Skip to content

UPDATE: 6.18.51 - #1372

Open
fepitre-bot wants to merge 3 commits into
QubesOS:stable-6.18from
fepitre-bot:update-v6.18.51
Open

fepitre-bot wants to merge 3 commits into
QubesOS:stable-6.18from
fepitre-bot:update-v6.18.51

Conversation

@fepitre-bot

Copy link
Copy Markdown
Contributor

Update to 6.18.51

Details

Changes since previous version:
gregkh/linux@ffa4f0be6965 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
gregkh/linux@bdf5deccfbf9 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
gregkh/linux@af2d3f6f29b0 drm/xe/guc_ads: allocate UM queues in a separate BO
gregkh/linux@a65b52f6cdc9 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX
gregkh/linux@8be5f23ae949 drm/xe/guc_ads: use uncached mapping for UM queue BO
gregkh/linux@c0a9bd5fca0b KVM: x86/mmu: Check write tracking in all address spaces
gregkh/linux@64561afb42d8 nvme-tcp: fix usage of page_frag_cache
gregkh/linux@71ecdc1ba07f Revert "selinux: reject a permission value exceeding the class permission count"
gregkh/linux@4ac3cc8a14db selinux: use u16 for security classes
gregkh/linux@42c5747a9f83 selinux: more strict policy parsing
gregkh/linux@dfc59a062c38 selinux: reject a permission value exceeding the class permission count
gregkh/linux@9ebaeeb6c2d4 selinux: require a class's permission values to cover its permission count
gregkh/linux@13d20517bee1 ASoC: nau8821: Cancel delayed work on component remove
gregkh/linux@85dc711f742b bpf: Fix use-after-free in offloaded map/prog info fill
gregkh/linux@0599aa23734c riscv: Fix register corruption from uninitialized cregs on error
gregkh/linux@caacbfb36721 ASoC: nau8821: Cancel pending work before suspend
gregkh/linux@34aef83af724 selinux: switch two allocations to use kzalloc_objs()
gregkh/linux@f2192741bdfc veth: fix OOB txq access in veth_poll() with asymmetric queue counts
gregkh/linux@b61ebb2826ca powerpc/hv-gpci: fix preempt count leak in sysfs show paths
gregkh/linux@2b7c6b90ce80 io_uring/futex: only mark private futex waits as inflight
gregkh/linux@e973a371d35a io_uring: simplify IORING_SETUP_DEFER_TASKRUN && !SQPOLL check
gregkh/linux@0bcec5dda029 io_uring/rsrc: improve regbuf iov validation
gregkh/linux@e22f4494cc94 io_uring: defer eventfd signaling when queued from a wakeup handler
gregkh/linux@70589b0c005d HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()
gregkh/linux@d0754db7883c HID: asus: simplify RGB init sequence
gregkh/linux@8b5debb6252c HID: asus: fix missing hid_is_usb() check
gregkh/linux@30c37ac21a45 HID: ft260: validate i2c input report length
gregkh/linux@a8e1f970f904 HID: ft260: fix stack-use-after-return write in I2C read race
gregkh/linux@6106fb7962a0 ksmbd: harden file lifetime during session teardown
gregkh/linux@8ec7271e05df fpga: dfl: fme: add error handling
gregkh/linux@9786c42df8ef accessibility: speakup: unregister tty ldisc on later init failures
gregkh/linux@56f20a406cc3 usb: xhci: Handle bogus TRB pointers in Missed Service Error events
gregkh/linux@45dbddc389c5 usb: xhci: Handle USB3 port events when there is one roothub
gregkh/linux@0d0faf3cc44c xhci: dbgtty: Fix unregister on tty_register_driver() failure
gregkh/linux@0f127d522dbc xhci: dbgtty: Fix unregister on tty_alloc_driver() failure
gregkh/linux@1758730d9eaa fuse: fix invalidate lock leak on setattr writeback failure
gregkh/linux@776e85fda752 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
gregkh/linux@3f6face69034 usb: usbtest: disable dynamic ID support
gregkh/linux@85aa61fedcb4 usb: gadget: f_tcm: keep port count until LUN teardown completes
gregkh/linux@dd1638c95163 KVM: SEV: Drop FOLL_WRITE for encrypted region registration
gregkh/linux@2de20fea6204 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests
gregkh/linux@a3d45c2d645c KVM: SEV: Extract loading of guest-provided VMSA to a separate helper
gregkh/linux@9a45e7b0b140 KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable
gregkh/linux@0b0a668febb6 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y
gregkh/linux@fadbc1ed2a87 tls: device: fix out-of-bounds write in tls_append_frag()
gregkh/linux@3d950e98f74a gtp: serialize PDP context updates
gregkh/linux@b5d1534db32a x86/CPU/AMD: Carve out a Zen5 models range
gregkh/linux@452774776023 net/tcp: fix TCP-AO key deletion in VRFs
gregkh/linux@70051a57786d tcp: fix AO info use-after-free in tcp_ao_connect_init()
gregkh/linux@73fde8fe4469 net/tcp-ao: fix use-after-free of current_key on reconnect to another peer
gregkh/linux@24efebecf415 xfrm: espintcp: fix UAF during close
gregkh/linux@328e40aa774b xfrm: drop ESP-in-TCP packets with no ingress device
gregkh/linux@5c86c895d1ca xfrm: avoid lock inversion in nat keepalive work
gregkh/linux@6733ae71268a xfrm: ah6: validate routing header segments_left
gregkh/linux@cf67361e78dc xfrm: fix xfrm_state_construct() auth-trunc leak
gregkh/linux@50229d334558 xfrm: bound nat keepalive state collection
gregkh/linux@c069f29da723 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context
gregkh/linux@3e4476e58343 ipv6: seg6: clear IPv4 control block on IPIP decapsulation
gregkh/linux@916ec741e65a batman-adv: reject unrepresentable multicast TVLV offsets
gregkh/linux@a8820c8a7718 vxlan: keep the last remote linked during FDB flush
gregkh/linux@07ee91e6b7b0 netfilter: nft_set_pipapo_avx2: add missing vzeroupper
gregkh/linux@6fa88d11983c netfilter: nf_tables: don't queue packet path object notifications
gregkh/linux@34f3c35dd13a mm/swap: reject swapon() on filesystem-level encrypted files
gregkh/linux@e90bc78125cd kunit: irq: Continue increasing hrtimer interval for longer
gregkh/linux@5545de5050cb crypto: virtio - bound the akcipher result length
gregkh/linux@070b73019a53 crypto: qcom-rng - Enable clock in hwrng case
gregkh/linux@14d9ee828646 crypto: qcom-rng - Remove crypto_rng interface
gregkh/linux@4c0018320942 crypto: qcom-rng - Allow zero as a random number
gregkh/linux@302ecd110606 crypto: atmel-tdes - use scatterlist length before DMA mapping
gregkh/linux@731a5b6fb4c1 crypto: krb5 - use kfree_sensitive() for derived key buffers
gregkh/linux@2f65718b9c10 crypto: qce - fix CCM AAD buffer underallocation
gregkh/linux@182f16a20d32 crypto: mxs-dcp - fix source scatterlist length access
gregkh/linux@545a6b9c91e2 crypto: qce - Remove unsafe/deprecated algorithms
gregkh/linux@935eeba27601 KVM: s390: vsie: zero stale crypto bits
gregkh/linux@d80b94680467 usb: core: Add lock to usb_wakeup_notification()
gregkh/linux@7eb02825b368 usb: core: Strengthen error handling in hub_hub_status()
gregkh/linux@91919b3b99ab ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
gregkh/linux@6d3e202670b8 ALSA: usb-audio: Complete cleanup after system-resume errors
gregkh/linux@2ef5560387f2 USB: serial: option: fix slab OOB read in interrupt URB callback
gregkh/linux@683df50fff0f USB: serial: spcp8x5: drop broken carrier detect support
gregkh/linux@b4cb8081cf80 USB: c67x00: fix use-after-free in c67x00_add_iso_urb()
gregkh/linux@22edb6786127 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb
gregkh/linux@5f08c45bdcfd usb: usbfs: fix use-after-free of usb_device in usbdev_release()
gregkh/linux@1c732c6b94f0 Linux 6.18.49
gregkh/linux@c79ef3342632 perf/x86/intel/uncore: Fix die ID init and look up bugs
gregkh/linux@8527ac1bce87 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
gregkh/linux@5fc3d921512d wifi: ath11k: fix memory leaks in beacon template setup
gregkh/linux@a8bbb2a60513 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
gregkh/linux@5d562153b471 ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS
gregkh/linux@ea150ffa9fc9 bpf: Fix incorrect pruning due to atomic fetch precision tracking
gregkh/linux@24ebaf6676ae nsfs: tighten permission checks for handle opening
gregkh/linux@2ab18de5ebb1 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
gregkh/linux@ce493f9261cd platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()
gregkh/linux@d5c9d19b0ff2 netfs: Fix missing locking around retry adding new subreqs
gregkh/linux@a1fa3d1197cc drm/amd/display: Skip PHY SSC reduction on some 8K panels
gregkh/linux@c6b915f0df31 drm/amd/display: Refactor amdgpu_dm_connector_detect (v2)
gregkh/linux@7d860bed1336 drm/amd/display: hide Apple Studio Display secondary tile
gregkh/linux@4628e40c9ca7 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile
gregkh/linux@7d00a3ff6244 alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
gregkh/linux@c25b2aa077d5 rust: time: fix as_micros_ceil() rounding near i64::MAX
gregkh/linux@312f85fdd029 alpha: don't leak hardware-fabricated FP exception bits to user space
gregkh/linux@d53c29a89a15 clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
gregkh/linux@bf38be01d43c clocksource/drivers/timer-sun4i: Advertise a real minimum delta
gregkh/linux@c03114634d34 fs: fix user path of nested backing files
gregkh/linux@e6da8a0f3976 powerpc/pseries/iommu: switch to Default DMA window during kdump
gregkh/linux@2bf5e8f7c9bf timers/itimer: Zero-init old itimerval before copy to userspace
gregkh/linux@138722d631ac rust: bug: skip arch-specific asm in testlib builds
gregkh/linux@0a10989de610 rust: kernel: list: fix incorrect pop_back example comment
gregkh/linux@753c978f2400 KEYS: trusted: Fix TPM teardown ordering
gregkh/linux@587a6a92b93e apparmor: fix cred UAF caused by begin_current_label_crit_section()
gregkh/linux@28069434aef6 apparmor: fix out-of-bounds write when null terminating a label vec
gregkh/linux@f2c14f4d427d include/linux/list.h: mark list_add and __list_add as __always_inline
gregkh/linux@d423737dca23 mm, swap: ratelimit bad swap entry reports
gregkh/linux@2cfa9ae90813 mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios()
gregkh/linux@3fc8044251de mm/kmemleak: avoid soft lockup when scanning task stacks
gregkh/linux@5dc0daff0341 mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
gregkh/linux@45489d4f9580 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
gregkh/linux@895cd4ecbb2e mm/pagewalk: fix stale walk->action escaping walk_pmd_range()
gregkh/linux@3fd502399863 mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
gregkh/linux@ef765a2e4f57 mm/zswap: fix global shrinker when memory cgroup is disabled
gregkh/linux@295f5a61d3ae mm: compaction: support non-movable compaction for pageblock requests
gregkh/linux@d0943afb5ed8 mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings
gregkh/linux@680b93894ddf mm: memcg-v1: fix memsw and TCP failcnt accounting
gregkh/linux@95d87030cae7 mm: memcg: stop reclaim when a limit update is superseded
gregkh/linux@5d866086d5f8 mm: memcontrol: update state_local when flushing NMI stats
gregkh/linux@b3d4b65085ef mm: mempolicy: fix automatic numa balancing for shmem
gregkh/linux@0df04778ea14 mm: page_alloc: __GFP_FS lockdep annotation for direct compaction
gregkh/linux@d435ba3c21a0 mm: page_alloc: move capture_control to the page allocator
gregkh/linux@461d23368f29 mm: page_alloc: fix non-movable reclaim storm in defrag_mode
gregkh/linux@d4bf3a74e2ba mm: vmscan: fix node reclaim ignoring swappiness parameter
gregkh/linux@968eea465942 tools/compiler: match glibc 2.42 definition of attribute_const
gregkh/linux@08b4cdef3c2e x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg()
gregkh/linux@b9ae969e6f1e x86/locking: Use sfence for wmb() if SSE is available
gregkh/linux@c4a221548708 x86/tdx: Fix off-by-one in port I/O handling
gregkh/linux@9b51dcb4f230 x86/tdx: Fix zero-extension for 32-bit port I/O
gregkh/linux@b503a61d5d39 hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start()
gregkh/linux@25a0758cf6bd tracing/user_events: Clear copied tracing state before fork duplication
gregkh/linux@adadf4192f70 tracing: Fix crash passing ERR_PTR to kthread_stop()
gregkh/linux@cdb6fb6cf1a7 tracing: Fix logged instance name on creation failure
gregkh/linux@ddbe921ed16a tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
gregkh/linux@b1a49c22de01 tracing: Fix use-after-free with same-name named triggers
gregkh/linux@4cd24873ab9f cdx: Fix double free when sysfs file creation fails
gregkh/linux@ba69d892ff4e device property: fix infinite loop in fwnode_for_each_child_node()
gregkh/linux@29e634a18957 misc: nsm: bound the device-reported response length
gregkh/linux@c3d4be91c6fc powerpc/powermac: fix OF node refcount
gregkh/linux@e6e925cc1f80 rapidio: mport_cdev: fix use-after-free in dma_req_free()
gregkh/linux@aad08b5f67d2 Revert "media: v4l2-dev: fix error handling in __video_register_device()"
gregkh/linux@28b932202fcd serial: imx: serialize imx_uart_ports[] lifetime
gregkh/linux@78f5c6e6aef9 staging: greybus: hid: fix SET_REPORT return value
gregkh/linux@316abfe39dce usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
gregkh/linux@448e95c0f3ea usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
gregkh/linux@51a311eb97e9 usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed
gregkh/linux@12414bbd3e3f USB: phy: fsl-usb: fix missing static keywords
gregkh/linux@d793bd8422e7 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive()
gregkh/linux@ebb840d982a6 usb: typec: thunderbolt: Disable work before freeing tbt on remove
gregkh/linux@14fa29f3be06 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion
gregkh/linux@4e747c864a88 usb: gadget: u_audio: Fix use-after-free on sound card disconnect
gregkh/linux@64005cf3e897 usb: gadget: snps_udc_plat: clean up PHY on probe deferral
gregkh/linux@a15c2acd3083 usb: gadget: midi2: remove default configfs groups on teardown
gregkh/linux@6bcd9ee6ad69 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
gregkh/linux@dbe2762ae8e5 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init()
gregkh/linux@9897b7da8c0a usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
gregkh/linux@34e88f536146 usb: gadget: f_fs: Prevent deadlock during ep0 read loop
gregkh/linux@827ec385458a fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
gregkh/linux@9f43499ce645 HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
gregkh/linux@7d658da725ea lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
gregkh/linux@0c260d3f97e5 media: cec: stm32: prevent out-of-bounds write on RX overflow
gregkh/linux@8c14472431e2 media: vicodec: fix out-of-bounds write in FWHT encoder
gregkh/linux@448636c745a3 nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
gregkh/linux@9253cfc5a85b of: fix out-of-bounds read in of_alias_scan() stem parser
gregkh/linux@e892f05f1f79 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
gregkh/linux@14afe18655c0 phy: rockchip-samsung-dcphy: fix out-of-range max_register
gregkh/linux@a1dc246f98bb ubifs: fix out-of-bounds read in signature length check
gregkh/linux@923578d0f0d0 zram: validate deflate params
gregkh/linux@344ae0e232d4 zsmalloc: account for handle size in class lookup
gregkh/linux@5215e734bf7c NFS/localio: fix ref leak on nfs_uuid_add_file failure
gregkh/linux@f3adf1643517 NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails
gregkh/linux@d8352da19634 NFSD: check truncate permission under inode lock
gregkh/linux@e547b06234f8 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
gregkh/linux@75d13317f163 NFSD: Fix off-by-one in DRC bucket pruning limit
gregkh/linux@4ed8d2317aef NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
gregkh/linux@7ef182a8fe9c NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
gregkh/linux@59baf45a0643 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
gregkh/linux@36e3f13bf072 NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
gregkh/linux@dc803d46a8b9 pNFS: Fix EBUSY check in pnfs_layout_need_return
gregkh/linux@f164eb52b6f3 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
gregkh/linux@467d56fd3ff5 nfsd: release path refs on follow_down() error
gregkh/linux@591134e059e3 nfsd: Reset write verifier when async COPY writeback fails
gregkh/linux@fc83f30731dd nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
gregkh/linux@8277d4a11ae2 nfsd: sample writeback error cursor before async COPY loop
gregkh/linux@1e4795766719 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
gregkh/linux@7ff8d6363cff nfsd: size fh_verify server sockaddr slot by xpt_locallen
gregkh/linux@7e7b93da7fa2 nfsd: validate nseconds in TIME_DELEG decode paths
gregkh/linux@2aca70c18c5f nfsd: validate sockaddr length per family in listener_set
gregkh/linux@895a485cd375 nfsd: validate symlink target length in NFSv4 CREATE
gregkh/linux@533964d420d3 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
gregkh/linux@bff024551a71 nfsd: add filehandle match check to nfsd4_delegreturn()
gregkh/linux@1aea0482b98e nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
gregkh/linux@311f7d926630 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
gregkh/linux@b42dc26a14b4 nfsd: check client ownership when cancelling a copy-notify stateid
gregkh/linux@b137930ee52e nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
gregkh/linux@e879148867bd nfsd: clear opcnt on compound arg release to prevent OOB read
gregkh/linux@631b7d5dbbba nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper
gregkh/linux@6703199f4d7e nfsd: defer vfree of compound ops to fix rpc_status UAF
gregkh/linux@72d40b103bb0 nfsd: don't free session slots that are still in use
gregkh/linux@00843074d9b8 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
gregkh/linux@607a56fea772 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
gregkh/linux@a631a26a8777 nfsd: fix cpntf publish race in nfs4_init_cp_state
gregkh/linux@c1ae0f973bcb nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
gregkh/linux@65c79d9bb371 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types
gregkh/linux@360e1b9e3f31 nfsd: fix netlink dumpit error handling for rpc_status_get
gregkh/linux@424d5c95108a nfsd: fix nfsd_file leak on inter-server COPY setup failure
gregkh/linux@3c5119b799a7 nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
gregkh/linux@cf081015a0d1 nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure
gregkh/linux@2ebbf4e3e9cf nfsd: fix reply size estimate for GET_DIR_DELEGATION
gregkh/linux@9b4e5e9ba5ae nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
gregkh/linux@4106d7a6aaf1 nfsd: fix version mismatch loops in nfsd_acl_init_request()
gregkh/linux@0380129b1373 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
gregkh/linux@41ebca28e17f nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
gregkh/linux@f951b22dbeec nfsd: gate nfs2 setacl by argp->mask
gregkh/linux@b3bff820d068 nfsd: gate nfs3 setacl by argp->mask
gregkh/linux@763c0bad8723 nfsd: hold rcu across localio cmpxchg retry
gregkh/linux@a4d7fedcaaf3 nfsd: initialize copy-notify stateid before publishing it
gregkh/linux@b57bd8cb739c nfsd: initialize DRC hash table before registering shrinker
gregkh/linux@4ae5d7490ae6 nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
gregkh/linux@54e02f5e32c5 nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
gregkh/linux@ad02d095439f nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
gregkh/linux@dbc11a12aa54 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
gregkh/linux@b56d2c5f01cd nfsd: revoke copy-notify stateids before dropping their reference
gregkh/linux@4804c58f73a8 NFSD: Prevent lock owner use-after-free during client teardown
gregkh/linux@b413ec5b23e3 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
gregkh/linux@2571b3588326 libceph: validate OSD extent maps before cursor advance
gregkh/linux@00562ccd4e88 libceph: reject buckets with mismatched CRUSH ids
gregkh/linux@fe46746087b5 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
gregkh/linux@4d298880f82c ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
gregkh/linux@06fb5e623cdc ceph: bound copied dentry name length in NFS export get_name
gregkh/linux@c37db86d2b5e ceph: bound MDSCapAuth path and fs_name decode in handle_session()
gregkh/linux@58c2d3e954c1 ceph: bound num_export_targets array for mds info v2/v3
gregkh/linux@1dd356310b16 ceph: bound xattr value length in __build_xattrs()
gregkh/linux@37d6edb2f03b ceph: do not repeat ceph_trim_dentries() if no progress possible
gregkh/linux@ec32015a955c ceph: fix leaked inode reference on writeback abort at umount
gregkh/linux@8a64baeb5bbb btrfs: drop recovered reloc root refs on recovery failure
gregkh/linux@f42efd634c0a btrfs: fix extent map leak in NOCOW direct I/O write
gregkh/linux@25128202a8df btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag
gregkh/linux@636a99bab36b audit: avoid dropping live tree ref on fsnotify rule autoremove
gregkh/linux@4f18c9e7ee46 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
gregkh/linux@c2a0dcb5a7a1 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
gregkh/linux@8b9b10fe5b8b cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
gregkh/linux@9ab46a13798a smb: client: clear ce->tgthint in free_tgts()
gregkh/linux@1f824f61d1df smb: client: fix ALIGN() overflow in symlink_data() error context loop
gregkh/linux@17a1922ada87 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
gregkh/linux@846f0709559b smb: client: harden DFS cache against invalid target hints
gregkh/linux@e78973fe3ef5 HID: apple: preserve keyboard backlight across T2 resume
gregkh/linux@79465a30050d HID: corsair-void: Check size of status and firmware events before reading them
gregkh/linux@471f4a939c66 HID: picolcd: clamp eeprom debugfs read to bytes actually received
gregkh/linux@da00eac19fee HID: roccat: free buffered reports when destroying device
gregkh/linux@f3f37b937a6e HID: sensor: custom: Fix field sysfs group cleanup on failure
gregkh/linux@114a58640aaf HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
gregkh/linux@01d9874e84d3 HID: universal-pidff: stop the device when force-feedback init fails
gregkh/linux@c99ba6c234d4 HID: mcp2221: stop device IO before hid_hw_stop
gregkh/linux@127de5919820 HID: mcp2221: validate report size in mcp2221_raw_event()
gregkh/linux@6fcefe71aeb5 HID: intel-thc-hid: intel-quickspi: validate report size before copy
gregkh/linux@72706b44b665 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
gregkh/linux@99f3e197920d HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown
gregkh/linux@b2301bdb4b3e HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown
gregkh/linux@5333e18e6b42 eventfs: Initialize ei->children and ei->list in init_ei()
gregkh/linux@2d94ffc9d7b5 fs/ntfs3: validate dirty page table on log replay
gregkh/linux@376ee45659a4 fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
gregkh/linux@7ccb94901f38 fs/ntfs3: bound page_lcns[] index by the log record
gregkh/linux@98b890563424 eCryptfs: bound the packet-length peek to the user buffer
gregkh/linux@c1bc956a615d ecryptfs: fix tag 11 packet exact-fit size check
gregkh/linux@0d9636ecba34 ecryptfs: hold msg ctx list lock when cleaning daemon queue
gregkh/linux@e5d254e654f2 ecryptfs: pass packet set buffer size to parser
gregkh/linux@14cb36a500a5 ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
gregkh/linux@b31da1ecf139 ecryptfs: reject too-small tag 70 packets
gregkh/linux@9319706316a8 ecryptfs: release message context on send failure
gregkh/linux@ce568f6e025d ecryptfs: show filename encryption options
gregkh/linux@92895a14329c efivarfs: Rate limit statfs() handler
gregkh/linux@66aa9a9e6481 fanotify: fix use-after-free of file range info
gregkh/linux@2f66f8ceefc2 fat: restore original value when fat_ent_write failed
gregkh/linux@76818e81cfca fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
gregkh/linux@3c1b5809615c fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
gregkh/linux@3bcab9b21f71 fbdev: ssd1307fb: defer I2C transfers from damage callbacks
gregkh/linux@466a8af0dee2 fbdev: uvesafb: unregister connector callback on init failure
gregkh/linux@0c3f4544ff38 forcedeth: fix off-by-one when saving/restoring non-PCI config space
gregkh/linux@137c61a6cfd9 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
gregkh/linux@4e019e5e247b hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
gregkh/linux@a3c65af20cce hugetlb: only adjust reservation during unmapping if mapcount is 0
gregkh/linux@c1a5bf1b6e1d accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
gregkh/linux@304323029665 accel/rocket: initialize job domain before cleanup paths
gregkh/linux@9ad8821573a3 accel/rocket: Fix error path handling in rocket_job_run()
gregkh/linux@c735dbce7ad0 acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
gregkh/linux@b7476b29b696 ACPI: APEI: Fix ERST timeout unit conversion
gregkh/linux@452eb28e0301 ACPI: APEI: GHES: fix ARM section length accounting after header
gregkh/linux@6d4ed2fd022b ACPI: pfr_update: fix stack buffer overflow in query_capability()
gregkh/linux@2fd984c44e3e alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
gregkh/linux@9e1eefc01912 alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
gregkh/linux@87d07aa5d38b alpha: marvel: Fix lock ordering in init_io7_irqs()
gregkh/linux@fdc0a5e2cbac ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
gregkh/linux@c2e3dccd6870 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
gregkh/linux@84858671842a auxdisplay: charlcd: cancel backlight work on registration failure
gregkh/linux@ce76ca5fb279 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
gregkh/linux@aa7b93fe98ba Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
gregkh/linux@bce588b4ca08 Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU
gregkh/linux@f609eac02d11 Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728
gregkh/linux@c21fa79301d7 Bluetooth: eir: Fix OOB read in eir_get_service_data()
gregkh/linux@4d36e38e4834 bnx2x: fix double free in bnx2x_init_firmware() error path
gregkh/linux@49dcefa83c8a bnxt_en: Write doorbell when linearizing skb fails
gregkh/linux@6886642414f5 bpf, x86: Fix per-CPU address resolution into an extended register
gregkh/linux@dbfecc8a6631 bpf: Disable preemption in __bpf_get_stack
gregkh/linux@c9189693db47 buffer: avoid tail commit walk for uptodate folios
gregkh/linux@272fcb4ba6fa bpf: Harden bloom filter sizing and indexing on 32-bit kernels
gregkh/linux@9493ac67623d dm-io: clone the source bio instead of copying its biovec
gregkh/linux@49694a363f7e dm-io: report non-retryable errors separatedly
gregkh/linux@36ff918637e3 dm-era: fix shadowed superblock leak on take-snap failure
gregkh/linux@644140527ae4 dm raid1: reserve space for NUL-terminator in build_constructor_string()
gregkh/linux@b33f76d33aae dm array: validate array block headers on read
gregkh/linux@ac4a5eb8b002 dm array: reject an array block whose value size is not the caller's
gregkh/linux@a807a9ef87ad coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior
gregkh/linux@2924b2e36514 cpufreq: schedutil: Fix rate limit overflow
gregkh/linux@14d52c15d5d9 cxl/features: bound fwctl command payload to the input buffer
gregkh/linux@c674c504bfdd cxl/pmem: Format the nvdimm serial number as unsigned decimal
gregkh/linux@1ed5982c5369 Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378
gregkh/linux@62100186f177 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@ec3992e38f77 Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
gregkh/linux@49fd7116f76b Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
gregkh/linux@946d76db77ee Bluetooth: RFCOMM: serialize security confirmation handling
gregkh/linux@68e7a31abc88 Bluetooth: hci_conn: re-enable advertising only for peripheral role
gregkh/linux@d0b28e9655f4 Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
gregkh/linux@1bad0896cbc0 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
gregkh/linux@94d548fc264a Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@657054159d83 Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative
gregkh/linux@15deb4e33f47 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
gregkh/linux@30e8cb8598aa kasan: fix cache shrink race with CPU hotplug
gregkh/linux@71c6b872c746 jbd2: bound shrinker scans by examined checkpoint buffers
gregkh/linux@f9182a85991a jbd2: check need_resched() when skipping busy checkpoint buffers
gregkh/linux@31e4be21dace ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
gregkh/linux@a8af6fbac895 ip: orphan prefetched skbs before multicast forwarding
gregkh/linux@b36dfd6e8cff ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
gregkh/linux@b8282668d8fa ip6_gre: fix hardware header length for NBMA tunnels
gregkh/linux@63f50e9f90d0 ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
gregkh/linux@a602cd128d17 ipv6: use RCU iterator to dump route exceptions
gregkh/linux@627ce4902df1 landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
gregkh/linux@09e649117c54 libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
gregkh/linux@121d35014e49 mailbox: qcom-ipcc: fix duplicate channel allocation across holes
gregkh/linux@0efabe6229dc md/raid10: fix still_degraded being inverted in raid10_sync_request()
gregkh/linux@3b097416b4cf md: do overflow check for sb->bblog_shift in super_1_load()
gregkh/linux@50d0aa7d25ba module: validate string table section types
gregkh/linux@d82b90a38c2c mpls: reload header after pskb_may_pull()
gregkh/linux@51887ccd8879 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
gregkh/linux@04ab51d4e369 module/kallsyms: fix nextval for data symbol lookup
gregkh/linux@ff110e85837d nouveau/gem: reserve the bo in the info ioctl around the vma lookup
gregkh/linux@704ecd010d4a params: fix charp corruption on allocation failure
gregkh/linux@f1b7b2c7ffa9 phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
gregkh/linux@ad0cce80d4af SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
gregkh/linux@e0778464049b SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
gregkh/linux@de942dd8c2c8 SUNRPC: svcauth_gss: enforce krb5 token minimum length
gregkh/linux@9d04d64ad192 sunrpc: route to a populated pool in svc_pool_for_cpu()
gregkh/linux@39981133df21 SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode
gregkh/linux@2e861ce2aaa4 SUNRPC: always drain cache_cleaner before destroying a cache_detail
gregkh/linux@bd1ef2cfb44d SUNRPC: Check svc pool percpu counter allocation
gregkh/linux@08bc49e05412 sunrpc: defer rq_argp and rq_resp free until after RCU grace period
gregkh/linux@e769fcde3cc7 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
gregkh/linux@fa46b6aa7a69 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
gregkh/linux@806584a4b67a SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
gregkh/linux@ebcbd2523a85 SUNRPC: harden gss_unwrap_resp_priv length checks
gregkh/linux@edeefb111d61 sunrpc: init gssp_lock before publishing proc entry
gregkh/linux@7a1d0501cbb9 SUNRPC: reject duplicate CREDS_VALUE options
gregkh/linux@1f9856af065b SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
gregkh/linux@1de391e8b94e SUNRPC: wait for in-flight client TLS handshake callback
gregkh/linux@a46b35f213c2 svcrdma: Fix offset arithmetic in read_chunk_range
gregkh/linux@a1c954ca4977 svcrdma: Fix pcl_for_each_segment for empty chunks
gregkh/linux@5aabe070c00e svcrdma: Fix unmatched rn_unregister on failed accept
gregkh/linux@3cf372cec7ab svcrdma: Reject connection when transport allocation fails
gregkh/linux@1949dd1576f7 svcrdma: Reject inline replies that overflow the pull-up buffer
gregkh/linux@a798714b5804 svcrdma: Reject Write/Reply chunks with segcount 0
gregkh/linux@f84ec84d8d4b svcrdma: Validate Read chunk positions before reconstruction
gregkh/linux@b95c33a4e743 udf: reject VAT indexes equal to the entry count
gregkh/linux@e1330d719c04 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
gregkh/linux@5be6d02837d4 wifi: mt76: mt7925: cancel pending mlo_pm_work
gregkh/linux@656d047dc0c2 staging: media: tegra-video: fix of_node_put() on VIP parse errors
gregkh/linux@7f6956b6dcd6 staging: media: tegra-video: vi: fix probe failure on skipped last port
gregkh/linux@2a8dd9fd12f3 media: staging/ipu7: fix async notifier UAF on probe error path
gregkh/linux@e7143c3f4e5c scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
gregkh/linux@eb57632f9418 rpmsg: glink: smem: order FIFO read after availability check
gregkh/linux@ff23eb4823d8 Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro"
gregkh/linux@6bb9469c34ff arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags
gregkh/linux@b6b3e4d5973b arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on
gregkh/linux@fe455c13bf01 arm64: dts: rockchip: fix eMMC reset polarity on PP-1516
gregkh/linux@5512c2323120 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
gregkh/linux@650d2d5c0df7 arm64: dts: rockchip: fix emmc reset polarity on px30-cobra
gregkh/linux@8fc4bafabc06 arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
gregkh/linux@5343399ed724 arm64: dts: rockchip: Fix rk3588s-roc-pc audio description
gregkh/linux@8f392916a354 riscv: acpi: Handle LPI architectural context loss flags
gregkh/linux@37797d5013c9 riscv: unaligned: stop using kthread for check_vector_unaligned_access()
gregkh/linux@c7e32814a6bf remoteproc: scp: Fix device reference leak on failed lookup
gregkh/linux@3f5677d2f817 ptp: vmclock: prevent read-only mappings from becoming writable
gregkh/linux@2a952fb1b20d qede: Fix NULL pointer dereference in TPA fragment processing
gregkh/linux@85f438382a86 RDMA/cxgb4: Cancel reg_work before freeing device on remove
gregkh/linux@a38cd610b24f RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget
gregkh/linux@28ac2dd41648 RDMA/ucma: Lock the handler in ucma_set_ib_path()
gregkh/linux@4f8bb11dd2ff RDMA/ucma: Lock the handler in ucma_write_cm_event()
gregkh/linux@71d5c41ac583 RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
gregkh/linux@95342d26f9c6 regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
gregkh/linux@20e5fbb8c1a4 regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
gregkh/linux@1c3036a81800 regulator: qcom-refgen: correct the regulator type to CURRENT
gregkh/linux@2dc510957fe8 ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
gregkh/linux@8c1ecdcdea73 ring-buffer: Free cpu_buffer::free_page with subbuf_order
gregkh/linux@6fcb0b745a0b ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
gregkh/linux@bc6fdd425fde PM: sleep: Unblock runtime PM when device prepare fails
gregkh/linux@f796f38a324e orangefs: fix double-free of trailer_buf on readdir copy failure
gregkh/linux@116d14f29a05 orangefs: skip leading spaces before parsing client debug masks
gregkh/linux@71f07b7f90b3 ocfs2: always run deallocs on copy-on-write completion
gregkh/linux@de10cd3b062a ocfs2: bound namelen in dlm_migrate_request_handler
gregkh/linux@50c4cc9183e1 ocfs2: validate lengths in dlm_mig_lockres_handler
gregkh/linux@0761d2c94944 ocfs2: validate rl_used against rl_count in refcount block validator
gregkh/linux@ce035f208d68 ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
gregkh/linux@251e38f5af7b ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
gregkh/linux@0608018a71f2 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
gregkh/linux@c0c165487a2e ocfs2: fix readdir position truncation on 32-bit kernels
gregkh/linux@d64a75369cd0 openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
gregkh/linux@e41a59fc056f openvswitch: only skb_tx_error() a packet we are about to drop
gregkh/linux@15d1feeae07d ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
gregkh/linux@e7c9b1d433b0 arm64: compat: Fix decrementing LDM/STM alignment emulation
gregkh/linux@f2a1a83487c6 arm64: proton-pack: Restore the nospectre_bhb command-line option
gregkh/linux@68c59343ad1a ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
gregkh/linux@9b38d9a2e46a hwmon: (max6621) fix negative temperature offset and crit readings
gregkh/linux@8d2c120d2d5b hwmon: (max6621) fix temperature clamp range
gregkh/linux@6aeff1636b39 i2c: mxs: fix DMA channel leak on probe error
gregkh/linux@3088e41292fe ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
gregkh/linux@41f0a6d31615 lockd: pin next file across nlm_inspect_file lock-drop
gregkh/linux@d662f7fc04fd lockd: fix NULL dereference on lockowner allocation failure
gregkh/linux@1e456cc2744e nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
gregkh/linux@67551d8430df nvme: zero the discard fallback page
gregkh/linux@0d4f317b07d6 nvme-pci: disable controller on admin queue IRQ setup failure
gregkh/linux@6a01b5826310 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
gregkh/linux@3b3d27670c0c nvme-tcp: fix host memory disclosure on R2T for a read command
gregkh/linux@8a02ad98798f nvme-tcp: reject a read that transferred too few bytes
gregkh/linux@fa306a40e716 sctp: stop processing a packet once its association is deleted
gregkh/linux@1035bdef1efb sctp: drop a chunk if its transport was removed
gregkh/linux@25419f516ea8 sctp: fix NULL deref on untransmitted RECONF completion
gregkh/linux@7ad8933bca97 sctp: distinguish sequence zero from wildcard in reconf lookup
gregkh/linux@d02a5794c3de sctp: fix stream->outcnt underflow on duplicate RECONF responses
gregkh/linux@f495808cdd6d power: supply: bq24257: fix use-after-free on remove
gregkh/linux@9e1aba34df9a power: supply: bq256xx: drain usb_work before freeing the charger
gregkh/linux@238320ad029a power: supply: bq25890: Fix power_supply reference leak
gregkh/linux@86e4fa65368f power: supply: charger-manager: register regulators before exposing sysfs
gregkh/linux@78be8b7403ff power: supply: cros_usbpd-charger: bound the EC-reported port count
gregkh/linux@4b1f2be1e1b7 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
gregkh/linux@ab6b1ad710be power: supply: lp8727: fix use-after-free in lp8727_release_irq()
gregkh/linux@b3aa1e9509e1 power: supply: lp8788-charger: fix use-after-free on remove
gregkh/linux@06618447029c power: supply: qcom_battmgr: fix use-after-free
gregkh/linux@ee053561e21c power: supply: qcom_battmgr: terminate the strings from firmware
gregkh/linux@1b9978433c61 power: supply: rt9455: quiesce delayed work before teardown
gregkh/linux@a4460e89d408 power: supply: twl4030_charger: cancel workers via devm
gregkh/linux@39b60d615dfa power: supply: ucs1002: fix use-after-free on remove
gregkh/linux@13fb0477da9b power: supply: max17040: propagate register read errors
gregkh/linux@17d43f64b17e power: supply: max17040: drop incorrect I2C functionality check
gregkh/linux@aad7247bd35a power: supply: max17040: synchronize work cancellation on suspend
gregkh/linux@dcce7a06ea69 s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
gregkh/linux@52b331c99baa s390/dasd: Do not complete a failed ESE read as successful
gregkh/linux@6452c13646af s390/dasd: Guard sysfs discipline callbacks against unallocated private data
gregkh/linux@ceafb262475a s390/dasd: Propagate partial completion length across ERP recovery
gregkh/linux@6053d6eacbfd PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip
gregkh/linux@1ad699485385 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
gregkh/linux@5d4bc470330a PCI: meson: Fix GPIO state while requesting PERST#
gregkh/linux@01c2f0c66bd1 PCI: plda: Fix use-after-free of event IRQs during teardown
gregkh/linux@4b575052ea65 PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
gregkh/linux@43cf455dd5a9 PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
gregkh/linux@7f4db64f0ba7 PCI/sysfs: Fix read byte order in pci_read_legacy_io()
gregkh/linux@6beadccc432c PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@4f887d8ed75f PCI/AER: Emit TLP Log only for unmasked errors
gregkh/linux@39c4dc79d77f PCI/AER: Fix mapping of errors to agent & layer
gregkh/linux@0e59a232aaa0 PCI/ASPM: Avoid L0s for Realtek RTS525A
gregkh/linux@b30713111325 PCI/MSI: Enable memory decoding before restoring MSI-X messages
gregkh/linux@301288f85679 PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
gregkh/linux@c2d4174f4924 PCI/proc: Use file_ns_capable() when checking config space read access
gregkh/linux@238e1f7a1463 PCI/proc: Warn on writes to kernel-exclusive config space regions
gregkh/linux@cfc5c1b2caa1 iommu/amd: Put PCI device after handling PPR faults
gregkh/linux@f532401be931 iommu/msm: Unwind probe state on registration failure
gregkh/linux@968e9a1f7114 iommu/sva: Set handle->dev before the SVA handle is visible
gregkh/linux@d903d99ffd22 iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
gregkh/linux@2235eafda9b3 iommu/arm-smmu-v3: Manage teardown with devm
gregkh/linux@f80f3acb6916 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
gregkh/linux@364279b5623f iommu/vt-d: Fix no_iommu to disable platform opt-in
gregkh/linux@45705a6bfdb2 iommu/vt-d: Force requesting ACS when tboot is enabled
gregkh/linux@436189ee4bb2 iommufd: Avoid locking internal accesses during unmap
gregkh/linux@4c33d00ad9a9 iommufd: Release current IOAS on xa_store() failure
gregkh/linux@cab289572951 iommufd: Fix UAF in selftest IOPF reporting
gregkh/linux@22222f92b0a5 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
gregkh/linux@1889a9156553 platform/x86: ISST: Validate level in perf mask ioctls
gregkh/linux@82e707eff9e3 platform/x86: ISST: Validate socket ID in clos_assoc ioctl
gregkh/linux@f7ff3027ef00 mmc: via-sdmmc: cancel card-detect work on remove
gregkh/linux@2550f89589ca mmc: via-sdmmc: stop card-detect handling on probe failure
gregkh/linux@c280fcd53b93 platform/x86: ISST: Add a NULL check for sst_inst[]
gregkh/linux@92c5fffa63ad platform/x86: ISST: Just allow 2 bits for SST feature enable
gregkh/linux@b14db79d02bd platform/x86: ISST: Use PP level enable mask
gregkh/linux@5b032e1dda48 platform/x86: ISST: Validate logical CPU id and clos id
gregkh/linux@93268bc3cd84 platform/x86: ISST: Validate parameter for core power state
gregkh/linux@62840acc3044 platform/x86: ISST: Validate parameter for frequency and priority
gregkh/linux@e07a42bb9c90 platform/x86: ISST: Return error during profile addition
gregkh/linux@e1b3f89673bd platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
gregkh/linux@d7cd3e4d7603 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response
gregkh/linux@89a076948ed6 platform/x86: think-lmi: Fix certificate thumbprint sysfs output
gregkh/linux@9c28adde051f platform/x86: think-lmi: Free system certificate signatures
gregkh/linux@56dc46094973 platform/x86: think-lmi: Fix current password length check
gregkh/linux@5eaf7faa9957 platform/chrome: sensorhub: Bound the EC-reported sensor number
gregkh/linux@98d91d5b6a98 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths
gregkh/linux@8178f59d7657 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
gregkh/linux@bc9aa5fe21c3 platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
gregkh/linux@0a14d35ef529 platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
gregkh/linux@0cd1530f84e1 platform/x86: hp-bioscfg: advance elem past consumed array elements
gregkh/linux@dea1a41160e7 platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
gregkh/linux@7cd8fe01aba3 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
gregkh/linux@0f9aad084248 platform/x86: hp-bioscfg: fix heap OOB read on empty password write
gregkh/linux@e3c1c5d1c923 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
gregkh/linux@b15b334fbc3c platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
gregkh/linux@95d2f9b5189d platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
gregkh/linux@a38127df99ae platform/x86: hp-bioscfg: pass validated element count to package parsers
gregkh/linux@0c12a798078b platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
gregkh/linux@417e02f7b605 io_uring/query: cap user size passed to copy_struct_to_user
gregkh/linux@db8147c5d5ad interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
gregkh/linux@5719431ca2b5 ipmi: ipmb: validate write message length
gregkh/linux@d46c97eddcbc ipmi: Remove all sysfs files on registration failure
gregkh/linux@53af3a8bae0a ipmi: si: Fix NULL pointer dereference after failed registration
gregkh/linux@99692252b348 ipmi:msghandler: Cancel work cleanly on an error
gregkh/linux@8e3763f1ccac net/iucv: filter frames in afiucv_hs_rcv() by ingress device
gregkh/linux@15d1f3c0dbe7 xdp: fix zero-copy frame layout
gregkh/linux@486577db8078 slip: fix use-after-free in sl_sync()
gregkh/linux@32785d75e60d net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
gregkh/linux@e098d9cc8859 net: tun: bound receive headroom
gregkh/linux@f71087e7c63a net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
gregkh/linux@42a33e679ea0 net: ibm: emac: mal: fix NAPI locking
gregkh/linux@62da38b4b3a0 net: ipa: fix stalled modem TX queue after runtime resume
gregkh/linux@9c340473f482 net: l2tp: do not propagate multicast notification errors
gregkh/linux@ac73e3af571d net: openvswitch: fix flow mask use-after-free on flow deletion
gregkh/linux@0860af127aa7 net: openvswitch: fix nf_connlabels leak in ovs_ct_init
gregkh/linux@b6b533f83461 net: phylink: correctly validate returned PCS in phylink_inband_caps
gregkh/linux@8d4d06d6e2b5 net: ravb: avoid dereferencing an invalid PTP clock
gregkh/linux@67a82e6f886b net: ravb: serialize PTP clock teardown
gregkh/linux@61ff3c353e5d net: thunderbolt: Release the Rx HopID that was handed out on mismatch
gregkh/linux@f01e6a35c440 net: thunderbolt: Mark the connection down when bringing it up fails
gregkh/linux@0c4aabc90449 NTB: ntb_transport: Recycle TX entries before client callbacks
gregkh/linux@894e136b432d NTB: ntb_transport: Fail TX enqueue when the QP link is down
gregkh/linux@6b6bbc6c878d NTB: ntb_transport: Reject oversized TX buffers
gregkh/linux@dfab7171cd39 net: ntb_netdev: Fix TX busy and drop handling
gregkh/linux@4fac86e97697 net: ntb_netdev: Avoid double-accounting netif_rx() drops
gregkh/linux@b893152a886b net: ntb_netdev: Count packets dropped on RX refill failure
gregkh/linux@486c699a8cde net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
gregkh/linux@f950e1b1f0aa net/smc: do not dereference an unset send buffer on the SMC-D teardown path
gregkh/linux@d89dc1bd8845 net/smc: fix socket refcount leak in smc_switch_conns()
gregkh/linux@0761e49aa78c net/smc: fix use-after-free in smc_rx_pipe_buf_release()
gregkh/linux@c52a998a223e net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
gregkh/linux@313f79149eb3 net/smc: stop killed, freed and out_of_sync sharing a byte
gregkh/linux@5bd8b764a610 net/smc: unregister the connection before draining the rx tasklet
gregkh/linux@af0ee8f04bea net: cap advertised IP tunnel headroom
gregkh/linux@34ab62c959f5 net: fix spurious TX timeout after dev_activate()
gregkh/linux@288f99706708 net: skbuff: don't touch shared zerocopy state in skb_tx_error()
gregkh/linux@cfa186a0857a seg6: reset IP6CB after IPv6 decapsulation
gregkh/linux@efe0ed4c0f4e hwrng: stm32 - Fix runtime PM cleanup on registration failure
gregkh/linux@5e7fe9c6c8c3 mfd: cgbc: Fix teardown ordering in cgbc_remove()
gregkh/linux@94ca4f040ba4 mfd: sm501: Fix potential memory leaks during remove
gregkh/linux@2a6f6fba3bd3 ALSA: 6fire: bound the MIDI event length from the device
gregkh/linux@7b3f98558493 ALSA: aloop: Check card index validity at probe
gregkh/linux@7df3194bdb74 ALSA: bcd2000: clear the URB pointers on disconnect
gregkh/linux@13d61a920435 ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
gregkh/linux@cc4215cc2a4b ALSA: mpu401: Check card index validity at probe
gregkh/linux@a4e774eeb61a ALSA: mts64: Check card index validity at probe
gregkh/linux@7ef9ad82d95d ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
gregkh/linux@d7ef7890e3e3 ALSA: portman2x4: Check card index validity at probe
gregkh/linux@7555e83d7738 ALSA: serial-u16550: Check card index validity at probe
gregkh/linux@40ee4224e2fe ALSA: virmidi: Check card index validity at probe
gregkh/linux@8acb66d0513d ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
gregkh/linux@37c3210c491a ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG
gregkh/linux@22fe01a2e2f7 ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
gregkh/linux@50f4a793c4ff ring-buffer: Fix subbuf resize race with ring buffer readers
gregkh/linux@b5fe67111e63 ovpn: run deferred work on a module-owned workqueue
gregkh/linux@44dc702be9a9 rust: rust_is_available: warn for bindgen < 0.72.1 && libclang >= 22
gregkh/linux@edf30d65e3ac net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
gregkh/linux@c860cd3f4038 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map()
gregkh/linux@74210fa07296 dm-stats: fix a crash if allocation of per-cpu data fails
gregkh/linux@296efdc110b1 dm-switch: use WRITE_ONCE() in switch_region_table_write()
gregkh/linux@ab5dcde6fa96 dm-pcache: validate geometry fields from on-disk cache_info
gregkh/linux@d8caf96040a0 dm-pcache: validate kset key_num and intra-segment bounds
gregkh/linux@91b93fe5cf4d dm-pcache: validate on-media seg_num against the cache device size
gregkh/linux@ffd9a214a94f dm-pcache: bound the persisted tail-position offset
gregkh/linux@2cd9776fe3f2 dm-pcache: clamp the tail kset read to the segment data region
gregkh/linux@663ee2f3824a dm-pcache: detect a cycle in the last-kset chain during replay
gregkh/linux@83e3116283ed dm-pcache: only hand out initialized cache segments
gregkh/linux@10acf740c3ad dm-pcache: fix implicit u8 truncation of gc_percent in message handler
gregkh/linux@1894fc7a3bab dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
gregkh/linux@a15a1b95de98 i3c: master: adi: initialize the lock before enabling interrupts
gregkh/linux@94fb9786d67a i3c: master: Fix info leak and UAF in device unregister path
gregkh/linux@5697d779577e i3c: master: svc: bound IBI payload to the requested max_payload_len
gregkh/linux@0093f9fc102b i3c: renesas: Check that the transfer is valid before accessing it
gregkh/linux@9382fcf3a8c4 i3c: renesas: Clean DATBAS register on detach
gregkh/linux@7ef23317f997 i3c: renesas: Reconfigure the DATBAS register on re-attach
gregkh/linux@261d7c7610b4 wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
gregkh/linux@84ba017a1e1e wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
gregkh/linux@620acb1e8037 wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
gregkh/linux@8e4f9110aba3 crypto: sun8i-ce - Remove crypto_rng interface
gregkh/linux@7c257a295e05 crypto: sun8i-ss - Remove crypto_rng interface
gregkh/linux@b1bbeb8970ee wifi: mwifiex: Detach sync cmd buffer on interrupted wait
gregkh/linux@97a1af5ac131 wifi: rtl818x: initialize eeprom_93cx6 struct to zero
gregkh/linux@0c0b374e12d5 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
gregkh/linux@dc8b0be0ec4d wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
gregkh/linux@7364713f0931 wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
gregkh/linux@34a505071d1f wifi: rtw88: pci: fix resource leak on failed NAPI setup
gregkh/linux@4506e229b2e4 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
gregkh/linux@5fdaf7016d76 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
gregkh/linux@304470333b7f wifi: mt76: mt7925: cancel mlo_pm_work on stop
gregkh/linux@01f2e0da8548 wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
gregkh/linux@03b81f015dbb wifi: mt76: mt7996: validate default EEPROM firmware size
gregkh/linux@165a330a68b5 vsock/virtio: flush works in dependency order
gregkh/linux@ae0c79a85270 w1: ds28e17: reject an oversize length on an I2C block read
gregkh/linux@f49e55b1c8fe xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
gregkh/linux@c3c7e87c76b4 zloop: truncate finished zones to zone capacity
gregkh/linux@cde2d927c29e tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
gregkh/linux@e8527de7fea1 sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
gregkh/linux@236c8ecaafc6 sticon/parisc: Detect default STI graphics card for console output
gregkh/linux@a246da20c8e4 signal: avoid shared siginfo namespace rewrites
gregkh/linux@ed64aa505875 smack: fix cred UAF in smack_file_send_sigiotask()
gregkh/linux@6067c39c2cec taskstats: fix cpumask parsing cutting off the last character
gregkh/linux@fecf1e377752 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
gregkh/linux@b7eff3f621ef timer: Keep debugobjects state consistent in migrate_timer_list()
gregkh/linux@2d6150e5e6aa udf: Fix i_lenExtents truncation on 32-bit kernels
gregkh/linux@e91d66e5ff66 selftests/mm: fix on-fault-limit false failure under sudo-rs
gregkh/linux@6a259dd31304 platform/chrome: sensorhub: Fix dropped timestamp events and log spam
gregkh/linux@381a0a524e96 mm: avoid unnecessary use of is_swap_pmd()
gregkh/linux@8e30f5427f34 mm/rmap: use huge_ptep_get() in try_to_unmap_one()
gregkh/linux@7cfc41f8e80f Linux 6.18.50
gregkh/linux@a13b1e80e501 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()
gregkh/linux@e15407c3a8a0 openvswitch: Fix CT limit teardown use-after-free
gregkh/linux@b5a5d389eee6 mm/page_vma_mapped: use huge_ptep_get() for hugetlb
gregkh/linux@459f33f82864 entry: Fix seccomp bypass after ptrace with TSYNC
gregkh/linux@947400af98b9 fsnotify: Fix stale object mask after concurrent mark updates
gregkh/linux@617b48fc0baf objtool/rust: add one more noreturn Rust function
gregkh/linux@0b6680e30639 mfd: qnap-mcu: keep the reply buffer alive past a command timeout
gregkh/linux@0ec897493ff8 drm/amd: Drop calls to restore power limit and clock from smu_resume()
gregkh/linux@a6b088bee95f fsnotify: inotify: pass mark connector to fsnotify_recalc_mask()
gregkh/linux@c96477e0cabf drm/xe: Don't hand out the flat CCS storage as usable VRAM
gregkh/linux@12ee39c2b1d3 bpf: fix the return value of push_stack
gregkh/linux@4814f28c45f5 drm/amd/display: fix division by zero in get_estimated_bw()
gregkh/linux@838455cc8bfe usb: image: mdc800: change kmalloc() to kzalloc()
gregkh/linux@9392a2c34676 ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
gregkh/linux@296a884cd6fe clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
gregkh/linux@7690a86b1932 media: usbtv: keep device alive while ALSA card exists
gregkh/linux@1c67f2ba9c5f usb-storage: ene_ub6250: fix race between scan work and probe
gregkh/linux@62a8b6796063 usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
gregkh/linux@0afe5c31612d usb: dwc3: clear forceRM when issuing EndTransfer
gregkh/linux@7c4e2f964c65 usb: storage: realtek_cr: fix use-after-free on disconnect
gregkh/linux@c614d7c44ca7 usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
gregkh/linux@1e4f33f99bfb usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails
gregkh/linux@d4e00a1eb391 usb: typec: qcom-pmic: cancel reset_work on stop
gregkh/linux@42828aeb40b4 usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling
gregkh/linux@6be5169e7615 usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x
gregkh/linux@33a81acd2d1d usb: typec: ucsi: displayport: Fix OOB altmode array index
gregkh/linux@9c3d5091e356 usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
gregkh/linux@e89e30f0b5d3 usb: gadget: f_midi2: fix use-after-free in string attribute show path
gregkh/linux@02ac76f27db2 usb: gadget: f_midi: initialize work in f_midi_alloc()
gregkh/linux@c29a83c1ff3f USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
gregkh/linux@d3a7fa61997d usb: gadget: fix null pointer dereference in usb_put_function_instance()
gregkh/linux@ff61aa328935 staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
gregkh/linux@b041e3f35e0d staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
gregkh/linux@efaab8938fb9 xhci: fix lost bounce buffers on TDs spanning several ring segments
gregkh/linux@ec2db87a0bbb thermal/drivers/imx: Disable clock on runtime resume failure
gregkh/linux@65c2029f3bba thermal/drivers/qoriq: Disable clock on resume failure
gregkh/linux@89f06342743c userfaultfd: reset err to be 0 when move_pages_ptes succeeded
gregkh/linux@e373c1acdbcf ublk: clear VM_MAYWRITE on read-only ublk char device mmap
gregkh/linux@907752a7b64a soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size
gregkh/linux@b782a7cb0a42 spi: bcm63xx-hsspi: disable clocks on resume failure
gregkh/linux@0acbfd61aee1 spi: bcm63xx: disable clock on resume failure
gregkh/linux@148a3f03aec8 spi: bcmbca-hsspi: disable clocks on resume failure
gregkh/linux@a38051fa2dde spi: Fix DMA mapping ownership on partial map failure
gregkh/linux@1624bff4c511 scsi: target: iscsi: Reserve a terminator byte for the login payload
gregkh/linux@4bb34769ef44 scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame
gregkh/linux@dd817463c9b4 scsi: pm8001: Use rollback index when freeing MSI-X vectors
gregkh/linux@71de5a082d2c mm/damon/vaddr-kunit: check region count in three_regions test
gregkh/linux@f0808262a761 samples/damon/mtier: handle damon_start() failure
gregkh/linux@3c07c57b8941 samples/damon/mtier: handle damon_stop() failure
gregkh/linux@9f370353bba7 samples/damon/prcl: handle damon_start() failure
gregkh/linux@2446d3820cba samples/damon/prcl: stop and free damon ctx when damon_call() fails
gregkh/linux@6179c7f47876 samples/damon/wsse: handle damon_start() failure
gregkh/linux@cb55606449fd samples/damon/wsse: stop and free damon ctx when damon_call() fails
gregkh/linux@b9847d539b9c mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs
gregkh/linux@8a1ebb241fc7 mm/damon/sysfs-schemes: kobject_del() scheme dirs
gregkh/linux@e608e7bbe82c mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
gregkh/linux@20a40e7eb5ec mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
gregkh/linux@23c7b91895ff mm/damon/sysfs-schemes: kobject_del() scheme region dirs
gregkh/linux@368f84ec7910 mm/damon/sysfs: kobject_del() region and target (error) dirs
gregkh/linux@382e58c24eab mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
gregkh/linux@1cd41131bc4b mm/damon/core-kunit: check region count before testing in split_at()
gregkh/linux@7d1559126d86 futex: Prevent rcuwait use-after-free during requeue PI
gregkh/linux@078adc03f6e6 ftrace: Synchronize the initialization of ftrace_ops
gregkh/linux@c7f927aa8b55 HID: bpf: serialize device reference release in struct_ops destroy path
gregkh/linux@f4cb9c4556dc HID: rmi: fix OOB access with undersized RMI reports
gregkh/linux@74ec08f7b81c HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
gregkh/linux@af1f32ccf805 dm: fix race when loading and unloading a table
gregkh/linux@36177beff2a9 dm: fix resume-vs-remove race
gregkh/linux@408ff2d5bf55 dma-direct: return struct page from dma_direct_alloc_from_pool()
gregkh/linux@d382aaf5fed3 dmaengine: fsl-edma: tracing: no ptr dereference during log output
gregkh/linux@3b313f7a00d1 dmaengine: dw-edma: Fix HDMA channel status register access
gregkh/linux@8fd47ccbba86 dmaengine: dw-edma: Complete descriptors before pausing
gregkh/linux@fac202d73e7a dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
gregkh/linux@b519dfce1998 cpuidle: dt_idle_genpd: kfree() the original name allocation
gregkh/linux@634e2d23736d cpuidle: psci: Fix support for probe deferral by dropping the faux device
gregkh/linux@bfb469f20aa9 block: flag zoned disks with GENHD_FL_NO_PART
gregkh/linux@a24a146ae2cb bpf: Fix infinite loop in pcpu_freelist push with one possible CPU
gregkh/linux@ca5bfea2045e ceph: lock mutex in ceph_mds_check_access()
gregkh/linux@685c195fbd7d ata: ahci: work around lost interrupts on Marvell 88SE61xx
gregkh/linux@f8a2f2a46023 ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
gregkh/linux@863f6726a5c0 irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
gregkh/linux@5da247e4d1e8 kprobes: Protect kprobe_blacklist with RCU
gregkh/linux@0ceda28f371d mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
gregkh/linux@4d6ccd3883df fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list
gregkh/linux@d07e281f2a77 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
gregkh/linux@7269bd95d707 Input: aiptek - validate raw macro indices before updating state
gregkh/linux@801bcbdbfd59 memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done
gregkh/linux@0a90e268cce7 memcg: make the v1 soft limit knob inert
gregkh/linux@350cb7821b3d rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt
gregkh/linux@a4d6666a65d6 rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
gregkh/linux@3a2b79eae5be rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm
gregkh/linux@267f0a4fb9fe rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
gregkh/linux@3c492c8eba02 perf/x86/intel: Fix kernel address leakages in LBR stack
gregkh/linux@f3a666313849 perf trace: Factor out BPF loop body
gregkh/linux@242138984073 perf trace: Refactor augmented_raw_syscalls using bpf_for
gregkh/linux@19d65da9f749 perf hisi-ptt: Fix PTT trace TLP header parsing
gregkh/linux@c643b6e7852e i2c: designware: Enable interrupt mask workaround for HJMC3001
gregkh/linux@954f30c8df0a i2c: qcom-geni: update frequency table to fix timing parameters
gregkh/linux@112b3d48084c i2c: core: fix debugfs UAF on adapter removal
gregkh/linux@2b3b06cb709c i2c: mux: Fix channel node leak on adapter add failure
gregkh/linux@68cbd70795dd arm64: mm: Fix the lockless page-table walk in show_pte()
gregkh/linux@cd090af03f5d arm64: errata: pass REVIDR when matching target implementation CPUs
gregkh/linux@1e67ad10373e ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
gregkh/linux@89992bda7dfb ALSA: harmony: initialize locks before requesting IRQ
gregkh/linux@7ad2ea7c1004 ALSA: pcm: Fix race between non-atomic ops and trigger-start
gregkh/linux@15d7a35a4892 nvme-fabrics: fix DHCHAP secret leak on parse failure
gregkh/linux@7df913a7ced5 nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
gregkh/linux@b4af7999a998 nvme-tcp: check the data direction of a C2HData PDU
gregkh/linux@d663944dbad8 nvme: add missing SRCU grace period in error path
gregkh/linux@7555ddd60af7 nvmet-auth: Synchronize timeout work during SQ teardown
gregkh/linux@dbc4acbdb3ca nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
gregkh/linux@cf1484d9a75d nvmet-tcp: reject unsolicited H2CData PDUs
gregkh/linux@6e96e2bb1065 pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig
gregkh/linux@8e287f463fc4 Revert "irqchip/mbigen: Fix mbigen node address layout"
gregkh/linux@ae6a8b0c6990 mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
gregkh/linux@631d8f39b33e mm/hugetlb: keep max_huge_pages when dissolving surplus folios
gregkh/linux@bdd929e60bc5 mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON()
gregkh/linux@6b1faf1f099f nvdimm/btt: reject an arena whose nfree is below the lane count
gregkh/linux@3e2691eeee83 parisc: eisa: Fix infinite loop when parsing invalid IRQ value
gregkh/linux@6ae9306c7598 parisc: Fix alignment of asm statements in head.S
gregkh/linux@df45337587db powerpc/kexec_file: Fix null-ptr-def in extra size calculation
gregkh/linux@da88a2a2119e powerpc/kexec_file: Prevent kexec range truncation
gregkh/linux@9c914b7a0bd1 powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
gregkh/linux@d2be3dd20e83 powerpc/pseries: Handle and log pseries-wdt registration failures
gregkh/linux@36dcb8c2e339 powerpc/pseries: Move H_WATCHDOG definitions to a common header
gregkh/linux@3b90d769b351 powerpc/crash: stop watchdogs before booting kdump kernel
gregkh/linux@fc069d00a0db s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()
gregkh/linux@3c5f51f257e1 s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove
gregkh/linux@f7d66afc34bc s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
gregkh/linux@178ea7a1c2c3 s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
gregkh/linux@c...

Comment thread config-base
@@ -1,14 +1,14 @@
# Base config based on Fedora's config (kernel-core-6.18.13-200.fc43.rpm)
# Base config based on Fedora's config (kernel-core-6.0.12-100.fc35.rpm)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What?! I think the bot is drunk...

fepitre added a commit to fepitre/qubes-components-updater that referenced this pull request Sep 13, 2026
Koji keeps a whole signed rpm only for some builds, mostly archived ones.
Everywhere else data/signed is a 404 and it serves the unsigned rpm plus a
detached signature header, so splice them back together the way
koji write-signed-rpm does, and verify that.

Fall back only between Fedora branches carrying the same kernel, they are
equivalent sources. Below that it is a different kernel: fail the update
instead of landing a config nobody asked for. Every 6.18.16 candidate 404'd
and QubesOS/qubes-linux-kernel#1372 ended up with the config of
kernel-6.0.12-100.fc35 for a 6.18.51 update.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants