aboutsummaryrefslogtreecommitdiffstatshomepage
AgeCommit message (Collapse)AuthorFilesLines
2026-07-30gpio: regmap: Add value_xlate callbackYu-Chun Lin2-4/+42
Introduce a new optional 'value_xlate' callback. This routine allows drivers to translate or modify the register value and mask immediately before a write operation. It is particularly useful for hardware that requires additional control bits, such as a write-enable bit, to be appended to the data dynamically. Reviewed-by: Michael Walle <mwalle@kernel.org> Reviewed-by: Linus Walleij <linusw@kernel.org> Suggested-by: Michael Walle <mwalle@kernel.org> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-7-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30gpio: regmap: Add gpio_regmap_operation to extend reg_mask_xlate callbackYu-Chun Lin11-29/+61
Extend the reg_mask_xlate callback with an operation type parameter (enum gpio_regmap_operation) to allow drivers to return different register/mask combinations depending on the specific GPIO operation. Consequently, update all existing drivers utilizing the gpio-regmap framework (across drivers/gpio, drivers/iio, and drivers/pinctrl) to accommodate the new reg_mask_xlate function signature. Acked-by: William Breathitt Gray <wbg@kernel.org> Acked-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com> #for-iio Suggested-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-6-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30gpio: regmap: Order kernel-doc descriptions with the actual appearanceAndy Shevchenko1-9/+9
Order kernel-doc descriptions with the actual appearance. Reviewed-by: Michael Walle <mwalle@kernel.org> Reviewed-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-5-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30gpio: regmap: Apply default resource callbacks for regmap IRQ chipAndy Shevchenko2-3/+18
When GPIO regmap creates an IRQ chip on behalf of the user, it also takes an ownership of the respective callbacks and driver data. With that being done, apply default resource callbacks that keep tracking the IRQ requests and releases. Reviewed-by: Michael Walle <mwalle@kernel.org> Reviewed-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Reviewed-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-4-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30gpio: regmap: Provide default IRQ resource request and release callbacksAndy Shevchenko2-0/+15
When GPIO regmap based driver supplies its own IRQ domain, it might still want to keep track of the IRQ requests and releases, in particular to prevent a GPIO, which is used and locked as IRQ, to be requested via standard ways. Provide default callbacks for such cases and keep struct gpio_chip private to GPIO regmap implementation. Reviewed-by: Michael Walle <mwalle@kernel.org> Reviewed-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-3-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30Revert "gpio: realtek: Add driver for Realtek DHC RTD1625 SoC"Yu-Chun Lin3-624/+0
This reverts commit a57e27c43b0315ee86c6896510d69be5257e093e. The driver will be rewritten to use the gpio-regmap infrastructure once Andy Shevchenko's patches for gpio-regmap are applied. Acked-by: Andy Shevchenko <andriy.shevchenko@intel.com> Acked-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Yu-Chun Lin <eleanor.lin@realtek.com> Link: https://patch.msgid.link/20260726125209.140307-2-eleanor.lin@realtek.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-07-30riscv: dts: spacemit: Add cpu scaling for Milk-V JupiterAurelien Jarno1-1/+34
Enable CPU DVFS on Milk-V Jupiter by including the OPP tables and wiring the CPU nodes to the CPU regulator supply. Reviewed-by: Yixun Lan <dlan@kernel.org> Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Link: https://patch.msgid.link/20260729160749.1621415-2-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30Merge tag 'imx-soc-7.3' of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux into soc/armArnd Bergmann7-16/+41
i.MX SoC Changes for v7.3 - Fix OF/device_node reference count leaks in imx_src_init(), imx7_src_init(), and the AVIC interrupt controller driver - Drop obsolete/unused declarations from `arch/arm/mach-imx/common.h` - firmware: imx: scu: Refactor mailbox channel management to use a per-instance handle instead of a global one - firmware: imx: sm-misc: Add NULL check for `kmalloc` return value in syslog_show - soc: imx9: Add error handling for `devm_kasprintf` return value * tag 'imx-soc-7.3' of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux: firmware: imx: scu: manage mailbox channels and global handle soc: imx9: devm_kasprintf error handling ARM: imx: Drop obsolete stuff from common.h firmware: imx: sm-misc: Add NULL check for kmalloc in syslog_show ARM: imx: fix device_node refcount leaks in imx7_src_init() ARM: imx: fix device_node refcount leak in imx_src_init() ARM: imx: avic: Fix OF node reference leaks Signed-off-by: Arnd Bergmann <arnd@arndb.de>
2026-07-30Merge tag 'qcom-arm64-fixes-for-7.2' of https://git.kernel.org/pub/scm/linux/kernel/git/qcom/linux into arm/fixesArnd Bergmann8-22/+29
Qualcomm Arm64 DeviceTree fixes for 7.2 Correct the ESPI interrupt specifiers for PCIe SMMU and QUP nodes in Glymur. Correct the GIC address cells on Monaco, to avoid DeviceTree validation failures introduces in v7.2-rc1. Drop the secondary interrupt from the GPU SMMU on Purwa. Fix the invalid PDC IRQ mapping for SC8280XP to ensure associated GPIOs have functional interrupt handling. Correct the EC interrupt on Huawei Matebook E Go. Reduce the depth of the requested sleep state for SDM850-based Lenovo Yoga C630, to work around the regression of suspend crashing the machine. Adjust the IPA IMEM address on SM8650, to avoid clobbering the wrong memory region in IMEM. Correct the DSI1 PHY reference clock on Eliza, to ensure that the right clock rate is used. * tag 'qcom-arm64-fixes-for-7.2' of https://git.kernel.org/pub/scm/linux/kernel/git/qcom/linux: arm64: dts: qcom: eliza: Fix DSI1 phy reference clock rate arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle arm64: dts: qcom: sc8280xp: gaokun3: correct EC interrupt pin arm64: dts: qcom: sc8280xp: add several missing pdc map entries arm64: dts: qcom: sm8650: Fix IPA IMEM slice arm64: dts: qcom: monaco: Add default GIC address cells arm64: dts: qcom: purwa: Fix GPU IOMMU property arm64: dts: qcom: glymur: fix QUP serial engine IRQs arm64: dts: qcom: glymur: fix PCIe SMMU interrupts Signed-off-by: Arnd Bergmann <arnd@arndb.de>
2026-07-30riscv: dts: spacemit: k1-bananapi-cm6: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the Banana Pi BPI-CM6 module, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: 46a8c01700ac ("riscv: dts: spacemit: k1: Add Banana Pi BPI-CM6 IO board") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-7-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30riscv: dts: spacemit: k1-orangepi-r2s: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the OrangePi R2S board, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: 793cc54475b4 ("riscv: dts: spacemit: enable PMIC on OrangePi R2S") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Cc: stable@vger.kernel.org Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-6-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30riscv: dts: spacemit: k1-musepi-pro: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the MusePi Pro board, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: e2dac7c7a3a8 ("riscv: dts: spacemit: k1-musepi-pro: add PMIC and power infrastructure") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Cc: stable@vger.kernel.org Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-5-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30riscv: dts: spacemit: k1-orangepi-rv2: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the OrangePi RV2 board, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: c02c047b925c ("riscv: dts: spacemit: Define the P1 PMIC regulators for OrangePi RV2") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Cc: stable@vger.kernel.org Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-4-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the Milk-V Jupiter board, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: 7d307daa12b1 ("riscv: dts: spacemit: Define the P1 PMIC regulators for Milk-V Jupiter") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Cc: stable@vger.kernel.org Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-3-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltageAurelien Jarno1-2/+2
