Skip to content

Merge/sound upstream 20261002 - #5963

Open
bardliao wants to merge 1596 commits into
thesofproject:topic/sof-devfrom
bardliao:merge/sound-upstream-20261002
Open

bardliao wants to merge 1596 commits into
thesofproject:topic/sof-devfrom
bardliao:merge/sound-upstream-20261002

Conversation

@bardliao

@bardliao bardliao commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Upstream merge

torvalds and others added 30 commits September 24, 2026 10:53
…rnel/git/mic/linux

Pull Landlock fixes from Mickaël Salaün:
 "This mainly fixes the Landlock tracepoint support merged this cycle so
  that denial and rule events report the intended policy context,
  whether through tracefs or BTF-visible callbacks.

  The size of this all is mainly from propagating the corrected contract
  through event definitions and producers, adding new tests for the
  reported context, and updating the documentation.

  Also improve annotation and fix a GCC 16 build warning"

* tag 'landlock-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/mic/linux:
  landlock: Widen ruleset versions to 64 bits
  landlock: Add counted_by in landlock_domain
  landlock: Fix tracepoint contract documentation
  selftests/landlock: Test network denial context
  selftests/landlock: Test filesystem denial blockers
  landlock: Report the effective signal number
  landlock: Report the actual ptrace tracer
  landlock: Fix network denial trace context
  landlock: Fix rule tracepoint context
  landlock: Fix filesystem denial blocker reporting
  landlock: Fix tracepoint fixed-width type names
  landlock: Work around gcc-16 -Wuninitialized warning
The device has a strict requirement that the minimum MSS
(gso_size) for TSO/GSO packets must be at least 88 bytes. If a packet
below this threshold is pushed to the hardware, it can cause
hardware to silently drop the packet, leading to increased latency
and retransmissions.

Currently, this is validated too late in the transmit pipeline
(gve_prep_tso), leading to silent drops.

Fix this by moving the validation into the .ndo_features_check
callback (gve_features_check_dqo). If we detect a GSO packet with
a gso_size smaller than GVE_TX_MIN_TSO_MSS_DQO, we clear the GSO
feature flags for this packet.

Fixes: a57e5de ("gve: DQO: Add TX path")
Signed-off-by: Eddie Phillips <eddiephillips@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260924004252.1196328-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
gve_prep_tso() notes that the device requires the MSS to be <= 9728,
but does not enforce it, assuming the 9K MTU enforced by the hypervisor
and the 64KB limit on TSO sizes are enough.

This does not hold for packets that were not generated locally.
A guest behind a tap, or any packet socket user, can provide an
arbitrary gso_size in virtio_net_hdr. Layer 2 forwarding does not check
the MTU for GSO packets (is_skb_forwardable()), and gso_features_check()
only bounds skb->len and gso_segs, never gso_size.

Such a packet reaches gve_tx_fill_tso_ctx_desc(), which puts gso_size
into the mss field of the TSO context descriptor. This field is 14 bits
wide, so a gso_size of 16384 is silently turned into an MSS of zero.

Drop these packets from gve_prep_tso(), and make sure that
gve_features_check_dqo() leaves their GSO bits alone: skb_segment()
splits at gso_size regardless of the MTU, so falling back to software
segmentation would give the device non TSO packets bigger than the
9728 bytes it supports.

Note that the device can still be given oversized non TSO packets when
the stack segments in software for other reasons, for instance after
TSO has been disabled with ethtool. This is a generic issue, because
the MTU check is skipped for GSO packets in the forwarding path, and
is addressed separately.

Fixes: a57e5de ("gve: DQO: Add TX path")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260924004252.1196328-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Eric Dumazet says:

====================
gve: DQO: fix handling of out of range TSO MSS

The DQO TX path assumes that the MSS of a TSO packet is within the
range supported by the device, [88, 9728].

This holds for locally generated traffic, but not for packets coming
from a tap or from a packet socket: virtio_net_hdr_to_skb() takes
gso_size from user space and only enforces a minimum, layer 2
forwarding does not check the MTU of GSO packets, and
gso_features_check() bounds skb->len and gso_segs but never gso_size.

Patch 1, from Eddie Phillips, deals with the lower bound. It moves the
existing test out of gve_prep_tso() into gve_features_check_dqo(), so
that these packets are segmented in software instead of being dropped.

Patch 2 deals with the upper bound, which is currently not checked at
all. gve_tx_fill_tso_ctx_desc() stores gso_size into a 14 bits wide
field, so that an MSS of 16384 silently becomes zero. Falling back to
software segmentation is not an option here, because skb_segment()
splits at gso_size regardless of the MTU, and would only replace an
invalid TSO packet by non TSO packets larger than the 9728 bytes the
device supports. These packets are dropped instead.

As noted in patch 2, oversized non TSO packets can still reach the
device whenever the stack segments in software. This is not specific
to gve and is better fixed in the core, so a patch for
__is_skb_forwardable() will be sent separately for net-next.
====================

Link: https://patch.msgid.link/20260924004252.1196328-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
llc_alloc_frame() reserves link-layer headroom using the device type.
This is insufficient for stacked Ethernet devices such as VLAN devices,
where vlan_dev_hard_header() pushes a VLAN header before the lower
device's Ethernet header. An LLC response on such a device can
therefore underflow skb headroom in eth_header().

Use LL_RESERVED_SPACE() to account for the device's actual required
headroom while preserving the existing LLC device-type check.

Fixes: bf9ae53 ("llc: use dev_hard_header")
Cc: stable@vger.kernel.org
Reported-by: VEGA <vega@nebusec.ai>
Signed-off-by: Zixuan Chai <petalzu987@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924012613.2533934-1-weir@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
In llc_conn_ac_resend_i_xxx_x_set_0_or_send_rr(), if llc_mac_hdr_init()
fails, kfree_skb(skb) is called instead of kfree_skb(nskb). This leaks
the newly allocated nskb, reads from the freed skb via LLC_I_GET_NR(pdu),
and double-frees skb when llc_conn_state_process() drops its reference.

In llc_sap_action_send_xid_r() and llc_sap_action_send_test_r(), nskb is
leaked if llc_mac_hdr_init() returns an error.

Free nskb in all three error paths.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
If llc_mac_hdr_init() fails (for instance if the port device type does
not support LLC or dev_hard_header() fails), br_send_bpdu() should drop
the skb instead of resetting the mac header to the LLC payload and
transmitting a malformed frame.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Nikolay Aleksandrov <razor@blackwall.org>
Cc: Ido Schimmel <idosch@nvidia.com>
Cc: bridge@lists.linux.dev
Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20260924082951.1599377-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
__teql_resolve() declares an inner 'int err;' inside the
'if (neigh_event_send(n, skb_res) == 0)' block, shadowing the outer
'int err = 0;'. As a result, a negative return from dev_hard_header()
is written to the inner variable and __teql_resolve() still returns 0.

Remove the shadowed variable and set the outer err to -EINVAL when
dev_hard_header() returns a negative error.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Closes: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Cc: Jiri Pirko <jiri@resnulli.us>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Callers that only reserve ETH_HLEN or less (such as llc_alloc_frame()),
or skbs allocated before dynamic device/headroom changes (e.g. toggling
VLAN_FLAG_REORDER_HDR or bonding/team switching slaves), can reach
vlan_dev_hard_header() with insufficient headroom and trigger
skb_under_panic().

Use skb_cow_head() in vlan_dev_hard_header() when VLAN_FLAG_REORDER_HDR
is not set to ensure sufficient headroom for the VLAN header(s) and the
underlying device hard header.

Use READ_ONCE() to read dev->hard_header_len and dev->needed_headroom as
they can be updated concurrently under RTNL (e.g. in
vlan_transfer_features()) while vlan_dev_hard_header() runs locklessly on
the transmit path. Also avoid LL_RESERVED_SPACE(dev) here so that the
extra HH_DATA_MOD alignment padding does not trigger unnecessary
pskb_expand_head() reallocations on inner stacked VLAN devices after the
outer VLAN header has been pushed.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Zixuan Chai <petalzu987@gmail.com>
Closes: https://lore.kernel.org/netdev/cover.1789987105.git.petalzu987@gmail.com/
Link: https://lore.kernel.org/netdev/179022851638.2160803.1808206741379444999@kernel.org/
Cc: Hangbin Liu <liuhangbin@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260924082951.1599377-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Eric Dumazet says:

====================
vlan: ensure sufficient headroom in vlan_dev_hard_header()

Callers that only reserve ETH_HLEN or less, or skbs allocated before
dynamic device/headroom changes (such as toggling VLAN_FLAG_REORDER_HDR
or bonding/team switching slaves), can reach vlan_dev_hard_header() with
insufficient headroom and trigger skb_under_panic().

When vlan_dev_hard_header() returns -ENOMEM upon skb_cow_head() failure,
a few callers of dev_hard_header() / llc_mac_hdr_init() had pre-existing
error-handling bugs:
====================

Link: https://patch.msgid.link/20260924082951.1599377-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
tcp_write_collapse_fence() sets TCP_SKB_CB(skb)->eor = 1 on
tcp_write_queue_tail(sk) to prevent skbs queued after a switch to
device encryption from being collapsed into earlier skbs.

The fence is a no-op if all earlier data has already been transmitted
when the switch happens: sk->sk_write_queue is empty. The not yet
acknowledged earlier skbs wait in sk->tcp_rtx_queue with eor 0.

On a subsequent retransmit or SACK shift, tcp_retrans_try_collapse() or
tcp_shift_skb_data() can then merge an skb queued after the switch into
one queued before it.

Both users of the fence are affected:

- psp: devices only encrypt skbs with skb->decrypted set. The merged skb
  keeps decrypted = 0 from the earlier skb, so merged data sent after
  psp_sock_assoc_set_tx() is retransmitted in cleartext.

- tls device offload: the merged skb straddles the start marker set in
  tls_set_device_offload(). The software fallback (fill_sg_in() returns
  -EINVAL) and the mlx5, nfp and funeth drivers cannot handle such an
  skb and drop it. Every retransmit rebuilds the same skb, so the
  connection stalls.

Fix this in two places, for defense in depth:

1. Fall back to tcp_rtx_queue_tail(sk) in tcp_write_collapse_fence()
   when tcp_write_queue_tail(sk) is NULL.

2. Check !skb_cmp_decrypted(to, from) in tcp_skb_can_collapse(), as
   tcp_skb_can_collapse_rx() does on receive. skb_shift(), which both
   collapse paths call, already has a DEBUG_NET_WARN_ON_ONCE() for this
   condition.

Fixes: e8f6979 ("net/tls: Add generic NIC offload infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Willem de Bruijn <willemb@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Daniel Zahka <daniel.zahka@gmail.com>
Link: https://patch.msgid.link/20260924154427.953800-1-willemdebruijn.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
rt1320_volatile_register() marks the SRAM ranges 0x10000000-0x10008fff
and 0x1000c000-0x1000dfff as volatile, but regmap only honors that flag
for a readable register and these ranges were missing from
 rt1320_readable_register(). They were therefore cached at probe and
replayed over SoundWire on every runtime resume, delaying the
first PCM open after autosuspend by about a second.

Make the ranges readable so the volatile flag takes effect and the SRAM
is no longer cached. Exclude 0x1000d000-0x1000d7ff from both callbacks,
since rt1320_rae_load() deliberately caches that tuning-tool window.

Signed-off-by: Jack Yu <jack.yu@realtek.com>
Link: https://patch.msgid.link/20260924020510.3551163-1-jack.yu@realtek.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Add new dai ids entries for Qualcomm Audio Interface (QAIF) AIF MI2S
and TDM audio lines.

Co-developed-by: Harendra Gautam <harendra.gautam@oss.qualcomm.com>
Signed-off-by: Harendra Gautam <harendra.gautam@oss.qualcomm.com>
Signed-off-by: Mohammad Rafi Shaik <mohammad.rafi.shaik@oss.qualcomm.com>
Reviewed-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Tested-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Link: https://patch.msgid.link/20260918-qaif_dai_id_support-v1-1-ed863c0e5e45@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
… dais

Add support for Qualcomm Audio Interface (QAIF) AIF MI2S and TDM dais in
the dai-driver, these dais are used in Shikra, Hawi and Nord based
Qualcomm platform devices.

Signed-off-by: Mohammad Rafi Shaik <mohammad.rafi.shaik@oss.qualcomm.com>
Reviewed-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Tested-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Reviewed-by: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
Link: https://patch.msgid.link/20260918-qaif_dai_id_support-v1-2-ed863c0e5e45@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Handle AIF MI2S and TDM DAI IDs in the SC8280XP machine driver
and extend LPASS_MAX_PORT to accommodate the additional audio
interfaces.

Signed-off-by: Mohammad Rafi Shaik <mohammad.rafi.shaik@oss.qualcomm.com>
Reviewed-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Tested-by: Prasad Kumpatla <prasad.kumpatla@oss.qualcomm.com>
Reviewed-by: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
Link: https://patch.msgid.link/20260918-qaif_dai_id_support-v1-3-ed863c0e5e45@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Mohammad Rafi Shaik <mohammad.rafi.shaik@oss.qualcomm.com> says:

Add support for Qualcomm Audio Interface (QAIF) AIF MI2S and TDM DAI
id's across the Qualcomm audio stack.

The new DAI IDs are required for platforms such as Shikra, Hawi, and Nord,
where QAIF audio interfaces are used to connect external audio devices.

Link: https://patch.msgid.link/20260918-qaif_dai_id_support-v1-0-ed863c0e5e45@oss.qualcomm.com
sst_acpi_probe() registers platform devices for the SST platform and
machine board using platform_device_register_data(), but does not
unregister them when later probe steps fail.

Fixes: caf94ed ("ASoC: Intel: bytcr_rt5640: fixup DAI codec_name with HID")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260924134932.1590967-1-lgs201920130244@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
…git/netdev/net

Pull networking fixes from Jakub Kicinski:
 "Including fixes from Bluetooth, NFC and Netfilter.

  Every week in this release is record-setting for number of posted
  patches. It doesn't seem like we're creating any regressions with all
  these fixes, three 'Fixes' tags here point to 7.2 commits but none are
  true regression fixes. We're trying to keep the count down,
  nonetheless.

  Previous releases - regressions:

   - net: don't require the hwtstamp NDOs when a PHY provides
     timestamping

   - ipv6: fix dst leak for uncached routes

   - vrf: stop corrupting skb->csum when capturing CHECKSUM_COMPLETE
     packets

  Previous releases - always broken:

   - packet: use ubuf_info completion for TX_RING packets

   - arp: terminate device name before lookup

   - ipv6: do not let ipv6_find_hdr() return an offset past the packet
     end

   - udp: remove a disconnected socket from the 4-tuple hash table

   - sctp: discard the rest of the packet on a stale-cookie error

   - eth: mlx5: Bridge, fix remaining switchdev ownership gaps on merged
     eswitch"

[ And lots of other random network driver fixes ]

* tag 'net-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (189 commits)
  tcp: prevent collapsing skbs across boundary in rtx queue
  vlan: ensure sufficient headroom in vlan_dev_hard_header()
  net/sched: sch_teql: fix shadowed err in __teql_resolve()
  bridge: check llc_mac_hdr_init() return value in br_send_bpdu()
  llc: fix skb UAF and leaks on llc_mac_hdr_init() failure
  llc: reserve device headroom for allocated frames
  gve: DQO: reject TSO packets with an out of range MSS
  gve: fix TX drop when GSO MSS is too small for hw
  gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO
  net: flush skb_defer_nodes in dev_cpu_dead()
  net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails
  af_packet: fix integer overflow in prb_calc_retire_blk_tmo()
  tipc: Fix a data race on mon->peer_cnt in mon_timeout()
  net: phy: intel-xway: workaround 100BASE-TX Link-Up issue
  net/smc: fix UAF on lgr list traversal in smcr_port_err()
  net/rds: size a connection's path set by the transport it ends up with
  nfp: hold IPsec RX state under the XArray lock
  net: ena: fix MMIO read buffer leak on probe failure
  net: ena: fix PHC cleanup on probe failure
  net/sched: act_ct: fix helper UAF due to extensions realloc
  ...
This patch adds the codec_info and route-related settings.

Signed-off-by: Shuming Fan <shumingf@realtek.com>
Link: https://patch.msgid.link/20260924-rt766-v2-2-e0b63606a5e8@realtek.com
Signed-off-by: Mark Brown <broonie@kernel.org>
We only need to check the function_status to determine
whether the system has undergone a cold or warm reboot.

Signed-off-by: Shuming Fan <shumingf@realtek.com>
Link: https://patch.msgid.link/20260924-rt766-v2-3-e0b63606a5e8@realtek.com
Signed-off-by: Mark Brown <broonie@kernel.org>
SND_SOC_AMD_LEGACY_SDW_MACH unconditionally selects SND_SOC_TAS2783_SDW,
but that codec depends on SND_SOC_SDCA and EFI in addition to SOUNDWIRE.
An unconditional select force-enables the codec even when those
dependencies are not met, which the kernel test robot reported as unmet
direct dependencies when EFI=n:

  WARNING: unmet direct dependencies detected for SND_SOC_TAS2783_SDW
    Depends on [n]: SOUND [=y] && SND [=y] && SND_SOC [=y] &&
      SOUNDWIRE [=y] && SND_SOC_SDCA [=y] && EFI [=n]
    Selected by [y]:
    - SND_SOC_AMD_LEGACY_SDW_MACH [=y] && ...

The other SoundWire codecs selected by this machine driver only depend
on SOUNDWIRE, which the driver already depends on, so they select
cleanly.  SND_SOC_TAS2783_SDW is the only one that additionally needs
the SDCA core and EFI (it reads speaker calibration data from EFI
variables).

