# All Global changes to build and install go here. # Per the below section about __spec_install_pre, any rpm # environment changes that affect %%install need to go # here before the %%install macro is pre-built. # Disable frame pointers %undefine _include_frame_pointers # Save default LTO flags before disabling (for use with kernel tools). %global _default_lto_cflags %{_lto_cflags} # Disable LTO in userspace packages (disabled for perf). %global _lto_cflags %{nil} # Option to enable compiling with clang instead of gcc. %bcond_with toolchain_clang %if %{with toolchain_clang} %global toolchain clang %endif # Compile the kernel with LTO (only supported when building with clang). %bcond_with clang_lto %if %{with clang_lto} && %{without toolchain_clang} {error:clang_lto requires --with toolchain_clang} %endif # RPM macros strip everything in BUILDROOT, either with __strip # or find-debuginfo.sh. Make use of __spec_install_post override # and save/restore binaries we want to package as unstripped. %define buildroot_unstripped %{_builddir}/root_unstripped %define buildroot_save_unstripped() \ (cd %{buildroot}; cp -rav --parents -t %{buildroot_unstripped}/ %1 || true) \ %{nil} %define __restore_unstripped_root_post \ echo "Restoring unstripped artefacts %{buildroot_unstripped} -> %{buildroot}" \ cp -rav %{buildroot_unstripped}/. %{buildroot}/ \ %{nil} # The kernel's %%install section is special # Normally the %%install section starts by cleaning up the BUILD_ROOT # like so: # # %%__spec_install_pre %%{___build_pre}\ # [ "$RPM_BUILD_ROOT" != "/" ] && rm -rf "${RPM_BUILD_ROOT}"\ # mkdir -p `dirname "$RPM_BUILD_ROOT"`\ # mkdir "$RPM_BUILD_ROOT"\ # %%{nil} # # But because of kernel variants, the %%build section, specifically # BuildKernel(), moves each variant to its final destination as the # variant is built. This violates the expectation of the %%install # section. As a result we snapshot the current env variables and # purposely leave out the removal section. All global wide changes # should be added above this line otherwise the %%install section # will not see them. %global __spec_install_pre %{___build_pre} # Replace '-' with '_' where needed so that variants can use '-' in # their name. %define uname_suffix() %{lua: local flavour = rpm.expand('%{?1:+%{1}}') flavour = flavour:gsub('-', '_') if flavour ~= '' then print(flavour) end } # This returns the main kernel tied to a debug variant. For example, # kernel-debug is the debug version of kernel, so we return an empty # string. However, kernel-64k-debug is the debug version of kernel-64k, # in this case we need to return "64k", and so on. This is used in # macros below where we need this for some uname based requires. %define uname_variant() %{lua: local flavour = rpm.expand('%{?1:%{1}}') _, _, main, sub = flavour:find("(%w+)-(.*)") if main then print("+" .. main) end } # At the time of this writing (2019-03), RHEL8 packages use w2.xzdio # compression for rpms (xz, level 2). # Kernel has several large (hundreds of mbytes) rpms, they take ~5 mins # to compress by single-threaded xz. Switch to threaded compression, # and from level 2 to 3 to keep compressed sizes close to "w2" results. # # NB: if default compression in /usr/lib/rpm/redhat/macros ever changes, # this one might need tweaking (e.g. if default changes to w3.xzdio, # change below to w4T.xzdio): # # This is disabled on i686 as it triggers oom errors %ifnarch i686 %define _binary_payload w3T.xzdio %endif Summary: The Linux kernel %if 0%{?fedora} %define secure_boot_arch x86_64 %else %define secure_boot_arch x86_64 aarch64 s390x ppc64le %endif # Signing for secure boot authentication %ifarch %{secure_boot_arch} %global signkernel 1 %else %global signkernel 0 %endif # RHEL/CentOS/Fedora specific .SBAT entries %if 0%{?centos} %global sbat_suffix centos %else %if 0%{?fedora} %global sbat_suffix fedora %else %global sbat_suffix rhel %endif %endif # Sign modules on all arches %global signmodules 1 # Add additional rhel certificates to system trusted keys. %global rhelkeys 1 # Compress modules only for architectures that build modules %ifarch noarch %global zipmodules 0 %else %global zipmodules 1 %endif # Default compression algorithm %global compression xz %global compression_flags --compress --check=crc32 --lzma2=dict=1MiB %global compext xz %if 0%{?fedora} %define primary_target fedora %else %define primary_target rhel %endif # # genspec.sh variables # # kernel package name %global package_name kernel %global gemini 0 # Include Fedora files %global include_fedora 0 # Include RHEL files %global include_rhel 1 # Include RT files %global include_rt 1 # Include Automotive files %global include_automotive 0 # Provide Patchlist.changelog file %global patchlist_changelog 0 # Set released_kernel to 1 when the upstream source tarball contains a # kernel release. (This includes prepatch or "rc" releases.) # Set released_kernel to 0 when the upstream source tarball contains an # unreleased kernel development snapshot. %global released_kernel 0 # Set debugbuildsenabled to 1 to build separate base and debug kernels # (on supported architectures). The kernel-debug-* subpackages will # contain the debug kernel. # Set debugbuildsenabled to 0 to not build a separate debug kernel, but # to build the base kernel using the debug configuration. (Specifying # the --with-release option overrides this setting.) %define debugbuildsenabled 1 # define buildid .local %define specrpmversion 6.12.0 %define specversion 6.12.0 %define patchversion 6.12 %define pkgrelease 274.rk35x.1 %define kversion 6 %define tarfile_release 6.12.0-274.rk35x.1.el10 # This is needed to do merge window version magic %define patchlevel 12 # This allows pkg_release to have configurable %%{?dist} tag %define specrelease 274.rk35x.1%{?buildid}%{?dist} # This defines the kabi tarball version %define kabiversion 6.12.0-274.rk35x.1.el10 # If this variable is set to 1, a bpf selftests build failure will cause a # fatal kernel package build error %define selftests_must_build 0 # # End of genspec.sh variables # %define pkg_release %{specrelease} # libexec dir is not used by the linker, so the shared object there # should not be exported to RPM provides %global __provides_exclude_from ^%{_libexecdir}/kselftests # The following build options are (mostly) enabled by default, but may become # enabled/disabled by later architecture-specific checks. # Where disabled by default, they can be enabled by using --with in the # rpmbuild command, or by forcing these values to 1. # Where enabled by default, they can be disabled by using --without in # the rpmbuild command, or by forcing these values to 0. # # standard kernel %define with_up %{?_without_up: 0} %{?!_without_up: 1} # build the base variants %define with_base %{?_without_base: 0} %{?!_without_base: 1} # build also debug variants %define with_debug %{?_without_debug: 0} %{?!_without_debug: 1} # kernel-zfcpdump (s390 specific kernel for zfcpdump) %define with_zfcpdump %{?_without_zfcpdump: 0} %{?!_without_zfcpdump: 1} # kernel-16k (aarch64 kernel with 16K page_size) %define with_arm64_16k %{?_with_arm64_16k: 1} %{?!_with_arm64_16k: 0} # kernel-64k (aarch64 kernel with 64K page_size) %define with_arm64_64k %{?_without_arm64_64k: 0} %{?!_without_arm64_64k: 1} # kernel-rt (x86_64 and aarch64 only PREEMPT_RT enabled kernel) %define with_realtime %{?_without_realtime: 0} %{?!_without_realtime: 1} # kernel-rt-64k (aarch64 RT kernel with 64K page_size) %define with_realtime_arm64_64k %{?_without_realtime_arm64_64k: 0} %{?!_without_realtime_arm64_64k: 1} # kernel-automotive (x86_64 and aarch64 with PREEMPT_RT enabled - currently off by default) %define with_automotive %{?_with_automotive: 1} %{?!_with_automotive: 0} # Supported variants # with_base with_debug with_gcov # up X X X # zfcpdump X X # arm64_16k X X X # arm64_64k X X X # realtime X X X # automotive X X X # kernel-doc %define with_doc %{?_without_doc: 0} %{?!_without_doc: 1} # kernel-headers %define with_headers %{?_without_headers: 0} %{?!_without_headers: 1} %define with_cross_headers %{?_without_cross_headers: 0} %{?!_without_cross_headers: 1} # perf %define with_perf %{?_without_perf: 0} %{?!_without_perf: 1} # libperf %define with_libperf %{?_without_libperf: 0} %{?!_without_libperf: 1} # tools %define with_tools %{?_without_tools: 0} %{?!_without_tools: 1} # ynl %define with_ynl %{?_without_ynl: 0} %{?!_without_ynl: 1} # kernel-debuginfo %define with_debuginfo %{?_without_debuginfo: 0} %{?!_without_debuginfo: 1} # kernel-kmap-internal: source-to-module mapping data (JSON) %define with_kmap %{?_without_kmap: 0} %{?!_without_kmap: 1} # kernel-abi-stablelists %define with_kernel_abi_stablelists %{?_without_kernel_abi_stablelists: 0} %{?!_without_kernel_abi_stablelists: 1} # internal samples and selftests %define with_selftests %{?_without_selftests: 0} %{?!_without_selftests: 1} # # Additional options for user-friendly one-off kernel building: # # Only build the base kernel (--with baseonly): %define with_baseonly %{?_with_baseonly: 1} %{?!_with_baseonly: 0} # Only build the debug variants (--with dbgonly): %define with_dbgonly %{?_with_dbgonly: 1} %{?!_with_dbgonly: 0} # Only build the realtime kernel (--with rtonly): %define with_rtonly %{?_with_rtonly: 1} %{?!_with_rtonly: 0} # Only build the automotive variant of the kernel (--with automotiveonly): %define with_automotiveonly %{?_with_automotiveonly: 1} %{?!_with_automotiveonly: 0} # Build the automotive kernel (--with automotive_build), this builds base variant with automotive config/options: %define with_automotive_build %{?_with_automotive_build: 1} %{?!_with_automotive_build: 0} # Control whether we perform a compat. check against published ABI. %define with_kabichk %{?_without_kabichk: 0} %{?!_without_kabichk: 1} # Temporarily disable kabi checks until RC. %define with_kabichk 0 # Control whether we perform a compat. check against DUP ABI. %define with_kabidupchk %{?_with_kabidupchk: 1} %{?!_with_kabidupchk: 0} # # Control whether to run an extensive DWARF based kABI check. # Note that this option needs to have baseline setup in SOURCE300. %define with_kabidwchk %{?_without_kabidwchk: 0} %{?!_without_kabidwchk: 1} %define with_kabidw_base %{?_with_kabidw_base: 1} %{?!_with_kabidw_base: 0} # # Control whether to install the vdso directories. %define with_vdso_install %{?_without_vdso_install: 0} %{?!_without_vdso_install: 1} # # should we do C=1 builds with sparse %define with_sparse %{?_with_sparse: 1} %{?!_with_sparse: 0} # # Cross compile requested? %define with_cross %{?_with_cross: 1} %{?!_with_cross: 0} # # build a release kernel on rawhide %define with_release %{?_with_release: 1} %{?!_with_release: 0} # verbose build, i.e. no silent rules and V=1 %define with_verbose %{?_with_verbose: 1} %{?!_with_verbose: 0} # # check for mismatched config options %define with_configchecks %{?_without_configchecks: 0} %{?!_without_configchecks: 1} # # gcov support %define with_gcov %{?_with_gcov:1}%{?!_with_gcov:0} # Want to build a vanilla kernel build without any non-upstream patches? %define with_vanilla %{?_with_vanilla: 1} %{?!_with_vanilla: 0} %ifarch x86_64 aarch64 riscv64 %define with_efiuki %{?_without_efiuki: 0} %{?!_without_efiuki: 1} %else %define with_efiuki 0 %endif %if 0%{?fedora} # Kernel headers are being split out into a separate package %define with_headers 0 %define with_cross_headers 0 # no stablelist %define with_kernel_abi_stablelists 0 %define with_arm64_64k 0 %define with_realtime 0 %define with_realtime_arm64_64k 0 %define with_automotive 0 %endif %if %{with_verbose} %define make_opts V=1 %else %define make_opts -s %endif %if %{with toolchain_clang} %ifarch s390x ppc64le %global llvm_ias 0 %else %global llvm_ias 1 %endif %global clang_make_opts HOSTCC=clang CC=clang LLVM_IAS=%{llvm_ias} %if %{with clang_lto} # LLVM=1 enables use of all LLVM tools. %global clang_make_opts %{clang_make_opts} LLVM=1 %endif %global make_opts %{make_opts} %{clang_make_opts} %endif # turn off debug kernel and kabichk for gcov builds %if %{with_gcov} %define with_debug 0 %define with_kabichk 0 %define with_kabidupchk 0 %define with_kabidwchk 0 %define with_kabidw_base 0 %define with_kernel_abi_stablelists 0 %endif # turn off kABI DWARF-based check if we're generating the base dataset %if %{with_kabidw_base} %define with_kabidwchk 0 %endif %define make_target bzImage %define image_install_path boot %define KVERREL %{specversion}-%{release}.%{_target_cpu} %define KVERREL_RE %(echo %KVERREL | sed 's/+/[+]/g') %define hdrarch %_target_cpu %define asmarch %_target_cpu %if 0%{!?nopatches:1} %define nopatches 0 %endif %if %{with_vanilla} %define nopatches 1 %endif %if %{with_release} %define debugbuildsenabled 1 %endif %if !%{with_debuginfo} %define _enable_debug_packages 0 %endif %define debuginfodir /usr/lib/debug # Needed because we override almost everything involving build-ids # and debuginfo generation. Currently we rely on the old alldebug setting. %global _build_id_links alldebug # if requested, only build base kernel %if %{with_baseonly} %define with_debug 0 %define with_realtime 0 %define with_vdso_install 0 %define with_perf 0 %define with_libperf 0 %define with_tools 0 %define with_kernel_abi_stablelists 0 %define with_selftests 0 %endif # if requested, only build debug kernel %if %{with_dbgonly} %define with_base 0 %define with_vdso_install 0 %define with_perf 0 %define with_libperf 0 %define with_tools 0 %define with_kernel_abi_stablelists 0 %define with_selftests 0 %endif # if requested, only build realtime kernel %if %{with_rtonly} %define with_realtime 1 %define with_realtime_arm64_64k 1 %define with_automotive 0 %define with_up 0 %define with_debug 0 %define with_debuginfo 0 %define with_vdso_install 0 %define with_perf 0 %define with_libperf 0 %define with_tools 0 %define with_kernel_abi_stablelists 0 %define with_selftests 0 %define with_headers 0 %define with_efiuki 0 %define with_zfcpdump 0 %define with_arm64_16k 0 %define with_arm64_64k 0 %endif # if requested, only build the automotive variant of the kernel %if %{with_automotiveonly} %define with_automotive 1 %define with_realtime 0 %define with_up 0 %define with_debug 0 %define with_debuginfo 0 %define with_vdso_install 0 %define with_selftests 1 %endif # if requested, build kernel-automotive %if %{with_automotive_build} %define with_automotive 1 %define with_selftests 1 %endif # RT and Automotive kernels are only built on x86_64 and aarch64 %ifnarch x86_64 aarch64 %define with_realtime 0 %define with_automotive 0 %endif %if %{with_automotive} # overrides compression algorithms for automotive %global compression zstd %global compression_flags --rm %global compext zst # automotive does not support the following variants %define with_realtime 0 %define with_realtime_arm64_64k 0 %define with_arm64_16k 0 %define with_arm64_64k 0 %define with_efiuki 0 %define with_doc 0 %define with_headers 0 %define with_cross_headers 0 %define with_perf 0 %define with_libperf 0 %define with_tools 0 %define with_kabichk 0 %define with_kernel_abi_stablelists 0 %define with_kabidw_base 0 %define signkernel 0 %define signmodules 1 %define rhelkeys 0 %endif %if %{zipmodules} %global zipsed -e 's/\.ko$/\.ko.%compext/' # for parallel xz processes, replace with 1 to go back to single process %endif # turn off kABI DUP check and DWARF-based check if kABI check is disabled %if !%{with_kabichk} %define with_kabidupchk 0 %define with_kabidwchk 0 %endif %if %{with_vdso_install} %define use_vdso 1 %endif %ifnarch noarch %define with_kernel_abi_stablelists 0 %endif # Overrides for generic default options # only package docs noarch %ifnarch noarch %define with_doc 0 %define doc_build_fail true %endif %if 0%{?fedora} # don't do debug builds on anything but aarch64 and x86_64 %ifnarch aarch64 x86_64 %define with_debug 0 %endif %endif %define all_configs %{name}-%{specrpmversion}-*.config # don't build noarch kernels or headers (duh) %ifarch noarch %define with_up 0 %define with_realtime 0 %define with_automotive 0 %define with_headers 0 %define with_cross_headers 0 %define with_tools 0 %define with_perf 0 %define with_libperf 0 %define with_selftests 0 %define with_debug 0 %endif # sparse blows up on ppc %ifnarch ppc64le %define with_sparse 0 %endif # zfcpdump mechanism is s390 only %ifnarch s390x %define with_zfcpdump 0 %endif # 16k and 64k variants only for aarch64 %ifnarch aarch64 %define with_arm64_16k 0 %define with_arm64_64k 0 %define with_realtime_arm64_64k 0 %endif %if 0%{?fedora} # This is not for Fedora %define with_zfcpdump 0 %endif # Per-arch tweaks %ifarch i686 %define asmarch x86 %define hdrarch i386 %define kernel_image arch/x86/boot/bzImage %endif %ifarch x86_64 %define asmarch x86 %define kernel_image arch/x86/boot/bzImage %endif %ifarch ppc64le %define asmarch powerpc %define hdrarch powerpc %define make_target vmlinux %define kernel_image vmlinux %define kernel_image_elf 1 %define use_vdso 0 %endif %ifarch s390x %define asmarch s390 %define hdrarch s390 %define kernel_image arch/s390/boot/bzImage %define vmlinux_decompressor arch/s390/boot/vmlinux %endif %ifarch aarch64 %define asmarch arm64 %define hdrarch arm64 %define make_target vmlinuz.efi %define kernel_image arch/arm64/boot/vmlinuz.efi %endif %ifarch riscv64 %define asmarch riscv %define hdrarch riscv %define make_target vmlinuz.efi %define kernel_image arch/riscv/boot/vmlinuz.efi %endif # Should make listnewconfig fail if there's config options # printed out? %if %{nopatches} %define with_configchecks 0 %endif # To temporarily exclude an architecture from being built, add it to # %%nobuildarches. Do _NOT_ use the ExclusiveArch: line, because if we # don't build kernel-headers then the new build system will no longer let # us use the previous build of that package -- it'll just be completely AWOL. # Which is a BadThing(tm). # We only build kernel-headers on the following... %if 0%{?fedora} %define nobuildarches i386 %else %define nobuildarches i386 i686 %endif %ifarch %nobuildarches # disable BuildKernel commands %define with_up 0 %define with_debug 0 %define with_zfcpdump 0 %define with_arm64_16k 0 %define with_arm64_64k 0 %define with_realtime 0 %define with_realtime_arm64_64k 0 %define with_automotive 0 %define with_debuginfo 0 %define with_perf 0 %define with_libperf 0 %define with_tools 0 %define with_selftests 0 %define _enable_debug_packages 0 %endif %ifnarch x86_64 ppc64le s390x aarch64 riscv64 %define with_kmap 0 %endif # Architectures we build tools/cpupower on %if 0%{?fedora} %define cpupowerarchs %{ix86} x86_64 ppc64le aarch64 %else %define cpupowerarchs i686 x86_64 ppc64le aarch64 riscv64 %endif %if 0%{?use_vdso} %define _use_vdso 1 %else %define _use_vdso 0 %endif # If build of debug packages is disabled, we need to know if we want to create # meta debug packages or not, after we define with_debug for all specific cases # above. So this must be at the end here, after all cases of with_debug or not. %define with_debug_meta 0 %if !%{debugbuildsenabled} %if %{with_debug} %define with_debug_meta 1 %endif %define with_debug 0 %endif # short-hand for "are we building base/non-debug variants of ...?" %if %{with_up} && %{with_base} %define with_up_base 1 %else %define with_up_base 0 %endif %if %{with_realtime} && %{with_base} %define with_realtime_base 1 %else %define with_realtime_base 0 %endif %if %{with_automotive} && %{with_base} && !%{with_automotive_build} %define with_automotive_base 1 %else %define with_automotive_base 0 %endif %if %{with_arm64_16k} && %{with_base} %define with_arm64_16k_base 1 %else %define with_arm64_16k_base 0 %endif %if %{with_arm64_64k} && %{with_base} %define with_arm64_64k_base 1 %else %define with_arm64_64k_base 0 %endif %if %{with_realtime_arm64_64k} && %{with_base} %define with_realtime_arm64_64k_base 1 %else %define with_realtime_arm64_64k_base 0 %endif # # Packages that need to be installed before the kernel is, because the %%post # scripts use them. # %define kernel_prereq coreutils, systemd >= 203-2, /usr/bin/kernel-install %define initrd_prereq dracut >= 027 Name: %{package_name} License: ((GPL-2.0-only WITH Linux-syscall-note) OR BSD-2-Clause) AND ((GPL-2.0-only WITH Linux-syscall-note) OR BSD-3-Clause) AND ((GPL-2.0-only WITH Linux-syscall-note) OR CDDL-1.0) AND ((GPL-2.0-only WITH Linux-syscall-note) OR Linux-OpenIB) AND ((GPL-2.0-only WITH Linux-syscall-note) OR MIT) AND ((GPL-2.0-or-later WITH Linux-syscall-note) OR BSD-3-Clause) AND ((GPL-2.0-or-later WITH Linux-syscall-note) OR MIT) AND 0BSD AND BSD-2-Clause AND (BSD-2-Clause OR Apache-2.0) AND BSD-3-Clause AND BSD-3-Clause-Clear AND CC0-1.0 AND GFDL-1.1-no-invariants-or-later AND GPL-1.0-or-later AND (GPL-1.0-or-later OR BSD-3-Clause) AND (GPL-1.0-or-later WITH Linux-syscall-note) AND GPL-2.0-only AND (GPL-2.0-only OR Apache-2.0) AND (GPL-2.0-only OR BSD-2-Clause) AND (GPL-2.0-only OR BSD-3-Clause) AND (GPL-2.0-only OR CDDL-1.0) AND (GPL-2.0-only OR GFDL-1.1-no-invariants-or-later) AND (GPL-2.0-only OR GFDL-1.2-no-invariants-only) AND (GPL-2.0-only WITH Linux-syscall-note) AND GPL-2.0-or-later AND (GPL-2.0-or-later OR BSD-2-Clause) AND (GPL-2.0-or-later OR BSD-3-Clause) AND (GPL-2.0-or-later OR CC-BY-4.0) AND (GPL-2.0-or-later WITH GCC-exception-2.0) AND (GPL-2.0-or-later WITH Linux-syscall-note) AND ISC AND LGPL-2.0-or-later AND (LGPL-2.0-or-later OR BSD-2-Clause) AND (LGPL-2.0-or-later WITH Linux-syscall-note) AND LGPL-2.1-only AND (LGPL-2.1-only OR BSD-2-Clause) AND (LGPL-2.1-only WITH Linux-syscall-note) AND LGPL-2.1-or-later AND (LGPL-2.1-or-later WITH Linux-syscall-note) AND (Linux-OpenIB OR GPL-2.0-only) AND (Linux-OpenIB OR GPL-2.0-only OR BSD-2-Clause) AND Linux-man-pages-copyleft AND MIT AND (MIT OR Apache-2.0) AND (MIT OR GPL-2.0-only) AND (MIT OR GPL-2.0-or-later) AND (MIT OR LGPL-2.1-only) AND (MPL-1.1 OR GPL-2.0-only) AND (X11 OR GPL-2.0-only) AND (X11 OR GPL-2.0-or-later) AND Zlib AND (copyleft-next-0.3.1 OR GPL-2.0-or-later) URL: https://www.kernel.org/ Version: %{specrpmversion} Release: %{pkg_release} # DO NOT CHANGE THE 'ExclusiveArch' LINE TO TEMPORARILY EXCLUDE AN ARCHITECTURE BUILD. # SET %%nobuildarches (ABOVE) INSTEAD %if 0%{?fedora} ExclusiveArch: noarch x86_64 s390x aarch64 ppc64le riscv64 %else ExclusiveArch: noarch i386 i686 x86_64 s390x aarch64 ppc64le riscv64 %endif ExclusiveOS: Linux %ifnarch %{nobuildarches} Requires: %{name}-core-uname-r = %{KVERREL} Requires: %{name}-modules-uname-r = %{KVERREL} Requires: %{name}-modules-core-uname-r = %{KVERREL} Requires: ((%{name}-modules-extra-uname-r = %{KVERREL}) if %{name}-modules-extra-matched) Provides: installonlypkg(kernel) %endif # # List the packages used during the kernel build # BuildRequires: kmod, bash, coreutils, tar, git-core, which BuildRequires: bzip2, xz, findutils, m4, perl-interpreter, perl-Carp, perl-devel, perl-generators, make, diffutils, gawk, %compression BuildRequires: gcc, binutils, redhat-rpm-config, hmaccalc, bison, flex, gcc-c++ %if 0%{?fedora} BuildRequires: rust, rust-src, bindgen %endif BuildRequires: net-tools, hostname, bc, elfutils-devel BuildRequires: dwarves BuildRequires: python3 BuildRequires: python3-devel BuildRequires: python3-pyyaml BuildRequires: kernel-rpm-macros # glibc-static is required for a consistent build environment (specifically # CONFIG_CC_CAN_LINK_STATIC=y). BuildRequires: glibc-static %if %{with_headers} || %{with_cross_headers} BuildRequires: rsync %endif %if %{with_doc} BuildRequires: xmlto, asciidoc, python3-sphinx, python3-sphinx_rtd_theme %endif %if %{with_sparse} BuildRequires: sparse %endif %if %{with_perf} BuildRequires: zlib-devel binutils-devel newt-devel perl(ExtUtils::Embed) bison flex xz-devel BuildRequires: audit-libs-devel python3-setuptools BuildRequires: java-devel BuildRequires: libbabeltrace-devel BuildRequires: libtraceevent-devel %ifnarch s390x BuildRequires: numactl-devel %endif %ifarch aarch64 BuildRequires: opencsd-devel >= 1.0.0 %endif %endif %if %{with_tools} BuildRequires: python3-docutils BuildRequires: gettext ncurses-devel BuildRequires: libcap-devel libcap-ng-devel # The following are rtla requirements BuildRequires: python3-docutils BuildRequires: libtraceevent-devel BuildRequires: libtracefs-devel BuildRequires: libbpf-devel BuildRequires: bpftool BuildRequires: clang %ifarch %{cpupowerarchs} # For libcpupower bindings BuildRequires: swig %endif %ifnarch s390x BuildRequires: pciutils-devel %endif %ifarch i686 x86_64 BuildRequires: libnl3-devel %endif %endif %if %{with_tools} && %{with_ynl} BuildRequires: python3-pyyaml python3-jsonschema python3-pip python3-setuptools python3-wheel %endif BuildRequires: openssl-devel %if %{with_selftests} BuildRequires: clang llvm-devel fuse-devel zlib-devel binutils-devel python3-docutils python3-jsonschema %ifarch x86_64 riscv64 BuildRequires: lld %endif BuildRequires: libcap-devel libcap-ng-devel rsync libmnl-devel libxml2-devel BuildRequires: numactl-devel BuildRequires: xxd %endif BuildConflicts: rhbuildsys(DiskFree) < 500Mb %if %{with_debuginfo} BuildRequires: rpm-build, elfutils BuildConflicts: rpm < 4.13.0.1-19 BuildConflicts: dwarves < 1.13 # Most of these should be enabled after more investigation %undefine _include_minidebuginfo %undefine _find_debuginfo_dwz_opts %undefine _unique_build_ids %undefine _unique_debug_names %undefine _unique_debug_srcs %undefine _debugsource_packages %undefine _debuginfo_subpackages # Remove -q option below to provide 'extracting debug info' messages %global _find_debuginfo_opts -r -q %global _missing_build_ids_terminate_build 1 %global _no_recompute_build_ids 1 %endif %if %{with_kabidwchk} || %{with_kabidw_base} BuildRequires: kabi-dw %endif %if %{signkernel}%{signmodules} BuildRequires: openssl %if %{signkernel} # ELN uses Fedora signing process, so exclude %if 0%{?rhel}%{?centos} && !0%{?eln} BuildRequires: system-sb-certs %endif %ifarch x86_64 aarch64 riscv64 BuildRequires: nss-tools BuildRequires: pesign >= 0.10-4 %endif %endif %endif # If CROSS_COMPILE is defined then we skip the BuildRequires because we do not # know which package maintains that toolchain prefix. %if %{with_cross} %if %{undefined CROSS_COMPILE} BuildRequires: binutils-%{_build_arch}-linux-gnu, gcc-%{_build_arch}-linux-gnu %define CROSS_COMPILE %{_build_arch}-linux-gnu- %endif %define cross_opts CROSS_COMPILE=%{CROSS_COMPILE} %define __strip %{CROSS_COMPILE}strip %endif # These below are required to build man pages %if %{with_perf} BuildRequires: xmlto %endif %if %{with_perf} || %{with_tools} BuildRequires: asciidoc %endif %if %{with toolchain_clang} BuildRequires: clang %endif %if %{with clang_lto} BuildRequires: llvm BuildRequires: lld %endif %if %{with_efiuki} BuildRequires: dracut >= 104 # For dracut UEFI uki binaries BuildRequires: binutils # For the initrd BuildRequires: lvm2 BuildRequires: systemd-boot-unsigned # For systemd-stub and systemd-pcrphase BuildRequires: systemd-udev >= 252-1 # For systemd-repart BuildRequires: xfsprogs e2fsprogs dosfstools # For UKI kernel cmdline addons BuildRequires: systemd-ukify # For TPM operations in UKI initramfs BuildRequires: tpm2-tools # For UKI sb cert %if 0%{?rhel}%{?centos} && !0%{?eln} %if 0%{?centos} BuildRequires: centos-sb-certs >= 9.0-23 %else BuildRequires: redhat-sb-certs >= 9.4-0.1 %endif %endif %endif # Because this is the kernel, it's hard to get a single upstream URL # to represent the base without needing to do a bunch of patching. This # tarball is generated from a src-git tree. If you want to see the # exact git commit you can run # # xzcat -qq ${TARBALL} | git get-tar-commit-id Source0: linux-%{tarfile_release}.tar.xz Source1: Makefile.rhelver Source2: %{package_name}.changelog Source10: redhatsecurebootca5.cer Source13: redhatsecureboot501.cer %if %{signkernel} # Name of the packaged file containing signing key %ifarch ppc64le %define signing_key_filename kernel-signing-ppc.cer %endif %ifarch s390x %define signing_key_filename kernel-signing-s390.cer %endif # pesign cert name is auto-discovered during build from secureboot_key_0, # see pesign_name_0 shell variable # # Fedora/ELN pesign macro expects to see these cert file names, see: # https://github.com/rhboot/pesign/blob/main/src/pesign-rpmbuild-helper.in#L216 %if 0%{?fedora}%{?eln} %define secureboot_ca_0 %{SOURCE10} %define secureboot_key_0 %{SOURCE13} %define secureboot_key_uki_0 %{secureboot_key_0} %endif # RHEL/centos certs come from system-sb-certs %if 0%{?rhel} && !0%{?eln} %define secureboot_ca_0 %{_datadir}/pki/sb-certs/secureboot-ca-%{_arch}.cer %define secureboot_key_0 %{_datadir}/pki/sb-certs/secureboot-kernel-%{_arch}.cer %define secureboot_key_uki_0 %{_datadir}/pki/sb-certs/secureboot-uki-virt-%{_arch}.cer # rhel && !eln %endif # signkernel %endif Source20: mod-denylist.sh Source21: mod-sign.sh Source22: filtermods.py %define modsign_cmd %{SOURCE21} %if 0%{?include_rhel} Source24: %{name}-aarch64-rhel.config Source25: %{name}-aarch64-debug-rhel.config Source27: %{name}-ppc64le-rhel.config Source28: %{name}-ppc64le-debug-rhel.config Source29: %{name}-s390x-rhel.config Source30: %{name}-s390x-debug-rhel.config Source31: %{name}-s390x-zfcpdump-rhel.config Source32: %{name}-x86_64-rhel.config Source33: %{name}-x86_64-debug-rhel.config # ARM64 64K page-size kernel config Source42: %{name}-aarch64-64k-rhel.config Source43: %{name}-aarch64-64k-debug-rhel.config Source44: %{name}-riscv64-rhel.config Source45: %{name}-riscv64-debug-rhel.config %endif %if %{include_rhel} || %{include_automotive} Source23: x509.genkey.rhel Source34: def_variants.yaml.rhel Source41: x509.genkey.centos %endif %if 0%{?include_fedora} Source50: x509.genkey.fedora Source52: %{name}-aarch64-fedora.config Source53: %{name}-aarch64-debug-fedora.config Source54: %{name}-aarch64-16k-fedora.config Source55: %{name}-aarch64-16k-debug-fedora.config Source56: %{name}-ppc64le-fedora.config Source57: %{name}-ppc64le-debug-fedora.config Source58: %{name}-s390x-fedora.config Source59: %{name}-s390x-debug-fedora.config Source60: %{name}-x86_64-fedora.config Source61: %{name}-x86_64-debug-fedora.config Source700: %{name}-riscv64-fedora.config Source701: %{name}-riscv64-debug-fedora.config Source62: def_variants.yaml.fedora %endif Source70: partial-kgcov-snip.config Source71: partial-kgcov-debug-snip.config Source72: partial-clang-snip.config Source73: partial-clang-debug-snip.config Source74: partial-clang_lto-x86_64-snip.config Source75: partial-clang_lto-x86_64-debug-snip.config Source76: partial-clang_lto-aarch64-snip.config Source77: partial-clang_lto-aarch64-debug-snip.config Source80: generate_all_configs.sh Source81: process_configs.sh Source83: uki.sbat.template Source84: uki-addons.sbat.template Source85: kernel.sbat.template Source86: dracut-virt.conf Source87: flavors Source151: uki_create_addons.py Source152: uki_addons.json # Temporary use redhatsecureboot504 for x86 UKI, see RHEL-122230 Source153: redhatsecureboot504.cer Source100: rheldup3.x509 Source101: rhelkpatch1.x509 Source102: nvidiagpuoot001.x509 Source103: rhelimaca1.x509 Source104: rhelima.x509 Source105: rhelima_centos.x509 Source106: fedoraimaca.x509 Source107: nvidiajetsonsoc.x509 Source108: nvidiabfdpu.x509 %if 0%{?fedora}%{?eln} %define ima_ca_cert %{SOURCE106} %endif %if 0%{?rhel} && !0%{?eln} %define ima_ca_cert %{SOURCE103} # rhel && !eln %endif %if 0%{?centos} %define ima_signing_cert %{SOURCE105} %else %define ima_signing_cert %{SOURCE104} %endif %define ima_cert_name ima.cer Source200: check-kabi Source201: Module.kabi_aarch64 Source202: Module.kabi_ppc64le Source203: Module.kabi_s390x Source204: Module.kabi_x86_64 Source205: Module.kabi_riscv64 Source210: Module.kabi_dup_aarch64 Source211: Module.kabi_dup_ppc64le Source212: Module.kabi_dup_s390x Source213: Module.kabi_dup_x86_64 Source214: Module.kabi_dup_riscv64 Source300: kernel-abi-stablelists-%{kabiversion}.tar.xz Source301: kernel-kabi-dw-%{kabiversion}.tar.xz %if 0%{include_rt} %if 0%{include_rhel} Source474: %{name}-aarch64-rt-rhel.config Source475: %{name}-aarch64-rt-debug-rhel.config Source476: %{name}-aarch64-rt-64k-rhel.config Source477: %{name}-aarch64-rt-64k-debug-rhel.config Source478: %{name}-x86_64-rt-rhel.config Source479: %{name}-x86_64-rt-debug-rhel.config %endif %if 0%{include_fedora} Source478: %{name}-aarch64-rt-fedora.config Source479: %{name}-aarch64-rt-debug-fedora.config Source480: %{name}-aarch64-rt-64k-fedora.config Source481: %{name}-aarch64-rt-64k-debug-fedora.config Source482: %{name}-x86_64-rt-fedora.config Source483: %{name}-x86_64-rt-debug-fedora.config Source484: %{name}-riscv64-rt-fedora.config Source485: %{name}-riscv64-rt-debug-fedora.config %endif %endif %if %{include_automotive} %if %{with_automotive_build} Source486: %{name}-aarch64-rhel.config Source487: %{name}-aarch64-debug-rhel.config Source488: %{name}-x86_64-rhel.config Source489: %{name}-x86_64-debug-rhel.config %else Source486: %{name}-aarch64-automotive-rhel.config Source487: %{name}-aarch64-automotive-debug-rhel.config Source488: %{name}-x86_64-automotive-rhel.config Source489: %{name}-x86_64-automotive-debug-rhel.config %endif %endif # Sources for kernel-tools Source2002: kvm_stat.logrotate # Sources for kernel-kmap-internal Source2100: kmap.py # Some people enjoy building customized kernels from the dist-git in Fedora and # use this to override configuration options. One day they may all use the # source tree, but in the mean time we carry this to support the legacy workflow Source3000: merge.py Source3001: kernel-local %if %{patchlist_changelog} Source3002: Patchlist.changelog %endif Source4000: README.rst Source4001: rpminspect.yaml Source4002: gating.yaml Source4003: plans.fmf ## Patches needed for building this package %if !%{nopatches} Patch1: patch-%{patchversion}-redhat.patch %endif # empty final patch to facilitate testing of kernel patches Patch999999: linux-kernel-test.patch # END OF PATCH DEFINITIONS %description The %{package_name} meta package # This macro does requires, provides, conflicts, obsoletes for a kernel package. # %%kernel_reqprovconf [-o] # It uses any kernel__conflicts and kernel__obsoletes # macros defined above. # -o: Skips main "Provides" that would satisfy general kernel requirements that # special-purpose kernels shouldn't include. # For example, used for zfcpdump-core to *not* provide kernel-core. (BZ 2027654) # %define kernel_reqprovconf(o) \ %if %{-o:0}%{!