]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
6.18-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 08:50:47 +0000 (10:50 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 08:50:47 +0000 (10:50 +0200)
added patches:
bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
ipmi-fix-refcount-leak-in-i_ipmi_request.patch
ipmi-fix-user-refcount-underflow-in-event-delivery.patch
loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch
pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch
rtc-mpfs-fix-counter-upload-completion-condition.patch
rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch

queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch [new file with mode: 0644]
queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch [new file with mode: 0644]
queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch [new file with mode: 0644]
queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch [new file with mode: 0644]
queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch [new file with mode: 0644]
queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch [new file with mode: 0644]
queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch [new file with mode: 0644]
queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch [new file with mode: 0644]
queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch [new file with mode: 0644]
queue-6.18/series

diff --git a/queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch b/queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
new file mode 100644 (file)
index 0000000..c247034
--- /dev/null
@@ -0,0 +1,43 @@
+From a986fde914d88af47eb78fd29c5d1af7952c3500 Mon Sep 17 00:00:00 2001
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Date: Sat, 20 Jun 2026 11:53:50 +0530
+Subject: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
+
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+
+commit a986fde914d88af47eb78fd29c5d1af7952c3500 upstream.
+
+If the allocation of fp[i].tpa_info fails, the error path will not free
+the struct bnx2x_fastpath allocated earlier, as it is not linked to the
+bp structure yet. Fix that by linking it immediately after allocation.
+
+Cc: stable@vger.kernel.org
+Fixes: 15192a8cf8a8 ("bnx2x: Split the FP structure")
+Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Reviewed-by: Simon Horman <horms@kernel.org>
+Link: https://patch.msgid.link/20260620062402.89549-1-nihaal@cse.iitm.ac.in
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c |    3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+--- a/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c
++++ b/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c
+@@ -4750,6 +4750,7 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp)
+       fp = kcalloc(bp->fp_array_size, sizeof(*fp), GFP_KERNEL);
+       if (!fp)
+               goto alloc_err;
++      bp->fp = fp;
+       for (i = 0; i < bp->fp_array_size; i++) {
+               fp[i].tpa_info =
+                       kcalloc(ETH_MAX_AGGREGATION_QUEUES_E1H_E2,
+@@ -4758,8 +4759,6 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp)
+                       goto alloc_err;
+       }
+-      bp->fp = fp;
+-
+       /* allocate sp objs */
+       bp->sp_objs = kcalloc(bp->fp_array_size, sizeof(struct bnx2x_sp_objs),
+                             GFP_KERNEL);
diff --git a/queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch b/queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
new file mode 100644 (file)
index 0000000..d8e51c4
--- /dev/null
@@ -0,0 +1,78 @@
+From 007800408002d871f5699bdb944f985896730b8f Mon Sep 17 00:00:00 2001
+From: Sabrina Dubroca <sd@queasysnail.net>
+Date: Fri, 12 Jun 2026 16:11:39 +0200
+Subject: espintcp: use sk_msg_free_partial to fix partial send
+
+From: Sabrina Dubroca <sd@queasysnail.net>
+
+commit 007800408002d871f5699bdb944f985896730b8f upstream.
+
+sk_msg_free_partial() ensures consistency of the skmsg at every
+iteration, without having to manually handle uncharges and offsets.
+This simplifies the code, and fixes some bugs in skmsg accounting when
+we don't send the full contents.
+
+Cc: stable@vger.kernel.org
+Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
+Reported-by: Aaron Esau <aaron1esau@gmail.com>
+Reported-by: Yiming Qian <yimingqian591@gmail.com>
+Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
+Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ net/xfrm/espintcp.c |   34 +++++++---------------------------
+ 1 file changed, 7 insertions(+), 27 deletions(-)
+
+--- a/net/xfrm/espintcp.c
++++ b/net/xfrm/espintcp.c
+@@ -215,43 +215,23 @@ static int espintcp_sendskmsg_locked(str
+       struct sk_msg *skmsg = &emsg->skmsg;
+       bool more = flags & MSG_MORE;
+       struct scatterlist *sg;
+-      int done = 0;
+       int ret;
+-      sg = &skmsg->sg.data[skmsg->sg.start];
+       do {
+               struct bio_vec bvec;
+-              size_t size = sg->length - emsg->offset;
+-              int offset = sg->offset + emsg->offset;
+-              struct page *p;
+-
+-              emsg->offset = 0;
++              sg = &skmsg->sg.data[skmsg->sg.start];
+               if (sg_is_last(sg) && !more)
+                       msghdr.msg_flags &= ~MSG_MORE;
+-              p = sg_page(sg);
+-retry:
+-              bvec_set_page(&bvec, p, size, offset);
+-              iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, size);
+-              ret = tcp_sendmsg_locked(sk, &msghdr, size);
+-              if (ret < 0) {
+-                      emsg->offset = offset - sg->offset;
+-                      skmsg->sg.start += done;
++              bvec_set_page(&bvec, sg_page(sg), sg->length, sg->offset);
++              iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, sg->length);
++              ret = tcp_sendmsg_locked(sk, &msghdr, sg->length);
++              if (ret < 0)
+                       return ret;
+-              }
+-              if (ret != size) {
+-                      offset += ret;
+-                      size -= ret;
+-                      goto retry;
+-              }
+-
+-              done++;
+-              put_page(p);
+-              sk_mem_uncharge(sk, sg->length);
+-              sg = sg_next(sg);
+-      } while (sg);
++              sk_msg_free_partial(sk, skmsg, ret);
++      } while (skmsg->sg.size);
+       memset(emsg, 0, sizeof(*emsg));
diff --git a/queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch b/queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch
new file mode 100644 (file)
index 0000000..92bd9fa
--- /dev/null
@@ -0,0 +1,55 @@
+From a3f3859cecacb64f18fd446271ece9a3b3f2d4de Mon Sep 17 00:00:00 2001
+From: Wentao Liang <vulab@iscas.ac.cn>
+Date: Wed, 3 Jun 2026 12:06:34 +0000
+Subject: ipmi: fix refcount leak in i_ipmi_request()
+
+From: Wentao Liang <vulab@iscas.ac.cn>
+
+commit a3f3859cecacb64f18fd446271ece9a3b3f2d4de upstream.
+
+When a caller provides a `supplied_recv` message to i_ipmi_request(),
+the function increments the user's `nr_msgs` reference count. If an
+error occurs later, the out_err cleanup path only frees the recv_msg
+if the function allocated it itself (i.e., !supplied_recv). In the
+supplied_recv case the cleanup is skipped, leaving the reference count
+elevated. The caller ipmi_request_supply_msgs() does not release the
+supplied_recv on error, so the reference is permanently leaked.
+
+Fix this by explicitly reverting the reference count operations when a
+supplied recv_msg with a valid user pointer is present in the error
+path: decrement nr_msgs and drop the user's kref.
+
+Cc: stable@vger.kernel.org
+Fixes: b52da4054ee0 ("ipmi: Rework user message limit handling")
+Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
+Message-ID: <20260603120634.3758747-1-vulab@iscas.ac.cn>
+Signed-off-by: Corey Minyard <corey@minyard.net>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/char/ipmi/ipmi_msghandler.c |    8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+--- a/drivers/char/ipmi/ipmi_msghandler.c
++++ b/drivers/char/ipmi/ipmi_msghandler.c
+@@ -2349,6 +2349,10 @@ static int i_ipmi_request(struct ipmi_us
+               if (smi_msg == NULL) {
+                       if (!supplied_recv)
+                               ipmi_free_recv_msg(recv_msg);
++                      else if (recv_msg->user) {
++                              atomic_dec(&recv_msg->user->nr_msgs);
++                              kref_put(&recv_msg->user->refcount, free_ipmi_user);
++                      }
+                       return -ENOMEM;
+               }
+       }
+@@ -2422,6 +2426,10 @@ out_err:
+                       ipmi_free_smi_msg(smi_msg);
+               if (!supplied_recv)
+                       ipmi_free_recv_msg(recv_msg);
++              else if (recv_msg->user) {
++                      atomic_dec(&recv_msg->user->nr_msgs);
++                      kref_put(&recv_msg->user->refcount, free_ipmi_user);
++              }
+       }
+       return rv;
+ }
diff --git a/queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch b/queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch
new file mode 100644 (file)
index 0000000..d9022d8
--- /dev/null
@@ -0,0 +1,48 @@
+From 6aa9e61c46465d231e9beddf56af7effd71be682 Mon Sep 17 00:00:00 2001
+From: Matt Fleming <mfleming@cloudflare.com>
+Date: Thu, 21 May 2026 14:06:27 +0100
+Subject: ipmi: Fix user refcount underflow in event delivery
+
+From: Matt Fleming <mfleming@cloudflare.com>
+
+commit 6aa9e61c46465d231e9beddf56af7effd71be682 upstream.