SND_SOC_SDCA cannot simply be selected here, as that introduces a
recursive Kconfig dependency (SOUNDWIRE depends on SND_SOC_SDCA_OPTIONAL,
whose default pulls in SND_SOC_SDCA), and EFI is a platform feature that
must not be selected by a driver.  Instead, guard the select with the
missing dependencies so the codec is only (and always) built when they
are satisfied:

  select SND_SOC_TAS2783_SDW if SND_SOC_SDCA && EFI

This keeps the TAS2783 SoundWire codec built together with the machine
driver on platforms that can use it, while avoiding the unmet dependency
when SND_SOC_SDCA or EFI is disabled.

Fixes: 2811499 ("ASoC: amd: acp: enable TAS2783 and add RT712-VB SoundWire machine")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609182147.gfofWIXW-lkp@intel.com/
Signed-off-by: Syed Saba Kareem <Syed.SabaKareem@amd.com>
Link: https://patch.msgid.link/20260924124205.3376083-1-syed.sabakareem@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
rt712_sdca_dmic_set_gain_get() and rt712_sdca_dmic_set_gain_put() take
the component drvdata as struct rt712_sdca_priv, but this driver stores
a struct rt712_sdca_dmic_priv.

regmap and mbq_regmap are at the same offsets in both structs, so the
register accesses work. slave is not: rt712_sdca_priv has dmic_component
in front of it, so its slave overlays rt712_sdca_dmic_priv's params,
which this driver never writes. When regmap_write() fails in the put
handler, dev_err() is called with &NULL->dev (RSI below):

  rt712-sdca-dmic sdw:0:3:025d:1713:01: Defer on undeferrable control: 40800f13
  BUG: kernel NULL pointer dereference, address: 0000000000000058
  RIP: 0010:__dev_printk+0x10/0x70
  RDX: ffffcdac45f83cd0 RSI: 0000000000000008 RDI: ffffffffa09cb5cb
  Call Trace:
   _dev_err+0x7f/0x99
   rt712_sdca_dmic_set_gain_put.cold+0x20/0x25 [snd_soc_rt712_sdca_dmic]
   snd_ctl_elem_write+0x19a/0x1f0 [snd]
   snd_ctl_ioctl+0x658/0x8a0 [snd]

Seen on a Dell Precision 5690 running 7.2.5-200.fc44, with alsactl
writing the control during boot. Compile-tested only.

Fixes: 63a5112 ("ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology")
Closes: https://bugzilla.redhat.com/show_bug.cgi?id=2532834
Cc: stable@vger.kernel.org
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Link: https://patch.msgid.link/20260920024232.710189-1-junjie.cao@intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
The ES8316 driver supports the everest,jack-detect-inverted property to
account for boards which invert the codec jack-detect signal. However,
the property is not described by the binding, so a valid user of the
driver fails schema validation because the binding rejects unknown
properties.

Document the flag so boards can describe the jack-detect polarity used
by their wiring.

Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Hongyang Zhao <hongyang.zhao@thundersoft.com>
Link: https://patch.msgid.link/20260904-rubikpi-next-20260605-v3-1-f49146d85af3@thundersoft.com
Signed-off-by: Mark Brown <broonie@kernel.org>
The QCS6490-based Thundercomm RubikPi 3 routes primary MI2S to an
external ES8316 headset codec and quaternary MI2S to the LT9611 HDMI
bridge. This requires board-specific DAI clocking and jack setup in the
sc8280xp machine driver.

The existing QCM6490 and QCS6490 compatibles select machine data for
boards using different codec and audio routing arrangements, so they
cannot be used as compatible fallbacks for RubikPi 3.

Add a dedicated compatible to select the RubikPi 3 machine data.

Signed-off-by: Hongyang Zhao <hongyang.zhao@thundersoft.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://patch.msgid.link/20260904-rubikpi-next-20260605-v3-2-f49146d85af3@thundersoft.com
Signed-off-by: Mark Brown <broonie@kernel.org>
qcom_snd_wcd_jack_setup() combines creation of the card-level headset
jack with the WCD-specific operation of attaching jack detection to
codecs on the TX codec DMA links. External codecs connected over MI2S
also provide component jack detection, but cannot use the WCD-specific
DAI filtering.

Factor the common jack allocation, DAPM pin registration and headset
button mappings into a private initializer. Reuse it from the existing
WCD path and add a generic setup helper which attaches the jack to every
codec component in a runtime.

Treat -ENOTSUPP as a no-op because snd_soc_component_set_jack() uses it
for components which do not provide a set_jack callback.

Add a matching cleanup helper so machine drivers can detach component
jack detection when the DAI link exits. The WCD setup behavior remains
unchanged.

Signed-off-by: Hongyang Zhao <hongyang.zhao@thundersoft.com>
Link: https://patch.msgid.link/20260904-rubikpi-next-20260605-v3-3-f49146d85af3@thundersoft.com
Signed-off-by: Mark Brown <broonie@kernel.org>
The board data currently applies codec sysclk, MI2S clock and jack setup
policy to every backend DAI on a sound card. This cannot describe a card
whose codecs have different clock requirements on different MI2S
interfaces.

Add an optional per-DAI configuration table indexed by CPU DAI ID. Each
entry can override the MCLK rate, CPU MCLK and BCLK programming, codec
sysclk setup and jack setup path. Keep the codec DAI format card-wide.

Cards without a matching per-DAI entry continue to use the existing
card-wide settings, keeping all current board data unchanged.

Signed-off-by: Hongyang Zhao <hongyang.zhao@thundersoft.com>
Link: https://patch.msgid.link/20260904-rubikpi-next-20260605-v3-4-f49146d85af3@thundersoft.com
Signed-off-by: Mark Brown <broonie@kernel.org>
RubikPi 3 connects an ES8316 codec to primary MI2S for headset playback
and capture, and an LT9611 bridge to quaternary MI2S for HDMI audio.

Add per-DAI data for the primary playback and capture links. Configure
the codecs for I2S with normal clock polarity and as bit and frame clock
consumers. Program the primary MI2S BCLK, configure the ES8316 for its
fixed 19.2 MHz MCLK and enable component jack detection on the playback
link.

The HDMI link inherits the card-wide I2S format but does not request
codec sysclk programming because the LT9611 codec DAI does not implement
set_sysclk().

Select this configuration through the RubikPi 3 sound-card compatible.

Signed-off-by: Hongyang Zhao <hongyang.zhao@thundersoft.com>
Link: https://patch.msgid.link/20260904-rubikpi-next-20260605-v3-5-f49146d85af3@thundersoft.com
Signed-off-by: Mark Brown <broonie@kernel.org>
qcom_geni_i2c_conf() writes a hardcoded 0 to SE_GENI_CLK_SEL, which
selects an index from the hardware clock performance table. This always
picks the first table entry regardless of the actual source clock
configuration. On platforms where the matching entry is not at index 0,
the wrong source clock divider is active and the I2C bus runs at an
incorrect frequency.

Use geni_se_clk_freq_match() in geni_i2c_clk_map_idx() to find the
performance table index for the source clock (32 MHz or 19.2 MHz). Store
the resolved index in a new clk_idx field in geni_i2c_dev and write it
to SE_GENI_CLK_SEL instead of the hardcoded 0.

Fixes: 37692de ("i2c: i2c-qcom-geni: Add bus driver for the Qualcomm GENI I2C controller")
Signed-off-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Cc: <stable@vger.kernel.org> # v4.19+
Reviewed-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260921-i2c-fix-se-clk-conf-v2-1-8b5537ceff2d@oss.qualcomm.com
…linux/kernel/git/tj/cgroup

Pull cgroup fixes from Tejun Heo:

 - With local event accounting, a fork rejected by the pids controller
   updated pids.events without notifying its pollers

 - A cgroup selftest failed to compile with fortification enabled
   because an O_TMPFILE open lacked its mode argument

* tag 'cgroup-for-7.3-rc4-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup:
  cgroup/pids: Restore pids.events notifications in local mode
  selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode
…cm/linux/kernel/git/tj/sched_ext

Pull sched_ext fixes from Tejun Heo:

 - A task reenqueued while its dispatch was still completing had its
   queued state clobbered by the dispatcher, dropping every later
   dispatch of the task. Wait for the in-flight dispatch to settle
   first

 - A wakeup activation on another CPU marked the destination runqueue as
   mid-wakeup, stranding a pending local reenqueue. If the scheduler was
   unloaded first, the stale request pointed into freed memory that the
   next scheduler dereferenced

 - ops.dequeue() ran with the source dispatch queue's lock held, so a
   scheduler iterating that queue from the callback deadlocked the CPU

 - Schedulers with their own CPU ID mapping had no way to learn a task's
   initial CPU mask and rebuilt it themselves, which went wrong across
   sub-scheduler enable and re-home. Pass it to ops.enable()

 - A bypass dispatch event counter missed the dispatches made by the
   end-of-dispatch fallback and under-reported

 - Selftests for the dequeue locking and initial mask changes

* tag 'sched_ext-for-7.3-rc4-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext:
  sched_ext: Count SCX_EV_SUB_BYPASS_DISPATCH in the dispatch fallback
  selftests/sched_ext: Check the cmask cid-form ops.enable() receives
  sched_ext: Pass the initial cmask to cid-form ops.enable()
  selftests/sched_ext: Test that ops.dequeue() can iterate the consumed DSQ
  sched_ext: Don't run ops.dequeue() with a DSQ lock held
  sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags
  sched_ext: Wait for SCX_OPSS_DISPATCHING before reenqueueing a task
tiwai and others added 16 commits September 29, 2026 17:09
The snd_power_ref_and_wait() skips the card->shutdown check when the
card is already in D0 state and immediately returns as successful, by
assuming the all-green in D0.  This assumption makes the code after
this sync point behaving as if all power is up and ready, even though
actually it might have been already at the disconnected state.

Add the missing check of shutdown flag there for the more consistent
behavior.

Cc: stable@vger.kernel.org
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260929125346.1478631-2-tiwai@suse.de
A use-after-free can be triggered via SNDRV_CTL_IOCTL_ELEM_ADD when a
USB audio card is disconnected while an ELEM_ADD ioctl is in flight.

The reproducer parks the ioctl thread inside copy_from_user() using
userfaultfd, then tears down the USB device.  Unlike every other
ALSA control _user handler (ELEM_INFO, ELEM_READ, ELEM_WRITE, TLV_*),
snd_ctl_elem_add_user() never calls snd_power_ref_and_wait(), so the
parked thread holds no power reference.  snd_card_disconnect() therefore
cannot observe it via snd_power_sync_ref() and proceeds unimpeded:

  1. card->shutdown is set to 1
  2. device_del(&card->card_dev) drops the kobject reference on the
     parent USB interface device (card->dev = &intf->dev)
  3. The USB core drops its own reference and calls device_release(),
     freeing the struct usb_interface, including the embedded struct
     device that card->dev points to

When the userfaultfd is resolved and the thread resumes,
snd_ctl_elem_add() acquires controls_rwsem without checking
card->shutdown and calls __snd_ctl_add_replace().  Because the
reproducer pre-registered the same control, the CTL_ADD_EXCLUSIVE
path calls dev_err(card->dev, ...) on the freed USB interface:

  KASAN: slab-use-after-free Read in __dev_printk

Add a card->shutdown guard immediately after acquiring controls_rwsem
in snd_ctl_elem_add().  At that point card->shutdown is guaranteed to
be stable: snd_card_disconnect() sets it before freeing the parent
device, and it never transitions back to 0.  A thread that acquired
the lock before disconnect sees shutdown=0 and holds the write lock
through the rest of the operation, preventing concurrent disconnect
from proceeding past its own controls_rwsem-less shutdown=1 store
(which happened earlier, outside the lock) from racing with dev_err().

Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Cc: stable@vger.kernel.org
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260929125346.1478631-3-tiwai@suse.de
This patch adds complete calibration workflow support for TAS2573.

Signed-off-by: Shenghao Ding <shenghao-ding@ti.com>
Link: https://patch.msgid.link/20260915044735.1305-1-shenghao-ding@ti.com
Signed-off-by: Mark Brown <broonie@kernel.org>
The driver obtains an IRQ number from device tree but never requests an
IRQ handler for the PCM6240 device.  Removing the device must not pass
that number to free_irq().

Leave IRQ ownership to a matching request path if one is added later.

Fixes: 1324eaf ("ASoc: PCM6240: Create PCM6240 Family driver code")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260929095920.2092147-1-runyu.xiao@seu.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
The matrix of input/output channels specified in a UAC2/3 mixer unit
must fit to the upper limit 256.  Add a sanity check and returns an
error if an invalid size is detected.

Link: https://lore.kernel.org/d46fcac6-bd7e-4fc4-95e1-4e8d39f92ad3@zipdox.net
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260930155356.348608-2-tiwai@suse.de
For a request for a Mixer Unit on UAC2 (also UAC3), the wValue is
different from UAC1 and an incompatible value must be passed.
Namely, UAC1 takes a word consisting of 1-based input channel in the
high byte and 1-based output channel in the low byte.
Meanwhile, UAC2/3 takes UAC2_MU_MIXER in the high byte and a MCN
(0-based bit position of input/output channels) in the low byte.
The current driver implementation blindly assumes the UAC1 way, hence
it would cause a firmware error.

This patch attempts to implement the conversion to UAC2 MCN at
get_ctl_value_v2() and snd_usb_mixer_set_ctl_value() for mixer units.
At the points above, the old wValue containing ICN and OCN is
converted to the corresponding MCN, and it's used as the proper
wValue.

Reported-by: Zipdox <zipdox@zipdox.net>
Closes: https://lore.kernel.org/d46fcac6-bd7e-4fc4-95e1-4e8d39f92ad3@zipdox.net
Fixes: 23caaf1 ("ALSA: usb-mixer: Add support for Audio Class v2.0")
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260930155356.348608-3-tiwai@suse.de
UAC2 feature and mixer units provide the mixer information about
minimum and max channels as well as the resolution in a single
UAC2_CS_RANGE request, but the current code tries to extract each of
them in an old way of UAC1.

This patch refactors the code to optimize the range info extraction
for UAC2.  Now the code for obtaining min/max/res info is done in
get_ctl_range() function.  For UAC1, this will call UAC_GET_MIN,
UAC_GET_MAX and UAC_GET_RES requests, while it calls a single
UAC2_CS_RANGE for UAC2/3.

Link: https://lore.kernel.org/d46fcac6-bd7e-4fc4-95e1-4e8d39f92ad3@zipdox.net
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260930155356.348608-4-tiwai@suse.de
Add reusable TAS_REG_ERR_LOG macro in tas2781 header, replace all
duplicated error logging code in register read/write/bulk ops and
update_bits functions. Add channel ID to error log for better debuggability.

Signed-off-by: Shenghao Ding <shenghao-ding@ti.com>
Link: https://patch.msgid.link/20261001024049.93-2-shenghao-ding@ti.com
Signed-off-by: Mark Brown <broonie@kernel.org>
The codec should be reset only once during io_init, regardless of
whether the system performs a warm or cold reboot.

Fixes: 4c9854a ("ASoC: rt712-sdca: reset codec at io_init to fix silent headphone")
Signed-off-by: Shuming Fan <shumingf@realtek.com>
Link: https://patch.msgid.link/20261001090219.797880-1-shumingf@realtek.com
Signed-off-by: Mark Brown <broonie@kernel.org>
On Dell XPS 13 DX13260 create an acpi_gpio_mapping with exactly two
GPIO entries to point at the two pins in the GpioIo(). Use this to
read the speaker ID GPIOs.

This fixes problems on Dell XPS 13 DX13260:

- No speaker audio
- The wrong firmware was loaded so the speaker protection did not match
  the speaker characteristics.

The Dell XPS 13 DX13260 has two speaker ID GPIOs, to form a 2-bit ID. The
ACPI GpioIo() has both pins but the Linux-specific spk-id-gpios property
only has a mapping to the first pin. This meant that the speaker ID was
wrong in most cases, and that would lead to the codec driver loading the
wrong amp firmware, or not finding a firmware (as 0 is not a valid ID on
this laptop).

Assisted-by: Codex:gpt-6-sol
Reported-by: Wiza Jalakasi <wjalakasi@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221956
Tested-by: Wiza Jalakasi <wjalakasi@gmail.com>
Fixes: f3c6051 ("spi: cs42l43: Add GPIO speaker id support to the bridge configuration")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20261001085830.4014291-1-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It merges extensive cross-subsystem kernel changes, including security, memory-management, filesystem, networking, and architecture-sensitive code.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Merges Linux 7.3-rc5 upstream changes, spanning sound, networking, filesystems, memory management, security, architecture code, drivers, documentation, and selftests.

Changes:

  • Adds audio hardware support, tests, and compatibility fixes.
  • Hardens validation, synchronization, cleanup, and error handling.
  • Updates documentation, bindings, configuration, and release metadata.
File Description
Makefile Advances the kernel version to 7.3-rc5.
.get_maintainer.ignore Updates ignored maintainer addresses.
tools/​testing/​selftests/​x86/​Makefile Enables the interrupt signal test.
tools/​testing/​selftests/​sched_ext/​Makefile Enables additional scheduler tests.
tools/​testing/​selftests/​net/​packetdrill/​config Reorders packetdrill configuration.
tools/​testing/​selftests/​net/​config Reorders network configuration.
tools/​testing/​selftests/​kvm/​Makefile.kvm Enables the VGIC ITS save test.
tools/​testing/​selftests/​kvm/​arm64/​smccc_filter.c Tests zero-length SMCCC filters.
tools/​testing/​selftests/​hid/​progs/​hid.c Enlarges the HID request buffer.
tools/​testing/​selftests/​ftrace/​test.d/​kprobe/​kprobe_non_uniq_symbol.tc Tightens symbol matching.
tools/​testing/​selftests/​filesystems/​mntns_cleanup/​Makefile Removes obsolete test build metadata.
tools/​testing/​selftests/​filesystems/​mntns_cleanup/​.gitignore Removes obsolete test ignore metadata.
tools/​testing/​selftests/​drivers/​net/​config Enables TLS support.
tools/​testing/​selftests/​cgroup/​test_memcontrol.c Supplies the temporary-file mode.
tools/​testing/​selftests/​bpf/​prog_tests/​spin_lock.c Adds spin-lock identity failures.
tools/​testing/​selftests/​bpf/​prog_tests/​exceptions.c Adds exception callback coverage.
tools/​testing/​selftests/​arm64/​mte/​check_gcr_el1_cswitch.c Corrects thread result storage width.
sound/​usb/​mixer.h Extends mixer metadata.
sound/​usb/​mixer_us16x08.h Corrects documentation spelling.
sound/​usb/​mixer_evo.h Declares Audient EVO support.
sound/​usb/​Makefile Builds the EVO mixer implementation.
sound/​usb/​line6/​playback.c Rejects oversized playback packets.
sound/​usb/​implicit.c Adds FCA1616 feedback handling.
sound/​usb/​card.h Tracks allocated packets per URB.
sound/​usb/​caiaq/​Makefile Builds CAIAQ LCD support.
sound/​usb/​caiaq/​lcd.h Declares CAIAQ LCD initialization.
sound/​soc/​ux500/​ux500_msp_i2s.c Corrects a comment.
sound/​soc/​ux500/​Makefile Removes obsolete MOP500 objects.
sound/​soc/​uniphier/​aio.h Corrects documentation spelling.
sound/​soc/​ti/​omap-mcbsp.c Corrects documentation spelling.
sound/​soc/​ti/​davinci-i2s.c Corrects documentation spelling.
sound/​soc/​tegra/​tegra186_asrc.c Corrects the Stream6 register index.
sound/​soc/​stm/​stm32_spdifrx.c Corrects a DMA error message.
sound/​soc/​sof/​topology.c Uses element-derived allocation sizing.
sound/​soc/​sof/​imx/​imx-common.c Prevents invalid AR register dumps.
sound/​soc/​sof/​amd/​pci-acp7x.c Adds ACP7x SoundWire metadata.
sound/​soc/​sof/​amd/​Kconfig Enables ACP7x SoundWire support.
sound/​soc/​soc-internal.h Declares internal DAI helpers.
sound/​soc/​sdw_utils/​soc_sdw_rt711.c Clears a released device pointer.
sound/​soc/​sdca/​sdca_functions.c Gates ACPI enumeration helpers.
sound/​soc/​sdca/​Kconfig Allows SDCA on non-ACPI systems.
sound/​soc/​rockchip/​rk3399_gru_sound.c Corrects DAI-link allocation sizing.
sound/​soc/​qcom/​qdsp6/​q6asm-dai.c Corrects documentation spelling.
sound/​soc/​qcom/​lpass-cpu.c Updates the correct DAI descriptor.
sound/​soc/​mediatek/​Makefile Adds AN7581 build integration.
sound/​soc/​mediatek/​common/​mtk-base-afe.h Adds per-IRQ regmap storage.
sound/​soc/​mediatek/​an7581/​Makefile Defines AN7581 audio objects.
sound/​soc/​intel/​common/​soc-acpi-intel-sdca-quirks.h Declares topology forcing support.
sound/​soc/​intel/​common/​soc-acpi-intel-lnl-match.c Forces function topology where required.
sound/​soc/​intel/​avs/​topology.h Removes obsolete declarations.
sound/​soc/​intel/​atom/​sst/​sst.h Corrects documentation spelling.
sound/​soc/​intel/​atom/​sst-mfld-dsp.h Corrects documentation spelling.
sound/​soc/​generic/​audio-graph-card.c Adds card removal cleanup.
sound/​soc/​fsl/​Kconfig Restricts MPC5200 AC97 support.
sound/​soc/​codecs/​wm8904.c Uses element-derived allocation sizing.
sound/​soc/​codecs/​tlv320dac33.c Corrects documentation spelling.
sound/​soc/​codecs/​rt712-sdca-sdw.c Destroys the missing mutex.
sound/​soc/​codecs/​rt5665.c Propagates register-cache errors.
sound/​soc/​codecs/​rt5660.c Propagates register-cache errors.
sound/​soc/​codecs/​rt5659.c Propagates register-cache errors.
sound/​soc/​codecs/​rt286.c Delays initial jack detection.
sound/​soc/​codecs/​rt274.c Programs the 44.1 kHz rate base.
sound/​soc/​codecs/​rt1318.c Propagates register-cache errors.
sound/​soc/​codecs/​rt1308.c Propagates register-cache errors.
sound/​soc/​codecs/​rt1305.c Propagates register-cache errors.
sound/​soc/​codecs/​rt1016.c Propagates register-cache errors.
sound/​soc/​codecs/​nau8540.c Propagates register-cache errors.
sound/​soc/​codecs/​nau8360-dsp.c Corrects parameterless DSP messages.
sound/​soc/​codecs/​max98363.c Initializes SoundWire configuration.
sound/​soc/​codecs/​hdac_hdmi.c Corrects documentation spelling.
sound/​soc/​codecs/​hdac_hda.c Corrects documentation spelling.
sound/​soc/​codecs/​es8326.h Defines HPF settings.
sound/​soc/​codecs/​da7210.c Corrects documentation spelling.
sound/​soc/​codecs/​cx20442.c Corrects documentation spelling.
sound/​soc/​codecs/​cs42l42.c Corrects documentation spelling.
sound/​soc/​codecs/​cs35l34.c Corrects documentation spelling.
sound/​soc/​codecs/​cs35l33.c Corrects documentation spelling.
sound/​soc/​codecs/​arizona-jack.c Balances runtime PM on failure.
sound/​soc/​codecs/​ak4642.c Propagates register-cache errors.
sound/​soc/​codecs/​adau17x1.c Propagates register-cache errors.
sound/​soc/​bcm/​cygnus-ssp.h Corrects documentation spelling.
sound/​soc/​atmel/​atmel-pcm-dma.c Corrects documentation spelling.
sound/​ppc/​tumbler.c Corrects documentation grammar.
sound/​pcmcia/​vx/​vxp_ops.c Corrects documentation spelling.
sound/​pci/​vx222/​vx222_ops.c Corrects documentation spelling.
sound/​pci/​trident/​trident_memory.c Corrects documentation spelling.
sound/​pci/​rme9652/​hdsp.c Corrects documentation grammar.
sound/​pci/​rme32.c Corrects documentation grammar.
sound/​pci/​lx6464es/​lx_defs.h Corrects documentation spelling.
sound/​pci/​echoaudio/​echoaudio.h Corrects documentation spelling.
sound/​pci/​au88x0/​au88x0.h Corrects documentation spelling.
sound/​pci/​au88x0/​au88x0_mpu401.c Corrects documentation spelling.
sound/​pci/​ac97/​ac97_codec.c Corrects documentation spelling.
sound/​isa/​opti9xx/​opti92x-ad1848.c Corrects documentation spelling.
sound/​i2c/​other/​ak4xxx-adda.c Corrects documentation spelling.
sound/​i2c/​other/​ak4114.c Corrects documentation spelling.
sound/​i2c/​other/​ak4113.c Corrects documentation spelling.
sound/​hda/​core/​controller.c Simplifies atomic bit assignment.
sound/​hda/​core/​component.c Simplifies atomic bit assignment.
sound/​hda/​core/​bus.c Corrects API documentation.
sound/​hda/​controllers/​tegra.c Applies the SDO limit to Tegra194.
sound/​hda/​common/​controller.c Avoids tracing an invalid stream.
sound/​hda/​common/​codec.c Corrects API documentation.
sound/​hda/​codecs/​realtek/​alc882.c Corrects documentation spelling.
sound/​hda/​codecs/​hdmi/​hdmi.c Corrects documentation spelling.
sound/​firewire/​bebob/​bebob_hwdep.c Corrects documentation spelling.
