF\npoints at.\n\nLong term we may want to add some indication in devlink whether\nthe port splitting is runtime (cmode of sorts), and fix the\ntest to follow driver env. But since no (known) NIC driver can\nsupport runtime anyway let\u0027s just hide the test from the selftest\nframework by moving it to extra files.\n\nHaving this test randomly break unrelated NICs within the DUT\nmakes people implement allow-lists for ksft, which then means\ntheir setups don\u0027t run new tests. It\u0027s very useful during test\nreview to see whether the test works across all the runners.\n\nReviewed-by: Petr Machata \u003cpetrm@nvidia.com\u003e\nLink: https://patch.msgid.link/20260811004645.1072124-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6d3724e616faf952c3adcf8414fc21a828ef3709",
      "tree": "3148ab1ca23138488733927322331ba98b0b2b24",
      "parents": [
        "484ec2ab78438b06153fb12b16827992a5ab8204"
      ],
      "author": {
        "name": "Zhang Changzhong",
        "email": "zhangchangzhong@huawei.com",
        "time": "Fri Aug 07 15:50:38 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:28:43 2026 -0700"
      },
      "message": "net/sched: cls_u32: skip hash tables in u32_bind_class()\n\nu32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode\nthrough the walker callback. u32_bind_class() unconditionally casts the\npassed fh to tc_u_knode and accesses \u0026n-\u003eres, so when fh is actually a\ntc_u_hnode, which has no tcf_result member, this results in a\nslab-out-of-bounds read of res-\u003eclassid in tc_cls_bind_class().\n\nThe issue can be reproduced with the following commands:\n\n    tc qdisc add dev lo root handle 1: hfsc\n    tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit\n    tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1\n    tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit\n\nFix this by skipping hash tables via the TC_U32_KEY(handle) check.\n\nFixes: 07d79fc7d94e (\"net_sched: add reverse binding for tc class\")\nSigned-off-by: Zhang Changzhong \u003czhangchangzhong@huawei.com\u003e\nAcked-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nLink: https://patch.msgid.link/1786089038-36366-1-git-send-email-zhangchangzhong@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5838193edccab7810d5dc51c165a316089272dc6",
      "tree": "24292aae44aefd644ba96654190eddfea7532946",
      "parents": [
        "0ed2ebecd5388a9ccd986437f4edfda9ea7afd5f"
      ],
      "author": {
        "name": "Vadim Fedorenko",
        "email": "vadim.fedorenko@linux.dev",
        "time": "Thu Aug 06 20:18:49 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:27:48 2026 -0700"
      },
      "message": "bnxt_en: enable PTM function\n\nThe patch mentioned in Fixes missed one main point of implementing\nproper PTM support. To make it fully operational it has to be explicitly\nenabled. Add missing call in probe callback and disable it in teardown\ncallback.\n\nSigned-off-by: Vadim Fedorenko \u003cvadim.fedorenko@linux.dev\u003e\nReviewed-by: Pavan Chebbi \u003cpavan.chebbi@broadcom.com\u003e\nLink: https://patch.msgid.link/20260806201849.3161402-1-vadim.fedorenko@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "484ec2ab78438b06153fb12b16827992a5ab8204",
      "tree": "52ea83f7cba7164878f82a029aba576a35a178fe",
      "parents": [
        "f60b396ee174206fe08ebf997d16cd3801b77b22",
        "3992ced109c70b771efad9e51ae68e5c7a04dea3"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:09 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:10 2026 -0700"
      },
      "message": "Merge branch \u0027gve-bug-fixes-for-header-split-and-ptp\u0027\n\nHarshitha Ramamurthy says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\ngve: Bug fixes for header-split and PTP\n\nThis series contains 2 bug fixes for gve.\n\nPatch 1 fixes an issue which causes TX timeouts due to HW detection of\nan illegal descriptor. This happens when receiving header-only packets\nwith header split enabled - this produces an SKB with a zero-length\nfragment.\n\nPatch 2 prevents a kernel NULL pointer dereference by stubbing the PTP\nadjfine callback.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807224315.234152-1-hramamurthy@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3992ced109c70b771efad9e51ae68e5c7a04dea3",
