Merge tag 'android14-6.1.118_r00' into android14-6.1
This merges up to the 6.1.118 LTS release into the android14-6.1 branch. Changes included in here are: * 2f2512ac Merge 6.1.118 into android14-6.1-lts |\ | * b67dc5c9 Linux 6.1.118 | * 6a8d39ee 9p: fix slab cache name creation for real | * 509c1c6b fs/ntfs3: Fix general protection fault in run_is_mapped_full | * ba0b09a2 platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors | * 486aeb5f mm: krealloc: Fix MTE false alarm in __do_krealloc | * b22346ee Bluetooth: L2CAP: Fix uaf in l2cap_connect | * cf3196e5 ext4: fix timer use-after-free on failed mount | * e7831613 drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer | * 0dc3ad9a uprobe: avoid out-of-bounds memory access of fetching args | * 02079f09 uprobes: encapsulate preparation of uprobe args buffer | * fdacd09f io_uring: fix possible deadlock in io_register_iowq_max_workers() | * 9478355c md/raid10: improve code of mrdev in raid10_sync_request | * d4b003f7 net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition | * 8118551b LoongArch: Use "Exception return address" to comment ERA | * 807692ab HID: lenovo: Add support for Thinkpad X1 Tablet Gen 3 keyboard | * 5622881c HID: multitouch: Add quirk for Logitech Bolt receiver w/ Casa touchpad | * 5a72b0d3 fs: Fix uninitialized value issue in from_kuid and from_kgid | * cdd28621 bpf: Fix mismatched RCU unlock flavour in bpf_out_neigh_v6 | * 32c982b5 vDPA/ifcvf: Fix pci_read_config_byte() return code handling | * afa22946 nvme: make keep-alive synchronous operation | * ffdebf3d powerpc/powernv: Free name on error in opal_event_init() | * 60de2e03 nvme-multipath: defer partition scanning | * f17c880a drm/vmwgfx: Limit display layout ioctl array size to VMWGFX_NUM_DISPLAY_UNITS | * b8d1f4d3 sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML | * 75a1b35d crypto: marvell/cesa - Disable hash algorithms | * 1bc59a7c crypto: api - Fix liveliness check in crypto_alg_tested | * 911c9bc0 bpf: use kvzmalloc to allocate BPF verifier environment | * ccf7d314 nvme: disable CC.CRIME (NVME_CC_CRIME) | * eb6751a2 HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad | * c2242eba HID: multitouch: Add support for B2402FVA track point | * 77b0a8b0 block: Fix elevator_get_default() checking for NULL q->tag_set | * 4f946479 nvme: tcp: avoid race between queue_lock lock and destroy | * 94a4d966 irqchip/ocelot: Fix trigger register address | * af39f19c 9p: Avoid creating multiple slab caches with the same name | * 903227b6 Revert "Bluetooth: hci_conn: Consolidate code for aborting connections" | * 4c69abb4 Revert "Bluetooth: hci_core: Fix possible buffer overflow" * | 27e7205c Merge 0625d7c2 ("Revert "Bluetooth: af_bluetooth: Fix deadlock"") into android14-6.1-lts |\| | * 0625d7c2 Revert "Bluetooth: af_bluetooth: Fix deadlock" | * 0337fb09 Revert "Bluetooth: hci_sync: Fix overwriting request callback" | * 21b39fa2 Revert "Bluetooth: fix use-after-free in accessing skb after sending it" * | bb58b1f9 Merge 6.1.117 into android14-6.1-lts |\| | * 59d7b1a7 Linux 6.1.117 | * 17837998 media: amphion: Fix VPU core alias name | * 44d29897 vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans | * 98d8dde9 hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer | * b911fa9e net: sched: use RCU read-side critical section in taprio_dump() | * 7f6c3c7f ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022 | * 7bce2c7a ucounts: fix counter leak in inc_rlimit_get_ucounts() | * 86dd0e8d ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove() | * 8525160e irqchip/gic-v3: Force propagation of the active state with a read-back | * ded5200f USB: serial: option: add Quectel RG650V | * 9b298c81 USB: serial: option: add Fibocom FG132 0x0112 composition | * 5a4a73a6 USB: serial: qcserial: add support for Sierra Wireless EM86xx | * 275258c3 USB: serial: io_edgeport: fix use after free in debug printk | * 604314ec usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd() | * 562804b1 usb: dwc3: fix fault at system suspend if device was already runtime suspended | * ccd811c3 usb: musb: sunxi: Fix accessing an released usb phy | * 012f4d5d signal: restore the override_rlimit logic | * 190911ce fs/proc: fix compile warning about variable 'vmcore_mmap_ops' | * 26530b75 filemap: Fix bounds checking in filemap_read() | * beced2cb media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format | * c8ec4e43 kselftest/arm64: Initialise current at build time in signal tests | * a60db84f net: do not delay dst_entries_add() in dst_release() | * 5cf45281 Revert "wifi: mac80211: fix RCU list iterations" | * 84d2f291 bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq | * 10ffafb4 riscv/purgatory: align riscv_kernel_entry | * 2cb1a73d btrfs: reinitialize delayed ref list after deleting it from the list | * ba884534 arm64: Kconfig: Make SME depend on BROKEN for now | * aa3e68bd mptcp: use sock_kfree_s instead of kfree | * 2cf0e77f net: vertexcom: mse102x: Fix possible double free of TX skb | * 424c4acb net: wwan: t7xx: Fix off-by-one error in t7xx_dpmaif_rx_buf_alloc() | * f6b2b2b9 nfs: Fix KMSAN warning in decode_getfattr_attrs() | * d3bcf406 posix-cpu-timers: Clear TICK_DEP_BIT_POSIX_TIMER on clone | * 1ced986a ALSA: hda/realtek: Fix headset mic on TUXEDO Gemini 17 Gen3 | * 4fee0ad1 ALSA: usb-audio: Add quirk for HP 320 FHD Webcam | * 80342c58 dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow | * c52ec00c dm cache: fix potential out-of-bounds access on the first resume | * 011450c2 dm cache: optimize dirty bit checking with find_next_bit when resizing | * 56507203 dm cache: fix out-of-bounds access to the dirty bitset when resizing | * 5a754d3c dm cache: fix flushing uninitialized delayed_work on cache_ctr error | * ffaf0f6e dm cache: correct the number of origin blocks to match the target length | * 66ada344 thermal/drivers/qcom/lmh: Remove false lockdep backtrace | * 1a9f55ed drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported | * 25d7e843 drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read() | * 91139f33 drm/amdgpu: Adjust debugfs eviction and IB access permissions | * 284e213f pwm: imx-tpm: Use correct MODULO value for EPWM mode | * f7557bbc ksmbd: fix slab-use-after-free in smb3_preauth_hash_rsp | * d8664ce7 ksmbd: Fix the missing xa_store error check | * f56446ba ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create | * 49500cfd can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing configuration when switching CAN modes | * 4ee68cf5 can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation | * f7503fd2 media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl() | * c63c30c9 media: v4l2-tpg: prevent the risk of a division by zero | * 4b132a46 media: pulse8-cec: fix data timestamp at pulse8_setup() | * fbefe31e media: cx24116: prevent overflows on SNR calculus | * c85db2d4 media: s5p-jpeg: prevent buffer overflows | * 5e152307 media: ar0521: don't overflow when checking PLL values | * 4f1d74f7 ASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove | * 2e9a53ee thermal/of: support thermal zones w/o trips subnode | * 648e7f59 tools/lib/thermal: Fix sampling handler context ptr | * 42a26e97 ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init() | * 3b4f6966 scsi: sd_zbc: Use kvzalloc() to allocate REPORT ZONES buffer | * d98c63c0 media: adv7604: prevent underflow condition when reporting colorspace | * fd6d84b8 media: dvb_frontend: don't play tricks with underflow values | * b751a960 media: dvbdev: prevent the risk of out of memory access | * d6386b27 media: stb0899_algo: initialize cfr before using it | * 3f8f470f Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown" | * 98ffd585 net: arc: rockchip: fix emac mdio node support | * fd4e062f net: arc: fix the device for dma_map_single/dma_unmap_single | * f3401e3c virtio_net: Add hash_key_length check | * 2af64992 net: stmmac: Fix unbalanced IRQ wake disable warning on single irq case | * 7efd9a10 net: phy: ti: add PHY_RST_AFTER_CLK_EN flag | * 76b155e1 net: hns3: fix kernel crash when uninstalling driver | * 7ad3fb3b i40e: fix race condition by adding filter's intermediate sync state | * 64aa0771 ice: change q_index variable type to s16 to store -1 value | * dac989c2 can: c_can: fix {rx,tx}_errors statistics | * bf9bff13 sctp: properly validate chunk size in sctp_sf_ootb() | * 12a39775 net: enetc: set MAC address to the VF net_device | * bbad2d5b security/keys: fix slab-out-of-bounds in key_task_permission | * 99659d23 nfs: avoid i_lock contention in nfs_clear_invalid_mapping | * ba5634fe NFSv3: handle out-of-order write replies. | * 9a65be81 NFSv3: only use NFS timeout for MOUNT when protocols are compatible | * f2223216 sunrpc: handle -ENOTCONN in xs_tcp_setup_socket() | * a50863dd platform/x86/amd/pmc: Detect when STB is not available | * 1884ab3d HID: core: zero-initialize the report buffer | * 5d739ad1 ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin | * 89e601bd ARM: dts: rockchip: Fix the spi controller on rk3036 | * 44c3b97a ARM: dts: rockchip: drop grf reference from rk3036 hdmi | * f7539956 ARM: dts: rockchip: fix rk3036 acodec node | * a45a7930 arm64: dts: imx8mp: correct sdhc ipg clk | * 65af08b5 arm64: dts: imx8-ss-vpu: Fix imx8qm VPU IRQs | * 272abcef arm64: dts: imx8qxp: Add VPU subsystem file | * ed5268f3 arm64: dts: imx8qm: Fix VPU core alias name | * 7219ff97 arm64: dts: rockchip: Fix LED triggers on rk3308-roc-cc | * 3746e8b2 arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion | * 72b96b79 arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards | * d6477a98 arm64: dts: rockchip: Fix wakeup prop names on PineNote BT node | * 8db0adae arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328 | * 89b30d16 arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator | * d7b0f08f arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-eaidk-610 * | 98a32bd6 Merge 6.1.116 into android14-6.1-lts |\| | * d7039b84 Linux 6.1.116 | * 7dcd6204 migrate_pages_batch: fix statistics for longterm pin retry | * b3660228 mm: avoid gcc complaint about pointer casting | * 23c4cb8a vt: prevent kernel-infoleak in con_font_get() | * 87de0a74 drm/amd/display: Skip on writeback when it's not applicable | * 5e84eda4 drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing | * a207af9b mtd: spi-nor: winbond: fix w25q128 regression | * 1c2f04ce LoongArch: Fix build errors due to backported TIMENS | * 82cae1e3 mm: shmem: fix data-race in shmem_getattr() | * cde8a7eb wifi: iwlwifi: mvm: fix 6 GHz scan construction | * cd0cdb51 nilfs2: fix kernel bug due to missing clearing of checked flag | * 0acaf4a5 wifi: mac80211: fix NULL dereference at band check in starting tx ba session | * 38c5fe74 x86/bugs: Use code segment selector for VERW operand | * 9f5a8347 io_uring: always lock __io_cqring_overflow_flush | * 79a727a9 vmscan,migrate: fix page count imbalance on node stats when demoting pages | * 8ca5f0ea migrate_pages: split unmap_and_move() to _unmap() and _move() | * f9e9725d migrate_pages: restrict number of pages to migrate in batch | * 1145493c migrate_pages: separate hugetlb folios migration | * 6058d02a migrate_pages: organize stats with struct migrate_pages_stats | * de0a1554 mm/migrate.c: stop using 0 as NULL pointer | * 2a4b092d migrate: convert migrate_pages() to use folios | * b0030b86 migrate: convert unmap_and_move() to use folios | * 01a0c928 mm: migrate: try again if THP split is failed due to page refcnt | * 9e8debb8 io_uring/rw: fix missing NOWAIT check for O_DIRECT start write | * 0ed78d3a io_uring: use kiocb_{start,end}_write() helpers | * 6d42982a fs: create kiocb_{start,end}_write() helpers | * 45676b82 io_uring: rename kiocb_end_write() local helper | * 8f6a0b1f kasan: remove vmalloc_percpu test | * c94e965f nvmet-auth: assign dh_key to NULL after kfree_sensitive | * 618d1939 ALSA: hda/realtek: Fix headset mic on TUXEDO Stellaris 16 Gen6 mb1 | * 47078933 mctp i2c: handle NULL header address | * 2fe5d62e ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow | * 189b9544 mm/page_alloc: let GFP_ATOMIC order-0 allocs access highatomic reserves | * bb414b7f mm/page_alloc: explicitly define how __GFP_HIGH non-blocking allocations accesses reserves | * 1cf97048 mm/page_alloc: explicitly define what alloc flags deplete min reserves * | 64e5459c Merge 7468bd2c ("mm/page_alloc: explicitly record high-order atomic allocations in alloc_flags") into android14-6.1-lts |/ * 7468bd2c mm/page_alloc: explicitly record high-order atomic allocations in alloc_flags Change-Id: I7e9c61362ad083dba825e399db297a3d91328d31 Signed-off-by:Greg Kroah-Hartman <gregkh@google.com>
Loading
Please sign in to comment