Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
546 commits
Select commit Hold shift + click to select a range
e067956
staging: media: tegra-video: vi: fix probe failure on skipped last port
alvin0603 Jul 7, 2026
687b35a
media: staging/ipu7: fix async notifier UAF on probe error path
Congnt264 Jul 30, 2026
8cb6a86
scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
Jun 28, 2026
763d123
rpmsg: glink: smem: order FIFO read after availability check
ChunkaiDeng Jun 18, 2026
6589725
Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinep…
Jul 3, 2026
e32f72b
arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
krzk Apr 13, 2026
f9609d4
arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
mike-scott May 21, 2026
7604276
arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
QSchulz Jun 12, 2026
af134e7
arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
QSchulz Jun 26, 2026
1f46ca2
arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
jakob-tsd Jun 9, 2026
ccf5f25
arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
Jul 17, 2026
1c41365
arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
Jul 3, 2026
e8ea266
riscv: acpi: Handle LPI architectural context loss flags
Aug 8, 2026
ae01f8f
riscv: unaligned: stop using kthread for check_vector_unaligned_access()
covanam Aug 8, 2026
b39214e
remoteproc: scp: Fix device reference leak on failed lookup
jhovold Jul 6, 2026
1ecc482
ptp: vmclock: prevent read-only mappings from becoming writable
suruurism Aug 13, 2026
2a8824e
qede: Fix NULL pointer dereference in TPA fragment processing
nagarevaibhav Aug 18, 2026
ccb7f97
RDMA/cxgb4: Cancel reg_work before freeing device on remove
Aug 6, 2026
2e998c1
RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
brettcreeley Aug 5, 2026
c0b25e7
RDMA/ucma: Lock the handler in ucma_set_ib_path()
nszetei Jul 27, 2026
f804b5f
RDMA/ucma: Lock the handler in ucma_write_cm_event()
nszetei Jul 27, 2026
03109e3
RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
jgunthorpe Jul 2, 2026
b6206cb
regulator: as3722_get_regulator_dt_data: fix premature of_node_put le…
ISCAS-Vulab Jun 26, 2026
edd7502
regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after o…
ISCAS-Vulab Jun 26, 2026
5644c7f
regulator: qcom-refgen: correct the regulator type to CURRENT
kathiravan-moorthy Jun 17, 2026
4aa33a6
ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
vdonnefort Aug 13, 2026
a69c68c
ring-buffer: Free cpu_buffer::free_page with subbuf_order
vdonnefort Aug 13, 2026
ce972da
ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
vdonnefort Aug 13, 2026
0e1238f
PM: sleep: Unblock runtime PM when device prepare fails
Aug 18, 2026
0bbddae
orangefs: fix double-free of trailer_buf on readdir copy failure
bhcsayx Aug 3, 2026
1808b40
orangefs: skip leading spaces before parsing client debug masks
Jul 23, 2026
83e7dd3
ocfs2: always run deallocs on copy-on-write completion
dmantipov Jul 21, 2026
556412e
ocfs2: bound namelen in dlm_migrate_request_handler
bryamzxz Jun 29, 2026
97351f4
ocfs2: validate lengths in dlm_mig_lockres_handler
bryamzxz Jun 29, 2026
5325713
ocfs2: validate rl_used against rl_count in refcount block validator
Jul 9, 2026
d269be5
ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_regi…
josephhz Jul 22, 2026
72af0d1
ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from …
josephhz Jul 22, 2026
92757ca
ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
josephhz Jul 22, 2026
2d7c58f
ocfs2: fix readdir position truncation on 32-bit kernels
zhanxusheng1024-os Aug 6, 2026
a74bf40
openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
lrfe Aug 21, 2026
9072f51
openvswitch: only skb_tx_error() a packet we are about to drop
nszetei Aug 22, 2026
193baca
ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
sammiee5311 Aug 8, 2026
8407782
arm64: compat: Fix decrementing LDM/STM alignment emulation
kmehltretter82 Aug 19, 2026
8fd56c6
arm64: proton-pack: Restore the nospectre_bhb command-line option
kmehltretter82 Jul 26, 2026
962dc9e
ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
cjtlabs Aug 23, 2026
a6f193b
hwmon: (max6621) fix negative temperature offset and crit readings
Congnt264 Aug 10, 2026
25ee495
hwmon: (max6621) fix temperature clamp range
Congnt264 Aug 10, 2026
218d7de
i2c: mxs: fix DMA channel leak on probe error
Ryuwang3 Aug 15, 2026
1de5616
ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
bhcsayx Aug 25, 2026
8507984
lockd: pin next file across nlm_inspect_file lock-drop
mjbommar May 24, 2026
4023689
lockd: fix NULL dereference on lockowner allocation failure
shuangpeng-kernel Jul 17, 2026
74f49db
nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in er…
May 13, 2026
74cecc9
nvme: zero the discard fallback page
Jul 30, 2026
aac49f9
nvme-pci: disable controller on admin queue IRQ setup failure
testacegi Jul 15, 2026
fbd924f
nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
Aug 1, 2026
7f87437
nvme-tcp: fix host memory disclosure on R2T for a read command
Jul 29, 2026
9bcc9c3
nvme-tcp: reject a read that transferred too few bytes
Aug 1, 2026
532b30a
sctp: stop processing a packet once its association is deleted
V4bel Aug 14, 2026
02ee002
sctp: drop a chunk if its transport was removed
V4bel Aug 19, 2026
8cbc8cb
sctp: fix NULL deref on untransmitted RECONF completion
winmin Aug 23, 2026
3474797
sctp: distinguish sequence zero from wildcard in reconf lookup
Aug 24, 2026
18655b0
