← Back to archive

Daily update · Sep 29–30, 2026

MTD fixes lead the day: SPI-NAND QE and no-ECC-engine bugs, vf610 NAND controller, RTC and mm cleanups

A batch of notable fixes across the MTD subsystem, plus RTC, memory management, module loader, and ARC patches.

In brief

The MTD subsystem received the bulk of today's fixes, with several SPI-NAND corrections around quad-enable (QE) bit handling and the no-ECC-engine code path, plus a pair of subtle vf610 NAND controller fixes. RTC, memory management, and the module loader also saw real bug fixes.

SPI-NAND fixes

Enable QE bit on all dies of multi-die SPI-NAND devices

On some multi-die SPI-NAND parts the QE (quad-enable) bit lives in a per-die config register. Updating only the currently selected die left other dies in non-quad mode. The fix iterates over all targets during initialization. Tested on ISSI IS38SMW04G8B.

Why it matters: Ensures consistent quad I/O across the entire device on multi-die SPI-NAND flash.

63d6cace2c4a

Do not clear the QE bit on SPI-NAND devices that lack one

A refactor made spinand_init_quad_enable() run unconditionally, clearing config-register bit 0 on devices without a QE bit. On the Winbond W25N02KV that bit is H-DIS (HOLD disable), so clearing it enables HOLD during single/dual I/O — if IO3 is not held high the flash can pause a command mid-transfer. H-DIS is not restored by a reset command, so the corruption persists.

Why it matters: Prevents silent flash command interruption and persistent misconfiguration on affected Winbond parts.

1c1a342aceec

Fix NULL pointer dereference when no ECC engine is configured

When 'nand-no-ecc-engine' is set in device tree, nanddev_get_ecc_engine() returns success but leaves nand->ecc.engine NULL. SPI-NAND code dereferenced it unconditionally to test for a pipelined engine, oopsing on probe. A new nand_ecc_is_pipelined() helper folds in the NULL check.

Why it matters: Fixes an immediate kernel oops when probing SPI-NAND devices configured without an ECC engine.

b890e6163761

Fix zero oobavail when no ECC engine is used

When no ECC engine is requested, mtd->oobavail was assigned from a zero return value, advertising zero available OOB bytes. This makes every automatic OOB access fail with -EINVAL, and JFFS2 — which stores its cleanmarker in OOB on NAND — refuses to mount entirely.

Why it matters: Restores correct OOB availability and JFFS2 mountability on SPI-NAND devices without an ECC engine.

636fe10d8f35

Raw NAND controller fixes

vf610_nfc: fix reads on chips with more than 64 bytes of OOB

The VF610 NFC controller transfers only 64 spare bytes per page; the driver clamps mtd->oobsize in attach_chip(), but nand_scan_tail() restores the chip's full OOB size afterward. The mismatch causes every ECC-protected read to fail with -EBADMSG. Measured on a Colibri VF61 with a Micron MX30LF4G28AC (112-byte OOB).

Why it matters: Fixes read failures on NAND chips whose OOB exceeds the controller's 64-byte spare area.

37adc9c5789c

vf610_nfc: fix false bitflips on reads of erased pages

When the ECC engine fails to decode a page, the driver re-reads OOB with the engine bypassed but runs the erased-page check on stale controller SRAM data. In 60-byte ECC mode the all-0xff erased page always decodes to the same error location, producing a phantom zero bit at data offset 0x5FD on every erased page. The fix ensures the erased-page check reads actual flash content.

Why it matters: Eliminates spurious corrected-bitflip reports on erased pages on the vf610 NFC controller.

68fe2faf5c69

Cadence NAND: initialize IRQ state before requesting the interrupt

The interrupt handler uses both an IRQ lock and a completion object, but the IRQ was registered before those were initialized, leaving a window for a pending interrupt to touch uninitialized synchronization state.

Why it matters: Closes a race where a pending interrupt could access uninitialized data during probe.

21f027016b12

Other MTD fixes

block2mtd: fix divide error when erase_size is zero

The erase size parsed from the 'block2mtd' module parameter can be set to zero. add_device() then evaluates 'size % erase_size' with a zero divisor, triggering a divide error. The fix rejects a zero erase size before the modulo.

Why it matters: Prevents a kernel oops when the block2mtd module parameter is given an erase_size of zero.

b5965c422116

core: avoid double-free of OTP NVMEM device

If factory OTP setup failed after user OTP NVMEM registration, the user device was unregistered but the pointer was not cleared, leading to a second unregister on error or teardown. The fix sets mtd->otp_user_nvmem to NULL after unregistering.

Why it matters: Fixes a double-free in the OTP NVMEM error and teardown paths.

26300879cd8e

core: call _get_device() with the master MTD, not the partition

__get_mtd_device() passed the possibly-partition-level mtd to the master's _get_device() callback, while __put_mtd_device() passed the master. This broke gluebi partitions, whose gluebi_get_device() uses container_of() and requires the master MTD.

Why it matters: Fixes gluebi partition handling by making get and put symmetric.

12b31d1acd20

mtd_intel_dg: reset poll counter for each 4K erase

The non-posted erase polling counter was initialized once per erase request, so large requests spanning multiple 4K erase commands shared a single polling budget and could fail with -ETIME even though no individual command timed out. The fix resets the counter per 4K erase command.

Why it matters: Prevents false -ETIME failures on large multi-erase requests on Intel DG NVM.

200c32e3cd53

spi-nor: fix mutex leak in spi_nor_rww_start_exclusive()

An exclusive read-while-write helper used guard(mutex) inconsistently with the other RWW helpers, leaving nor->lock held on the busy return path. The fix adopts the same guard pattern so the mutex is released on all paths.

Why it matters: Fixes a mutex leak that could deadlock SPI-NOR exclusive access paths.

44b8a0bf5f96

cfi_cmdset_0001: shrink do_write_buffer() stack frame for arm32 KASAN builds

arm32 allmodconfig with KASAN_STACK exceeded the 1280-byte frame limit because do_write_buffer() built a 32-byte map_word for each of twelve commands, and KASAN redzoned every temporary. The fix routes commands through a noinline helper that builds the map_word in its own frame, without changing the actual read/write sequence to the chip.

Why it matters: Fixes a build failure on arm32 allmodconfig with KASAN enabled.

39b975ff2086

RTC fixes

Zero-initialize rtc_wkalrm to prevent kernel stack leak via RTC_WKALRM_RD

struct rtc_wkalrm has padding holes after the 'pending' member. When returned to userspace via the RTC_WKALRM_RD ioctl, uninitialized kernel stack data in those holes could be leaked. Zero-initializing the struct at declaration eliminates the risk.

Why it matters: Closes an information leak through the RTC alarm read ioctl.

0ee5c5d804d5

EFI RTC: restore alarm support with runtime capability probe

A prior commit removed EFI RTC wakeup functionality entirely because many platforms incorrectly advertised the capability. However, this also broke platforms where the wakeup runtime service genuinely works — notably CIX SoCs, where the RTC is an I2C device owned by firmware and EFI runtime services are the only OS access path. The fix restores alarm support with a proper capability probe.

Why it matters: Restores RTC alarm functionality on EFI platforms where the wakeup service actually works.

b430d1f6d80c

spear and mpfs RTC: fix probe ordering and unchecked error pointer

The spear RTC driver requested its alarm IRQ before initializing the MMIO address and spinlock, allowing the handler to run on uninitialized state. The mpfs RTC driver passed an unchecked devm_clk_get() error pointer into clk_get_rate(), which dereferences it instead of returning 0 — a real crash on -EPROBE_DEFER.

Why it matters: Spear: closes a probe-time IRQ race. Mpfs: prevents a crash on deferred probe.

055ef5ce9f67ac41b05d15db

ac100 RTC: fix __counted_by ordering and clock provider use-after-free

The ac100 driver assigned .hws[] before .num, triggering UBSAN_BOUNDS warnings under CONFIG_UBSAN_BOUNDS since __counted_by requires .num first. Separately, if devm_rtc_register_device() failed after clocks were registered, the of_clk provider was left on the global list referencing devm-allocated memory freed during probe unwind — a use-after-free.

Why it matters: Ac100: fixes sanitizer warnings and a use-after-free on probe failure.

6a4117eee82dfcf0b58e976e

Memory management and module loader

shmem: ignore sysfs THP/mTHP settings for MADV_COLLAPSE

After a recent change, MADV_COLLAPSE on shmem depended on the shmem_enabled sysfs setting being 'inherit', causing unexpected failures. Documentation states MADV_COLLAPSE should ignore THP/mTHP interface settings. The fix returns shmem_huge_global_enabled() directly for collapse requests.

Why it matters: Fixes a userspace-visible performance regression where MADV_COLLAPSE on shmem could fail unexpectedly.

72c3d682c165

DAMON: fix quota adjustment being skipped while effective size is nonzero

When a user disables all DAMOS quotas via the online commit feature, damos_adjust_quota() skipped all work — including esz updates and charged-quota resets — even if esz was still nonzero from a previous configuration. This caused DAMOS to stop working unexpectedly. The fix corrects the quota-unset check.

Why it matters: Fixes DAMOS schemes silently stopping when quotas are disabled online with a residual effective size.

52ae167ce166

KASAN: unpoison task stack below watermark only in generic mode

CONFIG_KASAN_STACK enabled the stack-unpoisoning helper for SW_TAGS mode, but it derives the stack base from an untagged pointer and writes 0xff into shadow memory that still carries the original allocation tag, causing a tag mismatch on vmapped stacks. The fix restricts the helper to generic KASAN only.

Why it matters: Prevents false KASAN tag-mismatch reports on vmapped task stacks in SW_TAGS mode.

22ab0647764c

mm/vma: predicate setting mmap_prepare VMA fields on new VMA allocation

The mmap_prepare hook unconditionally overwrote vm_ops and vm_private_data even when the VMA was merged rather than newly allocated, destructively clearing existing state without calling vm_ops->mapped. The fix only manipulates those fields when a new VMA was actually allocated.

Why it matters: Prevents destructive state corruption when mmap_prepare runs on a merged VMA.

976d5e0ddac8

module: fix lost error code from codetag_load_module()

If codetag_load_module() failed, err was never set, so load_module() returned 0 for a module that had already been torn down. Additionally, for livepatch modules, mod->klp_info leaked on this error path. The fix sets the error code and adds a livepatch_cleanup label.

Why it matters: Prevents a false-success return after failed module codetag load and fixes a livepatch memory leak.

c79cf15eb35a

ARC architecture

Fix clk reference leak in /proc/cpuinfo and cmpxchg type-size bug

show_cpuinfo() called clk_get() but never clk_put(), leaking a clock reference every time /proc/cpuinfo was read. Separately, arch_cmpxchg_relaxed used the size of the pointer rather than the pointed-to type, which also exposed a missing arch_atomic64_cmpxchg_relaxed definition.

Why it matters: Clock leak: fixes per-read resource leak. Cmpxchg: fixes type-safety bug that affected two-byte cmpxchg emulation.

d12c6a6f0c8ff050c3e61d2a

Remove dead ARC_CANT_LLSC Kconfig option and unused profile.h includes

The ARC_CANT_LLSC config option could never be enabled and was referenced nowhere; it was removed as dead code found by kconfirm static analysis. Separately, unused profile.h includes were stripped from ARC kernel sources.

Why it matters: Routine cleanup with no functional change.

86ad6489e38c04eb7b5e043f

Source commits33 entries +
b5965c422116

mtd: block2mtd: Fix divide error when erase_size is zero

Pei Xiao · Aug 13, 2026 · 1 files

63d6cace2c4a

mtd: spinand: Enable QE on all dies

Han Xu · Aug 13, 2026 · 1 files

86ad6489e38c

ARC: cleanup dead ARC_CANT_LLSC option in Kconfig

Julian Braha · Aug 16, 2026 · 1 files

26300879cd8e

mtd: core: avoid double-free of OTP NVMEM device

Karl Mehltretter · Aug 16, 2026 · 1 files

12b31d1acd20

mtd: core: call _get_device() with the master MTD

Karl Mehltretter · Aug 16, 2026 · 1 files

04eb7b5e043f

arc: remove unused profile.h includes

Anthony Iliopoulos · Aug 20, 2026 · 1 files

39b975ff2086

mtd: cfi_cmdset_0001: shrink do_write_buffer() stack frame

Karl Mehltretter · Aug 24, 2026 · 1 files

0ee5c5d804d5

rtc: dev: zero-initialize struct rtc_wkalrm to prevent information leak

Liu Dalin · Aug 27, 2026 · 1 files

c79cf15eb35a

module: fix lost error code from codetag_load_module()

Hao Ge · Aug 27, 2026 · 1 files

200c32e3cd53

mtd: mtd_intel_dg: reset poll counter for each erase

Menachem Adin · Aug 27, 2026 · 1 files

44b8a0bf5f96

mtd: spi-nor: core: Fix mutex leak in spi_nor_rww_start_exclusive()

Runyu Xiao · Aug 27, 2026 · 1 files

b430d1f6d80c

rtc: efi: restore alarm support with runtime capability probe

Johnny.Fan · Aug 31, 2026 · 1 files

b890e6163761

mtd: spinand: fix NULL pointer dereference with no ECC engine

Nuno Sá · Aug 31, 2026 · 3 files

636fe10d8f35

mtd: spinand: fix zero oobavail when no ECC engine is used

Nuno Sá · Aug 31, 2026 · 1 files

37adc9c5789c

mtd: rawnand: vf610_nfc: fix reads on chips with more than 64 bytes of OOB

Mehmet Fide · Sep 1, 2026 · 1 files

68fe2faf5c69

mtd: rawnand: vf610_nfc: fix false bitflips on reads of erased pages

Mehmet Fide · Sep 1, 2026 · 1 files

21f027016b12

mtd: rawnand: cadence: Initialize IRQ state before requesting IRQ

Runyu Xiao · Sep 2, 2026 · 1 files

055ef5ce9f67

rtc: spear: initialize IRQ state before requesting alarm IRQ

Runyu Xiao · Sep 2, 2026 · 1 files

6a4117eee82d

rtc: ac100: Assign .num before accessing .hws

Aamir Ahmed · Sep 5, 2026 · 1 files

fcf0b58e976e

rtc: ac100: Fix clock provider use-after-free on probe failure

Aamir Ahmed · Sep 5, 2026 · 1 files

ac41b05d15db

rtc: mpfs: fix unchecked devm_clk_get() error pointer in probe()

Manush Prajwal · Sep 6, 2026 · 1 files

d12c6a6f0c8f

arc: kernel: Fix clk reference leak in show_cpuinfo()

blaze · Sep 9, 2026 · 1 files

1c1a342aceec

mtd: spinand: Do not update the QE bit on devices without one

Sagnik Sasmal · Sep 10, 2026 · 1 files

72c3d682c165

mm: shmem: ignore sysfs configs for shmem forced collapse

Baolin Wang · Sep 14, 2026 · 1 files

347c6ed8cf77

alloc_tag: avoid implicit padding in uapi

Arnd Bergmann · Sep 15, 2026 · 1 files

52ae167ce166

mm/damon/core: don't skip damos_adjust_quota() while esz is not zero

SJ Park · Sep 16, 2026 · 1 files

22ab0647764c

kasan: unpoison task stack below watermark only in generic mode

Andrey Ryabinin · Sep 16, 2026 · 1 files

711d886fe76e

MAINTAINERS: split up MEMORY MANAGEMENT - MEMORY POLICY AND MIGRATION

David Hildenbrand (Arm) · Sep 18, 2026 · 1 files

4050a73a90f4

MAINTAINERS: move memory tiering under MEMORY MANAGEMENT - NUMA PLACEMENT

David Hildenbrand (Arm) · Sep 18, 2026 · 1 files

b3f0c1a4e41f

MAINTAINERS: make Gregory a co-maintainer of MEMORY MANAGEMENT - NUMA PLACEMENT

David Hildenbrand (Arm) · Sep 18, 2026 · 1 files

6cc8f549f688

MAINTAINERS: add Heming Zhao as ocfs2 reviewer

Joseph Qi · Sep 23, 2026 · 1 files

976d5e0ddac8

mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc

Lorenzo Stoakes (ARM) · Sep 23, 2026 · 1 files

f050c3e61d2a

ARC: arch_cmpxchg_relaxed to use size of pointed type not pointer

Vineet Gupta · Sep 23, 2026 · 2 files