)]}'
{
  "log": [
    {
      "commit": "dc59e4fea9d83f03bad6bddf3fa2e52491777482",
      "tree": "766b19334c18bce59b3ea4101707abcb7d9776d2",
      "parents": [
        "0716f9b9338a86dd27796e00ed0fd560c653323a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 12:01:31 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 12:01:31 2026 -0700"
      },
      "message": "Linux 7.2-rc1\n"
    },
    {
      "commit": "0716f9b9338a86dd27796e00ed0fd560c653323a",
      "tree": "fe6680f5337288a549cda906ba05b4476c1d3dc5",
      "parents": [
        "8b69c047587112f7bcb4b0d83f2729d8dd29ebe2",
        "d1c3d45f87e89e5c1fa0769a72a48d1ad99106fc"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 07:46:12 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 07:46:12 2026 -0700"
      },
      "message": "Merge tag \u0027ntb-7.2\u0027 of https://github.com/jonmason/ntb\n\nPull NTB updates from Jon Mason:\n \"An EPF bug fix to prevent an invalid unmap during device removal,\n  along with documentation fixes and minor AMD driver cleanups\"\n\n* tag \u0027ntb-7.2\u0027 of https://github.com/jonmason/ntb:\n  ntb: amd: Use named initializer for pci_device_id::driver_data\n  NTB: fix kernel-doc warnings in ntb.h\n  NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR\n  ntb_hw_amd: Fix incorrect debug message in link disable path\n"
    },
    {
      "commit": "8b69c047587112f7bcb4b0d83f2729d8dd29ebe2",
      "tree": "54920f7ba9e9edce5a2bc5b7cc7acdb3e56aafc6",
      "parents": [
        "780d569e6c4b422290f5cba319eb904b355d64be",
        "d86d4f8cbb5a55a3b9b86f7b5ab8c4cdda600a3f"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 04:40:05 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sun Jun 28 04:40:05 2026 -0700"
      },
      "message": "Merge tag \u0027input-for-v7.2-rc0-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input\n\nPull more input updates from Dmitry Torokhov:\n\n - Updates to Synaptics RMI4 driver to fix potential OOB accesses in F30\n   and F3A keymap handling\n\n - A workaround in Synaptics RMI4 to tolerate buggy firmware on some\n   touchpads (e.g. ThinkPad T14 Gen 1) that report incomplete register\n   descriptor structures, preventing probe failures\n\n - A revert of an incorrect register descriptor address calculation in\n   Synaptics RMI4 driver\n\n - A fix for a regression in HP GSC PS/2 (gscps2) driver where the\n   receive buffer write index was not advanced, leaving keyboard and\n   mouse unusable.\n\n* tag \u0027input-for-v7.2-rc0-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/dtor/input:\n  Input: gscps2 - advance receive buffer write index\n  Input: rmi4 - tolerate short register descriptor structure\n  Revert \"Input: rmi4 - fix register descriptor address calculation\"\n  Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count\n  Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count\n"
    },
    {
      "commit": "780d569e6c4b422290f5cba319eb904b355d64be",
      "tree": "fdb07d20f25e372f1c63f4c11be5b819bdb1c992",
      "parents": [
        "f21df873208d41ef816b15024d6447813b97ab5e",
        "898ab0f30e008e411ce93ddf81c4099abd9d4e46"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 13:48:12 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 13:48:12 2026 -0700"
      },
      "message": "Merge tag \u0027pwm/for-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux\n\nPull pwm fixes from Uwe Kleine-König:\n \"Two more fixes that I managed to put into the public branch merged\n  into next before my first pull request but missed to include them in\n  it.\n\n  The first change is a relevant change that fixes misconfigurations due\n  to a variable overflow. The second is only cosmetic but very obviously\n  an improvement\"\n\n* tag \u0027pwm/for-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/ukleinek/linux:\n  pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages\n  pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64\n"
    },
    {
      "commit": "f21df873208d41ef816b15024d6447813b97ab5e",
      "tree": "2003ff326b5531655a43b86702a1b66bf14b04d8",
      "parents": [
        "14923571e78ae448ff4cc250d46d6f5fa442761c",
        "7f08fc10fa3d3366dc3af723970bd03d7d6d10e3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 12:52:20 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 12:52:20 2026 -0700"
      },
      "message": "Merge tag \u0027fbdev-for-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev\n\nPull more fbdev updates from Helge Deller:\n \"Fixes for generic fbdev \u0026 fbcon code for the handling of modelists\n  and preventing a potential NULL ptr dereference in the console code.\n\n  Fix missed cleanups in the error path of various fbdev drivers.\n\n  And Uwe Kleine-König contributed a cleanup patch to use named\n  initializers in the vga16fb driver\"\n\n* tag \u0027fbdev-for-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/deller/linux-fbdev:\n  fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var\n  fbcon: fix NULL pointer dereference for a console without vc_data\n  fbdev: fix use-after-free in store_modes()\n  fbdev: viafb: return an error when DMA copy times out\n  fbdev: goldfishfb: fail pan display on base-update timeout\n  fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()\n  fbdev: pm2fb: unwind WC setup on probe failure\n  fbdev: vga16fb: Drop unused assignment of platform_device_id driver data\n"
    },
    {
      "commit": "14923571e78ae448ff4cc250d46d6f5fa442761c",
      "tree": "1ee3e4f8c71082d4d9240dd4090cfdda75c08bb1",
      "parents": [
        "4bf54e47525dcacd4c6cdd97fb5902592414dd7a",
        "e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 12:15:23 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 12:15:23 2026 -0700"
      },
      "message": "Merge tag \u0027sound-fix-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound\n\nPull sound fixes from Takashi Iwai:\n \"A collection of small bug fixes accumulated over the last week.\n  Most are device-specific fixes while there are a few core fixes as\n  well.\n\n  Here are the highlights:\n\n  ALSA Core:\n   - A fix for an uninitialised heap leak in ALSA sequencer core\n   - A fix for error handling/resource leak in compress-offload API\n\n  USB-audio:\n   - A teardown-ordering fix in USB MIDI 2.0 to prevent use-after-free\n   - Bounds and length checks for packet data in Native Instruments\n     caiaq / Traktor Kontrol input parsers\n   - Avoidance of expensive kobject path lookups in DualSense controller\n     matches\n   - Robustness/memory leak fixes for Qualcomm USB offload driver\n   - Focusrite Control Protocol (FCP) NULL-pointer dereference fix and a\n     new device quirk (ISA C8X)\n   - Device-specific quirks for Yamaha CDS3000 and SC13A\n\n  HD-Audio:\n   - A bunch of quirks and mute/mic-mute LED fixups for various laptops\n     (Acer, Clevo, Lenovo, HP)\n\n  ASoC \u0026 SoundWire:\n   - Avoid failing card registration if the device_link creation fails\n   - A workaround for SoundWire randconfig build failures by making\n     helper functions static inline\n   - Corrected MCLK reference validation for CS530x codecs\n   - Clean up of untested, problematic guard() macro replacements in\n     Rockchip SAI driver\n   - Fix for eDMA maxburst misalignment with channel count in Freescale\n     ASRC\n   - Miscellaneous hardware-specific fixes (qcom, rt5650, tlv320aic3x,\n     tas2781/3)\n\n  Others:\n   - Bounds and length checks for packet data in Apple iSight\"\n\n* tag \u0027sound-fix-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound: (46 commits)\n  ALSA: FCP: Fix NULL pointer dereference in interface lookup\n  ALSA: hda/realtek: Update Acer Nitro ANV15-41 quirk to enable mute LED\n  ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count\n  ASoC: codecs: pcm512x: only print info once on no sclk\n  ASoC: tas2781: Update default register address to TAS2563\n  ALSA: firewire: isight: bound the sample count to the packet payload\n  ALSA: usb-audio: qcom: Free QMI handle\n  ALSA: hda: Add Lenovo Legion 7i 16IAX7 17AA3874 quirk\n  ALSA: usb-audio: avoid kobject path lookup in DualSense match\n  ALSA: hda/realtek: Add quirk for Acer Nitro ANV15-41\n  ASoC: soc-core: Don\u0027t fail if device_link could not be created\n  ASoC: rockchip: rockchip_sai: #include \u003clinux/platform_device.h\u003e explicitly\n  ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()\n  ASoC: rt5575: Use __le32 for SPI burst write address\n  ASoC: tas2783: Update loaded firmware names to linux-firmware 20260519\n  ASoC: SDCA: Validate written enum value in ge_put_enum_double()\n  ASoC: realtek: Add back local call to sdw_show_ping_status()\n  ASoC: ti: Add back local call to sdw_show_ping_status()\n  ASoC: max98373: Add back local call to sdw_show_ping_status()\n  ASoC: es9356: Add back local call to sdw_show_ping_status()\n  ...\n"
    },
    {
      "commit": "4bf54e47525dcacd4c6cdd97fb5902592414dd7a",
      "tree": "cc723c9984adf8a2d06fe6faef44b56c5fb8f379",
      "parents": [
        "da7ca04e331e3e83f661e29c30d381a91e6ca245",
        "10dd1a736d557e310a77117832874729a0175d57"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 11:33:30 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 11:33:30 2026 -0700"
      },
      "message": "Merge tag \u0027i2c-fixes-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux\n\nPull i2c fixes from Andi Shyti:\n\n - i801: fix error path in smbus transfer\n\n - mpc: fix timeout calculation\n\n* tag \u0027i2c-fixes-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux:\n  i2c: i801: fix hardware state machine corruption in error path\n  i2c: mpc: Fix timeout calculations\n"
    },
    {
      "commit": "da7ca04e331e3e83f661e29c30d381a91e6ca245",
      "tree": "60b462354bb5ed314712aaf236b724d1eaa7cd25",
      "parents": [
        "6ca693ea903df5748809f61b290831004036978d",
        "3c8f28578a0d68bc7fb91d881b832d55f734270c"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 11:00:18 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 11:00:18 2026 -0700"
      },
      "message": "Merge tag \u0027rtc-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/abelloni/linux\n\nPull RTC updates from Alexandre Belloni:\n \"Most of the work and improvements are for features of the m41t93.\n\n  The ds1307 also gets support for OSF (Oscillator Stop Flag) for\n  new variants.\n\n  The pcap driver is being removed as the Motorola EZX support was\n  removed a while ago.\n\n  Subsystem:\n   - add rtc_read_next_alarm() to read next expiring timer\n\n  Drivers:\n   - ds1307: handle OSF for ds1337/ds1339/ds3231, add clock provider for\n     ds1307, fix wday for rx8130\n   - m41t93: DT support, alarm, clock provider, watchdog support\n   - mv: add suspend/resume support for wakeup\n   - pcap: remove driver\n   - renesas-rtca3: many fixes\"\n\n* tag \u0027rtc-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/abelloni/linux: (36 commits)\n  rtc: ds1307: update reference to removed CONFIG_RTC_DRV_DS1307_HWMON\n  platform/x86: amd-pmc: Fix S0i3 wakeup with alarmtimer\n  rtc: s35390a: fix typo in comment\n  rtc: cmos: unregister HPET IRQ handler on probe failure\n  rtc: ds1307: Fix off-by-one issue with wday for rx8130\n  dt-bindings: rtc: ds1307: Add epson,rx8901\n  rtc: bq32000: add delay between RTC reads\n  rtc: m41t93: Add watchdog support\n  rtc: m41t93: Add square wave clock provider support\n  rtc: m41t93: Add alarm support\n  rtc: m41t93: migrate to regmap api for register access\n  rtc: m41t93: add device tree support\n  dt-bindings: rtc: Add ST m41t93\n  rtc: ds1307: add support for clock provider in ds1307\n  rtc: mv: add suspend/resume support for wakeup\n  rtc: aspeed: add AST2700 compatible\n  dt-bindings: rtc: add ASPEED AST2700 compatible\n  rtc: interface: fix typos in rtc_handle_legacy_irq() documentation\n  rtc: msc313: fix NULL deref in shared IRQ handler at probe\n  rtc: remove unused pcap driver\n  ...\n"
    },
    {
      "commit": "6ca693ea903df5748809f61b290831004036978d",
      "tree": "4658144e196db6e27bab200cb94ea174dffdc4a9",
      "parents": [
        "5a66900afbd6b2a063eebad35294038a654de2b0",
        "696c030e1e3438955aba443b308ee8b6faa3983e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 09:20:16 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Sat Jun 27 09:20:16 2026 -0700"
      },
      "message": "Merge tag \u0027fscrypt-for-linus\u0027 of git://git.kernel.org/pub/scm/fs/fscrypt/linux\n\nPull fscrypt fixes from Eric Biggers:\n\n - Fix a bug where in a specific edge case, file contents en/decryption\n   could be done with the wrong data unit size\n\n - Fix the data structure used for keeping track of users that have\n   added an fscrypt key to be a simple list instead of a \u0027struct key\u0027\n   keyring\n\n   This fixes issues such as a lockdep report found by syzbot and\n   possible unintended interactions with the keyctl() system calls\n\n* tag \u0027fscrypt-for-linus\u0027 of git://git.kernel.org/pub/scm/fs/fscrypt/linux:\n  fscrypt: Replace mk_users keyring with simple list\n  fscrypt: Fix key setup in edge case with multiple data unit sizes\n"
    },
    {
      "commit": "d86d4f8cbb5a55a3b9b86f7b5ab8c4cdda600a3f",
      "tree": "b18acec840133546891403ae5ecc78b7e1b54550",
      "parents": [
        "2d6d33e45dd4fb768758d5f6e747deadcd66b9fc"
      ],
      "author": {
        "name": "Xu Rao",
        "email": "raoxu@uniontech.com",
        "time": "Wed Jun 24 17:47:39 2026 +0800"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Fri Jun 26 22:42:56 2026 -0700"
      },
      "message": "Input: gscps2 - advance receive buffer write index\n\nCommit 44f920069911 (\"Input: gscps2 - use guard notation when\nacquiring spinlock\") moved the receive loop into gscps2_read_data()\nand gscps2_report_data().\n\nWhile moving the code, it preserved the writes to\nbuffer[ps2port-\u003eappend], but omitted the following producer index\nupdate from the original loop:\n\n\tps2port-\u003eappend \u003d (ps2port-\u003eappend + 1) \u0026 BUFFER_SIZE;\n\nAs a result, append never advances. Since gscps2_report_data() only\nreports bytes while act !\u003d append, the receive buffer always appears\nempty and no keyboard or mouse data reaches the serio core.\n\nRestore the omitted index update.\n\nFixes: 44f920069911 (\"Input: gscps2 - use guard notation when acquiring spinlock\")\nCc: stable@vger.kernel.org # 6.13+\nSigned-off-by: Xu Rao \u003craoxu@uniontech.com\u003e\nLink: https://patch.msgid.link/460B5655BA580C60+20260624094739.850306-1-raoxu@uniontech.com\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "2d6d33e45dd4fb768758d5f6e747deadcd66b9fc",
      "tree": "b310fe7c191e42fc1c0eeac59fbb2aff64f48edd",
      "parents": [
        "d85589879f19ad8514c508709865f064be761df5"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Fri Jun 26 16:33:21 2026 -0700"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Fri Jun 26 22:23:40 2026 -0700"
      },
      "message": "Input: rmi4 - tolerate short register descriptor structure\n\nSome touchpads (e.g. ThinkPad T14 Gen 1) have buggy firmware that reports\na register descriptor structure size that is too small for the number of\nregisters it claims to have in the presence map. The remaining bytes in\nthe structure are 0, which with the new strict bounds checking causes the\nparser to fail with -EIO, aborting the device probe.\n\nTolerate such short reads by dropping the remaining (unparseable or\n0-size) registers from the list instead of failing the probe,\npreventing the driver from trying to use them.\n\nFixes: 0adb483fbf2d (\"Input: rmi4 - refactor register descriptor parsing\")\nReported-by: Barry K. Nathan \u003cbarryn@pobox.com\u003e\nTested-by: Barry K. Nathan \u003cbarryn@pobox.com\u003e\nCc: stable@vger.kernel.org\nAssisted-by: Antigravity:gemini-3.5-flash\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "d85589879f19ad8514c508709865f064be761df5",
      "tree": "8c6965446003b3683f73e601f8fd49b592b49be1",
      "parents": [
        "d577e46785d45484b2ab7e7309c49b18764bf56c"
      ],
      "author": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Fri Jun 26 17:42:10 2026 -0700"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Fri Jun 26 22:22:42 2026 -0700"
      },
      "message": "Revert \"Input: rmi4 - fix register descriptor address calculation\"\n\nThe register descriptor presence register is a packet register, which\nmeans its bytes share a single RMI address. It does not occupy\nconsecutive addresses, and the register structure that follows it\nis located at the next RMI address (presence_address + 1), not\n(presence_address + presence_size).\n\nRevert the incorrect address calculation introduced in commit\na98518e72439.\n\nReported-by: \"Barry K. Nathan\" \u003cbarryn@pobox.com\u003e\nTested-by: \"Barry K. Nathan\" \u003cbarryn@pobox.com\u003e\nCc: stable@vger.kernel.org\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "d1c3d45f87e89e5c1fa0769a72a48d1ad99106fc",
      "tree": "0d0886623885d69c4aefe455e9dfe2f15a271962",
      "parents": [
        "8df969463bc26a7250707f485ee3ac61426d671f"
      ],
      "author": {
        "name": "Uwe Kleine-König (The Capable Hub)",
        "email": "u.kleine-koenig@baylibre.com",
        "time": "Thu May 07 09:41:01 2026 +0200"
      },
      "committer": {
        "name": "Jon Mason",
        "email": "jdmason@kudzu.us",
        "time": "Fri Jun 26 22:18:34 2026 -0400"
      },
      "message": "ntb: amd: Use named initializer for pci_device_id::driver_data\n\nThe current list initialisation depends on the well hidden two zeros in\nthe PCI_VDEVICE macro. Instead use a named initialisation that is more\nrobust and easier to understand.\n\nSigned-off-by: Uwe Kleine-König (The Capable Hub) \u003cu.kleine-koenig@baylibre.com\u003e\nReviewed-by: Dave Jiang \u003cdave.jiang@intel.com\u003e\nSigned-off-by: Jon Mason \u003cjdmason@kudzu.us\u003e\n"
    },
    {
      "commit": "8df969463bc26a7250707f485ee3ac61426d671f",
      "tree": "811843b58c25c5f33aa2b22d4a70d78878fe3395",
      "parents": [
        "d876153680e3d721d385e554def919bce3d18c74"
      ],
      "author": {
        "name": "Randy Dunlap",
        "email": "rdunlap@infradead.org",
        "time": "Wed Mar 11 22:14:15 2026 -0700"
      },
      "committer": {
        "name": "Jon Mason",
        "email": "jdmason@kudzu.us",
        "time": "Fri Jun 26 22:18:34 2026 -0400"
      },
      "message": "NTB: fix kernel-doc warnings in ntb.h\n\nCorrect a function name and function parameter name to avoid\nkernel-doc warnings:\n\nWarning: include/linux/ntb.h:575 expecting prototype for\n ntb_default_port_count(). Prototype was for ntb_default_peer_port_count()\n instead\nWarning: include/linux/ntb.h:590 function parameter \u0027pidx\u0027 not\n described in \u0027ntb_default_peer_port_number\u0027\n\nSigned-off-by: Randy Dunlap \u003crdunlap@infradead.org\u003e\nAcked-by: Dave Jiang \u003cdave.jiang@intel.com\u003e\nSigned-off-by: Jon Mason \u003cjdmason@kudzu.us\u003e\n"
    },
    {
      "commit": "d876153680e3d721d385e554def919bce3d18c74",
      "tree": "6341dff123d55bdcefdb67ab6c25bee4f8622ce8",
      "parents": [
        "4fc0625cf9c6c11f1f9b09e1f2e35fa2dd46ea6a"
      ],
      "author": {
        "name": "Koichiro Den",
        "email": "den@valinux.co.jp",
        "time": "Wed Mar 04 11:05:27 2026 +0900"
      },
      "committer": {
        "name": "Jon Mason",
        "email": "jdmason@kudzu.us",
        "time": "Fri Jun 26 22:18:21 2026 -0400"
      },
      "message": "NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR\n\nWhen BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown\npath ends up calling pci_iounmap() on the same iomem with some offset,\nwhich is unnecessary and triggers a kernel warning like the following:\n\n  Trying to vunmap() nonexistent vm area (0000000069a5ffe8)\n  WARNING: mm/vmalloc.c:3470 at vunmap+0x58/0x68, CPU#5: modprobe/2937\n  [...]\n  Call trace:\n   vunmap+0x58/0x68 (P)\n   iounmap+0x34/0x48\n   pci_iounmap+0x2c/0x40\n   ntb_epf_pci_remove+0x44/0x80 [ntb_hw_epf]\n   pci_device_remove+0x48/0xf8\n   device_remove+0x50/0x88\n   device_release_driver_internal+0x1c8/0x228\n   driver_detach+0x50/0xb0\n   bus_remove_driver+0x74/0x100\n   driver_unregister+0x34/0x68\n   pci_unregister_driver+0x34/0xa0\n   ntb_epf_pci_driver_exit+0x14/0xfe0 [ntb_hw_epf]\n  [...]\n\nFix it by unmapping only when PEER_SPAD and CONFIG use difference bars.\n\nCc: stable@vger.kernel.org\nFixes: e75d5ae8ab88 (\"NTB: epf: Allow more flexibility in the memory BAR map method\")\nReviewed-by: Frank Li \u003cFrank.Li@nxp.com\u003e\nSigned-off-by: Koichiro Den \u003cden@valinux.co.jp\u003e\nReviewed-by: Dave Jiang \u003cdave.jiang@intel.com\u003e\nSigned-off-by: Jon Mason \u003cjdmason@kudzu.us\u003e\n"
    },
    {
      "commit": "4fc0625cf9c6c11f1f9b09e1f2e35fa2dd46ea6a",
      "tree": "eba20d63b26dda5b43fe46206d8cb843a6befc1a",
      "parents": [
        "8cd9520d35a6c38db6567e97dd93b1f11f185dc6"
      ],
      "author": {
        "name": "Alok Tiwari",
        "email": "alok.a.tiwari@oracle.com",
        "time": "Sun Feb 08 08:49:00 2026 -0800"
      },
      "committer": {
        "name": "Jon Mason",
        "email": "jdmason@kudzu.us",
        "time": "Fri Jun 26 22:08:31 2026 -0400"
      },
      "message": "ntb_hw_amd: Fix incorrect debug message in link disable path\n\namd_ntb_link_disable() prints \"Enabling Link\" which is misleading.\nUpdate the message to reflect that the link is being disabled.\n\nSigned-off-by: Alok Tiwari \u003calok.a.tiwari@oracle.com\u003e\nReviewed-by: Dave Jiang \u003cdave.jiang@intel.com\u003e\nSigned-off-by: Jon Mason \u003cjdmason@kudzu.us\u003e\n"
    },
    {
      "commit": "5a66900afbd6b2a063eebad35294038a654de2b0",
      "tree": "7275867e5cffdbd8131acd9c461752501d94151c",
      "parents": [
        "fa6fe449343c3d97ed93fd01b020860c663f8807",
        "f24ba334afafc70c3149e9db9c0cf8ecc6d52a09"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 17:03:48 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 17:03:48 2026 -0700"
      },
      "message": "Merge tag \u0027drm-fixes-2026-06-27\u0027 of https://gitlab.freedesktop.org/drm/kernel\n\nPull drm fixes from Dave Airlie:\n \"These are just the fixes from our fixes branch, all pretty small and\n  scattered.\n\n  sysfb:\n   - drm/sysfb truncation and alignment fixes\n\n  edid:\n   - fix edid OOB read in tile parsing\n   - increase displayid topology id to correct size\n\n  nouveau:\n   - fix error handling paths in nouveau\n\n  amdxdna:\n   - get_bo_info fix\n\n  ivpu:\n   - fix leak when error handling in ivpu\"\n\n* tag \u0027drm-fixes-2026-06-27\u0027 of https://gitlab.freedesktop.org/drm/kernel:\n  drm/sysfb: Avoid truncating maximum stride\n  drm/sysfb: Return errno code from drm_sysfb_get_visible_size()\n  drm/sysfb: Avoid possible truncation with calculating visible size\n  drm/sysfb: Do not page-align visible size of the framebuffer\n  drm/edid: fix OOB read in drm_parse_tiled_block()\n  drm/nouveau: fix reversed error cleanup order in ucopy functions\n  drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()\n  accel/amdxdna: Use caller client for debug BO sync\n  drm/displayid: fix Tiled Display Topology ID size\n  accel/ivpu: fix HWS command queue leak on registration failure\n"
    },
    {
      "commit": "fa6fe449343c3d97ed93fd01b020860c663f8807",
      "tree": "af95b1cf04e9b9185667f76cb661d51b48f48340",
      "parents": [
        "5422e496b313b9b0b2f6df068902d6c79925d5e9",
        "b41df707b6d7b7ae6188c6fc37ba81859293cb94"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 16:41:30 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 16:41:30 2026 -0700"
      },
      "message": "Merge tag \u0027drm-next-2026-06-27\u0027 of https://gitlab.freedesktop.org/drm/kernel\n\nPull drm merge window fixes from Dave Airlie:\n \"This is the merge window fixes from our next tree, i915/xe and amdgpu\n  make up all of it.\n\n  I\u0027ve got a separate fixes pull from our fixes branch arriving after\n  this.\n\n  i915:\n   - Fix corrupted display output on GLK, #16209\n   - Add missing Spectre mitigation for parallel submit IOCTL\n   - MTL+ fix for DP resume\n   - clear CRTC blobs after dropping refs\n   - fix sharpness filter on DP MST\n\n  xe:\n   - Set TTM beneficial order to 9 in Xe\n   - Several error path cleanups\n   - Fix TDR for unstarted jobs on kernel queues\n   - Several TLB invalidation fixes related to suspending LR queues\n   - Some small RAS fixes\n   - Multi-queue suspend fix for LR queues\n   - Revert inclusion of NVL_S firmware\n\n  amdgpu:\n   - devcoredump fixes\n   - SMU15 fix\n   - Various irq put/get imbalance cleanup fixes\n   - 8K panel fix\n   - DCN3.5 fix\n   - lockdep fix\n   - Cleaner shader sysfs IB overflow fix\n   - Async flip fixes\n   - GET_MAPPING_INFO fix\n   - CP_GFX_SHADOW fix\n   - Ctx pstate handling fix\n   - GTT bo move handling fixes\n   - Old UVD BO placement fixes\n   - GC9 mode2 reset fix\n   - IH6.1 version fix\n   - Soft IH ring fix\n\n  amdkfd:\n   - Fix doorbell/mmio double unpin on free\n   - CRIU fixes\n   - SMI event fixes\n   - Sysfs teardown fix\n   - Various boundary checking fixes\n   - Various error checking fixes\n   - SVM fix\"\n\n* tag \u0027drm-next-2026-06-27\u0027 of https://gitlab.freedesktop.org/drm/kernel: (52 commits)\n  drm/i915/cdclk: Fix up CDCLK_FREQ_DECIMAL without a full PLL re-enable\n  drm/i915/gem: Add missing nospec on parallel submit slot\n  drm/amdgpu: Use system unbound workqueue for soft IH ring\n  amdgpu/ih6.1: Fix minor version\n  drm/amdkfd: Use exclusive bounds for SVM split alignment checks\n  drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2\n  drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn\u0027t at 0 (v2)\n  drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older\n  drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT\n  drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions\n  drm/amdgpu: Fix context pstate override handling\n  drm/amdkfd: Use memdup_array_user to copy data from/to user space at kfd ioctls\n  drm/amdkfd: check find_first_zero_bit before __set_bit on kfd-\u003edoorbell_bitmap\n  drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl\n  drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format\n  drm/amdgpu: convert amdgpu_vm_lock_by_pasid() to drm_exec\n  drm/amdgpu: Don\u0027t use UTS_RELEASE directly\n  drm/amdkfd: Fix NULL deref during sysfs teardown\n  drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1\n  drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO\n  ...\n"
    },
    {
      "commit": "5422e496b313b9b0b2f6df068902d6c79925d5e9",
      "tree": "e4d2c72b2aec88d1fd1857e0464abe8742e13e30",
      "parents": [
        "5f80d9113360c08111ae7471f662f3f89f23ce32",
        "7e1f9e2cd2d0e780c394a4402c40e125109fec72"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 16:15:53 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 16:15:53 2026 -0700"
      },
      "message": "Merge tag \u0027ceph-for-7.2-rc1\u0027 of https://github.com/ceph/ceph-client\n\nPull ceph updates from Ilya Dryomov:\n \"This adds support for manual client session reset in CephFS, allowing\n  operators to get out of tricky livelock situations involving caps and\n  file locks without evicting the problematic client instance on the MDS\n  side or rebooting the client node both of which can be disruptive\"\n\n* tag \u0027ceph-for-7.2-rc1\u0027 of https://github.com/ceph/ceph-client:\n  ceph: add manual reset debugfs control and tracepoints\n  ceph: add client reset state machine and session teardown\n  ceph: add diagnostic timeout loop to wait_caps_flush()\n  ceph: harden send_mds_reconnect and handle active-MDS peer reset\n  ceph: use proper endian conversion for flock_len in reconnect\n  ceph: convert inode flags to named bit positions and atomic bitops\n  rbd: switch to dynamic root device\n"
    },
    {
      "commit": "5f80d9113360c08111ae7471f662f3f89f23ce32",
      "tree": "67e4c1bc0bfdf2961c3028337542a6e71540c443",
      "parents": [
        "2dec87d0b195463fc4ea4b0817d3049630aebf3d",
        "4982e58669b11c43644efb5fb7435975848b716e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 15:13:06 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 15:13:06 2026 -0700"
      },
      "message": "Merge tag \u0027gfs2-for-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gfs2/linux-gfs2\n\nPull gfs2 updates from Andreas Gruenbacher:\n\n - fix page poisoning not handled correctly when growing files\n\n - quota initialization / destruction fixes: sleeping under a bitlock in\n   PREEMPT_RT, broken quota_init error recovery, missing RCU\n   synchronization\n\n* tag \u0027gfs2-for-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/gfs2/linux-gfs2:\n  gfs2: page poisoning fix\n  gfs2: Remove unused fallocate_chunk argument\n  gfs2: fix use-after-free in gfs2_qd_dealloc\n  gfs2: move quota_init qc iterator increment\n  gfs2: fix quota init duplicate scan\n"
    },
    {
      "commit": "2dec87d0b195463fc4ea4b0817d3049630aebf3d",
      "tree": "d03a35429dae4dcd92e538b6427ceca9d58a8928",
      "parents": [
        "e27d4bbe0d7380d9d26910de70541af6e77c29ea",
        "795f1b1a91ae13ebc012a364075e42f486a1cafe"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:24:59 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:24:59 2026 -0700"
      },
      "message": "Merge tag \u0027thermal-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n\nPull thermal control fixes from Rafael Wysocki:\n \"These fix a failure path in an Intel thermal driver and prevent\n  thermal testing module code from being executed after it has been\n  freed:\n\n   - Fix dangling resources on thermal_throttle_online() failure in the\n     Intel thermal_throttle driver (Ricardo Neri)\n\n   - Eliminate a possibility of running thermal testing module code\n     after that module has been removed (Rafael Wysocki)\"\n\n* tag \u0027thermal-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:\n  thermal: testing: zone: Flush work items during cleanup\n  thermal: intel: Fix dangling resources on thermal_throttle_online() failure\n"
    },
    {
      "commit": "e27d4bbe0d7380d9d26910de70541af6e77c29ea",
      "tree": "89e5516a06723c560e36dfdea5d39696d581ebf6",
      "parents": [
        "737b9ff0c816f7d2eac91897e44e89984939662c",
        "3a2976df778a9af95e91f7ff88008b4517ddc658"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:14:18 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:14:18 2026 -0700"
      },
      "message": "Merge tag \u0027pm-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n\nPull power management fixes from Rafael Wysocki:\n \"These fix the schedutil cpufreq governor and drop a bogus warning\n  from the cpuidle core:\n\n   - Remove a misguided warning along with an inaccurate comment\n     next to it from the cpuidle core (Rafael Wysocki)\n\n   - Clear need_freq_update as appropriate in the .adjust_perf()\n     path of the schedutil cpufreq governor to avoid calling\n     cpufreq_driver_adjust_perf() unnecessarily on every scheduler\n     utilization update (Zhongqiu Han)\"\n\n* tag \u0027pm-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:\n  cpuidle: Allow exit latency to exceed target residency\n  cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path\n"
    },
    {
      "commit": "737b9ff0c816f7d2eac91897e44e89984939662c",
      "tree": "cec5386e57d74bb3eca8ce12c25b9584c5617dc4",
      "parents": [
        "f0789fd342e015b20b4d2cb43b473268825ae077",
        "cf1e70d021343d33728e54a6227607925c8d5419"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:00:10 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 13:00:10 2026 -0700"
      },
      "message": "Merge tag \u0027acpi-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm\n\nPull ACPI support fixes and cleanups from Rafael Wysocki:\n \"These fix assorted issues and do cleanups in the ACPI support code,\n  which includes a fix for tools build breakage related to strncpy()\n  removal:\n\n   - Unbreak ACPICA tools builds after switching over to using\n     strscpy_pad() that is kernel-specific (Rafael Wysocki)\n\n   - Fix module parameter file paths in comments in the ACPI code\n     managing the general sysfs attributes (Zenghui Yu)\n\n   - Update kerneldoc comments in the ACPI resource management code to\n     follow the common style (Andy Shevchenko)\n\n   - Fix inverted interface check in ipmi_bmc_gone() that may cause ACPI\n     IPMI interfaces to be mishandled (Xu Rao)\n\n   - Add __cpuidle annotation to idle state management functions related\n     to ACPI _LPI to avoid trace-induced RCU warnings (Li RongQing)\"\n\n* tag \u0027acpi-7.2-rc1-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/rafael/linux-pm:\n  ACPI: processor_idle: Mark LPI enter functions as __cpuidle\n  ACPICA: Unbreak tools build after switching over to strscpy_pad()\n  ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()\n  ACPI: resource: Amend kernel-doc style\n  ACPI: sysfs: Fix path of module parameters in comments\n"
    },
    {
      "commit": "f0789fd342e015b20b4d2cb43b473268825ae077",
      "tree": "64959a75d79ef38eb02eedc3f617c97a0b8d7d58",
      "parents": [
        "76bf0658d66d69b24a0676ea113e710b2f6a257b",
        "245404c26563aafb36aafb01298f148db1851be3"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 11:18:49 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 11:18:49 2026 -0700"
      },
      "message": "Merge tag \u0027spi-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi\n\nPull spi fixes from Mark Brown:\n \"A fairly unremarkable collection of fixes that came in over the\n  merge window, plus a new device ID for the DesignWare controller\n  in the StarFive JHB100 SoC.\n\n  There\u0027s a couple of core fixes included, one avoiding freeing an\n  empty resource in error handling cases and another which fixes a\n  NULL dereference which could be triggered by using an abnormal\n  device registration flow like driver_override\"\n\n* tag \u0027spi-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/spi:\n  spi: imx: reconfigure for PIO when DMA cannot be started\n  spi: dw: Add support for snps,dwc-ssi-2.00a\n  spi: dt-bindings: snps,dw-apb-ssi: Add starfive,jhb100-spi\n  spi: rpc-if: Use correct device for hardware reinitialization on resume\n  spi: acpi: Free resource list at appropriate time\n  spi: dw: fix wrong BAUDR setting after resume\n  spi: uniphier: Fix completion initialization order before devm_request_irq()\n  spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data()\n"
    },
    {
      "commit": "76bf0658d66d69b24a0676ea113e710b2f6a257b",
      "tree": "e8197834d2bae9e2111857700d53fdfe2d84c068",
      "parents": [
        "fa956617b89c0669c651bf4f301ded8e9b20c6db",
        "7ddbf1cde4a03e36e17d06fbc711870eb0b256d7"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 11:07:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 11:07:26 2026 -0700"
      },
      "message": "Merge tag \u0027regulator-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator\n\nPull regulator fixes from Mark Brown:\n \"A couple of unremarkable driver specific fixes that came in during the\n  merge window\"\n\n* tag \u0027regulator-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regulator:\n  regulator: da9121: Use subvariant ids in the I2C table\n  regulator: pca9450: Correct default t_off_deb for PCA9451A/PCA9452\n"
    },
    {
      "commit": "fa956617b89c0669c651bf4f301ded8e9b20c6db",
      "tree": "11d19726f55758994c4a7adc14cac6c61b1e131a",
      "parents": [
        "fc91b7d77d78c6381b437b7c96aca6b03f7bbfed",
        "9108f7fa493b4c88cbc09503e0c164244456bad5"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 10:47:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 10:47:26 2026 -0700"
      },
      "message": "Merge tag \u0027regmap-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap\n\nPull regmap fix from Mark Brown:\n \"Ensure that we don\u0027t overwrite the error code when cleaning up a\n  failed cache initialisation, helping people debug issues if they\n  do arise\"\n\n* tag \u0027regmap-fix-v7.2-merge-window\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/broonie/regmap:\n  regcache: Do not overwrite error code when finalizing cache after error\n"
    },
    {
      "commit": "795f1b1a91ae13ebc012a364075e42f486a1cafe",
      "tree": "baa348e26dd36bad00f5e4f318f0540ea2fb6cf4",
      "parents": [
        "b91d287fa7a1ba0727eed5823c6ee4924ee5fa31",
        "fb1a5dfe86d3af1e1c3ce168cf0d8d43897e0f77"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 19:28:27 2026 +0200"
      },
      "committer": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 19:28:27 2026 +0200"
      },
      "message": "Merge branch \u0027thermal-testing\u0027\n\nMerge a fix eliminating a possibility of running the thermal testing\nmodule code after that module has been removed.\n\n* thermal-testing:\n  thermal: testing: zone: Flush work items during cleanup\n"
    },
    {
      "commit": "3a2976df778a9af95e91f7ff88008b4517ddc658",
      "tree": "8a95eb7cd823a41ee0f213730df4f18a55a0cb11",
      "parents": [
        "9ef450ca74e43dacf9a2a15db7a851052c78dcf0",
        "68ff4a3ccda9f98c74f23c70c8c7c581f9eee931"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 19:20:01 2026 +0200"
      },
      "committer": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 19:20:01 2026 +0200"
      },
      "message": "Merge branch \u0027pm-cpuidle\u0027\n\nMerge a cpuidle core fix that removes a misguided warning along with an\ninaccurate comment next to it.\n\n* pm-cpuidle:\n  cpuidle: Allow exit latency to exceed target residency\n"
    },
    {
      "commit": "cf1e70d021343d33728e54a6227607925c8d5419",
      "tree": "a904316ce8be432bdd82a91f9473cd96ae7f2352",
      "parents": [
        "292db66afd20dd0b7a3c9a3dad9b864a64c8bddf",
        "b2b42ad22828da9cdb876eedb8914134e0759355",
        "78ad5c7722b7bed9d35ffc5b45eb0f12e2c22fee",
        "71b57aca295d61276a60e131d8f62b0cc7cf1a35",
        "956ca5d72c76504824c8eb601879da9476973e15"
      ],
      "author": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 18:57:38 2026 +0200"
      },
      "committer": {
        "name": "Rafael J. Wysocki",
        "email": "rafael.j.wysocki@intel.com",
        "time": "Fri Jun 26 18:57:38 2026 +0200"
      },
      "message": "Merge branches \u0027acpi-sysfs\u0027, \u0027acpi-resource\u0027, \u0027acpi-driver\u0027 and \u0027acpi-processor\u0027\n\nMerge an update of comments regarding the ACPI sysfs code, a kernel-doc\nstyle fixup update of ACPI resource management, and ACPI IPMI driver\nfix, and an ACPI processor driver fix for 7.2-rc1:\n\n - Fix module parameter file paths in comments in the ACPI code managing\n   the general sysfs attributes (Zenghui Yu)\n\n - Update kerneldoc comments in the ACPI resource management code to\n   follow the common style (Andy Shevchenko)\n\n - Fix inverted interface check in ipmi_bmc_gone() which may cause ACPI\n   IPMI interfaces to be mishandled (Xu Rao)\n\n - Add __cpuidle to idle state management functions related to ACPI _LPI\n   to avoid trace-induced RCU warnings (Li RongQing)\n\n* acpi-sysfs:\n  ACPI: sysfs: Fix path of module parameters in comments\n\n* acpi-resource:\n  ACPI: resource: Amend kernel-doc style\n\n* acpi-driver:\n  ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()\n\n* acpi-processor:\n  ACPI: processor_idle: Mark LPI enter functions as __cpuidle\n"