-o:1}\ Provides: kernel = %{specversion}-%{pkg_release}\ Provides: %{name} = %{specversion}-%{pkg_release}\ %endif\ Provides: %{name}-%{_target_cpu} = %{specrpmversion}-%{pkg_release}%{uname_suffix %{?1}}\ Provides: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires(pre): %{kernel_prereq}\ Requires(pre): %{initrd_prereq}\ Requires(pre): ((linux-firmware >= 20150904-56.git6ebf5d57) if linux-firmware)\ Recommends: linux-firmware\ Requires(preun): systemd >= 200\ Conflicts: xfsprogs < 4.3.0-1\ Conflicts: xorg-x11-drv-vmmouse < 13.0.99\ %{expand:%%{?kernel%{?1:_%{1}}_conflicts:Conflicts: %%{kernel%{?1:_%{1}}_conflicts}}}\ %{expand:%%{?kernel%{?1:_%{1}}_obsoletes:Obsoletes: %%{kernel%{?1:_%{1}}_obsoletes}}}\ %{expand:%%{?kernel%{?1:_%{1}}_provides:Provides: %%{kernel%{?1:_%{1}}_provides}}}\ # We can't let RPM do the dependencies automatic because it'll then pick up\ # a correct but undesirable perl dependency from the module headers which\ # isn't required for the kernel proper to function\ AutoReq: no\ AutoProv: yes\ %{nil} %package doc Summary: Various documentation bits found in the kernel source Group: Documentation %description doc This package contains documentation files from the kernel source. Various bits of information about the Linux kernel and the device drivers shipped with it are documented in these files. You'll want to install this package if you need a reference to the options that can be passed to Linux kernel modules at load time. %if %{with_headers} %package headers Summary: Header files for the Linux kernel for use by glibc Obsoletes: glibc-kernheaders < 3.0-46 Provides: glibc-kernheaders = 3.0-46 %if 0%{?gemini} Provides: %{name}-headers = %{specversion}-%{release} Obsoletes: kernel-headers < %{specversion} %endif %description headers Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. %endif %if %{with_cross_headers} %package cross-headers Summary: Header files for the Linux kernel for use by cross-glibc %if 0%{?gemini} Provides: %{name}-cross-headers = %{specversion}-%{release} Obsoletes: kernel-cross-headers < %{specversion} %endif %description cross-headers Kernel-cross-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the cross-glibc package. %endif %package debuginfo-common-%{_target_cpu} Summary: Kernel source files used by %{name}-debuginfo packages Provides: installonlypkg(kernel) %description debuginfo-common-%{_target_cpu} This package is required by %{name}-debuginfo subpackages. It provides the kernel source files common to all builds. %if %{with_perf} %package -n perf %if 0%{gemini} Epoch: %{gemini} %endif Summary: Performance monitoring for the Linux kernel Requires: bzip2 %description -n perf This package contains the perf tool, which enables performance monitoring of the Linux kernel. %package -n perf-debuginfo %if 0%{gemini} Epoch: %{gemini} %endif Summary: Debug information for package perf Requires: %{name}-debuginfo-common-%{_target_cpu} = %{specrpmversion}-%{release} AutoReqProv: no %description -n perf-debuginfo This package provides debug information for the perf package. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_bindir}/perf(\.debug)?|.*%%{_libexecdir}/perf-core/.*|.*%%{_libdir}/libperf-jvmti.so(\.debug)?|XXX' -o perf-debuginfo.list} %package -n python3-perf %if 0%{gemini} Epoch: %{gemini} %endif Summary: Python bindings for apps which will manipulate perf events %description -n python3-perf The python3-perf package contains a module that permits applications written in the Python programming language to use the interface to manipulate perf events. %package -n python3-perf-debuginfo %if 0%{gemini} Epoch: %{gemini} %endif Summary: Debug information for package perf python bindings Requires: %{name}-debuginfo-common-%{_target_cpu} = %{specrpmversion}-%{release} AutoReqProv: no %description -n python3-perf-debuginfo This package provides debug information for the perf python bindings. # the python_sitearch macro should already be defined from above %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{python3_sitearch}/perf.*so(\.debug)?|XXX' -o python3-perf-debuginfo.list} # with_perf %endif %if %{with_libperf} %package -n libperf Summary: The perf library from kernel source %description -n libperf This package contains the kernel source perf library. %package -n libperf-devel Summary: Developement files for the perf library from kernel source Requires: libperf = %{version}-%{release} %description -n libperf-devel This package includes libraries and header files needed for development of applications which use perf library from kernel source. %package -n libperf-debuginfo Summary: Debug information for package libperf Group: Development/Debug Requires: %{name}-debuginfo-common-%{_target_cpu} = %{version}-%{release} AutoReqProv: no %description -n libperf-debuginfo This package provides debug information for the libperf package. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_libdir}/libperf.so.*(\.debug)?|XXX' -o libperf-debuginfo.list} # with_libperf %endif %if %{with_tools} %package -n %{package_name}-tools Summary: Assortment of tools for the Linux kernel %ifarch %{cpupowerarchs} Provides: cpupowerutils = 1:009-0.6.p1 Obsoletes: cpupowerutils < 1:009-0.6.p1 Provides: cpufreq-utils = 1:009-0.6.p1 Provides: cpufrequtils = 1:009-0.6.p1 Obsoletes: cpufreq-utils < 1:009-0.6.p1 Obsoletes: cpufrequtils < 1:009-0.6.p1 Obsoletes: cpuspeed < 1:1.5-16 Requires: %{package_name}-tools-libs = %{specrpmversion}-%{release} %endif %define __requires_exclude ^%{_bindir}/python %description -n %{package_name}-tools This package contains the tools/ directory from the kernel source and the supporting documentation. %package -n %{package_name}-tools-libs Summary: Libraries for the kernels-tools %description -n %{package_name}-tools-libs This package contains the libraries built from the tools/ directory from the kernel source. %package -n %{package_name}-tools-libs-devel Summary: Assortment of tools for the Linux kernel Requires: %{package_name}-tools = %{version}-%{release} %ifarch %{cpupowerarchs} Provides: cpupowerutils-devel = 1:009-0.6.p1 Obsoletes: cpupowerutils-devel < 1:009-0.6.p1 %endif Requires: %{package_name}-tools-libs = %{version}-%{release} Provides: %{package_name}-tools-devel %description -n %{package_name}-tools-libs-devel This package contains the development files for the tools/ directory from the kernel source. %package -n %{package_name}-tools-debuginfo Summary: Debug information for package %{package_name}-tools Requires: %{name}-debuginfo-common-%{_target_cpu} = %{version}-%{release} AutoReqProv: no %description -n %{package_name}-tools-debuginfo This package provides debug information for package %{package_name}-tools. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_bindir}/bootconfig(\.debug)?|.*%%{_bindir}/centrino-decode(\.debug)?|.*%%{_bindir}/powernow-k8-decode(\.debug)?|.*%%{_bindir}/cpupower(\.debug)?|.*%%{_libdir}/libcpupower.*|.*%%{python3_sitearch}/_raw_pylibcpupower.*|.*%%{_bindir}/turbostat(\.debug)?|.*%%{_bindir}/x86_energy_perf_policy(\.debug)?|.*%%{_bindir}/tmon(\.debug)?|.*%%{_bindir}/lsgpio(\.debug)?|.*%%{_bindir}/gpio-hammer(\.debug)?|.*%%{_bindir}/gpio-event-mon(\.debug)?|.*%%{_bindir}/gpio-watch(\.debug)?|.*%%{_bindir}/iio_event_monitor(\.debug)?|.*%%{_bindir}/iio_generic_buffer(\.debug)?|.*%%{_bindir}/lsiio(\.debug)?|.*%%{_bindir}/intel-speed-select(\.debug)?|.*%%{_bindir}/page_owner_sort(\.debug)?|.*%%{_bindir}/slabinfo(\.debug)?|.*%%{_sbindir}/intel_sdsi(\.debug)?|XXX' -o %{package_name}-tools-debuginfo.list} %package -n rtla %if 0%{gemini} Epoch: %{gemini} %endif Summary: Real-Time Linux Analysis tools Requires: libtraceevent Requires: libtracefs Requires: libbpf %ifarch %{cpupowerarchs} Requires: %{package_name}-tools-libs = %{version}-%{release} %endif %description -n rtla The rtla meta-tool includes a set of commands that aims to analyze the real-time properties of Linux. Instead of testing Linux as a black box, rtla leverages kernel tracing capabilities to provide precise information about the properties and root causes of unexpected results. %if %{with_debuginfo} %package -n rtla-debuginfo %if 0%{gemini} Epoch: %{gemini} %endif Summary: Debug information for package rtla Requires: %{name}-debuginfo-common-%{_target_cpu} = %{version}-%{release} AutoReqProv: no %description -n rtla-debuginfo This package provides debug information for the rtla package. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_bindir}/rtla(\.debug)?|.*%%{_bindir}/hwnoise(\.debug)?|.*%%{_bindir}/osnoise(\.debug)?|.*%%{_bindir}/timerlat(\.debug)?|XXX' -o rtla-debuginfo.list} %endif %package -n rv %if 0%{gemini} Epoch: %{gemini} %endif Summary: RV: Runtime Verification %description -n rv Runtime Verification (RV) is a lightweight (yet rigorous) method that complements classical exhaustive verification techniques (such as model checking and theorem proving) with a more practical approach for complex systems. The rv tool is the interface for a collection of monitors that aim to analyze the logical and timing behavior of Linux. %if %{with_debuginfo} %package -n rv-debuginfo %if 0%{gemini} Epoch: %{gemini} %endif Summary: Debug information for package rv Requires: %{name}-debuginfo-common-%{_target_cpu} = %{version}-%{release} AutoReqProv: no %description -n rv-debuginfo This package provides debug information for the rv package. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_bindir}/rv(\.debug)?|XXX' -o rv-debuginfo.list} %endif # with_tools %endif %if %{with_kmap} && %{with_base} %package -n %{name}-kmap-internal Summary: Kernel source-to-module mapping data and module list Group: Development/System BuildRequires: python3 %description -n %{name}-kmap-internal The %{name}-kmap-internal package contains a JSON mapping file that describes which C source files contributed to each kernel module and to the built-in vmlinux image, and which RPM package each module is shipped in. Files installed under /usr/share/%{name}-kmap-internal/: kernel-map-.json - unified mapping file for all kernel variants containing: - variants: list of variant names (e.g., ["stock", "rt", "automotive"]) - source-map: source file mappings - obj-src: maps kernel objects to source files with variant indices - src-obj: maps source files to kernel objects with variant indices - module-map: module to RPM mappings - module-rpm: maps module names to RPM package names with variant indices - rpm-modules: maps RPM package names to module names with variant indices %endif %if %{with_selftests} %package selftests-internal Summary: Kernel samples and selftests Requires: binutils, bpftool, iproute-tc, nmap-ncat, python3, fuse-libs, keyutils Provides: %{name}-selftests-internal-present %description selftests-internal Kernel sample programs and selftests. # Note that this pattern only works right to match the .build-id # symlinks because of the trailing nonmatching alternation and # the leading .*, because of find-debuginfo.sh's buggy handling # of matching the pattern against the symlinks file. %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_libexecdir}/(ksamples|kselftests)/.*|XXX' -o selftests-debuginfo.list} %define __requires_exclude ^liburandom_read.so.*$ # with_selftests %endif %define kernel_gcov_package() \ %package %{?1:%{1}-}gcov\ Summary: gcov graph and source files for coverage data collection.\ %description %{?1:%{1}-}gcov\ %{?1:%{1}-}gcov includes the gcov graph and source files for gcov coverage collection.\ %{nil} %if %{with_kernel_abi_stablelists} %package -n %{package_name}-abi-stablelists Summary: The Red Hat Enterprise Linux kernel ABI symbol stablelists AutoReqProv: no %description -n %{package_name}-abi-stablelists The kABI package contains information pertaining to the Red Hat Enterprise Linux kernel ABI, including lists of kernel symbols that are needed by external Linux kernel modules, and a yum plugin to aid enforcement. %endif %if %{with_kabidw_base} %package kernel-kabidw-base-internal Summary: The baseline dataset for kABI verification using DWARF data Group: System Environment/Kernel AutoReqProv: no %description kernel-kabidw-base-internal The package contains data describing the current ABI of the Red Hat Enterprise Linux kernel, suitable for the kabi-dw tool. %endif # # This macro creates a kernel--debuginfo package. # %%kernel_debuginfo_package # # Explanation of the find_debuginfo_opts: We build multiple kernels (debug, # rt, 64k etc.) so the regex filters those kernels appropriately. We also # have to package several binaries as part of kernel-devel but getting # unique build-ids is tricky for these userspace binaries. We don't really # care about debugging those so we just filter those out and remove it. %define kernel_debuginfo_package() \ %package %{?1:%{1}-}debuginfo\ Summary: Debug information for package %{name}%{?1:-%{1}}\ Requires: %{name}-debuginfo-common-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-debuginfo-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: installonlypkg(kernel)\ AutoReqProv: no\ %description %{?1:%{1}-}debuginfo\ This package provides debug information for package %{name}%{?1:-%{1}}.\ This is required to use SystemTap with %{name}%{?1:-%{1}}-%{KVERREL}.\ %{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} --keep-section '.BTF' -p '.*\/usr\/src\/kernels/.*|XXX' -o ignored-debuginfo.list -p '/.*/%%{KVERREL_RE}%{?1:[+]%{1}}/.*|/.*%%{KVERREL_RE}%{?1:\+%{1}}(\.debug)?' -o debuginfo%{?1}.list}\ %{nil} # # This macro creates a kernel--devel package. # %%kernel_devel_package [-m] # %define kernel_devel_package(m) \ %package %{?1:%{1}-}devel\ Summary: Development package for building kernel modules to match the %{?2:%{2} }kernel\ Provides: %{name}%{?1:-%{1}}-devel-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}-devel-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: kernel-devel-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Provides: %{name}-devel-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel)\ AutoReqProv: no\ Requires(pre): findutils\ Requires: findutils\ Requires: perl-interpreter\ Requires: openssl-devel\ Requires: elfutils-libelf-devel\ Requires: bison\ Requires: flex\ Requires: make\ Requires: gcc\ %if %{-m:1}%{!-m:0}\ Requires: %{name}-devel-uname-r = %{KVERREL}%{uname_variant %{?1}}\ %endif\ %description %{?1:%{1}-}devel\ This package provides kernel headers and makefiles sufficient to build modules\ against the %{?2:%{2} }kernel package.\ %{nil} # # This macro creates an empty kernel--devel-matched package that # requires both the core and devel packages locked on the same version. # %%kernel_devel_matched_package [-m] # %define kernel_devel_matched_package(m) \ %package %{?1:%{1}-}devel-matched\ Summary: Meta package to install matching core and devel packages for a given %{?2:%{2} }kernel\ Requires: %{package_name}%{?1:-%{1}}-devel = %{specrpmversion}-%{release}\ Requires: %{package_name}%{?1:-%{1}}-core = %{specrpmversion}-%{release}\ %description %{?1:%{1}-}devel-matched\ This meta package is used to install matching core and devel packages for a given %{?2:%{2} }kernel.\ %{nil} %define kernel_modules_extra_matched_package(m) \ %package modules-extra-matched\ Summary: Meta package which requires modules-extra to be installed for all kernels.\ %description modules-extra-matched\ This meta package provides a single reference that other packages can Require to have modules-extra installed for all kernels.\ %{nil} # # This macro creates a kernel--modules-internal package. # %%kernel_modules_internal_package # %define kernel_modules_internal_package() \ %package %{?1:%{1}-}modules-internal\ Summary: Extra kernel modules to match the %{?2:%{2} }kernel\ Group: System Environment/Kernel\ Provides: %{name}%{?1:-%{1}}-modules-internal-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-modules-internal-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: %{name}%{?1:-%{1}}-modules-internal = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel-module)\ Provides: %{name}%{?1:-%{1}}-modules-internal-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Supplements: (%{name}-selftests-internal-present and %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}})\ AutoReq: no\ AutoProv: yes\ %description %{?1:%{1}-}modules-internal\ This package provides kernel modules for the %{?2:%{2} }kernel package for Red Hat internal usage.\ %{nil} # # This macro creates a kernel--modules-extra package. # %%kernel_modules_extra_package [-m] # %define kernel_modules_extra_package(m) \ %package %{?1:%{1}-}modules-extra\ Summary: Extra kernel modules to match the %{?2:%{2} }kernel\ Provides: %{name}%{?1:-%{1}}-modules-extra-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-modules-extra-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: %{name}%{?1:-%{1}}-modules-extra = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel-module)\ Provides: %{name}%{?1:-%{1}}-modules-extra-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ %if %{-m:1}%{!-m:0}\ Requires: %{name}-modules-extra-uname-r = %{KVERREL}%{uname_variant %{?1}}\ %endif\ AutoReq: no\ AutoProv: yes\ %description %{?1:%{1}-}modules-extra\ This package provides less commonly used kernel modules for the %{?2:%{2} }kernel package.\ %{nil} # # This macro creates a kernel--modules package. # %%kernel_modules_package [-m] # %define kernel_modules_package(m) \ %package %{?1:%{1}-}modules\ Summary: kernel modules to match the %{?2:%{2}-}core kernel\ Provides: %{name}%{?1:-%{1}}-modules-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-modules-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: %{name}%{?1:-%{1}}-modules = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel-module)\ Provides: %{name}%{?1:-%{1}}-modules-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ %if %{-m:1}%{!-m:0}\ Requires: %{name}-modules-uname-r = %{KVERREL}%{uname_variant %{?1}}\ %endif\ AutoReq: no\ AutoProv: yes\ %description %{?1:%{1}-}modules\ This package provides commonly used kernel modules for the %{?2:%{2}-}core kernel package.\ %{nil} # # This macro creates a kernel--modules-core package. # %%kernel_modules_core_package [-m] # %define kernel_modules_core_package(m) \ %package %{?1:%{1}-}modules-core\ Summary: Core kernel modules to match the %{?2:%{2}-}core kernel\ Provides: %{name}%{?1:-%{1}}-modules-core-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-modules-core-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: %{name}%{?1:-%{1}}-modules-core = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel-module)\ Provides: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ %if %{-m:1}%{!-m:0}\ Requires: %{name}-modules-core-uname-r = %{KVERREL}%{uname_variant %{?1}}\ %endif\ AutoReq: no\ AutoProv: yes\ %description %{?1:%{1}-}modules-core\ This package provides essential kernel modules for the %{?2:%{2}-}core kernel package.\ %{nil} # # this macro creates a kernel- meta package. # %%kernel_meta_package # %define kernel_meta_package() \ %package %{1}\ summary: kernel meta-package for the %{1} kernel\ Requires: %{name}-%{1}-core-uname-r = %{KVERREL}%{uname_suffix %{1}}\ Requires: %{name}-%{1}-modules-uname-r = %{KVERREL}%{uname_suffix %{1}}\ Requires: %{name}-%{1}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{1}}\ Requires: ((%{name}-%{1}-modules-extra-uname-r = %{KVERREL}%{uname_suffix %{1}}) if %{name}-modules-extra-matched)\ %if "%{1}" == "rt" || "%{1}" == "rt-debug" || "%{1}" == "rt-64k" || "%{1}" == "rt-64k-debug"\ Requires: realtime-setup\ %endif\ Provides: installonlypkg(kernel)\ %description %{1}\ The meta-package for the %{1} kernel\ %{nil} # # This macro creates a kernel- and its -devel and -debuginfo too. # %%define variant_summary The Linux kernel compiled for # %%kernel_variant_package [-n ] [-m] [-o] # -m: Used with debugbuildsenabled==0 to create a "meta" debug variant that # depends on base variant and skips debug/internal/partner packages. # -o: Skips main "Provides" that would satisfy general kernel requirements that # special-purpose kernels shouldn't include. # %define kernel_variant_package(n:mo) \ %package %{?1:%{1}-}core\ Summary: %{variant_summary}\ Provides: %{name}-%{?1:%{1}-}core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel)\ %if %{-m:1}%{!-m:0}\ Requires: %{name}-core-uname-r = %{KVERREL}%{uname_variant %{?1}}\ Requires: %{name}-%{?1:%{1}-}-modules-core-uname-r = %{KVERREL}%{uname_variant %{?1}}\ %endif\ %{expand:%%kernel_reqprovconf %{?1:%{1}} %{-o:%{-o}}}\ %if %{?1:1} %{!?1:0} \ %{expand:%%kernel_meta_package %{?1:%{1}}}\ %endif\ %{expand:%%kernel_devel_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}} %{-m:%{-m}}}\ %{expand:%%kernel_devel_matched_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}} %{-m:%{-m}}}\ %{expand:%%kernel_modules_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}} %{-m:%{-m}}}\ %{expand:%%kernel_modules_core_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}} %{-m:%{-m}}}\ %{expand:%%kernel_modules_extra_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}} %{-m:%{-m}}}\ %if %{-m:0}%{!-m:1}\ %{expand:%%kernel_modules_internal_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}}}\ %if 0%{!?fedora:1}\ %{expand:%%kernel_modules_partner_package %{?1:%{1}} %{!?{-n}:%{1}}%{?{-n}:%{-n*}}}\ %endif\ %{expand:%%kernel_debuginfo_package %{?1:%{1}}}\ %endif\ %if %{with_efiuki} && ("%{1}" != "rt" && "%{1}" != "rt-debug" && "%{1}" != "rt-64k" && "%{1}" != "rt-64k-debug")\ %package %{?1:%{1}-}uki-virt\ Summary: %{variant_summary} unified kernel image for virtual machines\ Provides: installonlypkg(kernel)\ Provides: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires(pre): %{kernel_prereq}\ Requires(pre): systemd >= 254-1\ %package %{?1:%{1}-}uki-virt-addons\ Summary: %{variant_summary} unified kernel image addons for virtual machines\ Provides: installonlypkg(kernel)\ Requires: %{name}%{?1:-%{1}}-uki-virt = %{specrpmversion}-%{release}\ Requires(pre): systemd >= 254-1\ %endif\ %if %{with_gcov}\ %{expand:%%kernel_gcov_package %{?1:%{1}}}\ %endif\ %{nil} # # This macro creates a kernel--modules-partner package. # %%kernel_modules_partner_package # %define kernel_modules_partner_package() \ %package %{?1:%{1}-}modules-partner\ Summary: Extra kernel modules to match the %{?2:%{2} }kernel\ Group: System Environment/Kernel\ Provides: %{name}%{?1:-%{1}}-modules-partner-%{_target_cpu} = %{specrpmversion}-%{release}\ Provides: %{name}%{?1:-%{1}}-modules-partner-%{_target_cpu} = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: %{name}%{?1:-%{1}}-modules-partner = %{specrpmversion}-%{release}%{uname_suffix %{?1}}\ Provides: installonlypkg(kernel-module)\ Provides: %{name}%{?1:-%{1}}-modules-partner-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ AutoReq: no\ AutoProv: yes\ %description %{?1:%{1}-}modules-partner\ This package provides kernel modules for the %{?2:%{2} }kernel package for Red Hat partners usage.\ %{nil} # Now, each variant package. %if %{with_zfcpdump} %define variant_summary The Linux kernel compiled for zfcpdump usage %kernel_variant_package -o zfcpdump %description zfcpdump-core The kernel package contains the Linux kernel (vmlinuz) for use by the zfcpdump infrastructure. # with_zfcpdump %endif %if %{with_arm64_16k_base} %define variant_summary The Linux kernel compiled for 16k pagesize usage %kernel_variant_package 16k %description 16k-core The kernel package contains a variant of the ARM64 Linux kernel using a 16K page size. %endif %if %{with_arm64_16k} && %{with_debug} %define variant_summary The Linux kernel compiled with extra debugging enabled %if !%{debugbuildsenabled} %kernel_variant_package -m 16k-debug %else %kernel_variant_package 16k-debug %endif %description 16k-debug-core The debug kernel package contains a variant of the ARM64 Linux kernel using a 16K page size. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_arm64_64k_base} %define variant_summary The Linux kernel compiled for 64k pagesize usage %kernel_variant_package 64k %description 64k-core The kernel package contains a variant of the ARM64 Linux kernel using a 64K page size. %endif %if %{with_arm64_64k} && %{with_debug} %define variant_summary The Linux kernel compiled with extra debugging enabled %if !%{debugbuildsenabled} %kernel_variant_package -m 64k-debug %else %kernel_variant_package 64k-debug %endif %description 64k-debug-core The debug kernel package contains a variant of the ARM64 Linux kernel using a 64K page size. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_debug} && %{with_realtime} %define variant_summary The Linux PREEMPT_RT kernel compiled with extra debugging enabled %kernel_variant_package rt-debug %description rt-debug-core The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_realtime_base} %define variant_summary The Linux kernel compiled with PREEMPT_RT enabled %kernel_variant_package rt %description rt-core This package includes a version of the Linux kernel compiled with the PREEMPT_RT real-time preemption support %endif %if %{with_realtime_arm64_64k_base} %define variant_summary The Linux PREEMPT_RT kernel compiled for 64k pagesize usage %kernel_variant_package rt-64k %description rt-64k-core The kernel package contains a variant of the ARM64 Linux PREEMPT_RT kernel using a 64K page size. %endif %if %{with_realtime_arm64_64k} && %{with_debug} %define variant_summary The Linux PREEMPT_RT kernel compiled with extra debugging enabled %if !%{debugbuildsenabled} %kernel_variant_package -m rt-64k-debug %else %kernel_variant_package rt-64k-debug %endif %description rt-64k-debug-core The debug kernel package contains a variant of the ARM64 Linux PREEMPT_RT kernel using a 64K page size. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_debug} && %{with_automotive} && !%{with_automotive_build} %define variant_summary The Linux Automotive kernel compiled with extra debugging enabled %kernel_variant_package automotive-debug %description automotive-debug-core The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_automotive_base} %define variant_summary The Linux kernel compiled with PREEMPT_RT enabled %kernel_variant_package automotive %description automotive-core This package includes a version of the Linux kernel compiled with the PREEMPT_RT real-time preemption support, targeted for Automotive platforms %endif %if %{with_up} && %{with_debug} %if !%{debugbuildsenabled} %kernel_variant_package -m debug %else %kernel_variant_package debug %endif %description debug-core The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. This variant of the kernel has numerous debugging options enabled. It should only be installed when trying to gather additional information on kernel bugs, as some of these options impact performance noticably. %endif %if %{with_up_base} # And finally the main -core package %define variant_summary The Linux kernel %kernel_variant_package %description core The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. %endif %if %{with_up} && %{with_debug} && %{with_efiuki} %description debug-uki-virt Prebuilt debug unified kernel image for virtual machines. %description debug-uki-virt-addons Prebuilt debug unified kernel image addons for virtual machines. %endif %if %{with_up_base} && %{with_efiuki} %description uki-virt Prebuilt default unified kernel image for virtual machines. %description uki-virt-addons Prebuilt default unified kernel image addons for virtual machines. %endif %if %{with_arm64_16k} && %{with_debug} && %{with_efiuki} %description 16k-debug-uki-virt Prebuilt 16k debug unified kernel image for virtual machines. %description 16k-debug-uki-virt-addons Prebuilt 16k debug unified kernel image addons for virtual machines. %endif %if %{with_arm64_16k_base} && %{with_efiuki} %description 16k-uki-virt Prebuilt 16k unified kernel image for virtual machines. %description 16k-uki-virt-addons Prebuilt 16k unified kernel image addons for virtual machines. %endif %if %{with_arm64_64k} && %{with_debug} && %{with_efiuki} %description 64k-debug-uki-virt Prebuilt 64k debug unified kernel image for virtual machines. %description 64k-debug-uki-virt-addons Prebuilt 64k debug unified kernel image addons for virtual machines. %endif %if %{with_arm64_64k_base} && %{with_efiuki} %description 64k-uki-virt Prebuilt 64k unified kernel image for virtual machines. %description 64k-uki-virt-addons Prebuilt 64k unified kernel image addons for virtual machines. %endif %ifnarch noarch %{nobuildarches} %kernel_modules_extra_matched_package %endif %define log_msg() \ { set +x; } 2>/dev/null \ _log_msglineno=$(grep -n %{*} %{_specdir}/${RPM_PACKAGE_NAME}.spec | grep log_msg | cut -d":" -f1) \ echo "kernel.spec:${_log_msglineno}: %{*}" \ set -x %prep %{log_msg "Start of prep stage"} %{log_msg "Sanity checks"} # do a few sanity-checks for --with *only builds %if %{with_baseonly} %if !%{with_up} %{log_msg "Cannot build --with baseonly, up build is disabled"} exit 1 %endif %endif %if %{with_automotive} %if 0%{?fedora} %{log_msg "Cannot build automotive with a fedora baseline, must be rhel/centos/eln"} exit 1 %endif %endif # more sanity checking; do it quietly if [ "%{patches}" != "%%{patches}" ] ; then for patch in %{patches} ; do if [ ! -f $patch ] ; then %{log_msg "ERROR: Patch ${patch##/*/} listed in specfile but is missing"} exit 1 fi done fi 2>/dev/null patch_command='git --work-tree=. apply' ApplyPatch() { local patch=$1 shift if [ ! -f $RPM_SOURCE_DIR/$patch ]; then exit 1 fi if ! grep -E "^Patch[0-9]+: $patch\$" %{_specdir}/${RPM_PACKAGE_NAME}.spec ; then if [ "${patch:0:8}" != "patch-%{kversion}." ] ; then %{log_msg "ERROR: Patch $patch not listed as a source patch in specfile"} exit 1 fi fi 2>/dev/null case "$patch" in *.bz2) bunzip2 < "$RPM_SOURCE_DIR/$patch" | $patch_command ${1+"$@"} ;; *.gz) gunzip < "$RPM_SOURCE_DIR/$patch" | $patch_command ${1+"$@"} ;; *.xz) unxz < "$RPM_SOURCE_DIR/$patch" | $patch_command ${1+"$@"} ;; *) $patch_command ${1+"$@"} < "$RPM_SOURCE_DIR/$patch" ;; esac } # don't apply patch if it's empty ApplyOptionalPatch() { local patch=$1 shift %{log_msg "ApplyOptionalPatch: $1"} if [ ! -f $RPM_SOURCE_DIR/$patch ]; then exit 1 fi local C=$(wc -l $RPM_SOURCE_DIR/$patch | awk '{print $1}') if [ "$C" -gt 9 ]; then ApplyPatch $patch ${1+"$@"} fi } %{log_msg "Untar kernel tarball"} %setup -q -n kernel-%{tarfile_release} -c mv linux-%{tarfile_release} linux-%{KVERREL} cd linux-%{KVERREL} cp -a %{SOURCE1} . %{log_msg "Start of patch applications"} %if !%{nopatches} ApplyOptionalPatch patch-%{patchversion}-redhat.patch %endif ApplyOptionalPatch linux-kernel-test.patch %{log_msg "End of patch applications"} # END OF PATCH APPLICATIONS # Any further pre-build tree manipulations happen here. %{log_msg "Pre-build tree manipulations"} chmod +x scripts/checkpatch.pl mv COPYING COPYING-%{specrpmversion}-%{release} # on linux-next prevent scripts/setlocalversion from mucking with our version numbers rm -f localversion-next localversion-rt # Mangle /usr/bin/python shebangs to /usr/bin/python3 # Mangle all Python shebangs to be Python 3 explicitly # -p preserves timestamps # -n prevents creating ~backup files # -i specifies the interpreter for the shebang # This fixes errors such as # *** ERROR: ambiguous python shebang in /usr/bin/kvm_stat: #!/usr/bin/python. Change it to python3 (or python2) explicitly. # We patch all sources below for which we got a report/error. %{log_msg "Fixing Python shebangs..."} %py3_shebang_fix \ tools/kvm/kvm_stat/kvm_stat \ scripts/show_delta \ scripts/diffconfig \ scripts/bloat-o-meter \ scripts/jobserver-exec \ tools \ Documentation \ scripts/clang-tools 2> /dev/null # SBAT data sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE83} > uki.sbat sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE84} > uki-addons.sbat sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE85} > kernel.sbat # only deal with configs if we are going to build for the arch %ifnarch %nobuildarches if [ -L configs ]; then rm -f configs fi mkdir configs cd configs %{log_msg "Copy additional source files into buildroot"} # Drop some necessary files from the source dir into the buildroot cp $RPM_SOURCE_DIR/%{name}-*.config . cp %{SOURCE80} . # merge.py cp %{SOURCE3000} . # kernel-local - rename and copy for partial snippet config process cp %{SOURCE3001} partial-kernel-local-snip.config cp %{SOURCE3001} partial-kernel-local-debug-snip.config FLAVOR=%{primary_target} SPECPACKAGE_NAME=%{name} SPECVERSION=%{specversion} SPECRPMVERSION=%{specrpmversion} ./generate_all_configs.sh %{debugbuildsenabled} # Collect custom defined config options %{log_msg "Collect custom defined config options"} PARTIAL_CONFIGS="" %if %{with_gcov} PARTIAL_CONFIGS="$PARTIAL_CONFIGS %{SOURCE70} %{SOURCE71}" %endif %if %{with toolchain_clang} PARTIAL_CONFIGS="$PARTIAL_CONFIGS %{SOURCE72} %{SOURCE73}" %endif %if %{with clang_lto} PARTIAL_CONFIGS="$PARTIAL_CONFIGS %{SOURCE74} %{SOURCE75} %{SOURCE76} %{SOURCE77}" %endif PARTIAL_CONFIGS="$PARTIAL_CONFIGS partial-kernel-local-snip.config partial-kernel-local-debug-snip.config" GetArch() { case "$1" in *aarch64*) echo "aarch64" ;; *ppc64le*) echo "ppc64le" ;; *s390x*) echo "s390x" ;; *x86_64*) echo "x86_64" ;; *riscv64*) echo "riscv64" ;; # no arch, apply everywhere *) echo "" ;; esac } # Merge in any user-provided local config option changes %{log_msg "Merge in any user-provided local config option changes"} %ifnarch %nobuildarches for i in %{all_configs} do kern_arch="$(GetArch $i)" kern_debug="$(echo $i | grep -q debug && echo "debug" || echo "")" for j in $PARTIAL_CONFIGS do part_arch="$(GetArch $j)" part_debug="$(echo $j | grep -q debug && echo "debug" || echo "")" # empty arch means apply to all arches if [ "$part_arch" == "" -o "$part_arch" == "$kern_arch" ] && [ "$part_debug" == "$kern_debug" ] then mv $i $i.tmp ./merge.py $j $i.tmp > $i fi done rm -f $i.tmp done %if %{with_gcov} %{log_msg "Disabling CONFIG_OBJTOOL_WERROR for gcov build"} for i in %{all_configs} do sed -i "s|CONFIG_OBJTOOL_WERROR=y|# CONFIG_OBJTOOL_WERROR is not set|g" $i done %endif %endif %if %{signkernel}%{signmodules} # Add DUP and kpatch certificates to system trusted keys for RHEL truncate -s0 ../certs/rhel.pem %if 0%{?rhel} %if %{rhelkeys} %{log_msg "Add DUP and kpatch certificates to system trusted keys for RHEL"} openssl x509 -inform der -in %{SOURCE100} -out rheldup3.pem openssl x509 -inform der -in %{SOURCE101} -out rhelkpatch1.pem openssl x509 -inform der -in %{SOURCE102} -out nvidiagpuoot001.pem openssl x509 -inform der -in %{SOURCE107} -out nvidiajetsonsoc.pem openssl x509 -inform der -in %{SOURCE108} -out nvidiabfdpu.pem cat rheldup3.pem rhelkpatch1.pem nvidiagpuoot001.pem nvidiajetsonsoc.pem nvidiabfdpu.pem >> ../certs/rhel.pem # rhelkeys %endif %if %{signkernel} %ifarch s390x ppc64le openssl x509 -inform der -in %{secureboot_ca_0} -out secureboot.pem cat secureboot.pem >> ../certs/rhel.pem %endif %endif # rhel %endif openssl x509 -inform der -in %{ima_ca_cert} -out imaca.pem cat imaca.pem >> ../certs/rhel.pem for i in *.config; do sed -i 's@CONFIG_SYSTEM_TRUSTED_KEYS=""@CONFIG_SYSTEM_TRUSTED_KEYS="certs/rhel.pem"@' $i sed -i 's@CONFIG_EFI_SBAT_FILE=""@CONFIG_EFI_SBAT_FILE="kernel.sbat"@' $i done %endif # Adjust FIPS module name for RHEL %if 0%{?rhel} %{log_msg "Adjust FIPS module name for RHEL"} for i in *.config; do sed -i 's/CONFIG_CRYPTO_FIPS_NAME=.*/CONFIG_CRYPTO_FIPS_NAME="Red Hat Enterprise Linux %{rhel} - Kernel Cryptographic API"/' $i done %endif %{log_msg "Set process_configs.sh $OPTS"} cp %{SOURCE81} . OPTS="" %if %{with_configchecks} OPTS="$OPTS -w -n -c" %endif %if %{with clang_lto} for opt in %{clang_make_opts}; do OPTS="$OPTS -m $opt" done %endif %{log_msg "Generate redhat configs"} RHJOBS=$RPM_BUILD_NCPUS SPECPACKAGE_NAME=%{name} ./process_configs.sh $OPTS %{specrpmversion} # We may want to override files from the primary target in case of building # against a flavour of it (eg. centos not rhel), thus override it here if # necessary update_scripts() { TARGET="$1" for i in "$RPM_SOURCE_DIR"/*."$TARGET"; do NEW=${i%."$TARGET"} cp "$i" "$(basename "$NEW")" done } %{log_msg "Set scripts/SOURCES targets"} update_target=%{primary_target} if [ "%{primary_target}" == "rhel" ]; then : # no-op to avoid empty if-fi error %if 0%{?centos} update_scripts $update_target %{log_msg "Updating scripts/sources to centos version"} update_target=centos %endif fi update_scripts $update_target %endif %{log_msg "End of kernel config"} cd .. # # End of Configs stuff # get rid of unwanted files resulting from patch fuzz find . \( -name "*.orig" -o -name "*~" \) -delete >/dev/null # remove unnecessary SCM files find . -name .gitignore -delete >/dev/null cd .. ### ### build ### %build %{log_msg "Start of build stage"} %{log_msg "General arch build configuration"} rm -rf %{buildroot_unstripped} || true mkdir -p %{buildroot_unstripped} %if %{with_sparse} %define sparse_mflags C=1 %endif cp_vmlinux() { eu-strip --remove-comment -o "$2" "$1" } # Note we need to disable these flags for cross builds because the flags # from redhat-rpm-config assume that host == target so target arch # flags cause issues with the host compiler. %if !%{with_cross} %define build_hostcflags %{?build_cflags} %define build_hostldflags %{?build_ldflags} %endif %define make %{__make} %{?cross_opts} %{?make_opts} HOSTCFLAGS="%{?build_hostcflags}" HOSTLDFLAGS="%{?build_hostldflags}" InitBuildVars() { %{log_msg "InitBuildVars for $1"} %{log_msg "InitBuildVars: Initialize build variables"} # Initialize the kernel .config file and create some variables that are # needed for the actual build process. Variant=$1 # Pick the right kernel config file Config=%{name}-%{specrpmversion}-%{_target_cpu}${Variant:+-${Variant}}.config DevelDir=/usr/src/kernels/%{KVERREL}${Variant:++${Variant}} KernelVer=%{specversion}-%{release}.%{_target_cpu}${Variant:++${Variant}} %{log_msg "InitBuildVars: Update Makefile"} # make sure EXTRAVERSION says what we want it to say # Trim the release if this is a CI build, since KERNELVERSION is limited to 64 characters ShortRel=$(perl -e "print \"%{release}\" =~ s/\.pr\.[0-9A-Fa-f]{32}//r") perl -p -i -e "s/^EXTRAVERSION.*/EXTRAVERSION = -${ShortRel}.%{_target_cpu}${Variant:++${Variant}}/" Makefile # if pre-rc1 devel kernel, must fix up PATCHLEVEL for our versioning scheme # if we are post rc1 this should match anyway so this won't matter perl -p -i -e 's/^PATCHLEVEL.*/PATCHLEVEL = %{patchlevel}/' Makefile %{log_msg "InitBuildVars: Copy files"} %{make} %{?_smp_mflags} mrproper cp configs/$Config .config %if %{signkernel}%{signmodules} cp configs/x509.genkey certs/. %endif %if %{with_debuginfo} == 0 sed -i 's/^\(CONFIG_DEBUG_INFO.*\)=y/# \1 is not set/' .config %endif Arch=`head -1 .config | cut -b 3-` %{log_msg "InitBuildVars: USING ARCH=$Arch"} KCFLAGS="%{?kcflags}" } #Build bootstrap bpftool BuildBpftool(){ export BPFBOOTSTRAP_CFLAGS=$(echo "%{__global_compiler_flags}" | sed -r "s/\-specs=[^\ ]+\/redhat-annobin-cc1//") export BPFBOOTSTRAP_LDFLAGS=$(echo "%{__global_ldflags}" | sed -r "s/\-specs=[^\ ]+\/redhat-annobin-cc1//") CFLAGS="" LDFLAGS="" make EXTRA_CFLAGS="${BPFBOOTSTRAP_CFLAGS}" EXTRA_CXXFLAGS="${BPFBOOTSTRAP_CFLAGS}" EXTRA_LDFLAGS="${BPFBOOTSTRAP_LDFLAGS}" %{?make_opts} %{?clang_make_opts} V=1 -C tools/bpf/bpftool bootstrap } BuildKernel() { %{log_msg "BuildKernel for $4"} MakeTarget=$1 KernelImage=$2 DoVDSO=$3 Variant=$4 InstallName=${5:-vmlinuz} %{log_msg "Setup variables"} DoModules=1 if [ "$Variant" = "zfcpdump" ]; then DoModules=0 fi # When the bootable image is just the ELF kernel, strip it. # We already copy the unstripped file into the debuginfo package. if [ "$KernelImage" = vmlinux ]; then CopyKernel=cp_vmlinux else CopyKernel=cp fi %if %{with_gcov} %{log_msg "Setup build directories"} # Make build directory unique for each variant, so that gcno symlinks # are also unique for each variant. if [ -n "$Variant" ]; then ln -s $(pwd) ../linux-%{KVERREL}-${Variant} fi %{log_msg "GCOV - continuing build in: $(pwd)"} pushd ../linux-%{KVERREL}${Variant:+-${Variant}} pwd > ../kernel${Variant:+-${Variant}}-gcov.list %endif %{log_msg "Calling InitBuildVars for $Variant"} InitBuildVars $Variant %{log_msg "BUILDING A KERNEL FOR ${Variant} %{_target_cpu}..."} %{make} ARCH=$Arch olddefconfig >/dev/null %{log_msg "Setup build-ids"} # This ensures build-ids are unique to allow parallel debuginfo perl -p -i -e "s/^CONFIG_BUILD_SALT.*/CONFIG_BUILD_SALT=\"%{KVERREL}\"/" .config %{make} ARCH=$Arch KCFLAGS="$KCFLAGS" WITH_GCOV="%{?with_gcov}" %{?_smp_mflags} $MakeTarget %{?sparse_mflags} %{?kernel_mflags} if [ $DoModules -eq 1 ]; then %{make} ARCH=$Arch KCFLAGS="$KCFLAGS" WITH_GCOV="%{?with_gcov}" %{?_smp_mflags} modules %{?sparse_mflags} || exit 1 fi %{log_msg "Setup RPM_BUILD_ROOT directories"} mkdir -p $RPM_BUILD_ROOT/%{image_install_path} mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/systemtap %if %{with_debuginfo} mkdir -p $RPM_BUILD_ROOT%{debuginfodir}/%{image_install_path} %endif %ifarch aarch64 riscv64 %{log_msg "Build dtb kernel"} mkdir -p $RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer %{make} ARCH=$Arch dtbs INSTALL_DTBS_PATH=$RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer %{make} ARCH=$Arch dtbs_install INSTALL_DTBS_PATH=$RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer cp -r $RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer $RPM_BUILD_ROOT/lib/modules/$KernelVer/dtb find arch/$Arch/boot/dts -name '*.dtb' -type f -delete %endif %{log_msg "Cleanup temp btf files"} # Remove large intermediate files we no longer need to save space # (-f required for zfcpdump builds that do not enable BTF) rm -f vmlinux.o .tmp_vmlinux.btf %{log_msg "Install files to RPM_BUILD_ROOT"} # Comment out specific config settings that may use resources not available # to the end user so that the packaged config file can be easily reused with # upstream make targets %if %{signkernel}%{signmodules} sed -i -e '/^CONFIG_SYSTEM_TRUSTED_KEYS/{ i\# The kernel was built with s/^/# / a\# We are resetting this value to facilitate local builds a\CONFIG_SYSTEM_TRUSTED_KEYS="" }' .config %endif # Start installing the results install -m 644 .config $RPM_BUILD_ROOT/boot/config-$KernelVer install -m 644 .config $RPM_BUILD_ROOT/lib/modules/$KernelVer/config install -m 644 System.map $RPM_BUILD_ROOT/boot/System.map-$KernelVer install -m 644 System.map $RPM_BUILD_ROOT/lib/modules/$KernelVer/System.map %{log_msg "Create initrfamfs"} # We estimate the size of the initramfs because rpm needs to take this size # into consideration when performing disk space calculations. (See bz #530778) dd if=/dev/zero of=$RPM_BUILD_ROOT/boot/initramfs-$KernelVer.img bs=1M count=20 if [ -f arch/$Arch/boot/zImage.stub ]; then %{log_msg "Copy zImage.stub to RPM_BUILD_ROOT"} cp arch/$Arch/boot/zImage.stub $RPM_BUILD_ROOT/%{image_install_path}/zImage.stub-$KernelVer || : cp arch/$Arch/boot/zImage.stub $RPM_BUILD_ROOT/lib/modules/$KernelVer/zImage.stub-$KernelVer || : fi %if %{with_efiuki} # Preserve unsigned kernel for the UKI cp $KernelImage $KernelImage.unsigned %endif %if %{signkernel} %{log_msg "Copy kernel for signing"} if [ "$KernelImage" = vmlinux ]; then # We can't strip and sign $KernelImage in place, because # we need to preserve original vmlinux for debuginfo. # Use a copy for signing. $CopyKernel $KernelImage $KernelImage.tosign KernelImage=$KernelImage.tosign CopyKernel=cp fi SignImage=$KernelImage get_pesign_name() { # If it's a symlink, resolve it to get the pesign cert name # e.g. secureboot-kernel-x86_64.cer -> redhatsecureboot801.cer if [ -L "$1" ]; then basename "$(readlink "$1")" .cer return fi local fname fname=$(basename "$1") # If it's a regular file with a generic name (secureboot-*), # find a pesign-named cert with matching content in the same dir # e.g. secureboot-kernel-x86_64.cer has same md5 as centossecureboot801.cer # e.g. centos-sb-certs-10.0-23.el10.noarch.rpm doesn't have symlinks if [[ "$fname" == secureboot-* ]]; then local dir mysum match dir=$(dirname "$1") mysum=$(md5sum "$1" | awk '{print $1}') match=$(md5sum "$dir"/*.cer 2>/dev/null \ | grep -v 'secureboot-' \ | awk -v s="$mysum" '$1 == s {print $2; exit}') if [ -n "$match" ]; then basename "$match" .cer return fi fi # Fallback: use the filename as-is basename "$1" .cer } pesign_name_0=$(get_pesign_name %{secureboot_key_0}) %{log_msg "kernel signing: secureboot_key_0=%{secureboot_key_0} pesign_name_0=$pesign_name_0"} %ifarch x86_64 aarch64 %{log_msg "Sign kernel image"} %pesign -s -i $SignImage -o vmlinuz.signed -a %{secureboot_ca_0} -c %{secureboot_key_0} -n $pesign_name_0 %endif %ifarch s390x ppc64le if [ -x /usr/bin/rpm-sign ]; then rpm-sign --key "$pesign_name_0" --lkmsign $SignImage --output vmlinuz.signed elif [ "$DoModules" == "1" -a "%{signmodules}" == "1" ]; then chmod +x scripts/sign-file ./scripts/sign-file -p sha256 certs/signing_key.pem certs/signing_key.x509 $SignImage vmlinuz.signed else mv $SignImage vmlinuz.signed fi %endif if [ ! -s vmlinuz.signed ]; then %{log_msg "pesigning failed"} exit 1 fi mv vmlinuz.signed $SignImage # signkernel %endif %{log_msg "copy signed kernel"} $CopyKernel $KernelImage \ $RPM_BUILD_ROOT/%{image_install_path}/$InstallName-$KernelVer chmod 755 $RPM_BUILD_ROOT/%{image_install_path}/$InstallName-$KernelVer cp $RPM_BUILD_ROOT/%{image_install_path}/$InstallName-$KernelVer $RPM_BUILD_ROOT/lib/modules/$KernelVer/$InstallName # hmac sign the kernel for FIPS %{log_msg "hmac sign the kernel for FIPS"} %{log_msg "Creating hmac file: $RPM_BUILD_ROOT/%{image_install_path}/.vmlinuz-$KernelVer.hmac"} ls -l $RPM_BUILD_ROOT/%{image_install_path}/$InstallName-$KernelVer (cd $RPM_BUILD_ROOT/%{image_install_path} && sha512hmac $InstallName-$KernelVer) > $RPM_BUILD_ROOT/%{image_install_path}/.vmlinuz-$KernelVer.hmac; cp $RPM_BUILD_ROOT/%{image_install_path}/.vmlinuz-$KernelVer.hmac $RPM_BUILD_ROOT/lib/modules/$KernelVer/.vmlinuz.hmac if [ $DoModules -eq 1 ]; then %{log_msg "Install modules in RPM_BUILD_ROOT"} # Override $(mod-fw) because we don't want it to install any firmware # we'll get it from the linux-firmware package and we don't want conflicts %{make} %{?_smp_mflags} ARCH=$Arch INSTALL_MOD_PATH=$RPM_BUILD_ROOT %{?_smp_mflags} modules_install KERNELRELEASE=$KernelVer mod-fw= fi %if %{with_gcov} %{log_msg "install gcov-needed files to $BUILDROOT/$BUILD/"} # install gcov-needed files to $BUILDROOT/$BUILD/...: # gcov_info->filename is absolute path # gcno references to sources can use absolute paths (e.g. in out-of-tree builds) # sysfs symlink targets (set up at compile time) use absolute paths to BUILD dir find . \( -name '*.gcno' -o -name '*.[chS]' \) -exec install -D '{}' "$RPM_BUILD_ROOT/$(pwd)/{}" \; %endif %{log_msg "Add VDSO files"} # add an a noop %%defattr statement 'cause rpm doesn't like empty file list files echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-ldsoconf.list if [ $DoVDSO -ne 0 ]; then %{make} ARCH=$Arch INSTALL_MOD_PATH=$RPM_BUILD_ROOT vdso_install KERNELRELEASE=$KernelVer if [ -s ldconfig-kernel.conf ]; then install -D -m 444 ldconfig-kernel.conf \ $RPM_BUILD_ROOT/etc/ld.so.conf.d/kernel-$KernelVer.conf echo /etc/ld.so.conf.d/kernel-$KernelVer.conf >> ../kernel${Variant:+-${Variant}}-ldsoconf.list fi rm -rf $RPM_BUILD_ROOT/lib/modules/$KernelVer/vdso/.build-id fi %{log_msg "Save headers/makefiles, etc. for kernel-headers"} # And save the headers/makefiles etc for building modules against # # This all looks scary, but the end result is supposed to be: # * all arch relevant include/ files # * all Makefile/Kconfig files # * all script/ files rm -f $RPM_BUILD_ROOT/lib/modules/$KernelVer/build rm -f $RPM_BUILD_ROOT/lib/modules/$KernelVer/source mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/build (cd $RPM_BUILD_ROOT/lib/modules/$KernelVer ; ln -s build source) # dirs for additional modules per module-init-tools, kbuild/modules.txt mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/updates mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/weak-updates # CONFIG_KERNEL_HEADER_TEST generates some extra files in the process of # testing so just delete find . -name *.h.s -delete # first copy everything cp --parents `find -type f -name "Makefile*" -o -name "Kconfig*"` $RPM_BUILD_ROOT/lib/modules/$KernelVer/build if [ ! -e Module.symvers ]; then touch Module.symvers fi cp Module.symvers $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp System.map $RPM_BUILD_ROOT/lib/modules/$KernelVer/build if [ -s Module.markers ]; then cp Module.markers $RPM_BUILD_ROOT/lib/modules/$KernelVer/build fi # create the kABI metadata for use in packaging # NOTENOTE: the name symvers is used by the rpm backend # NOTENOTE: to discover and run the /usr/lib/rpm/fileattrs/kabi.attr # NOTENOTE: script which dynamically adds exported kernel symbol # NOTENOTE: checksums to the rpm metadata provides list. # NOTENOTE: if you change the symvers name, update the backend too %{log_msg "GENERATING kernel ABI metadata"} %compression --stdout %compression_flags < Module.symvers > $RPM_BUILD_ROOT/boot/symvers-$KernelVer.%compext cp $RPM_BUILD_ROOT/boot/symvers-$KernelVer.%compext $RPM_BUILD_ROOT/lib/modules/$KernelVer/symvers.%compext %if %{with_kabichk} %{log_msg "kABI checking is enabled in kernel SPEC file."} chmod 0755 $RPM_SOURCE_DIR/check-kabi if [ -e $RPM_SOURCE_DIR/Module.kabi_%{_target_cpu}$Variant ]; then cp $RPM_SOURCE_DIR/Module.kabi_%{_target_cpu}$Variant $RPM_BUILD_ROOT/Module.kabi $RPM_SOURCE_DIR/check-kabi -k $RPM_BUILD_ROOT/Module.kabi -s Module.symvers || exit 1 # for now, don't keep it around. rm $RPM_BUILD_ROOT/Module.kabi else %{log_msg "NOTE: Cannot find reference Module.kabi file."} fi %endif %if %{with_kabidupchk} %{log_msg "kABI DUP checking is enabled in kernel SPEC file."} if [ -e $RPM_SOURCE_DIR/Module.kabi_dup_%{_target_cpu}$Variant ]; then cp $RPM_SOURCE_DIR/Module.kabi_dup_%{_target_cpu}$Variant $RPM_BUILD_ROOT/Module.kabi $RPM_SOURCE_DIR/check-kabi -k $RPM_BUILD_ROOT/Module.kabi -s Module.symvers || exit 1 # for now, don't keep it around. rm $RPM_BUILD_ROOT/Module.kabi else %{log_msg "NOTE: Cannot find DUP reference Module.kabi file."} fi %endif %if %{with_kabidw_base} # Don't build kabi base for debug kernels if [ "$Variant" != "zfcpdump" -a "$Variant" != "debug" ]; then mkdir -p $RPM_BUILD_ROOT/kabi-dwarf tar -xvf %{SOURCE301} -C $RPM_BUILD_ROOT/kabi-dwarf mkdir -p $RPM_BUILD_ROOT/kabi-dwarf/stablelists tar -xvf %{SOURCE300} -C $RPM_BUILD_ROOT/kabi-dwarf/stablelists %{log_msg "GENERATING DWARF-based kABI baseline dataset"} chmod 0755 $RPM_BUILD_ROOT/kabi-dwarf/run_kabi-dw.sh $RPM_BUILD_ROOT/kabi-dwarf/run_kabi-dw.sh generate \ "$RPM_BUILD_ROOT/kabi-dwarf/stablelists/kabi-current/kabi_stablelist_%{_target_cpu}" \ "$(pwd)" \ "$RPM_BUILD_ROOT/kabidw-base/%{_target_cpu}${Variant:+.${Variant}}" || : rm -rf $RPM_BUILD_ROOT/kabi-dwarf fi %endif %if %{with_kabidwchk} if [ "$Variant" != "zfcpdump" ]; then mkdir -p $RPM_BUILD_ROOT/kabi-dwarf tar -xvf %{SOURCE301} -C $RPM_BUILD_ROOT/kabi-dwarf if [ -d "$RPM_BUILD_ROOT/kabi-dwarf/base/%{_target_cpu}${Variant:+.${Variant}}" ]; then mkdir -p $RPM_BUILD_ROOT/kabi-dwarf/stablelists tar -xvf %{SOURCE300} -C $RPM_BUILD_ROOT/kabi-dwarf/stablelists %{log_msg "GENERATING DWARF-based kABI dataset"} chmod 0755 $RPM_BUILD_ROOT/kabi-dwarf/run_kabi-dw.sh $RPM_BUILD_ROOT/kabi-dwarf/run_kabi-dw.sh generate \ "$RPM_BUILD_ROOT/kabi-dwarf/stablelists/kabi-current/kabi_stablelist_%{_target_cpu}" \ "$(pwd)" \ "$RPM_BUILD_ROOT/kabi-dwarf/base/%{_target_cpu}${Variant:+.${Variant}}.tmp" || : %{log_msg "kABI DWARF-based comparison report"} $RPM_BUILD_ROOT/kabi-dwarf/run_kabi-dw.sh compare \ "$RPM_BUILD_ROOT/kabi-dwarf/base/%{_target_cpu}${Variant:+.${Variant}}" \ "$RPM_BUILD_ROOT/kabi-dwarf/base/%{_target_cpu}${Variant:+.${Variant}}.tmp" || : %{log_msg "End of kABI DWARF-based comparison report"} else %{log_msg "Baseline dataset for kABI DWARF-BASED comparison report not found"} fi rm -rf $RPM_BUILD_ROOT/kabi-dwarf fi %endif %{log_msg "Cleanup Makefiles/Kconfig files"} # then drop all but the needed Makefiles/Kconfig files rm -rf $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/scripts rm -rf $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/include cp .config $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a scripts $RPM_BUILD_ROOT/lib/modules/$KernelVer/build rm -rf $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/scripts/tracing rm -f $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/scripts/spdxcheck.py %ifarch s390x # CONFIG_EXPOLINE_EXTERN=y produces arch/s390/lib/expoline/expoline.o # which is needed during external module build. %{log_msg "Copy expoline.o"} if [ -f arch/s390/lib/expoline/expoline.o ]; then cp -a --parents arch/s390/lib/expoline/expoline.o $RPM_BUILD_ROOT/lib/modules/$KernelVer/build fi %endif %{log_msg "Copy additional files for make targets"} # Files for 'make scripts' to succeed with kernel-devel. mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/security/selinux/include cp -a --parents security/selinux/include/classmap.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents security/selinux/include/initial_sid_to_string.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/tools/include/tools cp -a --parents tools/include/tools/be_byteshift.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/tools/le_byteshift.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build # Files for 'make prepare' to succeed with kernel-devel. cp -a --parents tools/include/linux/compiler* $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/linux/types.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/build/Build.include $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/build/fixdep.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/objtool/sync-check.sh $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/bpf/resolve_btfids $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents security/selinux/include/policycap_names.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents security/selinux/include/policycap.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/asm $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/asm-generic $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/linux $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/uapi/asm $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/uapi/asm-generic $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/uapi/linux $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/include/vdso $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/scripts/utilities.mak $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/lib/subcmd $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/lib/*.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/objtool/*.[ch] $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/objtool/Build $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/objtool/include/objtool/*.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/lib/bpf $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp --parents tools/lib/bpf/Build $RPM_BUILD_ROOT/lib/modules/$KernelVer/build if [ -f tools/objtool/objtool ]; then cp -a tools/objtool/objtool $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/tools/objtool/ || : fi if [ -f tools/objtool/fixdep ]; then cp -a tools/objtool/fixdep $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/tools/objtool/ || : fi if [ -d arch/$Arch/scripts ]; then cp -a arch/$Arch/scripts $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/arch/%{_arch} || : fi if [ -f arch/$Arch/*lds ]; then cp -a arch/$Arch/*lds $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/arch/%{_arch}/ || : fi if [ -f arch/%{asmarch}/kernel/module.lds ]; then cp -a --parents arch/%{asmarch}/kernel/module.lds $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ fi find $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/scripts \( -iname "*.o" -o -iname "*.cmd" \) -exec rm -f {} + %ifarch ppc64le cp -a --parents arch/powerpc/lib/crtsavres.[So] $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ %endif if [ -d arch/%{asmarch}/include ]; then cp -a --parents arch/%{asmarch}/include $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ fi if [ -d tools/arch/%{asmarch}/include ]; then cp -a --parents tools/arch/%{asmarch}/include $RPM_BUILD_ROOT/lib/modules/$KernelVer/build fi %ifarch aarch64 # arch/arm64/include/asm/xen references arch/arm cp -a --parents arch/arm/include/asm/xen $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ # arch/arm64/include/asm/opcodes.h references arch/arm cp -a --parents arch/arm/include/asm/opcodes.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ %endif cp -a include $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/include # Cross-reference from include/perf/events/sof.h cp -a sound/soc/sof/sof-audio.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/sound/soc/sof %ifarch i686 x86_64 # files for 'make prepare' to succeed with kernel-devel cp -a --parents arch/x86/entry/syscalls/syscall_32.tbl $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/entry/syscalls/syscall_64.tbl $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/tools/relocs_32.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/tools/relocs_64.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/tools/relocs.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/tools/relocs_common.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/tools/relocs.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/purgatory/purgatory.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/purgatory/stack.S $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/purgatory/setup-x86_64.S $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/purgatory/entry64.S $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/boot/string.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/boot/string.c $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents arch/x86/boot/ctype.h $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents scripts/syscalltbl.sh $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents scripts/syscallhdr.sh $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/ cp -a --parents tools/arch/x86/include/asm $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/arch/x86/include/uapi/asm $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/objtool/arch/x86/lib $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/arch/x86/lib/ $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/arch/x86/tools/gen-insn-attr-x86.awk $RPM_BUILD_ROOT/lib/modules/$KernelVer/build cp -a --parents tools/objtool/arch/x86/ $RPM_BUILD_ROOT/lib/modules/$KernelVer/build %endif %{log_msg "Clean up intermediate tools files"} # Clean up intermediate tools files find $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/tools \( -iname "*.o" -o -iname "*.cmd" \) -exec rm -f {} + # Make sure the Makefile, version.h, and auto.conf have a matching # timestamp so that external modules can be built touch -r $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/Makefile \ $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/include/generated/uapi/linux/version.h \ $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/include/config/auto.conf %if %{with_debuginfo} eu-readelf -n vmlinux | grep "Build ID" | awk '{print $NF}' > vmlinux.id cp vmlinux.id $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/vmlinux.id %{log_msg "Copy additional files for kernel-debuginfo rpm"} # # save the vmlinux file for kernel debugging into the kernel-debuginfo rpm # (use mv + symlink instead of cp to reduce disk space requirements) # mkdir -p $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer mv vmlinux $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer ln -s $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer/vmlinux vmlinux if [ -n "%{?vmlinux_decompressor}" ]; then eu-readelf -n %{vmlinux_decompressor} | grep "Build ID" | awk '{print $NF}' > vmlinux.decompressor.id # Without build-id the build will fail. But for s390 the build-id # wasn't added before 5.11. In case it is missing prefer not # packaging the debuginfo over a build failure. if [ -s vmlinux.decompressor.id ]; then cp vmlinux.decompressor.id $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/vmlinux.decompressor.id cp %{vmlinux_decompressor} $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer/vmlinux.decompressor fi fi # build and copy the vmlinux-gdb plugin files into kernel-debuginfo %{make} ARCH=$Arch %{?_smp_mflags} scripts_gdb cp -a --parents scripts/gdb/{,linux/}*.py $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer # this should be a relative symlink (Kbuild creates an absolute one) ln -s scripts/gdb/vmlinux-gdb.py $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer/vmlinux-gdb.py %py_byte_compile %{python3} $RPM_BUILD_ROOT%{debuginfodir}/lib/modules/$KernelVer/scripts/gdb %endif %{log_msg "Create modnames"} find $RPM_BUILD_ROOT/lib/modules/$KernelVer -name "*.ko" -type f >modnames # mark modules executable so that strip-to-file can strip them xargs --no-run-if-empty chmod u+x < modnames # Generate a list of modules for block and networking. %{log_msg "Generate a list of modules for block and networking"} grep -F /drivers/ modnames | xargs --no-run-if-empty nm -upA | sed -n 's,^.*/\([^/]*\.ko\): *U \(.*\)$,\1 \2,p' > drivers.undef collect_modules_list() { sed -r -n -e "s/^([^ ]+) \\.?($2)\$/\\1/p" drivers.undef | LC_ALL=C sort -u > $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.$1 if [ ! -z "$3" ]; then sed -r -e "/^($3)\$/d" -i $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.$1 fi } collect_modules_list networking \ 'register_netdev|ieee80211_register_hw|usbnet_probe|phy_driver_register|rt(l_|2x00)(pci|usb)_probe|register_netdevice' collect_modules_list block \ 'ata_scsi_ioctl|scsi_add_host|scsi_add_host_with_dma|blk_alloc_queue|blk_init_queue|register_mtd_blktrans|scsi_esp_register|scsi_register_device_handler|blk_queue_physical_block_size' 'pktcdvd.ko|dm-mod.ko' collect_modules_list drm \ 'drm_open|drm_init' collect_modules_list modesetting \ 'drm_crtc_init' %{log_msg "detect missing or incorrect license tags"} # detect missing or incorrect license tags ( find $RPM_BUILD_ROOT/lib/modules/$KernelVer -name '*.ko' | xargs /sbin/modinfo -l | \ grep -E -v 'GPL( v2)?$|Dual BSD/GPL$|Dual MPL/GPL$|GPL and additional rights$' ) && exit 1 if [ $DoModules -eq 0 ]; then %{log_msg "Create empty files for RPM packaging"} # Ensure important files/directories exist to let the packaging succeed echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-modules-core.list echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-modules.list echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-modules-extra.list echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-modules-internal.list echo '%%defattr(-,-,-)' > ../kernel${Variant:+-${Variant}}-modules-partner.list mkdir -p $RPM_BUILD_ROOT/lib/modules/$KernelVer/kernel # Add files usually created by make modules, needed to prevent errors # thrown by depmod during package installation touch $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.order touch $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.builtin fi # Copy the System.map file for depmod to use cp System.map $RPM_BUILD_ROOT/. if [[ "$Variant" == "rt" || "$Variant" == "rt-debug" || "$Variant" == "rt-64k" || "$Variant" == "rt-64k-debug" || "$Variant" == "automotive" || "$Variant" == "automotive-debug" ]]; then %{log_msg "Skipping efiuki build"} else %if %{with_efiuki} %if %{signkernel}%{signmodules} # Sign inner vmlinuz with the transient modules signing key to allow kexec KernelUnifiedVmlinuz="$KernelImage.signed.trans" /lib/systemd/systemd-sbsign sign --certificate certs/signing_key.pem --private-key certs/signing_key.pem "$KernelImage.unsigned" --output $KernelUnifiedVmlinuz %else KernelUnifiedVmlinuz="$KernelImage.unsigned" %endif %{log_msg "Setup the EFI UKI kernel"} KernelUnifiedImageDir="$RPM_BUILD_ROOT/lib/modules/$KernelVer" KernelUnifiedImage="$KernelUnifiedImageDir/$InstallName-virt.efi" KernelUnifiedInitrd="$KernelUnifiedImageDir/$InstallName-virt.img" mkdir -p $KernelUnifiedImageDir dracut --conf=%{SOURCE86} \ --confdir=$(mktemp -d) \ --no-hostonly \ --verbose \ --kver "$KernelVer" \ --kmoddir "$RPM_BUILD_ROOT/lib/modules/$KernelVer/" \ --logfile=$(mktemp) \ $KernelUnifiedInitrd ukify build --linux $KernelUnifiedVmlinuz --initrd $KernelUnifiedInitrd \ --sbat @uki.sbat --os-release @/etc/os-release --uname $KernelVer \ --cmdline 'console=tty0 console=ttyS0' --output $KernelUnifiedImage rm -f $KernelUnifiedInitrd KernelAddonsDirOut="$KernelUnifiedImage.extra.d" mkdir -p $KernelAddonsDirOut python3 %{SOURCE151} %{SOURCE152} $KernelAddonsDirOut virt %{primary_target} %{_target_cpu} @uki-addons.sbat %if %{signkernel} %{log_msg "Sign the EFI UKI kernel"} pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0}) %{log_msg "UKI signing: secureboot_key_uki_0=%{secureboot_key_uki_0} pesign_name_uki_0=$pesign_name_uki_0"} %pesign -s -i $KernelUnifiedImage -o $KernelUnifiedImage.signed -a %{secureboot_ca_0} -c %{secureboot_key_uki_0} -n $pesign_name_uki_0 if [ ! -s $KernelUnifiedImage.signed ]; then echo "pesigning failed" exit 1 fi mv $KernelUnifiedImage.signed $KernelUnifiedImage for addon in "$KernelAddonsDirOut"/*; do %pesign -s -i $addon -o $addon.signed -a %{secureboot_ca_0} -c %{secureboot_key_uki_0} -n $pesign_name_uki_0 rm -f $addon mv $addon.signed $addon done %endif # hmac sign the UKI for FIPS KernelUnifiedImageHMAC="$KernelUnifiedImageDir/.$InstallName-virt.efi.hmac" %{log_msg "hmac sign the UKI for FIPS"} %{log_msg "Creating hmac file: $KernelUnifiedImageHMAC"} (cd $KernelUnifiedImageDir && sha512hmac $InstallName-virt.efi) > $KernelUnifiedImageHMAC; # with_efiuki %endif : # in case of empty block fi # "$Variant" == "rt" || "$Variant" == "rt-debug" || "$Variant" == "automotive" || "$Variant" == "automotive-debug" # # Generate the modules files lists # move_kmod_list() { local module_list="$1" local subdir_name="$2" mkdir -p "$RPM_BUILD_ROOT/lib/modules/$KernelVer/$subdir_name" set +x while read -r kmod; do local target_file="$RPM_BUILD_ROOT/lib/modules/$KernelVer/$subdir_name/$kmod" local target_dir="${target_file%/*}" mkdir -p "$target_dir" mv "$RPM_BUILD_ROOT/lib/modules/$KernelVer/kernel/$kmod" "$target_dir" done < <(sed -e 's|^kernel/||' "$module_list") set -x } create_module_file_list() { # subdirectory within /lib/modules/$KernelVer where kmods should go local module_subdir="$1" # kmod list with relative paths produced by filtermods.py local relative_kmod_list="$2" # list with absolute paths to kmods and other files to be included local absolute_file_list="$3" # if 1, this adds also all kmod directories to absolute_file_list local add_all_dirs="$4" local run_mod_deny="$5" if [ "$module_subdir" != "kernel" ]; then # move kmods into subdirs if needed (internal, partner, extra,..) move_kmod_list $relative_kmod_list $module_subdir fi # make kmod paths absolute sed -e 's|^kernel/|/lib/modules/'$KernelVer'/'$module_subdir'/|' $relative_kmod_list > $absolute_file_list if [ "$run_mod_deny" -eq 1 ]; then # run deny-mod script, this adds blacklist-* files to absolute_file_list %{SOURCE20} "$RPM_BUILD_ROOT" lib/modules/$KernelVer $absolute_file_list fi %if %{zipmodules} # deny-mod script works with kmods as they are now (not compressed), # but if they will be we need to add compext to all sed -i %{?zipsed} $absolute_file_list %endif # add also dir for the case when there are no kmods # "kernel" subdir is covered in %files section, skip it here if [ "$module_subdir" != "kernel" ]; then echo "%dir /lib/modules/$KernelVer/$module_subdir" >> $absolute_file_list fi if [ "$add_all_dirs" -eq 1 ]; then (cd $RPM_BUILD_ROOT; find lib/modules/$KernelVer/kernel -mindepth 1 -type d | sort -n) > ../module-dirs.list sed -e 's|^lib|%dir /lib|' ../module-dirs.list >> $absolute_file_list fi } if [ $DoModules -eq 1 ]; then # save modules.dep for debugging cp $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.dep ../ %{log_msg "Create module list files for all kernel variants"} variants_param="" if [[ "$Variant" == "rt" || "$Variant" == "rt-debug" ]]; then variants_param="-r rt" fi if [[ "$Variant" == "rt-64k" || "$Variant" == "rt-64k-debug" ]]; then variants_param="-r rt-64k" fi if [[ "$Variant" == "automotive" || "$Variant" == "automotive-debug" ]]; then variants_param="-r automotive" fi # this creates ../modules-*.list output, where each kmod path is as it # appears in modules.dep (relative to lib/modules/$KernelVer) ret=0 %{SOURCE22} -l "../filtermods-$KernelVer.log" sort -d $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.dep -c configs/def_variants.yaml $variants_param -o .. || ret=$? if [ $ret -ne 0 ]; then echo "8< --- filtermods-$KernelVer.log ---" cat "../filtermods-$KernelVer.log" echo "--- filtermods-$KernelVer.log --- >8" echo "8< --- modules.dep ---" cat $RPM_BUILD_ROOT/lib/modules/$KernelVer/modules.dep echo "--- modules.dep --- >8" exit 1 fi create_module_file_list "kernel" ../modules-core.list ../kernel${Variant:+-${Variant}}-modules-core.list 1 0 create_module_file_list "kernel" ../modules.list ../kernel${Variant:+-${Variant}}-modules.list 0 0 create_module_file_list "internal" ../modules-internal.list ../kernel${Variant:+-${Variant}}-modules-internal.list 0 1 create_module_file_list "kernel" ../modules-extra.list ../kernel${Variant:+-${Variant}}-modules-extra.list 0 1 %if 0%{!?fedora:1} create_module_file_list "partner" ../modules-partner.list ../kernel${Variant:+-${Variant}}-modules-partner.list 1 1 %endif fi # $DoModules -eq 1 %if %{with_kmap} && %{with_base} # Generate source-to-module mapping data using kmap.py. # Must run before the next BuildKernel call issues make mrproper, which # would wipe the .cmd files that kmap.py reads. Skip debug variants # (same source mapping as the base kernel). if [[ "$Variant" != *debug* ]]; then _kmap_bdir=$(pwd) _kmap_basedir=%{_builddir}/kmap-data _kmap_merged=$_kmap_basedir/kernel-map.json _kmap_variant=${Variant:-stock} _kmap_listprefix=../kernel${Variant:+-${Variant}} mkdir -p $_kmap_basedir # Build kmap.py arguments; merge with existing data if present _kmap_args="--directory $_kmap_bdir --outputdir $_kmap_basedir --rhel upstream --variant $_kmap_variant --time" _kmap_args="$_kmap_args --vmlinux-rpm %{name}-core-%{KVERREL}.rpm" if [ -f "$_kmap_merged" ]; then _kmap_args="$_kmap_args --input kernel-map.json" fi # Add module list files for module-to-RPM mapping for _kmap_type in modules-core modules modules-extra modules-internal; do if [ -f "${_kmap_listprefix}-${_kmap_type}.list" ]; then _kmap_rpm=%{name}-${_kmap_type}-%{KVERREL}.rpm _kmap_args="$_kmap_args --module-list ${_kmap_rpm}:${_kmap_listprefix}-${_kmap_type}.list" fi done %if 0%{!?fedora:1} if [ -f "${_kmap_listprefix}-modules-partner.list" ]; then _kmap_rpm=%{name}-modules-partner-%{KVERREL}.rpm _kmap_args="$_kmap_args --module-list ${_kmap_rpm}:${_kmap_listprefix}-modules-partner.list" fi %endif python3 %{SOURCE2100} $_kmap_args fi %endif remove_depmod_files() { # remove files that will be auto generated by depmod at rpm -i time pushd $RPM_BUILD_ROOT/lib/modules/$KernelVer/ # in case below list needs to be extended, remember to add a # matching ghost entry in the files section as well rm -f modules.{alias,alias.bin,builtin.alias.bin,builtin.bin} \ modules.{dep,dep.bin,devname,softdep,symbols,symbols.bin,weakdep} popd } # Cleanup %{log_msg "Cleanup build files"} rm -f $RPM_BUILD_ROOT/System.map %{log_msg "Remove depmod files"} remove_depmod_files %if %{with_cross} make -C $RPM_BUILD_ROOT/lib/modules/$KernelVer/build M=scripts clean make -C $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/tools/bpf/resolve_btfids clean sed -i 's/REBUILD_SCRIPTS_FOR_CROSS:=0/REBUILD_SCRIPTS_FOR_CROSS:=1/' $RPM_BUILD_ROOT/lib/modules/$KernelVer/build/Makefile %endif # Move the devel headers out of the root file system %{log_msg "Move the devel headers to RPM_BUILD_ROOT"} mkdir -p $RPM_BUILD_ROOT/usr/src/kernels mv $RPM_BUILD_ROOT/lib/modules/$KernelVer/build $RPM_BUILD_ROOT/$DevelDir # This is going to create a broken link during the build, but we don't use # it after this point. We need the link to actually point to something # when kernel-devel is installed, and a relative link doesn't work across # the F17 UsrMove feature. ln -sf $DevelDir $RPM_BUILD_ROOT/lib/modules/$KernelVer/build %if %{with_debuginfo} # Generate vmlinux.h and put it to kernel-devel path # zfcpdump build does not have btf anymore if [ "$Variant" != "zfcpdump" ]; then %{log_msg "Build the bootstrap bpftool to generate vmlinux.h"} # Build the bootstrap bpftool to generate vmlinux.h BuildBpftool tools/bpf/bpftool/bootstrap/bpftool btf dump file vmlinux format c > $RPM_BUILD_ROOT/$DevelDir/vmlinux.h fi %endif %{log_msg "Cleanup kernel-devel and kernel-debuginfo files"} # prune junk from kernel-devel find $RPM_BUILD_ROOT/usr/src/kernels -name ".*.cmd" -delete # prune junk from kernel-debuginfo find $RPM_BUILD_ROOT/usr/src/kernels -name "*.mod.c" -delete # Red Hat UEFI Secure Boot CA cert, which can be used to authenticate the kernel %{log_msg "Install certs"} mkdir -p $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer %if %{signkernel} install -m 0644 %{secureboot_ca_0} $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/kernel-signing-ca.cer %ifarch s390x ppc64le if [ -x /usr/bin/rpm-sign ]; then install -m 0644 %{secureboot_key_0} $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/%{signing_key_filename} fi %endif %endif %if 0%{?rhel} # Red Hat IMA code-signing cert, which is used to authenticate package files install -m 0644 %{ima_signing_cert} $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/%{ima_cert_name} %endif %if %{signmodules} if [ $DoModules -eq 1 ]; then # Save the signing keys so we can sign the modules in __modsign_install_post cp certs/signing_key.pem certs/signing_key.pem.sign${Variant:++${Variant}} cp certs/signing_key.x509 certs/signing_key.x509.sign${Variant:++${Variant}} %ifarch s390x ppc64le if [ ! -x /usr/bin/rpm-sign ]; then install -m 0644 certs/signing_key.x509.sign${Variant:++${Variant}} $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/kernel-signing-ca.cer openssl x509 -in certs/signing_key.pem.sign${Variant:++${Variant}} -outform der -out $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/%{signing_key_filename} chmod 0644 $RPM_BUILD_ROOT%{_datadir}/doc/kernel-keys/$KernelVer/%{signing_key_filename} fi %endif fi %endif %if %{with_gcov} popd %endif } ### # DO it... ### # prepare directories rm -rf $RPM_BUILD_ROOT mkdir -p $RPM_BUILD_ROOT/boot mkdir -p $RPM_BUILD_ROOT%{_libexecdir} cd linux-%{KVERREL} %if %{with_debug} %if %{with_realtime} BuildKernel %make_target %kernel_image %{_use_vdso} rt-debug %endif %if %{with_realtime_arm64_64k} BuildKernel %make_target %kernel_image %{_use_vdso} rt-64k-debug %endif %if %{with_automotive} && !%{with_automotive_build} BuildKernel %make_target %kernel_image %{_use_vdso} automotive-debug %endif %if %{with_arm64_16k} BuildKernel %make_target %kernel_image %{_use_vdso} 16k-debug %endif %if %{with_arm64_64k} BuildKernel %make_target %kernel_image %{_use_vdso} 64k-debug %endif %if %{with_up} BuildKernel %make_target %kernel_image %{_use_vdso} debug %endif %endif %if %{with_zfcpdump} BuildKernel %make_target %kernel_image %{_use_vdso} zfcpdump %endif %if %{with_arm64_16k_base} BuildKernel %make_target %kernel_image %{_use_vdso} 16k %endif %if %{with_arm64_64k_base} BuildKernel %make_target %kernel_image %{_use_vdso} 64k %endif %if %{with_realtime_base} BuildKernel %make_target %kernel_image %{_use_vdso} rt %endif %if %{with_realtime_arm64_64k_base} BuildKernel %make_target %kernel_image %{_use_vdso} rt-64k %endif %if %{with_automotive_base} BuildKernel %make_target %kernel_image %{_use_vdso} automotive %endif %if %{with_up_base} BuildKernel %make_target %kernel_image %{_use_vdso} %endif %ifnarch noarch i686 %{nobuildarches} %if !%{with_debug} && !%{with_zfcpdump} && !%{with_up} && !%{with_arm64_16k} && !%{with_arm64_64k} && !%{with_realtime} && !%{with_realtime_arm64_64k} && !%{with_automotive} # If only building the user space tools, then initialize the build environment # and some variables so that the various userspace tools can be built. %{log_msg "Initialize userspace tools build environment"} InitBuildVars # Some tests build also modules, and need Module.symvers if ! [[ -e Module.symvers ]] && [[ -f $DevelDir/Module.symvers ]]; then %{log_msg "Found Module.symvers in DevelDir, copying to ."} cp "$DevelDir/Module.symvers" . fi %endif %endif %ifarch aarch64 %global perf_build_extra_opts CORESIGHT=1 %endif %global perf_make \ %{__make} %{?make_opts} EXTRA_CFLAGS="${RPM_OPT_FLAGS}" EXTRA_CXXFLAGS="${RPM_OPT_FLAGS}" LDFLAGS="%{__global_ldflags} -Wl,-E" %{?cross_opts} -C tools/perf V=1 NO_PERF_READ_VDSO32=1 NO_PERF_READ_VDSOX32=1 WERROR=0 NO_LIBUNWIND=1 HAVE_CPLUS_DEMANGLE=1 NO_GTK2=1 NO_STRLCPY=1 NO_BIONIC=1 LIBTRACEEVENT_DYNAMIC=1 %{?perf_build_extra_opts} prefix=%{_prefix} PYTHON=%{__python3} %if %{with_perf} %{log_msg "Build perf"} # perf # make sure check-headers.sh is executable chmod +x tools/perf/check-headers.sh %{perf_make} DESTDIR=$RPM_BUILD_ROOT all %endif %if %{with_libperf} %global libperf_make \ %{__make} %{?make_opts} EXTRA_CFLAGS="${RPM_OPT_FLAGS}" LDFLAGS="%{__global_ldflags}" %{?cross_opts} -C tools/lib/perf V=1 %{log_msg "build libperf"} %{libperf_make} DESTDIR=$RPM_BUILD_ROOT %endif %global tools_make \ CFLAGS="${RPM_OPT_FLAGS} %{_default_lto_cflags}" LDFLAGS="%{__global_ldflags}" EXTRA_CFLAGS="${RPM_OPT_FLAGS} %{_default_lto_cflags}" %{make} %{?make_opts} %ifarch %{cpupowerarchs} # link against in-tree libcpupower for idle state support %global rtla_make %{tools_make} LDFLAGS="%{__global_ldflags} -L../../power/cpupower" INCLUDES="-I../../power/cpupower/lib" # Build libcpupower Python bindings %global libcpupower_python_bindings_make %{tools_make} LDFLAGS="-L%{buildroot}%{_libdir} -lcpupower" %else %global rtla_make %{tools_make} %endif %if %{with_tools} %if %{with_ynl} pushd tools/net/ynl export PIP_CONFIG_FILE=/tmp/pip.config cat < $PIP_CONFIG_FILE [install] no-index = true no-build-isolation = false EOF %{tools_make} %{?_smp_mflags} DESTDIR=$RPM_BUILD_ROOT install popd %endif %ifarch %{cpupowerarchs} # cpupower # make sure version-gen.sh is executable. chmod +x tools/power/cpupower/utils/version-gen.sh %{log_msg "build cpupower"} %{tools_make} %{?_smp_mflags} -C tools/power/cpupower CPUFREQ_BENCH=false DEBUG=false %ifarch x86_64 pushd tools/power/cpupower/debug/x86_64 %{log_msg "build centrino-decode powernow-k8-decode"} %{tools_make} %{?_smp_mflags} centrino-decode powernow-k8-decode popd %endif %ifarch x86_64 pushd tools/power/x86/x86_energy_perf_policy/ %{log_msg "build x86_energy_perf_policy"} %{tools_make} popd pushd tools/power/x86/turbostat %{log_msg "build turbostat"} %{tools_make} popd pushd tools/power/x86/intel-speed-select %{log_msg "build intel-speed-select"} %{tools_make} popd pushd tools/arch/x86/intel_sdsi %{log_msg "build intel_sdsi"} %{tools_make} CFLAGS="${RPM_OPT_FLAGS}" popd %endif %endif pushd tools/thermal/tmon/ %{log_msg "build tmon"} %{tools_make} popd pushd tools/bootconfig/ %{log_msg "build bootconfig"} %{tools_make} popd pushd tools/iio/ %{log_msg "build iio"} %{tools_make} popd pushd tools/gpio/ %{log_msg "build gpio"} %{tools_make} popd # build VM tools pushd tools/mm/ %{log_msg "build slabinfo page_owner_sort"} %{tools_make} slabinfo page_owner_sort popd pushd tools/verification/rv/ %{log_msg "build rv"} %{tools_make} popd pushd tools/tracing/rtla %{log_msg "build rtla"} %{rtla_make} popd %endif #set RPM_VMLINUX_H if [ -f $RPM_BUILD_ROOT/$DevelDir/vmlinux.h ]; then RPM_VMLINUX_H=$RPM_BUILD_ROOT/$DevelDir/vmlinux.h elif [ -f $DevelDir/vmlinux.h ]; then RPM_VMLINUX_H=$DevelDir/vmlinux.h fi echo "${RPM_VMLINUX_H}" > ../vmlinux_h_path %if %{with_selftests} %{log_msg "start build selftests"} # Unfortunately, samples/bpf/Makefile expects that the headers are installed # in the source tree. We installed them previously to $RPM_BUILD_ROOT/usr # but there's no way to tell the Makefile to take them from there. %{log_msg "install headers for selftests"} %{make} %{?_smp_mflags} headers_install # If we re building only tools without kernel, we need to generate config # headers and prepare tree for modules building. The modules_prepare target # will cover both. if [ ! -f include/generated/autoconf.h ]; then %{log_msg "modules_prepare for selftests"} %{make} %{?_smp_mflags} modules_prepare fi # Build BPFtool for samples/bpf if [ ! -f tools/bpf/bpftool/bootstrap/bpftool ]; then BuildBpftool fi %{log_msg "build samples/bpf"} %{make} %{?_smp_mflags} EXTRA_CXXFLAGS="${RPM_OPT_FLAGS}" ARCH=$Arch BPFTOOL=$(pwd)/tools/bpf/bpftool/bootstrap/bpftool V=1 M=samples/bpf/ VMLINUX_H="${RPM_VMLINUX_H}" || true pushd tools/testing/selftests # We need to install here because we need to call make with ARCH set which # doesn't seem possible to do in the install section. %if %{selftests_must_build} force_targets="FORCE_TARGETS=1" %else force_targets="" %endif %{log_msg "main selftests compile"} # Some selftests (especially bpf) do not build with source fortification. # Since selftests are not shipped, disable source fortification for them. %global _fortify_level_bak %{_fortify_level} %undefine _fortify_level export CFLAGS="%{build_cflags}" export CXXFLAGS="%{build_cxxflags}" TARGETS="bpf cgroup kmod mm net net/can net/forwarding net/hsr net/mptcp net/netfilter net/packetdrill net/tcp_ao tc-testing memfd drivers/net/hw iommu cachestat pid_namespace rlimits timens pidfd capabilities clone3 exec filesystems firmware landlock mount mount_setattr move_mount_set_group nsfs openat2 proc safesetid seccomp tmpfs uevent vDSO" %{make} %{?_smp_mflags} EXTRA_CFLAGS="${RPM_OPT_FLAGS}" EXTRA_CXXFLAGS="${RPM_OPT_FLAGS}" EXTRA_LDFLAGS="%{__global_ldflags}" ARCH=$Arch V=1 TARGETS="$TARGETS" SKIP_TARGETS="" $force_targets VMLINUX_H="${RPM_VMLINUX_H}" # Restore the original level of source fortification %define _fortify_level %{_fortify_level_bak} export CFLAGS="%{build_cflags}" export CXXFLAGS="%{build_cxxflags}" # We must install all the targets in a single step as each `make install` # command overrides the kselftest-list.txt file. %{make} ARCH=$Arch TARGETS="${TARGETS}" SKIP_TARGETS="" $force_targets INSTALL_PATH=%{buildroot}%{_libexecdir}/kselftests install # 'make install' for bpf is broken and upstream refuses to fix it. # Install the needed files manually. %{log_msg "install selftests"} for dir in bpf bpf/no_alu32 bpf/cpuv4 bpf/progs; do # In ARK, the rpm build continues even if some of the selftests # cannot be built. It's not always possible to build selftests, # as upstream sometimes dependens on too new llvm version or has # other issues. If something did not get built, just skip it. test -d $dir || continue mkdir -p %{buildroot}%{_libexecdir}/kselftests/$dir find $dir -maxdepth 1 \( -type f -o -type l \) \ \( -executable -o \ -name '*.py' -o \ -name settings -o \ -name DENYLIST -o \ -name 'btf_dump_test_case_*.c' -o \ -name '*.ko' -o \ -name '*.o' -exec sh -c 'readelf -h "{}" | grep -q "^ Machine:.*BPF"' \; \ \) -print0 | \ xargs -0 cp -t %{buildroot}%{_libexecdir}/kselftests/$dir || true done %buildroot_save_unstripped "usr/libexec/kselftests/bpf/test_progs" %buildroot_save_unstripped "usr/libexec/kselftests/bpf/test_progs-no_alu32" %buildroot_save_unstripped "usr/libexec/kselftests/bpf/test_progs-cpuv4" # The urandom_read binary doesn't pass the check-rpaths check and upstream # refuses to fix it. So, we save it to buildroot_unstripped and delete it so it # will be hidden from check-rpaths and will automatically get restored later. %buildroot_save_unstripped "usr/libexec/kselftests/bpf/urandom_read" %buildroot_save_unstripped "usr/libexec/kselftests/bpf/no_alu32/urandom_read" %buildroot_save_unstripped "usr/libexec/kselftests/bpf/cpuv4/urandom_read" rm -f %{buildroot}/usr/libexec/kselftests/bpf/urandom_read rm -f %{buildroot}/usr/libexec/kselftests/bpf/no_alu32/urandom_read rm -f %{buildroot}/usr/libexec/kselftests/bpf/cpuv4/urandom_read # Copy bpftool to kselftests so selftests is packaged with # the full bpftool instead of bootstrap bpftool cp ./bpf/tools/sbin/bpftool %{buildroot}%{_libexecdir}/kselftests/bpf/bpftool # Append RHEL-specific BPF selftests DENYLIST.rhel to the global DENYLIST that # is automatically picked by BPF selftest runners. %if 0%{?rhel}%{?centos} cat ./bpf/DENYLIST.rhel >> %{buildroot}%{_libexecdir}/kselftests/bpf/DENYLIST %endif popd %{log_msg "end build selftests"} %endif %if %{with_doc} %{log_msg "start install docs"} # Make the HTML pages. %{log_msg "build html docs"} %{__make} PYTHON=/usr/bin/python3 htmldocs || %{doc_build_fail} # sometimes non-world-readable files sneak into the kernel source tree chmod -R a=rX Documentation find Documentation -type d | xargs chmod u+w %{log_msg "end install docs"} %endif # Module signing (modsign) # # This must be run _after_ find-debuginfo.sh runs, otherwise that will strip # the signature off of the modules. # # Don't sign modules for the zfcpdump variant as it is monolithic. %define __modsign_install_post \ if [ "%{signmodules}" -eq "1" ]; then \ %{log_msg "Signing kernel modules ..."} \ modules_dirs="$(shopt -s nullglob; echo $RPM_BUILD_ROOT/lib/modules/%{KVERREL}*)" \ for modules_dir in $modules_dirs; do \ variant_suffix="${modules_dir#$RPM_BUILD_ROOT/lib/modules/%{KVERREL}}" \ [ "$variant_suffix" == "+zfcpdump" ] && continue \ %{log_msg "Signing modules for %{KVERREL}${variant_suffix}"} \ %{modsign_cmd} certs/signing_key.pem.sign${variant_suffix} certs/signing_key.x509.sign${variant_suffix} $modules_dir/ \ done \ fi \ if [ "%{zipmodules}" -eq "1" ]; then \ %{log_msg "Compressing kernel modules ..."} \ find $RPM_BUILD_ROOT/lib/modules/ -type f -name '*.ko' | xargs -n 16 -P${RPM_BUILD_NCPUS} -r %compression %compression_flags; \ fi \ %{nil} ### ### Special hacks for debuginfo subpackages. ### # This macro is used by %%install, so we must redefine it before that. %define debug_package %{nil} %if %{with_debuginfo} %ifnarch noarch %{nobuildarches} %global __debug_package 1 %files -f debugfiles.list debuginfo-common-%{_target_cpu} %endif %endif # We don't want to package debuginfo for self-tests and samples but # we have to delete them to avoid an error messages about unpackaged # files. # Delete the debuginfo for kernel-devel files %define __remove_unwanted_dbginfo_install_post \ if [ "%{with_selftests}" -ne "0" ]; then \ rm -rf $RPM_BUILD_ROOT/usr/lib/debug/usr/libexec/ksamples; \ rm -rf $RPM_BUILD_ROOT/usr/lib/debug/usr/libexec/kselftests; \ fi \ rm -rf $RPM_BUILD_ROOT/usr/lib/debug/usr/src; \ %{nil} # Make debugedit and gdb-add-index use target versions of tools # when cross-compiling. This is supported since debugedit-5.1-5.fc42 # https://inbox.sourceware.org/debugedit/20250220153858.963312-1-mark@klomp.org/ %if %{with_cross} %define __override_target_tools_for_debugedit \ export OBJCOPY=%{CROSS_COMPILE}objcopy \ export NM=%{CROSS_COMPILE}nm \ export READELF=%{CROSS_COMPILE}readelf \ %{nil} %endif # # Disgusting hack alert! We need to ensure we sign modules *after* all # invocations of strip occur, which is in __debug_install_post if # find-debuginfo.sh runs, and __os_install_post if not. # %define __spec_install_post \ %{?__override_target_tools_for_debugedit:%{__override_target_tools_for_debugedit}}\ %{?__debug_package:%{__debug_install_post}}\ %{__arch_install_post}\ %{__os_install_post}\ %{__remove_unwanted_dbginfo_install_post}\ %{__restore_unstripped_root_post}\ %{__modsign_install_post} ### ### install ### %install cd linux-%{KVERREL} # re-define RPM_VMLINUX_H, because it doesn't carry over from %build RPM_VMLINUX_H="$(cat ../vmlinux_h_path)" %if %{with_doc} docdir=$RPM_BUILD_ROOT%{_datadir}/doc/kernel-doc-%{specversion}-%{pkgrelease} # copy the source over mkdir -p $docdir tar -h -f - --exclude=man --exclude='.*' -c Documentation | tar xf - -C $docdir cat %{SOURCE2} | xz > $docdir/kernel.changelog.xz chmod 0644 $docdir/kernel.changelog.xz # with_doc %endif # We have to do the headers install before the tools install because the # kernel headers_install will remove any header files in /usr/include that # it doesn't install itself. %if %{with_headers} # Install kernel headers %{__make} ARCH=%{hdrarch} INSTALL_HDR_PATH=$RPM_BUILD_ROOT/usr headers_install find $RPM_BUILD_ROOT/usr/include \ \( -name .install -o -name .check -o \ -name ..install.cmd -o -name ..check.cmd \) -delete %endif %if %{with_cross_headers} HDR_ARCH_LIST='arm64 powerpc s390 x86 riscv' mkdir -p $RPM_BUILD_ROOT/usr/tmp-headers for arch in $HDR_ARCH_LIST; do mkdir $RPM_BUILD_ROOT/usr/tmp-headers/arch-${arch} %{__make} ARCH=${arch} INSTALL_HDR_PATH=$RPM_BUILD_ROOT/usr/tmp-headers/arch-${arch} headers_install done find $RPM_BUILD_ROOT/usr/tmp-headers \ \( -name .install -o -name .check -o \ -name ..install.cmd -o -name ..check.cmd \) -delete # Copy all the architectures we care about to their respective asm directories for arch in $HDR_ARCH_LIST ; do mkdir -p $RPM_BUILD_ROOT/usr/${arch}-linux-gnu/include mv $RPM_BUILD_ROOT/usr/tmp-headers/arch-${arch}/include/* $RPM_BUILD_ROOT/usr/${arch}-linux-gnu/include/ done rm -rf $RPM_BUILD_ROOT/usr/tmp-headers %endif %if %{with_kernel_abi_stablelists} # kabi directory INSTALL_KABI_PATH=$RPM_BUILD_ROOT/lib/modules/ mkdir -p $INSTALL_KABI_PATH # install kabi releases directories tar -xvf %{SOURCE300} -C $INSTALL_KABI_PATH # with_kernel_abi_stablelists %endif %if %{with_perf} # perf tool binary and supporting scripts/binaries %{perf_make} DESTDIR=$RPM_BUILD_ROOT lib=%{_lib} install-bin # remove the 'trace' symlink. rm -f %{buildroot}%{_bindir}/trace # For both of the below, yes, this should be using a macro but right now # it's hard coded and we don't actually want it anyway right now. # Whoever wants examples can fix it up! # remove examples rm -rf %{buildroot}/usr/lib/perf/examples rm -rf %{buildroot}/usr/lib/perf/include # python-perf extension %{perf_make} DESTDIR=$RPM_BUILD_ROOT install-python_ext # perf man pages (note: implicit rpm magic compresses them later) mkdir -p %{buildroot}/%{_mandir}/man1 %{perf_make} DESTDIR=$RPM_BUILD_ROOT install-man # remove any tracevent files, eg. its plugins still gets built and installed, # even if we build against system's libtracevent during perf build (by setting # LIBTRACEEVENT_DYNAMIC=1 above in perf_make macro). Those files should already # ship with libtraceevent package. rm -rf %{buildroot}%{_libdir}/traceevent %endif %if %{with_libperf} %{libperf_make} DESTDIR=%{buildroot} prefix=%{_prefix} libdir=%{_libdir} install install_headers # This is installed on some arches and we don't want to ship it rm -rf %{buildroot}%{_libdir}/libperf.a %endif %if %{with_tools} %ifarch %{cpupowerarchs} %{make} -C tools/power/cpupower DESTDIR=$RPM_BUILD_ROOT libdir=%{_libdir} mandir=%{_mandir} CPUFREQ_BENCH=false install %find_lang cpupower mv cpupower.lang ../ %ifarch x86_64 pushd tools/power/cpupower/debug/x86_64 install -m755 centrino-decode %{buildroot}%{_bindir}/centrino-decode install -m755 powernow-k8-decode %{buildroot}%{_bindir}/powernow-k8-decode popd %endif chmod 0755 %{buildroot}%{_libdir}/libcpupower.so* %{log_msg "Build libcpupower Python bindings"} pushd tools/power/cpupower/bindings/python %{libcpupower_python_bindings_make} %{log_msg "Install libcpupower Python bindings"} %{make} INSTALL_DIR=$RPM_BUILD_ROOT%{python3_sitearch} install popd %endif %ifarch x86_64 mkdir -p %{buildroot}%{_mandir}/man8 pushd tools/power/x86/x86_energy_perf_policy %{tools_make} DESTDIR=%{buildroot} install popd pushd tools/power/x86/turbostat %{tools_make} DESTDIR=%{buildroot} install popd pushd tools/power/x86/intel-speed-select %{tools_make} DESTDIR=%{buildroot} install popd pushd tools/arch/x86/intel_sdsi %{tools_make} CFLAGS="${RPM_OPT_FLAGS}" DESTDIR=%{buildroot} install popd %endif pushd tools/thermal/tmon %{tools_make} INSTALL_ROOT=%{buildroot} install popd pushd tools/bootconfig %{tools_make} DESTDIR=%{buildroot} install popd pushd tools/iio %{tools_make} DESTDIR=%{buildroot} install popd pushd tools/gpio %{tools_make} DESTDIR=%{buildroot} install popd install -m644 -D %{SOURCE2002} %{buildroot}%{_sysconfdir}/logrotate.d/kvm_stat pushd tools/kvm/kvm_stat %{__make} INSTALL_ROOT=%{buildroot} install-tools %{__make} INSTALL_ROOT=%{buildroot} install-man install -m644 -D kvm_stat.service %{buildroot}%{_unitdir}/kvm_stat.service popd # install VM tools pushd tools/mm/ install -m755 slabinfo %{buildroot}%{_bindir}/slabinfo install -m755 page_owner_sort %{buildroot}%{_bindir}/page_owner_sort popd pushd tools/verification/rv/ %{tools_make} DESTDIR=%{buildroot} STRIP=/bin/true install popd pushd tools/tracing/rtla/ %{tools_make} DESTDIR=%{buildroot} STRIP=/bin/true install rm -f %{buildroot}%{_bindir}/hwnoise rm -f %{buildroot}%{_bindir}/osnoise rm -f %{buildroot}%{_bindir}/timerlat (cd %{buildroot} ln -sf rtla ./%{_bindir}/hwnoise ln -sf rtla ./%{_bindir}/osnoise ln -sf rtla ./%{_bindir}/timerlat ) popd %endif %if %{with_selftests} pushd samples install -d %{buildroot}%{_libexecdir}/ksamples # install bpf samples pushd bpf install -d %{buildroot}%{_libexecdir}/ksamples/bpf find -type f -executable -exec install -m755 {} %{buildroot}%{_libexecdir}/ksamples/bpf \; install -m755 *.sh %{buildroot}%{_libexecdir}/ksamples/bpf # test_lwt_bpf.sh compiles test_lwt_bpf.c when run; this works only from the # kernel tree. Just remove it. rm %{buildroot}%{_libexecdir}/ksamples/bpf/test_lwt_bpf.sh install -m644 *_kern.o %{buildroot}%{_libexecdir}/ksamples/bpf || true install -m644 tcp_bpf.readme %{buildroot}%{_libexecdir}/ksamples/bpf popd # install pktgen samples pushd pktgen install -d %{buildroot}%{_libexecdir}/ksamples/pktgen find . -type f -executable -exec install -m755 {} %{buildroot}%{_libexecdir}/ksamples/pktgen/{} \; find . -type f ! -executable -exec install -m644 {} %{buildroot}%{_libexecdir}/ksamples/pktgen/{} \; popd popd # install mm selftests pushd tools/testing/selftests/mm find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/mm/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/mm/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/mm/{} \; popd # install cgroup selftests pushd tools/testing/selftests/cgroup find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/cgroup/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/cgroup/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/cgroup/{} \; popd # install drivers/net selftests pushd tools/testing/selftests/drivers/net find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/drivers/net/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/{} \; popd # install drivers/net/mlxsw selftests pushd tools/testing/selftests/drivers/net/mlxsw find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/drivers/net/mlxsw/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/mlxsw/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/mlxsw/{} \; popd # install drivers/net/hw selftests pushd tools/testing/selftests/drivers/net/hw find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/drivers/net/hw/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/hw/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/hw/{} \; popd # install drivers/net/netdevsim selftests pushd tools/testing/selftests/drivers/net/netdevsim find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/drivers/net/netdevsim/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/netdevsim/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/netdevsim/{} \; popd # install drivers/net/bonding selftests pushd tools/testing/selftests/drivers/net/bonding find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/drivers/net/bonding/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/bonding/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/drivers/net/bonding/{} \; popd # install net/can selftests pushd tools/testing/selftests/net/can find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/can/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/can/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/can/{} \; popd # install net/forwarding selftests pushd tools/testing/selftests/net/forwarding find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/forwarding/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/forwarding/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/forwarding/{} \; popd # install net/hsr selftests pushd tools/testing/selftests/net/hsr find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/hsr/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/hsr/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/hsr/{} \; popd # install net/mptcp selftests pushd tools/testing/selftests/net/mptcp find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/mptcp/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/mptcp/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/mptcp/{} \; popd # install tc-testing selftests pushd tools/testing/selftests/tc-testing find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/tc-testing/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/tc-testing/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/tc-testing/{} \; popd # install net/netfilter selftests pushd tools/testing/selftests/net/netfilter find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/netfilter/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/netfilter/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/netfilter/{} \; popd # install net/packetdrill selftests pushd tools/testing/selftests/net/packetdrill find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/packetdrill/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/packetdrill/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/packetdrill/{} \; popd # install net/tcp_ao selftests pushd tools/testing/selftests/net/tcp_ao find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/net/tcp_ao/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/net/tcp_ao/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/net/tcp_ao/{} \; popd # install memfd selftests pushd tools/testing/selftests/memfd find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/memfd/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/memfd/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/memfd/{} \; popd # install iommu selftests pushd tools/testing/selftests/iommu find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/iommu/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/iommu/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/iommu/{} \; popd # install rlimits selftests pushd tools/testing/selftests/rlimits find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/rlimits/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/rlimits/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/rlimits/{} \; popd # install pid_namespace selftests pushd tools/testing/selftests/pid_namespace find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/pid_namespace/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/pid_namespace/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/pid_namespace/{} \; popd # install timens selftests pushd tools/testing/selftests/timens find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/timens/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/timens/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/timens/{} \; popd # install pidfd selftests pushd tools/testing/selftests/pidfd find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/pidfd/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/pidfd/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/pidfd/{} \; popd # install capabilities selftests pushd tools/testing/selftests/capabilities find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/capabilities/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/capabilities/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/capabilities/{} \; popd # install clone3 selftests pushd tools/testing/selftests/clone3 find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/clone3/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/clone3/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/clone3/{} \; popd # install exec selftests pushd tools/testing/selftests/exec find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/exec/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/exec/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/exec/{} \; popd # install filesystems selftests pushd tools/testing/selftests/filesystems find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/filesystems/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/filesystems/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/filesystems/{} \; popd # install firmware selftests pushd tools/testing/selftests/firmware find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/firmware/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/firmware/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/firmware/{} \; popd # install landlock selftests pushd tools/testing/selftests/landlock find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/landlock/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/landlock/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/landlock/{} \; popd # install mount selftests pushd tools/testing/selftests/mount find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/mount/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/mount/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/mount/{} \; popd # install mount_setattr selftests pushd tools/testing/selftests/mount_setattr find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/mount_setattr/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/mount_setattr/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/mount_setattr/{} \; popd # install move_mount_set_group selftests pushd tools/testing/selftests/move_mount_set_group find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/move_mount_set_group/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/move_mount_set_group/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/move_mount_set_group/{} \; popd # install nsfs selftests pushd tools/testing/selftests/nsfs find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/nsfs/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/nsfs/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/nsfs/{} \; popd # install openat2 selftests pushd tools/testing/selftests/openat2 find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/openat2/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/openat2/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/openat2/{} \; popd # install proc selftests pushd tools/testing/selftests/proc find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/proc/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/proc/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/proc/{} \; popd # install safesetid selftests pushd tools/testing/selftests/safesetid find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/safesetid/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/safesetid/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/safesetid/{} \; popd # install seccomp selftests pushd tools/testing/selftests/seccomp find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/seccomp/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/seccomp/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/seccomp/{} \; popd # install tmpfs selftests pushd tools/testing/selftests/tmpfs find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/tmpfs/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/tmpfs/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/tmpfs/{} \; popd # install uevent selftests pushd tools/testing/selftests/uevent find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/uevent/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/uevent/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/uevent/{} \; popd # install vDSO selftests pushd tools/testing/selftests/vDSO find -type d -exec install -d %{buildroot}%{_libexecdir}/kselftests/vDSO/{} \; find -type f -executable -exec install -D -m755 {} %{buildroot}%{_libexecdir}/kselftests/vDSO/{} \; find -type f ! -executable -exec install -D -m644 {} %{buildroot}%{_libexecdir}/kselftests/vDSO/{} \; popd %endif %if %{with_kmap} && %{with_base} # Install kmap data files produced during %build. _kmap_basedir=%{_builddir}/kmap-data _kmap_destbase=$RPM_BUILD_ROOT%{_datadir}/%{name}-kmap-internal mkdir -p $_kmap_destbase install -m 644 $_kmap_basedir/kernel-map.json $_kmap_destbase/kernel-map-%{KVERREL}.json %endif ### ### clean ### ### ### scripts ### %if %{with_tools} %post -n %{package_name}-tools-libs /sbin/ldconfig %postun -n %{package_name}-tools-libs /sbin/ldconfig %endif # # This macro defines a %%post script for a kernel*-devel package. # %%kernel_devel_post [] # Note we don't run hardlink if ostree is in use, as ostree is # a far more sophisticated hardlink implementation. # https://github.com/projectatomic/rpm-ostree/commit/58a79056a889be8814aa51f507b2c7a4dccee526 # # The deletion of *.hardlink-temporary files is a temporary workaround # for this bug in the hardlink binary (fixed in util-linux 2.38): # https://github.com/util-linux/util-linux/issues/1602 # %define kernel_devel_post() \ %{expand:%%post %{?1:%{1}-}devel}\ if [ -f /etc/sysconfig/kernel ]\ then\ . /etc/sysconfig/kernel || exit $?\ fi\ if [ "$HARDLINK" != "no" -a -x /usr/bin/hardlink -a ! -e /run/ostree-booted ] \ then\ (cd /usr/src/kernels/%{KVERREL}%{?1:+%{1}} &&\ /usr/bin/find . -type f | while read f; do\ hardlink -c /usr/src/kernels/*%{?dist}.*/$f $f > /dev/null\ done;\ /usr/bin/find /usr/src/kernels -type f -name '*.hardlink-temporary' -delete\ )\ fi\ %if %{with_cross}\ echo "Building scripts and resolve_btfids"\ env --unset=ARCH make -C /usr/src/kernels/%{KVERREL}%{?1:+%{1}} prepare_after_cross\ %endif\ %{nil} # # This macro defines a %%post script for a kernel*-modules-extra package. # It also defines a %%postun script that does the same thing. # %%kernel_modules_extra_post [] # %define kernel_modules_extra_post() \ %{expand:%%post %{?1:%{1}-}modules-extra}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil}\ %{expand:%%postun %{?1:%{1}-}modules-extra}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil} # # This macro defines a %%post script for a kernel*-modules-internal package. # It also defines a %%postun script that does the same thing. # %%kernel_modules_internal_post [] # %define kernel_modules_internal_post() \ %{expand:%%post %{?1:%{1}-}modules-internal}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil}\ %{expand:%%postun %{?1:%{1}-}modules-internal}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil} # # This macro defines a %%post script for a kernel*-modules-partner package. # It also defines a %%postun script that does the same thing. # %%kernel_modules_partner_post [] # %define kernel_modules_partner_post() \ %{expand:%%post %{?1:%{1}-}modules-partner}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil}\ %{expand:%%postun %{?1:%{1}-}modules-partner}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil} # # This macro defines a %%post script for a kernel*-modules package. # It also defines a %%postun script that does the same thing. # %%kernel_modules_post [] # %define kernel_modules_post() \ %{expand:%%post %{?1:%{1}-}modules}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ if [ -f /lib/modules/%{KVERREL}%{?1:+%{1}}/vmlinuz ] &&\ [ -f /boot/initramfs-%{KVERREL}%{?1:+%{1}}.img ] &&\ [ ! -f %{_localstatedir}/lib/rpm-state/%{name}/installing_core_%{KVERREL}%{?1:+%{1}} ]; then\ mkdir -p %{_localstatedir}/lib/rpm-state/%{name}\ touch %{_localstatedir}/lib/rpm-state/%{name}/need_to_run_dracut_%{KVERREL}%{?1:+%{1}}\ fi\ %{nil}\ %{expand:%%postun %{?1:%{1}-}modules}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil}\ %{expand:%%posttrans %{?1:%{1}-}modules}\ if [ -f %{_localstatedir}/lib/rpm-state/%{name}/need_to_run_dracut_%{KVERREL}%{?1:+%{1}} ]; then\ rm -f %{_localstatedir}/lib/rpm-state/%{name}/need_to_run_dracut_%{KVERREL}%{?1:+%{1}}\ echo "Running: dracut -f --kver %{KVERREL}%{?1:+%{1}} /boot/initramfs-%{KVERREL}%{?1:+%{1}}.img"\ dracut -f --kver "%{KVERREL}%{?1:+%{1}}" /boot/initramfs-%{KVERREL}%{?1:+%{1}}.img || exit $?\ fi\ %{nil} # # This macro defines a %%post script for a kernel*-modules-core package. # %%kernel_modules_core_post [] # %define kernel_modules_core_post() \ %{expand:%%posttrans %{?1:%{1}-}modules-core}\ /sbin/depmod -a %{KVERREL}%{?1:+%{1}}\ %{nil} # This macro defines a %%posttrans script for a kernel package. # %%kernel_variant_posttrans [-v ] [-u uki-suffix] # More text can follow to go at the end of this variant's %%post. # %define kernel_variant_posttrans(v:u:) \ %{expand:%%posttrans %{?-v:%{-v*}-}%{!?-u*:core}%{?-u*:uki-%{-u*}}}\ %if 0%{!?fedora:1}\ %if !%{with_automotive}\ if [ -x %{_sbindir}/weak-modules ]\ then\ %{_sbindir}/weak-modules --add-kernel %{KVERREL}%{?-v:+%{-v*}} || exit $?\ fi\ %endif\ %endif\ rm -f %{_localstatedir}/lib/rpm-state/%{name}/installing_core_%{KVERREL}%{?-v:+%{-v*}}\ /bin/kernel-install add %{KVERREL}%{?-v:+%{-v*}} /lib/modules/%{KVERREL}%{?-v:+%{-v*}}/vmlinuz%{?-u:-%{-u*}.efi} || exit $?\ if [[ ! -e "/boot/symvers-%{KVERREL}%{?-v:+%{-v*}}.%compext" ]]; then\ cp "/lib/modules/%{KVERREL}%{?-v:+%{-v*}}/symvers.%compext" "/boot/symvers-%{KVERREL}%{?-v:+%{-v*}}.%compext"\ if command -v restorecon &>/dev/null; then\ restorecon "/boot/symvers-%{KVERREL}%{?-v:+%{-v*}}.%compext"\ fi\ fi\ %{nil} # # This macro defines a %%post script for a kernel package and its devel package. # %%kernel_variant_post [-v ] [-r ] # More text can follow to go at the end of this variant's %%post. # %define kernel_variant_post(v:r:) \ %{expand:%%kernel_devel_post %{?-v*}}\ %{expand:%%kernel_modules_post %{?-v*}}\ %{expand:%%kernel_modules_core_post %{?-v*}}\ %{expand:%%kernel_modules_extra_post %{?-v*}}\ %{expand:%%kernel_modules_internal_post %{?-v*}}\ %if 0%{!?fedora:1}\ %{expand:%%kernel_modules_partner_post %{?-v*}}\ %endif\ %{expand:%%kernel_variant_posttrans %{?-v*:-v %{-v*}}}\ %{expand:%%post %{?-v*:%{-v*}-}core}\ %{-r:\ if [ `uname -i` == "x86_64" -o `uname -i` == "i386" ] &&\ [ -f /etc/sysconfig/kernel ]; then\ /bin/sed -r -i -e 's/^DEFAULTKERNEL=%{-r*}$/DEFAULTKERNEL=kernel%{?-v:-%{-v*}}/' /etc/sysconfig/kernel || exit $?\ fi}\ mkdir -p %{_localstatedir}/lib/rpm-state/%{name}\ touch %{_localstatedir}/lib/rpm-state/%{name}/installing_core_%{KVERREL}%{?-v:+%{-v*}}\ %{nil} # # This macro defines a %%preun script for a kernel package. # %%kernel_variant_preun [-v ] -u [uki-suffix] -e # Add kernel-install's --entry-type=type1|type2|all option (if supported) to limit removal # to a specific boot entry type. # %define kernel_variant_preun(v:u:e) \ %{expand:%%preun %{?-v:%{-v*}-}%{!?-u*:core}%{?-u*:uki-%{-u*}}}\ entry_type=""\ %{-e: \ /bin/kernel-install --help|grep -q -- '--entry-type=' &&\ entry_type="--entry-type %{!?-u:type1}%{?-u:type2}" \ }\ /bin/kernel-install remove %{KVERREL}%{?-v:+%{-v*}} $entry_type || exit $?\ %if !%{with_automotive}\ if [ -x %{_sbindir}/weak-modules ]\ then\ %{_sbindir}/weak-modules --remove-kernel %{KVERREL}%{?-v:+%{-v*}} || exit $?\ fi\ %endif\ %{nil} %if %{with_up_base} && %{with_efiuki} %kernel_variant_posttrans -u virt %kernel_variant_preun -u virt -e %endif %if %{with_up_base} %kernel_variant_preun -e %kernel_variant_post %endif %if %{with_zfcpdump} %kernel_variant_preun -v zfcpdump %kernel_variant_post -v zfcpdump %endif %if %{with_up} && %{with_debug} && %{with_efiuki} %kernel_variant_posttrans -v debug -u virt %kernel_variant_preun -v debug -u virt -e %endif %if %{with_up} && %{with_debug} %kernel_variant_preun -v debug -e %kernel_variant_post -v debug %endif %if %{with_arm64_16k_base} %kernel_variant_preun -v 16k -e %kernel_variant_post -v 16k %endif %if %{with_debug} && %{with_arm64_16k} %kernel_variant_preun -v 16k-debug -e %kernel_variant_post -v 16k-debug %endif %if %{with_arm64_16k} && %{with_debug} && %{with_efiuki} %kernel_variant_posttrans -v 16k-debug -u virt %kernel_variant_preun -v 16k-debug -u virt -e %endif %if %{with_arm64_16k_base} && %{with_efiuki} %kernel_variant_posttrans -v 16k -u virt %kernel_variant_preun -v 16k -u virt -e %endif %if %{with_arm64_64k_base} %kernel_variant_preun -v 64k -e %kernel_variant_post -v 64k %endif %if %{with_debug} && %{with_arm64_64k} %kernel_variant_preun -v 64k-debug -e %kernel_variant_post -v 64k-debug %endif %if %{with_arm64_64k} && %{with_debug} && %{with_efiuki} %kernel_variant_posttrans -v 64k-debug -u virt %kernel_variant_preun -v 64k-debug -u virt -e %endif %if %{with_arm64_64k_base} && %{with_efiuki} %kernel_variant_posttrans -v 64k -u virt %kernel_variant_preun -v 64k -u virt -e %endif %if %{with_realtime_base} %kernel_variant_preun -v rt %kernel_variant_post -v rt -r kernel %endif %if %{with_automotive_base} %kernel_variant_preun -v automotive %kernel_variant_post -v automotive -r kernel %endif %if %{with_realtime} && %{with_debug} %kernel_variant_preun -v rt-debug %kernel_variant_post -v rt-debug %endif %if %{with_realtime_arm64_64k_base} %kernel_variant_preun -v rt-64k %kernel_variant_post -v rt-64k %kernel_kvm_post rt-64k %endif %if %{with_debug} && %{with_realtime_arm64_64k} %kernel_variant_preun -v rt-64k-debug %kernel_variant_post -v rt-64k-debug %kernel_kvm_post rt-64k-debug %endif %if %{with_automotive} && %{with_debug} && !%{with_automotive_build} %kernel_variant_preun -v automotive-debug %kernel_variant_post -v automotive-debug %endif ### ### file lists ### %if %{with_headers} %files headers /usr/include/* %exclude %{_includedir}/cpufreq.h %if %{with_ynl} %exclude %{_includedir}/ynl %endif %endif %if %{with_cross_headers} %files cross-headers /usr/*-linux-gnu/include/* %endif %if %{with_kernel_abi_stablelists} %files -n %{package_name}-abi-stablelists /lib/modules/kabi-* %endif %if %{with_kabidw_base} %ifarch x86_64 s390x ppc64 ppc64le aarch64 riscv64 %files kernel-kabidw-base-internal %defattr(-,root,root) /kabidw-base/%{_target_cpu}/* %endif %endif # only some architecture builds need kernel-doc %if %{with_doc} %files doc %defattr(-,root,root) %{_datadir}/doc/kernel-doc-%{specversion}-%{pkgrelease}/Documentation/* %dir %{_datadir}/doc/kernel-doc-%{specversion}-%{pkgrelease}/Documentation %dir %{_datadir}/doc/kernel-doc-%{specversion}-%{pkgrelease} %{_datadir}/doc/kernel-doc-%{specversion}-%{pkgrelease}/kernel.changelog.xz %endif %if %{with_perf} %files -n perf %{_bindir}/perf %{_libdir}/libperf-jvmti.so %dir %{_libexecdir}/perf-core %{_libexecdir}/perf-core/* %{_mandir}/man[1-8]/perf* %{_sysconfdir}/bash_completion.d/perf %doc linux-%{KVERREL}/tools/perf/Documentation/examples.txt %{_docdir}/perf-tip/tips.txt %files -n python3-perf %{python3_sitearch}/perf* %if %{with_debuginfo} %files -f perf-debuginfo.list -n perf-debuginfo %files -f python3-perf-debuginfo.list -n python3-perf-debuginfo %endif # with_perf %endif %if %{with_libperf} %files -n libperf %{_libdir}/libperf.so.0 %{_libdir}/libperf.so.0.0.1 %files -n libperf-devel %{_libdir}/libperf.so %{_libdir}/pkgconfig/libperf.pc %{_includedir}/internal/*.h %{_includedir}/perf/bpf_perf.h %{_includedir}/perf/core.h %{_includedir}/perf/cpumap.h %{_includedir}/perf/perf_dlfilter.h %{_includedir}/perf/event.h %{_includedir}/perf/evlist.h %{_includedir}/perf/evsel.h %{_includedir}/perf/mmap.h %{_includedir}/perf/threadmap.h %{_mandir}/man3/libperf.3.gz %{_mandir}/man7/libperf-counting.7.gz %{_mandir}/man7/libperf-sampling.7.gz %{_docdir}/libperf/examples/sampling.c %{_docdir}/libperf/examples/counting.c %{_docdir}/libperf/html/libperf.html %{_docdir}/libperf/html/libperf-counting.html %{_docdir}/libperf/html/libperf-sampling.html %if %{with_debuginfo} %files -f libperf-debuginfo.list -n libperf-debuginfo %endif # with_libperf %endif %if %{with_tools} %ifnarch %{cpupowerarchs} %files -n %{package_name}-tools %else %files -n %{package_name}-tools -f cpupower.lang %{_bindir}/cpupower %{_datadir}/bash-completion/completions/cpupower %ifarch x86_64 %{_bindir}/centrino-decode %{_bindir}/powernow-k8-decode %endif %{_mandir}/man[1-8]/cpupower* %ifarch x86_64 %{_bindir}/x86_energy_perf_policy %{_mandir}/man8/x86_energy_perf_policy* %{_bindir}/turbostat %{_mandir}/man8/turbostat* %{_bindir}/intel-speed-select %{_sbindir}/intel_sdsi %endif # cpupowerarchs %endif %{_bindir}/tmon %{_bindir}/bootconfig %{_bindir}/iio_event_monitor %{_bindir}/iio_generic_buffer %{_bindir}/lsiio %{_bindir}/lsgpio %{_bindir}/gpio-hammer %{_bindir}/gpio-event-mon %{_bindir}/gpio-watch %{_mandir}/man1/kvm_stat* %{_bindir}/kvm_stat %{_unitdir}/kvm_stat.service %config(noreplace) %{_sysconfdir}/logrotate.d/kvm_stat %{_bindir}/page_owner_sort %{_bindir}/slabinfo %if %{with_ynl} %{_bindir}/ynl* %{_docdir}/ynl %{_datadir}/ynl %{python3_sitelib}/pyynl* %endif %if %{with_debuginfo} %files -f %{package_name}-tools-debuginfo.list -n %{package_name}-tools-debuginfo %endif %files -n %{package_name}-tools-libs %ifarch %{cpupowerarchs} %{_libdir}/libcpupower.so.1 %{_libdir}/libcpupower.so.0.0.1 %endif %files -n %{package_name}-tools-libs-devel %ifarch %{cpupowerarchs} %{_libdir}/libcpupower.so %{_includedir}/cpufreq.h %{_includedir}/cpuidle.h %{_includedir}/powercap.h # libcpupower Python bindings %{python3_sitearch}/_raw_pylibcpupower.so %{python3_sitearch}/raw_pylibcpupower.py %{python3_sitearch}/__pycache__/raw_pylibcpupower* %endif %if %{with_ynl} %{_libdir}/libynl* %{_includedir}/ynl %endif %files -n rtla %{_bindir}/rtla %{_bindir}/hwnoise %{_bindir}/osnoise %{_bindir}/timerlat %{_mandir}/man1/rtla-hwnoise.1.gz %{_mandir}/man1/rtla-osnoise-hist.1.gz %{_mandir}/man1/rtla-osnoise-top.1.gz %{_mandir}/man1/rtla-osnoise.1.gz %{_mandir}/man1/rtla-timerlat-hist.1.gz %{_mandir}/man1/rtla-timerlat-top.1.gz %{_mandir}/man1/rtla-timerlat.1.gz %{_mandir}/man1/rtla.1.gz %if %{with_debuginfo} %files -f rtla-debuginfo.list -n rtla-debuginfo %endif %files -n rv %{_bindir}/rv %{_mandir}/man1/rv-list.1.gz %{_mandir}/man1/rv-mon-wip.1.gz %{_mandir}/man1/rv-mon-wwnr.1.gz %{_mandir}/man1/rv-mon.1.gz %{_mandir}/man1/rv-mon-sched.1.gz %{_mandir}/man1/rv-mon-stall.1.gz %{_mandir}/man1/rv.1.gz %if %{with_debuginfo} %files -f rv-debuginfo.list -n rv-debuginfo %endif # with_tools %endif %if %{with_selftests} %files selftests-internal %{_libexecdir}/ksamples %{_libexecdir}/kselftests %endif %if %{with_kmap} && %{with_base} %files -n %{name}-kmap-internal %defattr(-,root,root) %dir %{_datadir}/%{name}-kmap-internal %{_datadir}/%{name}-kmap-internal/kernel-map-%{KVERREL}.json %endif # empty meta-package %if %{with_up_base} %ifnarch %nobuildarches noarch %files %endif %endif # This is %%{image_install_path} on an arch where that includes ELF files, # or empty otherwise. %define elf_image_install_path %{?kernel_image_elf:%{image_install_path}} # # This macro defines the %%files sections for a kernel package # and its devel and debuginfo packages. # %%kernel_variant_files [-k vmlinux] # %define kernel_variant_files(k:) \ %if %{2}\ %{expand:%%files %{?1:-f kernel-%{?3:%{3}-}ldsoconf.list} %{?3:%{3}-}core}\ %{!?_licensedir:%global license %%doc}\ %%license linux-%{KVERREL}/COPYING-%{version}-%{release}\ /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}\ %ghost /%{image_install_path}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}\ /lib/modules/%{KVERREL}%{?3:+%{3}}/.vmlinuz.hmac \ %ghost /%{image_install_path}/.vmlinuz-%{KVERREL}%{?3:+%{3}}.hmac \ %ifarch aarch64 riscv64\ /lib/modules/%{KVERREL}%{?3:+%{3}}/dtb \ %ghost /%{image_install_path}/dtb-%{KVERREL}%{?3:+%{3}} \ %endif\ /lib/modules/%{KVERREL}%{?3:+%{3}}/System.map\ %ghost /boot/System.map-%{KVERREL}%{?3:+%{3}}\ %dir /lib/modules\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}\ /lib/modules/%{KVERREL}%{?3:+%{3}}/symvers.%compext\ /lib/modules/%{KVERREL}%{?3:+%{3}}/config\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.builtin*\ %ghost %attr(0644, root, root) /boot/symvers-%{KVERREL}%{?3:+%{3}}.%compext\ %ghost %attr(0600, root, root) /boot/initramfs-%{KVERREL}%{?3:+%{3}}.img\ %ghost %attr(0644, root, root) /boot/config-%{KVERREL}%{?3:+%{3}}\ %{expand:%%files -f kernel-%{?3:%{3}-}modules-core.list %{?3:%{3}-}modules-core}\ %dir /lib/modules\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}/kernel\ /lib/modules/%{KVERREL}%{?3:+%{3}}/build\ /lib/modules/%{KVERREL}%{?3:+%{3}}/source\ /lib/modules/%{KVERREL}%{?3:+%{3}}/updates\ /lib/modules/%{KVERREL}%{?3:+%{3}}/weak-updates\ /lib/modules/%{KVERREL}%{?3:+%{3}}/systemtap\ %{_datadir}/doc/kernel-keys/%{KVERREL}%{?3:+%{3}}\ %if %{1}\ /lib/modules/%{KVERREL}%{?3:+%{3}}/vdso\ %endif\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.block\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.drm\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.modesetting\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.networking\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.order\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.alias\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.alias.bin\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.builtin.alias.bin\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.builtin.bin\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.dep\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.dep.bin\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.devname\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.softdep\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.symbols\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.symbols.bin\ %ghost %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.weakdep\ %{expand:%%files -f kernel-%{?3:%{3}-}modules.list %{?3:%{3}-}modules}\ %{expand:%%files %{?3:%{3}-}devel}\ %defverify(not mtime)\ /usr/src/kernels/%{KVERREL}%{?3:+%{3}}\ %{expand:%%files %{?3:%{3}-}devel-matched}\ %{expand:%%files -f kernel-%{?3:%{3}-}modules-extra.list %{?3:%{3}-}modules-extra}\ %{expand:%%files -f kernel-%{?3:%{3}-}modules-internal.list %{?3:%{3}-}modules-internal}\ %if 0%{!?fedora:1}\ %{expand:%%files -f kernel-%{?3:%{3}-}modules-partner.list %{?3:%{3}-}modules-partner}\ %endif\ %if %{with_debuginfo}\ %ifnarch noarch\ %{expand:%%files -f debuginfo%{?3}.list %{?3:%{3}-}debuginfo}\ %endif\ %endif\ %if %{with_efiuki} && "%{3}" != "rt" && "%{3}" != "rt-debug" && "%{3}" != "rt-64k" && "%{3}" != "rt-64k-debug"\ %{expand:%%files %{?3:%{3}-}uki-virt}\ %dir /lib/modules\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}\ /lib/modules/%{KVERREL}%{?3:+%{3}}/System.map\ /lib/modules/%{KVERREL}%{?3:+%{3}}/symvers.%compext\ /lib/modules/%{KVERREL}%{?3:+%{3}}/config\ /lib/modules/%{KVERREL}%{?3:+%{3}}/modules.builtin*\ %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi\ %attr(0644, root, root) /lib/modules/%{KVERREL}%{?3:+%{3}}/.%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi.hmac\ %ghost /%{image_install_path}/efi/EFI/Linux/%{?-k:%{-k*}}%{!?-k:*}-%{KVERREL}%{?3:+%{3}}.efi\ %{expand:%%files %{?3:%{3}-}uki-virt-addons}\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi.extra.d/ \ /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi.extra.d/*.addon.efi\ %endif\ %if %{?3:1} %{!?3:0}\ %{expand:%%files %{3}}\ %endif\ %if %{with_gcov}\ %ifnarch %nobuildarches noarch\ %{expand:%%files -f kernel-%{?3:%{3}-}gcov.list %{?3:%{3}-}gcov}\ %endif\ %endif\ %endif\ %{nil} %kernel_variant_files %{_use_vdso} %{with_up_base} %if %{with_up} %kernel_variant_files %{_use_vdso} %{with_debug} debug %endif %if %{with_arm64_16k} %kernel_variant_files %{_use_vdso} %{with_debug} 16k-debug %endif %if %{with_arm64_64k} %kernel_variant_files %{_use_vdso} %{with_debug} 64k-debug %endif %kernel_variant_files %{_use_vdso} %{with_realtime_base} rt %if %{with_realtime} %kernel_variant_files %{_use_vdso} %{with_debug} rt-debug %endif %kernel_variant_files %{_use_vdso} %{with_automotive_base} automotive %if %{with_automotive} && !%{with_automotive_build} %kernel_variant_files %{_use_vdso} %{with_debug} automotive-debug %endif %if %{with_debug_meta} %files debug %files debug-core %files debug-devel %files debug-devel-matched %files debug-modules %files debug-modules-core %files debug-modules-extra %if %{with_arm64_16k} %files 16k-debug %files 16k-debug-core %files 16k-debug-devel %files 16k-debug-devel-matched %files 16k-debug-modules %files 16k-debug-modules-extra %endif %if %{with_arm64_64k} %files 64k-debug %files 64k-debug-core %files 64k-debug-devel %files 64k-debug-devel-matched %files 64k-debug-modules %files 64k-debug-modules-extra %endif %endif %kernel_variant_files %{_use_vdso} %{with_zfcpdump} zfcpdump %kernel_variant_files %{_use_vdso} %{with_arm64_16k_base} 16k %kernel_variant_files %{_use_vdso} %{with_arm64_64k_base} 64k %kernel_variant_files %{_use_vdso} %{with_realtime_arm64_64k_base} rt-64k %if %{with_realtime_arm64_64k} %kernel_variant_files %{_use_vdso} %{with_debug} rt-64k-debug %endif %ifnarch noarch %{nobuildarches} %files modules-extra-matched %endif # plz don't put in a version string unless you're going to tag # and build. # # %changelog * Wed Oct 07 2026 Correlophus Ciliatus [6.12.0-274.rk35x.1.el10] - gitlab-ci: add pipeline to generate source rpm (Luca Magrone) - arm64: dts: rockchip: Move rk356x scmi SHMEM to reserved memory (Chukun Pan) - arm64: dts: rockchip: Add new SoC dtsi for the RK3566T variant (Dragan Simic) - arm64: dts: rockchip: Prepare RK356x SoC dtsi files for per-variant OPPs (Dragan Simic) - arm64: dts: rockchip: Update CPU OPP voltages in RK356x SoC dtsi (Dragan Simic) - drm/rockchip: Switch to drm_atomic_get_new_crtc_state() (Maxime Ripard) - drm/rockchip: vop2: Check bpc before switching DCLK source (Cristian Ciocaltea) - drm/rockchip: include drm_print.h where needed (Jani Nikula) - drm/rockchip: Set VOP for the DRM DMA device (Dmitry Osipenko) - drm: rockchip,panfrost: include drm_print.h (Luca Magrone) - redhat: configs: custom-overrides: aarch64: add new Mediatek configs (Luca Magrone) - PCI: dw-rockchip: Switch to FIELD_PREP_WM16 macro (Nicolas Frattaroli) - iommu: rockchip: Pass in old domain to attach_dev (Luca Magrone) - bitmap: introduce hardware-specific bitfield operations (Nicolas Frattaroli) - redhat: adopt derivative kernel build 'rk35x' (Luca Magrone) - drm/{panfrost,v3d}: Store the drm client_id in drm_sched_fence (Luca Magrone) - drm/panfrost: Use DRM_GPU_SCHED_STAT_NO_HANG to skip the reset (Maíra Canal) - drm/panfrost: Rename DRM_GPU_SCHED_STAT_NOMINAL to DRM_GPU_SCHED_STAT_RESET (Luca Magrone) - drm/gem/afbc: Eliminate redundant drm_get_format_info() (Ville Syrjälä) - drm/rockchip: Pass along the format info from .fb_create() to drm_helper_mode_fill_fb_struct() (Luca Magrone) - drm: Pass the format info to .fb_create() (Luca Magrone) - drm: Update drm_get_format_info() calls (Luca Magrone) - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed (Andy Yan) - iommu/rockchip: prevent iommus dead loop when two masters share one IOMMU (Simon Xue) - iommu/rockchip: Remove iommu_ops pgsize_bitmap (Luca Magrone) - iommu/rockchip: Remove iommu_free_page() (Luca Magrone) - redhat: Makefiles.variables: set RELEASE_LOCALVERSION to .0.rk35x (Luca Magrone) - redhat: configs: custom-overrides: aarch64: add new config lines as disabled (v6.16) (Luca Magrone) - drm/rockchip: dw_hdmi: Set cur_ctr to 0 always (Douglas Anderson) - drm/rockchip: dw_hdmi: Adjust cklvl & txlvl for RF/EMI (Yakir Yang) - drm/rockchip: dw_hdmi: Add phy_config for 594Mhz pixel clock (Nickey Yang) - drm/rockchip: Load crtc devices in preferred order (Jonas Karlman) - drm/rockchip: dw_hdmi: Enable 4K@60Hz mode on RK3399 and RK356x (Jonas Karlman) - drm/rockchip: dw_hdmi: Use auto-generated tables (Douglas Anderson) - drm/rockchip: dw_hdmi: Filter modes based on hdmiphy_clk (Jonas Karlman) - drm/rockchip: Fix a typo (Andrew Kreimer) - drm/rockchip: inno-hdmi: Fix video timing HSYNC/VSYNC polarity setting for rk3036 (Andy Yan) - drm/rockchip: inno-hdmi: Simplify error handler with dev_err_probe (Andy Yan) - drm/rockchip: rk3066_hdmi: switch to drm bridge (Andy Yan) - drm/rockchip: add CONFIG_OF dependency (Arnd Bergmann) - drm/rockchip: analogix_dp: Add support for RK3588 (Damon Ding) - drm/rockchip: analogix_dp: Add support to get panel from the DP AUX bus (Damon Ding) - drm/rockchip: dw_hdmi_qp: Fix io init for dw_hdmi_qp_rockchip_resume (Andy Yan) - drm/rockchip: vop2: Fix interface enable/mux setting of DP1 on rk3588 (Andy Yan) - drm/rockchip: vop: Consistently use rk3399 registers consts (Konstantin Shabanov) - drm/rockchip: vop2: Make overlay layer select register configuration take effect by vsync (Andy Yan) - drm/rockchip: vop: remove redundant condition check (Lucas Stach) - drm/rockchip: lvds: lower log severity for missing pinctrl settings (Heiko Stuebner) - drm/rockchip: lvds: Hide scary error messages on probe deferral (Heiko Stuebner) - drm/rockchip: lvds: move pclk preparation in with clk_get (Heiko Stuebner) - drm/rockchip: stop passing non struct drm_device to drm_err() and friends (Jani Nikula) - drm/rockchip: vop2: add missing bitfield.h include (Heiko Stuebner) - drm/rockchip: vop2: Add support for rk3576 (Andy Yan) - drm/rockchip: vop2: Add uv swap for cluster window (Andy Yan) - drm/rockchip: vop2: Set plane possible crtcs by possible vp mask (Andy Yan) - drm/rockchip: vop2: Register the primary plane and overlay plane separately (Andy Yan) - drm/rockchip: vop2: Consistently use dev_err_probe() (Cristian Ciocaltea) - drm/rockchip: vop2: Introduce vop hardware version (Andy Yan) - drm/rockchip: vop2: Support for different layer select configuration between VPs (Andy Yan) - drm/rockchip: vop2: Merge vop2_cluster/esmart_init function (Andy Yan) - drm/rockchip: vop2: Add platform specific callback (Andy Yan) - drm/rockchip: vop2: Remove AFBC from TRANSFORM_OFFSET register macro (Andy Yan) - drm/rockchip: vop2: use devm_regmap_field_alloc for cluster-regs (Andy Yan) - drm/rockchip: Fix shutdown when no drm-device is set up (Heiko Stuebner) - drm/rockchip: vop2: Improve display modes handling on RK3588 HDMI1 (Cristian Ciocaltea) - drm/rockchip: analogix_dp: Expand device data to support multiple edp display (Damon Ding) - drm/rockchip: analogix_dp: Use formalized struct definition for grf field (Damon Ding) - drm/atomic: Let drivers decide which planes to async flip (André Almeida) - drm/rockchip: vop2: Improve display modes handling on RK3588 HDMI0 (Cristian Ciocaltea) - drm/rockchip: vop2: Drop unnecessary if_pixclk_rate computation (Cristian Ciocaltea) - drm/rockchip: Don't change hdmi reference clock rate (Derek Foreman) - drm/connector: continue making mode_valid take a const struct drm_display_mode (Luca Magrone) - drm/rockchip: dw_hdmi_qp: Add basic RK3576 HDMI output support (Andy Yan) - drm/rockchip: dw_hdmi_qp: Add platform ctrl callback (Andy Yan) - drm/rockchip: vop2: Support 32x8 superblock afbc (Andy Yan) - drm/rockchip: vop2: include rockchip_drm_drv.h (Min-Hua Chen) - drm/rockchip: vop2: Add check for 32 bpp format for rk3588 (Andy Yan) - drm/rockchip: vop2: Check linear format for Cluster windows on rk3566/8 (Andy Yan) - drm/rockchip: vop2: Setup delay cycle for Esmart2/3 (Andy Yan) - drm/rockchip: vop2: Set AXI id for rk3588 (Andy Yan) - drm/rockchip: vop2: Fix the windows switch between different layers (Andy Yan) - drm/rockchip: vop2: Add debugfs support (Andy Yan) - drm/rockchip: Fix Copyright description (Andy Yan) - drm/rockchip: dw_hdmi_qp: Simplify clock handling (Cristian Ciocaltea) - drm/rockchip: vop2: don't check color_mgmt_changed in atomic_enable (Piotr Zalewski) - drm/rockchip: Remove unnecessary checking (Guoqing Jiang) - drm/rockchip: dw_hdmi_qp: Add support for RK3588 HDMI1 output (Cristian Ciocaltea) - drm/rockchip: vop2: Fix the mixer alpha setup for layer 0 (Andy Yan) - drm/rockchip: vop2: Fix cluster windows alpha ctrl regsiters offset (Andy Yan) - drm/rockchip: Add MIPI DSI2 glue driver for RK3588 (Heiko Stuebner) - drm/rockchip: vop2: fix rk3588 dp+dsi maxclk verification (Heiko Stuebner) - drm/rockchip: avoid 64-bit division (Arnd Bergmann) - drm/rockchip: analogix_dp: allow to work without panel (Lucas Stach) - rockchip/drm: vop2: add support for gamma LUT (Piotr Zalewski) - drm/rockchip: vop2: Don't spam logs in atomic update (Andy Yan) - drm/rockchip: cdn-dp: Use drm_connector_helper_hpd_irq_event() (Thomas Zimmermann) - drm/rockchip: Add basic RK3588 HDMI output support (Cristian Ciocaltea) - drm/{rockchip,panfrost}: change 'remove_new' to 'remove' (Luca Magrone) - drm/panfrost: Add GPU ID for MT8188 Mali-G57 MC3 (AngeloGioacchino Del Regno) - drm/panfrost: Remove unused id_mask from struct panfrost_model (Steven Price) - drm/panfrost: Add SYSTEM_TIMESTAMP and SYSTEM_TIMESTAMP_FREQUENCY parameters (Mary Guillemard) - drm/panfrost: Add missing OPP table refcnt decremental (Adrián Larumbe) - drm/panfrost: Fix scheduler workqueue bug (Philipp Stanner) - drm/panfrost: reorder pd/clk/rst sequence (Philippe Simons) - drm/panfrost: add h616 compatible string (Philippe Simons) - drm/panfrost: Add PM runtime flag (Philippe Simons) - drm/panfrost: Test for imported buffers with drm_gem_is_imported() (Thomas Zimmermann) - drm/panfrost: Force AARCH64_4K page table format on MediaTek MT8192 (Ariel D'Alessandro) - drm/panfrost: Force AARCH64_4K page table format on MediaTek MT8188 (Ariel D'Alessandro) - drm/panfrost: Add support for AARCH64_4K page table format (Ariel D'Alessandro) - drm/panfrost: Set HW_FEATURE_AARCH64_MMU feature flag on Bifrost models (Ariel D'Alessandro) - drm/panfrost: Use GPU_MMU_FEATURES_VA_BITS/PA_BITS macros (Ariel D'Alessandro) - drm/panfrost: Set IOMMU_CACHE flag (Ariel D'Alessandro) - drm/{lima,panfrost}: Use refcount_t for pages_use_count (Luca Magrone) - drm/shmem-helper: continue refactoring locked/unlocked functions (Luca Magrone) - drm/gem: Change locked/unlocked postfix of drm_gem_v/unmap() function names (Dmitry Osipenko) - redhat: configs: custom-overrides: aarch64: explicitly disable SND_SOC_ROCKCHIP_SAI (Luca Magrone) - iommu/rockchip: Retire global dma_dev workaround (Robin Murphy) - iommu/rockchip: Register in a sensible order (Robin Murphy) - iommu/rockchip: Allocate per-device data sensibly (Robin Murphy) - drm/panfrost: fix drm_sched_init() params (Luca Magrone) - drm/rockchip: stop passing non struct drm_device to drm_err() and friends (Luca Magrone) - redhat: configs: custom-overrides: rename RK808 to RK8XX (Luca Magrone) - redhat: configs: custom-overrides: move configs from arm to aarch64 (Luca Magrone) - redhat: do not bump release (Luca Magrone) - drm/sched: add optional errno to some drm_sched_start() calls (Luca Magrone) - drm/panfrost: Add cycle counter job requirement (Mary Guillemard) - drm: remove driver date from struct drm_driver and all drivers (Jani Nikula) - drm/rockchip: fix drm_client_setup.h header path (Luca Magrone) - drm/rockchip: Use video aperture helpers (Thomas Zimmermann) - drm/rockchip: Run DRM default client setup (Thomas Zimmermann) - crypto: rockchip: add rk3588 driver (Corentin Labbe) - reset: rockchip: secure reset must be used by SCMI (Corentin Labbe) - ARM64: dts: rk356x: add crypto node (Corentin Labbe) - ARM64: dts: rk3588: add crypto node (Corentin Labbe) - MAINTAINERS: add new dt-binding doc to the right entry (Corentin Labbe) - dt-bindings: crypto: add support for rockchip,crypto-rk3588 (Corentin Labbe) - redhat: configs: custom-overrides: aarch64: enable sm3_generic (Luca Magrone) - redhat: configs: custom-overrides: aarch64: fix mismatched configuration entries (Luca Magrone) - redhat: configs: custom-overrides: aarch64: make mmcblk built-in (Luca Magrone) - redhat: configs: custom-overrides: aarch64: add missing config entries (Luca Magrone) - redhat: configs: compile drm stack as a module (Luca Magrone) - redhat: configs: update SND configs and DRM_KMS_HELPERS (Luca Magrone) - redhat: configs: build rockchip drm and panfrost as modules (Luca Magrone) - redhat: configs: add required options (Luca Magrone) - redhat: configs: disable AST server chips (Luca Magrone) - redhat: configs: remove CONFIG_CONFIG_ARCH_ROCKCHIP (Luca Magrone) - redhat: configs: use the same configs as last working version (Luca Magrone) - Add configuration entries for Quartz64 (Luca Magrone) * Mon Oct 05 2026 CKI KWF Bot [6.12.0-274.el10] - smb: client: reject a tree connect response whose byte count is too small (CKI Backport Bot) [RHEL-271295] {CVE-2026-89631} - cpufreq: intel_pstate: Avoid using DESIRED_PERF when DEC is enabled (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Consolidate HWP P-states initialization (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Adjust policy->cur in active mode to policy (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Move two functions closer to callers (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Consolidate frequency values computation (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Introduce intel_pstate_update_freq_limits() (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Fix setting minimum P-state at init time (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Rename INTEL_PSTATE_HWP_BROADWELL (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Simplify HWP handling on Broadwell (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Rearrange checks in hybrid_get_cost() (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Improve warning message on HWP-disabled hybrid CPUs (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (Dennis Chen) [RHEL-242438] - cpufreq: intel_pstate: Allow repeated intel_pstate disable (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'wrmsrl_on_cpu()' to 'wrmsrq_on_cpu()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'rdmsrl_on_cpu()' to 'rdmsrq_on_cpu()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'rdmsrl_safe_on_cpu()' to 'rdmsrq_safe_on_cpu()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'wrmsrl_safe()' to 'wrmsrq_safe()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'rdmsrl_safe()' to 'rdmsrq_safe()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'wrmsrl()' to 'wrmsrq()' [partial] (Dennis Chen) [RHEL-242438] - x86/msr: Rename 'rdmsrl()' to 'rdmsrq()' [partial] (Dennis Chen) [RHEL-242438] - net: tun: bound receive headroom (CKI Backport Bot) [RHEL-264379] {CVE-2026-81000} - redhat/configs: automotive: disable CONFIG_CRYPTO_DEV_TEGRA (Erico Nunes) [RHEL-256830] - redhat/configs: automotive: disable CONFIG_CRYPTO_DEV_VIRTIO (Erico Nunes) [RHEL-256830] - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (CKI Backport Bot) [RHEL-254626] {CVE-2026-74574} - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CKI Backport Bot) [RHEL-254536] {CVE-2026-74516} - ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CKI Backport Bot) [RHEL-254423] {CVE-2026-74669} - eth: bnxt: improve the timing of stats (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix NULL pointer dereference (Anirudh Virdi) [RHEL-135356] - Reapply "bnxt_en: bring back rtnl_lock() in the bnxt_open() path" (Anirudh Virdi) [RHEL-135356] - eth: bnxt: disable rx-copybreak by default (Anirudh Virdi) [RHEL-135356] - bnxt_en: Drop pci_save_state() after pci_restore_state() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Use absolute target ns from ptp_clock_request (Anirudh Virdi) [RHEL-135356] - bnxt_en: Check return value of bnxt_hwrm_vnic_cfg (Anirudh Virdi) [RHEL-135356] - bnxt_en: Set bp->max_tpa according to what the FW supports (Anirudh Virdi) [RHEL-135356] - bnxt_en: Delay for 5 seconds after AER DPC for all chips (Anirudh Virdi) [RHEL-135356] - net: bnxt: Add TX inline buffer infrastructure (Anirudh Virdi) [RHEL-135356] - net: bnxt: Use dma_unmap_len for TX completion unmapping (Anirudh Virdi) [RHEL-135356] - net: bnxt: Add a helper for tx_bd_ext (Anirudh Virdi) [RHEL-135356] - net: bnxt: Export bnxt_xmit_get_cfa_action (Anirudh Virdi) [RHEL-135356] - bnxt_en: Restore default stat ctxs for ULP when resource is available (Anirudh Virdi) [RHEL-135356] - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Refactor some basic ring setup and adjustment logic (Anirudh Virdi) [RHEL-135356] - bnxt_en: set backing store type from query type (Anirudh Virdi) [RHEL-135356] - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (Anirudh Virdi) [RHEL-135356] - bnxt_en: Move bnxt_rss_ext_op into header (Anirudh Virdi) [RHEL-135356] - bnxt_en: Implement XDP RSS hash metadata extraction (Anirudh Virdi) [RHEL-135356] - bnxt_en: use bnxt_xdp_buff for xdp context (Anirudh Virdi) [RHEL-135356] - fwctl/bnxt_en: Create an aux device for fwctl (Anirudh Virdi) [RHEL-135356] - fwctl/bnxt_en: Refactor aux bus functions to be more generic (Anirudh Virdi) [RHEL-135356] - fwctl/bnxt_en: Move common definitions to include/linux/bnxt/ (Anirudh Virdi) [RHEL-135356] - bnxt_en: Resize RSS contexts on channel count change (Anirudh Virdi) [RHEL-135356] - bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix RSS table size check when changing ethtool channels (Anirudh Virdi) [RHEL-135356] - eth: bnxt: rename ring_err_stats -> ring_drv_stats (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix deleting of Ntuple filters (Anirudh Virdi) [RHEL-135356] - bnxt_en: Check RSS contexts in bnxt_need_reserve_rings() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Refactor bnxt_need_reserve_rings() (Anirudh Virdi) [RHEL-135356] - eth: bnxt: gather and report HW-GRO stats (Anirudh Virdi) [RHEL-135356] - bnxt_en: Allow ntuple filters for drops (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix build break on non-x86 platforms (Anirudh Virdi) [RHEL-135356] - bnxt_en: Implement ethtool_ops -> get_link_ext_state() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Use a larger RSS indirection table on P5_PLUS chips (Anirudh Virdi) [RHEL-135356] - bnxt_en: Add PTP .getcrosststamp() interface to get device/host times (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix NULL pointer crash in bnxt_ptp_enable during error cleanup (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix potential data corruption with HW GRO/LRO (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix XDP_TX path (Anirudh Virdi) [RHEL-135356] - net: bnxt: extract GRXRINGS from .get_rxnfc (Anirudh Virdi) [RHEL-135356] - bnxt_en: Add Virtual Admin Link State Support for VFs (Anirudh Virdi) [RHEL-135356] - bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips (Anirudh Virdi) [RHEL-135356] - bnxt_en: Add CQ ring dump to bnxt_dump_cp_sw_state() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Remove the redundant BNXT_EN_FLAG_MSIX_REQUESTED flag (Anirudh Virdi) [RHEL-135356] - bnxt_en: Enhance log message in bnxt_get_module_status() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Enhance TX pri counters (Anirudh Virdi) [RHEL-135356] - eth: bnxt: make use of napi_consume_skb() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix warning in bnxt_dl_reload_down() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Always provide max entry and entry size in coredump segments (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() (Anirudh Virdi) [RHEL-135356] - bnxt_en: Fix a possible memory leak in bnxt_ptp_init (Anirudh Virdi) [RHEL-135356] - bnxt_en: Shutdown FW DMA in bnxt_shutdown() (Anirudh Virdi) [RHEL-135356] - bnxt_en: support PPS in/out on all pins (Anirudh Virdi) [RHEL-135356] - bnxt_en: Enhance stats context reservation logic (Anirudh Virdi) [RHEL-135356] - eth: bnxt: support RSS on IPv6 Flow Label (Anirudh Virdi) [RHEL-135356] - redhat/configs: automotive: enable USB_CHIPIDEA_IMX (Jared Kangas) [RHEL-154111] * Thu Oct 01 2026 CKI KWF Bot [6.12.0-273.el10] - redhat: configs: rhel: Enable AMD XDNA config (Marco Pagani) [RHEL-259222] - crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (Ricardo Robaina) [RHEL-264233] {CVE-2025-39964} - crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (Ricardo Robaina) [RHEL-264233] {CVE-2025-39964} - xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264307] {CVE-2026-80844} - scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CKI Backport Bot) [RHEL-262561] {CVE-2026-89846} - mac802154: llsec: add skb_cow_data() before in-place crypto (CKI Backport Bot) [RHEL-231031] {CVE-2026-63831} - proc: protect ptrace_may_access() with exec_update_lock (FD links) (CKI Backport Bot) [RHEL-259924] {CVE-2026-64375} - proc: rename proc_setattr to proc_nochmod_setattr (CKI Backport Bot) [RHEL-259924] {CVE-2026-64375} - io_uring/poll: fix signed comparison in io_poll_get_ownership() (Jeff Moyer) [RHEL-227114] {CVE-2026-52933} - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (Mark Salter) [RHEL-239373] - arm64: tlb: Allow XZR argument to TLBI ops (Mark Salter) [RHEL-239373] - block: Fix start and length check added to iov_iter_extract_bvecs() (David Jeffery) [RHEL-246814] - block: validate user space vectors during extraction (David Jeffery) [RHEL-246814] - loop, zloop: fix dma_alignment for large or unreported limits (David Jeffery) [RHEL-246814] - loop: Fix recently introduced lock inversion (David Jeffery) [RHEL-246814] - zloop: set dma_alignment from the backing files for direct I/O (David Jeffery) [RHEL-246814] - loop: set dma_alignment from the backing file for direct I/O (David Jeffery) [RHEL-246814] - block: fix dio leak on metadata mapping error (David Jeffery) [RHEL-246814] - block: use blkdev_iov_iter_get_pages status for errors (David Jeffery) [RHEL-246814] - block: add a bio_endio_status helper (David Jeffery) [RHEL-246814] - block: don't set BIO_QUIET for BLK_STS_AGAIN (David Jeffery) [RHEL-246814] - bnxt_en: Gate TPH enablement behind BNXT_SUPPORTS_QUEUE_API check (CKI Backport Bot) [RHEL-235458] - hwrng: virtio: clamp device-reported used.len at copy_data() (CKI Backport Bot) [RHEL-225745] {CVE-2026-64456} - KVM: s390: Remove user triggerable WARN_ON (Cornelia Huck) [RHEL-136456] - KVM: s390: Fall back to short-term pinning in MAP ioctl (Cornelia Huck) [RHEL-136456] - KVM: s390: Introducing kvm_arch_set_irq_inatomic fast inject (Cornelia Huck) [RHEL-136456] - KVM: s390: Enable adapter_indicators_set to use mapped pages (Cornelia Huck) [RHEL-136456] - KVM: s390: Add map/unmap ioctl and clean mappings post-guest (Cornelia Huck) [RHEL-136456] - KVM: s390: Use guest address to mark guest page dirty (Cornelia Huck) [RHEL-136456] - ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-237202] {CVE-2026-68200} - ALSA: timer: drain a slave's callback before its master detaches it (CKI Backport Bot) [RHEL-236079] {CVE-2026-68201} - KEYS: fix overflow in keyctl_pkey_params_get_2() (Bruno Meneguele) [RHEL-229617] {CVE-2026-63824} - net: hsr: fix potential OOB access in supervision frame handling (Toke Høiland-Jørgensen) [RHEL-227932] {CVE-2026-64000} - ipvlan: Make the addrs_lock be per port (Toke Høiland-Jørgensen) [RHEL-246119] {CVE-2026-23103} - packet: use consistent hard_header_len in TX_RING send path (Toke Høiland-Jørgensen) [RHEL-244534] - packet: use consistent hard_header_len in non-ring send paths (Toke Høiland-Jørgensen) [RHEL-244534] {CVE-2026-74582} - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (Toke Høiland-Jørgensen) [RHEL-244534] {CVE-2026-31700} - net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Toke Høiland-Jørgensen) [RHEL-244534] - Revert "wireguard: device: enable threaded NAPI" (Toke Høiland-Jørgensen) [RHEL-226530] {CVE-2026-52945} - ipv6: sit: reload inner IPv6 header after GSO offloads (Toke Høiland-Jørgensen) [RHEL-225919] {CVE-2026-53228} - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Toke Høiland-Jørgensen) [RHEL-228945] {CVE-2026-63921} - ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Toke Høiland-Jørgensen) [RHEL-231747] {CVE-2026-63917} - pppoe: reload header pointer after dev_hard_header() (Toke Høiland-Jørgensen) [RHEL-242510] {CVE-2026-68121} - ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (Toke Høiland-Jørgensen) [RHEL-248848] {CVE-2026-68398} - ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Toke Høiland-Jørgensen) [RHEL-228007] {CVE-2026-53075} - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Toke Høiland-Jørgensen) [RHEL-231710] {CVE-2026-63993} - vxlan: require CAP_NET_ADMIN in the device netns for changelink (Toke Høiland-Jørgensen) [RHEL-239730] {CVE-2026-68432} - net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Toke Høiland-Jørgensen) [RHEL-247006] {CVE-2026-72052} - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Toke Høiland-Jørgensen) [RHEL-247057] {CVE-2026-63829} - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Toke Høiland-Jørgensen) [RHEL-230773] {CVE-2026-63992} - macsec: fix replay protection at XPN lower-PN wrap (Toke Høiland-Jørgensen) [RHEL-226667] {CVE-2026-63925} - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (Toke Høiland-Jørgensen) [RHEL-227468] {CVE-2026-63918} - xfrm: fix stale skb->prev after async crypto steals a GSO segment (Toke Høiland-Jørgensen) [RHEL-236118] {CVE-2026-68426} - xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (Toke Høiland-Jørgensen) [RHEL-236118] - xfrm: Fix dev use-after-free in xfrm async resumption (Toke Høiland-Jørgensen) [RHEL-233036] {CVE-2026-72463} - xfrm: hold dev ref until after transport_finish NF_HOOK (Toke Høiland-Jørgensen) [RHEL-233036] {CVE-2026-31663} - xfrm: hold device only for the asynchronous decryption (Toke Høiland-Jørgensen) [RHEL-233036] - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Toke Høiland-Jørgensen) [RHEL-228011] {CVE-2026-53239} - xfrm: input: hold netns during deferred transport reinjection (Toke Høiland-Jørgensen) [RHEL-227503] {CVE-2026-63919} - xfrm: route MIGRATE notifications to caller's netns (Toke Høiland-Jørgensen) [RHEL-225768] {CVE-2026-63914} - xfrm: espintcp: do not reuse an in-progress partial send (Toke Høiland-Jørgensen) [RHEL-222977] {CVE-2026-52935} - net/handshake: Drain pending requests at net namespace exit (Toke Høiland-Jørgensen) [RHEL-232141] {CVE-2026-63978} - net/handshake: Verify file-reference balance in submit paths (Toke Høiland-Jørgensen) [RHEL-230366] - net/handshake: Close the submit-side sock_hold race (Toke Høiland-Jørgensen) [RHEL-230366] - net/handshake: hand off the pinned file reference to accept_doit (Toke Høiland-Jørgensen) [RHEL-230366] {CVE-2026-63979} - net/handshake: Take a long-lived file reference at submit (Toke Høiland-Jørgensen) [RHEL-234163] {CVE-2026-64523} - net/handshake: Pass negative errno through handshake_complete() (Toke Høiland-Jørgensen) [RHEL-230366] - nvme-tcp: store negative errno in queue->tls_err (Toke Høiland-Jørgensen) [RHEL-230366] - net/handshake: Use spin_lock_bh for hn_lock (Toke Høiland-Jørgensen) [RHEL-230366] {CVE-2026-63980} - net/handshake: Fix null-ptr-deref in handshake_complete() (Toke Høiland-Jørgensen) [RHEL-230366] - net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE() (Toke Høiland-Jørgensen) [RHEL-230366] - file: ensure cleanup (Toke Høiland-Jørgensen) [RHEL-230366] - file: add FD_{ADD,PREPARE}() (Toke Høiland-Jørgensen) [RHEL-230366] - remove pointless includes of (Toke Høiland-Jørgensen) [RHEL-230366] - tools: ynl: add scope qualifier for definitions (Toke Høiland-Jørgensen) [RHEL-230366] - redhat/genlog: exclude only the merged branch of an excluded merge (Oleksii Baranov) - powerpc/pseries/htmdump: Add memory configuration dump support to htmdump module (Mamatha Inamdar) [RHEL-191925] - powerpc/pseries/htmdump: Fix the offset value used in htm status dump (Mamatha Inamdar) [RHEL-191925] - powerpc/pseries/htmdump: Fix the offset value used in processor configuration dump (Mamatha Inamdar) [RHEL-191925] - powerpc/pseries/htmdump: Free the global buffers in htmdump module exit (Mamatha Inamdar) [RHEL-191925] - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for EMC Symmetrix (Ewan D. Milne) [RHEL-272827] - redhat/configs: Enable CONFIG_TRUSTED_KEYS_PKWM (Mamatha Inamdar) [RHEL-191904] - powerpc/pseries: plpks: export plpks_wrapping_is_supported (Mamatha Inamdar) [RHEL-191904] - docs: trusted-encryped: add PKWM as a new trust source (Mamatha Inamdar) [RHEL-191904] - keys/trusted_keys: establish PKWM as a trusted source (Mamatha Inamdar) [RHEL-191904] - pseries/plpks: add HCALLs for PowerVM Key Wrapping Module (Mamatha Inamdar) [RHEL-191904] - pseries/plpks: expose PowerVM wrapping features via the sysfs (Mamatha Inamdar) [RHEL-191904] - powerpc/pseries: move the PLPKS config inside its own sysfs directory (Mamatha Inamdar) [RHEL-191904] - pseries/plpks: fix kernel-doc comment inconsistencies (Mamatha Inamdar) [RHEL-191904] - powerpc/crash: stop watchdogs before booting kdump kernel (Mamatha Inamdar) [RHEL-251771] - powerpc/pseries: Handle and log pseries-wdt registration failures (Mamatha Inamdar) [RHEL-251771] - powerpc/pseries: Move H_WATCHDOG definitions to a common header (Mamatha Inamdar) [RHEL-251771] - KVM: arm64: Remove extra ISBs when using msr_hcr_el2 (Gustavo Romero) [RHEL-216299] - dm-integrity: don't increment hash_offset twice (CKI Backport Bot) [RHEL-257778] {CVE-2026-72099} - add man-page for rv-mon-stall (Gabriele Monaco) [RHEL-151924] - redhat/configs: rv: Explicitly set hybrid automata (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Fix ltl2k writing True as a literal (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Fix options shared among commands (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Fix suffix strip in dot2k (Gabriele Monaco) [RHEL-151924] - tools/rv: Fix cleanup after failed trace setup (Gabriele Monaco) [RHEL-151924] - tools/rv: Fix substring match when listing container monitors (Gabriele Monaco) [RHEL-151924] - tools/rv: Fix substring match bug in monitor name search (Gabriele Monaco) [RHEL-151924] - tools/rv: Ensure monitor name and desc are NUL-terminated (Gabriele Monaco) [RHEL-151924] - rv: Use 0 to check preemption enabled in opid (Gabriele Monaco) [RHEL-151924] - rv: Prevent task migration while handling per-CPU events (Gabriele Monaco) [RHEL-151924] - rv: Ensure synchronous cleanup for HA monitors (Gabriele Monaco) [RHEL-151924] - rv: Add automatic cleanup handlers for per-task HA monitors (Gabriele Monaco) [RHEL-151924] - rv: Do not rely on clean monitor when initialising HA (Gabriele Monaco) [RHEL-151924] - rv: Fix monitor start ordering and memory ordering for monitoring flag (Gabriele Monaco) [RHEL-151924] - rv: Ensure all pending probes terminate on per-obj monitor destroy (Gabriele Monaco) [RHEL-151924] - rv: Prevent in-flight per-task handlers from using invalid slots (Gabriele Monaco) [RHEL-151924] - rv: Reset per-task DA monitors before releasing the slot (Gabriele Monaco) [RHEL-151924] - rv: Fix __user specifier usage in extract_params() (Gabriele Monaco) [RHEL-151924] - Documentation/rv: Replace stale website link (Gabriele Monaco) [RHEL-151924] - rv: Allow epoll in rtapp-sleep monitor (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix _fill_states() return type annotation (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix unbound loop variable warning (Gabriele Monaco) [RHEL-151924] - rv/rvgen: enforce presence of initial state (Gabriele Monaco) [RHEL-151924] - rv/rvgen: extract node marker string to class constant (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix isinstance check in Variable.expand() (Gabriele Monaco) [RHEL-151924] - rv/rvgen: make monitor arguments required in rvgen (Gabriele Monaco) [RHEL-151924] - rv/rvgen: remove unused __get_main_name method (Gabriele Monaco) [RHEL-151924] - rv/rvgen: remove unused sys import from dot2c (Gabriele Monaco) [RHEL-151924] - rv/rvgen: refactor automata.py to use iterator-based parsing (Gabriele Monaco) [RHEL-151924] - rv/rvgen: use class constant for init marker (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix DOT file validation logic error (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix PEP 8 whitespace violations (Gabriele Monaco) [RHEL-151924] - rv/rvgen: fix typos in automata and generator docstring and comments (Gabriele Monaco) [RHEL-151924] - rv/rvgen: use context managers for file operations (Gabriele Monaco) [RHEL-151924] - rv/rvgen: remove unnecessary semicolons (Gabriele Monaco) [RHEL-151924] - rv/rvgen: replace __len__() calls with len() (Gabriele Monaco) [RHEL-151924] - rv/rvgen: replace %% string formatting with f-strings (Gabriele Monaco) [RHEL-151924] - rv/rvgen: remove bare except clauses in generator (Gabriele Monaco) [RHEL-151924] - rv/rvgen: introduce AutomataError exception class (Gabriele Monaco) [RHEL-151924] - rv: Add nomiss deadline monitor (Gabriele Monaco) [RHEL-151924] - sched/deadline: Move some utility functions to deadline.h (Gabriele Monaco) [RHEL-151924] - sched: Add deadline tracepoints (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Add support for per-obj monitors (Gabriele Monaco) [RHEL-151924] - rv: Add support for per-object monitors in DA/HA (Gabriele Monaco) [RHEL-151924] - rv: Convert the opid monitor to a hybrid automaton (Gabriele Monaco) [RHEL-151924] - rv: Add sample hybrid monitor stall (Gabriele Monaco) [RHEL-151924] - Documentation/rv: Add documentation about hybrid automata (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Add support for Hybrid Automata (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Allow spaces in and events strings (Gabriele Monaco) [RHEL-151924] - rv: Add Hybrid Automata monitor type (Gabriele Monaco) [RHEL-151924] - rv: Unify DA event handling functions across monitor types (Gabriele Monaco) [RHEL-151924] - rv: Fix multiple definition of __pcpu_unique_da_mon_this (Gabriele Monaco) [RHEL-151924] - rv: Fix documentation reference in da_monitor.h (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Remove unused variable declaration from containers (Gabriele Monaco) [RHEL-151924] - verification/dot2c: Remove superfluous enum assignment and add last comma (Gabriele Monaco) [RHEL-151924] - verification/dot2c: Remove __buff_to_string() and cleanup (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Annotate DA functions with types (Gabriele Monaco) [RHEL-151924] - verification/rvgen: Adapt dot2k and templates after refactoring da_monitor.h (Gabriele Monaco) [RHEL-151924] - Documentation/rv: Adapt documentation after da_monitor refactoring (Gabriele Monaco) [RHEL-151924] - rv: Cleanup da_monitor after refactor (Gabriele Monaco) [RHEL-151924] - rv: Refactor da_monitor to minimise macros (Gabriele Monaco) [RHEL-151924] - Documentation/rv: Fix dead link to monitor_synthesis.rst (Gabriele Monaco) [RHEL-151924] - rv: Fix compilation if !CONFIG_RV_REACTORS (Gabriele Monaco) [RHEL-151924] - rv: Convert to use __free (Gabriele Monaco) [RHEL-151924] - rv: Convert to use lock guard (Gabriele Monaco) [RHEL-151924] - rv: Add explicit lockdep context for reactors (Gabriele Monaco) [RHEL-151924] - rv: Make rv_reacting_on() static (Gabriele Monaco) [RHEL-151924] - rv: Pass va_list to reactors (Gabriele Monaco) [RHEL-151924] - selftests/tracing: Fix to make --logdir option work again (Gabriele Monaco) [RHEL-151924] - selftests/verification: Add initial RV tests (Gabriele Monaco) [RHEL-151924] - selftest/ftrace: Generalise ftracetest to use with RV (Gabriele Monaco) [RHEL-151924] - iommu/vt-d: Simplify calculate_psi_aligned_address() (Jerry Snitselaar) [RHEL-214191] - iommufd: Take dma_resv lock before dma_buf_unpin() in release path (Jerry Snitselaar) [RHEL-214191] - dma-direct: fix use of max_pfn (Jerry Snitselaar) [RHEL-214191] - dma-mapping: introduce DMA_ATTR_CC_SHARED for shared memory (Jerry Snitselaar) [RHEL-214191] - dma: contiguous: Export dev_get_cma_area() (Jerry Snitselaar) [RHEL-214191] - dma: contiguous: Make dma_contiguous_default_area static (Jerry Snitselaar) [RHEL-214191] - dma: contiguous: Make dev_get_cma_area() a proper function (Jerry Snitselaar) [RHEL-214191] - dma: contiguous: Turn heap registration logic around (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: rework fdt_init_reserved_mem_node() (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: clarify fdt_scan_reserved_mem*() functions (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: rearrange code a bit (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: replace CMA quirks by generic methods (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: switch to ops based OF_DECLARE() (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: use -ENODEV instead of -ENOENT (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: remove fdt node from the structure (Jerry Snitselaar) [RHEL-214191] - of/reserved_mem: Simplify the logic of __reserved_mem_alloc_size() (Jerry Snitselaar) [RHEL-214191] - of/reserved_mem: Simplify the logic of fdt_scan_reserved_mem_reg_nodes() (Jerry Snitselaar) [RHEL-214191] - of/reserved_mem: Simplify the logic of __reserved_mem_reserve_reg() (Jerry Snitselaar) [RHEL-214191] - of/fdt: Fix the len check in early_init_dt_check_for_usable_mem_range() (Jerry Snitselaar) [RHEL-214191] - of/fdt: Fix the len check in early_init_dt_check_for_elfcorehdr() (Jerry Snitselaar) [RHEL-214191] - of/fdt: Consolidate duplicate code into helper functions (Jerry Snitselaar) [RHEL-214191] - of: reserved_mem: Fix placement of __free() annotation (Jerry Snitselaar) [RHEL-214191] - dma-mapping: fix false kernel-doc comment marker (Jerry Snitselaar) [RHEL-214191] - dma-mapping: Support batch mode for dma_direct_{map,unmap}_sg (Jerry Snitselaar) [RHEL-214191] - dma-mapping: Separate DMA sync issuing and completion waiting (Jerry Snitselaar) [RHEL-214191] - arm64: Provide dcache_inval_poc_nosync helper (Jerry Snitselaar) [RHEL-214191] - arm64: Provide dcache_clean_poc_nosync helper (Jerry Snitselaar) [RHEL-214191] - arm64: Provide dcache_by_myline_op_nosync helper (Jerry Snitselaar) [RHEL-214191] - iommufd: update outdated comment for renamed iommufd_hw_pagetable_alloc() (Jerry Snitselaar) [RHEL-214191] - iommufd: Constify struct dma_buf_attach_ops (Jerry Snitselaar) [RHEL-214191] - iommu/amd: Invalidate IRT cache for DMA aliases (Jerry Snitselaar) [RHEL-214191] - iommu/amd: Add NUMA node affinity for IOMMU log buffers (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Remove the remaining pages along the invalidation path (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Pass size_order to qi_desc_piotlb() not npages (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Split piotlb invalidation into range and all (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Remove dmar_writel() and dmar_writeq() (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Remove dmar_readl() and dmar_readq() (Jerry Snitselaar) [RHEL-214191] - iommufd/selftest: Test dirty tracking on PASID (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Support dirty tracking on PASID (Jerry Snitselaar) [RHEL-214191] - iommu/vt-d: Rename device_set_dirty_tracking() and pass dmar_domain pointer (Jerry Snitselaar) [RHEL-214191] - iommu/arm-smmu-v3: Update Arm errata (Jerry Snitselaar) [RHEL-214191] - iommufd: Add dma_buf_pin() (Jerry Snitselaar) [RHEL-214191] - iommu/dma: add support for DMA_ATTR_REQUIRE_COHERENT attribute (Jerry Snitselaar) [RHEL-214191] - dma-direct: prevent SWIOTLB path when DMA_ATTR_REQUIRE_COHERENT is set (Jerry Snitselaar) [RHEL-214191] - dma-mapping: Introduce DMA require coherency attribute (Jerry Snitselaar) [RHEL-214191] - dma-mapping: Clarify valid conditions for CPU cache line overlap (Jerry Snitselaar) [RHEL-214191] - iommu/io-pgtable: fix all kernel-doc warnings in io-pgtable.h (Jerry Snitselaar) [RHEL-214191] - rust: iommu: fix `srctree` link warning (Jerry Snitselaar) [RHEL-214191] - rust: iommu: add io_pgtable abstraction (Jerry Snitselaar) [RHEL-214191] - PCI: Suspend iommu function prior to resetting a device (Jerry Snitselaar) [RHEL-214191] - treewide: Replace kmalloc with kmalloc_obj for non-scalar types (Jerry Snitselaar) [RHEL-214191] - virtio: add missing kernel-doc for map and vmap members (Koushik Dutta) [RHEL-94833] - vduse: avoid adding implicit padding (Koushik Dutta) [RHEL-94833] - Documentation: Add documentation for VDUSE Address Space IDs (Koushik Dutta) [RHEL-94833] - vduse: bump version number (Koushik Dutta) [RHEL-94833] - vduse: add vq group asid support (Koushik Dutta) [RHEL-94833] - vduse: merge tree search logic of IOTLB_GET_FD and IOTLB_GET_INFO ioctls (Koushik Dutta) [RHEL-94833] - vduse: take out allocations from vduse_dev_alloc_coherent (Koushik Dutta) [RHEL-94833] - vduse: remove unused vaddr parameter of vduse_domain_free_coherent (Koushik Dutta) [RHEL-94833] - vduse: refactor vdpa_dev_add for goto err handling (Koushik Dutta) [RHEL-94833] - vhost: forbid change vq groups ASID if DRIVER_OK is set (Koushik Dutta) [RHEL-94833] - vdpa: document set_group_asid thread safety (Koushik Dutta) [RHEL-94833] - vduse: return internal vq group struct as map token (Koushik Dutta) [RHEL-94833] - vduse: add vq group support (Koushik Dutta) [RHEL-94833] - vduse: add v1 API definition (Koushik Dutta) [RHEL-94833] - vhost: move vdpa group bound check to vhost_vdpa (Koushik Dutta) [RHEL-94833] - virtio: fix map ops comment (Koushik Dutta) [RHEL-94833] - virtio: standardize Returns documentation style (Koushik Dutta) [RHEL-94833] - virtio: fix grammar in virtio_map_ops docs (Koushik Dutta) [RHEL-94833] - virtio: fix kernel-doc for mapping/free_coherent functions (Koushik Dutta) [RHEL-94833] - vduse: switch to use virtio map API instead of DMA API (Koushik Dutta) [RHEL-94833] - tools/virtio: Add DMA_MAPPING_ERROR and sg_dma_len api define for virtio test (Koushik Dutta) [RHEL-94833] - vdpa: introduce map ops (Koushik Dutta) [RHEL-94833] - vdpa: support virtio_map (Koushik Dutta) [RHEL-94833] - virtio: introduce map ops in virtio core (Koushik Dutta) [RHEL-94833] - virtio_ring: rename dma_handle to map_handle (Koushik Dutta) [RHEL-94833] - virtio: introduce virtio_map container union (Koushik Dutta) [RHEL-94833] - virtio: rename dma helpers (Koushik Dutta) [RHEL-94833] - virtio_ring: switch to use dma_{map|unmap}_page() (Koushik Dutta) [RHEL-94833] - virtio_ring: constify virtqueue pointer for DMA helpers (Koushik Dutta) [RHEL-94833] - virtio_ring: remove API virtqueue_set_dma_premapped (Koushik Dutta) [RHEL-94833] - virtio_ring: perform premapped operations based on per-buffer (Koushik Dutta) [RHEL-94833] - virtio_ring: packed: record extras for indirect buffers (Koushik Dutta) [RHEL-94833] - virtio_ring: split: record extras for indirect buffers (Koushik Dutta) [RHEL-94833] - virtio_ring: introduce vring_need_unmap_buffer (Koushik Dutta) [RHEL-94833] - virtio: Make vring_new_virtqueue support packed vring (Koushik Dutta) [RHEL-94833] - x86: uaccess: don't use runtime-const rewriting in modules (Waiman Long) [RHEL-213145] - x86/runtime-const: Add the RUNTIME_CONST_PTR assembly macro (Waiman Long) [RHEL-213145] - x86: use cmov for user address masking (Waiman Long) [RHEL-213145] - net: xdp: handle frags with unreadable memory (Jamie Bainbridge) [RHEL-185446] - net: xdp: pass full flags to xdp_update_skb_shared_info() (Jamie Bainbridge) [RHEL-185446] - xdp: produce a warning when calculated tailroom is negative (Michal Schmidt) [RHEL-177815] - libeth, idpf: use truesize as XDP RxQ info frag_size (Michal Schmidt) [RHEL-177815] - i40e: use xdp.frame_sz as XDP RxQ info frag_size (Michal Schmidt) [RHEL-177815] - i40e: fix registering XDP RxQ info (Michal Schmidt) [RHEL-177815] - ice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz (Michal Schmidt) [RHEL-177815] - xsk: introduce helper to determine rxq->frag_size (Michal Schmidt) [RHEL-177815] - xdp: use modulo operation to calculate XDP frag tailroom (Michal Schmidt) [RHEL-177815] - page_pool: Add page_pool_dev_alloc_netmems helper (Davide Caratti) [RHEL-132651] - net: Add skb_can_coalesce for netmem (Davide Caratti) [RHEL-132651] - net: Allow const args for of page_to_netmem() (Davide Caratti) [RHEL-132651] - xsk: add missing virtual address conversion for page (Davide Caratti) [RHEL-132651] - xsk: Bring back busy polling support in XDP_COPY (Davide Caratti) [RHEL-132651] - xsk: convert xdp_copy_frags_from_zc() to use page_pool_dev_alloc() (Davide Caratti) [RHEL-132651] - net: devmem: don't call queue stop / start when the interface is down (Davide Caratti) [RHEL-132651] - net: refactor netdev_rx_queue_restart() to use local qops (Davide Caratti) [RHEL-132651] * Mon Sep 28 2026 CKI KWF Bot [6.12.0-272.el10] - nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CKI Backport Bot) [RHEL-260474] {CVE-2026-64534} - nvmet-auth: reject short AUTH_RECEIVE buffers (CKI Backport Bot) [RHEL-244951] {CVE-2026-72130} - mm/huge_memory: update file PMD counter before folio_put() (Luiz Capitulino) [RHEL-231226] {CVE-2026-53189} - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CKI Backport Bot) [RHEL-234061] {CVE-2026-64298} - NFSv4/flexfiles: reject zero filehandle version count (CKI Backport Bot) [RHEL-229408] {CVE-2026-53392} - nfsd: fix dead ACL conflict guard in nfsd4_create (CKI Backport Bot) [RHEL-228958] {CVE-2026-53395} - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CKI Backport Bot) [RHEL-228037] {CVE-2026-53391} - nfsd: release layout stid on setlease failure (CKI Backport Bot) [RHEL-227795] {CVE-2026-53399} - pNFS: Fix use-after-free in pnfs_update_layout() (CKI Backport Bot) [RHEL-226320] {CVE-2026-63800} - nfsd: fix posix_acl leak on SETACL decode failure (CKI Backport Bot) [RHEL-225524] {CVE-2026-53397} - zram: fix use-after-free in zram_bvec_write_partial() (Jeff Moyer) [RHEL-191446] {CVE-2026-53185} - blk-mq: reinsert cached request to the list (Jeff Moyer) [RHEL-213154] - blk-mq: pop cached request if it is usable (Jeff Moyer) [RHEL-213154] {CVE-2026-64017} - block: don't overwrite bip_vcnt in bio_integrity_copy_user() (Jeff Moyer) [RHEL-232371] {CVE-2026-64053} - KVM: s390: vsie: Avoid injecting machine check on signal (Cornelia Huck) [RHEL-143729] - KVM: s390: log machine checks more aggressively (Cornelia Huck) [RHEL-143729] - KVM: s390: Fix gmap_helper_zap_one_page() again (Cornelia Huck) [RHEL-143729] - KVM: s390: Use generic VIRT_XFER_TO_GUEST_WORK functions (Cornelia Huck) [RHEL-143729] - KVM: s390: Enable and disable interrupts in entry code (Cornelia Huck) [RHEL-143729] - KVM: s390: Add signal_exits counter (Cornelia Huck) [RHEL-143729] - KVM: s390: fix missing present bit for gmap puds (Cornelia Huck) [RHEL-143729] - s390/mm: Replace the CSP instruction with CSPG (Cornelia Huck) [RHEL-143729] - s390/mm: Remove cpu_has_idte() (Cornelia Huck) [RHEL-143729] - s390: Add Dat-Enhancement facility 1 to architecture level set (Cornelia Huck) [RHEL-143729] - KVM: s390: Replace sprintf with snprintf for buffer safety (Cornelia Huck) [RHEL-143729] - KVM: s390: Remove unused return variable in kvm_arch_vcpu_ioctl_set_fpu (Cornelia Huck) [RHEL-143729] - KVM: S390: Remove sca_lock (Cornelia Huck) [RHEL-143729] - KVM: s390: Use ESCA instead of BSCA at VM init (Cornelia Huck) [RHEL-143729] - s390/asm-offsets: Rename __LC_PGM_INT_CODE (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_IDTE to cpu_has_idte() (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_TOPOLOGY to cpu_has_topology() (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_TLB_LC to cpu_has_tlb_lc() (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_GS to cpu_has_gs() (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_RDP to cpu_has_rdp() (Cornelia Huck) [RHEL-143729] - s390/cpufeature: Convert MACHINE_HAS_SEQ_INSN to cpu_has_seq_insn() (Cornelia Huck) [RHEL-143729] - net: aquantia: Add missing descriptor cache invalidation on ATL2 (CKI Backport Bot) [RHEL-172178] - libceph: Reject monmaps advertising zero monitors (CKI Backport Bot) [RHEL-240895] {CVE-2026-68155} - libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CKI Backport Bot) [RHEL-237157] {CVE-2026-68159} - libceph: Amend checking to fix `make W=1` build breakage (CKI Backport Bot) [RHEL-237157] {CVE-2026-68159} - nvmet-auth: validate reply message payload bounds against transfer length (CKI Backport Bot) [RHEL-234143] {CVE-2026-64319} - net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (CKI Backport Bot) [RHEL-183002] {CVE-2025-71066} - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228916] {CVE-2026-63801} - tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238038] {CVE-2026-68117} - sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229472] {CVE-2026-63971} - sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231580] {CVE-2026-52917} - sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236159] {CVE-2026-68315} - sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237096] {CVE-2026-68376} - sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237096] {CVE-2026-68300} - x86/bugs: Make Safe-RET robust against interrupt injection (Waiman Long) [RHEL-230476] {CVE-2026-68480} - redhat: kernel.spec: allow overriding CROSS_COMPILE (Scott Weaver) - redhat: drop the Fedora 41 cross-build gdb-index workaround (Scott Weaver) - random: Drop the extrng module reference when import_ubuf() fails (Vladislav Dronov) [2524262 RHEL-251529] - vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CKI Backport Bot) [RHEL-252823] {CVE-2026-68299} - ext4: fix e4b bitmap inconsistency reports (CKI Backport Bot) [RHEL-225941] {CVE-2026-45942} - tcp: initialize standalone TCP-AO response padding (Davide Caratti) [RHEL-153033] - net/tcp-ao: Drop support for most non-RFC-specified algorithms (Davide Caratti) [RHEL-153033] - net/tcp-ao: fix use-after-free of key in del_async path (Davide Caratti) [RHEL-153033] - tcp: defer md5sig_info kfree past RCU grace period in tcp_connect (Davide Caratti) [RHEL-153033] - tcp: restore RCU grace period in tcp_ao_destroy_sock (Davide Caratti) [RHEL-153033] - kernel.spec.template: add tcp_ao kselftests (Davide Caratti) [RHEL-153033] - Kconfig: enable CONFIG_TCP_AO (Davide Caratti) [RHEL-153033] - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). (Davide Caratti) [RHEL-153033] - net/tcp: Fix socket memory leak in TCP-AO failure handling for IPv6 (Davide Caratti) [RHEL-153033] {CVE-2025-39852} - net/tcp-ao: Fix MAC comparison to be constant-time (Davide Caratti) [RHEL-153033] {CVE-2026-43384} - tcp: Free TCP-AO/TCP-MD5 info/keys without RCU (Davide Caratti) [RHEL-153033] - tcp: Destroy TCP-AO, TCP-MD5 keys in .sk_destruct() (Davide Caratti) [RHEL-153033] - net/tcp: Add missing lockdep annotations for TCP-AO hlist traversals (Davide Caratti) [RHEL-153033] * Thu Sep 24 2026 CKI KWF Bot [6.12.0-271.el10] - lsm: hold cred_guard_mutex for lsm_set_self_attr() (Pablo Alessandro Santos Hugen) [RHEL-226809] {CVE-2026-64111} - dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244970] {CVE-2026-72098} - exfat: fix potential use-after-free in exfat_find_dir_entry() (CKI Backport Bot) [RHEL-231550] {CVE-2026-63808} - dm_early_create: fix freeing used table on dm_resume failure (Benjamin Marzinski) [RHEL-244946] {CVE-2026-72102} - scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CKI Backport Bot) [RHEL-254597] {CVE-2026-74556} - scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-254167] - block: save page offset gaps in cloned bio (Eric Auger) [RHEL-179725 RHEL-191742 RHEL-213968] - block: don't initialize bi_vcnt for cloned bio in bio_iov_bvec_set() (Eric Auger) [RHEL-179725 RHEL-191742 RHEL-213968] - block: fix partial IOVA mapping cleanup in blk_rq_dma_map_iova (Eric Auger) [RHEL-179725 RHEL-191742 RHEL-213968] - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191607] {CVE-2026-53176} - net: ena: PHC: Fix potential use-after-free in get_timestamp (Thilak KN) [RHEL-230628] {CVE-2026-52971} - cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size (Aristeu Rozanski) [RHEL-140832] - cxl/ras: Fix CPER handler device confusion (Aristeu Rozanski) [RHEL-140832] - cxl/pci: Add trace logging for CXL PCIe Port RAS errors (Aristeu Rozanski) [RHEL-140832] - acpi/ghes, cxl/pci: Process CXL CPER Protocol Errors (Aristeu Rozanski) [RHEL-140832] - acpi/ghes, cper: Recognize and cache CXL Protocol errors (Aristeu Rozanski) [RHEL-140832] - nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244925] {CVE-2026-72129} - ice: reject out-of-range ptype in ice_parser_profile_init (CKI Backport Bot) [RHEL-237210] {CVE-2026-68128} - octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Michal Schmidt) [RHEL-231043] {CVE-2026-72045} - octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (Michal Schmidt) [RHEL-231043] {CVE-2026-63923} - mshv: Fix infinite fault loop on permission-denied GPA intercepts (Maxim Levitsky) [RHEL-245033] - mshv: Fix error handling in mshv_region_pin (Maxim Levitsky) [RHEL-245033] - mshv: Fix use-after-free in mshv_map_user_memory error path (Maxim Levitsky) [RHEL-245033] - mshv: pass struct mshv_user_mem_region by reference (Maxim Levitsky) [RHEL-245033] - mshv: Handle insufficient root memory hypervisor statuses (Maxim Levitsky) [RHEL-245033] - mshv: Handle insufficient contiguous memory hypervisor status (Maxim Levitsky) [RHEL-245033] - mshv: Introduce hv_deposit_memory helper functions (Maxim Levitsky) [RHEL-245033] - mshv: Introduce hv_result_needs_memory() helper function (Maxim Levitsky) [RHEL-245033] - mshv: Add SMT_ENABLED_GUEST partition creation flag (Maxim Levitsky) [RHEL-245033] - mshv: Add support for integrated scheduler (Maxim Levitsky) [RHEL-245033] - mshv: Add debugfs to view hypervisor statistics (Maxim Levitsky) [RHEL-245033] - mshv: Add data for printing stats page counters (Maxim Levitsky) [RHEL-245033] - mshv: Update hv_stats_page definitions (Maxim Levitsky) [RHEL-245033] - mshv: Always map child vp stats pages regardless of scheduler type (Maxim Levitsky) [RHEL-245033] - mshv: Improve mshv_vp_stats_map/unmap(), add them to mshv_root.h (Maxim Levitsky) [RHEL-245033] - mshv: Use typed hv_stats_page pointers (Maxim Levitsky) [RHEL-245033] - mshv: Ignore second stats page map result failure (Maxim Levitsky) [RHEL-245033] - mm/khugepaged: write all dirty file folios when collapsing (Rafael Aquini) [RHEL-236348] {CVE-2026-68086} - xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188231] {CVE-2026-53091} - mm: shrinker: fix NULL pointer dereference in debugfs (Rafael Aquini) [RHEL-230834] {CVE-2026-64417} - mm: shrinker: fix shrinker_info teardown race with expansion (Rafael Aquini) [RHEL-230834] {CVE-2026-64418} - Reapply "firmware: arm_ffa: Change initcall level of ffa_init() to rootfs_initcall" (Jennifer Berringer) [RHEL-248828] - Revert "firmware: arm_ffa: Register core as a platform driver" (Jennifer Berringer) [RHEL-248828] - Revert "firmware: arm_ffa: Set the core device as FF-A device parent" (Jennifer Berringer) [RHEL-248828] - Revert "firmware: arm_ffa: Defer probe until pKVM is initialized" (Jennifer Berringer) [RHEL-248828] - tpm: tpm_crb_ffa: try to probe tpm_crb_ffa when it's built-in (Jennifer Berringer) [RHEL-248828] - mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (Rafael Aquini) [RHEL-223406] {CVE-2026-64368} - userfaultfd: prevent registration of special VMAs (Rafael Aquini) [RHEL-237864] {CVE-2026-68166} - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CKI Backport Bot) [RHEL-225286] {CVE-2026-45970} - ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227887] {CVE-2026-64113} - xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264309] {CVE-2026-80844} - nvme-tcp: fix host memory disclosure on R2T for a read command (CKI Backport Bot) [RHEL-263410] {CVE-2026-89481} - arm_mpam: Disable driver unbind to avoid UAF (Gavin Shan) [RHEL-256832] - arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt (Gavin Shan) [RHEL-256832] - arm_mpam: Apply T241-MPAM-6 to 63-bit counters (Gavin Shan) [RHEL-242415 RHEL-256832] - arm64: mpam: Add memory bandwidth usage (MBWU) documentation (Gavin Shan) [RHEL-242416 RHEL-256832] - arm_mpam: resctrl: Add resctrl_arch_cntr_read() & resctrl_arch_reset_cntr() (Gavin Shan) [RHEL-242416 RHEL-256832] - arm_mpam: resctrl: Add resctrl_arch_config_cntr() for ABMC use (Gavin Shan) [RHEL-242416 RHEL-256832] - arm_mpam: resctrl: Pre-allocate assignable monitors (Gavin Shan) [RHEL-242416 RHEL-256832] - arm_mpam: resctrl: Pick classes for use as MBM counters (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Document tasks file behaviour for task id 0 and idle tasks (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Document that automatic counter assignment is best effort (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Continue counter allocation after failure (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Add monitor property 'mbm_cntr_assign_fixed' (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Disallow the software controller when MBM counters are assignable (Gavin Shan) [RHEL-242416 RHEL-256832] - x86,fs/resctrl: Create 'event_filter' files read only if they're not configurable (Gavin Shan) [RHEL-242416 RHEL-256832] - fs/resctrl: Tidy up the error path in resctrl_mkdir_event_configs() (Gavin Shan) [RHEL-242416 RHEL-256832] - crypto/hkdf: Skip tests with keys too short in FIPS mode (Vladislav Dronov) [RHEL-131229] - smb: client: fix multiuser mount with krb5 (Jorge San Emeterio Villalain) [RHEL-254107] - smb/client: return EOPNOTSUPP for unsupported O_TMPFILE (Jorge San Emeterio Villalain) [RHEL-254107] - ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-253651] {CVE-2026-68200} - ALSA: timer: drain a slave's callback before its master detaches it (CKI Backport Bot) [RHEL-253619] {CVE-2026-68201} * Tue Sep 22 2026 CKI KWF Bot [6.12.0-270.el10] - KVM: SVM: make svm_flush_tlb_gva do a full asid flush if NPT enabled (Paolo Bonzini) [RHEL-188812] - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CKI Backport Bot) [RHEL-252966] {CVE-2026-46189} - security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225693] {CVE-2026-64015} - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CKI Backport Bot) [RHEL-228725] {CVE-2026-63889} - scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-235915] {CVE-2025-68745} - iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes) [RHEL-54449] - ALSA: virtio: Validate control metadata from the device (Jaroslav Kysela) [RHEL-230143] {CVE-2026-64490} - iomap: fix out-of-bounds bitmap_set() with zero-length range (CKI Backport Bot) [RHEL-240185] {CVE-2026-68145} - rhashtable: clear stale iter->p on table restart (Luiz Capitulino) [RHEL-248455] {CVE-2026-64563} - locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (Waiman Long) [RHEL-242859] {CVE-2026-72069} - redhat/configs: riscv: Enable SpacemiT V100 RISC-V platform support (Iker Pedrosa) [RHEL-259288] - redhat: disabled AMD_PMF_UTIL_SUPPORT config for x86 (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: fix build on !CONFIG_AMD_PMF_DEBUG (Krzysztof Pawlinski) [RHEL-222371] - Documentation/ABI: add testing entry for AMD PMF character device interface (Krzysztof Pawlinski) [RHEL-222371] - MAINTAINERS: Change AMD PMF driver status to "Supported" (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Introduce AMD PMF testing tool for driver metrics and features (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Add 1AH_M80H metrics table and NPU metrics support (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Refactor NPU metrics for platform extensibility (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Use upper/lower_32_bits() in amd_pmf_set_dram_addr() (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Add missing newline in dev_err message (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Move metrics code to dedicated file (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Add 1AH_M80H device IDs and extended SMU mailbox registers (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Use per-SoC smu_regs struct for SMU mailbox registers (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Implement util layer ioctl handler (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Move debug helper functions to UAPI header (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Store commonly used enums in the header file (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: store BIOS output values for user-space metrics via util IOCTL (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/pmf: Add util layer and userspace character device interface (Krzysztof Pawlinski) [RHEL-222371] - platform/x86/amd/hsmp: Add HSMP messages for Family 1Ah, Model 50h-5Fh (Steve Best) [RHEL-252297] - sched_ext: Use dsq->first_task instead of list_empty() in dispatch_enqueue() FIFO-tail (Phil Auld) [RHEL-151616] - sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters (Phil Auld) [RHEL-151616] - Revert "sched_ext: Use READ_ONCE() for the read side of dsq->nr update" (Phil Auld) [RHEL-151616] - sched_ext: Use WRITE_ONCE() for the write side of scx_enable helper pointer (Phil Auld) [RHEL-151616] - sched_ext: Fix enqueue_task_scx() truncation of upper enqueue flags (Phil Auld) [RHEL-151616] - sched_ext: Use READ_ONCE() for scx_slice_bypass_us in scx_bypass() (Phil Auld) [RHEL-151616] - sched_ext: Document task ownership state machine (Phil Auld) [RHEL-151616] - sched_ext: Use READ_ONCE() for lock-free reads of module param variables (Phil Auld) [RHEL-151616] - sched_ext: Use WRITE_ONCE() for the write side of dsq->seq update (Phil Auld) [RHEL-151616] - sched_ext: Fix starvation of scx_enable() under fair-class saturation (Phil Auld) [RHEL-151616] - sched_ext: Remove redundant css_put() in scx_cgroup_init() (Phil Auld) [RHEL-151616] - sched_ext: Use READ_ONCE() for plain reads of scx_watchdog_timeout (Phil Auld) [RHEL-151616] - sched_ext: Replace naked scx_root dereferences in kobject callbacks (Phil Auld) [RHEL-151616] - sched_ext: Use READ_ONCE() for the read side of dsq->nr update (Phil Auld) [RHEL-151616] - sched_ext: Fix SCX_EFLAG_INITIALIZED being a no-op flag (Phil Auld) [RHEL-151616] - sched_ext: Fix out-of-bounds access in scx_idle_init_masks() (Phil Auld) [RHEL-151616] - sched_ext: Disable preemption between scx_claim_exit() and kicking helper work (Phil Auld) [RHEL-151616] - sched_ext: Short-circuit sched_class operations on dead tasks (Phil Auld) [RHEL-151616] - selftests/sched_ext: Fix init_enable_count flakiness (Phil Auld) [RHEL-151616] - tools/sched_ext: update scx_show_state.py for scx_aborting change (Phil Auld) [RHEL-151616] - tools/sched_ext: fix scx_show_state.py for scx_root change (Phil Auld) [RHEL-151616] - sched_ext: Avoid multiple irq_work_queue() calls in destroy_dsq() (Phil Auld) [RHEL-151616] - sched_ext: Use the resched_cpu() to replace resched_curr() in the bypass_lb_node() (Phil Auld) [RHEL-151616] - sched_ext: Fix some comments in ext.c (Phil Auld) [RHEL-151616] - sched_ext: fix uninitialized ret on alloc_percpu() failure (Phil Auld) [RHEL-151616] - sched_ext: Remove unused code in the do_pick_task_scx() (Phil Auld) [RHEL-151616] - sched_ext: Fix missing post-enqueue handling in move_local_task_to_local_dsq() (Phil Auld) [RHEL-151616] - sched_ext: Factor out local_dsq_post_enq() from dispatch_enqueue() (Phil Auld) [RHEL-151616] - sched_ext: Fix bypass depth leak on scx_enable() failure (Phil Auld) [RHEL-151616] - sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next (Phil Auld) [RHEL-151616] - sched_ext: Fix the memleak for sch->helper objects (Phil Auld) [RHEL-151616] - sched_ext: Fix incorrect sched_class settings for per-cpu migration tasks (Phil Auld) [RHEL-151616] - sched_ext: Fix scx_enable() crash on helper kthread creation failure (Phil Auld) [RHEL-151616] - sched_ext: Use kvfree_rcu() to release per-cpu ksyncs object (Phil Auld) [RHEL-151616] - sched_ext: Use IRQ_WORK_INIT_HARD() to initialize rq->scx.kick_cpus_irq_work (Phil Auld) [RHEL-151616] - sched_ext: Pass locked CPU parameter to scx_hardlockup() and add docs (Phil Auld) [RHEL-151616] - sched_ext: Fix possible deadlock in the deferred_irq_workfn() (Phil Auld) [RHEL-151616] - sched_ext: Update comments replacing breather with aborting mechanism (Phil Auld) [RHEL-151616] - sched/ext: convert scx_tasks_lock to raw spinlock (Phil Auld) [RHEL-151616] - sched_ext: Implement load balancer for bypass mode (Phil Auld) [RHEL-151616] - sched_ext: Factor out abbreviated dispatch dequeue into dispatch_dequeue_locked() (Phil Auld) [RHEL-151616] - sched_ext: Factor out scx_dsq_list_node cursor initialization into INIT_DSQ_LIST_CURSOR (Phil Auld) [RHEL-151616] - sched_ext: Add scx_cpu0 example scheduler (Phil Auld) [RHEL-151616] - sched_ext: Hook up hardlockup detector (Phil Auld) [RHEL-151616] - sched_ext: Make handle_lockup() propagate scx_verror() result (Phil Auld) [RHEL-151616] - sched_ext: Refactor lockup handlers into handle_lockup() (Phil Auld) [RHEL-151616] - sched_ext: Make scx_exit() and scx_vexit() return bool (Phil Auld) [RHEL-151616] - sched_ext: Exit dispatch and move operations immediately when aborting (Phil Auld) [RHEL-151616] - sched_ext: Simplify breather mechanism with scx_aborting flag (Phil Auld) [RHEL-151616] - sched_ext: Use per-CPU DSQs instead of per-node global DSQs in bypass mode (Phil Auld) [RHEL-151616] - sched_ext: Refactor do_enqueue_task() local and global DSQ paths (Phil Auld) [RHEL-151616] - sched_ext: Use shorter slice in bypass mode (Phil Auld) [RHEL-151616] - sched_ext: Fix unsafe locking in the scx_dump_state() (Phil Auld) [RHEL-151616] - sched_ext: Mark racy bitfields to prevent adding fields that can't tolerate races (Phil Auld) [RHEL-151616] - sched_ext: Minor cleanups to scx_task_iter (Phil Auld) [RHEL-151616] - sched_ext: Move __SCX_DSQ_ITER_ALL_FLAGS BUILD_BUG_ON to the right place (Phil Auld) [RHEL-151616] - sched_ext: Fix cgroup exit ordering by moving sched_ext_free() to finish_task_switch() (Phil Auld) [RHEL-151616] - sched_ext/tools: Restore backward compat with v6.12 kernels (Phil Auld) [RHEL-151616] - sched_ext: Allow scx_bpf_reenqueue_local() to be called from anywhere (Phil Auld) [RHEL-151616] - sched_ext: Factor out reenq_local() from scx_bpf_reenqueue_local() (Phil Auld) [RHEL-151616] - sched_ext: Split schedule_deferred() into locked and unlocked variants (Phil Auld) [RHEL-151616] - sched_ext/tools: Add compat wrapper for scx_bpf_task_set_slice/dsq_vtime() (Phil Auld) [RHEL-151616] - sched_ext: Fix use of uninitialized variable in scx_bpf_cpuperf_set() (Phil Auld) [RHEL-151616] - sched_ext: Use SCX_TASK_READY test instead of tryget_task_struct() during class switch (Phil Auld) [RHEL-151616] - sched_ext: Add ___compat suffix to scx_bpf_dsq_insert___v2 in compat.bpf.h (Phil Auld) [RHEL-151616] - sched_ext: Fix scx_bpf_dsq_peek() with FIFO DSQs (Phil Auld) [RHEL-151616] - sched_ext: Fix scx_bpf_dsq_insert() backward binary compatibility (Phil Auld) [RHEL-151616] - sched_ext: Add a selftest for scx_bpf_dsq_peek (Phil Auld) [RHEL-151616] - sched_ext: Add lockless peek operation for DSQs (Phil Auld) [RHEL-151616] - sched/ext: Implement cgroup_set_idle() callback (Phil Auld) [RHEL-151616] - sched_ext: Make scx_bpf_dsq_insert*() return bool (Phil Auld) [RHEL-151616] - sched_ext: Wrap kfunc args in struct to prepare for aux__prog (Phil Auld) [RHEL-151616] - sched_ext: Add scx_bpf_task_set_slice() and scx_bpf_task_set_dsq_vtime() (Phil Auld) [RHEL-151616] - tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs (Phil Auld) [RHEL-151616] - tools/sched_ext: Receive updates from SCX repo (Phil Auld) [RHEL-151616] - sched_ext: Exit early on hotplug events during attach (Phil Auld) [RHEL-151616] - sched_ext: Sync error_irq_work before freeing scx_sched (Phil Auld) [RHEL-151616] - sched_ext: Mark scx_bpf_dsq_move_set_[slice|vtime]() with KF_RCU (Phil Auld) [RHEL-151616] - sched_ext: Misc updates around scx_sched instance pointer (Phil Auld) [RHEL-151616] - sched_ext: Drop scx_kf_exit() and scx_kf_error() (Phil Auld) [RHEL-151616] - sched_ext: Add the @sch parameter to scx_dsq_insert_preamble/commit() (Phil Auld) [RHEL-151616] - sched_ext: Drop kf_cpu_valid() (Phil Auld) [RHEL-151616] - sched_ext: Add the @sch parameter to ext_idle helpers (Phil Auld) [RHEL-151616] - sched_ext: Add the @sch parameter to __bstr_format() (Phil Auld) [RHEL-151616] - sched_ext: Separate out scx_kick_cpu() and add @sch to it (Phil Auld) [RHEL-151616] - tools/sched_ext: scx_qmap: Make debug output quieter by default (Phil Auld) [RHEL-151616] - sched_ext: Make qmap dump operation non-destructive (Phil Auld) [RHEL-151616] - sched_ext: Add SCX_EFLAG_INITIALIZED to indicate successful ops.init() (Phil Auld) [RHEL-151616] - sched_ext: Use bitfields for boolean warning flags (Phil Auld) [RHEL-151616] - sched_ext: Fix stray scx_root usage in task_can_run_on_remote_rq() (Phil Auld) [RHEL-151616] - sched_ext: Improve SCX_KF_DISPATCH comment (Phil Auld) [RHEL-151616] - sched_ext: Verify RCU protection in scx_bpf_cpu_curr() (Phil Auld) [RHEL-151616] - sched_ext: Add migration-disabled counter to error state dump (Phil Auld) [RHEL-151616] - sched_ext: Fix NULL dereference in scx_bpf_cpu_rq() warning (Phil Auld) [RHEL-151616] - tools/sched_ext: Add compat helper for scx_bpf_cpu_curr() (Phil Auld) [RHEL-151616] - sched_ext: deprecation warn for scx_bpf_cpu_rq() (Phil Auld) [RHEL-151616] - sched_ext: Introduce scx_bpf_cpu_curr() (Phil Auld) [RHEL-151616] - sched_ext: Introduce scx_bpf_locked_rq() (Phil Auld) [RHEL-151616] - sched_ext: Use cgroup_lock/unlock() to synchronize against cgroup operations (Phil Auld) [RHEL-151616] - sched_ext: Put event_stats_cpu in struct scx_sched_pcpu (Phil Auld) [RHEL-151616] - sched_ext: Keep bypass on between enable failure and scx_disable_workfn() (Phil Auld) [RHEL-151616] - net: stmmac: eic7700: add support for eth1 clock inversion variant (Jennifer Berringer) [RHEL-224408] - net: stmmac: eic7700: make RGMII delay properties optional (Jennifer Berringer) [RHEL-224408] - net: stmmac: eswin: validate RGMII delay values (Jennifer Berringer) [RHEL-224408] - net: stmmac: eswin: correct RGMII delay granularity to 20 ps (Jennifer Berringer) [RHEL-224408] - net: stmmac: eswin: clear TXD and RXD delay registers during initialization (Jennifer Berringer) [RHEL-224408] - net: stmmac: eswin: fix HSP CSR init ordering after clock enable (Jennifer Berringer) [RHEL-224408] - net: stmmac: pass struct device to init()/exit() methods (Jennifer Berringer) [RHEL-224408] - pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE (Jennifer Berringer) [RHEL-224408] - hwmon: Add Eswin EIC7700 PVT sensor driver (Jennifer Berringer) [RHEL-224408] - reset: eswin: Add eic7700 HSP reset driver (Jennifer Berringer) [RHEL-224408] - clk: eswin: Add eic7700 HSP clock driver (Jennifer Berringer) [RHEL-224408] - dt-bindings: clock: Add ESWIN eic7700 HSP clock and reset generator (Jennifer Berringer) [RHEL-224408] - MAINTAINERS: Add entry for ESWIN EIC7700 clock driver (Jennifer Berringer) [RHEL-224408] - clk: eswin: Zero-initialize stack-allocated clk_init_data (Jennifer Berringer) [RHEL-224408] - clk: eswin: Add CLK_IGNORE_UNUSED to NoC clock (Jennifer Berringer) [RHEL-224408] - clk: eswin: Add eic7700 clock driver (Jennifer Berringer) [RHEL-224408] - dt-bindings: clock: eswin: Documentation for eic7700 SoC (Jennifer Berringer) [RHEL-224408] - clk: divider: Add devm_clk_hw_register_divider_parent_data (Jennifer Berringer) [RHEL-224408] - clk: Add devm_clk_hw_register_gate_parent_hw() (Jennifer Berringer) [RHEL-224408] - PCI: eswin: Add ESWIN PCIe Root Complex driver (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Perform cleanup in the error path of dw_pcie_resume_noirq() (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Fix missing iATU setup when ECAM is enabled (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Clean up iATU index usage in dw_pcie_iatu_setup() (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Fix msg_atu_index assignment (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Use multiple iATU windows for mapping large bridge windows and DMA ranges (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Skip waiting for L2/L3 Ready if dw_pcie_rp::skip_l23_wait is true (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Invoke post_init in dw_pcie_resume_noirq() (Jennifer Berringer) [RHEL-224408] - PCI: dwc: Skip PME_Turn_Off broadcast and L2/L3 transition during suspend if link is not up (Jennifer Berringer) [RHEL-224408] - phy: eswin: Fix incorrect error check in probe() (Jennifer Berringer) [RHEL-224408] - phy: eswin: Create eswin directory and add EIC7700 SATA PHY driver (Jennifer Berringer) [RHEL-224408] - phy: usb: Add driver for Canaan K230 USB 2.0 PHY (Jennifer Berringer) [RHEL-224408] - mmc: sdhci-of-dwcmshc: Fix reset, clk, and SDIO support for Eswin EIC7700 (Jennifer Berringer) [RHEL-224408] - mmc: sdhci-of-dwcmshc: Promote the th1520 reset handling to ip level (Jennifer Berringer) [RHEL-224408] - mmc: sdhci-of-dwcmshc: Fix DMA 128MB boundary for Eswin EIC7700 (Jennifer Berringer) [RHEL-224408] - mmc: sdhci-of-dwcmshc: Fix init for AXI clock for Eswin EIC7700 (Jennifer Berringer) [RHEL-224408] - mmc: sdhci-of-dwcmshc: Add support for Eswin EIC7700 (Jennifer Berringer) [RHEL-224408] - redhat/configs: Enable new EIC7700 SoC configs for RISC-V (Jennifer Berringer) [RHEL-224408] - Reapply "firmware: arm_ffa: Change initcall level of ffa_init() to rootfs_initcall" (Jennifer Berringer) [RHEL-249190] - Revert "firmware: arm_ffa: Register core as a platform driver" (Jennifer Berringer) [RHEL-249190] - Revert "firmware: arm_ffa: Set the core device as FF-A device parent" (Jennifer Berringer) [RHEL-249190] - Revert "firmware: arm_ffa: Defer probe until pKVM is initialized" (Jennifer Berringer) [RHEL-249190] - tpm: tpm_crb_ffa: try to probe tpm_crb_ffa when it's built-in (Jennifer Berringer) [RHEL-249190] - redhat/configs: Enable ethernet for SpacemiT K1 and K3 (Jennifer Berringer) [RHEL-183437] - riscv: dts: starfive: remove "snps,en-tx-lpi-clockgating" property (Jennifer Berringer) [RHEL-183437] - wifi: rtw89: pci: enable 36-bit DMA on spacemit K3 (Jennifer Berringer) [RHEL-183437] - PCI: Move Spacemit vendor and device IDs to linux/pci_ids.h (Jennifer Berringer) [RHEL-183437] - net: stmmac: dwmac-spacemit: Fix wrong irq definition (Jennifer Berringer) [RHEL-183437] - net: stmmac: dwmac-spacemit: Fix wrong phy interface definition (Jennifer Berringer) [RHEL-183437] - net: spacemit: Fix error handling in emac_tx_mem_map() (Jennifer Berringer) [RHEL-183437] {CVE-2026-43462} - net: spacemit: Fix error handling in emac_alloc_rx_desc_buffers() (Jennifer Berringer) [RHEL-183437] - net: spacemit: Remove unused buff_addr fields (Jennifer Berringer) [RHEL-183437] - net: spacemit: k1-emac: fix jumbo frame support (Jennifer Berringer) [RHEL-183437] - net: spacemit: display phy driver information (Jennifer Berringer) [RHEL-183437] - net: spacemit: Check for netif_carrier_ok() in emac_stats_update() (Jennifer Berringer) [RHEL-183437] - net: spacemit: Remove broken flow control support (Jennifer Berringer) [RHEL-183437] - net: spacemit: Check netif_running() in emac_set_pauseparam() (Jennifer Berringer) [RHEL-183437] - net: spacemit: Avoid -Wflex-array-member-not-at-end warnings (Jennifer Berringer) [RHEL-183437] - net: spacemit: Make stats_lock softirq-safe (Jennifer Berringer) [RHEL-183437] - net: spacemit: Add K1 Ethernet MAC (Jennifer Berringer) [RHEL-183437] - of: base: Add of_get_available_child_by_name() (Jennifer Berringer) [RHEL-183437] - vrf: Make pcpu_dstats update functions available to other modules. (Jennifer Berringer) [RHEL-183437] - net: stmmac: Add glue layer for Spacemit K3 SoC (Jennifer Berringer) [RHEL-183437] - net: stmmac: platform: Add snps,dwmac-5.40a IP compatible string (Jennifer Berringer) [RHEL-183437] - net: add helper to pre-check if PP for an Rx queue will be unreadable [partial: helper-only] (Jamie Bainbridge) [RHEL-185444] - eth: bnxt: add support rx side device memory TCP [partial: helper-only] (Jamie Bainbridge) [RHEL-185444] - idpf: remove unused code for getting RSS info from device (Michal Schmidt) [RHEL-132835] - idpf: remove 'vport_params_reqd' field (Michal Schmidt) [RHEL-132835] - idpf: add missing cpu_to_le32 in idpf_tx_splitq_build_flow_desc (Michal Schmidt) [RHEL-132835] - idpf: Fix mailbox IRQ name leak on request failure (Michal Schmidt) [RHEL-132835] - idpf: adjust TxQ ring count minimum (Michal Schmidt) [RHEL-132835] - idpf: bound interrupt-vector register fill to the allocated array (Michal Schmidt) [RHEL-132835] - idpf: fix max_vport related crash on allocation error during init (Michal Schmidt) [RHEL-132835] - idpf: Replace use of system_unbound_wq with system_dfl_wq (Michal Schmidt) [RHEL-132835] - idpf: add padding to PTP virtchnl structures (Michal Schmidt) [RHEL-132835] - idpf: fix mailbox capability for set device clock time (Michal Schmidt) [RHEL-132835] - idpf: fix double free and use-after-free in aux device error paths (Michal Schmidt) [RHEL-132835] - idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() (Michal Schmidt) [RHEL-132835] - Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL uses [idpf] (Michal Schmidt) [RHEL-132835] - Convert more 'alloc_obj' cases to default GFP_KERNEL arguments [idpf] (Michal Schmidt) [RHEL-132835] - Convert 'alloc_flex' family to use the new default GFP_KERNEL argument [idpf] (Michal Schmidt) [RHEL-132835] - Convert 'alloc_obj' family to use the new default GFP_KERNEL argument [idpf] (Michal Schmidt) [RHEL-132835] - treewide: Replace kmalloc with kmalloc_obj for non-scalar types [idpf] (Michal Schmidt) [RHEL-132835] - idpf: set the payload size before calling the async handler (Michal Schmidt) [RHEL-132835] - idpf: improve locking around idpf_vc_xn_push_free() (Michal Schmidt) [RHEL-132835] - idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (Michal Schmidt) [RHEL-132835] - idpf: only assign num refillqs if allocation was successful (Michal Schmidt) [RHEL-132835] - idpf: clear stale cdev_info ptr (Michal Schmidt) [RHEL-132835] - idpf: Fix flow rule delete failure due to invalid validation (Michal Schmidt) [RHEL-132835] - idpf: change IRQ naming to match netdev and ethtool queue numbering (Michal Schmidt) [RHEL-132835] - idpf: nullify pointers after they are freed (Michal Schmidt) [RHEL-132835] - idpf: skip deallocating txq group's txqs if it is NULL (Michal Schmidt) [RHEL-132835] - idpf: skip deallocating bufq_sets from rx_qgrp if it is NULL (Michal Schmidt) [RHEL-132835] - idpf: increment completion queue next_to_clean in sw marker wait routine (Michal Schmidt) [RHEL-132835] - idpf: generalize mailbox API (Michal Schmidt) [RHEL-132835] - idpf: avoid calling get_rx_ptypes for each vport (Michal Schmidt) [RHEL-132835] - idpf: generalize send virtchnl message API (Michal Schmidt) [RHEL-132835] - idpf: remove vport pointer from queue sets (Michal Schmidt) [RHEL-132835] - idpf: add rss_data field to RSS function parameters (Michal Schmidt) [RHEL-132835] - idpf: reshuffle idpf_vport struct members to avoid holes (Michal Schmidt) [RHEL-132835] - idpf: move some iterator declarations inside for loops (Michal Schmidt) [RHEL-132835] - idpf: move queue resources to idpf_q_vec_rsrc structure (Michal Schmidt) [RHEL-132835] - idpf: introduce idpf_q_vec_rsrc struct and move vector resources to it (Michal Schmidt) [RHEL-132835] - idpf: introduce local idpf structure to store virtchnl queue chunks (Michal Schmidt) [RHEL-132835] - idpf: Fix kernel-doc descriptions to avoid warnings (Michal Schmidt) [RHEL-132835] - idpf: update idpf_up_complete() return type to void (Michal Schmidt) [RHEL-132835] * Thu Sep 17 2026 CKI KWF Bot [6.12.0-269.el10] - net: ipv6: clear suppressed fib6 rule result (Jamie Bainbridge) [RHEL-246370] {CVE-2026-74581} - fuse: fix race between interrupt and resend (CKI Backport Bot) [RHEL-249641] {CVE-2026-64265} - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (CKI Backport Bot) [RHEL-249641] {CVE-2026-64265} - block: remove redundant GD_NEED_PART_SCAN in add_disk_final() (Jeff Moyer) [RHEL-211072] - drbd: reject data replies with an out-of-range payload size (Jeff Moyer) [RHEL-211072] - blk-mq: bound blk_hctx_poll() to one jiffy (Jeff Moyer) [RHEL-211072] - blk-cgroup: defer blkcg css_put until blkg is unlinked from queue (Jeff Moyer) [RHEL-211072] - blk-cgroup: fix UAF in __blkcg_rstat_flush() (Jeff Moyer) [RHEL-211072] - block: Remove redundant plug in __submit_bio() (Jeff Moyer) [RHEL-211072] - block: check bio split for unaligned bvec (Jeff Moyer) [RHEL-211072] - block: account for bi_bvec_done in bio_may_need_split() (Jeff Moyer) [RHEL-211072] - block: use bvec iterator helper for bio_may_need_split() (Jeff Moyer) [RHEL-211072] - virtio-blk: clamp zone report to the report buffer capacity (Jeff Moyer) [RHEL-211072] - partitions: aix: bound the pp_count scan to the ppe array (Jeff Moyer) [RHEL-211072] - ublk: set canceling flag even when disk is not allocated (Jeff Moyer) [RHEL-211072] - block: Avoid mounting the bdev pseudo-filesystem in userspace (Jeff Moyer) [RHEL-211072] - block: partitions: fix of_node refcount leak in of_partition() (Jeff Moyer) [RHEL-211072] - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (Jeff Moyer) [RHEL-211072] - block: recompute nr_integrity_segments in blk_insert_cloned_request (Jeff Moyer) [RHEL-211072] - ublk: fix use-after-free in ublk_cancel_cmd() (Jeff Moyer) [RHEL-211072] - ublk: validate physical_bs_shift, io_min_shift and io_opt_shift (Jeff Moyer) [RHEL-211072] - ublk: use unchecked copy helpers for bio page data (Jeff Moyer) [RHEL-211072] - block: fix zones_cond memory leak on zone revalidation error paths (Jeff Moyer) [RHEL-211072] - ublk: fix NULL pointer dereference in ublk_ctrl_set_size() (Jeff Moyer) [RHEL-211072] - zloop: check for spurious options passed to remove (Jeff Moyer) [RHEL-211072] - zloop: advertise a volatile write cache (Jeff Moyer) [RHEL-211072] - drbd: fix null-pointer dereference on local read error (Jeff Moyer) [RHEL-211072] - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() (Jeff Moyer) [RHEL-211072] - rbd: check for EOD after exclusive lock is ensured to be held (Jeff Moyer) [RHEL-211072] - blk-mq: ABI/sysfs-block: fix docs build warnings (Jeff Moyer) [RHEL-211072] - blk-mq: add documentation for new queue attribute async_dpeth (Jeff Moyer) [RHEL-211072] - block, bfq: convert to use request_queue->async_depth (Jeff Moyer) [RHEL-211072] - mq-deadline: covert to use request_queue->async_depth (Jeff Moyer) [RHEL-211072] - kyber: covert to use request_queue->async_depth (Jeff Moyer) [RHEL-211072] - blk-mq: add a new queue sysfs attribute async_depth (Jeff Moyer) [RHEL-211072] - blk-mq: factor out a helper blk_mq_limit_depth() (Jeff Moyer) [RHEL-211072] - blk-mq-sched: unify elevators checking for async requests (Jeff Moyer) [RHEL-211072] - block: convert nr_requests to unsigned int (Jeff Moyer) [RHEL-211072] - ublk: Validate SQE128 flag before accessing the cmd (Jeff Moyer) [RHEL-211072] - ublk: restore auto buf unregister refcount optimization (Jeff Moyer) [RHEL-211072] - block: add __must_check attribute to sb_min_blocksize() (Jeff Moyer) [RHEL-211072] - xfs: check the return value of sb_min_blocksize() in xfs_fs_fill_super (Jeff Moyer) [RHEL-211072] - isofs: check the return value of sb_min_blocksize() in isofs_fill_super (Jeff Moyer) [RHEL-211072] - exfat: check return value of sb_min_blocksize in exfat_read_boot_sector (Jeff Moyer) [RHEL-211072] - vfat: fix missing sb_min_blocksize() return value checks (Jeff Moyer) [RHEL-211072] - zram: refuse to use zero sized block device as backing device (Jeff Moyer) [RHEL-211072] - ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (Paolo Abeni) [RHEL-225472] {CVE-2026-64114} - net: guard timestamp cmsgs to real error queue skbs (Paolo Abeni) [RHEL-225862] {CVE-2026-53223} - af_unix: Fix UAF read of tail->len in unix_stream_data_wait() (Paolo Abeni) [RHEL-225896] {CVE-2026-64109} - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (Paolo Abeni) [RHEL-227146] {CVE-2026-63987} - ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Paolo Abeni) [RHEL-227273] {CVE-2026-64002} - af_unix: Drop all SCM attributes for SOCKMAP. (Paolo Abeni) [RHEL-229255] {CVE-2026-53005} - af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). (Paolo Abeni) [RHEL-229255] - af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). (Paolo Abeni) [RHEL-229255] - net: add pskb_may_pull() to skb_gro_receive_list() (Paolo Abeni) [RHEL-229312] {CVE-2026-53235} - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (Paolo Abeni) [RHEL-229507] {CVE-2026-64025} - bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready(). (Paolo Abeni) [RHEL-229507] - ethtool: cmis: require exact CDB reply length (Paolo Abeni) [RHEL-229673] {CVE-2026-63996} - tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction (Paolo Abeni) [RHEL-231694] {CVE-2026-64024} - net: shaper: rework the VALID marking (again) (Paolo Abeni) [RHEL-231706] {CVE-2026-64027} - net: shaper: annotate the data races (Paolo Abeni) [RHEL-231706] - net: shaper: fix trivial ordering issue in net_shaper_commit() (Paolo Abeni) [RHEL-231706] - net: shaper: flip the polarity of the valid flag (Paolo Abeni) [RHEL-231706] - net: shaper: protect late read accesses to the hierarchy (Paolo Abeni) [RHEL-231706] - tcp: call sk_data_ready() after listener migration (Paolo Abeni) [RHEL-232243] {CVE-2026-46015} - flow_dissector: do not dissect PPPoE PFC frames (Paolo Abeni) [RHEL-232624] {CVE-2026-46306} - ipv4: fib: free fib_alias with kfree_rcu() on insert error path (Paolo Abeni) [RHEL-233126] {CVE-2026-64572} - bpf: Reject fragmented frames in devmap (Paolo Abeni) [RHEL-234199] {CVE-2026-64355} - tcp: fix TIME_WAIT socket reference leak on PSP policy failure (Paolo Abeni) [RHEL-236481] {CVE-2026-68379} - mptcp: pm: userspace: fix use-after-free in get_local_id (Paolo Abeni) [RHEL-236705] {CVE-2026-68169} - powerpc/qspinlock: Add spinlock contention tracepoint (Mamatha Inamdar) [RHEL-190816] - powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak (Mamatha Inamdar) [RHEL-238389] - powerpc/pseries: lparcfg - fix kbuf[] underflow (Mamatha Inamdar) [RHEL-238390] - powerpc/pseries: pci - logic bug (Mamatha Inamdar) [RHEL-238392] - cpufreq/amd-pstate: Document missing kernel-doc members (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate-ut: Add unit test for CPPC Performance Priority (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate-ut: Add unit test for "dynamic" EPP mode (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Reduce the scope of exported symbols (Dennis Chen) [RHEL-222490] - Documentation/amd-pstate: Update dynamic_epp documentation with new behavior (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Remove "amd_dynamic_epp" cmdline and "dynamic_epp" sysfs (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Add dynamic EPP as an "energy_performance_preference" mode (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Extract platform profile to EPP conversion into a helper (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Remove the defensive check for bios_min_perf (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Cache the firmware programmed EPP value (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization (Dennis Chen) [RHEL-222490] - cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Prevent the driver from loading on unsupported hardware (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Loosen requirement on lowest nonlinear frequency != min freq (Dennis Chen) [RHEL-222490] - cpufreq: intel_pstate: Adjust the .adjust_perf() driver callback (Dennis Chen) [RHEL-222490] - cpufreq: Remove driver default policy->min/max init (Dennis Chen) [RHEL-222490] - x86/msr: Switch rdmsrl_on_cpu() user to rdmsrq_on_cpu() (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Fix setting EPP in performance mode (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: drop stale @epp_cached kdoc (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate-ut: Disable dynamic_epp after the mode switch (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Drop Kconfig option for dynamic EPP (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate-ut: Drop policy reference before driver switch (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Use "epp_default_dc" as default when dynamic_epp is disabled (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Reorder notifier unregistration and floor perf reset (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Allow writes to dynamic_epp when state isn't modified (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Return -ENOMEM on failure to allocate profile_name (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Grab "amd_pstate_driver_lock" when toggling dynamic_epp (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Use FIELD_MODIFY() (Dennis Chen) [RHEL-222490] - cpufreq: Pass the policy to cpufreq_driver->adjust_perf() (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Pass the policy to amd_pstate_update() (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Add POWER_SUPPLY select for dynamic EPP (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate-ut: Add a unit test for raw EPP (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Add support for raw EPP writes (Dennis Chen) [RHEL-222490] - redhat/configs: x86: Build CONFIG_ACPI_PLATFORM_PROFILE as =y (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Add support for platform profile class (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: add kernel command line to override dynamic epp (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Add dynamic energy performance preference (Dennis Chen) [RHEL-222490] - Documentation: amd-pstate: fix dead links in the reference section (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Cache the max frequency in cpudata (Dennis Chen) [RHEL-222490] - Documentation/amd-pstate: Add documentation for amd_pstate_floor_{freq,count} (Dennis Chen) [RHEL-222490] - Documentation/amd-pstate: List amd_pstate_prefcore_ranking sysfs file (Dennis Chen) [RHEL-222490] - Documentation/amd-pstate: List amd_pstate_hw_prefcore sysfs file (Dennis Chen) [RHEL-222490] - amd-pstate-ut: Add a testcase to validate the visibility of driver attributes (Dennis Chen) [RHEL-222490] - amd-pstate-ut: Add module parameter to select testcases (Dennis Chen) [RHEL-222490] - amd-pstate: Introduce a tracepoint trace_amd_pstate_cppc_req2() (Dennis Chen) [RHEL-222490] - amd-pstate: Add sysfs support for floor_freq and floor_count (Dennis Chen) [RHEL-222490] - amd-pstate: Add support for CPPC_REQ2 and FLOOR_PERF (Dennis Chen) [RHEL-222490] - x86/cpufeatures: Add AMD CPPC Performance Priority feature. (Dennis Chen) [RHEL-222490] - amd-pstate: Make certain freq_attrs conditionally visible (Dennis Chen) [RHEL-222490] - amd-pstate: Update cppc_req_cached in fast_switch case (Dennis Chen) [RHEL-222490] - amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init() (Dennis Chen) [RHEL-222490] {CVE-2026-53121} - cpufreq: Allocate QoS freq_req objects with policy (Dennis Chen) [RHEL-222490] - cpufreq: Add boost_freq_req QoS request (Dennis Chen) [RHEL-222490] - cpufreq: Remove max_freq_req update for pre-existing policy (Dennis Chen) [RHEL-222490] - cpufreq/amd-pstate: Move max_perf limiting in amd_pstate_update (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'wrmsrl_on_cpu()' to 'wrmsrq_on_cpu()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'rdmsrl_on_cpu()' to 'rdmsrq_on_cpu()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'wrmsrl_safe_on_cpu()' to 'wrmsrq_safe_on_cpu()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'rdmsrl_safe_on_cpu()' to 'rdmsrq_safe_on_cpu()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'rdmsrl_safe()' to 'rdmsrq_safe()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'wrmsrl()' to 'wrmsrq()' [partial] (Dennis Chen) [RHEL-222490] - x86/msr: Rename 'rdmsrl()' to 'rdmsrq()' [partial] (Dennis Chen) [RHEL-222490] - x86/cpu: Add Intel CPU model number for rugged Panther Lake (Steve Best) [RHEL-250351] - tools/power/x86/intel-speed-select: v1.26 release (Steve Best) [RHEL-242440] - tools/power/x86/intel-speed-select: Print Version info when Incompatible API version is detected (Steve Best) [RHEL-242440] - tools/power/x86/intel-speed-select: Avoid current base freq as maximum (Steve Best) [RHEL-242440] - platform/x86: ISST: Add a NULL check for sst_inst[] (Steve Best) [RHEL-242440] - platform/x86: ISST: Return error during profile addition (Steve Best) [RHEL-242440] - platform/x86: ISST: Just allow 2 bits for SST feature enable (Steve Best) [RHEL-242440] - platform/x86: ISST: Use PP level enable mask (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate parameter for frequency and priority (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate parameter for core power state (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate max level for set feature (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate logical CPU id and clos id (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate level in perf mask ioctls (Steve Best) [RHEL-242440] - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (Steve Best) [RHEL-242440] - platform/x86: ISST: Restore SST-PP control to all domains (Steve Best) [RHEL-242440] - platform/x86: ISST: Reset core count to 0 (Steve Best) [RHEL-242440] - platform/x86: ISST: Correct locked bit width (Steve Best) [RHEL-242440] - platform/x86: ISST: Check HWP support before MSR access (Steve Best) [RHEL-242440] - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Enable protocol version 7 metric tables on the ACPI driver (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Add IOCTL_GET_TELEMETRY_DATA for metric table reads (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Source metric-table size from firmware (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Unify response_sz validation to an upper-bound check (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Serialize the data plane against socket teardown (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: ACPI HSMP refcounted sockets and coordinated release (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Clear mdev.this_device on deregister (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Serialize per-socket metric table reads with a mutex (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Map the metric table with ioremap() and unmap it explicitly (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Serialize ACPI HSMP probe and remove with an rwsem (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Gate the data plane on a fully initialized socket (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Pass struct device explicitly to ACPI mailbox parsers (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Validate _DSD mailbox sub-package element count (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Validate ACPI UID before parsing socket index (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Fix typo in error message (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Replace dev_err() with dev_info() for non-fatal errors (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Ensure success even if hwmon registration fails (Steve Best) [RHEL-222491] - platform/x86/amd/hsmp: Ensure sock->metric_tbl_addr is non-NULL (Steve Best) [RHEL-222491] - redhat/configs: automotive: enable RTC_DRV_PL031 (Eric Chanudet) [RHEL-242412] - ixgbe: e610: remove redundant assignment (Michal Schmidt) [RHEL-118532] - ixgbe: do not configure xps for XDP queues (Michal Schmidt) [RHEL-118532] - ixgbevf: fix use-after-free in VEPA multicast source pruning (Michal Schmidt) [RHEL-118534] - net: Consistently define pci_device_ids using named initializers [ixgbe,ixgbevf] (Michal Schmidt) [RHEL-118532 RHEL-118534] - ixgbe: E610: do not fill EEE lp_advertised from local PHY caps (Michal Schmidt) [RHEL-118532] - ixgbe: fix unaligned u32 access in ixgbe_update_flash_X550() (Michal Schmidt) [RHEL-118532] - ixgbe: E610: add EEE support (Michal Schmidt) [RHEL-118532] - ixgbe: move EEE config validation out of ixgbe_set_eee() (Michal Schmidt) [RHEL-118532] - ixgbe: E610: update ACI command structs with EEE fields (Michal Schmidt) [RHEL-118532] - ixgbe: E610: use new version of 0x601 ACI command buffer (Michal Schmidt) [RHEL-118532] - ixgbe: E610: update EEE supported speeds (Michal Schmidt) [RHEL-118532] - ixgbe: E610: add discovering EEE capability (Michal Schmidt) [RHEL-118532] - ixgbe: stop re-reading flash on every get_drvinfo for e610 (Michal Schmidt) [RHEL-118532] - libie: prevent memleak in fwlog code (Michal Schmidt) [RHEL-118532] - libie: don't unroll if fwlog isn't supported (Michal Schmidt) [RHEL-118532] - ixgbe: refactor: use DECLARE_BITMAP for ring state field (Michal Schmidt) [RHEL-118532] - ixgbevf: fix link setup issue (Michal Schmidt) [RHEL-118534] - Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL uses [ixgbe,libie] (Michal Schmidt) [RHEL-118532] - Convert more 'alloc_obj' cases to default GFP_KERNEL arguments [ixgbe,ixgbevf,libie] (Michal Schmidt) [RHEL-118532 RHEL-118534] - Convert 'alloc_flex' family to use the new default GFP_KERNEL argument [ixgbe] (Michal Schmidt) [RHEL-118532] - Convert 'alloc_obj' family to use the new default GFP_KERNEL argument [ixgbe,ixgbevf,libie] (Michal Schmidt) [RHEL-118532 RHEL-118534] - treewide: Replace kmalloc with kmalloc_obj for non-scalar types [ixgbe,ixgbevf,libie] (Michal Schmidt) [RHEL-118532 RHEL-118534] - ixgbe: don't initialize aci lock in ixgbe_recovery_probe() (Michal Schmidt) [RHEL-118532] - ixgbe: fix memory leaks in the ixgbe_recovery_probe() path (Michal Schmidt) [RHEL-118532] - ixgbe: Add 10G-BX support (Michal Schmidt) [RHEL-118532] - ceph: fix NULL pointer dereference in ceph_mds_auth_match() (Alex Markuze) [RHEL-177507] - ceph: fix multifs mds auth caps issue (Alex Markuze) [RHEL-177507] * Mon Sep 14 2026 CKI KWF Bot [6.12.0-268.el10] - drm/connector/hdmi: Fix out of bounds memory read (Mika Penttilä) [RHEL-222711] - watchdog: fix hrtimer start when pretimeout is zero (David Arcari) [RHEL-255219] - platform/x86: int1092: Fix info leak in parse_package() (Dennis Chen) [RHEL-248696] - platform/x86: int1092: Fix potential memory leak in sar_probe() (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: free ACPI discovery data on early errors (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: initialize empty PMT read result (Dennis Chen) [RHEL-248696] - Replace by more specific (c files) [partial] (Dennis Chen) [RHEL-248696] - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Add NVL PCI IDs for SSRAM telemetry discovery (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Make PMT registration optional (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Add ACPI discovery scaffolding (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Switch to static array with per-index probe state (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Refactor DEVID/PWRMBASE extraction into helper (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Add PCI platform data (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc/ssram: Rename probe and PCI ID table for consistency (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Add ACPI PWRM telemetry driver for Nova Lake S (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Add PMC SSRAM Kconfig description (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt: Unify header fetch and add ACPI source (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt: Cache the telemetry discovery header (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt: Pass discovery index instead of resource (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt/telemetry: Move overlap check to post-decode hook (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt/crashlog: Split init into pre-decode (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmt: Add pre/post decode hooks around header parsing (Dennis Chen) [RHEL-248696] - platform/x86: intel-hid: Add HP ProBook x360 440 G1 to button_array_table (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Restore BAR fallback for header walk (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: rate-limit LTR scale-factor warning (Dennis Chen) [RHEL-248696] - platform/x86/intel/tpmi: convert mutex in mem_write() to guard (Dennis Chen) [RHEL-248696] - platform/x86/intel/tpmi: use cleanup helpers in mem_write() (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Add TPS68470 board data for intel nvl (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Rename daisy-chain GPIO props to generic (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery (Dennis Chen) [RHEL-248696] - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (Dennis Chen) [RHEL-248696] - platform/x86: intel_sar: Check ACPI_HANDLE() against NULL (Dennis Chen) [RHEL-248696] - platform/x86: intel/smartconnect: Check ACPI_HANDLE() against NULL (Dennis Chen) [RHEL-248696] - platform/x86: intel/rst: Check ACPI_COMPANION() against NULL (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Add Nova Lake support to intel_pmc_core driver (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Retrieve PMC info only for available PMCs (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Add support for variable DMU offsets (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Use PCI DID for PMC SSRAM device discovery (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Enable Pkgc blocking residency counter (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Enable PkgC LTR blocking counter (Dennis Chen) [RHEL-248696] - platform/x86/intel/pmc: Use __free() in pmc_core_punit_pmt_init() (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: allocate res with intel_vsec_dev (Dennis Chen) [RHEL-248696] - platform/x86/intel-uncore-freq: Expose instance ID in the sysfs (Dennis Chen) [RHEL-248696] - platform/x86/intel-uncore-freq: Rename instance_id (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Add support for GPIO type 0x02 (IR flood LED) (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Parameterize LED con_id in registration (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Rename pled to led in LED registration code (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Use local variable for LED struct access (Dennis Chen) [RHEL-248696] - platform/x86/intel/tpmi: Use 32 bit aligned address for debugfs mem write (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Add more MSI AI evo laptops (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Match MSI laptop board name (Dennis Chen) [RHEL-248696] - platform: int3472: Drop redundant initialisation to 0 and NULL (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Plumb ACPI PMT discovery tables through vsec (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Return real error codes from registration path (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Switch exported helpers from pci_dev to device (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Decouple add/link helpers from PCI (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Make driver_data info const (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Refactor base_addr handling (Dennis Chen) [RHEL-248696] - platform: int3472: Add MSI prestige board data (Dennis Chen) [RHEL-248696] - gpio: tps68470: Add i2c daisy chain support (Dennis Chen) [RHEL-248696] - platform: int3472: Add gpio software node (Dennis Chen) [RHEL-248696] - platform/x86: intel/smartconnect: Convert ACPI driver to a platform one (Dennis Chen) [RHEL-248696] - platform/x86: intel/rst: Convert ACPI driver to a platform one (Dennis Chen) [RHEL-248696] - Convert remaining multi-line kmalloc_obj/flex GFP_KERNEL uses [partial] (Dennis Chen) [RHEL-248696] - Convert 'alloc_obj' family to use the new default GFP_KERNEL argument [partial] (Dennis Chen) [RHEL-248696] - treewide: Replace kmalloc with kmalloc_obj for non-scalar types [partial] (Dennis Chen) [RHEL-248696] - platform/x86: int3472: Handle GPIO type 0x10 (DOVDD) (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: correct kernel-doc comments (Dennis Chen) [RHEL-248696] - platform/x86/intel/vsec: Remove a useless mutex (Dennis Chen) [RHEL-248696] - Documentation: admin-guide: pm: Add documentation for die_id (Dennis Chen) [RHEL-248696] - Documentation: admin-guide: pm: Add documentation for agent_types (Dennis Chen) [RHEL-248696] - Revert "platform/x86/intel/vsec: Make driver_data info const" (Dennis Chen) [RHEL-248696] - Revert "platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery" (Dennis Chen) [RHEL-248696] * Thu Sep 10 2026 CKI KWF Bot [6.12.0-267.el10] - Fix the statement regarding CONFIG_RHEL_DIFFERENCES in the FAQ (Vladislav Dronov) - virtio-net: fix len check in receive_big() (Laurent Vivier) [RHEL-238371] - virtio-net: fix incorrect flags recording in big mode (Laurent Vivier) [RHEL-238371] - virtio-net: fix received length check in big packets (Laurent Vivier) [RHEL-238371] - netfilter: flowtable: publish GC-visible tuple last (CKI Backport Bot) [RHEL-250533] {CVE-2026-74746} - iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes) [RHEL-250489] - fuse: fix race between interrupt and resend (Miklos Szeredi) [RHEL-254171] {CVE-2026-64265} - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Miklos Szeredi) [RHEL-254171] {CVE-2026-64265} - ALSA: virtio: Validate control metadata from the device (CKI Backport Bot) [RHEL-252341] {CVE-2026-64490} * Fri Sep 04 2026 CKI KWF Bot [6.12.0-266.el10] - mm/list_lru: drain before clearing xarray entry on reparent (Rafael Aquini) [RHEL-227151] {CVE-2026-53153} - redhat: set defaults for RHEL 10.3 (Shivani Chandanshive) - powerpc/perf: Add power12 Base Performance Monitoring support (Mamatha Inamdar) [RHEL-190876] - powerpc: Add Power12 architected mode (Mamatha Inamdar) [RHEL-190876] - powerpc: Add Power12 raw mode (Mamatha Inamdar) [RHEL-190876] - powerpc/pseries: Limit PVR list to 16 entries for CAS negotiation (Mamatha Inamdar) [RHEL-190876] - KVM: PPC: Book3S HV: Add Power11 capability support for Nested PAPR guests (Mamatha Inamdar) [RHEL-190876] - stmmac: s32: enable support for Multi-IRQ mode (Jared Kangas) [RHEL-168971] - dt-bindings: net: nxp,s32-dwmac: Declare per-queue interrupts (Jared Kangas) [RHEL-168971] - net: stmmac: platform: read channels irq (Jared Kangas) [RHEL-168971] - spi: dt-bindings: fsl,dspi: Fix example indentation (Jared Kangas) [RHEL-248519] - watchdog: s32g_wdt: remove incorrect options in watchdog_info struct (Jared Kangas) [RHEL-248519] - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Jared Kangas) [RHEL-248519] - usb: chipidea: core: convert ci_role_switch to local variable (Jared Kangas) [RHEL-248519] - usb: chipidea: udc: support dynamic gadget add/remove (Jared Kangas) [RHEL-248519] - usb: chipidea: udc: add a helper ci_udc_enable_vbus_irq() (Jared Kangas) [RHEL-248519] - usb: chipidea: otg: not wait vbus drop if use role_switch (Jared Kangas) [RHEL-248519] - usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (Jared Kangas) [RHEL-248519] - usb: chipidea: core: refactor ci_usb_role_switch_set() (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: fix resume error handling (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume (Jared Kangas) [RHEL-248519] - mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore (Jared Kangas) [RHEL-248519] - dt: bindings: fsl,vf610-pit: Add compatible for s32g2 and s32g3 (Jared Kangas) [RHEL-248519] - dt-bindings: timer: Add fsl,vf610-pit.yaml (Jared Kangas) [RHEL-248519] - pinctrl: s32cc: use dev_err_probe() and improve error messages (Jared Kangas) [RHEL-248519] - pinctrl: s32: correct kernel-doc bad line warning (Jared Kangas) [RHEL-248519] - i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) (Jared Kangas) [RHEL-248519] - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Jared Kangas) [RHEL-248519] - i2c: imx: Cancel hrtimer before clearing slave pointer (Jared Kangas) [RHEL-248519] - i2c: imx: Fix slave registration race and error handling (Jared Kangas) [RHEL-248519] - i2c: imx: mark I2C adapter when hardware is powered down (Jared Kangas) [RHEL-248519] - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (Jared Kangas) [RHEL-248519] - gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock (Jared Kangas) [RHEL-248519] - replace kernel-qe-ci gating with osci tier0 plans (Bruno Goncalves) [RHEL-186035] - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CKI Backport Bot) [RHEL-179960] {CVE-2026-46189} * Tue Sep 01 2026 CKI KWF Bot [6.12.0-265.el10] - redhat: bump RHEL_MINOR to 10.4 (Oleksii Baranov) - hwmon: (k10temp) Add per-CCD temperature monitoring for Zen5 Turin (Dennis Chen) [RHEL-247220] - s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks (Jan Polensky) [RHEL-248146] - fs/resctrl: Add "*" shorthand to set io_alloc CBM for all domains (Steve Best) [RHEL-174711] - fs/resctrl: Report invalid domain ID when parsing io_alloc_cbm (Steve Best) [RHEL-174711] - hwmon: spd5118: Add I3C support (Jennifer Berringer) [RHEL-143335] - hwmon: spd5118: Remove 16-bit addressing (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: Add ACPI ID for Tegra410 (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: Add ACPI core clock frequency quirk (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: Add SETAASA as supported CCC (Jennifer Berringer) [RHEL-143335] - i3c: master: match I3C device through DT and ACPI (Jennifer Berringer) [RHEL-143335] - i3c: master: Add support for devices without PID (Jennifer Berringer) [RHEL-143335] - i3c: master: Add support for devices using SETAASA (Jennifer Berringer) [RHEL-143335] - i3c: master: Support ACPI enumeration of child devices (Jennifer Berringer) [RHEL-143335] - i3c: master: Use unified device property interface (Jennifer Berringer) [RHEL-143335] - dt-bindings: i3c: Add mipi-i3c-static-method to support SETAASA (Jennifer Berringer) [RHEL-143335] - i3c: master: Expose the APIs to support I3C hub (Jennifer Berringer) [RHEL-143335] - i3c: master: rename i3c_master_reattach_i3c_dev() to *_locked (Jennifer Berringer) [RHEL-143335] - i3c: master: Use unsigned int for dev_nack_retry_count consistently (Jennifer Berringer) [RHEL-143335] - i3c: master: Add missing runtime PM get in dev_nack_retry_count_store() (Jennifer Berringer) [RHEL-143335] - i3c: master: Update dev_nack_retry_count under maintenance lock (Jennifer Berringer) [RHEL-143335] - i3c: master: Prevent reuse of dynamic address on device add failure (Jennifer Berringer) [RHEL-143335] - i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (Jennifer Berringer) [RHEL-143335] - i3c: master: Make hot-join workqueue freezable to block hot-join during suspend (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: Fix IBI count register selection for versalnet (Jennifer Berringer) [RHEL-143335] - i3c: dw: Simplify xfer cleanup with __free(kfree) (Jennifer Berringer) [RHEL-143335] - i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() (Jennifer Berringer) [RHEL-143335] - i3c: master: dw-i3c: Fix missing reset assertion in remove() callback (Jennifer Berringer) [RHEL-143335] - i3c: fix missing newline in dev_err messages (Jennifer Berringer) [RHEL-143335] - i3c: master: Add sysfs option to rescan bus via entdaa (Jennifer Berringer) [RHEL-143335] - i3c: master: use kzalloc_flex (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: Set SIR_REJECT in DAT on device attach and reattach (Jennifer Berringer) [RHEL-143335] - i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter (Jennifer Berringer) [RHEL-143335] - i3c: master: Convert more 'alloc_obj' cases to default GFP_KERNEL arguments (Jennifer Berringer) [RHEL-143335] - i3c: master: Convert 'alloc_obj' family to use the new default GFP_KERNEL argument (Jennifer Berringer) [RHEL-143335] - i3c: master: Replace kmalloc with kmalloc_obj for non-scalar types (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: fix SIR reject bit mapping for dynamic addresses (Jennifer Berringer) [RHEL-143335] - i3c: dw-i3c-master: convert spinlock usage to scoped guards (Jennifer Berringer) [RHEL-143335] - i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers() (Jennifer Berringer) [RHEL-143335] {CVE-2026-45863} - i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery (Jennifer Berringer) [RHEL-143335] - i3c: dw: Initialize spinlock to avoid upsetting lockdep (Jennifer Berringer) [RHEL-143335] - i3c: master: Introduce optional Runtime PM support (Jennifer Berringer) [RHEL-143335] - i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked() (Jennifer Berringer) [RHEL-143335] - i3c: master: Update hot-join flag only on success (Jennifer Berringer) [RHEL-143335] - i3c: dw: Preserve DAT entry bits when restoring addresses (Jennifer Berringer) [RHEL-143335] - i3c: dw: use FIELD_PREP for device address table macros (Jennifer Berringer) [RHEL-143335] - i3c: dw: Add support for Device NACK Retry configuration (Jennifer Berringer) [RHEL-143335] - i3c: add sysfs entry and attribute for Device NACK Retry count (Jennifer Berringer) [RHEL-143335] - i3c: master: Fix confusing cleanup.h syntax (Jennifer Berringer) [RHEL-143335] - i3c: master: cleanup callback .priv_xfers() (Jennifer Berringer) [RHEL-143335] - i3c: master: switch to use new callback .i3c_xfers() from .priv_xfers() (Jennifer Berringer) [RHEL-143335] - i3c: document i3c_xfers (Jennifer Berringer) [RHEL-143335] - i3c: master: svc: Add basic HDR mode support (Jennifer Berringer) [RHEL-143335] - i3c: master: svc: Replace bool rnw with union for HDR support (Jennifer Berringer) [RHEL-143335] - i3c: Switch to use new i3c_xfer from i3c_priv_xfer (Jennifer Berringer) [RHEL-143335] - i3c: Add HDR API support (Jennifer Berringer) [RHEL-143335] - i3c: mipi-i3c-hci: Use core helpers for DMA mapping and bounce buffering (Jennifer Berringer) [RHEL-143335] - i3c: master: svc: skip address resend on repeat START (Jennifer Berringer) [RHEL-143335] - i3c: master: add WQ_PERCPU to alloc_workqueue users (Jennifer Berringer) [RHEL-143335] - i3c: master: Remove i3c_device_free_ibi from i3c_device_remove (Jennifer Berringer) [RHEL-143335] - i3c: fix big-endian FIFO transfers (Jennifer Berringer) [RHEL-143335] - i3c: Remove superfluous FIXME (Jennifer Berringer) [RHEL-143335] - i3c: Fix default I2C adapter timeout value (Jennifer Berringer) [RHEL-143335] - i3c: master: Add helpers for DMA mapping and bounce buffer handling (Jennifer Berringer) [RHEL-143335] - i3c: add missing include to internal header (Jennifer Berringer) [RHEL-143335] - i3c: dw: Remove redundant pm_runtime_mark_last_busy() calls (Jennifer Berringer) [RHEL-143335] - i3c: Add more parameters for controllers to the header (Jennifer Berringer) [RHEL-143335] - i3c: Standardize defines for specification parameters (Jennifer Berringer) [RHEL-143335] - i3c: master: cdns: Use i3c_writel_fifo() and i3c_readl_fifo() (Jennifer Berringer) [RHEL-143335] - i3c: master: dw: Use i3c_writel_fifo() and i3c_readl_fifo() (Jennifer Berringer) [RHEL-143335] - i3c: master: Add inline i3c_readl_fifo() and i3c_writel_fifo() (Jennifer Berringer) [RHEL-143335] - i3c: prefix hexadecimal entries in sysfs (Jennifer Berringer) [RHEL-143335] - i3c: dw: replace ENOTSUPP with SUSV4-compliant EOPNOTSUPP (Jennifer Berringer) [RHEL-143335] - i3c: master: replace ENOTSUPP with SUSV4-compliant EOPNOTSUPP (Jennifer Berringer) [RHEL-143335] - i3c: don't fail if GETHDRCAP is unsupported (Jennifer Berringer) [RHEL-143335] - i3c: master: Initialize ret in i3c_i2c_notifier_call() (Jennifer Berringer) [RHEL-143335] - i3c: dw: use adapter timeout value for I2C transfers (Jennifer Berringer) [RHEL-143335] - i3c: Add NULL pointer check in i3c_master_queue_ibi() (Jennifer Berringer) [RHEL-143335] {CVE-2025-23147} - i3c: mipi-i3c-hci: Use I2C DMA-safe api (Jennifer Berringer) [RHEL-143335] - i3c: Remove the const qualifier from i2c_msg pointer in i2c_xfers API (Jennifer Berringer) [RHEL-143335] - i3c: master: Fix missing 'ret' assignment in set_speed() (Jennifer Berringer) [RHEL-143335] - i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock (Jennifer Berringer) [RHEL-143335] {CVE-2024-43098} - i3c: Document I3C_ADDR_SLOT_EXT_STATUS_MASK (Jennifer Berringer) [RHEL-143335] - i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() (Jennifer Berringer) [RHEL-143335] {CVE-2024-56562} - i3c: master: Remove i3c_dev_disable_ibi_locked(olddev) on device hotjoin (Jennifer Berringer) [RHEL-143335] - i3c: master: Fix dynamic address leak when 'assigned-address' is present (Jennifer Berringer) [RHEL-143335] - i3c: master: Extend address status bit to 4 and add I3C_ADDR_SLOT_EXT_DESIRED (Jennifer Berringer) [RHEL-143335] - i3c: master: Replace hard code 2 with macro I3C_ADDR_SLOT_STATUS_BITS (Jennifer Berringer) [RHEL-143335] - ACPICA: fix I2C LVR item count in the conversion table (Jennifer Berringer) [RHEL-143335] - ACPICA: Mention the LVR bits (Jennifer Berringer) [RHEL-143335] - ACPICA: Change LVR to 8 bit value (Jennifer Berringer) [RHEL-143335] - ACPICA: Fetch LVR I2C resource descriptor (Jennifer Berringer) [RHEL-143335] - ACPICA: Add LVR to acrestyp.h (Jennifer Berringer) [RHEL-143335] - arm64: Add support for TSV110 Spectre-BHB mitigation (Steve Dunnagan) [RHEL-224485] - rcu: Fix rcu_read_unlock() deadloop due to softirq (Jerome Marchand) [RHEL-178446] ### # The following Emacs magic makes C-c C-e use UTC dates. # Local Variables: # rpm-change-log-uses-utc: t # End: ###