Skip to content

[rocky10_2] History Rebuild through kernel-6.12.0-211.56.1.el10_2 - #1617

Open
PlaidCat wants to merge 186 commits into
rocky10_2from
rocky10_2_rebuild
Open

PlaidCat wants to merge 186 commits into
rocky10_2from
rocky10_2_rebuild

Conversation

@PlaidCat

@PlaidCat PlaidCat commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

This is an automated kernel history rebuild using cron and internal tooling. It follows the same process used for previous history rebuilds:

  • Download all unprocessed src.rpm packages
  • For each src.rpm:
    • Identify all commits in the changelog up to the last known tag (6.12.0-211)
    • Replay commits in chronological order (oldest to newest in the changelog) using git cherry-pick
    • Replace the code in the branch with the output of rpmbuild -bp for the corresponding src.rpm
    • Tag the rebuild branch

JIRA Tickets

Rebuild Splat Inspection

kernel-6.12.0-211.55.1.el10_2

$ cat ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/rebuild.details.txt
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v6.12~1..kernel-mainline: 138299
Number of commits in rpm: 141
Number of commits matched with upstream: 131 (92.91%)
Number of commits in upstream but not in rpm: 138168
Number of commits NOT found in upstream: 10 (7.09%)

Rebuilding Kernel on Branch rocky10_2_rebuild_kernel-6.12.0-211.55.1.el10_2 for kernel-6.12.0-211.55.1.el10_2
Clean Cherry Picks: 111 (84.73%)
Empty Cherry Picks: 20 (15.27%)
_______________________________

__EMPTY COMMITS__________________________
0861615c28de668669d748ef4eb913ea9262d13b sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
6f4c80a2a7e6d06753b89a578b710a2499a5e62b sctp: validate embedded INIT chunk and address list lengths in cookie
da8fc7a39be897426e1ac05aa90263abf40621b7 af_unix: Don't trigger GC from close() if unnecessary.
384900542dc85f3aac7918fea8e7ef62141e3ea6 af_unix: Don't call wait_for_unix_gc() on every sendmsg().
e29c7a4cec867f9d860b8ff3da0fc44c7177876a af_unix: Refine wait_for_unix_gc().
ab8b23150abccd34fddc3effe7776ad32c44b6c9 af_unix: Remove unix_tot_inflight.
24fa77dad25c2f55cc4615c09df2201ef72c66f4 af_unix: Consolidate unix_schedule_gc() and wait_for_unix_gc().
e5b31d988a41549037b8d8721a3c3cae893d8670 af_unix: Give up GC if MSG_PEEK intervened.
d82ba05263c69fa2437fe93e4e561cc40f4c03af af_unix: Set gc_in_progress to true in unix_gc().
1c428b03840094410c5fb6a5db30640486bbbfcb xfrm: hold dev ref until after transport_finish NF_HOOK
8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff xfrm: Fix dev use-after-free in xfrm async resumption
ff225ba9ad71c4c5f900b9aa1b757adafcfb449d mshv: Add debugfs to view hypervisor statistics
4bef6b28bab8697b4f9255c375da2b6b6943a969 mshv: Add support for integrated scheduler
8927a108a7662eb83eb667bc0c5a0633397122b1 mshv: Add SMT_ENABLED_GUEST partition creation flag
ede54383e646821b499873c1caf2dd97551da8eb mshv: Introduce hv_deposit_memory helper functions
cf82dd5ea95815e6c0612b61118d2358ef5c05b0 mshv: Handle insufficient contiguous memory hypervisor status
158ebb578cd5f7881fdc7c4ecebddcf9463f91fd mshv: Handle insufficient root memory hypervisor statuses
4f3a998a173b4325c2efd90bdadc6ccd3ad9a431 drm/xe: Open-code GGTT MMIO access protection
225d02cb46d0e567eb788308168159f61735c8fe drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove
4c571885898c5c98934d086f2ab11b5e27e4f41f iio: Drop iio_device_claim_direct_scoped() and related infrastructure

__CHANGES NOT IN UPSTREAM________________
Add partial riscv64 support for build root'
Provide basic VisionFive 2 support'
iio: adc: nxp-sar-adc: Fix the delay calculation in nxp_sar_adc_wait_for()
redhat/configs: automotive: enable NXP_SAR_ADC as a module
iommu/vt-d: Fix UCTP context table slot when copying root entries
watchdog: fix hrtimer start when pretimeout is zero
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
xfrm: fix stale skb->prev after async crypto steals a GSO segment
xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()

BUILD

$ grep -E -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
  CLEAN   include/config include/generated
[TIMER]{MRPROPER}: 7s
x86_64 architecture detected, copying config
'configs/kernel-x86_64-rhel.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky10_2_rebuild-e03235a899b5"
Making olddefconfig
--
  HOSTCC  scripts/kconfig/util.o
  HOSTLD  scripts/kconfig/conf
#
# configuration written to .config
#
Starting Build
  GEN     arch/x86/include/generated/asm/orc_hash.h
  WRAP    arch/x86/include/generated/uapi/asm/bpf_perf_event.h
  WRAP    arch/x86/include/generated/uapi/asm/errno.h
  WRAP    arch/x86/include/generated/uapi/asm/fcntl.h
  WRAP    arch/x86/include/generated/uapi/asm/ioctls.h
--
  LD [M]  net/qrtr/qrtr-mhi.ko
  BTF [M] net/qrtr/qrtr.ko
  LD [M]  virt/lib/irqbypass.ko
  BTF [M] net/qrtr/qrtr-mhi.ko
  BTF [M] virt/lib/irqbypass.ko
[TIMER]{BUILD}: 2391s
Making Modules
  SYMLINK /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/build
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/modules.order
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/modules.builtin
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/modules.builtin.modinfo
--
  STRIP   /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/kernel/virt/lib/irqbypass.ko
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/kernel/virt/lib/irqbypass.ko
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/kernel/net/openvswitch/openvswitch.ko
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+/kernel/net/ceph/libceph.ko
  DEPMOD  /lib/modules/6.12.0-rocky10_2_rebuild-e03235a899b5+
[TIMER]{MODULES}: 15s
Making Install
  INSTALL /boot
[TIMER]{INSTALL}: 18s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-6.12.0-rocky10_2_rebuild-e03235a899b5+ and Index to 2
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 7s
[TIMER]{BUILD}: 2391s
[TIMER]{MODULES}: 15s
[TIMER]{INSTALL}: 18s
[TIMER]{TOTAL} 2435s
Rebooting in 10 seconds

KSelfTests

$ get_kselftest_diff.sh
kselftest.6.12.0-rocky10_2_rebuild-c99817d1264f+.log
492
kselftest.6.12.0-rocky10_2_rebuild-0e5a03790d6d+.log
491
kselftest.6.12.0-rocky10_2_rebuild-9d66c526c490+.log
492
kselftest.6.12.0-rocky10_2_rebuild-e03235a899b5+.log
492
Before: kselftest.6.12.0-rocky10_2_rebuild-9d66c526c490+.log
After: kselftest.6.12.0-rocky10_2_rebuild-e03235a899b5+.log
Diff:
No differences found.

jira KERNEL-1600
cve CVE-2026-43248
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Eugenio Pérez <eperezma@redhat.com>
commit cd025c1

Remove duplication by consolidating these here.  This reduces the
posibility of a parent driver missing them.

While we're at it, fix a bug in vdpa_sim where a valid ASID can be
assigned to a group equal to ngroups, causing an out of bound write.

	Cc: stable@vger.kernel.org
Fixes: bda324f ("vdpasim: control virtqueue support")
	Acked-by: Jason Wang <jasowang@redhat.com>
	Signed-off-by: Eugenio Pérez <eperezma@redhat.com>
	Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <20260119143306.1818855-2-eperezma@redhat.com>
(cherry picked from commit cd025c1)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-52924
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Xin Long <lucien.xin@gmail.com>
commit e374b22

sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound stream scheduler state (stream->out_curr) is expected to be
clean, since no user data should have been transmitted yet unless the
state machine has already partially progressed.

However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a
Stale Cookie ERROR is received, the association is rolled back from
COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already
have been queued and even bundled with the COOKIE-ECHO chunk.

During the rollback, sctp_stream_update() frees the old stream table
and installs a new one, but it does not invalidate stream->out_curr.
As a result, out_curr may still point to a freed sctp_stream_out
entry from the previous stream state.

Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on
stream->out_curr->ext, which can lead to use-after-free once the old
stream state has been released via sctp_stream_free().

This results in crashes such as (reported by Yuqi):

  BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140
  Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312
  CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted
     7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full)
   sctp_sched_fcfs_dequeue+0x13a/0x140
   sctp_outq_flush+0x1603/0x33e0
   sctp_do_sm+0x31c9/0x5d30
   sctp_assoc_bh_rcv+0x392/0x6f0
   sctp_inq_push+0x1db/0x270
   sctp_rcv+0x138d/0x3c10

Fix this by fully purging the association outqueue when handling the
Stale Cookie case. This ensures all pending transmit and retransmit
state is dropped, and any scheduler cached pointers are invalidated,
making it safe to rebuild stream state during COOKIE_WAIT restart.

Updating only stream->out_curr would be insufficient, since queued
and retransmittable data would still reference the old stream state and
trigger later use-after-free in dequeue paths.

Fixes: 5bbbbe3 ("sctp: introduce stream scheduler foundations")
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Reported-by: Yuqi Xu <xuyq21@lenovo.com>
	Reported-by: Ren Wei <n05ec@lzu.edu.cn>
	Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/94318159b9052907a6cbb7256aee8b5f8dfbfccb.1780510304.git.lucien.xin@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e374b22)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…how()

jira KERNEL-1600
cve CVE-2026-46149
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit 772a896

target_tg_pt_gp_members_show() formats LUN paths with snprintf() into a
256-byte stack buffer, then will memcpy() cur_len bytes from that
buffer.  snprintf() returns the length the output would have had, which
can exceed the buffer size when the fabric WWN is long because iSCSI IQN
names can be up to 223 bytes.  The check at the memcpy() site only
guards the destination page write, not the source read, so memcpy() will
read past the stack buffer and copy adjacent stack contents to the sysfs
reader, which when CONFIG_FORTIFY_SOURCE is enabled, fortify_panic()
will be triggered.

Commit 27e0665 ("scsi: target: target_core_configfs: Add length
check to avoid buffer overflow") added the same bound to the
target_lu_gp_members_show() but the tg_pt_gp variant was missed so
resolve that here.

	Cc: Martin K. Petersen <martin.petersen@oracle.com>
Fixes: c66ac9d ("[SCSI] target: Add LIO target core v4.0.0-rc6")
Assisted-by: gregkh_clanker_t1000
	Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Link: https://patch.msgid.link/2026041159-garter-theft-3be0@gregkh
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit 772a896)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-63889
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Michael Bommarito <michael.bommarito@gmail.com>
commit a9a3923

An adjacent Fibre Channel fabric actor that can deliver an FPIN ELS
frame to an lpfc or qla2xxx Linux initiator can trigger a non-return in
the generic FC transport. This is not a local userspace or IP network
path; the attacker must be able to inject fabric traffic, for example as
a compromised switch or fabric controller, or as a same-zone N_Port on a
fabric that permits source spoofing.

The Link-Integrity and Peer-Congestion FPIN walkers used a u8 loop
counter against the 32-bit on-wire pname_count field, and did not bound
pname_count by the descriptor body already validated by the TLV walker.
A pname_count of 256 therefore wraps the counter and keeps the loop
condition true indefinitely.

Factor the shared pname_list[] walk into one helper, widen the counter
to u32, and clamp pname_count against the entries that fit in the
descriptor body before iterating.

Fixes: 3dcfe0d ("scsi: fc: Parse FPIN packets and update statistics")
	Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-7
	Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
	Reviewed-by: Christoph Hellwig <hch@lst.de>
	Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260520133015.1018937-1-michael.bommarito@gmail.com
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit a9a3923)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-53131
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Zhengchuan Liang <zcliangcn@gmail.com>
commit 62443dc

`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and
`hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)`
after either assuming that the skb is associated with an Ethernet
device or checking only that the `ETH_HLEN` bytes at
`skb_mac_header(skb)` lie between `skb->head` and `skb->data`.

Make these paths first verify that the skb is associated with an
Ethernet device, that the MAC header was set, and that it spans at
least a full Ethernet header before accessing `eth_hdr(skb)`.

	Suggested-by: Florian Westphal <fw@strlen.de>
	Tested-by: Ren Wei <enjou1224z@gmail.com>
	Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Signed-off-by: Florian Westphal <fw@strlen.de>
(cherry picked from commit 62443dc)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2025-40149
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit c65f27b

get_netdev_for_sock() is called during setsockopt(),
so not under RCU.

Using sk_dst_get(sk)->dev could trigger UAF.

Let's use __sk_dst_get() and dst_dev_rcu().

Note that the only ->ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.

Fixes: e8f6979 ("net/tls: Add generic NIC offload infrastructure")
	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20250916214758.650211-6-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit c65f27b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-64111
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Stephen Smalley <stephen.smalley.work@gmail.com>
commit 4a9b165

Just as proc_pid_attr_write() already does before calling the LSM
hook. This only matters for SELinux and AppArmor which check
whether the process is being ptraced and if so, whether to
allow the transition.

	Cc: stable@vger.kernel.org
	Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
	Acked-by: Casey Schaufler <casey@schaufler-ca.com>
	Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit 4a9b165)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2025-68745
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Tony Battersby <tonyb@cybernetics.com>
commit d46c69a

Commit aefed3e ("scsi: qla2xxx: target: Fix offline port handling
and host reset handling") caused two problems:

1. Commands sent to FW, after chip reset got stuck and never freed as FW
   is not going to respond to them anymore.

2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd().  Commit 26f9ce5
   ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
   attempted to fix this, but introduced another bug under different
   circumstances when two different CPUs were racing to call
   qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in
   dma_unmap_sg_attrs().

So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and
partially revert "scsi: qla2xxx: target: Fix offline port handling and
host reset handling" at __qla2x00_abort_all_cmds.

Fixes: aefed3e ("scsi: qla2xxx: target: Fix offline port handling and host reset handling")
Fixes: 26f9ce5 ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
Co-developed-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
	Signed-off-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
	Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
Link: https://patch.msgid.link/0e7e5d26-e7a0-42d1-8235-40eeb27f3e98@cybernetics.com
	Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit d46c69a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-53246
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Xin Long <lucien.xin@gmail.com>
commit 0861615
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/0861615c.failed

When a listening SCTP server processes a COOKIE_ECHO chunk, the cached
peer INIT chunk embedded after the cookie is parsed and its parameters
are later walked by sctp_process_init() using sctp_walk_params().

However, the chunk header length of this cached INIT chunk was not
validated against the remaining buffer in the COOKIE_ECHO payload. If
the length field is inflated, the parameter walk can run beyond the
actual received data, leading to out-of-bounds reads and potential
memory corruption during later parameter handling (e.g. STATE_COOKIE
processing and kmemdup() copies).

Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT
chunk length does not exceed the available data in the COOKIE_ECHO
buffer before it is used.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Reported-by: Brian Geffon <bgeffon@google.com>
	Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/eb60825fa22d6f9e663c7d4dbb69f397b5d34d42.1780362366.git.lucien.xin@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 0861615)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/sctp/sm_make_chunk.c
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Xin Long <lucien.xin@gmail.com>
commit 6f4c80a
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/6f4c80a2.failed

sctp_unpack_cookie() only checked that the embedded INIT chunk length
did not exceed the remaining cookie payload, but did not ensure that the
INIT chunk is large enough to contain a complete INIT header.

A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose
length field is smaller than sizeof(struct sctp_init_chunk).  Later,
sctp_process_init() accesses INIT parameters unconditionally, which may
lead to out-of-bounds reads.

In addition, raw_addr_list_len is not fully validated against the
remaining cookie payload. When cookie authentication is disabled, an
attacker can supply an oversized raw_addr_list_len and cause
sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The
address parser also lacks sufficient bounds checks for parameter headers
and lengths, allowing malformed address parameters to trigger
out-of-bounds reads.

Fix this by:

- requiring the embedded INIT chunk length to be at least sizeof(struct
  sctp_init_chunk);
- validating that the INIT chunk and raw address list together fit
  within the cookie payload;
- verifying sufficient data exists for each address parameter header and
  payload before parsing it.

Note that sctp_verify_init() must be called after sctp_unpack_cookie()
and before sctp_process_init() when cookie authentication is disabled.
This will be addressed in a separate patch.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Reported-by: Sashiko <sashiko-bot@kernel.org>
	Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/75af23a89adf881a0895d511775e4770da367cbf.1780873427.git.lucien.xin@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 6f4c80a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/sctp/sm_make_chunk.c
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 84960bf

net/af_unix.h is included by core and some LSMs, but most definitions
need not be.

Let's move struct unix_{vertex,edge} to net/unix/garbage.c and other
definitions to net/unix/af_unix.h.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Reviewed-by: Joe Damato <jdamato@fastly.com>
Link: https://patch.msgid.link/20250318034934.86708-3-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 84960bf)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Stephen Rothwell <sfr@canb.auug.org.au>
commit 705094f

After merging the apparmor tree, today's linux-next build (x86_64
allmodconfig) failed like this:

security/apparmor/af_unix.c: In function 'unix_state_double_lock':
security/apparmor/af_unix.c:627:17: error: implicit declaration of function 'unix_state_lock'; did you mean 'unix_state_double_lock'? [-Wimplicit-function-declaration]
  627 |                 unix_state_lock(sk1);
      |                 ^~~~~~~~~~~~~~~
      |                 unix_state_double_lock
security/apparmor/af_unix.c: In function 'unix_state_double_unlock':
security/apparmor/af_unix.c:642:17: error: implicit declaration of function 'unix_state_unlock'; did you mean 'unix_state_double_lock'? [-Wimplicit-function-declaration]
  642 |                 unix_state_unlock(sk1);
      |                 ^~~~~~~~~~~~~~~~~
      |                 unix_state_double_lock

Caused by commit

  c05e705 ("apparmor: add fine grained af_unix mediation")

interacting with commit

  84960bf ("af_unix: Move internal definitions to net/unix/.")

from the net-next tree.

	Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Signed-off-by: Stephen Rothwell <sfr@canb.auug.org.au>
Link: https://patch.msgid.link/20250326150148.72d9138d@canb.auug.org.au
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 705094f)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit f9af583

This is a prep patch to make the following changes cleaner.

No functional change intended.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Reviewed-by: Joe Damato <jdamato@fastly.com>
Link: https://patch.msgid.link/20250318034934.86708-2-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f9af583)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 3056172

include/net/af_unix.h indirectly includes some definitions for structs.

Let's include such headers explicitly.

  linux/atomic.h   : scm_stat.nr_fds
  linux/net.h      : unix_sock.peer_wq
  linux/path.h     : unix_sock.path
  linux/spinlock.h : unix_sock.lock
  linux/wait.h     : unix_sock.peer_wake
  uapi/linux/un.h  : unix_address.name[]

linux/socket.h is removed as the structs there are not used directly,
and linux/un.h is clarified with uapi as un.h only exists under
include/uapi.

While at it, duplicate headers are removed from .c files.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20250318034934.86708-4-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 3056172)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 0083e3e

net/unix/*.c include many unnecessary header files (rtnetlink.h,
netdevice.h, etc).

Let's clean them up.

af_unix.c:

  +uapi/linux/sockios.h   : Only exist under include/uapi
  +uapi/linux/termios.h   : Only exist under include/uapi

  -linux/freezer.h        : No longer use freezable_schedule_timeout()
  -linux/in.h             : No ipv4_is_XXX() etc
  -linux/module.h         : No longer support CONFIG_UNIX=m
  -linux/netdevice.h      : No dev used
  -linux/rtnetlink.h      : Not part of rtnetlink API
  -linux/signal.h         : signal_pending() is defined in sched/signal.h
  -linux/stat.h           : No struct stat used
  -net/checksum.h         : CHECKSUM_UNNECESSARY is defined in skbuff.h

diag.c:

  +linux/dcache.h         : struct dentry in sk_diag_dump_vfs()
  +linux/user_namespace.h : struct user_namespace in sk_diag_dump_uid()
  +uapi/linux/unix_diag.h : Only exist under include/uapi/

garbage.c:

  +linux/list.h           : struct unix_{vertex,edge}, etc
  +linux/workqueue.h      : DECLARE_WORK(unix_gc_work, ...)

  -linux/file.h           : No fget() etc
  -linux/kernel.h         : No cond_resched() etc
  -linux/netdevice.h      : No dev used
  -linux/proc_fs.h        : No procfs provided
  -linux/string.h         : No memcpy(), kmemdup(), etc

sysctl_net_unix.c:

  +linux/string.h         : kmemdup()
  +net/net_namespace.h    : struct net, net_eq()

  -linux/mm.h             : slab.h is enough

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20250318034934.86708-5-kuniyu@amazon.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 0083e3e)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 60e6489

Quang Le reported that the AF_UNIX GC could garbage-collect a
receive queue of an alive in-flight socket, with a nice repro.

The repro consists of three stages.

  1)
    1-a. Create a single cyclic reference with many sockets
    1-b. close() all sockets
    1-c. Trigger GC

  2)
    2-a. Pass sk-A to an embryo sk-B
    2-b. Pass sk-X to sk-X
    2-c. Trigger GC

  3)
    3-a. accept() the embryo sk-B
    3-b. Pass sk-B to sk-C
    3-c. close() the in-flight sk-A
    3-d. Trigger GC

As of 2-c, sk-A and sk-X are linked to unix_unvisited_vertices,
and unix_walk_scc() groups them into two different SCCs:

  unix_sk(sk-A)->vertex->scc_index = 2 (UNIX_VERTEX_INDEX_START)
  unix_sk(sk-X)->vertex->scc_index = 3

Once GC completes, unix_graph_grouped is set to true.
Also, unix_graph_maybe_cyclic is set to true due to sk-X's
cyclic self-reference, which makes close() trigger GC.

At 3-b, unix_add_edge() allocates unix_sk(sk-B)->vertex and
links it to unix_unvisited_vertices.

unix_update_graph() is called at 3-a. and 3-b., but neither
unix_graph_grouped nor unix_graph_maybe_cyclic is changed
because both sk-B's listener and sk-C are not in-flight.

3-c decrements sk-A's file refcnt to 1.

Since unix_graph_grouped is true at 3-d, unix_walk_scc_fast()
is finally called and iterates 3 sockets sk-A, sk-B, and sk-X:

  sk-A -> sk-B (-> sk-C)
  sk-X -> sk-X

This is totally fine.  All of them are not yet close()d and
should be grouped into different SCCs.

However, unix_vertex_dead() misjudges that sk-A and sk-B are
in the same SCC and sk-A is dead.

  unix_sk(sk-A)->scc_index == unix_sk(sk-B)->scc_index <-- Wrong!
  &&
  sk-A's file refcnt == unix_sk(sk-A)->vertex->out_degree
                                       ^-- 1 in-flight count for sk-B
  -> sk-A is dead !?

The problem is that unix_add_edge() does not initialise scc_index.

Stage 1) is used for heap spraying, making a newly allocated
vertex have vertex->scc_index == 2 (UNIX_VERTEX_INDEX_START)
set by unix_walk_scc() at 1-c.

Let's track the max SCC index from the previous unix_walk_scc()
call and assign the max + 1 to a new vertex's scc_index.

This way, we can continue to avoid Tarjan's algorithm while
preventing misjudgments.

Fixes: ad08192 ("af_unix: Avoid Tarjan's algorithm if unnecessary.")
	Reported-by: Quang Le <quanglex97@gmail.com>
	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251109025233.3659187-1-kuniyu@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 60e6489)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 58b47c7

__unix_walk_scc() and unix_walk_scc_fast() call unix_scc_cyclic()
for each SCC to check if it forms a cyclic reference, so that we
can skip GC at the following invocations in case all SCCs do not
have any cycles.

If we count the number of cyclic SCCs in __unix_walk_scc(), we can
simplify unix_walk_scc_fast() because the number of cyclic SCCs
only changes when it garbage-collects a SCC.

So, let's count cyclic SCC in __unix_walk_scc() and decrement it
in unix_walk_scc_fast() when performing garbage collection.

Note that we will use this counter in a later patch to check if a
cycle existed in the previous GC run.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-2-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 58b47c7)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 6b6f3c7

GC manages its state by two variables, unix_graph_maybe_cyclic
and unix_graph_grouped, both of which are set to false in the
initial state.

When an AF_UNIX socket is passed to an in-flight AF_UNIX socket,
unix_update_graph() sets unix_graph_maybe_cyclic to true and
unix_graph_grouped to false, making the next GC invocation call
unix_walk_scc() to group SCCs.

Once unix_walk_scc() finishes, sockets in the same SCC are linked
via vertex->scc_entry.  Then, unix_graph_grouped is set to true
so that the following GC invocations can skip Tarjan's algorithm
and simply iterate through the list in unix_walk_scc_fast().

In addition, if we know there is at least one cyclic reference,
we set unix_graph_maybe_cyclic to true so that we do not skip GC.

So the state transitions as follows:

  (unix_graph_maybe_cyclic, unix_graph_grouped)
  =
  (false, false) -> (true, false) -> (true, true) or (false, true)
                         ^.______________/________________/

There is no transition to the initial state where both variables
are false.

If we consider the initial state as grouped, we can see that the
GC actually has a tristate.

Let's consolidate two variables into one enum.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-3-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 6b6f3c7)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit da8fc7a
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/da8fc7a3.failed

We have been triggering GC on every close() if there is even one
inflight AF_UNIX socket.

This is because the old GC implementation had no idea of the graph
shape formed by SCM_RIGHTS references.

The new GC knows whether there could be a cyclic reference or not,
and we can do better.

Let's not trigger GC from close() if there is no cyclic reference
or GC is already in progress.

While at it, unix_gc() is renamed to unix_schedule_gc() as it does
not actually perform GC since commit 8b90a9f ("af_unix: Run
GC on only one CPU.").

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-4-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit da8fc7a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/af_unix.c
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 3849005
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/38490054.failed

We have been calling wait_for_unix_gc() on every sendmsg() in case
there are too many inflight AF_UNIX sockets.

This is also because the old GC implementation had poor knowledge
of the inflight sockets and had to suspect every sendmsg().

This was improved by commit d9f21b3 ("af_unix: Try to run GC
async."), but we do not even need to call wait_for_unix_gc() if the
process is not sending AF_UNIX sockets.

The wait_for_unix_gc() call only helps when a malicious process
continues to create cyclic references, and we can detect that
in a better place and slow it down.

Let's move wait_for_unix_gc() to unix_prepare_fpl() that is called
only when AF_UNIX socket fd is passed via SCM_RIGHTS.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-5-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 3849005)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/af_unix.c
#	net/unix/af_unix.h
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit e29c7a4
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/e29c7a4c.failed

unix_tot_inflight is a poor metric, only telling the number of
inflight AF_UNXI sockets, and we should use unix_graph_state instead.

Also, if the receiver is catching up with the passed fds, the
sender does not need to schedule GC.

GC only helps unreferenced cyclic SCM_RIGHTS references, and in
such a situation, the malicious sendmsg() will continue to call
wait_for_unix_gc() and hit the UNIX_INFLIGHT_SANE_USER condition.

Let's make only malicious users schedule GC and wait for it to
finish if a cyclic reference exists during the previous GC run.

Then, sane users will pay almost no cost for wait_for_unix_gc().

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-6-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e29c7a4)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/garbage.c
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit ab8b231
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/ab8b2315.failed

unix_tot_inflight is no longer used.

Let's remove it.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-7-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit ab8b231)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/garbage.c
jira KERNEL-1600
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 24fa77d
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/24fa77da.failed

unix_schedule_gc() and wait_for_unix_gc() share some code.

Let's consolidate the two.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20251115020935.2643121-8-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 24fa77d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/af_unix.c
#	net/unix/af_unix.h
#	net/unix/garbage.c
jira KERNEL-1600
cve CVE-2026-23394
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit e5b31d9
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/e5b31d98.failed

Igor Ushakov reported that GC purged the receive queue of
an alive socket due to a race with MSG_PEEK with a nice repro.

This is the exact same issue previously fixed by commit
cbcf011 ("af_unix: fix garbage collect vs MSG_PEEK").

After GC was replaced with the current algorithm, the cited
commit removed the locking dance in unix_peek_fds() and
reintroduced the same issue.

The problem is that MSG_PEEK bumps a file refcount without
interacting with GC.

Consider an SCC containing sk-A and sk-B, where sk-A is
close()d but can be recv()ed via sk-B.

The bad thing happens if sk-A is recv()ed with MSG_PEEK from
sk-B and sk-B is close()d while GC is checking unix_vertex_dead()
for sk-A and sk-B.

  GC thread                    User thread
  ---------                    -----------
  unix_vertex_dead(sk-A)
  -> true   <------.
                    \
                     `------   recv(sk-B, MSG_PEEK)
              invalidate !!    -> sk-A's file refcount : 1 -> 2

                               close(sk-B)
                               -> sk-B's file refcount : 2 -> 1
  unix_vertex_dead(sk-B)
  -> true

Initially, sk-A's file refcount is 1 by the inflight fd in sk-B
recvq.  GC thinks sk-A is dead because the file refcount is the
same as the number of its inflight fds.

However, sk-A's file refcount is bumped silently by MSG_PEEK,
which invalidates the previous evaluation.

At this moment, sk-B's file refcount is 2; one by the open fd,
and one by the inflight fd in sk-A.  The subsequent close()
releases one refcount by the former.

Finally, GC incorrectly concludes that both sk-A and sk-B are dead.

One option is to restore the locking dance in unix_peek_fds(),
but we can resolve this more elegantly thanks to the new algorithm.

The point is that the issue does not occur without the subsequent
close() and we actually do not need to synchronise MSG_PEEK with
the dead SCC detection.

When the issue occurs, close() and GC touch the same file refcount.
If GC sees the refcount being decremented by close(), it can just
give up garbage-collecting the SCC.

Therefore, we only need to signal the race during MSG_PEEK with
a proper memory barrier to make it visible to the GC.

Let's use seqcount_t to notify GC when MSG_PEEK occurs and let
it defer the SCC to the next run.

This way no locking is needed on the MSG_PEEK side, and we can
avoid imposing a penalty on every MSG_PEEK unnecessarily.

Note that we can retry within unix_scc_dead() if MSG_PEEK is
detected, but we do not do so to avoid hung task splat from
abusive MSG_PEEK calls.

Fixes: 118f457 ("af_unix: Remove lock dance in unix_peek_fds().")
	Reported-by: Igor Ushakov <sysroot314@gmail.com>
	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260311054043.1231316-1-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e5b31d9)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/af_unix.h
#	net/unix/garbage.c
jira KERNEL-1600
cve CVE-2026-53361
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit d82ba05
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.55.1.el10_2/d82ba052.failed

Igor Ushakov reported that unix_gc() could run with gc_in_progress
being false if the work is scheduled while running:

  Thread 1         Thread 2                     Thread 3
  --------         --------                     --------
                   unix_schedule_gc()           unix_schedule_gc()
                   `- if (!gc_in_progress)      `- if (!gc_in_progress)
                      |- gc_in_progress = true     |
                      `- queue_work()              |
  unix_gc() <----------------/                     |
  |                                                |- gc_in_progress = true
  ...                                              `- queue_work()
  |                                                       |
  `- gc_in_progress = false                               |
                                                          |
  unix_gc() <---------------------------------------------'
  |
  ... /* gc_in_progress == false */
  |
  `- gc_in_progress = false

unix_peek_fpl() relies on gc_in_progress not to confuse GC
by MSG_PEEK.

Let's set gc_in_progress to true in unix_gc().

Fixes: 8b90a9f ("af_unix: Run GC on only one CPU.")
	Reported-by: Igor Ushakov <sysroot314@gmail.com>
	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260501073945.1884564-1-kuniyu@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit d82ba05)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	net/unix/garbage.c
jira KERNEL-1600
cve CVE-2026-63921
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Maoyi Xie <maoyixie.tju@gmail.com>
commit 8b484ef

After patch 1/2 in this series, vti6_update() unlinks and relinks
the tunnel through t->net. vti6_siocdevprivate() still uses
dev_net(dev) for the collision lookup. For a tunnel moved through
IFLA_NET_NS_FD, dev_net(dev) is the new netns, not t->net.

SIOCCHGTUNNEL on a migrated tunnel then runs:

  net = dev_net(dev)                    /* migrated netns */
  t   = vti6_locate(net, &p1, false)    /* misses target in t->net */
  ...
  t   = netdev_priv(dev)
  vti6_update(t, &p1, false)            /* mutates t->net's hash */

A caller in the migrated netns picks params that match a tunnel
in the creation netns. The lookup in dev_net(dev) finds nothing.
vti6_update() prepends the migrated tunnel at the head of the
creation netns hash bucket for those params. Later lookups in
the creation netns resolve to the migrated device. xfrm receive
delivers the matched packets through a device the caller controls.

Reachable from an unprivileged user namespace (unshare --user
--map-root-user --net). Cross tenant scope on container hosts.

Switch the SIOCCHGTUNNEL path on a non fallback device to use
t->net for the lookup. The lookup now matches the netns
vti6_update() operates on.

Also add ns_capable(self->net->user_ns, CAP_NET_ADMIN) before
the lookup. The check at the top of the case is against
dev_net(dev)->user_ns, which after migration is the attacker's
netns. A caller there can pick params absent from self->net,
the lookup returns NULL, t becomes self, and vti6_update()
inserts the device into the creation netns hash. The new check
requires CAP_NET_ADMIN in the creation netns user_ns too.

SIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep
dev_net(dev), which equals init_net there.

Fixes: 61220ab ("vti6: Enable namespace changing")
	Suggested-by: Jakub Kicinski <kuba@kernel.org>
	Suggested-by: Xiao Liang <shaw.leon@gmail.com>
	Cc: stable@vger.kernel.org # v5.15+
	Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://patch.msgid.link/20260521130555.3421684-3-maoyixie.tju@gmail.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 8b484ef)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-63917
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Kuniyuki Iwashima <kuniyu@google.com>
commit 11b326f

ip netns add ns1
ip netns add ns2
ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7
ip -n ns1 link set vti6_test netns ns2
ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9
ip netns del ns2
ip netns del ns1
[  132.495484] ------------[ cut here ]------------
[  132.497609] kernel BUG at net/core/dev.c:12376!

Commit 61220ab ("vti6: Enable namespace changing") dropped
NETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then
move through IFLA_NET_NS_FD. After the move dev_net(dev) points
at the new netns while t->net stays at the creation netns.

vti6_changelink() and vti6_update() still use dev_net(dev) and
dev_net(t->dev). They unlink from one per netns hash and relink
into another. The creation netns is left with a stale entry.
cleanup_net() of that netns later walks freed memory.

Reachable from an unprivileged user namespace (unshare --user
--map-root-user --net). Cross tenant scope on container hosts.

Fixes: 61220ab ("vti6: Enable namespace changing")
	Reported-by: Maoyi Xie <maoyi.xie@ntu.edu.sg>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
	Cc: stable@vger.kernel.org # v5.15+
	Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Link: https://patch.msgid.link/20260521130555.3421684-2-maoyixie.tju@gmail.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 11b326f)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…ctx()

jira KERNEL-1600
cve CVE-2026-53239
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Sanghyun Park <sanghyun.park.cnu@gmail.com>
commit 7f2d76c

Fix the race by pruning the bin while still holding xfrm_policy_lock,
before dropping it. Use __xfrm_policy_inexact_prune_bin() directly since
the lock is already held. The wrapper xfrm_policy_inexact_prune_bin()
becomes unused and is removed.

Race:

  CPU0 (XFRM_MSG_DELPOLICY)           CPU1 (XFRM_MSG_NEWSPDINFO)
  ==========================          ==========================
  xfrm_policy_bysel_ctx():
    spin_lock_bh(xfrm_policy_lock)
    bin = xfrm_policy_inexact_lookup()
    __xfrm_policy_unlink(pol)
    spin_unlock_bh(xfrm_policy_lock)
    xfrm_policy_kill(ret)
    // wide window, lock not held
                                       xfrm_hash_rebuild():
                                         spin_lock_bh(xfrm_policy_lock)
                                         __xfrm_policy_inexact_flush():
                                           kfree_rcu(bin)  // bin freed
                                         spin_unlock_bh(xfrm_policy_lock)
    xfrm_policy_inexact_prune_bin(bin)
    // UAF: bin is freed

Fixes: 6be3b0d ("xfrm: policy: add inexact policy search tree infrastructure")
	Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit 7f2d76c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-63919
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Zhengchuan Liang <zcliangcn@gmail.com>
commit c16f74d

Transport-mode reinjection stores a struct net pointer in skb->cb and
uses it later from xfrm_trans_reinject(). That pointer must stay valid
until the deferred callback runs.

Take a netns reference when queueing deferred reinjection work and drop
it after the callback completes. Use maybe_get_net() so the queueing
path does not revive a namespace that is already being torn down.

This keeps the existing workqueue design and fixes the netns lifetime
handling in one place for all users of xfrm_trans_queue_net().

Fixes: 7b38019 ("xfrm: introduce xfrm_trans_queue_net")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
Co-developed-by: Luxing Yin <tr0jan@lzu.edu.cn>
	Signed-off-by: Luxing Yin <tr0jan@lzu.edu.cn>
	Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
Assisted-by: Codex:gpt-5.4
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit c16f74d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1600
cve CVE-2026-31663
Rebuild_History Non-Buildable kernel-6.12.0-211.55.1.el10_2
commit-author Jianbo Liu <jianbol@nvidia.com>
commit b05d42e

The dev_hold() on skb->dev during packet reception was originally
added to prevent the device from being released prematurely during
asynchronous decryption operations.

As current hardware can offload decryption, this asynchronous path is
not always utilized. This often results in a pattern of dev_hold()
immediately followed by dev_put() for each packet, creating
unnecessary reference counting overhead detrimental to performance.

This patch optimizes this by skipping the dev_hold() and subsequent
dev_put() when asynchronous decryption is not being performed.

	Signed-off-by: Jianbo Liu <jianbol@nvidia.com>
	Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit b05d42e)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Daniel Lezcano <daniel.lezcano@linaro.org>
commit 5ba405c

The difference between the pit_clocksource_enable() and
pit_clocksource_disable() is only setting the TIF flag for the
clockevent. Let's group them and pass the TIF flag parameter to the
function so we save some lines of code. But as the base address is
different regarding if it is a clocksource or a clockevent, we pass
the base address in parameter instead of the struct pit_timer.

	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20250804152344.1109310-17-daniel.lezcano@linaro.org
(cherry picked from commit 5ba405c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Daniel Lezcano <daniel.lezcano@linaro.org>
commit 3c34321

Most the function are under the form pit_timer_*, let's change the
interrupt acknowledgment function name to have the same format.

No functional changes intended.

	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20250804152344.1109310-18-daniel.lezcano@linaro.org
(cherry picked from commit 3c34321)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Daniel Lezcano <daniel.lezcano@linaro.org>
commit fc346a1

The PIT acronym stands for Periodic Interrupt Timer which is found on
different NXP platforms not only on the Vybrid Family. Change the name
to be more generic for the NXP platforms in general. That will be
consistent with the NXP STM driver naming convention.

	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20250804152344.1109310-19-daniel.lezcano@linaro.org
(cherry picked from commit fc346a1)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Lukas Bulwahn <lukas.bulwahn@redhat.com>
commit d79c3eb

Commit 3f490a74a8a1 ("clocksource/drivers/vf-pit: Rename the VF PIT to NXP
PIT") renames the config VF_PIT_TIMER to NXP_PIT_TIMER, but it misses
adjusting a reference to VF_PIT_TIMER in arch/arm/mach-imx/Kconfig.

Adjust the config reference to the new name.

Fixes: 3f490a74a8a1 ("clocksource/drivers/vf-pit: Rename the VF PIT to NXP PIT")
	Signed-off-by: Lukas Bulwahn <lukas.bulwahn@redhat.com>
	Signed-off-by: Shawn Guo <shawnguo@kernel.org>
(cherry picked from commit d79c3eb)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Daniel Lezcano <daniel.lezcano@linaro.org>
commit bee33f2

The previous changes put in place the encapsulation of the code in
order to allow multiple instances of the driver.

The S32G platform has two Periodic Interrupt Timer (PIT). The IP is
exactly the same as the VF platform.

Each PIT has four channels which are 32 bits wide and counting
down. The two first channels can be chained to implement a 64 bits
counter. The channel usage is kept unchanged with the original driver,
channel 2 is used as a clocksource, channel 3 is used as a
clockevent. Other channels are unused.

In order to support the S32G platform which has two PIT, we initialize
the timer and bind it to a CPU. The S32G platforms can have 2, 4 or 8
CPUs and this kind of configuration can appear unusual as we may endup
with two PIT used as a clockevent for the two first CPUs while the
other CPUs use the architected timers. However, in the context of the
automotive, the platform can be partioned to assign 2 CPUs for Linux
and the others CPUs to third party OS. The PIT is then used with their
specifities like the ability to freeze the time which is needed for
instance for debugging purpose.

The setup found for this platform is each timer instance is bound to
CPU0 and CPU1.

A counter is incremented when a timer is successfully initialized and
assigned to a CPU. This counter is used as an index for the CPU number
and to detect when we reach the maximum possible instances for the
platform. That in turn triggers the CPU hotplug callbacks to achieve
the per CPU setup. It is the exact same mechanism found in the NXP STM
driver.

If the timers must be bound to different CPUs, it would require an
additionnal mechanism which is not part of these changes.

Tested on a s32g274a-rdb2.

	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://lore.kernel.org/r/20250804152344.1109310-21-daniel.lezcano@linaro.org
(cherry picked from commit bee33f2)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Johan Hovold <johan@kernel.org>
commit e25f964

The driver does not support unbinding (e.g. as clockevents cannot be
deregistered) so suppress the bind attributes to prevent the driver from
being unbound and rebound after registration (and disabling the timer
when reprobing fails).

Even if the driver can currently only be built-in, also switch to
builtin_platform_driver() to prevent it from being unloaded should
modular builds ever be enabled.

Fixes: bee33f2 ("clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support")
	Signed-off-by: Johan Hovold <johan@kernel.org>
	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Link: https://patch.msgid.link/20251111153226.579-3-johan@kernel.org
(cherry picked from commit e25f964)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Khristine Andreea Barbulescu <khristineandreea.barbulescu@oss.nxp.com>
commit afb6196

Add PIT0 and PIT1 for S32G2 and S32G3 SoCs

	Signed-off-by: Khristine Andreea Barbulescu <khristineandreea.barbulescu@oss.nxp.com>
	Reviewed-by: Enric Balletbo i Serra <eballetb@redhat.com>
	Signed-off-by: Frank Li <Frank.Li@nxp.com>
(cherry picked from commit afb6196)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Enric Balletbo i Serra <eballetb@redhat.com>
commit a9ac745
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.56.1.el10_2/a9ac745b.failed

The Kconfig logic for selecting the scheduler clocksource on
NXP Vybrid (VF610) uses a `choice` block restricted to 32-bit ARM. This
prevents 64-bit architectures, such as the NXP S32 family, from enabling
the NXP Periodic Interrupt Timer (PIT) driver (CONFIG_NXP_PIT_TIMER).

Relocate the NXP clocksource selection from arch/arm/mach-imx/Kconfig to
drivers/clocksource/Kconfig. This allows the configuration to be shared
across different architectures.

Update the selection to include support for ARCH_S32 and add a "None"
option restricted to ARCH_S32, since Vybrid lacks the ARM Architected
Timer. The Vybrid Global Timer option is restricted to ARCH_MULTI_V7
SOC_VF610 platforms to prevent it from being visible on Cortex-M4 builds,
which lack the ARM Global Timer hardware.

Fixes: bee33f2 ("clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support")
	Signed-off-by: Enric Balletbo i Serra <eballetb@redhat.com>
	Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
	Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260514-fix-nxp-timer-v3-1-a3e68fdb505e@redhat.com
(cherry picked from commit a9ac745)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/clocksource/Kconfig
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Daniel Lezcano <daniel.lezcano@linaro.org>
commit 84b1a90

The timer drivers could be converted into modules. The different
functions to register the clocksource or the clockevent are already
exporting their symbols for modules but the sched_clock_register()
function is missing.

Export the symbols so the drivers using this function can be converted
into modules.

	Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
	Reviewed-by: Thomas Gleixner <tglx@linutronix.de>
	Reviewed-by: Carlos Llamas <cmllamas@google.com>
	Reviewed-by: Will McVicker <willmcvicker@google.com>
	Acked-by: John Stultz <jstultz@google.com>
Link: https://lore.kernel.org/r/20250602151853.1942521-8-daniel.lezcano@linaro.org
(cherry picked from commit 84b1a90)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…diotap

jira KERNEL-1618
cve CVE-2026-63869
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Deepanshu Kartikey <kartikey406@gmail.com>
commit 6c0cf89

When parsing the radiotap header of an injected frame,
ieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value
directly as a shift count:

	info->control.antennas |= BIT(*iterator.this_arg);

*iterator.this_arg is an 8-bit value taken straight from the frame
supplied by userspace, so BIT() can be asked to shift by up to 255. That
is undefined behaviour on the unsigned long and is reported by UBSAN:

  UBSAN: shift-out-of-bounds in net/mac80211/tx.c:2174:30
  shift exponent 235 is too large for 64-bit type 'unsigned long'
  Call Trace:
   ieee80211_parse_tx_radiotap+0xadb/0x1950 net/mac80211/tx.c:2174
   ieee80211_monitor_start_xmit+0xb1f/0x1250 net/mac80211/tx.c:2451
   ...
   packet_sendmsg+0x3eb6/0x50f0 net/packet/af_packet.c:3109

info->control.antennas is a 2-bit bitmap (u8 antennas:2), so only antenna
indices 0 and 1 can ever be represented. Ignore any larger value instead
of shifting out of bounds.

	Reported-by: syzbot+8e0622f6d9446420271f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=8e0622f6d9446420271f
Fixes: ef246a1 ("wifi: mac80211: support antenna control in injection")
	Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260531011721.102941-1-kartikey406@gmail.com
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit 6c0cf89)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
cve CVE-2026-23172
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Kery Qi <qikeyu2017@gmail.com>
commit f0813bc

When receiving data in the DPMAIF RX path,
the t7xx_dpmaif_set_frag_to_skb() function adds
page fragments to an skb without checking if the number of
fragments has exceeded MAX_SKB_FRAGS. This could lead to a buffer overflow
in skb_shinfo(skb)->frags[] array, corrupting adjacent memory and
potentially causing kernel crashes or other undefined behavior.

This issue was identified through static code analysis by comparing with a
similar vulnerability fixed in the mt76 driver commit b102f0c ("mt76:
fix array overflow on receiving too many fragments for a packet").

The vulnerability could be triggered if the modem firmware sends packets
with excessive fragments. While under normal protocol conditions (MTU 3080
bytes, BAT buffer 3584 bytes),
a single packet should not require additional
fragments, the kernel should not blindly trust firmware behavior.
Malicious, buggy, or compromised firmware could potentially craft packets
with more fragments than the kernel expects.

Fix this by adding a bounds check before calling skb_add_rx_frag() to
ensure nr_frags does not exceed MAX_SKB_FRAGS.

The check must be performed before unmapping to avoid a page leak
and double DMA unmap during device teardown.

Fixes: d642b01 ("net: wwan: t7xx: Add data path interface")
	Signed-off-by: Kery Qi <qikeyu2017@gmail.com>
Link: https://patch.msgid.link/20260122170401.1986-2-qikeyu2017@gmail.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f0813bc)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
cve CVE-2026-64176
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Johannes Berg <johannes.berg@intel.com>
commit fb84b5c

On old devices such as 7265D, rates are still encoded in version 1
format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but
rather their PLCP value (e.g. 10 for 1 Mbps CCK rate.)

While introducing v3 rates, I changed the driver from internally
handling v1 rates and converting to v2, to internally handling v3
and converting to v1 or v2 according to the firmware. I accordingly
changed the code in iwl_mvm_mac80211_idx_to_hwrate() to no longer
have different values for different APIs. This was correct.

However, I later reverted this part of the change, because it was
reported that I had broken beacon rates, causing a FW assert/crash.
This caused TX_CMD rates to be set incorrectly, potentially causing
a warning when reported back from the device as having been used.

Fix this (hopefully correctly now) by handling beacon rates in the
TX_CMD that's embedded in the beacon template command separately.
Restore iwl_mvm_mac80211_idx_to_hwrate() to return only the rate
index, not PLCP value, fixing the real TX_CMD.

	Cc: stable@vger.kernel.org
	Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Link: https://patch.msgid.link/20260515151351.7407e293dff7.I4ea1a17f8fe99c933d3f3e30d077cf4246125c3e@changeid
	Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
(cherry picked from commit fb84b5c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
cve CVE-2026-64175
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Sheroz Juraev <goodmartiandev@gmail.com>
commit 2becb38

When iwlwifi firmware crashes (e.g., NMI_INTERRUPT_UNKNOWN on Intel
BE201/Wi-Fi 7), iwl_mld_nic_error() sets mld->fw_status.in_hw_restart
to true. However, iwl_mld_tx_from_txq() does not check this flag before
dequeuing frames from mac80211 and pushing them to the transport layer.

Since the firmware is dead, iwl_trans_tx() returns -EIO for each frame,
which then gets freed immediately. Under high-throughput conditions
(e.g., Tailscale UDP traffic or active SSH sessions), this creates a
tight dequeue-send-fail-free loop that wastes CPU cycles and generates
rapid skb allocation churn, leading to memory pressure from slab
fragmentation.

The RX path already has this guard (iwl_mld_rx_mpdu checks
in_hw_restart at rx.c:1906), and so does the TXQ allocation worker
(iwl_mld_add_txqs_wk at tx.c:156). Add the same guard to
iwl_mld_tx_from_txq() to stop all TX during firmware restart.

Frames left in mac80211's TXQs are naturally drained after restart
completes, when queue reallocation triggers iwl_mld_tx_from_txq()
via iwl_mld_add_txq_list(), or when new upper-layer traffic invokes
wake_tx_queue.

Tested on ASUS Zenbook 14 UX3405CA with Intel BE201 (Wi-Fi 7) on
kernel 6.19.5 where the firmware crashes approximately every 10-15
minutes under Tailscale traffic.

Fixes: d1e879e ("wifi: iwlwifi: add iwlmld sub-driver")
	Cc: stable@vger.kernel.org
	Signed-off-by: Sheroz Juraev <goodmartiandev@gmail.com>
Link: https://patch.msgid.link/20260315081221.2678478-1-goodmartiandev@gmail.com
	Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
(cherry picked from commit 2becb38)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit 3ad2a7b
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.56.1.el10_2/3ad2a7b9.failed

Implement locking in the hardware monitoring core for drivers using
the _with_info() API functions.

Most hardware monitoring drivers need to support locking to protect
against parallel accesses from userspace. With older API functions, such
locking had to be implemented in the driver code since sysfs attributes
were created by the driver. However, the _with_info() API creates sysfs
attributes in the hardware monitoring core. This makes it easy to move
the locking primitives into that code. This has the benefit of simplifying
driver code while at the same time reducing the risk of incomplete of bad
locking implementations in hardware monitoring drivers.

While this means that all accesses are forced to be synchronized, this
has little if any practical impact since accesses are expected to be low
frequency and are typically synchronized from userspace anyway since
only a single process is accessing the data. On top of that, many drivers
use regmap, which also has its own locking scheme and already serializes
accesses.

	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit 3ad2a7b)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	drivers/hwmon/hwmon.c
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit d1e720c
Empty-Commit: Cherry-Pick Conflicts during history rebuild.
Will be included in final tarball splat. Ref for failed cherry-pick at:
ciq/ciq_backports/kernel-6.12.0-211.56.1.el10_2/d1e720c7.failed

Add support for guard() and scoped_guard() for the hwmon subsystem lock
to simplify its use.

	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit d1e720c)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

# Conflicts:
#	Documentation/hwmon/hwmon-kernel-api.rst
#	include/linux/hwmon.h
…ster_with_info

jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Heiner Kallweit <hkallweit1@gmail.com>
commit c909e68

A number of network PHY drivers use the following code:

name = devm_hwmon_sanitize_name(dev, dev_name(dev));
if (IS_ERR(name))
	return PTR_ERR(name);
devm_hwmon_device_register_with_info(dev, name, ..);

Make this a generic fallback option and use the device name if no name
is provided to devm_hwmon_device_register_with_info(). This would allow
to simplify the affected drivers.

	Signed-off-by: Heiner Kallweit <hkallweit1@gmail.com>
Link: https://lore.kernel.org/r/1ebe6961-6445-4408-bfb4-b56173af9db5@gmail.com
[groeck: Update API document]
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit c909e68)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit de0da6a

Add configuration flag indicating if the chip supports alerts and limits
to prepare for adding INA260 support.

	Reviewed-by: Tzung-Bi Shih <tzungbi@kernel.org>
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit de0da6a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit 70fb84a

INA260 is similar to other chips of the series, except it has an internal
shunt resistor. The calibration register is therefore not present. Also,
the current register address was changed, though that does not matter for
the driver since the shunt voltage register (which is now the current
register) value is already used to read the current.

	Cc: Loic Guegan <loic.guegan@mailbox.org>
	Reviewed-by: Tzung-Bi Shih <tzungbi@kernel.org>
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit 70fb84a)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Wenliang Yan <wenliang202407@163.com>
commit 52172ad

SY24655: Support for current and voltage detection as well as
power calculation.

	Signed-off-by: Wenliang Yan <wenliang202407@163.com>
Message-ID: <20241106150547.2538-1-wenliang202407@163.com>
[groeck: Changed order of compatible entries;
 dropped spurious extra return statement in is_visible();
 fixed code problems]
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit 52172ad)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Ciprian Marian Costea <ciprianmarian.costea@oss.nxp.com>
commit 9b116ba

According to the 'ti,ina2xx' binding, the 'vs-supply' property is
optional. Use devm_regulator_get_enable_optional() to avoid a kernel
warning message if the property is not provided.

Co-developed-by: Florin Buica <florin.buica@nxp.com>
	Tested-by: Enric Balletbo i Serra <eballetbo@kernel.org>
	Signed-off-by: Florin Buica <florin.buica@nxp.com>
	Signed-off-by: Ciprian Marian Costea <ciprianmarian.costea@oss.nxp.com>
Link: https://lore.kernel.org/r/20250409074529.2233733-1-ciprianmarian.costea@oss.nxp.com
[groeck: Use standard multi-line comment]
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit 9b116ba)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit caff6fb

Attribute access is now serialized in the hardware monitoring core,
so locking in the driver code is no longer necessary. Drop it.

	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit caff6fb)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Ian Ray <ian.ray@gehealthcare.com>
commit f6e14b5

* Make sysfs entries documentation easier to maintain.
* Use multi-line enum.
* Correct "has_power_average" comment.

Create a new "has_update_interval" member for chips which support
averaging.

	Signed-off-by: Ian Ray <ian.ray@gehealthcare.com>
	Reviewed-by: Bence Csókás <bence98@sch.bme.hu> # v2
	Tested-by: Jens Almer <bagawk@gmail.com>
Link: https://lore.kernel.org/r/20260220112024.97446-3-ian.ray@gehealthcare.com
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit f6e14b5)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Jonas Rebmann <jre@pengutronix.de>
commit 932ca40

The list of supported chips in the header is incomplete and contains no
other information not readily available. Remove the list and instead
hint that the chips supported by this driver have 219/226 compatible
register layout [unlike the ones supported by e.g. ina238].

Remove the unused INA226_DIE_ID define.

	Signed-off-by: Jonas Rebmann <jre@pengutronix.de>
Link: https://lore.kernel.org/r/20260303-ina234-shift-v1-1-318c33ac4480@pengutronix.de
[groeck: macro -> define in commit message]
	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit 932ca40)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1618
Rebuild_History Non-Buildable kernel-6.12.0-211.56.1.el10_2
commit-author Guenter Roeck <linux@roeck-us.net>
commit bfca8ab

Use scoped_guard() instead of hwmon_lock() / hwmon_unlock() to acquire
and release the hardware monitoring subsystem lock.

	Signed-off-by: Guenter Roeck <linux@roeck-us.net>
(cherry picked from commit bfca8ab)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
Rebuild_History BUILDABLE
Rebuilding Kernel from rpm changelog with Fuzz Limit: 87.50%
Number of commits in upstream range v6.12~1..kernel-mainline: 138299
Number of commits in rpm: 67
Number of commits matched with upstream: 53 (79.10%)
Number of commits in upstream but not in rpm: 138246
Number of commits NOT found in upstream: 14 (20.90%)

Rebuilding Kernel on Branch rocky10_2_rebuild_kernel-6.12.0-211.56.1.el10_2 for kernel-6.12.0-211.56.1.el10_2
Clean Cherry Picks: 48 (90.57%)
Empty Cherry Picks: 5 (9.43%)
_______________________________

Full Details Located here:
ciq/ciq_backports/kernel-6.12.0-211.56.1.el10_2/rebuild.details.txt

Includes:
* git commit header above
* Empty Commits with upstream SHA
* RPM ChangeLog Entries that could not be matched

Individual Empty Commit failures contained in the same containing directory.
The git message for empty commits will have the path for the failed commit.
File names are the first 8 characters of the upstream SHA

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥌

@bmastbergen
bmastbergen requested a review from a team September 18, 2026 13:24
@PlaidCat
PlaidCat requested a review from a team September 18, 2026 17:32
@PlaidCat PlaidCat changed the title [rocky10_2] History Rebuild through kernel-6.12.0-211.55.1.el10_2 [rocky10_2] History Rebuild through kernel-6.12.0-211.56.1.el10_2 Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants