Skip to content

[rocky9_8] History Rebuild through kernel-5.14.0-687.36.1.el9_8 - #1518

Open
PlaidCat wants to merge 14 commits into
rocky9_8from
rocky9_8_rebuild
Open

[rocky9_8] History Rebuild through kernel-5.14.0-687.36.1.el9_8#1518
PlaidCat wants to merge 14 commits into
rocky9_8from
rocky9_8_rebuild

Conversation

@PlaidCat

@PlaidCat PlaidCat commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator

This is an automated kernel history rebuild using cron and internal tooling. It follows the same process used for previous history rebuilds:

  • Download all unprocessed src.rpm packages
  • For each src.rpm:
    • Identify all commits in the changelog up to the last known tag (5.14.0-687)
    • Replay commits in chronological order (oldest to newest in the changelog) using git cherry-pick
    • Replace the code in the branch with the output of rpmbuild -bp for the corresponding src.rpm
    • Tag the rebuild branch

JIRA Tickets

Rebuild Splat Inspection

kernel-5.14.0-687.36.1.el9_8

$ cat ciq/ciq_backports/kernel-5.14.0-687.36.1.el9_8/rebuild.details.txt
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v5.14~1..kernel-mainline: 394115
Number of commits in rpm: 19
Number of commits matched with upstream: 13 (68.42%)
Number of commits in upstream but not in rpm: 394102
Number of commits NOT found in upstream: 6 (31.58%)

Rebuilding Kernel on Branch rocky9_8_rebuild_kernel-5.14.0-687.36.1.el9_8 for kernel-5.14.0-687.36.1.el9_8
Clean Cherry Picks: 12 (92.31%)
Empty Cherry Picks: 1 (7.69%)
_______________________________

__EMPTY COMMITS__________________________
190a8c48ff623c3d67cb295b4536a660db2012aa futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()

__CHANGES NOT IN UPSTREAM________________
Replace sbat with Rocky Linux sbat
Change bug tracker URL
Ensure appended release in sbat is removed'
mm/vmscan: add sysctl to limit direct reclaim scanning depth
mm/memcg: refactor try_charge_memcg retry logic to use for loop
mm/memcg: introduce tunable sysctl for memory cgroup reclaim retries

BUILD

$ grep -E -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
  CLEAN   include/config include/generated
[TIMER]{MRPROPER}: 6s
x86_64 architecture detected, copying config
'configs/kernel-x86_64-rhel.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky9_8_rebuild-b77d4cd45c1b"
Making olddefconfig
--
  HOSTCC  scripts/kconfig/util.o
  HOSTLD  scripts/kconfig/conf
#
# configuration written to .config
#
Starting Build
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_32.h
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_64.h
  SYSHDR  arch/x86/include/generated/uapi/asm/unistd_x32.h
  SYSTBL  arch/x86/include/generated/asm/syscalls_32.h
  SYSHDR  arch/x86/include/generated/asm/unistd_32_ia32.h
--
  BTF [M] sound/usb/usx2y/snd-usb-usx2y.ko
  BTF [M] sound/xen/snd_xen_front.ko
  BTF [M] sound/usb/snd-usb-audio.ko
  BTF [M] sound/virtio/virtio_snd.ko
  BTF [M] sound/x86/snd-hdmi-lpe-audio.ko
[TIMER]{BUILD}: 1684s
Making Modules
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/arch/x86/crypto/blake2s-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/arch/x86/crypto/blowfish-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/arch/x86/crypto/camellia-aesni-avx-x86_64.ko
  INSTALL /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/arch/x86/crypto/camellia-aesni-avx2.ko
--
  STRIP   /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/sound/xen/snd_xen_front.ko
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/sound/usb/snd-usb-audio.ko
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/sound/x86/snd-hdmi-lpe-audio.ko
  SIGN    /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b/kernel/sound/xen/snd_xen_front.ko
  DEPMOD  /lib/modules/5.14.0-rocky9_8_rebuild-b77d4cd45c1b
[TIMER]{MODULES}: 10s
Making Install
sh ./arch/x86/boot/install.sh 5.14.0-rocky9_8_rebuild-b77d4cd45c1b \
	arch/x86/boot/bzImage System.map "/boot"
[TIMER]{INSTALL}: 27s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-5.14.0-rocky9_8_rebuild-b77d4cd45c1b and Index to 0
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 6s
[TIMER]{BUILD}: 1684s
[TIMER]{MODULES}: 10s
[TIMER]{INSTALL}: 27s
[TIMER]{TOTAL} 1732s
Rebooting in 10 seconds

