public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Justin M. Forbes <jforbes@fedoraproject.org>
To: git-commits@fedoraproject.org
Subject: [rpms/kernel] f45: kernel-7.2.1-300
Date: Thu, 27 Aug 2026 14:03:23 GMT [thread overview]
Message-ID: <178783940375.1.18243205906292501778.rpms-kernel-11f410760345@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : rpms/kernel
Branch : f45
Commit : 11f41076034553eeafbc7dd658b4249c12c854b0
Author : Justin M. Forbes <jforbes@fedoraproject.org>
Date : 2026-08-27T08:00:46-06:00
Stats : +226/-3100 in 45 file(s)
URL : https://src.fedoraproject.org/rpms/kernel/c/11f41076034553eeafbc7dd658b4249c12c854b0?branch=f45
Log:
kernel-7.2.1-300
* Thu Aug 27 2026 Justin M. Forbes <jforbes@fedoraproject.org> [7.2.1-0]
- Initial setup for stable Fedora release (Justin M. Forbes)
- Reset Makefile.rhelver for the 7.3 cycle (Justin M. Forbes)
- Merge configs into common for 7.2 (Justin M. Forbes)
- redhat/configs: automotive: enable RTC_DRV_PL031 (Eric Chanudet)
- redhat: name the dtb and UKI arch lists (Jan Stancek)
- redhat: use one spelling for the nobuildarches files guard (Jan Stancek)
- redhat: drop stale ppc64 from the kabidw-base arch list (Jan Stancek)
- redhat: document the kabichk force-off as a seasonal toggle (Jan Stancek)
- redhat: use one spelling for the include and gemini conditionals (Jan Stancek)
- redhat: remove unused elf_image_install_path and duplicate defines (Jan Stancek)
- redhat: drop the dead kernel-tools __requires_exclude python filter (Jan Stancek)
- redhat: drop the Fedora 41 cross-build gdb-index workaround (Jan Stancek)
- redhat: drop stale build switches from dist-perf and dist-rpm-baseonly (Jan Stancek)
- redhat: give kernel-automotive its own summary (Jan Stancek)
- redhat: drop leftover kernel_kvm_post calls for rt-64k (Jan Stancek)
- redhat: restore missing summary of the kernel-debug variant (Jan Stancek)
- redhat: fix parse error in baseonly sanity check message (Jan Stancek)
- Linux v7.2.1
Resolves:
Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
---
diff --git a/Makefile.rhelver b/Makefile.rhelver
index b9b4f35..95b9fd7 100644
--- a/Makefile.rhelver
+++ b/Makefile.rhelver
@@ -12,7 +12,7 @@ RHEL_MINOR = 99
#
# Use this spot to avoid future merge conflicts.
# Do not trim this comment.
-RHEL_RELEASE = 61
+RHEL_RELEASE = 0
#
# RHEL_REBASE_NUM
diff --git a/Patchlist.changelog b/Patchlist.changelog
index 8c0e973..37e92c5 100644
--- a/Patchlist.changelog
+++ b/Patchlist.changelog
@@ -1,486 +1,147 @@
-https://gitlab.com/cki-project/kernel-ark/-/commit/75c8343f66def9d6ab14cd59f464c872593298df
- 75c8343f66def9d6ab14cd59f464c872593298df Revert "Input: rmi4 - remove the need for artificial IRQ in case of HID"
+https://gitlab.com/cki-project/kernel-ark/-/commit/d088d8766e390303a72e82a86d2970f17e6846df
+ d088d8766e390303a72e82a86d2970f17e6846df redhat: Add DENYLIST.rhel to BPF selftests
-https://gitlab.com/cki-project/kernel-ark/-/commit/91f7589ddc98d53780b37dd67962c9cd62251a61
- 91f7589ddc98d53780b37dd67962c9cd62251a61 Revert "crypto: rng - Override drivers/char/random in FIPS mode"
+https://gitlab.com/cki-project/kernel-ark/-/commit/fed2f9921bcc8274c579cabd6cf57bcd50de047d
+ fed2f9921bcc8274c579cabd6cf57bcd50de047d Fix up rebase typo in drivers/pci/quirks.c
-https://gitlab.com/cki-project/kernel-ark/-/commit/af93b4d81dde5a52f0f86ce435c314e839d03ca5
- af93b4d81dde5a52f0f86ce435c314e839d03ca5 Revert "crypto: rng - Ensure stdrng is tested before user-space starts"
+https://gitlab.com/cki-project/kernel-ark/-/commit/a329f36cee87f3fcdbbc616fde04c5bbe0adfb26
+ a329f36cee87f3fcdbbc616fde04c5bbe0adfb26 efi: Fix swapped arguments to bsearch() in efi_status_to_*()
-https://gitlab.com/cki-project/kernel-ark/-/commit/aac5dfb97c234c4993a61b1e4cbd4ddb3a32b670
- aac5dfb97c234c4993a61b1e4cbd4ddb3a32b670 Revert "crypto: rng - Fix extrng EFAULT handling"
+https://gitlab.com/cki-project/kernel-ark/-/commit/65dca4201450be071fee7b4cd7ab2320e7bb1885
+ 65dca4201450be071fee7b4cd7ab2320e7bb1885 arm64: add early lockdown for secure boot
-https://gitlab.com/cki-project/kernel-ark/-/commit/717a71346af8ef0d53803599f4c76c43fd765fc3
- 717a71346af8ef0d53803599f4c76c43fd765fc3 Revert "Correct manual merge error in crypto/rng.c"
+https://gitlab.com/cki-project/kernel-ark/-/commit/70c2cc6755d54b9a9de77d14818f48d49401c404
+ 70c2cc6755d54b9a9de77d14818f48d49401c404 efi: pass secure boot mode to kernel proper
-https://gitlab.com/cki-project/kernel-ark/-/commit/ecc4e2a675b8259cc3a3f6afe08500c4c869eab4
- ecc4e2a675b8259cc3a3f6afe08500c4c869eab4 Revert "Fix up rebase issues with rng.c"
+https://gitlab.com/cki-project/kernel-ark/-/commit/0dbdb3f2b9a360f64bcc0736afcf58f830e68502
+ 0dbdb3f2b9a360f64bcc0736afcf58f830e68502 selftests/bpf: Remove ksyms_weak_lskel test
-https://gitlab.com/cki-project/kernel-ark/-/commit/ab9708d7c63369e49e0ffd0464443daf99778244
- ab9708d7c63369e49e0ffd0464443daf99778244 [redhat] drivers/scsi/sd.c: cleanup
+https://gitlab.com/cki-project/kernel-ark/-/commit/9dc8564d74c9bc7cd5eb634113c5b64c0a77d266
+ 9dc8564d74c9bc7cd5eb634113c5b64c0a77d266 Simplify include Makefile.rhelver
-https://gitlab.com/cki-project/kernel-ark/-/commit/2a8b73b44a1e17a51a654d0c984218358a816676
- 2a8b73b44a1e17a51a654d0c984218358a816676 Fix up rebase issues with rng.c
+https://gitlab.com/cki-project/kernel-ark/-/commit/a4a2f9f9e5061c723d24f419b70d2d89840e6d3a
+ a4a2f9f9e5061c723d24f419b70d2d89840e6d3a redhat: make ENABLE_WERROR also enable OBJTOOL_WERROR
-https://gitlab.com/cki-project/kernel-ark/-/commit/512eedc648e4fd3811c82b15c07dc622e4ceea6c
- 512eedc648e4fd3811c82b15c07dc622e4ceea6c redhat: rh_flags: mark !CONFIG_RHEL_DIFFERENCES stubs as static inline
+https://gitlab.com/cki-project/kernel-ark/-/commit/f49e14c2d5fc176eacc7f7911565a67f47aa2c71
+ f49e14c2d5fc176eacc7f7911565a67f47aa2c71 efi,lockdown: fix kernel lockdown on Secure Boot
-https://gitlab.com/cki-project/kernel-ark/-/commit/5f3a5f448b3c1cf35c6c9d3d182ac0df005200a9
- 5f3a5f448b3c1cf35c6c9d3d182ac0df005200a9 redhat: Add DENYLIST.rhel to BPF selftests
+https://gitlab.com/cki-project/kernel-ark/-/commit/40f0fa70effc108f71e4745f132c58034f6473ec
+ 40f0fa70effc108f71e4745f132c58034f6473ec redhat: fix modules.order target
-https://gitlab.com/cki-project/kernel-ark/-/commit/da90cfd07d2ffaa185b44af5579e21d716d44c46
- da90cfd07d2ffaa185b44af5579e21d716d44c46 Correct manual merge error in crypto/rng.c
+https://gitlab.com/cki-project/kernel-ark/-/commit/e855b8eee846e5923d9ced1d5279cbadb7a0494e
+ e855b8eee846e5923d9ced1d5279cbadb7a0494e crypto: sig - Disable signing
-https://gitlab.com/cki-project/kernel-ark/-/commit/69722a875a1ad5b5bd3cfbee8e0744f44b9a2d71
- 69722a875a1ad5b5bd3cfbee8e0744f44b9a2d71 Fix up rebase typo in drivers/pci/quirks.c
+https://gitlab.com/cki-project/kernel-ark/-/commit/4e191a2588542aa36ecc96e0a78b435318ee6d2c
+ 4e191a2588542aa36ecc96e0a78b435318ee6d2c redhat: include resolve_btfids in kernel-devel
-https://gitlab.com/cki-project/kernel-ark/-/commit/4f4f94f4b4fef0f4f2d7c25aa43fe408f67bf45b
- 4f4f94f4b4fef0f4f2d7c25aa43fe408f67bf45b rh_message.h: update support status of mlx5 devices
+https://gitlab.com/cki-project/kernel-ark/-/commit/6e2c18aa543d2d14647ec184aa759813fb356b7b
+ 6e2c18aa543d2d14647ec184aa759813fb356b7b redhat: workaround CKI cross compilation for scripts
-https://gitlab.com/cki-project/kernel-ark/-/commit/1fc49a8e60b44df7c053f37b81c038e152dc8c11
- 1fc49a8e60b44df7c053f37b81c038e152dc8c11 efi: Fix swapped arguments to bsearch() in efi_status_to_*()
+https://gitlab.com/cki-project/kernel-ark/-/commit/25b32a532a6004950851d9872562ab2700926548
+ 25b32a532a6004950851d9872562ab2700926548 crypto: akcipher - Disable signing and decryption
-https://gitlab.com/cki-project/kernel-ark/-/commit/cb6973630c116732f94c57d04dc7751e25502919
- cb6973630c116732f94c57d04dc7751e25502919 Revert "Removing Obsolete hba pci-ids from rhel8"
+https://gitlab.com/cki-project/kernel-ark/-/commit/0f7a4de55c51fca9d48f64874043dbdd3e09b39f
+ 0f7a4de55c51fca9d48f64874043dbdd3e09b39f crypto: dh - implement FIPS PCT
-https://gitlab.com/cki-project/kernel-ark/-/commit/0ad8c01f0d79a5652c6c4f0988a1ba1a90084900
- 0ad8c01f0d79a5652c6c4f0988a1ba1a90084900 rh_messages.h: add missing lpfc devices
+https://gitlab.com/cki-project/kernel-ark/-/commit/64dc741bc166a7b2584b0a9861f4fa65fb06a2a4
+ 64dc741bc166a7b2584b0a9861f4fa65fb06a2a4 crypto: ecdh - disallow plain "ecdh" usage in FIPS mode
-https://gitlab.com/cki-project/kernel-ark/-/commit/cc0e896ba5e16753fe0d071830713c6ecb852976
- cc0e896ba5e16753fe0d071830713c6ecb852976 kernel: extend rh_waived to cope better with the CVE mitigations case
+https://gitlab.com/cki-project/kernel-ark/-/commit/f7e0eaab7c8a9fef1e0e5a1a43d14ea02b6f39a6
+ f7e0eaab7c8a9fef1e0e5a1a43d14ea02b6f39a6 crypto: seqiv - flag instantiations as FIPS compliant
-https://gitlab.com/cki-project/kernel-ark/-/commit/334c64fb992273cc56d4a53b89b8e8ef7c2dbfcc
- 334c64fb992273cc56d4a53b89b8e8ef7c2dbfcc rh_messages.h: add missing aacraid device
+https://gitlab.com/cki-project/kernel-ark/-/commit/660f8f5df5bda978c8013d9a396ceba2bd71685b
+ 660f8f5df5bda978c8013d9a396ceba2bd71685b not upstream: Disable vdso getrandom when FIPS is enabled
-https://gitlab.com/cki-project/kernel-ark/-/commit/baf0fcb2bd236b00abb5545a35fe5888cac9a62c
- baf0fcb2bd236b00abb5545a35fe5888cac9a62c rh_messages.h: update unmaintained drivers
+https://gitlab.com/cki-project/kernel-ark/-/commit/e96fe3a1ef7c3602e63e203bf8f0bd889517cfa0
+ e96fe3a1ef7c3602e63e203bf8f0bd889517cfa0 lsm: update security_lock_kernel_down
-https://gitlab.com/cki-project/kernel-ark/-/commit/cb6357af0308b241092e271a1a01f6eceadb939e
- cb6357af0308b241092e271a1a01f6eceadb939e arm64: add early lockdown for secure boot
+https://gitlab.com/cki-project/kernel-ark/-/commit/5f8601c159981ec503bee144435d8cb5a45b37aa
+ 5f8601c159981ec503bee144435d8cb5a45b37aa random: replace import_single_range() with import_ubuf()
-https://gitlab.com/cki-project/kernel-ark/-/commit/e795a9a103f66b9de16837b58918ca9dfd015e49
- e795a9a103f66b9de16837b58918ca9dfd015e49 efi: pass secure boot mode to kernel proper
+https://gitlab.com/cki-project/kernel-ark/-/commit/7e48802c62d2ac8b6f91f5d2aecc765e3c6a0548
+ 7e48802c62d2ac8b6f91f5d2aecc765e3c6a0548 random: Add hook to override device reads and getrandom(2)
-https://gitlab.com/cki-project/kernel-ark/-/commit/f87f6140cb70b36479bf24e3cc25fd7dca88a00d
- f87f6140cb70b36479bf24e3cc25fd7dca88a00d selftests/bpf: Remove ksyms_weak_lskel test
+https://gitlab.com/cki-project/kernel-ark/-/commit/554351f5ab026d86b7acc5b75a217999f8a1a08b
+ 554351f5ab026d86b7acc5b75a217999f8a1a08b Revert "Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64"
-https://gitlab.com/cki-project/kernel-ark/-/commit/f57d4487f44e61c3b7a585e38b25d6283bf8c871
- f57d4487f44e61c3b7a585e38b25d6283bf8c871 Simplify include Makefile.rhelver
+https://gitlab.com/cki-project/kernel-ark/-/commit/f5c8da20fa3ab6ea951610201e8d28fa074417b1
+ f5c8da20fa3ab6ea951610201e8d28fa074417b1 Enable IO_URING for RHEL
-https://gitlab.com/cki-project/kernel-ark/-/commit/3a6c0c7b9a32bb31d764d0b907830dcd0ad06f6a
- 3a6c0c7b9a32bb31d764d0b907830dcd0ad06f6a redhat: make ENABLE_WERROR also enable OBJTOOL_WERROR
+https://gitlab.com/cki-project/kernel-ark/-/commit/f0490bfc945265df269aaba29733ddb4524adc45
+ f0490bfc945265df269aaba29733ddb4524adc45 Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64
-https://gitlab.com/cki-project/kernel-ark/-/commit/d02bbf7160607fa2a45aacbec779636fec20d0fe
- d02bbf7160607fa2a45aacbec779636fec20d0fe main.c: fix initcall blacklisted
+https://gitlab.com/cki-project/kernel-ark/-/commit/be31e8fd804b1f65ac7b6315b3a7897ee5bb2288
+ be31e8fd804b1f65ac7b6315b3a7897ee5bb2288 redhat: version two of Makefile.rhelver tweaks
-https://gitlab.com/cki-project/kernel-ark/-/commit/6883d08acb55a084683855512c911c79f055bdc6
- 6883d08acb55a084683855512c911c79f055bdc6 arch/x86/kernel/setup.c: fix rh_check_supported
+https://gitlab.com/cki-project/kernel-ark/-/commit/078b697814f551723a3d1736caedcf607d465ef2
+ 078b697814f551723a3d1736caedcf607d465ef2 redhat: adapt to upstream Makefile change
-https://gitlab.com/cki-project/kernel-ark/-/commit/ab03eaa7ff16b794ca40b30eaabdccca07238261
- ab03eaa7ff16b794ca40b30eaabdccca07238261 efi,lockdown: fix kernel lockdown on Secure Boot
+https://gitlab.com/cki-project/kernel-ark/-/commit/a0b408c739cdeb122d01e34691aec8c2bb24f777
+ a0b408c739cdeb122d01e34691aec8c2bb24f777 Change acpi_bus_get_acpi_device to acpi_get_acpi_dev
-https://gitlab.com/cki-project/kernel-ark/-/commit/16f208cdb77cc2b53efd91ecf2f23f5911b384ee
- 16f208cdb77cc2b53efd91ecf2f23f5911b384ee redhat: automotive: define CONFIG_RH_AUTOMOTIVE
+https://gitlab.com/cki-project/kernel-ark/-/commit/acc3464ce2308ad9807a80026d33babe60ffe49f
+ acc3464ce2308ad9807a80026d33babe60ffe49f RHEL: disable io_uring support
-https://gitlab.com/cki-project/kernel-ark/-/commit/7c3c1545025b2fd0c33b3fcf38f526e149fb6731
- 7c3c1545025b2fd0c33b3fcf38f526e149fb6731 redhat: fix modules.order target
+https://gitlab.com/cki-project/kernel-ark/-/commit/69fbb76eaab8832507e8256b7ce8f1ae06fa7317
+ 69fbb76eaab8832507e8256b7ce8f1ae06fa7317 REDHAT: coresight: etm4x: Disable coresight on HPE Apollo 70
-https://gitlab.com/cki-project/kernel-ark/-/commit/ee9db481f712f52a8f2f08a3ca4b65d7dce55011
- ee9db481f712f52a8f2f08a3ca4b65d7dce55011 [redhat] rh_messages.h: driver and device updates
+https://gitlab.com/cki-project/kernel-ark/-/commit/ccaf755201e6ae857ef48198dad07b58fb71805a
+ ccaf755201e6ae857ef48198dad07b58fb71805a KEYS: Make use of platform keyring for module signature verify
-https://gitlab.com/cki-project/kernel-ark/-/commit/767e89dc12393a9be7ec14ac578ce100a426f8f4
- 767e89dc12393a9be7ec14ac578ce100a426f8f4 crypto: rng - Fix extrng EFAULT handling
+https://gitlab.com/cki-project/kernel-ark/-/commit/608f5efc2dfb17e3c94994d4c1f6b94b5a3fc7d5
+ 608f5efc2dfb17e3c94994d4c1f6b94b5a3fc7d5 ARM: tegra: usb no reset
-https://gitlab.com/cki-project/kernel-ark/-/commit/f2e2bc5ad22b39e974d5cc0b973f175b09a395c1
- f2e2bc5ad22b39e974d5cc0b973f175b09a395c1 crypto: sig - Disable signing
+https://gitlab.com/cki-project/kernel-ark/-/commit/f00a8ae12e22f22968128bf9a7f4a85a81563620
+ f00a8ae12e22f22968128bf9a7f4a85a81563620 arm: make CONFIG_HIGHPTE optional without CONFIG_EXPERT
-https://gitlab.com/cki-project/kernel-ark/-/commit/d74ed5f596e4ead58bc33a5c8047c588a9ec7671
- d74ed5f596e4ead58bc33a5c8047c588a9ec7671 crypto: rng - Ensure stdrng is tested before user-space starts
+https://gitlab.com/cki-project/kernel-ark/-/commit/0890bd0cd30e73b6781e34ffdb44602f61538ecd
+ 0890bd0cd30e73b6781e34ffdb44602f61538ecd s390: Lock down the kernel when the IPL secure flag is set
-https://gitlab.com/cki-project/kernel-ark/-/commit/fe101ac78157faa706667423bb3f32427cf77ac1
- fe101ac78157faa706667423bb3f32427cf77ac1 [redhat] rh_messages.h: Mark BlueField-4 as disabled
+https://gitlab.com/cki-project/kernel-ark/-/commit/bb7fe52293d333bd79d715b4b81626f2b664b4c8
+ bb7fe52293d333bd79d715b4b81626f2b664b4c8 efi: Lock down the kernel if booted in secure boot mode
-https://gitlab.com/cki-project/kernel-ark/-/commit/4ab3ea9a662785071a6aea07b278beff0723d7d3
- 4ab3ea9a662785071a6aea07b278beff0723d7d3 Update the RHEL_DIFFERENCES help string
+https://gitlab.com/cki-project/kernel-ark/-/commit/35e536a3a7970b59263f34e2031492a5af32c44d
+ 35e536a3a7970b59263f34e2031492a5af32c44d efi: Add an EFI_SECURE_BOOT flag to indicate secure boot mode
-https://gitlab.com/cki-project/kernel-ark/-/commit/d4ef3630c0aad985b2513ac9eafd1ff9a7c14ce0
- d4ef3630c0aad985b2513ac9eafd1ff9a7c14ce0 redhat: include resolve_btfids in kernel-devel
+https://gitlab.com/cki-project/kernel-ark/-/commit/8b80b72d2ee13bff55f4fddda01a38534290b6a4
+ 8b80b72d2ee13bff55f4fddda01a38534290b6a4 security: lockdown: expose a hook to lock the kernel down
-https://gitlab.com/cki-project/kernel-ark/-/commit/a3394a8d6300de5dd2ba46356e2429fafe7f6ec6
- a3394a8d6300de5dd2ba46356e2429fafe7f6ec6 redhat: workaround CKI cross compilation for scripts
+https://gitlab.com/cki-project/kernel-ark/-/commit/bb18dc1a4c7a4b9f117de383fd785c2489c5763a
+ bb18dc1a4c7a4b9f117de383fd785c2489c5763a Make get_cert_list() use efi_status_to_str() to print error messages.
-https://gitlab.com/cki-project/kernel-ark/-/commit/922e64a6a51f24617a11aa13128f148a0a3c4de7
- 922e64a6a51f24617a11aa13128f148a0a3c4de7 crypto: akcipher - Disable signing and decryption
+https://gitlab.com/cki-project/kernel-ark/-/commit/3a70480a5e42324f2e05b1be7ce3206c7c15f43e
+ 3a70480a5e42324f2e05b1be7ce3206c7c15f43e Add efi_status_to_str() and rework efi_status_to_err().
