<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/next/linux-next.git/arch/arm64/include/asm, branch master</title>
<subtitle>The linux-next integration testing tree</subtitle>
<id>https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/atom?h=master</id>
<link rel='self' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/'/>
<updated>2026-09-16T13:34:13+00:00</updated>
<entry>
<title>Merge branch 'headers' of git://git.infradead.org/users/willy/pagecache.git</title>
<updated>2026-09-16T13:34:13+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-16T13:34:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=e411494241ee8ac2c46c59215e65ad382216f15c'/>
<id>urn:sha1:e411494241ee8ac2c46c59215e65ad382216f15c</id>
<content type='text'>
# Conflicts:
#	net/ceph/osd_client.c
</content>
</entry>
<entry>
<title>Merge branch 'next' of https://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm.git</title>
<updated>2026-09-16T12:29:48+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-16T12:29:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=1e367bc39b69fe866251109c72252befaeeaf314'/>
<id>urn:sha1:1e367bc39b69fe866251109c72252befaeeaf314</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'master' of https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git</title>
<updated>2026-09-16T12:29:31+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-16T12:29:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=0bf60a5f722b13a545b142ffbf201a2aaa1282ab'/>
<id>urn:sha1:0bf60a5f722b13a545b142ffbf201a2aaa1282ab</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'fixes' of https://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm.git</title>
<updated>2026-09-16T11:36:55+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-16T11:36:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=b8cc8279bfdaf159dceecc5ee9314eb88ba1f0c0'/>
<id>urn:sha1:b8cc8279bfdaf159dceecc5ee9314eb88ba1f0c0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch into tip/master: 'sched/core'</title>
<updated>2026-09-16T06:58:34+00:00</updated>
<author>
<name>Ingo Molnar</name>
<email>mingo@kernel.org</email>
</author>
<published>2026-09-16T06:58:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=3184fc90dcaa7c531f8cdbbb89ea4e470214823f'/>
<id>urn:sha1:3184fc90dcaa7c531f8cdbbb89ea4e470214823f</id>
<content type='text'>
 # New commits in sched/core:
    e81ee0630837 ("sched/fair: Reset NUMA fault locality after scan period update")
    ef9293b3b797 ("sched: dynamic: Fix preemption model strings")
    879eaa76e608 ("sched: Remove unneeded function type cast in do_balance_callbacks()")
    f549101187c8 ("sched/deadline: check start_dl_timer expiry with ktime_before()")
    2a672daa4b27 ("sched/feat: Use the new static key API for sched_feat")
    a5576ebce920 ("sched: Convert paravirt_steal to new static key APIs")
    9650ce11f2e3 ("sched: dynamic: Simplify preempt model accessors")
    5b9a28eeed37 ("sched: dynamic: Remove HAVE_PREEMPT_DYNAMIC_{CALL,KEY}")
    aa4178f63847 ("sched: dynamic: Simplify irqentry_exit_cond_resched()")
    b9d267b9d632 ("sched: dynamic: Simplify preempt_schedule{,_notrace}()")
    88e0b3bb9930 ("sched: dynamic: Simplify {cond,might}_resched()")
    d3d16750693b ("sched: dynamic: Make PREEMPT_DYNAMIC depend on ARCH_HAS_PREEMPT_LAZY")
    772d9ffbfd26 ("sched: Migrate whole chain in proxy_migrate_task()")
    6b73a09e943f ("sched: Break out core of attach_tasks() helper into sched.h")
    1f8805138593 ("sched: Switch rq-&gt;next_class in proxy_reset_donor()")
    09351db90a28 ("sched/core: Don't proxy-exec unmatched cookie lock owners")
    9be817f991e2 ("sched/core: Avoid migrating blocked_on tasks")
    3dd95f077371 ("sched/core: Don't steal a proxy-exec donor")

Signed-off-by: Ingo Molnar &lt;mingo@kernel.org&gt;
</content>
</entry>
<entry>
<title>KVM: arm64: Don't WARN on an unknown VM ioctl in protected mode</title>
<updated>2026-09-15T22:09:57+00:00</updated>
<author>
<name>Fuad Tabba</name>
<email>fuad.tabba@linux.dev</email>
</author>
<published>2026-09-14T09:38:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=49d9d295d69d07e850cae35933ba8519e2915f26'/>
<id>urn:sha1:49d9d295d69d07e850cae35933ba8519e2915f26</id>
<content type='text'>
kvm_pkvm_ioctl_allowed() WARNs when kvm_get_cap_for_kvm_ioctl() doesn't
find the ioctl number in vm_ioctl_caps[], and kvm_arch_vm_ioctl() calls
it for every number the generic code doesn't handle, so
ioctl(vm_fd, 0xdeadbeef) from userspace taints a pKVM host and panics it
under panic_on_warn. The lookup is fed userspace input: return false,
and userspace gets the -EINVAL kvm_arch_vm_ioctl() returns for that
number on a host without pKVM.

Fixes: b12b3b04f6ba0 ("KVM: arm64: Check whether a VM IOCTL is allowed in pKVM")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba &lt;fuad.tabba@linux.dev&gt;
Reviewed-by: Suzuki K Poulose &lt;suzuki.poulose@arm.com&gt;
Link: https://patch.msgid.link/20260914093838.1082637-1-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton &lt;oupton@kernel.org&gt;
</content>
</entry>
<entry>
<title>KVM: arm64: nv: Delay freeing of shadow S2 structures until VM destruction</title>
<updated>2026-09-15T22:09:57+00:00</updated>
<author>
<name>Marc Zyngier</name>
<email>maz@kernel.org</email>
</author>
<published>2026-09-11T16:22:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=e5843f4effaa2ffac3e789ecd4456403564961d4'/>
<id>urn:sha1:e5843f4effaa2ffac3e789ecd4456403564961d4</id>
<content type='text'>
We free the shadow S2 structures from kvm_arch_flush_shadow_all(), which
is a Bad Idea(tm). Freeing the page tables is fair game (this is what
this callback is for), but freeing the container that could still be
referenced by another part of the system is not great.

Instead, grow separate destructors that gets called when we tear the VM
down for good. From there, we can nuke both the individual MMUs as well
as the global array that points to them, safe in the knowledge that the
vcpus themselves have been destroyed already.

Fixes: 4f128f8e1aaac ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
Reviewed-by: Lorenzo Stoakes (ARM) &lt;ljs@kernel.org&gt;
Signed-off-by: Marc Zyngier &lt;maz@kernel.org&gt;
Cc: stable@vger.kernel.org
Reviewed-by: Wei-Lin Chang &lt;weilin.chang@arm.com&gt;
Link: https://patch.msgid.link/20260911162203.1919330-3-maz@kernel.org
Signed-off-by: Oliver Upton &lt;oupton@kernel.org&gt;
</content>
</entry>
<entry>
<title>KVM: arm64: nv: Fix life cycle of the nested_mmus array</title>
<updated>2026-09-15T22:09:57+00:00</updated>
<author>
<name>Marc Zyngier</name>
<email>maz@kernel.org</email>
</author>
<published>2026-09-11T16:22:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=33346f8960c7bb6a3b4e273b5cfe25c5a8be349f'/>
<id>urn:sha1:33346f8960c7bb6a3b4e273b5cfe25c5a8be349f</id>
<content type='text'>
The nested_mmus array holds the shadow page tables that are used when
a guest is running a nested context. These structures are allocated on
VCPU_INIT for whole guest, which implies that they may have to be
relocated as the array grows.

Should a VCPU_INIT occur whilst a vcpu is actively running an L2 and
that the allocation requires relocation, that vcpu will still be
running with a pointer to the previous structure, which will have been
freed.

Fix this by turning the array of structures to an array of pointers,
which is now allocated at VM creation, sized to the absolute maximum
that KVM can handle.

In turn, each VCPU_INIT contributes S2_MMU_PER_VCPU to the pool. No
reallocation is ever performed, and the life cycle of each object is
much clearer:

- the nested_mmus array is allocated in kvm_init_nested(), and freed
  in kvm_arch_destroy_vm()

- s2_mmu structures are allocated in kvm_vcpu_init_nested(), and freed
  on kvm_arch_flush_shadow_all()

Finally, the freeing of vcpu-&gt;arch.vncr_array is made consistent
rather than being done on some failure paths, but not others.

