]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
6.6-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 08:50:30 +0000 (10:50 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 08:50:30 +0000 (10:50 +0200)
added patches:
bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
rtc-mpfs-fix-counter-upload-completion-condition.patch

queue-6.6/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch [new file with mode: 0644]
queue-6.6/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch [new file with mode: 0644]
queue-6.6/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch [new file with mode: 0644]
queue-6.6/rtc-mpfs-fix-counter-upload-completion-condition.patch [new file with mode: 0644]
queue-6.6/series

diff --git a/queue-6.6/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch b/queue-6.6/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
new file mode 100644 (file)
index 0000000..b5b8421
--- /dev/null
@@ -0,0 +1,43 @@
+From a986fde914d88af47eb78fd29c5d1af7952c3500 Mon Sep 17 00:00:00 2001
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Date: Sat, 20 Jun 2026 11:53:50 +0530
+Subject: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
+
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+
+commit a986fde914d88af47eb78fd29c5d1af7952c3500 upstream.
+
+If the allocation of fp[i].tpa_info fails, the error path will not free
+the struct bnx2x_fastpath allocated earlier, as it is not linked to the
+bp structure yet. Fix that by linking it immediately after allocation.
+
+Cc: stable@vger.kernel.org
+Fixes: 15192a8cf8a8 ("bnx2x: Split the FP structure")
+Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Reviewed-by: Simon Horman <horms@kernel.org>
+Link: https://patch.msgid.link/20260620062402.89549-1-nihaal@cse.iitm.ac.in
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c |    3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+--- a/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c
++++ b/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c
+@@ -4752,6 +4752,7 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp)
+       fp = kcalloc(bp->fp_array_size, sizeof(*fp), GFP_KERNEL);
+       if (!fp)
+               goto alloc_err;
++      bp->fp = fp;
+       for (i = 0; i < bp->fp_array_size; i++) {
+               fp[i].tpa_info =
+                       kcalloc(ETH_MAX_AGGREGATION_QUEUES_E1H_E2,
+@@ -4760,8 +4761,6 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp)
+                       goto alloc_err;
+       }
+-      bp->fp = fp;
+-
+       /* allocate sp objs */
+       bp->sp_objs = kcalloc(bp->fp_array_size, sizeof(struct bnx2x_sp_objs),
+                             GFP_KERNEL);
diff --git a/queue-6.6/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch b/queue-6.6/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
new file mode 100644 (file)
index 0000000..05dcec7
--- /dev/null
@@ -0,0 +1,78 @@
+From 007800408002d871f5699bdb944f985896730b8f Mon Sep 17 00:00:00 2001
+From: Sabrina Dubroca <sd@queasysnail.net>
+Date: Fri, 12 Jun 2026 16:11:39 +0200
+Subject: espintcp: use sk_msg_free_partial to fix partial send
+
+From: Sabrina Dubroca <sd@queasysnail.net>
+
+commit 007800408002d871f5699bdb944f985896730b8f upstream.
+
+sk_msg_free_partial() ensures consistency of the skmsg at every
+iteration, without having to manually handle uncharges and offsets.
+This simplifies the code, and fixes some bugs in skmsg accounting when
+we don't send the full contents.
+
+Cc: stable@vger.kernel.org
+Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
+Reported-by: Aaron Esau <aaron1esau@gmail.com>
+Reported-by: Yiming Qian <yimingqian591@gmail.com>
+Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
+Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ net/xfrm/espintcp.c |   34 +++++++---------------------------
+ 1 file changed, 7 insertions(+), 27 deletions(-)
+
+--- a/net/xfrm/espintcp.c
++++ b/net/xfrm/espintcp.c
+@@ -213,43 +213,23 @@ static int espintcp_sendskmsg_locked(str
+       struct sk_msg *skmsg = &emsg->skmsg;
+       bool more = flags & MSG_MORE;
+       struct scatterlist *sg;
+-      int done = 0;
+       int ret;
+-      sg = &skmsg->sg.data[skmsg->sg.start];
+       do {
+               struct bio_vec bvec;
+-              size_t size = sg->length - emsg->offset;
+-              int offset = sg->offset + emsg->offset;
+-              struct page *p;
+-
+-              emsg->offset = 0;
++              sg = &skmsg->sg.data[skmsg->sg.start];
+               if (sg_is_last(sg) && !more)
+                       msghdr.msg_flags &= ~MSG_MORE;
+-              p = sg_page(sg);
+-retry:
+-              bvec_set_page(&bvec, p, size, offset);
+-              iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, size);
+-              ret = tcp_sendmsg_locked(sk, &msghdr, size);
+-              if (ret < 0) {
+-                      emsg->offset = offset - sg->offset;
+-                      skmsg->sg.start += done;
++              bvec_set_page(&bvec, sg_page(sg), sg->length, sg->offset);
++              iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, sg->length);
++              ret = tcp_sendmsg_locked(sk, &msghdr, sg->length);
++              if (ret < 0)
+                       return ret;
+-              }
+-              if (ret != size) {
+-                      offset += ret;
+-                      size -= ret;
+-                      goto retry;
+-              }
+-
+-              done++;
+-              put_page(p);
+-              sk_mem_uncharge(sk, sg->length);
+-              sg = sg_next(sg);
+-      } while (sg);
++              sk_msg_free_partial(sk, skmsg, ret);
++      } while (skmsg->sg.size);
+       memset(emsg, 0, sizeof(*emsg));
diff --git a/queue-6.6/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch b/queue-6.6/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
new file mode 100644 (file)
index 0000000..c4bd35e
--- /dev/null
@@ -0,0 +1,82 @@
+From 018e9828eb523c638fa3d9bdf0fd4956b74555b2 Mon Sep 17 00:00:00 2001
+From: Hongchen Zhang <zhanghongchen@loongson.cn>
+Date: Thu, 25 Jun 2026 13:03:49 +0800
+Subject: LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
+
+From: Hongchen Zhang <zhanghongchen@loongson.cn>
+
+commit 018e9828eb523c638fa3d9bdf0fd4956b74555b2 upstream.
+
+When hardware page table walker (PTW) is enabled on LoongArch, the CPU
+may set _PAGE_DIRTY directly in the page table entry during a write TLB
+miss, without going through the software TLB store handler. The software
+TLB store handler (tlbex.S:254) sets both _PAGE_DIRTY and_PAGE_MODIFIED
+together:
+
+    ori t0, t0, (_PAGE_VALID | _PAGE_DIRTY | _PAGE_MODIFIED)
+
+Since hardware PTW only sets _PAGE_DIRTY, the software-only bit, i.e.
+_PAGE_MODIFIED is left unchanged. This creates a window where a PTE has
+_PAGE_DIRTY set (hardware knows the page is dirty) but _PAGE_MODIFIED
+clear (software is unaware).
+
+When fork()/clone() triggers copy-on-write, __copy_present_ptes() calls
+pte_wrprotect(), which unconditionally clears both the _PAGE_WRITE and
+_PAGE_DIRTY bits:
+
+    pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+
+Since _PAGE_MODIFIED was never set, the dirtiness information is lost
+completely. Subsequently, when memory pressure triggers page reclaim,
+page_mkclean() / try_to_unmap() sees the page as clean (i.e. pte_dirty()
+returns false) and the page may be freed without writeback, causing data
+corruption.
+
+Fix this by propagating the _PAGE_DIRTY bit to the _PAGE_MODIFIED bit in
+both pte_wrprotect() and pmd_wrprotect() before clearing writeable bits:
+
+    if (pte_val(pte) & _PAGE_DIRTY)
+        pte_val(pte) |= _PAGE_MODIFIED;
+
+The pmd_wrprotect() fix handles the CONFIG_TRANSPARENT_HUGEPAGE case,
+where pmd entries need the same treatment.
+
+This ensures the software dirty tracking bit (checked by pte_dirty() and
+pmd_dirty(), which read both the _PAGE_DIRTY and _PAGE_MODIFIED bits) is
+preserved across fork COW write-protection.
+
+The issue was found by the LTP madvise09 test case, which exercises page
+reclaim after "madvise(MADV_FREE), write and fork" operation sequence on
+private anonymous mappings.
+
+Cc: stable@vger.kernel.org
+Fixes: 09cfefb7fa70 ("LoongArch: Add memory management")
+Co-developed-by: Tianyang Zhang <zhangtianyang@loongson.cn>
+Signed-off-by: Tianyang Zhang <zhangtianyang@loongson.cn>
+Signed-off-by: Hongchen Zhang <zhanghongchen@loongson.cn>
+Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ arch/loongarch/include/asm/pgtable.h |    4 ++++
+ 1 file changed, 4 insertions(+)
+
+--- a/arch/loongarch/include/asm/pgtable.h
++++ b/arch/loongarch/include/asm/pgtable.h
+@@ -410,6 +410,8 @@ static inline pte_t pte_mkwrite_novma(pt
+ static inline pte_t pte_wrprotect(pte_t pte)
+ {
++      if (pte_val(pte) & _PAGE_DIRTY)
++              pte_val(pte) |= _PAGE_MODIFIED;
+       pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+       return pte;
+ }
+@@ -522,6 +524,8 @@ static inline pmd_t pmd_mkwrite_novma(pm
+ static inline pmd_t pmd_wrprotect(pmd_t pmd)
+ {
++      if (pmd_val(pmd) & _PAGE_DIRTY)
++              pmd_val(pmd) |= _PAGE_MODIFIED;
+       pmd_val(pmd) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+       return pmd;
+ }
diff --git a/queue-6.6/rtc-mpfs-fix-counter-upload-completion-condition.patch b/queue-6.6/rtc-mpfs-fix-counter-upload-completion-condition.patch
new file mode 100644 (file)
index 0000000..489b886
--- /dev/null
@@ -0,0 +1,45 @@
+From 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 Mon Sep 17 00:00:00 2001
+From: Conor Dooley <conor.dooley@microchip.com>
+Date: Wed, 13 May 2026 18:55:55 +0100
+Subject: rtc: mpfs: fix counter upload completion condition
+
+From: Conor Dooley <conor.dooley@microchip.com>
+
+commit 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 upstream.
+
+The condition that needs to be checked for upload completion is the
+UPLOAD bit in the completion register going low. The original iterations
+of this driver used a do-while and this was converted to a
+read_poll_timeout() during upstreaming without the condition being
+inverted as it should have been.
+
+I suspect that this went unnoticed until now because a) the first read
+was done when the bit was still set, immediately completing the
+read_poll_timeout() and b) because the RTC doesn't hold time when power
+is removed from the SoC reducing its utility (I for one keep it
+disabled). If my first suspicion was true when the driver was
+upstreamed, it's not true any longer though, hence the detection of the
+problem.
+
+Fixes: 0b31d703598dc ("rtc: Add driver for Microchip PolarFire SoC")
+CC: stable@vger.kernel.org
+Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
+Tested-by: Valentina Fernandez <valentina.fernandezalanis@microchip.com>
+Link: https://patch.msgid.link/20260513-panhandle-ashy-70c6abf84d59@spud
+Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/rtc/rtc-mpfs.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/rtc/rtc-mpfs.c
++++ b/drivers/rtc/rtc-mpfs.c
+@@ -112,7 +112,7 @@ static int mpfs_rtc_settime(struct devic
+       ctrl |= CONTROL_UPLOAD_BIT;
+       writel(ctrl, rtcdev->base + CONTROL_REG);
+-      ret = read_poll_timeout(readl, prog, prog & CONTROL_UPLOAD_BIT, 0, UPLOAD_TIMEOUT_US,
++      ret = read_poll_timeout(readl, prog, !(prog & CONTROL_UPLOAD_BIT), 0, UPLOAD_TIMEOUT_US,
+                               false, rtcdev->base + CONTROL_REG);
+       if (ret) {
+               dev_err(dev, "timed out uploading time to rtc");
index d1aaa55b7e3ca5e0d4cb19e8093f57abdca488f6..159ea1499c8c3d5695b4c905b4ab67087c401d50 100644 (file)
@@ -1095,3 +1095,7 @@ net-sched-sch_teql-move-rcu_read_lock-spin_lock-from-_bh-variants.patch
 batman-adv-retrieve-ethhdr-after-potential-skb-reall.patch
 batman-adv-ensure-minimal-ethernet-header-on-tx.patch
 batman-adv-clean-untagged-vlan-on-netdev-registratio.patch
+loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
+espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
+bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
+rtc-mpfs-fix-counter-upload-completion-condition.patch