четверг

[Bug 2167571] Re: [SRU] Fix excessive internal microphone gain causing noisy recordings on Yoga Pro 7

** Description changed: [ Impact ] The internal microphone on affected Yoga Pro 7 systems records with excessive background noise when mic volume is set to 100%. The gain is stuck at the maximum level (Amp-In 0x03 / 29.25 dB), which makes hiss/static clearly audible and impacts normal audio recording use. + + kernel: 7.0.0 + ubuntu: 24.04 or 26.04 + [ Test Plan ] 1. Boot an affected Yoga Pro 7 system with the SRU kernel. 2. Set internal mic volume to 100%. 3. Record audio with the internal microphone. 4. Verify the recording no longer has excessive hiss/static and the gain no longer stays pinned at Amp-In 0x03. [ Where problems could occur ] This change affects the codec gain path, so a regression could make the internal microphone too quiet or alter input levels on related audio paths. [ Other Info ] The upstream fix is already merged in Linux kernel commit 6cd3d2c82651a9e77aa5b1b9c12aa918c0d6c0a9. https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=6cd3d2c82651a9e77aa5b1b9c12aa918c0d6c0a9 -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167571 Title: [SRU] Fix excessive internal microphone gain causing noisy recordings on Yoga Pro 7 Status in linux package in Ubuntu: New Bug description: [ Impact ] The internal microphone on affected Yoga Pro 7 systems records with excessive background noise when mic volume is set to 100%. The gain is stuck at the maximum level (Amp-In 0x03 / 29.25 dB), which makes hiss/static clearly audible and impacts normal audio recording use. kernel: 7.0.0 ubuntu: 24.04 or 26.04 [ Test Plan ] 1. Boot an affected Yoga Pro 7 system with the SRU kernel. 2. Set internal mic volume to 100%. 3. Record audio with the internal microphone. 4. Verify the recording no longer has excessive hiss/static and the gain no longer stays pinned at Amp-In 0x03. [ Where problems could occur ] This change affects the codec gain path, so a regression could make the internal microphone too quiet or alter input levels on related audio paths. [ Other Info ] The upstream fix is already merged in Linux kernel commit 6cd3d2c82651a9e77aa5b1b9c12aa918c0d6c0a9. https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=6cd3d2c82651a9e77aa5b1b9c12aa918c0d6c0a9 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167571/+subscriptions

[Bug 2167344] Re: FCoE not supported with HPE Synergy 4820C and 6820C CNA cards

What kernel version are using? Is this on resolute? -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167344 Title: FCoE not supported with HPE Synergy 4820C and 6820C CNA cards Status in linux package in Ubuntu: New Bug description: According to https://support.hpe.com/hpesc/public/docDisplay?docId=a00129603en_us, FCoE is not supported on Ubuntu 20.04 and up. It may be linked to an in-tree driver limitation, but we currently lack visibility into the technical details. This bug report will allow tracking from HPE. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167344/+subscriptions

[Bug 2167344] Re: FCoE not supported with HPE Synergy 4820C and 6820C CNA cards

I will need some logs, can we start with dmesg? -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167344 Title: FCoE not supported with HPE Synergy 4820C and 6820C CNA cards Status in linux package in Ubuntu: New Bug description: According to https://support.hpe.com/hpesc/public/docDisplay?docId=a00129603en_us, FCoE is not supported on Ubuntu 20.04 and up. It may be linked to an in-tree driver limitation, but we currently lack visibility into the technical details. This bug report will allow tracking from HPE. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167344/+subscriptions