-https://gitlab.com/cki-project/kernel-ark/-/commit/85070c923005f4495fdc6dba427a53bec033a21c
- 85070c923005f4495fdc6dba427a53bec033a21c crypto: dh - implement FIPS PCT
+https://gitlab.com/cki-project/kernel-ark/-/commit/fc9ca4ae3c482381c0c981f284e2a022350ee1f8
+ fc9ca4ae3c482381c0c981f284e2a022350ee1f8 arm: aarch64: Drop the EXPERT setting from ARM64_FORCE_52BIT
-https://gitlab.com/cki-project/kernel-ark/-/commit/744ee9560807d7c568f60d571f4140601eec2036
- 744ee9560807d7c568f60d571f4140601eec2036 crypto: ecdh - disallow plain "ecdh" usage in FIPS mode
+https://gitlab.com/cki-project/kernel-ark/-/commit/045787bed9bed2725cf8aa911ea4809b326a0d4a
+ 045787bed9bed2725cf8aa911ea4809b326a0d4a iommu/arm-smmu: workaround DMA mode issues
-https://gitlab.com/cki-project/kernel-ark/-/commit/c026a466c6774f87e07fc40159f94594ea08fba9
- c026a466c6774f87e07fc40159f94594ea08fba9 crypto: seqiv - flag instantiations as FIPS compliant
+https://gitlab.com/cki-project/kernel-ark/-/commit/798a41acca3d4e1802fbb7363475a47c45772fdd
+ 798a41acca3d4e1802fbb7363475a47c45772fdd ipmi: do not configure ipmi for HPE m400
-https://gitlab.com/cki-project/kernel-ark/-/commit/f266de4b6d21bc3dcedc7d8847fdcd979299b65f
- f266de4b6d21bc3dcedc7d8847fdcd979299b65f [kernel] bpf: set default value for bpf_jit_harden
+https://gitlab.com/cki-project/kernel-ark/-/commit/4feadfa31668ac3ec8e816be489013aaaa47e3e6
+ 4feadfa31668ac3ec8e816be489013aaaa47e3e6 ahci: thunderx2: Fix for errata that affects stop engine
-https://gitlab.com/cki-project/kernel-ark/-/commit/a13d615d5be3dbbb39f6630dd05cee52fd209cbe
- a13d615d5be3dbbb39f6630dd05cee52fd209cbe not upstream: Disable vdso getrandom when FIPS is enabled
+https://gitlab.com/cki-project/kernel-ark/-/commit/b4d148f31a398f259f9e7861047651de123e10c0
+ b4d148f31a398f259f9e7861047651de123e10c0 Vulcan: AHCI PCI bar fix for Broadcom Vulcan early silicon
-https://gitlab.com/cki-project/kernel-ark/-/commit/65f42b9ea395cee764763ee663d1bf00f8d01a1d
- 65f42b9ea395cee764763ee663d1bf00f8d01a1d Add support to rh_waived cmdline boot parameter
+https://gitlab.com/cki-project/kernel-ark/-/commit/4cb0584af56b1aa3dc42384756bfbadb94586a85
+ 4cb0584af56b1aa3dc42384756bfbadb94586a85 tags.sh: Ignore redhat/rpm
-https://gitlab.com/cki-project/kernel-ark/-/commit/de41dc3f9361d535713822d53327d294ea795f54
- de41dc3f9361d535713822d53327d294ea795f54 rh_flags: fix failed when register_sysctl_sz rh_flags_table to kernel
+https://gitlab.com/cki-project/kernel-ark/-/commit/fbf7ce33fab2f64614382562a2ccd93f35558c4b
+ fbf7ce33fab2f64614382562a2ccd93f35558c4b aarch64: acpi scan: Fix regression related to X-Gene UARTs
-https://gitlab.com/cki-project/kernel-ark/-/commit/a31a63632f34fd9047dd710ed8d7a277ca7a3be5
- a31a63632f34fd9047dd710ed8d7a277ca7a3be5 [redhat] rh_flags: constify the ctl_table argument of proc_handler
+https://gitlab.com/cki-project/kernel-ark/-/commit/39ad6f605e88f294e802afb8063c0fddf88352e9
+ 39ad6f605e88f294e802afb8063c0fddf88352e9 ACPI / irq: Workaround firmware issue on X-Gene based m400
-https://gitlab.com/cki-project/kernel-ark/-/commit/080c0998af6ce03109d97de34e19ed4a74a305c5
- 080c0998af6ce03109d97de34e19ed4a74a305c5 redhat: rh_flags: declare proper static methods when !CONFIG_RHEL_DIFFERENCES
+https://gitlab.com/cki-project/kernel-ark/-/commit/99c6a509b61259f23b72d1b07ecf41a57e95df1d
+ 99c6a509b61259f23b72d1b07ecf41a57e95df1d ACPI: APEI: arm64: Ignore broken HPE moonshot APEI support
-https://gitlab.com/cki-project/kernel-ark/-/commit/6b3a7dbd5aeed2b00699527f5dfcfcf7100c9231
- 6b3a7dbd5aeed2b00699527f5dfcfcf7100c9231 redhat: make bnx2xx drivers unmaintained in rhel-10
+https://gitlab.com/cki-project/kernel-ark/-/commit/c5bbc3ffdff8034dccf68623b0715e9f98034ca5
+ c5bbc3ffdff8034dccf68623b0715e9f98034ca5 Pull the RHEL version defines out of the Makefile
-https://gitlab.com/cki-project/kernel-ark/-/commit/76684e826bf1f1003bce44d8bcf8dbe181b231e1
- 76684e826bf1f1003bce44d8bcf8dbe181b231e1 rh_flags: Rename rh_features to rh_flags
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/b84843a8cc781e3cd3dfc2f49bc73c462cce6e75
- b84843a8cc781e3cd3dfc2f49bc73c462cce6e75 kernel: rh_features: fix reading empty feature list from /proc
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/22eedb8f773da5746791aecd125dc351fedf6137
- 22eedb8f773da5746791aecd125dc351fedf6137 rh_features: move rh_features entry to sys/kernel
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/02235bc4496d64877e26715e30b22dbab9fff954
- 02235bc4496d64877e26715e30b22dbab9fff954 rh_features: convert to atomic allocation
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/c4ac240c4a45bf8b15f75f1dd2734015080e7551
- c4ac240c4a45bf8b15f75f1dd2734015080e7551 add rh_features to /proc
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/f337427539dab69cb4774364681542e1148ff8ac
- f337427539dab69cb4774364681542e1148ff8ac add support for rh_features
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/efcd39c5597a50e7d3161048d39936377ffc5e10
- efcd39c5597a50e7d3161048d39936377ffc5e10 [redhat] PCI: Fix pci_rh_check_status() call semantics
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9ff994931e55bc9c03c89cda2d825845217b175c
- 9ff994931e55bc9c03c89cda2d825845217b175c scsi: sd: condition probe_type under RHEL_DIFFERENCES
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9fd8ba500b09bff66f125cc4022485c5e5519d6e
- 9fd8ba500b09bff66f125cc4022485c5e5519d6e [redhat] rh_messages.h: mark mlx5 on Bluefield-3 as unmaintained
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/664e0a9e9e7e27941f23da7bc9cd4fe2490f4b4d
- 664e0a9e9e7e27941f23da7bc9cd4fe2490f4b4d [redhat] rh_messages.h: initial driver and device lists
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/8bf304679c189fc9ee11c420b06cd49169072425
- 8bf304679c189fc9ee11c420b06cd49169072425 arch/x86: Fix XSAVE check for x86_64-v2 check
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/0cb55f9453031437858d4d5f28066a94aaaf0db1
- 0cb55f9453031437858d4d5f28066a94aaaf0db1 arch/x86/kernel/setup.c: fixup rh_check_supported
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/cabd3a1c7507ad3363c1a62fe3c9dc15c71fae88
- cabd3a1c7507ad3363c1a62fe3c9dc15c71fae88 lsm: update security_lock_kernel_down
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/05fbd86284af90211278801dfaa0382fc6866512
- 05fbd86284af90211278801dfaa0382fc6866512 arch/x86: mark x86_64-v1 and x86_64-v2 processors as deprecated
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/fda94efe9945911ff9984b6bded46029899c2260
- fda94efe9945911ff9984b6bded46029899c2260 redhat: kABI: add missing RH_KABI_SIZE_ALIGN_CHECKS Kconfig option
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/0bf1bbc7d2885f2b5f93a31bf9323b40d8da321c
- 0bf1bbc7d2885f2b5f93a31bf9323b40d8da321c redhat: rh_kabi: introduce RH_KABI_EXCLUDE_WITH_SIZE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/a5c9b34df9a6829569b017d7ed9285e2cd724cf9
- a5c9b34df9a6829569b017d7ed9285e2cd724cf9 redhat: rh_kabi: move semicolon inside __RH_KABI_CHECK_SIZE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/246e77ea865d4bec6e8474f0224f2428204b53e4
- 246e77ea865d4bec6e8474f0224f2428204b53e4 random: replace import_single_range() with import_ubuf()
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/2158f814522555b675b5b7c00ef5a9f95d0b1574
- 2158f814522555b675b5b7c00ef5a9f95d0b1574 ext4: Mark mounting fs-verity filesystems as tech-preview
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/579ac0e5e55961f9207048cb42b90691207208d9
- 579ac0e5e55961f9207048cb42b90691207208d9 erofs: Add tech preview markers at mount
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/79d12e3e56e53619de36ea725ca23cfc879232cc
- 79d12e3e56e53619de36ea725ca23cfc879232cc kernel/rh_messages.c: Mark functions as possibly unused
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/fd6c1237e048c56a3923115631d30348bb1e0ce1
- fd6c1237e048c56a3923115631d30348bb1e0ce1 crypto: rng - Override drivers/char/random in FIPS mode
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/dd084634fc48445609b8b667ba8cb14088a2a738
- dd084634fc48445609b8b667ba8cb14088a2a738 random: Add hook to override device reads and getrandom(2)
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/3f41ceb1f1433f3f0d84cd6e56a293b68ec3577d
- 3f41ceb1f1433f3f0d84cd6e56a293b68ec3577d [redhat] kernel/rh_messages.c: move hardware tables to rh_messages.h
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/32fa4676a1017e1642727b515a45630a7bd0e59b
- 32fa4676a1017e1642727b515a45630a7bd0e59b [redhat] kernel/rh_messages.c: Wire up new calls
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/fa6d16b9ac3acec6fba047a827e3a591809ae2d8
- fa6d16b9ac3acec6fba047a827e3a591809ae2d8 [redhat] drivers/pci: Update rh_messages.c
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/112e47862e089dbcc08b403cced39695e1b774ab
- 112e47862e089dbcc08b403cced39695e1b774ab [redhat] drivers/pci: Remove RHEL-only pci_hw_*() functions
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6f656b7b218087b698e65f827563224cd07ec796
- 6f656b7b218087b698e65f827563224cd07ec796 scsi: sd: Add "probe_type" module parameter to allow synchronous probing
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/20a8988251338078a907314cb886b74e5a2d113c
- 20a8988251338078a907314cb886b74e5a2d113c Revert "Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64"
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/a9b29f2f468ca69ced7062546b3ed542b507af78
- a9b29f2f468ca69ced7062546b3ed542b507af78 kernel/rh_messages.c: Another gcc12 warning on redundant NULL test
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6d42f7c135d7dadca75aebaa517667a4059622f3
- 6d42f7c135d7dadca75aebaa517667a4059622f3 Enable IO_URING for RHEL
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/bd51deb71d09b6559ce23cb7a7b888426fd747b4
- bd51deb71d09b6559ce23cb7a7b888426fd747b4 Remove EXPERT from ARCH_FORCE_MAX_ORDER for aarch64
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6925896320075aa0ac87e87e46cdbcdfd6362d27
- 6925896320075aa0ac87e87e46cdbcdfd6362d27 redhat: version two of Makefile.rhelver tweaks
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/1cab9aeb63fd3d1eaf43435ee8928d8314b03cb8
- 1cab9aeb63fd3d1eaf43435ee8928d8314b03cb8 redhat: adapt to upstream Makefile change
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/b81bcc2993aa143a7c3447524c4f3e8ab11415c9
- b81bcc2993aa143a7c3447524c4f3e8ab11415c9 kernel/rh_messages.c: gcc12 warning on redundant NULL test
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/d636276eae4cc4e735263d3f2236504c5e7f971f
- d636276eae4cc4e735263d3f2236504c5e7f971f Change acpi_bus_get_acpi_device to acpi_get_acpi_dev
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/5b1ec5efc280f86625e9b4ad8015fdaf1eb7ac36
- 5b1ec5efc280f86625e9b4ad8015fdaf1eb7ac36 ARK: Remove code marking devices unmaintained
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/4fc150edfbb6c36346b95fbe375de8f2d8e5034a
- 4fc150edfbb6c36346b95fbe375de8f2d8e5034a rh_message: Fix function name
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/7c52dfbcfcf64b275b7c1ff17a7a5bbcfeabf805
- 7c52dfbcfcf64b275b7c1ff17a7a5bbcfeabf805 Add Partner Supported taint flag to kAFS
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/7de69397e195396c930ca472cb9e4cd3f1d58ee3
- 7de69397e195396c930ca472cb9e4cd3f1d58ee3 Add Partner Supported taint flag
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/8cb5fb45a3ef2a598f5f78715ac015ee8eadb601
- 8cb5fb45a3ef2a598f5f78715ac015ee8eadb601 kabi: Add kABI macros for enum type
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/ab204aa67b06325eeeefcc519a33207e1de1c2b1
- ab204aa67b06325eeeefcc519a33207e1de1c2b1 kabi: expand and clarify documentation of aux structs
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/423190ab24dfaeeac66844d516727e64e25c020e
- 423190ab24dfaeeac66844d516727e64e25c020e kabi: introduce RH_KABI_USE_AUX_PTR
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/17e0ca5b9ce0f82fc51feeafb504e602c5ebe957
- 17e0ca5b9ce0f82fc51feeafb504e602c5ebe957 kabi: rename RH_KABI_SIZE_AND_EXTEND to AUX
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/27e55ed93f20dcb4e5ac0adbfd4932111b54bbfa
- 27e55ed93f20dcb4e5ac0adbfd4932111b54bbfa kabi: more consistent _RH_KABI_SIZE_AND_EXTEND
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/3307f100af96764975dc7f7cb86bb7643f629023
- 3307f100af96764975dc7f7cb86bb7643f629023 kabi: use fixed field name for extended part
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/1485ff8f2edaef1ee555cc08ff0e1e0a0126e960
- 1485ff8f2edaef1ee555cc08ff0e1e0a0126e960 kabi: fix dereference in RH_KABI_CHECK_EXT
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/b64d7ad5b2bc17bc0d7130074d35415162cad23b
- b64d7ad5b2bc17bc0d7130074d35415162cad23b kabi: fix RH_KABI_SET_SIZE macro
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9f4a882b6fd7033290f0471fc45bc60669ccd19e
- 9f4a882b6fd7033290f0471fc45bc60669ccd19e kabi: expand and clarify documentation
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/92daf096f42339a6f5d12ce91bbb904790160a30
- 92daf096f42339a6f5d12ce91bbb904790160a30 kabi: make RH_KABI_USE replace any number of reserved fields
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/860374d232814e79bf831646469bf7a3ac5af847
- 860374d232814e79bf831646469bf7a3ac5af847 kabi: rename RH_KABI_USE2 to RH_KABI_USE_SPLIT
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/c382e17399279f66f12a70db1cdbcdfd4bb00724
- c382e17399279f66f12a70db1cdbcdfd4bb00724 kabi: change RH_KABI_REPLACE2 to RH_KABI_REPLACE_SPLIT
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/2fa82fdf9eca8805bb585640272f380ba2c3e115
- 2fa82fdf9eca8805bb585640272f380ba2c3e115 kabi: change RH_KABI_REPLACE_UNSAFE to RH_KABI_BROKEN_REPLACE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/5ba803d67ab6f4762127b5e42831da79f76675c5
- 5ba803d67ab6f4762127b5e42831da79f76675c5 kabi: introduce RH_KABI_ADD_MODIFIER
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/57ad3e56d3c20902e2950bd43588d4661158d7c2
- 57ad3e56d3c20902e2950bd43588d4661158d7c2 kabi: Include kconfig.h
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/a076019fab3b6a7993a10e41a1e2e64cea52d465
- a076019fab3b6a7993a10e41a1e2e64cea52d465 kabi: macros for intentional kABI breakage
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/ced32dc58c71b977a3a8f444306b11272ab3c9fd
- ced32dc58c71b977a3a8f444306b11272ab3c9fd kabi: fix the note about terminating semicolon
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6426716cf7f9025c8db90179c215114f67a97c16
- 6426716cf7f9025c8db90179c215114f67a97c16 kabi: introduce RH_KABI_HIDE_INCLUDE and RH_KABI_FAKE_INCLUDE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/7039428623d9def4665f51a8f6e232dd5dc62075
- 7039428623d9def4665f51a8f6e232dd5dc62075 pci.h: Fix static include
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6853e4c29e97a33139969e584cf45421dec558ef
- 6853e4c29e97a33139969e584cf45421dec558ef drivers/pci/pci-driver.c: Fix if/ifdef typo
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/3d45867aa4fd6cd8c1889fe300dabb8894c52174
- 3d45867aa4fd6cd8c1889fe300dabb8894c52174 kernel/rh_taint.c: Update to new messaging
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9294b06c62295a5446a6ac845ed77ace67843ea8
- 9294b06c62295a5446a6ac845ed77ace67843ea8 redhat: Add mark_driver_deprecated()
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/f0aa81f948e15a35b1048c4dd67ee9ac4ab91e42
- f0aa81f948e15a35b1048c4dd67ee9ac4ab91e42 RHEL: disable io_uring support
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6bbb2d3c52b5970ac88665987fd10085f0994a82
- 6bbb2d3c52b5970ac88665987fd10085f0994a82 bpf: Fix unprivileged_bpf_disabled setup
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/894df4af71ba3ceb82ab57728dab67af1fa3ae65
- 894df4af71ba3ceb82ab57728dab67af1fa3ae65 wireguard: disable in FIPS mode
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/c3fb9dc29e1d477487c80531f6c0f846853682fb
- c3fb9dc29e1d477487c80531f6c0f846853682fb REDHAT: coresight: etm4x: Disable coresight on HPE Apollo 70
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/fb39d4e6bbecce6e5e60a4565f341ace0e3f92c7
- fb39d4e6bbecce6e5e60a4565f341ace0e3f92c7 redhat: remove remaining references of CONFIG_RH_DISABLE_DEPRECATED
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/55a844bdf35a1b308373c16efe1cbb53ed43b36d
- 55a844bdf35a1b308373c16efe1cbb53ed43b36d arch/x86: Remove vendor specific CPU ID checks
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/e30d809f23a4aeaa40a6ff38abb6d391977bb154
- e30d809f23a4aeaa40a6ff38abb6d391977bb154 redhat: Replace hardware.redhat.com link in Unsupported message
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/a6255a3cc6e13d0831f6bc625ed01d9f5ac3486e
- a6255a3cc6e13d0831f6bc625ed01d9f5ac3486e x86: Fix compile issues with rh_check_supported()
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/d862cadef1cd9701230e83a584e48639bd5a444e
- d862cadef1cd9701230e83a584e48639bd5a444e KEYS: Make use of platform keyring for module signature verify
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/ec5d3445b663a5ba7227a0a42ba4f7bd4d38ed4a
- ec5d3445b663a5ba7227a0a42ba4f7bd4d38ed4a Input: rmi4 - remove the need for artificial IRQ in case of HID
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9cd4b2fa3ac888c4785f39843a6f147dc15fac0e
- 9cd4b2fa3ac888c4785f39843a6f147dc15fac0e ARM: tegra: usb no reset
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/29d4e0c608192cd278c1f451d107f0f6187cfa0c
- 29d4e0c608192cd278c1f451d107f0f6187cfa0c arm: make CONFIG_HIGHPTE optional without CONFIG_EXPERT
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/2ad58fba8ee3398ac80937e82aea1fb6ec0dea6a
- 2ad58fba8ee3398ac80937e82aea1fb6ec0dea6a redhat: rh_kabi: deduplication friendly structs
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/8c5c003ced632c0d45937eda60e4683479fd7fd8
- 8c5c003ced632c0d45937eda60e4683479fd7fd8 redhat: rh_kabi add a comment with warning about RH_KABI_EXCLUDE usage
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/a14a03194482338487deca42b1b922654993426a
- a14a03194482338487deca42b1b922654993426a redhat: rh_kabi: introduce RH_KABI_EXTEND_WITH_SIZE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6ac2b532dd245dd1ff88f8b9456448b23b08c229
- 6ac2b532dd245dd1ff88f8b9456448b23b08c229 redhat: rh_kabi: Indirect EXTEND macros so nesting of other macros will resolve.
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/dfb5a2164d5f135268e80e4b5b326b1ae2941432
- dfb5a2164d5f135268e80e4b5b326b1ae2941432 redhat: rh_kabi: Fix RH_KABI_SET_SIZE to use dereference operator
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/8138cde88c8db4574474b6deb70e6191234fede0
- 8138cde88c8db4574474b6deb70e6191234fede0 redhat: rh_kabi: Add macros to size and extend structs
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/1e49424ef2fe92547088c51909dbce56f130f5ff
- 1e49424ef2fe92547088c51909dbce56f130f5ff Removing Obsolete hba pci-ids from rhel8
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/62340c8138c73246399ff4917d55b9c5aae3cb46
- 62340c8138c73246399ff4917d55b9c5aae3cb46 mptsas: pci-id table changes
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/e8ccde2a8f0b2fb14ac975e3d566cc39b58833dc
- e8ccde2a8f0b2fb14ac975e3d566cc39b58833dc mptspi: pci-id table changes
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/d0de13e51560be7a7bab1a2649317c0eb476db33
- d0de13e51560be7a7bab1a2649317c0eb476db33 qla2xxx: Remove PCI IDs of deprecated adapter
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/753a070b33e0b1bb9ec9dfd81f0441923512a987
- 753a070b33e0b1bb9ec9dfd81f0441923512a987 hpsa: remove old cciss-based smartarray pci ids
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/7da7b88ba5f2ae9203a2d8dfc616bab71778411b
- 7da7b88ba5f2ae9203a2d8dfc616bab71778411b kernel: add SUPPORT_REMOVED kernel taint
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/b02d2a5a792be445a1c9dc6ebdbb2b2a86c9f0f3
- b02d2a5a792be445a1c9dc6ebdbb2b2a86c9f0f3 Rename RH_DISABLE_DEPRECATED to RHEL_DIFFERENCES
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/35f09970b827bf7ee9d096e9eb2e561baf81fb35
- 35f09970b827bf7ee9d096e9eb2e561baf81fb35 s390: Lock down the kernel when the IPL secure flag is set
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/33e03790e31387b0ab6dd1f3651c245ba5beb39b
- 33e03790e31387b0ab6dd1f3651c245ba5beb39b efi: Lock down the kernel if booted in secure boot mode
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9fc841720d0db5f056ac2d5bc2c7f58a98afdc65
- 9fc841720d0db5f056ac2d5bc2c7f58a98afdc65 efi: Add an EFI_SECURE_BOOT flag to indicate secure boot mode
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/5043e288234061961caeeccecae1bdb8ab33c047
- 5043e288234061961caeeccecae1bdb8ab33c047 security: lockdown: expose a hook to lock the kernel down
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/179980868955497ae7d59a06ba1889480d2bbe03
- 179980868955497ae7d59a06ba1889480d2bbe03 Make get_cert_list() use efi_status_to_str() to print error messages.
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/cf5f6a256202c5cbd4f0dd3e68ff17483024e329
- cf5f6a256202c5cbd4f0dd3e68ff17483024e329 Add efi_status_to_str() and rework efi_status_to_err().
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/309a452fb3e39b7b48c1e366c03dee914e4a8837
- 309a452fb3e39b7b48c1e366c03dee914e4a8837 Add support for deprecating processors
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/acec8b0610ddd619d87d9f9a5522a4b76bbe590a
- acec8b0610ddd619d87d9f9a5522a4b76bbe590a arm: aarch64: Drop the EXPERT setting from ARM64_FORCE_52BIT
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/ba08a04d7f12b7a7cda63b4012711ae5344a147a
- ba08a04d7f12b7a7cda63b4012711ae5344a147a iommu/arm-smmu: workaround DMA mode issues
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/e4347a6b11e4603597921af3efc68a515705631d
- e4347a6b11e4603597921af3efc68a515705631d rh_kabi: introduce RH_KABI_EXCLUDE
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/95ffb4b90b1567bcdb7efea0fd144fe97a0e0da2
- 95ffb4b90b1567bcdb7efea0fd144fe97a0e0da2 ipmi: do not configure ipmi for HPE m400
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/4bbaf4b9fef9c58edbd958624c7765fc6d701b06
- 4bbaf4b9fef9c58edbd958624c7765fc6d701b06 kABI: Add generic kABI macros to use for kABI workarounds
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/6a15e5d9be196673139569b094f05127ea24c8d1
- 6a15e5d9be196673139569b094f05127ea24c8d1 add pci_hw_vendor_status()
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9c0dbd2f8eb39216b8fe7e5abbb4f91ce821bbd5
- 9c0dbd2f8eb39216b8fe7e5abbb4f91ce821bbd5 ahci: thunderx2: Fix for errata that affects stop engine
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/751d6e32b129851fb6df580afe1bca98a59da60f
- 751d6e32b129851fb6df580afe1bca98a59da60f Vulcan: AHCI PCI bar fix for Broadcom Vulcan early silicon
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/befc3412ecc7929cefeac1588f5d2c0022efa902
- befc3412ecc7929cefeac1588f5d2c0022efa902 bpf: set unprivileged_bpf_disabled to 1 by default, add a boot parameter
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/2e5de3f09720a8b1a453bebc734314cbc2b4b67e
- 2e5de3f09720a8b1a453bebc734314cbc2b4b67e add Red Hat-specific taint flags
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/629e0185d05867a514bec581daff214ead6275f9
- 629e0185d05867a514bec581daff214ead6275f9 tags.sh: Ignore redhat/rpm
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/d7ac10e5e36022b46c1a856fc99cd87428413a7e
- d7ac10e5e36022b46c1a856fc99cd87428413a7e put RHEL info into generated headers
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/abe40685636a95aae3c912c6cf1adf3a1da24df2
- abe40685636a95aae3c912c6cf1adf3a1da24df2 aarch64: acpi scan: Fix regression related to X-Gene UARTs
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/85c44483062c36ac5ef8df67ba381d32389744ac
- 85c44483062c36ac5ef8df67ba381d32389744ac ACPI / irq: Workaround firmware issue on X-Gene based m400
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/1f2eb3fb2d1f3c596a24a7bae9623c20f9a7ee00
- 1f2eb3fb2d1f3c596a24a7bae9623c20f9a7ee00 modules: add rhelversion MODULE_INFO tag
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/732795ece253683d5264e6f49873539ea8ae2ac1
- 732795ece253683d5264e6f49873539ea8ae2ac1 ACPI: APEI: arm64: Ignore broken HPE moonshot APEI support
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/dfa9e4767ce04c9671ced4ef67ec4f65c84502d7
- dfa9e4767ce04c9671ced4ef67ec4f65c84502d7 Add Red Hat tainting
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/252a3ec53bef578f5891e4cf799ca5f329272f52
- 252a3ec53bef578f5891e4cf799ca5f329272f52 Introduce CONFIG_RH_DISABLE_DEPRECATED
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/64e24815bf2b7ed3a71b7ac01bfbf8e94d394f23
- 64e24815bf2b7ed3a71b7ac01bfbf8e94d394f23 Pull the RHEL version defines out of the Makefile
-
-https://gitlab.com/cki-project/kernel-ark/-/commit/9c5f75d76ee4a7ca578cd645051269f4c5b94d1d
- 9c5f75d76ee4a7ca578cd645051269f4c5b94d1d [initial commit] Add Red Hat variables in the top level makefile
+https://gitlab.com/cki-project/kernel-ark/-/commit/d0cc5ae7a0d305c1e15a0a539faea9ea11af2868
+ d0cc5ae7a0d305c1e15a0a539faea9ea11af2868 [initial commit] Add Red Hat variables in the top level makefile
diff --git a/kernel-aarch64-16k-debug-fedora.config b/kernel-aarch64-16k-debug-fedora.config
index 86e4162..c22e074 100644
--- a/kernel-aarch64-16k-debug-fedora.config
+++ b/kernel-aarch64-16k-debug-fedora.config
@@ -7191,7 +7191,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-16k-fedora.config b/kernel-aarch64-16k-fedora.config
index 2b54e15..d0da2d2 100644
--- a/kernel-aarch64-16k-fedora.config
+++ b/kernel-aarch64-16k-fedora.config
@@ -7160,7 +7160,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-64k-debug-rhel.config b/kernel-aarch64-64k-debug-rhel.config
index cdaa66f..0c3e704 100644
--- a/kernel-aarch64-64k-debug-rhel.config
+++ b/kernel-aarch64-64k-debug-rhel.config
@@ -5874,9 +5874,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-64k-rhel.config b/kernel-aarch64-64k-rhel.config
index a52ee7f..5d4c4d4 100644
--- a/kernel-aarch64-64k-rhel.config
+++ b/kernel-aarch64-64k-rhel.config
@@ -5848,9 +5848,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-debug-fedora.config b/kernel-aarch64-debug-fedora.config
index 1dd8fcd..8c1b52f 100644
--- a/kernel-aarch64-debug-fedora.config
+++ b/kernel-aarch64-debug-fedora.config
@@ -7190,7 +7190,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-debug-rhel.config b/kernel-aarch64-debug-rhel.config
index e5df932..0833ee1 100644
--- a/kernel-aarch64-debug-rhel.config
+++ b/kernel-aarch64-debug-rhel.config
@@ -5871,9 +5871,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-fedora.config b/kernel-aarch64-fedora.config
index c791985..70ce8f6 100644
--- a/kernel-aarch64-fedora.config
+++ b/kernel-aarch64-fedora.config
@@ -7159,7 +7159,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-rhel.config b/kernel-aarch64-rhel.config
index 2453b2d..9dff18b 100644
--- a/kernel-aarch64-rhel.config
+++ b/kernel-aarch64-rhel.config
@@ -5845,9 +5845,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-rt-64k-debug-fedora.config b/kernel-aarch64-rt-64k-debug-fedora.config
index 7deeb57..fd4b320 100644
--- a/kernel-aarch64-rt-64k-debug-fedora.config
+++ b/kernel-aarch64-rt-64k-debug-fedora.config
@@ -7203,7 +7203,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-aarch64-rt-64k-debug-rhel.config b/kernel-aarch64-rt-64k-debug-rhel.config
index 5af6816..245f2bd 100644
--- a/kernel-aarch64-rt-64k-debug-rhel.config
+++ b/kernel-aarch64-rt-64k-debug-rhel.config
@@ -5919,9 +5919,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-rt-64k-fedora.config b/kernel-aarch64-rt-64k-fedora.config
index 5da27e6..02a81df 100644
--- a/kernel-aarch64-rt-64k-fedora.config
+++ b/kernel-aarch64-rt-64k-fedora.config
@@ -7172,7 +7172,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-aarch64-rt-64k-rhel.config b/kernel-aarch64-rt-64k-rhel.config
index 8d6fe18..4f847f2 100644
--- a/kernel-aarch64-rt-64k-rhel.config
+++ b/kernel-aarch64-rt-64k-rhel.config
@@ -5893,9 +5893,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-rt-debug-fedora.config b/kernel-aarch64-rt-debug-fedora.config
index 97203d4..b00ea7d 100644
--- a/kernel-aarch64-rt-debug-fedora.config
+++ b/kernel-aarch64-rt-debug-fedora.config
@@ -7199,7 +7199,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-aarch64-rt-debug-rhel.config b/kernel-aarch64-rt-debug-rhel.config
index 311004c..f527ee6 100644
--- a/kernel-aarch64-rt-debug-rhel.config
+++ b/kernel-aarch64-rt-debug-rhel.config
@@ -5915,9 +5915,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-aarch64-rt-fedora.config b/kernel-aarch64-rt-fedora.config
index 92efa94..bdf8078 100644
--- a/kernel-aarch64-rt-fedora.config
+++ b/kernel-aarch64-rt-fedora.config
@@ -7168,7 +7168,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-aarch64-rt-rhel.config b/kernel-aarch64-rt-rhel.config
index f7f9ae8..2a8ee18 100644
--- a/kernel-aarch64-rt-rhel.config
+++ b/kernel-aarch64-rt-rhel.config
@@ -5889,9 +5889,7 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-ppc64le-debug-fedora.config b/kernel-ppc64le-debug-fedora.config
index 7c23dc6..ad686b0 100644
--- a/kernel-ppc64le-debug-fedora.config
+++ b/kernel-ppc64le-debug-fedora.config
@@ -5694,7 +5694,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-ppc64le-debug-rhel.config b/kernel-ppc64le-debug-rhel.config
index 8a3f3af..9795322 100644
--- a/kernel-ppc64le-debug-rhel.config
+++ b/kernel-ppc64le-debug-rhel.config
@@ -5345,9 +5345,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-ppc64le-fedora.config b/kernel-ppc64le-fedora.config
index 178f858..81445d7 100644
--- a/kernel-ppc64le-fedora.config
+++ b/kernel-ppc64le-fedora.config
@@ -5662,7 +5662,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-ppc64le-rhel.config b/kernel-ppc64le-rhel.config
index b80ea41..1467aae 100644
--- a/kernel-ppc64le-rhel.config
+++ b/kernel-ppc64le-rhel.config
@@ -5321,9 +5321,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-riscv64-debug-fedora.config b/kernel-riscv64-debug-fedora.config
index ee58664..5b11306 100644
--- a/kernel-riscv64-debug-fedora.config
+++ b/kernel-riscv64-debug-fedora.config
@@ -5766,7 +5766,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-riscv64-debug-rhel.config b/kernel-riscv64-debug-rhel.config
index c19d3c0..d3f5a2c 100644
--- a/kernel-riscv64-debug-rhel.config
+++ b/kernel-riscv64-debug-rhel.config
@@ -5377,9 +5377,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-riscv64-fedora.config b/kernel-riscv64-fedora.config
index 9dfcc3c..fb5dc6b 100644
--- a/kernel-riscv64-fedora.config
+++ b/kernel-riscv64-fedora.config
@@ -5734,7 +5734,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-riscv64-rhel.config b/kernel-riscv64-rhel.config
index 30629f9..701da59 100644
--- a/kernel-riscv64-rhel.config
+++ b/kernel-riscv64-rhel.config
@@ -5353,9 +5353,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-riscv64-rt-debug-fedora.config b/kernel-riscv64-rt-debug-fedora.config
index 8d1841b..61b78c8 100644
--- a/kernel-riscv64-rt-debug-fedora.config
+++ b/kernel-riscv64-rt-debug-fedora.config
@@ -5775,7 +5775,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-riscv64-rt-fedora.config b/kernel-riscv64-rt-fedora.config
index 78020bc..6cdcf28 100644
--- a/kernel-riscv64-rt-fedora.config
+++ b/kernel-riscv64-rt-fedora.config
@@ -5743,7 +5743,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-s390x-debug-fedora.config b/kernel-s390x-debug-fedora.config
index bc7a048..849a06d 100644
--- a/kernel-s390x-debug-fedora.config
+++ b/kernel-s390x-debug-fedora.config
@@ -5629,7 +5629,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
# CONFIG_RFKILL is not set
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-s390x-debug-rhel.config b/kernel-s390x-debug-rhel.config
index 47feea0..ddbe6d9 100644
--- a/kernel-s390x-debug-rhel.config
+++ b/kernel-s390x-debug-rhel.config
@@ -5289,9 +5289,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-s390x-fedora.config b/kernel-s390x-fedora.config
index 81475e6..89978a6 100644
--- a/kernel-s390x-fedora.config
+++ b/kernel-s390x-fedora.config
@@ -5597,7 +5597,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
# CONFIG_RFKILL is not set
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-s390x-rhel.config b/kernel-s390x-rhel.config
index 4f8ee3a..c5a4bbe 100644
--- a/kernel-s390x-rhel.config
+++ b/kernel-s390x-rhel.config
@@ -5265,9 +5265,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-s390x-zfcpdump-rhel.config b/kernel-s390x-zfcpdump-rhel.config
index 09e8018..f063a43 100644
--- a/kernel-s390x-zfcpdump-rhel.config
+++ b/kernel-s390x-zfcpdump-rhel.config
@@ -5276,9 +5276,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
# CONFIG_RFKILL is not set
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-debug-fedora.config b/kernel-x86_64-debug-fedora.config
index 0d52ba2..4d39a11 100644
--- a/kernel-x86_64-debug-fedora.config
+++ b/kernel-x86_64-debug-fedora.config
@@ -6137,7 +6137,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-debug-rhel.config b/kernel-x86_64-debug-rhel.config
index 93c8912..6dd508a 100644
--- a/kernel-x86_64-debug-rhel.config
+++ b/kernel-x86_64-debug-rhel.config
@@ -5607,9 +5607,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-fedora.config b/kernel-x86_64-fedora.config
index 725be76..27ff4f1 100644
--- a/kernel-x86_64-fedora.config
+++ b/kernel-x86_64-fedora.config
@@ -6106,7 +6106,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-rhel.config b/kernel-x86_64-rhel.config
index 33ef26f..42edd27 100644
--- a/kernel-x86_64-rhel.config
+++ b/kernel-x86_64-rhel.config
@@ -5582,9 +5582,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-CONFIG_RH_KABI_SIZE_ALIGN_CHECKS=y
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-rt-debug-fedora.config b/kernel-x86_64-rt-debug-fedora.config
index d43268b..782d6ae 100644
--- a/kernel-x86_64-rt-debug-fedora.config
+++ b/kernel-x86_64-rt-debug-fedora.config
@@ -6146,7 +6146,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-x86_64-rt-debug-rhel.config b/kernel-x86_64-rt-debug-rhel.config
index f017d1b..c415aec 100644
--- a/kernel-x86_64-rt-debug-rhel.config
+++ b/kernel-x86_64-rt-debug-rhel.config
@@ -5651,9 +5651,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel-x86_64-rt-fedora.config b/kernel-x86_64-rt-fedora.config
index 0fa7469..3d401d6 100644
--- a/kernel-x86_64-rt-fedora.config
+++ b/kernel-x86_64-rt-fedora.config
@@ -6115,7 +6115,6 @@ CONFIG_RFKILL_GPIO=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RHEL_DIFFERENCES is not set
# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
CONFIG_RICHTEK_RTQ6056=m
CONFIG_RING_BUFFER_BENCHMARK=m
diff --git a/kernel-x86_64-rt-rhel.config b/kernel-x86_64-rt-rhel.config
index 8ef96cb..c011d19 100644
--- a/kernel-x86_64-rt-rhel.config
+++ b/kernel-x86_64-rt-rhel.config
@@ -5626,9 +5626,7 @@ CONFIG_RESOURCE_KUNIT_TEST=m
CONFIG_RFKILL_INPUT=y
CONFIG_RFKILL=m
CONFIG_RFS_ACCEL=y
-# CONFIG_RH_AUTOMOTIVE is not set
CONFIG_RHEL_DIFFERENCES=y
-# CONFIG_RH_KABI_SIZE_ALIGN_CHECKS is not set
# CONFIG_RICHTEK_RTQ6056 is not set
CONFIG_RING_BUFFER_BENCHMARK=m
# CONFIG_RING_BUFFER_PERSISTENT_INJECT is not set
diff --git a/kernel.changelog b/kernel.changelog
index 7ada5cb..1ee8be4 100644
--- a/kernel.changelog
+++ b/kernel.changelog
@@ -1,5 +1,22 @@
-* Mon Aug 17 2026 Fedora Kernel Team <kernel-team@fedoraproject.org> [7.2.0-61]
-- automotive: enable HUGETLBFS to workaround build error (Scott Weaver)
+* Thu Aug 27 2026 Justin M. Forbes <jforbes@fedoraproject.org> [7.2.1-0]
+- Initial setup for stable Fedora release (Justin M. Forbes)
+- Reset Makefile.rhelver for the 7.3 cycle (Justin M. Forbes)
+- Merge configs into common for 7.2 (Justin M. Forbes)
+- redhat/configs: automotive: enable RTC_DRV_PL031 (Eric Chanudet)
+- redhat: name the dtb and UKI arch lists (Jan Stancek)
+- redhat: use one spelling for the nobuildarches files guard (Jan Stancek)
+- redhat: drop stale ppc64 from the kabidw-base arch list (Jan Stancek)
+- redhat: document the kabichk force-off as a seasonal toggle (Jan Stancek)
+- redhat: use one spelling for the include and gemini conditionals (Jan Stancek)
+- redhat: remove unused elf_image_install_path and duplicate defines (Jan Stancek)
+- redhat: drop the dead kernel-tools __requires_exclude python filter (Jan Stancek)
+- redhat: drop the Fedora 41 cross-build gdb-index workaround (Jan Stancek)
+- redhat: drop stale build switches from dist-perf and dist-rpm-baseonly (Jan Stancek)
+- redhat: give kernel-automotive its own summary (Jan Stancek)
+- redhat: drop leftover kernel_kvm_post calls for rt-64k (Jan Stancek)
+- redhat: restore missing summary of the kernel-debug variant (Jan Stancek)
+- redhat: fix parse error in baseonly sanity check message (Jan Stancek)
+- Linux v7.2.1
Resolves:
* Mon Aug 17 2026 Fedora Kernel Team <kernel-team@fedoraproject.org> [7.2.0-60]
diff --git a/kernel.spec b/kernel.spec
index 8132f7f..5e34eea 100644
--- a/kernel.spec
+++ b/kernel.spec
@@ -122,6 +122,11 @@ Summary: The Linux kernel
%global signkernel 0
%endif
+# Arches whose kernels ship device tree blobs
+%global dtb_arches aarch64 riscv64
+# Arches that build the EFI unified kernel images
+%global uki_arches x86_64 aarch64 riscv64
+
# RHEL/CentOS specific .SBAT entries
%if 0%{?centos}
%global sbat_suffix centos
@@ -178,7 +183,7 @@ Summary: The Linux kernel
# kernel release. (This includes prepatch or "rc" releases.)
# Set released_kernel to 0 when the upstream source tarball contains an
# unreleased kernel development snapshot.
-%global released_kernel 0
+%global released_kernel 1
# Set debugbuildsenabled to 1 to build separate base and debug kernels
# (on supported architectures). The kernel-debug-* subpackages will
# contain the debug kernel.
@@ -187,18 +192,18 @@ Summary: The Linux kernel
# the --with-release option overrides this setting.)
%define debugbuildsenabled 1
# define buildid .local
-%define specrpmversion 7.2.0
-%define specversion 7.2.0
+%define specrpmversion 7.2.1
+%define specversion 7.2.1
%define patchversion 7.2
-%define pkgrelease 61
+%define pkgrelease 300
%define kversion 7
-%define tarfile_release 7.2
+%define tarfile_release 7.2.1
# This is needed to do merge window version magic
%define patchlevel 2
# This allows pkg_release to have configurable %%{?dist} tag
-%define specrelease 61%{?buildid}%{?dist}
+%define specrelease 300%{?buildid}%{?dist}
# This defines the kabi tarball version
-%define kabiversion 7.2.0
+%define kabiversion 7.2.1
# If this variable is set to 1, a bpf selftests build failure will cause a
# fatal kernel package build error
@@ -305,7 +310,9 @@ Summary: The Linux kernel
%define with_toolsonly %{?_with_toolsonly: 1} %{?!_with_toolsonly: 0}
# Control whether we perform a compat. check against published ABI.
%define with_kabichk %{?_without_kabichk: 0} %{?!_without_kabichk: 1}
-# Temporarily disable kabi checks until RC.
+# Seasonal toggle, not dead code: flipped off after a rebase and back on
+# once the kABI stablelists are updated for the new release (at RC).
+# While 0, it also forces with_kabidupchk and with_kabidwchk off below.
%define with_kabichk 0
# Control whether we perform a compat. check against DUP ABI.
%define with_kabidupchk %{?_with_kabidupchk: 1} %{?!_with_kabidupchk: 0}
@@ -341,7 +348,7 @@ Summary: The Linux kernel
# Want to build a vanilla kernel build without any non-upstream patches?
%define with_vanilla %{?_with_vanilla: 1} %{?!_with_vanilla: 0}
-%ifarch x86_64 aarch64 riscv64
+%ifarch %{uki_arches}
%define with_efiuki %{?_without_efiuki: 0} %{?!_without_efiuki: 1}
%else
%define with_efiuki 0
@@ -515,8 +522,6 @@ Summary: The Linux kernel
%define with_kabidwchk 0
%define with_kabidw_base 0
%define with_kernel_abi_stablelists 0
-%define with_selftests 0
-%define with_vdso_install 0
%define with_configchecks 0
%endif
@@ -645,7 +650,6 @@ Summary: The Linux kernel
%define hdrarch powerpc
%define make_target vmlinux
%define kernel_image vmlinux
-%define kernel_image_elf 1
%define use_vdso 0
%endif
@@ -934,16 +938,6 @@ BuildRequires: pesign >= 0.10-4
BuildRequires: binutils-%{_build_arch}-linux-gnu, gcc-%{_build_arch}-linux-gnu
%define cross_opts CROSS_COMPILE=%{_build_arch}-linux-gnu-
%define __strip %{_build_arch}-linux-gnu-strip
-
-%if 0%{?fedora} && 0%{?fedora} <= 41
-# Work around find-debuginfo for cross builds.
-# find-debuginfo doesn't support any of CROSS options (RHEL-21797),
-# and since debugedit > 5.0-16.el10, or since commit
-# dfe1f7ff30f4 ("find-debuginfo.sh: Exit with real exit status in parallel jobs")
-# it now aborts on failure and build fails.
-# debugedit-5.1-5 in F42 added support to override tools with target versions.
-%undefine _include_gdb_index
-%endif
%endif
# These below are required to build man pages
@@ -1066,7 +1060,7 @@ Source44: %{name}-riscv64-rhel.config
Source45: %{name}-riscv64-debug-rhel.config
%endif
-%if %{include_rhel} || %{include_automotive}
+%if 0%{?include_rhel} || 0%{?include_automotive}
Source23: x509.genkey.rhel
Source34: def_variants.yaml.rhel
Source41: x509.genkey.centos
@@ -1160,8 +1154,8 @@ Source214: Module.kabi_dup_riscv64
Source300: kernel-abi-stablelists-%{kabiversion}.tar.xz
Source301: kernel-kabi-dw-%{kabiversion}.tar.xz
-%if 0%{include_rt}
-%if 0%{include_rhel}
+%if 0%{?include_rt}
+%if 0%{?include_rhel}
Source474: %{name}-aarch64-rt-rhel.config
Source475: %{name}-aarch64-rt-debug-rhel.config
Source476: %{name}-aarch64-rt-64k-rhel.config
@@ -1169,7 +1163,7 @@ Source477: %{name}-aarch64-rt-64k-debug-rhel.config
Source478: %{name}-x86_64-rt-rhel.config
Source479: %{name}-x86_64-rt-debug-rhel.config
%endif
-%if 0%{include_fedora}
+%if 0%{?include_fedora}
Source480: %{name}-aarch64-rt-fedora.config
Source481: %{name}-aarch64-rt-debug-fedora.config
Source482: %{name}-aarch64-rt-64k-fedora.config
@@ -1181,7 +1175,7 @@ Source487: %{name}-riscv64-rt-debug-fedora.config
%endif
%endif
-%if %{include_automotive}
+%if 0%{?include_automotive}
%if %{with_automotive_build}
Source488: %{name}-aarch64-rhel.config
Source489: %{name}-aarch64-debug-rhel.config
@@ -1320,7 +1314,7 @@ It provides the kernel source files common to all builds.
%if %{with_perf}
%package -n perf
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Performance monitoring for the Linux kernel
@@ -1330,7 +1324,7 @@ This package contains the perf tool, which enables performance monitoring
of the Linux kernel.
%package -n perf-debuginfo
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Debug information for package perf
@@ -1346,7 +1340,7 @@ This package provides debug information for the perf package.
%{expand:%%global _find_debuginfo_opts %{?_find_debuginfo_opts} -p '.*%%{_bindir}/perf(\.debug)?|.*%%{_libexecdir}/perf-core/.*|.*%%{_libdir}/libperf-jvmti.so(\.debug)?|XXX' -o perf-debuginfo.list}
%package -n python3-perf
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Python bindings for apps which will manipulate perf events
@@ -1356,7 +1350,7 @@ written in the Python programming language to use the interface
to manipulate perf events.
%package -n python3-perf-debuginfo
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Debug information for package perf python bindings
@@ -1413,7 +1407,6 @@ Obsoletes: cpufrequtils < 1:009-0.6.p1
Obsoletes: cpuspeed < 1:1.5-16
Requires: %{name}-tools-libs = %{specrpmversion}-%{release}
%endif
-%define __requires_exclude ^%{_bindir}/python
%description -n %{name}-tools
This package contains the tools/ directory from the kernel source
and the supporting documentation.
@@ -1459,7 +1452,7 @@ shipped as part of the kernel tools including ynl.
%endif
%package -n rtla
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Real-Time Linux Analysis tools
@@ -1477,7 +1470,7 @@ about the properties and root causes of unexpected results.
%if %{with_debuginfo}
%package -n rtla-debuginfo
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Debug information for package rtla
@@ -1494,7 +1487,7 @@ This package provides debug information for the rtla package.
%endif
%package -n rv
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: RV: Runtime Verification
@@ -1508,7 +1501,7 @@ to analyze the logical and timing behavior of Linux.
%if %{with_debuginfo}
%package -n rv-debuginfo
-%if 0%{gemini}
+%if 0%{?gemini}
Epoch: %{gemini}
%endif
Summary: Debug information for package rv
@@ -1996,7 +1989,7 @@ on kernel bugs, as some of these options impact performance noticably.
%endif
%if %{with_debug} && %{with_automotive} && !%{with_automotive_build}
-%define variant_summary The Linux Automotive kernel compiled with extra debugging enabled
+%define variant_summary The Linux kernel compiled for Automotive use with PREEMPT_RT and extra debugging enabled
%kernel_variant_package automotive-debug
%description automotive-debug-core
The kernel package contains the Linux kernel (vmlinuz), the core of any
@@ -2010,7 +2003,7 @@ on kernel bugs, as some of these options impact performance noticably.
%endif
%if %{with_automotive_base}
-%define variant_summary The Linux kernel compiled with PREEMPT_RT enabled
+%define variant_summary The Linux kernel compiled for Automotive use with PREEMPT_RT enabled
%kernel_variant_package automotive
%description automotive-core
This package includes a version of the Linux kernel compiled with the
@@ -2018,6 +2011,7 @@ PREEMPT_RT real-time preemption support, targeted for Automotive platforms
%endif
%if %{with_stock} && %{with_debug}
+%define variant_summary The Linux kernel compiled with extra debugging enabled
%if !%{debugbuildsenabled}
%kernel_variant_package -m debug
%else
@@ -2126,7 +2120,7 @@ Prebuilt default kernel image with auto DTB selection for ARM64 UEFI devices.
# do a few sanity-checks for --with *only builds
%if %{with_baseonly}
%if !%{with_stock}
-%{log_msg "Cannot build --with baseonly, stock build is disabled"}
+%{log_msg "Cannot build with baseonly, stock build is disabled"}
exit 1
%endif
%endif
@@ -2550,7 +2544,7 @@ BuildKernel() {
mkdir -p $RPM_BUILD_ROOT%{debuginfodir}/%{image_install_path}
%endif
-%ifarch aarch64 riscv64
+%ifarch %{dtb_arches}
%{log_msg "Build dtb kernel"}
mkdir -p $RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer
%{make} ARCH=$Arch dtbs INSTALL_DTBS_PATH=$RPM_BUILD_ROOT/%{image_install_path}/dtb-$KernelVer
@@ -4529,13 +4523,11 @@ fi\
%if %{with_realtime_arm64_64k_base}
%kernel_variant_preun -v rt-64k
%kernel_variant_post -v rt-64k
-%kernel_kvm_post rt-64k
%endif
%if %{with_debug} && %{with_realtime_arm64_64k}
%kernel_variant_preun -v rt-64k-debug
%kernel_variant_post -v rt-64k-debug
-%kernel_kvm_post rt-64k-debug
%endif
%if %{with_automotive} && %{with_debug} && !%{with_automotive_build}
@@ -4567,7 +4559,7 @@ fi\
%endif
%if %{with_kabidw_base}
-%ifarch x86_64 s390x ppc64 ppc64le aarch64 riscv64
+%ifarch x86_64 s390x ppc64le aarch64 riscv64
%files kernel-kabidw-base-internal
%defattr(-,root,root)
/kabidw-base/%{_target_cpu}/*
@@ -4768,15 +4760,11 @@ fi\
# empty meta-package
%if %{with_stock_base}
-%ifnarch %nobuildarches noarch
+%ifnarch noarch %{nobuildarches}
%files
%endif
%endif
-# This is %%{image_install_path} on an arch where that includes ELF files,
-# or empty otherwise.
-%define elf_image_install_path %{?kernel_image_elf:%{image_install_path}}
-
#
# This macro defines the %%files sections for a kernel package
# and its devel and debuginfo packages.
@@ -4809,7 +4797,7 @@ fi\
%ghost /%{image_install_path}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}\
/lib/modules/%{KVERREL}%{?3:+%{3}}/.vmlinuz.hmac \
%ghost /%{image_install_path}/.vmlinuz-%{KVERREL}%{?3:+%{3}}.hmac \
-%ifarch aarch64 riscv64\
+%ifarch %{dtb_arches}\
/lib/modules/%{KVERREL}%{?3:+%{3}}/dtb \
%ghost /%{image_install_path}/dtb-%{KVERREL}%{?3:+%{3}} \
%endif\
@@ -4899,7 +4887,7 @@ fi\
%ghost %attr(0644, root, root) /boot/symvers-%{KVERREL}%{?3:+%{3}}.%compext\
%ghost %attr(0755, root, root) /%{image_install_path}/%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}\
%ghost %attr(0644, root, root) /%{image_install_path}/.%{?-k:%{-k*}}%{!?-k:vmlinuz}-%{KVERREL}%{?3:+%{3}}.hmac\
-%ifarch aarch64 riscv64\
+%ifarch %{dtb_arches}\
/lib/modules/%{KVERREL}%{?3:+%{3}}/dtb \
%ghost /%{image_install_path}/dtb-%{KVERREL}%{?3:+%{3}} \
%endif\
@@ -4908,7 +4896,7 @@ fi\
%{expand:%%files %{3}}\
%endif\
%if %{with_gcov}\
-%ifnarch %nobuildarches noarch\
+%ifnarch noarch %{nobuildarches}\
%{expand:%%files -f kernel-%{?3:%{3}-}gcov.list %{?3:%{3}-}gcov}\
%endif\
%endif\
@@ -4976,8 +4964,25 @@ fi\
#
#
%changelog
-* Mon Aug 17 2026 Fedora Kernel Team <kernel-team@fedoraproject.org> [7.2.0-61]
-- automotive: enable HUGETLBFS to workaround build error (Scott Weaver)
+* Thu Aug 27 2026 Justin M. Forbes <jforbes@fedoraproject.org> [7.2.1-0]
+- Initial setup for stable Fedora release (Justin M. Forbes)
+- Reset Makefile.rhelver for the 7.3 cycle (Justin M. Forbes)
+- Merge configs into common for 7.2 (Justin M. Forbes)
+- redhat/configs: automotive: enable RTC_DRV_PL031 (Eric Chanudet)
+- redhat: name the dtb and UKI arch lists (Jan Stancek)
+- redhat: use one spelling for the nobuildarches files guard (Jan Stancek)
+- redhat: drop stale ppc64 from the kabidw-base arch list (Jan Stancek)
+- redhat: document the kabichk force-off as a seasonal toggle (Jan Stancek)
+- redhat: use one spelling for the include and gemini conditionals (Jan Stancek)
+- redhat: remove unused elf_image_install_path and duplicate defines (Jan Stancek)
+- redhat: drop the dead kernel-tools __requires_exclude python filter (Jan Stancek)
+- redhat: drop the Fedora 41 cross-build gdb-index workaround (Jan Stancek)
+- redhat: drop stale build switches from dist-perf and dist-rpm-baseonly (Jan Stancek)
+- redhat: give kernel-automotive its own summary (Jan Stancek)
+- redhat: drop leftover kernel_kvm_post calls for rt-64k (Jan Stancek)
+- redhat: restore missing summary of the kernel-debug variant (Jan Stancek)
+- redhat: fix parse error in baseonly sanity check message (Jan Stancek)
+- Linux v7.2.1
* Mon Aug 17 2026 Fedora Kernel Team <kernel-team@fedoraproject.org> [7.2.0-60]
- dracut-virt.conf: change systemd-pcrphase to systemd-pcrextend (Vitaly Kuznetsov)
diff --git a/patch-7.2-redhat.patch b/patch-7.2-redhat.patch
index 798546b..f91510e 100644
--- a/patch-7.2-redhat.patch
+++ b/patch-7.2-redhat.patch
@@ -1,206 +1,50 @@
- Documentation/admin-guide/kernel-parameters.txt | 23 +
- Documentation/admin-guide/rh-waived-items.rst | 29 ++
- Kconfig | 2 +
- Kconfig.redhat | 31 ++
- Makefile | 38 +-
+ Makefile | 30 +++++
arch/arm/Kconfig | 4 +-
arch/arm64/Kconfig | 2 +-
- arch/arm64/kernel/setup.c | 27 +
+ arch/arm64/kernel/setup.c | 27 +++++
arch/s390/include/asm/ipl.h | 1 +
arch/s390/kernel/ipl.c | 5 +
arch/s390/kernel/setup.c | 4 +
- arch/x86/kernel/cpu/common.c | 1 +
- arch/x86/kernel/setup.c | 101 +++-
+ arch/x86/kernel/setup.c | 22 ++--
crypto/akcipher.c | 3 +-
- crypto/dh.c | 25 +
- crypto/seqiv.c | 15 +-
+ crypto/dh.c | 25 ++++
+ crypto/seqiv.c | 15 ++-
crypto/sig.c | 3 +-
crypto/testmgr.c | 6 +-
- drivers/acpi/apei/hest.c | 8 +
- drivers/acpi/irq.c | 17 +-
- drivers/acpi/scan.c | 9 +
- drivers/ata/libahci.c | 18 +
- drivers/char/ipmi/ipmi_dmi.c | 15 +
- drivers/char/ipmi/ipmi_msghandler.c | 16 +-
- drivers/char/random.c | 126 ++++-
+ drivers/acpi/apei/hest.c | 8 ++
+ drivers/acpi/irq.c | 17 ++-
+ drivers/acpi/scan.c | 9 ++
+ drivers/ata/libahci.c | 18 +++
+ drivers/char/ipmi/ipmi_dmi.c | 15 +++
+ drivers/char/ipmi/ipmi_msghandler.c | 16 ++-
+ drivers/char/random.c | 126 ++++++++++++++++++++-
drivers/firmware/efi/Makefile | 1 +
- drivers/firmware/efi/efi.c | 124 +++--
+ drivers/firmware/efi/efi.c | 124 +++++++++++++++-----
drivers/firmware/efi/libstub/fdt.c | 5 +
- drivers/firmware/efi/libstub/secureboot.c | 14 +-
- drivers/firmware/efi/secureboot.c | 38 ++
- drivers/hwtracing/coresight/coresight-etm4x-core.c | 19 +
- drivers/iommu/iommu.c | 22 +
- drivers/message/fusion/mptsas.c | 5 +
- drivers/message/fusion/mptspi.c | 5 +
- drivers/net/wireguard/main.c | 6 +
- drivers/pci/pci-driver.c | 9 +
- drivers/pci/quirks.c | 24 +
- drivers/scsi/hpsa.c | 4 +
- drivers/scsi/qla2xxx/qla_os.c | 6 +
- drivers/scsi/sd.c | 12 +
- drivers/usb/core/hub.c | 7 +
- fs/afs/main.c | 3 +
- fs/erofs/super.c | 9 +
- fs/ext4/super.c | 11 +
+ drivers/firmware/efi/libstub/secureboot.c | 14 ++-
+ drivers/firmware/efi/secureboot.c | 38 +++++++
+ drivers/hwtracing/coresight/coresight-etm4x-core.c | 19 ++++
+ drivers/iommu/iommu.c | 22 ++++
+ drivers/pci/quirks.c | 24 ++++
+ drivers/usb/core/hub.c | 7 ++
include/linux/crypto.h | 2 +
- include/linux/efi.h | 22 +-
- include/linux/kernel.h | 28 ++
+ include/linux/efi.h | 22 ++--
include/linux/lsm_hook_defs.h | 1 +
- include/linux/module.h | 5 +
- include/linux/panic.h | 17 +-
- include/linux/pci.h | 5 +
- include/linux/random.h | 10 +
- include/linux/rh_flags.h | 34 ++
- include/linux/rh_kabi.h | 541 +++++++++++++++++++++
- include/linux/rh_waived.h | 19 +
- include/linux/security.h | 9 +
- init/main.c | 5 +
- kernel/Makefile | 2 +
- kernel/bpf/core.c | 5 +
- kernel/bpf/syscall.c | 23 +
- kernel/module/main.c | 13 +
+ include/linux/random.h | 10 ++
+ include/linux/security.h | 9 ++
kernel/module/signing.c | 9 +-
- kernel/panic.c | 12 +
- kernel/rh_flags.c | 115 +++++
- kernel/rh_messages.c | 414 ++++++++++++++++
- kernel/rh_messages.h | 334 +++++++++++++
- kernel/rh_waived.c | 147 ++++++
scripts/Makefile.lib | 3 +
- scripts/mod/modpost.c | 8 +
scripts/tags.sh | 2 +
security/integrity/platform_certs/load_uefi.c | 6 +-
- security/lockdown/Kconfig | 13 +
- security/lockdown/lockdown.c | 11 +
- tools/testing/selftests/bpf/DENYLIST.rhel | 76 +++
+ security/lockdown/Kconfig | 13 +++
+ security/lockdown/lockdown.c | 11 ++
+ tools/testing/selftests/bpf/DENYLIST.rhel | 76 +++++++++++++
tools/testing/selftests/bpf/Makefile | 2 +-
- tools/testing/selftests/bpf/prog_tests/ksyms_btf.c | 31 --
- 76 files changed, 2669 insertions(+), 108 deletions(-)
+ tools/testing/selftests/bpf/prog_tests/ksyms_btf.c | 31 -----
+ 43 files changed, 701 insertions(+), 106 deletions(-)
-diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt
-index e8ff36982d97..0abff56b135d 100644
---- a/Documentation/admin-guide/kernel-parameters.txt
-+++ b/Documentation/admin-guide/kernel-parameters.txt
-@@ -6641,6 +6641,20 @@ Kernel parameters
- 2 The "airplane mode" button toggles between everything
- blocked and everything unblocked.
-
-+ rh_waived=
-+ Enable waived items in RHEL.
-+
-+ Some specific features, or security mitigations, can be
-+ waived (toggled on/off) on demand in RHEL. However,
-+ waiving any of these items should be used judiciously,
-+ as it generally means the system might end up being
-+ considered insecure or even out-of-scope for support.
-+
-+ Format: <item-1>,<item-2>...<item-n>
-+
-+ Use 'rh_waived' to enable all waived features listed at
-+ Documentation/admin-guide/rh-waived-features.rst
-+
- ring3mwait=disable
- [KNL] Disable ring 3 MONITOR/MWAIT feature on supported
- CPUs.
-@@ -8061,6 +8075,15 @@ Kernel parameters
- unknown_nmi_panic
- [X86] Cause panic on unknown NMI.
-
-+ unprivileged_bpf_disabled=
-+ Format: { "0" | "1" | "2" }
-+ Sets the initial value of
-+ kernel.unprivileged_bpf_disabled sysctl knob.
-+ 0 - unprivileged bpf() syscall access is enabled.
-+ 1 - unprivileged bpf() syscall access is disabled permanently.
-+ 2 - unprivileged bpf() syscall access is disabled.
-+ Default value is 2.
-+
- unwind_debug [X86-64,EARLY]
- Enable unwinder debug output. This can be
- useful for debugging certain unwinder error
-diff --git a/Documentation/admin-guide/rh-waived-items.rst b/Documentation/admin-guide/rh-waived-items.rst
-new file mode 100644
-index 000000000000..7471c891419c
---- /dev/null
-+++ b/Documentation/admin-guide/rh-waived-items.rst
-@@ -0,0 +1,29 @@
-+.. _rh_waived_items:
-+
-+====================
-+Red Hat Waived Items
-+====================
-+
-+Waived Items is a mechanism offered by Red Hat which allows customers to "waive"
-+and utilize features that are not enabled by default as these are considered as
-+unmaintained, insecure, rudimentary, or deprecated, but are shipped with the
-+RHEL kernel for customer's convinience only.
-+Waived Items can range from features that can be enabled on demand to specific
-+security mitigations that can be disabled on demand.
-+
-+To explicitly "waive" any of these items, RHEL offers the ``rh_waived``
-+kernel boot parameter. To allow set of waived items, append
-+``rh_waived=<item name>,...,<item name>`` to the kernel
-+cmdline.
-+Appending ``rh_waived=features`` will waive all features listed below,
-+and appending ``rh_waived=cves`` will waive all security mitigations
-+listed below.
-+
-+The waived items listed in the next session follow the pattern below:
-+
-+- item name
-+ item description
-+
-+List of Red Hat Waived Items
-+============================
-+
-diff --git a/Kconfig b/Kconfig
-index 307e581144de..11e93e479ce4 100644
---- a/Kconfig
-+++ b/Kconfig
-@@ -32,3 +32,5 @@ source "lib/Kconfig.debug"
- source "Documentation/Kconfig"
-
- source "io_uring/Kconfig"
-+
-+source "Kconfig.redhat"
-diff --git a/Kconfig.redhat b/Kconfig.redhat
-new file mode 100644
-index 000000000000..85771d74c34f
---- /dev/null
-+++ b/Kconfig.redhat
-@@ -0,0 +1,31 @@
-+# SPDX-License-Identifier: GPL-2.0-only
-+#
-+# Red Hat specific options
-+#
-+
-+menu "Red Hat options"
-+
-+config RHEL_DIFFERENCES
-+ bool "Enable RHEL-only code"
-+ help
-+ This option controls whether rhel-only changes are enabled during
-+ the build. Unless you want to enable rhel-only changes, say N here.
-+
-+config RH_KABI_SIZE_ALIGN_CHECKS
-+ bool "Enables more stringent kabi checks in the macros"
-+ depends on RHEL_DIFFERENCES
-+ default y
-+ help
-+ This option enables more stringent kabi checks. Those must
-+ be disabled in case of a debug build, because debug builds
-+ allow to change struct sizes.
-+
-+config RH_AUTOMOTIVE
-+ bool "Enable automotive only code"
-+ depends on RHEL_DIFFERENCES
-+ default n
-+ help
-+ This option controls whether code is included in the automotive
-+ kernel build. If you are building an automotive kernel, say Y.
-+
-+endmenu
diff --git a/Makefile b/Makefile
-index ddcc6dca1ece..7c52f4c368ef 100644
+index b36422350995..348c395cdeea 100644
--- a/Makefile
+++ b/Makefile
@@ -358,6 +358,17 @@ ifneq ($(filter install,$(MAKECMDGOALS)),)
@@ -230,22 +74,7 @@ index ddcc6dca1ece..7c52f4c368ef 100644
# KERNELRELEASE can change from a few different places, meaning version.h
# needs to be updated, so this check is forced on all builds
-@@ -1456,7 +1469,13 @@ define filechk_version.h
- ((c) > 255 ? 255 : (c)))'; \
- echo \#define LINUX_VERSION_MAJOR $(VERSION); \
- echo \#define LINUX_VERSION_PATCHLEVEL $(PATCHLEVEL); \
-- echo \#define LINUX_VERSION_SUBLEVEL $(SUBLEVEL)
-+ echo \#define LINUX_VERSION_SUBLEVEL $(SUBLEVEL); \
-+ echo '#define RHEL_MAJOR $(RHEL_MAJOR)'; \
-+ echo '#define RHEL_MINOR $(RHEL_MINOR)'; \
-+ echo '#define RHEL_RELEASE_VERSION(a,b) (((a) << 8) + (b))'; \
-+ echo '#define RHEL_RELEASE_CODE \
-+ $(shell expr $(RHEL_MAJOR) \* 256 + $(RHEL_MINOR))'; \
-+ echo '#define RHEL_RELEASE "$(RHEL_RELEASE)"'
- endef
-
- $(version_h): private PATCHLEVEL := $(or $(PATCHLEVEL), 0)
-@@ -2108,6 +2127,23 @@ endif
+@@ -2108,6 +2121,23 @@ endif
ifdef CONFIG_MODULES
@@ -397,20 +226,8 @@ index b60284328fe3..e4d37b08ca29 100644
/* Have one command line that is parsed and saved in /proc/cmdline */
/* boot_command_line has been already set up in early.c */
*cmdline_p = boot_command_line;
-diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c
-index a3caddd411ec..d654bb2b9c7a 100644
---- a/arch/x86/kernel/cpu/common.c
-+++ b/arch/x86/kernel/cpu/common.c
-@@ -1797,6 +1797,7 @@ static void __init early_identify_cpu(struct cpuinfo_x86 *c)
- get_cpu_vendor(c);
- intel_unlock_cpuid_leafs(c);
- get_cpu_cap(c);
-+ get_model_name(c); /* RHEL: get model name for unsupported check */
- setup_force_cpu_cap(X86_FEATURE_CPUID);
- get_cpu_address_sizes(c);
- cpu_parse_early_param();
diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c
-index 46882ce79c3a..49173ab3fcf7 100644
+index 46882ce79c3a..9c73814c31e0 100644
--- a/arch/x86/kernel/setup.c
+++ b/arch/x86/kernel/setup.c
@@ -21,6 +21,7 @@
@@ -421,98 +238,7 @@ index 46882ce79c3a..49173ab3fcf7 100644
#include <linux/static_call.h>
#include <linux/sysfb.h>
#include <linux/swiotlb.h>
-@@ -57,6 +58,10 @@
- #include <asm/thermal.h>
- #include <asm/unwind.h>
- #include <asm/vsyscall.h>
-+#include <asm/intel-family.h>
-+#if defined(CONFIG_X86_LOCAL_APIC)
-+#include <asm/nmi.h>
-+#endif
-
- /*
- * max_low_pfn_mapped: highest directly mapped pfn < 4 GB
-@@ -825,6 +830,79 @@ static void __init early_reserve_memory(void)
- trim_snb_memory();
- }
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+
-+static void rh_check_supported(void)
-+{
-+ bool guest;
-+
-+ guest = (x86_hyper_type != X86_HYPER_NATIVE || boot_cpu_has(X86_FEATURE_HYPERVISOR));
-+
-+ /* RHEL supports single cpu on guests only */
-+ if (((topology_num_threads_per_package() * __max_threads_per_core) == 1) &&
-+ !guest && !is_kdump_kernel()) {
-+ pr_crit("Detected single cpu native boot.\n");
-+ pr_crit("Important: In this kernel, single threaded, single CPU 64-bit physical systems are unsupported.");
-+ }
-+
-+ /*
-+ * If the RHEL kernel does not support this hardware, the kernel will
-+ * attempt to boot, but no support is provided for this hardware
-+ */
-+ switch (boot_cpu_data.x86_vendor) {
-+ case X86_VENDOR_AMD:
-+ case X86_VENDOR_INTEL:
-+ break;
-+ default:
-+ pr_crit("Detected processor %s %s\n",
-+ boot_cpu_data.x86_vendor_id,
-+ boot_cpu_data.x86_model_id);
-+ break;
-+ }
-+
-+ /*
-+ * Due to the complexity of x86 lapic & ioapic enumeration, and PCI IRQ
-+ * routing, ACPI is required for x86. acpi=off is a valid debug kernel
-+ * parameter, so just print out a loud warning in case something
-+ * goes wrong (which is most of the time).
-+ */
-+ if (acpi_disabled && !guest)
-+ pr_crit("ACPI has been disabled or is not available on this hardware. This may result in a single cpu boot, incorrect PCI IRQ routing, or boot failure.\n");
-+
-+ /*
-+ * x86_64 microarchitecture levels:
-+ * https://en.wikipedia.org/wiki/X86-64#Microarchitecture_levels
-+ *
-+ * RHEL9 has a minimum of the x86_64-v2 microarchitecture
-+ * RHEL10 has a minimum of the x86_64-v3 microarchitecture
-+ */
-+
-+ if (!boot_cpu_has(X86_FEATURE_CX16) || /* CMPXCHG16B */
-+ !boot_cpu_has(X86_FEATURE_LAHF_LM) || /* LAHF-SAHF */
-+ !boot_cpu_has(X86_FEATURE_POPCNT) ||
-+ !boot_cpu_has(X86_FEATURE_XMM3) || /* SSE-3 */
-+ !boot_cpu_has(X86_FEATURE_XMM4_1) || /* SSE4_1 */
-+ !boot_cpu_has(X86_FEATURE_XMM4_2) || /* SSE4_2 */
-+ !boot_cpu_has(X86_FEATURE_SSSE3)) {
-+ mark_hardware_deprecated("x86_64-v1", "%s:%s",
-+ boot_cpu_data.x86_vendor_id, boot_cpu_data.x86_model_id);
-+ } else if (!boot_cpu_has(X86_FEATURE_AVX) ||
-+ !boot_cpu_has(X86_FEATURE_AVX2) ||
-+ !boot_cpu_has(X86_FEATURE_BMI1) ||
-+ !boot_cpu_has(X86_FEATURE_BMI2) ||
-+ !boot_cpu_has(X86_FEATURE_F16C) ||
-+ !boot_cpu_has(X86_FEATURE_FMA) ||
-+ /* LZCNT is not explicitly listed, but appears to be paired with BMI2 */
-+ !boot_cpu_has(X86_FEATURE_MOVBE) ||
-+ !boot_cpu_has(X86_FEATURE_XSAVE)) {
-+ mark_hardware_deprecated("x86_64-v2", "%s:%s",
-+ boot_cpu_data.x86_vendor_id, boot_cpu_data.x86_model_id);
-+ }
-+}
-+#else
-+#define rh_check_supported()
-+#endif
-+
- /*
- * Dump out kernel offset information on panic.
- */
-@@ -995,6 +1073,13 @@ void __init setup_arch(char **cmdline_p)
+@@ -995,6 +996,13 @@ void __init setup_arch(char **cmdline_p)
if (efi_enabled(EFI_BOOT))
efi_init();
@@ -526,7 +252,7 @@ index 46882ce79c3a..49173ab3fcf7 100644
reserve_ibft_region();
x86_init.resources.dmi_setup();
-@@ -1156,19 +1241,7 @@ void __init setup_arch(char **cmdline_p)
+@@ -1156,19 +1164,7 @@ void __init setup_arch(char **cmdline_p)
/* Allocate bigger log buffer */
setup_log_buf(1);
@@ -547,15 +273,6 @@ index 46882ce79c3a..49173ab3fcf7 100644
reserve_initrd();
-@@ -1275,6 +1348,8 @@ void __init setup_arch(char **cmdline_p)
- efi_apply_memmap_quirks();
- #endif
-
-+ rh_check_supported();
-+
- unwind_init();
- }
-
diff --git a/crypto/akcipher.c b/crypto/akcipher.c
index 630bb19738be..8da7eedce31e 100644
--- a/crypto/akcipher.c
@@ -1421,103 +1138,6 @@ index e8f13dcebbde..dd7014ca962c 100644
/**
* iommu_setup_default_domain - Set the default_domain for the group
* @group: Group to change
-diff --git a/drivers/message/fusion/mptsas.c b/drivers/message/fusion/mptsas.c
-index c362f09a8c55..bcda62d89ecd 100644
---- a/drivers/message/fusion/mptsas.c
-+++ b/drivers/message/fusion/mptsas.c
-@@ -5377,6 +5377,10 @@ static void mptsas_remove(struct pci_dev *pdev)
- }
-
- static const struct pci_device_id mptsas_pci_table[] = {
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068,
-+ PCI_VENDOR_ID_VMWARE, PCI_ANY_ID },
-+#else
- { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1064,
- PCI_ANY_ID, PCI_ANY_ID },
- { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068,
-@@ -5389,6 +5393,7 @@ static const struct pci_device_id mptsas_pci_table[] = {
- PCI_ANY_ID, PCI_ANY_ID },
- { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_SAS1068_820XELP,
- PCI_ANY_ID, PCI_ANY_ID },
-+#endif
- {0} /* Terminating entry */
- };
- MODULE_DEVICE_TABLE(pci, mptsas_pci_table);
-diff --git a/drivers/message/fusion/mptspi.c b/drivers/message/fusion/mptspi.c
-index 56892b1f3de2..b0e55913bb2e 100644
---- a/drivers/message/fusion/mptspi.c
-+++ b/drivers/message/fusion/mptspi.c
-@@ -1240,12 +1240,17 @@ static struct spi_function_template mptspi_transport_functions = {
- */
-
- static const struct pci_device_id mptspi_pci_table[] = {
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1030,
-+ PCI_VENDOR_ID_VMWARE, PCI_ANY_ID },
-+#else
- { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1030,
- PCI_ANY_ID, PCI_ANY_ID },
- { PCI_VENDOR_ID_ATTO, MPI_MANUFACTPAGE_DEVID_53C1030,
- PCI_ANY_ID, PCI_ANY_ID },
- { PCI_VENDOR_ID_LSI_LOGIC, MPI_MANUFACTPAGE_DEVID_53C1035,
- PCI_ANY_ID, PCI_ANY_ID },
-+#endif
- {0} /* Terminating entry */
- };
- MODULE_DEVICE_TABLE(pci, mptspi_pci_table);
-diff --git a/drivers/net/wireguard/main.c b/drivers/net/wireguard/main.c
-index a00671b58701..eeef2766b8b3 100644
---- a/drivers/net/wireguard/main.c
-+++ b/drivers/net/wireguard/main.c
-@@ -12,6 +12,7 @@
-
- #include <uapi/linux/wireguard.h>
-
-+#include <linux/fips.h>
- #include <linux/init.h>
- #include <linux/module.h>
- #include <net/genetlink.h>
-@@ -21,6 +22,11 @@ static int __init wg_mod_init(void)
- {
- int ret;
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ if (fips_enabled)
-+ return -EOPNOTSUPP;
-+#endif
-+
- ret = wg_allowedips_slab_init();
- if (ret < 0)
- goto err_allowedips;
-diff --git a/drivers/pci/pci-driver.c b/drivers/pci/pci-driver.c
-index f36778e62ac1..7b4dc4aff7c5 100644
---- a/drivers/pci/pci-driver.c
-+++ b/drivers/pci/pci-driver.c
-@@ -19,6 +19,7 @@
- #include <linux/kexec.h>
- #include <linux/of_device.h>
- #include <linux/acpi.h>
-+#include <linux/kernel.h>
- #include <linux/dma-map-ops.h>
- #include <linux/iommu.h>
- #include "pci.h"
-@@ -329,7 +330,15 @@ static int local_pci_probe(struct drv_dev_and_id *ddi)
- */
- pm_runtime_get_sync(dev);
- pci_dev->driver = pci_drv;
-+
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ rc = -EACCES;
-+ if (!pci_rh_check_status(pci_dev))
-+ rc = pci_drv->probe(pci_dev, ddi->id);
-+#else
- rc = pci_drv->probe(pci_dev, ddi->id);
-+#endif
-+
- if (!rc)
- return rc;
- if (rc < 0) {
diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
index b09f27f7846f..b54fe538511a 100644
--- a/drivers/pci/quirks.c
@@ -1553,94 +1173,6 @@ index b09f27f7846f..b54fe538511a 100644
/*
* Intersil/Techwell TW686[4589]-based video capture cards have an empty (zero)
* class code. Fix it.
-diff --git a/drivers/scsi/hpsa.c b/drivers/scsi/hpsa.c
-index 8edad1830abe..e558acedfa44 100644
---- a/drivers/scsi/hpsa.c
-+++ b/drivers/scsi/hpsa.c
-@@ -82,7 +82,9 @@ MODULE_DESCRIPTION("Driver for HP Smart Array Controller version " \
- HPSA_DRIVER_VERSION);
- MODULE_VERSION(HPSA_DRIVER_VERSION);
- MODULE_LICENSE("GPL");
-+#ifndef CONFIG_RHEL_DIFFERENCES
- MODULE_ALIAS("cciss");
-+#endif
-
- static int hpsa_simple_mode;
- module_param(hpsa_simple_mode, int, S_IRUGO|S_IWUSR);
-@@ -144,10 +146,12 @@ static const struct pci_device_id hpsa_pci_device_id[] = {
- {PCI_VENDOR_ID_HP_3PAR, 0x0075, 0x1590, 0x007D},
- {PCI_VENDOR_ID_HP_3PAR, 0x0075, 0x1590, 0x0088},
- {PCI_VENDOR_ID_HP, 0x333f, 0x103c, 0x333f},
-+#ifndef CONFIG_RHEL_DIFFERENCES
- {PCI_VENDOR_ID_HP, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID,
- PCI_CLASS_STORAGE_RAID << 8, 0xffff << 8, 0},
- {PCI_VENDOR_ID_COMPAQ, PCI_ANY_ID, PCI_ANY_ID, PCI_ANY_ID,
- PCI_CLASS_STORAGE_RAID << 8, 0xffff << 8, 0},
-+#endif
- {0,}
- };
-
-diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c
-index 72b1c28e4dae..2226c9dffa94 100644
---- a/drivers/scsi/qla2xxx/qla_os.c
-+++ b/drivers/scsi/qla2xxx/qla_os.c
-@@ -8128,6 +8128,7 @@ static const struct pci_error_handlers qla2xxx_err_handler = {
- };
-
- static const struct pci_device_id qla2xxx_pci_tbl[] = {
-+#ifndef CONFIG_RHEL_DIFFERENCES
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2100) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2200) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2300) },
-@@ -8140,13 +8141,18 @@ static const struct pci_device_id qla2xxx_pci_tbl[] = {
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8432) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP5422) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP5432) },
-+#endif
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2532) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2031) },
-+#ifndef CONFIG_RHEL_DIFFERENCES
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8001) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8021) },
-+#endif
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8031) },
-+#ifndef CONFIG_RHEL_DIFFERENCES
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISPF001) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP8044) },
-+#endif
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2071) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2271) },
- { PCI_DEVICE(PCI_VENDOR_ID_QLOGIC, PCI_DEVICE_ID_QLOGIC_ISP2261) },
-diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
-index 599e75f33334..ec52c3a4fa14 100644
---- a/drivers/scsi/sd.c
-+++ b/drivers/scsi/sd.c
-@@ -145,6 +145,13 @@ static void sd_large_pool_destroy(void)
- }
- mutex_unlock(&sd_mutex_lock);
- }
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+static char sd_probe_type[6] = "async";
-+module_param_string(probe, sd_probe_type, sizeof(sd_probe_type),
-+ S_IRUGO|S_IWUSR);
-+MODULE_PARM_DESC(probe, "async or sync. Setting to 'sync' disables asynchronous "
-+ "device number assignments (sda, sdb, ...).");
-+#endif
-
- static void sd_disable_discard(struct scsi_disk *sdkp)
- {
-@@ -4460,6 +4467,11 @@ static int __init init_sd(void)
- goto err_out_class;
- }
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ if (!strcmp(sd_probe_type, "sync"))
-+ sd_template.gendrv.probe_type = PROBE_FORCE_SYNCHRONOUS;
-+#endif
-+
- err = scsi_register_driver(&sd_template);
- if (err)
- goto err_out_driver;
diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
index d92bf887739d..039fd5620282 100644
--- a/drivers/usb/core/hub.c
@@ -1659,69 +1191,6 @@ index d92bf887739d..039fd5620282 100644
/* Lock the device, then check to see if we were
* disconnected while waiting for the lock to succeed. */
usb_lock_device(hdev);
-diff --git a/fs/afs/main.c b/fs/afs/main.c
-index 7a883c59976f..907ec60e500a 100644
---- a/fs/afs/main.c
-+++ b/fs/afs/main.c
-@@ -194,6 +194,9 @@ static int __init afs_init(void)
- goto error_proc;
- }
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ mark_partner_supported(KBUILD_MODNAME, THIS_MODULE);
-+#endif
- return ret;
-
- error_proc:
-diff --git a/fs/erofs/super.c b/fs/erofs/super.c
-index 9d8f862f309f..3e1ede3e4f7b 100644
---- a/fs/erofs/super.c
-+++ b/fs/erofs/super.c
-@@ -599,6 +599,9 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
- {
- struct inode *inode;
- struct erofs_sb_info *sbi = EROFS_SB(sb);
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ static bool printed = false;
-+#endif
- int err;
-
- sb->s_magic = EROFS_SUPER_MAGIC;
-@@ -738,6 +741,12 @@ static int erofs_fc_fill_super(struct super_block *sb, struct fs_context *fc)
-
- sbi->dir_ra_bytes = EROFS_DIR_RA_BYTES;
- erofs_info(sb, "mounted with root inode @ nid %llu.", sbi->root_nid);
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ if (!printed) {
-+ mark_tech_preview("EROFS filesystem", NULL);
-+ printed = true;
-+ }
-+#endif
- return 0;
- }
-
-diff --git a/fs/ext4/super.c b/fs/ext4/super.c
-index 245f67d10ded..f1e49d37b270 100644
---- a/fs/ext4/super.c
-+++ b/fs/ext4/super.c
-@@ -5739,6 +5739,17 @@ static int __ext4_fill_super(struct fs_context *fc, struct super_block *sb)
- atomic_set(&sbi->s_warning_count, 0);
- atomic_set(&sbi->s_msg_count, 0);
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ if (ext4_has_feature_verity(sb)) {
-+ static bool printed = false;
-+
-+ if (!printed) {
-+ mark_tech_preview("fs-verity on ext4", NULL);
-+ printed = true;
-+ }
-+ }
-+#endif
-+
- /* Register sysfs after all initializations are complete. */
- err = ext4_register_sysfs(sb);
- if (err)
diff --git a/include/linux/crypto.h b/include/linux/crypto.h
index b7c97f1c47c9..0a484f45b24a 100644
--- a/include/linux/crypto.h
@@ -1803,43 +1272,6 @@ index ccbc35479684..8eb9a1276ba7 100644
static inline
enum efi_secureboot_mode efi_get_secureboot_mode(efi_get_variable_t *get_var)
{
-diff --git a/include/linux/kernel.h b/include/linux/kernel.h
-index e5570a16cbb1..82945b474e2e 100644
---- a/include/linux/kernel.h
-+++ b/include/linux/kernel.h
-@@ -194,4 +194,32 @@ extern enum system_states system_state;
- # define REBUILD_DUE_TO_DYNAMIC_FTRACE
- #endif
-
-+/* Permissions on a sysfs file: you didn't miss the 0 prefix did you? */
-+#define VERIFY_OCTAL_PERMISSIONS(perms) \
-+ (BUILD_BUG_ON_ZERO((perms) < 0) + \
-+ BUILD_BUG_ON_ZERO((perms) > 0777) + \
-+ /* USER_READABLE >= GROUP_READABLE >= OTHER_READABLE */ \
-+ BUILD_BUG_ON_ZERO((((perms) >> 6) & 4) < (((perms) >> 3) & 4)) + \
-+ BUILD_BUG_ON_ZERO((((perms) >> 3) & 4) < ((perms) & 4)) + \
-+ /* USER_WRITABLE >= GROUP_WRITABLE */ \
-+ BUILD_BUG_ON_ZERO((((perms) >> 6) & 2) < (((perms) >> 3) & 2)) + \
-+ /* OTHER_WRITABLE? Generally considered a bad idea. */ \
-+ BUILD_BUG_ON_ZERO((perms) & 2) + \
-+ (perms))
-+
-+struct module;
-+
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+void mark_hardware_unmaintained(const char *driver_name, char *fmt, ...);
-+void mark_hardware_deprecated(const char *driver_name, char *fmt, ...);
-+void mark_tech_preview(const char *msg, struct module *mod);
-+void mark_partner_supported(const char *msg, struct module *mod);
-+void init_rh_check_status(char *fn_name);
-+#else
-+static inline void mark_hardware_unmaintained(const char *driver_name, char *fmt, ...) { }
-+static inline void mark_hardware_deprecated(const char *driver_name, char *fmt, ...) { }
-+static inline void mark_tech_preview(const char *msg, struct module *mod) { }
-+static inline void mark_partner_supported(const char *msg, struct module *mod) { }
-+#endif
-+
- #endif
diff --git a/include/linux/lsm_hook_defs.h b/include/linux/lsm_hook_defs.h
index 65c9609ec207..2cc243ec73f6 100644
--- a/include/linux/lsm_hook_defs.h
@@ -1852,80 +1284,6 @@ index 65c9609ec207..2cc243ec73f6 100644
#ifdef CONFIG_PERF_EVENTS
LSM_HOOK(int, 0, perf_event_open, int type)
LSM_HOOK(int, 0, perf_event_alloc, struct perf_event *event)
-diff --git a/include/linux/module.h b/include/linux/module.h
-index 7566815fabbe..f18af7fdb45b 100644
---- a/include/linux/module.h
-+++ b/include/linux/module.h
-@@ -413,6 +413,7 @@ struct module {
- struct module_attribute *modinfo_attrs;
- const char *version;
- const char *srcversion;
-+ const char *rhelversion;
- const char *imported_namespaces;
- struct kobject *holders_dir;
-
-@@ -1020,6 +1021,10 @@ static inline unsigned long find_kallsyms_symbol_value(struct module *mod,
-
- #endif /* CONFIG_MODULES && CONFIG_KALLSYMS */
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+void module_rh_check_status(const char * module_name);
-+#endif
-+
- /* Define __free(module_put) macro for struct module *. */
- DEFINE_FREE(module_put, struct module *, if (_T) module_put(_T))
-
-diff --git a/include/linux/panic.h b/include/linux/panic.h
-index f1dd417e54b2..95344281ed2c 100644
---- a/include/linux/panic.h
-+++ b/include/linux/panic.h
-@@ -88,7 +88,22 @@ static inline void set_arch_panic_timeout(int timeout, int arch_default_timeout)
- #define TAINT_RANDSTRUCT 17
- #define TAINT_TEST 18
- #define TAINT_FWCTL 19
--#define TAINT_FLAGS_COUNT 20
-+/* Start of Red Hat-specific taint flags */
-+#define TAINT_20 20
-+#define TAINT_21 21
-+#define TAINT_22 22
-+#define TAINT_23 23
-+#define TAINT_24 24
-+#define TAINT_25 25
-+#define TAINT_PARTNER_SUPPORTED 26
-+#define TAINT_SUPPORT_REMOVED 27
-+/* Bits 28 - 31 are reserved for Red Hat use only */
-+#define TAINT_RESERVED28 28
-+#define TAINT_RESERVED29 29
-+#define TAINT_RESERVED30 30
-+#define TAINT_UNPRIVILEGED_BPF 31
-+/* End of Red Hat-specific taint flags */
-+#define TAINT_FLAGS_COUNT 32
- #define TAINT_FLAGS_MAX ((1UL << TAINT_FLAGS_COUNT) - 1)
-
- struct taint_flag {
-diff --git a/include/linux/pci.h b/include/linux/pci.h
-index 64b308b6e61c..0967f9be0b54 100644
---- a/include/linux/pci.h
-+++ b/include/linux/pci.h
-@@ -1715,6 +1715,7 @@ int pci_add_dynid(struct pci_driver *drv,
- unsigned long driver_data);
- const struct pci_device_id *pci_match_id(const struct pci_device_id *ids,
- struct pci_dev *dev);
-+
- int pci_scan_bridge(struct pci_bus *bus, struct pci_dev *dev, int max,
- int pass);
-
-@@ -2879,6 +2880,10 @@ static inline bool pci_is_thunderbolt_attached(struct pci_dev *pdev)
- return false;
- }
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+bool pci_rh_check_status(struct pci_dev *pci_dev);
-+#endif
-+
- #if defined(CONFIG_PCIEPORTBUS) || defined(CONFIG_EEH) || defined(CONFIG_S390)
- void pci_uevent_ers(struct pci_dev *pdev, enum pci_ers_result err_type);
- #endif
diff --git a/include/linux/random.h b/include/linux/random.h
index 8a8064dc3970..3238fab8f749 100644
--- a/include/linux/random.h
@@ -1954,791 +1312,24 @@ index 8a8064dc3970..3238fab8f749 100644
#ifndef MODULE
extern const struct file_operations random_fops, urandom_fops;
#endif
-diff --git a/include/linux/rh_flags.h b/include/linux/rh_flags.h
-new file mode 100644
-index 000000000000..4bb0f5585df0
---- /dev/null
-+++ b/include/linux/rh_flags.h
-@@ -0,0 +1,34 @@
-+/* SPDX-License-Identifier: GPL-2.0 */
-+/*
-+ * rh_flags.h -- Red Hat flags tracking
-+ *
-+ * Copyright (c) 2018 Red Hat, Inc. -- Jiri Benc <jbenc@redhat.com>
-+ *
-+ * The intent of the flag tracking is to provide better and more focused
-+ * support. Only those flags that are of a special interest for customer
-+ * support should be tracked.
-+ *
-+ * THE FLAGS DO NOT EXPRESS ANY SUPPORT POLICIES.
-+ */
-+
-+#ifndef _LINUX_RH_FLAGS_H
-+#define _LINUX_RH_FLAGS_H
-+
-+#if defined CONFIG_RHEL_DIFFERENCES
-+bool __rh_add_flag(const char *flag_name);
-+void rh_print_flags(void);
-+
-+#define rh_add_flag(flag_name) \
-+({ \
-+ static bool __mark_once __read_mostly; \
-+ bool __ret_mark_once = !__mark_once; \
-+ \
-+ if (!__mark_once) \
-+ __mark_once = __rh_add_flag(flag_name); \
-+ unlikely(__ret_mark_once); \
-+})
+diff --git a/include/linux/security.h b/include/linux/security.h
+index 153e9043058f..2ee3a8990968 100644
+--- a/include/linux/security.h
++++ b/include/linux/security.h
+@@ -2439,4 +2439,13 @@ static inline void security_initramfs_populated(void)
+ }
+ #endif /* CONFIG_SECURITY */
+
++#ifdef CONFIG_SECURITY_LOCKDOWN_LSM
++extern int security_lock_kernel_down(const char *where, enum lockdown_reason level);
+#else
-+static inline void rh_print_flags(void) { }
-+static inline void rh_add_flag(const char *flag_name) { }
-+#endif
-+#endif
-diff --git a/include/linux/rh_kabi.h b/include/linux/rh_kabi.h
-new file mode 100644
-index 000000000000..5139cb2cabdc
---- /dev/null
-+++ b/include/linux/rh_kabi.h
-@@ -0,0 +1,541 @@
-+/*
-+ * rh_kabi.h - Red Hat kABI abstraction header
-+ *
-+ * Copyright (c) 2014 Don Zickus
-+ * Copyright (c) 2015-2020 Jiri Benc
-+ * Copyright (c) 2015 Sabrina Dubroca, Hannes Frederic Sowa
-+ * Copyright (c) 2016-2018 Prarit Bhargava
-+ * Copyright (c) 2017 Paolo Abeni, Larry Woodman
-+ *
-+ * This file is released under the GPLv2.
-+ * See the file COPYING for more details.
-+ *
-+ * These kabi macros hide the changes from the kabi checker and from the
-+ * process that computes the exported symbols' checksums.
-+ * They have 2 variants: one (defined under __GENKSYMS__) used when
-+ * generating the checksums, and the other used when building the kernel's
-+ * binaries.
-+ *
-+ * The use of these macros does not guarantee that the usage and modification
-+ * of code is correct. As with all Red Hat only changes, an engineer must
-+ * explain why the use of the macro is valid in the patch containing the
-+ * changes.
-+ *
-+ */
-+
-+#ifndef _LINUX_RH_KABI_H
-+#define _LINUX_RH_KABI_H
-+
-+#include <linux/kconfig.h>
-+#include <linux/compiler.h>
-+#include <linux/stringify.h>
-+
-+/*
-+ * NOTE
-+ * Unless indicated otherwise, don't use ';' after these macros as it
-+ * messes up the kABI checker by changing what the resulting token string
-+ * looks like. Instead let the macros add the ';' so it can be properly
-+ * hidden from the kABI checker (mainly for RH_KABI_EXTEND, but applied to
-+ * most macros for uniformity).
-+ *
-+ *
-+ * RH_KABI_CONST
-+ * Adds a new const modifier to a function parameter preserving the old
-+ * checksum.
-+ *
-+ * RH_KABI_ADD_MODIFIER
-+ * Adds a new modifier to a function parameter or a typedef, preserving
-+ * the old checksum. Useful e.g. for adding rcu annotations or changing
-+ * int to unsigned. Beware that this may change the semantics; if you're
-+ * sure this is safe, always explain why binary compatibility with 3rd
-+ * party modules is retained.
-+ *
-+ * RH_KABI_DEPRECATE
-+ * Marks the element as deprecated and make it unusable by modules while
-+ * keeping a hole in its place to preserve binary compatibility.
-+ *
-+ * RH_KABI_DEPRECATE_FN
-+ * Marks the function pointer as deprecated and make it unusable by modules
-+ * while keeping a hole in its place to preserve binary compatibility.
-+ *
-+ * RH_KABI_EXTEND
-+ * Adds a new field to a struct. This must always be added to the end of
-+ * the struct. Before using this macro, make sure this is actually safe
-+ * to do - there is a number of conditions under which it is *not* safe.
-+ * In particular (but not limited to), this macro cannot be used:
-+ * - if the struct in question is embedded in another struct, or
-+ * - if the struct is allocated by drivers either statically or
-+ * dynamically, or
-+ * - if the struct is allocated together with driver data (an example of
-+ * such behavior is struct net_device or struct request).
-+ *
-+ * RH_KABI_EXTEND_WITH_SIZE
-+ * Adds a new element (usually a struct) to a struct and reserves extra
-+ * space for the new element. The provided 'size' is the total space to
-+ * be added in longs (i.e. it's 8 * 'size' bytes), including the size of
-+ * the added element. It is automatically checked that the new element
-+ * does not overflow the reserved space, now nor in the future. However,
-+ * no attempt is done to check the content of the added element (struct)
-+ * for kABI conformance - kABI checking inside the added element is
-+ * effectively switched off.
-+ * For any struct being added by RH_KABI_EXTEND_WITH_SIZE, it is
-+ * recommended its content to be documented as not covered by kABI
-+ * guarantee.
-+ *
-+ * RH_KABI_FILL_HOLE
-+ * Fills a hole in a struct.
-+ *
-+ * Warning: only use if a hole exists for _all_ arches. Use pahole to verify.
-+ *
-+ * RH_KABI_RENAME
-+ * Renames an element without changing its type. This macro can be used in
-+ * bitfields, for example.
