From: Greg Kroah-Hartman Date: Tue, 21 Jul 2026 08:50:47 +0000 (+0200) Subject: 6.18-stable patches X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e9ac7348954ef5071f8121276169dc32148d67a7;p=thirdparty%2Fkernel%2Fstable-queue.git 6.18-stable patches added patches: bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch ipmi-fix-refcount-leak-in-i_ipmi_request.patch ipmi-fix-user-refcount-underflow-in-event-delivery.patch loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch rtc-mpfs-fix-counter-upload-completion-condition.patch rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch --- diff --git a/queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch b/queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch new file mode 100644 index 0000000000..c247034ab4 --- /dev/null +++ b/queue-6.18/bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch @@ -0,0 +1,43 @@ +From a986fde914d88af47eb78fd29c5d1af7952c3500 Mon Sep 17 00:00:00 2001 +From: Abdun Nihaal +Date: Sat, 20 Jun 2026 11:53:50 +0530 +Subject: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() + +From: Abdun Nihaal + +commit a986fde914d88af47eb78fd29c5d1af7952c3500 upstream. + +If the allocation of fp[i].tpa_info fails, the error path will not free +the struct bnx2x_fastpath allocated earlier, as it is not linked to the +bp structure yet. Fix that by linking it immediately after allocation. + +Cc: stable@vger.kernel.org +Fixes: 15192a8cf8a8 ("bnx2x: Split the FP structure") +Signed-off-by: Abdun Nihaal +Reviewed-by: Simon Horman +Link: https://patch.msgid.link/20260620062402.89549-1-nihaal@cse.iitm.ac.in +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +--- a/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c ++++ b/drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c +@@ -4750,6 +4750,7 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp) + fp = kcalloc(bp->fp_array_size, sizeof(*fp), GFP_KERNEL); + if (!fp) + goto alloc_err; ++ bp->fp = fp; + for (i = 0; i < bp->fp_array_size; i++) { + fp[i].tpa_info = + kcalloc(ETH_MAX_AGGREGATION_QUEUES_E1H_E2, +@@ -4758,8 +4759,6 @@ int bnx2x_alloc_mem_bp(struct bnx2x *bp) + goto alloc_err; + } + +- bp->fp = fp; +- + /* allocate sp objs */ + bp->sp_objs = kcalloc(bp->fp_array_size, sizeof(struct bnx2x_sp_objs), + GFP_KERNEL); diff --git a/queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch b/queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch new file mode 100644 index 0000000000..d8e51c4201 --- /dev/null +++ b/queue-6.18/espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch @@ -0,0 +1,78 @@ +From 007800408002d871f5699bdb944f985896730b8f Mon Sep 17 00:00:00 2001 +From: Sabrina Dubroca +Date: Fri, 12 Jun 2026 16:11:39 +0200 +Subject: espintcp: use sk_msg_free_partial to fix partial send + +From: Sabrina Dubroca + +commit 007800408002d871f5699bdb944f985896730b8f upstream. + +sk_msg_free_partial() ensures consistency of the skmsg at every +iteration, without having to manually handle uncharges and offsets. +This simplifies the code, and fixes some bugs in skmsg accounting when +we don't send the full contents. + +Cc: stable@vger.kernel.org +Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)") +Reported-by: Aaron Esau +Reported-by: Yiming Qian +Signed-off-by: Sabrina Dubroca +Signed-off-by: Steffen Klassert +Signed-off-by: Greg Kroah-Hartman +--- + net/xfrm/espintcp.c | 34 +++++++--------------------------- + 1 file changed, 7 insertions(+), 