--- /dev/null
+From d27c71257825dced46104eefe42e4d9964bd032e Mon Sep 17 00:00:00 2001
+From: David Howells <dhowells@redhat.com>
+Date: Fri, 28 Nov 2025 10:19:05 +0000
+Subject: afs: Fix delayed allocation of a cell's anonymous key
+
+From: David Howells <dhowells@redhat.com>
+
+commit d27c71257825dced46104eefe42e4d9964bd032e upstream.
+
+The allocation of a cell's anonymous key is done in a background thread
+along with other cell setup such as doing a DNS upcall. In the reported
+bug, this is triggered by afs_parse_source() parsing the device name given
+to mount() and calling afs_lookup_cell() with the name of the cell.
+
+The normal key lookup then tries to use the key description on the
+anonymous authentication key as the reference for request_key() - but it
+may not yet be set and so an oops can happen.
+
+This has been made more likely to happen by the fix for dynamic lookup
+failure.
+
+Fix this by firstly allocating a reference name and attaching it to the
+afs_cell record when the record is created. It can share the memory
+allocation with the cell name (unfortunately it can't just overlap the cell
+name by prepending it with "afs@" as the cell name already has a '.'
+prepended for other purposes). This reference name is then passed to
+request_key().
+
+Secondly, the anon key is now allocated on demand at the point a key is
+requested in afs_request_key() if it is not already allocated. A mutex is
+used to prevent multiple allocation for a cell.
+
+Thirdly, make afs_request_key_rcu() return NULL if the anonymous key isn't
+yet allocated (if we need it) and then the caller can return -ECHILD to
+drop out of RCU-mode and afs_request_key() can be called.
+
+Note that the anonymous key is kind of necessary to make the key lookup
+cache work as that doesn't currently cache a negative lookup, but it's
+probably worth some investigation to see if NULL can be used instead.
+
+Fixes: 330e2c514823 ("afs: Fix dynamic lookup to fail on cell lookup failure")
+Reported-by: syzbot+41c68824eefb67cdf00c@syzkaller.appspotmail.com
+Signed-off-by: David Howells <dhowells@redhat.com>
+Link: https://patch.msgid.link/800328.1764325145@warthog.procyon.org.uk
+cc: Marc Dionne <marc.dionne@auristor.com>
+cc: linux-afs@lists.infradead.org
+cc: linux-fsdevel@vger.kernel.org
+Signed-off-by: Christian Brauner <brauner@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/afs/cell.c | 43 ++++++++-----------------------------------
+ fs/afs/internal.h | 1 +
+ fs/afs/security.c | 48 ++++++++++++++++++++++++++++++++++++++++--------
+ 3 files changed, 49 insertions(+), 43 deletions(-)
+
+--- a/fs/afs/cell.c
++++ b/fs/afs/cell.c
+@@ -140,7 +140,9 @@ static struct afs_cell *afs_alloc_cell(s
+ return ERR_PTR(-ENOMEM);
+ }
+
+- cell->name = kmalloc(1 + namelen + 1, GFP_KERNEL);
++ /* Allocate the cell name and the key name in one go. */
++ cell->name = kmalloc(1 + namelen + 1 +
++ 4 + namelen + 1, GFP_KERNEL);
+ if (!cell->name) {
+ kfree(cell);
+ return ERR_PTR(-ENOMEM);
+@@ -151,7 +153,11 @@ static struct afs_cell *afs_alloc_cell(s
+ cell->name_len = namelen;
+ for (i = 0; i < namelen; i++)
+ cell->name[i] = tolower(name[i]);
+- cell->name[i] = 0;
++ cell->name[i++] = 0;
++
++ cell->key_desc = cell->name + i;
++ memcpy(cell->key_desc, "afs@", 4);
++ memcpy(cell->key_desc + 4, cell->name, cell->name_len + 1);
+
+ cell->net = net;
+ refcount_set(&cell->ref, 1);
+@@ -719,33 +725,6 @@ void afs_set_cell_timer(struct afs_cell
+ }
+
+ /*
+- * Allocate a key to use as a placeholder for anonymous user security.
+- */
+-static int afs_alloc_anon_key(struct afs_cell *cell)
+-{
+- struct key *key;
+- char keyname[4 + AFS_MAXCELLNAME + 1], *cp, *dp;
+-
+- /* Create a key to represent an anonymous user. */
+- memcpy(keyname, "afs@", 4);
+- dp = keyname + 4;
+- cp = cell->name;
+- do {
+- *dp++ = tolower(*cp);
+- } while (*cp++);
+-
+- key = rxrpc_get_null_key(keyname);
+- if (IS_ERR(key))
+- return PTR_ERR(key);
+-
+- cell->anonymous_key = key;
+-
+- _debug("anon key %p{%x}",
+- cell->anonymous_key, key_serial(cell->anonymous_key));
+- return 0;
+-}
+-
+-/*
+ * Activate a cell.
+ */
+ static int afs_activate_cell(struct afs_net *net, struct afs_cell *cell)
+@@ -754,12 +733,6 @@ static int afs_activate_cell(struct afs_
+ struct afs_cell *pcell;
+ int ret;
+
+- if (!cell->anonymous_key) {
+- ret = afs_alloc_anon_key(cell);
+- if (ret < 0)
+- return ret;
+- }
+-
+ ret = afs_proc_cell_setup(cell);
+ if (ret < 0)
+ return ret;
+--- a/fs/afs/internal.h
++++ b/fs/afs/internal.h
+@@ -423,6 +423,7 @@ struct afs_cell {
+
+ u8 name_len; /* Length of name */
+ char *name; /* Cell name, case-flattened and NUL-padded */
++ char *key_desc; /* Authentication key description */
+ };
+
+ /*
+--- a/fs/afs/security.c
++++ b/fs/afs/security.c
+@@ -16,6 +16,30 @@
+
+ static DEFINE_HASHTABLE(afs_permits_cache, 10);
+ static DEFINE_SPINLOCK(afs_permits_lock);
++static DEFINE_MUTEX(afs_key_lock);
++
++/*
++ * Allocate a key to use as a placeholder for anonymous user security.
++ */
++static int afs_alloc_anon_key(struct afs_cell *cell)
++{
++ struct key *key;
++
++ mutex_lock(&afs_key_lock);
++ if (!cell->anonymous_key) {
++ key = rxrpc_get_null_key(cell->key_desc);
++ if (!IS_ERR(key))
++ cell->anonymous_key = key;
++ }
++ mutex_unlock(&afs_key_lock);
++
++ if (IS_ERR(key))
++ return PTR_ERR(key);
++
++ _debug("anon key %p{%x}",
++ cell->anonymous_key, key_serial(cell->anonymous_key));
++ return 0;
++}
+
+ /*
+ * get a key
+@@ -23,11 +47,12 @@ static DEFINE_SPINLOCK(afs_permits_lock)
+ struct key *afs_request_key(struct afs_cell *cell)
+ {
+ struct key *key;
++ int ret;
+
+- _enter("{%x}", key_serial(cell->anonymous_key));
++ _enter("{%s}", cell->key_desc);
+
+- _debug("key %s", cell->anonymous_key->description);
+- key = request_key_net(&key_type_rxrpc, cell->anonymous_key->description,
++ _debug("key %s", cell->key_desc);
++ key = request_key_net(&key_type_rxrpc, cell->key_desc,
+ cell->net->net, NULL);
+ if (IS_ERR(key)) {
+ if (PTR_ERR(key) != -ENOKEY) {
+@@ -35,6 +60,12 @@ struct key *afs_request_key(struct afs_c
+ return key;
+ }
+
++ if (!cell->anonymous_key) {
++ ret = afs_alloc_anon_key(cell);
++ if (ret < 0)
++ return ERR_PTR(ret);
++ }
++
+ /* act as anonymous user */
+ _leave(" = {%x} [anon]", key_serial(cell->anonymous_key));
+ return key_get(cell->anonymous_key);
+@@ -52,11 +83,10 @@ struct key *afs_request_key_rcu(struct a
+ {
+ struct key *key;
+
+- _enter("{%x}", key_serial(cell->anonymous_key));
++ _enter("{%s}", cell->key_desc);
+
+- _debug("key %s", cell->anonymous_key->description);
+- key = request_key_net_rcu(&key_type_rxrpc,
+- cell->anonymous_key->description,
++ _debug("key %s", cell->key_desc);
++ key = request_key_net_rcu(&key_type_rxrpc, cell->key_desc,
+ cell->net->net);
