)]}'
{
  "log": [
    {
      "commit": "cee9395acd8043be0644b25c34bfa86623f2b935",
      "tree": "40f18a04489cadca07bfa864ca8f62c8d3d80806",
      "parents": [
        "78bb208b99e7d3314f670710fa9ee0a793682bca"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 13:34:40 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 13:34:40 2026 -0700"
      },
      "message": "Linux 7.3-rc1\n"
    },
    {
      "commit": "78bb208b99e7d3314f670710fa9ee0a793682bca",
      "tree": "611c2459d965a68ff88af1a0241f8d5d89716e56",
      "parents": [
        "eea8bdcb59e02729a33a8666f7b0b5e30e6cb736",
        "b15b548d52b43ba8ac4652bc2c7244a8dd1e9622"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:53:24 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:53:24 2026 -0700"
      },
      "message": "Merge tag \u0027i2c-fixes-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux\n\nPull i2c fixes from Andi Shyti:\n \"Fixes mainly for teardown and resource handling, runtime PM and\n  hardware-specific controller issues:\n\n   - fix debugfs use-after-free when removing the adapter\n\n   - designware: apply interrupt mask quirk for HJMC3001\n\n   - imx-lpi2c: avoid target accesses on master-only controllers\n\n   - mux: release channel node when adapter registration fails\n\n   - qcom-cci: fix autosuspend and runtime PM cleanup on removal\n\n   - qcom-geni: fix timing parameters for 32 MHz clock\"\n\n* tag \u0027i2c-fixes-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:\n  i2c: core: fix debugfs UAF on adapter removal\n  i2c: imx-lpi2c: avoid accessing target registers on master-only controllers\n  i2c: qcom-cci: fix autosuspend cleanup\n  i2c: designware: Enable interrupt mask workaround for HJMC3001\n  i2c: qcom-geni: update frequency table to fix timing parameters\n  i2c: mux: Fix channel node leak on adapter add failure\n"
    },
    {
      "commit": "eea8bdcb59e02729a33a8666f7b0b5e30e6cb736",
      "tree": "13129668f546c78eb4c64ba97cfa9227c4e60b55",
      "parents": [
        "cbb4c6d9af7dde462f8c9261bdcd35c47a0b4054",
        "ef6a1dca8de41a408019310649e6d1b7b21ac4bc"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:42:40 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:42:40 2026 -0700"
      },
      "message": "Merge tag \u0027cocci-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jlawall/linux\n\nPull Coccinelle updates from Julia Lawall:\n\n - Clean up a number of the semantic patches in the scripts/coccinelle\n   directory, particularly with respect to functions that no longer\n   exist in the kernel (Sang-Heon Jeon)\n\n   He and I have also done some reorganizations that improve\n   performance.\n\n - Eliminate some false positives (me)\n\n - Fix an out of date URL (相浦彰)\n\n* tag \u0027cocci-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jlawall/linux:\n  coccinelle: ifnulldev_put: update error message\n  coccinelle: ifnulldev_put: update outdated helper names\n  coccinelle: atomic_as_refcounter: drop atomic_long_dec_and_lock\n  coccinelle: kfree_mismatch: drop vmalloc_exec\n  coccinelle: pool_zalloc-simple: drop the pci_pool_alloc rules\n  coccinelle: zalloc-simple: drop the kmem_alloc rules\n  coccinelle: alloc_cast: drop removed allocators\n  coccinelle: remove obsolete pci_free_consistent.cocci\n  scripts: coccinelle: devm_free: reduce false positives\n  coccinelle: misc: struct_size: drop unneeded parentheses\n  coccinelle: mini_lock: improve performance when searching loops\n  coccinelle: api: check for macro context\n  coccinelle: update Coccinelle website URL\n  coccinelle: misc: minmax: avoid unhelpful isomorphisms\n  coccinelle: misc: minmax: check for the presence of if cases\n  coccinelle: misc: minmax: drop unneeded parentheses\n  coccinelle: misc: minmax: improve performance when no candidate exists\n  coccinelle: double_lock: improve performance when no double lock exists\n"
    },
    {
      "commit": "cbb4c6d9af7dde462f8c9261bdcd35c47a0b4054",
      "tree": "7186d2b63cd47031f0b8f4e76b53a0f78276422d",
      "parents": [
        "a23cbb05744b22719efdc34f9e329a120e81e617"
      ],
      "author": {
        "name": "Darrick J. Wong",
        "email": "djwong@kernel.org",
        "time": "Fri Aug 28 09:15:01 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:29:08 2026 -0700"
      },
      "message": "CREDITS/mailmap: add some info about Darrick J. Wong\n\nAdd myself to CREDITS because apparently I\u0027ve never done that; and\nupdate mailmap so that all my old email addresses get remapped to the\nkernel.org redirector.\n\nSigned-off-by: \"Darrick J. Wong\" \u003cdjwong@kernel.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n"
    },
    {
      "commit": "a23cbb05744b22719efdc34f9e329a120e81e617",
      "tree": "f16d636557c5c6bf2e5528f926e64a2fb41da260",
      "parents": [
        "637836563deb95f4338decf2d2d832c4deef022a",
        "64f74d8f728877858372c52067e5c0c091f8db24"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:19:11 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 10:19:11 2026 -0700"
      },
      "message": "Merge tag \u0027timers-urgent-2026-08-30\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull timer fix from Ingo Molnar:\n\n - Fix UM build regression caused by the removal of the UM\n   specific timex.h header (Thomas Weißschuh)\n\n* tag \u0027timers-urgent-2026-08-30\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  um: Use asm-generic/timex.h over the host architecture one\n"
    },
    {
      "commit": "637836563deb95f4338decf2d2d832c4deef022a",
      "tree": "3310a88f40dc986e35a8d61bf7cab0c1e085d115",
      "parents": [
        "f59c074e76a6a9ea55818373decdf56c6fddca30",
        "46094a7708b7945cb7eba9eb887e3ea9757440a7"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:57:35 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:57:35 2026 -0700"
      },
      "message": "Merge tag \u0027locking-urgent-2026-08-30\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip\n\nPull locking fix from Ingo Molnar:\n\n - Revert a commit to spinlock cleanup guards that got caught up\n   in the subtle limitations \u0026 fragility of guards (again...) and\n   caused a regression (Peter Zijlstra)\n\n* tag \u0027locking-urgent-2026-08-30\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:\n  locking: Revert switching guards to _irq_{disable,enable}()\n"
    },
    {
      "commit": "f59c074e76a6a9ea55818373decdf56c6fddca30",
      "tree": "29fb3ea5dfb5a7a52977766b7178146b9fce83b6",
      "parents": [
        "0fe792fa9b616b790f03cbeed067b83eeaae7e7e",
        "1b0bab4a873f1034c27573cfc613394cff7e0a5b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:47:39 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:47:39 2026 -0700"
      },
      "message": "Merge tag \u0027rust-fixes-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux\n\nPull Rust fixes from Miguel Ojeda:\n \"Toolchain and infrastructure:\n\n   - Fix KCFI failures, such as in Rust doctests, by disabling function\n     merging when CFI is enabled. Gary reported the LLVM bug to upstream\n     and it is now fixed in their mainline.\n\n   - Fix \u0027objtool\u0027 fallthrough warnings under the experimental\n     \u0027CONFIG_RUST_INLINE_HELPERS\u0027 by passing (for the combined Rust and\n     helpers code) the LLVM options needed to preserve the unreachable\n     traps that \u0027rustc\u0027 normally emits.\n\n     In addition, fix \u0027objtool\u0027 errors when LTO is enabled on top, by\n     also filtering out the LTO flags (for the combined Rust and helpers\n     code) so that the traps are kept in place.\n\n   - Fix \u0027objtool\u0027 warnings by adding one more \u0027noreturn\u0027 function.\n\n   - Fix \u0027make rusttest\u0027 target when the \u0027rustc-dev\u0027 component is\n     installed and Rust \u003e\u003d 1.82.0, \u003c\u003d 1.87.0 is used.\n\n  \u0027kernel\u0027 crate:\n\n   - \u0027num\u0027 module: fix soundness issue in the \u0027Bounded\u0027 conversion from\n     \u0027bool\u0027 by restricting the conversions to unsigned \u0027Bounded\u0027.\n\n   - \u0027jump_label\u0027 module: fix future \u0027make rusttest\u0027 target failures\n     when \u0027ARCH\u003d\u0027 is set to an arch different than the host\u0027s.\n\n   - \u0027list\u0027 module: fix incorrect \u0027pop_back()\u0027 comment\"\n\n* tag \u0027rust-fixes-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ojeda/linux:\n  rust: kbuild: disambiguate `zerocopy_derive` for `rusttest`\n  rust: num: restrict bool conversion to unsigned Bounded\n  kbuild: rust: keep Rust objects out of Clang LTO with inline helpers\n  kbuild: rust: preserve unreachable traps with inline helpers\n  rust: cfi: disable function merging if CFI is enabled\n  rust: jump_label: skip arch-specific asm in `testlib` builds\n  objtool/rust: add one more `noreturn` Rust function\n  rust: kernel: list: fix incorrect pop_back example comment\n"
    },
    {
      "commit": "0fe792fa9b616b790f03cbeed067b83eeaae7e7e",
      "tree": "592def0c1a5ad43870105b325d0abe40c65ee3bd",
      "parents": [
        "fb5b59a6a678bab054a78d99eecfdb6f5558e82e",
        "1a89abc009cb5035d0cb4e5ba48d32b94f30e8e4"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:43:01 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:43:01 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rmk/linux\n\nPull arm updates from Russell King:\n \"Updates for 7.3:\n\n   - add module description for kprobes testing module\n\n   - remove references to CONFIG_CPU_ARM92x_CPU_IDLE options\n\n   - expand comment in ARM\u0027s __switch_to()\n\n  Also a number of fixes that missed 7.2:\n\n   - disable broken eBPF on RiscPC\n\n   - more BKPT fixes (guys, it\u0027s a *very* bad idea when everyone uses\n     the BKPT instruction for their own differing purposes)\n\n   - another preempt-rt fix, this time for siglock / CPU timers\n\n   - fix another path where we try to send signals to processes with\n     interrupts disabled\n\n   - acquire mmap write lock for show_pte() with user faults\"\n\n* tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rmk/linux:\n  ARM: 9480/1: entry: expand comment in __switch_to\n  ARM: 9478/1: Remove references to removed CONFIG_CPU_ARM92x_CPU_IDLE options\n  ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults\n  ARM: 9484/1: enable interrupts when unhandled user faults are triggered\n  ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK\n  ARM: 9481/2: breakpoint: CFI breakpoints only on demand\n  ARM: 9477/1: Disable broken eBPF JIT on the Risc PC\n  ARM: 9473/1: kprobes: test: add MODULE_DESCRIPTION\n"
    },
    {
      "commit": "fb5b59a6a678bab054a78d99eecfdb6f5558e82e",
      "tree": "5c777bc9b314223fbfc9418fae093d7df571031e",
      "parents": [
        "034dd340b08be1f2f0477ad16131d609f9dbd53c",
        "78004e9a87f240df03e2f73120d291763c32e0a7"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:26:54 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:26:54 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus\u0027 of https://github.com/openrisc/linux\n\nPull OpenRISC updates from Stafford Horne:\n \"One small trivial macro cleanup and one bug fix.\n\n  The bug fix is to fix an unchecked access in our or1k_atomic syscall,\n  I am debating if we should just deprecate this as there is minimal\n  need for it\"\n\n* tag \u0027for-linus\u0027 of https://github.com/openrisc/linux:\n  openrisc: fix arbitrary kernel memory access via or1k_atomic syscall\n  openrisc: drop unneeded semicolon\n"
    },
    {
      "commit": "034dd340b08be1f2f0477ad16131d609f9dbd53c",
      "tree": "2536f4b2d7893ccd916b5abdf3c454ad6edc03c2",
      "parents": [
        "08dbfad3f5040f5bdb6c529da20d6d4e81fefd72",
        "5eab74874d11160725c42ab676ba97a797a362eb"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:22:00 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Aug 30 09:22:00 2026 -0700"
      },
      "message": "Merge tag \u0027trace-v7.3-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull tracing fixes from Steven Rostedt:\n\n - Fix error output of boot instance creation failure\n\n   Currently if a boot instance creation fails, instead of printing out\n   the name of the instance that failed, it prints \"(null)\". That is\n   because it prints \"cur_str\" that had already been processed by\n   strsep(). Print the saved name instead.\n\n   While at it, print the error code of the failure.\n\n - Fix use-after-free for same named historgrams\n\n   Histograms can be named so that they can be used in multiple events.\n   But if the named histogram has a variable attached, the second event\n   that uses the named histogram which duplicates it and needs to free\n   the original after duplication leaves the old variable in place and\n   still visible. If another histogram uses than variable, it will use\n   the stale one which will try to reference the freed duplicate\n   histogram and crash the kernel.\n\n   Free the duplicate variables along with the duplicated histogram\n   data.\n\n - Check return value of kthread_run() in event self test\n\n   The events self tests uses a kthread for testing but does not check\n   if it succeeded in creating a kthread. If the kthread creation were\n   to fail, the code will still try to call kthread_stop() on the error\n   returned.\n\n - Fix race between reading trace_pipe and updating subbuffer size\n\n   If a user is reading the trace_pipe file at the same time they update\n   the ring buffer sub-buffer size, can cause the trace_pipe read to\n   read stale data. Add trace_access_lock() around updating the ring\n   buffer sub-buffer size.\n\n - Fix eventfs_inode on failure path in creation of the events directory\n\n   In the creation of the \"events\" directory, if after allocating the\n   eventfs_inode a failure is detected, it calls cleanup_ei() which\n   calls free_ei(). The free_ei() will test if eventfs_inode being freed\n   has no children. It is a bug if it does. But on the failure case of\n   the creation of the \"events\" directory, the children lists have not\n   yet been initialized and the free will trigger a warning because\n   list_empty() on an uninitialized list returns false.\n\n   Move the initialization into init_ei() where it makes more sense and\n   makes sure that a created eventfs_inode has its lists initialized\n   upon creation.\n\n - Check return value of kthread_run() in ftrace direct sample code\n\n   The sample code that shows how to use the ftrace direct calls does\n   not test the return of kthread_run() to see if it succeeds. Return a\n   failure if the kthread_run() doesn\u0027t succeed.\n\n - Clear user events state on fork in case of alloc failure\n\n   On fork, the child gets a pointer to the parent\u0027s user events state.\n   It makes a copy of it then updates the child\u0027s pointer to it. But if\n   the allocation fails, the duplication function leaves the child with\n   a pointer to its parent\u0027s descriptor. When the child cleans up its\n   data, it will free the parent\u0027s descriptor while the parent is still\n   using it.\n\n   In the duplication function, set the child\u0027s user_event_mm to NULL\n   before testing if the allocation succeeded, and when it exits it will\n   not free the parent\u0027s descriptor.\n\n - Fix retry exhaustion in simple ring buffer reader swap\n\n   simple_ring_buffer_swap_reader_page() starts with retry set to 8 and\n   post-decrements it only after a failed link replacement. On the final\n   attempt, a successful replacement leaves retry at zero, while a\n   failed replacement leaves it at -1.\n\n   But the check for success expects the retry value to be non-zero and\n   exits with an error on zero. This is the opposite result. Fix it.\n\n - Fail nicely when the remote swap_reader_page() returns an error\n\n   Currently, if the swap_reader_page() of a remote buffer fails, it\n   triggers a WARN_ON_ONCE() and continues normally. Instead, have it\n   exit with an error and a pr_warn() print instead of a full WARNING.\n\n* tag \u0027trace-v7.3-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  ring-buffer: Stop remote reader update when page swap fails\n  tracing: Fix retry exhaustion in simple ring buffer reader swap\n  tracing/user_events: Clear copied tracing state before fork duplication\n  samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify\n  samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify\n  eventfs: Initialize ei-\u003echildren and ei-\u003elist in init_ei()\n  tracing: Fix use-after-free in trace_pipe read on sub-buffer order change\n  tracing: Fix crash passing ERR_PTR to kthread_stop()\n  tracing: Fix use-after-free with same-name named triggers\n  tracing: Fix logged instance name on creation failure\n"
    },
    {
      "commit": "1a89abc009cb5035d0cb4e5ba48d32b94f30e8e4",
      "tree": "1d443a8a35c356b42e9f3f035f908c36b682ef56",
      "parents": [
        "1039bffd6ae9c75b42b7d148d6c1106134107b66",
        "bb3b2cfeb206f5b10b859e134651b54120e3f530"
      ],
      "author": {
        "name": "Russell King (Oracle)",
        "email": "rmk+kernel@armlinux.org.uk",
        "time": "Wed Aug 05 17:08:50 2026 +0100"
      },
      "committer": {
        "name": "Russell King",
        "email": "rmk+kernel@armlinux.org.uk",
        "time": "Sun Aug 30 15:05:54 2026 +0100"
      },
      "message": "Merge branches \u0027fixes\u0027 and \u0027misc\u0027 into for-linus\n"
    },
    {
      "commit": "ef6a1dca8de41a408019310649e6d1b7b21ac4bc",
      "tree": "2621d06098801b297805a40f45d1f9221b0a3818",
      "parents": [
        "f83b8a58695cbf419beaa3f63b9d3e264792d8ea"
      ],
      "author": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 14:36:11 2026 +0200"
      },
      "committer": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 14:36:11 2026 +0200"
      },
      "message": "coccinelle: ifnulldev_put: update error message\n\nUpdate the report and org mode messages to reflect the new\nfunction names.\n\nSigned-off-by: Julia Lawall \u003cJulia.Lawall@inria.fr\u003e\n"
    },
    {
      "commit": "f83b8a58695cbf419beaa3f63b9d3e264792d8ea",
      "tree": "f294ec57e7c66f0204ef02095dd9a79055f23c91",
      "parents": [
        "5264281879ef19b68f61846a7455a627f10b92e8"
      ],
      "author": {
        "name": "Sang-Heon Jeon",
        "email": "ekffu200098@gmail.com",
        "time": "Mon Aug 24 01:18:19 2026 +0900"
      },
      "committer": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 14:34:22 2026 +0200"
      },
      "message": "coccinelle: ifnulldev_put: update outdated helper names\n\ndev_put_track() and dev_hold_track() were renamed to netdev_put() and\nnetdev_hold() by commit d62607c3fe45 (\"net: rename reference+tracking\nhelpers\").\n\nSo update the names.\n\nSigned-off-by: Sang-Heon Jeon \u003cekffu200098@gmail.com\u003e\nSigned-off-by: Julia Lawall \u003cJulia.Lawall@inria.fr\u003e\n"
    },
    {
      "commit": "5264281879ef19b68f61846a7455a627f10b92e8",
      "tree": "312656fee0a536d44f7b7ec961485cef3170db6a",
      "parents": [
        "3beb6e620fae118f1dc1092b08b2c82b4e762b8a"
      ],
      "author": {
        "name": "Sang-Heon Jeon",
        "email": "ekffu200098@gmail.com",
        "time": "Mon Aug 24 01:18:18 2026 +0900"
      },
      "committer": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 14:17:25 2026 +0200"
      },
      "message": "coccinelle: atomic_as_refcounter: drop atomic_long_dec_and_lock\n\natomic_long_dec_and_lock() has never existed. So drop it from the rules.\n\nNo functional change.\n\nSigned-off-by: Sang-Heon Jeon \u003cekffu200098@gmail.com\u003e\nSigned-off-by: Julia Lawall \u003cJulia.Lawall@inria.fr\u003e\n"
    },
    {
      "commit": "3beb6e620fae118f1dc1092b08b2c82b4e762b8a",
      "tree": "94df61108e280d7745c22eeffc83b2eca8f2a790",
      "parents": [
        "729eb52aa17f480a14ec0e7df363deabd41e57a3"
      ],
      "author": {
        "name": "Sang-Heon Jeon",
        "email": "ekffu200098@gmail.com",
        "time": "Mon Aug 24 01:18:17 2026 +0900"
      },
      "committer": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 14:09:27 2026 +0200"
      },
      "message": "coccinelle: kfree_mismatch: drop vmalloc_exec\n\nvmalloc_exec() was removed by commit 7a0e27b2a0ce (\"mm: remove\nvmalloc_exec\").\n\nSo drop it from the rules.\n\nNo functional change.\n\nSigned-off-by: Sang-Heon Jeon \u003cekffu200098@gmail.com\u003e\nSigned-off-by: Julia Lawall \u003cJulia.Lawall@inria.fr\u003e\n"
    },
    {
      "commit": "729eb52aa17f480a14ec0e7df363deabd41e57a3",
      "tree": "2560f906f438453d358fb6af30157b1365678c3c",
      "parents": [
        "0319b42e1e28b845a3092082fa1e1ff9043f833e"
      ],
      "author": {
        "name": "Sang-Heon Jeon",
        "email": "ekffu200098@gmail.com",
        "time": "Mon Aug 24 01:18:16 2026 +0900"
      },
      "committer": {
        "name": "Julia Lawall",
        "email": "Julia.Lawall@inria.fr",
        "time": "Sun Aug 30 11:19:01 2026 +0200"
      },
      "message": "coccinelle: pool_zalloc-simple: drop the pci_pool_alloc rules\n\npci_pool_alloc() and pci_pool_zalloc() were removed by commit\n88dee3b0efe4 (\"PCI: Remove unused pci_pool wrappers\").\n\nSo drop the pci_pool_alloc rules.\n\nNo functional change.\n\nSigned-off-by: Sang-Heon Jeon \u003cekffu200098@gmail.com\u003e\nSigned-off-by: Julia Lawall \u003cJulia.Lawall@inria.fr\u003e\n"
    },
    {
      "commit": "08dbfad3f5040f5bdb6c529da20d6d4e81fefd72",
      "tree": "94767b4d009979fd40f7c1deab59bb578c88529b",
      "parents": [
        "cf72cbb39da84b6f02f90c07f33b102fc10b16f0",
        "12e67eb89eb2b9516685c744d3f7de0a2d1bd701"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 29 11:55:36 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Aug 29 11:55:36 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi\n\nPull more SCSI updates from Martin Petersen:\n \"Remaining updates for the 7.3 merge window. The only core change is\n  enabling context analysis for the SCSI layer and UFS.\n\n  The remaining changes are either bug fixes or hardening\"\n\n* tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi: (26 commits)\n  scsi: snic: Fix SCSI host leak on workqueue allocation failure\n  scsi: MAINTAINERS: Update my email address\n  scsi: MAINTAINERS: Leave the cumana_1 and oak drivers to the RISCPC maintainers\n  scsi: leapraid: Standardize NCQ priority sysfs attributes\n  scsi: leapraid: Serialize firmware log mmap with teardown\n  scsi: leapraid: Balance host references for firmware log VMAs\n  scsi: lpfc: Remove unnnecessary NULL check\n  scsi: qla2xxx: Fix an loop timeout test\n  scsi: qla2xxx: Fix an error code in qla_get_tmf()\n  scsi: ibmvfc: Fix use of uninitialized rport in ibmvfc_do_work()\n  scsi: core: Enable context analysis for hosts.o\n  scsi: lpfc: Replace strlcat() with sysfs_emit_at() in the sysfs show functions\n  scsi: lpfc: Replace strlcat() with seq_buf in the debugfs dump helpers\n  scsi: lpfc: Replace strlcat() with seq_buf in lpfc_rx_monitor_report()\n  scsi: lpfc: Replace strlcat() with scnprintf() in lpfc_vport_symbolic_node_name()\n  scsi: lpfc: Replace strlcat() with seq_buf in lpfc_info()\n  scsi: core: Enable context analysis\n  scsi: core: Protect host state changes with the host lock\n  scsi: core: Add lock context annotations\n  scsi: core: Pass the SCSI host pointer directly to scanning functions\n  ...\n"
    },
    {
      "commit": "78004e9a87f240df03e2f73120d291763c32e0a7",
      "tree": "137c22dd795222931b9d2bf2501d37cd766741aa",
      "parents": [
        "6620f5e8c11c4f7e41222a86f5c97150cc5f84a5"
      ],
      "author": {
        "name": "Ali Ahmet Memis",
        "email": "ali@iusegentoo.com",
        "time": "Fri Aug 21 01:45:27 2026 +0000"
      },
      "committer": {
        "name": "Stafford Horne",
        "email": "shorne@gmail.com",
        "time": "Sat Aug 29 07:32:26 2026 +0100"
      },
      "message": "openrisc: fix arbitrary kernel memory access via or1k_atomic syscall\n\nsys_or1k_atomic() (syscall 244 in the \"or1k\" ABI) takes two user\npointers, v1 and v2, and swaps the words they point to in hand-written\nassembly.\n\n    l.lwz   r29,0(r4)\n    l.lwz   r27,0(r5)\n    l.sw    0(r4),r27\n    l.sw    0(r5),r29\n\nThe pointers are not checked with access_ok(). The four memory\naccesses also have no exception table entries.\n\nA caller passes a kernel address as either pointer, and the syscall\nreads from and writes to it directly.\n\nThis gives an unprivileged process a kernel read/write primitive. It\noverwrites kernel data such as the sys_call_table, gaining code\nexecution in kernel context.\n\nCheck both pointers before entering the critical section. Add fixups\nfor the four memory accesses so faults on valid but unmapped user\naddresses return -EFAULT.\n\n[shorne@gmail.com: fix comment style]\nFixes: 9d02a4283e9c (\"OpenRISC: Boot code\")\nCc: stable@vger.kernel.org\nSigned-off-by: Ali Ahmet Memis \u003cali@iusegentoo.com\u003e\nSigned-off-by: Stafford Horne \u003cshorne@gmail.com\u003e\n"
    },
    {
      "commit": "cf72cbb39da84b6f02f90c07f33b102fc10b16f0",
      "tree": "b2277e9778654a59680b9d8799c778a84732dca9",
      "parents": [
        "a99d741df7372f2175677673d78a6335f3e0706f",
        "2cf20c4e0f72d523b8673053e7120d092ff1f074"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:51:14 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:51:14 2026 -0700"
      },
      "message": "Merge tag \u0027io_uring-7.3-20260828\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n\nPull io_uring fixes from Jens Axboe:\n \"A few smaller fixes for io_uring that should go into the 7.3-rc1\n  kernel, all three headed to stable as well. This contains:\n\n   - A few fixes around cancellation and teardown for waitid\n\n   - Cap the user size for the query interface copy-out\"\n\n* tag \u0027io_uring-7.3-20260828\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:\n  io_uring/waitid: avoid siginfo copy during ring teardown\n  io_uring/waitid: honor task_work cancellation\n  io_uring/query: cap user size passed to copy_struct_to_user\n"
    },
    {
      "commit": "a99d741df7372f2175677673d78a6335f3e0706f",
      "tree": "88ae56988eeca18429599a14503eed2068bd09aa",
      "parents": [
        "4cc4cc367fd5c37ddef3279038bccbf152ef68d9",
        "a8b02aa825803e6c5b6b27340f583900afa0861d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:37:55 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:37:55 2026 -0700"
      },
      "message": "Merge tag \u0027drm-next-2026-08-29\u0027 of https://gitlab.freedesktop.org/drm/kernel\n\nPull more drm updates from Dave Airlie:\n \"As mentioned last week, an msm pull request fell down the side of the\n  couch or whatever the email equivalent of that is. This has the msm\n  next stuff + the usual fixes for amd/intel.\n\n  core:\n   - use drm_warn instead of warn\n\n  msm:\n   - Bindings:\n      - Added Shikra support\n      - Document a840, a704, a722\n   - Core:\n      - Use drm_client buffers for fbdev emulation\n      - teardown fixes\n      - ARM32 DMA fixup\n      - Remove objects from evict list when re-validated\n      - Bunch of corner case and error path fixes\n   - DPU:\n      - Dropped dev_pm_opp_set_rate(0) preventing burnout\n      - Fixed SSPP offsets of Kaanapali\n   - DP:\n      - Dropped dev_pm_opp_set_rate(0) preventing burnout\n      - Cleaned up core code in preparation for MST support\n      - Fixed prepare() to let Pipewire continue in case of the unplugged cable\n   - GPU:\n      - Add support for a704\n      - Add support for a722\n   - HDMI:\n      - Simplifed register access\n\n  amdgpu:\n   - eGPU fixes\n   - Runtime PM fix\n   - UserQ fixes\n   - Backlight fix\n   - Discovery sysfs fix\n   - Reset handling fixes\n   - Buffer func handling fix for xgmi\n   - VCN boundary check fix\n   - DC lut handling fixes\n   - MES fixes\n   - UVD fix\n   - VCE 3 fix\n   - Enforce isolation fix\n   - HPD fix for VGA/LVDS\n   - DML fix\n   - DCN 6 fixes\n   - DC gpu reset fix\n\n  amdkfd:\n   - Fix return value\n   - CU occupancy for GFX 11\n   - CU occupancy for GFX 12/12.1\n   - Queue bounds checking fix\n   - SVM fixes\n   - CRIU bounds checking fix\n\n  radeon:\n   - iMac display fix\n\n  xe:\n   - error message cleanups\n   - i2c global register definitions as dependency for xe/i2c fixes\n   - Media workardound\n   - Add CCS to gt_idle debugfs print\n   - Page fault related fix\n   - i2c related fixes\n   - System Controller mailbox bit fix\"\n\n* tag \u0027drm-next-2026-08-29\u0027 of https://gitlab.freedesktop.org/drm/kernel: (121 commits)\n  drm/xe/sysctrl: Read mailbox phase bit from hardware\n  drm/xe/i2c: Keep the i2c controller always enabled\n  drm/xe/i2c: Fix the interrupt handling\n  i2c: designware: Global register definitions\n  drm/xe: Reject page faults from non-fault-mode scratch VMs\n  drm/xe/xe_gt_idle: Add CCS to the powergating info print\n  drm/xe: Do not apply WA 14025883347 to media 3503\n  drm/amd/display: fix dc_lock leak on GPU reset error paths\n  drm/amd/display: Fix redundant GPUVMEnable checks in dcn6 flip schedule\n  drm/amd/display: Fix wrong bytes-per-pixel value for dml2_422_packed_10\n  drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore\n  drm/amdgpu/userq: fix lock missing for userq fence error set\n  drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram\n  drm/amdkfd: Fix error path at svm_migrate_copy_to_ram\n  drm/amd/display: Log details when failing to register HPD IRQ\n  drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE\n  drm/amdgpu: clamp the isolation index for rings outside a partition\n  drm/amdkfd: Reject zero-sized AQL queue allocations after size halving\n  drm/amdgpu: Fix VCE 3 ring align_mask\n  drm/kfd: Add CU occupancy support to GFX12.1\n  ...\n"
    },
    {
      "commit": "4cc4cc367fd5c37ddef3279038bccbf152ef68d9",
      "tree": "ba53ffa6138c552ead9384d59d18be2f4e9ca49a",
      "parents": [
        "548e7bcd0c5460ddcbca9600cea603ebeebf4da7",
        "05ec76cfbce653e07cec19b9b8b20e33449d5d87"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:32:12 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 16:32:12 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus-7.3-1\u0027 of https://github.com/cminyard/linux-ipmi\n\nPull ipmi updates from Corey Minyard:\n \"Several cleanup on error fixes and a missing RCU wait and proper\n  validation on a received message in one place.\n\n  The biggest change is the initialization of the driver can be done\n  asynchronously on a work queue. That saves significant boot time\"\n\n* tag \u0027for-linus-7.3-1\u0027 of https://github.com/cminyard/linux-ipmi:\n  ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()\n  ipmi:msghandler: Cancel work cleanly on an error\n  ipmi:si: Add async init to ipmi_si\n  char: ipmi: use named initializers for acpi_device_id\n  ipmi: Fix leak in __ipmi_bmc_register\n  ipmi: Remove all sysfs files on registration failure\n  ipmi: si: Fix NULL pointer dereference after failed registration\n  ipmi: ipmb: validate write message length\n"
    },
    {
      "commit": "548e7bcd0c5460ddcbca9600cea603ebeebf4da7",
      "tree": "f6c9495617263ee073c84c9735afa173a3686a3b",
      "parents": [
        "ce727a090be04dc7c51edd5c0da2a41d2fb6e106",
        "8fdf946445732c2bcd685abc8bd0e509d2ebc158"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 11:51:05 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 11:51:05 2026 -0700"
      },
      "message": "Merge tag \u0027ceph-for-7.3-rc1\u0027 of https://github.com/ceph/ceph-client\n\nPull ceph updates from Ilya Dryomov:\n \"A wide variety of mostly CephFS fixes and cleanups, split between\n  changes that address edge cases (Sam, Xiubo, Matthew), efficiency\n  improvements (Max) and AI-assisted hardening (Michael, Jeremy).\n\n  One thing that stands out is Alex\u0027s change to how CephFS behaves in\n  NEARFULL scenarios: the long-standing \"make all writes synchronous\"\n  behavior has become opt-in. It was always somewhat controversial and\n  doesn\u0027t make much sense for modern deployments; the new default is to\n  continue normal operation (i.e. buffer writes as MDS allows, etc). The\n  behavior in case the cluster reaches any FULL state remains the same\n  as before\"\n\n* tag \u0027ceph-for-7.3-rc1\u0027 of https://github.com/ceph/ceph-client: (32 commits)\n  ceph: force a cap message when a deferred revoke can\u0027t be acked immediately\n  libceph: reject buckets with mismatched CRUSH ids\n  ceph: reject export_targets ranks \u003e\u003d CEPH_MAX_MDS in mdsmap decode\n  ceph: fix leaked inode reference on writeback abort at umount\n  libceph: remove ceph_put_page_vector()\n  libceph: validate banner payload length\n  ceph: make nearfull sync writes opt-in\n  ceph: do not repeat ceph_trim_dentries() if no progress possible\n  ceph: drop mdsc-\u003emutex before decoding the MDS reply\n  ceph: fix UAF in check_new_map() on session freed during unlock\n  ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock\n  ceph: pass inode pointer around instead of reloading it\n  ceph: mark cap remove with RB_CLEAR_NODE() instead of setting ci\u003dNULL\n  ceph: add helper function ceph_cap_is_removed()\n  ceph: make __ceph_remove_cap() static\n  ceph: cap delegated inode count in ceph_parse_deleg_inos()\n  ceph: bound num_export_targets array for mds info v2/v3\n  ceph: bound MDSCapAuth path and fs_name decode in handle_session()\n  ceph: bound xattr value length in __build_xattrs()\n  ceph: bound copied dentry name length in NFS export get_name\n  ...\n"
    },
    {
      "commit": "ce727a090be04dc7c51edd5c0da2a41d2fb6e106",
      "tree": "5c7c741e397b38eb198ef2a4b2c518dce68016eb",
      "parents": [
        "115bd364ab20b2dbef22824ec80d15901847dbe2",
        "a5e0055eac837a1168c781653943d4a0d9920af3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:59:07 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:59:07 2026 -0700"
      },
      "message": "Merge tag \u0027ubifs-for-linus-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rw/ubifs\n\nPull UBI and UBIFS updates from Richard Weinberger:\n \"UBI:\n   - Support for a per-device wear-leveling threshold\n   - Various fixes and cleanups of error paths\n   - Correctly preserve torture flag up wear-leveling\n\n  UBIFS:\n   - Various fixes and cleanups of error paths and kernel-doc\"\n\n* tag \u0027ubifs-for-linus-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rw/ubifs:\n  UBI: support per-device wear-leveling threshold\n  UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC\n  mtd: ubi: Release device reference on busy detach\n  ubi: Fix rollback for explicit UBI device numbers\n  ubifs: fix out-of-bounds read in signature length check\n  UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs\n  UBI: Preserve torture flag when rescheduling failed erasures\n  ubifs: ubifs.h: clean up kernel-doc comments\n  ubifs: key.h: use correct function parameter name\n  ubifs: debug.h: fix kernel-doc struct prototypes\n"
    },
    {
      "commit": "115bd364ab20b2dbef22824ec80d15901847dbe2",
      "tree": "dc4e57a6e9047e8efc745b9b737363015ae49099",
      "parents": [
        "c20313e98b04ce543936431b6122dd639d3a8346",
        "c966d29e01bbf829f8bb4a39a49811c56cdb49c3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:48:48 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:48:48 2026 -0700"
      },
      "message": "Merge tag \u0027f2fs-for-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs\n\nPull f2fs updates from Jaegeuk Kim:\n \"In this round, key enhancements focus on reducing inode management\n  memory overhead, introducing resizable tail sections with unified\n  pinned allocation, and boosting I/O throughput via parallel\n  multi-device flushes and asynchronous f2fs_write_end_io() execution.\n  We also add dynamic device alias reservations to allow on-the-fly\n  space donation from user partitions.\n\n  Alongside these features, critical bug fixes resolve folio race\n  conditions, lingering dirty flags, dentry and block counter leaks, and\n  potential deadloops in f2fs_fsync_node_pages(). Additional stability\n  patches address error-path handling across symlink, sync, and\n  rename/unlink operations, prevent pinned file fragmentation, and\n  correct segment migration and free section accounting in\n  free_segment_range.\n\n  Enhancements:\n   - reduce memory footprint of ino management\n   - support dynamic reserve/release for device aliasing\n   - issue multi-device flushes in parallel\n   - add a way to run f2fs_write_end_io() asynchronously\n   - support resizable tail section and unify pinned allocation\n\n  Bug fixes:\n   - fix to pass folio-\u003eindex to f2fs_sanity_check_node_footer()\n   - fix folio_nr_pages() race after put in large folio invalidate\n   - fix to clear dirty flag on folio in error path\n   - accurately adjust free_sections during free_segment_range\n   - fix to avoid potential deadloop in f2fs_fsync_node_pages()\n   - fix the error path in symlink, device alias in rename/unlink,\n     f2fs_sync_fs\n   - fix to migrate all curseg types during free_segment_range\n   - fix to avoid pinfile fragment on fragment:{block, segment} mode\n   - fix valid block count leak on data block allocation failure\n   - fix dentry folio leak in find_in_level\n   - reject overlapping move range after len expansion\n   - fix some bugs related to file pinning, GC functions, i_size\n\n  And, the series includes a number of minor bug fixes\"\n\n* tag \u0027f2fs-for-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs: (51 commits)\n  f2fs: support resizable tail section and unify pinned allocation\n  f2fs: don\u0027t leave the hashed inode while it\u0027s unlinked\n  f2fs: accurately adjust free_sections during free_segment_range\n  f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()\n  f2fs: use adjusted write range after f2fs_write_checks()\n  f2fs: fix to propagate error from f2fs_sync_fs()\n  f2fs: return symlink writeback errors\n  f2fs: fix error handling on device alias check in rename and unlink\n  f2fs: fix to reset all pinned status during fggc\n  f2fs: use f2fs_{down, up}_(read, write}_trace() for nat_tree_lock\n  f2fs: reduce memory footprint of ino management\n  f2fs: fix i_size when pinned fallocate partially fails\n  f2fs: fix to migrate all curseg types during free_segment_range\n  f2fs: avoid setting SBI_NEED_FSCK on transient resize failure\n  f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode\n  f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk}\n  f2fs: fix to shrink gc_lock coverage in f2fs_gc_range()\n  f2fs: fix to reclaim space in f2fs_allocate_pinning_section()\n  f2fs: unify add/remove ino entry API for all ino types\n  f2fs: fix to zero post-EOF data when extending file size\n  ...\n"
    },
    {
      "commit": "c20313e98b04ce543936431b6122dd639d3a8346",
      "tree": "072bec938a695bfbb143627045539dfa706b7548",
      "parents": [
        "275bc4eedf2c6081200998954efcb5eb90413a41",
        "c4a0927f535f779700d5ccda8182c2db01e9d551"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:01:02 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 10:01:02 2026 -0700"
      },
      "message": "Merge tag \u0027sound-fix-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n\nPull sound fixes from Takashi Iwai:\n \"A collection of various small fixes since the last PR. Most changes\n  are device-specific fixes, while there are a few fixes addressing the\n  issues reported recently by fuzzers.\n\n  Here are highlights:\n\n  ALSA Core:\n   - Prevent adding invalid kcontrols to the LED layer\n   - Workaround for a false-positive mutex lockdep warning in rawmidi\n\n  USB-audio:\n   - Relaxed the sticky mixer behavior check that caused regressions\n   - Fix an OOB write in Novation MIDI output\n   - Proper cleanup after system-resume errors\n   - Quirk updates for M-Audio Venom, Audient iD14 MkI, Logitech PRO X\n     Wireless, SMSL USB DAC, and Creative Sound Blaster Play! 3\n\n  HD-audio:\n   - Conexant headset plugin fixes\n   - Quirk additions and fixes for HP Laptop 15, Lenovo IdeaPad Slim 3,\n     TongFang XxAF5xxx, Lenovo Legion Pro 7, and Lenovo Yoga Pro 9\n\n  ASoC:\n   - DAPM: Fix off-by-one check on the second enum channel\n   - Tegra: Fix and sort register defaults\n   - AMD quirk updates for ASUS FA401EA, HP OmniBook X Flip 16,\n     HVY-WXX9/M1060, Alienware m18 R1, and MSI Thin A15 B7UC\n   - Fixes Qualcomm TDM handling\n   - Fix double put_device() on SoundWire\n   - Codec fixes for rt766, tac5xx2, rt712, tas2783, and max98926\n\n  Misc:\n   - Fix card leak on probe error on ice1712 driver\n   - Hardening for legacy aoa, mtpav and pcxhr drivers\"\n\n* tag \u0027sound-fix-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound: (53 commits)\n  ALSA: control: Don\u0027t add invalid kcontrols to LED layer\n  ASoC: amd: acp-config: change quirks to cover all ASUS FA401EA variants\n  ALSA: hda/conexant: Always enable the headset-mic pin on plugin\n  ASoC: dapm: Fix off-by-one check on the second enum channel\n  ASoC: amd: acp-config: force SoundWire probe on HP OmniBook X Flip 16\n  ASoC: amd: acp3x-es83xx: Add HVY-WXX9/M1060 DMI quirk\n  ASoC: amd: acp-config: Add HVY-WXX9/M1060 DMI quirk\n  ASoC: soc-generic-dmaengine: Fix DMA channel request warning\n  ALSA: rawmidi: Another workaround for false-positive mutex lockdep warning\n  ASoC: amd: yc: Add DMI entry for Alienware m18 R1 AMD\n  ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC\n  ALSA: hda/realtek: Fix speaker mute LED for HP Laptop 15-fd0039nt\n  ALSA: usb-audio: Complete cleanup after system-resume errors\n  ALSA: hda/realtek: Add quirk for Lenovo IdeaPad Slim 3 15ABR8\n  ALSA: aoa: i2sbus: Check IRQ before requesting it\n  ALSA: usb-audio: Skip mixer creation on M-Audio Venom\n  ALSA: usb-audio: Skip reading sample rate on M-Audio Venom\n  ASoC: rt766: add RT766/RT767 VA1 device IDs\n  ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx\n  ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()\n  ...\n"
    },
    {
      "commit": "275bc4eedf2c6081200998954efcb5eb90413a41",
      "tree": "f8f0b71a819301d7283fff7cc21f1f9e44170d6f",
      "parents": [
        "afe0579334f622c803f2864f22c04c20c320bd80",
        "afce9701d6423a63194a349d2f1e34c50ce76482"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:53:43 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:53:43 2026 -0700"
      },
      "message": "Merge tag \u0027rtc-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/abelloni/linux\n\nPull RTC updates from Alexandre Belloni:\n \"The RZN1 driver got a fairly comprehensive cleanup. More DT binding\n  are converted to DT schema, leaving only 5 remaining files to convert.\n\n  Subsystem:\n   - patchwork project is moving to kernel.org\n   - fully initialize clk_init_data\n   - add missing MODULE_DEVICE_TABLE()\n   - DT bindings conversions to DT schema\n\n  Drivers:\n   - ds1307: fix WADA bit for alarms on RX8130\n   - rzn1: add support for RZ/T2H and RZ/N2H, many fixes\"\n\n* tag \u0027rtc-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/abelloni/linux: (42 commits)\n  MAINTAINERS: update rtc subsystem patchwork location\n  rtc: msc313: Select by default on MSTARV7\n  rtc: microcrystal: Make sure clk_init_data is fully initialized\n  rtc: philips: Make sure clk_init_data is fully initialized\n  rtc: nct3018y: Make sure clk_init_data is fully initialized\n  rtc: m41t80: Make sure clk_init_data is fully initialized\n  rtc: hym8563: Make sure clk_init_data is fully initialized\n  rtc: rzn1: Add support for Renesas RZ/T2H and RZ/N2H SoCs\n  rtc: rzn1: Drop trailing comma from OF match table sentinel\n  rtc: rzn1: Add OF match data to gate SUBU register access\n  rtc: rzn1: use FIELD_PREP/FIELD_GET and GENMASK for register access\n  rtc: rzn1: Consistently use dev_err_probe()\n  rtc: rzn1: Use temporary variable for struct device\n  rtc: rzn1: Dynamically calculate synchronization delay based on clock rate\n  rtc: rzn1: Replace remove callback with devm_add_action_or_reset()\n  rtc: rzn1: Use pm_runtime_put_sync()\n  rtc: Kconfig: Broaden RTC_DRV_RZN1 dependency to ARCH_RENESAS\n  rtc: rzn1: Fix malformed MODULE_AUTHOR string\n  rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers\n  rtc: rzn1: Fix alarm range check truncation on 32-bit systems\n  ...\n"
