)]}'
{
  "log": [
    {
      "commit": "0b9bc2a3c36b742f372ce72d6bd3049841a48dc1",
      "tree": "c173144da6139c9b62357cae6d4c907ce4a6fdb6",
      "parents": [
        "8d3ae59288f1e7d58d76558a6ee96d533bc5019f"
      ],
      "author": {
        "name": "Paul Moore",
        "email": "paul@paul-moore.com",
        "time": "Thu May 29 17:20:52 2025 -0400"
      },
      "committer": {
        "name": "Paul Moore",
        "email": "paul@paul-moore.com",
        "time": "Mon Aug 17 15:12:42 2026 -0400"
      },
      "message": "lsm: add a LSM specific README.md and SECURITY.md\n\nDO NOT SUBMIT UPSTREAM\n"
    },
    {
      "commit": "8d3ae59288f1e7d58d76558a6ee96d533bc5019f",
      "tree": "a25d6a94ad99aa059aa6dc728c45052fb2968352",
      "parents": [
        "fd923b32d7614047c8b2acecae3915ec94f7afab"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 14:32:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 14:32:26 2026 -0700"
      },
      "message": "Linux 7.2\n"
    },
    {
      "commit": "fd923b32d7614047c8b2acecae3915ec94f7afab",
      "tree": "30d7b3414c9b907d554b504e8a5a90a98a801a5d",
      "parents": [
        "240de1acf318ba53b6d34094030822797c65154a",
        "333238da9a193ffc58792995f3e951e4cb87bfd2"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:15:23 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:15:23 2026 -0700"
      },
      "message": "Merge tag \u0027sched_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull scheduler fix from Borislav Petkov:\n\n - Make sure a delayed sched entity\u0027s runtime stats are updated at the\n   right time so that it receives the proper lag compensation\n\n* tag \u0027sched_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  sched: Update time before requeueing delayed entities\n"
    },
    {
      "commit": "240de1acf318ba53b6d34094030822797c65154a",
      "tree": "b04879ba4642b741300e00d96c39f90b8bf5c60e",
      "parents": [
        "7820dd4a127ae83b530e177faa8e213c2d5717e1",
        "94f39e4c017e66130e476268bdaa0bf61e914fa2"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:12:13 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:12:13 2026 -0700"
      },
      "message": "Merge tag \u0027timers_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull timer fixes from Borislav Petkov:\n\n - Detect a broken EL2 virtual timer in the bcm2712 SoC boards (RPi5)\n   and fallback to the physical one instead\n\n - Fix a build error with ARM rpc_defconfig and function tracer enabled\n\n* tag \u0027timers_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  clocksource/drivers/arm_arch_timer: Workaround bcm2712 broken EL2 virtual timer\n  tick: Include ktime.h and jiffies.h in linux/tick.h\n"
    },
    {
      "commit": "7820dd4a127ae83b530e177faa8e213c2d5717e1",
      "tree": "e799beeb2700da6fe49cd0bedb119c6cdcb4e6f8",
      "parents": [
        "d6e7d57ed967def9c964a58328ffba409f7efb64",
        "ada54c2ba652348c590d1ace6a2f4ff77cbbf809"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:09:37 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:09:37 2026 -0700"
      },
      "message": "Merge tag \u0027core_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull rseq fix from Borislav Petkov:\n\n - Prevent a lockup when rseq grants a timeslice extension\n\n* tag \u0027core_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  rseq: Prevent hard lockup on granted time slice extension\n"
    },
    {
      "commit": "d6e7d57ed967def9c964a58328ffba409f7efb64",
      "tree": "045c036568c4947493f72a01e8ee40e36eb5a5ef",
      "parents": [
        "d5b95e612cde33f9def1a7a6c3242d03d3bbde3a"
      ],
      "author": {
        "name": "Charlie-cy Wu",
        "email": "charlie-cy.wu@mediatek.corp-partner.google.com",
        "time": "Mon Jun 29 16:35:43 2026 +0800"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 11:07:18 2026 -0700"
      },
      "message": "wifi: mt76: mt7921: refactor regd update to fix recursive mutex deadlock\n\nSplit mt7921_mcu_regd_update() into two functions to prevent recursive\nmutex acquisition. Introduce __mt7921_mcu_regd_update() as the internal\nimplementation that assumes the mutex is already held by the caller,\nwhile mt7921_mcu_regd_update() remains as the external interface that\nhandles mutex acquisition and release.\n\nThis fixes a deadlock issue when mt7921_regd_set_6ghz_power_type() is\ncalled with the device mutex already held. Without this change, calling\nmt7921_mcu_regd_update() would attempt to acquire the same mutex again,\ncausing a recursive lock deadlock.\n\nThe __mt7921_mcu_regd_update() function can be safely called when the\ncaller has already acquired the device mutex, avoiding the deadlock\nwhile maintaining proper synchronization for regulatory domain updates.\n\nFixes: dc2608cf5224 (\"wifi: mt76: mt7921: refactor regulatory notifier flow\")\nSigned-off-by: Charlie-cy Wu \u003cCharlie-cy.Wu@mediatek.com\u003e\nTested-by: Mikhail Gavrilov \u003cmikhail.v.gavrilov@gmail.com\u003e\nTested-by: Devin Wittmayer \u003clucid_duck@justthetip.ca\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "d5b95e612cde33f9def1a7a6c3242d03d3bbde3a",
      "tree": "2466a37891ec5c469ee3785090cf861ed2d0d3f9",
      "parents": [
        "9da3fc37f5fe8b5adc0c6dd798d2caa3855dac4c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:40:14 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:40:14 2026 -0700"
      },
      "message": "Revert \"i2c: designware: defer probe if child GpioInt controllers are not bound\"\n\nThis reverts commit 0a4bb2abc3e56d7be6e69b050c88ba52c87e22bf.\n\nThis was reported to break the touchpad on at least some Thinkpads, and\nwhile the revert has hit the i2c tree, it hasn\u0027t hit mine.  So I\u0027m\nreverting it directly just to have this resolved for the imminent 7.2\nrelease.\n\nReported-by: Thorsten Leemhuis \u003clinux@leemhuis.info\u003e\nLink: https://lore.kernel.org/all/b4a4eadb-282f-464c-843a-19d415a34d0c@leemhuis.info/\nCc: Mario Limonciello \u003cmario.limonciello@amd.com\u003e\nCC: Hardik Prakash \u003chardikprakash.official@gmail.com\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "9da3fc37f5fe8b5adc0c6dd798d2caa3855dac4c",
      "tree": "625f8a4ca1eec67fce40f733cadc6d9d13117a62",
      "parents": [
        "16429bb371999e26b243f6462234d841d271c5f1",
        "42c5ca1f0a288a52878bd72a5595b08261057438"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:31:05 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:31:05 2026 -0700"
      },
      "message": "Merge tag \u0027perf_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull perf fixes from Borislav Petkov:\n\n - Prevent the use of exited events as group leaders\n\n - Avoid use-after-free of an event\u0027s group leader by promoting detached\n   sibling events to standalone entities and correct related accounting\n   and state transitions\n\n* tag \u0027perf_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  perf/core: Fix group leader use-after-free after sibling detach\n  perf: Reject exited events as group leaders\n"
    },
    {
      "commit": "16429bb371999e26b243f6462234d841d271c5f1",
      "tree": "5219b4f4f0afc783c3630ca9c43927795b047a21",
      "parents": [
        "dcb68831eac76dbfda1cf5930d3003d938890d34",
        "abe7c8b09bd72a9c726016257c6281f129b4c02d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:28:31 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 10:28:31 2026 -0700"
      },
      "message": "Merge tag \u0027x86_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull x86 fix from Borislav Petkov:\n\n - Add a proper kernel cmdline option to control the TLB invalidation\n   method on x86 prompted mainly by a recent finding on AMD related to\n   INVLPGB/TYLBSYNC invalidations.\n\n   Having the command line option is simply another way to alleviate\n   the situation short-term\n\n* tag \u0027x86_urgent_for_v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  x86/CPU: Add a tlbi\u003d cmdline switch\n"
    },
    {
      "commit": "dcb68831eac76dbfda1cf5930d3003d938890d34",
      "tree": "eb0f406a90219e1387b57e483f3d56f17e327d81",
      "parents": [
        "0bae94aab8208b7107a2dda5de6ce046466663fd",
        "c71bf113dfdf426bdaf106636f573ef87b6613a0"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 07:00:40 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 07:00:40 2026 -0700"
      },
      "message": "Merge tag \u0027block-7.2-20260815\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n\nPull block fix from Jens Axboe:\n \"A single fix for a regression in this cycle, where drbd would leak\n  shared secrets over netlink. This restores the behavior to match\n  what we had before\"\n\n* tag \u0027block-7.2-20260815\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:\n  drbd: don\u0027t leak the shared secret to unprivileged netlink dumps\n"
    },
    {
      "commit": "0bae94aab8208b7107a2dda5de6ce046466663fd",
      "tree": "8af82ec16610bc9b52027d099309969a266aab20",
      "parents": [
        "3eb40771c00a8488fa6ed2cc1fe203477908bf38",
        "6ca662cc71df7eb4eaf1b4bcb07cd3f188ad19f2"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 06:58:27 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 16 06:58:27 2026 -0700"
      },
      "message": "Merge tag \u0027io_uring-7.2-20260815\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n\nPull io_uring fix from Jens Axboe:\n \"Just a single fix for a potential issue on 32-bit x86 with PAE\"\n\n* tag \u0027io_uring-7.2-20260815\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:\n  io_uring/rsrc: reject overflowing regvec bvec byte counts\n"
    },
    {
      "commit": "c71bf113dfdf426bdaf106636f573ef87b6613a0",
      "tree": "c785ed2ff6057c06adb5eba5c252c0ac3a37a3a3",
      "parents": [
        "7f40b346462f563a0d6e841a77b5163d2a882a04"
      ],
      "author": {
        "name": "Christoph Böhmwalder",
        "email": "christoph.boehmwalder@linbit.com",
        "time": "Fri Aug 14 17:16:17 2026 +0200"
      },
      "committer": {
        "name": "Jens Axboe",
        "email": "axboe@kernel.dk",
        "time": "Sat Aug 15 20:00:10 2026 -0600"
      },
      "message": "drbd: don\u0027t leak the shared secret to unprivileged netlink dumps\n\nThe conversion to explicit netlink serialization dropped the\nexclude_sensitive parameter from net_conf_to_skb(), so each caller has\nto sanitize by hand. Two dump paths were missed:\ndrbd_nl_get_connections_dumpit() and the volume-less connection branch\nof get_one_status(). Neither op carries GENL_ADMIN_PERM, so any\nunprivileged local user could read the CRAM-HMAC secret.\n\nAdd a net_conf_to_skb_sanitized() wrapper and route all three callers\nthrough it.\n\nFixes: 8098eeb693c4 (\"drbd: replace genl_magic with explicit netlink serialization\")\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nSigned-off-by: Christoph Böhmwalder \u003cchristoph.boehmwalder@linbit.com\u003e\nLink: https://patch.msgid.link/20260814151617.73752-1-christoph.boehmwalder@linbit.com\nSigned-off-by: Jens Axboe \u003caxboe@kernel.dk\u003e\n"
    },
    {
      "commit": "3eb40771c00a8488fa6ed2cc1fe203477908bf38",
      "tree": "922aec7a266981d35502a328027e5f5536d0bde5",
      "parents": [
        "5e060ff9d18748dbb21b12b821fcfc738823ba93",
        "e36c0670d5ebebd7dba493f14966051f354fbb34"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 15 08:36:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 15 08:36:26 2026 -0700"
      },
      "message": "Merge tag \u0027soc-fixes-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc\n\nPull SoC fixes from Arnd Bergmann:\n \"These are three last-minute fixes for the 7.2 release, though nothing\n  alarming:\n\n   - one error handling fix for optee firmware\n\n   - incorrect i2c data for the apple M3 that was added in 7.2\n\n   - a boot time warning fix for nvidia tegra\"\n\n* tag \u0027soc-fixes-7.2-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc:\n  arm64: tegra: Add EL2 virtual timer interrupt for Tegra194\n  arm64: dts: apple: t8122: Fix I2C resources\n  optee: ffa: Add NULL check in optee_ffa_lend_protmem\n"
    },
    {
      "commit": "5e060ff9d18748dbb21b12b821fcfc738823ba93",
      "tree": "868901d5e925aba97300d5bb18d9bac9b3bd6610",
      "parents": [
        "15ef2f78c49d20d53ec7c0f1c9b40b02e089f2d6",
        "32ef1b30ad736519f7a207bcc2986f3d4129d972"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 15 08:05:58 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 15 08:05:58 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus\u0027 of https://github.com/openrisc/linux\n\nPull OpenRISC fix from Stafford Horne:\n \"A bug fix found by researchers:\n\n   - mask all privileged bits when restoring the supervisor register\n     from sigreturn\"\n\n* tag \u0027for-linus\u0027 of https://github.com/openrisc/linux:\n  openrisc: signal: do not restore privileged SR bits on sigreturn\n"
    },
    {
      "commit": "32ef1b30ad736519f7a207bcc2986f3d4129d972",
      "tree": "dcdcde418e1ce69a8631620374b00e23571ae795",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Ali Ahmet Memis",
        "email": "ali@iusegentoo.com",
        "time": "Fri Aug 07 23:42:30 2026 +0000"
      },
      "committer": {
        "name": "Stafford Horne",
        "email": "shorne@gmail.com",
        "time": "Sat Aug 15 07:14:55 2026 +0100"
      },
      "message": "openrisc: signal: do not restore privileged SR bits on sigreturn\n\nrestore_sigcontext() copies the whole supervision register (SR) from the\nsignal frame and only clears SPR_SR_SM before the value is reloaded into\nthe hardware SR (through ESR and l.rfe) on the return to user space.  All\nother SR bits are left under user control.\n\nAn unprivileged task can thus return from a signal handler through a\ncrafted sigframe that clears SPR_SR_DME.  With the data MMU disabled the\nCPU performs no translation or protection on data accesses, so the task\ngains read and write access to arbitrary physical memory, a local\nprivilege escalation.  SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH\nand the cache-enable bits are exposed the same way.  The ptrace GPR regset\nalready refuses any change to SR for exactly this reason.\n\nRestore only the arithmetic flag bits (F, CY, OV) from the signal frame\nand take every privileged control bit from the SR the kernel saved on\nsignal entry.\n\nVerified with qemu-system-or1k -M or1k-sim: before this change an\nunprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to\nphysical address 0x03000000 (beyond the kernel\u0027s mem\u003d32M); afterwards the\nsame PoC receives SIGSEGV and physical memory is unchanged.\n\nFixes: ac689eb7f9d4 (\"OpenRISC: Signal handling\")\nCc: stable@vger.kernel.org\nSigned-off-by: Ali Ahmet Memis \u003cali@iusegentoo.com\u003e\nSigned-off-by: Stafford Horne \u003cshorne@gmail.com\u003e\n"
    },
    {
      "commit": "15ef2f78c49d20d53ec7c0f1c9b40b02e089f2d6",
      "tree": "4bfdb0f0823fd9195932486565e1c78bfae25863",
      "parents": [
        "dac3e89a2c90c2feeb471e1f22a2512ad424b792",
        "062dc4693e2c10d77de06f61e6f3faf37c0a8383"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 21:51:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 21:51:26 2026 -0700"
      },
      "message": "Merge tag \u0027input-for-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input\n\nPull input fixes from Dmitry Torokhov:\n\n - A couple of fixes to the sur40 touchscreen driver to correct\n   registration and teardown ordering, and to fix error path\n   unwinding when video device registration fails.\n\n* tag \u0027input-for-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:\n  Input: sur40 - fix V4L error path cleanup\n  Input: sur40 - fix input device registration ordering\n"
    },
    {
      "commit": "dac3e89a2c90c2feeb471e1f22a2512ad424b792",
      "tree": "7ba50dba561b413288b6329fd6d37ec95ba56ace",
      "parents": [
        "b26d316aaa8e8b7ff6f4f77006a9b7c20ee848c8",
        "b2601e783a2e54f6963d65f0d94f96d96c146a3a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:48:05 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:48:05 2026 -0700"
      },
      "message": "Merge tag \u0027drm-fixes-2026-08-15\u0027 of https://gitlab.freedesktop.org/drm/kernel\n\nPull drm fixes from Dave Airlie:\n \"While this is large for rc8 time but also AI driven fixes is a lot of\n  it, we had a more traditional screw up, and a regression was just\n  found in the fair scheduling patches that went in back in rc1. This\n  reverts the fair scheduler back to an option and sets the default back\n  to what it should have been. We might have been a bit overly zealous\n  in switching over, but at least it feels more normal than the AI\n  driven fixes.\n\n  Apart from the scheduler, it\u0027s mostly amdgpu and xe fixes, with some\n  misc fixes to the log code and connector code.\n\n  scheduler:\n   - revert fair scheduler patches due to regression\n   - mark fair as experimental\n\n  connector:\n   - fix OOB read in hdmi audio infoframe\n\n  log:\n   - fix divide by 0 if module param is set to 0\n   - fix OOB read on empty message\n   - fix infinite loop for too large scale\n\n  xe:\n   - Fix DPT Allocation paths\n   - Fixes around UM queue BO\n   - Order ring writes before ring tail updates\n   - Add termination on resume for PXP\n   - Document Sentinel and make CTX_TIMESTAMP read TOCTOU-safe\n   - Fix sync entry leak on OA config emit failure\n   - Check managed mutex initilization errors\n   - Fix min frequency setting\n   - Fix xe_device_probe error path\n\n  amdgpu:\n   - Bounds checking fix in CS IOCTL\n   - Bounds checking fix in GEM IOCTL\n   - Display fixes\n   - GPUVM fix\n   - ASPM fix\n   - UVD bounds checking fixes\n   - VCE 3 fix\n   - BT.2020 fixes\n   - NBIF 6.3.1 fix\n   - IP discovery fix\n\n  radeon:\n   - Runtime pm fix\n\n  amdxdna:\n   - skip attempting to populate unmapped pages\"\n\n* tag \u0027drm-fixes-2026-08-15\u0027 of https://gitlab.freedesktop.org/drm/kernel: (51 commits)\n  drm/log: Fix infinite loop when scale is too large for display\n  drm/log: Fix out-of-bounds read on empty message length\n  drm/log: Fix division by zero when scale module parameter is 0\n  drm/xe: Fix xe_device_probe() failure\n  drm/xe: Fix a bug in pc_adjust_freq_bounds()\n  drm/xe/oa: Check managed mutex initialization errors\n  drm/xe/oa: Fix sync entry leak on OA config emit failure\n  drm/xe/lrc: document sentinel and make CTX_TIMESTAMP read TOCTOU-safe\n  drm/xe/pxp: add termination on resume\n  drm/xe: Order ring writes before ring tail updates\n  drm/xe/guc_ads: use uncached mapping for UM queue BO\n  drm/xe/guc_ads: allocate UM queues in VRAM on dGFX\n  drm/xe/guc_ads: allocate UM queues in a separate BO\n  drm/xe: Fix DPT allocation paths.\n  accel/amdxdna: Skip unmapped range in aie2_populate_range()\n  drm/amdgpu: Prefer default discovery offset\n  drm/amdgpu: Reject UVD message with invalid number of h265 refs\n  drm/amdgpu: fix nbif 6.3.1 l1 low power not functional\n  drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE\n  drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix\n  ...\n"
    },
    {
      "commit": "b26d316aaa8e8b7ff6f4f77006a9b7c20ee848c8",
      "tree": "f3627e2f13ee153b67b9b320851471c5e8e5d13e",
      "parents": [
        "06d9a86e0222dcf6858544ba7257994bfe9e63c7",
        "7ae8acad2d5c415ecb754409a4b64f09169c082e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:34:14 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:34:14 2026 -0700"
      },
      "message": "Merge tag \u0027clk-fixes-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux\n\nPull clk fixes from Stephen Boyd:\n \"Fixes for the Qualcomm, Rockchip, and SpacemiT clk drivers:\n\n   - Keep audio working on Rockchip rk3588 by skipping disabling unused\n     clks\n\n   - Fix SpacemiT USB2 clk data so they actually work and keep the HDMA\n     bus clk enabled to avoid system hangs\n\n   - Avoid clk hangs on Qualcomm Eliza display hardware and revert a\n     patch that breaks PCIe on some Qualcomm platforms\"\n\n* tag \u0027clk-fixes-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux:\n  dt-bindings: clock: Replace bouncing emails\n  Revert \"clk: qcom: regmap-phy-mux: Rework the implementation\"\n  clk: spacemit: k3: set hdma clock as critical\n  clk: spacemit: k3: fix USB2 bus clock\n  clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK\n  clk: rockchip: rk3588: don\u0027t disable unused I2S MCLK output gates\n"
    },
    {
      "commit": "06d9a86e0222dcf6858544ba7257994bfe9e63c7",
      "tree": "e1c284b8c553e1b66cf8fc8f2eb57ed5b98e195f",
      "parents": [
        "53313bf327bbc7fa6580d9be314a135513e46fa9",
        "11058bd3d47d57eb3473935feae53868d6d168b7"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:28:29 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:28:29 2026 -0700"
      },
      "message": "Merge tag \u0027spi-fix-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi\n\nPull spi fixes from Mark Brown:\n \"A couple of relatively minor (but as ever important if you\u0027re hitting\n  them) and straightforward driver specific fixes, plus one new device\n  ID documented in the DT bindings for the DesignWare controller\"\n\n* tag \u0027spi-fix-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:\n  spi: virtio: mark device ready before registering the controller\n  spi: dw: fix wrong RX_SAMPLE_DLY setting after resume\n  spi: dt-bindings: snps,dw-apb-ssi: Document Axiado AX3005\n"
    },
    {
      "commit": "53313bf327bbc7fa6580d9be314a135513e46fa9",
      "tree": "0880b913affc313e9c1b23a027575d467c563c5a",
      "parents": [
        "beea256806c4ec5a6d04dca910ec78a4e270e083",
        "66694b5f90f3876fccb87bbd02b453cdc33b3ae4"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:22:47 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 15:22:47 2026 -0700"
      },
      "message": "Merge tag \u0027regulator-fix-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator\n\nPull regulator fixes from Mark Brown:\n \"There\u0027s one fix here for a data entry error in the voltage mapping in\n  the fp9931 driver, and a device ID addition for a LDO in the Qualcomm\n  PM8350b that\u0027s just a trivial quirk\"\n\n* tag \u0027regulator-fix-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator:\n  regulator: fp9931: Fix VPOS/VNEG voltage selector table\n  regulator: qcom-rpmh: Add support for PM8350B\n  regulator: dt-bindings: qcom,rpmh: Add support for PM8350B\n"
    },
    {
      "commit": "beea256806c4ec5a6d04dca910ec78a4e270e083",
      "tree": "b78d180751148fcf0a7507596f7408f34b503432",
      "parents": [
        "d2ed9eaaf2631a4f1c1f3b2fc267aecb2150a7b2",
        "00268f9452d2a0d660aa9c1bb0ca07a994af6a4f"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:59:04 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:59:04 2026 -0700"
      },
      "message": "Merge tag \u0027regmap-fix-v7.2-rc7-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap\n\nPull regmap fixes from Mark Brown:\n \"A couple more fixes for regmap, this time for the SoundWire MBQ\n  support:\n\n   - Several drivers omit the readable_reg callback and it\u0027s generally\n     optional in regmap but the MBQ code had an assumption that one was\n     present added in one of the APIs, remove that\n\n   - The timeout and retry intervals were swapped in read_poll_timeout()\n     for soundwire-mbq\"\n\n* tag \u0027regmap-fix-v7.2-rc7-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap:\n  regmap: sdw-mbq: don\u0027t call an unset readable_reg callback\n  regmap: sdw-mbq: Fix swap of timeout and retry times\n"
    },
    {
      "commit": "d2ed9eaaf2631a4f1c1f3b2fc267aecb2150a7b2",
      "tree": "eafee427e9f5cef47ed576da58b6197a09c7a26b",
      "parents": [
        "a823c9da52b2cf81e2203870d758871470b3bcfc",
        "00179ed9fbe07799676e2cb63c4e7f0e7cd80a5c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:46:42 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:46:42 2026 -0700"
      },
      "message": "Merge tag \u0027mmc-v7.2-rc2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc\n\nPull MMC fixes from Ulf Hansson:\n\n - atmel-mci: Fix use-after-free in atmci_remove due to race condition\n\n - loongson2: Fix sg iteration in data reorder functions\n\n - omap_hsmmc: Fix busy_timeout overflow in ns conversion on 32-bit\n\n - sdhci:\n     - Make tuning_err a signed int\n     - Unmap the bounce buffer before device release\n\n* tag \u0027mmc-v7.2-rc2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc:\n  mmc: loongson2: Fix sg iteration in data reorder functions\n  mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit\n  mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition\n  mmc: sdhci: unmap the bounce buffer before device release\n  mmc: sdhci: make tuning_err a signed int\n"
    },
    {
      "commit": "a823c9da52b2cf81e2203870d758871470b3bcfc",
      "tree": "da83aa886da36e7461623d420905047a89fb0bed",
      "parents": [
        "a5161661ae99f497affa83a5b8654e457cda6267",
        "090a95dbe13df9965279b588d97eda134831769c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:34:17 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 14:34:17 2026 -0700"
      },
      "message": "Merge tag \u0027pmdomain-v7.2-rc2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm\n\nPull pmdomain fixes from Ulf Hansson:\n\n - arm: Don\u0027t treat performance state 0 as an error\n\n - mediatek:\n   - Fix mt8183 hang on boot\n   - Fix potential null pointer dereference\n   - Prevent using uninitialized data\n   - Avoid setting RTFF\u0027s CLK_DIS before NRESTORE\n\n - qcom: Add missing MXC and MMCX power domains for Eliza\n\n* tag \u0027pmdomain-v7.2-rc2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/linux-pm:\n  pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()\n  pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza\n  pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0\n  pmdomain: mediatek: Fix mt8183 hang on boot\n  pmdomain: mediatek: fix remaining %pOF after of_node_put()\n  pmdomains: mediatek: Avoid setting RTFF\u0027s CLK_DIS before NRESTORE\n"
    },
    {
      "commit": "a5161661ae99f497affa83a5b8654e457cda6267",
      "tree": "e5e86118cc504d8e1ac956e966e7f47b8f540598",
      "parents": [
        "c5890ac6d55c3d13e2d17817fec6676941ef08ee",
        "a92ee0d2486a8b3cd1483afdb6db21b51853867e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 10:41:36 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 10:41:36 2026 -0700"
      },
      "message": "Merge tag \u0027sound-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n\nPull sound fixes from Takashi Iwai\"\n \"A handful of small device-specific quirks, regression fixes, and build\n  fixes. Nothing really stands out.\n\n   - Fix for a potential UAF in in USB-audio MIDI2 endpoint handling\n\n   - Fix for a mixer regression on SteelSeries Arctis Nova 5 in\n     USB-audio\n\n   - ASoC Intel HDMI-In capture, ACPI match table additions and quirks\n\n   - ASoC AMD quirk for HyperX OMEN\n\n   - Fix for ASoC Xilinx about crash in pcm formatter IRQ handlers\n\n   - Fixes for ASoC Realtek rt1320 and rt5645 codecs\n\n   - Fixes for ASoC TI tas2781 and tac5xx2-sdw build errors\"\n\n* tag \u0027sound-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound:\n  ASoC: Intel: NVL: Add entry for HDMI-In capture support to non-I2S codec boards.\n  ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers\n  ASoC: tac5xx2-sdw: select REGMAP_SOUNDWIRE_MBQ\n  ASoC: rt1320: run the initialisation preset on the first hardware init\n  ASoC: rt5645: Perform the initial jack detect at probe\n  ASoC: Intel: sof_rt5682: Add HDMI-In capture with rt5682 support for NVL.\n  ASoC: Intel: soc-acpi: Add entry for HDMI_In capture support in NVL match table\n  ASoC: amd: yc: Add DMI quirk for HyperX OMEN Gaming Laptop 16-ap1xxx\n  ASoC: tas2781: fix clang build error for goto bypassing cleanup variable\n  ALSA: usb-audio: Fix mixer regression on SteelSeries Arctis Nova 5\n  ALSA: usb: Fix UAF at delayed release of MIDI2 EPs\n"
    },
    {
      "commit": "c5890ac6d55c3d13e2d17817fec6676941ef08ee",
      "tree": "1b943d277dca60ab99f85f5f651341b9187f4f85",
      "parents": [
        "ad8d485e665829ecbf3c97b22ce251f8ff5f8037",
        "91880e4a7fac45bc407771bc57bbaf4f37e9b4c3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 10:18:06 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 10:18:06 2026 -0700"
      },
      "message": "Merge tag \u0027ceph-for-7.2-rc8\u0027 of https://github.com/ceph/ceph-client\n\nPull ceph fixes from Ilya Dryomov:\n \"A handful of tiny fixes, with the main ones being a follow-up for\n  CEPH_IOC_SET_LAYOUT{,_POLICY} ioctl permissions check that went into\n  rc5 and a userspace compatibility fixup.  The rest mostly harden\n  against malformed network input.  All marked for stable\"\n\n* tag \u0027ceph-for-7.2-rc8\u0027 of https://github.com/ceph/ceph-client:\n  ceph: use the mount idmap for the owner checks in the SET_LAYOUT ioctls\n  ceph: fix MDS random selection readiness predicate\n  libceph: Avoid using invalid osd indices from primary_temp\n  libceph: fix OOB read in decode_watchers() via missing bounds check\n  libceph: fix multiple unsafe decodes in decode_locker()\n  libceph: tolerate addrvecs with multiple entries of the same type\n"
    },
    {
      "commit": "ad8d485e665829ecbf3c97b22ce251f8ff5f8037",
      "tree": "cdfb6ad04701df82290575494f40fbb00efe0512",
      "parents": [
        "97a91cc439d92e1afe77708d00d30681f1740bbc",
        "b64a9f67e082e04835ddd69d422a25168d69375b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 07:58:01 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 07:58:01 2026 -0700"
      },
      "message": "Merge tag \u0027vfs-7.2-rc8.fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs\n\nPull vfs fixes from Christian Brauner:\n\n - Don\u0027t warn when a mount is completed from another user namespace.\n\n   fsopen() records the caller\u0027s user namespace in fc-\u003euser_ns and\n   hands back an ordinary file descriptor. The task that calls\n   fsconfig(FSCONFIG_CMD_CREATE) doesn\u0027t have to be the one that\n   created the context, and mount_capable() lets it through as long\n   as the caller has CAP_SYS_ADMIN over fc-\u003euser_ns, which anyone in\n   an ancestor namespace does. So fc-\u003euser_ns !\u003d current_user_ns()\n   is something an unprivileged user can arrange.\n\n   Both overlayfs and binfmt_misc WARN_ON() that. Overlayfs already\n   has the same check as a plain error return in ovl_parse_param().\n\n   Drop the WARN_ON() and just refuse. Add selftests for both cases.\n\n - Reject pid allocations through dead ancestor pid namespaces.\n\n   Require PIDNS_ADDING in every namespace that will receive the pid\n   before publishing any of them. That preserves the invariant that\n   free_pid() never decrements pid_allocated in a namespace whose\n   child_reaper is no longer live. The existing ENOMEM behavior is\n   unchanged.\n\n* tag \u0027vfs-7.2-rc8.fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs:\n  pid: reject allocations through dead ancestor pid namespaces\n  selftests/filesystems: test completing a context from another user namespace\n  binfmt_misc: don\u0027t warn when the mount is completed from another user namespace\n  ovl: don\u0027t warn when the mount is completed from another user namespace\n"
    },
    {
      "commit": "97a91cc439d92e1afe77708d00d30681f1740bbc",
      "tree": "040478848d81307e149cc097697f6529f1da0e02",
      "parents": [
        "a64d500b0078e16e9abb25baca4dee1dbc9054fc",
        "5d588c684833e678a0008eb69c33190f01a65f4b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 07:51:55 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 07:51:55 2026 -0700"
      },
      "message": "Merge tag \u0027riscv-for-linus-v7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux\n\nPull RISC-V fixes from Paul Walmsley:\n\n - Fix a fault caused when the RISC-V Zbb-enabled strlen() is executed\n   on a string that ends right before a page boundary, when the next\n   page is unmapped\n\n - Fix a race with the misaligned vector performance testing code that\n   can prevent the outcome of the test from being stored into the vDSO\n   cache\n\n - Fix a kernel warning generated by the ftrace code when\n   ftrace_modify_call_code() runs against a ftrace-traced function where\n   a kprobe has already been attached. This shows up in the bpf\n   kselftests\n\n* tag \u0027riscv-for-linus-v7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux:\n  riscv: lib: Fix ZBB strnlen reading past count boundary\n  riscv: hwprobe: Register unaligned probes before usermode\n  riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions\n"
    },
    {
      "commit": "a64d500b0078e16e9abb25baca4dee1dbc9054fc",
      "tree": "fd778739b032e2d0b06c5b51a63b8defcd413287",
      "parents": [
        "2f1baf1fc8929e6c48370be543ad028ac7ad4131"
      ],
      "author": {
        "name": "Gao Xiang",
        "email": "xiang@kernel.org",
        "time": "Wed Aug 12 21:11:43 2026 +0800"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 14 07:44:41 2026 -0700"
      },
      "message": "erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms\n\nCONFIG_NR_CPUS doesn\u0027t define on some UP platforms (e.g.  arm), so this\ncan cause make oldconfig to loop indefinitely when CONFIG_SMP\u003dn:\n\n  $ make ARCH\u003darm allmodconfig\n  $ sed -i \"/CONFIG_SMP\u003dy/d\" .config\n  $ sed -i \"/CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS.*/d\" .config\n\n  EROFS LZMA default maximum decompression streams (EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS) [0] (NEW)\n  EROFS LZMA default maximum decompression streams (EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS) [0] (NEW)\n  ...\n\nLet\u0027s guard NR_CPUS with SMP instead of using a hardcoded arbitrary CPU\nuplimit here, similar to commit a3344078101c (\"mm: make SPLIT_PTE_PTLOCKS\ndepend on SMP\").\n\nThe initial report from SJ Park was for m68k [1] (m68k is the only arch\nwithout NR_CPUS in Kconfig), and that got fixed in commit 1fd495ef09ee\n(\"m68k: Define NR_CPUS to 1\")\n\nReported-by: SJ Park \u003csj@kernel.org\u003e\nLink: https://lore.kernel.org/all/anuyFHLUGDjZWY4K@XiangdeMacBook-Pro.local/T/#u [1]\nCloses: https://lore.kernel.org/r/20260728065447.91511-1-sj@kernel.org\nReported-by: Guenter Roeck \u003cgroeck7@gmail.com\u003e\nCloses: https://lore.kernel.org/r/87853c96-cc8f-49e6-81b1-02bfe409e372@roeck-us.net\nFixes: c9b47e6b2311 (\"erofs: cap LZMA stream pool size\")\nSigned-off-by: Gao Xiang \u003cxiang@kernel.org\u003e\nTested-by: SJ Park \u003csj@kernel.org\u003e\nTested-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "333238da9a193ffc58792995f3e951e4cb87bfd2",
      "tree": "799de0ffddefc3b9ae01f788885a793a3635302d",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Vincent Guittot",
        "email": "vincent.guittot@linaro.org",
        "time": "Fri Aug 14 15:52:41 2026 +0200"
      },
      "committer": {
        "name": "Peter Zijlstra",
        "email": "peterz@infradead.org",
        "time": "Fri Aug 14 16:12:55 2026 +0200"
      },
      "message": "sched: Update time before requeueing delayed entities\n\nIn order to compute the right lag, it is required to update time to \u0027now\u0027.\nWithout this, the delayed entity might appear younger than it really is and\nreceive less compensation for having waited.\n\nSigned-off-by: Vincent Guittot \u003cvincent.guittot@linaro.org\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\n"
    },
    {
      "commit": "b2601e783a2e54f6963d65f0d94f96d96c146a3a",
      "tree": "470bc9022dd7fc70d2d3662e56f779c634d7e960",
      "parents": [
        "7581e7c73e8fbea7c885583146fbe09a8462a25d",
        "ef526d122b62af5afa437f095aa6661a953676c4"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 14:24:11 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 15:41:40 2026 +1000"
      },
      "message": "Merge tag \u0027drm-xe-fixes-2026-08-13\u0027 of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes\n\nDriver Changes:\n- Fix DPT Allocation paths (Maarten)\n- Fixes around UM queue BO (Jia)\n- Order ring writes before ring tail updates (Matthew Brost)\n- Add termination on resume for PXP (Daniele)\n- Document Sentinel and make CTX_TIMESTAMP read TOCTOU-safe (Gajendra)\n- Fix sync entry leak on OA config emit failure (Linmao Li)\n- Check managed mutex initilization errors (Linmao Li)\n- Fix min frequency setting (Vinay)\n- Fix xe_device_probe error path (Raag)\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Thomas Hellstrom \u003cthomas.hellstrom@linux.intel.com\u003e\nLink: https://patch.msgid.link/an4ZogmPqP2Xtfx3@fedora\n"
    },
    {
      "commit": "7581e7c73e8fbea7c885583146fbe09a8462a25d",
      "tree": "1ad0663e3fb6a5ebaba9a3cd568b02119f3fb163",
      "parents": [
        "c3da119ddf7776d6be8ad521e9beef6400efa707",