sctp: fix stream->outcnt underflow on duplicate RECONF responses
Aug 24, 2026
e740d03
power: supply: bq24257: fix use-after-free on remove
Aug 1, 2026
b80b3aa
power: supply: bq256xx: drain usb_work before freeing the charger
Aug 4, 2026
0c1abea
power: supply: bq25890: Fix power_supply reference leak
Jul 22, 2026
8f3c9fa
power: supply: charger-manager: register regulators before exposing s…
Jul 28, 2026
adcab10
power: supply: cros_usbpd-charger: bound the EC-reported port count
bryamzxz Jun 17, 2026
957a351
power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
jthiesatgoogle Jul 22, 2026
5af10bf
power: supply: lp8727: fix use-after-free in lp8727_release_irq()
Aug 7, 2026
36add7b
power: supply: lp8788-charger: fix use-after-free on remove
Aug 2, 2026
7364056
power: supply: qcom_battmgr: fix use-after-free
Aug 1, 2026
a9b5cd6
power: supply: qcom_battmgr: terminate the strings from firmware
sammiee5311 Jul 27, 2026
5b89889
power: supply: rt9455: quiesce delayed work before teardown
Jul 23, 2026
d568be0
power: supply: twl4030_charger: cancel workers via devm
maoyixie Jul 25, 2026
a18b015
power: supply: ucs1002: fix use-after-free on remove
Aug 2, 2026
571407d
power: supply: max17040: propagate register read errors
Jul 27, 2026
63cd7ad
power: supply: max17040: drop incorrect I2C functionality check
Jul 31, 2026
552849b
power: supply: max17040: synchronize work cancellation on suspend
Aug 10, 2026
2f6a3d0
s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
Aug 11, 2026
db1d027
s390/dasd: Do not complete a failed ESE read as successful
Aug 5, 2026
49bf6af
s390/dasd: Guard sysfs discipline callbacks against unallocated priva…
Aug 5, 2026
79b4e25
s390/dasd: Propagate partial completion length across ERP recovery
Aug 5, 2026
97dd0ff
PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
Aug 10, 2026
66bc3f4
PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
raiz-deen Jul 23, 2026
20b8e60
PCI: meson: Fix GPIO state while requesting PERST#
rclaveau-tech Jun 16, 2026
67dabc3
PCI: plda: Fix use-after-free of event IRQs during teardown
alitariq4589-2 Jul 23, 2026
707dc9e
PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_inter…
alitariq4589-2 Jul 23, 2026
c007fcd
PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
Gateworks Jul 20, 2026
e58e98a
PCI/sysfs: Fix read byte order in pci_read_legacy_io()
kwilczynski Jun 16, 2026
904bfe6
PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
kwilczynski Jul 20, 2026
91a2a2b
PCI/AER: Emit TLP Log only for unmasked errors
l1k Jul 24, 2026
a7a0914
PCI/AER: Fix mapping of errors to agent & layer
l1k Jul 24, 2026
fb87942
PCI/ASPM: Avoid L0s for Realtek RTS525A
chochien Jul 7, 2026
a8867e8
PCI/MSI: Enable memory decoding before restoring MSI-X messages
Aug 5, 2026
24252fd
PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
kwilczynski Jul 29, 2026
480f2c4
PCI/proc: Use file_ns_capable() when checking config space read access
kwilczynski Jul 20, 2026
a372a4a
PCI/proc: Warn on writes to kernel-exclusive config space regions
kwilczynski Jul 29, 2026
ca0ffbf
iommu/amd: Put PCI device after handling PPR faults
axiqia Jul 27, 2026
d57b17c
iommu/msm: Unwind probe state on registration failure
Jul 16, 2026
a094a7d
iommu/sva: Set handle->dev before the SVA handle is visible
axiqia Jul 26, 2026
a5e738d
iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
nicolinc Jul 14, 2026
352c99d
iommu/arm-smmu-v3: Manage teardown with devm
Jun 29, 2026
acf3dcb
iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_…
BaldDemian Jul 11, 2026
523e6a7
iommu/vt-d: Fix no_iommu to disable platform opt-in
ktian1 Aug 4, 2026
7dde57f
iommu/vt-d: Force requesting ACS when tboot is enabled
ktian1 Aug 4, 2026
2f59d4e
iommufd: Avoid locking internal accesses during unmap
axiqia Jul 26, 2026
e489ea9
iommufd: Release current IOAS on xa_store() failure
axiqia Jul 26, 2026
ba06cc0
iommufd: Fix UAF in selftest IOPF reporting
BaldDemian Aug 11, 2026
9d223dd
platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
sammiee5311 Jun 14, 2026
7605649
platform/x86: ISST: Validate level in perf mask ioctls
sammiee5311 Aug 7, 2026
0e5603e
platform/x86: ISST: Validate socket ID in clos_assoc ioctl
sammiee5311 Aug 7, 2026
cafc76c
mmc: via-sdmmc: cancel card-detect work on remove
Jul 23, 2026
bd20d33
mmc: via-sdmmc: stop card-detect handling on probe failure
Jul 23, 2026
ec5a817
platform/x86: ISST: Add a NULL check for sst_inst[]
spandruvada Aug 11, 2026
0f394ae
platform/x86: ISST: Just allow 2 bits for SST feature enable
spandruvada Aug 11, 2026
cba415d
platform/x86: ISST: Use PP level enable mask
spandruvada Aug 11, 2026
f90d3fd
platform/x86: ISST: Validate logical CPU id and clos id
spandruvada Aug 11, 2026
8bae1e9
platform/x86: ISST: Validate parameter for core power state
spandruvada Aug 11, 2026
129b9e1
platform/x86: ISST: Validate parameter for frequency and priority
spandruvada Aug 11, 2026
bdbc12d
platform/x86: ISST: Return error during profile addition
spandruvada Aug 11, 2026
91cdd5d
platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe e…
Jun 24, 2026
0b506e8
platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch que…
realRobotix Jun 14, 2026
edad312
platform/x86: think-lmi: Fix certificate thumbprint sysfs output
toblux Aug 10, 2026
5162e06
platform/x86: think-lmi: Free system certificate signatures
toblux Aug 10, 2026
bca867b
platform/x86: think-lmi: Fix current password length check
toblux Aug 18, 2026
87ce26b
platform/chrome: sensorhub: Bound the EC-reported sensor number
bryamzxz Jun 18, 2026
33b354b
platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
superm1 Jul 21, 2026
19c0a91
platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
superm1 Jul 21, 2026
dea634d
platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
superm1 Jul 21, 2026
718a8b0
platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP …
Jul 9, 2026
556ac16
platform/x86: hp-bioscfg: advance elem past consumed array elements
Aug 12, 2026
c2602c7
platform/x86: hp-bioscfg: bound ordered-list parsing by the package c…
Jul 9, 2026
dfa3712
platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_sto…
Aug 12, 2026
be983ac
platform/x86: hp-bioscfg: fix heap OOB read on empty password write
Aug 12, 2026
081876d
platform/x86: hp-bioscfg: fix new_password_store() overwriting curren…
Aug 12, 2026
d318683
platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_…
Aug 12, 2026
def15ef
platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
Aug 12, 2026
55c4a3e
platform/x86: hp-bioscfg: pass validated element count to package par…
Jul 9, 2026
c93df69
platform/x86: hp-bioscfg: warn on element type mismatch instead of fa…
Jul 9, 2026
f0227af
io_uring/query: cap user size passed to copy_struct_to_user
laxmanacharya8 Aug 21, 2026
2dbe4db
interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
visitorckw Apr 16, 2026
d9805f2
ipmi: ipmb: validate write message length
Yousef13710 Jun 24, 2026
51d14de
ipmi: Remove all sysfs files on registration failure
Uuuuuuho Aug 3, 2026
82254f5
ipmi: si: Fix NULL pointer dereference after failed registration
Seiji-Nishikawa Jun 30, 2026
375fde6
ipmi:msghandler: Cancel work cleanly on an error
cminyard Aug 18, 2026
97fc1ed
net/iucv: filter frames in afiucv_hs_rcv() by ingress device
SandyWinter Aug 21, 2026
d3f0514
xdp: fix zero-copy frame layout
winmin Aug 18, 2026
1013f12
slip: fix use-after-free in sl_sync()
Aug 24, 2026
241f5d7
net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
fabio-porcedda Aug 12, 2026
72b6607
net: tun: bound receive headroom
manizada Aug 12, 2026
245b4ed
net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
a3f Aug 14, 2026
2f1533d
net: ibm: emac: mal: fix NAPI locking
Aug 11, 2026
642dfba
net: ipa: fix stalled modem TX queue after runtime resume
The-Mighty-Cat Aug 15, 2026
9e2af4b
net: l2tp: do not propagate multicast notification errors
Aug 20, 2026
e504695
net: openvswitch: fix flow mask use-after-free on flow deletion
igsilya Aug 15, 2026
e127ec6
net: openvswitch: fix nf_connlabels leak in ovs_ct_init
Ryuwang3 Aug 15, 2026
d2ccc42
net: phylink: correctly validate returned PCS in phylink_inband_caps
Ansuel Aug 17, 2026
475c215
net: ravb: avoid dereferencing an invalid PTP clock
Aug 11, 2026
85e1aa8
net: ravb: serialize PTP clock teardown
Aug 11, 2026
a338c97
net: thunderbolt: Release the Rx HopID that was handed out on mismatch
faliye Aug 11, 2026
cf4a4c6
net: thunderbolt: Mark the connection down when bringing it up fails
faliye Aug 11, 2026
7035203
NTB: ntb_transport: Recycle TX entries before client callbacks
lkpdn Aug 17, 2026
04a138f
NTB: ntb_transport: Fail TX enqueue when the QP link is down
lkpdn Aug 17, 2026
0dcd858
NTB: ntb_transport: Reject oversized TX buffers
lkpdn Aug 17, 2026
7133ac0
net: ntb_netdev: Fix TX busy and drop handling
lkpdn Aug 17, 2026
0286ea2
net: ntb_netdev: Avoid double-accounting netif_rx() drops
lkpdn Aug 19, 2026
aa9938c
net: ntb_netdev: Count packets dropped on RX refill failure
lkpdn Aug 19, 2026
8de0905
net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
Aug 19, 2026
1e332b3
net/smc: do not dereference an unset send buffer on the SMC-D teardow…
bryamzxz Aug 8, 2026
959bf21
net/smc: fix socket refcount leak in smc_switch_conns()
Aug 20, 2026
6979079
net/smc: fix use-after-free in smc_rx_pipe_buf_release()
Aug 20, 2026
67d7a9c
net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
Aug 19, 2026
6b33e5d
net/smc: stop killed, freed and out_of_sync sharing a byte
Aug 20, 2026
6c4f2ac
net/smc: unregister the connection before draining the rx tasklet
bryamzxz Aug 8, 2026
6d725f9
net: cap advertised IP tunnel headroom
Aug 12, 2026
5afa400
net: fix spurious TX timeout after dev_activate()
leitao Aug 25, 2026
c1f0b9c
net: skbuff: don't touch shared zerocopy state in skb_tx_error()
nszetei Aug 22, 2026
e79c090
seg6: reset IP6CB after IPv6 decapsulation
Aug 22, 2026
852fe3f
hwrng: stm32 - Fix runtime PM cleanup on registration failure
Jul 18, 2026
a273806
mfd: cgbc: Fix teardown ordering in cgbc_remove()
thom24 Jul 13, 2026
0575554
mfd: sm501: Fix potential memory leaks during remove
Jul 20, 2026
2fd7974
ALSA: 6fire: bound the MIDI event length from the device
baul1337 Aug 5, 2026
5af155e
ALSA: aloop: Check card index validity at probe
tiwai Aug 6, 2026
10a1b21
ALSA: bcd2000: clear the URB pointers on disconnect
baul1337 Aug 5, 2026
436869f
ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
Aug 13, 2026
d34e1d6
ALSA: mpu401: Check card index validity at probe
tiwai Aug 6, 2026
2856d62
ALSA: mts64: Check card index validity at probe
tiwai Aug 6, 2026
0eadf2e
ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
Aug 18, 2026
63ba2ae
ALSA: portman2x4: Check card index validity at probe
tiwai Aug 6, 2026
f25ae66
ALSA: serial-u16550: Check card index validity at probe
tiwai Aug 6, 2026
b98bcf0
ALSA: virmidi: Check card index validity at probe
tiwai Aug 6, 2026
0ffd70b
ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
Emohr-Tuxedo Aug 21, 2026
01e1174
ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q…
ii343hbka Aug 10, 2026
2e55b1b
ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
Aug 17, 2026
a71b6f2
ring-buffer: Fix subbuf resize race with ring buffer readers
vdonnefort Aug 13, 2026
43e1a68
ovpn: run deferred work on a module-owned workqueue
ralflici Sep 3, 2026
541ffe5
rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22
ojeda Sep 3, 2026
ac4846d
net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
Sep 3, 2026
214b4e1
arch_numa: avoid false positive fortify warning in setup_node_to_cpum…
nathanchance Aug 14, 2026
908b103
dm-stats: fix a crash if allocation of per-cpu data fails
Aug 3, 2026
d7aac67
dm-switch: use WRITE_ONCE() in switch_region_table_write()
ISCAS-Vulab Jul 11, 2026
6387e19
dm-pcache: validate geometry fields from on-disk cache_info
bryamzxz Jul 17, 2026
8eda155
dm-pcache: validate kset key_num and intra-segment bounds
bryamzxz Jul 17, 2026
c8eee26
dm-pcache: validate on-media seg_num against the cache device size
bryamzxz Jul 17, 2026
0f40210
dm-pcache: bound the persisted tail-position offset
bryamzxz Jul 17, 2026
0469a77
dm-pcache: clamp the tail kset read to the segment data region
bryamzxz Jul 17, 2026
e2e2347
dm-pcache: detect a cycle in the last-kset chain during replay
bryamzxz Jul 17, 2026
57abe43
dm-pcache: only hand out initialized cache segments
bryamzxz Jul 17, 2026
07765fd
dm-pcache: fix implicit u8 truncation of gc_percent in message handler
Jul 20, 2026
84ec95f
dm-pcache: fix use-after-free and invalid seg operations in kset_repl…
Jul 20, 2026
596fcad
i3c: master: adi: initialize the lock before enabling interrupts
Jun 17, 2026
dd98990
i3c: master: Fix info leak and UAF in device unregister path
ahunter6 Jul 23, 2026
15860a4
i3c: master: svc: bound IBI payload to the requested max_payload_len
maoyixie Jun 24, 2026
8483e3b
i3c: renesas: Check that the transfer is valid before accessing it
claudiubeznea Jul 13, 2026
5dd9de9
i3c: renesas: Clean DATBAS register on detach
claudiubeznea Jul 13, 2026
b9c671a
i3c: renesas: Reconfigure the DATBAS register on re-attach
claudiubeznea Jul 13, 2026
56063f1
wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
Aug 3, 2026
5f8395e
wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
Jun 24, 2026
f434cee
wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
Jun 30, 2026
8126d35
crypto: sun8i-ce - Remove crypto_rng interface
Jun 15, 2026
bfb84f8
crypto: sun8i-ss - Remove crypto_rng interface
Jun 15, 2026
7e8c4cf
wifi: mwifiex: Detach sync cmd buffer on interrupted wait
Jul 24, 2026
b9bfc4a
wifi: rtl818x: initialize eeprom_93cx6 struct to zero
sgruszka Jul 23, 2026
324392f
wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
Jun 20, 2026
021abaf
wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw…
Jul 23, 2026
ba46f85
wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
Jul 27, 2026
22240d2
wifi: rtw88: pci: fix resource leak on failed NAPI setup
Jun 17, 2026
5f17868
wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
Jun 12, 2026
e4c0c4a
wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE …
bryamzxz Jun 25, 2026
fed3dad
wifi: mt76: mt7925: cancel mlo_pm_work on stop
Lucid-Duck Jun 27, 2026
c085de6
wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
nbd168 Jul 22, 2026
fb7b32e
wifi: mt76: mt7996: validate default EEPROM firmware size
laxmanacharya8 Jul 13, 2026
ec857a8
vsock/virtio: flush works in dependency order
Ychame Aug 22, 2026
ca3f3fd
w1: ds28e17: reject an oversize length on an I2C block read
maoyixie Jun 29, 2026
71e0ac9
xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
x-y-z Aug 4, 2026
b821a71
zloop: truncate finished zones to zone capacity
Aug 4, 2026
a0914af
tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
testacegi Jun 26, 2026
14f7cbd
sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
oleg-nesterov Jul 20, 2026
03698a4
sticon/parisc: Detect default STI graphics card for console output
hdeller Aug 6, 2026
c1f0580
signal: avoid shared siginfo namespace rewrites
Jun 22, 2026
17f8472
smack: fix cred UAF in smack_file_send_sigiotask()
thejh Aug 6, 2026
518d342
taskstats: fix cpumask parsing cutting off the last character
Jul 23, 2026
53c1b8d
timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtim…
t-8ch Jul 31, 2026
5b21de5
timer: Keep debugobjects state consistent in migrate_timer_list()
Aug 17, 2026
01cb970
udf: Fix i_lenExtents truncation on 32-bit kernels
zhanxusheng1024-os Jul 22, 2026
02b65ca
selftests/mm: fix on-fault-limit false failure under sudo-rs
injaeryou Jul 13, 2026
29b7ceb
platform/chrome: sensorhub: Fix dropped timestamp events and log spam
Jul 15, 2026
135b4e2
mm: avoid unnecessary use of is_swap_pmd()
ljskernel Sep 3, 2026
2012d3e
mm/rmap: use huge_ptep_get() in try_to_unmap_one()
Sep 3, 2026
51a3a10
Linux 6.18.50
gregkh Sep 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion Documentation/ABI/testing/sysfs-bus-nvdimm
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,8 @@ What: /sys/bus/nd/devices/nmemX/cxl/id
Date: November 2022
KernelVersion: 6.2
Contact: Dave Jiang <dave.jiang@intel.com>
Description: (RO) Show the id (serial) of the device. This is CXL specific.
Description: (RO) Show the id (serial) of the device, formatted as an
unsigned 64-bit decimal value. This is CXL specific.

What: /sys/bus/nd/devices/nmemX/cxl/provider
Date: November 2022
Expand Down
9 changes: 4 additions & 5 deletions Documentation/admin-guide/blockdev/zoned_loop.rst
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,10 @@ indicates the position of the write pointer of the zone.

When resetting a sequential zone, its backing file size is truncated to zero.
Conversely, for a zone finish operation, the backing file is truncated to the
zone size. With this, the maximum capacity of a zloop zoned block device created
can be larger configured to be larger than the storage space available on the
backing file system. Of course, for such configuration, writing more data than
the storage space available on the backing file system will result in write
errors.
zone capacity. With this, a zloop zoned block device can be configured with a
larger capacity than the storage space available on the backing file system. Of
course, for such configuration, writing more data than the storage space
available on the backing file system will result in write errors.

The zoned loop block device driver implements a complete zone transition state
machine. That is, zones can be empty, implicitly opened, explicitly opened,
Expand Down
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 6
PATCHLEVEL = 18
SUBLEVEL = 49
SUBLEVEL = 50
EXTRAVERSION =
NAME = Baby Opossum Posse

Expand Down
8 changes: 6 additions & 2 deletions arch/alpha/include/uapi/asm/fpu.h
Original file line number Diff line number Diff line change
Expand Up @@ -101,7 +101,12 @@ ieee_swcr_to_fpcr(unsigned long sw)
| IEEE_TRAP_ENABLE_OVF)) << 48;
fp |= (~sw & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE)) << 57;
fp |= (sw & IEEE_MAP_UMZ ? FPCR_UNDZ | FPCR_UNFD : 0);
fp |= (~sw & IEEE_TRAP_ENABLE_DNO) << 41;
/*
* Disable denormal operand traps only when denormal inputs are to be
* flushed to zero. Otherwise they must keep trapping, so that /S
* instructions reach the kernel emulation handler.
*/
fp |= (sw & IEEE_MAP_DMZ ? FPCR_DNOD : 0);
return fp;
}

Expand All @@ -116,7 +121,6 @@ ieee_fpcr_to_swcr(unsigned long fp)
| IEEE_TRAP_ENABLE_OVF);
sw |= (~fp >> 57) & (IEEE_TRAP_ENABLE_UNF | IEEE_TRAP_ENABLE_INE);
sw |= (fp >> 47) & IEEE_MAP_UMZ;
sw |= (~fp >> 41) & IEEE_TRAP_ENABLE_DNO;
return sw;
}

Expand Down
6 changes: 3 additions & 3 deletions arch/alpha/kernel/pci-sysfs.c
Original file line number Diff line number Diff line change
Expand Up @@ -364,17 +364,17 @@ int pci_legacy_write(struct pci_bus *bus, loff_t port, u32 val, size_t size)

switch(size) {
case 1:
outb(port, val);
outb(val, port);
return 1;
case 2:
if (port & 1)
return -EINVAL;
outw(port, val);
outw(val, port);
return 2;
case 4:
if (port & 3)
return -EINVAL;
outl(port, val);
outl(val, port);
return 4;
}
return -EINVAL;
Expand Down
25 changes: 12 additions & 13 deletions arch/alpha/kernel/sys_marvel.c
Original file line number Diff line number Diff line change
Expand Up @@ -263,6 +263,18 @@ init_io7_irqs(struct io7 *io7,
*/
printk(" Interrupts reported to CPU at PE %u\n", boot_cpuid);

/* Set up the lsi irqs. */
for (i = 0; i < 128; ++i) {
irq_set_chip_and_handler(base + i, lsi_ops, handle_level_irq);
irq_set_status_flags(base + i, IRQ_LEVEL);
}

/* Set up the msi irqs. */
for (i = 128; i < (128 + 512); ++i) {
irq_set_chip_and_handler(base + i, msi_ops, handle_level_irq);
irq_set_status_flags(base + i, IRQ_LEVEL);
}

raw_spin_lock(&io7->irq_lock);

/* set up the error irqs */
Expand All @@ -272,26 +284,13 @@ init_io7_irqs(struct io7 *io7,
io7_redirect_irq(io7, &io7->csrs->STV_CTL.csr, boot_cpuid);
io7_redirect_irq(io7, &io7->csrs->HEI_CTL.csr, boot_cpuid);

/* Set up the lsi irqs. */
for (i = 0; i < 128; ++i) {
irq_set_chip_and_handler(base + i, lsi_ops, handle_level_irq);
irq_set_status_flags(i, IRQ_LEVEL);
}

/* Disable the implemented irqs in hardware. */
for (i = 0; i < 0x60; ++i)
init_one_io7_lsi(io7, i, boot_cpuid);

init_one_io7_lsi(io7, 0x74, boot_cpuid);
init_one_io7_lsi(io7, 0x75, boot_cpuid);


/* Set up the msi irqs. */
for (i = 128; i < (128 + 512); ++i) {
irq_set_chip_and_handler(base + i, msi_ops, handle_level_irq);
irq_set_status_flags(i, IRQ_LEVEL);
}

for (i = 0; i < 16; ++i)
init_one_io7_msi(io7, i, boot_cpuid);

Expand Down
6 changes: 3 additions & 3 deletions arch/alpha/kernel/traps.c
Original file line number Diff line number Diff line change
Expand Up @@ -166,12 +166,12 @@ static long dummy_emul(void) { return 0; }
long (*alpha_fp_emul_imprecise)(struct pt_regs *regs, unsigned long writemask)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul_imprecise);
long (*alpha_fp_emul) (unsigned long pc)
long (*alpha_fp_emul) (unsigned long pc, unsigned long summary)
= (void *)dummy_emul;
EXPORT_SYMBOL_GPL(alpha_fp_emul);
#else
long alpha_fp_emul_imprecise(struct pt_regs *regs, unsigned long writemask);
long alpha_fp_emul (unsigned long pc);
long alpha_fp_emul (unsigned long pc, unsigned long summary);
#endif

asmlinkage void
Expand All @@ -185,7 +185,7 @@ do_entArith(unsigned long summary, unsigned long write_mask,
emulate the instruction. If the processor supports
precise exceptions, we don't have to search. */
if (!amask(AMASK_PRECISE_TRAP))
si_code = alpha_fp_emul(regs->pc - 4);
si_code = alpha_fp_emul(regs->pc - 4, summary);
else
si_code = alpha_fp_emul_imprecise(regs, write_mask);
if (si_code == 0)
Expand Down
88 changes: 77 additions & 11 deletions arch/alpha/math-emu/math.c
Original file line number Diff line number Diff line change
Expand Up @@ -52,13 +52,13 @@ MODULE_DESCRIPTION("FP Software completion module");
MODULE_LICENSE("GPL v2");

extern long (*alpha_fp_emul_imprecise)(struct pt_regs *, unsigned long);
extern long (*alpha_fp_emul) (unsigned long pc);
extern long (*alpha_fp_emul) (unsigned long pc, unsigned long summary);

static long (*save_emul_imprecise)(struct pt_regs *, unsigned long);
static long (*save_emul) (unsigned long pc);
static long (*save_emul) (unsigned long pc, unsigned long summary);

long do_alpha_fp_emul_imprecise(struct pt_regs *, unsigned long);
long do_alpha_fp_emul(unsigned long);
long do_alpha_fp_emul(unsigned long, unsigned long);

static int alpha_fp_emul_init_module(void)
{
Expand Down Expand Up @@ -86,7 +86,22 @@ module_exit(alpha_fp_emul_cleanup_module);


/*
* Emulate the floating point instruction at address PC. Returns -1 if the
* Exception bits of the exception summary register (EXC_SUM). Bit 0 is the
* software completion bit; bits 1 through 5 report the exceptions the
* hardware attributed to the trapping instruction, and lie at the same
* positions as the corresponding IEEE_TRAP_ENABLE_* bits.
*/
#define EXC_SUM_INV (1UL << 1)
#define EXC_SUM_DZE (1UL << 2)
#define EXC_SUM_OVF (1UL << 3)
#define EXC_SUM_UNF (1UL << 4)
#define EXC_SUM_INE (1UL << 5)
#define EXC_SUM_MASK (EXC_SUM_INV | EXC_SUM_DZE | EXC_SUM_OVF \
| EXC_SUM_UNF | EXC_SUM_INE)

/*
* Emulate the floating point instruction at address PC. SUMMARY is the
* exception summary register the trap was delivered with. Returns -1 if the
* instruction to be emulated is illegal (such as with the opDEC trap), else
* the SI_CODE for a SIGFPE signal, else 0 if everything's ok.
*
Expand All @@ -95,7 +110,7 @@ module_exit(alpha_fp_emul_cleanup_module);
* stick the result of the operation into the appropriate register.
*/
long
alpha_fp_emul (unsigned long pc)
alpha_fp_emul (unsigned long pc, unsigned long summary)
{
FP_DECL_EX;
FP_DECL_S(SA); FP_DECL_S(SB); FP_DECL_S(SR);
Expand Down Expand Up @@ -300,12 +315,56 @@ alpha_fp_emul (unsigned long pc)
swcr |= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
current_thread_info()->ieee_state
|= (_fex << IEEE_STATUS_TO_EXCSUM_SHIFT);
}

/* Update hardware control register. */
fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
fpcr |= ieee_swcr_to_fpcr(swcr);
wrfpcr(fpcr);
/*
* EV6 records exception status bits in the FPCR before delivering the
* software completion trap, and swcr_update_status() above merged them
* into SWCR. Some can be wrong for the instruction we just emulated:
* a CVTTS of a value exactly representable as a subnormal sets FPCR_UNF
* even though the result is exact. Clear the exceptions the trap
* reported but that soft-fp did not raise.
*/
if (implver() == IMPLVER_EV6) {
unsigned long spurious = summary & EXC_SUM_MASK;

if (spurious & (EXC_SUM_UNF | EXC_SUM_OVF)) {
/*
* EXC_SUM reports only the underflow or overflow,
* but the hardware sets INE alongside it in the FPCR.
*/
spurious |= EXC_SUM_INE;
} else if (!spurious) {
/*
* No exception reported, so this was a denormal
* operand trap, for which INE and UNF can be
* fabricated as well.
*/
spurious = EXC_SUM_INE | EXC_SUM_UNF;
}

/*
* Never clear an exception software has confirmed. Every
* instruction that genuinely raises one traps for software
* completion and is recorded in ieee_state above, so a bit
* found there -- including one just set from _fex -- belongs
* to this or an earlier instruction and must survive.
*/
spurious &= ~(current_thread_info()->ieee_state
>> IEEE_STATUS_TO_EXCSUM_SHIFT);

swcr &= ~(spurious << IEEE_STATUS_TO_EXCSUM_SHIFT);
}

/*
* Update hardware control register. This has to happen even when
* soft-fp raised nothing, to clear any fabricated bits.
*/
fpcr &= (~FPCR_MASK | FPCR_DYN_MASK);
fpcr |= ieee_swcr_to_fpcr(swcr);
wrfpcr(fpcr);

if (_fex) {
/* Do we generate a signal? */
_fex = _fex & swcr & IEEE_TRAP_ENABLE_MASK;
si_code = 0;
Expand Down Expand Up @@ -387,9 +446,16 @@ alpha_fp_emul_imprecise (struct pt_regs *regs, unsigned long write_mask)
break;
}
if (!write_mask) {
/* Re-execute insns in the trap-shadow. */
/*
* Re-execute insns in the trap-shadow. Pass no
* exception summary: it describes the trap, which
* was taken anywhere in the shadow, and so is not
* attribution for this instruction. Nothing is
* lost, since only EV6 -- which traps precisely and
* never comes this way -- needs it.
*/
regs->pc = trigger_pc + 4;
si_code = alpha_fp_emul(trigger_pc);
si_code = alpha_fp_emul(trigger_pc, 0);
goto egress;
}
trigger_pc -= 4;
Expand Down
2 changes: 1 addition & 1 deletion arch/arm/Kconfig
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ config ARM
select HAVE_ARCH_TRACEHOOK
select HAVE_ARCH_TRANSPARENT_HUGEPAGE if ARM_LPAE
select HAVE_ARM_SMCCC if CPU_V7
select HAVE_EBPF_JIT if !CPU_ENDIAN_BE32
select HAVE_EBPF_JIT if !CPU_ENDIAN_BE32 && !CPU_32v3
select HAVE_CONTEXT_TRACKING_USER
select HAVE_C_RECORDMCOUNT
select HAVE_BUILDTIME_MCOUNT_SORT
Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/qcom/sm6115-fxtec-pro1x.dts
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@

interrupts-extended = <&tlmm 80 IRQ_TYPE_LEVEL_LOW>;

irq-gpios = <&tlmm 80 IRQ_TYPE_LEVEL_LOW>;
irq-gpios = <&tlmm 80 GPIO_ACTIVE_LOW>;
reset-gpios = <&tlmm 71 GPIO_ACTIVE_HIGH>;
AVDD28-supply = <&ts_vdd_supply>;
VDDIO-supply = <&ts_vddio_supply>;
Expand Down
2 changes: 2 additions & 0 deletions arch/arm64/boot/dts/qcom/x1-dell-thena.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -589,6 +589,7 @@
regulator-min-microvolt = <1200000>;
regulator-max-microvolt = <1200000>;
regulator-initial-mode = <RPMH_REGULATOR_MODE_HPM>;
regulator-always-on;
};

vreg_l13b_3p0: ldo13 {
Expand All @@ -610,6 +611,7 @@
regulator-min-microvolt = <1800000>;
regulator-max-microvolt = <1800000>;
regulator-initial-mode = <RPMH_REGULATOR_MODE_HPM>;
regulator-always-on;
};
};

Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-cobra.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

gpio-leds {
Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-pp1516.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

gpio-leds {
Expand Down
2 changes: 1 addition & 1 deletion arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
compatible = "mmc-pwrseq-emmc";
pinctrl-0 = <&emmc_reset>;
pinctrl-names = "default";
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_HIGH>;
reset-gpios = <&gpio1 RK_PB3 GPIO_ACTIVE_LOW>;
};

leds {
Expand Down
18 changes: 0 additions & 18 deletions arch/arm64/boot/dts/rockchip/rk3399-pinephone-pro.dts
Original file line number Diff line number Diff line change
Expand Up @@ -689,12 +689,6 @@
};
};

wifi {
wifi_host_wake_l: wifi-host-wake-l {
rockchip,pins = <4 RK_PD0 RK_FUNC_GPIO &pcfg_pull_none>;
};
};

wireless-bluetooth {
bt_wake_pin: bt-wake-pin {
rockchip,pins = <2 RK_PD2 RK_FUNC_GPIO &pcfg_pull_none>;
Expand All @@ -721,19 +715,7 @@
pinctrl-names = "default";
pinctrl-0 = <&sdio0_bus4 &sdio0_cmd &sdio0_clk>;
sd-uhs-sdr104;
#address-cells = <1>;
#size-cells = <0>;
status = "okay";

brcmf: wifi@1 {
compatible = "brcm,bcm4329-fmac";
reg = <1>;
interrupt-parent = <&gpio4>;
interrupts = <RK_PD0 IRQ_TYPE_LEVEL_HIGH>;
interrupt-names = "host-wake";
pinctrl-names = "default";
pinctrl-0 = <&wifi_host_wake_l>;
};
};

&pwm0 {
Expand Down
12 changes: 12 additions & 0 deletions arch/arm64/boot/dts/rockchip/rk3399-roc-pc-plus.dts
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,18 @@
<3 RK_PD7 1 &pcfg_pull_none>;
};

&i2s0_8ch_bus_bclk_off {
rockchip,pins =
<3 RK_PD0 RK_FUNC_GPIO &pcfg_pull_none>,
<3 RK_PD1 1 &pcfg_pull_none>,
<3 RK_PD2 1 &pcfg_pull_none>,
<3 RK_PD3 1 &pcfg_pull_none>,
<3 RK_PD4 1 &pcfg_pull_none>,
<3 RK_PD5 1 &pcfg_pull_none>,
<3 RK_PD6 1 &pcfg_pull_none>,
<3 RK_PD7 1 &pcfg_pull_none>;
};

&i2s1 {
pinctrl-names = "default";
pinctrl-0 = <&i2s_8ch_mclk_pin>, <&i2s1_2ch_bus>;
Expand Down
Loading
Loading