+ if (IS_ERR(key)) {
+ if (PTR_ERR(key) != -ENOKEY) {
+@@ -65,6 +95,8 @@ struct key *afs_request_key_rcu(struct a
+ }
+
+ /* act as anonymous user */
++ if (!cell->anonymous_key)
++ return NULL; /* Need to allocate */
+ _leave(" = {%x} [anon]", key_serial(cell->anonymous_key));
+ return key_get(cell->anonymous_key);
+ } else {
+@@ -408,7 +440,7 @@ int afs_permission(struct mnt_idmap *idm
+
+ if (mask & MAY_NOT_BLOCK) {
+ key = afs_request_key_rcu(vnode->volume->cell);
+- if (IS_ERR(key))
++ if (IS_ERR_OR_NULL(key))
+ return -ECHILD;
+
+ ret = -ECHILD;
--- /dev/null
+From f3cf725cd284b7912d5522babb44721bf38c8887 Mon Sep 17 00:00:00 2001
+From: Nan Li <tonanli66@gmail.com>
+Date: Mon, 22 Jun 2026 10:08:35 +0100
+Subject: afs: handle CB.InitCallBackState3 requests without a server record
+
+From: Nan Li <tonanli66@gmail.com>
+
+commit f3cf725cd284b7912d5522babb44721bf38c8887 upstream.
+
+The cache manager callback path now attaches the server record to an
+incoming call through the rxrpc peer's app data. That association is
+not guaranteed to exist for every callback request, and most callback
+handlers already tolerate that case.
+
+Make CB.InitCallBackState3 follow the same pattern by checking whether a
+server record was attached before using it. If the peer is not mapped
+to a server record, trace the request and ignore it, matching the
+existing behaviour for other unmatched callback requests.
+
+This keeps the callback handler consistent with the rest of the cache
+manager service and avoids depending on peer state that may not be
+available for a given request.
+
+Fixes: 40e8b52fe8c8 ("afs: Use the per-peer app data provided by rxrpc")
+Cc: stable@kernel.org
+Reported-by: Yuan Tan <yuantan098@gmail.com>
+Reported-by: Yifan Wu <yifanwucs@gmail.com>
+Reported-by: Juefei Pu <tomapufckgml@gmail.com>
+Reported-by: Xin Liu <bird@lzu.edu.cn>
+Signed-off-by: Nan Li <tonanli66@gmail.com>
+Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
+Signed-off-by: David Howells <dhowells@redhat.com>
+Link: https://patch.msgid.link/20260622090856.2746629-2-dhowells@redhat.com
+cc: Marc Dionne <marc.dionne@auristor.com>
+cc: linux-afs@lists.infradead.org
+Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/afs/cmservice.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+--- a/fs/afs/cmservice.c
++++ b/fs/afs/cmservice.c
+@@ -369,6 +369,11 @@ static int afs_deliver_cb_init_call_back
+ return 0;
+ }
+
++ if (!call->server) {
++ trace_afs_cm_no_server_u(call, call->request);
++ return 0;
++ }
++
+ if (memcmp(call->request, &call->server->_uuid, sizeof(call->server->_uuid)) != 0) {
+ pr_notice("Callback UUID does not match fileserver UUID\n");
+ trace_afs_cm_no_server_u(call, call->request);
--- /dev/null
+From 8b3c655fa2406b9853138142746a39b7615c54a2 Mon Sep 17 00:00:00 2001
+From: Edward Adam Davis <eadavis@qq.com>
+Date: Mon, 21 Jul 2025 15:26:51 +0100
+Subject: afs: Set vllist to NULL if addr parsing fails
+
+From: Edward Adam Davis <eadavis@qq.com>
+
+commit 8b3c655fa2406b9853138142746a39b7615c54a2 upstream.
+
+syzbot reported a bug in in afs_put_vlserverlist.
+
+ kAFS: bad VL server IP address
+ BUG: unable to handle page fault for address: fffffffffffffffa
+ ...