        "f4f2bba28df9b9aaa00262a462139dbbcdc38d9f"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 13:19:02 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 13:19:08 2026 +1000"
      },
      "message": "Merge tag \u0027drm-misc-fixes-2026-08-13\u0027 of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes\n\ndrm-misc-fixes for v7.3:\n- Revert fair scheduler patches and mark fair policy as experimental due\n  to reported regressions.\n- Fix OOB read in connector/hdmi infoframe.\n- Handle invalid scaling parameters and empty messages in log target.\n- Skip attempting to populate unmapped pages in amdxdna.\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Maarten Lankhorst \u003cmaarten.lankhorst@linux.intel.com\u003e\nLink: https://patch.msgid.link/a9b38792-bdd0-42da-a46a-7a048c26c0c2@linux.intel.com\n"
    },
    {
      "commit": "c3da119ddf7776d6be8ad521e9beef6400efa707",
      "tree": "15016808bff69b3cf9092b8e2a48013122e4974f",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58",
        "ac828b94e027d29af82325fcc55556dc8173fd85"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 12:41:01 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 14 12:43:06 2026 +1000"
      },
      "message": "Merge tag \u0027amd-drm-fixes-7.2-2026-08-12\u0027 of https://gitlab.freedesktop.org/agd5f/linux into drm-fixes\n\namd-drm-fixes-7.2-2026-08-12:\n\namdgpu:\n- Bounds checking fix in CS IOCTL\n- Bounds checking fix in GEM IOCTL\n- Display fixes\n- GPUVM fix\n- ASPM fix\n- UVD bounds checking fixes\n- VCE 3 fix\n- BT.2020 fixes\n- NBIF 6.3.1 fix\n- IP discovery fix\n\nradeon:\n- Runtime pm fix\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Alex Deucher \u003calexander.deucher@amd.com\u003e\nLink: https://patch.msgid.link/20260812200720.2155401-1-alexander.deucher@amd.com\n"
    },
    {
      "commit": "2f1baf1fc8929e6c48370be543ad028ac7ad4131",
      "tree": "fdbd28d6adfc8571c2de6bf4507941ce3670fc2f",
      "parents": [
        "3aa1dcaa4f6f5ae08936491e08bd456f331f2d40",
        "c3730b8373bb5059d735509b9e6a00d7eb337d7c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 16:08:22 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 16:08:22 2026 -0700"
      },
      "message": "Merge tag \u0027trace-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull tracing fixes from Steven Rostedt:\n\n - Fix NULL pointer dereference when matching unloaded module wildcard\n   event\n\n   The set_event can take events for modules that have not been loaded\n   yet. This is done by writing \u0027\u003cevent\u003e:mod:\u003cmodule\u003e\u0027.\n\n   If \u0027\u003cevent\u003e\u0027 is not added, then it means to add all events in\n   \u003cmodule\u003e. This wildcard is represented by a NULL pointer. If one were\n   to try to remove the same module item with a named event it would\n   cause a NULL pointer dereference when comparing the NULL with the\n   name in strcmp().\n\n      echo \u0027:mod:kvm\u0027 \u003e /sys/kernel/tracing/set_event\n      echo \u0027!kvm_ack_irq:mod:kvm\u0027 \u003e\u003e /sys/kernel/tracing/set_event\n\n   The above will do a strcmp(\"kvm_ack_irq\", NULL) and crash the kernel.\n\n   Test for NULL (wildcard) before doing the strcmp().\n\n - Fix event data field race in loading two modules at the same time\n\n   When a module loads, its trace events get registered. The fields of\n   the events are also dynamically created and added to the events\n   fields list. It also will call a function that will look at all the\n   events for updates that need to be done. If two modules load at the\n   same time, the one that scans all events and their fields may read\n   the one being added as the scan doesn\u0027t take the event_mutex. This\n   may cause a data race.\n\n   Have the scan take the event_mutex to prevent the race.\n\n* tag \u0027trace-v7.2-rc7\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  tracing: Fix race between update_event_fields and, event_define_fields\n  tracing: Fix NULL pointer dereference in module event cache removal\n"
    },
    {
      "commit": "c3730b8373bb5059d735509b9e6a00d7eb337d7c",
      "tree": "6aaf8a3bbdb155b15bf109eeb64a3fc9cc2e6ed8",
      "parents": [
        "b69859204d4db3acd86c1c2dadcef0d77b451933"
      ],
      "author": {
        "name": "Michael Wu",
        "email": "michael@allwinnertech.com",
        "time": "Mon Aug 10 14:32:30 2026 +0800"
      },
      "committer": {
        "name": "Steven Rostedt",
        "email": "rostedt@goodmis.org",
        "time": "Thu Aug 13 15:38:25 2026 -0400"
      },
      "message": "tracing: Fix race between update_event_fields and, event_define_fields\n\nThe following sequence may leads race between event_define_fields()\nand update_event_fields():\n\n CPU0 (loads module A)                      CPU1 (loads module B)\n \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d            \u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n load_module(A)                             load_module(B)\n   notifier_call_chain                        notifier_call_chain\n     trace_module_notify                        trace_module_notify\n       mutex_lock(\u0026event_mutex)                   trace_event_update_all()\n         trace_module_add_events(A)                 down_write(\u0026trace_event_sem)\n            __register_event(call_A)\n              __add_event_to_tracers(call_A)\n                event_define_fields(call_A)\n                  for each f:                         list_for_each_entry(field,\n                    list_add(\u0026f-\u003elink,                                    \u0026class-\u003efields, link)\n                             \u0026class-\u003efields)            field \u003d class-\u003efields-\u003enext;\n\nWhere access to the class-\u003efields is not protected by the event_mutex in\ntrace_event_update_all().\n\nThis produces the following panic:\n   Unable to handle kernel access ... at virtual address 0000000000000018\n   pc : update_event_fields+0xf8/0x368\n   Call trace:\n    update_event_fields+0xf8/0x368\n    trace_event_update_all+0x7c/0x2b4\n    trace_module_notify+0x4c/0x1dc\n    notifier_call_chain+0x84/0x168\n    blocking_notifier_call_chain_robust+0x64/0xd4\n    load_module+0x10c8/0x123c\n    __arm64_sys_finit_module+0x230/0x31c\n\nFix by taking event_mutex in trace_event_update_all() before\ntrace_event_sem.\n\nCc: stable@vger.kernel.org\nFixes: b3bc8547d3be (\"tracing: Have TRACE_DEFINE_ENUM affect trace event types as well\")\nLink: https://patch.msgid.link/2e5730d2-c631-da41-3a3a-ae35bb4895f3@allwinnertech.com\nSigned-off-by: Michael Wu \u003cmichael@allwinnertech.com\u003e\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\n"
    },
    {
      "commit": "b69859204d4db3acd86c1c2dadcef0d77b451933",
      "tree": "a294a374e9ba1049a80edca141ef841fe31cc53e",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Hui Su",
        "email": "sh_def@163.com",
        "time": "Wed Aug 12 01:39:03 2026 +0800"
      },
      "committer": {
        "name": "Steven Rostedt",
        "email": "rostedt@goodmis.org",
        "time": "Thu Aug 13 15:38:03 2026 -0400"
      },
      "message": "tracing: Fix NULL pointer dereference in module event cache removal\n\nA module-only event filter such as \":mod:foo\" is cached with a NULL\nevent_mod-\u003ematch when foo has not been loaded. If a later write tries to\nremove a specific match from the same module, remove_cache_mod() passes\nthe NULL cached match to strcmp(), causing a NULL pointer dereference.\n\nThe issue can be reproduced from userspace:\n\n  echo \u0027:mod:trace_events_kunit_missing\u0027 \u003e /sys/kernel/tracing/set_event\n  echo \u0027!foo_bar:mod:trace_events_kunit_missing\u0027 \u003e\u003e /sys/kernel/tracing/set_event\n\nThe second write must be a concatenation (\"\u003e\u003e\") to not include O_TRUNC as\nthat would cause ftrace_clear_events() to clear the cached modules lines.\n\nThe crash was reproduced on x86_64 QEMU while KUnit workers contended on\nthe event tracing path:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  #PF: supervisor read access in kernel mode\n  RIP: 0010:strcmp+0x10/0x30\n  Call Trace:\n   __ftrace_set_clr_event_nolock+0x373/0x4a0\n   ftrace_set_clr_event+0xf0/0x180\n   ftrace_event_write+0xdf/0x110\n   vfs_write+0xf6/0x440\n   ksys_write+0x68/0xe0\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCheck event_mod-\u003ematch before comparing it, consistent with the existing\nNULL checks for the cached system and event fields. The mismatched removal\ncontinues to return -EINVAL; a broad cached module filter is removed with\n\"!:mod:\u003cmodule\u003e\".\n\nCc: stable@vger.kernel.org\nLink: https://patch.msgid.link/20260811173902.1927376-2-sh_def@163.com\nFixes: b355247df104 (\"tracing: Cache \\\":mod:\\\" events for modules not loaded yet\")\nReported-by: syzbot+4d3143c8e28f6266c636@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/lkml/6a7a6b7f.9c11d2ce.289b96.00f8.GAE@google.com/\nSigned-off-by: Hui Su \u003csh_def@163.com\u003e\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\n"
    },
    {
      "commit": "11058bd3d47d57eb3473935feae53868d6d168b7",
      "tree": "f395541a8607eb8a97660e32206ca4b7be498539",
      "parents": [
        "133c71b2c0bc976a4751f9e05ef7cdea67f964e5"
      ],
      "author": {
        "name": "Jasper Wise",
        "email": "jaspwise@amazon.co.uk",
        "time": "Thu Aug 13 08:46:18 2026 +0000"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Thu Aug 13 17:34:01 2026 +0100"
      },
      "message": "spi: virtio: mark device ready before registering the controller\n\nvirtio_spi_probe() registers the SPI controller with\ndevm_spi_register_controller(). spi_register_controller() binds a child\ninline unless its driver has asked for asynchronous probing, so a\nperipheral that performs a transfer during its own probe reaches\nvirtio_spi_transfer_one(), which kicks the virtqueue before probe has\nreturned.\n\nThe driver never calls virtio_device_ready(), so DRIVER_OK is set on its\nbehalf by virtio_dev_probe(), only once probe has returned. The virtio\nspec is explicit about that ordering in 3.1 Device Initialization:\n  |  The driver MUST NOT send any buffer available notifications to the\n  |  device before setting DRIVER_OK.\n\nA device that waits for DRIVER_OK before servicing the queue therefore\nleaves the transfer unanswered, and virtio_spi_transfer_one() waits for its\ncompletion with no timeout, so probe never returns.\n\nMark the device ready before registering the controller, as done for the\nsame reason in commit f5866db64f34 (\"virtio_console: enable VQs early\") and\ncommit 1d774589f924 (\"i2c: virtio: mark device ready before registering the\nadapter\").\n\nFixes: f98cabe3f6cf (\"SPI: Add virtio SPI driver\")\nSigned-off-by: Jasper Wise \u003cjaspwise@amazon.co.uk\u003e\nLink: https://patch.msgid.link/20260813084618.613172-1-jaspwise@amazon.co.uk\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "3aa1dcaa4f6f5ae08936491e08bd456f331f2d40",
      "tree": "a54e92e33ab75e5545796457447ad8b9a5231107",
      "parents": [
        "e14aacefb78d942d2308d9821fe52d75d21a824e"
      ],
      "author": {
        "name": "Mikhail Gavrilov",
        "email": "mikhail.v.gavrilov@gmail.com",
        "time": "Tue Aug 04 17:00:04 2026 +0500"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 09:00:55 2026 -0700"
      },
      "message": "Revert \"wifi: mt76: Disable napi when removing device\"\n\nThis reverts commit 13b7e6a96a005c656d38f3da51581deaf9866375.\n\nThat commit made mt76_dma_cleanup() disable every RX NAPI instance before\ndeleting it, to silence WARNs in __netif_napi_del_locked() and\npage_pool_disable_direct_recycling() seen when unloading mt7915e with an\nMT7916.\n\nOn mt7921e and mt7925e the same instances are already disabled earlier,\nin mt7921e_unregister_device() and mt7925e_unregister_device(), which\nonly afterwards call mt792x_dma_cleanup() -\u003e mt76_dma_cleanup().  Each\ninstance is therefore disabled twice, and napi_disable() is not\nidempotent: on return it leaves NAPIF_STATE_SCHED and NAPIF_STATE_NPSVC\nset, so the second call spins in usleep_range() forever, waiting for bits\nthat nobody will clear.\n\nmt7921_pci_shutdown() and mt7925_pci_shutdown() reuse the remove path, so\nthis is hit on every reboot, poweroff and module unload.  It is silent:\nthe stuck task keeps sleeping and rescheduling, so neither the hung task\ndetector nor the lockup detectors fire, and the last line on the console\nis \"systemd-shutdown[1]: Rebooting.\"\n\n  task:modprobe        state:D stack:25720 pid:7954  tgid:7954\n  Call Trace:\n   \u003cTASK\u003e\n   __schedule+0x11b8/0x26d0\n   schedule+0xe7/0x2f0\n   schedule_hrtimeout_range_clock+0x218/0x330\n   usleep_range_state+0x133/0x1b0\n   napi_disable_locked+0x37d/0x5f0\n   napi_disable+0x43/0x80\n   mt76_dma_cleanup+0x2b4/0x860 [mt76]\n   mt7921_pci_remove+0x17f/0x350 [mt7921e]\n   pci_device_remove+0xb6/0x1e0\n   device_release_driver_internal+0x38d/0x540\n   driver_detach+0xd0/0x1b0\n   bus_remove_driver+0x127/0x2d0\n   pci_unregister_driver+0x2a/0x280\n   __do_sys_delete_module+0x36a/0x5b0\n   do_syscall_64+0x11c/0x6d0\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   \u003c/TASK\u003e\n\nDropping the two driver-side loops instead was tried and rejected: with\nthem gone, the RX poll can reach mt76_token_release() via\nPKT_TYPE_TXRX_NOTIFY and mt7921_mac_tx_free() while\nmt76_connac2_tx_token_put() is running idr_destroy(\u0026dev-\u003etoken) outside\ntoken_lock, which is a use-after-free rather than a hang [1].\n\nRevert for now, so that reboot, poweroff and module unload work again.\nThe WARNs on mt7915e are a less severe problem than an unbootable\nmachine, and fixing them belongs in the drivers that delete the NAPI\ninstances, where each one can pick a point that is safe for its own\nteardown order, rather than in the shared mt76_dma_cleanup().\n\n[ This is the \"landing soonish\" known regression fix mentioned in the\n  previous networking merge commit       - Linus ]\n\nReported-by: Bert Karwatzki \u003cspasswolf@web.de\u003e\nCloses: https://lore.kernel.org/all/20260724151419.26014-1-spasswolf@web.de/\nCloses: https://bugzilla.kernel.org/show_bug.cgi?id\u003d221818\nLink: https://lore.kernel.org/all/20260730050428.GA73812@sol/ [1]\nSigned-off-by: Mikhail Gavrilov \u003cmikhail.v.gavrilov@gmail.com\u003e\nAcked-by: Nicolas Cavallari \u003cnicolas.cavallari@green-communications.fr\u003e\nFixes: 13b7e6a96a00 (\"wifi: mt76: Disable napi when removing device\")\nTested-by: Devin Wittmayer \u003clucid_duck@justthetip.ca\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "e14aacefb78d942d2308d9821fe52d75d21a824e",
      "tree": "1bad843db01ff93e3951865d1fdb7080e6ac2493",
      "parents": [
        "83a4f90e9835d3d61fe3dd39ffbbcac752467d09",
        "9006c116dd111d457bf5d074990210f70a4ad2c8"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 08:37:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 08:37:26 2026 -0700"
      },
      "message": "Merge tag \u0027net-7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Paolo Abeni:\n \"Including fixes from netfilter.\n\n  There is a known WiFi/mt76 regression, waiting for a complete fix that\n  should land soonish.\n\n  Previous releases - regressions:\n\n   - tcp: fix icsk_ack.ato bitfield overflow\n\n   - af_unix: Unlink scc_entry in unix_del_edge()\n\n   - ipv4: fix use-after-free in fib_nhc_update_mtu()\n\n   - netfilter:\n      - ipset: fix refcount race between list:set GC and swap\n      - nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort\n        path\n\n   - sched: act_ct: fix sk_buff leak when the header checks reject a\n     packet\n\n   - sctp: clear new_transport when removing a peer\n\n   - dibs: correct freeing of dmb_clientid_arr\n\n   - ovpn: fix NULL dereference when killing missing key\n\n   - eth:\n      - veth: fix queue index used to wake the peer txq in veth_poll\n      - ngbe: fix NULL pointer dereference in non-MSI-X interrupt\n        enabling\n      - gve: fix zero-length skb frag with header-split\n\n  Previous releases - always broken:\n\n   - core: fix skb length accounting after generic XDP frag adjustment\n\n   - af_packet: don\u0027t send zero-byte data in tpacket_snd().\n\n   - eth:\n      - bnxt: avoid deadlock when canceling IRQ affinity notifier\n      - ipvlan: inherit needed_headroom and needed_tailroom from\n        phy_dev\"\n\n* tag \u0027net-7.2-rc8\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (55 commits)\n  l2tp: fix tunnel and session refcount leak on seq_file release\n  net/sched: cls_bpf: reject dev-bound programs bound to a different device\n  sctp: fix use-after-free of cached ASCONF chunk\n  net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n  sctp: clear new_transport when removing a peer\n  net/dibs: Correct freeing of dmb_clientid_arr\n  net/sched: cls_u32: skip hash tables in u32_bind_class()\n  gve: fix NULL dereference due to missing ptp adjfine\n  gve: fix zero-length skb frag with header-split\n  net/sched: act_api: fix TOCTOU NULL deref on a-\u003egoto_chain\n  af_packet: Don\u0027t send zero-byte data in tpacket_snd().\n  tipc: read le-\u003elink under the node lock in tipc_node_link_down()\n  selftests: tls: cover splice after a failed decrypt\n  net/tls: Fail tls_sw_splice_read() after a failed async decrypt\n  net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling\n  net: tap: fix wrong transport_header when sending VLAN-tagged frame\n  net: packet: fix wrong transport_header when sending VLAN-tagged frame\n  vxlan: do not arm the ageing timer on a device that is down\n  ipv4: fix use-after-free in fib_nhc_update_mtu()\n  NTB: ntb_netdev: Preserve RX queue depth on allocation failure\n  ...\n"
    },
    {
      "commit": "83a4f90e9835d3d61fe3dd39ffbbcac752467d09",
      "tree": "3bab72e9ae6a57ae6f25d92e518bae40cc8ef974",
      "parents": [
        "b4f5144d37403d529334573ef2a1bb6ca4a2c553",
        "42d217add8d80d6e7d9f58f80d11ea9b07ea113e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:31:21 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:31:21 2026 -0700"
      },
      "message": "Merge tag \u0027firewire-fixes-7.2-final\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394\n\nPull firewire fix from Takashi Sakamoto:\n \"Fix a NULL pointer dereference in 1394 OHCI PCI driver when probe()\n  returns early with an error, as detected by Syzkaller\"\n\n* tag \u0027firewire-fixes-7.2-final\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394:\n  firewire: ohci: fix NULL pointer dereference in ar_context_release\n"
    },
    {
      "commit": "b4f5144d37403d529334573ef2a1bb6ca4a2c553",
      "tree": "e5c97704314f918a7b782392804f0f2ca801bf39",
      "parents": [
        "64dc3ba55effbf8afcc0099162dfb4138009ad48",
        "44f3468a0aef1aabdad551898ab7cfa2a9d20e99"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:16:58 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:16:58 2026 -0700"
      },
      "message": "Merge tag \u0027gpio-fixes-for-v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull gpio fixes from Bartosz Golaszewski:\n\n - use raw_spinlock_t in gpio-ml-ioh to avoid locking context issues\n\n - fix a race condition in gpio-ml-ioh by sharing the register locks\n   across channels\n\n - fix a use-after-free bug in unbind path in gpio-sloppy-logic-analyzer\n\n* tag \u0027gpio-fixes-for-v7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind\n  gpio: ml-ioh: share the register lock across channels\n  gpio: ml-ioh: use raw_spinlock_t for the register lock\n  gpiolib: Check gc-\u003eget_direction() before calling gpiod_get_direction()\n"
    },
    {
      "commit": "64dc3ba55effbf8afcc0099162dfb4138009ad48",
      "tree": "80336659e12bde884a59cd016a889c2eb653e75d",
      "parents": [
        "3d6d817622b0a9721e3cc404df3469171582be13",
        "1fd495ef09eef96169a379a749c24b5e69974bb8"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:00:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 13 07:00:26 2026 -0700"
      },
      "message": "Merge tag \u0027m68k-for-v7.2-tag2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/geert/linux-m68k\n\nPull m68k fix from Geert Uytterhoeven:\n \"Define NR_CPUS to 1.\n\n  This fixes a long-standing but never critical before oddity on m68k,\n  that turned into a serious configuration issue after a recent erofs\n  change\"\n\n* tag \u0027m68k-for-v7.2-tag2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/geert/linux-m68k:\n  m68k: Define NR_CPUS to 1\n"
    },
    {
      "commit": "f4f2bba28df9b9aaa00262a462139dbbcdc38d9f",
      "tree": "d20e3bd7c46cd02a28ace2e2281502d53484725b",
      "parents": [
        "60baa179ed1333535f6e2da4133511db55278ee4"
      ],
      "author": {
        "name": "Shixiong Ou",
        "email": "oushixiong@kylinos.cn",
        "time": "Wed Jul 29 16:48:15 2026 +0800"
      },
      "committer": {
        "name": "Jocelyn Falempe",
        "email": "jfalempe@redhat.com",
        "time": "Thu Aug 13 15:49:40 2026 +0200"
      },
      "message": "drm/log: Fix infinite loop when scale is too large for display\n\nWhen scale is large enough that scaled_font exceeds the display\ndimensions, rows or columns become 0. A columns value of 0 causes\nan infinite loop in drm_log_draw_kmsg_record() because the loop\nnever decrements len.\n\nCheck for zero rows/columns in drm_log_setup_modeset() and return\nan error, cleaning up the already allocated buffer to avoid a leak.\n\nFixes: 8a4b913df427 (\"drm/log: Add integer scaling support\")\nSigned-off-by: Shixiong Ou \u003coushixiong@kylinos.cn\u003e\nReviewed-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\nLink: https://patch.msgid.link/20260729084815.692944-1-oushixiong1025@163.com\nSigned-off-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\n"
    },
    {
      "commit": "60baa179ed1333535f6e2da4133511db55278ee4",
      "tree": "e9e9469dc9dc9af56822a75b7c6bd9598b3c53f5",
      "parents": [
        "921ac6cb066d09b5765db892d0db0ffaffa98767"
      ],
      "author": {
        "name": "Shixiong Ou",
        "email": "oushixiong@kylinos.cn",
        "time": "Wed Jul 29 16:45:17 2026 +0800"
      },
      "committer": {
        "name": "Jocelyn Falempe",
        "email": "jfalempe@redhat.com",
        "time": "Thu Aug 13 15:47:50 2026 +0200"
      },
      "message": "drm/log: Fix out-of-bounds read on empty message length\n\ndrm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing\nnewline, but len is unsigned int. If len is 0, the subtraction wraps\nto UINT_MAX, causing an out-of-bounds read.\n\nAdd an early return when len is 0.\n\nFixes: 25e2c2a3eff5 (\"drm/log: Color the timestamp, to improve readability\")\nSigned-off-by: Shixiong Ou \u003coushixiong@kylinos.cn\u003e\nReviewed-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\nLink: https://patch.msgid.link/20260729084520.688087-1-oushixiong1025@163.com\nSigned-off-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\n"
    },
    {
      "commit": "921ac6cb066d09b5765db892d0db0ffaffa98767",
      "tree": "d56f07497add580e01213d568e38eb57ea0f7051",
      "parents": [
        "6c916e301fa10de9158b922474ade7b43d726cda"
      ],
      "author": {
        "name": "Shixiong Ou",
        "email": "oushixiong@kylinos.cn",
        "time": "Thu Jul 30 09:44:40 2026 +0800"
      },
      "committer": {
        "name": "Jocelyn Falempe",
        "email": "jfalempe@redhat.com",
        "time": "Thu Aug 13 15:46:50 2026 +0200"
      },
      "message": "drm/log: Fix division by zero when scale module parameter is 0\n\nThe scale module parameter can be set to 0 via kernel command line.\nWhen scale is 0, scaled_font_h and scaled_font_w become 0, causing\na division by zero in the rows/columns calculation.\n\nSince the scale module parameter is read-only (0444 permissions), it\ncannot be changed at runtime via sysfs. Clamp it to 1 once in\ndrm_log_register().\n\nFixes: 8a4b913df427 (\"drm/log: Add integer scaling support\")\nSigned-off-by: Shixiong Ou \u003coushixiong@kylinos.cn\u003e\nReviewed-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\nLink: https://patch.msgid.link/20260730014440.66323-1-oushixiong1025@163.com\nSigned-off-by: Jocelyn Falempe \u003cjfalempe@redhat.com\u003e\n"
    },
    {
      "commit": "a92ee0d2486a8b3cd1483afdb6db21b51853867e",
      "tree": "b7b3612048ba83d337137ceae86296ca48477221",
      "parents": [
        "885c22d259c8b245c479f3e19e9eeee54dee8b24",
        "079e27f52b929b554b90514b081ea40b3d632a25"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 13 15:32:36 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 13 15:32:36 2026 +0200"
      },
      "message": "Merge tag \u0027asoc-fix-v7.2-rc7\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus\n\nASoC: Fixes for v7.2\n\nThis set of fixes is bulked out quite a bit by the inclusion of a lot of\nquirks for various x86 platforms, though there are a few driver specific\nfixes in here too.  Nothing here is terribly critical, we should be fine\nwaiting for the merge window if it\u0027s too much.\n"
    },
    {
      "commit": "ef526d122b62af5afa437f095aa6661a953676c4",
      "tree": "3191046ea8f6f9993f4b993b6a562ba495440281",
      "parents": [
        "5cf82c8cec90056511eb881a267aab6101eaf57a"
      ],
      "author": {
        "name": "Raag Jadav",
        "email": "raag.jadav@intel.com",
        "time": "Mon Aug 10 18:08:20 2026 +0530"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:34 2026 +0200"
      },
      "message": "drm/xe: Fix xe_device_probe() failure\n\nCurrently, xe_device_probe() jumps to err_unregister_display label in case\nof failure except for its last call, which directly returns the error\nwithout required cleanup handling. This results in stale drm device that\nisn\u0027t cleaned up on unwind. Fix it.\n\n[  810.194180] sysfs: cannot create duplicate filename \u0027/devices/pci0000:00/0000:00:01.0/0000:01:00.0/0000:02:01.0/0000:03:00.0/drm/renderD128\u0027\n[  810.194183] CPU: 9 UID: 0 PID: 5616 Comm: modprobe Kdump: loaded Tainted: G S   U      E       7.2.0-rc2-xe #382 PREEMPT(full)\n[  810.194185] Tainted: [S]\u003dCPU_OUT_OF_SPEC, [U]\u003dUSER, [E]\u003dUNSIGNED_MODULE\n[  810.194186] Hardware name: ASUS System Product Name/PRIME Z790-P WIFI, BIOS 1805 10/30/2024\n[  810.194186] Call Trace:\n[  810.194187]  \u003cTASK\u003e\n[  810.194188]  dump_stack_lvl+0xe0/0x100\n[  810.194195]  dump_stack+0x14/0x20\n[  810.194197]  sysfs_warn_dup+0x5f/0x80\n[  810.194204]  sysfs_create_dir_ns+0xbe/0xd0\n[  810.194210]  kobject_add_internal+0xbc/0x2b0\n[  810.194215]  kobject_add+0x7c/0xe0\n[  810.194220]  ? get_device_parent+0xcf/0x1e0\n[  810.194227]  device_add+0xe3/0x870\n[  810.194231]  ? __pfx_drm_gem_name_info+0x10/0x10 [drm]\n[  810.194280]  drm_minor_register+0x73/0x130 [drm]\n[  810.194322]  drm_dev_register+0x76/0x2a0 [drm]\n\nCc: stable@vger.kernel.org\nFixes: da3799c97572 (\"drm/xe: Use GuC to do GGTT invalidations for the GuC firmware\")\nSigned-off-by: Raag Jadav \u003craag.jadav@intel.com\u003e\nReviewed-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nLink: https://patch.msgid.link/20260810123821.105605-1-raag.jadav@intel.com\nSigned-off-by: Matt Roper \u003cmatthew.d.roper@intel.com\u003e\n(cherry picked from commit 5ce3042c67c539480882567137ff8d56118885d6)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "5cf82c8cec90056511eb881a267aab6101eaf57a",
      "tree": "09e4d245b57842fe1e14549320d51e61e7f8b87f",
      "parents": [
        "f110dbbfa2a94c91704bf19806907a98fd73ca14"
      ],
      "author": {
        "name": "Vinay Belgaumkar",
        "email": "vinay.belgaumkar@intel.com",
        "time": "Wed Aug 05 16:46:49 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:34 2026 +0200"
      },
      "message": "drm/xe: Fix a bug in pc_adjust_freq_bounds()\n\nIn cases where min frequency was actually greater than BMG_MIN_FREQ,\nwe were not using the updated min frequency as there was a missing\ncall to pc_action_query_task_state() between the two settings of\nmin frequency. Since we know what min_freq was last set, use that\ncached value while comparing to BMG_MIN_FREQ to fix this issue.\n\nv2: pc-\u003efreq_ready is not set until after pc_adjust_freq_bounds(). Stay\nwith pc_action_query_task_state() instead.\n\nv3: Update commit message (Stuart)\n\nFixes: bdde16c9ac5c (\"drm/xe/bmg: Update Wa_14022085890\")\nSigned-off-by: Balasubramani Vivekanandan \u003cbalasubramani.vivekanandan@intel.com\u003e\nSigned-off-by: Vinay Belgaumkar \u003cvinay.belgaumkar@intel.com\u003e\nReviewed-by: Stuart Summers \u003cstuart.summers@intel.com\u003e\nLink: https://patch.msgid.link/20260805234649.2076384-1-vinay.belgaumkar@intel.com\n(cherry picked from commit a2c2d2b13a9ea9494d2d76b46273833111749507)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "f110dbbfa2a94c91704bf19806907a98fd73ca14",
      "tree": "f65023f37bcd06022e89d01b34e8d52f91816490",
      "parents": [
        "8d33c4987cd162527375a3905017ae129ba7c3fe"
      ],
      "author": {
        "name": "Linmao Li",
        "email": "lilinmao@kylinos.cn",
        "time": "Mon Jul 13 16:30:53 2026 +0800"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/oa: Check managed mutex initialization errors\n\ndrmm_mutex_init() can fail while registering its managed cleanup action.\nOn failure, the reset path destroys the mutex, so continuing OA setup\nleaves an unusable lock that later paths may acquire.\n\nReturn the error from per-GT OA initialization and abort device-wide OA\ninitialization if the metrics lock cannot be initialized.\n\nFixes: a9f905ae7b6f (\"drm/xe/oa/uapi: Initialize OA units\")\nFixes: cdf02fe1a94a (\"drm/xe/oa/uapi: Add/remove OA config perf ops\")\nSigned-off-by: Linmao Li \u003clilinmao@kylinos.cn\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nSigned-off-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260713083053.321091-1-lilinmao@kylinos.cn\n(cherry picked from commit 360b293de27bfdd0d07047f8efd5ba8e91fa90b7)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "8d33c4987cd162527375a3905017ae129ba7c3fe",
      "tree": "7f90dfc01238a61c958077ae558bd6277561d0df",
      "parents": [
        "cb4afddf9e018a83fec8614d8e337d313871569f"
      ],
      "author": {
        "name": "Linmao Li",
        "email": "lilinmao@kylinos.cn",
        "time": "Fri Jul 31 09:19:32 2026 +0800"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/oa: Fix sync entry leak on OA config emit failure\n\nxe_oa_emit_oa_config() releases the sync entries and the syncs array\nonly on its success path. When it fails before the point of no return\n(fence allocation, config buffer allocation or batch submission), it\nreturns without touching stream-\u003esyncs.\n\nThe stream open path handles such failures in the caller, but\nxe_oa_config_locked() propagates the error without any cleanup, so the\nsyncs array and the fence references held by the parsed entries are\nleaked. The next config ioctl overwrites stream-\u003esyncs, making the\nmemory unreachable for good.\n\nClean up the parsed syncs when xe_oa_emit_oa_config() fails, matching\nthe cleanup done by the stream open error path.\n\nFixes: 9920c8b88c5c (\"drm/xe/oa: Add syncs support to OA config ioctl\")\nSigned-off-by: Linmao Li \u003clilinmao@kylinos.cn\u003e\nReviewed-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nSigned-off-by: Ashutosh Dixit \u003cashutosh.dixit@intel.com\u003e\nLink: https://patch.msgid.link/20260731011932.3426219-1-lilinmao@kylinos.cn\n(cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "cb4afddf9e018a83fec8614d8e337d313871569f",
      "tree": "e8d56534dc00bff9ec625733c4df2a7847afe4f9",
      "parents": [
        "51afaf53e01e01bda489fc6ffacf07a706e72783"
      ],
      "author": {
        "name": "Gajendra Uttamchand",
        "email": "gajendra.uttamchand@intel.com",
        "time": "Mon Aug 10 07:18:14 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/lrc: document sentinel and make CTX_TIMESTAMP read TOCTOU-safe\n\nProblem: CTX_TIMESTAMP MMIO reads could be stale if a context\nswitched out between check and read; LRC stores a sentinel while\na context starts that must not be treated as a real timestamp.\n\nFix: Check the LRC-stored sentinel before and after the MMIO read;\nreturn the LRC value if the context switched out to avoid TOCTOU.\n\nNote: Keep XE_LRC_CTX_TIMESTAMP_ACTIVE in xe_lrc.h as the\ncanonical sentinel.\n\nFixes: d243ef6a39c6 (\"drm/xe/lrc: Refactor xe_lrc_timestamp to simplify logic\")\nCloses: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/7956\nAssisted-by: GitHub-Copilot:claude-sonnet-5\nSigned-off-by: Gajendra Uttamchand \u003cgajendra.uttamchand@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nAcked-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nSigned-off-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nLink: https://patch.msgid.link/20260810071812.213358-4-gajendra.uttamchand@intel.com\n(cherry picked from commit a806534474df071a730d930df479976a812b699d)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "51afaf53e01e01bda489fc6ffacf07a706e72783",
      "tree": "ba9d867dc14c59af0a688ee51bd41a986dc14c20",
      "parents": [
        "9f83c94469ff0fa37274b873ba24922e02531fa7"
      ],
      "author": {
        "name": "Daniele Ceraolo Spurio",
        "email": "daniele.ceraolospurio@intel.com",
        "time": "Mon Jul 20 15:27:58 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/pxp: add termination on resume\n\nSuspend/resume causes the PXP keys to become invalid, but doesn\u0027t\nactually kill the session. The driver also doesn\u0027t explicitly kill and\nre-start the session until a new PXP request comes in, which means that\nthe \"zombie\" session can potentially stick around if there are no new\nrequests from userspace. While this is not an issue for PXP, HDCP has a\nnew behavior starting on PTL where a communication is sent to GSC if a\nsession is active at suspend time (even if it doesn\u0027t have a valid key),\nwhich can lead to delays in the suspend flow if we suspend while the\nzombie session is still active.\nTo avoid this, we can trigger a termination on resume and kill the\nzombie session immediately, instead of delaying the termination to the\nnext PXP request. Due to restrictions in the rpm suspend/resume flow, we\ncan\u0027t call the termination flow from within the resume call itself, so\nthe pxp irq worker is expanded to cover this scenario.\nThe existing logic in the worker doesn\u0027t work as-is for the new flow,\nbecause the pm_get_if_active will fail if the worker runs before the\npci_resume call has completed (which is possible, since we queue it\nfrom within that call) or after we\u0027re started to suspend again.\nGiven that we always want to run the worker after a resume (differently\nfrom the irq case, where we want to skip if we\u0027re suspended), we can\nsolve this by just taking the PM reference before queueing the worker.\nAs part of this rework, the pxp-\u003eevents variable has been moved to atomic,\nto avoid having to take xe-\u003eirq.lock from non-irq related paths.\n\nFixes: b1dcec9bd8a1 (\"drm/xe/ptl: Enable PXP for PTL\")\nSigned-off-by: Daniele Ceraolo Spurio \u003cdaniele.ceraolospurio@intel.com\u003e\nCc: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nCc: Julia Filipchuk \u003cjulia.filipchuk@intel.com\u003e\nCc: Alan Previn \u003calan.previn.teres.alexis@intel.com\u003e\nReviewed-by: Alan Previn \u003calan.previn.teres.alexis@intel.com\u003e\nLink: https://patch.msgid.link/20260720222757.3876338-2-daniele.ceraolospurio@intel.com\n(cherry picked from commit 757bda2b8b93fa36ad9b2c7993081d5f9d0d6e3b)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "9f83c94469ff0fa37274b873ba24922e02531fa7",
      "tree": "0bd74acd4a7b6388bb7337dcc6a75def41a6b6b3",
      "parents": [
        "8d5134ae4177fa4f5a9bc8e71e6656cfc2852882"
      ],
      "author": {
        "name": "Matthew Brost",
        "email": "matthew.brost@intel.com",
        "time": "Fri Aug 07 10:17:16 2026 -0700"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe: Order ring writes before ring tail updates\n\nThe ring buffer and the LRC context image are both mapped WC, so the ring\ntail update can become visible to the device before the ring contents it\nis meant to publish.\n\nThe GuC CT send does contain an xe_device_wmb(), so sending the H2G would\nflush the ring contents. The problem is that it comes too late:\nxe_lrc_set_ring_tail() publishes the tail before the H2G is sent, and the\ndevice samples the tail from the context image independently of it, either\nat context switch-in or while the context is already resident. A submitter\nwhich is interrupted between updating the tail and sending its H2G\ntherefore leaves the device free to observe the new tail while the ring\ncontents behind it are not yet visible:\n\n  1. Thread A emits a job into the ring, sets the tail to T_A and sends\n     the H2G, which flushes A\u0027s ring contents. The GuC starts scheduling\n     the context in, but it is not executing yet.\n  2. Thread B emits a job into ring[T_A..T_B]. Those writes are not yet\n     visible to the device.\n  3. Thread B updates the ring tail to T_B. That write targets a\n     different page and becomes visible first.\n  4. Thread B is interrupted before it sends its H2G, so the flush which\n     would have published ring[T_A..T_B] has not happened yet.\n  5. The context is switched in and samples the ring tail from the\n     context image, picking up T_B rather than T_A.\n  6. The GPU executes A\u0027s job, advances HEAD to T_A, and continues on to\n     ring[T_A..T_B], which still holds the previous wrap\u0027s contents, so\n     the CS parses stale commands.\n\nThe result is command stream corruption, which typically manifests as a\nhang or a spurious pagefault rather than anything that points back at the\nsubmission path.\n\nKernel jobs are by far the most likely to hit this. Kernel queues such as\nthe migration queue are shared and can be driven by many threads\nconcurrently, producing back-to-back submissions on an LRC which is\nalready executing. User queues are typically tied to a single submitting\nthread, so the same interleaving is much harder to produce.\n\nAdd an xe_device_wmb() at the end of xe_lrc_write_ring() so that it covers\nevery ring tail publication site, and so the invariant is local: once\nxe_lrc_write_ring() returns, the ring contents are visible to the device.\n\nFixes: dd08ebf6c352 (\"drm/xe: Introduce a new DRM driver for Intel GPUs\")\nCloses: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8651\nCloses: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/7810\nCc: stable@vger.kernel.org\nSigned-off-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e\nAssisted-by: GitHub_Copilot:claude-opus-5\nReviewed-by: Stuart Summers \u003cstuart.summers@intel.com\u003e\nLink: https://patch.msgid.link/20260807171716.140475-1-matthew.brost@intel.com\n(cherry picked from commit 136360290f314890428a3fbf31aaa8e4f1d43567)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "8d5134ae4177fa4f5a9bc8e71e6656cfc2852882",
      "tree": "12d8826e9bdd6b440177681544e8ee231812bcdc",
      "parents": [
        "f342810a141f8a7e8b3786a6e4b6c0695a078a74"
      ],
      "author": {
        "name": "Jia Yao",
        "email": "jia.yao@intel.com",
        "time": "Tue Aug 04 16:50:57 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/guc_ads: use uncached mapping for UM queue BO\n\nOn Pre-Xe3p platform, the GAM write the UM queue through DPA using UC.\nif GuC reads the queue via GGTT (WB), stale data may be observed\nwhen the cacheline has been polluted by another agent.\n\nTo match the GAM\u0027s UC writes, configure the GuC mapping as UC as well.\n\nFixes: 9c57bc08652a (\"drm/xe/lnl: Drop force_probe requirement\")\nCc: Gwan-gyeong Mun \u003cgwan-gyeong.mun@intel.com\u003e\nCc: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.12+\nSigned-off-by: Jia Yao \u003cjia.yao@intel.com\u003e\nReviewed by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nLink: https://patch.msgid.link/20260804165057.129529-4-jia.yao@intel.com\n(cherry picked from commit 9daa302a82590eeee7bdc68023ddad302df4b88c)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "f342810a141f8a7e8b3786a6e4b6c0695a078a74",
      "tree": "a4e3117cd537a098cdf71a7b4e3a5544ba26d343",
      "parents": [
        "99b01815957bd7d848420cb697f79ed11f7f215c"
      ],
      "author": {
        "name": "Jia Yao",
        "email": "jia.yao@intel.com",
        "time": "Tue Aug 04 16:50:56 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/guc_ads: allocate UM queues in VRAM on dGFX\n\nOn iGPU, the UM queue BO is allocated in system memory. On dGFX, the BO\nwas previously created in system memory and later reallocated in\nxe_guc_realloc_post_hwconfig().  Allocate the UM queue BO directly in\nVRAM on dGFX, where it is ultimately required.\n\nFixes: 9c57bc08652a (\"drm/xe/lnl: Drop force_probe requirement\")\nCc: Gwan-gyeong Mun \u003cgwan-gyeong.mun@intel.com\u003e\nCc: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.12+\nSigned-off-by: Jia Yao \u003cjia.yao@intel.com\u003e\nReviewed-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nLink: https://patch.msgid.link/20260804165057.129529-3-jia.yao@intel.com\n(cherry picked from commit ace076ef0a854ab5940bacc539bf66afd61d118c)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "99b01815957bd7d848420cb697f79ed11f7f215c",
      "tree": "e5aff2e8bb68723d46f561988fcefb5e276150a0",
      "parents": [
        "fc648757908304aedbad74f74bf58192aec383db"
      ],
      "author": {
        "name": "Jia Yao",
        "email": "jia.yao@intel.com",
        "time": "Tue Aug 04 16:50:55 2026 +0000"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe/guc_ads: allocate UM queues in a separate BO\n\nMove the UM queues into a dedicated BO (ads-\u003eum_queue_bo) and avoid\nCPU memset operations on it, which eliminates the CPU as a potential\ncacheline-polluting agent and helps maintain consistency between GAM\nwrites and GuC reads.\n\nWe also need to ensure the base_dpa for the queue is contiguous on hw\nwhere this is used instead of a GGTT address. Another good reason to\nsplit this out to a separate BO.\n\nFixes: 9c57bc08652a (\"drm/xe/lnl: Drop force_probe requirement\")\nCc: Gwan-gyeong Mun \u003cgwan-gyeong.mun@intel.com\u003e\nCc: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.12+\nSigned-off-by: Jia Yao \u003cjia.yao@intel.com\u003e\nReviewed-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nSigned-off-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nLink: https://patch.msgid.link/20260804165057.129529-2-jia.yao@intel.com\n(cherry picked from commit 6af05de0dc19bbf3aaeec2020fe48b37c834b811)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "fc648757908304aedbad74f74bf58192aec383db",
      "tree": "d0a2389473bb76cd396c87041fe2359d643d7a52",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Maarten Lankhorst",
        "email": "dev@lankhorst.se",
        "time": "Tue Jun 30 15:55:20 2026 +0200"
      },
      "committer": {
        "name": "Thomas Hellström",
        "email": "thomas.hellstrom@linux.intel.com",
        "time": "Thu Aug 13 14:56:33 2026 +0200"
      },
      "message": "drm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn\u0027t work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren\u0027t counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT\u0027s, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\nLink: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/7513\nFixes: 775d0adc01a5 (\"drm/xe/fbdev: Limit the usage of stolen for LNL+\")\nCc: \u003cstable@vger.kernel.org\u003e # v6.12+\nReviewed-by: Matthew Auld \u003cmatthew.auld@intel.com\u003e\nLink: https://patch.msgid.link/20260630135523.1775379-2-dev@lankhorst.se\nSigned-off-by: Maarten Lankhorst \u003cdev@lankhorst.se\u003e\nAcked-by: Matthew Brost \u003cmatthew.brost@intel.com\u003e #teams\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)\nSigned-off-by: Thomas Hellström \u003cthomas.hellstrom@linux.intel.com\u003e\n"
    },
    {
      "commit": "42d217add8d80d6e7d9f58f80d11ea9b07ea113e",
      "tree": "154a9a3ebe93079eeb0d24087892a6f6264ad37d",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Aleksandr Nogikh",
        "email": "nogikh@google.com",
        "time": "Fri Aug 07 14:25:26 2026 +0000"
      },
      "committer": {
        "name": "Takashi Sakamoto",
        "email": "o-takashi@sakamocchi.jp",
        "time": "Thu Aug 13 21:02:23 2026 +0900"
      },
      "message": "firewire: ohci: fix NULL pointer dereference in ar_context_release\n\nDuring the error handling path of the driver\u0027s probe function, a NULL\npointer dereference can occur in ar_context_release().\n\nWhen pci_probe() fails early (e.g., if pcim_enable_device() or MMIO mapping\nfails), the devres cleanup mechanism invokes release_ohci(). This function\nunconditionally calls ar_context_release() to clean up the asynchronous\nreceive contexts. However, if ar_context_init() was not yet called,\nctx-\u003eohci remains NULL (as the fw_ohci structure is zero-initialized by\ndevres_alloc()).\n\nar_context_release() immediately dereferences ctx-\u003eohci to get the dev\npointer before checking if the context was actually initialized, leading to\na crash:\n\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nRIP: 0010:ar_context_release+0x3f/0x380 drivers/firewire/ohci.c:543\nCall Trace:\n release_ohci+0x3f/0x60 drivers/firewire/ohci.c:3567\n release_nodes drivers/base/devres.c:546 [inline]\n devres_release_all+0x1a8/0x260 drivers/base/devres.c:576\n device_unbind_cleanup drivers/base/dd.c:597 [inline]\n really_probe+0x451/0xae0 drivers/base/dd.c:772\n\nTo fix this, move the assignment of the dev pointer after the !ctx-\u003ebuffer\ncheck. If ctx-\u003ebuffer is NULL, it indicates that the context was never\nsuccessfully initialized and there is nothing to release, safely avoiding\nthe dereference of the uninitialized ctx-\u003eohci pointer.\n\nFixes: 5716e58aecdd (\"firewire: ohci: release buffer for AR req/resp contexts when managed resource is released\")\nAssisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot\nReported-by: syzbot+d30aad27833a559defab@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003dd30aad27833a559defab\nLink: https://syzkaller.appspot.com/ai_job?id\u003d10a18617-7893-42dd-bf1c-cd49e19e95d9\nSigned-off-by: Aleksandr Nogikh \u003cnogikh@google.com\u003e\nLink: https://lore.kernel.org/r/90c5db71-dd1f-4d46-b9d3-2f1046cbd5ea@mail.kernel.org\nSigned-off-by: Takashi Sakamoto \u003co-takashi@sakamocchi.jp\u003e\n"
    },
    {
      "commit": "9006c116dd111d457bf5d074990210f70a4ad2c8",
      "tree": "1e3e52af0001c78554a494b98e1a7e5fe62058c6",
      "parents": [
        "120977e2c096deea4e866e4273be9220b957c29e"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Aug 11 14:46:51 2026 +0000"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 11:49:31 2026 +0200"
      },
      "message": "l2tp: fix tunnel and session refcount leak on seq_file release\n\nIn pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state\n(pd-\u003etunnel and pd-\u003esession) is kept in seq_file private data to allow\niteration across multiple read() system calls.\n\nHowever, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels\nbefore reading to end-of-file (EOF), any tunnel or session reference stored in\npd-\u003etunnel / pd-\u003esession is left un-dropped when seq_file private data is freed.\n\nFix this by dropping any remaining pd-\u003etunnel and pd-\u003esession references in\npppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.\n\nFixes: 0e0c3fee3a59 (\"l2tp: hold reference on tunnels printed in pppol2tp proc file\")\nFixes: f726214d9b23 (\"l2tp: hold reference on tunnels printed in l2tp/tunnels debugfs file\")\nReported-by: syzbot+d6fa74e3f19d6ee01e3a@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6a760f32.01d0871a.3a0d52.004f.GAE@google.com/T/#u\nAssisted-by: Jetski:Gemini-3.1-Pro\nCc: James Chapman \u003cjchapman@katalix.com\u003e\nCc: Guillaume Nault \u003cgnault@redhat.com\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260811144651.2733424-1-edumazet@google.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "120977e2c096deea4e866e4273be9220b957c29e",
      "tree": "1a03859632a8800e49de9bbecf819e36b636bc4e",
      "parents": [
        "2bb155e92167cd5ad6aae312e83291da2454f8b0"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Sun Aug 09 05:44:18 2026 -0400"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 13 11:08:39 2026 +0200"
      },
      "message": "net/sched: cls_bpf: reject dev-bound programs bound to a different device\n\ncls_bpf_prog_from_efd() obtained a SCHED_CLS program via\nbpf_prog_get_type_dev() but never verified that a device-bound (offloaded)\nprogram\u0027s bound netdev matches the TC netdev the classifier is being\nattached to. This let a program loaded with prog_ifindex for device A be\nattached via cls_bpf + skip_sw to device B; deleting device A then\ndestroyed the program\u0027s offload state while it was still attached to\ndevice B, triggering a netdevsim WARN (panic with panic_on_warn\u003d1).\n\nMirror the XDP attach path (net/core/dev.c) and reject the attach with\n-EINVAL when a dev-bound program\u0027s bound device does not match the\ntarget device.\n\nFixes: 2b3486bc2d23 (\"bpf: Introduce device-bound XDP programs\")\nReported-by: vega@nebusec.ai\nTested-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nAcked-by: Daniel Borkmann \u003cdaniel@iogearbox.net\u003e\nLink: https://patch.msgid.link/20260809094418.901607-1-jhs@mojatatu.com\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "6c916e301fa10de9158b922474ade7b43d726cda",
      "tree": "8ae367e98be119020ad64d8fdb6c9069152719c2",
      "parents": [
        "9a11db68872055e6ead919bad04d6330851c522d"
      ],
      "author": {
        "name": "Lizhi Hou",
        "email": "lizhi.hou@amd.com",
        "time": "Wed Aug 12 13:56:28 2026 -0700"
      },
      "committer": {
        "name": "Lizhi Hou",
        "email": "lizhi.hou@amd.com",
        "time": "Wed Aug 12 23:12:20 2026 -0700"
      },
      "message": "accel/amdxdna: Skip unmapped range in aie2_populate_range()\n\naie2_populate_range() incorrectly failed jobs for BOs with multiple\nmmaps: if the unmapped entry appeared first in umap_list, the loop would\npick it up, call hmm_range_fault() on a gone VMA, and return -EFAULT\nwithout ever trying the remaining valid mapps.\n\nFix it by skipping unmapped entries. After the loop, if the map list is\nempty or all maps are valid, map_invalid can be cleared normally.\n\nFixes: e486147c912f (\"accel/amdxdna: Add BO import and export\")\nReviewed-by: Max Zhen \u003cmax.zhen@amd.com\u003e\nSigned-off-by: Lizhi Hou \u003clizhi.hou@amd.com\u003e\nLink: https://patch.msgid.link/20260812205628.810816-1-lizhi.hou@amd.com\n"
    },
    {
      "commit": "6ca662cc71df7eb4eaf1b4bcb07cd3f188ad19f2",
      "tree": "886c05e35a4f24e1634a7dd1da1d5bdcfa4bd400",
      "parents": [
        "bc0e8faf90e776a2f1f3967a04e8091e6bdb4977"
      ],
      "author": {
        "name": "Jérémy Jean",
        "email": "Jeremy.Jean@oss.cyber.gouv.fr",
        "time": "Wed Aug 12 20:30:42 2026 +0000"
      },
      "committer": {
        "name": "Jens Axboe",
        "email": "axboe@kernel.dk",
        "time": "Wed Aug 12 19:53:35 2026 -0600"
      },
      "message": "io_uring/rsrc: reject overflowing regvec bvec byte counts\n\nio_import_reg_vec() converts the estimated number of bio_vec entries\ninto iovec-sized storage when struct bio_vec is larger than struct\niovec. The conversion still multiplies nr_segs by sizeof(struct\nbio_vec) in size_t without checking for overflow.\n\nOn 32-bit kernels, a registered buffer large enough to make\nio_estimate_bvec_size() return 357913942 segments wraps the byte count\nfrom 0x100000008 to 8. io_vec_realloc() then reserves only the input\niovecs plus one extra slot while io_vec_fill_bvec() writes the full\nbio_vec array.\n\nCheck both the multiplication and the rounding addition before\nderiving the replacement iovec count.\n\nFixes: b4e41050b212 (\"io_uring/rsrc: raise registered buffer 1GB limit\")\nAssisted-by: Codex:gpt-5\nSigned-off-by: Jérémy Jean \u003cJeremy.Jean@oss.cyber.gouv.fr\u003e\nLink: https://patch.msgid.link/20260812203042.720348-1-Jeremy.Jean@oss.cyber.gouv.fr\nSigned-off-by: Jens Axboe \u003caxboe@kernel.dk\u003e\n"
    },
    {
      "commit": "2bb155e92167cd5ad6aae312e83291da2454f8b0",
      "tree": "bd07c87070eb72f83f62a12942f451b0215ba99a",
      "parents": [
        "8c283e7b56adce00193837f3311b06662466fb21",
        "2da3dfa1ddfe55a065f484750c83660e3bd4ac00"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:09:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 18:09:18 2026 -0700"
      },
      "message": "Merge tag \u0027ovpn-net-20260809\u0027 of https://github.com/OpenVPN/ovpn-net-next\n\nAntonio Quartulli says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nIncluded fixes:\n\n* release key slot crypto transforms from a workqueue rather than an RCU\n  callback, because crypto_free_aead() may sleep with async or hardware\n  implementations\n* run all deferred ovpn work on a module-owned workqueue and drain it on\n  module exit, so no work item can still be executing module text after\n  the module is unloaded\n* finish crypto callback cleanup (key slot release and leftover skb)\n  before dropping the peer reference that gates netdev unregistration\n  and module removal\n* avoid dereferencing a NULL key slot when userspace asks to kill a key\n  that is not installed on the peer\n\n* tag \u0027ovpn-net-20260809\u0027 of https://github.com/OpenVPN/ovpn-net-next:\n  ovpn: defer key slot crypto freeing to workqueue\n  ovpn: run deferred work on a module-owned workqueue\n  ovpn: finish crypto callback cleanup before peer release\n  ovpn: fix NULL dereference when killing missing key\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260809212142.2249027-1-antonio@openvpn.net\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "8c283e7b56adce00193837f3311b06662466fb21",
      "tree": "342de931e60235a1f5c5be678e5c7c4b2c1f7db8",
      "parents": [
        "36a05d2820077bb3955acb8111e1041d39148037"
      ],
      "author": {
        "name": "Yuxiang Yang",
        "email": "yangyx22@mails.tsinghua.edu.cn",
        "time": "Sun Aug 09 12:38:06 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:54:42 2026 -0700"
      },
      "message": "sctp: fix use-after-free of cached ASCONF chunk\n\naddip_last_asconf caches the outstanding outbound ASCONF chunk. The normal\nASCONF-ACK completion path releases the chunk and clears the pointer.\n\nHowever, sctp_asconf_queue_teardown() releases the cached chunk without\nclearing addip_last_asconf. During peer restart handling,\nsctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes\nsctp_asconf_queue_teardown() while the association remains alive and leaves\nthe pointer dangling.\n\nA delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),\nwhich accesses the stale chunk and passes it to sctp_process_asconf_ack(),\ncausing a use-after-free and a second release.\n\nClearing the pointer exposes a race with T4 expiry. Peer restart handling\nqueues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses\ntimer_delete(), which does not wait for a callback already running on\nanother CPU. Such a callback can reach sctp_sf_t4_timer_expire() after\nthe purge and dereference NULL.\n\nClear addip_last_asconf after releasing the cached chunk, and make\nsctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding\nASCONF remains.\n\nFixes: a000c01e60e4 (\"sctp: stop pending timers and purge queues when peer restart asoc\")\nCc: stable@vger.kernel.org\nSuggested-by: Xin Long \u003clucien.xin@gmail.com\u003e\nSigned-off-by: Yuxiang Yang \u003cyangyx22@mails.tsinghua.edu.cn\u003e\nAcked-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260809043806.2768302-1-yangyx22@mails.tsinghua.edu.cn\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "062dc4693e2c10d77de06f61e6f3faf37c0a8383",
      "tree": "4cdc8afe1955b2bcc7006438039cd6bc335ceaa6",
      "parents": [
        "9da976eb649c9e2f588a4499410e4d8af687925f"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Mon Jun 15 22:12:30 2026 -0700"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Wed Aug 12 17:51:54 2026 -0700"
      },
      "message": "Input: sur40 - fix V4L error path cleanup\n\nIn sur40_probe(), if video_register_device() fails, the error path jumps to\nerr_unreg_video. This incorrectly attempts to unregister a video device\nthat was never successfully registered, and fails to free the V4L2 control\nhandler (v4l2_ctrl_handler_free) that was initialized immediately prior.\n\nFix this by introducing an err_free_ctrl label to properly free the V4L2\ncontrol handler and bypass video_unregister_device() when video device\nregistration fails.\n\nReported-by: sashiko-bot@kernel.org\nCc: stable@vger.kernel.org\nAssisted-by: Antigravity:gemini-3.5-flash\nLink: https://patch.msgid.link/20260616051235.1549517-2-dmitry.torokhov@gmail.com\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "9da976eb649c9e2f588a4499410e4d8af687925f",
      "tree": "972c0f79bdf35cedf3355c0907f3b24f8d7b8008",
      "parents": [
        "3abd29c61d2ef37c4102cf755b18be53bb9dbea6"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Mon Jun 15 22:12:29 2026 -0700"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Wed Aug 12 17:51:48 2026 -0700"
      },
      "message": "Input: sur40 - fix input device registration ordering\n\nIn sur40_probe(), input_register_device() was previously called early before\nthe V4L2 video device and vb2_queue components were fully initialized. If\nuserspace opened the input device immediately upon registration, sur40_open()\nwould trigger and start the sur40_poll() worker thread. This worker thread\ninvokes sur40_process_video() and accesses the uninitialized vb2_queue\nstructure, leading to a data race and potential system crash.\n\nFurthermore, if V4L2 or video registration failed after input_register_device()\nsucceeded, the error path fell through to calling input_free_device() on a\nsuccessfully registered device instead of input_unregister_device(), corrupting\ninput core state.\n\nMove input_register_device() to the very end of sur40_probe(). This ensures\nthe V4L2 and video queue structures are fully initialized before polling can\nstart, and naturally resolves the error path bug since input_free_device()\nis now only called when input registration has not yet occurred.\n\nTo maintain strict LIFO (Last-In, First-Out) teardown ordering, also move\ninput_unregister_device() to the very beginning of sur40_disconnect(). This\nguarantees that the input polling worker thread is stopped before V4L2\nvideo components or control handlers are unregistered.\n\nReported-by: sashiko-bot@kernel.org\nCc: stable@vger.kernel.org\nAssisted-by: Antigravity:gemini-3.5-flash\nLink: https://patch.msgid.link/20260616051235.1549517-1-dmitry.torokhov@gmail.com\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "36a05d2820077bb3955acb8111e1041d39148037",
      "tree": "b5a34b99f6eab19cb5371c702adc3772300d5ff7",
      "parents": [
        "beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3"
      ],
      "author": {
        "name": "Siddharth Vadapalli",
        "email": "s-vadapalli@ti.com",
        "time": "Fri Aug 07 16:47:37 2026 +0530"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:36:19 2026 -0700"
      },
      "message": "net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n\nOn the packet reception path, the ID of the MAC Port on which the packet\nwas received, is embedded in the RX DMA Descriptor\u0027s metadata. The ID is\nextracted using the helper function cppi5_desc_get_tags_ids() which fills\nin the 16-bit Source Tag into the \u0027port_id\u0027 variable. However, it is only\nthe lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,\nwhile the upper 8-bits are Hardware-Reserved and carry an arbitrary value.\nWith the existing logic, sporadic kernel crash is observed due to the\nsubsequent driver code accessing out-of-bound memory because of an invalid\nport_id.\n\nHence, fix the port_id extraction logic to use only the lower 8-bits of the\nSource Tag as the MAC Port ID.\n\nFixes: 93a76530316a (\"net: ethernet: ti: introduce am65x/j721e gigabit eth subsystem driver\")\nSigned-off-by: Siddharth Vadapalli \u003cs-vadapalli@ti.com\u003e\nReviewed-by: Chintan Vankar \u003cc-vankar@ti.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260807111738.2055900-1-s-vadapalli@ti.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3",
      "tree": "32fbbeb4bde8d572cf3f1aa2b6a9ae2b1129046a",
      "parents": [
        "9e6869be49064915edb6c8776b27c376cfdb0df5"
      ],
      "author": {
        "name": "Qing Ming",
        "email": "a0yami@mailbox.org",
        "time": "Tue Aug 11 23:28:03 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:21:37 2026 -0700"
      },
      "message": "sctp: clear new_transport when removing a peer\n\nsctp_process_asconf_param() stores a newly added peer transport in\nasoc-\u003enew_transport. After all parameters in the ASCONF chunk have been\nprocessed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the\nnew transport.\n\nAn authenticated ASCONF from a remote SCTP peer can add a transport and\nremove it again with a wildcard DEL-IP parameter in the same chunk. The\nwildcard deletion preserves the transport on which the ASCONF arrived, but\nremoves the newly added transport through\nsctp_assoc_del_nonprimary_peers(). The removal does not clear\nasoc-\u003enew_transport, leaving it pointing to the removed transport.\n\nsctp_sf_do_asconf() then creates a HEARTBEAT whose chunk-\u003etransport points\nto the removed transport without holding a transport reference. During\nlocal address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on\ncontrol_chunk_list. After the transport is freed by RCU, a successful\nASCONF_ACK for the replacement address releases the queued HEARTBEAT and\nsctp_outq_select_transport() reads the freed transport\u0027s state.\n\nThe issue was found during a static audit of SCTP objects. With an\nauthenticated peer, the reproducer triggered the same KASAN report in 2\nof 2 unpatched runs on a KASAN-enabled netdev/main kernel:\n\n  BUG: KASAN: slab-use-after-free in sctp_outq_select_transport\n  Read of size 4 at addr ffff88800b9bd95c by task python3/197\n\n  Call Trace:\n   sctp_outq_select_transport+0x549/0x8b0 [sctp]\n   sctp_outq_flush+0x306/0x2c60 [sctp]\n   sctp_transport_immediate_rtx+0xaf/0x260 [sctp]\n   sctp_process_asconf_ack+0xa48/0xf70 [sctp]\n\n  Allocated by task 197:\n   sctp_transport_new+0x68/0x650 [sctp]\n   sctp_assoc_add_peer+0x258/0x12a0 [sctp]\n   sctp_process_asconf+0x5e9/0x1090 [sctp]\n\n  Last potentially related work creation:\n   __call_rcu_common.constprop.0+0x77/0xb70\n   sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]\n   sctp_process_asconf+0xd9c/0x1090 [sctp]\n\nThe first invalid access was a four-byte read of transport-\u003estate at\nnet/sctp/outqueue.c:833. The same reproducer completed the full\nauthenticated ASCONF and local-address replacement sequence with this\nchange without a KASAN report or oops.\n\nClear new_transport when its peer is removed, before it can be used to\ncreate the HEARTBEAT.\n\nFixes: 6af29ccc223b (\"sctp: Bundle HEAERTBEAT into ASCONF_ACK\")\nCc: stable@vger.kernel.org\nSigned-off-by: Qing Ming \u003ca0yami@mailbox.org\u003e\nAcked-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260811152803.5629-1-a0yami@mailbox.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9e6869be49064915edb6c8776b27c376cfdb0df5",
      "tree": "0fcb511f2a853639e6f0e19a6d727503d09e2946",
      "parents": [
        "7b53449540502cb21b32bca62a6258e22cd97bbe"
      ],
      "author": {
        "name": "Alexandra Winter",
        "email": "wintera@linux.ibm.com",
        "time": "Mon Aug 10 13:14:32 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Aug 12 17:08:05 2026 -0700"
      },
      "message": "net/dibs: Correct freeing of dmb_clientid_arr\n\nA dibs device interrupt handler can be active after dibs_dev_del() and\nmay still access dmb_clientid_arr. (UAF)\n\nIn case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe()\ndmb_clientid_arr is freed twice (double free).\n\nFree dmb_clientid_arr in dibs_dev_release() after last reference is gone.\nNote that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok\nfor now, because no dmbs can be registered before dibs_dev_add().\n\nFixes: cc21191b584c (\"dibs: Move data path to dibs layer\")\nCc: stable@vger.kernel.org\nCo-developed-by: Hidayath Khan \u003chidayath@linux.ibm.com\u003e\nSigned-off-by: Hidayath Khan \u003chidayath@linux.ibm.com\u003e\nSigned-off-by: Alexandra Winter \u003cwintera@linux.ibm.com\u003e\nReviewed-by: Dust Li \u003cdust.li@linux.alibaba.com\u003e\nLink: https://patch.msgid.link/20260810111432.2334900-1-wintera@linux.ibm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "91880e4a7fac45bc407771bc57bbaf4f37e9b4c3",
      "tree": "c32bc60a5f3a06e305795d0a745bce7eb143b760",
      "parents": [
        "2c11c4bfdb7bd2808b3b3ac228e1f2d9bcf25457"
      ],
      "author": {
        "name": "Zhan Xusheng",
        "email": "zhanxusheng@xiaomi.com",
        "time": "Mon Jul 27 09:47:44 2026 +0800"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:21:41 2026 +0200"
      },
      "message": "ceph: use the mount idmap for the owner checks in the SET_LAYOUT ioctls\n\nceph_ioctl_set_layout() and ceph_ioctl_set_layout_policy() call\ninode_owner_or_capable() with \u0026nop_mnt_idmap instead of the idmap of the\nmount the ioctl was issued on.\n\nCephFS supports idmapped mounts (FS_ALLOW_IDMAP), so on such a mount this\ncompares the caller\u0027s fsuid against the unmapped on-disk owner rather than\nthe mapped owner: the actual owner can be wrongly denied with -EACCES and\nan unrelated caller wrongly allowed.  Both functions already have the\nstruct file, so use file_mnt_idmap(file) instead.\n\nCc: stable@vger.kernel.org\nFixes: cee38bbf5556 (\"ceph: add owner/capability checks for CEPH_IOC_SET_LAYOUT*\")\nSigned-off-by: Zhan Xusheng \u003czhanxusheng@xiaomi.com\u003e\nReviewed-by: Xiubo Li \u003cxiubo.li@clyso.com\u003e\nReviewed-by: Alex Markuze \u003camarkuze@redhat.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "2c11c4bfdb7bd2808b3b3ac228e1f2d9bcf25457",
      "tree": "a4c7a0d1bdf148d848181132a8c8c47a83296eb1",
      "parents": [
        "3660b98d1204b419f6a77e9a295f148dcf38d042"
      ],
      "author": {
        "name": "Yiming Zhu",
        "email": "zhuyiming@kuaishou.com",
        "time": "Fri Jul 24 18:49:20 2026 +0800"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:21:41 2026 +0200"
      },
      "message": "ceph: fix MDS random selection readiness predicate\n\nCEPH_MDS_IS_READY() is parsed so that the ternary expression can\nreturn true for an MDS entry with state 0 when it is not laggy. This\nallows the random selector to choose a down/DNE rank.\n\nGroup the ternary expression under the state check so zero-state ranks\nare not treated as ready.\n\nCc: stable@vger.kernel.org\nFixes: b38c9eb4757d (\"ceph: add possible_max_rank and make the code more readable\")\nLink: https://tracker.ceph.com/issues/78648\nSigned-off-by: Yiming Zhu \u003czhuyiming@kuaishou.com\u003e\nReviewed-by: Viacheslav Dubeyko \u003cslava@dubeyko.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "3660b98d1204b419f6a77e9a295f148dcf38d042",
      "tree": "42662452c591cb9576c4fcae20fad8d0c71425bb",
      "parents": [
        "00ead17c7de137a692edee59f2772e6af687e8eb"
      ],
      "author": {
        "name": "Raphael Zimmer",
        "email": "raphael.zimmer@tu-ilmenau.de",
        "time": "Tue Jul 28 10:43:40 2026 +0200"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:21:41 2026 +0200"
      },
      "message": "libceph: Avoid using invalid osd indices from primary_temp\n\nA corrupted osdmap received from a Ceph monitor or OSD may contain osd\nindices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts\nthat don\u0027t exist, i.e., that are greater than max_osd or smaller than\nCEPH_HOMELESS_OSD (-1). These indices are used to create the up and\nacting set in ceph_pg_to_up_acting_osds(), called from calc_target().\nWhile most of these osd indices are checked, the one from primary_temp\nis not. Subsequently, this may lead to calc_target() returning this\n(potentially invalid) index as target osd for a (linger) request.\nBecause the osd_state, osd_weight, and osd_addr arrays only contain\nmax_osd entries (with indices 0 to max_osd -1), this leads to\nout-of-bounds accesses when trying to read values from these arrays.\n\nThis patch fixes the issue by adding a check to get_temp_osds(), so that\nonly valid osd indices from primary_temp are used, and it falls back to\nusing the primary from pg_temp or the up set if it is invalid.\n\n[ idryomov: changelog ]\n\nCc: stable@vger.kernel.org\nFixes: 5e8d4d36bf23 (\"libceph: add support for primary_temp mappings\")\nSigned-off-by: Raphael Zimmer \u003craphael.zimmer@tu-ilmenau.de\u003e\nReviewed-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "00ead17c7de137a692edee59f2772e6af687e8eb",
      "tree": "03d49fdfd3ce84cb395d0d324cb57595f801f35e",
      "parents": [
        "437b6551cfcc235eea1d735a874f9d421f555e17"
      ],
      "author": {
        "name": "Pavitra Jha",
        "email": "jhapavitra98@gmail.com",
        "time": "Wed Jul 08 01:39:41 2026 -0400"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:21:41 2026 +0200"
      },
      "message": "libceph: fix OOB read in decode_watchers() via missing bounds check\n\nceph_start_decoding() validates that struct_len bytes remain in the\nbuffer after the encoding header, but accepts struct_len\u003d0 as valid:\nceph_decode_need(p, end, 0, bad) always passes. When a malicious or\ncompromised OSD sends an obj_list_watch_response_t reply with\nstruct_len\u003d0, ceph_start_decoding() returns success with p \u003d\u003d end,\nleaving zero bytes guaranteed for subsequent reads.\n\nThe immediately following ceph_decode_32(p) in decode_watchers() has\nno preceding bounds check. With p \u003d\u003d end this is a 4-byte read past\nthe validated buffer boundary. The garbage value is then passed\ndirectly to kzalloc_objs() as the watcher count.\n\nThe sibling function decode_watcher() already uses the safe variants\n(ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32)\nafter its own ceph_start_decoding() call. decode_watchers() is the\nonly site that uses the bare variant, confirming an oversight.\n\nFix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end,\n*num_watchers, bad), consistent with the established pattern.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment (e.g. cloud) can trigger this against any kernel client\nthat calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges\nbeyond OSD session establishment.\n\n[ idryomov: trim changelog ]\n\nCc: stable@vger.kernel.org\nFixes: a4ed38d7a180 (\"libceph: support for CEPH_OSD_OP_LIST_WATCHERS\")\nSigned-off-by: Pavitra Jha \u003cjhapavitra98@gmail.com\u003e\nReviewed-by: Viacheslav Dubeyko \u003cSlava.Dubeyko@ibm.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "437b6551cfcc235eea1d735a874f9d421f555e17",
      "tree": "f0f626ca58733cfcd73993d4560b76a8e6c5f851",
      "parents": [
        "5a87925539acecfe88229bad76ab81bd75a7e3f5"
      ],
      "author": {
        "name": "Pavitra Jha",
        "email": "jhapavitra98@gmail.com",
        "time": "Tue Jun 02 01:02:19 2026 -0400"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:21:41 2026 +0200"
      },
      "message": "libceph: fix multiple unsafe decodes in decode_locker()\n\ndecode_locker() in cls_lock_client.c contains three unsafe decode\noperations that allow a malicious or compromised OSD to trigger\nslab-out-of-bounds reads:\n\n1. ceph_decode_copy() at the locker_id_t name field has no preceding\n   bounds check. With p \u003d\u003d end after ceph_start_decoding() accepts\n   struct_len\u003d0, this reads sizeof(ceph_entity_name) \u003d 9 bytes past\n   the validated buffer boundary.\n\n2. *p +\u003d sizeof(struct ceph_timespec) after the locker_info_t header\n   is an unchecked pointer advance. A malicious OSD can position p\n   past end, causing all subsequent _safe checks to pass against a\n   bogus boundary.\n\n3. len \u003d ceph_decode_32(p) has no preceding bounds check, and the\n   immediately following *p +\u003d len is uncapped. A malicious OSD can\n   send len\u003d0xffffffff, advancing p gigabytes past end and escaping\n   the decode window entirely.\n\nFix all three by replacing bare operations with their safe variants:\n  ceph_decode_copy   -\u003e ceph_decode_copy_safe\n  *p +\u003d sizeof(...)  -\u003e ceph_decode_skip_n\n  ceph_decode_32(p)  -\u003e ceph_decode_32_safe\n  *p +\u003d len          -\u003e ceph_decode_skip_n\n\nA new label is added to return -EINVAL on any bounds violation.\n-EINVAL is appropriate here: the data received from the OSD\nis structurally malformed, which is an invalid argument to the decode\ncontract regardless of whether the caller or the wire is at fault.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition)\nwithout any further privileges beyond OSD session establishment.\n\n[ idryomov: use ceph_decode_skip_string() to skip description, trim\n  changelog ]\n\nCc: stable@vger.kernel.org\nFixes: d4ed4a530562 (\"libceph: support for lock.lock_info\")\nSigned-off-by: Pavitra Jha \u003cjhapavitra98@gmail.com\u003e\nReviewed-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "5a87925539acecfe88229bad76ab81bd75a7e3f5",
      "tree": "7beaae8cbdbb8ad99830abfe490995c0ba676e47",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Kefu Chai",
        "email": "k.chai@proxmox.com",
        "time": "Thu Jun 11 19:32:51 2026 +0800"
      },
      "committer": {
        "name": "Ilya Dryomov",
        "email": "idryomov@gmail.com",
        "time": "Wed Aug 12 21:20:54 2026 +0200"
      },
      "message": "libceph: tolerate addrvecs with multiple entries of the same type\n\nceph_decode_entity_addrvec() rejects any addrvec containing more than\none entry that matches the requested msgr type (LEGACY or MSGR2),\nlogging \"another match of type N in addrvec\" and returning -EINVAL.\n\nSome admin tooling (e.g. pveceph mon create from Proxmox VE) generates\naddrvecs with multiple same-type entries when public_network lists more\nthan one CIDR: it picks one local IP per subnet and emits both a v2 and\na v1 entry for each IP.  Monmaps shaped this way cause:\n\n  libceph: mon0 (1)10.10.10.15:6789 session established\n  libceph: another match of type 1 in addrvec\n  libceph: problem decoding monmap, -22\n\nNo Ceph code uses the extra entries: since Nautilus, the userspace\nmessenger (AsyncMessenger) unconditionally picks the first address of\nthe requested type and ignores any subsequent matches.\n\nMatch that behavior: use the first matching entry and silently skip any\nsubsequent ones.  This is a compatibility fix for existing deployments\nand does not enable dual-stack or multi-subnet address selection.\n\n[ idryomov: tweak ceph_decode_entity_addrvec() comment ]\n\nCc: stable@vger.kernel.org\nFixes: a5cbd5fc22d5 (\"libceph, ceph: get and handle cluster maps with addrvecs\")\nLink: https://bugzilla.proxmox.com/show_bug.cgi?id\u003d7518\nSigned-off-by: Kefu Chai \u003ck.chai@proxmox.com\u003e\nReviewed-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\nSigned-off-by: Ilya Dryomov \u003cidryomov@gmail.com\u003e\n"
    },
    {
      "commit": "00268f9452d2a0d660aa9c1bb0ca07a994af6a4f",
      "tree": "95e8ecb07d4bd7eaecd22c8b1e4eb5fed5fe165c",
      "parents": [
        "ae7fd6ff4c6713270d2efe6db87a4a58ccb7cc61"
      ],
      "author": {
        "name": "Andrey Golovko",
        "email": "andrey.golovko@gmail.com",
        "time": "Tue Aug 11 22:14:35 2026 +0300"
      },
      "committer": {
        "name": "Mark Brown",
        "email": "broonie@kernel.org",
        "time": "Wed Aug 12 18:08:48 2026 +0100"
      },
      "message": "regmap: sdw-mbq: don\u0027t call an unset readable_reg callback\n\nregmap_sdw_mbq_poll_busy() decides whether to poll the Function Busy bit\nby calling ctx-\u003ereadable_reg(), which is a straight copy of\nconfig-\u003ereadable_reg. That callback is optional: regmap_readable() treats\na NULL -\u003ereadable_reg as \"every register is readable\", and drivers rely on\nthat. es9356 and tac5xx2-sdw both build an MBQ regmap without one.\n\nSince commit ca1b11b36d82 (\"regmap: sdw-mbq: Allow defers on undeferrable\ncontrols\") the poll runs on every -ENODATA, not only for Controls the\ndriver marked deferrable, so any of those devices answering\nCOMMAND_IGNORED takes the kernel through a NULL function pointer.\n\nTreat a missing callback the way the rest of regmap does and poll.\n\nFixes: 5bc493bf0c37 (\"regmap: sdw-mbq: Add support for SDCA deferred controls\")\nSigned-off-by: Andrey Golovko \u003candrey.golovko@gmail.com\u003e\nReviewed-by: Charles Keepax \u003cckeepax@opensource.cirrus.com\u003e\nLink: https://patch.msgid.link/20260811184500.5312-1-andrey.golovko@gmail.com\nSigned-off-by: Mark Brown \u003cbroonie@kernel.org\u003e\n"
    },
    {
      "commit": "94f39e4c017e66130e476268bdaa0bf61e914fa2",
      "tree": "680b4062f3176c3205f71efeff48f4dae564d5a1",
      "parents": [
        "45f8dffc0714c3ef49c83e5bba4c56a4499bd5fc"
      ],
      "author": {
        "name": "Marc Zyngier",
        "email": "maz@kernel.org",
        "time": "Fri Jul 10 09:09:58 2026 +0100"
      },
      "committer": {
        "name": "Thomas Gleixner",
        "email": "tglx@kernel.org",
        "time": "Wed Aug 12 17:09:29 2026 +0200"
      },
      "message": "clocksource/drivers/arm_arch_timer: Workaround bcm2712 broken EL2 virtual timer\n\nIt appears that the bcm2712 SoC found in the relatively popular RPi5 has a\nbroken EL2 virtual timer.\n\nTthe reason why the timer isn\u0027t working is unknown (the timer is ticking,\nbut the interrupt never fires), and the SoC vendor doesn\u0027t communicate on\nthe reason why this isn\u0027t working, leaving users and maintainers in the\ndark.\n\nPaper over the issue by detecting the broken HW, falling back to the\nphysical timer instead, and let the user know about it.  Also taint the\nkernel as the machine is definitely not compliant with the spec, and it\u0027s\nunknown what else is wrong with it.\n\nReported-by: John \u003ctherealgraysky@proton.me\u003e\nReported-by: Daniel Drake \u003cdan@reactivated.net\u003e\nReported-by: Marek Szyprowski \u003cm.szyprowski@samsung.com\u003e\nSigned-off-by: Marc Zyngier \u003cmaz@kernel.org\u003e\nSigned-off-by: Thomas Gleixner \u003ctglx@kernel.org\u003e\nTested-by: Gary Guo \u003cgary@garyguo.net\u003e\nAcked-by: Florian Fainelli \u003cflorian.fainelli@broadcom.com\u003e\nCc: Daniel Lezcano \u003cdaniel.lezcano@kernel.org\u003e\nLink: https://patch.msgid.link/20260710080958.491620-1-maz@kernel.org\n"
    },
    {
      "commit": "3d6d817622b0a9721e3cc404df3469171582be13",
      "tree": "8a171c5e234e3c8232d6d35fb6b1a7144658af19",
      "parents": [
        "f5bbbfec59b4e2fb7520a91de3df8a6174325d6a",
        "c4f6916a99cf105c3ff340b6210fcbba3fa66b35"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Aug 12 08:03:31 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Wed Aug 12 08:03:31 2026 -0700"
      },
      "message": "Merge tag \u0027scsi-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi\n\nPull SCSI fixes from James Bottomley:\n \"Two minor core fixes: one for power management issues in error\n  handling and the other to fix a deadlock in door locking of SCSI\n  devices with removable media; and a minor bug fix for the debug\n  driver\"\n\n* tag \u0027scsi-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:\n  scsi: scsi_debug: Negate wrapped memcmp() result\n  scsi: core: Do not block on tag allocation in scsi_eh_lock_door()\n  scsi: core: pair EH runtime PM get and put\n"
    },
    {
      "commit": "ac828b94e027d29af82325fcc55556dc8173fd85",
      "tree": "15016808bff69b3cf9092b8e2a48013122e4974f",
      "parents": [
        "9fca434208f1f9ab977feac62df8ebb1cc7ce893"
      ],
      "author": {
        "name": "Lijo Lazar",
        "email": "lijo.lazar@amd.com",
        "time": "Mon Jul 13 16:34:24 2026 +0530"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:23:07 2026 -0400"
      },
      "message": "drm/amdgpu: Prefer default discovery offset\n\nIf a valid signature is seen at the default offset, use the default\nsize/offset for discovery.\n\nFixes: 01bdc7e219c4 (\"drm/amdgpu: New interface to get IP discovery binary v3\")\nCloses: https://gitlab.freedesktop.org/drm/amd/-/work_items/5447\nSigned-off-by: Lijo Lazar \u003clijo.lazar@amd.com\u003e\nReviewed-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 46a0df99a0b2fa2fa61d864b04b6a5d5fe748779)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "9fca434208f1f9ab977feac62df8ebb1cc7ce893",
      "tree": "c02a2654518ac9bf7e770ba2d8e116e1b1abc741",
      "parents": [
        "cd688a3cb342b9f56399aa076157f1c324c15c5a"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Tue Aug 11 11:03:10 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:23:01 2026 -0400"
      },
      "message": "drm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nReviewed-by: Leo Liu \u003cleo.liu@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "cd688a3cb342b9f56399aa076157f1c324c15c5a",
      "tree": "e0493a35ebf3ffeb5915d3e3ef8347697695288c",
      "parents": [
        "cd22349e86faf6e15e6c622d70c0efc57d43201e"
      ],
      "author": {
        "name": "Yang Wang",
        "email": "kevinyang.wang@amd.com",
        "time": "Mon Aug 10 12:48:19 2026 +0800"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:53 2026 -0400"
      },
      "message": "drm/amdgpu: fix nbif 6.3.1 l1 low power not functional\n\nThe PCIe L1 low‑power settings for NBIF 6.3.1 were never applied due to\nunresolved register mapping, which caused the relevant code to be compiled out.\nAs a result, the PCIe link could not enter L1/L23 power‑down states or transition to L0s.\n\nProperly configure the link control register to enable L1 and L23 power‑down,\nand permit L0s link transitions. Keep LTR disabled and let the PCI core enable it\nonly after verifying end‑to‑end root complex support across switches.\n\nFixes: 894c6d3522d1 (\"drm/amdgpu: Add nbif v6_3_1 ip block support\")\nSigned-off-by: Yang Wang \u003ckevinyang.wang@amd.com\u003e\nSigned-off-by: Kenneth Feng \u003cKenneth.feng@amd.com\u003e\nReviewed-by: Kenneth Feng \u003ckenneth.feng@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit c2417f9fd7049d5a8d87eefd82fd6e36ba1ff7b6)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "cd22349e86faf6e15e6c622d70c0efc57d43201e",
      "tree": "3197b8dda2b35f222b2d1e0f674f101bbed328fd",
      "parents": [
        "2f9a5c0f018d4a1586ee892f81f1383219676415"
      ],
      "author": {
        "name": "Nathan Lucas",
        "email": "nlucasgit@gmail.com",
        "time": "Sun Aug 02 08:35:24 2026 -0600"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:47 2026 -0400"
      },
      "message": "drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE\n\nThe commit cited by the Fixes tag added separate limited and full-range\nBT.2020 YCbCr entries to the DCE output CSC tables, but populated both\nentries with the same matrix copied from the common DC table. That\nmatrix combined full-range scaling with limited-range luma offset and was\nincorrect for both limited and full-range output.\n\nReplace the coefficients in both entries in the DCE paths with those from\nthe new COLOR_SPACE_YCBCR2020_LIMITED_TYPE\nand COLOR_SPACE_YCBCR2020_FULL_TYPE entries in the preceding commit\n(\"drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix\").\n\nFixes: 51e6668ab4ba (\"drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs\")\nAssisted-by: OpenAI-Codex:GPT-5.6-Sol\nTested-by: Igor Paunovic \u003croyalnet026@gmail.com\u003e\nTested-by: Satyajit Roy \u003csroy14@alum.utk.edu\u003e\nSigned-off-by: Nathan Lucas \u003cnlucasgit@gmail.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 14c8726b79d19934d6eb6d35c612e3f7204af2c6)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "2f9a5c0f018d4a1586ee892f81f1383219676415",
      "tree": "ca498638762989def8d3c50b3535a24962b5881d",
      "parents": [
        "d5ab4c6a64efef2d143a96df5357f59703cd703d"
      ],
      "author": {
        "name": "Nathan Lucas",
        "email": "nlucasgit@gmail.com",
        "time": "Sun Aug 02 08:35:23 2026 -0600"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:39 2026 -0400"
      },
      "message": "drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix\n\nCOLOR_SPACE_YCBCR2020_TYPE, which is selected for\nCOLOR_SPACE_2020_YCBCR_LIMITED color_space, has coefficients that are\nincorrect for limited-range output. Its luma and chroma scaling is\nfull-range so output is too bright and colors are incorrect.\n\nCOLOR_SPACE_YCBCR2020_TYPE is closer to a full-range conversion matrix with\nincorrect luma offset, so correct the luma offset for full-range and rename\nit to COLOR_SPACE_YCBCR2020_FULL_TYPE.\n\nAdd COLOR_SPACE_YCBCR2020_LIMITED_TYPE with correct scaling and range for\nlimited-range output.\n\nFix related functions so COLOR_SPACE_YCBCR2020_LIMITED_TYPE and\nCOLOR_SPACE_YCBCR2020_FULL_TYPE are correctly selected based on\ndc_color_space.\n\nDerivation of both matrices follows ITU-T H.273:\n\nTable 4, MatrixCoefficients 9, BT.2020-NCL weights:\nKR \u003d 0.2627, KB \u003d 0.0593, KG \u003d 1 - KR - KB \u003d 0.6780.\n\nEquations 45-47 in matrix form:\n            [  KR             KG             KB            0 ]\nM2020_NCL \u003d [ -KR/(2(1-KB))  -KG/(2(1-KB))   1/2           0 ]\n            [  1/2           -KG/(2(1-KR))  -KB/(2(1-KR))  0 ]\n            [  0              0              0             1 ]\n\nLimited and Full transforms based on equations 30-32 and 36-38 with bit\ndepth 10, normalized by 1023:\n\n            [ 876/1023   0         0         64/1023  ]\nMLimited  \u003d [ 0          896/1023  0         512/1023 ]\n            [ 0          0         896/1023  512/1023 ]\n            [ 0          0         0         1        ]\n\n            [ 1023/1023  0         0         0        ]\n    MFull \u003d [ 0          1023/1023 0         512/1023 ]\n            [ 0          0         1023/1023 512/1023 ]\n            [ 0          0         0         1        ]\n\nM2020_NCL_Limited \u003d MLimited x M2020_NCL\nM2020_NCL_Full    \u003d MFull x M2020_NCL\n\nThe upper three rows of M2020_NCL_* are stored in CR, Y, CB order. Each\nM2020_NCL_* value is stored as Round(value * 8192) in its 16-bit\ntwo\u0027s-complement representation.\n\nFixes: 973a9c810c78 (\"drm/amd/display: Fix COLOR_SPACE_YCBCR2020_TYPE matrix\")\nAssisted-by: OpenAI-Codex:GPT-5.6-Sol\nTested-by: Igor Paunovic \u003croyalnet026@gmail.com\u003e\nTested-by: Satyajit Roy \u003csroy14@alum.utk.edu\u003e\nSigned-off-by: Nathan Lucas \u003cnlucasgit@gmail.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 3b906e1dc7e3c9ff9f7940f6828b367a6a9ec73c)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "d5ab4c6a64efef2d143a96df5357f59703cd703d",
      "tree": "c3c24beecc418977ecd0470a7380feb0cc3ab165",
      "parents": [
        "18727670b44753865b81c56a9338c0d7bd102c54"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Mon Aug 10 11:11:35 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:31 2026 -0400"
      },
      "message": "drm/amdgpu: Implement insert_end for VCE 3\n\nAfter a recent change VCE now hangs when VCE_CMD_END is emitted\nafter a pipeline sync without VM flush.\nImplement insert_end to correctly insert only one VCE_CMD_END per job.\n\nFixes: bc639a9eadc7 (\"drm/amdgpu: always emit the job vm fence\")\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nAcked-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 8897ea8c761b856f02061848a7908040a1fe5e68)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "18727670b44753865b81c56a9338c0d7bd102c54",
      "tree": "08889ef745e3fbbfa800904b4d3f5e99c8a098b5",
      "parents": [
        "b8bb9ba3f101a1b0011f785a577a4a0a38371174"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Thu Jul 30 18:05:52 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:24 2026 -0400"
      },
      "message": "drm/amdgpu: Fix UVD min buffer sizes\n\nUse correct size for message buffer \u003d sizeof(struct ruvd_msg).\nAdd ITSCALING_TABLE_BUFFER size.\n\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nAcked-by: Leo Liu \u003cleo.liu@amd.com\u003e\nReviewed-by: Ruijing Dong \u003cruijing.dong@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 37519d007e4261febbcf35b3045f8344f3145497)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "b8bb9ba3f101a1b0011f785a577a4a0a38371174",
      "tree": "e16f005b0d7736c0566713b58f1c5a08b7bd9d12",
      "parents": [
        "21a8084cd76223a13493237e04d45f5226d7cee6"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Thu Jul 30 18:01:51 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:17 2026 -0400"
      },
      "message": "drm/amdgpu: Fix UVD decode image min size calculation\n\nThis needs to use pitch instead of width. Also reject pitch\nover 4096 to avoid overflow.\n\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nAcked-by: Leo Liu \u003cleo.liu@amd.com\u003e\nReviewed-by: Ruijing Dong \u003cruijing.dong@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "21a8084cd76223a13493237e04d45f5226d7cee6",
      "tree": "ba512da893e2287cb542e2a1edc759a45566ea0a",
      "parents": [
        "8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Thu Jul 30 17:56:17 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:10 2026 -0400"
      },
      "message": "drm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nAcked-by: Leo Liu \u003cleo.liu@amd.com\u003e\nReviewed-by: Ruijing Dong \u003cruijing.dong@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08",
      "tree": "64620d2b52727fffb90d7e6255b5759ab12ed3c6",
      "parents": [
        "2a9c5154a5650c09ad44ff5e1dff74754e15a3c6"
      ],
      "author": {
        "name": "David Rosca",
        "email": "david.rosca@amd.com",
        "time": "Thu Jul 30 17:37:44 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:22:03 2026 -0400"
      },
      "message": "drm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\nSigned-off-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nAcked-by: Leo Liu \u003cleo.liu@amd.com\u003e\nReviewed-by: Ruijing Dong \u003cruijing.dong@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "2a9c5154a5650c09ad44ff5e1dff74754e15a3c6",
      "tree": "71bbb7127d9918e2d4f9065a60b2a86fec205e4b",
      "parents": [
        "587be7a17358ef8c0106775fcedae5a7bef50735"
      ],
      "author": {
        "name": "Yang Wang",
        "email": "kevinyang.wang@amd.com",
        "time": "Wed Aug 05 20:39:18 2026 +0800"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:21:31 2026 -0400"
      },
      "message": "drm/amdgpu: check ASPM on the dGPU host link\n\ndGPUs with an internal PCIe switch expose graphics functions below the\nswitch downstream port. The automatic ASPM check uses the display\nendpoint and evaluates the internal link instead of the host link.\n\nUse the switch upstream port for the check and report the selected\nlink.\n\nFixes: 0ab5d711ec74 (\"drm/amd: Refactor `amdgpu_aspm` to be evaluated per device\")\nSigned-off-by: Yang Wang \u003ckevinyang.wang@amd.com\u003e\nReviewed-by: Hawking Zhang \u003cHawking.Zhang@amd.com\u003e\nReviewed-by: Kenneth Feng \u003ckenneth.feng@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 4e0d6f2876e704fff707b18c40dbd383aea4a1c9)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "587be7a17358ef8c0106775fcedae5a7bef50735",
      "tree": "24005b293e0012a9d17a86cf782a8ce038fc390c",
      "parents": [
        "47cd31185090bd1439d4587b835ac22d7ba6f1e3"
      ],
      "author": {
        "name": "Guangshuo Li",
        "email": "lgs201920130244@gmail.com",
        "time": "Sat Aug 08 21:59:42 2026 +0800"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:21:23 2026 -0400"
      },
      "message": "drm/radeon: fix autosuspend cleanup during teardown\n\nradeon_driver_load_kms() calls pm_runtime_use_autosuspend() for PX\ndevices, but radeon_driver_unload_kms() does not call the matching\npm_runtime_dont_use_autosuspend() during teardown.\n\nIf the autosuspend delay is set to a negative value while autosuspend\nis enabled, the runtime PM core increments usage_count to prevent\nruntime suspend. Without calling pm_runtime_dont_use_autosuspend()\nduring teardown, this reference is not dropped.\n\nThe documentation for pm_runtime_use_autosuspend() also notes that it\nis important to undo it with pm_runtime_dont_use_autosuspend() at\ndriver exit time, unless runtime PM was initially enabled with\ndevm_pm_runtime_enable().\n\nAdd the missing pm_runtime_dont_use_autosuspend() call to the driver\nunload path.\n\nThis issue was found by manual code inspection.\n\nFixes: 10ebc0bc0934 (\"drm/radeon: add runtime PM support (v2)\")\nSigned-off-by: Guangshuo Li \u003clgs201920130244@gmail.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 0fdc1ff82ea14844c22795e9e0813c3ca03235e1)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "47cd31185090bd1439d4587b835ac22d7ba6f1e3",
      "tree": "6eb02ae55a536647820c611b9fa0cf4f1b0d9f8a",
      "parents": [
        "f2a1c4c6fe0a6fcde02e59dde546dba28d283635"
      ],
      "author": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Fri Jun 05 17:46:19 2026 -0400"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:21:14 2026 -0400"
      },
      "message": "drm/amdgpu: fix missing check in vm_flush()\n\nWe shouldn\u0027t return early if we need to emit spm update.\n\nReviewed-by: David Rosca \u003cdavid.rosca@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 54a118f1d7e184fcbb18f83889f48f17a767878a)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "f2a1c4c6fe0a6fcde02e59dde546dba28d283635",
      "tree": "09dfe584a7ca2229481f4e636f66f2fe0192d538",
      "parents": [
        "5e9d136ad74df4edec67e502ce267597064d8f86"
      ],
      "author": {
        "name": "Samuel Pitoiset",
        "email": "samuel.pitoiset@gmail.com",
        "time": "Fri Aug 07 16:58:55 2026 +0200"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:21:06 2026 -0400"
      },
      "message": "drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()\n\namdgpu_dm_crtc_set_vblank() dereferences acrtc_state-\u003estream when\nvblank is enabled/queried from DRM_IOCTL_MODE_CRTC_GET_SEQUENCE before\na stream is attached to it.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nRIP: amdgpu_dm_crtc_set_vblank+0x6b/0x4d0 [amdgpu]\nCall Trace:\n drm_vblank_enable\n drm_vblank_get\n drm_crtc_get_sequence_ioctl\n drm_ioctl_kernel\n drm_ioctl\n\nReproduced by running VKCTS with WSI tests enabled on RADV.\n\nGuard the enable path on acrtc_state-\u003estream being non-NULL, matching\nthe existing checks in this function.\n\nFixes: 34d66bc7ff10 (\"drm/amd/display: Fix Xorg desktop unresponsive on Replay panel\")\nReviewed-by: Melissa Wen \u003cmwen@igalia.com\u003e\nSigned-off-by: Samuel Pitoiset \u003csamuel.pitoiset@gmail.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 7b1b31bf6942e6f43509b48da23f8e27269aac39)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "5e9d136ad74df4edec67e502ce267597064d8f86",
      "tree": "d6f996d6c3547ef8abe413acde504b2c915fe5c2",
      "parents": [
        "931cd1d1baeae68e8eb2c23bc1f3d8934dca6241"
      ],
      "author": {
        "name": "Candice Li",
        "email": "candice.li@amd.com",
        "time": "Mon Jul 27 11:51:37 2026 +0800"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:20:58 2026 -0400"
      },
      "message": "drm/amdgpu: validate GEM_CREATE domain combinations\n\nAMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK,\nbut did not validate domain combinations. Userspace could combine\nCPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making\namdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and\nhit BUG_ON().\n\nAllow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/\nVRAM domains to be specified one at a time. Return -EINVAL for invalid\ncombinations in amdgpu_gem_create_ioctl().\n\nv2: Rename helper from amdgpu_gem_domain_valid() to\n    amdgpu_gem_are_domains_valid() (Christian)\n\nSigned-off-by: Candice Li \u003ccandice.li@amd.com\u003e\nReviewed-by: Christian König \u003cchristian.koenig@amd.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)\nCc: stable@vger.kernel.org\n"
    },
    {
      "commit": "931cd1d1baeae68e8eb2c23bc1f3d8934dca6241",
      "tree": "84af6d345a5b9c6a284f4ce08c23cf6c3a0521d6",
      "parents": [
        "db2ddb87143519e20a95aa36c60b36107b736a58"
      ],
      "author": {
        "name": "Junrui Luo",
        "email": "moonafterrain@outlook.com",
        "time": "Thu Aug 06 12:45:24 2026 +0800"
      },
      "committer": {
        "name": "Alex Deucher",
        "email": "alexander.deucher@amd.com",
        "time": "Wed Aug 12 10:20:50 2026 -0400"
      },
      "message": "drm/amdgpu: disallow multiple FENCE chunks in one submit\n\namdgpu_cs_pass1() dispatches on chunk_id once per chunk without\nrejecting repeated ids. p-\u003euf_bo is a single-slot field, so a\nsubmission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs\namdgpu_cs_p1_user_fence() twice, and the second run overwrites\np-\u003euf_bo with a freshly referenced BO without dropping the reference\ntaken by the first.\n\namdgpu_cs_parser_fini() only unrefs the final p-\u003euf_bo, so every FENCE\nchunk but the last leaks a BO reference. The leaked BO outlives handle\nclose and process exit.\n\nReject duplicate FENCE chunks the same way commit fec5f8e8c6bc\n(\"drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit\") did\nfor p-\u003ebo_list.\n\nFixes: d38ceaf99ed0 (\"drm/amdgpu: add core driver (v4)\")\nReported-by: Yuhao Jiang \u003cdanisjiang@gmail.com\u003e\nAssisted-by: Claude:claude-opus-5\nCc: stable@vger.kernel.org\nReviewed-by: Christian König \u003cchristian.koenig@amd.com\u003e\nSigned-off-by: Junrui Luo \u003cmoonafterrain@outlook.com\u003e\nSigned-off-by: Alex Deucher \u003calexander.deucher@amd.com\u003e\n(cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)\n"
    },
    {
      "commit": "1fd495ef09eef96169a379a749c24b5e69974bb8",
      "tree": "70f1f59796463e84056b08d90aff4f46ad1ca7e3",
      "parents": [
        "075b74841bd0065a3bda3440873c747938e69b68"
      ],
      "author": {
        "name": "Uwe Kleine-König",
        "email": "ukleinek@kernel.org",
        "time": "Fri Jul 31 11:49:49 2026 +0200"
      },
      "committer": {
        "name": "Geert Uytterhoeven",
        "email": "geert@linux-m68k.org",
        "time": "Wed Aug 12 13:53:44 2026 +0200"
      },
      "message": "m68k: Define NR_CPUS to 1\n\nThis fixes a Kconfig warning\n\n\tfs/erofs/Kconfig:137:warning: range is invalid\n\nwhich originates from EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS using\nNR_CPUS which up to now didn\u0027t exist for ARCH\u003dm68k.  All other\narchitectures define this symbol, so fix the outlier.\n\n[geert] This also fixes:\n  - CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS being set to the\n    literal NR_CPUS instead of a number by automatic configs like\n    \"make allmodconfig\" or \"make olddefconfig\",\n  - An infinite loop in manual configs like \"make oldconfig\" when\n    CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS is not present or\n    has an invalid value in your existing .config.\n\nFixes: c9b47e6b2311 (\"erofs: cap LZMA stream pool size\")\nSigned-off-by: Uwe Kleine-König \u003cukleinek@kernel.org\u003e\nReviewed-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\nLink: https://patch.msgid.link/20260731094950.1988084-2-ukleinek@kernel.org\nSigned-off-by: Geert Uytterhoeven \u003cgeert@linux-m68k.org\u003e\n"
    },
    {
      "commit": "b64a9f67e082e04835ddd69d422a25168d69375b",
      "tree": "66860d191c2ba5e301f81d36536be858d48bd36b",
      "parents": [
        "86bcfe2e37cee93bb495ecd3238116ffd21183e9"
      ],
      "author": {
        "name": "Jérémy Jean",
        "email": "Jeremy.Jean@oss.cyber.gouv.fr",
        "time": "Tue Aug 11 19:10:11 2026 +0000"
      },
      "committer": {
        "name": "Christian Brauner",
        "email": "brauner@kernel.org",
        "time": "Wed Aug 12 12:56:30 2026 +0200"
      },
      "message": "pid: reject allocations through dead ancestor pid namespaces\n\nalloc_pid() checks PIDNS_ADDING only on the leaf pid namespace before\nmaking a new struct pid visible in every ancestor namespace. That is\ninsufficient when an unborn descendant pid namespace outlives an\nancestor whose init task has already exited. The descendant can still be\ninitialized later through setns(), and the new pid is then published\ninto the dead ancestor as well.\n\nKeep the existing ENOMEM behavior, but require PIDNS_ADDING to be set in\nevery namespace that will receive the new pid before publishing any of\nthem. This preserves the invariant that free_pid() never decrements\npid_allocated in a namespace whose child_reaper is no longer live.\n\nFixes: a3bdc23ba8ea (\"pid_namespace: allow opening pid_for_children before init was created\")\nSigned-off-by: Jérémy Jean \u003cJeremy.Jean@oss.cyber.gouv.fr\u003e\nReviewed-by: Pavel Tikhomirov \u003cptikhomirov@virtuozzo.com\u003e\nSigned-off-by: Christian Brauner (Amutable) \u003cbrauner@kernel.org\u003e\n"
    },
    {
      "commit": "090a95dbe13df9965279b588d97eda134831769c",
      "tree": "34bd255415c48aaa294d6da1e320fbbb2aa9ca88",
      "parents": [
        "b48a0a0a76ccecec60f0568e2af4d89994b08bec"
      ],
      "author": {
        "name": "Karl Mehltretter",
        "email": "kmehltretter@gmail.com",
        "time": "Sat Aug 08 17:05:06 2026 +0200"
      },
      "committer": {
        "name": "Ulf Hansson",
        "email": "ulfh@kernel.org",
        "time": "Wed Aug 12 11:09:12 2026 +0200"
      },
      "message": "pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()\n\nmtk_mfg_attach_dev() reads prev_o on the first iteration of its loop,\nin \"if (prev_o \u0026\u0026 prev_o-\u003efreq \u003d\u003d o-\u003efreq)\", before prev_o is assigned\nat the end of the loop body. On that first iteration, evaluating prev_o\nreads an indeterminate value. If it is non-NULL, the condition\ndereferences a stale or invalid pointer, potentially faulting or\nincorrectly skipping the first OPP.\n\nInitialize prev_o to NULL. This matches the intent as well: there is no\nprevious OPP to compare against on the first iteration.\n\nFound with Clang\u0027s -Wconditional-uninitialized.\n\nFixes: f08e7a4e8d6ac (\"pmdomain: mediatek: Add support for MFlexGraphics\")\nAssisted-by: Claude:claude-fable-5\nSigned-off-by: Karl Mehltretter \u003ckmehltretter@gmail.com\u003e\nReviewed-by: Nicolas Frattaroli \u003cnicolas.frattaroli@collabora.com\u003e\nCc: stable@vger.kernel.org\nSigned-off-by: Ulf Hansson \u003culfh@kernel.org\u003e\n"
    },
    {
      "commit": "7b53449540502cb21b32bca62a6258e22cd97bbe",
      "tree": "e2917044e8bbf1eabe743db9d0a60b9adb99f32d",
      "parents": [
        "6d3724e616faf952c3adcf8414fc21a828ef3709",
        "490937b88cb592cc0c5367758edd700fd5abd15c"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:32:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:32:18 2026 -0700"
      },
      "message": "Merge tag \u0027nf-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf\n\nPablo Neira Ayuso says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nNetfilter/IPVS fixes for net\n\nThe following patchset contains Netfilter/IPVS fixes for net. Still\nlarge batch for this late -rc cycle but at least half of these fixes\nin this batch have been cooking for several weeks before:\n\n1) Fix race between ipset list:set GC and swap, use write_lock instead\n   of rcu read lock section when accessing the index to ensure\n   interference with ip_set_swap(), from Xiang Mei.\n\n2) Release template conntrack in bridge conntrack when packet is\n   neither IPv4 nor IPv6 before setting skb as untracked.\n   From Zhiling Zou.\n\n3) A series of 3 patches for IPVS to address sashiko reports:\n   Schedulers read destination overload state while connection\n   accounting and destination configuration can update it concurrently.\n   The first patch adds a single total connection counter. The second\n   patch uses it to identify threshold crossings precisely, and updates\n   OVERLOAD at the crossings and on a threshold edit under dst_lock.\n   The third patch moves configuration-controlled AVAILABLE to a\n   separate cflags word, so it cannot clobber OVERLOAD through an\n   unrelated read-modify-write update.\n\n4) Log invalid packets in TCP and SCTP connection tracking to address\n   a deadlock when nfnetlink_log is used as logging backend and the\n   nfnetlink_log conntrack glue support is used. From Zihan Xi.\n\n5) Wait for rcu grace period before releasing pernet state in\n   nfnetlink_log, otherwise packets can end up access already released\n   memory, triggering UaF. From Florian Westphal.\n\n6) IPVS needs to reset IP information in control buffer in skbuff when\n   encapsulating IP packets in ICMP, from Kyle Zeng.\n\n7) IPVS needs to validate ihl field of inner headers in when handling\n   ICMP response, from Julian Anastasov.\n\n8) Remove a WARN_ON_ONCE reachable from the nf_tables hardware offload\n   when triggering ENOMEM on GFP_KERNEL allocation,\n   from Alexey Velichayshiy.\n\n9) Publish reply tuple into the flowtable hashtable first, otherwise\n   GC might walk over a released tuple when insertion of the original\n   tuple fail. From Jeremy Jean.\n\n10) Elide counter increment when replacing an ipset element,\n    from Florian Westphal.\n\n11) Remove unneeded ipset accounting resets on destruction/flush,\n    from Florian Westphal.\n\n* tag \u0027nf-26-08-10\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:\n  netfilter: ipset: let destroy callbacks adjust ext mem size\n  netfilter: ipset: fix list type element drift bug\n  netfilter: flowtable: publish GC-visible tuple last\n  netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path\n  ipvs: revalidate ihl to prevent out-of-bounds access\n  ipvs: clear IPv4 options after rebasing tunnel ICMP errors\n  netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state\n  netfilter: nf_conntrack: defer invalid log until after unlock\n  ipvs: separate destination availability state\n  ipvs: properly update the overload flag on dest edit\n  ipvs: add totalconns for dest\n  netfilter: bridge: release template ct on non-IP path\n  netfilter: ipset: fix refcount race between list:set GC and swap\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260810190621.894119-1-pablo@netfilter.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6d3724e616faf952c3adcf8414fc21a828ef3709",
      "tree": "3148ab1ca23138488733927322331ba98b0b2b24",
      "parents": [
        "484ec2ab78438b06153fb12b16827992a5ab8204"
      ],
      "author": {
        "name": "Zhang Changzhong",
        "email": "zhangchangzhong@huawei.com",
        "time": "Fri Aug 07 15:50:38 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:28:43 2026 -0700"
      },
      "message": "net/sched: cls_u32: skip hash tables in u32_bind_class()\n\nu32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode\nthrough the walker callback. u32_bind_class() unconditionally casts the\npassed fh to tc_u_knode and accesses \u0026n-\u003eres, so when fh is actually a\ntc_u_hnode, which has no tcf_result member, this results in a\nslab-out-of-bounds read of res-\u003eclassid in tc_cls_bind_class().\n\nThe issue can be reproduced with the following commands:\n\n    tc qdisc add dev lo root handle 1: hfsc\n    tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit\n    tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1\n    tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit\n\nFix this by skipping hash tables via the TC_U32_KEY(handle) check.\n\nFixes: 07d79fc7d94e (\"net_sched: add reverse binding for tc class\")\nSigned-off-by: Zhang Changzhong \u003czhangchangzhong@huawei.com\u003e\nAcked-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nLink: https://patch.msgid.link/1786089038-36366-1-git-send-email-zhangchangzhong@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "484ec2ab78438b06153fb12b16827992a5ab8204",
      "tree": "52ea83f7cba7164878f82a029aba576a35a178fe",
      "parents": [
        "f60b396ee174206fe08ebf997d16cd3801b77b22",
        "3992ced109c70b771efad9e51ae68e5c7a04dea3"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:09 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:10 2026 -0700"
      },
      "message": "Merge branch \u0027gve-bug-fixes-for-header-split-and-ptp\u0027\n\nHarshitha Ramamurthy says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\ngve: Bug fixes for header-split and PTP\n\nThis series contains 2 bug fixes for gve.\n\nPatch 1 fixes an issue which causes TX timeouts due to HW detection of\nan illegal descriptor. This happens when receiving header-only packets\nwith header split enabled - this produces an SKB with a zero-length\nfragment.\n\nPatch 2 prevents a kernel NULL pointer dereference by stubbing the PTP\nadjfine callback.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260807224315.234152-1-hramamurthy@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3992ced109c70b771efad9e51ae68e5c7a04dea3",
      "tree": "52ea83f7cba7164878f82a029aba576a35a178fe",
      "parents": [
        "6bf14575c65569dcded90ef78afb8a6d57323f04"
      ],
      "author": {
        "name": "Jordan Rhee",
        "email": "jordanrhee@google.com",
        "time": "Fri Aug 07 22:43:15 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Tue Aug 11 18:26:04 2026 -0700"
      },
      "message": "gve: fix NULL dereference due to missing ptp adjfine\n\nFix NULL dereference due to missing implementation of adjfine, which can\nbe triggered from usermode as follows:\n\nsudo ./testptp -d /dev/ptp0 -f 0\n[  551.943697] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\n[  552.061946] Call Trace:\n[  552.064487]  \u003cTASK\u003e\n[  552.066681]  ptp_clock_adjtime+0x1c0/0x2c0\n[  552.070874]  ? get_clock_desc+0x6b/0xb0\n[  552.074825]  pc_clock_adjtime+0x78/0xc0\n[  552.078755]  __do_sys_clock_adjtime+0x85/0x110\n[  552.083293]  do_syscall_64+0xea/0x610\n\nCc: stable@vger.kernel.org\nFixes: acd16380523b (\"gve: Add initial PTP device support\")\nSigned-off-by: Jordan Rhee \u003cjordanrhee@google.com\u003e\nSigned-off-by: Harshitha Ramamurthy \u003chramamurthy@google.com\u003e\nReviewed-by: Vadim Fedorenko \u003cvadim.fedorenko@linux.dev\u003e\nLink: https://patch.msgid.link/20260807224315.234152-3-hramamurthy@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    }
  ],
  "next": "6bf14575c65569dcded90ef78afb8a6d57323f04"
}