[Bug 2167609] Re: Resolute update: upstream stable patchset 2026-09-17

** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167609 Title: Resolute update: upstream stable patchset 2026-09-17 Status in linux package in Ubuntu: Invalid Status in linux source package in Resolute: In Progress Bug description: SRU Justification Impact: The upstream process for stable tree updates is quite similar in scope to the Ubuntu SRU process, e.g., each patch has to demonstrably fix a bug, and each patch is vetted by upstream by originating either directly from a mainline/stable Linux tree or a minimally backported form of that patch. The following upstream stable patches should be included in the Ubuntu kernel: upstream stable patchset 2026-09-17 Ported from the following upstream stable releases: v6.18.49, v6.18.50, v7.2.2, v7.2.3, v7.2.4 from git://git.kernel.org/ fuse: fix race between interrupt and resend fuse: fix missing barrier when checking io-uring readiness fuse: publish io-uring queues with release semantics fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free vlan: fix skb_under_panic and races when toggling HW VLAN offload crypto: sun8i-ce - Remove crypto_rng interface UBUNTU: [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_CE_PRNG crypto: sun8i-ss - Remove crypto_rng interface UBUNTU: [Config] Remove CONFIG_CRYPTO_DEV_SUN8I_SS_PRNG ASoC: tegra210_i2s: sort the register default table ASoC: tegra210_i2s: sort the Tegra264 register default table ASoC: tegra210_mixer: sort the register default table ASoC: tegra: Fix the I2S enable default value ASoC: tegra: Fix the MIXER enable default value ASoC: tegra: Sort ADMAIF register defaults ASoC: tegra: Sort MBDRC register defaults ring-buffer: Fix subbuf resize race with ring buffer readers drm/amd/display: hide Apple Studio Display secondary tile drm/amd/display: Prune per-tile Timing from Apple Studio Display Primary Tile alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally rust: time: fix as_micros_ceil() rounding near i64::MAX alpha: don't leak hardware-fabricated FP exception bits to user space clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path clocksource/drivers/timer-sun4i: Advertise a real minimum delta fs: fix user path of nested backing files ovl: fix double end_creating() on the casefold-mismatch path pidfd: hold exec_update_lock around namespace ioctl powerpc/pseries/iommu: switch to Default DMA window during kdump rust: fmt: fix {:p} printing stack addresses timers/itimer: Zero-init old itimerval before copy to userspace objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0 rust: bug: skip arch-specific asm in `testlib` builds rust: bug: fix warn_on macro build error on UML rust: bug: prevent dead_code warning from warn_on!'s flags constant rust: rust_is_available: warn for `bindgen` < 0.72.1 && libclang >= 22 rust: kernel: list: fix incorrect pop_back example comment objtool/rust: add one more `noreturn` Rust function rust: num: restrict bool conversion to unsigned Bounded rust: cfi: disable function merging if CFI is enabled KEYS: trusted: Fix TPM teardown ordering apparmor: fix cred UAF caused by begin_current_label_crit_section() apparmor: fix out-of-bounds write when null terminating a label vec include/linux/list.h: mark list_add and __list_add as __always_inline mm, swap: ratelimit bad swap entry reports mm/gup: fix always draining LRU caches in collect_longterm_unpinnable_folios() mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd mm/huge_memory: use folio's memcg inside __folio_split() mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier mm/hugetlb_vmemmap: fix __hugetlb_vmemmap_optimize_folios() mm/kmemleak: avoid soft lockup when scanning task stacks mm/madvise: skip device-private PMDs in cold and pageout walks mm/mempolicy: skip non-present PMDs when queueing folios mm/mglru: use the common routine for dirty/writeback reactivation mm/mglru: fix and remove redundant unevictable folio handling mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() mm/migrate: use huge_ptep_get() in remove_migration_pte() mm/migrate_device: clear stale mapping after freeing swapcache mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg() mm/page_vma_mapped: use huge_ptep_get() for hugetlb mm/pagewalk: fix stale walk->action escaping walk_pmd_range() mm/rmap: use huge_ptep_get() in try_to_unmap_one() mm/rmap: use huge_ptep_get() in try_to_migrate_one() mm/slub: fix missing debugfs entries for caches created before sysfs init mm/slub: prevent pfmemalloc objects from entering the barn mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() mm/zswap: fix global shrinker when memory cgroup is disabled mm: compaction: support non-movable compaction for pageblock requests mm: memcg-v1: fix wrong linux-mm list address in deprecation warnings mm: memcg-v1: fix memsw and TCP failcnt accounting mm: memcg: stop reclaim when a limit update is superseded mm: memcontrol: update state_local when flushing NMI stats mm: mempolicy: fix automatic numa balancing for shmem mm: page_alloc: __GFP_FS lockdep annotation for direct compaction mm: page_alloc: move capture_control to the page allocator mm: page_alloc: fix non-movable reclaim storm in defrag_mode mm: vmscan: fix node reclaim ignoring swappiness parameter tools/compiler: match glibc 2.42 definition of __attribute_const__ x86/locking: Use sfence for wmb() if SSE is available x86/insn-eval: Move assign_register() out of KVM as insn_assign_reg() x86/tdx: Fix off-by-one in port I/O handling x86/tdx: Fix zero-extension for 32-bit port I/O x86/xen: fix init of balloon stats again hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() tracing/user_events: Clear copied tracing state before fork duplication tracing: Fix crash passing ERR_PTR to kthread_stop() tracing: Fix logged instance name on creation failure tracing: Fix use-after-free in trace_pipe read on sub-buffer order change tracing: Fix use-after-free with same-name named triggers cdx: Fix double free when sysfs file creation fails debugfs: Fix lockdown check for mmap_prepare device property: fix infinite loop in fwnode_for_each_child_node() misc: nsm: bound the device-reported response length powerpc/powermac: fix OF node refcount rapidio: mport_cdev: fix use-after-free in dma_req_free() Revert "media: v4l2-dev: fix error handling in __video_register_device()" serial: imx: serialize imx_uart_ports[] lifetime staging: greybus: hid: fix SET_REPORT return value usb: dwc2: gadget: Exit partial power down state when changing USB pull-up usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed USB: phy: fsl-usb: fix missing static keywords usb: typec: hd3ss3220: fix VBUS regulator error message usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() usb: typec: thunderbolt: Disable work before freeing tbt on remove usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion usb: gadget: u_audio: Fix use-after-free on sound card disconnect usb: gadget: snps_udc_plat: clean up PHY on probe deferral usb: gadget: midi2: remove default configfs groups on teardown usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() usb: gadget: f_fs: Prevent deadlock during ep0 read loop cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature i3c: renesas: Fix out-of-bounds access for newdevs mask KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() media: cec: stm32: prevent out-of-bounds write on RX overflow media: vicodec: fix out-of-bounds write in FWHT encoder nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation of: fix out-of-bounds read in of_alias_scan() stem parser PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() phy: rockchip-samsung-dcphy: fix out-of-range max_register ubifs: fix out-of-bounds read in signature length check zram: fix out-of-bounds access in read_block_state() zram: fix out-of-bounds access in writeback_store() zram: set default primary compressor in zram_destroy_comps() zram: validate deflate params zsmalloc: account for handle size in class lookup NFS/localio: fix ref leak on nfs_uuid_add_file failure NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails NFSD: check truncate permission under inode lock NFSD: Encode only the status in NFS-ACL v2 GETACL error replies NFSD: Fix off-by-one in DRC bucket pruning limit NFSD: fix up error returned by write_threads() NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check nfsd: guard nfsd_serv deref in nfsd_file_net_dispose NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path pNFS: Fix EBUSY check in pnfs_layout_need_return lockd, nfsd: RCU-protect nlmsvc_ops dispatch nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown nfsd: release path refs on follow_down() error nfsd: Reset write verifier when async COPY writeback fails nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types nfsd: sample writeback error cursor before async COPY loop nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd: size fh_verify server sockaddr slot by xpt_locallen nfsd: validate nseconds in TIME_DELEG decode paths nfsd: validate sockaddr length per family in listener_set nfsd: validate symlink target length in NFSv4 CREATE nfsd: move struct nfsd_genl_rqstp to nfsctl.c nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() nfsd: add filehandle match check to nfsd4_delegreturn() nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref nfsd: cap decoded POSIX ACL count to bound sort cost nfsd: check client ownership when cancelling a copy-notify stateid nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd: clear CALLBACK_RUNNING on failed delegation recall queue nfsd: clear opcnt on compound arg release to prevent OOB read nfsd: convert nfsd_net boolean flags to unsigned long flags word nfsd: dedup nfs4_client_to_reclaim inserts nfsd: defer setting NFSD4_CALLBACK_RUNNING in deleg_reaper nfsd: defer vfree of compound ops to fix rpc_status UAF nfsd: don't free session slots that are still in use nfsd: drop the stateid, not the stateowner, on seqid_op replay retry nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd: fix clock domain mismatch in clients_still_reclaiming() nfsd: fix cpntf publish race in nfs4_init_cp_state nfsd: fix dentry ref leak on V4ROOT export filehandle lookup nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net nfsd: fix FL_SLEEP being set unconditionally for all LOCK types nfsd: fix netlink dumpit error handling for rpc_status_get nfsd: fix nfsd_file leak on inter-server COPY setup failure nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs nfsd: fix partial-write detection in nfsd_direct_write nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() nfsd: fix refcount leak in nfsd_file_lru_add on insertion failure nfsd: fix reply size estimate for GET_DIR_DELEGATION nfsd: fix stale s2s_cp_stateids IDR entry for async COPY nfsd: fix UAF in async copy cancel and shutdown nfsd: fix version mismatch loops in nfsd_acl_init_request() nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo nfsd: gate nfs2 setacl by argp->mask nfsd: gate nfs3 setacl by argp->mask nfsd: hold rcu across localio cmpxchg retry nfsd: initialize copy-notify stateid before publishing it nfsd: initialize DRC hash table before registering shrinker nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE nfsd: reject reclaim LOCK after RECLAIM_COMPLETE nfsd: release OPEN-decoded posix ACLs via op_release nfsd: revoke copy-notify stateids before dropping their reference NFSD: Prevent lock owner use-after-free during client teardown NFSD: Prevent post-shutdown use-after-free in unlock_filesystem NFSD: Prevent client use-after-free during admin state revocation nfsd: convert global state_lock to per-net deleg_lock NFSD: Prevent client use-after-free during delegation revoke NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup nfsd: use test_and_clear_bit for somebody_reclaimed to prevent lost update libceph: validate OSD extent maps before cursor advance libceph: reject buckets with mismatched CRUSH ids ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock ceph: fix UAF in check_new_map() on session freed during unlock ceph: force a cap message when a deferred revoke can't be acked immediately ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode ceph: bound copied dentry name length in NFS export get_name ceph: bound MDSCapAuth path and fs_name decode in handle_session() ceph: bound num_export_targets array for mds info v2/v3 ceph: bound xattr value length in __build_xattrs() ceph: cap delegated inode count in ceph_parse_deleg_inos() ceph: do not repeat ceph_trim_dentries() if no progress possible ceph: fix leaked inode reference on writeback abort at umount btrfs: drop recovered reloc root refs on recovery failure btrfs: fix extent map leak in NOCOW direct I/O write btrfs: do not overwrite NODATASUM flag when removing NODATACOW flag audit: avoid dropping live tree ref on fsnotify rule autoremove smb: move some definitions from common/smb2pdu.h into common/fscc.h smb/client: reduce fallocate zero buffer allocation smb/client: emulate small EOF-extending mode 0 fallocate ranges cifs: add cifs_resize_file_locked() to guard fscache_resize_cookie() under i_rwsem smb/client: do not account EOF extension as allocation cifs: call pagecache_isize_extended() in cifs_setsize() when extending cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 smb: client: clear ce->tgthint in free_tgts() smb: client: fix ALIGN() overflow in symlink_data() error context loop smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr() smb: client: harden DFS cache against invalid target hints smb: client: reject a tree connect response whose byte count is too small smb: client: restore the data_offset bound in is_valid_oplock_break() HID: apple: preserve keyboard backlight across T2 resume HID: corsair-void: Check size of status and firmware events before reading them HID: picolcd: clamp eeprom debugfs read to bytes actually received HID: roccat: free buffered reports when destroying device HID: sensor: custom: Fix field sysfs group cleanup on failure HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind HID: universal-pidff: stop the device when force-feedback init fails HID: mcp2221: stop device IO before hid_hw_stop HID: mcp2221: fix OOB write in mcp2221_raw_event() HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes HID: mcp2221: validate report size in mcp2221_raw_event() HID: intel-thc-hid: intel-quickspi: validate report size before copy HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer HID: intel-thc-hid: intel-quicki2c: fix autosuspend cleanup during teardown HID: intel-thc-hid: intel-quickspi: fix autosuspend cleanup during teardown eventfs: Initialize ei->children and ei->list in init_ei() fs/ntfs3: validate dirty page table on log replay fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() fs/ntfs3: bound page_lcns[] index by the log record eCryptfs: bound the packet-length peek to the user buffer ecryptfs: fix tag 11 packet exact-fit size check ecryptfs: hold msg ctx list lock when cleaning daemon queue ecryptfs: pass packet set buffer size to parser ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet ecryptfs: reject too-small tag 70 packets ecryptfs: release message context on send failure ecryptfs: show filename encryption options efivarfs: Rate limit statfs() handler entry: Fix seccomp bypass after ptrace with TSYNC erofs: skip sufficiently large global buffers when resizing ext2: Fix lost inode updates for IS_SYNC inodes fanotify: fix use-after-free of file range info fat: restore original value when fat_ent_write failed fbdev: omapfb: panel-dsi-cm: initialize lock before registering display fbdev: pvr2fb: correct user pointer annotation and sentinel initializer fbdev: ssd1307fb: defer I2C transfers from damage callbacks fbdev: uvesafb: unregister connector callback on init failure forcedeth: fix off-by-one when saving/restoring non-PCI config space fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration fsnotify: Fix stale object mask after concurrent mark updates hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device hugetlb: only adjust reservation during unmapping if mapcount is 0 accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() accel/rocket: initialize job domain before cleanup paths accel/rocket: Fix error path handling in rocket_job_run() acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks ACPI: APEI: Fix ERST timeout unit conversion ACPI: APEI: GHES: fix ARM section length accounting after header ACPI: pfr_update: fix stack buffer overflow in query_capability() ACPI: scan: Avoid registering platform devices with resource overlaps alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write() alpha: marvel: Fix irq_set_status_flags to use correct IRQ number alpha: marvel: Fix lock ordering in init_io7_irqs() ARM: 9477/1: Disable broken eBPF JIT on the Risc PC ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes auxdisplay: charlcd: cancel backlight work on registration failure backlight: aw99706: Fix DT property names to match binding backlight: aw99706: Honor the core blank state in update_status() block: validate user space vectors during extraction block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead() Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU Bluetooth: btusb: Add ASUS USB-BT600 for Realtek 8761CU Bluetooth: btusb: limit RTL8761B BROKEN_EXT_SCAN quirk to 0bda:a728 Bluetooth: eir: Fix OOB read in eir_get_service_data() bnx2x: fix double free in bnx2x_init_firmware() error path bnxt_en: Write doorbell when linearizing skb fails bpf, x86: Fix per-CPU address resolution into an extended register bpf: Disable preemption in __bpf_get_stack buffer: avoid tail commit walk for uptodate folios bpf: Harden bloom filter sizing and indexing on 32-bit kernels dm-io: clone the source bio instead of copying its biovec dm-io: report non-retryable errors separatedly dm-era: fix shadowed superblock leak on take-snap failure dm raid1: reserve space for NUL-terminator in build_constructor_string() dm array: validate array block headers on read dm array: reject an array block whose value size is not the caller's coresight: etm3x: Fix cntr_val_show() to match cntr_val_store() behavior cpufreq: apple-soc: Fix OPP table cleanup cpufreq: schedutil: Fix rate limit overflow cxl/features: bound fwctl command payload to the input buffer dax/cxl, hmem: Initialize hmem early and defer dax_cxl binding cxl/region: Add helper to check Soft Reserved containment by CXL regions cxl/mce: Make the MCE notifier per-region cxl/pmem: Format the nvdimm serial number as unsigned decimal cxl/ras: Fix cxl_rch_get_aer_severity() wrong severity register Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative Bluetooth: hci_uart: Fix false success return in hci_uart_setup() Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready Bluetooth: RFCOMM: serialize security confirmation handling Bluetooth: hci_conn: re-enable advertising only for peripheral role Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request kasan: fix cache shrink race with CPU hotplug jbd2: bound shrinker scans by examined checkpoint buffers jbd2: check need_resched() when skipping busy checkpoint buffers ipip: fix skb leak in collect_md mode when metadata_dst allocation fails ip: orphan prefetched skbs before multicast forwarding ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() ip6_gre: fix hardware header length for NBMA tunnels ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6: use RCU iterator to dump route exceptions landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation libnvdimm/labels: Prevent integer overflow in __nd_label_validate() mailbox: qcom-ipcc: fix duplicate channel allocation across holes md/raid10: fix still_degraded being inverted in raid10_sync_request() md: do overflow check for sb->bblog_shift in super_1_load() module: validate string table section types mpls: reload header after pskb_may_pull() mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction module/kallsyms: fix nextval for data symbol lookup nouveau/gem: reserve the bo in the info ioctl around the vma lookup params: fix charp corruption on allocation failure phy: fsl-imx8mq-usb: fix typec switch leak on probe error path SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry SUNRPC: svcauth_gss: enforce krb5 token minimum length sunrpc: route to a populated pool in svc_pool_for_cpu() SUNRPC: Restore NUMA_NO_NODE for svc thread allocations in global mode SUNRPC: always drain cache_cleaner before destroying a cache_detail SUNRPC: Check svc pool percpu counter allocation SUNRPC: close backchannel before destroying callback service sunrpc: defer rq_argp and rq_resp free until after RCU grace period SUNRPC: fix gssx_dec_option_array error path bugs sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat SUNRPC: harden gss_krb5_unwrap_v2 against short tokens SUNRPC: harden gss_unwrap_resp_priv length checks sunrpc: init gssp_lock before publishing proc entry SUNRPC: reject duplicate CREDS_VALUE options SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 SUNRPC: wait for in-flight client TLS handshake callback svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails svcrdma: Fix offset arithmetic in read_chunk_range svcrdma: Fix pcl_for_each_segment for empty chunks svcrdma: Fix unmatched rn_unregister on failed accept svcrdma: Reject connection when transport allocation fails svcrdma: Reject inline replies that overflow the pull-up buffer svcrdma: Reject oversized Read segments at decode time svcrdma: Reject Read lists that exceed the page budget svcrdma: Reject Write/Reply chunks with segcount 0 svcrdma: Use svc_xprt_put to free listener on create failure svcrdma: Validate Read chunk positions before reconstruction udf: reject VAT indexes equal to the entry count wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets wifi: mt76: mt7925: cancel pending mlo_pm_work staging: media: tegra-video: fix of_node_put() on VIP parse errors staging: media: tegra-video: vi: fix probe failure on skipped last port media: staging/ipu7: fix async notifier UAF on probe error path sched/core: Handle pick_task() releasing the rq lock sched_ext: Fix exit_task leak on fork failure during enable sched_ext: Fix inverted ops.core_sched_before() invocation sched_ext: Keep kick_sync waiting on the rq's own CPU scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock rpmsg: glink: smem: order FIFO read after availability check Revert "arm64: dts: rockchip: Further describe the WiFi for the Pinephone Pro" arm64: dts: qcom: kodiak: avoid EFI overlap for ADSP remote heap arm64: dts: qcom: sm6115-pro1x: Correct touchscreen GPIO flags arm64: dts: qcom: x1-dell-thena: mark l12b and l15b always-on arm64: dts: rockchip: fix eMMC reset polarity on PP-1516 arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck arm64: dts: rockchip: fix emmc reset polarity on px30-cobra arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio arm64: dts: rockchip: Fix rk3588s-roc-pc audio description riscv: dts: spacemit: k1-bananapi-f3: fix maximum CPU core voltage riscv: dts: spacemit: k1-milkv-jupiter: fix maximum CPU core voltage RISC-V: KVM: Fix PMU event info array size overflow riscv: acpi: Handle LPI architectural context loss flags riscv: unaligned: stop using kthread for check_vector_unaligned_access() remoteproc: scp: Fix device reference leak on failed lookup ptp: vmclock: prevent read-only mappings from becoming writable qede: Fix NULL pointer dereference in TPA fragment processing RDMA/cxgb4: Cancel reg_work before freeing device on remove RDMA/ionic: Cap eq_count to the eth driver's interrupt vector budget RDMA/ionic: Embed counter driver data in rdma_counter allocation RDMA/ucma: Lock the handler in ucma_set_ib_path() RDMA/ucma: Lock the handler in ucma_write_cm_event() RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata regulator: qcom-refgen: correct the regulator type to CURRENT ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() ring-buffer: Free cpu_buffer::free_page with subbuf_order ring-buffer: Hold cpu_buffer::lock when resizing a subbuf ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page PM: sleep: Unblock runtime PM when device prepare fails orangefs: fix double-free of trailer_buf on readdir copy failure orangefs: skip leading spaces before parsing client debug masks ocfs2: always run deallocs on copy-on-write completion ocfs2: bound namelen in dlm_migrate_request_handler ocfs2: validate lengths in dlm_mig_lockres_handler ocfs2: validate rl_used against rl_count in refcount block validator ocfs2: validate dx_root extent list fields during block read ocfs2: validate directory-index entry counts when reading metadata ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item ocfs2: cluster: fix o2hb_dependent_users leak on pin failure ocfs2: fix cached cluster count after suballocator reclaim ocfs2: fix readdir position truncation on 32-bit kernels openrisc: fix arbitrary kernel memory access via or1k_atomic syscall openvswitch: Fix CT limit teardown use-after-free openvswitch: only skb_tx_error() a packet we are about to drop ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion arm64: compat: Fix decrementing LDM/STM alignment emulation arm64: proton-pack: Restore the nospectre_bhb command-line option ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC ASoC: codecs: aw88261: reduce log spam ASoC: codecs: aw88261: only check PLL and clock state at power-up hwmon: (max6621) fix negative temperature offset and crit readings hwmon: (max6621) fix temperature clamp range i2c: mxs: fix DMA channel leak on probe error ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() lockd: pin next file across nlm_inspect_file lock-drop lockd: fix NULL dereference on lockowner allocation failure lockd: fix swapped arguments in nlmsvc_match_ip() nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path nvme: zero the discard fallback page nvme-pci: disable controller on admin queue IRQ setup failure nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone nvme-tcp: fix host memory disclosure on R2T for a read command nvme-tcp: reject a read that transferred too few bytes sctp: stop processing a packet once its association is deleted sctp: drop a chunk if its transport was removed sctp: fix NULL deref on untransmitted RECONF completion sctp: distinguish sequence zero from wildcard in reconf lookup sctp: fix stream->outcnt underflow on duplicate RECONF responses power: supply: bq24257: fix use-after-free on remove power: supply: bq256xx: drain usb_work before freeing the charger power: supply: bq25890: Fix power_supply reference leak power: supply: charger-manager: register regulators before exposing sysfs power: supply: cros_usbpd-charger: bound the EC-reported port count power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS power: supply: lp8727: fix use-after-free in lp8727_release_irq() power: supply: lp8788-charger: fix use-after-free on remove power: supply: pf1550: enable charging when battery profile exists power: supply: qcom_battmgr: fix use-after-free power: supply: qcom_battmgr: terminate the strings from firmware power: supply: rt9455: quiesce delayed work before teardown power: supply: twl4030_charger: cancel workers via devm power: supply: ucs1002: fix use-after-free on remove power: supply: max17040: propagate register read errors power: supply: max17040: drop incorrect I2C functionality check power: supply: max17040: synchronize work cancellation on suspend s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks s390/dasd: Do not complete a failed ESE read as successful s390/dasd: Guard sysfs discipline callbacks against unallocated private data s390/dasd: Propagate partial completion length across ERP recovery PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk PCI: meson: Fix GPIO state while requesting PERST# PCI: starfive: Fix resource leaks on error paths in host_init() PCI: plda: Fix use-after-free of event IRQs during teardown PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] PCI/sysfs: Fix read byte order in pci_read_legacy_io() PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses PCI/AER: Emit TLP Log only for unmasked errors PCI/AER: Fix mapping of errors to agent & layer PCI/ASPM: Avoid L0s for Realtek RTS525A PCI/MSI: Enable memory decoding before restoring MSI-X messages PCI/proc: Avoid spurious runtime PM wakeup on config space accesses PCI/proc: Use file_ns_capable() when checking config space read access PCI/proc: Warn on writes to kernel-exclusive config space regions iommu/amd: Put PCI device after handling PPR faults iommu/msm: Unwind probe state on registration failure iommu/sva: Set handle->dev before the SVA handle is visible iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field iommu/arm-smmu-v3: Add HAFT support for SVA iommu/arm-smmu-v3: Manage teardown with devm iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add iommu/vt-d: Fix no_iommu to disable platform opt-in iommu/vt-d: Force requesting ACS when tboot is enabled iommupt: Return zero for invalid iova_to_phys() ranges iommufd: Avoid locking internal accesses during unmap iommufd: Release current IOAS on xa_store() failure iommufd: Fix UAF in selftest IOPF reporting platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer platform/x86: ISST: Validate level in perf mask ioctls platform/x86: ISST: Validate socket ID in clos_assoc ioctl mmc: via-sdmmc: cancel card-detect work on remove mmc: via-sdmmc: stop card-detect handling on probe failure platform/x86: ISST: Add a NULL check for sst_inst[] platform/x86: ISST: Just allow 2 bits for SST feature enable platform/x86: ISST: Use PP level enable mask platform/x86: ISST: Validate logical CPU id and clos id platform/x86: ISST: Validate max level for set feature platform/x86: ISST: Validate parameter for core power state platform/x86: ISST: Validate parameter for frequency and priority platform/x86: ISST: Return error during profile addition platform/x86: int1092: Fix potential memory leak in sar_probe() platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path platform/x86: lenovo/ymc: Only match lower byte in WMI lid switch query response platform/x86: think-lmi: Fix certificate thumbprint sysfs output platform/x86: think-lmi: Free system certificate signatures platform/x86: think-lmi: Fix current password length check platform/chrome: sensorhub: Bound the EC-reported sensor number platform/x86/amd/pmc: Restore msg_port on amd_stb_s2d_init() error paths platform/x86/amd/pmc: Propagate SMU errors and validate S2D address platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2() platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS platform/x86: hp-bioscfg: advance elem past consumed array elements platform/x86: hp-bioscfg: bound ordered-list parsing by the package count platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() platform/x86: hp-bioscfg: fix heap OOB read on empty password write platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed platform/x86: hp-bioscfg: pass validated element count to package parsers platform/x86: hp-bioscfg: warn on element type mismatch instead of failing io_uring/waitid: honor task_work cancellation io_uring/waitid: avoid siginfo copy during ring teardown io_uring/query: cap user size passed to copy_struct_to_user interconnect: Fix use after free in icc_get() and of_icc_get_by_index() ipmi: ipmb: validate write message length ipmi: Remove all sysfs files on registration failure ipmi: si: Fix NULL pointer dereference after failed registration ipmi:msghandler: Cancel work cleanly on an error net/iucv: filter frames in afiucv_hs_rcv() by ingress device xdp: fix zero-copy frame layout slip: fix use-after-free in sl_sync() net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition net: tun: bound receive headroom net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO net: ibm: emac: mal: fix NAPI locking net: ipa: fix stalled modem TX queue after runtime resume net: l2tp: do not propagate multicast notification errors net: openvswitch: fix flow mask use-after-free on flow deletion net: openvswitch: fix nf_connlabels leak in ovs_ct_init net: phylink: correctly validate returned PCS in phylink_inband_caps net: ravb: avoid dereferencing an invalid PTP clock net: ravb: serialize PTP clock teardown net: thunderbolt: Release the Rx HopID that was handed out on mismatch net: thunderbolt: Mark the connection down when bringing it up fails NTB: ntb_transport: Recycle TX entries before client callbacks NTB: ntb_transport: Fail TX enqueue when the QP link is down NTB: ntb_transport: Reject oversized TX buffers net: ntb_netdev: Fix TX busy and drop handling net: ntb_netdev: Avoid double-accounting netif_rx() drops net: ntb_netdev: Count packets dropped on RX refill failure net/mlx5e: SHAMPO, Always calculate page size net/mlx5e: do not HW-GRO coalesce small frames net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry net/smc: do not dereference an unset send buffer on the SMC-D teardown path net/smc: fix socket refcount leak in smc_switch_conns() net/smc: fix use-after-free in smc_rx_pipe_buf_release() net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() net/smc: stop killed, freed and out_of_sync sharing a byte net/smc: unregister the connection before draining the rx tasklet net: cap advertised IP tunnel headroom net: fix spurious TX timeout after dev_activate() net: skbuff: don't touch shared zerocopy state in skb_tx_error() seg6: reset IP6CB after IPv6 decapsulation hwrng: stm32 - Fix runtime PM cleanup on registration failure mfd: cgbc: Fix teardown ordering in cgbc_remove() mfd: qnap-mcu: keep the reply buffer alive past a command timeout mfd: sm501: Fix potential memory leaks during remove ALSA: 6fire: bound the MIDI event length from the device ALSA: aloop: Check card index validity at probe ALSA: bcd2000: clear the URB pointers on disconnect ALSA: FCP: do not copy out an uninitialised init response ALSA: hda/ext: preserve PPLCCTL bits when clearing reset ALSA: mpu401: Check card index validity at probe ALSA: mts64: Check card index validity at probe ALSA: pcxhr: initialize mutexes before requesting threaded IRQ ALSA: portman2x4: Check card index validity at probe ALSA: serial-u16550: Check card index validity at probe ALSA: virmidi: Check card index validity at probe ALSA: hda/realtek: Add quirk for TongFang XxAF5xxx ALSA: hda/realtek: Enable micmute LED on HP EliteBook 6 G1a p/n: AD3Q9ET#UUG ALSA: hda/realtek: Fix Lenovo Yoga Slim 7 14AKP10 quirk ordering arch_numa: avoid false positive fortify warning in setup_node_to_cpumask_map() dm-stats: fix a crash if allocation of per-cpu data fails dm-switch: use WRITE_ONCE() in switch_region_table_write() dm-pcache: validate geometry fields from on-disk cache_info dm-pcache: validate kset key_num and intra-segment bounds dm-pcache: validate on-media seg_num against the cache device size dm-pcache: bound the persisted tail-position offset dm-pcache: clamp the tail kset read to the segment data region dm-pcache: detect a cycle in the last-kset chain during replay dm-pcache: only hand out initialized cache segments dm-pcache: fix implicit u8 truncation of gc_percent in message handler dm-pcache: fix use-after-free and invalid seg operations in kset_replay() i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c: master: adi: initialize the lock before enabling interrupts i3c: master: Fix info leak and UAF in device unregister path i3c: master: svc: bound IBI payload to the requested max_payload_len i3c: renesas: Check that the transfer is valid before accessing it i3c: renesas: Clean DATBAS register on detach i3c: renesas: Follow the reset deassert order used in probe i3c: renesas: Reconfigure the DATBAS register on re-attach i3c: renesas: Reset the controller on resume i3c: renesas: Restore STDBR and EXTBR registers on resume i3c: renesas: Perform Dynamic Address Assignment on resume wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop fuse-uring: refactor io-uring header copying to ring fuse-uring: refactor io-uring header copying from ring fuse-uring: use enum types for header copying fuse-uring: refactor setting up copy state for payload copying fuse-uring: use named constants for io-uring iovec indices fuse: copy request headers via a stack buffer for io-uring crypto: iaa - unmap dst before software fallback on decompress crypto: atmel-ecc - clean up and improve ECDH comments crypto: atmel-ecc - avoid stale fallback key after set_secret failure mm/kmemleak: stop the task stack scan early when interrupted mm/kmemleak: report RCU-tasks quiescent states during the scan wifi: mwifiex: Detach sync cmd buffer on interrupted wait wifi: rtl818x: initialize eeprom_93cx6 struct to zero wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() wifi: rtw88: pci: fix resource leak on failed NAPI setup wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy wifi: mt76: mt7925: cancel mlo_pm_work on stop wifi: mt76: add external EEPROM support for mt799x chipsets wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames wifi: mt76: mt7996: validate default EEPROM firmware size vsock/virtio: flush works in dependency order w1: ds28e17: reject an oversize length on an I2C block read xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() zloop: truncate finished zones to zone capacity tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] sticon/parisc: Detect default STI graphics card for console output signal: avoid shared siginfo namespace rewrites smack: fix cred UAF in smack_file_send_sigiotask() taskstats: fix cpumask parsing cutting off the last character timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() timer: Keep debugobjects state consistent in migrate_timer_list() udf: Fix i_lenExtents truncation on 32-bit kernels selftests/mm: fix on-fault-limit false failure under sudo-rs resource: Add __resource_contains_unbound() for internal contains checks ACPI: scan: Do not combine resources that overlap completely platform/chrome: sensorhub: Fix dropped timestamp events and log spam UBUNTU: Upstream stable to v6.18.49, v6.18.50, v7.2.2, v7.2.3, v7.2.4 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167609/+subscriptions

[Bug 2167567] Re: [Resolute] Enable Device Tree overlays on amd64 for PCIe-attached FPGAs

** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167567 Title: [Resolute] Enable Device Tree overlays on amd64 for PCIe-attached FPGAs Status in linux package in Ubuntu: Confirmed Bug description: [Impact] AMD Embedded+ platforms need Device Tree support on x86 to describe IP blocks implemented in PCIe-attached FPGAs. Loading an overlay for a particular FPGA design allows existing Device Tree-based drivers to be reused without porting each driver to ACPI. The required configuration options are currently disabled or absent from the amd64 configuration. [Fix] Enable the following options for amd64 in linux-amd-embedded: CONFIG_OF=y Enable the core Device Tree infrastructure used to represent device nodes and properties in the kernel. CONFIG_OF_OVERLAY=y Enable support for applying Device Tree overlays at runtime. This also selects the dynamic tree, flattened tree and phandle resolution support required by overlays. CONFIG_DTC=y Enable the Device Tree compiler used during the kernel build to compile Device Tree sources into flattened binary form. This option is also selected through CONFIG_OF_FLATTREE. CONFIG_PCI_DYNAMIC_OF_NODES=y Enable creation of Device Tree nodes for PCI devices, providing nodes to which an FPGA driver can attach an overlay describing downstream devices. This requires CONFIG_OF_IRQ and selects CONFIG_OF_DYNAMIC. Synchronize the dependent amd64 configuration entries exposed by enabling CONFIG_OF. Most newly visible optional drivers remain explicitly disabled. Keep all overrides in the linux-amd-embedded configuration. The arm64 configuration and shared generic configuration remain unchanged. This change does not add an FPGA Discovery driver. [Test Plan] Export the amd64 configuration and run olddefconfig. Verify that all four requested options remain set to y. Run the Ubuntu annotations check against the resulting configuration. Compare the arm64 configuration before and after the change. These configuration checks pass. The arm64 export is identical. Full kernel build and runtime overlay testing remain to be done. [Where problems could occur] Enabling CONFIG_OF exposes additional configuration symbols and automatically selects supporting infrastructure. Incorrect or incomplete annotations could cause configuration checks to fail or produce unintended amd64 configuration changes. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167567/+subscriptions

[Bug 2165844] Re: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write

Control run, unpatched out-of-tree build of the same source. BUG_ON at 29.4 s, 56,013,951 inline mappings, 76 distinct offset_in_page values, 1 mapping violating iomap->length <= PAGE_SIZE - offset_in_page(iomap->inline_data). The bpftrace [DANGER] line predicting the crash is interleaved character by character with the oops text around the "kernel BUG at fs/iomap" line, because bpftrace and the kernel share the serial console. Deinterleaved it reads: [DANGER] off=4032 len=160 sum=4192 -- BUG_ON next matching RDX=0xfc0, RSI=0xa0, RAX=0x40 in the oops registers below it. qemu was killed 45 s after the hit, which is why the run length is 60 s. ** Attachment added: "Control run, unpatched: BUG_ON at 29.4 s (boot console log)" https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165844/+attachment/6000955/+files/boot-vanilla.log -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2165844 Title: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write Status in linux package in Ubuntu: Confirmed Bug description: [Summary] Any buffered write() to an ntfs3-mounted volume can hit a BUG_ON in the generic iomap write path and panic the kernel. An unprivileged process (rsync, uid 1000) took the whole machine down; the system froze instantly, then kdump rebooted into the capture kernel. [Impact] This is reachable from unprivileged userspace with a plain write(2) syscall. Whatever the state of the NTFS volume, the correct outcome is -EIO returned to the caller, not a kernel panic. Reproducing it needs nothing but a writable NTFS mount, which udisks/GNOME Files creates by default when a user clicks a Windows partition. [Environment] Ubuntu 26.04, linux-image-7.0.0-30-generic 7.0.0-30.30, x86_64 ASUS ROG STRIX B550-XE GAMING WIFI, BIOS 3607 NTFS volume: 1.8 TB Windows system partition, mounted read-write by udisks (driver ntfs3, POSIX ACLs enabled) [What happened] Writing to the NTFS mount, the kernel hit the assertion and died: kernel BUG at fs/iomap/buffered-io.c:1061! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 2 UID: 1000 PID: 18561 Comm: rsync Kdump: loaded Tainted: G O Hardware name: ASUS System Product Name/ROG STRIX B550-XE GAMING WIFI RIP: 0010:iomap_write_end+0x1e0/0x1f0 Call Trace: iomap_write_iter+0x171/0x340 iomap_file_buffered_write+0xa6/0x110 ntfs_file_write_iter+0x267/0x310 [ntfs3] vfs_write+0x25b/0x490 ksys_write+0x71/0xf0 __x64_sys_write+0x19/0x30 do_syscall_64+0x105/0x5a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The faulting syscall was a 137-byte write(2) to fd 1 (ORIG_RAX 0x1, RDX 0x89) — an ordinary small buffered write, not anything exotic. The G/O taint is the out-of-tree NVIDIA module (595.84). It is unrelated to this code path; ntfs3, iomap and the write path are all in-tree. [Preceding symptom] About 14 minutes before the panic, ntfs3 logged a large burst of metadata repairs on the same volume: ntfs3(nvme0n1p2): ino=..., Correct links count -> N ntfs3: 15286 callbacks suppressed So the volume was not perfectly clean. That may well be what steers the write path into the bad state — but an inconsistent filesystem must not be able to panic the kernel, so it looks like a missing error path rather than a disk problem. [Reproducer] Not deterministic here, but the shape is simple: 1. Mount an NTFS volume read-write with ntfs3 (udisksctl mount is enough). 2. Run sustained buffered I/O against it (rsync of a large tree). The other reports linked below describe the same trace from ordinary file writes, including games writing save data. [Already reported elsewhere] Same trace, same line, on 7.0.x kernels since roughly April 2026: - https://github.com/CachyOS/linux-cachyos/issues/841 - https://discuss.cachyos.org/t/kernel-bug-in-iomap-write-end-triggered-by-ntfs3-buffered-write-linux-7-0-1-cachyos/28546 - https://bbs.archlinux.org/viewtopic.php?pid=2296728 - https://forum.manjaro.org/t/total-system-hangs-and-fs-iomap-kernel-panic-on-7-0-10-stable-on-6-18-lts/188283 I could not find an upstream fix. Upstream appears to be replacing ntfs3 with the new ntfsplus driver in 7.1 rather than fixing this one. [Suggestion for Ubuntu] Since 26.04 ships 7.0 and a user can trigger a kernel panic by copying files onto a Windows partition from the file manager, it may be worth either backporting a fix or having udisks default NTFS mounts to read-only until 7.1 lands via HWE. [Attached] Full kernel ring buffer from the kdump vmcore (VmCoreDmesg), plus the usual apport-collected hardware and package data. Sanitisation applied before upload: firewall log lines were dropped, and MAC addresses, the wireless BSSID/SSID and LAN IPv4 addresses were replaced with placeholders in VmCoreDmesg, CurrentDmesg and WifiSyslog. Nothing else was altered; the panic trace is untouched. An incomplete vmcore (2.3 GB, truncated because the machine was power-cycled during the dump) is available if it would help. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-30-generic 7.0.0-30.30 ProcVersionSignature: Ubuntu 7.0.0-30.30-generic 7.0.12 Uname: Linux 7.0.0-30-generic x86_64 ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: pass Date: Sun Aug 30 11:45:03 2026 InstallationDate: Installed on 2026-07-12 (49 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: ASUS System Product Name PackageArchitecture: amd64 ProcFB: 0 nvidia-drmdrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-30-generic root=UUID=5778b2dd-b496-4525-b52f-223e5be557bc ro quiet splash crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux Title: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write UpgradeStatus: No upgrade log present (probably fresh install) _MarkForUpload: True dmi.bios.date: 03/18/2024 dmi.bios.release: 5.17 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 3607 dmi.board.asset.tag: Default string dmi.board.name: ROG STRIX B550-XE GAMING WIFI dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev X.0x dmi.chassis.asset.tag: Default string dmi.chassis.type: 3 dmi.chassis.vendor: Default string dmi.chassis.version: Default string dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr3607:bd03/18/2024:br5.17:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGSTRIXB550-XEGAMINGWIFI:rvrRevX.0x:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.: dmi.product.family: To be filled by O.E.M. dmi.product.name: System Product Name dmi.product.sku: SKU dmi.product.version: System Version dmi.sys.vendor: ASUS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165844/+subscriptions

[Bug 2165844] Re: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write

Reproduced in a VM and used to verify the patch proposed by Viktor Pashaiev. Reproducer and both boot logs attached. All runs on 7.0.0-30-generic, the kernel the original crash happened on. ## 1. Mechanism attr_data_get_block_locked() duplicates the resident attribute: *res = kmemdup(resident_data(attr_b), data_size, GFP_KERNEL); The pointer becomes iomap->inline_data, iomap->length becomes data_size. iomap_write_end_inline() then asserts iomap->length <= PAGE_SIZE - offset_in_page(iomap->inline_data) A slab object rarely starts on a page boundary. data_size 129..192 comes from kmalloc-192: order=1 slab, 42 objects, 192-byte stride. Object #21 starts at 4032, and 4032 + (129..192) = 4161..4224 > 4096. The other 41 objects pass. ## 2. The guest needs >= 16 vCPUs calculate_order() in mm/slub.c: nr_cpus = num_present_cpus(); min_objects = 4 * (fls(nr_cpus) + 1); min_order = max(slub_min_order, get_order(min_objects * size)); size=192, 15 CPUs: fls(15)=4, min_objects=20, 20*192=3840, get_order(3840)=0, min_order=0. calc_slab_order() at order 0: rem = 4096 % 192 = 64, threshold slab_size/16 = 256, 64 <= 256 so it stops. order=0: one page, 21 objects, offsets 0..3840, and 3840 + 192 = 4032 <= 4096. Nothing straddles a page boundary; the BUG_ON is unreachable. size=192, 16 CPUs: fls(16)=5, min_objects=24, 24*192=4608, get_order(4608)=1, min_order=1. order=1: 42 objects, object #21 at 4032. Threshold is exactly 16 present CPUs. Verify in the guest (mode 0400, root): # cat /sys/kernel/slab/kmalloc-192/order -> 1 # cat /sys/kernel/slab/kmalloc-192/objs_per_slab -> 42 Below that, a reproducer reports "not reproducible" on a broken kernel too. ## 3. Workload The original crash was a 137-byte write(2) to fd 1, rsync writing its log to an ntfs3 volume. attr_set_size_res() only goes non-resident once used + dsize > sbi->max_bytes_per_attr (~700 bytes at a 1024-byte MFT record), so a small new file stays resident and its first write takes the resident branch. Loop: create file, one write() of 129..192 bytes, unlink. Two constraints, both of which produce zero hits if violated: * Appending (open(p,'ab')) writes past i_size, goes through ntfs_extend() -> ntfs_set_size(), and once non-resident kmemdup() is never called again. * Unrelated kmalloc-192 traffic is required. The buffer lives only from iomap_begin to iomap_end, so SLUB returns the same object LIFO and object #21 never surfaces. Setup: qemu/KVM, 16 vCPUs, 4 GiB RAM, 4 GiB NTFS image, files seeded through ntfs-3g, then remounted with ntfs3 rw. ## 4. Result on an unmodified kernel Shipped ntfs3 module, BUG_ON 68.4 s after boot: kernel BUG at fs/iomap/buffered-io.c:1061! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 10 UID: 0 PID: 1788 Comm: python3 Not tainted 7.0.0-30-generic #30-Ubuntu RIP: 0010:iomap_write_end+0x1e0/0x1f0 RAX: 0000000000000040 RBX: fffffb5d41097280 RCX: fffffb5d41097280 RDX: 0000000000000fc0 RSI: 00000000000000b8 RDI: ffff8dc4cd852fc0 Call Trace: iomap_write_iter+0x171/0x340 iomap_file_buffered_write+0xa6/0x110 ntfs_file_write_iter+0x267/0x310 [ntfs3] vfs_write+0x25b/0x490 ksys_write+0x71/0xf0 __x64_sys_write+0x19/0x30 Against the crash originally reported here: original (rsync) reproducer RDX = offset_in_page 0xfc0 = 4032 0xfc0 = 4032 RAX = PAGE_SIZE - off 0x40 = 64 0x40 = 64 write length 0x89 = 137 0xb8 = 184 inline_data low bits ...c55acfc0 ...cd852fc0 Same signature in bugzilla.kernel.org #221446 (Arch, 7.0.2, process `git`): RDX 0xfc0, RAX 0x40, length 145. Three independent hits on offset 4032, all lengths inside the kmalloc-192 range. ## 5. Patch verification Built out of tree from linux-source-7.0.0 against 7.0.0-30-generic headers as two modules differing only by Viktor's patch, which applied with no offsets and no fuzz. Confirmed at machine-code level: in attr_data_get_block_locked() the unpatched build calls kmemdup_noprof, the patched build calls alloc_pages_noprof plus memcpy. An unpatched out-of-tree build was run first as a control. Without it, "no panic with the patch" would not distinguish a working fix from an out-of-tree build that differs from the shipped module. Each run verified the live module by comparing /sys/module/ntfs3/srcversion against the expected value. Same kernel, same image, same workload. Only the module differs. control patched live srcversion 99295717... (ok) A80EE935... (ok) kmalloc-192 geometry order=1 objs=42 order=1 objs=42 run length 60 s 840 s inline mappings observed 56,013,951 864,253,125 offset_in_page values seen 76 distinct only 0 mappings violating the check 1 0 BUG_ON yes, at 29.4 s none in 840 s The @DANGER counter and the oops agree on the same mapping. In the control run the probe fired on the return from ntfs_iomap_begin() with [DANGER] off=4032 len=160 sum=4192 -- BUG_ON next and the oops milliseconds later reports RDX=0xfc0 (4032), RSI=0xa0 (160), RAX=0x40 (4096 - 4032). In boot-vanilla.log that printf is interleaved character by character with the oops text, since bpftrace and the kernel share the console. So the counter that reads 0 across 864,253,125 mappings on the patched build is measuring the exact condition that crashes. The offset row is the load-bearing one. With the patch every inline mapping was page aligned, so length <= PAGE_SIZE - 0 holds for any resident size (at most ~700 bytes against 4096). The failure mode is removed structurally, not made rarer. The BUG_ON itself is probabilistic, which matters for SRU verification. Four unpatched runs here fired at 68.4 s, 25.7 s and 29.4 s after boot, and one did not fire at all in 360 s despite 319,225,379 inline mappings and 85 distinct offsets in that run. A violating mapping turns up on the order of once per a few hundred million inline mappings, since it needs the allocation to land in object #21 of a kmalloc-192 slab specifically. Absence of a BUG_ON in a single run is therefore not evidence of a fix on its own; the offset distribution is the reliable signal. Instrumentation caveat: offset 4032 alone is not a fault indicator. It is also the last object of a kmalloc-64 slab (63 * 64 = 4032), where 4032 + 64 = 4096 fits exactly. In longer runs most landings on 4032 were harmless for exactly that reason. The condition to test is length > PAGE_SIZE - offset_in_page(inline_data), which is what the @DANGER counter in the attached bpftrace script evaluates. ## 6. Upstream 70d3855594cf6e8791970714b65cac3202d6160e "ntfs3: Allocate iomap inline_data using alloc_page" Mihai Brodschi Fixes: 099ef9ab9203 ("fs/ntfs3: implement iomap-based file operations") fs/ntfs3/attrib.c and fs/ntfs3/inode.c. Mainline v7.2, stable v7.1.5. Checked both stable tags: fs/ntfs3/attrib.c in v7.1.4 still has kmemdup(resident_data(...)), in v7.1.5 it has alloc_page(). 099ef9ab9203, the iomap conversion, is what shipped in 7.0. 7.0.0-31.31 is at "Upstream stable to v6.18.39, v7.1.4". ## Attachments * ntfs3-2165844-reproducer.tar.gz - workload scripts, bpftrace script, runner, module build script, README with the recipe and the prerequisites. * boot-vanilla.log - control run, unpatched (next comment). * boot-patched.log - patched run (next comment). ** Attachment added: "Reproducer: workload scripts, bpftrace instrumentation, VM runner, module build script, README" https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165844/+attachment/6000954/+files/ntfs3-2165844-reproducer.tar.gz -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2165844 Title: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write Status in linux package in Ubuntu: Confirmed Bug description: [Summary] Any buffered write() to an ntfs3-mounted volume can hit a BUG_ON in the generic iomap write path and panic the kernel. An unprivileged process (rsync, uid 1000) took the whole machine down; the system froze instantly, then kdump rebooted into the capture kernel. [Impact] This is reachable from unprivileged userspace with a plain write(2) syscall. Whatever the state of the NTFS volume, the correct outcome is -EIO returned to the caller, not a kernel panic. Reproducing it needs nothing but a writable NTFS mount, which udisks/GNOME Files creates by default when a user clicks a Windows partition. [Environment] Ubuntu 26.04, linux-image-7.0.0-30-generic 7.0.0-30.30, x86_64 ASUS ROG STRIX B550-XE GAMING WIFI, BIOS 3607 NTFS volume: 1.8 TB Windows system partition, mounted read-write by udisks (driver ntfs3, POSIX ACLs enabled) [What happened] Writing to the NTFS mount, the kernel hit the assertion and died: kernel BUG at fs/iomap/buffered-io.c:1061! Oops: invalid opcode: 0000 [#1] SMP NOPTI CPU: 2 UID: 1000 PID: 18561 Comm: rsync Kdump: loaded Tainted: G O Hardware name: ASUS System Product Name/ROG STRIX B550-XE GAMING WIFI RIP: 0010:iomap_write_end+0x1e0/0x1f0 Call Trace: iomap_write_iter+0x171/0x340 iomap_file_buffered_write+0xa6/0x110 ntfs_file_write_iter+0x267/0x310 [ntfs3] vfs_write+0x25b/0x490 ksys_write+0x71/0xf0 __x64_sys_write+0x19/0x30 do_syscall_64+0x105/0x5a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The faulting syscall was a 137-byte write(2) to fd 1 (ORIG_RAX 0x1, RDX 0x89) — an ordinary small buffered write, not anything exotic. The G/O taint is the out-of-tree NVIDIA module (595.84). It is unrelated to this code path; ntfs3, iomap and the write path are all in-tree. [Preceding symptom] About 14 minutes before the panic, ntfs3 logged a large burst of metadata repairs on the same volume: ntfs3(nvme0n1p2): ino=..., Correct links count -> N ntfs3: 15286 callbacks suppressed So the volume was not perfectly clean. That may well be what steers the write path into the bad state — but an inconsistent filesystem must not be able to panic the kernel, so it looks like a missing error path rather than a disk problem. [Reproducer] Not deterministic here, but the shape is simple: 1. Mount an NTFS volume read-write with ntfs3 (udisksctl mount is enough). 2. Run sustained buffered I/O against it (rsync of a large tree). The other reports linked below describe the same trace from ordinary file writes, including games writing save data. [Already reported elsewhere] Same trace, same line, on 7.0.x kernels since roughly April 2026: - https://github.com/CachyOS/linux-cachyos/issues/841 - https://discuss.cachyos.org/t/kernel-bug-in-iomap-write-end-triggered-by-ntfs3-buffered-write-linux-7-0-1-cachyos/28546 - https://bbs.archlinux.org/viewtopic.php?pid=2296728 - https://forum.manjaro.org/t/total-system-hangs-and-fs-iomap-kernel-panic-on-7-0-10-stable-on-6-18-lts/188283 I could not find an upstream fix. Upstream appears to be replacing ntfs3 with the new ntfsplus driver in 7.1 rather than fixing this one. [Suggestion for Ubuntu] Since 26.04 ships 7.0 and a user can trigger a kernel panic by copying files onto a Windows partition from the file manager, it may be worth either backporting a fix or having udisks default NTFS mounts to read-only until 7.1 lands via HWE. [Attached] Full kernel ring buffer from the kdump vmcore (VmCoreDmesg), plus the usual apport-collected hardware and package data. Sanitisation applied before upload: firewall log lines were dropped, and MAC addresses, the wireless BSSID/SSID and LAN IPv4 addresses were replaced with placeholders in VmCoreDmesg, CurrentDmesg and WifiSyslog. Nothing else was altered; the panic trace is untouched. An incomplete vmcore (2.3 GB, truncated because the machine was power-cycled during the dump) is available if it would help. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-30-generic 7.0.0-30.30 ProcVersionSignature: Ubuntu 7.0.0-30.30-generic 7.0.12 Uname: Linux 7.0.0-30-generic x86_64 ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: pass Date: Sun Aug 30 11:45:03 2026 InstallationDate: Installed on 2026-07-12 (49 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: ASUS System Product Name PackageArchitecture: amd64 ProcFB: 0 nvidia-drmdrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-30-generic root=UUID=5778b2dd-b496-4525-b52f-223e5be557bc ro quiet splash crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux Title: linux 7.0.0-30: kernel BUG at fs/iomap/buffered-io.c:1061 in iomap_write_end() on ntfs3 buffered write UpgradeStatus: No upgrade log present (probably fresh install) _MarkForUpload: True dmi.bios.date: 03/18/2024 dmi.bios.release: 5.17 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 3607 dmi.board.asset.tag: Default string dmi.board.name: ROG STRIX B550-XE GAMING WIFI dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev X.0x dmi.chassis.asset.tag: Default string dmi.chassis.type: 3 dmi.chassis.vendor: Default string dmi.chassis.version: Default string dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr3607:bd03/18/2024:br5.17:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGSTRIXB550-XEGAMINGWIFI:rvrRevX.0x:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.: dmi.product.family: To be filled by O.E.M. dmi.product.name: System Product Name dmi.product.sku: SKU dmi.product.version: System Version dmi.sys.vendor: ASUS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165844/+subscriptions

среда

Re: [Bug 2161309] Re: Backlight regression

I can confirm that the fix resolves the original backlight issue on my hardware. Verification details: - Machine: HP Pavilion x360 Convertible 14-ba0xx - GPU: Intel HD Graphics 610 [8086:5906] - Ubuntu: 24.04 (Noble), amd64 - Running kernel: 7.0.0-31-generic - Package version: 7.0.0-31.31~24.04.1 Brightness hotkeys and the GNOME brightness slider now change the physical panel brightness normally. The original failure was reproducible with 7.0.0-28-generic, where the software brightness value changed but the physical backlight stayed dim. No i915.enable_dpcd_backlight workaround is present on the current kernel command line. This verifies the Noble generic/HWE kernel fix for my duplicate report #2163014. The linux-xuantie verification request does not apply to this amd64 machine. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2161309 Title: Backlight regression Status in linux package in Ubuntu: Fix Released Status in linux-hwe-7.0 package in Ubuntu: Fix Released Status in linux source package in Noble: Invalid Status in linux-hwe-7.0 source package in Noble: Fix Released Status in linux source package in Resolute: Fix Released Status in linux-hwe-7.0 source package in Resolute: Invalid Bug description: ----------------------------- Possible workaround until 7.0.0-31 kernel is released Boot with i915.enable_dpcd_backlight=0 parameter ----------------------------- ThinkPad T480 Intel UHD 620 brightness works on 7.0.0-27 brightness fails on 7.0.0-28 /sys/class/backlight/intel_backlight changes but panel does not ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-27-generic 7.0.0-27.27 ProcVersionSignature: Ubuntu 7.0.0-27.27-generic 7.0.6 Uname: Linux 7.0.0-27-generic x86_64 ApportVersion: 2.34.0-0ubuntu2 Architecture: amd64 AudioDevicesInUse:  USER PID ACCESS COMMAND  /dev/snd/controlC0: neal 3608 F.... wireplumber  /dev/snd/seq: neal 3589 F.... pipewire CasperMD5CheckResult: unknown CurrentDesktop: ubuntu:GNOME Date: Mon Jul 20 12:47:12 2026 InstallationDate: Installed on 2026-07-12 (8 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: LENOVO 20L6S6L601 ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-27-generic root=UUID=1cea3fcd-0665-4cb4-a85a-4ebc58d5aed0 ro quiet splash acpi_backlight=native crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 09/06/2025 dmi.bios.release: 1.56 dmi.bios.vendor: LENOVO dmi.bios.version: N24ET81W (1.56 ) dmi.board.asset.tag: Not Available dmi.board.name: 20L6S6L601 dmi.board.vendor: LENOVO dmi.board.version: SDK0J40697 WIN dmi.chassis.asset.tag: No Asset Information dmi.chassis.type: 10 dmi.chassis.vendor: LENOVO dmi.chassis.version: None dmi.ec.firmware.release: 1.22 dmi.modalias: dmi:bvnLENOVO:bvrN24ET81W(1.56):bd09/06/2025:br1.56:efr1.22:svnLENOVO:pn20L6S6L601:pvrThinkPadT480:rvnLENOVO:rn20L6S6L601:rvrSDK0J40697WIN:cvnLENOVO:ct10:cvrNone:skuLENOVO_MT_20L6_BU_Think_FM_ThinkPadT480:pfaThinkPadT480: dmi.product.family: ThinkPad T480 dmi.product.name: 20L6S6L601 dmi.product.sku: LENOVO_MT_20L6_BU_Think_FM_ThinkPad T480 dmi.product.version: ThinkPad T480 dmi.sys.vendor: LENOVO To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2161309/+subscriptions

[Bug 2167535] [NEW] amdgpu, suspend/resume, RX 6700 XT, affects linux-generic-7.0 package

Public bug reported: Hardware: RX 6700 XT (RDNA2), amdgpu, X11/Cinnamon on Mint 22.3 Regression window: fails intermittently on 7.0.0-31-generic, rock-solid on 6.8.0-139-generic over multi-day testing Symptom: monitor fails to wake from sleep, intermittent First observed: shortly after 2026-09-11, coinciding with the 7.0.0-31 point release Reported here too https://github.com/linuxmint/linuxmint/issues/912 ** Affects: linux (Ubuntu) Importance: Undecided Status: New ** Tags: kernel-bug ** Tags added: kernel-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167535 Title: amdgpu, suspend/resume, RX 6700 XT, affects linux-generic-7.0 package Status in linux package in Ubuntu: New Bug description: Hardware: RX 6700 XT (RDNA2), amdgpu, X11/Cinnamon on Mint 22.3 Regression window: fails intermittently on 7.0.0-31-generic, rock-solid on 6.8.0-139-generic over multi-day testing Symptom: monitor fails to wake from sleep, intermittent First observed: shortly after 2026-09-11, coinciding with the 7.0.0-31 point release Reported here too https://github.com/linuxmint/linuxmint/issues/912 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167535/+subscriptions

[Bug 2167524] Re: ThinkPad T14 Gen 2 AMD (20XL): ~10.26s s2idle resume stall; missing upstream AMD PMC quirk

** Tags added: kernel-daily-bug -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2167524 Title: ThinkPad T14 Gen 2 AMD (20XL): ~10.26s s2idle resume stall; missing upstream AMD PMC quirk Status in linux package in Ubuntu: New Bug description: Ubuntu 26.04.1 LTS, kernel 7.0.0-31-generic (package 7.0.0-31.31). Hardware: Lenovo ThinkPad T14 Gen 2a, product 20XLS14Y00. Current BIOS: R1MET65W (1.35), EC R1MHT65W. Suspend mode: s2idle. IOMMU default domain: Translated. Problem: Waking from suspend feels like roughly 30 seconds before the lock/login screen appears. Examination of four recorded suspend/resume cycles found a repeatable ~10.26-second stall inside kernel resume. This accounts for part of the perceived delay; the full 30 seconds has not been instrumented. The stall was observed with BIOS 1.33 and persists with BIOS 1.35. Evidence: Using the kernel's _SOURCE_MONOTONIC_TIMESTAMP from journalctl JSON, the most recent recorded cycle in the examined boot has: 92.332175: ACPI: EC: interrupt unblocked 102.592656: clocksource: Long readout interval, skipping watchdog check 102.607541: USB resume messages begin 102.608959: AMDGPU resume messages begin 102.615186: NVMe resume messages begin 103.136892: PM: suspend exit Three preceding cycles similarly show gaps of approximately 10.256, 10.265, and 10.261 seconds at the same point in resume. These are wake-time gaps, excluding the interval spent suspended. The kernel module amd-pmc.ko.zst contains a DMI entry for 20XK but no 20XL entry. No "Using s2idle quirk" message appears during boot. amd_pmc is loaded and bound; disable_workarounds is N. Likely cause / upstream fix: Commit e25fb2258bddbcf70df69d1358be3e1274bdc5f2: "platform/x86/amd/pmc: Add T14 Gen2 AMD (20XL) to s2idle quirk list" https://lists.openwall.net/linux-kernel/2026/07/17/358 The upstream report describes the same missing model match and ~10.25s firmware SMI stall on NVMe D3->D0 with IOMMU translation enabled. The fix adds the 20XL DMI match to the existing workaround. Please consider backporting this fix to the Ubuntu 26.04 GA kernel. Expected: Resume promptly to the lock screen. Actual: Repeated ~10.26s kernel stall before devices and desktop resume. Mainline testing: I have not yet tested a kernel containing the fix on this machine. Reproduction: Suspend using the desktop or by closing the lid, then wake the machine. Record the method used, suspend duration, dock/peripheral state, and measured wake-to-lock-screen delay in additional testing. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-31-generic 7.0.0-31.31 ProcVersionSignature: Ubuntu 7.0.0-31.31-generic 7.0.14 Uname: Linux 7.0.0-31-generic x86_64 ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Wed Sep 16 11:19:40 2026 InstallationDate: Installed on 2026-04-29 (141 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: LENOVO 20XLS14Y00 ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-31-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux Title: ThinkPad T14 Gen 2 AMD (20XL): ~10.26s s2idle resume stall; missing upstream AMD PMC quirk UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 08/07/2026 dmi.bios.release: 1.35 dmi.bios.vendor: LENOVO dmi.bios.version: R1MET65W (1.35 ) dmi.board.asset.tag: Not Available dmi.board.name: 20XLS14Y00 dmi.board.vendor: LENOVO dmi.board.version: SDK0J40697 WIN dmi.chassis.asset.tag: AI778595 dmi.chassis.type: 10 dmi.chassis.vendor: LENOVO dmi.chassis.version: None dmi.ec.firmware.release: 1.35 dmi.modalias: dmi:bvnLENOVO:bvrR1MET65W(1.35):bd08/07/2026:br1.35:efr1.35:svnLENOVO:pn20XLS14Y00:pvrThinkPadT14Gen2a:rvnLENOVO:rn20XLS14Y00:rvrSDK0J40697WIN:cvnLENOVO:ct10:cvrNone:skuLENOVO_MT_20XL_BU_Think_FM_ThinkPadT14Gen2a:pfaThinkPadT14Gen2a: dmi.product.family: ThinkPad T14 Gen 2a dmi.product.name: 20XLS14Y00 dmi.product.sku: LENOVO_MT_20XL_BU_Think_FM_ThinkPad T14 Gen 2a dmi.product.version: ThinkPad T14 Gen 2a dmi.sys.vendor: LENOVO To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167524/+subscriptions

[Bug 2165873] Re: Bluetooth fails to initialize due to a kernel NULL pointer error

I can confirm the bug affects a CyberPower Z890 Ultra 9 with ASUSTeK Z890 MAX GAMING WIFI7 motherboard and, of course, a MEDIATEK bluetooth device. Bluetooth does not work on 6.8.0-139-generic, but it does work on 6.8.0-138-generic -- the *previous* kernel (and several still earlier kernels). I recently upgraded my ASUS BIOS to version 3212. The problem persists (as does my 'hibernate will not resume' problem) in 139. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2165873 Title: Bluetooth fails to initialize due to a kernel NULL pointer error Status in linux package in Ubuntu: Confirmed Status in linux-hwe-6.8 package in Ubuntu: Confirmed Status in linux source package in Noble: In Progress Status in linux-hwe-6.8 source package in Noble: In Progress Bug description: SRU Justification [Impact] Bluetooth fails to start on HP systems with a MediaTek MT7922 controller (CID: 202401-33402) running 6.8.0-139.139~22.04.1. The kernel oopses during Bluetooth power-on. The worker thread dies, so hci0 stays in DOWN INIT and its BD address is all zeros. Bluetooth is unusable. rfkill unblock and hciconfig do not help. Error log: Bluetooth: hci0: HW/SW Version: 0x008a008a, Build Time: 20231120183620 BUG: kernel NULL pointer dereference, address: 0000000000000219 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 9 PID: 340 Comm: kworker/u33:1 Not tainted 6.8.0-139-generic Workqueue: hci0 hci_power_on [bluetooth] RIP: 0010:__pm_runtime_resume+0x1b/0x80 Call Trace: <TASK> usb_autopm_get_interface+0x1d/0x60 btmtk_usb_hci_wmt_sync+0xb9/0x340 [btmtk] btmtk_setup_firmware_79xx+0x1c7/0x360 [btmtk] btusb_mtk_setup+0x2d6/0x610 [btusb] hci_dev_setup_sync+0x6c/0x440 [bluetooth] hci_dev_init_sync+0x3e/0x1c0 [bluetooth] hci_dev_open_sync+0x8b/0x350 [bluetooth] hci_dev_do_open+0x28/0x70 [bluetooth] hci_power_on+0x50/0x210 [bluetooth] Hits 3 out of 3 boots. 6.8.0-138.138~22.04.1 is fine. This breaks these checkbox tests: com.canonical.certification::bluetooth/detect-output com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 This is not limited to the reporting machine. Any MediaTek MT766x or MT79xx USB Bluetooth controller takes the same path and hits the same oops on 6.8.0-139. [Fix] 6.8.0-139 picked up d019930b0049 ("Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c", v6.11) as a stable dependency of the urb->setup_packet leak fix. That commit moves the WMT command path into btmtk.c, where it reads intf, udev and ctrl_anchor out of struct btmtk_data. The commit that fills those three fields in is the next one in the same upstream series, and it was not picked: 5c5e8c52e3ca Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to btmtk.c (v6.11) So the pointers stay NULL. The first WMT command calls usb_autopm_get_interface(NULL) and oopses. The fix is to backport 5c5e8c52e3ca so the series is complete again. It adds the missing assignments in btusb_mtk_setup(): btmtk_data->drv_name = btusb_driver.name; btmtk_data->intf = data->intf; btmtk_data->udev = data->udev; btmtk_data->ctrl_anchor = &data->ctrl_anchor; btmtk_data->reset_sync = btusb_mtk_reset; udev and ctrl_anchor are just as NULL as intf, and are used by the WMT receive URB, so all of them are needed. A NULL check on intf alone would only move the oops. [Test Plan] On a machine with a MediaTek MT7922 Bluetooth controller. Boot the machine, then check for the oops: $ dmesg | grep -A20 'NULL pointer' $ journalctl -b -0 -k | grep btmtk Check the controller came up: $ sudo rfkill unblock bluetooth $ hciconfig -a $ hcitool dev Without patch: dmesg shows the NULL pointer oops in __pm_runtime_resume with btmtk_usb_hci_wmt_sync in the call trace. hciconfig shows hci0 DOWN INIT with BD Address 00:00:00:00:00:00. hcitool dev lists no device. With patch: no oops in dmesg. hciconfig shows hci0 UP RUNNING with a real BD address. hcitool dev lists hci0. Then run the two failing tests: $ checkbox-cli run com.canonical.certification::bluetooth/detect-output $ checkbox-cli run com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 Both pass with the patch, both fail without it. [Where problems could occur] Could break the btusb and btmtk drivers for all MediaTek Bluetooth controllers. This is not a small patch. It moves btusb_mtk_setup() and btusb_mtk_shutdown() and their helpers out of btusb.c into btmtk.c, so the whole MediaTek setup path is touched. If the move dropped or changed something, MediaTek Bluetooth would fail to set up. That would show up as "Failed to set up firmware" or "Failed to send wmt func ctrl" in dmesg, or as a timeout during hci0 power-on, and Bluetooth would stay down. The device reset path also moves (btusb_mtk_subsys_reset becomes btmtk_usb_subsys_reset). If that is wrong, chip recovery after a firmware crash would fail and the controller would need a reboot to come back. Nothing outside drivers/bluetooth is touched. Other Bluetooth vendors (Intel, Realtek, Qualcomm, Broadcom) are not affected, because btusb only calls this code for MediaTek devices. [Other Info] The patch is upstream in v6.11. It is the second half of a two-commit series; the first half is already in 6.8.0-139, which is what caused the regression. The backport needed manual conflict resolution in drivers/bluetooth/btusb.c. 6.8 is missing the intermediate commits that added fw_flavor handling and the BTMTK_FIRMWARE_LOADED flag, so the old copies of btusb_mtk_func_query(), btusb_mtk_uhw_reg_*(), btusb_mtk_reg_read(), btusb_mtk_id_get(), btusb_mtk_reset_done(), btusb_mtk_subsys_reset() and the open-coded btusb_mtk_setup() body all conflicted. Those are exactly the functions this commit deletes, so the upstream side was taken. The resulting btusb_mtk_setup() is identical to upstream at 5c5e8c52e3ca. =========================== The Bluetooth controller fails to initialize on kernel 6.8.0-139.139~22.04.1. During hci_power_on, the MediaTek btmtk driver hits a kernel NULL pointer dereference, the handling kworker dies with IRQs disabled, and hci0 is left stuck in DOWN INIT with an all-zero BD address. The previous kernel 6.8.0-138.138~22.04.1 is unaffected, with identical linux-firmware(20220329.git681281e4-0ubuntu3.42) and bluez(5.64-0ubuntu1.4), this seems to be a kernel regression. This failure affects the following checkbox tests: - com.canonical.certification::bluetooth/detect-output - com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 Machines: - https://certification.canonical.com/hardware/202401-33402/ Steps to reproduce: 1. Boot the machine with kernel 6.8.0-139.139~22.04.1. 2. Checkbox dmesg for crash, null pointer appears in btmtk_usb_hci_wmt_sync during hci power on. 3. run `sudo rfkill unblock bluetooth; hciconfig -a; hcitool dev` to check the controller state. 4. reboot into 6.8.0-138.138~22.04.1 and repeat steps 2-3. Fail rate: 3/3 on 6.8.0.139 ProblemType: Bug DistroRelease: Ubuntu 22.04 Package: linux-image-6.8.0-139-generic 6.8.0-139.139~22.04.1 ProcVersionSignature: Ubuntu 6.8.0-139.139~22.04.1-generic 6.8.12 Uname: Linux 6.8.0-139-generic x86_64 ApportVersion: 2.20.11-0ubuntu82.10 Architecture: amd64 AudioDevicesInUse:  USER PID ACCESS COMMAND  /dev/snd/controlC1: ubuntu 1307 F.... pulseaudio  /dev/snd/controlC0: ubuntu 1307 F.... pulseaudio CasperMD5CheckMismatches: ./preseed/project.cfg CasperMD5CheckResult: fail Date: Mon Aug 31 13:19:26 2026 DistributionChannelDescriptor:  # This is the distribution channel descriptor for the OEM CDs  # For more information see http://wiki.ubuntu.com/DistributionChannelDescriptor  canonical-oem-stella-jammy-amd64-20240408-800 InstallationDate: Installed on 2026-08-28 (3 days ago) InstallationMedia: Ubuntu 22.04 LTS "Jammy Jellyfish" - pc-stella-jammy-amd64-20240408-800 MachineType: HP HP ZBook Power 16 inch G11 A Mobile Workstation PC ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-6.8.0-139-generic root=UUID=6006e56e-4c1e-49e1-8a56-4c55eea6d70d ro automatic-oem-config quiet splash vt.handoff=7 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. RelatedPackageVersions:  linux-restricted-modules-6.8.0-139-generic N/A  linux-backports-modules-6.8.0-139-generic N/A  linux-firmware 20220329.git681281e4-0ubuntu3.42 SourcePackage: linux-hwe-6.8 UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 03/21/2024 dmi.bios.release: 1.1 dmi.bios.vendor: HP dmi.bios.version: W85 Ver. 01.01.01 dmi.board.name: 8C95 dmi.board.vendor: HP dmi.board.version: KBC Version 08.40.00 dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.ec.firmware.release: 8.64 dmi.modalias: dmi:bvnHP:bvrW85Ver.01.01.01:bd03/21/2024:br1.1:efr8.64:svnHP:pnHPZBookPower16inchG11AMobileWorkstationPC:pvrSBKPF:rvnHP:rn8C95:rvrKBCVersion08.40.00:cvnHP:ct10:cvr:skuXW8SKU3#ABA: dmi.product.family: 103C_5336AN HP ZBook dmi.product.name: HP ZBook Power 16 inch G11 A Mobile Workstation PC dmi.product.sku: XW8SKU3#ABA dmi.product.version: SBKPF dmi.sys.vendor: HP To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165873/+subscriptions

[Bug 2165873] Re: Bluetooth fails to initialize due to a kernel NULL pointer error

The reported bug affects my hardware as well Bluetooth USB: Bus 001 Device 002: ID 0489:e0e0 Foxconn / Hon Hai Wireless_Device Machine: Manufacturer: HP Product Name: HP ENVY x360 2-in-1 Laptop 15-ey0xxx Version: Type1ProductConfigId Motherboard: Manufacturer: HP Product Name: 8A31 Version: 26.11 BIOS: Vendor: Insyde Version: F.11 Release Date: 02/10/2023 For now I'm having to use older kernels to get bluetooth. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2165873 Title: Bluetooth fails to initialize due to a kernel NULL pointer error Status in linux package in Ubuntu: Confirmed Status in linux-hwe-6.8 package in Ubuntu: Confirmed Status in linux source package in Noble: In Progress Status in linux-hwe-6.8 source package in Noble: In Progress Bug description: SRU Justification [Impact] Bluetooth fails to start on HP systems with a MediaTek MT7922 controller (CID: 202401-33402) running 6.8.0-139.139~22.04.1. The kernel oopses during Bluetooth power-on. The worker thread dies, so hci0 stays in DOWN INIT and its BD address is all zeros. Bluetooth is unusable. rfkill unblock and hciconfig do not help. Error log: Bluetooth: hci0: HW/SW Version: 0x008a008a, Build Time: 20231120183620 BUG: kernel NULL pointer dereference, address: 0000000000000219 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 9 PID: 340 Comm: kworker/u33:1 Not tainted 6.8.0-139-generic Workqueue: hci0 hci_power_on [bluetooth] RIP: 0010:__pm_runtime_resume+0x1b/0x80 Call Trace: <TASK> usb_autopm_get_interface+0x1d/0x60 btmtk_usb_hci_wmt_sync+0xb9/0x340 [btmtk] btmtk_setup_firmware_79xx+0x1c7/0x360 [btmtk] btusb_mtk_setup+0x2d6/0x610 [btusb] hci_dev_setup_sync+0x6c/0x440 [bluetooth] hci_dev_init_sync+0x3e/0x1c0 [bluetooth] hci_dev_open_sync+0x8b/0x350 [bluetooth] hci_dev_do_open+0x28/0x70 [bluetooth] hci_power_on+0x50/0x210 [bluetooth] Hits 3 out of 3 boots. 6.8.0-138.138~22.04.1 is fine. This breaks these checkbox tests: com.canonical.certification::bluetooth/detect-output com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 This is not limited to the reporting machine. Any MediaTek MT766x or MT79xx USB Bluetooth controller takes the same path and hits the same oops on 6.8.0-139. [Fix] 6.8.0-139 picked up d019930b0049 ("Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c", v6.11) as a stable dependency of the urb->setup_packet leak fix. That commit moves the WMT command path into btmtk.c, where it reads intf, udev and ctrl_anchor out of struct btmtk_data. The commit that fills those three fields in is the next one in the same upstream series, and it was not picked: 5c5e8c52e3ca Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to btmtk.c (v6.11) So the pointers stay NULL. The first WMT command calls usb_autopm_get_interface(NULL) and oopses. The fix is to backport 5c5e8c52e3ca so the series is complete again. It adds the missing assignments in btusb_mtk_setup(): btmtk_data->drv_name = btusb_driver.name; btmtk_data->intf = data->intf; btmtk_data->udev = data->udev; btmtk_data->ctrl_anchor = &data->ctrl_anchor; btmtk_data->reset_sync = btusb_mtk_reset; udev and ctrl_anchor are just as NULL as intf, and are used by the WMT receive URB, so all of them are needed. A NULL check on intf alone would only move the oops. [Test Plan] On a machine with a MediaTek MT7922 Bluetooth controller. Boot the machine, then check for the oops: $ dmesg | grep -A20 'NULL pointer' $ journalctl -b -0 -k | grep btmtk Check the controller came up: $ sudo rfkill unblock bluetooth $ hciconfig -a $ hcitool dev Without patch: dmesg shows the NULL pointer oops in __pm_runtime_resume with btmtk_usb_hci_wmt_sync in the call trace. hciconfig shows hci0 DOWN INIT with BD Address 00:00:00:00:00:00. hcitool dev lists no device. With patch: no oops in dmesg. hciconfig shows hci0 UP RUNNING with a real BD address. hcitool dev lists hci0. Then run the two failing tests: $ checkbox-cli run com.canonical.certification::bluetooth/detect-output $ checkbox-cli run com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 Both pass with the patch, both fail without it. [Where problems could occur] Could break the btusb and btmtk drivers for all MediaTek Bluetooth controllers. This is not a small patch. It moves btusb_mtk_setup() and btusb_mtk_shutdown() and their helpers out of btusb.c into btmtk.c, so the whole MediaTek setup path is touched. If the move dropped or changed something, MediaTek Bluetooth would fail to set up. That would show up as "Failed to set up firmware" or "Failed to send wmt func ctrl" in dmesg, or as a timeout during hci0 power-on, and Bluetooth would stay down. The device reset path also moves (btusb_mtk_subsys_reset becomes btmtk_usb_subsys_reset). If that is wrong, chip recovery after a firmware crash would fail and the controller would need a reboot to come back. Nothing outside drivers/bluetooth is touched. Other Bluetooth vendors (Intel, Realtek, Qualcomm, Broadcom) are not affected, because btusb only calls this code for MediaTek devices. [Other Info] The patch is upstream in v6.11. It is the second half of a two-commit series; the first half is already in 6.8.0-139, which is what caused the regression. The backport needed manual conflict resolution in drivers/bluetooth/btusb.c. 6.8 is missing the intermediate commits that added fw_flavor handling and the BTMTK_FIRMWARE_LOADED flag, so the old copies of btusb_mtk_func_query(), btusb_mtk_uhw_reg_*(), btusb_mtk_reg_read(), btusb_mtk_id_get(), btusb_mtk_reset_done(), btusb_mtk_subsys_reset() and the open-coded btusb_mtk_setup() body all conflicted. Those are exactly the functions this commit deletes, so the upstream side was taken. The resulting btusb_mtk_setup() is identical to upstream at 5c5e8c52e3ca. =========================== The Bluetooth controller fails to initialize on kernel 6.8.0-139.139~22.04.1. During hci_power_on, the MediaTek btmtk driver hits a kernel NULL pointer dereference, the handling kworker dies with IRQs disabled, and hci0 is left stuck in DOWN INIT with an all-zero BD address. The previous kernel 6.8.0-138.138~22.04.1 is unaffected, with identical linux-firmware(20220329.git681281e4-0ubuntu3.42) and bluez(5.64-0ubuntu1.4), this seems to be a kernel regression. This failure affects the following checkbox tests: - com.canonical.certification::bluetooth/detect-output - com.canonical.certification::bluetooth4/beacon_eddystone_url_hc0 Machines: - https://certification.canonical.com/hardware/202401-33402/ Steps to reproduce: 1. Boot the machine with kernel 6.8.0-139.139~22.04.1. 2. Checkbox dmesg for crash, null pointer appears in btmtk_usb_hci_wmt_sync during hci power on. 3. run `sudo rfkill unblock bluetooth; hciconfig -a; hcitool dev` to check the controller state. 4. reboot into 6.8.0-138.138~22.04.1 and repeat steps 2-3. Fail rate: 3/3 on 6.8.0.139 ProblemType: Bug DistroRelease: Ubuntu 22.04 Package: linux-image-6.8.0-139-generic 6.8.0-139.139~22.04.1 ProcVersionSignature: Ubuntu 6.8.0-139.139~22.04.1-generic 6.8.12 Uname: Linux 6.8.0-139-generic x86_64 ApportVersion: 2.20.11-0ubuntu82.10 Architecture: amd64 AudioDevicesInUse:  USER PID ACCESS COMMAND  /dev/snd/controlC1: ubuntu 1307 F.... pulseaudio  /dev/snd/controlC0: ubuntu 1307 F.... pulseaudio CasperMD5CheckMismatches: ./preseed/project.cfg CasperMD5CheckResult: fail Date: Mon Aug 31 13:19:26 2026 DistributionChannelDescriptor:  # This is the distribution channel descriptor for the OEM CDs  # For more information see http://wiki.ubuntu.com/DistributionChannelDescriptor  canonical-oem-stella-jammy-amd64-20240408-800 InstallationDate: Installed on 2026-08-28 (3 days ago) InstallationMedia: Ubuntu 22.04 LTS "Jammy Jellyfish" - pc-stella-jammy-amd64-20240408-800 MachineType: HP HP ZBook Power 16 inch G11 A Mobile Workstation PC ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-6.8.0-139-generic root=UUID=6006e56e-4c1e-49e1-8a56-4c55eea6d70d ro automatic-oem-config quiet splash vt.handoff=7 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. RelatedPackageVersions:  linux-restricted-modules-6.8.0-139-generic N/A  linux-backports-modules-6.8.0-139-generic N/A  linux-firmware 20220329.git681281e4-0ubuntu3.42 SourcePackage: linux-hwe-6.8 UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 03/21/2024 dmi.bios.release: 1.1 dmi.bios.vendor: HP dmi.bios.version: W85 Ver. 01.01.01 dmi.board.name: 8C95 dmi.board.vendor: HP dmi.board.version: KBC Version 08.40.00 dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.ec.firmware.release: 8.64 dmi.modalias: dmi:bvnHP:bvrW85Ver.01.01.01:bd03/21/2024:br1.1:efr8.64:svnHP:pnHPZBookPower16inchG11AMobileWorkstationPC:pvrSBKPF:rvnHP:rn8C95:rvrKBCVersion08.40.00:cvnHP:ct10:cvr:skuXW8SKU3#ABA: dmi.product.family: 103C_5336AN HP ZBook dmi.product.name: HP ZBook Power 16 inch G11 A Mobile Workstation PC dmi.product.sku: XW8SKU3#ABA dmi.product.version: SBKPF dmi.sys.vendor: HP To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165873/+subscriptions