<feed xmlns='http://www.w3.org/2005/Atom'>
<title>wireguard-linux/include/linux, branch stable</title>
<subtitle>WireGuard for the Linux kernel</subtitle>
<id>https://git.zx2c4.com/wireguard-linux/atom/include/linux?h=stable</id>
<link rel='self' href='https://git.zx2c4.com/wireguard-linux/atom/include/linux?h=stable'/>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/'/>
<updated>2026-10-01T13:41:59Z</updated>
<entry>
<title>Merge tag 'net-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net</title>
<updated>2026-10-01T13:41:59Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-01T13:41:59Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=d24e8ac715de2e16a53c144005b1863660a5fbea'/>
<id>urn:sha1:d24e8ac715de2e16a53c144005b1863660a5fbea</id>
<content type='text'>
Pull networking fixes from Paolo Abeni:
 "Including fixes from Bluetooth, WiFi and netfilter.

  We are actively retargeting several non-urgent fixes towards next,
  but the traffic on the ML looks ever-increasing, and propagating the
  push-back towards subsystems is not immediate.

  No known outstanding regressions.

  Current release - regressions:

   - netfilter: nft_set_rbtree: skip transaction elements during GC

  Previous releases - regressions:

   - sched: cls_api: reclaim an empty proto on the error path

   - core:
      - fix checksum offsets in skb_splice_from_iter()
      - cap skb-&gt;queue_mapping when the tx queue is picked

   - page_pool: fix use-after-free in page_pool_recycle_ring_bulk()

   - wifi:
      - mac80211: fix slab-out-of-bounds read in ieee80211_monitor_select_queue()
      - mac80211: drop oversized fragments to avoid extra_len overflow

   - netfilter:
      - flowtable: restore ieee80211 forward path

   - bluetooth: hci_conn: Lock parent access during enhanced SCO setup

   - eth:
      - bcmgenet: allocate RX buffers as page fragments
      - stmmac: fix rx Scatter-Gather support
      - octeontx2-pf: fix aura BPID assignment when CONFIG_DCB is enabled
      - gve: DQO: accept TSO packets with non-protocol gso_type bits
      - r8169: disable EEE on RTL8168h/8111h

  Previous releases - always broken:

   - tcp: refresh TS.Recent for accepted old ACKs

   - wifi:
      - ath11k: reset ar-&gt;num_stations on hardware start
      - cfg80211: fix RTS threshold setting for single-radio PHY

   - bluetooth: btintel_pcie: fix plen overflow in btintel_pcie_recv_frame()

   - eth: bcmgenet: fix NULL dereference in set_coalesce before first open

  Misc:
   - Eric is retiring from google and updating his contact info"

* tag 'net-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net: (96 commits)
  net: phy: aquantia: fix system interface type not updated in forced mode
  net: usb: qmi_wwan: add Rolling Wireless RN947R
  net: mvneta: clear XDP pfmemalloc flag between frames
  ipv6: sr: use skb_get_hash_net() in seg6_make_flowlabel()
  net/mlx5e: Fix AF_XDP TX timestamp teardown NULL dereference
  r8169: disable EEE on RTL8168h/8111h
  octeontx2-pf: Fix RSS indirection table size
  sctp: check RCV_SHUTDOWN after the sendmsg connect wait
  net: sparx5: make ports inherit the switch base mac address type
  net: microchip: vcap: stop scanning after deleting key field
  netfilter: flowtable: restore ieee80211 forward path
  netfilter: flowtable: generalize pending status bit
  netfilter: bpf: reject invalid NAT manipulation types
  netfilter: nft_set_rbtree: skip transaction elements during GC
  ipvs: filter some flags received in the backup server
  ipvs: do not create invisible templates
  ipvs: bound LBLCR and LBLC cache growth
  ipvs: fix missing counter decrement in lblc
  netfilter: nft_flow_offload: drop flowtable reference on init error path
  selftests: net: check timestamp echo after an old ACK
  ...
</content>
</entry>
<entry>
<title>Merge tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf</title>
<updated>2026-10-01T10:00:40Z</updated>
<author>
<name>Paolo Abeni</name>
<email>pabeni@redhat.com</email>
</author>
<published>2026-10-01T10:00:40Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=e23a64eb244356ee47c0620f0722d51bd88db522'/>
<id>urn:sha1:e23a64eb244356ee47c0620f0722d51bd88db522</id>
<content type='text'>
Pablo Neira Ayuso says:

====================
Netfilter/IPVS fixes for net

The following batch contains Netfilter fixes for net. This batch
fixes crashes as recent feature regression, one of the due to a
dependency that has been pulled into -stable:

1) Expand existing ipset fix for bitmap sets to disallow comments
   updates from kernel-side adds, from Florian Westphal.

2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise
   flowtable cannot ever be removed, from Aohan Mei.

3) nft_rbtree GC should collect end elements that contained in
   this transaction batch, new or deleted elements are never
   expired. From Weiming Shi.

4) Restrict nf_nat_bpf so it does not set unknown NF_NAT_MANIP_*
   values, from Fernando F. Mancera.

5) Flowtable GC must skip flows that are pending hardware updates,
   generalize the PENDING flag and use it to inhibit GC.

6) Restore flowtable with ieee80211 which broke due to a relatively
   recent commit, which was pulled in by -stable, causing a regression
   in 6.18 kernels.

And the following IPVS fixes:

1) Fix accounting of cache entries in IPVS LBLC for destinations,
   which eventually fills up the table and trigger recurrent
   resizing, from Julian Anastasov.

2) Limit IPVS cache growth for LBLCR and LBLC schedulers,
   from Zhiling Zou.

3) Restrict IP_VS_CONN_F_ONE_PACKET for normal connections,
   do not allow to use it with templates. Also from Julian.

4) Sanitize flags in IPVS sync messages received in the backup.
   From Julian Anastasov.

netfilter pull request 26-09-30

* tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:
  netfilter: flowtable: restore ieee80211 forward path
  netfilter: flowtable: generalize pending status bit
  netfilter: bpf: reject invalid NAT manipulation types
  netfilter: nft_set_rbtree: skip transaction elements during GC
  ipvs: filter some flags received in the backup server
  ipvs: do not create invisible templates
  ipvs: bound LBLCR and LBLC cache growth
  ipvs: fix missing counter decrement in lblc
  netfilter: nft_flow_offload: drop flowtable reference on init error path
  netfilter: ipset: do not update comments from kernel-side adds
====================

Link: https://patch.msgid.link/20260930074142.298353-1-pablo@netfilter.org
Signed-off-by: Paolo Abeni &lt;pabeni@redhat.com&gt;
</content>
</entry>
<entry>
<title>netfilter: flowtable: restore ieee80211 forward path</title>
<updated>2026-09-30T07:35:20Z</updated>
<author>
<name>Pablo Neira Ayuso</name>
<email>pablo@netfilter.org</email>
</author>
<published>2026-09-23T18:46:18Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=3ae37eafd36694bb2d3227f60ac98fbf602470a2'/>
<id>urn:sha1:3ae37eafd36694bb2d3227f60ac98fbf602470a2</id>
<content type='text'>
Before commit 871df5007eda ("netfilter: flowtable: bail out if forward
path cannot be discovered"), there was a fallback to set up a forward
path in case .ndo_fill_forward_path fails or DEV_PATH_MTK_WDMA was used.
Such fallback was used by commit d787a3e38f01 ("mac80211: add support
for .ndo_fill_forward_path").

One possibility is to handle DEV_PATH_MTK_WDMA from the flowtable
forward path discovery. However, this is only used internally by drivers
to retrieve mtk_wdma information to set up hardware offload. Felix
decided to use the .fill_forward_path interface for this purpose due to
the lack of a better interface at that time.

Add a new DEV_PATH_IEEE80211 path which is offered if the new ieee80211
flag is set on in the struct net_device_path_ctx to restore the
flowtable with a ieee80211 netdevice. Handle this new DEV_PATH_IEEE80211
path just like DEV_PATH_ETHERNET and DEV_PATH_DSA, ie. this is the last
netdevice in the stack.

This new ieee80211 flag is implicitly unset for mtk_ppe and airoha which
call dev_fill_forward_path() to retrieve a DEV_PATH_MTK_WDMA path.

Fixes: 871df5007eda ("netfilter: flowtable: bail out if forward path cannot be discovered")
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</content>
</entry>
<entry>
<title>net: cap skb-&gt;queue_mapping when the tx queue is picked</title>
<updated>2026-09-30T00:49:35Z</updated>
<author>
<name>Jamal Hadi Salim</name>
<email>jhs@mojatatu.com</email>
</author>
<published>2026-09-28T12:46:16Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=ea4d4b5dddb5121e64f56fd8e0720bd8b447b63d'/>
<id>urn:sha1:ea4d4b5dddb5121e64f56fd8e0720bd8b447b63d</id>
<content type='text'>
skbedit can set skb-&gt;queue_mapping and raise the per-CPU skip_txqueue
flag so __dev_queue_xmit() honours the mapping. __dev_queue_xmit()
cleared the flag before sch_handle_egress() and only read it afterwards,
so the flag was not confined to the xmit that set it: a nested xmit
(mirred redirect or mirror, or a drop after skbedit) could set the flag
and the outer xmit would consume it for an skb that never went through
skbedit.

A forwarded packet still carries the ingress NIC's rx_queue + 1 in
skb-&gt;queue_mapping, so the outer device then indexes its tx queue state
with that stale value. Taprio's child array q-&gt;qdiscs[] is sized to the
device's queue count, so taprio_enqueue() indexes past its allocation
and dereferences the result as a struct Qdisc *.

We (ab)use the skb-&gt;nf_skip_egress which means "skip netfilter egress
for this packet" to tag to "am I in tc egress?". Despite the overload
I dont see it as a conflict since the marker is set only around the
single sch_handle_egress() call and ingress path is guarded by
tc_at_ingress.
I will send a followup(net-next) patch once this hits net-next to
rename the skb-&gt;nf_skip_egress bit/flag to skb-&gt;skip_egress

Arm the flag only from the egress classifier that can use it: raise
skip_txqueue from tcf_skbedit_act() only when it runs inside
sch_handle_egress(), thanks to skb-&gt;nf_skip_egress. An egress qdisc
classifier runs in q-&gt;enqueue(), after the tx queue has been picked,
so a mapping it sets cannot affect the current packet; arming the flag
there only pollutes it for a later xmit. Then own the flag for the xmit
frame the egress hook runs in: save the incoming value and clear it just
before sch_handle_egress(), and restore it after the hook - on the
consumed (drop) path, or, in the same call that reads it, on the
surviving path. The save and the restores stay inside the
egress_needed_key static branch, so a packet pays for them only when
egress hooks are active (2f1e85b1aee4).

Store the value netdev_cap_txqueue() selected back into skb-&gt;queue_mapping
in netdev_tx_queue_mapping(), as netdev_core_pick_tx() already does, so
the skip_txqueue path never hands a later reader on the xmit path a
mapping the device cannot serve. A store made still later in the same
frame, by a tc BPF program attached to a transmit qdisc, is outside this
path and is not re-capped; a separate followup will resolve that path.

netdev_xmit_skip_txqueue() returns the previous flag value so the
save-and-clear is one call, and a no-op stub is provided when
CONFIG_NET_EGRESS is disabled. skb-&gt;nf_skip_egress is compiled under
CONFIG_NET_EGRESS rather than CONFIG_NETFILTER_SKIP_EGRESS, so
skb_at_tc_egress() is valid whenever the egress path is built.

A local user in a network namespace can redirect a packet from a device
with more TX queues to one with fewer after setting a mapping valid only
on the larger device. That reaches these reads and, under KASAN, faults
with "slab-out-of-bounds in taprio_enqueue".

Conditions to recreate the bug: the report's own trigger is a local user
with CAP_NET_ADMIN in a network namespace, so no eBPF program is needed.
With CONFIG_NET_SCH_TAPRIO=y, CONFIG_NET_ACT_SKBEDIT=y,
CONFIG_NET_ACT_MIRRED=y, CONFIG_NET_CLS_MATCHALL=y,
CONFIG_NET_SCH_PRIO=y and KASAN enabled, create qa (3 queues), qb
(2 queues) and qc (1 queue) as dummy devices; put a taprio root on qb
(num_tc 1, queues 2@0) and clsact on all three; then add an egress
matchall filter on every device. On qa: "action skbedit queue_mapping 2
pipe action mirred egress redirect dev qb". On qb: "action mirred egress
mirror dev qc". On qc: "action skbedit queue_mapping 0 pipe". Send one
packet out qa. qc's skbedit sets the flag while qb's outer xmit is in
flight; without the fix qb consumes it and reads its two-entry taprio
child array with the forwarded packet's stale mapping. A qc whose
skbedit is instead installed in a transmit-qdisc classifier (a matchall
filter on the qc root qdisc) reaches the same code path the same way
without the fix.

Testing: on a KASAN build with panic_on_warn=1 the unfixed kernel panics
with "BUG: KASAN: slab-out-of-bounds in taprio_enqueue", a read 0 bytes
past a 16-byte taprio_init() allocation, for the clsact-setter and the
transmit-qdisc-classifier reproducers and for a clsact skbedit-then-tc-BPF
store; the fixed kernel runs all three with no report, and the BPF store
variant additionally shows the expected "selects TX queue" clamp notice
from the write-back.

Fixes: 2f1e85b1aee4 ("net: sched: use queue_mapping to pick tx queue")
Reported-by: Zero Day Initiative &lt;zdi-disclosures@trendmicro.com&gt;
Link: https://lore.kernel.org/netdev/CANn89iLwYx8nCVf0pCEk_MmEiyC6kQaMwCQT9WkQVeeNzNQHqQ@mail.gmail.com/
Link: https://lore.kernel.org/netdev/179008581937.2160803.7117814290574262942@kernel.org/
Link: https://lore.kernel.org/netdev/179033713973.2160803.4914570693994398206@kernel.org/
Link: https://lore.kernel.org/netdev/20260925180407.63647514@kernel.org/
Link: https://lore.kernel.org/netdev/CANn89i+k-mZKDQVtvws_MEXeuMTAdaCcOXFZE-RfhcGTu90sjA@mail.gmail.com/
Suggested-by: Eric Dumazet &lt;edumazet@google.com&gt;
Suggested-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
Tested-by: hybris &lt;hybris@mojatatu.ai&gt;
Signed-off-by: Jamal Hadi Salim &lt;jhs@mojatatu.com&gt;
Reviewed-by: Eric Dumazet &lt;edumazet@google.com&gt;
Link: https://patch.msgid.link/QDISC-9R8V.v4.20260928081529@mojatatu.com
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge tag 'mtd/fixes-for-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/mtd/linux</title>
<updated>2026-09-29T20:45:18Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-29T20:45:18Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=a243ede718463c7b481878656f1ff32a0ce0fd54'/>
<id>urn:sha1:a243ede718463c7b481878656f1ff32a0ce0fd54</id>
<content type='text'>
Pull MTD fixes from Miquel Raynal:
 "The most important set of fixes are around the handling of the QE bit
  in SPI NAND.

  There are also a couple of behavioral fixes (mutex issue in SPI-NOR,
  spurious bitflips on vf610_nfc, OOB bytes count in SPI NAND and
  cfi_cmdset stack usage).

  The rest is mostly AI fuzzing results"

* tag 'mtd/fixes-for-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/mtd/linux:
  mtd: spinand: Do not update the QE bit on devices without one
  mtd: spi-nor: core: Fix mutex leak in spi_nor_rww_start_exclusive()
  mtd: rawnand: cadence: Initialize IRQ state before requesting IRQ
  mtd: rawnand: vf610_nfc: fix false bitflips on reads of erased pages
  mtd: rawnand: vf610_nfc: fix reads on chips with more than 64 bytes of OOB
  mtd: spinand: fix zero oobavail when no ECC engine is used
  mtd: spinand: fix NULL pointer dereference with no ECC engine
  mtd: mtd_intel_dg: reset poll counter for each erase
  mtd: cfi_cmdset_0001: shrink do_write_buffer() stack frame
  mtd: core: call _get_device() with the master MTD
  mtd: core: avoid double-free of OTP NVMEM device
  mtd: spinand: Enable QE on all dies
  mtd: block2mtd: Fix divide error when erase_size is zero
</content>
</entry>
<entry>
<title>Merge tag 'sched-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-09-27T15:24:16Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-27T15:24:16Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=673dab7eac1618b6622bbee9eb2aaa47817631e3'/>
<id>urn:sha1:673dab7eac1618b6622bbee9eb2aaa47817631e3</id>
<content type='text'>
Pull scheduler fixes from Ingo Molnar:

 - Fix LLC mis-scheduling bugs (Tim Chen, Lu Wang)

 - Fix cache-grouping related scheduling statistics UAF bugs (Tim Chen)

 - Skip kernel threads for cache aware scheduling to rubustify the code
   (Chen Yu)

 - Refresh LLC capacity across CPU hotplug, to fix capacity
   underestimation bug (Davi Chaves Azevedo)

 - Account PSI IRQ time to the execution context, not the scheduling
   context, to fix proxy scheduling accounting bug (Zhan Xusheng)

* tag 'sched-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  sched/core: Account PSI IRQ time to the execution context, not the scheduling context
  sched/cache: Refresh LLC capacity across CPU hotplug, to fix capacity underestimation bug
  sched/cache: Skip kernel threads for cache aware scheduling to rubustify the code
  sched/cache: Introduce task_struct-&gt;sched_cache_grp to fix UAF
  sched/cache: Decouple sched_cache_group from mm to fix UAF
  sched/cache: Honor migrate_llc_task semantics in active load balance, to fix LLC mis-scheduling bug
  sched/cache: Keep nr_pref_llc_running in the runnable domain, to fix LLC mis-scheduling bug
</content>
</entry>
<entry>
<title>Merge tag 'perf-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip</title>
<updated>2026-09-27T15:15:58Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-27T15:15:58Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=5ccda18d1ba2ecf436102a211baf1fbd5d81703f'/>
<id>urn:sha1:5ccda18d1ba2ecf436102a211baf1fbd5d81703f</id>
<content type='text'>
Pull perf events fixes from Ingo Molnar:

 - Fixes for KVM guest PEBS virtualization (Sean Christopherson)

 - Fixes for various Intel PMUs related to PEBS data-source (Dapeng Mi)

 - Fix Intel Panther Cove event scheduling constraints (Dapeng Mi)

 - Fix Intel DMR/NVL OMR extra registers event scheduling (Dapeng Mi)

 - Rename two confusingly named PMU attributes (Dapeng Mi)

 - Fix a refcount leak in attach_perf_ctx_data() (Namhyung Kim)

 - Fix NULL pointer dereference crash in __perf_pmu_sched_task()
   (Puranjay Mohan)

 - Fix CPU-wide event scheduling (Puranjay Mohan)

 - Fix x86 LBR branch entry generation (Puranjay Mohan)

* tag 'perf-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  perf/core: Fill branch entries with a single assignment
  perf/core: Run sched_task() for PMUs with only CPU-wide events
  perf/core: Fix NULL pmu_ctx passed to pmu-&gt;sched_task()
  perf/core: Fix a refcount leak in attach_perf_ctx_data()
  perf/x86/intel: Rename NVL offcore_rsp attribute to offmodule_rsp
  perf/x86/intel: Rename DMR offcore_rsp attribute to offmodule_rsp
  perf/x86/intel: Fix precise OMR event scheduling for DMR/NVL
  perf/x86/intel: Constrain Panther Cove UOPS_DISPATCHED events to PMCs 0-3
  perf/x86/intel: Delete dead NVL PEBS data-source initcall
  perf/x86/intel: Fix Panther Cove PEBS data-source snoop states
  perf/x86/intel: Remove incorrect Panther Cove PEBS data-source constraints
  perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints
  perf/x86/intel: Update arw_latency_data() mem-op direction handling
  perf/x86/intel: Fix DKT PEBS load/store direction for latency events, to fix sample classification
  perf/x86/intel: Fix CMT PEBS load/store direction for latency events, to fix sample classification
  perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification
  perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs()
  perf/x86/intel: Don't pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused
  perf/x86/intel: Don't write PEBS_ENABLED on host&lt;=&gt;guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED
  perf/x86/intel: Ensure KVM guest PEBS path doesn't set unwanted PERF_GLOBAL_CTRL bits
</content>
</entry>
<entry>
<title>Merge tag 'ata-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux</title>
<updated>2026-09-26T18:14:35Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-26T18:14:35Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=fd179f8a05be3ccae366b9b96e176b51fbe54aab'/>
<id>urn:sha1:fd179f8a05be3ccae366b9b96e176b51fbe54aab</id>
<content type='text'>
Pull ata fixes from Niklas Cassel:

 - Extend the quirk "no LPM on ATI" quirk, that is currently only
   applied for Samsung drives, to include AMD controllers as well.

   The AMD AHCI controllers are newer versions of the ATI AHCI
   controllers, and these controllers still have LPM issues with
   Samsung drives - LPM works with drives from other vendors (me)

 - Fix errors in the libata.force parameter documentation (me)

 - Verify the sense data descriptor lengths for ATA PASS-THROUGH
   command, so that a malicious device cannot write past the buffer
   length (Matthias)

 - Mention the libata for-next branch in MAINTAINERS such that the
   git ls-remote command done by get_maintainer.pl --self-test=scm
   can verify it (Matthias)

* tag 'ata-7.3-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
  MAINTAINERS: name the libata/linux for-next branch
  ata: libata-scsi: bound the ATA passthru sense descriptor writes
  ata: libata: Correct libata.force parameter documentation
  ata: libata-core: Extend Samsung LPM quirk to AMD controllers
</content>
</entry>
<entry>
<title>Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm</title>
<updated>2026-09-26T15:26:12Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-26T15:26:12Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=eff8d2791c086388ba5bae36385afd9bc6f0507e'/>
<id>urn:sha1:eff8d2791c086388ba5bae36385afd9bc6f0507e</id>
<content type='text'>
Pull kvm fixes from Paolo Bonzini:
 "Arm:

   - Invalidate the ITS translation cache when the guest changes the
     base address of the ITS tables (Fuad Tabba)

   - Skip saving ITS devices with device IDs that are out-of-bounds
     rather than failing the entire ITS save ioctl (Fuad Tabba)

   - Close race between VM teardown and invalidations of nested MMUs
     when handling MMU operations that are allowed to block (Lorenzo
     Stoakes)

   - Various fixes for the handling of the host's untrusted SVE
     configuration in pKVM (Fuad Tabba)

   - Make sure that empty SMCCC ranges based at 0 are rejected by the
     kvm_smccc_set_filter() (Karl Mehltretter)

   - Revoke the host mapping for pKVM's private stack pages, along with
     a new sanity check that all mappings in the hyp's private VA range
     have been correctly marked as hyp-owned (Fuad Tabba)

   - Lifetime fixes for the array of shadow stage-2 MMUs, ensuring that
     concurrent vCPU initialization cannot relocate in-use MMUs. Defer
     the freeing of shadow stage-2 MMUs to the point that no other users
     (e.g. MMU notifier) could reference them (Marc Zyngier)

   - Drop useless WARN when rejecting an unsupported ioctl for pKVM
     (Fuad Tabba)

   - Fix the steal_time selftest to install correctly-sized mappings for
     non-4K hosts (Sebastian Ott)

   - Correct mapping of fine-grained trap for GCSPOPX instruction (Mark
     Brown)

   - Fix KVM_BUG_ON() due to missing handling of DBGBXVR&lt;n&gt; from 32-bit
     guests (Karl Mehltretter)

  RISC-V:

   - Synchronize hrtimer during VCPU teardown

   - Fix the conversion between vsip and hvip values

   - Serialize IMSIC attributes with vCPU migration

   - Release unused page after MMU invalidation

   - Propagate interrupted G-stage faults to KVM user-space as EINTR

   - Fix nested acceleration hfence entry update order

   - Fix sdata leak and stale snapshot_addr in snapshot_set_shmem

   - Preserve firmware counter value across PMU counter stop/start

   - Report PMU snapshot write failure to the guest

   - Fix perf-backed counter accounting across PMU stop and read

   - Correctly propagate error of a hart status SBI call

  s390:

   - Ensure that accesses through kvm_arch_set_irq_inatomic mark as
     dirty the pages that contain indicator and summary bits

   - Fix compile warning for kvm_s390_update_cmma_dirty()

   - Fix incorrect propagation of ENOENT from _gaccess_shadow_fault() to
     userspace

   - Move s390_kvm_mmu_commit_memory_region() into
     s390_kvm_mmu_prepare_memory_region() so that it can fail instead of
     WARN

   - Add missing srcu in kvm_s390_set_irq_state()

   - Fix potential races in storage functions

   - Fix race in _destroy_pages_crste()

   - Fix issues in the handling of KVM interrupt and page resources,
     when a queue that is assigned to a mediated device (mdev) is
     removed from the host's AP configuration

   - Fix loop condition in uv_find_secrets

   - Prevent potential out-of-bounds read

  x86:

   - Fix a brown paper bag bug where KVM would incorrectly treat Intel
     PMU MSRs as valid on AMD

   - Fix a regression in the hardware disable selftest where it checked
     the wrong macro when detecting glibc support (breaks at least musl)

   - Never clear KVM_REQ_VM_DEAD so that dead VMs stay dead, which is
     especially important for KVM_BUG_ON() flows, which often guard more
     dangerous bugs

   - Re-pend GET_NESTED_STATE_PAGES if getting the pages fails, to fix a
     bug where KVM would let userspace run a broken setup with stale
     vmcs12 pages

   - Fix a class of bugs where KVM would fail to fill kvm_run exit
     fields if getting nested pages failed

   - Treat reserved entries in the memory attributes xarray as "no
     attributes", to fix false positives when checking for mixed
     attributes

   - Fix memcg accounting for the memory attributes xarray (the xarray
     library subtly requires the xarray to be configured for accounting
     upfront; the gfp flags taken at runtime are used only rarely)

   - Don't pre-reserve xarray entries when storing empty attributes, as
     storing NULL must not require memory allocation (KVM and other
     subsystems heavily rely on this behavior)

   - Fix a memory leak and a cache maintenance issue related to doing
     intra-host migration on an SEV guest"

* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm: (54 commits)
  KVM: SEV: Do cache maintenance on the source VM during intra-host migration
  KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV
  KVM: Don't pre-reserve xarray entries when storing empty/NULL attributes
  KVM: Ensure memory attributes xarray nodes are accounted to the caller's memcg
  KVM: Don't treat reserved xarray entries as having memory attributes
  KVM: x86: Fill kvm_run exit fields in common get_nested_state_pages() error paths
  KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails
  KVM: arm64: Fix AArch32 DBGBXVR&lt;n&gt; handling
  KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP
  KVM: selftests: fix steal_time for arm64 with host page size &gt; 4K
  KVM: arm64: Don't WARN on an unknown VM ioctl in protected mode
  KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction
  KVM: arm64: nv: Fix life cycle of the nested_mmus array
  KVM: arm64: Check every private mapping is hyp-owned at pKVM init
  KVM: arm64: Move the private VA allocation cursor to __io_map_next
  KVM: arm64: Match hyp text by physical address in fix_host_ownership()
  KVM: arm64: Transfer the hyp stack pages out of the host stage-2
  KVM: arm64: selftests: Test empty SMCCC filter range at base 0
  KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0
  KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2
  ...
</content>
</entry>
<entry>
<title>Merge tag 'kvm-x86-fixes-7.3-rc5' of https://github.com/kvm-x86/linux into HEAD</title>
<updated>2026-09-26T04:40:07Z</updated>
<author>
<name>Paolo Bonzini</name>
<email>pbonzini@redhat.com</email>
</author>
<published>2026-09-26T04:40:07Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-linux/commit/?id=c2f24f140c2ee6c00775c2a93c6ac931acec2b60'/>
<id>urn:sha1:c2f24f140c2ee6c00775c2a93c6ac931acec2b60</id>
<content type='text'>
KVM fixes for 7.3-rcN

 - Fix a brown paper bag bug where KVM would incorrectly treat Intel PMU MSRs
   as valid on AMD.

 - Fix a regression in the hardware disable selftest where it checked the wrong
   macro when detecting glibc support (breaks at least musl).

 - Never clear KVM_REQ_VM_DEAD so that dead VMs stay dead, which is especially
   important for KVM_BUG_ON() flows, which often guard more dangerous bugs.

 - Re-pend GET_NESTED_STATE_PAGES if getting the pages fails, to fix a bug
   where KVM would let userspace run a broken setup with stale vmcs12 pages.

 - Fix a class of bugs where KVM would fail to fill kvm_run exit fields if
   getting nested pages failed.

 - Treat reserved entries in the memory attributes xarray as "no attributes",
   to fix false positives when checking for mixed attributes.

 - Fix memcg accounting for the memory attributes xarray (the xarray library
   subtly requires the xarray to be configured for accounting upfront; the gfp
   flags taken at runtime are used only rarely).

 - Don't pre-reserve xarray entries when storing empty attributes, as storing
   NULL must not require memory allocation (KVM and other subsystems heavily
   rely on this behavior).
</content>
</entry>
</feed>