    },
    {
      "commit": "afe0579334f622c803f2864f22c04c20c320bd80",
      "tree": "60294d63366c42dedf06ab285f6f21c5b283bc3f",
      "parents": [
        "9df08cdd33a70ee1310523065fc4e3f161f6242e",
        "55ba91d4c54ab31ee8387bae40e799de467f8269"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:36:27 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:36:27 2026 -0700"
      },
      "message": "Merge tag \u0027for-next-tpm-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd\n\nPull TPM updates from Jarkko Sakkinen:\n \"The bulk of this is Ross Philipson\u0027s TPM enablement for Trenchboot.\n  That exposes TPM constants, and decouple and improve robustness of\n  tpm_buf a bit in order to implement a minimal early TPM driver.\n\n  Early boot code will call either SKINIT on AMD or GETSEC[SENTER] on\n  Intel before jumping into kernel\u0027s entry point. They re-initalize TPM\n  PCRs but leave up to the early boot code measure initrd, boot_params\n  and Trenchboot associated metadata.\n\n  The motivation here is just that we would want in future iterations of\n  the series put our full focus to the x86 part of the review, and call\n  it a day as per TPM changes. Further, even if Trenchboot turned out to\n  be empty lottery the worst possible outcome for TPM driver is that\n  things get cleaned up a bit\"\n\n* tag \u0027for-next-tpm-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:\n  tpm-buf: Add TPM buffer support header for standalone reuse\n  tpm-buf: Memory-safe allocations\n  tpm-buf: Remove chip parameter from tpm_buf_append_handle()\n  tpm-buf: Merge TPM_BUF_BOUNDARY_ERROR and TPM_BUF_OVERFLOW\n  tpm: Remove main TPM header from TPM event log header\n  tpm: Move platform specific definitions to the new PTP header\n  tpm: Move TPM common base definitions to the command header\n  tpm: Move TPM2 specific definitions to the command header\n  tpm: Move TPM1 specific definitions to the command header\n  tpm: Initial step to reorganize TPM public headers\n  tpm: st33zp24: Validate locality read result\n  tpm: st33zp24: Return zero on status read failure\n  tpm: tpm_tis_spi: fix nodef CR50 tpm_tis_spi_resume is null\n  tpm: atmel: depend on X86\n  tpm: Remove redundant dev_err()\n  tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout\n"
    },
    {
      "commit": "9df08cdd33a70ee1310523065fc4e3f161f6242e",
      "tree": "4461f95d57f819fec8483a688403de6f49fcf64a",
      "parents": [
        "344be13211d0fceb791a7da70ef810ad13340fe0",
        "ee440d4fc0d2f15894ab1f64c474a3adbc858880"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:28:40 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:28:40 2026 -0700"
      },
      "message": "Merge tag \u0027v7.3-p2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6\n\nPull crypto fix from Herbert Xu:\n \"Fix a memory allocation overrun in crypto acomp\"\n\n* tag \u0027v7.3-p2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6:\n  crypto: acomp - allocate async request context when cloning\n"
    },
    {
      "commit": "344be13211d0fceb791a7da70ef810ad13340fe0",
      "tree": "c2eef88aacb8c70c7efa0c49fc21dfab040383c8",
      "parents": [
        "9d607ae0f7d629dc068aed5f498e24d3e9875ef1",
        "3b446d169a93e6abae9a93535369fa18bbcbefd9"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:09:01 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:09:01 2026 -0700"
      },
      "message": "Merge tag \u0027acpi-7.3-rc1-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n\nPull ACPI support fix from Rafael Wysocki:\n \"Revert an incomplete recent commit that may cause ACPI device power\n  management to stop working\"\n\n* tag \u0027acpi-7.3-rc1-3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:\n  Revert \"ACPI: scan: Defer device power initialization\"\n"
    },
    {
      "commit": "9d607ae0f7d629dc068aed5f498e24d3e9875ef1",
      "tree": "a66740d5e5fa38735a640f41b2e6d30ce9a43a60",
      "parents": [
        "72ecc30d607f6c8ef8ac0d7b88b0c176a7409367",
        "2bd533739234d79b74afabfece1abfe9c6d52c83"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:02:04 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 09:02:04 2026 -0700"
      },
      "message": "Merge tag \u0027arm64-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux\n\nPull arm64 fixes from Will Deacon:\n \"A mixture of ptdump, compat and MTE fixes that came in during the\n  merge window:\n\n   - Fix address handling of final memory region in ptdump\n\n   - Fix emulation of decrementing load/store multiple from 32-bit task\n\n   - Fix SCTLR context-switching for store-only MTE mode\n\n   - Fix numerous issues in MTE selftests\"\n\n* tag \u0027arm64-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:\n  selftests/arm64: Add MTE test config fragment\n  selftests/arm64: Fix MTE prctl TAP plan\n  selftests/arm64: Treat KSM merge_across_nodes as optional\n  selftests/arm64: Print missing MTE TAP headers\n  arm64: compat: Fix decrementing LDM/STM alignment emulation\n  arm64: process: Fix context switching MTE store-only tag check\n  KVM: arm64: ptdump: Flush the last region\n  arm64: ptdump: Make note_page_flush() range aware\n"
    },
    {
      "commit": "72ecc30d607f6c8ef8ac0d7b88b0c176a7409367",
      "tree": "239bc2903867e89c68f7be04a519ad54cfd7a082",
      "parents": [
        "874b43b9f3c704f24f0bdcc347b2e596ad3228ec",
        "eb049bdbf2b98d103d93daef44a5e1a0164d01eb"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 08:55:47 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 08:55:47 2026 -0700"
      },
      "message": "Merge tag \u0027xtensa-20260828\u0027 of https://github.com/jcmvbkbc/linux-xtensa\n\nPull Xtensa updates from Max Filippov:\n\n - use strnlen() to improve iss_console_write()\n\n - remove unused function setup_profiling_timer()\n\n - fix CONFIG_XTENSA_CALIBRATE_CCOUNT macro name in comment\n\n* tag \u0027xtensa-20260828\u0027 of https://github.com/jcmvbkbc/linux-xtensa:\n  xtensa: remove unused setup_profiling_timer function\n  xtensa: correct CONFIG_XTENSA_CALIBRATE_CCOUNT macro name in comment\n  tty: xtensa/iss: use strnlen to improve iss_console_write\n"
    },
    {
      "commit": "874b43b9f3c704f24f0bdcc347b2e596ad3228ec",
      "tree": "820b407a03c7004c94c3b353ccc7eb4060146f64",
      "parents": [
        "1b78070aaef63512688aebfbc82365ef9d6660f1",
        "de0dab22cbf6943d0f12f3b1e2eb1bbdd807f039"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 08:44:36 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Aug 28 08:44:36 2026 -0700"
      },
      "message": "Merge tag \u0027m68knommu-for-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gerg/m68knommu\n\nPull m68knommu updates from Greg Ungerer:\n \"This includes a couple more new defconfigs to improve test build\n  coverage, changes to use the more correct linux/gpio/legacy.h and\n  platform setup for the reset device of the ColdFire 5441x SoC\n  hardware.\n\n   - new defconfigs for 2 more ColdFire boards\n\n   - change to use linux/gpio/legacy.h\n\n   - add platform setup for reset device of the 5441x SoC boards\"\n\n* tag \u0027m68knommu-for-v7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gerg/m68knommu:\n  m68k: coldfire/5441x: register mcf-rcm-reset platform device\n  m68k/coldfire: replace linux/gpio.h inclusions\n  m68k: defconfig: add config for M5282EVB board\n  m68k: defconfig: add config for M52358EVB board\n"
    },
    {
      "commit": "a8b02aa825803e6c5b6b27340f583900afa0861d",
      "tree": "36d1458d1bd4ff48d15db459b5da1c3f13594210",
      "parents": [
        "1dd31281a6e3f370914f99b7cf6cccbc2c050ea3",
        "92a9eebd2a1f892fe482154d83f9f1626bc73d3b"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 28 13:27:51 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 28 13:31:33 2026 +1000"
      },
      "message": "Merge tag \u0027amd-drm-next-7.3-2026-08-27\u0027 of https://gitlab.freedesktop.org/agd5f/linux into drm-next\n\namd-drm-next-7.3-2026-08-27:\n\namdgpu:\n- MES fixes\n- Userq fixes\n- UVD fix\n- VCE 3 fix\n- Enforce isolation fix\n- HPD fix for VGA/LVDS\n- DML fix\n- DCN 6 fixes\n- DC gpu reset fix\n\namdkfd:\n- CU occupancy for GFX 11\n- CU occupancy for GFX 12/12.1\n- Queue bounds checking fix\n- SVM fixes\n- CRIU bounds checking fix\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Alex Deucher \u003calexander.deucher@amd.com\u003e\nLink: https://patch.msgid.link/20260827203610.3249084-1-alexander.deucher@amd.com\n"
    },
    {
      "commit": "1dd31281a6e3f370914f99b7cf6cccbc2c050ea3",
      "tree": "c20b0b4ca076abb893d4587f7a65e60b5c1e72c2",
      "parents": [
        "1ff8d3e3165fd077faa4259fd232bdddcd30249f",
        "a62212b35a214c2ff3bd1c785a440d7ad8205ec9"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 28 13:14:31 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Aug 28 13:14:52 2026 +1000"
      },
      "message": "Merge tag \u0027drm-xe-next-fixes-2026-08-27\u0027 of https://gitlab.freedesktop.org/drm/xe/kernel into drm-next\n\nCross-subsystem Changes:\n- i2c global register definitions as dependency for xe/i2c fixes. (Heikki)\n\nDriver Changes:\n- Media workardound (Daniele)\n- Add CCS to gt_idle debugfs print (Bala)\n- Page fault related fix (Arvind)\n- i2c related fixes (Heikki)\n- System Controller mailbox bit fix (Anoop)\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nLink: https://patch.msgid.link/apBrVgvZwIRIfuhR@intel.com\n"
    },
    {
      "commit": "5eab74874d11160725c42ab676ba97a797a362eb",
      "tree": "9834233e5bde5c0587aaa2ee57eb75420b40eb12",
      "parents": [
        "e0d3aed7b12cf37b74c7cc5265073d0263b49cde"
      ],
      "author": {
        "name": "Ivan Immanuel Shaji",
        "email": "ivanimmanuel1234@gmail.com",
        "time": "Tue Aug 25 12:52:50 2026 -0400"
      },
      "committer": {
        "name": "Steven Rostedt",
        "email": "rostedt@goodmis.org",
        "time": "Thu Aug 27 21:31:51 2026 -0400"
      },
      "message": "ring-buffer: Stop remote reader update when page swap fails\n\nThe remote swap_reader_page callback can return -EBUSY when the writer\nmoves the head before the remote catches it, particularly during an event\nstorm on a small buffer. __rb_get_reader_page_from_remote() currently\nwarns about that failure but continues with the unchanged reader ID and\nrearranges the local page list as though the swap succeeded.\n\nHandle the callback failure as a recoverable error. Report it with\npr_warn_ratelimited() and return NULL. Callers already handle a NULL reader\npage as a failed attempt. This avoids splicing the same page as both the\nprevious and new reader without flooding the log under contention.\n\nCc: stable@vger.kernel.org\nFixes: 2e67fabd8b77 (\"ring-buffer: Introduce ring-buffer remotes\")\nLink: https://patch.msgid.link/20260825-kernel-patch-1-v2-2-bb3461807a32@gmail.com\nAssisted-by: LLM sparse\nSigned-off-by: Ivan Immanuel Shaji \u003civanimmanuel1234@gmail.com\u003e\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\n"
    },
    {
      "commit": "e0d3aed7b12cf37b74c7cc5265073d0263b49cde",
      "tree": "a5b43543a712c3ab39facbbe3a4919b4692f006c",
      "parents": [
        "390f6bd8583d177029d9df4bea6667509e55a765"
      ],
      "author": {
        "name": "Ivan Immanuel Shaji",
        "email": "ivanimmanuel1234@gmail.com",
        "time": "Tue Aug 25 12:52:49 2026 -0400"
      },
      "committer": {
        "name": "Steven Rostedt",
        "email": "rostedt@goodmis.org",
        "time": "Thu Aug 27 21:31:41 2026 -0400"
      },
      "message": "tracing: Fix retry exhaustion in simple ring buffer reader swap\n\nsimple_ring_buffer_swap_reader_page() starts with retry set to 8 and\npost-decrements it only after a failed link replacement. On the final\nattempt, a successful replacement leaves retry at zero, while a failed\nreplacement leaves it at -1.\n\nThe current !retry test reverses both outcomes. It returns an error after\na successful final replacement, leaving the link update complete but the\nreader bookkeeping unfinished. After a failed final replacement, it\nfalls through and updates the head and reader pointers as though the\nreplacement succeeded, which can corrupt the ring.\n\nTreat only a negative counter as exhaustion and return the documented\n-EBUSY error.\n\nCc: stable@vger.kernel.org\nFixes: 34e5b958bdad (\"tracing: Introduce simple_ring_buffer\")\nLink: https://patch.msgid.link/20260825-kernel-patch-1-v2-1-bb3461807a32@gmail.com\nAssisted-by: LLM sparse\nReviewed-by: Vincent Donnefort \u003cvdonnefort@google.com\u003e\nSigned-off-by: Ivan Immanuel Shaji \u003civanimmanuel1234@gmail.com\u003e\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\n"
    },
    {
      "commit": "390f6bd8583d177029d9df4bea6667509e55a765",
      "tree": "5317be8482875dd24e4c04c99bdc7eb03bcda80d",
      "parents": [
        "6727b7618f49401acf373fa3ec5712e2ec52e5cf"
      ],
      "author": {
        "name": "Jérémy Jean",
        "email": "Jeremy.Jean@oss.cyber.gouv.fr",
        "time": "Thu Aug 27 18:43:22 2026 +0000"
      },
      "committer": {
        "name": "Steven Rostedt",
        "email": "rostedt@goodmis.org",
        "time": "Thu Aug 27 21:30:22 2026 -0400"
      },
      "message": "tracing/user_events: Clear copied tracing state before fork duplication\n\ndup_task_struct() copies user_event_mm from the parent into the child,\nwithout grabbing a reference to it. user_event_mm_dup() should\nreplace it, but it leaves that copied pointer unmodified if\nuser_event_mm_alloc() fails.\n\nWhen the child exits, user_event_mm_remove() decrements a reference\nthe child never owned, which ultimately frees user_event_mm, while\nthe parent still as a stale pointer to it. This creates a UAF, which\nKASAN reports as:\n\n    BUG: KASAN: slab-use-after-free in\n    current_user_event_mm+0x51/0x1d0 Write of size 4 at addr\n    ffff888005010d30 by task init/44\n\n    Call Trace:\n     \u003cTASK\u003e\n     kasan_report+0xce/0x100\n     kasan_check_range+0x10f/0x1e0\n     current_user_event_mm+0x51/0x1d0\n     user_events_ioctl+0x82e/0x15c0\n     __x64_sys_ioctl+0x139/0x1c0\n     do_syscall_64+0xce/0x450\n     entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n    Allocated by task 44:\n     __kasan_kmalloc+0x8f/0xa0\n     __kmalloc_cache_noprof+0x180/0x3a0\n     user_event_mm_alloc+0x3c/0x1f0\n     current_user_event_mm+0x88/0x1d0\n\n    Freed by task 42:\n     __kasan_slab_free+0x43/0x70\n     kfree+0x13a/0x390\n     process_one_work+0x696/0xf90\n     worker_thread+0x420/0xba0\n\nThe fix simply clears the copied pointer before any possible failure.\nIn case of failure, the child then has nothing to free.\n\nCc: stable@vger.kernel.org\nFixes: 7235759084a4 (\"tracing/user_events: Use remote writes for event enablement\")\nLink: https://patch.msgid.link/20260827184321.2964601-2-Jeremy.Jean@oss.cyber.gouv.fr\nAssisted-by: Codex:gpt-5\nSigned-off-by: Jérémy Jean \u003cJeremy.Jean@oss.cyber.gouv.fr\u003e\nReviewed-by: Bradley Morgan \u003cbrads@mainlining.org\u003e\nSigned-off-by: Steven Rostedt \u003crostedt@goodmis.org\u003e\n"
    },
    {
      "commit": "b15b548d52b43ba8ac4652bc2c7244a8dd1e9622",
      "tree": "0b605f892ce4086608fb2b5c3efa74365b7debaa",
      "parents": [
        "27c9445be86b1313746c46d659d3f823a5f7a218"
      ],
      "author": {
        "name": "Vasileios Almpanis",
        "email": "vasilisalmpanis@gmail.com",
        "time": "Wed Aug 12 11:14:48 2026 +0200"
      },
      "committer": {
        "name": "Andi Shyti",
        "email": "andi.shyti@kernel.org",
        "time": "Fri Aug 28 03:12:01 2026 +0200"
      },
      "message": "i2c: core: fix debugfs UAF on adapter removal\n\ni2c_del_adapter() frees the adapter\u0027s debugfs directory before it\nunregisters the adapter device, but the new_device sysfs attribute\nstays writable until device_del(). A write racing with removal still\nreaches i2c_device_probe(), which passes the freed adap-\u003edebugfs to\ndebugfs_create_dir() as the new client\u0027s parent:\n\n  BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430\n  Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090\n   lookup_noperm_common+0x407/0x430\n   simple_start_creating+0x9c/0x110\n   debugfs_start_creating+0xdb/0x1a0\n   debugfs_create_dir+0x24/0x350\n   i2c_device_probe+0x814/0xbf0\n\nIt\u0027s technically possible to create a client after i2c_deregister_clients\nhas run. That client will never be unregistered and make\nwait_for_completion hang.\n\nClose the window by removing the new_device attribute at the start of\ni2c_del_adapter(). device_remove_file() will drain any clients left.\n\nFixes: 73febd775bdb (\"i2c: create debugfs entry per adapter\")\nReported-by: syzbot+23ad911c819b923238b7@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d23ad911c819b923238b7\nSigned-off-by: Vasileios Almpanis \u003cvasilisalmpanis@gmail.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.8+\nTested-by: syzbot+23ad911c819b923238b7@syzkaller.appspotmail.com\nSigned-off-by: Andi Shyti \u003candi.shyti@kernel.org\u003e\nLink: https://patch.msgid.link/20260812-i2c-v2-1-5efaab4c3334@gmail.com\n"
    },
    {
      "commit": "27c9445be86b1313746c46d659d3f823a5f7a218",
      "tree": "57e975b54f1439a286b32a972919670b2185e452",
      "parents": [
        "f98d4986482151a835b521a734722fe8dc5ca37d"
      ],
      "author": {
        "name": "Carlos Song",
        "email": "carlos.song@nxp.com",
        "time": "Mon Aug 03 11:27:05 2026 +0800"
      },
      "committer": {
        "name": "Andi Shyti",
        "email": "andi.shyti@kernel.org",
        "time": "Fri Aug 28 03:00:32 2026 +0200"
      },
      "message": "i2c: imx-lpi2c: avoid accessing target registers on master-only controllers\n\nNot all LPI2C controller instances implement the Target block.\nSince commit 90311787f483 (\"i2c: imx-lpi2c: reset controller in\nprobe stage\"), the driver unconditionally resets both the Master\nand Target blocks during probe.\n\nOn controllers that do not support target mode, accessing the\nTarget registers triggers an asynchronous SError and prevents the\ndriver from probing successfully. For example on i.MX8QM:\n\n  SError Interrupt on CPU2, code 0x00000000bf000002 -- SError\n  Hardware name: Freescale i.MX8QM MEK (DT)\n  pc : lpi2c_imx_probe+0x280/0x594\n  lr : lpi2c_imx_probe+0x224/0x594\n  Kernel panic - not syncing: Asynchronous SError Interrupt\n\nThe VERID register is implemented in the Master block and can be\nsafely accessed on all controller variants. Its FEATURE field\nindicates whether target mode is supported.\n\nRead VERID during probe and use it to determine whether the\nTarget block is present. Only access Target registers when target\nmode is supported and reject target registration requests with\n-EOPNOTSUPP otherwise.\n\nFixes: 90311787f483 (\"i2c: imx-lpi2c: reset controller in probe stage\")\nSigned-off-by: Carlos Song \u003ccarlos.song@nxp.com\u003e\nReviewed-by: Frank Li \u003cFrank.Li@nxp.com\u003e\nSigned-off-by: Andi Shyti \u003candi.shyti@kernel.org\u003e\nLink: https://patch.msgid.link/20260803032705.2250373-1-carlos.song@oss.nxp.com\n"
    },
    {
      "commit": "f98d4986482151a835b521a734722fe8dc5ca37d",
      "tree": "b9eb6aa23050ce39ed16f6bbf05d8f7f5d2853c2",
      "parents": [
        "77549d01edecc20da73c8599e14648877198ce9b"
      ],
      "author": {
        "name": "Guangshuo Li",
        "email": "lgs201920130244@gmail.com",
        "time": "Wed Aug 12 17:44:25 2026 +0800"
      },
      "committer": {
        "name": "Andi Shyti",
        "email": "andi.shyti@kernel.org",
        "time": "Fri Aug 28 02:52:43 2026 +0200"
      },
      "message": "i2c: qcom-cci: fix autosuspend cleanup\n\ncci_probe() calls pm_runtime_use_autosuspend(), but the remove path\ndoes not call the matching pm_runtime_dont_use_autosuspend() before\ndisabling runtime PM.\n\nIf the autosuspend delay is set to a negative value while autosuspend\nis enabled, the runtime PM core increments usage_count to prevent\nruntime suspend. Without undoing the autosuspend setting during\nteardown, this reference is not dropped and usage_count remains\nunbalanced.\n\nUse devm_pm_runtime_set_active_enabled() to manage the runtime PM\nstate. Its managed cleanup disables autosuspend and runtime PM and\nrestores the suspended state on probe failure and driver removal.\nRemove the now redundant manual runtime PM cleanup.\n\nThis issue was found by manual code inspection.\n\nFixes: e517526195de (\"i2c: Add Qualcomm CCI I2C driver\")\nSigned-off-by: Guangshuo Li \u003clgs201920130244@gmail.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v5.8+\nReviewed-by: Vladimir Zapolskiy \u003cvladimir.zapolskiy@linaro.org\u003e\nReviewed-by: Loic Poulain \u003cloic.poulain@oss.qualcomm.com\u003e\nSigned-off-by: Andi Shyti \u003candi.shyti@kernel.org\u003e\nLink: https://patch.msgid.link/20260812094425.3515179-1-lgs201920130244@gmail.com\n"
    },
    {
      "commit": "77549d01edecc20da73c8599e14648877198ce9b",
      "tree": "b7f1a258f98b32b9778aaaac78f8f43037f1d5ce",
      "parents": [
        "a4f3fbccb65de757569686baaf2b72e329096aba"
      ],
      "author": {
        "name": "Hongbo Yao",
        "email": "andy.xu@hj-micro.com",
        "time": "Wed Aug 26 15:05:47 2026 +0800"
      },
      "committer": {
        "name": "Andi Shyti",
        "email": "andi.shyti@kernel.org",
        "time": "Fri Aug 28 02:38:00 2026 +0200"
      },