+ Oops: Oops: 0002 [#1] SMP KASAN PTI
+ ...
+ RIP: 0010:refcount_dec_and_test include/linux/refcount.h:450 [inline]
+ RIP: 0010:afs_put_vlserverlist+0x3a/0x220 fs/afs/vl_list.c:67
+ ...
+ Call Trace:
+ <TASK>
+ afs_alloc_cell fs/afs/cell.c:218 [inline]
+ afs_lookup_cell+0x12a5/0x1680 fs/afs/cell.c:264
+ afs_cell_init+0x17a/0x380 fs/afs/cell.c:386
+ afs_proc_rootcell_write+0x21f/0x290 fs/afs/proc.c:247
+ proc_simple_write+0x114/0x1b0 fs/proc/generic.c:825
+ pde_write fs/proc/inode.c:330 [inline]
+ proc_reg_write+0x23d/0x330 fs/proc/inode.c:342
+ vfs_write+0x25c/0x1180 fs/read_write.c:682
+ ksys_write+0x12a/0x240 fs/read_write.c:736
+ do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
+ do_syscall_64+0xcd/0x260 arch/x86/entry/syscall_64.c:94
+ entry_SYSCALL_64_after_hwframe+0x77/0x7f
+
+Because afs_parse_text_addrs() parses incorrectly, its return value -EINVAL
+is assigned to vllist, which results in -EINVAL being used as the vllist
+address when afs_put_vlserverlist() is executed.
+
+Set the vllist value to NULL when a parsing error occurs to avoid this
+issue.
+
+Fixes: e2c2cb8ef07a ("afs: Simplify cell record handling")
+Reported-by: syzbot+5c042fbab0b292c98fc6@syzkaller.appspotmail.com
+Closes: https://syzkaller.appspot.com/bug?extid=5c042fbab0b292c98fc6
+Tested-by: syzbot+5c042fbab0b292c98fc6@syzkaller.appspotmail.com
+Signed-off-by: Edward Adam Davis <eadavis@qq.com>
+Signed-off-by: David Howells <dhowells@redhat.com>
+Link: https://lore.kernel.org/4119365.1753108011@warthog.procyon.org.uk
+cc: Marc Dionne <marc.dionne@auristor.com>
+cc: linux-afs@lists.infradead.org
+cc: linux-fsdevel@vger.kernel.org
+Signed-off-by: Christian Brauner <brauner@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/afs/cell.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/fs/afs/cell.c
++++ b/fs/afs/cell.c
+@@ -177,6 +177,7 @@ static struct afs_cell *afs_alloc_cell(s
+ VL_SERVICE, AFS_VL_PORT);
+ if (IS_ERR(vllist)) {
+ ret = PTR_ERR(vllist);
++ vllist = NULL;
+ goto parse_failed;
+ }
+
--- /dev/null
+From 70d99623d5c11e1a9bcc564b8fbad6fa916913d8 Mon Sep 17 00:00:00 2001
+From: Ivan Vecera <ivecera@redhat.com>
+Date: Fri, 12 Sep 2025 11:33:31 +0200
+Subject: dpll: fix clock quality level reporting
+
+From: Ivan Vecera <ivecera@redhat.com>
+
+commit 70d99623d5c11e1a9bcc564b8fbad6fa916913d8 upstream.
+
+The DPLL_CLOCK_QUALITY_LEVEL_ITU_OPT1_EPRC is not reported via netlink
+due to bug in dpll_msg_add_clock_quality_level(). The usage of
+DPLL_CLOCK_QUALITY_LEVEL_MAX for both DECLARE_BITMAP() and
+for_each_set_bit() is not correct because these macros requires bitmap
+size and not the highest valid bit in the bitmap.
+
+Use correct bitmap size to fix this issue.