-+ *
-+ * NOTE: this macro does not add the final ';'
-+ *
-+ * RH_KABI_REPLACE
-+ * Replaces the _orig field by the _new field. The size of the occupied
-+ * space is preserved, it's fine if the _new field is smaller than the
-+ * _orig field. If a _new field is larger or has a different alignment,
-+ * compilation will abort.
-+ *
-+ * RH_KABI_REPLACE_SPLIT
-+ * Works the same as RH_KABI_REPLACE but replaces a single _orig field by
-+ * multiple new fields. The checks for size and alignment done by
-+ * RH_KABI_REPLACE are still applied.
-+ *
-+ * RH_KABI_HIDE_INCLUDE
-+ * Hides the given include file from kABI checksum computations. This is
-+ * used when a newly added #include makes a previously opaque struct
-+ * visible.
-+ *
-+ * Example usage:
-+ * #include RH_KABI_HIDE_INCLUDE(<linux/poll.h>)
-+ *
-+ * RH_KABI_FAKE_INCLUDE
-+ * Pretends inclusion of the given file for kABI checksum computations.
-+ * This is used when upstream removed a particular #include but that made
-+ * some structures opaque that were previously visible and is causing kABI
-+ * checker failures.
-+ *
-+ * Example usage:
-+ * #include RH_KABI_FAKE_INCLUDE(<linux/rhashtable.h>)
-+ *
-+ * RH_KABI_RESERVE
-+ * Adds a reserved field to a struct. This is done prior to kABI freeze
-+ * for structs that cannot be expanded later using RH_KABI_EXTEND (for
-+ * example because they are embedded in another struct or because they are
-+ * allocated by drivers or because they use unusual memory layout). The
-+ * size of the reserved field is 'unsigned long' and is assumed to be
-+ * 8 bytes.
-+ *
-+ * The argument is a number unique for the given struct; usually, multiple
-+ * RH_KABI_RESERVE macros are added to a struct with numbers starting from
-+ * one.
-+ *
-+ * Example usage:
-+ * struct foo {
-+ * int a;
-+ * RH_KABI_RESERVE(1)
-+ * RH_KABI_RESERVE(2)
-+ * RH_KABI_RESERVE(3)
-+ * RH_KABI_RESERVE(4)
-+ * };
-+ *
-+ * RH_KABI_USE
-+ * Uses a previously reserved field or multiple fields. The arguments are
-+ * one or more numbers assigned to RH_KABI_RESERVE, followed by a field to
-+ * be put in their place. The compiler ensures that the new field is not
-+ * larger than the reserved area.
-+ *
-+ * Example usage:
-+ * struct foo {
-+ * int a;
-+ * RH_KABI_USE(1, int b)
-+ * RH_KABI_USE(2, 3, int c[3])
-+ * RH_KABI_RESERVE(4)
-+ * };
-+ *
-+ * RH_KABI_USE_SPLIT
-+ * Works the same as RH_KABI_USE but replaces a single reserved field by
-+ * multiple new fields.
-+ *
-+ * RH_KABI_AUX_EMBED
-+ * RH_KABI_AUX_PTR
-+ * Adds an extenstion of a struct in the form of "auxiliary structure".
-+ * This is done prior to kABI freeze for structs that cannot be expanded
-+ * later using RH_KABI_EXTEND. See also RH_KABI_RESERVED, these two
-+ * approaches can (and often are) combined.
-+ *
-+ * To use this for 'struct foo' (the "base structure"), define a new
-+ * structure called 'struct foo_rh'; this new struct is called "auxiliary
-+ * structure". Then add RH_KABI_AUX_EMBED or RH_KABI_AUX_PTR to the end
-+ * of the base structure. The argument is the name of the base structure,
-+ * without the 'struct' keyword.
-+ *
-+ * RH_KABI_AUX_PTR stores a pointer to the aux structure in the base
-+ * struct. The lifecycle of the aux struct needs to be properly taken
-+ * care of.
-+ *
-+ * RH_KABI_AUX_EMBED embeds the aux struct into the base struct. This
-+ * cannot be used when the base struct is itself embedded into another
-+ * struct, allocated in an array, etc.
-+ *
-+ * Both approaches (ptr and embed) work correctly even when the aux struct
-+ * is allocated by modules. To ensure this, the code responsible for
-+ * allocation/assignment of the aux struct has to properly set the size of
-+ * the aux struct; see the RH_KABI_AUX_SET_SIZE and RH_KABI_AUX_INIT_SIZE
-+ * macros.
-+ *
-+ * New fields can be later added to the auxiliary structure, always to its
-+ * end. Note the auxiliary structure cannot be shrunk in size later (i.e.,
-+ * fields cannot be removed, only deprecated). Any code accessing fields
-+ * from the aux struct must guard the access using the RH_KABI_AUX macro.
-+ * The access itself is then done via a '_rh' field in the base struct.
-+ *
-+ * The auxiliary structure is not guaranteed for access by modules unless
-+ * explicitly commented as such in the declaration of the aux struct
-+ * itself or some of its elements.
-+ *
-+ * Example:
-+ *
-+ * struct foo_rh {
-+ * int newly_added;
-+ * };
-+ *
-+ * struct foo {
-+ * bool big_hammer;
-+ * RH_KABI_AUX_PTR(foo)
-+ * };
-+ *
-+ * void use(struct foo *f)
-+ * {
-+ * if (RH_KABI_AUX(f, foo, newly_added))
-+ * f->_rh->newly_added = 123;
-+ * else
-+ * // the field 'newly_added' is not present in the passed
-+ * // struct, fall back to old behavior
-+ * f->big_hammer = true;
-+ * }
-+ *
-+ * static struct foo_rh my_foo_rh {
-+ * .newly_added = 0;
-+ * }
-+ *
-+ * static struct foo my_foo = {
-+ * .big_hammer = false,
-+ * ._rh = &my_foo_rh,
-+ * RH_KABI_AUX_INIT_SIZE(foo)
-+ * };
-+ *
-+ * RH_KABI_USE_AUX_PTR
-+ * Creates an auxiliary structure post kABI freeze. This works by using
-+ * two reserved fields (thus there has to be two reserved fields still
-+ * available) and converting them to RH_KABI_AUX_PTR.
-+ *
-+ * Example:
-+ *
-+ * struct foo_rh {
-+ * };
-+ *
-+ * struct foo {
-+ * int a;
-+ * RH_KABI_RESERVE(1)
-+ * RH_KABI_USE_AUX_PTR(2, 3, foo)
-+ * };
-+ *
-+ * RH_KABI_AUX_SET_SIZE
-+ * RH_KABI_AUX_INIT_SIZE
-+ * Calculates and stores the size of the auxiliary structure.
-+ *
-+ * RH_KABI_AUX_SET_SIZE is for dynamically allocated base structs,
-+ * RH_KABI_AUX_INIT_SIZE is for statically allocated case structs.
-+ *
-+ * These macros must be called from the allocation (RH_KABI_AUX_SET_SIZE)
-+ * or declaration (RH_KABI_AUX_INIT_SIZE) site, regardless of whether
-+ * that happens in the kernel or in a module. Without calling one of
-+ * these macros, the aux struct will appear to have no fields to the
-+ * kernel.
-+ *
-+ * Note: since RH_KABI_AUX_SET_SIZE is intended to be invoked outside of
-+ * a struct definition, it does not add the semicolon and must be
-+ * terminated by semicolon by the caller.
-+ *
-+ * RH_KABI_AUX
-+ * Verifies that the given field exists in the given auxiliary structure.
-+ * This MUST be called prior to accessing that field; failing to do that
-+ * may lead to invalid memory access.
-+ *
-+ * The first argument is a pointer to the base struct, the second argument
-+ * is the name of the base struct (without the 'struct' keyword), the
-+ * third argument is the field name.
-+ *
-+ * This macro works for structs extended by either of RH_KABI_AUX_EMBED,
-+ * RH_KABI_AUX_PTR and RH_KABI_USE_AUX_PTR.
-+ *
-+ * RH_KABI_FORCE_CHANGE
-+ * Force change of the symbol checksum. The argument of the macro is a
-+ * version for cases we need to do this more than once.
-+ *
-+ * This macro does the opposite: it changes the symbol checksum without
-+ * actually changing anything about the exported symbol. It is useful for
-+ * symbols that are not whitelisted, we're changing them in an
-+ * incompatible way and want to prevent 3rd party modules to silently
-+ * corrupt memory. Instead, by changing the symbol checksum, such modules
-+ * won't be loaded by the kernel. This macro should only be used as a
-+ * last resort when all other KABI workarounds have failed.
-+ *
-+ * RH_KABI_EXCLUDE
-+ * !!! WARNING: DANGEROUS, DO NOT USE unless you are aware of all the !!!
-+ * !!! implications. This should be used ONLY EXCEPTIONALLY and only !!!
-+ * !!! under specific circumstances. Very likely, this macro does not !!!
-+ * !!! do what you expect it to do. Note that any usage of this macro !!!
-+ * !!! MUST be paired with a RH_KABI_FORCE_CHANGE annotation of !!!
-+ * !!! a suitable symbol (or an equivalent safeguard) and the commit !!!
-+ * !!! log MUST explain why the chosen solution is appropriate. !!!
-+ *
-+ * Exclude the element from checksum generation. Any such element is
-+ * considered not to be part of the kABI whitelist and may be changed at
-+ * will. Note however that it's the responsibility of the developer
-+ * changing the element to ensure 3rd party drivers using this element
-+ * won't panic, for example by not allowing them to be loaded. That can
-+ * be achieved by changing another, non-whitelisted symbol they use,
-+ * either by nature of the change or by using RH_KABI_FORCE_CHANGE.
-+ *
-+ * Also note that any change to the element must preserve its size. Change
-+ * of the size is not allowed and would constitute a silent kABI breakage.
-+ * Beware that the RH_KABI_EXCLUDE macro does not do any size checks.
-+ *
-+ * RH_KABI_EXCLUDE_WITH_SIZE
-+ * Like RH_KABI_EXCLUDE, this macro excludes the element from
-+ * checksum generation. The same warnings as for RH_KABI_EXCLUDE
-+ * apply: use RH_KABI_FORCE_CHANGE.
-+ *
-+ * This macro is intended to be used for elements embedded inside
-+ * kABI-protected structures (struct, array). In contrast with
-+ * RH_KABI_EXCLUDE, this macro reserves extra space, so that the
-+ * embedded element can grow without changing the offsets of the
-+ * fields that follow. The provided 'size' is the total space to be
-+ * added in longs (i.e. it's 8 * 'size' bytes), including the size
-+ * of the added element. It is automatically checked that the new
-+ * element does not overflow the reserved space, now nor in the
-+ * future. The size is also included in the checksum via the
-+ * reserved space, to ensure that we don't accidentally change it,
-+ * which would change the offsets of the fields that follow.
-+ *
-+ * RH_KABI_BROKEN_INSERT
-+ * RH_KABI_BROKEN_REMOVE
-+ * Insert a field to the middle of a struct / delete a field from a struct.
-+ * Note that this breaks kABI! It can be done only when it's certain that
-+ * no 3rd party driver can validly reach into the struct. A typical
-+ * example is a struct that is: both (a) referenced only through a long
-+ * chain of pointers from another struct that is part of a whitelisted
-+ * symbol and (b) kernel internal only, it should have never been visible
-+ * to genksyms in the first place.
-+ *
-+ * Another example are structs that are explicitly exempt from kABI
-+ * guarantee but we did not have enough foresight to use RH_KABI_EXCLUDE.
-+ * In this case, the warning for RH_KABI_EXCLUDE applies.
-+ *
-+ * A detailed explanation of correctness of every RH_KABI_BROKEN_* macro
-+ * use is especially important.
-+ *
-+ * RH_KABI_BROKEN_INSERT_BLOCK
-+ * RH_KABI_BROKEN_REMOVE_BLOCK
-+ * A version of RH_KABI_BROKEN_INSERT / REMOVE that allows multiple fields
-+ * to be inserted or removed together. All fields need to be terminated
-+ * by ';' inside(!) the macro parameter. The macro itself must not be
-+ * terminated by ';'.
-+ *
-+ * RH_KABI_BROKEN_REPLACE
-+ * Replace a field by a different one without doing any checking. This
-+ * allows replacing a field by another with a different size. Similarly
-+ * to other RH_KABI_BROKEN macros, use of this indicates a kABI breakage.
-+ *
-+ * RH_KABI_BROKEN_INSERT_ENUM
-+ * RH_KABI_BROKEN_REMOVE_ENUM
-+ * Insert a field to the middle of an enumaration type / delete a field from
-+ * an enumaration type. Note that this can break kABI especially if the
-+ * number of enum fields is used in an array within a structure. It can be
-+ * done only when it is certain that no 3rd party driver will use the
-+ * enumeration type or a structure that embeds an array with size determined
-+ * by an enumeration type.
-+ *
-+ * RH_KABI_EXTEND_ENUM
-+ * Adds a new field to an enumeration type. This must always be added to
-+ * the end of the enum. Before using this macro, make sure this is actually
-+ * safe to do.
-+ */
-+
-+#undef linux
-+#define linux linux
-+
-+#ifdef __GENKSYMS__
-+
-+# define RH_KABI_CONST
-+# define RH_KABI_ADD_MODIFIER(_new)
-+# define RH_KABI_EXTEND(_new)
-+# define RH_KABI_FILL_HOLE(_new)
-+# define RH_KABI_FORCE_CHANGE(ver) __attribute__((rh_kabi_change ## ver))
-+# define RH_KABI_RENAME(_orig, _new) _orig
-+# define RH_KABI_HIDE_INCLUDE(_file) <linux/rh_kabi.h>
-+# define RH_KABI_FAKE_INCLUDE(_file) _file
-+# define RH_KABI_BROKEN_INSERT(_new)
-+# define RH_KABI_BROKEN_REMOVE(_orig) _orig;
-+# define RH_KABI_BROKEN_INSERT_BLOCK(_new)
-+# define RH_KABI_BROKEN_REMOVE_BLOCK(_orig) _orig
-+# define RH_KABI_BROKEN_REPLACE(_orig, _new) _orig;
-+# define RH_KABI_BROKEN_INSERT_ENUM(_new)
-+# define RH_KABI_BROKEN_REMOVE_ENUM(_orig) _orig,
-+# define RH_KABI_EXTEND_ENUM(_new)
-+
-+# define _RH_KABI_DEPRECATE(_type, _orig) _type _orig
-+# define _RH_KABI_DEPRECATE_FN(_type, _orig, _args...) _type (*_orig)(_args)
-+# define _RH_KABI_REPLACE(_orig, _new) _orig
-+# define _RH_KABI_EXCLUDE(_elem)
-+
-+# define __RH_KABI_CHECK_SIZE(_item, _size)
-+
-+#else
-+
-+# define RH_KABI_ALIGN_WARNING ". Disable CONFIG_RH_KABI_SIZE_ALIGN_CHECKS if debugging."
-+
-+# define RH_KABI_CONST const
-+# define RH_KABI_ADD_MODIFIER(_new) _new
-+# define RH_KABI_EXTEND(_new) _new;
-+# define RH_KABI_FILL_HOLE(_new) _new;
-+# define RH_KABI_FORCE_CHANGE(ver)
-+# define RH_KABI_RENAME(_orig, _new) _new
-+# define RH_KABI_HIDE_INCLUDE(_file) _file
-+# define RH_KABI_FAKE_INCLUDE(_file) <linux/rh_kabi.h>
-+# define RH_KABI_BROKEN_INSERT(_new) _new;
-+# define RH_KABI_BROKEN_REMOVE(_orig)
-+# define RH_KABI_BROKEN_INSERT_BLOCK(_new) _new
-+# define RH_KABI_BROKEN_REMOVE_BLOCK(_orig)
-+# define RH_KABI_BROKEN_REPLACE(_orig, _new) _new;
-+# define RH_KABI_BROKEN_INSERT_ENUM(_new) _new,
-+# define RH_KABI_BROKEN_REMOVE_ENUM(_orig)
-+# define RH_KABI_EXTEND_ENUM(_new) _new,
-+
-+#if IS_BUILTIN(CONFIG_RH_KABI_SIZE_ALIGN_CHECKS)
-+# define __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new) \
-+ union { \
-+ _Static_assert(sizeof(struct{_new;}) <= sizeof(struct{_orig;}), \
-+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_new) " is larger than " __stringify(_orig) RH_KABI_ALIGN_WARNING); \
-+ _Static_assert(__alignof__(struct{_new;}) <= __alignof__(struct{_orig;}), \
-+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_orig) " is not aligned the same as " __stringify(_new) RH_KABI_ALIGN_WARNING); \
-+ }
-+# define __RH_KABI_CHECK_SIZE(_item, _size) \
-+ _Static_assert(sizeof(struct{_item;}) <= _size, \
-+ __FILE__ ":" __stringify(__LINE__) ": " __stringify(_item) " is larger than the reserved size (" __stringify(_size) " bytes)" RH_KABI_ALIGN_WARNING);
-+#else
-+# define __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new)
-+# define __RH_KABI_CHECK_SIZE(_item, _size)
-+#endif
-+
-+#define RH_KABI_UNIQUE_ID __PASTE(rh_kabi_hidden_, __LINE__)
-+
-+# define _RH_KABI_DEPRECATE(_type, _orig) _type rh_reserved_##_orig
-+# define _RH_KABI_DEPRECATE_FN(_type, _orig, _args...) \
-+ _type (* rh_reserved_##_orig)(_args)
-+# define _RH_KABI_REPLACE(_orig, _new) \
-+ union { \
-+ _new; \
-+ struct { \
-+ _orig; \
-+ } RH_KABI_UNIQUE_ID; \
-+ __RH_KABI_CHECK_SIZE_ALIGN(_orig, _new); \
-+ }
-+
-+# define _RH_KABI_EXCLUDE(_elem) _elem
-+
-+#endif /* __GENKSYMS__ */
-+
-+# define RH_KABI_DEPRECATE(_type, _orig) _RH_KABI_DEPRECATE(_type, _orig);
-+# define RH_KABI_DEPRECATE_FN(_type, _orig, _args...) \
-+ _RH_KABI_DEPRECATE_FN(_type, _orig, _args);
-+# define RH_KABI_REPLACE(_orig, _new) _RH_KABI_REPLACE(_orig, _new);
-+
-+#define _RH_KABI_REPLACE1(_new) _new;
-+#define _RH_KABI_REPLACE2(_new, ...) _new; _RH_KABI_REPLACE1(__VA_ARGS__)
-+#define _RH_KABI_REPLACE3(_new, ...) _new; _RH_KABI_REPLACE2(__VA_ARGS__)
-+#define _RH_KABI_REPLACE4(_new, ...) _new; _RH_KABI_REPLACE3(__VA_ARGS__)
-+#define _RH_KABI_REPLACE5(_new, ...) _new; _RH_KABI_REPLACE4(__VA_ARGS__)
-+#define _RH_KABI_REPLACE6(_new, ...) _new; _RH_KABI_REPLACE5(__VA_ARGS__)
-+#define _RH_KABI_REPLACE7(_new, ...) _new; _RH_KABI_REPLACE6(__VA_ARGS__)
-+#define _RH_KABI_REPLACE8(_new, ...) _new; _RH_KABI_REPLACE7(__VA_ARGS__)
-+#define _RH_KABI_REPLACE9(_new, ...) _new; _RH_KABI_REPLACE8(__VA_ARGS__)
-+#define _RH_KABI_REPLACE10(_new, ...) _new; _RH_KABI_REPLACE9(__VA_ARGS__)
-+#define _RH_KABI_REPLACE11(_new, ...) _new; _RH_KABI_REPLACE10(__VA_ARGS__)
-+#define _RH_KABI_REPLACE12(_new, ...) _new; _RH_KABI_REPLACE11(__VA_ARGS__)
-+
-+#define RH_KABI_REPLACE_SPLIT(_orig, ...) _RH_KABI_REPLACE(_orig, \
-+ struct { __PASTE(_RH_KABI_REPLACE, COUNT_ARGS(__VA_ARGS__))(__VA_ARGS__) });
-+
-+# define RH_KABI_RESERVE(n) _RH_KABI_RESERVE(n);
-+
-+#define _RH_KABI_USE1(n, _new) _RH_KABI_RESERVE(n), _new
-+#define _RH_KABI_USE2(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE1(__VA_ARGS__)
-+#define _RH_KABI_USE3(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE2(__VA_ARGS__)
-+#define _RH_KABI_USE4(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE3(__VA_ARGS__)
-+#define _RH_KABI_USE5(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE4(__VA_ARGS__)
-+#define _RH_KABI_USE6(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE5(__VA_ARGS__)
-+#define _RH_KABI_USE7(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE6(__VA_ARGS__)
-+#define _RH_KABI_USE8(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE7(__VA_ARGS__)
-+#define _RH_KABI_USE9(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE8(__VA_ARGS__)
-+#define _RH_KABI_USE10(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE9(__VA_ARGS__)
-+#define _RH_KABI_USE11(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE10(__VA_ARGS__)
-+#define _RH_KABI_USE12(n, ...) _RH_KABI_RESERVE(n); _RH_KABI_USE11(__VA_ARGS__)
-+
-+#define _RH_KABI_USE(...) _RH_KABI_REPLACE(__VA_ARGS__)
-+#define RH_KABI_USE(n, ...) _RH_KABI_USE(__PASTE(_RH_KABI_USE, COUNT_ARGS(__VA_ARGS__))(n, __VA_ARGS__));
-+
-+# define RH_KABI_USE_SPLIT(n, ...) RH_KABI_REPLACE_SPLIT(_RH_KABI_RESERVE(n), __VA_ARGS__)
-+
-+# define _RH_KABI_RESERVE(n) unsigned long rh_reserved##n
-+
-+#define RH_KABI_EXCLUDE(_elem) _RH_KABI_EXCLUDE(_elem);
-+
-+#define RH_KABI_EXCLUDE_WITH_SIZE(_new, _size) \
-+ union { \
-+ RH_KABI_EXCLUDE(_new) \
-+ unsigned long RH_KABI_UNIQUE_ID[_size]; \
-+ __RH_KABI_CHECK_SIZE(_new, 8 * (_size)) \
-+ };
-+
-+#define RH_KABI_EXTEND_WITH_SIZE(_new, _size) \
-+ RH_KABI_EXTEND(union { \
-+ _new; \
-+ unsigned long RH_KABI_UNIQUE_ID[_size]; \
-+ __RH_KABI_CHECK_SIZE(_new, 8 * (_size)) \
-+ })
-+
-+#define _RH_KABI_AUX_PTR(_struct) \
-+ size_t _struct##_size_rh; \
-+ _RH_KABI_EXCLUDE(struct _struct##_rh *_rh)
-+#define RH_KABI_AUX_PTR(_struct) \
-+ _RH_KABI_AUX_PTR(_struct);
-+
-+#define _RH_KABI_AUX_EMBED(_struct) \
-+ size_t _struct##_size_rh; \
-+ _RH_KABI_EXCLUDE(struct _struct##_rh _rh)
-+#define RH_KABI_AUX_EMBED(_struct) \
-+ _RH_KABI_AUX_EMBED(_struct);
-+
-+#define RH_KABI_USE_AUX_PTR(n1, n2, _struct) \
-+ RH_KABI_USE(n1, n2, \
-+ struct { RH_KABI_AUX_PTR(_struct) })
-+
-+#define RH_KABI_AUX_SET_SIZE(_name, _struct) ({ \
-+ (_name)->_struct##_size_rh = sizeof(struct _struct##_rh); \
-+})
-+
-+#define RH_KABI_AUX_INIT_SIZE(_struct) \
-+ ._struct##_size_rh = sizeof(struct _struct##_rh),
-+
-+#define RH_KABI_AUX(_ptr, _struct, _field) ({ \
-+ size_t __off = offsetof(struct _struct##_rh, _field); \
-+ (_ptr)->_struct##_size_rh > __off ? true : false; \
-+})
-+
-+#endif /* _LINUX_RH_KABI_H */
-diff --git a/include/linux/rh_waived.h b/include/linux/rh_waived.h
-new file mode 100644
-index 000000000000..d62a9e896b5e
---- /dev/null
-+++ b/include/linux/rh_waived.h
-@@ -0,0 +1,19 @@
-+/* SPDX-License-Identifier: GPL-2.0 */
-+/*
-+ * include/linux/rh_waived.h
-+ *
-+ * rh_waived cmdline parameter interface.
-+ *
-+ * Copyright (C) 2024, Red Hat, Inc. Ricardo Robaina <rrobaina@redhat.com>
-+ */
-+#ifndef _RH_WAIVED_H
-+#define _RH_WAIVED_H
-+
-+enum rh_waived_items {
-+ /* RH_WAIVED_ITEMS must always be the last item in the enum */
-+ RH_WAIVED_ITEMS,
-+};
-+
-+bool is_rh_waived(enum rh_waived_items feat);
-+
-+#endif /* _RH_WAIVED_H */
-diff --git a/include/linux/security.h b/include/linux/security.h
-index 153e9043058f..2ee3a8990968 100644
---- a/include/linux/security.h
-+++ b/include/linux/security.h
-@@ -2439,4 +2439,13 @@ static inline void security_initramfs_populated(void)
- }
- #endif /* CONFIG_SECURITY */
-
-+#ifdef CONFIG_SECURITY_LOCKDOWN_LSM
-+extern int security_lock_kernel_down(const char *where, enum lockdown_reason level);
-+#else
-+static inline int security_lock_kernel_down(const char *where, enum lockdown_reason level)
-+{
-+ return 0;
-+}
-+#endif /* CONFIG_SECURITY_LOCKDOWN_LSM */
++static inline int security_lock_kernel_down(const char *where, enum lockdown_reason level)
++{
++ return 0;
++}
++#endif /* CONFIG_SECURITY_LOCKDOWN_LSM */
+
#endif /* ! __LINUX_SECURITY_H */
-diff --git a/init/main.c b/init/main.c
-index e363232b428b..27d9d82b7658 100644
---- a/init/main.c
-+++ b/init/main.c
-@@ -1236,8 +1236,10 @@ static bool __init_or_module initcall_blacklisted(initcall_t fn)
- char fn_name[KSYM_SYMBOL_LEN];
- unsigned long addr;
-
-+#ifndef CONFIG_RHEL_DIFFERENCES
- if (list_empty(&blacklisted_initcalls))
- return false;
-+#endif
-
- addr = (unsigned long) dereference_function_descriptor(fn);
- sprint_symbol_no_offset(fn_name, addr);
-@@ -1248,6 +1250,9 @@ static bool __init_or_module initcall_blacklisted(initcall_t fn)
- */
- strreplace(fn_name, ' ', '\0');
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ init_rh_check_status(fn_name);
-+#endif
- list_for_each_entry(entry, &blacklisted_initcalls, next) {
- if (!strcmp(fn_name, entry->buf)) {
- pr_debug("initcall %s blacklisted\n", fn_name);
-diff --git a/kernel/Makefile b/kernel/Makefile
-index 1e1a31673577..60af4f6c2316 100644
---- a/kernel/Makefile
-+++ b/kernel/Makefile
-@@ -12,6 +12,8 @@ obj-y = fork.o exec_domain.o exec_state.o panic.o \
- notifier.o ksysfs.o cred.o reboot.o \
- async.o range.o smpboot.o ucount.o regset.o ksyms_common.o
-
-+obj-$(CONFIG_RHEL_DIFFERENCES) += rh_messages.o rh_flags.o rh_waived.o
-+obj-$(CONFIG_USERMODE_DRIVER) += usermode_driver.o
- obj-$(CONFIG_MULTIUSER) += groups.o
- obj-$(CONFIG_VHOST_TASK) += vhost_task.o
-
-diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c
-index 6e19a030da6f..840338c51e6c 100644
---- a/kernel/bpf/core.c
-+++ b/kernel/bpf/core.c
-@@ -547,7 +547,12 @@ void bpf_prog_kallsyms_del_all(struct bpf_prog *fp)
- /* All BPF JIT sysctl knobs here. */
- int bpf_jit_enable __read_mostly = IS_BUILTIN(CONFIG_BPF_JIT_DEFAULT_ON);
- int bpf_jit_kallsyms __read_mostly = IS_BUILTIN(CONFIG_BPF_JIT_DEFAULT_ON);
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+/* RHEL-only: set it to 1 by default */
-+int bpf_jit_harden __read_mostly = 1;
-+#else
- int bpf_jit_harden __read_mostly;
-+#endif /* CONFIG_RHEL_DIFFERENCES */
- long bpf_jit_limit __read_mostly;
- long bpf_jit_limit_max __read_mostly;
-
-diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
-index 6db306d23b47..a758feebfe03 100644
---- a/kernel/bpf/syscall.c
-+++ b/kernel/bpf/syscall.c
-@@ -28,6 +28,7 @@
- #include <linux/ctype.h>
- #include <linux/nospec.h>
- #include <linux/audit.h>
-+#include <linux/init.h>
- #include <uapi/linux/btf.h>
- #include <linux/pgtable.h>
- #include <linux/bpf_lsm.h>
-@@ -66,6 +67,23 @@ static DEFINE_SPINLOCK(map_idr_lock);
- static DEFINE_IDR(link_idr);
- static DEFINE_SPINLOCK(link_idr_lock);
-
-+static int __init unprivileged_bpf_setup(char *str)
-+{
-+ unsigned long disabled;
-+ if (!kstrtoul(str, 0, &disabled))
-+ sysctl_unprivileged_bpf_disabled = !!disabled;
-+
-+ if (!sysctl_unprivileged_bpf_disabled) {
-+ pr_warn("Unprivileged BPF has been enabled "
-+ "(unprivileged_bpf_disabled=0 has been supplied "
-+ "in boot parameters), tainting the kernel");
-+ add_taint(TAINT_UNPRIVILEGED_BPF, LOCKDEP_STILL_OK);
-+ }
-+
-+ return 1;
-+}
-+__setup("unprivileged_bpf_disabled=", unprivileged_bpf_setup);
-+
- int sysctl_unprivileged_bpf_disabled __read_mostly =
- IS_BUILTIN(CONFIG_BPF_UNPRIV_DEFAULT_OFF) ? 2 : 0;
-
-@@ -6754,6 +6772,11 @@ static int bpf_unpriv_handler(const struct ctl_table *table, int write,
- if (write && !ret) {
- if (locked_state && unpriv_enable != 1)
- return -EPERM;
-+ if (!unpriv_enable) {
-+ pr_warn("Unprivileged BPF has been enabled, "
-+ "tainting the kernel");
-+ add_taint(TAINT_UNPRIVILEGED_BPF, LOCKDEP_STILL_OK);
-+ }
- *(int *)table->data = unpriv_enable;
- }
-
-diff --git a/kernel/module/main.c b/kernel/module/main.c
-index 46dd8d25a605..e82b2b13f588 100644
---- a/kernel/module/main.c
-+++ b/kernel/module/main.c
-@@ -66,6 +66,8 @@
- #define CREATE_TRACE_POINTS
- #include <trace/events/module.h>
-
-+#include <linux/rh_flags.h>
-+
- /*
- * Mutex protects:
- * 1) List of modules (also safely readable within RCU read section),
-@@ -604,6 +606,7 @@ static const struct module_attribute modinfo_##field = { \
-
- MODINFO_ATTR(version);
- MODINFO_ATTR(srcversion);
-+MODINFO_ATTR(rhelversion);
-
- static void setup_modinfo_import_ns(struct module *mod, const char *s)
- {
-@@ -1086,6 +1089,7 @@ const struct module_attribute *const modinfo_attrs[] = {
- &module_uevent,
- &modinfo_version,
- &modinfo_srcversion,
-+ &modinfo_rhelversion,
- &modinfo_import_ns,
- &modinfo_initstate,
- &modinfo_coresize,
-@@ -3396,6 +3400,11 @@ static int early_mod_check(struct load_info *info, int flags)
- return -EPERM;
- }
-
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ if (get_modinfo(info, "intree"))
-+ module_rh_check_status(info->name);
-+#endif
-+
- err = rewrite_section_headers(info, flags);
- if (err)
- return err;
-@@ -3974,6 +3983,10 @@ void print_modules(void)
- pr_cont(" [last unloaded: %s%s]", last_unloaded_module.name,
- last_unloaded_module.taints);
- pr_cont("\n");
-+
-+#ifdef CONFIG_RHEL_DIFFERENCES
-+ rh_print_flags();
-+#endif
- }
-
- #ifdef CONFIG_MODULE_DEBUGFS
diff --git a/kernel/module/signing.c b/kernel/module/signing.c
index 590ba29c85ab..02153d857531 100644
--- a/kernel/module/signing.c
@@ -2762,1063 +1353,6 @@ index 590ba29c85ab..02153d857531 100644
}
int module_sig_check(struct load_info *info, int flags)
-diff --git a/kernel/panic.c b/kernel/panic.c
-index 213725b612aa..a823d01f1f05 100644
---- a/kernel/panic.c
-+++ b/kernel/panic.c
-@@ -826,6 +826,18 @@ const struct taint_flag taint_flags[TAINT_FLAGS_COUNT] = {
- TAINT_FLAG(RANDSTRUCT, 'T', ' '),
- TAINT_FLAG(TEST, 'N', ' '),
- TAINT_FLAG(FWCTL, 'J', ' '),
-+ TAINT_FLAG(20, '?', '-'),
-+ TAINT_FLAG(21, '?', '-'),
-+ TAINT_FLAG(22, '?', '-'),
-+ TAINT_FLAG(23, '?', '-'),
-+ TAINT_FLAG(24, '?', '-'),
-+ TAINT_FLAG(25, '?', '-'),
-+ TAINT_FLAG(PARTNER_SUPPORTED, 'p', ' '),
-+ TAINT_FLAG(SUPPORT_REMOVED, 'h', ' '),
-+ TAINT_FLAG(RESERVED28, '?', '-'),
-+ TAINT_FLAG(RESERVED29, '?', '-'),
-+ TAINT_FLAG(RESERVED30, '?', '-'),
-+ TAINT_FLAG(UNPRIVILEGED_BPF, 'u', ' '),
- };
-
- #undef TAINT_FLAG
-diff --git a/kernel/rh_flags.c b/kernel/rh_flags.c
-new file mode 100644
-index 000000000000..10d26958f840
---- /dev/null
-+++ b/kernel/rh_flags.c
-@@ -0,0 +1,115 @@
-+#include <linux/kernel.h>
-+#include <linux/list.h>
-+#include <linux/proc_fs.h>
-+#include <linux/seq_file.h>
-+#include <linux/slab.h>
-+#include <linux/spinlock.h>
-+#include <linux/rh_flags.h>
-+
-+#define RH_FLAG_NAME_LEN 32
-+#define MAX_RH_FLAGS 128
-+#define MAX_RH_FLAG_NAME_LEN (MAX_RH_FLAGS * RH_FLAG_NAME_LEN)
-+
-+struct rh_flag {
-+ struct list_head list;
-+ char name[RH_FLAG_NAME_LEN];
-+};
-+
-+static LIST_HEAD(rh_flag_list);
-+static DEFINE_SPINLOCK(rh_flag_lock);
-+
-+bool __rh_add_flag(const char *flag_name)
-+{
-+ struct rh_flag *feat, *iter;
-+
-+ BUG_ON(in_interrupt());
-+ feat = kzalloc(sizeof(*feat), GFP_ATOMIC);
-+ if (WARN(!feat, "Adding Red Hat flag %s.\n", flag_name))
-+ return false;
-+ strscpy(feat->name, flag_name, RH_FLAG_NAME_LEN);
-+
-+ spin_lock(&rh_flag_lock);
-+ list_for_each_entry_rcu(iter, &rh_flag_list, list) {
-+ if (!strcmp(iter->name, flag_name)) {
-+ kfree(feat);
-+ feat = NULL;
-+ break;
-+ }
-+ }
-+ if (feat)
-+ list_add_rcu(&feat->list, &rh_flag_list);
-+ spin_unlock(&rh_flag_lock);
-+
-+ if (feat)
-+ pr_info("Adding Red Hat flag %s.\n", flag_name);
-+ return true;
-+}
-+EXPORT_SYMBOL(__rh_add_flag);
-+
-+void rh_print_flags(void)
-+{
-+ struct rh_flag *feat;
-+
-+ /*
-+ * This function cannot do any locking, we're oopsing. Traversing
-+ * rh_flag_list is okay, though, even without the rcu_read_lock
-+ * taken: we never delete from that list and thus don't need the
-+ * delayed free. All we need are the smp barriers invoked by the rcu
-+ * list manipulation routines.
-+ */
-+ if (list_empty(&rh_flag_list))
-+ return;
-+ printk(KERN_DEFAULT "Red Hat flags:");
-+ list_for_each_entry_lockless(feat, &rh_flag_list, list) {
-+ pr_cont(" %s", feat->name);
-+ }
-+ pr_cont("\n");
-+}
-+EXPORT_SYMBOL(rh_print_flags);
-+
-+#ifdef CONFIG_SYSCTL
-+static int rh_flags_show(const struct ctl_table *ctl, int write,
-+ void __user *buffer, size_t *lenp,
-+ loff_t *ppos)
-+{
-+ struct ctl_table tbl = { .maxlen = MAX_RH_FLAG_NAME_LEN, };
-+ struct rh_flag *feat;
-+ size_t offs = 0;
-+ int ret;
-+
-+ tbl.data = kmalloc(tbl.maxlen, GFP_KERNEL);
-+ if (!tbl.data)
-+ return -ENOMEM;
-+ ((char *)tbl.data)[0] = '\0';
-+
-+ rcu_read_lock();
-+ list_for_each_entry_rcu(feat, &rh_flag_list, list) {
-+ offs += scnprintf(tbl.data + offs, tbl.maxlen - offs, "%s%s",
-+ offs == 0 ? "" : " ", feat->name);
-+ }
-+ rcu_read_unlock();
-+
-+ ret = proc_dostring(&tbl, write, buffer, lenp, ppos);
-+ kfree(tbl.data);
-+ return ret;
-+}
-+
-+static struct ctl_table rh_flags_table[] = {
-+ {
-+ .procname = "rh_flags",
-+ .data = &rh_flag_list,
-+ .maxlen = MAX_RH_FLAG_NAME_LEN,
-+ .mode = 0444,
-+ .proc_handler = rh_flags_show,
-+ },
-+};
-+#endif
-+
-+static __init int rh_flags_init(void)
-+{
-+#ifdef CONFIG_SYSCTL
-+ register_sysctl_init("kernel", rh_flags_table);
-+#endif
-+ return 0;
-+}
-+subsys_initcall(rh_flags_init);
-diff --git a/kernel/rh_messages.c b/kernel/rh_messages.c
-new file mode 100644
-index 000000000000..bb69e8965748
---- /dev/null
-+++ b/kernel/rh_messages.c
-@@ -0,0 +1,414 @@
-+/*
-+ * The following functions are used by Red Hat to indicate to users that
-+ * hardware and drivers are unsupported, or have limited support in RHEL major
-+ * and minor releases. These functions output loud warning messages to the end
-+ * user and should be USED WITH CAUTION.
-+ *
-+ * Any use of these functions _MUST_ be documented in the RHEL Release Notes,
-+ * and have approval of management.
-+ *
-+ * Generally, the process of disabling a driver or device in RHEL requires the
-+ * driver or device to be marked as 'deprecated' in all existing releases, and
-+ * then either 'unmaintained' or 'disabled' in a future release.
-+ *
-+ * In general, deprecated and unmaintained drivers continue to receive security
-+ * related fixes until they are disabled.
-+ */
-+
-+#include <linux/kernel.h>
-+#include <linux/module.h>
-+#include <linux/pci.h>
-+#include "rh_messages.h"
-+
-+/**
-+ * mark_hardware_unmaintained() - Mark hardware as unmaintained.
-+ * @driver_name: driver name
-+ * @fmt: format for device description
-+ * @...: args for device description
-+ *
-+ * Called to notify users that the device will no longer be tested on a routine
-+ * basis and driver code associated with this device is no longer being updated.
-+ * Red Hat may, at their own discretion, fix security-related and critical
-+ * issues. Support for this device will be disabled in a future major release
-+ * and users deploying this device should plan to replace the device in
-+ * production systems.
-+ *
-+ * This function should be used when the driver's usage can be tied to a
-+ * specific hardware device. For example, a network device driver loading on a
-+ * specific device that is no longer maintained by the manufacturer.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused mark_hardware_unmaintained(const char *driver_name, char *fmt, ...)
-+{
-+ char device_description[DEV_DESC_LEN];
-+ va_list args;
-+
-+ va_start(args, fmt);
-+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args);
-+ pr_crit(RH_UNMAINT_HW,
-+ driver_name, device_description);
-+ va_end(args);
-+}
-+EXPORT_SYMBOL(mark_hardware_unmaintained);
-+
-+/**
-+ * mark_hardware_deprecated() - Mark hardware as deprecated.
-+ * @driver_name: driver name
-+ * @fmt: format for device description
-+ * @...: args for device description
-+ *
-+ * Called to notify users that support for the device is planned to be
-+ * unmaintained in a future major release, and will eventually be disabled in a
-+ * future major release. This device should not be used in new production
-+ * environments and users should replace the device in production systems.
-+ *
-+ * This function should be used when the driver's usage can be tied to a
-+ * specific hardware device. For example, a network device driver loading on a
-+ * specific device that is no longer maintained by the manufacturer.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused mark_hardware_deprecated(const char *driver_name, char *fmt, ...)
-+{
-+ char device_description[DEV_DESC_LEN];
-+ va_list args;
-+
-+ va_start(args, fmt);
-+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args);
-+ pr_crit(RH_DEPRECATED_HW,
-+ driver_name, device_description);
-+ va_end(args);
-+}
-+
-+/**
-+ * mark_hardware_disabled() - Mark a driver as removed.
-+ * @driver_name: driver name
-+ * @fmt: format for device description
-+ * @...: args for device description
-+ *
-+ * Called to notify users that a device's support has been completely disabled
-+ * and no future support updates will occur. This device cannot be used in new
-+ * production environments, and users must replace the device in production
-+ * systems.
-+ *
-+ * This function should be used when the driver's usage can be tied to a
-+ * specific hardware device. For example, a network device driver loading on a
-+ * specific device that is no longer maintained by the manufacturer.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void __maybe_unused mark_hardware_disabled(const char *driver_name, char *fmt, ...)
-+{
-+ char device_description[DEV_DESC_LEN];
-+ va_list args;
-+
-+ va_start(args, fmt);
-+ vsnprintf(device_description, DEV_DESC_LEN, fmt, args);
-+ pr_crit(RH_DISABLED_HW,
-+ driver_name, device_description);
-+ va_end(args);
-+}
-+
-+#ifdef CONFIG_PCI
-+/**
-+ * pci_hw_deprecated() - Mark a PCI device deprecated.
-+ * @dev: the PCI device structure to match against
-+ *
-+ * Called to check if this @dev is in the list of deprecated devices.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void __maybe_unused pci_hw_deprecated(struct pci_dev *dev)
-+{
-+ const struct pci_device_id *ret = pci_match_id(rh_deprecated_pci_devices, dev);
-+
-+ if (!ret)
-+ return;
-+
-+ mark_hardware_deprecated(dev_driver_string(&dev->dev), "%04X:%04X @ %s",
-+ dev->device, dev->vendor, pci_name(dev));
-+}
-+
-+/**
-+ * pci_hw_unmaintained() - Mark a PCI device unmaintained.
-+ * @dev: the PCI device structure to match against
-+ *
-+ * Called to check if this @dev is in the list of unmaintained devices.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void pci_hw_unmaintained(struct pci_dev *dev)
-+{
-+ const struct pci_device_id *ret = pci_match_id(rh_unmaintained_pci_devices, dev);
-+
-+ if (!ret)
-+ return;
-+
-+ mark_hardware_unmaintained(dev_driver_string(&dev->dev), "%04X:%04X @ %s",
-+ dev->device, dev->vendor, pci_name(dev));
-+}
-+
-+/**
-+ * pci_hw_disabled() - Mark a PCI device disabled.
-+ * @dev: the PCI device structure to match against
-+ *
-+ * Called to check if this @dev is in the list of disabled devices.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static bool __maybe_unused pci_hw_disabled(struct pci_dev *dev)
-+{
-+ const struct pci_device_id *ret = pci_match_id(rh_disabled_pci_devices, dev);
-+
-+ if (!ret)
-+ return false;
-+
-+ mark_hardware_disabled(dev_driver_string(&dev->dev), "%04X:%04X @ %s",
-+ dev->device, dev->vendor, pci_name(dev));
-+ return true;
-+}
-+#endif
-+
-+/**
-+ * driver_unmaintained() - check to see if a driver is unmaintained
-+ * @module_name: module name
-+ *
-+ * Called to notify users that a driver will no longer be tested on a routine
-+ * basis and the driver code is no longer being updated. Red Hat may fix
-+ * security-related and critical issues. Support for this driver will be
-+ * disabled in a future major release, and users should replace any affected
-+ * devices in production systems.
-+ *
-+ * This function should be used when a driver's usage cannot be tied to a
-+ * specific hardware device. For example, a network bonding driver or a higher
-+ * level storage layer driver that is no longer maintained upstream.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void __maybe_unused driver_unmaintained(const char* module_name)
-+{
-+ int i = 0;
-+
-+ while (rh_unmaintained_drivers[i]) {
-+ if (strcmp(rh_unmaintained_drivers[i], module_name) == 0) {
-+ pr_crit(RH_UNMAINT_DR, module_name);
-+ return;
-+ }
-+ i++;
-+ }
-+}
-+
-+/**
-+ * driver_deprecated() - check to see if a driver is deprecated
-+ * @driver_name: module name
-+ *
-+ * Called to notify users that support for this driver is planned to be
-+ * unmaintained in a future major release, and will eventually be disabled in a
-+ * future major release. This driver should not be used in new production
-+ * environments and users should replace any affected devices in production
-+ * systems.
-+ *
-+ * This function should be used when a driver's usage cannot be tied to a
-+ * specific hardware device. For example, a network bonding driver or a higher
-+ * level storage layer driver that is no longer maintained upstream.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void __maybe_unused driver_deprecated(const char* module_name)
-+{
-+ int i = 0;
-+
-+ while (rh_deprecated_drivers[i]) {
-+ if (strcmp(rh_deprecated_drivers[i], module_name) == 0) {
-+ pr_crit(RH_DEPRECATED_DR, module_name);
-+ return;
-+ }
-+ i++;
-+ }
-+}
-+
-+/* There is no driver_disabled() function. Disabled drivers are configured off ;). */
-+
-+/**
-+ * init_fn_unmaintained - check to see if a built-in driver is unmaintained.
-+ * @fn_name: module's module_init function name
-+ *
-+ * Called to notify users that a built-in driver will no longer be tested on a routine
-+ * basis and the built-in driver code is no longer being updated. Red Hat may fix
-+ * security-related and critical issues. Support for this built-in driver will be
-+ * disabled in a future major release, and users should replace any affected
-+ * devices in production systems.
-+ *
-+ * This function should be used when a built-in driver's usage cannot be tied to a
-+ * specific hardware device. For example, a network bonding driver or a higher
-+ * level storage layer driver that is no longer maintained upstream.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+
-+static void __maybe_unused init_fn_unmaintained(char* fn_name)
-+{
-+ int i = 0;
-+
-+ while (rh_unmaintained_init_fns[i]) {
-+ if (strcmp(rh_unmaintained_init_fns[i], fn_name) == 0) {
-+ pr_crit(RH_UNMAINT_DR, fn_name);
-+ return;
-+ }
-+ i++;
-+ }
-+}
-+
-+/**
-+ * init_fn_deprecated() - check to see if a built-in driver is deprecated
-+ * @fn_name: module's module_init function name
-+ *
-+ * Called to notify users that support for this built-in driver is planned to be
-+ * unmaintained in a future major release, and will eventually be disabled in a
-+ * future major release. This driver should not be used in new production
-+ * environments and users should replace any affected devices in production
-+ * systems.
-+ *
-+ * This function should be used when a built-in driver's usage cannot be tied to a
-+ * specific hardware device. For example, a network bonding driver or a higher
-+ * level storage layer driver that is no longer maintained upstream.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+static void __maybe_unused init_fn_deprecated(char* fn_name)
-+{
-+ int i = 0;
-+
-+ while (rh_deprecated_init_fns[i]) {
-+ if (strcmp(rh_deprecated_init_fns[i], fn_name) == 0) {
-+ pr_crit(RH_DEPRECATED_DR, fn_name);
-+ return;
-+ }
-+ i++;
-+ }
-+}
-+
-+/**
-+ * mark_tech_preview() - Mark driver or kernel subsystem as 'Tech Preview'
-+ * @msg: Driver or kernel subsystem name
-+ *
-+ * Called to minimize the support status of a new driver. This does TAINT the
-+ * kernel. Calling this function indicates that the driver or subsystem has
-+ * had limited testing and is not marked for full support within this RHEL
-+ * minor release. The next RHEL minor release may contain full support for
-+ * this driver. Red Hat does not guarantee that bugs reported against this
-+ * driver or subsystem will be resolved.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused mark_tech_preview(const char *msg, struct module *mod)
-+{
-+ const char *str = NULL;
-+
-+ if (msg)
-+ str = msg;
-+#ifdef CONFIG_MODULES
-+ else if (mod)
-+ str = mod->name;
-+#endif
-+
-+ pr_warn(RH_TECH_PREVIEW, (str ? str : "kernel"));
-+ add_taint(TAINT_AUX, LOCKDEP_STILL_OK);
-+#ifdef CONFIG_MODULES
-+ if (mod)
-+ mod->taints |= (1U << TAINT_AUX);
-+#endif
-+}
-+EXPORT_SYMBOL(mark_tech_preview);
-+
-+/**
-+ * mark_partner_supported() - Mark driver or kernel subsystem as 'Partner Supported'
-+ * @msg: Driver or kernel subsystem name
-+ *
-+ * Called to minimize the support status of a new driver. This does TAINT the
-+ * kernel. Calling this function indicates that the driver or subsystem
-+ * is not supported directly by Red Hat but by a partner engineer.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused mark_partner_supported(const char *msg, struct module *mod)
-+{
-+ const char *str = NULL;
-+
-+ if (msg)
-+ str = msg;
-+#ifdef CONFIG_MODULES
-+ else if (mod)
-+ str = mod->name;
-+#endif
-+
-+ pr_warn(RH_PARTNER_SUPPORTED, (str ? str : "kernel"));
-+ add_taint(TAINT_PARTNER_SUPPORTED, LOCKDEP_STILL_OK);
-+#ifdef CONFIG_MODULES
-+ if (mod)
-+ mod->taints |= (1U << TAINT_PARTNER_SUPPORTED);
-+#endif
-+}
-+EXPORT_SYMBOL(mark_partner_supported);
-+
-+/*
-+ *
-+ * Functions called by 'main' kernel code.
-+ *
-+ */
-+
-+#ifdef CONFIG_PCI
-+/**
-+ * pci_rh_check_status - checks the status of a PCI device.
-+ * @pci_dev: PCI device to be examined
-+ *
-+ * This function is called by the PCI driver subsystem to check the status of a
-+ * PCI device.
-+ *
-+ * This function returns true if the PCI device is disabled, and false otherwise.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+bool __maybe_unused pci_rh_check_status(struct pci_dev *pci_dev)
-+{
-+ if (pci_dev->driver->driver.owner != NULL) {
-+ if (!test_bit(TAINT_OOT_MODULE, &pci_dev->driver->driver.owner->taints)) {
-+ pci_hw_unmaintained(pci_dev);
-+ pci_hw_deprecated(pci_dev);
-+ return pci_hw_disabled(pci_dev);
-+ }
-+ }
-+ return false;
-+}
-+#endif
-+
-+/** module_rh_check_status - checks the status of a module.
-+ * @module_name: Name of module to be examined
-+ *
-+ * This function is called by the module loading code to check the status of a
-+ * module.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused module_rh_check_status(const char * module_name)
-+{
-+ driver_unmaintained(module_name);
-+ driver_deprecated(module_name);
-+}
-+
-+/**
-+ * init_rh_check_status - checks the status of a built-in module.
-+ * @fn_name: init function of module to be examined
-+ *
-+ * This function is called by the init code to check the status of a built-in module.
-+ * When a module is built-in, the module_init() function is converted into an initcall.
-+ * The initcall is the called during boot with the other system initcalls.
-+ *
-+ * Reserved for Internal Red Hat use only.
-+ */
-+void __maybe_unused init_rh_check_status(char *fn_name)
-+{
-+ init_fn_deprecated(fn_name);
-+ init_fn_unmaintained(fn_name);
-+}
-diff --git a/kernel/rh_messages.h b/kernel/rh_messages.h
-new file mode 100644
-index 000000000000..6c757a2fe4e0
---- /dev/null
-+++ b/kernel/rh_messages.h
-@@ -0,0 +1,334 @@
-+/*
-+ * WARNING: This file is auto-generated by an internal Red Hat script and,
-+ * in general, should not be modified by hand.
-+ * See: https://gitlab.com/redhat/rhel/src/kernel/hardware-removal-support
-+ */
-+
-+/*
-+ * The following tables are used by Red Hat to define what hardware and drivers
-+ * are unsupported, or have limited support in RHEL major and minor releases.
-+ *
-+ * Generally, the process of disabling a driver or device in RHEL requires the
-+ * driver or device to be marked as 'deprecated' in all existing releases, and
-+ * then either 'unmaintained' or 'disabled' in a future release.
-+ *
-+ * In general, deprecated and unmaintained drivers continue to receive security
-+ * related fixes until they are disabled.
-+ */
-+
-+#ifndef __RH_MESSAGES_H
-+#define __RH_MESSAGES_H
-+
-+#include <linux/version.h>
-+#include <linux/pci.h>
-+
-+#define DEV_DESC_LEN 256
-+
-+#define RH_UNMAINT_HW "Warning: Unmaintained Hardware is detected: %s:%s\n"
-+
-+#define RH_UNMAINT_DR "Warning: Unmaintained driver is detected: %s\n"
-+
-+#define RH_DEPRECATED_HW "Warning: Deprecated Hardware is detected: %s:%s " \
-+ "will not be maintained in a future major release " \
-+ "and may be disabled\n"
-+
-+#define RH_DEPRECATED_DR "Warning: Deprecated Driver is detected: %s will " \
-+ "not be maintained in a future major release and " \
-+ "may be disabled\n"
-+
-+#define RH_DISABLED_HW "Warning: Disabled Hardware is detected: %s:%s is " \
-+ "no longer enabled in this release.\n"
-+
-+#define RH_TECH_PREVIEW "TECH PREVIEW: %s may not be fully supported.\n" \
-+ "Please review provided documentation for " \
-+ "limitations.\n"
-+
-+#define RH_PARTNER_SUPPORTED "Warning: %s is a Partner supported GPL " \
-+ "module and not supported directly by Red Hat.\n"
-+
-+static const char *rh_deprecated_drivers[] = {
-+ 0 /* Terminating entry */
-+};
-+
-+static const char *rh_deprecated_init_fns[] = {
-+ 0 /* Terminating entry */
-+};
-+
-+static const char *rh_unmaintained_drivers[] = {
-+ "aacraid",
-+ "af_key",
-+ "ahci_seattle",
-+ "ahci_xgene",
-+ "arp_tables",
-+ "bnx2",
-+ "bnx2fc",
-+ "bnx2i",
-+ "bnx2x",
-+ "cnic",
-+ "dl2k",
-+ "e1000",
-+ "ebtables",
-+ "hdlc_fr",
-+ "hisi_sas_main",
-+ "hpsa",
-+ "ip6_tables",
-+ "ip_set",
-+ "ip_tables",
-+ "mptbase",
-+ "mptsas",
-+ "mptscsih",
-+ "mptspi",
-+ "myri10ge",
-+ "netxen_nic",
-+ "nft_compat",
-+ "nicpf",
-+ "nicvf",
-+ "nvmet_fc",
-+ "nvmet_tcp",
-+ "team",
-+ 0 /* Terminating entry */
-+};
-+
-+static const char *rh_unmaintained_init_fns[] = {
-+ "bnx2_pci_driver_init",
-+ "e1000_init_module",
-+ "rio_driver_init",
-+ "hpsa_init",
-+ "fusion_init",
-+ "mptsas_init",
-+ "fusion_init",
-+ "mptspi_init",
-+ "myri10ge_init_module",
-+ "netxen_init_module",
-+ "hdlc_fr_init",
-+ "nvmet_fc_init_module",
-+ "nvmet_tcp_init",
-+ "team_module_init",
-+ "ebtables_init",
-+ "arp_tables_init",
-+ "ip_tables_init",
-+ "ip6_tables_init",
-+ "ip_set_init",
-+ "nft_compat_module_init",
-+ "nicvf_init_module",
-+ "nic_init_module",
-+ "ipsec_pfkey_init",
-+ "aac_init",
-+ "cnic_init",
-+ "bnx2x_init",
-+ "bnx2fc_mod_init",
-+ "bnx2i_mod_init",
-+ "ahci_seattle_probe",
-+ "xgene_ahci_probe",
-+ "hisi_sas_init",
-+ 0 /* Terminating entry */
-+};
-+
-+static const struct pci_device_id rh_deprecated_pci_devices[] = {
-+ {0} /* Terminating entry */
-+};
-+
-+static const struct pci_device_id rh_disabled_pci_devices[] = {
-+ { 0x1011, 0x0046, 0x103c, 0x10c2 },
-+ { 0x1011, 0x0046, 0x9005, 0x0364 },
-+ { 0x1011, 0x0046, 0x9005, 0x0365 },
-+ { 0x1011, 0x0046, 0x9005, 0x1364 },
-+ { 0x1028, 0x0001, 0x1028, 0x0001 },
-+ { 0x1028, 0x0002, 0x1028, 0x0002 },
-+ { 0x1028, 0x0002, 0x1028, 0x00d1 },
-+ { 0x1028, 0x0002, 0x1028, 0x00d9 },
-+ { 0x1028, 0x0003, 0x1028, 0x0003 },
-+ { 0x1028, 0x0004, 0x1028, 0x00d0 },
-+ { 0x1028, 0x000a, 0x1028, 0x0106 },
-+ { 0x1028, 0x000a, 0x1028, 0x011b },
-+ { 0x1028, 0x000a, 0x1028, 0x0121 },
-+ { 0x9005, 0x0200, 0x9005, 0x0200 },
-+ { 0x9005, 0x0283, 0x9005, 0x0283 },
-+ { 0x9005, 0x0284, 0x9005, 0x0284 },
-+ { 0x9005, 0x0285, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x9005, 0x0285, 0x1014, 0x02F2 },
-+ { 0x9005, 0x0285, 0x1014, 0x0312 },
-+ { 0x9005, 0x0285, 0x1028, PCI_ANY_ID },
-+ { 0x9005, 0x0285, 0x1028, 0x0287 },
-+ { 0x9005, 0x0285, 0x1028, 0x0291 },
-+ { 0x9005, 0x0285, 0x103C, 0x3227 },
-+ { 0x9005, 0x0285, 0x17aa, PCI_ANY_ID },
-+ { 0x9005, 0x0285, 0x17aa, 0x0286 },
-+ { 0x9005, 0x0285, 0x17aa, 0x0287 },
-+ { 0x9005, 0x0285, 0x9005, 0x0285 },
-+ { 0x9005, 0x0285, 0x9005, 0x0286 },
-+ { 0x9005, 0x0285, 0x9005, 0x0287 },
-+ { 0x9005, 0x0285, 0x9005, 0x0288 },
-+ { 0x9005, 0x0285, 0x9005, 0x0289 },
-+ { 0x9005, 0x0285, 0x9005, 0x028a },
-+ { 0x9005, 0x0285, 0x9005, 0x028b },
-+ { 0x9005, 0x0285, 0x9005, 0x028e },
-+ { 0x9005, 0x0285, 0x9005, 0x028f },
-+ { 0x9005, 0x0285, 0x9005, 0x0290 },
-+ { 0x9005, 0x0285, 0x9005, 0x0291 },
-+ { 0x9005, 0x0285, 0x9005, 0x0292 },
-+ { 0x9005, 0x0285, 0x9005, 0x0293 },
-+ { 0x9005, 0x0285, 0x9005, 0x0294 },
-+ { 0x9005, 0x0285, 0x9005, 0x0296 },
-+ { 0x9005, 0x0285, 0x9005, 0x0297 },
-+ { 0x9005, 0x0285, 0x9005, 0x0298 },
-+ { 0x9005, 0x0285, 0x9005, 0x0299 },
-+ { 0x9005, 0x0285, 0x9005, 0x029a },
-+ { 0x9005, 0x0285, 0x9005, 0x02a4 },
-+ { 0x9005, 0x0285, 0x9005, 0x02a5 },
-+ { 0x9005, 0x0286, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x9005, 0x0286, 0x1014, 0x9540 },
-+ { 0x9005, 0x0286, 0x1014, 0x9580 },
-+ { 0x9005, 0x0286, 0x9005, 0x028c },
-+ { 0x9005, 0x0286, 0x9005, 0x028d },
-+ { 0x9005, 0x0286, 0x9005, 0x029b },
-+ { 0x9005, 0x0286, 0x9005, 0x029c },
-+ { 0x9005, 0x0286, 0x9005, 0x029d },
-+ { 0x9005, 0x0286, 0x9005, 0x029e },
-+ { 0x9005, 0x0286, 0x9005, 0x029f },
-+ { 0x9005, 0x0286, 0x9005, 0x02a0 },
-+ { 0x9005, 0x0286, 0x9005, 0x02a1 },
-+ { 0x9005, 0x0286, 0x9005, 0x02a2 },
-+ { 0x9005, 0x0286, 0x9005, 0x02a3 },
-+ { 0x9005, 0x0286, 0x9005, 0x02a6 },
-+ { 0x9005, 0x0286, 0x9005, 0x0800 },
-+ { 0x9005, 0x0287, 0x9005, 0x0800 },
-+ { 0x9005, 0x0288, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0222, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0712, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x212, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x702, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x703, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0700, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0211, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0710, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0221, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0xe220, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0x1ae5, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe100, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe131, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe180, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe260, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf095, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf098, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0a1, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0a5, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0d1, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0d5, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0e1, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0e5, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0f5, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0f6, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf0f7, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf180, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf700, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf800, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf900, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf980, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfa00, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfb00, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfc00, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfc10, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfc20, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfc50, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfd00, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfd11, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfd12, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfe00, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfe05, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfe11, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfe12, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0704, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x19a2, 0x0714, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe208, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe268, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0060, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0078, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x007C, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0411, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0413, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1028, 0x0015, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1002, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6340, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x634A, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6354, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6368, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6372, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6732, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x673C, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6746, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6750, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x675A, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x6764, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x676E, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1003, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1004, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1005, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1006, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1007, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1008, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1009, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100a, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100b, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100c, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100d, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100e, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x100f, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1010, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x15B3, 0x1027, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0064, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0065, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0070, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0072, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0074, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0076, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0077, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x007E, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x2422, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x2432, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x5422, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x5432, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8001, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8021, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8044, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8432, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0xF000, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8022, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8032, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8042, PCI_ANY_ID, PCI_ANY_ID },
-+ {0} /* Terminating entry */
-+};
-+
-+static const struct pci_device_id rh_unmaintained_pci_devices[] = {
-+ { 0x10df, 0xe220, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0x0724, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xe200, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf011, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf015, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xf100, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x10df, 0xfc40, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x005b, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0071, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0073, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0079, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x006E, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0080, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0081, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0082, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0083, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0084, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0085, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0086, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1000, 0x0087, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x177d, 0xa01e, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x177d, 0xa034, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x177d, 0x0011, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x2031, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x2532, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1077, 0x8031, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1924, 0x0803, PCI_ANY_ID, PCI_ANY_ID },
-+ { 0x1924, 0x0813, PCI_ANY_ID, PCI_ANY_ID },
-+ {0} /* Terminating entry */
-+};
-+
-+#endif /* __RH_MESSAGES_H */
-diff --git a/kernel/rh_waived.c b/kernel/rh_waived.c
-new file mode 100644
-index 000000000000..20966f7c7277
---- /dev/null
-+++ b/kernel/rh_waived.c
-@@ -0,0 +1,147 @@
-+/* SPDX-License-Identifier: GPL-2.0 */
-+/*
-+ * kernel/rh_waived.c
-+ *
-+ * rh_waived cmdline parameter support.
-+ *
-+ * Copyright (C) 2024, Red Hat, Inc. Ricardo Robaina <rrobaina@redhat.com>
-+ */
-+#include <linux/types.h>
-+#include <linux/init.h>
-+#include <linux/printk.h>
-+#include <linux/string.h>
-+#include <linux/panic.h>
-+#include <linux/module.h>
-+#include <linux/kernel.h>
-+#include <linux/rh_flags.h>
-+#include <linux/rh_waived.h>
-+
-+/*
-+ * * RH_INSERT_WAIVED_ITEM
-+ * This macro is intended to be used to insert items into the
-+ * rh_waived_list array. It expects to get an item from
-+ * enum rh_waived_items as its first argument, and a string
-+ * holding the feature name as its second argument.
-+ *
-+ * The feature name is also utilized as the token for the
-+ * boot parameter parser.
-+ *
-+ * Example usage:
-+ * struct rh_waived_item foo[RH_WAIVED_FEAT_ITEMS] = {
-+ * RH_INSERT_WAIVED_ITEM(FOO_FEAT, "foo_feat_short_str", "alias", RH_WAIVED_FEAT),
-+ * };
-+ */
-+#define RH_INSERT_WAIVED_ITEM(enum_item, item, item_alt, class) \
-+ [(enum_item)] = { .name = (item), .alias = (item_alt), \
-+ .type = (class), .waived = 0, }
-+
-+/* Indicates if the rh_flag 'rh_waived' should be added. */
-+bool __initdata add_rh_flag = false;
-+
-+typedef enum {
-+ RH_WAIVED_FEAT,
-+ RH_WAIVED_CVE,
-+ RH_WAIVED_ANY
-+} rh_waived_t;
-+
-+struct rh_waived_item {
-+ char *name, *alias;
-+ rh_waived_t type;
-+ unsigned int waived;
-+
-+};
-+
-+/* Always use the marco RH_INSERT_WAIVED to insert items to this array. */
-+struct rh_waived_item rh_waived_list[RH_WAIVED_ITEMS] = {
-+};
-+
-+/*
-+ * is_rh_waived() - Checks if a given item has been marked as waived.
-+ *
-+ * @item: waived item.
-+ */
-+__inline__ bool is_rh_waived(enum rh_waived_items item)
-+{
-+ return !!rh_waived_list[item].waived;
-+}
-+EXPORT_SYMBOL(is_rh_waived);
-+
-+static void __init rh_waived_parser(char *s, rh_waived_t type)
-+{
-+ int i;
-+ char *token;
-+
-+ pr_info(KERN_CONT "rh_waived: ");
-+
-+ if (!s) {
-+ for (i = 0; i < RH_WAIVED_ITEMS; i++) {
-+ if (type != RH_WAIVED_ANY && rh_waived_list[i].type != type)
-+ continue;
-+
-+ rh_waived_list[i].waived = 1;
-+ pr_info(KERN_CONT "%s%s", rh_waived_list[i].name,
-+ i < RH_WAIVED_ITEMS - 1 ? " " : "\n");
-+ }
-+
-+ add_rh_flag = true;
-+ return;
-+ }
-+
-+ while ((token = strsep(&s, ",")) != NULL) {
-+ for (i = 0; i < RH_WAIVED_ITEMS; i++) {
-+ char *alias = rh_waived_list[i].alias;
-+
-+ if (type != RH_WAIVED_ANY && rh_waived_list[i].type != type)
-+ continue;
-+
-+ if (!strcmp(token, rh_waived_list[i].name) ||
-+ (alias && !strcmp(token, alias))) {
-+ rh_waived_list[i].waived = 1;
-+ pr_info(KERN_CONT "%s ", rh_waived_list[i].name);
-+ }
-+ }
-+ }
-+
-+ pr_info(KERN_CONT "\n");
-+ add_rh_flag = true;
-+}
-+
-+static int __init rh_waived_setup(char *s)
-+{
-+ /*
-+ * originally, if no string was passed to the cmdline option
-+ * all listed features would be waived, so we keep that same
-+ * compromise with the new contract.
-+ */
-+ if (!s || !strcmp(s, "features")) {
-+ rh_waived_parser(NULL, RH_WAIVED_FEAT);
-+ return 0;
-+ }
-+
-+ /* waive all possible mitigations in the list */
-+ if (!strcmp(s, "cves")) {
-+ rh_waived_parser(NULL, RH_WAIVED_CVE);
-+ return 0;
-+ }
-+
-+ /* otherwise, just deal with the enumerated waive list */
-+ rh_waived_parser(s, RH_WAIVED_ANY);
-+
-+ return 0;
-+}
-+early_param("rh_waived", rh_waived_setup);
-+
-+/*
-+ * rh_flags is initialized at subsys_initcall, calling rh_add_flag()
-+ * from rh_waived_setup() would result in a can't boot situation.
-+ * Deffering the inclusion 'rh_waived' rh_flag to late_initcall to
-+ * avoid this issue.
-+ */
-+static int __init __add_rh_flag(void)
-+{
-+ if (add_rh_flag)
-+ rh_add_flag("rh_waived");
-+
-+ return 0;
-+}
-+late_initcall(__add_rh_flag);
diff --git a/scripts/Makefile.lib b/scripts/Makefile.lib
index 0a4fdd8bd975..dcb12dad419f 100644
--- a/scripts/Makefile.lib
@@ -3834,39 +1368,6 @@ index 0a4fdd8bd975..dcb12dad419f 100644
objtool-args = $(objtool-args-y) \
$(if $(delay-objtool), --link) \
-diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c
-index a7b72a81d248..9b62ee078734 100644
---- a/scripts/mod/modpost.c
-+++ b/scripts/mod/modpost.c
-@@ -27,6 +27,7 @@
- #include <xalloc.h>
- #include "modpost.h"
- #include "../../include/linux/license.h"
-+#include "../../include/generated/uapi/linux/version.h"
-
- #define MODULE_NS_PREFIX "module:"
-
-@@ -2066,6 +2067,12 @@ static void write_buf(struct buffer *b, const char *fname)
- }
- }
-
-+static void add_rhelversion(struct buffer *b, struct module *mod)
-+{
-+ buf_printf(b, "MODULE_INFO(rhelversion, \"%d.%d\");\n", RHEL_MAJOR,
-+ RHEL_MINOR);
-+}
-+
- static void write_if_changed(struct buffer *b, const char *fname)
- {
- char *tmp;
-@@ -2150,6 +2157,7 @@ static void write_mod_c_file(struct module *mod)
- }
-
- add_srcversion(&buf, mod);
-+ add_rhelversion(&buf, mod);
-
- ret = snprintf(fname, sizeof(fname), "%s.mod.c", mod->name);
- if (ret >= sizeof(fname)) {
diff --git a/scripts/tags.sh b/scripts/tags.sh
index 243373683f98..2affd5e58ee8 100755
--- a/scripts/tags.sh
diff --git a/sources b/sources
index 4ab9eab..e476dce 100644
--- a/sources
+++ b/sources
@@ -1,3 +1,3 @@
-SHA512 (linux-7.2.tar.xz) = cfa78fe506c20ceed1e4f4a01a92efc1a2bc59d5567f8d5534843d3f1be8c6b06d09a94960889981bc1a645e2583659cba0ed4a24fe6aaa3f7ba6d89327d0ac7
-SHA512 (kernel-abi-stablelists-7.2.0.tar.xz) = 38637ce71efa3ccfc16a4cf2a0e8dba58296088775aa05e85c10648bedf0ccb22862941892823ac5d50ccc516ef27ee18a5d6ae1c4ec357e214f8c0266a51bd1
-SHA512 (kernel-kabi-dw-7.2.0.tar.xz) = a86ef37b507c2fef220e4fd93d3ac1f2a517c256ba9fa94e006937cd3cdb2d99f3b122b4c6a48e0c6ab9fba7dcee405bec851c6942fd25f8fca8c22d504516dc
+SHA512 (linux-7.2.1.tar.xz) = da48ac95ae2293dae34f0644c85ccb44e682edba5756e33603cbc525fa60d858e89632b178e64995c58c2b2918b3dd71b3998d3a6c4f65271af553c6573a5898
+SHA512 (kernel-abi-stablelists-7.2.1.tar.xz) = 6b0dd09c76466f880bef584f809baa0cad188457a2dd1dbd57f891bf484ccf76bd379ae025f4708df15048d748540e07c61097561979e54af0103ec6914d08e4
+SHA512 (kernel-kabi-dw-7.2.1.tar.xz) = 5154ca7404cbe9a5c4e17baed3b517196a94cdebb09f1dde1d77e0f935cc67fb2556b533617b66a077a8e947ca0a86cd8eefb6a933401e0368c7804954b0d659
reply other threads:[~2026-08-27 14:03 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178783940375.1.18243205906292501778.rpms-kernel-11f410760345@fedoraproject.org \
--to=jforbes@fedoraproject.org \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox