From: Greg Kroah-Hartman Date: Mon, 20 Jul 2026 12:26:13 +0000 (+0200) Subject: 7.1-stable patches X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=0e9cc8c7873267bb60daba98406c49b6322de825;p=thirdparty%2Fkernel%2Fstable-queue.git 7.1-stable patches added patches: arm-dts-imx6ul-var-som-fix-warning-for-non-existent-dc-supply-property.patch arm-dts-stm32-stm32mp15x-mecio1-io-enable-internal-adc-reference.patch arm-dts-stm32-stm32mp15x-mecio1-io-fix-adc-sampling-times.patch arm-dts-stm32-stm32mp15x-mecio1-io-fix-expander-gpio-line-typo.patch arm-dts-stm32-stm32mp15x-mecio1-io-fix-gpio-names-typo.patch arm-dts-stm32-stm32mp15x-mecio1-io-move-divergent-mecio1-adc-channels-to-board-files.patch arm-dts-stm32-stm32mp15x-mecio1-io-move-expander-gpio-line-names-to-board-files.patch arm-dts-stm32-stm32mp15x-mecio1-io-move-gpio-line-names-to-board-files.patch arm64-dts-imx8ulp-evk-correct-type-c-int-gpio-flags.patch arm64-dts-qcom-hamoa-fix-opp-tables-for-all-displayport-controllers.patch arm64-dts-qcom-sdm630-describe-adsp_mem-region-properly.patch arm64-dts-renesas-ironhide-describe-inline-ecc-carveouts.patch arm64-dts-rockchip-fix-ethernet-phy-not-found-on-px30-ringneck.patch arm64-dts-s32g3-fix-swt8-watchdog-address.patch arm64-dts-ti-k3-am62a7-sk-add-bootph-all-tag-to-vqmmc.patch arm64-fpsimd-fix-type-mismatch-in-sve_-save-load-_state.patch asoc-sof-ipc3-control-fix-toctou-in-bytes_put-and-bytes_get.patch asoc-sof-ipc3-control-use-overflow-checks-in-control_update-size-calc.patch asoc-sof-ipc4-control-fix-toctou-in-sof_ipc4_bytes_put.patch asoc-sof-ipc4-control-validate-notification-payload-size.patch asoc-sof-topology-validate-vendor-array-size-before-parsing.patch idpf-add-padding-to-ptp-virtchnl-structures.patch kvm-arm64-account-pkvm-reclaim-against-the-vm-mm.patch kvm-arm64-ensure-level-is-always-initialized-when-relaxing-perms.patch kvm-arm64-nv-drop-bogus-warn-for-write-to-zcr_el2.patch kvm-arm64-nv-fix-spsr_el2-restore-in-kvm_hyp_handle_mops.patch kvm-arm64-nv-inject-sea-if-guest-vncr-isn-t-normal-memory.patch kvm-arm64-nv-inject-sea-if-kvm_translate_vncr-can-t-resolve-pfn.patch kvm-arm64-nv-re-translate-vncr-before-injecting-abort.patch kvm-arm64-nv-respect-read-only-pfn-when-mapping-l1-vncr.patch kvm-arm64-nv-write-esr_el2-for-injected-nested-serror-exceptions.patch kvm-arm64-vgic-check-the-interrupt-is-still-ours-before-migrating-it.patch kvm-arm64-vgic-handle-race-between-interrupt-affinity-change-and-lpi-disabling.patch kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch kvm-nvmx-move-vtpr-vs.-tpr-threshold-consistency-check-into-normal-checks.patch kvm-nvmx-put-vmcs12-pages-if-nested-vm-enter-fails-due-to-invalid-guest-state.patch kvm-s390-fix-unlikely-race-in-try_get_locked_pte.patch kvm-s390-initialize-kvm_s390_get_cmma_bits-memory.patch kvm-s390-pci-fix-gisc-refcount-leak-on-aif-enable-failure.patch kvm-s390-pci-fix-handling-of-aif-enable-without-aisb.patch kvm-s390-silence-potential-warnings-in-_gmap_crstep_xchg_atomic.patch kvm-s390-vsie-add-missing-radix_tree_preload-in-_gaccess_shadow_fault.patch kvm-s390-vsie-fix-allocation-of-struct-vsie_rmap.patch kvm-s390-vsie-use-mmu-cache-to-allocate-rmap.patch kvm-sev-do-not-allow-intra-host-migration-mirroring-of-snp-vms.patch kvm-tdx-reject-concurrent-change-to-cpuid-entry-count.patch kvm-x86-ignore-pending-pv-eoi-if-the-vcpu-has-since-disabled-pv-eois.patch kvm-x86-nullify-irqfd-producer-if-updating-irte-for-bypass-fails.patch loongarch-kvm-check-irq-validity-in-kvm_vcpu_ioctl_interrupt.patch loongarch-kvm-check-the-return-values-for-put_user.patch loongarch-kvm-fix-fpu-register-width-with-user-access-api.patch loongarch-kvm-return-full-old-csr-value-from-kvm_emu_xchg_csr.patch loongarch-kvm-validate-irqchip-index-in-irqfd-routing.patch mlxsw-fix-refcount-leak-in-mlxsw_sp_port_lag_join.patch mlxsw-fix-refcount-leak-in-mlxsw_sp_vrs_lpm_tree_replace.patch net-atm-reject-out-of-range-traffic-classes-in-qos-validation.patch net-ife-require-eth_hlen-to-be-pullable-in-ife_decode.patch net-qrtr-fix-32-bit-integer-overflow-in-qrtr_endpoint_post.patch octeontx2-pf-clear-stale-mailbox-irq-state-before-request_irq.patch octeontx2-vf-clear-stale-mailbox-irq-state-before-request_irq.patch powerpc-pseries-kconfig-enable-config_vpa_pmu-to-be-used-with-kvm.patch tipc-restrict-socket-queue-dumps-in-enqueue-tracepoints.patch vduse-avoid-leaking-information-to-userspace.patch vduse-fix-race-in-vduse_dev_msg_sync-and-vduse_dev_read_iter.patch --- diff --git a/queue-7.1/arm-dts-imx6ul-var-som-fix-warning-for-non-existent-dc-supply-property.patch b/queue-7.1/arm-dts-imx6ul-var-som-fix-warning-for-non-existent-dc-supply-property.patch new file mode 100644 index 0000000000..9382a6dac4 --- /dev/null +++ b/queue-7.1/arm-dts-imx6ul-var-som-fix-warning-for-non-existent-dc-supply-property.patch @@ -0,0 +1,40 @@ +From 0372cc5776e7fd5570884aed0c1e9a8a546cad66 Mon Sep 17 00:00:00 2001 +From: Hugo Villeneuve +Date: Thu, 5 Mar 2026 13:06:16 -0500 +Subject: ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property + +From: Hugo Villeneuve + +commit 0372cc5776e7fd5570884aed0c1e9a8a546cad66 upstream. + +The dc-supply property is non-existent in Linux now, nor when this DTS file +was created when importing it from Variscite own kernel. + +Therefore remove it to fix this warning: + + imx6ul-var-som-concerto.dtb: cpu@0 (arm,cortex-a7): Unevaluated + properties are not allowed ('dc-supply' was unexpected) + from schema $id: http://devicetree.org/schemas/arm/cpus.yaml + +Fixes: 9d6a67d9c7a9 ("ARM: dts: imx6ul: Add Variscite VAR-SOM-MX6UL SoM support") +Cc: stable@kernel.org +Signed-off-by: Hugo Villeneuve +Signed-off-by: Frank Li +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/nxp/imx/imx6ul-var-som.dtsi | 4 ---- + 1 file changed, 4 deletions(-) + +--- a/arch/arm/boot/dts/nxp/imx/imx6ul-var-som.dtsi ++++ b/arch/arm/boot/dts/nxp/imx/imx6ul-var-som.dtsi +@@ -45,10 +45,6 @@ + assigned-clock-rates = <786432000>; + }; + +-&cpu0 { +- dc-supply = <®_gpio_dvfs>; +-}; +- + &fec1 { + pinctrl-names = "default"; + pinctrl-0 = <&pinctrl_enet1>, <&pinctrl_enet1_gpio>, <&pinctrl_enet1_mdio>; diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-enable-internal-adc-reference.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-enable-internal-adc-reference.patch new file mode 100644 index 0000000000..5cc3808ace --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-enable-internal-adc-reference.patch @@ -0,0 +1,51 @@ +From c84f22405085d91cd5f0c5b967318371c07904ba Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:17 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference + +From: David Jander + +commit c84f22405085d91cd5f0c5b967318371c07904ba upstream. + +Switch the ADC reference supply from the general 3.3V rail to the +internal 2.5V VREFBUF regulator. The ADC circuits on this board are +designed for the internal 2.5V reference. Without this change, all ADC +measurement values are incorrect. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: +Link: https://lore.kernel.org/r/20260318105123.819807-2-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 9 ++++++++- + 1 file changed, 8 insertions(+), 1 deletion(-) + +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -95,7 +95,7 @@ + pinctrl-names = "default"; + vdd-supply = <&v3v3>; + vdda-supply = <&v3v3>; +- vref-supply = <&v3v3>; ++ vref-supply = <&vrefbuf>; + status = "okay"; + }; + +@@ -362,6 +362,13 @@ + phy-supply = <&v3v3>; + }; + ++&vrefbuf { ++ regulator-min-microvolt = <2500000>; ++ regulator-max-microvolt = <2500000>; ++ vdda-supply = <&v3v3>; ++ status = "okay"; ++}; ++ + &pinctrl { + adc12_pins_mecsbc: adc12-ain-mecsbc-0 { + pins { diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-adc-sampling-times.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-adc-sampling-times.patch new file mode 100644 index 0000000000..f2fd3d357a --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-adc-sampling-times.patch @@ -0,0 +1,146 @@ +From 8407e611faf80ce790a393addf7b44cc595742af Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:18 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times + +From: David Jander + +commit 8407e611faf80ce790a393addf7b44cc595742af upstream. + +Increase the minimum ADC sample times for all configured channels on +ADC1 and ADC2 to ensure measurement accuracy meets specifications. + +The default 5us sample time is insufficient for the internal sampling +capacitor to fully charge. Increase the default time to 20us to relax +the input impedance requirements. + +Additionally, the phint0_ain and phint1_ain channels require a much +longer sampling period due to their specific circuit design. Increase +their sample times to 200us. Remove stale comments regarding clock +cycles that no longer match the updated timings. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: +Link: https://lore.kernel.org/r/20260318105123.819807-3-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 32 +++++++++++-------------- + 1 file changed, 15 insertions(+), 17 deletions(-) + +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -104,80 +104,79 @@ + + channel@0 { + reg = <0>; +- /* 16.5 ck_cycles sampling time */ +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "p24v_stp"; + }; + + channel@1 { + reg = <1>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "p24v_hpdcm"; + }; + + channel@2 { + reg = <2>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "ain0"; + }; + + channel@3 { + reg = <3>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpdcm1_i2"; + }; + + channel@5 { + reg = <5>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpout1_i"; + }; + + channel@6 { + reg = <6>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "ain1"; + }; + + channel@9 { + reg = <9>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpout0_i"; + }; + + channel@10 { + reg = <10>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <200000>; + label = "phint0_ain"; + }; + + channel@13 { + reg = <13>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <200000>; + label = "phint1_ain"; + }; + + channel@15 { + reg = <15>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpdcm0_i1"; + }; + + channel@16 { + reg = <16>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "lsin"; + }; + + channel@18 { + reg = <18>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpdcm0_i2"; + }; + + channel@19 { + reg = <19>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "hpdcm1_i1"; + }; + }; +@@ -187,14 +186,13 @@ + + channel@2 { + reg = <2>; +- /* 16.5 ck_cycles sampling time */ +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "ain2"; + }; + + channel@6 { + reg = <6>; +- st,min-sample-time-ns = <5000>; ++ st,min-sample-time-ns = <20000>; + label = "ain3"; + }; + }; diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-expander-gpio-line-typo.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-expander-gpio-line-typo.patch new file mode 100644 index 0000000000..fffbd730a3 --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-expander-gpio-line-typo.patch @@ -0,0 +1,40 @@ +From dfb93c4acce8ad9c4f573128b2cf7ddb936e0de7 Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:22 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo + +From: David Jander + +commit dfb93c4acce8ad9c4f573128b2cf7ddb936e0de7 upstream. + +Fix a copy-paste error in the GPIO line names for the TCA6416 expander +(gpio@20). + +The common mecio1-io include file was originally defined using the +mecio1r1 (Revision 1) hardware layout, but incorrectly labeled pin 13 +as "HSIN9_BIAS" instead of the actual "HSIN7_BIAS" present in the +schematics. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: stable@vger.kernel.org +Link: https://lore.kernel.org/r/20260318105123.819807-7-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -186,7 +186,7 @@ + #gpio-cells = <2>; + gpio-line-names = "HSIN0_BIAS", "HSIN1_BIAS", "HSIN2_BIAS", "HSIN3_BIAS", + "", "", "HSIN_VREF0_LVL", "HSIN_VREF1_LVL", +- "HSIN4_BIAS", "HSIN5_BIAS", "HSIN6_BIAS", "HSIN9_BIAS", ++ "HSIN4_BIAS", "HSIN5_BIAS", "HSIN6_BIAS", "HSIN7_BIAS", + "", "", "", ""; + }; + diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-gpio-names-typo.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-gpio-names-typo.patch new file mode 100644 index 0000000000..7c8a14838a --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-fix-gpio-names-typo.patch @@ -0,0 +1,47 @@ +From b04ccecb714de913e360f0866c66f38e1606e89b Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:20 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo + +From: David Jander + +commit b04ccecb714de913e360f0866c66f38e1606e89b upstream. + +The reset pins for the LPOUT lines were incorrectly prefixed with "GPOUT" +instead of "LPOUT" in the gpio-line-names array. Fix these typos so the +pin names consistently match the LPOUT0-4 signals they belong to. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: +Link: https://lore.kernel.org/r/20260318105123.819807-5-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 10 +++++----- + 1 file changed, 5 insertions(+), 5 deletions(-) + +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -185,14 +185,14 @@ + &gpioe { + gpio-line-names = "HPOUT0_RESETN", "HPOUT1", "HPOUT1_ALERTN", "", + "", "", "HPOUT1_RESETN", +- "LPOUT0", "LPOUT0_ALERTN", "GPOUT0_RESETN", +- "LPOUT1", "LPOUT1_ALERTN", "GPOUT1_RESETN", +- "LPOUT2", "LPOUT2_ALERTN", "GPOUT2_RESETN"; ++ "LPOUT0", "LPOUT0_ALERTN", "LPOUT0_RESETN", ++ "LPOUT1", "LPOUT1_ALERTN", "LPOUT1_RESETN", ++ "LPOUT2", "LPOUT2_ALERTN", "LPOUT2_RESETN"; + }; + + &gpiof { +- gpio-line-names = "LPOUT3", "LPOUT3_ALERTN", "GPOUT3_RESETN", +- "LPOUT4", "LPOUT4_ALERTN", "GPOUT4_RESETN", ++ gpio-line-names = "LPOUT3", "LPOUT3_ALERTN", "LPOUT3_RESETN", ++ "LPOUT4", "LPOUT4_ALERTN", "LPOUT4_RESETN", + "", "", + "", "", "", "", + "", "", "", ""; diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-divergent-mecio1-adc-channels-to-board-files.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-divergent-mecio1-adc-channels-to-board-files.patch new file mode 100644 index 0000000000..78bd8b1044 --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-divergent-mecio1-adc-channels-to-board-files.patch @@ -0,0 +1,248 @@ +From 70f1d8fcbd121a40f51b6c846d41e8cbb38ba210 Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:19 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files + +From: David Jander + +commit 70f1d8fcbd121a40f51b6c846d41e8cbb38ba210 upstream. + +Move the divergent adc1 channel definitions out of the common +mecio1-io.dtsi file and into the specific Revision 0 and Revision 1 +board files. + +The original common file contained incorrect schematic labels for the +Revision 0 hardware (e.g., labeling ana0 as p24v_hpdcm instead of +ain_aux0) and failed to account for physical signal routing changes +between the board revisions. + +Retain only the strictly shared channels in the common include file. Map +the correct channels and schematic labels directly within +stm32mp151c-mecio1r0.dts and stm32mp153c-mecio1r1.dts. + +Crucially, ensure that the required 200us sample time follows the +phint1_ain signal to its new physical location on channel 3 for the +Revision 1 hardware. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: +Link: https://lore.kernel.org/r/20260318105123.819807-4-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts | 50 +++++++++++++++++++++++++ + arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts | 50 +++++++++++++++++++++++++ + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 50 ------------------------- + 3 files changed, 101 insertions(+), 49 deletions(-) + +--- a/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts ++++ b/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts +@@ -36,6 +36,56 @@ + }; + }; + ++&adc1 { ++ channel@0 { ++ reg = <0>; ++ st,min-sample-time-ns = <20000>; ++ label = "ain_aux0"; ++ }; ++ ++ channel@1 { ++ reg = <1>; ++ st,min-sample-time-ns = <20000>; ++ label = "ain_aux1"; ++ }; ++ ++ channel@3 { ++ reg = <3>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm1_i2"; ++ }; ++ ++ channel@5 { ++ reg = <5>; ++ st,min-sample-time-ns = <20000>; ++ label = "pout1_i"; ++ }; ++ ++ channel@9 { ++ reg = <9>; ++ st,min-sample-time-ns = <20000>; ++ label = "pout0_i"; ++ }; ++ ++ channel@13 { ++ reg = <13>; ++ st,min-sample-time-ns = <200000>; ++ label = "phint1_ain"; ++ }; ++ ++ channel@15 { ++ reg = <15>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm0_i1"; ++ }; ++ ++ channel@18 { ++ reg = <18>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm0_i2"; ++ }; ++}; ++ + &clk_hse { + clock-frequency = <25000000>; + }; +--- a/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts ++++ b/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts +@@ -36,6 +36,56 @@ + }; + }; + ++&adc1 { ++ channel@0 { ++ reg = <0>; ++ st,min-sample-time-ns = <20000>; ++ label = "p24v_hpdcm"; ++ }; ++ ++ channel@1 { ++ reg = <1>; ++ st,min-sample-time-ns = <20000>; ++ label = "p24v_stp"; ++ }; ++ ++ channel@3 { ++ reg = <3>; ++ st,min-sample-time-ns = <200000>; ++ label = "phint1_ain"; ++ }; ++ ++ channel@5 { ++ reg = <5>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpout1_i"; ++ }; ++ ++ channel@9 { ++ reg = <9>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpout0_i"; ++ }; ++ ++ channel@13 { ++ reg = <13>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm0_i2"; ++ }; ++ ++ channel@15 { ++ reg = <15>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm1_i2"; ++ }; ++ ++ channel@18 { ++ reg = <18>; ++ st,min-sample-time-ns = <20000>; ++ label = "hpdcm0_i1"; ++ }; ++}; ++ + &clk_hse { + clock-frequency = <24000000>; + }; +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -90,7 +90,7 @@ + }; + + &adc { +- /* ANA0, ANA1 are dedicated pins and don't need pinctrl: only in6. */ ++ /* ANA0, ANA1 are dedicated pins and don't need pinctrl. */ + pinctrl-0 = <&adc12_pins_mecsbc>; + pinctrl-names = "default"; + vdd-supply = <&v3v3>; +@@ -102,78 +102,30 @@ + &adc1 { + status = "okay"; + +- channel@0 { +- reg = <0>; +- st,min-sample-time-ns = <20000>; +- label = "p24v_stp"; +- }; +- +- channel@1 { +- reg = <1>; +- st,min-sample-time-ns = <20000>; +- label = "p24v_hpdcm"; +- }; +- + channel@2 { + reg = <2>; + st,min-sample-time-ns = <20000>; + label = "ain0"; + }; + +- channel@3 { +- reg = <3>; +- st,min-sample-time-ns = <20000>; +- label = "hpdcm1_i2"; +- }; +- +- channel@5 { +- reg = <5>; +- st,min-sample-time-ns = <20000>; +- label = "hpout1_i"; +- }; +- + channel@6 { + reg = <6>; + st,min-sample-time-ns = <20000>; + label = "ain1"; + }; + +- channel@9 { +- reg = <9>; +- st,min-sample-time-ns = <20000>; +- label = "hpout0_i"; +- }; +- + channel@10 { + reg = <10>; + st,min-sample-time-ns = <200000>; + label = "phint0_ain"; + }; + +- channel@13 { +- reg = <13>; +- st,min-sample-time-ns = <200000>; +- label = "phint1_ain"; +- }; +- +- channel@15 { +- reg = <15>; +- st,min-sample-time-ns = <20000>; +- label = "hpdcm0_i1"; +- }; +- + channel@16 { + reg = <16>; + st,min-sample-time-ns = <20000>; + label = "lsin"; + }; + +- channel@18 { +- reg = <18>; +- st,min-sample-time-ns = <20000>; +- label = "hpdcm0_i2"; +- }; +- + channel@19 { + reg = <19>; + st,min-sample-time-ns = <20000>; diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-expander-gpio-line-names-to-board-files.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-expander-gpio-line-names-to-board-files.patch new file mode 100644 index 0000000000..bae904392a --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-expander-gpio-line-names-to-board-files.patch @@ -0,0 +1,105 @@ +From a0d6c2a06fffff47bcca4d5bfdab4cc428a315fc Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:23 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files + +From: David Jander + +commit a0d6c2a06fffff47bcca4d5bfdab4cc428a315fc upstream. + +Move the gpio-line-names properties for the I2C GPIO expanders (gpio0 +and gpio1) out of the common mecio1-io.dtsi file and into the specific +board dts files. + +The layout originally defined in the common include file belonged to the +mecio1r1 (Revision 1) hardware. This layout is moved 1:1 into the +stm32mp153c-mecio1r1.dts file. + +The mecio1r0 (Revision 0) hardware utilizes a completely different +pinout for these expanders. A new, accurate mapping reflecting the +Revision 0 schematics is added to stm32mp151c-mecio1r0.dts. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: stable@vger.kernel.org +Link: https://lore.kernel.org/r/20260318105123.819807-8-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts | 14 ++++++++++++++ + arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts | 14 ++++++++++++++ + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 8 -------- + 3 files changed, 28 insertions(+), 8 deletions(-) + +--- a/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts ++++ b/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts +@@ -97,6 +97,20 @@ + st,eth-clk-sel; + }; + ++&gpio0 { ++ gpio-line-names = "HSIN0_BIAS", "HSIN1_BIAS", "HSIN2_BIAS", "HSIN3_BIAS", ++ "HSIN4_BIAS", "", "STP_VREF0_LVL", "HSIN_VREF0_LVL", ++ "STP0_FB_BIAS", "STP1_FB_BIAS", "STP2_FB_BIAS", "STP3_FB_BIAS", ++ "", "", "", ""; ++}; ++ ++&gpio1 { ++ gpio-line-names = "HSIN5_BIAS", "HSIN6_BIAS", "HSIN7_BIAS", "HSIN8_BIAS", ++ "HSIN9_BIAS", "", "STP_VREF1_LVL", "HSIN_VREF1_LVL", ++ "STP4_FB_BIAS", "STP5_FB_BIAS", "STP6_FB_BIAS", "", ++ "", "", "LSIN8_BIAS", "LSIN9_BIAS"; ++}; ++ + &gpiod { + gpio-line-names = "", "", "", "", + "", "", "", "", +--- a/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts ++++ b/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts +@@ -90,6 +90,20 @@ + clock-frequency = <24000000>; + }; + ++&gpio0 { ++ gpio-line-names = "HSIN0_BIAS", "HSIN1_BIAS", "HSIN2_BIAS", "HSIN3_BIAS", ++ "", "", "HSIN_VREF0_LVL", "HSIN_VREF1_LVL", ++ "HSIN4_BIAS", "HSIN5_BIAS", "HSIN6_BIAS", "HSIN7_BIAS", ++ "", "", "", ""; ++}; ++ ++&gpio1 { ++ gpio-line-names = "HSIN8_BIAS", "HSIN9_BIAS", "HSIN10_BIAS", "HSIN11_BIAS", ++ "", "", "HSIN_VREF2_LVL", "HSIN_VREF3_LVL", ++ "HSIN12_BIAS", "HSIN13_BIAS", "HSIN14_BIAS", "HSIN15_BIAS", ++ "", "", "LSIN8_BIAS", "LSIN9_BIAS"; ++}; ++ + &gpioa { + gpio-line-names = "", "", "", "", + "", "", "", "", +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -184,10 +184,6 @@ + reg = <0x20>; + gpio-controller; + #gpio-cells = <2>; +- gpio-line-names = "HSIN0_BIAS", "HSIN1_BIAS", "HSIN2_BIAS", "HSIN3_BIAS", +- "", "", "HSIN_VREF0_LVL", "HSIN_VREF1_LVL", +- "HSIN4_BIAS", "HSIN5_BIAS", "HSIN6_BIAS", "HSIN7_BIAS", +- "", "", "", ""; + }; + + gpio1: gpio@21 { +@@ -195,10 +191,6 @@ + reg = <0x21>; + gpio-controller; + #gpio-cells = <2>; +- gpio-line-names = "HSIN8_BIAS", "HSIN9_BIAS", "HSIN10_BIAS", "HSIN11_BIAS", +- "", "", "HSIN_VREF2_LVL", "HSIN_VREF3_LVL", +- "HSIN12_BIAS", "HSIN13_BIAS", "HSIN14_BIAS", "HSIN15_BIAS", +- "", "", "LSIN8_BIAS", "LSIN9_BIAS"; + }; + }; + diff --git a/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-gpio-line-names-to-board-files.patch b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-gpio-line-names-to-board-files.patch new file mode 100644 index 0000000000..2ede3559bf --- /dev/null +++ b/queue-7.1/arm-dts-stm32-stm32mp15x-mecio1-io-move-gpio-line-names-to-board-files.patch @@ -0,0 +1,265 @@ +From 4f5069609ac99894c0632d8b8c4c016f85199de9 Mon Sep 17 00:00:00 2001 +From: David Jander +Date: Wed, 18 Mar 2026 11:51:21 +0100 +Subject: ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files + +From: David Jander + +commit 4f5069609ac99894c0632d8b8c4c016f85199de9 upstream. + +Move the gpio-line-names properties out of the common mecio1-io.dtsi file +and into the specific board dts files. + +The pinout originally defined in the common include file belonged to the +mecio1r0 (Revision 0) hardware. This is moved 1:1 into the +stm32mp151c-mecio1r0.dts file without any modifications. + +A large number of GPIO pins are swapped on the mecio1r1 (Revision 1) +hardware, so a new, board-specific gpio-line-names mapping is added to +stm32mp153c-mecio1r1.dts to reflect those hardware changes. + +Fixes: 8267753c891c ("ARM: dts: stm32: Add MECIO1 and MECT1S board variants") +Co-developed-by: Oleksij Rempel +Signed-off-by: David Jander +Signed-off-by: Oleksij Rempel +Cc: +Link: https://lore.kernel.org/r/20260318105123.819807-6-o.rempel@pengutronix.de +Signed-off-by: Alexandre Torgue +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts | 64 ++++++++++++++++++++ + arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts | 80 +++++++++++++++++++++++++ + arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi | 63 ------------------- + 3 files changed, 144 insertions(+), 63 deletions(-) + +--- a/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts ++++ b/arch/arm/boot/dts/st/stm32mp151c-mecio1r0.dts +@@ -96,3 +96,67 @@ + assigned-clock-rates = <125000000>; /* Clock PLL3 to 625Mhz in tf-a. */ + st,eth-clk-sel; + }; ++ ++&gpiod { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "", "", "", "", ++ "STP_RESETN", "STP_ENABLEN", "HPOUT0", "HPOUT0_ALERTN"; ++ pinctrl-names = "default"; ++ pinctrl-0 = <&pinctrl_hog_d_mecsbc>; ++}; ++ ++&gpioe { ++ gpio-line-names = "HPOUT0_RESETN", "HPOUT1", "HPOUT1_ALERTN", "", ++ "", "", "HPOUT1_RESETN", ++ "LPOUT0", "LPOUT0_ALERTN", "LPOUT0_RESETN", ++ "LPOUT1", "LPOUT1_ALERTN", "LPOUT1_RESETN", ++ "LPOUT2", "LPOUT2_ALERTN", "LPOUT2_RESETN"; ++}; ++ ++&gpiof { ++ gpio-line-names = "LPOUT3", "LPOUT3_ALERTN", "LPOUT3_RESETN", ++ "LPOUT4", "LPOUT4_ALERTN", "LPOUT4_RESETN", ++ "", "", ++ "", "", "", "", ++ "", "", "", ""; ++}; ++ ++&gpiog { ++ gpio-line-names = "LPOUT5", "LPOUT5_ALERTN", "", "LPOUT5_RESETN", ++ "", "", "", "", ++ "", "", "", "", ++ "", "", "", ""; ++}; ++ ++&gpioh { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "GPIO0_RESETN", "", "", "", ++ "", "", "", ""; ++}; ++ ++&gpioi { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "HPDCM0_SLEEPN", "HPDCM1_SLEEPN", "GPIO1_RESETN", "", ++ "", "", "", ""; ++}; ++ ++&gpioj { ++ gpio-line-names = "HSIN10", "HSIN11", "HSIN12", "HSIN13", ++ "HSIN14", "HSIN15", "", "", ++ "", "", "", "", ++ "", "RTD_RESETN", "", ""; ++}; ++ ++&gpiok { ++ gpio-line-names = "", "", "HSIN0", "HSIN1", ++ "HSIN2", "HSIN3", "HSIN4", "HSIN5"; ++}; ++ ++&gpioz { ++ gpio-line-names = "", "", "", "HSIN6", ++ "HSIN7", "HSIN8", "HSIN9", ""; ++}; ++ +--- a/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts ++++ b/arch/arm/boot/dts/st/stm32mp153c-mecio1r1.dts +@@ -90,6 +90,86 @@ + clock-frequency = <24000000>; + }; + ++&gpioa { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "", "", "GPIO1_RESETN", "", ++ "", "", "", "LPOUT5"; ++}; ++ ++&gpiob { ++ gpio-line-names = "", "", "", "", ++ "LPOUT4_RESETN", "", "", "", ++ "", "LPOUT4_ALERTN", "", "", ++ "", "", "", ""; ++}; ++ ++&gpioc { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "", "LPOUT4", "", "", ++ "", "", "", ""; ++}; ++ ++&gpiod { ++ gpio-line-names = "LPOUT2", "", "LPOUT3_RESETN", "", ++ "LPOUT2_ALERTN", "", "MECIO_ADDR0", "", ++ "HPOUT1_ALERTN", "HPOUT1_RESETN", "", "", ++ "", "", "HPOUT0", "HPOUT1"; ++}; ++ ++&gpioe { ++ gpio-line-names = "LPOUT0_RESETN", "", "", "", ++ "", "LPOUT3", "LPOUT5_ALERTN", "", ++ "", "", "", "", ++ "", "", "", "HSIN_RESETN"; ++}; ++ ++&gpiof { ++ gpio-line-names = "LPOUT5_RESETN", "", "", "HPOUT0_ALERTN", ++ "", "LPOUT1", "", "", ++ "", "", "", "", ++ "", "", "", ""; ++}; ++ ++&gpiog { ++ gpio-line-names = "", "", "", "HPOUT0_RESETN", ++ "", "", "LPOUT3_ALERTN", "", ++ "", "", "GPIO0_RESETN", "", ++ "", "", "", "LPOUT2_RESETN"; ++}; ++ ++&gpioh { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "", "LPOUT0", "", "", ++ "", "LPOUT0_ALERTN", "STP_ENABLEN", "STP_RESETN"; ++}; ++ ++&gpioi { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "", ++ "", "", "SPE_RESETN", "", ++ "HPDCM0_SLEEPN", "", "", ""; ++}; ++ ++&gpioj { ++ gpio-line-names = "", "", "", "", ++ "", "", "", "MECIO_ADDR1", ++ "", "", "", "", ++ "", "", "", "LPOUT1_RESETN"; ++}; ++ ++&gpiok { ++ gpio-line-names = "", "", "RTD_RESETN", "", ++ "", "LPOUT1_ALERTN", "", ""; ++}; ++ ++&gpioz { ++ gpio-line-names = "", "", "", "", ++ "HPDCM1_SLEEPN", "", "", ""; ++}; ++ + &m_can1 { + pinctrl-names = "default", "sleep"; + pinctrl-0 = <&m_can1_pins_b>; +--- a/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi ++++ b/arch/arm/boot/dts/st/stm32mp15x-mecio1-io.dtsi +@@ -173,69 +173,6 @@ + }; + }; + +-&gpiod { +- gpio-line-names = "", "", "", "", +- "", "", "", "", +- "", "", "", "", +- "STP_RESETN", "STP_ENABLEN", "HPOUT0", "HPOUT0_ALERTN"; +- pinctrl-names = "default"; +- pinctrl-0 = <&pinctrl_hog_d_mecsbc>; +-}; +- +-&gpioe { +- gpio-line-names = "HPOUT0_RESETN", "HPOUT1", "HPOUT1_ALERTN", "", +- "", "", "HPOUT1_RESETN", +- "LPOUT0", "LPOUT0_ALERTN", "LPOUT0_RESETN", +- "LPOUT1", "LPOUT1_ALERTN", "LPOUT1_RESETN", +- "LPOUT2", "LPOUT2_ALERTN", "LPOUT2_RESETN"; +-}; +- +-&gpiof { +- gpio-line-names = "LPOUT3", "LPOUT3_ALERTN", "LPOUT3_RESETN", +- "LPOUT4", "LPOUT4_ALERTN", "LPOUT4_RESETN", +- "", "", +- "", "", "", "", +- "", "", "", ""; +-}; +- +-&gpiog { +- gpio-line-names = "LPOUT5", "LPOUT5_ALERTN", "", "LPOUT5_RESETN", +- "", "", "", "", +- "", "", "", "", +- "", "", "", ""; +-}; +- +-&gpioh { +- gpio-line-names = "", "", "", "", +- "", "", "", "", +- "GPIO0_RESETN", "", "", "", +- "", "", "", ""; +-}; +- +-&gpioi { +- gpio-line-names = "", "", "", "", +- "", "", "", "", +- "HPDCM0_SLEEPN", "HPDCM1_SLEEPN", "GPIO1_RESETN", "", +- "", "", "", ""; +-}; +- +-&gpioj { +- gpio-line-names = "HSIN10", "HSIN11", "HSIN12", "HSIN13", +- "HSIN14", "HSIN15", "", "", +- "", "", "", "", +- "", "RTD_RESETN", "", ""; +-}; +- +-&gpiok { +- gpio-line-names = "", "", "HSIN0", "HSIN1", +- "HSIN2", "HSIN3", "HSIN4", "HSIN5"; +-}; +- +-&gpioz { +- gpio-line-names = "", "", "", "HSIN6", +- "HSIN7", "HSIN8", "HSIN9", ""; +-}; +- + &i2c2 { + pinctrl-names = "default"; + pinctrl-0 = <&i2c2_pins_a>; diff --git a/queue-7.1/arm64-dts-imx8ulp-evk-correct-type-c-int-gpio-flags.patch b/queue-7.1/arm64-dts-imx8ulp-evk-correct-type-c-int-gpio-flags.patch new file mode 100644 index 0000000000..ee27eb3deb --- /dev/null +++ b/queue-7.1/arm64-dts-imx8ulp-evk-correct-type-c-int-gpio-flags.patch @@ -0,0 +1,47 @@ +From b4f5c46163b3fe3ec7ed8a76dff8b7e80a776a1f Mon Sep 17 00:00:00 2001 +From: Krzysztof Kozlowski +Date: Mon, 13 Apr 2026 11:07:24 +0200 +Subject: arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags + +From: Krzysztof Kozlowski + +commit b4f5c46163b3fe3ec7ed8a76dff8b7e80a776a1f upstream. + +IRQ_TYPE_xxx flags are not correct in the context of GPIO flags. +These are simple defines so they could be used in DTS but they will not +have the same meaning: IRQ_TYPE_EDGE_FALLING = 2 = GPIO_SINGLE_ENDED. + +Correct the Type-C int-gpios to use proper flags, assuming the author of +the code wanted similar logical behavior: + + IRQ_TYPE_EDGE_FALLING => GPIO_ACTIVE_LOW + +Fixes: c4b4593ecb0b ("arm64: dts: imx8ulp-evk: enable usb nodes and add ptn5150 nodes") +Cc: stable@vger.kernel.org +Signed-off-by: Krzysztof Kozlowski +Signed-off-by: Frank Li +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/freescale/imx8ulp-evk.dts | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts ++++ b/arch/arm64/boot/dts/freescale/imx8ulp-evk.dts +@@ -166,7 +166,7 @@ + ptn5150_1: typec@1d { + compatible = "nxp,ptn5150"; + reg = <0x1d>; +- int-gpios = <&gpiof 3 IRQ_TYPE_EDGE_FALLING>; ++ int-gpios = <&gpiof 3 GPIO_ACTIVE_LOW>; + pinctrl-names = "default"; + pinctrl-0 = <&pinctrl_typec1>; + status = "disabled"; +@@ -182,7 +182,7 @@ + ptn5150_2: typec@3d { + compatible = "nxp,ptn5150"; + reg = <0x3d>; +- int-gpios = <&gpiof 5 IRQ_TYPE_EDGE_FALLING>; ++ int-gpios = <&gpiof 5 GPIO_ACTIVE_LOW>; + pinctrl-names = "default"; + pinctrl-0 = <&pinctrl_typec2>; + status = "disabled"; diff --git a/queue-7.1/arm64-dts-qcom-hamoa-fix-opp-tables-for-all-displayport-controllers.patch b/queue-7.1/arm64-dts-qcom-hamoa-fix-opp-tables-for-all-displayport-controllers.patch new file mode 100644 index 0000000000..82c54dea33 --- /dev/null +++ b/queue-7.1/arm64-dts-qcom-hamoa-fix-opp-tables-for-all-displayport-controllers.patch @@ -0,0 +1,172 @@ +From c17e220946675232d383620ed9cff6685735ec48 Mon Sep 17 00:00:00 2001 +From: Abel Vesa +Date: Mon, 23 Mar 2026 12:01:12 +0200 +Subject: arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers + +From: Abel Vesa + +commit c17e220946675232d383620ed9cff6685735ec48 upstream. + +According to internal documentation, the corners specific for each rate +from the DP link clock are: + - LOWSVS_D1 -> 19.2 MHz + - LOWSVS -> 270 MHz + - SVS -> 540 MHz (594 MHz in case of DP3) + - SVS_L1 -> 594 MHz + - NOM -> 810 MHz + - NOM_L1 -> 810 MHz + - TURBO -> 810 MHz + +So fix all tables for each of the four controllers according to the +documentation, but since DP0 through DP2 have the same entries in their +tables, lets drop the DP1 and DP2 and have all of them share the DP0 +table instead. However keep a separate table for the DP3 as it is +different for the SVS, compared to the rest of the controllers. + +The 19.2 MHz @ LOWSVS_D1 isn't needed as it's not an actual working +frequency and the controller will never select it. So remove it. + +Cc: stable@vger.kernel.org # v6.9+ +Fixes: 1940c25eaa63 ("arm64: dts: qcom: x1e80100: Add display nodes") +Suggested-by: Dmitry Baryshkov +Reviewed-by: Konrad Dybcio +Reviewed-by: Dmitry Baryshkov +Signed-off-by: Abel Vesa +Link: https://lore.kernel.org/r/20260323-hamoa-fix-dp3-opp-table-v3-1-a823776bd1b0@oss.qualcomm.com +Signed-off-by: Bjorn Andersson +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/qcom/hamoa.dtsi | 77 +++++------------------------------- + 1 file changed, 12 insertions(+), 65 deletions(-) + +--- a/arch/arm64/boot/dts/qcom/hamoa.dtsi ++++ b/arch/arm64/boot/dts/qcom/hamoa.dtsi +@@ -5744,18 +5744,18 @@ + mdss_dp0_opp_table: opp-table { + compatible = "operating-points-v2"; + +- opp-162000000 { +- opp-hz = /bits/ 64 <162000000>; +- required-opps = <&rpmhpd_opp_low_svs>; +- }; +- + opp-270000000 { + opp-hz = /bits/ 64 <270000000>; +- required-opps = <&rpmhpd_opp_svs>; ++ required-opps = <&rpmhpd_opp_low_svs>; + }; + + opp-540000000 { + opp-hz = /bits/ 64 <540000000>; ++ required-opps = <&rpmhpd_opp_svs>; ++ }; ++ ++ opp-594000000 { ++ opp-hz = /bits/ 64 <594000000>; + required-opps = <&rpmhpd_opp_svs_l1>; + }; + +@@ -5796,7 +5796,7 @@ + <&usb_1_ss1_qmpphy QMP_USB43DP_DP_VCO_DIV_CLK>, + <&usb_1_ss1_qmpphy QMP_USB43DP_DP_VCO_DIV_CLK>; + +- operating-points-v2 = <&mdss_dp1_opp_table>; ++ operating-points-v2 = <&mdss_dp0_opp_table>; + + power-domains = <&rpmhpd RPMHPD_MMCX>; + +@@ -5829,30 +5829,6 @@ + }; + }; + }; +- +- mdss_dp1_opp_table: opp-table { +- compatible = "operating-points-v2"; +- +- opp-162000000 { +- opp-hz = /bits/ 64 <162000000>; +- required-opps = <&rpmhpd_opp_low_svs>; +- }; +- +- opp-270000000 { +- opp-hz = /bits/ 64 <270000000>; +- required-opps = <&rpmhpd_opp_svs>; +- }; +- +- opp-540000000 { +- opp-hz = /bits/ 64 <540000000>; +- required-opps = <&rpmhpd_opp_svs_l1>; +- }; +- +- opp-810000000 { +- opp-hz = /bits/ 64 <810000000>; +- required-opps = <&rpmhpd_opp_nom>; +- }; +- }; + }; + + mdss_dp2: displayport-controller@ae9a000 { +@@ -5885,7 +5861,7 @@ + <&usb_1_ss2_qmpphy QMP_USB43DP_DP_VCO_DIV_CLK>, + <&usb_1_ss2_qmpphy QMP_USB43DP_DP_VCO_DIV_CLK>; + +- operating-points-v2 = <&mdss_dp2_opp_table>; ++ operating-points-v2 = <&mdss_dp0_opp_table>; + + power-domains = <&rpmhpd RPMHPD_MMCX>; + +@@ -5917,30 +5893,6 @@ + }; + }; + }; +- +- mdss_dp2_opp_table: opp-table { +- compatible = "operating-points-v2"; +- +- opp-162000000 { +- opp-hz = /bits/ 64 <162000000>; +- required-opps = <&rpmhpd_opp_low_svs>; +- }; +- +- opp-270000000 { +- opp-hz = /bits/ 64 <270000000>; +- required-opps = <&rpmhpd_opp_svs>; +- }; +- +- opp-540000000 { +- opp-hz = /bits/ 64 <540000000>; +- required-opps = <&rpmhpd_opp_svs_l1>; +- }; +- +- opp-810000000 { +- opp-hz = /bits/ 64 <810000000>; +- required-opps = <&rpmhpd_opp_nom>; +- }; +- }; + }; + + mdss_dp3: displayport-controller@aea0000 { +@@ -6004,19 +5956,14 @@ + mdss_dp3_opp_table: opp-table { + compatible = "operating-points-v2"; + +- opp-162000000 { +- opp-hz = /bits/ 64 <162000000>; +- required-opps = <&rpmhpd_opp_low_svs>; +- }; +- + opp-270000000 { + opp-hz = /bits/ 64 <270000000>; +- required-opps = <&rpmhpd_opp_svs>; ++ required-opps = <&rpmhpd_opp_low_svs>; + }; + +- opp-540000000 { +- opp-hz = /bits/ 64 <540000000>; +- required-opps = <&rpmhpd_opp_svs_l1>; ++ opp-594000000 { ++ opp-hz = /bits/ 64 <594000000>; ++ required-opps = <&rpmhpd_opp_svs>; + }; + + opp-810000000 { diff --git a/queue-7.1/arm64-dts-qcom-sdm630-describe-adsp_mem-region-properly.patch b/queue-7.1/arm64-dts-qcom-sdm630-describe-adsp_mem-region-properly.patch new file mode 100644 index 0000000000..6dcc240945 --- /dev/null +++ b/queue-7.1/arm64-dts-qcom-sdm630-describe-adsp_mem-region-properly.patch @@ -0,0 +1,44 @@ +From ce414263e9ebe5080381a50cbdf9065c29816202 Mon Sep 17 00:00:00 2001 +From: Nickolay Goppen +Date: Wed, 29 Apr 2026 12:30:11 +0300 +Subject: arm64: dts: qcom: sdm630: describe adsp_mem region properly + +From: Nickolay Goppen + +commit ce414263e9ebe5080381a50cbdf9065c29816202 upstream. + +Downstream [1] this region is marked as shared, reusable and dynamic so +describe it that way. + +[1]: https://github.com/xiaomi-sdm660/android_kernel_xiaomi_sdm660/blob/11-EAS/arch/arm/boot/dts/qcom/sdm660.dtsi#L448 + +Fixes: b190fb010664 ("arm64: dts: qcom: sdm630: Add sdm630 dts file") +Cc: stable@vger.kernel.org +Reviewed-by: Ekansh Gupta +Reviewed-by: Dmitry Baryshkov +Signed-off-by: Nickolay Goppen +Link: https://lore.kernel.org/r/20260429-qcom-sdm660-cdsp-adsp-fastrpc-dts-fix-v5-4-16bc82e622ad@mainlining.org +Signed-off-by: Bjorn Andersson +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/qcom/sdm630.dtsi | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +--- a/arch/arm64/boot/dts/qcom/sdm630.dtsi ++++ b/arch/arm64/boot/dts/qcom/sdm630.dtsi +@@ -494,9 +494,12 @@ + no-map; + }; + +- adsp_mem: adsp-region@f6000000 { +- reg = <0x0 0xf6000000 0x0 0x800000>; +- no-map; ++ adsp_mem: adsp-region { ++ compatible = "shared-dma-pool"; ++ alloc-ranges = <0x0 0x80000000 0x0 0x80000000>; ++ alignment = <0x0 0x400000>; ++ size = <0x0 0x800000>; ++ reusable; + }; + + qseecom_mem: qseecom-region@f6800000 { diff --git a/queue-7.1/arm64-dts-renesas-ironhide-describe-inline-ecc-carveouts.patch b/queue-7.1/arm64-dts-renesas-ironhide-describe-inline-ecc-carveouts.patch new file mode 100644 index 0000000000..dedbc4b6df --- /dev/null +++ b/queue-7.1/arm64-dts-renesas-ironhide-describe-inline-ecc-carveouts.patch @@ -0,0 +1,84 @@ +From 6fa6ee724d8dadf392139e242ac936b5da730c4b Mon Sep 17 00:00:00 2001 +From: Marek Vasut +Date: Fri, 10 Jul 2026 18:04:22 +0200 +Subject: arm64: dts: renesas: ironhide: Describe inline ECC carveouts + +From: Marek Vasut + +commit 6fa6ee724d8dadf392139e242ac936b5da730c4b upstream. + +The DBSC5 DRAM controller protects DRAM content using inline ECC. +The inline ECC utilizes areas of DRAM for its operation, which are +in the DRAM address range, but must not be accessed or modified. +Describe the inline ECC carveout areas used by the DBSC5 controller +on this hardware as reserved-memory, which must not be accessed. +Include DRAM areas which are unprotected by ECC as well, those are +parts of the DRAM which directly precede the ECC carveout. + +In case of high DRAM utilization, unless the inline ECC carveouts +are properly reserved, Linux may use and corrupt the memory used +by the DBSC5 DRAM controller for inline ECC, which would lead to +the system becoming unstable. + +Fixes: ad142a4ef710 ("arm64: dts: renesas: r8a78000: Add initial Ironhide board support") +Cc: stable@vger.kernel.org +Signed-off-by: Marek Vasut +Tested-by: Geert Uytterhoeven +Reviewed-by: Geert Uytterhoeven +Link: https://patch.msgid.link/20260710160450.64967-1-marek.vasut+renesas@mailbox.org +Signed-off-by: Geert Uytterhoeven +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts | 41 ++++++++++++++++++++++ + 1 file changed, 41 insertions(+) + +--- a/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts ++++ b/arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts +@@ -93,6 +93,47 @@ + reg = <0x0 0x8c400000 0x0 0x02000000>; + no-map; + }; ++ ++ /* DRAM controller inline ECC areas */ ++ ecc@10cccc0000 { ++ reg = <0x10 0xcccc0000 0x0 0x33340000>; ++ no-map; ++ }; ++ ++ ecc@12cccc0000 { ++ reg = <0x12 0xcccc0000 0x0 0x33340000>; ++ no-map; ++ }; ++ ++ ecc@14cccc0000 { ++ reg = <0x14 0xcccc0000 0x0 0x33340000>; ++ no-map; ++ }; ++ ++ ecc@16cccc0000 { ++ reg = <0x16 0xcccc0000 0x0 0x33340000>; ++ no-map; ++ }; ++ ++ ecc@18cccc0000 { ++ reg = <0x18 0xcccc0000 0x0 0x33340000>; ++ no-map; ++ }; ++ ++ ecc@1a66660000 { ++ reg = <0x1a 0x66660000 0x0 0x999a0000>; ++ no-map; ++ }; ++ ++ ecc@1c66660000 { ++ reg = <0x1c 0x66660000 0x0 0x999a0000>; ++ no-map; ++ }; ++ ++ ecc@1e66660000 { ++ reg = <0x1e 0x66660000 0x0 0x999a0000>; ++ no-map; ++ }; + }; + }; + diff --git a/queue-7.1/arm64-dts-rockchip-fix-ethernet-phy-not-found-on-px30-ringneck.patch b/queue-7.1/arm64-dts-rockchip-fix-ethernet-phy-not-found-on-px30-ringneck.patch new file mode 100644 index 0000000000..c95ebf2e32 --- /dev/null +++ b/queue-7.1/arm64-dts-rockchip-fix-ethernet-phy-not-found-on-px30-ringneck.patch @@ -0,0 +1,53 @@ +From ae653cb854f36d1555681ce70ca3d80d0ec73516 Mon Sep 17 00:00:00 2001 +From: Quentin Schulz +Date: Tue, 21 Apr 2026 11:45:06 +0200 +Subject: arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck + +From: Quentin Schulz + +commit ae653cb854f36d1555681ce70ca3d80d0ec73516 upstream. + +When not passing the PHY ID with an ethernet-phy-idX.Y compatible +property, the MDIO bus will attempt to auto-detect the PHY by reading +its registers and then probing the appropriate driver. For this to work, +the PHY needs to be in a working state. + +Unfortunately, the net subsystem doesn't control the PHY reset GPIO when +attempting to auto-detect the PHY. This means the PHY needs to be in a +working state when entering the Linux kernel. This historically has been +the case for this device, but only because the bootloader was taking +care of initializing the Ethernet controller even when not using it. +We're attempting to support the removal of the network stack in the +bootloader, which means the Linux kernel will be entered with the PHY +still in reset and now Ethernet doesn't work anymore. + +The devices in the field only ever had a TI DP83825, so let's simply +bypass the auto-detection mechanism entirely by passing the appropriate +PHY IDs via the compatible. + +Note that this is only an issue since commit e463625af7f9 ("arm64: dts: +rockchip: move reset to dedicated eth-phy node on ringneck") as before +that commit the reset was done by the MAC controller before starting the +MDIO auto-detection mechanism, via the snps,reset-* properties. + +Cc: stable@vger.kernel.org +Fixes: e463625af7f9 ("arm64: dts: rockchip: move reset to dedicated eth-phy node on ringneck") +Signed-off-by: Quentin Schulz +Link: https://patch.msgid.link/20260421-px30-eth-phy-v2-2-68c375b120fd@cherry.de +Signed-off-by: Heiko Stuebner +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi ++++ b/arch/arm64/boot/dts/rockchip/px30-ringneck.dtsi +@@ -344,7 +344,7 @@ + + &mdio { + dp83825: ethernet-phy@0 { +- compatible = "ethernet-phy-ieee802.3-c22"; ++ compatible = "ethernet-phy-id2000.a140"; + reg = <0x0>; + pinctrl-names = "default"; + pinctrl-0 = <&phy_rst>; diff --git a/queue-7.1/arm64-dts-s32g3-fix-swt8-watchdog-address.patch b/queue-7.1/arm64-dts-s32g3-fix-swt8-watchdog-address.patch new file mode 100644 index 0000000000..51cf485092 --- /dev/null +++ b/queue-7.1/arm64-dts-s32g3-fix-swt8-watchdog-address.patch @@ -0,0 +1,40 @@ +From 65210e81f7837a871a17237d15e4b1191d5e8771 Mon Sep 17 00:00:00 2001 +From: Krzysztof Kozlowski +Date: Thu, 28 May 2026 14:03:24 +0200 +Subject: arm64: dts: s32g3: Fix SWT8 watchdog address + +From: Krzysztof Kozlowski + +commit 65210e81f7837a871a17237d15e4b1191d5e8771 upstream. + +Add missing hex annotation to fix the SWT8 watchdog address in 'reg' +property, as reported by dtc W=1: + + s32g3.dtsi:863.27-869.5: Warning (simple_bus_reg): /soc@0/watchdog@40500000: simple-bus unit address format error, expected "269fb20" + +Lack of hex '0x' meant address would be interpreted as decimal thus +completely different value used as this device MMIO. If device was +enabled this could lead to corruption of other device address space and +broken boot. + +Cc: stable@vger.kernel.org +Fixes: 6db84f042745 ("arm64: dts: s32g3: Add the Software Timer Watchdog (SWT) nodes") +Signed-off-by: Krzysztof Kozlowski +Reviewed-by: Daniel Lezcano +Signed-off-by: Frank Li +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/freescale/s32g3.dtsi | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/arm64/boot/dts/freescale/s32g3.dtsi ++++ b/arch/arm64/boot/dts/freescale/s32g3.dtsi +@@ -862,7 +862,7 @@ + + swt8: watchdog@40500000 { + compatible = "nxp,s32g3-swt", "nxp,s32g2-swt"; +- reg = <40500000 0x1000>; ++ reg = <0x40500000 0x1000>; + clocks = <&clks 0x3a>, <&clks 0x3b>, <&clks 0x3b>; + clock-names = "counter", "module", "register"; + status = "disabled"; diff --git a/queue-7.1/arm64-dts-ti-k3-am62a7-sk-add-bootph-all-tag-to-vqmmc.patch b/queue-7.1/arm64-dts-ti-k3-am62a7-sk-add-bootph-all-tag-to-vqmmc.patch new file mode 100644 index 0000000000..ffaa8196ef --- /dev/null +++ b/queue-7.1/arm64-dts-ti-k3-am62a7-sk-add-bootph-all-tag-to-vqmmc.patch @@ -0,0 +1,41 @@ +From d8fe8442366ffd8306575028bda92389d0dfb674 Mon Sep 17 00:00:00 2001 +From: Judith Mendez +Date: Tue, 24 Mar 2026 09:02:47 -0500 +Subject: arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc + +From: Judith Mendez + +commit d8fe8442366ffd8306575028bda92389d0dfb674 upstream. + +Add bootph-all property to vqmmc voltage regulator node and its +corresponding pinmux node to make it available during all boot +phases. This allows to run tuning early in SPL stages of boot. + +Fixes: 8f023012eb4a ("arm64: dts: ti: k3-am62a: Enable UHS mode support for SD cards") +Cc: stable@vger.kernel.org +Signed-off-by: Judith Mendez +Link: https://patch.msgid.link/20260324140247.1200631-1-jm@ti.com +Signed-off-by: Nishanth Menon +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/boot/dts/ti/k3-am62a7-sk.dts | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/arch/arm64/boot/dts/ti/k3-am62a7-sk.dts ++++ b/arch/arm64/boot/dts/ti/k3-am62a7-sk.dts +@@ -154,6 +154,7 @@ + gpios = <&main_gpio0 31 GPIO_ACTIVE_HIGH>; + states = <1800000 0x0>, + <3300000 0x1>; ++ bootph-all; + }; + + leds { +@@ -407,6 +408,7 @@ + pinctrl-single,pins = < + AM62AX_IOPAD(0x07c, PIN_OUTPUT, 7) /* (N22) GPMC0_CLK.GPIO0_31 */ + >; ++ bootph-all; + }; + + main_ecap0_pins_default: main-ecap0-default-pins { diff --git a/queue-7.1/arm64-fpsimd-fix-type-mismatch-in-sve_-save-load-_state.patch b/queue-7.1/arm64-fpsimd-fix-type-mismatch-in-sve_-save-load-_state.patch new file mode 100644 index 0000000000..986a3e79be --- /dev/null +++ b/queue-7.1/arm64-fpsimd-fix-type-mismatch-in-sve_-save-load-_state.patch @@ -0,0 +1,76 @@ +From ae24f6b06e90681ec36b9c21c3f5c09618350f5a Mon Sep 17 00:00:00 2001 +From: Mark Rutland +Date: Wed, 3 Jun 2026 12:06:11 +0100 +Subject: arm64: fpsimd: Fix type mismatch in sve_{save,load}_state() + +From: Mark Rutland + +commit ae24f6b06e90681ec36b9c21c3f5c09618350f5a upstream. + +The sve_save_state() and sve_load_state() functions take a 32-bit int +argument that describes whether to save/restore the FFR. Their assembly +implementations consume the entire 64-bit register containing this +32-bit value, and will attempt to save/restore the FFR if any bit of +that 64-bit register is non-zero. + +Per the AAPCS64 parameter passing rules, the callee is responsible for +any necessary widening, and the upper 32-bits are permitted to contain +arbitrary values. If the upper 32 bits are non-zero, this could result +in an unexpected attempt to save/restore the FFR, and consequently could +lead to unexpected traps/undefs/faults. + +In practice compilers are very unlikely to generate code where the upper +32-bits would be non-zero, but they are permitted to do so. + +Fix this by only consuming the low 32 bits of the register, and update +comments accordingly. + +The hyp code __sve_save_state() and __sve_restore_state() functions +don't have the same latent bug as they override the full 64-bit register +containing the argument. + +Fixes: 9f5848665788 ("arm64/sve: Make access to FFR optional") +Signed-off-by: Mark Rutland +Cc: Catalin Marinas +Cc: Fuad Tabba +Cc: James Morse +Cc: Marc Zyngier +Cc: Mark Brown +Cc: Oliver Upton +Cc: Vladimir Murzin +Cc: Will Deacon +Cc: stable@vger.kernel.org +Signed-off-by: Will Deacon +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kernel/entry-fpsimd.S | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +--- a/arch/arm64/kernel/entry-fpsimd.S ++++ b/arch/arm64/kernel/entry-fpsimd.S +@@ -38,10 +38,10 @@ SYM_FUNC_END(fpsimd_load_state) + * + * x0 - pointer to buffer for state + * x1 - pointer to storage for FPSR +- * x2 - Save FFR if non-zero ++ * w2 - Save FFR if non-zero + */ + SYM_FUNC_START(sve_save_state) +- sve_save 0, x1, x2, 3 ++ sve_save 0, x1, w2, 3 + ret + SYM_FUNC_END(sve_save_state) + +@@ -50,10 +50,10 @@ SYM_FUNC_END(sve_save_state) + * + * x0 - pointer to buffer for state + * x1 - pointer to storage for FPSR +- * x2 - Restore FFR if non-zero ++ * w2 - Restore FFR if non-zero + */ + SYM_FUNC_START(sve_load_state) +- sve_load 0, x1, x2, 4 ++ sve_load 0, x1, w2, 4 + ret + SYM_FUNC_END(sve_load_state) + diff --git a/queue-7.1/asoc-sof-ipc3-control-fix-toctou-in-bytes_put-and-bytes_get.patch b/queue-7.1/asoc-sof-ipc3-control-fix-toctou-in-bytes_put-and-bytes_get.patch new file mode 100644 index 0000000000..1f54ba250b --- /dev/null +++ b/queue-7.1/asoc-sof-ipc3-control-fix-toctou-in-bytes_put-and-bytes_get.patch @@ -0,0 +1,85 @@ +From 1f97760417b5faa60e9642fd0ed61eb17d0b1b39 Mon Sep 17 00:00:00 2001 +From: Peter Ujfalusi +Date: Tue, 9 Jun 2026 11:34:57 +0300 +Subject: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get + +From: Peter Ujfalusi + +commit 1f97760417b5faa60e9642fd0ed61eb17d0b1b39 upstream. + +In sof_ipc3_bytes_put(), the size used for the memcpy is derived from +the old data->size already in the buffer, not the incoming new data's +size field. If the new data has a different size, the copy length is +wrong: it may truncate valid data or copy stale bytes. + +Similarly, sof_ipc3_bytes_get() checks data->size against max_size +without accounting for the sizeof(struct sof_ipc_ctrl_data) offset +of the flex array within the allocation. + +Fix bytes_put to validate and use the incoming data's sof_abi_hdr.size +from ucontrol before copying. Fix bytes_get to subtract sizeof(*cdata) +from the bounds check to match the actual available space. + +Fixes: 544ac8858f24 ("ASoC: SOF: Add bytes_get/put control IPC ops for IPC3") +Cc: stable@vger.kernel.org +Signed-off-by: Peter Ujfalusi +Reviewed-by: Liam Girdwood +Reviewed-by: Bard Liao +Link: https://patch.msgid.link/20260609083458.31193-6-peter.ujfalusi@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Greg Kroah-Hartman +--- + sound/soc/sof/ipc3-control.c | 23 ++++++++++++++++------- + 1 file changed, 16 insertions(+), 7 deletions(-) + +--- a/sound/soc/sof/ipc3-control.c ++++ b/sound/soc/sof/ipc3-control.c +@@ -315,10 +315,13 @@ static int sof_ipc3_bytes_get(struct snd + } + + /* be->max has been verified to be >= sizeof(struct sof_abi_hdr) */ +- if (data->size > scontrol->max_size - sizeof(*data)) { ++ if (data->size > scontrol->max_size - sizeof(*cdata) - ++ sizeof(*data)) { + dev_err_ratelimited(scomp->dev, + "%u bytes of control data is invalid, max is %zu\n", +- data->size, scontrol->max_size - sizeof(*data)); ++ data->size, ++ scontrol->max_size - sizeof(*cdata) - ++ sizeof(*data)); + return -EINVAL; + } + +@@ -336,6 +339,8 @@ static int sof_ipc3_bytes_put(struct snd + struct sof_ipc_ctrl_data *cdata = scontrol->ipc_control_data; + struct snd_soc_component *scomp = scontrol->scomp; + struct sof_abi_hdr *data = cdata->data; ++ const struct sof_abi_hdr *new_hdr = ++ (const struct sof_abi_hdr *)ucontrol->value.bytes.data; + size_t size; + + if (scontrol->max_size > sizeof(ucontrol->value.bytes.data)) { +@@ -344,14 +349,18 @@ static int sof_ipc3_bytes_put(struct snd + return -EINVAL; + } + +- /* scontrol->max_size has been verified to be >= sizeof(struct sof_abi_hdr) */ +- if (data->size > scontrol->max_size - sizeof(*data)) { +- dev_err_ratelimited(scomp->dev, "data size too big %u bytes max is %zu\n", +- data->size, scontrol->max_size - sizeof(*data)); ++ /* Validate the new data's size, not the old one */ ++ if (new_hdr->size > scontrol->max_size - sizeof(*cdata) - ++ sizeof(*new_hdr)) { ++ dev_err_ratelimited(scomp->dev, ++ "data size too big %u bytes max is %zu\n", ++ new_hdr->size, ++ scontrol->max_size - sizeof(*cdata) - ++ sizeof(*new_hdr)); + return -EINVAL; + } + +- size = data->size + sizeof(*data); ++ size = new_hdr->size + sizeof(*new_hdr); + + /* copy from kcontrol */ + memcpy(data, ucontrol->value.bytes.data, size); diff --git a/queue-7.1/asoc-sof-ipc3-control-use-overflow-checks-in-control_update-size-calc.patch b/queue-7.1/asoc-sof-ipc3-control-use-overflow-checks-in-control_update-size-calc.patch new file mode 100644 index 0000000000..0bfeb8b0c7 --- /dev/null +++ b/queue-7.1/asoc-sof-ipc3-control-use-overflow-checks-in-control_update-size-calc.patch @@ -0,0 +1,65 @@ +From 8791977d7289f6e9d2b014f60a5455f053a7bc04 Mon Sep 17 00:00:00 2001 +From: Peter Ujfalusi +Date: Tue, 9 Jun 2026 11:34:55 +0300 +Subject: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc + +From: Peter Ujfalusi + +commit 8791977d7289f6e9d2b014f60a5455f053a7bc04 upstream. + +In sof_ipc3_control_update(), the expected_size calculation uses +firmware-provided cdata->num_elems in arithmetic that could overflow +on 32-bit platforms, wrapping to a small value. This would allow the +cdata->rhdr.hdr.size comparison to pass with mismatched sizes, +potentially leading to out-of-bounds access in snd_sof_update_control. + +Use check_mul_overflow() and check_add_overflow() to detect and reject +overflowed size calculations. + +Fixes: 10f461d79c2d ("ASoC: SOF: Add IPC3 topology control ops") +Cc: stable@vger.kernel.org +Signed-off-by: Peter Ujfalusi +Reviewed-by: Liam Girdwood +Reviewed-by: Bard Liao +Link: https://patch.msgid.link/20260609083458.31193-4-peter.ujfalusi@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Greg Kroah-Hartman +--- + sound/soc/sof/ipc3-control.c | 20 ++++++++++++++++---- + 1 file changed, 16 insertions(+), 4 deletions(-) + +--- a/sound/soc/sof/ipc3-control.c ++++ b/sound/soc/sof/ipc3-control.c +@@ -626,16 +626,28 @@ static void sof_ipc3_control_update(stru + return; + } + +- expected_size = sizeof(struct sof_ipc_ctrl_data); + switch (cdata->type) { + case SOF_CTRL_TYPE_VALUE_CHAN_GET: + case SOF_CTRL_TYPE_VALUE_CHAN_SET: +- expected_size += cdata->num_elems * +- sizeof(struct sof_ipc_ctrl_value_chan); ++ if (check_mul_overflow((size_t)cdata->num_elems, ++ sizeof(struct sof_ipc_ctrl_value_chan), ++ &expected_size)) ++ return; ++ if (check_add_overflow(expected_size, ++ sizeof(struct sof_ipc_ctrl_data), ++ &expected_size)) ++ return; + break; + case SOF_CTRL_TYPE_DATA_GET: + case SOF_CTRL_TYPE_DATA_SET: +- expected_size += cdata->num_elems + sizeof(struct sof_abi_hdr); ++ if (check_add_overflow((size_t)cdata->num_elems, ++ sizeof(struct sof_abi_hdr), ++ &expected_size)) ++ return; ++ if (check_add_overflow(expected_size, ++ sizeof(struct sof_ipc_ctrl_data), ++ &expected_size)) ++ return; + break; + default: + return; diff --git a/queue-7.1/asoc-sof-ipc4-control-fix-toctou-in-sof_ipc4_bytes_put.patch b/queue-7.1/asoc-sof-ipc4-control-fix-toctou-in-sof_ipc4_bytes_put.patch new file mode 100644 index 0000000000..28a80c4933 --- /dev/null +++ b/queue-7.1/asoc-sof-ipc4-control-fix-toctou-in-sof_ipc4_bytes_put.patch @@ -0,0 +1,61 @@ +From 3ad673e7139cf214afd24321a829aad6575f4163 Mon Sep 17 00:00:00 2001 +From: Peter Ujfalusi +Date: Tue, 9 Jun 2026 11:34:53 +0300 +Subject: ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put + +From: Peter Ujfalusi + +commit 3ad673e7139cf214afd24321a829aad6575f4163 upstream. + +In sof_ipc4_bytes_put(), the copy size is derived from the old +data->size in the buffer rather than the incoming new data's size +field from ucontrol. If the new data has a different size, the copy +uses the wrong length: it may truncate valid data or copy stale bytes. + +Fix by validating and using the incoming data's sof_abi_hdr.size from +ucontrol before copying. + +Fixes: a062c8899fed ("ASoC: SOF: ipc4-control: Add support for bytes control get and put") +Cc: stable@vger.kernel.org +Signed-off-by: Peter Ujfalusi +Reviewed-by: Liam Girdwood +Reviewed-by: Bard Liao +Link: https://patch.msgid.link/20260609083458.31193-2-peter.ujfalusi@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Greg Kroah-Hartman +--- + sound/soc/sof/ipc4-control.c | 11 +++++++---- + 1 file changed, 7 insertions(+), 4 deletions(-) + +--- a/sound/soc/sof/ipc4-control.c ++++ b/sound/soc/sof/ipc4-control.c +@@ -562,6 +562,8 @@ static int sof_ipc4_bytes_put(struct snd + struct snd_soc_component *scomp = scontrol->scomp; + struct snd_sof_dev *sdev = snd_soc_component_get_drvdata(scomp); + struct sof_abi_hdr *data = cdata->data; ++ const struct sof_abi_hdr *new_hdr = ++ (const struct sof_abi_hdr *)ucontrol->value.bytes.data; + size_t size; + int ret; + +@@ -572,15 +574,16 @@ static int sof_ipc4_bytes_put(struct snd + return -EINVAL; + } + +- /* scontrol->max_size has been verified to be >= sizeof(struct sof_abi_hdr) */ +- if (data->size > scontrol->max_size - sizeof(*data)) { ++ /* Validate the new data's size, not the old one */ ++ if (new_hdr->size > scontrol->max_size - sizeof(*new_hdr)) { + dev_err_ratelimited(scomp->dev, + "data size too big %u bytes max is %zu\n", +- data->size, scontrol->max_size - sizeof(*data)); ++ new_hdr->size, ++ scontrol->max_size - sizeof(*new_hdr)); + return -EINVAL; + } + +- size = data->size + sizeof(*data); ++ size = new_hdr->size + sizeof(*new_hdr); + + /* copy from kcontrol */ + memcpy(data, ucontrol->value.bytes.data, size); diff --git a/queue-7.1/asoc-sof-ipc4-control-validate-notification-payload-size.patch b/queue-7.1/asoc-sof-ipc4-control-validate-notification-payload-size.patch new file mode 100644 index 0000000000..bec4764a3c --- /dev/null +++ b/queue-7.1/asoc-sof-ipc4-control-validate-notification-payload-size.patch @@ -0,0 +1,70 @@ +From 5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c Mon Sep 17 00:00:00 2001 +From: Peter Ujfalusi +Date: Tue, 9 Jun 2026 11:34:54 +0300 +Subject: ASoC: SOF: ipc4-control: Validate notification payload size + +From: Peter Ujfalusi + +commit 5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c upstream. + +Validate MODULE_NOTIFICATION payload length before reading +bytes/channel data in control update handling. + +Fixes: 2a28b5240f2b ("ASoC: SOF: ipc4-control: Add support for generic bytes control") +Cc: stable@vger.kernel.org +Signed-off-by: Peter Ujfalusi +Reviewed-by: Liam Girdwood +Reviewed-by: Bard Liao +Link: https://patch.msgid.link/20260609083458.31193-3-peter.ujfalusi@linux.intel.com +Signed-off-by: Mark Brown +Signed-off-by: Greg Kroah-Hartman +--- + sound/soc/sof/ipc4-control.c | 23 +++++++++++++++++++++++ + 1 file changed, 23 insertions(+) + +--- a/sound/soc/sof/ipc4-control.c ++++ b/sound/soc/sof/ipc4-control.c +@@ -883,6 +883,16 @@ static void sof_ipc4_control_update(stru + */ + if (type == SND_SOC_TPLG_TYPE_BYTES) { + struct sof_abi_hdr *data = cdata->data; ++ size_t source_size = struct_size(msg_data, data, msg_data->num_elems); ++ ++ if (source_size > ndata->event_data_size) { ++ dev_warn(sdev->dev, ++ "%s: invalid bytes notification size for %s (%zu, %u)\n", ++ __func__, scontrol->name, source_size, ++ ndata->event_data_size); ++ scontrol->comp_data_dirty = true; ++ goto notify; ++ } + + if (msg_data->num_elems > scontrol->max_size - sizeof(*data)) { + dev_warn(sdev->dev, +@@ -895,6 +905,17 @@ static void sof_ipc4_control_update(stru + scontrol->size = sizeof(*cdata) + sizeof(*data) + data->size; + } + } else { ++ size_t source_size = struct_size(msg_data, chanv, msg_data->num_elems); ++ ++ if (source_size > ndata->event_data_size) { ++ dev_warn(sdev->dev, ++ "%s: invalid channel notification size for %s (%zu, %u)\n", ++ __func__, scontrol->name, source_size, ++ ndata->event_data_size); ++ scontrol->comp_data_dirty = true; ++ goto notify; ++ } ++ + for (i = 0; i < msg_data->num_elems; i++) { + u32 channel = msg_data->chanv[i].channel; + +@@ -922,6 +943,8 @@ static void sof_ipc4_control_update(stru + scontrol->comp_data_dirty = true; + } + ++notify: ++ + /* + * Look up the ALSA kcontrol of the scontrol to be able to send a + * notification to user space diff --git a/queue-7.1/asoc-sof-topology-validate-vendor-array-size-before-parsing.patch b/queue-7.1/asoc-sof-topology-validate-vendor-array-size-before-parsing.patch new file mode 100644 index 0000000000..8a6f6f0b5e --- /dev/null +++ b/queue-7.1/asoc-sof-topology-validate-vendor-array-size-before-parsing.patch @@ -0,0 +1,57 @@ +From 8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?C=C3=A1ssio=20Gabriel?= +Date: Wed, 3 Jun 2026 14:57:54 -0300 +Subject: ASoC: SOF: topology: validate vendor array size before parsing +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Cássio Gabriel + +commit 8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05 upstream. + +sof_parse_token_sets() reads array->size while iterating over topology +private data. The loop condition only checks that some data remains, so a +malformed topology with a truncated trailing vendor array can make the +parser read the size field before a full vendor-array header is available. + +Validate that the remaining private data contains a complete +snd_soc_tplg_vendor_array header before reading array->size. + +The declared array size check also needs to remain signed. asize is an int, +but sizeof(*array) has type size_t, so comparing them directly promotes +negative asize values to unsigned and lets them pass the check, +as reported in the stable review thread reference below. + +Cast sizeof(*array) to int when validating the declared array size. This +rejects negative, zero and otherwise too-small sizes before the parser +dispatches to the tuple-specific code. + +Link: https://lore.kernel.org/stable/CANiDSCsjR5NHqu_Ui5cOqWdJgFqmYsQ9WR8O7m0WOhngaYXFpw@mail.gmail.com/t/#m9b3be379221e79327cc13fd71009287368ef4f23 +Fixes: 215e5fe75881 ("ASoC: SOF: topology: reject invalid vendor array size in token parser") +Cc: stable@vger.kernel.org +Signed-off-by: Cássio Gabriel +Link: https://patch.msgid.link/20260603-sof-topology-array-size-signed-v1-1-84f97879a4ef@gmail.com +Signed-off-by: Mark Brown +Signed-off-by: Greg Kroah-Hartman +--- + sound/soc/sof/topology.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +--- a/sound/soc/sof/topology.c ++++ b/sound/soc/sof/topology.c +@@ -733,10 +733,13 @@ static int sof_parse_token_sets(struct s + int ret; + + while (array_size > 0 && total < count * token_instance_num) { ++ if (array_size < (int)sizeof(*array)) ++ return -EINVAL; ++ + asize = le32_to_cpu(array->size); + + /* validate asize */ +- if (asize < sizeof(*array)) { ++ if (asize < (int)sizeof(*array)) { + dev_err(scomp->dev, "error: invalid array size 0x%x\n", + asize); + return -EINVAL; diff --git a/queue-7.1/idpf-add-padding-to-ptp-virtchnl-structures.patch b/queue-7.1/idpf-add-padding-to-ptp-virtchnl-structures.patch new file mode 100644 index 0000000000..438824b2ed --- /dev/null +++ b/queue-7.1/idpf-add-padding-to-ptp-virtchnl-structures.patch @@ -0,0 +1,88 @@ +From d1e8f9fd6b98307bc8d2863c7baa465d8a5a43be Mon Sep 17 00:00:00 2001 +From: Przemyslaw Korba +Date: Mon, 25 May 2026 10:38:03 +0200 +Subject: idpf: add padding to PTP virtchnl structures + +From: Przemyslaw Korba + +commit d1e8f9fd6b98307bc8d2863c7baa465d8a5a43be upstream. + +Add padding to virtchnl2 PTP structures to match the Control Plane +expected message sizes: +* virtchnl2_ptp_get_dev_clk_time: 8 -> 16 bytes +* virtchnl2_ptp_set_dev_clk_time: 8 -> 16 bytes +* virtchnl2_ptp_get_cross_time: 16 -> 24 bytes + +The FW expects the above sizes and PTP negotiation fails due to the +mismatch. Previously neither the FW nor the driver checked message/reply +sizes strictly, so the problem appeared only after recent validation +improvements. + +reproduction steps: +ptp4l -i -m +Observe: failed to open /dev/ptp0: Permission denied + +Fixes: bf27283ba594 ("virtchnl: add PTP virtchnl definitions") +Cc: stable@vger.kernel.org +Reviewed-by: Aleksandr Loktionov +Reviewed-by: Alexander Lobakin +Signed-off-by: Przemyslaw Korba +Tested-by: Samuel Salin +Signed-off-by: Tony Nguyen +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/intel/idpf/virtchnl2.h | 12 +++++++++--- + 1 file changed, 9 insertions(+), 3 deletions(-) + +--- a/drivers/net/ethernet/intel/idpf/virtchnl2.h ++++ b/drivers/net/ethernet/intel/idpf/virtchnl2.h +@@ -1572,13 +1572,15 @@ VIRTCHNL2_CHECK_STRUCT_LEN(16, virtchnl2 + * struct virtchnl2_ptp_get_dev_clk_time - Associated with message + * VIRTCHNL2_OP_PTP_GET_DEV_CLK_TIME. + * @dev_time_ns: Device clock time value in nanoseconds ++ * @pad: Padding for future extensions + * + * PF/VF sends this message to receive the time from the main timer. + */ + struct virtchnl2_ptp_get_dev_clk_time { + __le64 dev_time_ns; ++ u8 pad[8]; + }; +-VIRTCHNL2_CHECK_STRUCT_LEN(8, virtchnl2_ptp_get_dev_clk_time); ++VIRTCHNL2_CHECK_STRUCT_LEN(16, virtchnl2_ptp_get_dev_clk_time); + + /** + * struct virtchnl2_ptp_get_cross_time: Associated with message +@@ -1586,26 +1588,30 @@ VIRTCHNL2_CHECK_STRUCT_LEN(8, virtchnl2_ + * @sys_time_ns: System counter value expressed in nanoseconds, read + * synchronously with device time + * @dev_time_ns: Device clock time value expressed in nanoseconds ++ * @pad: Padding for future extensions + * + * PF/VF sends this message to receive the cross time. + */ + struct virtchnl2_ptp_get_cross_time { + __le64 sys_time_ns; + __le64 dev_time_ns; ++ u8 pad[8]; + }; +-VIRTCHNL2_CHECK_STRUCT_LEN(16, virtchnl2_ptp_get_cross_time); ++VIRTCHNL2_CHECK_STRUCT_LEN(24, virtchnl2_ptp_get_cross_time); + + /** + * struct virtchnl2_ptp_set_dev_clk_time: Associated with message + * VIRTCHNL2_OP_PTP_SET_DEV_CLK_TIME. + * @dev_time_ns: Device time value expressed in nanoseconds to set ++ * @pad: Padding for future extensions + * + * PF/VF sends this message to set the time of the main timer. + */ + struct virtchnl2_ptp_set_dev_clk_time { + __le64 dev_time_ns; ++ u8 pad[8]; + }; +-VIRTCHNL2_CHECK_STRUCT_LEN(8, virtchnl2_ptp_set_dev_clk_time); ++VIRTCHNL2_CHECK_STRUCT_LEN(16, virtchnl2_ptp_set_dev_clk_time); + + /** + * struct virtchnl2_ptp_adj_dev_clk_fine: Associated with message diff --git a/queue-7.1/kvm-arm64-account-pkvm-reclaim-against-the-vm-mm.patch b/queue-7.1/kvm-arm64-account-pkvm-reclaim-against-the-vm-mm.patch new file mode 100644 index 0000000000..4bbe6bac75 --- /dev/null +++ b/queue-7.1/kvm-arm64-account-pkvm-reclaim-against-the-vm-mm.patch @@ -0,0 +1,42 @@ +From d098bb75d14fde2f12155f1a95ec0168160867ce Mon Sep 17 00:00:00 2001 +From: Bradley Morgan +Date: Sun, 21 Jun 2026 21:31:55 +0000 +Subject: KVM: arm64: account pKVM reclaim against the VM mm + +From: Bradley Morgan + +commit d098bb75d14fde2f12155f1a95ec0168160867ce upstream. + +Protected guest faults charge long term pins to the VM's mm. Teardown +can run later from file release, where current->mm may be unrelated. + +Drop the charge from kvm->mm instead. + +Fixes: 4e6e03f9eadd ("KVM: arm64: Hook up reclaim hypercall to pkvm_pgtable_stage2_destroy()") +Signed-off-by: Bradley Morgan +Reviewed-by: Fuad Tabba +Tested-by: Fuad Tabba +Link: https://patch.msgid.link/20260621213155.6019-1-include@grrlz.net +Signed-off-by: Marc Zyngier +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/pkvm.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/arm64/kvm/pkvm.c b/arch/arm64/kvm/pkvm.c +index 053e4f733e4b..428723b1b0f5 100644 +--- a/arch/arm64/kvm/pkvm.c ++++ b/arch/arm64/kvm/pkvm.c +@@ -352,7 +352,7 @@ static int __pkvm_pgtable_stage2_reclaim(struct kvm_pgtable *pgt, u64 start, u64 + page = pfn_to_page(mapping->pfn); + WARN_ON_ONCE(mapping->nr_pages != 1); + unpin_user_pages_dirty_lock(&page, 1, true); +- account_locked_vm(current->mm, 1, false); ++ account_locked_vm(kvm->mm, 1, false); + pkvm_mapping_remove(mapping, &pgt->pkvm_mappings); + kfree(mapping); + } +-- +2.55.0 + diff --git a/queue-7.1/kvm-arm64-ensure-level-is-always-initialized-when-relaxing-perms.patch b/queue-7.1/kvm-arm64-ensure-level-is-always-initialized-when-relaxing-perms.patch new file mode 100644 index 0000000000..1ff5182154 --- /dev/null +++ b/queue-7.1/kvm-arm64-ensure-level-is-always-initialized-when-relaxing-perms.patch @@ -0,0 +1,39 @@ +From 100baf0184896f859290a684f864b8200d8ac872 Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Wed, 1 Jul 2026 16:16:19 -0700 +Subject: KVM: arm64: Ensure level is always initialized when relaxing perms + +From: Oliver Upton + +commit 100baf0184896f859290a684f864b8200d8ac872 upstream. + +stage2_update_leaf_attrs() returns early before writing to @level if the +table walker returned an error. At the same time, +kvm_pgtable_stage2_relax_perms() uses the level as a TLBI TTL hint when the +error was EAGAIN, indicating the vCPU raced with a table update and the TLB +entry it hit is now stale. + +Fall back to an unknown TTL if none was provided by the walk. + +Cc: stable@vger.kernel.org +Fixes: be097997a273 ("KVM: arm64: Always invalidate TLB for stage-2 permission faults") +Signed-off-by: Oliver Upton +Reviewed-by: Wei-Lin Chang +Link: https://patch.msgid.link/20260701231620.3300204-2-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/hyp/pgtable.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/arm64/kvm/hyp/pgtable.c ++++ b/arch/arm64/kvm/hyp/pgtable.c +@@ -1358,7 +1358,7 @@ int kvm_pgtable_stage2_relax_perms(struc + enum kvm_pgtable_prot prot, enum kvm_pgtable_walk_flags flags) + { + kvm_pte_t xn = 0, set = 0, clr = 0; +- s8 level; ++ s8 level = TLBI_TTL_UNKNOWN; + int ret; + + if (prot & KVM_PTE_LEAF_ATTR_HI_SW) diff --git a/queue-7.1/kvm-arm64-nv-drop-bogus-warn-for-write-to-zcr_el2.patch b/queue-7.1/kvm-arm64-nv-drop-bogus-warn-for-write-to-zcr_el2.patch new file mode 100644 index 0000000000..0c8bd00f84 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-drop-bogus-warn-for-write-to-zcr_el2.patch @@ -0,0 +1,37 @@ +From 9f1667098c6ae7ec81a9a56859cfdacb822aa0d0 Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Sun, 14 Jun 2026 22:13:24 -0700 +Subject: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 + +From: Oliver Upton + +commit 9f1667098c6ae7ec81a9a56859cfdacb822aa0d0 upstream. + +It is entirely possible for a guest to write to the ZCR_EL2 sysreg alias +while in a nested context, as it is expected if FEAT_NV2 is advertised +to the L1 hypervisor. + +Get rid of the bogus WARN which, since the hyp vectors were installed at +this point, has the effect of a hyp_panic... + +Cc: stable@vger.kernel.org +Fixes: 0cfc85b8f5cf ("KVM: arm64: nv: Load guest FP state for ZCR_EL2 trap") +Signed-off-by: Oliver Upton +Link: https://patch.msgid.link/20260615051324.830045-1-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/hyp/include/hyp/switch.h | 2 -- + 1 file changed, 2 deletions(-) + +--- a/arch/arm64/kvm/hyp/include/hyp/switch.h ++++ b/arch/arm64/kvm/hyp/include/hyp/switch.h +@@ -601,8 +601,6 @@ static inline bool kvm_hyp_handle_fpsimd + return false; + break; + case ESR_ELx_EC_SYS64: +- if (WARN_ON_ONCE(!is_hyp_ctxt(vcpu))) +- return false; + fallthrough; + case ESR_ELx_EC_SVE: + if (!sve_guest) diff --git a/queue-7.1/kvm-arm64-nv-fix-spsr_el2-restore-in-kvm_hyp_handle_mops.patch b/queue-7.1/kvm-arm64-nv-fix-spsr_el2-restore-in-kvm_hyp_handle_mops.patch new file mode 100644 index 0000000000..76d3446641 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-fix-spsr_el2-restore-in-kvm_hyp_handle_mops.patch @@ -0,0 +1,60 @@ +From ff1022c3de46753eb7eba2f6efd990569e66ff95 Mon Sep 17 00:00:00 2001 +From: Weiming Shi +Date: Wed, 17 Jun 2026 12:08:21 +0800 +Subject: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() + +From: Weiming Shi + +commit ff1022c3de46753eb7eba2f6efd990569e66ff95 upstream. + +kvm_hyp_handle_mops() resets the single-step state machine as part of +rewinding state for a MOPS exception by modifying vcpu_cpsr() and +writing the result directly into hardware. + +In the case of nested virtualization, vcpu_cpsr() is a synthetic value +such that the rest of KVM can deal with vEL2 cleanly. That means the +value requires translation before being written into hardware, which is +unfortunately missing from the MOPS handler. + +Fix it by directly modifying SPSR_EL2 and avoiding the synthetic state +altogether, which will be resynchronized on the next 'full' exit back +to KVM. + +Fixes: 2de451a329cf ("KVM: arm64: Add handler for MOPS exceptions") +Reported-by: Zhong Wang +Reported-by: Xuanqing Shi +Link: https://lore.kernel.org/all/ajE4lHQevXNHpl1M@Air.local/ +Cc: stable@vger.kernel.org +Signed-off-by: Weiming Shi +Link: https://patch.msgid.link/20260617040820.2194831-2-bestswngs@gmail.com +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/hyp/include/hyp/switch.h | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +--- a/arch/arm64/kvm/hyp/include/hyp/switch.h ++++ b/arch/arm64/kvm/hyp/include/hyp/switch.h +@@ -448,16 +448,19 @@ static inline bool __populate_fault_info + + static inline bool kvm_hyp_handle_mops(struct kvm_vcpu *vcpu, u64 *exit_code) + { ++ u64 spsr; ++ + *vcpu_pc(vcpu) = read_sysreg_el2(SYS_ELR); + arm64_mops_reset_regs(vcpu_gp_regs(vcpu), vcpu->arch.fault.esr_el2); + write_sysreg_el2(*vcpu_pc(vcpu), SYS_ELR); + + /* + * Finish potential single step before executing the prologue +- * instruction. ++ * instruction. Modify the hardware SPSR_EL2 directly, as vcpu_cpsr() ++ * may hold a synthetic (vEL2) value for a guest hypervisor. + */ +- *vcpu_cpsr(vcpu) &= ~DBG_SPSR_SS; +- write_sysreg_el2(*vcpu_cpsr(vcpu), SYS_SPSR); ++ spsr = read_sysreg_el2(SYS_SPSR); ++ write_sysreg_el2(spsr & ~DBG_SPSR_SS, SYS_SPSR); + + return true; + } diff --git a/queue-7.1/kvm-arm64-nv-inject-sea-if-guest-vncr-isn-t-normal-memory.patch b/queue-7.1/kvm-arm64-nv-inject-sea-if-guest-vncr-isn-t-normal-memory.patch new file mode 100644 index 0000000000..7a6e3f93ad --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-inject-sea-if-guest-vncr-isn-t-normal-memory.patch @@ -0,0 +1,48 @@ +From 4bd7dbe0b2243e6aa735cae4d5e1ff988b30b2a6 Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Thu, 18 Jun 2026 16:42:05 -0700 +Subject: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory + +From: Oliver Upton + +commit 4bd7dbe0b2243e6aa735cae4d5e1ff988b30b2a6 upstream. + +When constructing an L1 VNCR mapping, KVM unconditionally uses cacheable +memory attributes, even if the underlying PFN isn't memory. This gets +particularly hairy if the endpoint doesn't support cacheable memory +attributes, potentially throwing an SError on writeback... + +While KVM does permit cacheable memory attributes on certain PFNMAP +VMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the +simpler thing for now and just reject everything that isn't memory. + +Cc: stable@vger.kernel.org +Fixes: 2a359e072596 ("KVM: arm64: nv: Handle mapping of VNCR_EL2 at EL2") +Signed-off-by: Oliver Upton +Link: https://patch.msgid.link/20260618234207.1063941-5-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/nested.c | 11 +++++++++++ + 1 file changed, 11 insertions(+) + +--- a/arch/arm64/kvm/nested.c ++++ b/arch/arm64/kvm/nested.c +@@ -1333,6 +1333,17 @@ static int kvm_translate_vncr(struct kvm + writable = !(memslot->flags & KVM_MEM_READONLY); + } + ++ /* ++ * FIXME: This check is too restrictive as KVM allows cacheable memory ++ * attributes for PFNMAP VMAs that have cacheable attributes in host ++ * stage-1. ++ */ ++ if (!pfn_is_map_memory(pfn)) { ++ kvm_release_faultin_page(vcpu->kvm, page, true, false); ++ fail_s1_walk(&vt->wr, ESR_ELx_FSC_EXTABT, false); ++ return -EINVAL; ++ } ++ + scoped_guard(write_lock, &vcpu->kvm->mmu_lock) { + if (mmu_invalidate_retry(vcpu->kvm, mmu_seq)) { + kvm_release_faultin_page(vcpu->kvm, page, true, false); diff --git a/queue-7.1/kvm-arm64-nv-inject-sea-if-kvm_translate_vncr-can-t-resolve-pfn.patch b/queue-7.1/kvm-arm64-nv-inject-sea-if-kvm_translate_vncr-can-t-resolve-pfn.patch new file mode 100644 index 0000000000..286b059f75 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-inject-sea-if-kvm_translate_vncr-can-t-resolve-pfn.patch @@ -0,0 +1,97 @@ +From 9f3e83345a56280efffe235c65593c7e544c0fcc Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Thu, 18 Jun 2026 16:42:03 -0700 +Subject: KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN + +From: Oliver Upton + +commit 9f3e83345a56280efffe235c65593c7e544c0fcc upstream. + +kvm_handle_vncr_abort() assumes that s1_walk_result conveys an abort +when kvm_translate_vncr() returns -EFAULT. This is not always the case +as it's possible to encounter 'late' failures on the output of S1 +translation, e.g. a GFN outside of the memslots. + +Fix it by preparing an external abort before returning from +kvm_translate_vncr(). Get rid of the BUG_ON() in the fault injection +path while at it. + +Cc: stable@vger.kernel.org +Fixes: 2a359e072596 ("KVM: arm64: nv: Handle mapping of VNCR_EL2 at EL2") +Signed-off-by: Oliver Upton +Link: https://patch.msgid.link/20260618234207.1063941-3-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/include/asm/kvm_nested.h | 8 ++++++++ + arch/arm64/kvm/at.c | 8 -------- + arch/arm64/kvm/nested.c | 10 ++++++---- + 3 files changed, 14 insertions(+), 12 deletions(-) + +--- a/arch/arm64/include/asm/kvm_nested.h ++++ b/arch/arm64/include/asm/kvm_nested.h +@@ -388,6 +388,14 @@ struct s1_walk_result { + bool failed; + }; + ++static inline void fail_s1_walk(struct s1_walk_result *wr, u8 fst, bool s1ptw) ++{ ++ wr->fst = fst; ++ wr->ptw = s1ptw; ++ wr->s2 = s1ptw; ++ wr->failed = true; ++} ++ + int __kvm_translate_va(struct kvm_vcpu *vcpu, struct s1_walk_info *wi, + struct s1_walk_result *wr, u64 va); + int __kvm_find_s1_desc_level(struct kvm_vcpu *vcpu, u64 va, u64 ipa, +--- a/arch/arm64/kvm/at.c ++++ b/arch/arm64/kvm/at.c +@@ -11,14 +11,6 @@ + #include + #include + +-static void fail_s1_walk(struct s1_walk_result *wr, u8 fst, bool s1ptw) +-{ +- wr->fst = fst; +- wr->ptw = s1ptw; +- wr->s2 = s1ptw; +- wr->failed = true; +-} +- + #define S1_MMU_DISABLED (-127) + + static int get_ia_size(struct s1_walk_info *wi) +--- a/arch/arm64/kvm/nested.c ++++ b/arch/arm64/kvm/nested.c +@@ -1309,15 +1309,19 @@ static int kvm_translate_vncr(struct kvm + + gfn = vt->wr.pa >> PAGE_SHIFT; + memslot = gfn_to_memslot(vcpu->kvm, gfn); +- if (!memslot) ++ if (!memslot) { ++ fail_s1_walk(&vt->wr, ESR_ELx_FSC_EXTABT, false); + return -EFAULT; ++ } + + *is_gmem = kvm_slot_has_gmem(memslot); + if (!*is_gmem) { + pfn = __kvm_faultin_pfn(memslot, gfn, write_fault ? FOLL_WRITE : 0, + &writable, &page); +- if (is_error_noslot_pfn(pfn)) ++ if (is_error_noslot_pfn(pfn)) { ++ fail_s1_walk(&vt->wr, ESR_ELx_FSC_EXTABT, false); + return -EFAULT; ++ } + } else { + ret = kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, &page, NULL); + if (ret) { +@@ -1444,8 +1448,6 @@ int kvm_handle_vncr_abort(struct kvm_vcp + * Translation failed, inject the corresponding + * exception back to EL2. + */ +- BUG_ON(!vt->wr.failed); +- + esr &= ~ESR_ELx_FSC; + esr |= FIELD_PREP(ESR_ELx_FSC, vt->wr.fst); + diff --git a/queue-7.1/kvm-arm64-nv-re-translate-vncr-before-injecting-abort.patch b/queue-7.1/kvm-arm64-nv-re-translate-vncr-before-injecting-abort.patch new file mode 100644 index 0000000000..a977b8dae9 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-re-translate-vncr-before-injecting-abort.patch @@ -0,0 +1,165 @@ +From bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Thu, 18 Jun 2026 16:42:04 -0700 +Subject: KVM: arm64: nv: Re-translate VNCR before injecting abort + +From: Oliver Upton + +commit bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f upstream. + +KVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts +for a write, similar to how a regular stage-2 mapping is handled. It is +entirely possible that the guest reads from the VNCR before writing to +it, in which case the PFN could only be read-only. + +Invalidate the VNCR TLB and re-fetch the translation upon taking a VNCR +abort, allowing the host mapping to be faulted in for write the second +time around. Interestingly enough, this also satisfies the ordering +requirements of FEAT_ETS2/3 between descriptor updates and MMU faults. + +Cc: stable@vger.kernel.org +Fixes: 2a359e072596 ("KVM: arm64: nv: Handle mapping of VNCR_EL2 at EL2") +Reported-by: Sashiko +Signed-off-by: Oliver Upton +Link: https://patch.msgid.link/20260618234207.1063941-4-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/nested.c | 115 ++++++++++++++++++------------------------------ + 1 file changed, 44 insertions(+), 71 deletions(-) + +--- a/arch/arm64/kvm/nested.c ++++ b/arch/arm64/kvm/nested.c +@@ -1380,88 +1380,61 @@ static void handle_vncr_perm(struct kvm_ + kvm_inject_nested_sync(vcpu, esr); + } + +-static bool kvm_vncr_tlb_lookup(struct kvm_vcpu *vcpu) +-{ +- struct vncr_tlb *vt = vcpu->arch.vncr_tlb; +- +- lockdep_assert_held_read(&vcpu->kvm->mmu_lock); +- +- if (!vt->valid) +- return false; +- +- if (read_vncr_el2(vcpu) != vt->gva) +- return false; +- +- if (vt->wr.nG) +- return get_asid_by_regime(vcpu, TR_EL20) == vt->wr.asid; +- +- return true; +-} +- + int kvm_handle_vncr_abort(struct kvm_vcpu *vcpu) + { + struct vncr_tlb *vt = vcpu->arch.vncr_tlb; + u64 esr = kvm_vcpu_get_esr(vcpu); ++ bool is_gmem = false; ++ bool perm; ++ int ret; + + WARN_ON_ONCE(!(esr & ESR_ELx_VNCR)); + + if (kvm_vcpu_abt_issea(vcpu)) + return kvm_handle_guest_sea(vcpu); + +- if (esr_fsc_is_permission_fault(esr)) { +- handle_vncr_perm(vcpu); +- } else if (esr_fsc_is_translation_fault(esr)) { +- bool valid, is_gmem = false; +- int ret; +- +- scoped_guard(read_lock, &vcpu->kvm->mmu_lock) +- valid = kvm_vncr_tlb_lookup(vcpu); +- +- if (!valid) +- ret = kvm_translate_vncr(vcpu, &is_gmem); +- else +- ret = -EPERM; +- +- switch (ret) { +- case -EAGAIN: +- /* Let's try again... */ +- break; +- case -ENOMEM: +- /* +- * For guest_memfd, this indicates that it failed to +- * create a folio to back the memory. Inform userspace. +- */ +- if (is_gmem) +- return 0; +- /* Otherwise, let's try again... */ +- break; +- case -EFAULT: +- case -EIO: +- case -EHWPOISON: +- if (is_gmem) +- return 0; +- fallthrough; +- case -EINVAL: +- case -ENOENT: +- case -EACCES: +- /* +- * Translation failed, inject the corresponding +- * exception back to EL2. +- */ +- esr &= ~ESR_ELx_FSC; +- esr |= FIELD_PREP(ESR_ELx_FSC, vt->wr.fst); +- +- kvm_inject_nested_sync(vcpu, esr); +- break; +- case -EPERM: +- /* Hack to deal with POE until we get kernel support */ +- handle_vncr_perm(vcpu); +- break; +- case 0: +- break; +- } +- } else { ++ if (!esr_fsc_is_translation_fault(esr) && !esr_fsc_is_permission_fault(esr)) { + WARN_ONCE(1, "Unhandled VNCR abort, ESR=%llx\n", esr); ++ return 1; ++ } ++ ++ ret = kvm_translate_vncr(vcpu, &is_gmem); ++ switch (ret) { ++ case -EAGAIN: ++ /* Let's try again... */ ++ return 1; ++ case -ENOMEM: ++ /* ++ * For guest_memfd, this indicates that it failed to ++ * create a folio to back the memory. Inform userspace. ++ */ ++ if (is_gmem) ++ return 0; ++ /* Otherwise, let's try again... */ ++ break; ++ case -EFAULT: ++ case -EIO: ++ case -EHWPOISON: ++ if (is_gmem) ++ return 0; ++ fallthrough; ++ case -EINVAL: ++ case -ENOENT: ++ case -EACCES: ++ /* ++ * Translation failed, inject the corresponding ++ * exception back to EL2. ++ */ ++ esr &= ~ESR_ELx_FSC; ++ esr |= FIELD_PREP(ESR_ELx_FSC, vt->wr.fst); ++ ++ kvm_inject_nested_sync(vcpu, esr); ++ break; ++ case 0: ++ perm = kvm_is_write_fault(vcpu) ? vt->wr.pw && vt->hpa_writable : vt->wr.pr; ++ if (!perm) ++ handle_vncr_perm(vcpu); ++ break; + } + + return 1; diff --git a/queue-7.1/kvm-arm64-nv-respect-read-only-pfn-when-mapping-l1-vncr.patch b/queue-7.1/kvm-arm64-nv-respect-read-only-pfn-when-mapping-l1-vncr.patch new file mode 100644 index 0000000000..f27596b1e5 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-respect-read-only-pfn-when-mapping-l1-vncr.patch @@ -0,0 +1,134 @@ +From 2684e02bac41c5220f6c1ab2bdcc957b71812977 Mon Sep 17 00:00:00 2001 +From: Oliver Upton +Date: Thu, 18 Jun 2026 16:42:02 -0700 +Subject: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR + +From: Oliver Upton + +commit 2684e02bac41c5220f6c1ab2bdcc957b71812977 upstream. + +KVM currently maps the L1 VNCR into the host stage-1 by relying entirely +on the permissions of the guest stage-1. At the same time, it is +entirely possible that the backing PFN is read-only (e.g. RO memslot), +meaning that the L1 VNCR should use at most a read-only mapping. + +Cache the writability of the PFN in the VNCR TLB and use it to constrain +the resulting fixmap permissions. Promote VNCR permission faults to an +SEA in the case where the guest attempts to write to a read-only +endpoint. Conveniently, this also plugs a page leak found by Sashiko [*] +resulting from the early return for a read-only PFN. + +Cc: stable@vger.kernel.org +Fixes: 2a359e072596 ("KVM: arm64: nv: Handle mapping of VNCR_EL2 at EL2") +Link: https://lore.kernel.org/kvm/20260608082603.16AEC1F00893@smtp.kernel.org/ +Signed-off-by: Oliver Upton +Link: https://patch.msgid.link/20260618234207.1063941-2-oupton@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/nested.c | 36 ++++++++++++++++++++++++++---------- + 1 file changed, 26 insertions(+), 10 deletions(-) + +--- a/arch/arm64/kvm/nested.c ++++ b/arch/arm64/kvm/nested.c +@@ -24,6 +24,7 @@ struct vncr_tlb { + struct s1_walk_result wr; + + u64 hpa; ++ bool hpa_writable; + + /* -1 when not mapped on a CPU */ + int cpu; +@@ -1315,7 +1316,7 @@ static int kvm_translate_vncr(struct kvm + if (!*is_gmem) { + pfn = __kvm_faultin_pfn(memslot, gfn, write_fault ? FOLL_WRITE : 0, + &writable, &page); +- if (is_error_noslot_pfn(pfn) || (write_fault && !writable)) ++ if (is_error_noslot_pfn(pfn)) + return -EFAULT; + } else { + ret = kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, &page, NULL); +@@ -1324,6 +1325,8 @@ static int kvm_translate_vncr(struct kvm + write_fault, false, false); + return ret; + } ++ ++ writable = !(memslot->flags & KVM_MEM_READONLY); + } + + scoped_guard(write_lock, &vcpu->kvm->mmu_lock) { +@@ -1334,28 +1337,41 @@ static int kvm_translate_vncr(struct kvm + + vt->gva = va; + vt->hpa = pfn << PAGE_SHIFT; ++ vt->hpa_writable = writable; + vt->valid = true; + vt->cpu = -1; + + kvm_make_request(KVM_REQ_MAP_L1_VNCR_EL2, vcpu); +- kvm_release_faultin_page(vcpu->kvm, page, false, vt->wr.pw); ++ kvm_release_faultin_page(vcpu->kvm, page, false, vt->wr.pw && vt->hpa_writable); + } + +- if (vt->wr.pw) ++ if (vt->wr.pw && vt->hpa_writable) + mark_page_dirty(vcpu->kvm, gfn); + + return 0; + } + +-static void inject_vncr_perm(struct kvm_vcpu *vcpu) ++static void handle_vncr_perm(struct kvm_vcpu *vcpu) + { + struct vncr_tlb *vt = vcpu->arch.vncr_tlb; + u64 esr = kvm_vcpu_get_esr(vcpu); ++ u64 fsc; ++ ++ /* ++ * Promote to an external abort if the stage-1 permits writes but the ++ * HPA is read-only (e.g. RO memslot). ++ */ ++ if (kvm_is_write_fault(vcpu) && vt->wr.pw && !vt->hpa_writable) ++ fsc = ESR_ELx_FSC_EXTABT; ++ /* ++ * Otherwise, inject a permission fault using the guest's translation ++ * level rather than the host's. ++ */ ++ else ++ fsc = ESR_ELx_FSC_PERM_L(vt->wr.level); + +- /* Adjust the fault level to reflect that of the guest's */ + esr &= ~ESR_ELx_FSC; +- esr |= FIELD_PREP(ESR_ELx_FSC, +- ESR_ELx_FSC_PERM_L(vt->wr.level)); ++ esr |= FIELD_PREP(ESR_ELx_FSC, fsc); + + kvm_inject_nested_sync(vcpu, esr); + } +@@ -1389,7 +1405,7 @@ int kvm_handle_vncr_abort(struct kvm_vcp + return kvm_handle_guest_sea(vcpu); + + if (esr_fsc_is_permission_fault(esr)) { +- inject_vncr_perm(vcpu); ++ handle_vncr_perm(vcpu); + } else if (esr_fsc_is_translation_fault(esr)) { + bool valid, is_gmem = false; + int ret; +@@ -1437,7 +1453,7 @@ int kvm_handle_vncr_abort(struct kvm_vcp + break; + case -EPERM: + /* Hack to deal with POE until we get kernel support */ +- inject_vncr_perm(vcpu); ++ handle_vncr_perm(vcpu); + break; + case 0: + break; +@@ -1481,7 +1497,7 @@ static void kvm_map_l1_vncr(struct kvm_v + + vt->cpu = smp_processor_id(); + +- if (vt->wr.pw && vt->wr.pr) ++ if (vt->hpa_writable && vt->wr.pw && vt->wr.pr) + prot = PAGE_KERNEL; + else if (vt->wr.pr) + prot = PAGE_KERNEL_RO; diff --git a/queue-7.1/kvm-arm64-nv-write-esr_el2-for-injected-nested-serror-exceptions.patch b/queue-7.1/kvm-arm64-nv-write-esr_el2-for-injected-nested-serror-exceptions.patch new file mode 100644 index 0000000000..5e6815a567 --- /dev/null +++ b/queue-7.1/kvm-arm64-nv-write-esr_el2-for-injected-nested-serror-exceptions.patch @@ -0,0 +1,40 @@ +From e2cb1f4578625e71f461d5c1ce70984193389cbb Mon Sep 17 00:00:00 2001 +From: Fuad Tabba +Date: Mon, 15 Jun 2026 14:11:16 +0100 +Subject: KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions + +From: Fuad Tabba + +commit e2cb1f4578625e71f461d5c1ce70984193389cbb upstream. + +kvm_inject_el2_exception() writes ESR_EL2 for synchronous exceptions +but not for SError. enter_exception64() does not write ESR_ELx for any +exception type, so the constructed syndrome is dropped. A guest L2 +hypervisor taking a nested SError observes stale ESR_EL2. + +This affects both kvm_inject_nested_serror() and the EASE path in +kvm_inject_nested_sea(). + +Write ESR_EL2 for except_type_serror, matching except_type_sync. + +Fixes: 77ee70a07357 ("KVM: arm64: nv: Honor SError exception routing / masking") +Reported-by: sashiko +Signed-off-by: Fuad Tabba +Link: https://patch.msgid.link/20260615131116.390977-1-tabba@google.com +Signed-off-by: Marc Zyngier +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/emulate-nested.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/arch/arm64/kvm/emulate-nested.c ++++ b/arch/arm64/kvm/emulate-nested.c +@@ -2818,6 +2818,7 @@ static void kvm_inject_el2_exception(str + break; + case except_type_serror: + kvm_pend_exception(vcpu, EXCEPT_AA64_EL2_SERR); ++ vcpu_write_sys_reg(vcpu, esr_el2, ESR_EL2); + break; + default: + WARN_ONCE(1, "Unsupported EL2 exception injection %d\n", type); diff --git a/queue-7.1/kvm-arm64-vgic-check-the-interrupt-is-still-ours-before-migrating-it.patch b/queue-7.1/kvm-arm64-vgic-check-the-interrupt-is-still-ours-before-migrating-it.patch new file mode 100644 index 0000000000..e8c8ba85a7 --- /dev/null +++ b/queue-7.1/kvm-arm64-vgic-check-the-interrupt-is-still-ours-before-migrating-it.patch @@ -0,0 +1,60 @@ +From 0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe Mon Sep 17 00:00:00 2001 +From: Hyunwoo Kim +Date: Fri, 5 Jun 2026 05:59:15 +0900 +Subject: KVM: arm64: vgic: Check the interrupt is still ours before migrating it + +From: Hyunwoo Kim + +commit 0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe upstream. + +vgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating +an interrupt to another vCPU. After reacquiring the locks it only checks +that the affinity is unchanged (target_vcpu == vgic_target_oracle(irq)) +before moving the interrupt, which assumes that an interrupt whose affinity +is preserved is still queued on this vCPU's ap_list. + +That assumption no longer holds if the interrupt is taken off the ap_list +while the locks are dropped. vgic_flush_pending_lpis() removes the +interrupt from the list and sets irq->vcpu to NULL, but leaves +enabled/pending/target_vcpu untouched. As the interrupt is still enabled +and pending, vgic_target_oracle() returns the same target_vcpu, so the +affinity check passes and list_del() is run a second time on an entry that +has already been removed. + +Also check that the interrupt is still assigned to this vCPU +(irq->vcpu == vcpu) before moving it. + +Fixes: 0919e84c0fc1 ("KVM: arm/arm64: vgic-new: Add IRQ sync/flush framework") +Signed-off-by: Hyunwoo Kim +Link: https://patch.msgid.link/aiHnI1mu6SGQrgnz@v4bel +Signed-off-by: Marc Zyngier +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/vgic/vgic.c | 11 ++++++----- + 1 file changed, 6 insertions(+), 5 deletions(-) + +--- a/arch/arm64/kvm/vgic/vgic.c ++++ b/arch/arm64/kvm/vgic/vgic.c +@@ -818,15 +818,16 @@ retry: + raw_spin_lock(&irq->irq_lock); + + /* +- * If the affinity has been preserved, move the +- * interrupt around. Otherwise, it means things have +- * changed while the interrupt was unlocked, and we +- * need to replay this. ++ * If the interrupt is still ours and its affinity has ++ * been preserved, move it around. Otherwise, it means ++ * things have changed while the interrupt was unlocked ++ * (it may even have been taken off the list with its ++ * affinity left untouched), and we need to replay this. + * + * In all cases, we cannot trust the list not to have + * changed, so we restart from the beginning. + */ +- if (target_vcpu == vgic_target_oracle(irq)) { ++ if (irq->vcpu == vcpu && target_vcpu == vgic_target_oracle(irq)) { + struct vgic_cpu *new_cpu = &target_vcpu->arch.vgic_cpu; + + list_del(&irq->ap_list); diff --git a/queue-7.1/kvm-arm64-vgic-handle-race-between-interrupt-affinity-change-and-lpi-disabling.patch b/queue-7.1/kvm-arm64-vgic-handle-race-between-interrupt-affinity-change-and-lpi-disabling.patch new file mode 100644 index 0000000000..fbf19a421d --- /dev/null +++ b/queue-7.1/kvm-arm64-vgic-handle-race-between-interrupt-affinity-change-and-lpi-disabling.patch @@ -0,0 +1,76 @@ +From 7258770e5814f15e8308ebda82ac9acf6964ba8e Mon Sep 17 00:00:00 2001 +From: Marc Zyngier +Date: Mon, 15 Jun 2026 19:16:25 +0100 +Subject: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling + +From: Marc Zyngier + +commit 7258770e5814f15e8308ebda82ac9acf6964ba8e upstream. + +Hyunwoo Kim reports some really bad races should the following +situation occur: + +- LPI-I is pending in vcpu-B's AP list +- vcpu-A writes to vcpu-B's RD to disable its LPIs +- vcpu-C moves I from B to C + +If the last two race nicely enough, vgic_prune_ap_list() can drop +the irq and AP list locks, reacquire them, and in the interval +the irq has been freed. UAF follows. + +The fix is two-fold: + +- Before dropping the irq and ap_list locks, take a reference on + the irq + +- Do not try to handle migration of the pending bit: there is no + expectation that this state is retained, as per the architecture + +With that, we're sure that the interrupt is still around, and we +safely remove it from the AP list as it has no target at this +stage (unless another interrupt fires, but that's another story). + +Reported-by: Hyunwoo Kim +Tested-by: Hyunwoo Kim +Link: https://lore.kernel.org/r/ailsCnyoS82r_QRz@v4bel +Link: https://patch.msgid.link/20260615181625.3029352-1-maz@kernel.org +Fixes: 5dd4b924e390a ("KVM: arm/arm64: vgic: Add refcounting for IRQs") +Signed-off-by: Marc Zyngier +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/vgic/vgic.c | 9 ++++++++- + 1 file changed, 8 insertions(+), 1 deletion(-) + +--- a/arch/arm64/kvm/vgic/vgic.c ++++ b/arch/arm64/kvm/vgic/vgic.c +@@ -204,6 +204,7 @@ void vgic_flush_pending_lpis(struct kvm_ + list_for_each_entry_safe(irq, tmp, &vgic_cpu->ap_list_head, ap_list) { + if (irq_is_lpi(vcpu->kvm, irq->intid)) { + raw_spin_lock(&irq->irq_lock); ++ irq->pending_latch = false; + list_del(&irq->ap_list); + irq->vcpu = NULL; + raw_spin_unlock(&irq->irq_lock); +@@ -795,7 +796,11 @@ retry: + continue; + } + +- /* This interrupt looks like it has to be migrated. */ ++ /* ++ * This interrupt looks like it has to be migrated, ++ * make sure it is kept alive while locks are dropped. ++ */ ++ vgic_get_irq_ref(irq); + + raw_spin_unlock(&irq->irq_lock); + raw_spin_unlock(&vgic_cpu->ap_list_lock); +@@ -840,6 +845,8 @@ retry: + raw_spin_unlock(&vcpuB->arch.vgic_cpu.ap_list_lock); + raw_spin_unlock(&vcpuA->arch.vgic_cpu.ap_list_lock); + ++ deleted_lpis |= vgic_put_irq_norelease(vcpu->kvm, irq); ++ + if (target_vcpu_needs_kick) { + kvm_make_request(KVM_REQ_IRQ_PENDING, target_vcpu); + kvm_vcpu_kick(target_vcpu); diff --git a/queue-7.1/kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch b/queue-7.1/kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch new file mode 100644 index 0000000000..daf29100ca --- /dev/null +++ b/queue-7.1/kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch @@ -0,0 +1,79 @@ +From 3a07249981629ace483ebbef81ef6b34c2d2afec Mon Sep 17 00:00:00 2001 +From: Marc Zyngier +Date: Sat, 27 Jun 2026 11:51:05 +0100 +Subject: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers + +From: Marc Zyngier + +commit 3a07249981629ace483ebbef81ef6b34c2d2afec upstream. + +kvm_io_bus_get_dev() returns a device that is only matched by the +address, and nothing else. This can cause a lifetime issue if +the matched device is not the expected type, as by the time +the caller can introspect the object, it might be gone (the srcu +lock having been dropped). + +Given that there is only a single user of this helper, the simplest +option is to move the locking responsibility to the caller, which +can keep the srcu lock held for as long as it wants. + +Note that this aligns with other kvm_io_bus*() helpers, which +already require the srcu lock to be held by the callers. + +Reported-by: Will Deacon +Fixes: 8a39d00670f07 ("KVM: kvm_io_bus: Add kvm_io_bus_get_dev() call") +Link: https://lore.kernel.org/all/20260626111344.802555-1-maz@kernel.org +Cc: stable@vger.kernel.org +Reviewed-by: Oliver Upton +Link: https://patch.msgid.link/20260627105105.1005990-1-maz@kernel.org +Signed-off-by: Marc Zyngier +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kvm/vgic/vgic-its.c | 2 ++ + virt/kvm/kvm_main.c | 16 +++++----------- + 2 files changed, 7 insertions(+), 11 deletions(-) + +--- a/arch/arm64/kvm/vgic/vgic-its.c ++++ b/arch/arm64/kvm/vgic/vgic-its.c +@@ -507,6 +507,8 @@ static struct vgic_its *__vgic_doorbell_ + struct kvm_io_device *kvm_io_dev; + struct vgic_io_device *iodev; + ++ guard(srcu)(&kvm->srcu); ++ + kvm_io_dev = kvm_io_bus_get_dev(kvm, KVM_MMIO_BUS, db); + if (!kvm_io_dev) + return ERR_PTR(-EINVAL); +--- a/virt/kvm/kvm_main.c ++++ b/virt/kvm/kvm_main.c +@@ -6069,25 +6069,19 @@ struct kvm_io_device *kvm_io_bus_get_dev + gpa_t addr) + { + struct kvm_io_bus *bus; +- int dev_idx, srcu_idx; +- struct kvm_io_device *iodev = NULL; ++ int dev_idx; + +- srcu_idx = srcu_read_lock(&kvm->srcu); ++ lockdep_assert_held(&kvm->srcu); + + bus = kvm_get_bus_srcu(kvm, bus_idx); + if (!bus) +- goto out_unlock; ++ return NULL; + + dev_idx = kvm_io_bus_get_first_dev(bus, addr, 1); + if (dev_idx < 0) +- goto out_unlock; ++ return NULL; + +- iodev = bus->range[dev_idx].dev; +- +-out_unlock: +- srcu_read_unlock(&kvm->srcu, srcu_idx); +- +- return iodev; ++ return bus->range[dev_idx].dev; + } + EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_io_bus_get_dev); + diff --git a/queue-7.1/kvm-nvmx-move-vtpr-vs.-tpr-threshold-consistency-check-into-normal-checks.patch b/queue-7.1/kvm-nvmx-move-vtpr-vs.-tpr-threshold-consistency-check-into-normal-checks.patch new file mode 100644 index 0000000000..fcd0fe0de3 --- /dev/null +++ b/queue-7.1/kvm-nvmx-move-vtpr-vs.-tpr-threshold-consistency-check-into-normal-checks.patch @@ -0,0 +1,136 @@ +From ebdac7554abb347ca4197be241116842161acd9b Mon Sep 17 00:00:00 2001 +From: Sean Christopherson +Date: Fri, 12 Jun 2026 07:56:41 -0700 +Subject: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks + +From: Sean Christopherson + +commit ebdac7554abb347ca4197be241116842161acd9b upstream. + +Move the off-by-default consistency check for vmcs12.tpr_threshold vs. +the virtual APIC vTPR into the "normal" controls checks, as waiting until +KVM has loaded some amount of state is unnecessary and actively dangerous. +Specifically, failure to unwind vmcs01.GUEST_CR3 to KVM's value when EPT +is disabled results in KVM running L1 with an L1-controlled CR3, not with +KVM's CR3! + +Alternatively, KVM could simply reset the MMU to force a reload of +vmcs01.GUEST_CR3, but the _only_ reason the check was shoved into a "late" +flow was to wait until the vmcs12 pages were retrieved. Rather than build +up more crusty code, simply access vTPR using a regular guest memory access +(performance isn't a concern). To circumvent the restrictions that led to +KVM deferring nested_get_vmcs12_pages(), (a) use a VM-scoped API to read +guest memory so that it always hits non-SMM memslots (for RSM), and (b) +skip the check (since its off-by-default anyways) when the vCPU doesn't +want to run, i.e. when userspace is restoring/stuffing state. + +If reading guest memory fails, simply skip the consistency check, as KVM's +de facto ABI is that VMX instruction accesses to non-existent memory get +PCI Bus Error semantics, where reads return 0xFFs. And if vTPR=0xFF, then +the vTPR is guaranteed to be greater than or equal to TPR_THRESHOLD. + +Fixes: 1100e4910ad2 ("KVM: nVMX: Add an off-by-default module param to WARN on missed consistency checks") +Cc: stable@vger.kernel.org +Link: https://patch.msgid.link/20260612145642.452392-2-seanjc@google.com +Signed-off-by: Sean Christopherson +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/vmx/nested.c | 66 ++++++++++++++++++++-------------------------- + 1 file changed, 29 insertions(+), 37 deletions(-) + +--- a/arch/x86/kvm/vmx/nested.c ++++ b/arch/x86/kvm/vmx/nested.c +@@ -553,6 +553,9 @@ static int nested_vmx_check_msr_bitmap_c + static int nested_vmx_check_tpr_shadow_controls(struct kvm_vcpu *vcpu, + struct vmcs12 *vmcs12) + { ++ gpa_t vtpr_gpa = vmcs12->virtual_apic_page_addr + APIC_TASKPRI; ++ u32 vtpr; ++ + if (!nested_cpu_has(vmcs12, CPU_BASED_TPR_SHADOW)) + return 0; + +@@ -562,6 +565,32 @@ static int nested_vmx_check_tpr_shadow_c + if (CC(!nested_cpu_has_vid(vmcs12) && vmcs12->tpr_threshold >> 4)) + return -EINVAL; + ++ /* ++ * Do the illegal vTPR vs. TPR Threshold consistency check if and only ++ * if KVM is configured to WARN on missed consistency checks, otherwise ++ * it's a waste of time. KVM needs to rely on hardware to fully detect ++ * an illegal combination due to the vTPR being writable by L1 at all ++ * times (it's an in-memory value, not a VMCS field). I.e. even if the ++ * check passes now, it might fail at the actual VM-Enter. ++ * ++ * If reading guest memory fails, skip the check as KVM's de facto ABI ++ * for VMX instruction accesses to non-existent memory is to provide ++ * PCI Bus Error semantics (reads return 0xFFs), in which case the vTPR ++ * is guaranteed to greater than or equal to the threshold. ++ * ++ * Note! Deliberately use the VM-scoped API when reading guest memory, ++ * to ensure the read doesn't hit SMRAM when restoring L2 state on RSM, ++ * and only perform the check when in KVM_RUN, to avoid a false failure ++ * if userspace hasn't yet configured memslots during state restore. ++ */ ++ if (warn_on_missed_cc && vcpu->wants_to_run && ++ nested_cpu_has(vmcs12, CPU_BASED_TPR_SHADOW) && ++ !nested_cpu_has_vid(vmcs12) && ++ !nested_cpu_has2(vmcs12, SECONDARY_EXEC_VIRTUALIZE_APIC_ACCESSES) && ++ !kvm_read_guest(vcpu->kvm, vtpr_gpa, &vtpr, sizeof(vtpr)) && ++ CC((vmcs12->tpr_threshold & GENMASK(3, 0)) > ((vtpr >> 4) & GENMASK(3, 0)))) ++ return -EINVAL; ++ + return 0; + } + +@@ -3085,38 +3114,6 @@ static int nested_vmx_check_controls(str + return 0; + } + +-static int nested_vmx_check_controls_late(struct kvm_vcpu *vcpu, +- struct vmcs12 *vmcs12) +-{ +- void *vapic = to_vmx(vcpu)->nested.virtual_apic_map.hva; +- u32 vtpr = vapic ? (*(u32 *)(vapic + APIC_TASKPRI)) >> 4 : 0; +- +- /* +- * Don't bother with the consistency checks if KVM isn't configured to +- * WARN on missed consistency checks, as KVM needs to rely on hardware +- * to fully detect an illegal vTPR vs. TRP Threshold combination due to +- * the vTPR being writable by L1 at all times (it's an in-memory value, +- * not a VMCS field). I.e. even if the check passes now, it might fail +- * at the actual VM-Enter. +- * +- * Keying off the module param also allows treating an invalid vAPIC +- * mapping as a consistency check failure without increasing the risk +- * of breaking a "real" VM. +- */ +- if (!warn_on_missed_cc) +- return 0; +- +- if ((exec_controls_get(to_vmx(vcpu)) & CPU_BASED_TPR_SHADOW) && +- nested_cpu_has(vmcs12, CPU_BASED_TPR_SHADOW) && +- !nested_cpu_has_vid(vmcs12) && +- !nested_cpu_has2(vmcs12, SECONDARY_EXEC_VIRTUALIZE_APIC_ACCESSES) && +- (CC(!vapic) || +- CC((vmcs12->tpr_threshold & GENMASK(3, 0)) > (vtpr & GENMASK(3, 0))))) +- return -EINVAL; +- +- return 0; +-} +- + static int nested_vmx_check_address_space_size(struct kvm_vcpu *vcpu, + struct vmcs12 *vmcs12) + { +@@ -3666,11 +3663,6 @@ enum nvmx_vmentry_status nested_vmx_ente + return NVMX_VMENTRY_KVM_INTERNAL_ERROR; + } + +- if (nested_vmx_check_controls_late(vcpu, vmcs12)) { +- vmx_switch_vmcs(vcpu, &vmx->vmcs01); +- return NVMX_VMENTRY_VMFAIL; +- } +- + if (nested_vmx_check_guest_state(vcpu, vmcs12, + &entry_failure_code)) { + exit_reason.basic = EXIT_REASON_INVALID_STATE; diff --git a/queue-7.1/kvm-nvmx-put-vmcs12-pages-if-nested-vm-enter-fails-due-to-invalid-guest-state.patch b/queue-7.1/kvm-nvmx-put-vmcs12-pages-if-nested-vm-enter-fails-due-to-invalid-guest-state.patch new file mode 100644 index 0000000000..a511e2849d --- /dev/null +++ b/queue-7.1/kvm-nvmx-put-vmcs12-pages-if-nested-vm-enter-fails-due-to-invalid-guest-state.patch @@ -0,0 +1,44 @@ +From 2f2312c422fd2695da772cecb30c69994b795964 Mon Sep 17 00:00:00 2001 +From: Sean Christopherson +Date: Tue, 14 Jul 2026 09:03:06 -0700 +Subject: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state + +From: Sean Christopherson + +commit 2f2312c422fd2695da772cecb30c69994b795964 upstream. + +Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid +guest while emulating VMLAUNCH or VMRESUME. The invalid guest state path +doesn't use nested_vmx_vmexit() as that API is intended to be used if and +only if L2 is active, and the open coded equivalent neglects to put the +vmcs12 pages. Failure to put the vmcs12 pages leaks any pinned pages +(and/or mappings) if L1 retries VMLAUNCH/VMRESUME. + +Note, the !from_vmenter scenario doesn't suffer the same problem, as +vmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is +active, i.e. if a "full" VM-Exit is guaranteed before KVM will retry +getting vmcs12 pages. + +Fixes: 96c66e87deee ("KVM/nVMX: Use kvm_vcpu_map when mapping the virtual APIC page") +Fixes: 3278e0492554 ("KVM/nVMX: Use kvm_vcpu_map when mapping the posted interrupt descriptor table") +Fixes: fe1911aa443e ("KVM: nVMX: Use kvm_vcpu_map() to get/pin vmcs12's APIC-access page") +Reported-by: Minh Nguyen +Cc: stable@vger.kernel.org +Signed-off-by: Sean Christopherson +Signed-off-by: Paolo Bonzini +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/vmx/nested.c | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/arch/x86/kvm/vmx/nested.c ++++ b/arch/x86/kvm/vmx/nested.c +@@ -3747,6 +3747,8 @@ vmentry_fail_vmexit: + if (!from_vmentry) + return NVMX_VMENTRY_VMEXIT; + ++ nested_put_vmcs12_pages(vcpu); ++ + load_vmcs12_host_state(vcpu, vmcs12); + vmcs12->vm_exit_reason = exit_reason.full; + if (enable_shadow_vmcs || nested_vmx_is_evmptr12_valid(vmx)) diff --git a/queue-7.1/kvm-s390-fix-unlikely-race-in-try_get_locked_pte.patch b/queue-7.1/kvm-s390-fix-unlikely-race-in-try_get_locked_pte.patch new file mode 100644 index 0000000000..815f1842ea --- /dev/null +++ b/queue-7.1/kvm-s390-fix-unlikely-race-in-try_get_locked_pte.patch @@ -0,0 +1,48 @@ +From 5670b7f927f8d98685f3f5873dbf9f8d7a5a63f3 Mon Sep 17 00:00:00 2001 +From: Claudio Imbrenda +Date: Thu, 11 Jun 2026 12:48:47 +0200 +Subject: KVM: s390: Fix unlikely race in try_get_locked_pte() + +From: Claudio Imbrenda + +commit 5670b7f927f8d98685f3f5873dbf9f8d7a5a63f3 upstream. + +Fix an unlikely race in try_get_locked_pte(), which could have happened +if puds or pmds get unmapped between the p?dp_get() and p?d_offset() +functions. + +Fixes: 89fa757931dc ("KVM: s390: Avoid potentially sleeping while atomic when zapping pages") +CC: stable@vger.kernel.org # 7.1 +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611104850.110313-3-imbrenda@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/mm/gmap_helpers.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/arch/s390/mm/gmap_helpers.c b/arch/s390/mm/gmap_helpers.c +index 1cfe4724fbe2..ee3f37af8aee 100644 +--- a/arch/s390/mm/gmap_helpers.c ++++ b/arch/s390/mm/gmap_helpers.c +@@ -51,15 +51,15 @@ pte_t *try_get_locked_pte(struct mm_struct *mm, unsigned long vmaddr, spinlock_t + pgd = pgdp_get(pgdp); + if (pgd_none(pgd) || !pgd_present(pgd)) + return NULL; +- p4dp = p4d_offset(pgdp, vmaddr); ++ p4dp = p4d_offset_lockless(pgdp, pgd, vmaddr); + p4d = p4dp_get(p4dp); + if (p4d_none(p4d) || !p4d_present(p4d)) + return NULL; +- pudp = pud_offset(p4dp, vmaddr); ++ pudp = pud_offset_lockless(p4dp, p4d, vmaddr); + pud = pudp_get(pudp); + if (pud_none(pud) || pud_leaf(pud) || !pud_present(pud)) + return NULL; +- pmdp = pmd_offset(pudp, vmaddr); ++ pmdp = pmd_offset_lockless(pudp, pud, vmaddr); + pmd = pmdp_get_lockless(pmdp); + if (pmd_none(pmd) || pmd_leaf(pmd) || !pmd_present(pmd)) + return NULL; +-- +2.55.0 + diff --git a/queue-7.1/kvm-s390-initialize-kvm_s390_get_cmma_bits-memory.patch b/queue-7.1/kvm-s390-initialize-kvm_s390_get_cmma_bits-memory.patch new file mode 100644 index 0000000000..d89ecf1efd --- /dev/null +++ b/queue-7.1/kvm-s390-initialize-kvm_s390_get_cmma_bits-memory.patch @@ -0,0 +1,51 @@ +From c7dda3d0f869dc97223448a06c9a2e5235928e48 Mon Sep 17 00:00:00 2001 +From: Christian Borntraeger +Date: Thu, 11 Jun 2026 12:50:36 +0200 +Subject: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory + +From: Christian Borntraeger + +commit c7dda3d0f869dc97223448a06c9a2e5235928e48 upstream. + +kvm_s390_get_cmma_bits() allocates its output buffer with vmalloc(), +which does not zero the returned pages: + + values = vmalloc(args->count); + +In the non-peek (migration) path, dat_get_cmma() reports a byte count +spanning from the first to the last dirty page, but __dat_get_cmma_pte() +writes values[gfn - start] only for pages whose CMMA dirty bit is set. +The walk uses DAT_WALK_IGN_HOLES, so clean and unmapped pages that lie +between two dirty pages within the reported span are visited but never +store their byte. Those gaps (up to KVM_S390_MAX_BIT_DISTANCE pages +each) stay uninitialized yet fall inside [0, count) and are copied out +by copy_to_user(), disclosing stale kernel memory to user space. + +Before the switch to the new gmap implementation the buffer was fully +populated for every gfn in the span, so no uninitialized bytes were +exposed; the dirty-only walk introduced the leak. + +Use vzalloc() so the gaps read back as zero. + +Fixes: e38c884df921 ("KVM: s390: Switch to new gmap") +Cc: stable@vger.kernel.org +Signed-off-by: Christian Borntraeger +Reviewed-by: Claudio Imbrenda +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611105036.11491-1-borntraeger@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/kvm-s390.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/arch/s390/kvm/kvm-s390.c ++++ b/arch/s390/kvm/kvm-s390.c +@@ -2252,7 +2252,7 @@ static int kvm_s390_get_cmma_bits(struct + return 0; + } + +- values = vmalloc(args->count); ++ values = vzalloc(args->count); + if (!values) + return -ENOMEM; + diff --git a/queue-7.1/kvm-s390-pci-fix-gisc-refcount-leak-on-aif-enable-failure.patch b/queue-7.1/kvm-s390-pci-fix-gisc-refcount-leak-on-aif-enable-failure.patch new file mode 100644 index 0000000000..478ee7e049 --- /dev/null +++ b/queue-7.1/kvm-s390-pci-fix-gisc-refcount-leak-on-aif-enable-failure.patch @@ -0,0 +1,41 @@ +From 7b69729046a4c58f4cb457184e5ac4aaa179bff4 Mon Sep 17 00:00:00 2001 +From: Haoxiang Li +Date: Wed, 24 Jun 2026 14:19:10 +0800 +Subject: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure + +From: Haoxiang Li + +commit 7b69729046a4c58f4cb457184e5ac4aaa179bff4 upstream. + +kvm_s390_gisc_register() registers the guest ISC before pinning +the guest interrupt forwarding pages and allocating the AISB bit. +If any of the later setup steps fails, the function unwinds the +pinned pages and other local state, but does not unregister the +GISC reference. Add the missing kvm_s390_gisc_unregister() to the +error unwind path. + +Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding") +Cc: stable@vger.kernel.org +Signed-off-by: Haoxiang Li +Reviewed-by: Matthew Rosato +Tested-by: Matthew Rosato +Acked-by: Claudio Imbrenda +Reviewed-by: Christian Borntraeger +Signed-off-by: Claudio Imbrenda +Message-ID: <20260624061910.2794734-1-haoxiang_li2024@163.com> +Signed-off-by: Christian Borntraeger +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/pci.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/arch/s390/kvm/pci.c ++++ b/arch/s390/kvm/pci.c +@@ -328,6 +328,7 @@ unpin2: + unpin1: + unpin_user_page(aibv_page); + out: ++ kvm_s390_gisc_unregister(kvm, fib->fmt0.isc); + return rc; + } + diff --git a/queue-7.1/kvm-s390-pci-fix-handling-of-aif-enable-without-aisb.patch b/queue-7.1/kvm-s390-pci-fix-handling-of-aif-enable-without-aisb.patch new file mode 100644 index 0000000000..7c09c1164f --- /dev/null +++ b/queue-7.1/kvm-s390-pci-fix-handling-of-aif-enable-without-aisb.patch @@ -0,0 +1,43 @@ +From 3e3aa6da87d30a0064a17b836685cd43c90a3572 Mon Sep 17 00:00:00 2001 +From: Matthew Rosato +Date: Thu, 9 Jul 2026 09:54:04 -0400 +Subject: KVM: s390: pci: Fix handling of AIF enable without AISB + +From: Matthew Rosato + +commit 3e3aa6da87d30a0064a17b836685cd43c90a3572 upstream. + +When a guest seeks to register IRQs without a summary bit specified, +ensure that the associated GAITE then stores 0 for the guest AISB +location instead of virt_to_phys(page_address(NULL)). + +Fixes: 3c5a1b6f0a18 ("KVM: s390: pci: provide routines for enabling/disabling interrupt forwarding") +Cc: stable@vger.kernel.org +Reviewed-by: Farhan Ali +Signed-off-by: Matthew Rosato +Signed-off-by: Christian Borntraeger +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/pci.c | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +--- a/arch/s390/kvm/pci.c ++++ b/arch/s390/kvm/pci.c +@@ -300,9 +300,14 @@ static int kvm_s390_pci_aif_enable(struc + + gaite->gisc = fib->fmt0.isc; + gaite->count++; +- gaite->aisbo = fib->fmt0.aisbo; +- gaite->aisb = virt_to_phys(page_address(aisb_page) + (fib->fmt0.aisb & +- ~PAGE_MASK)); ++ if (fib->fmt0.sum == 1) { ++ gaite->aisbo = fib->fmt0.aisbo; ++ gaite->aisb = virt_to_phys(page_address(aisb_page) + ++ (fib->fmt0.aisb & ~PAGE_MASK)); ++ } else { ++ gaite->aisbo = 0; ++ gaite->aisb = 0; ++ } + aift->kzdev[zdev->aisb] = zdev->kzdev; + spin_unlock_irq(&aift->gait_lock); + diff --git a/queue-7.1/kvm-s390-silence-potential-warnings-in-_gmap_crstep_xchg_atomic.patch b/queue-7.1/kvm-s390-silence-potential-warnings-in-_gmap_crstep_xchg_atomic.patch new file mode 100644 index 0000000000..ebd2d98c9d --- /dev/null +++ b/queue-7.1/kvm-s390-silence-potential-warnings-in-_gmap_crstep_xchg_atomic.patch @@ -0,0 +1,49 @@ +From f79413b2dde10829a1b526543e725dd5c1847e9a Mon Sep 17 00:00:00 2001 +From: Claudio Imbrenda +Date: Thu, 11 Jun 2026 12:48:46 +0200 +Subject: KVM: s390: Silence potential warnings in _gmap_crstep_xchg_atomic() + +From: Claudio Imbrenda + +commit f79413b2dde10829a1b526543e725dd5c1847e9a upstream. + +While dat_crstep_xchg_atomic() is marked as __must_check, in this +particular case the return value should be ignored. + +Silence potential compiler warnings with a pointless check, and add a +comment to explain the situation. + +Fixes: d1adc098ce08 ("KVM: s390: Fix _gmap_crstep_xchg_atomic()") +CC: stable@vger.kernel.org # 7.1 +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611104850.110313-2-imbrenda@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/gmap.h | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/arch/s390/kvm/gmap.h b/arch/s390/kvm/gmap.h +index 5374f21aaf8d..20881e3ce9d8 100644 +--- a/arch/s390/kvm/gmap.h ++++ b/arch/s390/kvm/gmap.h +@@ -279,7 +279,16 @@ static inline bool __must_check _gmap_crstep_xchg_atomic(struct gmap *gmap, unio + gmap_handle_vsie_unshadow_event(gmap, gfn); + else + _gmap_handle_vsie_unshadow_event(gmap, gfn); +- dat_crstep_xchg_atomic(crstep, oldcrste, newcrste, gfn, gmap->asce); ++ if (!dat_crstep_xchg_atomic(crstep, oldcrste, newcrste, gfn, gmap->asce)) ++ return false; ++ /* ++ * Return false even if the swap was successful, as it only ++ * indicates that the best effort clearing of the vsie_notif ++ * bit was successful. The caller will have to try again ++ * regardless, since the desired value has not been set. ++ * This pointless check is needed to silence a potential ++ * __must_check warning. ++ */ + return false; + } + if (!oldcrste.s.fc1.d && newcrste.s.fc1.d && !newcrste.s.fc1.s) +-- +2.55.0 + diff --git a/queue-7.1/kvm-s390-vsie-add-missing-radix_tree_preload-in-_gaccess_shadow_fault.patch b/queue-7.1/kvm-s390-vsie-add-missing-radix_tree_preload-in-_gaccess_shadow_fault.patch new file mode 100644 index 0000000000..390de61c15 --- /dev/null +++ b/queue-7.1/kvm-s390-vsie-add-missing-radix_tree_preload-in-_gaccess_shadow_fault.patch @@ -0,0 +1,101 @@ +From 668e70cc545e2659f3c4adad20a0883533042473 Mon Sep 17 00:00:00 2001 +From: Claudio Imbrenda +Date: Thu, 11 Jun 2026 12:48:49 +0200 +Subject: KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault() + +From: Claudio Imbrenda + +commit 668e70cc545e2659f3c4adad20a0883533042473 upstream. + +Add missing radix_tree_preload() in _gaccess_shadow_fault() to +guarantee forward progress. The core of _gaccess_shadow_fault() has +been split into ___gaccess_shadow_fault() in order to simplify locking. + +Fixes: e38c884df921 ("KVM: s390: Switch to new gmap") +CC: stable@vger.kernel.org # 7.1 +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611104850.110313-5-imbrenda@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/gaccess.c | 59 +++++++++++++++++++++++++---------------- + 1 file changed, 36 insertions(+), 23 deletions(-) + +diff --git a/arch/s390/kvm/gaccess.c b/arch/s390/kvm/gaccess.c +index 20e28b183c1a..0584fc91606f 100644 +--- a/arch/s390/kvm/gaccess.c ++++ b/arch/s390/kvm/gaccess.c +@@ -1582,35 +1582,48 @@ static int _gaccess_do_shadow(struct kvm_s390_mmu_cache *mc, struct gmap *sg, + return _do_shadow_crste(sg, saddr, host, table, entries + LEVEL_MEM, w->p); + } + +-static inline int _gaccess_shadow_fault(struct kvm_vcpu *vcpu, struct gmap *sg, gpa_t saddr, +- unsigned long seq, struct pgtwalk *walk) ++static inline int ___gaccess_shadow_fault(struct kvm_vcpu *vcpu, struct gmap *sg, gpa_t saddr, ++ unsigned long seq, struct pgtwalk *walk) + { + struct gmap *parent; + int rc; + ++ if (kvm_s390_array_needs_retry_safe(vcpu->kvm, seq, walk->raw_entries)) ++ return -EAGAIN; ++ parent = READ_ONCE(sg->parent); ++ if (!parent) ++ return -EAGAIN; ++ scoped_guard(spinlock, &parent->children_lock) { ++ if (READ_ONCE(sg->parent) != parent) ++ return -EAGAIN; ++ sg->invalidated = false; ++ rc = _gaccess_do_shadow(vcpu->arch.mc, sg, saddr, walk); ++ } ++ if (!rc) ++ kvm_s390_release_faultin_array(vcpu->kvm, walk->raw_entries, false); ++ return rc; ++} ++ ++static inline int _gaccess_shadow_fault(struct kvm_vcpu *vcpu, struct gmap *sg, gpa_t saddr, ++ unsigned long seq, struct pgtwalk *walk) ++{ ++ int rc; ++ + if (kvm_s390_array_needs_retry_unsafe(vcpu->kvm, seq, walk->raw_entries)) + return -EAGAIN; +-again: +- rc = kvm_s390_mmu_cache_topup(vcpu->arch.mc); +- if (rc) +- return rc; +- scoped_guard(read_lock, &vcpu->kvm->mmu_lock) { +- if (kvm_s390_array_needs_retry_safe(vcpu->kvm, seq, walk->raw_entries)) +- return -EAGAIN; +- parent = READ_ONCE(sg->parent); +- if (!parent) +- return -EAGAIN; +- scoped_guard(spinlock, &parent->children_lock) { +- if (READ_ONCE(sg->parent) != parent) +- return -EAGAIN; +- sg->invalidated = false; +- rc = _gaccess_do_shadow(vcpu->arch.mc, sg, saddr, walk); +- } +- if (rc == -ENOMEM) +- goto again; +- if (!rc) +- kvm_s390_release_faultin_array(vcpu->kvm, walk->raw_entries, false); +- } ++ ++ do { ++ rc = kvm_s390_mmu_cache_topup(vcpu->arch.mc); ++ if (rc) ++ return rc; ++ rc = radix_tree_preload(GFP_KERNEL); ++ if (rc) ++ return rc; ++ scoped_guard(read_lock, &vcpu->kvm->mmu_lock) ++ rc = ___gaccess_shadow_fault(vcpu, sg, saddr, seq, walk); ++ radix_tree_preload_end(); ++ } while (rc == -ENOMEM); ++ + return rc; + } + +-- +2.55.0 + diff --git a/queue-7.1/kvm-s390-vsie-fix-allocation-of-struct-vsie_rmap.patch b/queue-7.1/kvm-s390-vsie-fix-allocation-of-struct-vsie_rmap.patch new file mode 100644 index 0000000000..7e140c3654 --- /dev/null +++ b/queue-7.1/kvm-s390-vsie-fix-allocation-of-struct-vsie_rmap.patch @@ -0,0 +1,39 @@ +From 505fcce0c64957f475f9b11fb1403821b7f33e7e Mon Sep 17 00:00:00 2001 +From: Claudio Imbrenda +Date: Thu, 11 Jun 2026 12:48:48 +0200 +Subject: KVM: s390: vsie: Fix allocation of struct vsie_rmap + +From: Claudio Imbrenda + +commit 505fcce0c64957f475f9b11fb1403821b7f33e7e upstream. + +The allocation size for struct vsie_rmap in kvm_s390_mmu_cache_topup() +was wrong due to a copy-paste error. + +Fix it by using the type name. + +Fixes: 12f2f61a9e1a ("KVM: s390: KVM page table management functions: allocation") +CC: stable@vger.kernel.org # 7.1 +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611104850.110313-4-imbrenda@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/dat.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/s390/kvm/dat.c b/arch/s390/kvm/dat.c +index 4a41c0247ffa..a4fe664f65ee 100644 +--- a/arch/s390/kvm/dat.c ++++ b/arch/s390/kvm/dat.c +@@ -45,7 +45,7 @@ int kvm_s390_mmu_cache_topup(struct kvm_s390_mmu_cache *mc) + mc->pts[mc->n_pts] = o; + } + for ( ; mc->n_rmaps < KVM_S390_MMU_CACHE_N_RMAPS; mc->n_rmaps++) { +- o = kzalloc_obj(*mc->rmaps[0], GFP_KERNEL_ACCOUNT); ++ o = kzalloc_obj(struct vsie_rmap, GFP_KERNEL_ACCOUNT); + if (!o) + return -ENOMEM; + mc->rmaps[mc->n_rmaps] = o; +-- +2.55.0 + diff --git a/queue-7.1/kvm-s390-vsie-use-mmu-cache-to-allocate-rmap.patch b/queue-7.1/kvm-s390-vsie-use-mmu-cache-to-allocate-rmap.patch new file mode 100644 index 0000000000..38758cf80a --- /dev/null +++ b/queue-7.1/kvm-s390-vsie-use-mmu-cache-to-allocate-rmap.patch @@ -0,0 +1,129 @@ +From abeb7eb57f1671d9185ddf11236c784f07bdb928 Mon Sep 17 00:00:00 2001 +From: Claudio Imbrenda +Date: Thu, 11 Jun 2026 12:48:50 +0200 +Subject: KVM: s390: vsie: Use mmu cache to allocate rmap + +From: Claudio Imbrenda + +commit abeb7eb57f1671d9185ddf11236c784f07bdb928 upstream. + +Use kvm_s390_mmu_cache_alloc_rmap() to allocate the rmap in +gmap_insert_rmap(), instead of a normal kzalloc_obj() with GFP_ATOMIC. + +This guarantees forward progress. + +Fixes: a2c17f9270cc ("KVM: s390: New gmap code") +CC: stable@vger.kernel.org # 7.1 +Signed-off-by: Claudio Imbrenda +Message-ID: <20260611104850.110313-6-imbrenda@linux.ibm.com> +Signed-off-by: Greg Kroah-Hartman +--- + arch/s390/kvm/gaccess.c | 16 ++++++++-------- + arch/s390/kvm/gmap.c | 7 ++++--- + arch/s390/kvm/gmap.h | 3 ++- + 3 files changed, 14 insertions(+), 12 deletions(-) + +diff --git a/arch/s390/kvm/gaccess.c b/arch/s390/kvm/gaccess.c +index 0584fc91606f..36102b2727fb 100644 +--- a/arch/s390/kvm/gaccess.c ++++ b/arch/s390/kvm/gaccess.c +@@ -1419,8 +1419,8 @@ static int walk_guest_tables(struct gmap *sg, unsigned long saddr, struct pgtwal + return kvm_s390_get_guest_page(kvm, entries + LEVEL_MEM, table.pte.pfra, wr); + } + +-static int _do_shadow_pte(struct gmap *sg, gpa_t raddr, union pte *ptep_h, union pte *ptep, +- struct guest_fault *f, bool p) ++static int _do_shadow_pte(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gpa_t raddr, ++ union pte *ptep_h, union pte *ptep, struct guest_fault *f, bool p) + { + union pgste pgste; + union pte newpte; +@@ -1430,7 +1430,7 @@ static int _do_shadow_pte(struct gmap *sg, gpa_t raddr, union pte *ptep_h, union + lockdep_assert_held(&sg->parent->children_lock); + + scoped_guard(spinlock, &sg->host_to_rmap_lock) +- rc = gmap_insert_rmap(sg, f->gfn, gpa_to_gfn(raddr), TABLE_TYPE_PAGE_TABLE); ++ rc = gmap_insert_rmap(mc, sg, f->gfn, gpa_to_gfn(raddr), TABLE_TYPE_PAGE_TABLE); + if (rc) + return rc; + +@@ -1462,8 +1462,8 @@ static int _do_shadow_pte(struct gmap *sg, gpa_t raddr, union pte *ptep_h, union + return 0; + } + +-static int _do_shadow_crste(struct gmap *sg, gpa_t raddr, union crste *host, union crste *table, +- struct guest_fault *f, bool p) ++static int _do_shadow_crste(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gpa_t raddr, ++ union crste *host, union crste *table, struct guest_fault *f, bool p) + { + union crste newcrste, oldcrste; + unsigned long mask; +@@ -1476,7 +1476,7 @@ static int _do_shadow_crste(struct gmap *sg, gpa_t raddr, union crste *host, uni + mask = is_pmd(*table) ? _SEGMENT_FR_MASK : _REGION3_FR_MASK; + r_gfn = gpa_to_gfn(raddr) & mask; + scoped_guard(spinlock, &sg->host_to_rmap_lock) +- rc = gmap_insert_rmap(sg, f->gfn & mask, r_gfn, host->h.tt); ++ rc = gmap_insert_rmap(mc, sg, f->gfn & mask, r_gfn, host->h.tt); + if (rc) + return rc; + +@@ -1578,8 +1578,8 @@ static int _gaccess_do_shadow(struct kvm_s390_mmu_cache *mc, struct gmap *sg, + if (KVM_BUG_ON(l > TABLE_TYPE_REGION3, sg->kvm)) + return -EFAULT; + if (l == TABLE_TYPE_PAGE_TABLE) +- return _do_shadow_pte(sg, saddr, ptep_h, ptep, entries + LEVEL_MEM, w->p); +- return _do_shadow_crste(sg, saddr, host, table, entries + LEVEL_MEM, w->p); ++ return _do_shadow_pte(mc, sg, saddr, ptep_h, ptep, entries + LEVEL_MEM, w->p); ++ return _do_shadow_crste(mc, sg, saddr, host, table, entries + LEVEL_MEM, w->p); + } + + static inline int ___gaccess_shadow_fault(struct kvm_vcpu *vcpu, struct gmap *sg, gpa_t saddr, +diff --git a/arch/s390/kvm/gmap.c b/arch/s390/kvm/gmap.c +index 52d55ddea8d4..1d289f8fa3b2 100644 +--- a/arch/s390/kvm/gmap.c ++++ b/arch/s390/kvm/gmap.c +@@ -1000,7 +1000,8 @@ int gmap_pv_destroy_range(struct gmap *gmap, gfn_t start, gfn_t end, bool interr + return 0; + } + +-int gmap_insert_rmap(struct gmap *sg, gfn_t p_gfn, gfn_t r_gfn, int level) ++int gmap_insert_rmap(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gfn_t p_gfn, ++ gfn_t r_gfn, int level) + { + struct vsie_rmap *rmap __free(kvfree) = NULL; + struct vsie_rmap *temp; +@@ -1010,7 +1011,7 @@ int gmap_insert_rmap(struct gmap *sg, gfn_t p_gfn, gfn_t r_gfn, int level) + KVM_BUG_ON(!is_shadow(sg), sg->kvm); + lockdep_assert_held(&sg->host_to_rmap_lock); + +- rmap = kzalloc_obj(*rmap, GFP_ATOMIC); ++ rmap = kvm_s390_mmu_cache_alloc_rmap(mc); + if (!rmap) + return -ENOMEM; + +@@ -1057,7 +1058,7 @@ int gmap_protect_rmap(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gfn_t p_gf + if (level <= TABLE_TYPE_REGION1) { + bitmask = -1UL << (8 + 11 * level); + scoped_guard(spinlock, &sg->host_to_rmap_lock) +- rc = gmap_insert_rmap(sg, p_gfn, r_gfn & bitmask, level); ++ rc = gmap_insert_rmap(mc, sg, p_gfn, r_gfn & bitmask, level); + } + if (rc) + return rc; +diff --git a/arch/s390/kvm/gmap.h b/arch/s390/kvm/gmap.h +index 20881e3ce9d8..1c040472f56d 100644 +--- a/arch/s390/kvm/gmap.h ++++ b/arch/s390/kvm/gmap.h +@@ -100,7 +100,8 @@ int gmap_ucas_map(struct gmap *gmap, gfn_t p_gfn, gfn_t c_gfn, unsigned long cou + void gmap_ucas_unmap(struct gmap *gmap, gfn_t c_gfn, unsigned long count); + int gmap_enable_skeys(struct gmap *gmap); + int gmap_pv_destroy_range(struct gmap *gmap, gfn_t start, gfn_t end, bool interruptible); +-int gmap_insert_rmap(struct gmap *sg, gfn_t p_gfn, gfn_t r_gfn, int level); ++int gmap_insert_rmap(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gfn_t p_gfn, ++ gfn_t r_gfn, int level); + int gmap_protect_rmap(struct kvm_s390_mmu_cache *mc, struct gmap *sg, gfn_t p_gfn, gfn_t r_gfn, + kvm_pfn_t pfn, int level, bool wr); + void gmap_set_cmma_all_dirty(struct gmap *gmap); +-- +2.55.0 + diff --git a/queue-7.1/kvm-sev-do-not-allow-intra-host-migration-mirroring-of-snp-vms.patch b/queue-7.1/kvm-sev-do-not-allow-intra-host-migration-mirroring-of-snp-vms.patch new file mode 100644 index 0000000000..374af337ba --- /dev/null +++ b/queue-7.1/kvm-sev-do-not-allow-intra-host-migration-mirroring-of-snp-vms.patch @@ -0,0 +1,60 @@ +From 6ee4140788234a6fabf59e6a50e38cdb936008cd Mon Sep 17 00:00:00 2001 +From: Atish Patra +Date: Tue, 2 Jun 2026 15:36:32 -0700 +Subject: KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs + +From: Atish Patra + +commit 6ee4140788234a6fabf59e6a50e38cdb936008cd upstream. + +The intra-host migration/mirroring feature is not fully implemented for +SEV-SNP VMs. The proper migration requires additional SNP-specific +state such as guest_req_mutex, guest_req_buf, and guest_resp_buf to be +transferred or initialized on the destination. + +The SNP VM mirroring requires vmsa features to be copied as well otherwise +ASID would be bound to SNP range while VM is detected as a SEV VM. + +Reject SNP source VMs in migration/mirroring until proper SNP state +transfer is implemented. + +Fixes: 1dfe571c12cf ("KVM: SEV: Add initial SEV-SNP support") + +Reported-by: Chris Mason +Reported-by: Sashiko +Assisted-by: Claude:claude-opus-4-6 +Reviewed-by: Tom Lendacky +Signed-off-by: Atish Patra +Link: https://patch.msgid.link/20260602-sev_snp_fixes-v3-1-24bfd3ae047c@meta.com +Cc: stable@vger.kernel.org +[sean: let lines poke past 80 chars, tag for stable] +Signed-off-by: Sean Christopherson +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/svm/sev.c | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +--- a/arch/x86/kvm/svm/sev.c ++++ b/arch/x86/kvm/svm/sev.c +@@ -2142,8 +2142,9 @@ int sev_vm_move_enc_context_from(struct + if (ret) + return ret; + ++ /* Do not allow SNP VM migration until additional state transfer is implemented */ + if (kvm->arch.vm_type != source_kvm->arch.vm_type || +- sev_guest(kvm) || !sev_guest(source_kvm)) { ++ sev_guest(kvm) || !sev_guest(source_kvm) || sev_snp_guest(source_kvm)) { + ret = -EINVAL; + goto out_unlock; + } +@@ -2865,8 +2866,9 @@ int sev_vm_copy_enc_context_from(struct + * disallow out-of-band SEV/SEV-ES init if the target is already an + * SEV guest, or if vCPUs have been created. KVM relies on vCPUs being + * created after SEV/SEV-ES initialization, e.g. to init intercepts. ++ * Also do not allow SNP VM mirroring until additional state transfer is implemented. + */ +- if (sev_guest(kvm) || !sev_guest(source_kvm) || ++ if (sev_guest(kvm) || !sev_guest(source_kvm) || sev_snp_guest(source_kvm) || + is_mirroring_enc_context(source_kvm) || kvm->created_vcpus) { + ret = -EINVAL; + goto e_unlock; diff --git a/queue-7.1/kvm-tdx-reject-concurrent-change-to-cpuid-entry-count.patch b/queue-7.1/kvm-tdx-reject-concurrent-change-to-cpuid-entry-count.patch new file mode 100644 index 0000000000..781c320b31 --- /dev/null +++ b/queue-7.1/kvm-tdx-reject-concurrent-change-to-cpuid-entry-count.patch @@ -0,0 +1,50 @@ +From cfbebb55e5127dc162e73fa8956000055a78606c Mon Sep 17 00:00:00 2001 +From: Binbin Wu +Date: Fri, 10 Jul 2026 11:53:23 +0800 +Subject: KVM: TDX: Reject concurrent change to CPUID entry count + +From: Binbin Wu + +commit cfbebb55e5127dc162e73fa8956000055a78606c upstream. + +Reject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the +initial read and the subsequent copy of the initialization data. + +tdx_td_init() first reads user_data->cpuid.nent to size the flexible +kvm_tdx_init_vm copy. The copied structure also contains cpuid.nent, +and that field can differ from the value used to size the allocation if +userspace modifies the input concurrently. setup_tdparams_cpuids() later +passes init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as +the array bound for the copied entries. + +Require the copied count to match the value used to size the allocation +so that CPUID parsing cannot access beyond the entries actually copied. + +Fixes: 0bd0a4a1428b ("KVM: TDX: Replace kmalloc + copy_from_user with memdup_user in tdx_td_init()") +Reported-by: Sashiko:gemini-3.1-pro-preview +Cc: +Signed-off-by: Binbin Wu +Reviewed-by: Xiaoyao Li +Reviewed-by: Thorsten Blum +Link: https://patch.msgid.link/20260710035324.3170534-1-binbin.wu@linux.intel.com +Signed-off-by: Sean Christopherson +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/vmx/tdx.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +--- a/arch/x86/kvm/vmx/tdx.c ++++ b/arch/x86/kvm/vmx/tdx.c +@@ -2725,7 +2725,11 @@ static int tdx_td_init(struct kvm *kvm, + goto out; + } + +- if (init_vm->cpuid.padding) { ++ /* ++ * Reject the request if userspace changes cpuid.nent between the ++ * initial read and the subsequent copy. ++ */ ++ if (init_vm->cpuid.padding || init_vm->cpuid.nent != nr_user_entries) { + ret = -EINVAL; + goto out; + } diff --git a/queue-7.1/kvm-x86-ignore-pending-pv-eoi-if-the-vcpu-has-since-disabled-pv-eois.patch b/queue-7.1/kvm-x86-ignore-pending-pv-eoi-if-the-vcpu-has-since-disabled-pv-eois.patch new file mode 100644 index 0000000000..10e6eb54fb --- /dev/null +++ b/queue-7.1/kvm-x86-ignore-pending-pv-eoi-if-the-vcpu-has-since-disabled-pv-eois.patch @@ -0,0 +1,65 @@ +From 9285e4070df2c40585c3d7ec9571faa7a2b97e17 Mon Sep 17 00:00:00 2001 +From: Sean Christopherson +Date: Wed, 24 Jun 2026 15:05:16 -0700 +Subject: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs + +From: Sean Christopherson + +commit 9285e4070df2c40585c3d7ec9571faa7a2b97e17 upstream. + +Ignore KVM's internal "service pending PV EOI" request if the vCPU has +disabled PV EOIs since the request was made. Asserting that PV EOIs are +enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e. +if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables +PV EOIs. + + kernel BUG at arch/x86/kvm/lapic.c:3338! + Oops: invalid opcode: 0000 [#1] SMP + CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT + Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 + RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm] + Call Trace: + + kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm] + kvm_vcpu_ioctl+0x2d5/0x980 [kvm] + __x64_sys_ioctl+0x8a/0xd0 + do_syscall_64+0xb5/0xb40 + entry_SYSCALL_64_after_hwframe+0x4b/0x53 + + Modules linked in: kvm_intel kvm irqbypass + ---[ end trace 0000000000000000 ]--- + +Fixes: ae7a2a3fb6f8 ("KVM: host side for eoi optimization") +Cc: stable@vger.kernel.org +Reviewed-by: Kai Huang +Link: https://patch.msgid.link/20260624220516.3033391-1-seanjc@google.com +Signed-off-by: Sean Christopherson +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/lapic.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +--- a/arch/x86/kvm/lapic.c ++++ b/arch/x86/kvm/lapic.c +@@ -3371,6 +3371,12 @@ static void apic_sync_pv_eoi_from_guest( + struct kvm_lapic *apic) + { + int vector; ++ ++ if (unlikely(!pv_eoi_enabled(vcpu))) { ++ __clear_bit(KVM_APIC_PV_EOI_PENDING, &vcpu->arch.apic_attention); ++ return; ++ } ++ + /* + * PV EOI state is derived from KVM_APIC_PV_EOI_PENDING in host + * and KVM_PV_EOI_ENABLED in guest memory as follows: +@@ -3382,8 +3388,6 @@ static void apic_sync_pv_eoi_from_guest( + * KVM_APIC_PV_EOI_PENDING is set, KVM_PV_EOI_ENABLED is unset: + * -> host enabled PV EOI, guest executed EOI. + */ +- BUG_ON(!pv_eoi_enabled(vcpu)); +- + if (pv_eoi_test_and_clr_pending(vcpu)) + return; + vector = apic_set_eoi(apic); diff --git a/queue-7.1/kvm-x86-nullify-irqfd-producer-if-updating-irte-for-bypass-fails.patch b/queue-7.1/kvm-x86-nullify-irqfd-producer-if-updating-irte-for-bypass-fails.patch new file mode 100644 index 0000000000..7785ac1afd --- /dev/null +++ b/queue-7.1/kvm-x86-nullify-irqfd-producer-if-updating-irte-for-bypass-fails.patch @@ -0,0 +1,40 @@ +From ed446e8aa894883c08892cfee69782fdf8f6c3ca Mon Sep 17 00:00:00 2001 +From: leixiang +Date: Mon, 22 Jun 2026 15:51:01 +0800 +Subject: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails + +From: leixiang + +commit ed446e8aa894883c08892cfee69782fdf8f6c3ca upstream. + +Nullify irqfd->producer if updating the IRTE for bypass fails, as leaving a +dangling pointer will result in a use-after-free if the irqfd is reachable +through KVM's routing, but the producer is freed separately. E.g. for VFIO +PCI, the producer is embedded in struct "vfio_pci_irq_ctx" and freed when +the vector is disabled, which can happen independent of routing updates. + +Fixes: 77e1b8332d1d ("KVM: x86: Decouple device assignment from IRQ bypass") +Cc: stable@vger.kernel.org +Signed-off-by: leixiang +Link: https://patch.msgid.link/1782119051448443.14545.seg@mailgw.kylinos.cn +[sean: drop PPC change, massage changelog] +Signed-off-by: Sean Christopherson +Signed-off-by: Greg Kroah-Hartman +--- + arch/x86/kvm/irq.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +--- a/arch/x86/kvm/irq.c ++++ b/arch/x86/kvm/irq.c +@@ -488,8 +488,10 @@ int kvm_arch_irq_bypass_add_producer(str + + if (irqfd->irq_entry.type == KVM_IRQ_ROUTING_MSI) { + ret = kvm_pi_update_irte(irqfd, &irqfd->irq_entry); +- if (ret) ++ if (ret) { + kvm->arch.nr_possible_bypass_irqs--; ++ irqfd->producer = NULL; ++ } + } + spin_unlock_irq(&kvm->irqfds.lock); + diff --git a/queue-7.1/loongarch-kvm-check-irq-validity-in-kvm_vcpu_ioctl_interrupt.patch b/queue-7.1/loongarch-kvm-check-irq-validity-in-kvm_vcpu_ioctl_interrupt.patch new file mode 100644 index 0000000000..56099a24d3 --- /dev/null +++ b/queue-7.1/loongarch-kvm-check-irq-validity-in-kvm_vcpu_ioctl_interrupt.patch @@ -0,0 +1,34 @@ +From 09b318ab77b7a4fc9987fd98d1525fc55ddc2617 Mon Sep 17 00:00:00 2001 +From: Bibo Mao +Date: Thu, 11 Jun 2026 20:46:40 +0800 +Subject: LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() + +From: Bibo Mao + +commit 09b318ab77b7a4fc9987fd98d1525fc55ddc2617 upstream. + +Function kvm_vcpu_ioctl_interrupt() can be called from userspace, here +add irq validility cheking in kvm_vcpu_ioctl_interrupt(). + +Cc: stable@vger.kernel.org +Fixes: f45ad5b8aa93 ("LoongArch: KVM: Implement vcpu interrupt operations") +Signed-off-by: Bibo Mao +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/kvm/vcpu.c | 4 ++++ + 1 file changed, 4 insertions(+) + +--- a/arch/loongarch/kvm/vcpu.c ++++ b/arch/loongarch/kvm/vcpu.c +@@ -1487,6 +1487,10 @@ void kvm_lose_fpu(struct kvm_vcpu *vcpu) + int kvm_vcpu_ioctl_interrupt(struct kvm_vcpu *vcpu, struct kvm_interrupt *irq) + { + int intr = (int)irq->irq; ++ unsigned int vector = abs(intr); ++ ++ if (vector >= EXCCODE_INT_NUM) ++ return -EINVAL; + + if (intr > 0) + kvm_queue_irq(vcpu, intr); diff --git a/queue-7.1/loongarch-kvm-check-the-return-values-for-put_user.patch b/queue-7.1/loongarch-kvm-check-the-return-values-for-put_user.patch new file mode 100644 index 0000000000..ba3d77eceb --- /dev/null +++ b/queue-7.1/loongarch-kvm-check-the-return-values-for-put_user.patch @@ -0,0 +1,33 @@ +From fb89e0fe2dc4246c86ad0eb0fa2b7cb2f8ba9728 Mon Sep 17 00:00:00 2001 +From: Qiang Ma +Date: Thu, 11 Jun 2026 20:46:43 +0800 +Subject: LoongArch: KVM: Check the return values for put_user() + +From: Qiang Ma + +commit fb89e0fe2dc4246c86ad0eb0fa2b7cb2f8ba9728 upstream. + +put_user() may return -EFAULT, so, when the user space address is +invalid, the caller should return -EFAULT. + +Cc: stable@vger.kernel.org +Reviewed-by: Bibo Mao +Signed-off-by: Qiang Ma +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/kvm/vcpu.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +--- a/arch/loongarch/kvm/vcpu.c ++++ b/arch/loongarch/kvm/vcpu.c +@@ -1108,7 +1108,8 @@ static int kvm_loongarch_cpucfg_get_attr + return -ENXIO; + } + +- put_user(val, uaddr); ++ if (put_user(val, uaddr)) ++ return -EFAULT; + + return ret; + } diff --git a/queue-7.1/loongarch-kvm-fix-fpu-register-width-with-user-access-api.patch b/queue-7.1/loongarch-kvm-fix-fpu-register-width-with-user-access-api.patch new file mode 100644 index 0000000000..81aebda2cf --- /dev/null +++ b/queue-7.1/loongarch-kvm-fix-fpu-register-width-with-user-access-api.patch @@ -0,0 +1,44 @@ +From f4caaac76379daf4a617d9134b6087fb2636fb31 Mon Sep 17 00:00:00 2001 +From: Bibo Mao +Date: Thu, 11 Jun 2026 20:46:40 +0800 +Subject: LoongArch: KVM: Fix FPU register width with user access API + +From: Bibo Mao + +commit f4caaac76379daf4a617d9134b6087fb2636fb31 upstream. + +At the beginning, only 64 bit FPU is supported. With FPU register get +interface, 64 bit FPU data is copied to user space, the same with FPU +register set API. However with LSX and LASX supported in later, there +should be FPU data copied with bigger width. So here fixes this issue, +copy the whole 256 bit FPU data from/to user space. + +Cc: stable@vger.kernel.org +Fixes: db1ecca22edf ("LoongArch: KVM: Add LSX (128bit SIMD) support") +Signed-off-by: Bibo Mao +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/kvm/vcpu.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/arch/loongarch/kvm/vcpu.c ++++ b/arch/loongarch/kvm/vcpu.c +@@ -1313,7 +1313,7 @@ int kvm_arch_vcpu_ioctl_get_fpu(struct k + fpu->fcc = vcpu->arch.fpu.fcc; + fpu->fcsr = vcpu->arch.fpu.fcsr; + for (i = 0; i < NUM_FPU_REGS; i++) +- memcpy(&fpu->fpr[i], &vcpu->arch.fpu.fpr[i], FPU_REG_WIDTH / 64); ++ memcpy(&fpu->fpr[i], &vcpu->arch.fpu.fpr[i], sizeof(union fpureg)); + + return 0; + } +@@ -1325,7 +1325,7 @@ int kvm_arch_vcpu_ioctl_set_fpu(struct k + vcpu->arch.fpu.fcc = fpu->fcc; + vcpu->arch.fpu.fcsr = fpu->fcsr; + for (i = 0; i < NUM_FPU_REGS; i++) +- memcpy(&vcpu->arch.fpu.fpr[i], &fpu->fpr[i], FPU_REG_WIDTH / 64); ++ memcpy(&vcpu->arch.fpu.fpr[i], &fpu->fpr[i], sizeof(union fpureg)); + + return 0; + } diff --git a/queue-7.1/loongarch-kvm-return-full-old-csr-value-from-kvm_emu_xchg_csr.patch b/queue-7.1/loongarch-kvm-return-full-old-csr-value-from-kvm_emu_xchg_csr.patch new file mode 100644 index 0000000000..ca80ddfb53 --- /dev/null +++ b/queue-7.1/loongarch-kvm-return-full-old-csr-value-from-kvm_emu_xchg_csr.patch @@ -0,0 +1,38 @@ +From ebd50de14f1a06b7e0206083904bcc62b9ba65be Mon Sep 17 00:00:00 2001 +From: Qiang Ma +Date: Thu, 11 Jun 2026 20:46:43 +0800 +Subject: LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr() + +From: Qiang Ma + +commit ebd50de14f1a06b7e0206083904bcc62b9ba65be upstream. + +The LoongArch CSRXCHG instruction returns the full old CSR value in rd +after applying the masked update. kvm_emu_xchg_csr() currently masks +the saved value before returning it to the guest, so rd receives only +the bits selected by the write mask. + +That breaks the architectural behavior and makes a zero mask return 0 +instead of the previous CSR value. So, keep the masked CSR update, but +return the unmodified old CSR value. + +Cc: stable@vger.kernel.org +Fixes: da50f5a693ff ("LoongArch: KVM: Implement handle csr exception") +Reviewed-by: Bibo Mao +Signed-off-by: Qiang Ma +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/kvm/exit.c | 1 - + 1 file changed, 1 deletion(-) + +--- a/arch/loongarch/kvm/exit.c ++++ b/arch/loongarch/kvm/exit.c +@@ -103,7 +103,6 @@ static unsigned long kvm_emu_xchg_csr(st + old = kvm_read_sw_gcsr(csr, csrid); + val = (old & ~csr_mask) | (val & csr_mask); + kvm_write_sw_gcsr(csr, csrid, val); +- old = old & csr_mask; + } else + pr_warn_once("Unsupported csrxchg 0x%x with pc %lx\n", csrid, vcpu->arch.pc); + diff --git a/queue-7.1/loongarch-kvm-validate-irqchip-index-in-irqfd-routing.patch b/queue-7.1/loongarch-kvm-validate-irqchip-index-in-irqfd-routing.patch new file mode 100644 index 0000000000..cedce477be --- /dev/null +++ b/queue-7.1/loongarch-kvm-validate-irqchip-index-in-irqfd-routing.patch @@ -0,0 +1,37 @@ +From 3474037904c20ff915e3ebab0ab5c1e41bbe549e Mon Sep 17 00:00:00 2001 +From: Yanfei Xu +Date: Thu, 11 Jun 2026 20:46:43 +0800 +Subject: LoongArch: KVM: Validate irqchip index in irqfd routing + +From: Yanfei Xu + +commit 3474037904c20ff915e3ebab0ab5c1e41bbe549e upstream. + +Sashiko reported that the irqchip index is not validated for LoongArch. +Add validation and reject out-of-range irqchip indexes to avoid indexing +past the routing table's chip array. + +Cc: stable@vger.kernel.org +Fixes: 1928254c5ccb ("LoongArch: KVM: Add irqfd support") +Closes: https://lore.kernel.org/kvm/20260525051714.485D51F000E9@smtp.kernel.org/ +Reported-by: Sashiko +Reviewed-by: Bibo Mao +Signed-off-by: Yanfei Xu +Signed-off-by: Huacai Chen +Signed-off-by: Greg Kroah-Hartman +--- + arch/loongarch/kvm/irqfd.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +--- a/arch/loongarch/kvm/irqfd.c ++++ b/arch/loongarch/kvm/irqfd.c +@@ -51,7 +51,8 @@ int kvm_set_routing_entry(struct kvm *kv + e->irqchip.irqchip = ue->u.irqchip.irqchip; + e->irqchip.pin = ue->u.irqchip.pin; + +- if (e->irqchip.pin >= KVM_IRQCHIP_NUM_PINS) ++ if (e->irqchip.pin >= KVM_IRQCHIP_NUM_PINS || ++ e->irqchip.irqchip >= KVM_NR_IRQCHIPS) + return -EINVAL; + + return 0; diff --git a/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_port_lag_join.patch b/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_port_lag_join.patch new file mode 100644 index 0000000000..f10828bce7 --- /dev/null +++ b/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_port_lag_join.patch @@ -0,0 +1,40 @@ +From 41c8c1d65b32beacd8d916a22457b4f6e47f45af Mon Sep 17 00:00:00 2001 +From: Wentao Liang +Date: Tue, 9 Jun 2026 08:37:09 +0000 +Subject: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() + +From: Wentao Liang + +commit 41c8c1d65b32beacd8d916a22457b4f6e47f45af upstream. + +When mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join() +returns an error without releasing the lag reference obtained by +the earlier mlxsw_sp_lag_get(). All other error paths in the +function jump to the cleanup label that ends with +mlxsw_sp_lag_put(), so this is a single missed release. + +Fix the leak by replacing the bare 'return err' with a goto to the +existing error cleanup label, which will drop the reference safely. + +Cc: stable@vger.kernel.org +Fixes: 0d65fc13042f ("mlxsw: spectrum: Implement LAG port join/leave") +Signed-off-by: Wentao Liang +Reviewed-by: Ido Schimmel +Link: https://patch.msgid.link/20260609083709.209743-1-vulab@iscas.ac.cn +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/mellanox/mlxsw/spectrum.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/drivers/net/ethernet/mellanox/mlxsw/spectrum.c ++++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum.c +@@ -4360,7 +4360,7 @@ static int mlxsw_sp_port_lag_join(struct + lag_id = lag->lag_id; + err = mlxsw_sp_port_lag_index_get(mlxsw_sp, lag_id, &port_index); + if (err) +- return err; ++ goto err_lag_uppers_bridge_join; + + err = mlxsw_sp_lag_uppers_bridge_join(mlxsw_sp_port, lag_dev, + extack); diff --git a/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_vrs_lpm_tree_replace.patch b/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_vrs_lpm_tree_replace.patch new file mode 100644 index 0000000000..35d081d662 --- /dev/null +++ b/queue-7.1/mlxsw-fix-refcount-leak-in-mlxsw_sp_vrs_lpm_tree_replace.patch @@ -0,0 +1,47 @@ +From 21cf8dc478a49e8de039c2739b1646a774cb1944 Mon Sep 17 00:00:00 2001 +From: Wentao Liang +Date: Tue, 9 Jun 2026 08:47:30 +0000 +Subject: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() + +From: Wentao Liang + +commit 21cf8dc478a49e8de039c2739b1646a774cb1944 upstream. + +When mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs, +the error rollback loop does not correctly revert the preceding +replacements. The loop decrements the index but fails to update the +vr pointer, which still points to the VR that caused the failure. As +a result, the condition and the rollback call always operate on the +same VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple +times on it while never rolling back the earlier VRs. Those VRs +continue to hold a reference to new_tree acquired via +mlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree. + +Fix by reinitializing vr inside the error loop with the updated index: + + vr = &mlxsw_sp->router->vrs[i]; + +so that the loop correctly iterates over all VRs that were actually +replaced. + +Cc: stable@vger.kernel.org +Fixes: fc922bb0dd94 ("mlxsw: spectrum_router: Use one LPM tree for all virtual routers") +Signed-off-by: Wentao Liang +Reviewed-by: Ido Schimmel +Link: https://patch.msgid.link/20260609084730.215732-1-vulab@iscas.ac.cn +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c ++++ b/drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c +@@ -1018,6 +1018,7 @@ static int mlxsw_sp_vrs_lpm_tree_replace + + err_tree_replace: + for (i--; i >= 0; i--) { ++ vr = &mlxsw_sp->router->vrs[i]; + if (!mlxsw_sp_vr_lpm_tree_should_replace(vr, proto, new_id)) + continue; + mlxsw_sp_vr_lpm_tree_replace(mlxsw_sp, diff --git a/queue-7.1/net-atm-reject-out-of-range-traffic-classes-in-qos-validation.patch b/queue-7.1/net-atm-reject-out-of-range-traffic-classes-in-qos-validation.patch new file mode 100644 index 0000000000..15d830ffae --- /dev/null +++ b/queue-7.1/net-atm-reject-out-of-range-traffic-classes-in-qos-validation.patch @@ -0,0 +1,46 @@ +From cdf19f380e46192e7084be559638aab1f6ed86a2 Mon Sep 17 00:00:00 2001 +From: Zhengchuan Liang +Date: Tue, 9 Jun 2026 16:34:37 +0800 +Subject: net: atm: reject out-of-range traffic classes in QoS validation + +From: Zhengchuan Liang + +commit cdf19f380e46192e7084be559638aab1f6ed86a2 upstream. + +Reject ATM traffic classes above ATM_ANYCLASS in check_tp(). +SO_ATMQOS stores the supplied QoS after check_qos() succeeds, so +accepting larger values leaves invalid traffic_class values in +vcc->qos. + +That bad state later reaches pvc_info(), which indexes class_name[] +with vcc->qos.{rx,tp}.traffic_class. Values above ATM_ANYCLASS cause +an out-of-bounds read when /proc/net/atm/pvc is read. + +Tighten the existing QoS validation so invalid traffic_class values +are rejected at the point where user supplied QoS is accepted. + +Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") +Cc: stable@vger.kernel.org +Reported-by: Yuan Tan +Reported-by: Xin Liu +Signed-off-by: Zhengchuan Liang +Signed-off-by: Ren Wei +Reviewed-by: Simon Horman +Link: https://patch.msgid.link/58f02c6f73d9818fd5d2022e1116759fdde6116b.1780965530.git.zcliangcn@gmail.com +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + net/atm/common.c | 2 ++ + 1 file changed, 2 insertions(+) + +--- a/net/atm/common.c ++++ b/net/atm/common.c +@@ -720,6 +720,8 @@ static int atm_change_qos(struct atm_vcc + static int check_tp(const struct atm_trafprm *tp) + { + /* @@@ Should be merged with adjust_tp */ ++ if (tp->traffic_class > ATM_ANYCLASS) ++ return -EINVAL; + if (!tp->traffic_class || tp->traffic_class == ATM_ANYCLASS) + return 0; + if (tp->traffic_class != ATM_UBR && !tp->min_pcr && !tp->pcr && diff --git a/queue-7.1/net-ife-require-eth_hlen-to-be-pullable-in-ife_decode.patch b/queue-7.1/net-ife-require-eth_hlen-to-be-pullable-in-ife_decode.patch new file mode 100644 index 0000000000..76b3da82cd --- /dev/null +++ b/queue-7.1/net-ife-require-eth_hlen-to-be-pullable-in-ife_decode.patch @@ -0,0 +1,45 @@ +From 9406f6012b7343661efb516a11c62d4db2b62f75 Mon Sep 17 00:00:00 2001 +From: Yong Wang +Date: Thu, 11 Jun 2026 02:37:43 +0800 +Subject: net: ife: require ETH_HLEN to be pullable in ife_decode() + +From: Yong Wang + +commit 9406f6012b7343661efb516a11c62d4db2b62f75 upstream. + +ife decode may return after making only the outer IFE header and +metadata pullable. The caller then passes the decapsulated packet to +eth_type_trans(), which expects the inner Ethernet header to be +accessible from the linear data area. + +With a malformed IFE frame, the inner Ethernet header may still be +shorter than ETH_HLEN in the linear area, which can lead to a crash in +the original code. + +Fix this by extending the pull check in ife_decode() so that the inner +Ethernet header is also guaranteed to be pullable before returning. + +Fixes: ef6980b6becb ("introduce IFE action") +Cc: stable@vger.kernel.org +Reported-by: Yuan Tan +Reported-by: Xin Liu +Signed-off-by: Yong Wang +Signed-off-by: Ren Wei +Link: https://patch.msgid.link/20260610183814.1648888-2-n05ec@lzu.edu.cn +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + net/ife/ife.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/net/ife/ife.c ++++ b/net/ife/ife.c +@@ -79,7 +79,7 @@ void *ife_decode(struct sk_buff *skb, u1 + if (unlikely(ifehdrln < 2)) + return NULL; + +- if (unlikely(!pskb_may_pull(skb, total_pull))) ++ if (unlikely(!pskb_may_pull(skb, total_pull + ETH_HLEN))) + return NULL; + + ifehdr = (struct ifeheadr *)(skb->data + skb->dev->hard_header_len); diff --git a/queue-7.1/net-qrtr-fix-32-bit-integer-overflow-in-qrtr_endpoint_post.patch b/queue-7.1/net-qrtr-fix-32-bit-integer-overflow-in-qrtr_endpoint_post.patch new file mode 100644 index 0000000000..19cd376179 --- /dev/null +++ b/queue-7.1/net-qrtr-fix-32-bit-integer-overflow-in-qrtr_endpoint_post.patch @@ -0,0 +1,46 @@ +From 20054869770c7df060c5ecee3e8bbf9029c47191 Mon Sep 17 00:00:00 2001 +From: Michael Bommarito +Date: Thu, 11 Jun 2026 08:54:55 -0400 +Subject: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() + +From: Michael Bommarito + +commit 20054869770c7df060c5ecee3e8bbf9029c47191 upstream. + +qrtr_endpoint_post() validates an incoming packet with + + if (!size || len != ALIGN(size, 4) + hdrlen) + goto err; + +where size comes from the wire. On 32-bit, size_t is 32 bits and +ALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check +passes and skb_put_data(skb, data + hdrlen, size) writes past the +hdrlen-sized skb and oopses the kernel. 64-bit is unaffected. + +This is the 32-bit residual of ad9d24c9429e2 ("net: qrtr: fix OOB +Read in qrtr_endpoint_post"), which fixed only the 64-bit case. + +Reject any size that cannot fit the buffer before the ALIGN. + +Fixes: ad9d24c9429e2 ("net: qrtr: fix OOB Read in qrtr_endpoint_post") +Cc: stable@vger.kernel.org +Signed-off-by: Michael Bommarito +Reviewed-by: Simon Horman +Link: https://patch.msgid.link/20260611125455.2352279-1-michael.bommarito@gmail.com +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + net/qrtr/af_qrtr.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/net/qrtr/af_qrtr.c ++++ b/net/qrtr/af_qrtr.c +@@ -496,7 +496,7 @@ int qrtr_endpoint_post(struct qrtr_endpo + if (cb->dst_port == QRTR_PORT_CTRL_LEGACY) + cb->dst_port = QRTR_PORT_CTRL; + +- if (!size || len != ALIGN(size, 4) + hdrlen) ++ if (!size || size > len || len != ALIGN(size, 4) + hdrlen) + goto err; + + if ((cb->type == QRTR_TYPE_NEW_SERVER || diff --git a/queue-7.1/octeontx2-pf-clear-stale-mailbox-irq-state-before-request_irq.patch b/queue-7.1/octeontx2-pf-clear-stale-mailbox-irq-state-before-request_irq.patch new file mode 100644 index 0000000000..eeaabcfe6d --- /dev/null +++ b/queue-7.1/octeontx2-pf-clear-stale-mailbox-irq-state-before-request_irq.patch @@ -0,0 +1,78 @@ +From f918554fb7246e89b98ef90abe80801f038258b3 Mon Sep 17 00:00:00 2001 +From: Runyu Xiao +Date: Fri, 12 Jun 2026 00:00:13 +0800 +Subject: octeontx2-pf: clear stale mailbox IRQ state before request_irq() + +From: Runyu Xiao + +commit f918554fb7246e89b98ef90abe80801f038258b3 upstream. + +otx2_register_mbox_intr() currently installs the PF mailbox IRQ handler +before clearing stale mailbox interrupt state. The function itself then +comments that the local interrupt bits must be cleared first to avoid +spurious interrupts, but that clear happens only after request_irq() has +already exposed the handler to irq delivery. + +A running system can reach this during PF mailbox interrupt registration +while stale or latched RVU_PF_INT state is still present. If delivery +happens in the request_irq()-to-clear window, +otx2_pfaf_mbox_intr_handler() can run before local quiesce and touch +the same pf->mbox and pf->mbox_wq carrier that probe and teardown later +reuse or destroy. + +Move the stale mailbox interrupt clear ahead of request_irq(), but keep +interrupt enabling after the handler is installed. This closes the +pre-clear early-IRQ window without creating a new enable-before-handler +window. + +Fixes: 5a6d7c9daef3 ("octeontx2-pf: Mailbox communication with AF") +Cc: stable@vger.kernel.org +Signed-off-by: Runyu Xiao +Reviewed-by: Simon Horman +Reviewed-by: Ratheesh Kannoth +Link: https://patch.msgid.link/20260611160014.3202224-2-runyu.xiao@seu.edu.cn +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c | 20 ++++++++----------- + 1 file changed, 9 insertions(+), 11 deletions(-) + +--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c ++++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c +@@ -1119,9 +1119,16 @@ int otx2_register_mbox_intr(struct otx2_ + { + struct otx2_hw *hw = &pf->hw; + struct msg_req *req; ++ u64 mbox_int_mask; + char *irq_name; + int err; + ++ mbox_int_mask = !is_cn20k(pf->pdev) ? BIT_ULL(0) : ++ BIT_ULL(0) | BIT_ULL(1); ++ ++ /* Clear stale mailbox interrupt state before installing the handler. */ ++ otx2_write64(pf, RVU_PF_INT, mbox_int_mask); ++ + /* Register mailbox interrupt handler */ + if (!is_cn20k(pf->pdev)) { + irq_name = &hw->irq_name[RVU_PF_INT_VEC_AFPF_MBOX * NAME_SIZE]; +@@ -1147,17 +1154,8 @@ int otx2_register_mbox_intr(struct otx2_ + return err; + } + +- /* Enable mailbox interrupt for msgs coming from AF. +- * First clear to avoid spurious interrupts, if any. +- */ +- if (!is_cn20k(pf->pdev)) { +- otx2_write64(pf, RVU_PF_INT, BIT_ULL(0)); +- otx2_write64(pf, RVU_PF_INT_ENA_W1S, BIT_ULL(0)); +- } else { +- otx2_write64(pf, RVU_PF_INT, BIT_ULL(0) | BIT_ULL(1)); +- otx2_write64(pf, RVU_PF_INT_ENA_W1S, BIT_ULL(0) | +- BIT_ULL(1)); +- } ++ /* Enable mailbox interrupt for msgs coming from AF. */ ++ otx2_write64(pf, RVU_PF_INT_ENA_W1S, mbox_int_mask); + + if (!probe_af) + return 0; diff --git a/queue-7.1/octeontx2-vf-clear-stale-mailbox-irq-state-before-request_irq.patch b/queue-7.1/octeontx2-vf-clear-stale-mailbox-irq-state-before-request_irq.patch new file mode 100644 index 0000000000..bbc5a6cc8c --- /dev/null +++ b/queue-7.1/octeontx2-vf-clear-stale-mailbox-irq-state-before-request_irq.patch @@ -0,0 +1,80 @@ +From 0b352f04b9be2c83c0240aa6dae7257fefa90464 Mon Sep 17 00:00:00 2001 +From: Runyu Xiao +Date: Fri, 12 Jun 2026 00:00:14 +0800 +Subject: octeontx2-vf: clear stale mailbox IRQ state before request_irq() + +From: Runyu Xiao + +commit 0b352f04b9be2c83c0240aa6dae7257fefa90464 upstream. + +otx2vf_register_mbox_intr() currently installs the VF mailbox IRQ +handler before clearing stale mailbox interrupt state. The code then says +that local interrupt bits should be cleared first to avoid spurious +interrupts, but that clear still happens only after request_irq() has +already made the handler reachable. + +A running system can reach this during VF mailbox interrupt registration +while stale or latched RVU_VF_INT state is still present. If delivery +happens in the request_irq()-to-clear window, +otx2vf_vfaf_mbox_intr_handler() can run before local quiesce and touch +the same vf->mbox and vf->mbox_wq carrier that probe and teardown later +reuse or destroy. + +Move the stale mailbox interrupt clear ahead of request_irq(), but keep +interrupt enabling after the handler is installed. This closes the +pre-clear early-IRQ window without creating a new enable-before-handler +window. + +Fixes: 3184fb5ba96e ("octeontx2-vf: Virtual function driver support") +Cc: stable@vger.kernel.org +Signed-off-by: Runyu Xiao +Reviewed-by: Simon Horman +Reviewed-by: Ratheesh Kannoth +Link: https://patch.msgid.link/20260611160014.3202224-3-runyu.xiao@seu.edu.cn +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + drivers/net/ethernet/marvell/octeontx2/nic/otx2_vf.c | 22 ++++++++----------- + 1 file changed, 10 insertions(+), 12 deletions(-) + +--- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_vf.c ++++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_vf.c +@@ -251,9 +251,17 @@ static int otx2vf_register_mbox_intr(str + { + struct otx2_hw *hw = &vf->hw; + struct msg_req *req; ++ u64 mbox_int_mask; + char *irq_name; + int err; + ++ mbox_int_mask = !is_cn20k(vf->pdev) ? BIT_ULL(0) : ++ BIT_ULL(0) | BIT_ULL(1) | ++ BIT_ULL(2) | BIT_ULL(3); ++ ++ /* Clear stale mailbox interrupt state before installing the handler. */ ++ otx2_write64(vf, RVU_VF_INT, mbox_int_mask); ++ + /* Register mailbox interrupt handler */ + irq_name = &hw->irq_name[RVU_VF_INT_VEC_MBOX * NAME_SIZE]; + snprintf(irq_name, NAME_SIZE, "RVUVF%d AFVF Mbox", ((vf->pcifunc & +@@ -274,18 +282,8 @@ static int otx2vf_register_mbox_intr(str + return err; + } + +- /* Enable mailbox interrupt for msgs coming from PF. +- * First clear to avoid spurious interrupts, if any. +- */ +- if (!is_cn20k(vf->pdev)) { +- otx2_write64(vf, RVU_VF_INT, BIT_ULL(0)); +- otx2_write64(vf, RVU_VF_INT_ENA_W1S, BIT_ULL(0)); +- } else { +- otx2_write64(vf, RVU_VF_INT, BIT_ULL(0) | BIT_ULL(1) | +- BIT_ULL(2) | BIT_ULL(3)); +- otx2_write64(vf, RVU_VF_INT_ENA_W1S, BIT_ULL(0) | +- BIT_ULL(1) | BIT_ULL(2) | BIT_ULL(3)); +- } ++ /* Enable mailbox interrupt for msgs coming from PF. */ ++ otx2_write64(vf, RVU_VF_INT_ENA_W1S, mbox_int_mask); + + if (!probe_pf) + return 0; diff --git a/queue-7.1/powerpc-pseries-kconfig-enable-config_vpa_pmu-to-be-used-with-kvm.patch b/queue-7.1/powerpc-pseries-kconfig-enable-config_vpa_pmu-to-be-used-with-kvm.patch new file mode 100644 index 0000000000..89f09c2adf --- /dev/null +++ b/queue-7.1/powerpc-pseries-kconfig-enable-config_vpa_pmu-to-be-used-with-kvm.patch @@ -0,0 +1,40 @@ +From fe179677b6dcb4b658586038a811f87265e97777 Mon Sep 17 00:00:00 2001 +From: Gautam Menghani +Date: Mon, 15 Jun 2026 14:41:19 +0530 +Subject: powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM + +From: Gautam Menghani + +commit fe179677b6dcb4b658586038a811f87265e97777 upstream. + +Currently, CONFIG_VPA_PMU is not enabled by default, and consequently +cannot be used for KVM guests at all, unless explicitly enabled on +host kernel. + +Mark CONFIG_VPA_PMU as "default m" to ensure it is available when KVM is +being used. + +Cc: stable@vger.kernel.org # v6.13+ +Suggested-by: Sean Christopherson +Reviewed-by: Amit Machhiwal +Reviewed-by: Harsh Prateek Bora +Reviewed-by: Ritesh Harjani (IBM) +Signed-off-by: Gautam Menghani +[Maddy: Changed tag order] +Signed-off-by: Madhavan Srinivasan +Link: https://patch.msgid.link/20260615091120.84169-1-gautam@linux.ibm.com +Signed-off-by: Greg Kroah-Hartman +--- + arch/powerpc/platforms/pseries/Kconfig | 1 + + 1 file changed, 1 insertion(+) + +--- a/arch/powerpc/platforms/pseries/Kconfig ++++ b/arch/powerpc/platforms/pseries/Kconfig +@@ -154,6 +154,7 @@ config HV_PERF_CTRS + config VPA_PMU + tristate "VPA PMU events" + depends on KVM_BOOK3S_64_HV && HV_PERF_CTRS ++ default m + help + Enable access to the VPA PMU counters via perf. This enables + code that support measurement for KVM on PowerVM(KoP) feature. diff --git a/queue-7.1/series b/queue-7.1/series index 7d5e34926f..7faa95fbbb 100644 --- a/queue-7.1/series +++ b/queue-7.1/series @@ -1524,3 +1524,67 @@ drm-imagination-make-pvr_fw_trace_init_mask_ops-stat.patch tracing-remotes-fix-leak-in-trace_remote_alloc_buffe.patch tracing-remotes-fix-struct_len-in-trace_remote_alloc.patch ring-buffer-allow-sparse-cpu-masks-in-ring_buffer_de.patch +idpf-add-padding-to-ptp-virtchnl-structures.patch +mlxsw-fix-refcount-leak-in-mlxsw_sp_port_lag_join.patch +mlxsw-fix-refcount-leak-in-mlxsw_sp_vrs_lpm_tree_replace.patch +vduse-fix-race-in-vduse_dev_msg_sync-and-vduse_dev_read_iter.patch +vduse-avoid-leaking-information-to-userspace.patch +asoc-sof-ipc4-control-fix-toctou-in-sof_ipc4_bytes_put.patch +asoc-sof-ipc4-control-validate-notification-payload-size.patch +asoc-sof-ipc3-control-use-overflow-checks-in-control_update-size-calc.patch +asoc-sof-ipc3-control-fix-toctou-in-bytes_put-and-bytes_get.patch +asoc-sof-topology-validate-vendor-array-size-before-parsing.patch +tipc-restrict-socket-queue-dumps-in-enqueue-tracepoints.patch +net-qrtr-fix-32-bit-integer-overflow-in-qrtr_endpoint_post.patch +net-atm-reject-out-of-range-traffic-classes-in-qos-validation.patch +octeontx2-pf-clear-stale-mailbox-irq-state-before-request_irq.patch +octeontx2-vf-clear-stale-mailbox-irq-state-before-request_irq.patch +net-ife-require-eth_hlen-to-be-pullable-in-ife_decode.patch +arm64-fpsimd-fix-type-mismatch-in-sve_-save-load-_state.patch +arm64-dts-s32g3-fix-swt8-watchdog-address.patch +arm64-dts-renesas-ironhide-describe-inline-ecc-carveouts.patch +arm-dts-imx6ul-var-som-fix-warning-for-non-existent-dc-supply-property.patch +arm64-dts-qcom-sdm630-describe-adsp_mem-region-properly.patch +arm64-dts-rockchip-fix-ethernet-phy-not-found-on-px30-ringneck.patch +arm-dts-stm32-stm32mp15x-mecio1-io-fix-adc-sampling-times.patch +arm-dts-stm32-stm32mp15x-mecio1-io-move-divergent-mecio1-adc-channels-to-board-files.patch +arm64-dts-ti-k3-am62a7-sk-add-bootph-all-tag-to-vqmmc.patch +arm-dts-stm32-stm32mp15x-mecio1-io-enable-internal-adc-reference.patch +arm64-dts-imx8ulp-evk-correct-type-c-int-gpio-flags.patch +arm-dts-stm32-stm32mp15x-mecio1-io-fix-gpio-names-typo.patch +arm64-dts-qcom-hamoa-fix-opp-tables-for-all-displayport-controllers.patch +arm-dts-stm32-stm32mp15x-mecio1-io-move-gpio-line-names-to-board-files.patch +arm-dts-stm32-stm32mp15x-mecio1-io-fix-expander-gpio-line-typo.patch +arm-dts-stm32-stm32mp15x-mecio1-io-move-expander-gpio-line-names-to-board-files.patch +loongarch-kvm-validate-irqchip-index-in-irqfd-routing.patch +loongarch-kvm-check-irq-validity-in-kvm_vcpu_ioctl_interrupt.patch +loongarch-kvm-check-the-return-values-for-put_user.patch +loongarch-kvm-fix-fpu-register-width-with-user-access-api.patch +loongarch-kvm-return-full-old-csr-value-from-kvm_emu_xchg_csr.patch +kvm-s390-vsie-fix-allocation-of-struct-vsie_rmap.patch +kvm-s390-vsie-add-missing-radix_tree_preload-in-_gaccess_shadow_fault.patch +kvm-s390-silence-potential-warnings-in-_gmap_crstep_xchg_atomic.patch +kvm-s390-vsie-use-mmu-cache-to-allocate-rmap.patch +kvm-s390-initialize-kvm_s390_get_cmma_bits-memory.patch +kvm-s390-fix-unlikely-race-in-try_get_locked_pte.patch +powerpc-pseries-kconfig-enable-config_vpa_pmu-to-be-used-with-kvm.patch +kvm-s390-pci-fix-gisc-refcount-leak-on-aif-enable-failure.patch +kvm-arm64-vgic-check-the-interrupt-is-still-ours-before-migrating-it.patch +kvm-arm64-vgic-handle-race-between-interrupt-affinity-change-and-lpi-disabling.patch +kvm-nvmx-move-vtpr-vs.-tpr-threshold-consistency-check-into-normal-checks.patch +kvm-s390-pci-fix-handling-of-aif-enable-without-aisb.patch +kvm-sev-do-not-allow-intra-host-migration-mirroring-of-snp-vms.patch +kvm-tdx-reject-concurrent-change-to-cpuid-entry-count.patch +kvm-x86-ignore-pending-pv-eoi-if-the-vcpu-has-since-disabled-pv-eois.patch +kvm-x86-nullify-irqfd-producer-if-updating-irte-for-bypass-fails.patch +kvm-nvmx-put-vmcs12-pages-if-nested-vm-enter-fails-due-to-invalid-guest-state.patch +kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch +kvm-arm64-account-pkvm-reclaim-against-the-vm-mm.patch +kvm-arm64-ensure-level-is-always-initialized-when-relaxing-perms.patch +kvm-arm64-nv-drop-bogus-warn-for-write-to-zcr_el2.patch +kvm-arm64-nv-write-esr_el2-for-injected-nested-serror-exceptions.patch +kvm-arm64-nv-fix-spsr_el2-restore-in-kvm_hyp_handle_mops.patch +kvm-arm64-nv-respect-read-only-pfn-when-mapping-l1-vncr.patch +kvm-arm64-nv-inject-sea-if-kvm_translate_vncr-can-t-resolve-pfn.patch +kvm-arm64-nv-re-translate-vncr-before-injecting-abort.patch +kvm-arm64-nv-inject-sea-if-guest-vncr-isn-t-normal-memory.patch diff --git a/queue-7.1/tipc-restrict-socket-queue-dumps-in-enqueue-tracepoints.patch b/queue-7.1/tipc-restrict-socket-queue-dumps-in-enqueue-tracepoints.patch new file mode 100644 index 0000000000..f6f01ac65b --- /dev/null +++ b/queue-7.1/tipc-restrict-socket-queue-dumps-in-enqueue-tracepoints.patch @@ -0,0 +1,93 @@ +From acd7df8d955480a6f6e5bb809da67b1500cc3cf4 Mon Sep 17 00:00:00 2001 +From: Li Xiasong +Date: Thu, 11 Jun 2026 21:56:47 +0800 +Subject: tipc: restrict socket queue dumps in enqueue tracepoints + +From: Li Xiasong + +commit acd7df8d955480a6f6e5bb809da67b1500cc3cf4 upstream. + +tipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is +owned by user context. The spinlock protects the backlog queue in this +path, but it does not serialize against the socket owner consuming or +purging sk_receive_queue. + +KASAN reported: + + CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy) + Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 + Call Trace: + + dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123 + print_report+0xce/0x5b0 mm/kasan/report.c:482 + kasan_report+0xc6/0x100 mm/kasan/report.c:597 + __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380 + tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73 + tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187 + tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996 + trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188 + tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497 + tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689 + __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512 + tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400 + sock_sendmsg+0x2f6/0x3e0 net/socket.c:825 + splice_to_socket+0x7f9/0x1010 fs/splice.c:884 + do_splice+0xe21/0x2330 fs/splice.c:936 + __do_splice+0x153/0x260 fs/splice.c:1431 + __x64_sys_splice+0x150/0x230 fs/splice.c:1616 + x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41 + do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63 + entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130 + RIP: 0033:0x71624e8aafe2 + Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66 + RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113 + RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2 + RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066 + RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001 + R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00 + R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40 + + +The TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump +sk_receive_queue and can therefore dereference skbs that the socket +owner has already dequeued or freed. Restrict these dumps to +TIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held +spinlock. + +Keep the change limited to the enqueue path, where the unsafe queue dump +is reachable while the socket is owned by user context. + +Fixes: 01e661ebfbad ("tipc: add trace_events for tipc socket") +Cc: stable@vger.kernel.org +Signed-off-by: Li Xiasong +Reviewed-by: Tung Nguyen +Link: https://patch.msgid.link/20260611135647.3666727-1-lixiasong1@huawei.com +Signed-off-by: Jakub Kicinski +Signed-off-by: Greg Kroah-Hartman +--- + net/tipc/socket.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +--- a/net/tipc/socket.c ++++ b/net/tipc/socket.c +@@ -2455,17 +2455,17 @@ static void tipc_sk_enqueue(struct sk_bu + atomic_set(dcnt, 0); + lim = rcvbuf_limit(sk, skb) + atomic_read(dcnt); + if (likely(!sk_add_backlog(sk, skb, lim))) { +- trace_tipc_sk_overlimit1(sk, skb, TIPC_DUMP_ALL, ++ trace_tipc_sk_overlimit1(sk, skb, TIPC_DUMP_SK_BKLGQ, + "bklg & rcvq >90% allocated!"); + continue; + } + +- trace_tipc_sk_dump(sk, skb, TIPC_DUMP_ALL, "err_overload!"); ++ trace_tipc_sk_dump(sk, skb, TIPC_DUMP_SK_BKLGQ, "err_overload!"); + /* Overload => reject message back to sender */ + onode = tipc_own_addr(sock_net(sk)); + sk_drops_inc(sk); + if (tipc_msg_reverse(onode, &skb, TIPC_ERR_OVERLOAD)) { +- trace_tipc_sk_rej_msg(sk, skb, TIPC_DUMP_ALL, ++ trace_tipc_sk_rej_msg(sk, skb, TIPC_DUMP_SK_BKLGQ, + "@sk_enqueue!"); + __skb_queue_tail(xmitq, skb); + } diff --git a/queue-7.1/vduse-avoid-leaking-information-to-userspace.patch b/queue-7.1/vduse-avoid-leaking-information-to-userspace.patch new file mode 100644 index 0000000000..8cba9e3138 --- /dev/null +++ b/queue-7.1/vduse-avoid-leaking-information-to-userspace.patch @@ -0,0 +1,52 @@ +From 9c1523803445ee0348f62b77793266dd981596e0 Mon Sep 17 00:00:00 2001 +From: Jason Wang +Date: Fri, 30 Jan 2026 13:07:50 +0800 +Subject: VDUSE: avoid leaking information to userspace +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Jason Wang + +commit 9c1523803445ee0348f62b77793266dd981596e0 upstream. + +The bounceing is not necessarily page aligned, so current VDUSE can +leak kernel information through mapping bounce pages to +userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking +information to userspace. + +Fixes: 8c773d53fb7b ("vduse: Implement an MMU-based software IOTLB") +Cc: stable@vger.kernel.org +Signed-off-by: Jason Wang +Reviewed-by: Xie Yongji +Reviewed-by: Eugenio Pérez +Signed-off-by: Michael S. Tsirkin +Message-ID: <20260130050750.4050-1-jasowang@redhat.com> +Signed-off-by: Greg Kroah-Hartman +--- + drivers/vdpa/vdpa_user/iova_domain.c | 2 +- + drivers/vdpa/vdpa_user/vduse_dev.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +--- a/drivers/vdpa/vdpa_user/iova_domain.c ++++ b/drivers/vdpa/vdpa_user/iova_domain.c +@@ -124,7 +124,7 @@ static int vduse_domain_map_bounce_page( + if (!map->bounce_page) { + head_map = &domain->bounce_maps[(iova & PAGE_MASK) >> BOUNCE_MAP_SHIFT]; + if (!head_map->bounce_page) { +- tmp_page = alloc_page(GFP_ATOMIC); ++ tmp_page = alloc_page(GFP_ATOMIC | __GFP_ZERO); + if (!tmp_page) + return -ENOMEM; + if (cmpxchg(&head_map->bounce_page, NULL, tmp_page)) +--- a/drivers/vdpa/vdpa_user/vduse_dev.c ++++ b/drivers/vdpa/vdpa_user/vduse_dev.c +@@ -999,7 +999,7 @@ static void *vduse_dev_alloc_coherent(un + if (!token.group) + return NULL; + +- addr = alloc_pages_exact(size, flag); ++ addr = alloc_pages_exact(size, flag | __GFP_ZERO); + if (!addr) + return NULL; + diff --git a/queue-7.1/vduse-fix-race-in-vduse_dev_msg_sync-and-vduse_dev_read_iter.patch b/queue-7.1/vduse-fix-race-in-vduse_dev_msg_sync-and-vduse_dev_read_iter.patch new file mode 100644 index 0000000000..e7665d243a --- /dev/null +++ b/queue-7.1/vduse-fix-race-in-vduse_dev_msg_sync-and-vduse_dev_read_iter.patch @@ -0,0 +1,108 @@ +From ae9c13b6fd79087cc5a216ee1649b6f012c2a238 Mon Sep 17 00:00:00 2001 +From: Zhang Tianci +Date: Thu, 26 Feb 2026 19:55:50 +0800 +Subject: vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +From: Zhang Tianci + +commit ae9c13b6fd79087cc5a216ee1649b6f012c2a238 upstream. + +There is one race case in vduse_dev_msg_sync and vduse_dev_read_iter: + +vduse_dev_read_iter(): + lock(msg_lock); + dequeue_msg(send_list); + unlock(msg_lock); +vduse_dev_msg_sync(): + wait_timeout() finish + lock(msg_lock); + check msg->complete is false + list_del(msg); <- double list_del() crash! + +To fix this case, we shall ensure vduse_msg is on send_list or recv_list +outside the msg_lock critical section. + +Fixes: c8a6153b6c59 ("vduse: Introduce VDUSE - vDPA Device in Userspace") +Cc: stable@vger.kernel.org +Signed-off-by: Zhang Tianci +Reviewed-by: Xie Yongji +Acked-by: Jason Wang +Acked-by: Eugenio Pérez +Acked-by: Michael S. Tsirkin +Signed-off-by: Michael S. Tsirkin +Message-ID: <20260226115550.1814-3-zhangtianci.1997@bytedance.com> +Signed-off-by: Greg Kroah-Hartman +--- + drivers/vdpa/vdpa_user/vduse_dev.c | 37 +++++++++++++++++++++++++++---------- + 1 file changed, 27 insertions(+), 10 deletions(-) + +--- a/drivers/vdpa/vdpa_user/vduse_dev.c ++++ b/drivers/vdpa/vdpa_user/vduse_dev.c +@@ -364,6 +364,7 @@ static ssize_t vduse_dev_read_iter(struc + struct file *file = iocb->ki_filp; + struct vduse_dev *dev = file->private_data; + struct vduse_dev_msg *msg; ++ struct vduse_dev_request req; + int size = sizeof(struct vduse_dev_request); + ssize_t ret; + +@@ -375,12 +376,11 @@ static ssize_t vduse_dev_read_iter(struc + msg = vduse_dequeue_msg(&dev->send_list); + if (msg) + break; ++ spin_unlock(&dev->msg_lock); + +- ret = -EAGAIN; + if (file->f_flags & O_NONBLOCK) +- goto unlock; ++ return -EAGAIN; + +- spin_unlock(&dev->msg_lock); + ret = wait_event_interruptible_exclusive(dev->waitq, + !list_empty(&dev->send_list)); + if (ret) +@@ -388,17 +388,34 @@ static ssize_t vduse_dev_read_iter(struc + + spin_lock(&dev->msg_lock); + } ++ ++ memcpy(&req, &msg->req, sizeof(req)); ++ /* ++ * We must ensure vduse_msg is on send_list or recv_list before unlock ++ * dev->msg_lock. Because vduse_dev_msg_sync() may be timeout when we ++ * copy data to userspace, and will call list_del() for this msg. ++ */ ++ vduse_enqueue_msg(&dev->recv_list, msg); + spin_unlock(&dev->msg_lock); +- ret = copy_to_iter(&msg->req, size, to); +- spin_lock(&dev->msg_lock); ++ ++ ret = copy_to_iter(&req, size, to); + if (ret != size) { ++ /* ++ * Roll back: move msg back to send_list if still pending. ++ * ++ * NOTE: ++ * vduse_find_msg() must use req.request_id instead of `msg`. ++ * A malicious userspace may reply to this request, and wake up ++ * the caller, after which `msg` will have already been freed. ++ * And here vduse_find_msg() will return NULL then do nothing. ++ */ ++ spin_lock(&dev->msg_lock); ++ msg = vduse_find_msg(&dev->recv_list, req.request_id); ++ if (msg) ++ vduse_enqueue_msg_head(&dev->send_list, msg); ++ spin_unlock(&dev->msg_lock); + ret = -EFAULT; +- vduse_enqueue_msg_head(&dev->send_list, msg); +- goto unlock; + } +- vduse_enqueue_msg(&dev->recv_list, msg); +-unlock: +- spin_unlock(&dev->msg_lock); + + return ret; + }