Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package kernel-source for openSUSE:Factory 
checked in at 2026-08-09 21:33:03
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/kernel-source (Old)
 and      /work/SRC/openSUSE:Factory/.kernel-source.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "kernel-source"

Sun Aug  9 21:33:03 2026 rev:853 rq:1370211 version:7.1.7

Changes:
--------
--- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes        
2026-08-05 17:48:12.821444395 +0200
+++ /work/SRC/openSUSE:Factory/.kernel-source.new.16738/dtb-aarch64.changes     
2026-08-09 21:34:17.924051318 +0200
@@ -1,0 +2,1338 @@
+Fri Aug  7 12:29:37 CEST 2026 - [email protected]
+
+- x86/mm: Fix and document DEBUG_PAGEALLOC (bsc#1271202).
+- Refresh
+  
patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch.
+- Refresh
+  
patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch.
+- Refresh
+  
patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch.
+- Delete
+  patches.suse/x86-mm-pat-introcude-cpa_lock-and-cpa_unlock.patch.
+  Replace:
+  x86-mm-pat-introcude-cpa_lock-and-cpa_unlock.patch
+  by the solution from upstream (tip):
+  x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch.
+  And fix up the context in the others.
+- commit a5cdd68
+
+-------------------------------------------------------------------
+Fri Aug  7 11:02:46 CEST 2026 - [email protected]
+
+- Refresh
+  patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch.
+- Refresh
+  patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch.
+  Update upstream status.
+- commit 67505b5
+
+-------------------------------------------------------------------
+Thu Aug  6 19:54:13 CEST 2026 - [email protected]
+
+- Update
+  
patches.kernel.org/7.1.2-002-fuse-re-lock-request-before-replacing-page-cach.patch
+  (bsc#1012628 CVE-2026-53388 bsc#1271825).
+- Update
+  
patches.kernel.org/7.1.2-005-iio-light-veml6075-add-bounds-check-to-veml6075.patch
+  (bsc#1012628 CVE-2026-53387 bsc#1271835).
+- Update
+  
patches.kernel.org/7.1.2-006-iio-adc-ti-ads1298-add-bounds-check-to-pga_sett.patch
+  (bsc#1012628 CVE-2026-53386 bsc#1271820).
+- Update
+  
patches.kernel.org/7.1.2-007-crypto-qat-remove-unused-character-device-and-I.patch
+  (bsc#1012628 CVE-2026-64529).
+- Update
+  
patches.kernel.org/7.1.2-008-vc_screen-fix-null-ptr-deref-in-vcs_notifier-du.patch
+  (bsc#1012628 CVE-2026-53385 bsc#1271834).
+- Update
+  
patches.kernel.org/7.1.2-010-serial-8250_dw-unregister-8250-port-if-clk_noti.patch
+  (bsc#1012628 CVE-2026-53384 bsc#1271817).
+- Update
+  
patches.kernel.org/7.1.2-011-drivers-base-memory-set-mem-altmap-after-succes.patch
+  (bsc#1012628 CVE-2026-64244 bsc#1273812).
+- Update
+  
patches.kernel.org/7.1.2-012-ksmbd-reject-non-VALID-session-in-compound-requ.patch
+  (bsc#1012628 CVE-2026-53383 bsc#1271719).
+- Update
+  
patches.kernel.org/7.1.2-013-media-vidtv-fix-NULL-pointer-dereference-in-vid.patch
+  (bsc#1012628 CVE-2026-53382 bsc#1271717).
+- Update
+  patches.kernel.org/7.1.2-014-virtiofs-fix-UAF-on-submount-umount.patch
+  (bsc#1012628 CVE-2026-53381 bsc#1271830).
+- Update
+  
patches.kernel.org/7.1.3-006-batman-adv-tp_meter-avoid-divide-by-zero-for-de.patch
+  (bsc#1012628 CVE-2026-63836 bsc#1272246).
+- Update
+  
patches.kernel.org/7.1.3-018-batman-adv-v-prevent-OGM-aggregation-on-disable.patch
+  (bsc#1012628 CVE-2026-63835 bsc#1272244).
+- Update
+  
patches.kernel.org/7.1.3-019-batman-adv-tp_meter-restrict-number-of-unacked-.patch
+  (bsc#1012628 CVE-2026-63834 bsc#1272239).
+- Update
+  
patches.kernel.org/7.1.3-030-ntfs3-reject-direct-userspace-writes-to-reserve.patch
+  (bsc#1012628 CVE-2026-63833 bsc#1272177).
+- Update
+  
patches.kernel.org/7.1.3-031-wifi-mt76-add-wcid-publish-check-in-mt76_sta_ad.patch
+  (bsc#1012628 CVE-2026-63832 bsc#1272186).
+- Update
+  
patches.kernel.org/7.1.3-032-mac802154-llsec-add-skb_cow_data-before-in-plac.patch
+  (bsc#1012628 CVE-2026-63831 bsc#1272184).
+- Update
+  
patches.kernel.org/7.1.3-033-net-skmsg-preserve-sg.copy-across-SG-transforms.patch
+  (bsc#1012628 CVE-2026-63830 bsc#1272178).
+- Update
+  
patches.kernel.org/7.1.3-034-net-ip_gre-require-CAP_NET_ADMIN-in-the-device-.patch
+  (bsc#1012628 CVE-2026-63829 bsc#1272176).
+- Update
+  
patches.kernel.org/7.1.3-036-apparmor-mediate-the-implicit-connect-of-TCP-fa.patch
+  (bsc#1012628 CVE-2026-63828 bsc#1272175).
+- Update
+  
patches.kernel.org/7.1.3-037-apparmor-fix-use-after-free-in-rawdata-dedup-lo.patch
+  (bko#221513 bsc#1012628 CVE-2026-63827 bsc#1272179).
+- Update
+  
patches.kernel.org/7.1.3-038-NTB-epf-Avoid-pci_iounmap-with-offset-when-PEER.patch
+  (bsc#1012628 CVE-2026-64254 bsc#1273736).
+- Update
+  patches.kernel.org/7.1.3-039-fbdev-fix-use-after-free-in-store_modes.patch
+  (bsc#1012628 CVE-2026-63826 bsc#1272183).
+- Update
+  
patches.kernel.org/7.1.3-041-kernel-fork-clear-PF_BLOCK_TS-in-copy_process.patch
+  (bsc#1012628 CVE-2026-64253 bsc#1273904).
+- Update
+  
patches.kernel.org/7.1.3-045-gcov-use-atomic-counter-updates-to-fix-concurre.patch
+  (bsc#1012628 CVE-2026-63825 bsc#1272181).
+- Update
+  
patches.kernel.org/7.1.3-046-KEYS-fix-overflow-in-keyctl_pkey_params_get_2.patch
+  (bsc#1012628 CVE-2026-63824 bsc#1272180).
+- Update
+  
patches.kernel.org/7.1.3-047-keys-Pin-request_key_auth-payload-in-instantiat.patch
+  (bsc#1012628 CVE-2026-63823 bsc#1272182).
+- Update
+  patches.kernel.org/7.1.3-052-wifi-ath11k-fix-warning-when-unbinding.patch
+  (bsc#1012628 CVE-2026-63822 bsc#1272187).
+- Update
+  
patches.kernel.org/7.1.3-056-wifi-rtw88-usb-fix-memory-leaks-on-USB-write-fa.patch
+  (bsc#1012628 CVE-2026-63821 bsc#1271967).
+- Update
+  
patches.kernel.org/7.1.3-059-wifi-iwlwifi-mld-validate-sta_mask-before-ffs-i.patch
+  (bsc#1012628 CVE-2026-64255 bsc#1273821).
+- Update
+  
patches.kernel.org/7.1.3-060-f2fs-fix-missing-read-bio-submission-on-large-f.patch
+  (bsc#1012628 CVE-2026-63820 bsc#1271966).
+- Update
+  
patches.kernel.org/7.1.3-063-f2fs-fix-to-do-sanity-check-on-f2fs_get_node_fo.patch
+  (bsc#1012628 CVE-2026-63819 bsc#1271962).
+- Update
+  patches.kernel.org/7.1.3-064-f2fs-validate-orphan-inode-entry-count.patch
+  (bsc#1012628 CVE-2026-63818 bsc#1271958).
+- Update
+  
patches.kernel.org/7.1.3-065-f2fs-validate-compress-cache-inode-only-when-en.patch
+  (bsc#1012628 CVE-2026-63817 bsc#1271954).
+- Update
+  
patches.kernel.org/7.1.3-066-f2fs-atomic-fix-UAF-issue-on-f2fs_inode_info.at.patch
+  (bsc#1012628 CVE-2026-63816 bsc#1272309).
+- Update
+  
patches.kernel.org/7.1.3-068-f2fs-bound-i_inline_xattr_size-for-non-inline-x.patch
+  (bsc#1012628 CVE-2026-63815 bsc#1272308).
+- Update
+  
patches.kernel.org/7.1.3-069-f2fs-validate-ACL-entry-sizes-in-f2fs_acl_from_.patch
+  (bsc#1012628 CVE-2026-63814 bsc#1272285).
+- Update
+  
patches.kernel.org/7.1.3-070-Revert-f2fs-remove-non-uptodate-folio-from-the-.patch
+  (bsc#1012628 CVE-2026-63813 bsc#1272174).
+- Update
+  
patches.kernel.org/7.1.3-071-f2fs-fix-incorrect-FI_NO_EXTENT-handling-in-__d.patch
+  (bsc#1012628 CVE-2026-63812 bsc#1272185).
+- Update
+  
patches.kernel.org/7.1.3-073-f2fs-read-COW-data-with-the-original-inode-duri.patch
+  (bsc#1012628 CVE-2026-63811 bsc#1272173).
+- Update
+  
patches.kernel.org/7.1.3-074-block-Avoid-mounting-the-bdev-pseudo-filesystem.patch
+  (bsc#1012628 CVE-2026-63810 bsc#1272297).
+- Update
+  
patches.kernel.org/7.1.3-075-bpf-use-kvfree-for-replaced-sysctl-write-buffer.patch
+  (bsc#1012628 CVE-2026-63809 bsc#1272296).
+- Update
+  
patches.kernel.org/7.1.3-076-MIPS-DEC-Prevent-initial-console-buffer-from-la.patch
+  (bsc#1012628 CVE-2026-64252 bsc#1273932).
+- Update
+  
patches.kernel.org/7.1.3-077-exfat-fix-potential-use-after-free-in-exfat_fin.patch
+  (bsc#1012628 CVE-2026-63808 bsc#1272260).
+- Update
+  
patches.kernel.org/7.1.3-078-KVM-x86-mmu-Ensure-hugepage-is-in-by-slot-befor.patch
+  (bsc#1012628 CVE-2026-63807 bsc#1272263).
+- Update
+  
patches.kernel.org/7.1.3-079-KVM-Replace-guest-triggerable-BUG_ON-in-ioevent.patch
+  (bsc#1012628 CVE-2026-63806 bsc#1272268).
+- Update
+  patches.kernel.org/7.1.3-080-crypto-nx-fix-nx_crypto_ctx_exit-argument.patch
+  (bsc#1012628 CVE-2026-63805 bsc#1272288).
+- Update
+  patches.kernel.org/7.1.3-081-gfs2-fix-use-after-free-in-gfs2_qd_dealloc.patch
+  (bsc#1012628 CVE-2026-63804 bsc#1272287).
+- Update
+  
patches.kernel.org/7.1.3-082-pwrseq-core-fix-use-after-free-in-pwrseq_debugf.patch
+  (bsc#1012628 CVE-2026-64251 bsc#1273777).
+- Update
+  
patches.kernel.org/7.1.3-083-hdlc_ppp-sync-per-proto-timers-before-freeing-h.patch
+  (bsc#1012628 CVE-2026-63803 bsc#1272284).
+- Update
+  patches.kernel.org/7.1.3-084-blk-cgroup-fix-UAF-in-__blkcg_rstat_flush.patch
+  (bsc#1012628 CVE-2026-63802 bsc#1272282).
+- Update
+  
patches.kernel.org/7.1.3-085-tipc-fix-slab-use-after-free-Read-in-tipc_aead_.patch
+  (bsc#1012628 CVE-2026-63801 bsc#1272230).
+- Update
+  
patches.kernel.org/7.1.3-086-LoongArch-Report-dying-CPU-to-RCU-in-stop_this_.patch
+  (bsc#1012628 CVE-2026-64250 bsc#1273815).
+- Update
+  
patches.kernel.org/7.1.3-087-pNFS-Fix-use-after-free-in-pnfs_update_layout.patch
+  (bsc#1012628 CVE-2026-63800 bsc#1272270).
+- Update
+  
patches.kernel.org/7.1.3-088-sched-mmcid-Fix-OOB-clear_bit-when-CID-is-MM_CI.patch
+  (bsc#1012628 CVE-2026-63799 bsc#1272141).
+- Update
+  
patches.kernel.org/7.1.3-089-irqchip-imgpdc-Fix-resource-leak-add-missing-ch.patch
+  (bsc#1012628 CVE-2026-63798 bsc#1271802).
+- Update
+  
patches.kernel.org/7.1.3-090-fpga-region-fix-use-after-free-in-child_regions.patch
+  (bsc#1012628 CVE-2026-64249 bsc#1273810).
+- Update
+  
patches.kernel.org/7.1.3-091-rpmsg-char-Fix-use-after-free-on-probe-error-pa.patch
+  (bsc#1012628 CVE-2026-63797 bsc#1272138).
+- Update
+  
patches.kernel.org/7.1.3-092-ocfs2-reject-oversized-group-bitmap-descriptors.patch
+  (bsc#1012628 CVE-2026-63796 bsc#1273191).
+- Update
+  
patches.kernel.org/7.1.3-093-9p-avoid-putting-oldfid-in-p9_client_walk-error.patch
+  (bsc#1012628 CVE-2026-63795 bsc#1271955).
+- Update
+  
patches.kernel.org/7.1.3-094-MIPS-smp-report-dying-CPU-to-RCU-in-stop_this_c.patch
+  (bsc#1012628 CVE-2026-64248 bsc#1273820).
+- Update
+  
patches.kernel.org/7.1.3-095-KVM-x86-hyper-v-Bound-the-bank-index-when-query.patch
+  (bsc#1012628 CVE-2026-64247 bsc#1273903).
+- Update
+  
patches.kernel.org/7.1.3-096-KVM-SVM-Fix-page-overflow-in-sev_dbg_crypt-for-.patch
+  (bsc#1012628 CVE-2026-63794 bsc#1271964).
+- Update
+  
patches.kernel.org/7.1.3-097-power-reset-linkstation-poweroff-fix-use-after-.patch
+  (bsc#1012628 CVE-2026-64246 bsc#1273945).
+- Update
+  patches.kernel.org/7.1.3-100-ntfs-serialize-volume-label-accesses.patch
+  (bsc#1012628 CVE-2026-63793 bsc#1271953).
+- Update
+  
patches.kernel.org/7.1.3-101-fbdev-Fix-fb_new_modelist-to-prevent-null-ptr-d.patch
+  (bsc#1012628 CVE-2026-53403 bsc#1271731).
+- Update
+  
patches.kernel.org/7.1.3-102-fbdev-fbcon-fix-out-of-bounds-read-in-err_out-o.patch
+  (bsc#1012628 CVE-2026-53402 bsc#1271908).
+- Update
+  
patches.kernel.org/7.1.3-103-fbdev-omap2-fix-use-after-free-in-omapfb_mmap.patch
+  (bsc#1012628 CVE-2026-53401 bsc#1271828).
+- Update
+  
patches.kernel.org/7.1.3-104-fbdev-modedb-fix-a-possible-UAF-in-fb_find_mode.patch
+  (bsc#1012628 CVE-2026-64245 bsc#1273905).
+- Update
+  patches.kernel.org/7.1.3-106-i2c-core-fix-adapter-registration-race.patch
+  (bsc#1012628 CVE-2026-53400 bsc#1271906).
+- Update
+  
patches.kernel.org/7.1.3-107-nfsd-release-layout-stid-on-setlease-failure.patch
+  (bsc#1012628 CVE-2026-53399 bsc#1271832).
+- Update
+  
patches.kernel.org/7.1.3-108-NFSD-Fix-SECINFO_NO_NAME-decode-error-cleanup.patch
+  (bsc#1012628 CVE-2026-53398 bsc#1271870).
+- Update
+  
patches.kernel.org/7.1.3-109-nfsd-fix-posix_acl-leak-on-SETACL-decode-failur.patch
+  (bsc#1012628 CVE-2026-53397 bsc#1271869).
+- Update
+  
patches.kernel.org/7.1.3-111-nfsd-fix-posix_acl-leak-and-ignored-error-in-nf.patch
+  (bsc#1012628 CVE-2026-53396 bsc#1271829).
+- Update
+  
patches.kernel.org/7.1.3-113-nfsd-fix-dead-ACL-conflict-guard-in-nfsd4_creat.patch
+  (bsc#1012628 CVE-2026-53395 bsc#1271865).
+- Update
+  
patches.kernel.org/7.1.3-114-nfsd-avoid-leaking-pre-allocated-openowner-on-u.patch
+  (bsc#1012628 CVE-2026-53394 bsc#1271859).
+- Update
+  
patches.kernel.org/7.1.3-115-nfsd-reset-write-verifier-on-deferred-writeback.patch
+  (bsc#1012628 CVE-2026-53393 bsc#1271858).
+- Update
+  
patches.kernel.org/7.1.3-116-NFSv4-flexfiles-reject-zero-filehandle-version-.patch
+  (bsc#1012628 CVE-2026-53392 bsc#1271826).
+- Update
+  
patches.kernel.org/7.1.3-117-NFSv4-pNFS-reject-zero-length-r_addr-in-nfs4_de.patch
+  (bsc#1012628 CVE-2026-53391 bsc#1271904).
+- Update
+  
patches.kernel.org/7.1.3-120-ksmbd-fix-out-of-bounds-read-in-smb_check_perm_.patch
+  (bsc#1012628 CVE-2026-53390 bsc#1271871).
+- Update
+  
patches.kernel.org/7.1.3-121-net-tcp-ao-fix-use-after-free-of-key-in-del_asy.patch
+  (bsc#1012628 CVE-2026-53389 bsc#1271863).
+- Update
+  
patches.kernel.org/7.1.4-003-userfaultfd-gate-must_wait-writability-check-on.patch
+  (bsc#1012628 CVE-2026-64514 bsc#1274044).
+- Update
+  
patches.kernel.org/7.1.4-004-net-sched-dualpi2-fix-GSO-backlog-accounting.patch
+  (bsc#1012628 CVE-2026-64207 bsc#1272216).
+- Update
+  
patches.kernel.org/7.1.4-009-KVM-VMX-Grab-vmcs12-on-CR8-interception-update-.patch
+  (bsc#1012628 CVE-2026-64604).
+- Update
+  
patches.kernel.org/7.1.4-010-KVM-x86-Unconditionally-recompute-CR8-intercept.patch
+  (bsc#1012628 CVE-2026-64513 bsc#1273327).
+- Update
+  
patches.kernel.org/7.1.4-011-ACPI-CPPC-Suppress-UBSAN-warning-caused-by-fiel.patch
+  (bsc#1012628 CVE-2026-64512 bsc#1273597).
+- Update
+  
patches.kernel.org/7.1.4-012-ACPI-NFIT-core-Fix-possible-NULL-pointer-derefe.patch
+  (bsc#1012628 CVE-2026-64511 bsc#1273796).
+- Update
+  
patches.kernel.org/7.1.4-013-ACPI-NFIT-core-Fix-acpi_nfit_init-error-cleanup.patch
+  (bsc#1012628 CVE-2026-64510).
+- Update
+  
patches.kernel.org/7.1.4-014-platform-x86-intel-hid-Protect-ACPI-notify-hand.patch
+  (bsc#1012628 CVE-2026-64603).
+- Update
+  patches.kernel.org/7.1.4-019-rust-block-fix-GenDisk-cleanup-paths.patch
++++ 1041 more lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes
++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.16738/dtb-aarch64.changes
dtb-armv6l.changes: same change
dtb-armv7l.changes: same change
dtb-riscv64.changes: same change
kernel-64kb.changes: same change
kernel-default.changes: same change
kernel-docs.changes: same change
kernel-kvmsmall.changes: same change
kernel-lpae.changes: same change
kernel-obs-build.changes: same change
kernel-obs-qa.changes: same change
kernel-pae.changes: same change
kernel-source.changes: same change
kernel-syms.changes: same change
kernel-vanilla.changes: same change
kernel-zfcpdump.changes: same change

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ dtb-aarch64.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.356270723 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.360270860 +0200
@@ -17,7 +17,7 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
+%define patchversion 7.1.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -25,9 +25,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           dtb-aarch64
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

dtb-armv6l.spec: same change
dtb-armv7l.spec: same change
dtb-riscv64.spec: same change
++++++ kernel-64kb.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.524276454 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.528276590 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-64kb
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

kernel-default.spec: same change
++++++ kernel-docs.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.608279319 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.608279319 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define build_html 1
 %define build_pdf 0
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-docs
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

++++++ kernel-kvmsmall.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.640280411 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.644280547 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-kvmsmall
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

kernel-lpae.spec: same change
++++++ kernel-obs-build.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.720283140 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.720283140 +0200
@@ -19,7 +19,7 @@
 
 #!BuildIgnore: post-build-checks
 
-%define patchversion 7.1.6
+%define patchversion 7.1.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -38,23 +38,23 @@
 %endif
 %endif
 %endif
-%global kernel_package 
kernel%kernel_flavor-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e
+%global kernel_package 
kernel%kernel_flavor-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %endif
 %if 0%{?rhel_version}
 %global kernel_package kernel
 %endif
 
 Name:           kernel-obs-build
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif
 Summary:        package kernel and initrd for OBS VM builds
 License:        GPL-2.0-only
 Group:          SLES
-Provides:       
kernel-obs-build-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e
+Provides:       
kernel-obs-build-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 BuildRequires:  coreutils
 BuildRequires:  device-mapper
 BuildRequires:  dracut

++++++ kernel-obs-qa.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.756284367 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.760284504 +0200
@@ -17,15 +17,15 @@
 # needsrootforbuild
 
 
-%define patchversion 7.1.6
+%define patchversion 7.1.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-obs-qa
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif
@@ -36,7 +36,7 @@
 # kernel-obs-build must be also configured as VMinstall, but is required
 # here as well to avoid that qa and build package build parallel
 %if ! 0%{?qemu_user_space_build}
-BuildRequires:  
kernel-obs-build-srchash-ae5c1b55de3bd891574adbec8ff5c8802def979e
+BuildRequires:  
kernel-obs-build-srchash-a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %endif
 BuildRequires:  modutils
 ExclusiveArch:  aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64

++++++ kernel-pae.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.796285732 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.796285732 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-pae
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

++++++ kernel-source.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.836287096 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.840287233 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define gcc_package gcc
 %define gcc_compiler gcc
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-source
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

++++++ kernel-syms.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.876288461 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.876288461 +0200
@@ -16,15 +16,15 @@
 #
 
 
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-syms
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

++++++ kernel-vanilla.spec ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:24.916289825 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:24.916289825 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.1
-%define patchversion 7.1.6
-%define git_commit ae5c1b55de3bd891574adbec8ff5c8802def979e
+%define patchversion 7.1.7
+%define git_commit a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-vanilla
-Version:        7.1.6
+Version:        7.1.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.gae5c1b5
+Release:        <RELEASE>.ga5cdd68
 %else
 Release:        0
 %endif

kernel-zfcpdump.spec: same change
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:25.108296375 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:25.112296512 +0200
@@ -1,6 +1,6 @@
-mtime: 1785751697
-commit: b54580a80ae04c8a5a35577820138d87ee926e132e71c4331eeaeff61e031985
+mtime: 1786099159
+commit: 61bc19496f97f0d4b5cd778085992cf6c986906fc7b302122b81507281758ad7
 url: https://src.opensuse.org/jirislaby/kernel-source
-revision: b54580a80ae04c8a5a35577820138d87ee926e132e71c4331eeaeff61e031985
+revision: 61bc19496f97f0d4b5cd778085992cf6c986906fc7b302122b81507281758ad7
 trackingbranch: Kernel/stable
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-08-07 12:39:19.000000000 +0200
@@ -0,0 +1 @@
+.osc



++++++ modversions ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:25.576312339 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:25.580312476 +0200
@@ -109,7 +109,7 @@
        next if /^$/;
        chomp;
 
-       if (/^\/\* (.*)\.o \*\//) {
+       if (/^\/\* (.*)\.(o|symtypes) \*\//) {
            close STDOUT;
            mkpath(dirname("$dir/$1$ext"));
            open STDOUT, "> $dir/$1$ext"


++++++ patches.kernel.org.tar.bz2 ++++++
++++ 5286 lines of diff (skipped)

++++++ patches.suse.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/drm-amd-display-use-proper-context-for-logging.patch 
new/patches.suse/drm-amd-display-use-proper-context-for-logging.patch
--- old/patches.suse/drm-amd-display-use-proper-context-for-logging.patch       
1970-01-01 01:00:00.000000000 +0100
+++ new/patches.suse/drm-amd-display-use-proper-context-for-logging.patch       
2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,174 @@
+From: "Jiri Slaby (SUSE)" <[email protected]>
+Date: Thu, 23 Jul 2026 06:25:48 +0200
+Subject: drm/amd/display: use proper context for logging
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+Git-commit: 114b42507b6a23d9d24e24e4ef165233332c64d4
+Patch-mainline: v7.2-rc6
+References: bsc#1271175
+
+The same as the rest of the code, get_ss_info_from_atombios() uses
+calc_pll_cs->ctx->logger for logging. But calc_pll_cs->ctx is
+initialized only later in calc_pll_max_vco_construct(). Therefore, any
+output using DC_LOG_SYNC() leads to a NULL pointer deference in
+get_ss_info_from_atombios().
+
+According to Sashiko, the very same problem exists in
+dce112_get_pix_clk_dividers() and dcn3_get_pix_clk_dividers() too.
+
+To avoid accessing the NULL context, use clk_src->base.ctx->logger
+everywhere. That context in base is initialized earlier in
+dce110_clk_src_construct() and dce112_clk_src_construct(). Before
+get_ss_info_from_atombios() or Sashiko's get_pix_clk_dividers functions
+above are actually called. This is done by redefining DC_LOGGER to
+CTX->logger.
+
+Before:
+dce110_clk_src_construct() did:
+ -> sets clk_src->base.ctx = ctx;
+ -> ss_info_from_atombios_create()
+   -> get_ss_info_from_atombios()   <- uses calc_pll_cs->ctx  # BOOM
+ -> calc_pll_max_vco_construct()    <- sets calc_pll_cs->ctx
+
+After:
+dce110_clk_src_construct() does:
+ -> sets clk_src->base.ctx = ctx;
+ -> ss_info_from_atombios_create()
+   -> get_ss_info_from_atombios()   <- uses clk_src->base.ctx
+
+Closes: https://bugzilla.suse.com/show_bug.cgi?id=1271175
+Closes: 
https://lore.kernel.org/all/[email protected]/
+Fixes: 1296423bf23c ("drm/amd/display: define DC_LOGGER for logger")
+Reviewed-by: Bhawanpreet Lakha <[email protected]>
+Signed-off-by: Jiri Slaby (SUSE) <[email protected]>
+Cc: Lakha, Bhawanpreet <[email protected]>
+Cc: Harry Wentland <[email protected]>
+Cc: Leo Li <[email protected]>
+Cc: Rodrigo Siqueira <[email protected]>
+Cc: Alex Deucher <[email protected]>
+Cc: "Christian König" <[email protected]>
+Cc: David Airlie <[email protected]>
+Cc: Simona Vetter <[email protected]>
+Cc: [email protected]
+Signed-off-by: Alex Deucher <[email protected]>
+(cherry picked from commit 6f16fcbb0c46a87e3d9685407e906573d60104b0)
+Cc: [email protected]
+
+Acked-by: Jiri Slaby <[email protected]>
+---
+ drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c |   20 
++++++++----------
+ 1 file changed, 9 insertions(+), 11 deletions(-)
+
+--- a/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c
++++ b/drivers/gpu/drm/amd/display/dc/dce/dce_clock_source.c
+@@ -45,9 +45,7 @@
+       clk_src->base.ctx
+ 
+ #define DC_LOGGER \
+-      calc_pll_cs->ctx->logger
+-#define DC_LOGGER_INIT() \
+-      struct calc_pll_clock_source *calc_pll_cs = &clk_src->calc_pll
++      CTX->logger
+ 
+ #undef FN
+ #define FN(reg_name, field_name) \
+@@ -289,6 +287,7 @@ static bool calc_pll_dividers_in_range(
+ }
+ 
+ static uint32_t calculate_pixel_clock_pll_dividers(
++              struct dce110_clk_src *clk_src,
+               struct calc_pll_clock_source *calc_pll_cs,
+               struct pll_settings *pll_settings)
+ {
+@@ -477,7 +476,7 @@ static uint32_t dce110_get_pix_clk_divid
+ {
+       uint32_t field = 0;
+       uint32_t pll_calc_error = MAX_PLL_CALC_ERROR;
+-      DC_LOGGER_INIT();
++
+       /* Check if reference clock is external (not pcie/xtalin)
+       * HW Dce80 spec:
+       * 00 - PCIE_REFCLK, 01 - XTALIN,    02 - GENERICA,    03 - GENERICB
+@@ -520,12 +519,14 @@ static uint32_t dce110_get_pix_clk_divid
+               /*Calculate Dividers by HDMI object, no SS case or SS case */
+               pll_calc_error =
+                       calculate_pixel_clock_pll_dividers(
++                                      clk_src,
+                                       &clk_src->calc_pll_hdmi,
+                                       pll_settings);
+       else
+               /*Calculate Dividers by default object, no SS case or SS case */
+               pll_calc_error =
+                       calculate_pixel_clock_pll_dividers(
++                                      clk_src,
+                                       &clk_src->calc_pll,
+                                       pll_settings);
+ 
+@@ -571,7 +572,6 @@ static uint32_t dce110_get_pix_clk_divid
+ {
+       struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
+       uint32_t pll_calc_error = MAX_PLL_CALC_ERROR;
+-      DC_LOGGER_INIT();
+ 
+       if (pix_clk_params == NULL || pll_settings == NULL
+                       || pix_clk_params->requested_pix_clk_100hz == 0) {
+@@ -603,7 +603,6 @@ static uint32_t dce112_get_pix_clk_divid
+               struct pll_settings *pll_settings)
+ {
+       struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
+-      DC_LOGGER_INIT();
+ 
+       if (pix_clk_params == NULL || pll_settings == NULL
+                       || pix_clk_params->requested_pix_clk_100hz == 0) {
+@@ -1372,8 +1371,6 @@ static uint32_t dcn3_get_pix_clk_divider
+       unsigned long long actual_pix_clk_100Hz = pix_clk_params ? 
pix_clk_params->requested_pix_clk_100hz : 0;
+       struct dce110_clk_src *clk_src = TO_DCE110_CLK_SRC(cs);
+ 
+-      DC_LOGGER_INIT();
+-
+       if (pix_clk_params == NULL || pll_settings == NULL
+                       || pix_clk_params->requested_pix_clk_100hz == 0) {
+               DC_LOG_ERROR(
+@@ -1443,7 +1440,6 @@ static const struct clock_source_funcs d
+       .get_pixel_clk_frequency_100hz = get_pixel_clk_frequency_100hz
+ };
+ 
+-
+ static void get_ss_info_from_atombios(
+               struct dce110_clk_src *clk_src,
+               enum as_signal_type as_signal,
+@@ -1456,7 +1452,7 @@ static void get_ss_info_from_atombios(
+       struct spread_spectrum_info *ss_info_cur;
+       struct spread_spectrum_data *ss_data_cur;
+       uint32_t i;
+-      DC_LOGGER_INIT();
++
+       if (ss_entries_num == NULL) {
+               DC_LOG_SYNC(
+                       "Invalid entry !!!\n");
+@@ -1587,6 +1583,7 @@ static void ss_info_from_atombios_create
+ }
+ 
+ static bool calc_pll_max_vco_construct(
++                      struct dce110_clk_src *clk_src,
+                       struct calc_pll_clock_source *calc_pll_cs,
+                       struct calc_pll_clock_source_init_data *init_data)
+ {
+@@ -1738,6 +1735,7 @@ bool dce110_clk_src_construct(
+       ss_info_from_atombios_create(clk_src);
+ 
+       if (!calc_pll_max_vco_construct(
++                      clk_src,
+                       &clk_src->calc_pll,
+                       &calc_pll_cs_init_data)) {
+               ASSERT_CRITICAL(false);
+@@ -1752,7 +1750,7 @@ bool dce110_clk_src_construct(
+ 
+ 
+       if (!calc_pll_max_vco_construct(
+-                      &clk_src->calc_pll_hdmi, &calc_pll_cs_init_data_hdmi)) {
++                      clk_src, &clk_src->calc_pll_hdmi, 
&calc_pll_cs_init_data_hdmi)) {
+               ASSERT_CRITICAL(false);
+               goto unexpected_failure;
+       }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
--- 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,77 @@
+From: Pedro Falcato <[email protected]>
+Date: Mon, 3 Aug 2026 13:16:25 +0100
+Subject: x86/alternative: exclude text poking against change_page_attr()
+References: bsc#1271202
+Patch-mainline: Submitted, [email protected]
+
+From time to time, the following BUG can be observed[0]:
+
+> kernel BUG at arch/x86/kernel/alternative.c:2576!
+> Oops: invalid opcode: 0000 [#1] SMP NOPTI
+> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 
PREEMPT(full) openSUSE Tumbleweed  8c1795b03ec64f997e57a8ad38b1161e3b98da64
+> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 
02/02/2022
+> RIP: 0010:__text_poke+0x2aa/0x450
+> Call Trace:
+>  <TASK>
+>  smp_text_poke_batch_finish+0x2a7/0x320
+>  __static_call_transform+0xb7/0x220
+>  arch_static_call_transform+0x5b/0xb0
+>  __static_call_init+0xe9/0x270
+>  static_call_module_notify+0x11f/0x150
+>  notifier_call_chain+0x61/0xe0
+>  blocking_notifier_call_chain_robust+0x63/0xc0
+>  load_module+0x1c92/0x20c0
+>  init_module_from_file+0xd8/0x140
+>  idempotent_init_module+0x100/0x2f0
+>  __x64_sys_finit_module+0x71/0xe0
+>  do_syscall_64+0xe1/0x610
+>  entry_SYSCALL_64_after_hwframe+0x76/0x7e
+
+which matches the following BUG_ON in alternative.c:
+       /*
+        * If something went wrong, crash and burn since recovery paths are not
+        * implemented.
+        */
+       BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));
+
+This can happen if vmalloc_to_page() fails, for any reason. Such can happen
+if text poking races with CPA, which can possibly result in the collapsing
+of page tables (or breaking of PMD hugepages). It is not a problem for most
+users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when
+CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc
+range, and can call set_memory_*() in parallel on it. This can happen to
+race against __text_poke and cause havoc in vmalloc_to_page().
+
+Fix it by excluding against CPA using the init_mm mmap read lock.
+
+Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
+Reported-by: Jiri Slaby <[email protected]>
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Reported-by: Steffen Dirkwinkel <[email protected]>
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Cc: [email protected]
+Signed-off-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/kernel/alternative.c | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/arch/x86/kernel/alternative.c b/arch/x86/kernel/alternative.c
+index 62936a3bde19..9071eb870eab 100644
+--- a/arch/x86/kernel/alternative.c
++++ b/arch/x86/kernel/alternative.c
+@@ -2559,6 +2559,14 @@ static void *__text_poke(text_poke_f func, void *addr, 
const void *src, size_t l
+        */
+       BUG_ON(!after_bootmem);
+ 
++      /*
++       * Exclude against change_page_attr() collapse in execmem ROX regions.
++       * These are PMD sized and this module may not own the whole PMD,
++       * thus breakdown/collapse may happen at any moment by concurrent module
++       * loading, which races with vmalloc_to_page().
++       */
++      guard(mmap_read_lock)(&init_mm);
++
+       if (!core_kernel_text((unsigned long)addr)) {
+               pages[0] = vmalloc_to_page(addr);
+               if (cross_page_boundary)
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 
new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch
--- old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch      
1970-01-01 01:00:00.000000000 +0100
+++ new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch      
2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,199 @@
+From: Peter Zijlstra <[email protected]>
+Date: Wed, 29 Jul 2026 13:08:10 +0200
+Subject: x86/mm: Fix and document DEBUG_PAGEALLOC
+References: bsc#1271202
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 7da514d819a0afb148634aac92b3d190f34947c3
+Patch-mainline: Queued in subsystem maintainer repository
+
+It turns out that commit 5fce67641a3e ("x86/mm/pat: Don't gate
+cpa_lock on debug_pagealloc_enabled()") was a little too quick to
+remove the debug_pagealloc exception for cpa_lock.
+
+Notably __kernel_map_pages() is used by the page-allocator from any
+context the page-allocator itself is used, which violates the cpa_lock
+rules.
+
+Re-instate the exception, except make it specific to the
+__kernel_map_pages() such that any other cpa() usage is still fully
+serialized by cpa_lock. Also note that since cpa() should not be used
+on memory that isn't allocated, the page-allocator locking and cpa are
+infact mutually exclusive and all cpa usage in fully serialized.
+
+Add a comment explaining this and other 'funnies' surrounding
+DEBUG_PAGEALLOC, including how pgd_lock is not affected and the TLB
+trickery.
+
+Fixes: 5fce67641a3e ("x86/mm/pat: Don't gate cpa_lock on 
debug_pagealloc_enabled()")
+Signed-off-by: Peter Zijlstra (Intel) <[email protected]>
+Link: https://patch.msgid.link/[email protected]
+Signed-off-by: Jiri Slaby <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c |   80 
+++++++++++++++++++++++++++++++------------
+ 1 file changed, 58 insertions(+), 22 deletions(-)
+
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -68,11 +68,12 @@ static const int cpa_warn_level = CPA_PR
+  */
+ static DEFINE_SPINLOCK(cpa_lock);
+ 
+-#define CPA_FLUSHTLB 1
+-#define CPA_ARRAY 2
+-#define CPA_PAGES_ARRAY 4
+-#define CPA_NO_CHECK_ALIAS 8 /* Do not search for aliases */
+-#define CPA_COLLAPSE 16 /* try to collapse large pages */
++#define CPA_FLUSHTLB          0x01
++#define CPA_ARRAY             0x02
++#define CPA_PAGES_ARRAY               0x04
++#define CPA_NO_CHECK_ALIAS    0x08 /* Do not search for aliases */
++#define CPA_COLLAPSE          0x10 /* try to collapse large pages */
++#define CPA_DEBUG_PAGEALLOC   0x20
+ 
+ static inline pgprot_t cachemode2pgprot(enum page_cache_mode pcm)
+ {
+@@ -2007,6 +2008,7 @@ static int __change_page_attr_set_clr(st
+ {
+       unsigned long numpages = cpa->numpages;
+       unsigned long rempages = numpages;
++      bool lock = true;
+       int ret = 0;
+ 
+       /*
+@@ -2016,6 +2018,29 @@ static int __change_page_attr_set_clr(st
+           !cpa->force_split)
+               return ret;
+ 
++      /*
++       * DEBUG_PAGEALLOC is special; it is called from any context the
++       * page-allocator is, which violates the normal cpa_lock locking
++       * rules.
++       *
++       * However, since it is part of the page-allocator, things are still
++       * properly serialized by the page-allocator locking and the fact that
++       * when a page is owned by the page-allocator, it isn't owned by
++       * anybody else. That is, you *SHOULD NOT* be calling cpa() on memory
++       * that isn't allocated.
++       *
++       * Additionally, DEBUG_PAGEALLOC ensures (per probe_page_size_mask())
++       * that the kernel mapping is 4k pages, therefore there are no large
++       * pages to split/collapse.
++       *
++       * Furthermore, the page-allocator strictly manages pages that
++       * *exist*, avoiding pgd_lock.
++       *
++       * Therefore, it is safe to not take cpa_lock.
++       */
++      if (debug_pagealloc_enabled() && (cpa->flags & CPA_DEBUG_PAGEALLOC))
++              lock = false;
++
+       while (rempages) {
+               /*
+                * Store the remaining nr of pages for the large page
+@@ -2026,9 +2051,12 @@ static int __change_page_attr_set_clr(st
+               if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY))
+                       cpa->numpages = 1;
+ 
+-              spin_lock(&cpa_lock);
+-              ret = __change_page_attr(cpa, primary);
+-              spin_unlock(&cpa_lock);
++              if (lock) {
++                      guard(spinlock)(&cpa_lock);
++                      ret = __change_page_attr(cpa, primary);
++              } else {
++                      ret = __change_page_attr(cpa, primary);
++              }
+               if (ret)
+                       goto out;
+ 
+@@ -2607,7 +2635,7 @@ int set_pages_rw(struct page *page, int
+       return set_memory_rw(addr, numpages);
+ }
+ 
+-static int __set_pages_p(struct page *page, int numpages)
++static int __set_pages_p(struct page *page, int numpages, unsigned int 
cpa_flags)
+ {
+       unsigned long tempaddr = (unsigned long) page_address(page);
+       struct cpa_data cpa = { .vaddr = &tempaddr,
+@@ -2615,7 +2643,7 @@ static int __set_pages_p(struct page *pa
+                               .numpages = numpages,
+                               .mask_set = __pgprot(_PAGE_PRESENT | _PAGE_RW),
+                               .mask_clr = __pgprot(0),
+-                              .flags = CPA_NO_CHECK_ALIAS };
++                              .flags = CPA_NO_CHECK_ALIAS | cpa_flags };
+ 
+       /*
+        * No alias checking needed for setting present flag. otherwise,
+@@ -2626,7 +2654,7 @@ static int __set_pages_p(struct page *pa
+       return __change_page_attr_set_clr(&cpa, 1);
+ }
+ 
+-static int __set_pages_np(struct page *page, int numpages)
++static int __set_pages_np(struct page *page, int numpages, unsigned int 
cpa_flags)
+ {
+       unsigned long tempaddr = (unsigned long) page_address(page);
+       struct cpa_data cpa = { .vaddr = &tempaddr,
+@@ -2634,7 +2662,7 @@ static int __set_pages_np(struct page *p
+                               .numpages = numpages,
+                               .mask_set = __pgprot(0),
+                               .mask_clr = __pgprot(_PAGE_PRESENT | _PAGE_RW | 
_PAGE_DIRTY),
+-                              .flags = CPA_NO_CHECK_ALIAS };
++                              .flags = CPA_NO_CHECK_ALIAS | cpa_flags };
+ 
+       /*
+        * No alias checking needed for setting not present flag. otherwise,
+@@ -2647,20 +2675,20 @@ static int __set_pages_np(struct page *p
+ 
+ int set_direct_map_invalid_noflush(struct page *page)
+ {
+-      return __set_pages_np(page, 1);
++      return __set_pages_np(page, 1, 0);
+ }
+ 
+ int set_direct_map_default_noflush(struct page *page)
+ {
+-      return __set_pages_p(page, 1);
++      return __set_pages_p(page, 1, 0);
+ }
+ 
+ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
+ {
+       if (valid)
+-              return __set_pages_p(page, nr);
++              return __set_pages_p(page, nr, 0);
+ 
+-      return __set_pages_np(page, nr);
++      return __set_pages_np(page, nr, 0);
+ }
+ 
+ #ifdef CONFIG_DEBUG_PAGEALLOC
+@@ -2679,15 +2707,23 @@ void __kernel_map_pages(struct page *pag
+        * and hence no memory allocations during large page split.
+        */
+       if (enable)
+-              __set_pages_p(page, numpages);
++              __set_pages_p(page, numpages, CPA_DEBUG_PAGEALLOC);
+       else
+-              __set_pages_np(page, numpages);
++              __set_pages_np(page, numpages, CPA_DEBUG_PAGEALLOC);
+ 
+       /*
+-       * We should perform an IPI and flush all tlbs,
+-       * but that can deadlock->flush only current cpu.
+-       * Preemption needs to be disabled around __flush_tlb_all() due to
+-       * CR3 reload in __native_flush_tlb().
++       * We should perform an IPI and flush all tlbs, but that can
++       * deadlock, settle for a local flush.
++       *
++       * Not doing a global TLB flush means that remote CPUs will retain
++       * stale TLB entries. In case of P->NP (on free) this means the remote
++       * CPUs will not take the faults, making the debug scheme less
++       * reliable. On the NP->P (on alloc) this means the remote CPUs can
++       * take a spurious fault. However spurious_kernel_fault() will observe
++       * *_present() and fix it up.
++       *
++       * Preemption needs to be disabled around __flush_tlb_all() due to CR3
++       * reload in __native_flush_tlb().
+        */
+       preempt_disable();
+       __flush_tlb_all();
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
 
new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
--- 
old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
    2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,85 @@
+From: "Mike Rapoport (Microsoft)" <[email protected]>
+Date: Wed, 15 Jul 2026 17:45:19 +0300
+Subject: x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled()
+References: bsc#1271202
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 5fce67641a3ed9a0782eaa228ddece526461a367
+Patch-mainline: Queued in subsystem maintainer repository
+
+The splitting and merging of kernel page table mappings between small and
+large is protected by cpa_lock. The merging is relatively new but the
+splitting is ancient.
+
+The splitting has a locking optimization: since DEBUG_PAGEALLOC forces all
+mappings to 4k, there are no large pages to split. So the code that *might*
+cause a split can just skip the locking (and a few other things).
+
+This is entertaining, but it adds complexity and makes for weird locking
+rules. Plus it's all for a debugging feature which makes the kernel super
+slow in the first place. Optimizing something which is already super slow
+and not used in production is not the best way to spend our complexity
+budget.
+
+Stop gating cpa_lock on debug_pagealloc_enabled() to simplify the code
+and the locking rules.
+
+[ dhansen: flesh out changelog ]
+
+Suggested-by: Dave Hansen <[email protected]>
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
+Link: https://patch.msgid.link/[email protected]
+Link: 
https://lore.kernel.org/all/[email protected]/
+
+Acked-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c | 19 +++++++------------
+ 1 file changed, 7 insertions(+), 12 deletions(-)
+
+diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
+index 45623d4c24c9..e9b408343c5d 100644
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -62,10 +62,9 @@ enum cpa_warn {
+ static const int cpa_warn_level = CPA_PROTECT;
+ 
+ /*
+- * Serialize cpa() (for !DEBUG_PAGEALLOC which uses large identity mappings)
+- * using cpa_lock. So that we don't allow any other cpu, with stale large tlb
+- * entries change the page attribute in parallel to some other cpu
+- * splitting a large page entry along with changing the attribute.
++ * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with
++ * stale large tlb entries, to change the page attribute in parallel to some
++ * other cpu splitting a large page entry along with changing the attribute.
+  */
+ static DEFINE_SPINLOCK(cpa_lock);
+ 
+@@ -1234,11 +1233,9 @@ static int split_large_page(struct cpa_data *cpa, pte_t 
*kpte,
+ {
+       struct ptdesc *ptdesc;
+ 
+-      if (!debug_pagealloc_enabled())
+-              spin_unlock(&cpa_lock);
++      spin_unlock(&cpa_lock);
+       ptdesc = pagetable_alloc(GFP_KERNEL, 0);
+-      if (!debug_pagealloc_enabled())
+-              spin_lock(&cpa_lock);
++      spin_lock(&cpa_lock);
+       if (!ptdesc)
+               return -ENOMEM;
+ 
+@@ -2022,11 +2019,9 @@ static int __change_page_attr_set_clr(struct cpa_data 
*cpa, int primary)
+               if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY))
+                       cpa->numpages = 1;
+ 
+-              if (!debug_pagealloc_enabled())
+-                      spin_lock(&cpa_lock);
++              spin_lock(&cpa_lock);
+               ret = __change_page_attr(cpa, primary);
+-              if (!debug_pagealloc_enabled())
+-                      spin_unlock(&cpa_lock);
++              spin_unlock(&cpa_lock);
+               if (ret)
+                       goto out;
+ 
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch 
new/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch
--- old/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch  
1970-01-01 01:00:00.000000000 +0100
+++ new/patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch  
2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,101 @@
+From: "Denis V. Lunev" <[email protected]>
+Date: Wed, 15 Jul 2026 20:34:52 +0200
+Subject: x86/mm/pat: Take cpa_lock around large-page collapse
+References: bsc#1271202
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 1aac65f3e651334259ecb2a5f5ddb81c01f02599
+Patch-mainline: Queued in subsystem maintainer repository
+
+Loading and unloading modules concurrently on several CPUs on a KASAN
+build, with a short delay injected at the CPA page-table lookup to
+widen the window, faults within minutes:
+
+  BUG: KASAN: use-after-free in __change_page_attr+0x7cc/0x7e0
+  Write of size 8 at addr ffff888181139718 by task modprobe
+  ...
+  The buggy address belongs to the physical page:
+   pfn:0x181139 ... page_type: f2(table)
+
+cpa_collapse_large_pages() rebuilds a leaf PMD from its 4K PTEs and
+frees the old PTE-table pages, while __change_page_attr() fetches a
+PTE pointer from a lockless lookup_address_in_pgd_attr() and writes
+it with set_pte_atomic() only later. When module text is served from
+a shared large ROX mapping the two run on the same PMD:
+
+  CPU A (module load)              CPU B (module finalize)
+  -------------------              -----------------------
+  execmem_make_temp_rw
+   set_memory_nx
+    __change_page_attr
+     split 2M -> 4K table P
+     kpte = &P[i]  (lockless)
+                                   execmem_restore_rox
+                                    set_memory_rox (CPA_COLLAPSE)
+                                     cpa_collapse_large_pages
+                                      rebuild leaf PMD
+                                      flush_tlb_all
+                                      pagetable_free(P)
+     set_pte_atomic(kpte, ...)
+       -> writes into freed P
+
+P is a page-table page (page_type: table), reused at once, so the
+write corrupts whatever got the page next: a bad-pte or bad-page
+splat, or a fatal fault once P has been turned into read-only text.
+
+The flush_tlb_all() before the free does not close this: its IPI only
+serializes against page-table walkers that run with interrupts off
+(e.g. GUP-fast); the walk in __change_page_attr() runs with interrupts
+on, so nothing stops it from holding a stale pointer into P.
+
+Serialize the collapse - the PMD rebuild, TLB flush and PTE-table
+free - under cpa_lock, the same lock __change_page_attr() now takes
+unconditionally since commit ("x86/mm/pat: stop gating cpa_lock on
+debug_pagealloc_enabled()"), so a concurrent walker can no longer
+hold a pointer into a table the collapse is about to free.
+
+Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
+Signed-off-by: Denis V. Lunev <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
+Acked-by: Kiryl Shutsemau (Meta) <[email protected]>
+Link: https://patch.msgid.link/[email protected]
+
+Acked-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c | 8 +++++++-
+ 1 file changed, 7 insertions(+), 1 deletion(-)
+
+diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
+index e9b408343c5d..b1e780a465b5 100644
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -417,6 +417,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
+       int collapsed = 0;
+       int i;
+ 
++      spin_lock(&cpa_lock);
++
+       if (cpa->flags & (CPA_PAGES_ARRAY | CPA_ARRAY)) {
+               for (i = 0; i < cpa->numpages; i++)
+                       collapsed += collapse_large_pages(__cpa_addr(cpa, i),
+@@ -430,8 +432,10 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
+                       collapsed += collapse_large_pages(addr, &pgtables);
+       }
+ 
+-      if (!collapsed)
++      if (!collapsed) {
++              spin_unlock(&cpa_lock);
+               return;
++      }
+ 
+       flush_tlb_all();
+ 
+@@ -439,6 +443,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
+               list_del(&ptdesc->pt_list);
+               pagetable_free(ptdesc);
+       }
++
++      spin_unlock(&cpa_lock);
+ }
+ 
+ static void cpa_flush(struct cpa_data *cpa, int cache)
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,163 @@
+From: "Lorenzo Stoakes (ARM)" <[email protected]>
+Date: Tue, 28 Jul 2026 16:07:46 +0300
+Subject: x86/mm/pat: acquire init_mm read lock on attribute change to avoid
+ UAF
+References: bsc#1271202
+Patch-mainline: Submitted, [email protected]
+
+A previous commit protected us against races between ptdump and CPA
+collapse, however one still exists between attribute changes and collapse
+as reported by Denis V. Lunev (linked).
+
+When an attribute change arises, a lockless page table walker obtains a PTE
+entry, which is later written to via set_pte_atomic():
+
+...
+-> change_page_attr_set_clr()
+-> __change_page_attr_set_clr()
+-> __change_page_attr()
+       -> _lookup_address_cpa()
+       -> lookup_address_in_pgd_attr()
+       -> [ lockless page table walker ]
+-> set_pte_atomic()
+
+There is nothing preventing a concurrent CPA collapse which can free the
+PTE that was retrieved here, resulting in a use-after-free.
+
+With the mmap write lock taken on init_mm over CPA collapse, we can now
+resolve this race by acquiring an mmap read lock on init_mm over
+__change_page_attr_set_clr().
+
+This locks across the whole operation over which the walk and the PTE entry
+write occurs, solving the race.
+
+It is safe to do this here, as no spinlocks are held upon entry to
+__change_page_attr_set_clr().
+
+However, the lock must not be held over an allocation, as allocation can
+trigger reclaim and shrinkers may call into CPA recursively, making
+deadlocks possible (init_mm -> ... -> fs_reclaim -> init_mm).
+
+A page table is allocated when a huge page needs to be split:
+
+-> change_page_attr_set_clr()
+-> __change_page_attr_set_clr()
+-> __change_page_attr()
+-> split_large_page()
+[ pagetable_alloc() ]
+-> __split_large_page()
+
+Avoid deadlocks by dropping the mmap lock across pagetable_alloc() in
+split_large_page() and track whether this is needed by adding a new
+'init_mm_read_locked' flag to struct cpa_data.
+
+This is safe as __split_large_page() (called with locks re-established)
+revalidates that the page table entry is the same as it was prior to the
+locks being dropped and __change_page_attr() repeats the entire page table
+walk whenever a split occurs, so concurrent split and collapse are
+accounted for.
+
+Concurrent ptdump is also safe as the lock is only dropped over page table
+allocation during which time the page table has not yet been modified.
+
+The CPA_COLLAPSE flag is only set by set_memory_rox(), which exclusively
+operates upon vmalloc ranges, and on x86 only within the module mapping
+space.
+
+This is important, because some callers directly invoke
+__change_page_attr_set_clr(), bypassing this lock. However, none of these
+operate within the module mapping space.
+
+* cpa_process_alias() - a recursive helper called by
+  __change_page_attr_set_clr().
+* __set_memory_enc_pgtable() - operates on the direct mapping and (via
+  __vmbus_establish_gpadl()) the vmalloc mapping space.
+* __set_pages_[n]p() - called by set_direct_map_[invalid, default,
+  valid]_noflush(), __kernel_map_pages() - operates on the direct map.
+* kernel_[un]map_pages_in_pgd() - operates on EFI ranges.
+
+This work is based upon Denis V. Lunev's excellent analysis of the bug with
+gratitude.
+
+Link: https://lore.kernel.org/all/[email protected]/
+Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
+Cc: [email protected]
+Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Signed-off-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c |   22 +++++++++++++---------
+ 1 file changed, 13 insertions(+), 9 deletions(-)
+
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -50,7 +50,8 @@ struct cpa_data {
+       unsigned int    flags;
+       unsigned int    force_split             : 1,
+                       force_static_prot       : 1,
+-                      force_flush_all         : 1;
++                      force_flush_all         : 1,
++                      init_mm_read_locked     : 1;
+       struct page     **pages;
+ };
+ 
+@@ -419,8 +420,6 @@ static void __cpa_collapse_large_pages(s
+       int collapsed = 0;
+       int i;
+ 
+-      spin_lock(&cpa_lock);
+-
+       if (cpa->flags & (CPA_PAGES_ARRAY | CPA_ARRAY)) {
+               for (i = 0; i < cpa->numpages; i++)
+                       collapsed += collapse_large_pages(__cpa_addr(cpa, i),
+@@ -434,10 +433,8 @@ static void __cpa_collapse_large_pages(s
+                       collapsed += collapse_large_pages(addr, &pgtables);
+       }
+ 
+-      if (!collapsed) {
+-              spin_unlock(&cpa_lock);
++      if (!collapsed)
+               return;
+-      }
+ 
+       flush_tlb_all();
+ 
+@@ -445,8 +442,6 @@ static void __cpa_collapse_large_pages(s
+               list_del(&ptdesc->pt_list);
+               pagetable_free(ptdesc);
+       }
+-
+-      spin_unlock(&cpa_lock);
+ }
+ 
+ static void cpa_collapse_large_pages(struct cpa_data *cpa)
+@@ -1255,8 +1250,13 @@ static int split_large_page(struct cpa_d
+       struct ptdesc *ptdesc;
+ 
+       spin_unlock(&cpa_lock);
++      if (cpa->init_mm_read_locked)
++              mmap_read_unlock(&init_mm);
+       ptdesc = pagetable_alloc(GFP_KERNEL, 0);
++      if (cpa->init_mm_read_locked)
++              mmap_read_lock(&init_mm);
+       spin_lock(&cpa_lock);
++
+       if (!ptdesc)
+               return -ENOMEM;
+ 
+@@ -2151,7 +2151,11 @@ static int change_page_attr_set_clr(unsi
+       cpa.curpage = 0;
+       cpa.force_split = force_split;
+ 
+-      ret = __change_page_attr_set_clr(&cpa, 1);
++      /* Avoid race with concurrent CPA collapse. */
++      cpa.init_mm_read_locked = true;
++      scoped_guard(mmap_read_lock, &init_mm)
++              ret = __change_page_attr_set_clr(&cpa, 1);
++      cpa.init_mm_read_locked = false;
+ 
+       /*
+        * Check whether we really changed something:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,114 @@
+From: "Lorenzo Stoakes (ARM)" <[email protected]>
+Date: Tue, 28 Jul 2026 16:07:45 +0300
+Subject: x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
+References: bsc#1271202
+Patch-mainline: Submitted, [email protected]
+
+x86 implements page attribute modification using its Change Page
+Attributes (CPA) mechanism.
+
+This tracks properties of ranges such as cache mode through x86 page
+attributes, and as part of that logic manipulates kernel page tables.
+
+Since commit 41d88484c71c ("x86/mm/pat: restore large ROX pages after
+fragmentation") ranges of kernel page table entries can be collapsed into
+huge page table entries as part of this logic.
+
+As part of this collapse, it frees the page tables which the collapsed
+entries previously pointed to, and it does so without any relevant locks
+being held to preclude concurrent kernel page table walkers.
+
+The only way this code can be reached is if CPA_COLLAPSE is specified, and
+this is only set in set_memory_rox() via:
+
+set_memory_rox()
+-> change_page_attr_set_clr()
+-> cpa_flush()
+-> cpa_collapse_large_pages()
+
+Notable users of this are execmem and bpf when manipulating executable
+mappings.
+
+However, this is problematic for ptdump as it walks ranges it does not own
+and thus runs the risk of a use-after-free on page tables freed underneath
+it.
+
+In addition, concurrent CPA collapse operations are possible which can also
+cause races.
+
+Resolve the issue by acquiring the mmap write lock on init_mm across the
+whole operation.
+
+It is safe to acquire a sleeping lock as all the callers invoke
+set_memory_rox() from process context and in any case,
+change_page_attr_set_clr() calls vm_unmap_alias() which ultimately takes a
+mutex, disallowing atomic context here.
+
+Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
+Cc: [email protected]
+Reviewed-by: Mike Rapoport (Microsoft) <[email protected]>
+Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]>
+Reviewed-by: David Hildenbrand (Arm) <[email protected]>
+Reviewed-by: Dave Hansen <[email protected]>
+Reviewed-by: Will Deacon <[email protected]>
+Reviewed-by: David Carlier <[email protected]>
+Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Signed-off-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c |   15 ++++++++++++++-
+ include/linux/mmap_lock.h    |    2 ++
+ 2 files changed, 16 insertions(+), 1 deletion(-)
+
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -22,6 +22,7 @@
+ #include <linux/cc_platform.h>
+ #include <linux/set_memory.h>
+ #include <linux/memregion.h>
++#include <linux/cleanup.h>
+ 
+ #include <asm/e820/api.h>
+ #include <asm/processor.h>
+@@ -410,7 +411,7 @@ static void __cpa_flush_tlb(void *data)
+ 
+ static int collapse_large_pages(unsigned long addr, struct list_head 
*pgtables);
+ 
+-static void cpa_collapse_large_pages(struct cpa_data *cpa)
++static void __cpa_collapse_large_pages(struct cpa_data *cpa)
+ {
+       unsigned long start, addr, end;
+       struct ptdesc *ptdesc, *tmp;
+@@ -448,6 +449,18 @@ static void cpa_collapse_large_pages(str
+       spin_unlock(&cpa_lock);
+ }
+ 
++static void cpa_collapse_large_pages(struct cpa_data *cpa)
++{
++      /*
++       * Take the mmap write lock on init_mm to:
++       * - Avoid a use-after-free if raced by ptdump (which takes its own
++       *   write lock on init_mm).
++       * - Serialise concurrent CPA walkers.
++       */
++      scoped_guard(mmap_write_lock, &init_mm)
++              __cpa_collapse_large_pages(cpa);
++}
++
+ static void cpa_flush(struct cpa_data *cpa, int cache)
+ {
+       unsigned int i;
+--- a/include/linux/mmap_lock.h
++++ b/include/linux/mmap_lock.h
+@@ -621,6 +621,8 @@ static inline void mmap_read_unlock(stru
+ 
+ DEFINE_GUARD(mmap_read_lock, struct mm_struct *,
+            mmap_read_lock(_T), mmap_read_unlock(_T))
++DEFINE_GUARD(mmap_write_lock, struct mm_struct *,
++           mmap_write_lock(_T), mmap_write_unlock(_T))
+ 
+ static inline void mmap_read_unlock_non_owner(struct mm_struct *mm)
+ {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
--- 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,125 @@
+From: "Lorenzo Stoakes (ARM)" <[email protected]>
+Date: Tue, 28 Jul 2026 16:07:47 +0300
+Subject: x86/mm/pat: allocate split page tables as kernel page tables
+References: bsc#1271202
+Patch-mainline: Submitted, [email protected]
+
+When splitting a large page in CPA in __split_large_page() we allocate a
+PTE directly without going through the standard page table allocation
+routines such as pte_alloc_one_kernel().
+
+This means the page table constructor is never called nor is the page table
+marked as a kernel page table.
+
+The former results in the folio associated with the page table not being
+marked as a page table (__pagetable_ctor() is never called thus neither is
+__folio_set_pgtable()) nor are statistics updated to reflect
+it (lruvec_stat_add_folio() is never called).
+
+The latter issue of failing to mark the page table as a kernel page
+table (ptdesc_set_kernel() is never called) is far more problematic.
+
+Since commit 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page
+tables") kernel page table freeing has been batched and since the
+subsequent commit e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries
+for kernel address space") IOTLB cache entries for kernel page tables have
+been invalidated upon being freed.
+
+Since split page tables are freed without this invalidation, the IOTLB can
+contain stale entries for them.
+
+Resolve the issue by using the ordinary PTE allocation API at split time.
+
+This results in these kernel page tables invoking a page table constructor,
+and thus requires a page table destructor.
+
+Since we cannot assume one is always present (early allocated direct map
+page tables are not marked as such), we conditionally call
+pagetable_dtor_free() if the PG_table folio flag for the ptdesc is set,
+otherwise we free the page table via pagetable_free().
+
+Regardless of which path is taken page tables marked as kernel page tables,
+which now includes split page tables, take the correct route through
+pagetable_free_kernel().
+
+There is a user-visible side effect in that split page tables will appear
+in nr_page_table_pages in /proc/vmstat (as do other kernel page tables
+allocated after early boot), however this is a positive change.
+
+This issue started being markedly problematic after commit
+5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so
+choose this as the Fixes target.
+
+Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables")
+Cc: [email protected]
+Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
+Acked-by: Vishal Moola <[email protected]>
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Signed-off-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c |   25 ++++++++++++++++---------
+ 1 file changed, 16 insertions(+), 9 deletions(-)
+
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -440,7 +440,15 @@ static void __cpa_collapse_large_pages(s
+ 
+       list_for_each_entry_safe(ptdesc, tmp, &pgtables, pt_list) {
+               list_del(&ptdesc->pt_list);
+-              pagetable_free(ptdesc);
++              /*
++               * Only early alloc'd direct map should not be flagged PG_table
++               * here and those shouldn't be collapsed. However be abundantly
++               * cautious and handle the !PG_table case too.
++               */
++              if (PageTable((ptdesc_page(ptdesc))))
++                      pagetable_dtor_free(ptdesc);
++              else
++                      pagetable_free(ptdesc);
+       }
+ }
+ 
+@@ -1139,11 +1147,10 @@ set:
+ 
+ static int
+ __split_large_page(struct cpa_data *cpa, pte_t *kpte, unsigned long address,
+-                 struct ptdesc *ptdesc)
++                 pte_t *pbase)
+ {
+       unsigned long lpaddr, lpinc, ref_pfn, pfn, pfninc = 1;
+-      struct page *base = ptdesc_page(ptdesc);
+-      pte_t *pbase = (pte_t *)page_address(base);
++      struct page *base = virt_to_page(pbase);
+       unsigned int i, level;
+       pgprot_t ref_prot;
+       bool nx, rw;
+@@ -1247,21 +1254,21 @@ __split_large_page(struct cpa_data *cpa,
+ static int split_large_page(struct cpa_data *cpa, pte_t *kpte,
+                           unsigned long address)
+ {
+-      struct ptdesc *ptdesc;
++      pte_t *pte;
+ 
+       spin_unlock(&cpa_lock);
+       if (cpa->init_mm_read_locked)
+               mmap_read_unlock(&init_mm);
+-      ptdesc = pagetable_alloc(GFP_KERNEL, 0);
++      pte = pte_alloc_one_kernel(&init_mm);
+       if (cpa->init_mm_read_locked)
+               mmap_read_lock(&init_mm);
+       spin_lock(&cpa_lock);
+ 
+-      if (!ptdesc)
++      if (!pte)
+               return -ENOMEM;
+ 
+-      if (__split_large_page(cpa, kpte, address, ptdesc))
+-              pagetable_free(ptdesc);
++      if (__split_large_page(cpa, kpte, address, pte))
++              pte_free_kernel(&init_mm, pte);
+ 
+       return 0;
+ }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
 
new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
--- 
old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
   1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
   2026-08-07 12:29:37.000000000 +0200
@@ -0,0 +1,87 @@
+From: "Mike Rapoport (Microsoft)" <[email protected]>
+Date: Tue, 28 Jul 2026 16:07:48 +0300
+Subject: x86/mm/pat: fix effective RW computation in
+ lookup_address_in_pgd_attr()
+References: bsc#1271202
+Patch-mainline: Submitted, [email protected]
+
+lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of
+the walked page table levels so that verify_rwx() can detect mappings that
+are both writable and executable.
+
+The RW bits are folded into a bool with
+
+       rw &= pXd_flags(*pXd) & _PAGE_RW;
+
+but _PAGE_RW is 0x2. So consider the accumulation line:
+
+        rw &= pXd_flags(*pXd) & _PAGE_RW;
+
+where rw=0x1 and the right side evaluates down to 0x2. It'll end up doing:
+
+        rw = 0x1 & 0x2
+
+and rw always ends up 0.
+
+This way rw becomes false at the first level walked, regardless of the
+actual permissions, and verify_rwx() treats every mapping as non-writable
+and never reports a W^X violation.
+
+Add double negation to the right side to normalize the _PAGE_RW flag to
+0 or 1.
+
+Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()")
+Cc: [email protected]
+Assisted-by: Copilot:claude-opus-4.8
+Reviewed-by: Juergen Gross <[email protected]>
+Tested-by: [email protected]
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Signed-off-by: Pedro Falcato <[email protected]>
+---
+ arch/x86/mm/pat/set_memory.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
+index 1b63d4caba20..7d656520887c 100644
+--- a/arch/x86/mm/pat/set_memory.c
++++ b/arch/x86/mm/pat/set_memory.c
+@@ -769,7 +769,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned 
long address,
+ 
+       *level = PG_LEVEL_512G;
+       *nx |= pgd_flags(*pgd) & _PAGE_NX;
+-      *rw &= pgd_flags(*pgd) & _PAGE_RW;
++      *rw &= !!(pgd_flags(*pgd) & _PAGE_RW);
+ 
+       p4d = p4d_offset(pgd, address);
+       if (p4d_none(*p4d))
+@@ -780,7 +780,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned 
long address,
+ 
+       *level = PG_LEVEL_1G;
+       *nx |= p4d_flags(*p4d) & _PAGE_NX;
+-      *rw &= p4d_flags(*p4d) & _PAGE_RW;
++      *rw &= !!(p4d_flags(*p4d) & _PAGE_RW);
+ 
+       pud = pud_offset(p4d, address);
+       if (pud_none(*pud))
+@@ -791,7 +791,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned 
long address,
+ 
+       *level = PG_LEVEL_2M;
+       *nx |= pud_flags(*pud) & _PAGE_NX;
+-      *rw &= pud_flags(*pud) & _PAGE_RW;
++      *rw &= !!(pud_flags(*pud) & _PAGE_RW);
+ 
+       pmd = pmd_offset(pud, address);
+       if (pmd_none(*pmd))
+@@ -802,7 +802,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned 
long address,
+ 
+       *level = PG_LEVEL_4K;
+       *nx |= pmd_flags(*pmd) & _PAGE_NX;
+-      *rw &= pmd_flags(*pmd) & _PAGE_RW;
++      *rw &= !!(pmd_flags(*pmd) & _PAGE_RW);
+ 
+       return pte_offset_kernel(pmd, address);
+ }
+

++++++ series.conf ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:28.608415766 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:28.616416038 +0200
@@ -3522,6 +3522,8 @@
        
patches.kernel.org/7.1.6-740-cifs-fix-time_last_write-stamp-placement-in-set.patch
        
patches.kernel.org/7.1.6-741-cifs-consolidate-time_last_write-stamp-into-_ci.patch
        patches.kernel.org/7.1.6-742-Linux-7.1.6.patch
+       
patches.kernel.org/7.1.7-001-x86-bugs-Make-Safe-RET-robust-against-interrupt.patch
+       patches.kernel.org/7.1.7-002-Linux-7.1.7.patch
 
        ########################################################
        # Build fixes that apply to the vanilla kernel too.
@@ -3567,6 +3569,19 @@
        patches.suse/selftests-bpf-Tolerate-missing-files-during-install.patch
        
patches.suse/ima-return-error-early-if-file-xattr-cannot-be-changed.patch
        patches.suse/soundwire-dmi-quirks-Disable-ghost-Realtek-devices.patch
+       patches.suse/drm-amd-display-use-proper-context-for-logging.patch
+
+       # tip/tip
+       
patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
+       patches.suse/x86-mm-pat-Take-cpa_lock-around-large-page-collapse.patch
+       patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch
+
+       # out-of-tree patches
+       
patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
+       
patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
+       
patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
+       
patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
+       
patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
 
        ########################################################
        # end of sorted patches

++++++ source-timestamp ++++++
--- /var/tmp/diff_new_pack.754shK/_old  2026-08-09 21:34:28.648417130 +0200
+++ /var/tmp/diff_new_pack.754shK/_new  2026-08-09 21:34:28.648417130 +0200
@@ -1,4 +1,4 @@
-2026-08-03 10:04:30 +0000
-GIT Revision: ae5c1b55de3bd891574adbec8ff5c8802def979e
+2026-08-07 10:29:37 +0000
+GIT Revision: a5cdd684dc2dc7e2c2eb8f78c80c64961c8d4f6b
 GIT Branch: stable
 

Reply via email to