Daily update · Sep 29–30, 2026
MTD fixes lead the day: SPI-NAND QE and no-ECC-engine bugs, vf610 NAND controller, RTC and mm cleanups
A batch of notable fixes across the MTD subsystem, plus RTC, memory management, module loader, and ARC patches.
In brief
The MTD subsystem received the bulk of today's fixes, with several SPI-NAND corrections around quad-enable (QE) bit handling and the no-ECC-engine code path, plus a pair of subtle vf610 NAND controller fixes. RTC, memory management, and the module loader also saw real bug fixes.
SPI-NAND fixes
Enable QE bit on all dies of multi-die SPI-NAND devices
On some multi-die SPI-NAND parts the QE (quad-enable) bit lives in a per-die config register. Updating only the currently selected die left other dies in non-quad mode. The fix iterates over all targets during initialization. Tested on ISSI IS38SMW04G8B.
Why it matters: Ensures consistent quad I/O across the entire device on multi-die SPI-NAND flash.
Do not clear the QE bit on SPI-NAND devices that lack one
A refactor made spinand_init_quad_enable() run unconditionally, clearing config-register bit 0 on devices without a QE bit. On the Winbond W25N02KV that bit is H-DIS (HOLD disable), so clearing it enables HOLD during single/dual I/O — if IO3 is not held high the flash can pause a command mid-transfer. H-DIS is not restored by a reset command, so the corruption persists.
Why it matters: Prevents silent flash command interruption and persistent misconfiguration on affected Winbond parts.
Fix NULL pointer dereference when no ECC engine is configured
When 'nand-no-ecc-engine' is set in device tree, nanddev_get_ecc_engine() returns success but leaves nand->ecc.engine NULL. SPI-NAND code dereferenced it unconditionally to test for a pipelined engine, oopsing on probe. A new nand_ecc_is_pipelined() helper folds in the NULL check.
Why it matters: Fixes an immediate kernel oops when probing SPI-NAND devices configured without an ECC engine.
Fix zero oobavail when no ECC engine is used
When no ECC engine is requested, mtd->oobavail was assigned from a zero return value, advertising zero available OOB bytes. This makes every automatic OOB access fail with -EINVAL, and JFFS2 — which stores its cleanmarker in OOB on NAND — refuses to mount entirely.
Why it matters: Restores correct OOB availability and JFFS2 mountability on SPI-NAND devices without an ECC engine.
Raw NAND controller fixes
vf610_nfc: fix reads on chips with more than 64 bytes of OOB
The VF610 NFC controller transfers only 64 spare bytes per page; the driver clamps mtd->oobsize in attach_chip(), but nand_scan_tail() restores the chip's full OOB size afterward. The mismatch causes every ECC-protected read to fail with -EBADMSG. Measured on a Colibri VF61 with a Micron MX30LF4G28AC (112-byte OOB).
Why it matters: Fixes read failures on NAND chips whose OOB exceeds the controller's 64-byte spare area.
vf610_nfc: fix false bitflips on reads of erased pages
When the ECC engine fails to decode a page, the driver re-reads OOB with the engine bypassed but runs the erased-page check on stale controller SRAM data. In 60-byte ECC mode the all-0xff erased page always decodes to the same error location, producing a phantom zero bit at data offset 0x5FD on every erased page. The fix ensures the erased-page check reads actual flash content.
Why it matters: Eliminates spurious corrected-bitflip reports on erased pages on the vf610 NFC controller.
Cadence NAND: initialize IRQ state before requesting the interrupt
The interrupt handler uses both an IRQ lock and a completion object, but the IRQ was registered before those were initialized, leaving a window for a pending interrupt to touch uninitialized synchronization state.
Why it matters: Closes a race where a pending interrupt could access uninitialized data during probe.
Other MTD fixes
block2mtd: fix divide error when erase_size is zero
The erase size parsed from the 'block2mtd' module parameter can be set to zero. add_device() then evaluates 'size % erase_size' with a zero divisor, triggering a divide error. The fix rejects a zero erase size before the modulo.
Why it matters: Prevents a kernel oops when the block2mtd module parameter is given an erase_size of zero.
core: avoid double-free of OTP NVMEM device
If factory OTP setup failed after user OTP NVMEM registration, the user device was unregistered but the pointer was not cleared, leading to a second unregister on error or teardown. The fix sets mtd->otp_user_nvmem to NULL after unregistering.
Why it matters: Fixes a double-free in the OTP NVMEM error and teardown paths.
core: call _get_device() with the master MTD, not the partition
__get_mtd_device() passed the possibly-partition-level mtd to the master's _get_device() callback, while __put_mtd_device() passed the master. This broke gluebi partitions, whose gluebi_get_device() uses container_of() and requires the master MTD.
Why it matters: Fixes gluebi partition handling by making get and put symmetric.
mtd_intel_dg: reset poll counter for each 4K erase
The non-posted erase polling counter was initialized once per erase request, so large requests spanning multiple 4K erase commands shared a single polling budget and could fail with -ETIME even though no individual command timed out. The fix resets the counter per 4K erase command.
Why it matters: Prevents false -ETIME failures on large multi-erase requests on Intel DG NVM.
spi-nor: fix mutex leak in spi_nor_rww_start_exclusive()
An exclusive read-while-write helper used guard(mutex) inconsistently with the other RWW helpers, leaving nor->lock held on the busy return path. The fix adopts the same guard pattern so the mutex is released on all paths.
Why it matters: Fixes a mutex leak that could deadlock SPI-NOR exclusive access paths.
cfi_cmdset_0001: shrink do_write_buffer() stack frame for arm32 KASAN builds
arm32 allmodconfig with KASAN_STACK exceeded the 1280-byte frame limit because do_write_buffer() built a 32-byte map_word for each of twelve commands, and KASAN redzoned every temporary. The fix routes commands through a noinline helper that builds the map_word in its own frame, without changing the actual read/write sequence to the chip.
Why it matters: Fixes a build failure on arm32 allmodconfig with KASAN enabled.
RTC fixes
Zero-initialize rtc_wkalrm to prevent kernel stack leak via RTC_WKALRM_RD
struct rtc_wkalrm has padding holes after the 'pending' member. When returned to userspace via the RTC_WKALRM_RD ioctl, uninitialized kernel stack data in those holes could be leaked. Zero-initializing the struct at declaration eliminates the risk.
Why it matters: Closes an information leak through the RTC alarm read ioctl.
EFI RTC: restore alarm support with runtime capability probe
A prior commit removed EFI RTC wakeup functionality entirely because many platforms incorrectly advertised the capability. However, this also broke platforms where the wakeup runtime service genuinely works — notably CIX SoCs, where the RTC is an I2C device owned by firmware and EFI runtime services are the only OS access path. The fix restores alarm support with a proper capability probe.
Why it matters: Restores RTC alarm functionality on EFI platforms where the wakeup service actually works.
spear and mpfs RTC: fix probe ordering and unchecked error pointer
The spear RTC driver requested its alarm IRQ before initializing the MMIO address and spinlock, allowing the handler to run on uninitialized state. The mpfs RTC driver passed an unchecked devm_clk_get() error pointer into clk_get_rate(), which dereferences it instead of returning 0 — a real crash on -EPROBE_DEFER.
Why it matters: Spear: closes a probe-time IRQ race. Mpfs: prevents a crash on deferred probe.
ac100 RTC: fix __counted_by ordering and clock provider use-after-free
The ac100 driver assigned .hws[] before .num, triggering UBSAN_BOUNDS warnings under CONFIG_UBSAN_BOUNDS since __counted_by requires .num first. Separately, if devm_rtc_register_device() failed after clocks were registered, the of_clk provider was left on the global list referencing devm-allocated memory freed during probe unwind — a use-after-free.
Why it matters: Ac100: fixes sanitizer warnings and a use-after-free on probe failure.
Memory management and module loader
shmem: ignore sysfs THP/mTHP settings for MADV_COLLAPSE
After a recent change, MADV_COLLAPSE on shmem depended on the shmem_enabled sysfs setting being 'inherit', causing unexpected failures. Documentation states MADV_COLLAPSE should ignore THP/mTHP interface settings. The fix returns shmem_huge_global_enabled() directly for collapse requests.
Why it matters: Fixes a userspace-visible performance regression where MADV_COLLAPSE on shmem could fail unexpectedly.
DAMON: fix quota adjustment being skipped while effective size is nonzero
When a user disables all DAMOS quotas via the online commit feature, damos_adjust_quota() skipped all work — including esz updates and charged-quota resets — even if esz was still nonzero from a previous configuration. This caused DAMOS to stop working unexpectedly. The fix corrects the quota-unset check.
Why it matters: Fixes DAMOS schemes silently stopping when quotas are disabled online with a residual effective size.
KASAN: unpoison task stack below watermark only in generic mode
CONFIG_KASAN_STACK enabled the stack-unpoisoning helper for SW_TAGS mode, but it derives the stack base from an untagged pointer and writes 0xff into shadow memory that still carries the original allocation tag, causing a tag mismatch on vmapped stacks. The fix restricts the helper to generic KASAN only.
Why it matters: Prevents false KASAN tag-mismatch reports on vmapped task stacks in SW_TAGS mode.
mm/vma: predicate setting mmap_prepare VMA fields on new VMA allocation
The mmap_prepare hook unconditionally overwrote vm_ops and vm_private_data even when the VMA was merged rather than newly allocated, destructively clearing existing state without calling vm_ops->mapped. The fix only manipulates those fields when a new VMA was actually allocated.
Why it matters: Prevents destructive state corruption when mmap_prepare runs on a merged VMA.
module: fix lost error code from codetag_load_module()
If codetag_load_module() failed, err was never set, so load_module() returned 0 for a module that had already been torn down. Additionally, for livepatch modules, mod->klp_info leaked on this error path. The fix sets the error code and adds a livepatch_cleanup label.
Why it matters: Prevents a false-success return after failed module codetag load and fixes a livepatch memory leak.
ARC architecture
Fix clk reference leak in /proc/cpuinfo and cmpxchg type-size bug
show_cpuinfo() called clk_get() but never clk_put(), leaking a clock reference every time /proc/cpuinfo was read. Separately, arch_cmpxchg_relaxed used the size of the pointer rather than the pointed-to type, which also exposed a missing arch_atomic64_cmpxchg_relaxed definition.
Why it matters: Clock leak: fixes per-read resource leak. Cmpxchg: fixes type-safety bug that affected two-byte cmpxchg emulation.
Remove dead ARC_CANT_LLSC Kconfig option and unused profile.h includes
The ARC_CANT_LLSC config option could never be enabled and was referenced nowhere; it was removed as dead code found by kconfirm static analysis. Separately, unused profile.h includes were stripped from ARC kernel sources.
Why it matters: Routine cleanup with no functional change.
Source commits33 entries +
mtd: block2mtd: Fix divide error when erase_size is zero
Pei Xiao · Aug 13, 2026 · 1 files
mtd: spinand: Enable QE on all dies
Han Xu · Aug 13, 2026 · 1 files
ARC: cleanup dead ARC_CANT_LLSC option in Kconfig
Julian Braha · Aug 16, 2026 · 1 files
mtd: core: avoid double-free of OTP NVMEM device
Karl Mehltretter · Aug 16, 2026 · 1 files
mtd: core: call _get_device() with the master MTD
Karl Mehltretter · Aug 16, 2026 · 1 files
arc: remove unused profile.h includes
Anthony Iliopoulos · Aug 20, 2026 · 1 files
mtd: cfi_cmdset_0001: shrink do_write_buffer() stack frame
Karl Mehltretter · Aug 24, 2026 · 1 files
rtc: dev: zero-initialize struct rtc_wkalrm to prevent information leak
Liu Dalin · Aug 27, 2026 · 1 files
module: fix lost error code from codetag_load_module()
Hao Ge · Aug 27, 2026 · 1 files
mtd: mtd_intel_dg: reset poll counter for each erase
Menachem Adin · Aug 27, 2026 · 1 files
mtd: spi-nor: core: Fix mutex leak in spi_nor_rww_start_exclusive()
Runyu Xiao · Aug 27, 2026 · 1 files
rtc: efi: restore alarm support with runtime capability probe
Johnny.Fan · Aug 31, 2026 · 1 files
mtd: spinand: fix NULL pointer dereference with no ECC engine
Nuno Sá · Aug 31, 2026 · 3 files
mtd: spinand: fix zero oobavail when no ECC engine is used
Nuno Sá · Aug 31, 2026 · 1 files
mtd: rawnand: vf610_nfc: fix reads on chips with more than 64 bytes of OOB
Mehmet Fide · Sep 1, 2026 · 1 files
mtd: rawnand: vf610_nfc: fix false bitflips on reads of erased pages
Mehmet Fide · Sep 1, 2026 · 1 files
mtd: rawnand: cadence: Initialize IRQ state before requesting IRQ
Runyu Xiao · Sep 2, 2026 · 1 files
rtc: spear: initialize IRQ state before requesting alarm IRQ
Runyu Xiao · Sep 2, 2026 · 1 files
rtc: ac100: Assign .num before accessing .hws
Aamir Ahmed · Sep 5, 2026 · 1 files
rtc: ac100: Fix clock provider use-after-free on probe failure
Aamir Ahmed · Sep 5, 2026 · 1 files
rtc: mpfs: fix unchecked devm_clk_get() error pointer in probe()
Manush Prajwal · Sep 6, 2026 · 1 files
arc: kernel: Fix clk reference leak in show_cpuinfo()
blaze · Sep 9, 2026 · 1 files
mtd: spinand: Do not update the QE bit on devices without one
Sagnik Sasmal · Sep 10, 2026 · 1 files
mm: shmem: ignore sysfs configs for shmem forced collapse
Baolin Wang · Sep 14, 2026 · 1 files
alloc_tag: avoid implicit padding in uapi
Arnd Bergmann · Sep 15, 2026 · 1 files
mm/damon/core: don't skip damos_adjust_quota() while esz is not zero
SJ Park · Sep 16, 2026 · 1 files
kasan: unpoison task stack below watermark only in generic mode
Andrey Ryabinin · Sep 16, 2026 · 1 files
MAINTAINERS: split up MEMORY MANAGEMENT - MEMORY POLICY AND MIGRATION
David Hildenbrand (Arm) · Sep 18, 2026 · 1 files
MAINTAINERS: move memory tiering under MEMORY MANAGEMENT - NUMA PLACEMENT
David Hildenbrand (Arm) · Sep 18, 2026 · 1 files
MAINTAINERS: make Gregory a co-maintainer of MEMORY MANAGEMENT - NUMA PLACEMENT
David Hildenbrand (Arm) · Sep 18, 2026 · 1 files
MAINTAINERS: add Heming Zhao as ocfs2 reviewer
Joseph Qi · Sep 23, 2026 · 1 files
mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc
Lorenzo Stoakes (ARM) · Sep 23, 2026 · 1 files
ARC: arch_cmpxchg_relaxed to use size of pointed type not pointer
Vineet Gupta · Sep 23, 2026 · 2 files