On the Banana Pi BPI-F3 board, the buck1 and buck2 voltage regulators, which supply the CPU core voltage, are configured with a maximum output voltage of 3.45V, while the highest operating point requires only 1.050V. This means that a kernel bug, OPP misconfiguration, or privileged userspace could request a voltage above the safe operating limit, causing possible permanent CPU damage. Set the maximum regulator voltage to 1.050V instead. Fixes: 09a412d39748 ("riscv: dts: spacemit: define regulator constraints") Link: https://sashiko.dev/#/message/20260728211020.1248676-2-aurelien%40aurel32.net Cc: stable@vger.kernel.org Signed-off-by: Aurelien Jarno <aurelien@aurel32.net> Reviewed-by: Yixun Lan <dlan@kernel.org> Link: https://patch.msgid.link/20260729150722.1598630-2-aurelien@aurel32.net Signed-off-by: Yixun Lan <dlan@kernel.org>
2026-07-30md/raid5: fix lockless max_nr_stripes readsChen Cheng1-4/+4
max_nr_stripes is updated under cache_size_mutex in the stripe cache grow/shrink paths, while is_inactive_blocked() and raid5_end_read_request() read it without that lock. Use READ_ONCE() for those reads in lockless path to match the WRITE_ONCE() updates and avoid KCSAN data race reports. A similar issue was previously fixed in commit-id: dfd2bf436709b2bccb78c2dda550dde93700efa7. Fixes: 0009fad03337 ("raid5 improve too many read errors msg by adding limits") Fixes: 3514da58be9c ("md/raid5: Make is_inactive_blocked() helper") KCSAN report: ================= BUG: KCSAN: data-race in grow_one_stripe / is_inactive_blocked write (marked) to 0xffff8f01f0b5a268 of 4 bytes by task 12616 on cpu 9: grow_one_stripe+0x2d8/0x320 raid5d+0xb57/0xba0 md_thread+0x15a/0x2d0 [..........] read to 0xffff8f01f0b5a268 of 4 bytes by task 12670 on cpu 11: is_inactive_blocked+0x97/0xc0 raid5_get_active_stripe+0x2fd/0xa70 raid5_make_request+0x4aa/0x2940 [..........] value changed: 0x000003b9 -> 0x000003ba Signed-off-by: Chen Cheng <chencheng@fnnas.com> Reviewed-by: Yu Kuai <yukuai@fygo.io> Link: https://patch.msgid.link/20260624024042.2561803-1-chencheng@fnnas.com Signed-off-by: Yu Kuai <yukuai@fygo.io>
2026-07-30Merge tag 'imx-maintainers-7.3' of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux into arm/fixesArnd Bergmann1-12/+1
MAINTAINERS: ARM/FREESCALE: Update for v7.2 - Merge Layerscape entry into i.MX entry * tag 'imx-maintainers-7.3' of https://git.kernel.org/pub/scm/linux/kernel/git/frank.li/linux: MAINTAINERS: ARM/FREESCALE: merge Layerscape entry into i.MX entry Signed-off-by: Arnd Bergmann <arnd@arndb.de>
2026-07-30fs/ntfs3: Add basic support for alternative data streamsKonstantin Komarov11-184/+684
An ADS (alternative data stream) is a named $DATA (0x80) attribute. Until now ntfs3 ignored named data attributes entirely, so the only stream reachable from userspace was the unnamed one. Introduce a colon-delimited name syntax so streams can be reached through the regular VFS interfaces. ntfs_nls_to_utf16() now splits a lookup name at ':' and stores the stream part in cpu_str::ads_len (the previously unused padding byte). ntfs_iget5_flags() first instantiates the base inode, then allocates a second inode whose ->base points at it and whose ->file.ads holds the stream name. ntfs_test_inode() compares the stream name as well as the MFT reference, so base and streams get distinct inodes for the same record. Because the MFT record belongs to the base inode, the many helpers in frecord.c and attrlist.c that operate on the record redirect to ni->base, and ni_lock() and friends take the base inode's mutex. The attrib.c paths that used to hardcode an unnamed $DATA lookup now pass ni->file.ads.{name,len}. ni_write_inode() and ni_write_parents() are no-ops for stream inodes, and ntfs_setattr() drops ATTR_SIZE for them. Usage, for a file with streams 'ads1' and 'ads2': cat file:query_streams - list stream names, one per line cat file:ads1 - read a stream touch file:ads3 - create a stream on an existing file rm file:ads1 - remove a stream The pseudo-stream 'query_streams' is handled in ntfs_file_read_iter() via ni_query_ads(), which enumerates named $DATA attributes and returns their names separated by '\n'. The feature is controlled by the new 'ads' mount option, enabled by default; mount with 'ads=0' to restore the previous behaviour. Not implemented yet: - creating a file and a stream in a single call - renaming (moving) a stream Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
2026-07-30fs/ntfs3: Rename 'err' to 'ret' in read pathsKonstantin Komarov1-20/+21
ntfs_file_read_iter() and ntfs_file_splice_read() store both error codes and the number of bytes transferred in a variable named 'err', which is misleading on the success path. Rename it to 'ret'. While here, rename the 'in' parameter of ntfs_file_splice_read() to 'file' for consistency with the rest of the file, and add a local 'ni' instead of calling ntfs_i() inline. Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
2026-07-30fs/ntfs3: Fix memory leak in indx_find_sort()Konstantin Komarov1-0/+1
When popping a level from the index lookup stack, indx_find_sort() frees the struct indx_node but not the index buffer it owns. Every call that descends and then pops a level leaks that allocation. Free n->index before freeing the node itself. Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
2026-07-30md/raid1: protect sequential read hints for read balanceChen Cheng1-8/+10
The patch just suppress KCSAN noise. No functional change. KCSAN reports a race, point to update_read_sectors() update next_seq_sect vs. read next_seq_sect. Protect next_seq_sect and seq_start with READ_ONCE/WRITE_ONCE, otherwise, read balance see stale sequential-read hints. KCSAN report: ============== BUG: KCSAN: data-race in raid1_read_request / raid1_read_request write to 0xffff8e3a2d6736d0 of 8 bytes by task 593784 on cpu 10: raid1_read_request+0xe5a/0x19f0 raid1_make_request+0xdf/0x1990 md_handle_request+0x4a2/0xa40 [...] read to 0xffff8e3a2d6736d0 of 8 bytes by task 593776 on cpu 11: raid1_read_request+0xe3f/0x19f0 raid1_make_request+0xdf/0x1990 md_handle_request+0x4a2/0xa40 [...] value changed: 0x0000000000356368 -> 0x0000000000356370 Signed-off-by: Chen Cheng <chencheng@fnnas.com> Reviewed-by: Yu Kuai <yukuai@fygo.io> Link: https://patch.msgid.link/20260623075940.2476255-1-chencheng@fnnas.com Signed-off-by: Yu Kuai <yukuai@fygo.io>
2026-07-30Merge branch 'net-lan743x-add-rmii-support-for-pci11x1x'Paolo Abeni2-4/+37
Thangaraj Samynathan says: ==================== net: lan743x: add RMII support for PCI11x1x From: Thangaraj Samynathan <thangaraj.s@microchip.com> This series adds RMII interface support for the Microchip PCI11x1x Ethernet controller. The PCI11x1x device supports RMII as an alternative MAC-PHY interface, selected via the STRAP_READ software strap register. Patch 1 reads the RMII strap bits from this register and sets the is_rmii_en flag. Patch 2 uses this flag to configure the PHY interface mode, phylink supported interfaces, and enables RMII in hardware via the RMII_CTL register. ==================== Link: https://patch.msgid.link/20260723050827.694832-1-Thangaraj.S@microchip.com Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2026-07-30net: lan743x: add support for RMII interfaceThangaraj Samynathan2-2/+24
Enable RMII interface in the lan743x driver for PHY and MAC configuration. - Select RMII interface in lan743x_phy_interface_select(). - Update phylink supported_interfaces and MAC capabilities. - Enable RMII via RMII_CTL in lan743x_hardware_init(). - Define RMII_CTL register and enable bit in lan743x_main.h. EEE is not supported with RMII on PCI11x1x: the hardware does not implement LPI signaling over RMII. Clear RMII from lpi_interfaces to prevent phylink from enabling EEE on this interface. Signed-off-by: Thangaraj Samynathan <thangaraj.s@microchip.com> Link: https://patch.msgid.link/20260723050827.694832-3-Thangaraj.S@microchip.com Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2026-07-30net: lan743x: add RMII strap status detection for PCI11x1xThangaraj Samynathan2-2/+13
Extend pci11x1x_strap_get_status() to read the RMII strap bits from the STRAP_READ register. The is_rmii_en flag is initialized to false and updated based on the hardware strap only if SGMII is not already enabled. This ensures correct interface identification during adapter initialization. Update the netif_dbg() to report the selected interface as SGMII, RMII, or RGMII. Signed-off-by: Thangaraj Samynathan <thangaraj.s@microchip.com> Link: https://patch.msgid.link/20260723050827.694832-2-Thangaraj.S@microchip.com Signed-off-by: Paolo Abeni <pabeni@redhat.com>
2026-07-30md/raid5-ppl: fix use-after-free in ppl_do_flush()Sajal Gupta1-1/+3
The loop in ppl_do_flush() continues iterating after calling ppl_io_unit_finished(), touching io->pending_flushes and leading to a use-after-free. Add a break statement to stop the loop once io is freed. Fixes: 1532d9e87e8b ("raid5-ppl: PPL support for disks with write-back cache enabled") Reported-by: Dan Carpenter <error27@gmail.com> Closes: https://lore.kernel.org/all/ajJF2wKYWRk4GGCK@stanley.mountain/ Signed-off-by: Sajal Gupta <sajal2005gupta@gmail.com> Reviewed-by: Yu Kuai <yukuai@fygo.io> Link: https://patch.msgid.link/20260622142146.56637-1-sajal2005gupta@gmail.com Signed-off-by: Yu Kuai <yukuai@fygo.io>
2026-07-30Merge branch 'mm-stable-6d098029de09' of https://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm into kho-scratchMike Rapoport (Microsoft)3426-12333/+25981
2026-07-30crypto: af_alg - Allow cbc(paes)Richard Weinberger1-1/+7
Commit 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") breaks a special use case. The cbc-paes-caam driver implements the algorithm cbc(paes), it offers a way to use AES in CBC mode with key material unknown to userspace. Instead of an AES key a CAAM BLOB is passed to the kernel. So, this crypto operation cannot be implemented in a userspace library and needs always help from the kernel. Explicitly allow this use case. Cc: Demi Marie Obenour <demiobenour@gmail.com> Suggested-by: Eric Biggers <ebiggers@kernel.org> Fixes: 7524070f26d8 ("crypto: af_alg - Drop support for off-CPU cryptography") Signed-off-by: Richard Weinberger <richard@nod.at> Reviewed-by: Eric Biggers <ebiggers@kernel.org> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30RISC-V: KVM: Add more arch-specific tracepointsYuhang.Chen4-4/+98
Add RISC-V KVM tracepoints for events that are useful when debugging guest exits and in-kernel emulation paths. The existing kvm_entry and kvm_exit tracepoints are kept, with the kvm_entry PC format fixed to use zero-padded hexadecimal output. The newly added tracepoints cover: - kvm_vcpu_exit for synchronous guest traps - kvm_vcpu_irq for VS-mode interrupt set/clear - kvm_mmio_emulate for MMIO load/store emulation kvm_vcpu_exit reports the full trap context (sepc/scause/stval/htval/ htinst) so userspace can filter by scause, and is placed after the interrupt early-return so it fires only for synchronous traps. kvm_vcpu_irq covers every set/unset_interrupt() caller from a single place. Example trace output: kvm_vcpu_exit: VCPU: 0, SEPC: 0x80200000, SCAUSE: 0x17, STVAL: 0x10000000, HTVAL: 0x4000000, HTINST: 0x2023 kvm_mmio_emulate: VCPU: 0, Store MMIO at 0x10000000, len 4, insn 0x2023, sepc 0x80200000 kvm_vcpu_irq: VCPU: 0, IRQ: 10, level: 1 Testing: A QEMU-based test program was used to exercise: - Guest page faults - MMIO emulation - IRQ injection Verified trace output generation for: - kvm_vcpu_exit - kvm_vcpu_irq - kvm_mmio_emulate Assisted-by: YuanSheng:deepseek-v4-pro Co-developed-by: Quan Zhou <zhouquan@iscas.ac.cn> Signed-off-by: Quan Zhou <zhouquan@iscas.ac.cn> Signed-off-by: Yuhang.Chen <yhchen312@gmail.com> Reviewed-by: Anup Patel <anup@brainfault.org> Link: https://lore.kernel.org/r/20260730065711.3721489-1-yhchen312@gmail.com Signed-off-by: Anup Patel <anup@brainfault.org>
2026-07-30soc: mediatek: add missing MODULE_DEVICE_TABLE()Pengpeng Hou1-0/+1
The driver has an OF match table wired to .of_match_table, but does not export the table with MODULE_DEVICE_TABLE(). Add the missing MODULE_DEVICE_TABLE(of, ...) entry so module alias information is generated for OF based module autoloading. This is a source-level fix. It does not claim dynamic hardware reproduction; the evidence is the driver-owned match table, its use by the platform driver, and the missing module alias publication. Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn> Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
2026-07-30soc: mediatek: mtk-mmsys: Use MMSYS_ROUTE() in default routing tableAngeloGioacchino Del Regno1-165/+114
All of the mtk_mmsys_routes tables for all SoCs were converted to use the MMSYS_ROUTE() macro but the default one used for MT2701, MT2712 and SoCs from that generation was not: convert this one as well. This brings no functional change. Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
2026-07-30soc: mediatek: mtk-mmsys: Rework routes to specify component IDAngeloGioacchino Del Regno9-193/+201
In preparation for a refactoring of multimedia related MediaTek drivers, including mmsys, mutex and mediatek-drm, rework all of the MMSYS routes to specify a hardware component instance number (or "SubID") alongside the hardware component type. This also is one step of preparation towards the removal of the catch-all mtk_ddp_comp_id enumeration and towards the migration from a predefined-coupling static hardware component IDSubID mapping (carrying around a very long enumeration and also some multiple big arrays in mediatek-drm) to a more flexible map of Component ID (Type) decoupled from Component SubID (HW Instance) as then, anyway, techniques to handle components are always the same on a type basis. Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
2026-07-30crypto: af_alg - clean up kernel-doc warningsRandy Dunlap1-13/+17
- add missing struct member @wait, drop @completion - convert function comments to kernel-doc format - for af_alg_readable(), change comments from "writable" to "readable" Warning: include/crypto/if_alg.h:161 struct member 'wait' not described in 'af_alg_ctx' Warning: include/crypto/if_alg.h:161 Excess struct member 'completion' description in 'af_alg_ctx' Warning: include/crypto/if_alg.h:187 This comment starts with '/**', but isn't a kernel-doc comment. * Size of available buffer for sending data from user space to kernel. Warning: include/crypto/if_alg.h:202 This comment starts with '/**', but isn't a kernel-doc comment. * Can the send buffer still be written to? Warning: include/crypto/if_alg.h:213 This comment starts with '/**', but isn't a kernel-doc comment. * Size of available buffer used by kernel for the RX user space operation. Warning: include/crypto/if_alg.h:228 This comment starts with '/**', but isn't a kernel-doc comment. * Can the RX buffer still be written to? Signed-off-by: Randy Dunlap <rdunlap@infradead.org> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: drivers - remove conditional return with no effectSang-Heon Jeon2-12/+3
Both branches of the check return the same value, so the check has no effect. Remove it and return the value directly. This is the result of running the Coccinelle script from scripts/coccinelle/misc/cond_return_no_effect.cocci. Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: octeontx - simplify get_{eng,ucode}_type_str helpersThorsten Blum1-16/+8
Remove the local variables, add default cases, and return the strings directly. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: qce - drop redundant variable in qce_skcipher_doneThorsten Blum1-4/+2
Remove the local ret variable and return the result directly. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: bcm - use memcpy_and_pad in ahash_hmac_setkeyThorsten Blum1-3/+1
Use memcpy_and_pad() instead of memcpy() followed by memset() to simplify ahash_hmac_setkey(). Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: cesa - manage SRAM teardown with devmRosen Penev2-33/+24
mv_cesa_put_sram() is called explicitly from both the probe error path and mv_cesa_remove(). The non-pool ioremap is already devm-managed, but dma_map_resource() and gen_pool_dma_alloc() have no devm helpers, so the mapping is released by hand. This is error-prone: the error path iterates over every engine and can dma_unmap_resource() an uninitialized/zero address for engines that were never set up. Convert the teardown into a devm_add_action_or_reset() callback registered only after a mapping is successfully established. The callback fires automatically on probe failure (devres rollback) and on device detach, after mv_cesa_remove() has already stopped the engine and freed the IRQ, so the unmap still happens in a safe order. This deletes the explicit mv_cesa_put_sram() calls and the uninitialized-engine bug at once. Add a struct mv_cesa_dev back-pointer to struct mv_cesa_engine so the callback can reach cesa->dev and cesa->sram_size from the engine alone. Assisted-by: opencode:hy3-free Signed-off-by: Rosen Penev <rosenp@gmail.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: starfive - use scatterlist length before DMA mappingThorsten Blum1-1/+1
Using sg_dma_len() is only valid after mapping a scatterlist with dma_map_sg(). However, starfive_aes_aead_do_one_req() uses it before mapping the scatterlist. Use the original scatterlist length because the DMA length has not been populated yet when CONFIG_NEED_SG_DMA_LENGTH=y. Fixes: 7467147ef9bf ("crypto: starfive - Use dma for aes requests") Cc: stable@vger.kernel.org Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: qce - fix error path in devm_qce_register_algsThorsten Blum1-1/+1
If ops->register_algs() fails, the error path repeatedly calls the same ops->unregister_algs() from the failed registration. Use the loop index to unregister the previously registered algorithms instead. Fixes: e80cf84b6087 ("crypto: qce - unregister previously registered algos in error path") Cc: stable@vger.kernel.org Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30rhashtable: fix false-positive lockdep splat on rhltable destructionFlorian Westphal1-1/+1
Blamed commit removed ht->mutex usage during destruction but forgot to switch rhashtable_free_one() to rcu_dereference_raw(), this triggers a lockdep splat when an rhltable gets zapped. Fixes: 09ae540e1d5c ("rhashtable: drop ht->mutex in rhashtable_free_and_destroy()") Signed-off-by: Florian Westphal <fw@strlen.de> Reviewed-by: Mikhail Gavrilov <mikhail.v.gavrilov@gmail.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()Vladislav Dronov1-19/+3
Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may lead to a crash if a caller does not call tegra_gcm_setauthsize() and so ctx->authsize remains zero. Then a decrypt operation with incorrect rctx->cryptlen will lead to a write beyound rctx->dst_sg buffer. As a follow-up cleanup delete struct tegra_aead_ctx->authsize field since it appears to be completely unused. Also simplify tegra_ccm_setauthsize() and tegra_gcm_setauthsize() functions respectively. Fixes: 0880bb3b00c8 ("crypto: tegra - Add Tegra Security Engine driver") Signed-off-by: Vladislav Dronov <vdronov@redhat.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30crypto: ccm - Set rfc4309 maxauthsize from childHerbert Xu1-1/+1
Set the maxauthsize of rfc4309 using that of the child algorithm. Fixes: 4a49b499dfa0 ("[CRYPTO] ccm: Added CCM mode") Reported-by: Seohyeon Maeng <bioloidgp@gmail.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2026-07-30md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistencyChen Cheng1-4/+6
kcsan detect race : - raid5d() closes the current bitmap batch by updating conf->seq_flush under conf->device_lock. - __add_stripe_bio() read conf->seq_flush without that lock when assigning sh->bm_seq. so, protect seq_flush/seq_write consistency for multiple CPUs by READ_ONCE()/WRITE_ONCE() under the path without held device_lock. re-explain the stripe batch sequence number update flow: 1. sh->bm_seq declare which batch number the stripe belongs to when perform bitmap-related write. ==> bm_seq = seq_flush+1 2. stripe be handled, * if sh->bm_seq - conf->seq_write > 0, means the batch stripes **newer than** the last written batch, it cannot proceed yet, queued on bitmap_list. * otherwise , has already proceed. 3. raid5d() `++seq_flush` to closes the current batch, means * no more stripes join that old batch * just-closed batch ready to write-out to disk 4. raid5d() calls bitmap hooks unplug() or writeout, then, `++seq_write` to the same as bm_seq. - seq_flush - for producer, to close batches. - seq_write - for consumer, the checkpoint number. the report: ==================================== BUG: KCSAN: data-race in __add_stripe_bio / raid5d write to 0xffff88ba5625d470 of 4 bytes by task 82401 on cpu 0: raid5d+0x1d9/0xba0 [.....] read to 0xffff88ba5625d470 of 4 bytes by task 82421 on cpu 8: __add_stripe_bio+0x332/0x400 raid5_make_request+0x6ac/0x2930 md_handle_request+0x4a2/0xa40 md_submit_bio+0x109/0x1a0 __submit_bio+0x2ec/0x390 [.....] Fixes: 7c13edc87510 ("md: incorporate new plugging into raid5.") v1 -> v2: - remove WRITE_ONCE(conf->seq_write) in held device_lock path. - remove READ_ONCE(conf->seq_flush) in held device_lock path. Signed-off-by: Chen Cheng <chencheng@fnnas.com> Reviewed-by: Yu Kuai <yukuai@fygo.io> Link: https://patch.msgid.link/20260622124649.1780233-1-chencheng@fnnas.com Signed-off-by: Yu Kuai <yukuai@fygo.io>
2026-07-30mm/mm_init: remove unnecessary initialization of pgdat->per_cpu_nodestatsSang-Heon Jeon1-1/+0
free_area_init_node() sets pgdat->per_cpu_nodestats to NULL and later calls free_area_init_core(), which unconditionally overwrites it with &boot_nodestats. Nothing reads the field in between, so the store has no effect. Remove unnecessary initialization. No functional change. Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com> Link: https://patch.msgid.link/20260729155143.177790-1-ekffu200098@gmail.com Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
2026-07-30RISC-V: KVM: Mark the reset callback of FWFT extension always dirties CSRInochi Amaoto1-0/+2
As the CSR is only flushed when the csr_dirty is set, always set the csr_dirty field in kvm_sbi_ext_fwft_reset() so the CSR change can take effect immediately. This unconditional set should be safe as all supported FWFT features change the CSR state currently. Signed-off-by: Inochi Amaoto <inochiama@gmail.com> Reviewed-by: Anup Patel <anup@brainfault.org> Link: https://lore.kernel.org/r/20260729232527.139183-5-inochiama@gmail.com Signed-off-by: Anup Patel <anup@brainfault.org>
2026-07-30RISC-V: KVM: Reset the SBI extension when disable itInochi Amaoto1-0/+7
The SBI extension validation callback can only fix the parameter if the extension is enabled. However, if the extension is disabled after modifty some parameters, the state of the extension is still broken. Reset the extension when the extension is disabled so it can have a clear context. Signed-off-by: Inochi Amaoto <inochiama@gmail.com> Reviewed-by: Anup Patel <anup@brainfault.org> Link: https://lore.kernel.org/r/20260729232527.139183-4-inochiama@gmail.com Signed-off-by: Anup Patel <anup@brainfault.org>
2026-07-30RISC-V: KVM: Add SBI FWFT validation supportInochi Amaoto1-0/+25
Since the KVM SBI has extension parameters validation support, implement it for the SBI FWFT support. Signed-off-by: Inochi Amaoto <inochiama@gmail.com> Reviewed-by: Anup Patel <anup@brainfault.org> Link: https://lore.kernel.org/r/20260729232527.139183-3-inochiama@gmail.com Signed-off-by: Anup Patel <anup@brainfault.org>
2026-07-30RISC-V: KVM: Add SBI extension validate callbackInochi Amaoto3-0/+29
When user disable FWFT extension after setting any value of the FWFT feature, the state of vCPU will be broken since the value of disable FWFT feature is still functional. Add the generic SBI extension validate callback so the FWFT extension can fix its parameters before the first run. Signed-off-by: Inochi Amaoto <inochiama@gmail.com> Reviewed-by: Anup Patel <anup@brainfault.org> Link: https://lore.kernel.org/r/20260729232527.139183-2-inochiama@gmail.com Signed-off-by: Anup Patel <anup@brainfault.org>
2026-07-30wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()Abdun Nihaal1-0/+1
The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the skb before returning. This can lead to a memory leak in rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_skb(). Fixes: aaab5d0e6737 ("rtw88: kick off TX packets once for higher efficiency") Cc: stable@vger.kernel.org Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in> Acked-by: Ping-Ke Shih <pkshih@realtek.com> Signed-off-by: Ping-Ke Shih <pkshih@realtek.com> Link: https://patch.msgid.link/20260727064223.61836-1-nihaal@cse.iitm.ac.in
2026-07-30wifi: rtw89: remove conditional return with no effect in sys_init_*()Sang-Heon Jeon2-10/+2
Both branches of the check return the same value, so the check has no effect. Remove it and return the value directly. This is the result of running the Coccinelle script from scripts/coccinelle/misc/cond_return_no_effect.cocci. Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com> Acked-by: Ping-Ke Shih <pkshih@realtek.com> Signed-off-by: Ping-Ke Shih <pkshih@realtek.com> Link: https://patch.msgid.link/20260726134034.1385834-3-ekffu200098@gmail.com