summaryrefslogtreecommitdiff
path: root/include
AgeCommit message (Collapse)Author
26 hoursMerge branch 'kbuild-for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux.git # Conflicts: # scripts/kallsyms.c
26 hoursMerge branch 'mm-nonmm-unstable' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
26 hoursMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/mm/linux.git # Conflicts: # arch/arm64/kvm/mmu.c
26 hoursMerge branch 'mm-nonmm-hotfixes-unstable' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
26 hoursMerge branch 'tip/urgent' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
26 hoursMerge branch 'fixes' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/sre/linux-power-supply.git
26 hoursMerge branch 'master' of git://git.kernel.org/pub/scm/virt/kvm/kvm.gitMark Brown
26 hoursMerge branch 'usb-linus' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git
26 hoursMerge branch 'tty-linus' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty.git
26 hoursMerge branch 'master' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth.git
26 hoursMerge branch 'master' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/
26 hoursMerge branch 'main' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git
27 hoursMerge branch 'vfs.all' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs.git # Conflicts: # fs/smb/server/smb2pdu.c # fs/smb/server/vfs.c # fs/smb/server/vfs.h
27 hoursMerge branch 'nfsd-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/cel/linux
27 hoursMerge branch 'linux-next' of git://git.linux-nfs.org/projects/anna/linux-nfs.gitMark Brown
27 hoursMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/mszeredi/fuse.git
27 hoursMerge branch 'dev' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/jaegeuk/f2fs.git
27 hoursMerge branch 'for_next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/jack/linux-fs.git
27 hoursMerge branch 'configfs-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/leitao/linux.git
27 hoursMerge branch 'cifs-next' of https://git.manguebit.org/linux.gitMark Brown
27 hoursMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux.git
28 hoursseg6: fix HMAC validation when an extension header precedes the SRHYuya Kusakabe
seg6_hmac_validate_skb() derived the SRH from skb_transport_header(). That only holds while the two coincide, which is not true on the seg6_local input path. ip6_rcv_core() leaves the transport header just past the IPv6 header. A Hop-by-Hop options header is consumed before the route lookup and advances it, but a Destination Options header is not: the seg6_local lwtunnel is entered through an input redirect from the route lookup, which bypasses the extension header handlers. The transport header then still points at the Destination Options header while seg6_get_srh() has located the real SRH further down the chain. The HMAC is therefore computed over the Destination Options header, and a packet carrying a valid HMAC TLV is dropped when seg6_require_hmac is set. Such a packet is legitimate: RFC 8200 allows Destination Options before a routing header, and get_srh() has walked the header chain since commit 5829d70b0b6c ("ipv6: sr: fix get_srh() to comply with IPv6 standard "RFC 8200""). With a Fragment or an Authentication header in front of the SRH, the same mistake also reads past the data pulled by seg6_get_srh(). This happens before seg6_require_hmac is read, so the default configuration is affected. Reproduce by giving a node a seg6local End SID with net.ipv6.conf.<dev>.seg6_require_hmac=1 and a key installed with "ip sr hmac set <keyid> sha1", then sending IPv6 -> Destination Options -> SRH (carrying a valid HMAC TLV) -> payload to that SID: it is dropped, while the same packet without the Destination Options header passes. Fixes: 5829d70b0b6c ("ipv6: sr: fix get_srh() to comply with IPv6 standard "RFC 8200"") Assisted-by: LLM Signed-off-by: Yuya Kusakabe <yuya.kusakabe@gmail.com> Reviewed-by: Andrea Mayer <andrea.mayer@uniroma2.it> Link: https://patch.msgid.link/20260926-b4-seg6-hmac-transport-header-v2-1-8087b76f6375@gmail.com Signed-off-by: Paolo Abeni <pabeni@redhat.com>
29 hoursMerge tag 'nf-26-09-30' of ↵Paolo Abeni