    },
    {
      "commit": "fc91b7d77d78c6381b437b7c96aca6b03f7bbfed",
      "tree": "f73b4d52754f196a96c20bfdd6b560660dada377",
      "parents": [
        "51cb1aa1250c36269474b8b6ca6b6319e170f5a5",
        "b39a6b2e9d5bd6a3153aed4c7440172b8f6a739e"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 09:14:52 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 09:14:52 2026 -0700"
      },
      "message": "Merge tag \u0027devicetree-fixes-for-7.2-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux\n\nPull devicetree fixes from Rob Herring:\n\n - Drop unnecessary type reference from khadas,mcu \"fan-supply\"\n\n - Fix clocks in Renesas R-Mobile APE6 example\n\n - Add missing Unisoc SC2730 PMIC regulators schema\n\n - Fix Amlogic thermal example\n\n - kernel-doc fix for of_map_id()\n\n - Handle negative index in of_fwnode_get_reference_args()\n\n* tag \u0027devicetree-fixes-for-7.2-1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/robh/linux:\n  dt-bindings: mfd: khadas,mcu: Drop type reference from \"fan-supply\"\n  dt-bindings: clock: renesas: div6: Use ZT/ZTR trace clock in R-Mobile APE6 example\n  regulator: dt-bindings: Add Unisoc SC2730 PMIC\n  dt-bindings: thermal: amlogic: Correct \u0027reg\u0027 in the example\n  dt-bindings: thermal: amlogic: Fix missing header in the example\n  of: Fix RST inline emphasis warnings in of_map_id() kernel-doc\n  of: property: Fix of_fwnode_get_reference_args() with negative index\n"
    },
    {
      "commit": "51cb1aa1250c36269474b8b6ca6b6319e170f5a5",
      "tree": "cfdfc6da1dcd0cd44e7ddc98b505e931a6ac65d7",
      "parents": [
        "e7c93451eeb06b67b4eb23017824b3dee90b360e",
        "262a3b4fa1792d40728c69995924e11cf761f5cf"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:42:49 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:42:49 2026 -0700"
      },
      "message": "Merge tag \u0027loongarch-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson\n\nPull LoongArch updates from Huacai Chen:\n\n - Add THREAD_INFO_IN_TASK implementation\n\n - Add build salt to the vDSO\n\n - Add some BPF JIT inline helpers\n\n - Update DTS for I2C clocks and clock-frequency\n\n - Some bug fixes and other small changes\n\n* tag \u0027loongarch-7.2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/chenhuacai/linux-loongson:\n  selftests/bpf: Test jited inline of bpf_get_smp_processor_id() for LoongArch\n  selftests/bpf: Test jited inline of bpf_get_current_task() for LoongArch\n  selftests/bpf: Add __arch_loongarch to limit test cases for LoongArch\n  selftests/bpf: Add get_preempt_count() support for LoongArch\n  LoongArch: dts: Add i2c clocks and clock-frequency properties to LS2K2000\n  LoongArch: dts: Add i2c clocks and clock-frequency properties to LS2K1000\n  LoongArch: dts: Add i2c clocks and clock-frequency properties to LS2K0500\n  LoongArch: BPF: Inline bpf_get_smp_processor_id() helper\n  LoongArch: BPF: Inline bpf_get_current_task/_btf() helpers\n  LoongArch: BPF: Fix off-by-one error in tail call\n  LoongArch: BPF: Fix outdated tail call comments\n  LoongArch: Add build salt to the vDSO\n  LoongArch: Fix nr passing in set_direct_map_valid_noflush()\n  LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()\n  LoongArch: Move struct kimage forward declaration before use\n  LoongArch: Report dying CPU to RCU in stop_this_cpu()\n  LoongArch: Add PIO for early access before ACPI PCI root register\n  LoongArch: Add THREAD_INFO_IN_TASK implementation\n"
    },
    {
      "commit": "e7c93451eeb06b67b4eb23017824b3dee90b360e",
      "tree": "281a9534b09205855748ced071f2df5c0fb078b8",
      "parents": [
        "c292ea294dde77ae442d3d764f53c251d2d6df90",
        "36fa5ffa60344bcc59fb3f50b33af8187e6b8753"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:40:35 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:40:35 2026 -0700"
      },
      "message": "Merge tag \u0027arm64-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux\n\nPull arm64 fixes from Will Deacon:\n \"Small crop of arm64 fixes for -rc1. We\u0027ve got a build fix for a new\n  randconfig permutation, a fix for a long-standing truncation issue\n  with hardware watchpoints and a KVM initialisation fix for the newly\n  merged remapping of the kernel data and bss sections:\n\n   - Fix randconfig build failure due to missing include of asm/insn.h\n\n   - Reject unaligned hardware watchpoints which were silently being\n     truncated\n\n   - Fix crash in KVM initialisation by deferring the read-only\n     remapping of the kernel data and bss sections\"\n\n* tag \u0027arm64-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux:\n  arm64: mm: Defer read-only remap of data/bss linear alias\n  arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS\n  arm64: static_call: include asm/insns.h\n"
    },
    {
      "commit": "c292ea294dde77ae442d3d764f53c251d2d6df90",
      "tree": "db4c86e39fff208efba3b063f5b660c090f18c67",
      "parents": [
        "71fab6fa7615fdf52679a3f80795f33b7f7e61d6",
        "95ce5ffd54cf66098f91892f98606c3bd33846fe"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:24:06 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:24:06 2026 -0700"
      },
      "message": "Merge tag \u0027ecryptfs-7.2-rc1-updates\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tyhicks/ecryptfs\n\nPull ecryptfs updates from Tyler Hicks:\n \"No functional changes, just code cleanups:\n\n   - replace kmalloc()/snprintf() with kasprintf()\n\n   - simplify code flow by removing an unnecessary variable\"\n\n* tag \u0027ecryptfs-7.2-rc1-updates\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/tyhicks/ecryptfs:\n  ecryptfs: use kasprintf in ecryptfs_crypto_api_algify_cipher_name\n  ecryptfs: remove redundant variable found_auth_tok\n"
    },
    {
      "commit": "71fab6fa7615fdf52679a3f80795f33b7f7e61d6",
      "tree": "23cde22e8aeb5159de5e8baa491334e9172c2b6f",
      "parents": [
        "ad054be8117d06838b4d904dc57e0807768658cb",
        "da793cf6d60233f47ea5e7e9e39425d71dfcdb79"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:17:42 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Fri Jun 26 08:17:42 2026 -0700"
      },
      "message": "Merge tag \u0027v7.2-rc-part2-smb3-server-fixes\u0027 of git://git.samba.org/ksmbd\n\nPull smb server updates from Steve French:\n \"This is mostly a correctness and compatibility update for ksmbd\u0027s\n  SMB2/3 lease, oplock, durable handle, compound request, CREATE,\n  rename, stream and share-mode handling.\n\n  A large part of the series fixes cases found by smbtorture where ksmbd\n  diverged from the SMB2/3 protocol requirements.\n\n  The main changes are:\n\n   - Rework SMB2 lease state handling so lease state is shared per\n     ClientGuid/LeaseKey across opens, with better validation of lease\n     create contexts, ACK handling, epochs, break-in-progress reporting,\n     v2 lease notification routing, and chained lease breaks\n\n   - Fix several oplock break corner cases, including ACK validation,\n     timeout downgrade behavior, level-II break handling on unlink,\n     share-conflict lease breaks, and read-control/stat-open behavior\n\n   - Fix durable handle behavior around delete-on-close, stale\n     reconnects, reconnect context parsing, oplock/lease break\n     invalidation, and durable v2 AppInstanceId replacement\n\n   - Fix compound request handling so related commands propagate failed\n     statuses correctly, preserve response framing across chained\n     errors, keep compound FIDs across READ/WRITE/FLUSH, and send\n     interim STATUS_PENDING where clients expect cancellable compound\n     I/O\n\n   - Tighten CREATE and stream semantics, including create attribute\n     validation, allocation size reporting, explicit create security\n     descriptors, unnamed DATA stream handling, stream directory\n     validation, and stream delete sharing against the base file\n\n   - Fix rename and metadata behavior, including parent directory\n     sharing checks, denying directory rename with open children, and\n     preserving SMB ChangeTime across rename for open handles\n\n   - Fix two important safety issues: a multichannel byte-range lock\n     list owner race that could lead to use-after-free, and an NTLMv2\n     session key update before authentication proof validation\n\n   - Fix a concurrent SMB2 NEGOTIATE preauth use-after-free, a UBSAN\n     warning in compression capability parsing, a false hung-task\n     warning in the durable handle scavenger, endian debug logging,\n     Smatch indentation warnings, and kernel-doc warnings\n\n   - Increase the default SMB3 transaction size from 1MB to 4MB to\n     better match modern read/write negotiation and improve sequential\n     I/O behavior\"\n\n* tag \u0027v7.2-rc-part2-smb3-server-fixes\u0027 of git://git.samba.org/ksmbd: (50 commits)\n  ksmbd: fix kernel-doc warnings in smb2_lease_break_noti()\n  ksmbd: fix inconsistent indenting warnings\n  ksmbd: validate NTLMv2 response before updating session key\n  ksmbd: increase SMB3_DEFAULT_TRANS_SIZE from 1MB to 4MB\n  ksmbd: fix UBSAN array-index-out-of-bounds in decode_compress_ctxt()\n  ksmbd: sleep interruptibly in the durable handle scavenger\n  ksmbd: start file id allocation at 1\n  ksmbd: treat read-control opens as stat opens only for leases\n  ksmbd: validate :: stream type against directory create\n  ksmbd: break conflicting-open leases only as far as needed\n  ksmbd: break handle caching for share conflicts\n  ksmbd: normalize ungrantable lease states\n  ksmbd: return oplock protocol error for level II ack\n  ksmbd: avoid level II oplock break notification on unlink\n  ksmbd: downgrade oplock after break timeout\n  ksmbd: apply create security descriptor first\n  ksmbd: return requested create allocation size\n  ksmbd: tighten create file attribute validation\n  ksmbd: reject empty-attribute synchronize-only create\n  ksmbd: honor stream delete sharing for base file\n  ...\n"
    },
    {
      "commit": "7f08fc10fa3d3366dc3af723970bd03d7d6d10e3",
      "tree": "d020ae878641a940bffb611fca0fbf6cc92353b5",
      "parents": [
        "5fae9a928482d4845bca169a3a098789203a1ca4"
      ],
      "author": {
        "name": "Ian Bridges",
        "email": "icb@fastmail.org",
        "time": "Wed Jun 24 23:13:12 2026 -0500"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Fri Jun 26 15:12:45 2026 +0200"
      },
      "message": "fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var\n\ninfo-\u003evar, a framebuffer\u0027s current mode, is expected to have a matching\nentry in info-\u003emodelist. var_to_display() relies on this and treats a\nfailed fb_match_mode() as \"This should not happen\". fb_set_var() keeps it\ntrue by adding the mode to the list on every change, and\ndo_register_framebuffer() does the same at registration.\n\nstore_modes() replaces the modelist from userspace. fb_new_modelist()\nvalidates the new modes but does not check that info-\u003evar still has a\nmatch. It relies on fbcon_new_modelist() to re-point consoles, but that\nonly handles consoles mapped to the framebuffer. With fbcon unbound there\nare none, so info-\u003evar is left describing a mode that is no longer in the\nlist.\n\nA later console takeover runs var_to_display(), where fb_match_mode()\nreturns NULL and leaves fb_display[i].mode NULL. fbcon_switch() passes it\nto display_to_var(), and fb_videomode_to_var() dereferences the NULL mode.\n\nKeep the current mode in the list in fb_new_modelist(), the same way\nfb_set_var() does.\n\nCc: stable@vger.kernel.org\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Ian Bridges \u003cicb@fastmail.org\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "5fae9a928482d4845bca169a3a098789203a1ca4",
      "tree": "389dbf8ac1c93aa8401c7e3841818b119de6a467",
      "parents": [
        "2c1c805c65fb7dc7524e20376d6987721e73a0b1"
      ],
      "author": {
        "name": "Ian Bridges",
        "email": "icb@fastmail.org",
        "time": "Wed Jun 24 16:11:36 2026 -0500"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Fri Jun 26 15:07:38 2026 +0200"
      },
      "message": "fbcon: fix NULL pointer dereference for a console without vc_data\n\nfbcon_new_modelist() runs when a framebuffer\u0027s modelist changes. For each\nconsole mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and\npasses the vc_num to fbcon_set_disp(). This assumes a console with a mode\nset has a vc_data, but it can be NULL. fbcon_set_disp() sets\nfb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the\nmode set after the vc_data is freed. fbcon_new_modelist() then dereferences\nthe NULL vc_data.\n\nKeep fb_display[i].mode set only while the console has a vc_data. Check\nvc_data before setting the mode in fbcon_set_disp(), and clear the mode in\nfbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips\nsuch consoles.\n\nReported-by: syzbot+42525d636f430fd5d983@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d42525d636f430fd5d983\nCc: stable@vger.kernel.org\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Ian Bridges \u003cicb@fastmail.org\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "2c1c805c65fb7dc7524e20376d6987721e73a0b1",
      "tree": "ef14394f1b07b380defb5b0726b0cbf83784ff83",
      "parents": [
        "4da933bf4e7317310f32d6918c774174253483c1"
      ],
      "author": {
        "name": "Ian Bridges",
        "email": "icb@fastmail.org",
        "time": "Thu Jun 25 23:50:48 2026 -0500"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Fri Jun 26 14:56:13 2026 +0200"
      },
      "message": "fbdev: fix use-after-free in store_modes()\n\nstore_modes() replaces a framebuffer\u0027s modelist with modes from userspace.\nOn success it frees the old modelist with fb_destroy_modelist(). Two\nfields still point into that freed list.\n\nOne pointer is fb_display[i].mode, the mode a console is using.\nfbcon_new_modelist() moves these pointers to the new list. It only does so\nfor consoles still mapped to the framebuffer. An unmapped console is\nskipped and keeps its stale pointer. Unbinding fbcon, for example, sets\ncon2fb_map[i] to -1 but leaves fb_display[i].mode set. An\nFBIOPUT_VSCREENINFO ioctl with FB_ACTIVATE_INV_MODE later reaches\nfbcon_mode_deleted(). That function reads the stale fb_display[i].mode\nthrough fb_mode_is_equal(). The read is a use-after-free.\n\nThe other pointer is fb_info-\u003emode, the current mode. It is set through\nthe mode sysfs attribute. store_modes() does not update fb_info-\u003emode, so\nit is left pointing into the freed list. show_mode(), the attribute\u0027s read\nhandler, dereferences the stale fb_info-\u003emode through mode_string(). The\nread is a use-after-free.\n\nClear both pointers before freeing the list. Commit a1f305893074 (\"fbcon:\nSet fb_display[i]-\u003emode to NULL when the mode is released\") added the\nhelper fbcon_delete_modelist(). It clears every fb_display[i].mode that\npoints into a given list. So far it is called only from the unregister\npath. Call it from store_modes() too, and set fb_info-\u003emode to NULL.\n\nReported-by: syzbot+81c7c6b52649fd07299d@syzkaller.appspotmail.com\nCloses: https://syzkaller.appspot.com/bug?extid\u003d81c7c6b52649fd07299d\nCc: stable@vger.kernel.org\nLink: https://lore.kernel.org/all/ajjoDhAi2y4ArSlz@dev/\nAssisted-by: Claude:claude-opus-4-8\nSigned-off-by: Ian Bridges \u003cicb@fastmail.org\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c",
      "tree": "29a9b9af113b578b625a115338d76d2cf318e8f4",
      "parents": [
        "9dbbe81962b973fe71592ad8615d1e6cd28451bf"
      ],
      "author": {
        "name": "Jiaming Zhang",
        "email": "r772577952@gmail.com",
        "time": "Thu Jun 25 21:49:33 2026 +0800"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jun 26 07:46:59 2026 +0200"
      },
      "message": "ALSA: FCP: Fix NULL pointer dereference in interface lookup\n\nA malformed USB device can provide a vendor-specific interface without\nany endpoint descriptors. fcp_find_fc_interface() currently selects the\nfirst vendor-specific interface and reads endpoint 0 from it, without\nchecking whether the interface actually has any endpoints.\n\nWhen bNumEndpoints is zero, no endpoint array is allocated for the parsed\nalternate setting, so get_endpoint(..., 0) yields an invalid endpoint\ndescriptor pointer. Dereferencing it through usb_endpoint_num() then\ntriggers a NULL pointer dereference.\n\nSkip vendor-specific interfaces that do not have any endpoints.\n\nFixes: 46757a3e7d50 (\"ALSA: FCP: Add Focusrite Control Protocol driver\")\nReported-by: Jiaming Zhang \u003cr772577952@gmail.com\u003e\nCloses: https://lore.kernel.org/lkml/CANypQFb1EHj0xX8bA1WxSOSK-5xca6ZNKzOQcp12\u003ds\u003dpuY7VFw@mail.gmail.com/\nSigned-off-by: Jiaming Zhang \u003cr772577952@gmail.com\u003e\nLink: https://patch.msgid.link/20260625134933.425785-1-r772577952@gmail.com\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\n"
    },
    {
      "commit": "9dbbe81962b973fe71592ad8615d1e6cd28451bf",
      "tree": "cb672e8bb844ae5146907b60c69d0c04075797a7",
      "parents": [
        "677b16108a7457c1fa1cd1b39301e46dfc3aed06"
      ],
      "author": {
        "name": "Oleg Kucheryavenko",
        "email": "oleg.kucheryavenko2018@gmail.com",
        "time": "Thu Jun 25 16:49:55 2026 +0300"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jun 26 07:45:13 2026 +0200"
      },
      "message": "ALSA: hda/realtek: Update Acer Nitro ANV15-41 quirk to enable mute LED\n\nThe laptop has a microphone mute LED on the F4 key, but it was not\ntaken in mind when the previous quirk was added\nin commit 00e44a68efef50f65b12854b41f098b4d50f10be (\"ALSA:\nhda/realtek: Add quirk for Acer Nitro ANV15-41\").\nReplace ALC2XX_FIXUP_HEADSET_MIC with ALC245_FIXUP_ACER_MICMUTE_LED,\nwhich enables the LED and chains the previous quirk for the headset\nmicrophone.\n\nFixes: 00e44a68efef (\"ALSA: hda/realtek: Add quirk for Acer Nitro ANV15-41\")\nSigned-off-by: Oleg Kucheryavenko \u003coleg.kucheryavenko2018@gmail.com\u003e\nLink: https://patch.msgid.link/20260625134955.27465-1-oleg.kucheryavenko2018@gmail.com\nSigned-off-by: Takashi Iwai \u003ctiwai@suse.de\u003e\n"
    },
    {
      "commit": "677b16108a7457c1fa1cd1b39301e46dfc3aed06",
      "tree": "7fb2eeffe0f8036ad239f41c73fc7b41d5455baa",
      "parents": [
        "29b9667982e4df2ed7744f86b1144f8bb58eb698",
        "cf6f56990ea21172e085f0588e5bbf2089ce8f58"
      ],
      "author": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jun 26 07:33:15 2026 +0200"
      },
      "committer": {
        "name": "Takashi Iwai",
        "email": "tiwai@suse.de",
        "time": "Fri Jun 26 07:33:15 2026 +0200"
      },
      "message": "Merge tag \u0027asoc-fix-v7.2-merge-window\u0027 of https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound into for-linus\n\nASoC: Fixes for v7.2\n\nWe\u0027ve got a good collection of device specific fix here, plus a couple\nof stand out things:\n\n - Richard fixed some special cases with the new device_link creation\n   by more gracefully handling any errors during creation.\n - Charles did some light refactoring of the SoundWire interfaces to\n   fix some persistent randconfig issues that people kept running into.\n"
    },
    {
      "commit": "d577e46785d45484b2ab7e7309c49b18764bf56c",
      "tree": "8f686b72803bea66cbb88b1af7099d81d1aad409",
      "parents": [
        "57c10915f2c16c90e0d46ad00876bf39ece40fc2"
      ],
      "author": {
        "name": "Bryam Vargas",
        "email": "hexlabsecurity@proton.me",
        "time": "Sun Jun 14 00:36:12 2026 -0500"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Thu Jun 25 17:46:20 2026 -0700"
      },
      "message": "Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count\n\nrmi_f30_map_gpios() allocates gpioled_key_map with\nmin(gpioled_count, TRACKSTICK_RANGE_END) \u003d\u003d at most 6 entries, but\nrmi_f30_attention() iterates the full f30-\u003egpioled_count (device query\nregister, range 0..31) and dereferences gpioled_key_map[i], and\ninput-\u003ekeycodemax is set to the full gpioled_count while input-\u003ekeycode\npoints at the 6-entry allocation.\n\nA device that reports gpioled_count \u003e 6 with GPIO support enabled\ntherefore causes an out-of-bounds read on the attention interrupt and\nout-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,\nwhich bound the index only against keycodemax. This is the same defect\nas the F3A handler, which was copied from F30.\n\nSize the keymap for the full gpioled_count; the mapping loop still\nassigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.\n\nFixes: 3e64fcbdbd10 (\"Input: synaptics-rmi4 - limit the range of what GPIOs are buttons\")\nCc: stable@vger.kernel.org\nSigned-off-by: Bryam Vargas \u003chexlabsecurity@proton.me\u003e\nLink: https://patch.msgid.link/20260614-b4-disp-818d6bda-v1-2-cf39a3615085@proton.me\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "57c10915f2c16c90e0d46ad00876bf39ece40fc2",
      "tree": "a82ea527642562c6fe38d94078a918882fe2550d",
      "parents": [
        "7a0e692a0381254b2f77c54dec100cd3325a6fdf"
      ],
      "author": {
        "name": "Bryam Vargas",
        "email": "hexlabsecurity@proton.me",
        "time": "Sun Jun 14 00:36:11 2026 -0500"
      },
      "committer": {
        "name": "Dmitry Torokhov",
        "email": "dmitry.torokhov@gmail.com",
        "time": "Thu Jun 25 17:46:20 2026 -0700"
      },
      "message": "Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count\n\nrmi_f3a_initialize() takes the GPIO count from the device query register\n(f3a-\u003egpio_count \u003d buf \u0026 RMI_F3A_GPIO_COUNT, range 0..127).\nrmi_f3a_map_gpios() then allocates gpio_key_map with\nmin(gpio_count, TRACKSTICK_RANGE_END) \u003d\u003d at most 6 entries, but\nrmi_f3a_attention() iterates the full gpio_count and dereferences\ngpio_key_map[i], and input-\u003ekeycodemax is set to the full gpio_count\nwhile input-\u003ekeycode points at the 6-entry allocation.\n\nA device that reports gpio_count \u003e 6 therefore causes an out-of-bounds\nread of gpio_key_map[] on every attention interrupt, and out-of-bounds\naccesses through the input core\u0027s default keymap ioctls: EVIOCGKEYCODE\nreads past the buffer (leaking adjacent slab memory to user space) and\nEVIOCSKEYCODE writes a caller-controlled value past it, for any process\nable to open the evdev node, since input_default_getkeycode() and\ninput_default_setkeycode() only bound the index against keycodemax.\n\nSize the keymap for the full gpio_count. The mapping loop is unchanged:\nit still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END)\nentries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills)\nand are skipped when reporting.\n\nFixes: 9e4c596bfd00 (\"Input: synaptics-rmi4 - add support for F3A\")\nCc: stable@vger.kernel.org\nSigned-off-by: Bryam Vargas \u003chexlabsecurity@proton.me\u003e\nLink: https://patch.msgid.link/20260614-b4-disp-818d6bda-v1-1-cf39a3615085@proton.me\nSigned-off-by: Dmitry Torokhov \u003cdmitry.torokhov@gmail.com\u003e\n"
    },
    {
      "commit": "ad054be8117d06838b4d904dc57e0807768658cb",
      "tree": "323710acb8fa7dc3ac7922a177f3933902c49da2",
      "parents": [
        "4edcdefd4083ae04b1a5656f4be6cd83ae919ef4",
        "f53208233b2acaafe2af99c63c02481b2f5bcb39"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 17:16:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 17:16:26 2026 -0700"
      },
      "message": "Merge tag \u0027v7.2-rc-part2-smb3-client-fixes\u0027 of git://git.samba.org/sfrench/cifs-2.6\n\nPull smb client fixes from Steve French:\n - fix potential double frees\n - fix potential memory leak in receiving compound response\n - querydir improvement\n - fix chown with smb311 posix extensions\n - ACL setting fixes\n - minor debug improvement and cleanup\n - add some missing protocol defines\n - sparse file fixes\n\n* tag \u0027v7.2-rc-part2-smb3-client-fixes\u0027 of git://git.samba.org/sfrench/cifs-2.6:\n  cifs: define variable sized buffer for querydir responses\n  smb/client: do not account EOF extension as allocation\n  smb/client: preserve errors from smb2_set_sparse()\n  smb: client: Fix next buffer leak in receive_encrypted_standard()\n  smb/client: use %pe to print error pointer\n  smb/client: name the default fallocate mode\n  smb common: add missing AAPL defines\n  smb/client: fix chown/chgrp with SMB3 POSIX Extensions\n  smb/client: fix security flag calculation when setting security descriptors\n  smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl()\n  smb: client: fix query directory replay double-free\n  smb: client: fix change notify replay double-free\n  smb: client: fix query_info() replay double-free\n  smb: client: fix double-free in SMB2_close() replay\n  smb: client: fix double-free in SMB2_ioctl() replay\n  smb: client: fix double-free in SMB2_open() replay\n  smb: client: fix double-free in SMB2_flush() replay\n"
    },
    {
      "commit": "f24ba334afafc70c3149e9db9c0cf8ecc6d52a09",
      "tree": "2d4bb0ee67c5db28de37f2e4d876d02edf465e21",
      "parents": [
        "8cd9520d35a6c38db6567e97dd93b1f11f185dc6",
        "9206b22fb959f4a9cf1921f34aed0df1dcb1ab04"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jun 26 08:16:14 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jun 26 08:16:41 2026 +1000"
      },
      "message": "Merge tag \u0027drm-misc-fixes-2026-06-25\u0027 of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes\n\ndrm-misc-fixes for v7.2:\n- drm/sysfb truncation and alignment fixes.\n- fix edid OOB read.\n- fix error handling paths in nouveau\n- amdxdna get_bo_info fix.\n- increase displayid topology id to correct size.\n- fix leak when error handling in ivpu.\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\n\nFrom: Maarten Lankhorst \u003cmaarten.lankhorst@linux.intel.com\u003e\nLink: https://patch.msgid.link/2d17f718-43f5-4772-9c04-a975c9ad4bc3@linux.intel.com\n"
    },
    {
      "commit": "b41df707b6d7b7ae6188c6fc37ba81859293cb94",
      "tree": "6d109a4a78c8a5b1ea37e40c7cc3ccc5c98c7883",
      "parents": [
        "0e8233409d4f6def051dd42a432c6815bb780d78",
        "2ee8dbd880b14fb0b5115bf2353c7900aa33b95b"
      ],
      "author": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jun 26 07:14:07 2026 +1000"
      },
      "committer": {
        "name": "Dave Airlie",
        "email": "airlied@redhat.com",
        "time": "Fri Jun 26 07:14:08 2026 +1000"
      },
      "message": "Merge tag \u0027drm-intel-next-fixes-2026-06-25-1\u0027 of https://gitlab.freedesktop.org/drm/i915/kernel into drm-next\n\n- Fix corrupted display output on GLK, #16209 (Ville)\n- Add missing Spectre mitigation for parallel submit IOCTL (Joonas)\n\nSigned-off-by: Dave Airlie \u003cairlied@redhat.com\u003e\nFrom: Joonas Lahtinen \u003cjoonas.lahtinen@linux.intel.com\u003e\nLink: https://patch.msgid.link/ajzIhInnHnGCwMlu@jlahtine-mobl\n"
    },
    {
      "commit": "4edcdefd4083ae04b1a5656f4be6cd83ae919ef4",
      "tree": "52f12981c8044a73f2b0963555bd1505c42217f1",
      "parents": [
        "8c04c1292dca29a57ea82c6a44348be49749fc22",
        "12091470c6b4c1c14b2de12dcbae2ada6cb6d20b"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 14:09:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 14:09:26 2026 -0700"
      },
      "message": "Merge tag \u0027bpf-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf\n\nPull bpf fixes from Alexei Starovoitov:\n\n - Fix effective prog array index with BPF_F_PREORDER (Amery Hung)\n\n - Zero-initialize the fib lookup flow struct (Avinash Duduskar)\n\n - Disable xfrm_decode_session hook attachment (Bradley Morgan)\n\n - Allow type tag BTF records to succeed other modifier records (Emil\n   Tsalapatis)\n\n - Fix build_id caching in stack_map_get_build_id_offset() (Ihor\n   Solodrai)\n\n - Add missing access_ok call to copy_user_syms (Jiri Olsa)\n\n - Fix stack slot index in nospec checks (Nuoqi Gui)\n\n - Preserve pointer spill metadata during half-slot cleanup (Nuoqi Gui)\n\n - Fix partial copy of non-linear test_run output (Sun Jian)\n\n - Fix BPF_PROG_ASSOC_STRUCT_OPS last field check (Thiébaud Weksteen)\n\n - Reset register bounds before narrowing retval range (Tristan Madani)\n\n - Fix vmlinux BTF leak in bpftool cgroup commands (Yichong Chen)\n\n - Guard error writes in conntrack kfuncs (Yiyang Chen)\n\n* tag \u0027bpf-fixes\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf:\n  bpf: Disable xfrm_decode_session hook attachment\n  selftests/bpf: Add test for stale bounds on LSM retval context load\n  bpf: Reset register bounds before narrowing retval range in check_mem_access()\n  selftests/bpf: Cover small conntrack opts error writes\n  bpf: Guard conntrack opts error writes\n  selftests/bpf: Cover half-slot cleanup of pointer spills\n  bpf: Preserve pointer spill metadata during half-slot cleanup\n  selftests/bpf: Test cgroup link replace with BPF_F_PREORDER\n  bpf: Fix effective prog array index with BPF_F_PREORDER\n  bpf: Fix BPF_PROG_ASSOC_STRUCT_OPS last field check\n  bpf: zero-initialize the fib lookup flow struct\n  bpftool: Fix vmlinux BTF leak in cgroup commands\n  bpf: Add missing access_ok call to copy_user_syms\n  bpf: Allow type tag BTF records to succeed other modifier records\n  bpf: Emit verbose message when prog-specific btf_struct_access rejects a write\n  bpf: Fix build_id caching in stack_map_get_build_id_offset()\n  bpf: Fix partial copy of non-linear test_run output\n  selftests/bpf: Cover stack nospec slot indexing\n  bpf: Fix stack slot index in nospec checks\n"
    },
    {
      "commit": "8c04c1292dca29a57ea82c6a44348be49749fc22",
      "tree": "3f129c03b08f493c31d163421fc5ee52aac96b9b",
      "parents": [
        "ca3e303061a4abbb92cf306aea2057c59a734757",
        "92010229c4b38897f1319d260162d2f96925ed17"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:48:57 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:48:57 2026 -0700"
      },
      "message": "Merge tag \u0027clk-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux\n\nPull clk updates from Stephen Boyd:\n \"This is all clk driver updates. Mostly new SoC support for various\n  Qualcomm chips and Canaan K230. Otherwise there\u0027s non-critical fixes\n  and updates to clk data such as adding missing clks to existing\n  drivers or marking clks critical. Nothing looks especially exciting\"\n\n* tag \u0027clk-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux: (106 commits)\n  clk: qcom: regmap-phy-mux: Rework the implementation\n  clk: qcom: a53: Corrected frequency multiplier for 1152MHz\n  clk: qcom: camcc-milos: Declare icc path dependency for CAMSS_TOP_GDSC\n  clk: qcom: gdsc: Support enabling interconnect path for power domain\n  dt-bindings: clock: qcom,milos-camcc: Document interconnect path\n  interconnect: Add devm_of_icc_get_by_index() as exported API for users\n  clk: qcom: camcc-x1p42100: Add support for camera clock controller\n  clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks\n  clk: qcom: videocc-x1p42100: Add support for video clock controller\n  dt-bindings: clock: qcom: Add X1P42100 camera clock controller\n  dt-bindings: clock: qcom: Add X1P42100 video clock controller\n  clk: keystone: sci-clk: fix application of sizeof to pointer\n  clk: keystone: don\u0027t cache clock rate\n  clk: spacemit: k3: Add PCIe DBI clock\n  dt-bindings: soc: spacemit: k3: Add PCIe DBI clock IDs\n  clk: spacemit: k3: Fix PCIe clock register offset\n  clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock\n  clk: at91: keep securam node alive while mapping it\n  clk: samsung: exynos990: Fix PERIC0/1 USI clock types\n  clk: renesas: r9a08g045: Drop unused pm_domain header file\n  ...\n"
    },
    {
      "commit": "ca3e303061a4abbb92cf306aea2057c59a734757",
      "tree": "463b24402a58baca6a8d5c57b24c96304a8b669f",
      "parents": [
        "75218b7acec35b0306572bf5fdf179486d463c9e",
        "3443eec9c55d128064c83225a9111f1a1a37277a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:38:52 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:38:52 2026 -0700"
      },
      "message": "Merge tag \u0027spmi-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/sboyd/spmi\n\nPull SPMI updates from Stephen Boyd:\n \"Support for Qualcomm PMIC arbiter v8.5 and Hawi along with a\n  kernel doc cleanup and a kzalloc flex usage\"\n\n* tag \u0027spmi-for-linus\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/sboyd/spmi:\n  spmi: use kzalloc_flex in main allocation\n  spmi: clean up kernel-doc in spmi.h\n  spmi: spmi-pmic-arb: add support for PMIC arbiter v8.5\n  dt-bindings: spmi: glymur-spmi-pmic-arb: Add compatible for Qualcomm Hawi SoC\n"
    },
    {
      "commit": "75218b7acec35b0306572bf5fdf179486d463c9e",
      "tree": "c362e3418ae53deda10d623cc0b7fb8eb17847d3",
      "parents": [
        "805185b7c7a1069e407b6f7b3bc98e44d415f484",
        "c35eb77a67515d4201bc91294f40761591f43bbd"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:33:15 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:33:15 2026 -0700"
      },
      "message": "Merge tag \u0027trace-tools-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace\n\nPull rtla fixes from Steven Rostedt:\n\n - Fix and cleanup .gitignore\n\n - Fix pgrep filter in get_workload_pids.sh\n\n   Fix parsing of kernel thread names in get_workload_pids() helper\n   function. On some systems pgrep matches kernel thread names including\n   the brackets (e.g. \"[osnoise/0]\") and other systems brackets are not\n   included. Fix the tests to handle both.\n\n* tag \u0027trace-tools-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:\n  rtla/tests: Fix pgrep filter in get_workload_pids.sh\n  rtla: Fix and clean up .gitignore\n"
    },
    {
      "commit": "805185b7c7a1069e407b6f7b3bc98e44d415f484",
      "tree": "8e252490fc55ac4a2ef591efa06d078211fc639f",
      "parents": [
        "c75597caada080effbfbc0a7fb10dc2a3bb543ad",
        "fe9f4ee6c61a1410afd73bf011de5ae618004796"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:25:36 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 12:25:36 2026 -0700"
      },
      "message": "Merge tag \u0027net-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net\n\nPull networking fixes from Jakub Kicinski:\n \"Including fixes from netfilter and IPsec.\n\n  Current release - regressions:\n\n   - do not acquire dev-\u003etx_global_lock in netdev_watchdog_up()\n\n   - ethtool: keep rtnl_lock for ops using ethtool_op_get_link()\n\n   - fix deadlock in nested UP notifier events\n\n  Current release - new code bugs:\n\n   - eth:\n      - cn20k: fix subbank free list indexing for search order\n      - airoha: fix BQL underflow in shared QDMA TX ring\n\n  Previous releases - regressions:\n\n   - netfilter:\n     - flowtable: fix offloaded ct timeout never being extended\n     - nf_conncount: prevent connlimit drops for early confirmed ct\n\n  Previous releases - always broken:\n\n   - require CAP_NET_ADMIN in the originating netns when modifying\n     cross-netns devices\n\n   - report NAPI thread PID in the caller\u0027s pid namespace\n\n   - mac802154: fix dirty frag in in-place crypto for IOT radios\n\n   - sctp: hold socket lock when dumping endpoints in sctp_diag, avoid\n     an overflow\n\n   - eth: gve: fix header buffer corruption with header-split and HW-GRO\n\n   - af_key: initialize alg_key_len for IPComp states, prevent OOB read\"\n\n* tag \u0027net-7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (213 commits)\n  selftests: bonding: add a test for VLAN propagation over a bonded real device\n  vlan: defer real device state propagation to netdev_work\n  net: add the driver-facing netdev_work scheduling API\n  net: turn the rx_mode work into a generic netdev_work facility\n  net: ethtool: keep rtnl_lock for ops using ethtool_op_get_link()\n  rxrpc: Fix rxrpc_rotate_tx_rotate() to check there\u0027s something to rotate\n  rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)\n  rxrpc: Fix socket notification race\n  rxrpc: Fix potential infinite loop in rxrpc_recvmsg()\n  rxrpc: Fix oob challenge leak in cleanup after notification failure\n  rxrpc: Fix the reception of a reply packet before data transmission\n  afs: Fix uncancelled rxrpc OOB message handler\n  afs: Fix further netns teardown to cancel the preallocation charger\n  rxrpc: Fix double unlock in rxrpc_recvmsg()\n  rxrpc: Fix leak of connection from OOB challenge\n  rxrpc: Fix ACKALL packet handling\n  net: hns3: differentiate autoneg default values between copper and fiber\n  net: hns3: fix permanent link down deadlock after reset\n  net: hns3: refactor MAC autoneg and speed configuration\n  net: hns3: unify copper port ksettings configuration path\n  ...\n"
    },
    {
      "commit": "c75597caada080effbfbc0a7fb10dc2a3bb543ad",
      "tree": "b8c2f933fbb2175cdebeaf24786fc338f42f7533",
      "parents": [
        "a142da0b2d32b68a6d1b183343bbe43de8c222f9",
        "098e32cba334da0f3fa8cfd4e022ae7c72341400"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 10:21:13 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 10:21:13 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/virt/kvm/kvm\n\nPull kvm fixes from Paolo Bonzini:\n \"s390:\n\n   - Fix S390_USER_OPEREXEC so it can now be enabled regardless of other\n     unrelated capabilities\n\n   - Fix handling of the _PAGE_UNUSED pte bit that could lead to guest\n     memory corruption in some scenarios\n\n   - A bunch of misc gmap fixes (locking, behaviour under memory\n     pressure)\n\n   - Fix CMMA dirty tracking\n\n  x86:\n\n   - Tidy up some WARN_ON() and BUG_ON(), replacing them with\n     WARN_ON_ONCE() or KVM_BUG_ON(). All of these have obviously never\n     triggered, or somebody would have been annoyed earlier, but still...\n\n   - Fix missing interrupt due to stale CR8 intercept\n\n   - Add a statistic that can come in handy to debug leaks as well as\n     the vulnerability to a class of recently-discovered issues\n\n   - Do not ask arch/x86/kernel to export\n     default_cpu_present_to_apicid() just for KVM\"\n\n* tag \u0027for-linus\u0027 of git://git.kernel.org/pub/scm/virt/kvm/kvm: (22 commits)\n  x86/apic: KVM: Use cpu_physical_id() to get APIC ID of running vCPU for AVIC\n  KVM: x86/mmu: Expose number of shadow MMU shadow pages as a stat\n  KVM: x86: Unconditionally recompute CR8 intercept on PPR update\n  KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode\n  KVM: x86: WARN (once) if RTC pending EOI tracking goes off the rails\n  KVM: x86: WARN and fail kvm_set_irq() if a PIC or I/O APIC vector is invalid\n  KVM: x86: Bug the VM, not the kernel, if the ISR count {under,over}flows\n  KVM: x86/mmu: Bug the VM, not the host kernel, if KVM write-protects upper SPTEs\n  KVM: x86: Replace BUG_ON() with WARN_ON_ONCE() on \"bad\" nested GPA translation\n  KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()\n  KVM: s390: Return failure in case of failure in kvm_s390_set_cmma_bits()\n  KVM: s390: selftests: Fix cmma selftest\n  KVM: s390: Fix cmma dirty tracking\n  KVM: s390: Fix locking in kvm_s390_set_mem_control()\n  KVM: s390: Fix handle_{sske,pfmf} under memory pressure\n  KVM: s390: Fix code typo in gmap_protect_asce_top_level()\n  KVM: s390: Do not set special large pages dirty\n  KVM: s390: Fix dat_peek_cmma() overflow\n  s390/mm: Fix handling of _PAGE_UNUSED pte bit\n  KVM: s390: Fix typo in UCONTROL documentation\n  ...\n"
    },
    {
      "commit": "fe9f4ee6c61a1410afd73bf011de5ae618004796",
      "tree": "4585457ad181200fa84bc605c3679656f8a17e84",
      "parents": [
        "1105ef941c1a28e115d1b97f17e1c85576884100",
        "e83d0a2472617327e04b74272a61fca06f6f84ff"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:09:02 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:41 2026 -0700"
      },
      "message": "Merge branch \u0027net-avoid-nested-up-notifier-events\u0027\n\nJakub Kicinski says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: avoid nested UP notifier events\n\nsyzbot reported that recent ethtool rework leads to deadlock\non stacked devices. VLANs create nested notifications, confusing\nexecution context. Bringing up dummy causes vlan to bring itself\nup as well. Which in turn causes bond to ask for link state -\na call chain traveling in the opposite direction.\n\n  bond    (3) bond_update_speed_duplex(vlan)\n    |           ^                v\n  vlan    (2) UP(vlan)    (4) vlan_ethtool_get_link_ksettings()\n    |           ^                v\n  dummy   (1) UP(dummy)   (5) __ethtool_get_link_ksettings()\n\nWe locked the instance lock of dummy at (1) and will will\ntry to lock it again at (5) - which of course deadlocks.\n\nFor non-nested notifications this is avoided because NETDEV_UP\nis always run ops-locked (so that bond asks for link using the\nnetif_ API which assumes instance lock already held). The nesting,\nhowever, makes this problematic, we cannot carry the state of\nthe whole chain back in the opposite direction.\n\nAFAICT vlan is the only driver which causes such issues.\nSo let\u0027s try a localized fix of deferring vlan auto-open\nto a workqueue.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260624182018.2445732-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e83d0a2472617327e04b74272a61fca06f6f84ff",
      "tree": "4585457ad181200fa84bc605c3679656f8a17e84",
      "parents": [
        "cd1c188db1091991fc1d7f565824d077d659425b"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Jun 24 11:20:18 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:40 2026 -0700"
      },
      "message": "selftests: bonding: add a test for VLAN propagation over a bonded real device\n\nAdd a regression test for the VLAN notifier handling that the netdev_work\ndeferral fixed.\n\nA VLAN\u0027s real device propagates its UP/DOWN, MTU and feature changes onto\nthe VLANs stacked on top of it. This used to be done synchronously from the\nreal device\u0027s notifier and deadlocked when the real device was brought up\nwhile enslaved to a bond (instance lock held across NETDEV_UP) and the VLAN\non top was itself a bond member: the synchronous propagation re-entered the\nstack and took the same instance lock again.\n\nThe test covers both halves:\n - that the deferred UP/DOWN, MTU and feature propagation actually lands on\n   the VLAN (link state and MTU use an ops-locked dummy, i.e. the deferral\n   path; features use veth, which exports vlan_features to inherit), and\n - that the deadlock-prone topology - a VLAN on a dummy, with the VLAN and\n   the dummy each enslaved to a different bond - can be built without\n   hanging.\n\nReviewed-by: Aleksandr Loktionov \u003caleksandr.loktionov@intel.com\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nLink: https://patch.msgid.link/20260624182018.2445732-5-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "cd1c188db1091991fc1d7f565824d077d659425b",
      "tree": "7e851c2ced991bade8899e3b8d07aee78d14092a",
      "parents": [
        "129cdce9da9e44c52d38889e0411be9817bca114"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Jun 24 11:20:17 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:40 2026 -0700"
      },
      "message": "vlan: defer real device state propagation to netdev_work\n\nvlan_device_event() generates nested UP/DOWN, MTU and feature\nchange events. It executes an event for the VLAN device directly\nfrom the notifier - while the locks of the lower device are held.\n\nThis causes deadlocks, for example:\n\n  bond    (3) bond_update_speed_duplex(vlan)\n    |           ^                v\n  vlan    (2) UP(vlan)    (4) vlan_ethtool_get_link_ksettings()\n    |           ^                v\n  dummy   (1) UP(dummy)   (5) __ethtool_get_link_ksettings()\n\nThe dummy device is ops locked, vlan creates a nested event (2),\nthen bond wants to ask vlan for link state (3). bond uses the\n\"I\u0027m already holding the instance lock\" flavor of API. But in\nthis case the lock held refers to vlan itself. We hit vlan\u0027s\nlink settings trampoline (4) and call __ethtool_get_link_ksettings()\nwhich tries to lock dummy. Deadlock. There\u0027s no clean way for us\nto tell the vlan_ethtool_get_link_ksettings() that the caller\nis already in lower device\u0027s critical section.\n\nDefer the propagation to the per-netdev work facility instead:\nthe notifier only schedules netdev_work_sched(vlandev, VLAN_WORK_*),\nand ndo_work (vlan_dev_work) applies the change later. Hopefully\nnobody expects the VLAN state changes to be instantaneous.\n\nIf someone does expect the changes to be instantaneous we will\nhave to do the same thing Stan did for rx_mode and \"strategically\"\nplace sync calls, to make sure such delayed works are executed\nafter we drop the ops lock but before we drop rtnl_lock.\n\nStan suggests that if we need that down the line we may\nconsider reshaping the mechanism into \"async notifications\".\nAFAICT only vlan does this sort of netdev open chaining,\nso as a first try I think that sticking the complexity into\nthe vlan code makes sense.\n\nOne corner case is that we need to cancel the event if user\nexplicitly changes the state before work could run. Consider\nthe following operations with vlan0 on top of dummy0:\n\n  ip link set dev dummy0 up    # queues work to up vlan0\n  ip link set dev vlan0 down   # user explicitly downs the vlan\n  ndo_work                     # acts on the stale event\n\nReported-by: syzbot+09da62a8b78959ceb8bb@syzkaller.appspotmail.com\nReported-by: syzbot+cb67c392b0b8f0fd0fc1@syzkaller.appspotmail.com\nReported-by: syzbot+9bb8bd77f3966641f298@syzkaller.appspotmail.com\nFixes: 9f275c2e9020 (\"net: ethtool: make sure __ethtool_get_link_ksettings() is ops-locked\")\nReviewed-by: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nReviewed-by: Nicolai Buchwitz \u003cnb@tipi-net.de\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nLink: https://patch.msgid.link/20260624182018.2445732-4-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "129cdce9da9e44c52d38889e0411be9817bca114",
      "tree": "7d9bbc0d71bc16f4817ee6ade42064244e900232",
      "parents": [
        "12c765be84d28f22deca10e775889f54bd571a85"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Jun 24 11:20:16 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:40 2026 -0700"
      },
      "message": "net: add the driver-facing netdev_work scheduling API\n\nWith an extra event mask we can easily extend the netdev work\nto also service driver-defined events. For advanced drivers\nthis is probably not a perfect match, but it makes running\ndeferred work easier in simple cases.\n\nExpose the netdev_work facility to drivers. Add helpers\nto schedule work and a dedicated ndo to perform the driver-\n-scheduled actions.\n\nReviewed-by: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nLink: https://patch.msgid.link/20260624182018.2445732-3-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "12c765be84d28f22deca10e775889f54bd571a85",
      "tree": "7948df147704d04fd0a9fb3669575407b365f298",
      "parents": [
        "1105ef941c1a28e115d1b97f17e1c85576884100"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Jun 24 11:20:15 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:40 2026 -0700"
      },
      "message": "net: turn the rx_mode work into a generic netdev_work facility\n\nThe rx_mode update runs from a workqueue: drivers have their\nndo_set_rx_mode_async() callback executed by a single global\nwork item under RTNL and ops lock. This is a useful pattern.\n\nSupport multiple \"events\" that need to be serviced and make RX_MODE\nsync the first one. Call the events \"core\" because later on\nwe will let drivers define and schedule their own.\n\nReviewed-by: Kuniyuki Iwashima \u003ckuniyu@google.com\u003e\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nLink: https://patch.msgid.link/20260624182018.2445732-2-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "1105ef941c1a28e115d1b97f17e1c85576884100",
      "tree": "26c90777896f27ffbc392a1f72aef8e574370a05",
      "parents": [
        "2c0f1b651d8730c74a4b0cc325ec25808ec92e44"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Wed Jun 24 12:04:39 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:18:34 2026 -0700"
      },
      "message": "net: ethtool: keep rtnl_lock for ops using ethtool_op_get_link()\n\nBreno reports following splats on mlx5:\n\n  RTNL: assertion failed at net/core/dev.c (2241)\n  WARNING: net/core/dev.c:2241 at netif_state_change+0xed/0x130, CPU#5: ethtool/1335\n  RIP: 0010:netif_state_change+0xf9/0x130\n  Call Trace:\n    \u003cTASK\u003e\n     __linkwatch_sync_dev+0xea/0x120\n     ethtool_op_get_link+0xe/0x20\n     __ethtool_get_link+0x26/0x40\n     linkstate_prepare_data+0x51/0x200\n     ethnl_default_doit+0x213/0x470\n     genl_family_rcv_msg_doit+0xdd/0x110\n\nLooks like I missed ethtool_op_get_link() trying to sync linkwatch,\nwhich needs rtnl_lock. Not all drivers do this - bnxt doesn\u0027t,\nit just returns the link state, so add an opt-in bit.\n\nReported-by: Breno Leitao \u003cleitao@debian.org\u003e\nFixes: 45079e00133e (\"net: ethtool: optionally skip rtnl_lock on Netlink path for GET ops\")\nAcked-by: Stanislav Fomichev \u003csdf@fomichev.me\u003e\nReviewed-by: Breno Leitao \u003cleitao@debian.org\u003e\nAcked-by: Harshitha Ramamurthy \u003chramamurthy@google.com\u003e\nLink: https://patch.msgid.link/20260624190439.2521219-1-kuba@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2c0f1b651d8730c74a4b0cc325ec25808ec92e44",
      "tree": "63fd1d888a8838f33a08704f65b47154b192590a",
      "parents": [
        "b78f348d4c4d862b1ad232f30c818f3ec8b97efb",
        "a5462da5a349fc7f17ad5ebd899380260d03e7ed"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:35 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:35 2026 -0700"
      },
      "message": "Merge branch \u0027rxrpc-miscellaneous-fixes\u0027\n\nDavid Howells says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nrxrpc: Miscellaneous fixes\n\nHere are some miscellaneous AF_RXRPC fixes for more stuff found by Sashiko[1][2]:\n\n (1) Fix ACKALL handling by adding two more call states to simplify when\n     ACKs are valid.\n\n (2) Fix connection leak from AF_RXRPC recvmsg userspace OOB handling.\n\n (3) Fix double unlock in AF_RXRPC recvmsg userspace OOB handling.\n\n (4) Fix AFS preallocate charge to flush the waitqueue after unlistening\n     the socket so that any charging thread that does manage to get started\n     will be waited for before socket destruction.\n\n (5) Fix AFS OOB notify handling to cancel in-progress OOB notification\n     handling and then to flush the workqueue it\u0027s on.\n\n (6) Fix handling of apparent reply reception before initial transmission\n     starts in client call.\n\n (7) Fix OOB challenge leak in cleanup on notification failure.\n\n (8) Fix infinite loop in recvmsg if OOB packet available, but no calls.\n\n (9) Fix notify vs recvmsg race where notify thinks the call is already\n     queued.\n\n(10) Fix MSG_PEEK call leak for calls with no content.\n\n(11) Fix rxrpc_rotate_tx_window() to check that there\u0027s something in the Tx\n     buffer before attempting to rotate it.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260624163819.3017002-1-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a5462da5a349fc7f17ad5ebd899380260d03e7ed",
      "tree": "63fd1d888a8838f33a08704f65b47154b192590a",
      "parents": [
        "4bdb9e471f5b1ac9cbe4add5de7ff085a0ec303c"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:18 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:19 2026 -0700"
      },
      "message": "rxrpc: Fix rxrpc_rotate_tx_rotate() to check there\u0027s something to rotate\n\nFix rxrpc_rotate_tx_rotate() to check that there\u0027s something in the\ntransmission buffer to be rotated before it attempts to rotate anything.\n\nFixes: b341a0263b1b (\"rxrpc: Implement progressive transmission queue struct\")\nLink: https://sashiko.dev/#/patchset/20260618134802.2477777-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-12-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4bdb9e471f5b1ac9cbe4add5de7ff085a0ec303c",
      "tree": "e9469dcb6c920bab3a780f2646d07bbb6b98114c",
      "parents": [
        "e66f8f32f50116670dbbee5bc9e692cd2cd0c8f8"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:17 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:19 2026 -0700"
      },
      "message": "rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)\n\nFix rxrpc_recvmsg() to also drop the ref it holds on an already-released\ncall if MSG_PEEK is in force (the function holds a ref on the call\nirrespective of whether MSG_PEEK is specified or not).\n\nFixes: 962fb1f651c2 (\"rxrpc: Fix recv-recv race of completed call\")\nLink: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-11-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "e66f8f32f50116670dbbee5bc9e692cd2cd0c8f8",
      "tree": "afe44d67ba8e32cccc23a66f282c4b474979b9a5",
      "parents": [
        "67a0332f442ef07713cd2d9c13d59db0f1c23648"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:16 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:19 2026 -0700"
      },
      "message": "rxrpc: Fix socket notification race\n\nThere\u0027s a race between rxrpc_recvmsg() and rxrpc_notify_socket(), whereby\nthe latter\u0027s attempt to avoid disabling interrupts and taking the socket\u0027s\nrecvmsg_lock if the call is already queued may happen simultaneously with\nthe former\u0027s discarding of a call that has nothing queued.\n\nFix this by removing the shortcut.  Note that this only affects userspace\u0027s\nuse of AF_RXRPC; the AFS filesystem driver doesn\u0027t use the socket queue.\n\nFixes: 248f219cb8bc (\"rxrpc: Rewrite the data and ack handling code\")\nLink: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-10-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "67a0332f442ef07713cd2d9c13d59db0f1c23648",
      "tree": "a73a1f7a4f237ebf2e5c200a0f539a97b38a1c9d",
      "parents": [
        "092275882aec4a70ba55c3efb66fff947c81656a"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:15 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "rxrpc: Fix potential infinite loop in rxrpc_recvmsg()\n\nFix the wait in rxrpc_recvmsg() also take check the oob queue.\n\nFixes: 5800b1cf3fd8 (\"rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE\")\nLink: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-9-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "092275882aec4a70ba55c3efb66fff947c81656a",
      "tree": "52e442ca42f4be4457975a41a2f704be526b4271",
      "parents": [
        "a58e33405acd2584e730c1da72635f822ada6b49"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:14 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "rxrpc: Fix oob challenge leak in cleanup after notification failure\n\nFix rxrpc_notify_socket_oob() to return an indication of failure in the\nevent that it failed to queue a packet and fix rxrpc_post_challenge() to\nclean up the connection ref in such an event.\n\nFixes: 5800b1cf3fd8 (\"rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE\")\nLink: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-8-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a58e33405acd2584e730c1da72635f822ada6b49",
      "tree": "78ae3a7d214a40c9f47d436e03b63c07c5c44906",
      "parents": [
        "a4057e58b07005d0fe0491bdbf1868c1491909ee"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:13 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "rxrpc: Fix the reception of a reply packet before data transmission\n\nFix rxrpc_receiving_reply() to handle the reception of an apparent reply\nDATA packet before rxrpc has had a chance to send any request DATA packets\non a client call by checking to see if the call has been exposed yet by\nsending the first packet.\n\nWithout this, rxrpc_rotate_tx_window() might oops.\n\nAlso fix rxrpc_rotate_tx_window() to handle the Tx queue being empty by\nchanging the do...while loop into a while loop, just in case a call is\nabnormally terminated by an early reply before the last request packet is\ntransmitted.\n\nFixes: b341a0263b1b (\"rxrpc: Implement progressive transmission queue struct\")\nLink: https://sashiko.dev/#/patchset/20260616155749.2125907-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-7-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a4057e58b07005d0fe0491bdbf1868c1491909ee",
      "tree": "608a3936d9a67edaf39dc235cc6fba8a4f58edd4",
      "parents": [
        "2daf8ac812c3d78c642fe7652f62e29df5e3da20"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:12 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "afs: Fix uncancelled rxrpc OOB message handler\n\nFix AFS to cancel its OOB message processing (typically to respond to\nsecurity challenges).  Also move OOB message processing to afs_wq so that\nit\u0027s also waited for and make the OOB handler just return if the net\nnamespace is no longer live.\n\nFixes: 5800b1cf3fd8 (\"rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE\")\nLink: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Li Daming \u003cd4n.for.sec@gmail.com\u003e\ncc: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-6-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "2daf8ac812c3d78c642fe7652f62e29df5e3da20",
      "tree": "d70b8235961ce39632d0f2510496bd0bb891ad1d",
      "parents": [
        "a2f299b4d5510147fa8629a6aba2869bbcc88aea"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:11 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "afs: Fix further netns teardown to cancel the preallocation charger\n\nWhen an afs network namespace is torn down, it cancels and waits for the\nwork item that keeps the preallocated rxrpc call/conn/peer queue charged\nbefore disabling incoming (i.e. listen 0), but there\u0027s a small window in\nwhich it can be requeued by an incoming call wending through the I/O\nthread.\n\nFix this by cancelling the charger work item again after reducing the\nlisten backlog to zero.\n\nFixes: 47694fbc9d24 (\"afs: Fix netns teardown to cancel the preallocation charger\")\nReported-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nLink: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com\ncc: Li Daming \u003cd4n.for.sec@gmail.com\u003e\ncc: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Jeffrey Altman \u003cjaltman@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-5-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a2f299b4d5510147fa8629a6aba2869bbcc88aea",
      "tree": "8fc55a3556ee794cf26a9f109795de8f2c088f4c",
      "parents": [
        "4b28876e78fd60979afa91fd2ec6ad9cc8b7a6d0"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:10 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:18 2026 -0700"
      },
      "message": "rxrpc: Fix double unlock in rxrpc_recvmsg()\n\nFix a double unlock in rxrpc_recvmsg() when dealing with OOB messages.\n\nFixes: 5800b1cf3fd8 (\"rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE\")\nLink: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-4-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "4b28876e78fd60979afa91fd2ec6ad9cc8b7a6d0",
      "tree": "dab53d27d38708a6352f93b24928a4f0eb521c00",
      "parents": [
        "9b6ce594808580b2a19e6e1aa459ef56c0153ac1"
      ],
      "author": {
        "name": "David Howells",
        "email": "dhowells@redhat.com",
        "time": "Wed Jun 24 17:38:09 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:17 2026 -0700"
      },
      "message": "rxrpc: Fix leak of connection from OOB challenge\n\nFix leak of connection object from OOB challenge queue when response is\nprovided by userspace.\n\nFixes: 5800b1cf3fd8 (\"rxrpc: Allow CHALLENGEs to the passed to the app for a RESPONSE\")\nLink: https://sashiko.dev/#/patchset/20260609140911.838677-1-dhowells%40redhat.com\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: Simon Horman \u003chorms@kernel.org\u003e\ncc: linux-afs@lists.infradead.org\ncc: stable@kernel.org\nLink: https://patch.msgid.link/20260624163819.3017002-3-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "9b6ce594808580b2a19e6e1aa459ef56c0153ac1",
      "tree": "da8d7c20b7fdeedc2875cd5e290faebbc5051764",
      "parents": [
        "b78f348d4c4d862b1ad232f30c818f3ec8b97efb"
      ],
      "author": {
        "name": "Wyatt Feng",
        "email": "bronzed_45_vested@icloud.com",
        "time": "Wed Jun 24 17:38:08 2026 +0100"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 10:07:17 2026 -0700"
      },
      "message": "rxrpc: Fix ACKALL packet handling\n\nrxrpc_input_ackall() accepts ACKALL packets without checking whether the\ncall is in a state that can legitimately have outstanding transmit buffers.\nA forged ACKALL can therefore reach a new service call in\nRXRPC_CALL_SERVER_RECV_REQUEST before any reply packets have been queued.\n\nIn that state call-\u003etx_top is zero and call-\u003etx_queue is NULL, so\nrxrpc_rotate_tx_window() dereferences a NULL txqueue and triggers a\nnull-pointer dereference.\n\nFix the handling of ACKALL packets by the following means:\n\n (1) Add two new call states: RXRPC_CALL_CLIENT_PRE_SEND which indicates\n     that the client call is connected, but nothing has been transmitted as\n     yet; and RXRPC_CALL_CLIENT_AWAIT_ACK, which indicates that everything\n     has been transmitted at least once, but we\u0027re now waiting for the\n     stuff remaining in the Tx buffer to be ACK\u0027d (retransmissions may\n     still happen).\n\n     The RXRPC_CALL_CLIENT_PRE_SEND state is set when the call is assigned\n     a channel and transitions to RXRPC_CALL_CLIENT_SEND_REQUEST when the\n     first packet is transmitted.\n\n     RXRPC_CALL_CLIENT_AWAIT_REPLY is then narrowed in scope to indicate\n     that all Tx packets have been ACK\u0027d and we\u0027re now waiting for the\n     reply to be received.\n\n (2) As per Wyatt Feng\u0027s original patch[1], the ACKALL handler then checks\n     that the call state is one in which there might be stuff in the Tx\n     buffer to ACK, but now this includes AWAIT_ACK rather than\n     AWAIT_REPLY.  ACKALL packets are ignored if received in the wrong\n     state.\n\n     Note that unlike Wyatt Feng\u0027s patch, it\u0027s no longer necessary to check\n     to see if the Tx buffer exists as this the state set now covers this.\n\n (3) Make the ACKALL handler use call-\u003etx_transmitted rather than\n     call-\u003etx_top as the former is explicitly the highest packet seq number\n     transmitted, whereas the latter has a looser definition.\n\nThanks to Jeffrey Altman for a description of the history of the ACKALL\npacket[1].\n\nFixes: b341a0263b1b (\"rxrpc: Implement progressive transmission queue struct\")\nReported-by: Yuan Tan \u003cyuantan098@gmail.com\u003e\nReported-by: Yifan Wu \u003cyifanwucs@gmail.com\u003e\nReported-by: Juefei Pu \u003ctomapufckgml@gmail.com\u003e\nReported-by: Zhengchuan Liang \u003czcliangcn@gmail.com\u003e\nReported-by: Xin Liu \u003cbird@lzu.edu.cn\u003e\nSigned-off-by: Wyatt Feng \u003cbronzed_45_vested@icloud.com\u003e\nCo-developed-by: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\ncc: Ren Wei \u003cn05ec@lzu.edu.cn\u003e\ncc: Marc Dionne \u003cmarc.dionne@auristor.com\u003e\ncc: linux-afs@lists.infradead.org\nCc: stable@vger.kernel.org\nLink: https://lore.kernel.org/r/20260616155749.2125907-2-dhowells@redhat.com/ [1]\nLink: https://lore.kernel.org/r/c0fd4fec-1576-4070-b31e-a37d5506f5ed@auristor.com/ [2]\nReviewed-by: Jeffrey Altman \u003cjaltman@auristor.com\u003e\nLink: https://patch.msgid.link/20260624163819.3017002-2-dhowells@redhat.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "a142da0b2d32b68a6d1b183343bbe43de8c222f9",
      "tree": "5a34a2353fa25d1b498f98e28a7776f7cdaec8d2",
      "parents": [
        "c58ddac1aa507b71cb5a95a95c641bdd73a3f075",
        "a1c8bdbbd72564cebb0d02948c1ed57b80b2e773"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:56:47 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:56:47 2026 -0700"
      },
      "message": "Merge tag \u0027block-7.2-20260625\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n\nPull block fixes from Jens Axboe:\n\n - blk-cgroup locking rework and fixes:\n      - fix a use-after-free in __blkcg_rstat_flush()\n      - defer freeing policy data until after an RCU grace period\n      - defer the blkcg css_put until the blkg is unlinked from\n        the queue\n      - unwind the queue_lock nesting under RCU / blkcg-\u003elock\n        across the lookup, create, associate and destroy paths\n\n - NVMe fixes via Keith:\n      - Fix a crash and memory leak during invalid cdev teardown,\n        and related cdev cleanups (Maurizio, John)\n      - nvmet fixes: handle TCP_CLOSING in the tcp state_change\n        handler, reject short AUTH_RECEIVE buffers, handle inline\n        data with a nonzero offset in rdma, fix an sq refcount leak,\n        and allocate ana_state with the port (Maurizio, Michael,\n        Bryam, Wentao, Rosen)\n      - nvme-fc fix to not cancel requests on an IO target before it\n        is initialized (Mohamed)\n      - nvme-apple fix to prevent shared tags across queues on Apple\n        A11 (Nick)\n      - Various smaller fixes and cleanups (John)\n\n - MD fixes via Yu Kuai:\n      - raid1/raid10 fixes for writes_pending and barrier reference\n        leaks on write and discard failures, plus REQ_NOWAIT handling\n        fixes (Abd-Alrhman)\n      - raid5 discard accounting and validation, and a batch of fixes\n        for stripe batch races (Yu Kuai, Chen)\n      - Protect raid1 head_position during read balancing (Chen)\n\n - block bio-integrity fixes: correct an error injection static key\n   decrement, fix GFP flag confusion in bio_integrity_alloc_buf(), and\n   handle REQ_OP_ZONE_APPEND in __bio_integrity_action() (Christoph)\n\n - Fixes for bio_iov_iter_bounce_write(): revert the iov_iter after a\n   short copy, and respect the iov_iter nofault flag (Qu)\n\n - Invalidate the cached plug timestamp after a task switch, and clear\n   PF_BLOCK_TS in copy_process() (Usama)\n\n - Fix the IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd()\n   (Yitang)\n\n - Remove a redundant plug in __submit_bio() (Wen)\n\n - Don\u0027t warn when reclassifying a busy socket lock in nbd (Deepanshu)\n\n* tag \u0027block-7.2-20260625\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux: (45 commits)\n  block: handle REQ_OP_ZONE_APPEND in __bio_integrity_action\n  block: fix GFP_ flags confusion in bio_integrity_alloc_buf\n  block, bfq: don\u0027t grab queue_lock to initialize bfq\n  mm/page_io: don\u0027t nest queue_lock under rcu in bio_associate_blkg_from_page()\n  blk-cgroup: don\u0027t nest queue_lock under blkcg-\u003elock in blkcg_destroy_blkgs()\n  blk-cgroup: don\u0027t nest queue_lock under rcu in bio_associate_blkg()\n  blk-cgroup: don\u0027t nest queue_lock under rcu in blkg_lookup_create()\n  blk-cgroup: don\u0027t nest queue_lock under rcu in blkcg_print_blkgs()\n  blk-cgroup: delay freeing policy data after rcu grace period\n  blk-cgroup: protect iterating blkgs with blkcg-\u003elock in blkcg_print_stat()\n  md/raid5: avoid R5_Overlap races while breaking stripe batches\n  md/raid5: use stripe state snapshot in break_stripe_batch_list()\n  blk-cgroup: defer blkcg css_put until blkg is unlinked from queue\n  blk-cgroup: fix UAF in __blkcg_rstat_flush()\n  block, bfq: protect async queue reset with blkcg locks\n  nbd: don\u0027t warn when reclassifying a busy socket lock\n  block: fix incorrect error injection static key decrement\n  md/raid5: let stripe batch bm_seq comparison wrap-safe\n  md/raid1: protect head_position for read balance\n  md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry\n  ...\n"
    },
    {
      "commit": "c58ddac1aa507b71cb5a95a95c641bdd73a3f075",
      "tree": "e76f8958c94783d52565afb2846de6fd0f500ec4",
      "parents": [
        "962528fef90253aeded29cee20a9b6ff3595fed4",
        "3996771b8f759729cba0a28007438c085f814d61"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:53:31 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:53:31 2026 -0700"
      },
      "message": "Merge tag \u0027io_uring-7.2-20260625\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux\n\nPull io_uring fixes from Jens Axboe:\n\n - Fix a file reference leak in the nop opcode when used with\n   IOSQE_FIXED_FILE\n\n - Preserve the SQ array entries when resizing the ring via the register\n   path\n\n - Preserve the partial result for an iopoll request rather than\n   overwriting it\n\n - Don\u0027t audit log IORING_OP_RECV_ZC\n\n - Bound io_pin_pages() by the page array byte size in the memmap path\n\n - Follow-up cleanup to the task_work mpscq conversion, getting rid of\n   the now-unnecessary tw_pending tracking for the !DEFER_TASKRUN path\n\n - Switch a system_unbound_wq user over to system_dfl_wq\n\n* tag \u0027io_uring-7.2-20260625\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:\n  io_uring/memmap: bound io_pin_pages() by page array byte size\n  io_uring: Use system_dfl_wq instead of system_unbound_wq\n  io_uring/register: preserve SQ array entries on resize\n  io_uring, audit: don\u0027t log IORING_OP_RECV_ZC\n  io_uring: get rid of tw_pending for !DEFER task work\n  io_uring/rw: preserve partial result for iopoll\n  io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE\n"
    },
    {
      "commit": "4da933bf4e7317310f32d6918c774174253483c1",
      "tree": "4f374e2556d07ed87d5409b66128b5e772d6cea0",
      "parents": [
        "a11aa7b85021f5456fad8ec81467bcbdd2ac6945"
      ],
      "author": {
        "name": "Pengpeng Hou",
        "email": "pengpeng@iscas.ac.cn",
        "time": "Wed Jun 24 22:43:13 2026 +0800"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Thu Jun 25 18:36:53 2026 +0200"
      },
      "message": "fbdev: viafb: return an error when DMA copy times out\n\nviafb_dma_copy_out_sg() logs a VIA DMA timeout when the DONE bit is not\nset after the completion wait and grace delay, but still returns success\nto the caller.\n\nPreserve the existing cleanup sequence and return -ETIMEDOUT when the DMA\nengine did not report completion.\n\nSigned-off-by: Pengpeng Hou \u003cpengpeng@iscas.ac.cn\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "962528fef90253aeded29cee20a9b6ff3595fed4",
      "tree": "69f2373365d74da31f90a8ba4aec7dd47fb80717",
      "parents": [
        "ec85be724c5c0c2cc392f5681b45da0403ea60ec",
        "4e8eb6952aa6749726c6c3763ae0032a6332c24f"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:33:23 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:33:23 2026 -0700"
      },
      "message": "Merge tag \u0027gpio-fixes-for-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull gpio fixes from Bartosz Golaszewski:\n\n - fix locking context with shared GPIOs in gpio-tegra\n\n - fix IRQ domain leak in error path in gpio-davinci\n\n - fix returning a potentially uninitialized integer in\n   gpiochip_set_multiple()\n\n - use raw spinlock in gpio-eic-sprd and gpio-sch to address locking\n   context issues\n\n - bail out of probe() if registering the GPIO chip fails in gpio-mlxbf3\n\n - fix varible type for storing the \"ngpios\" property in gpio-pisosr\n\n - fix out-of-bounds pin access in GPIO ACPI\n\n - make GPIO ACPI core only trigger interrupts on boot that are marked\n   as ActiveBoth\n\n - fix kerneldoc in gpio-tb10x\n\n - reference the real software node of the cs5535 GPIO controller in\n   Geode board file\n\n* tag \u0027gpio-fixes-for-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  gpio: davinci: fix IRQ domain leak on devm_kzalloc failure\n  gpio: tegra: do not call pinctrl for GPIO direction\n  gpio: tb10x: fix struct tb10x_gpio kernel-doc\n  gpiolib: initialize return value in gpiochip_set_multiple()\n  x86/platform/geode: reference the real node of the cs5535 GPIO controller\n  gpio: eic-sprd: use raw_spinlock_t in the irq startup path\n  gpio: sch: use raw_spinlock_t in the irq startup path\n  gpiolib: acpi: Prevent out-of-bounds pin access in OperationRegion handler\n  gpiolib: acpi: Add robust bounds-checking for GPIO pin resources\n  gpio: mlxbf3: fail probe if gpiochip registration fails\n  gpio: pisosr: Read \"ngpios\" as u32\n  gpiolib: acpi: Only trigger ActiveBoth interrupts on boot\n"
    },
    {
      "commit": "a11aa7b85021f5456fad8ec81467bcbdd2ac6945",
      "tree": "d4bf30cd45acc6aabca8e11a639dbeb4eb61c0b6",
      "parents": [
        "8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2"
      ],
      "author": {
        "name": "Pengpeng Hou",
        "email": "pengpeng@iscas.ac.cn",
        "time": "Thu Jun 25 11:01:02 2026 +0800"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Thu Jun 25 18:29:14 2026 +0200"
      },
      "message": "fbdev: goldfishfb: fail pan display on base-update timeout\n\ngoldfish_fb_pan_display() waits for the device to acknowledge the new\nframebuffer base, but it only logs a timeout and still reports success.\nThe probe path also ignores the initial pan-display result before\nregistering the framebuffer.\n\nReturn -ETIMEDOUT when the base-update acknowledgment does not arrive,\nand propagate that error from the initial probe-time base update before\nthe framebuffer is published.\n\nSigned-off-by: Pengpeng Hou \u003cpengpeng@iscas.ac.cn\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "ec85be724c5c0c2cc392f5681b45da0403ea60ec",
      "tree": "2c45e9aacfc9b43b796e0c71043d8fbf3bcede3e",
      "parents": [
        "da07894d1d2ff9164cff88d15669f1e03e810b5c",
        "2d5a7d406ecece5837af1e278ffbbf6c0315560a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:20:26 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:20:26 2026 -0700"
      },
      "message": "Merge tag \u0027pwrseq-fixes-for-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux\n\nPull power sequencing fixes from Bartosz Golaszewski:\n\n - fix an ABBA deadlock in pwrseq unregister path\n\n - fix a use-after-free bug in pwrseq core\n\n - sort PCI device IDs in ascending order in pwrseq-pcie-m2\n\n* tag \u0027pwrseq-fixes-for-v7.2-rc1\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux:\n  power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()\n  power: sequencing: pcie-m2: Sort PCI device IDs in ascending order\n  pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()\n"
    },
    {
      "commit": "8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2",
      "tree": "f155d6d13c184a4fb8f1ff3a927e90035b350b83",
      "parents": [
        "16eb19f0c90af03bda6ba66586d7bb0e9cf85b43"
      ],
      "author": {
        "name": "Mingyu Wang",
        "email": "25181214217@stu.xidian.edu.cn",
        "time": "Fri Jun 26 00:03:06 2026 +0800"
      },
      "committer": {
        "name": "Helge Deller",
        "email": "deller@gmx.de",
        "time": "Thu Jun 25 18:15:48 2026 +0200"
      },
      "message": "fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()\n\nWhen fbcon_do_set_font() fails (e.g., due to a memory allocation failure\ninside vc_resize() under heavy memory pressure), it jumps to the `err_out`\nlabel to roll back the console state. However, the current rollback logic\nforgets to restore the `hi_font` state, leading to a severe state machine\ncorruption.\n\nEarlier in the function, `set_vc_hi_font()` might be called to change\n`vc-\u003evc_hi_font_mask` and mutate the screen buffer. If `vc_resize()`\nsubsequently fails, the `err_out` path restores `vc_font.charcount`\nbut entirely skips rolling back the `vc_hi_font_mask` and the screen\nbuffer.\n\nThis mismatch leaves the terminal in a desynchronized state. Because\n`vc_hi_font_mask` remains set, the VT subsystem will still accept\ncharacter indices greater than 255 from userspace and write them to the\nscreen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will\nthen use these inflated indices to access the reverted, 256-character\nfont array, leading to a deterministic out-of-bounds read and potential\nkernel memory disclosure.\n\nFix this by adding the missing rollback logic for the `hi_font` mask\nand screen buffer in the error path.\n\nFixes: a5a923038d70 (\"fbdev: fbcon: Properly revert changes when vc_resize() failed\")\nCc: stable@vger.kernel.org\nSigned-off-by: Mingyu Wang \u003c25181214217@stu.xidian.edu.cn\u003e\nReviewed-by: Thomas Zimmermann \u003ctzimmermann@suse.de\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n"
    },
    {
      "commit": "b78f348d4c4d862b1ad232f30c818f3ec8b97efb",
      "tree": "029df15a6f9cb0eab58cc4243975b7d6321dd4ea",
      "parents": [
        "5316394b1752f6cf3f9901e7fefdec1cd1d97fd3",
        "d9d349c4e8a0acd73bac8baa3605443c0df5eb26"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:46 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:47 2026 -0700"
      },
      "message": "Merge branch \u0027net-hns3-fix-configuration-deadlocks-and-refactor-link-setup\u0027\n\nJijie Shao says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnet: hns3: fix configuration deadlocks and refactor link setup\n\nThis patch series addresses a sequence of link configuration deadlocks\nand parameter contamination issues in the hns3 network driver, which\ntypically occur during hardware resets or driver initialization under\nspecific user-configured scenarios.\n\nThe bugs root from asynchronous discrepancies between the MAC state\nmachine and cached user requests during sudden hardware resets, leading\nto invalid parameter combos or frozen registers.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260624141319.271439-1-shaojijie@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "d9d349c4e8a0acd73bac8baa3605443c0df5eb26",
      "tree": "029df15a6f9cb0eab58cc4243975b7d6321dd4ea",
      "parents": [
        "c711f6d1cee955e04d1cd1f76cd8abd024b27a72"
      ],
      "author": {
        "name": "Shuaisong Yang",
        "email": "yangshuaisong@h-partners.com",
        "time": "Wed Jun 24 22:13:19 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:44 2026 -0700"
      },
      "message": "net: hns3: differentiate autoneg default values between copper and fiber\n\nFix a link loss issue during driver initialization on optical ports\nconnected to forced-mode (non-autoneg) remote switches.\n\nPreviously, during driver probe or initialization, hclge_configure()\nblindly hardcoded hdev-\u003ehw.mac.req_autoneg to AUTONEG_ENABLE for all\nmedia types. While this is necessary for copper (BASE-T) ports to\nestablish a link, many high-speed optical (fiber) ports in data\ncenters are connected to switches running in forced mode (fixed speed,\nautoneg disabled). Forcing autoneg on these optical ports during\ninitialization causes a permanent link failure since the remote end\nrefuses to respond to autoneg pulses.\n\nFix this by implementing media-type differentiated initialization in\nhclge_init_ae_dev(). Copper ports continue to default to\nAUTONEG_ENABLE, while optical ports strictly inherit the preset\nautoneg status pre-configured by the firmware (hdev-\u003ehw.mac.autoneg),\npreserving native compatibility with forced-mode network environments.\n\nFixes: 05eb60e9648c (\"net: hns3: using user configure after hardware reset\")\nSigned-off-by: Shuaisong Yang \u003cyangshuaisong@h-partners.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nLink: https://patch.msgid.link/20260624141319.271439-5-shaojijie@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c711f6d1cee955e04d1cd1f76cd8abd024b27a72",
      "tree": "eec0d683f82e3fa1f316aacfeb96c816c7adcf3e",
      "parents": [
        "c01f6e6bdc1ccd21b2d07d23f50b82437b8cbf88"
      ],
      "author": {
        "name": "Shuaisong Yang",
        "email": "yangshuaisong@h-partners.com",
        "time": "Wed Jun 24 22:13:18 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:44 2026 -0700"
      },
      "message": "net: hns3: fix permanent link down deadlock after reset\n\nFix a critical race condition deadlock where the network interface\nremains permanently Link Down after a hardware reset under specific\nethtool sequences.\n\nThis issue exclusively manifests in firmware-controlled PHY topologies\nwhere the driver relies on the IMP firmware to arbitrate link parameters.\nStandard devices driven by the kernel\u0027s native PHY_LIB are unaffected.\n\nThe deadlock occurs via the following path:\n1. User disables autoneg and forces an unmatched speed, forcing link\n   down: `ethtool -s ethx autoneg off speed 10 duplex full`\n2. User re-enables autoneg: `ethtool -s ethx autoneg on`. The netdev\n   stack passes cmd-\u003ebase.speed as SPEED_UNKNOWN (0xffffffff).\n3. Driver saves req_autoneg\u003d1, but before the interface can link up,\n   a hardware reset is triggered.\n4. During reset recovery, MAC init reads the un-synchronized runtime\n   state mac.autoneg (which is still 0/OFF), misinterprets it as\n   forced mode, and pushes the cached SPEED_UNKNOWN into the hardware\n   registers, causing the MAC firmware state machine to freeze.\n   Meanwhile, PHY init reads req_autoneg\u003d1 and enables PHY autoneg.\n\nSince the MAC is frozen with 0xffffffff and PHY is running autoneg,\nthey mismatch permanently.\n\nFix this by:\n1. Intercepting SPEED_UNKNOWN/DUPLEX_UNKNOWN in\n   hclge_set_phy_link_ksettings() and hclge_cfg_mac_speed_dup_h() to\n   prevent it from corrupting the driver\u0027s cached valid configuration.\n2. Save req_autoneg in hclge_set_autoneg().\n3. Aligning the state judgment in hclge_set_autoneg_speed_dup() to use\n   req_autoneg instead of the un-synchronized runtime mac.autoneg,\n   ensuring both MAC and PHY consistently enter the autoneg branch to\n   eliminate configuration discrepancies during reset recovery.\n\nFixes: 05eb60e9648c (\"net: hns3: using user configure after hardware reset\")\nSigned-off-by: Shuaisong Yang \u003cyangshuaisong@h-partners.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nLink: https://patch.msgid.link/20260624141319.271439-4-shaojijie@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c01f6e6bdc1ccd21b2d07d23f50b82437b8cbf88",
      "tree": "80aadb1def8171c28de18081273637d8c8aab7e4",
      "parents": [
        "d77e98f8b2b382b06be7f17e482480dd8c4c5046"
      ],
      "author": {
        "name": "Shuaisong Yang",
        "email": "yangshuaisong@h-partners.com",
        "time": "Wed Jun 24 22:13:17 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:44 2026 -0700"
      },
      "message": "net: hns3: refactor MAC autoneg and speed configuration\n\nExtract the MAC autoneg and speed/duplex/lane configuration logic out\nof hclge_mac_init() and encapsulate it into a new dedicated helper\nfunction hclge_set_autoneg_speed_dup().\n\nIn the init path (hclge_init_ae_dev), this helper is now called after\nhclge_update_port_info() so that firmware-reported autoneg values are\nalready populated before applying the link configuration.\n\nIntroduce a separate req_lane_num field in struct hclge_mac to isolate\nthe user-requested lane count from mac.lane_num, which firmware may\noverwrite via hclge_get_sfp_info() with stale values from a prior link\nlifecycle (e.g., lane_num\u003d4 from 100G). During probe, req_lane_num is\ninitialized to 0, which instructs firmware to auto-select the correct\nlane count for the current speed, rather than reusing the firmware-\nreported mac.lane_num that may be inconsistent with the target speed.\nThis prevents probe failures from mismatched (speed, lane_num) pairs.\n\nIn the reset path (hclge_reset_ae_dev), it runs immediately after\nhclge_mac_init(), using the previously cached req_* values to restore\nthe link without re-querying firmware.\n\nSigned-off-by: Shuaisong Yang \u003cyangshuaisong@h-partners.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nLink: https://patch.msgid.link/20260624141319.271439-3-shaojijie@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "d77e98f8b2b382b06be7f17e482480dd8c4c5046",
      "tree": "fa3a5fd4c18a6c5b6249636f812b0d195f5b76b2",
      "parents": [
        "5316394b1752f6cf3f9901e7fefdec1cd1d97fd3"
      ],
      "author": {
        "name": "Shuaisong Yang",
        "email": "yangshuaisong@h-partners.com",
        "time": "Wed Jun 24 22:13:16 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:15:44 2026 -0700"
      },
      "message": "net: hns3: unify copper port ksettings configuration path\n\nRefactor hns3_set_link_ksettings() and hclge_set_phy_link_ksettings()\nto unify the configuration path for copper ports.\n\nPreviously, netdevs with a native kernel phy attached bypassed the main\nMAC parameter caching logic and returned early via\nphy_ethtool_ksettings_set(). This prevented the driver from updating\nhdev-\u003ehw.mac.req_xxx variables for kernel PHY setups, leaving them\nout-of-sync during reset recovery.\n\nClean this up by routing all copper port configurations through\nops-\u003eset_phy_link_ksettings(), and perform driver-level or kernel-level\nPHY arbitration inside hclge_set_phy_link_ksettings() via\nhnae3_dev_phy_imp_supported(). This ensures that the user\u0027s intended link\nprofiles (req_speed, req_duplex, req_autoneg) are uniformly recorded\nacross all copper and fiber deployment topologies, laying the groundwork\nfor stable reset recovery.\n\nFor copper ports where neither IMP firmware nor a kernel PHY is available\n(e.g. PHY_INEXISTENT), hclge_set_phy_link_ksettings() returns -ENODEV.\nIn hns3_set_link_ksettings(), this is caught so the configuration falls\nthrough to the existing MAC-level path (check_ksettings_param -\u003e\ncfg_mac_speed_dup_h), preserving compatibility with PHY-less copper\ndeployments.\n\nSigned-off-by: Shuaisong Yang \u003cyangshuaisong@h-partners.com\u003e\nSigned-off-by: Jijie Shao \u003cshaojijie@huawei.com\u003e\nLink: https://patch.msgid.link/20260624141319.271439-2-shaojijie@huawei.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5316394b1752f6cf3f9901e7fefdec1cd1d97fd3",
      "tree": "c62ad39a1ce3ec33ab0e87da5a46e72177dd714e",
      "parents": [
        "3e52f56875c6fafee619b5c2b4ded25f2efbd2ec"
      ],
      "author": {
        "name": "Shradha Gupta",
        "email": "shradhagupta@linux.microsoft.com",
        "time": "Wed Jun 24 00:21:35 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:10:35 2026 -0700"
      },
      "message": "net: mana: Optimize irq affinity for low vcpu configs\n\nBefore the commit 755391121038 (\"net: mana: Allocate MSI-X vectors\ndynamically\"), all the MANA IRQs were assigned statically and together\nduring early driver load.\n\nAfter this commit, the IRQ allocation for MANA was done in two phases.\nHWC IRQ allocated earlier and then, queue IRQs dynamically added at a\nlater point. By this time, the IRQ weights on vCPUs can become imbalanced\nand if IRQ count is greater than the vCPU count the topology aware IRQ\ndistribution logic in MANA can cause multiple MANA IRQs to land on the\nsame vCPUs, while other sibling vCPUs have none (case 1).\n\nOn SMP enabled, low-vCPU systems, this becomes a bigger problem as the\nsoftIRQ handling overhead of two IRQs on the same vCPUs becomes much more\nthan their overheads if they were spread across sibling vCPUs.\n\nIn such cases when many parallel TCP connections are tested, the\nthroughput drops significantly.\n\nFix the affinity assignment logic, in cases where the IRQ count is greater\nthan the vCPU count and when IRQs are added dynamically, by utilizing all\nthe vCPUs irrespective of their NUMA/core bindings (case 2).\n\nThe results of setting the affinity and hint to NULL were also studied,\nand we observed that, with this logic if there are pre-existing IRQs\nallocated on the VM (apart from MANA), during MANA IRQs allocation, it\nleads to clustering of the MANA queue IRQs again (case 3).\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nCase 1: without this patch\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n4 vcpu(2 cores), 5 MANA IRQs (1 HWC + 4 Queue)\n\n\tTYPE\t\teffective vCPU aff\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nIRQ0:\tHWC\t\t0\nIRQ1:\tmana_q1\t\t0\nIRQ2:\tmana_q2\t\t2\nIRQ3:\tmana_q3\t\t0\nIRQ4:\tmana_q4\t\t3\n\n%soft on each vCPU(mpstat -P ALL 1) on receiver\nvCPU\t\t0\t1\t2\t3\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\npass 1:\t\t38.85\t0.03\t24.89\t24.65\npass 2:\t\t39.15\t0.03\t24.57\t25.28\npass 3:\t\t40.36\t0.03\t23.20\t23.17\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nCase 2: with this patch\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n4 vcpu(2 cores), 5 MANA IRQs (1 HWC + 4 Queue)\n\n        TYPE            effective vCPU aff\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nIRQ0:   HWC             0\nIRQ1:   mana_q1         0\nIRQ2:   mana_q2         1\nIRQ3:   mana_q3         2\nIRQ4:   mana_q4         3\n\n%soft on each vCPU(mpstat -P ALL 1) on receiver\nvCPU            0       1       2       3\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\npass 1:         15.42\t15.85\t14.99\t14.51\npass 2:         15.53\t15.94\t15.81\t15.93\npass 3:         16.41\t16.35\t16.40\t16.36\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nCase 3: with affinity set to NULL\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n4 vCPU(2 cores), 5 MANA IRQs (1 HWC + 4 Queue)\n\n\tTYPE\t\teffective vCPU aff\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nIRQ0:\tHWC\t\t\t0\nIRQ1:\tmana_q1\t\t\t2\nIRQ2:\tmana_q2\t\t\t3\nIRQ3:\tmana_q3\t\t\t2\nIRQ4:\tmana_q4\t\t\t3\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nThroughput Impact(in Gbps, same env)\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nTCP conn\twith patch\tw/o patch\taff NULL\n20480\t\t15.65\t\t7.73\t\t5.25\n10240\t\t15.63\t\t8.93\t\t5.77\n8192\t\t15.64\t\t9.69\t\t7.16\n6144\t\t15.64\t\t13.16\t\t9.33\n4096\t\t15.69\t\t15.75\t\t13.50\n2048\t\t15.69\t\t15.83\t\t13.61\n1024\t\t15.71\t\t15.28\t\t13.60\n\nFixes: 755391121038 (\"net: mana: Allocate MSI-X vectors dynamically\")\nCc: stable@vger.kernel.org\nCo-developed-by: Erni Sri Satya Vennela \u003cernis@linux.microsoft.com\u003e\nSigned-off-by: Erni Sri Satya Vennela \u003cernis@linux.microsoft.com\u003e\nSigned-off-by: Shradha Gupta \u003cshradhagupta@linux.microsoft.com\u003e\nReviewed-by: Haiyang Zhang \u003chaiyangz@microsoft.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nReviewed-by: Yury Norov \u003cynorov@nvidia.com\u003e\nLink: https://patch.msgid.link/20260624072138.1632849-1-shradhagupta@linux.microsoft.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "da07894d1d2ff9164cff88d15669f1e03e810b5c",
      "tree": "cbe25b7bd7152f9de87b1089cc48cc55eba5c892",
      "parents": [
        "6cc37b86f80985774809aba82283fe0d564d870f",
        "b13f724df35c4f1a69e20c965a2fc74fd2921e59"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:09:38 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:09:38 2026 -0700"
      },
      "message": "Merge tag \u0027docs-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/docs/linux\n\nPull more documentation updates from Jonathan Corbet:\n \"A handful of late-arriving docs fixes, along with one document update\n  that fell through the cracks before\"\n\n* tag \u0027docs-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/docs/linux:\n  docs: tools: Fix typo \u0027ackward\u0027 to \u0027awkward\u0027 in unittest.rst\n  kdoc: xforms: ignore special static/inline macros\n  kdoc: xforms_lists: handle DECLARE_PER_CPU() in kernel-doc\n  MAINTAINERS: Fix regex for kdoc\n  docs: kgdb: Fix path of driver options\n  Documentation: tracing: fix typo in events documentation\n  Docs/driver-api/uio-howto: document mmap_prepare callback\n  docs/mm: clarify that we are not looking for LLM generated content\n  kernel-doc: xforms: support __SYSFS_FUNCTION_ALTERNATIVE()\n"
    },
    {
      "commit": "6cc37b86f80985774809aba82283fe0d564d870f",
      "tree": "d630cead2441628c0ce6dfc60a5cea078f847ed9",
      "parents": [
        "504c8065288befdc8a89e98858ac563deae9d7ba",
        "645323a7f4e55bb3abb0cb003b6b9dc715c8dc21"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:06:12 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:06:12 2026 -0700"
      },
      "message": "Merge tag \u0027kbuild-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux\n\nPull more Kbuild updates from Nathan Chancellor:\n\n - Link host programs with ld.lld when $(LLVM) is set to match user\u0027s\n   expectations that LLVM will be used exclusively during the build\n   process\n\n - Fix modpost warnings from static variable name promotion that can\n   happen more aggressively with the recently merged distributed ThinLTO\n   support\n\n - Add an optional warning for user-supplied Kconfig values that changed\n   after processing, such as out of range values or options that have\n   incorrect / missing dependencies\n\n* tag \u0027kbuild-7.2-2\u0027 of git://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux:\n  kconfig: add optional warnings for changed input values\n  modpost: Ignore Clang LTO suffixes in symbol matching\n  kbuild: Use ld.lld for linking host programs when LLVM is set\n"
    },
    {
      "commit": "3e52f56875c6fafee619b5c2b4ded25f2efbd2ec",
      "tree": "edd9df35c3d0acaba251af07eb377dcbda12a38d",
      "parents": [
        "483be61b4a9a6df3b7cb277e8f189e082dee4cb8"
      ],
      "author": {
        "name": "Nirmoy Das",
        "email": "nirmoyd@nvidia.com",
        "time": "Wed Jun 24 06:44:16 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 09:01:58 2026 -0700"
      },
      "message": "selftests: tls: size splice_short pipe by page size\n\nsplice_short grows its pipe with (MAX_FRAGS + 1) * 0x1000 so it can\nqueue one short vmsplice() buffer for each fragment before draining the\npipe. That assumes 4K pipe buffers.\n\nOn 64K-page kernels the request is rounded to 262144 bytes, which\nprovides only four pipe buffers. The fifth one-byte vmsplice() blocks in\npipe_wait_writable and the test times out before it reaches the TLS path.\n\nRequest enough bytes for the same number of pipe buffers using the\nruntime page size, and assert that the kernel granted at least that much.\nIf an unprivileged run cannot raise the pipe above the system\npipe-max-size limit, skip the test because it cannot exercise the\nintended path.\n\nFixes: 3667e9b442b9 (\"selftests: tls: add test for short splice due to full skmsg\")\nSigned-off-by: Nirmoy Das \u003cnirmoyd@nvidia.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260624134416.3235403-1-nirmoyd@nvidia.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "504c8065288befdc8a89e98858ac563deae9d7ba",
      "tree": "2bc88bc333aa750f17c4faf639c59566016782a5",
      "parents": [
        "ab9de95c9cf952332ab79453b4b5d1bfca8e514f",
        "de9aa5ea2d9ea55234e78af1e6182979aa4f646a"
      ],
      "author": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:00:53 2026 -0700"
      },
      "committer": {
        "name": "Linus Torvalds",
        "email": "torvalds@linux-foundation.org",
        "time": "Thu Jun 25 09:00:53 2026 -0700"
      },
      "message": "Merge tag \u0027for-linus-7.2-1\u0027 of https://github.com/cminyard/linux-ipmi\n\nPull ipmi updates from Corey Minyard:\n \"Lots of little tweaks.\n\n  Nothing huge, the biggest issue was a possible refcount underflow that\n  could cause a memory leak in some situations. Otherwise, fixing\n  formatting and style things and some docs typos\"\n\n* tag \u0027for-linus-7.2-1\u0027 of https://github.com/cminyard/linux-ipmi:\n  docs: ipmi: Fix path of the \"hotmod\" module parameter\n  ipmi: Drop unused assignment of platform_device_id driver data\n  ipmi: si: Use platform_get_irq_optional() to retrieve interrupt\n  ipmi: fix refcount leak in i_ipmi_request()\n  ipmi:ssif: Drop unused assignment of platform_device_id driver data\n  ipmi: Fix user refcount underflow in event delivery\n  ipmi: Use named initializers for struct i2c_device_id\n  ipmi: Use LIST_HEAD() to initialize on stack list head\n  ipmi:kcs: Reduce the number of retries\n"
    },
    {
      "commit": "483be61b4a9a6df3b7cb277e8f189e082dee4cb8",
      "tree": "d030070376c8edc6c454c59fec553c83bd532952",
      "parents": [
        "106f6b1dfa1f45f116c5c700342188a3cd4a4b9f"
      ],
      "author": {
        "name": "Haoxiang Li",
        "email": "haoxiang_li2024@163.com",
        "time": "Tue Jun 23 19:57:14 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:54:04 2026 -0700"
      },
      "message": "net: sparx5: unregister blocking notifier on init failure\n\nsparx5_register_notifier_blocks() registers the switchdev blocking\nnotifier before allocating the ordered workqueue. If the workqueue\nallocation fails, the error path unregisters the switchdev and netdevice\nnotifiers, but leaves the blocking notifier registered.\n\nAdd a separate error label for the workqueue allocation failure path and\nunregister the switchdev blocking notifier there.\n\nFixes: d6fce5141929 (\"net: sparx5: add switching support\")\nCc: stable@vger.kernel.org\nSigned-off-by: Haoxiang Li \u003chaoxiang_li2024@163.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260623115714.2192074-1-haoxiang_li2024@163.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "106f6b1dfa1f45f116c5c700342188a3cd4a4b9f",
      "tree": "1c9330007771e51609e6080f025dc8379e3c1c23",
      "parents": [
        "36323f54cd323122a1be89ab2c316a6e55a94e30",
        "c1481c94e74c955e0448ddf46b8615a44d840c1e"
      ],
      "author": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:53:02 2026 -0700"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:53:03 2026 -0700"
      },
      "message": "Merge branch \u0027tipc-syzbot-related-fixes\u0027\n\nEric Dumazet says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\ntipc: syzbot related fixes\n\nFirst patch fixes a recent syzbot report.\n\nSecond patch is inspired by numerous syzbot soft lockup\nreports with RTNL pressure.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nLink: https://patch.msgid.link/20260623173030.2925059-1-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "c1481c94e74c955e0448ddf46b8615a44d840c1e",
      "tree": "1c9330007771e51609e6080f025dc8379e3c1c23",
      "parents": [
        "7116764ca53ff529335d7ab7c364a69f094b23a5"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Jun 23 17:30:30 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:53:00 2026 -0700"
      },
      "message": "tipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(\u0026tn-\u003ewq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed.\n\nFixes: 04c26faa51d1 (\"tipc: wait and exit until all work queues are done\")\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Jon Maloy \u003cjmaloy@redhat.com\u003e\nCc: tipc-discussion@lists.sourceforge.net\nReviewed-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260623173030.2925059-3-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "7116764ca53ff529335d7ab7c364a69f094b23a5",
      "tree": "31fae2d28997d256314f0b8bc89c71fef8c98e18",
      "parents": [
        "36323f54cd323122a1be89ab2c316a6e55a94e30"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Tue Jun 23 17:30:29 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:53:00 2026 -0700"
      },
      "message": "tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()\n\nTIPC UDP media bearer teardown calls dst_cache_destroy() on its\nreplicast caches before calling synchronize_net() to wait for\nconcurrent RCU readers (transmitters) to finish:\n\nstatic void cleanup_bearer(struct work_struct *work)\n{\n...\n\tlist_for_each_entry_safe(rcast, tmp, \u0026ub-\u003ercast.list, list) {\n\t\tdst_cache_destroy(\u0026rcast-\u003edst_cache);\n\t\tlist_del_rcu(\u0026rcast-\u003elist);\n\t\tkfree_rcu(rcast, rcu);\n\t}\n...\n\tdst_cache_destroy(\u0026ub-\u003ercast.dst_cache);\n\tudp_tunnel_sock_release(ub-\u003esk);\n\tsynchronize_net();\n...\n}\n\nThis is highly buggy because dst_cache_destroy() immediately frees the\nper-CPU cache memory (free_percpu()) and releases the cached dst\nentries without any synchronization.\n\nIf a concurrent transmitter (e.g., tipc_udp_xmit()) is running on another\nCPU under RCU protection, it can call dst_cache_get() concurrently,\nleading to:\n1. Use-After-Free on the per-CPU cache pointer itself (crash).\n2. \"rcuref - imbalanced put()\" warning if it attempts to release a\n   dst that was concurrently released by dst_cache_destroy().\n\nFurthermore, calling kfree(ub) immediately after synchronize_net() without\nclosing the socket first (or waiting after closing it) leaves a window\nwhere a concurrent receiver (tipc_udp_recv()) could start after\nsynchronize_net(), access ub, and suffer a UAF when kfree(ub) runs.\n\nTo fix this, we must defer dst_cache_destroy() and kfree(ub) until after\nwe have ensured that no more readers can see the bearer/socket and all\nexisting readers have finished:\n\n1. Defer rcast entry destruction (both dst_cache_destroy() and kfree())\n   to an RCU callback using call_rcu_hurry().\n   Using call_rcu_hurry() ensures the dst entries are released quickly.\n\n2. Release the bearer socket using udp_tunnel_sock_release() (stops\n   new receive readers).\n\n3. Call synchronize_net() to wait for all outstanding RCU readers\n   (both transmit and receive) to finish.\n\n4. Now that it is safe, call dst_cache_destroy() on the main bearer\n   cache, and free ub.\n\nNote: 3) and 4) can be changed later in net-next to also use\ncall_rcu_hurry() and get rid of the synchronize_net() latency.\n\nFixes: e9c1a793210f (\"tipc: add dst_cache support for udp media\")\nReported-by: syzbot+e14bc5d4942756023b77@syzkaller.appspotmail.com\nCloses: https://lore.kernel.org/netdev/6a396a66.52ae72c2.136ac7.0003.GAE@google.com/T/#u\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nCc: Jon Maloy \u003cjmaloy@redhat.com\u003e\nCc: tipc-discussion@lists.sourceforge.net\nReviewed-by: Xin Long \u003clucien.xin@gmail.com\u003e\nLink: https://patch.msgid.link/20260623173030.2925059-2-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "36323f54cd323122a1be89ab2c316a6e55a94e30",
      "tree": "2341cc74a585cc1e4a70f6d1d58fb44aaa6148ae",
      "parents": [
        "efd7fb21bad80997bba27c04851bcbc2deeeef4d"
      ],
      "author": {
        "name": "Haoxiang Li",
        "email": "haoxiang_li2024@163.com",
        "time": "Tue Jun 23 19:43:16 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:47:59 2026 -0700"
      },
      "message": "octeontx2-af: Free BPID bitmap on setup failure\n\nnix_setup_bpids() allocates bp-\u003ebpids with rvu_alloc_bitmap(), which uses\na plain kcalloc(). If any of the following devm_kcalloc() allocations for\nthe BPID mapping arrays fails, the function returns without freeing the\nbitmap. Free the BPID bitmap before returning from those error paths.\n\nFixes: d6212d2e41a0 (\"octeontx2-af: Create BPIDs free pool\")\nCc: stable@vger.kernel.org\nSigned-off-by: Haoxiang Li \u003chaoxiang_li2024@163.com\u003e\nReviewed-by: Simon Horman \u003chorms@kernel.org\u003e\nLink: https://patch.msgid.link/20260623114316.2182271-1-haoxiang_li2024@163.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "efd7fb21bad80997bba27c04851bcbc2deeeef4d",
      "tree": "fd6e3142a618adf1997333719beedbafd363af54",
      "parents": [
        "5da65537792b68b6052ffcab65e04c27aea6dfe4"
      ],
      "author": {
        "name": "Krzysztof Kozlowski",
        "email": "krzysztof.kozlowski@oss.qualcomm.com",
        "time": "Tue Jun 23 09:33:08 2026 +0200"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:46:29 2026 -0700"
      },
      "message": "net: ethernet: qualcomm: ppe: Demote from supported and fix maintainer addresses\n\nEmails to the maintainer of Qualcomm PPE Ethernet driver (Luo Jie\n\u003cquic_luoj@quicinc.com\u003e) bounce permanently (full mailbox), because the\n\"quicinc.com\" addresses were deprecated for public work.  All Qualcomm\ncontributors are aware of that and were asked to fix their addresses.\n\nDriver is not supported - in terms of how netdev understands supported\ncommitment - if maintainer does not care to receive the patches for its\ncode, so demote it to \"maintained\" to reflect true status.\n\nFix all occurences of Luo Jie email address to preferred and working\ndomain.\n\nSigned-off-by: Krzysztof Kozlowski \u003ckrzysztof.kozlowski@oss.qualcomm.com\u003e\nAcked-by: Luo Jie \u003cjie.luo@oss.qualcomm.com\u003e\nLink: https://patch.msgid.link/20260623073307.36483-2-krzysztof.kozlowski@oss.qualcomm.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "5da65537792b68b6052ffcab65e04c27aea6dfe4",
      "tree": "2dcef3e28d40d1442314ccf5edf84807d3ee4e9d",
      "parents": [
        "14eb1d2c03b38ce3427f299967f7a4d97ebff4c2"
      ],
      "author": {
        "name": "Wei Fang",
        "email": "wei.fang@nxp.com",
        "time": "Wed Jun 24 15:27:26 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:40:08 2026 -0700"
      },
      "message": "net: enetc: fix potential divide-by-zero when num_vsi is zero\n\nFor i.MX94 series, all the standalone ENETCs do not support SR-IOV, so\npf-\u003ecaps.num_vsi is zero. This leads to a divide-by-zero in\nenetc4_default_rings_allocation() when distributing rings among PF and\nVFs.\n\nDivision by zero is undefined behavior in C. On ARM64, the UDIV/SDIV\ninstructions silently return zero rather than raising an exception, so\nthe issue does not cause a visible crash. However, relying on this\nbehavior is incorrect and poses a cross-platform compatibility risk.\n\nAdd an explicit check for num_vsi \u003d\u003d 0 and return early after the PF\u0027s\nrings have been configured.\n\nFixes: 2d673b0e2f8d (\"net: enetc: add standalone ENETC support for i.MX94\")\nSigned-off-by: Wei Fang \u003cwei.fang@nxp.com\u003e\nReviewed-by: Maxime Chevallier \u003cmaxime.chevallier@bootlin.com\u003e\nLink: https://patch.msgid.link/20260624072726.1238903-1-wei.fang@oss.nxp.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "14eb1d2c03b38ce3427f299967f7a4d97ebff4c2",
      "tree": "97e2b9fdb8e4fdbd0552cb1efcd5198d570df7b1",
      "parents": [
        "0e901ee5c6f9e1a382099cd7dbee1360c80c441c"
      ],
      "author": {
        "name": "Rob Herring (Arm)",
        "email": "robh@kernel.org",
        "time": "Wed Jun 24 10:02:50 2026 -0500"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:38:36 2026 -0700"
      },
      "message": "dt-bindings: net: renesas,ether: Drop example \"ethernet-phy-ieee802.3-c22\" fallback\n\nFix the Micrel PHY in the example which shouldn\u0027t have the\nfallback \"ethernet-phy-ieee802.3-c22\" compatible:\n\nDocumentation/devicetree/bindings/net/renesas,ether.example.dtb: ethernet-phy@1 \\\n  (ethernet-phy-id0022.1537): compatible: [\u0027ethernet-phy-id0022.1537\u0027, \u0027ethernet-phy-ieee802.3-c22\u0027] is too long\n        from schema $id: http://devicetree.org/schemas/net/micrel.yaml\n\nSigned-off-by: Rob Herring (Arm) \u003crobh@kernel.org\u003e\nReviewed-by: Andrew Lunn \u003candrew@lunn.ch\u003e\nAcked-by: Conor Dooley \u003cconor.dooley@microchip.com\u003e\nAcked-by: Niklas Söderlund \u003cniklas.soderlund+renesas@ragnatech.se\u003e\nFixes: 37a2fce09001 (\"dt-bindings: sh_eth convert bindings to json-schema\")\nLink: https://patch.msgid.link/20260624150250.131966-2-robh@kernel.org\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "0e901ee5c6f9e1a382099cd7dbee1360c80c441c",
      "tree": "e35f45bacd6d936cb14d4353484f015690951775",
      "parents": [
        "ecf69d4b43370c587e48d4d70289dbdb7e039d4d"
      ],
      "author": {
        "name": "Runyu Xiao",
        "email": "runyu.xiao@seu.edu.cn",
        "time": "Wed Jun 24 23:01:49 2026 +0800"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:38:00 2026 -0700"
      },
      "message": "openvswitch: conntrack: annotate ct limit hlist traversal\n\nct_limit_set() is documented as being called with ovs_mutex held. It\nwalks the ct limit hlist with hlist_for_each_entry_rcu(), but the\niterator does not currently pass the OVS lockdep condition used\nelsewhere for RCU-protected OVS objects.\n\nPass lockdep_ovsl_is_held() to the iterator. This matches the function\u0027s\nexisting caller contract and lets CONFIG_PROVE_RCU_LIST distinguish the\novs_mutex-protected update path from the RCU read-side ct_limit_get()\npath.\n\nThis was found by our static analysis tool and then manually reviewed\nagainst the current tree. In the reviewed CONFIG_PROVE_RCU_LIST triage\nrun, the writer-side ct limit update produced the expected \"RCU-list\ntraversed in non-reader section!!\" warning while ovs_mutex was held,\nwith the stack matching ct_limit_set() and ovs_ct_limit_set_zone_limit().\nThe change is limited to documenting the existing protection contract.\n\nThis is a lockdep annotation cleanup. It does not change the conntrack\nlimit list update or release behavior.\n\nSigned-off-by: Runyu Xiao \u003crunyu.xiao@seu.edu.cn\u003e\nReviewed-by: Eelco Chaudron \u003cechaudro@redhat.com\u003e\nLink: https://patch.msgid.link/20260624150149.3510541-1-runyu.xiao@seu.edu.cn\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "ecf69d4b43370c587e48d4d70289dbdb7e039d4d",
      "tree": "864b0868e13ff9b06174d62b2d08815fdb3e028c",
      "parents": [
        "02f144fbb4c86c360495d33debe307cb46a57f95"
      ],
      "author": {
        "name": "Eric Dumazet",
        "email": "edumazet@google.com",
        "time": "Thu Jun 25 06:59:36 2026 +0000"
      },
      "committer": {
        "name": "Jakub Kicinski",
        "email": "kuba@kernel.org",
        "time": "Thu Jun 25 08:35:51 2026 -0700"
      },
      "message": "net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync\n\nYue Sun reported a use-after-free and debugobjects warning in\nudp_tunnel_nic_device_sync_work() during concurrent device operations.\n\nThe workqueue core clears the internal pending bit before invoking the\nworker. At that point, a concurrent thread can queue the work again.\nWhen the already running worker eventually clears the work_pending flag\nto 0, it mistakenly clears the flag for the newly queued instance.\nudp_tunnel_nic_unregister() then observes work_pending as 0 and frees\nthe structure while the second work item is still active in the queue,\nleading to UAF.\n\nFix this by returning early in udp_tunnel_nic_device_sync() if\nwork_pending is already set, preventing redundant work queueing.\n\nFixes: cc4e3835eff4 (\"udp_tunnel: add central NIC RX port offload infrastructure\")\nReported-by: Yue Sun \u003csamsun1006219@gmail.com\u003e\nSuggested-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\nSigned-off-by: Eric Dumazet \u003cedumazet@google.com\u003e\nLink: https://patch.msgid.link/20260625065938.654652-2-edumazet@google.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n"
    },
    {
      "commit": "92010229c4b38897f1319d260162d2f96925ed17",
      "tree": "2fe74026ae00aca9d38102cc4743e0fc076007fd",
      "parents": [
        "db810874e581db749c8c6ed9820a97fe63ea6e42",
        "19ec63c4efa84db23b8de192d792783f70f90fae",
        "9e5c34544e37fb3bda02346b38c57e0aae724e57"
      ],
      "author": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:47 2026 -0700"
      },
      "committer": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:47 2026 -0700"
      },
      "message": "Merge branches \u0027clk-microchip\u0027 and \u0027clk-qcom\u0027 into clk-next\n\n* clk-microchip:\n  clk: at91: keep securam node alive while mapping it\n  clk: at91: sama7d65: add peripheral clock for I3C\n  clk: microchip: mpfs-ccc: fix peripheral driver registration failures after oob fix\n  clk: at91: sam9x7: Fix gmac_gclk clock definition\n  clk: at91: sam9x7: Rename macb0_clk to gmac_clk\n  clk: at91: sam9x7: Remove gmac peripheral clock with ID 67\n  clk: microchip: rename clk-core to clk-pic32\n\n* clk-qcom: (32 commits)\n  clk: qcom: regmap-phy-mux: Rework the implementation\n  clk: qcom: a53: Corrected frequency multiplier for 1152MHz\n  clk: qcom: camcc-milos: Declare icc path dependency for CAMSS_TOP_GDSC\n  clk: qcom: gdsc: Support enabling interconnect path for power domain\n  dt-bindings: clock: qcom,milos-camcc: Document interconnect path\n  interconnect: Add devm_of_icc_get_by_index() as exported API for users\n  clk: qcom: camcc-x1p42100: Add support for camera clock controller\n  clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks\n  clk: qcom: videocc-x1p42100: Add support for video clock controller\n  dt-bindings: clock: qcom: Add X1P42100 camera clock controller\n  dt-bindings: clock: qcom: Add X1P42100 video clock controller\n  clk: qcom: nord: negcc: add support for the USB2 PHY reset\n  dt-bindings: clock: qcom: add the definition for the USB2 PHY reset\n  clk: qcom: clk-rpmh: Make all VRMs optional\n  clk: qcom: Add support for global clock controller on Hawi\n  clk: qcom: clk-alpha-pll: Add support for Taycan EHA_T PLL\n  clk: qcom: Add Hawi TCSR clock controller driver\n  clk: qcom: rpmh: Add support for Hawi RPMH clocks\n  dt-bindings: clock: qcom: Add Hawi global clock controller\n  dt-bindings: clock: qcom: Add Hawi TCSR clock controller\n  ...\n"
    },
    {
      "commit": "db810874e581db749c8c6ed9820a97fe63ea6e42",
      "tree": "542f919cb6de11a6cd088407c25cd0ddbdc634f5",
      "parents": [
        "e08f2083dd50fb86fe86ccd276201901bcf08c7e",
        "c400e4ceb915effc506bbdb1756b3ac587fa3a82",
        "3bb620aefbe01d7a48ace99d9484b9772d360b8f",
        "0f92f188c8622b7e64d35be99e7ad946a04d5242",
        "834b14a5c4a753a637939008d6c59d4fdc299c7e"
      ],
      "author": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:38 2026 -0700"
      },
      "committer": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:38 2026 -0700"
      },
      "message": "Merge branches \u0027clk-ti\u0027, \u0027clk-samsung\u0027, \u0027clk-rockchip\u0027 and \u0027clk-spacemit\u0027 into clk-next\n\n* clk-ti:\n  clk: keystone: sci-clk: fix application of sizeof to pointer\n  clk: keystone: don\u0027t cache clock rate\n\n* clk-samsung:\n  clk: samsung: exynos990: Fix PERIC0/1 USI clock types\n  clk: samsung: exynos850: mark APM I3C clocks as critical\n\n* clk-rockchip:\n  clk: rockchip: allow COMPILE_TEST builds\n  clk: rockchip: rk3588: add GATE_GRF clocks for I2S MCLK output to IO\n  soc: rockchip: rk3588: add SYS_GRF SOC_CON6 register offset\n  clk: rockchip: add helper to register auxiliary GRFs\n  clk: rockchip: allow grf_type_sys lookup in aux_grf_table\n  dt-bindings: clock: rockchip,rk3588-cru: add I2S MCLK output to IO clock IDs\n\n* clk-spacemit:\n  clk: spacemit: k3: Add PCIe DBI clock\n  dt-bindings: soc: spacemit: k3: Add PCIe DBI clock IDs\n  clk: spacemit: k3: Fix PCIe clock register offset\n  clk: spacemit: k3: Switch to pll2_d6 as parent for PCIe clock\n"
    },
    {
      "commit": "e08f2083dd50fb86fe86ccd276201901bcf08c7e",
      "tree": "1e3933980b3ce95214f9f2115b7275ac50ff9be6",
      "parents": [
        "124e5c5ec9524af8402106a850b0cfe285245ce0",
        "5c2fd8bb7314edf7348c17426a05e70c9219fe71",
        "c0c07529485bb8026b99cf5160d668654074f7dc",
        "392627674a6114c9176a64540760d097611a3c9f",
        "df2e28941e8abbae432d019dca0911292b8f4ac7"
      ],
      "author": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:26 2026 -0700"
      },
      "committer": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:26 2026 -0700"
      },
      "message": "Merge branches \u0027clk-renesas\u0027, \u0027clk-socfpga\u0027, \u0027clk-amlogic\u0027 and \u0027clk-canaan\u0027 into clk-next\n\n* clk-renesas: (36 commits)\n  clk: renesas: r9a08g045: Drop unused pm_domain header file\n  clk: renesas: r8a779g0: Add DSC clock\n  clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing\n  clk: renesas: r9a08g045: Drop unused DEF_G3S_MUX macro\n  clk: renesas: rzg2l: Rename RZG3L-prefixed PLL macros to CPG-prefixed ones\n  clk: renesas: rzg3s/rzg3l: Simplify PLL configuration macro\n  clk: renesas: rzg2l: Simplify SAM PLL configuration macro\n  clk: renesas: r8a73a4: Add ZT/ZTR trace clocks\n  dt-bindings: clock: renesas,cpg-clocks: Document ZT/ZTR trace clock on R-Mobile APE6\n  clk: renesas: r9a08g046: Add RSPI clocks and resets\n  clk: renesas: r9a08g046: Add SSIF-2 clocks and resets\n  clk: renesas: r9a08g046: Add RSCI clocks and resets\n  clk: renesas: cpg-mssr: Add number of clock cells check\n  clk: renesas: rzg2l: Refactor rzg3l_cpg_pll_clk_endisable()\n  clk: renesas: rzg2l: Consolidate DEF_MUX() and DEF_MUX_FLAGS()\n  clk: renesas: r9a08g046: Add IA55_PCLK to critical module clocks\n  clk: renesas: r9a09g047: Add support for LCDC{0,1} clocks and resets\n  clk: renesas: r9a09g047: Add support for DSI clocks and resets\n  clk: renesas: r9a09g047: Add support for SMUX2_DSI{0,1}_CLK\n  clk: renesas: r9a09g047: Add CLK_PLLDSI{0,1}_CSDIV clocks\n  ...\n\n* clk-socfpga:\n  clk: socfpga: agilex: implement l3_main_free_clk\n\n* clk-amlogic:\n  dt-bindings: clock: amlogic: t7: Add missing mpll3 parent clock\n  dt-bindings: clock: amlogic: Fix redundant hyphen in \"amlogic,t7-gp1--pll\" string.\n\n* clk-canaan:\n  clk: canaan: Add clock driver for Canaan K230\n  dt-bindings: clock: Add Canaan K230 clock controller\n"
    },
    {
      "commit": "124e5c5ec9524af8402106a850b0cfe285245ce0",
      "tree": "4c57f65a2fc12af1e10b55039d2622ac7905e892",
      "parents": [
        "7b03559044d20bb4cfa1a19df79dd1b52e27fb3a",
        "845a025a9436d40517b8fab0baea2d6157e0a552",
        "8267609a380f3f0f47c1e0d13440cb87b3a65d6e",
        "0aef2f0db6db22c2a441e067d8e8458106fb0483"
      ],
      "author": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:16 2026 -0700"
      },
      "committer": {
        "name": "Stephen Boyd",
        "email": "sboyd@kernel.org",
        "time": "Thu Jun 25 07:55:16 2026 -0700"
      },
      "message": "Merge branches \u0027clk-cleanup\u0027, \u0027clk-mediatek\u0027, \u0027clk-marvell\u0027 and \u0027clk-versal\u0027 into clk-next\n\n* clk-cleanup:\n  clk: hisilicon: Improve deallocation in error path\n  clk-lpc18xx-ccu: kzalloc + kcalloc to kzalloc_flex\n  clk: bulk: Use dev_err_probe() helper in of_clk_bulk_get()\n  clk: bcm: iproc-asiu: simplify allocation\n  clk: clk-max77686: kzalloc + kcalloc to kzalloc\n  clk: visconti: pll: use kzalloc_flex\n  clk: hisilicon: clkdivider-hi6220: use kzalloc_flex\n  clk: mvebu: use kzalloc_flex\n\n* clk-mediatek:\n  clk: mediatek: mt7988: use MUX_CLR_SET for gate-less muxes\n  clk: mediatek: mt8192: use MUX_CLR_SET\n  clk: mediatek: add MUX_CLR_SET macro\n\n* clk-marvell:\n  clk: mmp: pxa1908-apbcp: Add reset cells\n  clk: mmp: pxa1908-apbc: Add reset cells\n  dt-bindings: clock: marvell,pxa1908: Add #reset-cells\n\n* clk-versal:\n  clk: clk-axi-clkgen: Add support versal timings\n"
    }
  ],
  "next": "cf6f56990ea21172e085f0588e5bbf2089ce8f58"
}
