Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kernel-source for openSUSE:Factory checked in at 2026-09-09 16:19:31 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kernel-source (Old) and /work/SRC/openSUSE:Factory/.kernel-source.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kernel-source" Wed Sep 9 16:19:31 2026 rev:858 rq:1376230 version:7.2.4 Changes: -------- --- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes 2026-09-07 11:28:45.346803371 +0200 +++ /work/SRC/openSUSE:Factory/.kernel-source.new.1265/dtb-aarch64.changes 2026-09-09 16:21:41.763388213 +0200 @@ -1,0 +2,1340 @@ +Mon Sep 7 17:57:41 CEST 2026 - [email protected] + +- Linux 7.2.4 (bsc#1012628). +- platform/chrome: sensorhub: Fix dropped timestamp events and + log spam (bsc#1012628). +- ACPI: scan: Do not combine resources that overlap completely + (bsc#1012628). +- selftests/mm: fix on-fault-limit false failure under sudo-rs + (bsc#1012628). +- udf: Fix i_lenExtents truncation on 32-bit kernels + (bsc#1012628). +- timer: Keep debugobjects state consistent in + migrate_timer_list() (bsc#1012628). +- timekeeping: Check the return value of tk_get_aux_ts64 in + __do_adjtimex() (bsc#1012628). +- taskstats: fix cpumask parsing cutting off the last character + (bsc#1012628). +- smack: fix cred UAF in smack_file_send_sigiotask() + (bsc#1012628). +- signal: avoid shared siginfo namespace rewrites (bsc#1012628). +- sticon/parisc: Detect default STI graphics card for console + output (bsc#1012628). +- sysctl: move the "cad_pid" entry from pid_table[] to + kern_reboot_table[] (bsc#1012628). +- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (bsc#1012628). +- zloop: truncate finished zones to zone capacity (bsc#1012628). +- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() + (bsc#1012628). +- w1: ds28e17: reject an oversize length on an I2C block read + (bsc#1012628). +- vsock/virtio: flush works in dependency order (bsc#1012628). +- wifi: mt76: mt7996: validate default EEPROM firmware size + (bsc#1012628). +- wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames + (bsc#1012628). +- wifi: mt76: mt7996: bound the device EEPROM address before + the EFUSE copy (bsc#1012628). +- wifi: mt76: mt7925: cancel mlo_pm_work on stop (bsc#1012628). +- wifi: mt76: mt7915: bound the device EEPROM address before + the EFUSE copy (bsc#1012628). +- wifi: mt76: mt7615: avoid waiting for mac work under the mt76 + mutex (bsc#1012628). +- wifi: rtw89: pci: add .shutdown callback to stop rfkill polling + on reboot (bsc#1012628). +- wifi: rtw88: pci: fix resource leak on failed NAPI setup + (bsc#1012628). +- wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() + (bsc#1012628). +- wifi: rtlwifi: rtl8192du: Fix possible memory leak in + rtl92du_init_sw_vars() (bsc#1012628). +- wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids + (bsc#1012628). +- wifi: rtl818x: initialize eeprom_93cx6 struct to zero + (bsc#1012628). +- wifi: mwifiex: Detach sync cmd buffer on interrupted wait + (bsc#1012628). +- mm/kmemleak: report RCU-tasks quiescent states during the scan + (bsc#1012628). +- mm/kmemleak: stop the task stack scan early when interrupted + (bsc#1012628). +- crypto: atmel-ecc - avoid stale fallback key after set_secret + failure (bsc#1012628). +- crypto: atmel-ecc - clean up and improve ECDH comments + (bsc#1012628). +- crypto: iaa - unmap dst before software fallback on decompress + (bsc#1012628). +- fuse: copy request headers via a stack buffer for io-uring + (bsc#1012628). +- fuse: decouple fuse_ring creation from ent registration + (bsc#1012628). +- wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop + (bsc#1012628). +- wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() + (bsc#1012628). +- wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() + (bsc#1012628). +- i3c: renesas: Perform Dynamic Address Assignment on resume + (bsc#1012628). +- i3c: renesas: Restore STDBR and EXTBR registers on resume + (bsc#1012628). +- i3c: renesas: Reset the controller on resume (bsc#1012628). +- i3c: renesas: Reconfigure the DATBAS register on re-attach + (bsc#1012628). +- i3c: renesas: Follow the reset deassert order used in probe + (bsc#1012628). +- i3c: renesas: Clean DATBAS register on detach (bsc#1012628). +- i3c: renesas: Check that the transfer is valid before accessing + it (bsc#1012628). +- i3c: master: svc: bound IBI payload to the requested + max_payload_len (bsc#1012628). +- i3c: master: Fix info leak and UAF in device unregister path + (bsc#1012628). +- i3c: master: adi: initialize the lock before enabling interrupts + (bsc#1012628). +- i3c: Fix unlocked dereference of dev->desc in + i3c_device_get_supported_xfer_mode() (bsc#1012628). +- dm-pcache: fix use-after-free and invalid seg operations in + kset_replay() (bsc#1012628). +- dm-pcache: fix implicit u8 truncation of gc_percent in message + handler (bsc#1012628). +- dm-pcache: only hand out initialized cache segments + (bsc#1012628). +- dm-pcache: detect a cycle in the last-kset chain during replay + (bsc#1012628). +- dm-pcache: clamp the tail kset read to the segment data region + (bsc#1012628). +- dm-pcache: bound the persisted tail-position offset + (bsc#1012628). +- dm-pcache: validate on-media seg_num against the cache device + size (bsc#1012628). +- dm-pcache: validate kset key_num and intra-segment bounds + (bsc#1012628). +- dm-pcache: validate geometry fields from on-disk cache_info + (bsc#1012628). +- dm-switch: use WRITE_ONCE() in switch_region_table_write() + (bsc#1012628). +- dm-stats: fix a crash if allocation of per-cpu data fails + (bsc#1012628). +- arch_numa: avoid false positive fortify warning in + setup_node_to_cpumask_map() (bsc#1012628). +- rust: num: reject Bounded::shr overshifts at build time + (bsc#1012628). +- ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering + (bsc#1012628). +- ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: + AD3Q9ET#UUG (bsc#1012628). +- ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r + (bsc#1012628). +- ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx + (bsc#1012628). +- ALSA: virmidi: Check card index validity at probe (bsc#1012628). +- ALSA: serial-u16550: Check card index validity at probe + (bsc#1012628). +- ALSA: portman2x4: Check card index validity at probe + (bsc#1012628). +- ALSA: pcxhr: initialize mutexes before requesting threaded IRQ + (bsc#1012628). +- ALSA: mts64: Check card index validity at probe (bsc#1012628). +- ALSA: mpu401: Check card index validity at probe (bsc#1012628). +- ALSA: hda/ext: preserve PPLCCTL bits when clearing reset + (bsc#1012628). +- ALSA: FCP: do not copy out an uninitialised init response + (bsc#1012628). +- ALSA: bcd2000: clear the URB pointers on disconnect + (bsc#1012628). +- ALSA: aloop: Check card index validity at probe (bsc#1012628). +- ALSA: 6fire: bound the MIDI event length from the device + (bsc#1012628). +- mfd: sm501: Fix potential memory leaks during remove + (bsc#1012628). +- mfd: qnap-mcu: keep the reply buffer alive past a command + timeout (bsc#1012628). +- mfd: cgbc: Fix teardown ordering in cgbc_remove() (bsc#1012628). +- hwrng: stm32 - Fix runtime PM cleanup on registration failure + (bsc#1012628). +- seg6: reset IP6CB after IPv6 decapsulation (bsc#1012628). +- net: skbuff: don't touch shared zerocopy state in skb_tx_error() + (bsc#1012628). +- net: fix spurious TX timeout after dev_activate() (bsc#1012628). +- net: cap advertised IP tunnel headroom (bsc#1012628). +- net/smc: unregister the connection before draining the rx + tasklet (bsc#1012628). +- net/smc: stop killed, freed and out_of_sync sharing a byte + (bsc#1012628). +- net/smc: fix use-after-free of the LLC qentry in + smc_llc_srv_add_link() (bsc#1012628). +- net/smc: fix use-after-free in smc_rx_pipe_buf_release() + (bsc#1012628). +- net/smc: fix socket refcount leak in smc_switch_conns() + (bsc#1012628). +- net/smc: do not dereference an unset send buffer on the SMC-D + teardown path (bsc#1012628). +- net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry + (bsc#1012628). +- net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages + (bsc#1012628). +- net/mlx5e: do not HW-GRO coalesce small frames (bsc#1012628). +- net: ntb_netdev: Count packets dropped on RX refill failure + (bsc#1012628). +- net: ntb_netdev: Avoid double-accounting netif_rx() drops + (bsc#1012628). +- net: ntb_netdev: Fix TX busy and drop handling (bsc#1012628). +- NTB: ntb_transport: Reject oversized TX buffers (bsc#1012628). +- NTB: ntb_transport: Fail TX enqueue when the QP link is down + (bsc#1012628). +- NTB: ntb_transport: Recycle TX entries before client callbacks + (bsc#1012628). +- net: thunderbolt: Mark the connection down when bringing it + up fails (bsc#1012628). +- net: thunderbolt: Release the Rx HopID that was handed out on + mismatch (bsc#1012628). +- net: ravb: serialize PTP clock teardown (bsc#1012628). +- net: ravb: avoid dereferencing an invalid PTP clock + (bsc#1012628). +- net: phylink: correctly validate returned PCS in + phylink_inband_caps (bsc#1012628). +- net: openvswitch: fix nf_connlabels leak in ovs_ct_init + (bsc#1012628). +- net: openvswitch: fix flow mask use-after-free on flow deletion + (bsc#1012628). +- net: mctp: hold a reference to the route device in + mctp_route_lookup() (bsc#1012628). +- net: l2tp: do not propagate multicast notification errors + (bsc#1012628). +- net: ipa: fix stalled modem TX queue after runtime resume + (bsc#1012628). +- net: ibm: emac: mal: fix NAPI locking (bsc#1012628). +- net: bnxt: ring the doorbell when SW USO exits early + (bsc#1012628). +- net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO + (bsc#1012628). +- net: tun: bound receive headroom (bsc#1012628). +- net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition + (bsc#1012628). +- slip: fix use-after-free in sl_sync() (bsc#1012628). +- xdp: fix zero-copy frame layout (bsc#1012628). +- net/iucv: filter frames in afiucv_hs_rcv() by ingress device + (bsc#1012628). +- ipmi:msghandler: Cancel work cleanly on an error (bsc#1012628). +- ipmi: si: Fix NULL pointer dereference after failed registration + (bsc#1012628). +- ipmi: Remove all sysfs files on registration failure + (bsc#1012628). +- ipmi: ipmb: validate write message length (bsc#1012628). +- interconnect: Fix use after free in icc_get() and + of_icc_get_by_index() (bsc#1012628). +- io_uring/query: cap user size passed to copy_struct_to_user + (bsc#1012628). +- io_uring/waitid: avoid siginfo copy during ring teardown + (bsc#1012628). +- io_uring/waitid: honor task_work cancellation (bsc#1012628). +- platform/x86: hp-bioscfg: warn on element type mismatch instead + of failing (bsc#1012628). +- platform/x86: hp-bioscfg: pass validated element count to + package parsers (bsc#1012628). +- platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being + parsed (bsc#1012628). +- platform/x86: hp-bioscfg: fix off-by-one write in + hp_get_string_from_buffer() (bsc#1012628). +- platform/x86: hp-bioscfg: fix new_password_store() overwriting + current_password (bsc#1012628). +- platform/x86: hp-bioscfg: fix heap OOB read on empty password + write (bsc#1012628). +- platform/x86: hp-bioscfg: fix heap OOB read in sk_store() + and kek_store() (bsc#1012628). +- platform/x86: hp-bioscfg: bound ordered-list parsing by the + package count (bsc#1012628). +- platform/x86: hp-bioscfg: advance elem past consumed array + elements (bsc#1012628). +- platform/x86: hp-bioscfg: accept reduced ACPI packages from + older HP BIOS (bsc#1012628). +- platform/x86/amd/pmc: Fix msg_port restoration in + amd_stb_debugfs_open_v2() (bsc#1012628). +- platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init + fails (bsc#1012628). +- platform/x86/amd/pmc: Propagate SMU errors and validate S2D + address (bsc#1012628). +- platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() + error paths (bsc#1012628). +- platform/chrome: sensorhub: Bound the EC-reported sensor number + (bsc#1012628). +- platform/x86: think-lmi: Fix current password length check + (bsc#1012628). +- platform/x86: think-lmi: Free system certificate signatures + (bsc#1012628). +- platform/x86: think-lmi: Fix certificate thumbprint sysfs output + (bsc#1012628). +- platform/x86: panasonic-laptop: Fix sentinel write past + pcc->sinf[] (bsc#1012628). +- platform/x86: lenovo/ymc: Only match lower byte in WMI lid + switch query response (bsc#1012628). +- platform/x86: ishtp_eclite: Fix ACPI device reference leak in + probe error path (bsc#1012628). +- platform/x86: int1092: Fix potential memory leak in sar_probe() + (bsc#1012628). +- platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6) + (bsc#1012628). +- platform/x86: ISST: Return error during profile addition + (bsc#1012628). +- platform/x86: ISST: Validate parameter for frequency and + priority (bsc#1012628). +- platform/x86: ISST: Validate parameter for core power state + (bsc#1012628). +- platform/x86: ISST: Validate max level for set feature + (bsc#1012628). +- platform/x86: ISST: Validate logical CPU id and clos id + (bsc#1012628). +- platform/x86: ISST: Use PP level enable mask (bsc#1012628). +- platform/x86: ISST: Just allow 2 bits for SST feature enable + (bsc#1012628). +- platform/x86: ISST: Add a NULL check for sst_inst[] + (bsc#1012628). +- mmc: via-sdmmc: stop card-detect handling on probe failure + (bsc#1012628). +- mmc: via-sdmmc: cancel card-detect work on remove (bsc#1012628). +- platform/x86: ISST: Validate socket ID in clos_assoc ioctl + (bsc#1012628). ++++ 1055 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes ++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.1265/dtb-aarch64.changes dtb-armv6l.changes: same change dtb-armv7l.changes: same change dtb-riscv64.changes: same change kernel-64kb.changes: same change kernel-default.changes: same change kernel-docs.changes: same change kernel-kvmsmall.changes: same change kernel-lpae.changes: same change kernel-obs-build.changes: same change kernel-obs-qa.changes: same change kernel-pae.changes: same change kernel-source.changes: same change kernel-syms.changes: same change kernel-vanilla.changes: same change kernel-zfcpdump.changes: same change ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dtb-aarch64.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.183697416 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.185697499 +0200 @@ -17,7 +17,7 @@ %define srcversion 7.2 -%define patchversion 7.2.3 +%define patchversion 7.2.4 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -25,9 +25,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: dtb-aarch64 -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif dtb-armv6l.spec: same change dtb-armv7l.spec: same change dtb-riscv64.spec: same change ++++++ kernel-64kb.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.372705292 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.374705375 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-64kb -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif kernel-default.spec: same change ++++++ kernel-docs.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.459708917 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.462709042 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define build_html 1 %define build_pdf 0 @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-docs -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif ++++++ kernel-kvmsmall.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.519711417 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.521711501 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-kvmsmall -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif kernel-lpae.spec: same change ++++++ kernel-obs-build.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.617715501 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.620715626 +0200 @@ -19,7 +19,7 @@ #!BuildIgnore: post-build-checks -%define patchversion 7.2.3 +%define patchversion 7.2.4 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -38,23 +38,23 @@ %endif %endif %endif -%global kernel_package kernel%kernel_flavor-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%global kernel_package kernel%kernel_flavor-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %endif %if 0%{?rhel_version} %global kernel_package kernel %endif Name: kernel-obs-build -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif Summary: package kernel and initrd for OBS VM builds License: GPL-2.0-only Group: SLES -Provides: kernel-obs-build-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +Provides: kernel-obs-build-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 BuildRequires: coreutils BuildRequires: device-mapper BuildRequires: dracut ++++++ kernel-obs-qa.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.668717627 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.671717752 +0200 @@ -17,15 +17,15 @@ # needsrootforbuild -%define patchversion 7.2.3 +%define patchversion 7.2.4 %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-obs-qa -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif @@ -36,7 +36,7 @@ # kernel-obs-build must be also configured as VMinstall, but is required # here as well to avoid that qa and build package build parallel %if ! 0%{?qemu_user_space_build} -BuildRequires: kernel-obs-build-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +BuildRequires: kernel-obs-build-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %endif BuildRequires: modutils ExclusiveArch: aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64 ++++++ kernel-pae.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.728720127 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.731720252 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-pae -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif ++++++ kernel-source.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.777722169 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.779722252 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define gcc_package gcc %define gcc_compiler gcc @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-source -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif ++++++ kernel-syms.