<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-next.git/net/devlink, branch master</title>
<subtitle>Linux kernel latest source</subtitle>
<id>http://mirrors.hust.edu.cn/git/linux-next.git/atom?h=master</id>
<link rel='self' href='http://mirrors.hust.edu.cn/git/linux-next.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/'/>
<updated>2026-09-18T01:23:35+00:00</updated>
<entry>
<title>devlink: validate the port index in the rate set request</title>
<updated>2026-09-18T01:23:35+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-09-15T16:13:41+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=2a22788ba265881eb048f224534b7556815026de'/>
<id>urn:sha1:2a22788ba265881eb048f224534b7556815026de</id>
<content type='text'>
port-index is the only way rate-set can address a leaf (port) rate object,
but it was never listed in the request, so the generated policy has no
entry for it. The op declares .maxattr = DEVLINK_ATTR_PARENT_DEV, so the
attribute still reaches info-&gt;attrs[], validated against a zeroed slot -
NLA_UNSPEC, length 0 - which GENL_DONT_VALIDATE_STRICT accepts at any
length.

devlink_port_get_from_attrs() then runs nla_get_u32() on it. Handed a
zero-length port-index the kernel reads the four bytes past the payload,
which are the next attribute's header, and acts on the port index those
spell out. Since we're reading a linear skb the OOB read is still
within the same memory allocation, it's just garbage. We also do not
echo the garbage back to the user so it's not an info leak either.
Hence not treating this is a real bug fix.

rate-new is left alone on purpose. It creates rate nodes, resolved by
name through devlink_rate_node_get_from_attrs(), and never looks at
port-index.

Link: https://patch.msgid.link/20260915161341.1053476-10-kuba@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>devlink: generate the port function policy from the spec</title>
<updated>2026-09-18T01:23:35+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-09-15T16:13:37+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=3ec610a6bb12bcd6f93e8c3eaf14ccbe68558bd4'/>
<id>urn:sha1:3ec610a6bb12bcd6f93e8c3eaf14ccbe68558bd4</id>
<content type='text'>
devlink has a one huge root attribute set for the whole family,
we haven't taken the time to properly define the sub-sets for
each command. Do it for port-set so that we can drop the hand
written policy used by devlink_port_function_set().

We need this subsetting because within the DEVLINK_ATTR_PORT_FUNCTION
nest DEVLINK_PORT_FN_ATTR_OPSTATE and DEVLINK_PORT_FN_ATTR_DEVLINK
are output-only so we have to filter them out of the input set.

Link: https://patch.msgid.link/20260915161341.1053476-6-kuba@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>netlink: specs: devlink: complete the port function nest</title>
<updated>2026-09-18T01:23:35+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-09-15T16:13:36+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=4ced66fc97bf7f979f76256ee04a180f65261b7e'/>
<id>urn:sha1:4ced66fc97bf7f979f76256ee04a180f65261b7e</id>
<content type='text'>
dl-port-function stops at caps, but the nest also carries
DEVLINK_PORT_FN_ATTR_DEVLINK (5) and DEVLINK_PORT_FN_ATTR_MAX_IO_EQS (6)
both put by devlink_nl_port_function_attrs_put() on every port-get
do and dump. YNL raises

  Space 'dl-port-function' has no attribute with value '6'

for any port reporting max_io_eqs or a nested devlink handle,
i.e. for mlx5 SFs and VFs.

Commit 5af3e3876d56 ("devlink: Support setting max_io_eqs") added the
uAPI value and the hand written policy but never touched the spec.

Add the missing attributes, subsequent commit reworks the code
to use the YNL-generated policy.

Link: https://patch.msgid.link/20260915161341.1053476-5-kuba@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>devlink: fix the enum behind DEVLINK_ATTR_RELOAD_LIMITS</title>
<updated>2026-09-18T01:23:34+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-09-15T16:13:33+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=6c53effab88df871c5196b4f026cdac6943283e2'/>
<id>urn:sha1:6c53effab88df871c5196b4f026cdac6943283e2</id>
<content type='text'>
DEVLINK_ATTR_RELOAD_LIMITS carries enum devlink_reload_limit, the spec
says enum devlink_reload_action. The two are unrelated, and have
a different set of values (bits 1, 2 vs bits 0, 1).

AFAICT this is a cosmetic change - both DEVLINK_RELOAD_LIMIT_UNSPEC
and the out of bounds bit 2 will be rejected either way because drivers
don't declare them as supported. User will see either a policy
validation failure or "Requested limit is not supported by the driver".

While at it annotate the right enum for reload-stats-limit

Link: https://patch.msgid.link/20260915161341.1053476-2-kuba@kernel.org
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net</title>
<updated>2026-09-10T22:14:05+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-08-06T18:51:42+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=99d76b4da88f21edd14b169f65de33e8df1b7804'/>
<id>urn:sha1:99d76b4da88f21edd14b169f65de33e8df1b7804</id>
<content type='text'>
Cross-merge networking fixes after downstream PR (net-7.3-rc3).

Conflicts:

drivers/net/dsa/mt7530.c
  3c18e3c9a54e ("net: dsa: mt7530: populate lpi_interfaces to fix EEE support")
  10d9d8328e8a ("net: dsa: mt7530: replace mt7530_read with regmap_read")

Adjacent changes:

drivers/net/bonding/bond_alb.c
  1746ef2e2df2 ("bonding: use skb_cow_head() in bond_do_alb_xmit() and rlb_arp_xmit()")
  4cef95f72bbd ("bonding: fix u32 overflow in compute_gap()")

Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>treewide: refresh kmalloc_obj() conversions</title>
<updated>2026-09-05T04:37:00+00:00</updated>
<author>
<name>Kees Cook</name>
<email>kees+treewide@kernel.org</email>
</author>
<published>2026-09-02T22:31:14+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=3a2c4d55e32ad65efebdb6de44eef3bfa08bb49d'/>
<id>urn:sha1:3a2c4d55e32ad65efebdb6de44eef3bfa08bb49d</id>
<content type='text'>
This is another run of the Coccinelle script for converting kmalloc()
family of allocations to kmalloc_obj() via the existing rules in
scripts/coccinelle/api/kmalloc_objs.cocci

This catches both the set of kmalloc() uses added since the first
kmalloc_obj() conversions in v7.0 and adds a large group missed in the
first pass due to Coccinelle not interacting well with the cleanup.h
scoped_...() family of macros[1]. I worked around this with spatch's
"--macro-file" argument to a file with all the scoped_...() macros mapped
to Coccinelle's YACFE_ITERATOR[2] as that was the closest viable control
flow indicator I could find.

Build tested allmodconfig on x86, arm64, arm, loongarch, mips, powerpc,
riscv, and s390 with no new warnings.

Link: https://lore.kernel.org/lkml/202609021314.8A9C0B8@keescook/ [1]
Link: https://github.com/coccinelle/coccinelle/blob/master/standard.h [2]
Signed-off-by: Kees Cook &lt;kees+treewide@kernel.org&gt;
</content>
</entry>
<entry>
<title>devlink: use direct firmware requests for flash updates</title>
<updated>2026-09-04T00:11:37+00:00</updated>
<author>
<name>Miguel Garcia</name>
<email>miguelgarciaroman8@gmail.com</email>
</author>
<published>2026-09-02T09:57:30+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=94284e5442bac57a33da5dd48549eb5ec803fa97'/>
<id>urn:sha1:94284e5442bac57a33da5dd48549eb5ec803fa97</id>
<content type='text'>
request_firmware() may enter the sysfs fallback and call
try_to_freeze(). Devlink invokes it while holding the instance lock,
causing syzbot to report:

  WARNING: syz-executor/... still has locks held!

Firmware flash requests already name a file provided by userspace.
Use request_firmware_direct() in both flash update paths so a missing
file fails immediately instead of entering the sysfs fallback. This
keeps the normal devlink locking intact.

On systems with CONFIG_FW_LOADER_USER_HELPER_FALLBACK=y, devlink flash
can no longer obtain a missing image through that fallback. Callers still
receive the existing error result, and netlink users retain the extack
message.

Cc: stable+noautosel@kernel.org # FW_LOADER_USER_HELPER_FALLBACK=y has no known use
Reported-by: syzbot+372a7d84708b07f64d9b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=372a7d84708b07f64d9b
Suggested-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
Signed-off-by: Miguel Garcia &lt;miguelgarciaroman8@gmail.com&gt;
Link: https://patch.msgid.link/20260902095739.3587287-1-miguelgarciaroman8@gmail.com
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>devlink: add generic device max_sfs parameter</title>
<updated>2026-08-12T01:06:30+00:00</updated>
<author>
<name>Nikolay Aleksandrov</name>
<email>nikolay@nvidia.com</email>
</author>
<published>2026-08-06T07:30:36+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=26ba30221c03364d6ed9910be8da4c1fd871b07b'/>
<id>urn:sha1:26ba30221c03364d6ed9910be8da4c1fd871b07b</id>
<content type='text'>
Add a new generic devlink device parameter (max_sfs) to control if and
how many light-weight NIC subfunctions can be created. Subfunctions are
a light-weight network functions backed by an underlying PCI function.
Their lifecycle can already be managed by devlink, but currently users
cannot enable them in the device. They can be enabled/disabled only via
external vendor tools. This parameter allows subfunctions to be enabled
(&gt;0) or disabled (0) via devlink. A subsequent patch will add support
for max_sfs to the mlx5 driver.

Signed-off-by: Nikolay Aleksandrov &lt;nikolay@nvidia.com&gt;
Reviewed-by: David Ahern &lt;dsahern@kernel.org&gt;
Reviewed-by: Jiri Pirko &lt;jiri@nvidia.com&gt;
Reviewed-by: Aleksandr Loktionov &lt;aleksandr.loktionov@intel.com&gt;
Reviewed-by: Alexander Lobakin &lt;aleksander.lobakin@intel.com&gt;
Signed-off-by: Tariq Toukan &lt;tariqt@nvidia.com&gt;
Link: https://patch.msgid.link/20260806073037.3001886-2-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net</title>
<updated>2026-08-06T18:53:47+00:00</updated>
<author>
<name>Jakub Kicinski</name>
<email>kuba@kernel.org</email>
</author>
<published>2026-08-06T18:51:42+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=1962afd211597001c0582414a9dee66908a8ad8a'/>
<id>urn:sha1:1962afd211597001c0582414a9dee66908a8ad8a</id>
<content type='text'>
Cross-merge networking fixes after downstream PR (net-7.2-rc7).

No conflicts, or adjacent changes.

Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>devlink: Expose external flag for PCI SF ports</title>
<updated>2026-08-05T23:39:54+00:00</updated>
<author>
<name>Shay Drory</name>
<email>shayd@nvidia.com</email>
</author>
<published>2026-08-03T09:00:12+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=cb59bfd419d0c560b9f7273522f9a4799062aad5'/>
<id>urn:sha1:cb59bfd419d0c560b9f7273522f9a4799062aad5</id>
<content type='text'>
The external flag is part of the PCI SF port attributes, but unlike the
PCI PF and PCI VF flavours it was never filled into the port dump, so
userspace could not query it directly.

Reporting of the external flag was missed for SF ports. Hence, put
DEVLINK_ATTR_PORT_EXTERNAL for the PCI SF flavour as well, matching what
PCI PF and PCI VF ports already report.

$ devlink port show pci/0033:01:00.0/163840
 pci/0033:01:00.0/163840: type eth netdev eth1 flavour pcisf controller 1 pfnum 0 sfnum 77 external true splittable false

Reviewed-by: Parav Pandit &lt;parav@nvidia.com&gt;
Signed-off-by: Shay Drory &lt;shayd@nvidia.com&gt;
Link: https://patch.msgid.link/20260803090012.257242-1-shayd@nvidia.com
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
</feed>
