Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package kernel-source for openSUSE:Factory 
checked in at 2026-09-09 16:19:31
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/kernel-source (Old)
 and      /work/SRC/openSUSE:Factory/.kernel-source.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "kernel-source"

Wed Sep  9 16:19:31 2026 rev:858 rq:1376230 version:7.2.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes        
2026-09-07 11:28:45.346803371 +0200
+++ /work/SRC/openSUSE:Factory/.kernel-source.new.1265/dtb-aarch64.changes      
2026-09-09 16:21:41.763388213 +0200
@@ -1,0 +2,1340 @@
+Mon Sep  7 17:57:41 CEST 2026 - [email protected]
+
+- Linux 7.2.4 (bsc#1012628).
+- platform/chrome: sensorhub: Fix dropped timestamp events and
+  log spam (bsc#1012628).
+- ACPI: scan: Do not combine resources that overlap completely
+  (bsc#1012628).
+- selftests/mm: fix on-fault-limit false failure under sudo-rs
+  (bsc#1012628).
+- udf: Fix i_lenExtents truncation on 32-bit kernels
+  (bsc#1012628).
+- timer: Keep debugobjects state consistent in
+  migrate_timer_list() (bsc#1012628).
+- timekeeping: Check the return value of tk_get_aux_ts64 in
+  __do_adjtimex() (bsc#1012628).
+- taskstats: fix cpumask parsing cutting off the last character
+  (bsc#1012628).
+- smack: fix cred UAF in smack_file_send_sigiotask()
+  (bsc#1012628).
+- signal: avoid shared siginfo namespace rewrites (bsc#1012628).
+- sticon/parisc: Detect default STI graphics card for console
+  output (bsc#1012628).
+- sysctl: move the "cad_pid" entry from pid_table[] to
+  kern_reboot_table[] (bsc#1012628).
+- tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (bsc#1012628).
+- zloop: truncate finished zones to zone capacity (bsc#1012628).
+- xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc()
+  (bsc#1012628).
+- w1: ds28e17: reject an oversize length on an I2C block read
+  (bsc#1012628).
+- vsock/virtio: flush works in dependency order (bsc#1012628).
+- wifi: mt76: mt7996: validate default EEPROM firmware size
+  (bsc#1012628).
+- wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
+  (bsc#1012628).
+- wifi: mt76: mt7996: bound the device EEPROM address before
+  the EFUSE copy (bsc#1012628).
+- wifi: mt76: mt7925: cancel mlo_pm_work on stop (bsc#1012628).
+- wifi: mt76: mt7915: bound the device EEPROM address before
+  the EFUSE copy (bsc#1012628).
+- wifi: mt76: mt7615: avoid waiting for mac work under the mt76
+  mutex (bsc#1012628).
+- wifi: rtw89: pci: add .shutdown callback to stop rfkill polling
+  on reboot (bsc#1012628).
+- wifi: rtw88: pci: fix resource leak on failed NAPI setup
+  (bsc#1012628).
+- wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
+  (bsc#1012628).
+- wifi: rtlwifi: rtl8192du: Fix possible memory leak in
+  rtl92du_init_sw_vars() (bsc#1012628).
+- wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
+  (bsc#1012628).
+- wifi: rtl818x: initialize eeprom_93cx6 struct to zero
+  (bsc#1012628).
+- wifi: mwifiex: Detach sync cmd buffer on interrupted wait
+  (bsc#1012628).
+- mm/kmemleak: report RCU-tasks quiescent states during the scan
+  (bsc#1012628).
+- mm/kmemleak: stop the task stack scan early when interrupted
+  (bsc#1012628).
+- crypto: atmel-ecc - avoid stale fallback key after set_secret
+  failure (bsc#1012628).
+- crypto: atmel-ecc - clean up and improve ECDH comments
+  (bsc#1012628).
+- crypto: iaa - unmap dst before software fallback on decompress
+  (bsc#1012628).
+- fuse: copy request headers via a stack buffer for io-uring
+  (bsc#1012628).
+- fuse: decouple fuse_ring creation from ent registration
+  (bsc#1012628).
+- wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
+  (bsc#1012628).
+- wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
+  (bsc#1012628).
+- wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
+  (bsc#1012628).
+- i3c: renesas: Perform Dynamic Address Assignment on resume
+  (bsc#1012628).
+- i3c: renesas: Restore STDBR and EXTBR registers on resume
+  (bsc#1012628).
+- i3c: renesas: Reset the controller on resume (bsc#1012628).
+- i3c: renesas: Reconfigure the DATBAS register on re-attach
+  (bsc#1012628).
+- i3c: renesas: Follow the reset deassert order used in probe
+  (bsc#1012628).
+- i3c: renesas: Clean DATBAS register on detach (bsc#1012628).
+- i3c: renesas: Check that the transfer is valid before accessing
+  it (bsc#1012628).
+- i3c: master: svc: bound IBI payload to the requested
+  max_payload_len (bsc#1012628).
+- i3c: master: Fix info leak and UAF in device unregister path
+  (bsc#1012628).
+- i3c: master: adi: initialize the lock before enabling interrupts
+  (bsc#1012628).
+- i3c: Fix unlocked dereference of dev->desc in
+  i3c_device_get_supported_xfer_mode() (bsc#1012628).
+- dm-pcache: fix use-after-free and invalid seg operations in
+  kset_replay() (bsc#1012628).
+- dm-pcache: fix implicit u8 truncation of gc_percent in message
+  handler (bsc#1012628).
+- dm-pcache: only hand out initialized cache segments
+  (bsc#1012628).
+- dm-pcache: detect a cycle in the last-kset chain during replay
+  (bsc#1012628).
+- dm-pcache: clamp the tail kset read to the segment data region
+  (bsc#1012628).
+- dm-pcache: bound the persisted tail-position offset
+  (bsc#1012628).
+- dm-pcache: validate on-media seg_num against the cache device
+  size (bsc#1012628).
+- dm-pcache: validate kset key_num and intra-segment bounds
+  (bsc#1012628).
+- dm-pcache: validate geometry fields from on-disk cache_info
+  (bsc#1012628).
+- dm-switch: use WRITE_ONCE() in switch_region_table_write()
+  (bsc#1012628).
+- dm-stats: fix a crash if allocation of per-cpu data fails
+  (bsc#1012628).
+- arch_numa: avoid false positive fortify warning in
+  setup_node_to_cpumask_map() (bsc#1012628).
+- rust: num: reject Bounded::shr overshifts at build time
+  (bsc#1012628).
+- ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering
+  (bsc#1012628).
+- ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n:
+  AD3Q9ET#UUG (bsc#1012628).
+- ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
+  (bsc#1012628).
+- ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx
+  (bsc#1012628).
+- ALSA: virmidi: Check card index validity at probe (bsc#1012628).
+- ALSA: serial-u16550: Check card index validity at probe
+  (bsc#1012628).
+- ALSA: portman2x4: Check card index validity at probe
+  (bsc#1012628).
+- ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
+  (bsc#1012628).
+- ALSA: mts64: Check card index validity at probe (bsc#1012628).
+- ALSA: mpu401: Check card index validity at probe (bsc#1012628).
+- ALSA: hda/ext: preserve PPLCCTL bits when clearing reset
+  (bsc#1012628).
+- ALSA: FCP: do not copy out an uninitialised init response
+  (bsc#1012628).
+- ALSA: bcd2000: clear the URB pointers on disconnect
+  (bsc#1012628).
+- ALSA: aloop: Check card index validity at probe (bsc#1012628).
+- ALSA: 6fire: bound the MIDI event length from the device
+  (bsc#1012628).
+- mfd: sm501: Fix potential memory leaks during remove
+  (bsc#1012628).
+- mfd: qnap-mcu: keep the reply buffer alive past a command
+  timeout (bsc#1012628).
+- mfd: cgbc: Fix teardown ordering in cgbc_remove() (bsc#1012628).
+- hwrng: stm32 - Fix runtime PM cleanup on registration failure
+  (bsc#1012628).
+- seg6: reset IP6CB after IPv6 decapsulation (bsc#1012628).
+- net: skbuff: don't touch shared zerocopy state in skb_tx_error()
+  (bsc#1012628).
+- net: fix spurious TX timeout after dev_activate() (bsc#1012628).
+- net: cap advertised IP tunnel headroom (bsc#1012628).
+- net/smc: unregister the connection before draining the rx
+  tasklet (bsc#1012628).
+- net/smc: stop killed, freed and out_of_sync sharing a byte
+  (bsc#1012628).
+- net/smc: fix use-after-free of the LLC qentry in
+  smc_llc_srv_add_link() (bsc#1012628).
+- net/smc: fix use-after-free in smc_rx_pipe_buf_release()
+  (bsc#1012628).
+- net/smc: fix socket refcount leak in smc_switch_conns()
+  (bsc#1012628).
+- net/smc: do not dereference an unset send buffer on the SMC-D
+  teardown path (bsc#1012628).
+- net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
+  (bsc#1012628).
+- net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
+  (bsc#1012628).
+- net/mlx5e: do not HW-GRO coalesce small frames (bsc#1012628).
+- net: ntb_netdev: Count packets dropped on RX refill failure
+  (bsc#1012628).
+- net: ntb_netdev: Avoid double-accounting netif_rx() drops
+  (bsc#1012628).
+- net: ntb_netdev: Fix TX busy and drop handling (bsc#1012628).
+- NTB: ntb_transport: Reject oversized TX buffers (bsc#1012628).
+- NTB: ntb_transport: Fail TX enqueue when the QP link is down
+  (bsc#1012628).
+- NTB: ntb_transport: Recycle TX entries before client callbacks
+  (bsc#1012628).
+- net: thunderbolt: Mark the connection down when bringing it
+  up fails (bsc#1012628).
+- net: thunderbolt: Release the Rx HopID that was handed out on
+  mismatch (bsc#1012628).
+- net: ravb: serialize PTP clock teardown (bsc#1012628).
+- net: ravb: avoid dereferencing an invalid PTP clock
+  (bsc#1012628).
+- net: phylink: correctly validate returned PCS in
+  phylink_inband_caps (bsc#1012628).
+- net: openvswitch: fix nf_connlabels leak in ovs_ct_init
+  (bsc#1012628).
+- net: openvswitch: fix flow mask use-after-free on flow deletion
+  (bsc#1012628).
+- net: mctp: hold a reference to the route device in
+  mctp_route_lookup() (bsc#1012628).
+- net: l2tp: do not propagate multicast notification errors
+  (bsc#1012628).
+- net: ipa: fix stalled modem TX queue after runtime resume
+  (bsc#1012628).
+- net: ibm: emac: mal: fix NAPI locking (bsc#1012628).
+- net: bnxt: ring the doorbell when SW USO exits early
+  (bsc#1012628).
+- net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
+  (bsc#1012628).
+- net: tun: bound receive headroom (bsc#1012628).
+- net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition
+  (bsc#1012628).
+- slip: fix use-after-free in sl_sync() (bsc#1012628).
+- xdp: fix zero-copy frame layout (bsc#1012628).
+- net/iucv: filter frames in afiucv_hs_rcv() by ingress device
+  (bsc#1012628).
+- ipmi:msghandler: Cancel work cleanly on an error (bsc#1012628).
+- ipmi: si: Fix NULL pointer dereference after failed registration
+  (bsc#1012628).
+- ipmi: Remove all sysfs files on registration failure
+  (bsc#1012628).
+- ipmi: ipmb: validate write message length (bsc#1012628).
+- interconnect: Fix use after free in icc_get() and
+  of_icc_get_by_index() (bsc#1012628).
+- io_uring/query: cap user size passed to copy_struct_to_user
+  (bsc#1012628).
+- io_uring/waitid: avoid siginfo copy during ring teardown
+  (bsc#1012628).
+- io_uring/waitid: honor task_work cancellation (bsc#1012628).
+- platform/x86: hp-bioscfg: warn on element type mismatch instead
+  of failing (bsc#1012628).
+- platform/x86: hp-bioscfg: pass validated element count to
+  package parsers (bsc#1012628).
+- platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being
+  parsed (bsc#1012628).
+- platform/x86: hp-bioscfg: fix off-by-one write in
+  hp_get_string_from_buffer() (bsc#1012628).
+- platform/x86: hp-bioscfg: fix new_password_store() overwriting
+  current_password (bsc#1012628).
+- platform/x86: hp-bioscfg: fix heap OOB read on empty password
+  write (bsc#1012628).
+- platform/x86: hp-bioscfg: fix heap OOB read in sk_store()
+  and kek_store() (bsc#1012628).
+- platform/x86: hp-bioscfg: bound ordered-list parsing by the
+  package count (bsc#1012628).
+- platform/x86: hp-bioscfg: advance elem past consumed array
+  elements (bsc#1012628).
+- platform/x86: hp-bioscfg: accept reduced ACPI packages from
+  older HP BIOS (bsc#1012628).
+- platform/x86/amd/pmc: Fix msg_port restoration in
+  amd_stb_debugfs_open_v2() (bsc#1012628).
+- platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init
+  fails (bsc#1012628).
+- platform/x86/amd/pmc: Propagate SMU errors and validate S2D
+  address (bsc#1012628).
+- platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init()
+  error paths (bsc#1012628).
+- platform/chrome: sensorhub: Bound the EC-reported sensor number
+  (bsc#1012628).
+- platform/x86: think-lmi: Fix current password length check
+  (bsc#1012628).
+- platform/x86: think-lmi: Free system certificate signatures
+  (bsc#1012628).
+- platform/x86: think-lmi: Fix certificate thumbprint sysfs output
+  (bsc#1012628).
+- platform/x86: panasonic-laptop: Fix sentinel write past
+  pcc->sinf[] (bsc#1012628).
+- platform/x86: lenovo/ymc: Only match lower byte in WMI lid
+  switch query response (bsc#1012628).
+- platform/x86: ishtp_eclite: Fix ACPI device reference leak in
+  probe error path (bsc#1012628).
+- platform/x86: int1092: Fix potential memory leak in sar_probe()
+  (bsc#1012628).
+- platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
+  (bsc#1012628).
+- platform/x86: ISST: Return error during profile addition
+  (bsc#1012628).
+- platform/x86: ISST: Validate parameter for frequency and
+  priority (bsc#1012628).
+- platform/x86: ISST: Validate parameter for core power state
+  (bsc#1012628).
+- platform/x86: ISST: Validate max level for set feature
+  (bsc#1012628).
+- platform/x86: ISST: Validate logical CPU id and clos id
+  (bsc#1012628).
+- platform/x86: ISST: Use PP level enable mask (bsc#1012628).
+- platform/x86: ISST: Just allow 2 bits for SST feature enable
+  (bsc#1012628).
+- platform/x86: ISST: Add a NULL check for sst_inst[]
+  (bsc#1012628).
+- mmc: via-sdmmc: stop card-detect handling on probe failure
+  (bsc#1012628).
+- mmc: via-sdmmc: cancel card-detect work on remove (bsc#1012628).
+- platform/x86: ISST: Validate socket ID in clos_assoc ioctl
+  (bsc#1012628).
++++ 1055 more lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes
++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.1265/dtb-aarch64.changes
dtb-armv6l.changes: same change
dtb-armv7l.changes: same change
dtb-riscv64.changes: same change
kernel-64kb.changes: same change
kernel-default.changes: same change
kernel-docs.changes: same change
kernel-kvmsmall.changes: same change
kernel-lpae.changes: same change
kernel-obs-build.changes: same change
kernel-obs-qa.changes: same change
kernel-pae.changes: same change
kernel-source.changes: same change
kernel-syms.changes: same change
kernel-vanilla.changes: same change
kernel-zfcpdump.changes: same change

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ dtb-aarch64.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.183697416 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.185697499 +0200
@@ -17,7 +17,7 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
+%define patchversion 7.2.4
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -25,9 +25,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           dtb-aarch64
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

dtb-armv6l.spec: same change
dtb-armv7l.spec: same change
dtb-riscv64.spec: same change
++++++ kernel-64kb.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.372705292 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.374705375 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-64kb
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

kernel-default.spec: same change
++++++ kernel-docs.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.459708917 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.462709042 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define build_html 1
 %define build_pdf 0
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-docs
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

++++++ kernel-kvmsmall.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.519711417 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.521711501 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-kvmsmall
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

kernel-lpae.spec: same change
++++++ kernel-obs-build.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.617715501 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.620715626 +0200
@@ -19,7 +19,7 @@
 
 #!BuildIgnore: post-build-checks
 
-%define patchversion 7.2.3
+%define patchversion 7.2.4
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -38,23 +38,23 @@
 %endif
 %endif
 %endif
-%global kernel_package 
kernel%kernel_flavor-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%global kernel_package 
kernel%kernel_flavor-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %endif
 %if 0%{?rhel_version}
 %global kernel_package kernel
 %endif
 
 Name:           kernel-obs-build
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif
 Summary:        package kernel and initrd for OBS VM builds
 License:        GPL-2.0-only
 Group:          SLES
-Provides:       
kernel-obs-build-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+Provides:       
kernel-obs-build-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 BuildRequires:  coreutils
 BuildRequires:  device-mapper
 BuildRequires:  dracut

++++++ kernel-obs-qa.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.668717627 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.671717752 +0200
@@ -17,15 +17,15 @@
 # needsrootforbuild
 
 
-%define patchversion 7.2.3
+%define patchversion 7.2.4
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-obs-qa
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif
@@ -36,7 +36,7 @@
 # kernel-obs-build must be also configured as VMinstall, but is required
 # here as well to avoid that qa and build package build parallel
 %if ! 0%{?qemu_user_space_build}
-BuildRequires:  
kernel-obs-build-srchash-263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+BuildRequires:  
kernel-obs-build-srchash-eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %endif
 BuildRequires:  modutils
 ExclusiveArch:  aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64

++++++ kernel-pae.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.728720127 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.731720252 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-pae
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

++++++ kernel-source.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.777722169 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.779722252 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define gcc_package gcc
 %define gcc_compiler gcc
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-source
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

++++++ kernel-syms.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.829724336 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.831724419 +0200
@@ -16,15 +16,15 @@
 #
 
 
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-syms
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

++++++ kernel-vanilla.spec ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:49.877726336 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:49.880726461 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.3
-%define git_commit 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+%define patchversion 7.2.4
+%define git_commit eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-vanilla
-Version:        7.2.3
+Version:        7.2.4
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g263d925
+Release:        <RELEASE>.geac7913
 %else
 Release:        0
 %endif

kernel-zfcpdump.spec: same change
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:50.110736045 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:50.115736254 +0200
@@ -1,6 +1,6 @@
-mtime: 1788414228
-commit: bc47402a8f0b7bfd77fb34a9f7380eb1b2387e15ae66e4747ffe59c246070c92
+mtime: 1788797792
+commit: a3ee9771a981d07615b129ad162aba3ab497c888f67adb7a0bc441af930deeb1
 url: https://src.opensuse.org/jirislaby/kernel-source
-revision: bc47402a8f0b7bfd77fb34a9f7380eb1b2387e15ae66e4747ffe59c246070c92
+revision: a3ee9771a981d07615b129ad162aba3ab497c888f67adb7a0bc441af930deeb1
 trackingbranch: Kernel/stable
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-07 18:16:32.000000000 +0200
@@ -0,0 +1 @@
+.osc




++++++ patches.kernel.org.tar.bz2 ++++++
++++ 65875 lines of diff (skipped)

++++++ patches.suse.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
 
new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
--- 
old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
        1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
        2026-09-04 09:27:27.000000000 +0200
@@ -0,0 +1,114 @@
+From 5f171116a59871a7690adb6b8621de0c226738ad Mon Sep 17 00:00:00 2001
+From: "Ritesh Harjani (IBM)" <[email protected]>
+Date: Sun, 30 Aug 2026 20:24:30 +0530
+Subject: [PATCH 4/4] powerpc: Do not restore KUAP in
+ arch_exit_to_user_mode_prepare()
+
+References: bsc#1277802 ltc#222379
+Patch-mainline: Submitted 
https://lore.kernel.org/all/52fee44fd23acf8e1c024ace668728e626a783a8.1788101609.git.ritesh.l...@gmail.com/
+
+KUAP means kernel cannot touch user memory unless it explicitly is
+enabled. In the kernel it should stay AMR_KUAP_BLOCKED. While returning
+to userspace just before RFI, kernel should restore the user AMR value
+back.
+
+Looks like GENERIC_ENTRY might be treating arch_exit_to_user_mode_prepare()
+as the last architecture step before returning to userspace.
+commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
+therefore called kuap_user_restore() from that hook. But on PowerPC that
+is too early. After irqentry_exit() / syscall_exit_to_user_mode() we
+still run platform specific exit routines.
+
+e.g. code snippets showing both exception handling and system call
+handling as the callers of function arch_exit_to_user_mode_prepare()
+which does kuap_user_restore(). The below path shows that calling
+kuap_user_restore() is too early when called from
+arch_exit_to_user_mode_prepare().
+
+Exception handling in exceptions-64s.S
+=======================================
+
+bl     CFUNC(do_page_fault)
+         ..DEFINE_INTERRUPT_HANDLER_ASYNC(do_page_fault)
+             arch_interrupt_async_enter_prepare(regs);
+             state = irqentry_enter(regs);
+             instrumentation_begin();
+             irq_enter_rcu();
+             handler(regs);
+             nap_adjust_return(regs);
+             irq_exit_rcu();
+             instrumentation_end();
+             arch_interrupt_async_exit_prepare(regs);
+             irqentry_exit(regs, state);                  <<< too early
+               irqentry_exit_to_user_mode()
+                 __exit_to_user_mode_prepare(regs, EXIT_TO_USER_MODE_WORK_IRQ);
+                   arch_exit_to_user_mode_prepare(regs, ti_work);  <<< too 
early
+b      interrupt_return_srr
+               .. bl   CFUNC(interrupt_exit_user_prepare) <<< already calls 
kuap_user_restore
+
+prep_irq_for_enabled_exit() retry can run kernel code with IRQs on. So
+only when that routine is fully finished is when the user KUAP should be
+fully restored which interrupt_exit_user_prepare() already takes care of
+before returning.
+
+Similarly for system call handling in interrupt_64.S
+======================================================
+
+       bl      CFUNC(system_call_exception)
+
+.Lsyscall_exit:
+       addi    r4,r1,STACK_INT_FRAME_REGS
+       li      r5,0 /* !scv */
+       bl      CFUNC(syscall_exit_prepare)
+                 .. kuap_assert_locked();
+                    syscall_exit_to_user_mode(regs); <<< too early
+                      syscall_exit_to_user_mode_prepare(regs);  <<< too early
+                    kuap_user_restore(regs);         <<< already calls
+
+syscall_exit_prepare(), which can enable IRQs, replay a pending
+interrupt, and only then rfi. Those functions already restore KUAP
+immediately before rfi.
+
+Note that if we restore the user AMR too early like in the current code
+as shown from the code snippets above, then we get the following warning
+when CONFIG_PPC_KUAP_DEBUG is enabled:
+  WARNING: arch/powerpc/include/asm/book3s/64/kup.h:293 at 
interrupt_exit_user_prepare+0x1a0/0x1c0
+  Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected)
+  TRAP: 0700
+  LR: c00000000000d8d4 CTR: c0000000021fe500
+  MSR: <SF,EE,ME,IR,DR,RI,LE>  CR: 44000804  XER: 20040000
+  interrupt_exit_user_prepare+0x1a0/0x1c0
+  interrupt_return_srr_user+0x8/0x12c
+
+Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
+Fixes: 02565a782c1ee ("powerpc: Introduce syscall exit arch functions")
+Signed-off-by: Ritesh Harjani (IBM) <[email protected]>
+Acked-by: Michal Suchanek <[email protected]>
+---
+ arch/powerpc/include/asm/entry-common.h | 10 ++++++++--
+ 1 file changed, 8 insertions(+), 2 deletions(-)
+
+diff --git a/arch/powerpc/include/asm/entry-common.h 
b/arch/powerpc/include/asm/entry-common.h
+index 2a153dca962c7..839ab69c72d35 100644
+--- a/arch/powerpc/include/asm/entry-common.h
++++ b/arch/powerpc/include/asm/entry-common.h
+@@ -515,8 +515,14 @@ static inline void arch_exit_to_user_mode_prepare(struct 
pt_regs *regs,
+ #ifdef CONFIG_PPC_TRANSACTIONAL_MEM
+       local_paca->tm_scratch = regs->msr;
+ #endif
+-      /* Restore user access locks last */
+-      kuap_user_restore(regs);
++      /*
++       * Do not restore KUAP here. Generic entry might treat this as the last
++       * arch step before userspace but PowerPC still has kernel work after
++       * irqentry_exit()/syscall_exit_to_user_mode() i.e. in
++       * interrupt_exit_user_prepare() / syscall_exit_prepare() may enable
++       * IRQs and retry. Those functions restore KUAP immediately before rfi,
++       * which is where it should belong.
++       */
+ }
+ 
+ #define arch_exit_to_user_mode_prepare arch_exit_to_user_mode_prepare
+-- 
+2.51.0
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 
new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch
--- 
old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch    
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch    
    2026-09-04 09:27:27.000000000 +0200
@@ -0,0 +1,94 @@
+From 8b51f35e51cd17626f1fbf6022824186e33e208f Mon Sep 17 00:00:00 2001
+From: "Ritesh Harjani (IBM)" <[email protected]>
+Date: Sat, 29 Aug 2026 09:49:00 +0530
+Subject: [PATCH 1/4] powerpc: Don't drop _TIF_RESTOREALL on syscall restart
+
+References: bsc#1277802 ltc#222379
+Patch-mainline: Submitted 
https://lore.kernel.org/all/10c86c909f870d90b3094f76b692b44ebe9caeac.1787976185.git.ritesh.l...@gmail.com/
+
+So the syscall return sequence is as follows:
+A syscall return to userspace is prepared and then a short asm sequence
+that actually does the RFI. Note that this asm range is restartable i.e.
+EE is still on, so an interrupt (e.g. decrementer or external interrupt)
+can hit while SRR/GPRs are being loaded. This is defined via:
+
+RESTART_TABLE(.Lsyscall_rst_start, .Lsyscall_rst_end, syscall_restart)
+
+This restart table then sends us to syscall_restart rather than resuming
+in the middle of the RFI. The same stub is also used if irq_happened
+already has a pending bit (soft-masked irq that has not been replayed
+yet (PowerPC special case of local_irq_disable())).
+
+Here is a bit of a flow of sequence of code to visualize:
+  syscall_exit_prepare
+      decide full-GPR restore (_TIF_RESTOREALL) for signal,
+      rt_sigreturn or syscall trace
+      save that in regs->exit_result and return it in r3
+           |
+           v
+  .Lsyscall_rst_start .. _end     EE still on
+      irq_happened set or interrupt in this range?
+           | no                         | yes
+           v                            v
+      cmpdi r3,0                  syscall_exit_restart
+      restore all / zero            replay irq, try exit again
+      volatiles; RFI                must return flags in r3
+                                    again for the same cmpdi
+
+Now r3 after prepare is the flags word, not the actual syscall return. A nested
+interrupt clobbers it, so the restart stub reloads RESULT into r3 and the
+C handler (syscall_exit_restart()) should put the flags back (because later asm
+checks whether r3 returned from C has _TIF_RESTOREALL set or not):
+       cmpdi r3, 0
+       bne     .Lsyscall_restore_regs
+
+Note that syscall_exit_restart() already ORs any new _TIF_RESTOREALL into
+exit_result, but then it only returns the new sample and not the full
+regs->exit_result.
+
+That sample could be often 0 even when restore-all is still required:
+
+  - rt_sigreturn / syscall trace set the bit in prepare's local
+    ret and in exit_result. They never set exit_flags, which is
+    what restart samples.
+
+  - a signal does set exit_flags but restart clears it. A
+    second pass through the stub then returns 0 while
+    exit_result still has the bit.
+
+The asm as mentioned earlier then treats r3==0 as the fast path and
+zeros r0/r4-r12. That means the userspace that needed the full register
+set could SIGSEGVs, (which could happen often in ld64.so.2 like while
+doing a parallel kernel build as reported by Venkat).
+
+So we should instead return the accumulated exit_result, like how we do
+in interrupt_exit_user_restart(). Note that prior to this commit
+263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace")
+we were returning regs->exit_result from syscall_exit_restart(), but
+this commit changed that behaviour.
+
+Fixes: 263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for 
ptrace")
+Reported-by: Venkat Rao Bagalkote <[email protected]>
+Closes: 
https://lore.kernel.org/all/[email protected]/
+Signed-off-by: Ritesh Harjani (IBM) <[email protected]>
+Acked-by: Michal Suchanek <[email protected]>
+---
+ arch/powerpc/kernel/interrupt.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/arch/powerpc/kernel/interrupt.c b/arch/powerpc/kernel/interrupt.c
+index 5b88bf72786c7..55f9c0c9922ac 100644
+--- a/arch/powerpc/kernel/interrupt.c
++++ b/arch/powerpc/kernel/interrupt.c
+@@ -175,7 +175,7 @@ notrace unsigned long syscall_exit_restart(unsigned long 
r3, struct pt_regs *reg
+       current_thread_info()->exit_flags &= ~_TIF_RESTOREALL;
+       regs->exit_result |= ret;
+ 
+-      return ret;
++      return regs->exit_result;
+ }
+ #endif
+ 
+-- 
+2.51.0
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
 
new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
--- 
old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
  1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
  2026-09-04 09:27:27.000000000 +0200
@@ -0,0 +1,97 @@
+From d6770f7fe9e114e02629d4f0666b9f2053d538b7 Mon Sep 17 00:00:00 2001
+From: Aboorva Devarajan <[email protected]>
+Date: Fri, 4 Sep 2026 08:28:30 +0530
+Subject: [PATCH 5/5] powerpc/entry: Fix double accounting of user time on
+ interrupt entry
+
+References: bsc#1277802 ltc#222379
+Patch-mainline: Submitted 
https://lore.kernel.org/all/[email protected]/
+
+Since the switch to generic entry, an interrupt from user mode
+accounts user time twice: once in arch_interrupt_enter_prepare()
+and again in arch_enter_from_user_mode(), which irqentry_enter()
+invokes for the same interrupt:
+
+       arch_interrupt_enter_prepare()
+         account_cpu_user_entry()              /* first */
+       irqentry_enter()
+         arch_enter_from_user_mode()
+           account_cpu_user_entry()            /* second */
+
+The second call charges the same interval again, because
+account_cpu_user_entry() accumulates the time spent in user mode
+since the last return to user space.
+
+The two calls come from the GENERIC_ENTRY preparation series,
+where each step was a no-op on its own. Commit 09a9d3a8499d
+("powerpc: introduce arch_enter_from_user_mode") added the hook
+with the user-time accounting in it, but nothing called it yet.
+Commit 893082ac769b ("powerpc: Prepare for IRQ entry exit")
+copied interrupt_enter_prepare() verbatim into entry-common.h as
+arch_interrupt_enter_prepare(); that copy was equally unused, as
+handlers still called interrupt_enter_prepare().
+
+Commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
+made both live. On the syscall side it did the full conversion:
+system_call_exception() now accounts once through the hook via
+syscall_enter_from_user_mode(), rather than calling
+account_cpu_user_entry() directly. On the interrupt side it
+switched the handler macros to arch_interrupt_enter_prepare()
+followed by irqentry_enter(), which also runs the hook, but the
+accounting in arch_interrupt_enter_prepare() was not removed to
+match. The double accounting starts with that commit.
+
+With CONFIG_VIRT_CPU_ACCOUNTING_NATIVE=y this roughly doubles the
+reported user time of any workload that takes interrupts. The
+other accounting modes compile account_cpu_user_entry() to an
+empty stub, so they are not affected.
+
+Remove the accounting from arch_interrupt_enter_prepare() and rely
+on arch_enter_from_user_mode(), which already runs for both
+syscalls and interrupts. The duplicate account_stolen_time() call
+is removed the same way.
+
+On a pseries LPAR a busy loop reports 6s user time in 3s elapsed
+(~210% CPU) before the fix, and 3s (~105% CPU) after it:
+
+  $ python3 -c 'while True: pass' &
+  $ sleep 3; ps -p $! -o etime,time,pcpu
+
+            ELAPSED     TIME  %CPU
+  Before      00:03 00:00:06   210
+  After       00:03 00:00:03   105
+
+A 50% load reports ~70% usr / 30% idle before the fix, and
+~49% usr / 51% idle after it:
+
+  $ taskset -c 6 stress-ng --cpu 1 --cpu-load 50 &
+  $ mpstat -P 6 1
+
+            CPU    %usr   %idle
+  Before      6   69.74   30.26
+  After       6   48.51   50.50
+
+Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
+Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
+Signed-off-by: Aboorva Devarajan <[email protected]>
+Acked-by: Michal Suchanek <[email protected]>
+---
+ arch/powerpc/include/asm/entry-common.h | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/arch/powerpc/include/asm/entry-common.h 
b/arch/powerpc/include/asm/entry-common.h
+index 839ab69c72d35..b899978e1a47c 100644
+--- a/arch/powerpc/include/asm/entry-common.h
++++ b/arch/powerpc/include/asm/entry-common.h
+@@ -222,8 +222,6 @@ static inline void arch_interrupt_enter_prepare(struct 
pt_regs *regs)
+ 
+       if (user_mode(regs)) {
+               kuap_lock();
+-              account_cpu_user_entry();
+-              account_stolen_time();
+       } else {
+               kuap_save_and_lock(regs);
+               /*
+-- 
+2.51.0
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
 
new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
--- 
old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
        1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
        2026-09-04 09:27:27.000000000 +0200
@@ -0,0 +1,105 @@
+From 817ffd5c832368950e4b498a200a7789b0601571 Mon Sep 17 00:00:00 2001
+From: "Mukesh Kumar Chaurasiya (IBM)" <[email protected]>
+Date: Thu, 20 Aug 2026 19:17:18 +0530
+Subject: [PATCH 3/4] powerpc/entry: Fix irq_soft_mask corruption on replayed
+ interrupt exit
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+References: bsc#1277802 ltc#222379
+Patch-mainline: Submitted 
https://lore.kernel.org/all/[email protected]/
+
+When __replay_soft_interrupts() replays a pending interrupt (e.g.
+PACA_IRQ_DEC → timer_interrupt), it calls the handler directly with a
+synthetic pt_regs. The DEFINE_INTERRUPT_HANDLER_ASYNC wrapper around
+each handler calls arch_interrupt_async_exit_prepare() on the way out,
+which calls arch_interrupt_exit_prepare() → local_irq_disable() →
+arch_local_irq_disable(), which does:
+
+    irq_soft_mask_set(IRQS_DISABLED)   /* 0x1 */
+
+This unconditionally overwrites irq_soft_mask with IRQS_DISABLED (0x1),
+stripping the IRQS_PMI_DISABLED (0x2) bit. The result is that
+irq_soft_mask is 0x1 instead of IRQS_ALL_DISABLED (0x3) when the
+handler returns to __replay_soft_interrupts().
+
+For a normally-taken interrupt this is harmless: the next interrupt
+always enters through arch_interrupt_enter_prepare() which
+unconditionally sets irq_soft_mask to IRQS_ALL_DISABLED.
+But during replay, next_interrupt() is called
+directly between replayed handlers without going back through
+arch_interrupt_enter_prepare(), so the stripped bit is never restored.
+next_interrupt() then fires a WARNING:
+
+    WARNING: arch/powerpc/kernel/irq_64.c:75
+    WARN_ON(irq_soft_mask_return() != IRQS_ALL_DISABLED)
+
+This was introduced by commit bee25f97ad24 ("powerpc: Enable
+GENERIC_ENTRY feature"). Before that commit, the old
+interrupt_async_exit_prepare() called irq_exit() followed by an empty
+interrupt_exit_prepare() stub and never touched irq_soft_mask at all,
+so the soft mask was left at IRQS_ALL_DISABLED throughout replay.
+
+The root cause: arch_interrupt_exit_prepare() uses local_irq_disable()
+whose only job is to set the IRQS_DISABLED bit; it has no knowledge of
+IRQS_PMI_DISABLED. It is there to satisfy irqentry_exit()'s
+requirement that interrupts be disabled, but using the plain
+irq_soft_mask_set(IRQS_ALL_DISABLED) is the right primitive:
+
+  - irq_soft_mask_set(IRQS_ALL_DISABLED): sets soft mask to 0x3
+    (both IRQS_DISABLED and IRQS_PMI_DISABLED). Touches only the soft
+    mask. MSR[EE] and PACA_IRQ_HARD_DIS are already correct because
+    hard interrupts were never re-enabled during replay
+    (PACA_IRQ_REPLAYING is in PACA_IRQ_MUST_HARD_MASK, which blocks
+    should_hard_irq_enable()).
+
+  - local_irq_disable() / arch_local_irq_disable(): sets soft mask to
+    IRQS_DISABLED (0x1) only, silently dropping IRQS_PMI_DISABLED.
+
+  - hard_irq_disable(): also issues __mtmsrd to clear MSR[EE] in
+    hardware and sets PACA_IRQ_HARD_DIS — redundant and wrong here
+    since both are already set.
+
+Fix by replacing local_irq_disable() with irq_soft_mask_set(IRQS_ALL_DISABLED)
+in arch_interrupt_exit_prepare(), making the exit symmetric with the
+entry path in arch_interrupt_enter_prepare() which always sets
+IRQS_ALL_DISABLED.
+
+The warning was observed early in boot on a POWER10 pseries guest
+during kmem_cache_init_late(), where a spinlock release triggers
+interrupt replay that processes a pending timer interrupt.
+
+Debugger state confirming the bug:
+  Before timer_interrupt(&regs):
+    irq_soft_mask = 0x3 (IRQS_ALL_DISABLED)   correct
+    irq_happened  = 0x41 (HARD_DIS|REPLAYING)  correct
+  After timer_interrupt(&regs) returns:
+    irq_soft_mask = 0x1 (IRQS_DISABLED)        WRONG — PMI bit stripped
+    irq_happened  = 0x41                        unchanged
+
+Fixes: 334f3f6d7a16 ("powerpc/entry: Disable interrupts before irqentry_exit")
+Reported-by: Venkat Rao Bagalkote <[email protected]>
+Closes: 
https://lore.kernel.org/all/[email protected]/
+Signed-off-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
+Acked-by: Michal Suchanek <[email protected]>
+---
+ arch/powerpc/include/asm/entry-common.h | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/arch/powerpc/include/asm/entry-common.h 
b/arch/powerpc/include/asm/entry-common.h
+index c5adb50063610..2a153dca962c7 100644
+--- a/arch/powerpc/include/asm/entry-common.h
++++ b/arch/powerpc/include/asm/entry-common.h
+@@ -270,7 +270,7 @@ static inline void arch_interrupt_exit_prepare(struct 
pt_regs *regs)
+       }
+ 
+       /* irqentry_exit expects to be called with interrupts disabled */
+-      local_irq_disable();
++      irq_soft_mask_set(IRQS_ALL_DISABLED);
+ }
+ 
+ static inline void arch_interrupt_async_enter_prepare(struct pt_regs *regs)
+-- 
+2.51.0
+
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
--- 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   2026-08-28 10:54:09.000000000 +0200
+++ 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   2026-09-04 09:27:27.000000000 +0200
@@ -1,12 +1,12 @@
 From: Pedro Falcato <[email protected]>
-Date: Wed, 12 Aug 2026 18:02:54 +0300
-Subject: x86/alternative: exclude text poking against change_page_attr()
+Date: Thu, 13 Aug 2026 12:01:26 +0300
+Subject: x86/alternative: Exclude text poking against change_page_attr()
 References: bsc#1271202
-Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git
-Git-commit: 23fa304705d959c48d98fe63f950de65fc2dc917
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: e679ba0983757e9567aeda97cc35c99241d420ee
 Patch-mainline: Queued in subsystem maintainer repository
 
-From time to time, the following BUG can be observed[0]:
+>From time to time, the following BUG can be observed[0]:
 
 > kernel BUG at arch/x86/kernel/alternative.c:2576!
 > Oops: invalid opcode: 0000 [#1] SMP NOPTI
@@ -46,16 +46,26 @@
 
 Fix it by excluding against CPA using the init_mm mmap read lock.
 
+[ dhansen: Fix up SoB ordering. The actual code flow here was:
+          Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain
+          now. I *believe* Mike simply picked up Lorenzo's update to
+          Pedro's post from the Link: ]
+
 Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
 Reported-by: Jiri Slaby <[email protected]>
-Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
 Reported-by: Steffen Dirkwinkel <[email protected]>
-Link: 
https://lore.kernel.org/linux-mm/[email protected]/
-Cc: [email protected]
-Co-developed-by: "Lorenzo Stoakes (ARM)" <[email protected]>
-Signed-off-by: "Lorenzo Stoakes (ARM)" <[email protected]>
 Signed-off-by: Pedro Falcato <[email protected]>
+Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
+Co-developed-by: Lorenzo Stoakes (ARM) <[email protected]>
 Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
+Tested-by: Jiri Slaby <[email protected]>
+Tested-by: Atish Patra <[email protected]>
+Tested-by: Nikunj A Dadhania <[email protected]>
+Cc:[email protected]
+Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
+Link: 
https://lore.kernel.org/linux-mm/[email protected]/
+Link: https://patch.msgid.link/[email protected]
 Signed-off-by: Pedro Falcato <[email protected]>
 ---
  arch/x86/kernel/alternative.c |   39 ++++++++++++++++++++++++++++++++++++---
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   2026-08-28 10:54:09.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   2026-09-04 09:27:27.000000000 +0200
@@ -1,15 +1,15 @@
 From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Thu, 23 Jul 2026 16:16:33 +0100
-Subject: x86/mm/pat: acquire init_mm read lock on attribute change to avoid
+Date: Thu, 13 Aug 2026 12:01:25 +0300
+Subject: x86/mm/pat: Acquire init_mm read lock on attribute change to avoid
  UAF
 References: bsc#1271202
-Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git
-Git-commit: bbe7d7397af14436bf3b4f3c0d2d13c84e246c2f
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 884801a901bd340c44a202e2ef5c29b48e3a4d93
 Patch-mainline: Queued in subsystem maintainer repository
 
-A previous commit protected us against races between ptdump and CPA
-collapse, however one still exists between attribute changes and collapse
-as reported by Denis V. Lunev (linked).
+A previous commit protected against races between ptdump and CPA collapse,
+however one still exists between attribute changes and collapse as reported
+by Denis V. Lunev (linked).
 
 When an attribute change arises, a lockless page table walker obtains a PTE
 entry, which is later written to via set_pte_atomic():
@@ -26,8 +26,8 @@
 There is nothing preventing a concurrent CPA collapse which can free the
 PTE that was retrieved here, resulting in a use-after-free.
 
-With the mmap write lock taken on init_mm over CPA collapse, we can now
-resolve this race by acquiring an mmap read lock on init_mm over
+With the mmap write lock taken on init_mm over CPA collapse, resolve this
+race by acquiring an mmap read lock on init_mm over
 __change_page_attr_set_clr().
 
 This locks across the whole operation over which the walk and the PTE entry
@@ -81,11 +81,17 @@
 This work is based upon Denis V. Lunev's excellent analysis of the bug with
 gratitude.
 
-Link: https://lore.kernel.org/all/[email protected]/
+[ dhansen: move to imperative voice in changelog ]
+
 Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
-Cc: [email protected]
 Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
 Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
+Tested-by: Atish Patra <[email protected]>
+Tested-by: Nikunj A Dadhania <[email protected]>
+Link: https://lore.kernel.org/all/[email protected]/
+Cc:[email protected]
+Link: https://patch.msgid.link/[email protected]
 Signed-off-by: Pedro Falcato <[email protected]>
 ---
  arch/x86/mm/pat/set_memory.c |   13 +++++++++++--
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   2026-08-28 10:54:09.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   2026-09-04 09:27:27.000000000 +0200
@@ -1,9 +1,9 @@
 From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Thu, 23 Jul 2026 16:16:32 +0100
-Subject: x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
+Date: Thu, 13 Aug 2026 12:01:24 +0300
+Subject: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF
 References: bsc#1271202
-Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git
-Git-commit: c949657f06599c5ed33d7626e4c280549c5f4128
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 4cfad2657c7c87b1172a9c343b74cf59b3769873
 Patch-mainline: Queued in subsystem maintainer repository
 
 x86 implements page attribute modification using its Change Page
@@ -47,16 +47,21 @@
 mutex, disallowing atomic context here.
 
 Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
-Cc: [email protected]
+Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
 Reviewed-by: Mike Rapoport (Microsoft) <[email protected]>
 Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]>
 Reviewed-by: David Hildenbrand (Arm) <[email protected]>
 Reviewed-by: Dave Hansen <[email protected]>
 Reviewed-by: Will Deacon <[email protected]>
 Reviewed-by: David Carlier <[email protected]>
-Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Tested-by: Atish Patra <[email protected]>
+Tested-by: Nikunj A Dadhania <[email protected]>
+Cc:[email protected]
+Link: https://patch.msgid.link/[email protected]
 Signed-off-by: Pedro Falcato <[email protected]>
+
 ---
  arch/x86/mm/pat/set_memory.c |   15 ++++++++++++++-
  include/linux/mmap_lock.h    |    2 ++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
--- 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   2026-08-28 10:54:09.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   2026-09-04 09:27:27.000000000 +0200
@@ -1,14 +1,14 @@
 From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Tue, 21 Jul 2026 13:14:52 +0100
-Subject: x86/mm/pat: allocate split page tables as kernel page tables
+Date: Thu, 13 Aug 2026 12:01:27 +0300
+Subject: x86/mm/pat: Allocate split page tables as kernel page tables
 References: bsc#1271202
-Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git
-Git-commit: aae434cbad05053b33809a9174490966337ccb12
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 0e33126d5def407397deaf617559a1a2a7f4b1ae
 Patch-mainline: Queued in subsystem maintainer repository
 
-When splitting a large page in CPA in __split_large_page() we allocate a
-PTE directly without going through the standard page table allocation
-routines such as pte_alloc_one_kernel().
+A PTE is allocated directly without going through the standard page table
+allocation routines (such as pte_alloc_one_kernel()) when the CPA code
+splits a large page (__split_large_page()).
 
 This means the page table constructor is never called nor is the page table
 marked as a kernel page table.
@@ -35,10 +35,10 @@
 This results in these kernel page tables invoking a page table constructor,
 and thus requires a page table destructor.
 
-Since we cannot assume one is always present (early allocated direct map
-page tables are not marked as such), we conditionally call
-pagetable_dtor_free() if the PG_table folio flag for the ptdesc is set,
-otherwise we free the page table via pagetable_free().
+Destructors are not always present, like for early allocated direct map
+page tables). Conditionally call pagetable_dtor_free() if the PG_table
+folio flag for the ptdesc is set, otherwise we free the page table via
+pagetable_free().
 
 Regardless of which path is taken page tables marked as kernel page tables,
 which now includes split page tables, take the correct route through
@@ -52,11 +52,17 @@
 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so
 choose this as the Fixes target.
 
+[ dhansen: rephrase in imperative mood ]
+
 Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables")
-Cc: [email protected]
 Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Acked-by: Vishal Moola <[email protected]>
 Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
+Acked-by: Vishal Moola <[email protected]>
+Tested-by: Atish Patra <[email protected]>
+Tested-by: Nikunj A Dadhania <[email protected]>
+Cc:[email protected]
+Link: https://patch.msgid.link/[email protected]
 Signed-off-by: Pedro Falcato <[email protected]>
 ---
  arch/x86/mm/pat/set_memory.c |   25 ++++++++++++++++---------
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
 
new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
--- 
old/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
   2026-08-28 10:54:09.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch
   2026-09-04 09:27:27.000000000 +0200
@@ -1,10 +1,10 @@
 From: "Mike Rapoport (Microsoft)" <[email protected]>
-Date: Fri, 17 Jul 2026 12:41:43 +0300
-Subject: x86/mm/pat: fix effective RW computation in
+Date: Thu, 13 Aug 2026 12:01:28 +0300
+Subject: x86/mm/pat: Fix effective RW computation in
  lookup_address_in_pgd_attr()
 References: bsc#1271202
-Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git
-Git-commit: e7598bc2bb43dfcc51711da0507027c86973ec3e
+Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
+Git-commit: 453e7859443446b837d905d6f2983a76c867247d
 Patch-mainline: Queued in subsystem maintainer repository
 
 lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of
@@ -32,12 +32,17 @@
 Add double negation to the right side to normalize the _PAGE_RW flag to
 0 or 1.
 
-Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()")
-Cc: [email protected]
 Assisted-by: Copilot:claude-opus-4.8
+Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()")
+Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Signed-off-by: Dave Hansen <[email protected]>
 Reviewed-by: Juergen Gross <[email protected]>
+Reviewed-by: Lorenzo Stoakes (ARM) <[email protected]>
 Tested-by: [email protected]
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
+Tested-by: Atish Patra <[email protected]>
+Tested-by: Nikunj A Dadhania <[email protected]>
+Cc:[email protected]
+Link: https://patch.msgid.link/[email protected]
 Signed-off-by: Pedro Falcato <[email protected]>
 ---
  arch/x86/mm/pat/set_memory.c |    8 ++++----

++++++ series.conf ++++++
++++ 753 lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kernel-source/series.conf
++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.1265/series.conf

++++++ source-timestamp ++++++
--- /var/tmp/diff_new_pack.TzkPBf/_old  2026-09-09 16:21:51.667800928 +0200
+++ /var/tmp/diff_new_pack.TzkPBf/_new  2026-09-09 16:21:51.672801136 +0200
@@ -1,4 +1,4 @@
-2026-09-03 05:42:23 +0000
-GIT Revision: 263d9258ef078247c90a6b2b59d6e65ef2f26ae6
+2026-09-07 16:12:54 +0000
+GIT Revision: eac7913e822e4173ccdb1ffbf447f1d91f5a8a32
 GIT Branch: stable
 

Reply via email to