+
+Fixes: a1afb959add1 ("dpll: add clock quality level attribute and op")
+Signed-off-by: Ivan Vecera <ivecera@redhat.com>
+Reviewed-by: Arkadiusz Kubalewski <arkadiusz.kubalewski@intel.com>
+Link: https://patch.msgid.link/20250912093331.862333-1-ivecera@redhat.com
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/dpll/dpll_netlink.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/drivers/dpll/dpll_netlink.c
++++ b/drivers/dpll/dpll_netlink.c
+@@ -191,8 +191,8 @@ static int
+ dpll_msg_add_clock_quality_level(struct sk_buff *msg, struct dpll_device *dpll,
+ struct netlink_ext_ack *extack)
+ {
++ DECLARE_BITMAP(qls, DPLL_CLOCK_QUALITY_LEVEL_MAX + 1) = { 0 };
+ const struct dpll_device_ops *ops = dpll_device_ops(dpll);
+- DECLARE_BITMAP(qls, DPLL_CLOCK_QUALITY_LEVEL_MAX) = { 0 };
+ enum dpll_clock_quality_level ql;
+ int ret;
+
+@@ -201,7 +201,7 @@ dpll_msg_add_clock_quality_level(struct
+ ret = ops->clock_quality_level_get(dpll, dpll_priv(dpll), qls, extack);
+ if (ret)
+ return ret;
+- for_each_set_bit(ql, qls, DPLL_CLOCK_QUALITY_LEVEL_MAX)
++ for_each_set_bit(ql, qls, DPLL_CLOCK_QUALITY_LEVEL_MAX + 1)
+ if (nla_put_u32(msg, DPLL_A_CLOCK_QUALITY_LEVEL, ql))
+ return -EMSGSIZE;
+
--- /dev/null
+From e2537326e3b6b1bb18f834ebb80b8453c0018883 Mon Sep 17 00:00:00 2001
+From: Lukas Bulwahn <lukas.bulwahn@redhat.com>
+Date: Thu, 6 Mar 2025 10:47:53 +0100
+Subject: net: ethernet: Remove accidental duplication in Kconfig file
+
+From: Lukas Bulwahn <lukas.bulwahn@redhat.com>
+
+commit e2537326e3b6b1bb18f834ebb80b8453c0018883 upstream.
+
+Commit fb3dda82fd38 ("net: airoha: Move airoha_eth driver in a dedicated
+folder") accidentally added the line:
+
+ source "drivers/net/ethernet/mellanox/Kconfig"
+
+in drivers/net/ethernet/Kconfig, so that this line is duplicated in that
+file.
+
+Remove this accidental duplication.
+
+Fixes: fb3dda82fd38 ("net: airoha: Move airoha_eth driver in a dedicated folder")
+Signed-off-by: Lukas Bulwahn <lukas.bulwahn@redhat.com>
+Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
+Link: https://patch.msgid.link/20250306094753.63806-1-lukas.bulwahn@redhat.com
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/net/ethernet/Kconfig | 1 -
+ 1 file changed, 1 deletion(-)
+
+--- a/drivers/net/ethernet/Kconfig
++++ b/drivers/net/ethernet/Kconfig
+@@ -21,7 +21,6 @@ source "drivers/net/ethernet/adaptec/Kco
+ source "drivers/net/ethernet/aeroflex/Kconfig"
+ source "drivers/net/ethernet/agere/Kconfig"
+ source "drivers/net/ethernet/airoha/Kconfig"
+-source "drivers/net/ethernet/mellanox/Kconfig"
+ source "drivers/net/ethernet/alacritech/Kconfig"
+ source "drivers/net/ethernet/allwinner/Kconfig"
+ source "drivers/net/ethernet/alteon/Kconfig"
--- /dev/null
+From d920270a6dbf756384b125ce39c17666a7c0c9f4 Mon Sep 17 00:00:00 2001
+From: David Howells <dhowells@redhat.com>
+Date: Thu, 12 Dec 2024 20:58:15 +0000
+Subject: rxrpc: Disable IRQ, not BH, to take the lock for ->attend_link
+
+From: David Howells <dhowells@redhat.com>
+
+commit d920270a6dbf756384b125ce39c17666a7c0c9f4 upstream.
+
+Use spin_lock_irq(), not spin_lock_bh() to take the lock when accessing the
+->attend_link() to stop a delay in the I/O thread due to an interrupt being
+taken in the app thread whilst that holds the lock and vice versa.