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf Pablo Neira Ayuso says: ==================== Netfilter/IPVS fixes for net The following batch contains Netfilter fixes for net. This batch fixes crashes as recent feature regression, one of the due to a dependency that has been pulled into -stable: 1) Expand existing ipset fix for bitmap sets to disallow comments updates from kernel-side adds, from Florian Westphal. 2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise flowtable cannot ever be removed, from Aohan Mei. 3) nft_rbtree GC should collect end elements that contained in this transaction batch, new or deleted elements are never expired. From Weiming Shi. 4) Restrict nf_nat_bpf so it does not set unknown NF_NAT_MANIP_* values, from Fernando F. Mancera. 5) Flowtable GC must skip flows that are pending hardware updates, generalize the PENDING flag and use it to inhibit GC. 6) Restore flowtable with ieee80211 which broke due to a relatively recent commit, which was pulled in by -stable, causing a regression in 6.18 kernels. And the following IPVS fixes: 1) Fix accounting of cache entries in IPVS LBLC for destinations, which eventually fills up the table and trigger recurrent resizing, from Julian Anastasov. 2) Limit IPVS cache growth for LBLCR and LBLC schedulers, from Zhiling Zou. 3) Restrict IP_VS_CONN_F_ONE_PACKET for normal connections, do not allow to use it with templates. Also from Julian. 4) Sanitize flags in IPVS sync messages received in the backup. From Julian Anastasov. netfilter pull request 26-09-30 * tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf: netfilter: flowtable: restore ieee80211 forward path netfilter: flowtable: generalize pending status bit netfilter: bpf: reject invalid NAT manipulation types netfilter: nft_set_rbtree: skip transaction elements during GC ipvs: filter some flags received in the backup server ipvs: do not create invisible templates ipvs: bound LBLCR and LBLC cache growth ipvs: fix missing counter decrement in lblc netfilter: nft_flow_offload: drop flowtable reference on init error path netfilter: ipset: do not update comments from kernel-side adds ==================== Link: https://patch.msgid.link/20260930074142.298353-1-pablo@netfilter.org Signed-off-by: Paolo Abeni <pabeni@redhat.com>
29 hoursdt-bindings: clock: ma35d1: Add missing WDT/WWDT parent clocksMiquel Raynal
The WDT and WWDT muxes have PCLK3/4096 and PCLK4/4096 among their possible parents, but these fixed factor clocks are currently not defined, even though they are needed to properly describe the clock tree. Add them to the bindings. Acked-by: Conor Dooley <conor.dooley@microchip.com> Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com> Link: https://patch.msgid.link/20260930-perso-ma35d1-upstream-clk-v6-4-48937ee6c9bb@bootlin.com Signed-off-by: Jerome Brunet <jbrunet@baylibre.com>
29 hoursdt-bindings: clock: ma35d1: Drop CLK_MAX_IDX defineMiquel Raynal
Drop CLK_MAX_IDX define of MA35D1 include. This is not a binding and should not be placed here. Value is defined in the user driver. Acked-by: Conor Dooley <conor.dooley@microchip.com> Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com> Link: https://patch.msgid.link/20260930-perso-ma35d1-upstream-clk-v6-3-48937ee6c9bb@bootlin.com Signed-off-by: Jerome Brunet <jbrunet@baylibre.com>
29 hoursdrm/intel: rename I915_GTT_VIEW_* enumerations to INTEL_GTT_VIEW_*Jani Nikula
Make the I915_GTT_VIEW_* enumerators less i915 specific, and rename them INTEL_GTT_VIEW_*. $ sed -i 's/I915_GTT_VIEW_/INTEL_GTT_VIEW_/g' -- $(git grep -l I915_GTT_VIEW_) Reviewed-by: Maarten Lankhorst <dev@lankhorst.se> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com> Link: https://patch.msgid.link/6e66fd6b61e361ffde316e5399baf9432383ced5.1790780340.git.jani.nikula@intel.com Signed-off-by: Jani Nikula <jani.nikula@intel.com>
29 hoursdrm/intel: add intel_gtt_view_is_partial() for completenessJani Nikula
There's a helper for all other view types, add one for intel_gtt_view_is_partial() too. Reviewed-by: Maarten Lankhorst <dev@lankhorst.se> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com> Link: https://patch.msgid.link/be522421df45be071ec8f298f4d5b7a49fa6bab8.1790780340.git.jani.nikula@intel.com Signed-off-by: Jani Nikula <jani.nikula@intel.com>
29 hoursdrm/intel: rename i915_gtt_view* struct/enum to intel_gtt_view*Jani Nikula
Make enum i915_gtt_view_type and struct i915_gtt_view less i915 specific, and rename them enum intel_gtt_view_type and struct intel_gtt_view, respectively. $ sed -i 's/i915_gtt_view/intel_gtt_view/g' -- $(git grep -l i915_gtt_view) Reviewed-by: Maarten Lankhorst <dev@lankhorst.se> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com> Link: https://patch.msgid.link/4ca4ad3d11b0f8167a54d69d6eef0c8a78218c53.1790780340.git.jani.nikula@intel.com Signed-off-by: Jani Nikula <jani.nikula@intel.com>
29 hoursdrm/intel: rename i915_gtt_view_is_*() helpers to intel_gtt_view_is_*()Jani Nikula
Make the i915_gtt_view_is_*() helpers less i915 specific, and rename them intel_gtt_view_is_*(). $ sed -i 's/i915_gtt_view_is_/intel_gtt_view_is_/g' -- $(git grep -l i915_gtt_view_is_) Reviewed-by: Maarten Lankhorst <dev@lankhorst.se> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com> Link: https://patch.msgid.link/8230339be1738a1f7c87047f2516dfa66b03d9aa.1790780340.git.jani.nikula@intel.com Signed-off-by: Jani Nikula <jani.nikula@intel.com>
29 hoursdrm/intel: move i915_gtt_view_types.h to include/drm/intelJani Nikula
The i915 and xe drivers share i915_gtt_view_types.h from i915 source. Move it to include/drm/intel/gtt_view_types.h. Remove the i915 compat header. v2: Keep comment for header guard #endif (Ville) Reviewed-by: Maarten Lankhorst <dev@lankhorst.se> Reviewed-by: Ville Syrjälä <ville.syrjala@linux.intel.com> Link: https://patch.msgid.link/174f7e26be755b29a1286bf8b8ef0342dcc083a6.1790780340.git.jani.nikula@intel.com Signed-off-by: Jani Nikula <jani.nikula@intel.com>
29 hourstcp: annotate lockless access to sk->sk_errQuanye Yang
BUG: KCSAN: data-race in do_recvmmsg / mptcp_recvmsg read-write (marked) to 0xffff8880134d391c of 4 bytes by task 2619 on cpu 1: instrument_atomic_read_write include/linux/instrumented.h:113 [inline] sock_error include/net/sock.h:2565 [inline] do_recvmmsg+0x50c/0x580 net/socket.c:3049 __sys_recvmmsg net/socket.c:3144 [inline] __do_sys_recvmmsg net/socket.c:3167 [inline] __se_sys_recvmmsg net/socket.c:3160 [inline] __x64_sys_recvmmsg+0x161/0x180 net/socket.c:3160 x64_sys_call+0x19c7/0x1ca0 arch/x86/include/generated/asm/syscalls_64.h:300 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline] do_syscall_64+0xde/0x3d0 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe+0x77/0x7f read to 0xffff8880134d391c of 4 bytes by task 2620 on cpu 0: tcp_recv_should_stop include/net/tcp.h:3086 [inline] mptcp_recvmsg+0x54d/0xd50 net/mptcp/protocol.c:2466 inet_recvmsg+0x204/0x210 net/ipv4/af_inet.c:894 sock_recvmsg_nosec net/socket.c:1151 [inline] sock_recvmsg+0x11a/0x140 net/socket.c:1173 ____sys_recvmsg+0x14b/0x3c0 net/socket.c:2933 ___sys_recvmsg+0x116/0x160 net/socket.c:2975 __sys_recvmsg net/socket.c:3008 [inline] __do_sys_recvmsg net/socket.c:3014 [inline] __se_sys_recvmsg net/socket.c:3011 [inline] __x64_sys_recvmsg+0xeb/0x160 net/socket.c:3011 x64_sys_call+0x1319/0x1ca0 arch/x86/include/generated/asm/syscalls_64.h:48 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline] do_syscall_64+0xde/0x3d0 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe+0x77/0x7f value changed: 0x0000006b -> 0x00000000 Reported by Kernel Concurrency Sanitizer on: CPU: 0 UID: 0 PID: 2620 Comm: syz.2.33 Not tainted 7.2.0-g39d4f32c5d53 #76 PREEMPT(full) Hardware name: QEMU Ubuntu 26.04 PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014 do_recvmmsg() and getsockopt(SO_ERROR) call sock_error() without the socket lock. sock_error() clears sk_err with xchg(), which races with unmarked loads of the same field. KCSAN reported the unmarked peek in tcp_recv_should_stop(). Annotate that helper and the other send-side peeks with READ_ONCE(). On the no-data recv and splice paths, if (sk_err) followed by sock_error() and an unconditional break can return 0 after another thread consumes the error. Call sock_error() once and only stop when it returns a non-zero error. tcp_bpf_sendmsg() read sk_err twice; fold those unmarked loads into one READ_ONCE() and use that value as the returned errno. The field is still not consumed. MPTCP is handled in the next patch. Suggested-by: Jiayuan Chen <jiayuan.chen@linux.dev> Link: https://lore.kernel.org/netdev/8bbee583-6f21-4817-bfeb-2d60057380a3@linux.dev/ Reported-by: Matthieu Baerts (NGI0) <matttbe@kernel.org> Closes: https://github.com/multipath-tcp/mptcp_net-next/issues/632 Signed-off-by: Quanye Yang <quanyeyang@proton.me> Reviewed-by: Eric Dumazet <edumazet@kernel.org> Link: https://patch.msgid.link/20260925-mptcp-sk-err-net-v5-1-0cac04d6ea48@proton.me Signed-off-by: Paolo Abeni <pabeni@redhat.com>
30 hourstty: fix saved termios reset raceJohan Hovold
Resetting saved termios state on device registration is needed where a minor number can be reused for an entirely different device and where the old settings may prevent the port from even being opened (e.g. when CLOCAL is not set). Not all TTY drivers guarantee that the minor number is no longer in use when registering devices however, something which can lead to a use-after-free when closing a TTY (and saving its termios) races with re-registration. Add a new TTY_DRIVER_RESET_SAVED_TERMIOS flag to request that any saved termios state is reset on registration and only set it for drivers that make sure that the minor number is no longer in use. Fixes: 93857edd9829 ("tty: reset termios state on device registration") Reported-by: Chengfeng Ye <nicoyip.dev@gmail.com> Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com Cc: stable@kernel.org # 4.12 Signed-off-by: Johan Hovold <johan@kernel.org> Link: https://patch.msgid.link/20260930131845.1809256-1-johan@kernel.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
30 hoursmedia: mali-c55: add padding to mali_c55_params_ccm structureArnd Bergmann
The newly added structure has extra padding on the on some architectures, which triggers a pedantic uapi check: ./usr/include/linux/media/arm/mali-c55-config.h:807:1: error: padding struct size to alignment boundary with 2 bytes [-Werror=padded] Add explicit padding here to avoid risking information leaks and incompatibilities between architectures. Fixes: bb401df68c06 ("media: mali-c55: Add support for CCM") Cc: stable@vger.kernel.org Signed-off-by: Arnd Bergmann <arnd@arndb.de> Reviewed-by: Vincenzo Frascino <vincenzo.frascino@arm.com> Reviewed-by: Linus Walleij <linusw@kernel.org> Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com> Signed-off-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com> Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
30 hoursMerge branch 'devel' into for-nextLinus Walleij
30 hoursMerge branch 'for-next/vexpress/fixes', tags 'scmi-updates-7.4' and ↵Sudeep Holla
'juno-updates-7.4' of git://git.kernel.org/pub/scm/linux/kernel/git/sudeep.holla/linux Arm SCMI updates for v7.4 Add an ACPI PCC transport for SCMI. The core now propagates firmware nodes and supports protocol-specific channel lookup, while the new transport parses and validates ACPI _DSD mappings for shared and dedicated command and notification channels. ACPI protocol devices can be initialized without device tree child nodes. Enable SCMI protocol driver module autoloading by generating stable SCMI module aliases and creating standard protocol devices before their drivers register. Fix delayed-response completion and raw transfer reuse races, and release a raw transfer on an error path. Also consolidate reset domain information queries and use string helpers in SCMI trace events. Arm FVP/Juno device tree updates for v7.4 Three updates to the FVP RevC device tree: - Add the missing CPU topology information by describing the eight CPUs as two clusters of four in cpu-map. - Add the EL2 Generic Watchdog control and refresh frames. - Add a 4 GiB PCIe memory window, matching the range advertised by the ACPI description. * tag 'scmi-updates-7.4' of git://git.kernel.org/pub/scm/linux/kernel/git/sudeep.holla/linux: firmware: arm_scmi: Always create devices for standard protocols firmware: arm_scmi: Add SCMI device table alias support firmware: arm_scmi: Validate PCC shared memory signature firmware: arm_scmi: Initialise known ACPI protocol devices and channels firmware: arm_scmi: Add ACPI PCC transport firmware: arm_scmi: Refactor protocol device creation logic firmware: arm_scmi: Pass protocol ID to transport chan_available() firmware: arm_scmi: Fall back to ACPI HID when "compatible" is absent firmware: arm_scmi: Convert OF-only paths to generic fwnode in SCMI core firmware: arm_scmi: Extend transport driver macro to support ACPI firmware: arm_scmi: Set generated device fwnode with platform helpers firmware: arm_scmi: Merge scmi_reset_proto_ops.name_get() and .latency_get() firmware: arm_scmi: Fix error path leak in scmi_raw_message_send() firmware: arm_scmi: Don't reuse raw xfers with async_done still armed firmware: arm_scmi: Protect xfer->async_done with xfer->lock include: trace: Use string helpers in msg_dump trace events * tag 'juno-updates-7.4' of git://git.kernel.org/pub/scm/linux/kernel/git/sudeep.holla/linux: arm64: dts: fvp: Add additional PCIe memory region arm64: dts: fvp: Add EL2 Generic watchdog arm64: dts: fvp: Add cpu-map property * 'for-next/vexpress/fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/sudeep.holla/linux: ARM: vexpress: fix device_node refcount leak in vexpress_smp_dt_prepare_cpus() ARM: vexpress: fix device_node refcount leak in vexpress_flags_set()
30 hoursllc: strip the leftovers of the llc2 removalJakub Kicinski
Nothing in tree registers the type 1 / type 2 packet handlers or the station handler any more, and nothing looks at the socket hashes hanging off struct llc_sap. The two SAPs opened in tree - SNAP, and STP for the bridge's BPDUs and GARP's PDUs - receive through the per-SAP rcv_func(), so llc_rcv() boils down to a SAP lookup and a call. llc_sap_list becomes static and five exports go away with all this; the llc2 module out of tree has been reworked to open its own SAPs. Frames with a NULL DSAP used to be handed to the station handler before the SAP lookup. They take the normal path now, meaning they get dropped unless something registers SAP 0. struct llc_sap is down to 48 bytes on 64-bit from over a kilobyte, which also moves its GFP_ATOMIC allocation from kmalloc-2k to kmalloc-64. The two 64-entry socket hashes are the bulk of it, and the address it carried is now just the SAP number - nothing has read the MAC half since the socket layer left. llc_pdu.h keeps only what its remaining users need, plus LLC_PDU_RSP to document the one argument which can take it. That takes out the type 2 (I and S format, FRMR) definitions, the XID and TEST builders with their constants - the kernel neither sends nor answers either any more - the SAP address defines, the field accessors, and the prototypes of the llc_pdu.c helpers which went out of tree with the rest of LLC2. With the I and S formats gone llc_pdu_header_init() has one PDU type left, so drop the argument. Signed-off-by: Jakub Kicinski <kuba@kernel.org> Link: https://patch.msgid.link/20260928190800.2521749-3-kuba@kernel.org Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org> Signed-off-by: Paolo Abeni <pabeni@redhat.com>
30 hoursllc: move the type 2 sockets out of treeJakub Kicinski
802.2 LLC is only used in tree by protocols which need the connectionless type 1 subset: STP, which carries the bridge's BPDUs, GARP, which sends its own UI PDUs, and SNAP. The llc2 module on top of the core - the type 2 connection state machine, the type 1 SAP state machine, the station component and the PF_LLC socket family - has no in-kernel users and nobody who can test it; what we get instead is a slow trickle of drive-by fixes. There was a recent patch from Ernestas Kulik indicating potential real life use, but it was new/experimental and that person is not responding to off-list pings. Let LLC2 follow AX.25, hamradio and AppleTalk out of the Linux tree. We will maintain the code at: github.com/linux-netdev/mod-orphan for anyone interested in playing with it. PF_LLC goes in full, both the class two SOCK_STREAM and the class one SOCK_DGRAM half, and so do /proc/net/llc/ and /proc/sys/net/llc/. Note that the kernel also stops answering XID and TEST commands, addressed to a SAP or to the station - those are type 1, but they lived in the module, and they got answered whether or not any socket was open. Nothing in tree asks for them; what the core keeps is SAP registration and the UI path the in-tree users need. Retain the uAPI for now, like we did for AppleTalk. Only the socket ABI half of it is vestigial: STP, GARP, the bridge and openvswitch use the SAP numbers it defines. Cleaning up what the core no longer needs follows in the next patch. Signed-off-by: Jakub Kicinski <kuba@kernel.org> Link: https://patch.msgid.link/20260928190800.2521749-2-kuba@kernel.org Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org> Signed-off-by: Paolo Abeni <pabeni@redhat.com>
31 hoursdrm/fbdev: Move fbdev helpers into client libraryThomas Zimmermann
DRM's fbdev helpers are for the fbdev-emulation clients. Move them into the client-library module. Fix include statements throughout DRM drivers. While at it, rename the files from drm_fb_helper to drm_fbdev_helper. The old name was too reminiscent of DRM's framebuffer code. The GEM support code for fbdev remains part of DRM's memory managers. v4: - fix the depedendencies from v3 v3: - remove obsolete dependencies from Kconfig v2: - update armada und docs Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de> Reviewed-by: Alex Deucher <alexander.deucher@amd.com> Acked-by: Jani Nikula <jani.nikula@intel.com> Reviewed-by: Javier Martinez Canillas <javierm@redhat.com> Link: https://patch.msgid.link/20260928080323.23909-3-tzimmermann@suse.de
32 hoursMerge https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm.git ↵David Hildenbrand (Arm)
mm-unstable into for-next Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
32 hoursMerge https://git.kernel.org/pub/scm/linux/kernel/git/mm/memblock.git ↵David Hildenbrand (Arm)
for-next into for-next Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
32 hoursMerge https://git.kernel.org/pub/scm/linux/kernel/git/mm/core.git for-next ↵David Hildenbrand (Arm)
into for-next Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
34 hoursdrm/gpusvm: Add devmem callback to get_pagesHimal Prasad Ghimiray
Add an optional drm_gpusvm_ctx.devmem_fn, invoked for each device-memory allocation backing the range's faulted pages. It runs under the notifier lock and independently of the DMA map, so it also fires with no_dma_map. Adjacent pages of one allocation are coalesced, so the callback must be idempotent. v2 Reset last to NULL for non-devmem pages(Sashiko/Matt) v3 Run drm_gpusvm_pages_valid_unlocked() on the map_dma path even when devmem_fn is set, so an invalidated range's stale inline mapping is reset. Suggested-by: Matthew Brost <matthew.brost@intel.com> Reviewed-by: Matthew Brost <matthew.brost@intel.com> Link: https://patch.msgid.link/20261001033602.3166274-8-himal.prasad.ghimiray@intel.com Signed-off-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
34 hoursdrm/pagemap: Add helper to access backing devmem allocationHimal Prasad Ghimiray
drm_pagemap_zdd is private, so add drm_pagemap_page_to_devmem() to let callers get the drm_pagemap_devmem backing a device-private/coherent page. Add a NULL stub for !CONFIG_ZONE_DEVICE. Cc: Matthew Brost <matthew.brost@intel.com> Reviewed-by: Matthew Brost <matthew.brost@intel.com> Link: https://patch.msgid.link/20261001033602.3166274-7-himal.prasad.ghimiray@intel.com Signed-off-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
37 hoursMerge tag 'topic/pci-vgaarb-rework-2026-10-01' of ↵Dave Airlie
https://gitlab.freedesktop.org/drm/kernel into drm-next pci/vgaarb rework for drm/vfio This reworks the vgaarb API to be a bit more sane. Signed-off-by: Dave Airlie <airlied@redhat.com> From: Dave Airlie <airlied@gmail.com> Link: https://patch.msgid.link/CAPM=9tzd3LteJG-Au=na-_X5Rff4tacFZ3X_cp5g0bCcQkV_jA@mail.gmail.com
38 hoursnet: mana: Add support for CDX device ID 0x00C2Manish Awasthi
Add the CDX transport as mana_cdx.ko for device ID 0x00C2, using the shared gdma_core.ko. Allocate interrupts at probe, limit queues to available vectors, use 32-bit DMA, and keep CDX auxiliary devices separate from PCI. Signed-off-by: Manish Awasthi <mawasthi@linux.microsoft.com> Reviewed-by: Simon Horman <horms@kernel.org> Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com> Link: https://patch.msgid.link/20260924173054.589291-5-mawasthi@linux.microsoft.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
38 hoursnet: mana: Build the PCI transport as a separate moduleManish Awasthi
Build the shared GDMA and Ethernet code as gdma_core.ko, selected by MICROSOFT_GDMA_CORE. Build the PCI transport separately as mana.ko and export the required core symbols. Preserve the PCI module name, device table, and mana.eth/mana.rdma auxiliary-device names. Each transport registers its own bus driver. Signed-off-by: Manish Awasthi <mawasthi@linux.microsoft.com> Reviewed-by: Simon Horman <horms@kernel.org> Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com> Link: https://patch.msgid.link/20260924173054.589291-4-mawasthi@linux.microsoft.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
38 hoursnet: mana: Move PCI transport code into gdma_pci.cManish Awasthi
Move PCI transport code and driver callbacks from gdma_main.c into gdma_pci.c. Keep shared IRQ bookkeeping in the core and update build wiring. Signed-off-by: Manish Awasthi <mawasthi@linux.microsoft.com> Reviewed-by: Simon Horman <horms@kernel.org> Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com> Link: https://patch.msgid.link/20260924173054.589291-3-mawasthi@linux.microsoft.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
38 hoursnet: mana: Introduce gdma_bus_ops for bus-specific operationsManish Awasthi
Introduce per-device gdma_bus_ops for interrupt allocation, IRQ lookup, reset, servicing, and bus-specific capabilities. Route the shared GDMA code through these callbacks and provide the PCI implementation. Move common device bring-up and teardown into mana_gd_setup() and mana_gd_cleanup(), including hardware-channel initialization, device enumeration, interrupt-pool sizing, and servicing workqueue management. Record the vPort count for transport-specific queue sizing and keep shared IRQ context bookkeeping in the core. This prepares the driver for additional bus transports without duplicating the core or adding configuration checks throughout it. Signed-off-by: Manish Awasthi <mawasthi@linux.microsoft.com> Reviewed-by: Simon Horman <horms@kernel.org> Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com> Link: https://patch.msgid.link/20260924173054.589291-2-mawasthi@linux.microsoft.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
38 hoursnet: mvneta: clear XDP pfmemalloc flag between framesLorenzo Bianconi
mvneta_swbm_add_rx_fragment() sets XDP_FLAGS_FRAGS_PF_MEMALLOC on the xdp_buff when a fragment page is a pfmemalloc one (page under memory pressure). The xdp_buff is reused for the next frame, but only the XDP_FLAGS_HAS_FRAGS bit was cleared at frame start, so the pfmemalloc bit leaked from one frame into the following ones. mvneta_swbm_build_skb() propagates the flag to skb->pfmemalloc through xdp_update_skb_frags_info(), so the skb of a subsequent fragmented frame could be wrongly marked as pfmemalloc even if none of its pages are under pressure. Clear all the xdp_buff flags in mvneta_swbm_rx_frame(), which is invoked for each new frame, instead of just the XDP_FLAGS_HAS_FRAGS bit. Fixes: ed7a58cb40bd ("net: marvell: rely on xdp_update_skb_shared_info utility routine") Reviewed-by: Simon Horman <horms@kernel.org> Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com> Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com> Link: https://patch.msgid.link/20260929-mvneta-xdp-clear-frag-fix-v4-1-1e63b25eeed8@oss.qualcomm.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
38 hourss390/ism: Zerorize dmb at allocationAlexandra Winter
Sashiko reported [1] that 'Missing __GFP_ZERO in folio_alloc() causes uninitialized kernel memory to be exposed in the receive message buffer'. An ism dmb is receive-only, so the data is not leaked to a remote peer. In general the smc kernel module (dibs client) will only push newly received data to userspace. We still should not have uninitialized data in a receive buffer. Since commit 750afb08ca71 ("cross-tree: phase out dma_zalloc_coherent()") dma_alloc_coherent no longer required the __GFP_ZERO flag, but when commit 83781384a96b ("s390/ism: Properly fix receive message buffer allocation") switched to folio_alloc(), it should have added back the __GFP_ZERO flag. Add __GFP_ZERO flag and state in dibs.h that register_dbm() provides a zerorized buffer (dibs_lo already does). Link: https://lore.kernel.org/linux-s390/20260903143746.A5CC41F00A3A@smtp.kernel.org/ [1] Fixes: 83781384a96b ("s390/ism: Properly fix receive message buffer allocation") Signed-off-by: Alexandra Winter <wintera@linux.ibm.com> Reviewed-by: Julian Ruess <julianr@linux.ibm.com> Link: https://patch.msgid.link/20260928151420.383105-1-wintera@linux.ibm.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>