      "message": "i2c: designware: Enable interrupt mask workaround for HJMC3001\n\nOn HJMicro ARM64 servers, the DesignWare I2C controller does not\nretrigger a pending interrupt if the interrupt status changes after\nthe current status bits have been cleared.\n\nThe issue is exposed under heavy system load when the corresponding\nSPI is routed across sockets to a core in the remote socket. The\ninterrupt is then lost and the I2C transfer times out.\n\nEnable ACCESS_INTR_MASK for HJMC3001. This toggles DW_IC_INTR_MASK\nbefore returning from the interrupt handler and retriggers any\npending interrupt.\n\nFixes: 6816ce57c479 (\"i2c: designware: Add a new ACPI HID for HJMC01 I2C controller\")\nSigned-off-by: Hongbo Yao \u003candy.xu@hj-micro.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.13+\nAcked-by: Mika Westerberg \u003cmika.westerberg@linux.intel.com\u003e\nSigned-off-by: Andi Shyti \u003candi.shyti@kernel.org\u003e\nLink: https://patch.msgid.link/20260826070547.268672-1-andy.xu@hj-micro.com\n"
    },
    {
      "commit": "a4f3fbccb65de757569686baaf2b72e329096aba",
      "tree": "bc91ba99121801e40966558ba5b616873dc7b2c8",
      "parents": [
        "385c7af4e3b95d0769fd211831674e83b16a2ebf"
      ],
      "author": {
        "name": "Kathiravan Thirumoorthy",
        "email": "kathiravan.thirumoorthy@oss.qualcomm.com",
        "time": "Wed Aug 12 14:00:55 2026 +0530"
      },
      "committer": {
        "name": "Andi Shyti",
        "email": "andi.shyti@kernel.org",
        "time": "Fri Aug 28 02:27:57 2026 +0200"
      },
      "message": "i2c: qcom-geni: update frequency table to fix timing parameters\n\nIn IPQ5424, to meet the setup and hold timing requirements in the\nstandard mode, update the frequency table with the values recommended by\nHW design team.\n\nAlso remove the stray space in the I2C_MAX_FAST_MODE_FREQ entry.\n\nFixes: 85c34532849d (\"i2c: qcom-geni: fix I2C frequency table to achieve accurate bus rates\")\nFixes: 506bb2ab0075 (\"i2c: qcom-geni: Support systems with 32MHz serial engine clock\")\nSigned-off-by: Kathiravan Thirumoorthy \u003ckathiravan.thirumoorthy@oss.qualcomm.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e # v6.13+\nReviewed-by: Mukesh Savaliya \u003cmukesh.savaliya@oss.qualcomm.com\u003e\nReviewed-by: Konrad Dybcio \u003ckonrad.dybcio@oss.qualcomm.com\u003e\nSigned-off-by: Andi Shyti \u003candi.shyti@kernel.org\u003e\nLink: https://patch.msgid.link/20260812-ipq5424_i2c_scl_updates-v2-1-e09cd39d01d7@oss.qualcomm.com\n"
    },
    {
      "commit": "afce9701d6423a63194a349d2f1e34c50ce76482",
      "tree": "43c375b0e0e6f506fa45a2e3f192a471ffb2ac6b",
      "parents": [
        "c9e17e381e021536a9f0fe36f4c9c693d6c0f27c"
      ],
      "author": {
        "name": "Alexandre Belloni",
        "email": "alexandre.belloni@bootlin.com",
        "time": "Fri Aug 21 22:07:58 2026 +0200"
      },
      "committer": {
        "name": "Alexandre Belloni",
        "email": "alexandre.belloni@bootlin.com",
        "time": "Thu Aug 27 23:35:24 2026 +0200"
      },
      "message": "MAINTAINERS: update rtc subsystem patchwork location\n\nThe RTC subsystem is migrating it patchwork to kernel.org.\n\nLink: https://patch.msgid.link/202608212007582a463833@mail.local\nSigned-off-by: Alexandre Belloni \u003calexandre.belloni@bootlin.com\u003e\n"
    },
    {
      "commit": "1b78070aaef63512688aebfbc82365ef9d6660f1",
      "tree": "691c0aeaa3d92278ceeb6ace56bc8cd56a7f2ae8",
      "parents": [
        "3ba13f5e7180c034b0a1ef7e052fb780856b134e",
        "4a9d62a8774f130a5b8de26ca9f415e6050a9d51"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 13:53:43 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 13:53:43 2026 -0700"
      },
      "message": "Merge tag \u0027net-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Jakub Kicinski:\n \"Including fixes from Bluetooth, IPSec and Netfilter.\n\n  Current release - fix to a fix:\n\n   - netfilter: ipset: remove need to allocate memory on delete operations\n\n  Current release - regressions:\n\n   - macb: drop CONFIG_OF #if block, fix build\n\n  Previous releases - always broken:\n\n   - stream of fixes for SCTP continues\n\n   - inet: frags: strip GSO state from fragments before reassembly\n\n   - virtio-net: ensure that TCP packets don\u0027t overflow gso_segs\n\n   - tcp-ao: fix use-after-free of current_key on reconnect to another\n     peer\n\n   - page_pool: remove zone/policy GFP flags when allocating XArray\n     entries\n\n   - Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN\n\n   - tls: device: fix out-of-bounds write in tls_append_frag()\n\n   - eth: bnxt:\n      - ring the doorbell when SW USO exits early, avoid packets stuck\n        in Tx\n      - gate TPH enablement behind BNXT_SUPPORTS_QUEUE_API check, avoid\n        users of older NICs seeing non-actionable warning messages\n\n   - eth: qede: fix NULL pointer dereference in TPA fragment processing\"\n\n* tag \u0027net-7.3-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (216 commits)\n  inet: frags: strip GSO state from fragments before reassembly\n  net/sched: sch_htb: limit htb_classify inner-class filter hops\n  selftests/net: packetdrill: add tcp_urg_ptr_retransmit\n  tcp: fix corruption of urgent data on multi-segment retransmit\n  usb: atm: usbatm: fix invalid ci_range initialization\n  net: fec: only stop PTP if it was initialized\n  slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()\n  net: bridge: mcast: fix use-after-free of a master VLAN\u0027s multicast context\n  net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup\n  net: dsa: mxl862xx: enable assisted learning on CPU port\n  net: stmmac: restore NET_IP_ALIGN in the RX DMA offset\n  net: stmmac: drop gso_enabled_types and rely on netdev features\n  net: stmmac: selftests: Don\u0027t test flow control for small rx fifos\n  net: stmmac: selftests: Account for the UC filter list for filtering tests\n  net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering\n  net: stmmac: dwmac4: Account for the primary MAC address for UC filtering\n  net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering\n  net: stmmac: selftests: Check multiple MMC counters\n  selftests: net: Fix slow configurations in big_tcp_tunnels.sh\n  selftests: net: Lower threshold with csum offload off in big_tcp_tunnels.sh\n  ...\n"
    },
    {
      "commit": "4a9d62a8774f130a5b8de26ca9f415e6050a9d51",
      "tree": "bffd1527dc117d4b445cd7a11841499f46b0594d",
      "parents": [
        "d5dc1e69fd7258ea605c9952e5d5947539159ae3",
        "fc04229727d8fffbf02e0635de38413fe0102d02"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 13:13:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 13:13:18 2026 -0700"
      },
      "message": "Merge tag \u0027nf-26-08-27\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf\n\nPablo Neira Ayuso says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nNetfilter fixes for net\n\nThe following patchset contains Netfilter fixes for net:\n\n1) Use DEBUG_NET_WARN_ON_ONCE() instead of WARN_ON() from the tproxy\n   datapath, a recent bug found a way to reach WARN_ON from datapath\n   due to insufficient validation of xt_TPROTO checkentry.\n   From Fernando F. Mancera.\n\n2) Similar to previous patch to replace WARN_ON_ONCE by\n   DEBUG_NET_WARN_ON_ONCE() for connlimit. Not known issue, but\n   since this patch has been around for a while, let\u0027s merge it.\n   Also from Fernando.\n\n3) Move nf_tables harware offload commit path after chain blob\n   and audit to reduce chances of leaving the hardware in\n   inconsistent state.\n\n4) Add missing vzeroupper to nf_tables pipapo AVX2 to address\n   performace degradation to later user of SSE code,\n   from Eric Biggers.\n\n5) Remove pr_debug() in x_tables extensions, a recent bogus found a\n   way to print a unsanitized string in xt_IDLETIMER, many of these\n   pr_debug() calls are there for historical reasons.\n\n6) Use pr_info_ratelimited() in x_tables .checkentry.\n\n7) Fix an imbalance in module refcount due to incorrect override\n   expression logic with sets. Remove unnecessary clone in control\n   plane, use the existing expressions provided by set or dynset\n   expression. Release override expressions only.\n\n8) Tigthen nf_tables device name removal, it is possible to remove\n   prefix strings with exact device name. From Fernando F. Mancera.\n\n9) Set on the set dead bit earlier, otherwise it is possible to\n   call .commit on deleted sets. This also addresses the\n   re-introduction of a bug.\n\n* tag \u0027nf-26-08-27\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:\n  netfilter: nf_tables: remove leftover set_update_list\n  netfilter: nf_tables: set on dead bit when performing early element removal\n  netfilter: nf_tables: skip double clone set expressions on element insert\n  netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited()\n  netfilter: x_tables: remove pr_debug\n  netfilter: nft_set_pipapo_avx2: add missing vzeroupper\n  netfilter: nf_tables: move hardware offload step after building the chain blob\n  netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit\n  netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260827141733.423453-1-pablo@netfilter.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "3ba13f5e7180c034b0a1ef7e052fb780856b134e",
      "tree": "d8dc386ad29ac55b8b4a6d8a58019a9c24ceb75d",
      "parents": [
        "9bb34313d94b17a379ea68fae65be0810c88ee64",
        "5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:53:43 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:53:43 2026 -0700"
      },
      "message": "Merge tag \u0027devicetree-fixes-for-7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux\n\nPull devicetree fixes from Rob Herring:\n\n - Fix possible out-of-bounds access in of_alias_scan()\n\n - Fix refcount leak in of_irq_get_affinity()\n\n - Add Qualcomm SPMI PMIC haptics input which is already referenced\n\n* tag \u0027devicetree-fixes-for-7.3-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux:\n  of: fix out-of-bounds read in of_alias_scan() stem parser\n  of/irq: Fix device node refcount leak in of_irq_get_affinity()\n  dt-bindings: input: Add Qualcomm SPMI PMIC haptics\n"
    },
    {
      "commit": "d5dc1e69fd7258ea605c9952e5d5947539159ae3",
      "tree": "2b6e087f85f5a0a2764413a6839e6e88b4d0503e",
      "parents": [
        "729c4896ab829169f95915d65edd530325910b37"
      ],
      "author": {
        "name": "Xinyang Ge",
        "email": "xinyang@anthropic.com",
        "time": "Thu Aug 27 16:07:07 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:52:10 2026 -0700"
      },
      "message": "inet: frags: strip GSO state from fragments before reassembly\n\nA virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark\nan IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.\ninet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first\nfragment\u0027s skb as the head of the reassembled datagram, including its\nshinfo-\u003egso_size/gso_type/gso_segs, and chain the remaining fragments\non frag_list with whatever linear/paged layout they arrived with.\n\nAfter ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the\nreassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and\nthe next software segmentation point - udp_rcv_segment() on local\ndelivery, validate_xmit_skb(), or the ip_finish_output_gso() slow\npath - hands it to skb_segment(). skb_segment()\u0027s frag_list walk\nassumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to\na tap by an unprivileged user in its own userns are enough:\n\n  kernel BUG at net/core/skbuff.c:4899!\n  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n  CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2\n  RIP: 0010:skb_segment+0x20ca/0x48b0\n  Call Trace:\n   \u003cTASK\u003e\n   __udp_gso_segment+0x29a/0x27d0\n   udp4_ufo_fragment+0x458/0x6c0\n   inet_gso_segment+0x429/0x1340\n   skb_mac_gso_segment+0x233/0x4f0\n   __skb_gso_segment+0x308/0x660\n   udp_queue_rcv_skb+0x440/0xad0\n   udp_unicast_rcv_skb+0xc7/0x2c0\n   udp_rcv+0x16ce/0x2260\n   ip_protocol_deliver_rcu+0x197/0x2d0\n   ip_local_deliver+0x430/0x690\n   ip_rcv+0x16f/0x1f0\n   __netif_receive_skb_one_core+0x15e/0x1c0\n   __netif_receive_skb+0x1e/0x110\n   netif_receive_skb+0xf6/0x5c0\n   tun_rx_batched.isra.0+0x3ab/0x790\n   tun_get_user+0x17c3/0x3550\n   tun_chr_write_iter+0xba/0x1b0\n   vfs_write+0x646/0x1130\n   \u003c/TASK\u003e\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nThis runs with BH disabled, so it is a panic rather than an oops. The\nsame is reachable with CAP_NET_RAW in a netns where a defrag point\nprecedes a GSO point, and from a guest whose VMM forwards\nvirtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by\ncommit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when splitting\ngso_size mangled skb having linear-headed frag_list\") and by\ncommit 9e4b7a99a03a (\"net: gso: fix panic on frag_list with mixed head\nalloc types\") do not cover it: page-backed heads skip them, and kmalloc\nheads skip them when gso_size \u003d\u003d skb_headlen(head), which the sender\ncontrols.\n\nAn skb entering a frag queue is an IP fragment by definition and\ncannot legitimately carry GSO state: GRO does not merge fragments and\nthe stack segments before it fragments, so only untrusted sources are\naffected. This has been reachable since\ncommit f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\"), the first\npath that let userspace attach GSO metadata to an IP fragment. Reset\nthe GSO fields of every fragment as it is queued, in\ninet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and\n6lowpan reassembly share; then neither the head nor the frag_list\nmembers of the reassembled skb carry them (the members matter too:\nthe ip_do_fragment()/ip6_fragment() fast paths send them out as they\nare). The head may remain CHECKSUM_PARTIAL; that is already accepted\non receive and resolved by skb_checksum_help() in\nip_do_fragment()/ip6_fragment() on forward.\n\nTested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer\nabove, two further IPv4 frag_list geometries that reach\nBUG_ON(i \u003e\u003d nfrags) and BUG_ON(!list_skb-\u003ehead_frag), and an IPv6\nfragment-header variant (udp6_ufo_fragment()) each panic the unpatched\nkernel; with this patch all four datagrams are delivered intact and\nnothing is logged.\n\nFixes: f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\")\nCc: stable@kernel.org\nSuggested-by: Eric Dumazet \u003cedumazet@google.com\u003e\nSigned-off-by: Xinyang Ge \u003cxinyang@anthropic.com\u003e\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/937926e509f2acd8e0e66520dc2b30fd6b4d1687.1787839506.git.pabeni@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "729c4896ab829169f95915d65edd530325910b37",
      "tree": "6ef0be24e18acef873929a0c986f959d4f93cc83",
      "parents": [
        "6a7e91f890eceb4fd9d3662e7ffba1fcb55cc00e"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Wed Aug 26 11:33:39 2026 -0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:47:58 2026 -0700"
      },
      "message": "net/sched: sch_htb: limit htb_classify inner-class filter hops\n\nhtb_classify() follows each filter-selected inner class by switching\nto cl-\u003efilter_list, but never bounds the number of hops. A filter on\nan inner class can point back to itself or to another inner class that\npoints back, creating an infinite loop in the packet classification\npath with the qdisc lock held and BH disabled — a soft lockup / panic\nfrom a single packet.\n\nBound the traversal with a hop counter and drop the packet with a\nrate-limited warning once the bound is exceeded. The counter is\nincremented at the point the inner filter chain is picked up, after the\nTC_ACT_* switch has consumed the classifier verdict, so a terminal\nTC_ACT_QUEUED/STOLEN/TRAP on the last permitted chain still sets *qerr\nto __NET_XMIT_STOLEN and the packet is not charged as a drop by this\nqdisc or its parent.\n\nThe bound is TC_HTB_MAXDEPTH, taken from HTB\u0027s own parameters rather than\nfrom the qdisc hierarchy depth limit. Class levels run from 0 to\nTC_HTB_MAXDEPTH - 1, so a traversal that strictly descends in level can\ntake at most TC_HTB_MAXDEPTH hops. That descent is what a sane\nconfiguration does, but it is assumed here rather than enforced:\nhtb_find() resolves a classid against every class in the qdisc, so a\nfilter may equally select a sibling or an ancestor. The normal\nroot -\u003e inner -\u003e leaf path takes a single hop, so the bound does not\naffect legitimate classification.\n\nhtb_classify() can now return NULL irrespective of CONFIG_NET_CLS_ACT,\nwhereas previously every NULL return sat inside that ifdef. The NULL\nhandler in htb_enqueue() therefore cannot stay conditional either, so\ndrop the ifdef around it. This matches hfsc_enqueue(), which has always\nhandled a NULL class unconditionally. Without it, a kernel built\nwithout actions would dereference a NULL class instead of dropping.\n\nConditions to recreate the bug:\n- CONFIG_NET_SCHED, CONFIG_NET_SCH_HTB, CONFIG_NET_CLS_U32,\n  CONFIG_LOCKUP_DETECTOR.\n- Create an HTB qdisc on a device (e.g. lo), add an inner class\n  1:1 with a leaf child 1:10, install a root u32 filter selecting\n  1:1, and an inner-class u32 filter on 1:1 also selecting 1:1.\n- Send one packet (ping). On the unfixed kernel the classify loop\n  spins with the qdisc lock held; with softlockup_panic\u003d1 it panics.\n- Reachable from unprivileged user via unshare -Urn (CAP_NET_ADMIN).\n\nFixes: 1da177e4c3f4 (\"Linux-2.6.12-rc2\")\nReported-by: Vega \u003cvega@nebusec.ai\u003e\nCo-developed-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260826143339.271935-1-victor@mojatatu.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6a7e91f890eceb4fd9d3662e7ffba1fcb55cc00e",
      "tree": "98365cd23bcfbda7709155208a607e2e1e85409b",
      "parents": [
        "ce2b807f42ed5e55567b8864ab72963f90779270"
      ],
      "author": {
        "name": "Jiayuan Chen",
        "email": "jiayuan.chen@linux.dev",
        "time": "Wed Aug 26 22:11:27 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:47:34 2026 -0700"
      },
      "message": "selftests/net: packetdrill: add tcp_urg_ptr_retransmit\n\nDrive a connection into urgent mode and force a multi-segment retransmit,\nchecking that each retransmitted segment keeps its own urg_ptr.\n\nThe test asserts the fixed behaviour: the hole is retransmitted as two\nindependent skbs, each with its own urg_ptr (5001 and 4001) and no PSH.\nAn unpatched kernel instead sends one super-skb whose GSO split copies\nurg_ptr onto the second segment and also sets PSH there, so on an unpatched\nkernel the mismatch shows up on the PSH bit (actual P.U ... urg 5001) before\nthe urg_ptr:\n\n\ttcp_urg_ptr_retransmit.pkt:63: live packet field tcp_psh:\n\t\texpected: 0 (0x0) vs actual: 1 (0x1)\n\tscript packet:  .U 1001:2001(1000) ack 1\n\tactual packet:  P.U 1001:2001(1000) ack 1 win 1050\n\nAfter the fix the retransmit carries a per-segment urg_ptr and the test\npasses.\n\nSigned-off-by: Jiayuan Chen \u003cjiayuan.chen@linux.dev\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260826141145.67823-2-jiayuan.chen@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ce2b807f42ed5e55567b8864ab72963f90779270",
      "tree": "630f204f6ed81dc972d9b177ace820b1288902b9",
      "parents": [
        "a60fd8c6dbaa76da4163cf225ed2b9e982540f39"
      ],
      "author": {
        "name": "Jiayuan Chen",
        "email": "jiayuan.chen@linux.dev",
        "time": "Wed Aug 26 22:11:26 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:47:34 2026 -0700"
      },
      "message": "tcp: fix corruption of urgent data on multi-segment retransmit\n\nOn the normal xmit path, while in urgent mode we refuse to build a\nmulti-segment TSO packet, so every segment gets its own urg_ptr:\n\n\t/* tcp_write_xmit() */\n\tlimit \u003d mss_now;\n\tif (tso_segs \u003e 1 \u0026\u0026 !tcp_urg_mode(tp))\n\t\tlimit \u003d tcp_mss_split_point(...);\n\nThe retransmit path has no such guard. __tcp_retransmit_skb() builds a\nsegs \u003e 1 skb and hands it to the GSO layer, which only advances th-\u003eseq\nper segment and copies urg_ptr verbatim:\n\n\t/* __tcp_retransmit_skb() */\n\tlen \u003d cur_mss * segs;\t\t/* segs \u003e 1, no urg_mode check */\n\t...\n\t/* tcp_gso_segment(): bumps seq only, urg_ptr is copied */\n\nurg_ptr is an offset from the segment\u0027s own seq, so a copied value points\nat a different place on each segment. The receiver rebuilds the absolute\nurgent seq as seg.seq + urg_ptr, so it walks a moving urgent point instead\nof the one OOB byte:\n\n\tseg1  seq 1     urg_ptr 5001 -\u003e urgent @ 5001   (ok)\n\tseg2  seq 1001  urg_ptr 5001 -\u003e urgent @ 6001   (wrong, +MSS)\n\tseg3  seq 2001  urg_ptr 5001 -\u003e urgent @ 7001   (wrong, +2*MSS)\n\nThe real OOB byte is never pointed at, so the receiver stops splicing it\nout and delivers it as normal in-band data, corrupting the stream.\n\nGuard the retransmit length like the xmit path: keep segs \u003d 1 while in\nurgent mode.\n\nFixes: 10d3be569243 (\"tcp-tso: do not split TSO packets at retransmit time\")\nSigned-off-by: Jiayuan Chen \u003cjiayuan.chen@linux.dev\u003e\nReviewed-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260826141145.67823-1-jiayuan.chen@linux.dev\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a60fd8c6dbaa76da4163cf225ed2b9e982540f39",
      "tree": "cccdf9a4d16ddd050015b0720daaa108c8e0b190",
      "parents": [
        "dd890ae29299636fb037276fc1b5238698d08b03"
      ],
      "author": {
        "name": "Deepanshu Kartikey",
        "email": "kartikey406@gmail.com",
        "time": "Wed Aug 26 19:02:58 2026 +0530"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:46:16 2026 -0700"
      },
      "message": "usb: atm: usbatm: fix invalid ci_range initialization\n\nsyzbot reported a shift-out-of-bounds in __vcc_connect():\n\n  UBSAN: shift-out-of-bounds in net/atm/common.c:382:32\n  shift exponent -1 is negative\n  CPU: 0 UID: 0 PID: 5987 Comm: syz.0.18 Not tainted syzkaller #0 PREEMPT(full)\n  Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/05/2026\n  Call Trace:\n   \u003cTASK\u003e\n   dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n   ubsan_epilogue+0xa/0x30 lib/ubsan.c:233\n   __ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494\n   __vcc_connect+0x14b4/0x19c0 net/atm/common.c:382\n   vcc_connect+0x328/0x8f0 net/atm/common.c:498\n   pvc_bind+0x272/0x380 net/atm/pvc.c:52\n   __sys_bind+0x2e3/0x410 net/socket.c:1976\n   __x64_sys_bind+0x7a/0x90 net/socket.c:1979\n   ...\n\nATM device ci_range fields (vpi_bits and vci_bits) represent the\nnumber of bits supported for VPI and VCI addressing on the device.\nnet/atm/common.c directly uses these fields as bit shift counts:\n  vpi \u003e\u003e dev-\u003eci_range.vpi_bits\n  vci \u003e\u003e dev-\u003eci_range.vci_bits\n  1 \u003c\u003c vcc-\u003edev-\u003eci_range.vpi_bits\n  1 \u003c\u003c vcc-\u003edev-\u003eci_range.vci_bits\n\nusbatm_atm_init() sets ci_range.vpi_bits and ci_range.vci_bits to\nATM_CI_MAX (-1), which is defined in \u003cuapi/linux/atmdev.h\u003e as a\nsentinel value for userspace ATM_SETCIRANGE requests, not a valid bit\ncount. Shifting by -1 is undefined behavior and triggers UBSAN\nwarnings.\n\nATM UNI cell headers allow up to 8 bits for VPI (0..255) and 16 bits\nfor VCI (0..65535). Initialize vpi_bits to 8 and vci_bits to 16, as\ndone by solos-pci.\n\nFixes: c59bba75fa50 (\"[PATCH] USB ATM: new usbatm core\")\nReported-by: syzbot+6665d3db5fef15914802@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d6665d3db5fef15914802\nSuggested-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://lore.kernel.org/all/20260824024620.23485-1-kartikey406@gmail.com/T/ [v1]\nSigned-off-by: Deepanshu Kartikey \u003ckartikey406@gmail.com\u003e\nLink: https://patch.msgid.link/20260826133258.8306-1-kartikey406@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "dd890ae29299636fb037276fc1b5238698d08b03",
      "tree": "0d4ff2c5b9f03e0551b74aa811a6ac5db5fc0262",
      "parents": [
        "23c53269f2baaedf2d92784290cb9ef6db2a3bce"
      ],
      "author": {
        "name": "bui duc phuc",
        "email": "phucduc.bui@gmail.com",
        "time": "Wed Aug 26 17:34:28 2026 +0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:41:14 2026 -0700"
      },
      "message": "net: fec: only stop PTP if it was initialized\n\nfec_ptp_init() is only called when fep-\u003ebufdesc_ex is available.\nHowever, fec_probe() unconditionally calls fec_ptp_stop() on the\nfailed_init path, and fec_drv_remove() unconditionally calls\nfec_ptp_stop() during device removal.\n\nCheck fep-\u003ebufdesc_ex before calling fec_ptp_stop() in both paths\nto avoid stopping PTP when it was not initialized.\n\nFixes: 32cba57ba74b (\"net: fec: introduce fec_ptp_stop and use in probe fail path\")\nReviewed-by: Wei Fang \u003cwei.fang@nxp.com\u003e\nReviewed-by: Frank Li \u003cFrank.Li@nxp.com\u003e\nSigned-off-by: bui duc phuc \u003cphucduc.bui@gmail.com\u003e\nLink: https://patch.msgid.link/20260826103428.32807-1-phucduc.bui@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "23c53269f2baaedf2d92784290cb9ef6db2a3bce",
      "tree": "956574aa5e44baeb5b212748a2e9053da7797045",
      "parents": [
        "50e5c6605cc9c2dd57bd2d1b3459674d19738983"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Wed Aug 26 10:52:38 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:38:27 2026 -0700"
      },
      "message": "slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()\n\nJaeyoung Chung and Eulgyu Kim reported a slab-use-after-free read\nin slip_receive_buf() when racing against tty hangup.\n\ntty_ldisc_hangup() calls ld-\u003eops-\u003ehangup() while holding only\na read lock on tty-\u003eldisc_sem (via tty_ldisc_ref()).\nBecause slip_hangup() simply called slip_close(), it ran concurrently\nwith reader functions such as slip_receive_buf().\n\nslip_close() unregisters and frees the net device and its private\nstruct slip, causing concurrent reader threads in slip_receive_buf()\nto dereference freed memory.\n\nLine discipline close() is already guaranteed to be called under\nthe write lock of tty-\u003eldisc_sem during hangup processing\n(in tty_ldisc_reinit() or tty_ldisc_kill()).\n\nRemove slip_hangup() so teardown is serialized cleanly by slip_close().\n\nFixes: 5342b77c4123 (\"slip: Clean up create and destroy\")\nReported-by: Jaeyoung Chung \u003cjjy600901@snu.ac.kr\u003e\nReported-by: Eulgyu Kim \u003ceulgyukim@snu.ac.kr\u003e\nCloses: https://lore.kernel.org/netdev/20260825150655.1450271-1-jjy600901@snu.ac.kr/\nCc: Qingfang Deng \u003cqingfang.deng@linux.dev\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260826105238.3323436-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9bb34313d94b17a379ea68fae65be0810c88ee64",
      "tree": "7cb98cbe4dae4b35c6cd371cbb3c3e8d6683ae79",
      "parents": [
        "6253a29206959128f5d99a119fcf29bd7fb3c106",
        "a9c2f0d401fd1e11ce59e4243946a59bd818e8c5"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:38:05 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:38:05 2026 -0700"
      },
      "message": "Merge tag \u0027spi-fix-v7.3-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi\n\nPull spi fixes from Mark Brown:\n \"A couple of fixes that came in during the merge window: Geert fixed an\n  uninitialised data bug in the amlogic-spisg driver which could crash\n  and in the Loongson driver Li Jun hooked up the existing suspend\n  operations more fully to fix hibernation\"\n\n* tag \u0027spi-fix-v7.3-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:\n  spi: loongson: pm: add .freeze .poweroff .thaw .restore\n  spi: amlogic-spisg: Make sure clk_init_data is fully initialized\n"
    },
    {
      "commit": "50e5c6605cc9c2dd57bd2d1b3459674d19738983",
      "tree": "895a6215b9bbe233f115472ab917ad60d59941bc",
      "parents": [
        "8f735d64382dcf162f4276d6699d03ad2f859c0b"
      ],
      "author": {
        "name": "Norbert Szetei",
        "email": "norbert@doyensec.com",
        "time": "Wed Aug 26 11:12:27 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:35:03 2026 -0700"
      },
      "message": "net: bridge: mcast: fix use-after-free of a master VLAN\u0027s multicast context\n\nbr_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under\nbr-\u003emulticast_lock before stopping a VLAN\u0027s multicast context.  That is\nthe teardown handshake: lockless readers gate on the flag through\nbr_multicast_ctx_should_use() -\u003e br_multicast_ctx_vlan_disabled(), so\nonce it is cleared under the lock no reader can arm the context again.\n\nFor a master VLAN the handshake never runs.  __vlan_del() clears\nBRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so\nbr_multicast_toggle_one_vlan(masterv, false) returns early on\n!br_vlan_is_brentry(vlan): the flag stays set and br-\u003emulticast_lock is\nnever taken.  br_vlan_put_master() then drains the context in\nbr_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a\nreader still inside rcu_read_lock() sees the context as enabled and\nre-arms it.  The port and port-VLAN branch of the function has no\nbr_vlan_is_brentry() test and flips the flag under br-\u003emulticast_lock,\nso it is not affected.\n\nThe reader is the bridge transmit path.  For a master VLAN\nbr_multicast_rcv() selects brmctx \u003d \u0026vlan-\u003ebr_mcast_ctx with\npmctx \u003d NULL, so IGMP sent to the bridge device re-arms the context\u0027s\ntimers after br_multicast_ctx_deinit() has already stopped them.\n\n  BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0\n  Write of size 8 at addr ffff88810ac39918 by task brmc/601\n   __mod_timer+0x51a/0xc50\n   br_multicast_host_join+0x25b/0x390\n   __br_multicast_add_group+0x468/0x530\n   br_ip4_multicast_add_group+0x1a0/0x260\n   br_multicast_rcv+0x2cda/0x61e0\n   br_dev_xmit+0x6c4/0x1540\n  Allocated by task 610:\n   br_vlan_add+0x111/0xb40\n   br_vlan_info+0x370/0x3e0\n  Freed by task 0:\n   kfree+0x1a7/0x4f0\n   rcu_core+0x7dc/0x10a0\n\nOnly test br_vlan_is_brentry() when enabling, like the\nbr_multicast_ctx_vlan_global_disabled() test next to it.  Disabling then\nalways clears BR_VLFLAG_MCAST_ENABLED under br-\u003emulticast_lock before\nbr_multicast_ctx_deinit() drains the context.\n\nFixes: 7b54aaaf53cb (\"net: bridge: multicast: add vlan state initialization and control\")\nCc: stable@vger.kernel.org\nSigned-off-by: Norbert Szetei \u003cnorbert@doyensec.com\u003e\nAcked-by: Nikolay Aleksandrov \u003crazor@blackwall.org\u003e\nLink: https://patch.msgid.link/D400F6C7-543A-4B79-9E5B-D1D8974DE5C9@doyensec.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6253a29206959128f5d99a119fcf29bd7fb3c106",
      "tree": "f934fd74b724c39efa0e29b0eb3fa6c6fe9bcd78",
      "parents": [
        "7cec13314dd8935afbfc0430d9d43fad75285b37",
        "44f7b876b7c6c7b3a219b7a810d3d9548df21540"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:21:56 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:21:56 2026 -0700"
      },
      "message": "Merge tag \u0027regulator-fix-v7.3-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator\n\nPull regulator fix from Mark Brown:\n \"One fix here, for a race condition on startup in the tps65185 driver\n  which is seen on actual boards - we need a delay after waking the chip\n  before it is ready to talk to the host\"\n\n* tag \u0027regulator-fix-v7.3-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator:\n  regulator: tps65185: wait for the IC to wake before the first I2C access\n"
    },
    {
      "commit": "7cec13314dd8935afbfc0430d9d43fad75285b37",
      "tree": "95197ca50c45776aba2a5bf2ea8ff24c4a30f126",
      "parents": [
        "f7e3f4d9f425cf4c5577cd84a096e6e618488083",
        "1476cca098f6d3a553fcec6fe9b7d86e15c00b59"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:14:19 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 12:14:19 2026 -0700"
      },
      "message": "Merge tag \u0027dma-mapping-7.3-2026-08-27\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux\n\nPull dma-mapping fix from Marek Szyprowski:\n\n - integer overflow fix for kernel cmdline parser for DMA contiguous\n   initialization code (Alexander Graf)\n\n* tag \u0027dma-mapping-7.3-2026-08-27\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/mszyprowski/linux:\n  dma-contiguous: fix truncation of numa_cma / cma_pernuma sizes \u003e\u003d 2G\n"
    },
    {
      "commit": "8f735d64382dcf162f4276d6699d03ad2f859c0b",
      "tree": "845dd9d119ebec7c95618810acb2435f3688eae9",
      "parents": [
        "88c71cc0ad9800d8814bd3627b21a0da9028e057"
      ],
      "author": {
        "name": "Jamal Hadi Salim",
        "email": "jhs@mojatatu.com",
        "time": "Tue Aug 25 04:14:03 2026 -0400"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 12:12:36 2026 -0700"
      },
      "message": "net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup\n\nqdisc_get_stab() accepts a user-supplied size table, and\n__qdisc_calculate_pkt_len() amplifies qdisc_pkt_len() through the\noverhead, the size-table data (u16), and size_log (up to\nSTAB_SIZE_LOG_MAX). A crafted stab can therefore set qdisc_pkt_len()\nto ~1 GiB for an ordinary skb. Per-flow deficit schedulers such as\nDRR and ETS replenish one quantum per loop iteration; with a tiny\nquantum (1) they spin billions of times under the qdisc lock,\nproducing a soft lockup / RCU stall as illustrated by vega@nebusec.ai.\n\nCap the final qdisc_pkt_len() to QDISC_PKT_LEN_MAX so the size-table\namplification cannot drive deficit schedulers into an unbounded loop.\nA legitimate size table (e.g. qfq\u0027s overhead 999999999, which is\nhandled by dropping) is still accepted.\n\nIntroduce cap QDISC_PKT_LEN_MAX (1 \u003c\u003c 20) \u003d 1 MiB which is well above\nany legitimate single-skb wire length: the largest current skb-\u003elen\nis GSO_MAX_SIZE (524280), and an ATM-style size table (53/48 cell tax)\namplifies that to ~578 KB, both comfortably below 1 MiB. At the same\ntime, 1 MiB bounds the deficit refill loop to ~1M iterations per\npacket with quantum\u003d1, which completes in a few milliseconds well\nunder the demonstrated softlockup threshold (~10^9 iterations).\n\nConditions to recreate the bug:\n- CONFIG_NET_SCHED\u003dy, CONFIG_NET_SCH_DRR\u003dy (or CONFIG_NET_SCH_ETS\u003dy).\n- Attach a DRR (or ETS) root qdisc with a crafted TCA_STAB that\n  amplifies qdisc_pkt_len to ~1 GiB (e.g. size_log\u003d15, data\u003d[32768]).\n- Add a class with a tiny quantum of 1 and send one small packet; the\n  deficit loop spins billions of times under the qdisc lock and trips\n  the softlockup detector (panic with kernel.softlockup_panic\u003d1).\n- Reachable as root or from an unprivileged user in a fresh user+net\n  namespace (unshare -Urn) with namespace-local CAP_NET_ADMIN.\n\nFixes: 1da177e4c3f4 (\"Linux-2.6.12-rc2\")\nReported-by: vega@nebusec.ai\nTested-by: Victor Nogueira \u003cvictor@mojatatu.com\u003e\nSigned-off-by: Jamal Hadi Salim \u003cjhs@mojatatu.com\u003e\nLink: https://patch.msgid.link/20260825081403.133992-1-jhs@mojatatu.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "88c71cc0ad9800d8814bd3627b21a0da9028e057",
      "tree": "47daaa90fa71d915136cb908efe1c60088ba2fbd",
      "parents": [
        "23680bf5f8c69c923546b84a8e6c401bef8b88fe"
      ],
      "author": {
        "name": "Edoardo Pinci",
        "email": "epinci@outlook.com",
        "time": "Mon Aug 24 15:11:43 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 11:41:25 2026 -0700"
      },
      "message": "net: dsa: mxl862xx: enable assisted learning on CPU port\n\nThe MxL862xx driver enables FDB isolation but does not enable assisted\nlearning on the CPU port. Consequently, MAC addresses learned through a\nphysical switch port are not updated in hardware when the corresponding\nstation moves to a foreign bridge port, such as a Wi-Fi interface.\n\nThe stale hardware FDB entry continues directing return traffic toward\nthe original physical port. Traffic entering that same port is then\nfiltered instead of being forwarded to the CPU and software bridge. This\ncauses downstream unicast traffic, including DHCP OFFER and ACK packets,\nto disappear after a client roams to a local wireless interface. The\nclient eventually considers the connection unusable and disconnects.\n\nEnable assisted CPU-port learning so DSA installs foreign bridge FDB\nentries on the CPU port. This keeps the hardware FDB synchronized with\nthe software bridge and allows return traffic to reach locally attached\nWi-Fi clients after roaming.\n\nTested on a BPI R4 PRO with a MxL862xx switch and a BE14000 WiFi interface.\n- Without patch, wired uplink on lan6 port (mxl path)\n  Wifi clients connect but roam away not getting DHCP offers\n- Without patch, wired uplink on wan port (no mxl path)\n  Wifi clients connect and roam successfully\n- With this patch, uplink on lan6 (mxl path)\n  Wifi clients connect and roam successfully\n\nFixes: 340bdf984613 (\"net: dsa: mxl862xx: implement bridge offloading\")\nSigned-off-by: Edoardo Pinci \u003cepinci@outlook.com\u003e\nLink: https://patch.msgid.link/DU0P251MB069949C6DEB4D1D51F31FE87C4A02@DU0P251MB0699.EURP251.PROD.OUTLOOK.COM\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "23680bf5f8c69c923546b84a8e6c401bef8b88fe",
      "tree": "6c06ab0a5afa838fa0180b0788d73e64f64ac8d0",
      "parents": [
        "9c24a504a3af1acb96da8d6a45a373fda8a9c687"
      ],
      "author": {
        "name": "Pascal Kneuper",
        "email": "PKneuper@dspace.de",
        "time": "Mon Aug 24 14:50:14 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 11:40:24 2026 -0700"
      },
      "message": "net: stmmac: restore NET_IP_ALIGN in the RX DMA offset\n\nSince the RX path was converted to zero-copy, the page pool page is handed\nto the stack directly as the skb head, and the offset the DMA engine writes\nat is what determines the alignment of the packet headers.\n\nBefore the conversion the payload was copied into an skb obtained from\nnapi_alloc_skb(), which reserves NET_SKB_PAD + NET_IP_ALIGN. The\nconversion moved the headroom into stmmac_rx_offset() but did not carry\nover NET_IP_ALIGN, so on architectures where NET_IP_ALIGN is 2 the IP\nheader now lands misaligned:\n\n  64 (NET_SKB_PAD) + 14 (ethernet) + 20 (IP) \u003d 98\n\nSame for the XDP branch:\n\n  256 (XDP_PACKET_HEADROOM) + 14 (ethernet) + 20 (IP) \u003d 290\n\nOn ARM32 this is fatal, because ldm and ldrd trap on unaligned addresses\neven when CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS is set.\n\nAny received echo request panics the machine, e.g:\n\n  Unhandled fault: alignment exception (0x001) at 0x81873062\n  Internal error: : 1 [#1] SMP ARM\n  Hardware name: Altera SOCFPGA Arria10\n  PC is at icmp_echo+0x38/0xa8\n  LR is at icmp_rcv+0x22c/0x370\n  Call trace:\n   icmp_echo from icmp_rcv+0x22c/0x370\n   icmp_rcv from ip_protocol_deliver_rcu+0x2c/0x224\n   ip_protocol_deliver_rcu from ip_local_deliver+0xc8/0x1a0\n   ip_local_deliver from ip_sublist_rcv_finish+0x3c/0x50\n   ip_sublist_rcv_finish from ip_list_rcv_finish+0x110/0x118\n   ip_list_rcv_finish from ip_list_rcv+0xc8/0xdc\n   ip_list_rcv from __netif_receive_skb_list_core+0x170/0x1c0\n   ...\n   napi_complete_done from stmmac_napi_poll_rx+0xcb0/0x1030\n  Code: e24dd068 e59020a0 e28dc010 e0822001 (e8920003)\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nThe faulting instruction is the ldm of *icmp_hdr(skb) in icmp_echo().\n\nFix by adding NET_IP_ALIGN back to the RX offset, which restores the\nalignment the stack used to get.\n\nNote that commit a955318fe67e (\"stmmac: align RX buffers\") made a similar\nchange in 2021 and was reverted by commit 12d125b4574b (\"stmmac: Revert\n\"stmmac: align RX buffers\"\") because it caused packet corruption. That\npatch raised the offset from 0 without adjusting the buffer size\naccounting, so the DMA engine could arguably write past the end of the RX\nbuffers, though this was never root caused.\nCommit df542f669307 (\"net: stmmac: Switch to zero-copy in non-XDP RX\npath\") since derives the page pool allocation from stmmac_rx_offset(), so\nthe extra bytes are accounted for.\n\nFixes: df542f669307 (\"net: stmmac: Switch to zero-copy in non-XDP RX path\")\nCc: Daniel Baldin \u003cDBaldin@dspace.de\u003e\nSigned-off-by: Pascal Kneuper \u003cPKneuper@dspace.de\u003e\nLink: https://patch.msgid.link/20260824125014.47862-1-PKneuper@dspace.de\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f7e3f4d9f425cf4c5577cd84a096e6e618488083",
      "tree": "17f98d2f55b128f319491c389ccc042c0dcd025a",
      "parents": [
        "7cc2726d4847c48844eb0ee16f973d449260f248",
        "cf1a12e0804515e0ed8b3f50c1c32f7f425bd660"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 11:16:39 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 11:16:39 2026 -0700"
      },
      "message": "Merge tag \u0027backlight-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/backlight\n\nPull backlight updates from Lee Jones:\n \"New Support \u0026 Features:\n   - Silergy SY7758: Add driver for the 6-channel high-efficiency LED\n     driver\n\n  Improvements \u0026 Fixes\n   - Awinic AW99706: Fix device tree property names to match the\n     binding, consistently validate all property values, and honor the\n     core blank state in `update_status()`\n   - Kinetic KTD2801: Add missing dependency on `GPIOLIB` in Kconfig\n   - Qualcomm WLED: Remove redundant `dev_err()` calls\n\n  Cleanups \u0026 Refactoring\n   - Core: Use `sysfs_emit()` instead of `sprintf()` in sysfs show\n     callbacks\n   - Maintainers: Update Junjie Cao\u0027s email address for the Awinic\n     AW99706 driver\n\n  Device Tree Binding Updates\n   - Marvell 88PM860X: Add missing bracket in the example\n   - Silergy SY7758: Document the 6-channel high-efficiency LED driver\"\n\n* tag \u0027backlight-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/backlight:\n  backlight: Use sysfs_emit() instead of sprintf()\n  backlight: qcom-wled: Remove redundant dev_err()\n  backlight: ktd2801: Fix unmet dependency on GPIOLIB\n  backlight: aw99706: Honor the core blank state in update_status()\n  backlight: aw99706: Validate all DT property values consistently\n  backlight: aw99706: Fix DT property names to match binding\n  dt-bindings: backlight: 88pm860x: Add missing bracket\n  MAINTAINERS: Update my email address for the AW99706 backlight driver\n  backlight: Add SY7758 6-channel High Efficiency LED Driver support\n  dt-bindings: leds: backlight: Document the SY7758 6-channel High Efficiency LED Driver\n"
    },
    {
      "commit": "7cc2726d4847c48844eb0ee16f973d449260f248",
      "tree": "eb69381bb308fb07f7bb049a24b9572669e46c55",
      "parents": [
        "79b4f3baae2fa65060c30f827e3c0e8f1db99f98",
        "f8cca63a0a4f3475199d9ab7f86782bdfeb0744d"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 11:05:51 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 11:05:51 2026 -0700"
      },
      "message": "Merge tag \u0027leds-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/leds\n\nPull LED updates from Lee Jones:\n \"New Support \u0026 Features:\n   - Core: Extend netdev trigger speeds up to 100G\n   - PWM Multicolor: Introduce default-intensity property\n   - Analog Devices LTC3220: Add support for 18 channel LED driver\n   - NXP PCA963x: Add multicolor LED class support\n\n  Improvements \u0026 Fixes:\n   - GPIO: Clear error pointers for skipped LEDs\n   - Broadcom BCM63138: Use %pe to print pinctrl error instead of %ld\n   - ISSI IS31FL319x: Modernize device registration by using fwnode APIs\n   - NXP PCA9532: Fix inverted GPIO output polarity\n   - NXP PCA9532: Fix phantom device registration on missing hardware\n   - STMicroelectronics ST1202: Correct and extend hw_pattern\n     documentation\n   - STMicroelectronics ST1202: Fix channel disable logic on zero\n     brightness and ensure brightness changes are applied in active mode\n   - STMicroelectronics ST1202: Fix hardware pattern sequence\n     programming, validate inputs, and correct pattern duration\n     calculations\n   - STMicroelectronics ST1202: Validate LED reg property against\n     channel count\n   - TI LP5860: Fix a potential double-unlock during device\n     initialization and fix error handling path by using\n     devm_mutex_init()\n\n  Cleanups \u0026 Refactoring:\n   - GPIO: Make legacy gpiolib interface optional\n\n  Device Tree Binding Updates:\n   - Core: Add default-intensity property\n   - Core: Document \"gpio\" trigger\n   - Analog Devices LTC3220: Add DT binding for LTC3220 18 channel LED\n     driver\n   - Broadcom BCM6358: Convert to DT schema\n   - LaCie NS2: Convert to DT schema\n   - NXP PCA963x: Add multicolor LED support\n   - NXP PCA963x: Fix reg maximum for pca9635\n   - TI TPS65217: Convert backlight bindings to DT schema\"\n\n* tag \u0027leds-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/leds: (29 commits)\n  leds: is31fl319x: Modernize registration\n  dt-bindings: leds: lacie,ns2-leds: Convert to DT schema\n  leds: pca963x: Add multicolor LED class support\n  dt-bindings: leds: nxp,pca963x: Add multicolor LED support\n  dt-bindings: leds: nxp,pca963x: Fix reg maximum for pca9635\n  leds: gpio: Clear error pointers for skipped LEDs\n  dt-bindings: leds: backlight: Convert TPS65217 to DT schema\n  leds: pca9532: Fix phantom device registration on missing hardware\n  leds: gpio: Make legacy gpiolib interface optional\n  leds: bcm63138: Use %pe to print pinctrl error instead of %ld\n  dt-bindings: leds: Add default-intensity property\n  leds: ltc3220: Add Support for LTC3220 18 channel LED Driver\n  dt-bindings: leds: Add LTC3220 18 channel LED Driver\n  dt-bindings: leds: bcm6358: Convert to DT schema\n  dt-bindings: leds: Document \"gpio\" trigger\n  leds: st1202: Correct and extend hw_pattern documentation\n  leds: st1202: Validate LED reg property against channel count\n  leds: st1202: Disable channel when brightness is set to zero\n  leds: st1202: Fix brightness having no effect while pattern mode is active\n  leds: st1202: Fix spurious pattern sequence start in setup\n  ...\n"
    },
    {
      "commit": "9c24a504a3af1acb96da8d6a45a373fda8a9c687",
      "tree": "1100da1ba5771df9d3694b7b7f8cd542f0c95a85",
      "parents": [
        "6fe66698b959357c8f780fd21c809b2d83d2a7ee"
      ],
      "author": {
        "name": "Lorenzo Bianconi",
        "email": "lorenzo.bianconi@oss.qualcomm.com",
        "time": "Mon Aug 24 11:59:08 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 11:05:34 2026 -0700"
      },
      "message": "net: stmmac: drop gso_enabled_types and rely on netdev features\n\nThe gso_enabled_types field is used by stmmac_xmit() to decide whether a\nGSO skb should be passed to stmmac_tso_xmit(). It is updated in\nstmmac_set_features() based solely on NETIF_F_TSO, so disabling IPv4\nTSO while keeping IPv6 TSO (NETIF_F_TSO6) enabled zeroes the mask. As a\nresult IPv6 GSO frames, which the networking stack still generates since\nNETIF_F_TSO6 is enabled, fall through to the non-TSO xmit path where\nthey are not handled.\n\nThe networking stack already manages the GSO logic: a GSO skb is only\ndelivered to the driver when the matching offload feature (NETIF_F_TSO,\nNETIF_F_TSO6 or NETIF_F_GSO_UDP_L4) is enabled, otherwise the frame is\nsegmented in software before reaching ndo_start_xmit().\nstmmac_features_check() also validates each GSO frame against the TSO\nhardware constraints and falls back to software GSO when they are not met.\n\nDrop the gso_enabled_types field and rely on skb_is_gso() in\nstmmac_xmit() instead, which correctly routes IPv6 GSO frames to the TSO\npath when NETIF_F_TSO is disabled. This also removes the data race\nbetween stmmac_set_gso_types(), called from the feature-set path, and\nthe lockless read of gso_enabled_types in stmmac_xmit().\n\nFixes: 2e4082e4b739 (\"net: stmmac: simplify GSO/TSO test in stmmac_xmit()\")\nSigned-off-by: Lorenzo Bianconi \u003clorenzo.bianconi@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260824-stmmac-fix-tso6-features-v3-1-c73a7a4a0ec7@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6fe66698b959357c8f780fd21c809b2d83d2a7ee",
      "tree": "df0ca950aa3af07e2ef623238401ff4587ec522e",
      "parents": [
        "e2a6641e3bfde58f2284f9859c2b0fdcc6d1c0da",
        "96e8cb5527ce50c024a8e2d22d2bfedeccaf97d0"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:32 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:33 2026 -0700"
      },
      "message": "Merge branch \u0027net-stmmac-more-selftest-related-fixes\u0027\n\nMaxime Chevallier says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: stmmac: More selftest related fixes\n\nThis series addresses some (but not all) issues found while running the\nethtool selftest on various stmmac platforms. As a reminder, ethtool\nselftest are run with \u0027ethtool -t ethX\u0027, and for stmmac the goal is to test\nhardware features and bugs from the IP integration in the platform.\n\nI\u0027ve been running this on :\n\n - Altera CycloneV (dwmac-socfpga, dwmac1000 IP, v3.70a)\n - NXP imx8mp (dwmac-imx, dwmac4, v5.10a)\n - Allwinner H2S (dwmac-sun8i, dwmac1000)\n - Amlogic S905X3 (dwmac-meson8b, dwmac1000, v3.70a)\n - STM32mp157a (dwmac-stm32, dwmac4, v4.20a)\n - SiFive JH7110 (dwmac-starfive, dwmac4, v5.20)\n\nHere\u0027s the results before this series, noting that some bugs were already\nfixed, some are ongoing (cf. the IP proto patch here [1])\n\n[1] : https://lore.kernel.org/netdev/20260825211748.360935-1-maxime.chevallier@bootlin.com/\n\nTests are OK if return is 0 or -95 (-EOPNOTSUPP), tests are KO otherwise\n\nTest                     imx   socfpga   sun8i   meson8b   stm32 starfive\nMAC Loopback              0      0        0        0        0       0\nMMC Counters              0      0        -95      -22      0       -22\nEEE                       -95    -95      -95      -95      -95     -95\nHash Filter MC            0      0        -95      0        0       0\nPerfect Filter UC         0      0        0        0        0       0\nMC Filter                 0      0        -95      0        0       0\nUC Filter                 0      0        -95      -22      0       0\nFlow Control              -110   0        -110     0        0       -110\nRSS                       -95    -95      -95      -95      -95     -95\nVLAN Filtering            -110   -95      -95      -95      -110    -110\nVLAN Filtering (perf)     -110   -95      -95      -95      -110    -110\nDouble VLAN Filter        -110   -95      -95      -95      -110    -110\nDouble VLAN Filter (perf) -110   -95      -95      -95      -110    -110\nFlexible RX Parser        0      -95      -95      -95      -95     -95\nSA Insertion (desc)       0      -95      -95      -95      0       0\nSA Replacement (desc)     0      -95      -95      -95      0       0\nSA Insertion (reg         0      -95      -95      -95      0       0\nSA Replacement (reg)      0      -95      -95      -95      0       0\nVLAN TX Insertion         -110   -95      -95      -95      -110    -110\nSVLAN TX Insertion        -110   -95      -95      -95      -110    -95\nL3 DA Filtering           0      -95      -95      -95      -95     -95\nL3 SA Filtering           0      -95      -95      -95      -95     -95\nL4 DA TCP Filtering       0      -95      -95      -95      -95     -95\nL4 SA TCP Filtering       0      -95      -95      -95      -95     -95\nL4 DA UDP Filtering       0      -95      -95      -95      -95     -95\nL4 SA UDP Filtering       0      -95      -95      -95      -95     -95\nARP Offload               -95    -95      -95      -95      -110    -110\nJumbo Frame               0      0        0        0        0       0\nMultichannel Jumbo        0      -95      -95      -95      -95     -95\nSplit Header             -95     -95      -95      -95      -95     -95\nTBS (ETF Scheduler)      -95     -95      -95      -95      -95     -95\n\nSo, only sogfpga is all OK (in all fairness, it doesn\u0027t support much)\n\nSeveral issues :\n\n - MMC test failing on starfive and meson8b, solved by patch 1\n\nMMC counters maintained by the MAC are optional, which one is implemented\ndepends on how the IP is synthesized. On starfive and meson8b, the counter\nused by the selftest to validate the MMC counters feature isn\u0027t implemented.\n\nSolved by adding other counters in the validation step, kinda fragile as\nthis doesn\u0027t guarantee this will work on all platforms.\n\n - Flow control test failing on starfive, imx8mp, sun8i, solved by patch 6\n\nTurns out these platforms actually never emit any Pause frame, as they don\u0027t\nhave enough room in their per-queue RX Fifo. They do correctly process RX\nPause frames. The fix isn\u0027t to change the advertised pauseparams, as the\npause negotiation process based on MAC capabilities doesn\u0027t allow us to\nsay we \"just\" support RX pause, so let\u0027s just not run the Pause tests if\nthe RX fifo is too small.\n\n - UC filter failing on meson8b, fixed by patches 2,3,4 and 5\n\nThis one is quite the rabbit hole, and is a combination of multiple issues.\n\n - Unicast filtering uses the same filter (perfect filter) to allow the\n   primary MAC address and the secondary addresses (dev-\u003euc) to flow\n   through the interface. That means if we have say 64 slots in the\n   perfect filter, only 63 can be used for the dev-\u003euc list, as the first\n   entry stores the MAC address. If the filter is full, we switch to UC\n   promisc mode, were we let all UC frames flow. There\u0027s an off-by-one\n   error in dwmac1000, dwmac4 and dwxgmac2.\n\n - The selftest itself needs an empty slot in the filter, so it has to\n   check that sizeof(dev-\u003euc) is $number_of_slots - 2 (one for primary\n   MAC, one for the test). There\u0027s an off-by-two error in the selftest.\n\n - This leads to an interesting finding (not addressed by this series) :\n\n   The size of the perfect filter isn\u0027t reported by the HW, so it comes\n   from firmware (snps,perfect-filter-entries). A lot of platforms don\u0027t\n   specify that in DT (e.g. imx8mp doesn\u0027t, it has 128 entries but the\n   driver thinks there\u0027s only 1...). I\u0027ve reached out to Synopsys to\n   see if there\u0027s some sane default we could use on dwmac4, if anyone\n   has a dwmac4 databook I\u0027d appreciate if you could look this up, as I\n   don\u0027t have access to them, I\u0027m not a vendor... Otherwise, we\u0027ll have\n   to patch all the .dtsi if we want to avoid going in UC promisc as\n   soon as we add an entry in dev-\u003euc.\n\nAfter this series, socfpga, starfive and sun8i are all OK :)\n\nSome issues are still out there, the VLAN filtering and tagging fails on\nimx8mp and stm32 (so, dwmac4) butI haven\u0027t got there yet.\n\nARP offload doesn\u0027t work on stm32mp157a and starfive JH7110 either.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260826140500.616466-1-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "96e8cb5527ce50c024a8e2d22d2bfedeccaf97d0",
      "tree": "df0ca950aa3af07e2ef623238401ff4587ec522e",
      "parents": [
        "cd8c3b2752c684141eab2282e294cae2971a9759"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:58 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:28 2026 -0700"
      },
      "message": "net: stmmac: selftests: Don\u0027t test flow control for small rx fifos\n\nOn dwmac1000, dwmac4 and dwxgmac, we only emit pause frames if there\u0027s\nat least 4096 bytes in each queue\u0027s fifo.\n\nThe phylink mac capabilities are still MAC_ASYM_PAUSE | MAC_SYM_PAUSE as\notherwise we won\u0027t be able to negotiate \u0027rx on\u0027 pause. ASYM only will\nprevent negotiating \u0027rx off tx on\u0027, while SYM only doesn\u0027t really\nmatche the reality (not symmetric if we can only do RX pause).\n\nFixes: 091810dbded9 (\"net: stmmac: Introduce selftests support\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-7-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "cd8c3b2752c684141eab2282e294cae2971a9759",
      "tree": "1434c70198829dd1197d5ff129f94792f40170e1",
      "parents": [
        "2739d6f9a2b8729b0d85cbe0dc93e1d68670b6f2"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:57 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:28 2026 -0700"
      },
      "message": "net: stmmac: selftests: Account for the UC filter list for filtering tests\n\nOn dwmac, one of the Unicast filter entries is used to store the local\nHW addr. This means that we have to use promisc mode for any kind of\nunicast filtering if we only have one slot in our unicast filter.\n\nThe number of slots available depends on how the IP is integrated, and\nwe can\u0027t autodiscover how many of these slots we have available, so\nthe DT property snps,perfect-filter-entries can be used to specify how\nmany are available.\n\nMost IP variants default to 1 if this isn\u0027t specified, which is the case\nfor the amlogic variants (in this case, S905X3).\n\nThe stmmac selftests for UC filtering look if we have enough slots in\nthe filter to store the dev-\u003euc list, but doesn\u0027t account for the\ndevice\u0027s own MAC address. The dev-\u003euc list\u0027s size we get with\nnetdev_uc_count() also doesn\u0027t account for the HW addr.\n\nAs the selftest only requires one available slot, in the case of\nsingle-slot platforms, that means we erroneously consider we have enough\nroom for the test, when we actually don\u0027t, and the filtering test fails.\n\nFixes: 091810dbded9 (\"net: stmmac: Introduce selftests support\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-6-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2739d6f9a2b8729b0d85cbe0dc93e1d68670b6f2",
      "tree": "4cfe126c634e3665e48a776f6b54c1c723e75053",
      "parents": [
        "82187f42c014d22520b9c3c4e2cfb519223fb29b"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:56 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:28 2026 -0700"
      },
      "message": "net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering\n\nThe same filter slots are used to store the main MAC address as well as\nthe address for the unicast filter. Let\u0027s account for that when deciding\nwhether or not to use promisc when programming the UC list in hardware.\n\nFixes: 0efedbf11f07 (\"net: stmmac: xgmac: Fix XGMAC selftests\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-5-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "82187f42c014d22520b9c3c4e2cfb519223fb29b",
      "tree": "1053fe32ba2145ae07d95e1af9a668f1dd309504",
      "parents": [
        "9698b6da3714fd2ef47846cb63098d2b2d252e25"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:55 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:27 2026 -0700"
      },
      "message": "net: stmmac: dwmac4: Account for the primary MAC address for UC filtering\n\nThe same filter slots are used to store the main MAC address as well as\nthe address for the unicast filter. Let\u0027s account for that when deciding\nwhether or not to use promisc when programming the UC list in hardware.\n\nFixes: 477286b53f55 (\"stmmac: add GMAC4 core support\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-4-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9698b6da3714fd2ef47846cb63098d2b2d252e25",
      "tree": "b371b2a3ce4612402d01d95da627ad3d16fccb76",
      "parents": [
        "d29b399150b07796dfa81d8778d4804c08c2a41d"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:54 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:27 2026 -0700"
      },
      "message": "net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering\n\nThe same filter slots are used to store the main MAC address as well as\nthe address for the unicast filter. Let\u0027s account for that when deciding\nwhether or not to use promisc when programming the UC list in hardware.\n\nFixes: 47dd7a540b8a (\"net: add support for STMicroelectronics Ethernet controllers.\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-3-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "d29b399150b07796dfa81d8778d4804c08c2a41d",
      "tree": "55c37e7d2d0de46824b950032dac05041f8c48d6",
      "parents": [
        "e2a6641e3bfde58f2284f9859c2b0fdcc6d1c0da"
      ],
      "author": {
        "name": "Maxime Chevallier",
        "email": "maxime.chevallier@bootlin.com",
        "time": "Wed Aug 26 16:04:53 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 10:53:27 2026 -0700"
      },
      "message": "net: stmmac: selftests: Check multiple MMC counters\n\nThe MMC counters report MAC statistics. Multiple counters can be\nenabled when the IP is integrated, however there\u0027s no way to know\nexactly which ones. Un-implemented counters seem to report 0.\n\nIt was found that on StarFive JH7110 and Amlogic SM1, the counter that\u0027s\nused by the selftest (mmc_tx_framecount_g) isn\u0027t implemented, triggering\nan MMC selftest failure.\n\nBoth the above SoCs seem to implement mmc_rx_framecount_gb, let\u0027s use\nthis counter as well for MMC counter validation.\n\nNote that this doesn\u0027t guarantee that we won\u0027t encounter the same issue\nagain if another IP implements yet another set of counters that don\u0027t\ninclude that new one.\n\nIf the game of whack-a-mole with implemented counters becomes too hard to\nmaintain, we may simply consider removing the MMC selftest entirely.\n\nFixes: 091810dbded9 (\"net: stmmac: Introduce selftests support\")\nSigned-off-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nLink: https://patch.msgid.link/20260826140500.616466-2-maxime.chevallier@bootlin.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "79b4f3baae2fa65060c30f827e3c0e8f1db99f98",
      "tree": "0ca4815b6f7e61a17343ae20b672744a10badb8e",
      "parents": [
        "18fbf5151d2c0bfe433c7428eef03cabf5fdb2fa",
        "9d0e4b1ae5b045a2c92b0b9a1c3b268191c219d9"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 10:45:08 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 10:45:08 2026 -0700"
      },
      "message": "Merge tag \u0027mfd-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd\n\nPull MFD updates from Lee Jones:\n \"New Support \u0026 Features:\n   - MediaTek MT6397: Add mt6323 AUXADC support\n   - MediaTek MT6397: Add mt6323 EFUSE support\n   - Spreadtrum SC27xx: Add SC2730 regulator cell\n\n  Improvements \u0026 Fixes:\n   - Apple SMC: Fix key count endianness annotation\n   - Azoteq IQS62x: Reject zero-length firmware records\n   - ChromeOS EC: Introduce cros_ec_read_features helper and read\n     features during probe to catch transfer errors\n   - Cirrus Logic CS42L43: Fix regmap defaults ordering\n   - Cirrus Logic CS42L43: Remove redundant NULL checks on SoundWire\n   - Congatec Board Controller: Fix teardown ordering in cgbc_remove()\n   - HP iPAQ Micro: Fix out-of-bounds stack read in ipaq_micro_str\n   - Marvell 88PM886: Initialize the battery page\n   - QNAP MCU: Keep the reply buffer alive past a command timeout\n   - RAVE SP: Validate received frame payload lengths\n   - Silicon Labs Si476x: Drop duplicate NULL checks\n   - Silicon Labs Si476x: Modernize GPIO handling\n   - Silicon Motion SM501: Fix potential memory leaks during remove\n   - UCB1x00: Convert Assabet gpio-keys to use software nodes and\n     register software node for GPIO controller\n   - Viperboard: Fix native fields type in structures as little-endian\n   - Viperboard: Remove redundant NULL check before kfree()\n   - X-Powers AXP20x: Preserve other control bits when powering off\n\n  Cleanups \u0026 Refactoring:\n   - Core: Drop unused assignment of spi_device_id driver data\n   - Core: Initialize spi_device_id arrays using member names\n   - Core: Unify style of spi_device_id arrays\n   - Maintainers: Add Intel LPSS section to follow the changes\n   - Maintainers: Add a mailing list entry to MFD\n   - Cirrus Logic CS42L43: Format sdw_device_id table\n   - Cirrus Logic CS42L43: Use new SoundWire enumeration helper\n   - ROHM PMIC: Factor out power button registration and convert\n     gpio-keys to use software nodes\n   - ST-Ericsson DB8500: Fold dbx500 header into db8500\n\n  Device Tree Binding Updates:\n   - Core: Add techvision vendor prefix\n   - Marvell 88PM886: Allow vbus regulator\n   - MediaTek MT8195 SCP: Add support for MT8189 SoC\n   - Qualcomm SPMI PMIC: Document PMG1110\n   - Qualcomm SPMI PMIC: Document haptics device\n   - Qualcomm TCSR: Add compatible for Hawi and Maili SoCs\n   - Qualcomm TCSR: Add compatible for Shikra\n   - Qualcomm TCSR: Document the IPQ9650 TCSR block\n   - STMicroelectronics STMPE: Fix typo st,stmpe601 (should be\n     st,stmpe610)\n   - Syscon: Add ESWIN EIC7700 compatible\n   - Syscon: Allow syscon compatible for Loongson-2K0300 chip id\n   - Syscon: Disallow simple-bus with syscon\n   - Syscon: Drop custom select for older dtschema\n   - TI OMAP USBHS TLL: Convert to DT schema\"\n\n* tag \u0027mfd-next-7.3\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/lee/mfd: (45 commits)\n  mfd: cs42l43: Fix regmap defaults ordering\n  dt-bindings: mfd: syscon: Allow syscon compatible for Loongson-2K0300 chip id\n  dt-bindings: mfd: syscon: Add ESWIN EIC7700 compatible\n  mfd: qnap-mcu: keep the reply buffer alive past a command timeout\n  dt-bindings: mfd: qcom,tcsr: Document the IPQ9650 TCSR block\n  mfd: macsmc: Fix key count endianness annotation\n  dt-bindings: mfd: qcom,spmi-pmic: Document haptics device\n  mfd: iqs62x: Reject zero-length firmware records\n  mfd: rave-sp: validate received frame payload lengths\n  mfd: sm501: Fix potential memory leaks during remove\n  mfd: viperboard: Fix native fields type in structures as little-endian\n  mfd: si476x-i2c: Get rid of duplicate NULL checks\n  dt-bindings: mfd: Convert OMAP USB TLL to DT schema\n  mfd: cgbc: Fix teardown ordering in cgbc_remove()\n  mfd: mt6397-core: Add mt6323 AUXADC support\n  dt-bindings: mfd: qcom,tcsr: Add compatible for Hawi and Maili SoCs\n  mfd: rohm: Factor out power button registration\n  mfd: ucb1x00: Convert Assabet gpio-keys to use software nodes\n  mfd: ucb1x00: Register software node for GPIO controller\n  mfd: cs42l43: Tidy up formatting on sdw_device_id table\n  ...\n"
    },
    {
      "commit": "18fbf5151d2c0bfe433c7428eef03cabf5fdb2fa",
      "tree": "6e151850bf46f900bbf9dcc682e0c75d91924865",
      "parents": [
        "5e6ff28676dd92a608eb00eeb8d1319ad34024dc",
        "0685630fdccb62dcb0e3f44525a40578da5f6dc8"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 09:17:06 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Aug 27 09:17:06 2026 -0700"
      },
      "message": "Merge tag \u0027mm-stable-2026-08-26-15-22\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm\n\nPull more MM updates from Andrew Morton:\n\n - \"mm/rmap: index MAP_PRIVATE file-backed folios by anonymous pgoff\"\n   (Lorenzo Stoakes)\n\n   Index MAP_PRIVATE file-backed folios by their anonymous page offset\n   to resolve confusion around reverse mapping for zeroed and CoW\u0027d\n   file-backed memory.\n\n   Use this new VMA anonymous page offset tracking to eliminate index\n   conflicts and lay the foundation for scalable CoW performance\n   improvements.\n\n - \"promote mapped executable folios after first usage for MGLRU\"\n   (Baolin Wang)\n\n   Make MGLRU\u0027s protection of mapped executable file folios more\n   reliable. Follow the classical LRU\u0027s logic, promoting mapped\n   executable file folios after their first usage to give executable\n   code a better chance to stay in memory and improve workload\n   performance.\n\n - \"mm: vmscan: fix node reclaim ignoring swappiness parameter\" (Ridong\n   Chen)\n\n   Fix per-node proactive reclaim interface\u0027s ignoring the swappiness\n   parameter when CONFIG_MEMCG is disabled by consolidating\n   sc_swappiness() into a single function that checks\n   proactive_swappiness regardless of kernel configuration.\n\n - \"mm/vmscan: reduce lru_lock contention via vmstat-derived\n   scan-balance cost\" (Usama Arif)\n\n   Reduce lru_lock contention in the reclaim path by deriving\n   scan-balance costs from vmstat counters rather than lock-acquired\n   producer updates.\n\n   Read and decay these cost signals on the reclaim side under a\n   dedicated per-lruvec lock, reducing total LRU lock wait time by over\n   60% without impacting scan throughput.\n\n - \"zram: fix zram issues reported by sashiko\" (Sergey Senozhatsky)\n\n   Fix two low-risk zram bugs which Sashiko spotted in drive-by review.\n\n - \"Honor XA_FLAGS_ACCOUNT in xas_split_alloc() and charge to folio\u0027s\n   memcg\" (Zi Yan)\n\n   Fix xas_split_alloc() by enabling target folio memcg charging during\n   splits and adding the missing __GFP_ACCOUNT flag for proper XArray\n   node memory accounting.\n\n - \"selftests/mm: use pattern matching in .gitignore\" (Pratyush Mallick)\n\n   Replace hardcoded binary names in selftests/mm/.gitignore with a\n   generic pattern-matching rule to automatically ignore generated test\n   files and avoid manual updates when adding new tests.\n\n - \"mm/page_ext: remove pgdat_page_ext_init()\" (Sang-Heon Jeon)\n\n   Make the incompatibility between FLATMEM and NUMA explicit in\n   mm/Kconfig and remove the unused pgdat_page_ext_init() function.\n\n - \"zram: fix zstd error paths and add parameter validation\" (Haoqin\n   Huang)\n\n   Clean up zram compression backends by removing redundant error\n   cleanup, adding parameter and dictionary validation, auto-prefixing\n   algorithm error logs, and resetting parameters prior to\n   reinitialization.\n\n - \"zram: fix stale scan bounds after reinitialization\" (Longlong Xia)\n\n   Prevent out-of-bounds slot accesses during concurrent zram resets by\n   moving table scan bound calculations under dev_lock in\n   writeback_store() and read_block_state().\n\n - \"add anon mTHP collapse test cases\" (Baolin Wang)\n\n   Extend selftests helper functions to support arbitrary page orders\n   and add new test cases and options for mTHP collapse in khugepaged.\n\n - \"selftests/mm: Handle unsupported and transient test conditions\"\n   (Muhammad Usama Anjum)\n\n   Update MM selftests to report a SKIP status instead of a failure when\n   required kernel or filesystem features are unsupported, while adding\n   retry logic for transient page migration errors.\n\n - \"mm/zswap: Fixes and improves the zswap shrink\" (Hao Jia)\n\n   Fix the missing zswap global shrinker when CONFIG_MEMCG is disabled\n   and extend shrink_memcg() to support batch writeback for improved\n   writeback efficiency.\n\n - \"alloc_tag: introduce IOCTL-based filtering for MAP\" (Suren\n   Baghdasaryan)\n\n   Introduce an IOCTL-based binary interface for memory allocation\n   profiling that enables kernel-side filtering before per-CPU counter\n   aggregation.\n\n   This eliminates the text-parsing overhead of /proc/allocinfo and\n   provides up to a 20x speedup by transferring only filtered allocation\n   data to userspace.\n\n - \"better block swap batching and a different take on swap_ops v5\"\n   (Christoph Hellwig)\n\n   Refactor block swap I/O to use swap_iocb for batching instead of\n   single-bio requests and rebase the swap_ops interface, achieving\n   faster swap throughput during kernel builds.\n\n - \"mm: kmemleak: reduce transient false positives by confirming leaks\"\n   (Catalin Marinas)\n\n   Reduce false-positive kmemleak reports by combining two kmemleak\n   enhancements that add a second confirmation scan and a configurable\n   minimum unreferenced scan count module parameter.\n\n - \"mm: kmemleak: default min_unref_scans to 2 for verbose kernels\"\n   (Breno Leitao)\n\n   Auto-scanning kernels can generate false-positive memory leak reports\n   on single scans, so this patch defaults min_unref_scans to 2 when\n   CONFIG_DEBUG_KMEMLEAK_VERBOSE is enabled to require a second\n   confirming scan.\n\n - \"swap_ops updates\" (Christoph Hellwig)\n\n   Batching I/O for synchronous swap devices causes performance\n   regressions and filesystem-based swap suffers from double-indirection\n   overhead. This series resolves both issues by reintroducing per-folio\n   writes for synchronous swap and allowing filesystems to directly\n   export their own swap_ops.\n\n - \"mm/khugepaged: several cleanups\" (Nico Pache)\n\n   khugepaged accumulated redundant state-checking patterns and outdated\n   comments following mTHP integration. Introduce dedicated helpers for\n   PTE validation and event counting while refreshing the internal\n   documentation.\n\n - \"maple_tree: lock checking and clean ups\" (Liam Howlett)\n\n   Syzbot reports incorrectly blame memory management exit paths for\n   locking bugs, maple tree erase operations risk allocation failures\n   without gfp flags and internal documentation lacks clarity.\n\n   Improve lock error detection, update docs, fix race and allocation\n   edge cases and optimize erase allocations using a fallback to\n   GFP_KERNEL | GFP_NOFAIL.\n\n* tag \u0027mm-stable-2026-08-26-15-22\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm: (172 commits)\n  selftests/proc: make proc-maps-race work with READ_IMPLIES_EXEC\n  memcg: move LRU size accounting on reparenting instead of copying it\n  mm/vmscan: fix comment logic in balance_pgdat\n  maple_tree: add helper mas_make_walkable()\n  maple_tree: avoid extra gap calculation\n  maple_tree: fix argument name in header\n  maple_tree: change two GFP flags in tests\n  maple_tree: document erase and allocations better\n  maple_tree: avoid mas_erase() and mtree_erase() failures\n  maple_tree: document that erase may use GFP_KERNEL for allocations\n  maple_tree: catch race in mas_alloc_cyclic()\n  maple_tree: add bulk parent set helper\n  maple_tree: micro optimisation of mas_wr_store_type()\n  maple_tree: optimise mas_wr_node_store() when not in rcu mode\n  maple_tree: use prefetched value in mas_wr_store_type()\n  maple_tree: clarify comments on mas_nomem()\n  maple_tree: drop MAPLE_ALLOC_SLOTS\n  maple_tree: drop dead code from mas_extend_spanning_null()\n  maple_tree: documentation fix\n  maple_tree: add write lock checking with lockdep sequence numbers\n  ...\n"
    },
    {
      "commit": "a62212b35a214c2ff3bd1c785a440d7ad8205ec9",
      "tree": "c20b0b4ca076abb893d4587f7a65e60b5c1e72c2",
      "parents": [
        "244abef7f280a6a84297bfab5fd2e77147bc419a"
      ],
      "author": {
        "name": "Anoop Vijay",
        "email": "anoop.c.vijay@intel.com",
        "time": "Tue Aug 25 10:28:28 2026 -0700"
      },
      "committer": {
        "name": "Rodrigo Vivi",
        "email": "rodrigo.vivi@intel.com",
        "time": "Thu Aug 27 12:00:17 2026 -0400"
      },
      "message": "drm/xe/sysctrl: Read mailbox phase bit from hardware\n\nThe mailbox PHASE bit in SYSCTRL_MB_CTRL is toggled per-message and\nwas tracked in software as sc-\u003ephase_bit, reset to 0 on error paths.\nIf the cached value ever drifts from what the hardware last saw, all\nfollowing messages carry the wrong phase and get silently misread by\nfirmware.\n\nDrop the cache and read PHASE directly from SYSCTRL_MB_CTRL before\neach frame instead, removing xe_sysctrl_mailbox_init() and its call\nsites along with it.\n\nFixes: 1f95f618182b (\"drm/xe/xe_sysctrl: Add System Controller mailbox communication support\")\nSigned-off-by: Anoop Vijay \u003canoop.c.vijay@intel.com\u003e\nReviewed-by: Umesh Nerlige Ramappa \u003cumesh.nerlige.ramappa@intel.com\u003e\nReviewed-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nLink: https://patch.msgid.link/20260825172827.3801591-2-anoop.c.vijay@intel.com\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n(cherry picked from commit 04984fcdbf6876c940c01026a7404c1e9cc91ba7)\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n"
    },
    {
      "commit": "244abef7f280a6a84297bfab5fd2e77147bc419a",
      "tree": "ca22aa0a9e3eb25312a09480aceea23fd5ae5b70",
      "parents": [
        "f43fa4b8522ba6038b77e86e5f0d94be35effcde"
      ],
      "author": {
        "name": "Heikki Krogerus",
        "email": "heikki.krogerus@linux.intel.com",
        "time": "Tue Aug 11 14:10:08 2026 +0200"
      },
      "committer": {
        "name": "Rodrigo Vivi",
        "email": "rodrigo.vivi@intel.com",
        "time": "Thu Aug 27 12:00:17 2026 -0400"
      },
      "message": "drm/xe/i2c: Keep the i2c controller always enabled\n\nSome platforms make an assumption that the i2c controller\u0027s\nenabled state indicates also the power state of the\ncontroller. This can create a problem when the controller is\nin disabled state, because the hardware may assume\nincorrectly that it is then also in low-power state.\n\nTo fix this, the controller is kept enabled by taking over\nthe IC_ENABLE register. The controller has to be disabled\nwhen the configuration is updated and when the target\naddress or the slave address are assigned, so disabling it\nwhen IC_CON, IC_TAR or IC_SAR registers are programmed, and\nthen re-enabling it again.\n\nFixes: f0e53aadd702 (\"drm/xe: Support for I2C attached MCUs\")\nCc: stable@vger.kernel.org\nSigned-off-by: Heikki Krogerus \u003cheikki.krogerus@linux.intel.com\u003e\nReviewed-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\nLink: https://patch.msgid.link/20260811121008.1493015-4-heikki.krogerus@linux.intel.com\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n(cherry picked from commit 76cc14e2faed1adae20f4ee144ead0e3a7566c49)\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n"
    },
    {
      "commit": "f43fa4b8522ba6038b77e86e5f0d94be35effcde",
      "tree": "6b77a50935c50cc89d7d8b1ac22401391e6d4b6d",
      "parents": [
        "874ef9a6f2fc45d3f6021842d92fa5420fa4c825"
      ],
      "author": {
        "name": "Heikki Krogerus",
        "email": "heikki.krogerus@linux.intel.com",
        "time": "Tue Aug 11 14:10:07 2026 +0200"
      },
      "committer": {
        "name": "Rodrigo Vivi",
        "email": "rodrigo.vivi@intel.com",
        "time": "Thu Aug 27 12:00:16 2026 -0400"
      },
      "message": "drm/xe/i2c: Fix the interrupt handling\n\nThe platforms that support the interrupt from the I2C\nadapter can not handle the amount of interrupts the adapter\ngenerates because of the way the IRQ is routed in the\nhardware. The I2C controller driver has to be kept in\npolling mode because of that.\n\nThe AMC MCU can still generate critical alerts that have to\nbe handled. The interrupt from SMBus Alert is left enabled\nand handled separately in the Xe. The alerts from the AMC\nwill cause the device to be declared wedged for now.\n\nFixes: f0e53aadd702 (\"drm/xe: Support for I2C attached MCUs\")\nCc: stable@vger.kernel.org\nReviewed-by: Raag Jadav \u003craag.jadav@intel.com\u003e\nCo-developed-by: Ramesh Babu B \u003cramesh.babu.b@intel.com\u003e\nSigned-off-by: Ramesh Babu B \u003cramesh.babu.b@intel.com\u003e\nSigned-off-by: Heikki Krogerus \u003cheikki.krogerus@linux.intel.com\u003e\nLink: https://patch.msgid.link/20260811121008.1493015-3-heikki.krogerus@linux.intel.com\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n(cherry picked from commit a55b76b8bc2c49b11d753c1c6d06ec3a2c61c85e)\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n"
    },
    {
      "commit": "874ef9a6f2fc45d3f6021842d92fa5420fa4c825",
      "tree": "96a37dc656e3b466662a38f6623a9dadebd903bc",
      "parents": [
        "5e977521d21717edb8e91d004434697d6e3f248c"
      ],
      "author": {
        "name": "Heikki Krogerus",
        "email": "heikki.krogerus@linux.intel.com",
        "time": "Tue Aug 11 14:10:06 2026 +0200"
      },
      "committer": {
        "name": "Rodrigo Vivi",
        "email": "rodrigo.vivi@intel.com",
        "time": "Thu Aug 27 12:00:16 2026 -0400"
      },
      "message": "i2c: designware: Global register definitions\n\nMoving the register definitions to a global header file\ninclude/linux/designware_i2c.h. That removes the need to\nduplicate them in the adaptation layers for this driver\noutside of drivers/i2c/busses/. There is at least one of\nthose in drivers/gpu/drm/xe/xe_i2c.c.\n\nSuggested-by: Andy Shevchenko \u003candriy.shevchenko@linux.intel.com\u003e\nSuggested-by: Raag Jadav \u003craag.jadav@intel.com\u003e\nReviewed-by: Raag Jadav \u003craag.jadav@intel.com\u003e\nReviewed-by: Mika Westerberg \u003cmika.westerberg@linux.intel.com\u003e\nReviewed-by: Andy Shevchenko \u003candriy.shevchenko@linux.intel.com\u003e\nSigned-off-by: Heikki Krogerus \u003cheikki.krogerus@linux.intel.com\u003e\nAcked-by: Mika Westerberg \u003cmika.westerberg@linux.intel.com\u003e\nLink: https://patch.msgid.link/20260811121008.1493015-2-heikki.krogerus@linux.intel.com\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n(cherry picked from commit 2ab2fb31411a494e4579dfacda986a2672f80e65)\nSigned-off-by: Rodrigo Vivi \u003crodrigo.vivi@intel.com\u003e\n"
    },
    {
      "commit": "e2a6641e3bfde58f2284f9859c2b0fdcc6d1c0da",
      "tree": "b2562439718f723a8edc3c9e1c80ecdd868b2fdf",
      "parents": [
        "6fe7e31a45e3418a39e6343a85126124feec1c2f",
        "1d62b83fb75125344693db8ebf970653db529f40"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:30 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:30 2026 -0700"
      },
      "message": "Merge branch \u0027improve-stability-of-big_tcp_tunnels-sh-selftest\u0027\n\nAlice Mikityanska says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nImprove stability of big_tcp_tunnels.sh selftest\n\nThis series addresses flakiness of big_tcp_tunnels.sh discussed at:\n\nhttps://lore.kernel.org/netdev/349c582c-73e3-468c-91cd-ad6cc3562700@app.fastmail.com/\n\nLower the thresholds to avoid failures like this (number of packets\nbelow the threshold):\n\nhttps://netdev-ctrl.bots.linux.dev/logview.html?f\u003d/logs/vmksft/net-dbg/results/754376/28-big-tcp-tunnels-sh/stdout\n\nTweak tcp_min_tso_segs and initcwnd to avoid failures like this (BIG TCP\ndoesn\u0027t kick in in slow configurations):\n\nhttps://netdev-ctrl.bots.linux.dev/logview.html?f\u003d/logs/vmksft/net-dbg/results/751124/21-big-tcp-tunnels-sh/stdout\n\nv2 changes: Use $KSFT_MACHINE_SLOW instead of probing kernel config.\n\nv1: https://lore.kernel.org/netdev/20260814194124.3102581-1-alice.kernel@fastmail.im/\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260822120308.1165200-1-alice.kernel@fastmail.im\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "1d62b83fb75125344693db8ebf970653db529f40",
      "tree": "b2562439718f723a8edc3c9e1c80ecdd868b2fdf",
      "parents": [
        "f7d0400bd3452ed6915592b1929ba1d39d8e6552"
      ],
      "author": {
        "name": "Alice Mikityanska",
        "email": "alice@isovalent.com",
        "time": "Sat Aug 22 15:03:08 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:28 2026 -0700"
      },
      "message": "selftests: net: Fix slow configurations in big_tcp_tunnels.sh\n\nThe combination of checksum offload disabled (that causes software GSO)\nand a debug kernel is inherently slow. Depending on the CPU power and\nload, RTT may increase, limiting sk_pacing_rate, so tcp_tso_autosize\ncaps SKBs at around 40 segments, and zero BIG TCP packets are produced.\n\nIncrease sysctl net.ipv4.tcp_min_tso_segs and set a bigger initial value\nof CWND in these configurations to force BIG TCP.\n\nFixes: 5cb53743e1ff (\"selftests: net: Add a test for BIG TCP in UDP tunnels\")\nSigned-off-by: Alice Mikityanska \u003calice@isovalent.com\u003e\nAcked-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260822120308.1165200-5-alice.kernel@fastmail.im\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "f7d0400bd3452ed6915592b1929ba1d39d8e6552",
      "tree": "a8f4400a5684f4e3473b07d895007cf2974ec909",
      "parents": [
        "bb42c16f489f10144f7d2fbb1f57753f14e12ac8"
      ],
      "author": {
        "name": "Alice Mikityanska",
        "email": "alice@isovalent.com",
        "time": "Sat Aug 22 15:03:07 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:28 2026 -0700"
      },
      "message": "selftests: net: Lower threshold with csum offload off in big_tcp_tunnels.sh\n\nWith checksum offload disabled, much fewer BIG TCP packets are generated\ndue to overall loss of throughput. Use a separate threshold in these\ntests, which is 1/10 of the threshold set for the rest of tests.\n\nFixes: 5cb53743e1ff (\"selftests: net: Add a test for BIG TCP in UDP tunnels\")\nSigned-off-by: Alice Mikityanska \u003calice@isovalent.com\u003e\nAcked-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260822120308.1165200-4-alice.kernel@fastmail.im\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "bb42c16f489f10144f7d2fbb1f57753f14e12ac8",
      "tree": "39c5c7f0c188dbf5fff4bdb0fb0cffadf7ed8fe7",
      "parents": [
        "dc170da3347e0f7b6d120d13882c4e1f04ca00d6"
      ],
      "author": {
        "name": "Alice Mikityanska",
        "email": "alice@isovalent.com",
        "time": "Sat Aug 22 15:03:06 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:28 2026 -0700"
      },
      "message": "selftests: net: Lower threshold on debug kernels for big_tcp_tunnels.sh\n\nDebug kernels on upstream CI runners run slower and generate fewer BIG\nTCP packets, making the test flaky on upstream CI runners. Lower the\ndefault threshold for those kernels.\n\nFixes: 5cb53743e1ff (\"selftests: net: Add a test for BIG TCP in UDP tunnels\")\nSigned-off-by: Alice Mikityanska \u003calice@isovalent.com\u003e\nAcked-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260822120308.1165200-3-alice.kernel@fastmail.im\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "dc170da3347e0f7b6d120d13882c4e1f04ca00d6",
      "tree": "1a202d0047d1cabe72c54c570a540fb4eabd28e2",
      "parents": [
        "6fe7e31a45e3418a39e6343a85126124feec1c2f"
      ],
      "author": {
        "name": "Alice Mikityanska",
        "email": "alice@isovalent.com",
        "time": "Sat Aug 22 15:03:05 2026 +0300"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:42:28 2026 -0700"
      },
      "message": "selftests: net: Wait for netserver to launch\n\nUse wait_local_port_listen after starting netserver in\nbig_tcp_tunnels.sh to ensure it\u0027s listening when the test starts.\n\nFixes: 5cb53743e1ff (\"selftests: net: Add a test for BIG TCP in UDP tunnels\")\nSigned-off-by: Alice Mikityanska \u003calice@isovalent.com\u003e\nAcked-by: Matthieu Baerts (NGI0) \u003cmatttbe@kernel.org\u003e\nLink: https://patch.msgid.link/20260822120308.1165200-2-alice.kernel@fastmail.im\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "6fe7e31a45e3418a39e6343a85126124feec1c2f",
      "tree": "4e4488ea046ed2d0f089e08d5ef16c3e5c8956de",
      "parents": [
        "81eb1867e059bf1dbbfbba536385a5cb26f700cd"
      ],
      "author": {
        "name": "Daniel Pawlik",
        "email": "pawlik.dan@gmail.com",
        "time": "Thu Aug 20 10:59:40 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Aug 27 08:36:47 2026 -0700"
      },
      "message": "net: airoha: npu: fix missing streaming DMA mask\n\nThe driver calls dma_set_coherent_mask() but never dma_set_mask(),\nleaving the streaming DMA mask at the bus default. On the non-coherent\nEN7581 platform (Cortex-A53), this causes the NPU mailbox to hang\nafter approximately 41 calls when using streaming DMA mappings.\n\nReplace dma_set_coherent_mask() with dma_set_mask_and_coherent() to\nset both the streaming and coherent DMA masks, matching standard\ndriver practice.\n\nFixes: 6f884eb87a79 (\"net: airoha: Fix DMA direction for NPU mailbox buffer\")\nLink: https://patchwork.kernel.org/project/linux-mediatek/patch/20260814110017.2795022-1-pawlik.dan@gmail.com/\nLink: https://patchwork.kernel.org/project/linux-mediatek/patch/20260809152813.585797-1-pawlik.dan@gmail.com/\nLink: https://patchwork.kernel.org/project/linux-mediatek/patch/20260805070851.2885888-1-pawlik.dan@gmail.com/\nSigned-off-by: Daniel Pawlik \u003cpawlik.dan@gmail.com\u003e\nAcked-by: Lorenzo Bianconi \u003clorenzo@kernel.org\u003e\nLink: https://patch.msgid.link/20260820085941.380401-1-pawlik.dan@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f",
      "tree": "3323596b26642fd08d3f4960dbef413dfd51641d",
      "parents": [
        "fe66c3ff85e85d492673c6dc95c3d624a63e0282"
      ],
      "author": {
        "name": "Abdurrahman Hussain",
        "email": "abdurrahman@nexthop.ai",
        "time": "Wed Aug 05 13:31:00 2026 -0700"
      },
      "committer": {
        "name": "Rob Herring (Arm)",
        "email": "robh@kernel.org",
        "time": "Thu Aug 27 09:36:05 2026 -0500"
      },
      "message": "of: fix out-of-bounds read in of_alias_scan() stem parser\n\nThe stem parser tests isdigit(*(end - 1)) before checking end \u003e start\nand so reads one byte before the property name when the name is empty\nor all digits. Check the bound first.\n\nFixes: 611cad720148 (\"dt: add of_alias_scan and of_alias_get_id\")\nCc: stable@vger.kernel.org\nAssisted-by: Claude:claude-fable-5 [Claude Code]\nSigned-off-by: Abdurrahman Hussain \u003cabdurrahman@nexthop.ai\u003e\nReviewed-by: Geert Uytterhoeven \u003cgeert+renesas@glider.be\u003e\nLink: https://patch.msgid.link/20260805-nh-of-alias-overlay-v6-1-74f21d440819@nexthop.ai\nSigned-off-by: Rob Herring (Arm) \u003crobh@kernel.org\u003e\n"
    },
    {
      "commit": "2bd533739234d79b74afabfece1abfe9c6d52c83",
      "tree": "6bdf2023f559b97e7be0c0cde861816376ff2e1d",
      "parents": [
        "bb52892f9234e4ecd982fa51222aab33ce282f79"
      ],
      "author": {
        "name": "Muhammad Usama Anjum",
        "email": "usama.anjum@arm.com",
        "time": "Tue Aug 25 12:18:37 2026 +0100"
      },
      "committer": {
        "name": "Will Deacon",
        "email": "will@kernel.org",
        "time": "Thu Aug 27 14:18:39 2026 +0000"
      },
      "message": "selftests/arm64: Add MTE test config fragment\n\nThe arm64 selftest collection has no Kconfig fragment, so kernels built\nwith the selftest requirements are not guaranteed to provide the support\nused by these tests.\n\nAdd a fragment covering all tests in arm64.\n\nReviewed-by: Mark Brown \u003cbroonie@kernel.org\u003e\nSigned-off-by: Muhammad Usama Anjum \u003cusama.anjum@arm.com\u003e\nReviewed-by: Vincenzo Frascino \u003cvincenzo.frascino@arm.com\u003e\nSigned-off-by: Will Deacon \u003cwill@kernel.org\u003e\n"
    },
    {
      "commit": "bb52892f9234e4ecd982fa51222aab33ce282f79",
      "tree": "9c1a98eb29aad40e29e1bdc301d19c009feb5c59",
      "parents": [
        "1a0dba077f34a2f8faa98308d30d4b546d073145"
      ],
      "author": {
        "name": "Muhammad Usama Anjum",
        "email": "usama.anjum@arm.com",
        "time": "Tue Aug 25 12:18:36 2026 +0100"
      },
      "committer": {
        "name": "Will Deacon",
        "email": "will@kernel.org",
        "time": "Thu Aug 27 14:18:39 2026 +0000"
      },
      "message": "selftests/arm64: Fix MTE prctl TAP plan\n\nThe MTE prctl test emits one result from check_basic_read() followed by\none result for each of the seven entries in mte_modes[]. However, the TAP\nplan only accounts for the array entries, producing:\n\n  # Planned tests !\u003d run tests (7 !\u003d 8)\n\nInclude the basic read check in the plan so that all eight emitted results\nare declared.\n\nReviewed-by: Mark Brown \u003cbroonie@kernel.org\u003e\nFixes: 1f488fb91378 (\"kselftest/arm64/mte: Add MTE_STORE_ONLY testcases\")\nSigned-off-by: Muhammad Usama Anjum \u003cusama.anjum@arm.com\u003e\nReviewed-by: Vincenzo Frascino \u003cvincenzo.frascino@arm.com\u003e\nSigned-off-by: Will Deacon \u003cwill@kernel.org\u003e\n"
    },
    {
      "commit": "1a0dba077f34a2f8faa98308d30d4b546d073145",
      "tree": "1388c79eb7c04f76b6de598b7b907161173a1e85",
      "parents": [
        "8d2237e9d6902e234bb89aabb9cd6a9e91357223"
      ],
      "author": {
        "name": "Muhammad Usama Anjum",
        "email": "usama.anjum@arm.com",
        "time": "Tue Aug 25 12:18:35 2026 +0100"
      },
      "committer": {
        "name": "Will Deacon",
        "email": "will@kernel.org",
        "time": "Thu Aug 27 14:18:39 2026 +0000"
      },
      "message": "selftests/arm64: Treat KSM merge_across_nodes as optional\n\nThe MTE KSM test requires write access to KSM sysfs but does not check\nthat it is running as root. It also unconditionally saves, enables and\nrestores the merge_across_nodes attribute. The kernel only creates this\nattribute when CONFIG_NUMA\u003dy, so a non-NUMA kernel prints the following\nmessage three times even though every KSM subtest passes:\n\n  # ERR: missing /sys/kernel/mm/ksm/merge_across_nodes\n\nSkip the test when it is not running as root. Check that the optional\nattribute is readable and writable, treating ENOENT as its expected\nabsence on non-NUMA kernels and skipping the test for other access\nfailures. Only save, enable and restore the attribute when it is\navailable.\n\nCheck MTE availability before the privilege and sysfs checks so systems\nwithout MTE retain the existing feature-unavailable skip result.\n\nThis preserves the existing behavior on NUMA kernels without requiring\nNUMA or reducing KSM coverage on single-node systems.\n\nFixes: f981d8fa2646 (\"kselftest/arm64: Verify KSM page merge for MTE pages\")\nSigned-off-by: Muhammad Usama Anjum \u003cusama.anjum@arm.com\u003e\nReviewed-by: Vincenzo Frascino \u003cvincenzo.frascino@arm.com\u003e\nReviewed-by: Mark Brown \u003cbroonie@kernel.org\u003e\nSigned-off-by: Will Deacon \u003cwill@kernel.org\u003e\n"
    },
    {
      "commit": "8d2237e9d6902e234bb89aabb9cd6a9e91357223",
      "tree": "3bd61fdcf747937ee99daa9da004f99552cb5019",
      "parents": [
        "f5b8b9037df387394a73aab47c5437bbac975077"
      ],
      "author": {
        "name": "Muhammad Usama Anjum",
        "email": "usama.anjum@arm.com",
        "time": "Tue Aug 25 12:18:34 2026 +0100"
      },
      "committer": {
        "name": "Will Deacon",
        "email": "will@kernel.org",
        "time": "Thu Aug 27 14:18:39 2026 +0000"
      },
      "message": "selftests/arm64: Print missing MTE TAP headers\n\nMost MTE tests set a TAP plan and emit results without first printing\nthe TAP version header. Direct execution therefore starts with a plan\nsuch as \"1..20\" instead of \"TAP version 13\".\n\nThe problem is particularly visible in the GCR_EL1 context-switch test.\nIt prints its plan before forking 1,024 child processes. When stdout is\nfully buffered, the plan remains in the stdio buffer. Each child inherits\nthe pending \"1..1\" line and flushes its copy from exit(), producing\nrepeated plan lines.\n\nksft_print_header() prints the TAP header and enables line buffering.\nCall it in every MTE test that is missing it. In the GCR_EL1 test, call\nit before the plan so the plan is flushed before the children are\nforked. In the remaining tests, call it before setup and prerequisite\nchecks so early failures and whole-test skips also retain the header.\n\nFixes: 29f080881601 (\"kselftest/arm64: check GCR_EL1 after context switch\")\nSigned-off-by: Muhammad Usama Anjum \u003cusama.anjum@arm.com\u003e\nReviewed-by: Vincenzo Frascino \u003cvincenzo.frascino@arm.com\u003e\nReviewed-by: Mark Brown \u003cbroonie@kernel.org\u003e\nSigned-off-by: Will Deacon \u003cwill@kernel.org\u003e\n"
    },
    {
      "commit": "f5b8b9037df387394a73aab47c5437bbac975077",
      "tree": "f900bfa50ab1a9d54f0da6c29ce1b5deeeb7a8fe",
      "parents": [
        "b8f070ac3167595069feb1f794c127b805115645"
      ],
      "author": {
        "name": "Karl Mehltretter",
        "email": "kmehltretter@gmail.com",
        "time": "Thu Aug 20 00:27:12 2026 +0200"
      },
      "committer": {
        "name": "Will Deacon",
        "email": "will@kernel.org",
        "time": "Thu Aug 27 14:16:04 2026 +0000"
      },
      "message": "arm64: compat: Fix decrementing LDM/STM alignment emulation\n\nThe compat alignment emulator inherited unsigned long data addresses from\nthe 32-bit ARM implementation.\n\nIn do_alignment_ldmstm(), nr_regs is an unsigned int holding the transfer\nsize. The function uses the same address addition for both transfer\ndirections, negating nr_regs first for a decrementing LDM or STM. The\n32-bit negation wraps before the addition, so the handler adds nearly\n4 GiB instead of subtracting the transfer size.\nThe resulting address lies outside the compat task\u0027s address space, so\ndecrementing LDM/STM emulation fails, while incrementing forms work.\n\nFor example, a backwards-moving copy routine using decrementing LDM/STM can\ntake an alignment fault when called with unaligned pointers. The compat\nhandler should emulate the transfer, but this bug instead causes SIGBUS.\n\nThe offset negated in do_alignment_finish_ldst() is offset_union.un, which\nis already unsigned long and does not have this width mismatch.\n\nMake nr_regs unsigned long so its negation and the address arithmetic\nuse the same width.\n\nFixes: 3fc24ef32d3b (\"arm64: compat: Implement misalignment fixups for multiword loads\")\nCc: stable@vger.kernel.org\nSuggested-by: Arnd Bergmann \u003carnd@arndb.de\u003e\nAssisted-by: Codex:gpt-5.6-sol\nSigned-off-by: Karl Mehltretter \u003ckmehltretter@gmail.com\u003e\nSigned-off-by: Will Deacon \u003cwill@kernel.org\u003e\n"
    },
    {
      "commit": "c4a0927f535f779700d5ccda8182c2db01e9d551",
      "tree": "28e7ea542f66be5867090d9c2eee57efe425b597",
      "parents": [
        "74e3b979ce8b78a690f8b94ccf2e2c965f7f5c11",
        "15596a87fcc6fa07a162858e5fd00ba31752096b"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 27 16:15:47 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 27 16:15:47 2026 +0200"
      },
      "message": "Merge tag \u0027asoc-fix-v7.3-merge-window\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus\n\nASoC: Fixes for v7.3\n\nA fairly big batch of fixes that came in during the merge window.\nThere\u0027s a lot of quirks for x86 systems and a bunch of driver specific\nfixes, the most critical being the fixes for Tegra\u0027s register\ndefinitions.  It turned out that they had been relying on the regmap\ndefault handling bugs that were fixed in v7.2 and so audio was fairly\nbadly broken, unfortunately the issue wasn\u0027t noticed in time for\nrelease.\n"
    },
    {
      "commit": "74e3b979ce8b78a690f8b94ccf2e2c965f7f5c11",
      "tree": "ca7e48404dd7010961828cc927fa075cf4c1c914",
      "parents": [
        "9642a5e843758686e02a7f0d1df9eb0f7f96603c"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 27 13:39:03 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Thu Aug 27 16:15:08 2026 +0200"
      },
      "message": "ALSA: control: Don\u0027t add invalid kcontrols to LED layer\n\nThe kcontrol LED state layer tries to track the all associated\nkcontrol elements with naive assumptions that they are readable.\nBut one can create a write-only element that has no get callback (even\na user element can do it), and this may lead to a NULL dereference at\nthe call chain of snd_ctl_led_notify(), as found by syzkaller.\n\nFor avoiding the Oops, add a sanity check of the kcontrol\u0027s info and\nget callbacks, and just skip the invalid kcontrols before assigning\nthe kctl to the LED layer.\n\nReported-by: syzbot+b7fe2760ea6f1ee44b4d@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/6a9007b3.1d9ded08.62e62.00cd.GAE@google.com\nFixes: 22d8de62f11b (\"ALSA: control - add generic LED trigger module as the new control layer\")\nReviewed-by: Jaroslav Kysela \u003cperex@perex.cz\u003e\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\nLink: https://patch.msgid.link/20260827113951.893291-1-tiwai@suse.de\n"
    },
    {
      "commit": "fc04229727d8fffbf02e0635de38413fe0102d02",
      "tree": "3cec53d663fecd60b11bde17675ecb25010b73c1",
      "parents": [
        "132a02beb46fc4d497c41c81ed0dda7956fa4171"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Fri Aug 21 12:25:55 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: nf_tables: remove leftover set_update_list\n\nThis list has been moved to per-netns, remove onstack list which is not\nused anymore.\n\nFixes: b343ededb3f9 (\"netfilter: nf_tables: move set_update_list to nftables per-netns\")\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "132a02beb46fc4d497c41c81ed0dda7956fa4171",
      "tree": "044853e8670d98eff5f50cde6f9dd6f004c536e6",
      "parents": [
        "43559058d21e0493aa220ac167e0279334dea5f9"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 20 10:26:32 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: nf_tables: set on dead bit when performing early element removal\n\n.commit call for sets is skipped if set-\u003edead flag is set on, but this\nflag is set on later in the commit path.\n\nThis also reintroduces the bug fixed in commit 7315dc1e122c8\n(\"netfilter: nf_tables: skip set commit for deleted/destroyed sets\").\n\nFixes: 1e3b9e1c77fe (\"netfilter: nf_tables: call set ops .commit when building new ruleset blob\")\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "43559058d21e0493aa220ac167e0279334dea5f9",
      "tree": "9b1f855dd8de90841bfc44e832042d2f3f414a7c",
      "parents": [
        "793d9eda4821f75b5f7cc9e6a870b72a58b44c2b"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Wed Aug 19 13:42:36 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: nf_tables: skip double clone set expressions on element insert\n\nBoth the dynset and newsetelem path clone the existing set expressions\nwhen setting set element expressions if no override expressions are\nprovided. This results in a double clone, once to clone the template set\nexpressions then another clone on the new element. Add a flag to\nannotate if userspace provides a override expression (ie. expression of\nthe same type of the set but different configuration), otherwise borrow\nthe existing expression from the set. Add conditionals to release\nexpression iif they represent an override. Use this new override_exprs\nflag to dump the dynset expression override to userspace.\n\nThis simplifies the existing logic and it also fixes a bug with the\nconnlimit expression which results in a module refcount imbalance\nWARNING splat when resorting on the default set expressions.\n\nFixes: 65038428b2c6 (\"netfilter: nf_tables: allow to specify stateful expression in set definition\")\nFixes: fca05d4d61e6 (\"netfilter: nft_dynset: honor stateful expressions in set definition\")\nReported-by: Xingyuan Mo \u003chdthky0@gmail.com\u003e\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "793d9eda4821f75b5f7cc9e6a870b72a58b44c2b",
      "tree": "a73370438eb519bb72e2951b086695524fb9ba04",
      "parents": [
        "f43358489db46c8ad63207ee229ebdf1e7932be9"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Tue Aug 18 10:31:24 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited()\n\nSeveral xtables extension still use pr_err() or pr_info() without\nratelimit.\n\nFor xt_cgroup, while at this, remove redundant \"xt_cgroup:\" prefix\nsince pr_fmt is already set on.\n\nFixes: c38c4597e4bf (\"netfilter: implement xt_cgroup cgroup2 path match\")\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "f43358489db46c8ad63207ee229ebdf1e7932be9",
      "tree": "ea32482070fd2c14f457f1a0630dc953f6b70b65",
      "parents": [
        "55dd20f0f4b1be5c9c8a0275d8d763c86563eac2"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Tue Aug 18 10:15:05 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: x_tables: remove pr_debug\n\nRemove pr_debug() for these xtables extensions, these have no use\nthese days. Still, turn pr_debug() into pr_info_ratelimited() in the\n.checkentry path since this helps provide a hint via dmesg in legacy\niptables.\n\nException is xt_IDLETIMER in the module init path, where pr_err() is\nused.\n\nAdd missing pr_fmt() definition in xt_REDIRECT, xt_NETMAP and\nxt_MASQUERADE.\n\nAdd missing \\n to several pr_debug() that were translated to use\npr_info_ratelimited().\n\nLink: https://patch.msgid.link/cover.1786933680.git.rakukuip@gmail.com/\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "55dd20f0f4b1be5c9c8a0275d8d763c86563eac2",
      "tree": "67e02bfd066bddcd3d97e920f88dc87fc9389414",
      "parents": [
        "b1881d362e1924b66f6016c3efd28807032b41bf"
      ],
      "author": {
        "name": "Eric Biggers",
        "email": "ebiggers@kernel.org",
        "time": "Sat Aug 15 13:57:50 2026 -0700"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: nft_set_pipapo_avx2: add missing vzeroupper\n\nSince pipapo_get_avx2() uses YMM registers, execute vzeroupper before\nreturning from it.  This is needed to avoid degrading the performance of\nany later SSE code that may happen to be executed.\n\nFixes: 7400b063969b (\"nft_set_pipapo: Introduce AVX2-based lookup implementation\")\nCc: stable@vger.kernel.org\nSigned-off-by: Eric Biggers \u003cebiggers@kernel.org\u003e\nReviewed-by: Stefano Brivio \u003csbrivio@redhat.com\u003e\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "b1881d362e1924b66f6016c3efd28807032b41bf",
      "tree": "2ce6f2f1af08f3e5f52f8751af39e6910b6755e8",
      "parents": [
        "9b4ab1f3fed89d8c1e953dc069a0ddd705a73f09"
      ],
      "author": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 13 02:16:02 2026 +0200"
      },
      "committer": {
        "name": "Pablo Neira Ayuso",
        "email": "pablo@netfilter.org",
        "time": "Thu Aug 27 16:10:57 2026 +0200"
      },
      "message": "netfilter: nf_tables: move hardware offload step after building the chain blob\n\nAllocate the chain blob before the ruleset offload to reduce chances of\nentering an inconsistent state where the offloaded ruleset in the nic\nand the software ruleset differ.\n\nFixes: c9626a2cbdb2 (\"netfilter: nf_tables: add hardware offload support\")\nSigned-off-by: Pablo Neira Ayuso \u003cpablo@netfilter.org\u003e\n"
    },
    {
      "commit": "3b446d169a93e6abae9a93535369fa18bbcbefd9",
      "tree": "5bf635014c1f042f0fd36b7c3f61843ad840679e",
      "parents": [
        "3382bfbca58c7d5ee3f31a7b37fbeb208e98e656"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Thu Aug 27 15:59:32 2026 +0200"
      },
      "committer": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Thu Aug 27 16:03:20 2026 +0200"
      },
      "message": "Revert \"ACPI: scan: Defer device power initialization\"\n\nRevert commit dc948f8b384a (\"ACPI: scan: Defer device power\ninitialization\") that is incomplete and may cause ACPI power\nmanagement of devices to fail.\n\nThe problem is that PCI devices are associated with the\ncorresponding ACPI device objects before acpi_bus_attach()\nruns for them, so after commit dc948f8b384a, ACPI power\nmanagement will not be initialized for them before making\nthat association.  Consequently, the reference counting of\nACPI power resources may not work as expected going forward\nand power management issues may appear.  If they appear, they\nmay be elusive and hard to diagnose.\n\nWhile this is fixable, I am not sure if fixing it on top of\ncommit dc948f8b384a is the best way to go, so it is better to\nrevert that commit for now and revisit the whole thing in the\nnext cycle.\n\nSigned-off-by: Rafael J. Wysocki \u003crafael.j.wysocki@intel.com\u003e\nLink: https://patch.msgid.link/6029658.DvuYhMxLoT@rafael.j.wysocki\n"
    },
    {
      "commit": "81eb1867e059bf1dbbfbba536385a5cb26f700cd",
      "tree": "f6d28ba20e028279fdc90a8a15b1104986673244",
      "parents": [
        "2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d",
        "0b13256ce37b66dbd0e4ce78d5bee32fd38db1a5"
      ],
      "author": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 27 15:47:19 2026 +0200"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 27 15:47:19 2026 +0200"
      },
      "message": "Merge branch \u0027guard-against-gso_segs-overflows\u0027\n\nAlice Mikityanska says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nGuard against gso_segs overflows\n\nThis series is a follow-up on the discussion:\n\nhttps://lore.kernel.org/netdev/CAD0BsJWzSr2zduf5v3mVC4zd\u003dLj6ZAoC+V42-VBdg42aDY8XXw@mail.gmail.com/T/#m1e22fca273c36cc8844e516505d3251cc1418fea\n\nskb_segment is patched to avoid possible overflows in partial GSO. The\nprimary possible source of too many GSO segments is also addressed:\nvirtio-net clamps gso_size to \u003e\u003d8 in TCP, as suggested by Eric.\n\nv2: https://lore.kernel.org/netdev/20260813174613.2920246-1-alice.kernel@fastmail.im/\nv1: https://lore.kernel.org/netdev/20260723155145.158572-1-alice.kernel@fastmail.im/\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260822120117.1163423-1-alice.kernel@fastmail.im\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    },
    {
      "commit": "0b13256ce37b66dbd0e4ce78d5bee32fd38db1a5",
      "tree": "f6d28ba20e028279fdc90a8a15b1104986673244",
      "parents": [
        "c27c449d455aafd9018a3cbab150f1c42c87923f"
      ],
      "author": {
        "name": "Alice Mikityanska",
        "email": "alice@isovalent.com",
        "time": "Sat Aug 22 15:01:17 2026 +0300"
      },
      "committer": {
        "name": "Paolo Abeni",
        "email": "pabeni@redhat.com",
        "time": "Thu Aug 27 15:47:18 2026 +0200"
      },
      "message": "net: Guard for gso_segs overflow in skb_segment\n\nskb_segment calculates 32-bit partial_segs as len / gso_size, and then\nassigns it to the 16-bit gso_segs field. The division might overflow in\nsome edge cases where the SKB is BIG TCP (65536 \u003c\u003d len \u003c\u003d 8*65535), and\ngso_size \u003c TCP_MIN_GSO_SIZE \u003d 8. While normally this can\u0027t happen due to\nTCP_MIN_GSO_SIZE, an AF_PACKET PACKET_VNET_HDR socket could generate\nsuch a malformed packet until the previous patch.\n\nBlocking malformed virtio_net packets was implemented in the previous\npatch, but this patch clamps partial_segs in skb_segment itself for more\ngeneric robustness. Should len / gso_size happen to be bigger than\n65535 in partial GSO, skb_segment will now just produce more than two\noutput SKBs, all of which will be valid with gso_segs \u003c\u003d 65535.\n\nIn order to catch possible other cases of too many partial_segs, add a\nDEBUG_NET_WARN_ON_ONCE when len / gso_size happens to be too big.\n\nSigned-off-by: Alice Mikityanska \u003calice@isovalent.com\u003e\nLink: https://patch.msgid.link/20260822120117.1163423-3-alice.kernel@fastmail.im\nSigned-off-by: Paolo Abeni \u003cpabeni@redhat.com\u003e\n"
    }
  ],
  "next": "c27c449d455aafd9018a3cbab150f1c42c87923f"
}