+
+ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the
+receive message, and ipmi_free_recv_msg() drops it again. If event delivery
+fails after allocating receive messages for earlier users,
+handle_read_event_rsp() rolls those messages back with
+ipmi_free_recv_msg().
+
+That rollback path still drops user->refcount explicitly after freeing each
+message. The extra put can free a user that remains linked on intf->users,
+so later event delivery may dereference a freed user or trip refcount_t's
+addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire
+another reference.
+
+Remove the stale explicit put and the now-dead user assignment. Keep the
+list_del() and ipmi_free_recv_msg() calls; they are the required rollback
+operations.
+
+Fixes: b52da4054ee0 ("ipmi: Rework user message limit handling")
+Cc: stable@vger.kernel.org # v6.18+
+Signed-off-by: Matt Fleming <mfleming@cloudflare.com>
+Message-ID: <20260521130628.3641050-1-matt@readmodwrite.com>
+Signed-off-by: Corey Minyard <corey@minyard.net>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/char/ipmi/ipmi_msghandler.c |    2 --
+ 1 file changed, 2 deletions(-)
+
+--- a/drivers/char/ipmi/ipmi_msghandler.c
++++ b/drivers/char/ipmi/ipmi_msghandler.c
+@@ -4475,10 +4475,8 @@ static int handle_read_event_rsp(struct
+                       mutex_unlock(&intf->users_mutex);
+                       list_for_each_entry_safe(recv_msg, recv_msg2, &msgs,
+                                                link) {
+-                              user = recv_msg->user;
+                               list_del(&recv_msg->link);
+                               ipmi_free_recv_msg(recv_msg);
+-                              kref_put(&user->refcount, free_ipmi_user);
+                       }
+                       /*
+                        * We couldn't allocate memory for the
diff --git a/queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch b/queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
new file mode 100644 (file)
index 0000000..254ad3e
--- /dev/null
@@ -0,0 +1,82 @@
+From 018e9828eb523c638fa3d9bdf0fd4956b74555b2 Mon Sep 17 00:00:00 2001
+From: Hongchen Zhang <zhanghongchen@loongson.cn>
+Date: Thu, 25 Jun 2026 13:03:49 +0800
+Subject: LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
+
+From: Hongchen Zhang <zhanghongchen@loongson.cn>
+
+commit 018e9828eb523c638fa3d9bdf0fd4956b74555b2 upstream.
+
+When hardware page table walker (PTW) is enabled on LoongArch, the CPU
+may set _PAGE_DIRTY directly in the page table entry during a write TLB
+miss, without going through the software TLB store handler. The software
+TLB store handler (tlbex.S:254) sets both _PAGE_DIRTY and_PAGE_MODIFIED
+together:
+
+    ori t0, t0, (_PAGE_VALID | _PAGE_DIRTY | _PAGE_MODIFIED)
+
+Since hardware PTW only sets _PAGE_DIRTY, the software-only bit, i.e.
+_PAGE_MODIFIED is left unchanged. This creates a window where a PTE has
+_PAGE_DIRTY set (hardware knows the page is dirty) but _PAGE_MODIFIED
+clear (software is unaware).
+
+When fork()/clone() triggers copy-on-write, __copy_present_ptes() calls
+pte_wrprotect(), which unconditionally clears both the _PAGE_WRITE and
+_PAGE_DIRTY bits:
+
+    pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+
+Since _PAGE_MODIFIED was never set, the dirtiness information is lost
+completely. Subsequently, when memory pressure triggers page reclaim,
+page_mkclean() / try_to_unmap() sees the page as clean (i.e. pte_dirty()
+returns false) and the page may be freed without writeback, causing data
+corruption.
+
+Fix this by propagating the _PAGE_DIRTY bit to the _PAGE_MODIFIED bit in
+both pte_wrprotect() and pmd_wrprotect() before clearing writeable bits:
+
+    if (pte_val(pte) & _PAGE_DIRTY)
+        pte_val(pte) |= _PAGE_MODIFIED;
+
+The pmd_wrprotect() fix handles the CONFIG_TRANSPARENT_HUGEPAGE case,
+where pmd entries need the same treatment.
+
+This ensures the software dirty tracking bit (checked by pte_dirty() and
+pmd_dirty(), which read both the _PAGE_DIRTY and _PAGE_MODIFIED bits) is
+preserved across fork COW write-protection.
+
+The issue was found by the LTP madvise09 test case, which exercises page
+reclaim after "madvise(MADV_FREE), write and fork" operation sequence on
+private anonymous mappings.
+
+Cc: stable@vger.kernel.org
+Fixes: 09cfefb7fa70 ("LoongArch: Add memory management")
+Co-developed-by: Tianyang Zhang <zhangtianyang@loongson.cn>
+Signed-off-by: Tianyang Zhang <zhangtianyang@loongson.cn>
+Signed-off-by: Hongchen Zhang <zhanghongchen@loongson.cn>
+Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ arch/loongarch/include/asm/pgtable.h |    4 ++++
+ 1 file changed, 4 insertions(+)
+
+--- a/arch/loongarch/include/asm/pgtable.h
++++ b/arch/loongarch/include/asm/pgtable.h
+@@ -392,6 +392,8 @@ static inline pte_t pte_mkwrite_novma(pt
+ static inline pte_t pte_wrprotect(pte_t pte)
+ {
++      if (pte_val(pte) & _PAGE_DIRTY)
++              pte_val(pte) |= _PAGE_MODIFIED;
+       pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+       return pte;
+ }
+@@ -498,6 +500,8 @@ static inline pmd_t pmd_mkwrite_novma(pm
+ static inline pmd_t pmd_wrprotect(pmd_t pmd)
+ {
++      if (pmd_val(pmd) & _PAGE_DIRTY)
++              pmd_val(pmd) |= _PAGE_MODIFIED;
+       pmd_val(pmd) &= ~(_PAGE_WRITE | _PAGE_DIRTY);
+       return pmd;
+ }
diff --git a/queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch b/queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch
new file mode 100644 (file)
index 0000000..04ea740
--- /dev/null
@@ -0,0 +1,33 @@
+From 70378a710598432f13509bdc16a1c0f06b3ecb53 Mon Sep 17 00:00:00 2001
+From: Xuewen Wang <wangxuewen@kylinos.cn>
+Date: Thu, 25 Jun 2026 13:03:49 +0800
+Subject: LoongArch: Fix nr passing in set_direct_map_valid_noflush()
+
+From: Xuewen Wang <wangxuewen@kylinos.cn>
+
+commit 70378a710598432f13509bdc16a1c0f06b3ecb53 upstream.
+
+set_direct_map_valid_noflush() incorrectly passes 1 to __set_memory()
+instead of nr. This causes only the first page's attr to be updated when
+nr > 1.
+
+Other architectures all pass nr correctly.
