diff --git a/Makefile.rhelver b/Makefile.rhelver index 7098d7f26..95b9fd7b5 100644 --- a/Makefile.rhelver +++ b/Makefile.rhelver @@ -12,7 +12,7 @@ RHEL_MINOR = 99 # # Use this spot to avoid future merge conflicts. # Do not trim this comment. -RHEL_RELEASE = 59 +RHEL_RELEASE = 0 # # RHEL_REBASE_NUM diff --git a/Patchlist.changelog b/Patchlist.changelog index f4ca7a233..774758f9c 100644 --- a/Patchlist.changelog +++ b/Patchlist.changelog @@ -1,474 +1,159 @@ -https://gitlab.com/cki-project/kernel-ark/-/commit/49bcc48074ba1f9c772b5c7ae11123a8ed3e0ac1 - 49bcc48074ba1f9c772b5c7ae11123a8ed3e0ac1 efi: Fix swapped arguments to bsearch() in efi_status_to_*() +https://gitlab.com/cki-project/kernel-ark/-/commit/81a20aa2ab1d77ac14d2cc33e0ef81e2a471aa87 + 81a20aa2ab1d77ac14d2cc33e0ef81e2a471aa87 efi: Fix swapped arguments to bsearch() in efi_status_to_*() -https://gitlab.com/cki-project/kernel-ark/-/commit/fe3e9e24af806d756edbda922103b1fa95d9b89b - fe3e9e24af806d756edbda922103b1fa95d9b89b Revert "Removing Obsolete hba pci-ids from rhel8" +https://gitlab.com/cki-project/kernel-ark/-/commit/a01dfc2eecc355280f3e891c22a442043a144d09 + a01dfc2eecc355280f3e891c22a442043a144d09 arm64: add early lockdown for secure boot -https://gitlab.com/cki-project/kernel-ark/-/commit/c4a0a995da9df8732f688d09db5252173277589d - c4a0a995da9df8732f688d09db5252173277589d rh_messages.h: add missing lpfc devices +https://gitlab.com/cki-project/kernel-ark/-/commit/835aad4b48e7c3c796f38827cdc7c89c1d7c3671 + 835aad4b48e7c3c796f38827cdc7c89c1d7c3671 efi: pass secure boot mode to kernel proper -https://gitlab.com/cki-project/kernel-ark/-/commit/0ad9a88c3263fa8fa39437f69472588917255c99 - 0ad9a88c3263fa8fa39437f69472588917255c99 kernel: extend rh_waived to cope better with the CVE mitigations case +https://gitlab.com/cki-project/kernel-ark/-/commit/67ad645623d11a9d075bcee4176500288463a4fc + 67ad645623d11a9d075bcee4176500288463a4fc selftests/bpf: Remove ksyms_weak_lskel test -https://gitlab.com/cki-project/kernel-ark/-/commit/cf18c49636f2583c85831f909699034026325242 - cf18c49636f2583c85831f909699034026325242 rh_messages.h: add missing aacraid device +https://gitlab.com/cki-project/kernel-ark/-/commit/20b98e0f6dc975660f0a7a8287066765a987be92 + 20b98e0f6dc975660f0a7a8287066765a987be92 Simplify include Makefile.rhelver -https://gitlab.com/cki-project/kernel-ark/-/commit/26ca931184edb2c3c7f7c1951f53fa3333d9c90e - 26ca931184edb2c3c7f7c1951f53fa3333d9c90e rh_messages.h: update unmaintained drivers +https://gitlab.com/cki-project/kernel-ark/-/commit/02f378d0fe07dfcbb30e3aa591314902881ef4fa + 02f378d0fe07dfcbb30e3aa591314902881ef4fa redhat: make ENABLE_WERROR also enable OBJTOOL_WERROR -https://gitlab.com/cki-project/kernel-ark/-/commit/c1c1a1b7059900f4b9b657f5189285a287160e11 - c1c1a1b7059900f4b9b657f5189285a287160e11 arm64: add early lockdown for secure boot +https://gitlab.com/cki-project/kernel-ark/-/commit/6e07edcef9f7b0403e831926b736abf6c90523d3 + 6e07edcef9f7b0403e831926b736abf6c90523d3 efi,lockdown: fix kernel lockdown on Secure Boot -https://gitlab.com/cki-project/kernel-ark/-/commit/a613ae52a8d9378e6fa70f697b3ce0acee220491 - a613ae52a8d9378e6fa70f697b3ce0acee220491 efi: pass secure boot mode to kernel proper +https://gitlab.com/cki-project/kernel-ark/-/commit/490870ddbac940ef0951b51ff5114abcb000e5a0 + 490870ddbac940ef0951b51ff5114abcb000e5a0 Revert "nvme: Return BLK_STS_TARGET if the DNR bit is set" -https://gitlab.com/cki-project/kernel-ark/-/commit/f869258b6b654d316e84325e46e431da4dfd04e7 - f869258b6b654d316e84325e46e431da4dfd04e7 selftests/bpf: Remove ksyms_weak_lskel test +https://gitlab.com/cki-project/kernel-ark/-/commit/ccea25924b377a216198fd17e0946a728403cfdb + ccea25924b377a216198fd17e0946a728403cfdb Revert "nvme: allow local retry and proper failover for REQ_FAILFAST_TRANSPORT" -https://gitlab.com/cki-project/kernel-ark/-/commit/8b69219fe6a11766cf1a2e07dc94e56448b47824 - 8b69219fe6a11766cf1a2e07dc94e56448b47824 Simplify include Makefile.rhelver +https://gitlab.com/cki-project/kernel-ark/-/commit/26a5bf6f642f52094c1a755a1075dabed2481f9b + 26a5bf6f642f52094c1a755a1075dabed2481f9b Revert "nvme: decouple basic ANA log page re-read support from native multipathing" -https://gitlab.com/cki-project/kernel-ark/-/commit/c2621ac616e25a9a04fbcb8af0c1f8b2bdd8c099 - c2621ac616e25a9a04fbcb8af0c1f8b2bdd8c099 redhat: make ENABLE_WERROR also enable OBJTOOL_WERROR +https://gitlab.com/cki-project/kernel-ark/-/commit/a07913220b780b88b3b8e0cbb9d57a10e48ba316 + a07913220b780b88b3b8e0cbb9d57a10e48ba316 Revert "nvme: nvme_mpath_init remove multipath check" -https://gitlab.com/cki-project/kernel-ark/-/commit/d28cbdeb89fe565e10fb4be8d8378153e86611f6 - d28cbdeb89fe565e10fb4be8d8378153e86611f6 main.c: fix initcall blacklisted +https://gitlab.com/cki-project/kernel-ark/-/commit/dda25f2c4d7f9b7f2c7e5abca2ab3c91cbbe7305 + dda25f2c4d7f9b7f2c7e5abca2ab3c91cbbe7305 redhat: fix modules.order target -https://gitlab.com/cki-project/kernel-ark/-/commit/b71ab57c8db44881edc32a124ddc2ebe536b6a4c - b71ab57c8db44881edc32a124ddc2ebe536b6a4c arch/x86/kernel/setup.c: fix rh_check_supported +https://gitlab.com/cki-project/kernel-ark/-/commit/d1f964250e5c64b3f2cb292068673a859828cc72 + d1f964250e5c64b3f2cb292068673a859828cc72 crypto: sig - Disable signing -https://gitlab.com/cki-project/kernel-ark/-/commit/c4ea2384863e54e0c5582b3508518e659581ce69 - c4ea2384863e54e0c5582b3508518e659581ce69 efi,lockdown: fix kernel lockdown on Secure Boot +https://gitlab.com/cki-project/kernel-ark/-/commit/47ec3de0fcd11ebed1c88d95bf1d14f72eba9f6f + 47ec3de0fcd11ebed1c88d95bf1d14f72eba9f6f redhat: include resolve_btfids in kernel-devel -https://gitlab.com/cki-project/kernel-ark/-/commit/60b2ddeb0986e1c43a98b44a4ab414a7e2744701 - 60b2ddeb0986e1c43a98b44a4ab414a7e2744701 Revert "nvme: Return BLK_STS_TARGET if the DNR bit is set" +https://gitlab.com/cki-project/kernel-ark/-/commit/8355fba715f1b9f1f9701c91e04518856f7b792c + 8355fba715f1b9f1f9701c91e04518856f7b792c redhat: workaround CKI cross compilation for scripts -https://gitlab.com/cki-project/kernel-ark/-/commit/860632dd288c7aa7807959a79af9159482510cd1 - 860632dd288c7aa7807959a79af9159482510cd1 Revert "nvme: allow local retry and proper failover for REQ_FAILFAST_TRANSPORT" +https://gitlab.com/cki-project/kernel-ark/-/commit/5b7011e0ec2c0fa155d032baa3ac5b9392f81ad9 + 5b7011e0ec2c0fa155d032baa3ac5b9392f81ad9 crypto: akcipher - Disable signing and decryption -https://gitlab.com/cki-project/kernel-ark/-/commit/aaef2c3ee081c8980bb60fd4b7a6ed9e187d9048 - aaef2c3ee081c8980bb60fd4b7a6ed9e187d9048 Revert "nvme: decouple basic ANA log page re-read support from native multipathing" +https://gitlab.com/cki-project/kernel-ark/-/commit/30810a7b696881d18110b621c52b63a5014e74dc + 30810a7b696881d18110b621c52b63a5014e74dc crypto: dh - implement FIPS PCT -https://gitlab.com/cki-project/kernel-ark/-/commit/5cd4353dae0ee79d13f57b7ccee85cd0bcbe4b4f - 5cd4353dae0ee79d13f57b7ccee85cd0bcbe4b4f Revert "nvme: nvme_mpath_init remove multipath check" +https://gitlab.com/cki-project/kernel-ark/-/commit/bf3913021e0c10dab5d3502ff50de625cd1a47e3 + bf3913021e0c10dab5d3502ff50de625cd1a47e3 crypto: ecdh - disallow plain "ecdh" usage in FIPS mode -https://gitlab.com/cki-project/kernel-ark/-/commit/656a0565ffe54f99ac1390a68c5ee7050ab6fb25 - 656a0565ffe54f99ac1390a68c5ee7050ab6fb25 redhat: automotive: define CONFIG_RH_AUTOMOTIVE +https://gitlab.com/cki-project/kernel-ark/-/commit/ae4f5f81d9eded60a977c1f9a70b9770bc280d29 + ae4f5f81d9eded60a977c1f9a70b9770bc280d29 crypto: seqiv - flag instantiations as FIPS compliant -https://gitlab.com/cki-project/kernel-ark/-/commit/f1025d6236c72b4fbd03940b6fa2178f2a84f418 - f1025d6236c72b4fbd03940b6fa2178f2a84f418 redhat: fix modules.order target +https://gitlab.com/cki-project/kernel-ark/-/commit/db4bbc919011393058e3b5c8248085123e5968ba + db4bbc919011393058e3b5c8248085123e5968ba lsm: update security_lock_kernel_down -https://gitlab.com/cki-project/kernel-ark/-/commit/6e0fa997052c92d6085a50083e75dedc0160443f - 6e0fa997052c92d6085a50083e75dedc0160443f [redhat] rh_messages.h: driver and device updates +https://gitlab.com/cki-project/kernel-ark/-/commit/5071f9d14a7bb68922b2128d4954765079d3bd96 + 5071f9d14a7bb68922b2128d4954765079d3bd96 scsi: sd: Add "probe_type" module parameter to allow synchronous probing -https://gitlab.com/cki-project/kernel-ark/-/commit/d8822fd0573e9f254f097c1743078e4e74ac70f5 - d8822fd0573e9f254f097c1743078e4e74ac70f5 crypto: rng - Fix extrng EFAULT handling +https://gitlab.com/cki-project/kernel-ark/-/commit/f1d1d525f515912337d656d9bb7e48f4e3def2b1 + f1d1d525f515912337d656d9bb7e48f4e3def2b1 Revert "Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64" -https://gitlab.com/cki-project/kernel-ark/-/commit/c224e4b6a61af08574bb0565755ed609bf08cacb - c224e4b6a61af08574bb0565755ed609bf08cacb crypto: sig - Disable signing +https://gitlab.com/cki-project/kernel-ark/-/commit/da0867c57355fc7ef170a3321f10dccf47e94877 + da0867c57355fc7ef170a3321f10dccf47e94877 Enable IO_URING for RHEL -https://gitlab.com/cki-project/kernel-ark/-/commit/39417e970be7f6bc63f34d5ed5511f7e629802c2 - 39417e970be7f6bc63f34d5ed5511f7e629802c2 crypto: rng - Ensure stdrng is tested before user-space starts +https://gitlab.com/cki-project/kernel-ark/-/commit/2d3d5239bce0555195108ad6e379a097ecea499a + 2d3d5239bce0555195108ad6e379a097ecea499a Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64 -https://gitlab.com/cki-project/kernel-ark/-/commit/52be246b6342ed5b1486729fd5c5893b10549a92 - 52be246b6342ed5b1486729fd5c5893b10549a92 [redhat] rh_messages.h: Mark BlueField-4 as disabled +https://gitlab.com/cki-project/kernel-ark/-/commit/7b5ad41adec2a06994d3ab0b2d861ef8169133e1 + 7b5ad41adec2a06994d3ab0b2d861ef8169133e1 redhat: version two of Makefile.rhelver tweaks -https://gitlab.com/cki-project/kernel-ark/-/commit/2c9e64af9fa1f8599ce05877441afcac8ac91b04 - 2c9e64af9fa1f8599ce05877441afcac8ac91b04 Update the RHEL_DIFFERENCES help string +https://gitlab.com/cki-project/kernel-ark/-/commit/4f9d20c40eddd10e3a39aa41619649d20da8805c + 4f9d20c40eddd10e3a39aa41619649d20da8805c redhat: adapt to upstream Makefile change -https://gitlab.com/cki-project/kernel-ark/-/commit/beef34cb1efc34b7fbee35535c66915995d12ed1 - beef34cb1efc34b7fbee35535c66915995d12ed1 redhat: include resolve_btfids in kernel-devel +https://gitlab.com/cki-project/kernel-ark/-/commit/332f2b8dcdd8f49900e96bc9a09d41c4a0c4c9d2 + 332f2b8dcdd8f49900e96bc9a09d41c4a0c4c9d2 Change acpi_bus_get_acpi_device to acpi_get_acpi_dev -https://gitlab.com/cki-project/kernel-ark/-/commit/1a1426b7a8df854c78385dd8ce8b74e9ee641477 - 1a1426b7a8df854c78385dd8ce8b74e9ee641477 redhat: workaround CKI cross compilation for scripts +https://gitlab.com/cki-project/kernel-ark/-/commit/7a6cdc8326ca715509cf539a57dd2e1dd8700170 + 7a6cdc8326ca715509cf539a57dd2e1dd8700170 RHEL: disable io_uring support -https://gitlab.com/cki-project/kernel-ark/-/commit/2c83d6cfffe1f891bf024df81be6cd41c2073ad9 - 2c83d6cfffe1f891bf024df81be6cd41c2073ad9 crypto: akcipher - Disable signing and decryption +https://gitlab.com/cki-project/kernel-ark/-/commit/65567a1d41062bd1fe51272cf7455144492c9116 + 65567a1d41062bd1fe51272cf7455144492c9116 nvme: nvme_mpath_init remove multipath check -https://gitlab.com/cki-project/kernel-ark/-/commit/af93553b8d335ccf5dd4f90ab9419e497aa36a80 - af93553b8d335ccf5dd4f90ab9419e497aa36a80 crypto: dh - implement FIPS PCT +https://gitlab.com/cki-project/kernel-ark/-/commit/be68429eff112e9e3f38ad7f10972977b69a16ed + be68429eff112e9e3f38ad7f10972977b69a16ed nvme: decouple basic ANA log page re-read support from native multipathing -https://gitlab.com/cki-project/kernel-ark/-/commit/f0540d9d32978dff227cbb930193e8dc2557b23b - f0540d9d32978dff227cbb930193e8dc2557b23b crypto: ecdh - disallow plain "ecdh" usage in FIPS mode +https://gitlab.com/cki-project/kernel-ark/-/commit/6eca5f6e83d3738905e1e3493f48fd3d0680e3a0 + 6eca5f6e83d3738905e1e3493f48fd3d0680e3a0 nvme: allow local retry and proper failover for REQ_FAILFAST_TRANSPORT -https://gitlab.com/cki-project/kernel-ark/-/commit/243ef89ad354eea332d7bfb23fd4cf259240de91 - 243ef89ad354eea332d7bfb23fd4cf259240de91 crypto: seqiv - flag instantiations as FIPS compliant +https://gitlab.com/cki-project/kernel-ark/-/commit/29677a43a8c362240703059390d6faf59c76aa6c + 29677a43a8c362240703059390d6faf59c76aa6c nvme: Return BLK_STS_TARGET if the DNR bit is set -https://gitlab.com/cki-project/kernel-ark/-/commit/6a23cbc588e9b9f7b2bc7250c6c6903d4d904eb1 - 6a23cbc588e9b9f7b2bc7250c6c6903d4d904eb1 [kernel] bpf: set default value for bpf_jit_harden +https://gitlab.com/cki-project/kernel-ark/-/commit/31187c801e8fb3a0b973158d466f39e3b5b0e160 + 31187c801e8fb3a0b973158d466f39e3b5b0e160 REDHAT: coresight: etm4x: Disable coresight on HPE Apollo 70 -https://gitlab.com/cki-project/kernel-ark/-/commit/bb84b630a172d0204c8d243c57a6a1d2eae7843c - bb84b630a172d0204c8d243c57a6a1d2eae7843c not upstream: Disable vdso getrandom when FIPS is enabled +https://gitlab.com/cki-project/kernel-ark/-/commit/5aa0d0b6ef436e759028dc0199f6814c67f0cdd7 + 5aa0d0b6ef436e759028dc0199f6814c67f0cdd7 KEYS: Make use of platform keyring for module signature verify -https://gitlab.com/cki-project/kernel-ark/-/commit/b643998c61552fb5615268e7e529999d64d54175 - b643998c61552fb5615268e7e529999d64d54175 Add support to rh_waived cmdline boot parameter +https://gitlab.com/cki-project/kernel-ark/-/commit/cf2e0ac64302ca6a1d1332ce374345ba0f12465a + cf2e0ac64302ca6a1d1332ce374345ba0f12465a Input: rmi4 - remove the need for artificial IRQ in case of HID -https://gitlab.com/cki-project/kernel-ark/-/commit/a1e04b6f3580382a902256c7bf8b395b9a1be47f - a1e04b6f3580382a902256c7bf8b395b9a1be47f rh_flags: fix failed when register_sysctl_sz rh_flags_table to kernel +https://gitlab.com/cki-project/kernel-ark/-/commit/c6a7b31d6b58e3d39693c0dd69d66adcea5465dd + c6a7b31d6b58e3d39693c0dd69d66adcea5465dd ARM: tegra: usb no reset -https://gitlab.com/cki-project/kernel-ark/-/commit/03cf1862c6221ee2a6de9a5ab25adaec6460b62e - 03cf1862c6221ee2a6de9a5ab25adaec6460b62e [redhat] rh_flags: constify the ctl_table argument of proc_handler +https://gitlab.com/cki-project/kernel-ark/-/commit/b3fc067af0dce9006d34cf04bc0ee070000e1513 + b3fc067af0dce9006d34cf04bc0ee070000e1513 arm: make CONFIG_HIGHPTE optional without CONFIG_EXPERT -https://gitlab.com/cki-project/kernel-ark/-/commit/e2708e55f9151652da80e388b4bf88c649288c0f - e2708e55f9151652da80e388b4bf88c649288c0f redhat: rh_flags: declare proper static methods when !CONFIG_RHEL_DIFFERENCES +https://gitlab.com/cki-project/kernel-ark/-/commit/113c3d73bb8e5e0bbb2ab746dbef82b9e3295599 + 113c3d73bb8e5e0bbb2ab746dbef82b9e3295599 s390: Lock down the kernel when the IPL secure flag is set -https://gitlab.com/cki-project/kernel-ark/-/commit/6f593811cc1e5664f45fe2d09916eada1187e992 - 6f593811cc1e5664f45fe2d09916eada1187e992 redhat: make bnx2xx drivers unmaintained in rhel-10 +https://gitlab.com/cki-project/kernel-ark/-/commit/7e05e4541f984c3a02bde4ea74105fc5b1d1d8ff + 7e05e4541f984c3a02bde4ea74105fc5b1d1d8ff efi: Lock down the kernel if booted in secure boot mode -https://gitlab.com/cki-project/kernel-ark/-/commit/5db8220bd67c719a20c1269233585b40f48837da - 5db8220bd67c719a20c1269233585b40f48837da rh_flags: Rename rh_features to rh_flags +https://gitlab.com/cki-project/kernel-ark/-/commit/fdb8edeac9bfcc347b01ff1e2b04966c8e945e53 + fdb8edeac9bfcc347b01ff1e2b04966c8e945e53 efi: Add an EFI_SECURE_BOOT flag to indicate secure boot mode -https://gitlab.com/cki-project/kernel-ark/-/commit/19ca502a0087eed65a014c6271f9bfc207d8d7eb - 19ca502a0087eed65a014c6271f9bfc207d8d7eb kernel: rh_features: fix reading empty feature list from /proc +https://gitlab.com/cki-project/kernel-ark/-/commit/da26048afc4475d607b0e6112dbe0e619196f5c1 + da26048afc4475d607b0e6112dbe0e619196f5c1 security: lockdown: expose a hook to lock the kernel down -https://gitlab.com/cki-project/kernel-ark/-/commit/ba24639032f00b47748a6f39a4eb33950df015c2 - ba24639032f00b47748a6f39a4eb33950df015c2 rh_features: move rh_features entry to sys/kernel +https://gitlab.com/cki-project/kernel-ark/-/commit/2e0577ec1ecda4e786f778d4c512bfad989f3799 + 2e0577ec1ecda4e786f778d4c512bfad989f3799 Make get_cert_list() use efi_status_to_str() to print error messages. -https://gitlab.com/cki-project/kernel-ark/-/commit/883e43fe6a0da0d9ad90e7c997a95f11bab9b888 - 883e43fe6a0da0d9ad90e7c997a95f11bab9b888 rh_features: convert to atomic allocation +https://gitlab.com/cki-project/kernel-ark/-/commit/aa05f82cd8824e07e328dd53c2f37f823fad2bb8 + aa05f82cd8824e07e328dd53c2f37f823fad2bb8 Add efi_status_to_str() and rework efi_status_to_err(). -https://gitlab.com/cki-project/kernel-ark/-/commit/c8daa2e832df14ee9174435a357b2ae0994a3ef3 - c8daa2e832df14ee9174435a357b2ae0994a3ef3 add rh_features to /proc +https://gitlab.com/cki-project/kernel-ark/-/commit/25db20d85b2c112ec891575b50a29b509557ddbd + 25db20d85b2c112ec891575b50a29b509557ddbd arm: aarch64: Drop the EXPERT setting from ARM64_FORCE_52BIT -https://gitlab.com/cki-project/kernel-ark/-/commit/4f33dbbe3ec578d49e12c07421b913bf480fccef - 4f33dbbe3ec578d49e12c07421b913bf480fccef add support for rh_features +https://gitlab.com/cki-project/kernel-ark/-/commit/26db08a9d6667f8df4cb3f60ec2b1308a6faa9ed + 26db08a9d6667f8df4cb3f60ec2b1308a6faa9ed iommu/arm-smmu: workaround DMA mode issues -https://gitlab.com/cki-project/kernel-ark/-/commit/53a5900b05260b81f13eb3b9d6a9419429f310ab - 53a5900b05260b81f13eb3b9d6a9419429f310ab [redhat] PCI: Fix pci_rh_check_status() call semantics +https://gitlab.com/cki-project/kernel-ark/-/commit/70eb5149137f763f65462b234053fb48da161a93 + 70eb5149137f763f65462b234053fb48da161a93 ahci: thunderx2: Fix for errata that affects stop engine -https://gitlab.com/cki-project/kernel-ark/-/commit/aeb9a237a0ec39b7bde89d8bb040cd5b267f6802 - aeb9a237a0ec39b7bde89d8bb040cd5b267f6802 scsi: sd: condition probe_type under RHEL_DIFFERENCES +https://gitlab.com/cki-project/kernel-ark/-/commit/3a43b7b70276843241a76d70af450e38ec7f7747 + 3a43b7b70276843241a76d70af450e38ec7f7747 Vulcan: AHCI PCI bar fix for Broadcom Vulcan early silicon -https://gitlab.com/cki-project/kernel-ark/-/commit/159e72af8b1631b720f4a7e0012fa624764cecde - 159e72af8b1631b720f4a7e0012fa624764cecde scsi: sd: remove unused sd_probe_types +https://gitlab.com/cki-project/kernel-ark/-/commit/4e813b1d3ac0451a582e9e2e38f3c96f4687ce78 + 4e813b1d3ac0451a582e9e2e38f3c96f4687ce78 tags.sh: Ignore redhat/rpm -https://gitlab.com/cki-project/kernel-ark/-/commit/d8c04860eb7bf29617ca1754f1076fd9f5992e77 - d8c04860eb7bf29617ca1754f1076fd9f5992e77 [redhat] rh_messages.h: mark mlx5 on Bluefield-3 as unmaintained +https://gitlab.com/cki-project/kernel-ark/-/commit/2593cba969b5b10f4aaa0dce46e456d56f7f11fc + 2593cba969b5b10f4aaa0dce46e456d56f7f11fc aarch64: acpi scan: Fix regression related to X-Gene UARTs -https://gitlab.com/cki-project/kernel-ark/-/commit/496c64b4afece4ab525467a6be71ffe60d0c564f - 496c64b4afece4ab525467a6be71ffe60d0c564f [redhat] rh_messages.h: initial driver and device lists +https://gitlab.com/cki-project/kernel-ark/-/commit/07a6ba976d578afb4a9eb2e52d388a0c43bf842a + 07a6ba976d578afb4a9eb2e52d388a0c43bf842a ACPI / irq: Workaround firmware issue on X-Gene based m400 -https://gitlab.com/cki-project/kernel-ark/-/commit/5cf456aaba6f5c9406421c04c65d43b2c71f5927 - 5cf456aaba6f5c9406421c04c65d43b2c71f5927 arch/x86: Fix XSAVE check for x86_64-v2 check +https://gitlab.com/cki-project/kernel-ark/-/commit/780094b5a948e95e69ba480849f1dd4a57be6165 + 780094b5a948e95e69ba480849f1dd4a57be6165 ACPI: APEI: arm64: Ignore broken HPE moonshot APEI support -https://gitlab.com/cki-project/kernel-ark/-/commit/252bf9586fca6e57a51966c0294a9a0cb33ff4f5 - 252bf9586fca6e57a51966c0294a9a0cb33ff4f5 arch/x86/kernel/setup.c: fixup rh_check_supported +https://gitlab.com/cki-project/kernel-ark/-/commit/b374ae53ea943c1733cbe316d5b44a7ace15b929 + b374ae53ea943c1733cbe316d5b44a7ace15b929 Pull the RHEL version defines out of the Makefile -https://gitlab.com/cki-project/kernel-ark/-/commit/30faf17591afbd4230d590355351044294ad43d2 - 30faf17591afbd4230d590355351044294ad43d2 lsm: update security_lock_kernel_down - -https://gitlab.com/cki-project/kernel-ark/-/commit/e88ee9e2e869e7259faa5bf3ff6689becabb53cb - e88ee9e2e869e7259faa5bf3ff6689becabb53cb arch/x86: mark x86_64-v1 and x86_64-v2 processors as deprecated - -https://gitlab.com/cki-project/kernel-ark/-/commit/26ebc304df38a49ce7cc69b4bdf220298cff2460 - 26ebc304df38a49ce7cc69b4bdf220298cff2460 redhat: kABI: add missing RH_KABI_SIZE_ALIGN_CHECKS Kconfig option - -https://gitlab.com/cki-project/kernel-ark/-/commit/8c71392703448be8e8217592dd46ea1cc8b157e1 - 8c71392703448be8e8217592dd46ea1cc8b157e1 redhat: rh_kabi: introduce RH_KABI_EXCLUDE_WITH_SIZE - -https://gitlab.com/cki-project/kernel-ark/-/commit/d42afcb843fcc87e59ba39b5574c18d89fd07a91 - d42afcb843fcc87e59ba39b5574c18d89fd07a91 redhat: rh_kabi: move semicolon inside __RH_KABI_CHECK_SIZE - -https://gitlab.com/cki-project/kernel-ark/-/commit/95a56955f9ba6ef1e1dd2d99d8f98254da274267 - 95a56955f9ba6ef1e1dd2d99d8f98254da274267 random: replace import_single_range() with import_ubuf() - -https://gitlab.com/cki-project/kernel-ark/-/commit/92d6612578b79fd3a09e10504ed71209ba43c271 - 92d6612578b79fd3a09e10504ed71209ba43c271 ext4: Mark mounting fs-verity filesystems as tech-preview - -https://gitlab.com/cki-project/kernel-ark/-/commit/5c51745b8aec113ff0605ab833c3e472d99c55c8 - 5c51745b8aec113ff0605ab833c3e472d99c55c8 erofs: Add tech preview markers at mount - -https://gitlab.com/cki-project/kernel-ark/-/commit/6d687c70a7eda10eac0ddc6eedeaccc30eef5349 - 6d687c70a7eda10eac0ddc6eedeaccc30eef5349 kernel/rh_messages.c: Mark functions as possibly unused - -https://gitlab.com/cki-project/kernel-ark/-/commit/dfb09b1d833cad815ea2f5cb69505010de260c40 - dfb09b1d833cad815ea2f5cb69505010de260c40 crypto: rng - Override drivers/char/random in FIPS mode - -https://gitlab.com/cki-project/kernel-ark/-/commit/ddbe3667f2462817f3f936141fff08604dde1564 - ddbe3667f2462817f3f936141fff08604dde1564 random: Add hook to override device reads and getrandom(2) - -https://gitlab.com/cki-project/kernel-ark/-/commit/92525a9129d85fa6400c9e653379862a67cb43b2 - 92525a9129d85fa6400c9e653379862a67cb43b2 [redhat] kernel/rh_messages.c: move hardware tables to rh_messages.h - -https://gitlab.com/cki-project/kernel-ark/-/commit/eacd81fdaf31d456a82c553735faf64c8efad2eb - eacd81fdaf31d456a82c553735faf64c8efad2eb [redhat] kernel/rh_messages.c: Wire up new calls - -https://gitlab.com/cki-project/kernel-ark/-/commit/32af8640a651c642ee5706dda0cf35ff508bcdcb - 32af8640a651c642ee5706dda0cf35ff508bcdcb [redhat] drivers/pci: Update rh_messages.c - -https://gitlab.com/cki-project/kernel-ark/-/commit/db366977f9e13f903cc9b7f22936b581594a7731 - db366977f9e13f903cc9b7f22936b581594a7731 [redhat] drivers/pci: Remove RHEL-only pci_hw_*() functions - -https://gitlab.com/cki-project/kernel-ark/-/commit/402504ff66e5d118b514253df5d55f8413e2e167 - 402504ff66e5d118b514253df5d55f8413e2e167 scsi: sd: Add "probe_type" module parameter to allow synchronous probing - -https://gitlab.com/cki-project/kernel-ark/-/commit/5e96a345c6fb24e282ce1769223c1a339d0dbe94 - 5e96a345c6fb24e282ce1769223c1a339d0dbe94 Revert "Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64" - -https://gitlab.com/cki-project/kernel-ark/-/commit/ce943989ae8cb2b8e0b4699c148584d3cd18ec9b - ce943989ae8cb2b8e0b4699c148584d3cd18ec9b kernel/rh_messages.c: Another gcc12 warning on redundant NULL test - -https://gitlab.com/cki-project/kernel-ark/-/commit/c0624b3913d8c3f262e20910a2f2c4d2f99ce61f - c0624b3913d8c3f262e20910a2f2c4d2f99ce61f Enable IO_URING for RHEL - -https://gitlab.com/cki-project/kernel-ark/-/commit/861f2d38d82cfb374799ec517f18cc021701068e - 861f2d38d82cfb374799ec517f18cc021701068e Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64 - -https://gitlab.com/cki-project/kernel-ark/-/commit/e02ec93117d6eea21e80baf69e6f9848cf1a9774 - e02ec93117d6eea21e80baf69e6f9848cf1a9774 redhat: version two of Makefile.rhelver tweaks - -https://gitlab.com/cki-project/kernel-ark/-/commit/964e830b4fae678dec5b8b93dcd402c73fdf2912 - 964e830b4fae678dec5b8b93dcd402c73fdf2912 redhat: adapt to upstream Makefile change - -https://gitlab.com/cki-project/kernel-ark/-/commit/60a4025a3b1cdec1c7bbdabf1e30278f615bb493 - 60a4025a3b1cdec1c7bbdabf1e30278f615bb493 kernel/rh_messages.c: gcc12 warning on redundant NULL test - -https://gitlab.com/cki-project/kernel-ark/-/commit/a5c9e3c6e3dcda60b5f753d1bae86a686f3ac087 - a5c9e3c6e3dcda60b5f753d1bae86a686f3ac087 Change acpi_bus_get_acpi_device to acpi_get_acpi_dev - -https://gitlab.com/cki-project/kernel-ark/-/commit/092e751fe418623c5ad04e77fa6c993d48d96533 - 092e751fe418623c5ad04e77fa6c993d48d96533 ARK: Remove code marking devices unmaintained - -https://gitlab.com/cki-project/kernel-ark/-/commit/c27fa327fb3de69773568d211fd2f8f13a72e342 - c27fa327fb3de69773568d211fd2f8f13a72e342 rh_message: Fix function name - -https://gitlab.com/cki-project/kernel-ark/-/commit/c9b07fd3a141ad0283d7eaadf5a06aec9af2b8c9 - c9b07fd3a141ad0283d7eaadf5a06aec9af2b8c9 Add Partner Supported taint flag to kAFS - -https://gitlab.com/cki-project/kernel-ark/-/commit/6b0e3a47ec436527a736c0e7159b41624d176dd9 - 6b0e3a47ec436527a736c0e7159b41624d176dd9 Add Partner Supported taint flag - -https://gitlab.com/cki-project/kernel-ark/-/commit/3a4e2ad92c430d2f584f56ca686bc75a469d06c0 - 3a4e2ad92c430d2f584f56ca686bc75a469d06c0 kabi: Add kABI macros for enum type - -https://gitlab.com/cki-project/kernel-ark/-/commit/04fbd46f834f3a012ca9d5bef91db377a3dbaed0 - 04fbd46f834f3a012ca9d5bef91db377a3dbaed0 kabi: expand and clarify documentation of aux structs - -https://gitlab.com/cki-project/kernel-ark/-/commit/cf8df8ef88e094ebb049a7e1e6fec069aaf54faa - cf8df8ef88e094ebb049a7e1e6fec069aaf54faa kabi: introduce RH_KABI_USE_AUX_PTR - -https://gitlab.com/cki-project/kernel-ark/-/commit/31779ca0c6c9aab28184a42ac3f17ac219b37b2b - 31779ca0c6c9aab28184a42ac3f17ac219b37b2b kabi: rename RH_KABI_SIZE_AND_EXTEND to AUX - -https://gitlab.com/cki-project/kernel-ark/-/commit/2e12a05d339ed936b9cd59f420b161d70b4a130a - 2e12a05d339ed936b9cd59f420b161d70b4a130a kabi: more consistent _RH_KABI_SIZE_AND_EXTEND - -https://gitlab.com/cki-project/kernel-ark/-/commit/b83556eebdc2efdc2d2c22610b7cd7c5cafb2bae - b83556eebdc2efdc2d2c22610b7cd7c5cafb2bae kabi: use fixed field name for extended part - -https://gitlab.com/cki-project/kernel-ark/-/commit/4c9a3b306a34ed7017e35b0de26b2d98e1a04373 - 4c9a3b306a34ed7017e35b0de26b2d98e1a04373 kabi: fix dereference in RH_KABI_CHECK_EXT - -https://gitlab.com/cki-project/kernel-ark/-/commit/a961660df0a73bcf2dcd8cb8855c2f5d5ded0ae9 - a961660df0a73bcf2dcd8cb8855c2f5d5ded0ae9 kabi: fix RH_KABI_SET_SIZE macro - -https://gitlab.com/cki-project/kernel-ark/-/commit/9f9ef5e8b4694fa7fb6a8f941fb741121fe5aab3 - 9f9ef5e8b4694fa7fb6a8f941fb741121fe5aab3 kabi: expand and clarify documentation - -https://gitlab.com/cki-project/kernel-ark/-/commit/308d17beeaa6cb4a514f77319b636c9a2c15f5eb - 308d17beeaa6cb4a514f77319b636c9a2c15f5eb kabi: make RH_KABI_USE replace any number of reserved fields - -https://gitlab.com/cki-project/kernel-ark/-/commit/f3d12dffffeee8d6692be46044b9fc8448901692 - f3d12dffffeee8d6692be46044b9fc8448901692 kabi: rename RH_KABI_USE2 to RH_KABI_USE_SPLIT - -https://gitlab.com/cki-project/kernel-ark/-/commit/520e726b4e78101e73fa3d77cdcbc21d204a75a9 - 520e726b4e78101e73fa3d77cdcbc21d204a75a9 kabi: change RH_KABI_REPLACE2 to RH_KABI_REPLACE_SPLIT - -https://gitlab.com/cki-project/kernel-ark/-/commit/7160868bd40d04e6d1a80f55d1bf9bb62ede0ba3 - 7160868bd40d04e6d1a80f55d1bf9bb62ede0ba3 kabi: change RH_KABI_REPLACE_UNSAFE to RH_KABI_BROKEN_REPLACE - -https://gitlab.com/cki-project/kernel-ark/-/commit/0b83063cf6c57dc20a80c35396fa425ec1963d53 - 0b83063cf6c57dc20a80c35396fa425ec1963d53 kabi: introduce RH_KABI_ADD_MODIFIER - -https://gitlab.com/cki-project/kernel-ark/-/commit/d276c2393792e3eec80a73a4fe964f9ec11145a7 - d276c2393792e3eec80a73a4fe964f9ec11145a7 kabi: Include kconfig.h - -https://gitlab.com/cki-project/kernel-ark/-/commit/28c30de9c771ff91994c9f0a42bdcc260fa97c2d - 28c30de9c771ff91994c9f0a42bdcc260fa97c2d kabi: macros for intentional kABI breakage - -https://gitlab.com/cki-project/kernel-ark/-/commit/9b671c725ac69c47874321e5636e6541bb6d219d - 9b671c725ac69c47874321e5636e6541bb6d219d kabi: fix the note about terminating semicolon - -https://gitlab.com/cki-project/kernel-ark/-/commit/6443eef17fb53f62886ecce519b6e12dd310e7f5 - 6443eef17fb53f62886ecce519b6e12dd310e7f5 kabi: introduce RH_KABI_HIDE_INCLUDE and RH_KABI_FAKE_INCLUDE - -https://gitlab.com/cki-project/kernel-ark/-/commit/47746fc3837b476ec265e2a0c2aaa86de0d3994e - 47746fc3837b476ec265e2a0c2aaa86de0d3994e pci.h: Fix static include - -https://gitlab.com/cki-project/kernel-ark/-/commit/67ce66385c6b619356c4030e6163c4fb18a50427 - 67ce66385c6b619356c4030e6163c4fb18a50427 drivers/pci/pci-driver.c: Fix if/ifdef typo - -https://gitlab.com/cki-project/kernel-ark/-/commit/0dfd7feeadc964ef2a9d118218b54831381c8d7a - 0dfd7feeadc964ef2a9d118218b54831381c8d7a kernel/rh_taint.c: Update to new messaging - -https://gitlab.com/cki-project/kernel-ark/-/commit/35e5ee153637e59c9297c9cc8ba7f3960277ffc2 - 35e5ee153637e59c9297c9cc8ba7f3960277ffc2 redhat: Add mark_driver_deprecated() - -https://gitlab.com/cki-project/kernel-ark/-/commit/ff7aa8cae4c7e3e7bbc1bb5612efc2157c81fa7d - ff7aa8cae4c7e3e7bbc1bb5612efc2157c81fa7d RHEL: disable io_uring support - -https://gitlab.com/cki-project/kernel-ark/-/commit/517351ed810bf2707e7fdb2ab22029aeb594db59 - 517351ed810bf2707e7fdb2ab22029aeb594db59 bpf: Fix unprivileged_bpf_disabled setup - -https://gitlab.com/cki-project/kernel-ark/-/commit/48fe2e5f40c901e92d1f8c62bc97f58af4b0906a - 48fe2e5f40c901e92d1f8c62bc97f58af4b0906a nvme: nvme_mpath_init remove multipath check - -https://gitlab.com/cki-project/kernel-ark/-/commit/1c9bd09f303e2c9d2c67fdc46604d94e00cbf67c - 1c9bd09f303e2c9d2c67fdc46604d94e00cbf67c wireguard: disable in FIPS mode - -https://gitlab.com/cki-project/kernel-ark/-/commit/57872981891fe8f3f7205daa4b78c8c0d676b171 - 57872981891fe8f3f7205daa4b78c8c0d676b171 nvme: decouple basic ANA log page re-read support from native multipathing - -https://gitlab.com/cki-project/kernel-ark/-/commit/0561f5953431ff471193611cd73af65dd394c8cd - 0561f5953431ff471193611cd73af65dd394c8cd nvme: allow local retry and proper failover for REQ_FAILFAST_TRANSPORT - -https://gitlab.com/cki-project/kernel-ark/-/commit/f801483d711fa5f83a0f9d4c479eeba702d1d477 - f801483d711fa5f83a0f9d4c479eeba702d1d477 nvme: Return BLK_STS_TARGET if the DNR bit is set - -https://gitlab.com/cki-project/kernel-ark/-/commit/4f2bc09956ad4829d139e9d69b86ba8b9ebc66e2 - 4f2bc09956ad4829d139e9d69b86ba8b9ebc66e2 REDHAT: coresight: etm4x: Disable coresight on HPE Apollo 70 - -https://gitlab.com/cki-project/kernel-ark/-/commit/65a21d545cc43328ea00fdbd62e7b45f375adce8 - 65a21d545cc43328ea00fdbd62e7b45f375adce8 redhat: remove remaining references of CONFIG_RH_DISABLE_DEPRECATED - -https://gitlab.com/cki-project/kernel-ark/-/commit/1c1b5380b0b56d3be978997b128f84aeb9906656 - 1c1b5380b0b56d3be978997b128f84aeb9906656 arch/x86: Remove vendor specific CPU ID checks - -https://gitlab.com/cki-project/kernel-ark/-/commit/f7c032c856ba6379a77b76179d0352929d6039ec - f7c032c856ba6379a77b76179d0352929d6039ec redhat: Replace hardware.redhat.com link in Unsupported message - -https://gitlab.com/cki-project/kernel-ark/-/commit/9a6eb49603959cf0aab0198e13946eaee07801c3 - 9a6eb49603959cf0aab0198e13946eaee07801c3 x86: Fix compile issues with rh_check_supported() - -https://gitlab.com/cki-project/kernel-ark/-/commit/8a605436efddfa7dbc6e007b2881fa81f17968a5 - 8a605436efddfa7dbc6e007b2881fa81f17968a5 KEYS: Make use of platform keyring for module signature verify - -https://gitlab.com/cki-project/kernel-ark/-/commit/c7c191f662438423a23592db42838ff550c2bdda - c7c191f662438423a23592db42838ff550c2bdda Input: rmi4 - remove the need for artificial IRQ in case of HID - -https://gitlab.com/cki-project/kernel-ark/-/commit/4ae139284600cd6fef133ce7a981485ea73381ab - 4ae139284600cd6fef133ce7a981485ea73381ab ARM: tegra: usb no reset - -https://gitlab.com/cki-project/kernel-ark/-/commit/8156e2102f753bbe0f0dd222a5f232e7f3d99883 - 8156e2102f753bbe0f0dd222a5f232e7f3d99883 arm: make CONFIG_HIGHPTE optional without CONFIG_EXPERT - -https://gitlab.com/cki-project/kernel-ark/-/commit/823e733a88ddd21c735288dd3b08348e79872b91 - 823e733a88ddd21c735288dd3b08348e79872b91 redhat: rh_kabi: deduplication friendly structs - -https://gitlab.com/cki-project/kernel-ark/-/commit/61d2a751fe1b1305684d6c1899f26fa9e38ac0a9 - 61d2a751fe1b1305684d6c1899f26fa9e38ac0a9 redhat: rh_kabi add a comment with warning about RH_KABI_EXCLUDE usage - -https://gitlab.com/cki-project/kernel-ark/-/commit/7d09cb3ea3dd2f3cda5a6a31be429f259106ca61 - 7d09cb3ea3dd2f3cda5a6a31be429f259106ca61 redhat: rh_kabi: introduce RH_KABI_EXTEND_WITH_SIZE - -https://gitlab.com/cki-project/kernel-ark/-/commit/c0c51c6f123df02948e11680d9b90324593ba547 - c0c51c6f123df02948e11680d9b90324593ba547 redhat: rh_kabi: Indirect EXTEND macros so nesting of other macros will resolve. - -https://gitlab.com/cki-project/kernel-ark/-/commit/96b20c70b39cd28efcec2336417cb0db9ff7853c - 96b20c70b39cd28efcec2336417cb0db9ff7853c redhat: rh_kabi: Fix RH_KABI_SET_SIZE to use dereference operator - -https://gitlab.com/cki-project/kernel-ark/-/commit/198030a81d85dbac8f4030e69d3d376327433487 - 198030a81d85dbac8f4030e69d3d376327433487 redhat: rh_kabi: Add macros to size and extend structs - -https://gitlab.com/cki-project/kernel-ark/-/commit/695af00ed9e393abe88d9ee4de3702c15ded186d - 695af00ed9e393abe88d9ee4de3702c15ded186d Removing Obsolete hba pci-ids from rhel8 - -https://gitlab.com/cki-project/kernel-ark/-/commit/736038bd8039d1543468c1dc8925f20929645804 - 736038bd8039d1543468c1dc8925f20929645804 mptsas: pci-id table changes - -https://gitlab.com/cki-project/kernel-ark/-/commit/83cdf2924bdcc90c433a58129b4501e10b1295dc - 83cdf2924bdcc90c433a58129b4501e10b1295dc mptspi: pci-id table changes - -https://gitlab.com/cki-project/kernel-ark/-/commit/0b634d81ed7f0730e13d720508dbaa6ab94e54d2 - 0b634d81ed7f0730e13d720508dbaa6ab94e54d2 qla2xxx: Remove PCI IDs of deprecated adapter - -https://gitlab.com/cki-project/kernel-ark/-/commit/0d11491f9e7fe0c8c301db3256cb47c66ae8450f - 0d11491f9e7fe0c8c301db3256cb47c66ae8450f hpsa: remove old cciss-based smartarray pci ids - -https://gitlab.com/cki-project/kernel-ark/-/commit/75f69a4f7b8f9d38c5efb0231186ed8726e526f2 - 75f69a4f7b8f9d38c5efb0231186ed8726e526f2 kernel: add SUPPORT_REMOVED kernel taint - -https://gitlab.com/cki-project/kernel-ark/-/commit/50081b0865239d853d77bc71e54d13fad8bac9f0 - 50081b0865239d853d77bc71e54d13fad8bac9f0 Rename RH_DISABLE_DEPRECATED to RHEL_DIFFERENCES - -https://gitlab.com/cki-project/kernel-ark/-/commit/dc84f3cc1b19a0524e58a382c382f34081dc6c35 - dc84f3cc1b19a0524e58a382c382f34081dc6c35 s390: Lock down the kernel when the IPL secure flag is set - -https://gitlab.com/cki-project/kernel-ark/-/commit/cb55378c04d6516f303e98061ec7ddd6563429a8 - cb55378c04d6516f303e98061ec7ddd6563429a8 efi: Lock down the kernel if booted in secure boot mode - -https://gitlab.com/cki-project/kernel-ark/-/commit/9b06e1f07c3cc9e1d0533b8615426d4d5d9e4ebb - 9b06e1f07c3cc9e1d0533b8615426d4d5d9e4ebb efi: Add an EFI_SECURE_BOOT flag to indicate secure boot mode - -https://gitlab.com/cki-project/kernel-ark/-/commit/db249925c6802b38d910927e4d032af1e00bee56 - db249925c6802b38d910927e4d032af1e00bee56 security: lockdown: expose a hook to lock the kernel down - -https://gitlab.com/cki-project/kernel-ark/-/commit/f9604bcd305aba2a94e713ee758a51143687ae9f - f9604bcd305aba2a94e713ee758a51143687ae9f Make get_cert_list() use efi_status_to_str() to print error messages. - -https://gitlab.com/cki-project/kernel-ark/-/commit/b75eb3e922c93d78d4190a759f5725e856d35439 - b75eb3e922c93d78d4190a759f5725e856d35439 Add efi_status_to_str() and rework efi_status_to_err(). - -https://gitlab.com/cki-project/kernel-ark/-/commit/2f80042d6b8199fceadf3623243402066e0cd4ea - 2f80042d6b8199fceadf3623243402066e0cd4ea Add support for deprecating processors - -https://gitlab.com/cki-project/kernel-ark/-/commit/5a3b4f5754788e42db8ed550b359382b600f2b08 - 5a3b4f5754788e42db8ed550b359382b600f2b08 arm: aarch64: Drop the EXPERT setting from ARM64_FORCE_52BIT - -https://gitlab.com/cki-project/kernel-ark/-/commit/36cd5d0a0aa0a3be8ac385ca8991563c9e58227f - 36cd5d0a0aa0a3be8ac385ca8991563c9e58227f iommu/arm-smmu: workaround DMA mode issues - -https://gitlab.com/cki-project/kernel-ark/-/commit/ca34010e072550c8d5ea57f9436bab254c3521cc - ca34010e072550c8d5ea57f9436bab254c3521cc rh_kabi: introduce RH_KABI_EXCLUDE - -https://gitlab.com/cki-project/kernel-ark/-/commit/26054e2c4e2253fe955a351971dc6b931cb68961 - 26054e2c4e2253fe955a351971dc6b931cb68961 ipmi: do not configure ipmi for HPE m400 - -https://gitlab.com/cki-project/kernel-ark/-/commit/9cb0f734492a21a7e506d7145caf143ccd927b2a - 9cb0f734492a21a7e506d7145caf143ccd927b2a kABI: Add generic kABI macros to use for kABI workarounds - -https://gitlab.com/cki-project/kernel-ark/-/commit/4960e5ee4a0e9bb28e512eb35cfa633ac4552049 - 4960e5ee4a0e9bb28e512eb35cfa633ac4552049 add pci_hw_vendor_status() - -https://gitlab.com/cki-project/kernel-ark/-/commit/291c4e2878431fd6937c5b9248babe8ec8d4233e - 291c4e2878431fd6937c5b9248babe8ec8d4233e ahci: thunderx2: Fix for errata that affects stop engine - -https://gitlab.com/cki-project/kernel-ark/-/commit/996869cc0b3e78cb9182a4ebced2c46ee2774935 - 996869cc0b3e78cb9182a4ebced2c46ee2774935 Vulcan: AHCI PCI bar fix for Broadcom Vulcan early silicon - -https://gitlab.com/cki-project/kernel-ark/-/commit/c1c7a887998ab12c5a1180c4bca3b41c31fe4aa6 - c1c7a887998ab12c5a1180c4bca3b41c31fe4aa6 bpf: set unprivileged_bpf_disabled to 1 by default, add a boot parameter - -https://gitlab.com/cki-project/kernel-ark/-/commit/e40c9d10474d1a5b5f7f01175a72ba4a3c7f5e8e - e40c9d10474d1a5b5f7f01175a72ba4a3c7f5e8e add Red Hat-specific taint flags - -https://gitlab.com/cki-project/kernel-ark/-/commit/f23f446b724fbb79c1e09a278fcb427fc29c0c05 - f23f446b724fbb79c1e09a278fcb427fc29c0c05 tags.sh: Ignore redhat/rpm - -https://gitlab.com/cki-project/kernel-ark/-/commit/a68aa65a20fba1908a7326e5321ce8bc39a9ae14 - a68aa65a20fba1908a7326e5321ce8bc39a9ae14 put RHEL info into generated headers - -https://gitlab.com/cki-project/kernel-ark/-/commit/80937f1973d73fccdc75db4026fbed7cba16f489 - 80937f1973d73fccdc75db4026fbed7cba16f489 aarch64: acpi scan: Fix regression related to X-Gene UARTs - -https://gitlab.com/cki-project/kernel-ark/-/commit/3362fd10fe075b48ff8af023da5643bc9477a4c6 - 3362fd10fe075b48ff8af023da5643bc9477a4c6 ACPI / irq: Workaround firmware issue on X-Gene based m400 - -https://gitlab.com/cki-project/kernel-ark/-/commit/ffc66b174954abecfb360dcc3b98c3139ef12d96 - ffc66b174954abecfb360dcc3b98c3139ef12d96 modules: add rhelversion MODULE_INFO tag - -https://gitlab.com/cki-project/kernel-ark/-/commit/7e469c23b8f648d79e8a0e82ee41cda0e50b2f19 - 7e469c23b8f648d79e8a0e82ee41cda0e50b2f19 ACPI: APEI: arm64: Ignore broken HPE moonshot APEI support - -https://gitlab.com/cki-project/kernel-ark/-/commit/a0f49117d038de2d4db4940f5f039addb2f7231d - a0f49117d038de2d4db4940f5f039addb2f7231d Add Red Hat tainting - -https://gitlab.com/cki-project/kernel-ark/-/commit/fa67c16e780ed355f9847da90e8055ad1175c238 - fa67c16e780ed355f9847da90e8055ad1175c238 Introduce CONFIG_RH_DISABLE_DEPRECATED - -https://gitlab.com/cki-project/kernel-ark/-/commit/e7e1371803470a7840dc61da628cb912834ec149 - e7e1371803470a7840dc61da628cb912834ec149 Pull the RHEL version defines out of the Makefile - -https://gitlab.com/cki-project/kernel-ark/-/commit/84d1d3e3d0c2c7ed1f571c8495bad3b4d97cfa8e - 84d1d3e3d0c2c7ed1f571c8495bad3b4d97cfa8e [initial commit] Add Red Hat variables in the top level makefile +https://gitlab.com/cki-project/kernel-ark/-/commit/b2d2610643c4a618cc6caa3fd8346c4c9dd90824 + b2d2610643c4a618cc6caa3fd8346c4c9dd90824 [initial commit] Add Red Hat variables in the top level makefile diff --git a/dtbloader.sbat.template b/dtbloader.sbat.template new file mode 100644 index 000000000..0a1480bcc --- /dev/null +++ b/dtbloader.sbat.template @@ -0,0 +1,2 @@ +sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md +kernel-dtbloader.@SBAT_SUFFIX,1,Red Hat,kernel-uki-virt,@KVER,mailto:secalert@redhat.com diff --git a/kernel-aarch64-16k-debug-fedora.config b/kernel-aarch64-16k-debug-fedora.config index 2595ec301..ee72fbef9 100644 --- a/kernel-aarch64-16k-debug-fedora.config +++ b/kernel-aarch64-16k-debug-fedora.config @@ -6857,7 +6857,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7217,7 +7216,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-16k-fedora.config b/kernel-aarch64-16k-fedora.config index 0903092b0..440c27eaf 100644 --- a/kernel-aarch64-16k-fedora.config +++ b/kernel-aarch64-16k-fedora.config @@ -6828,7 +6828,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7188,7 +7187,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-64k-debug-rhel.config b/kernel-aarch64-64k-debug-rhel.config index 0b9892182..1321b2b97 100644 --- a/kernel-aarch64-64k-debug-rhel.config +++ b/kernel-aarch64-64k-debug-rhel.config @@ -5605,7 +5605,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5859,9 +5858,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-64k-rhel.config b/kernel-aarch64-64k-rhel.config index def539c5c..79df7b111 100644 --- a/kernel-aarch64-64k-rhel.config +++ b/kernel-aarch64-64k-rhel.config @@ -5581,7 +5581,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5835,9 +5834,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-debug-fedora.config b/kernel-aarch64-debug-fedora.config index 53a7f0468..5dd433a34 100644 --- a/kernel-aarch64-debug-fedora.config +++ b/kernel-aarch64-debug-fedora.config @@ -6856,7 +6856,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7216,7 +7215,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-debug-rhel.config b/kernel-aarch64-debug-rhel.config index ff2f1f3f1..7cf8542b8 100644 --- a/kernel-aarch64-debug-rhel.config +++ b/kernel-aarch64-debug-rhel.config @@ -5602,7 +5602,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5856,9 +5855,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-fedora.config b/kernel-aarch64-fedora.config index b8887ffd4..3cddae3f1 100644 --- a/kernel-aarch64-fedora.config +++ b/kernel-aarch64-fedora.config @@ -6827,7 +6827,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7187,7 +7186,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-rhel.config b/kernel-aarch64-rhel.config index aff5c6323..72ca74a19 100644 --- a/kernel-aarch64-rhel.config +++ b/kernel-aarch64-rhel.config @@ -5578,7 +5578,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5832,9 +5831,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-rt-64k-debug-fedora.config b/kernel-aarch64-rt-64k-debug-fedora.config index 7785567e6..4c0da1c61 100644 --- a/kernel-aarch64-rt-64k-debug-fedora.config +++ b/kernel-aarch64-rt-64k-debug-fedora.config @@ -6866,7 +6866,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7229,7 +7228,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-aarch64-rt-64k-debug-rhel.config b/kernel-aarch64-rt-64k-debug-rhel.config index be862af0f..ddea03864 100644 --- a/kernel-aarch64-rt-64k-debug-rhel.config +++ b/kernel-aarch64-rt-64k-debug-rhel.config @@ -5647,7 +5647,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5904,9 +5903,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-rt-64k-fedora.config b/kernel-aarch64-rt-64k-fedora.config index 98d2923e8..428ee4535 100644 --- a/kernel-aarch64-rt-64k-fedora.config +++ b/kernel-aarch64-rt-64k-fedora.config @@ -6837,7 +6837,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7200,7 +7199,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-aarch64-rt-64k-rhel.config b/kernel-aarch64-rt-64k-rhel.config index aa4748367..7e3506eb7 100644 --- a/kernel-aarch64-rt-64k-rhel.config +++ b/kernel-aarch64-rt-64k-rhel.config @@ -5623,7 +5623,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5880,9 +5879,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-rt-debug-fedora.config b/kernel-aarch64-rt-debug-fedora.config index dcdf5f67f..a864eb614 100644 --- a/kernel-aarch64-rt-debug-fedora.config +++ b/kernel-aarch64-rt-debug-fedora.config @@ -6862,7 +6862,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7225,7 +7224,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-aarch64-rt-debug-rhel.config b/kernel-aarch64-rt-debug-rhel.config index 71be95e6c..bf65a88c1 100644 --- a/kernel-aarch64-rt-debug-rhel.config +++ b/kernel-aarch64-rt-debug-rhel.config @@ -5643,7 +5643,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5900,9 +5899,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-aarch64-rt-fedora.config b/kernel-aarch64-rt-fedora.config index f1ec4ef32..35dc767e6 100644 --- a/kernel-aarch64-rt-fedora.config +++ b/kernel-aarch64-rt-fedora.config @@ -6833,7 +6833,6 @@ CONFIG_QCOM_Q6V5_MSS=m CONFIG_QCOM_Q6V5_PAS=m CONFIG_QCOM_Q6V5_WCSS=m CONFIG_QCOM_QDF2400_ERRATUM_0065=y -CONFIG_QCOM_QFPROM=m CONFIG_QCOM_QMI_HELPERS=m CONFIG_QCOM_QSEECOM_UEFISECAPP=y CONFIG_QCOM_QSEECOM=y @@ -7196,7 +7195,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-aarch64-rt-rhel.config b/kernel-aarch64-rt-rhel.config index b8369af84..0b1f9e4f6 100644 --- a/kernel-aarch64-rt-rhel.config +++ b/kernel-aarch64-rt-rhel.config @@ -5619,7 +5619,6 @@ CONFIG_QCOM_L3_PMU=y # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set CONFIG_QCOM_QDF2400_ERRATUM_0065=y -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_QSEECOM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set @@ -5876,9 +5875,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-ppc64le-debug-fedora.config b/kernel-ppc64le-debug-fedora.config index f896902df..d00ba4e2a 100644 --- a/kernel-ppc64le-debug-fedora.config +++ b/kernel-ppc64le-debug-fedora.config @@ -5771,7 +5771,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-ppc64le-debug-rhel.config b/kernel-ppc64le-debug-rhel.config index 933ec7627..76d1b37f3 100644 --- a/kernel-ppc64le-debug-rhel.config +++ b/kernel-ppc64le-debug-rhel.config @@ -5121,7 +5121,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5334,9 +5333,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-ppc64le-fedora.config b/kernel-ppc64le-fedora.config index a9a9a87ec..61fe3313e 100644 --- a/kernel-ppc64le-fedora.config +++ b/kernel-ppc64le-fedora.config @@ -5741,7 +5741,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-ppc64le-rhel.config b/kernel-ppc64le-rhel.config index 91809a1cb..ebb84ff7b 100644 --- a/kernel-ppc64le-rhel.config +++ b/kernel-ppc64le-rhel.config @@ -5099,7 +5099,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5312,9 +5311,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-riscv64-debug-fedora.config b/kernel-riscv64-debug-fedora.config index 24d2b3f50..8d649c119 100644 --- a/kernel-riscv64-debug-fedora.config +++ b/kernel-riscv64-debug-fedora.config @@ -5831,7 +5831,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-riscv64-debug-rhel.config b/kernel-riscv64-debug-rhel.config index 77d20353d..a657377d6 100644 --- a/kernel-riscv64-debug-rhel.config +++ b/kernel-riscv64-debug-rhel.config @@ -5094,7 +5094,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5333,9 +5332,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-riscv64-fedora.config b/kernel-riscv64-fedora.config index 2fb92ee52..c965e019b 100644 --- a/kernel-riscv64-fedora.config +++ b/kernel-riscv64-fedora.config @@ -5801,7 +5801,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-riscv64-rhel.config b/kernel-riscv64-rhel.config index 34009c7c1..1661da5f3 100644 --- a/kernel-riscv64-rhel.config +++ b/kernel-riscv64-rhel.config @@ -5072,7 +5072,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5311,9 +5310,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-riscv64-rt-debug-fedora.config b/kernel-riscv64-rt-debug-fedora.config index 698847186..5637e604b 100644 --- a/kernel-riscv64-rt-debug-fedora.config +++ b/kernel-riscv64-rt-debug-fedora.config @@ -5840,7 +5840,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-riscv64-rt-fedora.config b/kernel-riscv64-rt-fedora.config index 580ed1641..6db74ae8e 100644 --- a/kernel-riscv64-rt-fedora.config +++ b/kernel-riscv64-rt-fedora.config @@ -5810,7 +5810,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-s390x-debug-fedora.config b/kernel-s390x-debug-fedora.config index 741207d72..8c3eba6f8 100644 --- a/kernel-s390x-debug-fedora.config +++ b/kernel-s390x-debug-fedora.config @@ -5708,7 +5708,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y # CONFIG_RFKILL is not set CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-s390x-debug-rhel.config b/kernel-s390x-debug-rhel.config index b6cd20221..cdf8530f0 100644 --- a/kernel-s390x-debug-rhel.config +++ b/kernel-s390x-debug-rhel.config @@ -5060,7 +5060,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5278,9 +5277,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-s390x-fedora.config b/kernel-s390x-fedora.config index 961f6995e..65f4dc07b 100644 --- a/kernel-s390x-fedora.config +++ b/kernel-s390x-fedora.config @@ -5678,7 +5678,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y # CONFIG_RFKILL is not set CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-s390x-rhel.config b/kernel-s390x-rhel.config index e12752410..8bf8c7c5a 100644 --- a/kernel-s390x-rhel.config +++ b/kernel-s390x-rhel.config @@ -5038,7 +5038,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5256,9 +5255,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-s390x-zfcpdump-rhel.config b/kernel-s390x-zfcpdump-rhel.config index 1f8ab8666..a99269394 100644 --- a/kernel-s390x-zfcpdump-rhel.config +++ b/kernel-s390x-zfcpdump-rhel.config @@ -5050,7 +5050,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5268,9 +5267,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y # CONFIG_RFKILL is not set CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-debug-fedora.config b/kernel-x86_64-debug-fedora.config index b3c3246cf..f4b3504e3 100644 --- a/kernel-x86_64-debug-fedora.config +++ b/kernel-x86_64-debug-fedora.config @@ -6249,7 +6249,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-debug-rhel.config b/kernel-x86_64-debug-rhel.config index 0c8f0045e..cb8c0ba1d 100644 --- a/kernel-x86_64-debug-rhel.config +++ b/kernel-x86_64-debug-rhel.config @@ -5396,7 +5396,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5624,9 +5623,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-fedora.config b/kernel-x86_64-fedora.config index 5cdccc0c3..c82bef9ab 100644 --- a/kernel-x86_64-fedora.config +++ b/kernel-x86_64-fedora.config @@ -6220,7 +6220,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-rhel.config b/kernel-x86_64-rhel.config index 39c3be6c7..a7f29c9d3 100644 --- a/kernel-x86_64-rhel.config +++ b/kernel-x86_64-rhel.config @@ -5373,7 +5373,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5601,9 +5600,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-rt-debug-fedora.config b/kernel-x86_64-rt-debug-fedora.config index 34b4cccde..a5b7d72ae 100644 --- a/kernel-x86_64-rt-debug-fedora.config +++ b/kernel-x86_64-rt-debug-fedora.config @@ -6258,7 +6258,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-x86_64-rt-debug-rhel.config b/kernel-x86_64-rt-debug-rhel.config index 699d1d739..757aafe3c 100644 --- a/kernel-x86_64-rt-debug-rhel.config +++ b/kernel-x86_64-rt-debug-rhel.config @@ -5437,7 +5437,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5668,9 +5667,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel-x86_64-rt-fedora.config b/kernel-x86_64-rt-fedora.config index bb25c719b..1001d2661 100644 --- a/kernel-x86_64-rt-fedora.config +++ b/kernel-x86_64-rt-fedora.config @@ -6229,7 +6229,7 @@ CONFIG_RFKILL_GPIO=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RHEL_DIFFERENCES is not set +# CONFIG_RH_DISABLE_DEPRECATED is not set # CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set CONFIG_RICHTEK_RTQ6056=m CONFIG_RING_BUFFER_BENCHMARK=m diff --git a/kernel-x86_64-rt-rhel.config b/kernel-x86_64-rt-rhel.config index db29f0436..d957dba06 100644 --- a/kernel-x86_64-rt-rhel.config +++ b/kernel-x86_64-rt-rhel.config @@ -5414,7 +5414,6 @@ CONFIG_QCA83XX_PHY=m # CONFIG_QCOM_PDC is not set # CONFIG_QCOM_PD_MAPPER is not set # CONFIG_QCOM_PPE is not set -# CONFIG_QCOM_QFPROM is not set # CONFIG_QCOM_RAMP_CTRL is not set # CONFIG_QCOM_RMTFS_MEM is not set # CONFIG_QCOM_RPM_MASTER_STATS is not set @@ -5645,9 +5644,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m CONFIG_RFKILL_INPUT=y CONFIG_RFKILL=m CONFIG_RFS_ACCEL=y -# CONFIG_RH_AUTOMOTIVE is not set CONFIG_RHEL_DIFFERENCES=y -# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set # CONFIG_RICHTEK_RTQ6056 is not set CONFIG_RING_BUFFER_BENCHMARK=m # CONFIG_RING_BUFFER_STARTUP_TEST is not set diff --git a/kernel.spec b/kernel.spec index c29620696..3e39bc5b3 100644 --- a/kernel.spec +++ b/kernel.spec @@ -175,7 +175,7 @@ Summary: The Linux kernel # kernel release. (This includes prepatch or "rc" releases.) # Set released_kernel to 0 when the upstream source tarball contains an # unreleased kernel development snapshot. -%global released_kernel 0 +%global released_kernel 1 # Set debugbuildsenabled to 1 to build separate base and debug kernels # (on supported architectures). The kernel-debug-* subpackages will # contain the debug kernel. @@ -187,13 +187,13 @@ Summary: The Linux kernel %define specrpmversion 6.19.0 %define specversion 6.19.0 %define patchversion 6.19 -%define pkgrelease 59 +%define pkgrelease 300 %define kversion 6 %define tarfile_release 6.19 # This is needed to do merge window version magic %define patchlevel 19 # This allows pkg_release to have configurable %%{?dist} tag -%define specrelease 59%{?buildid}%{?dist} +%define specrelease 300%{?buildid}%{?dist} # This defines the kabi tarball version %define kabiversion 6.19.0 @@ -342,6 +342,17 @@ Summary: The Linux kernel %define with_efiuki 0 %endif +%ifarch aarch64 +# dtbloader sub-package requires stubble which is only in Fedora for now +%if 0%{?fedora} +%define with_dtbloader %{?_without_dtbloader: 0} %{?!_without_dtbloader: 1} +%else +%define with_dtbloader 0 +%endif +%else +%define with_dtbloader 0 +%endif + %if 0%{?fedora} # Kernel headers are being split out into a separate package %define with_headers 0 @@ -450,6 +461,7 @@ Summary: The Linux kernel %define with_selftests 0 %define with_headers 0 %define with_efiuki 0 +%define with_dtbloader 0 %define with_zfcpdump 0 %define with_arm64_16k 0 %define with_arm64_64k 0 @@ -488,6 +500,7 @@ Summary: The Linux kernel %define with_selftests 0 %define with_headers 0 %define with_efiuki 0 +%define with_dtbloader 0 %define with_zfcpdump 0 %define with_vdso_install 0 %define with_kabichk 0 @@ -517,6 +530,7 @@ Summary: The Linux kernel %define with_arm64_16k 0 %define with_arm64_64k 0 %define with_efiuki 0 +%define with_dtbloader 0 %define with_doc 0 %define with_headers 0 %define with_cross_headers 0 @@ -948,15 +962,22 @@ BuildRequires: dracut BuildRequires: binutils # For the initrd BuildRequires: lvm2 -BuildRequires: systemd-boot-unsigned # For systemd-stub and systemd-pcrphase BuildRequires: systemd-udev >= 252-1 # For systemd-repart BuildRequires: xfsprogs e2fsprogs dosfstools -# For UKI kernel cmdline addons -BuildRequires: systemd-ukify # For TPM operations in UKI initramfs BuildRequires: tpm2-tools +%endif + +%if %{with_dtbloader} +BuildRequires: stubble +%endif + +%if %{with_efiuki} || %{with_dtbloader} +BuildRequires: systemd-boot-unsigned +# For UKI kernel cmdline addons +BuildRequires: systemd-ukify # For UKI sb cert %if 0%{?rhel}%{?centos} && !0%{?eln} %if 0%{?centos} @@ -996,18 +1017,23 @@ Source13: redhatsecureboot501.cer %define pesign_name_0 redhatsecureboot501 %define secureboot_ca_0 %{SOURCE10} %define secureboot_key_0 %{SOURCE13} +%define pesign_name_uki_0 %{pesign_name_0} +%define secureboot_key_uki_0 %{secureboot_key_0} %endif # RHEL/centos certs come from system-sb-certs %if 0%{?rhel} && !0%{?eln} %define secureboot_ca_0 %{_datadir}/pki/sb-certs/secureboot-ca-%{_arch}.cer %define secureboot_key_0 %{_datadir}/pki/sb-certs/secureboot-kernel-%{_arch}.cer +%define secureboot_key_uki_0 %{_datadir}/pki/sb-certs/secureboot-uki-virt-%{_arch}.cer %if 0%{?centos} %define pesign_name_0 centossecureboot201 +%define pesign_name_uki_0 centossecureboot204 %else %ifarch x86_64 aarch64 %define pesign_name_0 redhatsecureboot501 +%define pesign_name_uki_0 redhatsecureboot504 %endif %ifarch s390x %define pesign_name_0 redhatsecureboot302 @@ -1082,6 +1108,7 @@ Source77: partial-clang_lto-aarch64-debug-snip.config Source80: generate_all_configs.sh Source81: process_configs.sh +Source82: dtbloader.sbat.template Source83: uki.sbat.template Source84: uki-addons.sbat.template Source85: kernel.sbat.template @@ -1795,6 +1822,18 @@ Provides: installonlypkg(kernel)\ Requires: %{name}%{?1:-%{1}}-uki-virt = %{specrpmversion}-%{release}\ Requires(pre): systemd >= 254-1\ %endif\ +%if %{with_dtbloader} && ("%{?1}" == "" || "%{1}" == "debug")\ +# This is not a full UKI, uki is in the name for compat with kernel_variant_posttrans -u\ +%package %{?1:%{1}-}uki-dtbloader\ +Summary: %{variant_summary} with systemd-stub for auto DTB loading\ +Provides: installonlypkg(kernel)\ +Provides: %{name}-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ +Requires: %{name}%{?1:-%{1}}-modules-core-uname-r = %{KVERREL}%{uname_suffix %{?1}}\ +Requires(pre): %{kernel_prereq}\ +# "kernel-install add ..." treats this as a regular kernel, which is what we want.\ +# This causes a /boot/vmlinuz-$(uname -r) and BLS .conf file conflict with kernel-core.\ +Conflicts: %{name}%{?1:-%{1}}-core = %{specrpmversion}-%{release}\ +%endif\ %if %{with_gcov}\ %{expand:%%kernel_gcov_package %{?1:%{1}}}\ %endif\ @@ -2022,6 +2061,16 @@ Prebuilt 64k unified kernel image for virtual machines. Prebuilt 64k unified kernel image addons for virtual machines. %endif +%if %{with_stock} && %{with_debug} && %{with_dtbloader} +%description debug-uki-dtbloader +Prebuilt debug kernel image with auto DTB selection for ARM64 UEFI devices. +%endif + +%if %{with_stock_base} && %{with_dtbloader} +%description uki-dtbloader +Prebuilt default kernel image with auto DTB selection for ARM64 UEFI devices. +%endif + %ifnarch noarch %{nobuildarches} %kernel_modules_extra_matched_package %endif @@ -2149,6 +2198,7 @@ rm -f localversion-next localversion-rt scripts/clang-tools 2> /dev/null # SBAT data +sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE82} > dtbloader.sbat sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE83} > uki.sbat sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE84} > uki-addons.sbat sed -e s,@KVER,%{KVERREL}, -e s,@SBAT_SUFFIX,%{sbat_suffix}, %{SOURCE85} > kernel.sbat @@ -2256,14 +2306,6 @@ for i in *.config; do done %endif -# Adjust FIPS module name for RHEL -%if 0%{?rhel} -%{log_msg "Adjust FIPS module name for RHEL"} -for i in *.config; do - sed -i 's/CONFIG_CRYPTO_FIPS_NAME=.*/CONFIG_CRYPTO_FIPS_NAME="Red Hat Enterprise Linux %{rhel} - Kernel Cryptographic API"/' $i -done -%endif - %{log_msg "Set process_configs.sh $OPTS"} cp %{SOURCE81} . OPTS="-w -n -c" @@ -2939,51 +2981,82 @@ BuildKernel() { rm -f $KernelUnifiedInitrd - KernelAddonsDirOut="$KernelUnifiedImage.extra.d" - mkdir -p $KernelAddonsDirOut - python3 %{SOURCE151} %{SOURCE152} $KernelAddonsDirOut virt %{primary_target} %{_target_cpu} @uki-addons.sbat + KernelAddonsDirOut="$KernelUnifiedImage.extra.d" + mkdir -p $KernelAddonsDirOut + python3 %{SOURCE151} %{SOURCE152} $KernelAddonsDirOut virt %{primary_target} %{_target_cpu} @uki-addons.sbat %if %{signkernel} %{log_msg "Sign the EFI UKI kernel"} -%if 0%{?fedora}%{?eln} - %pesign -s -i $KernelUnifiedImage -o $KernelUnifiedImage.signed -a %{secureboot_ca_0} -c %{secureboot_key_0} -n %{pesign_name_0} -%else -%if 0%{?centos} - UKI_secureboot_name=centossecureboot204 -%else - UKI_secureboot_name=redhatsecureboot504 -%endif - UKI_secureboot_cert=%{_datadir}/pki/sb-certs/secureboot-uki-virt-%{_arch}.cer - - %pesign -s -i $KernelUnifiedImage -o $KernelUnifiedImage.signed -a %{secureboot_ca_0} -c $UKI_secureboot_cert -n $UKI_secureboot_name -# 0%{?fedora}%{?eln} -%endif + %pesign -s -i $KernelUnifiedImage -o $KernelUnifiedImage.signed -a %{secureboot_ca_0} -c %{secureboot_key_uki_0} -n %{pesign_name_uki_0} if [ ! -s $KernelUnifiedImage.signed ]; then echo "pesigning failed" exit 1 fi mv $KernelUnifiedImage.signed $KernelUnifiedImage - for addon in "$KernelAddonsDirOut"/*; do - %pesign -s -i $addon -o $addon.signed -a %{secureboot_ca_0} -c %{secureboot_key_0} -n %{pesign_name_0} - rm -f $addon - mv $addon.signed $addon - done - -# signkernel + for addon in "$KernelAddonsDirOut"/*; do + %pesign -s -i $addon -o $addon.signed -a %{secureboot_ca_0} -c %{secureboot_key_0} -n %{pesign_name_0} + rm -f $addon + mv $addon.signed $addon + done %endif - # hmac sign the UKI for FIPS - KernelUnifiedImageHMAC="$KernelUnifiedImageDir/.$InstallName-virt.efi.hmac" - %{log_msg "hmac sign the UKI for FIPS"} - %{log_msg "Creating hmac file: $KernelUnifiedImageHMAC"} - (cd $KernelUnifiedImageDir && sha512hmac $InstallName-virt.efi) > $KernelUnifiedImageHMAC; + # hmac sign the UKI for FIPS + KernelUnifiedImageHMAC="$KernelUnifiedImageDir/.$InstallName-virt.efi.hmac" + %{log_msg "hmac sign the UKI for FIPS"} + %{log_msg "Creating hmac file: $KernelUnifiedImageHMAC"} + (cd $KernelUnifiedImageDir && sha512hmac $InstallName-virt.efi) > $KernelUnifiedImageHMAC; # with_efiuki %endif : # in case of empty block fi # "$Variant" == "rt" || "$Variant" == "rt-debug" || "$Variant" == "automotive" || "$Variant" == "automotive-debug" +%if %{with_dtbloader} + if [[ -z "$Variant" || "$Variant" == "debug" ]]; then + %{log_msg "Setup the DTB-loader kernel"} + DtbloaderImage="$RPM_BUILD_ROOT/lib/modules/$KernelVer/$InstallName-dtbloader.efi" + DtbPath=$RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer/qcom + + pushd $DtbPath + Dtbs="" + for i in x1 sc8?80x; do + Dtbs="$Dtbs $(ls $i*.dtb | grep -v -E 'el2|devkit|crd|qcp|primus')" + done + popd + + DevicetreeAuto="" + for i in $Dtbs; do + DevicetreeAuto="$DevicetreeAuto --devicetree-auto=$DtbPath/$i" + done + + # os-release is unset, so that this is not seen as a full UKI by + # "kernel-install add" and instead is treated as a normal kernel image, + # causing kernel-install to generate an initrd + standard BLS cfg. + # This is also required for systemd-stub to work with a GRUB provided + # initramfs. + ukify build --linux=$(realpath $KernelImage) \ + --sbat=@dtbloader.sbat --os-release="" --uname=$KernelVer \ + --hwids=/usr/share/stubble/hwids $DevicetreeAuto --output=$DtbloaderImage + +%if %{signkernel} + %{log_msg "Sign the DTB-loader kernel"} + %pesign -s -i $DtbloaderImage -o $DtbloaderImage.signed -a %{secureboot_ca_0} -c %{secureboot_key_0} -n %{pesign_name_0} + if [ ! -s $DtbloaderImage.signed ]; then + echo "pesigning failed" + exit 1 + fi + mv $DtbloaderImage.signed $DtbloaderImage +%endif + chmod 755 $DtbloaderImage + + %{log_msg "hmac sign the DTB-loader kernel for FIPS"} + pushd $(dirname $DtbloaderImage) + sha512hmac $(basename $DtbloaderImage) > .$(basename $DtbloaderImage).hmac + popd + fi # -z "$Variant" || "$Variant" == "debug" +# with_dtbloader +%endif # # Generate the modules files lists @@ -4207,6 +4280,11 @@ fi\ %kernel_variant_preun -u virt -e %endif +%if %{with_stock_base} && %{with_dtbloader} +%kernel_variant_posttrans -u dtbloader +%kernel_variant_preun -u dtbloader +%endif + %if %{with_stock_base} %kernel_variant_preun -e %kernel_variant_post @@ -4222,6 +4300,11 @@ fi\ %kernel_variant_preun -v debug -u virt -e %endif +%if %{with_stock} && %{with_debug} && %{with_dtbloader} +%kernel_variant_posttrans -v debug -u dtbloader +%kernel_variant_preun -v debug -u dtbloader +%endif + %if %{with_stock} && %{with_debug} %kernel_variant_preun -v debug -e %kernel_variant_post -v debug @@ -4545,6 +4628,7 @@ fi\ # - kernel-devel: headers and build infrastructure # - kernel-debuginfo: vmlinux with debug symbols (if with_debuginfo) # - kernel-uki-virt: unified kernel image for VMs (if with_efiuki) +# - kernel-uki-dtbloader: kernel with systemd-stub for auto DTB loading (if with_dtbloader) # %define kernel_variant_files(k:) \ %if %{2}\ @@ -4628,6 +4712,28 @@ fi\ %dir /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi.extra.d/ \ /lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-virt.efi.extra.d/*.addon.efi\ %endif\ +%if %{with_dtbloader} && ("%{?3}" == "" || "%{3}" == "debug")\ +%{expand:%%files %{?3:%{3}-}uki-dtbloader}\ +%%license linux-%{KVERREL}/COPYING-%{version}-%{release}\ +%dir /lib/modules\ +%dir /lib/modules/%{KVERREL}%{?3:+%{3}}\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/System.map\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/config\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/modules.builtin*\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/symvers.%compext\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-dtbloader.efi\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/.%{?-k:%{-k*}}%{!?-k:vmlinuz}-dtbloader.efi.hmac\ +%ghost %attr(0644, root, root) /boot/System.map-%{KVERREL}%{?3:+%{3}}\ +%ghost %attr(0644, root, root) /boot/config-%{KVERREL}%{?3:+%{3}}\ +%ghost %attr(0600, root, root) /boot/initramfs-%{KVERREL}%{?3:+%{3}}.img\ +%ghost %attr(0644, root, root) /boot/symvers-%{KVERREL}%{?3:+%{3}}.%compext\ +%ghost %attr(0755, root, root) /%{image_install_path}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}\ +%ghost %attr(0644, root, root) /%{image_install_path}/.%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}.hmac\ +%ifarch aarch64 riscv64\ +/lib/modules/%{KVERREL}%{?3:+%{3}}/dtb \ +%ghost /%{image_install_path}/dtb-%{KVERREL}%{?3:+%{3}} \ +%endif\ +%endif\ %if %{?3:1} %{!?3:0}\ %{expand:%%files %{3}}\ %endif\ @@ -4700,6 +4806,14 @@ fi\ # # %changelog +* Tue Feb 10 2026 Justin M. Forbes [6.19.0-300] +- redhat/kernel.spec.template: Add kernel-uki-dtbloader sub-package (Hans de Goede) +- redhat/kernel.spec.template: Simplify uki-virt signing (Hans de Goede) +- redhat/kernel.spec.template: Fix indentation of uki-virt generation code (Hans de Goede) +- Initial setup for stable Fedora releases (Justin M. Forbes) +- Reset RHEL_RELEASE for the 7.0 series (Justin M. Forbes) +- redhat/configs: rename CONFIG_QCOM_QFPROM to CONFIG_NVMEM_QCOM_QFPROM (Eric Chanudet) + * Mon Feb 09 2026 Fedora Kernel Team [6.19.0-59] - Linux v6.19.0 diff --git a/patch-6.19-redhat.patch b/patch-6.19-redhat.patch index b959b69be..5bfa44b9e 100644 --- a/patch-6.19-redhat.patch +++ b/patch-6.19-redhat.patch @@ -1,210 +1,49 @@ - Documentation/admin-guide/kernel-parameters.txt | 23 + - Documentation/admin-guide/rh-waived-items.rst | 29 ++ - Kconfig | 2 + - Kconfig.redhat | 31 ++ - Makefile | 38 +- + Makefile | 30 +++++ arch/arm/Kconfig | 4 +- arch/arm64/Kconfig | 2 +- - arch/arm64/kernel/setup.c | 27 + + arch/arm64/kernel/setup.c | 27 +++++ arch/s390/include/asm/ipl.h | 1 + arch/s390/kernel/ipl.c | 5 + arch/s390/kernel/setup.c | 4 + - arch/x86/kernel/cpu/common.c | 1 + - arch/x86/kernel/setup.c | 101 +++- + arch/x86/kernel/setup.c | 22 ++-- crypto/akcipher.c | 3 +- - crypto/dh.c | 25 + - crypto/drbg.c | 18 +- - crypto/rng.c | 155 +++++- - crypto/seqiv.c | 15 +- + crypto/dh.c | 25 +++++ + crypto/seqiv.c | 15 ++- crypto/sig.c | 3 +- crypto/testmgr.c | 6 +- - drivers/acpi/apei/hest.c | 8 + - drivers/acpi/irq.c | 17 +- - drivers/acpi/scan.c | 9 + - drivers/ata/libahci.c | 18 + - drivers/char/ipmi/ipmi_dmi.c | 15 + - drivers/char/ipmi/ipmi_msghandler.c | 16 +- - drivers/char/random.c | 126 ++++- + drivers/acpi/apei/hest.c | 8 ++ + drivers/acpi/irq.c | 17 ++- + drivers/acpi/scan.c | 9 ++ + drivers/ata/libahci.c | 18 +++ drivers/firmware/efi/Makefile | 1 + - drivers/firmware/efi/efi.c | 124 +++-- + drivers/firmware/efi/efi.c | 124 +++++++++++++++------ drivers/firmware/efi/libstub/fdt.c | 5 + - drivers/firmware/efi/libstub/secureboot.c | 14 +- - drivers/firmware/efi/secureboot.c | 38 ++ - drivers/hid/hid-rmi.c | 66 --- - drivers/hwtracing/coresight/coresight-etm4x-core.c | 19 + - drivers/input/rmi4/rmi_driver.c | 124 +++-- - drivers/iommu/iommu.c | 22 + - drivers/message/fusion/mptsas.c | 5 + - drivers/message/fusion/mptspi.c | 5 + - drivers/net/wireguard/main.c | 6 + - drivers/pci/pci-driver.c | 9 + - drivers/pci/quirks.c | 24 + - drivers/scsi/hpsa.c | 4 + - drivers/scsi/qla2xxx/qla_os.c | 6 + - drivers/scsi/sd.c | 13 + - drivers/usb/core/hub.c | 7 + - fs/afs/main.c | 3 + - fs/erofs/super.c | 9 + - fs/ext4/super.c | 11 + - include/linux/crypto.h | 3 + - include/linux/efi.h | 22 +- - include/linux/kernel.h | 16 + + drivers/firmware/efi/libstub/secureboot.c | 14 ++- + drivers/firmware/efi/secureboot.c | 38 +++++++ + drivers/hid/hid-rmi.c | 66 ----------- + drivers/hwtracing/coresight/coresight-etm4x-core.c | 19 ++++ + drivers/input/rmi4/rmi_driver.c | 124 ++++++++++++--------- + drivers/iommu/iommu.c | 22 ++++ + drivers/pci/quirks.c | 24 ++++ + drivers/scsi/sd.c | 10 ++ + drivers/usb/core/hub.c | 7 ++ + include/linux/crypto.h | 2 + + include/linux/efi.h | 22 ++-- include/linux/lsm_hook_defs.h | 1 + - include/linux/module.h | 5 + - include/linux/panic.h | 17 +- - include/linux/pci.h | 5 + - include/linux/random.h | 10 + - include/linux/rh_flags.h | 34 ++ - include/linux/rh_kabi.h | 541 +++++++++++++++++++++ - include/linux/rh_waived.h | 19 + include/linux/rmi.h | 1 + - include/linux/security.h | 9 + - init/main.c | 5 + - kernel/Makefile | 2 + - kernel/bpf/core.c | 5 + - kernel/bpf/syscall.c | 23 + - kernel/module/main.c | 13 + + include/linux/security.h | 9 ++ kernel/module/signing.c | 9 +- - kernel/panic.c | 12 + - kernel/rh_flags.c | 115 +++++ - kernel/rh_messages.c | 414 ++++++++++++++++ - kernel/rh_messages.h | 335 +++++++++++++ - kernel/rh_waived.c | 147 ++++++ scripts/Makefile.lib | 3 + - scripts/mod/modpost.c | 8 + scripts/tags.sh | 2 + security/integrity/platform_certs/load_uefi.c | 6 +- - security/lockdown/Kconfig | 13 + - security/lockdown/lockdown.c | 11 + + security/lockdown/Kconfig | 13 +++ + security/lockdown/lockdown.c | 11 ++ tools/testing/selftests/bpf/Makefile | 2 +- - tools/testing/selftests/bpf/prog_tests/ksyms_btf.c | 31 -- - 80 files changed, 2813 insertions(+), 243 deletions(-) + tools/testing/selftests/bpf/prog_tests/ksyms_btf.c | 31 ------ + 42 files changed, 545 insertions(+), 220 deletions(-) -diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt -index aa0031108bc1..22d4dcd92c12 100644 ---- a/Documentation/admin-guide/kernel-parameters.txt -+++ b/Documentation/admin-guide/kernel-parameters.txt -@@ -6600,6 +6600,20 @@ Kernel parameters - 2 The "airplane mode" button toggles between everything - blocked and everything unblocked. - -+ rh_waived= -+ Enable waived items in RHEL. -+ -+ Some specific features, or security mitigations, can be -+ waived (toggled on/off) on demand in RHEL. However, -+ waiving any of these items should be used judiciously, -+ as it generally means the system might end up being -+ considered insecure or even out-of-scope for support. -+ -+ Format: ,... -+ -+ Use 'rh_waived' to enable all waived features listed at -+ Documentation/admin-guide/rh-waived-features.rst -+ - ring3mwait=disable - [KNL] Disable ring 3 MONITOR/MWAIT feature on supported - CPUs. -@@ -7981,6 +7995,15 @@ Kernel parameters - unknown_nmi_panic - [X86] Cause panic on unknown NMI. - -+ unprivileged_bpf_disabled= -+ Format: { "0" | "1" | "2" } -+ Sets the initial value of -+ kernel.unprivileged_bpf_disabled sysctl knob. -+ 0 - unprivileged bpf() syscall access is enabled. -+ 1 - unprivileged bpf() syscall access is disabled permanently. -+ 2 - unprivileged bpf() syscall access is disabled. -+ Default value is 2. -+ - unwind_debug [X86-64,EARLY] - Enable unwinder debug output. This can be - useful for debugging certain unwinder error -diff --git a/Documentation/admin-guide/rh-waived-items.rst b/Documentation/admin-guide/rh-waived-items.rst -new file mode 100644 -index 000000000000..7471c891419c ---- /dev/null -+++ b/Documentation/admin-guide/rh-waived-items.rst -@@ -0,0 +1,29 @@ -+.. _rh_waived_items: -+ -+==================== -+Red Hat Waived Items -+==================== -+ -+Waived Items is a mechanism offered by Red Hat which allows customers to "waive" -+and utilize features that are not enabled by default as these are considered as -+unmaintained, insecure, rudimentary, or deprecated, but are shipped with the -+RHEL kernel for customer's convinience only. -+Waived Items can range from features that can be enabled on demand to specific -+security mitigations that can be disabled on demand. -+ -+To explicitly "waive" any of these items, RHEL offers the ``rh_waived`` -+kernel boot parameter. To allow set of waived items, append -+``rh_waived=,...,`` to the kernel -+cmdline. -+Appending ``rh_waived=features`` will waive all features listed below, -+and appending ``rh_waived=cves`` will waive all security mitigations -+listed below. -+ -+The waived items listed in the next session follow the pattern below: -+ -+- item name -+ item description -+ -+List of Red Hat Waived Items -+============================ -+ -diff --git a/Kconfig b/Kconfig -index 307e581144de..11e93e479ce4 100644 ---- a/Kconfig -+++ b/Kconfig -@@ -32,3 +32,5 @@ source "lib/Kconfig.debug" - source "Documentation/Kconfig" - - source "io_uring/Kconfig" -+ -+source "Kconfig.redhat" -diff --git a/Kconfig.redhat b/Kconfig.redhat -new file mode 100644 -index 000000000000..85771d74c34f ---- /dev/null -+++ b/Kconfig.redhat -@@ -0,0 +1,31 @@ -+# SPDX-License-Identifier: GPL-2.0-only -+# -+# Red Hat specific options -+# -+ -+menu "Red Hat options" -+ -+config RHEL_DIFFERENCES -+ bool "Enable RHEL-only code" -+ help -+ This option controls whether rhel-only changes are enabled during -+ the build. Unless you want to enable rhel-only changes, say N here. -+ -+config RH_KABI_SIZE_ALIGN_CHECKS -+ bool "Enables more stringent kabi checks in the macros" -+ depends on RHEL_DIFFERENCES -+ default y -+ help -+ This option enables more stringent kabi checks. Those must -+ be disabled in case of a debug build, because debug builds -+ allow to change struct sizes. -+ -+config RH_AUTOMOTIVE -+ bool "Enable automotive only code" -+ depends on RHEL_DIFFERENCES -+ default n -+ help -+ This option controls whether code is included in the automotive -+ kernel build. If you are building an automotive kernel, say Y. -+ -+endmenu diff --git a/Makefile b/Makefile -index d3a8482bdbd0..4ee96b698f1e 100644 +index d3a8482bdbd0..c9bef1fc94e9 100644 --- a/Makefile +++ b/Makefile @@ -355,6 +355,17 @@ ifneq ($(filter install,$(MAKECMDGOALS)),) @@ -234,22 +73,7 @@ index d3a8482bdbd0..4ee96b698f1e 100644 # KERNELRELEASE can change from a few different places, meaning version.h # needs to be updated, so this check is forced on all builds -@@ -1362,7 +1375,13 @@ define filechk_version.h - ((c) > 255 ? 255 : (c)))'; \ - echo \#define LINUX_VERSION_MAJOR $(VERSION); \ - echo \#define LINUX_VERSION_PATCHLEVEL $(PATCHLEVEL); \ -- echo \#define LINUX_VERSION_SUBLEVEL $(SUBLEVEL) -+ echo \#define LINUX_VERSION_SUBLEVEL $(SUBLEVEL); \ -+ echo '#define RHEL_MAJOR $(RHEL_MAJOR)'; \ -+ echo '#define RHEL_MINOR $(RHEL_MINOR)'; \ -+ echo '#define RHEL_RELEASE_VERSION(a,b) (((a) << 8) + (b))'; \ -+ echo '#define RHEL_RELEASE_CODE \ -+ $(shell expr $(RHEL_MAJOR) \* 256 + $(RHEL_MINOR))'; \ -+ echo '#define RHEL_RELEASE "$(RHEL_RELEASE)"' - endef - - $(version_h): private PATCHLEVEL := $(or $(PATCHLEVEL), 0) -@@ -1976,6 +1995,23 @@ endif +@@ -1976,6 +1989,23 @@ endif ifdef CONFIG_MODULES @@ -401,20 +225,8 @@ index c1fe0b53c5ac..8e17bfe788cb 100644 /* Have one command line that is parsed and saved in /proc/cmdline */ /* boot_command_line has been already set up in early.c */ *cmdline_p = boot_command_line; -diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c -index e7ab22fce3b5..0860d1eb51c7 100644 ---- a/arch/x86/kernel/cpu/common.c -+++ b/arch/x86/kernel/cpu/common.c -@@ -1780,6 +1780,7 @@ static void __init early_identify_cpu(struct cpuinfo_x86 *c) - get_cpu_vendor(c); - intel_unlock_cpuid_leafs(c); - get_cpu_cap(c); -+ get_model_name(c); /* RHEL: get model name for unsupported check */ - setup_force_cpu_cap(X86_FEATURE_CPUID); - get_cpu_address_sizes(c); - cpu_parse_early_param(); diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c -index 1b2edd07a3e1..201705bc317a 100644 +index 1b2edd07a3e1..1c434c6900eb 100644 --- a/arch/x86/kernel/setup.c +++ b/arch/x86/kernel/setup.c @@ -21,6 +21,7 @@ @@ -425,98 +237,7 @@ index 1b2edd07a3e1..201705bc317a 100644 #include #include #include -@@ -56,6 +57,10 @@ - #include - #include - #include -+#include -+#if defined(CONFIG_X86_LOCAL_APIC) -+#include -+#endif - - /* - * max_low_pfn_mapped: highest directly mapped pfn < 4 GB -@@ -821,6 +826,79 @@ static void __init early_reserve_memory(void) - trim_snb_memory(); - } - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ -+static void rh_check_supported(void) -+{ -+ bool guest; -+ -+ guest = (x86_hyper_type != X86_HYPER_NATIVE || boot_cpu_has(X86_FEATURE_HYPERVISOR)); -+ -+ /* RHEL supports single cpu on guests only */ -+ if (((topology_num_threads_per_package() * __max_threads_per_core) == 1) && -+ !guest && !is_kdump_kernel()) { -+ pr_crit("Detected single cpu native boot.\n"); -+ pr_crit("Important: In this kernel, single threaded, single CPU 64-bit physical systems are unsupported."); -+ } -+ -+ /* -+ * If the RHEL kernel does not support this hardware, the kernel will -+ * attempt to boot, but no support is provided for this hardware -+ */ -+ switch (boot_cpu_data.x86_vendor) { -+ case X86_VENDOR_AMD: -+ case X86_VENDOR_INTEL: -+ break; -+ default: -+ pr_crit("Detected processor %s %s\n", -+ boot_cpu_data.x86_vendor_id, -+ boot_cpu_data.x86_model_id); -+ break; -+ } -+ -+ /* -+ * Due to the complexity of x86 lapic & ioapic enumeration, and PCI IRQ -+ * routing, ACPI is required for x86. acpi=off is a valid debug kernel -+ * parameter, so just print out a loud warning in case something -+ * goes wrong (which is most of the time). -+ */ -+ if (acpi_disabled && !guest) -+ pr_crit("ACPI has been disabled or is not available on this hardware. This may result in a single cpu boot, incorrect PCI IRQ routing, or boot failure.\n"); -+ -+ /* -+ * x86_64 microarchitecture levels: -+ * https://en.wikipedia.org/wiki/X86-64#Microarchitecture_levels -+ * -+ * RHEL9 has a minimum of the x86_64-v2 microarchitecture -+ * RHEL10 has a minimum of the x86_64-v3 microarchitecture -+ */ -+ -+ if (!boot_cpu_has(X86_FEATURE_CX16) || /* CMPXCHG16B */ -+ !boot_cpu_has(X86_FEATURE_LAHF_LM) || /* LAHF-SAHF */ -+ !boot_cpu_has(X86_FEATURE_POPCNT) || -+ !boot_cpu_has(X86_FEATURE_XMM3) || /* SSE-3 */ -+ !boot_cpu_has(X86_FEATURE_XMM4_1) || /* SSE4_1 */ -+ !boot_cpu_has(X86_FEATURE_XMM4_2) || /* SSE4_2 */ -+ !boot_cpu_has(X86_FEATURE_SSSE3)) { -+ mark_hardware_deprecated("x86_64-v1", "%s:%s", -+ boot_cpu_data.x86_vendor_id, boot_cpu_data.x86_model_id); -+ } else if (!boot_cpu_has(X86_FEATURE_AVX) || -+ !boot_cpu_has(X86_FEATURE_AVX2) || -+ !boot_cpu_has(X86_FEATURE_BMI1) || -+ !boot_cpu_has(X86_FEATURE_BMI2) || -+ !boot_cpu_has(X86_FEATURE_F16C) || -+ !boot_cpu_has(X86_FEATURE_FMA) || -+ /* LZCNT is not explicitly listed, but appears to be paired with BMI2 */ -+ !boot_cpu_has(X86_FEATURE_MOVBE) || -+ !boot_cpu_has(X86_FEATURE_XSAVE)) { -+ mark_hardware_deprecated("x86_64-v2", "%s:%s", -+ boot_cpu_data.x86_vendor_id, boot_cpu_data.x86_model_id); -+ } -+} -+#else -+#define rh_check_supported() -+#endif -+ - /* - * Dump out kernel offset information on panic. - */ -@@ -991,6 +1069,13 @@ void __init setup_arch(char **cmdline_p) +@@ -991,6 +992,13 @@ void __init setup_arch(char **cmdline_p) if (efi_enabled(EFI_BOOT)) efi_init(); @@ -530,7 +251,7 @@ index 1b2edd07a3e1..201705bc317a 100644 reserve_ibft_region(); x86_init.resources.dmi_setup(); -@@ -1154,19 +1239,7 @@ void __init setup_arch(char **cmdline_p) +@@ -1154,19 +1162,7 @@ void __init setup_arch(char **cmdline_p) /* Allocate bigger log buffer */ setup_log_buf(1); @@ -551,15 +272,6 @@ index 1b2edd07a3e1..201705bc317a 100644 reserve_initrd(); -@@ -1278,6 +1351,8 @@ void __init setup_arch(char **cmdline_p) - efi_apply_memmap_quirks(); - #endif - -+ rh_check_supported(); -+ - unwind_init(); - } - diff --git a/crypto/akcipher.c b/crypto/akcipher.c index a36f50c83827..f4f421e6cff2 100644 --- a/crypto/akcipher.c @@ -614,286 +326,6 @@ index 8250eeeebd0f..01f0f3963a74 100644 } } -diff --git a/crypto/drbg.c b/crypto/drbg.c -index 1d433dae9955..c9899547752c 100644 ---- a/crypto/drbg.c -+++ b/crypto/drbg.c -@@ -1280,13 +1280,14 @@ static int drbg_generate(struct drbg_state *drbg, - * Wrapper around drbg_generate which can pull arbitrary long strings - * from the DRBG without hitting the maximum request limitation. - * -- * Parameters: see drbg_generate -+ * Parameters: see drbg_generate, except @reseed, which triggers reseeding - * Return codes: see drbg_generate -- if one drbg_generate request fails, - * the entire drbg_generate_long request fails - */ - static int drbg_generate_long(struct drbg_state *drbg, - unsigned char *buf, unsigned int buflen, -- struct drbg_string *addtl) -+ struct drbg_string *addtl, -+ bool reseed) - { - unsigned int len = 0; - unsigned int slice = 0; -@@ -1296,6 +1297,8 @@ static int drbg_generate_long(struct drbg_state *drbg, - slice = ((buflen - len) / drbg_max_request_bytes(drbg)); - chunk = slice ? drbg_max_request_bytes(drbg) : (buflen - len); - mutex_lock(&drbg->drbg_mutex); -+ if (reseed) -+ drbg->seeded = DRBG_SEED_STATE_UNSEEDED; - err = drbg_generate(drbg, buf + len, chunk, addtl); - mutex_unlock(&drbg->drbg_mutex); - if (0 > err) -@@ -1697,6 +1700,7 @@ static int drbg_kcapi_random(struct crypto_rng *tfm, - struct drbg_state *drbg = crypto_rng_ctx(tfm); - struct drbg_string *addtl = NULL; - struct drbg_string string; -+ int err; - - if (slen) { - /* linked list variable is now local to allow modification */ -@@ -1704,7 +1708,15 @@ static int drbg_kcapi_random(struct crypto_rng *tfm, - addtl = &string; - } - -- return drbg_generate_long(drbg, dst, dlen, addtl); -+ err = drbg_generate_long(drbg, dst, dlen, addtl, -+ (crypto_tfm_get_flags(crypto_rng_tfm(tfm)) & -+ CRYPTO_TFM_REQ_NEED_RESEED) == -+ CRYPTO_TFM_REQ_NEED_RESEED); -+ -+ crypto_tfm_clear_flags(crypto_rng_tfm(tfm), -+ CRYPTO_TFM_REQ_NEED_RESEED); -+ -+ return err; - } - - /* -diff --git a/crypto/rng.c b/crypto/rng.c -index ee1768c5a400..05ec1f0fca47 100644 ---- a/crypto/rng.c -+++ b/crypto/rng.c -@@ -12,10 +12,13 @@ - #include - #include - #include -+#include - #include - #include - #include - #include -+#include -+#include - #include - #include - #include -@@ -23,7 +26,9 @@ - - #include "internal.h" - --static DEFINE_MUTEX(crypto_default_rng_lock); -+static ____cacheline_aligned_in_smp DEFINE_MUTEX(crypto_reseed_rng_lock); -+static struct crypto_rng *crypto_reseed_rng; -+static ____cacheline_aligned_in_smp DEFINE_MUTEX(crypto_default_rng_lock); - struct crypto_rng *crypto_default_rng; - EXPORT_SYMBOL_GPL(crypto_default_rng); - static int crypto_default_rng_refcnt; -@@ -107,31 +112,37 @@ struct crypto_rng *crypto_alloc_rng(const char *alg_name, u32 type, u32 mask) - } - EXPORT_SYMBOL_GPL(crypto_alloc_rng); - --int crypto_get_default_rng(void) -+static int crypto_get_rng(struct crypto_rng **rngp) - { - struct crypto_rng *rng; - int err; - -- mutex_lock(&crypto_default_rng_lock); -- if (!crypto_default_rng) { -+ if (!*rngp) { - rng = crypto_alloc_rng("stdrng", 0, 0); - err = PTR_ERR(rng); - if (IS_ERR(rng)) -- goto unlock; -+ return err; - - err = crypto_rng_reset(rng, NULL, crypto_rng_seedsize(rng)); - if (err) { - crypto_free_rng(rng); -- goto unlock; -+ return err; - } - -- crypto_default_rng = rng; -+ *rngp = rng; - } - -- crypto_default_rng_refcnt++; -- err = 0; -+ return 0; -+} -+ -+int crypto_get_default_rng(void) -+{ -+ int err; - --unlock: -+ mutex_lock(&crypto_default_rng_lock); -+ err = crypto_get_rng(&crypto_default_rng); -+ if (!err) -+ crypto_default_rng_refcnt++; - mutex_unlock(&crypto_default_rng_lock); - - return err; -@@ -147,24 +158,33 @@ void crypto_put_default_rng(void) - EXPORT_SYMBOL_GPL(crypto_put_default_rng); - - #if defined(CONFIG_CRYPTO_RNG) || defined(CONFIG_CRYPTO_RNG_MODULE) --int crypto_del_default_rng(void) -+static int crypto_del_rng(struct crypto_rng **rngp, int *refcntp, -+ struct mutex *lock) - { - int err = -EBUSY; - -- mutex_lock(&crypto_default_rng_lock); -- if (crypto_default_rng_refcnt) -+ mutex_lock(lock); -+ if (refcntp && *refcntp) - goto out; - -- crypto_free_rng(crypto_default_rng); -- crypto_default_rng = NULL; -+ crypto_free_rng(*rngp); -+ *rngp = NULL; - - err = 0; - - out: -- mutex_unlock(&crypto_default_rng_lock); -+ mutex_unlock(lock); - - return err; - } -+ -+int crypto_del_default_rng(void) -+{ -+ return crypto_del_rng(&crypto_default_rng, &crypto_default_rng_refcnt, -+ &crypto_default_rng_lock) ?: -+ crypto_del_rng(&crypto_reseed_rng, NULL, -+ &crypto_reseed_rng_lock); -+} - EXPORT_SYMBOL_GPL(crypto_del_default_rng); - #endif - -@@ -226,5 +246,108 @@ void crypto_unregister_rngs(struct rng_alg *algs, int count) - } - EXPORT_SYMBOL_GPL(crypto_unregister_rngs); - -+static ssize_t crypto_devrandom_read_iter(struct iov_iter *iter, bool reseed) -+{ -+ struct crypto_rng *rng; -+ u8 tmp[256]; -+ ssize_t ret; -+ -+ if (unlikely(!iov_iter_count(iter))) -+ return 0; -+ -+ if (reseed) { -+ u32 flags = 0; -+ -+ /* If reseeding is requested, acquire a lock on -+ * crypto_reseed_rng so it is not swapped out until -+ * the initial random bytes are generated. -+ * -+ * The algorithm implementation is also protected with -+ * a separate mutex (drbg->drbg_mutex) around the -+ * reseed-and-generate operation. -+ */ -+ mutex_lock(&crypto_reseed_rng_lock); -+ -+ /* If crypto_default_rng is not set, it will be seeded -+ * at creation in __crypto_get_default_rng and thus no -+ * reseeding is needed. -+ */ -+ if (crypto_reseed_rng) -+ flags |= CRYPTO_TFM_REQ_NEED_RESEED; -+ -+ ret = crypto_get_rng(&crypto_reseed_rng); -+ if (ret) { -+ mutex_unlock(&crypto_reseed_rng_lock); -+ return ret; -+ } -+ -+ rng = crypto_reseed_rng; -+ crypto_tfm_set_flags(crypto_rng_tfm(rng), flags); -+ } else { -+ ret = crypto_get_default_rng(); -+ if (ret) -+ return ret; -+ rng = crypto_default_rng; -+ } -+ -+ for (;;) { -+ size_t i, copied; -+ int err; -+ -+ i = min_t(size_t, iov_iter_count(iter), sizeof(tmp)); -+ err = crypto_rng_get_bytes(rng, tmp, i); -+ if (err) { -+ ret = ret ?: err; -+ break; -+ } -+ -+ copied = copy_to_iter(tmp, i, iter); -+ ret += copied; -+ if (!iov_iter_count(iter) || copied != i) -+ break; -+ -+ BUILD_BUG_ON(PAGE_SIZE % sizeof(tmp) != 0); -+ if (ret % PAGE_SIZE == 0) { -+ if (signal_pending(current)) -+ break; -+ cond_resched(); -+ } -+ } -+ -+ if (reseed) -+ mutex_unlock(&crypto_reseed_rng_lock); -+ else -+ crypto_put_default_rng(); -+ memzero_explicit(tmp, sizeof(tmp)); -+ return ret ? ret : -EFAULT; -+} -+ -+static const struct random_extrng crypto_devrandom_rng = { -+ .extrng_read_iter = crypto_devrandom_read_iter, -+ .owner = THIS_MODULE, -+}; -+ -+static int __init crypto_rng_init(void) -+{ -+ int err; -+ -+ if (fips_enabled) { -+ err = crypto_get_default_rng(); -+ if (err) -+ return err; -+ crypto_put_default_rng(); -+ random_register_extrng(&crypto_devrandom_rng); -+ } -+ return 0; -+} -+ -+static void __exit crypto_rng_exit(void) -+{ -+ random_unregister_extrng(); -+} -+ -+late_initcall(crypto_rng_init); -+module_exit(crypto_rng_exit); -+ - MODULE_LICENSE("GPL"); - MODULE_DESCRIPTION("Random Number Generator"); diff --git a/crypto/seqiv.c b/crypto/seqiv.c index 678bb4145d78..fcc059e7d3db 100644 --- a/crypto/seqiv.c @@ -1089,278 +521,6 @@ index c79abdfcd7a9..e23bfb7f94c7 100644 /* wait for engine to stop. This could be as long as 500 msec */ tmp = ata_wait_register(ap, port_mmio + PORT_CMD, PORT_CMD_LIST_ON, PORT_CMD_LIST_ON, 1, 500); -diff --git a/drivers/char/ipmi/ipmi_dmi.c b/drivers/char/ipmi/ipmi_dmi.c -index bbf7029e224b..cf7faa970dd6 100644 ---- a/drivers/char/ipmi/ipmi_dmi.c -+++ b/drivers/char/ipmi/ipmi_dmi.c -@@ -215,6 +215,21 @@ static int __init scan_for_dmi_ipmi(void) - { - const struct dmi_device *dev = NULL; - -+#ifdef CONFIG_ARM64 -+ /* RHEL-only -+ * If this is ARM-based HPE m400, return now, because that platform -+ * reports the host-side ipmi address as intel port-io space, which -+ * does not exist in the ARM architecture. -+ */ -+ const char *dmistr = dmi_get_system_info(DMI_PRODUCT_NAME); -+ -+ if (dmistr && (strcmp("ProLiant m400 Server", dmistr) == 0)) { -+ pr_debug("%s does not support host ipmi\n", dmistr); -+ return 0; -+ } -+ /* END RHEL-only */ -+#endif -+ - while ((dev = dmi_find_device(DMI_DEV_TYPE_IPMI, NULL, dev))) - dmi_decode_ipmi((const struct dmi_header *) dev->device_data); - -diff --git a/drivers/char/ipmi/ipmi_msghandler.c b/drivers/char/ipmi/ipmi_msghandler.c -index 3f48fc6ab596..7b7b1abe02ec 100644 ---- a/drivers/char/ipmi/ipmi_msghandler.c -+++ b/drivers/char/ipmi/ipmi_msghandler.c -@@ -34,6 +34,7 @@ - #include - #include - #include -+#include - #include - - #define IPMI_DRIVER_VERSION "39.2" -@@ -5596,8 +5597,21 @@ static int __init ipmi_init_msghandler_mod(void) - { - int rv; - -- pr_info("version " IPMI_DRIVER_VERSION "\n"); -+#ifdef CONFIG_ARM64 -+ /* RHEL-only -+ * If this is ARM-based HPE m400, return now, because that platform -+ * reports the host-side ipmi address as intel port-io space, which -+ * does not exist in the ARM architecture. -+ */ -+ const char *dmistr = dmi_get_system_info(DMI_PRODUCT_NAME); - -+ if (dmistr && (strcmp("ProLiant m400 Server", dmistr) == 0)) { -+ pr_debug("%s does not support host ipmi\n", dmistr); -+ return -ENOSYS; -+ } -+ /* END RHEL-only */ -+#endif -+ pr_info("version " IPMI_DRIVER_VERSION "\n"); - mutex_lock(&ipmi_interfaces_mutex); - rv = ipmi_register_driver(); - mutex_unlock(&ipmi_interfaces_mutex); -diff --git a/drivers/char/random.c b/drivers/char/random.c -index bab03c7c4194..1eb70c54d122 100644 ---- a/drivers/char/random.c -+++ b/drivers/char/random.c -@@ -51,9 +51,11 @@ - #include - #include - #include -+#include - #include - #include - #include -+#include - #include - #include - #ifdef CONFIG_VDSO_GETRANDOM -@@ -330,6 +332,11 @@ static void crng_fast_key_erasure(u8 key[CHACHA_KEY_SIZE], - memzero_explicit(first_block, sizeof(first_block)); - } - -+/* -+ * Hook for external RNG. -+ */ -+static const struct random_extrng __rcu *extrng; -+ - /* - * This function returns a ChaCha state that you may use for generating - * random data. It also returns up to 32 bytes on its own of random data -@@ -745,7 +752,8 @@ static void __cold _credit_init_bits(size_t bits) - queue_work(system_dfl_wq, &set_ready); - atomic_notifier_call_chain(&random_ready_notifier, 0, NULL); - #ifdef CONFIG_VDSO_GETRANDOM -- WRITE_ONCE(vdso_k_rng_data->is_ready, true); -+ if (!fips_enabled) -+ WRITE_ONCE(vdso_k_rng_data->is_ready, true); - #endif - wake_up_interruptible(&crng_init_wait); - kill_fasync(&fasync, SIGIO, POLL_IN); -@@ -765,6 +773,9 @@ static void __cold _credit_init_bits(size_t bits) - } - - -+static const struct file_operations extrng_random_fops; -+static const struct file_operations extrng_urandom_fops; -+ - /********************************************************************** - * - * Entropy collection routines. -@@ -981,6 +992,19 @@ void __init add_bootloader_randomness(const void *buf, size_t len) - credit_init_bits(len * 8); - } - -+void random_register_extrng(const struct random_extrng *rng) -+{ -+ rcu_assign_pointer(extrng, rng); -+} -+EXPORT_SYMBOL_GPL(random_register_extrng); -+ -+void random_unregister_extrng(void) -+{ -+ RCU_INIT_POINTER(extrng, NULL); -+ synchronize_rcu(); -+} -+EXPORT_SYMBOL_GPL(random_unregister_extrng); -+ - #if IS_ENABLED(CONFIG_VMGENID) - static BLOCKING_NOTIFIER_HEAD(vmfork_chain); - -@@ -1395,6 +1419,7 @@ SYSCALL_DEFINE3(getrandom, char __user *, ubuf, size_t, len, unsigned int, flags - { - struct iov_iter iter; - int ret; -+ const struct random_extrng *rng; - - if (flags & ~(GRND_NONBLOCK | GRND_RANDOM | GRND_INSECURE)) - return -EINVAL; -@@ -1406,6 +1431,21 @@ SYSCALL_DEFINE3(getrandom, char __user *, ubuf, size_t, len, unsigned int, flags - if ((flags & (GRND_INSECURE | GRND_RANDOM)) == (GRND_INSECURE | GRND_RANDOM)) - return -EINVAL; - -+ rcu_read_lock(); -+ rng = rcu_dereference(extrng); -+ if (rng && !try_module_get(rng->owner)) -+ rng = NULL; -+ rcu_read_unlock(); -+ -+ if (rng) { -+ ret = import_ubuf(ITER_DEST, ubuf, len, &iter); -+ if (unlikely(ret)) -+ return ret; -+ ret = rng->extrng_read_iter(&iter, !!(flags & GRND_RANDOM)); -+ module_put(rng->owner); -+ return ret; -+ } -+ - if (!crng_ready() && !(flags & GRND_INSECURE)) { - if (flags & GRND_NONBLOCK) - return -EAGAIN; -@@ -1426,6 +1466,12 @@ static __poll_t random_poll(struct file *file, poll_table *wait) - return crng_ready() ? EPOLLIN | EPOLLRDNORM : EPOLLOUT | EPOLLWRNORM; - } - -+static __poll_t extrng_poll(struct file *file, poll_table * wait) -+{ -+ /* extrng pool is always full, always read, no writes */ -+ return EPOLLIN | EPOLLRDNORM; -+} -+ - static ssize_t write_pool_user(struct iov_iter *iter) - { - u8 block[BLAKE2S_BLOCK_SIZE]; -@@ -1566,7 +1612,58 @@ static int random_fasync(int fd, struct file *filp, int on) - return fasync_helper(fd, filp, on, &fasync); - } - -+static int random_open(struct inode *inode, struct file *filp) -+{ -+ const struct random_extrng *rng; -+ -+ rcu_read_lock(); -+ rng = rcu_dereference(extrng); -+ if (rng && !try_module_get(rng->owner)) -+ rng = NULL; -+ rcu_read_unlock(); -+ -+ if (!rng) -+ return 0; -+ -+ filp->f_op = &extrng_random_fops; -+ filp->private_data = rng->owner; -+ -+ return 0; -+} -+ -+static int urandom_open(struct inode *inode, struct file *filp) -+{ -+ const struct random_extrng *rng; -+ -+ rcu_read_lock(); -+ rng = rcu_dereference(extrng); -+ if (rng && !try_module_get(rng->owner)) -+ rng = NULL; -+ rcu_read_unlock(); -+ -+ if (!rng) -+ return 0; -+ -+ filp->f_op = &extrng_urandom_fops; -+ filp->private_data = rng->owner; -+ -+ return 0; -+} -+ -+static int extrng_release(struct inode *inode, struct file *filp) -+{ -+ module_put(filp->private_data); -+ return 0; -+} -+ -+static ssize_t -+extrng_read_iter(struct kiocb *kiocb, struct iov_iter *iter) -+{ -+ return rcu_dereference_raw(extrng)->extrng_read_iter(iter, false); -+} -+ - const struct file_operations random_fops = { -+ .open = random_open, - .read_iter = random_read_iter, - .write_iter = random_write_iter, - .poll = random_poll, -@@ -1579,6 +1676,7 @@ const struct file_operations random_fops = { - }; - - const struct file_operations urandom_fops = { -+ .open = urandom_open, - .read_iter = urandom_read_iter, - .write_iter = random_write_iter, - .unlocked_ioctl = random_ioctl, -@@ -1589,6 +1687,32 @@ const struct file_operations urandom_fops = { - .splice_write = iter_file_splice_write, - }; - -+static const struct file_operations extrng_random_fops = { -+ .open = random_open, -+ .read_iter = extrng_read_iter, -+ .write_iter = random_write_iter, -+ .poll = extrng_poll, -+ .unlocked_ioctl = random_ioctl, -+ .compat_ioctl = compat_ptr_ioctl, -+ .fasync = random_fasync, -+ .llseek = noop_llseek, -+ .release = extrng_release, -+ .splice_read = copy_splice_read, -+ .splice_write = iter_file_splice_write, -+}; -+ -+static const struct file_operations extrng_urandom_fops = { -+ .open = urandom_open, -+ .read_iter = extrng_read_iter, -+ .write_iter = random_write_iter, -+ .unlocked_ioctl = random_ioctl, -+ .compat_ioctl = compat_ptr_ioctl, -+ .fasync = random_fasync, -+ .llseek = noop_llseek, -+ .release = extrng_release, -+ .splice_read = copy_splice_read, -+ .splice_write = iter_file_splice_write, -+}; - - /******************************************************************** - * diff --git a/drivers/firmware/efi/Makefile b/drivers/firmware/efi/Makefile index 8efbcf699e4f..96d5a1ca981d 100644 --- a/drivers/firmware/efi/Makefile @@ -1999,103 +1159,6 @@ index 2ca990dfbb88..b9175e0d497c 100644 /** * iommu_setup_default_domain - Set the default_domain for the group * @group: Group to change -diff --git a/drivers/message/fusion/mptsas.c b/drivers/message/fusion/mptsas.c -index 185c08eab4ca..215a68b1d863 100644 ---- a/drivers/message/fusion/mptsas.c -+++ b/drivers/message/fusion/mptsas.c -@@ -5378,6 +5378,10 @@ static void mptsas_remove(struct pci_dev *pdev) - } - - static const struct pci_device_id mptsas_pci_table[] = { -+#ifdef CONFIG_RHEL_DIFFERENCES -+ { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068, -+ PCI_VENDOR_ID_VMWARE, PCI_ANY_ID }, -+#else - { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1064, - PCI_ANY_ID, PCI_ANY_ID }, - { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068, -@@ -5390,6 +5394,7 @@ static const struct pci_device_id mptsas_pci_table[] = { - PCI_ANY_ID, PCI_ANY_ID }, - { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068_820XELP, - PCI_ANY_ID, PCI_ANY_ID }, -+#endif - {0} /* Terminating entry */ - }; - MODULE_DEVICE_TABLE(pci, mptsas_pci_table); -diff --git a/drivers/message/fusion/mptspi.c b/drivers/message/fusion/mptspi.c -index a3901fbfac4f..83add1994d2c 100644 ---- a/drivers/message/fusion/mptspi.c -+++ b/drivers/message/fusion/mptspi.c -@@ -1240,12 +1240,17 @@ static struct spi_function_template mptspi_transport_functions = { - */ - - static const struct pci_device_id mptspi_pci_table[] = { -+#ifdef CONFIG_RHEL_DIFFERENCES -+ { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1030, -+ PCI_VENDOR_ID_VMWARE, PCI_ANY_ID }, -+#else - { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1030, - PCI_ANY_ID, PCI_ANY_ID }, - { PCI_VENDOR_ID_ATTO, MPI_MANUFACTPAGE_DEVID_53C1030, - PCI_ANY_ID, PCI_ANY_ID }, - { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1035, - PCI_ANY_ID, PCI_ANY_ID }, -+#endif - {0} /* Terminating entry */ - }; - MODULE_DEVICE_TABLE(pci, mptspi_pci_table); -diff --git a/drivers/net/wireguard/main.c b/drivers/net/wireguard/main.c -index a00671b58701..eeef2766b8b3 100644 ---- a/drivers/net/wireguard/main.c -+++ b/drivers/net/wireguard/main.c -@@ -12,6 +12,7 @@ - - #include - -+#include - #include - #include - #include -@@ -21,6 +22,11 @@ static int __init wg_mod_init(void) - { - int ret; - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ if (fips_enabled) -+ return -EOPNOTSUPP; -+#endif -+ - ret = wg_allowedips_slab_init(); - if (ret < 0) - goto err_allowedips; -diff --git a/drivers/pci/pci-driver.c b/drivers/pci/pci-driver.c -index 7c2d9d596258..ee6ea4241bf3 100644 ---- a/drivers/pci/pci-driver.c -+++ b/drivers/pci/pci-driver.c -@@ -19,6 +19,7 @@ - #include - #include - #include -+#include - #include - #include - #include "pci.h" -@@ -321,7 +322,15 @@ static long local_pci_probe(void *_ddi) - */ - pm_runtime_get_sync(dev); - pci_dev->driver = pci_drv; -+ -+#ifdef CONFIG_RHEL_DIFFERENCES -+ rc = -EACCES; -+ if (!pci_rh_check_status(pci_dev)) -+ rc = pci_drv->probe(pci_dev, ddi->id); -+#else - rc = pci_drv->probe(pci_dev, ddi->id); -+#endif -+ - if (!rc) - return rc; - if (rc < 0) { diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c index 280cd50d693b..9317f6903a05 100644 --- a/drivers/pci/quirks.c @@ -2131,92 +1194,31 @@ index 280cd50d693b..9317f6903a05 100644 /* * Intersil/Techwell TW686[4589]-based video capture cards have an empty (zero) * class code. Fix it. -diff --git a/drivers/scsi/hpsa.c b/drivers/scsi/hpsa.c -index 3654b12c5d5a..9bc907e146a5 100644 ---- a/drivers/scsi/hpsa.c -+++ b/drivers/scsi/hpsa.c -@@ -82,7 +82,9 @@ MODULE_DESCRIPTION("Driver for HP Smart Array Controller version " \ - HPSA_DRIVER_VERSION); - MODULE_VERSION(HPSA_DRIVER_VERSION); - MODULE_LICENSE("GPL"); -+#ifndef CONFIG_RHEL_DIFFERENCES - MODULE_ALIAS("cciss"); -+#endif - - static int hpsa_simple_mode; - module_param(hpsa_simple_mode, int, S_IRUGO|S_IWUSR); -@@ -144,10 +146,12 @@ static const struct pci_device_id hpsa_pci_device_id[] = { - {PCI_VENDOR_ID_HP_3PAR, 0x0075, 0x1590, 0x007D}, - {PCI_VENDOR_ID_HP_3PAR, 0x0075, 0x1590, 0x0088}, - {PCI_VENDOR_ID_HP, 0x333f, 0x103c, 0x333f}, -+#ifndef CONFIG_RHEL_DIFFERENCES - {PCI_VENDOR_ID_HP, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID, - PCI_CLASS_STORAGE_RAID << 8, 0xffff << 8, 0}, - {PCI_VENDOR_ID_COMPAQ, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID, - PCI_CLASS_STORAGE_RAID << 8, 0xffff << 8, 0}, -+#endif - {0,} - }; - -diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c -index e939bc88e151..3992159a106f 100644 ---- a/drivers/scsi/qla2xxx/qla_os.c -+++ b/drivers/scsi/qla2xxx/qla_os.c -@@ -8130,6 +8130,7 @@ static const struct pci_error_handlers qla2xxx_err_handler = { - }; - - static const struct pci_device_id qla2xxx_pci_tbl[] = { -+#ifndef CONFIG_RHEL_DIFFERENCES - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2100) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2200) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2300) }, -@@ -8142,13 +8143,18 @@ static const struct pci_device_id qla2xxx_pci_tbl[] = { - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8432) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP5422) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP5432) }, -+#endif - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2532) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2031) }, -+#ifndef CONFIG_RHEL_DIFFERENCES - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8001) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8021) }, -+#endif - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8031) }, -+#ifndef CONFIG_RHEL_DIFFERENCES - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISPF001) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8044) }, -+#endif - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2071) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2271) }, - { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2261) }, diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c -index f50b92e63201..9dc483fe6687 100644 +index f50b92e63201..f1ca4960fc59 100644 --- a/drivers/scsi/sd.c +++ b/drivers/scsi/sd.c @@ -121,6 +121,14 @@ static const char *sd_cache_types[] = { "write back, no read (daft)" }; -+#ifdef CONFIG_RHEL_DIFFERENCES ++static const char *sd_probe_types[] = { "async", "sync" }; ++ +static char sd_probe_type[6] = "async"; +module_param_string(probe, sd_probe_type, sizeof(sd_probe_type), + S_IRUGO|S_IWUSR); +MODULE_PARM_DESC(probe, "async or sync. Setting to 'sync' disables asynchronous " + "device number assignments (sda, sdb, ...)."); -+#endif + static void sd_set_flush_flag(struct scsi_disk *sdkp, struct queue_limits *lim) { -@@ -4417,6 +4425,11 @@ static int __init init_sd(void) +@@ -4417,6 +4425,8 @@ static int __init init_sd(void) goto err_out_class; } -+#ifdef CONFIG_RHEL_DIFFERENCES + if (!strcmp(sd_probe_type, "sync")) + sd_template.gendrv.probe_type = PROBE_FORCE_SYNCHRONOUS; -+#endif -+ err = scsi_register_driver(&sd_template.gendrv); if (err) goto err_out_driver; @@ -2238,83 +1240,19 @@ index be50d03034a9..9ce9b6518acd 100644 /* Lock the device, then check to see if we were * disconnected while waiting for the lock to succeed. */ usb_lock_device(hdev); -diff --git a/fs/afs/main.c b/fs/afs/main.c -index e6bb8237db98..68fcbaf74e60 100644 ---- a/fs/afs/main.c -+++ b/fs/afs/main.c -@@ -194,6 +194,9 @@ static int __init afs_init(void) - goto error_proc; - } - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ mark_partner_supported(KBUILD_MODNAME, THIS_MODULE); -+#endif - return ret; - - error_proc: -diff --git a/fs/erofs/super.c b/fs/erofs/super.c -index 5136cda5972a..a2a74963a6a2 100644 ---- a/fs/erofs/super.c -+++ b/fs/erofs/super.c -@@ -630,6 +630,9 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc) - { - struct inode *inode; - struct erofs_sb_info *sbi = EROFS_SB(sb); -+#ifdef CONFIG_RHEL_DIFFERENCES -+ static bool printed = false; -+#endif - int err; - - sb->s_magic = EROFS_SUPER_MAGIC; -@@ -767,6 +770,12 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc) - - sbi->dir_ra_bytes = EROFS_DIR_RA_BYTES; - erofs_info(sb, "mounted with root inode @ nid %llu.", sbi->root_nid); -+#ifdef CONFIG_RHEL_DIFFERENCES -+ if (!printed) { -+ mark_tech_preview("EROFS filesystem", NULL); -+ printed = true; -+ } -+#endif - return 0; - } - -diff --git a/fs/ext4/super.c b/fs/ext4/super.c -index 87205660c5d0..d4b8483a5722 100644 ---- a/fs/ext4/super.c -+++ b/fs/ext4/super.c -@@ -5688,6 +5688,17 @@ static int __ext4_fill_super(struct fs_context *fc, struct super_block *sb) - atomic_set(&sbi->s_warning_count, 0); - atomic_set(&sbi->s_msg_count, 0); - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ if (ext4_has_feature_verity(sb)) { -+ static bool printed = false; -+ -+ if (!printed) { -+ mark_tech_preview("fs-verity on ext4", NULL); -+ printed = true; -+ } -+ } -+#endif -+ - /* Register sysfs after all initializations are complete. */ - err = ext4_register_sysfs(sb); - if (err) diff --git a/include/linux/crypto.h b/include/linux/crypto.h -index a2137e19be7d..df268ca70170 100644 +index a2137e19be7d..79ccb6fabc10 100644 --- a/include/linux/crypto.h +++ b/include/linux/crypto.h -@@ -151,6 +151,9 @@ - #define CRYPTO_TFM_REQ_MAY_SLEEP 0x00000200 +@@ -152,6 +152,8 @@ #define CRYPTO_TFM_REQ_MAY_BACKLOG 0x00000400 #define CRYPTO_TFM_REQ_ON_STACK 0x00000800 -+#define CRYPTO_TFM_REQ_NEED_RESEED 0x00001000 -+ -+#define CRYPTO_TFM_FIPS_COMPLIANCE 0x80000000 ++#define CRYPTO_TFM_FIPS_COMPLIANCE 0x80000000 ++ /* * Miscellaneous stuff. + */ diff --git a/include/linux/efi.h b/include/linux/efi.h index 2a43094e23f7..4fcf05f8232c 100644 --- a/include/linux/efi.h @@ -2383,31 +1321,6 @@ index 2a43094e23f7..4fcf05f8232c 100644 static inline enum efi_secureboot_mode efi_get_secureboot_mode(efi_get_variable_t *get_var) { -diff --git a/include/linux/kernel.h b/include/linux/kernel.h -index 5b46924fdff5..ffd5e38d3cb7 100644 ---- a/include/linux/kernel.h -+++ b/include/linux/kernel.h -@@ -403,4 +403,20 @@ static inline void ftrace_dump(enum ftrace_dump_mode oops_dump_mode) { } - /* OTHER_WRITABLE? Generally considered a bad idea. */ \ - BUILD_BUG_ON_ZERO((perms) & 2) + \ - (perms)) -+ -+struct module; -+ -+#ifdef CONFIG_RHEL_DIFFERENCES -+void mark_hardware_unmaintained(const char *driver_name, char *fmt, ...); -+void mark_hardware_deprecated(const char *driver_name, char *fmt, ...); -+void mark_tech_preview(const char *msg, struct module *mod); -+void mark_partner_supported(const char *msg, struct module *mod); -+void init_rh_check_status(char *fn_name); -+#else -+static inline void mark_hardware_unmaintained(const char *driver_name, char *fmt, ...) { } -+static inline void mark_hardware_deprecated(const char *driver_name, char *fmt, ...) { } -+static inline void mark_tech_preview(const char *msg, struct module *mod) { } -+static inline void mark_partner_supported(const char *msg, struct module *mod) { } -+#endif -+ - #endif diff --git a/include/linux/lsm_hook_defs.h b/include/linux/lsm_hook_defs.h index 8c42b4bde09c..694ce5c5bcd4 100644 --- a/include/linux/lsm_hook_defs.h @@ -2420,720 +1333,6 @@ index 8c42b4bde09c..694ce5c5bcd4 100644 #ifdef CONFIG_PERF_EVENTS LSM_HOOK(int, 0, perf_event_open, int type) LSM_HOOK(int, 0, perf_event_alloc, struct perf_event *event) -diff --git a/include/linux/module.h b/include/linux/module.h -index d80c3ea57472..662dff7438d7 100644 ---- a/include/linux/module.h -+++ b/include/linux/module.h -@@ -419,6 +419,7 @@ struct module { - struct module_attribute *modinfo_attrs; - const char *version; - const char *srcversion; -+ const char *rhelversion; - struct kobject *holders_dir; - - /* Exported symbols */ -@@ -1018,6 +1019,10 @@ static inline unsigned long find_kallsyms_symbol_value(struct module *mod, - - #endif /* CONFIG_MODULES && CONFIG_KALLSYMS */ - -+#ifdef CONFIG_RHEL_DIFFERENCES -+void module_rh_check_status(const char * module_name); -+#endif -+ - /* Define __free(module_put) macro for struct module *. */ - DEFINE_FREE(module_put, struct module *, if (_T) module_put(_T)) - -diff --git a/include/linux/panic.h b/include/linux/panic.h -index a00bc0937698..7cce62f1c50b 100644 ---- a/include/linux/panic.h -+++ b/include/linux/panic.h -@@ -80,7 +80,22 @@ static inline void set_arch_panic_timeout(int timeout, int arch_default_timeout) - #define TAINT_RANDSTRUCT 17 - #define TAINT_TEST 18 - #define TAINT_FWCTL 19 --#define TAINT_FLAGS_COUNT 20 -+/* Start of Red Hat-specific taint flags */ -+#define TAINT_20 20 -+#define TAINT_21 21 -+#define TAINT_22 22 -+#define TAINT_23 23 -+#define TAINT_24 24 -+#define TAINT_25 25 -+#define TAINT_PARTNER_SUPPORTED 26 -+#define TAINT_SUPPORT_REMOVED 27 -+/* Bits 28 - 31 are reserved for Red Hat use only */ -+#define TAINT_RESERVED28 28 -+#define TAINT_RESERVED29 29 -+#define TAINT_RESERVED30 30 -+#define TAINT_UNPRIVILEGED_BPF 31 -+/* End of Red Hat-specific taint flags */ -+#define TAINT_FLAGS_COUNT 32 - #define TAINT_FLAGS_MAX ((1UL << TAINT_FLAGS_COUNT) - 1) - - struct taint_flag { -diff --git a/include/linux/pci.h b/include/linux/pci.h -index b5cc0c2b9906..5f39e3063372 100644 ---- a/include/linux/pci.h -+++ b/include/linux/pci.h -@@ -1682,6 +1682,7 @@ int pci_add_dynid(struct pci_driver *drv, - unsigned long driver_data); - const struct pci_device_id *pci_match_id(const struct pci_device_id *ids, - struct pci_dev *dev); -+ - int pci_scan_bridge(struct pci_bus *bus, struct pci_dev *dev, int max, - int pass); - -@@ -2816,6 +2817,10 @@ static inline bool pci_is_thunderbolt_attached(struct pci_dev *pdev) - return false; - } - -+#ifdef CONFIG_RHEL_DIFFERENCES -+bool pci_rh_check_status(struct pci_dev *pci_dev); -+#endif -+ - #if defined(CONFIG_PCIEPORTBUS) || defined(CONFIG_EEH) || defined(CONFIG_S390) - void pci_uevent_ers(struct pci_dev *pdev, enum pci_ers_result err_type); - #endif -diff --git a/include/linux/random.h b/include/linux/random.h -index 8a8064dc3970..3238fab8f749 100644 ---- a/include/linux/random.h -+++ b/include/linux/random.h -@@ -9,6 +9,13 @@ - - #include - -+struct iov_iter; -+ -+struct random_extrng { -+ ssize_t (*extrng_read_iter)(struct iov_iter *iter, bool reseed); -+ struct module *owner; -+}; -+ - struct notifier_block; - - void add_device_randomness(const void *buf, size_t len); -@@ -135,6 +142,9 @@ int random_prepare_cpu(unsigned int cpu); - int random_online_cpu(unsigned int cpu); - #endif - -+void random_register_extrng(const struct random_extrng *rng); -+void random_unregister_extrng(void); -+ - #ifndef MODULE - extern const struct file_operations random_fops, urandom_fops; - #endif -diff --git a/include/linux/rh_flags.h b/include/linux/rh_flags.h -new file mode 100644 -index 000000000000..d498d319ace3 ---- /dev/null -+++ b/include/linux/rh_flags.h -@@ -0,0 +1,34 @@ -+/* SPDX-License-Identifier: GPL-2.0 */ -+/* -+ * rh_flags.h -- Red Hat flags tracking -+ * -+ * Copyright (c) 2018 Red Hat, Inc. -- Jiri Benc -+ * -+ * The intent of the flag tracking is to provide better and more focused -+ * support. Only those flags that are of a special interest for customer -+ * support should be tracked. -+ * -+ * THE FLAGS DO NOT EXPRESS ANY SUPPORT POLICIES. -+ */ -+ -+#ifndef _LINUX_RH_FLAGS_H -+#define _LINUX_RH_FLAGS_H -+ -+#if defined CONFIG_RHEL_DIFFERENCES -+bool __rh_add_flag(const char *flag_name); -+void rh_print_flags(void); -+ -+#define rh_add_flag(flag_name) \ -+({ \ -+ static bool __mark_once __read_mostly; \ -+ bool __ret_mark_once = !__mark_once; \ -+ \ -+ if (!__mark_once) \ -+ __mark_once = __rh_add_flag(flag_name); \ -+ unlikely(__ret_mark_once); \ -+}) -+#else -+static void rh_print_flags(void) { } -+static void rh_add_flag(const char *flag_name) { } -+#endif -+#endif -diff --git a/include/linux/rh_kabi.h b/include/linux/rh_kabi.h -new file mode 100644 -index 000000000000..5139cb2cabdc ---- /dev/null -+++ b/include/linux/rh_kabi.h -@@ -0,0 +1,541 @@ -+/* -+ * rh_kabi.h - Red Hat kABI abstraction header -+ * -+ * Copyright (c) 2014 Don Zickus -+ * Copyright (c) 2015-2020 Jiri Benc -+ * Copyright (c) 2015 Sabrina Dubroca, Hannes Frederic Sowa -+ * Copyright (c) 2016-2018 Prarit Bhargava -+ * Copyright (c) 2017 Paolo Abeni, Larry Woodman -+ * -+ * This file is released under the GPLv2. -+ * See the file COPYING for more details. -+ * -+ * These kabi macros hide the changes from the kabi checker and from the -+ * process that computes the exported symbols' checksums. -+ * They have 2 variants: one (defined under __GENKSYMS__) used when -+ * generating the checksums, and the other used when building the kernel's -+ * binaries. -+ * -+ * The use of these macros does not guarantee that the usage and modification -+ * of code is correct. As with all Red Hat only changes, an engineer must -+ * explain why the use of the macro is valid in the patch containing the -+ * changes. -+ * -+ */ -+ -+#ifndef _LINUX_RH_KABI_H -+#define _LINUX_RH_KABI_H -+ -+#include -+#include -+#include -+ -+/* -+ * NOTE -+ * Unless indicated otherwise, don't use ';' after these macros as it -+ * messes up the kABI checker by changing what the resulting token string -+ * looks like. Instead let the macros add the ';' so it can be properly -+ * hidden from the kABI checker (mainly for RH_KABI_EXTEND, but applied to -+ * most macros for uniformity). -+ * -+ * -+ * RH_KABI_CONST -+ * Adds a new const modifier to a function parameter preserving the old -+ * checksum. -+ * -+ * RH_KABI_ADD_MODIFIER -+ * Adds a new modifier to a function parameter or a typedef, preserving -+ * the old checksum. Useful e.g. for adding rcu annotations or changing -+ * int to unsigned. Beware that this may change the semantics; if you're -+ * sure this is safe, always explain why binary compatibility with 3rd -+ * party modules is retained. -+ * -+ * RH_KABI_DEPRECATE -+ * Marks the element as deprecated and make it unusable by modules while -+ * keeping a hole in its place to preserve binary compatibility. -+ * -+ * RH_KABI_DEPRECATE_FN -+ * Marks the function pointer as deprecated and make it unusable by modules -+ * while keeping a hole in its place to preserve binary compatibility. -+ * -+ * RH_KABI_EXTEND -+ * Adds a new field to a struct. This must always be added to the end of -+ * the struct. Before using this macro, make sure this is actually safe -+ * to do - there is a number of conditions under which it is *not* safe. -+ * In particular (but not limited to), this macro cannot be used: -+ * - if the struct in question is embedded in another struct, or -+ * - if the struct is allocated by drivers either statically or -+ * dynamically, or -+ * - if the struct is allocated together with driver data (an example of -+ * such behavior is struct net_device or struct request). -+ * -+ * RH_KABI_EXTEND_WITH_SIZE -+ * Adds a new element (usually a struct) to a struct and reserves extra -+ * space for the new element. The provided 'size' is the total space to -+ * be added in longs (i.e. it's 8 * 'size' bytes), including the size of -+ * the added element. It is automatically checked that the new element -+ * does not overflow the reserved space, now nor in the future. However, -+ * no attempt is done to check the content of the added element (struct) -+ * for kABI conformance - kABI checking inside the added element is -+ * effectively switched off. -+ * For any struct being added by RH_KABI_EXTEND_WITH_SIZE, it is -+ * recommended its content to be documented as not covered by kABI -+ * guarantee. -+ * -+ * RH_KABI_FILL_HOLE -+ * Fills a hole in a struct. -+ * -+ * Warning: only use if a hole exists for _all_ arches. Use pahole to verify. -+ * -+ * RH_KABI_RENAME -+ * Renames an element without changing its type. This macro can be used in -+ * bitfields, for example. -+ * -+ * NOTE: this macro does not add the final ';' -+ * -+ * RH_KABI_REPLACE -+ * Replaces the _orig field by the _new field. The size of the occupied -+ * space is preserved, it's fine if the _new field is smaller than the -+ * _orig field. If a _new field is larger or has a different alignment, -+ * compilation will abort. -+ * -+ * RH_KABI_REPLACE_SPLIT -+ * Works the same as RH_KABI_REPLACE but replaces a single _orig field by -+ * multiple new fields. The checks for size and alignment done by -+ * RH_KABI_REPLACE are still applied. -+ * -+ * RH_KABI_HIDE_INCLUDE -+ * Hides the given include file from kABI checksum computations. This is -+ * used when a newly added #include makes a previously opaque struct -+ * visible. -+ * -+ * Example usage: -+ * #include RH_KABI_HIDE_INCLUDE() -+ * -+ * RH_KABI_FAKE_INCLUDE -+ * Pretends inclusion of the given file for kABI checksum computations. -+ * This is used when upstream removed a particular #include but that made -+ * some structures opaque that were previously visible and is causing kABI -+ * checker failures. -+ * -+ * Example usage: -+ * #include RH_KABI_FAKE_INCLUDE() -+ * -+ * RH_KABI_RESERVE -+ * Adds a reserved field to a struct. This is done prior to kABI freeze -+ * for structs that cannot be expanded later using RH_KABI_EXTEND (for -+ * example because they are embedded in another struct or because they are -+ * allocated by drivers or because they use unusual memory layout). The -+ * size of the reserved field is 'unsigned long' and is assumed to be -+ * 8 bytes. -+ * -+ * The argument is a number unique for the given struct; usually, multiple -+ * RH_KABI_RESERVE macros are added to a struct with numbers starting from -+ * one. -+ * -+ * Example usage: -+ * struct foo { -+ * int a; -+ * RH_KABI_RESERVE(1) -+ * RH_KABI_RESERVE(2) -+ * RH_KABI_RESERVE(3) -+ * RH_KABI_RESERVE(4) -+ * }; -+ * -+ * RH_KABI_USE -+ * Uses a previously reserved field or multiple fields. The arguments are -+ * one or more numbers assigned to RH_KABI_RESERVE, followed by a field to -+ * be put in their place. The compiler ensures that the new field is not -+ * larger than the reserved area. -+ * -+ * Example usage: -+ * struct foo { -+ * int a; -+ * RH_KABI_USE(1, int b) -+ * RH_KABI_USE(2, 3, int c[3]) -+ * RH_KABI_RESERVE(4) -+ * }; -+ * -+ * RH_KABI_USE_SPLIT -+ * Works the same as RH_KABI_USE but replaces a single reserved field by -+ * multiple new fields. -+ * -+ * RH_KABI_AUX_EMBED -+ * RH_KABI_AUX_PTR -+ * Adds an extenstion of a struct in the form of "auxiliary structure". -+ * This is done prior to kABI freeze for structs that cannot be expanded -+ * later using RH_KABI_EXTEND. See also RH_KABI_RESERVED, these two -+ * approaches can (and often are) combined. -+ * -+ * To use this for 'struct foo' (the "base structure"), define a new -+ * structure called 'struct foo_rh'; this new struct is called "auxiliary -+ * structure". Then add RH_KABI_AUX_EMBED or RH_KABI_AUX_PTR to the end -+ * of the base structure. The argument is the name of the base structure, -+ * without the 'struct' keyword. -+ * -+ * RH_KABI_AUX_PTR stores a pointer to the aux structure in the base -+ * struct. The lifecycle of the aux struct needs to be properly taken -+ * care of. -+ * -+ * RH_KABI_AUX_EMBED embeds the aux struct into the base struct. This -+ * cannot be used when the base struct is itself embedded into another -+ * struct, allocated in an array, etc. -+ * -+ * Both approaches (ptr and embed) work correctly even when the aux struct -+ * is allocated by modules. To ensure this, the code responsible for -+ * allocation/assignment of the aux struct has to properly set the size of -+ * the aux struct; see the RH_KABI_AUX_SET_SIZE and RH_KABI_AUX_INIT_SIZE -+ * macros. -+ * -+ * New fields can be later added to the auxiliary structure, always to its -+ * end. Note the auxiliary structure cannot be shrunk in size later (i.e., -+ * fields cannot be removed, only deprecated). Any code accessing fields -+ * from the aux struct must guard the access using the RH_KABI_AUX macro. -+ * The access itself is then done via a '_rh' field in the base struct. -+ * -+ * The auxiliary structure is not guaranteed for access by modules unless -+ * explicitly commented as such in the declaration of the aux struct -+ * itself or some of its elements. -+ * -+ * Example: -+ * -+ * struct foo_rh { -+ * int newly_added; -+ * }; -+ * -+ * struct foo { -+ * bool big_hammer; -+ * RH_KABI_AUX_PTR(foo) -+ * }; -+ * -+ * void use(struct foo *f) -+ * { -+ * if (RH_KABI_AUX(f, foo, newly_added)) -+ * f->_rh->newly_added = 123; -+ * else -+ * // the field 'newly_added' is not present in the passed -+ * // struct, fall back to old behavior -+ * f->big_hammer = true; -+ * } -+ * -+ * static struct foo_rh my_foo_rh { -+ * .newly_added = 0; -+ * } -+ * -+ * static struct foo my_foo = { -+ * .big_hammer = false, -+ * ._rh = &my_foo_rh, -+ * RH_KABI_AUX_INIT_SIZE(foo) -+ * }; -+ * -+ * RH_KABI_USE_AUX_PTR -+ * Creates an auxiliary structure post kABI freeze. This works by using -+ * two reserved fields (thus there has to be two reserved fields still -+ * available) and converting them to RH_KABI_AUX_PTR. -+ * -+ * Example: -+ * -+ * struct foo_rh { -+ * }; -+ * -+ * struct foo { -+ * int a; -+ * RH_KABI_RESERVE(1) -+ * RH_KABI_USE_AUX_PTR(2, 3, foo) -+ * }; -+ * -+ * RH_KABI_AUX_SET_SIZE -+ * RH_KABI_AUX_INIT_SIZE -+ * Calculates and stores the size of the auxiliary structure. -+ * -+ * RH_KABI_AUX_SET_SIZE is for dynamically allocated base structs, -+ * RH_KABI_AUX_INIT_SIZE is for statically allocated case structs. -+ * -+ * These macros must be called from the allocation (RH_KABI_AUX_SET_SIZE) -+ * or declaration (RH_KABI_AUX_INIT_SIZE) site, regardless of whether -+ * that happens in the kernel or in a module. Without calling one of -+ * these macros, the aux struct will appear to have no fields to the -+ * kernel. -+ * -+ * Note: since RH_KABI_AUX_SET_SIZE is intended to be invoked outside of -+ * a struct definition, it does not add the semicolon and must be -+ * terminated by semicolon by the caller. -+ * -+ * RH_KABI_AUX -+ * Verifies that the given field exists in the given auxiliary structure. -+ * This MUST be called prior to accessing that field; failing to do that -+ * may lead to invalid memory access. -+ * -+ * The first argument is a pointer to the base struct, the second argument -+ * is the name of the base struct (without the 'struct' keyword), the -+ * third argument is the field name. -+ * -+ * This macro works for structs extended by either of RH_KABI_AUX_EMBED, -+ * RH_KABI_AUX_PTR and RH_KABI_USE_AUX_PTR. -+ * -+ * RH_KABI_FORCE_CHANGE -+ * Force change of the symbol checksum. The argument of the macro is a -+ * version for cases we need to do this more than once. -+ * -+ * This macro does the opposite: it changes the symbol checksum without -+ * actually changing anything about the exported symbol. It is useful for -+ * symbols that are not whitelisted, we're changing them in an -+ * incompatible way and want to prevent 3rd party modules to silently -+ * corrupt memory. Instead, by changing the symbol checksum, such modules -+ * won't be loaded by the kernel. This macro should only be used as a -+ * last resort when all other KABI workarounds have failed. -+ * -+ * RH_KABI_EXCLUDE -+ * !!! WARNING: DANGEROUS, DO NOT USE unless you are aware of all the !!! -+ * !!! implications. This should be used ONLY EXCEPTIONALLY and only !!! -+ * !!! under specific circumstances. Very likely, this macro does not !!! -+ * !!! do what you expect it to do. Note that any usage of this macro !!! -+ * !!! MUST be paired with a RH_KABI_FORCE_CHANGE annotation of !!! -+ * !!! a suitable symbol (or an equivalent safeguard) and the commit !!! -+ * !!! log MUST explain why the chosen solution is appropriate. !!! -+ * -+ * Exclude the element from checksum generation. Any such element is -+ * considered not to be part of the kABI whitelist and may be changed at -+ * will. Note however that it's the responsibility of the developer -+ * changing the element to ensure 3rd party drivers using this element -+ * won't panic, for example by not allowing them to be loaded. That can -+ * be achieved by changing another, non-whitelisted symbol they use, -+ * either by nature of the change or by using RH_KABI_FORCE_CHANGE. -+ * -+ * Also note that any change to the element must preserve its size. Change -+ * of the size is not allowed and would constitute a silent kABI breakage. -+ * Beware that the RH_KABI_EXCLUDE macro does not do any size checks. -+ * -+ * RH_KABI_EXCLUDE_WITH_SIZE -+ * Like RH_KABI_EXCLUDE, this macro excludes the element from -+ * checksum generation. The same warnings as for RH_KABI_EXCLUDE -+ * apply: use RH_KABI_FORCE_CHANGE. -+ * -+ * This macro is intended to be used for elements embedded inside -+ * kABI-protected structures (struct, array). In contrast with -+ * RH_KABI_EXCLUDE, this macro reserves extra space, so that the -+ * embedded element can grow without changing the offsets of the -+ * fields that follow. The provided 'size' is the total space to be -+ * added in longs (i.e. it's 8 * 'size' bytes), including the size -+ * of the added element. It is automatically checked that the new -+ * element does not overflow the reserved space, now nor in the -+ * future. The size is also included in the checksum via the -+ * reserved space, to ensure that we don't accidentally change it, -+ * which would change the offsets of the fields that follow. -+ * -+ * RH_KABI_BROKEN_INSERT -+ * RH_KABI_BROKEN_REMOVE -+ * Insert a field to the middle of a struct / delete a field from a struct. -+ * Note that this breaks kABI! It can be done only when it's certain that -+ * no 3rd party driver can validly reach into the struct. A typical -+ * example is a struct that is: both (a) referenced only through a long -+ * chain of pointers from another struct that is part of a whitelisted -+ * symbol and (b) kernel internal only, it should have never been visible -+ * to genksyms in the first place. -+ * -+ * Another example are structs that are explicitly exempt from kABI -+ * guarantee but we did not have enough foresight to use RH_KABI_EXCLUDE. -+ * In this case, the warning for RH_KABI_EXCLUDE applies. -+ * -+ * A detailed explanation of correctness of every RH_KABI_BROKEN_* macro -+ * use is especially important. -+ * -+ * RH_KABI_BROKEN_INSERT_BLOCK -+ * RH_KABI_BROKEN_REMOVE_BLOCK -+ * A version of RH_KABI_BROKEN_INSERT / REMOVE that allows multiple fields -+ * to be inserted or removed together. All fields need to be terminated -+ * by ';' inside(!) the macro parameter. The macro itself must not be -+ * terminated by ';'. -+ * -+ * RH_KABI_BROKEN_REPLACE -+ * Replace a field by a different one without doing any checking. This -+ * allows replacing a field by another with a different size. Similarly -+ * to other RH_KABI_BROKEN macros, use of this indicates a kABI breakage. -+ * -+ * RH_KABI_BROKEN_INSERT_ENUM -+ * RH_KABI_BROKEN_REMOVE_ENUM -+ * Insert a field to the middle of an enumaration type / delete a field from -+ * an enumaration type. Note that this can break kABI especially if the -+ * number of enum fields is used in an array within a structure. It can be -+ * done only when it is certain that no 3rd party driver will use the -+ * enumeration type or a structure that embeds an array with size determined -+ * by an enumeration type. -+ * -+ * RH_KABI_EXTEND_ENUM -+ * Adds a new field to an enumeration type. This must always be added to -+ * the end of the enum. Before using this macro, make sure this is actually -+ * safe to do. -+ */ -+ -+#undef linux -+#define linux linux -+ -+#ifdef __GENKSYMS__ -+ -+# define RH_KABI_CONST -+# define RH_KABI_ADD_MODIFIER(_new) -+# define RH_KABI_EXTEND(_new) -+# define RH_KABI_FILL_HOLE(_new) -+# define RH_KABI_FORCE_CHANGE(ver) __attribute__((rh_kabi_change ## ver)) -+# define RH_KABI_RENAME(_orig, _new) _orig -+# define RH_KABI_HIDE_INCLUDE(_file) -+# define RH_KABI_FAKE_INCLUDE(_file) _file -+# define RH_KABI_BROKEN_INSERT(_new) -+# define RH_KABI_BROKEN_REMOVE(_orig) _orig; -+# define RH_KABI_BROKEN_INSERT_BLOCK(_new) -+# define RH_KABI_BROKEN_REMOVE_BLOCK(_orig) _orig -+# define RH_KABI_BROKEN_REPLACE(_orig, _new) _orig; -+# define RH_KABI_BROKEN_INSERT_ENUM(_new) -+# define RH_KABI_BROKEN_REMOVE_ENUM(_orig) _orig, -+# define RH_KABI_EXTEND_ENUM(_new) -+ -+# define _RH_KABI_DEPRECATE(_type, _orig) _type _orig -+# define _RH_KABI_DEPRECATE_FN(_type, _orig, _args...) _type (*_orig)(_args) -+# define _RH_KABI_REPLACE(_orig, _new) _orig -+# define _RH_KABI_EXCLUDE(_elem) -+ -+# define __RH_KABI_CHECK_SIZE(_item, _size) -+ -+#else -+ -+# define RH_KABI_ALIGN_WARNING ". Disable CONFIG_RH_KABI_SIZE_ALIGN_CHECKS if debugging." -+ -+# define RH_KABI_CONST const -+# define RH_KABI_ADD_MODIFIER(_new) _new -+# define RH_KABI_EXTEND(_new) _new; -+# define RH_KABI_FILL_HOLE(_new) _new; -+# define RH_KABI_FORCE_CHANGE(ver) -+# define RH_KABI_RENAME(_orig, _new) _new -+# define RH_KABI_HIDE_INCLUDE(_file) _file -+# define RH_KABI_FAKE_INCLUDE(_file) -+# define RH_KABI_BROKEN_INSERT(_new) _new; -+# define RH_KABI_BROKEN_REMOVE(_orig) -+# define RH_KABI_BROKEN_INSERT_BLOCK(_new) _new -+# define RH_KABI_BROKEN_REMOVE_BLOCK(_orig) -+# define RH_KABI_BROKEN_REPLACE(_orig, _new) _new; -+# define RH_KABI_BROKEN_INSERT_ENUM(_new) _new, -+# define RH_KABI_BROKEN_REMOVE_ENUM(_orig) -+# define RH_KABI_EXTEND_ENUM(_new) _new, -+ -+#if IS_BUILTIN(CONFIG_RH_KABI_SIZE_ALIGN_CHECKS) -+# define __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new) \ -+ union { \ -+ _Static_assert(sizeof(struct{_new;}) <= sizeof(struct{_orig;}), \ -+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_new) " is larger than " __stringify(_orig) RH_KABI_ALIGN_WARNING); \ -+ _Static_assert(__alignof__(struct{_new;}) <= __alignof__(struct{_orig;}), \ -+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_orig) " is not aligned the same as " __stringify(_new) RH_KABI_ALIGN_WARNING); \ -+ } -+# define __RH_KABI_CHECK_SIZE(_item, _size) \ -+ _Static_assert(sizeof(struct{_item;}) <= _size, \ -+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_item) " is larger than the reserved size (" __stringify(_size) " bytes)" RH_KABI_ALIGN_WARNING); -+#else -+# define __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new) -+# define __RH_KABI_CHECK_SIZE(_item, _size) -+#endif -+ -+#define RH_KABI_UNIQUE_ID __PASTE(rh_kabi_hidden_, __LINE__) -+ -+# define _RH_KABI_DEPRECATE(_type, _orig) _type rh_reserved_##_orig -+# define _RH_KABI_DEPRECATE_FN(_type, _orig, _args...) \ -+ _type (* rh_reserved_##_orig)(_args) -+# define _RH_KABI_REPLACE(_orig, _new) \ -+ union { \ -+ _new; \ -+ struct { \ -+ _orig; \ -+ } RH_KABI_UNIQUE_ID; \ -+ __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new); \ -+ } -+ -+# define _RH_KABI_EXCLUDE(_elem) _elem -+ -+#endif /* __GENKSYMS__ */ -+ -+# define RH_KABI_DEPRECATE(_type, _orig) _RH_KABI_DEPRECATE(_type, _orig); -+# define RH_KABI_DEPRECATE_FN(_type, _orig, _args...) \ -+ _RH_KABI_DEPRECATE_FN(_type, _orig, _args); -+# define RH_KABI_REPLACE(_orig, _new) _RH_KABI_REPLACE(_orig, _new); -+ -+#define _RH_KABI_REPLACE1(_new) _new; -+#define _RH_KABI_REPLACE2(_new, ...) _new; _RH_KABI_REPLACE1(__VA_ARGS__) -+#define _RH_KABI_REPLACE3(_new, ...) _new; _RH_KABI_REPLACE2(__VA_ARGS__) -+#define _RH_KABI_REPLACE4(_new, ...) _new; _RH_KABI_REPLACE3(__VA_ARGS__) -+#define _RH_KABI_REPLACE5(_new, ...) _new; _RH_KABI_REPLACE4(__VA_ARGS__) -+#define _RH_KABI_REPLACE6(_new, ...) _new; _RH_KABI_REPLACE5(__VA_ARGS__) -+#define _RH_KABI_REPLACE7(_new, ...) _new; _RH_KABI_REPLACE6(__VA_ARGS__) -+#define _RH_KABI_REPLACE8(_new, ...) _new; _RH_KABI_REPLACE7(__VA_ARGS__) -+#define _RH_KABI_REPLACE9(_new, ...) _new; _RH_KABI_REPLACE8(__VA_ARGS__) -+#define _RH_KABI_REPLACE10(_new, ...) _new; _RH_KABI_REPLACE9(__VA_ARGS__) -+#define _RH_KABI_REPLACE11(_new, ...) _new; _RH_KABI_REPLACE10(__VA_ARGS__) -+#define _RH_KABI_REPLACE12(_new, ...) _new; _RH_KABI_REPLACE11(__VA_ARGS__) -+ -+#define RH_KABI_REPLACE_SPLIT(_orig, ...) _RH_KABI_REPLACE(_orig, \ -+ struct { __PASTE(_RH_KABI_REPLACE, COUNT_ARGS(__VA_ARGS__))(__VA_ARGS__) }); -+ -+# define RH_KABI_RESERVE(n) _RH_KABI_RESERVE(n); -+ -+#define _RH_KABI_USE1(n, _new) _RH_KABI_RESERVE(n), _new -+#define _RH_KABI_USE2(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE1(__VA_ARGS__) -+#define _RH_KABI_USE3(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE2(__VA_ARGS__) -+#define _RH_KABI_USE4(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE3(__VA_ARGS__) -+#define _RH_KABI_USE5(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE4(__VA_ARGS__) -+#define _RH_KABI_USE6(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE5(__VA_ARGS__) -+#define _RH_KABI_USE7(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE6(__VA_ARGS__) -+#define _RH_KABI_USE8(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE7(__VA_ARGS__) -+#define _RH_KABI_USE9(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE8(__VA_ARGS__) -+#define _RH_KABI_USE10(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE9(__VA_ARGS__) -+#define _RH_KABI_USE11(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE10(__VA_ARGS__) -+#define _RH_KABI_USE12(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE11(__VA_ARGS__) -+ -+#define _RH_KABI_USE(...) _RH_KABI_REPLACE(__VA_ARGS__) -+#define RH_KABI_USE(n, ...) _RH_KABI_USE(__PASTE(_RH_KABI_USE, COUNT_ARGS(__VA_ARGS__))(n, __VA_ARGS__)); -+ -+# define RH_KABI_USE_SPLIT(n, ...) RH_KABI_REPLACE_SPLIT(_RH_KABI_RESERVE(n), __VA_ARGS__) -+ -+# define _RH_KABI_RESERVE(n) unsigned long rh_reserved##n -+ -+#define RH_KABI_EXCLUDE(_elem) _RH_KABI_EXCLUDE(_elem); -+ -+#define RH_KABI_EXCLUDE_WITH_SIZE(_new, _size) \ -+ union { \ -+ RH_KABI_EXCLUDE(_new) \ -+ unsigned long RH_KABI_UNIQUE_ID[_size]; \ -+ __RH_KABI_CHECK_SIZE(_new, 8 * (_size)) \ -+ }; -+ -+#define RH_KABI_EXTEND_WITH_SIZE(_new, _size) \ -+ RH_KABI_EXTEND(union { \ -+ _new; \ -+ unsigned long RH_KABI_UNIQUE_ID[_size]; \ -+ __RH_KABI_CHECK_SIZE(_new, 8 * (_size)) \ -+ }) -+ -+#define _RH_KABI_AUX_PTR(_struct) \ -+ size_t _struct##_size_rh; \ -+ _RH_KABI_EXCLUDE(struct _struct##_rh *_rh) -+#define RH_KABI_AUX_PTR(_struct) \ -+ _RH_KABI_AUX_PTR(_struct); -+ -+#define _RH_KABI_AUX_EMBED(_struct) \ -+ size_t _struct##_size_rh; \ -+ _RH_KABI_EXCLUDE(struct _struct##_rh _rh) -+#define RH_KABI_AUX_EMBED(_struct) \ -+ _RH_KABI_AUX_EMBED(_struct); -+ -+#define RH_KABI_USE_AUX_PTR(n1, n2, _struct) \ -+ RH_KABI_USE(n1, n2, \ -+ struct { RH_KABI_AUX_PTR(_struct) }) -+ -+#define RH_KABI_AUX_SET_SIZE(_name, _struct) ({ \ -+ (_name)->_struct##_size_rh = sizeof(struct _struct##_rh); \ -+}) -+ -+#define RH_KABI_AUX_INIT_SIZE(_struct) \ -+ ._struct##_size_rh = sizeof(struct _struct##_rh), -+ -+#define RH_KABI_AUX(_ptr, _struct, _field) ({ \ -+ size_t __off = offsetof(struct _struct##_rh, _field); \ -+ (_ptr)->_struct##_size_rh > __off ? true : false; \ -+}) -+ -+#endif /* _LINUX_RH_KABI_H */ -diff --git a/include/linux/rh_waived.h b/include/linux/rh_waived.h -new file mode 100644 -index 000000000000..d62a9e896b5e ---- /dev/null -+++ b/include/linux/rh_waived.h -@@ -0,0 +1,19 @@ -+/* SPDX-License-Identifier: GPL-2.0 */ -+/* -+ * include/linux/rh_waived.h -+ * -+ * rh_waived cmdline parameter interface. -+ * -+ * Copyright (C) 2024, Red Hat, Inc. Ricardo Robaina -+ */ -+#ifndef _RH_WAIVED_H -+#define _RH_WAIVED_H -+ -+enum rh_waived_items { -+ /* RH_WAIVED_ITEMS must always be the last item in the enum */ -+ RH_WAIVED_ITEMS, -+}; -+ -+bool is_rh_waived(enum rh_waived_items feat); -+ -+#endif /* _RH_WAIVED_H */ diff --git a/include/linux/rmi.h b/include/linux/rmi.h index ab7eea01ab42..fff7c5f737fc 100644 --- a/include/linux/rmi.h @@ -3164,161 +1363,6 @@ index 83a646d72f6f..65b72854a046 100644 +#endif /* CONFIG_SECURITY_LOCKDOWN_LSM */ + #endif /* ! __LINUX_SECURITY_H */ -diff --git a/init/main.c b/init/main.c -index b84818ad9685..cfd0ae9a8b2b 100644 ---- a/init/main.c -+++ b/init/main.c -@@ -1267,8 +1267,10 @@ static bool __init_or_module initcall_blacklisted(initcall_t fn) - char fn_name[KSYM_SYMBOL_LEN]; - unsigned long addr; - -+#ifndef CONFIG_RHEL_DIFFERENCES - if (list_empty(&blacklisted_initcalls)) - return false; -+#endif - - addr = (unsigned long) dereference_function_descriptor(fn); - sprint_symbol_no_offset(fn_name, addr); -@@ -1279,6 +1281,9 @@ static bool __init_or_module initcall_blacklisted(initcall_t fn) - */ - strreplace(fn_name, ' ', '\0'); - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ init_rh_check_status(fn_name); -+#endif - list_for_each_entry(entry, &blacklisted_initcalls, next) { - if (!strcmp(fn_name, entry->buf)) { - pr_debug("initcall %s blacklisted\n", fn_name); -diff --git a/kernel/Makefile b/kernel/Makefile -index e83669841b8c..8ae573420fdb 100644 ---- a/kernel/Makefile -+++ b/kernel/Makefile -@@ -12,6 +12,8 @@ obj-y = fork.o exec_domain.o panic.o \ - notifier.o ksysfs.o cred.o reboot.o \ - async.o range.o smpboot.o ucount.o regset.o ksyms_common.o - -+obj-$(CONFIG_RHEL_DIFFERENCES) += rh_messages.o rh_flags.o rh_waived.o -+obj-$(CONFIG_USERMODE_DRIVER) += usermode_driver.o - obj-$(CONFIG_MULTIUSER) += groups.o - obj-$(CONFIG_VHOST_TASK) += vhost_task.o - -diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c -index 1b9b18e5b03c..475b9cd8641d 100644 ---- a/kernel/bpf/core.c -+++ b/kernel/bpf/core.c -@@ -543,7 +543,12 @@ void bpf_prog_kallsyms_del_all(struct bpf_prog *fp) - /* All BPF JIT sysctl knobs here. */ - int bpf_jit_enable __read_mostly = IS_BUILTIN(CONFIG_BPF_JIT_DEFAULT_ON); - int bpf_jit_kallsyms __read_mostly = IS_BUILTIN(CONFIG_BPF_JIT_DEFAULT_ON); -+#ifdef CONFIG_RHEL_DIFFERENCES -+/* RHEL-only: set it to 1 by default */ -+int bpf_jit_harden __read_mostly = 1; -+#else - int bpf_jit_harden __read_mostly; -+#endif /* CONFIG_RHEL_DIFFERENCES */ - long bpf_jit_limit __read_mostly; - long bpf_jit_limit_max __read_mostly; - -diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c -index 4ff82144f885..839c3ff15a5c 100644 ---- a/kernel/bpf/syscall.c -+++ b/kernel/bpf/syscall.c -@@ -27,6 +27,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -64,6 +65,23 @@ static DEFINE_SPINLOCK(map_idr_lock); - static DEFINE_IDR(link_idr); - static DEFINE_SPINLOCK(link_idr_lock); - -+static int __init unprivileged_bpf_setup(char *str) -+{ -+ unsigned long disabled; -+ if (!kstrtoul(str, 0, &disabled)) -+ sysctl_unprivileged_bpf_disabled = !!disabled; -+ -+ if (!sysctl_unprivileged_bpf_disabled) { -+ pr_warn("Unprivileged BPF has been enabled " -+ "(unprivileged_bpf_disabled=0 has been supplied " -+ "in boot parameters), tainting the kernel"); -+ add_taint(TAINT_UNPRIVILEGED_BPF, LOCKDEP_STILL_OK); -+ } -+ -+ return 1; -+} -+__setup("unprivileged_bpf_disabled=", unprivileged_bpf_setup); -+ - int sysctl_unprivileged_bpf_disabled __read_mostly = - IS_BUILTIN(CONFIG_BPF_UNPRIV_DEFAULT_OFF) ? 2 : 0; - -@@ -6492,6 +6510,11 @@ static int bpf_unpriv_handler(const struct ctl_table *table, int write, - if (write && !ret) { - if (locked_state && unpriv_enable != 1) - return -EPERM; -+ if (!unpriv_enable) { -+ pr_warn("Unprivileged BPF has been enabled, " -+ "tainting the kernel"); -+ add_taint(TAINT_UNPRIVILEGED_BPF, LOCKDEP_STILL_OK); -+ } - *(int *)table->data = unpriv_enable; - } - -diff --git a/kernel/module/main.c b/kernel/module/main.c -index 710ee30b3bea..3a43d9d322e7 100644 ---- a/kernel/module/main.c -+++ b/kernel/module/main.c -@@ -65,6 +65,8 @@ - #define CREATE_TRACE_POINTS - #include - -+#include -+ - /* - * Mutex protects: - * 1) List of modules (also safely readable within RCU read section), -@@ -606,6 +608,7 @@ static const struct module_attribute modinfo_##field = { \ - - MODINFO_ATTR(version); - MODINFO_ATTR(srcversion); -+MODINFO_ATTR(rhelversion); - - static struct { - char name[MODULE_NAME_LEN]; -@@ -1058,6 +1061,7 @@ const struct module_attribute *const modinfo_attrs[] = { - &module_uevent, - &modinfo_version, - &modinfo_srcversion, -+ &modinfo_rhelversion, - &modinfo_initstate, - &modinfo_coresize, - #ifdef CONFIG_ARCH_WANTS_MODULES_DATA_IN_VMALLOC -@@ -3325,6 +3329,11 @@ static int early_mod_check(struct load_info *info, int flags) - return -EPERM; - } - -+#ifdef CONFIG_RHEL_DIFFERENCES -+ if (get_modinfo(info, "intree")) -+ module_rh_check_status(info->name); -+#endif -+ - err = rewrite_section_headers(info, flags); - if (err) - return err; -@@ -3909,6 +3918,10 @@ void print_modules(void) - pr_cont(" [last unloaded: %s%s]", last_unloaded_module.name, - last_unloaded_module.taints); - pr_cont("\n"); -+ -+#ifdef CONFIG_RHEL_DIFFERENCES -+ rh_print_flags(); -+#endif - } - - #ifdef CONFIG_MODULE_DEBUGFS diff --git a/kernel/module/signing.c b/kernel/module/signing.c index a2ff4242e623..f0d2be1ee4f1 100644 --- a/kernel/module/signing.c @@ -3342,1064 +1386,6 @@ index a2ff4242e623..f0d2be1ee4f1 100644 } int module_sig_check(struct load_info *info, int flags) -diff --git a/kernel/panic.c b/kernel/panic.c -index 0c20fcaae98a..60d48ec1fadd 100644 ---- a/kernel/panic.c -+++ b/kernel/panic.c -@@ -663,6 +663,18 @@ const struct taint_flag taint_flags[TAINT_FLAGS_COUNT] = { - TAINT_FLAG(RANDSTRUCT, 'T', ' '), - TAINT_FLAG(TEST, 'N', ' '), - TAINT_FLAG(FWCTL, 'J', ' '), -+ TAINT_FLAG(20, '?', '-'), -+ TAINT_FLAG(21, '?', '-'), -+ TAINT_FLAG(22, '?', '-'), -+ TAINT_FLAG(23, '?', '-'), -+ TAINT_FLAG(24, '?', '-'), -+ TAINT_FLAG(25, '?', '-'), -+ TAINT_FLAG(PARTNER_SUPPORTED, 'p', ' '), -+ TAINT_FLAG(SUPPORT_REMOVED, 'h', ' '), -+ TAINT_FLAG(RESERVED28, '?', '-'), -+ TAINT_FLAG(RESERVED29, '?', '-'), -+ TAINT_FLAG(RESERVED30, '?', '-'), -+ TAINT_FLAG(UNPRIVILEGED_BPF, 'u', ' '), - }; - - #undef TAINT_FLAG -diff --git a/kernel/rh_flags.c b/kernel/rh_flags.c -new file mode 100644 -index 000000000000..10d26958f840 ---- /dev/null -+++ b/kernel/rh_flags.c -@@ -0,0 +1,115 @@ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#define RH_FLAG_NAME_LEN 32 -+#define MAX_RH_FLAGS 128 -+#define MAX_RH_FLAG_NAME_LEN (MAX_RH_FLAGS * RH_FLAG_NAME_LEN) -+ -+struct rh_flag { -+ struct list_head list; -+ char name[RH_FLAG_NAME_LEN]; -+}; -+ -+static LIST_HEAD(rh_flag_list); -+static DEFINE_SPINLOCK(rh_flag_lock); -+ -+bool __rh_add_flag(const char *flag_name) -+{ -+ struct rh_flag *feat, *iter; -+ -+ BUG_ON(in_interrupt()); -+ feat = kzalloc(sizeof(*feat), GFP_ATOMIC); -+ if (WARN(!feat, "Adding Red Hat flag %s.\n", flag_name)) -+ return false; -+ strscpy(feat->name, flag_name, RH_FLAG_NAME_LEN); -+ -+ spin_lock(&rh_flag_lock); -+ list_for_each_entry_rcu(iter, &rh_flag_list, list) { -+ if (!strcmp(iter->name, flag_name)) { -+ kfree(feat); -+ feat = NULL; -+ break; -+ } -+ } -+ if (feat) -+ list_add_rcu(&feat->list, &rh_flag_list); -+ spin_unlock(&rh_flag_lock); -+ -+ if (feat) -+ pr_info("Adding Red Hat flag %s.\n", flag_name); -+ return true; -+} -+EXPORT_SYMBOL(__rh_add_flag); -+ -+void rh_print_flags(void) -+{ -+ struct rh_flag *feat; -+ -+ /* -+ * This function cannot do any locking, we're oopsing. Traversing -+ * rh_flag_list is okay, though, even without the rcu_read_lock -+ * taken: we never delete from that list and thus don't need the -+ * delayed free. All we need are the smp barriers invoked by the rcu -+ * list manipulation routines. -+ */ -+ if (list_empty(&rh_flag_list)) -+ return; -+ printk(KERN_DEFAULT "Red Hat flags:"); -+ list_for_each_entry_lockless(feat, &rh_flag_list, list) { -+ pr_cont(" %s", feat->name); -+ } -+ pr_cont("\n"); -+} -+EXPORT_SYMBOL(rh_print_flags); -+ -+#ifdef CONFIG_SYSCTL -+static int rh_flags_show(const struct ctl_table *ctl, int write, -+ void __user *buffer, size_t *lenp, -+ loff_t *ppos) -+{ -+ struct ctl_table tbl = { .maxlen = MAX_RH_FLAG_NAME_LEN, }; -+ struct rh_flag *feat; -+ size_t offs = 0; -+ int ret; -+ -+ tbl.data = kmalloc(tbl.maxlen, GFP_KERNEL); -+ if (!tbl.data) -+ return -ENOMEM; -+ ((char *)tbl.data)[0] = '\0'; -+ -+ rcu_read_lock(); -+ list_for_each_entry_rcu(feat, &rh_flag_list, list) { -+ offs += scnprintf(tbl.data + offs, tbl.maxlen - offs, "%s%s", -+ offs == 0 ? "" : " ", feat->name); -+ } -+ rcu_read_unlock(); -+ -+ ret = proc_dostring(&tbl, write, buffer, lenp, ppos); -+ kfree(tbl.data); -+ return ret; -+} -+ -+static struct ctl_table rh_flags_table[] = { -+ { -+ .procname = "rh_flags", -+ .data = &rh_flag_list, -+ .maxlen = MAX_RH_FLAG_NAME_LEN, -+ .mode = 0444, -+ .proc_handler = rh_flags_show, -+ }, -+}; -+#endif -+ -+static __init int rh_flags_init(void) -+{ -+#ifdef CONFIG_SYSCTL -+ register_sysctl_init("kernel", rh_flags_table); -+#endif -+ return 0; -+} -+subsys_initcall(rh_flags_init); -diff --git a/kernel/rh_messages.c b/kernel/rh_messages.c -new file mode 100644 -index 000000000000..bb69e8965748 ---- /dev/null -+++ b/kernel/rh_messages.c -@@ -0,0 +1,414 @@ -+/* -+ * The following functions are used by Red Hat to indicate to users that -+ * hardware and drivers are unsupported, or have limited support in RHEL major -+ * and minor releases. These functions output loud warning messages to the end -+ * user and should be USED WITH CAUTION. -+ * -+ * Any use of these functions _MUST_ be documented in the RHEL Release Notes, -+ * and have approval of management. -+ * -+ * Generally, the process of disabling a driver or device in RHEL requires the -+ * driver or device to be marked as 'deprecated' in all existing releases, and -+ * then either 'unmaintained' or 'disabled' in a future release. -+ * -+ * In general, deprecated and unmaintained drivers continue to receive security -+ * related fixes until they are disabled. -+ */ -+ -+#include -+#include -+#include -+#include "rh_messages.h" -+ -+/** -+ * mark_hardware_unmaintained() - Mark hardware as unmaintained. -+ * @driver_name: driver name -+ * @fmt: format for device description -+ * @...: args for device description -+ * -+ * Called to notify users that the device will no longer be tested on a routine -+ * basis and driver code associated with this device is no longer being updated. -+ * Red Hat may, at their own discretion, fix security-related and critical -+ * issues. Support for this device will be disabled in a future major release -+ * and users deploying this device should plan to replace the device in -+ * production systems. -+ * -+ * This function should be used when the driver's usage can be tied to a -+ * specific hardware device. For example, a network device driver loading on a -+ * specific device that is no longer maintained by the manufacturer. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused mark_hardware_unmaintained(const char *driver_name, char *fmt, ...) -+{ -+ char device_description[DEV_DESC_LEN]; -+ va_list args; -+ -+ va_start(args, fmt); -+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args); -+ pr_crit(RH_UNMAINT_HW, -+ driver_name, device_description); -+ va_end(args); -+} -+EXPORT_SYMBOL(mark_hardware_unmaintained); -+ -+/** -+ * mark_hardware_deprecated() - Mark hardware as deprecated. -+ * @driver_name: driver name -+ * @fmt: format for device description -+ * @...: args for device description -+ * -+ * Called to notify users that support for the device is planned to be -+ * unmaintained in a future major release, and will eventually be disabled in a -+ * future major release. This device should not be used in new production -+ * environments and users should replace the device in production systems. -+ * -+ * This function should be used when the driver's usage can be tied to a -+ * specific hardware device. For example, a network device driver loading on a -+ * specific device that is no longer maintained by the manufacturer. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused mark_hardware_deprecated(const char *driver_name, char *fmt, ...) -+{ -+ char device_description[DEV_DESC_LEN]; -+ va_list args; -+ -+ va_start(args, fmt); -+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args); -+ pr_crit(RH_DEPRECATED_HW, -+ driver_name, device_description); -+ va_end(args); -+} -+ -+/** -+ * mark_hardware_disabled() - Mark a driver as removed. -+ * @driver_name: driver name -+ * @fmt: format for device description -+ * @...: args for device description -+ * -+ * Called to notify users that a device's support has been completely disabled -+ * and no future support updates will occur. This device cannot be used in new -+ * production environments, and users must replace the device in production -+ * systems. -+ * -+ * This function should be used when the driver's usage can be tied to a -+ * specific hardware device. For example, a network device driver loading on a -+ * specific device that is no longer maintained by the manufacturer. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void __maybe_unused mark_hardware_disabled(const char *driver_name, char *fmt, ...) -+{ -+ char device_description[DEV_DESC_LEN]; -+ va_list args; -+ -+ va_start(args, fmt); -+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args); -+ pr_crit(RH_DISABLED_HW, -+ driver_name, device_description); -+ va_end(args); -+} -+ -+#ifdef CONFIG_PCI -+/** -+ * pci_hw_deprecated() - Mark a PCI device deprecated. -+ * @dev: the PCI device structure to match against -+ * -+ * Called to check if this @dev is in the list of deprecated devices. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void __maybe_unused pci_hw_deprecated(struct pci_dev *dev) -+{ -+ const struct pci_device_id *ret = pci_match_id(rh_deprecated_pci_devices, dev); -+ -+ if (!ret) -+ return; -+ -+ mark_hardware_deprecated(dev_driver_string(&dev->dev), "%04X:%04X @ %s", -+ dev->device, dev->vendor, pci_name(dev)); -+} -+ -+/** -+ * pci_hw_unmaintained() - Mark a PCI device unmaintained. -+ * @dev: the PCI device structure to match against -+ * -+ * Called to check if this @dev is in the list of unmaintained devices. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void pci_hw_unmaintained(struct pci_dev *dev) -+{ -+ const struct pci_device_id *ret = pci_match_id(rh_unmaintained_pci_devices, dev); -+ -+ if (!ret) -+ return; -+ -+ mark_hardware_unmaintained(dev_driver_string(&dev->dev), "%04X:%04X @ %s", -+ dev->device, dev->vendor, pci_name(dev)); -+} -+ -+/** -+ * pci_hw_disabled() - Mark a PCI device disabled. -+ * @dev: the PCI device structure to match against -+ * -+ * Called to check if this @dev is in the list of disabled devices. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static bool __maybe_unused pci_hw_disabled(struct pci_dev *dev) -+{ -+ const struct pci_device_id *ret = pci_match_id(rh_disabled_pci_devices, dev); -+ -+ if (!ret) -+ return false; -+ -+ mark_hardware_disabled(dev_driver_string(&dev->dev), "%04X:%04X @ %s", -+ dev->device, dev->vendor, pci_name(dev)); -+ return true; -+} -+#endif -+ -+/** -+ * driver_unmaintained() - check to see if a driver is unmaintained -+ * @module_name: module name -+ * -+ * Called to notify users that a driver will no longer be tested on a routine -+ * basis and the driver code is no longer being updated. Red Hat may fix -+ * security-related and critical issues. Support for this driver will be -+ * disabled in a future major release, and users should replace any affected -+ * devices in production systems. -+ * -+ * This function should be used when a driver's usage cannot be tied to a -+ * specific hardware device. For example, a network bonding driver or a higher -+ * level storage layer driver that is no longer maintained upstream. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void __maybe_unused driver_unmaintained(const char* module_name) -+{ -+ int i = 0; -+ -+ while (rh_unmaintained_drivers[i]) { -+ if (strcmp(rh_unmaintained_drivers[i], module_name) == 0) { -+ pr_crit(RH_UNMAINT_DR, module_name); -+ return; -+ } -+ i++; -+ } -+} -+ -+/** -+ * driver_deprecated() - check to see if a driver is deprecated -+ * @driver_name: module name -+ * -+ * Called to notify users that support for this driver is planned to be -+ * unmaintained in a future major release, and will eventually be disabled in a -+ * future major release. This driver should not be used in new production -+ * environments and users should replace any affected devices in production -+ * systems. -+ * -+ * This function should be used when a driver's usage cannot be tied to a -+ * specific hardware device. For example, a network bonding driver or a higher -+ * level storage layer driver that is no longer maintained upstream. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void __maybe_unused driver_deprecated(const char* module_name) -+{ -+ int i = 0; -+ -+ while (rh_deprecated_drivers[i]) { -+ if (strcmp(rh_deprecated_drivers[i], module_name) == 0) { -+ pr_crit(RH_DEPRECATED_DR, module_name); -+ return; -+ } -+ i++; -+ } -+} -+ -+/* There is no driver_disabled() function. Disabled drivers are configured off ;). */ -+ -+/** -+ * init_fn_unmaintained - check to see if a built-in driver is unmaintained. -+ * @fn_name: module's module_init function name -+ * -+ * Called to notify users that a built-in driver will no longer be tested on a routine -+ * basis and the built-in driver code is no longer being updated. Red Hat may fix -+ * security-related and critical issues. Support for this built-in driver will be -+ * disabled in a future major release, and users should replace any affected -+ * devices in production systems. -+ * -+ * This function should be used when a built-in driver's usage cannot be tied to a -+ * specific hardware device. For example, a network bonding driver or a higher -+ * level storage layer driver that is no longer maintained upstream. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+ -+static void __maybe_unused init_fn_unmaintained(char* fn_name) -+{ -+ int i = 0; -+ -+ while (rh_unmaintained_init_fns[i]) { -+ if (strcmp(rh_unmaintained_init_fns[i], fn_name) == 0) { -+ pr_crit(RH_UNMAINT_DR, fn_name); -+ return; -+ } -+ i++; -+ } -+} -+ -+/** -+ * init_fn_deprecated() - check to see if a built-in driver is deprecated -+ * @fn_name: module's module_init function name -+ * -+ * Called to notify users that support for this built-in driver is planned to be -+ * unmaintained in a future major release, and will eventually be disabled in a -+ * future major release. This driver should not be used in new production -+ * environments and users should replace any affected devices in production -+ * systems. -+ * -+ * This function should be used when a built-in driver's usage cannot be tied to a -+ * specific hardware device. For example, a network bonding driver or a higher -+ * level storage layer driver that is no longer maintained upstream. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+static void __maybe_unused init_fn_deprecated(char* fn_name) -+{ -+ int i = 0; -+ -+ while (rh_deprecated_init_fns[i]) { -+ if (strcmp(rh_deprecated_init_fns[i], fn_name) == 0) { -+ pr_crit(RH_DEPRECATED_DR, fn_name); -+ return; -+ } -+ i++; -+ } -+} -+ -+/** -+ * mark_tech_preview() - Mark driver or kernel subsystem as 'Tech Preview' -+ * @msg: Driver or kernel subsystem name -+ * -+ * Called to minimize the support status of a new driver. This does TAINT the -+ * kernel. Calling this function indicates that the driver or subsystem has -+ * had limited testing and is not marked for full support within this RHEL -+ * minor release. The next RHEL minor release may contain full support for -+ * this driver. Red Hat does not guarantee that bugs reported against this -+ * driver or subsystem will be resolved. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused mark_tech_preview(const char *msg, struct module *mod) -+{ -+ const char *str = NULL; -+ -+ if (msg) -+ str = msg; -+#ifdef CONFIG_MODULES -+ else if (mod) -+ str = mod->name; -+#endif -+ -+ pr_warn(RH_TECH_PREVIEW, (str ? str : "kernel")); -+ add_taint(TAINT_AUX, LOCKDEP_STILL_OK); -+#ifdef CONFIG_MODULES -+ if (mod) -+ mod->taints |= (1U << TAINT_AUX); -+#endif -+} -+EXPORT_SYMBOL(mark_tech_preview); -+ -+/** -+ * mark_partner_supported() - Mark driver or kernel subsystem as 'Partner Supported' -+ * @msg: Driver or kernel subsystem name -+ * -+ * Called to minimize the support status of a new driver. This does TAINT the -+ * kernel. Calling this function indicates that the driver or subsystem -+ * is not supported directly by Red Hat but by a partner engineer. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused mark_partner_supported(const char *msg, struct module *mod) -+{ -+ const char *str = NULL; -+ -+ if (msg) -+ str = msg; -+#ifdef CONFIG_MODULES -+ else if (mod) -+ str = mod->name; -+#endif -+ -+ pr_warn(RH_PARTNER_SUPPORTED, (str ? str : "kernel")); -+ add_taint(TAINT_PARTNER_SUPPORTED, LOCKDEP_STILL_OK); -+#ifdef CONFIG_MODULES -+ if (mod) -+ mod->taints |= (1U << TAINT_PARTNER_SUPPORTED); -+#endif -+} -+EXPORT_SYMBOL(mark_partner_supported); -+ -+/* -+ * -+ * Functions called by 'main' kernel code. -+ * -+ */ -+ -+#ifdef CONFIG_PCI -+/** -+ * pci_rh_check_status - checks the status of a PCI device. -+ * @pci_dev: PCI device to be examined -+ * -+ * This function is called by the PCI driver subsystem to check the status of a -+ * PCI device. -+ * -+ * This function returns true if the PCI device is disabled, and false otherwise. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+bool __maybe_unused pci_rh_check_status(struct pci_dev *pci_dev) -+{ -+ if (pci_dev->driver->driver.owner != NULL) { -+ if (!test_bit(TAINT_OOT_MODULE, &pci_dev->driver->driver.owner->taints)) { -+ pci_hw_unmaintained(pci_dev); -+ pci_hw_deprecated(pci_dev); -+ return pci_hw_disabled(pci_dev); -+ } -+ } -+ return false; -+} -+#endif -+ -+/** module_rh_check_status - checks the status of a module. -+ * @module_name: Name of module to be examined -+ * -+ * This function is called by the module loading code to check the status of a -+ * module. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused module_rh_check_status(const char * module_name) -+{ -+ driver_unmaintained(module_name); -+ driver_deprecated(module_name); -+} -+ -+/** -+ * init_rh_check_status - checks the status of a built-in module. -+ * @fn_name: init function of module to be examined -+ * -+ * This function is called by the init code to check the status of a built-in module. -+ * When a module is built-in, the module_init() function is converted into an initcall. -+ * The initcall is the called during boot with the other system initcalls. -+ * -+ * Reserved for Internal Red Hat use only. -+ */ -+void __maybe_unused init_rh_check_status(char *fn_name) -+{ -+ init_fn_deprecated(fn_name); -+ init_fn_unmaintained(fn_name); -+} -diff --git a/kernel/rh_messages.h b/kernel/rh_messages.h -new file mode 100644 -index 000000000000..05ad12af6a6d ---- /dev/null -+++ b/kernel/rh_messages.h -@@ -0,0 +1,335 @@ -+/* -+ * WARNING: This file is auto-generated by an internal Red Hat script and, -+ * in general, should not be modified by hand. -+ * See: https://gitlab.com/redhat/rhel/src/kernel/hardware-removal-support -+ */ -+ -+/* -+ * The following tables are used by Red Hat to define what hardware and drivers -+ * are unsupported, or have limited support in RHEL major and minor releases. -+ * -+ * Generally, the process of disabling a driver or device in RHEL requires the -+ * driver or device to be marked as 'deprecated' in all existing releases, and -+ * then either 'unmaintained' or 'disabled' in a future release. -+ * -+ * In general, deprecated and unmaintained drivers continue to receive security -+ * related fixes until they are disabled. -+ */ -+ -+#ifndef __RH_MESSAGES_H -+#define __RH_MESSAGES_H -+ -+#include -+#include -+ -+#define DEV_DESC_LEN 256 -+ -+#define RH_UNMAINT_HW "Warning: Unmaintained Hardware is detected: %s:%s\n" -+ -+#define RH_UNMAINT_DR "Warning: Unmaintained driver is detected: %s\n" -+ -+#define RH_DEPRECATED_HW "Warning: Deprecated Hardware is detected: %s:%s " \ -+ "will not be maintained in a future major release " \ -+ "and may be disabled\n" -+ -+#define RH_DEPRECATED_DR "Warning: Deprecated Driver is detected: %s will " \ -+ "not be maintained in a future major release and " \ -+ "may be disabled\n" -+ -+#define RH_DISABLED_HW "Warning: Disabled Hardware is detected: %s:%s is " \ -+ "no longer enabled in this release.\n" -+ -+#define RH_TECH_PREVIEW "TECH PREVIEW: %s may not be fully supported.\n" \ -+ "Please review provided documentation for " \ -+ "limitations.\n" -+ -+#define RH_PARTNER_SUPPORTED "Warning: %s is a Partner supported GPL " \ -+ "module and not supported directly by Red Hat.\n" -+ -+static const char *rh_deprecated_drivers[] = { -+ 0 /* Terminating entry */ -+}; -+ -+static const char *rh_deprecated_init_fns[] = { -+ 0 /* Terminating entry */ -+}; -+ -+static const char *rh_unmaintained_drivers[] = { -+ "aacraid", -+ "af_key", -+ "ahci_seattle", -+ "ahci_xgene", -+ "arp_tables", -+ "bnx2", -+ "bnx2fc", -+ "bnx2i", -+ "bnx2x", -+ "cnic", -+ "dl2k", -+ "e1000", -+ "ebtables", -+ "hdlc_fr", -+ "hisi_sas_main", -+ "hpsa", -+ "ip6_tables", -+ "ip_set", -+ "ip_tables", -+ "mptbase", -+ "mptsas", -+ "mptscsih", -+ "mptspi", -+ "myri10ge", -+ "netxen_nic", -+ "nft_compat", -+ "nicpf", -+ "nicvf", -+ "nvmet_fc", -+ "nvmet_tcp", -+ "team", -+ 0 /* Terminating entry */ -+}; -+ -+static const char *rh_unmaintained_init_fns[] = { -+ "bnx2_pci_driver_init", -+ "e1000_init_module", -+ "rio_driver_init", -+ "hpsa_init", -+ "fusion_init", -+ "mptsas_init", -+ "fusion_init", -+ "mptspi_init", -+ "myri10ge_init_module", -+ "netxen_init_module", -+ "hdlc_fr_init", -+ "nvmet_fc_init_module", -+ "nvmet_tcp_init", -+ "team_module_init", -+ "ebtables_init", -+ "arp_tables_init", -+ "ip_tables_init", -+ "ip6_tables_init", -+ "ip_set_init", -+ "nft_compat_module_init", -+ "nicvf_init_module", -+ "nic_init_module", -+ "ipsec_pfkey_init", -+ "aac_init", -+ "cnic_init", -+ "bnx2x_init", -+ "bnx2fc_mod_init", -+ "bnx2i_mod_init", -+ "ahci_seattle_probe", -+ "xgene_ahci_probe", -+ "hisi_sas_init", -+ 0 /* Terminating entry */ -+}; -+ -+static const struct pci_device_id rh_deprecated_pci_devices[] = { -+ {0} /* Terminating entry */ -+}; -+ -+static const struct pci_device_id rh_disabled_pci_devices[] = { -+ { 0x1011, 0x0046, 0x103c, 0x10c2 }, -+ { 0x1011, 0x0046, 0x9005, 0x0364 }, -+ { 0x1011, 0x0046, 0x9005, 0x0365 }, -+ { 0x1011, 0x0046, 0x9005, 0x1364 }, -+ { 0x1028, 0x0001, 0x1028, 0x0001 }, -+ { 0x1028, 0x0002, 0x1028, 0x0002 }, -+ { 0x1028, 0x0002, 0x1028, 0x00d1 }, -+ { 0x1028, 0x0002, 0x1028, 0x00d9 }, -+ { 0x1028, 0x0003, 0x1028, 0x0003 }, -+ { 0x1028, 0x0004, 0x1028, 0x00d0 }, -+ { 0x1028, 0x000a, 0x1028, 0x0106 }, -+ { 0x1028, 0x000a, 0x1028, 0x011b }, -+ { 0x1028, 0x000a, 0x1028, 0x0121 }, -+ { 0x9005, 0x0200, 0x9005, 0x0200 }, -+ { 0x9005, 0x0283, 0x9005, 0x0283 }, -+ { 0x9005, 0x0284, 0x9005, 0x0284 }, -+ { 0x9005, 0x0285, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x9005, 0x0285, 0x1014, 0x02F2 }, -+ { 0x9005, 0x0285, 0x1014, 0x0312 }, -+ { 0x9005, 0x0285, 0x1028, PCI_ANY_ID }, -+ { 0x9005, 0x0285, 0x1028, 0x0287 }, -+ { 0x9005, 0x0285, 0x1028, 0x0291 }, -+ { 0x9005, 0x0285, 0x103C, 0x3227 }, -+ { 0x9005, 0x0285, 0x17aa, PCI_ANY_ID }, -+ { 0x9005, 0x0285, 0x17aa, 0x0286 }, -+ { 0x9005, 0x0285, 0x17aa, 0x0287 }, -+ { 0x9005, 0x0285, 0x9005, 0x0285 }, -+ { 0x9005, 0x0285, 0x9005, 0x0286 }, -+ { 0x9005, 0x0285, 0x9005, 0x0287 }, -+ { 0x9005, 0x0285, 0x9005, 0x0288 }, -+ { 0x9005, 0x0285, 0x9005, 0x0289 }, -+ { 0x9005, 0x0285, 0x9005, 0x028a }, -+ { 0x9005, 0x0285, 0x9005, 0x028b }, -+ { 0x9005, 0x0285, 0x9005, 0x028e }, -+ { 0x9005, 0x0285, 0x9005, 0x028f }, -+ { 0x9005, 0x0285, 0x9005, 0x0290 }, -+ { 0x9005, 0x0285, 0x9005, 0x0291 }, -+ { 0x9005, 0x0285, 0x9005, 0x0292 }, -+ { 0x9005, 0x0285, 0x9005, 0x0293 }, -+ { 0x9005, 0x0285, 0x9005, 0x0294 }, -+ { 0x9005, 0x0285, 0x9005, 0x0296 }, -+ { 0x9005, 0x0285, 0x9005, 0x0297 }, -+ { 0x9005, 0x0285, 0x9005, 0x0298 }, -+ { 0x9005, 0x0285, 0x9005, 0x0299 }, -+ { 0x9005, 0x0285, 0x9005, 0x029a }, -+ { 0x9005, 0x0285, 0x9005, 0x02a4 }, -+ { 0x9005, 0x0285, 0x9005, 0x02a5 }, -+ { 0x9005, 0x0286, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x9005, 0x0286, 0x1014, 0x9540 }, -+ { 0x9005, 0x0286, 0x1014, 0x9580 }, -+ { 0x9005, 0x0286, 0x9005, 0x028c }, -+ { 0x9005, 0x0286, 0x9005, 0x028d }, -+ { 0x9005, 0x0286, 0x9005, 0x029b }, -+ { 0x9005, 0x0286, 0x9005, 0x029c }, -+ { 0x9005, 0x0286, 0x9005, 0x029d }, -+ { 0x9005, 0x0286, 0x9005, 0x029e }, -+ { 0x9005, 0x0286, 0x9005, 0x029f }, -+ { 0x9005, 0x0286, 0x9005, 0x02a0 }, -+ { 0x9005, 0x0286, 0x9005, 0x02a1 }, -+ { 0x9005, 0x0286, 0x9005, 0x02a2 }, -+ { 0x9005, 0x0286, 0x9005, 0x02a3 }, -+ { 0x9005, 0x0286, 0x9005, 0x02a6 }, -+ { 0x9005, 0x0286, 0x9005, 0x0800 }, -+ { 0x9005, 0x0287, 0x9005, 0x0800 }, -+ { 0x9005, 0x0288, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0222, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0712, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x212, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x702, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x703, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0700, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0211, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0710, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0221, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0xe220, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0x1ae5, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe100, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe131, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe180, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe260, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf095, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf098, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0a1, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0a5, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0d1, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0d5, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0e1, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0e5, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0f5, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0f6, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf0f7, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf180, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf700, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf800, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf900, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf980, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfa00, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfb00, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfc00, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfc10, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfc20, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfc50, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfd00, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfd11, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfd12, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfe00, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfe05, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfe11, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfe12, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0704, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x19a2, 0x0714, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe208, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe268, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0060, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0078, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x007C, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0411, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0413, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1028, 0x0015, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1002, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6340, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x634A, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6354, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6368, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6372, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6732, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x673C, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6746, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6750, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x675A, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x6764, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x676E, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1003, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1004, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1005, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1006, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1007, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1008, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1009, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100a, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100b, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100c, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100d, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100e, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x100f, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1010, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0x1025, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x15B3, 0xA2DF, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0064, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0065, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0070, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0072, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0074, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0076, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0077, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x007E, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x2422, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x2432, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x5422, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x5432, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8001, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8021, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8044, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8432, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0xF000, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8022, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8032, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8042, PCI_ANY_ID, PCI_ANY_ID }, -+ {0} /* Terminating entry */ -+}; -+ -+static const struct pci_device_id rh_unmaintained_pci_devices[] = { -+ { 0x10df, 0xe220, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0x0724, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xe200, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf011, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf015, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xf100, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x10df, 0xfc40, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x005b, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0071, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0073, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0079, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x006E, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0080, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0081, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0082, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0083, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0084, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0085, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0086, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1000, 0x0087, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x177d, 0xa01e, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x177d, 0xa034, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x177d, 0x0011, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x2031, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x2532, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1077, 0x8031, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1924, 0x0803, PCI_ANY_ID, PCI_ANY_ID }, -+ { 0x1924, 0x0813, PCI_ANY_ID, PCI_ANY_ID }, -+ {0} /* Terminating entry */ -+}; -+ -+#endif /* __RH_MESSAGES_H */ -diff --git a/kernel/rh_waived.c b/kernel/rh_waived.c -new file mode 100644 -index 000000000000..20966f7c7277 ---- /dev/null -+++ b/kernel/rh_waived.c -@@ -0,0 +1,147 @@ -+/* SPDX-License-Identifier: GPL-2.0 */ -+/* -+ * kernel/rh_waived.c -+ * -+ * rh_waived cmdline parameter support. -+ * -+ * Copyright (C) 2024, Red Hat, Inc. Ricardo Robaina -+ */ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* -+ * * RH_INSERT_WAIVED_ITEM -+ * This macro is intended to be used to insert items into the -+ * rh_waived_list array. It expects to get an item from -+ * enum rh_waived_items as its first argument, and a string -+ * holding the feature name as its second argument. -+ * -+ * The feature name is also utilized as the token for the -+ * boot parameter parser. -+ * -+ * Example usage: -+ * struct rh_waived_item foo[RH_WAIVED_FEAT_ITEMS] = { -+ * RH_INSERT_WAIVED_ITEM(FOO_FEAT, "foo_feat_short_str", "alias", RH_WAIVED_FEAT), -+ * }; -+ */ -+#define RH_INSERT_WAIVED_ITEM(enum_item, item, item_alt, class) \ -+ [(enum_item)] = { .name = (item), .alias = (item_alt), \ -+ .type = (class), .waived = 0, } -+ -+/* Indicates if the rh_flag 'rh_waived' should be added. */ -+bool __initdata add_rh_flag = false; -+ -+typedef enum { -+ RH_WAIVED_FEAT, -+ RH_WAIVED_CVE, -+ RH_WAIVED_ANY -+} rh_waived_t; -+ -+struct rh_waived_item { -+ char *name, *alias; -+ rh_waived_t type; -+ unsigned int waived; -+ -+}; -+ -+/* Always use the marco RH_INSERT_WAIVED to insert items to this array. */ -+struct rh_waived_item rh_waived_list[RH_WAIVED_ITEMS] = { -+}; -+ -+/* -+ * is_rh_waived() - Checks if a given item has been marked as waived. -+ * -+ * @item: waived item. -+ */ -+__inline__ bool is_rh_waived(enum rh_waived_items item) -+{ -+ return !!rh_waived_list[item].waived; -+} -+EXPORT_SYMBOL(is_rh_waived); -+ -+static void __init rh_waived_parser(char *s, rh_waived_t type) -+{ -+ int i; -+ char *token; -+ -+ pr_info(KERN_CONT "rh_waived: "); -+ -+ if (!s) { -+ for (i = 0; i < RH_WAIVED_ITEMS; i++) { -+ if (type != RH_WAIVED_ANY && rh_waived_list[i].type != type) -+ continue; -+ -+ rh_waived_list[i].waived = 1; -+ pr_info(KERN_CONT "%s%s", rh_waived_list[i].name, -+ i < RH_WAIVED_ITEMS - 1 ? " " : "\n"); -+ } -+ -+ add_rh_flag = true; -+ return; -+ } -+ -+ while ((token = strsep(&s, ",")) != NULL) { -+ for (i = 0; i < RH_WAIVED_ITEMS; i++) { -+ char *alias = rh_waived_list[i].alias; -+ -+ if (type != RH_WAIVED_ANY && rh_waived_list[i].type != type) -+ continue; -+ -+ if (!strcmp(token, rh_waived_list[i].name) || -+ (alias && !strcmp(token, alias))) { -+ rh_waived_list[i].waived = 1; -+ pr_info(KERN_CONT "%s ", rh_waived_list[i].name); -+ } -+ } -+ } -+ -+ pr_info(KERN_CONT "\n"); -+ add_rh_flag = true; -+} -+ -+static int __init rh_waived_setup(char *s) -+{ -+ /* -+ * originally, if no string was passed to the cmdline option -+ * all listed features would be waived, so we keep that same -+ * compromise with the new contract. -+ */ -+ if (!s || !strcmp(s, "features")) { -+ rh_waived_parser(NULL, RH_WAIVED_FEAT); -+ return 0; -+ } -+ -+ /* waive all possible mitigations in the list */ -+ if (!strcmp(s, "cves")) { -+ rh_waived_parser(NULL, RH_WAIVED_CVE); -+ return 0; -+ } -+ -+ /* otherwise, just deal with the enumerated waive list */ -+ rh_waived_parser(s, RH_WAIVED_ANY); -+ -+ return 0; -+} -+early_param("rh_waived", rh_waived_setup); -+ -+/* -+ * rh_flags is initialized at subsys_initcall, calling rh_add_flag() -+ * from rh_waived_setup() would result in a can't boot situation. -+ * Deffering the inclusion 'rh_waived' rh_flag to late_initcall to -+ * avoid this issue. -+ */ -+static int __init __add_rh_flag(void) -+{ -+ if (add_rh_flag) -+ rh_add_flag("rh_waived"); -+ -+ return 0; -+} -+late_initcall(__add_rh_flag); diff --git a/scripts/Makefile.lib b/scripts/Makefile.lib index 28a1c08e3b22..3126a6fa6328 100644 --- a/scripts/Makefile.lib @@ -4415,39 +1401,6 @@ index 28a1c08e3b22..3126a6fa6328 100644 objtool-args = $(objtool-args-y) \ $(if $(delay-objtool), --link) \ -diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c -index 755b842f1f9b..af9188ed4ff0 100644 ---- a/scripts/mod/modpost.c -+++ b/scripts/mod/modpost.c -@@ -27,6 +27,7 @@ - #include - #include "modpost.h" - #include "../../include/linux/license.h" -+#include "../../include/generated/uapi/linux/version.h" - - #define MODULE_NS_PREFIX "module:" - -@@ -2034,6 +2035,12 @@ static void write_buf(struct buffer *b, const char *fname) - } - } - -+static void add_rhelversion(struct buffer *b, struct module *mod) -+{ -+ buf_printf(b, "MODULE_INFO(rhelversion, \"%d.%d\");\n", RHEL_MAJOR, -+ RHEL_MINOR); -+} -+ - static void write_if_changed(struct buffer *b, const char *fname) - { - char *tmp; -@@ -2118,6 +2125,7 @@ static void write_mod_c_file(struct module *mod) - } - - add_srcversion(&buf, mod); -+ add_rhelversion(&buf, mod); - - ret = snprintf(fname, sizeof(fname), "%s.mod.c", mod->name); - if (ret >= sizeof(fname)) { diff --git a/scripts/tags.sh b/scripts/tags.sh index 99ce427d9a69..f191cd9d7ee6 100755 --- a/scripts/tags.sh diff --git a/sources b/sources index a948c1ebc..4692a5291 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ SHA512 (linux-6.19.tar.xz) = 58991ba2c44887efb92b0a2f7194033f25f5204b3f571558f1709f75651d6f0273f6f9e2949a16d6db119259f0733314c827421babb164a851ee3a5b64c7a896 -SHA512 (kernel-abi-stablelists-6.19.0.tar.xz) = 0f7671ff5385175ba09f7d825764cc1dbed9f3688578b004ad4d61ec9c3b6f5a8692f09ece2fe414494b78c20e1d233d1d63d6514d430a63d26f92eeda68b45f -SHA512 (kernel-kabi-dw-6.19.0.tar.xz) = 852786824dbfb83f2875fd0581117d3df749b2b6a1ad013136ec6ec49841ee051090e91303ccc84656bae04448b3ca682c70c4be36e362663530456a55d40447 +SHA512 (kernel-abi-stablelists-6.19.0.tar.xz) = 45ec9e0d7c375e0aaa6ca4017700477eb84bc856171406f18c80fbe129792b2cbb235b4d0e5c00648e54862cf87fc8b788f5fee2773cfea1367791cb2850c90f +SHA512 (kernel-kabi-dw-6.19.0.tar.xz) = c752d4a5ae3e293009a072e5c611f6c87966557511a1ec9a41515a6a49e2b44464cfec7aeb05ad7c57c72f18575a682274047a02b773d5362531ee5c55406d36