      "tree": "52ea83f7cba7164878f82a029aba576a35a178fe",
      "parents": [
        "6bf14575c65569dcded90ef78afb8a6d57323f04"
      ],
      "author": {
        "name": "Jordan Rhee",
        "email": "jordanrhee@google.com",
        "time": "Fri Aug 07 22:43:15 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:04 2026 -0700"
      },
      "message": "gve: fix NULL dereference due to missing ptp adjfine\n\nFix NULL dereference due to missing implementation of adjfine, which can\nbe triggered from usermode as follows:\n\nsudo ./testptp -d /dev/ptp0 -f 0\n[  551.943697] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\n[  552.061946] Call Trace:\n[  552.064487]  \u003cTASK\u003e\n[  552.066681]  ptp_clock_adjtime+0x1c0/0x2c0\n[  552.070874]  ? get_clock_desc+0x6b/0xb0\n[  552.074825]  pc_clock_adjtime+0x78/0xc0\n[  552.078755]  __do_sys_clock_adjtime+0x85/0x110\n[  552.083293]  do_syscall_64+0xea/0x610\n\nCc: stable@vger.kernel.org\nFixes: acd16380523b (\"gve: Add initial PTP device support\")\nSigned-off-by: Jordan Rhee \u003cjordanrhee@google.com\u003e\nSigned-off-by: Harshitha Ramamurthy \u003chramamurthy@google.com\u003e\nReviewed-by: Vadim Fedorenko \u003cvadim.fedorenko@linux.dev\u003e\nLink: https://patch.msgid.link/20260807224315.234152-3-hramamurthy@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6bf14575c65569dcded90ef78afb8a6d57323f04",
      "tree": "c5d629a9651adf2e9ef3e3214372de5067552e1f",
      "parents": [
        "f60b396ee174206fe08ebf997d16cd3801b77b22"
      ],
      "author": {
        "name": "Jordan Rhee",
        "email": "jordanrhee@google.com",
        "time": "Fri Aug 07 22:43:14 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:04 2026 -0700"
      },
      "message": "gve: fix zero-length skb frag with header-split\n\nWhen header split is enabled and a header-only packet is\nreceived such as a pure TCP ACK, GVE will indicate an\nRX SKB with a zero-length fragment. If this SKB is then\nhairpinned and sent back out, the GVE TX path will emit\na zero-length descriptor. Hardware considers this\nan illegal descriptor and stops the queue, causing a\nTX timeout and interface reset.\n\nFix it by not adding the zero-length skb frag.\n\nCc: stable@vger.kernel.org\nFixes: 5e37d8254e7f (\"gve: Add header split data path\")\nSuggested-by: Praveen Kaligineedi \u003cpkaligineedi@google.com\u003e\nCo-developed-by: Ziwei Xiao \u003cziweixiao@google.com\u003e\nSigned-off-by: Ziwei Xiao \u003cziweixiao@google.com\u003e\nSigned-off-by: Jordan Rhee \u003cjordanrhee@google.com\u003e\nSigned-off-by: Harshitha Ramamurthy \u003chramamurthy@google.com\u003e\nLink: https://patch.msgid.link/20260807224315.234152-2-hramamurthy@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "0ed2ebecd5388a9ccd986437f4edfda9ea7afd5f",
      "tree": "970bef3bb2ad179f304be46e28f1fbd3beab958e",
      "parents": [
        "bc27fa08d090a0a921064ab9fa61b47d497c177d",
        "b5d24f604506e75bd6eb606f116e03976d89b642"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:25:04 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:25:05 2026 -0700"
      },
      "message": "Merge branch \u0027net-selftests-adjustments-to-ipv6_flowlabel_mgr\u0027\n\nMarcelo Mendes Spessoto Junior says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: selftests: adjustments to ipv6_flowlabel_mgr\n\nThe ipv6_flowlabel_mgr test file was lacking coverage for the\nIPV6_FL_A_RENEW action, and the IPV6_FL_F_REMOTE and IPV6_FL_F_REFLECT\nflags. The first two patches from this set aim to add a proper test\ncase for RENEW and REMOTE.\n\nThe third patch was added to insert network namespace creation inside\nthe test suite, instead of relying on external wrapper scripts. This\nchange conforms to other net test implementations, such as\ntools/testing/selftests/net/icmp_rfc4884.c, and it is important for\nthe fourth and fifth patches.\n\nThe fourth patch adds the IPV6_FL_F_REFLECT test.\n\nThe fifth patch proposes the adoption of \"kselftest_harness.h\" helpers,\nimproving code readability and conforming to the implementation of the most\nrecent selftests.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807220942.421382-1-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b5d24f604506e75bd6eb606f116e03976d89b642",
      "tree": "970bef3bb2ad179f304be46e28f1fbd3beab958e",