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.829724336 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.831724419 +0200 @@ -16,15 +16,15 @@ # -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-syms -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif ++++++ kernel-vanilla.spec ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:49.877726336 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:49.880726461 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.3 -%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +%define patchversion 7.2.4 +%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-vanilla -Version: 7.2.3 +Version: 7.2.4 %if 0%{?is_kotd} -Release: <RELEASE>.g263d925 +Release: <RELEASE>.geac7913 %else Release: 0 %endif kernel-zfcpdump.spec: same change ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:50.110736045 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:50.115736254 +0200 @@ -1,6 +1,6 @@ -mtime: 1788414228 -commit: bc47402a8f0b7bfd77fb34a9f7380eb1b2387e15ae66e4747ffe59c246070c92 +mtime: 1788797792 +commit: a3ee9771a981d07615b129ad162aba3ab497c888f67adb7a0bc441af930deeb1 url: https://src.opensuse.org/jirislaby/kernel-source -revision: bc47402a8f0b7bfd77fb34a9f7380eb1b2387e15ae66e4747ffe59c246070c92 +revision: a3ee9771a981d07615b129ad162aba3ab497c888f67adb7a0bc441af930deeb1 trackingbranch: Kernel/stable ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-07 18:16:32.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ patches.kernel.org.tar.bz2 ++++++ ++++ 65875 lines of diff (skipped) ++++++ patches.suse.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch --- old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch 2026-09-04 09:27:27.000000000 +0200 @@ -0,0 +1,114 @@ +From 5f171116a59871a7690adb6b8621de0c226738ad Mon Sep 17 00:00:00 2001 +From: "Ritesh Harjani (IBM)" <[email protected]> +Date: Sun, 30 Aug 2026 20:24:30 +0530 +Subject: [PATCH 4/4] powerpc: Do not restore KUAP in + arch_exit_to_user_mode_prepare() + +References: bsc#1277802 ltc#222379 +Patch-mainline: Submitted https://lore.kernel.org/all/52fee44fd23acf8e1c024ace668728e626a783a8.1788101609.git.ritesh.l...@gmail.com/ + +KUAP means kernel cannot touch user memory unless it explicitly is +enabled. In the kernel it should stay AMR_KUAP_BLOCKED. While returning +to userspace just before RFI, kernel should restore the user AMR value +back. + +Looks like GENERIC_ENTRY might be treating arch_exit_to_user_mode_prepare() +as the last architecture step before returning to userspace. +commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") +therefore called kuap_user_restore() from that hook. But on PowerPC that +is too early. After irqentry_exit() / syscall_exit_to_user_mode() we +still run platform specific exit routines. + +e.g. code snippets showing both exception handling and system call +handling as the callers of function arch_exit_to_user_mode_prepare() +which does kuap_user_restore(). The below path shows that calling +kuap_user_restore() is too early when called from +arch_exit_to_user_mode_prepare(). + +Exception handling in exceptions-64s.S +======================================= + +bl CFUNC(do_page_fault) + ..DEFINE_INTERRUPT_HANDLER_ASYNC(do_page_fault) + arch_interrupt_async_enter_prepare(regs); + state = irqentry_enter(regs); + instrumentation_begin(); + irq_enter_rcu(); + handler(regs); + nap_adjust_return(regs); + irq_exit_rcu(); + instrumentation_end(); + arch_interrupt_async_exit_prepare(regs); + irqentry_exit(regs, state); <<< too early + irqentry_exit_to_user_mode() + __exit_to_user_mode_prepare(regs, EXIT_TO_USER_MODE_WORK_IRQ); + arch_exit_to_user_mode_prepare(regs, ti_work); <<< too early +b interrupt_return_srr + .. bl CFUNC(interrupt_exit_user_prepare) <<< already calls kuap_user_restore + +prep_irq_for_enabled_exit() retry can run kernel code with IRQs on. So +only when that routine is fully finished is when the user KUAP should be +fully restored which interrupt_exit_user_prepare() already takes care of +before returning. + +Similarly for system call handling in interrupt_64.S +====================================================== + + bl CFUNC(system_call_exception) + +.Lsyscall_exit: + addi r4,r1,STACK_INT_FRAME_REGS + li r5,0 /* !scv */ + bl CFUNC(syscall_exit_prepare) + .. kuap_assert_locked(); + syscall_exit_to_user_mode(regs); <<< too early + syscall_exit_to_user_mode_prepare(regs); <<< too early + kuap_user_restore(regs); <<< already calls + +syscall_exit_prepare(), which can enable IRQs, replay a pending +interrupt, and only then rfi. Those functions already restore KUAP +immediately before rfi. + +Note that if we restore the user AMR too early like in the current code +as shown from the code snippets above, then we get the following warning +when CONFIG_PPC_KUAP_DEBUG is enabled: + WARNING: arch/powerpc/include/asm/book3s/64/kup.h:293 at interrupt_exit_user_prepare+0x1a0/0x1c0 + Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) + TRAP: 0700 + LR: c00000000000d8d4 CTR: c0000000021fe500 + MSR: <SF,EE,ME,IR,DR,RI,LE> CR: 44000804 XER: 20040000 + interrupt_exit_user_prepare+0x1a0/0x1c0 + interrupt_return_srr_user+0x8/0x12c + +Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") +Fixes: 02565a782c1ee ("powerpc: Introduce syscall exit arch functions") +Signed-off-by: Ritesh Harjani (IBM) <[email protected]> +Acked-by: Michal Suchanek <[email protected]> +--- + arch/powerpc/include/asm/entry-common.h | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/arch/powerpc/include/asm/entry-common.h b/arch/powerpc/include/asm/entry-common.h +index 2a153dca962c7..839ab69c72d35 100644 +--- a/arch/powerpc/include/asm/entry-common.h ++++ b/arch/powerpc/include/asm/entry-common.h +@@ -515,8 +515,14 @@ static inline void arch_exit_to_user_mode_prepare(struct pt_regs *regs, + #ifdef CONFIG_PPC_TRANSACTIONAL_MEM + local_paca->tm_scratch = regs->msr; + #endif +- /* Restore user access locks last */ +- kuap_user_restore(regs); ++ /* ++ * Do not restore KUAP here. Generic entry might treat this as the last ++ * arch step before userspace but PowerPC still has kernel work after ++ * irqentry_exit()/syscall_exit_to_user_mode() i.e. in ++ * interrupt_exit_user_prepare() / syscall_exit_prepare() may enable ++ * IRQs and retry. Those functions restore KUAP immediately before rfi, ++ * which is where it should belong. ++ */ + } + + #define arch_exit_to_user_mode_prepare arch_exit_to_user_mode_prepare +-- +2.51.0 + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch --- old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 2026-09-04 09:27:27.000000000 +0200 @@ -0,0 +1,94 @@ +From 8b51f35e51cd17626f1fbf6022824186e33e208f Mon Sep 17 00:00:00 2001 +From: "Ritesh Harjani (IBM)" <[email protected]> +Date: Sat, 29 Aug 2026 09:49:00 +0530 +Subject: [PATCH 1/4] powerpc: Don't drop _TIF_RESTOREALL on syscall restart + +References: bsc#1277802 ltc#222379 +Patch-mainline: Submitted https://lore.kernel.org/all/10c86c909f870d90b3094f76b692b44ebe9caeac.1787976185.git.ritesh.l...@gmail.com/ + +So the syscall return sequence is as follows: +A syscall return to userspace is prepared and then a short asm sequence +that actually does the RFI. Note that this asm range is restartable i.e. +EE is still on, so an interrupt (e.g. decrementer or external interrupt) +can hit while SRR/GPRs are being loaded. This is defined via: + +RESTART_TABLE(.Lsyscall_rst_start, .Lsyscall_rst_end, syscall_restart) + +This restart table then sends us to syscall_restart rather than resuming +in the middle of the RFI. The same stub is also used if irq_happened +already has a pending bit (soft-masked irq that has not been replayed +yet (PowerPC special case of local_irq_disable())). + +Here is a bit of a flow of sequence of code to visualize: + syscall_exit_prepare + decide full-GPR restore (_TIF_RESTOREALL) for signal, + rt_sigreturn or syscall trace + save that in regs->exit_result and return it in r3 + | + v + .Lsyscall_rst_start .. _end EE still on + irq_happened set or interrupt in this range? + | no | yes + v v + cmpdi r3,0 syscall_exit_restart + restore all / zero replay irq, try exit again + volatiles; RFI must return flags in r3 + again for the same cmpdi + +Now r3 after prepare is the flags word, not the actual syscall return. A nested +interrupt clobbers it, so the restart stub reloads RESULT into r3 and the +C handler (syscall_exit_restart()) should put the flags back (because later asm +checks whether r3 returned from C has _TIF_RESTOREALL set or not): + cmpdi r3, 0 + bne .Lsyscall_restore_regs + +Note that syscall_exit_restart() already ORs any new _TIF_RESTOREALL into +exit_result, but then it only returns the new sample and not the full +regs->exit_result. + +That sample could be often 0 even when restore-all is still required: + + - rt_sigreturn / syscall trace set the bit in prepare's local + ret and in exit_result. They never set exit_flags, which is + what restart samples. + + - a signal does set exit_flags but restart clears it. A + second pass through the stub then returns 0 while + exit_result still has the bit. + +The asm as mentioned earlier then treats r3==0 as the fast path and +zeros r0/r4-r12. That means the userspace that needed the full register +set could SIGSEGVs, (which could happen often in ld64.so.2 like while +doing a parallel kernel build as reported by Venkat). + +So we should instead return the accumulated exit_result, like how we do +in interrupt_exit_user_restart(). Note that prior to this commit +263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace") +we were returning regs->exit_result from syscall_exit_restart(), but +this commit changed that behaviour. + +Fixes: 263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace") +Reported-by: Venkat Rao Bagalkote <[email protected]> +Closes: https://lore.kernel.org/all/[email protected]/ +Signed-off-by: Ritesh Harjani (IBM) <[email protected]> +Acked-by: Michal Suchanek <[email protected]> +--- + arch/powerpc/kernel/interrupt.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/powerpc/kernel/interrupt.c b/arch/powerpc/kernel/interrupt.c +index 5b88bf72786c7..55f9c0c9922ac 100644 +--- a/arch/powerpc/kernel/interrupt.c ++++ b/arch/powerpc/kernel/interrupt.c +@@ -175,7 +175,7 @@ notrace unsigned long syscall_exit_restart(unsigned long r3, struct pt_regs *reg + current_thread_info()->exit_flags &= ~_TIF_RESTOREALL; + regs->exit_result |= ret; + +- return ret; ++ return regs->exit_result; + } + #endif + +-- +2.51.0 + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch --- old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch 2026-09-04 09:27:27.000000000 +0200 @@ -0,0 +1,97 @@ +From d6770f7fe9e114e02629d4f0666b9f2053d538b7 Mon Sep 17 00:00:00 2001 +From: Aboorva Devarajan <[email protected]> +Date: Fri, 4 Sep 2026 08:28:30 +0530 +Subject: [PATCH 5/5] powerpc/entry: Fix double accounting of user time on + interrupt entry + +References: bsc#1277802 ltc#222379 +Patch-mainline: Submitted https://lore.kernel.org/all/[email protected]/ + +Since the switch to generic entry, an interrupt from user mode +accounts user time twice: once in arch_interrupt_enter_prepare() +and again in arch_enter_from_user_mode(), which irqentry_enter() +invokes for the same interrupt: + + arch_interrupt_enter_prepare() + account_cpu_user_entry() /* first */ + irqentry_enter() + arch_enter_from_user_mode() + account_cpu_user_entry() /* second */ + +The second call charges the same interval again, because +account_cpu_user_entry() accumulates the time spent in user mode +since the last return to user space. + +The two calls come from the GENERIC_ENTRY preparation series, +where each step was a no-op on its own. Commit 09a9d3a8499d +("powerpc: introduce arch_enter_from_user_mode") added the hook +with the user-time accounting in it, but nothing called it yet. +Commit 893082ac769b ("powerpc: Prepare for IRQ entry exit") +copied interrupt_enter_prepare() verbatim into entry-common.h as +arch_interrupt_enter_prepare(); that copy was equally unused, as +handlers still called interrupt_enter_prepare(). + +Commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") +made both live. On the syscall side it did the full conversion: +system_call_exception() now accounts once through the hook via +syscall_enter_from_user_mode(), rather than calling +account_cpu_user_entry() directly. On the interrupt side it +switched the handler macros to arch_interrupt_enter_prepare() +followed by irqentry_enter(), which also runs the hook, but the +accounting in arch_interrupt_enter_prepare() was not removed to +match. The double accounting starts with that commit. + +With CONFIG_VIRT_CPU_ACCOUNTING_NATIVE=y this roughly doubles the +reported user time of any workload that takes interrupts. The +other accounting modes compile account_cpu_user_entry() to an +empty stub, so they are not affected. + +Remove the accounting from arch_interrupt_enter_prepare() and rely +on arch_enter_from_user_mode(), which already runs for both +syscalls and interrupts. The duplicate account_stolen_time() call +is removed the same way. + +On a pseries LPAR a busy loop reports 6s user time in 3s elapsed +(~210% CPU) before the fix, and 3s (~105% CPU) after it: + + $ python3 -c 'while True: pass' & + $ sleep 3; ps -p $! -o etime,time,pcpu + + ELAPSED TIME %CPU + Before 00:03 00:00:06 210 + After 00:03 00:00:03 105 + +A 50% load reports ~70% usr / 30% idle before the fix, and +~49% usr / 51% idle after it: + + $ taskset -c 6 stress-ng --cpu 1 --cpu-load 50 & + $ mpstat -P 6 1 + + CPU %usr %idle + Before 6 69.74 30.26 + After 6 48.51 50.50 + +Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") +Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> +Signed-off-by: Aboorva Devarajan <[email protected]> +Acked-by: Michal Suchanek <[email protected]> +--- + arch/powerpc/include/asm/entry-common.h | 2 -- + 1 file changed, 2 deletions(-) + +diff --git a/arch/powerpc/include/asm/entry-common.h b/arch/powerpc/include/asm/entry-common.h +index 839ab69c72d35..b899978e1a47c 100644 +--- a/arch/powerpc/include/asm/entry-common.h ++++ b/arch/powerpc/include/asm/entry-common.h +@@ -222,8 +222,6 @@ static inline void arch_interrupt_enter_prepare(struct pt_regs *regs) + + if (user_mode(regs)) { + kuap_lock(); +- account_cpu_user_entry(); +- account_stolen_time(); + } else { + kuap_save_and_lock(regs); + /* +-- +2.51.0 + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch --- old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch 2026-09-04 09:27:27.000000000 +0200 @@ -0,0 +1,105 @@ +From 817ffd5c832368950e4b498a200a7789b0601571 Mon Sep 17 00:00:00 2001 +From: "Mukesh Kumar Chaurasiya (IBM)" <[email protected]> +Date: Thu, 20 Aug 2026 19:17:18 +0530 +Subject: [PATCH 3/4] powerpc/entry: Fix irq_soft_mask corruption on replayed + interrupt exit +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +References: bsc#1277802 ltc#222379 +Patch-mainline: Submitted https://lore.kernel.org/all/[email protected]/ + +When __replay_soft_interrupts() replays a pending interrupt (e.g. +PACA_IRQ_DEC → timer_interrupt), it calls the handler directly with a +synthetic pt_regs. The DEFINE_INTERRUPT_HANDLER_ASYNC wrapper around +each handler calls arch_interrupt_async_exit_prepare() on the way out, +which calls arch_interrupt_exit_prepare() → local_irq_disable() → +arch_local_irq_disable(), which does: + + irq_soft_mask_set(IRQS_DISABLED) /* 0x1 */ + +This unconditionally overwrites irq_soft_mask with IRQS_DISABLED (0x1), +stripping the IRQS_PMI_DISABLED (0x2) bit. The result is that +irq_soft_mask is 0x1 instead of IRQS_ALL_DISABLED (0x3) when the +handler returns to __replay_soft_interrupts(). + +For a normally-taken interrupt this is harmless: the next interrupt +always enters through arch_interrupt_enter_prepare() which +unconditionally sets irq_soft_mask to IRQS_ALL_DISABLED. +But during replay, next_interrupt() is called +directly between replayed handlers without going back through +arch_interrupt_enter_prepare(), so the stripped bit is never restored. +next_interrupt() then fires a WARNING: + + WARNING: arch/powerpc/kernel/irq_64.c:75 + WARN_ON(irq_soft_mask_return() != IRQS_ALL_DISABLED) + +This was introduced by commit bee25f97ad24 ("powerpc: Enable +GENERIC_ENTRY feature"). Before that commit, the old +interrupt_async_exit_prepare() called irq_exit() followed by an empty +interrupt_exit_prepare() stub and never touched irq_soft_mask at all, +so the soft mask was left at IRQS_ALL_DISABLED throughout replay. + +The root cause: arch_interrupt_exit_prepare() uses local_irq_disable() +whose only job is to set the IRQS_DISABLED bit; it has no knowledge of +IRQS_PMI_DISABLED. It is there to satisfy irqentry_exit()'s +requirement that interrupts be disabled, but using the plain +irq_soft_mask_set(IRQS_ALL_DISABLED) is the right primitive: + + - irq_soft_mask_set(IRQS_ALL_DISABLED): sets soft mask to 0x3 + (both IRQS_DISABLED and IRQS_PMI_DISABLED). Touches only the soft + mask. MSR[EE] and PACA_IRQ_HARD_DIS are already correct because + hard interrupts were never re-enabled during replay + (PACA_IRQ_REPLAYING is in PACA_IRQ_MUST_HARD_MASK, which blocks + should_hard_irq_enable()). + + - local_irq_disable() / arch_local_irq_disable(): sets soft mask to + IRQS_DISABLED (0x1) only, silently dropping IRQS_PMI_DISABLED. + + - hard_irq_disable(): also issues __mtmsrd to clear MSR[EE] in + hardware and sets PACA_IRQ_HARD_DIS — redundant and wrong here + since both are already set. + +Fix by replacing local_irq_disable() with irq_soft_mask_set(IRQS_ALL_DISABLED) +in arch_interrupt_exit_prepare(), making the exit symmetric with the +entry path in arch_interrupt_enter_prepare() which always sets +IRQS_ALL_DISABLED. + +The warning was observed early in boot on a POWER10 pseries guest +during kmem_cache_init_late(), where a spinlock release triggers +interrupt replay that processes a pending timer interrupt. + +Debugger state confirming the bug: + Before timer_interrupt(®s): + irq_soft_mask = 0x3 (IRQS_ALL_DISABLED) correct + irq_happened = 0x41 (HARD_DIS|REPLAYING) correct + After timer_interrupt(®s) returns: + irq_soft_mask = 0x1 (IRQS_DISABLED) WRONG — PMI bit stripped + irq_happened = 0x41 unchanged + +Fixes: 334f3f6d7a16 ("powerpc/entry: Disable interrupts before irqentry_exit") +Reported-by: Venkat Rao Bagalkote <[email protected]> +Closes: https://lore.kernel.org/all/[email protected]/ +Signed-off-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> +Acked-by: Michal Suchanek <[email protected]> +--- + arch/powerpc/include/asm/entry-common.h | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/powerpc/include/asm/entry-common.h b/arch/powerpc/include/asm/entry-common.h +index c5adb50063610..2a153dca962c7 100644 +--- a/arch/powerpc/include/asm/entry-common.h ++++ b/arch/powerpc/include/asm/entry-common.h +@@ -270,7 +270,7 @@ static inline void arch_interrupt_exit_prepare(struct pt_regs *regs) + } + + /* irqentry_exit expects to be called with interrupts disabled */ +- local_irq_disable(); ++ irq_soft_mask_set(IRQS_ALL_DISABLED); + } + + static inline void arch_interrupt_async_enter_prepare(struct pt_regs *regs) +-- +2.51.0 + diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch --- old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 2026-08-28 10:54:09.000000000 +0200 +++ new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 2026-09-04 09:27:27.000000000 +0200 @@ -1,12 +1,12 @@ From: Pedro Falcato <[email protected]> -Date: Wed, 12 Aug 2026 18:02:54 +0300 -Subject: x86/alternative: exclude text poking against change_page_attr() +Date: Thu, 13 Aug 2026 12:01:26 +0300 +Subject: x86/alternative: Exclude text poking against change_page_attr() References: bsc#1271202 -Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git -Git-commit: 23fa304705d959c48d98fe63f950de65fc2dc917 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: e679ba0983757e9567aeda97cc35c99241d420ee Patch-mainline: Queued in subsystem maintainer repository -From time to time, the following BUG can be observed[0]: +>From time to time, the following BUG can be observed[0]: > kernel BUG at arch/x86/kernel/alternative.c:2576! > Oops: invalid opcode: 0000 [#1] SMP NOPTI @@ -46,16 +46,26 @@ Fix it by excluding against CPA using the init_mm mmap read lock. +[ dhansen: Fix up SoB ordering. The actual code flow here was: + Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain + now. I *believe* Mike simply picked up Lorenzo's update to + Pedro's post from the Link: ] + Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") Reported-by: Jiri Slaby <[email protected]> -Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] Reported-by: Steffen Dirkwinkel <[email protected]> -Link: https://lore.kernel.org/linux-mm/[email protected]/ -Cc: [email protected] -Co-developed-by: "Lorenzo Stoakes (ARM)" <[email protected]> -Signed-off-by: "Lorenzo Stoakes (ARM)" <[email protected]> Signed-off-by: Pedro Falcato <[email protected]> +Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> +Co-developed-by: Lorenzo Stoakes (ARM) <[email protected]> Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> +Tested-by: Jiri Slaby <[email protected]> +Tested-by: Atish Patra <[email protected]> +Tested-by: Nikunj A Dadhania <[email protected]> +Cc:[email protected] +Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] +Link: https://lore.kernel.org/linux-mm/[email protected]/ +Link: https://patch.msgid.link/[email protected] Signed-off-by: Pedro Falcato <[email protected]> --- arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++++++++++++++--- diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 2026-08-28 10:54:09.000000000 +0200 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 2026-09-04 09:27:27.000000000 +0200 @@ -1,15 +1,15 @@ From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Thu, 23 Jul 2026 16:16:33 +0100 -Subject: x86/mm/pat: acquire init_mm read lock on attribute change to avoid +Date: Thu, 13 Aug 2026 12:01:25 +0300 +Subject: x86/mm/pat: Acquire init_mm read lock on attribute change to avoid UAF References: bsc#1271202 -Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git -Git-commit: bbe7d7397af14436bf3b4f3c0d2d13c84e246c2f +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 884801a901bd340c44a202e2ef5c29b48e3a4d93 Patch-mainline: Queued in subsystem maintainer repository -A previous commit protected us against races between ptdump and CPA -collapse, however one still exists between attribute changes and collapse -as reported by Denis V. Lunev (linked). +A previous commit protected against races between ptdump and CPA collapse, +however one still exists between attribute changes and collapse as reported +by Denis V. Lunev (linked). When an attribute change arises, a lockless page table walker obtains a PTE entry, which is later written to via set_pte_atomic(): @@ -26,8 +26,8 @@ There is nothing preventing a concurrent CPA collapse which can free the PTE that was retrieved here, resulting in a use-after-free. -With the mmap write lock taken on init_mm over CPA collapse, we can now -resolve this race by acquiring an mmap read lock on init_mm over +With the mmap write lock taken on init_mm over CPA collapse, resolve this +race by acquiring an mmap read lock on init_mm over __change_page_attr_set_clr(). This locks across the whole operation over which the walk and the PTE entry @@ -81,11 +81,17 @@ This work is based upon Denis V. Lunev's excellent analysis of the bug with gratitude. -Link: https://lore.kernel.org/all/[email protected]/ +[ dhansen: move to imperative voice in changelog ] + Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") -Cc: [email protected] Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> +Tested-by: Atish Patra <[email protected]> +Tested-by: Nikunj A Dadhania <[email protected]> +Link: https://lore.kernel.org/all/[email protected]/ +Cc:[email protected] +Link: https://patch.msgid.link/[email protected] Signed-off-by: Pedro Falcato <[email protected]> --- arch/x86/mm/pat/set_memory.c | 13 +++++++++++-- diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 2026-08-28 10:54:09.000000000 +0200 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 2026-09-04 09:27:27.000000000 +0200 @@ -1,9 +1,9 @@ From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Thu, 23 Jul 2026 16:16:32 +0100 -Subject: x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF +Date: Thu, 13 Aug 2026 12:01:24 +0300 +Subject: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF References: bsc#1271202 -Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git -Git-commit: c949657f06599c5ed33d7626e4c280549c5f4128 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 4cfad2657c7c87b1172a9c343b74cf59b3769873 Patch-mainline: Queued in subsystem maintainer repository x86 implements page attribute modification using its Change Page @@ -47,16 +47,21 @@ mutex, disallowing atomic context here. Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") -Cc: [email protected] +Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> Reviewed-by: Mike Rapoport (Microsoft) <[email protected]> Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]> Reviewed-by: David Hildenbrand (Arm) <[email protected]> Reviewed-by: Dave Hansen <[email protected]> Reviewed-by: Will Deacon <[email protected]> Reviewed-by: David Carlier <[email protected]> -Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Tested-by: Atish Patra <[email protected]> +Tested-by: Nikunj A Dadhania <[email protected]> +Cc:[email protected] +Link: https://patch.msgid.link/[email protected] Signed-off-by: Pedro Falcato <[email protected]> + --- arch/x86/mm/pat/set_memory.c | 15 ++++++++++++++- include/linux/mmap_lock.h | 2 ++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch --- old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 2026-08-28 10:54:09.000000000 +0200 +++ new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 2026-09-04 09:27:27.000000000 +0200 @@ -1,14 +1,14 @@ From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Tue, 21 Jul 2026 13:14:52 +0100 -Subject: x86/mm/pat: allocate split page tables as kernel page tables +Date: Thu, 13 Aug 2026 12:01:27 +0300 +Subject: x86/mm/pat: Allocate split page tables as kernel page tables References: bsc#1271202 -Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git -Git-commit: aae434cbad05053b33809a9174490966337ccb12 +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 0e33126d5def407397deaf617559a1a2a7f4b1ae Patch-mainline: Queued in subsystem maintainer repository -When splitting a large page in CPA in __split_large_page() we allocate a -PTE directly without going through the standard page table allocation -routines such as pte_alloc_one_kernel(). +A PTE is allocated directly without going through the standard page table +allocation routines (such as pte_alloc_one_kernel()) when the CPA code +splits a large page (__split_large_page()). This means the page table constructor is never called nor is the page table marked as a kernel page table. @@ -35,10 +35,10 @@ This results in these kernel page tables invoking a page table constructor, and thus requires a page table destructor. -Since we cannot assume one is always present (early allocated direct map -page tables are not marked as such), we conditionally call -pagetable_dtor_free() if the PG_table folio flag for the ptdesc is set, -otherwise we free the page table via pagetable_free(). +Destructors are not always present, like for early allocated direct map +page tables). Conditionally call pagetable_dtor_free() if the PG_table +folio flag for the ptdesc is set, otherwise we free the page table via +pagetable_free(). Regardless of which path is taken page tables marked as kernel page tables, which now includes split page tables, take the correct route through @@ -52,11 +52,17 @@ 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so choose this as the Fixes target. +[ dhansen: rephrase in imperative mood ] + Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") -Cc: [email protected] Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Acked-by: Vishal Moola <[email protected]> Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> +Acked-by: Vishal Moola <[email protected]> +Tested-by: Atish Patra <[email protected]> +Tested-by: Nikunj A Dadhania <[email protected]> +Cc:[email protected] +Link: https://patch.msgid.link/[email protected] Signed-off-by: Pedro Falcato <[email protected]> --- arch/x86/mm/pat/set_memory.c | 25 ++++++++++++++++--------- diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch --- old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch 2026-08-28 10:54:09.000000000 +0200 +++ new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch 2026-09-04 09:27:27.000000000 +0200 @@ -1,10 +1,10 @@ From: "Mike Rapoport (Microsoft)" <[email protected]> -Date: Fri, 17 Jul 2026 12:41:43 +0300 -Subject: x86/mm/pat: fix effective RW computation in +Date: Thu, 13 Aug 2026 12:01:28 +0300 +Subject: x86/mm/pat: Fix effective RW computation in lookup_address_in_pgd_attr() References: bsc#1271202 -Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git -Git-commit: e7598bc2bb43dfcc51711da0507027c86973ec3e +Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git +Git-commit: 453e7859443446b837d905d6f2983a76c867247d Patch-mainline: Queued in subsystem maintainer repository lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of @@ -32,12 +32,17 @@ Add double negation to the right side to normalize the _PAGE_RW flag to 0 or 1. -Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()") -Cc: [email protected] Assisted-by: Copilot:claude-opus-4.8 +Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()") +Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Signed-off-by: Dave Hansen <[email protected]> Reviewed-by: Juergen Gross <[email protected]> +Reviewed-by: Lorenzo Stoakes (ARM) <[email protected]> Tested-by: [email protected] -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> +Tested-by: Atish Patra <[email protected]> +Tested-by: Nikunj A Dadhania <[email protected]> +Cc:[email protected] +Link: https://patch.msgid.link/[email protected] Signed-off-by: Pedro Falcato <[email protected]> --- arch/x86/mm/pat/set_memory.c | 8 ++++---- ++++++ series.conf ++++++ ++++ 753 lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kernel-source/series.conf ++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.1265/series.conf ++++++ source-timestamp ++++++ --- /var/tmp/diff_new_pack.TzkPBf/_old 2026-09-09 16:21:51.667800928 +0200 +++ /var/tmp/diff_new_pack.TzkPBf/_new 2026-09-09 16:21:51.672801136 +0200 @@ -1,4 +1,4 @@ -2026-09-03 05:42:23 +0000 -GIT Revision: 263d9258ef078247c90a6b2b59d6e65ef2f26ae6 +2026-09-07 16:12:54 +0000 +GIT Revision: eac7913e822e4173ccdb1ffbf447f1d91f5a8a32 GIT Branch: stable
