From patchwork Sun Sep 27 07:42:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99301 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2C7ECA5FAA for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33578.1790495021139118459 for ; Sun, 27 Sep 2026 00:43:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=aS/1QduU; spf=pass (domain: smile.fr, ip: 209.85.221.52, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-48870973bddso932429f8f.1 for ; Sun, 27 Sep 2026 00:43:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495019; x=1791099819; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=s/8VsgU7Ry1rcW3c4Btm+XkLj/vyHGTsc21Y2CxDYOQ=; b=aS/1QduU1almxROaLaqBDGvtJe2F24esxDalSRRsYUN2Bii/fPma/AYWpT/wlLdESi qWR8yDILqgZwRv/hU2/bR5stHeV+qqLiC3Y41cl4c9k+REaXYKtFybwE/DfIcpYxuZZV uCvIMMDBPIIIkk1Uex4+GNLnFUN4/ifzNpXLE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495019; x=1791099819; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=s/8VsgU7Ry1rcW3c4Btm+XkLj/vyHGTsc21Y2CxDYOQ=; b=Og3cvBVUasi/7RnR/KbQZ7GwxQ+gk3YrmsEotYhCycL9O/++ILl97fuArNnuWcA3c6 92MjAFNkeE8HFWE7SUtqnF0Rn2tLcXV/z7wBRaXwj9bGtBlVM8Il/lRDnHQLQ4dc1uyy 5ZUg0281aFz4lp8zyBK3i/6cg8DyEWVVu5BTLCDQvPV9xb91s3IdafH4v7mQJwIMUmgf EluuNuE35rW3SA03GDhRh1zxlur88cpWs0b5lFgWwu/i3xb9YXm4pFApk6KWACaxdFVi HJNyBa6Ic0WHpicaGfMH2lGj9CJtA0kMaalKPWcm73QapWPoaiNqhaqfavASTHiKRBSb Xssg== X-Gm-Message-State: AFq9FYIPT0cT5SPMoTLlOcBWaaP3sATFAsq56AvYXJgvQh2rhu2Spy52 B5JF7gU/E/16PGvJgvRue/YfnNpWVo3vo34g0pidacV9ExBzbhAaZN5yq5W9IvCOnYtuc5p6Y4V Q1oGdH1s= X-Gm-Gg: AYBFou3aCvoeabd8lknFwytS6+RdxqO11d0o3sVAMWli2yeKAMB91U4IqUvW+ClUpdi UzKb1bxyRtzSY8B2R2hlM+und2PncgrIA9ECqrF9jMVfRcccsCugeUsfmnxwbXmr746ygK0Maeh BTYBmotubIJ2toBDx47RpwjJMqDvsepoRyABnS66YZGFicwjAvYBWxbGxbLeDkRgVcvoNEafZG4 uBZYpEOafFCDKXjKXvYyySQGbVyybQxuzC691Fwt8Ds5L1GRxWnJ+dotK5LdpNQZMATIl63WwwF OBWeSzYaSi00fFmUqOxnvovbq83WSS2uRx/+3FeEe2MoAL2BDt65I3YqicIkZldvJH6X1kUj3mS tv884HSa2mSQHH7j+lRfKHZs0nZo1Sp14ueysYvCgTMC5mtlSSHHYgqO2EZE12E83vTcquexO6M 2r0MjTvqS8u7v15QT1d59GQbXmdND50mC5W6bx8VYlVaqBCpZ2yGVBShG1DWCr2QHb8j5ELzZPL glmYf0zQO+gwyLqT4vu7MRqzEUrOzwO+MWd7wXGljnCe+gAU1mlISZKU25nzxztsZz3xbp3rC5L tgwli9+Q X-Received: by 2002:a05:6000:4b19:b0:488:8882:d504 with SMTP id ffacd0b85a97d-4888882d749mr6094377f8f.10.1790495019015; Sun, 27 Sep 2026 00:43:39 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.38 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:38 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 01/28] go: upgrade 1.26.7 -> 1.26.8 Date: Sun, 27 Sep 2026 09:42:52 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246651 From: Peter Marko Upgrade to latest 1.26.x release [1]: $ git --no-pager log --oneline go1.26.7..go1.26.8 c293dd49cb (tag: go1.26.8) [release-branch.go1.26] go1.26.8 3cc00d9c2b [release-branch.go1.26] cmd/compile: fix mergelocals for arm32/s390x/riscv64 e9fde2dea1 [release-branch.go1.26] debug/elf: use addend when applying ppc relocations d19a1e81bc [release-branch.go1.26] cmd/go/internal: fix copy paste error dbe8fd98d7 [release-branch.go1.26] os: don't symlink on Root.Mkdir("symlink/") on openbsd d1434dbd34 [release-branch.go1.26] internal/cpu: disable AVX+ on netbsd/amd64 This is a bugfix release. Release information: [2] [1] https://github.com/golang/go/compare/go1.26.7...go1.26.8 [2] https://groups.google.com/g/golang-announce/c/QiTRm-HGGtI Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/go/{go-1.26.7.inc => go-1.26.8.inc} | 2 +- ...o-binary-native_1.26.7.bb => go-binary-native_1.26.8.bb} | 6 +++--- ...cross-canadian_1.26.7.bb => go-cross-canadian_1.26.8.bb} | 0 .../go/{go-cross_1.26.7.bb => go-cross_1.26.8.bb} | 0 .../go/{go-crosssdk_1.26.7.bb => go-crosssdk_1.26.8.bb} | 0 .../go/{go-runtime_1.26.7.bb => go-runtime_1.26.8.bb} | 0 meta/recipes-devtools/go/{go_1.26.7.bb => go_1.26.8.bb} | 0 7 files changed, 4 insertions(+), 4 deletions(-) rename meta/recipes-devtools/go/{go-1.26.7.inc => go-1.26.8.inc} (90%) rename meta/recipes-devtools/go/{go-binary-native_1.26.7.bb => go-binary-native_1.26.8.bb} (80%) rename meta/recipes-devtools/go/{go-cross-canadian_1.26.7.bb => go-cross-canadian_1.26.8.bb} (100%) rename meta/recipes-devtools/go/{go-cross_1.26.7.bb => go-cross_1.26.8.bb} (100%) rename meta/recipes-devtools/go/{go-crosssdk_1.26.7.bb => go-crosssdk_1.26.8.bb} (100%) rename meta/recipes-devtools/go/{go-runtime_1.26.7.bb => go-runtime_1.26.8.bb} (100%) rename meta/recipes-devtools/go/{go_1.26.7.bb => go_1.26.8.bb} (100%) diff --git a/meta/recipes-devtools/go/go-1.26.7.inc b/meta/recipes-devtools/go/go-1.26.8.inc similarity index 90% rename from meta/recipes-devtools/go/go-1.26.7.inc rename to meta/recipes-devtools/go/go-1.26.8.inc index fed87015b2c..7fa02ad7100 100644 --- a/meta/recipes-devtools/go/go-1.26.7.inc +++ b/meta/recipes-devtools/go/go-1.26.8.inc @@ -16,4 +16,4 @@ SRC_URI += "\ file://0009-go-Filter-build-paths-on-staticly-linked-arches.patch \ file://0010-cmd-go-clear-GOROOT-for-func-ldShared-when-trimpath-.patch \ " -SRC_URI[main.sha256sum] = "0ed24eac755105085b89fe9cabc2742b91a0ad7b94b59d3ad364918ebc8956ad" +SRC_URI[main.sha256sum] = "4e39b98e42f946fa05ac8bc5b71877df97dbdb7cbb1a777b541667ad7117fd2e" diff --git a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb b/meta/recipes-devtools/go/go-binary-native_1.26.8.bb similarity index 80% rename from meta/recipes-devtools/go/go-binary-native_1.26.7.bb rename to meta/recipes-devtools/go/go-binary-native_1.26.8.bb index 034c051cee7..1865c700fd4 100644 --- a/meta/recipes-devtools/go/go-binary-native_1.26.7.bb +++ b/meta/recipes-devtools/go/go-binary-native_1.26.8.bb @@ -9,9 +9,9 @@ PROVIDES = "go-native" # Checksums available at https://go.dev/dl/ SRC_URI = "https://dl.google.com/go/go${PV}.${BUILD_GOOS}-${BUILD_GOARCH}.tar.gz;name=go_${BUILD_GOTUPLE}" -SRC_URI[go_linux_amd64.sha256sum] = "ffb5f8de10c62550dfddab66b36b57030721e0a44a3218e9e1181d7b59f121ca" -SRC_URI[go_linux_arm64.sha256sum] = "5a4ec883379d51ee9ce1040d5e87f8d35e20387574dd8c947feb01eabc3c1b37" -SRC_URI[go_linux_ppc64le.sha256sum] = "22d3b362d557175fd16b79651cab0cad64f8aaaedca745f66d16f44d56bc5de1" +SRC_URI[go_linux_amd64.sha256sum] = "d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b" +SRC_URI[go_linux_arm64.sha256sum] = "211ffced9dcb9633a55eac6364816ec0ddd951389a740e88fa8b3337971bdda0" +SRC_URI[go_linux_ppc64le.sha256sum] = "0ddf3ecab842013e6bd618602823a0b8158a18d3e9362f2540463ea5aa184975" UPSTREAM_CHECK_URI = "https://golang.org/dl/" UPSTREAM_CHECK_REGEX = "go(?P\d+(\.\d+)+)\.linux" diff --git a/meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb b/meta/recipes-devtools/go/go-cross-canadian_1.26.8.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross-canadian_1.26.7.bb rename to meta/recipes-devtools/go/go-cross-canadian_1.26.8.bb diff --git a/meta/recipes-devtools/go/go-cross_1.26.7.bb b/meta/recipes-devtools/go/go-cross_1.26.8.bb similarity index 100% rename from meta/recipes-devtools/go/go-cross_1.26.7.bb rename to meta/recipes-devtools/go/go-cross_1.26.8.bb diff --git a/meta/recipes-devtools/go/go-crosssdk_1.26.7.bb b/meta/recipes-devtools/go/go-crosssdk_1.26.8.bb similarity index 100% rename from meta/recipes-devtools/go/go-crosssdk_1.26.7.bb rename to meta/recipes-devtools/go/go-crosssdk_1.26.8.bb diff --git a/meta/recipes-devtools/go/go-runtime_1.26.7.bb b/meta/recipes-devtools/go/go-runtime_1.26.8.bb similarity index 100% rename from meta/recipes-devtools/go/go-runtime_1.26.7.bb rename to meta/recipes-devtools/go/go-runtime_1.26.8.bb diff --git a/meta/recipes-devtools/go/go_1.26.7.bb b/meta/recipes-devtools/go/go_1.26.8.bb similarity index 100% rename from meta/recipes-devtools/go/go_1.26.7.bb rename to meta/recipes-devtools/go/go_1.26.8.bb From patchwork Sun Sep 27 07:42:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99287 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 24F49C98324 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33579.1790495021473427915 for ; Sun, 27 Sep 2026 00:43:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Pe0IANu6; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49fff72474fso2790545e9.3 for ; Sun, 27 Sep 2026 00:43:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495019; x=1791099819; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TfCYmfmmfiw0ZvQn/582uN/Gss5ZZgKQHk4Km4WHwuY=; b=Pe0IANu6wvFHAbr3pbmW7SXgqdu25bhYkUUcw8NraZYOFeuns8+Uw14MUnCiwjonE9 +viiX7ChhicisZ4uR8t+gB6XQlY4pfGZVq1bEX1twsivBorDLGJgoLb2K0AANMj5WOBC j9Bvd+6idfHFPiO1ZpRRsFglcd2VETifRbeP4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495019; x=1791099819; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TfCYmfmmfiw0ZvQn/582uN/Gss5ZZgKQHk4Km4WHwuY=; b=ZJ+XZIR3Px3lLwcG6cfIfdjuWt9oSlDS30aSmKY0Q5ERmRfqecFrQQFgXU7UoNtOjA WLTn2PuI/tVeu4qJj3BS/704dn69woOJZ2mPdIHjcUo83NtkJwqSWkvc+JCePe+V3Z4c ivYbQ4nRcK8+Y74QpMXhcYK8AynjaT36V0ROFMmayJeHRSoEcbfVOJvqEx/tdlR68Vrf J9tjXRRxkSzRJFcZ+yXIdAOwJoz8AvGeUqhH7p+dK9fip/7Dc/3P8jP414Qo863RB9NQ AoegLKFDW1cFRb3QOQ4YaLNW3ZlJtuOz7u8GWT3LAQkoNuGuc6o20oq7CL+5yINaFJrZ XB1A== X-Gm-Message-State: AFuF++mEl6QeD+but1o6Zh6fSExaH8/rReiSGZi2/ds6+Ab+eydZjFK2 tv+Xb9Dq4JJI9aK7e3rXh6r0v9dCS8+8rhYW+3t8XVev7xrs7HPYFVpJ7IgerDZ/9cEn4FgaWUg iq2YTkQc= X-Gm-Gg: AYBFou1IYjz5nDI5apZ2na/wH0gSJlfyfDJabU9GMpmfpn+T7MGOr/cULDyXT0xdW+l Z4RaePlDlSD4JbsYE1rlv2rvaYujEwyX8o9wz57iWrA2vzsqysZ6QlUCLjXdndvJV0324n0Y1Jw ooXxBEIqLg1zr3cc7/mLl1s2LSWsCMytCOQcj45ervIm0bSaDVCyzEguDflkk1c8nADeajy9Rif 7U4/ddSHFcehpu7zj9NSEQ8W5jvoc9k96p9hJboohmGXHfFgEn4U/se8P8epJ3ZsUjr+R3UrB+u HOUv1wNklWQ/pZJ5Gb2L42hZjHBslaJQKAUtAY0Fw/o08croARG9XGlOF0A5PVMzmGR5VAa3Lxj MGVNJn4mPlRRNWft76+Il+uSVgS91hKa2wZ8Cn/tYUsHYS5P6JhrKRPasswi6Be3nKTTsGmRlH6 t+5cEsRsR5v1CWNasyRQ6QJWIGGVbiuRCWVi2vwDycBOukdfCpKebq1l13lkbvpOE76QFVHI4Xa JYRV6OU742Z4Knq7VC094R7ix3n/BIs/ItF6AciM4k7DYWG5Z0zRSyT4hTOXmPk2UtB25WykQ== X-Received: by 2002:a05:600c:3b05:b0:4a0:321:6ddd with SMTP id 5b1f17b1804b1-4a003217170mr5490375e9.34.1790495019583; Sun, 27 Sep 2026 00:43:39 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 02/28] cpio: fix "CVE:" marker in CVE-2026-66484.patch Date: Sun, 27 Sep 2026 09:42:53 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246652 From: Yoann Congal "CVE-2026-66484.patch" should point to "CVE: CVE-2026-66484" Cc: Peter Marko Signed-off-by: Yoann Congal Signed-off-by: Richard Purdie (cherry picked from commit 1f561c3454924dc288c86be0978bd2e2038785a8) Signed-off-by: Yoann Congal --- meta/recipes-extended/cpio/files/CVE-2026-66484.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-extended/cpio/files/CVE-2026-66484.patch b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch index 97ce9a785cf..538f80daf9b 100644 --- a/meta/recipes-extended/cpio/files/CVE-2026-66484.patch +++ b/meta/recipes-extended/cpio/files/CVE-2026-66484.patch @@ -6,7 +6,7 @@ Subject: [PATCH] The --no-absolute-filenames option affects hard link targets * src/tar.c (stash_tar_linkname): Apply cpio_safer_name_suffix. -CVE: CVE-2026-66485 +CVE: CVE-2026-66484 Upstream-Status: Backport [https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad] Signed-off-by: Peter Marko --- From patchwork Sun Sep 27 07:42:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99295 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B8EFDCA5FA7 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr2-f17.google.com (mail-wr2-f17.google.com [74.125.225.81]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33580.1790495022062123892 for ; Sun, 27 Sep 2026 00:43:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=ougarz23; spf=pass (domain: smile.fr, ip: 74.125.225.81, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f17.google.com with SMTP id ffacd0b85a97d-4887d06c669so1576296f8f.3 for ; Sun, 27 Sep 2026 00:43:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495020; x=1791099820; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ju4T4+nI0Ckg0c+w4U2y9F/tTSGQ1ESr1vXL35iGoiA=; b=ougarz23rbQJ9LavwjM38tcAkShsuNCHjcgmwjqdZOXxxp+lCPSRxB/PpEHVaMuc99 fHykWYvhC75n/SHlDDATMk1LAsDrtsbHvmfAhEexe6ektNCCbIvTbE8FtleNOcDl3s3+ j5/7BXM9ZTwG5haPdB41yuQGY4HmIzr9KZkxc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495020; x=1791099820; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ju4T4+nI0Ckg0c+w4U2y9F/tTSGQ1ESr1vXL35iGoiA=; b=t072Hs/hVGPf1L+1SkugqlMz95d6fBJSY35R1s3MoeMYq/GG2ZPiQ6GTOU1zvqBqvM s//ywRgfTJtMSFkZ28Kmu9dN6r+VoDckWoTu7sfNP+mKWUVpNMyyaTj4Kjrk7yPAnOts HMkFaRxeg8AO9y6dV23LXNIWuhxMM/eOxboP10d+IhjtB4LnBU41YvQDi2CZHiGBzGVJ 7XSbRO1SRq2/6xkrE+hvuknyXXR47iS8qnhL4BtxYOx1HEYrzxNlyLmdD07hQdaOIJPv clQ3qC8zZp446olASxXdPcYj9UXASsr+i2RVE96Rwe7bGJE4DKwDM/LorSsr55yCrA50 WC0A== X-Gm-Message-State: AFq9FYJvy4im9ooRXIzb8cI/9xuHMO8dtg/AsxywIqhS5QtwUCCUAglE Out67T36rJUHnx+ieUiehyQLouOmqx1coE2NuTPTq7gO7hrZRMF5VN5WlmsO4v7W7upyYNTG9KI sMI+tgKQ= X-Gm-Gg: AYBFou1FakuVKg+PMuwH6mNZ4GcaoxFfcJ8yOjOpAP/A5fbpYjl8nCtCwJW6Na9QD0t xyVf19TX7r//nFM4TpEPbP41gx9KBwdBxWuh6ig2xQbjhJnFJBbMZ6iQevImUL8IvIyCu53NllK BXOWv76BApggQgLTOAyNW4l8vGCDe+y/i4oTApsgBHfB1irYLbxws90yTD2plubv2/29GNzpqQX +MVi9iFqHOXN3eE69DqtkvJRSJrT07G/R2mZ7YLGp3MEUVv2BeKA5ZzxiutSi9I26ys+rsququ9 FgxwdJ/O0D6lKH+D7UZnFC3tpjotUBxFAmSQ1nSS91bA2jCX4EX2uluXS67HA2KtC1+kXkwuB7a uZuvm/ZYYwhOoztAV7eAd9mkrB0AMq0JSwkmEeUK8V8hfGo2uwhfLD2JOc9h+h9kUg/5cHBipoS wQ3Eh88FmX2o0xN0awcTDRBB6gd3Zudw3JMHWMP8my1WpTEunv7YzK5rHECKhBcGkGtTVRkYbve YeBGRdxDyRxItycbuoEmIA8mb0oBuNOncKCSDibd9kR1HeiWtLiadi01Qc/GeFbWOaEHqKtTg== X-Received: by 2002:a05:6000:268a:b0:486:f9d9:fe0d with SMTP id ffacd0b85a97d-48872abc48emr18865140f8f.29.1790495020311; Sun, 27 Sep 2026 00:43:40 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.39 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:39 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 03/28] dhcpcd: upgrade 10.3.1 -> 10.3.2 Date: Sun, 27 Sep 2026 09:42:54 +0200 Message-ID: <3fc3aa51109a3bb43d92b2664e4005848b87f1c1.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246653 From: Richard Purdie Signed-off-by: Richard Purdie (cherry picked from commit 1e61572f9a24839a1a2386a51d40b561f340f78f) Signed-off-by: Jaipaul Cheernam Signed-off-by: Yoann Congal --- .../dhcpcd/{dhcpcd_10.3.1.bb => dhcpcd_10.3.2.bb} | 2 +- ...20-resolv.conf-improve-the-sitation-of-working-with-.patch | 2 +- ...001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch | 4 ++-- .../0001-remove-INCLUDEDIR-to-prevent-build-issues.patch | 4 ++-- 4 files changed, 6 insertions(+), 6 deletions(-) rename meta/recipes-connectivity/dhcpcd/{dhcpcd_10.3.1.bb => dhcpcd_10.3.2.bb} (97%) diff --git a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.1.bb b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.2.bb similarity index 97% rename from meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.1.bb rename to meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.2.bb index eb257cb27c1..5895a2669d9 100644 --- a/meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.1.bb +++ b/meta/recipes-connectivity/dhcpcd/dhcpcd_10.3.2.bb @@ -21,7 +21,7 @@ SRC_URI = "git://github.com/NetworkConfiguration/dhcpcd;protocol=https;branch=ma file://CVE-2026-56117.patch \ " -SRCREV = "42ff6d2548209af3185473e6cb6f9d235c48bbf4" +SRCREV = "243ad84ac67a87d631ff7eb83b2eed2727acebb5" # Doesn't use automake so we can't do out-of-tree builds inherit pkgconfig autotools-brokensep systemd useradd diff --git a/meta/recipes-connectivity/dhcpcd/files/0001-20-resolv.conf-improve-the-sitation-of-working-with-.patch b/meta/recipes-connectivity/dhcpcd/files/0001-20-resolv.conf-improve-the-sitation-of-working-with-.patch index 512e33aebf9..7e04b5c303d 100644 --- a/meta/recipes-connectivity/dhcpcd/files/0001-20-resolv.conf-improve-the-sitation-of-working-with-.patch +++ b/meta/recipes-connectivity/dhcpcd/files/0001-20-resolv.conf-improve-the-sitation-of-working-with-.patch @@ -1,4 +1,4 @@ -From d1581ce103db0a5db0b1761907fff9ddd6b55a8a Mon Sep 17 00:00:00 2001 +From c91f9cdc0ef56fa64f6ffdd811cc5b0e41991b2e Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Wed, 9 Nov 2022 16:33:18 +0800 Subject: [PATCH] 20-resolv.conf: improve the sitation of working with systemd diff --git a/meta/recipes-connectivity/dhcpcd/files/0001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch b/meta/recipes-connectivity/dhcpcd/files/0001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch index 484b84f94ae..9d3065a48b8 100644 --- a/meta/recipes-connectivity/dhcpcd/files/0001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch +++ b/meta/recipes-connectivity/dhcpcd/files/0001-dhcpcd.8-Fix-conflict-error-when-enable-multilib.patch @@ -1,4 +1,4 @@ -From e9b1376c59b15e7b03611429187d9d89167154b5 Mon Sep 17 00:00:00 2001 +From dd892eba0147120efdcae923746c444a9d2a76d2 Mon Sep 17 00:00:00 2001 From: Lei Maohui Date: Fri, 10 Mar 2023 03:48:46 +0000 Subject: [PATCH] dhcpcd.8: Fix conflict error when enable multilib. @@ -29,7 +29,7 @@ Signed-off-by: Lei Maohui 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/dhcpcd.8.in b/src/dhcpcd.8.in -index 91fdde2c..b467dc3b 100644 +index ebbf06c0..c7ffee6b 100644 --- a/src/dhcpcd.8.in +++ b/src/dhcpcd.8.in @@ -826,7 +826,7 @@ Configuration file for dhcpcd. diff --git a/meta/recipes-connectivity/dhcpcd/files/0001-remove-INCLUDEDIR-to-prevent-build-issues.patch b/meta/recipes-connectivity/dhcpcd/files/0001-remove-INCLUDEDIR-to-prevent-build-issues.patch index fd3fae7e7e0..bebc79831d6 100644 --- a/meta/recipes-connectivity/dhcpcd/files/0001-remove-INCLUDEDIR-to-prevent-build-issues.patch +++ b/meta/recipes-connectivity/dhcpcd/files/0001-remove-INCLUDEDIR-to-prevent-build-issues.patch @@ -1,4 +1,4 @@ -From c2ebc32112e0cd29390b4dc951b65efae36d607b Mon Sep 17 00:00:00 2001 +From 0775eb1b965bbf9b0efb0b1c42c3adf3d8cd31cb Mon Sep 17 00:00:00 2001 From: Stefano Cappa Date: Sun, 13 Jan 2019 01:50:52 +0100 Subject: [PATCH] remove INCLUDEDIR to prevent build issues @@ -11,7 +11,7 @@ Signed-off-by: Stefano Cappa 1 file changed, 5 deletions(-) diff --git a/configure b/configure -index a60da137..3673de8b 100755 +index e9c08f18..3f0770b7 100755 --- a/configure +++ b/configure @@ -26,7 +26,6 @@ BUILD= From patchwork Sun Sep 27 07:42:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99299 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2DC0BCA5FA8 for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33581.1790495022531761895 for ; Sun, 27 Sep 2026 00:43:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=V41Qp6E8; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f63546c5so1807952f8f.2 for ; Sun, 27 Sep 2026 00:43:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495021; x=1791099821; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=lY6HYo6u5HEiyok9gJ4pBuUaJXvZPiTN5wt2jCTWDOY=; b=V41Qp6E86Md09woX0fUVTT1RL5hF2c5hlRO4xNWTK5mP1AYlvYEY/2MP4s0hYi+j/q Yh72i3B9LkGgcOZ9w1GeTiKjAt8yMIil9JKH7jrz4CPz9OVaZcRVSHTV7Dd6GsxENJ4A vxZL3CqliricOV9WM01y8Rtp2jk1er5gQC2jg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495021; x=1791099821; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=lY6HYo6u5HEiyok9gJ4pBuUaJXvZPiTN5wt2jCTWDOY=; b=pXcOIm8NS+c5IdFnbV07Jwjlzk5c0BjxLJo8zJen4zeKMb1MCpc7R0h44HkvcaEzRJ r9j+Aux+z4F+LATmPtTUu1su049n9b17mWoi7XWQd+KJKK/zqsGy+B8x3/FMT5GUXvUc ERmZdD+6wGVCeQnUSkCu6ejrBOH9aoIBc9JDEawfnFovSJ/+Y3HmmybRR4/1f2iIh4FL nE3B68hDx/1q77BAkgm+eJqYb8U53axA2INC1vRAm4RCF62HtNznpszZsba8nk5+N1Hw IPhnvVgdZbzEInht6OlOSspfiVrmq+Xk8UqK0TLlGTyy6c/CzR0BiBfBKbSQAPOSQeAf zL9g== X-Gm-Message-State: AFq9FYIRvU638vLa01U1UtyJtacyNAXl9EzSibIoB0/yIyv3yONGl1BW sMDnT6BRYhYkQq/+SuEUiZIs4ScOu1CgdSWQ1wTbW7zscTrAO3AU6EHGZDcw84lNp2xQnZprgNR vrISiHaU= X-Gm-Gg: AYBFou0+dkuv6AlX9t7pO9BRV7f43/SOcLNwFhPxB//QypVFdWVRaAVQUWwSAihPKxM BCWC8iSPas7wGLJT7orVrjpR+4p5r8/i72cepeIjVP2t0toNATIa69CGnCLpf0eLhdveX+0fx7E 7WfouSuVgx0vIwh8MfjgwoZRwfiHdUy+qCfPQEwb58+kq09NxIHUjQUM1Qyw9K3lZ4mN/Bjh+v0 H1zm3IwYQj/e73z8A/yqB/RqyTfjvLkNuKKABPOs7EuCYl/FbJ6ePSL03yEMRCDdQRXZZIU9HZ1 srujHl4ZSBsMwE210xJKOgmSH07IGokQQ6bH0YYq0gXuqBVC9/Is7HHPkKZfuTPCCao5T78W9gx jDKY3sa232zctfu/sdiULdo17h7MF0gCZ1ixu5Kkh71lZAo+JpBFTfZii4d1/zNE6A/tgRYB4UY iO99G7KUxzD8e6jTkFJds0Pu2qYA3kRuJESwwfoBOiWlRYGgpfc4aqKVJtebwj7d/GckKI490hh pU8ULPLovCZrmAmDcs967dlITZRfEhwmi4FLzBJmOCJeSeUyKUzXq20bB75+/+aMLDoZLRvoQ== X-Received: by 2002:a5d:5c87:0:b0:488:7dc6:4ea with SMTP id ffacd0b85a97d-4887dc60806mr8387837f8f.10.1790495020777; Sun, 27 Sep 2026 00:43:40 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:40 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 04/28] kernel-fit-image: Don't add hash node when signing is enabled Date: Sun, 27 Sep 2026 09:42:55 +0200 Message-ID: <9b41949a431661ad5c6e01955734c2d83fef732d.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246654 From: Jonas Juffinger When fit image signing is enabled, mkimage does not fill the configuration hash node even if it is present. This causes the verification to fail in U-Boot with a "Bad Data Hash" error because the hash node exists but is empty. This patch adds a check to only add the configuration hash node if signing is not enabled and fixes the respective test cases. The example FIT from the official documentation also shows the configuration field with only the signature, without the hash field: https://docs.u-boot.org/en/latest/usage/fit/signature.html#signed-configurations To further ensure that this change is valid, I also checked the U-Boot source for the hash and signature generation code: https://github.com/u-boot/u-boot/blob/main/tools/image-host.c#L1593 The function fit_config_add_verification_data only adds the signature and no hash. Compare with fit_image_add_verification_data which adds both. Signed-off-by: Jonas Juffinger Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 7346ffe190482ee4932728ba8d8741be8bed1d5b) Signed-off-by: Denys Dmytriyenko Signed-off-by: Yoann Congal --- meta/lib/oe/fitimage.py | 2 +- meta/lib/oeqa/selftest/cases/fitimage.py | 8 +++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/meta/lib/oe/fitimage.py b/meta/lib/oe/fitimage.py index d7e21171ab9..a1040181a23 100644 --- a/meta/lib/oe/fitimage.py +++ b/meta/lib/oe/fitimage.py @@ -480,7 +480,7 @@ class ItsNodeRootKernel(ItsNode): f"{default_flag} {', '.join(conf_desc)}", opt_props=opt_props ) - if self._hash_algo: + if self._hash_algo and not self._sign_enable: ItsNodeHash( "hash-1", conf_node, diff --git a/meta/lib/oeqa/selftest/cases/fitimage.py b/meta/lib/oeqa/selftest/cases/fitimage.py index b35dda6674a..84e21346abe 100644 --- a/meta/lib/oeqa/selftest/cases/fitimage.py +++ b/meta/lib/oeqa/selftest/cases/fitimage.py @@ -627,9 +627,10 @@ class KernelFitImageBase(FitImageTestCase): if uboot_sign_enable == "1" and fit_sign_individual == "1": req_its_paths.append(['/', 'images', image, 'signature-1']) for configuration in configurations: - req_its_paths.append(['/', 'configurations', configuration, 'hash-1']) if uboot_sign_enable == "1": req_its_paths.append(['/', 'configurations', configuration, 'signature-1']) + else: + req_its_paths.append(['/', 'configurations', configuration, 'hash-1']) not_req_its_paths = [] for image in not_images: @@ -792,14 +793,15 @@ class KernelFitImageBase(FitImageTestCase): # Add signing related properties if needed if uboot_sign_enable == "1": for section in req_sections: - req_sections[section]['Hash algo'] = fit_hash_alg if section.startswith(bb_vars['FIT_CONF_PREFIX']): - req_sections[section]['Hash value'] = "unavailable" req_sections[section]['Sign algo'] = "%s,%s:%s" % (fit_hash_alg, fit_sign_alg, uboot_sign_keyname) num_signatures += 1 elif fit_sign_individual == "1": + req_sections[section]['Hash algo'] = fit_hash_alg req_sections[section]['Sign algo'] = "%s,%s:%s" % (fit_hash_alg, fit_sign_alg, uboot_sign_img_keyname) num_signatures += 1 + else: + req_sections[section]['Hash algo'] = fit_hash_alg return (req_sections, num_signatures) def _check_signing(self, bb_vars, sections, num_signatures, uboot_tools_bindir, fitimage_path): From patchwork Sun Sep 27 07:42:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99300 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C61F1C98338 for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33582.1790495023341611260 for ; Sun, 27 Sep 2026 00:43:43 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Olv59hxk; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-4887f6cf16bso1182661f8f.0 for ; Sun, 27 Sep 2026 00:43:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495021; x=1791099821; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=n+ltU5Fptqu5AZtCGP7ruogO2bYxnfQbtV/912E9LRE=; b=Olv59hxk/Oke5aJPQqvCTmbtYs4MgKIhXnzpkIqzLi8HZ7NXCB6ZlsY4PXSIGdFY/6 3Gvt4TpwAh6lMtDjacRSDlX4maKTMwD69j1EqMnU3hefQ+R4jjd6ATEC8/oMth4ONyn8 8rS5mLHU5M9futGRzPUogUcjh21B6ioDbpSKg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495021; x=1791099821; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=n+ltU5Fptqu5AZtCGP7ruogO2bYxnfQbtV/912E9LRE=; b=ltZv3+O4s4CWHeiyru2dgmWhKSEeDBWNPG9Sv3T8x6veFWbS2FKr4qWA7wktW2U+pb LQJO9XVtugq2T20SSt1NqSN3aE3XnPwdEnc9xOJaWeqmMf0Vo5CYqkISR797Kxa+z4qC 5YMLDX+reExEkYMjB1oIAHERiys4+rjpmKZZvXraTm9eDNJpYMSVJlR45N7NFwrMeZKb f9tFp6AaWjyRU7NM73ndmBjdcl+Fg6t5o6F38bLSAvuR2aAQGC++zYvolgBYUxPOTTGM ILS3/ccfQnEtuNglFZDDEHpHD41+cqiyyJQ95w5Q7A6KVbM6/849AwxliBkQo+XFRa6T 0eXA== X-Gm-Message-State: AFq9FYLN/4M0zoEycs72XNIfZnDSA+Oaezq9BQh30KzeYYNWkwn/m5FW 6WfbDFvJH+knlZvk+PvQTz7inUSZFkaUyidVgRXGCiNacbta+C1+Xo4EBJXMa7dzH8iTMqUkJJz yvtsfPeQ= X-Gm-Gg: AYBFou05r/SGCwNQkDXLtTXuyudF/qYQjfv4ydZ/Uo1nzKnEkwYi3m1P2i7bvHczXLQ BQlkqgZmnhNroVYRM8ZrcUUImgMy+ApL71Xtq2HP4Hv0lr2beEzhxgEJPeLlF5W8gs2omrnJW3G mrdt/sgoMwFu0pLBzmiFf1JKpzNaJRJrnNWv3QP81HLdiYXFe20D2iGECrgstjoxkvQIO95D+Le 5m0pm8lwKUY0LjZktdaFEvukHsIwpjTOXg2J9KvzoV3DuB5+1Gt3yLUyUQS3aemQYR+RLAfQcSl X0bJTPbIHUGznpeW38a4yfLR8Zlq4qouhHV0bV5YTxex5NOAIn2IM0LRg2EeBxGSDxIx4nAcZqU HSbuxB1skHOMh8pyDOLLhk4e1VNqoCVU7Ny1EDBV6G4RNvAcW/xwB2t0Uxu43ROlLHOpE9odVaL cMKbG6Sgy0V5CLayA2um1QiNWIFH1aF7cdmk10w6wwQUKTqtJBdjb82Ne+SIYo/ZahJlm6rrinf 7hdNcl+T0QU3LeKSAnMhdrt6utBQGIkqvkfYDeHm2BxGm277y8BNdKCgEy68/4q98yu6vLxzg== X-Received: by 2002:a05:6000:40e1:b0:488:5fca:a837 with SMTP id ffacd0b85a97d-4887da11182mr12247663f8f.20.1790495021535; Sun, 27 Sep 2026 00:43:41 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.40 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:40 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 05/28] ffmpeg: mark CVE-2026-52295, CVE-2026-52296 and CVE-2026-52297 fixed Date: Sun, 27 Sep 2026 09:42:56 +0200 Message-ID: <0970f28b05c0f328c7c93335797237346fd5eb2d.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246655 From: Ankur Tyagi CVE-2026-52295: Debian[1] identified the fix[2] which exists[3] in the upstream version. CVE-2026-52296: Debian[4] identified the fix[5] which exists[6] in the upstream version. CVE-2026-52297: Debian[7] identified the fix[8] which exists[9] in the upstream version. [1]https://security-tracker.debian.org/tracker/CVE-2026-52295 [2]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/016a241102250372a9c2e96f6e8dca67ec01d3f7 [3]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ff43ef5219ad543e57ed56d065e9d4a3b0426468 [4]https://security-tracker.debian.org/tracker/CVE-2026-52296 [5]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/23227a444de4a8f7696f46660cdd044b460f7e47 [6]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d18354f8d4bd018eb486d18079ff0afb3b84c506 [7]https://security-tracker.debian.org/tracker/CVE-2026-52297 [8]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8439e0203744a30d280668fcd086f74ed5001da1 [9]https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ebff1abbad8b036bfc0f52a4785433b06e865e3b Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal [YC: fixed a typo] --- meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 48ece247600..b3b78a7936b 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -196,3 +196,6 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0" CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0" CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3" CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2" +CVE_STATUS[CVE-2026-52295] = "fixed-version: fixed since v8.0.2" +CVE_STATUS[CVE-2026-52296] = "fixed-version: fixed since v8.0.2" +CVE_STATUS[CVE-2026-52297] = "fixed-version: fixed since v8.0.2" From patchwork Sun Sep 27 07:42:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99298 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 09ED4CA5FA6 for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33583.1790495024246754121 for ; Sun, 27 Sep 2026 00:43:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=h001ax1H; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d3931so16333725e9.3 for ; Sun, 27 Sep 2026 00:43:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495022; x=1791099822; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=/qN+5oh8Trn3DSSJ6/h20ldcGjoVA4cchj69KA/U2+Q=; b=h001ax1HsZTSbaCosnnuO6sVAPRvuIeCjqYGZo5TSYPe6ZveMEKEDm1FvY8ibd92Wp Nd0intKKyldkU6jFRjRVoc3zbAVbCo57WQOgxFXNyEfyEhRRS9J2m76I+wmM8KBSdgOI yr6OLLG6p0DLwfSNC3Wyb/xWt6XznwlFFvwAw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495022; x=1791099822; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=/qN+5oh8Trn3DSSJ6/h20ldcGjoVA4cchj69KA/U2+Q=; b=LVpzTHVw5zdUzxB9MQaPHOI7+fWXXefPFyJtUcSswZS+wVcUyLM3Ru8HSEd3OkJHtn CHfIV9ApPtAA3ewO5DJJ9siAdu6wBYUp+h213o/c1XYzC78K18S0VSg6uegrYOosWNzz yVyG04igKilR3ErRAZ9CRyDwfceXXWveQVHevZ2e15YrPyeHKVYq0tKlUcUAZ92q5YAS aNVN2pnCy4QK8zPlR9SAIFqWlXtSTJ0aDKqkoqk5Uj7KowgztNfdKdjyhkjhL19lh6ao i47JiaAtGBAmwFWk6AM1J5d3B7CpcOIBk7eAz6gPIjs3R7hr2pSPE5W3KHnSpevHymTr q3hw== X-Gm-Message-State: AFuF++kdMe6/4+/6+lE7MJuhxlDEJz80O5VZBN/scPU7vgZtAbzPEg4C dreBvZJtRQfdoRRJzAeBTv6o5I6xJ1MGIhBgp23D4nlbEvmQt40TpOO9fX/BKtp3aXpx+JNbV9B idej/3jI= X-Gm-Gg: AYBFou3AE4+BfSUckCTJK0c+EYy0pYBVXntV3DLNeeW8AkPtd73cL5Qpg4pfjpLhJj9 DVK1wXaNw2Md34dILe2pOXSwDl7E3QzwxrlhgulRFkdCCvAqGU8dLHjAcCy0vHidPi9wO0ldxEG TujknWAxD83KgU5l9aUmOc5tNNoQ/xcCmdXV15epB+opCWzHmvt/o0CPrpbUvuX1ywxiNKjDmZT JAXvAMqJgZ4DE1b90WYQss8/8r2LoRf8+25MhTbO/cpHipbltfBUE6DX9LoOZi/LeAlqH0OKbmY DeSSSFhRoCf83k8iss86pGgsdSEnWZCwXDy7LXyftT8wdc77Nm2NINwBRj/klVelnY7f5znhmHJ yHeT6UU0Pq1l8Jku/bw8HFQqZeKXsSJ1fy/FR8B68sdaqUcPC/B8DiAC/MTjDHXGwTPt3d5gred EkoczTw767vNu5NaAVVwD3bKViNB/7b97LSUdDxPgDhi7qNk7EEbqz+l+zM65l9abh+0Syl9wE8 Z+MmRnqijo9gKC2UcmD+xqvbkPO+LFrQjIVjMZtUO7otCA454NsgiihA0b7b6MrEdG857cwEPk= X-Received: by 2002:a05:600c:8b8a:b0:49c:fc6c:be15 with SMTP id 5b1f17b1804b1-49fe6701f1amr170560085e9.27.1790495022507; Sun, 27 Sep 2026 00:43:42 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.41 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:41 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 06/28] libxfont2: patch CVE-2026-59679 Date: Sun, 27 Sep 2026 09:42:57 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246656 From: Ankur Tyagi Debian[1] also identified the fix. [1]https://security-tracker.debian.org/tracker/CVE-2026-59679 Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-59679.patch | 93 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 94 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch new file mode 100644 index 00000000000..8e2ea4bd62b --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-59679.patch @@ -0,0 +1,93 @@ +From 016a21b1eea8e4aef4949e19cdf5f386f36fd978 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 13 Jul 2026 15:48:06 +1000 +Subject: [PATCH] fserve: validate num_chars against encoding array size in + fs_read_glyphs + +FS_QueryXExtents16 causes us to allocate the encoding[] array, later +during the FS_QueryXBitmaps16 reply handling we fill in that array. +There is no verification that the allocation is large enough, a +malicious font server could send us a small numExtents and a +large num_chars to force underallocation and OOB read/rwrite. + +A regression test is included that constructs a crafted +FS_QueryXBitmaps16 reply with num_chars > num_encoding and verifies +the library rejects it. + +CVE-2026-59679 + +Found-by: Zhixi "Jace" Sun, independent security researcher +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: + +CVE: CVE-2026-59679 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/668fea81f40bcb48ec67fb55d0b851049d265290] + +Dropped makefile and test changes during backport. + +Signed-off-by: Ankur Tyagi +--- + src/fc/fserve.c | 22 ++++++++++++++++++++++ + src/fc/fservestr.h | 1 + + 2 files changed, 23 insertions(+) + +diff --git a/src/fc/fserve.c b/src/fc/fserve.c +index abf7d07..744a68c 100644 +--- a/src/fc/fserve.c ++++ b/src/fc/fserve.c +@@ -1081,6 +1081,7 @@ fs_read_extent_info(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + return AllocError; + } + fsfont->encoding = pCI; ++ fsfont->num_encoding = numExtents; + if (haveInk) + fsfont->inkMetrics = pCI + numExtents; + else +@@ -1980,6 +1981,17 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + { + minchar = 0; + maxchar = rep->num_chars; ++ ++ /* Reject replies where num_chars exceeds the encoding array ++ size allocated in fs_read_extent_info() to prevent ++ out-of-bounds access on encoding[]. */ ++ if (rep->num_chars > (CARD32)fsdata->num_encoding) ++ { ++ ErrorF("fserve: num_chars (%u) > num_encoding (%d)\n", ++ (unsigned) rep->num_chars, fsdata->num_encoding); ++ err = AllocError; ++ goto bail; ++ } + } + + off_adr = (char *)ppbits; +@@ -2001,6 +2013,16 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + for (i = 0; i < rep->num_chars; i++) + { + memcpy(&local_off, off_adr, SIZEOF(fsOffset32)); /* align it */ ++ /* Bounds-check minchar against the encoding array size to ++ prevent out-of-bounds access from a malicious font server ++ reply with more num_chars than num_extents. */ ++ if (minchar >= (unsigned long)fsdata->num_encoding) ++ { ++ ErrorF("fserve: glyph index %lu >= num_encoding (%d)\n", ++ minchar, fsdata->num_encoding); ++ err = AllocError; ++ goto bail; ++ } + if (blockrec->type == FS_OPEN_FONT || + fsdata->encoding[minchar].bits == &_fs_glyph_requested) + { +diff --git a/src/fc/fservestr.h b/src/fc/fservestr.h +index 29ae46e..da95e41 100644 +--- a/src/fc/fservestr.h ++++ b/src/fc/fservestr.h +@@ -43,6 +43,7 @@ typedef struct _fs_glyph { + typedef struct _fs_font { + CharInfoPtr pDefault; + CharInfoPtr encoding; ++ int num_encoding; + CharInfoPtr inkMetrics; + FSGlyphPtr glyphs; + } FSFontRec, *FSFontPtr; diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index de6418b11a5..8775d1cc13d 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -18,6 +18,7 @@ BBCLASSEXTEND = "native" SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ file://CVE-2026-56003.patch \ + file://CVE-2026-59679.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" From patchwork Sun Sep 27 07:42:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99291 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5B4B6CA5FA3 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32855.1790495025287474914 for ; Sun, 27 Sep 2026 00:43:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=hw8utQ92; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-4887d06c669so1576312f8f.3 for ; Sun, 27 Sep 2026 00:43:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495023; x=1791099823; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=uHWIKBHi2HOlR4eEKUSrqGZswLFireko1xikBLg3V+c=; b=hw8utQ92EmiqymkZConPHq/LdIDXlizd8UoNm1kV7dDXeWetBYsK2ctrmh4i6H5vnw RqyWTva7ONlIj/Wl2rb6F0s0RZ29ango4JmvZ0HB2IFvTfebu7pYkxdM5xlRGZyTYO4m UdQsoUQHm1BydfmXO7MTbZP23WOzUKAvEAuz8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495023; x=1791099823; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uHWIKBHi2HOlR4eEKUSrqGZswLFireko1xikBLg3V+c=; b=hYcVfywOOkr/wlof6BQEeZx8115JEtUaldQVaYk2MeOZydlrF+zOuZEmKsO9UZB/N0 9IteEWFmJXiMuouzBswoJH5Ak1HdVVlQOZ+wQhB5DksMtochpXFMfK42bExuFXw4SbSB 919diw43AYy4rddKt494WChRBkxq1stAP4VbRr5GHTIjcczQnYvJw+Vx0U4UXBdmkzPS q6iQn4JeVHWWgMD7Rl63Q3NWfSAi3NqPCp18MCqppBFnLYIH/cPjf1oeUpaEPYUuJ4Uj QA5+HyXvA1WeELCB3nFxml8pAyo9loVLH6vkvMKMFXWuPSh9SeITtjWCqwoVeUIpQYCL EjXQ== X-Gm-Message-State: AFq9FYJI20NIB34lapcXTRk88XSshIQkafo7EyqhlJaUWgiIQtP9w8UF Tn55NFlclPEkd1qFnVJT7bzP5JKV0c4PCdIP9tnIoxIBD2n1dtHXau4qMZztcxCod6FiAfw7stl zfEnMM18= X-Gm-Gg: AYBFou0uYtLYxJ4uLgQG3EGq+A3e7w5wjUJ59hY5qAecfxiLUaoqfWlcUF709/86FqE qDKr/gn118/q08m/TfPbSi3SW8JbLBWl/TZwWjy6kSsEWrjwHSxpFP0pGl80SeYA6wXOP1hFoqz R/BQeBWw2JGcsL8/RG7gL1rHjr2zZedVs6o5q0YeLMNDCqvpsI4psylHzSBIRnTsCiO8z/Bkbpl XioQsD5a2+90nM84kvlq8IonE6q6yeNX6hf29s43BWnpjepbpoyNAM2C7A7xErJ8hfUj0GmYLxt akyclPPguh79GyplWgxXHSjBzYRef+zA98UbyVMc38HBLYI/WJNjT/i40C4fufvC9fMzowy6szJ +RewM/eqiiSF4hzcQhXaNc0JdsQpZ21DkI7Lgh8qVdywwXs7KLSC/6wBdPg76sOiJM538KHWTXK evPJE68jHmLiNbuq0vbK4hj5MoZbZcE0X8EveE1KTCba9yTDdXLZ2mGwwcOm+mMbCd7FHzeeG2c osjrIu9zVeELjV2F/hYr5JlKLWCPpB7faM5PY1TsMYEYlGEx+PX4pI4xLQT/OfGCV/h0pnNBQ== X-Received: by 2002:a05:6000:41d1:b0:488:5db4:791e with SMTP id ffacd0b85a97d-48872a5c50amr18058057f8f.11.1790495023399; Sun, 27 Sep 2026 00:43:43 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.42 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:42 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 07/28] libxfont2: patch CVE-2026-44950 Date: Sun, 27 Sep 2026 09:42:58 +0200 Message-ID: <8d24302fac46c0cbb94b930465c139d1cc1b7e6e.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246657 From: Ankur Tyagi Debian[1] also identified the fix. [1]https://security-tracker.debian.org/tracker/CVE-2026-44950 Signed-off-by: Ankur Tyagi Signed-off-by: Yoann Congal --- .../xorg-lib/libxfont2/CVE-2026-44950.patch | 99 +++++++++++++++++++ .../xorg-lib/libxfont2_2.0.7.bb | 1 + 2 files changed, 100 insertions(+) create mode 100644 meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch diff --git a/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch new file mode 100644 index 00000000000..96e3c1f0a85 --- /dev/null +++ b/meta/recipes-graphics/xorg-lib/libxfont2/CVE-2026-44950.patch @@ -0,0 +1,99 @@ +From b48aa50f2ba02f74167492c1c3aa312a7590991a Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 13 Jul 2026 15:50:09 +1000 +Subject: [PATCH] fserve: bounds-check cumulative glyph data writes in + fs_read_glyphs + +fs_read_glyphs() copies each glyph's bitmap into a single allbits +buffer allocated to rep->nbytes bytes. The per-glyph guard validates +only that the source slice (position, length) lies within the pbitmaps +source buffer. It does not check whether the running destination cursor +has exceeded the allocation. + +A malicious font server can send overlapping source offsets (e.g. 1000 +glyphs each referencing {position:0, length:64} with nbytes=64). Each +individual source range passes validation, but the cumulative writes +total 64000 bytes into a 64-byte destination buffer. + +Interestingly there was an unconditional debug printf in place that +sort-of warned about this but didn't prevent this. Let's remove that and +instead use the actual check to bail out before we run OOB. + +A regression test is included that sends 100 glyphs each referencing +the same 64-byte source slice into a 64-byte destination buffer, and +verifies the library rejects the overflow. + +CVE-2026-44950 + +Found-by: Zhixi "Jace" Sun, independent security researcher +Assisted-by: Claude:claude-opus-4-6 +Signed-off-by: Peter Hutterer +Part-of: +(cherry picked from commit c2d222bb22c623d8a40f3275077fc7e6617f2c8a) + +CVE: CVE-2026-44950 +Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/c2d222bb22c623d8a40f3275077fc7e6617f2c8a] + +Dropped test changes during the backport. + +Signed-off-by: Ankur Tyagi +--- + src/fc/fserve.c | 23 ++++++++++++++--------- + 1 file changed, 14 insertions(+), 9 deletions(-) + +diff --git a/src/fc/fserve.c b/src/fc/fserve.c +index abf7d07..0fdc090 100644 +--- a/src/fc/fserve.c ++++ b/src/fc/fserve.c +@@ -1899,10 +1899,7 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + fsOffset32 local_off; + char *off_adr; + pointer pbitmaps; +- char *bits, *allbits; +-#ifdef DEBUG +- char *origallbits; +-#endif ++ char *bits, *allbits, *origallbits; + int i, + err; + int nranges = 0; +@@ -1992,8 +1989,8 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + goto bail; + } + +-#ifdef DEBUG + origallbits = allbits; ++#ifdef DEBUG + fprintf (stderr, "Reading %d glyphs in %d bytes for %s\n", + (int) rep->num_chars, (int) rep->nbytes, fsd->name); + #endif +@@ -2014,6 +2011,18 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + (local_off.position < rep->nbytes) && + (local_off.length <= (rep->nbytes - local_off.position))) + { ++ /* Check that the destination buffer has enough room ++ for this glyph to prevent a heap overflow from ++ overlapping source offsets. */ ++ if (local_off.length > ++ rep->nbytes - (allbits - origallbits)) ++ { ++ ErrorF("fserve: glyph data overflow: " ++ "cumulative write exceeds nbytes (%u)\n", ++ (unsigned) rep->nbytes); ++ err = AllocError; ++ goto bail; ++ } + bits = allbits; + allbits += local_off.length; + memcpy(bits, (char *)pbitmaps + local_off.position, +@@ -2041,10 +2050,6 @@ fs_read_glyphs(FontPathElementPtr fpe, FSBlockDataPtr blockrec) + } + off_adr += SIZEOF(fsOffset32); + } +-#ifdef DEBUG +- fprintf (stderr, "Used %d bytes instead of %d\n", +- (int) (allbits - origallbits), (int) rep->nbytes); +-#endif + + if (blockrec->type == FS_OPEN_FONT) + { diff --git a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb index 8775d1cc13d..17cfc133d66 100644 --- a/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb +++ b/meta/recipes-graphics/xorg-lib/libxfont2_2.0.7.bb @@ -19,6 +19,7 @@ SRC_URI += "file://CVE-2026-56001.patch \ file://CVE-2026-56002.patch \ file://CVE-2026-56003.patch \ file://CVE-2026-59679.patch \ + file://CVE-2026-44950.patch \ " SRC_URI[sha256sum] = "8b7b82fdeba48769b69433e8e3fbb984a5f6bf368b0d5f47abeec49de3e58efb" From patchwork Sun Sep 27 07:42:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99294 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A03F2CA5FA5 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr2-f36.google.com (mail-wr2-f36.google.com [74.125.225.100]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33584.1790495026192413252 for ; Sun, 27 Sep 2026 00:43:46 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=rMBe9NqO; spf=pass (domain: smile.fr, ip: 74.125.225.100, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f36.google.com with SMTP id ffacd0b85a97d-4843c3ee4cfso945431f8f.2 for ; Sun, 27 Sep 2026 00:43:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495024; x=1791099824; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=e/4uUKZU3YSXbJYb8+trpXBNoskde5b0Pl1tQxHutyg=; b=rMBe9NqOtnEufb14QgFEDpGs0fxp1bdrTzm144ZOq5tmZnHw/s+2Rj02DTkkSbFCjd koGWb3ILGknvPySlGMTz8scU+n1g5hMuuCNSbI+go/e5ffre5TbvyKl27sxkpd7j6Mf/ IY+JsdqjUFeSj7ZB9/ZmRrbX+lFYdDF0SuaZU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495024; x=1791099824; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=e/4uUKZU3YSXbJYb8+trpXBNoskde5b0Pl1tQxHutyg=; b=cDP4H/c7woMj4mSI4G1fucalHp/WO5WXfdueL0KHJQPHM2h6BbI4bg/cSdWqRa1cbA U6X7r3pWJajuPdBKi/qC+sZFpDFZjwjiC7OTilybCL1pZDg7Q24W+WmHr6wwWgcfBVTi llN1LFA8s214tt6NTtGojAEht9RI4wV+N2Hei9gO/wbuwvHbRuoBfO0hU77Zqoc3npYC fzlnY3CX20+rLcNlWlZ0WiS3MNj71pzTSU1wHRovAAaT+sdZkUCAGUZUig7OfVpc2Tdd rE1k+qWVBLWlSbB0tULARoxjVIUwI4WhJyCT0lbgsE+u/+el7OnF4nmbskjkIrxXb54C FmPw== X-Gm-Message-State: AFq9FYLVQtiN+cdoWfkhPNmwkHdSWt1UD4ryXw03axPOYtbwLMC+SP88 Vc4QKvPBRYYhgjYa0sHJReqzHUhlPDj34PdEu4Eyx3YqMbGQ/ESRjMdFO/UqS6ZoVbNY8p9JLfV pxt9Kf8U= X-Gm-Gg: AYBFou05lqBnSoMaMwZvjUMIK6pk+XbH56VXYxn8da/39e9GSn65W7fFbYbfWTkRXfs q04pJlLdhxazf8lHhNOLaDoEhZtUFJjMhDCuOGXBS+YzHGTBQ9lDo79t5CTWjg/7WbfZb2focAH BtSxxGvZ+4RQhV3XssIp4ucOJAxV7nF84QKxXlFeeVKQ7AfTESdMVEIUTYAAXU/WLRktRugUh5J pT0n/CrEOL9PdbQSar+tvIuEPb488Zuh8UMvsXVESSby7qRPtYK+NZ/EJ0qF2dkcVs6BOGxapsl NBk+XZU9NBFmERPzARaBxueZb5UFWulYbKDnHoGWIVL+NYqOADkPgPYxqGlmwFPjiGonw2+SjDi 6e2gMezbSe70ufoSAOf24ZFenJteq2XoKXxFFFR2Y7oNl38BFA2/U2ETywLVTaCD3JJT6y32BnZ qQXWWkeTshvMOWNaCDxm63Bh4xImU8JG5Xchv2VA8sz5w0cnVdZDS/N9aHAHMYCFYwdkqKo28fG cBbvOQl5chT5g2vEj7uwAr6FrfxVnMuyJR0YOMjRA+eVB6Q3UiaXKs32Q/t2lnlEku97HeVNA== X-Received: by 2002:a05:6000:4910:b0:488:8b16:ab33 with SMTP id ffacd0b85a97d-4888b16ae2amr3426563f8f.10.1790495024221; Sun, 27 Sep 2026 00:43:44 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:43 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 08/28] bluez5: restrict delta=0 RSSI to proximity filters Date: Sun, 27 Sep 2026 09:42:59 +0200 Message-ID: <9c8556d59cb8a5d4fa78f617782b8daf3b2b22fa.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246658 From: Xiuzhuo Shang When a discovery filter is active (filtered_discovery=true), BlueZ unconditionally calls device_set_rssi_with_delta(..., delta=0), causing every BLE advertisement to emit a PropertiesChanged(RSSI) signal regardless of whether the RSSI value changed. delta=0 is only needed when a client has expressed explicit proximity interest by setting an RSSI or pathloss threshold in its discovery filter. Filters that specify only transport type or UUIDs do not require per-packet RSSI precision; for those, the standard RSSI_THRESHOLD=8 rate-limiting is both correct and desirable. Signed-off-by: Xiuzhuo Shang Signed-off-by: Yoann Congal [YC: fixed patch format] --- meta/recipes-connectivity/bluez5/bluez5.inc | 1 + ...ct-delta-0-RSSI-to-proximity-filters.patch | 86 +++++++++++++++++++ 2 files changed, 87 insertions(+) create mode 100644 meta/recipes-connectivity/bluez5/bluez5/0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch diff --git a/meta/recipes-connectivity/bluez5/bluez5.inc b/meta/recipes-connectivity/bluez5/bluez5.inc index ad07e0d3c4f..d857c23a577 100644 --- a/meta/recipes-connectivity/bluez5/bluez5.inc +++ b/meta/recipes-connectivity/bluez5/bluez5.inc @@ -75,6 +75,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/bluetooth/bluez-${PV}.tar.xz \ file://0001-advertising-Fix-sending-extra-bytes-with-MGMT_OP_ADD.patch \ file://0001-src-device-Fix-stored-gatt-cache-DB-Hash-value-no.patch \ file://0001-profile-Set-L2CAP-IMTU-for-OBEX-profile-listeners.patch \ + file://0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch \ " S = "${UNPACKDIR}/bluez-${PV}" diff --git a/meta/recipes-connectivity/bluez5/bluez5/0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch b/meta/recipes-connectivity/bluez5/bluez5/0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch new file mode 100644 index 00000000000..8dd9e318feb --- /dev/null +++ b/meta/recipes-connectivity/bluez5/bluez5/0001-adapter-restrict-delta-0-RSSI-to-proximity-filters.patch @@ -0,0 +1,86 @@ +From d00dd99229bc9ce78b0e8bb3bb523a3cd504473c Mon Sep 17 00:00:00 2001 +From: Xiuzhuo Shang +Date: Wed, 15 Jul 2026 17:06:35 +0800 +Subject: [PATCH] adapter: restrict delta=0 RSSI to proximity filters + +When a discovery filter is active (filtered_discovery=true), BlueZ +unconditionally calls device_set_rssi_with_delta(..., delta=0), +causing every BLE advertisement to emit a PropertiesChanged(RSSI) +signal regardless of whether the RSSI value changed. + +delta=0 is only needed when a client has expressed explicit proximity +interest by setting an RSSI or pathloss threshold in its discovery +filter. Filters that specify only transport type or UUIDs do not +require per-packet RSSI precision; for those, the standard +RSSI_THRESHOLD=8 rate-limiting is both correct and desirable. + +The problem is triggered on dual-mode adapters by a transport-only +filter (e.g. Transport=le). In merge_discovery_filters(), the +transport-specific scan type (SCAN_TYPE_LE=6) does not equal the +adapter scan type (SCAN_TYPE_DUAL=7), so has_filtered_discovery is +set, filtered_discovery becomes true, and delta=0 is applied even +though no proximity condition was requested. With hundreds of BLE +devices advertising simultaneously this generates hundreds of +unnecessary PropertiesChanged(RSSI) signals per second. + +Confirmed on QCS6490 (BlueZ 5.72) with Transport=le filter: + + adapter.c: filtered_discovery=1 (current_discovery_filter=set) + device.c: device_set_rssi_with_delta() rssi=-86 delta_threshold=0 + device.c: device_set_rssi_with_delta() rssi=-79 delta_threshold=0 + +Add discovery_filter_has_proximity() which walks discovery_list and +returns true only when at least one active filter carries a real +proximity condition (rssi != DISTANCE_VAL_INVALID or pathloss != +DISTANCE_VAL_INVALID). Use this to gate the delta=0 path. + +Other filter fields (transport, uuids, duplicate, discoverable) +express capability or content criteria and carry no proximity +implication, so they are intentionally excluded from the check. + +Upstream-Status: Backport [e004414a1751d29216ccab976d6c7174ec48d11c] +Signed-off-by: Xiuzhuo Shang +--- + src/adapter.c | 19 ++++++++++++++++++- + 1 file changed, 18 insertions(+), 1 deletion(-) + +diff --git a/src/adapter.c b/src/adapter.c +index fb95e8553..1023e43a2 100644 +--- a/src/adapter.c ++++ b/src/adapter.c +@@ -7255,6 +7255,22 @@ static void filter_duplicate_data(void *data, void *user_data) + *duplicate = client->discovery_filter->duplicate; + } + ++static bool discovery_filter_has_proximity(struct btd_adapter *adapter) ++{ ++ GSList *l; ++ ++ for (l = adapter->discovery_list; l; l = g_slist_next(l)) { ++ struct discovery_client *client = l->data; ++ struct discovery_filter *filter = client->discovery_filter; ++ ++ if (filter && (filter->rssi != DISTANCE_VAL_INVALID || ++ filter->pathloss != DISTANCE_VAL_INVALID)) ++ return true; ++ } ++ ++ return false; ++} ++ + static bool device_is_discoverable(struct btd_adapter *adapter, + struct eir_data *eir, const char *addr, + uint8_t bdaddr_type, bool *auto_connect) +@@ -7451,7 +7467,8 @@ void btd_adapter_device_found(struct btd_adapter *adapter, + if (name_resolve_failed) + device_name_resolve_fail(dev); + +- if (adapter->filtered_discovery) ++ if (adapter->filtered_discovery && ++ discovery_filter_has_proximity(adapter)) + device_set_rssi_with_delta(dev, rssi, 0); + else + device_set_rssi(dev, rssi); +-- +2.43.0 + From patchwork Sun Sep 27 07:43:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99292 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 91CB8CA5FA4 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32856.1790495026777840491 for ; Sun, 27 Sep 2026 00:43:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=cqpw23bJ; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f6351831so1148990f8f.1 for ; Sun, 27 Sep 2026 00:43:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495025; x=1791099825; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=MWpjyzqXOrR1qK0UQs0H5jyVw0bZX5U+gDM2ofEXjaM=; b=cqpw23bJzNIGRUKB9yGq1zaGrs0W0KhGeILKpDqY4ZAmgj2Td4YpW7RxyQCOnjeA/g VBpYcjkgZsV/MjLwhI4zfsWDavVUD4c62aH4B2cTIdYxjccky7ZkojN8lKXjfeSNU4bj wVwqNwpFo7XuQXa1CeQPlgYx5S952HYczBZMg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495025; x=1791099825; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=MWpjyzqXOrR1qK0UQs0H5jyVw0bZX5U+gDM2ofEXjaM=; b=Rgm8sqhalBDN1bkVyhrtxFp8ulcWnRkC81nCqCzFogLsfpltf46M9yEMXUl/RailzS +D0EmJIuyaReHsJbz3+GN0jqbrYaRb0RM6xtpHEINxJFMhRPzgYXKZmOt6L2m/tFfrwT WY1/anyhfcTabv+kDkiFmVFTgTcZEOfz4KSUlfqcaQyUqXh2ANO+SwMFDQzIzvlgVaXP dOjnh/Z6mxZcRrdY/yxMY4ZW3DmEwWybIJqy81QKKf84t/i3gsWRIFrhnsuOx3aE4jVb WwWz7+LETjJ2o3StT3+nrgC2wKPkb+EPCdoz/SqnGvN5vbFjwavGyNgrjzj/8GZl6KcK aOMw== X-Gm-Message-State: AFq9FYK0sZ1cGG47DzcuHEp/srpI4/cUZnlW+N8FjrOxyHred10A7QF+ cj724uJOl50SI2j08It/VPTkdaA3BEpSgqWzbKXcdU3vBNnMuuvxXTS5iI3pZoDIBVMCGH187CH jm9dJqME= X-Gm-Gg: AYBFou3w9X353W/WMV+7fxGwkqgUzn3juKNgatKIMNqOC8EuF9sR13RvTy/900nHPty wwC1HhJ8iTgskmmaMqk0O/wWFiQnV4HanVwmciYXAiZu09txbf4B4mju3y5NBoIwQCAuEU5oRSl aUEiKyZTkcl5Fw5e2nUH1df4VRThY3wq9TxJ8sJKU0lTUvkp8UeKdzt5okzyvQ+HpLnAgfFJSbD OlldlAYNeWV9avRanONOIYs15gCGYfJ2vWLEls9ZaLauwtpjcAS0Gf5L2GUz6HAg4FyyqsDK3BX CvN5+gRfA+r8Z/LZGKMg9B4vGZpLEmkXtXluDBtNjsDDl2y7z2oykG14hSvOvyA1kVvcqPZfEqw uQG4SwZz3wl/9wZHhKvqbw/rVktStkdUJzDbO2hLaGbr8fDeHGCWurIe2gjiFiLhkPFwmFzA4b0 FJBkrCvn2iLuVbQzd9xBzzf9aLrYiQHL/mKAYKzkxD4cKunN51UAodiWtT5mLi0Qt6QItSWX3Qp f+CQJ/M/Mjmr9a1QTlisd4YvfIloa0+vboNfmgYSeBCdnERICeqFqpHW7aqY2TGYrvObV6pVw== X-Received: by 2002:a05:6000:144f:b0:488:8726:8f96 with SMTP id ffacd0b85a97d-488872690a6mr6420391f8f.29.1790495025109; Sun, 27 Sep 2026 00:43:45 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.44 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:44 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 09/28] fmt: update branch name to main Date: Sun, 27 Sep 2026 09:43:00 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246659 From: Peter Marko Upstream repository has renamed branch master to main. Fetching currently does not work (except from downloads mirror). Master branch has updated this in upgrade commit * 3336a94097f57485e4b06e91e7bddd5fdef99e80 Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/recipes-devtools/fmt/fmt_12.1.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/recipes-devtools/fmt/fmt_12.1.0.bb b/meta/recipes-devtools/fmt/fmt_12.1.0.bb index 22cab6f1382..b51e0eed650 100644 --- a/meta/recipes-devtools/fmt/fmt_12.1.0.bb +++ b/meta/recipes-devtools/fmt/fmt_12.1.0.bb @@ -4,7 +4,7 @@ HOMEPAGE = "https://fmt.dev" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://LICENSE;md5=b9257785fc4f3803a4b71b76c1412729" -SRC_URI = "git://github.com/fmtlib/fmt;branch=master;protocol=https;tag=${PV} \ +SRC_URI = "git://github.com/fmtlib/fmt;branch=main;protocol=https;tag=${PV} \ file://0001-Workaround-an-ABI-issue-in-spdlog.patch \ file://run-ptest \ " From patchwork Sun Sep 27 07:43:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99293 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 76265CA5FA2 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32857.1790495027540750274 for ; Sun, 27 Sep 2026 00:43:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=kBM94Zv0; spf=pass (domain: smile.fr, ip: 209.85.221.46, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-488885c3844so554943f8f.0 for ; Sun, 27 Sep 2026 00:43:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495026; x=1791099826; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BpGVufLe95AwW+tM2WALjrjpgZUmd+E/9jCdnWYwKc4=; b=kBM94Zv0TG74VLvZZiawJp7WWJqRuW/wTNy1OpRrUqCcOYQev3EX50KN/0Z9Jihx0h 3A46OWp2uGkXEEJZJnXkZRjxok0E18NwsukDfb7ceLYQBt2B/67VZ6Wz+kR57TPhkhy+ XwFuuMeFk1rmnN65MF3YLjz9w3vpA4MEXHVLA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495026; x=1791099826; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=BpGVufLe95AwW+tM2WALjrjpgZUmd+E/9jCdnWYwKc4=; b=HDoTMsYBOixbsdyXMvA37pC6R/WUj3KqbUvBj/j8EDyzTGnVvY3mtjfmbcDYOoUYsw 6YcpdRiBPJSDt1+hl6e9nSV4k8RtvAfVyW78GlCRYwBM2/qG3kYhO3VRu7F/l6uRPab7 ztqv2iKsW0v4+8NxCUcSgXdYghqe1vP6ofYXrpOCbCDxsJGrlkOwRcW8eJ92zcf7dgip GUo/VbpvK1Po6XCDN6XVUu4J3yo8fexBGGi+hTrntZ4Dpqu0gsUJ3VF3LBOENO/c9pJD zubPoiRUBMSu3t7AfSboAzcuMs/dcPlV5nML4faLwVgw6f+zsW2EkC2zY1EeOUovLnuy JHmw== X-Gm-Message-State: AFq9FYKQBoqLLexTqWnxYH3hHoIMI2AOsfIkA7Yldx4YeLsqdi6jj/Q0 k0q/p7e4sWzWRDAHbzCUK/AFQI1G/QUXJckP+Tu+Fge+e/CCZpOqAS0e2gT3KdtXtWp1g/8G+7c 4sFlTufE= X-Gm-Gg: AYBFou37s7LkZKQLiSuOhGFdMn7YIjFmo5+W97wdiLf6xvbtJRjfrYPNFmNt/0HPV0e TJ/6V6k0W0PnjAJGhzHxBasm1PZxk89w1nSu6Ohg1BiMaQfOznf95puVl1w9h3J0R0/UrMi1Zh2 laQoJQan1BSsrFbTa2kev8BJZzOFKCGUirQK/DdF+g0k7FiPUzNIfrBTNLBWvwdE4fq144a+n86 OMTxyIbB0KC/DhATfgoyqYi4uEGGXvcSqmzyvT+MBS7shCXJO2g6QRudXGQdehaD+4b56uP1cma tErNXjJFo1k0mn5Ovo4Rj4Btx2yr8sWindQzcq2ZuSeCnFxEEn1TJDoGHt4pjY/etIOR75U/jIj k8VnbMgtgYwQskzce0CS+2s3bWnxPkfxerByIzFtlO4G1xAx664Mq2RRcczFf0+TwGy26J15EsK 98paI4oTjhG9o5EFNAH70r1Hbn+P+ljNLpSYnGj+SrtRj1rA6rTQOxlF+Srnfl2E3QtDg/yNvH7 cNleSoeCns8SfL5MzdsBm2buC1WNz/JhV+3HmxbxFkypomANNMNr5s6yOVxZ7mB5bAu9AAcjA== X-Received: by 2002:a05:6000:4103:b0:487:c3e:d6cc with SMTP id ffacd0b85a97d-4887171e51bmr18231511f8f.31.1790495025757; Sun, 27 Sep 2026 00:43:45 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 10/28] vim: Fix CVE-2026-28417 hostname regression Date: Sun, 27 Sep 2026 09:43:01 +0200 Message-ID: <8aad82361ba459a6ec3947a1f38bce28c52e0941.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246660 From: Devansh Patel The older Vim patch 9.2.0073 fixed CVE-2026-28417 by tightening netrw hostname validation. That CVE fix requires follow-up regression patches because it rejects valid hostnames containing optional ports or underscores. Vim 9.2.0340 already contains that CVE fix and patch 9.2.0089, which corrects optional-port handling. It still needs patch 9.2.0553 to accept underscores, so backport that commit and retain its _gateway regression test. The netrw history hunk is adapted to preserve Wrynose's existing multi-line history and append the upstream 2026 May 28 entry. The src/version.c hunk is omitted because this backport does not change the recipe version or Vim's upstream patch-number table. [1] https://github.com/vim/vim/commit/79348dbbc09332130f4c86045e1541d68514fcc1 [2] https://github.com/vim/vim/commit/a6198523fb28a50d96945458792cdb4787d3cdda [3] https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11 [4] https://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336 Signed-off-by: Devansh Patel Signed-off-by: Yoann Congal --- .../vim/files/CVE-2026-28417-regression.patch | 65 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-28417-regression.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-28417-regression.patch b/meta/recipes-support/vim/files/CVE-2026-28417-regression.patch new file mode 100644 index 00000000000..e5d947b7374 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-28417-regression.patch @@ -0,0 +1,65 @@ +From a058d0dcd289ddb934b30125ac732f737bf89eb7 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 28 May 2026 20:53:53 +0000 +Subject: [PATCH] patch 9.2.0553: runtime(netrw): netrw rejects hostnames + containing _ + +Problem: runtime(netrw): netrw rejects hostnames containing _ + (lilydjwg) +Solution: Relax the restriction and allow the underscore + +fixes: #20344 + +CVE: CVE-2026-28417 +Upstream-Status: Backport [https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11] + +Backport Changes: +- Wrynose's netrw header uses a chronological change-history list instead + of upstream's "Last Change:" field, so add the equivalent 2026 May 28 + history entry. +- Omitted src/version.c because this backport does not change the recipe's + Vim version or its upstream patch-number table. + +Signed-off-by: Christian Brabandt +(cherry picked from commit 93d177cd2b69bac58fc51a5a514d7bc71e264b11) +Signed-off-by: Devansh Patel +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 5 +++-- + src/testdir/test_plugin_netrw.vim | 1 + + 2 files changed, 4 insertions(+), 2 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index c240bbd13..54be15b3f 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -24,6 +24,7 @@ + " 2026 Mar 01 by Vim Project include portnumber in hostname checking #19533 + " 2026 Apr 01 by Vim Project use fnameescape() with netrw#FileUrlEdit() + " 2026 Apr 05 by Vim Project Fix netrw#RFC2396() #19913 ++" 2026 May 28 by Vim Project allow underscores in hostname checking #20344 + " 2026 Jun 16 by Vim Project Fix filename escaping in local file deletion + " Copyright: Copyright (C) 2016 Charles E. Campbell {{{1 + " Permission is hereby granted to use and distribute this code, +@@ -2604,8 +2605,8 @@ function s:NetrwValidateHostname(hostname) + " Username: + let user_pat = '\%([a-zA-Z0-9._-]\+@\)\?' + " Hostname: 1-64 chars, alphanumeric/dots/hyphens. +- " No underscores. No leading/trailing dots/hyphens. +- let host_pat = '[a-zA-Z0-9]\%([-a-zA-Z0-9.]\{0,62}[a-zA-Z0-9]\)\?' ++ " No leading/trailing dots/hyphens. ++ let host_pat = '[a-zA-Z0-9_]\%([-a-zA-Z0-9._]\{0,62}[a-zA-Z0-9_]\)\?' + " Port: 16 bit unsigned integer + let port_pat = '\%(:\d\{1,5\}\)\?$' + +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index a0a3915f5..8d7167793 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -574,6 +574,7 @@ endfunc + func Test_netrw_hostname() + let valid_hostnames = [ + \ 'localhost', ++ \ '_gateway', + \ '127.0.0.1', + \ '::1', + \ '0:0:0:0:0:0:0:1', diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index b3732cb780e..de639a65026 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -46,6 +46,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-73076.patch \ file://CVE-2026-73077.patch \ file://CVE-2026-73078.patch \ + file://CVE-2026-28417-regression.patch \ " PV .= ".0340" From patchwork Sun Sep 27 07:43:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99296 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3BADAC9830E for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33585.1790495028014749962 for ; Sun, 27 Sep 2026 00:43:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=D2KeztHV; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-485984ebf5cso1625338f8f.0 for ; Sun, 27 Sep 2026 00:43:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495026; x=1791099826; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=I/cVBnea7LnXXs0VgcP/HtkafhU6jxQyEXhC9rmlNfI=; b=D2KeztHVcb395iFm5i8IvgEHbTyOD4I+Jba2p1UAj6vc1W0avPy1Aq6kMeAgDjEF2w 25eFoMypaXhkzEjdePmUMWZIRaD3kgEdeop9ECVN4TWSp4OI0YdHxOv1iuL94yZFubJl XqHH4cY+PuE0eWEe2dJC3W2ChHbuvrawBebFk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495026; x=1791099826; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=I/cVBnea7LnXXs0VgcP/HtkafhU6jxQyEXhC9rmlNfI=; b=Z9KycMUrNUFw86/xONjQ/tqsOB35lSdnNSAb58QmSwiKU55WlKTwhc9HIas8NF0EM9 /80BA8hGIg74j0dfAMLvGzabPIkTCXU27VxUnhVz3A839pNDJUNOPTXrftc9ul7VNkF1 Y6Phv0625A2gqbeh45AORpwidDiAAJ+5qd8pEYTQLQrKmza1xRB5OS5b6oE8UAG0yuD1 MmW3cYi3B1FJDuZNqX4gkjh5jlO5VpoJTRs71km7lBgV5A769LdEO02gdE5bCWB46LKq mVDc3WerKGHFYI4bn9z4g7KqRvFC7qBd4iwBPZxZbPu/GlIxZZKNArUstY5qYDY1MSKY LvHg== X-Gm-Message-State: AFq9FYIQt+J+WKUXcOXPjZQ8XquOM4RVnY+Ve6Imf6j4OXAwpj3ZXy6h EzAWx6NXrpZgt2g5ECgwcTBkotqfxlgszcUIfU6n/iWre40miogtQ+bAab4/UxJfCaExgj/qe66 WmLenkfg= X-Gm-Gg: AYBFou1vfi+FFNWMu2PmliGqwbqzhH0G3FOFam+9xWEolkrgZiorBLJKCNnQ7XkCkaT BHoMZiihvh6mN9enxwTzgit67p7NTszI9R+sK8Cdy0ElOT/09+BHRQbF5YtyE98PzTuEvOYr9mJ L6So5hQfn/9gZLXADEsWgpp1PPc3QFBdP/DJ4I0HiRS9u+EaZ7ApOXzJo87BXXc+GwWRoRncjy7 inwxB+49AqQyASdXVPk3GBHVT+5oq2zStdUqVVM70GLIgScwNRt7cOfq5fUC7IjtO7KzYr4scAI 2xb1i/M0+zFGVrtnK54YxFtJIWX8pAUSA4r+Fw/DaHdGXzqe6zbXo+N5fb/S6f/iLqZ9kKkzrJh wPVTrEdQXP0OzWfB41hlNN1j0JS5BAv+gIBn3IwDpNlz81Rg/265AdQX0zG6jTM1Fu6wAI0+6FG D3VYo7hTxkN3Jd/Clr+b9UOz8LTwCWaBOwZ4U6dVhSHp3ByCYwuuw0W0NQMBFbyOIF/dSWZt3nV LObsK27TifxNpag4MYiv2V0kpuujJxT9+ltUiTEc1HuGP8L4S4/ShkFsK+D6puQ8p9h5S+eVw== X-Received: by 2002:a5d:5d08:0:b0:487:35c:6e6b with SMTP id ffacd0b85a97d-48872a5c2d7mr20201612f8f.12.1790495026287; Sun, 27 Sep 2026 00:43:46 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:45 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 11/28] toolchain-scripts: fix kernel host tool builds broken in the SDK Date: Sun, 27 Sep 2026 09:43:02 +0200 Message-ID: <18584d330d0711d1d670c73b806e1f98e1d11c69.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246661 From: Daniel Dragomir Building an out-of-tree kernel module with an SDK fails while the kernel is compiling its own host tools: $ cd $SDKTARGETSYSROOT/usr/lib/modules/*/build $ make modules_prepare ... /usr/include/sys/cdefs.h:486: error: "__attribute_const__" redefined /usr/include/stdlib.h:219: error: redundant redeclaration of 'strtol' objtool and the other tools under tools/ ask pkg-config where libelf is, via HOSTPKG_CONFIG. They are host programs, but the SDK environment sets PKG_CONFIG_SYSROOT_DIR and PKG_CONFIG_PATH so that pkg-config answers for the target, and that answer now contains -I/usr/include. Passing /usr/include explicitly with -I makes the compiler treat those headers as ordinary headers rather than system headers, so the warnings inside them stop being suppressed and -Werror turns them into errors. Ordinary applications built with the SDK are affected too, less visibly: they pick up a redundant -I$SDKTARGETSYSROOT/usr/include and -L$SDKTARGETSYSROOT/usr/lib that they never used to get. Neither the kernel nor the SDK layout changed. What changed is which pkg-config implementation the SDK ships. pkg-config dropped system directories such as /usr/include from its answer on its own. pkgconf only drops them if they are listed in PKG_CONFIG_SYSTEM_INCLUDE_PATH and PKG_CONFIG_SYSTEM_LIBRARY_PATH, and it compares those lists against paths that already have the sysroot prepended. So the lists have to hold sysroot-prefixed paths, and the SDK environment never set them at all. a3320989ca ("class/pkgconfig: use pkgconf instead of pkgconfig") already sysroot-prefixed both variables for the build environment, in pkgconfig.bbclass. Do the same for the SDK environment. Checked with pkgconf 2.5.1 on a .pc file inside a sysroot, with PKG_CONFIG_SYSROOT_DIR set: before: -I$S/usr/include -I$S/usr/include/bsd-1.0 -L$S/usr/lib -lbsd after: -I$S/usr/include/bsd-1.0 -lbsd which is what pkg-config used to return for the same input. The native sysroot directories are listed as well. Setting either variable replaces pkgconf's built-in list instead of adding to it, and for nativesdk-pkgconf that built-in list is what currently keeps nativesdk .pc files from leaking their own -I and -L into host tool builds. toolchain_create_tree_env_script() is left alone: it already passes an unset $libdir and $prefix to its own PKG_CONFIG_PATH line, so it needs a separate look. Assisted-by: kiro:claude-opus-5 Signed-off-by: Daniel Dragomir Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (cherry picked from commit 1d61d5ba90e07525029343e347dca4963364c55b) Signed-off-by: Yoann Congal --- meta/classes-recipe/toolchain-scripts.bbclass | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/classes-recipe/toolchain-scripts.bbclass b/meta/classes-recipe/toolchain-scripts.bbclass index 8c062ef0e74..3c1ceb32bf7 100644 --- a/meta/classes-recipe/toolchain-scripts.bbclass +++ b/meta/classes-recipe/toolchain-scripts.bbclass @@ -63,6 +63,8 @@ toolchain_create_sdk_env_script () { echo "export PATH=$sdkpathnative$bindir:$sdkpathnative$sbindir:$sdkpathnative$base_bindir:$sdkpathnative$base_sbindir:$sdkpathnative$bindir/../${HOST_SYS}/bin:$sdkpathnative$bindir/${TARGET_SYS}"$EXTRAPATH':"$PATH"' >> $script echo 'export PKG_CONFIG_SYSROOT_DIR=$SDKTARGETSYSROOT' >> $script echo 'export PKG_CONFIG_PATH=$SDKTARGETSYSROOT'"$libdir"'/pkgconfig:$SDKTARGETSYSROOT'"$prefix"'/share/pkgconfig' >> $script + echo 'export PKG_CONFIG_SYSTEM_INCLUDE_PATH=$SDKTARGETSYSROOT'"$prefix"'/include:'"$sdkpathnative${includedir_nativesdk}" >> $script + echo 'export PKG_CONFIG_SYSTEM_LIBRARY_PATH=$SDKTARGETSYSROOT'"$libdir"':$SDKTARGETSYSROOT/${baselib}:'"$sdkpathnative${libdir_nativesdk}" >> $script echo 'export CONFIG_SITE=${SDKPATH}/site-config-'"${multimach_target_sys}" >> $script echo "export OECORE_NATIVE_SYSROOT=\"$sdkpathnative\"" >> $script echo 'export OECORE_TARGET_SYSROOT="$SDKTARGETSYSROOT"' >> $script From patchwork Sun Sep 27 07:43:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99290 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 315E0CA5FA1 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33586.1790495028864610454 for ; Sun, 27 Sep 2026 00:43:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=fvl0cRNy; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49b912d391aso14758575e9.2 for ; Sun, 27 Sep 2026 00:43:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495027; x=1791099827; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=TanhanvSwXs9grXrRE+yM2+44PPo+WRZjAeHgqAN9kY=; b=fvl0cRNyBcynF6YTiwEJbKF4dPoiAO9+VNVwzL6lf6uxqbq9hDUL1ukQrIK/HqFoQQ tY7O/yM5zp2wIfhYbmNP5fDeQ9KWqDpkprd1xyUtF4cScRqnxxGrzOHxQbZwaIPGbZuV zuj8p+3ATCvCJSrHZTqiGwQ7g5rpUo4yy3BQk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495027; x=1791099827; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=TanhanvSwXs9grXrRE+yM2+44PPo+WRZjAeHgqAN9kY=; b=bT7m71lCMuFq78uQpPQ2FrCyn5NO2fI4CMXsyYKv6SVJjQlSZUbqdC+bNSJzC6Km5X j4NeTjB9OHy2Ntg/8D52uNr2we5iIRRW7EKv775So7P1DqJyDmYw3c93voiyWRJk6hCW FXV8GJMhbj/PrJRg7Gx6ZNDvt1/MH5YR0yiCkJ3BRsDVxKn+fdfTDRMiILWQvIgRpi+0 poANkHNav5vxr57NtseoPqA0XJKFJDZD5homSVPSbyLKZgqp0u/Sxh4Xw7D6fY2FWEWl kpGP/ywq93krm49m21txrMPd1NJbi24EwGmr2wjTzX8qTnVLy6m0ueKyo+2SYJKfvbJ2 uvbg== X-Gm-Message-State: AFuF++kg5EYz9vjJIKPvL23HmTIJfFqksppqXpNDjqOXLSKCm9YRDN0K WgOd/6tDZS+dEkIUtEKmVl2uRnlluKrWLSyzNcb9z1Q+Mi9SvUeTudu3l05clfjjwf2/V/HqRLz ncoO/iRk= X-Gm-Gg: AYBFou1BXOQJe3Ggm7YGm5LxUwLp14YvBx1u6B/KA00wIDIeOu3uddtC2x9g4lAUkYl yfAoLb16H6gsBCZGzgJcqZboaP3gI3EuDdr9xyT2wF81nJyzEqh3nfXeinfgkuaaSKmcyzOaQ6U Vya4/+JlkgNsAUr9srnLox3BzIWXtoqwOTwHRC9eqKxH1ud+BXUS/5lWHP9TFUBQZbGy8VTEHXn k3DheuSdTCIH0Fz5z8ncaEkx0ZZNMdJJZxoH0s04A2mcA3vX/RBcj5WQMSRck1LXXpWTuEtlGsL sf4WCgR7ecolBiGvcCMcBvzCLr1+gfPg4h6Kp5WZWRvd8O+5sIXZsxyQd08Bgj5YfKbF2mDu62A LUoQl5KsXON7Fia4goiINq2wTw0RumtDtmmzcVQrplmBZA8VSDQTkRC57tbywoZHr0CxmVwQNaE uTEJoqVV2OXDQlK4h1GamT+ae7em3c2LHWbvqy4wQpmQZUOzHRi3KBNi4Vn4PxUhtYW4NQfshNQ pOjtedok1TGVyG+B+W1bN2OFlg67nKTLdenctwIzSIdBPslm5ARuaUvdH/b3e+3uonKXvbf5g== X-Received: by 2002:a05:600c:1d1c:b0:49c:eb16:9fd with SMTP id 5b1f17b1804b1-49fe66c9ae3mr178270355e9.3.1790495027106; Sun, 27 Sep 2026 00:43:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:46 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 12/28] at-spi2-core: RDEPENDS on gsettings-desktop-schemas Date: Sun, 27 Sep 2026 09:43:03 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246662 From: Tim Orling at-spi-bus-launcher aborts when no compiled GSettings schema is present. This has been a fatal error since [1]: "26f75dc0 bus: Abort if we cannot get the default GSettingsSchemaSource" [1] https://gitlab.gnome.org/GNOME/at-spi2-core/-/commit/26f75dc00eb16ccec89561aefe15f4036d45b4ec Signed-off-by: Tim Orling Signed-off-by: Richard Purdie (cherry picked from commit fb1b8a5338201a2163fcdb5d46550f46da716d8b) Signed-off-by: Yoann Congal --- meta/recipes-support/atk/at-spi2-core_2.60.0.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-support/atk/at-spi2-core_2.60.0.bb b/meta/recipes-support/atk/at-spi2-core_2.60.0.bb index 8e3314222c7..a32cce56cbc 100644 --- a/meta/recipes-support/atk/at-spi2-core_2.60.0.bb +++ b/meta/recipes-support/atk/at-spi2-core_2.60.0.bb @@ -23,6 +23,8 @@ DEPENDS = " \ PROVIDES += "atk at-spi2-atk" RPROVIDES:${PN} += "atk at-spi2-atk" +RDEPENDS:${PN}:append:class-target = " gsettings-desktop-schemas" + inherit gnomebase gi-docgen gettext systemd upstream-version-is-even gobject-introspection python3targetconfig EXTRA_OEMESON = " -Dsystemd_user_dir=${systemd_user_unitdir} \ From patchwork Sun Sep 27 07:43:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99289 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 11D9CCA5FA0 for ; Sun, 27 Sep 2026 07:43:55 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32858.1790495029563733000 for ; Sun, 27 Sep 2026 00:43:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=bFsG7ibO; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-488811c9ebaso882170f8f.2 for ; Sun, 27 Sep 2026 00:43:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495028; x=1791099828; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=u9xaCOnWB5duaChlG23cDu5emzobes7ZXgL0/9TvHVQ=; b=bFsG7ibOfK3PGAYOI6q1WyYU2paB1IlbhPBRIQcuP0hYvtExjRm+P/UnDSOo0nP16s YhX+vu2gHITCqut+C6tiqe71+jDHeiRxvqdPGrflUQ5Kcp7NVbG8cBYSlmeSRBluTcPH v4mSPZrNc27gB3p6SPed8c465zoiwUAmMisnQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495028; x=1791099828; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=u9xaCOnWB5duaChlG23cDu5emzobes7ZXgL0/9TvHVQ=; b=Yzvn9S3Nf1uD43UpmleogLsPaKoswpVbpWw0/JAKUYNm04+HokKJOFjuDNZCug6ZVN C4MEjhM9lb6gEGgrNo4DyKYOJ0gISjElUWtjzG/E7VvO0jnUsO2Jr/dO4VbjTUsEAzg+ UV2N/6uBVGtcVB2yql9gzaEw117C7eVJfodf5Jwgi5eglRChfzCoKfujx5VjKOghO2nZ Ebwh6VErzWSlGXyFu8kdq5UpgALwsVezS/4S6RkMmANh2YxuPPgNOiitBqPn7md6uIvM iAeVkmkIi5cGrs1BSB5SDTZsTUBwXFtcMg7ZYqMXx2skgLZb6jvMyWrMjNhBY9wD9X6Z zdAg== X-Gm-Message-State: AFuF++kdW0jJG6q+3mHl2V+yPTAASgjaTDkiOmA5bVMD61Wo1zUycQAT fLVxKvndLVOoDVd0YEHI6NcVYSL2Du/9SC2mdlz1/BHwGCHrsNRXsHIF2FkDwKxWhhW5r+pkyK8 +z2lc7Vo= X-Gm-Gg: AYBFou1FFLalG/ARhDhN2C7PZ11Tyg9Uc0XkYRRHWBoB8EdIMNNEMOxP9xZkGLG+Kh9 f9TrAEGeCR2asjUKXNB7HTCAAhOG+0g80Du4qDB0gesyPjHz8bJ9nWAnSmtUUdzlcVdBIkRFE9P ugyQCmMCBwe5q+mv6qaxEBXeJfzo3mrvIqmBBY8wAfgfnaWFn9ZxhwGTDi8041vzPw+rpC7cmhy RSPDpJlxs592E6As4ULtdYRpuogFt8EY+CG7vP8i/hEksZnqsYYjm3tzGFosmcBp8cv6HzVYk3y cVho12/6SbEuQPNa1mbaPX9qgtEvuUlKe3qXEncZXBM4rudwALQ3//6BOw4Y7qSQmzOJNdK00Hb EEtU4n35r7cbg78KyfwpTajHrCeLPCOVbKI5HUVuoyQv2CkH2yOovHVfFYrOY9ASb2bsb7dSz1f +S/hZivcsCtarH9j5FPhqChKHQ+BfQq7zxDIahvVCZMGvBnHhRcCmnmrdo3Zt1YF5kG6W4vHr4e zqYSie5Ab3jg9y/da0rvlVWcWZeFlEcjJbKBjAOpIaNQo/7Z0nvu/jKDvXAnUSDSW6YTphAVVM= X-Received: by 2002:a05:600c:6994:b0:49b:d03:8d3a with SMTP id 5b1f17b1804b1-49fe66cbb4dmr169822405e9.11.1790495027816; Sun, 27 Sep 2026 00:43:47 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:47 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 13/28] sbom-cve-check-update-nvd-native,sbom-cve-check-update-cvelist-native: upgrade 2026.08.03-000011 -> 2026.08.25-000009 Date: Sun, 27 Sep 2026 09:43:04 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:55 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246663 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Mathieu Dubois-Briand Signed-off-by: Richard Purdie (From OE-Core rev: 8d6b930f4d11627b90db3e902e382692c38cde15) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...03.bb => sbom-cve-check-update-cvelist-native_2026-08-25.bb} | 2 +- ...bb => sbom-cve-check-update-nvd-native_2026.08.25-000009.bb} | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-08-03.bb => sbom-cve-check-update-cvelist-native_2026-08-25.bb} (89%) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.08.03-000011.bb => sbom-cve-check-update-nvd-native_2026.08.25-000009.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb index aa21b06953e..dcbd98396d2 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-03.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5" SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "cvelist" -SRCREV = "b160e6f2915ac726b29ee0689fc920f5016abef5" +SRCREV = "ce11dbdcf79189e965d64b29161af93993619281" UPSTREAM_CHECK_GITTAGREGEX = "(?P.+)_baseline" require sbom-cve-check-update-db.inc diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb index 720b5ded0ac..473e33411c6 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.03-000011.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "b9f52bb052695dac5cabbd58e049eaac73697161" +SRCREV = "08cb7bde86fe9057c2338d7d61a705e642775bfd" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Sun Sep 27 07:43:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99288 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E7001C9833F for ; Sun, 27 Sep 2026 07:43:54 +0000 (UTC) Received: from mail-wr2-f34.google.com (mail-wr2-f34.google.com [74.125.225.98]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32859.1790495030772905753 for ; Sun, 27 Sep 2026 00:43:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=UofkWtfU; spf=pass (domain: smile.fr, ip: 74.125.225.98, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f34.google.com with SMTP id ffacd0b85a97d-48884b021dbso544474f8f.3 for ; Sun, 27 Sep 2026 00:43:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495029; x=1791099829; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=N90MvScTbg6bWUKUoSeKUqZiVzSM/6dkCB7r5dlscfY=; b=UofkWtfUy7HqNQ8eV/rZF5H57btxPXs4rZUOk3iwdy4yJl8KyBOiOPe4pyQZaeql9H 5zDZ4cWbe4d+c5rLt+zaRTnXWV7Ku1Z1uPOYQX6Vlt/lyufjDhxiskVu1OIdSEUda6Jd kIshjMZtWduIsx+NmXwwgLnHBTWO56MAZT4Ow= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495029; x=1791099829; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=N90MvScTbg6bWUKUoSeKUqZiVzSM/6dkCB7r5dlscfY=; b=1CNMAZyR16T81ucWv66paBWHeRNyL24iXUbMpfJYqdexnigPz7wb3c17MkDt8YQ7Dx QneJHF1VhezkgcviRTxUCA6CezpUQzX+JJBzd9krdEZ6uANNkoLMGMbXLm9IG5jxDDeq 6CsPam1K9VlC+0tBZ5NjjDKa70ykB34Ubl80wefrtYD3K5sjKBmMs5XTm/akgcW+titF lbn6s/26swBWQoRlyh4NAXzD+Ue2oSPHCg7j7kGib6zyb7ZyFHXLcAmTZM8iMK4jGMqh K4iYvMdxhB77MTzxaVo/uW23nIe/Ex7NTmSLuG082yVEEBDi6cQZbqXG+lGgtM/zkpWQ HX7Q== X-Gm-Message-State: AFq9FYKE9xOEkQoLmC0nXIHpBBdzk5TEDsW85c3/aMh+eOkwerxqPb15 zrFg49mM/QEudmvMBm6VjJirg8eNHA6IyHG/xPUsAJiFgwZXM+RSXt2lBow6ZLFdrcxzA9skAQd 3W+vnJ3A= X-Gm-Gg: AYBFou2vhUXZ192l+q8HAuC+1DS4+KekmVhNMvLNdpneOLE6euT6BQqz6x97PWvLM5d BKekHqFaKHSzyDq7cv+kFEquBvZ08pjae8LlxCYlu/Bfw9w4nVZQ1kqq8R2yhgxPCscUPOrhmka vdAxvjZA7e4M3pqTi7DSQYtsSLd7S9NfrOzmBD8CHik2HpFh/EGPFegZtQdyLp311WvcyAdTLXf mhzdNGISJIrvi4YB+CrCmJObNBWenV9E6kdQJTNb/lmD/yF7h6gKugmfy0XtoBBaQwFfOP56qei un9db4dU9TBNA7RHWYwq0anzPqYE7g8mUxYIa1ZywQAXd6GJWmvUSsHggP/r48NBhTee6YMYkxD 4jcXkQ0aFm6mjTZTKCrRHL5RF4yQqUD+HCBZXCFvhQ+3kDLgXlooButJJPpNEBCtxtQlT1vQUhD WLd9BvogA0AWopv3NhqlDgWp/sJvaZXaI1+QSOObSPL1mpep4APIXefkXQeul8JYwImlEnUhw0U 6TXT5NZL7xpkDXNOUCP8C6A00vAJdJsT7x+F7UyNX51p18Ig8CfcxvkJZTBwBCJuW/AYFOKqg== X-Received: by 2002:a05:6000:41cc:b0:488:83fc:a7d1 with SMTP id ffacd0b85a97d-48883fca9cemr8951630f8f.9.1790495028950; Sun, 27 Sep 2026 00:43:48 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:48 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 14/28] sbom-cve-check-update-db: Exclude recipes from rm_work Date: Sun, 27 Sep 2026 09:43:05 +0200 Message-ID: <480c6440f3947ef6deb6d1a00ae3aa46f1e74571.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246664 From: Benjamin Robin If the "rm_work" task runs on these recipes, the next execution of the do_sbom_cve_check task would force the CVE databases to be extracted again. Excluding the recipes from "rm_work" allows the build system to remember that the unpack and patch tasks were already executed, so it does not run them a second time. Extracting the CVE databases is slow, and it also removes the database "index", which sbom-cve-check has to regenerate — an even slower step. Keeping WORKDIR around is cheap: for the recipes downloading the CVE databases, it stays below 400 kB (not counting the "temp" directory, which rm_work leaves in place anyway). Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 3b81e8bc30552359125f2ca40f36ad11ce8ee969) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- .../recipes-devtools/sbom-cve-check/sbom-cve-check-update-db.inc | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-db.inc b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-db.inc index fbdc561e8c6..2efc080b932 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-db.inc +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-db.inc @@ -2,6 +2,7 @@ INHIBIT_DEFAULT_DEPS = "1" EXCLUDE_FROM_WORLD = "1" +RM_WORK_EXCLUDE += "${PN}" inherit native require conf/sbom-cve-check-config.inc From patchwork Sun Sep 27 07:43:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99297 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 11268CA5FA9 for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33587.1790495031464307360 for ; Sun, 27 Sep 2026 00:43:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=CGcyZrp1; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd4ba9f68so24097625e9.1 for ; Sun, 27 Sep 2026 00:43:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495030; x=1791099830; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=9F8ehRXL7I39966yFoBsmuX7q8wuFbhoriGJX7Bp5Qc=; b=CGcyZrp15YtiACthkkqW5a5bG1HBmf9F1+TcPVAEv+Hthc0PM1SgDkCQHwaGY5bCVV vOdK6JcUibtFIPqvLw0lwQmiej+NGdXNjDRP/0cix/fNkPvC+DJ1bCbSge8oAEHYm5eN GdrkOhZg1D58GSTwJ5SlTV+DY2Bm3M3k3kGqY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495030; x=1791099830; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=9F8ehRXL7I39966yFoBsmuX7q8wuFbhoriGJX7Bp5Qc=; b=1nxcMpvx10BT86tqyYenBL6zzkDJheuxpZqHqzc/dGezJK5BJjBWoAunM8HfEPPFjl IS9XaVPjU6Q/QADY3LufzTyVX+i5XN0YrNAz3XMfU0KXYK0kPkWoBu86ifLKgu1kOwb+ qpE2TQJurP66+HUmuuAxARL5sr8feS9W4/KNTpJqw4+HwB7F5g4qw0y1xMUIxqko0/75 WV6TO5M8I8fDIt31qqX1shbOim7KsKX24LrthjWfl5cKIuBMIQ7MfWZQN7YFPN+vOa5w CucVk/SOrqDFsGqHYwh5I4K4M/fFMxYQdFyYNbVTs34ABodUjNbtiooNd73e0SoBt+Ml jbpA== X-Gm-Message-State: AFuF++n3em3DSM6qTQ48kF1/ZXGn6DGg5oISR9fSY3aYkNRxSyXj5grW RtNAoPdXcwpBv0yPnbYzV1iBOJxYQT101V/Qlcze35Prc2wls1aEySEFFJBagyw/XH5GkMjhalj qEr8e3OU= X-Gm-Gg: AYBFou0LCBfAFxottBIrYH3HprqedB2neOP2JqutMW+l2Psdi/aLX7hL04wpnv41cVX y+axkaIPUDpyi0ACe4OdQ3nx9rLkonVVZ8uqqOh7QJAlbqTjF1E2IlEmwNVl6m3fAa2o81HGPjs g0t1n2E+VJnHKBqR+eRp+gDd4XPO4YOqXih7GXneKa6o1MkXEl96Yj3/5fz5+xj8YW0Z5rJOilQ MtUG5Y/oz6b/gv2bMDVV4DI0X5G7fOko3QYVxlsXRb1DwhGMqHOJf+D6mslC0/FFMTEEe1b5ntQ YDkTh38LvQm+Y4dtQkHe3Usyt08sqC8SHW5mshLcNJf2S/+f9Wf/RBd0J2ufcAKhJVKwjF3HhcH 2xaELnI+P5JxGDsY0fF+EoeKimnB4pc1+DDkgcmQ1GRmKiEO9zN3PBCyYM1bzETCcz1lqEtJZn6 hFoF36r2r8Y6p/MQtkFnra5bVEVpS4a9+SaSXzWjEtnYK1LAyhQZAJ1gntalonXZv2m8ok+X0lu ZssXPlCzrwYga0VvHOQJXxFmAtxz2UyvVDDsT9xZc6fuNkMWXY0re0uPknDG8bwOpKUX+iFv3c= X-Received: by 2002:a05:600c:8484:b0:49c:fe46:7219 with SMTP id 5b1f17b1804b1-49fe66d8135mr171727855e9.20.1790495029693; Sun, 27 Sep 2026 00:43:49 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 15/28] python3-sbom-cve-check: update to version 1.3.4 Date: Sun, 27 Sep 2026 09:43:06 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246665 From: Benjamin Robin For details on this new release, see: https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.4 Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 9fcb4b9b16594710b8be34b228042c426b48ee0e) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...-sbom-cve-check_1.3.3.bb => python3-sbom-cve-check_1.3.4.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.3.bb => python3-sbom-cve-check_1.3.4.bb} (82%) diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb similarity index 82% rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb index 2aca1005694..c26ce6e6b30 100644 --- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.3.bb +++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb @@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce" PYPI_PACKAGE = "sbom_cve_check" -SRC_URI[sha256sum] = "8b766be1ae92b4eceaa2f694dd4724e310886c6436f44267a6bbc6a7b81ab8b9" +SRC_URI[sha256sum] = "aa2f4e183b600fdad7ce6eb67f7d642bd3e7c67293ae9ffda7d3a2fde433e02b" inherit pypi python_hatchling From patchwork Sun Sep 27 07:43:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99285 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 52AF3C9830E for ; Sun, 27 Sep 2026 07:43:53 +0000 (UTC) Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33588.1790495032303209536 for ; Sun, 27 Sep 2026 00:43:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=1hCFh6GB; spf=pass (domain: smile.fr, ip: 74.125.225.140, mailfrom: yoann.congal@smile.fr) Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49ccf3ca626so11934835e9.0 for ; Sun, 27 Sep 2026 00:43:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495030; x=1791099830; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=y4QB3LORk7ZIWPAYPpHxUAEnHg4Oju+LbnIHl2HR7h8=; b=1hCFh6GBwi7clp5h8vm8sM607tj02naDmSs5Fay3fFHcMeYPrxlQNJCCL5MqQwlqeC JWKX9nmlQ0Ew0jcblhVon0WA/ylPaT0BSIOqW3/dRIF8sbEKEjlIXXp2Tb36eWv1lNWq I/VQ42LkRqa8Z+eMtvHwtfQYIaWTsNdp54NEQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495030; x=1791099830; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=y4QB3LORk7ZIWPAYPpHxUAEnHg4Oju+LbnIHl2HR7h8=; b=20XcNSmjXP4iOD9hdkW3ph5tTC1hFDbWjS/OnsUl5BKujQzGb4tBkMOUiwJBBI+o/n bJ96x3Kly8A/dtTdsMrjN6ZgHEb4hz5nG2P8tw6lRDjXhfoAlONjeW4QIOLHnkROUqMS Zsscow6uEIIKKxx0R0xYAcq/8jlG5/5SfjoWCI1VDcp5nybKEE5Kwsum/UBXzqKjBGY5 bcPGa989crcXMrdsqqU4vCa6ajUgRAlbofL0hM/A7x8AI02+kY+6unTjJNzGY9wMePMO tYQEvBpDKG1wdhaHrj+nsBsZlAIB3QM0yO0tr5OBH9KOwvk175h+jqO8IwioQ7gsCS5T tFFQ== X-Gm-Message-State: AFuF++l1So7DdAKXsBE7Qei3U4X74Yhz1JuXF39OoHiSzh5x9PMJvhWi inuzV8UfRCKLp88eteWnOImMZk8XHw4kDGicp6/yX9F79qh7vBzjISHzUvyEOX0cs68Te8Cz0jn j500dKNE= X-Gm-Gg: AYBFou07f1ZXv4AZdJN5tBJC1OcZXA54mYq6eWhEE6IKjw1mOHKdD86qNduLAmO1SsQ 6hxTgzbf9tYnfYistgwF8qlDgkj7ovJNTv1wu6/bhLNXWl+Tt91ACA4zIfHcmcSKK2eNGReIShy Nf4/hyMT28Wx1I4k694kbj0X2TRrRnkRfBxC8dr/K4ERfK8BETevJig/w6MTINXerTqlgWr7Pt0 ODTTepLCb0Z0X4g2EczXUjFc9TSFM+v87SO1dtgTDlBeYtJX8CwAH63dXks9s0Z2VSLD1HWvcmo tDSNNZV+Zvy77iDnF0x4qqewjeymdxCtjkm+HbsioYLsOOwY5gxpWS09ZDonvrKyFmiuFd1CP+P CAWwDigj4V8dxqt34sRTcY1wn6hkUmNViwd3+0AwbrBHp815gUtti1Vdy4MwdNQH4SIscaJtM/h MGqHDQKxukgRH4uBVGIlJFKL8b5gfC1zBl3oqSrEfqyxej8QHl4Mewlld9YpCa46lH6XD1U0+Xu UUrp+vNcH/4zO7GJRmBKVCAWmuqQ6xdZcC4185IS3/D4nXPzBor+wefQt0G7FQdqOwDSI8YPx/5 pqyikZwU X-Received: by 2002:a05:600c:530f:b0:49f:ffdc:939d with SMTP id 5b1f17b1804b1-49fffdc9a4amr25838785e9.9.1790495030514; Sun, 27 Sep 2026 00:43:50 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.49 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:49 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 16/28] sbom-cve-check-update-{nvd-native,cvelist-native}: upgrade 2026.08.25 -> 2026.09.12 Date: Sun, 27 Sep 2026 09:43:07 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246666 From: Richard Purdie Update to newer database versions. Signed-off-by: Richard Purdie (From OE-Core rev: 5bc50f5f1d7a8b4c37d32d78558f79a2337c3752) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...25.bb => sbom-cve-check-update-cvelist-native_2026-09-12.bb} | 2 +- ...bb => sbom-cve-check-update-nvd-native_2026.09.12-000023.bb} | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-cvelist-native_2026-08-25.bb => sbom-cve-check-update-cvelist-native_2026-09-12.bb} (89%) rename meta/recipes-devtools/sbom-cve-check/{sbom-cve-check-update-nvd-native_2026.08.25-000009.bb => sbom-cve-check-update-nvd-native_2026.09.12-000023.bb} (89%) diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-09-12.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-09-12.bb index dcbd98396d2..b609b43f22e 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-08-25.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-cvelist-native_2026-09-12.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/CVEProject/cvelistV5" SRC_URI = "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "cvelist" -SRCREV = "ce11dbdcf79189e965d64b29161af93993619281" +SRCREV = "9b9889cfd98306bf29b91df076c5118aae80b63f" UPSTREAM_CHECK_GITTAGREGEX = "(?P.+)_baseline" require sbom-cve-check-update-db.inc diff --git a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.09.12-000023.bb similarity index 89% rename from meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb rename to meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.09.12-000023.bb index 473e33411c6..7ba8647d6ae 100644 --- a/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.08.25-000009.bb +++ b/meta/recipes-devtools/sbom-cve-check/sbom-cve-check-update-nvd-native_2026.09.12-000023.bb @@ -6,7 +6,7 @@ HOMEPAGE = "https://github.com/fkie-cad/nvd-json-data-feeds" SRC_URI = "git://github.com/fkie-cad/nvd-json-data-feeds.git;branch=main;protocol=https;destsuffix=" SBOM_CVE_CHECK_DB_NAME = "nvd-fkie" -SRCREV = "08cb7bde86fe9057c2338d7d61a705e642775bfd" +SRCREV = "82336c26ab85706ae56efaa36ef5851ab92dd32c" UPSTREAM_CHECK_GITTAGREGEX = "v(?P.+)" require sbom-cve-check-update-db.inc From patchwork Sun Sep 27 07:43:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99302 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E801BCA5FAB for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33589.1790495032954765362 for ; Sun, 27 Sep 2026 00:43:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=L6lqOjqA; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843c3ee4cfso945459f8f.2 for ; Sun, 27 Sep 2026 00:43:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495031; x=1791099831; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=oK2nkp1tt6doPFQ8wvm/dlIVPe2xuc50dBC1MAIu4o4=; b=L6lqOjqABp8OebHqpOu3EHNS83PKWkPoevi95eDH3MS8a2Uz5b4iuWcuwLwoKn84Dm PuDnIIv89XNnpbUwMLo4ko/fOWwqa3U2kDnWIiBp2oumqCce0KZUYHOsEorvzxXqdQqs 8woSTnwvlTTZohWvktTrKuZrYbVnPtiNJeAeI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495031; x=1791099831; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=oK2nkp1tt6doPFQ8wvm/dlIVPe2xuc50dBC1MAIu4o4=; b=YoDibxW4F9DRlLM6VOvLRYBxlm9lpxahMYkmYitb1oX66vLFQswv8QMIPbz/ighGac cTIvP9kMHZE3tntgrXUX1fJ+LxIfiHVQWlIcU7ouc18bkHZPtGVLoidtn9nQtpZukFlb BWLJ3t9flosHon3a4vaBPDaMQGU/hFxY/d1Zk7/ZzO2q5VcvIEZFcqRX3ZF/IghsViwn yzYCN1JkCsPTVq1xwlebA0yhukEShHvB+yZgL9Vff8JjtT36nnXMveTXXgnovXBeWw6L 1lKf0dArYpQ2eWihRlPIx/h9H21ot4r1FMzEy8IOQQjW9TNcSb9BgOg2/jy5hG7ZxWLk 4X1A== X-Gm-Message-State: AFq9FYIOM/yjefzvFgYBjEgOmAcpWkAKHBtDjSPn9dOed9ph2yRm1uGZ o/9oLdlNNiadncZ5P5XCx4KcqkaOpMPZ+wOE3RLUtIUJA/u+nuVwlaf2hs4MWNC7wwBrhZKvGsx K05wZCVM= X-Gm-Gg: AYBFou0TFR9vI8hT1pMlETRgG9DHosHlPK7Ae16k5uv7ikRh/1Wy3HctsR8swkEq6Ne p0jHJMn2zksSm4oDW2BG5ISdGfQN2gklEj6G/4QzV9ieyu72vSVbnSefPXVJwVGNn31o1jenNGP AsSljMM6ZPdaupLCFyqAVtPfPh5S7Nwnf0eB8RLvlbnnc+cfCa56dHObkDCyu2COKeDUj1mYn0e AuzFXuumhDqxrk/6cqz50tYUIwxAXsE2bM5wUV9174edfIxqYzsMnfJaD6hggilFoFvylQgESx2 PF8bX9Te+suWvxDpUrlcl/glZsWrJXqQhS1+muUIvnQpo3nyFFurOR3L5aD4Rnf+JtCaJ34Gm7J xFo88d3Eu9f7e0QqdkzGii7fntIJZMWI+sur2W+Ky6rdbNTaMtsEsUj51+W8ifONSyz9alFQVHd FCxuKeovwMNyLbmfNZhGKItJdKphLJNDbFhoWaLESrtxCSGtP+o0/qTBSRN30TEhMRmGO4q+s+k Ei1s3hUDRSBr//r+2iYUyHLkuqzWWackPrYR21RojimN6vGHgo4NXgFrDV3T7xfC9yE7yL+HQ== X-Received: by 2002:a05:6000:288e:b0:488:80d4:754d with SMTP id ffacd0b85a97d-48880d47663mr12081943f8f.40.1790495031209; Sun, 27 Sep 2026 00:43:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:50 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 17/28] python3-sbom-cve-check: update to version 1.3.5 Date: Sun, 27 Sep 2026 09:43:08 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246667 From: Benjamin Robin For details on this new release, see: https://github.com/bootlin/sbom-cve-check/releases/tag/v1.3.5 Signed-off-by: Benjamin Robin (Schneider Electric) Signed-off-by: Richard Purdie (From OE-Core rev: 65804d3f2eec44a3bdba68d8865619818886a4d1) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- ...-sbom-cve-check_1.3.4.bb => python3-sbom-cve-check_1.3.5.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-devtools/sbom-cve-check/{python3-sbom-cve-check_1.3.4.bb => python3-sbom-cve-check_1.3.5.bb} (82%) diff --git a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.5.bb similarity index 82% rename from meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb rename to meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.5.bb index c26ce6e6b30..83d420835da 100644 --- a/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.4.bb +++ b/meta/recipes-devtools/sbom-cve-check/python3-sbom-cve-check_1.3.5.bb @@ -5,7 +5,7 @@ LICENSE = "GPL-2.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=570a9b3749dd0463a1778803b12a6dce" PYPI_PACKAGE = "sbom_cve_check" -SRC_URI[sha256sum] = "aa2f4e183b600fdad7ce6eb67f7d642bd3e7c67293ae9ffda7d3a2fde433e02b" +SRC_URI[sha256sum] = "9ed8b0e9c46015444cd3e30332d9558e0be5f5fec97f6df47c6760166a314167" inherit pypi python_hatchling From patchwork Sun Sep 27 07:43:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99307 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8005CCA5FAD for ; Sun, 27 Sep 2026 07:43:57 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33590.1790495033633574325 for ; Sun, 27 Sep 2026 00:43:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=uSrfAL3k; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f63546c5so1808015f8f.2 for ; Sun, 27 Sep 2026 00:43:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495032; x=1791099832; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7iuWXfDwrSQbiHQEyi+M6FimvwK6XSQdDwDkIkPboLg=; b=uSrfAL3kUpnWZUQU+QsxbW101CgZSHMGcsSMoshoMHbUvV9R8h6xHGb71Sy7F14/aW Oo1HW79/LyT6einVLKKYtXreR6pCNDorLeIJo26q1dnjGCB/CO4ks6gyZemd9Q50Ojfg MEPUrMTm+AivHnEg6adWFeiYL9NZUmQA4JMGI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495032; x=1791099832; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7iuWXfDwrSQbiHQEyi+M6FimvwK6XSQdDwDkIkPboLg=; b=gyLXQtB4w+u8RrXKHJA/0ycJIdDuWRlKu9ttecrIluRVHveRXA+Vbnrv3cJ8UrfXbM mjOjdMZnVgQ1Kzw0qJ2DOp/PCANi2Ms9jm9HyOV1kl+8+l12siLHcmk0rBUDvZghPW8J Tza31V66o5ELEIDfFPCg/pVr/YDPjkQAKLQ0Ys7jYCIfeuQULVPLg/d5nmc0orDBLKr2 y+u9Vg30LoSCJ9KblnyoKG0HEth2sWFCNPznjrIygOBlNtGFCOHuqWesJn/mYjK8L/nZ aqdax7C2rZtKGgongzHB1nvDh8QBLXLSMzXKvsc9ckpMc3UnQn7/VWWOSTQJtZBiV6jF NBtA== X-Gm-Message-State: AFq9FYIxmvqLlQL/JfeDRMqr/F34ZM/nHxwjRl3X/dVnFlOsBWmwlO0w xns2aXpRXCrWswqmmA5c+oTI5/eomR/A64Q58/y+/ecBED2cBbfNlrPSzz9LYS8U8AvgPyfz1WE P+s+y34c= X-Gm-Gg: AYBFou2f2RFLTRXYyptnDUbbY4es7U9fRtMK3oXlpYwfvIyW3H5FRIOK5j7D4oy9lLv hk7DuJ3ZH1nvRIYaEFvrOohrJ9zQtGWbVHa2g9hpEYIGU2E8/6p1nZR+EdX9g+wxva0qH8x4V0i 59rWfLbEg5Qs2VTkFVk/qg/8IVIebwIoosAJUSsLYGBpq6XNOOHT033mZQDuIXGO9qOEtw28trz G83808qy2MVqETE+EP0VtEvoPlw2Vw0ztxtGPTmOQYMnSAnNXw+vPVLpufWf3QzgFvlSQB6t5El GPvAFUr4RsFdHbGz/7Vet6L9NejY/Yv4S0cDw2wVzsXckWuC8L6Pi+6c3e3g9uqzB4lYWOnyFFH CSCEMDz27m62JcCIg0zspbKBeY8Te+m3ihMYt7GmdKcMi+AskWC1jcDbvB2U0BumlLmDymbHs55 sVJYqHhknX/tmkQpKvOL2R2ZfO/ssQ8b9m05JAOwWQPRjfmA/7yptmYO7DdY0G4Osy5x1Iz98hc cefRIlVFZUiL/WzJQ18hztfmPQNVTTkdiuc6NeVxy8X1zo3yrVqe6Wllu85NxuO6HVlXlJEWQ== X-Received: by 2002:a05:6000:719:b0:486:ecc3:2d1a with SMTP id ffacd0b85a97d-4887175f50cmr17110841f8f.31.1790495031850; Sun, 27 Sep 2026 00:43:51 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:51 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 18/28] qemu: fix CVE-2026-48914 Date: Sun, 27 Sep 2026 09:43:09 +0200 Message-ID: <3aa95311cab190eef60940aec3eaf666ee38467a.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246668 From: Roopa Kalmath flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process. Reference: [https://nvd.nist.gov/vuln/detail/CVE-2026-48914] [https://security-tracker.debian.org/tracker/CVE-2026-48914] Backport the patch to fix CVE-2026-48914: [https://gitlab.com/qemu-project/qemu/-/commit/f5e2c6906cad9a84140e232f2e3eb7a46bf07f62] Signed-off-by: Roopa Kalmath Signed-off-by: Yoann Congal --- meta/recipes-devtools/qemu/qemu.inc | 1 + .../qemu/qemu/CVE-2026-48914.patch | 60 +++++++++++++++++++ 2 files changed, 61 insertions(+) create mode 100644 meta/recipes-devtools/qemu/qemu/CVE-2026-48914.patch diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index cc8f2ecdfad..6a217cdaeba 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc @@ -42,6 +42,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \ file://CVE-2025-14876_p1.patch \ file://CVE-2025-14876_p2.patch \ file://0012-linux-user-Check-if-RESOLVE_CACHED-flag-is-defined-b.patch \ + file://CVE-2026-48914.patch \ " # file index at download.qemu.org isn't reliable: https://gitlab.com/qemu-project/qemu-web/-/issues/9 UPSTREAM_CHECK_URI = "https://www.qemu.org" diff --git a/meta/recipes-devtools/qemu/qemu/CVE-2026-48914.patch b/meta/recipes-devtools/qemu/qemu/CVE-2026-48914.patch new file mode 100644 index 00000000000..e38292d4718 --- /dev/null +++ b/meta/recipes-devtools/qemu/qemu/CVE-2026-48914.patch @@ -0,0 +1,60 @@ +From f5e2c6906cad9a84140e232f2e3eb7a46bf07f62 Mon Sep 17 00:00:00 2001 +From: Stefan Hajnoczi +Date: Tue, 26 May 2026 11:49:57 -0400 +Subject: [PATCH] virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check + (CVE-2026-48914) + +Check that the iovec containing struct virtio_scsi_inhdr is large enough +before storing an error value there. + +Feifan Qian pointed out that this can be used to +corrupt heap memory when the descriptor uses an MMIO address and a +length of 1, forcing QEMU to allocate a 1-byte heap bounce buffer. +virtio_stl_p() stores 4 bytes and therefore corrupts whatever is beyond +the bounce buffer. + +Fixes: CVE-2026-48914 +Fixes: f34e73cd69bd ("virtio-blk: report non-zero status when failing SG_IO requests") + +CVE: CVE-2026-48914 + +Upstream-Status: Backport [https://gitlab.com/qemu-project/qemu/-/commit/f5e2c6906cad9a84140e232f2e3eb7a46bf07f62] + +Reported-by: Feifan Qian +Cc: Paolo Bonzini +Signed-off-by: Stefan Hajnoczi +Message-ID: <20260526154957.1741622-1-stefanha@redhat.com> +Reviewed-by: Kevin Wolf +Signed-off-by: Kevin Wolf +(cherry picked from commit aeea0c2804c42f24915467a1e4c70e649e39b8e0) +Signed-off-by: Michael Tokarev +Signed-off-by: Roopa Kalmath +--- + hw/block/virtio-blk.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c +index 9cb9f1fb2b..6b92066aff 100644 +--- a/hw/block/virtio-blk.c ++++ b/hw/block/virtio-blk.c +@@ -199,10 +199,16 @@ static void virtio_blk_handle_scsi(VirtIOBlockReq *req) + + /* + * The scsi inhdr is placed in the second-to-last input segment, just +- * before the regular inhdr. ++ * before the regular inhdr. VIRTIO implementations normally do not rely on ++ * the precise message framing, but legacy implementations did and so we do ++ * too for the legacy virtio-blk SCSI request type. + * + * Just put anything nonzero so that the ioctl fails in the guest. + */ ++ if (elem->in_sg[elem->in_num - 2].iov_len != sizeof(*scsi)) { ++ status = VIRTIO_BLK_S_IOERR; ++ goto fail; ++ } + scsi = (void *)elem->in_sg[elem->in_num - 2].iov_base; + virtio_stl_p(vdev, &scsi->errors, 255); + status = VIRTIO_BLK_S_UNSUPP; +-- +GitLab + From patchwork Sun Sep 27 07:43:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99304 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0E5EFCA5FAE for ; Sun, 27 Sep 2026 07:43:57 +0000 (UTC) Received: from mail-wr2-f42.google.com (mail-wr2-f42.google.com [74.125.225.106]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32860.1790495034127456022 for ; Sun, 27 Sep 2026 00:43:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=Hmn9aEx4; spf=pass (domain: smile.fr, ip: 74.125.225.106, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f42.google.com with SMTP id ffacd0b85a97d-4888598e4f9so977403f8f.0 for ; Sun, 27 Sep 2026 00:43:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495032; x=1791099832; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=D6O/N06EjLtCPF8Ketii4RCS6BFjKTnB6CTS2RQgIe8=; b=Hmn9aEx43emmmqBPDXKJnAyGNF7xRrD/b1O/eCTXk/LOufSIyZzS2/ys+YKHY5L74W rWx+RsniArqYRb7z1HRZtCf0g6WYRL+GMPyysyqe+5gubuZctNMfEmBz+DemCb31QXRW RZUIQ/7vahUybsg1co3QiCHLa3ChQ+cbswWdg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495032; x=1791099832; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=D6O/N06EjLtCPF8Ketii4RCS6BFjKTnB6CTS2RQgIe8=; b=CCyA2Q7tnfocUmYcOMWvoLo0QGLOgfNRxTKMick8RmDAcRUlWS9hhexf3ggNxj/jb7 z2lmjYzbQl2j7i0uR+1UVNY4TvjMx4R9SUCUZ4u1LJoGZwXXI6mM3rqrPCiI1V/dg5Yc zJkOdwBeFX76orV08v9A0LYBK9ENoaFCdSJsqk2N30Us5W2y4tdVsltS7fnnrEirvAcf 7jJkPw7UfNPvPXde6oBN59i9b/JUpp2rXmciw5vd1LXpbVbeIcePynG4Q+WzTQ9FNYrs +lIfEBhYZhml1y+jr1HpitJm65SzhuK06/xemuvC9v1gzbK5yLzWQJjLW9mXcm1MWtN1 QMAw== X-Gm-Message-State: AFq9FYJtlOXYiEqZI0l5YGI4rMrBSmsd7XakKv29Bs2QJtNOeJ4OMyQO 81e5xP9cDBIr0aqGR6WfY9YH9x8mjxtMk7Uj686M0sEZdc2I6PY1OdImecXY5aIODBlvqeLZges OljyM4Wk= X-Gm-Gg: AYBFou1pevXC4+dJCkHaEcKspnvc79EkNR/v+YiXoaU0C7nEDrtuNcFakREU0phmvCs 9FcNf1aOxbQcgaFbGkU9tb50Z9kuIv6HN5GbOHRCZ09MWMKNt/Q0sCNOepQ/XIg2/AfddI7GkQS NKQcMkBY5rOSbDN9NhnEOMR5BJQFbLJkAKIZGrqzJHj0rdqJ28QR/gInXnCrihkm6oRcIcm6Ido nhb0FBXzfohOEmdnSObLBIyVPhPQJLGMFSr2bZMu0dJWAEA1la9dMlXeH1hk9yOC4K+SagjBG/h R7wWq2w46dUcoFbUL/un/449hUrTw25vzZcT/g0ThsleNTbe+nttIwt0bJGgQrIgUXLVED4s7DD bZLT3kfqxEDVWCoiuFUdFJ9cDA7jzTo66k453ay0cLW4zHCtukmU2NYLGbHOhSN/WcY5+UES5Au Gkn+qMxtZkEDbSKKLOlCppeUtbUmqM5N62YBgZFyFgEUxLDtJjTAGZ6Cm/Dj+FZwCjx99WpEgAv PfUJD5/6iuUdWFw8BDzRQQ5AViX1+4QdcM5cZfP7o/FMDNIoMBr6y+ppEyjcMkcTGCU02F7Ow== X-Received: by 2002:a05:6000:40d7:b0:488:78ea:184e with SMTP id ffacd0b85a97d-48878ea18e0mr9780211f8f.11.1790495032395; Sun, 27 Sep 2026 00:43:52 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 19/28] bitbake.conf: pseudo add rootfs-dbg to PSEUDO_INCLUDE_PATHS Date: Sun, 27 Sep 2026 09:43:10 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246669 From: Adrian Freihofer This is a fix for commit 2502da8170 ("bitbake.conf/pseudo: Switch from exclusion list to inclusion list"), which forgot ${WORKDIR}/rootfs-dbg. oe/rootfs.py's _setup_dbg_rootfs() builds the debug tree under ${WORKDIR}/rootfs (already included) and only renames it to ${WORKDIR}/rootfs-dbg as the very last step, so the rename itself doesn't lose anything: pseudo's database is keyed by (device, inode), not by path. But PSEUDO_INCLUDE_PATHS also gates whether pseudo intercepts any *later* access made through the new path prefix, and rootfs-dbg wasn't covered. That silently broke image-combined-dbg.bbclass's combine_dbg_image(), which runs under fakeroot in do_image: tar -C ${IMAGE_ROOTFS} -cf - . | tar -C ${IMAGE_ROOTFS}-dbg -xf - The extracting tar's chown() calls into ${IMAGE_ROOTFS}-dbg fell through to real, unprivileged syscalls instead of being faked by pseudo, so files copied into rootfs-dbg silently ended up owned by the build user instead of their correct target ownership. Signed-off-by: Adrian Freihofer Signed-off-by: Richard Purdie (From OE-Core rev: 2dd3a54134c04147a863ada4997edab3e8afc6fa) Signed-off-by: Peter Marko Signed-off-by: Yoann Congal --- meta/conf/bitbake.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta/conf/bitbake.conf b/meta/conf/bitbake.conf index 24e095632e9..c5f84124f0e 100644 --- a/meta/conf/bitbake.conf +++ b/meta/conf/bitbake.conf @@ -748,7 +748,7 @@ SRC_URI = "" PSEUDO_LOCALSTATEDIR ?= "${WORKDIR}/pseudo/" PSEUDO_PASSWD ?= "${STAGING_DIR_TARGET}:${PSEUDO_SYSROOT}" PSEUDO_SYSROOT = "${COMPONENTS_DIR}/${BUILD_ARCH}/pseudo-native" -PSEUDO_INCLUDE_PATHS = "/proc,${WORKDIR}/image,${WORKDIR}/package,${WORKDIR}/rootfs,${WORKDIR}/sstate-build-package/,${WORKDIR}/sstate-install-package/,${WORKDIR}/pkgdata,${WORKDIR}/minidebuginfo,${WORKDIR}/devtool-deploy-target-stripped" +PSEUDO_INCLUDE_PATHS = "/proc,${WORKDIR}/image,${WORKDIR}/package,${WORKDIR}/rootfs,${WORKDIR}/rootfs-dbg,${WORKDIR}/sstate-build-package/,${WORKDIR}/sstate-install-package/,${WORKDIR}/pkgdata,${WORKDIR}/minidebuginfo,${WORKDIR}/devtool-deploy-target-stripped" export PSEUDO_DISABLED = "1" #export PSEUDO_PREFIX = "${STAGING_DIR_NATIVE}${prefix_native}" From patchwork Sun Sep 27 07:43:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99305 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 37748CA5FAF for ; Sun, 27 Sep 2026 07:43:57 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33591.1790495034982485190 for ; Sun, 27 Sep 2026 00:43:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=L2EI9RcB; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-482f6351831so1149009f8f.1 for ; Sun, 27 Sep 2026 00:43:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495033; x=1791099833; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=fcSQO4uFI+YRMVWF2TN8o7An+B7Ck6jYyYU4BHraQvE=; b=L2EI9RcByW74GWw9qe3FDbKw0gTvjooZjzlk3bggs8C3FEUGC4x7/BxVsXYqAc28My 661Hcgo8K6IPWIRGcKgcQWI+TV65k5TYroWHrNAr3UEOOBsTnlE+iR8bex/Yf7AjVKWv ElfGZIE+EPvQ5sYUzFojs173L1F3kmgpPPXcU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495033; x=1791099833; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fcSQO4uFI+YRMVWF2TN8o7An+B7Ck6jYyYU4BHraQvE=; b=ZGmnxtdkZPKmH8JYrvq4tQTPjKslZLToMFVV0T9fjVUn/IIShBqTuyd2yRKutZrdRe +UiRPvi+bt0JE0Hc4owFjxELbOdRCVvPY7zflqfJscziZKWWao2D9SQGNpT2HbshsZ1I TrwfRlErJotgB1aOHgWxiCjgzsi3qa8ZbjdWKKr4uGPgEMl2Qnw8rrNTastCTMkjMJod EluaogfND78vGOkmMVEEpCpuTa5ShxgCxTAb1y3s7q3Qd0z8m41OspGBeXd77uuMak8w FyVKMtY++CDKSP3lGty+xwnJ/7TWkOoeFy0uuP0F3ys1ddPPWd/DVIVykeYNSD82oZdH WWaQ== X-Gm-Message-State: AFq9FYK8U/79tPOd4pb5TeeaKevDCJneWW06pC8Rh2E3z9vCL8S9ByqV tyDn8mmHNT6QfGgjkgDG0c0MSU/8kMXOXgC28ifCZPm4iwnC490DCquw/8e9LBEHtarmpY+qJF5 he2eCfiA= X-Gm-Gg: AYBFou3C5MkbMIjtDqKWsgROxH2wB49eiPU9Eis/tZYdOl+XWLCXLiYCWy+m6TjwJaZ YU0mXMyF6Q2+63snNE0RIyZFd1SMx0MS53dC3PA5jz0CNQ4ulDb5guF+1bkRQSf6/Mwf4JcKhR8 Sl3M+VrMWvmCl7kGiBfdGI+DgB90Is+IJOHEVmUmZVUGgGys0lP8yVvHVmf+02eRkDViGazzBTe 3MnFmc6+AaTQLsnk1lsZzuBB2h8y4M6clnc1e/9f2R0LkuGyas7K6+5UBfgiNzHX6Ji5C9G3vfa y8oU+4ldHYyWQ9hOZV95wrJsoJaflFx5PuuvsO0Co5XvURxbTYE3dGw7QzO8Cd2gOhYxVqXBI6/ ORGM5lkgLzgivfFZsL+A0STUt/2nwran54mBjzJ3oxWx4TRO5ChWl2iE42ieDrSucQ/GOip+oO+ zB6iMJSaKyK+jdY9AFY118GwkOGl9teeZdHu3hbosyGdupjpadQkUOihFZmJ4bYTJIBbaXWjhVg A9OH3Nt0URyBDvKfpFCNEzqxGhwA8ckeeHnImZSLQyTY5tr8IIG3MoQiOlrYecKRt0pQRTNrA== X-Received: by 2002:a05:6000:1863:b0:487:342:d142 with SMTP id ffacd0b85a97d-4887175ae72mr20315904f8f.44.1790495033191; Sun, 27 Sep 2026 00:43:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:52 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 20/28] ffmpeg: Fix for CVE-2026-66037 Date: Sun, 27 Sep 2026 09:43:11 +0200 Message-ID: <66194543cd579ef06d1fc5c34ac7716f9f82d8a0.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246670 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5 [2] https://nvd.nist.gov/vuln/detail/cve-2026-66037 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-66037.patch | 39 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66037.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66037.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66037.patch new file mode 100644 index 00000000000..1b93c0ca86b --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66037.patch @@ -0,0 +1,39 @@ +From f02c8cd37dee2b333de229c6ac6834322f56e2c9 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 28 Jun 2026 22:05:28 +0200 +Subject: [PATCH] avformat/iamf_parse: check count_label against the available + bytes + +Fixes: unbounded allocation / denial of service +Fixes: tP59h4cpaFyg +Fixes: 4ee05182b7 (avformat: Immersive Audio Model and Formats demuxer) +Found-by: Adrian Junge (vurlo) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-66037 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavformat/iamf_parse.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/libavformat/iamf_parse.c b/libavformat/iamf_parse.c +index 29b8acd351..a36759e282 100644 +--- a/libavformat/iamf_parse.c ++++ b/libavformat/iamf_parse.c +@@ -969,6 +969,11 @@ static int mix_presentation_obu(void *s, IAMFContext *c, AVIOContext *pb, int le + mix_presentation->cmix = mix; + + mix_presentation->count_label = ffio_read_leb(pbc); ++ if (mix_presentation->count_label > len - avio_tell(pbc)) { ++ mix_presentation->count_label = 0; ++ ret = AVERROR_INVALIDDATA; ++ goto fail; ++ } + mix_presentation->language_label = av_calloc(mix_presentation->count_label, + sizeof(*mix_presentation->language_label)); + if (!mix_presentation->language_label) { +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index b3b78a7936b..4e278a5ac97 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -37,6 +37,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-65705_p1.patch \ file://CVE-2026-65705_p2.patch \ file://CVE-2026-65706.patch \ + file://CVE-2026-66037.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Sun Sep 27 07:43:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99303 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EB886CA5FAC for ; Sun, 27 Sep 2026 07:43:56 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33592.1790495035710772337 for ; Sun, 27 Sep 2026 00:43:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=CH5RZpZg; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-4843f22dc83so1718375f8f.1 for ; Sun, 27 Sep 2026 00:43:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495034; x=1791099834; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=N03H/+ZvyWin99rx4HzNS+KuoiMwCOOJImbrdxzk1Dk=; b=CH5RZpZg9Mu2Efr7m5/xkEZwPU70oZ9kyP8DwZ3QODZqlVqA4tgUSZHkGal48NN93U gPRFzgIlROYGwE5/vdQ+N3n3+vmXQETqXd8GDBfNuLTi9BNEI6YVNh2OLOmYyxFx0L8d F3JZLfavQ7DUdz8AMaXIf+fANIt8dmjqBIU50= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495034; x=1791099834; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=N03H/+ZvyWin99rx4HzNS+KuoiMwCOOJImbrdxzk1Dk=; b=uXt46pZzpAXpolrS98pRVQvBhKC8SX5wyttoX0pZqvJNsXDTn6OSslHEDJ/EVAf61r K5efQvZ5vlENFZ/A8I2ODKr2Fi2oizrBdG2KYtLw2sbEEliCrqReGU7UcZo0ME0vn6Lz dkKPPdWVyNhwQmCjyeztGrIYvUpoYfrGttBtNnepaqZdcwnH23dA4MYmlbyZ1FerpYCN ldDc5icBJP4JHcQg+IWTkmdyxv01oLPm70XR2lhVzvPQYaen6u5LtVr2BwyWdbotxB37 aXiPrFwF5l/P49VrH2JOwNvstlIK0uGq0mqSqOnQMkwzvctFf3sOjIBNllZtKXrw9t2R xzAA== X-Gm-Message-State: AFq9FYKtYBp3XWOr2Nnfn5vWHf7FDGJfK2ygo5nMzeQSMPt/CZ9GYyEG rrFUb0Y2agqFDgD9B0elBkCAd+0iVQ0FCkhSq/fTJr51NwcvoWt39B+HUNZk7U78XzdoBLnz08O DQ6QirRQ= X-Gm-Gg: AYBFou2Ga3DA08xEx8i9nOTBz1gSg41NDBSlqp4bxMuMx349Sv3IDgV0wRpT758dO1A 3f61BLFo432KRWx3iQDlHxO9ihsETBukd41TdyhE6eMoYj72ztLrHmh2rLQLBDdVFb222mrdkaH rLc8xmt/JLjNKul7YXQZp4Q4Q0Uukojza5QUy/4IPLo3YXd60DVD7SmQpltAGjCXUb7a8endktc +eRrwCApV7Iy/CvSvtIkEYHsmyTbEoc7GRgdsFRUYxdxU/40MyjRLPdo7ApOAxEBc6TlSBlLfGw gdlKNvWdVRg82erAL8Aaw2WYgxzsGRHsXl7Cv22WdFgUsSfZgsPbtRGcqyb6nSqvKM82SYtFgE0 aHR3D3I4nIJelnYNElZFQh0CSGevYHVFsMZ4SJuiaN22qkLGWLqA4lent8XcRClsWZi7VLonzfQ 1StFov7VTu/tZE8xYXB956IcdVT3X/BWYbctSVxPc0RXE3A9Ga05b/iyA0hRMKO2VXfnrD7QlaB kNmIIAn5OV8DtxwrmtgZkunMPsQhf3o7T+KGSl0KLEZX2hhu43j9feFtfc3ivPWEv2KdPii9w== X-Received: by 2002:a05:6000:2404:b0:487:219e:5e20 with SMTP id ffacd0b85a97d-48872ad7816mr17943269f8f.51.1790495033957; Sun, 27 Sep 2026 00:43:53 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:53 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 21/28] ffmpeg: Fix for CVE-2026-66038 Date: Sun, 27 Sep 2026 09:43:12 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246671 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c [2] https://nvd.nist.gov/vuln/detail/cve-2026-66038 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-66038.patch | 50 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 51 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66038.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66038.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66038.patch new file mode 100644 index 00000000000..4c2be955907 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66038.patch @@ -0,0 +1,50 @@ +From 5fc1e9d8af5019a83a5683e30d92c41c7a606c2d Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Sun, 28 Jun 2026 19:04:07 +0200 +Subject: [PATCH] avcodec/lcldec: zero the not-decoded tail to avoid heap + disclosure + +Fixes: use of uninitialized memory +Fixes: CsNDKB1K1U0C +Fixes: e2c3aa8e2b (avcodec/lcldec: More space for rgb24) +Found-by: Adrian Junge (vurlo) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-66038 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/lcldec.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/libavcodec/lcldec.c b/libavcodec/lcldec.c +index e9d4283eef..71c6d070e2 100644 +--- a/libavcodec/lcldec.c ++++ b/libavcodec/lcldec.c +@@ -119,6 +119,9 @@ static unsigned int mszh_decomp(const unsigned char * srcptr, int srclen, unsign + } + } + ++ if (destptr < destptr_end) ++ memset(destptr, 0, destptr_end - destptr); ++ + return destptr - destptr_bak; + } + +@@ -152,8 +155,11 @@ static int zlib_decomp(AVCodecContext *avctx, const uint8_t *src, int src_len, i + if (expected != (unsigned int)zstream->total_out) { + av_log(avctx, AV_LOG_ERROR, "Decoded size differs (%d != %lu)\n", + expected, zstream->total_out); +- if (expected > (unsigned int)zstream->total_out) ++ if (expected > (unsigned int)zstream->total_out) { ++ memset(c->decomp_buf + offset + zstream->total_out, 0, ++ c->decomp_size - offset - zstream->total_out); + return (unsigned int)zstream->total_out; ++ } + return AVERROR_UNKNOWN; + } + return zstream->total_out; +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 4e278a5ac97..57805f17095 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -38,6 +38,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-65705_p2.patch \ file://CVE-2026-65706.patch \ file://CVE-2026-66037.patch \ + file://CVE-2026-66038.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Sun Sep 27 07:43:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99306 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A56A5CA5FB1 for ; Sun, 27 Sep 2026 07:43:57 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32861.1790495036418867910 for ; Sun, 27 Sep 2026 00:43:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=qMHBFznn; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-48882c1f2baso246991f8f.1 for ; Sun, 27 Sep 2026 00:43:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495035; x=1791099835; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=irBSgGgri+SNGsEWYroJCrgTc014m8hzqrx0a/YQjMA=; b=qMHBFznnR/G/7Ahr9yjGDTaK6ODIlvnRNlFvAB+fKX68JqzKGSetpM84RFIE7eIQLM eHgFoHQJ2zvWoECwE5JKScW7ySEp0w2zaEk1X4Rkm1cIhkg+CjFEgoFiHfAL/syoTSM8 Qnx69XRFV6wfbfyzJDtg1kR6E5gpH2SE/Qvho= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495035; x=1791099835; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=irBSgGgri+SNGsEWYroJCrgTc014m8hzqrx0a/YQjMA=; b=03qOrDJJ9UUbHdYlgZGcExol25hKBBQCev76wB/rfvG4kZo/aa2ZNzWykrReFPQIjj RmCDbPAjcx6ihxwnnPevTgZWoRkKX+vzTbnCHy6EqTb2IC/PqTdJRVkuVk1aU8tPaXy0 A2Z+GQHZ81iSyU6OS1SU1pWmXu1CMsR9woUTuqlLymNpcGJUG5wuzlrBUozgXx0SnMnA gw8P1AL73ce8ZjgfkLWPDagXfllVgJzazybjC9+Zn5Y+bWs4A7htR/kqcFkmJbqG6C9z O96Mpl8ZnAcs/p8CSKaVhP2i7WMuWfm7kjICh/xBStKuX3bho022R8KrMkSrK9ykH1wD QZww== X-Gm-Message-State: AFq9FYLL69TL5aRU23M254JV6zmEUMS3KgOaveu0a2TAHeYc88A/h4/p +am/h5BnfcCFWr/BfVkP4kMHzZcR563jxonvLCqqLMCxIQ7pFlW4SYjsojvpDLq/e4HpCkD0LFj 1+LxkIPE= X-Gm-Gg: AYBFou1ynrpLpOU9u+SimlgRXGYu130dHOEiXkgdVppD5qZNusco8UKSCMc5m9onkAv ouJvL38zmPeIgTRBnpXlJrOUYEOaq9d3fUoddyxUaeodOOMJgYTPf2FjX4laTBAnDvDh8koL6ZK ZWGuU/S0Nam3MfI4Ilr1MLrruCXPxoONAJmsbaNbWg8fiXj2lalcukLYnT2Gxkfs/GW4SrCkxsL Sol8B3e8e7fQoBh9EODy506eH2RO2oaYt4srA9bfXo0whUldwch330wSbulxMP2PeBcYjhLyNiw sijgWAM0yEaulCf1QZzrLmToRw6jVc4/N+UWhyHi7R2VcCtkn+R+lhd9BgAAAUlCJVnlA1EOIBD JF8Cw2nOQLrA+bdis4aDm2ejq+UdxLexpAYNJ4RLqrq6/JtFlKWeQOWSdUjuB+yX8LhExLWyHFQ awEv7la1cHi+gs23bSuDZAfRwl3KhVWezrbaXygcYlbXT+mHtN9gh+c2QvHL6qmWI4dDWWBh3J6 6daam7H1odZivoen9li0oQ0+87d6pwJzd6wuO8Af1yPoVgb7elbaRQ2sPtPOeLMX7lQw8+yWf3W gyYoVYGq X-Received: by 2002:a05:6000:290e:b0:487:27f9:837 with SMTP id ffacd0b85a97d-4887170f426mr18936334f8f.44.1790495034605; Sun, 27 Sep 2026 00:43:54 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 22/28] ffmpeg: Fix for CVE-2026-66039 Date: Sun, 27 Sep 2026 09:43:13 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:43:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246672 From: Bhavesh R Maheshwari Pick the patch from [1], also referenced in the NVD report [2]. [1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718 [2] https://nvd.nist.gov/vuln/detail/cve-2026-66039 Signed-off-by: Bhavesh R Maheshwari Signed-off-by: Yoann Congal --- .../ffmpeg/ffmpeg/CVE-2026-66039.patch | 38 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66039.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66039.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66039.patch new file mode 100644 index 00000000000..2e34923eda5 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66039.patch @@ -0,0 +1,38 @@ +From b3562273e37397669fdb3f4ec933e2fa57e28dbd Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer +Date: Mon, 29 Jun 2026 01:16:44 +0200 +Subject: [PATCH] avcodec/mace: reject sample counts that overflow int + +Fixes: heap buffer overflow +Fixes: FmXBI2dbgvgD +Fixes: 0eea212943544d40f99b05571aa7159d78667154 (Add avcodec_decode_audio4().) +Found-by: Adrian Junge (vurlo) +Signed-off-by: Michael Niedermayer + +CVE: CVE-2026-66039 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718] + +Signed-off-by: Bhavesh R Maheshwari +--- + libavcodec/mace.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/libavcodec/mace.c b/libavcodec/mace.c +index 2aa54fb548..716dd0c00a 100644 +--- a/libavcodec/mace.c ++++ b/libavcodec/mace.c +@@ -252,7 +252,10 @@ static int mace_decode_frame(AVCodecContext *avctx, AVFrame *frame, + } + + /* get output buffer */ +- frame->nb_samples = 3 * (buf_size << (1 - is_mace3)) / channels; ++ int64_t nb_samples = 3 * ((int64_t)buf_size << (1 - is_mace3)) / channels; ++ if (nb_samples > INT_MAX) ++ return AVERROR_INVALIDDATA; ++ frame->nb_samples = nb_samples; + if ((ret = ff_get_buffer(avctx, frame, 0)) < 0) + return ret; + samples = (int16_t **)frame->extended_data; +-- +2.53.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 57805f17095..06c6e402c97 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -39,6 +39,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-65706.patch \ file://CVE-2026-66037.patch \ file://CVE-2026-66038.patch \ + file://CVE-2026-66039.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" From patchwork Sun Sep 27 07:43:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99308 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 83E31C9830E for ; Sun, 27 Sep 2026 07:44:07 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32862.1790495037266535505 for ; Sun, 27 Sep 2026 00:43:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=OtHFAwZg; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-4887f6cf16bso1182736f8f.0 for ; Sun, 27 Sep 2026 00:43:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495035; x=1791099835; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=1c5NfZ3Wf48RJgYI/DHW03HlYlDUCv46e/Wrl536QH8=; b=OtHFAwZg66na+fcUohH4mCTKBNOaojgX3EYfRqILS2IXnRZwweilQh9vfPEdEaInXQ UsKj50gS2R9Xq3afe8WGDUloqY2qTnADjugIfpfQMXPB4C2sjoJ82npRVaw2GVqM/B0+ 3iD6dbBM6tsFEgMJIq1/zev8HLqC/IgAhuUPQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495035; x=1791099835; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=1c5NfZ3Wf48RJgYI/DHW03HlYlDUCv46e/Wrl536QH8=; b=OrN1PnvT0Z78Pb5/yy28wvqS3kqMWN9NqE97eh/7F2lAeMN350p6SZmIJgz5v0Ov41 A+PNDH79HdtNNtJXxqX8doG7bWQXmllaDj51md0YMJrFK4NK+X5yS25XjjsKr6WcBQv9 FmxsBsovnXaAz3ECIoIqK2yhusYC6lMALSQdH6zcvpJpuFDNAVnrUKaKUC2Rxyf4lh/E RUZr8Wtw/qtfuGp1eFEKe1k+hPPZ/erpAKDmqYLavj0YncBZ1w0EAdLXGKAXImMLl9QA BFnr44GoaUVNy8cy84+p7XZQVfx2TQa8RqyR/PYp01MB8muUjPNJZ/UMwiF2RvCgtsLi jrpg== X-Gm-Message-State: AFq9FYJNI3vAZ9JeFl6RHzFQZBs46fcl14YEOG40joDn2RH+h1uYvA1F L/ufZkW1TJif2Et3ryNbYuEj7KOu06YA0TQZw7mzGu9VuIp31tG85FSFmvPWtN31X9npqmNmUw2 ehyv/Dq4= X-Gm-Gg: AYBFou2mKWXbtkFL1V799zZKpKc71Q6NK81CRTqrMaBZSvTtAqruzq3HQz0PnFqCh8x z9ANnku1rC2JgL8sqrxyKRiPu7PZlgTqUBSNZrMrnaCvXXer9PxEdcR4QmANDUdI/z1yr9dL9uV DLXGgJtMkb6f7NpvwE8ASsqucnHvioAfllA6HUd9zukch7XkHTgfQpegy6HeejsZRBIqib/jQs3 FPi/EBzwR20NZ109Klo2bYnHYPESaMLRX97xJNC+8HwbPMuvPV2bwkdw9jicJ4O/u3r2hRi+vX1 l9OoJJBFV2grT1lDWjGCIDH5nQtlRl67xoyTcDRM6RvpIfbIwTfWPVj5ETxgb6fbKtA/HUy0wjp fQx2WNohS/jaAB6np6gzoYSsPLjSgBHzLm7MEOlElkcQfjwREpwPf7pNm62MhIuS2/nAGJkc3tq SnANqqcBvdDpf2bH/qXF4AyDSAWBxwKbB0l9tw1MQ5CGEOpez1VtehFDJKExplbzJTzP1V+nNbv k3jZ1nxQtGth7Zgd2HSZEr6VcbtgNta+/1KmwYfKVCXyfL5QE4FMiHEB6kVrlBhva5cUz3HWpk= X-Received: by 2002:a05:6000:2909:b0:487:a49:69d3 with SMTP id ffacd0b85a97d-4887db555d1mr12151644f8f.55.1790495035509; Sun, 27 Sep 2026 00:43:55 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:54 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 23/28] sstate: Update mtime/atime for sig/siginfo files in sstate_checkhashes() Date: Sun, 27 Sep 2026 09:43:14 +0200 Message-ID: <53a663be633c5bf4d1aeb5924705131068d7ae82.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246673 From: Richard Purdie If we touch sstatefile, we should also touch any .sig/.siginfo file if we can. We try and keep them both updated with accesses so one isn't removed without the other and they stay consistent. [YOCTO #15289] Signed-off-by: Richard Purdie (cherry picked from commit cc07895f951140dbbffcf32d3eabf65788cc4d00) Signed-off-by: Yoann Congal --- meta/classes-global/sstate.bbclass | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/classes-global/sstate.bbclass b/meta/classes-global/sstate.bbclass index 4ac63823351..5beeded1e88 100644 --- a/meta/classes-global/sstate.bbclass +++ b/meta/classes-global/sstate.bbclass @@ -977,6 +977,9 @@ def sstate_checkhashes(sq_data, d, siginfo=False, currentcount=0, summary=True, if os.path.exists(sstatefile): oe.utils.touch(sstatefile) + for ext in ['.sig', '.siginfo']: + if os.path.exists(sstatefile + ext): + oe.utils.touch(sstatefile + ext) found.add(tid) bb.debug(2, "SState: Found valid sstate file %s" % sstatefile) else: From patchwork Sun Sep 27 07:43:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99311 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 66D3FC9833F for ; Sun, 27 Sep 2026 07:44:08 +0000 (UTC) Received: from mail-wr2-f12.google.com (mail-wr2-f12.google.com [74.125.225.76]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32863.1790495037833386012 for ; Sun, 27 Sep 2026 00:43:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=KbaLxNW4; spf=pass (domain: smile.fr, ip: 74.125.225.76, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f12.google.com with SMTP id ffacd0b85a97d-48434392b02so1726115f8f.3 for ; Sun, 27 Sep 2026 00:43:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495036; x=1791099836; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=UqKdY8iHVNnOoZTFk2FApeLrK3avLKCFad/W5NgvZtM=; b=KbaLxNW4VgesPDUxvK8KJsD79D4OuAxORBDzNeYD8rCI9pQCG9rG4GFNSsY88H27EC uFrRuY1mB2Ar6pWaaDPxHV5DvZuB9xgzXfn4SfRHWLAnK8AfzWLhJoT0Zxr2LhO+fZGe NsUCmiA9t9cgcyztINCaRIAw2HvTHBH71FFDw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495036; x=1791099836; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=UqKdY8iHVNnOoZTFk2FApeLrK3avLKCFad/W5NgvZtM=; b=Ymw1bL71XDoYwIv4dPQbdNnTSQnoalEabVlPiNUrFELg1amYP3M7tJlN0cBrOiqjBG yW0mhC415en0AMovgrcnxNUK3Rq6kex2+Mylz38gGg4EM+Fu4WR5FTwLwzBSmcURjJwG mGL4RghUi//FBoAWbK0FG5ZuyN14pKOzuRs1IwPGlB85xgbs7duTnjLslv9kWaudlzuI 1U8XoJ+8ljDenwvXCHI201laWkPhTV7VcxPp1ukT7uXU4Ofq6+51v7RCUoxz2QOm2twS X8u2+Nr1UOEYD3ahkMDlZeZ4dveM0CECsTqbmWnKeLRZ5BQ7cHZ+JG6vm+5lND362E85 88uQ== X-Gm-Message-State: AFq9FYIMXImGcTs/y8Nt/eVarLc6dTEPRYTdNWx43rCjWVKRWJAxDxGd gDnczVy1fVqUTZn91arTXxHuVCzap6i+tT+PjRftxP/pxp2VOW+TLPyxhnRERluTXjGDT9B2G8k b/q8Pmb4= X-Gm-Gg: AYBFou2qqx5h6Iabk6qe6a+89dmdW3tf40QVMO6Xoi7NtwRlurl/WaUOc/qhJ5DGsIX tjNNFHM2YDufH1lWny8CDt5O/aarHLEwb8d/ccnG7+d8Fx5wBnCwX1A9J5P6suHOWNK/XaU41LT +XETt6fFjwPr5v9wkNHWulRZAtI3ZYe4u82HZ4MRby+nNjX/M7rOOvJaLd5CCnBJ/cVCWDlj7i2 7jVV6ga6D5hU86ceCNgWILIisIol5TWRxfJm6VNOUvebezRxoiZUDKBN5HdKzbKoKyKpclsZCLf tbUf1DeFtjblJ/DhZ8Qhz1V8WMEqnVdueDQ1CLHgL1zr10x/IF49tc+IO9g5CpBWwKsdag+zE69 oz89aPsCMqv91jOu5oBLLo54Hs4yPwaBH2h2Yk7Ov6ou/VOvKLXA475QNBfoWTw1qkv/cvP1RAr 75lB/yM/PeDPmlhXm3yFV87KAhC+sBR/2mPLhau9SYk0vBMGGpOtOpGxjZI3a7UTiXU7n2DCt48 5P7lUHZik9QRd7tSAsokakuVbdQs71eoiiAc+zPbMh7AagLdRldM1Kj81viNoNNthS69GN6ew== X-Received: by 2002:a05:6000:4013:b0:488:84b0:3abb with SMTP id ffacd0b85a97d-48884b03b19mr8745918f8f.27.1790495036048; Sun, 27 Sep 2026 00:43:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:55 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 24/28] sstate: Update unpack touch code to be consistent Date: Sun, 27 Sep 2026 09:43:15 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246674 From: Richard Purdie When we unpack sstate files, we want to update the mtime+atime of the sstate object and any sig/siginfo files, both for the files themselves and symlinks. The logic was getting a bit hard to follow and wasn't entirely consistent with only a time in some cases. Clean it up and be consistent for all the files. Signed-off-by: Richard Purdie (cherry picked from commit 5213ca88cbec4e86b50d8da1fe4c300ca8f5de17) Signed-off-by: Yoann Congal [YC: for [YOCTO #15289] ] --- meta/classes-global/sstate.bbclass | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/meta/classes-global/sstate.bbclass b/meta/classes-global/sstate.bbclass index 5beeded1e88..a9f139acd7d 100644 --- a/meta/classes-global/sstate.bbclass +++ b/meta/classes-global/sstate.bbclass @@ -931,12 +931,13 @@ sstate_unpack_package () { fi tar -I "$ZSTD" -xvpf ${SSTATE_PKG} - # update .siginfo atime on local/NFS mirror if it is a symbolic link - [ ! -h ${SSTATE_PKG}.siginfo ] || [ ! -e ${SSTATE_PKG}.siginfo ] || touch -a ${SSTATE_PKG}.siginfo 2>/dev/null || true - # update each symbolic link instead of any referenced file - touch --no-dereference ${SSTATE_PKG} 2>/dev/null || true - [ ! -e ${SSTATE_PKG}.sig ] || touch --no-dereference ${SSTATE_PKG}.sig 2>/dev/null || true - [ ! -e ${SSTATE_PKG}.siginfo ] || touch --no-dereference ${SSTATE_PKG}.siginfo 2>/dev/null || true + + # Update both any file and any symlink pointing to the file for sigs as well as the file + for file in ${SSTATE_PKG} ${SSTATE_PKG}.sig ${SSTATE_PKG}.siginfo + do + [ ! -e $file ] || touch $file 2>/dev/null || true + [ ! -e $file ] || touch --no-dereference $file 2>/dev/null || true + done } BB_HASHCHECK_FUNCTION = "sstate_checkhashes" From patchwork Sun Sep 27 07:43:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99310 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D7A2FC98338 for ; Sun, 27 Sep 2026 07:44:07 +0000 (UTC) Received: from mail-wr2-f33.google.com (mail-wr2-f33.google.com [74.125.225.97]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33593.1790495038630802444 for ; Sun, 27 Sep 2026 00:43:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=waQw+5+h; spf=pass (domain: smile.fr, ip: 74.125.225.97, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f33.google.com with SMTP id ffacd0b85a97d-482f6351831so1149019f8f.1 for ; Sun, 27 Sep 2026 00:43:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495037; x=1791099837; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=HY39bORHzKaiAIfiMh1fv9OVVPpBGCw12z5aytjyCAc=; b=waQw+5+hpl41GxHDgQDnBbqL60dZI0PRe4aP0RWyBghzUZ3CMDbDRR3jGvY97fvbzt 4pYD9sQp7dVuFKKsQQ8m+DFbeGyVb42O1adQQdVsyt70VNFXkg2axnkk3iga+CyrOE7I Eoc0XWZb+DPYck+hwKlxuOkIKh9ME5el29ODI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495037; x=1791099837; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=HY39bORHzKaiAIfiMh1fv9OVVPpBGCw12z5aytjyCAc=; b=2Qwf8YCqXrZafJIFMPPphML05XFJ1JX4T8NtzK3nC1vpLbGBp7HcFz/N9sVctO+G6D V9lrXrrUM9LdCVFeYBMCNKx6ucQ8gVAE9IvrsG9yixpIVBghXYH6jEw6xP4aLZt1NXII GYlxRJ3cLbrCGLV66Ifeb+4wS26/xYiC5mBUKuR8fAzfDkKfRT3zMx/ZIZOFxGdmgfxT QxgWa7OgbA9Io8j8plPeAQVAz+QWqokazw9i0JoJ+E3Rk4ZoiTFJMmyormk1C3DzjerF bYv4/I81o8HZzxIxQHtzza7yLAHXvbw4AJPVSqsiVcgbs4tybRf5P7V1ZmbA/PH+Sji5 Dwxg== X-Gm-Message-State: AFq9FYKdb6jyY68MBWfjrx4yWaMiDb2iCGaYW6VMmg3I2QgO8w5PLt11 1/ZKgfUmLuiqwQMA/MEBfW2OaEEFF1RbAP5tEWXRyB92UTBf1Rw1ffggZnp+y1KGgDXdu9QU6Eg n/RS7Mj0= X-Gm-Gg: AYBFou1x8+izMiHU54A2O9TgqKaITT0TNTKc95mSFYzhQ54z9jcqSXrUMNjVQs9B+Sj e549EnyJ/L5Bd2nKx1nq1htGEJTeTk2IQJOt3m+WkEw4R87FAgb5fkyGE6i4V5tHmMoK+8D5Pkr 9spul0IzUruaXuXI98UvIXizLJJmB00fXs2Xc3yq1BcVrOhSys1l3B+emL05WfGaRqpiUxqIAv9 yocr8kBmHbQw1zHFvUrlA1CZwS0ssgdwJZdvzRH4E3afoW8do6RUbQqA6quI+jDX1/xz7/ZZd2X DThGQrpA7HaOUNEFX1aSIQN0JtZ3E5VPGigFosrOcUIhhD/ctjzfIUboiplKhiBjsVVgfD3Nucn 9aqZlAau6ZJmD2eGDOALKKXbjHhnqF5rE7cU9J4M1YdlpH2bPt4xoMaGZnLkH1CFk6MaZuVw+FD uwt8j/RzQvac98jsdVCuOBT/Fm5WgzTnP5lv1XLVS+8SUOU5Aks82yTd+SbSGYUo42avTYFet4n Hi43y352lsuqoBwDuRuCz7tmCKoaoaM5uhLABiXIG9xrrF7YCDttLETAigZkQ89fBQd0ZQlEw== X-Received: by 2002:a5d:59c5:0:b0:487:faa:b1e0 with SMTP id ffacd0b85a97d-4887170dd86mr19486220f8f.12.1790495036814; Sun, 27 Sep 2026 00:43:56 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 25/28] linux-yocto/6.18: rt: update to v6.18.37-rt6 Date: Sun, 27 Sep 2026 09:43:16 +0200 Message-ID: <904f0f2ead7c8b53fd3dc8807d2597f0cdb00f77.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246675 From: Bruce Ashfield Integrating the following commit(s) to linux-yocto/6.18: 1/4 [ Author: Sebastian Andrzej Siewior Email: bigeasy@linutronix.de Subject: v6.18.13-rt4 Date: Wed, 25 Feb 2026 11:35:17 +0100 Signed-off-by: Sebastian Andrzej Siewior ] 2/4 [ Author: Sebastian Andrzej Siewior Email: bigeasy@linutronix.de Subject: v6.18.35-rt5 Date: Wed, 17 Jun 2026 09:43:08 +0200 Signed-off-by: Sebastian Andrzej Siewior ] 3/4 [ Author: Sebastian Andrzej Siewior Email: bigeasy@linutronix.de Subject: ARM: Fixup the stable merge. Date: Mon, 29 Jun 2026 16:47:21 +0200 This a merge fixup, properly replaces ARM: mm: fault: Move harden_branch_predictor() before interrupts are enabled ARM: mm: fault: Enable interrupts before invoking __do_user_fault() with ARM: ensure interrupts are enabled in __do_user_fault() It is needed because "other" patches were applied as part of the stable series. This contains the patches that were applied upstream. Signed-off-by: Sebastian Andrzej Siewior ] 4/4 [ Author: Sebastian Andrzej Siewior Email: bigeasy@linutronix.de Subject: v6.18.37-rt6 Date: Mon, 29 Jun 2026 16:52:33 +0200 Signed-off-by: Sebastian Andrzej Siewior ] Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit e9a7fd90765d277d126cc58a5c4905e4e200ae39) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 4 ++-- .../linux/linux-yocto-tiny_6.18.bb | 4 ++-- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 20 +++++++++---------- 3 files changed, 14 insertions(+), 14 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index a0c2abf1c5f..55f3fe8907c 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,8 +15,8 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "40cf3a2e9ae15c3d4b3a528d4de015263639cac3" -SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" +SRCREV_machine ?= "c82ff0cbda2a00b9073e06c9fe4ba550c9056d45" +SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 0d4c98f2840..3b1342d6774 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" +SRCREV_machine ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 1a7a8659bf8..80301434799 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,18 +17,18 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "1cd95e881ac1b4f07906bd0e9482891e12f84a83" -SRCREV_machine:qemuarm64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_machine:qemuloongarch64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemuarm ?= "0f778c0a178fdc50063c212b5320b1f082f83f1a" +SRCREV_machine:qemuarm64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemuloongarch64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_machine:qemuriscv64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_machine:qemuriscv32 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_machine:qemux86 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_machine:qemux86-64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" +SRCREV_machine:qemuppc ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemuriscv64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemuriscv32 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemux86 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemux86-64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0" -SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468" +SRCREV_machine ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same From patchwork Sun Sep 27 07:43:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99312 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F0FECCA5FA0 for ; Sun, 27 Sep 2026 07:44:07 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32864.1790495039921091436 for ; Sun, 27 Sep 2026 00:44:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=O76Kstqy; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-488811c9ebaso882201f8f.2 for ; Sun, 27 Sep 2026 00:43:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495038; x=1791099838; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=jJ3egdKuDo9UDpm8mXI/srmKuhSthOttWapemapzLaQ=; b=O76KstqybwHFfG1i6Idjx+D689mlb7SWABbJxOxyCK7JT5EQaRj/Ly/a1DH3SidsNj mber2KHaQfOKkHbwyGe2KMijUIN38PKYoDfwgR1NCfMxtJa93IIL9jUFXceuH33LBGVS vQjJfqu+PUdGWA5HPofZV31rRyjTt3+9Df9Bg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495038; x=1791099838; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=jJ3egdKuDo9UDpm8mXI/srmKuhSthOttWapemapzLaQ=; b=aRxTzaceUEEJcHZtn9gP8U//usllEXBCJEo87vDrbKwb75Hp1toruM2Se3JJHJa+mY uBxZ9OIrWUghxS0d8TbtsB0sStLmjMu0sW3OmqdXfEMio952PLYfpJLV/G13v/nH6uy5 GaMTMBX23RvCsMO8V0ucykC17ZraXC8l5fAvLlbSUlk3OoHkPSkLKQMC5O6vCUqRxkkR sR/G6RhudjFIGvU18I+REHq8/26AaNF3hbsxfqViw2qQ+5L6PBl483ZKbm3N1ZtMx5ii SywYHUlEwnZ9JiTWTD/E1G2sINvlMk5OztQNUW2J7wuCqm2nO5dKD8vjQyluXDinL+jM 1P3Q== X-Gm-Message-State: AFq9FYJSZ6mXmh6N2SQnk8wNb4r7LmA3xXHRYxbeda3Mj61fM7xa1tf7 RyR/GrkIpAeyb/In/TCgi1WEnobFA1ksRAvzZuFxrl8eJVuQTCdmZCbbfH+UbShR4m6vvS52KfH xlMllxgg= X-Gm-Gg: AYBFou3Z0OQTwDGNwYBDDuyMXfGvKDI9q+Z24lx/gp/niY6YTMpIhJAmXxHa4GxoTlt l+5uPR8W55odd7uNaxqb4DahiNoXDudsmfpS34ADROPxiK5nRaSAakEKGOPQesEv0S0aiozxfzE lfmknyvXJItfZTwY7xijrGNyTsjq9/BgqU3U/J+626cK0WnUpWBYuN2uFLTZxHN7VO8b5dkiRrA 0Fr7TtNbiYPFq35Ys6N+eSbkch3V571TNXhnMTfWEOGTCNfs6Op6bONM5SmNNjlHcYtZ5LmFvgl 9HaiS80bCEguqKx3zjNvUFzDYIhhPFGFNXW67yQcmQUmiVi2Ycq8ea06QIgzD3xxmanbEW5Bcsl ZXyyLBCC69FBl+jbG6NWhIYJ78qq1KsZ9VUI63cotcnOy179eFHvupnUrFhrlh9N1OiG5jFaqDy KdXl3O/kTiRNEFAt7zWKfLd20b0RU+qVT32fSMAE/gnK59sGBDte3wdVzg6dUfq1rtk8KG0XNgg 9Dr8QnABBhd6yNVT/1fxdfFLJqRGU1lOLMtncALUghUev0RV2FoHoN0FhxO/7g8Ln/IhkPJ3Q== X-Received: by 2002:a05:6000:2f82:b0:488:8b07:f3f0 with SMTP id ffacd0b85a97d-4888b07f865mr3212709f8f.24.1790495037506; Sun, 27 Sep 2026 00:43:57 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:56 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 26/28] linux-yocto/6.18: update to v6.18.50 Date: Sun, 27 Sep 2026 09:43:17 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246676 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 7cfc41f8e80f1 Linux 6.18.50 8e30f5427f345 mm/rmap: use huge_ptep_get() in try_to_unmap_one() 381a0a524e967 mm: avoid unnecessary use of is_swap_pmd() 6a259dd313043 platform/chrome: sensorhub: Fix dropped timestamp events and log spam e91d66e5ff661 selftests/mm: fix on-fault-limit false failure under sudo-rs 2d6150e5e6aa6 udf: Fix i_lenExtents truncation on 32-bit kernels b7eff3f621ef2 timer: Keep debugobjects state consistent in migrate_timer_list() fecf1e3777526 timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() 6067c39c2cec1 taskstats: fix cpumask parsing cutting off the last character ed64aa505875a smack: fix cred UAF in smack_file_send_sigiotask() a246da20c8e4a signal: avoid shared siginfo namespace rewrites 236c8ecaafc63 sticon/parisc: Detect default STI graphics card for console output e8527de7fea19 sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cde2d927c29e8 tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout c3c7e87c76b42 zloop: truncate finished zones to zone capacity f49e55b1c8fe1 xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() ae0c79a852704 w1: ds28e17: reject an oversize length on an I2C block read 165a330a68b5f vsock/virtio: flush works in dependency order 03b81f015dbb2 wifi: mt76: mt7996: validate default EEPROM firmware size 01f2e0da8548f wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames 304470333b7f5 wifi: mt76: mt7925: cancel mlo_pm_work on stop 5fdaf7016d768 wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy 4506e229b2e46 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex 34a505071d1ff wifi: rtw88: pci: fix resource leak on failed NAPI setup 7364713f0931e wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() dc8b0be0ec4d9 wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() 0c0b374e12d52 wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids 97a1af5ac131b wifi: rtl818x: initialize eeprom_93cx6 struct to zero b1bbeb8970eeb wifi: mwifiex: Detach sync cmd buffer on interrupted wait 7c257a295e05c crypto: sun8i-ss - Remove crypto_rng interface 8e4f9110aba31 crypto: sun8i-ce - Remove crypto_rng interface 620acb1e8037b wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop 84ba017a1e1ea wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() 261d7c7610b4b wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() 7ef23317f9976 i3c: renesas: Reconfigure the DATBAS register on re-attach 9382fcf3a8c44 i3c: renesas: Clean DATBAS register on detach 0093f9fc102ba i3c: renesas: Check that the transfer is valid before accessing it 5697d779577e2 i3c: master: svc: bound IBI payload to the requested max_payload_len 94fb9786d67a8 i3c: master: Fix info leak and UAF in device unregister path a15a1b95de980 i3c: master: adi: initialize the lock before enabling interrupts 1894fc7a3bab9 dm-pcache: fix use-after-free and invalid seg operations in kset_replay() 10acf740c3adb dm-pcache: fix implicit u8 truncation of gc_percent in message handler 83e3116283ed2 dm-pcache: only hand out initialized cache segments 663ee2f3824a5 dm-pcache: detect a cycle in the last-kset chain during replay 2cd9776fe3f2d dm-pcache: clamp the tail kset read to the segment data region ffd9a214a94f9 dm-pcache: bound the persisted tail-position offset 91b93fe5cf4d6 dm-pcache: validate on-media seg_num against the cache device size d8caf96040a06 dm-pcache: validate kset key_num and intra-segment bounds ab5dcde6fa96b dm-pcache: validate geometry fields from on-disk cache_info 296efdc110b10 dm-switch: use WRITE_ONCE() in switch_region_table_write() 74210fa072960 dm-stats: fix a crash if allocation of per-cpu data fails c860cd3f40382 arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map() edf30d65e3ac5 net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry 44dc702be9a9e rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22 b5fe67111e63a ovpn: run deferred work on a module-owned workqueue 50f4a793c4ff2 ring-buffer: Fix subbuf resize race with ring buffer readers 22fe01a2e2f7c ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering 37c3210c491ac ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG 8acb66d0513de ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx 40ee4224e2fe2 ALSA: virmidi: Check card index validity at probe 7555e83d7738e ALSA: serial-u16550: Check card index validity at probe d7ef7890e3e35 ALSA: portman2x4: Check card index validity at probe 7ef9ad82d95dd ALSA: pcxhr: initialize mutexes before requesting threaded IRQ a4e774eeb61ae ALSA: mts64: Check card index validity at probe cc4215cc2a4b2 ALSA: mpu401: Check card index validity at probe 13d61a920435d ALSA: hda/ext: preserve PPLCCTL bits when clearing reset 7df3194bdb747 ALSA: bcd2000: clear the URB pointers on disconnect 7b3f985584936 ALSA: aloop: Check card index validity at probe 2a6f6fba3bd31 ALSA: 6fire: bound the MIDI event length from the device 94ca4f040ba48 mfd: sm501: Fix potential memory leaks during remove 5e7fe9c6c8c31 mfd: cgbc: Fix teardown ordering in cgbc_remove() efe0ed4c0f4e8 hwrng: stm32 - Fix runtime PM cleanup on registration failure cfa186a0857a0 seg6: reset IP6CB after IPv6 decapsulation 288f997067084 net: skbuff: don't touch shared zerocopy state in skb_tx_error() 34ab62c959f5f net: fix spurious TX timeout after dev_activate() af0ee8f04bea2 net: cap advertised IP tunnel headroom 5bd8b764a610b net/smc: unregister the connection before draining the rx tasklet 313f79149eb33 net/smc: stop killed, freed and out_of_sync sharing a byte c52a998a223e7 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() 0761e49aa78c2 net/smc: fix use-after-free in smc_rx_pipe_buf_release() d89dc1bd8845c net/smc: fix socket refcount leak in smc_switch_conns() f950e1b1f0aad net/smc: do not dereference an unset send buffer on the SMC-D teardown path 486c699a8cde8 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages b893152a886bb net: ntb_netdev: Count packets dropped on RX refill failure 4fac86e976975 net: ntb_netdev: Avoid double-accounting netif_rx() drops dfab7171cd391 net: ntb_netdev: Fix TX busy and drop handling 6b6bbc6c878d6 NTB: ntb_transport: Reject oversized TX buffers 894e136b432da NTB: ntb_transport: Fail TX enqueue when the QP link is down 0c4aabc904490 NTB: ntb_transport: Recycle TX entries before client callbacks f01e6a35c440b net: thunderbolt: Mark the connection down when bringing it up fails 61ff3c353e5d2 net: thunderbolt: Release the Rx HopID that was handed out on mismatch 67a82e6f886be net: ravb: serialize PTP clock teardown 8d4d06d6e2b50 net: ravb: avoid dereferencing an invalid PTP clock b6b533f83461c net: phylink: correctly validate returned PCS in phylink_inband_caps 0860af127aa79 net: openvswitch: fix nf_connlabels leak in ovs_ct_init ac73e3af571da net: openvswitch: fix flow mask use-after-free on flow deletion 9c340473f4822 net: l2tp: do not propagate multicast notification errors 62da38b4b3a0d net: ipa: fix stalled modem TX queue after runtime resume 42a33e679ea05 net: ibm: emac: mal: fix NAPI locking f71087e7c63aa net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO e098d9cc88596 net: tun: bound receive headroom 32785d75e60df net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition 486577db80789 slip: fix use-after-free in sl_sync() 15d1f3c0dbe7a xdp: fix zero-copy frame layout 8e3763f1ccac3 net/iucv: filter frames in afiucv_hs_rcv() by ingress device 99692252b348c ipmi:msghandler: Cancel work cleanly on an error 53af3a8bae0a9 ipmi: si: Fix NULL pointer dereference after failed registration d46c97eddcbc5 ipmi: Remove all sysfs files on registration failure 5719431ca2b5f ipmi: ipmb: validate write message length db8147c5d5ad2 interconnect: Fix use after free in icc_get() and of_icc_get_by_index() 417e02f7b6051 io_uring/query: cap user size passed to copy_struct_to_user 0c12a798078bc platform/x86: hp-bioscfg: warn on element type mismatch instead of failing a38127df99ae8 platform/x86: hp-bioscfg: pass validated element count to package parsers 95d2f9b5189d0 platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed b15b334fbc3c0 platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() e3c1c5d1c9230 platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password 0f9aad0842488 platform/x86: hp-bioscfg: fix heap OOB read on empty password write 7cd8fe01aba30 platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() dea1a41160e70 platform/x86: hp-bioscfg: bound ordered-list parsing by the package count 0cd1530f84e1c platform/x86: hp-bioscfg: advance elem past consumed array elements 0a14d35ef529a platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS bc9aa5fe21c39 platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails 8178f59d76570 platform/x86/amd/pmc: Propagate SMU errors and validate S2D address 98d91d5b6a988 platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths 5eaf7faa99578 platform/chrome: sensorhub: Bound the EC-reported sensor number 56dc46094973d platform/x86: think-lmi: Fix current password length check 9c28adde051fe platform/x86: think-lmi: Free system certificate signatures 89a076948ed61 platform/x86: think-lmi: Fix certificate thumbprint sysfs output d7cd3e4d76034 platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response e1b3f89673bd1 platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path e07a42bb9c909 platform/x86: ISST: Return error during profile addition 62840acc3044f platform/x86: ISST: Validate parameter for frequency and priority 93268bc3cd84f platform/x86: ISST: Validate parameter for core power state 5b032e1dda486 platform/x86: ISST: Validate logical CPU id and clos id b14db79d02bd3 platform/x86: ISST: Use PP level enable mask 92c5fffa63ad9 platform/x86: ISST: Just allow 2 bits for SST feature enable c280fcd53b938 platform/x86: ISST: Add a NULL check for sst_inst[] 2550f89589caa mmc: via-sdmmc: stop card-detect handling on probe failure f7ff3027ef004 mmc: via-sdmmc: cancel card-detect work on remove 82e707eff9e3b platform/x86: ISST: Validate socket ID in clos_assoc ioctl 1889a9156553f platform/x86: ISST: Validate level in perf mask ioctls 22222f92b0a51 platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer cab2895729516 iommufd: Fix UAF in selftest IOPF reporting 4c33d00ad9a91 iommufd: Release current IOAS on xa_store() failure 436189ee4bb2c iommufd: Avoid locking internal accesses during unmap 45705a6bfdb28 iommu/vt-d: Force requesting ACS when tboot is enabled 364279b5623f7 iommu/vt-d: Fix no_iommu to disable platform opt-in f80f3acb69164 iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add 2235eafda9b3d iommu/arm-smmu-v3: Manage teardown with devm d903d99ffd22b iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field 968e9a1f71140 iommu/sva: Set handle->dev before the SVA handle is visible f532401be9312 iommu/msm: Unwind probe state on registration failure cfc5c1b2caa17 iommu/amd: Put PCI device after handling PPR faults 238e1f7a1463f PCI/proc: Warn on writes to kernel-exclusive config space regions c2d4174f49245 PCI/proc: Use file_ns_capable() when checking config space read access 301288f85679a PCI/proc: Avoid spurious runtime PM wakeup on config space accesses b30713111325e PCI/MSI: Enable memory decoding before restoring MSI-X messages 0e59a232aaa04 PCI/ASPM: Avoid L0s for Realtek RTS525A 39c4dc79d77f8 PCI/AER: Fix mapping of errors to agent & layer 4f887d8ed75f8 PCI/AER: Emit TLP Log only for unmasked errors 6beadccc432cf PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses 7f4db64f0ba7b PCI/sysfs: Fix read byte order in pci_read_legacy_io() 43cf455dd5a9b PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] 4b575052ea654 PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() 01c2f0c66bd1f PCI: plda: Fix use-after-free of event IRQs during teardown 5d4bc470330a6 PCI: meson: Fix GPIO state while requesting PERST# 1ad6994853853 PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk 6053d6eacbfd2 PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip ceafb262475ac s390/dasd: Propagate partial completion length across ERP recovery 6452c13646af7 s390/dasd: Guard sysfs discipline callbacks against unallocated private data 52b331c99baac s390/dasd: Do not complete a failed ESE read as successful dcce7a06ea690 s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks aad7247bd35ad power: supply: max17040: synchronize work cancellation on suspend 17d43f64b17e4 power: supply: max17040: drop incorrect I2C functionality check 13fb0477da9b4 power: supply: max17040: propagate register read errors 39b60d615dfa1 power: supply: ucs1002: fix use-after-free on remove a4460e89d4088 power: supply: twl4030_charger: cancel workers via devm 1b9978433c61a power: supply: rt9455: quiesce delayed work before teardown ee053561e21ce power: supply: qcom_battmgr: terminate the strings from firmware 06618447029c6 power: supply: qcom_battmgr: fix use-after-free b3aa1e9509e1b power: supply: lp8788-charger: fix use-after-free on remove ab6b1ad710bed power: supply: lp8727: fix use-after-free in lp8727_release_irq() 4b1f2be1e1b74 power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS 78be8b7403ff7 power: supply: cros_usbpd-charger: bound the EC-reported port count 86e4fa65368f3 power: supply: charger-manager: register regulators before exposing sysfs 238320ad029a3 power: supply: bq25890: Fix power_supply reference leak 9e1aba34df9a8 power: supply: bq256xx: drain usb_work before freeing the charger f495808cdd6d9 power: supply: bq24257: fix use-after-free on remove d02a5794c3dee sctp: fix stream->outcnt underflow on duplicate RECONF responses 7ad8933bca97b sctp: distinguish sequence zero from wildcard in reconf lookup 25419f516ea84 sctp: fix NULL deref on untransmitted RECONF completion 1035bdef1efb9 sctp: drop a chunk if its transport was removed fa306a40e716c sctp: stop processing a packet once its association is deleted 8a02ad98798fd nvme-tcp: reject a read that transferred too few bytes 3b3d27670c0c8 nvme-tcp: fix host memory disclosure on R2T for a read command 6a01b58263108 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone 0d4f317b07d6c nvme-pci: disable controller on admin queue IRQ setup failure 67551d8430df9 nvme: zero the discard fallback page 1e456cc2744ee nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path d662f7fc04fde lockd: fix NULL dereference on lockowner allocation failure 41f0a6d31615f lockd: pin next file across nlm_inspect_file lock-drop 3088e41292fec ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() 6aeff1636b398 i2c: mxs: fix DMA channel leak on probe error 8d2c120d2d5bf hwmon: (max6621) fix temperature clamp range 9b38d9a2e46a2 hwmon: (max6621) fix negative temperature offset and crit readings 68c59343ad1a7 ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC f2a1a83487c6c arm64: proton-pack: Restore the nospectre_bhb command-line option e7c9b1d433b05 arm64: compat: Fix decrementing LDM/STM alignment emulation 15d1feeae07d0 ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion e41a59fc056f6 openvswitch: only skb_tx_error() a packet we are about to drop d64a75369cd0f openrisc: fix arbitrary kernel memory access via or1k_atomic syscall c0c165487a2ea ocfs2: fix readdir position truncation on 32-bit kernels 0608018a71f24 ocfs2: cluster: fix o2hb_dependent_users leak on pin failure 251e38f5af7b2 ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item ce035f208d68b ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() 0761d2c949442 ocfs2: validate rl_used against rl_count in refcount block validator 50c4cc9183e11 ocfs2: validate lengths in dlm_mig_lockres_handler de10cd3b062a5 ocfs2: bound namelen in dlm_migrate_request_handler 71f07b7f90b31 ocfs2: always run deallocs on copy-on-write completion 116d14f29a052 orangefs: skip leading spaces before parsing client debug masks f796f38a324e8 orangefs: fix double-free of trailer_buf on readdir copy failure bc6fdd425fdeb PM: sleep: Unblock runtime PM when device prepare fails 6fcb0b745a0b8 ring-buffer: Hold cpu_buffer::lock when resizing a subbuf 8c1ecdcdea738 ring-buffer: Free cpu_buffer::free_page with subbuf_order 2dc510957fe8f ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() 1c3036a818005 regulator: qcom-refgen: correct the regulator type to CURRENT 20e5fbb8c1a4c regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata 95342d26f9c6b regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer 71d5c41ac583d RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR 4f8bb11dd2ff3 RDMA/ucma: Lock the handler in ucma_write_cm_event() 28ac2dd416482 RDMA/ucma: Lock the handler in ucma_set_ib_path() a38cd610b24f7 RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget 85f438382a865 RDMA/cxgb4: Cancel reg_work before freeing device on remove 2a952fb1b20d8 qede: Fix NULL pointer dereference in TPA fragment processing 3f5677d2f8173 ptp: vmclock: prevent read-only mappings from becoming writable c7e32814a6bf2 remoteproc: scp: Fix device reference leak on failed lookup 37797d5013c9e riscv: unaligned: stop using kthread for check_vector_unaligned_access() 8f392916a3540 riscv: acpi: Handle LPI architectural context loss flags 5343399ed7242 arm64: dts: rockchip: Fix rk3588s-roc-pc audio description 8fc4bafabc065 arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio 650d2d5c0df7e arm64: dts: rockchip: fix emmc reset polarity on px30-cobra 5512c23231206 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck fe455c13bf01e arm64: dts: rockchip: fix eMMC reset polarity on PP-1516 b6b3e4d5973bd arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on 6bb9469c34fff arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags ff23eb4823d82 Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro" eb57632f9418f rpmsg: glink: smem: order FIFO read after availability check e7143c3f4e5c0 scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() 2a8dd9fd12f3f media: staging/ipu7: fix async notifier UAF on probe error path 7f6956b6dcd66 staging: media: tegra-video: vi: fix probe failure on skipped last port 656d047dc0c29 staging: media: tegra-video: fix of_node_put() on VIP parse errors 5be6d02837d41 wifi: mt76: mt7925: cancel pending mlo_pm_work e1330d719c047 wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets b95c33a4e7438 udf: reject VAT indexes equal to the entry count f84ec84d8d4bc svcrdma: Validate Read chunk positions before reconstruction a798714b58041 svcrdma: Reject Write/Reply chunks with segcount 0 1949dd1576f7a svcrdma: Reject inline replies that overflow the pull-up buffer 3cf372cec7ab2 svcrdma: Reject connection when transport allocation fails 5aabe070c00e5 svcrdma: Fix unmatched rn_unregister on failed accept a1c954ca4977a svcrdma: Fix pcl_for_each_segment for empty chunks a46b35f213c24 svcrdma: Fix offset arithmetic in read_chunk_range 1de391e8b94e3 SUNRPC: wait for in-flight client TLS handshake callback 1f9856af065b6 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field 7a1d0501cbb96 SUNRPC: reject duplicate CREDS_VALUE options edeefb111d618 sunrpc: init gssp_lock before publishing proc entry ebcbd2523a852 SUNRPC: harden gss_unwrap_resp_priv length checks 806584a4b67a7 SUNRPC: harden gss_krb5_unwrap_v2 against short tokens fa46b6aa7a698 SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat e769fcde3cc73 sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir 08bc49e054126 sunrpc: defer rq_argp and rq_resp free until after RCU grace period bd1ef2cfb44d7 SUNRPC: Check svc pool percpu counter allocation 2e861ce2aaa46 SUNRPC: always drain cache_cleaner before destroying a cache_detail 39981133df21c SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode 9d04d64ad1924 sunrpc: route to a populated pool in svc_pool_for_cpu() de942dd8c2c83 SUNRPC: svcauth_gss: enforce krb5 token minimum length e0778464049b0 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry ad0cce80d4af2 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow f1b7b2c7ffa97 phy: fsl-imx8mq-usb: fix typec switch leak on probe error path 704ecd010d4a9 params: fix charp corruption on allocation failure ff110e85837d7 nouveau/gem: reserve the bo in the info ioctl around the vma lookup 04ab51d4e369a module/kallsyms: fix nextval for data symbol lookup 51887ccd88791 mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction d82b90a38c2ca mpls: reload header after pskb_may_pull() 50d0aa7d25ba4 module: validate string table section types 3b097416b4cff md: do overflow check for sb->bblog_shift in super_1_load() 0efabe6229dc6 md/raid10: fix still_degraded being inverted in raid10_sync_request() 121d35014e497 mailbox: qcom-ipcc: fix duplicate channel allocation across holes 09e649117c54b libnvdimm/labels: Prevent integer overflow in __nd_label_validate() 627ce4902df1d landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation a602cd128d17a ipv6: use RCU iterator to dump route exceptions 63f50e9f90d02 ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() b8282668d8fa7 ip6_gre: fix hardware header length for NBMA tunnels b36dfd6e8cff0 ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() a8af6fbac895f ip: orphan prefetched skbs before multicast forwarding 31e4be21dacee ipip: fix skb leak in collect_md mode when metadata_dst allocation fails f9182a85991a0 jbd2: check need_resched() when skipping busy checkpoint buffers 71c6b872c7464 jbd2: bound shrinker scans by examined checkpoint buffers 30e8cb8598aa4 kasan: fix cache shrink race with CPU hotplug 15deb4e33f474 Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request 657054159d83a Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative 94d548fc264a2 Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative 1bad0896cbc06 Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection d0b28e9655f4b Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb 68e7a31abc88b Bluetooth: hci_conn: re-enable advertising only for peripheral role 946d76db77ee5 Bluetooth: RFCOMM: serialize security confirmation handling 49fd7116f76b8 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready ec3992e38f777 Bluetooth: hci_uart: Fix false success return in hci_uart_setup() 62100186f1771 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative 1ed5982c53699 Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 c674c504bfdd0 cxl/pmem: Format the nvdimm serial number as unsigned decimal 14d52c15d5d99 cxl/features: bound fwctl command payload to the input buffer 2924b2e365148 cpufreq: schedutil: Fix rate limit overflow a807a9ef87ad0 coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior ac4a5eb8b002a dm array: reject an array block whose value size is not the caller's b33f76d33aaea dm array: validate array block headers on read 644140527ae49 dm raid1: reserve space for NUL-terminator in build_constructor_string() 36ff918637e35 dm-era: fix shadowed superblock leak on take-snap failure 49694a363f7ec dm-io: report non-retryable errors separatedly 9493ac67623d4 dm-io: clone the source bio instead of copying its biovec 272fcb4ba6fab bpf: Harden bloom filter sizing and indexing on 32-bit kernels c9189693db47a buffer: avoid tail commit walk for uptodate folios dbfecc8a6631c bpf: Disable preemption in __bpf_get_stack 6886642414f59 bpf, x86: Fix per-CPU address resolution into an extended register 49dcefa83c8ab bnxt_en: Write doorbell when linearizing skb fails 4d36e38e48340 bnx2x: fix double free in bnx2x_init_firmware() error path c21fa79301d7d Bluetooth: eir: Fix OOB read in eir_get_service_data() f609eac02d110 Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728 bce588b4ca081 Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU aa7b93fe98ba7 Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU ce76ca5fb2794 block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead() 84858671842ae auxdisplay: charlcd: cancel backlight work on registration failure c2e3dccd68706 ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes fdc0a5e2cbace ARM: 9477/1: Disable broken eBPF JIT on the Risc PC 87d07aa5d38b6 alpha: marvel: Fix lock ordering in init_io7_irqs() 9e1eefc01912c alpha: marvel: Fix irq_set_status_flags to use correct IRQ number 2fd984c44e3e4 alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write() 6d4ed2fd022bc ACPI: pfr_update: fix stack buffer overflow in query_capability() 452eb28e03015 ACPI: APEI: GHES: fix ARM section length accounting after header b7476b29b6961 ACPI: APEI: Fix ERST timeout unit conversion c735dbce7ad03 acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks 9ad8821573a36 accel/rocket: Fix error path handling in rocket_job_run() 3043230296653 accel/rocket: initialize job domain before cleanup paths c1a5bf1b6e1d5 accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() a3c65af20cceb hugetlb: only adjust reservation during unmapping if mapcount is 0 4e019e5e247bf hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device 137c61a6cfd96 fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration 0c3f4544ff387 forcedeth: fix off-by-one when saving/restoring non-PCI config space 466a8af0dee2c fbdev: uvesafb: unregister connector callback on init failure 3bcab9b21f71d fbdev: ssd1307fb: defer I2C transfers from damage callbacks 3c1b5809615c3 fbdev: pvr2fb: correct user pointer annotation and sentinel initializer 76818e81cfcae fbdev: omapfb: panel-dsi-cm: initialize lock before registering display 2f66f8ceefc25 fat: restore original value when fat_ent_write failed 66aa9a9e6481b fanotify: fix use-after-free of file range info 92895a14329cc efivarfs: Rate limit statfs() handler ce568f6e025df ecryptfs: show filename encryption options 9319706316a8e ecryptfs: release message context on send failure b31da1ecf1392 ecryptfs: reject too-small tag 70 packets 14cb36a500a5a ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet e5d254e654f23 ecryptfs: pass packet set buffer size to parser 0d9636ecba34b ecryptfs: hold msg ctx list lock when cleaning daemon queue c1bc956a615d0 ecryptfs: fix tag 11 packet exact-fit size check 98b890563424a eCryptfs: bound the packet-length peek to the user buffer 7ccb94901f38a fs/ntfs3: bound page_lcns[] index by the log record 376ee45659a4b fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() 2d94ffc9d7b5b fs/ntfs3: validate dirty page table on log replay 5333e18e6b425 eventfs: Initialize ei->children and ei->list in init_ei() b2301bdb4b3ed HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown 99f3e197920df HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown 72706b44b6656 HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer 6fcefe71aeb52 HID: intel-thc-hid: intel-quickspi: validate report size before copy 127de5919820f HID: mcp2221: validate report size in mcp2221_raw_event() c99ba6c234d4d HID: mcp2221: stop device IO before hid_hw_stop 01d9874e84d3a HID: universal-pidff: stop the device when force-feedback init fails 114a58640aaf3 HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind f3f37b937a6ea HID: sensor: custom: Fix field sysfs group cleanup on failure da00eac19feef HID: roccat: free buffered reports when destroying device 471f4a939c66d HID: picolcd: clamp eeprom debugfs read to bytes actually received 79465a30050da HID: corsair-void: Check size of status and firmware events before reading them e78973fe3ef59 HID: apple: preserve keyboard backlight across T2 resume 846f0709559b9 smb: client: harden DFS cache against invalid target hints 17a1922ada873 smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV 1f824f61d1df5 smb: client: fix ALIGN() overflow in symlink_data() error context loop 9ab46a13798a6 smb: client: clear ce->tgthint in free_tgts() 8b9b10fe5b8b4 cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC c2a0dcb5a7a15 cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 4f18c9e7ee464 cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() 636a99bab36ba audit: avoid dropping live tree ref on fsnotify rule autoremove 25128202a8df5 btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag f42efd634c0ae btrfs: fix extent map leak in NOCOW direct I/O write 8a64baeb5bbb7 btrfs: drop recovered reloc root refs on recovery failure ec32015a955c5 ceph: fix leaked inode reference on writeback abort at umount 37d6edb2f03b2 ceph: do not repeat ceph_trim_dentries() if no progress possible 1dd356310b166 ceph: bound xattr value length in __build_xattrs() 58c2d3e954c13 ceph: bound num_export_targets array for mds info v2/v3 c37db86d2b5e9 ceph: bound MDSCapAuth path and fs_name decode in handle_session() 06fb5e623cdc2 ceph: bound copied dentry name length in NFS export get_name 4d298880f82c4 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode fe46746087b5b ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock 00562ccd4e88d libceph: reject buckets with mismatched CRUSH ids 2571b35883268 libceph: validate OSD extent maps before cursor advance b413ec5b23e34 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup 4804c58f73a80 NFSD: Prevent lock owner use-after-free during client teardown b56d2c5f01cdd nfsd: revoke copy-notify stateids before dropping their reference dbc11a12aa545 nfsd: reject reclaim LOCK after RECLAIM_COMPLETE ad02d095439f8 nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE 54e02f5e32c52 nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops 4ae5d7490ae6a nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() b57bd8cb739cb nfsd: initialize DRC hash table before registering shrinker a4d7fedcaaf33 nfsd: initialize copy-notify stateid before publishing it 763c0bad87236 nfsd: hold rcu across localio cmpxchg retry b3bff820d068e nfsd: gate nfs3 setacl by argp->mask f951b22dbeec4 nfsd: gate nfs2 setacl by argp->mask 41ebca28e17f8 nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo 0380129b1373c nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget 4106d7a6aaf1e nfsd: fix version mismatch loops in nfsd_acl_init_request() 9b4e5e9ba5ae1 nfsd: fix stale s2s_cp_stateids IDR entry for async COPY 2ebbf4e3e9cf5 nfsd: fix reply size estimate for GET_DIR_DELEGATION cf081015a0d1b nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure 3c5119b799a7f nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs 424d5c95108a4 nfsd: fix nfsd_file leak on inter-server COPY setup failure 360e1b9e3f316 nfsd: fix netlink dumpit error handling for rpc_status_get 65c79d9bb3717 nfsd: fix FL_SLEEP being set unconditionally for all LOCK types c1ae0f973bcba nfsd: fix dentry ref leak on V4ROOT export filehandle lookup a631a26a8777b nfsd: fix cpntf publish race in nfs4_init_cp_state 607a56fea772c nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke 00843074d9b84 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry 72d40b103bb03 nfsd: don't free session slots that are still in use 6703199f4d7e7 nfsd: defer vfree of compound ops to fix rpc_status UAF 631b7d5dbbba8 nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper e879148867bd4 nfsd: clear opcnt on compound arg release to prevent OOB read b137930ee52e3 nfsd: clear CALLBACK_RUNNING on failed delegation recall queue b42dc26a14b4a nfsd: check client ownership when cancelling a copy-notify stateid 311f7d9266309 nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref 1aea0482b98ec nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry bff024551a713 nfsd: add filehandle match check to nfsd4_delegreturn() 533964d420d38 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() 895a485cd3758 nfsd: validate symlink target length in NFSv4 CREATE 2aca70c18c5f5 nfsd: validate sockaddr length per family in listener_set 7e7b93da7fa2e nfsd: validate nseconds in TIME_DELEG decode paths 7ff8d6363cfff nfsd: size fh_verify server sockaddr slot by xpt_locallen 1e4795766719f nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations 8277d4a11ae2c nfsd: sample writeback error cursor before async COPY loop fc83f30731dd2 nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types 591134e059e34 nfsd: Reset write verifier when async COPY writeback fails 467d56fd3ff57 nfsd: release path refs on follow_down() error f164eb52b6f3c nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown dc803d46a8b90 pNFS: Fix EBUSY check in pnfs_layout_need_return 36e3f13bf0728 NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path 59baf45a06435 nfsd: guard nfsd_serv deref in nfsd_file_net_dispose 7ef182a8fe9c1 NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check 4ed8d2317aef2 NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock 75d13317f163a NFSD: Fix off-by-one in DRC bucket pruning limit e547b06234f88 NFSD: Encode only the status in NFS-ACL v2 GETACL error replies d8352da196349 NFSD: check truncate permission under inode lock f3adf16435173 NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails 5215e734bf7cb NFS/localio: fix ref leak on nfs_uuid_add_file failure 344ae0e232d4f zsmalloc: account for handle size in class lookup 923578d0f0d07 zram: validate deflate params a1dc246f98bb9 ubifs: fix out-of-bounds read in signature length check 14afe18655c09 phy: rockchip-samsung-dcphy: fix out-of-range max_register e892f05f1f790 PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() 9253cfc5a85be of: fix out-of-bounds read in of_alias_scan() stem parser 448636c745a3f nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation 8c14472431e27 media: vicodec: fix out-of-bounds write in FWHT encoder 0c260d3f97e52 media: cec: stm32: prevent out-of-bounds write on RX overflow 7d658da725ea8 lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() 9f43499ce6458 HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature 827ec385458ad fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write 34e88f5361464 usb: gadget: f_fs: Prevent deadlock during ep0 read loop 9897b7da8c0ad usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() dbe2762ae8e54 usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() 6bcd9ee6ad698 usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() a15c2acd30834 usb: gadget: midi2: remove default configfs groups on teardown 64005cf3e897e usb: gadget: snps_udc_plat: clean up PHY on probe deferral 4e747c864a885 usb: gadget: u_audio: Fix use-after-free on sound card disconnect 14fa29f3be066 usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion ebb840d982a61 usb: typec: thunderbolt: Disable work before freeing tbt on remove d793bd8422e78 usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() 12414bbd3e3f3 USB: phy: fsl-usb: fix missing static keywords 51a311eb97e91 usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed 448e95c0f3eaa usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition 316abfe39dce7 usb: dwc2: gadget: Exit partial power down state when changing USB pull-up 78f5c6e6aef9a staging: greybus: hid: fix SET_REPORT return value 28b932202fcdb serial: imx: serialize imx_uart_ports[] lifetime aad08b5f67d2a Revert "media: v4l2-dev: fix error handling in __video_register_device()" e6e925cc1f806 rapidio: mport_cdev: fix use-after-free in dma_req_free() c3d4be91c6fce powerpc/powermac: fix OF node refcount 29e634a18957a misc: nsm: bound the device-reported response length ba69d892ff4e4 device property: fix infinite loop in fwnode_for_each_child_node() 4cd24873ab9fd cdx: Fix double free when sysfs file creation fails b1a49c22de01f tracing: Fix use-after-free with same-name named triggers ddbe921ed16a0 tracing: Fix use-after-free in trace_pipe read on sub-buffer order change cdb6fb6cf1a7a tracing: Fix logged instance name on creation failure adadf4192f700 tracing: Fix crash passing ERR_PTR to kthread_stop() 25a0758cf6bdb tracing/user_events: Clear copied tracing state before fork duplication b503a61d5d392 hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() 9b51dcb4f2305 x86/tdx: Fix zero-extension for 32-bit port I/O c4a2215487081 x86/tdx: Fix off-by-one in port I/O handling b9ae969e6f1e3 x86/locking: Use sfence for wmb() if SSE is available 08b4cdef3c2ef x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg() 968eea4659420 tools/compiler: match glibc 2.42 definition of __attribute_const__ d4bf3a74e2bae mm: vmscan: fix node reclaim ignoring swappiness parameter 461d23368f296 mm: page_alloc: fix non-movable reclaim storm in defrag_mode d435ba3c21a02 mm: page_alloc: move capture_control to the page allocator 0df04778ea14a mm: page_alloc: __GFP_FS lockdep annotation for direct compaction b3d4b65085ef5 mm: mempolicy: fix automatic numa balancing for shmem 5d866086d5f8d mm: memcontrol: update state_local when flushing NMI stats 95d87030cae77 mm: memcg: stop reclaim when a limit update is superseded 680b93894ddf6 mm: memcg-v1: fix memsw and TCP failcnt accounting d0943afb5ed8b mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings 295f5a61d3aea mm: compaction: support non-movable compaction for pageblock requests ef765a2e4f579 mm/zswap: fix global shrinker when memory cgroup is disabled 3fd5023998630 mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() 895cd4ecbb2e0 mm/pagewalk: fix stale walk->action escaping walk_pmd_range() 45489d4f95802 mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn 5dc0daff0341c mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() 3fc8044251de2 mm/kmemleak: avoid soft lockup when scanning task stacks 2cfa9ae90813b mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios() d423737dca23f mm, swap: ratelimit bad swap entry reports f2c14f4d427d1 include/linux/list.h: mark list_add and __list_add as __always_inline 28069434aef66 apparmor: fix out-of-bounds write when null terminating a label vec 587a6a92b93ec apparmor: fix cred UAF caused by begin_current_label_crit_section() 753c978f2400f KEYS: trusted: Fix TPM teardown ordering 0a10989de6103 rust: kernel: list: fix incorrect pop_back example comment 138722d631acf rust: bug: skip arch-specific asm in `testlib` builds 2bf5e8f7c9bf4 timers/itimer: Zero-init old itimerval before copy to userspace e6da8a0f39769 powerpc/pseries/iommu: switch to Default DMA window during kdump c03114634d342 fs: fix user path of nested backing files bf38be01d43c4 clocksource/drivers/timer-sun4i: Advertise a real minimum delta d53c29a89a15e clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path 312f85fdd029b alpha: don't leak hardware-fabricated FP exception bits to user space c25b2aa077d5b rust: time: fix as_micros_ceil() rounding near i64::MAX 7d00a3ff6244f alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally 4628e40c9ca79 drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile 7d860bed13369 drm/amd/display: hide Apple Studio Display secondary tile c6b915f0df311 drm/amd/display: Refactor amdgpu_dm_connector_detect (v2) a1fa3d1197cc2 drm/amd/display: Skip PHY SSC reduction on some 8K panels d5c9d19b0ff2f netfs: Fix missing locking around retry adding new subreqs ce493f9261cd3 platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int() 2ab18de5ebb11 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths 24ebaf6676ae4 nsfs: tighten permission checks for handle opening ea150ffa9fc9f bpf: Fix incorrect pruning due to atomic fetch precision tracking 5d562153b4719 ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS a8bbb2a60513b fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free 5fc3d921512d3 wifi: ath11k: fix memory leaks in beacon template setup 8527ac1bce87a wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() c79ef3342632e perf/x86/intel/uncore: Fix die ID init and look up bugs 1c732c6b94f0f Linux 6.18.49 5f08c45bdcfd2 usb: usbfs: fix use-after-free of usb_device in usbdev_release() 22edb67861272 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb b4cb8081cf80f USB: c67x00: fix use-after-free in c67x00_add_iso_urb() 683df50fff0f5 USB: serial: spcp8x5: drop broken carrier detect support 2ef5560387f2c USB: serial: option: fix slab OOB read in interrupt URB callback 6d3e202670b81 ALSA: usb-audio: Complete cleanup after system-resume errors 91919b3b99ab7 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() 7eb02825b3684 usb: core: Strengthen error handling in hub_hub_status() d80b946804674 usb: core: Add lock to usb_wakeup_notification() 935eeba276012 KVM: s390: vsie: zero stale crypto bits 545a6b9c91e2b crypto: qce - Remove unsafe/deprecated algorithms 182f16a20d329 crypto: mxs-dcp - fix source scatterlist length access 2f65718b9c109 crypto: qce - fix CCM AAD buffer underallocation 731a5b6fb4c17 crypto: krb5 - use kfree_sensitive() for derived key buffers 302ecd1106065 crypto: atmel-tdes - use scatterlist length before DMA mapping 4c00183209420 crypto: qcom-rng - Allow zero as a random number 14d9ee8286460 crypto: qcom-rng - Remove crypto_rng interface 070b73019a534 crypto: qcom-rng - Enable clock in hwrng case 5545de5050cbc crypto: virtio - bound the akcipher result length e90bc78125cd7 kunit: irq: Continue increasing hrtimer interval for longer 34f3c35dd13a3 mm/swap: reject swapon() on filesystem-level encrypted files 6fa88d11983c6 netfilter: nf_tables: don't queue packet path object notifications 07ee91e6b7b0a netfilter: nft_set_pipapo_avx2: add missing vzeroupper a8820c8a77183 vxlan: keep the last remote linked during FDB flush 916ec741e65af batman-adv: reject unrepresentable multicast TVLV offsets 3e4476e58343f ipv6: seg6: clear IPv4 control block on IPIP decapsulation c069f29da7232 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context 50229d334558a xfrm: bound nat keepalive state collection cf67361e78dca xfrm: fix xfrm_state_construct() auth-trunc leak 6733ae71268a2 xfrm: ah6: validate routing header segments_left 5c86c895d1cac xfrm: avoid lock inversion in nat keepalive work 328e40aa774b4 xfrm: drop ESP-in-TCP packets with no ingress device 24efebecf415b xfrm: espintcp: fix UAF during close 73fde8fe4469f net/tcp-ao: fix use-after-free of current_key on reconnect to another peer 70051a57786d5 tcp: fix AO info use-after-free in tcp_ao_connect_init() 4527747760239 net/tcp: fix TCP-AO key deletion in VRFs b5d1534db32af x86/CPU/AMD: Carve out a Zen5 models range 3d950e98f74af gtp: serialize PDP context updates fadbc1ed2a872 tls: device: fix out-of-bounds write in tls_append_frag() 0b0a668febb62 KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y 9a45e7b0b140a KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable a3d45c2d645c6 KVM: SEV: Extract loading of guest-provided VMSA to a separate helper 2de20fea62043 KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests dd1638c95163d KVM: SEV: Drop FOLL_WRITE for encrypted region registration 85aa61fedcb4e usb: gadget: f_tcm: keep port count until LUN teardown completes 3f6face69034f usb: usbtest: disable dynamic ID support 776e85fda752f fuse: fix invalidate lock leak on open O_TRUNC DAX failure 1758730d9eaa3 fuse: fix invalidate lock leak on setattr writeback failure 0f127d522dbcb xhci: dbgtty: Fix unregister on tty_alloc_driver() failure 0d0faf3cc44c4 xhci: dbgtty: Fix unregister on tty_register_driver() failure 45dbddc389c59 usb: xhci: Handle USB3 port events when there is one roothub 56f20a406cc3b usb: xhci: Handle bogus TRB pointers in Missed Service Error events 9786c42df8efb accessibility: speakup: unregister tty ldisc on later init failures 8ec7271e05df7 fpga: dfl: fme: add error handling 6106fb7962a00 ksmbd: harden file lifetime during session teardown a8e1f970f9040 HID: ft260: fix stack-use-after-return write in I2C read race 30c37ac21a458 HID: ft260: validate i2c input report length 8b5debb6252cd HID: asus: fix missing hid_is_usb() check d0754db7883c8 HID: asus: simplify RGB init sequence 70589b0c005db HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() e22f4494cc948 io_uring: defer eventfd signaling when queued from a wakeup handler 0bcec5dda029c io_uring/rsrc: improve regbuf iov validation e973a371d35a2 io_uring: simplify IORING_SETUP_DEFER_TASKRUN && !SQPOLL check 2b7c6b90ce801 io_uring/futex: only mark private futex waits as inflight b61ebb2826ca1 powerpc/hv-gpci: fix preempt count leak in sysfs show paths f2192741bdfc7 veth: fix OOB txq access in veth_poll() with asymmetric queue counts 34aef83af724a selinux: switch two allocations to use kzalloc_objs() caacbfb367210 ASoC: nau8821: Cancel pending work before suspend 0599aa23734c4 riscv: Fix register corruption from uninitialized cregs on error 85dc711f742b1 bpf: Fix use-after-free in offloaded map/prog info fill 13d20517bee1c ASoC: nau8821: Cancel delayed work on component remove 9ebaeeb6c2d42 selinux: require a class's permission values to cover its permission count dfc59a062c386 selinux: reject a permission value exceeding the class permission count 42c5747a9f839 selinux: more strict policy parsing 4ac3cc8a14db6 selinux: use u16 for security classes 71ecdc1ba07fd Revert "selinux: reject a permission value exceeding the class permission count" 64561afb42d83 nvme-tcp: fix usage of page_frag_cache c0a9bd5fca0b5 KVM: x86/mmu: Check write tracking in all address spaces 8be5f23ae9490 drm/xe/guc_ads: use uncached mapping for UM queue BO a65b52f6cdc92 drm/xe/guc_ads: allocate UM queues in VRAM on dGFX af2d3f6f29b07 drm/xe/guc_ads: allocate UM queues in a separate BO bdf5deccfbf9f RDMA/rxe: Fix OOB in free_rd_atomic_resources() ffa4f0be69656 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 3f4893ae361ec1ba8fe7829786dd0db69d1769ef) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 55f3fe8907c..d4ca18a7b20 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "c82ff0cbda2a00b9073e06c9fe4ba550c9056d45" -SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" +SRCREV_machine ?= "ed7481e8a1df4a3417915acd6bef5a72d6fa71bb" +SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.48" +LINUX_VERSION ?= "6.18.50" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 3b1342d6774..56a3d18ee5b 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.48" +LINUX_VERSION ?= "6.18.50" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" +SRCREV_machine ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 80301434799..719c1fa51a8 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "0f778c0a178fdc50063c212b5320b1f082f83f1a" -SRCREV_machine:qemuarm64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_machine:qemuloongarch64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemuarm ?= "dbe5ee845060d0b8ddf934a2e3d96627fdb1bd81" +SRCREV_machine:qemuarm64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemuloongarch64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_machine:qemuriscv64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_machine:qemuriscv32 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_machine:qemux86 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_machine:qemux86-64 ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" +SRCREV_machine:qemuppc ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemuriscv64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemuriscv32 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemux86 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemux86-64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "ad9d5e451874e64e4e51093f3c9c6ca4426d3b0a" -SRCREV_meta ?= "c8484925c85ec1e6510c75d9e1b36e01d6e2e904" +SRCREV_machine ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "5bbb9c9f8f808710e2123f2b30f0d61d7d698f52" +SRCREV_machine:class-devupstream ?= "7cfc41f8e80f11ffa8382ed1a505154ceffb79c7" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.48" +LINUX_VERSION ?= "6.18.50" PV = "${LINUX_VERSION}+git" From patchwork Sun Sep 27 07:43:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99313 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 677F8CA5FA1 for ; Sun, 27 Sep 2026 07:44:08 +0000 (UTC) Received: from mail-wr2-f35.google.com (mail-wr2-f35.google.com [74.125.225.99]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.32865.1790495042504978410 for ; Sun, 27 Sep 2026 00:44:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=amFEDwLa; spf=pass (domain: smile.fr, ip: 74.125.225.99, mailfrom: yoann.congal@smile.fr) Received: by mail-wr2-f35.google.com with SMTP id ffacd0b85a97d-4887f6cf16bso1182766f8f.0 for ; Sun, 27 Sep 2026 00:44:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495041; x=1791099841; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=2xay+aHKIbBgQqlQ24JH+yjKQ7mYaiBL+m7p7dVDx9U=; b=amFEDwLaFFb0xlY4HKMEev+Ep4th5mWpjdyqxGXzJ7tl2qMk8bioLhw76zSg+acv+y a5jVdGZ9B20XJOX+K3Oe0WqdaBn00PB6qCVtC37gtGGvVjAlFK0gtYD+BraprHNu+fvC tpe62+YufmYqEOBPJKDqDO/W/prqwWyipweBY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495041; x=1791099841; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=2xay+aHKIbBgQqlQ24JH+yjKQ7mYaiBL+m7p7dVDx9U=; b=OvSPxBUBe5eWLAyDopMrjhN7Axguu2TpFAPyiPcZdgVExl0rnFTYUy8u+2PR38zfyf kGikMSyfMki+mj6LGhwDHe2zisZH27IAk/ueov2IHNkacByXIIKt0D/hKza3n0xVI4z/ jpg7SvB2FX7I4S61trwcHezIwImmV6NtL1NfyPdeVrl+p0jxG2MXGyB20jx8IDUR/qqP gkbtf1gb85ePd0ViUUEjTLu+WYgNm1sOX8ipdbewjP0gTxOd7o5zAC0PEiPAYIRF+d3A 6RWwU7r1ljeYOyxVFAWN8myuusAvDJD3aAZKLf6JBhn/NpbYzTmq+eDH+Xd0DhmiUDBE CN9g== X-Gm-Message-State: AFq9FYKpsqImlsmxsqYlyaCD1OXc+cPphRoWW5ibYTF8HkM0UGHbkKwS lDSOUHRXUY9jA3odk1uCj3EdpFHC8tNVGQGQ73yIF3scJVRUk+yGwdqQLE71/HUJEoVQp5bb/CU fuoerw+Y= X-Gm-Gg: AYBFou3m0WXhWYURXK/sEMtF+OeyiLgONgflJ4zF76lv3hO+VRgmn1C4Sar++2OBPCX nXuFdPjRiM2IIwaIQDutEKVts1ajx4OhtskG/KIhLR0mpY076eldnUEFpm51A4s7P9b0WzxMkHe hFuxQPfPWb8c321WbsJdXX+GFT8FV1iGQ/TK3AWzvBHMNlhhbaRY1PWv2DwWop2dX3kNVRcCk9B EpLKh97cUg2/1M2G+9Ea6UASi73yN52wgWresCB8WoOjod/TDHjgPrgiD6qWVRyqVu3nncAOwY+ Kl/gBtp57lA10NA1EpGu9v9acddMbDEgj74njNpJFMrpLpVnB/F0582dX3zVILl8U7ASI3PP1aK HWfGPC5apfCpEVgqc080OUHjZ82guxnxb/yLZvu+SVYTahC9WMmB+JC+cIHxEXIu8ANToXFFE/x nTj5U+E+z/SByQ2jeRC46xQIeI6YIioKS0SV5o7f8DRIl8Uk4KgzgED/nEKriXDGwAWlkPKQn6c UMigg+Gz0O16moJX8J/1Dr54JG68+sMP3mHcZ7xCE/EBaZHzjiQQecbBnsUXN/0+5ezghXGOQ== X-Received: by 2002:adf:e005:0:20b0:488:8212:5d73 with SMTP id ffacd0b85a97d-48882125f39mr7018821f8f.31.1790495039036; Sun, 27 Sep 2026 00:43:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:57 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 27/28] linux-yocto/6.18: update to v6.18.52 Date: Sun, 27 Sep 2026 09:43:18 +0200 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246678 From: Bruce Ashfield Updating linux-yocto/6.18 to the latest korg -stable release that comprises the following commits: 8f3741e6feb04 Linux 6.18.52 0d0c637410df6 wifi: mt76: fix airoha_npu dependency tracking 637e0ea73f690 staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction 7d4024037ee30 staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc 7bca33d6f6e00 pinctrl: airoha: an7583: add missed gpio22 pin group 9aa021b63ab73 ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver() 4ba887b2bacc8 ACPI: processor: idle: Remove redundant static variable and rename cstate check function e1cfb85ab258c ACPI: processor: idle: Move max_cstate update out of the loop fcc577939931a ACPI: processor: idle: Remove redundant cstate check in acpi_processor_power_init 8ddc1da773644 cpufreq/amd-pstate: Allow writes to dynamic_epp when state isn't modified 9c178eba1542a cpufreq/amd-pstate: Use "epp_default_dc" as default when dynamic_epp is disabled bf897a1fa96cb cpufreq/amd-pstate: Add support for raw EPP writes b461ae97f2e44 cpufreq/amd-pstate: Add static asserts for EPP indices 8f8db9af24b9a cpufreq/amd-pstate: Fix some whitespace issues a3d24aed0a3e7 io_uring/waitid: fix KCSAN warning on io_waitid->head 934ffdd1cdef2 io_uring/waitid: use io_waitid_remove_wq() consistently 798283cd0fe7b net/sched: fq: clamp quantum and initial_quantum in change path 9289c94fcfe04 Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array 2151b2bcf6fce tcp: reject non zerocopy devmem tx 384907f29dd1e ipmr: Add __rcu to netns_ipv4.mrt. 7708973e268c4 ipmr: Call ipmr_fib_lookup() under RCU. 5029156b99bd9 erofs: fix EFSCORRUPTED on multi-algorithm images in z_erofs_map_sanity_check() a295f239dee45 erofs: relax sanity check for tail pclusters due to ztailpacking bf8601feeb469 block: fix merging data-less bios 43a4c2afcb5ab blk-mq-dma: always initialize dma state f54f709bfb5e4 block: save page offset gaps in cloned bio 0268313b5de3e integrity: Eliminate weak definition of arch_get_secureboot() 60aee9cbb82e0 apparmor: fix kernel-doc comments for inview caf1e44e672b5 pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function 0ca274a45eaea pinctrl: airoha: Fix AIROHA_PINCTRL_CONFS_DRIVE_E2 in an7583_pinctrl_match_data 2e7c3c433fd79 pinctrl: airoha: an7583: add missed gpio32 pin group 46bae3189cf5c pinctrl: airoha: an7583: fix misprint in gpio19 pinconf 591424f9f5d51 pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin function cf2e698957b65 pinctrl: airoha: an7583: fix gpio21 pin group 6d0bcb2153128 pinctrl: airoha: an7583: fix phy1_led1 pin function 5331bf0d5ca05 pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin function fc00a596268a0 phy: renesas: rcar-gen3-usb2: add regulator dependency e97bd4417010c perf annotate: Fix build with NO_SLANG=1 fe44ae31ca78a wifi: nl80211: fix UHR capability validation 3ca32b70e825f wifi: mt76: npu: Add missing rx_token_size initialization b0af766d64bc2 wifi: mt76: restrict NPU/PPE active checks to MMIO devices 15a9acc5e6553 s390/kexec: Disable stack protector in s390_reset_system() adf8f940e450d selftests: vDSO: getrandom: Fix path to s390 chacha implementation dffea40a832bb cpufreq/amd-pstate: Fix setting EPP in performance mode 3b4b39f8bfb9b cpufreq/amd-pstate: Add POWER_SUPPLY select for dynamic EPP c6584e98b60ee cpufreq/amd-pstate: Grab "amd_pstate_driver_lock" when toggling dynamic_epp eee67e91751e0 cpufreq/amd-pstate: Return -ENOMEM on failure to allocate profile_name c9d79e27eaefb cpufreq/amd-pstate: Reorder notifier unregistration and floor perf reset 70c8c8b50d80f cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks be5d0964da97f usb: ucsi: huawei_gaokun: move typec_altmode off stack 65d97c3d9060f serial: 8250: Ignore flow control on suspend/resume with no_console_suspend a79848859b1a8 platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL bd8946ddbe9a3 perf tests kvm: Avoid leaving perf.data.guest file around 3641a3aed2ecc tracing: Move d_max_latency out of CONFIG_FSNOTIFY protection 3e3fb150abad9 mtd: rawnand: pl353: Fix debug prints 9988c1c9e0d1c dm-integrity: fix buffer overflow with keyed discard e54be9aa503a0 net/sched: sch_htb: limit htb_classify inner-class filter hops b8f08a94b2a4a tcp: fix corruption of urgent data on multi-segment retransmit ff7f77a234f7b usb: atm: usbatm: fix invalid ci_range initialization 1f9639caeece7 net: fec: only stop PTP if it was initialized ddbc5dc5a2e29 slip: remove slip_hangup() to fix use-after-free in slip_receive_buf() 1a5c26e586481 net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup 2ea42936416b2 net: stmmac: restore NET_IP_ALIGN in the RX DMA offset 6257ec22f6173 net: stmmac: selftests: Account for the UC filter list for filtering tests f09abff67d1f2 net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering edce4b5a76dd7 net: stmmac: dwmac4: Account for the primary MAC address for UC filtering f64902e8ae1fa net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering 57f598f312f91 net: stmmac: selftests: Check multiple MMC counters 66cfb39635529 net: airoha: npu: fix missing streaming DMA mask 99036078abd96 selftests/arm64: Fix MTE prctl TAP plan d3bb129dad152 selftests/arm64: Treat KSM merge_across_nodes as optional 1c6940784c556 selftests/arm64: Print missing MTE TAP headers 2f0c97b1a32fb ALSA: control: Don't add invalid kcontrols to LED layer 67dd5a6c449b4 netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited() 3b1066a859dbb netfilter: xt_HL: add pr_fmt and checkentry validation d5497644329d3 netfilter: nf_tables: move hardware offload step after building the chain blob 0e5ed3b98d1d8 virtio-net: Ensure that TCP packets don't overflow gso_segs 023f06c98e031 drm/xe/xe_gt_idle: Add CCS to the powergating info print c826e980f2767 net: stmmac: selftests: Pass the IP proto mask in the TC selftest 30be8c9d598f3 net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs 84180988a455f net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure 557599edb522a net: ethernet: sun4i-emac: Fix IRQ error handling 626614df9080d samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify 8de8e5476be39 samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify 6d1c6f228854a libceph: validate banner payload length 792bfe803228c ceph: revalidate ki_pos for O_APPEND writes after cap acquisition 33b3dc47202d0 ceph: Fix ERR_PTR(0) in ceph_mkdir() 10a36512c21f8 ASoC: dapm: Fix off-by-one check on the second enum channel 5449f715f24e8 apparmor: policy_int make sure list heads are initialized before fail path 59fba1d249dce apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init d48197cbd5d34 crypto: acomp - allocate async request context when cloning fdc992f4bc45f tpm: st33zp24: Validate locality read result 14feaa498c20c tpm: st33zp24: Return zero on status read failure 96bc345a3f175 net/sched: sch_teql: restore skb->dev on the slave failure path aeb8196ecb951 net/sched: sfq: clamp quantum to avoid signed overflow soft lockup 99770b5d8e0e1 net/sched: hhf: clamp quantum before hhf_change() to avoid overflow 044fa2498bbc2 net/sched: fq_pie: clamp default quantum to avoid signed overflow 7ca8a8717a9fe net/sched: sch_codel: clamp default mtu to avoid disabling CoDel dfb4b61db8869 net/sched: fq_codel: clamp default quantum and mtu f6b3e3848a5fc net/sched: fq: add overflow bounds to quantum and initial quantum 76c847e80d2b6 net: fix a resource leak in copy_net_ns() error handling path d1c084d4e9f03 net: core: check skb_frags_readable before uncloning in skb_copy_ubufs 1719865b20b22 net/sched: act_skbmod: fix length calculations and avoid invalid header warnings 3e07d284ef085 selftests/proc: make proc-maps-race work with READ_IMPLIES_EXEC 4e70c064213ef maple_tree: fix argument name in header 64ae85a3a29de maple_tree: catch race in mas_alloc_cyclic() 005343e0c3294 selftests/mm: skip COW tmpfile cases when fallocate() is unsupported 3d1b2d84b4909 cifs: fix clearing stats for fastest execution of each smb2 command b003d5b4e46ca octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup bf2b8130723ef net/rds: use wq_has_sleeper() in rds_cong_map_updated() d218ea7df6eba net/sched: act_ife: Only operate on Ethernet frames 936e33035d54d net/sched: add qstats_cpu_drop_inc() helper ab8e0164c0fee net: enetc: restore RX ring congestion mode after ring reconfiguration 276e747373170 octeontx2-af: Fix TL3/TL2 link config ENA clearing 7abe769e72c79 net: qualcomm: rmnet: restore skb->dev on deaggregated frames 42a139332ce81 octeontx2-vf: fix workqueue and netdev race in probe/remove 537e11a1700f6 octeontx2-af: fix NULL deref in NIX TM tree debugfs read path 7677eb2cbf2cc gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free 53a5b262d706b xsk: honor XDP_TX_METADATA in zero-copy path 5b913e87af4b2 xsk: align TX metadata layout across ABIs aeee917a4878a Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop a644b8df94966 Bluetooth: btnxpuart: Validate the FW dump header length 7b37556d7d801 Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path 566da1197d340 Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX 3818502f2f69d Bluetooth: btmtk: Do not discard the subsystem reset timeout f3465a143c87c Bluetooth: btmtk: Do not report success when subsys reset fails 9fc4fd78bc650 Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read() 5a2cb90e23587 Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support 61d5ddbd524c7 Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan c3f63610bceaa Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference 87276dc15b559 Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN 00a73ce437e27 arm64: process: Fix context switching MTE store-only tag check 4a888ccb33d0c arm64: ptdump: Make note_page_flush() range aware f365f36bbb5ac erofs: Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS default logic f30c8905abdae scsi: qla2xxx: Fix an loop timeout test aa17842bbccae Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition ff422b8597c28 syscore: Pass context data to callbacks f7914ff92e4aa net_sched: sch_fq: fix pacing delay underflow with pacing offload 9c5d7bdb29ef1 net: page_pool: Remove zone/policy GFP flags when allocating XArray entries b9838b655b708 net: libwx: fix concurrent bitmap overwrite in PTP setup a13a63558e5c8 net: txgbe: fix MISC interrupt unmasking in non-MSI-X mode and device shutdown 38fa06f9ccccc net: wangxun: introduce WX_STATE_DOWN to serialize device shutdown state 6bf50b58f40d0 net: wangxun: schedule hardware stats update in watchdog b1d311224479e net: wangxun: replace busy-wait reset flag with kernel mutex 71adad90236b1 net: txgbe: support RSC offload 80fd6d42f07ce net: txgbe: support RX desc merge mode 51fe3fe0ffec0 ptp: netc: fix period truncation and potential divide-by-zero in PEROUT 430afa27beb92 bnxt_en: Gate TPH enablement behind BNXT_SUPPORTS_QUEUE_API check 001ff5d8e68aa bnxt_en: Fix call to hardware monitoring event handler 012bebc861106 rtc: pcf85363: Add error checking to regmap calls in probe() 27f640cd92eeb NFSv4/pnfs: key the data server cache on the NFS version 3815b894b922e NFSv4.2: fix LAYOUTSTATS send buffer exhaustion 0879ea157acc1 net/smc: free pending qentry in smc_llc_flow_stop() before memset 0fb9a51376607 net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition 8b2d8c70b969b net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue 220cfdb17ff6a net: tcp: block mixing readable and unreadable frags 857681f6835d5 inetpeer: randomize RB-tree node comparison using SipHash c7f9740f7a1b2 ip6mr: plug drop_reason to ip6mr_cache_report() 38778f6abdbda ipmr: Free mr_table after RCU grace period. 65f87de5f3c3b net: change sock_queue_rcv_skb_reason() to return a drop_reason 84264cb4e541f ipmr: Remove RTNL in ipmr_rules_init() and ipmr_net_init(). 53eefb9db0b27 ipmr: Convert ipmr_net_exit_batch() to ->exit_rtnl(). b30f0801b9187 ipmr: Move unregister_netdevice_many() out of ipmr_free_table(). 4012a0656797d ipmr: Move unregister_netdevice_many() out of mroute_clean_tables(). 4be733a450c86 net: qlcnic: validate unified ROM sections before loading bf87e4c1e58a0 net: add missing ref_tracker_dir_exit() to net_passive_dec() f30cf8fd98722 ipv6: avoid divide by zero in rt6_multipath_rebalance b8f32b0804b4b netdevsim: update queue NAPI association on queue reset 9d7b6916d5f85 net: ipa: balance runtime PM reference on remove error 5a66873d04b0f forcedeth: stop the tx_timeout register dump past the requested window bcf88c039af86 net/mlx5: E-Switch, preserve max tx speed on vport state modification 38354e591e3ef net/mlx5: Move vport DOWN state check out of mlx5_query_vport_max_tx_speed() 55d18f3ead831 net/mlx5: Skip disabled vports when setting max TX speed 6f4adc05c788d RDMA/mlx5: Implement query_port_speed callback 9137881591f22 IB/core: Add query_port_speed verb 0864bab42677c IB/core: Add helper to convert port attributes to data rate 361dfb9322fdc net/mlx5: Add support for querying bond speed 70cd46d12d7cc net/mlx5: Handle port and vport speed change events in MPESW e59b430283455 net/mlx5: E-Switch, use state lock for vport state changes 99300ea5c4365 net/mlx5: Propagate LAG effective max_tx_speed to vports 409dc14183ad1 net/mlx5: Add max_tx_speed and its CAP bit to IFC 4d3fb6977248d net/mlx5: E-Switch, support eswitch inactive mode ed246bad28d4e net/mlx5: MPFS, add support for dynamic enable/disable 01677786ed4f0 devlink: Introduce switchdev_inactive eswitch mode ec750e1f82385 net: thunderbolt: Count delivered packets in rx_packets and rx_bytes ac2201b484822 net/sched: add get_fill_size callbacks for actions missing them c0444d7499f11 net: bridge: Reject descending VLAN tunnel ranges 214fb79b0379c xsk: fix NULL pointer dereference in __xsk_rcv() 4585691b28614 xsk: avoid double checking against rx queue being full 5f02599590a4e irqchip/irq-realtek-rtl: Use readl_be()/writel_be() instead of readl()/writel() 5aa7bbe0bac89 irqchip/irq-realtek-rtl: Add mask for interrupt handling 2aa9fcf31f387 irqchip/irq-realtek-rtl: Add interrupt data structure 421615e833d73 irqchip/irq-realtek-rtl: Split out parent setup code f7d818afcc225 irqchip/irq-realtek-rtl: Add multicore support a9be529935266 irqchip/irq-realtek-rtl: Add/simplify register helpers 94834742ef195 smb: server: remove unused DES crypto header 72a3e6e0c8248 smb: server: Remove obsolete "select CRYPTO_LIB_DES" from Kconfig file 392c985c6b03d ALSA: mtpav: shut down output timer before card teardown bfce0f324efaa spi: amlogic-spisg: Make sure clk_init_data is fully initialized 4d99a477e61fc RDMA/ucma: Allow path records to exactly fit the output buffer b15782627b656 ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup 735384a9dd599 ALSA: core: Add scoped cleanup helper for card references dca93566f0e20 irqchip/gic-v5: Use logical cpu 0 irs_data for dynamic IST allocation 265fdce1efb1b irqchip/gic-v5: Fix gicv5_init_common() error paths 76ed544059cae irqchip/gic-v5: Check for NULL LPI domain on domain teardown 099772e948cc7 irqchip/gic-v5: Synchronize CPU interface disable 8f7980033e9f7 clk: visconti: Make sure clk_init_data is fully initialized 58c368552f830 clk: ti: Make sure clk_init_data is fully initialized 41c2ccf0d740e prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator 589f8d44c9dca lib/interval_tree: fix allocation warning messages 5a8f18a7d3691 rtc: gamecube: check return value of devm_rtc_register_device() fdc4b500071a2 i2c: ocores: Disable clock on failed resume 38c6831fefde0 irqchip/renesas-rzg2l: Fix loss of interrupt 367dbc320b27d rtc: zynqmp: Return optional clock lookup errors dbaca07f78a82 cifs: remove dead size-update blocks in cifs_setattr_unix/nounix 442c5f1358ced smb: client: fix request buffer leak in smb2_new_read_req() 6fd823a8872dc rtc: spacemit: handle regmap_test_bits() error return 08a59c28c2bdb rtc: pcf8563: fix clock provider leak on unbind 28701b74c22d2 virtio: rtc: time out alarm requests 6ca752850de3b vdpa/mlx5: fix wrong list iterated in add_direct_chain error path 4d059e7af5e92 virtio_pci: fix wrong queue index for admin vq in intx path 4f723111a852b vhost/net: fix clear_user start address in VHOST_GET_FEATURES_ARRAY 6dd28e32f4d81 virtio_balloon: quiesce balloon work before device shutdown 808b1751540dd virtio_balloon: factor out virtballoon_quiesce() 0d7b20057d4fd virtio: add virtio_device_shutdown() helper 68b726b3a01fb vdpa_sim: fix cleanup after worker creation failure 8b3edaa10a303 virtio_balloon: disable indirect descriptors 5fe03b5257095 net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs() 4f80425ad5a06 bonding: initialize err for empty target lists 795e7b3a356e8 mlxbf-bootctl: fix the build error with FIELD_PREP() 2c09cadec116e platform/x86/amd/hsmp: Reject negative power cap writes in hwmon ace1ba5fca0ab platform/x86: hp-bioscfg: fix password encoding bounds check 4d35c6d698085 vsock: use sock_error() to consume sk_err after a failed connect 36e5fa009f98a vsock: don't check the listener's sk_err in vsock_accept() 06c95182234ae vsock: avoid timeout for non-blocking accept() with empty backlog df8f661b4f329 platform/x86: dell-wmi-sysman: Fix instance ID bounds 3e8fe6503d0c1 net/smc: hash socket only after full initialisation in smc_sk_init() 6ea95c886d703 8139cp: fix Rx and Tx not being disabled in cp_suspend 3e6b705bc162f vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() 5f22943cd2c84 ALSA: hda: Fix connection list comparison in proc output a5129155ca9fb fuse: check for NULL root inode in fuse_fill_super_submount 5559dd7888d2c soc: qcom: ubwc: Fix missing include aab1880058ac7 fs/ntfs3: validate ef->size covers the record's name and value 74a83aa05f730 fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() 389bd349ddbcf cuse: wait for pending RCU callbacks on module exit fdb9cd16f8b6e net: bridge: vlan: fix inverted default vlan notification a34d2e0bfb74a tls: fix RX desync on overlapping skbs f3b6834c13edd net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error daebc7064a1b4 vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes 4aed450adaee3 ipvs: fix integer overflow in ftp helper port/address parsing 448f505e19241 f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode 32ee27946f097 f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk} dd5d8f4a9c67f f2fs:Fix incomplete search range in f2fs_get_victim when f2fs_need_rand_seg is enabled 65702339b3e9f net: hsr: free learned nodes on device setup failure 54bc96aeee050 pppox: drain queued packets on channel handoff fb511bf117edd net: dsa: b53: fix error propagation from b53_fdb_dump() 292846223eadd net: kcm: Hold RCU read lock while running BPF parser 31fbed0b409a6 ionic: fix completion descriptor access with 2x desc size 3ec0225b9d750 ptp: netc: skip PEROUT disable if channel is not enabled 00f1000a644e8 drm/xe: tests: fix error message in xe_migrate_sanity_test() e794cdc5c369c hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed c0f208d8a5726 octeontx2-af: initialize lmac_bmap in rvu_mcs_set_lmac_bmap() ea7b35dcc9430 bpf, xdp: move offload check into dev_xdp_install() 9e5e2ccc51dfc clk: ti: mux: resolve parent clocks by DT index, not by name 9d4843f105125 clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() 4c067f5ffb469 nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3 d148a652d52fd NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease() 163c16e01f53f NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers 1e1c36b206c65 pnfs/blocklayout: Fix device leaks on parse failure 3f2387e8bfbc4 NFSv4: remove callback IDR entry on client allocation failure 4c59aca79da0e nfs: refactor pNFS functions using clear_and_wake_up_bit 8179b8a1d636b nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper b967a595fb735 smb/server: fix session leak in ksmbd_session_register() a4a307d149327 ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size a21597b5730bc ksmbd: disconnect on SMB3 decryption failure 2bdbe00454200 bpf: Reject negative optlen in cgroup getsockopt hook be98f92fc2446 m68k: nfcon: Do not call console_is_registered() in nfcon_device() fe91c3f64a738 bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks 64eec7314e289 erofs: fix unused pcluster_pools for higher page sizes 7cf561843ed0a lwt_bpf: Restore reserved headroom after xmit program a3d6e590268ee erofs: guard on-disk algorithm IDs against Z_EROFS_COMPRESSION_MAX ddb7ea4fd99bf erofs: fix interlaced ztailpacking pclusters 7f10dc9a7a496 erofs: error out obviously illegal extents in advance 169f6633d2a35 erofs: clean up encoded map flags 892048f595505 smb/server: preserve error status in smb2_handle_negotiate() b2d78c199dfd9 smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() 8461f27902727 smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() a41a98ee16ae0 ksmbd: free preauth sessions on connection teardown 9f37719d6be82 ksmbd: do not advertise unimplemented CA support 0aa8f94bfd4d8 ksmbd: validate ipc response length before dereferencing its fields 7a98c3b903b10 smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer 84c2d8e807ac4 ksmbd: Do not skip lock checks for single-byte ranges db141a5ebcb04 hwmon: (emc1403) Drop hysteresis for low limit temperature c38cc41bb9dc2 hwmon: (emc1403) Rely on subsystem locking 86c1617b7d4b0 hwmon: (coretemp) Fix core_data leak on CPUs without PTS 00cce5e457cb6 apparmor: fix deadlock in complain-mode change_hat 4609e0e0be709 block: mtip32xx: synchronize ioctls with device removal 7e3e5273fc9ec ublk: reject non-power-of-2 zone sizes in SET_PARAMS 32456a8599557 null_blk: serialize configfs attribute updates with device setup 65cae82fd3c39 null_blk: serialize configfs attribute stores with the lock 3e35ad503386a null_blk: reject per-device queue resize for shared tag set b2437d37fcc31 null_blk: free zones array on device power-off 2b59484ac1e64 null_blk: free global tag_set on init error path d761be1b8f2bb null_blk: register configfs subsystem after creating default devices c7dea90c9b4ef null_blk: use DEFINE_MUTEX for the file-scope mutex cbc24bce70dfd mailbox: riscv-sbi-mpxy: validate RPMI notification lengths 1bd910aae6abd mailbox: pcc: Fix command timeout due to missed interrupt d255b6575650b mailbox: rockchip: disable pclk on probe failure and unbind 413b0b94d6d06 mailbox: qcom-cpucp: handle NULL data in send_data callback 8b8de6400c869 mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler eb05c19dfb36d perf dso: Replace assert with runtime check in dso__read_symbol() ac09bbbde1d49 perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() d3eaeabc08ae9 perf dso: Use stored fd error instead of stale errno in file_read() and file_size() dd9560c7b46e2 perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() b40859b325772 perf dso: Guard against errno==0 when dso__get_filename() returns NULL b8f8642178656 sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry 9d634e8f9e20a crypto: lskcipher - propagate errors from unaligned crypt 8c9b0a3a6d27f crypto: hisilicon/sec2 - fix CCM algorithm long packet failure efcfda20b7b7f selftests/sched_ext: Fix flaky ddsp failure tests on busy systems 6b019f0daa613 bpf: Fix pending_pos walk on 32-bit ring position wrap 15512c6b5dea7 ACPI: scan: fix bus ID cleanup on device_add() failures 04a43c321e106 ring-buffer: Remove trace_buffer::cpus 801ae90f8ce09 riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args 5a19c3fccc7e3 selftests/bpf: Use ping_command() for IPv6 pings in lwt_ip_encap 17a4dd3b0e6da selftests/bpf: Add tests to verify the fix of encapsulating VxLAN in lwt 54bff7c8e410a HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU d2f41287b51a3 ASoC: SOF: validate topology volume range before allocation e30214289e623 tracing: Have trace_event_update_all() only handle module that is loading 324cc98b71f0d HID: haptic: don't write an uninitialized value to unhandled usages a561012868ae3 ALSA: core: Fix use-after-free in snd_card_do_free() ce9a619c432b9 fs/ntfs3: reject out-of-range evcn in mi_enum_attr() dc6d85de7e265 fs/ntfs3: fix integer overflow in MFT cluster validation 863e10c4508cf bpf, arm64: Fix stack-passed arguments for indirect trampolines 424a9fc4876cc net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race e44b3b35bb153 scsi: ufs: core: Set task state before io_schedule_timeout() 2dbdd025b2281 scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers b6273cd8dc55f selftests/bpf: Fix for veristat file/prog filters processing d0a3729d464fc Squashfs: check block offset is not negative f8747d81aa6d3 ocfs2: fix circular locking dependency in ocfs2_init_acl() e35fa6eb4d2a3 ocfs2: validate DIO orphan slot during inode read c6c908f9b4edf ocfs2: validate orphan slot during inode read 508907eb8ea4a bpftool: Fix double close in map dump b000458cab958 x86/pkeys: Fix pkey_alloc() return value when pkeys are not supported 0ef3f5629051f selftests/cgroup: Preserve CPU hotplug write errors 210c193a9ef13 ALSA: seq: midi: Serialize input teardown with event_input 5c94ea1e64d3b ALSA: seq: midi: Optimize event_input locking with RCU 1f6d28c428cae clocksource/drivers/armada: Unwind timer clock on init failure fa0901c1c5551 clocksource/drivers/clps711x: Do not unmap clocksource MMIO 5d83f3faa3fb7 s390/debug: Fix deadlock during unregister e0cb87f438854 xenbus: Unregister reboot notifier on init failure ac7b10121140a power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address b3827f2e7b609 power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address 2f890ba8521f7 power: supply: bq27xxx: bq27520g4: fix REG_TTES address 7d181b48da3ff power: supply: bd99954: Drop bad register fields 3ab6f4eccbbf5 PCI/ASPM: Disable/restore ASPM on every function for multi-function devices a3040b9e90eb4 spi: img-spfi: don't disable runtime PM on DMA deferred probe 41849630000ec selftests/bpf: vmtest.sh: Preserve command quoting when running in the VM 5e41939ae4929 selftests: harness: Mark test fixture objects __maybe_unused d97cb1421c944 selftests: harness: Restore order of test functions e17ba89f8b78f kunit: tool: fix _list_tests filtering wrong variable when list has TAP prefix afc211a293999 perf build: Remove leftover feature tests for removed cxx and clang support 1e94e67483e01 super: fix dying superblock warning messages c01652db11c29 PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore d6037e42aa4dd firewire: core: fix memory leak in error path of build_tree() 4679bf3517cec firewire: core: validate parent port count before allocating nodes in build_tree() 861e6dd1f5939 firewire: core: consolidate port counting in build_tree() 6d2eba5cdb815 firewire: core: add KUnit tests for failure of tree building d7d075f17d612 firewire: core: add KUnit tests for successful tree building b5d3c30d03dbc firewire: core: add KUnit test skeleton for node tree 3216ff97d329a UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC 8b30628dfc2b2 ASoC: xilinx: formatter_pcm: fix stream_data leak on open error e065960366b55 mtd: ubi: Release device reference on busy detach e3f7e58189bc2 ubi: Fix rollback for explicit UBI device numbers e6d77e2ea55f1 UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs 34b180031021f UBI: Preserve torture flag when rescheduling failed erasures e06806a8f4cf2 ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready efc40977e7104 ASoC: pxa: Use devm_clk_get_optional() for extclk clock 99c554f193478 idpf: add missing cpu_to_le32 in idpf_tx_splitq_build_flow_desc f06d77436aab6 ice: acquire NVM lock around each flash read 42ff18e407e9c ice: refactor to use helpers c0fcef8e24a8b ice: clear the default forwarding VSI rule when releasing a VSI f5071e3ad4ca3 ice: fall back to SBQ when LL PHY timer interface times out 544e40805dbb6 RDMA/cma: Fix WARNING in res_to_rt 046425412529d RDMA/cxgb4: Free debugfs on registration failure 3c9c9b56fbaff dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal b1e8d40663997 ALSA: seq: Don't leak the extension cell pointer in the bounce payload 4f0483bbcdacc nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing 9cfe74542b544 nfc: digital: Do not dump a NULL response in command completion 7a8e0a7aef807 nfc: pn533: hold a reference to the request skb during send_frame 749a9048bf51a nfc: llcp: bound SNL TLV parsing to the skb and add length checks ba4c776af3dc2 nfc: nci: fix double completion race in nci_data_exchange_complete 156e65bd29307 nfc: llcp: read llcp_sock->local under the socket lock in getsockopt 8bf228fa02b1e nfc: llcp: avoid userspace overflow on invalid optlen 4b59f93cf4baa nvme: reject passthrough of driver-managed Set Features 736b7c6adc7a6 nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() 1fb1236312ee1 nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns() a2cf452ba7109 nvme-apple: Drop the PRP null check chicken bit 311e4e21ffd41 nvme-apple: Require page aligned buffers on the admin queue 5ee7e381b1bc8 nvme: Add a quirk for page aligned admin queue buffers 25c76e0c07f2a nvme: expose active quirks in sysfs 95e93ee7053b8 nvme: remove virtual boundary for sgl capable devices 85571e5a37ff2 block: accumulate memory segment gaps per bio 897184def60c9 nvme-apple: Never set the opcode in the NVMMU TCB 751e8e18be0a4 nvme-apple: Don't set a DMA direction for commands without a data transfer 215d1682f0bae nvme-apple: Destroy the admin queue on removal c38a818632679 nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() cb30449ee9a9c nvme: Add the DHCHAP maximum HD IDs a3453d50130cb s390/irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN af20646a329e6 s390: Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT 283d2d61c4a3b integrity: Make arch_ima_get_secureboot integrity-wide d408d69f92b8c arm64: bti: Disable in-kernel BTI with recent versions of Clang bc34d10432303 ASoC: qcom: q6apm: keep the graph start count in sync with the DSP 79c05936be12c spi: sprd-adi: Fix probe succeeding without registering the controller b68d3a7a14585 phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy b499e89a828ed phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms becb8b30d9da6 phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings e1ce0661c0ce8 phy: qualcomm: Update the QMP clamp register for V6 aa615671f486a phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for regulator setup 660b56537e180 phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs 31b8b620a8aa1 phy: renesas: rcar-gen3-usb2: Ignore missing VBUS regulator 832022bb2ba5a rust: uapi: replace direct asm-generic/ioctl.h include with linux/ioctl.h 218c36fdd5c63 iommu/amd: Fix incorrect device ID in invalid PASID error message 7d1099b86356d apparmor: fix unconfined user namespace restriction forced stack 07485821b20b2 apparmor: change fn_label_build() call to not return NULL ab64b1584a905 apparmor: split xxx_in_ns into its two separate semantic use cases c7f53d35455d1 powerpc/configs: enable CONFIG_RAS to fix EDAC support 569eb11f09908 amt: Don't support cross-netns setup. 6033cc02fe27d selftests/sched_ext: Check skeleton open failure in exit test f1872cddf12ab cgroup/cpuset: Use WRITE_ONCE() for shared prs_err updates 474da0e00d0c9 cgroup/cpuset: Fail if isolated and nohz_full don't leave any housekeeping 4fd62a9418ab9 cgroup/cpuset: Rename update_unbound_workqueue_cpumask() to update_isolation_cpumasks() c25b6b28a35f9 nvme-pci: release descriptor pools on probe failure 9e489dc3fbbf4 nvmet: propagate percpu_ref_init() failure in nvmet_ns_enable() 33f07f8fbb9cb nvmet: fix Reservation Register Replace for unregistered host with IEKEY da652cb17f9fa sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE cda4aacfb0bbf SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 7d0554350d884 hwmon: (cros_ec) Synchronize EC access from the thermal device callbacks 13ad7a04b97a6 hwmon: (cros_ec) Store the hwmon device in cros_ec_hwmon_priv 49390d9d8eaf0 hwmon: (cros_ec) Register the thermal devices after the hwmon ones 786409d4dcd1b hwmon: Support guard() and scoped_guard for subsystem locks 1a010fcc0f1b0 hwmon: (cros_ec) Add support for temperature thresholds 14ec266275419 hwmon: (cros_ec) Move temperature channel params to a macro 6fa77dea178e7 hwmon: (cros_ec) Split up supported features in the documentation 28e9bcb654f19 arm64: Disable KCSAN instrumentation in delay.o 0f7f363cc6ceb xdrgen: Fix opaque and string encoders for unbounded members 97c12f3e24e7d xdrgen: Do not declare union XDR functions in the definitions header 184a3e5bbc01b xdrgen: Address some checkpatch whitespace complaints 221a025fb6aa6 m68k: Fix backtraces for non-running tasks 0fdc6aaea2965 hwrng: imx-rngc - Disable clock on registration failure 5067a5fbbd025 crypto: qat - remove dead ADF_HEX code 0c68bf6b4842e crypto: qat - use 2-arg strscpy where destination size is known a803141597d61 iommu/vt-d: Flush context cache with correct SID when tearing down aliases d0e978ced7429 iommu/vt-d: Tear down scalable-mode context on probe failure 3c88cfedc7768 iommu/vt-d: Clear Present bit before tearing down copied context entry 686bd59429ffe iommu/vt-d: Fix UCTP context table slot when copying root entries e3c53e9173a47 iommu/dma: Restore locking around msi_page_list 7508654e409ed fbdev: clps711x-fb: Remove unreachable unregister_framebuffer() call 33e54e3e0b2ca fbdev: kyro: Validate overlay viewport coordinates 656e580c19ca1 fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() 656e43f7afabb perf synthetic-events: Fix divide by zero in perf_event__synthesize_threads e0b01aedf85f8 perf python: Fix memory leak in pyrf__metrics_cb 9eebbaf7a33be perf python: Validate CPU and thread maps in pyrf_evsel__open ce4c4c03ef5bd perf python: Handle Py_None for thread and cpu maps 2fef75555c0aa perf python: Check counts_values size in set_values aba46bc65e083 perf test: Fix skiplist leak in cmd_test 02ffce64f7ad6 perf test: Support dynamic test suites with setup callback and private data 122c64347d9a4 perf synthetic-events: Fix uninitialized pthread_join a9ee5e8eae20d perf stat: Fix evsel_list leak in cmd_stat b567e25ffda7b ARM: dts: helios4: add SATA regulator supplies 37dac96549d91 ARM: dts: helios4: add vcc-supply to GPIO expander 5934c1c867070 ARM: dts: helios4: add vcc-supply to EEPROM 19ebf0422fe91 arm64: dts: turris-mox: fix usb3 phys c2178137a7893 i3c: renesas: Don't register devices when ENTDAA times out 8ca083c0fe2c2 i3c: renesas: Follow a unified pattern for transfer and command initialization 4e2b33373a0f3 i3c: renesas: Return immediately if there is no transfer a052ad5edccf5 bpf: Fix mmap_lock leak in irq_work path cc1c1c70d203a bpf: Avoid faultable build ID reads under mm locks b25ce833d8f12 bpf: Factor out stack_map build ID helpers c1d79bb9c4662 riscv: cpufeature: Clarify ISA spec version for canonical order bbe2fd6d77df6 net/sched: cls_api: fix teardown of an adopted proto on insert-race loss 457ee7219c9ee iio: light: gp2ap002: re-enable irq if runtime suspend fails 0fc740c25c9ab iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes 1ab7ef7ccfb86 iio: light: opt4060: Fix pointer type passed to div_u64_rem() 1ab3da12061d7 bpf, cgroup: Fix storage null-ptr-deref after replacing prog 7c2658023d839 Bluetooth: MSFT: validate evt_prefix_len against the response length 7efd7fb4c9c77 Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is negative e1fc9c5878f03 Bluetooth: btmtk: add MT7902 SDIO support 534d3efd59b3c Bluetooth: btmtk: add MT7902 MCU support c00556fbe75eb mmc: sdio: add MediaTek MT7902 SDIO device ID e0cd7b34dc6b5 Bluetooth: MGMT: free the HCI command when it is cancelled 05438d338a875 Bluetooth: MGMT: free the mesh send cancel command when it is cancelled 9c3b6c1413bd0 Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths c1fe3c74a89a7 Bluetooth: hci_conn: fix the SCO setup context lifetime 2f907608cbcfc Bluetooth: btintel: Fix diagnostics event detection be1e3df2c49c9 Bluetooth: virtio_bt: avoid OOB read of build info string 244d029900814 pinctrl: airoha: fix edge-triggered interrupts handling c7596135e7e9a pinctrl: airoha: fix IRQ mask/unmask code fda7350f257e5 pinctrl: airoha: add missed IRQ resource helpers 9ea692247ee24 pinctrl: airoha: fix getting gpiochip/pinctrl pointers in the IRQ handling code f3b8fe04dbfe3 pinctrl: airoha: add missed get_direction() function for gpio_chip 7d2b3f8a996d1 pinctrl: airoha: an7583: fix spi group pins 38a2a4d6c7ac7 pinctrl: airoha: an7583: fix muxing of non-gpio default pins 2313f262999c7 pinctrl: airoha: an7581: fix mux/conf of pcie_reset pins 2ad2147082592 pinctrl: airoha: fix pwm pin function for an7581 and an7583 cfe4350fdcb53 pinctrl: airoha: convert PWM GPIO to macro fa27ddca66022 pinctrl: airoha: an7583: fix I2C0_SDA_PD register bit order cbde1169bdd2c pinctrl: airoha: an7581: fix pinconf of i2c_scl/i2c_sda pins 75ceddfa7df7e pinctrl: airoha: fix mdio bitfield names 4bf51df55d7bd pinctrl: airoha: add support for Airoha AN7583 PINs 74c2c5b459b42 pinctrl: airoha: convert PHY LED GPIO to macro e6edde29990af btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() b0059242735ea btrfs: avoid GFP_ATOMIC allocations in qgroup free paths f44616db1dbce btrfs: use aligned range for locking in extent_fiemap() 92484ad014f2e btrfs: zoned: don't clobber the extent buffer when zeroing it out 12b6d1a1715cb btrfs: retry verity reads for not-uptodate Merkle folios 58ce50b1802a4 btrfs: always wait for ordered extents to avoid OE races 76b7c505c74f4 btrfs: merge setting ret and return ret 8a34b30bd1bfc btrfs: make btrfs_repair_io_failure() handle bs > ps cases without large folios a9701dd06e82c btrfs: defrag: fix deadlock between defrag and delalloc space reservation 34f67cfb15fa5 scsi: sd: Fix sd_done() sense handling condition 8bd807995dd5d perf trace-event: Fix integer truncation in do_read() and skip() 14470bc005ec6 Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices 4ea16cbcc58e3 Bluetooth: btusb: Record matched usb_device_id into btusb_data 5ca4aa51ab378 Bluetooth: btusb: refactor endpoint lookup dc849d11a7d2b Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() 4ea53de3e47fa Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event 1403beab27c64 sched/fair: Check CPU capacity before comparing group types during load balance ce065b76c89cb sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY cab5015ee3f25 perf/x86/intel/pt: Fix stop/start with no update b53e430f8eab8 perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED ad9d3402f4b05 perf/x86/intel/pt: Factor out pt_config_enable() 54eb9b2d18f8b ACPI: video: Release PCI device reference after lookup 679b862781010 regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling 053ec85cb9f26 bpf, arm64: Fix exception table metadata for arena load-acquire 415257c38a3fc bpf, x86: Fix exception table metadata for arena load-acquire 5f13a844d0c9b bpf, riscv: Add and use bpf_atomic_is_load_acq() helper c4c8de3bf48d3 bpf: Reject load-acquire from pointers requiring fault protection 57b72442c1672 perf: arm_pmuv3: Zero initialize hw_id branch stack field f61f65fc81dcd coresight: Refactor etm4_config_timestamp_event() 9e804dbe28b74 coresight: etm4x: fix leaked trace id 1ade9a335c69f coresight: etm4x: fix underflow for usage of (nrseqstate - 1) 9241edfb84a0d coresight: Change syncfreq to be a u8 a29d753e9d83b coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() f9cdb5bb8efbf md/raid1: don't set array_frozen in raid1_takeover() c55aa6c17f019 md/md-llbitmap: stop daemon timer rearm on destroy 930cc4f1af5a1 md/md-llbitmap: prevent create failure bitmap UAF d81822fd5fa81 md: avoid stale clone I/O accounting timestamps 73881ff7a7591 md: wait for behind writes before destroying bitmap 02c10581866d0 md/raid5: round bitmap stripes with sector division d2c069ddaec79 phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets 5547fd950d6bf phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend 61749681e4a36 phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend 52ad86ea5f98d phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend f67686d826755 phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads 12d35c6572622 phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() a834458ecaadb soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() dfe848cadfde4 hugetlbfs: release subpool on fill_super failure 2177c04ca0684 pinctrl: rockchip: Reset the pin count when recalculating SoC data 6eaa632d0ed7b firmware_loader: do not queue completed sysfs fallback requests 067504c00fe17 scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path 8d752f1bb73fa drm/amdgpu/gfx6: Use PFP on the compute queues too 375adae128dd0 drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets 1a1ea9738c41d perf trace-event: Fix buffer overflow in read_string() b8ae06ccde3ff phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table 1489b694b1f32 phy: sunplus: fix error handling in sp_uphy_init() bf7fefbc26e29 phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator b464367d7397b phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control 733d3c1f3f513 phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic 66ef9160e878a arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node 7c4c228b0cc3e ext4: fix spurious message about orphan cleanup on RO fs d2d543f9313fa drm/amdgpu/gfx6: Fixup emit_cntxcntl() 037d9babf6c6b leds: gpio: Clear error pointers for skipped LEDs b75f84c010274 mfd: macsmc: Fix key count endianness annotation f59ccd8eeaa09 mfd: iqs62x: Reject zero-length firmware records 8ae4d0ff3e357 mfd: rave-sp: validate received frame payload lengths 519e7de2c4c7b arm64: hibernate: Restore DAIF state on error 012823494e20c arm64: hibernate: mask DAIF before restoring hibernated kernel 73979c96a3b8f wifi: mac80211: skip default WMM setup for AP_VLAN links 48b5a520b80a7 RDMA/erdma: restrict the driver to little-endian systems b2709aad7599f module/dups: Fix use-after-free in kmod_dup_req lifetime handling ef7c354f7377f module/dups: Inform duplicate requests about the result directly 11fa3f7ffd4f7 module: use strscpy() to copy module names in stats and dup tracking ba7e83ce0b340 module: replace use of system_wq with system_dfl_wq de603f01d9ccf RDMA/siw: Fix use-after-free in siw_accept() 6c506fee5a5f2 IB/isert: post the full-feature receive buffers after session registration a6c19af05c170 IB/isert: delay the final Login Response until the session is registered aaa66e60c0e21 cpufreq: imx6q: fix out-of-bounds write when probed more than once e2d2612e63e29 cpufreq: imx6q: fix devres accumulation across driver rebind db0a49f0a37d4 rust: cpufreq: Fix temporary write in Registration::bios_limit_callback 2973978781908 rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table b43a2518c3eca drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz 46510c3e496b6 drm/sun4i: dw-hdmi: Drop TCON TOP port reference 17a588752ddf8 drm/sun4i: tcon: Drop remote endpoint reference 65bc02fec98e4 drm/sun4i: crtc: Propagate layer initialization error 50806c951a68c drm/sun4i: hdmi: Don't leak sync polarity bits into packet control 1ca06d47ac40b drm/sun4i: tcon: Drop TCON TOP device reference 425a414f9b5de drm/sun4i: tcon: Set output mux for DSI and LVDS 6ec54d801440e drm/sun4i: vi scaler: Fix coefficient selection 46a5fe1a43574 clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 aee687a2fb369 ocfs2: synchronize heartbeat callbacks with o2net teardown ba32c7d6129db perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly 59cc63d244d93 perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info() c473f3aa721e8 perf libbfd: Validate BPF prog info arrays before pointer cast c71f9a56520b4 ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults 314f1a6762b5d ARM: 9481/2: breakpoint: CFI breakpoints only on demand dc2272c00d7c0 RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ ec987c0654651 RDMA/erdma: Hold QP references for AE and CM processing 1fc9c1933959d RDMA/erdma: Hold CQ references when processing EQ events 56ea0a1f9f93d kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile 933076eb1d3d6 modpost: prevent leak when early return no suffix .o in read_symbols() 0fde935ae0ea9 scripts/tags.sh: Prevent binary files appearing in cscope.files 804378ff0d62c intel_idle: Avoid using deep idle states during initialization 56450feb6f485 intel_idle: Add cmdline option to adjust C-states table 33a5d2f00cac3 intel_idle: Initialize sysfs after cpuidle driver initialization 6ee7b00888498 bpf: Check load-acquire src ptr type before the load cb0671ffce488 arm64: dts: qcom: sar2130p: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies af38023bc47dc arm64: dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies f068388689bea arm64: dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies e70a165b79419 arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies 2fa866714f227 selftests/mm: fix ternary operator precedence in ksm_tests 5cd78a904275a selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes 335b75cfed44b selftests/mm: ksm_tests: use kselftest framework 86ead17630110 bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed 6fd220604f06c remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() 5a5ed571032e9 remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() a356d08d7151a remoteproc: Move resource table data structure to its own header 90361f45ffe85 arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC 9063b30faae8c drm/omap: dsi: Do not copy isr table d1cfbccccad7d riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller 571ea4263d69d fat: release buffer head after rebuilding parent 44a37264b2691 rapidio: clear mport->net when rio_add_net() fails 9df662fcac6fe pps-gpio: remove dead capture_clear code 599d4c92aa0b4 pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler e31ff723811ee pps: don't try to wait for negative timeouts in PPS_FETCH f637a83115b32 lib/string: fix memchr_inv() for large ranges 8abb2b7c60d2b ocfs2/cluster: keep heartbeat local node stable b55e7e61c5c19 ublk: check for ublk_unmap_io() returning 0 0121c84adb6a4 ublk: check import_ubuf() return value b4e971c80e64f block/kyber-iosched: flush per-cpu latency buckets over possible CPUs 7c25949cee2f0 block/blk-iocost: collect per-cpu latency stats over possible CPUs 55bda3de92f8c block/blk-stat: drain per-cpu callback stats over possible CPUs 3d8c3da95c75a blk-cgroup: skip dying blkg in blkcg_activate_policy() ac34e655dffa7 blk-cgroup: fix race between policy activation and blkg destruction c4487e4d5309d phonet: pep: do not write beyond optlen in getsockopt f16c2c3932ce7 net: stmmac: Skip PHY attach if custom PCS is in use c65d67b08bab4 iio: light: tsl2583: return zero in write_raw() on success 7a6a9bc87c6ee iio: light: isl29028: return zero in write_raw() on success 1e628f7ce4bc2 iio: light: tsl2772: fix ALS calibscale readback 6c98ec4447d2c perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero 9a857be21e2f3 perf intel-bts: Fix off-by-one in auxtrace_info minimum size check b3a42fd1a0cd1 perf intel-pt: Fix off-by-one in auxtrace_info minimum size check 59910f142da84 perf auxtrace: Fix queue grow overflow and old array leak 003de0cf0810c perf thread-stack: Fix heap buffer overflow on branch stack wrap copy 5db6e27ad43d2 HID: lg4ff: validate report length before fixed offsets bef8426d7138c HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure f694ea0ead544 HID: steam: Reject short reads 78c39dd5cc4ae HID: steam: Improve logging and other cleanup a0fbd9437d7dc HID: steam: Add support for sensor events on the Steam Controller (2015) 041e63bd2f73c HID: steam: Rename some constants that got renamed upstream d73725bf86120 HID: steam: Refactor and clean up report parsing 17e532415518a HID: i2c-hid: Fix "(null)" output when reading report descriptor fails 01eeb601a1626 HID: synchronize input before cleaning up a failed probe e5b6af32ecdd8 HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver d7f2ec073a05a misc: pci_endpoint_test: Check SUCCESS bit for doorbell status 5c58ea19a909e dm-integrity: replace forgeable discard filler with a keyed sector marker 4f6bd79bb7e55 tty: clear cdev pointer after cdev_add() failure 5b77848423f4a serial: amba-pl011: keep console clock enabled for atomic writes 5ac19e4e26e99 serial: amba-pl011: unprepare console clock on unregister ea7fd4e8e8b87 MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL 6bdbc2b4df1f5 soc: fsl: qe: implement get_direction() 0f3d1d7ab5d2f soc: fsl: qe: properly scan GPIO nodes at startup 90d953002cf0b powerpc/irq: Fix missing r2 clobber in PCREL inline assembly 5fa92c6466fa2 powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass b59a47e20040a pinctrl: spacemit: validate pins in pinconf callbacks 41eba3b3ef86f pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE 2d98a3b89394f firmware: coreboot: Validate table bounds d0a19a59580a2 firmware: google: Add bounds checks in coreboot_table_populate() 7a22cbc6c6bdd wifi: cfg80211: stop PMSR before P2P and NAN teardown 0a0c03e4b7c63 wifi: cfg80211: Add an API to configure local NAN schedule 84263694c8d1f wifi: nl80211: split out UHR operation information e182bf30a38c3 wifi: nl80211: refactor nl80211_parse_chandef 6481459f78be3 wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver 335c515932a59 wifi: cfg80211: add initial UHR support be90aa8bf1775 wifi: ieee80211: add some initial UHR definitions 66722acd740be wifi: nl80211: Add support for EPP peer indication 93b4c9130461c wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel e7bc5ab93acd1 wifi: mac80211: disconnect on CSA to channel 0 7c3d762bc15c5 wifi: mac80211: skip unused probe response countdown offsets 979ad5269bdf0 wifi: zd1211rw: reject secondary interfaces to prevent conflicts 26e6123a93dca wifi: mac80211: send TWT teardown to peer after setup TX failure 97dd2f6560ce3 perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register 9ba040f4fec87 iommu/arm-smmu-v3: Convert to use atomic poll timeout 2a08fd5a082e1 kselftest/arm64: Don't write to P0 in irritator on SME only systems ee46a1714d3a9 kselftest/arm64: fp-ptrace: Fix checks for inactive SVE and SSVE regsets 695e976e25a11 arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets a2ff70c44fe8e arm64: smp: Fix IPI teardown for GICv5 flow 80818e72aec4d wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations 7039825a7479d wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump 637bb99cc766a wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() 13f6a9c786022 wifi: mt76: reject out-of-range link ids in mt76_vif_link() 81ccb9faf3c43 wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum 0ead464cb43ef wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band c59c8b962c4d8 wifi: mt76: fix queue assignment for disassoc packets 292bc52d8420a wifi: mt76: mt7915: report RX chain signal for all RX paths 4dee6aca79295 wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 76144da3c6184 wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed d4326105ee28d wifi: mt76: mt7996: fix reg addr remap when addr is 0 ed5cc46a3c8f4 wifi: mt76: mt7915: release hif2 reference on probe IRQ failure a7fd3bae8e11a wifi: mt76: mt7915: fix ext PHY use-after-free on register error path 249cbaa187355 wifi: mt76: mt7915: fix double hif2 init on the non-WED path 51c6d1f665401 wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990 2b10eb3636d0c wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset f3d8cf8c09e3b wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER 2cc7d32b42dab wifi: mt76: mt7996: skip key upload when adding an offchannel link 6bce0f1280c94 wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement 40f3bfbbb222b bpf, x86: Fix trampoline stack size for 128-bit arguments f6202ed975070 perf machine: Check snprintf truncation for guest kallsyms path eaa350a2ec347 perf machine: Free scandir entries in guest kernel map creation 9054ad50ffe27 perf machine: Reset errno before strtol in guest kernel map creation c0b06d47ac329 perf machine: Don't abort guest map creation on first inaccessible dir b3b3175103acf perf machine: Check snprintf truncation in machines__findnew() 15159fc5441bc perf machine: Guard against NULL strlist in machines__findnew() e3a2ed4c0e8e0 perf machine: Fix NULL parent dereference in fork event processing 28bb9ea64c0c5 perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir() 0b950aa7ec95e regulator: core: use system_freezable_wq for init complete work 2e2d63f68211e ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach 5589af278c504 ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors 551f3e27486bc ASoC: tas2783: Use new SoundWire enumeration helper 0b5c09512f21b soundwire: Add a helper function to wait for device initialisation f5bb3471c9f46 wifi: ath11k: fix leak in ath11k_service_ready_ext_event() 83bc4eab83ae5 drm/msm/dsi: Drop dev_pm_opp_set_rate(0) e0d1d1253ea2a drm/msm/dp: Drop dev_pm_opp_set_rate(0) be73b1984086f drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) 81d21396fea2d perf: arm_spe: Make wakeup range check overflow safe ad1d83816b845 drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active 6572b5a74ab1c drm/msm/dp: reject YUV420-only modes without VSC SDP support 08827aa40f0ee drm/msm: don't tear down KMS twice when KMS init fails 64976f3b34b07 ACPI: processor: Unregister cpufreq notifier on init failure 6cffb59ee50ea ACPI: processor: idle: Optimize ACPI idle driver registration efc57983a1d46 wifi: mt76: only consume the WO drop bit on WED v2 devices 19f108fee1470 wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar b93d0f07ed040 wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields 92dc45686b9f1 wifi: mt76: mt7996: don't leak MLD group index on remap alloc failure 45d8896e4cfff wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV 906ad486ba5c4 wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER 507eddb8175a6 wifi: mt76: mt7915: unwind state on add_interface failure d0bb2189ade61 wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config 1c7ad1236bc6f wifi: mt76: check txfree done event on the WED hw path 31faa92cd5074 wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie 7ac05ed3a50e5 wifi: mt76: fix RXDMAD_C buffer recycling race 576683faa9381 wifi: mt76: fix uninitialised RXDMAD_C descriptor info 423be355be5ae wifi: mt76: fix stranded frames in mt76_txq_schedule_pending 471586e88861d wifi: mt76: mt7915: write RX header translation bit to the correct register 522101cbbb3bc wifi: mt76: mt7996: don't report a zero TX bitrate 6ce78d04c7ea4 wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss b4a41a47a67c7 wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear bf59177bab17b wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset 0f53ece876e1f wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] 310edc8f3f56b wifi: mt76: assign link_id when sending probe request during scan fc7fae55255cc wifi: mt76: fix non-AQL packet accounting for MLO stations 5183b9f092fc0 wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP 990ec9215ebe1 wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart 25b765aa9a61f wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch 5c350e3b6065f wifi: mt76: mt7996: support fixed rate for link station 62aea1d45b524 wifi: mt76: fix RX data queuing of RRO 3.0 97a77dc0abd90 wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU 674e0ad0ae15f wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations ddf6a17d8e3d0 wifi: mt76: mt792x: Fix memory leak in SDIO TX path 52c7bcf067861 wifi: mt76: mt7925: fix msg len mismatch between driver and firmware 383bb0511dfe6 wifi: mt76: mt7925: update clc before setting sar power table 670b3dc4e3713 wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash 0015b56dff60f wifi: mt76: always enable RRO queues for non-MT7992 chipset 6e9207ac476ca wifi: mt76: Introduce the NPU generic layer c0dbce50c8961 wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h 50c896af50e02 wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 17d6b89e09eac wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length 0340bd33b4e21 wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996() 1991d605a45f6 fanotify: report full event length for FIONREAD 6248eb1833ff0 misc: sgi-gru: remove interrupt-context page-table walks e6e4cbc9e8fdd misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() 2a1c16c4700cd powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr() 7969b571ae940 powerpc/44x: Set GPIO chip parent 687d42d9eea41 powerpc: implement get_direction() in cpm2 e7c69c6695d84 locking/lockdep: Fix NULL pointer dereference in __lock_set_class() 37f11973c3eb7 md/raid1: create serial pool adding rdev to array with serialize_policy=1 71da948d249a5 fs: annotate inode timestamp accessors 039e490e3ac47 i3c: master: adi: add OF module alias for autoloading 9eaac0cb4ca94 i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices 35e0103177826 swiotlb: Preserve allocation virtual address for dynamic pools fb0b39287ba89 iommu/dma: Check atomic pool allocation result directly 28fdea874f68c md: scope memalloc_noio to allocation critical sections c510626bbacb1 md: skip redundant raid_disks update when value is unchanged 9f16747fc3b23 md: remove unused mddev argument from export_rdev 6763fb409a0b4 md/bitmap: resume array on backlog_store() error path 85ece0386c4fe clk: qcom: Return expected ENOMEM error on dynamic allocation failure 64abdd6961290 clk: qcom: gpucc-qcm2290: Park RCG's clk source at XO during disable af7a6d6ec36a1 lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone 85cf991c881e7 bpf: Fix potential UAF when reading bpf link info bda86e9f31b9a bpf: Fix potential UAF in bpf_netns_link_update_prog d5266b4c5c771 power: supply: sc2731_charger: cancel work on remove f312c5d17f2a7 power: supply: isp1704_charger: cancel work on remove 1a35eda51a501 arm64: dts: qcom: qcs6490-rb3gen2: Fix the PCIe iommu-map entries e1c65abeb6aaf arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries 03a85ccf857ac arm64: dts: qcom: lemans: Move PCIe devices into soc node 76e14b0e86567 arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration 8d7411cc0bd95 arm64: dts: qcom: lemans: add QCrypto node 610d253bef458 arm64: dts: qcom: lemans: add refgen regulator and use it for DSI ca29c5c0cc615 arm64: dts: qcom: lemans: move USB PHYs to a proper place 349752c7ab6be arm64: dts: qcom: talos: Fix the PCIe iommu-map entries fc2980ea69202 arm64: dts: qcom: sm8750: Fix the PCIe iommu-map entries f418e83ac1abe arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries e8a7928da474e arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries dbcbbb2033736 arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries 793dbaa91c3bf arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries c8fd2cabd0b7c arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries 152e82a60d70e arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries a98b8bb0ca25f arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries 8dfc4641001fb arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries 54176af35d989 arm64: dts: qcom: sar2130p: Fix the PCIe iommu-map entries d2b404826bf93 arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries f063039d2e439 arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID d29c5a88d5703 block: fix dio leak on metadata mapping error 642828f274eb7 block: add a bio_endio_status helper 8b1817b36ca5c block: don't set BIO_QUIET for BLK_STS_AGAIN 2b239a920a992 blk-crypto: use on-stack skcipher requests for fallback en/decryption 196a8f954ae6d blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio 30439432f3f2e blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep f57adb5beca6b firmware: qcom: scm: Fix tzmem state on probe retry 1da025b5ceb45 firmware: qcom: scm: Fix reserved memory cleanup on probe failure 1d753df5899ec firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published d72c76684a4a9 firmware: qcom: scm: instrument SMC call path with tracepoints 347efe779f55f firmware: qcom: scm: add trace events for the SMC call interface 889ca992d9c4e firmware: qcom_scm: Support multiple waitq contexts 3d028e241c2aa firmware: qcom_scm: Add API to get waitqueue IRQ info 81af527ead79c arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en 5793229726e25 clk: qcom: gcc-qcm2290: don't park QUP RCGs upon registration 939c917d037a5 arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes 4ea052255a4a6 arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property d098dd6ec09b8 arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override 9346a92337075 arm64: dts: qcom: msm8998: Don't pull-up I2C pins by default in sleep 179713adff1bd rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs badab2078d459 md/raid10: consistently fail atomic writes that require splitting 75185e2b214e8 wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() b9a5d12cbdeb8 wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() ec6edba35aa7b Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration" d44a02724576c selftests/zram: fix kernel_gte() for POSIX sh e5ac7ab78467b md: recheck spare changes before starting sync 47b61029f146f tools/nolibc/powerpc: mark ctr and xer as clobbered by system call a2fbef8a6318b fanotify: stop permission watchdog when timeout is zero 9d65cb2142533 md/raid5: protect lockless recovery_offset accesses during reshape 455b56209f961 md/raid5-ppl: fix use-after-free in ppl_do_flush() dcd3d87cfc148 md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency 4fb17a7c437f1 bus: mhi: host: Fix controller cleanup on EDL sysfs failure 21ce330f921a5 bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET a89818977338b wifi: rtlwifi: pci: fix error path in rtl_pci_probe() e2cbe14361d7c platform/chrome: cros_ec_debugfs: Unregister panic notifier b95664e3f82da platform/chrome: cros_ec_debugfs: Clean up console log on probe failure e7768f3dae9f2 media: qcom: iris: handle runtime PM resume failure in core deinit c1a48452cc16e media: qcom: iris: Fix bitmask test in iris_allow_cmd() 794f6d4c4ddef drm/msm: remove objects from evit list after pinning them b3624eecb65a2 PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe 257a0a59598f5 PCI: starfive: Fix Runtime PM handling and teardown ordering aa8226f873c91 wifi: ath12k: validate TLV length in process_tpc_stats() 0364926fb4bfb wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() 3b544072185c3 spi: davinci: switch to managed controller allocation bd764baf82bb4 nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request c345d9d0b3eef IB/isert: reject login PDUs declaring more data than was received cf36fa5357a2f IB/isert: reject PDUs declaring more data than was received 429b75000c6a9 media: staging/ipu7: fix async notifier leak on init error a2e37d1ab773b RDMA/cxgb4: free STAG index when TPT entry write fails b1fe9a1bd0012 RDMA/mlx5: Send cong param changes to the resolved port mdev 4599311e78e88 RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs 75424c5a6620b scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches. 3904fb0ee741e nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch 842397fdfd2e6 nilfs2: prevent out-of-bounds read in super root block parsing 1fc6df85b4954 nilfs2: fix infinite loop in nilfs_clean_segments() 49a7d62d64f79 clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs 666071b3128ac clk: mediatek: mt8135: Fix inverted gate control for devapc_ck 1158a9adc7dce clk/x86: pmc_atom: add kasprintf return value check b8b81c6c89f0c clk: palmas: Manage external-control prepare with devm d35e45e5bad4f clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path ac6f7740655d8 clk: mediatek: Refactor pllfh registration to pass device c945468a6df72 clk: mediatek: Pass device to clk_hw_register for PLLs b7cd043b8412e clk: mediatek: Refactor pll registration to pass device 03e070e517204 clk: tegra: tegra124-emc: put EMC node on register failure 75653b0408d52 arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix 730e71d747051 wifi: mac80211: fix per-STA profile length in cross-link CSA parsing da7805f0211af RDMA/efa: Fix PBL chunk length computation 5f1933163327c RDMA/rxe: Fix UAF in ODP init error-handling path 1d2271d7df523 iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path 9b37afb2d34d9 iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID 735698e81f798 iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs 2f627118b6686 iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs bcb82407633c3 iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init 792f720fc23fe iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized aad605a450611 fs/ntfs3: reject restart table growth beyond U16_MAX entries 7a7d30b1cb890 staging: rtl8723bs: use kfree_sensitive() for key material 6b2e70e9d52c0 firmware: qcom_scm: Introduce PAS context allocator helper function f15cde1129840 remoteproc: Prevent crash handling to race with rproc_del() df92f0e142edb remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() d6bf603246c90 remoteproc: Allow shutdown of crashed processors a098f5894fcb4 remoteproc: core: Drop redundant initialization of 'ret' in rproc_shutdown() 8b93b783db329 cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf 9b95f10e1688c cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy 172f24df0dab4 w1: ds2482: Fix signedness bug in ds2482_w1_triplet() ef5cc4a8c088d spi: oc-tiny: switch to managed controller allocation 67e2ffe98d710 clk: mediatek: mt6735: Unregister PLLs on probe failure 106e1a3b2b345 isofs: release zisofs block pointer buffer head c39eb307b4976 powercap: intel_rapl_tpmi: Handle PMU registration failure during probe bf32f103a325a thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp 686a92cc9f19b thermal/drivers/airoha: Fix copy paste error for sen internal a06b2e6b8f508 thermal/drivers/airoha: Fix copy paste error on clamp_t low temp 5b6cfc6d7ff09 RDMA/mlx5: Fix integer overflow of user QP buffer size 9c9c64abed530 crypto: keembay - publish OF module alias for OCS AES/SM4 7efb51a5893b2 crypto: keembay - Initialize completion before requesting IRQ cc92af8cc0e4d scsi: ufs: debugfs: Reserve space for a string terminator 15d4fc8f5f108 power: supply: sbs-battery: Use a per-device serial number buffer e505092cb200d arm64: RSI: fix field-spanning write warning in attestation token init 386600507b23f tools/build: Allow versioning of all LLVM tools defined in Makefile.include 7f6d898179ca4 pinctrl: mediatek: free EINT resources on unbind f54b96e8aadbf cxl/region: Fix use-after-free in find_pos_and_ways() error path b804df9aa2942 selftests/bpf: Fix memory leak on subtest_states reallocation b7983cd5ba2c7 selftests/bpf: Fix incorrect error checking for pthread_create c78a9289084a7 ARM: lpc32xx: only run SoC init on LPC32xx hardware 85a33c910edc3 bpf: Fix CFI mismatch in task work callback 4f7e0be664af7 arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property 9ca64fd7a2fde arm64: dts: rockchip: Fix Gru WLAN sideband interrupt 053220e061c7d arm64: dts: rockchip: Add missing hclk for RK3588 eDP1 f5b4bc09c42f2 arm64: dts: rockchip: Add missing hclk for RK3588 eDP0 d65261e0902b4 drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() 64bb6000bfbdf fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init e70d48fcf8382 netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet 2e199e3ede9c1 drm/tve200: add OF module alias for autoloading d9e01c333cebc perf cap: Remove used_root parameter and simplify capability checks a73a88bc4f452 leds: pca9532: Fix phantom device registration on missing hardware f1e8c4d48583d PM: hibernate: Fix memory leak in snapshot_write_next() error path ce7d205c26466 RDMA/erdma: complete object teardown when the destroy command fails 02deb637e9659 xfrm: Fix skb double-free in xfrm_dev_direct_output() 78da16d23496f perf cs-etm: Avoid truncating AUX buffer sizes to int f78fba8549204 perf cs-etm: Flush thread stacks after decoder reset 25be36738f5fc riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups fe9d15fb66d5e riscv: dts: spacemit: Add OrangePi R2S board device tree 9933e5f1f61ec riscv: dts: spacemit: add MusePi Pro board device tree a76b20b1f0309 firmware: arm_scmi: Unrequest devices if driver registration fails 456856a349064 firmware: arm_scmi: Roll back partial protocol table registration 406d5ead1bcb0 cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems 821b41f6e3e4f cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization 95ad5fd298bcd cpufreq/amd-pstate: Add support for platform profile class 471d6659925aa cpufreq/amd-pstate: Add dynamic energy performance preference 0b99dd4201c25 amd-pstate: Make certain freq_attrs conditionally visible ea49944836140 cpufreq/amd-pstate: Use sysfs_match_string() for epp baf5a7fd3f3e2 cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active 937f09ce104c1 ARM: dts: allwinner: a10: Fix PMU interrupt 3933884bc3102 ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() 1399f102d8a18 ext4: fix buffer_head leak in ext4_init_orphan_info 0afbfe019c881 RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap 72a5e45f606ec wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() 95d1bd1db9e9d wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() ccca0f7d9e906 wifi: ath11k: Correctly copy the hint BSSID in WMI scan request 8f86a58ab9412 wifi: ath12k: Correctly copy the hint BSSID in WMI scan request 0c9eac0d1fb47 wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region e69fd62e8117e wifi: ath12k: refactor QMI memory assignment 42bc932e05093 wifi: ath12k: switch to name-based reserved memory lookup abda58f4529d7 wifi: ath6kl: avoid buffer overreads in WMI event handlers 64d445d40e5ea ext4: validate readdir offset before accessing dirent bd8d74bd46d09 ext4: use fsdata to track inline data write state and fix race 4e4e3eec50624 ext4: drain in-flight DIO before buffered write fallback aa0042630b1f7 ext4: clear stale xarray tags on folios skipped during writeback d7b025d3fdf3c thermal: intel: int3400: clean up ODVP on probe failures 466358635a2e4 iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64 267fb3771ddf6 iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() 0812b282703a7 iommu/qcom: Remove sysfs device on probe failure path 8aabe0fba0148 iommu/amd: Fix undefined behavior in devid_write debugfs function c3d4ef1c0ca69 firmware: arm_scmi: Fix requested device removal race 66d65f36d3975 RDMA/core: Fix potential use after free in ib_dealloc_pd_user() 8b22722f45a29 RDMA/core: Fix potential use after free in uverbs_free_dmah() 9abea37942534 RDMA/core: Fix potential use after free in ib_free_cq() 8c013e3a8d827 RDMA/core: Fix potential use after free in counter_release() bedd7dee72588 RDMA/core: Fix potential use after free in ib_destroy_srq_user() 197c262dbf94c RDMA/core: Fix potential use after free in ib_destroy_cq_user() 038cf231b7099 RDMA/core: Fix use after free in ib_query_qp() c538cd121be77 RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations a07cba1296aaa RDMA/nldev: Fix locking when accessing mr->pd b7091e0e2ebab RDMA/restrack: Fix typos in the comments 4aaa2ab816c71 RDMA/mana_ib: drain QP references after partial table insertion a60c36d8d17f1 RDMA/erdma: Fix CEQ tasklet use-after-free on removal 53446b921cdd6 PCI: j721e: Fix incorrect max_lanes for J7200 8c24bda66dd1c RDMA/srpt: Pass the mapped task attribute to target_init_cmd() e42cede6f9017 bpf: Mark bpf_refcount field as unique 28d5f20ed022a bpf: Preserve unique-field state across nested structs dfdce1f20a7e5 bpf: Fix offset warn check for bpf_res_spin_lock 2d2616b4f3728 virt: arm-cca-guest: use migrate_disable() for attestation token requests 662f242863fd8 ACPI: battery: Adjust charging status validation check 26d9496c82658 bpf, riscv: Fix extable handling for arena load_acquire 34b1bb33a0257 riscv, bpf: Fix kernel stack corruption in tailcall with CFI 5cadc66b534fe riscv, bpf: Fix memory leak in bpf_jit_free e991c317d4a00 libbpf: Search /lib64 and /lib in resolve_full_path() 1534c4bff3aac bpf: Zero queue and stack outputs on lock failure 5af710a4f3e39 platform/x86: acer-wmi: reject missing gaming WMI results 7ace189b9ea79 ext4: skip extra isize expansion during mount to prevent deadlock 6702c7da86d8c ext4: fix out-of-bounds read in ext4_read_inline_dir() e4223231b6860 ext4: fix circular lock dependency in ext4_ext_migrate 3eee4c21931dc ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root 4d8ecaa332c16 ACPI: processor: validate MADT IOAPIC entry bounds 87735eb21d7e5 ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer 0bfa897e3e1a6 RDMA/nldev: validate dynamic counter attribute length 6eb1f1414bf70 irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() 93290f29be8f9 selftests/bpf: Silence array bounds warning in global_map_resize 03cf3a1d950f4 selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256 86ce84cf93d2c x86/bugs: Don't use cpu-type matching in cpu_vuln_blacklist 1654875005c7b arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 18b1deba71546 kcsan: avoid unintended access checking in NMIs af073bd245180 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 13cb7160e5b79 RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] 3416db552eb37 RDMA/hfi1: Propagate sdma_txinit_ahg() errors e166856d4ef2d arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe 0da7e87b3044d arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins 624ddc40f2185 phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe 41cacaa222b0d phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe 8fec16898f184 ASoC: meson: Keep link pointers valid on realloc failure 20b92646ee030 dmaengine: dw-edma: Clear stale requests on termination fe0ffa0190e86 dmaengine: dw-edma: Serialize channel state checks 0c3294066c36d dmaengine: dw-edma: Serialize abort state updates be87d86537de7 dmaengine: dw-edma: Terminate all descriptors without callbacks a968dffa5ab3c bpf: Reject arena frees below the arena base 122ad34f72583 drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg 333246218efd5 driver core: soc: Unregister bus on early device registration failure df5466412b362 software node: Fix software_node_get_reference_args() with index -1 13a234359ca8d perf ui hists: Fix uninitialized stack memory free on pstack allocation failure 398aca2f90122 mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() 5c349c533e72a mtd: mtdswap: Avoid freeing registered blktrans device twice b63058bd5e1be mtd: intel-dg: Fix runtime PM error path in probe 31f3f496da280 mtd: intel-dg: wake card on operations 533d0c5feef85 vfio/pci: clear vdev->msi_perm after freeing it on init failure 21d576fc7e298 char: xilinx_hwicap: unregister class on init errors 1a3258e105f71 ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove 29df4ee11433c ppdev: prevent overflow when setting port timeout e4a7ace58941e cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) 98bb638f583db misc: lan966x_pci: depopulate children on populate failure c7ff7a70f405a misc: ad525x_dpot: use driver core groups for sysfs files c8b85cad0fa49 misc: rtsx: add missing write register handling a45d6dd3c11e9 misc: bcm-vk: Use acquire/release for msgq_inited 5310334762c3f speakup: keyhelp: guard letter_offsets possible out-of-range indexing 8688fe2941d54 accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() 16695e9059d80 uio: Fix stale info pointer in failed registration path 1e805a7f4fe01 gpib: Move stuck SRQ update under lock 6c9f6a3b9fdd3 staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths 28ebc34373f04 staging: rtl8723bs: remove multiple blank lines in core/ 368f19a5ed15f staging: rtl8723bs: replace rtw_zmalloc() with kzalloc() aa89cd88ae034 staging: rtl8723bs: expand multiple assignment into separate statements 87ccaea185696 staging: rtl8723bs: fix operator and type cast spacing d8664fa56c46b staging: rtl8723bs: use standard offsetof in cfg80211 operations 11b3765fcb71d staging: rtl8723bs: Fix operator spacing in rtw_security.c 8da8fd3df9fc1 UDF symlink pathComponent header OOB read f42e35e9a7e69 tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 2ed25c9d4400c usb: gadget: f_uac1_legacy: remove broken string configfs attributes 772f29206544f ACPI: processor: idle: Expand _LPI package sanity checks 19ae79f185bc5 crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping d43e1bbfd4345 drm/msm: Only fini scheduler after successful init 6c472fde2c809 drm/msm: Fix task_struct reference leak in recover_worker 133c9aa5b896c drm/msm/a6xx: Fix A621 GPUCC register list for state capture 15d9b29c7da18 drm/msm/a6xx: Rebase GMU register offsets 8bc35465c51be drm/msm/a6xx: Fix A663 GPUCC register list for state capture e36284257eeca drm/msm: Recover HW before retire hung submit 8298883bb3edb drm/msm/a6xx: Fix stale rpmh votes after suspend 9ad7a6ccc7b83 gpu: host1x: Avoid stack over-read in debug output helpers 9211efca5c657 gpu: host1x: Fix offset calculation in trace_write_gather 6b7d5abf3e374 wifi: iwlwifi: mei: pass correct argument to function f26f72c244882 wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments 242125bbf19a2 wifi: iwlwifi: mei: check SAP message length before reading it c9d8641aea01c wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser 8d8a526f3ec65 wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs f20b182ff2d44 spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto badb810da2b09 soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS" d9f25cc138c74 clk: qcom: gcc-glymur: Enable runtime PM 563a1fcf551cd perf jevents: Add more components to the metric sorting order 0b5f752d635c5 arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table c795f18678de6 arm64: dts: qcom: sm8250: sort out Iris power domains 4e59a0b78e048 arm64: qcom: ipq5018: Add GEPHY RX and TX clocks c9fed0c7056c5 arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate 5d0fc8094678f arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin 188344787dacb arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO 591b6fac9df3f x86/mm/pat: Take cpa_lock around large-page collapse 57c567e0e8aa7 drm/bridge: tc358767: clamp the reported AUX read size to the request b6b68da41b270 perf: evsel: Fix error handling in tp_format lookup 4bc18263ef7ac remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev b44f085fb484d cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() c23a708a71afc cpufreq: intel_pstate: Fix setting minimum P-state at init time ce51fcf0d2385 drm/amd/display: Remove unused-but-set variable hubp from 8ee385305e890 drm/amd/display: Fix DM I2C teardown race 5323ed5a7bb25 media: ipu6: Do not free aux device pdata after init 2c29cd408ef86 media: bcm2835-unicam: Fix asc leaked in error/remove path 96baeead354ab media: i2c: rdacm21: Fix missing media_entity_cleanup() 9acc996cb2e84 irqchip/renesas-irqc: Fix generic interrupt chip leak on remove f6f6bdf1708ac PCI: xgene: Drop unnecessary OF node reference 9c001b7dd4d6c cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() 6a37acecc7c29 dax: read holder_ops once in dax_holder_notify_failure() 91be086330c3f libnvdimm/labels: Bound the on-media label size before the shift 25b472c156364 tools/sched_ext: scx_qmap: Fix stale API name in comment 85e5eeb651a13 regulator: adp5055: Fix error code in adp5055_of_parse_cb() b8abbd5c2928f cxl/features: Clamp Get Feature output size to the remaining buffer 1281dc84c8157 cxl/features: Reject Set Features output buffer smaller than the header 3f02031a0a53d cxl/features: Reject Get Feature count larger than the output buffer c656427440ea6 firmware: arm_scmi: Fix transport device teardown lookup 3b0b02134ab90 firmware: arm_scmi: Unwind P2A receiver mailbox setup failure 717b8e972a667 firmware: arm_scmi: Unwind TX receiver mailbox setup failure a54dc23e8bd22 firmware: arm_scmi: Drop handle on protocol bind failures 8197bc6acc517 firmware: arm_scmi: Protect device request lookup with RCU 71c1f8ced3cc0 firmware: arm_scmi: Use channel ID for transport teardown e66756313d1b4 firmware: arm_scmi: Reject out of range DT protocol IDs 54e5a4f7d83db firmware: arm_scmi: Avoid IDR updates while cleaning channels d7c60c0fe2bd4 firmware: arm_scmi: Free transport channel on IDR failure d33b2b68bce6d firmware: arm_scmi: Clean up channels on setup failure 2aac23bc0a79a firmware: arm_scmi: Quiesce notifications before teardown f5e528f631425 firmware: arm_scmi: Unregister device notifier before IDR teardown 1bea027f7ef6f firmware: arm_scmi: Publish channel state before callbacks b967c097d1b6a x86/entry/fred: Encode frame pointer on entry 2bb2a778a4873 wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate e31985c67ba00 hfsplus: validate thread record before delete key rebuild 5b894d01117b2 cxl/port: Restart port enumeration when a sibling adds the dport first 7a14b995931f1 cxl/pci: Honor -EPROBE_DEFER from component register setup 6ad491cef1a81 cxl/mbox: Break poison list loop on an empty payload 485bf44090491 cxl/memdev: Fix firmware upload exact-fit handling a97eef0d6e2fe iommufd: Simplify iommufd_device_remove_vdev() ecad679e2b92c rpmsg: glink: fix deadlock in endpoint destroy during driver detach dd2b56f44be49 rpmsg: glink: remove duplicate code for rpmsg device remove c7f41c7f7d68f perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push f476567a3a965 perf record: Return the written size from process_comp_header() 8b771b43710f7 perf zstd: Fix compression error path in zstd_compress_stream_to_records() ae69f936e8ffe fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() 65e55f34fb2d6 media: v4l2-async: Unregister sub-device if asc_list is empty f0b084c999606 iommufd/selftest: Avoid selftest dirty bitmap size wrap cd616aa0449a7 isofs: fix out-of-bounds page array access on empty zisofs block 81ff877e458e0 ASoC: apple: mca: increase SERDES reset delay 1b769e5d5c33c RDMA/hfi1: Initialize debugfs after probe completes a913960dd85dc RDMA/hfi1: Stop flushing the global IB workqueue e32f985ea38aa RDMA/hfi1: Create workqueues before device initialization 460aaad5044d5 RDMA/hfi1: Remove redundant PCI device ID validation 149a14ec70887 RDMA/hfi1: Free RX data on late probe failure fd4d3ad5f244a RDMA/hfi1: Preserve unit 0 on allocation failure 186df50ce26fb misc: rtsx_usb: avoid USB I/O in runtime autosuspend 1c1c2df09daac pmdomain: bcm: bcm2835: handle genpd provider registration errors 36cbb7249819a ALSA: hpi: Check transport errors during HPI6000 adapter initialization 0f679e0523ddf xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full b0f7343a002f9 crash_dump: release keyring reference at the correct time c115b908e3508 hwrng: ks-sa - Fix runtime PM cleanup on registration failure 4a52a2fb96d10 crypto: ccp - Fix memory leak in SEV INIT_EX path 634e56b4f9913 Revert "drm/msm: dsi: fix PLL init in bonded mode" 287f458ca2251 drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID 399713f1f0eac RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state 8dc5ffcb8efcc RDMA/ipoib: Drain RCU callbacks during module teardown 7babc25d8dd5b RDMA/mlx5: Drain RCU callbacks during module teardown 9d998297fdaf4 RDMA/core: Wait for RCU callbacks before unloading ib_core 0e5c6bf4a04c8 iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE dbe8894db922c wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready 6e4b73b6b743d wifi: rtw89: phy: support per PHY RX statistics 0bae3ec6a16a9 wifi: rtw89: mlo: rearrange MLSR link decision flow e0abd0b1e2f56 wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element 84cb2ae9c0123 wifi: rtw89: fw: parse firmware element of DIAG_MAC f345b7d23c6f0 wifi: rtw89: pci: add to read PCI configuration space from common code 0cfc9348a045d bpf: Require a BPF cpumask for bpf_cpumask_populate() abe7ac019ad99 tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs 9257ece49ae72 clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK 086ac3881a8c2 bus: qcom-ebi2: use managed resources for clocks and children 03991f9a561ce soc: qcom: rpmh-rsc: manage PM notifiers with devres dae798b950388 perf metricgroup: Fix metric expression copy leaks 846ce4d3fda94 drm/panel: samsung-s6d16d0: Power off on prepare failure 39b000d393dea usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure 7f2d926a464bb usb: ucsi: huawei_gaokun: support mode switching 6b0d4519bcf09 usb: renesas_usbhs: Fix power-off ordering on unbind f0cfba808e632 usb: mtu3: allow system suspend during active gadget connection 7fea5a310e3b2 platform/surface: acpi-notify: Check ACPI companion before use 71ba8b6e28f7a platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL 7e795801295c8 usb: fix UAF when probe runs concurrent to dyn ID removal ff6e88e29965b usb: gadget: aspeed_udc: check endpoint DMA allocation aed958c4f784a usb: ljca: bound bank_num in ljca_enumerate_gpio() afbf39c0f2297 usb: gadget: configfs: fix out-of-bounds read of qw_sign 5fd8baacc7dc4 usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths c02d030747c46 serial: qcom-geni: do not advance stale DMA completions 783961be18f5c serial: ma35d1: Fix OF node reference leaks in console init 4e2a433822524 serial: 8250: Clear CON_PRINTBUFFER on port re-registration 45c64f2c09b2d serial: 8250: Add support for console flow control 71d8fcbb767b8 serial: 8250: Set cons_flow on port registration 7416aefeeb822 serial: Replace driver usage of UPF_CONS_FLOW b897b1f791f34 serial: core: Add dedicated uart_port field for console flow ed07324ed4871 spi: qcom-geni: Fix missing error check on pm_runtime_get_sync() 4c59f0e5ee0df perf capstone: Fix kernel map reference count leak 45181de1077c0 selftests/sched_ext: Fix bpf_link leak on early return in prog_run 892bb4715265f hwspinlock: propagate errno when registering single lock 7420aac8b1f7e remoteproc: qcom_q6v5_adsp: Fix reference leak for device node 9a85e2d35e542 platform/x86: lg-laptop: Fix LED resource handling c5c3e0036a7ae platform/x86: lg-laptop: Convert ACPI driver to a platform one f7f83b0826738 platform/x86: lg-laptop: Drop debug-only ACPI notify handler 6ff6af62f042b platform/x86: dell-wmi-base: Fix resource leak on module load failure 9f860050c3d17 platform/x86: dell-privacy: Fix race condition c9729ced165d6 ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling 4cdcf4e19ed31 ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() 7857f19b5219c ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination fbf9bb81b2153 printk: Fix possible console use-after-free b84065e9a8307 printk: Introduce console_flush_one_record d095438ac3320 leds: st1202: Validate LED reg property against channel count 4efb94335d70f leds: st1202: Disable channel when brightness is set to zero 9666b92fe2383 leds: st1202: Fix brightness having no effect while pattern mode is active 2176b43f70da0 leds: st1202: Set all pattern PWM slots to full after clearing pattern 48a05db611027 leds: st1202: Fix spurious pattern sequence start in setup 45dee22d52fd9 leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker b8136daec6308 leds: st1202: Stop pattern sequence before reprogramming e774c612b7f8e leds: pca9532: Fix inverted GPIO output polarity fb43400a3a0f3 iommu/amd: Fix false positive in SB IOAPIC IVRS validation 21750cb34ca87 iommu/amd: Add support for Hygon family 18h model 4h IOAPIC 1fe5653706500 iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors 3df590e85e1a2 iommu/msm: Return -ENOMEM on memory allocation failure in probe 9fb04596eb957 bpf: Fix security_bpf_map_create error handling e7eda48c34679 iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX 5587e7871ce99 bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation 86d54cf069fc5 bpf: Fix use-after-free on mm_struct in bpf_find_vma() ca71ee2f6c28c efi: fix stale reference to efi_recover_from_page_fault() 2892f3f44bf86 bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux 78cae066f029a perf dso: Fix kallsyms DSO detection with fallback logic e69d90bfae1aa perf vendor events amd: Reintroduce deprecated Zen 5 core events 71e3023c5dddf bpftool: Check EVP_Digest when computing excl_prog_hash 11afe1912140f udf: Mark LVID buffer as uptodate before marking it dirty 6648c47091837 usb: gadget: r8a66597: avoid double free of ep0_req in probe error path 1f44d001620fd usb: typec: ucsi: unregister debugfs entries on teardown 35bf61798e7d4 thermal/drivers/rcar: Fix error checking in probe() 593fda71983b9 staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() fb9fab1a4d635 staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys() 947056a91d232 perf data convert json: Fix trace_seq memory leak in process_sample_event() 4b759af64a214 clk: qcom: gcc-qcs8300: Use retention for USB power domains a2e4ebada6840 clk: qcom: gcc-qcs8300: Use retention for PCIe power domains 448f948c9767c arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net 3a624b08d7736 arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes 25026bef5183c arm64: dts: qcom: sc8180x-primus: Describe the display power net 76208cf896aab arm64: dts: qcom: sc8180x-primus: Rename regulator nodes badb18b11215b arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode f60f495858379 clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() f8fe8cb89d3a8 clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains e97f24ad63b83 clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status 27b68ba9af9dd arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware 05a95478f9603 timekeeping: Account for monotonicity adjustment in ntp_error 0fcf7857ae110 y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 db667d2970c75 time/namespace: Validate nanosecond field in proc_timens_set_offset() ecd622375e6d5 timens: Simplify some calls to put_time_ns() 453812e92c760 timens: Add a __free() wrapper for put_time_ns() b19176ff94a01 vdso/timens: Move functions to new file 6e4b520553836 x86/tsx: Make tsx_ctrl_state static e165c01653920 timers/migration: Fix memory leak in tmigr_setup_groups() error path ed7472619e614 timekeeping: Unwind aux clock sysfs children on failure 4222494df71bd clocksource: Unregister subsystem on device registration failure f84b1c25712ab selftests: timers: leap-a-day: Fix -w option and update usage comment d76656e421466 irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() 68de28e0a098a irqchip/gic-v3-its: Fix memleak in its_probe_one() 8da5dc215ebc9 selftests/lsm: Fix memory leak in attr_lsm_count 4d6923a9912da selftests/bpf: Fix memory leak in msg_alloc_iov 58dc854c302a1 selftests/bpf: Fix memory leak in msg_alloc_iov error path 3201c4e882847 ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() 737c928ff5092 staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() 89f9f433271fa staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown ab63b49bad0da staging: octeon: replace pr_warn with dev_warn in fill and rx paths b62bc652590fe staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions 269d16a78a5be staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown 2c0c9956596e4 staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown bcd95498f0cfe staging: fbtft: Use sysfs_emit_at() to print to sysfs file c9191f2e2f35f greybus: audio: bound the topology section sizes against the fetched size c458311637182 staging: sm750fb: Add missing Kconfig dependency af65ceb437971 staging: sm750fb: gate dualview dataflow using g_dualview 311a2e65e42af staging: greybus: audio: correct sscanf() return value check e7fccad2c8e6e wifi: mac80211_hwsim: avoid NULL skb in stop queue drain 2496d9829ab5e bus: qcom-ebi2: Fix clock leak on probe failure e6edd7339153c bus: qcom-ebi2: Simplify with scoped for each OF child loop 3cf9e40432c5d clk: qcom: gcc-glymur: Move EVA clocks to critical clock list 7be3c0bae7c58 arm64: dts: qcom: hamoa: Fix clocks for HSPHYs 62b399c4e9856 arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name a81fad1ff1047 arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset e5965ae3f7c91 cgroup/cpuset: Make nr_deadline_tasks an atomic_t 3a1b23f9ede95 PM: sleep: Fix off-by-one in wakelocks number limit check 0f297bc93bbfd bus: ti-sysc: Fix /chosen node reference leak ca795fc1d8a1a nvmet-rdma: fix response resource leak on queue teardown 0fed8c64266c2 nvmet-rdma: factor out response resource cleanup e5a79244a3c52 nvme-apple: Use acquire/release for queue enabled state 7117f27eb3bfb arm64: dts: qcom: sm8750: wire UFS to ice instance 07974c267f603 RDMA/irdma: Add refcounting to user ring MRs 2ed1164153e92 RDMA/irdma: Add irdma_cq fields to track pbl allocations e11379ca6e90b RDMA/irdma: Add a refcount to track user ring MR associations 8fb2c3106a911 RDMA/irdma: Deduplicate the irdma_del_memlist logic 5bbb726d27ff6 crypto: keembay - Fix AEAD unregister count in error path e7d8ddd471d28 crypto: rk3288 - fail ahash requests on HASH idle timeout 62219775a07ce hwrng: xilinx-trng - propagate timeout before any data is read 91ded4742fcde crypto: sa2ul - stop probe if context pool creation fails f4d347fb1309b crypto: atmel-sha204a - fix heap info leak on I2C transfer failure e64d6f1aae8c8 crypto: atmel-ecc - reject hardware ECDH without a public key 9af019e213ada crypto: qat - clear AES key schedule from stack 6b19f343ae8ad crypto: qat - cancel work on re-enable SR-IOV timeout cf293c9c7424d hwrng: core - fix rng list on registration error 48b8b438d2342 perf vendor events amd: Update Zen 5 core events 0f456e4eca61a perf/x86/amd/uncore: Add group validation c6466466185c1 perf cs-etm: Fix thread leaks on trace queue init failure 47b3686dd841a tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only e3aa0446e37d1 fanotify: initialize permission event watchdog state f2a01deff7d0d wifi: rtw89: fix HE extended capability length check 8f68dd7e4b2f9 wifi: rtw89: check return values in rtw89_ops_start_ap() 74f26d1fa61b2 wifi: rtw89: update format of addr cam H2C command 19052c700bff0 wifi: rtw89: fill addr cam H2C command by struct 847a5ba0ac75f platform/chrome: sensorhub: Fix memory overread in ring handler e4e2d06623d32 selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check a776afa894245 csky: Fix a4/a5 restoration in syscall trace path 5ac21c880dcd6 iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure 69f73ad463b2e soundwire: qcom: Fix port exhaustion check in stream_alloc_ports a13974410cee7 dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe 32f69e6c95b59 dmaengine: zynqmp_dma: fix race between runtime PM and device removal ec927657524be dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers e429184ed58d6 dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure bc3b5e6519b8d mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug d3498c7b587b7 mm: name the anonymous MMOP enum as enum mmop 420d65038c344 mm: change type of state in struct memory_block fff12ff7b3c47 mm: convert memory block states (MEM_*) macros to enum d5f2f741a9001 bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks 01c5ad41cf4db selftests/bpf: Mask socket type flags in mptcpify prog d51a838da7a79 selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr 5e9f698298355 bpf: Copy per-CPU map value padding in copy_map_value_long() e5f6d43168b2e tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands 82a43463ab091 tools/bpf/bpftool: Reset vmlinux BTF after map commands 46d27e56dbd63 drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup 8a3db9f593b64 drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup 68ce4f8223b78 regulator: tps6594: Fix device node reference leaks in multiphase loop 506a6aca57c78 perf tests: Fix flakiness in branch stack sampling tests 7980e2a92a76a perf test: Fixes for check branch stack sampling 82c0378d4569b perf tests: Fix flakiness in BPF counters test on hybrid systems da65eac26fb1f perf test: Fix perf stat --bpf-counters on hybrid machines 0eec12a34b949 perf tests: Fix flakiness in trace record and replay test 81877759d7161 perf tests: Add robust record retry helper and use subsecond workloads 2ab5938f8427c perf test kvm: Add some basic perf kvm test coverage f597922c6e521 perf tests: Skip metrics validation if system-wide recording lacks permission 98e165f28d9b4 perf test: Do not skip when some metrics tests succeeded 79ddb9f98a8ae perf test all metrics: Fully ignore Default metric failures 2f1b696dbbb26 perf test metrics: Update all metrics for possibly failing default metrics 97660f007672a perf test: Truncate test description to fit terminal width de9c6dc47601f perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping 17e39d310b884 perf test: Add -j/--junit option for JUnit XML test reports bdd10298be150 perf test: Fix subtest status alignment for multi-digit indexes 68a81a1eb8d3c perf test: Add summary reporting 456e1e7ce2092 perf test: Show snippet failure output for verbose=1 a3d0aad7e44a1 perf test: Refactor parallel poll loop to drain all pipes simultaneously 1acc1bedf4e69 perf test: Drain pipe after child finishes to avoid losing output a2590ff90dca6 wifi: ath12k: correct monitor destination ring size 5d80268945dfe media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define 6ee86a39a2ff6 media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define 9be10543297f0 riscv: kexec_file: Fix crashk_low_res not exclude bug 68ea6dd23b732 pinctrl: bcm2835: Don't remove an unregistered GPIO chip d623e292c6a4c perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails 18fdd0978ec3d sched/fair: Fix overflow in update_tg_cfs_runnable() 912e7263488e1 mm/mm_init: fix incorrect node_spanned_pages e2a7cee341986 drm/lima: call drm_mm_init() with a valid allocation range d46160ed28478 clk: imx: scu: drop redundant init.ops variable assignment 79927acbd4594 arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB 6b82e11ed1833 ARM: imx: fix device_node refcount leaks in imx7_src_init() cfec229dbe9ab ARM: imx: fix device_node refcount leak in imx_src_init() 9326fd5972eaa clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller e921cc73fae68 ASoC: fsl_audmix: rework runtime PM handling in probe 1e8fddab6cbe5 ASoC: rt700-sdw: always drain jack work on remove 61cae8df14219 clk: stm32: add missing bitfield.h header c77bf8b2ca740 clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic 4c7503f14f25b clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc e165e15e1a9c8 clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation 5e273be0a987a clk: moxart: remove unused variables, fix refcount leak fe3e4196a57a9 clk: versaclock7: Fix APLL clock leak on probe failure 4ffaaef885fcc cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() 31d4841eca7c4 cxl/mbox: Clamp mailbox output allocation to the payload size 5b616612511eb media: cec-pin: Fix event FIFO ordering f1fac4561cda1 soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() 635914c60da26 HID: roccat: bound device-supplied profile index dc32c7423b346 HID: nintendo: Fix imu_timestamp_us double increment per report 544ebb25bd58f HID: core: quiesce input in hid_hw_stop() to prevent use-after-free 97093398e75a7 selftests: proc: include fcntl.h in proc-pidns e4728288473a5 platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count f633cc23dbcc4 x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() 71ddadef3b912 sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging 9c73cf53361f2 smack: restrict smackfs/{direct,mapped} values to 0-255 01d32783bbe01 smack: deduplicate smackfs/{direct,mapped} file_operations 845525bfb547a smack: simplify write handlers of sysfs entries c2ab27c2e1159 smack: fix incorrect task context in smack_msg_queue_msgrcv 04e674840f7e1 drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure 97b8580a112cc drm/bridge: cdns-dsi: Return an error pointer on allocation failure 4614b7cfaf813 drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format e4c3fb6999a49 drm/rockchip: vop2: Add RK3576 to the RG swap special case 3a8aa74859dd7 drm/v3d: Clear queue->active_job when v3d_fence_create() fails 7d65d9651f104 drm/bridge: display-connector: trigger initial HPD event for DP 826426c26b243 drm/bridge: display-connector: don't autoenable HPD IRQ 396a193867c6e drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup 55fda5c2887a2 drm/rockchip: analogix_dp: Enable hclk for RK3588 b4eb01616c0da drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL e97f4b4efc1ab drm/rockchip: vop2: Fix wrong wait target in layer cfg done check 362e005b816ee drm/rockchip: dw_dp: Release core resources fe000d791c608 drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message 82861bdcafda0 drm/rockchip: dw_dp: Simplify error handling 435de4476dd87 drm/bridge: synopsys: dw-dp: Set pixel mode by platform data b2bec2d4a769d drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel 5afa737da00e5 drm: lcdif: Wait for vblank before disabling DMA fa633af222c82 drm: Remove unused header in drm_dumb_buffers.c 2a0423c648a6d Smack: Fix error in capability bypass 31507f01ba6d6 KVM: x86: Check EFER validity on KVM_SET_SREGS* d975b36e56876 KVM: x86: Move the bulk of register specific code from x86.c to regs.c 10ddef36d1cc0 KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2() 8c03b907b0955 KVM: x86: Extract REGS and SREGS runtime sync code to helpers 9b046de62b809 KVM: s390: Zero initialize data structures for inject_pfault_token 310df38690e9f KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported 5453b85c7ebb6 KVM: arm64: Remove VM-wide VNCR mapping counter fd33e8abbcad1 media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP 5cbd8761d001c KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping 892fb48d9dc77 KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr() 8195cf3f4a82e dm-pcache: validate the persisted dirty_tail chain at load 3d5a87cb909c1 dm-pcache: bound the logical key offset from persistent memory 01a700e9278da dm-pcache: reject a kset that overruns its segment 9693980cd7d2f wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot 9e8dd2a7a8ccb usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() d1856e87ee562 usb: cdnsp: fix wakeup from S3 after controller context loss 3776b82c8099e tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member 240558d6e6caf staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit() e5daaf27b14db platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6) 1b5c3f11ba548 platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2() bf87d1ec3bc23 perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities cbb25069fd2e7 mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs 853043cb12947 mm/secretmem: properly account locked pages 8e3adebbdd20f mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP effe3cc6d4fdd mm/huge_memory: transfer the pmd dirty bit to the folio on zap 4f3145db05fed i3c: master: Fix use-after-free of master->this d0cc00957292e i3c: master: Do not treat master device as a duplicate target 83fd7eca5ab0d ftrace: Take trace_array reference before accessing its ftrace_ops 3ae455597e3ea clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs 45962da5821d0 accel/amdxdna: return early from a zero-length flush be072a5d5e35f nvdimm: virtio_pmem: refcount requests for token lifetime 4fbee1039c460 io_uring/waitid: avoid siginfo copy during ring teardown 7549d2d113d4a nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags 0879697520abd io_uring/waitid: honor task_work cancellation 8c6bc1974311a nvdimm: virtio_pmem: always wake -ENOSPC waiters 63e1a529bb89b io_uring: add wrapper type for io_req_tw_func_t arg c5e2e145bc5e3 nvdimm: virtio_pmem: stop allocating child flush bio 0860017371131 io_uring: only call io_should_terminate_tw() once for ctx d0f37d77b9b4b tracing: Take trace_array reference when opening options file 23a02ff3464b2 i2c: qcom-cci: fix autosuspend cleanup 844839aa89e79 futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling 770a90c212722 nvdimm: pmem: keep PREFLUSH before data writes 15d10440b7968 io_uring/waitid: have io_waitid_complete() remove wait queue entry 76648677aa6ef tracing: Make printk_trace global for tracing system 538ef70da5229 i2c: qcom-cci: Remove overcautious disable_irq() calls 884e8484c5fe8 futex: Optimize futex hash bucket access patterns 5f00df2a88ab4 udf: Fix data loss when converting inline inodes to out of line e4cb2bbe73089 tracing/probes: Fix BTF kflag check for anonymous struct member access 4420cc71841b5 staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() 6ba2bacc2dd3e ring-buffer: Allow splice reads on static buffers f5eed5182d664 platform/x86: ISST: Validate max level for set feature 08dab7065f936 platform/x86: int1092: Fix potential memory leak in sar_probe() 929cb3b9dc818 perf: Fix use-after-free when perf mmap() revival races with the last munmap() 2050d900f9adb PCI: Allow per function PCI slots to fix slot reset on s390 7fad53ae2052a nvme: skip the zoned limits update if the zone info query failed 6906fb70af2de net/mlx5e: do not HW-GRO coalesce small frames 558bfaea4926c mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses 824348676a50f misc: fastrpc: don't publish fd before copy_to_user() succeeds f3d97800b03cd iio: light: apds9306: fix PM reference leak in apds9306_read_data() b25232f66e8cd i3c: master: Fix recursive locking during device registration e9e52437120fb ALSA: FCP: do not copy out an uninitialised init response 5881506012f39 nvdimm: preserve flush callback -ENOMEM 545daf1133323 io_uring: unify task_work cancelation checks 400607f57f11d tracing: Clean up use of trace_create_maxlat_file() 871019760cd42 i2c: qcom-cci: Do not check return value of cci_init() 54bc09b41bf3a compiler_types: Move lock checking attributes to compiler-context-analysis.h 9e5abb5e2ade0 wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy 84d983e550c75 udf: Move udf_map_block() up 7d73adba5c851 tracing/probes: ignore id update from btf_type_skip_modifiers 956cb6c72ae5c staging: rtl8723bs: fix spacing around operators cca153095a185 ring-buffer: Show persistent buffer dropped events in trace_pipe file 803208a50b042 PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR() 0d4fb4f15e550 platform/x86: ISST: Check for admin capability for write commands e94b156e5cad0 platform/x86: intel_sar: Check ACPI_HANDLE() against NULL b07bcdca18fb9 perf/core: Fix deadlock in perf_mmap() failure path 1d7be6ff21edc PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value b8adb1ffa263c nvme: fold nvme_config_discard() into nvme_update_disk_info() 2158e178dfc85 net/mlx5e: SHAMPO, Always calculate page size 285f7f3a651c7 mtd: rawnand: pl353: Add message about ECC mode 7ef12e1dd06e4 i3c: master: Fix device_register() error path 69d57dbadb27f dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds 9d89ffd9101c8 ALSA: usb-audio: Relax __free() variable declarations 37ac5eb981f42 batman-adv: fix TX priority extraction for BATADV_FORW_MCAST a1a0959b2da03 mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs() 8bcfa58c4277b batman-adv: bla: avoid CRC corruption due to parallel claim add a5e4d6cb4f684 batman-adv: dat: atomically update mac addresses 463743d1d5ef2 drm/amd/display: Scale custom brightness curve from full range 7e56deae5a796 drm/amd/display: Fix backlight max_brightness to match exported range 54a97ef102523 net/mlx5e: xsk: Fix unlocked writing to ICOSQ f6388029ea9e2 Linux 6.18.51 d83a9de7cecd4 ksmbd: zero pipe read compound padding 75640976cf474 cifs: add fscache_resize_cookie() to cifs_setsize() d73f79d1a2c26 mm/hugetlb_vmemmap: fix incorrect vmemmap restore in rollback 15803e2276067 pidfs: protect PIDFD_GET_* ioctls() via ifdef ed7380f4621f6 mm/huge_memory: use folio's memcg inside __folio_split() 80656031dfcd4 migrate: replace RMP_ flags with TTU_ flags e4307837d92ca mm/huge_memory: replace can_split_folio() with direct refcount calculation f07c94cd3cc20 mm/huge_memory: change folio_split_supported() to folio_check_splittable() 305f9b6eb8a06 mm: thp: use folio_batch to handle THP splitting in deferred_split_scan() 0a4a3d7202640 mm: thp: introduce folio_split_queue_lock and its variants d913a85cc5f7a mm/damon/core: initialize damos->last_applied 05bdb7b867bef mm/damon/core-kunit: handle region split failure in filter_out() 7d4ecfb507f33 mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs() cd6d7f45abc82 mm/damon/core: skip aging from repeated aggressive merging 081ee85b43096 mm/damon/ops-common: use nr_accesses moving sum for quota score cf94a9043f4a6 mm/damon/paddr: drop last same folio access check reuse optimization 11e4859ec0d8b mm/damon/vaddr: drop last same folio access check optimization 4c7275444ac65 mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() 05dc22d5c4fac iommu/arm-smmu-v3: Add HAFT support for SVA c660c017dec1f power: supply: ab8500_fg: fix use-after-free on remove 68916940332d1 power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe() 62fb3124bf740 Docs/ABI/damon: fix typo in intervals_goal sysfs path 1811bd8792ee1 mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios() dba93b8cceb00 hugetlb: remove VMEMMAP_SYNCHRONIZE_RCU e4d1300b457e2 mm: rework compound_head() for power-of-2 sizeof(struct page) 5cec3e60e9f2d zram: set default primary compressor in zram_destroy_comps() fb0e9ecffae59 zram: fix the issue that the write - back limits might overflow 9a78de3befad6 zram: read slot block idx under slot lock fcd467124b19f zram: drop wb_limit_lock d1743ec2dd2c8 zram: take write lock in wb limit store handlers e7dbcb7a561a2 zram: fix out-of-bounds access in read_block_state() 878edb39ecf48 zram: fixup read_block_state() 83dd59ac1c345 NFSD: Prevent client use-after-free during close_lru reaping cd489b0358737 NFSD: Prevent client use-after-free during blocked-lock reaping 7f1abc50ce253 NFSD: Consolidate the revocation-path client unpin 3be89e8039a85 smb: client: reject a tree connect response whose byte count is too small b7e74bccf5887 cifs: Do some preparation prior to organising the function declarations 672cf86aa6aa0 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() 9eed72e9534b1 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 31307a05ed827 cifs: SMB1 split: Separate out SMB1 decls into smb1proto.h 6493277a52b24 cifs: SMB1 split: Create smb1proto.h for SMB1 declarations e7779c9f7e7f9 cifs: Remove dead function prototypes b10015807e4c6 smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions a3e8b98c823d5 cifs: Scripted clean up fs/smb/client/smb2proto.h 72796c2ec6e90 cifs: Scripted clean up fs/smb/client/fs_context.h 4fb5a561866c4 cifs: Scripted clean up fs/smb/client/fscache.h 1537c6c675104 cifs: Scripted clean up fs/smb/client/cifs_unicode.h 549bd9868e9d7 NFSD: Prevent client use-after-free during admin state revocation 3c0a53ee0b442 NFSD: Prevent client use-after-free during delegation revoke 969b1fefb07d1 nfsd: convert global state_lock to per-net deleg_lock 6d6b9f6a75c37 nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache 9031493ef7369 nfsd: fix UAF in async copy cancel and shutdown ba0ee9e04b7a0 nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net f9cec313efb2f nfsd: fix clock domain mismatch in clients_still_reclaiming() 03c512f22d3fb nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage ccc069d5c47cd nfsd: move struct nfsd_genl_rqstp to nfsctl.c 430ed49a16cf9 nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() 380d138a6b086 net: advertise TCP MSS from the configured MTU, not the learned PMTU cfb44c6028e6f tcp: clamp route advmss to TCP_MIN_MSS ea44679bc7d21 ipv4: use dst4_mtu() instead of dst_mtu() a615a2c8c3062 ipv6: use dst6_mtu() instead of dst_mtu() 920dacce8734d inet: add dst4_mtu() and dst6_mtu() helpers b650560c5ee21 ipv6: add some unlikely()/likely() clauses in ip6_output.c a294168185fe8 ipv6: pass proto by value to ipv6_push_nfrag_opts() and ipv6_push_frag_opts() 194d0fb0ea472 fuse: copy request headers via a stack buffer for io-uring b96b0d2c25d14 fuse-uring: use named constants for io-uring iovec indices f12ebb0a3ed7d fuse-uring: refactor setting up copy state for payload copying 121fc8edf5832 fuse-uring: use enum types for header copying c46805193fbef fuse-uring: refactor io-uring header copying from ring 6bb5347e9f8aa fuse-uring: refactor io-uring header copying to ring 8974575898cd7 fuse: fix missing barrier when checking io-uring readiness f1c91222188be PCI: starfive: Fix resource leaks on error paths in host_init() e5c1d10003b4d PCI: starfive: Use regulator APIs to control the 3v3 power supply of PCIe slots 0d72e78c9d38d lockd: fix swapped arguments in nlmsvc_match_ip() fcfcba8fe17db ocfs2: validate directory-index entry counts when reading metadata 625e00fd25ef5 ocfs2: validate dx_root extent list fields during block read a1dabe68fb537 ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page a6f3b8dfbdf4f ASoC: codecs: aw88261: only check PLL and clock state at power-up 0ac722e964cdc ASoC: codecs: aw88261: reduce log spam d013b7de4dccf remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check d6eab9066be0f firmware: qcom_scm: Rename peripheral as pas_id 9d69422ddaa13 sched/core: Make core-sched flips wait for in-flight selections fef4b8f17e1c5 sched: Rework prev_balance() to avoid stale prev references c522333c35d48 sched: Add assert_balance_callbacks_empty helper c97be9d5ab04c sched_ext: Fix inverted ops.core_sched_before() invocation c4ade059aaeb5 scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock c98197ee3cd28 RDMA/ionic: Embed counter driver data in rdma_counter allocation 27b7b0dacae79 sched_ext: Fix exit_task leak on fork failure during enable 1a3af2262cb38 svcrdma: Reject Read lists that exceed the page budget 59bcf1b38f898 svcrdma: Reject oversized Read segments at decode time 3c97b8e76ca2b rpcrdma: arm rn_done before publishing the notification 9f2f5d0999364 svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id ee7f6e5600ae1 svcrdma: Release transport resources synchronously 3ff45361e9469 SUNRPC: fix gssx_dec_option_array error path bugs 5563db13c9528 cxl/mce: Make the MCE notifier per-region 513a9613f7a63 cxl/region: Add helper to check Soft Reserved containment by CXL regions 040cface98ffd dax/cxl, hmem: Initialize hmem early and defer dax_cxl binding dfc86b0c2698e cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register ccf481d73bce6 bpf: Disable preemption in bpf_get_stackid b466ff95324f8 bpf: Use stack id functions instead of __bpf_get_stackid 73ebef25aec49 bpf: Factor stackid_new_bucket from __bpf_get_stackid ba1e22a224c39 bpf: Factor stackid_fastpath function from __bpf_get_stackid 201a381bef3ac bpf: Factor stackid_init function from __bpf_get_stackid 7c19b94c625dc cpufreq: apple-soc: Fix OPP table cleanup e989cede44392 ACPI: TAD: Add locking around AML evaluations dd440f6a2e67f ACPI: TAD: Rearrange RT data validation checking 0a7a192862232 ACPI: x86/rtc-cmos: Use platform device for driver binding ec2d81115485d ACPI: x86: cmos_rtc: Create a CMOS RTC platform device f2e08c3f994c9 ACPI: CPPC: Reject desired_perf reads on _CPC revision 4+ 7267557ce98cc erofs: skip sufficiently large global buffers when resizing 03c34309eb1bc HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes 1a503fbb116da HID: mcp2221: fix OOB write in mcp2221_raw_event() 3b4709e486490 HID: sony: clean up device list on probe failure a15def9a6311e HID: sony: use guard() and scoped_guard() d2dd2cced65bc cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie() under i_rwsem 85d239160dc1b smb/client: emulate small EOF-extending mode 0 fallocate ranges 41f4c99787398 smb/client: reduce fallocate zero buffer allocation c2ae13662137c smb: move some definitions from common/smb2pdu.h into common/fscc.h 110747ff535e3 ceph: properly decrypt filenames in vmalloc() buffers 104a51265042b NFSD: Guard admin state-revocation walks with NFSD_NET_UP 0e763ab306a81 ceph: force a cap message when a deferred revoke can't be acked immediately c040e139f1a62 ceph: cap delegated inode count in ceph_parse_deleg_inos() 8bd3523df1319 cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read 6f9b62687a383 cxl/pci: Move CXL driver's RCH error handling into core/ras_rch.c 153b5ecd29ed0 usb: gadget: f_fs: Fix Use-After-Free in AIO error path f3d31484b3f26 USB: gadget: ffs: fix mm lifetime handling 06c76d3c389ff mm/page_alloc: don't spin_trylock() in NMI on UP 22bbde1960d1d x86/xen: fix init of balloon stats again 6f53c64a880ff xen/balloon: improve accuracy of initial balloon target for dom0 b4a6050bde9ec mm/slub: fix missing debugfs entries for caches created before sysfs init d08ea0fd70386 mm/slab: move and refactor __kmem_cache_alias() e7bd804e3c719 mm/rmap: use huge_ptep_get() in try_to_migrate_one() 54a58d6656dd4 mm/mglru: fix and remove redundant unevictable folio handling d4812d21689f1 mm/mglru: use the common routine for dirty/writeback reactivation 09505232eced5 mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier daeffb841bb96 mm/hugetlb: refactor code around vmemmap_walk b662d7bcb5ecd mm/hugetlb: defer vmemmap population for bootmem hugepages edc017be82664 rust: bug: prevent dead_code warning from warn_on!'s flags constant cf24ce48d6022 pidfd: hold exec_update_lock around namespace ioctl 7aa9ab5321589 pidfs: simplify PIDFD_GET__NAMESPACE ioctls 2fa220bc0f845 ovl: fix double end_creating() on the casefold-mismatch path 1c4b90902c05c crypto: atmel-ecc - avoid stale fallback key after set_secret failure 5c1e763b713f0 crypto: atmel-ecc - clean up and improve ECDH comments e39767b9a54d9 crypto: atmel-ecc - replace min_t with min fc933a4a419ba crypto: iaa - unmap dst before software fallback on decompress 4fcbc9f4082ca crypto: iaa - fall back to software for multi-entry scatterlists 1517d1996b523 vlan: fix skb_under_panic and races when toggling HW VLAN offload ed25ed29034dd net/packet: defer vmalloc TX_RING free until skbs finish 0f93090445294 fuse: fix race between interrupt and resend f98640c27cde3 fuse: remove fm arg of args->end callback 952f7a6d392b8 fuse: split off fuse_args and related definitions into a separate header a5bb215dbc34b fuse: publish io-uring queues with release semantics c051f66b62169 usb: xhci: bail out of setup if the controller is inaccessible f0ccc2d323d06 usb: xhci: simplify handling of Structural Parameters 1 values 46fb722a3bcf0 usb: xhci: use cached HCSPARAMS1 value 4e141571d0257 usb: xhci: implement USB Port Register Set struct 8dbc9c86c3186 usb: xhci: add USB Port Register Set struct 8b7ca0029e94b usb: xhci: add helper to read PORTSC register a363197790a87 usb: xhci: add tracing for PORTSC register writes 78e8ee25a5e8f afs: Fix leak of ungot volume c8279ae8df68c ksmbd: fix use-after-free in oplock break notification e5e7a61fa9e82 drm/nouveau/gsp: fix vblank interrupts on GB20x dc7c40ffaa1b6 drm/nouveau/disp: fix head state readback on GB20x 0e346b65a4130 drm/nouveau/disp: fix HDMI GCP AVMute register offsets on GB20x ecb110991bc94 drm/nouveau/disp: fix HDMI vendor infoframes on GB20x 4739d519def72 drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks 94d8195eb4185 drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp a046e789ab66e drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c 1101cbfe7f342 drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE 24c25b182d17d drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE b7dc03e09313d drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op 4cf436de06ca9 drm/nouveau: Use write-combined maps for coherent f3830fdd6930e drm/nouveau: unsubscribe the channel-kill event before the fence context 5ba4bcb3b96cd drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware 859d8b6c5b274 drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug ded6ad826fe0f drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation 6892f0a2f6b59 drm/sysfb: simpledrm: Improve stride validation 54e32ad5e0c74 drm/sysfb: simpledrm: Improve panel-size validation 8d65b8d1722d8 drm/sysfb: simpledrm: Improve framebuffer-size validation fd3462acf6590 drm/amdkfd: Reject zero-sized AQL queue allocations after size halving ebffa44e7a21e drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore ae806a95b28fc drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram da87bcad1f781 drm/amdkfd: Fix error path at svm_migrate_copy_to_ram e230c546ed937 drm/amdkfd: Add TLB flush after MES queue eviction/suspension 2e4b909fab96c drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT 65e643703f150 drm/amdgpu: update the fw version for gfx12 userqueues b7cb1b6696137 drm/amdgpu: update the fw version for gfx11 userqueues 8de8b4e11ce48 drm/amdgpu: Skip accessing psp rum time db for APUs 492dbf832964c drm/amdgpu: fix autosuspend cleanup during removal 812c406f75291 drm/amdgpu: Disable runtime PM for externally attached dGPUs 964de255497ff drm/amdgpu: clamp the isolation index for rings outside a partition b3a7e0b69903e drm/amdgpu: check thunderbolt before switcheroo registration 66b1b30988633 drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used acd2dd6ecd89e drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value 72a95df6bbc7d drm/gud: validate TV mode names before creating enum property b86438a5c6b02 drm/gud: NUL-terminate TV mode names read from the device 7e28853c78c20 drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check 0b2615b8b54f5 drm/amd/display: validate plane degamma LUT size for private color prop 295d2bf42061d drm/amd/display: fix dc_lock leak on GPU reset error paths ee28fafb50f58 drm/amd/display: avoid divide-by-zero in __is_lut_linear() 4ac7677221754 drm/hibmc: Use drm_atomic_helper_check_plane_state() ed38f0be5b61d drm/hibmc: Fix list of formats on the primary plane f5acd8f48cacc drm/nouveau/disp/r535: Add scanline position support + head state support 6f9bdbe713fdf drm/ssd130x: fix column and row end address in partial updates in ssd133x 6f776d0e43e04 drm/sun4i: fix refcount leak in sun4i_backend_init_sat() 63c70e292e6b4 drm/ssd130x: fix column and row end address in partial updates for ssd132x 18b3433f10ee9 drm/i915: Guard against NULL driver_data in i915_pci_probe() 79d09cfe90304 drm: fix race between partial drm_dev_register() failure and ioctl 0259846b15a66 drm/panel-edp: fix i2c adapter leak on probe failure b51d8fb5e58c2 drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure 80c9528661c77 drm/panthor: fix firmware control interface bounds checks 5516f1acfd075 drm/panthor: harden firmware build-info bounds checks ef41e8e4ae5b7 drm/xe/vram: report FLAT_CCS base misalignment e184e46ca1ba6 drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() 91ec55ddc097c f2fs: fix to zero post-EOF data when extending file size a984446aa9d5b f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() dde99df5a9d3b f2fs: fix valid block count leak on data block allocation failure ab35ae07f2b5b f2fs: fix to clear dirty flag on folio in error path c16cc4622e4b6 f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() f6c49fae98f0f f2fs: fix i_size when pinned fallocate partially fails 161513f53e4ac f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() b8ae1228c1536 f2fs: fix to migrate all curseg types during free_segment_range aefcec3bebdee f2fs: avoid NULL checkpoint thread access in sysfs aefb4b0f465b6 f2fs: fix dentry folio leak in find_in_level 94917ffab3a94 f2fs: fix to avoid potential section-unaligned pinfile 3e61c3944b83c f2fs: return writeback error from collapse range 3b681229e9f8f f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() db504781ea9b0 f2fs: dirty directory inodes on mtime/ctime update dc652b2fe916c f2fs: fix to avoid move_range and defragment on device_alias file 445e4a1e6025e f2fs: only redirty pinned folios in redirty_blocks 7f89e2775d5bb f2fs: reject overlapping move range after len expansion 95d5975c9d1c5 f2fs: return symlink writeback errors ac4b019ac0784 scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started 4fe5790674097 scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak 0bdd0f7a1094a scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics 776e4e8cbcf15 scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition 16c731c4f2961 scsi: qla2xxx: Drop vport reference under lock in report ID acquisition 17fb63c1d0fcd scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort 5dd9bec8004ba scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() d7f7746ff031a scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 9fa1d71233a82 scsi: qla2xxx: Avoid double completion in async IOCB timeout 10e9f05f7fd0a scsi: qla2xxx: Quiesce response IRQ before freeing request queue 31715d1e1cbf3 scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() e93aa3c5125d9 scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path a194684853dce scsi: qla2xxx: Don't query firmware state while chip is down 7203d4aed8f44 scsi: qla2xxx: Fix FCE trace enable parsing in debugfs e6cfb1ee18336 scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() 8e7a26931b611 scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump 8286a9095fb59 scsi: qla2xxx: Fix cs84xx use-after-free on host teardown 8d11613711937 scsi: qla2xxx: Serialize flash version read in reset handler 7a448f5ed0b28 scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation 11834e5773e20 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 7b22b4cb88228 scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() 5ecdb336df2a9 scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() 67f0d5187c293 scsi: qla2xxx: Initialize NVMe abort_work once at submission 47272152a13d2 scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() 206df5ffa72dc scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters 94bfb61478bcb scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check 97ca58b0fb026 scsi: qla2xxx: Bound i2c->length in I2C bsg handlers b157256c28086 scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers dec5624a3f8cb media: chips-media: wave5: Set inst->std during default format initialization a0506198a77b9 media: chips-media: wave5: Guard bit depth check with initial_info_obtained ff98cd2b8b54c media: qcom: iris: use disable_irq() during power-off ab6f088a44ef7 media: qcom: iris: fix state-change debug log printing stale value f1c4f3885df1f media: zoran: Avoid freeing a registered video_device twice dc005cb7ccb0c media: vimc: fix pixel format lookup in enum_framesizes 52fd9d80c0cea media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure 4a187d9443845 media: venus: fix payload size calculation in parse_raw_formats() d031b5ecc4b39 media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() 3ced388b79082 media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link 331f22dd63bf9 media: v4l2-ctrls: Allow unknown HDR10 white point and luminance 3345746e0957b media: v4l2-async: avoid deleting unlinked ASC entry on link error 7c62bd6535639 media: tda18250: fix possible integer overflow 4d2048466af9e media: saa7164: fix cleanup on resource allocation failure 342632a4d8ba3 media: s2255: check firmware size before reading trailing marker 68d664f1b4efe media: s2255: bound JPEG frame size before copying into the buffer 93e6ed88f5084 media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement 26a2a985bbeee media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure 7443b16b6dd88 media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak 12b88016c199e media: rkvdec: Propagate platform_get_irq() errors 5b58d8c206f37 media: rc: sunxi-cir: Unregister rc device on probe failure 8281acf5d7049 media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks 9392375dd4c01 media: nxp: imx8-isi: Correct color map between V4L2 and ISI 2f9b2768d5ceb media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing 5026f927ef415 media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup 252850653569f media: platform: mtk-mdp3: Fix SCP device refcounting 96dafbae77f50 media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common 24aca88390388 media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder 27b7997be552e media: intel/ipu6: fix async notifier cleanup leak on parse error 1d59c5254c33a media: imx355: Avoid calling imx355_power_off twice in error path af81f35e4f429 media: i2c: ov7740: fix use-after-destroy in remove 90f9b421fc6d4 media: i2c: ov02a10: fix endpoint parsing use-after-free 4f8fd40b39bf7 media: i2c: imx415: Return test pattern write errors 1aa66bb3ba440 media: i2c: imx415: Release runtime PM reference on VBLANK error 312c68e9ed8a4 media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure 0745a59945d92 media: go7007: defer the ALSA v4l2 put until card release 0782807552b6a media: em28xx: fix use-after-free of dev_next->devlist on disconnect f9322ac9f8629 media: em28xx: defer audio-only extension registration bf3f49273d5bf media: cx23885: cancel NetUP CI work before teardown 7087bef6510c7 media: cx231xx: reject geometry changes while the VBI queue is busy cb1218da234ea media: cobalt: Avoid freeing ALSA private data twice f78cf36cabf91 media: cedrus: fix memory leak in cedrus_init_ctrls() 5c62095acc2a9 media: cec: Serialize exclusive follower delivery 38c14532adb34 media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash 673611cc2ab97 media: cec: extron-da-hd-4k-plus: add sanity check a3adb63b12193 media: cec: disable delayed work before freeing an interrupted transmit 695063fc57574 media: cec: core: Fix kmemleak due to missed rc_free_device() call cb7a4cf63fa20 media: amphion: Remove obsolete frame_count check in venc_start_session 297fee023f46d media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref 347e9d2246b89 rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments 76395109a051b LoongArch: Avoid preempt count underflow without probe 266ffc92e6859 LoongArch: Do not save/restore percpu base register in rethook trampoline d692b825dc246 LoongArch: Do not select HAVE_RUST when KASAN is enabled d3fd094c13c6d LoongArch: Fix acpi_package_ids[] array overflow 882b8912b7e92 LoongArch: BPF: Refactor jump offset calculation in tail call 462e6abc8293f LoongArch: BPF: Optimize redundant TCC loads in epilogue ab275a23b4d9f LoongArch: Add DIRECT_MAP_PHYSMEM_END definition 4e4dbc341b158 LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY 6b78786ee7260 LoongArch: KVM: Free init resources if kvm_init() fails 07c3037e45c94 LoongArch: KVM: Fix TOCTOU race on pv_features b7fab314ade26 LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path 566b1f08d9836 KVM: arm64: Correctly cap TLBI Range to the architural limit 3d4c26b16a04a KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save 2f1a571af300e KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure de9b4e8f37ce6 KVM: arm64: vgic: Fix detection of MI on no pending LR 7631f95297560 KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables 72bce82c4171b KVM: arm64: Sign-extend VA for range-based TLBI invalidation d8580e7aa189b KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry ce447651a52ec KVM: arm64: Correctly handle end of VA space TLBI invalidation be54a70067c7d KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 6408605cbd509 KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page 150c43473dcf0 KVM: s390: Restore sigset on error path 5ed801685a8a3 KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP 6ee52d3af2a1b KVM: s390: Fix memory corruption by not reinjecting CK machine checks 3904a3296e40d KVM: s390: Zero initialize irq in reinject_machine_check cc710ee45395e KVM: s390: Take srcu when importing watchpoint data b5acacfdb8966 KVM: s390: Free guest debug data on vcpu destroy f55e4d415d953 KVM: s390: Fix old_data leak in guest debug error path 44bf3792c10f4 KVM: s390: Fix memory leak in guest debug handling beb9c55af609c KVM: s390: Fix length check __import_wp_info() 39f7abd5927bf KVM: x86: Ensure runtime reads of disabled_quirks are resolved once 929fd2d87851a KVM: x86: Serialize writes to disabled_quirks using kvm->lock 3097582b73a8e KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock 41debfc98526c KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk 7b2721d66525f KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot 0a25ee42e7d1a KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU e29e9a9d81140 KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves 93b7f6eb76a13 KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() 27bdeb5fd1904 KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU c43563e7518e6 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 674a3244f07f3 KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit d689dd4eae48d KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 22dfcc22c95e9 KVM: nVMX: Always flush vpid02 on first use 5778dda871f15 KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode c9f2c50bad37d iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask b6cedf011bd95 iio: light: opt4001: Reject integration times with a non-zero seconds part 958d691403936 iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() 4a9820aa8ef7e iio: light: opt4001: Fix power down clearing bits of the wrong register 6d00b4fec5bf2 iio: light: opt4060: Fix incorrect register name in threshold read error message 38f58a0249666 iio: light: opt4060: Reject integration times with a non-zero seconds part fcddb4da54ab9 iio: ti-ads7138: Disable STATS_EN bit while reading conversion results c0d491c243e70 iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() c2d6437663d7c iio: srf04: fix pm_runtime handling on probe error path eef652190b00f iio: pressure: mpl115: Fix runtime PM cleanup 7ded5b76ec2df iio: pressure: dps310: fix NULL pointer dereference on ACPI probe 0614928a3eda3 iio: light: ltrf216a: fix runtime PM reference leak in error path 1ce47f00e9c00 iio: light: gp2ap002: Disable regulators on resume failure 9c1b74fdcffa4 iio: light: cm32181: return zero after writing calibscale d2b32b71fa5bd iio: gyro: mpu3050: fix sign of raw angular velocity readings 08ac8d2976d57 iio: dac: m62332: Fix regulator reference count imbalance bcc324f3033cd iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show 2d386efb4c37a iio: chemical: sgp30: Handle IAQ thread creation failure 2071624c3d0f4 iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF 43bce901047e9 iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable 510497e31be4f iio: buffer: Tie IIO dma fence lock lifetime to the fence 06a9460b8b792 iio: buffer: Make IIO DMA fence release RCU-safe f1f8f0e8e0af9 iio: buffer: Fix potential use-after-free in anonymous buffer release 8de90e0e0f6d9 iio: adc: pac1921: fix wrong channel used in trigger handler read beec14368c943 iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig d2ed166c901e9 iio: adc: adi-axi-adc: add data size support for AD408X backend e9627244ac0d7 ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get 4e580d84a638f ASoC: loongson: Fix error handling in ACPI property parsing e11b056d69b8c AsoC: intel: sst: fix PCI device reference leak on probe failure e8ea01a045708 ASoC: hdac_hda: Fix hlink refcount leak on component registration failure 0966b76a0e23c ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division 5ca4bd7543524 ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure 5a4fe7a87841a ASoC: cs35l34: drain threaded IRQ before runtime suspend 6e369bc46663b ASoC: cs35l33: drain threaded IRQ before runtime suspend eb5d39dd862f5 i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure b2b87f2e0bb16 clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks 4763197c6f344 clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk bd326b0c5b339 clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk c67fc2fd71395 clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src 206a6e21a0cf4 clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src 526b0a71a4d91 clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src cc2941bc37351 clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk 51b40cb17c216 clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk 4582949b7badc clk: meson: align gxbb_32k_clk_sel number of parents with actual count 88fe6792be2b3 clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen 05952e503cf65 clk: clocking-wizard: fix integer overflow in rate calculation 82f78c2b3af8f batman-adv: bla: prevent CRC corruptions after claim flush 871acdf97f64c batman-adv: bla: fix freeing of claims on meshif deletion 1cfa7d5f70d54 batman-adv: dat: avoid unaligned fault in IP extraction c32e5e25c4120 batman-adv: mcast: linearize skbuff for packet generation cedacfecf4b40 batman-adv: mcast: ensure unshared skb for multicast packets e91d2cc7441d8 batman-adv: fix stale receive device on merged fragments c8f86e375b39c mtd: rawnand: validate ONFI extended parameter page sections 4b282dc6a9e96 mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE() d06f91a52af11 mtd: mtdoops: free page bitmap when the backing MTD is removed 18916f475057c mtd: afs: validate v2 image info bounds e8bcb9d54429b s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object 6d554f2571e6b s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap 69632952aca04 s390/vfio-ap: Fix NULL deref in status_show() during queue probe 647916988272f s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects c45753c32d452 s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed 178ea7a1c2c3c s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL f7d66afc34bc6 s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove 3c5f51f257e14 s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove fc069d00a0dbe s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() 3b90d769b351a powerpc/crash: stop watchdogs before booting kdump kernel 36dcb8c2e3391 powerpc/pseries: Move H_WATCHDOG definitions to a common header d2be3dd20e833 powerpc/pseries: Handle and log pseries-wdt registration failures 9c914b7a0bd18 powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population da88a2a2119e4 powerpc/kexec_file: Prevent kexec range truncation df45337587db2 powerpc/kexec_file: Fix null-ptr-def in extra size calculation 6ae9306c75981 parisc: Fix alignment of asm statements in head.S 3e2691eeee83a parisc: eisa: Fix infinite loop when parsing invalid IRQ value 6b1faf1f099f7 nvdimm/btt: reject an arena whose nfree is below the lane count bdd929e60bc54 mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON() 631d8f39b33e7 mm/hugetlb: keep max_huge_pages when dissolving surplus folios ae6a8b0c69901 mm/hugetlb: fix missing migratable flag on same-node hugetlb migration 8e287f463fc4f Revert "irqchip/mbigen: Fix mbigen node address layout" 6e96e2bb1065b pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig cf1484d9a75de nvmet-tcp: reject unsolicited H2CData PDUs dbc4acbdb3ca8 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 7555ddd60af72 nvmet-auth: Synchronize timeout work during SQ teardown d663944dbad81 nvme: add missing SRCU grace period in error path b4af7999a9987 nvme-tcp: check the data direction of a C2HData PDU 7df913a7ced5d nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails 15d7a35a48928 nvme-fabrics: fix DHCHAP secret leak on parse failure 7ad2ea7c10044 ALSA: pcm: Fix race between non-atomic ops and trigger-start 89992bda7dfbb ALSA: harmony: initialize locks before requesting IRQ 1e67ad10373ea ALSA: rawmidi: Return the error from snd_rawmidi_input_params() cd090af03f5df arm64: errata: pass REVIDR when matching target implementation CPUs 68cbd70795dd8 arm64: mm: Fix the lockless page-table walk in show_pte() 2b3b06cb709c4 i2c: mux: Fix channel node leak on adapter add failure 112b3d48084c8 i2c: core: fix debugfs UAF on adapter removal 954f30c8df0a0 i2c: qcom-geni: update frequency table to fix timing parameters c643b6e7852e9 i2c: designware: Enable interrupt mask workaround for HJMC3001 19d65da9f7497 perf hisi-ptt: Fix PTT trace TLP header parsing 2421389840738 perf trace: Refactor augmented_raw_syscalls using bpf_for f3a6663138496 perf trace: Factor out BPF loop body 3c492c8eba026 perf/x86/intel: Fix kernel address leakages in LBR stack 267f0a4fb9fe7 rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers 3a2b79eae5bef rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm a4d6666a65d6f rtc: rzn1: Fix weekday underflow when alarm crosses month boundary 350cb7821b3d2 rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt 0a90e268cce70 memcg: make the v1 soft limit knob inert 801bcbdbfd595 memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done 7269bd95d707e Input: aiptek - validate raw macro indices before updating state d07e281f2a771 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 4d6ccd3883df6 fs/ntfs3: fix KMSAN uninit-value in ni_create_attr_list 0ceda28f371df mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() 5da247e4d1e86 kprobes: Protect kprobe_blacklist with RCU 863f6726a5c02 irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout f8a2f2a460231 ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() 685c195fbd7d4 ata: ahci: work around lost interrupts on Marvell 88SE61xx ca5bfea2045ef ceph: lock mutex in ceph_mds_check_access() a24a146ae2cb5 bpf: Fix infinite loop in pcpu_freelist push with one possible CPU bfb469f20aa9e block: flag zoned disks with GENHD_FL_NO_PART 634e2d23736d4 cpuidle: psci: Fix support for probe deferral by dropping the faux device b519dfce1998c cpuidle: dt_idle_genpd: kfree() the original name allocation fac202d73e7a6 dmaengine: dw-edma: Initialize IRQ data before requesting IRQs 8fd47ccbba86c dmaengine: dw-edma: Complete descriptors before pausing 3b313f7a00d14 dmaengine: dw-edma: Fix HDMA channel status register access d382aaf5fed38 dmaengine: fsl-edma: tracing: no ptr dereference during log output 408ff2d5bf555 dma-direct: return struct page from dma_direct_alloc_from_pool() 36177beff2a9d dm: fix resume-vs-remove race af1f32ccf8051 dm: fix race when loading and unloading a table 74ec08f7b81c2 HID: wacom: validate report length in wacom_intuos_pro2_bt_irq f4cb9c4556dcb HID: rmi: fix OOB access with undersized RMI reports c7f927aa8b550 HID: bpf: serialize device reference release in struct_ops destroy path 078adc03f6e60 ftrace: Synchronize the initialization of ftrace_ops 7d1559126d86b futex: Prevent rcuwait use-after-free during requeue PI 1cd41131bc4b8 mm/damon/core-kunit: check region count before testing in split_at() 382e58c24eabf mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs 368f84ec79104 mm/damon/sysfs: kobject_del() region and target (error) dirs 23c7b91895ff0 mm/damon/sysfs-schemes: kobject_del() scheme region dirs 20a40e7eb5ec3 mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs e608e7bbe82cb mm/damon/sysfs-schemes: kobject_del() scheme filter dirs 8a1ebb241fc70 mm/damon/sysfs-schemes: kobject_del() scheme dirs b9847d539b9c8 mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs cb55606449fd6 samples/damon/wsse: stop and free damon ctx when damon_call() fails 6179c7f47876d samples/damon/wsse: handle damon_start() failure 2446d3820cbaf samples/damon/prcl: stop and free damon ctx when damon_call() fails 9f370353bba7f samples/damon/prcl: handle damon_start() failure 3c07c57b89411 samples/damon/mtier: handle damon_stop() failure f0808262a7616 samples/damon/mtier: handle damon_start() failure 71de5a082d2ca mm/damon/vaddr-kunit: check region count in three_regions test dd817463c9b42 scsi: pm8001: Use rollback index when freeing MSI-X vectors 4bb34769ef44a scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame 1624bff4c5118 scsi: target: iscsi: Reserve a terminator byte for the login payload a38051fa2dded spi: Fix DMA mapping ownership on partial map failure 148a3f03aec89 spi: bcmbca-hsspi: disable clocks on resume failure 0acbfd61aee18 spi: bcm63xx: disable clock on resume failure b782a7cb0a424 spi: bcm63xx-hsspi: disable clocks on resume failure 907752a7b64a6 soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size e373c1acdbcf8 ublk: clear VM_MAYWRITE on read-only ublk char device mmap 89f06342743ca userfaultfd: reset err to be 0 when move_pages_ptes succeeded 65c2029f3bbae thermal/drivers/qoriq: Disable clock on resume failure ec2db87a0bbb8 thermal/drivers/imx: Disable clock on runtime resume failure efaab8938fb92 xhci: fix lost bounce buffers on TDs spanning several ring segments b041e3f35e0d2 staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() ff61aa3289355 staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() d3a7fa61997db usb: gadget: fix null pointer dereference in usb_put_function_instance() c29a83c1ff3f0 USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() 02ac76f27db23 usb: gadget: f_midi: initialize work in f_midi_alloc() e89e30f0b5d30 usb: gadget: f_midi2: fix use-after-free in string attribute show path 9c3d5091e3568 usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs 33a81acd2d1d0 usb: typec: ucsi: displayport: Fix OOB altmode array index 6be5169e7615d usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x 42828aeb40b4a usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling d4e00a1eb3917 usb: typec: qcom-pmic: cancel reset_work on stop 1e4f33f99bfb7 usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails c614d7c44ca7f usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop 7c4e2f964c65d usb: storage: realtek_cr: fix use-after-free on disconnect 0afe5c31612de usb: dwc3: clear forceRM when issuing EndTransfer 62a8b67960637 usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() 1c67f2ba9c5f7 usb-storage: ene_ub6250: fix race between scan work and probe 7690a86b19327 media: usbtv: keep device alive while ALSA card exists 296a884cd6feb clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset 9392a2c346762 ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() 838455cc8bfe1 usb: image: mdc800: change kmalloc() to kzalloc() 4814f28c45f58 drm/amd/display: fix division by zero in get_estimated_bw() 12ee39c2b1d3c bpf: fix the return value of push_stack c96477e0cabf5 drm/xe: Don't hand out the flat CCS storage as usable VRAM a6b088bee95fd fsnotify: inotify: pass mark connector to fsnotify_recalc_mask() 0ec897493ff82 drm/amd: Drop calls to restore power limit and clock from smu_resume() 0b6680e306397 mfd: qnap-mcu: keep the reply buffer alive past a command timeout 617b48fc0baf0 objtool/rust: add one more `noreturn` Rust function 947400af98b9e fsnotify: Fix stale object mask after concurrent mark updates 459f33f828647 entry: Fix seccomp bypass after ptrace with TSYNC b5a5d389eee65 mm/page_vma_mapped: use huge_ptep_get() for hugetlb e15407c3a8a00 openvswitch: Fix CT limit teardown use-after-free a13b1e80e5015 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 3ab0b618ccd761fdaf325fec2657ec36f0a9544b) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 6 ++--- .../linux/linux-yocto-tiny_6.18.bb | 6 ++--- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++---------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index d4ca18a7b20..31a0294070e 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,13 +15,13 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "ed7481e8a1df4a3417915acd6bef5a72d6fa71bb" -SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" +SRCREV_machine ?= "c191bb993af1f71ef139504fcce530a9ba167a0d" +SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" -LINUX_VERSION ?= "6.18.50" +LINUX_VERSION ?= "6.18.52" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 56a3d18ee5b..1b7575be0cd 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc -LINUX_VERSION ?= "6.18.50" +LINUX_VERSION ?= "6.18.52" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}" @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" +SRCREV_machine ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 719c1fa51a8..055a2d39ddb 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "dbe5ee845060d0b8ddf934a2e3d96627fdb1bd81" -SRCREV_machine:qemuarm64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_machine:qemuloongarch64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemuarm ?= "4932d76684b2bc2cbf8dc6e0e46ada17ad020c71" +SRCREV_machine:qemuarm64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemuloongarch64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_machine:qemuriscv64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_machine:qemuriscv32 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_machine:qemux86 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_machine:qemux86-64 ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" +SRCREV_machine:qemuppc ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemuriscv64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemuriscv32 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemux86 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemux86-64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "aba8c69040fd3d5763477a733b4696a79c0514e1" -SRCREV_meta ?= "bf8faf1b184fcf6c555ee951f501e76f88eccf35" +SRCREV_machine ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same # meta SRCREV as the linux-yocto-standard builds. Select your version using the # normal PREFERRED_VERSION settings. BBCLASSEXTEND = "devupstream:target" -SRCREV_machine:class-devupstream ?= "7cfc41f8e80f11ffa8382ed1a505154ceffb79c7" +SRCREV_machine:class-devupstream ?= "8f3741e6feb045da5b406df0a80b42a1adfb289b" PN:class-devupstream = "linux-yocto-upstream" KBRANCH:class-devupstream = "v6.18/base" @@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" -LINUX_VERSION ?= "6.18.50" +LINUX_VERSION ?= "6.18.52" PV = "${LINUX_VERSION}+git" From patchwork Sun Sep 27 07:43:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yoann Congal X-Patchwork-Id: 99309 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CA11EC98324 for ; Sun, 27 Sep 2026 07:44:07 +0000 (UTC) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.33595.1790495041665035539 for ; Sun, 27 Sep 2026 00:44:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@smile.fr header.s=google header.b=lvkVOgwO; spf=pass (domain: smile.fr, ip: 209.85.221.41, mailfrom: yoann.congal@smile.fr) Received: by mail-wr1-f41.google.com with SMTP id ffacd0b85a97d-488885c3844so555012f8f.0 for ; Sun, 27 Sep 2026 00:44:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smile.fr; s=google; t=1790495040; x=1791099840; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=+sG5nRZk3pCIl/yle+TyxluPh/3N/xw+nJXJF405Cp4=; b=lvkVOgwO9EndLoXuc6Ux8neVLQY0Posl78+Q1yxLiGCJIR7zYJ5CF/4B0C+5v4x6gZ JR7npzTdv3uZ98Zj7ZIpa2UUyo+nBzYfXmxF7S7/RmNoA7W7JU+L8abA0i054L2HG8DL oRiEhdTw7F9rG4qWuMSC+J+Q2t+Saw7MJ3LKE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790495040; x=1791099840; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=+sG5nRZk3pCIl/yle+TyxluPh/3N/xw+nJXJF405Cp4=; b=2TGRvSgHy4uallNNifo4iqhk2vV2wqRhTRvzQeBqUTux5rlBnjxdJMOY2yWZe3EZgs Yt0uuUyIYxVUJs2ZqdprPxoTWSdKxRypN6cyU7x+RZHTws4cpaU0K+V06lBT8qmIJfRe rBzXjkAj7JxHl+p0z+fl5o3cX3LpEmqbm6YTc4W/Zpoxm8i/OmV/+H11kYvYJ7VdhfbK W3HOJ03pW69pnJ0m/eEspyh1ljNx4CAhS0ZlHjU1VQC/gtKAf3H75pNtKZu52++Hqbfh rWObBje6XvpXoqJwRIqff2Prma2uFA9yWsFCjAbN7ffx4m0zPaW6QWzAFW5bVz+w2YKV tN2g== X-Gm-Message-State: AFq9FYJMfK7Jb4I3QUbc16hI2nGZkpSNmkJVejPLYTcro5rHySFd74p1 0P0CxkB/xuZycNkMgsA5JYNgkOQ5i9XluPX7/kf2XLz2jGSbpFcntDRUa1egnbPLPBtE75oPe3l TOccK2/8= X-Gm-Gg: AYBFou3hKkQxEGlL+JSyA6DmwUtJ+4pfihznW+nMvx/rYpDAXAIYtpfv5QaxoGw5OOw FEmCpkJqP6tn2+WROwMpHcu5YjgmYtEgTHNwN18u1nO7j6l9JgLb69emmIDwInsRME7q3DPg/wr oIjWDdLXvGB+SDppNLuC2MAmkMT3Wr0uPgDKzLXD8gPuk6uMFSbMEiPJ8heAV4CfAz8idWwyVst F1jOTc4mqz8lU9DUSScDmSDhxbQie0HBkht8szruY37ieYZpl3PKDXqaM+iS/9YO6yV3f32f+Ev V1kRsiyjiN4b0YE91rNPSd2zwcCXhM3tZTpodLnl+iOIXjR7OUsmhYeAqpjxdH6J/NIzqXc0hBC FnHdGt0RIQ+z8otxWjy9a5nKGw9On5vJnLoW+Vi/M+sZtIQSeI0gd3O0LEJQUbCe+AxX3tAUPmE loViRkWUkTsuiiVSQeoAxYeMUm2dykM6u0fytE4KULufNX2pWqnb4bKxbAEDbDL5S2EnbakGedn QuzuPBf5n1ah6ZcvxPgXWPcw50VUIFCM0+SCRwCNFvzkvl+e2M2NZQyEsfg4XBVblgF8VjBsw== X-Received: by 2002:a05:6000:2893:b0:485:8226:c69e with SMTP id ffacd0b85a97d-4887170dbf7mr19881845f8f.29.1790495039894; Sun, 27 Sep 2026 00:43:59 -0700 (PDT) Received: from FRSMI25-LASER.home (2a01cb001331aa00a2e4fb7b0d887544.ipv6.abo.wanadoo.fr. [2a01:cb00:1331:aa00:a2e4:fb7b:d88:7544]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4887a30c43asm19821375f8f.3.2026.09.27.00.43.59 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 27 Sep 2026 00:43:59 -0700 (PDT) From: Yoann Congal To: openembedded-core@lists.openembedded.org Subject: [OE-core][wrynose 28/28] linux-yocto/6.18: fix kernel reproducibility issues Date: Sun, 27 Sep 2026 09:43:19 +0200 Message-ID: <40993b0c42411caa5df71a75739b569fdffe981f.1790494949.git.yoann.congal@smile.fr> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sun, 27 Sep 2026 07:44:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/246677 From: Bruce Ashfield Integrating the following commit(s) to linux-yocto/6.18: 1/1 [ Author: Bruce Ashfield Email: bruce.ashfield@gmail.com Subject: x86/Kconfig.cpu: pin CC_HAS_MARCH_NATIVE off for reproducible builds Date: Tue, 22 Sep 2026 21:50:19 -0400 CONFIG_CC_HAS_MARCH_NATIVE is a def_bool computed from $(cc-option, -march=native), i.e. it is probed from the build-host compiler. In cross builds the result varies by build host: the kernel's own comment already notes "This flag might not be available in cross-compilers" So it is captured differently across otherwise identical builds and breaks kernel package reproducibility: .config / auto.conf: CONFIG_CC_HAS_MARCH_NATIVE=y (host A) vs absent (host B) autoconf.h: #define CONFIG_CC_HAS_MARCH_NATIVE 1 .config: # CONFIG_X86_NATIVE_CPU is not set rustc_cfg: --cfg=CONFIG_CC_HAS_MARCH_NATIVE With CONFIG_IKCONFIG=y the .config is gzip-embedded into the kernel (kernel_config_data), so the difference also propagates into vmlinux/bzImage/kernel-dbg (the blob shifts kernel_config_data_end and every symbol after it), failing reproducibility across the whole kernel package set. Not just the config text files, which is why a post-package filter is not sufficient. CC_HAS_MARCH_NATIVE protects only X86_NATIVE_CPU ("build and optimize for local/native CPU"), which is never enabled in these builds and is not something we should do in a distributed/reproducible kernel. Pin the symbol off so the captured config is deterministic regardless of build host. On-target 'make scripts prepare' uses this same patched Kconfig, so it recomputes the same value and needs no reconfiguration. Signed-off-by: Bruce Ashfield ] Signed-off-by: Bruce Ashfield Signed-off-by: Richard Purdie (cherry picked from commit 72473a0e03ef236072299b3fbf4efb555009a198) Signed-off-by: Yoann Congal --- .../linux/linux-yocto-rt_6.18.bb | 4 ++-- .../linux/linux-yocto-tiny_6.18.bb | 4 ++-- meta/recipes-kernel/linux/linux-yocto_6.18.bb | 20 +++++++++---------- 3 files changed, 14 insertions(+), 14 deletions(-) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 31a0294070e..03487e9f4a2 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -15,8 +15,8 @@ python () { raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it") } -SRCREV_machine ?= "c191bb993af1f71ef139504fcce530a9ba167a0d" -SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" +SRCREV_machine ?= "a23529ae3d1aa70979a3399f370638f3086587e3" +SRCREV_meta ?= "2184786cc3deed04926e1cca6c320ed9314da9da" SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \ git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 1b7575be0cd..d2bd34732f9 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native" KMETA = "kernel-meta" KCONF_BSP_AUDIT_LEVEL = "2" -SRCREV_machine ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" +SRCREV_machine ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_meta ?= "2184786cc3deed04926e1cca6c320ed9314da9da" PV = "${LINUX_VERSION}+git" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 055a2d39ddb..3008f1751f6 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -17,18 +17,18 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base" KBRANCH:qemuloongarch64 ?= "v6.18/standard/base" KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta" -SRCREV_machine:qemuarm ?= "4932d76684b2bc2cbf8dc6e0e46ada17ad020c71" -SRCREV_machine:qemuarm64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_machine:qemuloongarch64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemuarm ?= "49ec63d52f864d8cece5c6caa6be446362478003" +SRCREV_machine:qemuarm64 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_machine:qemuloongarch64 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e" -SRCREV_machine:qemuppc ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_machine:qemuriscv64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_machine:qemuriscv32 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_machine:qemux86 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_machine:qemux86-64 ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" +SRCREV_machine:qemuppc ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_machine:qemuriscv64 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_machine:qemuriscv32 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_machine:qemux86 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_machine:qemux86-64 ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4" -SRCREV_machine ?= "08edce0ecd6a36020447f51f11329b6641d3c0e2" -SRCREV_meta ?= "9e9d8b1f9128b07d938b8b7d5921aeb3ddf907a1" +SRCREV_machine ?= "364c4b44ab2dcc7dfff16076522b62827bcb0e7d" +SRCREV_meta ?= "2184786cc3deed04926e1cca6c320ed9314da9da" # set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll # get the /base branch, which is pure upstream -stable, and the same