1. Jun 22, 2023
    • Yogesh's avatar
      fs: jfs: Fix UBSAN: array-index-out-of-bounds in dbAllocDmapLev · 4e302336
      Yogesh authored
      Syzkaller reported the following issue:
      
      UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:1965:6
      index -84 is out of range for type 's8[341]' (aka 'signed char[341]')
      CPU: 1 PID: 4995 Comm: syz-executor146 Not tainted 6.4.0-rc6-syzkaller-00037-gb6dad517
      
       #0
      Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023
      Call Trace:
       <TASK>
       __dump_stack lib/dump_stack.c:88 [inline]
       dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106
       ubsan_epilogue lib/ubsan.c:217 [inline]
       __ubsan_handle_out_of_bounds+0x11c/0x150 lib/ubsan.c:348
       dbAllocDmapLev+0x3e5/0x430 fs/jfs/jfs_dmap.c:1965
       dbAllocCtl+0x113/0x920 fs/jfs/jfs_dmap.c:1809
       dbAllocAG+0x28f/0x10b0 fs/jfs/jfs_dmap.c:1350
       dbAlloc+0x658/0xca0 fs/jfs/jfs_dmap.c:874
       dtSplitUp fs/jfs/jfs_dtree.c:974 [inline]
       dtInsert+0xda7/0x6b00 fs/jfs/jfs_dtree.c:863
       jfs_create+0x7b6/0xbb0 fs/jfs/namei.c:137
       lookup_open fs/namei.c:3492 [inline]
       open_last_lookups fs/namei.c:3560 [inline]
       path_openat+0x13df/0x3170 fs/namei.c:3788
       do_filp_open+0x234/0x490 fs/namei.c:3818
       do_sys_openat2+0x13f/0x500 fs/open.c:1356
       do_sys_open fs/open.c:1372 [inline]
       __do_sys_openat fs/open.c:1388 [inline]
       __se_sys_openat fs/open.c:1383 [inline]
       __x64_sys_openat+0x247/0x290 fs/open.c:1383
       do_syscall_x64 arch/x86/entry/common.c:50 [inline]
       do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
       entry_SYSCALL_64_after_hwframe+0x63/0xcd
      RIP: 0033:0x7f1f4e33f7e9
      Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 51 14 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
      RSP: 002b:00007ffc21129578 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
      RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f1f4e33f7e9
      RDX: 000000000000275a RSI: 0000000020000040 RDI: 00000000ffffff9c
      RBP: 00007f1f4e2ff080 R08: 0000000000000000 R09: 0000000000000000
      R10: 0000000000000000 R11: 0000000000000246 R12: 00007f1f4e2ff110
      R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
       </TASK>
      
      The bug occurs when the dbAllocDmapLev()function attempts to access
      dp->tree.stree[leafidx + LEAFIND] while the leafidx value is negative.
      
      To rectify this, the patch introduces a safeguard within the
      dbAllocDmapLev() function. A check has been added to verify if leafidx is
      negative. If it is, the function immediately returns an I/O error, preventing
      any further execution that could potentially cause harm.
      
      Tested via syzbot.
      
      Reported-by: default avatar <syzbot+853a6f4dfa3cf37d3aea@syzkaller.appspotmail.com>
      Link: https://syzkaller.appspot.com/bug?extid=ae2f5a27a07ae44b0f17
      
      
      Signed-off-by: default avatarYogesh <yogi.kernel@gmail.com>
      Signed-off-by: default avatarDave Kleikamp <dave.kleikamp@oracle.com>
      4e302336
  2. Jun 21, 2023
  3. Jun 20, 2023
    • Linus Torvalds's avatar
      Merge tag 'hyperv-fixes-signed-20230619' of... · 692b7dc8
      Linus Torvalds authored
      Merge tag 'hyperv-fixes-signed-20230619' of git://git.kernel.org/pub/scm/linux/kernel/git/hyperv/linux
      
      Pull hyperv fixes from Wei Liu:
      
       - Fix races in Hyper-V PCI controller (Dexuan Cui)
      
       - Fix handling of hyperv_pcpu_input_arg (Michael Kelley)
      
       - Fix vmbus_wait_for_unload to scan present CPUs (Michael Kelley)
      
       - Call hv_synic_free in the failure path of hv_synic_alloc (Dexuan Cui)
      
       - Add noop for real mode handlers for virtual trust level code (Saurabh
         Sengar)
      
      * tag 'hyperv-fixes-signed-20230619' of git://git.kernel.org/pub/scm/linux/kernel/git/hyperv/linux:
        PCI: hv: Add a per-bus mutex state_lock
        Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally"
        PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev
        PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic
        PCI: hv: Fix a race condition bug in hv_pci_query_relations()
        arm64/hyperv: Use CPUHP_AP_HYPERV_ONLINE state to fix CPU online sequencing
        x86/hyperv: Fix hyperv_pcpu_input_arg handling when CPUs go online/offline
        Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs
        Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails
        x86/hyperv/vtl: Add noop for realmode pointers
      692b7dc8
    • Linus Torvalds's avatar
      Merge tag 'afs-fixes-20230719' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs · dbad9ce9
      Linus Torvalds authored
      Pull AFS writeback fixes from David Howells:
      
       - release the acquired batch before returning if we got >=5 skips
      
       - retry a page we had to wait for rather than skipping over it after
         the wait
      
      * tag 'afs-fixes-20230719' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs:
        afs: Fix waiting for writeback then skipping folio
        afs: Fix dangling folio ref counts in writeback
      dbad9ce9
  4. Jun 19, 2023
  5. Jun 18, 2023
    • Dexuan Cui's avatar
      PCI: hv: Add a per-bus mutex state_lock · 067d6ec7
      Dexuan Cui authored
      In the case of fast device addition/removal, it's possible that
      hv_eject_device_work() can start to run before create_root_hv_pci_bus()
      starts to run; as a result, the pci_get_domain_bus_and_slot() in
      hv_eject_device_work() can return a 'pdev' of NULL, and
      hv_eject_device_work() can remove the 'hpdev', and immediately send a
      message PCI_EJECTION_COMPLETE to the host, and the host immediately
      unassigns the PCI device from the guest; meanwhile,
      create_root_hv_pci_bus() and the PCI device driver can be probing the
      dead PCI device and reporting timeout errors.
      
      Fix the issue by adding a per-bus mutex 'state_lock' and grabbing the
      mutex before powering on the PCI bus in hv_pci_enter_d0(): when
      hv_eject_device_work() starts to run, it's able to find the 'pdev' and call
      pci_stop_and_remove_bus_device(pdev): if the PCI device driver has
      loaded, the PCI device driver's probe() function is already called in
      create_root_hv_pci_bus() -> pci_bus_add_devices(), and now
      hv_eject_device_work() -> pci_stop_and_remove_bus_device() is able
      to call the PCI device driver's remove() function and remove the device
      reliably; if the PCI device driver hasn't loaded yet, the function call
      hv_eject_device_work() -> pci_stop_and_remove_bus_device() is able to
      remove the PCI device reliably and the PCI device driver's probe()
      function won't be called; if the PCI device driver's probe() is already
      running (e.g., systemd-udev is loading the PCI device driver), it must
      be holding the per-device lock, and after the probe() finishes and releases
      the lock, hv_eject_device_work() -> pci_stop_and_remove_bus_device() is
      able to proceed to remove the device reliably.
      
      Fixes: 4daace0d
      
       ("PCI: hv: Add paravirtual PCI front-end for Microsoft Hyper-V VMs")
      Signed-off-by: default avatarDexuan Cui <decui@microsoft.com>
      Reviewed-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Acked-by: default avatarLorenzo Pieralisi <lpieralisi@kernel.org>
      Cc: stable@vger.kernel.org
      Link: https://lore.kernel.org/r/20230615044451.5580-6-decui@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      067d6ec7
    • Dexuan Cui's avatar
      Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally" · a847234e
      Dexuan Cui authored
      This reverts commit d6af2ed2.
      
      The statement "the hv_pci_bus_exit() call releases structures of all its
      child devices" in commit d6af2ed2 is not true: in the path
      hv_pci_probe() -> hv_pci_enter_d0() -> hv_pci_bus_exit(hdev, true): the
      parameter "keep_devs" is true, so hv_pci_bus_exit() does *not* release the
      child "struct hv_pci_dev *hpdev" that is created earlier in
      pci_devices_present_work() -> new_pcichild_device().
      
      The commit d6af2ed2
      
       was originally made in July 2020 for RHEL 7.7,
      where the old version of hv_pci_bus_exit() was used; when the commit was
      rebased and merged into the upstream, people didn't notice that it's
      not really necessary. The commit itself doesn't cause any issue, but it
      makes hv_pci_probe() more complicated. Revert it to facilitate some
      upcoming changes to hv_pci_probe().
      
      Signed-off-by: default avatarDexuan Cui <decui@microsoft.com>
      Reviewed-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Acked-by: default avatarWei Hu <weh@microsoft.com>
      Cc: stable@vger.kernel.org
      Link: https://lore.kernel.org/r/20230615044451.5580-5-decui@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      a847234e
    • Dexuan Cui's avatar
      PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev · add9195e
      Dexuan Cui authored
      
      
      The hpdev->state is never really useful. The only use in
      hv_pci_eject_device() and hv_eject_device_work() is not really necessary.
      
      Signed-off-by: default avatarDexuan Cui <decui@microsoft.com>
      Reviewed-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Acked-by: default avatarLorenzo Pieralisi <lpieralisi@kernel.org>
      Cc: stable@vger.kernel.org
      Link: https://lore.kernel.org/r/20230615044451.5580-4-decui@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      add9195e
    • Dexuan Cui's avatar
      PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic · 2738d5ab
      Dexuan Cui authored
      When the host tries to remove a PCI device, the host first sends a
      PCI_EJECT message to the guest, and the guest is supposed to gracefully
      remove the PCI device and send a PCI_EJECTION_COMPLETE message to the host;
      the host then sends a VMBus message CHANNELMSG_RESCIND_CHANNELOFFER to
      the guest (when the guest receives this message, the device is already
      unassigned from the guest) and the guest can do some final cleanup work;
      if the guest fails to respond to the PCI_EJECT message within one minute,
      the host sends the VMBus message CHANNELMSG_RESCIND_CHANNELOFFER and
      removes the PCI device forcibly.
      
      In the case of fast device addition/removal, it's possible that the PCI
      device driver is still configuring MSI-X interrupts when the guest receives
      the PCI_EJECT message; the channel callback calls hv_pci_eject_device(),
      which sets hpdev->state to hv_pcichild_ejecting, and schedules a work
      hv_eject_device_work(); if the PCI device driver is calling
      pci_alloc_irq_vectors() -> ... -> hv_compose_msi_msg(), we can break the
      while loop in hv_compose_msi_msg() due to the updated hpdev->state, and
      leave data->chip_data with its default value of NULL; later, when the PCI
      device driver calls request_irq() -> ... -> hv_irq_unmask(), the guest
      crashes in hv_arch_irq_unmask() due to data->chip_data being NULL.
      
      Fix the issue by not testing hpdev->state in the while loop: when the
      guest receives PCI_EJECT, the device is still assigned to the guest, and
      the guest has one minute to finish the device removal gracefully. We don't
      really need to (and we should not) test hpdev->state in the loop.
      
      Fixes: de0aa7b2
      
       ("PCI: hv: Fix 2 hang issues in hv_compose_msi_msg()")
      Signed-off-by: default avatarDexuan Cui <decui@microsoft.com>
      Reviewed-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Cc: stable@vger.kernel.org
      Link: https://lore.kernel.org/r/20230615044451.5580-3-decui@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      2738d5ab
    • Dexuan Cui's avatar
      PCI: hv: Fix a race condition bug in hv_pci_query_relations() · 440b5e36
      Dexuan Cui authored
      Since day 1 of the driver, there has been a race between
      hv_pci_query_relations() and survey_child_resources(): during fast
      device hotplug, hv_pci_query_relations() may error out due to
      device-remove and the stack variable 'comp' is no longer valid;
      however, pci_devices_present_work() -> survey_child_resources() ->
      complete() may be running on another CPU and accessing the no-longer-valid
      'comp'. Fix the race by flushing the workqueue before we exit from
      hv_pci_query_relations().
      
      Fixes: 4daace0d
      
       ("PCI: hv: Add paravirtual PCI front-end for Microsoft Hyper-V VMs")
      Signed-off-by: default avatarDexuan Cui <decui@microsoft.com>
      Reviewed-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Acked-by: default avatarLorenzo Pieralisi <lpieralisi@kernel.org>
      Cc: stable@vger.kernel.org
      Link: https://lore.kernel.org/r/20230615044451.5580-2-decui@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      440b5e36
    • Damien Le Moal's avatar
      ata: libata-scsi: Avoid deadlock on rescan after device resume · 6aa0365a
      Damien Le Moal authored
      
      
      When an ATA port is resumed from sleep, the port is reset and a power
      management request issued to libata EH to reset the port and rescanning
      the device(s) attached to the port. Device rescanning is done by
      scheduling an ata_scsi_dev_rescan() work, which will execute
      scsi_rescan_device().
      
      However, scsi_rescan_device() takes the generic device lock, which is
      also taken by dpm_resume() when the SCSI device is resumed as well. If
      a device rescan execution starts before the completion of the SCSI
      device resume, the rcu locking used to refresh the cached VPD pages of
      the device, combined with the generic device locking from
      scsi_rescan_device() and from dpm_resume() can cause a deadlock.
      
      Avoid this situation by changing struct ata_port scsi_rescan_task to be
      a delayed work instead of a simple work_struct. ata_scsi_dev_rescan() is
      modified to check if the SCSI device associated with the ATA device that
      must be rescanned is not suspended. If the SCSI device is still
      suspended, ata_scsi_dev_rescan() returns early and reschedule itself for
      execution after an arbitrary delay of 5ms.
      
      Reported-by: default avatarKai-Heng Feng <kai.heng.feng@canonical.com>
      Reported-by: default avatarJoe Breuer <linux-kernel@jmbreuer.net>
      Closes: https://bugzilla.kernel.org/show_bug.cgi?id=217530
      Fixes: a19a93e4
      
       ("scsi: core: pm: Rely on the device driver core for async power management")
      Signed-off-by: default avatarDamien Le Moal <dlemoal@kernel.org>
      Reviewed-by: default avatarHannes Reinecke <hare@suse.de>
      Tested-by: default avatarKai-Heng Feng <kai.heng.feng@canonical.com>
      Tested-by: default avatarJoe Breuer <linux-kernel@jmbreuer.net>
      6aa0365a
    • Michael Kelley's avatar
      arm64/hyperv: Use CPUHP_AP_HYPERV_ONLINE state to fix CPU online sequencing · 52ae076c
      Michael Kelley authored
      
      
      State CPUHP_AP_HYPERV_ONLINE has been introduced to correctly sequence the
      initialization of hyperv_pcpu_input_arg. Use this new state for Hyper-V
      initialization so that hyperv_pcpu_input_arg is allocated early enough.
      
      Signed-off-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Reviewed-by: default avatarDexuan Cui <decui@microsoft.com>
      Link: https://lore.kernel.org/r/1684862062-51576-2-git-send-email-mikelley@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      52ae076c
    • Michael Kelley's avatar
      x86/hyperv: Fix hyperv_pcpu_input_arg handling when CPUs go online/offline · 9636be85
      Michael Kelley authored
      These commits
      
      a494aef2 ("PCI: hv: Replace retarget_msi_interrupt_params with hyperv_pcpu_input_arg")
      2c6ba421
      
       ("PCI: hv: Enable PCI pass-thru devices in Confidential VMs")
      
      update the Hyper-V virtual PCI driver to use the hyperv_pcpu_input_arg
      because that memory will be correctly marked as decrypted or encrypted
      for all VM types (CoCo or normal). But problems ensue when CPUs in the
      VM go online or offline after virtual PCI devices have been configured.
      
      When a CPU is brought online, the hyperv_pcpu_input_arg for that CPU is
      initialized by hv_cpu_init() running under state CPUHP_AP_ONLINE_DYN.
      But this state occurs after state CPUHP_AP_IRQ_AFFINITY_ONLINE, which
      may call the virtual PCI driver and fault trying to use the as yet
      uninitialized hyperv_pcpu_input_arg. A similar problem occurs in a CoCo
      VM if the MMIO read and write hypercalls are used from state
      CPUHP_AP_IRQ_AFFINITY_ONLINE.
      
      When a CPU is taken offline, IRQs may be reassigned in state
      CPUHP_TEARDOWN_CPU. Again, the virtual PCI driver may fault trying to
      use the hyperv_pcpu_input_arg that has already been freed by a
      higher state.
      
      Fix the onlining problem by adding state CPUHP_AP_HYPERV_ONLINE
      immediately after CPUHP_AP_ONLINE_IDLE (similar to CPUHP_AP_KVM_ONLINE)
      and before CPUHP_AP_IRQ_AFFINITY_ONLINE. Use this new state for
      Hyper-V initialization so that hyperv_pcpu_input_arg is allocated
      early enough.
      
      Fix the offlining problem by not freeing hyperv_pcpu_input_arg when
      a CPU goes offline. Retain the allocated memory, and reuse it if
      the CPU comes back online later.
      
      Signed-off-by: default avatarMichael Kelley <mikelley@microsoft.com>
      Reviewed-by: default avatarVitaly Kuznetsov <vkuznets@redhat.com>
      Acked-by: default avatarBorislav Petkov (AMD) <bp@alien8.de>
      Reviewed-by: default avatarDexuan Cui <decui@microsoft.com>
      Link: https://lore.kernel.org/r/1684862062-51576-1-git-send-email-mikelley@microsoft.com
      
      
      Signed-off-by: default avatarWei Liu <wei.liu@kernel.org>
      9636be85
    • Linus Torvalds's avatar
      Merge tag 'staging-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging · 1b29d271
      Linus Torvalds authored
      Pull staging driver fix from Greg KH:
       "Here is a single staging driver "fix" for 6.4-rc7. I've been sitting
        on it in my tree for many weeks as it is just a simple documentation
        update, with the hope that maybe some other staging driver fixes would
        need to be merged for 6.4-final, but that does not seem to be the
        case.
      
        So please, pull in this one documentation update so that Aaro doesn't
        get emails going forward that he can't do anything about"
      
      * tag 'staging-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging:
        staging: octeon: delete my name from TODO contact
      1b29d271
    • Linus Torvalds's avatar
      Merge tag 'usb-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb · 670062e7
      Linus Torvalds authored
      Pull USB / Thunderbolt fixes from Greg KH:
       "Here are some small USB and Thunderbolt driver fixes and new device
        ids for 6.4-rc7 to resolve some reported problems. Included in here
        are:
      
         - new USB serial device ids
      
         - USB gadget core fixes for long-dissussed problems
      
         - dwc3 bugfixes for reported issues.
      
         - typec driver fixes
      
         - thunderbolt driver fixes
      
        All of these have been in linux-next this week with no reported issues"
      
      * tag 'usb-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb:
        usb: gadget: udc: core: Prevent soft_connect_store() race
        usb: gadget: udc: core: Offload usb_udc_vbus_handler processing
        usb: typec: Fix fast_role_swap_current show function
        usb: typec: ucsi: Fix command cancellation
        USB: dwc3: fix use-after-free on core driver unbind
        USB: dwc3: qcom: fix NULL-deref on suspend
        usb: dwc3: gadget: Reset num TRBs before giving back the request
        usb: gadget: udc: renesas_usb3: Fix RZ/V2M {modprobe,bind} error
        USB: serial: option: add Quectel EM061KGL series
        thunderbolt: Mask ring interrupt on Intel hardware as well
        thunderbolt: Do not touch CL state configuration during discovery
        thunderbolt: Increase DisplayPort Connection Manager handshake timeout
        thunderbolt: dma_test: Use correct value for absent rings when creating paths
      670062e7
    • Linus Torvalds's avatar
      Merge tag 'tty-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty · 3c0eb442
      Linus Torvalds authored
      Pull serial driver fixes from Greg KH:
       "Here are two small serial driver fixes for 6.4-rc7 that resolve some
        reported problems:
      
         - lantiq serial driver irq fix
      
         - fsl_lpuart serial driver watermark fix
      
        Both of these have been in linux-next this week with no reported issues"
      
      * tag 'tty-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty:
        tty: serial: fsl_lpuart: reduce RX watermark to 0 on LS1028A
        serial: lantiq: add missing interrupt ack
      3c0eb442
  6. Jun 17, 2023
    • Ben Hutchings's avatar
      parisc: Delete redundant register definitions in <asm/assembly.h> · b5b2a02b
      Ben Hutchings authored
      
      
      We define sp and ipsw in <asm/asmregs.h> using ".reg", and when using
      current binutils (snapshot 2.40.50.20230611) the definitions in
      <asm/assembly.h> using "=" conflict with those:
      
      arch/parisc/include/asm/assembly.h: Assembler messages:
      arch/parisc/include/asm/assembly.h:93: Error: symbol `sp' is already defined
      arch/parisc/include/asm/assembly.h:95: Error: symbol `ipsw' is already defined
      
      Delete the duplicate definitions in <asm/assembly.h>.
      
      Also delete the definition of gp, which isn't used anywhere.
      
      Signed-off-by: default avatarBen Hutchings <benh@debian.org>
      Cc: stable@vger.kernel.org # v6.0+
      Signed-off-by: default avatarHelge Deller <deller@gmx.de>
      b5b2a02b
    • Linus Torvalds's avatar
      Merge tag 'clk-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux · c6cf6be9
      Linus Torvalds authored
      Pull clk fixes from Stephen Boyd:
       "A handful of clk driver fixes:
      
         - Fix an OOB issue in the Mediatek mt8365 driver where arrays of clks
           are mismatched in size
      
         - Use the proper clk_ops for a few clks in the Mediatek mt8365 driver
      
         - Stop using abs() in clk_composite_determine_rate() because 64-bit
           math goes wrong on large unsigned long numbers that are subtracted
           and passed into abs()
      
         - Zero initialize a struct clk_init_data in clk-loongson2 to avoid
           stack junk confusing clk_hw_register()
      
         - Actually use a pointer to __iomem for writel() in
           pxa3xx_clk_update_accr() so we don't oops"
      
      * tag 'clk-fixes-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/clk/linux:
        clk: pxa: fix NULL pointer dereference in pxa3xx_clk_update_accr
        clk: clk-loongson2: Zero init clk_init_data
        clk: mediatek: mt8365: Fix inverted topclk operations
        clk: composite: Fix handling of high clock rates
        clk: mediatek: mt8365: Fix index issue
      c6cf6be9
    • Linus Torvalds's avatar
      Merge tag 'drm-fixes-2023-06-17' of git://anongit.freedesktop.org/drm/drm · 1639fae5
      Linus Torvalds authored
      Pull drm fixes from Dave Airlie:
       "A bunch of misc fixes across the board.
      
        amdgpu is the usual bulk with a revert and other fixes, nouveau has a
        race fix that was causing a UAF that was hard hanging systems,
        otherwise some qaic, bridge and radeon.
      
        amdgpu:
         - GFX9 preemption fixes
         - Add missing radeon secondary PCI ID
         - vblflash fixes
         - SMU 13 fix
         - VCN 4.0 fix
         - Re-enable TOPDOWN flag for large BAR systems to fix regression
         - eDP fix
         - PSR hang fix
         - DPIA fix
      
        radeon:
         - fbdev client warning fix
      
        qaic:
         - leak fix
         - null ptr deref fix
      
        nouveau:
         - use-after-free caused by fence race fix
         - runtime pm fix
         - NULL ptr checks
      
        bridge:
         - ti-sn65dsi86: Avoid possible buffer overflow"
      
      * tag 'drm-fixes-2023-06-17' of git://anongit.freedesktop.org/drm/drm: (21 commits)
        nouveau: fix client work fence deletion race
        drm/amd/display: limit DPIA link rate to HBR3
        drm/amd/display: fix the system hang while disable PSR
        drm/amd/display: edp do not add non-edid timings
        Revert "drm/amdgpu: remove TOPDOWN flags when allocating VRAM in large bar system"
        drm/amdgpu: vcn_4_0 set instance 0 init sched score to 1
        drm/radeon: Disable outputs when releasing fbdev client
        drm/amd/pm: workaround for compute workload type on some skus
        drm/amd: Tighten permissions on VBIOS flashing attributes
        drm/amd: Make sure image is written to trigger VBIOS image update flow
        drm/amdgpu: add missing radeon secondary PCI ID
        drm/amdgpu: Implement gfx9 patch functions for resubmission
        drm/amdgpu: Modify indirect buffer packages for resubmission
        drm/amdgpu: Program gds backup address as zero if no gds allocated
        drm/nouveau: add nv_encoder pointer check for NULL
        drm/amdgpu: Reset CP_VMID_PREEMPT after trailing fence signaled
        drm/nouveau/dp: check for NULL nv_connector->native_mode
        drm/bridge: ti-sn65dsi86: Avoid possible buffer overflow
        drm/nouveau: don't detect DSM for non-NVIDIA device
        accel/qaic: Fix NULL pointer deref in qaic_destroy_drm_device()
        ...
      1639fae5
    • David Howells's avatar
      afs: Fix vlserver probe RTT handling · ba00b190
      David Howells authored
      In the same spirit as commit ca57f022 ("afs: Fix fileserver probe
      RTT handling"), don't rule out using a vlserver just because there
      haven't been enough packets yet to calculate a real rtt.  Always set the
      server's probe rtt from the estimate provided by rxrpc_kernel_get_srtt,
      which is capped at 1 second.
      
      This could lead to EDESTADDRREQ errors when accessing a cell for the
      first time, even though the vl servers are known and have responded to a
      probe.
      
      Fixes: 1d4adfaf
      
       ("rxrpc: Make rxrpc_kernel_get_srtt() indicate validity")
      Signed-off-by: default avatarMarc Dionne <marc.dionne@auristor.com>
      Signed-off-by: default avatarDavid Howells <dhowells@redhat.com>
      cc: linux-afs@lists.infradead.org
      Link: http://lists.infradead.org/pipermail/linux-afs/2023-June/006746.html
      
      
      Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
      ba00b190
    • Dave Airlie's avatar
      Merge tag 'drm-misc-fixes-2023-06-16' of git://anongit.freedesktop.org/drm/drm-misc into drm-fixes · 9930f518
      Dave Airlie authored
      
      
      drm-misc-fixes maybe in time for v6.4-rc7:
      - qaic leak and null deref fix.
      - Fix runtime pm in nouveau.
      - Fix array overflow in ti-sn65dsi86 pwm chip handling.
      - Assorted null check fixes in nouveau.
      
      Signed-off-by: default avatarDave Airlie <airlied@redhat.com>
      From: Maarten Lankhorst <dev@lankhorst.se>
      Link: https://patchwork.freedesktop.org/patch/msgid/641eb8a8-fbd7-90ad-0805-310b7fec9344@lankhorst.se
      9930f518
    • Linus Torvalds's avatar
      Merge tag 'for-6.4-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux · 4973ca29
      Linus Torvalds authored
      Pull btrfs fixes from David Sterba:
       "Two fixes for NOCOW files, a regression fix in scrub and an assertion
        fix:
      
         - NOCOW fixes:
            - keep length of iomap direct io request in case of a failure
            - properly pass mode of extent reference checking, this can break
              some cases for swapfile
      
         - fix error value confusion when scrubbing a stripe
      
         - convert assertion to a proper error handling when loading global
           roots, reported by syzbot"
      
      * tag 'for-6.4-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux:
        btrfs: scrub: fix a return value overwrite in scrub_stripe()
        btrfs: do not ASSERT() on duplicated global roots
        btrfs: can_nocow_file_extent should pass down args->strict from callers
        btrfs: fix iomap_begin length for nocow writes
      4973ca29
    • Linus Torvalds's avatar
      Merge tag 'block-6.4-2023-06-15' of git://git.kernel.dk/linux · b9c1133a
      Linus Torvalds authored
      Pull block fix from Jens Axboe:
       "Just a single fix for blk-cg stats flushing"
      
      * tag 'block-6.4-2023-06-15' of git://git.kernel.dk/linux:
        blk-cgroup: Flush stats before releasing blkcg_gq
      b9c1133a
    • Linus Torvalds's avatar
      Merge tag 'io_uring-6.4-2023-06-15' of git://git.kernel.dk/linux · 3a12faba
      Linus Torvalds authored
      Pull io_uring fixes from Jens Axboe:
       "A fix for sendmsg with CMSG, and the followup fix discussed for
        avoiding touching task->worker_private after the worker has started
        exiting"
      
      * tag 'io_uring-6.4-2023-06-15' of git://git.kernel.dk/linux:
        io_uring/io-wq: clear current->worker_private on exit
        io_uring/net: save msghdr->msg_control for retries
      3a12faba
    • Linus Torvalds's avatar
      Merge tag 'sound-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound · b4af6821
      Linus Torvalds authored
      Pull sound fixes from Takashi Iwai:
       "Just a few small fixes. The only change to the core code is for a
        minor race in ALSA OSS sequencer, and the rest are all device-specific
        fixes (regression fixes and a usual quirk)"
      
      * tag 'sound-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai/sound:
        ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback
        ALSA: usb-audio: Fix broken resume due to UAC3 power state
        ALSA: seq: oss: Fix racy open/close of MIDI devices
        ASoC: tegra: Fix Master Volume Control
        ALSA: hda/realtek: Add a quirk for Compaq N14JP6
        firmware: cs_dsp: Log correct region name in bin error messages
      b4af6821
    • Linus Torvalds's avatar
      Merge tag 'urgent-rcu.2023.06.11a' of... · b73056e9
      Linus Torvalds authored
      Merge tag 'urgent-rcu.2023.06.11a' of git://git.kernel.org/pub/scm/linux/kernel/git/paulmck/linux-rcu
      
      Pull RCU fix from Paul McKenney:
       "This fixes a spinlock-initialization regression in SRCU that causes
        the SRCU notifier to fail.
      
        The fix simply adds the initialization, but introduces a #ifdef
        because there is no spinlock to initialize for the Tiny SRCU used in
        !SMP builds.
      
        Yes, it would be nice to abstract this somehow in order to hide it in
        SRCU, but I still don't see a good way of doing this"
      
      * tag 'urgent-rcu.2023.06.11a' of git://git.kernel.org/pub/scm/linux/kernel/git/paulmck/linux-rcu:
        notifier: Initialize new struct srcu_usage field
      b73056e9
    • Linus Torvalds's avatar
      Merge tag 'riscv-for-linus-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux · f4fd69a3
      Linus Torvalds authored
      Pull RISC-V fix from Palmer Dabbelt:
      
       - A documentation patch describing how we use patchwork
      
      * tag 'riscv-for-linus-6.4-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/riscv/linux:
        Documentation: RISC-V: patch-acceptance: mention patchwork's role
      f4fd69a3
  7. Jun 16, 2023