+
+Fixes: a2ea9a907260 ("rxrpc: Use irq-disabling spinlocks between app and I/O thread")
+Signed-off-by: David Howells <dhowells@redhat.com>
+cc: Marc Dionne <marc.dionne@auristor.com>
+cc: linux-afs@lists.infradead.org
+Link: https://patch.msgid.link/2870146.1734037095@warthog.procyon.org.uk
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ net/rxrpc/io_thread.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+--- a/net/rxrpc/io_thread.c
++++ b/net/rxrpc/io_thread.c
+@@ -482,9 +482,9 @@ int rxrpc_io_thread(void *data)
+ while ((conn = list_first_entry_or_null(&conn_attend_q,
+ struct rxrpc_connection,
+ attend_link))) {
+- spin_lock_bh(&local->lock);
++ spin_lock_irq(&local->lock);
+ list_del_init(&conn->attend_link);
+- spin_unlock_bh(&local->lock);
++ spin_unlock_irq(&local->lock);
+ rxrpc_input_conn_event(conn, NULL);
+ rxrpc_put_connection(conn, rxrpc_conn_put_poke);
+ }
+@@ -501,9 +501,9 @@ int rxrpc_io_thread(void *data)
+ while ((call = list_first_entry_or_null(&call_attend_q,
+ struct rxrpc_call,
+ attend_link))) {
+- spin_lock_bh(&local->lock);
++ spin_lock_irq(&local->lock);
+ list_del_init(&call->attend_link);
+- spin_unlock_bh(&local->lock);
++ spin_unlock_irq(&local->lock);
+ trace_rxrpc_call_poked(call);
+ rxrpc_input_call_event(call);
+ rxrpc_put_call(call, rxrpc_call_put_poke);
--- /dev/null
+From 71f5409176f4ffd460689eb5423a20332d00e342 Mon Sep 17 00:00:00 2001
+From: David Howells <dhowells@redhat.com>
+Date: Tue, 18 Feb 2025 19:22:46 +0000
+Subject: rxrpc: Fix locking issues with the peer record hash
+
+From: David Howells <dhowells@redhat.com>
+
+commit 71f5409176f4ffd460689eb5423a20332d00e342 upstream.
+
+rxrpc_new_incoming_peer() can't use spin_lock_bh() whilst its caller has
+interrupts disabled.
+
+ WARNING: CPU: 0 PID: 1550 at kernel/softirq.c:369 __local_bh_enable_ip+0x46/0xd0
+ ...
+ Call Trace:
+ rxrpc_alloc_incoming_call+0x1b0/0x400
+ rxrpc_new_incoming_call+0x1dd/0x5e0
+ rxrpc_input_packet+0x84a/0x920
+ rxrpc_io_thread+0x40d/0xb40
+ kthread+0x2ec/0x300
+ ret_from_fork+0x24/0x40
+ ret_from_fork_asm+0x1a/0x30
+ </TASK>
+ irq event stamp: 1811
+ hardirqs last enabled at (1809): _raw_spin_unlock_irq+0x24/0x50
+ hardirqs last disabled at (1810): _raw_read_lock_irq+0x17/0x70
+ softirqs last enabled at (1182): handle_softirqs+0x3ee/0x430
+ softirqs last disabled at (1811): rxrpc_new_incoming_peer+0x56/0x120
+
+Fix this by using a plain spin_lock() instead. IRQs are held, so softirqs
+can't happen.