      "parents": [
        "b2690523a71fedf92c0bd1f8908c1cd7b62e26f6"
      ],
      "author": {
        "name": "Marcelo Mendes Spessoto Junior",
        "email": "marcelomspessoto@gmail.com",
        "time": "Fri Aug 07 19:09:42 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:24:56 2026 -0700"
      },
      "message": "selftests: net: adopt harness for flow label mgr\n\nThe kselftest_harness.h file contains modern helpers to build tests\nfor kselftest. Dropping the custom test helpers in ipv6_flowlabel_mgr\nin favor of the harness makes tests more legible and conforms to the\nstructure of the latest selftests. It also enforces the TAP standard.\n\nAnother change made to the structure of the ipv6_flowlabel_mgr test\nfile was the removal of parse_opts. The supported opts were already\nunused: the binary is listed in TEST_GEN_FILES, and is driven solely\nby ipv6_flowlabel.sh via \"./ipv6_flowlabel_mgr\", which never passed -l\nor -v. Dropping the -l gate means the two checks it previously guarded\n(each with a 13-second sleep, ~26 seconds total) are now\nunconditionally enabled on every run instead of never running at all.\nThe TH_LOG calls and code comments now cover the information that the\nremoved, custom -v flag used to print.\n\nFinally, FIXTURE_SETUP(flowlabel) ensures each test gets its own\nisolated network namespace. The previously added setup() helper was\ndropped to conform to the netns setup pattern used in icmp_rfc4884.c.\ndisable_flowlabel_consistency() was moved next to reflect_flag, the\nonly test that calls it, and now uses SKIP() instead of an ad hoc\n[INFO] message when the sysctl cannot be disabled.\n\nSigned-off-by: Marcelo Mendes Spessoto Junior \u003cmarcelomspessoto@gmail.com\u003e\nLink: https://patch.msgid.link/20260807220942.421382-6-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "b2690523a71fedf92c0bd1f8908c1cd7b62e26f6",
      "tree": "6820c0243eae0aea9de3bb53eb361c3da748eac2",
      "parents": [
        "03df0d155ba11ec37e0b48bb93fede143ffef556"
      ],
      "author": {
        "name": "Marcelo Mendes Spessoto Junior",
        "email": "marcelomspessoto@gmail.com",
        "time": "Fri Aug 07 19:09:41 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:24:56 2026 -0700"
      },
      "message": "selftests: net: test IPV6_FL_F_REFLECT\n\nAccording to the source code, flowlabel_consistency must be\ndeactivated for the IPV6_FL_F_REFLECT flag to work. Since\nipv6_flowlabel_mgr now runs in its own network namespace, do this\ndirectly from the test binary. Attempt to disable\nnet.ipv6.flowlabel_consistency and skip the reflect test if that\nfails. A disabled flowlabel_consistency does not affect the remaining\nfeatures being tested on the file, and failing to disable is not fatal\nand skips the reflect test only.\n\nThe previously defined tcp_listen and tcp_connect helpers were reused,\nsince the connection flow required for REFLECT validation is very\nsimilar to REMOTE.\n\nSigned-off-by: Marcelo Mendes Spessoto Junior \u003cmarcelomspessoto@gmail.com\u003e\nLink: https://patch.msgid.link/20260807220942.421382-5-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "03df0d155ba11ec37e0b48bb93fede143ffef556",
      "tree": "692f2b7077beedfb494c189d36dac243811dacc9",
      "parents": [
        "39dd045c15143b9a40473e4b79263b3f94d5f3a0"
      ],
      "author": {
        "name": "Marcelo Mendes Spessoto Junior",
        "email": "marcelomspessoto@gmail.com",
        "time": "Fri Aug 07 19:09:40 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:24:55 2026 -0700"
      },
      "message": "selftests: net: create own netns in ipv6_flowlabel_mgr\n\nHave ipv6_flowlabel_mgr create and configure its own network\nnamespace (unshare(CLONE_NEWNET) + bring up lo), the same way\nipv6_fragmentation.c and icmp_rfc4884.c already do, instead of\nrelying on the in_netns.sh wrapper script.\n\nThe setup can then be reused across tests through fixtures and\nprovide isolated network environments for each test in the case\nof a future adoption of kselftest_harness.\n\nIt also avoids the leak of modifications to the netns in case the\nuser runs the test file directly, outside the wrapper and without\nthe in_netns.sh file.\n\nSigned-off-by: Marcelo Mendes Spessoto Junior \u003cmarcelomspessoto@gmail.com\u003e\nLink: https://patch.msgid.link/20260807220942.421382-4-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "39dd045c15143b9a40473e4b79263b3f94d5f3a0",
      "tree": "2154bd5924b0e202c37c7cba7756f02ca8efc8a2",
      "parents": [
        "bfad9937de98755fa73bba4181e1de05069e7d54"
      ],
      "author": {
        "name": "Marcelo Mendes Spessoto Junior",
        "email": "marcelomspessoto@gmail.com",
        "time": "Fri Aug 07 19:09:39 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:24:55 2026 -0700"
      },
      "message": "selftests: net: test IPV6_FL_F_REMOTE\n\nThis flag retrieves the flow label seen by the socket at connection\nsetup via a getsockopt query. Therefore, the validation of this flag\nrequires a brief connection setup (source code for flow label shows\nit must be TCP).\n\nThe simple TCP connection logic was wrapped inside two simple helpers,\nbecause there are other uncovered features of flow label mgr that\ncould benefit from it (such as IPV6_FL_F_REFLECT).\n\nSigned-off-by: Marcelo Mendes Spessoto Junior \u003cmarcelomspessoto@gmail.com\u003e\nLink: https://patch.msgid.link/20260807220942.421382-3-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "bfad9937de98755fa73bba4181e1de05069e7d54",
      "tree": "0d51779a48684378ec20e760a4a8adb24b660c6d",
      "parents": [
        "bc27fa08d090a0a921064ab9fa61b47d497c177d"
      ],
      "author": {
        "name": "Marcelo Mendes Spessoto Junior",
        "email": "marcelomspessoto@gmail.com",
        "time": "Fri Aug 07 19:09:38 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:24:55 2026 -0700"
      },
      "message": "selftests: net: test IPV6_FL_A_RENEW\n\nRENEW was the only flow label action without selftests coverage.\n\nAssert renew returns no error on correct usage and fails for labels\nthat do not exist.\n\nThis test is based on the previously implemented EXCL share test,\nwhich demonstrates that a new flow label with the same value can be\ncreated after the linger period. Renew is used here to show that a\nflow label can last longer and block a new flow label creation after\nthe previous linger time. This test, however, demands sleep during\nexecution, and should be placed as a conditional test under the -l\noption.\n\nThe addition of the expect_fail_errno helper is necessary to assert\nthe corresponding error when a function can fail in multiple ways.\n\nSigned-off-by: Marcelo Mendes Spessoto Junior \u003cmarcelomspessoto@gmail.com\u003e\nLink: https://patch.msgid.link/20260807220942.421382-2-marcelomspessoto@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f60b396ee174206fe08ebf997d16cd3801b77b22",
      "tree": "fb1426e742fe3ea0799f5868650a64eb67550428",
      "parents": [
        "6bcd76c134c55c697148acb5c0194e9666abdf84"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Sun Aug 09 05:09:28 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:21:46 2026 -0700"
      },
      "message": "net/sched: act_api: fix TOCTOU NULL deref on a-\u003egoto_chain\n\ntcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking\nrcu_access_pointer(a-\u003egoto_chain) and then calling\ntcf_action_goto_chain_exec(), which does a second, independent\nrcu_dereference_bh(a-\u003egoto_chain) read and immediately dereferences\nchain-\u003efilter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact\nreplace path) can clear a-\u003egoto_chain between the two reads, so the second\nread returns NULL and tcf_action_goto_chain_exec() dereferences NULL.\n\nFix the race by doing a single rcu_dereference_bh() read of a-\u003egoto_chain\nin tcf_action_exec(), checking it once for NULL, and passing the resulting\nchain pointer into tcf_action_goto_chain_exec(). This turns the split\ncheck/use into a single check/use on one value.\n\nFixes: ee3bbfe806cd (\"net/sched: let actions use RCU to access \u0027goto_chain\u0027\")\nReported-by: vega@nebusec.ai\nTested-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nReviewed-by: Davide Caratti \u003cdcaratti@redhat.com\u003e\nLink: https://patch.msgid.link/20260809090928.868186-1-jhs@mojatatu.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "bc27fa08d090a0a921064ab9fa61b47d497c177d",
      "tree": "13f7cbcf6f9a7c04e6781f1358e72f7ab686ce75",
      "parents": [
        "6266eeb24fd7028f1ae871e7592a7c1b150629aa",
        "38c35fdd801eaa67b83ea3b4d317f3fd2b87de63"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:06:34 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:06:35 2026 -0700"
      },
      "message": "Merge branch \u0027devlink-add-generic-device-max_sfs-parameter\u0027\n\nTariq Toukan says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\ndevlink: add generic device max_sfs parameter\n\nThis series by Nikolay introduces a new generic devlink device\nparameter, max_sfs, to control the number of light-weight NIC\nsubfunctions (SFs) that can be created on a device.\n\nThe first patch adds the generic devlink parameter and infrastructure\nsupport.\nThe second patch implements support for the parameter in the mlx5\ndriver.\n\nWith this addition, users can enable or disable SF creation directly via\ndevlink, without relying on external vendor-specific tools.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260806073037.3001886-1-tariqt@nvidia.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "38c35fdd801eaa67b83ea3b4d317f3fd2b87de63",
      "tree": "13f7cbcf6f9a7c04e6781f1358e72f7ab686ce75",
      "parents": [
        "26ba30221c03364d6ed9910be8da4c1fd871b07b"
      ],
      "author": {
        "name": "Nikolay Aleksandrov",
        "email": "nikolay@nvidia.com",
        "time": "Thu Aug 06 10:30:37 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:06:30 2026 -0700"
      },
      "message": "net/mlx5: implement max_sfs parameter\n\nImplement max_sfs generic parameter to allow users to control the total\nlight-weight NIC subfunctions that can be created using devlink instead\nof external vendor tools. A value of 0 will effectively disable creation\nof new subfunction devices. A warning is sent to user-space via extack\n(returning extack without error code is interpreted as a warning by\nuser-space tools). The maximum value is capped at U16_MAX.\n\nSigned-off-by: Nikolay Aleksandrov \u003cnikolay@nvidia.com\u003e\nReviewed-by: David Ahern \u003cdsahern@kernel.org\u003e\nReviewed-by: Alexander Lobakin \u003caleksander.lobakin@intel.com\u003e\nSigned-off-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nLink: https://patch.msgid.link/20260806073037.3001886-3-tariqt@nvidia.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "26ba30221c03364d6ed9910be8da4c1fd871b07b",
      "tree": "8d4761900f05afe0aa22c561fcfb839853654e0f",
      "parents": [
        "6266eeb24fd7028f1ae871e7592a7c1b150629aa"
      ],
      "author": {
        "name": "Nikolay Aleksandrov",
        "email": "nikolay@nvidia.com",
        "time": "Thu Aug 06 10:30:36 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:06:30 2026 -0700"
      },
      "message": "devlink: add generic device max_sfs parameter\n\nAdd a new generic devlink device parameter (max_sfs) to control if and\nhow many light-weight NIC subfunctions can be created. Subfunctions are\na light-weight network functions backed by an underlying PCI function.\nTheir lifecycle can already be managed by devlink, but currently users\ncannot enable them in the device. They can be enabled/disabled only via\nexternal vendor tools. This parameter allows subfunctions to be enabled\n(\u003e0) or disabled (0) via devlink. A subsequent patch will add support\nfor max_sfs to the mlx5 driver.\n\nSigned-off-by: Nikolay Aleksandrov \u003cnikolay@nvidia.com\u003e\nReviewed-by: David Ahern \u003cdsahern@kernel.org\u003e\nReviewed-by: Jiri Pirko \u003cjiri@nvidia.com\u003e\nReviewed-by: Aleksandr Loktionov \u003caleksandr.loktionov@intel.com\u003e\nReviewed-by: Alexander Lobakin \u003caleksander.lobakin@intel.com\u003e\nSigned-off-by: Tariq Toukan \u003ctariqt@nvidia.com\u003e\nLink: https://patch.msgid.link/20260806073037.3001886-2-tariqt@nvidia.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6266eeb24fd7028f1ae871e7592a7c1b150629aa",
      "tree": "442ba2e63cfd25fe495b3a430b986b098b908c2f",
      "parents": [
        "e6802833990725e855f1a4bb78b08ad67b2599a2"
      ],
      "author": {
        "name": "Christian Marangi",
        "email": "ansuelsmth@gmail.com",
        "time": "Mon Aug 10 16:37:05 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 17:52:55 2026 -0700"
      },
      "message": "MAINTAINERS: add myself as QCA8K maintainer\n\nList all the files of the QCA8K DSA Switch driver and add myself as\nmaintainer.\n\nSigned-off-by: Christian Marangi \u003cansuelsmth@gmail.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260810143740.652804-1-ansuelsmth@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e6802833990725e855f1a4bb78b08ad67b2599a2",
      "tree": "143330bc14e6cfff99371b83f9a415387781965f",
      "parents": [
        "31397cf1819210bd63fa3d2c7d8c24f7c8667d99"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Mon Aug 10 11:01:48 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 17:46:22 2026 -0700"
      },
      "message": "MAINTAINERS: make Tung an official TIPC maintainer\n\nTung Quang Nguyen has been working as the de facto TIPC maintainer\nfor a few years now. Make sure the MAINTAINERS file reflects this\nreality. Dealing with the flood of AI patches is a significant\neffort, and Tung\u0027s work and responsiveness is exemplary.\n\nLink: https://patch.msgid.link/20260810180148.680425-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6bcd76c134c55c697148acb5c0194e9666abdf84",
      "tree": "5723bf16e14d4b327b687188bf4cd06421dbdedf",
      "parents": [
        "cba9ccb47e9fa4cc77692fb896cc5ab57a667882"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Mon Aug 10 15:04:47 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 17:32:53 2026 -0700"
      },
      "message": "af_packet: Don\u0027t send zero-byte data in tpacket_snd().\n\nsyzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():\n\nskb_assert_len\nWARNING: at include/linux/skbuff.h:2753 skb_assert_len\nWARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781\n\nCall Trace:\n \u003cTASK\u003e\n dev_queue_xmit include/linux/netdevice.h:3448 [inline]\n packet_xmit+0x243/0x310 net/packet/af_packet.c:276\n tpacket_snd net/packet/af_packet.c:2907 [inline]\n packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134\n\nWhen sending 0-byte packets via TPACKET ring buffer on devices with no\nhard header (e.g. dev-\u003ehard_header_len \u003d\u003d 0), tpacket_fill_skb()\npopulates an skb with skb-\u003elen \u003d\u003d 0 and returns 0. tpacket_snd() then\nforwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to\nhit skb_assert_len(skb).\n\nSimilar checks exist in packet_snd() via commit dc633700f00f\n(\"net/af_packet: check len when min_header_len equals to 0\") and in\npacket_sendmsg_spkt() via commit 6a341729fb31 (\"af_packet: Don\u0027t send\nzero-byte data in packet_sendmsg_spkt().\").\n\nReturn -EINVAL in tpacket_fill_skb() when skb-\u003elen is zero to reject\nzero-length packets in tpacket_snd().\n\nFixes: 1da177e4c3f4 (\"Linux-2.6.12-rc2\")\nReported-by: syzbot+30b93b6845b19cc38581@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6a79e807.01d0871a.3a0d52.00ac.GAE@google.com/T/#u\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nReviewed-by: Willem de Bruijn \u003cwillemb@google.com\u003e\nReviewed-by: Jiayuan Chen \u003cjiayuan.chen@linux.dev\u003e\nLink: https://patch.msgid.link/20260810150447.1220864-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "31397cf1819210bd63fa3d2c7d8c24f7c8667d99",
      "tree": "cf9d69329f7f09767ad9e849010b08d3ed1fcc15",
      "parents": [
        "b54074ffb813aa4b97585d97ae1ead69d96432b5",
        "f57b277e8b6f6e6d3bc082be6b67c6bec02d5cbd"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 16:02:04 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 16:02:04 2026 +0200"
      },
      "message": "Merge branch \u0027net-hns3-some-cleanups-for-hns3-driver\u0027\n\nJijie Shao says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: hns3: some cleanups for hns3 driver\n\nPatch 1 sets msg-\u003edesc to NULL after kfree to avoid leaving a\ndangling pointer in a struct that is reused across loop iterations.\n\nPatch 2 adds the missing const qualifier to the reg parameter of\nhclge_log_error(), which is never modified within the function.\n\nPatch 3 uses the txqueue parameter passed by the ndo_tx_timeout\ncallback directly, instead of iterating all tx queues to find the\ntimed out one.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807095435.2959246-1-shaojijie@huawei.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f57b277e8b6f6e6d3bc082be6b67c6bec02d5cbd",
      "tree": "cf9d69329f7f09767ad9e849010b08d3ed1fcc15",
      "parents": [