sound/​core/​timer.c Adds 32-bit user-timer ioctl support.
sound/​core/​timer_compat.c Handles user-timer creation compatibly.
sound/​core/​seq/​seq_compat.c Serializes compat sequencer ioctls.
sound/​core/​seq/​oss/​seq_oss.c Warns about OSS sequencer deprecation.
sound/​core/​seq/​oss/​seq_oss_init.c Corrects documentation grammar.
sound/​core/​control.c Rejects controls on shutdown cards.
security/​selinux/​avc.c Initializes denied zero-request decisions.
security/​landlock/​ruleset.h Expands ruleset versions to 64 bits.
security/​landlock/​domain.h Annotates a flexible array.
security/​keys/​gc.c Uses ordered clear-and-wake handling.
security/​ipe/​policy_fs.c Audits successful signed policy loads.
security/​ipe/​fs.c Adjusts policy-load auditing flow.
security/​ipe/​eval.h Marks the root hash as RCU-protected.
scripts/​generate_rust_target.rs Disables Rust APX generation.
net/​xfrm/​espintcp.c Validates the transport-header offset.
net/​wireless/​rdev-ops.h Tracks scan request ownership.
net/​vmw_vsock/​af_vsock.c Handles zero-length sysctl operations.
net/​tipc/​monitor.c Moves peer-count access under lock.
net/​tipc/​group.c Tightens broadcast ACK validation.
net/​sctp/​sm_statefuns.c Discards stale-cookie packets.
net/​sctp/​input.c Corrects timer reference handling.
net/​sched/​em_text.c Initializes exported configuration.
net/​rds/​ib_cm.c Drops rather than destroys live connections.
net/​rds/​connection.c Sizes paths from the active transport.
net/​qrtr/​qrtr.h Declares endpoint hello support.
net/​psp/​psp_sock.c Rejects incompatible decrypt users.
net/​packet/​internal.h Widens private block size storage.
net/​nfc/​llcp.h Adds deferred release work.
net/​nfc/​llcp_commands.c Bounds debug-string output.
net/​netfilter/​nft_synproxy.c Uses protocol-family-aware checksums.
net/​netfilter/​nft_nat.c Initializes the mapped address.
net/​netfilter/​nf_conntrack_netlink.c Uses lock-protected RCU dereferencing.
net/​mptcp/​protocol.h Tracks resetting subflows.
net/​mctp/​route.c Searches the socket-local tag list.
net/​mac80211/​scan.c Avoids warning on empty scans.
net/​mac80211/​offchannel.c Defers ROC work during scans.
net/​mac80211/​main.c Accounts for 6 GHz scan IEs.
net/​mac80211/​ieee80211_i.h Extends the suspend interface.
net/​mac80211/​debugfs.c Marks debugfs suspension as reset.
net/​llc/​llc_c_ac.c Frees the correct cloned packet.
net/​ipv6/​tcp_ipv6.c Avoids option cloning for closed sockets.
net/​ipv6/​netfilter/​ip6t_rpfilter.c Rejects routes without an interface.
net/​ipv6/​ip6_gre.c Uses the ERSPAN metadata unlink helper.
net/​ipv6/​ip6_fib.c Corrects teardown ordering.
net/​ipv6/​exthdrs_core.c Validates extension-header lengths.
net/​ipv6/​esp6.c Balances managed fragment references.
net/​ipv4/​tcp_ulp.c Rejects incompatible decrypt users.
net/​ipv4/​inet_connection_sock.c Avoids rescheduling in BPF context.
net/​ipv4/​fou_core.c Requires a direct-encapsulation protocol.
net/​ipv4/​esp4.c Balances managed fragment references.
net/​ipv4/​devinet.c Correctly parses configuration attributes.
net/​ipv4/​arp.c Terminates user-provided device names.
net/​ethtool/​common.h Adds self-test locking requirements.
net/​core/​sock_map.c Bounds socket-map entry counts.
net/​core/​skmsg.c Avoids ingress self-redirection.
net/​core/​netdev-genl.c Documents unprivileged TX binding.
net/​core/​dev.h Declares deferred-node flushing.
net/​bridge/​br_stp_bpdu.c Handles MAC-header construction errors.
net/​bridge/​br_mdb.c Restarts iteration after list mutation.
net/​bpf/​test_run.c Frees virtually allocated arrays correctly.
net/​bluetooth/​rfcomm/​core.c Validates extended frame lengths.
net/​bluetooth/​hci_sync.c Protects codec-list cleanup.
net/​bluetooth/​eir.c Validates service-data UUID lengths.
net/​8021q/​vlan_dev.c Ensures VLAN header headroom.
mm/​swapfile.c Corrects the atomic-long flag width.
mm/​shrinker.c Initializes the shrinker ID.
mm/​rmap.c Publishes anon VMAs with release ordering.
mm/​mlock.c Uses the appropriate zone-stat helper.
mm/​memcontrol.c Uses the unified charge path.
mm/​folio.c Exports folio draining for KVM.
mm/​filemap.c Avoids invalidating mapped folios.
mm/​backing-dev.c Reports Tasks RCU quiescent states.
kernel/​sched/​ext/​types.h Documents scheduler ABI layout rules.
kernel/​sched/​ext/​inlines.h Accounts for bypass dispatches.
kernel/​dma/​coherent.c Propagates coherent-memory assignment errors.
kernel/​cgroup/​pids.c Notifies the correct event files.
kernel/​bpf/​offload.c Tightens offload-device matching.
kernel/​bpf/​crypto.c Validates the structure size first.
include/​uapi/​sound/​asound.h Adds the CAIAQ hardware interface.
include/​uapi/​rdma/​bnxt_re-abi.h Reserves an unused ABI field.
include/​uapi/​linux/​input-event-codes.h Documents legacy LED restrictions.
include/​trace/​events/​dma.h Avoids reporting invalid DMA addresses.
include/​sound/​emux_legacy.h Corrects documentation grammar.
include/​rdma/​uverbs_types.h Removes an obsolete mutex.
include/​net/​sock.h Declares decrypt-user detection.
include/​net/​nfc/​nfc.h Adds bounded general-byte copying.
include/​net/​nfc/​hci.h Embeds general-byte storage.
include/​net/​netfilter/​nf_conntrack.h Adds shared-connection detection.
include/​net/​ip6_route.h Corrects uncached route handling.
include/​net/​dst.h Preserves sufficient MAC headroom.
include/​net/​codel.h Caps drops per dequeue.
include/​linux/​sched/​topology.h Updates cache-size refresh arguments.
include/​linux/​mmap_lock.h Adds a write-lock guard.
include/​linux/​mempool.h Adds non-reserve allocation.
include/​linux/​if_vlan.h Validates inner-tag packet length.
include/​linux/​firmware/​cirrus/​cs_dsp.h Annotates coefficient-cache sizing.
include/​linux/​dmaengine.h Removes a deprecated DMA helper.
include/​linux/​btf.h Adds the CAP_PERFMON kfunc flag.
include/​linux/​bpf.h Tracks sleepable verification separately.
include/​keys/​request_key_auth-type.h Stores a referenced PID object.
fs/​xfs/​xfs_zone_gc.c Corrects documentation wording.
fs/​xfs/​xfs_platform.h Corrects documentation spelling.
fs/​xfs/​xfs_log_cil.c Corrects documentation spelling.
fs/​xfs/​xfs_inode.c Corrects documentation spelling.
fs/​xfs/​xfs_icache.c Uses the group quota predicate.
fs/​xfs/​xfs_healthmon.c Keeps different errors separate.
fs/​xfs/​xfs_bmap_item.c Corrects documentation wording.
fs/​xfs/​scrub/​scrub.h Uses wrap-safe time comparison.
fs/​xfs/​scrub/​rmap_repair.c Releases the AGFL buffer.
fs/​xfs/​scrub/​reap.c Corrects documentation wording.
fs/​xfs/​scrub/​inode.c Corrects fork-offset validation.
fs/​xfs/​scrub/​inode_repair.c Validates the correct block count.
fs/​xfs/​scrub/​health.c Handles unhealthy reports correctly.
fs/​xfs/​scrub/​findparent.c Handles failed inode references.
fs/​xfs/​scrub/​dirtree.c Corrects documentation spelling.
fs/​xfs/​scrub/​dir.c Avoids block-format padding checks.
fs/​xfs/​scrub/​alloc_repair.c Corrects documentation wording.
fs/​xfs/​scrub/​agheader_repair.c Corrects documentation wording.
fs/​xfs/​libxfs/​xfs_inode_buf.c Corrects documentation wording.
fs/​xfs/​libxfs/​xfs_format.h Corrects documentation wording.
fs/​xfs/​libxfs/​xfs_errortag.h Corrects documentation spelling.
fs/​xfs/​libxfs/​xfs_attr_leaf.c Corrects documentation spelling.
fs/​xfs/​libxfs/​xfs_ag.h Corrects documentation spelling.
fs/​smb/​server/​stats.h Adds session-timeout statistics.
fs/​smb/​server/​server.c Performs complete session cleanup.
fs/​smb/​server/​proc.c Exposes session-timeout statistics.
fs/​smb/​client/​trace.h Adds an EA offset trace reason.
fs/​smb/​client/​file.c Retains the original tree connection.
fs/​smb/​client/​cifssmb.c Validates reparse response size.
fs/​overlayfs/​overlayfs.h Avoids logging a released dentry.
fs/​ntfs/​namei.c Supplies the MFT data VCN.
fs/​ntfs/​mft.h Extends MFT allocation parameters.
fs/​ntfs/​file.c Uses lock-aware mapping updates.
fs/​ntfs/​compress.c Uses lock-aware mapping updates.
fs/​ntfs/​attrlist.h Declares lock-aware attribute updates.
fs/​nfsd/​export.c Sets layouts only for pNFS exports.
fs/​netfs/​rolling_buffer.c Avoids consuming mempool reserves.
fs/​netfs/​read_collect.c Clamps rounded direct-I/O results.
fs/​kernfs/​mount.c Clarifies superblock teardown behavior.
fs/​dcache.c Unpoisons inline dentry names for KMSAN.
fs/​btrfs/​zoned.c Supports more zoned RAID profiles.
fs/​btrfs/​file.c Aborts failed extent replacement transactions.
fs/​btrfs/​disk-io.c Validates chunk-header availability.
fs/​btrfs/​dev-replace.c Acquires commit serialization.
fs/​bpf_fs_kfuncs.c Removes incorrectly classified path hooks.
fs/​autofs/​inode.c Ensures the daemon pipe is released.
drivers/​watchdog/​starfive-wdt.c Uses balanced runtime PM acquisition.
drivers/​spi/​spi-virtio.c Uses per-transfer word width.
drivers/​soundwire/​dmi-quirks.c Adds an ASUS address-remap quirk.
drivers/​scsi/​qla2xxx/​qla_os.c Corrects a module parameter description.
drivers/​scsi/​megaraid/​megaraid_sas_base.c Serializes controller information reads.
drivers/​scsi/​libiscsi_tcp.c Validates data-in direction.
drivers/​scsi/​Kconfig Prevents invalid IBMVFC/NVMe combinations.
drivers/​scsi/​fnic/​fnic.h Updates the FNIC driver version.
drivers/​s390/​cio/​vfio_ccw_fsm.c Checks subchannel validity.
drivers/​s390/​cio/​device_fsm.c Avoids invalid path recovery.
drivers/​s390/​cio/​cmf.c Converts measurement addresses to DMA.
drivers/​s390/​cio/​chp.c Avoids invalid path-mask access.
drivers/​s390/​char/​vmlogrdr.c Corrects documentation spelling.
drivers/​s390/​char/​raw3270.c Updates usable-area documentation.
drivers/​power/​sequencing/​Kconfig Selects the auxiliary bus dependency.
drivers/​platform/​x86/​serial-multi-instantiate.c Adds CLSA0102 support.
drivers/​pinctrl/​qcom/​pinctrl-ipq5210.c Exports the device table.
drivers/​pinctrl/​pinctrl-single.c Correctly unwinds IRQ setup.
drivers/​pinctrl/​meson/​pinctrl-meson-s4.c Corrects an I²C pin group name.
drivers/​phy/​mediatek/​phy-mtk-hdmi-mt8195.h Defines TX clock divisors.
drivers/​perf/​arm_brbe.c Fully initializes branch entries.
drivers/​nfc/​virtual_ncidev.c Adds compatible ioctl handling.
drivers/​nfc/​trf7970a.c Powers down after startup failure.
drivers/​nfc/​port100.c Rejects truncated frames.
drivers/​nfc/​pn533/​usb.c Bounds ACR122 frame lengths.
drivers/​net/​wwan/​t7xx/​t7xx_netdev.c Validates network interface indices.
drivers/​net/​wireless/​ti/​wlcore/​main.c Balances runtime PM during recovery.
drivers/​net/​wireless/​rsi/​rsi_91x_mgmt.c Avoids invalid key-buffer clearing.
drivers/​net/​wireless/​marvell/​mwifiex/​pcie.c Frees the correct MSI-X contexts.
drivers/​net/​wireless/​marvell/​libertas_tf/​main.c Stops the timer before freeing commands.
drivers/​net/​wireless/​intel/​iwlegacy/​common.c Fully clears broadcast station state.
drivers/​net/​wireless/​broadcom/​brcm80211/​brcmfmac/​core.c Orders waitqueue-visible decrements.
drivers/​net/​wireless/​ath/​wcn36xx/​dxe.c Shuts down the acknowledgment timer safely.
drivers/​net/​vrf.c Avoids an incorrect checksum adjustment.
drivers/​net/​usb/​sr9700.c Accounts for receive overhead.
drivers/​net/​usb/​lan78xx.c Releases deferred URB references.
drivers/​net/​phy/​micrel.c Advances through register data.
drivers/​net/​pcs/​pcs-xpcs.c Releases clocks after enable failure.
drivers/​net/​pcs/​pcs-rzn1-miic.c Initializes the complete configuration array.
drivers/​net/​fddi/​skfp/​skfddi.c Avoids resetting a stopped adapter.
drivers/​net/​ethernet/​wangxun/​libwx/​wx_type.h Adds PTP transmit locking.
drivers/​net/​ethernet/​wangxun/​libwx/​wx_hw.c Initializes PTP transmit locking.
drivers/​net/​ethernet/​ti/​netcp_core.c Uses balanced runtime PM acquisition.
drivers/​net/​ethernet/​stmicro/​stmmac/​stmmac_ethtool.c Preserves the unavailable PHC index.
drivers/​net/​ethernet/​stmicro/​stmmac/​ring_mode.c Clarifies buffer-length handling.
drivers/​net/​ethernet/​spacemit/​k1_emac.c Clears failed TX descriptors.
drivers/​net/​ethernet/​meta/​fbnic/​fbnic_fw.h Tracks mailbox response errors.
drivers/​net/​ethernet/​mellanox/​mlx5/​core/​lag/​shared_fdb.c Unloads representors during unwind.
drivers/​net/​ethernet/​mellanox/​mlx5/​core/​en/​tc_ct.c Releases reverse CT entries.
drivers/​net/​ethernet/​mellanox/​mlx5/​core/​en_main.c Removes unsupported VLAN MACsec features.
drivers/​net/​ethernet/​google/​gve/​gve_desc_dqo.h Defines the hardware TSO MSS limit.
drivers/​net/​ethernet/​freescale/​fman/​fman.c Releases the clock reference.
drivers/​net/​ethernet/​amazon/​ena/​ena_netdev.c Completes probe-failure cleanup.
drivers/​net/​dsa/​mt7530.c Avoids premature IRQ-domain cleanup.
drivers/​net/​bonding/​bond_main.c Returns the appropriate unsupported error.
drivers/​mmc/​host/​mxcmmc.c Quiesces asynchronous work on removal.
drivers/​mmc/​host/​mmci.c Cancels busy-detection work.
drivers/​mmc/​host/​mmc_spi.c Resets transfer accounting before retry.
drivers/​mmc/​core/​sdio_uart.c Frees FIFO state after registration failure.
drivers/​mmc/​core/​host.c Cancels SDIO IRQ work.
drivers/​mmc/​core/​bus.c Always releases the OF node.
drivers/​memstick/​core/​ms_block.c Destroys the I/O workqueue.
drivers/​input/​touchscreen/​eeti_ts.c Exports the device table.
drivers/​input/​touchscreen/​cyttsp5.c Bounds reported input size.
drivers/​input/​serio/​hp_sdc.c Shuts down the timer safely.
drivers/​input/​mouse/​synaptics.c Disables broken intertouch hardware.
drivers/​input/​keyboard/​atkbd.c Adds a Redmi keyboard quirk.
drivers/​input/​input-compat.c Initializes compat force-feedback data.
drivers/​input/​evdev.c Initializes partial absolute-axis data.
drivers/​infiniband/​ulp/​rtrs/​rtrs-clt.h Tracks connection destruction.
drivers/​infiniband/​sw/​rxe/​rxe_mr.c Uses overflow-safe range validation.
drivers/​infiniband/​hw/​efa/​efa_com.h Declares event-queue arming.
drivers/​infiniband/​core/​uverbs_flow.c Frees collections on allocation failure.
drivers/​infiniband/​core/​rdma_core.c Removes obsolete mutex teardown.
drivers/​i2c/​i2c-atr.c Clears failed adapter registration.
drivers/​i2c/​busses/​i2c-at91.h Declares DMA release support.
drivers/​hwmon/​w83793.c Uses reference-counted probe cleanup.
drivers/​hwmon/​w83791d.c Removes the secondary sysfs group.
drivers/​hwmon/​k10temp.c Corrects the Turin model range.
drivers/​hid/​wacom_sys.c Processes each reported HID value.
drivers/​hid/​Kconfig Documents additional SteelSeries devices.
drivers/​hid/​hid-oxp.c Synchronizes delayed-work cancellation.
drivers/​gpu/​drm/​xe/​xe_wa_oob.rules Adds a non-SR-IOV workaround.
drivers/​gpu/​drm/​xe/​xe_mmio_gem.h Extends GEM destruction context.
drivers/​gpu/​drm/​xe/​xe_guc_ads.c Applies the new MMIO workaround.
drivers/​gpu/​drm/​xe/​regs/​xe_gt_regs.h Defines the power-brake mask.
drivers/​gpu/​drm/​virtio/​virtgpu_prime.c Restricts blob-based imports.
drivers/​gpu/​drm/​virtio/​virtgpu_gem.c Releases failed GEM objects correctly.
drivers/​gpu/​drm/​verisilicon/​vs_primary_plane.c Uses primary-plane formats.
drivers/​gpu/​drm/​verisilicon/​vs_hwdb.h Distinguishes primary-plane formats.
drivers/​gpu/​drm/​vc4/​vc4_kms.c Uses managed polling cleanup.
drivers/​gpu/​drm/​ttm/​ttm_bo.c Handles swapout progress correctly.
drivers/​gpu/​drm/​nouveau/​nvkm/​subdev/​gsp/​rm/​r535/​fbsr.c Simplifies the suspend callback.
drivers/​gpu/​drm/​nouveau/​nvkm/​subdev/​gsp/​priv.h Declares GCX readiness support.
drivers/​gpu/​drm/​nouveau/​nvkm/​subdev/​fb/​ramnv1a.c Releases the PCI bridge reference.
drivers/​gpu/​drm/​nouveau/​nvif/​vmm.c Clears a freed page pointer.
drivers/​gpu/​drm/​nouveau/​nouveau_sched.h Adds RCU scheduler teardown.
drivers/​gpu/​drm/​nouveau/​nouveau_sched.c Defers scheduler freeing through RCU.
drivers/​gpu/​drm/​nouveau/​nouveau_dmem.c Allocates the full device-memory range.
drivers/​gpu/​drm/​nouveau/​nouveau_bo.c Avoids pinning incompatible resources.
drivers/​gpu/​drm/​nouveau/​include/​nvif/​device.h Declares GCX readiness querying.
drivers/​gpu/​drm/​msm/​msm_ringbuffer.h Adds RCU ring teardown.
drivers/​gpu/​drm/​msm/​msm_ringbuffer.c Defers ring freeing through RCU.
drivers/​gpu/​drm/​msm/​msm_gem.h Adds RCU VM teardown.
drivers/​gpu/​drm/​msm/​msm_gem_vma.c Defers VM freeing through RCU.
drivers/​gpu/​drm/​msm/​msm_fbdev.c Marks system-memory framebuffers.
drivers/​gpu/​drm/​msm/​disp/​dpu1/​dpu_hw_ctl.c Clears pending peripheral flushes.
drivers/​gpu/​drm/​msm/​adreno/​adreno_device.c Corrects module parameter documentation.
drivers/​gpu/​drm/​msm/​adreno/​a6xx_gmu.c Extends firmware startup timeout.
drivers/​gpu/​drm/​imagination/​pvr_mmu.h Passes the mapped device address.
drivers/​gpu/​drm/​i915/​display/​intel_dp_mst.h Declares stream-disconnect detection.
drivers/​gpu/​drm/​i915/​display/​intel_display_types.h Tracks selective-fetch clearing.
drivers/​gpu/​drm/​bridge/​samsung-dsim.c Manages TE GPIO lifetime explicitly.
drivers/​gpu/​drm/​amd/​amdgpu/​amdgpu.h Tracks both PCIe link endpoints.
drivers/​gpu/​drm/​amd/​amdgpu/​amdgpu_vm.c Releases the last update fence.
drivers/​gpu/​drm/​amd/​amdgpu/​amdgpu_eviction_fence.c Waits outside fence-signalling context.
drivers/​gpu/​drm/​amd/​amdgpu/​amdgpu_amdkfd.c Avoids clearing uninitialized KFD state.
drivers/​gpu/​drm/​amd/​amdgpu/​amdgpu_acpi.c Releases ACPI references on failure.
drivers/​gpio/​gpiolib.c Restores GPIO hog name fallback.
drivers/​gpio/​gpio-zynq.c Uses balanced runtime PM acquisition.
drivers/​gpio/​gpio-virtuser.c Avoids freeing IRQ zero.
drivers/​firmware/​arm_scmi/​driver.c Corrects documentation wording.
drivers/​firmware/​arm_ffa/​driver.c Cleans up FF-A during shutdown.
drivers/​firewire/​core-cdev.c Preserves concurrent deallocation requests.
drivers/​dma-buf/​Kconfig Uses the correct debug configuration.
drivers/​ata/​libahci_platform.c Releases child-device references.
drivers/​acpi/​scan.c Adds CLSA0102 enumeration.
drivers/​accel/​ivpu/​ivpu_pm.c Records job timeout detection.
drivers/​accel/​ivpu/​ivpu_mmu.c Stops treating MMU faults as timeouts.
drivers/​accel/​ivpu/​ivpu_drv.h Renames the timeout state.
Documentation/​netlink/​specs/​rt-neigh.yaml Bounds neighbor probe intervals.
Documentation/​netlink/​specs/​netdev.yaml Documents unprivileged TX binding.
Documentation/​devicetree/​bindings/​vendor-prefixes.yaml Adds ESS Technology.
Documentation/​devicetree/​bindings/​sound/​ti,tpa6130a2.yaml Corrects example indentation.
Documentation/​devicetree/​bindings/​sound/​ti,tlv320dac3100.yaml Corrects example indentation.
Documentation/​devicetree/​bindings/​sound/​ti,tas2781.yaml Tightens compatible matching.
Documentation/​devicetree/​bindings/​sound/​qcom,sm8250.yaml Adds Rubik Pi 3 support.
Documentation/​devicetree/​bindings/​sound/​invensense,ics43432.yaml Corrects example indentation.
Documentation/​devicetree/​bindings/​sound/​imx-audio-card.yaml Corrects example indentation.
Documentation/​devicetree/​bindings/​sound/​hisilicon,hi6210-i2s.yaml Documents graph ports.
Documentation/​devicetree/​bindings/​sound/​everest,es8316.yaml Adds inverted jack detection.
Documentation/​devicetree/​bindings/​input/​mediatek,mt6779-keypad.yaml Adds MT6572 keypad compatibility.
Documentation/​devicetree/​bindings/​display/​msm/​qcom,sm8350-mdss.yaml Corrects example indentation.
Documentation/​devicetree/​bindings/​display/​msm/​qcom,sar2130p-mdss.yaml Corrects example indentation.
Documentation/​arch/​s390/​pci.rst Corrects the SR-IOV sysfs path.
Documentation/​ABI/​testing/​sysfs-devices-platform-trackpoint Corrects the inertia sysfs path.
arch/​x86/​Makefile Prevents native APX EGPR generation.
arch/​x86/​kvm/​vmx/​tdx.c Preserves the VM-dead request.
arch/​x86/​kvm/​vmx/​pmu_intel.c Validates global PMU MSRs.
arch/​x86/​kvm/​mmu/​mmu.c Preserves the VM-dead request.
arch/​x86/​kernel/​kprobes/​core.c Corrects emulated call return addresses.
arch/​x86/​include/​asm/​text-patching.h Extends emulated call arguments.
arch/​x86/​include/​asm/​pgtable.h Preserves PMD dirty state.
arch/​x86/​include/​asm/​div64.h Restricts an inline-assembly operand.
arch/​x86/​events/​amd/​brs.c Fully initializes branch entries.
arch/​s390/​pci/​pci_report.h Adds PCI device context to reports.
arch/​s390/​kvm/​s390/​s390.h Makes the old memory slot const.
arch/​s390/​kvm/​gmap/​kvm_mmu.h Removes an obsolete callback declaration.
arch/​s390/​crypto/​hmac_s390.c Uses the correct non-final hash instruction.
arch/​riscv/​kvm/​vcpu.c Uses the shared interrupt conversion helper.
arch/​riscv/​kvm/​vcpu_timer.c Always cancels initialized timers.
arch/​riscv/​kvm/​vcpu_exit.c Suppresses expected interrupt errors.
arch/​powerpc/​kvm/​book3s_hv_uvmem.c Releases failed page-in pages.
arch/​powerpc/​kernel/​iommu.c Adds overflow-safe IOVA validation.
arch/​parisc/​include/​asm/​thread_info.h Keeps larger 64-bit IRQ stacks.
arch/​mips/​net/​bpf_jit_comp64.c Always zero-extends 16-bit swaps.
arch/​mips/​net/​bpf_jit_comp32.c Uses the immediate add instruction.
arch/​arm64/​net/​bpf_jit_comp.c Enables callback BPF stack frames.
arch/​arm64/​kvm/​sys_regs.c Handles the additional debug register encoding.
arch/​arm64/​kvm/​hypercalls.c Rejects empty SMCCC filters.
arch/​arm64/​kvm/​hyp/​include/​nvhe/​mm.h Declares host-ownership checking.
arch/​arm64/​kernel/​mte.c Returns the expected tag-access error.
arch/​arm64/​kernel/​hibernate.c Uses the active virtual-address width.
arch/​arm64/​kernel/​hibernate-asm.S Restores EL2 vectors correctly.
arch/​arm64/​include/​asm/​kvm_pkvm.h Avoids warning on unsupported ioctls.
arch/​arm64/​include/​asm/​kvm_host.h Stores nested MMUs as pointers.
arch/​arm64/​include/​asm/​io.h Silently rejects invalid protections.
arch/​arm64/​boot/​dts/​amlogic/​amlogic-t7-a311d2-an400.dts Corrects the UART peripheral clock.
arch/​arm/​mach-socfpga/​Kconfig Selects the required cache erratum.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@@ -420,7 +420,7 @@ struct raw3270_ua { /* Query Reply structure for Usable Area */
char flags0;
char flags1;
short w; /* Width of usable area */
short h; /* Heigth of usavle area */
short h; /* Height of usavle area */
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.