summaryrefslogtreecommitdiff
path: root/arch
AgeCommit message (Collapse)AuthorFilesLines
2026-08-01bpf, x86: Fix trampoline stack size for 128-bit argumentsYonghong Song1-5/+2
btf_distill_func_proto() accepts a function argument up to 16 bytes, so a 128-bit scalar such as __int128 reaches the x86 trampoline with arg_size == 16. But the current implementation assumes an __int128 argument only needs one register, so the register save area is under-allocated and save_args() overwrites adjacent stack slots. Compute the register count from arg_size for all arguments to fix it. Fixes: a9c5ad31fbdc ("bpf: x86: Support in-register struct arguments in trampoline programs") Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Acked-by: Leon Hwang <leon.hwang@linux.dev> Link: https://lore.kernel.org/bpf/20260729050204.2586457-1-yonghong.song@linux.dev Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-07-31KVM: VMX: Fix stale PID-pointer table entry left after vCPU freeDmytro Maluka1-0/+3
vCPU creation in kvm_vm_ioctl_create_vcpu() may fail after kvm_arch_vcpu_create() -> vmx_vcpu_create() already succeeded. In such case kvm_vm_ioctl_create_vcpu() destroys the newly created vCPU in the failure path. However, that leaves a side effect: the IPIv pid_table entry remains configured with this vCPU's pi_desc address. As a result, when another vCPU sends an IPI to the APIC ID of this failed-to-create vCPU, it will cause HW to write to this (freed!) pi_desc memory. [*] Fix this by clearing the pid_table entry when destroying the vCPU. Note that the same issue exists for SVM AVIC as well [1], to be fixed. [*] Although, since this memory is freed into the kvm_vcpu_cache kmem cache which is only used for allocating kvm_vcpus, _maybe_ this memory will only be reused for pi_desc of another vCPU, not for anything else. So _maybe_ this will only result in delivering the IPI to a wrong vCPU (possibly of another VM) in the worst case, not in a random corruption of kernel memory. Link: https://lore.kernel.org/kvm/al4rNqpBYy8FGKPw@blrnaveerao1 [1] Signed-off-by: Dmytro Maluka <dmaluka@chromium.org> Reviewed-by: Kai Huang <kai.huang@intel.com> Link: https://patch.msgid.link/20260729170621.308809-3-dmaluka@chromium.org Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31x86/cpu: Use parsed CPUID(0x1)Ahmed S. Darwish1-11/+11
On early boot CPU detection, use parsed CPUID(0x1) instead of a direct CPUID query. Beside the parser's centralization benefits, use the auto generated CPUID data types, and their C99 bitfields, instead of doing ugly bitwise operations. [ bp: - Use a common code pattern for l1 of fetching and checking it right after that - flip the check to save an indentation level - align assignments vertically. ] Signed-off-by: Ahmed S. Darwish <darwi@linutronix.de> Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de> Link: https://patch.msgid.link/20260528153923.403473-12-darwi@linutronix.de
2026-07-31KVM: x86: Rework kvm_x86_ops.vcpu_pre_run() into .vcpu_needs_initialization()Sean Christopherson10-33/+21
Rework .vcpu_pre_run() into a more specific .vcpu_needs_initialization() to consolidate the SNP and TDX control flows, and to eliminate the potentially confusing almost-collision between svm_vcpu_pre_run() and pre_sev_run(): the former is SEV specific, but is pre-KVM_RUN, whereas the latter is pre-VMRUN. Link: https://patch.msgid.link/20260731173340.2644656-4-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31KVM: nVMX: Synthesize SHUTDOWN on RSM if L2 requires emulationSean Christopherson1-0/+4
Synthesize SHUTDOWN (for L1) if L2 requires unhandleable emulation after loading guest state from SMRAM during RSM to prevent a misbehaving L1 (or userspace via L1) from tripping the sanity check that KVM doesn't try to cancel a pending nested VM-Enter. If SMRAM is modified such that RSM will load what should be impossible state for L2, then KVM will detect that it needs to emulate the current code stream and will abort VM-Entry to L2. And because KVM (rightly) expects such a scenario to be impossible, KVM WARNs and bugs the VM. __ret && !