Skip to content

[RLC-10] Rebase Custom Changes to rlc-10/6.12.0-211.56.1.el10_2 - #1633

Merged
PlaidCat merged 80 commits into
rlc-10/6.12.0-211.56.1.el10_2from
jmaple_rlc-10/6.12.0-211.56.1.el10_2
Sep 22, 2026
Merged

PlaidCat merged 80 commits into
rlc-10/6.12.0-211.56.1.el10_2from
jmaple_rlc-10/6.12.0-211.56.1.el10_2

Conversation

@PlaidCat

Copy link
Copy Markdown
Collaborator

https://ciqinc.atlassian.net/browse/KERNEL-1619

Update process (This kernel CentOS base for 6.12.0-211.56.1.el10_2)

  • Rolling Release Rebase Process
  • Create rlc-10/6.12.0-211.56.1.el10_2 branch from rocky10_2
  • Cherry-pick all code from previous branch rlc-10/6.12.0-211.54.1.el10_2 into new branch (skipping unneeded code)
    • Fix conflicts as they arise
  • Build and Test

Rebase Log

Already on 'rlc-10/6.12.0-211.54.1.el10_2'
Already on 'jmaple_rlc-10/6.12.0-211.56.1.el10_2'
[rolling release update] Rolling Product:  rlc-10
[rolling release update] Checking out branch:  rlc-10/6.12.0-211.54.1.el10_2
[rolling release update] Gathering all the RESF kernel Tags
[rolling release update] Found 27 RESF kernel tags
[rolling release update] Checking out branch:  rocky10_2
[rolling release update] Gathering all the RESF kernel Tags
[rolling release update] Found 29 RESF kernel tags
[rolling release update] Common tag sha:  b'9d66c526c490'
"9d66c526c490a865388d2b124ae3262aff28916d Rebuild rocky10_2 with kernel-6.12.0-211.54.1.el10_2"
[rolling release update] Checking for FIPS protected changes between the common tag and HEAD
[rolling release update] Checking for FIPS protected changes
[rolling release update] Getting SHAS 9d66c526c490..HEAD
[rolling release update] Number of commits to check:  187
[rolling release update] Checking modifications of shas
[rolling release update] Checked 18 of 187 commits
[rolling release update] Checked 36 of 187 commits
[rolling release update] Checked 54 of 187 commits
[rolling release update] Checked 72 of 187 commits
[rolling release update] Checked 90 of 187 commits
[rolling release update] Checked 108 of 187 commits
[rolling release update] Checked 126 of 187 commits
[rolling release update] Checked 144 of 187 commits
[rolling release update] Checked 162 of 187 commits
[rolling release update] Checked 180 of 187 commits
[rolling release update] 0 of 187 commits have FIPS protected changes
[rolling release update] Checking out old rolling branch:  rlc-10/6.12.0-211.54.1.el10_2
[rolling release update] Finding the CIQ Kernel and Associated Upstream commits between the last resf tag and HEAD
[rolling release update] Getting SHAS 9d66c526c490..HEAD
[rolling release update] Last RESF tag sha:  b'9d66c526c490'
[rolling release update] Total commits in old branch: 94
[rolling release update] Checking out new base branch:  rocky10_2
[rolling release update] Finding the kernel version for the new rolling release
[rolling release update] New Branch to create: rlc-10/6.12.0-211.56.1.el10_2
[rolling release update] Creating new branch: rlc-10/6.12.0-211.56.1.el10_2
[rolling release update] Creating new branch for PR:  jmaple_rlc-10/6.12.0-211.56.1.el10_2
[rolling release update] Creating Map of all new commits from last rolling release fork
[rolling release update] Total commits in new branch: 186
[rolling release update] Checking if any of the commits from the old rolling release are already present in the new base branch
- Old commit 805208c92fc0 backported upstream e374b22e9b07
  Already in new base as e6b0f807c045: sctp: purge outqueue on stale COOKIE-ECHO handling
- Old commit 699dfd9326f1 backported upstream d82ba05263c6
  Already in new base as 89c10266c5dc: af_unix: Set gc_in_progress to true in unix_gc().
- Old commit f13d892962d1 backported upstream e5b31d988a41
  Already in new base as 3aefcc1d1cd7: af_unix: Give up GC if MSG_PEEK intervened.
- Old commit 4702f42a6b34 backported upstream 60e6489f8e3b
  Already in new base as 8845817e1e74: af_unix: Initialise scc_index in unix_add_edge().
[rolling release update] Found 4 duplicate commits to remove
[rolling release update] Removing duplicate commits:
  - 805208c92fc0425d607c0cee55e5a8adfce41561 sctp: purge outqueue on stale COOKIE-ECHO handling
  - 699dfd9326f1d72187c22dedc0a567b3d6b60d40 af_unix: Set gc_in_progress to true in unix_gc().
  - f13d892962d1f5ff9427da16b1420b2a65dd2c30 af_unix: Give up GC if MSG_PEEK intervened.
  - 4702f42a6b34c37cacad569342baff443406a599 af_unix: Initialise scc_index in unix_add_edge().
[rolling release update] Applying 90 remaining commits to the new branch
  [1/90] 0061817753fe github actions: Add kernelCI for rlc-10
  [2/90] 3f0eb566e015 github actions: Use trigger for kernelCI
  [3/90] d390949fdb0f github actions: Pin Checkout action to v6.0.2
  [4/90] ac95454bc4ee github actions: set make to `nproc` rather than hardcoded
  [5/90] f155e39daddc tools: hv: Enable debug logs for hv_kvp_daemon
  [6/90] f683882ef3ac dcache: export shrink_dentry_list() and add new helper d_dispose_if_unused()
  [7/90] 98665faf9e40 fuse: don't truncate cached, mutated symlink
  [8/90] fea8ddbd9306 fuse: add more control over cache invalidation behaviour
  [9/90] 781ae2efbf6e fuse: fix possibly missing fuse_copy_finish() call in fuse_notify()
  [10/90] 191acc86798b fs: fuse: add dev id to /dev/fuse fdinfo
  [11/90] ad3fbbba7b73 fuse: respect FOPEN_KEEP_CACHE on opendir
  [12/90] 9457659113b2 KVM: arm64: Reassign nested_mmus array behind mmu_lock
  [13/90] 8163a18ddc20 gve: move DQO rx buffer management related code to a new file
  [14/90] 96aaaa9a6adf gve: clean XDP queues in gve_tx_stop_ring_gqi
  [15/90] 4811bd56f3b2 gve: fix XDP allocation path in edge cases
  [16/90] 7d62660faedd gve: prevent ethtool ops after shutdown
  [17/90] c994e77ac4a5 gve: defer interrupt enabling until NAPI registration
  [18/90] 3871614009ad gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL
  [19/90] 095e29a894b4 gve: Update QPL page registration logic
  [20/90] bc9c82216ef5 gve: Enable reading max ring size from the device in DQO-QPL mode
  [21/90] 2aa7e8f62e7e gve: fix zero-length skb frag with header-split
  [22/90] 49db8b29f411 gve: bound DQO-QPL TX buffer count to the s16 free-list range
  [23/90] 3766909a80ab xfrm: nat_keepalive: avoid double free on send error
  [24/90] ddea5241b3b1 af_unix: Set error only when needed in unix_dgram_sendmsg().
[rolling release update] ERROR: Failed to cherry-pick commit ddea5241b3b15c7415c82e3e9169e9cfd250784b
error: could not apply ddea5241b3b1... af_unix: Set error only when needed in unix_dgram_sendmsg().
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [25/90] 2578b80b8f24 af_unix: Sort headers.
[rolling release update] ERROR: Failed to cherry-pick commit 2578b80b8f245632a170b9806c4e03f7e40e3ce7
error: could not apply 2578b80b8f24... af_unix: Sort headers.
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [26/90] 2b125277cdd2 af_unix: Move internal definitions to net/unix/.
[rolling release update] ERROR: Failed to cherry-pick commit 2b125277cdd2a58c0988d0a3e09fe4b62173b283
error: could not apply 2b125277cdd2... af_unix: Move internal definitions to net/unix/.
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [27/90] dc1b90fc89a4 net: unix: remove outdated BSD behavior comment in unix_release_sock()
[rolling release update] ERROR: Failed to cherry-pick commit dc1b90fc89a4785af9b7a631d0b37e800b75da9c
error: could not apply dc1b90fc89a4... net: unix: remove outdated BSD behavior comment in unix_release_sock()
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [28/90] d5b846424cae af_unix: Count cyclic SCC.
[rolling release update] ERROR: Failed to cherry-pick commit d5b846424caebc5a86032772a32f543e3434817d
error: could not apply d5b846424cae... af_unix: Count cyclic SCC.
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [29/90] 11dad4d18121 af_unix: Simplify GC state.
[rolling release update] ERROR: Failed to cherry-pick commit 11dad4d1812120ffefddf0288bb93561d32713e9
error: could not apply 11dad4d18121... af_unix: Simplify GC state.
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [30/90] b1c833225379 af_unix: Don't trigger GC from close() if unnecessary.
[rolling release update] ERROR: Failed to cherry-pick commit b1c8332253798fdb2a4b0ef2a61fcd80a2af3017
error: could not apply b1c833225379... af_unix: Don't trigger GC from close() if unnecessary.
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [31/90] dca8847ec171 af_unix: Don't call wait_for_unix_gc() on every sendmsg().
[rolling release update] ERROR: Failed to cherry-pick commit dca8847ec1714330e687457d2c85cd97da661332
error: could not apply dca8847ec171... af_unix: Don't call wait_for_unix_gc() on every sendmsg().
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [32/90] 8399231b7da6 af_unix: Refine wait_for_unix_gc().
[rolling release update] ERROR: Failed to cherry-pick commit 8399231b7da6f3988d48c411d3422b2989b96ddf
error: could not apply 8399231b7da6... af_unix: Refine wait_for_unix_gc().
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [33/90] d3d28f9fcb46 af_unix: Remove unix_tot_inflight.
[rolling release update] ERROR: Failed to cherry-pick commit d3d28f9fcb4630aab29764204946db0c55099e50
The previous cherry-pick is now empty, possibly due to conflict resolution.
If you wish to commit it anyway, use:

    git commit --allow-empty

Otherwise, please use 'git cherry-pick --skip'

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [34/90] ce33d4548baa af_unix: Consolidate unix_schedule_gc() and wait_for_unix_gc().
[rolling release update] ERROR: Failed to cherry-pick commit ce33d4548baa4ed3c253bca7701d045ab4d6ae54
error: could not apply ce33d4548baa... af_unix: Consolidate unix_schedule_gc() and wait_for_unix_gc().
hint: After resolving the conflicts, mark them with
hint: "git add/rm <pathspec>", then run
hint: "git cherry-pick --continue".
hint: You can instead skip this commit with "git cherry-pick --skip".
hint: To abort and get back to the state before "git cherry-pick",
hint: run "git cherry-pick --abort".
hint: Disable this message with "git config set advice.mergeConflict false"

[rolling release update] ========================================
[rolling release update] INTERACTIVE MODE: Merge conflict detected
[rolling release update] ========================================
[rolling release update] Please resolve or skip the merge conflict manually.
[rolling release update] To resolve:
[rolling release update]   1. Fix merge conflicts in the working directory
[rolling release update]   2. Stage resolved files: git add <files>
[rolling release update]   3. Complete cherry-pick: git cherry-pick --continue
[rolling release update]      (or commit manually if needed)
[rolling release update] To skip:
[rolling release update]   1. To skip this commit: git cherry-pick --skip
[rolling release update] When done:
[rolling release update]   Return here and press Enter to continue
[rolling release update] ========================================
[rolling release update] Press Enter when resolved (or type "stop"/"abort" to exit): [rolling release update] Cherry-pick resolved successfully, continuing...
  [35/90] c41528b02d10 sctp: fix auth_hmacs array size in struct sctp_cookie
  [36/90] 75c473aed1e1 openvswitch: defer tunnel netdev_put to RCU release
  [37/90] ce2d67e70573 netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
  [38/90] bb2fefa5fb37 openvswitch: vport: fix self-deadlock on release of tunnel ports
  [39/90] 6e9c5dcec9fe ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
  [40/90] 69121bd70ef3 fuse: rename to fuse_dev_end_requests and make non-static
  [41/90] abcd576e2d79 fuse: Move fuse_get_dev to header file
  [42/90] 7c8f9a853bbb fuse: Move request bits
  [43/90] 178b40008ff0 fuse: make args->in_args[0] to be always the header
  [44/90] 5e6ddf037762 fuse: {io-uring} Handle SQEs - register commands
  [45/90] 3a359cca064c fuse: Make fuse_copy non static
  [46/90] 52865b8992a7 fuse: Add fuse-io-uring handling into fuse_copy
  [47/90] c239edcd2510 fuse: {io-uring} Make hash-list req unique finding functions non-static
  [48/90] edbb576b6c38 fuse: Add io-uring sqe commit and fetch support
  [49/90] 1f3634945206 fuse: {io-uring} Handle teardown of ring entries
  [50/90] bbbd721b0b87 fuse: {io-uring} Make fuse_dev_queue_{interrupt,forget} non-static
  [51/90] 13aa7ef74011 fuse: Allow to queue fg requests through io-uring
  [52/90] c6252a360b4a fuse: Allow to queue bg requests through io-uring
  [53/90] eef5456e177c fuse: {io-uring} Prevent mount point hang on fuse-server termination
  [54/90] a06f6a71ab53 fuse: block request allocation until io-uring init is complete
  [55/90] f0f58a8d0ddd fuse: enable fuse-over-io-uring
  [56/90] 9cddbc05b02a fuse: prevent disabling io-uring on active connections
  [57/90] f3622211ddcb fuse: fix uring race condition for null dereference of fc
  [58/90] 0964cc50cfad fuse: fix possible deadlock if rings are never initialized
  [59/90] 6810905a6e68 fuse: removed unused function fuse_uring_create() from header
  [60/90] 653f9170684e fuse: {io-uring} Fix a possible req cancellation race
  [61/90] 210220ddf6e0 fuse: remove unneeded atomic set in uring creation
  [62/90] cb1462114967 fuse: missing copy_finish in fuse-over-io-uring argument copies
  [63/90] 7377cb99278e fuse: fix io-uring list corruption for terminated non-committed requests
  [64/90] 215a03e15322 fuse-uring: fix EFAULT clobber in fuse_uring_commit
  [65/90] bf9bd5bfe6e1 fuse-uring: fix data races on ring->ready
  [66/90] 98b8bc19c0fb fuse-uring: fix race between registration and connection abortion
  [67/90] 0d657e09938c fuse-uring: check connection abort during ring creation
  [68/90] 4106fd9b9327 fuse-uring: fix moving cancelled entry to ent_in_userspace list
  [69/90] dea72b80309f fuse-uring: end fuse_req on io-uring cancel task work
  [70/90] 1f9626c76ec7 fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
  [71/90] 7361129fbd01 fuse-uring: Avoid queue->stopped races and set/read that value under lock
  [72/90] f492f8b80f28 fuse-uring: make a fuse_req on SQE commit only findable after memcpy
  [73/90] 2d020c1edff1 fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
  [74/90] 5c0b678acb4d fuse: fix io-uring background queue dispatch on request completion
  [75/90] 8cd764fdbecf fuse-uring: clear ent->fuse_req in commit_fetch error path
  [76/90] 94486198079d fuse: fix missing barrier when checking io-uring readiness
  [77/90] 3fe903cde1a4 fuse: publish io-uring queues with release semantics
  [78/90] 4a795a9d2e04 fuse: copy request headers via a stack buffer for io-uring
  [79/90] b56bb892568d fuse: Fix the condition to enable over-io-uring
  [80/90] 58d9542a6732 configs: enable CONFIG_FUSE_IO_URING=y on x86_64 and aarch64
  [81/90] 31c2caf0e975 selftests: filesystems: Add functional test for the abort file in fusectl
  [82/90] 68b080975c7b selftests/fuse: adapt fuse_mnt to libfuse3 API
  [83/90] 2a06bd0881b8 selftests/fuse: add ACL_DONT_CACHE regression test
  [84/90] 4c67028d231b selftests/fuse: add FUSE io-uring integration test
  [85/90] b9e0efa0825c sctp: stream: fully roll back denied add-stream state
  [86/90] 50d2fe18a8a3 mpls: add seqcount to protect the platform_label{,s} pair
  [87/90] 53a0874bbf80 xfrm: ah6: validate routing header segments_left
  [88/90] 54ea82ea45bb net: tun: bound receive headroom
  [89/90] 7e54b626878b pppoe: reload header pointer after dev_hard_header()
  [90/90] 9379311d9999 sctp: prevent peer transport count overflow
[rolling release update] Successfully applied all 90 commits

BUILD

$ egrep -B 5 -A 5 "\[TIMER\]|^Starting Build" $(ls -t kbuild* | head -n1)
/mnt/code/kernel-src-tree-build
Running make mrproper...
  CLEAN   scripts/basic
  CLEAN   scripts/kconfig
  CLEAN   include/config include/generated
[TIMER]{MRPROPER}: 7s
x86_64 architecture detected, copying config
'configs/kernel-x86_64-rhel.config' -> '.config'
Setting Local Version for build
CONFIG_LOCALVERSION="-rocky10_2_rebuild-6f820739bb74"
Making olddefconfig
--
  HOSTCC  scripts/kconfig/util.o
  HOSTLD  scripts/kconfig/conf
#
# configuration written to .config
#
Starting Build
  GEN     arch/x86/include/generated/asm/orc_hash.h
  WRAP    arch/x86/include/generated/uapi/asm/bpf_perf_event.h
  WRAP    arch/x86/include/generated/uapi/asm/errno.h
  WRAP    arch/x86/include/generated/uapi/asm/fcntl.h
  WRAP    arch/x86/include/generated/uapi/asm/ioctl.h
--
  BTF [M] net/hsr/hsr.ko
  BTF [M] net/qrtr/qrtr.ko
  BTF [M] net/hsr/prp_dup_discard_test.ko
  BTF [M] virt/lib/irqbypass.ko
  BTF [M] net/qrtr/qrtr-mhi.ko
[TIMER]{BUILD}: 2356s
Making Modules
  SYMLINK /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/build
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/modules.order
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/modules.builtin
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/modules.builtin.modinfo
--
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/kernel/net/qrtr/qrtr.ko
  INSTALL /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/kernel/virt/lib/irqbypass.ko
  STRIP   /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/kernel/virt/lib/irqbypass.ko
  SIGN    /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+/kernel/virt/lib/irqbypass.ko
  DEPMOD  /lib/modules/6.12.0-rocky10_2_rebuild-6f820739bb74+
[TIMER]{MODULES}: 15s
Making Install
  INSTALL /boot
[TIMER]{INSTALL}: 19s
Checking kABI
kABI check passed
Setting Default Kernel to /boot/vmlinuz-6.12.0-rocky10_2_rebuild-6f820739bb74+ and Index to 2
Hopefully Grub2.0 took everything ... rebooting after time metrices
[TIMER]{MRPROPER}: 7s
[TIMER]{BUILD}: 2356s
[TIMER]{MODULES}: 15s
[TIMER]{INSTALL}: 19s
[TIMER]{TOTAL} 2400s
Rebooting in 10 seconds

KSelfTest

$ ./kernel-tools/kernel_auto_rebuild/get_kselftest_diff.sh
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.47.1.el10_2-ebd0384b8607+-1.log: 489 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.49.1.el10_2-3fc580e00781+-1.log: 491 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.54.1.el10_2-60f4ccb9409d+-1.log: 487 passed
selftest-6.12.0-jmaple_rlc-10_6.12.0-211.56.1.el10_2-a9a6f307c983+-1.log: 492 passed

Before: selftest-6.12.0-jmaple_rlc-10_6.12.0-211.54.1.el10_2-60f4ccb9409d+-1.log
After: selftest-6.12.0-jmaple_rlc-10_6.12.0-211.56.1.el10_2-a9a6f307c983+-1.log
Diff:
+ok 2 selftests: seccomp: seccomp_benchmark
+ok 52 selftests: net: txtimestamp.sh
+ok 5 selftests: damon: sysfs_update_schemes_tried_regions_wss_estimation.py
+ok 6 selftests: damon: damos_quota.py
+ok 7 selftests: timers: raw_skew

roxanan1996 and others added 30 commits September 21, 2026 13:49
Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
jira LE-3207
feature tools_hv
commit-author Shradha Gupta <shradhagupta@linux.microsoft.com>
commit a9c0b33

Allow the KVP daemon to log the KVP updates triggered in the VM
with a new debug flag(-d).
When the daemon is started with this flag, it logs updates and debug
information in syslog with loglevel LOG_DEBUG. This information comes
in handy for debugging issues where the key-value pairs for certain
pools show mismatch/incorrect values.
The distro-vendors can further consume these changes and modify the
respective service files to redirect the logs to specific files as
needed.

	Signed-off-by: Shradha Gupta <shradhagupta@linux.microsoft.com>
	Reviewed-by: Naman Jain <namjain@linux.microsoft.com>
	Reviewed-by: Dexuan Cui <decui@microsoft.com>
Link: https://lore.kernel.org/r/1744715978-8185-1-git-send-email-shradhagupta@linux.microsoft.com
	Signed-off-by: Wei Liu <wei.liu@kernel.org>
Message-ID: <1744715978-8185-1-git-send-email-shradhagupta@linux.microsoft.com>
(cherry picked from commit a9c0b33)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
…nused()

jira SECO-468
commit-author Luis Henriques <luis@igalia.com>
commit 395b955

Add and export a new helper d_dispose_if_unused() which is simply a wrapper
around to_shrink_list(), to add an entry to a dispose list if it's not used
anymore.

Also export shrink_dentry_list() to kill all dentries in a dispose list.

	Suggested-by: Miklos Szeredi <miklos@szeredi.hu>
	Signed-off-by: Luis Henriques <luis@igalia.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 395b955)
	Signed-off-by: Roxana Nicolescu <rnicolescu@ciq.com>
jira SECO-478
RFBugFix: FUSE
commit-author Miklos Szeredi <mszeredi@redhat.com>
commit b4c173d

Fuse allows the value of a symlink to change and this property is exploited
by some filesystems (e.g. CVMFS).

It has been observed, that sometimes after changing the symlink contents,
the value is truncated to the old size.

This is caused by fuse_getattr() racing with fuse_reverse_inval_inode().
fuse_reverse_inval_inode() updates the fuse_inode's attr_version, which
results in fuse_change_attributes() exiting before updating the cached
attributes

This is okay, as the cached attributes remain invalid and the next call to
fuse_change_attributes() will likely update the inode with the correct
values.

The reason this causes problems is that cached symlinks will be
returned through page_get_link(), which truncates the symlink to
inode->i_size.  This is correct for filesystems that don't mutate
symlinks, but in this case it causes bad behavior.

The solution is to just remove this truncation.  This can cause a
regression in a filesystem that relies on supplying a symlink larger than
the file size, but this is unlikely.  If that happens we'd need to make
this behavior conditional.

	Reported-by: Laura Promberger <laura.promberger@cern.ch>
	Tested-by: Sam Lewis <samclewis@google.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
Link: https://lore.kernel.org/r/20250220100258.793363-1-mszeredi@redhat.com
	Reviewed-by: Bernd Schubert <bschubert@ddn.com>
	Signed-off-by: Christian Brauner <brauner@kernel.org>
(cherry picked from commit b4c173d)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira SECO-478
RFBugFix: FUSE
commit-author Luis Henriques <luis@igalia.com>
commit 2396356
upstream-diff | conflict in fs/fuse/dir.c due to missing this piece:
       d701902 - fuse: return correct dentry for ->mkdir
       Which is a part of a larger changeset here that we're not going to
       take: https://lore.kernel.org/all/20250227013949.536172-1-neilb@suse.de/
       | Additionally this bumps the Kernel FUSE API minor version from 41
       to 44.  The interface into via fuse3 currently in Rocky 10.1 is
       limited to API 38 anyways at 3.16.2.
       | There is a build conflict due to a major rewrite of the d_revalidate
       calls which now includes the parent directory being passed.
       5be1fa8 Pass parent directory inode and expected name to ->d_revalidate()
       In this case we can use the dentry->i_sb because we only need the
       superblock for get_fuse_conn_super().

Currently userspace is able to notify the kernel to invalidate the cache
for an inode.  This means that, if all the inodes in a filesystem need to
be invalidated, then userspace needs to iterate through all of them and do
this kernel notification separately.

This patch adds the concept of 'epoch': each fuse connection will have the
current epoch initialized and every new dentry will have it's d_time set to
the current epoch value.  A new operation will then allow userspace to
increment the epoch value.  Every time a dentry is d_revalidate()'ed, it's
epoch is compared with the current connection epoch and invalidated if it's
value is different.

	Signed-off-by: Luis Henriques <luis@igalia.com>
	Tested-by: Laura Promberger <laura.promberger@cern.ch>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 2396356)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>

build fix: fuse: add more control over cache invalidation behaviour
jira SECO-478
BUGFIX: FUSE
commit-author Miklos Szeredi <mszeredi@redhat.com>
commit 0b563aa

In case of FUSE_NOTIFY_RESEND and FUSE_NOTIFY_INC_EPOCH fuse_copy_finish()
isn't called.

Fix by always calling fuse_copy_finish() after fuse_notify().  It's a no-op
if called a second time.

Fixes: 760eac7 ("fuse: Introduce a new notification type for resend pending requests")
Fixes: 2396356 ("fuse: add more control over cache invalidation behaviour")
	Cc: <stable@vger.kernel.org> # v6.9
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 0b563aa)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira SECO-511
commit-author Chen Linxuan <chenlinxuan@uniontech.com>
commit f092229
upstream-diff | There were conflicts seen while applying
this patch due to the following missing commit :-
786412a ("fuse: enable fuse-over-io-uring")

This commit add fuse connection device id to
fdinfo of opened /dev/fuse files.

Related discussions can be found at links below.

Link: https://lore.kernel.org/all/CAJfpegvEYUgEbpATpQx8NqVR33Mv-VK96C+gbTag1CEUeBqvnA@mail.gmail.com/
	Signed-off-by: Chen Linxuan <chenlinxuan@uniontech.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit f092229)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira SECO-518
commit-author Amir Goldstein <amir73il@gmail.com>
commit 03f275a

The re-factoring of fuse_dir_open() missed the need to invalidate
directory inode page cache with open flag FOPEN_KEEP_CACHE.

Fixes: 7de64d5 ("fuse: break up fuse_open_common()")
	Reported-by: Prince Kumar <princer@google.com>
Closes: https://lore.kernel.org/linux-fsdevel/CAEW=TRr7CYb4LtsvQPLj-zx5Y+EYBmGfM24SuzwyDoGVNoKm7w@mail.gmail.com/
	Signed-off-by: Amir Goldstein <amir73il@gmail.com>
Link: https://lore.kernel.org/r/20250101130037.96680-1-amir73il@gmail.com
	Reviewed-by: Bernd Schubert <bernd.schubert@fastmail.fm>
	Signed-off-by: Christian Brauner <brauner@kernel.org>
(cherry picked from commit 03f275a)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-2026-46317
commit-author Hyunwoo Kim <imv4bel@gmail.com>
commit 7054335

kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.

Allocate the new array outside of mmu_lock, as the allocation can sleep.
Under the lock, copy the existing entries, fix up the back pointers and
reassign the array. Free the old buffer after dropping the lock, as
kvfree() can sleep as well.

Fixes: 4f128f8 ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
	Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
	Reviewed-by: Oliver Upton <oupton@kernel.org>
Link: https://patch.msgid.link/aiKIVVeIr1aAB1yp@v4bel
	Signed-off-by: Marc Zyngier <maz@kernel.org>
	Cc: stable@vger,kernel.org
(cherry picked from commit 7054335)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
jira KERNEL-1217
commit-author Harshitha Ramamurthy <hramamurthy@google.com>
commit 93c68f1

In preparation for the upcoming page pool adoption for DQO
raw addressing mode, move RX buffer management code to a new
file. In the follow on patches, page pool code will be added
to this file.

No functional change, just movement of code.

	Reviewed-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Reviewed-by: Shailend Chand <shailend@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Signed-off-by: Harshitha Ramamurthy <hramamurthy@google.com>
	Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20241014202108.1051963-2-pkaligineedi@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 93c68f1)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
commit-author Joshua Washington <joshwash@google.com>
commit 6321f5f

When stopping XDP TX rings, the XDP clean function needs to be called to
clean out the entire queue, similar to what happens in the normal TX
queue case. Otherwise, the FIFO won't be cleared correctly, and
xsk_tx_completed won't be reported.

Fixes: 75eaae1 ("gve: Add XDP DROP and TX support for GQI-QPL format")
	Cc: stable@vger.kernel.org
	Signed-off-by: Joshua Washington <joshwash@google.com>
	Signed-off-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Reviewed-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit 6321f5f)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
commit-author Joshua Washington <joshwash@google.com>
commit de63ac4

This patch fixes a number of consistency issues in the queue allocation
path related to XDP.

As it stands, the number of allocated XDP queues changes in three
different scenarios.
1) Adding an XDP program while the interface is up via
   gve_add_xdp_queues
2) Removing an XDP program while the interface is up via
   gve_remove_xdp_queues
3) After queues have been allocated and the old queue memory has been
   removed in gve_queues_start.

However, the requirement for the interface to be up for
gve_(add|remove)_xdp_queues to be called, in conjunction with the fact
that the number of queues stored in priv isn't updated until _after_ XDP
queues have been allocated in the normal queue allocation path means
that if an XDP program is added while the interface is down, XDP queues
won't be added until the _second_ if_up, not the first.

Given the expectation that the number of XDP queues is equal to the
number of RX queues, scenario (3) has another problematic implication.
When changing the number of queues while an XDP program is loaded, the
number of XDP queues must be updated as well, as there is logic in the
driver (gve_xdp_tx_queue_id()) which relies on every RX queue having a
corresponding XDP TX queue. However, the number of XDP queues stored in
priv would not be updated until _after_ a close/open leading to a
mismatch in the number of XDP queues reported vs the number of XDP
queues which actually exist after the queue count update completes.

This patch remedies these issues by doing the following:
1) The allocation config getter function is set up to retrieve the
   _expected_ number of XDP queues to allocate instead of relying
   on the value stored in `priv` which is only updated once the queues
   have been allocated.
2) When adjusting queues, XDP queues are adjusted to match the number of
   RX queues when XDP is enabled. This only works in the case when
   queues are live, so part (1) of the fix must still be available in
   the case that queues are adjusted when there is an XDP program and
   the interface is down.

Fixes: 5f08cd3 ("gve: Alloc before freeing when adjusting queues")
	Cc: stable@vger.kernel.org
	Signed-off-by: Joshua Washington <joshwash@google.com>
	Signed-off-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Reviewed-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Reviewed-by: Shailend Chand <shailend@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Signed-off-by: David S. Miller <davem@davemloft.net>
(cherry picked from commit de63ac4)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
cve CVE-2025-38735
commit-author Jordan Rhee <jordanrhee@google.com>
commit 75a9a46

A crash can occur if an ethtool operation is invoked
after shutdown() is called.

shutdown() is invoked during system shutdown to stop DMA operations
without performing expensive deallocations. It is discouraged to
unregister the netdev in this path, so the device may still be visible
to userspace and kernel helpers.

In gve, shutdown() tears down most internal data structures. If an
ethtool operation is dispatched after shutdown(), it will dereference
freed or NULL pointers, leading to a kernel panic. While graceful
shutdown normally quiesces userspace before invoking the reboot
syscall, forced shutdowns (as observed on GCP VMs) can still trigger
this path.

Fix by calling netif_device_detach() in shutdown().
This marks the device as detached so the ethtool ioctl handler
will skip dispatching operations to the driver.

Fixes: 974365e ("gve: Implement suspend/resume/shutdown")
	Signed-off-by: Jordan Rhee <jordanrhee@google.com>
	Signed-off-by: Jeroen de Borst <jeroendb@google.com>
Link: https://patch.msgid.link/20250818211245.1156919-1-jeroendb@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 75a9a46)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
cve CVE-2025-71156
commit-author Ankit Garg <nktgrg@google.com>
commit 3d970ed
upstream-diff RLC 10 does not carry the netif_napi_set_irq_locked()
  call this commit's gve_add_napi() hunk lands beside (it has
  block->irq but not the napi-irq wiring), so enable_irq(block->irq)
  is added directly after netif_napi_add_locked().

Currently, interrupts are automatically enabled immediately upon
request. This allows interrupt to fire before the associated NAPI
context is fully initialized and cause failures like below:

[    0.946369] Call Trace:
[    0.946369]  <IRQ>
[    0.946369]  __napi_poll+0x2a/0x1e0
[    0.946369]  net_rx_action+0x2f9/0x3f0
[    0.946369]  handle_softirqs+0xd6/0x2c0
[    0.946369]  ? handle_edge_irq+0xc1/0x1b0
[    0.946369]  __irq_exit_rcu+0xc3/0xe0
[    0.946369]  common_interrupt+0x81/0xa0
[    0.946369]  </IRQ>
[    0.946369]  <TASK>
[    0.946369]  asm_common_interrupt+0x22/0x40
[    0.946369] RIP: 0010:pv_native_safe_halt+0xb/0x10

Use the `IRQF_NO_AUTOEN` flag when requesting interrupts to prevent auto
enablement and explicitly enable the interrupt in NAPI initialization
path (and disable it during NAPI teardown).

This ensures that interrupt lifecycle is strictly coupled with
readiness of NAPI context.

	Cc: stable@vger.kernel.org
Fixes: 1dfc2e4 ("gve: Refactor napi add and remove functions")
	Signed-off-by: Ankit Garg <nktgrg@google.com>
	Reviewed-by: Jordan Rhee <jordanrhee@google.com>
	Reviewed-by: Joshua Washington <joshwash@google.com>
	Signed-off-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20251219102945.2193617-1-hramamurthy@google.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 3d970ed)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
… QPL

jira KERNEL-1217
cve CVE-2026-23386
commit-author Ankit Garg <nktgrg@google.com>
commit fb868db
upstream-diff The moved gve_unmap_packet() keeps this tree's
  dma_unmap_page() for the frag entries; the netmem conversion
  (netmem_dma_unmap_page_attrs) is not in this tree.

In DQ-QPL mode, gve_tx_clean_pending_packets() incorrectly uses the RDA
buffer cleanup path. It iterates num_bufs times and attempts to unmap
entries in the dma array.

This leads to two issues:
1. The dma array shares storage with tx_qpl_buf_ids (union).
 Interpreting buffer IDs as DMA addresses results in attempting to
 unmap incorrect memory locations.
2. num_bufs in QPL mode (counting 2K chunks) can significantly exceed
 the size of the dma array, causing out-of-bounds access warnings
(trace below is how we noticed this issue).

UBSAN: array-index-out-of-bounds in
drivers/net/ethernet/drivers/net/ethernet/google/gve/gve_tx_dqo.c:178:5 index 18 is out of
range for type 'dma_addr_t[18]' (aka 'unsigned long long[18]')
Workqueue: gve gve_service_task [gve]
Call Trace:
<TASK>
dump_stack_lvl+0x33/0xa0
__ubsan_handle_out_of_bounds+0xdc/0x110
gve_tx_stop_ring_dqo+0x182/0x200 [gve]
gve_close+0x1be/0x450 [gve]
gve_reset+0x99/0x120 [gve]
gve_service_task+0x61/0x100 [gve]
process_scheduled_works+0x1e9/0x380

Fix this by properly checking for QPL mode and delegating to
gve_free_tx_qpl_bufs() to reclaim the buffers.

	Cc: stable@vger.kernel.org
Fixes: a6fb8d5 ("gve: Tx path for DQO-QPL")
	Signed-off-by: Ankit Garg <nktgrg@google.com>
	Reviewed-by: Jordan Rhee <jordanrhee@google.com>
	Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
	Signed-off-by: Joshua Washington <joshwash@google.com>
	Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260220215324.1631350-1-joshwash@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>

(cherry picked from commit fb868db)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
commit-author Matt Olson <maolson@google.com>
commit 07993df
upstream-diff Conflicts from the gve_queue_config split and page_pool/
  netmem/XDP refactors not in RLC 10. Kept RLC 10 struct names (qcfg/
  qcfg_tx, no num_xdp_rings) and datapath (no page_pool/xsk); the
  gve_update_num_qpl_pages() body is applied verbatim except
  rx_alloc_cfg->qcfg_rx->num_queues -> ->qcfg->num_queues. buffer-mgmt
  and rx_dqo num_buf_states use cfg->pages_per_qpl / priv->rx_pages_per_qpl.

For DQO, change QPL page registration logic to be more flexible to honor
the "max_registered_pages" parameter from the gVNIC device.

Previously the number of RX pages per QPL was hardcoded to twice the
ring size, and the number of TX pages per QPL was dictated by the device
in the DQO-QPL device option. Now [in DQO-QPL mode], the driver will
ignore the "tx_pages_per_qpl" parameter indicated in the DQO-QPL device
option and instead allocate up to (tx_queue_length / 2) pages per TX QPL
and up to (rx_queue_length * 2) pages per RX QPL while keeping the total
number of pages under the "max_registered_pages".

Merge DQO and GQI QPL page calculation logic into a unified
gve_update_num_qpl_pages function. Add rx_pages_per_qpl to the priv
struct for consumption by both DQO and GQI.

	Signed-off-by: Matt Olson <maolson@google.com>
	Signed-off-by: Max Yuan <maxyuan@google.com>
	Reviewed-by: Jordan Rhee <jordanrhee@google.com>
	Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
	Reviewed-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Signed-off-by: Joshua Washington <joshwash@google.com>
Link: https://patch.msgid.link/20260225182342.1049816-2-joshwash@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 07993df)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
commit-author Matt Olson <maolson@google.com>
commit a2f1918

The gVNIC device indicates a device option (MODIFY_RING) to the driver,
which presents a range of ring sizes from which the user is allowed to
select. But in DQO-QPL queue format, the driver ignores the "max" of
this range and instead allows the user to configure the ring size in the
range [min, default]. This was done because increasing the ring size
could result in the number of registered pages being higher than the max
allowed by the device.

In order to support large ring sizes, stop ignoring the "max" of the
range presented in the MODIFY_RING option.

	Signed-off-by: Matt Olson <maolson@google.com>
	Signed-off-by: Max Yuan <maxyuan@google.com>
	Reviewed-by: Jordan Rhee <jordanrhee@google.com>
	Reviewed-by: Harshitha Ramamurthy <hramamurthy@google.com>
	Reviewed-by: Praveen Kaligineedi <pkaligineedi@google.com>
	Signed-off-by: Joshua Washington <joshwash@google.com>
Link: https://patch.msgid.link/20260225182342.1049816-3-joshwash@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit a2f1918)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217
commit-author Jordan Rhee <jordanrhee@google.com>
commit 6bf1457
upstream-diff RLC 10 predates the page-pool conversion and has no
  gve_free_buffer(); the freed buffer goes through
  gve_enqueue_buf_state(rx, &rx->dqo.recycled_buf_states, buf_state),
  the same form this tree's rx error path uses, which is what
  upstream's helper reduces to on non-page-pool queues.

When header split is enabled and a header-only packet is
received such as a pure TCP ACK, GVE will indicate an
RX SKB with a zero-length fragment. If this SKB is then
hairpinned and sent back out, the GVE TX path will emit
a zero-length descriptor. Hardware considers this
an illegal descriptor and stops the queue, causing a
TX timeout and interface reset.

Fix it by not adding the zero-length skb frag.

	Cc: stable@vger.kernel.org
Fixes: 5e37d82 ("gve: Add header split data path")
	Suggested-by: Praveen Kaligineedi <pkaligineedi@google.com>
Co-developed-by: Ziwei Xiao <ziweixiao@google.com>
	Signed-off-by: Ziwei Xiao <ziweixiao@google.com>
	Signed-off-by: Jordan Rhee <jordanrhee@google.com>
	Signed-off-by: Harshitha Ramamurthy <hramamurthy@google.com>
Link: https://patch.msgid.link/20260807224315.234152-2-hramamurthy@google.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>

(cherry picked from commit 6bf1457)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira KERNEL-1217

gve_tx_qpl_buf_init() sizes the TX buffer free list as
GVE_TX_BUFS_PER_PAGE_DQO * num_entries, but the free-list links
(tx_qpl_buf_next) are s16.  GVE_TX_BUFS_PER_PAGE_DQO is PAGE_SIZE >> 11,
so on 64K-page builds (the aarch64-64k config ships CONFIG_GVE=m) a
4096-entry TX ring yields 2048 pages and 65536 buffers: entry 32767 is
seeded with a link of 32768, which reads back as -32768, and once 32768
buffers have been allocated gve_alloc_tx_qpl_buf() dereferences
tx_qpl_buf_next[-32768] and returns ids that index outside the QPL.

Clamp the count to S16_MAX, leaving an oversized QPL's tail unused
rather than mislinked.

This is not unique to this backport: upstream has the same unclamped
math at its tip. Kept as a separate commit so it can be dropped in
favor of the upstream fix once one lands;

Fixes: 07993df ("gve: Update QPL page registration logic")
Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-2026-72137
commit-author Qianyu Luo <qianyuluo3@gmail.com>
commit 226f4a4

nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6
send helper reports an error.

That cleanup is only correct before the skb is handed to the output
path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the
networking stack may already have consumed the skb before returning an
error, so freeing it again is unsafe.

Handle the pre-handoff failure cases inside nat_keepalive_send_ipv4()
and nat_keepalive_send_ipv6(), where the caller still owns the skb, and
keep nat_keepalive_send() responsible only for family dispatch and the
unsupported-family cleanup path.

Fixes: f531d13 ("xfrm: support sending NAT keepalives in ESP in UDP states")
	Cc: stable@vger.kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Qianyu Luo <qianyuluo3@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Reviewed-by: Eyal Birger <eyal.birger@gmail.com>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit 226f4a4)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve-pre CVE-2026-53361
commit-author Kuniyuki Iwashima <kuniyu@amazon.com>
commit 001a250
upstream-diff |
    Context difference due to backported commit by redhat that
    technically comes after this change.
    3849005
    [af_unix: Don't call wait_for_unix_gc() on every sendmsg().]

We will introduce skb drop reason for AF_UNIX, then we need to
set an errno and a drop reason for each path.

Let's set an error only when it's needed in unix_dgram_sendmsg().

Then, we need not (re)set 0 to err.

	Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com>
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>

(cherry picked from commit 001a250)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-68376
commit-author Xin Long <lucien.xin@gmail.com>
commit e0b5252

The auth_hmacs array in struct sctp_cookie is supposed to store a complete
SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr
followed by N HMAC identifiers.

However, the array size was calculated using an extra 2 bytes instead of
sizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers
are configured, the HMAC-ALGO parameter stored in the endpoint is larger
than the auth_hmacs buffer in the cookie.

As a result, sctp_association_init() copies beyond the end of auth_hmacs
when initializing the association, corrupting the adjacent auth_chunks
field. This can lead to an invalid HMAC identifier being accepted and later
cause an out-of-bounds read in sctp_auth_get_hmac().

Fix the array size calculation by including the full SCTP parameter header
size.

Fixes: 1f48564 ("[SCTP]: Implement SCTP-AUTH internals")
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Xin Liu <dstsmallbird@foxmail.com>
	Reported-by: Zihan Xi <xizh2024@lzu.edu.cn>
	Reported-by: Ren Wei <enjou1224z@gmail.com>
	Signed-off-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/634a0de0d5de29532915e6d47c92a0cbc206e03f.1783707155.git.lucien.xin@gmail.com
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit e0b5252)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-31678
commit-author Yang Yang <n05ec@lzu.edu.cn>
commit 6931d21

ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already
detached the device. Dropping the netdev reference in destroy can race
with concurrent readers that still observe vport->dev.

Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let
vport_netdev_free() drop the reference from the RCU callback, matching
the non-tunnel destroy path and avoiding additional synchronization
under RTNL.

Fixes: a9020fd ("openvswitch: Move tunnel destroy function to oppenvswitch module.")
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Tested-by: Ao Zhou <n05ec@lzu.edu.cn>
Co-developed-by: Yuan Tan <tanyuan98@outlook.com>
	Signed-off-by: Yuan Tan <tanyuan98@outlook.com>
	Suggested-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Yang Yang <n05ec@lzu.edu.cn>
	Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Link: https://patch.msgid.link/20260319074241.3405262-1-n05ec@lzu.edu.cn
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 6931d21)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-72255
commit-author Haoze Xie <royenheart@gmail.com>
commit c9c9b37

The br_netfilter fake rtable is embedded in struct net_bridge and is
attached to bridged packets with skb_dst_set_noref(). If such a packet is
queued to NFQUEUE, __nf_queue() upgrades that fake dst with
skb_dst_force().

At that point the queued skb can hold a real dst reference after bridge
teardown has started. The problem is not that every bridged packet needs
its own dst reference. The problem is that NFQUEUE can keep the bridge
private fake dst alive after unregister begins.

Fix this by keeping the bridge fake dst model unchanged and pinning the
bridge master device only while the packet sits in NFQUEUE. Record the
bridge device in nf_queue_entry when the queued skb carries a bridge fake
dst, take a device reference for the queue lifetime, and drop it when the
queue entry is freed.

Also make sure queued entries are reaped when that bridge device goes
down, and drop the redundant nf_bridge_info_exists() test from the fake
dst detection.

This keeps netdev_priv(br->dev) alive until verdict completion, so the
embedded fake rtable and its metrics backing storage cannot be freed out
from under dst_release(). It also avoids the constant refcount bump and
avoids using ipv4-specific dst helpers for IPv6 bridge traffic.

Fixes: 34666d4 ("netfilter: bridge: move br_netfilter out of the core")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Haoze Xie <royenheart@gmail.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
(cherry picked from commit c9c9b37)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-46165
commit-author Ilya Maximets <i.maximets@ovn.org>
commit aa69918

vports are used concurrently and protected by RCU, so netdev_put()
must happen after the RCU grace period.  So, either in an RCU call or
after the synchronize_net().  The rtnl_delete_link() must happen under
RTNL and so can't be executed in RCU context.  Calling synchronize_net()
while holding RTNL is not a good idea for performance and system
stability under load in general, so calling netdev_put() in RCU call
is the right solution here.

However,
when the device is deleted, rtnl_unlock() will call netdev_run_todo()
and block until all the references are gone.  In the current code this
means that we never reach the call_rcu() and the vport is never freed
and the reference is never released, causing a self-deadlock on device
removal.

Fix that by moving the rcu_call() before the rtnl_unlock(), so the
scheduled RCU callback will be executed when synchronize_net() is
called from the rtnl_unlock()->netdev_run_todo() while the RTNL itself
is already released.

Fixes: 6931d21 ("openvswitch: defer tunnel netdev_put to RCU release")
	Cc: stable@vger.kernel.org
	Acked-by: Eelco Chaudron <echaudro@redhat.com>
	Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
	Acked-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/20260430233848.440994-2-i.maximets@ovn.org
	Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit aa69918)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-74597
commit-author Zhiling Zou <zhilinz@nebusec.ai>
commit f803c08

ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the
quoted inner IPv6 packet, and then passes the clone to icmpv6_send().
The clone still carries the outer packet's inet6_skb_parm in skb->cb.

If the outer packet had a Home Address Option, IP6CB(skb2)->dsthao
remains non-zero after skb_pull(). icmpv6_send() later calls
mip6_addr_swap(), which uses that stale dsthao offset against the quoted
inner packet. A malformed inner destination-options header can then make
the HAO lookup and address swap run past the end of the quoted packet
and corrupt skb_shared_info.

Clear skb2->cb[] before pulling the quoted inner IPv6 packet so the
reply path does not reuse metadata left by the outer IPv6 stack.

Fixes: e490d1d ("[IPV6] IP6TUNNEL: Split out generic routine in ip6ip6_err().")
	Cc: stable@vger.kernel.org
	Reported-by: Vega <vega@nebusec.ai>
	Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
	Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/fe1a5e765fbca88d69391887f0ed26a19e3e4d39.1785736562.git.zhilinz@nebusec.ai
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit f803c08)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Bernd Schubert <bschubert@ddn.com>
commit 92270d0

This function is needed by fuse_uring.c to clean ring queues,
so make it non static. Especially in non-static mode the function
name 'end_requests' should be prefixed with fuse_

	Signed-off-by: Bernd Schubert <bschubert@ddn.com>
	Reviewed-by: Josef Bacik <josef@toxicpanda.com>
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Reviewed-by: Luis Henriques <luis@igalia.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 92270d0)
	Signed-off-by: Jonathan Maple <jmaple@ciq.com>
bmastbergen and others added 24 commits September 21, 2026 14:18
jira SECO-478
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit c146284
upstream-diff |
	fch->lock/fch->connected changed to fc->lock/fc->connected
	in fuse_uring_do_register() already applied in 23e9c1c.
	Only the fuse_uring_create() hunk is new.

Check fc->connected under fc->lock in fuse_uring_create() before
attaching a new ring. Without this, a race between fuse_uring_create()
and fuse_conn_destroy() can result in the ring, queue, and fpq.processing
table being created after fuse_uring_abort() has already run, leading
to unnecessary allocation and teardown. These are eventually cleaned up
by fuse_uring_destruct() but will linger until the process exits, even
with the connection aborted.

	Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
	Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit c146284)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
cve CVE-2026-64263
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit 198f45e
upstream-diff |
	io_uring_cmd_done() uses 4 args (res2=0) vs upstream 3 args.
	list_move used instead of list_move_tail.

fuse_uring_cancel() moves entries that are available (these have no reqs
attached) to the ent_in_userspace list. ent_list_request_expired()
checks the first entry on ent_in_userspace and dereferences
ent->fuse_req unconditionally, which will crash on a cancelled entry
that was moved to this list.

Fix this by freeing the entry and dropping queue_refs directly in
fuse_uring_cancel(). This is safe because cancel is the cancel handler
itself - after io_uring_cmd_done(), no more cancels will be dispatched
for this command, and teardown serializes with cancel via queue->lock.

Since cancel now decrements queue_refs, fuse_uring_abort() must no
longer gate fuse_uring_abort_end_requests() on queue_refs > 0, as
cancelled entries may have already dropped queue_refs while requests are
still queued. Remove the gate so abort always flushes requests and stops
queues.

	Reported-by: Heechan Kang <gganji11@naver.com>
	Tested-by: Heechan Kang <gganji11@naver.com>
	Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
	Fixes: 4fea593 ("fuse: optimize over-io-uring request expiration check")
	Cc: stable@vger.kernel.org
	Suggested-by: Jian Huang Li <ali@ddn.com>
	Suggested-by: Horst Birthelmer <horst@birthelmer.de>
	Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 198f45e)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
cve CVE-2026-64262
RFE: FUSE_IO_URING
commit-author Chris Mason <clm@meta.com>
commit bea4fe9
upstream-diff |
	fuse_uring_send_in_task has different signature
	(missing io_tw_req/io_tw_token_t API in this kernel)
	io_uring_cmd_done() call corrected to pass 4 args
	(res2=0 was missing in upstream adaptation). Upstream
	dropped the res2 param in:
	  ef9f603 - io_uring/cmd: drop unused res2 param from io_uring_cmd_done()

When io_uring delivers task work with tw.cancel set (PF_EXITING,
PF_KTHREAD fallback, or percpu_ref_is_dying on the ring context),
fuse_uring_send_in_task() takes the cancel branch, assigns
-ECANCELED, and falls through to fuse_uring_send(). That path only
flips the entry to FRRS_USERSPACE and completes the io_uring cmd;
it never discharges the ring entry's owning reference to the
fuse_req that fuse_uring_add_req_to_ring_ent() handed it at
dispatch time.

    fuse_uring_send_in_task()
      tw.cancel == true
        err = -ECANCELED
      fuse_uring_send(ent, cmd, err, issue_flags)
        ent->state = FRRS_USERSPACE
        list_move(&ent->list, &queue->ent_in_userspace)
        ent->cmd = NULL
        io_uring_cmd_done(-ECANCELED)
        /* ent->fuse_req still set, req still hashed */

The fuse_req stays linked on fpq->processing[hash] and
fuse_request_end() is never invoked. The originating syscall
thread blocks in D-state in request_wait_answer() until
fuse_abort_conn() runs, which can be the entire connection
lifetime. For FR_BACKGROUND requests fc->num_background is never
decremented either, so repeated cancels inflate the counter until
max_background is hit and all later background ops stall. tw.cancel does
not imply a connection abort (e.g. a single io_uring worker thread exits
while the fuse connection stays up), so this cannot be left for
fuse_abort_conn() to clean up.

Ending the req but still routing the entry through fuse_uring_send()
is not enough: that leaves a req-less entry on ent_in_userspace, and
ent_list_request_expired() dereferences ent->fuse_req unconditionally
on the head of that list, which would then NULL-deref.

Fix the cancel branch to release the entry directly. Remove it from the
queue, complete the io_uring cmd, end the fuse_req, free the entry, and
drop its queue_refs (waking the teardown waiter if it was the last).

Fixes: c2c9af9 ("fuse: Allow to queue fg requests through io-uring")
Cc: stable@vger.kernel.org
Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
Assisted-by: kres (claude-opus-4-7)
Signed-off-by: Chris Mason <clm@meta.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit bea4fe9)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
cve CVE-2026-64261
RFE: FUSE_IO_URING
commit-author Bernd Schubert <bernd@bsbernd.com>
commit d351da7
upstream-diff |
	ring->fc used instead of ring->chan->conn

fuse_uring_async_stop_queues() might run when the last reference
on ring->queue_refs was already dropped.

In order to avoid an early destruction a reference on struct fuse_conn
is now taken before starting fuse_uring_async_stop_queues() and that
reference is only released when that delayed work queue terminates.

	Fixes: 4a9bfb9 ("fuse: {io-uring} Handle teardown of ring entries")
	Cc: stable@kernel.org # 6.14
	Reported-by: Berkant Koc <me@berkoc.com>
	Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit d351da7)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
…lock

jira SECO-478
cve CVE-2026-64260
RFE: FUSE_IO_URING
commit-author Bernd Schubert <bernd@bsbernd.com>
commit b70a3ac
upstream-diff |
	ring->fc used instead of ring->chan->conn

There are several readers of queue->stopped that check the value
under lock, but fuse_uring_commit_fetch() did not and actually
the value was not set under the lock in fuse_uring_abort_end_requests()
either. Especially in fuse_uring_commit_fetch it is important
to check under a lock, because due to races 'struct fuse_req'
might be freed with fuse_request_end, but another thread/cpu
might already do teardown work.

	Cc: stable@kernel.org # 6.14
	Fixes: 4a9bfb9 ("fuse: {io-uring} Handle teardown of ring entries")
	Reported-by: Berkant Koc <me@berkoc.com>
	Reported-by: xlabai <xlabai@tencent.com>
	Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit b70a3ac)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
cve CVE-2026-64259
RFE: FUSE_IO_URING
commit-author Bernd Schubert <bernd@bsbernd.com>
commit 1efd3d4
upstream-diff |
	list_move used instead of list_move_tail and
	io_uring_cmd_done has extra arg (older API in this kernel)

Bad userspace might try to trick us and send commit SQEs request
unique / commit-id of requests that are not even send to
fuse-server (io_uring_cmd_done() not called) yet.

fuse_uring_commit_fetch() ends the fuse request when the ring entry
has a wrong state, but that could have caused a use-after-free
with the memcpy operations in fuse_uring_send_in_task().
In order to avoid such races the call of fuse_uring_add_to_pq()
is moved after the copy operations and just before completing
the io-uring request - malicious userspace cannot find the request
anymore until all prepration work in fuse-client/kernel is completed.

This also moves fuse_uring_add_to_pq() a bit up in the code to
avoid a forward declaration. Also not with a preparation commit,
to make it easier to back port to older kernels.

Reported-by: xlabai <xlabai@tencent.com>
Reported-by: Berkant Koc <me@berkoc.com>
Fixes: c090c8a ("fuse: Add io-uring sqe commit and fetch support")
Cc: stable@kernel.org # 6.14
Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 1efd3d4)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
…ULL deref

jira SECO-478
cve CVE-2026-64258
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit 1c57a69

If a copy into the userspace ring buffer fails, a request will be
terminated and fuse_uring_req_end() will set ent->fuse_req to NULL but
it will leave the entry on ent_w_req_queue in FRRS_FUSE_REQ state. This
can lead to a NULL deref if the request expiration logic scans
ent_w_req_queue in the window before the entry is moved off it.

Fix this by taking the entry off ent_w_req_queue and changing its state
from FRRS_FUSE_REQ to FRRS_INVALID before terminating the request.

	Fixes: 4fea593 ("fuse: optimize over-io-uring request expiration check")
	Cc: stable@kernel.org
	Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 1c57a69)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit 31da059
upstream-diff |
	fuse_copy_init uses int write vs bool write in this kernel

When a background request completes via the io_uring path, the
background queue gets flushed to dispatch pending background requests,
but this is done before the connection-level background counters
(fc->num_background, fc->active_background) are properly accounted,
which may reduce effective queue depth to one.

The connection-level counters are decremented in fuse_request_end(), but
flush_bg_queue() flushes the /dev/fuse path queue (fc->bg_queue), not
the io_uring per-queue bg one, which means pending uring background
requests on the queue are never dispatched in this path.

Fix this by accounting the connection-level background counters first
before flushing the queue's background queue. Since
fuse_request_bg_finish() clears FR_BACKGROUND, fuse_request_end() will
skip the background cleanup branch entirely, which avoids any
double-decrements; it will call the wake_up(&req->waitq) branch but this
is effectively a no-op as background requests have no waiters on
req->waitq.

Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
Fixes: 857b026 ("fuse: Allow to queue bg requests through io-uring")
Cc: stable@vger.kernel.org
Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 31da059)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Zhenghang Xiao <kipreyyy@gmail.com>
commit 7d87a5a

fuse_uring_commit_fetch() error path called fuse_request_end(req) without
clearing ent->fuse_req when fuse_ring_ent_set_commit() fails. The
still-pending fuse_uring_send_in_task() task-work later dereferences the
dangling pointer through fuse_uring_prepare_send(), causing a
use-after-free.

End the request with fuse_uring_req_end(), which handles all conditions
already.

Annotation/edition by Bernd: The UAF should be fixed by other means already
and actually has to be avoided that way.
Just checking for ent->fuse_req == NULL in fuse_uring_send_in_task()
would be prone to race conditions, because if malicious userspace
would commit requests that have passed the NULL check, but are
in doing args copy, it would still trigger a use-after-free.
Setting ent->fuse_req = NULL in fuse_uring_commit_fetch() still
makes sense, though.

	Reported-by: Shuvam Pandey <shuvampandey1@gmail.com>
	Reported-by: Berkant Koc <me@berkoc.com>
	Signed-off-by: Zhenghang Xiao <kipreyyy@gmail.com>
	Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 7d87a5a)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit edb310b
upstream-diff |
	fuse_conn/fc used instead of fuse_chan/fch
	in this kernel

fuse_block_alloc() reads fch->initialized and then fch->io_uring.
fch->io_uring is set before fch->initialized, ordered by the smp_wmb()
in fuse_chan_set_intialized(), but fuse_block_alloc() has no matching
read barrier between the two loads.

This may lead a CPU to observe fch->initialized=1 but fch->io_uring=0,
and skip the check that blocks request allocation until the io-uring
queues are ready. This can reintroduce the lock-order inversion deadlock
that commit 3393ff9 prevents.

Add an smp_rmb() barrier to pair with the smp_wmb() in
fuse_chan_set_initialized() to prevent this.

Fixes: 3393ff9 ("fuse: block request allocation until io-uring init is complete")
	Cc: stable@vger.kernel.org
	Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
	Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit edb310b)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Joanne Koong <joannelkoong@gmail.com>
commit 42df916
upstream-diff |
	fc->lock used instead of fch->lock in this kernel

fuse_uring_create_queue() initializes a fuse_ring_queue and then
publishes the pointer into ring->queues[qid] with WRITE_ONCE() under the
fch->lock. There are several readers that may concurrently be fetching
that pointer locklessly and then deferencing it.

WRITE_ONCE() doesn't ensure ordering of the queue's field
initialization before the ring->queues[qid] pointer assignment. The
queue must be published with smp_store_release() so the field
initialization is guaranteed to happen before.

Readers in paths where the read may happen concurrently with the store
need to use READ_ONCE() because any race involving a plain access is
undefined.

Fixes: 24fe962 ("fuse: {io-uring} Handle SQEs - register commands")
	Cc: stable@vger.kernel.org
	Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
	Signed-off-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 42df916)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Xiang Mei <xmei5@asu.edu>
commit fd10f40
upstream-diff |
	copy_{to,from}_user used directly instead of
	copy_header_{to,from}_ring helpers in this kernel;
	fc used instead of fch

The fuse-io-uring transport copies req->in.h out to the ring in
fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit().
Both headers live inside the fuse_request slab object, whose cache
(fuse_req_cachep) is created without a usercopy whitelist, so copying
them directly to/from userspace trips CONFIG_HARDENED_USERCOPY and
panics:

  usercopy: Kernel memory exposure attempt detected from SLUB object
  'fuse_request' (offset 56, size 40)!
  kernel BUG at mm/usercopy.c:102!
  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
  RIP: 0010:usercopy_abort (mm/usercopy.c:90)
  Call Trace:
   __check_heap_object (mm/slub.c:8268)
   __check_object_size (mm/usercopy.c:197 mm/usercopy.c:258 mm/usercopy.c:223)
   copy_header_to_ring (fs/fuse/dev_uring.c:618)
   fuse_uring_prepare_send (fs/fuse/dev_uring.c:776 fs/fuse/dev_uring.c:785)
   fuse_uring_send_in_task (fs/fuse/dev_uring.c:1306)
   tctx_task_work_run (io_uring/tw.c:96)
   task_work_run (kernel/task_work.c:233)
   io_run_task_work (io_uring/tw.h:84)
   io_cqring_wait (io_uring/wait.c:278)
   __do_sys_io_uring_enter (io_uring/io_uring.c:2685)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

Bounce both headers through an on-stack copy so the usercopy touches
stack memory, not the slab object.

Fixes: c090c8a ("fuse: Add io-uring sqe commit and fetch support")
	Cc: stable@vger.kernel.org
	Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
	Signed-off-by: Xiang Mei <xmei5@asu.edu>
	Reviewed-by: Bernd Schubert <bernd@bsbernd.com>
	Reviewed-by: Joanne Koong <joannelkoong@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit fd10f40)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Bernd Schubert <bernd@bsbernd.com>
commit 1f59015
upstream-diff |
	fc/fc->aborted used instead of fch/fch->abort_with_err;
	fuse_set_initialized() used instead of
	fuse_chan_set_initialized() in this kernel

The existing condition in fuse_uring_cmd() is there only to avoid
disabling io-uring for connections that already run with it, missing
was a condition to refuse any IORING_OP_URING_CMD if the
connection/channel didn't get enabled because of missing FUSE_INIT
reply flag FUSE_OVER_IO_URING. Without the reply flag the barrier in
fuse_uring_ready() doesn't work and IO could already be going on and
cause deadlock states (at a minimum one between fch->bg_lock and
queue->lock).

The change itself is trivial, but brings behavior change,
FUSE_OVER_IO_URING has to be set in the FUSE_INIT_REPLY by fuse servers
to accept any IORING_OP_URING_CMD. Libfuse does that and the only
non-libfuse implementation I found (fractal-fuse) also does it.
Qemu patches for fuse-io-uring are not merged yet, as far as I know.

Moved up is the smp_load_acquire(&fch->initialized) check, as a
fuse-server implementation might try to setup io-uring before FUSE_INIT
is processed and might have gotten -EOPNOTSUPP instead of -EAGAIN.

Also fixed is a stale comment that explains the handling of the
FUSE_OVER_IO_URING flag in early RFC versions.

If there should be a report from any library or application we
probably need to revert this commit.

Fixes: 3393ff9 ("fuse: block request allocation until io-uring init is complete")
	Signed-off-by: Bernd Schubert <bernd@bsbernd.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 1f59015)
Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING

Enable FUSE io-uring support in x86_64 and aarch64 configs that have
both prerequisites (CONFIG_FUSE_FS=m and CONFIG_IO_URING=y), across
all variants (debug, rt, 64k).

Skipped configs lacking prerequisites:
  - kernel-riscv64-*.config (no CONFIG_FUSE_FS or CONFIG_IO_URING)
  - kernel-s390x-zfcpdump-rhel.config (CONFIG_FUSE_FS is not set)

The feature is gated at runtime by the enable_uring module parameter
which defaults to disabled.

Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
…ectl

jira SECO-478
RFE: FUSE_IO_URING
commit-author Chen Linxuan <chenlinxuan@uniontech.com>
commit 1a7b137

This patch add a simple functional test for the 'abort' file in
fusectlfs (/sys/fs/fuse/connections/ID/abort). A simple fuse daemon
is added for testing.

	Signed-off-by: Chen Linxuan <chenlinxuan@uniontech.com>
	Acked-by: Shuah Khan <skhan@linuxfoundation.org>
	Reviewed-by: Amir Goldstein <amir73il@gmail.com>
	Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
(cherry picked from commit 1a7b137)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
On systems with only libfuse3-devel installed (no libfuse2-devel),
fuse_mnt.c fails to compile because fuse3 requires API version 30+.

Update fuse_mnt.c from FUSE API version 26 to 31:

  - getattr, truncate: add struct fuse_file_info * parameter
  - readdir: add enum fuse_readdir_flags parameter
  - filler calls: add flags argument

Also update the Makefile to try pkg-config fuse3 as a fallback when
pkg-config fuse is not available.

Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
commit-author Amir Goldstein <amir73il@gmail.com>
commit 9acb102
upstream-diff |
	kselftest_harness.h include uses relative path
	(../../kselftest_harness.h) because commit e6fbd17
	("selftests: complete kselftest include centralization")
	is not present in this tree.

A FUSE mount that does not negotiate FUSE_POSIX_ACL initialises every
inode with i_acl = i_default_acl = ACL_DONT_CACHE.  When a fresh stat
is needed (e.g. AT_STATX_FORCE_SYNC), fuse_update_get_attr() calls
forget_all_cached_acls() before issuing FUSE_GETATTR.  On an unfixed
kernel, __forget_cached_acl() replaces ACL_DONT_CACHE with
ACL_NOT_CACHED, inadvertently enabling the kernel ACL cache for that
inode.

This test validates the fix that preserves ACL_DONT_CACHE state in
forget_cached_acl().

	Signed-off-by: Amir Goldstein <amir73il@gmail.com>
	Signed-off-by: Christian Brauner <brauner@kernel.org>
(cherry picked from commit 9acb102)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
jira SECO-478
RFE: FUSE_IO_URING
Add a kselftest for the FUSE io-uring request dispatch path.  A
minimal in-memory FUSE daemon runs in a thread, negotiates
FUSE_OVER_IO_URING during FUSE_INIT, and handles requests through
FUSE_IO_URING_CMD_REGISTER / FUSE_IO_URING_CMD_COMMIT_AND_FETCH.
An atomic counter verifies requests are served through io_uring.

Test cases:
  - read_file: read and verify file content
  - write_and_readback: write data, read it back, compare
  - readdir: list directory, verify entries
  - stat_files: stat root and file, verify attributes
  - concurrent_io: 4 threads doing interleaved reads and writes
  - requests_via_uring: per-operation verification that read, write,
    readdir, and stat each produce io_uring requests
  - sustained_io: write 256KB in 4KB chunks, read back, verify pattern
  - crash_recovery: fork daemon, SIGKILL with active I/O, verify
    kernel health
  - abort_before_ring_ready: negotiate io_uring but never register
    entries, abort connection, verify no deadlock or leak

Tests SKIP when prerequisites are not met (no root, io_uring
disabled, enable_uring != Y).

Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-52929
commit-author Wyatt Feng <bronzed_45_vested@icloud.com>
commit a5f8a90

When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and
then lowers outcnt. That leaves removed stream metadata behind, so a
later re-add can reuse a stale ext and hit a null-pointer dereference in
the scheduler get path.

Fix the rollback by tearing down the removed stream state the same way
other stream resizes do. Unschedule the current scheduler state, drop
the removed stream ext state with sctp_stream_outq_migrate(), and then
reschedule the remaining streams.

This keeps scheduler-private RR/FC/PRIO lists consistent while fully
rolling back denied outgoing stream additions.

Fixes: 637784a ("sctp: introduce priority based stream scheduler")
	Cc: stable@kernel.org
	Reported-by: Yuan Tan <yuantan098@gmail.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Zhengchuan Liang <zcliangcn@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
	Signed-off-by: Wyatt Feng <bronzed_45_vested@icloud.com>
	Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/d78954ecd94954653ee299400e98d74a03a6f7d3.1780603399.git.bronzed_45_vested@icloud.com
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit a5f8a90)
	Signed-off-by: Shreeya Patel <spatel@ciq.com>
cve CVE-2026-43042
commit-author Sabrina Dubroca <sd@queasysnail.net>
commit 629ec78
upstream-diff Uses a file-scope seqcount_t instead of upstream's
  per-netns seqcount_mutex_t to avoid a kABI-breaking struct
  change. Write side uses local_bh_disable() with preempt_disable_nested()
  for RT safety. Uses rcu_dereference_rtnl() instead of
  upstream's plain rcu_dereference() to stay lockdep-clean
  under RTNL. mpls_dump_routes() still runs under RTNL on
  this tree; the seqcount there is extra hardening.

The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have
an inconsistent view of platform_labels vs platform_label in case of a
concurrent resize (resize_platform_label_table, under
platform_mutex). This can lead to OOB accesses.

This patch adds a seqcount, so that we get a consistent snapshot.

Note that mpls_label_ok is also susceptible to this, so the check
against RTA_DST in rtm_to_route_config, done outside platform_mutex,
is not sufficient. This value gets passed to mpls_label_ok once more
in both mpls_route_add and mpls_route_del, so there is no issue, but
that additional check must not be removed.

	Reported-by: Yuan Tan <tanyuan98@outlook.com>
	Reported-by: Yifan Wu <yifanwucs@gmail.com>
	Reported-by: Juefei Pu <tomapufckgml@gmail.com>
	Reported-by: Xin Liu <bird@lzu.edu.cn>
Fixes: 7720c01 ("mpls: Add a sysctl to control the size of the mpls label table")
Fixes: dde1b38 ("mpls: Convert mpls_dump_routes() to RCU.")
	Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/cd8fca15e3eb7e212b094064cd83652e20fd9d31.1774284088.git.sd@queasysnail.net
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 629ec78)
	Signed-off-by: Brett Mastbergen <bmastbergen@ciq.com>
cve CVE-2026-80844
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 7bad4bd

AH6 rearranges routing-header addresses before computing or verifying the
ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than
the number of addresses described by the routing header's hdrlen field.

That assumption does not hold for raw IPv6 HDRINCL packets. A packet with
hdrlen equal to 2 describes one address, but can carry an arbitrary
segments_left value. With segments_left equal to 255, the function moves
its address pointer 4,064 bytes backwards and passes a 4,064-byte length to
memmove(), resulting in an out-of-bounds access.

Validate the invariant locally before modifying the routing header or
performing any address-pointer arithmetic, and propagate malformed-header
errors to the existing AH6 input and output error paths.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
(cherry picked from commit 7bad4bd)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
cve CVE-2026-81000
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit 447c930

tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

Bound the headroom stored by TUN to the one-page skb-head budget and the
largest non-sentinel 16-bit skb header offset. Leave one linear byte for
raw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.

Also pull the raw-TUN protocol byte and the TAP Ethernet header before
accessing them, so these checks remain safe for nonlinear skbs supplied by
other allocation paths.

Fixes: eaea34b ("net/tun: implement ndo_set_rx_headroom")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260812012139.2134643-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 447c930)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
cve CVE-2026-68121
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit e9c238f

pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into it.

This can happen when a send is blocked in copy_from_user() while the first
non-Ethernet port is added to an empty team device. The team's delegated
GRE header callback then expands the skb head. PPPoE subsequently writes
six bytes through the stale pointer into the freed head.

Reload the PPPoE header through the skb's network-header offset after
device header creation. pskb_expand_head() updates that offset when it
relocates the head.

Fixes: 1da177e ("Linux-2.6.12-rc2")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
	Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260722093814.3017176-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit e9c238f)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
cve CVE-2026-74469
commit-author Asim Viladi Oglu Manizada <manizada@pm.me>
commit bd0e928

sctp_assoc_add_peer() increments the association's 16-bit transport_count
for every new unique peer. Adding the 65,536th transport wraps the count to
zero.

SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,
then copies one sockaddr_storage for every entry in transport_addr_list.
After the wrap, a diagnostic dump reserves an empty payload and writes
8 MiB of peer addresses past the skb tail.

Reject a new unique peer when transport_count has reached U16_MAX. Perform
the check after the existing-peer lookup so a duplicate address continues
to return its existing transport at the limit.

Fixes: 8f840e4 ("sctp: add the sctp_diag.c file")
	Cc: stable@vger.kernel.org
	Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
	Acked-by: Xin Long <lucien.xin@gmail.com>
Link: https://patch.msgid.link/20260725032053.521705-1-manizada@pm.me
	Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit bd0e928)
Signed-off-by: Jonathan Maple <jmaple@ciq.com>
@PlaidCat PlaidCat self-assigned this Sep 22, 2026
@PlaidCat
PlaidCat requested a review from a team September 22, 2026 13:27

@bmastbergen bmastbergen left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Below is the check_kernel_commits output for this PR:

 % python ./check_kernel_commits.py --repo ~/ciq/kernel-src-tree --pr_branch origin/jmaple_rlc-10/6.12.0-211.56.1.el10_2 --base_branch origin/rlc-10/6.12.0-211.56.1.el10_2 --check-cves
[FIXES] PR commit 66a5f7c25455c (fuse: add more control over cache invalidation
        behaviour) references upstream commit 2396356a945b, which has Fixes
        tags:

    6648f54f3459c fuse: move "epoch" from dentry.d_time to fuse_dentry.epoch (Miklos Szeredi)
    0fa8346099b57 fuse: invalidate readdir cache on epoch bump (Jun Wu)
    5a6baf2046105 fuse: fix uninit-value in fuse_dentry_revalidate() (Luis Henriques) (CVE-2026-53311)

[FIXES] PR commit b4cfa1e4b59f9 (fuse: {io-uring} Handle SQEs - register
        commands) references upstream commit 24fe962c86f5, which has Fixes tags:

    1dfe2a220e9cd fuse: fix uring race condition for null dereference of fc (Joanne Koong)

[CVE-MISSING] PR commit 8b6969821270d (fuse: fix missing barrier when checking
              io-uring readiness) does not reference a CVE but upstream commit
              edb310bc27f0 is associated with CVE-2026-80859

[CVE-MISSING] PR commit f72ebdf4c8e80 (fuse: publish io-uring queues with
              release semantics) does not reference a CVE but upstream commit
              42df916e5a5f is associated with CVE-2026-80858

[CVE-MISSING] PR commit c07b0a6e9ae33 (fuse: copy request headers via a stack
              buffer for io-uring) does not reference a CVE but upstream commit
              fd10f40af314 is associated with CVE-2026-80946

[CVE-MISSING] PR commit 043b73de49e9f (fuse: Fix the condition to enable
              over-io-uring) does not reference a CVE but upstream commit
              1f59015e9581 is associated with CVE-2026-90095

I haven't investigated the fixes yet, so I'm going to approve, but look into whether we want the fixes (especially the CVE-2026-53311 fix) for future releases

@PlaidCat
PlaidCat merged commit 56cdadb into rlc-10/6.12.0-211.56.1.el10_2 Sep 22, 2026
5 checks passed
@PlaidCat
PlaidCat deleted the jmaple_rlc-10/6.12.0-211.56.1.el10_2 branch September 22, 2026 18:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants