Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kernel-source for openSUSE:Factory checked in at 2026-09-24 22:55:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kernel-source (Old) and /work/SRC/openSUSE:Factory/.kernel-source.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kernel-source" Thu Sep 24 22:55:34 2026 rev:861 rq:1379616 version:7.2.7 Changes: -------- --- /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes 2026-09-17 15:17:50.357984423 +0200 +++ /work/SRC/openSUSE:Factory/.kernel-source.new.383539/dtb-aarch64.changes 2026-09-24 22:56:04.422734574 +0200 @@ -1,0 +2,4062 @@ +Tue Sep 22 10:00:24 CEST 2026 - [email protected] + +- Update + patches.kernel.org/7.2.4-001-drm-amd-display-Skip-Update-HDCP-Config-In-Tran.patch + (bsc#1012628 CVE-2026-89773 bsc#1280700). +- Update + patches.kernel.org/7.2.4-009-btrfs-write-protect-folios-during-data-writebac.patch + (bsc#1012628 CVE-2026-89772 bsc#1280699). +- Update + patches.kernel.org/7.2.4-010-ring-buffer-Fix-subbuf-resize-race-with-ring-bu.patch + (bsc#1012628 CVE-2026-89771 bsc#1280712). +- Update + patches.kernel.org/7.2.4-014-iomap-don-t-free-integrity-payload-that-doesn-t.patch + (bsc#1012628 CVE-2026-89770 bsc#1280710). +- Update + patches.kernel.org/7.2.4-017-clocksource-drivers-nxp-pit-Fix-IRQ-leak-on-cpu.patch + (bsc#1012628 CVE-2026-89769 bsc#1280708). +- Update + patches.kernel.org/7.2.4-019-fs-fix-user-path-of-nested-backing-files.patch + (bsc#1012628 CVE-2026-89768 bsc#1280734). +- Update + patches.kernel.org/7.2.4-020-ovl-fix-double-end_creating-on-the-casefold-mis.patch + (bsc#1012628 CVE-2026-89767 bsc#1280730). +- Update + patches.kernel.org/7.2.4-021-pidfd-hold-exec_update_lock-around-namespace-io.patch + (bsc#1012628 CVE-2026-89766 bsc#1280725). +- Update + patches.kernel.org/7.2.4-024-timers-itimer-Zero-init-old-itimerval-before-co.patch + (bsc#1012628 CVE-2026-89765 bsc#1281182). +- Update + patches.kernel.org/7.2.4-032-rust-devres-fix-race-between-concurrent-revoker.patch + (bsc#1012628 CVE-2026-89764 bsc#1280818). +- Update + patches.kernel.org/7.2.4-041-KEYS-trusted-Fix-TPM-teardown-ordering.patch + (bsc#1012628 CVE-2026-89763 bsc#1280820). +- Update + patches.kernel.org/7.2.4-042-apparmor-fix-cred-UAF-caused-by-begin_current_l.patch + (bsc#1012628 CVE-2026-89762 bsc#1280749). +- Update + patches.kernel.org/7.2.4-043-apparmor-fix-out-of-bounds-write-when-null-term.patch + (bsc#1012628 CVE-2026-89761 bsc#1280745). +- Update + patches.kernel.org/7.2.4-045-mm-swap-don-t-free-a-hibernation-slot-that-is-i.patch + (bsc#1012628 CVE-2026-89760 bsc#1280740). +- Update + patches.kernel.org/7.2.4-053-mm-kmemleak-avoid-soft-lockup-when-scanning-tas.patch + (bsc#1012628 CVE-2026-89759 bsc#1280821). +- Update + patches.kernel.org/7.2.4-055-mm-mempolicy-skip-non-present-PMDs-when-queuein.patch + (bsc#1012628 CVE-2026-89758 bsc#1280757). +- Update + patches.kernel.org/7.2.4-056-mm-mglru-fix-and-remove-redundant-unevictable-f.patch + (bsc#1012628 CVE-2026-89757 bsc#1280763). +- Update + patches.kernel.org/7.2.4-057-mm-migrate-report-RCU-tasks-quiescent-states-in.patch + (bsc#1012628 CVE-2026-89756 bsc#1280756). +- Update + patches.kernel.org/7.2.4-059-mm-migrate_device-clear-stale-mapping-after-fre.patch + (bsc#1012628 CVE-2026-89755 bsc#1280770). +- Update + patches.kernel.org/7.2.4-063-mm-pagewalk-fix-stale-walk-action-escaping-walk.patch + (bsc#1012628 CVE-2026-89754 bsc#1280769). +- Update + patches.kernel.org/7.2.4-069-mm-vmscan-report-RCU-tasks-quiescent-states-in-.patch + (bsc#1012628 CVE-2026-89753 bsc#1281178). +- Update + patches.kernel.org/7.2.4-074-mm-memcg-stop-reclaim-when-a-limit-update-is-su.patch + (bsc#1012628 CVE-2026-89752 bsc#1281176). +- Update + patches.kernel.org/7.2.4-084-x86-tdx-Fix-off-by-one-in-port-I-O-handling.patch + (bsc#1012628 CVE-2026-89751 bsc#1280822). +- Update + patches.kernel.org/7.2.4-088-tracing-user_events-Clear-copied-tracing-state-.patch + (bsc#1012628 CVE-2026-89750 bsc#1281172). +- Update + patches.kernel.org/7.2.4-089-tracing-Fix-crash-passing-ERR_PTR-to-kthread_st.patch + (bsc#1012628 CVE-2026-89749 bsc#1281166). +- Update + patches.kernel.org/7.2.4-091-tracing-Fix-retry-exhaustion-in-simple-ring-buf.patch + (bsc#1012628 CVE-2026-89748 bsc#1281024). +- Update + patches.kernel.org/7.2.4-092-tracing-Fix-use-after-free-in-trace_pipe-read-o.patch + (bsc#1012628 CVE-2026-89747 bsc#1281025). +- Update + patches.kernel.org/7.2.4-093-tracing-Fix-use-after-free-with-same-name-named.patch + (bsc#1012628 CVE-2026-89746 bsc#1281026). +- Update + patches.kernel.org/7.2.4-095-debugfs-Fix-lockdown-check-for-mmap_prepare.patch + (bsc#1012628 CVE-2026-89745 bsc#1281209). +- Update + patches.kernel.org/7.2.4-096-device-property-fix-infinite-loop-in-fwnode_for.patch + (bsc#1012628 CVE-2026-89744 bsc#1281029). +- Update + patches.kernel.org/7.2.4-097-misc-nsm-bound-the-device-reported-response-len.patch + (bsc#1012628 CVE-2026-89743 bsc#1281028). +- Update + patches.kernel.org/7.2.4-099-rapidio-mport_cdev-fix-use-after-free-in-dma_re.patch + (bsc#1012628 CVE-2026-89742 bsc#1281027). +- Update + patches.kernel.org/7.2.4-100-Revert-media-v4l2-dev-fix-error-handling-in-__v.patch + (bsc#1012628 CVE-2026-89741 bsc#1281030). +- Update + patches.kernel.org/7.2.4-101-serial-imx-serialize-imx_uart_ports-lifetime.patch + (bsc#1012628 CVE-2026-89740 bsc#1281032). +- Update + patches.kernel.org/7.2.4-104-usb-dwc3-gadget-Fix-use-after-free-in-dwc3_gadg.patch + (bsc#1012628 CVE-2026-89739 bsc#1281191). +- Update + patches.kernel.org/7.2.4-105-usb-gadget-at91_udc-drain-polled-VBUS-timer-wor.patch + (bsc#1012628 CVE-2026-89738 bsc#1280526). +- Update + patches.kernel.org/7.2.4-109-usb-typec-thunderbolt-Disable-work-before-freei.patch + (bsc#1012628 CVE-2026-89737 bsc#1280528). +- Update + patches.kernel.org/7.2.4-111-usb-gadget-u_audio-Fix-use-after-free-on-sound-.patch + (bsc#1012628 CVE-2026-89736 bsc#1281130). +- Update + patches.kernel.org/7.2.4-113-usb-gadget-midi2-remove-default-configfs-groups.patch + (bsc#1012628 CVE-2026-89735 bsc#1281013). +- Update + patches.kernel.org/7.2.4-115-usb-gadget-uvc-Fix-null-pointer-dereference-in-.patch + (bsc#1012628 CVE-2026-89734 bsc#1280529). +- Update + patches.kernel.org/7.2.4-116-usb-gadget-uvc-fix-dangling-pointers-in-uvc_fun.patch + (bsc#1012628 CVE-2026-89733 bsc#1281008). +- Update + patches.kernel.org/7.2.4-117-usb-gadget-f_fs-Prevent-deadlock-during-ep0-rea.patch + (bsc#1012628 CVE-2026-89732 bsc#1280505). +- Update + patches.kernel.org/7.2.4-118-cxl-ras-Fix-cxl_rch_get_aer_info-out-of-bounds-.patch + (bsc#1012628 CVE-2026-89731 bsc#1281031). +- Update + patches.kernel.org/7.2.4-119-fpga-altera-cvp-Avoid-out-of-bounds-read-in-tra.patch + (bsc#1012628 CVE-2026-89730 bsc#1281034). +- Update + patches.kernel.org/7.2.4-120-HID-sensor-hub-Fix-out-of-bounds-write-in-senso.patch + (bsc#1012628 CVE-2026-89729 bsc#1280785). +- Update + patches.kernel.org/7.2.4-121-i3c-renesas-Fix-out-of-bounds-access-for-newdev.patch + (bsc#1012628 CVE-2026-89728 bsc#1280796). +- Update + patches.kernel.org/7.2.4-122-KVM-arm64-GICv2-Don-t-WARN-on-out-of-range-GICV.patch + (bsc#1012628 CVE-2026-89727 bsc#1280506). +- Update + patches.kernel.org/7.2.4-123-lib-ucs2_string.c-fix-out-of-bounds-read-in-ucs.patch + (bsc#1012628 CVE-2026-89726 bsc#1281058). +- Update + patches.kernel.org/7.2.4-124-media-cec-stm32-prevent-out-of-bounds-write-on-.patch + (bsc#1012628 CVE-2026-89725 bsc#1280777). +- Update + patches.kernel.org/7.2.4-125-media-vicodec-fix-out-of-bounds-write-in-FWHT-e.patch + (bsc#1012628 CVE-2026-89724 bsc#1280813). +- Update + patches.kernel.org/7.2.4-126-nilfs2-fix-slab-out-of-bounds-in-nilfs_direct_p.patch + (bsc#1012628 CVE-2026-89723 bsc#1280815). +- Update + patches.kernel.org/7.2.4-128-PCI-sysfs-Fix-out-of-bounds-read-in-pci_write_l.patch + (bsc#1012628 CVE-2026-89722 bsc#1280535). +- Update + patches.kernel.org/7.2.4-129-phy-rockchip-samsung-dcphy-fix-out-of-range-max.patch + (bsc#1012628 CVE-2026-89721 bsc#1280808). +- Update + patches.kernel.org/7.2.4-130-ubifs-fix-out-of-bounds-read-in-signature-lengt.patch + (bsc#1012628 CVE-2026-89720 bsc#1280533). +- Update + patches.kernel.org/7.2.4-131-zram-fix-out-of-bounds-access-in-read_block_sta.patch + (bsc#1012628 CVE-2026-89719 bsc#1280838). +- Update + patches.kernel.org/7.2.4-132-zram-fix-out-of-bounds-access-in-writeback_stor.patch + (bsc#1012628 CVE-2026-89718 bsc#1280823). +- Update + patches.kernel.org/7.2.4-133-zram-set-default-primary-compressor-in-zram_des.patch + (bsc#1012628 CVE-2026-89717 bsc#1280824). +- Update + patches.kernel.org/7.2.4-134-zram-validate-deflate-params.patch + (bsc#1012628 CVE-2026-89716 bsc#1280825). +- Update + patches.kernel.org/7.2.4-136-NFS-localio-fix-ref-leak-on-nfs_uuid_add_file-f.patch + (bsc#1012628 CVE-2026-89715 bsc#1280833). +- Update + patches.kernel.org/7.2.4-137-NFS-fix-delegation_hash_table-leak-when-nfs4_se.patch + (bsc#1012628 CVE-2026-89714 bsc#1280828). +- Update + patches.kernel.org/7.2.4-138-NFSD-check-truncate-permission-under-inode-lock.patch + (bsc#1012628 CVE-2026-89713 bsc#1280872). +- Update + patches.kernel.org/7.2.4-142-NFSD-restart-ssc_expire_umount-walk-after-dropp.patch + (bsc#1012628 CVE-2026-89712 bsc#1280870). +- Update + patches.kernel.org/7.2.4-143-NFSD-remove-flawed-WARN_ON_ONCE-from-nfsd_mode_.patch + (bsc#1012628 CVE-2026-89711 bsc#1281035). +- Update + patches.kernel.org/7.2.4-145-NFSv4.1-fix-layout-segment-leak-on-the-pnfs_lay.patch + (bsc#1012628 CVE-2026-89710 bsc#1280455). +- Update + patches.kernel.org/7.2.4-147-lockd-nfsd-RCU-protect-nlmsvc_ops-dispatch.patch + (bsc#1012628 CVE-2026-89709 bsc#1281158). +- Update + patches.kernel.org/7.2.4-148-nfsd-RCU-protect-cl_cb_session-to-fix-use-after.patch + (bsc#1012628 CVE-2026-89708 bsc#1280448). +- Update + patches.kernel.org/7.2.4-149-nfsd-release-path-refs-on-follow_down-error.patch + (bsc#1012628 CVE-2026-89707 bsc#1280468). +- Update + patches.kernel.org/7.2.4-150-nfsd-Reset-write-verifier-when-async-COPY-write.patch + (bsc#1012628 CVE-2026-89706 bsc#1280477). +- Update + patches.kernel.org/7.2.4-151-nfsd-restore-rq_status_counter-to-even-on-all-n.patch + (bsc#1012628 CVE-2026-89705 bsc#1280464). +- Update + patches.kernel.org/7.2.4-153-nfsd-sample-writeback-error-cursor-before-async.patch + (bsc#1012628 CVE-2026-89704 bsc#1280490). +- Update + patches.kernel.org/7.2.4-154-nfsd-set-SC_STATUS_FREED-in-nfsd4_drop_revoked_.patch + (bsc#1012628 CVE-2026-89703 bsc#1280488). +- Update + patches.kernel.org/7.2.4-155-nfsd-size-fh_verify-server-sockaddr-slot-by-xpt.patch + (bsc#1012628 CVE-2026-89702 bsc#1280487). +- Update + patches.kernel.org/7.2.4-156-nfsd-validate-nseconds-in-TIME_DELEG-decode-pat.patch + (bsc#1012628 CVE-2026-89701 bsc#1280495). +- Update + patches.kernel.org/7.2.4-157-nfsd-validate-sockaddr-length-per-family-in-lis.patch + (bsc#1012628 CVE-2026-89700 bsc#1280497). +- Update + patches.kernel.org/7.2.4-158-nfsd-validate-symlink-target-length-in-NFSv4-CR.patch + (bsc#1012628 CVE-2026-89699 bsc#1281077). +- Update + patches.kernel.org/7.2.4-159-nfsd-widen-nfsd_genl_rqstp-address-fields-to-so.patch + (bsc#1012628 CVE-2026-89698 bsc#1280494). +- Update + patches.kernel.org/7.2.4-202-nfsd-reject-out-of-range-nseconds-in-NFSv3-SETA.patch + (bsc#1012628 CVE-2026-89666 bsc#1281074). +- Update + patches.kernel.org/7.2.4-203-nfsd-reject-out-of-range-useconds-in-NFSv2-SETA.patch + (bsc#1012628 CVE-2026-89665 bsc#1281057). +- Update + patches.kernel.org/7.2.4-206-nfsd-revoke-copy-notify-stateids-before-droppin.patch + (bsc#1012628 CVE-2026-89663 bsc#1280518). +- Update + patches.kernel.org/7.2.4-207-NFSD-Prevent-lock-owner-use-after-free-during-c.patch + (bsc#1012628 CVE-2026-89662 bsc#1280509). +- Update + patches.kernel.org/7.2.4-208-NFSD-Prevent-post-shutdown-use-after-free-in-un.patch + (bsc#1012628 CVE-2026-89661 bsc#1280532). +- Update + patches.kernel.org/7.2.4-209-NFSD-Prevent-client-use-after-free-during-admin.patch + (bsc#1012628 CVE-2026-89660 bsc#1280525). +- Update + patches.kernel.org/7.2.4-210-NFSD-Prevent-client-use-after-free-during-deleg.patch + (bsc#1012628 CVE-2026-89659 bsc#1280527). +- Update + patches.kernel.org/7.2.4-211-NFSD-Prevent-client-use-after-free-during-NFSv4.patch + (bsc#1012628 CVE-2026-89658 bsc#1280576). +- Update + patches.kernel.org/7.2.4-213-libceph-validate-OSD-extent-maps-before-cursor-.patch + (bsc#1012628 CVE-2026-89657 bsc#1280545). +- Update + patches.kernel.org/7.2.4-214-libceph-reject-buckets-with-mismatched-CRUSH-id.patch + (bsc#1012628 CVE-2026-89656 bsc#1280563). +- Update + patches.kernel.org/7.2.4-215-ceph-fix-UAF-in-__kick_flushing_caps-on-cf-entr.patch + (bsc#1012628 CVE-2026-89655 bsc#1280398). +- Update + patches.kernel.org/7.2.4-216-ceph-fix-UAF-in-check_new_map-on-session-freed-.patch + (bsc#1012628 CVE-2026-89654 bsc#1280415). +- Update + patches.kernel.org/7.2.4-218-ceph-reject-export_targets-ranks-CEPH_MAX_MDS-i.patch + (bsc#1012628 CVE-2026-89653 bsc#1280401). +- Update + patches.kernel.org/7.2.4-219-ceph-bound-copied-dentry-name-length-in-NFS-exp.patch + (bsc#1012628 CVE-2026-89652 bsc#1280419). +- Update + patches.kernel.org/7.2.4-220-ceph-bound-MDSCapAuth-path-and-fs_name-decode-i.patch + (bsc#1012628 CVE-2026-89651 bsc#1280418). +- Update + patches.kernel.org/7.2.4-221-ceph-bound-num_export_targets-array-for-mds-inf.patch + (bsc#1012628 CVE-2026-89650 bsc#1280417). +- Update + patches.kernel.org/7.2.4-222-ceph-bound-xattr-value-length-in-__build_xattrs.patch + (bsc#1012628 CVE-2026-89649 bsc#1280434). +- Update + patches.kernel.org/7.2.4-223-ceph-cap-delegated-inode-count-in-ceph_parse_de.patch + (bsc#1012628 CVE-2026-89648 bsc#1280427). +- Update + patches.kernel.org/7.2.4-224-ceph-do-not-repeat-ceph_trim_dentries-if-no-pro.patch + (bsc#1012628 CVE-2026-89647 bsc#1280422). +- Update + patches.kernel.org/7.2.4-225-ceph-fix-leaked-inode-reference-on-writeback-ab.patch + (bsc#1012628 CVE-2026-89646 bsc#1280491). +- Update + patches.kernel.org/7.2.4-226-btrfs-drop-recovered-reloc-root-refs-on-recover.patch + (bsc#1012628 CVE-2026-89645 bsc#1281055). +- Update + patches.kernel.org/7.2.4-227-btrfs-fix-extent-map-leak-in-NOCOW-direct-I-O-w.patch + (bsc#1012628 CVE-2026-89644 bsc#1281054). +- Update ++++ 3765 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kernel-source/dtb-aarch64.changes ++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.383539/dtb-aarch64.changes dtb-armv6l.changes: same change dtb-armv7l.changes: same change dtb-riscv64.changes: same change kernel-64kb.changes: same change kernel-default.changes: same change kernel-docs.changes: same change kernel-kvmsmall.changes: same change kernel-lpae.changes: same change kernel-obs-build.changes: same change kernel-obs-qa.changes: same change kernel-pae.changes: same change kernel-source.changes: same change kernel-syms.changes: same change kernel-vanilla.changes: same change kernel-zfcpdump.changes: same change ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dtb-aarch64.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.505325970 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.507326054 +0200 @@ -17,7 +17,7 @@ %define srcversion 7.2 -%define patchversion 7.2.6 +%define patchversion 7.2.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -25,9 +25,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: dtb-aarch64 -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif dtb-armv6l.spec: same change dtb-armv7l.spec: same change dtb-riscv64.spec: same change ++++++ kernel-64kb.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.626331064 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.628331148 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-64kb -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif kernel-default.spec: same change ++++++ kernel-docs.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.690333758 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.692333842 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define build_html 1 %define build_pdf 0 @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-docs -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif ++++++ kernel-kvmsmall.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.718334937 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.720335021 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-kvmsmall -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif kernel-lpae.spec: same change ++++++ kernel-obs-build.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.771337168 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.773337252 +0200 @@ -19,7 +19,7 @@ #!BuildIgnore: post-build-checks -%define patchversion 7.2.6 +%define patchversion 7.2.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros @@ -38,23 +38,23 @@ %endif %endif %endif -%global kernel_package kernel%kernel_flavor-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb +%global kernel_package kernel%kernel_flavor-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559 %endif %if 0%{?rhel_version} %global kernel_package kernel %endif Name: kernel-obs-build -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif Summary: package kernel and initrd for OBS VM builds License: GPL-2.0-only Group: SLES -Provides: kernel-obs-build-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb +Provides: kernel-obs-build-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559 BuildRequires: coreutils BuildRequires: device-mapper BuildRequires: dracut ++++++ kernel-obs-qa.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.798338304 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.799338347 +0200 @@ -17,15 +17,15 @@ # needsrootforbuild -%define patchversion 7.2.6 +%define patchversion 7.2.7 %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-obs-qa -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif @@ -36,7 +36,7 @@ # kernel-obs-build must be also configured as VMinstall, but is required # here as well to avoid that qa and build package build parallel %if ! 0%{?qemu_user_space_build} -BuildRequires: kernel-obs-build-srchash-3d19f111ece9212f3590114d07b4ea06f11e6cdb +BuildRequires: kernel-obs-build-srchash-e601a2de7e673ef35afa7dc8af2866342bb61559 %endif BuildRequires: modutils ExclusiveArch: aarch64 armv6hl armv7hl ppc64le riscv64 s390x x86_64 ++++++ kernel-pae.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.828339567 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.830339652 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-pae -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif ++++++ kernel-source.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.855340704 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.856340746 +0200 @@ -17,8 +17,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define gcc_package gcc %define gcc_compiler gcc @@ -28,9 +28,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-source -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif ++++++ kernel-syms.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.892342262 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.894342346 +0200 @@ -16,15 +16,15 @@ # -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %include %_sourcedir/kernel-spec-macros Name: kernel-syms -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif ++++++ kernel-vanilla.spec ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:18.918343356 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:18.920343440 +0200 @@ -18,8 +18,8 @@ %define srcversion 7.2 -%define patchversion 7.2.6 -%define git_commit 3d19f111ece9212f3590114d07b4ea06f11e6cdb +%define patchversion 7.2.7 +%define git_commit e601a2de7e673ef35afa7dc8af2866342bb61559 %define variant %{nil} %define compress_modules zstd %define compress_vmlinux xz @@ -40,9 +40,9 @@ %(chmod +x %_sourcedir/{guards,apply-patches,check-for-config-changes,group-source-files.pl,split-modules,modversions,kabi.pl,arch-symbols,check-module-license,splitflist,mergedep,moddep,modflist,kernel-subpackage-build}) Name: kernel-vanilla -Version: 7.2.6 +Version: 7.2.7 %if 0%{?is_kotd} -Release: <RELEASE>.g3d19f11 +Release: <RELEASE>.ge601a2d %else Release: 0 %endif kernel-zfcpdump.spec: same change ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:19.078350092 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:19.081350218 +0200 @@ -1,6 +1,6 @@ -mtime: 1789455114 -commit: ebd4b6e3758e082507f7bdd81cd3012c90dbc1f65aec2894935933073aa48022 +mtime: 1790064153 +commit: ec88da9a4fb5f106bf4253160361208d003345bec30e583bfa0aa6d6364dfab3 url: https://src.opensuse.org/jirislaby/kernel-source -revision: ebd4b6e3758e082507f7bdd81cd3012c90dbc1f65aec2894935933073aa48022 +revision: ec88da9a4fb5f106bf4253160361208d003345bec30e583bfa0aa6d6364dfab3 trackingbranch: Kernel/stable ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-22 10:02:33.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ patches.kernel.org.tar.bz2 ++++++ ++++ 84331 lines of diff (skipped) ++++++ patches.suse.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch new/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch --- old/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,38 +0,0 @@ -From: Matthias Brugger <[email protected]> -Date: Sat, 9 Jan 2021 02:38:10 +0100 -Subject: regulator: mt6360: Add OF match table -Patch-mainline: Submitted, [email protected] -References: bsc#1180731 - -Binding documentation mentions that a compatible is required for the -MT6360 device node, but the driver doesn't provide a OF match table. - -Fixes: d321571d5e4c ("regulator: mt6360: Add support for MT6360 regulator") -Signed-off-by: Matthias Brugger <[email protected]> - ---- - drivers/regulator/mt6360-regulator.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - ---- a/drivers/regulator/mt6360-regulator.c -+++ b/drivers/regulator/mt6360-regulator.c -@@ -443,10 +443,19 @@ static const struct platform_device_id mt6360_regulator_id_table[] = { - }; - MODULE_DEVICE_TABLE(platform, mt6360_regulator_id_table); - -+#ifdef CONFIG_OF -+static const struct of_device_id mt6360_of_match[] = { -+ { .compatible = "mediatek,mt6360-regulator", }, -+ { /* sentinel */ }, -+}; -+MODULE_DEVICE_TABLE(of, mt6360_of_match); -+#endif -+ - static struct platform_driver mt6360_regulator_driver = { - .driver = { - .name = "mt6360-regulator", - .probe_type = PROBE_PREFER_ASYNCHRONOUS, -+ .of_match_table = of_match_ptr(mt6360_of_match), - }, - .probe = mt6360_regulator_probe, - .id_table = mt6360_regulator_id_table, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch new/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch --- old/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,40 +0,0 @@ -From: Matthias Brugger <[email protected]> -Date: Sat, 9 Jan 2021 02:41:09 +0100 -Subject: regulator: mt6358: Add OF match table -Patch-mainline: Submitted, [email protected] -References: bsc#1180731 - -The binding documentation mentions that a compatible is required for the -MT6358 device node. But the driver does not provide a OF match table. -This way auto-loading is broken as the MFD driver that registers the -device has a .of_compatible set which makes the platform .uevent -callback report a OF modalias, but that's not in the module. - -Fixes: f67ff1bd58f0 ("regulator: mt6358: Add support for MT6358 regulator") -Signed-off-by: Matthias Brugger <[email protected]> ---- - drivers/regulator/mt6358-regulator.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - ---- a/drivers/regulator/mt6358-regulator.c -+++ b/drivers/regulator/mt6358-regulator.c -@@ -730,10 +730,19 @@ static const struct platform_device_id mt6358_platform_ids[] = { - }; - MODULE_DEVICE_TABLE(platform, mt6358_platform_ids); - -+#ifdef CONFIG_OF -+static const struct of_device_id mt6358_of_match[] = { -+ { .compatible = "mediatek,mt6358-regulator", }, -+ { /* sentinel */ }, -+}; -+MODULE_DEVICE_TABLE(of, mt6358_of_match); -+#endif -+ - static struct platform_driver mt6358_regulator_driver = { - .driver = { - .name = "mt6358-regulator", - .probe_type = PROBE_PREFER_ASYNCHRONOUS, -+ .of_match_table = of_match_ptr(mt6358_of_match), - }, - .probe = mt6358_regulator_probe, - .id_table = mt6358_platform_ids, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch new/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch --- old/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,40 +0,0 @@ -From: Matthias Brugger <[email protected]> -Date: Sat, 9 Jan 2021 02:45:45 +0100 -Subject: regulator: mt6323: Add OF match table -Patch-mainline: Submitted, [email protected] -References: bsc#1180731 - -The binding documentation mentions that a compatible is required for the -MT6323 device node. But the driver does not provide a OF match table. -This way auto-loading is broken as the MFD driver that registers the -device has a .of_compatible set which makes the platform .uevent -callback report a OF modalias, but that's not in the module. - -Fixes: 2fdf82923618 ("regulator: mt6323: Add support for MT6323 regulator") -Signed-off-by: Matthias Brugger <[email protected]> ---- - drivers/regulator/mt6323-regulator.c | 9 +++++++++ - 1 file changed, 9 insertions(+) - ---- a/drivers/regulator/mt6323-regulator.c -+++ b/drivers/regulator/mt6323-regulator.c -@@ -406,10 +406,19 @@ static const struct platform_device_id mt6323_platform_ids[] = { - }; - MODULE_DEVICE_TABLE(platform, mt6323_platform_ids); - -+#ifdef CONFIG_OF -+static const struct of_device_id mt6323_of_match[] = { -+ { .compatible = "mediatek,mt6323-regulator", }, -+ { /* sentinel */ }, -+}; -+MODULE_DEVICE_TABLE(of, mt6323_of_match); -+#endif -+ - static struct platform_driver mt6323_regulator_driver = { - .driver = { - .name = "mt6323-regulator", - .probe_type = PROBE_PREFER_ASYNCHRONOUS, -+ .of_match_table = of_match_ptr(mt6323_of_match), - }, - .probe = mt6323_regulator_probe, - .id_table = mt6323_platform_ids, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch new/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch --- old/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch 1970-01-01 01:00:00.000000000 +0100 +++ new/patches.suse/ASoC-ux500-Parenthesize-MSP_-RX-TX-_CLKPOL_BIT-argume.patch 2026-09-22 08:44:29.000000000 +0200 @@ -0,0 +1,57 @@ +From: Sasha Levin <[email protected]> +Date: Sun, 13 Sep 2026 13:31:32 -0400 +Subject: ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments +Git-commit: 11fc0048a6930f4fca44fe3bd16a0023e78846a2 +Patch-mainline: v7.3-rc4 +References: git-fixes + +arm allmodconfig fails to build with gcc: + + In file included from sound/soc/ux500/ux500_msp_i2s.c:20: + sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses + around arithmetic in operand of '^' [-Werror=parentheses] + sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro + 'MSP_TX_CLKPOL_BIT' + cc1: all warnings being treated as errors + +The macros never parenthesized their argument: + + #define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT) + +That went unnoticed while every caller passed a plain variable, but +configure_protocol() now passes an XOR expression, which binds as +"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly +complains. + +No functional change: tx_clk_pol and rx_clk_pol only ever hold +MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a +bool, so masking before or after the XOR gives the same 0/1 result. +Parenthesize the argument anyway - it fixes the build and stops the +macros from silently mis-evaluating a future composite argument. + +Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration") +Reported-by: kernel test robot <[email protected]> +Closes: https://lore.kernel.org/oe-kbuild-all/[email protected]/ +Assisted-by: LLM +Signed-off-by: Sasha Levin <[email protected]> +Reviewed-by: Linus Walleij <[email protected]> +Link: https://patch.msgid.link/[email protected] +Signed-off-by: Mark Brown <[email protected]> +Acked-by: Jiri Slaby <[email protected]> +--- + sound/soc/ux500/ux500_msp_i2s.h | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/sound/soc/ux500/ux500_msp_i2s.h ++++ b/sound/soc/ux500/ux500_msp_i2s.h +@@ -147,8 +147,8 @@ enum msp_direction { + #define RCKPOL_MASK BIT(0) + #define TCKPOL_MASK BIT(0) + #define SPICKM_MASK (BIT(1) | BIT(0)) +-#define MSP_RX_CLKPOL_BIT(n) ((n & RCKPOL_MASK) << RCKPOL_SHIFT) +-#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT) ++#define MSP_RX_CLKPOL_BIT(n) (((n) & RCKPOL_MASK) << RCKPOL_SHIFT) ++#define MSP_TX_CLKPOL_BIT(n) (((n) & TCKPOL_MASK) << TCKPOL_SHIFT) + + #define P1ELEN_SHIFT 0 + #define P1FLEN_SHIFT 3 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch --- old/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/powerpc-Do-not-restore-KUAP-in-arch_exit_to_user_mode_prepare.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,116 +0,0 @@ -From: "Ritesh Harjani (IBM)" <[email protected]> -Date: Sun, 30 Aug 2026 20:24:30 +0530 -Subject: powerpc: Do not restore KUAP in arch_exit_to_user_mode_prepare() -References: bsc#1277802 ltc#222379 -Git-commit: c2549d749539487239475fbc8c614a1f9244d655 -Patch-mainline: v7.3 or v7.3-rc3 (next release) - -KUAP means kernel cannot touch user memory unless it explicitly is -enabled. In the kernel it should stay AMR_KUAP_BLOCKED. While returning -to userspace just before RFI, kernel should restore the user AMR value -back. - -Looks like GENERIC_ENTRY might be treating arch_exit_to_user_mode_prepare() -as the last architecture step before returning to userspace. -commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") -therefore called kuap_user_restore() from that hook. But on PowerPC that -is too early. After irqentry_exit() / syscall_exit_to_user_mode() we -still run platform specific exit routines. - -e.g. code snippets showing both exception handling and system call -handling as the callers of function arch_exit_to_user_mode_prepare() -which does kuap_user_restore(). The below path shows that calling -kuap_user_restore() is too early when called from -arch_exit_to_user_mode_prepare(). - -Exception handling in exceptions-64s.S -======================================= - -bl CFUNC(do_page_fault) - ..DEFINE_INTERRUPT_HANDLER_ASYNC(do_page_fault) - arch_interrupt_async_enter_prepare(regs); - state = irqentry_enter(regs); - instrumentation_begin(); - irq_enter_rcu(); - handler(regs); - nap_adjust_return(regs); - irq_exit_rcu(); - instrumentation_end(); - arch_interrupt_async_exit_prepare(regs); - irqentry_exit(regs, state); <<< too early - irqentry_exit_to_user_mode() - __exit_to_user_mode_prepare(regs, EXIT_TO_USER_MODE_WORK_IRQ); - arch_exit_to_user_mode_prepare(regs, ti_work); <<< too early -b interrupt_return_srr - .. bl CFUNC(interrupt_exit_user_prepare) <<< already calls kuap_user_restore - -prep_irq_for_enabled_exit() retry can run kernel code with IRQs on. So -only when that routine is fully finished is when the user KUAP should be -fully restored which interrupt_exit_user_prepare() already takes care of -before returning. - -Similarly for system call handling in interrupt_64.S -====================================================== - - bl CFUNC(system_call_exception) - -.Lsyscall_exit: - addi r4,r1,STACK_INT_FRAME_REGS - li r5,0 /* !scv */ - bl CFUNC(syscall_exit_prepare) - .. kuap_assert_locked(); - syscall_exit_to_user_mode(regs); <<< too early - syscall_exit_to_user_mode_prepare(regs); <<< too early - kuap_user_restore(regs); <<< already calls - -syscall_exit_prepare(), which can enable IRQs, replay a pending -interrupt, and only then rfi. Those functions already restore KUAP -immediately before rfi. - -Note that if we restore the user AMR too early like in the current code -as shown from the code snippets above, then we get the following warning -when CONFIG_PPC_KUAP_DEBUG is enabled: - WARNING: arch/powerpc/include/asm/book3s/64/kup.h:293 at interrupt_exit_user_prepare+0x1a0/0x1c0 - Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) - TRAP: 0700 - LR: c00000000000d8d4 CTR: c0000000021fe500 - MSR: <SF,EE,ME,IR,DR,RI,LE> CR: 44000804 XER: 20040000 - interrupt_exit_user_prepare+0x1a0/0x1c0 - interrupt_return_srr_user+0x8/0x12c - -Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") -Fixes: 02565a782c1ee ("powerpc: Introduce syscall exit arch functions") -Signed-off-by: Ritesh Harjani (IBM) <[email protected]> -Tested-by: Venkat Rao Bagalkote <[email protected]> -Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> -Signed-off-by: Madhavan Srinivasan <[email protected]> -Link: https://patch.msgid.link/52fee44fd23acf8e1c024ace668728e626a783a8.1788101609.git.ritesh.l...@gmail.com -Acked-by: Michal Suchanek <[email protected]> ---- - arch/powerpc/include/asm/entry-common.h | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/arch/powerpc/include/asm/entry-common.h b/arch/powerpc/include/asm/entry-common.h -index c5adb5006361..94083516df57 100644 ---- a/arch/powerpc/include/asm/entry-common.h -+++ b/arch/powerpc/include/asm/entry-common.h -@@ -515,8 +515,14 @@ static inline void arch_exit_to_user_mode_prepare(struct pt_regs *regs, - #ifdef CONFIG_PPC_TRANSACTIONAL_MEM - local_paca->tm_scratch = regs->msr; - #endif -- /* Restore user access locks last */ -- kuap_user_restore(regs); -+ /* -+ * Do not restore KUAP here. Generic entry might treat this as the last -+ * arch step before userspace but PowerPC still has kernel work after -+ * irqentry_exit()/syscall_exit_to_user_mode() i.e. in -+ * interrupt_exit_user_prepare() / syscall_exit_prepare() may enable -+ * IRQs and retry. Those functions restore KUAP immediately before rfi, -+ * which is where it should belong. -+ */ - } - - #define arch_exit_to_user_mode_prepare arch_exit_to_user_mode_prepare --- -2.55.0 - diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch --- old/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/powerpc-Don-t-drop-_TIF_RESTOREALL-on-syscall-restart.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,101 +0,0 @@ -From: "Ritesh Harjani (IBM)" <[email protected]> -Date: Sat, 29 Aug 2026 09:49:00 +0530 -Subject: powerpc: Don't drop _TIF_RESTOREALL on syscall restart -References: bsc#1277802 ltc#222379 -Git-commit: c7585b8e99ad97a0f5dd21e45c90a33aeab0d92b -Patch-mainline: v7.3 or v7.3-rc3 (next release) - -So the syscall return sequence is as follows: -A syscall return to userspace is prepared and then a short asm sequence -that actually does the RFI. Note that this asm range is restartable i.e. -EE is still on, so an interrupt (e.g. decrementer or external interrupt) -can hit while SRR/GPRs are being loaded. This is defined via: - -RESTART_TABLE(.Lsyscall_rst_start, .Lsyscall_rst_end, syscall_restart) - -This restart table then sends us to syscall_restart rather than resuming -in the middle of the RFI. The same stub is also used if irq_happened -already has a pending bit (soft-masked irq that has not been replayed -yet (PowerPC special case of local_irq_disable())). - -Here is a bit of a flow of sequence of code to visualize: - syscall_exit_prepare - decide full-GPR restore (_TIF_RESTOREALL) for signal, - rt_sigreturn or syscall trace - save that in regs->exit_result and return it in r3 - | - v - .Lsyscall_rst_start .. _end EE still on - irq_happened set or interrupt in this range? - | no | yes - v v - cmpdi r3,0 syscall_exit_restart - restore all / zero replay irq, try exit again - volatiles; RFI must return flags in r3 - again for the same cmpdi - -Now r3 after prepare is the flags word, not the actual syscall return. A nested -interrupt clobbers it, so the restart stub reloads RESULT into r3 and the -C handler (syscall_exit_restart()) should put the flags back (because later asm -checks whether r3 returned from C has _TIF_RESTOREALL set or not): - cmpdi r3, 0 - bne .Lsyscall_restore_regs - -Note that syscall_exit_restart() already ORs any new _TIF_RESTOREALL into -exit_result, but then it only returns the new sample and not the full -regs->exit_result. - -That sample could be often 0 even when restore-all is still required: - - - rt_sigreturn / syscall trace set the bit in prepare's local - ret and in exit_result. They never set exit_flags, which is - what restart samples. - - - a signal does set exit_flags but restart clears it. A - second pass through the stub then returns 0 while - exit_result still has the bit. - -The asm as mentioned earlier then treats r3==0 as the fast path and -zeros r0/r4-r12. That means the userspace that needed the full register -set could SIGSEGVs, (which could happen often in ld64.so.2 like while -doing a parallel kernel build as reported by Venkat). - -So we should instead return the accumulated exit_result, like how we do -in interrupt_exit_user_restart(). Note that prior to this commit -263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace") -we were returning regs->exit_result from syscall_exit_restart(), but -this commit changed that behaviour. - -Fixes: 263e5159e00a ("powerpc: Fix exit_flags field placement in pt_regs for ptrace") -Reported-by: Venkat Rao Bagalkote <[email protected]> -Closes: https://lore.kernel.org/all/[email protected]/ -Signed-off-by: Ritesh Harjani (IBM) <[email protected]> -Tested-by: Amit Machhiwal <[email protected]> -Tested-by: Shrikanth Hegde <[email protected]> -Tested-by: Venkat Rao Bagalkote <[email protected]> -Reviewed-by: Amit Machhiwal <[email protected]> -Reviewed-by: Shrikanth Hegde <[email protected]> -Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> -Signed-off-by: Madhavan Srinivasan <[email protected]> -Link: https://patch.msgid.link/10c86c909f870d90b3094f76b692b44ebe9caeac.1787976185.git.ritesh.l...@gmail.com -Acked-by: Michal Suchanek <[email protected]> ---- - arch/powerpc/kernel/interrupt.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/arch/powerpc/kernel/interrupt.c b/arch/powerpc/kernel/interrupt.c -index 5b88bf72786c..55f9c0c9922a 100644 ---- a/arch/powerpc/kernel/interrupt.c -+++ b/arch/powerpc/kernel/interrupt.c -@@ -175,7 +175,7 @@ notrace unsigned long syscall_exit_restart(unsigned long r3, struct pt_regs *reg - current_thread_info()->exit_flags &= ~_TIF_RESTOREALL; - regs->exit_result |= ret; - -- return ret; -+ return regs->exit_result; - } - #endif - --- -2.55.0 - diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch --- old/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/powerpc-entry-Fix-double-accounting-of-user-time-on-interrupt-entry.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,97 +0,0 @@ -From: Aboorva Devarajan <[email protected]> -Date: Fri, 4 Sep 2026 08:28:30 +0530 -Subject: powerpc/entry: Fix double accounting of user time on interrupt entry -Git-commit: 11ae2e1dc58304a48816fc8ca4afa8f2ef9d1bdf -Patch-mainline: v7.3-rc3 -References: bsc#1277802 ltc#222379 - -Since the switch to generic entry, an interrupt from user mode -accounts user time twice: once in arch_interrupt_enter_prepare() -and again in arch_enter_from_user_mode(), which irqentry_enter() -invokes for the same interrupt: - - arch_interrupt_enter_prepare() - account_cpu_user_entry() /* first */ - irqentry_enter() - arch_enter_from_user_mode() - account_cpu_user_entry() /* second */ - -The second call charges the same interval again, because -account_cpu_user_entry() accumulates the time spent in user mode -since the last return to user space. - -The two calls come from the GENERIC_ENTRY preparation series, -where each step was a no-op on its own. Commit 09a9d3a8499d -("powerpc: introduce arch_enter_from_user_mode") added the hook -with the user-time accounting in it, but nothing called it yet. -Commit 893082ac769b ("powerpc: Prepare for IRQ entry exit") -copied interrupt_enter_prepare() verbatim into entry-common.h as -arch_interrupt_enter_prepare(); that copy was equally unused, as -handlers still called interrupt_enter_prepare(). - -Commit bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") -made both live. On the syscall side it did the full conversion: -system_call_exception() now accounts once through the hook via -syscall_enter_from_user_mode(), rather than calling -account_cpu_user_entry() directly. On the interrupt side it -switched the handler macros to arch_interrupt_enter_prepare() -followed by irqentry_enter(), which also runs the hook, but the -accounting in arch_interrupt_enter_prepare() was not removed to -match. The double accounting starts with that commit. - -With CONFIG_VIRT_CPU_ACCOUNTING_NATIVE=y this roughly doubles the -reported user time of any workload that takes interrupts. The -other accounting modes compile account_cpu_user_entry() to an -empty stub, so they are not affected. - -Remove the accounting from arch_interrupt_enter_prepare() and rely -on arch_enter_from_user_mode(), which already runs for both -syscalls and interrupts. The duplicate account_stolen_time() call -is removed the same way. - -On a pseries LPAR a busy loop reports 6s user time in 3s elapsed -(~210% CPU) before the fix, and 3s (~105% CPU) after it: - - $ python3 -c 'while True: pass' & - $ sleep 3; ps -p $! -o etime,time,pcpu - - ELAPSED TIME %CPU - Before 00:03 00:00:06 210 - After 00:03 00:00:03 105 - -A 50% load reports ~70% usr / 30% idle before the fix, and -~49% usr / 51% idle after it: - - $ taskset -c 6 stress-ng --cpu 1 --cpu-load 50 & - $ mpstat -P 6 1 - - CPU %usr %idle - Before 6 69.74 30.26 - After 6 48.51 50.50 - -Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") -Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> -Signed-off-by: Aboorva Devarajan <[email protected]> -Tested-by: Venkat Rao Bagalkote <[email protected]> -Reviewed-by: Amit Machhiwal <[email protected]> -Reviewed-by: Ritesh Harjani (IBM) <[email protected]> -Reviewed-by: Christophe Leroy (CS GROUP) <[email protected]> -Signed-off-by: Madhavan Srinivasan <[email protected]> -Link: https://patch.msgid.link/[email protected] - -Acked-by: Michal Suchanek <[email protected]> ---- - arch/powerpc/include/asm/entry-common.h | 2 -- - 1 file changed, 2 deletions(-) - ---- a/arch/powerpc/include/asm/entry-common.h -+++ b/arch/powerpc/include/asm/entry-common.h -@@ -222,8 +222,6 @@ static inline void arch_interrupt_enter_ - - if (user_mode(regs)) { - kuap_lock(); -- account_cpu_user_entry(); -- account_stolen_time(); - } else { - kuap_save_and_lock(regs); - /* diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch --- old/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/powerpc-entry-Fix-irq_soft_mask-corruption-on-replayed-interrupt-exit.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,99 +0,0 @@ -From: "Mukesh Kumar Chaurasiya (IBM)" <[email protected]> -Date: Fri, 4 Sep 2026 14:38:58 +0530 -Subject: powerpc/entry: Fix irq_soft_mask corruption on replayed interrupt - exit -References: bsc#1277802 ltc#222379 -Git-commit: 63a7531ca31f9f097d9cc1cc3fe86ae683cdabdd -Patch-mainline: v7.3 or v7.3-rc3 (next release) - -When __replay_soft_interrupts() replays a pending interrupt (e.g. -PACA_IRQ_DEC -> timer_interrupt), it calls the handler directly with a -synthetic pt_regs. The DEFINE_INTERRUPT_HANDLER_ASYNC wrapper around -each handler calls arch_interrupt_async_exit_prepare() on the way out, -which calls arch_interrupt_exit_prepare() -> local_irq_disable() -> -arch_local_irq_disable(), which does: - - irq_soft_mask_set(IRQS_DISABLED) /* 0x1 */ - -This unconditionally overwrites irq_soft_mask with IRQS_DISABLED (0x1), -stripping the IRQS_PMI_DISABLED (0x2) bit. The result is that -irq_soft_mask is 0x1 instead of IRQS_ALL_DISABLED (0x3) when the -handler returns to __replay_soft_interrupts(). - -For a normally-taken interrupt this is harmless: the next interrupt -always enters through arch_interrupt_enter_prepare() which -unconditionally sets irq_soft_mask to IRQS_ALL_DISABLED. But during -replay, next_interrupt() is called directly between replayed handlers -without going back through arch_interrupt_enter_prepare(), so the -stripped bit is never restored. next_interrupt() then fires a WARNING: - - WARNING: arch/powerpc/kernel/irq_64.c:75 - WARN_ON(irq_soft_mask_return() != IRQS_ALL_DISABLED) - -The warning was observed early in boot on a POWER10 pseries guest -during kmem_cache_init_late(), where a spinlock release triggers -interrupt replay that processes a pending timer interrupt. - -Debugger state confirming the bug: - Before timer_interrupt(®s): - irq_soft_mask = 0x3 (IRQS_ALL_DISABLED) correct - irq_happened = 0x41 (HARD_DIS|REPLAYING) correct - After timer_interrupt(®s) returns: - irq_soft_mask = 0x1 (IRQS_DISABLED) WRONG - PMI bit stripped - irq_happened = 0x41 unchanged - -The fix is to replace local_irq_disable() with hard_irq_disable(). - -hard_irq_disable() is the right primitive here for two reasons: - -1. On PPC64 (hw_irq.h:301) it calls irq_soft_mask_set_return(IRQS_ALL_DISABLED), - setting the soft mask to 0x3 (both IRQS_DISABLED and IRQS_PMI_DISABLED), - which preserves the PMI bit and fixes the WARNING. The additional - work it does (__hard_irq_disable(), PACA_IRQ_HARD_DIS |=) is - redundant but safe since both are already set at this point in the - exit path; the trace_hardirqs_off() inside is guarded by - if (!arch_irqs_disabled_flags(flags)) so it will not double-fire. - -2. On PPC32 (hw_irq.h:467) hard_irq_disable() maps to - arch_local_irq_disable() -> __hard_irq_disable(), which clears - MSR[EE] in hardware. This is exactly correct: PPC32 has no soft-mask - PACA mechanism, so the hardware disable is the right way to satisfy - irqentry_exit()'s requirement. This also fixes a build error on PPC32 - where irq_soft_mask_set() is only defined under CONFIG_PPC64: - - arch/powerpc/include/asm/entry-common.h:273: error: implicit - declaration of function 'irq_soft_mask_set' - - Using hard_irq_disable() requires no #ifdef and is consistent with - how the rest of the entry code (e.g. entry-common.h:463) handles the - same PPC32/PPC64 split. - -Fixes: 334f3f6d7a16 ("powerpc/entry: Disable interrupts before irqentry_exit") -Reported-by: Venkat Rao Bagalkote <[email protected]> -Closes: https://lore.kernel.org/all/[email protected]/ -Tested-by: Venkat Rao Bagalkote <[email protected]> -Reviewed-by: Shrikanth Hegde <[email protected]> -Signed-off-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]> -Signed-off-by: Madhavan Srinivasan <[email protected]> -Link: https://patch.msgid.link/[email protected] -Acked-by: Michal Suchanek <[email protected]> ---- - arch/powerpc/include/asm/entry-common.h | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/arch/powerpc/include/asm/entry-common.h b/arch/powerpc/include/asm/entry-common.h -index 94083516df57..80b07750b531 100644 ---- a/arch/powerpc/include/asm/entry-common.h -+++ b/arch/powerpc/include/asm/entry-common.h -@@ -270,7 +270,7 @@ static inline void arch_interrupt_exit_prepare(struct pt_regs *regs) - } - - /* irqentry_exit expects to be called with interrupts disabled */ -- local_irq_disable(); -+ hard_irq_disable(); - } - - static inline void arch_interrupt_async_enter_prepare(struct pt_regs *regs) --- -2.55.0 - diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch --- old/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,135 +0,0 @@ -From: Pedro Falcato <[email protected]> -Date: Thu, 13 Aug 2026 12:01:26 +0300 -Subject: x86/alternative: Exclude text poking against change_page_attr() -References: bsc#1271202 -Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git -Git-commit: e679ba0983757e9567aeda97cc35c99241d420ee -Patch-mainline: Queued in subsystem maintainer repository - ->From time to time, the following BUG can be observed[0]: - -> kernel BUG at arch/x86/kernel/alternative.c:2576! -> Oops: invalid opcode: 0000 [#1] SMP NOPTI -> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed 8c1795b03ec64f997e57a8ad38b1161e3b98da64 -> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022 -> RIP: 0010:__text_poke+0x2aa/0x450 -> Call Trace: -> <TASK> -> smp_text_poke_batch_finish+0x2a7/0x320 -> __static_call_transform+0xb7/0x220 -> arch_static_call_transform+0x5b/0xb0 -> __static_call_init+0xe9/0x270 -> static_call_module_notify+0x11f/0x150 -> notifier_call_chain+0x61/0xe0 -> blocking_notifier_call_chain_robust+0x63/0xc0 -> load_module+0x1c92/0x20c0 -> init_module_from_file+0xd8/0x140 -> idempotent_init_module+0x100/0x2f0 -> __x64_sys_finit_module+0x71/0xe0 -> do_syscall_64+0xe1/0x610 -> entry_SYSCALL_64_after_hwframe+0x76/0x7e - -which matches the following BUG_ON in alternative.c: - /* - * If something went wrong, crash and burn since recovery paths are not - * implemented. - */ - BUG_ON(!pages[0] || (cross_page_boundary && !pages[1])); - -This can happen if vmalloc_to_page() fails, for any reason. Such can happen -if text poking races with CPA, which can possibly result in the collapsing -of page tables (or breaking of PMD hugepages). It is not a problem for most -users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when -CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc -range, and can call set_memory_*() in parallel on it. This can happen to -race against __text_poke and cause havoc in vmalloc_to_page(). - -Fix it by excluding against CPA using the init_mm mmap read lock. - -[ dhansen: Fix up SoB ordering. The actual code flow here was: - Pedro=>Lorenzo=>Mike=>Me which is reflected in the SoB chain - now. I *believe* Mike simply picked up Lorenzo's update to - Pedro's post from the Link: ] - -Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support") -Reported-by: Jiri Slaby <[email protected]> -Reported-by: Steffen Dirkwinkel <[email protected]> -Signed-off-by: Pedro Falcato <[email protected]> -Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Co-developed-by: Lorenzo Stoakes (ARM) <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> -Signed-off-by: Dave Hansen <[email protected]> -Tested-by: Jiri Slaby <[email protected]> -Tested-by: Atish Patra <[email protected]> -Tested-by: Nikunj A Dadhania <[email protected]> -Cc:[email protected] -Link: https://bugzilla.opensuse.org/show_bug.cgi?id=1271202 [0] -Link: https://lore.kernel.org/linux-mm/[email protected]/ -Link: https://patch.msgid.link/[email protected] -Signed-off-by: Pedro Falcato <[email protected]> ---- - arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++++++++++++++--- - 1 file changed, 36 insertions(+), 3 deletions(-) - ---- a/arch/x86/kernel/alternative.c -+++ b/arch/x86/kernel/alternative.c -@@ -6,6 +6,9 @@ - #include <linux/vmalloc.h> - #include <linux/memory.h> - #include <linux/execmem.h> -+#include <linux/cleanup.h> -+#include <linux/kgdb.h> -+#include <linux/mmap_lock.h> - - #include <asm/text-patching.h> - #include <asm/insn.h> -@@ -2543,6 +2546,38 @@ static void text_poke_memset(void *dst, - - typedef void text_poke_f(void *dst, const void *src, size_t len); - -+static void __poke_vmalloc_pages(struct page **pages, void *addr, -+ bool cross_page_boundary) -+{ -+ pages[0] = vmalloc_to_page(addr); -+ if (cross_page_boundary) -+ pages[1] = vmalloc_to_page(addr + PAGE_SIZE); -+} -+ -+static void poke_vmalloc_pages(struct page **pages, void *addr, -+ bool cross_page_boundary) -+{ -+ if (in_dbg_master()) { -+ /* -+ * If called from kgdb cannot sleep, but all other CPUs stopped -+ * anyway so safe to proceed without locks -+ */ -+ __poke_vmalloc_pages(pages, addr, cross_page_boundary); -+ } else { -+ /* -+ * execmem ROX ranges are shared between modules and can be -+ * collapsed to huge PMD entries, and this collapse can happen -+ * concurrently with a racing set_memory_rox(). -+ * -+ * Prevent vmalloc_to_page() from racing by acquiring an -+ * init_mm read lock which pairs with the init_mm write lock in -+ * cpa_collapse_large_pages(). -+ */ -+ guard(mmap_read_lock)(&init_mm); -+ __poke_vmalloc_pages(pages, addr, cross_page_boundary); -+ } -+} -+ - static void *__text_poke(text_poke_f func, void *addr, const void *src, size_t len) - { - bool cross_page_boundary = offset_in_page(addr) + len > PAGE_SIZE; -@@ -2560,9 +2595,7 @@ static void *__text_poke(text_poke_f fun - BUG_ON(!after_bootmem); - - if (!core_kernel_text((unsigned long)addr)) { -- pages[0] = vmalloc_to_page(addr); -- if (cross_page_boundary) -- pages[1] = vmalloc_to_page(addr + PAGE_SIZE); -+ poke_vmalloc_pages(pages, addr, cross_page_boundary); - } else { - pages[0] = virt_to_page(addr); - WARN_ON(!PageReserved(pages[0])); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch --- old/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-mm-Fix-and-document-DEBUG_PAGEALLOC.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,198 +0,0 @@ -From: Peter Zijlstra <[email protected]> -Date: Wed, 29 Jul 2026 13:08:10 +0200 -Subject: x86/mm: Fix and document DEBUG_PAGEALLOC -References: bsc#1271202 -Git-commit: 7da514d819a0afb148634aac92b3d190f34947c3 -Patch-mainline: v7.3-rc1 - -It turns out that commit 5fce67641a3e ("x86/mm/pat: Don't gate -cpa_lock on debug_pagealloc_enabled()") was a little too quick to -remove the debug_pagealloc exception for cpa_lock. - -Notably __kernel_map_pages() is used by the page-allocator from any -context the page-allocator itself is used, which violates the cpa_lock -rules. - -Re-instate the exception, except make it specific to the -__kernel_map_pages() such that any other cpa() usage is still fully -serialized by cpa_lock. Also note that since cpa() should not be used -on memory that isn't allocated, the page-allocator locking and cpa are -infact mutually exclusive and all cpa usage in fully serialized. - -Add a comment explaining this and other 'funnies' surrounding -DEBUG_PAGEALLOC, including how pgd_lock is not affected and the TLB -trickery. - -Fixes: 5fce67641a3e ("x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled()") -Signed-off-by: Peter Zijlstra (Intel) <[email protected]> -Link: https://patch.msgid.link/[email protected] -Signed-off-by: Jiri Slaby <[email protected]> ---- - arch/x86/mm/pat/set_memory.c | 80 +++++++++++++++++++++++++++++++------------ - 1 file changed, 58 insertions(+), 22 deletions(-) - ---- a/arch/x86/mm/pat/set_memory.c -+++ b/arch/x86/mm/pat/set_memory.c -@@ -68,11 +68,12 @@ static const int cpa_warn_level = CPA_PR - */ - static DEFINE_SPINLOCK(cpa_lock); - --#define CPA_FLUSHTLB 1 --#define CPA_ARRAY 2 --#define CPA_PAGES_ARRAY 4 --#define CPA_NO_CHECK_ALIAS 8 /* Do not search for aliases */ --#define CPA_COLLAPSE 16 /* try to collapse large pages */ -+#define CPA_FLUSHTLB 0x01 -+#define CPA_ARRAY 0x02 -+#define CPA_PAGES_ARRAY 0x04 -+#define CPA_NO_CHECK_ALIAS 0x08 /* Do not search for aliases */ -+#define CPA_COLLAPSE 0x10 /* try to collapse large pages */ -+#define CPA_DEBUG_PAGEALLOC 0x20 - - static inline pgprot_t cachemode2pgprot(enum page_cache_mode pcm) - { -@@ -2007,6 +2008,7 @@ static int __change_page_attr_set_clr(st - { - unsigned long numpages = cpa->numpages; - unsigned long rempages = numpages; -+ bool lock = true; - int ret = 0; - - /* -@@ -2016,6 +2018,29 @@ static int __change_page_attr_set_clr(st - !cpa->force_split) - return ret; - -+ /* -+ * DEBUG_PAGEALLOC is special; it is called from any context the -+ * page-allocator is, which violates the normal cpa_lock locking -+ * rules. -+ * -+ * However, since it is part of the page-allocator, things are still -+ * properly serialized by the page-allocator locking and the fact that -+ * when a page is owned by the page-allocator, it isn't owned by -+ * anybody else. That is, you *SHOULD NOT* be calling cpa() on memory -+ * that isn't allocated. -+ * -+ * Additionally, DEBUG_PAGEALLOC ensures (per probe_page_size_mask()) -+ * that the kernel mapping is 4k pages, therefore there are no large -+ * pages to split/collapse. -+ * -+ * Furthermore, the page-allocator strictly manages pages that -+ * *exist*, avoiding pgd_lock. -+ * -+ * Therefore, it is safe to not take cpa_lock. -+ */ -+ if (debug_pagealloc_enabled() && (cpa->flags & CPA_DEBUG_PAGEALLOC)) -+ lock = false; -+ - while (rempages) { - /* - * Store the remaining nr of pages for the large page -@@ -2026,9 +2051,12 @@ static int __change_page_attr_set_clr(st - if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY)) - cpa->numpages = 1; - -- spin_lock(&cpa_lock); -- ret = __change_page_attr(cpa, primary); -- spin_unlock(&cpa_lock); -+ if (lock) { -+ guard(spinlock)(&cpa_lock); -+ ret = __change_page_attr(cpa, primary); -+ } else { -+ ret = __change_page_attr(cpa, primary); -+ } - if (ret) - goto out; - -@@ -2607,7 +2635,7 @@ int set_pages_rw(struct page *page, int - return set_memory_rw(addr, numpages); - } - --static int __set_pages_p(struct page *page, int numpages) -+static int __set_pages_p(struct page *page, int numpages, unsigned int cpa_flags) - { - unsigned long tempaddr = (unsigned long) page_address(page); - struct cpa_data cpa = { .vaddr = &tempaddr, -@@ -2615,7 +2643,7 @@ static int __set_pages_p(struct page *pa - .numpages = numpages, - .mask_set = __pgprot(_PAGE_PRESENT | _PAGE_RW), - .mask_clr = __pgprot(0), -- .flags = CPA_NO_CHECK_ALIAS }; -+ .flags = CPA_NO_CHECK_ALIAS | cpa_flags }; - - /* - * No alias checking needed for setting present flag. otherwise, -@@ -2626,7 +2654,7 @@ static int __set_pages_p(struct page *pa - return __change_page_attr_set_clr(&cpa, 1); - } - --static int __set_pages_np(struct page *page, int numpages) -+static int __set_pages_np(struct page *page, int numpages, unsigned int cpa_flags) - { - unsigned long tempaddr = (unsigned long) page_address(page); - struct cpa_data cpa = { .vaddr = &tempaddr, -@@ -2634,7 +2662,7 @@ static int __set_pages_np(struct page *p - .numpages = numpages, - .mask_set = __pgprot(0), - .mask_clr = __pgprot(_PAGE_PRESENT | _PAGE_RW | _PAGE_DIRTY), -- .flags = CPA_NO_CHECK_ALIAS }; -+ .flags = CPA_NO_CHECK_ALIAS | cpa_flags }; - - /* - * No alias checking needed for setting not present flag. otherwise, -@@ -2647,20 +2675,20 @@ static int __set_pages_np(struct page *p - - int set_direct_map_invalid_noflush(struct page *page) - { -- return __set_pages_np(page, 1); -+ return __set_pages_np(page, 1, 0); - } - - int set_direct_map_default_noflush(struct page *page) - { -- return __set_pages_p(page, 1); -+ return __set_pages_p(page, 1, 0); - } - - int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid) - { - if (valid) -- return __set_pages_p(page, nr); -+ return __set_pages_p(page, nr, 0); - -- return __set_pages_np(page, nr); -+ return __set_pages_np(page, nr, 0); - } - - #ifdef CONFIG_DEBUG_PAGEALLOC -@@ -2679,15 +2707,23 @@ void __kernel_map_pages(struct page *pag - * and hence no memory allocations during large page split. - */ - if (enable) -- __set_pages_p(page, numpages); -+ __set_pages_p(page, numpages, CPA_DEBUG_PAGEALLOC); - else -- __set_pages_np(page, numpages); -+ __set_pages_np(page, numpages, CPA_DEBUG_PAGEALLOC); - - /* -- * We should perform an IPI and flush all tlbs, -- * but that can deadlock->flush only current cpu. -- * Preemption needs to be disabled around __flush_tlb_all() due to -- * CR3 reload in __native_flush_tlb(). -+ * We should perform an IPI and flush all tlbs, but that can -+ * deadlock, settle for a local flush. -+ * -+ * Not doing a global TLB flush means that remote CPUs will retain -+ * stale TLB entries. In case of P->NP (on free) this means the remote -+ * CPUs will not take the faults, making the debug scheme less -+ * reliable. On the NP->P (on alloc) this means the remote CPUs can -+ * take a spurious fault. However spurious_kernel_fault() will observe -+ * *_present() and fix it up. -+ * -+ * Preemption needs to be disabled around __flush_tlb_all() due to CR3 -+ * reload in __native_flush_tlb(). - */ - preempt_disable(); - __flush_tlb_all(); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch --- old/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-mm-pat-Don-t-gate-cpa_lock-on-debug_pagealloc_enabled.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,84 +0,0 @@ -From: "Mike Rapoport (Microsoft)" <[email protected]> -Date: Wed, 15 Jul 2026 17:45:19 +0300 -Subject: x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled() -References: bsc#1271202 -Git-commit: 5fce67641a3ed9a0782eaa228ddece526461a367 -Patch-mainline: v7.3-rc1 - -The splitting and merging of kernel page table mappings between small and -large is protected by cpa_lock. The merging is relatively new but the -splitting is ancient. - -The splitting has a locking optimization: since DEBUG_PAGEALLOC forces all -mappings to 4k, there are no large pages to split. So the code that *might* -cause a split can just skip the locking (and a few other things). - -This is entertaining, but it adds complexity and makes for weird locking -rules. Plus it's all for a debugging feature which makes the kernel super -slow in the first place. Optimizing something which is already super slow -and not used in production is not the best way to spend our complexity -budget. - -Stop gating cpa_lock on debug_pagealloc_enabled() to simplify the code -and the locking rules. - -[ dhansen: flesh out changelog ] - -Suggested-by: Dave Hansen <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> -Signed-off-by: Dave Hansen <[email protected]> -Link: https://patch.msgid.link/[email protected] -Link: https://lore.kernel.org/all/[email protected]/ - -Acked-by: Pedro Falcato <[email protected]> ---- - arch/x86/mm/pat/set_memory.c | 19 +++++++------------ - 1 file changed, 7 insertions(+), 12 deletions(-) - -diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c -index 45623d4c24c9..e9b408343c5d 100644 ---- a/arch/x86/mm/pat/set_memory.c -+++ b/arch/x86/mm/pat/set_memory.c -@@ -62,10 +62,9 @@ enum cpa_warn { - static const int cpa_warn_level = CPA_PROTECT; - - /* -- * Serialize cpa() (for !DEBUG_PAGEALLOC which uses large identity mappings) -- * using cpa_lock. So that we don't allow any other cpu, with stale large tlb -- * entries change the page attribute in parallel to some other cpu -- * splitting a large page entry along with changing the attribute. -+ * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with -+ * stale large tlb entries, to change the page attribute in parallel to some -+ * other cpu splitting a large page entry along with changing the attribute. - */ - static DEFINE_SPINLOCK(cpa_lock); - -@@ -1234,11 +1233,9 @@ static int split_large_page(struct cpa_data *cpa, pte_t *kpte, - { - struct ptdesc *ptdesc; - -- if (!debug_pagealloc_enabled()) -- spin_unlock(&cpa_lock); -+ spin_unlock(&cpa_lock); - ptdesc = pagetable_alloc(GFP_KERNEL, 0); -- if (!debug_pagealloc_enabled()) -- spin_lock(&cpa_lock); -+ spin_lock(&cpa_lock); - if (!ptdesc) - return -ENOMEM; - -@@ -2022,11 +2019,9 @@ static int __change_page_attr_set_clr(struct cpa_data *cpa, int primary) - if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY)) - cpa->numpages = 1; - -- if (!debug_pagealloc_enabled()) -- spin_lock(&cpa_lock); -+ spin_lock(&cpa_lock); - ret = __change_page_attr(cpa, primary); -- if (!debug_pagealloc_enabled()) -- spin_unlock(&cpa_lock); -+ spin_unlock(&cpa_lock); - if (ret) - goto out; - - diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,136 +0,0 @@ -From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Thu, 13 Aug 2026 12:01:25 +0300 -Subject: x86/mm/pat: Acquire init_mm read lock on attribute change to avoid - UAF -References: bsc#1271202 -Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git -Git-commit: 884801a901bd340c44a202e2ef5c29b48e3a4d93 -Patch-mainline: Queued in subsystem maintainer repository - -A previous commit protected against races between ptdump and CPA collapse, -however one still exists between attribute changes and collapse as reported -by Denis V. Lunev (linked). - -When an attribute change arises, a lockless page table walker obtains a PTE -entry, which is later written to via set_pte_atomic(): - -... --> change_page_attr_set_clr() --> __change_page_attr_set_clr() --> __change_page_attr() - -> _lookup_address_cpa() - -> lookup_address_in_pgd_attr() - -> [ lockless page table walker ] --> set_pte_atomic() - -There is nothing preventing a concurrent CPA collapse which can free the -PTE that was retrieved here, resulting in a use-after-free. - -With the mmap write lock taken on init_mm over CPA collapse, resolve this -race by acquiring an mmap read lock on init_mm over -__change_page_attr_set_clr(). - -This locks across the whole operation over which the walk and the PTE entry -write occurs, solving the race. - -It is safe to do this here, as no spinlocks are held upon entry to -__change_page_attr_set_clr(). - -However, the lock must not be held over an allocation, as allocation can -trigger reclaim and shrinkers may call into CPA recursively, making -deadlocks possible (init_mm -> ... -> fs_reclaim -> init_mm). - -A page table is allocated when a huge page needs to be split: - --> change_page_attr_set_clr() --> __change_page_attr_set_clr() --> __change_page_attr() --> split_large_page() -[ pagetable_alloc() ] --> __split_large_page() - -Avoid deadlocks by dropping the mmap lock across pagetable_alloc() in -split_large_page() and track whether this is needed by adding a new -'init_mm_read_locked' flag to struct cpa_data. - -This is safe as __split_large_page() (called with locks re-established) -revalidates that the page table entry is the same as it was prior to the -locks being dropped and __change_page_attr() repeats the entire page table -walk whenever a split occurs, so concurrent split and collapse are -accounted for. - -Concurrent ptdump is also safe as the lock is only dropped over page table -allocation during which time the page table has not yet been modified. - -The CPA_COLLAPSE flag is only set by set_memory_rox(), which exclusively -operates upon vmalloc ranges, and on x86 only within the module mapping -space. - -This is important, because some callers directly invoke -__change_page_attr_set_clr(), bypassing this lock. However, none of these -operate within the module mapping space. - -* cpa_process_alias() - a recursive helper called by - __change_page_attr_set_clr(). -* __set_memory_enc_pgtable() - operates on the direct mapping and (via - __vmbus_establish_gpadl()) the vmalloc mapping space. -* __set_pages_[n]p() - called by set_direct_map_[invalid, default, - valid]_noflush(), __kernel_map_pages() - operates on the direct map. -* kernel_[un]map_pages_in_pgd() - operates on EFI ranges. - -This work is based upon Denis V. Lunev's excellent analysis of the bug with -gratitude. - -[ dhansen: move to imperative voice in changelog ] - -Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") -Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> -Signed-off-by: Dave Hansen <[email protected]> -Tested-by: Atish Patra <[email protected]> -Tested-by: Nikunj A Dadhania <[email protected]> -Link: https://lore.kernel.org/all/[email protected]/ -Cc:[email protected] -Link: https://patch.msgid.link/[email protected] -Signed-off-by: Pedro Falcato <[email protected]> ---- - arch/x86/mm/pat/set_memory.c | 13 +++++++++++-- - 1 file changed, 11 insertions(+), 2 deletions(-) - ---- a/arch/x86/mm/pat/set_memory.c -+++ b/arch/x86/mm/pat/set_memory.c -@@ -50,7 +50,8 @@ struct cpa_data { - unsigned int flags; - unsigned int force_split : 1, - force_static_prot : 1, -- force_flush_all : 1; -+ force_flush_all : 1, -+ init_mm_read_locked : 1; - struct page **pages; - }; - -@@ -1255,7 +1256,11 @@ static int split_large_page(struct cpa_d - struct ptdesc *ptdesc; - - spin_unlock(&cpa_lock); -+ if (cpa->init_mm_read_locked) -+ mmap_read_unlock(&init_mm); - ptdesc = pagetable_alloc(GFP_KERNEL, 0); -+ if (cpa->init_mm_read_locked) -+ mmap_read_lock(&init_mm); - spin_lock(&cpa_lock); - if (!ptdesc) - return -ENOMEM; -@@ -2151,7 +2156,11 @@ static int change_page_attr_set_clr(unsi - cpa.curpage = 0; - cpa.force_split = force_split; - -- ret = __change_page_attr_set_clr(&cpa, 1); -+ /* Avoid race with concurrent CPA collapse. */ -+ cpa.init_mm_read_locked = true; -+ scoped_guard(mmap_read_lock, &init_mm) -+ ret = __change_page_attr_set_clr(&cpa, 1); -+ cpa.init_mm_read_locked = false; - - /* - * Check whether we really changed something: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch --- old/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,118 +0,0 @@ -From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Thu, 13 Aug 2026 12:01:24 +0300 -Subject: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF -References: bsc#1271202 -Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git -Git-commit: 4cfad2657c7c87b1172a9c343b74cf59b3769873 -Patch-mainline: Queued in subsystem maintainer repository - -x86 implements page attribute modification using its Change Page -Attributes (CPA) mechanism. - -This tracks properties of ranges such as cache mode through x86 page -attributes, and as part of that logic manipulates kernel page tables. - -Since commit 41d88484c71c ("x86/mm/pat: restore large ROX pages after -fragmentation") ranges of kernel page table entries can be collapsed into -huge page table entries as part of this logic. - -As part of this collapse, it frees the page tables which the collapsed -entries previously pointed to, and it does so without any relevant locks -being held to preclude concurrent kernel page table walkers. - -The only way this code can be reached is if CPA_COLLAPSE is specified, and -this is only set in set_memory_rox() via: - -set_memory_rox() --> change_page_attr_set_clr() --> cpa_flush() --> cpa_collapse_large_pages() - -Notable users of this are execmem and bpf when manipulating executable -mappings. - -However, this is problematic for ptdump as it walks ranges it does not own -and thus runs the risk of a use-after-free on page tables freed underneath -it. - -In addition, concurrent CPA collapse operations are possible which can also -cause races. - -Resolve the issue by acquiring the mmap write lock on init_mm across the -whole operation. - -It is safe to acquire a sleeping lock as all the callers invoke -set_memory_rox() from process context and in any case, -change_page_attr_set_clr() calls vm_unmap_alias() which ultimately takes a -mutex, disallowing atomic context here. - -Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation") -Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> -Signed-off-by: Dave Hansen <[email protected]> -Reviewed-by: Mike Rapoport (Microsoft) <[email protected]> -Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]> -Reviewed-by: David Hildenbrand (Arm) <[email protected]> -Reviewed-by: Dave Hansen <[email protected]> -Reviewed-by: Will Deacon <[email protected]> -Reviewed-by: David Carlier <[email protected]> -Tested-by: Atish Patra <[email protected]> -Tested-by: Nikunj A Dadhania <[email protected]> -Cc:[email protected] -Link: https://patch.msgid.link/[email protected] -Signed-off-by: Pedro Falcato <[email protected]> - ---- - arch/x86/mm/pat/set_memory.c | 15 ++++++++++++++- - include/linux/mmap_lock.h | 2 ++ - 2 files changed, 16 insertions(+), 1 deletion(-) - ---- a/arch/x86/mm/pat/set_memory.c -+++ b/arch/x86/mm/pat/set_memory.c -@@ -22,6 +22,7 @@ - #include <linux/cc_platform.h> - #include <linux/set_memory.h> - #include <linux/memregion.h> -+#include <linux/cleanup.h> - - #include <asm/e820/api.h> - #include <asm/processor.h> -@@ -410,7 +411,7 @@ static void __cpa_flush_tlb(void *data) - - static int collapse_large_pages(unsigned long addr, struct list_head *pgtables); - --static void cpa_collapse_large_pages(struct cpa_data *cpa) -+static void __cpa_collapse_large_pages(struct cpa_data *cpa) - { - unsigned long start, addr, end; - struct ptdesc *ptdesc, *tmp; -@@ -448,6 +449,18 @@ static void cpa_collapse_large_pages(str - spin_unlock(&cpa_lock); - } - -+static void cpa_collapse_large_pages(struct cpa_data *cpa) -+{ -+ /* -+ * Take the mmap write lock on init_mm to: -+ * - Avoid a use-after-free if raced by ptdump (which takes its own -+ * write lock on init_mm). -+ * - Serialise concurrent CPA walkers. -+ */ -+ scoped_guard(mmap_write_lock, &init_mm) -+ __cpa_collapse_large_pages(cpa); -+} -+ - static void cpa_flush(struct cpa_data *cpa, int cache) - { - unsigned int i; ---- a/include/linux/mmap_lock.h -+++ b/include/linux/mmap_lock.h -@@ -622,6 +622,8 @@ static inline void mmap_read_unlock(stru - DEFINE_GUARD(mmap_read_lock, struct mm_struct *, - mmap_read_lock(_T), mmap_read_unlock(_T)) - DEFINE_GUARD_COND(mmap_read_lock, _try, mmap_read_trylock(_T)) -+DEFINE_GUARD(mmap_write_lock, struct mm_struct *, -+ mmap_write_lock(_T), mmap_write_unlock(_T)) - - static inline void mmap_read_unlock_non_owner(struct mm_struct *mm) - { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch --- old/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 2026-09-15 08:50:07.000000000 +0200 +++ new/patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,129 +0,0 @@ -From: "Lorenzo Stoakes (ARM)" <[email protected]> -Date: Thu, 13 Aug 2026 12:01:27 +0300 -Subject: x86/mm/pat: Allocate split page tables as kernel page tables -References: bsc#1271202 -Git-repo: https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git -Git-commit: 0e33126d5def407397deaf617559a1a2a7f4b1ae -Patch-mainline: Queued in subsystem maintainer repository - -A PTE is allocated directly without going through the standard page table -allocation routines (such as pte_alloc_one_kernel()) when the CPA code -splits a large page (__split_large_page()). - -This means the page table constructor is never called nor is the page table -marked as a kernel page table. - -The former results in the folio associated with the page table not being -marked as a page table (__pagetable_ctor() is never called thus neither is -__folio_set_pgtable()) nor are statistics updated to reflect -it (lruvec_stat_add_folio() is never called). - -The latter issue of failing to mark the page table as a kernel page -table (ptdesc_set_kernel() is never called) is far more problematic. - -Since commit 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page -tables") kernel page table freeing has been batched and since the -subsequent commit e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries -for kernel address space") IOTLB cache entries for kernel page tables have -been invalidated upon being freed. - -Since split page tables are freed without this invalidation, the IOTLB can -contain stale entries for them. - -Resolve the issue by using the ordinary PTE allocation API at split time. - -This results in these kernel page tables invoking a page table constructor, -and thus requires a page table destructor. - -Destructors are not always present, like for early allocated direct map -page tables). Conditionally call pagetable_dtor_free() if the PG_table -folio flag for the ptdesc is set, otherwise we free the page table via -pagetable_free(). - -Regardless of which path is taken page tables marked as kernel page tables, -which now includes split page tables, take the correct route through -pagetable_free_kernel(). - -There is a user-visible side effect in that split page tables will appear -in nr_page_table_pages in /proc/vmstat (as do other kernel page tables -allocated after early boot), however this is a positive change. - -This issue started being markedly problematic after commit -5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") so -choose this as the Fixes target. - -[ dhansen: rephrase in imperative mood ] - -Fixes: 5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables") -Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> -Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> -Signed-off-by: Dave Hansen <[email protected]> -Acked-by: Vishal Moola <[email protected]> -Tested-by: Atish Patra <[email protected]> -Tested-by: Nikunj A Dadhania <[email protected]> -Cc:[email protected] -Link: https://patch.msgid.link/[email protected] -Signed-off-by: Pedro Falcato <[email protected]> ---- - arch/x86/mm/pat/set_memory.c | 25 ++++++++++++++++--------- - 1 file changed, 16 insertions(+), 9 deletions(-) - ---- a/arch/x86/mm/pat/set_memory.c -+++ b/arch/x86/mm/pat/set_memory.c -@@ -444,7 +444,15 @@ static void __cpa_collapse_large_pages(s - - list_for_each_entry_safe(ptdesc, tmp, &pgtables, pt_list) { - list_del(&ptdesc->pt_list); -- pagetable_free(ptdesc); -+ /* -+ * Only early alloc'd direct map should not be flagged PG_table -+ * here and those shouldn't be collapsed. However be abundantly -+ * cautious and handle the !PG_table case too. -+ */ -+ if (PageTable((ptdesc_page(ptdesc)))) -+ pagetable_dtor_free(ptdesc); -+ else -+ pagetable_free(ptdesc); - } - - spin_unlock(&cpa_lock); -@@ -1145,11 +1153,10 @@ set: - - static int - __split_large_page(struct cpa_data *cpa, pte_t *kpte, unsigned long address, -- struct ptdesc *ptdesc) -+ pte_t *pbase) - { - unsigned long lpaddr, lpinc, ref_pfn, pfn, pfninc = 1; -- struct page *base = ptdesc_page(ptdesc); -- pte_t *pbase = (pte_t *)page_address(base); -+ struct page *base = virt_to_page(pbase); - unsigned int i, level; - pgprot_t ref_prot; - bool nx, rw; -@@ -1253,20 +1260,20 @@ __split_large_page(struct cpa_data *cpa, - static int split_large_page(struct cpa_data *cpa, pte_t *kpte, - unsigned long address) - { -- struct ptdesc *ptdesc; -+ pte_t *pte; - - spin_unlock(&cpa_lock); - if (cpa->init_mm_read_locked) - mmap_read_unlock(&init_mm); -- ptdesc = pagetable_alloc(GFP_KERNEL, 0); -+ pte = pte_alloc_one_kernel(&init_mm); - if (cpa->init_mm_read_locked) - mmap_read_lock(&init_mm); - spin_lock(&cpa_lock); -- if (!ptdesc) -+ if (!pte) - return -ENOMEM; - -- if (__split_large_page(cpa, kpte, address, ptdesc)) -- pagetable_free(ptdesc); -+ if (__split_large_page(cpa, kpte, address, pte)) -+ pte_free_kernel(&init_mm, pte); - - return 0; - } ++++++ series.conf ++++++ ++++ 778 lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kernel-source/series.conf ++++ and /work/SRC/openSUSE:Factory/.kernel-source.new.383539/series.conf ++++++ source-timestamp ++++++ --- /var/tmp/diff_new_pack.LMGrMr/_old 2026-09-24 22:56:21.130436477 +0200 +++ /var/tmp/diff_new_pack.LMGrMr/_new 2026-09-24 22:56:21.133436603 +0200 @@ -1,4 +1,4 @@ -2026-09-15 06:50:07 +0000 -GIT Revision: 3d19f111ece9212f3590114d07b4ea06f11e6cdb +2026-09-22 08:00:24 +0000 +GIT Revision: e601a2de7e673ef35afa7dc8af2866342bb61559 GIT Branch: stable
