<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/next/linux-next.git/include/net, branch master</title>
<subtitle>The linux-next integration testing tree</subtitle>
<id>https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/atom?h=master</id>
<link rel='self' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/'/>
<updated>2026-09-09T12:11:55+00:00</updated>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next.git</title>
<updated>2026-09-09T12:11:55+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T12:11:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=1e58b62bed6c846f69892f641a7cb2d347db0ffb'/>
<id>urn:sha1:1e58b62bed6c846f69892f641a7cb2d347db0ffb</id>
<content type='text'>
# Conflicts:
#	include/net/mac80211.h
#	net/mac80211/iface.c
#	net/mac80211/tx.c
</content>
</entry>
<entry>
<title>Merge branch 'master' of https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git</title>
<updated>2026-09-09T12:03:25+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T12:03:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=0ec458570d4c1126e50d781d27ab679269f4145d'/>
<id>urn:sha1:0ec458570d4c1126e50d781d27ab679269f4145d</id>
<content type='text'>
# Conflicts:
#	net/bluetooth/hci_sync.c
#	net/bluetooth/l2cap_core.c
</content>
</entry>
<entry>
<title>Merge branch 'main' of https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git</title>
<updated>2026-09-09T12:03:15+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T12:03:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=d835e902bd1289df4c7615cd7be120639b79d594'/>
<id>urn:sha1:d835e902bd1289df4c7615cd7be120639b79d594</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/rdma/rdma.git</title>
<updated>2026-09-09T12:03:13+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T12:03:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=e6815a0ec420d5b17e52219c2ca3d73fd5e9cfb7'/>
<id>urn:sha1:e6815a0ec420d5b17e52219c2ca3d73fd5e9cfb7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/mm/linux.git</title>
<updated>2026-09-09T11:39:26+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T11:39:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=1e3fc311a4694982985224ec180c9b8c0b04edf0'/>
<id>urn:sha1:1e3fc311a4694982985224ec180c9b8c0b04edf0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git</title>
<updated>2026-09-09T11:24:56+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-09-09T11:24:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=79923813bdf1bd0fabdd9a89792738b9b3dc5e93'/>
<id>urn:sha1:79923813bdf1bd0fabdd9a89792738b9b3dc5e93</id>
<content type='text'>
</content>
</entry>
<entry>
<title>mm: drop stale MAX_ORDER references</title>
<updated>2026-09-09T06:30:09+00:00</updated>
<author>
<name>Qi Xi</name>
<email>xiqi2@huawei.com</email>
</author>
<published>2026-08-19T08:20:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=8c7ef8ebbc8133978976819f7366f1f677e39cea'/>
<id>urn:sha1:8c7ef8ebbc8133978976819f7366f1f677e39cea</id>
<content type='text'>
The treewide rename in commit 5e0a760b4441 ("mm, treewide: rename
MAX_ORDER to MAX_PAGE_ORDER") left a few spots still using the old name:

  - two comments in include/net/mana/mana.h and mm/page_alloc.c;
  - the gdb helper scripts/gdb/linux/mm.py, where self.MAX_ORDER is
    a local mirror of the kernel's MAX_ORDER define.

Rename the leftover instances to MAX_PAGE_ORDER so the tree is consistent.

No functional changes.

Link: https://lore.kernel.org/20260819082052.3338603-1-xiqi2@huawei.com
Signed-off-by: Qi Xi &lt;xiqi2@huawei.com&gt;
Reviewed-by: Zi Yan &lt;ziy@nvidia.com&gt;
Cc: Jan Kiszka &lt;jan.kiszka@siemens.com&gt;
Cc: Johannes Weiner &lt;hannes@cmpxchg.org&gt;
Cc: Kefeng Wang &lt;wangkefeng.wang@huawei.com&gt;
Cc: Kieran Bingham &lt;kbingham@kernel.org&gt;
Cc: Konstantin Taranov &lt;kotaranov@microsoft.com&gt;
Cc: Long Li &lt;longli@microsoft.com&gt;
Cc: Michal Hocko &lt;mhocko@suse.com&gt;
Cc: Nanyong Sun &lt;sunnanyong@huawei.com&gt;
Cc: Suren Baghdasaryan &lt;surenb@google.com&gt;
Cc: Vlastimil Babka &lt;vbabka@kernel.org&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
</content>
</entry>
<entry>
<title>Bluetooth: coredump: Quiesce dump work on unregister</title>
<updated>2026-09-08T16:18:45+00:00</updated>
<author>
<name>Weiming Shi</name>
<email>bestswngs@gmail.com</email>
</author>
<published>2026-09-06T15:43:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=701ca71884b3d101fd25b7adbf972355056ef352'/>
<id>urn:sha1:701ca71884b3d101fd25b7adbf972355056ef352</id>
<content type='text'>
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.

Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.

Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump")
Reported-by: syzbot+b170dbf55520ebf5969a@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b170dbf55520ebf5969a
Reported-by: Aby Sam Ross &lt;abysamross@gmail.com&gt;
Link: https://lore.kernel.org/r/20260322210849.68743-1-abysamross@gmail.com
Suggested-by: Aby Sam Ross &lt;abysamross@gmail.com&gt;
Reported-by: Tristan Madani &lt;tristan@talencesecurity.com&gt;
Link: https://lore.kernel.org/r/20260814231248.3096377-1-tristmd@gmail.com
Reported-by: Xiang Mei &lt;xmei5@asu.edu&gt;
Assisted-by: OpenAI Codex:gpt-5
Signed-off-by: Weiming Shi &lt;bestswngs@gmail.com&gt;
Reported-by: Xiang Mei &lt;xmei5@asu.edu&gt;
Signed-off-by: Luiz Augusto von Dentz &lt;luiz.von.dentz@intel.com&gt;
</content>
</entry>
<entry>
<title>wifi: mac80211: don't allow injecting frames wider than the chanctx</title>
<updated>2026-09-08T13:39:06+00:00</updated>
<author>
<name>Johannes Berg</name>
<email>johannes.berg@intel.com</email>
</author>
<published>2026-09-08T12:28:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=d4b31f7757d81eb45cf40bf1a7875b43cef28c53'/>
<id>urn:sha1:d4b31f7757d81eb45cf40bf1a7875b43cef28c53</id>
<content type='text'>
Frames injected on a monitor interface can carry a radiotap
field requesting a bandwidth, which mac80211 passes down to
the driver regardless of the the actual operational bandwidth.

If the bandwidth requested is too wide, that triggers a warning
in hwsim:

  WARN_ON(hwsim_get_chanwidth(bw) &gt; hwsim_get_chanwidth(confbw))

Drop such frames entirely instead since they cannot be sent.

Assisted-by: LLM
Fixes: 646e76bb5daf ("mac80211: parse VHT info in injected frames")
Reported-by: syzbot+435fdb053cf98bfa5778@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=435fdb053cf98bfa5778
Link: https://patch.msgid.link/20260908122838.201719-13-johannes@sipsolutions.net
Signed-off-by: Johannes Berg &lt;johannes.berg@intel.com&gt;
</content>
</entry>
<entry>
<title>tcp: Do not allow buggy transitions between ehash and lhash2.</title>
<updated>2026-09-08T00:40:26+00:00</updated>
<author>
<name>Kuniyuki Iwashima</name>
<email>kuniyu@google.com</email>
</author>
<published>2026-09-04T03:35:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.landau.one/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=8cc3aef0cb198049805ecc061a2cc7b79b0ae43e'/>
<id>urn:sha1:8cc3aef0cb198049805ecc061a2cc7b79b0ae43e</id>
<content type='text'>
The following state transitions have long been a playground for
syzbot, and recently AI joined in, reporting a lot more bugs.

  * listen() + shutdown() + connect()
  * connect() + connect(AF_UNSPEC) + listen()

All the fix attempts would add more code to the fast path, which
is not worth it.

Instead of playing whack-a-mole with these edge-case bugs,
let's disallow these transitions.

Note that unhashed_state is placed in the 4-byte hole after
icsk_pmtu_cookie.

  $ pahole -C inet_connection_sock vmlinux
  struct inet_connection_sock {
  ...
	__u32                      icsk_pmtu_cookie;     /*  1208     4 */
	unsigned char              unhashed_state;       /*  1212     1 */

	/* XXX 3 bytes hole, try to pack */

Reported-by: Kyle Zeng &lt;kylebot@openai.com&gt;
Closes: https://lore.kernel.org/netdev/20260731140512.566464-1-david.lee@trailofbits.com/
Reported-by: Michal Luczaj &lt;mhal@rbox.co&gt;
Closes: https://lore.kernel.org/netdev/20260803-sockmap-lookup-tcp-leak-v2-0-306e025bfe66@rbox.co/
Reported-by: Hyunwoo Kim &lt;imv4bel@gmail.com&gt;
Closes: https://lore.kernel.org/netdev/20260824033331.1084971-1-imv4bel@gmail.com/
Signed-off-by: Kuniyuki Iwashima &lt;kuniyu@google.com&gt;
Link: https://patch.msgid.link/20260904033543.2635540-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski &lt;kuba@kernel.org&gt;
</content>
</entry>
</feed>