+
+Fixes: a2ea9a907260 ("rxrpc: Use irq-disabling spinlocks between app and I/O thread")
+Signed-off-by: David Howells <dhowells@redhat.com>
+cc: Marc Dionne <marc.dionne@auristor.com>
+cc: Simon Horman <horms@kernel.org>
+cc: linux-afs@lists.infradead.org
+Link: https://patch.msgid.link/20250218192250.296870-4-dhowells@redhat.com
+Signed-off-by: Jakub Kicinski <kuba@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ net/rxrpc/peer_object.c | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/net/rxrpc/peer_object.c
++++ b/net/rxrpc/peer_object.c
+@@ -314,10 +314,10 @@ void rxrpc_new_incoming_peer(struct rxrp
+ hash_key = rxrpc_peer_hash_key(local, &peer->srx);
+ rxrpc_init_peer(local, peer, hash_key);
+
+- spin_lock_bh(&rxnet->peer_hash_lock);
++ spin_lock(&rxnet->peer_hash_lock);
+ hash_add_rcu(rxnet->peer_hash, &peer->hash_link, hash_key);
+ list_add_tail(&peer->keepalive_link, &rxnet->peer_keepalive_new);
+- spin_unlock_bh(&rxnet->peer_hash_lock);
++ spin_unlock(&rxnet->peer_hash_lock);
+ }
+
+ /*
usb-musb-omap2430-do-not-put-borrowed-of_node-in-probe.patch
net-mlx5e-fix-null-pointer-dereference-in-ioctl-module-eeprom-query.patch
gpu-fix-uninitialized-buddy-for-built-in-drivers.patch
+rxrpc-disable-irq-not-bh-to-take-the-lock-for-attend_link.patch
+rxrpc-fix-locking-issues-with-the-peer-record-hash.patch
+wifi-nl80211-fix-nl80211_start_radar_detection-return-value.patch
+net-ethernet-remove-accidental-duplication-in-kconfig-file.patch
+afs-set-vllist-to-null-if-addr-parsing-fails.patch
+dpll-fix-clock-quality-level-reporting.patch
+afs-fix-delayed-allocation-of-a-cell-s-anonymous-key.patch
+afs-handle-cb.initcallbackstate3-requests-without-a-server-record.patch
--- /dev/null
+From 22159143ff99883667f340998cfbb52b4aaac14c Mon Sep 17 00:00:00 2001
+From: Nicolas Escande <nico.escande@gmail.com>
+Date: Thu, 9 Jan 2025 17:10:40 +0100
+Subject: wifi: nl80211: fix nl80211_start_radar_detection return value
+
+From: Nicolas Escande <nico.escande@gmail.com>
+
+commit 22159143ff99883667f340998cfbb52b4aaac14c upstream.
+
+Since the wiphy_guard changes, rdev_start_radar_detection's return value
+in nl80211_start_radar_detection is ignored and we always returned 0.
+
+Fixes: f42d22d3f796 ("wifi: cfg80211: define and use wiphy guard")
+Signed-off-by: Nicolas Escande <nico.escande@gmail.com>
+Link: https://patch.msgid.link/20250109161040.325742-1-nico.escande@gmail.com
+Signed-off-by: Johannes Berg <johannes.berg@intel.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ net/wireless/nl80211.c | 37 +++++++++++++++++++------------------
+ 1 file changed, 19 insertions(+), 18 deletions(-)
+
+--- a/net/wireless/nl80211.c
++++ b/net/wireless/nl80211.c
+@@ -10140,25 +10140,26 @@ static int nl80211_start_radar_detection
+
+ err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms,
+ link_id);
+- if (!err) {
+- switch (wdev->iftype) {
+- case NL80211_IFTYPE_AP:
+- case NL80211_IFTYPE_P2P_GO:
+- wdev->links[0].ap.chandef = chandef;
+- break;
+- case NL80211_IFTYPE_ADHOC:
+- wdev->u.ibss.chandef = chandef;
+- break;
+- case NL80211_IFTYPE_MESH_POINT:
+- wdev->u.mesh.chandef = chandef;
+- break;
+- default:
+- break;
+- }
+- wdev->links[link_id].cac_started = true;
+- wdev->links[link_id].cac_start_time = jiffies;
+- wdev->links[link_id].cac_time_ms = cac_time_ms;
++ if (err)
++ return err;
++
++ switch (wdev->iftype) {
++ case NL80211_IFTYPE_AP:
++ case NL80211_IFTYPE_P2P_GO:
++ wdev->links[0].ap.chandef = chandef;
++ break;
++ case NL80211_IFTYPE_ADHOC:
++ wdev->u.ibss.chandef = chandef;
++ break;
++ case NL80211_IFTYPE_MESH_POINT:
++ wdev->u.mesh.chandef = chandef;
++ break;
++ default:
++ break;
+ }
++ wdev->links[link_id].cac_started = true;
++ wdev->links[link_id].cac_start_time = jiffies;
++ wdev->links[link_id].cac_time_ms = cac_time_ms;
+
+ return 0;
+ }