        "b8f554e13899fe2635a59f0260eec9a047247009"
      ],
      "author": {
        "name": "Jian Shen",
        "email": "shenjian15@huawei.com",
        "time": "Fri Aug 07 17:54:35 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 16:01:54 2026 +0200"
      },
      "message": "net: hns3: use txqueue parameter directly in ndo_tx_timeout\n\nThe ndo_tx_timeout callback already provides the timed out txqueue\nindex. Use it directly instead of iterating all tx queues to find\nthe timed out one.\n\nUse h-\u003ekinfo.num_tqps for the bounds check instead of\nndev-\u003enum_tx_queues, as the ring array is allocated with num_tqps\nentries and num_tx_queues may be larger.  This issue has not been\nencountered in practice, so it is folded into this cleanup rather\nthan tracked as a separate bugfix.\n\nSigned-off-by: Jian Shen \u003cshenjian15@huawei.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260807095435.2959246-4-shaojijie@huawei.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "b8f554e13899fe2635a59f0260eec9a047247009",
      "tree": "8719e0ad53c4acc91c81aaadec296f5c7bb0aa55",
      "parents": [
        "4f20c628b62eb86babdc28cbd1befa6bd858a62d"
      ],
      "author": {
        "name": "Jijie Shao",
        "email": "shaojijie@huawei.com",
        "time": "Fri Aug 07 17:54:34 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 16:01:54 2026 +0200"
      },
      "message": "net: hns3: add missing const qualifier to hclge_log_error() reg parameter\n\nThe reg parameter of hclge_log_error() is never modified within the\nfunction, but is declared as \u0027char *\u0027. Callers pass const strings,\ncausing a compiler warning about discarding the \u0027const\u0027 qualifier.\nAdd the missing const to fix the warning.\n\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260807095435.2959246-3-shaojijie@huawei.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "4f20c628b62eb86babdc28cbd1befa6bd858a62d",
      "tree": "58053bdfee410dce0e987361dd493e3ea3713bbf",
      "parents": [
        "b54074ffb813aa4b97585d97ae1ead69d96432b5"
      ],
      "author": {
        "name": "Jian Shen",
        "email": "shenjian15@huawei.com",
        "time": "Fri Aug 07 17:54:33 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 16:01:54 2026 +0200"
      },
      "message": "net: hns3: set msg-\u003edesc to NULL after kfree in hclge_query_reg_info()\n\nIn hclge_query_reg_info(), msg-\u003edesc is freed by kfree(), but the\ncaller continues to use msg across loop iterations. Set msg-\u003edesc\nto NULL to avoid leaving a dangling pointer in the reused struct.\n\nSigned-off-by: Jian Shen \u003cshenjian15@huawei.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260807095435.2959246-2-shaojijie@huawei.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "f5bbbfec59b4e2fb7520a91de3df8a6174325d6a",
      "tree": "2c8c80de83e682633abc6cf0777022fde66c8e5f",
      "parents": [
        "d58772d8520c7ef247c4b95c9bd76d3a25da9ff5",
        "24aa630f6259e6a2107936c06fed72063f712b64"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Aug 11 06:51:46 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Tue Aug 11 06:51:46 2026 -0700"
      },
      "message": "Merge tag \u0027probes-fixes-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull probes fix from Masami Hiramatsu:\n\n - Convert ELF entry point to file offset in uprobe test\n\n   Convert the ELF entry point address (e_entry) to a file offset using\n   LOAD segment headers in add_remove_uprobe test. This fixes uprobe\n   registration failures (-EINVAL) on non-PIE executables where vaddr\n   exceeds file size.\n\n* tag \u0027probes-fixes-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  selftests/ftrace: Convert ELF entry point to file offset in uprobe test\n"
    },
    {
      "commit": "cba9ccb47e9fa4cc77692fb896cc5ab57a667882",
      "tree": "dadc18f208359bf77eeb9d3f6d33d3e82d11a14a",
      "parents": [
        "71b3ced5047a94c2776e796fe79c387ad9c31d5a"
      ],
      "author": {
        "name": "Jun Yang",
        "email": "junvyyang@tencent.com",
        "time": "Mon Aug 10 18:21:38 2026 +0800"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 15:50:22 2026 +0200"
      },
      "message": "tipc: read le-\u003elink under the node lock in tipc_node_link_down()\n\ntipc_node_link_down() caches the link pointer before taking n-\u003elock:\n\n\tstruct tipc_link *l \u003d le-\u003elink;\t\t/* unlocked */\n\n\tif (!l)\n\t\treturn;\n\ttipc_node_write_lock(n);\n\tif (!tipc_link_is_establishing(l)) {\t/* deref l */\n\t...\n\t\ttipc_link_reset(l);\t\t/* write into l */\n\tif (delete) {\n\t\tkfree(l);\n\t\tle-\u003elink \u003d NULL;\n\nThe delete\u003dtrue caller frees that very object under n-\u003elock, so the lock\ndoes not protect the cached pointer against it:\n\n - CPU A, delete\u003dfalse: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link\n   supervision timer via tipc_node_timeout(), reads l unlocked and then\n   dereferences it under n-\u003elock;\n - CPU B, delete\u003dtrue: netlink TIPC_NL_BEARER_DISABLE -\u003e bearer_disable()\n   -\u003e tipc_node_delete_links() -\u003e tipc_node_link_down(n, bearer_id, true)\n   -\u003e kfree(l).\n\nThe link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers\ndisable_media() only schedules the asynchronous cleanup_bearer() work, so\nits synchronize_net() runs after the links are already gone.  An in-flight\nCPU A that has read l therefore dereferences freed memory once B frees it:\na use-after-free read in tipc_link_is_establishing(), and a use-after-free\nwrite via tipc_link_reset() on the establishing branch.\n\nThe following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:\n\n  BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)\n  Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0\n   tipc_link_is_establishing (net/tipc/link.c:285)\n   tipc_node_link_down (net/tipc/node.c:1076)\n   tipc_node_timeout (net/tipc/node.c:843)\n  Allocated by task 9549:\n   tipc_link_create (net/tipc/link.c:490)\n   tipc_node_check_dest (net/tipc/node.c:1279)\n   tipc_disc_rcv (net/tipc/discover.c:252)\n   tipc_udp_recv (net/tipc/udp_media.c:389)\n  Freed by task 9549:\n   tipc_node_link_down (net/tipc/node.c:1084)\n   tipc_node_delete_links (net/tipc/node.c:1320)\n   bearer_disable (net/tipc/bearer.c:414)\n   __tipc_nl_bearer_disable (net/tipc/bearer.c:992)\n\nMove the le-\u003elink read inside tipc_node_write_lock(), so it is serialised\nagainst the kfree() in the delete path.  A racing teardown now either has\nnot run yet, and we see a valid link, or has already run, and we see NULL.\n\nFixes: 73f646cec354 (\"tipc: delay ESTABLISH state event when link is established\")\nCc: stable@kernel.org\nReported-by: TencentOS Corvus AI \u003ccorvus@tencent.com\u003e\nAssisted-by: tencentos-corvus-ai:kimi-k3\nSigned-off-by: Jun Yang \u003cjunvyyang@tencent.com\u003e\nReviewed-by: Tung Nguyen \u003ctung.quang.nguyen@est.tech\u003e\nLink: https://patch.msgid.link/20260810102147.48191-1-juny24602@gmail.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "71b3ced5047a94c2776e796fe79c387ad9c31d5a",
      "tree": "0fd46ea753d432a7eb993fda696f9c69a0915459",
      "parents": [
        "5f3a13e0bb5ebcc1ca2dfda42ea40b9f3c2be6ea",
        "8a422297391328b8128e5f6b7e1c49b0240ffa82"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 15:39:02 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Tue Aug 11 15:39:02 2026 +0200"
      },
      "message": "Merge branch \u0027net-tls-fail-splice-after-a-failed-async-decrypt\u0027\n\nChuck Lever says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet/tls: Fail splice after a failed async decrypt\n\ntls_sw_recvmsg() and tls_sw_read_sock() both read ctx-\u003easync_wait.err\nonce they hold the reader lock, so a record that failed\nauthentication fails the call. tls_sw_splice_read() has no such\ncheck. sk_err does not stand in for one. The first reader to reach\nsock_error() clears sk_err, while async_wait.err persists. A splice\ntherefore keeps delivering records on a connection the other two\nreaders have already refused.\n\nBoth patches come from a receive-path series for zero-length data\nrecords. Jakub asked for them separately, since the rest of that\nseries is still under discussion.\n\nLink to the original series:\nhttps://patch.msgid.link/20260726-tls-follow-on-v1-0-99bf4cc1c729@kernel.org\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260806-tls-splice-crypto-fix-v1-0-a2624005a286@kernel.org\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    }
  ],
  "next": "8a422297391328b8128e5f6b7e1c49b0240ffa82"
}
