Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package kernel-source for openSUSE:Factory 
checked in at 2026-09-24 22:55:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/kernel-source (Old)
 and      /work/SRC/openSUSE:Factory/.kernel-source.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "kernel-source"

Thu Sep 24 22:55:34 2026 rev:861 rq:1379616 version:7.2.7

Changes:
--------
--- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes        
2026-09-17 15:17:50.357984423 +0200
+++ /work/SRC/openSUSE:Factory/.kernel-source.new.383539/dtb-aarch64.changes    
2026-09-24 22:56:04.422734574 +0200
@@ -1,0 +2,4062 @@
+Tue Sep 22 10:00:24 CEST 2026 - [email protected]
+
+- Update
+  
patches.kernel.org/7.2.4-001-drm-amd-display-Skip-Update-HDCP-Config-In-Tran.patch
+  (bsc#1012628 CVE-2026-89773 bsc#1280700).
+- Update
+  
patches.kernel.org/7.2.4-009-btrfs-write-protect-folios-during-data-writebac.patch
+  (bsc#1012628 CVE-2026-89772 bsc#1280699).
+- Update
+  
patches.kernel.org/7.2.4-010-ring-buffer-Fix-subbuf-resize-race-with-ring-bu.patch
+  (bsc#1012628 CVE-2026-89771 bsc#1280712).
+- Update
+  
patches.kernel.org/7.2.4-014-iomap-don-t-free-integrity-payload-that-doesn-t.patch
+  (bsc#1012628 CVE-2026-89770 bsc#1280710).
+- Update
+  
patches.kernel.org/7.2.4-017-clocksource-drivers-nxp-pit-Fix-IRQ-leak-on-cpu.patch
+  (bsc#1012628 CVE-2026-89769 bsc#1280708).
+- Update
+  patches.kernel.org/7.2.4-019-fs-fix-user-path-of-nested-backing-files.patch
+  (bsc#1012628 CVE-2026-89768 bsc#1280734).
+- Update
+  
patches.kernel.org/7.2.4-020-ovl-fix-double-end_creating-on-the-casefold-mis.patch
+  (bsc#1012628 CVE-2026-89767 bsc#1280730).
+- Update
+  
patches.kernel.org/7.2.4-021-pidfd-hold-exec_update_lock-around-namespace-io.patch
+  (bsc#1012628 CVE-2026-89766 bsc#1280725).
+- Update
+  
patches.kernel.org/7.2.4-024-timers-itimer-Zero-init-old-itimerval-before-co.patch
+  (bsc#1012628 CVE-2026-89765 bsc#1281182).
+- Update
+  
patches.kernel.org/7.2.4-032-rust-devres-fix-race-between-concurrent-revoker.patch
+  (bsc#1012628 CVE-2026-89764 bsc#1280818).
+- Update
+  patches.kernel.org/7.2.4-041-KEYS-trusted-Fix-TPM-teardown-ordering.patch
+  (bsc#1012628 CVE-2026-89763 bsc#1280820).
+- Update
+  
patches.kernel.org/7.2.4-042-apparmor-fix-cred-UAF-caused-by-begin_current_l.patch
+  (bsc#1012628 CVE-2026-89762 bsc#1280749).
+- Update
+  
patches.kernel.org/7.2.4-043-apparmor-fix-out-of-bounds-write-when-null-term.patch
+  (bsc#1012628 CVE-2026-89761 bsc#1280745).
+- Update
+  
patches.kernel.org/7.2.4-045-mm-swap-don-t-free-a-hibernation-slot-that-is-i.patch
+  (bsc#1012628 CVE-2026-89760 bsc#1280740).
+- Update
+  
patches.kernel.org/7.2.4-053-mm-kmemleak-avoid-soft-lockup-when-scanning-tas.patch
+  (bsc#1012628 CVE-2026-89759 bsc#1280821).
+- Update
+  
patches.kernel.org/7.2.4-055-mm-mempolicy-skip-non-present-PMDs-when-queuein.patch
+  (bsc#1012628 CVE-2026-89758 bsc#1280757).
+- Update
+  
patches.kernel.org/7.2.4-056-mm-mglru-fix-and-remove-redundant-unevictable-f.patch
+  (bsc#1012628 CVE-2026-89757 bsc#1280763).
+- Update
+  
patches.kernel.org/7.2.4-057-mm-migrate-report-RCU-tasks-quiescent-states-in.patch
+  (bsc#1012628 CVE-2026-89756 bsc#1280756).
+- Update
+  
patches.kernel.org/7.2.4-059-mm-migrate_device-clear-stale-mapping-after-fre.patch
+  (bsc#1012628 CVE-2026-89755 bsc#1280770).
+- Update
+  
patches.kernel.org/7.2.4-063-mm-pagewalk-fix-stale-walk-action-escaping-walk.patch
+  (bsc#1012628 CVE-2026-89754 bsc#1280769).
+- Update
+  
patches.kernel.org/7.2.4-069-mm-vmscan-report-RCU-tasks-quiescent-states-in-.patch
+  (bsc#1012628 CVE-2026-89753 bsc#1281178).
+- Update
+  
patches.kernel.org/7.2.4-074-mm-memcg-stop-reclaim-when-a-limit-update-is-su.patch
+  (bsc#1012628 CVE-2026-89752 bsc#1281176).
+- Update
+  
patches.kernel.org/7.2.4-084-x86-tdx-Fix-off-by-one-in-port-I-O-handling.patch
+  (bsc#1012628 CVE-2026-89751 bsc#1280822).
+- Update
+  
patches.kernel.org/7.2.4-088-tracing-user_events-Clear-copied-tracing-state-.patch
+  (bsc#1012628 CVE-2026-89750 bsc#1281172).
+- Update
+  
patches.kernel.org/7.2.4-089-tracing-Fix-crash-passing-ERR_PTR-to-kthread_st.patch
+  (bsc#1012628 CVE-2026-89749 bsc#1281166).
+- Update
+  
patches.kernel.org/7.2.4-091-tracing-Fix-retry-exhaustion-in-simple-ring-buf.patch
+  (bsc#1012628 CVE-2026-89748 bsc#1281024).
+- Update
+  
patches.kernel.org/7.2.4-092-tracing-Fix-use-after-free-in-trace_pipe-read-o.patch
+  (bsc#1012628 CVE-2026-89747 bsc#1281025).
+- Update
+  
patches.kernel.org/7.2.4-093-tracing-Fix-use-after-free-with-same-name-named.patch
+  (bsc#1012628 CVE-2026-89746 bsc#1281026).
+- Update
+  
patches.kernel.org/7.2.4-095-debugfs-Fix-lockdown-check-for-mmap_prepare.patch
+  (bsc#1012628 CVE-2026-89745 bsc#1281209).
+- Update
+  
patches.kernel.org/7.2.4-096-device-property-fix-infinite-loop-in-fwnode_for.patch
+  (bsc#1012628 CVE-2026-89744 bsc#1281029).
+- Update
+  
patches.kernel.org/7.2.4-097-misc-nsm-bound-the-device-reported-response-len.patch
+  (bsc#1012628 CVE-2026-89743 bsc#1281028).
+- Update
+  
patches.kernel.org/7.2.4-099-rapidio-mport_cdev-fix-use-after-free-in-dma_re.patch
+  (bsc#1012628 CVE-2026-89742 bsc#1281027).
+- Update
+  
patches.kernel.org/7.2.4-100-Revert-media-v4l2-dev-fix-error-handling-in-__v.patch
+  (bsc#1012628 CVE-2026-89741 bsc#1281030).
+- Update
+  
patches.kernel.org/7.2.4-101-serial-imx-serialize-imx_uart_ports-lifetime.patch
+  (bsc#1012628 CVE-2026-89740 bsc#1281032).
+- Update
+  
patches.kernel.org/7.2.4-104-usb-dwc3-gadget-Fix-use-after-free-in-dwc3_gadg.patch
+  (bsc#1012628 CVE-2026-89739 bsc#1281191).
+- Update
+  
patches.kernel.org/7.2.4-105-usb-gadget-at91_udc-drain-polled-VBUS-timer-wor.patch
+  (bsc#1012628 CVE-2026-89738 bsc#1280526).
+- Update
+  
patches.kernel.org/7.2.4-109-usb-typec-thunderbolt-Disable-work-before-freei.patch
+  (bsc#1012628 CVE-2026-89737 bsc#1280528).
+- Update
+  
patches.kernel.org/7.2.4-111-usb-gadget-u_audio-Fix-use-after-free-on-sound-.patch
+  (bsc#1012628 CVE-2026-89736 bsc#1281130).
+- Update
+  
patches.kernel.org/7.2.4-113-usb-gadget-midi2-remove-default-configfs-groups.patch
+  (bsc#1012628 CVE-2026-89735 bsc#1281013).
+- Update
+  
patches.kernel.org/7.2.4-115-usb-gadget-uvc-Fix-null-pointer-dereference-in-.patch
+  (bsc#1012628 CVE-2026-89734 bsc#1280529).
+- Update
+  
patches.kernel.org/7.2.4-116-usb-gadget-uvc-fix-dangling-pointers-in-uvc_fun.patch
+  (bsc#1012628 CVE-2026-89733 bsc#1281008).
+- Update
+  
patches.kernel.org/7.2.4-117-usb-gadget-f_fs-Prevent-deadlock-during-ep0-rea.patch
+  (bsc#1012628 CVE-2026-89732 bsc#1280505).
+- Update
+  
patches.kernel.org/7.2.4-118-cxl-ras-Fix-cxl_rch_get_aer_info-out-of-bounds-.patch
+  (bsc#1012628 CVE-2026-89731 bsc#1281031).
+- Update
+  
patches.kernel.org/7.2.4-119-fpga-altera-cvp-Avoid-out-of-bounds-read-in-tra.patch
+  (bsc#1012628 CVE-2026-89730 bsc#1281034).
+- Update
+  
patches.kernel.org/7.2.4-120-HID-sensor-hub-Fix-out-of-bounds-write-in-senso.patch
+  (bsc#1012628 CVE-2026-89729 bsc#1280785).
+- Update
+  
patches.kernel.org/7.2.4-121-i3c-renesas-Fix-out-of-bounds-access-for-newdev.patch
+  (bsc#1012628 CVE-2026-89728 bsc#1280796).
+- Update
+  
patches.kernel.org/7.2.4-122-KVM-arm64-GICv2-Don-t-WARN-on-out-of-range-GICV.patch
+  (bsc#1012628 CVE-2026-89727 bsc#1280506).
+- Update
+  
patches.kernel.org/7.2.4-123-lib-ucs2_string.c-fix-out-of-bounds-read-in-ucs.patch
+  (bsc#1012628 CVE-2026-89726 bsc#1281058).
+- Update
+  
patches.kernel.org/7.2.4-124-media-cec-stm32-prevent-out-of-bounds-write-on-.patch
+  (bsc#1012628 CVE-2026-89725 bsc#1280777).
+- Update
+  
patches.kernel.org/7.2.4-125-media-vicodec-fix-out-of-bounds-write-in-FWHT-e.patch
+  (bsc#1012628 CVE-2026-89724 bsc#1280813).
+- Update
+  
patches.kernel.org/7.2.4-126-nilfs2-fix-slab-out-of-bounds-in-nilfs_direct_p.patch
+  (bsc#1012628 CVE-2026-89723 bsc#1280815).
+- Update
+  
patches.kernel.org/7.2.4-128-PCI-sysfs-Fix-out-of-bounds-read-in-pci_write_l.patch
+  (bsc#1012628 CVE-2026-89722 bsc#1280535).
+- Update
+  
patches.kernel.org/7.2.4-129-phy-rockchip-samsung-dcphy-fix-out-of-range-max.patch
+  (bsc#1012628 CVE-2026-89721 bsc#1280808).
+- Update
+  
patches.kernel.org/7.2.4-130-ubifs-fix-out-of-bounds-read-in-signature-lengt.patch
+  (bsc#1012628 CVE-2026-89720 bsc#1280533).
+- Update
+  
patches.kernel.org/7.2.4-131-zram-fix-out-of-bounds-access-in-read_block_sta.patch
+  (bsc#1012628 CVE-2026-89719 bsc#1280838).
+- Update
+  
patches.kernel.org/7.2.4-132-zram-fix-out-of-bounds-access-in-writeback_stor.patch
+  (bsc#1012628 CVE-2026-89718 bsc#1280823).
+- Update
+  
patches.kernel.org/7.2.4-133-zram-set-default-primary-compressor-in-zram_des.patch
+  (bsc#1012628 CVE-2026-89717 bsc#1280824).
+- Update
+  patches.kernel.org/7.2.4-134-zram-validate-deflate-params.patch
+  (bsc#1012628 CVE-2026-89716 bsc#1280825).
+- Update
+  
patches.kernel.org/7.2.4-136-NFS-localio-fix-ref-leak-on-nfs_uuid_add_file-f.patch
+  (bsc#1012628 CVE-2026-89715 bsc#1280833).
+- Update
+  
patches.kernel.org/7.2.4-137-NFS-fix-delegation_hash_table-leak-when-nfs4_se.patch
+  (bsc#1012628 CVE-2026-89714 bsc#1280828).
+- Update
+  
patches.kernel.org/7.2.4-138-NFSD-check-truncate-permission-under-inode-lock.patch
+  (bsc#1012628 CVE-2026-89713 bsc#1280872).
+- Update
+  
patches.kernel.org/7.2.4-142-NFSD-restart-ssc_expire_umount-walk-after-dropp.patch
+  (bsc#1012628 CVE-2026-89712 bsc#1280870).
+- Update
+  
patches.kernel.org/7.2.4-143-NFSD-remove-flawed-WARN_ON_ONCE-from-nfsd_mode_.patch
+  (bsc#1012628 CVE-2026-89711 bsc#1281035).
+- Update
+  
patches.kernel.org/7.2.4-145-NFSv4.1-fix-layout-segment-leak-on-the-pnfs_lay.patch
+  (bsc#1012628 CVE-2026-89710 bsc#1280455).
+- Update
+  patches.kernel.org/7.2.4-147-lockd-nfsd-RCU-protect-nlmsvc_ops-dispatch.patch
+  (bsc#1012628 CVE-2026-89709 bsc#1281158).
+- Update
+  
patches.kernel.org/7.2.4-148-nfsd-RCU-protect-cl_cb_session-to-fix-use-after.patch
+  (bsc#1012628 CVE-2026-89708 bsc#1280448).
+- Update
+  
patches.kernel.org/7.2.4-149-nfsd-release-path-refs-on-follow_down-error.patch
+  (bsc#1012628 CVE-2026-89707 bsc#1280468).
+- Update
+  
patches.kernel.org/7.2.4-150-nfsd-Reset-write-verifier-when-async-COPY-write.patch
+  (bsc#1012628 CVE-2026-89706 bsc#1280477).
+- Update
+  
patches.kernel.org/7.2.4-151-nfsd-restore-rq_status_counter-to-even-on-all-n.patch
+  (bsc#1012628 CVE-2026-89705 bsc#1280464).
+- Update
+  
patches.kernel.org/7.2.4-153-nfsd-sample-writeback-error-cursor-before-async.patch
+  (bsc#1012628 CVE-2026-89704 bsc#1280490).
+- Update
+  
patches.kernel.org/7.2.4-154-nfsd-set-SC_STATUS_FREED-in-nfsd4_drop_revoked_.patch
+  (bsc#1012628 CVE-2026-89703 bsc#1280488).
+- Update
+  
patches.kernel.org/7.2.4-155-nfsd-size-fh_verify-server-sockaddr-slot-by-xpt.patch
+  (bsc#1012628 CVE-2026-89702 bsc#1280487).
+- Update
+  
patches.kernel.org/7.2.4-156-nfsd-validate-nseconds-in-TIME_DELEG-decode-pat.patch
+  (bsc#1012628 CVE-2026-89701 bsc#1280495).
+- Update
+  
patches.kernel.org/7.2.4-157-nfsd-validate-sockaddr-length-per-family-in-lis.patch
+  (bsc#1012628 CVE-2026-89700 bsc#1280497).
+- Update
+  
patches.kernel.org/7.2.4-158-nfsd-validate-symlink-target-length-in-NFSv4-CR.patch
+  (bsc#1012628 CVE-2026-89699 bsc#1281077).
+- Update
+  
patches.kernel.org/7.2.4-159-nfsd-widen-nfsd_genl_rqstp-address-fields-to-so.patch
+  (bsc#1012628 CVE-2026-89698 bsc#1280494).
+- Update
+  
patches.kernel.org/7.2.4-202-nfsd-reject-out-of-range-nseconds-in-NFSv3-SETA.patch
+  (bsc#1012628 CVE-2026-89666 bsc#1281074).
+- Update
+  
patches.kernel.org/7.2.4-203-nfsd-reject-out-of-range-useconds-in-NFSv2-SETA.patch
+  (bsc#1012628 CVE-2026-89665 bsc#1281057).
+- Update
+  
patches.kernel.org/7.2.4-206-nfsd-revoke-copy-notify-stateids-before-droppin.patch
+  (bsc#1012628 CVE-2026-89663 bsc#1280518).
+- Update
+  
patches.kernel.org/7.2.4-207-NFSD-Prevent-lock-owner-use-after-free-during-c.patch
+  (bsc#1012628 CVE-2026-89662 bsc#1280509).
+- Update
+  
patches.kernel.org/7.2.4-208-NFSD-Prevent-post-shutdown-use-after-free-in-un.patch
+  (bsc#1012628 CVE-2026-89661 bsc#1280532).
+- Update
+  
patches.kernel.org/7.2.4-209-NFSD-Prevent-client-use-after-free-during-admin.patch
+  (bsc#1012628 CVE-2026-89660 bsc#1280525).
+- Update
+  
patches.kernel.org/7.2.4-210-NFSD-Prevent-client-use-after-free-during-deleg.patch
+  (bsc#1012628 CVE-2026-89659 bsc#1280527).
+- Update
+  
patches.kernel.org/7.2.4-211-NFSD-Prevent-client-use-after-free-during-NFSv4.patch
+  (bsc#1012628 CVE-2026-89658 bsc#1280576).
+- Update
+  
patches.kernel.org/7.2.4-213-libceph-validate-OSD-extent-maps-before-cursor-.patch
+  (bsc#1012628 CVE-2026-89657 bsc#1280545).
+- Update
+  
patches.kernel.org/7.2.4-214-libceph-reject-buckets-with-mismatched-CRUSH-id.patch
+  (bsc#1012628 CVE-2026-89656 bsc#1280563).
+- Update
+  
patches.kernel.org/7.2.4-215-ceph-fix-UAF-in-__kick_flushing_caps-on-cf-entr.patch
+  (bsc#1012628 CVE-2026-89655 bsc#1280398).
+- Update
+  
patches.kernel.org/7.2.4-216-ceph-fix-UAF-in-check_new_map-on-session-freed-.patch
+  (bsc#1012628 CVE-2026-89654 bsc#1280415).
+- Update
+  
patches.kernel.org/7.2.4-218-ceph-reject-export_targets-ranks-CEPH_MAX_MDS-i.patch
+  (bsc#1012628 CVE-2026-89653 bsc#1280401).
+- Update
+  
patches.kernel.org/7.2.4-219-ceph-bound-copied-dentry-name-length-in-NFS-exp.patch
+  (bsc#1012628 CVE-2026-89652 bsc#1280419).
+- Update
+  
patches.kernel.org/7.2.4-220-ceph-bound-MDSCapAuth-path-and-fs_name-decode-i.patch
+  (bsc#1012628 CVE-2026-89651 bsc#1280418).
+- Update
+  
patches.kernel.org/7.2.4-221-ceph-bound-num_export_targets-array-for-mds-inf.patch
+  (bsc#1012628 CVE-2026-89650 bsc#1280417).
+- Update
+  
patches.kernel.org/7.2.4-222-ceph-bound-xattr-value-length-in-__build_xattrs.patch
+  (bsc#1012628 CVE-2026-89649 bsc#1280434).
+- Update
+  
patches.kernel.org/7.2.4-223-ceph-cap-delegated-inode-count-in-ceph_parse_de.patch
+  (bsc#1012628 CVE-2026-89648 bsc#1280427).
+- Update
+  
patches.kernel.org/7.2.4-224-ceph-do-not-repeat-ceph_trim_dentries-if-no-pro.patch
+  (bsc#1012628 CVE-2026-89647 bsc#1280422).
+- Update
+  
patches.kernel.org/7.2.4-225-ceph-fix-leaked-inode-reference-on-writeback-ab.patch
+  (bsc#1012628 CVE-2026-89646 bsc#1280491).
+- Update
+  
patches.kernel.org/7.2.4-226-btrfs-drop-recovered-reloc-root-refs-on-recover.patch
+  (bsc#1012628 CVE-2026-89645 bsc#1281055).
+- Update
+  
patches.kernel.org/7.2.4-227-btrfs-fix-extent-map-leak-in-NOCOW-direct-I-O-w.patch
+  (bsc#1012628 CVE-2026-89644 bsc#1281054).
+- Update
++++ 3765 more lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes
++++ and 
/work/SRC/openSUSE:Factory/.kernel-source.new.383539/dtb-aarch64.changes
dtb-armv6l.changes: same change
dtb-armv7l.changes: same change
dtb-riscv64.changes: same change
kernel-64kb.changes: same change
kernel-default.changes: same change
kernel-docs.changes: same change
kernel-kvmsmall.changes: same change
kernel-lpae.changes: same change
kernel-obs-build.changes: same change
kernel-obs-qa.changes: same change
kernel-pae.changes: same change
kernel-source.changes: same change
kernel-syms.changes: same change
kernel-vanilla.changes: same change
kernel-zfcpdump.changes: same change

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ dtb-aarch64.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.505325970 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.507326054 +0200
@@ -17,7 +17,7 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
+%define patchversion 7.2.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -25,9 +25,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           dtb-aarch64
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

dtb-armv6l.spec: same change
dtb-armv7l.spec: same change
dtb-riscv64.spec: same change
++++++ kernel-64kb.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.626331064 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.628331148 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-64kb
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

kernel-default.spec: same change
++++++ kernel-docs.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.690333758 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.692333842 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define build_html 1
 %define build_pdf 0
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-docs
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

++++++ kernel-kvmsmall.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.718334937 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.720335021 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-kvmsmall
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

kernel-lpae.spec: same change
++++++ kernel-obs-build.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.771337168 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.773337252 +0200
@@ -19,7 +19,7 @@
 
 #!BuildIgnore: post-build-checks
 
-%define patchversion 7.2.6
+%define patchversion 7.2.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
@@ -38,23 +38,23 @@
 %endif
 %endif
 %endif
-%global kernel_package 
kernel%kernel_flavor-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%global kernel_package 
kernel%kernel_flavor-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559
 %endif
 %if 0%{?rhel_version}
 %global kernel_package kernel
 %endif
 
 Name:           kernel-obs-build
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif
 Summary:        package kernel and initrd for OBS VM builds
 License:        GPL-2.0-only
 Group:          SLES
-Provides:       
kernel-obs-build-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb
+Provides:       
kernel-obs-build-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559
 BuildRequires:  coreutils
 BuildRequires:  device-mapper
 BuildRequires:  dracut

++++++ kernel-obs-qa.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.798338304 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.799338347 +0200
@@ -17,15 +17,15 @@
 # needsrootforbuild
 
 
-%define patchversion 7.2.6
+%define patchversion 7.2.7
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-obs-qa
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif
@@ -36,7 +36,7 @@
 # kernel-obs-build must be also configured as VMinstall, but is required
 # here as well to avoid that qa and build package build parallel
 %if ! 0%{?qemu_user_space_build}
-BuildRequires:  
kernel-obs-build-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb
+BuildRequires:  
kernel-obs-build-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559
 %endif
 BuildRequires:  modutils
 ExclusiveArch:  aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64

++++++ kernel-pae.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.828339567 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.830339652 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-pae
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

++++++ kernel-source.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.855340704 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.856340746 +0200
@@ -17,8 +17,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define gcc_package gcc
 %define gcc_compiler gcc
@@ -28,9 +28,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-source
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

++++++ kernel-syms.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.892342262 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.894342346 +0200
@@ -16,15 +16,15 @@
 #
 
 
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 
 %include %_sourcedir/kernel-spec-macros
 
 Name:           kernel-syms
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

++++++ kernel-vanilla.spec ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:18.918343356 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:18.920343440 +0200
@@ -18,8 +18,8 @@
 
 
 %define srcversion 7.2
-%define patchversion 7.2.6
-%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+%define patchversion 7.2.7
+%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559
 %define variant %{nil}
 %define compress_modules zstd
 %define compress_vmlinux xz
@@ -40,9 +40,9 @@
 %(chmod +x 
%_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build})
 
 Name:           kernel-vanilla
-Version:        7.2.6
+Version:        7.2.7
 %if 0%{?is_kotd}
-Release:        <RELEASE>.g3d19f11
+Release:        <RELEASE>.ge601a2d
 %else
 Release:        0
 %endif

kernel-zfcpdump.spec: same change
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:19.078350092 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:19.081350218 +0200
@@ -1,6 +1,6 @@
-mtime: 1789455114
-commit: ebd4b6e3758e082507f7bdd81cd3012c90dbc1f65aec2894935933073aa48022
+mtime: 1790064153
+commit: ec88da9a4fb5f106bf4253160361208d003345bec30e583bfa0aa6d6364dfab3
 url: https://src.opensuse.org/jirislaby/kernel-source
-revision: ebd4b6e3758e082507f7bdd81cd3012c90dbc1f65aec2894935933073aa48022
+revision: ec88da9a4fb5f106bf4253160361208d003345bec30e583bfa0aa6d6364dfab3
 trackingbranch: Kernel/stable
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-22 10:02:33.000000000 +0200
@@ -0,0 +1 @@
+.osc




++++++ patches.kernel.org.tar.bz2 ++++++
++++ 84331 lines of diff (skipped)

++++++ patches.suse.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch 
new/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch
--- old/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch     
2026-09-15 08:50:07.000000000 +0200
+++ new/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch     
1970-01-01 01:00:00.000000000 +0100
@@ -1,38 +0,0 @@
-From: Matthias Brugger <[email protected]>
-Date: Sat, 9 Jan 2021 02:38:10 +0100
-Subject: regulator: mt6360: Add OF match table
-Patch-mainline: Submitted, [email protected]
-References: bsc#1180731
-
-Binding documentation mentions that a compatible is required for the
-MT6360 device node, but the driver doesn't provide a OF match table.
-
-Fixes: d321571d5e4c ("regulator: mt6360: Add support for MT6360 regulator")
-Signed-off-by: Matthias Brugger <[email protected]>
-
----
- drivers/regulator/mt6360-regulator.c | 9 +++++++++
- 1 file changed, 9 insertions(+)
-
---- a/drivers/regulator/mt6360-regulator.c
-+++ b/drivers/regulator/mt6360-regulator.c
-@@ -443,10 +443,19 @@ static const struct platform_device_id 
mt6360_regulator_id_table[] = {
- };
- MODULE_DEVICE_TABLE(platform, mt6360_regulator_id_table);
- 
-+#ifdef CONFIG_OF
-+static const struct of_device_id mt6360_of_match[] = {
-+      { .compatible = "mediatek,mt6360-regulator", },
-+      { /* sentinel */ },
-+};
-+MODULE_DEVICE_TABLE(of, mt6360_of_match);
-+#endif
-+
- static struct platform_driver mt6360_regulator_driver = {
-       .driver = {
-               .name = "mt6360-regulator",
-               .probe_type = PROBE_PREFER_ASYNCHRONOUS,
-+              .of_match_table = of_match_ptr(mt6360_of_match),
-       },
-       .probe = mt6360_regulator_probe,
-       .id_table = mt6360_regulator_id_table,
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch 
new/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch
--- old/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch     
2026-09-15 08:50:07.000000000 +0200
+++ new/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch     
1970-01-01 01:00:00.000000000 +0100
@@ -1,40 +0,0 @@
-From: Matthias Brugger <[email protected]>
-Date: Sat, 9 Jan 2021 02:41:09 +0100
-Subject: regulator: mt6358: Add OF match table
-Patch-mainline: Submitted, [email protected]
-References: bsc#1180731
-
-The binding documentation mentions that a compatible is required for the
-MT6358 device node. But the driver does not provide a OF match table.
-This way auto-loading is broken as the MFD driver that registers the
-device has a .of_compatible set which makes the platform .uevent
-callback report a OF modalias, but that's not in the module.
-
-Fixes: f67ff1bd58f0 ("regulator: mt6358: Add support for MT6358 regulator")
-Signed-off-by: Matthias Brugger <[email protected]>
----
- drivers/regulator/mt6358-regulator.c | 9 +++++++++
- 1 file changed, 9 insertions(+)
-
---- a/drivers/regulator/mt6358-regulator.c
-+++ b/drivers/regulator/mt6358-regulator.c
-@@ -730,10 +730,19 @@ static const struct platform_device_id 
mt6358_platform_ids[] = {
- };
- MODULE_DEVICE_TABLE(platform, mt6358_platform_ids);
- 
-+#ifdef CONFIG_OF
-+static const struct of_device_id mt6358_of_match[] = {
-+      { .compatible = "mediatek,mt6358-regulator", },
-+      { /* sentinel */ },
-+};
-+MODULE_DEVICE_TABLE(of, mt6358_of_match);
-+#endif
-+
- static struct platform_driver mt6358_regulator_driver = {
-       .driver = {
-               .name = "mt6358-regulator",
-               .probe_type = PROBE_PREFER_ASYNCHRONOUS,
-+              .of_match_table = of_match_ptr(mt6358_of_match),
-       },
-       .probe = mt6358_regulator_probe,
-       .id_table = mt6358_platform_ids,
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch 
new/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch
--- old/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch     
2026-09-15 08:50:07.000000000 +0200
+++ new/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch     
1970-01-01 01:00:00.000000000 +0100
@@ -1,40 +0,0 @@
-From: Matthias Brugger <[email protected]>
-Date: Sat, 9 Jan 2021 02:45:45 +0100
-Subject: regulator: mt6323: Add OF match table
-Patch-mainline: Submitted, [email protected]
-References: bsc#1180731
-
-The binding documentation mentions that a compatible is required for the
-MT6323 device node. But the driver does not provide a OF match table.
-This way auto-loading is broken as the MFD driver that registers the
-device has a .of_compatible set which makes the platform .uevent
-callback report a OF modalias, but that's not in the module.
-
-Fixes: 2fdf82923618 ("regulator: mt6323: Add support for MT6323 regulator")
-Signed-off-by: Matthias Brugger <[email protected]>
----
- drivers/regulator/mt6323-regulator.c | 9 +++++++++
- 1 file changed, 9 insertions(+)
-
---- a/drivers/regulator/mt6323-regulator.c
-+++ b/drivers/regulator/mt6323-regulator.c
-@@ -406,10 +406,19 @@ static const struct platform_device_id 
mt6323_platform_ids[] = {
- };
- MODULE_DEVICE_TABLE(platform, mt6323_platform_ids);
- 
-+#ifdef CONFIG_OF
-+static const struct of_device_id mt6323_of_match[] = {
-+      { .compatible = "mediatek,mt6323-regulator", },
-+      { /* sentinel */ },
-+};
-+MODULE_DEVICE_TABLE(of, mt6323_of_match);
-+#endif
-+
- static struct platform_driver mt6323_regulator_driver = {
-       .driver = {
-               .name = "mt6323-regulator",
-               .probe_type = PROBE_PREFER_ASYNCHRONOUS,
-+              .of_match_table = of_match_ptr(mt6323_of_match),
-       },
-       .probe = mt6323_regulator_probe,
-       .id_table = mt6323_platform_ids,
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch 
new/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch
--- 
old/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch    
    1970-01-01 01:00:00.000000000 +0100
+++ 
new/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch    
    2026-09-22 08:44:29.000000000 +0200
@@ -0,0 +1,57 @@
+From: Sasha Levin <[email protected]>
+Date: Sun, 13 Sep 2026 13:31:32 -0400
+Subject: ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
+Git-commit: 11fc0048a6930f4fca44fe3bd16a0023e78846a2
+Patch-mainline: v7.3-rc4
+References: git-fixes
+
+arm allmodconfig fails to build with gcc:
+
+  In file included from sound/soc/ux500/ux500_msp_i2s.c:20:
+  sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses
+  around arithmetic in operand of '^' [-Werror=parentheses]
+  sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro
+  'MSP_TX_CLKPOL_BIT'
+  cc1: all warnings being treated as errors
+
+The macros never parenthesized their argument:
+
+  #define MSP_TX_CLKPOL_BIT(n)  ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
+
+That went unnoticed while every caller passed a plain variable, but
+configure_protocol() now passes an XOR expression, which binds as
+"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly
+complains.
+
+No functional change: tx_clk_pol and rx_clk_pol only ever hold
+MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a
+bool, so masking before or after the XOR gives the same 0/1 result.
+Parenthesize the argument anyway - it fixes the build and stops the
+macros from silently mis-evaluating a future composite argument.
+
+Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration")
+Reported-by: kernel test robot <[email protected]>
+Closes: 
https://lore.kernel.org/oe-kbuild-all/[email protected]/
+Assisted-by: LLM
+Signed-off-by: Sasha Levin <[email protected]>
+Reviewed-by: Linus Walleij <[email protected]>
+Link: https://patch.msgid.link/[email protected]
+Signed-off-by: Mark Brown <[email protected]>
+Acked-by: Jiri Slaby <[email protected]>
+---
+ sound/soc/ux500/ux500_msp_i2s.h |    4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+--- a/sound/soc/ux500/ux500_msp_i2s.h
++++ b/sound/soc/ux500/ux500_msp_i2s.h
+@@ -147,8 +147,8 @@ enum msp_direction {
+ #define RCKPOL_MASK           BIT(0)
+ #define TCKPOL_MASK           BIT(0)
+ #define SPICKM_MASK           (BIT(1) | BIT(0))
+-#define MSP_RX_CLKPOL_BIT(n)     ((n & RCKPOL_MASK) << RCKPOL_SHIFT)
+-#define MSP_TX_CLKPOL_BIT(n)     ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
++#define MSP_RX_CLKPOL_BIT(n)     (((n) & RCKPOL_MASK) << RCKPOL_SHIFT)
++#define MSP_TX_CLKPOL_BIT(n)     (((n) & TCKPOL_MASK) << TCKPOL_SHIFT)
+ 
+ #define P1ELEN_SHIFT          0
+ #define P1FLEN_SHIFT          3
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
 
new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
--- 
old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
        2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch
        1970-01-01 01:00:00.000000000 +0100
@@ -1,116 +0,0 @@
-From: "Ritesh Harjani (IBM)" <[email protected]>
-Date: Sun, 30 Aug 2026 20:24:30 +0530
-Subject: powerpc: Do not restore KUAP in arch_exit_to_user_mode_prepare()
-References: bsc#1277802 ltc#222379
-Git-commit: c2549d749539487239475fbc8c614a1f9244d655
-Patch-mainline: v7.3 or v7.3-rc3 (next release)
-
-KUAP means kernel cannot touch user memory unless it explicitly is
-enabled. In the kernel it should stay AMR_KUAP_BLOCKED. While returning
-to userspace just before RFI, kernel should restore the user AMR value
-back.
-
-Looks like GENERIC_ENTRY might be treating arch_exit_to_user_mode_prepare()
-as the last architecture step before returning to userspace.
-commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
-therefore called kuap_user_restore() from that hook. But on PowerPC that
-is too early. After irqentry_exit() / syscall_exit_to_user_mode() we
-still run platform specific exit routines.
-
-e.g. code snippets showing both exception handling and system call
-handling as the callers of function arch_exit_to_user_mode_prepare()
-which does kuap_user_restore(). The below path shows that calling
-kuap_user_restore() is too early when called from
-arch_exit_to_user_mode_prepare().
-
-Exception handling in exceptions-64s.S
-=======================================
-
-bl     CFUNC(do_page_fault)
-         ..DEFINE_INTERRUPT_HANDLER_ASYNC(do_page_fault)
-             arch_interrupt_async_enter_prepare(regs);
-             state = irqentry_enter(regs);
-             instrumentation_begin();
-             irq_enter_rcu();
-             handler(regs);
-             nap_adjust_return(regs);
-             irq_exit_rcu();
-             instrumentation_end();
-             arch_interrupt_async_exit_prepare(regs);
-             irqentry_exit(regs, state);                  <<< too early
-               irqentry_exit_to_user_mode()
-                 __exit_to_user_mode_prepare(regs, EXIT_TO_USER_MODE_WORK_IRQ);
-                   arch_exit_to_user_mode_prepare(regs, ti_work);  <<< too 
early
-b      interrupt_return_srr
-               .. bl   CFUNC(interrupt_exit_user_prepare) <<< already calls 
kuap_user_restore
-
-prep_irq_for_enabled_exit() retry can run kernel code with IRQs on. So
-only when that routine is fully finished is when the user KUAP should be
-fully restored which interrupt_exit_user_prepare() already takes care of
-before returning.
-
-Similarly for system call handling in interrupt_64.S
-======================================================
-
-       bl      CFUNC(system_call_exception)
-
-.Lsyscall_exit:
-       addi    r4,r1,STACK_INT_FRAME_REGS
-       li      r5,0 /* !scv */
-       bl      CFUNC(syscall_exit_prepare)
-                 .. kuap_assert_locked();
-                    syscall_exit_to_user_mode(regs); <<< too early
-                      syscall_exit_to_user_mode_prepare(regs);  <<< too early
-                    kuap_user_restore(regs);         <<< already calls
-
-syscall_exit_prepare(), which can enable IRQs, replay a pending
-interrupt, and only then rfi. Those functions already restore KUAP
-immediately before rfi.
-
-Note that if we restore the user AMR too early like in the current code
-as shown from the code snippets above, then we get the following warning
-when CONFIG_PPC_KUAP_DEBUG is enabled:
-  WARNING: arch/powerpc/include/asm/book3s/64/kup.h:293 at 
interrupt_exit_user_prepare+0x1a0/0x1c0
-  Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected)
-  TRAP: 0700
-  LR: c00000000000d8d4 CTR: c0000000021fe500
-  MSR: <SF,EE,ME,IR,DR,RI,LE>  CR: 44000804  XER: 20040000
-  interrupt_exit_user_prepare+0x1a0/0x1c0
-  interrupt_return_srr_user+0x8/0x12c
-
-Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
-Fixes: 02565a782c1ee ("powerpc: Introduce syscall exit arch functions")
-Signed-off-by: Ritesh Harjani (IBM) <[email protected]>
-Tested-by: Venkat Rao Bagalkote <[email protected]>
-Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
-Signed-off-by: Madhavan Srinivasan <[email protected]>
-Link: 
https://patch.msgid.link/52fee44fd23acf8e1c024ace668728e626a783a8.1788101609.git.ritesh.l...@gmail.com
-Acked-by: Michal Suchanek <[email protected]>
----
- arch/powerpc/include/asm/entry-common.h | 10 ++++++++--
- 1 file changed, 8 insertions(+), 2 deletions(-)
-
-diff --git a/arch/powerpc/include/asm/entry-common.h 
b/arch/powerpc/include/asm/entry-common.h
-index c5adb5006361..94083516df57 100644
---- a/arch/powerpc/include/asm/entry-common.h
-+++ b/arch/powerpc/include/asm/entry-common.h
-@@ -515,8 +515,14 @@ static inline void arch_exit_to_user_mode_prepare(struct 
pt_regs *regs,
- #ifdef CONFIG_PPC_TRANSACTIONAL_MEM
-       local_paca->tm_scratch = regs->msr;
- #endif
--      /* Restore user access locks last */
--      kuap_user_restore(regs);
-+      /*
-+       * Do not restore KUAP here. Generic entry might treat this as the last
-+       * arch step before userspace but PowerPC still has kernel work after
-+       * irqentry_exit()/syscall_exit_to_user_mode() i.e. in
-+       * interrupt_exit_user_prepare() / syscall_exit_prepare() may enable
-+       * IRQs and retry. Those functions restore KUAP immediately before rfi,
-+       * which is where it should belong.
-+       */
- }
- 
- #define arch_exit_to_user_mode_prepare arch_exit_to_user_mode_prepare
--- 
-2.55.0
-
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 
new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch
--- 
old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch    
    2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch    
    1970-01-01 01:00:00.000000000 +0100
@@ -1,101 +0,0 @@
-From: "Ritesh Harjani (IBM)" <[email protected]>
-Date: Sat, 29 Aug 2026 09:49:00 +0530
-Subject: powerpc: Don't drop _TIF_RESTOREALL on syscall restart
-References: bsc#1277802 ltc#222379
-Git-commit: c7585b8e99ad97a0f5dd21e45c90a33aeab0d92b
-Patch-mainline: v7.3 or v7.3-rc3 (next release)
-
-So the syscall return sequence is as follows:
-A syscall return to userspace is prepared and then a short asm sequence
-that actually does the RFI. Note that this asm range is restartable i.e.
-EE is still on, so an interrupt (e.g. decrementer or external interrupt)
-can hit while SRR/GPRs are being loaded. This is defined via:
-
-RESTART_TABLE(.Lsyscall_rst_start, .Lsyscall_rst_end, syscall_restart)
-
-This restart table then sends us to syscall_restart rather than resuming
-in the middle of the RFI. The same stub is also used if irq_happened
-already has a pending bit (soft-masked irq that has not been replayed
-yet (PowerPC special case of local_irq_disable())).
-
-Here is a bit of a flow of sequence of code to visualize:
-  syscall_exit_prepare
-      decide full-GPR restore (_TIF_RESTOREALL) for signal,
-      rt_sigreturn or syscall trace
-      save that in regs->exit_result and return it in r3
-           |
-           v
-  .Lsyscall_rst_start .. _end     EE still on
-      irq_happened set or interrupt in this range?
-           | no                         | yes
-           v                            v
-      cmpdi r3,0                  syscall_exit_restart
-      restore all / zero            replay irq, try exit again
-      volatiles; RFI                must return flags in r3
-                                    again for the same cmpdi
-
-Now r3 after prepare is the flags word, not the actual syscall return. A nested
-interrupt clobbers it, so the restart stub reloads RESULT into r3 and the
-C handler (syscall_exit_restart()) should put the flags back (because later asm
-checks whether r3 returned from C has _TIF_RESTOREALL set or not):
-       cmpdi r3, 0
-       bne     .Lsyscall_restore_regs
-
-Note that syscall_exit_restart() already ORs any new _TIF_RESTOREALL into
-exit_result, but then it only returns the new sample and not the full
-regs->exit_result.
-
-That sample could be often 0 even when restore-all is still required:
-
-  - rt_sigreturn / syscall trace set the bit in prepare's local
-    ret and in exit_result. They never set exit_flags, which is
-    what restart samples.
-
-  - a signal does set exit_flags but restart clears it. A
-    second pass through the stub then returns 0 while
-    exit_result still has the bit.
-
-The asm as mentioned earlier then treats r3==0 as the fast path and
-zeros r0/r4-r12. That means the userspace that needed the full register
-set could SIGSEGVs, (which could happen often in ld64.so.2 like while
-doing a parallel kernel build as reported by Venkat).
-
-So we should instead return the accumulated exit_result, like how we do
-in interrupt_exit_user_restart(). Note that prior to this commit
-263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace")
-we were returning regs->exit_result from syscall_exit_restart(), but
-this commit changed that behaviour.
-
-Fixes: 263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for 
ptrace")
-Reported-by: Venkat Rao Bagalkote <[email protected]>
-Closes: 
https://lore.kernel.org/all/[email protected]/
-Signed-off-by: Ritesh Harjani (IBM) <[email protected]>
-Tested-by: Amit Machhiwal <[email protected]>
-Tested-by: Shrikanth Hegde <[email protected]>
-Tested-by: Venkat Rao Bagalkote <[email protected]>
-Reviewed-by: Amit Machhiwal <[email protected]>
-Reviewed-by: Shrikanth Hegde <[email protected]>
-Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
-Signed-off-by: Madhavan Srinivasan <[email protected]>
-Link: 
https://patch.msgid.link/10c86c909f870d90b3094f76b692b44ebe9caeac.1787976185.git.ritesh.l...@gmail.com
-Acked-by: Michal Suchanek <[email protected]>
----
- arch/powerpc/kernel/interrupt.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/arch/powerpc/kernel/interrupt.c b/arch/powerpc/kernel/interrupt.c
-index 5b88bf72786c..55f9c0c9922a 100644
---- a/arch/powerpc/kernel/interrupt.c
-+++ b/arch/powerpc/kernel/interrupt.c
-@@ -175,7 +175,7 @@ notrace unsigned long syscall_exit_restart(unsigned long 
r3, struct pt_regs *reg
-       current_thread_info()->exit_flags &= ~_TIF_RESTOREALL;
-       regs->exit_result |= ret;
- 
--      return ret;
-+      return regs->exit_result;
- }
- #endif
- 
--- 
-2.55.0
-
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
 
new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
--- 
old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
  2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch
  1970-01-01 01:00:00.000000000 +0100
@@ -1,97 +0,0 @@
-From: Aboorva Devarajan <[email protected]>
-Date: Fri, 4 Sep 2026 08:28:30 +0530
-Subject: powerpc/entry: Fix double accounting of user time on interrupt entry
-Git-commit: 11ae2e1dc58304a48816fc8ca4afa8f2ef9d1bdf
-Patch-mainline: v7.3-rc3
-References: bsc#1277802 ltc#222379
-
-Since the switch to generic entry, an interrupt from user mode
-accounts user time twice: once in arch_interrupt_enter_prepare()
-and again in arch_enter_from_user_mode(), which irqentry_enter()
-invokes for the same interrupt:
-
-       arch_interrupt_enter_prepare()
-         account_cpu_user_entry()              /* first */
-       irqentry_enter()
-         arch_enter_from_user_mode()
-           account_cpu_user_entry()            /* second */
-
-The second call charges the same interval again, because
-account_cpu_user_entry() accumulates the time spent in user mode
-since the last return to user space.
-
-The two calls come from the GENERIC_ENTRY preparation series,
-where each step was a no-op on its own. Commit 09a9d3a8499d
-("powerpc: introduce arch_enter_from_user_mode") added the hook
-with the user-time accounting in it, but nothing called it yet.
-Commit 893082ac769b ("powerpc: Prepare for IRQ entry exit")
-copied interrupt_enter_prepare() verbatim into entry-common.h as
-arch_interrupt_enter_prepare(); that copy was equally unused, as
-handlers still called interrupt_enter_prepare().
-
-Commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
-made both live. On the syscall side it did the full conversion:
-system_call_exception() now accounts once through the hook via
-syscall_enter_from_user_mode(), rather than calling
-account_cpu_user_entry() directly. On the interrupt side it
-switched the handler macros to arch_interrupt_enter_prepare()
-followed by irqentry_enter(), which also runs the hook, but the
-accounting in arch_interrupt_enter_prepare() was not removed to
-match. The double accounting starts with that commit.
-
-With CONFIG_VIRT_CPU_ACCOUNTING_NATIVE=y this roughly doubles the
-reported user time of any workload that takes interrupts. The
-other accounting modes compile account_cpu_user_entry() to an
-empty stub, so they are not affected.
-
-Remove the accounting from arch_interrupt_enter_prepare() and rely
-on arch_enter_from_user_mode(), which already runs for both
-syscalls and interrupts. The duplicate account_stolen_time() call
-is removed the same way.
-
-On a pseries LPAR a busy loop reports 6s user time in 3s elapsed
-(~210% CPU) before the fix, and 3s (~105% CPU) after it:
-
-  $ python3 -c 'while True: pass' &
-  $ sleep 3; ps -p $! -o etime,time,pcpu
-
-            ELAPSED     TIME  %CPU
-  Before      00:03 00:00:06   210
-  After       00:03 00:00:03   105
-
-A 50% load reports ~70% usr / 30% idle before the fix, and
-~49% usr / 51% idle after it:
-
-  $ taskset -c 6 stress-ng --cpu 1 --cpu-load 50 &
-  $ mpstat -P 6 1
-
-            CPU    %usr   %idle
-  Before      6   69.74   30.26
-  After       6   48.51   50.50
-
-Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature")
-Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
-Signed-off-by: Aboorva Devarajan <[email protected]>
-Tested-by: Venkat Rao Bagalkote <[email protected]>
-Reviewed-by: Amit Machhiwal <[email protected]>
-Reviewed-by: Ritesh Harjani (IBM) <[email protected]>
-Reviewed-by: Christophe Leroy (CS GROUP) <[email protected]>
-Signed-off-by: Madhavan Srinivasan <[email protected]>
-Link: https://patch.msgid.link/[email protected]
-
-Acked-by: Michal Suchanek <[email protected]>
----
- arch/powerpc/include/asm/entry-common.h |    2 --
- 1 file changed, 2 deletions(-)
-
---- a/arch/powerpc/include/asm/entry-common.h
-+++ b/arch/powerpc/include/asm/entry-common.h
-@@ -222,8 +222,6 @@ static inline void arch_interrupt_enter_
- 
-       if (user_mode(regs)) {
-               kuap_lock();
--              account_cpu_user_entry();
--              account_stolen_time();
-       } else {
-               kuap_save_and_lock(regs);
-               /*
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
 
new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
--- 
old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
        2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch
        1970-01-01 01:00:00.000000000 +0100
@@ -1,99 +0,0 @@
-From: "Mukesh Kumar Chaurasiya (IBM)" <[email protected]>
-Date: Fri, 4 Sep 2026 14:38:58 +0530
-Subject: powerpc/entry: Fix irq_soft_mask corruption on replayed interrupt
- exit
-References: bsc#1277802 ltc#222379
-Git-commit: 63a7531ca31f9f097d9cc1cc3fe86ae683cdabdd
-Patch-mainline: v7.3 or v7.3-rc3 (next release)
-
-When __replay_soft_interrupts() replays a pending interrupt (e.g.
-PACA_IRQ_DEC -> timer_interrupt), it calls the handler directly with a
-synthetic pt_regs. The DEFINE_INTERRUPT_HANDLER_ASYNC wrapper around
-each handler calls arch_interrupt_async_exit_prepare() on the way out,
-which calls arch_interrupt_exit_prepare() -> local_irq_disable() ->
-arch_local_irq_disable(), which does:
-
-    irq_soft_mask_set(IRQS_DISABLED)   /* 0x1 */
-
-This unconditionally overwrites irq_soft_mask with IRQS_DISABLED (0x1),
-stripping the IRQS_PMI_DISABLED (0x2) bit. The result is that
-irq_soft_mask is 0x1 instead of IRQS_ALL_DISABLED (0x3) when the
-handler returns to __replay_soft_interrupts().
-
-For a normally-taken interrupt this is harmless: the next interrupt
-always enters through arch_interrupt_enter_prepare() which
-unconditionally sets irq_soft_mask to IRQS_ALL_DISABLED. But during
-replay, next_interrupt() is called directly between replayed handlers
-without going back through arch_interrupt_enter_prepare(), so the
-stripped bit is never restored. next_interrupt() then fires a WARNING:
-
-    WARNING: arch/powerpc/kernel/irq_64.c:75
-    WARN_ON(irq_soft_mask_return() != IRQS_ALL_DISABLED)
-
-The warning was observed early in boot on a POWER10 pseries guest
-during kmem_cache_init_late(), where a spinlock release triggers
-interrupt replay that processes a pending timer interrupt.
-
-Debugger state confirming the bug:
-  Before timer_interrupt(&regs):
-    irq_soft_mask = 0x3 (IRQS_ALL_DISABLED)   correct
-    irq_happened  = 0x41 (HARD_DIS|REPLAYING)  correct
-  After timer_interrupt(&regs) returns:
-    irq_soft_mask = 0x1 (IRQS_DISABLED)        WRONG - PMI bit stripped
-    irq_happened  = 0x41                        unchanged
-
-The fix is to replace local_irq_disable() with hard_irq_disable().
-
-hard_irq_disable() is the right primitive here for two reasons:
-
-1. On PPC64 (hw_irq.h:301) it calls 
irq_soft_mask_set_return(IRQS_ALL_DISABLED),
-   setting the soft mask to 0x3 (both IRQS_DISABLED and IRQS_PMI_DISABLED),
-   which preserves the PMI bit and fixes the WARNING. The additional
-   work it does (__hard_irq_disable(), PACA_IRQ_HARD_DIS |=) is
-   redundant but safe since both are already set at this point in the
-   exit path; the trace_hardirqs_off() inside is guarded by
-   if (!arch_irqs_disabled_flags(flags)) so it will not double-fire.
-
-2. On PPC32 (hw_irq.h:467) hard_irq_disable() maps to
-   arch_local_irq_disable() -> __hard_irq_disable(), which clears
-   MSR[EE] in hardware. This is exactly correct: PPC32 has no soft-mask
-   PACA mechanism, so the hardware disable is the right way to satisfy
-   irqentry_exit()'s requirement. This also fixes a build error on PPC32
-   where irq_soft_mask_set() is only defined under CONFIG_PPC64:
-
-       arch/powerpc/include/asm/entry-common.h:273: error: implicit
-       declaration of function 'irq_soft_mask_set'
-
-   Using hard_irq_disable() requires no #ifdef and is consistent with
-   how the rest of the entry code (e.g. entry-common.h:463) handles the
-   same PPC32/PPC64 split.
-
-Fixes: 334f3f6d7a16 ("powerpc/entry: Disable interrupts before irqentry_exit")
-Reported-by: Venkat Rao Bagalkote <[email protected]>
-Closes: 
https://lore.kernel.org/all/[email protected]/
-Tested-by: Venkat Rao Bagalkote <[email protected]>
-Reviewed-by: Shrikanth Hegde <[email protected]>
-Signed-off-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
-Signed-off-by: Madhavan Srinivasan <[email protected]>
-Link: https://patch.msgid.link/[email protected]
-Acked-by: Michal Suchanek <[email protected]>
----
- arch/powerpc/include/asm/entry-common.h | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/arch/powerpc/include/asm/entry-common.h 
b/arch/powerpc/include/asm/entry-common.h
-index 94083516df57..80b07750b531 100644
---- a/arch/powerpc/include/asm/entry-common.h
-+++ b/arch/powerpc/include/asm/entry-common.h
-@@ -270,7 +270,7 @@ static inline void arch_interrupt_exit_prepare(struct 
pt_regs *regs)
-       }
- 
-       /* irqentry_exit expects to be called with interrupts disabled */
--      local_irq_disable();
-+      hard_irq_disable();
- }
- 
- static inline void arch_interrupt_async_enter_prepare(struct pt_regs *regs)
--- 
-2.55.0
-
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
--- 
old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch
   1970-01-01 01:00:00.000000000 +0100
@@ -1,135 +0,0 @@
-From: Pedro Falcato <[email protected]>
-Date: Thu, 13 Aug 2026 12:01:26 +0300
-Subject: x86/alternative: Exclude text poking against change_page_attr()
-References: bsc#1271202
-Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
-Git-commit: e679ba0983757e9567aeda97cc35c99241d420ee
-Patch-mainline: Queued in subsystem maintainer repository
-
->From time to time, the following BUG can be observed[0]:
-
-> kernel BUG at arch/x86/kernel/alternative.c:2576!
-> Oops: invalid opcode: 0000 [#1] SMP NOPTI
-> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 
PREEMPT(full) openSUSE Tumbleweed  8c1795b03ec64f997e57a8ad38b1161e3b98da64
-> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 
02/02/2022
-> RIP: 0010:__text_poke+0x2aa/0x450
-> Call Trace:
->  <TASK>
->  smp_text_poke_batch_finish+0x2a7/0x320
->  __static_call_transform+0xb7/0x220
->  arch_static_call_transform+0x5b/0xb0
->  __static_call_init+0xe9/0x270
->  static_call_module_notify+0x11f/0x150
->  notifier_call_chain+0x61/0xe0
->  blocking_notifier_call_chain_robust+0x63/0xc0
->  load_module+0x1c92/0x20c0
->  init_module_from_file+0xd8/0x140
->  idempotent_init_module+0x100/0x2f0
->  __x64_sys_finit_module+0x71/0xe0
->  do_syscall_64+0xe1/0x610
->  entry_SYSCALL_64_after_hwframe+0x76/0x7e
-
-which matches the following BUG_ON in alternative.c:
-       /*
-        * If something went wrong, crash and burn since recovery paths are not
-        * implemented.
-        */
-       BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));
-
-This can happen if vmalloc_to_page() fails, for any reason. Such can happen
-if text poking races with CPA, which can possibly result in the collapsing
-of page tables (or breaking of PMD hugepages). It is not a problem for most
-users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when
-CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc
-range, and can call set_memory_*() in parallel on it. This can happen to
-race against __text_poke and cause havoc in vmalloc_to_page().
-
-Fix it by excluding against CPA using the init_mm mmap read lock.
-
-[ dhansen: Fix up SoB ordering. The actual code flow here was:
-          Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain
-          now. I *believe* Mike simply picked up Lorenzo's update to
-          Pedro's post from the Link: ]
-
-Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
-Reported-by: Jiri Slaby <[email protected]>
-Reported-by: Steffen Dirkwinkel <[email protected]>
-Signed-off-by: Pedro Falcato <[email protected]>
-Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Co-developed-by: Lorenzo Stoakes (ARM) <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
-Signed-off-by: Dave Hansen <[email protected]>
-Tested-by: Jiri Slaby <[email protected]>
-Tested-by: Atish Patra <[email protected]>
-Tested-by: Nikunj A Dadhania <[email protected]>
-Cc:[email protected]
-Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0]
-Link: 
https://lore.kernel.org/linux-mm/[email protected]/
-Link: https://patch.msgid.link/[email protected]
-Signed-off-by: Pedro Falcato <[email protected]>
----
- arch/x86/kernel/alternative.c |   39 ++++++++++++++++++++++++++++++++++++---
- 1 file changed, 36 insertions(+), 3 deletions(-)
-
---- a/arch/x86/kernel/alternative.c
-+++ b/arch/x86/kernel/alternative.c
-@@ -6,6 +6,9 @@
- #include <linux/vmalloc.h>
- #include <linux/memory.h>
- #include <linux/execmem.h>
-+#include <linux/cleanup.h>
-+#include <linux/kgdb.h>
-+#include <linux/mmap_lock.h>
- 
- #include <asm/text-patching.h>
- #include <asm/insn.h>
-@@ -2543,6 +2546,38 @@ static void text_poke_memset(void *dst,
- 
- typedef void text_poke_f(void *dst, const void *src, size_t len);
- 
-+static void __poke_vmalloc_pages(struct page **pages, void *addr,
-+                               bool cross_page_boundary)
-+{
-+      pages[0] = vmalloc_to_page(addr);
-+      if (cross_page_boundary)
-+              pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
-+}
-+
-+static void poke_vmalloc_pages(struct page **pages, void *addr,
-+                             bool cross_page_boundary)
-+{
-+      if (in_dbg_master()) {
-+              /*
-+               * If called from kgdb cannot sleep, but all other CPUs stopped
-+               * anyway so safe to proceed without locks
-+               */
-+              __poke_vmalloc_pages(pages, addr, cross_page_boundary);
-+      } else {
-+              /*
-+               * execmem ROX ranges are shared between modules and can be
-+               * collapsed to huge PMD entries, and this collapse can happen
-+               * concurrently with a racing set_memory_rox().
-+               *
-+               * Prevent vmalloc_to_page() from racing by acquiring an
-+               * init_mm read lock which pairs with the init_mm write lock in
-+               * cpa_collapse_large_pages().
-+               */
-+              guard(mmap_read_lock)(&init_mm);
-+              __poke_vmalloc_pages(pages, addr, cross_page_boundary);
-+      }
-+}
-+
- static void *__text_poke(text_poke_f func, void *addr, const void *src, 
size_t len)
- {
-       bool cross_page_boundary = offset_in_page(addr) + len > PAGE_SIZE;
-@@ -2560,9 +2595,7 @@ static void *__text_poke(text_poke_f fun
-       BUG_ON(!after_bootmem);
- 
-       if (!core_kernel_text((unsigned long)addr)) {
--              pages[0] = vmalloc_to_page(addr);
--              if (cross_page_boundary)
--                      pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
-+              poke_vmalloc_pages(pages, addr, cross_page_boundary);
-       } else {
-               pages[0] = virt_to_page(addr);
-               WARN_ON(!PageReserved(pages[0]));
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 
new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch
--- old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch      
2026-09-15 08:50:07.000000000 +0200
+++ new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch      
1970-01-01 01:00:00.000000000 +0100
@@ -1,198 +0,0 @@
-From: Peter Zijlstra <[email protected]>
-Date: Wed, 29 Jul 2026 13:08:10 +0200
-Subject: x86/mm: Fix and document DEBUG_PAGEALLOC
-References: bsc#1271202
-Git-commit: 7da514d819a0afb148634aac92b3d190f34947c3
-Patch-mainline: v7.3-rc1
-
-It turns out that commit 5fce67641a3e ("x86/mm/pat: Don't gate
-cpa_lock on debug_pagealloc_enabled()") was a little too quick to
-remove the debug_pagealloc exception for cpa_lock.
-
-Notably __kernel_map_pages() is used by the page-allocator from any
-context the page-allocator itself is used, which violates the cpa_lock
-rules.
-
-Re-instate the exception, except make it specific to the
-__kernel_map_pages() such that any other cpa() usage is still fully
-serialized by cpa_lock. Also note that since cpa() should not be used
-on memory that isn't allocated, the page-allocator locking and cpa are
-infact mutually exclusive and all cpa usage in fully serialized.
-
-Add a comment explaining this and other 'funnies' surrounding
-DEBUG_PAGEALLOC, including how pgd_lock is not affected and the TLB
-trickery.
-
-Fixes: 5fce67641a3e ("x86/mm/pat: Don't gate cpa_lock on 
debug_pagealloc_enabled()")
-Signed-off-by: Peter Zijlstra (Intel) <[email protected]>
-Link: https://patch.msgid.link/[email protected]
-Signed-off-by: Jiri Slaby <[email protected]>
----
- arch/x86/mm/pat/set_memory.c |   80 
+++++++++++++++++++++++++++++++------------
- 1 file changed, 58 insertions(+), 22 deletions(-)
-
---- a/arch/x86/mm/pat/set_memory.c
-+++ b/arch/x86/mm/pat/set_memory.c
-@@ -68,11 +68,12 @@ static const int cpa_warn_level = CPA_PR
-  */
- static DEFINE_SPINLOCK(cpa_lock);
- 
--#define CPA_FLUSHTLB 1
--#define CPA_ARRAY 2
--#define CPA_PAGES_ARRAY 4
--#define CPA_NO_CHECK_ALIAS 8 /* Do not search for aliases */
--#define CPA_COLLAPSE 16 /* try to collapse large pages */
-+#define CPA_FLUSHTLB          0x01
-+#define CPA_ARRAY             0x02
-+#define CPA_PAGES_ARRAY               0x04
-+#define CPA_NO_CHECK_ALIAS    0x08 /* Do not search for aliases */
-+#define CPA_COLLAPSE          0x10 /* try to collapse large pages */
-+#define CPA_DEBUG_PAGEALLOC   0x20
- 
- static inline pgprot_t cachemode2pgprot(enum page_cache_mode pcm)
- {
-@@ -2007,6 +2008,7 @@ static int __change_page_attr_set_clr(st
- {
-       unsigned long numpages = cpa->numpages;
-       unsigned long rempages = numpages;
-+      bool lock = true;
-       int ret = 0;
- 
-       /*
-@@ -2016,6 +2018,29 @@ static int __change_page_attr_set_clr(st
-           !cpa->force_split)
-               return ret;
- 
-+      /*
-+       * DEBUG_PAGEALLOC is special; it is called from any context the
-+       * page-allocator is, which violates the normal cpa_lock locking
-+       * rules.
-+       *
-+       * However, since it is part of the page-allocator, things are still
-+       * properly serialized by the page-allocator locking and the fact that
-+       * when a page is owned by the page-allocator, it isn't owned by
-+       * anybody else. That is, you *SHOULD NOT* be calling cpa() on memory
-+       * that isn't allocated.
-+       *
-+       * Additionally, DEBUG_PAGEALLOC ensures (per probe_page_size_mask())
-+       * that the kernel mapping is 4k pages, therefore there are no large
-+       * pages to split/collapse.
-+       *
-+       * Furthermore, the page-allocator strictly manages pages that
-+       * *exist*, avoiding pgd_lock.
-+       *
-+       * Therefore, it is safe to not take cpa_lock.
-+       */
-+      if (debug_pagealloc_enabled() && (cpa->flags & CPA_DEBUG_PAGEALLOC))
-+              lock = false;
-+
-       while (rempages) {
-               /*
-                * Store the remaining nr of pages for the large page
-@@ -2026,9 +2051,12 @@ static int __change_page_attr_set_clr(st
-               if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY))
-                       cpa->numpages = 1;
- 
--              spin_lock(&cpa_lock);
--              ret = __change_page_attr(cpa, primary);
--              spin_unlock(&cpa_lock);
-+              if (lock) {
-+                      guard(spinlock)(&cpa_lock);
-+                      ret = __change_page_attr(cpa, primary);
-+              } else {
-+                      ret = __change_page_attr(cpa, primary);
-+              }
-               if (ret)
-                       goto out;
- 
-@@ -2607,7 +2635,7 @@ int set_pages_rw(struct page *page, int
-       return set_memory_rw(addr, numpages);
- }
- 
--static int __set_pages_p(struct page *page, int numpages)
-+static int __set_pages_p(struct page *page, int numpages, unsigned int 
cpa_flags)
- {
-       unsigned long tempaddr = (unsigned long) page_address(page);
-       struct cpa_data cpa = { .vaddr = &tempaddr,
-@@ -2615,7 +2643,7 @@ static int __set_pages_p(struct page *pa
-                               .numpages = numpages,
-                               .mask_set = __pgprot(_PAGE_PRESENT | _PAGE_RW),
-                               .mask_clr = __pgprot(0),
--                              .flags = CPA_NO_CHECK_ALIAS };
-+                              .flags = CPA_NO_CHECK_ALIAS | cpa_flags };
- 
-       /*
-        * No alias checking needed for setting present flag. otherwise,
-@@ -2626,7 +2654,7 @@ static int __set_pages_p(struct page *pa
-       return __change_page_attr_set_clr(&cpa, 1);
- }
- 
--static int __set_pages_np(struct page *page, int numpages)
-+static int __set_pages_np(struct page *page, int numpages, unsigned int 
cpa_flags)
- {
-       unsigned long tempaddr = (unsigned long) page_address(page);
-       struct cpa_data cpa = { .vaddr = &tempaddr,
-@@ -2634,7 +2662,7 @@ static int __set_pages_np(struct page *p
-                               .numpages = numpages,
-                               .mask_set = __pgprot(0),
-                               .mask_clr = __pgprot(_PAGE_PRESENT | _PAGE_RW | 
_PAGE_DIRTY),
--                              .flags = CPA_NO_CHECK_ALIAS };
-+                              .flags = CPA_NO_CHECK_ALIAS | cpa_flags };
- 
-       /*
-        * No alias checking needed for setting not present flag. otherwise,
-@@ -2647,20 +2675,20 @@ static int __set_pages_np(struct page *p
- 
- int set_direct_map_invalid_noflush(struct page *page)
- {
--      return __set_pages_np(page, 1);
-+      return __set_pages_np(page, 1, 0);
- }
- 
- int set_direct_map_default_noflush(struct page *page)
- {
--      return __set_pages_p(page, 1);
-+      return __set_pages_p(page, 1, 0);
- }
- 
- int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
- {
-       if (valid)
--              return __set_pages_p(page, nr);
-+              return __set_pages_p(page, nr, 0);
- 
--      return __set_pages_np(page, nr);
-+      return __set_pages_np(page, nr, 0);
- }
- 
- #ifdef CONFIG_DEBUG_PAGEALLOC
-@@ -2679,15 +2707,23 @@ void __kernel_map_pages(struct page *pag
-        * and hence no memory allocations during large page split.
-        */
-       if (enable)
--              __set_pages_p(page, numpages);
-+              __set_pages_p(page, numpages, CPA_DEBUG_PAGEALLOC);
-       else
--              __set_pages_np(page, numpages);
-+              __set_pages_np(page, numpages, CPA_DEBUG_PAGEALLOC);
- 
-       /*
--       * We should perform an IPI and flush all tlbs,
--       * but that can deadlock->flush only current cpu.
--       * Preemption needs to be disabled around __flush_tlb_all() due to
--       * CR3 reload in __native_flush_tlb().
-+       * We should perform an IPI and flush all tlbs, but that can
-+       * deadlock, settle for a local flush.
-+       *
-+       * Not doing a global TLB flush means that remote CPUs will retain
-+       * stale TLB entries. In case of P->NP (on free) this means the remote
-+       * CPUs will not take the faults, making the debug scheme less
-+       * reliable. On the NP->P (on alloc) this means the remote CPUs can
-+       * take a spurious fault. However spurious_kernel_fault() will observe
-+       * *_present() and fix it up.
-+       *
-+       * Preemption needs to be disabled around __flush_tlb_all() due to CR3
-+       * reload in __native_flush_tlb().
-        */
-       preempt_disable();
-       __flush_tlb_all();
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
 
new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
--- 
old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
    2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch
    1970-01-01 01:00:00.000000000 +0100
@@ -1,84 +0,0 @@
-From: "Mike Rapoport (Microsoft)" <[email protected]>
-Date: Wed, 15 Jul 2026 17:45:19 +0300
-Subject: x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled()
-References: bsc#1271202
-Git-commit: 5fce67641a3ed9a0782eaa228ddece526461a367
-Patch-mainline: v7.3-rc1
-
-The splitting and merging of kernel page table mappings between small and
-large is protected by cpa_lock. The merging is relatively new but the
-splitting is ancient.
-
-The splitting has a locking optimization: since DEBUG_PAGEALLOC forces all
-mappings to 4k, there are no large pages to split. So the code that *might*
-cause a split can just skip the locking (and a few other things).
-
-This is entertaining, but it adds complexity and makes for weird locking
-rules. Plus it's all for a debugging feature which makes the kernel super
-slow in the first place. Optimizing something which is already super slow
-and not used in production is not the best way to spend our complexity
-budget.
-
-Stop gating cpa_lock on debug_pagealloc_enabled() to simplify the code
-and the locking rules.
-
-[ dhansen: flesh out changelog ]
-
-Suggested-by: Dave Hansen <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
-Signed-off-by: Dave Hansen <[email protected]>
-Link: https://patch.msgid.link/[email protected]
-Link: 
https://lore.kernel.org/all/[email protected]/
-
-Acked-by: Pedro Falcato <[email protected]>
----
- arch/x86/mm/pat/set_memory.c | 19 +++++++------------
- 1 file changed, 7 insertions(+), 12 deletions(-)
-
-diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
-index 45623d4c24c9..e9b408343c5d 100644
---- a/arch/x86/mm/pat/set_memory.c
-+++ b/arch/x86/mm/pat/set_memory.c
-@@ -62,10 +62,9 @@ enum cpa_warn {
- static const int cpa_warn_level = CPA_PROTECT;
- 
- /*
-- * Serialize cpa() (for !DEBUG_PAGEALLOC which uses large identity mappings)
-- * using cpa_lock. So that we don't allow any other cpu, with stale large tlb
-- * entries change the page attribute in parallel to some other cpu
-- * splitting a large page entry along with changing the attribute.
-+ * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with
-+ * stale large tlb entries, to change the page attribute in parallel to some
-+ * other cpu splitting a large page entry along with changing the attribute.
-  */
- static DEFINE_SPINLOCK(cpa_lock);
- 
-@@ -1234,11 +1233,9 @@ static int split_large_page(struct cpa_data *cpa, pte_t 
*kpte,
- {
-       struct ptdesc *ptdesc;
- 
--      if (!debug_pagealloc_enabled())
--              spin_unlock(&cpa_lock);
-+      spin_unlock(&cpa_lock);
-       ptdesc = pagetable_alloc(GFP_KERNEL, 0);
--      if (!debug_pagealloc_enabled())
--              spin_lock(&cpa_lock);
-+      spin_lock(&cpa_lock);
-       if (!ptdesc)
-               return -ENOMEM;
- 
-@@ -2022,11 +2019,9 @@ static int __change_page_attr_set_clr(struct cpa_data 
*cpa, int primary)
-               if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY))
-                       cpa->numpages = 1;
- 
--              if (!debug_pagealloc_enabled())
--                      spin_lock(&cpa_lock);
-+              spin_lock(&cpa_lock);
-               ret = __change_page_attr(cpa, primary);
--              if (!debug_pagealloc_enabled())
--                      spin_unlock(&cpa_lock);
-+              spin_unlock(&cpa_lock);
-               if (ret)
-                       goto out;
- 
-
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch
   1970-01-01 01:00:00.000000000 +0100
@@ -1,136 +0,0 @@
-From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Thu, 13 Aug 2026 12:01:25 +0300
-Subject: x86/mm/pat: Acquire init_mm read lock on attribute change to avoid
- UAF
-References: bsc#1271202
-Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
-Git-commit: 884801a901bd340c44a202e2ef5c29b48e3a4d93
-Patch-mainline: Queued in subsystem maintainer repository
-
-A previous commit protected against races between ptdump and CPA collapse,
-however one still exists between attribute changes and collapse as reported
-by Denis V. Lunev (linked).
-
-When an attribute change arises, a lockless page table walker obtains a PTE
-entry, which is later written to via set_pte_atomic():
-
-...
--> change_page_attr_set_clr()
--> __change_page_attr_set_clr()
--> __change_page_attr()
-       -> _lookup_address_cpa()
-       -> lookup_address_in_pgd_attr()
-       -> [ lockless page table walker ]
--> set_pte_atomic()
-
-There is nothing preventing a concurrent CPA collapse which can free the
-PTE that was retrieved here, resulting in a use-after-free.
-
-With the mmap write lock taken on init_mm over CPA collapse, resolve this
-race by acquiring an mmap read lock on init_mm over
-__change_page_attr_set_clr().
-
-This locks across the whole operation over which the walk and the PTE entry
-write occurs, solving the race.
-
-It is safe to do this here, as no spinlocks are held upon entry to
-__change_page_attr_set_clr().
-
-However, the lock must not be held over an allocation, as allocation can
-trigger reclaim and shrinkers may call into CPA recursively, making
-deadlocks possible (init_mm -> ... -> fs_reclaim -> init_mm).
-
-A page table is allocated when a huge page needs to be split:
-
--> change_page_attr_set_clr()
--> __change_page_attr_set_clr()
--> __change_page_attr()
--> split_large_page()
-[ pagetable_alloc() ]
--> __split_large_page()
-
-Avoid deadlocks by dropping the mmap lock across pagetable_alloc() in
-split_large_page() and track whether this is needed by adding a new
-'init_mm_read_locked' flag to struct cpa_data.
-
-This is safe as __split_large_page() (called with locks re-established)
-revalidates that the page table entry is the same as it was prior to the
-locks being dropped and __change_page_attr() repeats the entire page table
-walk whenever a split occurs, so concurrent split and collapse are
-accounted for.
-
-Concurrent ptdump is also safe as the lock is only dropped over page table
-allocation during which time the page table has not yet been modified.
-
-The CPA_COLLAPSE flag is only set by set_memory_rox(), which exclusively
-operates upon vmalloc ranges, and on x86 only within the module mapping
-space.
-
-This is important, because some callers directly invoke
-__change_page_attr_set_clr(), bypassing this lock. However, none of these
-operate within the module mapping space.
-
-* cpa_process_alias() - a recursive helper called by
-  __change_page_attr_set_clr().
-* __set_memory_enc_pgtable() - operates on the direct mapping and (via
-  __vmbus_establish_gpadl()) the vmalloc mapping space.
-* __set_pages_[n]p() - called by set_direct_map_[invalid, default,
-  valid]_noflush(), __kernel_map_pages() - operates on the direct map.
-* kernel_[un]map_pages_in_pgd() - operates on EFI ranges.
-
-This work is based upon Denis V. Lunev's excellent analysis of the bug with
-gratitude.
-
-[ dhansen: move to imperative voice in changelog ]
-
-Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
-Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
-Signed-off-by: Dave Hansen <[email protected]>
-Tested-by: Atish Patra <[email protected]>
-Tested-by: Nikunj A Dadhania <[email protected]>
-Link: https://lore.kernel.org/all/[email protected]/
-Cc:[email protected]
-Link: https://patch.msgid.link/[email protected]
-Signed-off-by: Pedro Falcato <[email protected]>
----
- arch/x86/mm/pat/set_memory.c |   13 +++++++++++--
- 1 file changed, 11 insertions(+), 2 deletions(-)
-
---- a/arch/x86/mm/pat/set_memory.c
-+++ b/arch/x86/mm/pat/set_memory.c
-@@ -50,7 +50,8 @@ struct cpa_data {
-       unsigned int    flags;
-       unsigned int    force_split             : 1,
-                       force_static_prot       : 1,
--                      force_flush_all         : 1;
-+                      force_flush_all         : 1,
-+                      init_mm_read_locked     : 1;
-       struct page     **pages;
- };
- 
-@@ -1255,7 +1256,11 @@ static int split_large_page(struct cpa_d
-       struct ptdesc *ptdesc;
- 
-       spin_unlock(&cpa_lock);
-+      if (cpa->init_mm_read_locked)
-+              mmap_read_unlock(&init_mm);
-       ptdesc = pagetable_alloc(GFP_KERNEL, 0);
-+      if (cpa->init_mm_read_locked)
-+              mmap_read_lock(&init_mm);
-       spin_lock(&cpa_lock);
-       if (!ptdesc)
-               return -ENOMEM;
-@@ -2151,7 +2156,11 @@ static int change_page_attr_set_clr(unsi
-       cpa.curpage = 0;
-       cpa.force_split = force_split;
- 
--      ret = __change_page_attr_set_clr(&cpa, 1);
-+      /* Avoid race with concurrent CPA collapse. */
-+      cpa.init_mm_read_locked = true;
-+      scoped_guard(mmap_read_lock, &init_mm)
-+              ret = __change_page_attr_set_clr(&cpa, 1);
-+      cpa.init_mm_read_locked = false;
- 
-       /*
-        * Check whether we really changed something:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
--- 
old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch
   1970-01-01 01:00:00.000000000 +0100
@@ -1,118 +0,0 @@
-From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Thu, 13 Aug 2026 12:01:24 +0300
-Subject: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF
-References: bsc#1271202
-Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
-Git-commit: 4cfad2657c7c87b1172a9c343b74cf59b3769873
-Patch-mainline: Queued in subsystem maintainer repository
-
-x86 implements page attribute modification using its Change Page
-Attributes (CPA) mechanism.
-
-This tracks properties of ranges such as cache mode through x86 page
-attributes, and as part of that logic manipulates kernel page tables.
-
-Since commit 41d88484c71c ("x86/mm/pat: restore large ROX pages after
-fragmentation") ranges of kernel page table entries can be collapsed into
-huge page table entries as part of this logic.
-
-As part of this collapse, it frees the page tables which the collapsed
-entries previously pointed to, and it does so without any relevant locks
-being held to preclude concurrent kernel page table walkers.
-
-The only way this code can be reached is if CPA_COLLAPSE is specified, and
-this is only set in set_memory_rox() via:
-
-set_memory_rox()
--> change_page_attr_set_clr()
--> cpa_flush()
--> cpa_collapse_large_pages()
-
-Notable users of this are execmem and bpf when manipulating executable
-mappings.
-
-However, this is problematic for ptdump as it walks ranges it does not own
-and thus runs the risk of a use-after-free on page tables freed underneath
-it.
-
-In addition, concurrent CPA collapse operations are possible which can also
-cause races.
-
-Resolve the issue by acquiring the mmap write lock on init_mm across the
-whole operation.
-
-It is safe to acquire a sleeping lock as all the callers invoke
-set_memory_rox() from process context and in any case,
-change_page_attr_set_clr() calls vm_unmap_alias() which ultimately takes a
-mutex, disallowing atomic context here.
-
-Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
-Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
-Signed-off-by: Dave Hansen <[email protected]>
-Reviewed-by: Mike Rapoport (Microsoft) <[email protected]>
-Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]>
-Reviewed-by: David Hildenbrand (Arm) <[email protected]>
-Reviewed-by: Dave Hansen <[email protected]>
-Reviewed-by: Will Deacon <[email protected]>
-Reviewed-by: David Carlier <[email protected]>
-Tested-by: Atish Patra <[email protected]>
-Tested-by: Nikunj A Dadhania <[email protected]>
-Cc:[email protected]
-Link: https://patch.msgid.link/[email protected]
-Signed-off-by: Pedro Falcato <[email protected]>
-
----
- arch/x86/mm/pat/set_memory.c |   15 ++++++++++++++-
- include/linux/mmap_lock.h    |    2 ++
- 2 files changed, 16 insertions(+), 1 deletion(-)
-
---- a/arch/x86/mm/pat/set_memory.c
-+++ b/arch/x86/mm/pat/set_memory.c
-@@ -22,6 +22,7 @@
- #include <linux/cc_platform.h>
- #include <linux/set_memory.h>
- #include <linux/memregion.h>
-+#include <linux/cleanup.h>
- 
- #include <asm/e820/api.h>
- #include <asm/processor.h>
-@@ -410,7 +411,7 @@ static void __cpa_flush_tlb(void *data)
- 
- static int collapse_large_pages(unsigned long addr, struct list_head 
*pgtables);
- 
--static void cpa_collapse_large_pages(struct cpa_data *cpa)
-+static void __cpa_collapse_large_pages(struct cpa_data *cpa)
- {
-       unsigned long start, addr, end;
-       struct ptdesc *ptdesc, *tmp;
-@@ -448,6 +449,18 @@ static void cpa_collapse_large_pages(str
-       spin_unlock(&cpa_lock);
- }
- 
-+static void cpa_collapse_large_pages(struct cpa_data *cpa)
-+{
-+      /*
-+       * Take the mmap write lock on init_mm to:
-+       * - Avoid a use-after-free if raced by ptdump (which takes its own
-+       *   write lock on init_mm).
-+       * - Serialise concurrent CPA walkers.
-+       */
-+      scoped_guard(mmap_write_lock, &init_mm)
-+              __cpa_collapse_large_pages(cpa);
-+}
-+
- static void cpa_flush(struct cpa_data *cpa, int cache)
- {
-       unsigned int i;
---- a/include/linux/mmap_lock.h
-+++ b/include/linux/mmap_lock.h
-@@ -622,6 +622,8 @@ static inline void mmap_read_unlock(stru
- DEFINE_GUARD(mmap_read_lock, struct mm_struct *,
-            mmap_read_lock(_T), mmap_read_unlock(_T))
- DEFINE_GUARD_COND(mmap_read_lock, _try, mmap_read_trylock(_T))
-+DEFINE_GUARD(mmap_write_lock, struct mm_struct *,
-+           mmap_write_lock(_T), mmap_write_unlock(_T))
- 
- static inline void mmap_read_unlock_non_owner(struct mm_struct *mm)
- {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
--- 
old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   2026-09-15 08:50:07.000000000 +0200
+++ 
new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch
   1970-01-01 01:00:00.000000000 +0100
@@ -1,129 +0,0 @@
-From: "Lorenzo Stoakes (ARM)" <[email protected]>
-Date: Thu, 13 Aug 2026 12:01:27 +0300
-Subject: x86/mm/pat: Allocate split page tables as kernel page tables
-References: bsc#1271202
-Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git
-Git-commit: 0e33126d5def407397deaf617559a1a2a7f4b1ae
-Patch-mainline: Queued in subsystem maintainer repository
-
-A PTE is allocated directly without going through the standard page table
-allocation routines (such as pte_alloc_one_kernel()) when the CPA code
-splits a large page (__split_large_page()).
-
-This means the page table constructor is never called nor is the page table
-marked as a kernel page table.
-
-The former results in the folio associated with the page table not being
-marked as a page table (__pagetable_ctor() is never called thus neither is
-__folio_set_pgtable()) nor are statistics updated to reflect
-it (lruvec_stat_add_folio() is never called).
-
-The latter issue of failing to mark the page table as a kernel page
-table (ptdesc_set_kernel() is never called) is far more problematic.
-
-Since commit 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page
-tables") kernel page table freeing has been batched and since the
-subsequent commit e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries
-for kernel address space") IOTLB cache entries for kernel page tables have
-been invalidated upon being freed.
-
-Since split page tables are freed without this invalidation, the IOTLB can
-contain stale entries for them.
-
-Resolve the issue by using the ordinary PTE allocation API at split time.
-
-This results in these kernel page tables invoking a page table constructor,
-and thus requires a page table destructor.
-
-Destructors are not always present, like for early allocated direct map
-page tables). Conditionally call pagetable_dtor_free() if the PG_table
-folio flag for the ptdesc is set, otherwise we free the page table via
-pagetable_free().
-
-Regardless of which path is taken page tables marked as kernel page tables,
-which now includes split page tables, take the correct route through
-pagetable_free_kernel().
-
-There is a user-visible side effect in that split page tables will appear
-in nr_page_table_pages in /proc/vmstat (as do other kernel page tables
-allocated after early boot), however this is a positive change.
-
-This issue started being markedly problematic after commit
-5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so
-choose this as the Fixes target.
-
-[ dhansen: rephrase in imperative mood ]
-
-Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables")
-Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
-Signed-off-by: Mike Rapoport (Microsoft) <[email protected]>
-Signed-off-by: Dave Hansen <[email protected]>
-Acked-by: Vishal Moola <[email protected]>
-Tested-by: Atish Patra <[email protected]>
-Tested-by: Nikunj A Dadhania <[email protected]>
-Cc:[email protected]
-Link: https://patch.msgid.link/[email protected]
-Signed-off-by: Pedro Falcato <[email protected]>
----
- arch/x86/mm/pat/set_memory.c |   25 ++++++++++++++++---------
- 1 file changed, 16 insertions(+), 9 deletions(-)
-
---- a/arch/x86/mm/pat/set_memory.c
-+++ b/arch/x86/mm/pat/set_memory.c
-@@ -444,7 +444,15 @@ static void __cpa_collapse_large_pages(s
- 
-       list_for_each_entry_safe(ptdesc, tmp, &pgtables, pt_list) {
-               list_del(&ptdesc->pt_list);
--              pagetable_free(ptdesc);
-+              /*
-+               * Only early alloc'd direct map should not be flagged PG_table
-+               * here and those shouldn't be collapsed. However be abundantly
-+               * cautious and handle the !PG_table case too.
-+               */
-+              if (PageTable((ptdesc_page(ptdesc))))
-+                      pagetable_dtor_free(ptdesc);
-+              else
-+                      pagetable_free(ptdesc);
-       }
- 
-       spin_unlock(&cpa_lock);
-@@ -1145,11 +1153,10 @@ set:
- 
- static int
- __split_large_page(struct cpa_data *cpa, pte_t *kpte, unsigned long address,
--                 struct ptdesc *ptdesc)
-+                 pte_t *pbase)
- {
-       unsigned long lpaddr, lpinc, ref_pfn, pfn, pfninc = 1;
--      struct page *base = ptdesc_page(ptdesc);
--      pte_t *pbase = (pte_t *)page_address(base);
-+      struct page *base = virt_to_page(pbase);
-       unsigned int i, level;
-       pgprot_t ref_prot;
-       bool nx, rw;
-@@ -1253,20 +1260,20 @@ __split_large_page(struct cpa_data *cpa,
- static int split_large_page(struct cpa_data *cpa, pte_t *kpte,
-                           unsigned long address)
- {
--      struct ptdesc *ptdesc;
-+      pte_t *pte;
- 
-       spin_unlock(&cpa_lock);
-       if (cpa->init_mm_read_locked)
-               mmap_read_unlock(&init_mm);
--      ptdesc = pagetable_alloc(GFP_KERNEL, 0);
-+      pte = pte_alloc_one_kernel(&init_mm);
-       if (cpa->init_mm_read_locked)
-               mmap_read_lock(&init_mm);
-       spin_lock(&cpa_lock);
--      if (!ptdesc)
-+      if (!pte)
-               return -ENOMEM;
- 
--      if (__split_large_page(cpa, kpte, address, ptdesc))
--              pagetable_free(ptdesc);
-+      if (__split_large_page(cpa, kpte, address, pte))
-+              pte_free_kernel(&init_mm, pte);
- 
-       return 0;
- }

++++++ series.conf ++++++
++++ 778 lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kernel-source/series.conf
++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.383539/series.conf

++++++ source-timestamp ++++++
--- /var/tmp/diff_new_pack.LMGrMr/_old  2026-09-24 22:56:21.130436477 +0200
+++ /var/tmp/diff_new_pack.LMGrMr/_new  2026-09-24 22:56:21.133436603 +0200
@@ -1,4 +1,4 @@
-2026-09-15 06:50:07 +0000
-GIT Revision: 3d19f111ece9212f3590114d07b4ea06f11e6cdb
+2026-09-22 08:00:24 +0000
+GIT Revision: e601a2de7e673ef35afa7dc8af2866342bb61559
 GIT Branch: stable
 

Reply via email to