27 deletions(-) + +--- a/net/xfrm/espintcp.c ++++ b/net/xfrm/espintcp.c +@@ -215,43 +215,23 @@ static int espintcp_sendskmsg_locked(str + struct sk_msg *skmsg = &emsg->skmsg; + bool more = flags & MSG_MORE; + struct scatterlist *sg; +- int done = 0; + int ret; + +- sg = &skmsg->sg.data[skmsg->sg.start]; + do { + struct bio_vec bvec; +- size_t size = sg->length - emsg->offset; +- int offset = sg->offset + emsg->offset; +- struct page *p; +- +- emsg->offset = 0; + ++ sg = &skmsg->sg.data[skmsg->sg.start]; + if (sg_is_last(sg) && !more) + msghdr.msg_flags &= ~MSG_MORE; + +- p = sg_page(sg); +-retry: +- bvec_set_page(&bvec, p, size, offset); +- iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, size); +- ret = tcp_sendmsg_locked(sk, &msghdr, size); +- if (ret < 0) { +- emsg->offset = offset - sg->offset; +- skmsg->sg.start += done; ++ bvec_set_page(&bvec, sg_page(sg), sg->length, sg->offset); ++ iov_iter_bvec(&msghdr.msg_iter, ITER_SOURCE, &bvec, 1, sg->length); ++ ret = tcp_sendmsg_locked(sk, &msghdr, sg->length); ++ if (ret < 0) + return ret; +- } + +- if (ret != size) { +- offset += ret; +- size -= ret; +- goto retry; +- } +- +- done++; +- put_page(p); +- sk_mem_uncharge(sk, sg->length); +- sg = sg_next(sg); +- } while (sg); ++ sk_msg_free_partial(sk, skmsg, ret); ++ } while (skmsg->sg.size); + + memset(emsg, 0, sizeof(*emsg)); + diff --git a/queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch b/queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch new file mode 100644 index 0000000000..92bd9fab83 --- /dev/null +++ b/queue-6.18/ipmi-fix-refcount-leak-in-i_ipmi_request.patch @@ -0,0 +1,55 @@ +From a3f3859cecacb64f18fd446271ece9a3b3f2d4de Mon Sep 17 00:00:00 2001 +From: Wentao Liang +Date: Wed, 3 Jun 2026 12:06:34 +0000 +Subject: ipmi: fix refcount leak in i_ipmi_request() + +From: Wentao Liang + +commit a3f3859cecacb64f18fd446271ece9a3b3f2d4de upstream. + +When a caller provides a `supplied_recv` message to i_ipmi_request(), +the function increments the user's `nr_msgs` reference count. If an +error occurs later, the out_err cleanup path only frees the recv_msg +if the function allocated it itself (i.e., !supplied_recv). In the +supplied_recv case the cleanup is skipped, leaving the reference count +elevated. The caller ipmi_request_supply_msgs() does not release the +supplied_recv on error, so the reference is permanently leaked. + +Fix this by explicitly reverting the reference count operations when a +supplied recv_msg with a valid user pointer is present in the error +path: decrement nr_msgs and drop the user's kref. + +Cc: stable@vger.kernel.org +Fixes: b52da4054ee0 ("ipmi: Rework user message limit handling") +Signed-off-by: Wentao Liang +Message-ID: <20260603120634.3758747-1-vulab@iscas.ac.cn> +Signed-off-by: Corey Minyard +Signed-off-by: Greg Kroah-Hartman +--- + drivers/char/ipmi/ipmi_msghandler.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +--- a/drivers/char/ipmi/ipmi_msghandler.c ++++ b/drivers/char/ipmi/ipmi_msghandler.c +@@ -2349,6 +2349,10 @@ static int i_ipmi_request(struct ipmi_us + if (smi_msg == NULL) { + if (!supplied_recv) + ipmi_free_recv_msg(recv_msg); ++ else if (recv_msg->user) { ++ atomic_dec(&recv_msg->user->nr_msgs); ++ kref_put(&recv_msg->user->refcount, free_ipmi_user); ++ } + return -ENOMEM; + } + } +@@ -2422,6 +2426,10 @@ out_err: + ipmi_free_smi_msg(smi_msg); + if (!supplied_recv) + ipmi_free_recv_msg(recv_msg); ++ else if (recv_msg->user) { ++ atomic_dec(&recv_msg->user->nr_msgs); ++ kref_put(&recv_msg->user->refcount, free_ipmi_user); ++ } + } + return rv; + } diff --git a/queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch b/queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch new file mode 100644 index 0000000000..d9022d87e9 --- /dev/null +++ b/queue-6.18/ipmi-fix-user-refcount-underflow-in-event-delivery.patch @@ -0,0 +1,48 @@ +From 6aa9e61c46465d231e9beddf56af7effd71be682 Mon Sep 17 00:00:00 2001 +From: Matt Fleming +Date: Thu, 21 May 2026 14:06:27 +0100 +Subject: ipmi: Fix user refcount underflow in event delivery + +From: Matt Fleming + +commit 6aa9e61c46465d231e9beddf56af7effd71be682 upstream. + +ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the +receive message, and ipmi_free_recv_msg() drops it again. If event delivery +fails after allocating receive messages for earlier users, +handle_read_event_rsp() rolls those messages back with +ipmi_free_recv_msg(). + +That rollback path still drops user->refcount explicitly after freeing each +message. The extra put can free a user that remains linked on intf->users, +so later event delivery may dereference a freed user or trip refcount_t's +addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire +another reference. + +Remove the stale explicit put and the now-dead user assignment. Keep the +list_del() and ipmi_free_recv_msg() calls; they are the required rollback +operations. + +Fixes: b52da4054ee0 ("ipmi: Rework user message limit handling") +Cc: stable@vger.kernel.org # v6.18+ +Signed-off-by: Matt Fleming +Message-ID: <20260521130628.3641050-1-matt@readmodwrite.com> +Signed-off-by: Corey Minyard +Signed-off-by: Greg Kroah-Hartman +--- + drivers/char/ipmi/ipmi_msghandler.c | 2 -- + 1 file changed, 2 deletions(-) + +--- a/drivers/char/ipmi/ipmi_msghandler.c ++++ b/drivers/char/ipmi/ipmi_msghandler.c +@@ -4475,10 +4475,8 @@ static int handle_read_event_rsp(struct + mutex_unlock(&intf->users_mutex); + list_for_each_entry_safe(recv_msg, recv_msg2, &msgs, + link) { +- user = recv_msg->user; + list_del(&recv_msg->link); + ipmi_free_recv_msg(recv_msg); +- kref_put(&user->refcount, free_ipmi_user); + } + /* + * We couldn't allocate memory for the diff --git a/queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch b/queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch new file mode 100644 index 0000000000..254ad3e094 --- /dev/null +++ b/queue-6.18/loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch @@ -0,0 +1,82 @@ +From 018e9828eb523c638fa3d9bdf0fd4956b74555b2 Mon Sep 17 00:00:00 2001 +From: Hongchen Zhang +Date: Thu, 25 Jun 2026 13:03:49 +0800 +Subject: LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect() + +From: Hongchen Zhang + +commit 018e9828eb523c638fa3d9bdf0fd4956b74555b2 upstream. + +When hardware page table walker (PTW) is enabled on LoongArch, the CPU +may set _PAGE_DIRTY directly in the page table entry during a write TLB +miss, without going through the software TLB store handler. The software +TLB store handler (tlbex.S:254) sets both _PAGE_DIRTY and_PAGE_MODIFIED +together: + + ori t0, t0, (_PAGE_VALID | _PAGE_DIRTY | _PAGE_MODIFIED) + +Since hardware PTW only sets _PAGE_DIRTY, the software-only bit, i.e. +_PAGE_MODIFIED is left unchanged. This creates a window where a PTE has +_PAGE_DIRTY set (hardware knows the page is dirty) but _PAGE_MODIFIED +clear (software is unaware). + +When fork()/clone() triggers copy-on-write, __copy_present_ptes() calls +pte_wrprotect(), which unconditionally clears both the _PAGE_WRITE and +_PAGE_DIRTY bits: + + pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY); + +Since _PAGE_MODIFIED was never set, the dirtiness information is lost +completely. Subsequently, when memory pressure triggers page reclaim, +page_mkclean() / try_to_unmap() sees the page as clean (i.e. pte_dirty() +returns false) and the page may be freed without writeback, causing data +corruption. + +Fix this by propagating the _PAGE_DIRTY bit to the _PAGE_MODIFIED bit in +both pte_wrprotect() and pmd_wrprotect() before clearing writeable bits: + + if (pte_val(pte) & _PAGE_DIRTY) + pte_val(pte) |= _PAGE_MODIFIED; + +The pmd_wrprotect() fix handles the CONFIG_TRANSPARENT_HUGEPAGE case, +where pmd entries need the same treatment. + +This ensures the software dirty tracking bit (checked by pte_dirty() and +pmd_dirty(), which read both the _PAGE_DIRTY and _PAGE_MODIFIED bits) is +preserved across fork COW write-protection. + +The issue was found by the LTP madvise09 test case, which exercises page +reclaim after "madvise(MADV_FREE), write and fork" operation sequence on +private anonymous mappings. + +Cc: stable@vger.kernel.org +Fixes: 09cfefb7fa70 ("LoongArch: Add memory management") +Co-developed-by: Tianyang Zhang +Signed-off-by: Tianyang Zhang +Signed-off-by: Hongchen Zhang +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/include/asm/pgtable.h | 4 ++++ + 1 file changed, 4 insertions(+) + +--- a/arch/loongarch/include/asm/pgtable.h ++++ b/arch/loongarch/include/asm/pgtable.h +@@ -392,6 +392,8 @@ static inline pte_t pte_mkwrite_novma(pt + + static inline pte_t pte_wrprotect(pte_t pte) + { ++ if (pte_val(pte) & _PAGE_DIRTY) ++ pte_val(pte) |= _PAGE_MODIFIED; + pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY); + return pte; + } +@@ -498,6 +500,8 @@ static inline pmd_t pmd_mkwrite_novma(pm + + static inline pmd_t pmd_wrprotect(pmd_t pmd) + { ++ if (pmd_val(pmd) & _PAGE_DIRTY) ++ pmd_val(pmd) |= _PAGE_MODIFIED; + pmd_val(pmd) &= ~(_PAGE_WRITE | _PAGE_DIRTY); + return pmd; + } diff --git a/queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch b/queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch new file mode 100644 index 0000000000..04ea740326 --- /dev/null +++ b/queue-6.18/loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch @@ -0,0 +1,33 @@ +From 70378a710598432f13509bdc16a1c0f06b3ecb53 Mon Sep 17 00:00:00 2001 +From: Xuewen Wang +Date: Thu, 25 Jun 2026 13:03:49 +0800 +Subject: LoongArch: Fix nr passing in set_direct_map_valid_noflush() + +From: Xuewen Wang + +commit 70378a710598432f13509bdc16a1c0f06b3ecb53 upstream. + +set_direct_map_valid_noflush() incorrectly passes 1 to __set_memory() +instead of nr. This causes only the first page's attr to be updated when +nr > 1. + +Other architectures all pass nr correctly. + +Cc: stable@vger.kernel.org +Fixes: 0c6378a71574 ("arch: introduce set_direct_map_valid_noflush()") +Signed-off-by: Xuewen Wang +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/mm/pageattr.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/loongarch/mm/pageattr.c ++++ b/arch/loongarch/mm/pageattr.c +@@ -234,5 +234,5 @@ int set_direct_map_valid_noflush(struct + clear = __pgprot(_PAGE_PRESENT | _PAGE_VALID); + } + +- return __set_memory(addr, 1, set, clear); ++ return __set_memory(addr, nr, set, clear); + } diff --git a/queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch b/queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch new file mode 100644 index 0000000000..ade7c5cc8e --- /dev/null +++ b/queue-6.18/pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch @@ -0,0 +1,41 @@ +From 2b40d72de9354a76f5e3bb71230a4210eaa92849 Mon Sep 17 00:00:00 2001 +From: Biju Das +Date: Thu, 4 Jun 2026 10:56:31 +0100 +Subject: pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64 +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Biju Das + +commit 2b40d72de9354a76f5e3bb71230a4210eaa92849 upstream. + +period_ticks is used to store PWM period values that can exceed the 32-bit +range, so change its type from u32 to u64 to prevent overflow. + +Cc: stable@kernel.org +Fixes: 061f087f5d0b ("pwm: Add support for RZ/G2L GPT") +Signed-off-by: Biju Das +Link: https://patch.msgid.link/20260604095647.108654-2-biju.das.jz@bp.renesas.com +Signed-off-by: Uwe Kleine-König +Signed-off-by: Greg Kroah-Hartman +--- + drivers/pwm/pwm-rzg2l-gpt.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/drivers/pwm/pwm-rzg2l-gpt.c b/drivers/pwm/pwm-rzg2l-gpt.c +index 4856af080e8e..c9dfa59bc1ea 100644 +--- a/drivers/pwm/pwm-rzg2l-gpt.c ++++ b/drivers/pwm/pwm-rzg2l-gpt.c +@@ -81,7 +81,7 @@ struct rzg2l_gpt_chip { + void __iomem *mmio; + struct mutex lock; /* lock to protect shared channel resources */ + unsigned long rate_khz; +- u32 period_ticks[RZG2L_MAX_HW_CHANNELS]; ++ u64 period_ticks[RZG2L_MAX_HW_CHANNELS]; + u32 channel_request_count[RZG2L_MAX_HW_CHANNELS]; + u32 channel_enable_count[RZG2L_MAX_HW_CHANNELS]; + }; +-- +2.55.0 + diff --git a/queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch b/queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch new file mode 100644 index 0000000000..489b8865dd --- /dev/null +++ b/queue-6.18/rtc-mpfs-fix-counter-upload-completion-condition.patch @@ -0,0 +1,45 @@ +From 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 Mon Sep 17 00:00:00 2001 +From: Conor Dooley +Date: Wed, 13 May 2026 18:55:55 +0100 +Subject: rtc: mpfs: fix counter upload completion condition + +From: Conor Dooley + +commit 9792ff8afa9017fe14f436f3ef3cd75f41f9f145 upstream. + +The condition that needs to be checked for upload completion is the +UPLOAD bit in the completion register going low. The original iterations +of this driver used a do-while and this was converted to a +read_poll_timeout() during upstreaming without the condition being +inverted as it should have been. + +I suspect that this went unnoticed until now because a) the first read +was done when the bit was still set, immediately completing the +read_poll_timeout() and b) because the RTC doesn't hold time when power +is removed from the SoC reducing its utility (I for one keep it +disabled). If my first suspicion was true when the driver was +upstreamed, it's not true any longer though, hence the detection of the +problem. + +Fixes: 0b31d703598dc ("rtc: Add driver for Microchip PolarFire SoC") +CC: stable@vger.kernel.org +Signed-off-by: Conor Dooley +Tested-by: Valentina Fernandez +Link: https://patch.msgid.link/20260513-panhandle-ashy-70c6abf84d59@spud +Signed-off-by: Alexandre Belloni +Signed-off-by: Greg Kroah-Hartman +--- + drivers/rtc/rtc-mpfs.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/drivers/rtc/rtc-mpfs.c ++++ b/drivers/rtc/rtc-mpfs.c +@@ -112,7 +112,7 @@ static int mpfs_rtc_settime(struct devic + ctrl |= CONTROL_UPLOAD_BIT; + writel(ctrl, rtcdev->base + CONTROL_REG); + +- ret = read_poll_timeout(readl, prog, prog & CONTROL_UPLOAD_BIT, 0, UPLOAD_TIMEOUT_US, ++ ret = read_poll_timeout(readl, prog, !(prog & CONTROL_UPLOAD_BIT), 0, UPLOAD_TIMEOUT_US, + false, rtcdev->base + CONTROL_REG); + if (ret) { + dev_err(dev, "timed out uploading time to rtc"); diff --git a/queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch b/queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch new file mode 100644 index 0000000000..81d721ac2f --- /dev/null +++ b/queue-6.18/rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch @@ -0,0 +1,50 @@ +From 7e342d87aa8e6b831cf6d21ca41b1f7e032d0fcf Mon Sep 17 00:00:00 2001 +From: Lad Prabhakar +Date: Tue, 2 Jun 2026 20:25:55 +0100 +Subject: rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path + +From: Lad Prabhakar + +commit 7e342d87aa8e6b831cf6d21ca41b1f7e032d0fcf upstream. + +In rtca3_set_alarm(), the setup_failed path attempts to disable the +Periodic Interrupt Enable (PIE) bit and wait until it is cleared. +However, the polling condition passed to readb_poll_timeout_atomic() +uses an incorrect expression: + + !(tmp & ~RTCA3_RCR1_PIE) + +As ~RTCA3_RCR1_PIE evaluates to a mask of all bits except PIE, the +condition effectively waits for all non-PIE bits to become zero, which +is unrelated to the intended operation and is unlikely to ever be true. +This causes the poll to time out unnecessarily. + +Fix the condition to check for the PIE bit itself being cleared: + + !(tmp & RTCA3_RCR1_PIE) + +This correctly waits until PIE is deasserted after being cleared. + +Fixes: d4488377609e3 ("rtc: renesas-rtca3: Add driver for RTCA-3 available on Renesas RZ/G3S SoC") +Cc: stable@vger.kernel.org +Signed-off-by: Lad Prabhakar +Reviewed-by: Claudiu Beznea +Tested-by: Claudiu Beznea # on RZ/G3S +Link: https://patch.msgid.link/20260602192559.1791344-2-prabhakar.mahadev-lad.rj@bp.renesas.com +Signed-off-by: Alexandre Belloni +Signed-off-by: Greg Kroah-Hartman +--- + drivers/rtc/rtc-renesas-rtca3.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/drivers/rtc/rtc-renesas-rtca3.c ++++ b/drivers/rtc/rtc-renesas-rtca3.c +@@ -455,7 +455,7 @@ setup_failed: + * specified timeout for setup. + */ + writeb(rcr1 & ~RTCA3_RCR1_PIE, priv->base + RTCA3_RCR1); +- readb_poll_timeout_atomic(priv->base + RTCA3_RCR1, tmp, !(tmp & ~RTCA3_RCR1_PIE), ++ readb_poll_timeout_atomic(priv->base + RTCA3_RCR1, tmp, !(tmp & RTCA3_RCR1_PIE), + 10, RTCA3_DEFAULT_TIMEOUT_US); + atomic_set(&priv->alrm_sstep, RTCA3_ALRM_SSTEP_DONE); + } diff --git a/queue-6.18/series b/queue-6.18/series index 17c37f0987..34b76263e8 100644 --- a/queue-6.18/series +++ b/queue-6.18/series @@ -1423,3 +1423,12 @@ net-sched-sch_teql-move-rcu_read_lock-spin_lock-from-_bh-variants.patch drm-xe-userptr-stub-notifier_lock-helpers-when-drm_gpusvm-n.patch kvm-tdx-account-all-non-transient-page-allocations-f.patch selftests-bpf-add-simple-strscpy-implementation.patch +pwm-rzg2l-gpt-fix-period_ticks-type-from-u32-to-u64.patch +loongarch-fix-nr-passing-in-set_direct_map_valid_noflush.patch +loongarch-fix-missing-dirty-page-tracking-in-pte-pmd-_wrprotect.patch +ipmi-fix-user-refcount-underflow-in-event-delivery.patch +espintcp-use-sk_msg_free_partial-to-fix-partial-send.patch +ipmi-fix-refcount-leak-in-i_ipmi_request.patch +bnx2x-fix-potential-memory-leak-in-bnx2x_alloc_mem_bp.patch +rtc-renesas-rtca3-fix-pie-clear-polling-condition-in-alarm-setup-error-path.patch +rtc-mpfs-fix-counter-upload-completion-condition.patch