summaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorFilesLines
2026-07-17fuse: allow larger read requests by setting bdi->io_pagesJim Harris1-0/+1
A FUSE server that advertises a large max_pages and max_write (e.g. max_pages=256, max_write=1MB) cannot currently obtain matching FUSE_READ request sizes from the kernel. Buffered sequential writes arrive at the server at the negotiated max_write size, but a large buffered read() is split into several smaller FUSE_READ requests. For a buffered read, filemap_get_pages() -> page_cache_sync_ra() sizes the read against ractl_max_pages(): max_pages = ractl->ra->ra_pages; if (req_size > max_pages && bdi->io_pages > max_pages) max_pages = min(req_size, bdi->io_pages); fuse leaves bdi->io_pages at the default VM_READAHEAD_PAGES (128KB), so a 1MB read() (req_size = 256 pages) is clamped to the readahead window (128KB, or 256KB for POSIX_FADV_SEQUENTIAL), producing four 256KB FUSE_READ round-trips instead of one. Set bdi->io_pages to fc->max_pages after feature negotiation. As the code above shows, io_pages only raises the limit when the request size already exceeds the readahead window, so it enlarges explicitly requested reads without enlarging the speculative readahead window. This avoids increasing speculative page-cache readahead on behalf of an unprivileged server. NFS does the same, setting io_pages from rpages while leaving ra_pages at the default. fc->max_pages is already bounded by fc->max_pages_limit (and, for virtio-fs, by the virtqueue descriptor count), so io_pages inherits the same bound. Suggested-by: Joanne Koong <joannelkoong@gmail.com> Signed-off-by: Jim Harris <jim.harris@nvidia.com> Assisted-by: Cursor:claude-opus-4.8 Reviewed-by: Joanne Koong <joannelkoong@gmail.com> Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
2026-07-17selftests: ntsync: correct CONFIG_NTSYNC nameEthan Nelson-Moore1-1/+1
The config fragment for these tests defines CONFIG_WINESYNC, which refers to an earlier name for the ntsync driver before it was merged [1]. Correct it to define CONFIG_NTSYNC instead. [1] https://lore.kernel.org/all/f4cc1a38-1441-62f8-47e4-0c67f5ad1d43@codeweavers.com/ Fixes: 7f853a252cde ("selftests: ntsync: Add some tests for semaphore state.") Cc: stable <stable@kernel.org> Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com> Reviewed-by: Elizabeth Figura <zfigura@codeweavers.com> Link: https://patch.msgid.link/20260609175505.19632-1-enelsonmoore@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17comedi: comedi_parport: deal with premature interruptIan Abbott1-3/+10
Syzbot reported a general protection fault in `comedi_get_is_subdevice_running()`, which was called from the interrupt handler `parport_interrupt()` in the "comedi_parport" driver, but it does not currently have a C reproducer for the problem. It's probably due to a premature interrupt for one of two reasons: 1. The driver sets up the interrupt handler before the comedi subdevices used by the interrupt handler have been allocated, but does not disable the interrupt in the parallel port's CTRL register first. 2. The driver uses a user-supplied I/O port base address which Syzbot would have supplied, but it might not be backed by real parallel port hardware. Change the initialization order in the driver's comedi "attach" handler (`parport_attach()`) so that the hardware registers are initialized before the interrupt handler is requested. This should prevent premature interrupts occurring for real hardware. Also add a test to the interrupt handler to ensure the comedi device is fully attached and return early if it isn't. Fixes: 241ab6ad7108e ("Staging: comedi: add comedi_parport driver") Reported-by: syzbot+f24c3d5d316011bacc70@syzkaller.appspotmail.com Cc: stable <stable@kernel.org> Signed-off-by: Ian Abbott <abbotti@mev.co.uk> Link: https://patch.msgid.link/20260527125104.96596-1-abbotti@mev.co.uk Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17uio_hv_generic: Bind to FCopy device by defaultBen Hutchings1-1/+7
The Hyper-V kernel-mode fcopy driver was removed in 6.10 and the new fcopy daemon requires this uio driver to function. However, by default the driver does not bind to any devices, and must be configured through the sysfs "new_id" file. Since the FCopy device is now only usable through this driver, add its ID to the driver's ID table so that the daemon will work "out of the box". Signed-off-by: Ben Hutchings <benh@debian.org> Fixes: ec314f61e4fc ("Drivers: hv: Remove fcopy driver") Cc: stable <stable@kernel.org> Link: https://patch.msgid.link/ahQ6xuhSReidmN-3@decadent.org.uk Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17MAINTAINERS: Add Greg Kroah-Hartman to GPIBDave Penkler1-0/+1
Greg was not receiving patches for the GPIB subsystem from folks using scripts/get_maintainer.pl -f drivers/gpib. Signed-off-by: Dave Penkler <dpenkler@gmail.com> Link: https://patch.msgid.link/20260630155517.5685-1-dpenkler@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17dmaengine: Constify struct dma_descriptor_metadata_opsChristophe JAILLET3-3/+3
'struct dma_descriptor_metadata_ops' in not modified in these drivers. Constifying these structures moves some data to a read-only section, so increases overall security, especially when the structure holds some function pointers. On a x86_64, with allmodconfig, as an example: Before: ====== text data bss dec hex filename 120635 21584 64 142283 22bcb drivers/dma/xilinx/xilinx_dma.o After: ===== text data bss dec hex filename 120699 21520 64 142283 22bcb drivers/dma/xilinx/xilinx_dma.o Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr> Reviewed-by: Frank Li <Frank.Li@nxp.com> Reviewed-by: Sai Sree Kartheek Adivi <s-adivi@ti.com> Reviewed-by: Manivannan Sadhasivam <mani@kernel.org> Reviewed-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com> Link: https://patch.msgid.link/b0a22171f3ed68e156a2fa84383e99c23ec6b2ff.1784037977.git.christophe.jaillet@wanadoo.fr Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17dmaengine: validate dev and name in dma_request_chan()bui duc phuc1-1/+6
dma_request_chan() assumes both @dev and @name are valid, but neither is checked before use. dev is dereferenced immediately via dev_fwnode(), which accesses dev->of_node or dev->fwnode without checking for NULL. Likewise, if name is NULL and the OF/ACPI lookup does not succeed, the legacy filter-map path eventually passes it to strcmp(), resulting in a NULL pointer dereference. These are caller bugs rather than normal lookup failures, so add a WARN_ON() at function entry to catch invalid arguments early during development instead of crashing later. No functional change for valid callers. Signed-off-by: bui duc phuc <phucduc.bui@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260716052758.23465-1-phucduc.bui@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17Merge tag 'svc_fixes_for_v7.2' of ↵Greg Kroah-Hartman2-13/+22
ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/dinguyen/linux into char-misc-linus Dinh writes: firmware: stratix10-svc: fixes for v7.2 - Fix a memory leak by explicitly using kfree() to match the list-managed lifetime - Fix FCS SMC call documentation - Add proper handling of a no response from the SDM - Fix teardown order of service driver * tag 'svc_fixes_for_v7.2' of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/dinguyen/linux: firmware: stratix10-svc: fix teardown order in remove to prevent race firmware: stratix10-svc: handle NO_RESPONSE in async poll firmware: stratix10-svc: fix FCS SMC call kernel-doc firmware: stratix10-svc: fix memory leaks and list corruption bugs
2026-07-17docs/zh_CN: Update rust/testing.rst translationBen Guo1-0/+4
Update Documentation/rust/testing.rst translation. Update the translation through commit 09699b24199a ("Documentation: rust: testing: add Kconfig guidance") Reviewed-by: Gary Guo <gary@garyguo.net> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Ben Guo <ben.guo@openatom.club> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: Update rust/arch-support.rst translationBen Guo1-0/+1
Update Documentation/rust/arch-support.rst translation. Update the translation through commit 3f70ebe63858 ("s390: Enable Rust support") Reviewed-by: Gary Guo <gary@garyguo.net> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Ben Guo <ben.guo@openatom.club> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: Update rust/general-information.rst translationBen Guo1-3/+79
Update Documentation/rust/general-information.rst translation. Update the translation through commit 86c5d1c6740c ("docs: rust: general-information: use real example") Reviewed-by: Gary Guo <gary@garyguo.net> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Ben Guo <ben.guo@openatom.club> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: Update rust/quick-start.rst translationBen Guo1-29/+19
Update Documentation/rust/quick-start.rst translation. Update the translation through commit a4392ed1c8b9 ("docs: rust: quick-start: remove GDB/Binutils mention") Reviewed-by: Gary Guo <gary@garyguo.net> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Ben Guo <ben.guo@openatom.club> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: fix KASAN SW_TAGS mode descriptionchengyaqiang1-1/+1
CONFIG_KASAN_SW_TAGS enables Software Tag-Based KASAN mode, not Hardware Tag-Based mode. Fix the incorrect translation in the Chinese documentation. The original text incorrectly described both CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_HW_TAGS as "基于硬件标签" (hardware tag-based). Correct CONFIG_KASAN_SW_TAGS to "基于软件标签" (software tag-based). Signed-off-by: chengyaqiang <chengyaqiang@tsinghua.edu.cn> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: update admin-guide/index.rst translationYan Zhu1-50/+152
update Documentation/admin-guide/index.rst Chinese translation Update the translation through commit f0efd29aa60c ("doc: Add CPU Isolation documentation") Signed-off-by: Yan Zhu <zhuyan2015@qq.com> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: fix CONFIG_CONPAT typo for CONFIG_COMPATEthan Nelson-Moore1-1/+1
The Simplified Chinese translation of security/self-protection.rst contains a typo CONFIG_CONPAT for CONFIG_COMPAT. Fix it. Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev> Reviewed-by: WangYuli <wangyl5933@chinaunicom.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: fix CONFIG_CGROUP typo for CONFIG_CGROUPSEthan Nelson-Moore1-1/+1
The Simplified Chinese translation of accounting/psi.rst contains a typo CONFIG_CGROUP for CONFIG_CGROUPS. Fix it. Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_TW: replace 接口 with 介面 in stable-api-nonsense.rstpanzhipop1-31/+31
In Taiwan's standard terminology, as defined by the National Academy for Educational Research (NAER) term bank (https://terms.naer.edu.tw/), the correct Traditional Chinese translation for "interface" is "介面", not "接口" (which is used in Simplified Chinese/Mainland China). Update the zh_TW translation of stable-api-nonsense.rst to use the proper Taiwanese terminology. Signed-off-by: panzhipop <kipp455187@gmail.com> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: add module-signing Chinese translationYan Zhu1-0/+250
Translate .../admin-guide/module-signing.rst into Chinese. Update the translation through commit 0ad9a71933e7 ("modsign: Enable ML-DSA module signing") Reported-by: kernel test robot <lkp@intel.com> Closes: https://lore.kernel.org/oe-kbuild-all/202604182216.Qpd5KifK-lkp@intel.com/ Signed-off-by: Yan Zhu <zhuyan2015@qq.com> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: restructure how-to.rst patch submission workflowDongliang Mu1-28/+77
Split "导出补丁和制作封面" into separate "导出补丁" and "为补丁集制作封面" sections, and document the single-patch (git format-patch -1) and multi-patch (-N) flows side by side so new contributors do not have to infer one from the other. Replace the invalid "git am --amend" invocations with "git commit --amend" in both the checkpatch fix-up and the iteration sections. Expand the iteration section with a worked v2 example showing where the changelog goes relative to the --- separator, and describe how v3/v4 changelogs stack newest-on-top. Finally, add a note reminding submitters to carry Reviewed-by tags from reviewers into the next revision, placed below Signed-off-by. Assisted-by: Claude:claude-opus-4-7 Signed-off-by: Dongliang Mu <dzm91@hust.edu.cn> Reviewed-by: Yanteng Si <si.yanteng@linux.dev> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: add --no-merges to git log example in how-to.rstBen Guo1-1/+3
Add --no-merges flag to prevent referencing merge commits in the through-commit field of translation commit messages. Signed-off-by: Ben Guo <ben.guo@openatom.club> Reviewed-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17docs/zh_CN: polish how-to.rstDongliang Mu1-23/+23
Editorial pass on the Chinese translation contributor guide. - Fix typos: 网络通常 → 通畅; remove trailing backticks on the checktransupdate.py command; mis-placed 。 → , in the 紧急处理 section; 您/你 and 的/地 inconsistencies in 进阶. - Correct "git email" to "git send-email", matching usage elsewhere in the document. - Replace an invalid <URL> inline form with a bare URL so Sphinx renders the lore.kernel.org link. - Tighten grammar and wording: 针对于 → 面向; drop redundant 最多 before 不超过 and tautological 即可; remove double 的 in 您的翻译的内容; resolve ambiguity around 继续 placement in the 把补丁提交到邮件列表 section; and similar small fixes. Assisted-by: Claude:claude-opus-4-6 Signed-off-by: Dongliang Mu <dzm91@hust.edu.cn> Signed-off-by: Alex Shi <alexs@kernel.org>
2026-07-17staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()Moksh Panicker1-1/+8
rtw_get_wps_ie() iterates over IE data from network frames without validating that the IE header and payload fit within the remaining buffer before reading them. Specifically: - in_ie[cnt + 1] is read without checking cnt + 1 < in_len - memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check - in_ie[cnt + 1] is used as length without verifying payload fits Add bounds checks at the top of the loop body to break early if fewer than 2 bytes remain for the IE header, or if the declared payload extends past the end of the buffer. Also require at least 4 bytes of payload before comparing the WPS OUI. Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver") Cc: stable <stable@kernel.org> Signed-off-by: Moksh Panicker <mokshpanicker.7@gmail.com> Link: https://patch.msgid.link/20260625202911.26782-1-mokshpanicker.7@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: fix inverted HT40 secondary channel offsetMinJea Kim1-1/+1
rtw_get_chan_type() maps the driver's channel offset to nl80211 channel types the wrong way around. In this driver HAL_PRIME_CHNL_OFFSET_LOWER means the primary channel is the lower 20 MHz half of the 40 MHz pair, i.e. the secondary channel is above the primary one: rtw_get_center_ch() computes the center channel as "channel + 2" for OFFSET_LOWER, and bwmode_update_check() sets OFFSET_LOWER when the AP's HT operation IE announces SCA (secondary channel above). In nl80211 terms that is NL80211_CHAN_HT40PLUS, not HT40MINUS. Because of the inversion, cfg80211_rtw_get_channel() reports an HT40+ association as HT40-. For an HT40+ AP on a low channel (e.g. channel 3) the resulting chandef spans below the 2.4 GHz band edge and is invalid, so the regulatory core tears the connection down 60 seconds (REG_ENFORCE_GRACE_MS) after the AP's country IE triggers a regdomain change: reg_check_chans_work() considers the reported chandef unusable and calls cfg80211_leave(). The supplicant then reconnects, the country IE changes the regdomain again, and the cycle repeats, causing a disconnect/reconnect loop every ~65 seconds for as long as the link is up. Observed on a TECLAST X80 Power tablet (RTL8723BS) associated to an HT40+ AP on channel 3 with a KR country IE; a kprobe trace showed cfg80211_disconnect() being invoked from reg_check_chans_work(). With the mapping fixed, "iw dev wlan0 info" reports the correct "width: 40 MHz, center1: 2432 MHz" and the periodic disconnects stop. Fixes: 5402cc178c5d ("staging: rtl8723bs: add get_channel cfg80211 implementation") Cc: stable@vger.kernel.org Assisted-by: Claude-Code:claude-fable-5 bpftrace Signed-off-by: MinJea Kim <qndkdrnl@gmail.com> Link: https://patch.msgid.link/20260714131421.3980-1-qndkdrnl@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17dma: fsl_raid: use devm_platform_ioremap_resourceRosen Penev1-9/+5
Replace the open-coded platform_get_resource() plus devm_ioremap() sequence with devm_platform_ioremap_resource(), which fetches the resource, requests the region and maps it in one call. Switch the error check to IS_ERR()/PTR_ERR() and drop the now-unused struct resource pointer. The raideng node has a single reg region (0x320000, 0x10000); the job-queue/ring children are separate OF devices probed independently, so the region reservation added by devm_ioremap_resource() is exclusive and does not introduce overlap failures. Assisted-by: opencode:hy3-free Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260716202949.677290-5-rosenp@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17dma: fsl_raid: keep MMIO bases as void __iomem and cast at accessRosen Penev2-11/+12
The fsl_re_ctrl and fsl_re_chan_cfg structures describe memory-mapped RAID Engine registers accessed only via ioread32be()/iowrite32be(), yet the pointers to them (re_regs in struct fsl_re_drv_private, and jrregs in struct fsl_re_chan) were not __iomem-qualified, so sparse emitted "different address spaces" warnings for every register access. Store both MMIO bases as a plain void __iomem * and derive jrregs with void __iomem * arithmetic from re_regs, rather than carrying typed register struct pointers through the driver. Each function that touches the registers introduces a local typed pointer (struct fsl_re_ctrl __iomem *ctrl) and uses ->field, which is the idiomatic kernel pattern and keeps the registers' __iomem qualification intact. Reported-by: kernel test robot <lkp@intel.com> Link: https://lore.kernel.org/oe-kbuild-all/202008111749.yy85rFMD%25lkp@intel.com/ Assisted-by: opencode:hy3-free Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260716202949.677290-4-rosenp@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17dma: fsl_raid: set final bit via fill_cfd_frame() argumentRosen Penev1-8/+8
The final-frame bit is now passed as the "final" argument of fill_cfd_frame() (as fsl_re_prep_dma_memcpy already did) and set in CPU order before the single cpu_to_be32() store, replacing the previous read-modify-write of the __be32 efrl32 field. Assisted-by: opencode:hy3-free Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260716202949.677290-3-rosenp@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17dma: fsl_raid: convert descriptor stores to big-endianRosen Penev1-6/+7
The descriptor structs (fsl_re_cmpnd_frame / fsl_re_hw_desc) are in-memory but their fields are __be32, because the structures are handed to the device as big-endian. The driver stored CPU-endian u32 values into them directly, which is both wrong (the engine would see byte-swapped lengths/addresses) and flagged by sparse as a base-type mismatch. Wrap those stores in cpu_to_be32() so the values are little->big converted. Reported-by: kernel test robot <lkp@intel.com> Link: https://lore.kernel.org/oe-kbuild-all/202008111749.yy85rFMD%25lkp@intel.com/ Assisted-by: opencode:hy3-free Signed-off-by: Rosen Penev <rosenp@gmail.com> Reviewed-by: Frank Li <Frank.Li@nxp.com> Link: https://patch.msgid.link/20260716202949.677290-2-rosenp@gmail.com Signed-off-by: Vinod Koul <vkoul@kernel.org>
2026-07-17staging: rtl8723bs: Split multiple assignments in _rtw_open_pktfileAmin Madani1-2/+4
In _rtw_open_pktfile(), multiple variables are assigned on the same line. According to the Linux kernel coding style, multiple assignments on a single line should be avoided. Split them into separate lines to improve readability. Signed-off-by: Amin Madani <aminmadani112@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260716083822.2898-1-aminmadani112@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: sm750fb: remove unused set_all_eng_off fieldHungyu Lin3-35/+0
The set_all_eng_off field is only initialized to 0 and is never set by any caller. Remove the unused field together with the dead cleanup path guarded by it. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Link: https://patch.msgid.link/20260716044613.2659-1-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: Fix spacing around ternary operator in sdio_intf.cAmin Madani1-1/+1
Add spaces around '?' and ':' in the return statement in sdio_intf.c according to the Linux kernel coding style. Signed-off-by: Amin Madani <aminmadani112@gmail.com> Link: https://patch.msgid.link/20260715170606.96002-1-aminmadani112@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error pathsCong Nguyen1-5/+17
issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management xmit_frame together with its xmit_buf from the driver's fixed-size management-TX pools via alloc_mgtxmitframe(). On the normal path the frame is handed to dump_mgntframe(), which transfers ownership and eventually returns both objects to their pools (the frame and, for beacons, the buf in rtl8723bs_mgnt_xmit(); other bufs via the pending-xmitbuf/TX-completion path). Several error/edge paths return early after a successful alloc_mgtxmitframe() but before dump_mgntframe(), so ownership is never transferred and neither object is freed: - issue_beacon(): beacon larger than 512 bytes - issue_probersp(): cur_network->ie_length > MAX_IE_SZ - issue_probersp(): kzalloc() of the SSID scratch buffer fails - issue_asocrsp(): pkt_type is neither ASSOCRSP nor REASSOCRSP Because alloc_mgtxmitframe() removes the frame and buf from their free lists (list_del_init) without placing them on any pending list, an orphaned pair is on no list and referenced by nobody, so it is only reclaimed at driver teardown. Repeated hits progressively exhaust the management-TX pools until alloc_mgtxmitframe() returns NULL and the interface can no longer send beacons or probe/assoc responses. Free the frame and buffer on these paths, matching the existing correct error handling in issue_assocreq(). Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver") Signed-off-by: Cong Nguyen <congnt264@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260715111710.295052-1-congnt264@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: rtw_mlme: make rtw_add_network() staticGongwei Li1-2/+1
Function rtw_add_network() used only in rtw_mlme.c file, so it should be declared static. Remove the redundant prototype and add static keyword to the definition. Signed-off-by: Gongwei Li <ligongwei@kylinos.cn> Link: https://patch.msgid.link/20260715085542.1648015-1-13875017792@163.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: greybus: uart: return tty_alloc_driver() errorsAlfie Varghese1-1/+1
gb_tty_init() maps any tty_alloc_driver() failure to -ENOMEM. tty_alloc_driver() currently always returns -ENOMEM on failure, so this does not change behavior in practice. However, returning PTR_ERR(gb_tty_driver) is more correct and consistent with kernel conventions, preserving any future error codes the function might return. Signed-off-by: Alfie Varghese <alfievarghese22@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260714134921.817-1-alfievarghese22@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: convert rtw_xmitframe_coalesce() to return errnoHungyu Lin3-7/+7
Convert rtw_xmitframe_coalesce() to return 0 on success and a negative errno on failure. Propagate errno values returned by the helper functions instead of converting them to _FAIL. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260713070537.15903-6-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: simplify rtw_xmitframe_coalesce() control flowHungyu Lin1-11/+5
Replace goto-based error handling with direct returns and remove the temporary res variable. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260713070537.15903-5-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: convert xmitframe_addmic() to return errnoHungyu Lin1-5/+6
Convert xmitframe_addmic() to return 0 on success and a negative errno on failure. Update the immediate caller to handle errno return values while preserving the existing _SUCCESS/_FAIL semantics. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260713070537.15903-4-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: convert rtw_make_wlanhdr() to return errnoHungyu Lin2-8/+9
Convert rtw_make_wlanhdr() to return 0 on success and a negative errno on failure. Update the immediate caller to handle errno return values while preserving the existing _SUCCESS/_FAIL semantics. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260713070537.15903-3-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove redundant return variable in rtw_make_wlanhdr()Hungyu Lin1-5/+2
The temporary return variable is no longer needed because the only error path returns directly. Remove the redundant variable and exit label, and return _SUCCESS directly on the success path. No functional change intended. Signed-off-by: Hungyu Lin <dennylin0707@gmail.com> Reviewed-by: Dan Carpenter <error27@gmail.com> Link: https://patch.msgid.link/20260713070537.15903-2-dennylin0707@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: Remove unused parameter pnetdevDalvin-Ehinoma Noah Aiguobas1-2/+2
Remove unused parameter pnetdev from the function loadparam. This function is called once and the argument is adjusted as well. Signed-off-by: Dalvin-Ehinoma Noah Aiguobas <fliegbert2@gmail.com> Link: https://patch.msgid.link/20260712215617.35003-1-fliegbert2@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: axis-fifo: Fix kernel-doc return value warningsBabanpreet Singh1-2/+2
The kernel-doc comments for axis_fifo_read() and axis_fifo_write() describe their return values as free text, which kernel-doc does not recognize as a return section: $ scripts/kernel-doc -Wall -none drivers/staging/axis-fifo/axis-fifo.c Warning: drivers/staging/axis-fifo/axis-fifo.c:121 No description found for return value of 'axis_fifo_read' Warning: drivers/staging/axis-fifo/axis-fifo.c:214 No description found for return value of 'axis_fifo_write' These warnings only show up in a direct kernel-doc invocation or a W=2 build (-Wall is added to kernel-doc only when KBUILD_EXTRA_WARN contains 2), which is why W=1 builds appear clean. Convert the trailing "Returns ..." sentences into Return: sections so kernel-doc recognizes the existing return value documentation. No functional change. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com> Link: https://patch.msgid.link/20260712214115.7-1-bbnpreetsingh@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: nvec: nvec_power: use GFP_KERNEL in probe()Igor Putko1-1/+1
nvec_power_probe() calls devm_kzalloc() with GFP_NOWAIT, which disables direct reclaim and is meant for atomic context. probe() runs in normal process context and may sleep, so this needlessly risks a spurious -ENOMEM under memory pressure instead of just waiting for reclaim like every other probe() allocation does. nvec.c's own tegra_nvec_probe() already uses GFP_KERNEL for the identical pattern, confirming this is an oversight, not intentional. Signed-off-by: Igor Putko <igorpetindev@gmail.com> Acked-by: Marc Dietrich <marvin24@gmx.de> Link: https://patch.msgid.link/20260710150113.3041-1-igorpetindev@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: rename Switch_DM_Func to switch_dm_funcAnirban Bose4-10/+10
I changed the Switch_DM_Func() to switch_dm_func() to fix the CamelCase, I changed it in every instance where it was present Signed-off-by: Anirban Bose <boses156@gmail.com> Link: https://patch.msgid.link/20260712142846.3369-1-boses156@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: Fix logical operator alignment in rtw_mlme.cDalvin-Ehinoma Noah Aiguobas1-12/+11
Move logical operators to the end of continuation lines and adjust indentation in rtw_mlme.c to comply with the Linux kernel coding style. Signed-off-by: Dalvin-Ehinoma Noah Aiguobas <fliegbert2@gmail.com> Link: https://patch.msgid.link/20260712061143.2982-1-fliegbert2@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove unused 'bTXPowerDataReadFromEEPORM'Nikolay Kulikov2-4/+0
The 'bTXPowerDataReadFromEEPORM' field of the struct hal_com_data is set but never used; remove it. Signed-off-by: Nikolay Kulikov <nikolayof23@gmail.com> Link: https://patch.msgid.link/20260710165220.68599-6-nikolayof23@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove unused EEPROMBluetoothType from hal_com_dataNikolay Kulikov3-8/+0
The value 'BT_RTL8723B' is written to this field, but it is not used in any other way, so remove it. Signed-off-by: Nikolay Kulikov <nikolayof23@gmail.com> Link: https://patch.msgid.link/20260710165220.68599-5-nikolayof23@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove unused EEPROMVersion from struct hal_com_dataNikolay Kulikov5-17/+0
A value is written to this field, but it is never used. Remove it, along with the associated functions and macros, to simplify the code. Signed-off-by: Nikolay Kulikov <nikolayof23@gmail.com> Link: https://patch.msgid.link/20260710165220.68599-4-nikolayof23@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove unused ForcedDataRate from hal_com_dataNikolay Kulikov2-2/+0
This field is set once and never used, so remove it. Signed-off-by: Nikolay Kulikov <nikolayof23@gmail.com> Link: https://patch.msgid.link/20260710165220.68599-3-nikolayof23@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: remove unused 'EEPROMCustomerID' from hal_com_dataNikolay Kulikov5-17/+0
This field is set during initialization but never used, so remove it. Signed-off-by: Nikolay Kulikov <nikolayof23@gmail.com> Link: https://patch.msgid.link/20260710165220.68599-2-nikolayof23@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: Rename camelcase enum values dot11AuthAlgrthm_WAPI and ↵Dalvin-Ehinoma Noah Aiguobas2-3/+3
dot11AuthAlgrthm_MaxNum Rename enum values dot11AuthAlgrthm_WAPI and dot11AuthAlgrthm_MaxNum to fix checkpatch.pl CamelCase finding. Signed-off-by: Dalvin-Ehinoma Noah Aiguobas <fliegbert2@gmail.com> Link: https://patch.msgid.link/20260710162017.5660-6-fliegbert2@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-17staging: rtl8723bs: Rename camelcase enum value dot11AuthAlgrthm_SharedDalvin-Ehinoma Noah Aiguobas5-10/+10
Rename enum value dot11AuthAlgrthm_Shared to dot11_auth_algrthm_shared to fix checkpatch.pl CamelCase finding. Signed-off-by: Dalvin-Ehinoma Noah Aiguobas <fliegbert2@gmail.com> Link: https://patch.msgid.link/20260710162017.5660-5-fliegbert2@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>