Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
b609915
io_uring/net: Avoid msghdr on op_connect/op_bind async data
krisman Jun 17, 2026
29706ac
net: stmmac: fix stm32 (and potentially others) resume regression
Jan 30, 2026
af28922
fuse: re-lock request before replacing page cache folio
joannekoong May 19, 2026
95f9eb1
Revert "NFSD: Defer sub-object cleanup in export put callbacks"
May 13, 2026
a460935
debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
Jun 22, 2026
9cd2087
debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
Jun 22, 2026
3a408ca
debugobjects: Do not fill_pool() if pi_blocked_on
helen-fornazier Jun 22, 2026
44b8b03
debugobjects: Dont call fill_pool() in early boot hardirq context
Waiman-Long Jun 22, 2026
e2b143d
RDMA/bnxt_re: zero shared page before exposing to userspace
L0rdS474n May 9, 2026
5f4d2bd
i2c: stub: Reject I2C block transfers with invalid length
winmin Apr 14, 2026
8b17adf
net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
winmin May 14, 2026
53483a9
agp/amd64: Fix broken error propagation in agp_amd64_probe()
Wmingyu May 4, 2026
19b3691
ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
Jun 24, 2026
7dac298
rose: fix dev_put() leak in rose_loopback_timer()
f6bvp May 16, 2026
fe8cbcc
rose: hold loopback neighbour reference across timer callback
f6bvp May 16, 2026
940f39e
rose: fix race between loopback timer and module removal
f6bvp May 16, 2026
270ef70
rose: clear neighbour pointer after rose_neigh_put() in state machines
f6bvp May 16, 2026
1d94857
rose: guard rose_neigh_put() against NULL in timer expiry
f6bvp May 16, 2026
1913902
rose: fix netdev double-hold in rose_rx_call_request()
f6bvp May 26, 2026
c98cc00
rose: fix notifier unregistered too early in rose_exit()
f6bvp May 26, 2026
ab849a6
rose: set SOCK_DESTROY in rose_kill_by_device() for prompt cleanup
f6bvp May 27, 2026
ce27bcd
rose: disconnect orphaned STATE_2 sockets when device is gone
f6bvp May 28, 2026
c794d35
rose: fix netdev double-hold in rose_make_new()
f6bvp May 28, 2026
74cbe94
rose: release netdev ref and destroy orphaned incoming sockets
f6bvp May 28, 2026
c31a0fa
rose: drop CALL_REQUEST in loopback timer when device is not running
f6bvp May 28, 2026
9e8fc21
rose: cancel neighbour timers in rose_neigh_put() before freeing
f6bvp May 31, 2026
395b657
rose: clear neighbour pointer in rose_kill_by_device()
f6bvp May 31, 2026
9477cbc
rose: don't free fd-owned sockets when reaping in the heartbeat
f6bvp May 31, 2026
bde74af
regulator: core: fix locking in regulator_resolve_supply() error path
andred Jan 9, 2026
072bbd2
hv: utils: handle and propagate errors in kvp_register
toblux Jun 16, 2026
02ac3ba
Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
dcui Jun 16, 2026
eee6be6
firmware: samsung: acpm: Fix cross-thread RX length corruption
ambarus Jun 17, 2026
0de7db2
sctp: disable BH before calling udp_tunnel_xmit_skb()
lxin Jun 25, 2026
efce8a4
mm: introduce VM_MAYBE_GUARD and make visible in /proc/$pid/smaps
ljskernel May 15, 2026
bdeadba
mm: add atomic VMA flags and set VM_MAYBE_GUARD as such
ljskernel May 15, 2026
a093c80
mm: update vma_modify_flags() to handle residual flags, document
ljskernel May 15, 2026
05cdec2
mm: implement sticky VMA flags
ljskernel May 15, 2026
3d6cb2e
mm: introduce copy-on-fork VMAs and make VM_MAYBE_GUARD one
ljskernel May 15, 2026
b836839
mm: set the VM_MAYBE_GUARD flag on guard region install
ljskernel May 15, 2026
f563ce9
mm: propagate VM_SOFTDIRTY on merge
ljskernel May 15, 2026
cc1494f
testing/selftests/mm: add soft-dirty merge self-test
ljskernel May 15, 2026
c5b3871
net: export netif_open for self_test usage
mmarcini Mar 7, 2026
76db054
net: net_failover: Fix the deadlock in slave register
faicker May 11, 2026
0a89002
iio: light: veml6075: add bounds check to veml6075_it_ms index
May 14, 2026
d08d82d
iio: adc: ti-ads1298: add bounds check to pga_settings index
May 14, 2026
b8ebf00
crypto: qat - remove unused character device and IOCTLs
gcabiddu May 11, 2026
7cc3dd7
vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs…
Jun 4, 2026
50b7207
serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
vdadhani May 28, 2026
6c25bf4
drivers/base/memory: set mem->altmap after successful device registra…
May 14, 2026
7cad3ce
ksmbd: reject non-VALID session in compound request branch
dhkts1 Jun 11, 2026
f965cf2
media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
norus Mar 17, 2026
2abfd3f
virtiofs: fix UAF on submount umount
May 28, 2026
71003a3
mm: do not copy page tables unnecessarily for VM_UFFD_WP
ljskernel Jan 14, 2026
0c503cf
Linux 6.18.37
gregkh Jun 27, 2026
90a16cd
Merge tag 'v6.18.37' into linux-6.18.y-rt
Jun 29, 2026
868deef
ARM: Fixup the stable merge.
Jun 29, 2026
a3c2a80
v6.18.37-rt6
Jun 29, 2026
043b43c
Merge latest upstream v6.18.37-rt6
jatinjb444 Aug 13, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions Documentation/filesystems/proc.rst
Original file line number Diff line number Diff line change
Expand Up @@ -553,7 +553,7 @@ otherwise.
kernel flags associated with the particular virtual memory area in two letter
encoded manner. The codes are the following:

== =======================================
== =============================================================
rd readable
wr writeable
ex executable
Expand Down Expand Up @@ -591,7 +591,8 @@ encoded manner. The codes are the following:
sl sealed
lf lock on fault pages
dp always lazily freeable mapping
== =======================================
gu maybe contains guard regions (if not set, definitely doesn't)
== =============================================================

Note that there is no guarantee that every flag and associated mnemonic will
be present in all further kernel releases. Things get changed, the flags may
Expand Down
1 change: 0 additions & 1 deletion Documentation/userspace-api/ioctl/ioctl-number.rst
Original file line number Diff line number Diff line change
Expand Up @@ -229,7 +229,6 @@ Code Seq# Include File Comments
<mailto:gregkh@linuxfoundation.org>
'a' all linux/atm*.h, linux/sonet.h ATM on linux
<http://lrcwww.epfl.ch/>
'a' 00-0F drivers/crypto/qat/qat_common/adf_cfg_common.h conflict! qat driver
'b' 00-FF conflict! bit3 vme host bridge
<mailto:natalia@nikhefk.nikhef.nl>
'b' 00-0F linux/dma-buf.h conflict!
Expand Down
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 6
PATCHLEVEL = 18
SUBLEVEL = 36
SUBLEVEL = 37
EXTRAVERSION =
NAME = Baby Opossum Posse

Expand Down
19 changes: 8 additions & 11 deletions arch/arm/mm/fault.c
Original file line number Diff line number Diff line change
Expand Up @@ -190,14 +190,17 @@ __do_kernel_fault(struct mm_struct *mm, unsigned long addr, unsigned int fsr,

/*
* Something tried to access memory that isn't in our memory map..
* User mode accesses just cause a SIGSEGV
* User mode accesses just cause a SIGSEGV. Ensure interrupts are enabled
* for preempt RT.
*/
static void
__do_user_fault(unsigned long addr, unsigned int fsr, unsigned int sig,
int code, struct pt_regs *regs)
{
struct task_struct *tsk = current;

local_irq_enable();

#ifdef CONFIG_DEBUG_USER
if (((user_debug & UDBG_SEGV) && (sig == SIGSEGV)) ||
((user_debug & UDBG_BUS) && (sig == SIGBUS))) {
Expand Down Expand Up @@ -230,14 +233,10 @@ void do_bad_area(unsigned long addr, unsigned int fsr, struct pt_regs *regs)
* If we are in kernel mode at this point, we
* have no context to handle this fault with.
*/
if (user_mode(regs)) {
if (addr >= TASK_SIZE)
harden_branch_predictor();
local_irq_enable();
if (user_mode(regs))
__do_user_fault(addr, fsr, SIGSEGV, SEGV_MAPERR, regs);
} else {
else
__do_kernel_fault(mm, addr, fsr, regs);
}
}

#ifdef CONFIG_MMU
Expand Down Expand Up @@ -272,6 +271,7 @@ do_kernel_address_page_fault(struct mm_struct *mm, unsigned long addr,
* should not be faulting in kernel space, which includes the
* vector/khelper page. Handle the branch predictor hardening
* while interrupts are still disabled, then send a SIGSEGV.
* Note that __do_user_fault() will enable interrupts.
*/
harden_branch_predictor();
__do_user_fault(addr, fsr, SIGSEGV, SEGV_MAPERR, regs);
Expand Down Expand Up @@ -314,11 +314,8 @@ do_page_fault(unsigned long addr, unsigned int fsr, struct pt_regs *regs)
return do_kernel_address_page_fault(mm, addr, fsr, regs);

/* Enable interrupts if they were enabled in the parent context. */
if (interrupts_enabled(regs)) {
if (user_mode(regs) && addr >= TASK_SIZE)
harden_branch_predictor();
if (interrupts_enabled(regs))
local_irq_enable();
}

/*
* If we're in an interrupt or have no user
Expand Down
41 changes: 15 additions & 26 deletions drivers/acpi/scan.c
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@

#define pr_fmt(fmt) "ACPI: " fmt

#include <linux/async.h>
#include <linux/module.h>
#include <linux/init.h>
#include <linux/slab.h>
Expand Down Expand Up @@ -2360,46 +2361,34 @@ static int acpi_dev_get_next_consumer_dev_cb(struct acpi_dep_data *dep, void *da
return 0;
}

struct acpi_scan_clear_dep_work {
struct work_struct work;
struct acpi_device *adev;
};

static void acpi_scan_clear_dep_fn(struct work_struct *work)
static void acpi_scan_clear_dep_fn(void *dev, async_cookie_t cookie)
{
struct acpi_scan_clear_dep_work *cdw;

cdw = container_of(work, struct acpi_scan_clear_dep_work, work);
struct acpi_device *adev = to_acpi_device(dev);

acpi_scan_lock_acquire();
acpi_bus_attach(cdw->adev, (void *)true);
acpi_bus_attach(adev, (void *)true);
acpi_scan_lock_release();

acpi_dev_put(cdw->adev);
kfree(cdw);
acpi_dev_put(adev);
}

static bool acpi_scan_clear_dep_queue(struct acpi_device *adev)
{
struct acpi_scan_clear_dep_work *cdw;

if (adev->dep_unmet)
return false;

cdw = kmalloc(sizeof(*cdw), GFP_KERNEL);
if (!cdw)
return false;

cdw->adev = adev;
INIT_WORK(&cdw->work, acpi_scan_clear_dep_fn);
/*
* Since the work function may block on the lock until the entire
* initial enumeration of devices is complete, put it into the unbound
* workqueue.
* Async schedule the deferred acpi_scan_clear_dep_fn() since:
* - acpi_bus_attach() needs to hold acpi_scan_lock which cannot
* be acquired under acpi_dep_list_lock (held here)
* - the deferred work at boot stage is ensured to be finished
* before userspace init task by the async_synchronize_full()
* barrier
*
* Use _nocall variant since it'll return on failure instead of
* run the function synchronously.
*/
queue_work(system_unbound_wq, &cdw->work);

return true;
return async_schedule_dev_nocall(acpi_scan_clear_dep_fn, &adev->dev);
}

static void acpi_scan_delete_dep_data(struct acpi_dep_data *dep)
Expand Down
3 changes: 2 additions & 1 deletion drivers/base/memory.c
Original file line number Diff line number Diff line change
Expand Up @@ -828,7 +828,6 @@ static int add_memory_block(unsigned long block_id, int nid, unsigned long state
mem->start_section_nr = block_id * sections_per_block;
mem->state = state;
mem->nid = nid;
mem->altmap = altmap;
INIT_LIST_HEAD(&mem->group_next);

#ifndef CONFIG_NUMA
Expand All @@ -846,6 +845,8 @@ static int add_memory_block(unsigned long block_id, int nid, unsigned long state
if (ret)
return ret;

mem->altmap = altmap;

if (group) {
mem->group = group;
list_add(&mem->group_next, &group->memory_blocks);
Expand Down
2 changes: 1 addition & 1 deletion drivers/char/agp/amd64-agp.c
Original file line number Diff line number Diff line change
Expand Up @@ -546,7 +546,7 @@ static int agp_amd64_probe(struct pci_dev *pdev,
/* Fill in the mode register */
pci_read_config_dword(pdev, bridge->capndx+PCI_AGP_STATUS, &bridge->mode);

if (cache_nbs(pdev, cap_ptr) == -1) {
if (cache_nbs(pdev, cap_ptr) < 0) {
agp_put_bridge(bridge);
return -ENODEV;
}
Expand Down
10 changes: 0 additions & 10 deletions drivers/crypto/intel/qat/qat_common/adf_cfg.c
Original file line number Diff line number Diff line change
Expand Up @@ -103,16 +103,6 @@ static void adf_cfg_section_del_all(struct list_head *head);
static void adf_cfg_section_del_all_except(struct list_head *head,
const char *section_name);

void adf_cfg_del_all(struct adf_accel_dev *accel_dev)
{
struct adf_cfg_device_data *dev_cfg_data = accel_dev->cfg;

down_write(&dev_cfg_data->lock);
adf_cfg_section_del_all(&dev_cfg_data->sec_list);
up_write(&dev_cfg_data->lock);
clear_bit(ADF_STATUS_CONFIGURED, &accel_dev->status);
}

void adf_cfg_del_all_except(struct adf_accel_dev *accel_dev,
const char *section_name)
{
Expand Down
1 change: 0 additions & 1 deletion drivers/crypto/intel/qat/qat_common/adf_cfg.h
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,6 @@ void adf_cfg_dev_remove(struct adf_accel_dev *accel_dev);
void adf_cfg_dev_dbgfs_add(struct adf_accel_dev *accel_dev);
void adf_cfg_dev_dbgfs_rm(struct adf_accel_dev *accel_dev);
int adf_cfg_section_add(struct adf_accel_dev *accel_dev, const char *name);
void adf_cfg_del_all(struct adf_accel_dev *accel_dev);
void adf_cfg_del_all_except(struct adf_accel_dev *accel_dev,
const char *section_name);
int adf_cfg_add_key_value_param(struct adf_accel_dev *accel_dev,
Expand Down
32 changes: 0 additions & 32 deletions drivers/crypto/intel/qat/qat_common/adf_cfg_common.h
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,11 @@
#define ADF_CFG_COMMON_H_

#include <linux/types.h>
#include <linux/ioctl.h>

#define ADF_CFG_MAX_STR_LEN 64
#define ADF_CFG_MAX_KEY_LEN_IN_BYTES ADF_CFG_MAX_STR_LEN
#define ADF_CFG_MAX_VAL_LEN_IN_BYTES ADF_CFG_MAX_STR_LEN
#define ADF_CFG_MAX_SECTION_LEN_IN_BYTES ADF_CFG_MAX_STR_LEN
#define ADF_CFG_BASE_DEC 10
#define ADF_CFG_BASE_HEX 16
#define ADF_CFG_ALL_DEVICES 0xFE
#define ADF_CFG_NO_DEVICE 0xFF
#define ADF_CFG_AFFINITY_WHATEVER 0xFF
#define MAX_DEVICE_NAME_SIZE 32
#define ADF_MAX_DEVICES (32 * 32)
#define ADF_DEVS_ARRAY_SIZE BITS_TO_LONGS(ADF_MAX_DEVICES)

Expand Down Expand Up @@ -51,29 +44,4 @@ enum adf_device_type {
DEV_420XX,
DEV_6XXX,
};

struct adf_dev_status_info {
enum adf_device_type type;
__u32 accel_id;
__u32 instance_id;
__u8 num_ae;
__u8 num_accel;
__u8 num_logical_accel;
__u8 banks_per_accel;
__u8 state;
__u8 bus;
__u8 dev;
__u8 fun;
char name[MAX_DEVICE_NAME_SIZE];
};

#define ADF_CTL_IOC_MAGIC 'a'
#define IOCTL_CONFIG_SYS_RESOURCE_PARAMETERS _IOW(ADF_CTL_IOC_MAGIC, 0, \
struct adf_user_cfg_ctl_data)
#define IOCTL_STOP_ACCEL_DEV _IOW(ADF_CTL_IOC_MAGIC, 1, \
struct adf_user_cfg_ctl_data)
#define IOCTL_START_ACCEL_DEV _IOW(ADF_CTL_IOC_MAGIC, 2, \
struct adf_user_cfg_ctl_data)
#define IOCTL_STATUS_ACCEL_DEV _IOW(ADF_CTL_IOC_MAGIC, 3, __u32)
#define IOCTL_GET_NUM_DEVICES _IOW(ADF_CTL_IOC_MAGIC, 4, __s32)
#endif
38 changes: 0 additions & 38 deletions drivers/crypto/intel/qat/qat_common/adf_cfg_user.h

This file was deleted.

3 changes: 0 additions & 3 deletions drivers/crypto/intel/qat/qat_common/adf_common_drv.h
Original file line number Diff line number Diff line change
Expand Up @@ -68,10 +68,7 @@ int adf_devmgr_add_dev(struct adf_accel_dev *accel_dev,
void adf_devmgr_rm_dev(struct adf_accel_dev *accel_dev,
struct adf_accel_dev *pf);
struct list_head *adf_devmgr_get_head(void);
struct adf_accel_dev *adf_devmgr_get_dev_by_id(u32 id);
struct adf_accel_dev *adf_devmgr_pci_to_accel_dev(struct pci_dev *pci_dev);
int adf_devmgr_verify_id(u32 id);
void adf_devmgr_get_num_dev(u32 *num);
int adf_devmgr_in_reset(struct adf_accel_dev *accel_dev);
int adf_dev_started(struct adf_accel_dev *accel_dev);
int adf_dev_restarting_notify(struct adf_accel_dev *accel_dev);
Expand Down
Loading
Loading