(vcpu->kvm)->vm_bugged WARNING: arch/x86/kvm/vmx/vmx.c:6741 at vmx_handle_exit+0x65/0x790 [kvm_intel], CPU#13: vmx_invalid_nes/2902 Modules linked in: kvm_intel kvm irqbypass [last unloaded: kvm] CPU: 13 UID: 1000 PID: 2902 Comm: vmx_invalid_nes Tainted: G W 7.2.0-rc2 #124 PREEMPT Tainted: [W]=WARN Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:vmx_handle_exit+0x65/0x790 [kvm_intel] Call Trace: <TASK> kvm_arch_vcpu_ioctl_run+0xdf8/0x1d00 [kvm] kvm_vcpu_ioctl+0x2d5/0x960 [kvm] __x64_sys_ioctl+0x8a/0xd0 do_syscall_64+0xb7/0x570 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> Alternatively, KVM could suppress the WARN for the RSM case, but that would still leave the vCPU in a "bad" state that KVM doesn't know how to handle (which is also why KVM rejects attempts to do KVM_RUN when the vCPU is loaded with invalid state). And architecturally, the Intel SDM explicitly states that RSM leads to shutdown if the CPU detects invalid state. Fixes: 2bb8cafea80b ("KVM: vVMX: signal failure for nested VMEntry if emulation_required") Reported-by: Hao Zhang <zhanghao1@kylinos.cn> Link: https://patch.msgid.link/20260731173340.2644656-3-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31KVM: x86: Extract VMX's unhandleable emulation check to common x86Sean Christopherson6-6/+21
Expose VMX's check for unhandleable emulation as its own kvm_x86_ops hook, and move the actual pre-KVM_RUN check into common x86. This will allow sharing the core logic with KVM's RSM emulation without needed to add a post-RSM hook, and is a step towards removing the .vcpu_pre_run() hook entirely. Alternatively, KVM could provide a post-RSM hook as mentioned, but pre/post hooks tend to be unwieldy as the exact "timing" of the call often matters greatly. E.g. in this case, the call must slot in exactly between loading guest state from SMRAM and the hack to force the vCPU out of L2 on SHUTDOWN. Link: https://patch.msgid.link/20260731173340.2644656-2-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31x86/lib: Add CPUID(0x1) family and model calculationAhmed S. Darwish2-16/+35
The x86 library provides x86_family() and x86_model(). They take raw CPUID register output and calculate the CPU family and model from it. In follow-up work, the x86 subsystem will use APIs which access previously-parsed CPUID leafs structure instead of doing direct CPUID queries. These new APIs force using the auto generated leaf data types at <asm/cpuid/leaf_types.h>. Introduce x86 family and model calculation functions that take these auto-generated data types. Refactor the original code so that no logic is duplicated. [ bp: Massage commit message, unbreak too long line. ] Signed-off-by: Ahmed S. Darwish <darwi@linutronix.de> Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de> Link: https://patch.msgid.link/20260528153923.403473-11-darwi@linutronix.de
2026-07-31KVM: VMX: Cap VMX preemption timer to work around Intel erratumJim Mattson1-5/+35
Due to a widespread Intel erratum (e.g. EMR158), programming the VMX-preemption timer with certain large values may cause the timer to expire earlier than expected. The recommended workaround is to cap the VMX-preemption timer value to strictly less than: 2^25 * CPUID.15H:EBX[31:0] / CPUID.15H:EAX[31:0]. Calculate the maximum "safe" preemption timer value during hardware setup based on CPUID 15H when available, and use the adjusted max value in all locations where KVM currently hardcodes the max architectural value, including in the subtle case where KVM soft-disables the timer. Don't apply the workaround when running as a VM, because absent explicit enumeration to state the bug is present (or not), it's L0's responsibility to faithfully emulate/virtualize the VMX preemption timer. WARN if the above logic would result in a max value of zero and fall back to the maximum architectural value, as the expectation is that real hardware will never provide problematic EAX/EBX values (which is another reason to ignore the erratum when running as a VM; there's less chance of a false positive on the WARN due to L0 providing an unanticipated ratio). Reported-by: Sean Christopherson <seanjc@google.com> Closes: https://lore.kernel.org/all/Zn9X0yFxZi_Mrlnt@google.com/ Suggested-by: Chao Gao <chao.gao@intel.com> Assisted-by: Gemini:Gemini-Next Reviewed-by: Chao Gao <chao.gao@intel.com> Signed-off-by: Jim Mattson <jmattson@google.com> Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com> [sean: track inclusive max instead of exclusive limit, massage changelog] Link: https://patch.msgid.link/20260731171926.2629627-3-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31KVM: VMX: Bury all of the VMX preemption timer code under CONFIG_X86_64=ySean Christopherson1-53/+69
Double down on using the VMX preemption timer only for 64-bit kernels, and bury the setup and runtime adjustment code, and all global variables, under CONFIG_X86_64=y. This will allow addressing a widespread Intel erratum without running afoul of unused-but-set-variable and __udivdi3() errors on 32-bit kernels. No functional change intended. Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com> Reviewed-by: Chao Gao <chao.gao@intel.com> Link: https://patch.msgid.link/20260731171926.2629627-2-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
2026-07-31x86/cpu: Use parsed CPUID(0x0)Ahmed S. Darwish1-5/+6
Use parsed CPUID(0x0) instead of a direct CPUID query. [ bp: Drop the unnecessary NULL check. ] Signed-off-by: Ahmed S. Darwish <darwi@linutronix.de> Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de> Link: https://patch.msgid.link/20260528153923.403473-10-darwi@linutronix.de
2026-07-31Merge tag 'uml-for-linus-7.2-rc5' of ↵Linus Torvalds1-0/+3
git://git.kernel.org/pub/scm/linux/kernel/git/uml/linux Pull UML fix from Richard Weinberger: - Fix use-after-free in UML's vector networking driver * tag 'uml-for-linus-7.2-rc5' of git://git.kernel.org/pub/scm/linux/kernel/git/uml/linux: um: vector: fix use-after-free in vector_mmsg_rx()
2026-07-31Merge tag 'mm-hotfixes-stable-2026-07-30-19-30' of ↵Linus Torvalds2-2/+3
git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm Pull misc fixes from Andrew Morton: "12 hotfixes. 6 are cc:stable. 9 are for MM. There's a two-patch series from Nico which fixes a couple of PMD level mTHP accounting bugs and a two-patch series from Chris Gellermann which addresses mishandling of getline() in selftests. All the remainder are singletons - please see the changelogs for details" * tag 'mm-hotfixes-stable-2026-07-30-19-30' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm: selftests/mm: fix potential wild pointer access of getline due to missing init selftests/clone3: fix wild pointer access of getline due to missing init mm/page_reporting: use system_freezable_wq to fix UAF during suspend mm: vmscan: abort proactive reclaim early when freezing for suspend MAINTAINERS: update Nico Pache's email address arm64, mailmap: update email address for Peter Collingbourne MAINTAINERS: update address for Burak Emir mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios riscv/mm: use physical alignment for vmemmap_start_pfn mm/migrate: exclude hugetlb folios from MTHP_STAT_NR_ANON accounting mm: decrement MTHP_STAT_NR_ANON in free_zone_device_folio() mm: memcg: initialize *locked in memcg1_oom_prepare() stub
2026-07-31arm64: tegra: Correct Tegra234 p3740 interrupt flagsKrzysztof Kozlowski1-1/+1
GPIO_ACTIVE_x flags are not correct in the context of interrupt flags. These are simple defines so they could be used in DTS but they will not have the same meaning: 1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE 2. GPIO_ACTIVE_LOW = 1 => IRQ_TYPE_EDGE_RISING Realtek RT5640 codec driver requests interrupt on rising edge, so correct the interrupt flags, assuming the author of the code wanted the similar logical behavior behind the name "ACTIVE_xxx", this is: ACTIVE_HIGH => IRQ_TYPE_EDGE_RISING Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Correct Tegra234 p3737 interrupt flagsKrzysztof Kozlowski1-1/+1
GPIO_ACTIVE_x flags are not correct in the context of interrupt flags. These are simple defines so they could be used in DTS but they will not have the same meaning: 1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE 2. GPIO_ACTIVE_LOW = 1 => IRQ_TYPE_EDGE_RISING Realtek RT5640 codec driver requests interrupt on rising edge, so correct the interrupt flags, assuming the author of the code wanted the similar logical behavior behind the name "ACTIVE_xxx", this is: ACTIVE_HIGH => IRQ_TYPE_EDGE_RISING Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Correct Tegra194 p2972 interrupt flagsKrzysztof Kozlowski1-1/+1
GPIO_ACTIVE_x flags are not correct in the context of interrupt flags. These are simple defines so they could be used in DTS but they will not have the same meaning: 1. GPIO_ACTIVE_HIGH = 0 => IRQ_TYPE_NONE 2. GPIO_ACTIVE_LOW = 1 => IRQ_TYPE_EDGE_RISING Realtek RT5658 codec driver requests interrupt on both edges, so correct the interrupt flags, assuming the author of the code wanted the similar logical behavior behind the name "ACTIVE_xxx", this is: ACTIVE_HIGH => IRQ_TYPE_EDGE_RISING Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Drop CPU masks from GICv3 PPI interruptsGeert Uytterhoeven1-5/+5
Unlike older GIC variants, the GICv3 DT bindings do not support specifying a CPU mask in PPI interrupt specifiers. Drop the masks. Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be> Reviewed-by: Jon Hunter <jonathanh@nvidia.com> Tested-by: Jon Hunter <jonathanh@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31ARM: tegra: Replace __ASSEMBLY__ with __ASSEMBLER__Thomas Huth2-2/+2
While the GCC and Clang compilers already define __ASSEMBLER__ automatically when compiling assembly code, __ASSEMBLY__ is a macro that only gets defined by the Makefiles in the kernel. This can be very confusing when switching between userspace and kernelspace coding, or when dealing with uapi headers that rather should use __ASSEMBLER__ instead. So let's standardize now on the __ASSEMBLER__ macro that is provided by the compilers. This is a completely mechanical patch (done with a simple "sed -i" statement). Signed-off-by: Thomas Huth <thuth@redhat.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Add Lenovo ThinkEdge SE70 device treeJiqi Li2-0/+112
Add initial device tree support for the Lenovo ThinkEdge SE70, an industrial edge gateway based on the NVIDIA Jetson Xavier NX module (P3668-0001) with a custom carrier board. This initial submission includes: - 40-pin expansion header pinmux configuration - External Micro SD card slot with dedicated 3.3V regulator - I2C bus for 40-pin header Static verification passed: dt_binding_check and dtbs compilation complete without errors. Reviewed-by: Mikko Perttunen <mperttunen@nvidia.com> Signed-off-by: Jiqi Li <lijq9@lenovo.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Add pinctrl nodes for Tegra264Prathamesh Shete1-0/+15
Add the three pin controller (MAIN, UPHY, AON) device-tree nodes found on Tegra264. Signed-off-by: Prathamesh Shete <pshete@nvidia.com> Reviewed-by: Jon Hunter <jonathanh@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Fix CMDQV interrupt type on Tegra264Ashish Mhetre1-5/+5
The CMDQV interrupts on Tegra264 are described as level-triggered, but per the hardware interrupt documentation these interrupts are actually edge-triggered. Correct the interrupt type for all CMDQV nodes from IRQ_TYPE_LEVEL_HIGH to IRQ_TYPE_EDGE_RISING. Fixes: fe57d0ac4835 ("arm64: tegra: Add nodes for CMDQV") Reported-by: Nicolin Chen <nicolinc@nvidia.com> Signed-off-by: Ashish Mhetre <amhetre@nvidia.com> Acked-by: Jon Hunter <jonathanh@nvidia.com> Acked-by: Nicolin Chen <nicolinc@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Properly sort devices on Tegra264Thierry Reding1-83/+83
We always sort by unit-address and fallback to alphanumeric sorting for nodes that don't have a unit-address. Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Add GTE nodes for Tegra264Suneel Garapati1-0/+19
Add AON GPIO and system LIC GTE instances for Tegra264. Signed-off-by: Suneel Garapati <suneelg@nvidia.com> Acked-by: Dipen Patel <dipenp@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Add Host1x and VIC on Tegra264Mikko Perttunen1-0/+63
Tegra264 has a host1x instance with a VIC (video image compositor). Other multimedia engines have moved outside host1x. Stream IDs are now namespaced by device rather than being defined globally -- however, the only engine we have using context isolation is VIC so we only define VIC's range of context devices. Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Populate CPU and L2 cache nodes on Tegra264Sumit Gupta1-0/+321
Add the remaining 12 CPU nodes and all 14 L2 cache nodes for the Tegra264 CPU Complex, which comprises up to 14 ARM Neoverse V3AE CPUs. Each CPU has its own private 1MB L2 cache. Signed-off-by: Sumit Gupta <sumitg@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31arm64: tegra: Enable GPCDMA in Tegra264 and add iommu-mapAkhil R2-0/+5
Enable GPCDMA in Tegra264 and add the iommu-map property so that each channel uses a separate stream ID and gets its own IOMMU domain for memory. Signed-off-by: Akhil R <akhilrajeev@nvidia.com> Reviewed-by: Jon Hunter <jonathanh@nvidia.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31ARM: tegra: Fix OF node reference leaks in IRQ initYuho Choi1-3/+6
tegra114_gic_cpu_pm_registration() and tegra_init_irq() use of_find_matching_node() for temporary IRQ init lookups, but the helper returns a referenced node even when the result is used only as a boolean or as an of_iomap() input. Use scoped device_node cleanup for both lookups so the references are dropped when the functions return. Fixes: 7e8b15dbc392 ("ARM: tegra114: Reprogram GIC CPU interface to bypass IRQ on CPU PM entry") Fixes: e9479e0e832b ("ARM: tegra: skip gic_arch_extn setup if DT has a LIC node") Signed-off-by: Yuho Choi <dbgh9129@gmail.com> Signed-off-by: Thierry Reding <treding@nvidia.com>
2026-07-31powerpc/kexec_file: Prevent kexec range truncationJinjie Ruan1-7/+5
Sashiko AI review pointed out the following issue. The __merge_memory_ranges() function incorrectly handles overlapping memory ranges when merging them. Although sort_memory_ranges() sorts all ranges by their start address in ascending order beforehand, the merge logic remains defective in two ways: 1. It compares the current range's start against the previous element (i-1) instead of the running target index (idx) 2. It unconditionally overwrites 'ranges[idx].end' with 'ranges[i].end'. This logic flaw leads to critical memory truncation when a larger memory range completely subsumes subsequent smaller ranges. For example, consider a sorted input array with three ranges: Range A (idx=0): [0x1000 - 0x9000] Range B (i=1): [0x2000 - 0x5000] (completely inside Range A) Range C (i=2): [0x6000 - 0x8000] (completely inside Range A) 1. When i=1 (Range B): ranges[1].start (0x2000) <= ranges[0].end + 1 (0x9001) is TRUE. The code executes: ranges[0].end = ranges[1].end, which erroneously shrinks Range A's end from 0x9000 down to 0x5000. 2. When i=2 (Range C): ranges[2].start (0x6000) <= ranges[1].end + 1 (0x5001) is FALSE. The code falls into the else block, creating a broken new range. As a result, valid memory fragments [0x5001 - 0x5fff] and [0x8001 - 0x9000] are completely lost from the kexec exclude lists, potentially allowing the crash kernel to overwrite active memory, causing data corruption or crashes. Fix this by ensuring the start of the current range is compared against the end of the active merged range (idx), and use max() to safely prevent the outer boundary from being truncated. Cc: stable@vger.kernel.org Fixes: 180adfc532a8 ("powerpc/kexec_file: Add helper functions for getting memory ranges") Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com> Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260729012948.2797865-4-ruanjinjie@huawei.com
2026-07-31powerpc/kexec_file: Fix null-ptr-def in extra size calculationJinjie Ruan1-1/+1
A static Sashiko AI review identified a potential NULL pointer dereference in kexec_extra_fdt_size_ppc64(). On platforms without any reserved memory regions, get_reserved_memory_ranges() can return 0 while leaving 'rmem' unallocated as NULL. Passing it directly leads to a kernel panic when evaluating 'rmem->nr_ranges'. Add a NULL check for 'rmem' to prevent this crash. Cc: stable@vger.kernel.org Fixes: 0d3ff067331e ("powerpc/kexec_file: fix extra size calculation for kexec FDT") Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com> Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260729012948.2797865-3-ruanjinjie@huawei.com
2026-07-31powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr()Jinjie Ruan1-1/+1
In get_crash_memory_ranges(), if crash_exclude_mem_range() failed after realloc_mem_ranges() has successfully allocated the cmem memory, it just returns an error but leaves cmem pointing to the allocated memory, nor is it freed in the caller update_crash_elfcorehdr(), which cause a memory leak, goto out to free the cmem. Fixes: 849599b702ef ("powerpc/crash: add crash memory hotplug support") Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com> Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260729012948.2797865-2-ruanjinjie@huawei.com
2026-07-31powerpc/44x: Set GPIO chip parentRosen Penev1-0/+1
The PPC4xx GPIO driver stopped assigning an explicit parent to the gpio_chip when it moved away from of_mm_gpiochip_add_data(). Restore that association from the platform device so OF GPIO lookup can match phandles to the registered gpiochip. Tested on: Cisco MX60W. No more probe deferral. Assisted-by: Codex:GPT-5.5 Fixes: 1044dbaf2a77 ("powerpc/44x: Change GPIO driver to a proper platform driver") Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Reviewed-by: Linus Walleij <linusw@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260517063754.21819-1-rosenp@gmail.com
2026-07-31powerpc: implement get_direction() in cpm2Christophe Leroy (CS GROUP)1-0/+13
The lack of get_direction() callback in this driver causes GPIOLIB to emit a warning. Implement it. Fixes: e623c4303ed1 ("gpiolib: sanitize the return value of gpio_chip::get_direction()") Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/c6eb70aa0e1ba6e15f947c827006aa79edace05c.1785318836.git.chleroy@kernel.org
2026-07-31powerpc/serial: Use generic BASE_BAUD in asm/serial.hThorsten Blum1-2/+2
Include asm-generic/serial.h and use the generic BASE_BAUD definition instead of redefining it. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260729223807.570178-3-thorsten.blum@linux.dev
2026-07-31powerpc/boot: Remove unused sprintf()Thorsten Blum2-14/+0
There have been no sprintf() callers in the boot wrapper since commit e275e023aa69 ("powerpc/44x: Warp patches for the new NDFC driver"). Remove the function definition and declaration. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260724172200.208722-2-thorsten.blum@linux.dev
2026-07-31powerpc/pseries: Avoid strlen() in do_{remove,update}_property()Thorsten Blum1-2/+2
Check only the first byte instead of scanning the entire string with strlen(). Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260721155346.121975-4-thorsten.blum@linux.dev
2026-07-31powerpc/powernv: Avoid strlen() in pnv_restart()Thorsten Blum1-1/+1
Check only the first byte instead of scanning the entire string with strlen(). Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260721155346.121975-3-thorsten.blum@linux.dev
2026-07-31powerpc/powermac: Simplify bootx_scan_dt_build_struct()Thorsten Blum1-3/+1
Assign the empty string directly instead of NULL checking namep again. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260720231453.117271-2-thorsten.blum@linux.dev
2026-07-31powerpc/ps3: Use cpu_relax() in ps3_create_spu()Thorsten Blum1-6/+4
Use cpu_relax() to wait for the execution status SPE_EX_STATE_EXECUTED. Drop the comments while at it. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260720231153.116827-2-thorsten.blum@linux.dev
2026-07-31powerpc/dt_cpu_ftrs: Avoid separate strlen() in scan_callback()Thorsten Blum1-4/+3
Check only the first byte instead of scanning the entire string with strlen(). While at it, keep dt_cpu_name static, but move it into dt_cpu_ftrs_scan_callback(), where it is assigned. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260701114428.818748-3-thorsten.blum@linux.dev
2026-07-31powerpc/pseries/ras: Use struct_size() to simplify fwnmi_get_errinfo()Thorsten Blum1-9/+7
Now that struct rtas_error_log uses a flexible array member for the extended log buffer, use struct_size() to calculate the total RTAS error log size and avoid using the hard-coded header size of 8 bytes. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260627104730.276858-4-thorsten.blum@linux.dev
2026-07-31powerpc/rtasd: Use struct_size() to simplify log_rtas_len()Thorsten Blum1-13/+6
Now that struct rtas_error_log uses a flexible array member for the extended log buffer, use struct_size() to calculate the total RTAS error log size and avoid using the hard-coded header size of 8 bytes. Use min() to replace the open-coded implementation while at it. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260627104730.276858-3-thorsten.blum@linux.dev
2026-07-31powerpc/pseries: Simplify attribute description check in papr_init()Thorsten Blum1-5/+1
Check only the first byte instead of scanning the entire string with strnlen(). Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260626110718.4367-2-thorsten.blum@linux.dev
2026-07-31s390/smp: Reflect (de)configured CPUs to cpu_enabled_maskMete Durlu1-0/+5
On s390, CPUs can be in a state where it is not possible to hotplug them online before certain prequisite steps. For example the CPUs which get introduced during runtime of a system can posses a "deconfigured" state which prevents them from being hotplugged online before they get configured. Another case is when users set the configured state of CPUs themselves via "chcpu" or sysfs attributes. On s390 available CPUs are being registered as new devices via smp_add_core() either during boot or after a CPU rescan (for newly added CPUs during runtime). Registered CPUs are marked as enabled without considering the configure states. Add necessary checks to smp_add_core() and userspace configure attribute handler. Reflect the configured CPUs to cpu_enabled_mask to correctly represent which CPUs can be hotplugged online. Signed-off-by: Mete Durlu <meted@linux.ibm.com> Acked-by: Heiko Carstens <hca@linux.ibm.com> Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-31s390/sclp: Allow SCLP Action Qualifiers for Spyre card status reportingNiklas Schnelle1-0/+3
Add SCLP Action Qualifiers used by the Spyre stack for reporting of the card's initialization status, recoverable errors, and telemetry data. Co-developed-by: Andreas Krebbel <krebbel@linux.ibm.com> Signed-off-by: Andreas Krebbel <krebbel@linux.ibm.com> Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com> Reviewed-by: Benjamin Block <bblock@linux.ibm.com> Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-31s390/ap: Fix queue depth field lengthFinn Callies1-2/+2
The queue depth field is defined as a 5 bit field in the Z architecture instead of a 4 bit field. The queue depth (qd) can be in range 0-31 and is reported in bits 59-63 of the TAPQ response. Currently this has no effect as all CEX generations report a queue depth of 7, which fits into 4 bits. However, future CEX generations reporting a value >15 would not be properly reflected by the ap bus and therefore all user space applications relying on it. Reviewed-by: Harald Freudenberger <freude@linux.ibm.com> Signed-off-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-31powerpc: rtas: use get_user to simplify manage_flash_writeThorsten Blum1-17/+10
Drop the local 10-byte buffer. The old code copied at most 9 bytes from the user buffer, but only the first byte was used to select the RTAS operation. Use get_user() to read the command byte instead and compare it directly with '0' and '1'. Drop the explicit user buffer check, since get_user() will fail on a NULL pointer and correctly return -EFAULT instead of -EINVAL. Remove the now-obsolete string constants as well as any strncmp() and strlen() calls. Return the original count instead of a potentially capped value, since the full user write has been consumed once the command is accepted. Use unsigned int op to better match the manage_flash() interface. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260528201226.1599977-3-thorsten.blum@linux.dev
2026-07-31s390/pci: Fix s390_pci_mmio_write syscall error return without MIONiklas Schnelle1-0/+1
On a machine without PCI memory-I/O (MIO) support or when running with pci=nomio the s390 specific PCI MMIO write syscall checks if the MMIO cookie is above ZPCI_IOMAP_ADDR_BASE as a sanity check before even trying to perform the MMIO. If this check fails the return value was left unchanged and thus 0 from prior operations falsely indicating success. This could potentially confuse user-space into falsely believing the MMIO, on a mapping not valid for MMIO was successful. Fix this by setting the return value to -EFAULT prior to the check following the same pattern as elsewhere in the same function. Cc: stable@vger.kernel.org Reviewed-by: Julian Ruess <julianr@linux.ibm.com> Reviewed-by: Farhan Ali <alifm@linux.ibm.com> Fixes: a67a88b0b8de ("s390/pci: remove races against pte updates") Signed-off-by: Niklas Schnelle <schnelle@linux.ibm.com> Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-31powerpc/boot: drop redundant assignment in serial_edit_cmdlineThorsten Blum1-1/+0
Drop the redundant buffer assignment in serial_edit_cmdline() since the cp pointer is immediately overwritten. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260528082357.1397611-3-thorsten.blum@linux.dev
2026-07-31powerpc/kexec_file: use snprintf to simplify setup_kdump_cmdlineThorsten Blum1-10/+4
Replace the manual string length accounting, memcpy(), and NUL termination with a single snprintf() call to prepend the elfcorehdr= address and to detect string truncation at the same time. Use kmalloc() to avoid unnecessarily zeroing the memory. While at it, also use "prepending" instead of "appending" in the error message. Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260527000105.1081651-3-thorsten.blum@linux.dev
2026-07-31powerpc: enable to run posix cpu timers in task contextShrikanth Hegde1-0/+1
Now that all kvm entry to guest paths handle the task work using the generic framework, enable HAVE_POSIX_CPU_TIMERS_TASK_WORK which allows running posix cpu timers in task context instead of running them in hardirq. This would is a necessary step towards enabling PREEMPT_RT on powerNV systems. Signed-off-by: Shrikanth Hegde <sshegde@linux.ibm.com> Signed-off-by: Vishal Chourasia <vishalc@linux.ibm.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260709092140.1753715-5-vishalc@linux.ibm.com
2026-07-31KVM: powerpc: Use generic xfer to guest work functionVishal Chourasia4-23/+55
Since commit 2cd571245b43 ("sched/fair: Add related data structure for task based throttle") in v6.18, CFS bandwidth throttling no longer dequeues a task directly; it queues task_work via TWA_RESUME and sets TIF_NOTIFY_RESUME, relying on that work running before the task returns to guest/user mode. The powerpc KVM run loops only checked for reschedule and signals, never TIF_NOTIFY_RESUME, so the deferred throttle never ran while a vCPU stayed in the run loop: a CPU-bound guest that rarely exits to userspace ran far past its cpu.max quota and then appeared frozen for minutes while the accrued throttle debt was repaid. Use the generic infrastructure to check for and handle pending work before transitioning into guest mode, replacing the open-coded need_resched() and cond_resched() checks in the Book3S HV run loops and in the common kvmppc_prepare_to_enter() used by the Book3S PR and BookE run loops. The redundant signal_pending() recheck (and its sigpend label) in kvmhv_run_single_vcpu() is also dropped, as xfer_to_guest_mode_work_pending() is a superset of it. This picks up handling for TIF_NOTIFY_RESUME, which was previously ignored, meaning task work will now be correctly handled on every guest re-entry. Selecting VIRT_XFER_TO_GUEST_WORK disables RCU's last-resort self-IPI fallback for vCPU tasks (see rcu_irq_work_resched()), which on nohz_full CPUs was what forced a reschedule for deferred rcuog wakeups queued right before guest entry. Take over that obligation the same way x86 and s390 do: call xfer_to_guest_mode_prepare() with IRQs disabled immediately before the final xfer_to_guest_mode_work_pending() check at each guest-entry gate (kvmhv_run_single_vcpu(), kvmppc_run_core() and kvmppc_prepare_to_enter()). In kvmppc_prepare_to_enter(), IRQs are now disabled with local_irq_disable() before hard_irq_disable(): on 32-bit, hard_irq_disable() is a raw MSR[EE] clear that bypasses the lockdep/irq-tracing state, and the strict xfer_to_guest_mode helpers assert that IRQs are seen as disabled. This also allows upgrading the racy __xfer_to_guest_mode_work_pending() check to the asserting variant, as this loop is the terminal gate for the PR and BookE paths. In kvmhv_run_single_vcpu(), the -EINTR exit and the pre-existing kvmhv_setup_mmu() failure exit now leave via the done label instead of returning directly, keeping the run_vcpu enter/exit tracepoints balanced and vcpu->arch.ret consistent with the returned value. In kvmppc_prepare_to_enter() the generic helper accounts the signal exit (vcpu->stat.signal_exits and KVM_EXIT_INTR) but does not set the exit type, so kvmppc_set_exit_type(SIGNAL_EXITS) is retained on the signal path to preserve the E500 CONFIG_KVM_EXIT_TIMING histogram; it is a no-op otherwise. Signed-off-by: Vishal Chourasia <vishalc@linux.ibm.com> Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com> Link: https://patch.msgid.link/20260709092140.1753715-4-vishalc@linux.ibm.com