Fixes: 4f128f8e1aaa ("KVM: arm64: nv: Support multiple nested Stage-2 mmu structures")
Reported-by: Shen Yongchao &lt;grayhat@foxmail.com&gt;
Reported-by: Karl Mehltretter &lt;kmehltretter@gmail.com&gt;
Suggested-by: Karl Mehltretter &lt;kmehltretter@gmail.com&gt;
Acked-by: Lorenzo Stoakes (ARM) &lt;ljs@kernel.org&gt;
Link: https://lore.kernel.org/r/20260803224405.41468-1-kmehltretter@gmail.com
Signed-off-by: Marc Zyngier &lt;maz@kernel.org&gt;
Cc: stable@vger.kernel.org
Reviewed-by: Wei-Lin Chang &lt;weilin.chang@arm.com&gt;
Link: https://patch.msgid.link/20260911162203.1919330-2-maz@kernel.org
Signed-off-by: Oliver Upton &lt;oupton@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge branch kvm-arm64/hyp-type-checking-7.4 into kvmarm-master/next</title>
<updated>2026-09-14T10:52:09+00:00</updated>
<author>
<name>Marc Zyngier</name>
<email>maz@kernel.org</email>
</author>
<published>2026-09-14T10:52:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=892fc33977cf8b2cf98065e5ae532e4ddbbe09cc'/>
<id>urn:sha1:892fc33977cf8b2cf98065e5ae532e4ddbbe09cc</id>
<content type='text'>
* kvm-arm64/hyp-type-checking-7.4:
  : \
  : Restore some sanity in the EL2 department by enforcing the type
  : checking that was lost when converting the KVM internal
  : interface to SMCCC. Patches courtesy of Fuad Tabba.
  :
  : From the cover letter:
  :
  : "This series implements that, in plain preprocessor macros rather than
  : an external generator, in the mold of the syscall wrappers. Each
  : hypercall's signature is declared once, in kvm_hcall.h:
  : kvm_call_hyp_nvhe() resolves to a typed nvhe_hvc_##f() stub generated
  : from the declaration, and the hyp-main.c handlers unmarshal their
  : arguments through glue that is type-checked against the same
  : declaration. A mistyped or stale call, or a handler that drifts from
  : its caller, now fails to compile. On top of that shared declaration,
  : host-VA parameters gain a __kern sparse address space, so
  : dereferencing one at EL2 without kern_hyp_va_host() translation is
  : flagged by sparse. The address space is KVM-private and lives with the
  : interface it annotates rather than in compiler_types.h, like x86's
  : __seg_gs in asm/percpu.h. The deeper instances of that bug class, host
  : VAs reached through struct fields after the boundary, are follow-up
  : work."
  : /
  KVM: arm64: Tag host-VA hypercall parameters __kern
  KVM: arm64: nVHE: Check hypercall handlers against the declared ABI
  KVM: arm64: Type-check hypercall arguments at the caller
  KVM: arm64: Move the host hypercall interface to its own header
  KVM: arm64: nVHE: Pass host VA arguments as pointers
  arm64: pi: Run the source checker on the libfdt objects under C=2
  KVM: arm64: nVHE: Run the source checker under C=2
  KVM: arm64: nVHE: Use NULL to reset the trace buffer backing pointer
  KVM: arm64: nVHE: Declare the hyp event IDs before defining them
  KVM: arm64: nVHE: Share the stacktrace per-CPU declarations with EL2
  tracing: Include linux/types.h in trace_remote_event.h

Signed-off-by: Marc Zyngier &lt;maz@kernel.org&gt;
</content>
</entry>
<entry>
<title>KVM: arm64: Tag host-VA hypercall parameters __kern</title>
<updated>2026-09-14T10:26:51+00:00</updated>
<author>
<name>Fuad Tabba</name>
<email>fuad.tabba@linux.dev</email>
</author>
<published>2026-09-01T14:03:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=8bd0e6812a1be71d50620f00445940ded0df897c'/>
<id>urn:sha1:8bd0e6812a1be71d50620f00445940ded0df897c</id>
<content type='text'>
The nVHE hypervisor takes host virtual addresses as hypercall arguments
and translates each with kern_hyp_va() before use. Nothing marks them as
host-owned, so dereferencing one untranslated at EL2 - a recurring bug
class - is invisible to the compiler.

Add a __kern sparse address space, active only for EL2 code, and tag the
host-VA parameters in the hypercall declarations. kern_hyp_va_host() is
the only sanctioned unwrap: it translates the address, preserves the
pointee type (stripped of qualifiers, as with the percpu accessors) and
drops the tag with a __force cast, so an untranslated host VA fails
sparse. The tag flows from the shared declaration into the generated
handler and on into the donated-memory and tracing-descriptor helpers,
so a handler cannot extract a host VA without it. Host code sees plain
pointers, and the tag is checker-only: no code is generated.

container_of() casts through void * and drops the address space, so
__get_host_hyp_vcpus() now takes an already translated vCPU and its
callers unwrap. Translating a vgic_v3_cpu_if before taking its container
is equivalent, since va_mask spans every bit in which two linear-map
addresses differ.

Reviewed-by: Marc Zyngier &lt;maz@kernel.org&gt;
Signed-off-by: Fuad Tabba &lt;fuad.tabba@linux.dev&gt;
Link: https://patch.msgid.link/20260901140326.3812068-12-fuad.tabba@linux.dev
Signed-off-by: Marc Zyngier &lt;maz@kernel.org&gt;
</content>
</entry>
</feed>