KSelfTests

$ get_kselftest_diff.sh
kselftest.5.14.0-rocky9_8_rebuild-47aa54c0c001.log
311
kselftest.5.14.0-rocky9_8_rebuild-b186dfd3b15c.log
311
kselftest.5.14.0-rocky9_8_rebuild-1293b303d524.log
311
kselftest.5.14.0-rocky9_8_rebuild-b77d4cd45c1b.log
311
Before: kselftest.5.14.0-rocky9_8_rebuild-1293b303d524.log
After: kselftest.5.14.0-rocky9_8_rebuild-b77d4cd45c1b.log
Diff:
No differences found.

PlaidCat added 14 commits August 7, 2026 00:01
…le()

jira KERNEL-1450
cve CVE-2026-43450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Hyunwoo Kim <imv4bel@gmail.com>
commit 6dcee84

nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label
inside the for loop body.  When the "last" helper saved in cb->args[1]
is deleted between dump rounds, every entry fails the (cur != last)
check, so cb->args[1] is never cleared.  The for loop finishes with
cb->args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back
into the loop body bypassing the bounds check, causing an 8-byte
out-of-bounds read on nf_ct_helper_hash[nf_ct_helper_hsize].

The 'goto restart' block was meant to re-traverse the current bucket
when "last" is no longer found, but it was placed after the for loop
instead of inside it.  Move the block into the for loop body so that
the restart only occurs while cb->args[0] is still within bounds.

 BUG: KASAN: slab-out-of-bounds in nfnl_cthelper_dump_table+0x9f/0x1b0
 Read of size 8 at addr ffff888104ca3000 by task poc_cthelper/131
 Call Trace:
  nfnl_cthelper_dump_table+0x9f/0x1b0
  netlink_dump+0x333/0x880
  netlink_recvmsg+0x3e2/0x4b0
  sock_recvmsg+0xde/0xf0
  __sys_recvfrom+0x150/0x200
  __x64_sys_recvfrom+0x76/0x90
  do_syscall_64+0xc3/0x6e0

 Allocated by task 1:
  __kvmalloc_node_noprof+0x21b/0x700
  nf_ct_alloc_hashtable+0x65/0xd0
  nf_conntrack_helper_init+0x21/0x60
  nf_conntrack_init_start+0x18d/0x300
  nf_conntrack_standalone_init+0x12/0xc0

Fixes: 12f7a50 ("netfilter: add user-space connection tracking helper infrastructure")
	Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
	Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit 6dcee84)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Kery Qi <qikeyu2017@gmail.com>
commit f93fc5d

octep_vf_request_irqs() requests MSI-X queue IRQs with dev_id set to
ioq_vector. If request_irq() fails part-way, the rollback loop calls
free_irq() with dev_id set to 'oct', which does not match the original
dev_id and may leave the irqaction registered.

This can keep IRQ handlers alive while ioq_vector is later freed during
unwind/teardown, leading to a use-after-free or crash when an interrupt
fires.

Fix the error path to free IRQs with the same ioq_vector dev_id used
during request_irq().

Fixes: 1cd3b40 ("octeon_ep_vf: add Tx/Rx processing and interrupt support")
	Signed-off-by: Kery Qi <qikeyu2017@gmail.com>
Link: https://patch.msgid.link/20260108164256.1749-2-qikeyu2017@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f93fc5d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Vimlesh Kumar <vimleshk@marvell.com>
commit 484e834

Make sure the OUT DBELL base address reflects the
latest values written to it.

Fix:
Add a wait until the OUT DBELL base address register
is updated with the DMA ring descriptor address,
and modify the setup_oq function to properly
handle failures.

Fixes: 2c0c32c ("octeon_ep_vf: add hardware configuration APIs")
	Signed-off-by: Sathesh Edara <sedara@marvell.com>
	Signed-off-by: Shinas Rasheed <srasheed@marvell.com>
	Signed-off-by: Vimlesh Kumar <vimleshk@marvell.com>
Link: https://patch.msgid.link/20260206111510.1045092-4-vimleshk@marvell.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 484e834)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Vimlesh Kumar <vimleshk@marvell.com>
commit 2ae7d20

Relocate IQ/OQ IN/OUT_CNTS updates to occur before NAPI completion.
Moving the IQ/OQ counter updates before napi_complete_done ensures
1. Counter registers are updated before re-enabling interrupts.
2. Prevents a race where new packets arrive but counters aren't properly
   synchronized.

Fixes: 1cd3b40 ("octeon_ep_vf: add Tx/Rx processing and interrupt support")
	Signed-off-by: Sathesh Edara <sedara@marvell.com>
	Signed-off-by: Shinas Rasheed <srasheed@marvell.com>
	Signed-off-by: Vimlesh Kumar <vimleshk@marvell.com>
Link: https://patch.msgid.link/20260227091402.1773833-4-vimleshk@marvell.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 2ae7d20)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Vimlesh Kumar <vimleshk@marvell.com>
commit 6c73126

Utilize READ_ONCE and WRITE_ONCE APIs for IO queue Tx/Rx
variable access to prevent compiler optimization and reordering.
Additionally, ensure IO queue OUT/IN_CNT registers are flushed
by performing a read-back after writing.

The compiler could reorder reads/writes to pkts_pending, last_pkt_count,
etc., causing stale values to be used when calculating packets to process
or register updates to send to hardware. The Octeon hardware requires a
read-back after writing to OUT_CNT/IN_CNT registers to ensure the write
has been flushed through any posted write buffers before the interrupt
resend bit is set. Without this, we have observed cases where the hardware
didn't properly update its internal state.

wmb/rmb only provides ordering guarantees but doesn't prevent the compiler
from performing optimizations like caching in registers, load tearing etc.

Fixes: 1cd3b40 ("octeon_ep_vf: add Tx/Rx processing and interrupt support")
	Signed-off-by: Sathesh Edara <sedara@marvell.com>
	Signed-off-by: Shinas Rasheed <srasheed@marvell.com>
	Signed-off-by: Vimlesh Kumar <vimleshk@marvell.com>
Link: https://patch.msgid.link/20260227091402.1773833-5-vimleshk@marvell.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 6c73126)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author David Carlier <devnexen@gmail.com>
commit 4e5bc3f

Introduce octep_vf_oq_next_idx() to consolidate the repeated
ring index advance and wraparound pattern in __octep_vf_oq_process_rx().

No functional change intended.

	Signed-off-by: David Carlier <devnexen@gmail.com>
Link: https://patch.msgid.link/20260409184009.930359-2-devnexen@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 4e5bc3f)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author David Carlier <devnexen@gmail.com>
commit dd66b42

napi_build_skb() can return NULL on allocation failure. In
__octep_vf_oq_process_rx(), the result is used directly without a NULL
check in both the single-buffer and multi-fragment paths, leading to a
NULL pointer dereference.

Add NULL checks after both napi_build_skb() calls, properly advancing
descriptors and consuming remaining fragments on failure.

Fixes: 1cd3b40 ("octeon_ep_vf: add Tx/Rx processing and interrupt support")
	Cc: stable@vger.kernel.org
	Signed-off-by: David Carlier <devnexen@gmail.com>
Link: https://patch.msgid.link/20260409184009.930359-3-devnexen@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit dd66b42)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
cve CVE-2026-23415
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Hao-Yu Yang <naup96721@gmail.com>
commit 190a8c4
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-5.14.0-687.36.1.el9_8/190a8c48.failed

During futex_key_to_node_opt() execution, vma->vm_policy is read under
speculative mmap lock and RCU. Concurrently, mbind() may call
vma_replace_policy() which frees the old mempolicy immediately via
kmem_cache_free().

This creates a race where __futex_key_to_node() dereferences a freed
mempolicy pointer, causing a use-after-free read of mpol->mode.

[  151.412631] BUG: KASAN: slab-use-after-free in __futex_key_to_node (kernel/futex/core.c:349)
[  151.414046] Read of size 2 at addr ffff888001c49634 by task e/87

[  151.415969] Call Trace:

[  151.416732]  __asan_load2 (mm/kasan/generic.c:271)
[  151.416777]  __futex_key_to_node (kernel/futex/core.c:349)
[  151.416822]  get_futex_key (kernel/futex/core.c:374 kernel/futex/core.c:386 kernel/futex/core.c:593)

Fix by adding rcu to __mpol_put().

Fixes: c042c50 ("futex: Implement FUTEX2_MPOL")
	Reported-by: Hao-Yu Yang <naup96721@gmail.com>
	Suggested-by: Eric Dumazet <edumazet@google.com>
	Signed-off-by: Hao-Yu Yang <naup96721@gmail.com>
	Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Link: https://patch.msgid.link/20260324174418.GB1850007@noisy.programming.kicks-ass.net
(cherry picked from commit 190a8c4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	include/linux/mempolicy.h
jira KERNEL-1450
cve CVE-2026-31555
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Davidlohr Bueso <dave@stgolabs.net>
commit 210d36d

Fuzzying/stressing futexes triggered:

    WARNING: kernel/futex/core.c:825 at wait_for_owner_exiting+0x7a/0x80, CPU#11: futex_lock_pi_s/524

When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY
and stores a refcounted task pointer in 'exiting'.

After wait_for_owner_exiting() consumes that reference, the local pointer
is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a
different error, the bogus pointer is passed to wait_for_owner_exiting().

  CPU0			     CPU1		       CPU2
  futex_lock_pi(uaddr)
  // acquires the PI futex
  exit()
    futex_cleanup_begin()
      futex_state = EXITING;
			     futex_lock_pi(uaddr)
			       futex_lock_pi_atomic()
				 attach_to_pi_owner()
				   // observes EXITING
				   *exiting = owner;  // takes ref
				   return -EBUSY
			       wait_for_owner_exiting(-EBUSY, owner)
				 put_task_struct();   // drops ref
			       // exiting still points to owner
			       goto retry;
			       futex_lock_pi_atomic()
				 lock_pi_update_atomic()
				   cmpxchg(uaddr)
					*uaddr ^= WAITERS // whatever
				   // value changed
				 return -EAGAIN;
			       wait_for_owner_exiting(-EAGAIN, exiting) // stale
				 WARN_ON_ONCE(exiting)

Fix this by resetting upon retry, essentially aligning it with requeue_pi.

Fixes: 3ef240e ("futex: Prevent exit livelock")
	Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
	Signed-off-by: Thomas Gleixner <tglx@kernel.org>
	Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260326001759.4129680-1-dave@stgolabs.net
(cherry picked from commit 210d36d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
cve CVE-2026-31554
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Peter Zijlstra <peterz@infradead.org>
commit 19f94b3

Nicholas reported that his LLM found it was possible to create a UaF
when sys_futex_requeue() is used with different flags. The initial
motivation for allowing different flags was the variable sized futex,
but since that hasn't been merged (yet), simply mandate the flags are
identical, as is the case for the old style sys_futex() requeue
operations.

Fixes: 0f4b5f9 ("futex: Add sys_futex_requeue()")
	Reported-by: Nicholas Carlini <npc@anthropic.com>
	Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
(cherry picked from commit 19f94b3)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
cve CVE-2026-52977
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Sebastian Andrzej Siewior <bigeasy@linutronix.de>
commit bc7304f

During wait-requeue-pi (task A) and requeue-PI (task B) the following
race can happen:

     Task A                             Task B
  futex_wait_requeue_pi()
    futex_setup_timer()
    futex_do_wait()
                                   futex_requeue()
                                        CLASS(hb, hb1)(&key1);
                                        CLASS(hb, hb2)(&key2);
        *timeout*
    futex_requeue_pi_wakeup_sync()
        requeue_state = Q_REQUEUE_PI_IGNORE

    *blocks on hb->lock*

                                        futex_proxy_trylock_atomic()
                                          futex_requeue_pi_prepare()
                                            Q_REQUEUE_PI_IGNORE => -EAGAIN
                                        double_unlock_hb(hb1, hb2)
                                         *retry*

Task B acquires both hb locks and attempts to acquire the PI-lock of the
top most waiter (task B). Task A is leaving early due to a signal/
timeout and started removing itself from the queue. It updates its
requeue_state but can not remove it from the list because this requires
the hb lock which is owned by task B.

Usually task A is able to swoop the lock after task B unlocked it.
However if task B is of higher priority then task A may not be able to
wake up in time and acquire the lock before task B gets it again.
Especially on a UP system where A is never scheduled.

As a result task A blocks on the lock and task B busy loops, trying to
make progress but live locks the system instead. Tragic.

This can be fixed by removing the top most waiter from the list in this
case. This allows task B to grab the next top waiter (if any) in the
next iteration and make progress.

Remove the top most waiter if futex_requeue_pi_prepare() fails.
Let the waiter conditionally remove itself from the list in
handle_early_requeue_pi_wakeup().

Fixes: 07d91ef ("futex: Prevent requeue_pi() lock nesting issue on RT")
	Reported-by: Moritz Klammler <Moritz.Klammler@ferchau.com>
	Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
	Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260428103425.dywXyPd3@linutronix.de
Closes: https://lore.kernel.org/all/VE1PR06MB6894BE61C173D802365BE19DFF4CA@VE1PR06MB6894.eurprd06.prod.outlook.com
(cherry picked from commit bc7304f)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…d memory

jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Gaurav Batra <gbatra@linux.ibm.com>
commit 1471c51

Leverage ARCH_HAS_DMA_MAP_DIRECT config option for coherent allocations as
well. This will bypass DMA ops for memory allocations that have been
pre-mapped.

Always set device bus_dma_limit when memory is pre-mapped. In some
architectures, like PowerPC, pmemory can be converted to regular memory via
daxctl command. This will gate the coherent allocations to pre-mapped RAM
only, by dma_coherent_ok().

	Signed-off-by: Gaurav Batra <gbatra@linux.ibm.com>
	Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20251107161105.85999-1-gbatra@linux.ibm.com

(cherry picked from commit 1471c51)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1450
Rebuild_History Non-Buildable kernel-5.14.0-687.36.1.el9_8
commit-author Gaurav Batra <gbatra@linux.ibm.com>
commit 328335a

In a PowerNV environment, for devices that supports DMA mask less than
64 bit but larger than 32 bits, iommu is incorrectly bypassing DMA
APIs while allocating and mapping buffers for DMA operations.

Devices are failing with ENOMEN during probe with the following messages

amdgpu 0000:01:00.0: [drm] Detected VRAM RAM=4096M, BAR=4096M
amdgpu 0000:01:00.0: [drm] RAM width 128bits GDDR5
amdgpu 0000:01:00.0: iommu: 64-bit OK but direct DMA is limited by 0
amdgpu 0000:01:00.0: dma_iommu_get_required_mask: returning bypass mask 0xfffffffffffffff
amdgpu 0000:01:00.0:  4096M of VRAM memory ready
amdgpu 0000:01:00.0:  32570M of GTT memory ready.
amdgpu 0000:01:00.0: (-12) failed to allocate kernel bo
amdgpu 0000:01:00.0: [drm] Debug VRAM access will use slowpath MM access
amdgpu 0000:01:00.0: [drm] GART: num cpu pages 4096, num gpu pages 65536
amdgpu 0000:01:00.0: [drm] PCIE GART of 256M enabled (table at 0x000000F4FFF80000).
amdgpu 0000:01:00.0: (-12) failed to allocate kernel bo
amdgpu 0000:01:00.0: (-12) create WB bo failed
amdgpu 0000:01:00.0: amdgpu_device_wb_init failed -12
amdgpu 0000:01:00.0: amdgpu_device_ip_init failed
amdgpu 0000:01:00.0: Fatal error during GPU init
amdgpu 0000:01:00.0: finishing device.
amdgpu 0000:01:00.0: probe with driver amdgpu failed with error -12
amdgpu 0000:01:00.0:  ttm finalized

Fixes: 1471c51 ("powerpc/iommu: bypass DMA APIs for coherent allocations for pre-mapped memory")
	Suggested-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
	Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
	Reported-by: Dan Horák <dan@danny.cz>
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5039
	Tested-by: Dan Horak <dan@danny.cz>
Closes: https://lore.kernel.org/linuxppc-dev/20260313142351.609bc4c3efe1184f64ca5f44@danny.cz/
	Signed-off-by: Gaurav Batra <gbatra@linux.ibm.com>
Closes: https://lore.kernel.org/linuxppc-dev/20260313142351.609bc4c3efe1184f64ca5f44@danny.cz/
[Maddy: Fixed tags]
	Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260331223022.47488-1-gbatra@linux.ibm.com
(cherry picked from commit 328335a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v5.14~1..kernel-mainline: 394115
Number of commits in rpm: 19
Number of commits matched with upstream: 13 (68.42%)
Number of commits in upstream but not in rpm: 394102
Number of commits NOT found in upstream: 6 (31.58%)

Rebuilding Kernel on Branch rocky9_8_rebuild_kernel-5.14.0-687.36.1.el9_8 for kernel-5.14.0-687.36.1.el9_8
Clean Cherry Picks: 12 (92.31%)
Empty Cherry Picks: 1 (7.69%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-5.14.0-687.36.1.el9_8/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA
@PlaidCat PlaidCat self-assigned this Aug 7, 2026
@PlaidCat
PlaidCat requested review from a team August 7, 2026 04:51

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants