Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kernel-source for openSUSE:Factory checked in at 2026-08-09 21:33:03 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kernel-source (Old) and /work/SRC/openSUSE:Factory/.kernel-source.new.16738 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kernel-source" Sun Aug 9 21:33:03 2026 rev:853 rq:1370211 version:7.1.7 Changes: -------- --- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes 2026-08-05 17:48:12.821444395 +0200 +++ /work/SRC/openSUSE:Factory/.kernel-source.new.16738/dtb-aarch64.changes 2026-08-09 21:34:17.924051318 +0200 @@ -1,0 +2,1338 @@ +Fri Aug 7 12:29:37 CEST 2026 - [email protected] + +- x86/mm: Fix and document DEBUG_PAGEALLOC (bsc#1271202). +- Refresh + patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch. +- Refresh + patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch. +- Refresh + patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch. +- Delete + patches.suse/x86-mm-pat-introcude-cpa_lock-and-cpa_unlock.patch. + Replace: + x86-mm-pat-introcude-cpa_lock-and-cpa_unlock.patch + by the solution from upstream (tip): + x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch. + And fix up the context in the others. +- commit a5cdd68 + +------------------------------------------------------------------- +Fri Aug 7 11:02:46 CEST 2026 - [email protected] + +- Refresh + patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch. +- Refresh + patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch. + Update upstream status. +- commit 67505b5 + +------------------------------------------------------------------- +Thu Aug 6 19:54:13 CEST 2026 - [email protected] + +- Update + patches.kernel.org/7.1.2-002-fuse-re-lock-request-before-replacing-page-cach.patch + (bsc#1012628 CVE-2026-53388 bsc#1271825). +- Update + patches.kernel.org/7.1.2-005-iio-light-veml6075-add-bounds-check-to-veml6075.patch + (bsc#1012628 CVE-2026-53387 bsc#1271835). +- Update + patches.kernel.org/7.1.2-006-iio-adc-ti-ads1298-add-bounds-check-to-pga_sett.patch + (bsc#1012628 CVE-2026-53386 bsc#1271820). +- Update + patches.kernel.org/7.1.2-007-crypto-qat-remove-unused-character-device-and-I.patch + (bsc#1012628 CVE-2026-64529). +- Update + patches.kernel.org/7.1.2-008-vc_screen-fix-null-ptr-deref-in-vcs_notifier-du.patch + (bsc#1012628 CVE-2026-53385 bsc#1271834). +- Update + patches.kernel.org/7.1.2-010-serial-8250_dw-unregister-8250-port-if-clk_noti.patch + (bsc#1012628 CVE-2026-53384 bsc#1271817). +- Update + patches.kernel.org/7.1.2-011-drivers-base-memory-set-mem-altmap-after-succes.patch + (bsc#1012628 CVE-2026-64244 bsc#1273812). +- Update + patches.kernel.org/7.1.2-012-ksmbd-reject-non-VALID-session-in-compound-requ.patch + (bsc#1012628 CVE-2026-53383 bsc#1271719). +- Update + patches.kernel.org/7.1.2-013-media-vidtv-fix-NULL-pointer-dereference-in-vid.patch + (bsc#1012628 CVE-2026-53382 bsc#1271717). +- Update + patches.kernel.org/7.1.2-014-virtiofs-fix-UAF-on-submount-umount.patch + (bsc#1012628 CVE-2026-53381 bsc#1271830). +- Update + patches.kernel.org/7.1.3-006-batman-adv-tp_meter-avoid-divide-by-zero-for-de.patch + (bsc#1012628 CVE-2026-63836 bsc#1272246). +- Update + patches.kernel.org/7.1.3-018-batman-adv-v-prevent-OGM-aggregation-on-disable.patch + (bsc#1012628 CVE-2026-63835 bsc#1272244). +- Update + patches.kernel.org/7.1.3-019-batman-adv-tp_meter-restrict-number-of-unacked-.patch + (bsc#1012628 CVE-2026-63834 bsc#1272239). +- Update + patches.kernel.org/7.1.3-030-ntfs3-reject-direct-userspace-writes-to-reserve.patch + (bsc#1012628 CVE-2026-63833 bsc#1272177). +- Update + patches.kernel.org/7.1.3-031-wifi-mt76-add-wcid-publish-check-in-mt76_sta_ad.patch + (bsc#1012628 CVE-2026-63832 bsc#1272186). +- Update + patches.kernel.org/7.1.3-032-mac802154-llsec-add-skb_cow_data-before-in-plac.patch + (bsc#1012628 CVE-2026-63831 bsc#1272184). +- Update + patches.kernel.org/7.1.3-033-net-skmsg-preserve-sg.copy-across-SG-transforms.patch + (bsc#1012628 CVE-2026-63830 bsc#1272178). +- Update + patches.kernel.org/7.1.3-034-net-ip_gre-require-CAP_NET_ADMIN-in-the-device-.patch + (bsc#1012628 CVE-2026-63829 bsc#1272176). +- Update + patches.kernel.org/7.1.3-036-apparmor-mediate-the-implicit-connect-of-TCP-fa.patch + (bsc#1012628 CVE-2026-63828 bsc#1272175). +- Update + patches.kernel.org/7.1.3-037-apparmor-fix-use-after-free-in-rawdata-dedup-lo.patch + (bko#221513 bsc#1012628 CVE-2026-63827 bsc#1272179). +- Update + patches.kernel.org/7.1.3-038-NTB-epf-Avoid-pci_iounmap-with-offset-when-PEER.patch + (bsc#1012628 CVE-2026-64254 bsc#1273736). +- Update + patches.kernel.org/7.1.3-039-fbdev-fix-use-after-free-in-store_modes.patch + (bsc#1012628 CVE-2026-63826 bsc#1272183). +- Update + patches.kernel.org/7.1.3-041-kernel-fork-clear-PF_BLOCK_TS-in-copy_process.patch + (bsc#1012628 CVE-2026-64253 bsc#1273904). +- Update + patches.kernel.org/7.1.3-045-gcov-use-atomic-counter-updates-to-fix-concurre.patch + (bsc#1012628 CVE-2026-63825 bsc#1272181). +- Update + patches.kernel.org/7.1.3-046-KEYS-fix-overflow-in-keyctl_pkey_params_get_2.patch + (bsc#1012628 CVE-2026-63824 bsc#1272180). +- Update + patches.kernel.org/7.1.3-047-keys-Pin-request_key_auth-payload-in-instantiat.patch + (bsc#1012628 CVE-2026-63823 bsc#1272182). +- Update + patches.kernel.org/7.1.3-052-wifi-ath11k-fix-warning-when-unbinding.patch + (bsc#1012628 CVE-2026-63822 bsc#1272187). +- Update + patches.kernel.org/7.1.3-056-wifi-rtw88-usb-fix-memory-leaks-on-USB-write-fa.patch + (bsc#1012628 CVE-2026-63821 bsc#1271967). +- Update + patches.kernel.org/7.1.3-059-wifi-iwlwifi-mld-validate-sta_mask-before-ffs-i.patch + (bsc#1012628 CVE-2026-64255 bsc#1273821). +- Update + patches.kernel.org/7.1.3-060-f2fs-fix-missing-read-bio-submission-on-large-f.patch + (bsc#1012628 CVE-2026-63820 bsc#1271966). +- Update + patches.kernel.org/7.1.3-063-f2fs-fix-to-do-sanity-check-on-f2fs_get_node_fo.patch + (bsc#1012628 CVE-2026-63819 bsc#1271962). +- Update + patches.kernel.org/7.1.3-064-f2fs-validate-orphan-inode-entry-count.patch + (bsc#1012628 CVE-2026-63818 bsc#1271958). +- Update + patches.kernel.org/7.1.3-065-f2fs-validate-compress-cache-inode-only-when-en.patch + (bsc#1012628 CVE-2026-63817 bsc#1271954). +- Update + patches.kernel.org/7.1.3-066-f2fs-atomic-fix-UAF-issue-on-f2fs_inode_info.at.patch + (bsc#1012628 CVE-2026-63816 bsc#1272309). +- Update + patches.kernel.org/7.1.3-068-f2fs-bound-i_inline_xattr_size-for-non-inline-x.patch + (bsc#1012628 CVE-2026-63815 bsc#1272308). +- Update + patches.kernel.org/7.1.3-069-f2fs-validate-ACL-entry-sizes-in-f2fs_acl_from_.patch + (bsc#1012628 CVE-2026-63814 bsc#1272285). +- Update + patches.kernel.org/7.1.3-070-Revert-f2fs-remove-non-uptodate-folio-from-the-.patch + (bsc#1012628 CVE-2026-63813 bsc#1272174). +- Update + patches.kernel.org/7.1.3-071-f2fs-fix-incorrect-FI_NO_EXTENT-handling-in-__d.patch + (bsc#1012628 CVE-2026-63812 bsc#1272185). +- Update + patches.kernel.org/7.1.3-073-f2fs-read-COW-data-with-the-original-inode-duri.patch + (bsc#1012628 CVE-2026-63811 bsc#1272173). +- Update + patches.kernel.org/7.1.3-074-block-Avoid-mounting-the-bdev-pseudo-filesystem.patch + (bsc#1012628 CVE-2026-63810 bsc#1272297). +- Update + patches.kernel.org/7.1.3-075-bpf-use-kvfree-for-replaced-sysctl-write-buffer.patch + (bsc#1012628 CVE-2026-63809 bsc#1272296). +- Update + patches.kernel.org/7.1.3-076-MIPS-DEC-Prevent-initial-console-buffer-from-la.patch + (bsc#1012628 CVE-2026-64252 bsc#1273932). +- Update + patches.kernel.org/7.1.3-077-exfat-fix-potential-use-after-free-in-exfat_fin.patch + (bsc#1012628 CVE-2026-63808 bsc#1272260). +- Update + patches.kernel.org/7.1.3-078-KVM-x86-mmu-Ensure-hugepage-is-in-by-slot-befor.patch + (bsc#1012628 CVE-2026-63807 bsc#1272263). +- Update + patches.kernel.org/7.1.3-079-KVM-Replace-guest-triggerable-BUG_ON-in-ioevent.patch + (bsc#1012628 CVE-2026-63806 bsc#1272268). +- Update + patches.kernel.org/7.1.3-080-crypto-nx-fix-nx_crypto_ctx_exit-argument.patch + (bsc#1012628 CVE-2026-63805 bsc#1272288). +- Update + patches.kernel.org/7.1.3-081-gfs2-fix-use-after-free-in-gfs2_qd_dealloc.patch + (bsc#1012628 CVE-2026-63804 bsc#1272287). +- Update + patches.kernel.org/7.1.3-082-pwrseq-core-fix-use-after-free-in-pwrseq_debugf.patch + (bsc#1012628 CVE-2026-64251 bsc#1273777). +- Update + patches.kernel.org/7.1.3-083-hdlc_ppp-sync-per-proto-timers-before-freeing-h.patch + (bsc#1012628 CVE-2026-63803 bsc#1272284). +- Update + patches.kernel.org/7.1.3-084-blk-cgroup-fix-UAF-in-__blkcg_rstat_flush.patch + (bsc#1012628 CVE-2026-63802 bsc#1272282). +- Update + patches.kernel.org/7.1.3-085-tipc-fix-slab-use-after-free-Read-in-tipc_aead_.patch + (bsc#1012628 CVE-2026-63801 bsc#1272230). +- Update + patches.kernel.org/7.1.3-086-LoongArch-Report-dying-CPU-to-RCU-in-stop_this_.patch + (bsc#1012628 CVE-2026-64250 bsc#1273815). +- Update + patches.kernel.org/7.1.3-087-pNFS-Fix-use-after-free-in-pnfs_update_layout.patch + (bsc#1012628 CVE-2026-63800 bsc#1272270). +- Update + patches.kernel.org/7.1.3-088-sched-mmcid-Fix-OOB-clear_bit-when-CID-is-MM_CI.patch + (bsc#1012628 CVE-2026-63799 bsc#1272141). +- Update + patches.kernel.org/7.1.3-089-irqchip-imgpdc-Fix-resource-leak-add-missing-ch.patch + (bsc#1012628 CVE-2026-63798 bsc#1271802). +- Update + patches.kernel.org/7.1.3-090-fpga-region-fix-use-after-free-in-child_regions.patch + (bsc#1012628 CVE-2026-64249 bsc#1273810). +- Update + patches.kernel.org/7.1.3-091-rpmsg-char-Fix-use-after-free-on-probe-error-pa.patch + (bsc#1012628 CVE-2026-63797 bsc#1272138). +- Update + patches.kernel.org/7.1.3-092-ocfs2-reject-oversized-group-bitmap-descriptors.patch + (bsc#1012628 CVE-2026-63796 bsc#1273191). +- Update + patches.kernel.org/7.1.3-093-9p-avoid-putting-oldfid-in-p9_client_walk-error.patch + (bsc#1012628 CVE-2026-63795 bsc#1271955). +- Update + patches.kernel.org/7.1.3-094-MIPS-smp-report-dying-CPU-to-RCU-in-stop_this_c.patch + (bsc#1012628 CVE-2026-64248 bsc#1273820). +- Update + patches.kernel.org/7.1.3-095-KVM-x86-hyper-v-Bound-the-bank-index-when-query.patch + (bsc#1012628 CVE-2026-64247 bsc#1273903). +- Update + patches.kernel.org/7.1.3-096-KVM-SVM-Fix-page-overflow-in-sev_dbg_crypt-for-.patch + (bsc#1012628 CVE-2026-63794 bsc#1271964). +- Update + patches.kernel.org/7.1.3-097-power-reset-linkstation-poweroff-fix-use-after-.patch + (bsc#1012628 CVE-2026-64246 bsc#1273945). +- Update + patches.kernel.org/7.1.3-100-ntfs-serialize-volume-label-accesses.patch + (bsc#1012628 CVE-2026-63793 bsc#1271953). +- Update + patches.kernel.org/7.1.3-101-fbdev-Fix-fb_new_modelist-to-prevent-null-ptr-d.patch + (bsc#1012628 CVE-2026-53403 bsc#1271731). +- Update + patches.kernel.org/7.1.3-102-fbdev-fbcon-fix-out-of-bounds-read-in-err_out-o.patch + (bsc#1012628 CVE-2026-53402 bsc#1271908). +- Update + patches.kernel.org/7.1.3-103-fbdev-omap2-fix-use-after-free-in-omapfb_mmap.patch + (bsc#1012628 CVE-2026-53401 bsc#1271828). +- Update + patches.kernel.org/7.1.3-104-fbdev-modedb-fix-a-possible-UAF-in-fb_find_mode.patch + (bsc#1012628 CVE-2026-64245 bsc#1273905). +- Update + patches.kernel.org/7.1.3-106-i2c-core-fix-adapter-registration-race.patch + (bsc#1012628 CVE-2026-53400 bsc#1271906). +- Update + patches.kernel.org/7.1.3-107-nfsd-release-layout-stid-on-setlease-failure.patch + (bsc#1012628 CVE-2026-53399 bsc#1271832). +- Update + patches.kernel.org/7.1.3-108-NFSD-Fix-SECINFO_NO_NAME-decode-error-cleanup.patch + (bsc#1012628 CVE-2026-53398 bsc#1271870). +- Update + patches.kernel.org/7.1.3-109-nfsd-fix-posix_acl-leak-on-SETACL-decode-failur.patch + (bsc#1012628 CVE-2026-53397 bsc#1271869). +- Update + patches.kernel.org/7.1.3-111-nfsd-fix-posix_acl-leak-and-ignored-error-in-nf.patch + (bsc#1012628 CVE-2026-53396 bsc#1271829). +- Update + patches.kernel.org/7.1.3-113-nfsd-fix-dead-ACL-conflict-guard-in-nfsd4_creat.patch + (bsc#1012628 CVE-2026-53395 bsc#1271865). +- Update + patches.kernel.org/7.1.3-114-nfsd-avoid-leaking-pre-allocated-openowner-on-u.patch + (bsc#1012628 CVE-2026-53394 bsc#1271859). +- Update + patches.kernel.org/7.1.3-115-nfsd-reset-write-verifier-on-deferred-writeback.patch + (bsc#1012628 CVE-2026-53393 bsc#1271858). +- Update + patches.kernel.org/7.1.3-116-NFSv4-flexfiles-reject-zero-filehandle-version-.patch + (bsc#1012628 CVE-2026-53392 bsc#1271826). +- Update + patches.kernel.org/7.1.3-117-NFSv4-pNFS-reject-zero-length-r_addr-in-nfs4_de.patch + (bsc#1012628 CVE-2026-53391 bsc#1271904). +- Update + patches.kernel.org/7.1.3-120-ksmbd-fix-out-of-bounds-read-in-smb_check_perm_.patch + (bsc#1012628 CVE-2026-53390 bsc#1271871). +- Update + patches.kernel.org/7.1.3-121-net-tcp-ao-fix-use-after-free-of-key-in-del_asy.patch + (bsc#1012628 CVE-2026-53389 bsc#1271863). +- Update + patches.kernel.org/7.1.4-003-userfaultfd-gate-must_wait-writability-check-on.patch + (bsc#1012628 CVE-2026-64514 bsc#1274044). +- Update + patches.kernel.org/7.1.4-004-net-sched-dualpi2-fix-GSO-backlog-accounting.patch + (bsc#1012628 CVE-2026-64207 bsc#1272216). +- Update + patches.kernel.org/7.1.4-009-KVM-VMX-Grab-vmcs12-on-CR8-interception-update-.patch + (bsc#1012628 CVE-2026-64604). +- Update + patches.kernel.org/7.1.4-010-KVM-x86-Unconditionally-recompute-CR8-intercept.patch + (bsc#1012628 CVE-2026-64513 bsc#1273327). +- Update + patches.kernel.org/7.1.4-011-ACPI-CPPC-Suppress-UBSAN-warning-caused-by-fiel.patch + (bsc#1012628 CVE-2026-64512 bsc#1273597). +- Update + patches.kernel.org/7.1.4-012-ACPI-NFIT-core-Fix-possible-NULL-pointer-derefe.patch + (bsc#1012628 CVE-2026-64511 bsc#1273796). +- Update + patches.kernel.org/7.1.4-013-ACPI-NFIT-core-Fix-acpi_nfit_init-error-cleanup.patch + (bsc#1012628 CVE-2026-64510). +- Update + patches.kernel.org/7.1.4-014-platform-x86-intel-hid-Protect-ACPI-notify-hand.patch + (bsc#1012628 CVE-2026-64603). +- Update + patches.kernel.org/7.1.4-019-rust-block-fix-GenDisk-cleanup-paths.patch ++++ 1041 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes ++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.16738/dtb-aarch64.changes dtb-armv6l.changes: same change dtb-armv7l.changes: same change dtb-riscv64.changes: same change kernel-64kb.changes: same change kernel-default.changes: same change kernel-docs.changes: same change kernel-kvmsmall.changes: same change kernel-lpae.changes: same change kernel-obs-build.changes: same change kernel-obs-qa.changes: same change kernel-pae.changes: same change kernel-source.changes: same change kernel-syms.changes: same change kernel-vanilla.changes: same change kernel-zfcpdump.changes: same change ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dtb-aarch64.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.356270723 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.360270860 +0200 @@ -17,7 +17,7 @@ %define srcversion 7.1 -%define patchversion 7.1.6 +%define patchversion 7.1.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -25,9 +25,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: dtb-aarch64 -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif dtb-armv6l.spec: same change dtb-armv7l.spec: same change dtb-riscv64.spec: same change ++++++ kernel-64kb.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.524276454 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.528276590 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-64kb -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif kernel-default.spec: same change ++++++ kernel-docs.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.608279319 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.608279319 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define build_html 1 %define build_pdf 0 @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-docs -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif ++++++ kernel-kvmsmall.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.640280411 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.644280547 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-kvmsmall -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif kernel-lpae.spec: same change ++++++ kernel-obs-build.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.720283140 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.720283140 +0200 @@ -19,7 +19,7 @@ #!BuildIgnore: post-build-checks -%define patchversion 7.1.6 +%define patchversion 7.1.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -38,23 +38,23 @@ %endif %endif %endif -%global kernel_package kernel%kernel_flavor-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e +%global kernel_package kernel%kernel_flavor-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %endif %if 0%{?rhel_version} %global kernel_package kernel %endif Name: kernel-obs-build -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif Summary: package kernel and initrd for OBS VM builds License: GPL-2.0-only Group: SLES -Provides: kernel-obs-build-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e +Provides: kernel-obs-build-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b BuildRequires: coreutils BuildRequires: device-mapper BuildRequires: dracut ++++++ kernel-obs-qa.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.756284367 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.760284504 +0200 @@ -17,15 +17,15 @@ # needsrootforbuild -%define patchversion 7.1.6 +%define patchversion 7.1.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-obs-qa -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif @@ -36,7 +36,7 @@ # kernel-obs-build must be also configured as VMinstall, but is required # here as well to avoid that qa and build package build parallel %if ! 0%{?qemu_user_space_build} -BuildRequires: kernel-obs-build-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e +BuildRequires: kernel-obs-build-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %endif BuildRequires: modutils ExclusiveArch: aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64 ++++++ kernel-pae.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.796285732 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.796285732 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-pae -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif ++++++ kernel-source.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.836287096 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.840287233 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define gcc_package gcc %define gcc_compiler gcc @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-source -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif ++++++ kernel-syms.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.876288461 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.876288461 +0200 @@ -16,15 +16,15 @@ # -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-syms -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif ++++++ kernel-vanilla.spec ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:24.916289825 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:24.916289825 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.1 -%define patchversion 7.1.6 -%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e +%define patchversion 7.1.7 +%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-vanilla -Version: 7.1.6 +Version: 7.1.7 %if 0%{?is_kotd} -Release: <RELEASE>.gae5c1b5 +Release: <RELEASE>.ga5cdd68 %else Release: 0 %endif kernel-zfcpdump.spec: same change ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:25.108296375 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:25.112296512 +0200 @@ -1,6 +1,6 @@ -mtime: 1785751697 -commit: b54580a80ae04c8a5a35577820138d87ee926e132e71c4331eeaeff61e031985 +mtime: 1786099159 +commit: 61bc19496f97f0d4b5cd778085992cf6c986906fc7b302122b81507281758ad7 url: https://src.opensuse.org/jirislaby/kernel-source -revision: b54580a80ae04c8a5a35577820138d87ee926e132e71c4331eeaeff61e031985 +revision: 61bc19496f97f0d4b5cd778085992cf6c986906fc7b302122b81507281758ad7 trackingbranch: Kernel/stable ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-08-07 12:39:19.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ modversions ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:25.576312339 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:25.580312476 +0200 @@ -109,7 +109,7 @@ next if /^$/; chomp; - if (/^\/\* (.*)\.o \*\//) { + if (/^\/\* (.*)\.(o|symtypes) \*\//) { close STDOUT; mkpath(dirname("$dir/$1$ext")); open STDOUT, "> $dir/$1$ext" ++++++ patches.kernel.org.tar.bz2 ++++++ ++++ 5286 lines of diff (skipped) ++++++ patches.suse.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/drm-amd-display-use-proper-context-for-logging.patch new/patches.suse/drm-amd-display-use-proper-context-for-logging.patch --- old/patches.suse/drm-amd-display-use-proper-context-for-logging.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/drm-amd-display-use-proper-context-for-logging.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,174 @@ +From: "Jiri Slaby (SUSE)" <[email protected]> +Date: Thu, 23 Jul 2026 06:25:48 +0200 +Subject: drm/amd/display: use proper context for logging +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit +Git-commit: 114b42507b6a23d9d24e24e4ef165233332c64d4 +Patch-mainline: v7.2-rc6 +References: bsc#1271175 + +The same as the rest of the code, get_ss_info_from_atombios() uses +calc_pll_cs->ctx->logger for logging. But calc_pll_cs->ctx is +initialized only later in calc_pll_max_vco_construct(). Therefore, any +output using DC_LOG_SYNC() leads to a NULL pointer deference in +get_ss_info_from_atombios(). + +According to Sashiko, the very same problem exists in +dce112_get_pix_clk_dividers() and dcn3_get_pix_clk_dividers() too. + +To avoid accessing the NULL context, use clk_src->base.ctx->logger +everywhere. That context in base is initialized earlier in +dce110_clk_src_construct() and dce112_clk_src_construct(). Before +get_ss_info_from_atombios() or Sashiko's get_pix_clk_dividers functions +above are actually called. This is done by redefining DC_LOGGER to +CTX->logger. + +Before: +dce110_clk_src_construct() did: + -> sets clk_src->base.ctx = ctx; + -> ss_info_from_atombios_create() + -> get_ss_info_from_atombios() <- uses calc_pll_cs->ctx # BOOM + -> calc_pll_max_vco_construct() <- sets calc_pll_cs->ctx + +After: +dce110_clk_src_construct() does: + -> sets clk_src->base.ctx = ctx; + -> ss_info_from_atombios_create() + -> get_ss_info_from_atombios() <- uses clk_src->base.ctx + +Closes: https://bugzilla.suse.com/show_bug.cgi?id=1271175 +Closes: https://lore.kernel.org/all/[email protected]/ +Fixes: 1296423bf23c ("drm/amd/display: define DC_LOGGER for logger") +Reviewed-by: Bhawanpreet Lakha <[email protected]> +Signed-off-by: Jiri Slaby (SUSE) <[email protected]> +Cc: Lakha, Bhawanpreet <[email protected]> +Cc: Harry Wentland <[email protected]> +Cc: Leo Li <[email protected]> +Cc: Rodrigo Siqueira <[email protected]> +Cc: Alex Deucher <[email protected]> +Cc: "Christian König" <[email protected]> +Cc: David Airlie <[email protected]> +Cc: Simona Vetter <[email protected]> +Cc: [email protected] +Signed-off-by: Alex Deucher <[email protected]> +(cherry picked from commit 6f16fcbb0c46a87e3d9685407e906573d60104b0) +Cc: [email protected] + +Acked-by: Jiri Slaby <[email protected]> +--- + drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c | 20 ++++++++---------- + 1 file changed, 9 insertions(+), 11 deletions(-) + +--- a/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c ++++ b/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c +@@ -45,9 +45,7 @@ + clk_src->base.ctx + + #define DC_LOGGER \ +- calc_pll_cs->ctx->logger +-#define DC_LOGGER_INIT() \ +- struct calc_pll_clock_source *calc_pll_cs = &clk_src->calc_pll ++ CTX->logger + + #undef FN + #define FN(reg_name, field_name) \ +@@ -289,6 +287,7 @@ static bool calc_pll_dividers_in_range( + } + + static uint32_t calculate_pixel_clock_pll_dividers( ++ struct dce110_clk_src *clk_src, + struct calc_pll_clock_source *calc_pll_cs, + struct pll_settings *pll_settings) + { +@@ -477,7 +476,7 @@ static uint32_t dce110_get_pix_clk_divid + { + uint32_t field = 0; + uint32_t pll_calc_error = MAX_PLL_CALC_ERROR; +- DC_LOGGER_INIT(); ++ + /* Check if reference clock is external (not pcie/xtalin) + * HW Dce80 spec: + * 00 - PCIE_REFCLK, 01 - XTALIN, 02 - GENERICA, 03 - GENERICB +@@ -520,12 +519,14 @@ static uint32_t dce110_get_pix_clk_divid + /*Calculate Dividers by HDMI object, no SS case or SS case */ + pll_calc_error = + calculate_pixel_clock_pll_dividers( ++ clk_src, + &clk_src->calc_pll_hdmi, + pll_settings); + else + /*Calculate Dividers by default object, no SS case or SS case */ + pll_calc_error = + calculate_pixel_clock_pll_dividers( ++ clk_src, + &clk_src->calc_pll, + pll_settings); + +@@ -571,7 +572,6 @@ static uint32_t dce110_get_pix_clk_divid + { + struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs); + uint32_t pll_calc_error = MAX_PLL_CALC_ERROR; +- DC_LOGGER_INIT(); + + if (pix_clk_params == NULL || pll_settings == NULL + || pix_clk_params->requested_pix_clk_100hz == 0) { +@@ -603,7 +603,6 @@ static uint32_t dce112_get_pix_clk_divid + struct pll_settings *pll_settings) + { + struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs); +- DC_LOGGER_INIT(); + + if (pix_clk_params == NULL || pll_settings == NULL + || pix_clk_params->requested_pix_clk_100hz == 0) { +@@ -1372,8 +1371,6 @@ static uint32_t dcn3_get_pix_clk_divider + unsigned long long actual_pix_clk_100Hz = pix_clk_params ? pix_clk_params->requested_pix_clk_100hz : 0; + struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs); + +- DC_LOGGER_INIT(); +- + if (pix_clk_params == NULL || pll_settings == NULL + || pix_clk_params->requested_pix_clk_100hz == 0) { + DC_LOG_ERROR( +@@ -1443,7 +1440,6 @@ static const struct clock_source_funcs d + .get_pixel_clk_frequency_100hz = get_pixel_clk_frequency_100hz + }; + +- + static void get_ss_info_from_atombios( + struct dce110_clk_src *clk_src, + enum as_signal_type as_signal, +@@ -1456,7 +1452,7 @@ static void get_ss_info_from_atombios( + struct spread_spectrum_info *ss_info_cur; + struct spread_spectrum_data *ss_data_cur; + uint32_t i; +- DC_LOGGER_INIT(); ++ + if (ss_entries_num == NULL) { + DC_LOG_SYNC( + "Invalid entry !!!\n"); +@@ -1587,6 +1583,7 @@ static void ss_info_from_atombios_create + } + + static bool calc_pll_max_vco_construct( ++ struct dce110_clk_src *clk_src, + struct calc_pll_clock_source *calc_pll_cs, + struct calc_pll_clock_source_init_data *init_data) + { +@@ -1738,6 +1735,7 @@ bool dce110_clk_src_construct( + ss_info_from_atombios_create(clk_src); + + if (!calc_pll_max_vco_construct( ++ clk_src, + &clk_src->calc_pll, + &calc_pll_cs_init_data)) { + ASSERT_CRITICAL(false); +@@ -1752,7 +1750,7 @@ bool dce110_clk_src_construct( + + + if (!calc_pll_max_vco_construct( +- &clk_src->calc_pll_hdmi, &calc_pll_cs_init_data_hdmi)) { ++ clk_src, &clk_src->calc_pll_hdmi, &calc_pll_cs_init_data_hdmi)) { + ASSERT_CRITICAL(false); + goto unexpected_failure; + } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch --- old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,77 @@ +From: Pedro Falcato <[email protected]> +Date: Mon, 3 Aug 2026 13:16:25 +0100 +Subject: x86/alternative: exclude text poking against change_page_attr() +References: bsc#1271202 +Patch-mainline: Submitted, [email protected] + +From time to time, the following BUG can be observed[0]: + +> kernel BUG at arch/x86/kernel/alternative.c:2576! +> Oops: invalid opcode: 0000 [#1] SMP NOPTI +> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed 8c1795b03ec64f997e57a8ad38b1161e3b98da64 +> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022 +> RIP: 0010:__text_poke+0x2aa/0x450 +> Call Trace: +> <TASK> +> smp_text_poke_batch_finish+0x2a7/0x320 +> __static_call_transform+0xb7/0x220 +> arch_static_call_transform+0x5b/0xb0 +> __static_call_init+0xe9/0x270 +> static_call_module_notify+0x11f/0x150 +> notifier_call_chain+0x61/0xe0 +> blocking_notifier_call_chain_robust+0x63/0xc0 +> load_module+0x1c92/0x20c0 +> init_module_from_file+0xd8/0x140 +> idempotent_init_module+0x100/0x2f0 +> __x64_sys_finit_module+0x71/0xe0 +> do_syscall_64+0xe1/0x610 +> entry_SYSCALL_64_after_hwframe+0x76/0x7e + +which matches the following BUG_ON in alternative.c: + /* + * If something went wrong, crash and burn since recovery paths are not + * implemented. + */ + BUG_ON(!pages[0] || (cross_page_boundary && !pages[1])); + +This can happen if vmalloc_to_page() fails, for any reason. Such can happen +if text poking races with CPA, which can possibly result in the collapsing +of page tables (or breaking of PMD hugepages). It is not a problem for most +users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when +CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc +range, and can call set_memory_*() in parallel on it. This can happen to +race against __text_poke and cause havoc in vmalloc_to_page(). + +Fix it by excluding against CPA using the init_mm mmap read lock. + +Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") +Reported-by: Jiri Slaby <[email protected]> +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Reported-by: Steffen Dirkwinkel <[email protected]> +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Cc: [email protected] +Signed-off-by: Pedro Falcato <[email protected]> +--- + arch/x86/kernel/alternative.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/arch/x86/kernel/alternative.c b/arch/x86/kernel/alternative.c +index 62936a3bde19..9071eb870eab 100644 +--- a/arch/x86/kernel/alternative.c ++++ b/arch/x86/kernel/alternative.c +@@ -2559,6 +2559,14 @@ static void *__text_poke(text_poke_f func, void *addr, const void *src, size_t l + */ + BUG_ON(!after_bootmem); + ++ /* ++ * Exclude against change_page_attr() collapse in execmem ROX regions. ++ * These are PMD sized and this module may not own the whole PMD, ++ * thus breakdown/collapse may happen at any moment by concurrent module ++ * loading, which races with vmalloc_to_page(). ++ */ ++ guard(mmap_read_lock)(&init_mm); ++ + if (!core_kernel_text((unsigned long)addr)) { + pages[0] = vmalloc_to_page(addr); + if (cross_page_boundary) + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch --- old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,199 @@ +From: Peter Zijlstra <[email protected]> +Date: Wed, 29 Jul 2026 13:08:10 +0200 +Subject: x86/mm: Fix and document DEBUG_PAGEALLOC +References: bsc#1271202 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 7da514d819a0afb148634aac92b3d190f34947c3 +Patch-mainline: Queued in subsystem maintainer repository + +It turns out that commit 5fce67641a3e ("x86/mm/pat: Don't gate +cpa_lock on debug_pagealloc_enabled()") was a little too quick to +remove the debug_pagealloc exception for cpa_lock. + +Notably __kernel_map_pages() is used by the page-allocator from any +context the page-allocator itself is used, which violates the cpa_lock +rules. + +Re-instate the exception, except make it specific to the +__kernel_map_pages() such that any other cpa() usage is still fully +serialized by cpa_lock. Also note that since cpa() should not be used +on memory that isn't allocated, the page-allocator locking and cpa are +infact mutually exclusive and all cpa usage in fully serialized. + +Add a comment explaining this and other 'funnies' surrounding +DEBUG_PAGEALLOC, including how pgd_lock is not affected and the TLB +trickery. + +Fixes: 5fce67641a3e ("x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled()") +Signed-off-by: Peter Zijlstra (Intel) <[email protected]> +Link: https://patch.msgid.link/[email protected] +Signed-off-by: Jiri Slaby <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 80 +++++++++++++++++++++++++++++++------------ + 1 file changed, 58 insertions(+), 22 deletions(-) + +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -68,11 +68,12 @@ static const int cpa_warn_level = CPA_PR + */ + static DEFINE_SPINLOCK(cpa_lock); + +-#define CPA_FLUSHTLB 1 +-#define CPA_ARRAY 2 +-#define CPA_PAGES_ARRAY 4 +-#define CPA_NO_CHECK_ALIAS 8 /* Do not search for aliases */ +-#define CPA_COLLAPSE 16 /* try to collapse large pages */ ++#define CPA_FLUSHTLB 0x01 ++#define CPA_ARRAY 0x02 ++#define CPA_PAGES_ARRAY 0x04 ++#define CPA_NO_CHECK_ALIAS 0x08 /* Do not search for aliases */ ++#define CPA_COLLAPSE 0x10 /* try to collapse large pages */ ++#define CPA_DEBUG_PAGEALLOC 0x20 + + static inline pgprot_t cachemode2pgprot(enum page_cache_mode pcm) + { +@@ -2007,6 +2008,7 @@ static int __change_page_attr_set_clr(st + { + unsigned long numpages = cpa->numpages; + unsigned long rempages = numpages; ++ bool lock = true; + int ret = 0; + + /* +@@ -2016,6 +2018,29 @@ static int __change_page_attr_set_clr(st + !cpa->force_split) + return ret; + ++ /* ++ * DEBUG_PAGEALLOC is special; it is called from any context the ++ * page-allocator is, which violates the normal cpa_lock locking ++ * rules. ++ * ++ * However, since it is part of the page-allocator, things are still ++ * properly serialized by the page-allocator locking and the fact that ++ * when a page is owned by the page-allocator, it isn't owned by ++ * anybody else. That is, you *SHOULD NOT* be calling cpa() on memory ++ * that isn't allocated. ++ * ++ * Additionally, DEBUG_PAGEALLOC ensures (per probe_page_size_mask()) ++ * that the kernel mapping is 4k pages, therefore there are no large ++ * pages to split/collapse. ++ * ++ * Furthermore, the page-allocator strictly manages pages that ++ * *exist*, avoiding pgd_lock. ++ * ++ * Therefore, it is safe to not take cpa_lock. ++ */ ++ if (debug_pagealloc_enabled() && (cpa->flags & CPA_DEBUG_PAGEALLOC)) ++ lock = false; ++ + while (rempages) { + /* + * Store the remaining nr of pages for the large page +@@ -2026,9 +2051,12 @@ static int __change_page_attr_set_clr(st + if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY)) + cpa->numpages = 1; + +- spin_lock(&cpa_lock); +- ret = __change_page_attr(cpa, primary); +- spin_unlock(&cpa_lock); ++ if (lock) { ++ guard(spinlock)(&cpa_lock); ++ ret = __change_page_attr(cpa, primary); ++ } else { ++ ret = __change_page_attr(cpa, primary); ++ } + if (ret) + goto out; + +@@ -2607,7 +2635,7 @@ int set_pages_rw(struct page *page, int + return set_memory_rw(addr, numpages); + } + +-static int __set_pages_p(struct page *page, int numpages) ++static int __set_pages_p(struct page *page, int numpages, unsigned int cpa_flags) + { + unsigned long tempaddr = (unsigned long) page_address(page); + struct cpa_data cpa = { .vaddr = &tempaddr, +@@ -2615,7 +2643,7 @@ static int __set_pages_p(struct page *pa + .numpages = numpages, + .mask_set = __pgprot(_PAGE_PRESENT | _PAGE_RW), + .mask_clr = __pgprot(0), +- .flags = CPA_NO_CHECK_ALIAS }; ++ .flags = CPA_NO_CHECK_ALIAS | cpa_flags }; + + /* + * No alias checking needed for setting present flag. otherwise, +@@ -2626,7 +2654,7 @@ static int __set_pages_p(struct page *pa + return __change_page_attr_set_clr(&cpa, 1); + } + +-static int __set_pages_np(struct page *page, int numpages) ++static int __set_pages_np(struct page *page, int numpages, unsigned int cpa_flags) + { + unsigned long tempaddr = (unsigned long) page_address(page); + struct cpa_data cpa = { .vaddr = &tempaddr, +@@ -2634,7 +2662,7 @@ static int __set_pages_np(struct page *p + .numpages = numpages, + .mask_set = __pgprot(0), + .mask_clr = __pgprot(_PAGE_PRESENT | _PAGE_RW | _PAGE_DIRTY), +- .flags = CPA_NO_CHECK_ALIAS }; ++ .flags = CPA_NO_CHECK_ALIAS | cpa_flags }; + + /* + * No alias checking needed for setting not present flag. otherwise, +@@ -2647,20 +2675,20 @@ static int __set_pages_np(struct page *p + + int set_direct_map_invalid_noflush(struct page *page) + { +- return __set_pages_np(page, 1); ++ return __set_pages_np(page, 1, 0); + } + + int set_direct_map_default_noflush(struct page *page) + { +- return __set_pages_p(page, 1); ++ return __set_pages_p(page, 1, 0); + } + + int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid) + { + if (valid) +- return __set_pages_p(page, nr); ++ return __set_pages_p(page, nr, 0); + +- return __set_pages_np(page, nr); ++ return __set_pages_np(page, nr, 0); + } + + #ifdef CONFIG_DEBUG_PAGEALLOC +@@ -2679,15 +2707,23 @@ void __kernel_map_pages(struct page *pag + * and hence no memory allocations during large page split. + */ + if (enable) +- __set_pages_p(page, numpages); ++ __set_pages_p(page, numpages, CPA_DEBUG_PAGEALLOC); + else +- __set_pages_np(page, numpages); ++ __set_pages_np(page, numpages, CPA_DEBUG_PAGEALLOC); + + /* +- * We should perform an IPI and flush all tlbs, +- * but that can deadlock->flush only current cpu. +- * Preemption needs to be disabled around __flush_tlb_all() due to +- * CR3 reload in __native_flush_tlb(). ++ * We should perform an IPI and flush all tlbs, but that can ++ * deadlock, settle for a local flush. ++ * ++ * Not doing a global TLB flush means that remote CPUs will retain ++ * stale TLB entries. In case of P->NP (on free) this means the remote ++ * CPUs will not take the faults, making the debug scheme less ++ * reliable. On the NP->P (on alloc) this means the remote CPUs can ++ * take a spurious fault. However spurious_kernel_fault() will observe ++ * *_present() and fix it up. ++ * ++ * Preemption needs to be disabled around __flush_tlb_all() due to CR3 ++ * reload in __native_flush_tlb(). + */ + preempt_disable(); + __flush_tlb_all(); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch --- old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,85 @@ +From: "Mike Rapoport (Microsoft)" <[email protected]> +Date: Wed, 15 Jul 2026 17:45:19 +0300 +Subject: x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled() +References: bsc#1271202 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 5fce67641a3ed9a0782eaa228ddece526461a367 +Patch-mainline: Queued in subsystem maintainer repository + +The splitting and merging of kernel page table mappings between small and +large is protected by cpa_lock. The merging is relatively new but the +splitting is ancient. + +The splitting has a locking optimization: since DEBUG_PAGEALLOC forces all +mappings to 4k, there are no large pages to split. So the code that *might* +cause a split can just skip the locking (and a few other things). + +This is entertaining, but it adds complexity and makes for weird locking +rules. Plus it's all for a debugging feature which makes the kernel super +slow in the first place. Optimizing something which is already super slow +and not used in production is not the best way to spend our complexity +budget. + +Stop gating cpa_lock on debug_pagealloc_enabled() to simplify the code +and the locking rules. + +[ dhansen: flesh out changelog ] + +Suggested-by: Dave Hansen <[email protected]> +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> +Link: https://patch.msgid.link/[email protected] +Link: https://lore.kernel.org/all/[email protected]/ + +Acked-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 19 +++++++------------ + 1 file changed, 7 insertions(+), 12 deletions(-) + +diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c +index 45623d4c24c9..e9b408343c5d 100644 +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -62,10 +62,9 @@ enum cpa_warn { + static const int cpa_warn_level = CPA_PROTECT; + + /* +- * Serialize cpa() (for !DEBUG_PAGEALLOC which uses large identity mappings) +- * using cpa_lock. So that we don't allow any other cpu, with stale large tlb +- * entries change the page attribute in parallel to some other cpu +- * splitting a large page entry along with changing the attribute. ++ * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with ++ * stale large tlb entries, to change the page attribute in parallel to some ++ * other cpu splitting a large page entry along with changing the attribute. + */ + static DEFINE_SPINLOCK(cpa_lock); + +@@ -1234,11 +1233,9 @@ static int split_large_page(struct cpa_data *cpa, pte_t *kpte, + { + struct ptdesc *ptdesc; + +- if (!debug_pagealloc_enabled()) +- spin_unlock(&cpa_lock); ++ spin_unlock(&cpa_lock); + ptdesc = pagetable_alloc(GFP_KERNEL, 0); +- if (!debug_pagealloc_enabled()) +- spin_lock(&cpa_lock); ++ spin_lock(&cpa_lock); + if (!ptdesc) + return -ENOMEM; + +@@ -2022,11 +2019,9 @@ static int __change_page_attr_set_clr(struct cpa_data *cpa, int primary) + if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY)) + cpa->numpages = 1; + +- if (!debug_pagealloc_enabled()) +- spin_lock(&cpa_lock); ++ spin_lock(&cpa_lock); + ret = __change_page_attr(cpa, primary); +- if (!debug_pagealloc_enabled()) +- spin_unlock(&cpa_lock); ++ spin_unlock(&cpa_lock); + if (ret) + goto out; + + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch new/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch --- old/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,101 @@ +From: "Denis V. Lunev" <[email protected]> +Date: Wed, 15 Jul 2026 20:34:52 +0200 +Subject: x86/mm/pat: Take cpa_lock around large-page collapse +References: bsc#1271202 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 1aac65f3e651334259ecb2a5f5ddb81c01f02599 +Patch-mainline: Queued in subsystem maintainer repository + +Loading and unloading modules concurrently on several CPUs on a KASAN +build, with a short delay injected at the CPA page-table lookup to +widen the window, faults within minutes: + + BUG: KASAN: use-after-free in __change_page_attr+0x7cc/0x7e0 + Write of size 8 at addr ffff888181139718 by task modprobe + ... + The buggy address belongs to the physical page: + pfn:0x181139 ... page_type: f2(table) + +cpa_collapse_large_pages() rebuilds a leaf PMD from its 4K PTEs and +frees the old PTE-table pages, while __change_page_attr() fetches a +PTE pointer from a lockless lookup_address_in_pgd_attr() and writes +it with set_pte_atomic() only later. When module text is served from +a shared large ROX mapping the two run on the same PMD: + + CPU A (module load) CPU B (module finalize) + ------------------- ----------------------- + execmem_make_temp_rw + set_memory_nx + __change_page_attr + split 2M -> 4K table P + kpte = &P[i] (lockless) + execmem_restore_rox + set_memory_rox (CPA_COLLAPSE) + cpa_collapse_large_pages + rebuild leaf PMD + flush_tlb_all + pagetable_free(P) + set_pte_atomic(kpte, ...) + -> writes into freed P + +P is a page-table page (page_type: table), reused at once, so the +write corrupts whatever got the page next: a bad-pte or bad-page +splat, or a fatal fault once P has been turned into read-only text. + +The flush_tlb_all() before the free does not close this: its IPI only +serializes against page-table walkers that run with interrupts off +(e.g. GUP-fast); the walk in __change_page_attr() runs with interrupts +on, so nothing stops it from holding a stale pointer into P. + +Serialize the collapse - the PMD rebuild, TLB flush and PTE-table +free - under cpa_lock, the same lock __change_page_attr() now takes +unconditionally since commit ("x86/mm/pat: stop gating cpa_lock on +debug_pagealloc_enabled()"), so a concurrent walker can no longer +hold a pointer into a table the collapse is about to free. + +Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") +Signed-off-by: Denis V. Lunev <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> +Acked-by: Kiryl Shutsemau (Meta) <[email protected]> +Link: https://patch.msgid.link/[email protected] + +Acked-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c +index e9b408343c5d..b1e780a465b5 100644 +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -417,6 +417,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa) + int collapsed = 0; + int i; + ++ spin_lock(&cpa_lock); ++ + if (cpa->flags & (CPA_PAGES_ARRAY | CPA_ARRAY)) { + for (i = 0; i < cpa->numpages; i++) + collapsed += collapse_large_pages(__cpa_addr(cpa, i), +@@ -430,8 +432,10 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa) + collapsed += collapse_large_pages(addr, &pgtables); + } + +- if (!collapsed) ++ if (!collapsed) { ++ spin_unlock(&cpa_lock); + return; ++ } + + flush_tlb_all(); + +@@ -439,6 +443,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa) + list_del(&ptdesc->pt_list); + pagetable_free(ptdesc); + } ++ ++ spin_unlock(&cpa_lock); + } + + static void cpa_flush(struct cpa_data *cpa, int cache) + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,163 @@ +From: "Lorenzo Stoakes (ARM)" <[email protected]> +Date: Tue, 28 Jul 2026 16:07:46 +0300 +Subject: x86/mm/pat: acquire init_mm read lock on attribute change to avoid + UAF +References: bsc#1271202 +Patch-mainline: Submitted, [email protected] + +A previous commit protected us against races between ptdump and CPA +collapse, however one still exists between attribute changes and collapse +as reported by Denis V. Lunev (linked). + +When an attribute change arises, a lockless page table walker obtains a PTE +entry, which is later written to via set_pte_atomic(): + +... +-> change_page_attr_set_clr() +-> __change_page_attr_set_clr() +-> __change_page_attr() + -> _lookup_address_cpa() + -> lookup_address_in_pgd_attr() + -> [ lockless page table walker ] +-> set_pte_atomic() + +There is nothing preventing a concurrent CPA collapse which can free the +PTE that was retrieved here, resulting in a use-after-free. + +With the mmap write lock taken on init_mm over CPA collapse, we can now +resolve this race by acquiring an mmap read lock on init_mm over +__change_page_attr_set_clr(). + +This locks across the whole operation over which the walk and the PTE entry +write occurs, solving the race. + +It is safe to do this here, as no spinlocks are held upon entry to +__change_page_attr_set_clr(). + +However, the lock must not be held over an allocation, as allocation can +trigger reclaim and shrinkers may call into CPA recursively, making +deadlocks possible (init_mm -> ... -> fs_reclaim -> init_mm). + +A page table is allocated when a huge page needs to be split: + +-> change_page_attr_set_clr() +-> __change_page_attr_set_clr() +-> __change_page_attr() +-> split_large_page() +[ pagetable_alloc() ] +-> __split_large_page() + +Avoid deadlocks by dropping the mmap lock across pagetable_alloc() in +split_large_page() and track whether this is needed by adding a new +'init_mm_read_locked' flag to struct cpa_data. + +This is safe as __split_large_page() (called with locks re-established) +revalidates that the page table entry is the same as it was prior to the +locks being dropped and __change_page_attr() repeats the entire page table +walk whenever a split occurs, so concurrent split and collapse are +accounted for. + +Concurrent ptdump is also safe as the lock is only dropped over page table +allocation during which time the page table has not yet been modified. + +The CPA_COLLAPSE flag is only set by set_memory_rox(), which exclusively +operates upon vmalloc ranges, and on x86 only within the module mapping +space. + +This is important, because some callers directly invoke +__change_page_attr_set_clr(), bypassing this lock. However, none of these +operate within the module mapping space. + +* cpa_process_alias() - a recursive helper called by + __change_page_attr_set_clr(). +* __set_memory_enc_pgtable() - operates on the direct mapping and (via + __vmbus_establish_gpadl()) the vmalloc mapping space. +* __set_pages_[n]p() - called by set_direct_map_[invalid, default, + valid]_noflush(), __kernel_map_pages() - operates on the direct map. +* kernel_[un]map_pages_in_pgd() - operates on EFI ranges. + +This work is based upon Denis V. Lunev's excellent analysis of the bug with +gratitude. + +Link: https://lore.kernel.org/all/[email protected]/ +Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") +Cc: [email protected] +Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Signed-off-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 22 +++++++++++++--------- + 1 file changed, 13 insertions(+), 9 deletions(-) + +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -50,7 +50,8 @@ struct cpa_data { + unsigned int flags; + unsigned int force_split : 1, + force_static_prot : 1, +- force_flush_all : 1; ++ force_flush_all : 1, ++ init_mm_read_locked : 1; + struct page **pages; + }; + +@@ -419,8 +420,6 @@ static void __cpa_collapse_large_pages(s + int collapsed = 0; + int i; + +- spin_lock(&cpa_lock); +- + if (cpa->flags & (CPA_PAGES_ARRAY | CPA_ARRAY)) { + for (i = 0; i < cpa->numpages; i++) + collapsed += collapse_large_pages(__cpa_addr(cpa, i), +@@ -434,10 +433,8 @@ static void __cpa_collapse_large_pages(s + collapsed += collapse_large_pages(addr, &pgtables); + } + +- if (!collapsed) { +- spin_unlock(&cpa_lock); ++ if (!collapsed) + return; +- } + + flush_tlb_all(); + +@@ -445,8 +442,6 @@ static void __cpa_collapse_large_pages(s + list_del(&ptdesc->pt_list); + pagetable_free(ptdesc); + } +- +- spin_unlock(&cpa_lock); + } + + static void cpa_collapse_large_pages(struct cpa_data *cpa) +@@ -1255,8 +1250,13 @@ static int split_large_page(struct cpa_d + struct ptdesc *ptdesc; + + spin_unlock(&cpa_lock); ++ if (cpa->init_mm_read_locked) ++ mmap_read_unlock(&init_mm); + ptdesc = pagetable_alloc(GFP_KERNEL, 0); ++ if (cpa->init_mm_read_locked) ++ mmap_read_lock(&init_mm); + spin_lock(&cpa_lock); ++ + if (!ptdesc) + return -ENOMEM; + +@@ -2151,7 +2151,11 @@ static int change_page_attr_set_clr(unsi + cpa.curpage = 0; + cpa.force_split = force_split; + +- ret = __change_page_attr_set_clr(&cpa, 1); ++ /* Avoid race with concurrent CPA collapse. */ ++ cpa.init_mm_read_locked = true; ++ scoped_guard(mmap_read_lock, &init_mm) ++ ret = __change_page_attr_set_clr(&cpa, 1); ++ cpa.init_mm_read_locked = false; + + /* + * Check whether we really changed something: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,114 @@ +From: "Lorenzo Stoakes (ARM)" <[email protected]> +Date: Tue, 28 Jul 2026 16:07:45 +0300 +Subject: x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF +References: bsc#1271202 +Patch-mainline: Submitted, [email protected] + +x86 implements page attribute modification using its Change Page +Attributes (CPA) mechanism. + +This tracks properties of ranges such as cache mode through x86 page +attributes, and as part of that logic manipulates kernel page tables. + +Since commit 41d88484c71c ("x86/mm/pat: restore large ROX pages after +fragmentation") ranges of kernel page table entries can be collapsed into +huge page table entries as part of this logic. + +As part of this collapse, it frees the page tables which the collapsed +entries previously pointed to, and it does so without any relevant locks +being held to preclude concurrent kernel page table walkers. + +The only way this code can be reached is if CPA_COLLAPSE is specified, and +this is only set in set_memory_rox() via: + +set_memory_rox() +-> change_page_attr_set_clr() +-> cpa_flush() +-> cpa_collapse_large_pages() + +Notable users of this are execmem and bpf when manipulating executable +mappings. + +However, this is problematic for ptdump as it walks ranges it does not own +and thus runs the risk of a use-after-free on page tables freed underneath +it. + +In addition, concurrent CPA collapse operations are possible which can also +cause races. + +Resolve the issue by acquiring the mmap write lock on init_mm across the +whole operation. + +It is safe to acquire a sleeping lock as all the callers invoke +set_memory_rox() from process context and in any case, +change_page_attr_set_clr() calls vm_unmap_alias() which ultimately takes a +mutex, disallowing atomic context here. + +Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") +Cc: [email protected] +Reviewed-by: Mike Rapoport (Microsoft) <[email protected]> +Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]> +Reviewed-by: David Hildenbrand (Arm) <[email protected]> +Reviewed-by: Dave Hansen <[email protected]> +Reviewed-by: Will Deacon <[email protected]> +Reviewed-by: David Carlier <[email protected]> +Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Signed-off-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 15 ++++++++++++++- + include/linux/mmap_lock.h | 2 ++ + 2 files changed, 16 insertions(+), 1 deletion(-) + +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -22,6 +22,7 @@ + #include <linux/cc_platform.h> + #include <linux/set_memory.h> + #include <linux/memregion.h> ++#include <linux/cleanup.h> + + #include <asm/e820/api.h> + #include <asm/processor.h> +@@ -410,7 +411,7 @@ static void __cpa_flush_tlb(void *data) + + static int collapse_large_pages(unsigned long addr, struct list_head *pgtables); + +-static void cpa_collapse_large_pages(struct cpa_data *cpa) ++static void __cpa_collapse_large_pages(struct cpa_data *cpa) + { + unsigned long start, addr, end; + struct ptdesc *ptdesc, *tmp; +@@ -448,6 +449,18 @@ static void cpa_collapse_large_pages(str + spin_unlock(&cpa_lock); + } + ++static void cpa_collapse_large_pages(struct cpa_data *cpa) ++{ ++ /* ++ * Take the mmap write lock on init_mm to: ++ * - Avoid a use-after-free if raced by ptdump (which takes its own ++ * write lock on init_mm). ++ * - Serialise concurrent CPA walkers. ++ */ ++ scoped_guard(mmap_write_lock, &init_mm) ++ __cpa_collapse_large_pages(cpa); ++} ++ + static void cpa_flush(struct cpa_data *cpa, int cache) + { + unsigned int i; +--- a/include/linux/mmap_lock.h ++++ b/include/linux/mmap_lock.h +@@ -621,6 +621,8 @@ static inline void mmap_read_unlock(stru + + DEFINE_GUARD(mmap_read_lock, struct mm_struct *, + mmap_read_lock(_T), mmap_read_unlock(_T)) ++DEFINE_GUARD(mmap_write_lock, struct mm_struct *, ++ mmap_write_lock(_T), mmap_write_unlock(_T)) + + static inline void mmap_read_unlock_non_owner(struct mm_struct *mm) + { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch --- old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,125 @@ +From: "Lorenzo Stoakes (ARM)" <[email protected]> +Date: Tue, 28 Jul 2026 16:07:47 +0300 +Subject: x86/mm/pat: allocate split page tables as kernel page tables +References: bsc#1271202 +Patch-mainline: Submitted, [email protected] + +When splitting a large page in CPA in __split_large_page() we allocate a +PTE directly without going through the standard page table allocation +routines such as pte_alloc_one_kernel(). + +This means the page table constructor is never called nor is the page table +marked as a kernel page table. + +The former results in the folio associated with the page table not being +marked as a page table (__pagetable_ctor() is never called thus neither is +__folio_set_pgtable()) nor are statistics updated to reflect +it (lruvec_stat_add_folio() is never called). + +The latter issue of failing to mark the page table as a kernel page +table (ptdesc_set_kernel() is never called) is far more problematic. + +Since commit 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page +tables") kernel page table freeing has been batched and since the +subsequent commit e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries +for kernel address space") IOTLB cache entries for kernel page tables have +been invalidated upon being freed. + +Since split page tables are freed without this invalidation, the IOTLB can +contain stale entries for them. + +Resolve the issue by using the ordinary PTE allocation API at split time. + +This results in these kernel page tables invoking a page table constructor, +and thus requires a page table destructor. + +Since we cannot assume one is always present (early allocated direct map +page tables are not marked as such), we conditionally call +pagetable_dtor_free() if the PG_table folio flag for the ptdesc is set, +otherwise we free the page table via pagetable_free(). + +Regardless of which path is taken page tables marked as kernel page tables, +which now includes split page tables, take the correct route through +pagetable_free_kernel(). + +There is a user-visible side effect in that split page tables will appear +in nr_page_table_pages in /proc/vmstat (as do other kernel page tables +allocated after early boot), however this is a positive change. + +This issue started being markedly problematic after commit +5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so +choose this as the Fixes target. + +Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") +Cc: [email protected] +Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> +Acked-by: Vishal Moola <[email protected]> +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Signed-off-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 25 ++++++++++++++++--------- + 1 file changed, 16 insertions(+), 9 deletions(-) + +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -440,7 +440,15 @@ static void __cpa_collapse_large_pages(s + + list_for_each_entry_safe(ptdesc, tmp, &pgtables, pt_list) { + list_del(&ptdesc->pt_list); +- pagetable_free(ptdesc); ++ /* ++ * Only early alloc'd direct map should not be flagged PG_table ++ * here and those shouldn't be collapsed. However be abundantly ++ * cautious and handle the !PG_table case too. ++ */ ++ if (PageTable((ptdesc_page(ptdesc)))) ++ pagetable_dtor_free(ptdesc); ++ else ++ pagetable_free(ptdesc); + } + } + +@@ -1139,11 +1147,10 @@ set: + + static int + __split_large_page(struct cpa_data *cpa, pte_t *kpte, unsigned long address, +- struct ptdesc *ptdesc) ++ pte_t *pbase) + { + unsigned long lpaddr, lpinc, ref_pfn, pfn, pfninc = 1; +- struct page *base = ptdesc_page(ptdesc); +- pte_t *pbase = (pte_t *)page_address(base); ++ struct page *base = virt_to_page(pbase); + unsigned int i, level; + pgprot_t ref_prot; + bool nx, rw; +@@ -1247,21 +1254,21 @@ __split_large_page(struct cpa_data *cpa, + static int split_large_page(struct cpa_data *cpa, pte_t *kpte, + unsigned long address) + { +- struct ptdesc *ptdesc; ++ pte_t *pte; + + spin_unlock(&cpa_lock); + if (cpa->init_mm_read_locked) + mmap_read_unlock(&init_mm); +- ptdesc = pagetable_alloc(GFP_KERNEL, 0); ++ pte = pte_alloc_one_kernel(&init_mm); + if (cpa->init_mm_read_locked) + mmap_read_lock(&init_mm); + spin_lock(&cpa_lock); + +- if (!ptdesc) ++ if (!pte) + return -ENOMEM; + +- if (__split_large_page(cpa, kpte, address, ptdesc)) +- pagetable_free(ptdesc); ++ if (__split_large_page(cpa, kpte, address, pte)) ++ pte_free_kernel(&init_mm, pte); + + return 0; + } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch --- old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch 2026-08-07 12:29:37.000000000 +0200 @@ -0,0 +1,87 @@ +From: "Mike Rapoport (Microsoft)" <[email protected]> +Date: Tue, 28 Jul 2026 16:07:48 +0300 +Subject: x86/mm/pat: fix effective RW computation in + lookup_address_in_pgd_attr() +References: bsc#1271202 +Patch-mainline: Submitted, [email protected] + +lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of +the walked page table levels so that verify_rwx() can detect mappings that +are both writable and executable. + +The RW bits are folded into a bool with + + rw &= pXd_flags(*pXd) & _PAGE_RW; + +but _PAGE_RW is 0x2. So consider the accumulation line: + + rw &= pXd_flags(*pXd) & _PAGE_RW; + +where rw=0x1 and the right side evaluates down to 0x2. It'll end up doing: + + rw = 0x1 & 0x2 + +and rw always ends up 0. + +This way rw becomes false at the first level walked, regardless of the +actual permissions, and verify_rwx() treats every mapping as non-writable +and never reports a W^X violation. + +Add double negation to the right side to normalize the _PAGE_RW flag to +0 or 1. + +Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()") +Cc: [email protected] +Assisted-by: Copilot:claude-opus-4.8 +Reviewed-by: Juergen Gross <[email protected]> +Tested-by: [email protected] +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Signed-off-by: Pedro Falcato <[email protected]> +--- + arch/x86/mm/pat/set_memory.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c +index 1b63d4caba20..7d656520887c 100644 +--- a/arch/x86/mm/pat/set_memory.c ++++ b/arch/x86/mm/pat/set_memory.c +@@ -769,7 +769,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address, + + *level = PG_LEVEL_512G; + *nx |= pgd_flags(*pgd) & _PAGE_NX; +- *rw &= pgd_flags(*pgd) & _PAGE_RW; ++ *rw &= !!(pgd_flags(*pgd) & _PAGE_RW); + + p4d = p4d_offset(pgd, address); + if (p4d_none(*p4d)) +@@ -780,7 +780,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address, + + *level = PG_LEVEL_1G; + *nx |= p4d_flags(*p4d) & _PAGE_NX; +- *rw &= p4d_flags(*p4d) & _PAGE_RW; ++ *rw &= !!(p4d_flags(*p4d) & _PAGE_RW); + + pud = pud_offset(p4d, address); + if (pud_none(*pud)) +@@ -791,7 +791,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address, + + *level = PG_LEVEL_2M; + *nx |= pud_flags(*pud) & _PAGE_NX; +- *rw &= pud_flags(*pud) & _PAGE_RW; ++ *rw &= !!(pud_flags(*pud) & _PAGE_RW); + + pmd = pmd_offset(pud, address); + if (pmd_none(*pmd)) +@@ -802,7 +802,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address, + + *level = PG_LEVEL_4K; + *nx |= pmd_flags(*pmd) & _PAGE_NX; +- *rw &= pmd_flags(*pmd) & _PAGE_RW; ++ *rw &= !!(pmd_flags(*pmd) & _PAGE_RW); + + return pte_offset_kernel(pmd, address); + } + ++++++ series.conf ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:28.608415766 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:28.616416038 +0200 @@ -3522,6 +3522,8 @@ patches.kernel.org/7.1.6-740-cifs-fix-time_last_write-stamp-placement-in-set.patch patches.kernel.org/7.1.6-741-cifs-consolidate-time_last_write-stamp-into-_ci.patch patches.kernel.org/7.1.6-742-Linux-7.1.6.patch + patches.kernel.org/7.1.7-001-x86-bugs-Make-Safe-RET-robust-against-interrupt.patch + patches.kernel.org/7.1.7-002-Linux-7.1.7.patch ######################################################## # Build fixes that apply to the vanilla kernel too. @@ -3567,6 +3569,19 @@ patches.suse/selftests-bpf-Tolerate-missing-files-during-install.patch patches.suse/ima-return-error-early-if-file-xattr-cannot-be-changed.patch patches.suse/soundwire-dmi-quirks-Disable-ghost-Realtek-devices.patch + patches.suse/drm-amd-display-use-proper-context-for-logging.patch + + # tip/tip + patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch + patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch + patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch + + # out-of-tree patches + patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch + patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch + patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch + patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch + patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch ######################################################## # end of sorted patches ++++++ source-timestamp ++++++ --- /var/tmp/diff_new_pack.754shK/_old 2026-08-09 21:34:28.648417130 +0200 +++ /var/tmp/diff_new_pack.754shK/_new 2026-08-09 21:34:28.648417130 +0200 @@ -1,4 +1,4 @@ -2026-08-03 10:04:30 +0000 -GIT Revision: ae5c1b55de3bd891574adbec8ff5c8802def979e +2026-08-07 10:29:37 +0000 +GIT Revision: a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b GIT Branch: stable