+
+Cc: stable@vger.kernel.org
+Fixes: 0c6378a71574 ("arch: introduce set_direct_map_valid_noflush()")
+Signed-off-by: Xuewen Wang <wangxuewen@kylinos.cn>
+Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ arch/loongarch/mm/pageattr.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/arch/loongarch/mm/pageattr.c
++++ b/arch/loongarch/mm/pageattr.c
+@@ -234,5 +234,5 @@ int set_direct_map_valid_noflush(struct
+               clear = __pgprot(_PAGE_PRESENT | _PAGE_VALID);
+       }
+-      return __set_memory(addr, 1, set, clear);
++      return __set_memory(addr, nr, set, clear);
+ }
diff --git a/queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch b/queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch
new file mode 100644 (file)
index 0000000..ade7c5c
--- /dev/null
@@ -0,0 +1,41 @@
+From 2b40d72de9354a76f5e3bb71230a4210eaa92849 Mon Sep 17 00:00:00 2001
+From: Biju Das <biju.das.jz@bp.renesas.com>
+Date: Thu, 4 Jun 2026 10:56:31 +0100
+Subject: pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+From: Biju Das <biju.das.jz@bp.renesas.com>
+
+commit 2b40d72de9354a76f5e3bb71230a4210eaa92849 upstream.
+
+period_ticks is used to store PWM period values that can exceed the 32-bit
+range, so change its type from u32 to u64 to prevent overflow.
+
+Cc: stable@kernel.org
+Fixes: 061f087f5d0b ("pwm: Add support for RZ/G2L GPT")
+Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
+Link: https://patch.msgid.link/20260604095647.108654-2-biju.das.jz@bp.renesas.com
+Signed-off-by: Uwe Kleine-König <ukleinek@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/pwm/pwm-rzg2l-gpt.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/drivers/pwm/pwm-rzg2l-gpt.c b/drivers/pwm/pwm-rzg2l-gpt.c
+index 4856af080e8e..c9dfa59bc1ea 100644
+--- a/drivers/pwm/pwm-rzg2l-gpt.c
++++ b/drivers/pwm/pwm-rzg2l-gpt.c
+@@ -81,7 +81,7 @@ struct rzg2l_gpt_chip {
+       void __iomem *mmio;
+       struct mutex lock; /* lock to protect shared channel resources */
+       unsigned long rate_khz;
+-      u32 period_ticks[RZG2L_MAX_HW_CHANNELS];
++      u64 period_ticks[RZG2L_MAX_HW_CHANNELS];
+       u32 channel_request_count[RZG2L_MAX_HW_CHANNELS];
+       u32 channel_enable_count[RZG2L_MAX_HW_CHANNELS];
+ };
+-- 
+2.55.0
+
diff --git a/queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch b/queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch
new file mode 100644 (file)
index 0000000..489b886
--- /dev/null
@@ -0,0 +1,45 @@
+From 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 Mon Sep 17 00:00:00 2001
+From: Conor Dooley <conor.dooley@microchip.com>
+Date: Wed, 13 May 2026 18:55:55 +0100
+Subject: rtc: mpfs: fix counter upload completion condition
+
+From: Conor Dooley <conor.dooley@microchip.com>
+
+commit 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 upstream.
+
+The condition that needs to be checked for upload completion is the
+UPLOAD bit in the completion register going low. The original iterations
+of this driver used a do-while and this was converted to a
+read_poll_timeout() during upstreaming without the condition being
+inverted as it should have been.
+
+I suspect that this went unnoticed until now because a) the first read
+was done when the bit was still set, immediately completing the
+read_poll_timeout() and b) because the RTC doesn't hold time when power
+is removed from the SoC reducing its utility (I for one keep it
+disabled). If my first suspicion was true when the driver was
+upstreamed, it's not true any longer though, hence the detection of the
+problem.
+
+Fixes: 0b31d703598dc ("rtc: Add driver for Microchip PolarFire SoC")
+CC: stable@vger.kernel.org
+Signed-off-by: Conor Dooley <conor.dooley@microchip.com>
+Tested-by: Valentina Fernandez <valentina.fernandezalanis@microchip.com>
+Link: https://patch.msgid.link/20260513-panhandle-ashy-70c6abf84d59@spud
+Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/rtc/rtc-mpfs.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/rtc/rtc-mpfs.c
++++ b/drivers/rtc/rtc-mpfs.c
+@@ -112,7 +112,7 @@ static int mpfs_rtc_settime(struct devic
+       ctrl |= CONTROL_UPLOAD_BIT;
+       writel(ctrl, rtcdev->base + CONTROL_REG);
+-      ret = read_poll_timeout(readl, prog, prog & CONTROL_UPLOAD_BIT, 0, UPLOAD_TIMEOUT_US,
++      ret = read_poll_timeout(readl, prog, !(prog & CONTROL_UPLOAD_BIT), 0, UPLOAD_TIMEOUT_US,
+                               false, rtcdev->base + CONTROL_REG);
+       if (ret) {
+               dev_err(dev, "timed out uploading time to rtc");
diff --git a/queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch b/queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch
new file mode 100644 (file)
index 0000000..81d721a
--- /dev/null
@@ -0,0 +1,50 @@
+From 7e342d87aa8e6b831cf6d21ca41b1f7e032d0fcf Mon Sep 17 00:00:00 2001
+From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
+Date: Tue, 2 Jun 2026 20:25:55 +0100
+Subject: rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
+
+From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
+
+commit 7e342d87aa8e6b831cf6d21ca41b1f7e032d0fcf upstream.
+
+In rtca3_set_alarm(), the setup_failed path attempts to disable the
+Periodic Interrupt Enable (PIE) bit and wait until it is cleared.
+However, the polling condition passed to readb_poll_timeout_atomic()
+uses an incorrect expression:
+
+    !(tmp & ~RTCA3_RCR1_PIE)
+
+As ~RTCA3_RCR1_PIE evaluates to a mask of all bits except PIE, the
+condition effectively waits for all non-PIE bits to become zero, which
+is unrelated to the intended operation and is unlikely to ever be true.
+This causes the poll to time out unnecessarily.
+
+Fix the condition to check for the PIE bit itself being cleared:
+
+    !(tmp & RTCA3_RCR1_PIE)
+
+This correctly waits until PIE is deasserted after being cleared.
+
+Fixes: d4488377609e3 ("rtc: renesas-rtca3: Add driver for RTCA-3 available on Renesas RZ/G3S SoC")
+Cc: stable@vger.kernel.org
+Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
+Reviewed-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
+Tested-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com> # on RZ/G3S
+Link: https://patch.msgid.link/20260602192559.1791344-2-prabhakar.mahadev-lad.rj@bp.renesas.com
+Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/rtc/rtc-renesas-rtca3.c |    2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/rtc/rtc-renesas-rtca3.c
++++ b/drivers/rtc/rtc-renesas-rtca3.c
+@@ -455,7 +455,7 @@ setup_failed:
+                * specified timeout for setup.
+                */
+               writeb(rcr1 & ~RTCA3_RCR1_PIE, priv->base + RTCA3_RCR1);
+-              readb_poll_timeout_atomic(priv->base + RTCA3_RCR1, tmp, !(tmp & ~RTCA3_RCR1_PIE),
++              readb_poll_timeout_atomic(priv->base + RTCA3_RCR1, tmp, !(tmp & RTCA3_RCR1_PIE),
+                                         10, RTCA3_DEFAULT_TIMEOUT_US);
+               atomic_set(&priv->alrm_sstep, RTCA3_ALRM_SSTEP_DONE);
+       }
index 17c37f0987e726dbb229c565e6011d2b5bda153d..34b76263e8be8d0705cef1cbd779d9767d42cf77 100644 (file)
@@ -1423,3 +1423,12 @@ net-sched-sch_teql-move-rcu_read_lock-spin_lock-from-_bh-variants.patch
 drm-xe-userptr-stub-notifier_lock-helpers-when-drm_gpusvm-n.patch
 kvm-tdx-account-all-non-transient-page-allocations-f.patch
 selftests-bpf-add-simple-strscpy-implementation.patch
+pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch
+loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch
+loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch
+ipmi-fix-user-refcount-underflow-in-event-delivery.patch
+espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch
+ipmi-fix-refcount-leak-in-i_ipmi_request.patch
+bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch
+rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch
+rtc-mpfs-fix-counter-upload-completion-condition.patch