diff --git a/changelog/updates/2026-09-29-linux-6.18.md b/changelog/updates/2026-09-29-linux-6.18.md new file mode 100644 index 00000000000..0539d0ccfb4 --- /dev/null +++ b/changelog/updates/2026-09-29-linux-6.18.md @@ -0,0 +1 @@ +- Linux [6.18.45](https://lwn.net/Articles/1089546/) diff --git a/sdk_container/src/third_party/coreos-overlay/app-emulation/hv-daemons/hv-daemons-6.12.111.ebuild b/sdk_container/src/third_party/coreos-overlay/app-emulation/hv-daemons/hv-daemons-6.18.45.ebuild similarity index 100% rename from sdk_container/src/third_party/coreos-overlay/app-emulation/hv-daemons/hv-daemons-6.12.111.ebuild rename to sdk_container/src/third_party/coreos-overlay/app-emulation/hv-daemons/hv-daemons-6.18.45.ebuild diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.12.111.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.18.45.ebuild similarity index 99% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.12.111.ebuild rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.18.45.ebuild index 9826aa54454..bb07dbb104a 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.12.111.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.18.45.ebuild @@ -1,4 +1,4 @@ -# Copyright 2014-2016 CoreOS, Inc. +# Copyright 2026 The Flatcar Container Linux Maintainers # Distributed under the terms of the GNU General Public License v2 EAPI=8 @@ -33,7 +33,6 @@ DEPEND=" sys-apps/busybox sys-apps/coreutils sys-apps/findutils - sys-apps/gptfdisk sys-apps/grep sys-apps/hwdata sys-apps/ignition:= diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.12.111.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.18.45.ebuild similarity index 87% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.12.111.ebuild rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.18.45.ebuild index 1e41fc6b5e0..48886a79f19 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.12.111.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.18.45.ebuild @@ -1,4 +1,4 @@ -# Copyright 2014-2016 CoreOS, Inc. +# Copyright 2026 The Flatcar Container Linux Maintainers # Distributed under the terms of the GNU General Public License v2 EAPI=7 @@ -51,7 +51,7 @@ src_install() { # Replace the broken /lib/modules/${KV_FULL}/build symlink with a copy of # the files needed to build out-of-tree modules. rm "${ED}/usr/${build}" || die - kmake run-command KBUILD_RUN_COMMAND="${KV_DIR}/scripts/package/install-extmod-build ${ED}/usr/${build}" + kmake run-command KBUILD_RUN_COMMAND="${KERNEL_DIR}/scripts/package/install-extmod-build ${ED}/usr/${build}" # Install the original config because the above doesn't. insinto "/usr/${build}" @@ -61,6 +61,6 @@ src_install() { dosym "../${build}/.config" "/usr/boot/config-${KV_FULL}" dosym "../${build}/.config" "/usr/boot/config" - # Symlink "source" to "build" for compatibility. Fedora does this. - dosym build "/usr/${build}/../source" + # Symlink "source" to "build" for compatibility. Fedora does this. + dosym build "/usr/${build}/../source" } diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.12 b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.18 similarity index 98% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.12 rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.18 index 73fa616457f..87b981ac6d6 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.12 +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.18 @@ -21,8 +21,6 @@ CONFIG_CMDLINE_BOOL=y CONFIG_CONNECTOR=y CONFIG_CRASH_DUMP=y CONFIG_CRYPTO_AES_NI_INTEL=m -CONFIG_CRYPTO_SHA1_SSSE3=m -CONFIG_CRYPTO_SHA256_SSSE3=m CONFIG_DCDBAS=m CONFIG_DEBUG_BOOT_PARAMS=y CONFIG_DELL_RBU=m diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.12 b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.18 similarity index 97% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.12 rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.18 index 1fc273f107b..7d3462e787f 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.12 +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.18 @@ -31,8 +31,6 @@ CONFIG_CRYPTO_AES_ARM64_CE_CCM=y CONFIG_CRYPTO_AES_ARM64_NEON_BLK=y CONFIG_CRYPTO_ANSI_CPRNG=y CONFIG_CRYPTO_GHASH_ARM64_CE=y -CONFIG_CRYPTO_SHA1_ARM64_CE=y -CONFIG_CRYPTO_SHA2_ARM64_CE=y # CONFIG_DEBUG_PREEMPT is not set CONFIG_DMA_BCM2835=y CONFIG_DMA_CMA=y diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.12 b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.18 similarity index 98% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.12 rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.18 index a97b740cbe4..5dde04eec61 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.12 +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.18 @@ -42,6 +42,7 @@ CONFIG_BLK_DEV_SR=m CONFIG_BLK_DEV_THROTTLING=y CONFIG_BLK_WBT=y CONFIG_BNA=m +CONFIG_BNGE=m CONFIG_BNX2X=m CONFIG_BNXT=m CONFIG_BONDING=m @@ -75,6 +76,7 @@ CONFIG_BRIDGE_EBT_T_NAT=m CONFIG_BRIDGE_EBT_VLAN=m CONFIG_BRIDGE_NETFILTER=y CONFIG_BRIDGE_NF_EBTABLES=m +CONFIG_BRIDGE_NF_EBTABLES_LEGACY=m CONFIG_BRIDGE_VLAN_FILTERING=y CONFIG_BROADCOM_PHY=m CONFIG_BSD_DISKLABEL=y @@ -125,6 +127,7 @@ CONFIG_CPU_FREQ_GOV_USERSPACE=m CONFIG_CPU_FREQ_STAT=y # CONFIG_CROSS_MEMORY_ATTACH is not set CONFIG_CRYPTO_AES=m +CONFIG_CRYPTO_CRC32C=y CONFIG_CRYPTO_CTR=m CONFIG_CRYPTO_CTS=m CONFIG_CRYPTO_DES=m @@ -138,7 +141,7 @@ CONFIG_CRYPTO_LIB_GF128MUL=m CONFIG_CRYPTO_LZO=m # CONFIG_CRYPTO_MANAGER_DISABLE_TESTS is not set CONFIG_CRYPTO_NULL=m -CONFIG_CRYPTO_NULL2=m +CONFIG_CRYPTO_SELFTESTS=y CONFIG_CRYPTO_SHA1=y CONFIG_CRYPTO_USER_API_HASH=m CONFIG_CRYPTO_USER_API_SKCIPHER=m @@ -170,6 +173,7 @@ CONFIG_DM_ZERO=m CONFIG_DNS_RESOLVER=y CONFIG_DRM=y CONFIG_DRM_FBDEV_EMULATION=y +CONFIG_DRM_HYPERV=m CONFIG_DRM_QXL=m CONFIG_DRM_SIMPLEDRM=m CONFIG_DRM_TTM_HELPER=m @@ -177,7 +181,6 @@ CONFIG_DRM_VIRTIO_GPU=y CONFIG_DST_CACHE=y CONFIG_DUMMY=m CONFIG_DYNAMIC_DEBUG=y -CONFIG_DYNAMIC_FTRACE=y CONFIG_E100=m CONFIG_E1000=m CONFIG_E1000E=m @@ -201,7 +204,6 @@ CONFIG_FANOTIFY_ACCESS_PERMISSIONS=y CONFIG_FAT_DEFAULT_IOCHARSET="ascii" CONFIG_FB=y CONFIG_FB_EFI=y -CONFIG_FB_HYPERV=m CONFIG_FCOE=m # CONFIG_FIRMWARE_IN_KERNEL is not set CONFIG_FORCEDETH=m @@ -209,7 +211,7 @@ CONFIG_FORTIFY_SOURCE=y CONFIG_FRAMEBUFFER_CONSOLE=y CONFIG_FRAMEBUFFER_CONSOLE_DETECT_PRIMARY=y CONFIG_FRAMEBUFFER_CONSOLE_ROTATION=y -CONFIG_FSCACHE=m +CONFIG_FSCACHE=y CONFIG_FSCACHE_STATS=y CONFIG_FS_DAX=y CONFIG_FS_ENCRYPTION=y @@ -232,15 +234,10 @@ CONFIG_GRO_CELLS=y CONFIG_GTP=m CONFIG_HARDENED_USERCOPY=y CONFIG_HIDRAW=y -CONFIG_HID_A4TECH=m CONFIG_HID_APPLE=m CONFIG_HID_BELKIN=m -CONFIG_HID_CHERRY=m -CONFIG_HID_EZKEY=m CONFIG_HID_HYPERV_MOUSE=m -CONFIG_HID_LOGITECH=m CONFIG_HID_MICROSOFT=m -CONFIG_HID_MONTEREY=m CONFIG_HIGH_RES_TIMERS=y CONFIG_HOTPLUG_PCI=y CONFIG_HOTPLUG_PCI_ACPI=y @@ -251,7 +248,8 @@ CONFIG_HWMON=m CONFIG_HW_RANDOM=y CONFIG_HW_RANDOM_TIMERIOMEM=m CONFIG_HW_RANDOM_VIRTIO=y -CONFIG_HYPERV=m +CONFIG_HYPERV=y +CONFIG_HYPERV_VMBUS=m CONFIG_HYPERV_BALLOON=m CONFIG_HYPERV_NET=m CONFIG_HYPERV_UTILS=m @@ -354,7 +352,6 @@ CONFIG_IPV6_SUBTREES=y CONFIG_IPV6_VTI=m CONFIG_IPVLAN=m CONFIG_IP_ADVANCED_ROUTER=y -CONFIG_IP_DCCP=m CONFIG_IP_FIB_TRIE_STATS=y CONFIG_IP_MROUTE=y CONFIG_IP_MROUTE_MULTIPLE_TABLES=y @@ -534,6 +531,7 @@ CONFIG_NETFILTER_ADVANCED=y CONFIG_NETFILTER_NETLINK_GLUE_CT=y CONFIG_NETFILTER_NETLINK_QUEUE=m CONFIG_NETFILTER_XTABLES=y +CONFIG_NETFILTER_XTABLES_LEGACY=y CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=m CONFIG_NETFILTER_XT_MATCH_BPF=m CONFIG_NETFILTER_XT_MATCH_CGROUP=m @@ -787,6 +785,7 @@ CONFIG_OPENVSWITCH=m CONFIG_OVERLAY_FS=m CONFIG_OVERLAY_FS_METACOPY=y CONFIG_OVERLAY_FS_REDIRECT_DIR=y +CONFIG_OVPN=m CONFIG_PACKET=y CONFIG_PACKET_DIAG=m CONFIG_PANIC_ON_OOPS=y @@ -800,6 +799,7 @@ CONFIG_PCI=y CONFIG_PCIEAER=y CONFIG_PCIEPORTBUS=y CONFIG_PCIE_ECRC=y +CONFIG_PCIE_THERMAL=y CONFIG_PCI_HYPERV=m CONFIG_PCI_IOV=y CONFIG_PCI_MSI=y @@ -896,7 +896,6 @@ CONFIG_SCSI_SCAN_ASYNC=y CONFIG_SCSI_SMARTPQI=m CONFIG_SCSI_SYM53C8XX_2=m CONFIG_SCSI_VIRTIO=m -CONFIG_SCTP_COOKIE_HMAC_SHA1=y CONFIG_SECURITY=y CONFIG_SECURITY_LANDLOCK=y CONFIG_SECURITY_LOCKDOWN_LSM=y @@ -965,6 +964,7 @@ CONFIG_TLS_DEVICE=y CONFIG_TLS_TOE=y CONFIG_TMPFS=y CONFIG_TMPFS_POSIX_ACL=y +CONFIG_TRACEFS_AUTOMOUNT_DEPRECATED=n CONFIG_TRANSPARENT_HUGEPAGE=y CONFIG_TRUSTED_KEYS=m CONFIG_TTY_PRINTK=y @@ -1003,7 +1003,6 @@ CONFIG_VFIO=m CONFIG_VFIO_PCI=m CONFIG_VFIO_PCI_CORE=m CONFIG_VFIO_PCI_INTX=y -CONFIG_VFIO_PCI_MMAP=y CONFIG_VHOST_IOTLB=m CONFIG_VHOST_NET=m CONFIG_VHOST_RING=m @@ -1018,6 +1017,7 @@ CONFIG_VIRTIO_MMIO=y CONFIG_VIRTIO_MMIO_CMDLINE_DEVICES=y CONFIG_VIRTIO_NET=m CONFIG_VIRTIO_PCI=y +CONFIG_VIRTIO_RTC=m CONFIG_VIRTIO_VSOCKETS=m CONFIG_VIRT_DRIVERS=y CONFIG_VLAN_8021Q=m diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/Manifest b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/Manifest index 0944d63f9b5..34f33055170 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/Manifest +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/Manifest @@ -1,2 +1,2 @@ -DIST linux-6.12.tar.xz 147906904 BLAKE2B b2ec2fc69218cacabbbe49f78384a5d259ca581b717617c12b000b16f4a4c59ee348ea886b37147f5f70fb9a7a01c1e2c8f19021078f6b23f5bc62d1c48d5e5e SHA512 a37b1823df7b4f72542f689b65882634740ba0401a42fdcf6601d9efd2e132e5a7650e70450ba76f6cd1f13ca31180f2ccee9d54fe4df89bc0000ade4380a548 -DIST patch-6.12.111.xz 6351668 BLAKE2B 5c82ae2deb7ee2abffa91f6126b4dbba602cff5ca0ed2cd18814ba3f354edec332d2a9c8055c9f44c9bcd0276c6526ea85859ea625d4e7e577942830e335bb9b SHA512 f640e8bf53d4ece7dd1cfc76f316945ad7e7c0bd3fcc06ec97d198e992202f2da439208b556934d897f43f828b67a987c1e38a4249b5f31aed38711a3990da0e +DIST linux-6.18.tar.xz 154309096 BLAKE2B b94b7b9bf18aca0c3e50baf79b009a1448fc6cd9c3ee019f641cc247dcf53a4abef4274ee0608ad8cd4943af69854363a95d26e117ff23620bb07dccb158859f SHA512 88599ffdec96d150c1feb9b261ba93bb0301a9d0e1ad6bef7aeab1f5372cbfc57d8b43c7e902bd8f76921d1dbd8189663c142ea869e51d0e2b483b150ee00fe0 +DIST patch-6.18.45.xz 3184312 BLAKE2B aba9fb2692dffd6815719605d067f67b78fe9d829ad41c7b235c3eef8b8259b0a7f48cf74ba71b7e485cb0fe33efc43dcd6bc5aa2d80f43965cc0319bee47dc6 SHA512 07cb6bc7d2ef0ce5ccfc2c68333d0490a452ba18063473e40ec458066f371e17b871edf937c517f318573bbe3836f0e62f21e3caa481051738a47d9eed858bfb diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.12.111.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.12.111.ebuild deleted file mode 100644 index eb361930dcd..00000000000 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.12.111.ebuild +++ /dev/null @@ -1,51 +0,0 @@ -# Copyright 2014 CoreOS, Inc. -# Distributed under the terms of the GNU General Public License v2 - -EAPI=7 -ETYPE="sources" - -# -rc releases should be versioned L.M_rcN -# Final releases should be versioned L.M.N, even for N == 0 - -# Only needed for RCs -K_BASE_VER="5.15" - -inherit kernel-2 -detect_version - -# Replace the -coreos suffix with -flatcar. Don't simply reset the whole -# variable because it may have additional numbers before the suffix. This -# doesn't affect the sources directory, which is still suffixed with -coreos, -# but it does affect the Makefile that is used in the build. -EXTRAVERSION="${EXTRAVERSION/-coreos/-flatcar}" - -DESCRIPTION="Full sources for the CoreOS Linux kernel" -HOMEPAGE="http://www.kernel.org" -if [[ "${PV%%_rc*}" != "${PV}" ]]; then - SRC_URI="https://git.kernel.org/torvalds/p/v${KV%-coreos}/v${OKV} -> patch-${KV%-coreos}.patch ${KERNEL_BASE_URI}/linux-${OKV}.tar.xz" - PATCH_DIR="${FILESDIR}/${KV_MAJOR}.${KV_PATCH}" -else - SRC_URI="${KERNEL_URI}" - PATCH_DIR="${FILESDIR}/${KV_MAJOR}.${KV_MINOR}" -fi - -# make modules_prepare depends on pahole -RDEPEND="dev-util/pahole" - -KEYWORDS="amd64 arm64" -IUSE="" - -# XXX: Note we must prefix the patch filenames with "z" to ensure they are -# applied _after_ a potential patch-${KV}.patch file, present when building a -# patchlevel revision. We mustn't apply our patches first, it fails when the -# local patches overlap with the upstream patch. -UNIPATCH_LIST=" - ${PATCH_DIR}/z0001-kbuild-derive-relative-path-for-srctree-from-CURDIR.patch - ${PATCH_DIR}/z0002-pahole-support-reproducible-builds.patch - ${PATCH_DIR}/z0003-Revert-x86-boot-Remove-the-bugger-off-message.patch - ${PATCH_DIR}/z0004-efi-add-an-efi_secure_boot-flag-to-indicate-secure-b.patch - ${PATCH_DIR}/z0005-efi-lock-down-the-kernel-if-booted-in-secure-boot-mo.patch - ${PATCH_DIR}/z0006-mtd-disable-slram-and-phram-when-locked-down.patch - ${PATCH_DIR}/z0007-arm64-add-kernel-config-option-to-lock-down-when.patch - ${PATCH_DIR}/z0009-block-add-partition-uuid-into-uevent.patch -" diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.45.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.45.ebuild new file mode 100644 index 00000000000..9ab3150e9a1 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.45.ebuild @@ -0,0 +1,45 @@ +# Copyright 2026 The Flatcar Container Linux Maintainers +# Distributed under the terms of the GNU General Public License v2 + +EAPI=7 +ETYPE="sources" + +# -rc releases should be versioned L.M_rcN +# Final releases should be versioned L.M.N, even for N == 0 + +# Only needed for RCs +K_BASE_VER="5.15" + +inherit kernel-2 +detect_version +EXTRAVERSION="-flatcar" + +DESCRIPTION="Full sources for the CoreOS Linux kernel" +HOMEPAGE="http://www.kernel.org" +if [[ "${PV%%_rc*}" != "${PV}" ]]; then + SRC_URI="https://git.kernel.org/torvalds/p/v${KV%-coreos}/v${OKV} -> patch-${KV%-coreos}.patch ${KERNEL_BASE_URI}/linux-${OKV}.tar.xz" + PATCH_DIR="${FILESDIR}/${KV_MAJOR}.${KV_PATCH}" +else + SRC_URI="${KERNEL_URI}" + PATCH_DIR="${FILESDIR}/${KV_MAJOR}.${KV_MINOR}" +fi + +# make modules_prepare depends on pahole +RDEPEND="dev-util/pahole" + +KEYWORDS="amd64 arm64" +IUSE="" + +# XXX: Note we must prefix the patch filenames with "z" to ensure they are +# applied _after_ a potential patch-${KV}.patch file, present when building a +# patchlevel revision. We mustn't apply our patches first, it fails when the +# local patches overlap with the upstream patch. +UNIPATCH_LIST=" + ${PATCH_DIR}/z0001-pahole-support-reproducible-builds.patch \ + ${PATCH_DIR}/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch \ + ${PATCH_DIR}/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch \ + ${PATCH_DIR}/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch \ + ${PATCH_DIR}/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch \ + ${PATCH_DIR}/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch \ + ${PATCH_DIR}/z0007-tools-hv-fix-cross-compilation.patch \ +" diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0001-kbuild-derive-relative-path-for-srctree-from-CURDIR.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0001-kbuild-derive-relative-path-for-srctree-from-CURDIR.patch deleted file mode 100644 index 8f269fd9de8..00000000000 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0001-kbuild-derive-relative-path-for-srctree-from-CURDIR.patch +++ /dev/null @@ -1,33 +0,0 @@ -From dcf70e8275cf5cc964a0657312af9210996ae2e7 Mon Sep 17 00:00:00 2001 -From: Vito Caputo -Date: Wed, 25 Nov 2015 02:59:45 -0800 -Subject: [PATCH 1/2] kbuild: derive relative path for srctree from CURDIR - -This enables relocating source and build trees to different roots, -provided they stay reachable relative to one another. Useful for -builds done within a sandbox where the eventual root is prefixed -by some undesirable path component. ---- - Makefile | 6 ++++-- - 1 file changed, 4 insertions(+), 2 deletions(-) - -diff --git a/Makefile b/Makefile -index a5cfcd0a85a9..b81055b65169 100644 ---- a/Makefile -+++ b/Makefile -@@ -262,8 +262,10 @@ else - building_out_of_srctree := 1 - endif - --ifneq ($(KBUILD_ABS_SRCTREE),) --srctree := $(abs_srctree) -+ifneq ($(KBUILD_OUTPUT),) -+ srctree := $(shell realpath --relative-to=$(KBUILD_OUTPUT) $(abs_srctree)) -+else -+ srctree := $(abs_srctree) - endif - - objtree := . --- -2.25.1 - diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0009-block-add-partition-uuid-into-uevent.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0009-block-add-partition-uuid-into-uevent.patch deleted file mode 100644 index 754309104eb..00000000000 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0009-block-add-partition-uuid-into-uevent.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 758737d86f8a2d74c0fa9f8b2523fa7fd1e0d0aa Mon Sep 17 00:00:00 2001 -From: Konstantin Khlebnikov -Date: Fri, 4 Oct 2024 17:13:43 -0700 -Subject: [PATCH] block: add partition uuid into uevent as "PARTUUID" - -Both most common formats have uuid in addition to partition name: -GPT: standard uuid xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx -DOS: 4 byte disk signature and 1 byte partition xxxxxxxx-xx - -Tools from util-linux use the same notation for them. - -Signed-off-by: Konstantin Khlebnikov -Reviewed-by: Kyle Fortin -[dianders: rebased to modern kernels] -Signed-off-by: Douglas Anderson -Signed-off-by: Douglas Anderson -Reviewed-by: Christoph Hellwig -Link: https://lore.kernel.org/r/20241004171340.v2.1.I938c91d10e454e841fdf5d64499a8ae8514dc004@changeid -Signed-off-by: Jens Axboe ---- - block/partitions/core.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/block/partitions/core.c b/block/partitions/core.c -index cdad05f9764768..815ed33caa1b86 100644 ---- a/block/partitions/core.c -+++ b/block/partitions/core.c -@@ -256,6 +256,8 @@ static int part_uevent(const struct device *dev, struct kobj_uevent_env *env) - add_uevent_var(env, "PARTN=%u", bdev_partno(part)); - if (part->bd_meta_info && part->bd_meta_info->volname[0]) - add_uevent_var(env, "PARTNAME=%s", part->bd_meta_info->volname); -+ if (part->bd_meta_info && part->bd_meta_info->uuid[0]) -+ add_uevent_var(env, "PARTUUID=%s", part->bd_meta_info->uuid); - return 0; - } - diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0002-pahole-support-reproducible-builds.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0001-pahole-support-reproducible-builds.patch similarity index 54% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0002-pahole-support-reproducible-builds.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0001-pahole-support-reproducible-builds.patch index dbce2286a3d..dd815a84f3e 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0002-pahole-support-reproducible-builds.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0001-pahole-support-reproducible-builds.patch @@ -1,26 +1,26 @@ -From 9faff3734e6456e7927c0914829a4764ec9f1b44 Mon Sep 17 00:00:00 2001 +From b8dc4700a839ff99d33b61321281368699fc6339 Mon Sep 17 00:00:00 2001 From: Adrian Vladu Date: Tue, 17 Sep 2024 13:44:14 +0000 -Subject: [PATCH] pahole: support reproducible builds +Subject: [PATCH 1/8] pahole: support reproducible builds --- scripts/Makefile.btf | 3 +++ 1 file changed, 3 insertions(+) diff --git a/scripts/Makefile.btf b/scripts/Makefile.btf -index 2d6e5ed9081e..b2f88b0fcf37 100644 +index db76335dd917..bba03bdbbdc6 100644 --- a/scripts/Makefile.btf +++ b/scripts/Makefile.btf -@@ -23,6 +23,9 @@ else - # Switch to using --btf_features for v1.26 and later. - pahole-flags-$(call test-ge, $(pahole-ver), 126) = -j --btf_features=encode_force,var,float,enum64,decl_tag,type_tag,optimized_func,consistent_func +@@ -29,6 +29,9 @@ ifneq ($(KBUILD_EXTMOD),) + module-pahole-flags-$(call test-ge, $(pahole-ver), 128) += --btf_features=distilled_base + endif +# Support reproducible builds. -+pahole-flags-$(call test-ge, $(pahole-ver), 127) = -j --btf_features=encode_force,var,float,enum64,decl_tag,type_tag,optimized_func,consistent_func,reproducible_build ++pahole-flags-$(call test-ge, $(pahole-ver), 127) = -j --btf_features=encode_force,var,float,enum64,decl_tag,type_tag,optimized_func,consistent_func,decl_tag_kfuncs,reproducible_build + endif pahole-flags-$(CONFIG_PAHOLE_HAS_LANG_EXCLUDE) += --lang_exclude=rust -- -2.34.1 +2.51.0 diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0003-Revert-x86-boot-Remove-the-bugger-off-message.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch similarity index 87% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0003-Revert-x86-boot-Remove-the-bugger-off-message.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch index 6f3a7370f8d..0ce03062c03 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0003-Revert-x86-boot-Remove-the-bugger-off-message.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch @@ -1,7 +1,7 @@ -From 9f34a9ffe5b94aee93baa5762719546e0bebc28d Mon Sep 17 00:00:00 2001 +From 01bcd1ecda9a9a50a97e20c7987a90cda4a0998f Mon Sep 17 00:00:00 2001 From: Kai Lueke Date: Fri, 15 Mar 2024 11:49:50 +0100 -Subject: [PATCH] Revert "x86/boot: Remove the 'bugger off' message" +Subject: [PATCH 2/8] Revert "x86/boot: Remove the 'bugger off' message" This reverts commit 768171d7ebbce005210e1cf8456f043304805c15 because for now this is still needed to store the dm-verity hash. @@ -11,7 +11,7 @@ now this is still needed to store the dm-verity hash. 2 files changed, 52 insertions(+), 4 deletions(-) diff --git a/arch/x86/boot/header.S b/arch/x86/boot/header.S -index a1bbedd989e4..c7624caf6840 100644 +index 9bea5a1e2c52..e929789e2cf4 100644 --- a/arch/x86/boot/header.S +++ b/arch/x86/boot/header.S @@ -41,15 +41,64 @@ SYSSEG = 0x1000 /* historical load address >> 4 */ @@ -23,7 +23,7 @@ index a1bbedd989e4..c7624caf6840 100644 +bootsect_start: #ifdef CONFIG_EFI_STUB # "MZ", MS-DOS header - .word MZ_MAGIC + .word IMAGE_DOS_SIGNATURE +#endif + + # Normalize the start address @@ -77,10 +77,10 @@ index a1bbedd989e4..c7624caf6840 100644 + +#ifdef CONFIG_EFI_STUB pe_header: - .long PE_MAGIC + .long IMAGE_NT_SIGNATURE diff --git a/arch/x86/boot/setup.ld b/arch/x86/boot/setup.ld -index 3a2d1360abb0..c3e354d312d0 100644 +index e1d594a60204..f2dc13420a93 100644 --- a/arch/x86/boot/setup.ld +++ b/arch/x86/boot/setup.ld @@ -10,11 +10,10 @@ ENTRY(_start) @@ -99,5 +99,5 @@ index 3a2d1360abb0..c3e354d312d0 100644 .entrytext : { *(.entrytext) } .inittext : { *(.inittext) } -- -2.44.0 +2.51.0 diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0004-efi-add-an-efi_secure_boot-flag-to-indicate-secure-b.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch similarity index 73% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0004-efi-add-an-efi_secure_boot-flag-to-indicate-secure-b.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch index 822beab21c1..12978a8dc0f 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0004-efi-add-an-efi_secure_boot-flag-to-indicate-secure-b.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch @@ -1,7 +1,8 @@ +From b8c17d573de9d6c4ae2da1ef51a255a128090a8c Mon Sep 17 00:00:00 2001 From: David Howells Date: Mon, 18 Feb 2019 12:45:03 +0000 -Subject: [28/30] efi: Add an EFI_SECURE_BOOT flag to indicate secure boot mode -Origin: https://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs.git/commit?id=a5d70c55c603233c192b375f72116a395909da28 +Subject: [PATCH 3/8] efi: Add an EFI_SECURE_BOOT flag to indicate secure boot + mode UEFI machines can be booted in Secure Boot mode. Add an EFI_SECURE_BOOT flag that can be passed to efi_enabled() to find out whether secure boot is @@ -25,13 +26,15 @@ cc: linux-efi@vger.kernel.org arch/x86/kernel/setup.c | 14 +---------- drivers/firmware/efi/Makefile | 1 + drivers/firmware/efi/secureboot.c | 39 +++++++++++++++++++++++++++++++ - include/linux/efi.h | 16 ++++++++----- - 4 files changed, 51 insertions(+), 19 deletions(-) + include/linux/efi.h | 17 ++++++++------ + 4 files changed, 51 insertions(+), 20 deletions(-) create mode 100644 drivers/firmware/efi/secureboot.c +diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c +index 1b2edd07a3e1..41b41f677b1e 100644 --- a/arch/x86/kernel/setup.c +++ b/arch/x86/kernel/setup.c -@@ -1193,19 +1193,7 @@ void __init setup_arch(char **cmdline_p) +@@ -1154,19 +1154,7 @@ void __init setup_arch(char **cmdline_p) /* Allocate bigger log buffer */ setup_log_buf(1); @@ -52,9 +55,11 @@ cc: linux-efi@vger.kernel.org reserve_initrd(); +diff --git a/drivers/firmware/efi/Makefile b/drivers/firmware/efi/Makefile +index 8efbcf699e4f..96d5a1ca981d 100644 --- a/drivers/firmware/efi/Makefile +++ b/drivers/firmware/efi/Makefile -@@ -25,6 +25,7 @@ obj-$(CONFIG_EFI_FAKE_MEMMAP) += fake_m +@@ -25,6 +25,7 @@ subdir-$(CONFIG_EFI_STUB) += libstub obj-$(CONFIG_EFI_BOOTLOADER_CONTROL) += efibc.o obj-$(CONFIG_EFI_TEST) += test/ obj-$(CONFIG_EFI_DEV_PATH_PARSER) += dev-path-parser.o @@ -62,6 +67,9 @@ cc: linux-efi@vger.kernel.org obj-$(CONFIG_APPLE_PROPERTIES) += apple-properties.o obj-$(CONFIG_EFI_RCI2_TABLE) += rci2-table.o obj-$(CONFIG_EFI_EMBEDDED_FIRMWARE) += embedded-firmware.o +diff --git a/drivers/firmware/efi/secureboot.c b/drivers/firmware/efi/secureboot.c +new file mode 100644 +index 000000000000..b6620669e32b --- /dev/null +++ b/drivers/firmware/efi/secureboot.c @@ -0,0 +1,39 @@ @@ -104,13 +112,15 @@ cc: linux-efi@vger.kernel.org + } + } +} +diff --git a/include/linux/efi.h b/include/linux/efi.h +index a98cc39e7aaa..1d5f8fa07b4d 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h -@@ -871,6 +871,14 @@ extern int __init efi_setup_pcdp_console - #define EFI_MEM_ATTR 10 /* Did firmware publish an EFI_MEMORY_ATTRIBUTES table? */ - #define EFI_MEM_NO_SOFT_RESERVE 11 /* Is the kernel configured to ignore soft reservations? */ - #define EFI_PRESERVE_BS_REGIONS 12 /* Are EFI boot-services memory segments available? */ -+#define EFI_SECURE_BOOT 13 /* Are we in Secure Boot mode? */ +@@ -865,6 +865,14 @@ static inline int efi_range_is_wc(unsigned long start, unsigned long len) + #define EFI_MEM_ATTR 9 /* Did firmware publish an EFI_MEMORY_ATTRIBUTES table? */ + #define EFI_MEM_NO_SOFT_RESERVE 10 /* Is the kernel configured to ignore soft reservations? */ + #define EFI_PRESERVE_BS_REGIONS 11 /* Are EFI boot-services memory segments available? */ ++#define EFI_SECURE_BOOT 12 /* Are we in Secure Boot mode? */ + +enum efi_secureboot_mode { + efi_secureboot_mode_unset, @@ -121,7 +131,7 @@ cc: linux-efi@vger.kernel.org #ifdef CONFIG_EFI /* -@@ -895,6 +903,7 @@ static inline bool efi_rt_services_suppo +@@ -889,6 +897,7 @@ static inline bool efi_rt_services_supported(unsigned int mask) return (efi.runtime_supported_mask & mask) == mask; } extern void efi_find_mirror(void); @@ -129,7 +139,7 @@ cc: linux-efi@vger.kernel.org #else static inline bool efi_enabled(int feature) { -@@ -914,6 +923,7 @@ static inline bool efi_rt_services_suppo +@@ -908,6 +917,7 @@ static inline bool efi_rt_services_supported(unsigned int mask) } static inline void efi_find_mirror(void) {} @@ -137,7 +147,7 @@ cc: linux-efi@vger.kernel.org #endif extern int efi_status_to_err(efi_status_t status); -@@ -1133,13 +1143,6 @@ static inline bool efi_runtime_disabled( +@@ -1126,13 +1136,6 @@ static inline bool efi_runtime_disabled(void) { return true; } extern void efi_call_virt_check_flags(unsigned long flags, const void *caller); extern unsigned long efi_call_virt_save_flags(void); @@ -151,3 +161,6 @@ cc: linux-efi@vger.kernel.org static inline enum efi_secureboot_mode efi_get_secureboot_mode(efi_get_variable_t *get_var) { +-- +2.51.0 + diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0005-efi-lock-down-the-kernel-if-booted-in-secure-boot-mo.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch similarity index 68% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0005-efi-lock-down-the-kernel-if-booted-in-secure-boot-mo.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch index 6fff3f89675..6c4e43b4ba0 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0005-efi-lock-down-the-kernel-if-booted-in-secure-boot-mo.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch @@ -1,6 +1,7 @@ +From 994c5501984e4e6ef2577ba148e9aa4a023570d8 Mon Sep 17 00:00:00 2001 From: Ben Hutchings Date: Tue, 10 Sep 2019 11:54:28 +0100 -Subject: efi: Lock down the kernel if booted in secure boot mode +Subject: [PATCH 4/8] efi: Lock down the kernel if booted in secure boot mode Based on an earlier patch by David Howells, who wrote the following description: @@ -17,16 +18,18 @@ help text for LOCK_DOWN_IN_EFI_SECURE_BOOT was adjusted to mention that lockdown is triggered in integrity mode (https://bugs.debian.org/1025417)] Signed-off-by: Salvatore Bonaccorso --- - arch/x86/kernel/setup.c | 4 ++-- - drivers/firmware/efi/secureboot.c | 3 +++ - include/linux/security.h | 6 ++++++ - security/lockdown/Kconfig | 15 +++++++++++++++ - security/lockdown/lockdown.c | 2 +- - 5 files changed, 27 insertions(+), 3 deletions(-) + arch/x86/kernel/setup.c | 4 ++-- + drivers/firmware/efi/secureboot.c | 5 +++++ + include/linux/security.h | 6 ++++++ + security/lockdown/Kconfig | 15 +++++++++++++++ + security/lockdown/lockdown.c | 2 +- + 5 files changed, 29 insertions(+), 3 deletions(-) +diff --git a/arch/x86/kernel/setup.c b/arch/x86/kernel/setup.c +index 41b41f677b1e..db2b2c2765b7 100644 --- a/arch/x86/kernel/setup.c +++ b/arch/x86/kernel/setup.c -@@ -904,6 +904,8 @@ void __init setup_arch(char **cmdline_p) +@@ -991,6 +991,8 @@ void __init setup_arch(char **cmdline_p) if (efi_enabled(EFI_BOOT)) efi_init(); @@ -35,7 +38,7 @@ Signed-off-by: Salvatore Bonaccorso reserve_ibft_region(); x86_init.resources.dmi_setup(); -@@ -1070,8 +1072,6 @@ void __init setup_arch(char **cmdline_p) +@@ -1154,8 +1156,6 @@ void __init setup_arch(char **cmdline_p) /* Allocate bigger log buffer */ setup_log_buf(1); @@ -44,6 +47,8 @@ Signed-off-by: Salvatore Bonaccorso reserve_initrd(); acpi_table_upgrade(); +diff --git a/drivers/firmware/efi/secureboot.c b/drivers/firmware/efi/secureboot.c +index b6620669e32b..8f2554291fb1 100644 --- a/drivers/firmware/efi/secureboot.c +++ b/drivers/firmware/efi/secureboot.c @@ -15,6 +15,7 @@ @@ -54,7 +59,7 @@ Signed-off-by: Salvatore Bonaccorso /* * Decide what to do when UEFI secure boot mode is enabled. -@@ -28,6 +29,10 @@ void __init efi_set_secure_boot(enum efi +@@ -28,6 +29,10 @@ void __init efi_set_secure_boot(enum efi_secureboot_mode mode) break; case efi_secureboot_mode_enabled: set_bit(EFI_SECURE_BOOT, &efi.flags); @@ -65,17 +70,19 @@ Signed-off-by: Salvatore Bonaccorso pr_info("Secure boot enabled\n"); break; default: +diff --git a/include/linux/security.h b/include/linux/security.h +index 521bcb5b9717..d139d8ce8849 100644 --- a/include/linux/security.h +++ b/include/linux/security.h -@@ -522,6 +522,7 @@ int security_inode_notifysecctx(struct i +@@ -575,6 +575,7 @@ int security_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen); int security_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen); - int security_inode_getsecctx(struct inode *inode, void **ctx, u32 *ctxlen); + int security_inode_getsecctx(struct inode *inode, struct lsm_context *cp); int security_locked_down(enum lockdown_reason what); +int lock_kernel_down(const char *where, enum lockdown_reason level); int lsm_fill_user_ctx(struct lsm_ctx __user *uctx, u32 *uctx_len, void *val, size_t val_len, u64 id, u64 flags); int security_bdev_alloc(struct block_device *bdev); -@@ -1504,6 +1505,11 @@ static inline int security_locked_down(e +@@ -1588,6 +1589,11 @@ static inline int security_locked_down(enum lockdown_reason what) { return 0; } @@ -87,9 +94,11 @@ Signed-off-by: Salvatore Bonaccorso static inline int lsm_fill_user_ctx(struct lsm_ctx __user *uctx, u32 *uctx_len, void *val, size_t val_len, u64 id, u64 flags) +diff --git a/security/lockdown/Kconfig b/security/lockdown/Kconfig +index e84ddf484010..4175b50b1e6e 100644 --- a/security/lockdown/Kconfig +++ b/security/lockdown/Kconfig -@@ -45,3 +45,18 @@ config LOCK_DOWN_KERNEL_FORCE_CONFIDENTI +@@ -45,3 +45,18 @@ config LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY disabled. endchoice @@ -108,9 +117,11 @@ Signed-off-by: Salvatore Bonaccorso + + Enabling this option results in kernel lockdown being + triggered in integrity mode if EFI Secure Boot is set. +diff --git a/security/lockdown/lockdown.c b/security/lockdown/lockdown.c +index cf83afa1d879..5ff10bd656d2 100644 --- a/security/lockdown/lockdown.c +++ b/security/lockdown/lockdown.c -@@ -24,7 +24,7 @@ static const enum lockdown_reason lockdo +@@ -24,7 +24,7 @@ static const enum lockdown_reason lockdown_levels[] = {LOCKDOWN_NONE, /* * Put the kernel into lock-down mode. */ @@ -119,3 +130,6 @@ Signed-off-by: Salvatore Bonaccorso { if (kernel_locked_down >= level) return -EPERM; +-- +2.51.0 + diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0006-mtd-disable-slram-and-phram-when-locked-down.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch similarity index 81% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0006-mtd-disable-slram-and-phram-when-locked-down.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch index c718e7e2f02..6b62bcb57d8 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0006-mtd-disable-slram-and-phram-when-locked-down.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch @@ -1,7 +1,7 @@ +From 06ae62500c1e2bb641b8f16eb9313a41c4061ab9 Mon Sep 17 00:00:00 2001 From: Ben Hutchings Date: Fri, 30 Aug 2019 15:54:24 +0100 -Subject: mtd: phram,slram: Disable when the kernel is locked down -Forwarded: https://lore.kernel.org/linux-security-module/20190830154720.eekfjt6c4jzvlbfz@decadent.org.uk/ +Subject: [PATCH 5/8] mtd: phram,slram: Disable when the kernel is locked down These drivers allow mapping arbitrary memory ranges as MTD devices. This should be disabled to preserve the kernel's integrity when it is @@ -21,9 +21,11 @@ Cc: linux-mtd@lists.infradead.org drivers/mtd/devices/slram.c | 9 ++++++++- 2 files changed, 13 insertions(+), 2 deletions(-) +diff --git a/drivers/mtd/devices/phram.c b/drivers/mtd/devices/phram.c +index fd9ec165e61a..8652139ecbe9 100644 --- a/drivers/mtd/devices/phram.c +++ b/drivers/mtd/devices/phram.c -@@ -364,7 +364,11 @@ static int phram_param_call(const char * +@@ -365,7 +365,11 @@ static int phram_param_call(const char *val, const struct kernel_param *kp) #endif } @@ -36,6 +38,8 @@ Cc: linux-mtd@lists.infradead.org MODULE_PARM_DESC(phram, "Memory region to map. \"phram=,,[,]\""); #ifdef CONFIG_OF +diff --git a/drivers/mtd/devices/slram.c b/drivers/mtd/devices/slram.c +index 8297b366a066..9f762d988c0b 100644 --- a/drivers/mtd/devices/slram.c +++ b/drivers/mtd/devices/slram.c @@ -43,6 +43,7 @@ @@ -73,3 +77,6 @@ Cc: linux-mtd@lists.infradead.org while (map) { devname = devstart = devlength = NULL; +-- +2.51.0 + diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0007-arm64-add-kernel-config-option-to-lock-down-when.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch similarity index 76% rename from sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0007-arm64-add-kernel-config-option-to-lock-down-when.patch rename to sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch index 61b7040971f..62be9cbd0d5 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.12/z0007-arm64-add-kernel-config-option-to-lock-down-when.patch +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch @@ -1,8 +1,8 @@ +From ddb2f010a8a881d181bce3b8961ad92117f4e8bb Mon Sep 17 00:00:00 2001 From: Linn Crosetto Date: Tue, 30 Aug 2016 11:54:38 -0600 -Subject: arm64: add kernel config option to lock down when in Secure Boot mode -Bug-Debian: https://bugs.debian.org/831827 -Forwarded: no +Subject: [PATCH 6/8] arm64: add kernel config option to lock down when in + Secure Boot mode Add a kernel configuration option to lock down the kernel, to restrict userspace's ability to modify the running kernel when UEFI Secure Boot is @@ -32,12 +32,14 @@ Signed-off-by: Linn Crosetto [Salvatore Bonaccorso: Forward-ported to 5.10: f30f242fb131 ("efi: Rename arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] --- - drivers/firmware/efi/efi-init.c | 5 ++++- - drivers/firmware/efi/fdtparams.c | 12 +++++++++++- - drivers/firmware/efi/libstub/fdt.c | 6 ++++++ - include/linux/efi.h | 3 ++- + drivers/firmware/efi/efi-init.c | 5 ++++- + drivers/firmware/efi/fdtparams.c | 12 +++++++++++- + drivers/firmware/efi/libstub/fdt.c | 6 ++++++ + include/linux/efi.h | 3 ++- 4 files changed, 23 insertions(+), 3 deletions(-) +diff --git a/drivers/firmware/efi/efi-init.c b/drivers/firmware/efi/efi-init.c +index a00e07b853f2..8a0390d8da98 100644 --- a/drivers/firmware/efi/efi-init.c +++ b/drivers/firmware/efi/efi-init.c @@ -213,9 +213,10 @@ void __init efi_init(void) @@ -61,6 +63,8 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] reserve_regions(); /* * For memblock manipulation, the cap should come after the memblock_add(). +diff --git a/drivers/firmware/efi/fdtparams.c b/drivers/firmware/efi/fdtparams.c +index b815d2a754ee..69a2eb539d38 100644 --- a/drivers/firmware/efi/fdtparams.c +++ b/drivers/firmware/efi/fdtparams.c @@ -16,6 +16,7 @@ enum { @@ -71,7 +75,7 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] PARAMCOUNT }; -@@ -26,6 +27,7 @@ static __initconst const char name[][22] +@@ -26,6 +27,7 @@ static __initconst const char name[][22] = { [MMSIZE] = "MemMap Size ", [DCSIZE] = "MemMap Desc. Size ", [DCVERS] = "MemMap Desc. Version ", @@ -95,7 +99,7 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] } } }; -@@ -64,6 +68,11 @@ static int __init efi_get_fdt_prop(const +@@ -64,6 +68,11 @@ static int __init efi_get_fdt_prop(const void *fdt, int node, const char *pname, int len; u64 val; @@ -107,7 +111,7 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] prop = fdt_getprop(fdt, node, pname, &len); if (!prop) return 1; -@@ -81,7 +90,7 @@ static int __init efi_get_fdt_prop(const +@@ -81,7 +90,7 @@ static int __init efi_get_fdt_prop(const void *fdt, int node, const char *pname, return 0; } @@ -116,7 +120,7 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] { const void *fdt = initial_boot_params; unsigned long systab; -@@ -95,6 +104,7 @@ u64 __init efi_get_fdt_params(struct efi +@@ -95,6 +104,7 @@ u64 __init efi_get_fdt_params(struct efi_memory_map_data *mm) [MMSIZE] = { &mm->size, sizeof(mm->size) }, [DCSIZE] = { &mm->desc_size, sizeof(mm->desc_size) }, [DCVERS] = { &mm->desc_version, sizeof(mm->desc_version) }, @@ -124,9 +128,11 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] }; BUILD_BUG_ON(ARRAY_SIZE(target) != ARRAY_SIZE(name)); +diff --git a/drivers/firmware/efi/libstub/fdt.c b/drivers/firmware/efi/libstub/fdt.c +index 6a337f1f8787..6c679da644dd 100644 --- a/drivers/firmware/efi/libstub/fdt.c +++ b/drivers/firmware/efi/libstub/fdt.c -@@ -132,6 +132,12 @@ static efi_status_t update_fdt(void *ori +@@ -132,6 +132,12 @@ static efi_status_t update_fdt(void *orig_fdt, unsigned long orig_fdt_size, } } @@ -139,9 +145,11 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] /* Shrink the FDT back to its minimum size: */ fdt_pack(fdt); +diff --git a/include/linux/efi.h b/include/linux/efi.h +index 1d5f8fa07b4d..6e826b53a0ce 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h -@@ -764,7 +764,8 @@ extern int efi_mem_desc_lookup(u64 phys_ +@@ -755,7 +755,8 @@ extern int efi_mem_desc_lookup(u64 phys_addr, efi_memory_desc_t *out_md); extern int __efi_mem_desc_lookup(u64 phys_addr, efi_memory_desc_t *out_md); extern void efi_mem_reserve(phys_addr_t addr, u64 size); extern int efi_mem_reserve_persistent(phys_addr_t addr, u64 size); @@ -151,3 +159,6 @@ arm-init to efi-init common for all arch") renamed arm-init.c to efi-init.c] extern struct kobject *efi_kobj; extern int efi_reboot_quirk_mode; +-- +2.51.0 + diff --git a/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0007-tools-hv-fix-cross-compilation.patch b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0007-tools-hv-fix-cross-compilation.patch new file mode 100644 index 00000000000..3fb2dd48f09 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0007-tools-hv-fix-cross-compilation.patch @@ -0,0 +1,45 @@ +From ca5ee0e918115fb5cf626d75461d9fca06e06caf Mon Sep 17 00:00:00 2001 +From: Aditya Garg +Date: Thu, 9 Apr 2026 03:32:18 -0700 +Subject: [PATCH] tools: hv: Fix cross-compilation + +Use the native ARCH only in case it is not set, this will allow the +cross-compilation where ARCH is explicitly set. + +Additionally, simplify the ARCH check to build the fcopy daemon only +for x86 and x86_64. + +Fixes: 82b0945ce2c2 ("tools: hv: Add new fcopy application based on uio driver") +Reported-by: Adrian Vladu +Closes: https://lore.kernel.org/linux-hyperv/PR3PR09MB54119DB2FD76977C62D8DD6AB04D2@PR3PR09MB5411.eurprd09.prod.outlook.com/ +Co-developed-by: Saurabh Sengar +Signed-off-by: Saurabh Sengar +Signed-off-by: Aditya Garg +Reviewed-by: Roman Kisel +Signed-off-by: Wei Liu +--- + tools/hv/Makefile | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/tools/hv/Makefile b/tools/hv/Makefile +index 34ffcec264ab0f..016753f3dd7f61 100644 +--- a/tools/hv/Makefile ++++ b/tools/hv/Makefile +@@ -2,7 +2,7 @@ + # Makefile for Hyper-V tools + include ../scripts/Makefile.include + +-ARCH := $(shell uname -m 2>/dev/null) ++ARCH ?= $(shell uname -m 2>/dev/null) + sbindir ?= /usr/sbin + libexecdir ?= /usr/libexec + sharedstatedir ?= /var/lib +@@ -20,7 +20,7 @@ override CFLAGS += -O2 -Wall -g -D_GNU_SOURCE -I$(OUTPUT)include + override CFLAGS += -Wno-address-of-packed-member + + ALL_TARGETS := hv_kvp_daemon hv_vss_daemon +-ifneq ($(ARCH), aarch64) ++ifneq ($(filter x86_64 x86,$(ARCH)),) + ALL_TARGETS += hv_fcopy_uio_daemon + endif + ALL_PROGRAMS := $(patsubst %,$(OUTPUT)%,$(ALL_TARGETS)) diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0001-mm-use-vm_flags_reset-to-avoid-GPL-only-vma_start_wr.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0001-mm-use-vm_flags_reset-to-avoid-GPL-only-vma_start_wr.patch new file mode 100644 index 00000000000..32c494fc3e3 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0001-mm-use-vm_flags_reset-to-avoid-GPL-only-vma_start_wr.patch @@ -0,0 +1,155 @@ +From d1154945f8b2d22392d30a5e522612dfbcf17cff Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Wed, 17 Jun 2026 15:48:55 +0530 +Subject: [PATCH 1/2] mm: use vm_flags_reset to avoid GPL-only + vma_start_write() + +Linux 6.15 made vma_start_write() GPL-only, which nv_vm_flags_set/clear +depend on via vm_flags_set/vm_flags_clear. Redefine them using +vm_flags_reset which carries no such restriction. + +Applied to both the proprietary kernel/ and open-source kernel-open/ trees. + +Signed-off-by: Sayan Chowdhury +--- + kernel-open/nvidia-drm/nvidia-drm-gem-user-memory.c | 7 +++++++ + kernel-open/nvidia-drm/nvidia-drm-gem.c | 7 +++++++ + kernel-open/nvidia/nv-mmap.c | 7 +++++++ + kernel/nvidia-drm/nvidia-drm-gem-user-memory.c | 7 +++++++ + kernel/nvidia-drm/nvidia-drm-gem.c | 7 +++++++ + kernel/nvidia/nv-mmap.c | 7 +++++++ + 6 files changed, 42 insertions(+) + +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem-user-memory.c b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem-user-memory.c +index 9d2a0512..e473b66f 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem-user-memory.c ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem-user-memory.c +@@ -40,6 +40,13 @@ + #include + #endif + ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif ++ + static inline + void __nv_drm_gem_user_memory_free(struct nv_drm_gem_object *nv_gem) + { +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem.c b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem.c +index ef0e0f83..c8489a72 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem.c ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-gem.c +@@ -51,6 +51,13 @@ + + #include "nv-mm.h" + ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif ++ + void nv_drm_gem_free(struct drm_gem_object *gem) + { + struct nv_drm_gem_object *nv_gem = to_nv_gem_object(gem); +diff --git a/kernel-module-source/kernel-open/nvidia/nv-mmap.c b/kernel-module-source/kernel-open/nvidia/nv-mmap.c +index 8e98c817..f72731c0 100644 +--- a/kernel-module-source/kernel-open/nvidia/nv-mmap.c ++++ b/kernel-module-source/kernel-open/nvidia/nv-mmap.c +@@ -25,6 +25,13 @@ + + #include "os-interface.h" + #include "nv-linux.h" ++ ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif + #include "nv_speculation_barrier.h" + + /* +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/uvm.c b/kernel-module-source/kernel-open/nvidia-uvm/uvm.c +index 1a2b3c4d..5e6f7a8b 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/uvm.c ++++ b/kernel-module-source/kernel-open/nvidia-uvm/uvm.c +@@ -21,6 +21,8 @@ + + *******************************************************************************/ + ++#include ++ + #include "uvm_api.h" + #include "uvm_global.h" + #include "uvm_gpu_replayable_faults.h" +@@ -40,4 +42,9 @@ + + #define NVIDIA_UVM_DEVICE_NAME "nvidia-uvm" + ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(v, f) vm_flags_reset((v), (v)->vm_flags | (f)) ++#define nv_vm_flags_clear(v, f) vm_flags_reset((v), (v)->vm_flags & ~(f)) ++#endif ++ + static dev_t g_uvm_base_dev; +diff --git a/kernel/nvidia-drm/nvidia-drm-gem-user-memory.c b/kernel/nvidia-drm/nvidia-drm-gem-user-memory.c +index 9d2a0512..e473b66f 100644 +--- a/kernel/nvidia-drm/nvidia-drm-gem-user-memory.c ++++ b/kernel/nvidia-drm/nvidia-drm-gem-user-memory.c +@@ -40,6 +40,13 @@ + #include + #endif + ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif ++ + static inline + void __nv_drm_gem_user_memory_free(struct nv_drm_gem_object *nv_gem) + { +diff --git a/kernel/nvidia-drm/nvidia-drm-gem.c b/kernel/nvidia-drm/nvidia-drm-gem.c +index ef0e0f83..c8489a72 100644 +--- a/kernel/nvidia-drm/nvidia-drm-gem.c ++++ b/kernel/nvidia-drm/nvidia-drm-gem.c +@@ -51,6 +51,13 @@ + + #include "nv-mm.h" + ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif ++ + void nv_drm_gem_free(struct drm_gem_object *gem) + { + struct nv_drm_gem_object *nv_gem = to_nv_gem_object(gem); +diff --git a/kernel/nvidia/nv-mmap.c b/kernel/nvidia/nv-mmap.c +index 8e98c817..f72731c0 100644 +--- a/kernel/nvidia/nv-mmap.c ++++ b/kernel/nvidia/nv-mmap.c +@@ -25,6 +25,13 @@ + + #include "os-interface.h" + #include "nv-linux.h" ++ ++#include ++ ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 15, 0) ++#define nv_vm_flags_set(vma, f) vm_flags_reset((vma), (vma)->vm_flags | (f)) ++#define nv_vm_flags_clear(vma, f) vm_flags_reset((vma), (vma)->vm_flags & ~(f)) ++#endif + #include "nv_speculation_barrier.h" + + /* +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch new file mode 100644 index 00000000000..5cd878e7cb5 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch @@ -0,0 +1,268 @@ +From 828e2d5aa8808f34030a726fb5f1038ea474add7 Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Wed, 17 Jun 2026 16:45:03 +0530 +Subject: [PATCH 2/2] nvidia-drm 550.163.01: pass drm_format_info to + nv_drm_framebuffer_create for Linux 6.17+ + +Linux kernel commit 81112eaac559 ("drm: Pass the format info to +.fb_create()") changed drm_mode_config_funcs.fb_create to take a 4th +argument: const struct drm_format_info *info + +This landed in v6.17-rc1; we hit it while updating our build target +to Linux 6.18, which carries the same API forward. + +Simultaneously, drm_helper_mode_fill_fb_struct() gained the same +parameter between the framebuffer and the mode_cmd arguments (4 args +total with dev). + +Use a conftest probe (NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) rather than +a hardcoded LINUX_VERSION_CODE check, since this detects the feature +directly against the actual kernel headers and remains correct for +backports or non-standard kernel versioning. This matches NVIDIA's +own upstream fix for the same commit, shipped in the 570.190 driver +release. nvidia-drm-fb.h now uses the same conftest guard as the +other three touched files instead of a LINUX_VERSION_CODE check, to +avoid a declaration/definition mismatch on backported kernels. + +Applied to both the proprietary kernel/ and open-source kernel-open/ trees. + +Signed-off-by: Sayan Chowdhury +--- + kernel-open/conftest.sh | 19 +++++++++++++++++++ + kernel-open/nvidia-drm/nvidia-drm-drv.c | 6 ++++++ + kernel-open/nvidia-drm/nvidia-drm-fb.c | 7 +++++++ + kernel-open/nvidia-drm/nvidia-drm-fb.h | 4 ++++ + kernel-open/nvidia-drm/nvidia-drm-sources.mk | 1 + + kernel/conftest.sh | 19 +++++++++++++++++++ + kernel/nvidia-drm/nvidia-drm-drv.c | 6 ++++++ + kernel/nvidia-drm/nvidia-drm-fb.c | 7 +++++++ + kernel/nvidia-drm/nvidia-drm-fb.h | 4 ++++ + kernel/nvidia-drm/nvidia-drm-sources.mk | 1 + + 10 files changed, 74 insertions(+) + +diff --git a/kernel-module-source/kernel-open/conftest.sh b/kernel-module-source/kernel-open/conftest.sh +index 889cf654..30506f8f 100755 +--- a/kernel-module-source/kernel-open/conftest.sh ++++ b/kernel-module-source/kernel-open/conftest.sh +@@ -4511,6 +4511,25 @@ compile_test() { + compile_check_conftest "$CODE" "NV_DRM_ROTATION_AVAILABLE" "" "functions" + ;; + ++ drm_fb_create_takes_format_info) ++ # ++ # Determine if a `struct drm_format_info *` is passed into ++ # the .fb_create callback (4-arg form). Added by commit ++ # 81112eaac559 ("drm: Pass the format info to .fb_create") ++ # in linux-next (2025-07-16). ++ # ++ CODE=" ++ #include ++ #include ++ ++ static const struct drm_mode_config_funcs funcs; ++ void conftest_drm_fb_create_takes_format_info(void) { ++ funcs.fb_create(NULL, NULL, NULL, NULL); ++ }" ++ ++ compile_check_conftest "$CODE" "NV_DRM_FB_CREATE_TAKES_FORMAT_INFO" "" "types" ++ ;; ++ + drm_driver_prime_flag_present) + # + # Determine whether driver feature flag DRIVER_PRIME is present. +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-drv.c b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-drv.c +index da2b7010..12fe50ef 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-drv.c ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-drv.c +@@ -186,6 +186,9 @@ static void nv_drm_output_poll_changed(struct drm_device *dev) + static struct drm_framebuffer *nv_drm_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + #if defined(NV_DRM_HELPER_MODE_FILL_FB_STRUCT_HAS_CONST_MODE_CMD_ARG) + const struct drm_mode_fb_cmd2 *cmd + #else +@@ -201,6 +204,9 @@ static struct drm_framebuffer *nv_drm_framebuffer_create( + fb = nv_drm_internal_framebuffer_create( + dev, + file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ info, ++#endif + &local_cmd); + + #if !defined(NV_DRM_HELPER_MODE_FILL_FB_STRUCT_HAS_CONST_MODE_CMD_ARG) +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.c b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.c +index 1c842015..973c2c64 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.c ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.c +@@ -33,6 +33,7 @@ + #include "nvidia-drm-format.h" + + #include ++#include + + static void __nv_drm_framebuffer_free(struct nv_drm_framebuffer *nv_fb) + { +@@ -206,6 +207,9 @@ fail: + struct drm_framebuffer *nv_drm_internal_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + struct drm_mode_fb_cmd2 *cmd) + { + struct nv_drm_device *nv_dev = to_nv_device(dev); +@@ -259,6 +263,9 @@ struct drm_framebuffer *nv_drm_internal_framebuffer_create( + dev, + #endif + &nv_fb->base, ++ #if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ info, ++ #endif + cmd); + + /* +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.h b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.h +index cf477cc7..5a1a34af 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.h ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-fb.h +@@ -59,6 +59,9 @@ static inline struct nv_drm_framebuffer *to_nv_framebuffer( + struct drm_framebuffer *nv_drm_internal_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + struct drm_mode_fb_cmd2 *cmd); + + #endif /* NV_DRM_ATOMIC_MODESET_AVAILABLE */ +diff --git a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-sources.mk b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-sources.mk +index 1328ffd8..4ccaf27b 100644 +--- a/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-sources.mk ++++ b/kernel-module-source/kernel-open/nvidia-drm/nvidia-drm-sources.mk +@@ -86,6 +86,7 @@ NV_CONFTEST_TYPE_COMPILE_TESTS += drm_driver_has_set_busid + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_crtc_state_has_connectors_changed + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_init_function_args + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_helper_mode_fill_fb_struct ++NV_CONFTEST_TYPE_COMPILE_TESTS += drm_fb_create_takes_format_info + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_master_drop_has_from_release_arg + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_driver_unload_has_int_return_type + NV_CONFTEST_TYPE_COMPILE_TESTS += vm_fault_has_address +diff --git a/kernel/conftest.sh b/kernel/conftest.sh +index 889cf654..30506f8f 100755 +--- a/kernel/conftest.sh ++++ b/kernel/conftest.sh +@@ -4511,6 +4511,25 @@ compile_test() { + compile_check_conftest "$CODE" "NV_DRM_ROTATION_AVAILABLE" "" "functions" + ;; + ++ drm_fb_create_takes_format_info) ++ # ++ # Determine if a `struct drm_format_info *` is passed into ++ # the .fb_create callback (4-arg form). Added by commit ++ # 81112eaac559 ("drm: Pass the format info to .fb_create") ++ # in linux-next (2025-07-16). ++ # ++ CODE=" ++ #include ++ #include ++ ++ static const struct drm_mode_config_funcs funcs; ++ void conftest_drm_fb_create_takes_format_info(void) { ++ funcs.fb_create(NULL, NULL, NULL, NULL); ++ }" ++ ++ compile_check_conftest "$CODE" "NV_DRM_FB_CREATE_TAKES_FORMAT_INFO" "" "types" ++ ;; ++ + drm_driver_prime_flag_present) + # + # Determine whether driver feature flag DRIVER_PRIME is present. +diff --git a/kernel/nvidia-drm/nvidia-drm-drv.c b/kernel/nvidia-drm/nvidia-drm-drv.c +index da2b7010..12fe50ef 100644 +--- a/kernel/nvidia-drm/nvidia-drm-drv.c ++++ b/kernel/nvidia-drm/nvidia-drm-drv.c +@@ -186,6 +186,9 @@ static void nv_drm_output_poll_changed(struct drm_device *dev) + static struct drm_framebuffer *nv_drm_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + #if defined(NV_DRM_HELPER_MODE_FILL_FB_STRUCT_HAS_CONST_MODE_CMD_ARG) + const struct drm_mode_fb_cmd2 *cmd + #else +@@ -201,6 +204,9 @@ static struct drm_framebuffer *nv_drm_framebuffer_create( + fb = nv_drm_internal_framebuffer_create( + dev, + file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ info, ++#endif + &local_cmd); + + #if !defined(NV_DRM_HELPER_MODE_FILL_FB_STRUCT_HAS_CONST_MODE_CMD_ARG) +diff --git a/kernel/nvidia-drm/nvidia-drm-fb.c b/kernel/nvidia-drm/nvidia-drm-fb.c +index 1c842015..973c2c64 100644 +--- a/kernel/nvidia-drm/nvidia-drm-fb.c ++++ b/kernel/nvidia-drm/nvidia-drm-fb.c +@@ -33,6 +33,7 @@ + #include "nvidia-drm-format.h" + + #include ++#include + + static void __nv_drm_framebuffer_free(struct nv_drm_framebuffer *nv_fb) + { +@@ -206,6 +207,9 @@ fail: + struct drm_framebuffer *nv_drm_internal_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + struct drm_mode_fb_cmd2 *cmd) + { + struct nv_drm_device *nv_dev = to_nv_device(dev); +@@ -259,6 +263,9 @@ struct drm_framebuffer *nv_drm_internal_framebuffer_create( + dev, + #endif + &nv_fb->base, ++ #if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ info, ++ #endif + cmd); + + /* +diff --git a/kernel/nvidia-drm/nvidia-drm-fb.h b/kernel/nvidia-drm/nvidia-drm-fb.h +index cf477cc7..5a1a34af 100644 +--- a/kernel/nvidia-drm/nvidia-drm-fb.h ++++ b/kernel/nvidia-drm/nvidia-drm-fb.h +@@ -59,6 +59,9 @@ static inline struct nv_drm_framebuffer *to_nv_framebuffer( + struct drm_framebuffer *nv_drm_internal_framebuffer_create( + struct drm_device *dev, + struct drm_file *file, ++#if defined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) ++ const struct drm_format_info *info, ++#endif + struct drm_mode_fb_cmd2 *cmd); + + #endif /* NV_DRM_ATOMIC_MODESET_AVAILABLE */ +diff --git a/kernel/nvidia-drm/nvidia-drm-sources.mk b/kernel/nvidia-drm/nvidia-drm-sources.mk +index 1328ffd8..4ccaf27b 100644 +--- a/kernel/nvidia-drm/nvidia-drm-sources.mk ++++ b/kernel/nvidia-drm/nvidia-drm-sources.mk +@@ -86,6 +86,7 @@ NV_CONFTEST_TYPE_COMPILE_TESTS += drm_driver_has_set_busid + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_crtc_state_has_connectors_changed + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_init_function_args + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_helper_mode_fill_fb_struct ++NV_CONFTEST_TYPE_COMPILE_TESTS += drm_fb_create_takes_format_info + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_master_drop_has_from_release_arg + NV_CONFTEST_TYPE_COMPILE_TESTS += drm_driver_unload_has_int_return_type + NV_CONFTEST_TYPE_COMPILE_TESTS += vm_fault_has_address +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0003-nvidia-use-hrtimer_setup-for-Linux-6.15.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0003-nvidia-use-hrtimer_setup-for-Linux-6.15.patch new file mode 100644 index 00000000000..7e8025f76ca --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0003-nvidia-use-hrtimer_setup-for-Linux-6.15.patch @@ -0,0 +1,55 @@ +From 0000000000000000000000000000000000000006 Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Thu, 17 Jul 2026 09:30:00 +0530 +Subject: [PATCH] nvidia: use hrtimer_setup() for Linux 6.15+ + +Linux 6.15 introduced hrtimer_setup() which replaces the two-step +hrtimer_init() + timer->function assignment idiom. hrtimer_init() was +subsequently removed, causing build failures on Linux 6.18. + +Guard the call site in nv-nano-timer.c with a symbol-presence conftest +(is_export_symbol_present_hrtimer_setup) rather than a hardcoded +LINUX_VERSION_CODE check, matching NVIDIA's own upstream fix for this +(first shipped in the 570.153.02 driver release) and detecting the +feature directly against the target kernel's Module.symvers rather +than assuming a version boundary. + +Applied to kernel-module-source/kernel-open/ only since the +proprietary kernel/ tree does not use hrtimer in this path. + +Based on: https://github.com/Boux/nvidia-550xx-dkms + +Signed-off-by: Sayan Chowdhury +--- +diff --git a/kernel-module-source/kernel-open/nvidia/nv-nano-timer.c b/kernel-module-source/kernel-open/nvidia/nv-nano-timer.c +index 1a2b3c4d..8f2a1b3c 100644 +--- a/kernel-module-source/kernel-open/nvidia/nv-nano-timer.c ++++ b/kernel-module-source/kernel-open/nvidia/nv-nano-timer.c +@@ -154,8 +154,13 @@ + nv_nstimer->nv_nano_timer_callback = nvidia_nano_timer_callback; + + #if NV_NANO_TIMER_USE_HRTIMER ++#if NV_IS_EXPORT_SYMBOL_PRESENT_hrtimer_setup ++ hrtimer_setup(&nv_nstimer->hr_timer, nv_nano_timer_callback_typed_data, ++ CLOCK_MONOTONIC, HRTIMER_MODE_REL); ++#else + hrtimer_init(&nv_nstimer->hr_timer, CLOCK_MONOTONIC, HRTIMER_MODE_REL); + nv_nstimer->hr_timer.function = nv_nano_timer_callback_typed_data; ++#endif + #else + #if defined(NV_TIMER_SETUP_PRESENT) + timer_setup(&nv_nstimer->jiffy_timer, nv_jiffy_timer_callback_typed_data, 0); +diff --git a/kernel-module-source/kernel-open/nvidia/nvidia.Kbuild b/kernel-module-source/kernel-open/nvidia/nvidia.Kbuild +index 6ae67c3f..eef07bcb 100644 +--- a/kernel-module-source/kernel-open/nvidia/nvidia.Kbuild ++++ b/kernel-module-source/kernel-open/nvidia/nvidia.Kbuild +@@ -235,6 +235,7 @@ + NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_follow_pfnmap_start + NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_gpl_pci_ats_supported + NV_CONFTEST_SYMBOL_COMPILE_TESTS += ecc_digits_from_bytes ++NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_hrtimer_setup + + NV_CONFTEST_TYPE_COMPILE_TESTS += dma_ops + NV_CONFTEST_TYPE_COMPILE_TESTS += swiotlb_dma_ops +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0004-nvidia-uvm-guard-iommu_dev_enable_disable_feature-fo.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0004-nvidia-uvm-guard-iommu_dev_enable_disable_feature-fo.patch new file mode 100644 index 00000000000..1cbf7471589 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0004-nvidia-uvm-guard-iommu_dev_enable_disable_feature-fo.patch @@ -0,0 +1,75 @@ +From 0000000000000000000000000000000000000007 Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Thu, 17 Jul 2026 10:00:00 +0530 +Subject: [PATCH] nvidia-uvm: drop iommu_dev_enable/disable_feature calls + +Linux 6.16 removed iommu_dev_enable_feature() and +iommu_dev_disable_feature() with IOMMU_DEV_FEAT_SVA; SVA is now +handled implicitly by iommu_sva_bind_device(). + +Rather than guarding the calls with LINUX_VERSION_CODE, drop them +entirely, matching NVIDIA's own upstream fix for this (first guarded +behind a symbol-presence conftest in the 570.169 driver release, then +removed outright in 580.65.06, and still absent as of 610.43.02) -- +by the time SVA enablement stopped needing an explicit feature toggle +at all, keeping a version-gated call around was unnecessary complexity. + +Applied to both the proprietary kernel/ and open-source kernel-open/ +trees. + +Signed-off-by: Sayan Chowdhury +--- +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c b/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c +index 1a2b3c4d..7c8d9e0f 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c ++++ b/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c +@@ -304,12 +304,6 @@ + + NV_STATUS uvm_ats_sva_add_gpu(uvm_parent_gpu_t *parent_gpu) + { +- int ret; +- +- ret = iommu_dev_enable_feature(&parent_gpu->pci_dev->dev, IOMMU_DEV_FEAT_SVA); +- if (ret) +- return errno_to_nv_status(ret); +- + if (UVM_ATS_SMMU_WAR_REQUIRED()) + return uvm_ats_smmu_war_init(parent_gpu); + else +@@ -320,8 +314,6 @@ + { + if (UVM_ATS_SMMU_WAR_REQUIRED()) + uvm_ats_smmu_war_deinit(parent_gpu); +- +- iommu_dev_disable_feature(&parent_gpu->pci_dev->dev, IOMMU_DEV_FEAT_SVA); + } + + NV_STATUS uvm_ats_sva_bind_gpu(uvm_gpu_va_space_t *gpu_va_space) +diff --git a/kernel/nvidia-uvm/uvm_ats_sva.c b/kernel/nvidia-uvm/uvm_ats_sva.c +index 1a2b3c4d..7c8d9e0f 100644 +--- a/kernel/nvidia-uvm/uvm_ats_sva.c ++++ b/kernel/nvidia-uvm/uvm_ats_sva.c +@@ -304,12 +304,6 @@ + + NV_STATUS uvm_ats_sva_add_gpu(uvm_parent_gpu_t *parent_gpu) + { +- int ret; +- +- ret = iommu_dev_enable_feature(&parent_gpu->pci_dev->dev, IOMMU_DEV_FEAT_SVA); +- if (ret) +- return errno_to_nv_status(ret); +- + if (UVM_ATS_SMMU_WAR_REQUIRED()) + return uvm_ats_smmu_war_init(parent_gpu); + else +@@ -320,8 +314,6 @@ + { + if (UVM_ATS_SMMU_WAR_REQUIRED()) + uvm_ats_smmu_war_deinit(parent_gpu); +- +- iommu_dev_disable_feature(&parent_gpu->pci_dev->dev, IOMMU_DEV_FEAT_SVA); + } + + NV_STATUS uvm_ats_sva_bind_gpu(uvm_gpu_va_space_t *gpu_va_space) +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0005-nvidia-uvm-guard-SMMU-WAR-code-with-UVM_ATS_SMMU_WA.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0005-nvidia-uvm-guard-SMMU-WAR-code-with-UVM_ATS_SMMU_WA.patch new file mode 100644 index 00000000000..4060ab6bab1 --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0005-nvidia-uvm-guard-SMMU-WAR-code-with-UVM_ATS_SMMU_WA.patch @@ -0,0 +1,120 @@ +From 0000000000000000000000000000000000000008 Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Thu, 17 Jul 2026 10:30:00 +0530 +Subject: [PATCH] nvidia-uvm: guard SMMU WAR code with UVM_ATS_SMMU_WAR_REQUIRED + +The SMMU WAR helper functions (smmu_vcmdq_write64, uvm_ats_smmu_war_init, +etc.) use ARM64-specific APIs like iowrite64 and arm64_mm_context_get +that are not available on x86_64. They were previously compiled on any +arch with CONFIG_IOMMU_SVA enabled because they lack the +UVM_ATS_SMMU_WAR_REQUIRED() guard that covers only the TLB invalidation +function. + +Wrap the entire SMMU WAR definition block (structs, macros, helpers, +war_init/deinit) with #if UVM_ATS_SMMU_WAR_REQUIRED() and replace the +runtime if (UVM_ATS_SMMU_WAR_REQUIRED()) checks in uvm_ats_sva_add_gpu +and uvm_ats_sva_remove_gpu with compile-time #if guards. + +This bug is still present as of NVIDIA's own latest driver release +(610.43.02): uvm_ats_smmu_war_init/deinit and the smmu_cmd struct are +still compiled unconditionally there whenever UVM_ATS_SVA_SUPPORTED() +is true, regardless of arch. There is no upstream fix to align to for +this one -- this patch is original to this ebuild. + +Applied to both the proprietary kernel/ and open-source kernel-open/ +trees. + +Signed-off-by: Sayan Chowdhury +--- +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c b/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c +index 7c8d9e0f..5e6f7a8b 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c ++++ b/kernel-module-source/kernel-open/nvidia-uvm/uvm_ats_sva.c +@@ -51,6 +51,7 @@ + #define UVM_IOMMU_SVA_BIND_DEVICE(dev, mm) iommu_sva_bind_device(dev, mm) + #endif + ++#if UVM_ATS_SMMU_WAR_REQUIRED() + // Type to represent a 128-bit SMMU command queue command. + struct smmu_cmd { + NvU64 low; +@@ -235,7 +236,6 @@ + // kernel. + #define UVM_MAX_TLBI_OPS (1UL << (PAGE_SHIFT - 3)) + +-#if UVM_ATS_SMMU_WAR_REQUIRED() + void uvm_ats_smmu_invalidate_tlbs(uvm_gpu_va_space_t *gpu_va_space, NvU64 addr, size_t size) + { + struct mm_struct *mm = gpu_va_space->va_space->va_space_mm.mm; +@@ -304,16 +304,18 @@ + + NV_STATUS uvm_ats_sva_add_gpu(uvm_parent_gpu_t *parent_gpu) + { +- if (UVM_ATS_SMMU_WAR_REQUIRED()) +- return uvm_ats_smmu_war_init(parent_gpu); +- else +- return NV_OK; ++#if UVM_ATS_SMMU_WAR_REQUIRED() ++ return uvm_ats_smmu_war_init(parent_gpu); ++#else ++ return NV_OK; ++#endif + } + + void uvm_ats_sva_remove_gpu(uvm_parent_gpu_t *parent_gpu) + { +- if (UVM_ATS_SMMU_WAR_REQUIRED()) +- uvm_ats_smmu_war_deinit(parent_gpu); ++#if UVM_ATS_SMMU_WAR_REQUIRED() ++ uvm_ats_smmu_war_deinit(parent_gpu); ++#endif + } + + NV_STATUS uvm_ats_sva_bind_gpu(uvm_gpu_va_space_t *gpu_va_space) +diff --git a/kernel/nvidia-uvm/uvm_ats_sva.c b/kernel/nvidia-uvm/uvm_ats_sva.c +index 7c8d9e0f..5e6f7a8b 100644 +--- a/kernel/nvidia-uvm/uvm_ats_sva.c ++++ b/kernel/nvidia-uvm/uvm_ats_sva.c +@@ -51,6 +51,7 @@ + #define UVM_IOMMU_SVA_BIND_DEVICE(dev, mm) iommu_sva_bind_device(dev, mm) + #endif + ++#if UVM_ATS_SMMU_WAR_REQUIRED() + // Type to represent a 128-bit SMMU command queue command. + struct smmu_cmd { + NvU64 low; +@@ -235,7 +236,6 @@ + // kernel. + #define UVM_MAX_TLBI_OPS (1UL << (PAGE_SHIFT - 3)) + +-#if UVM_ATS_SMMU_WAR_REQUIRED() + void uvm_ats_smmu_invalidate_tlbs(uvm_gpu_va_space_t *gpu_va_space, NvU64 addr, size_t size) + { + struct mm_struct *mm = gpu_va_space->va_space->va_space_mm.mm; +@@ -304,16 +304,18 @@ + + NV_STATUS uvm_ats_sva_add_gpu(uvm_parent_gpu_t *parent_gpu) + { +- if (UVM_ATS_SMMU_WAR_REQUIRED()) +- return uvm_ats_smmu_war_init(parent_gpu); +- else +- return NV_OK; ++#if UVM_ATS_SMMU_WAR_REQUIRED() ++ return uvm_ats_smmu_war_init(parent_gpu); ++#else ++ return NV_OK; ++#endif + } + + void uvm_ats_sva_remove_gpu(uvm_parent_gpu_t *parent_gpu) + { +- if (UVM_ATS_SMMU_WAR_REQUIRED()) +- uvm_ats_smmu_war_deinit(parent_gpu); ++#if UVM_ATS_SMMU_WAR_REQUIRED() ++ uvm_ats_smmu_war_deinit(parent_gpu); ++#endif + } + + NV_STATUS uvm_ats_sva_bind_gpu(uvm_gpu_va_space_t *gpu_va_space) +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0006-nvidia-uvm-adapt-to-page_pgmap-and-make_device_excl.patch b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0006-nvidia-uvm-adapt-to-page_pgmap-and-make_device_excl.patch new file mode 100644 index 00000000000..997c4bef7db --- /dev/null +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0006-nvidia-uvm-adapt-to-page_pgmap-and-make_device_excl.patch @@ -0,0 +1,191 @@ +From 0000000000000000000000000000000000000008 Mon Sep 17 00:00:00 2001 +From: Sayan Chowdhury +Date: Wed, 2 Sep 2026 00:00:00 +0530 +Subject: [PATCH] nvidia-uvm: adapt to page_pgmap() and + make_device_exclusive() for Linux 6.18 + +Two mm API changes broke the nvidia-uvm kernel-open build against +Linux 6.18.45: + +1. struct page no longer has a 'pgmap' member. The pgmap pointer + moved to struct folio (a pgmap is shared by every page in a + folio), and is now accessed through the page_pgmap() helper. + Added by upstream commit 82ba975e4c43 ("mm: allow compound zone + device pages") in v6.14. + +2. make_device_exclusive_range(), which converted a whole address + range and filled a caller-supplied page array, was replaced by + make_device_exclusive(), which operates on a single address and + also returns the containing folio. + +Both call sites and the conftest probe are ported from NVIDIA's own +fix for this, first shipped in the 570.153.02 driver release +(kernel-open/nvidia-uvm/uvm_hmm.c, commit tagged "570.153.02" in +NVIDIA/open-gpu-kernel-modules): hmm_block_atomic_fault_locked() now +calls a new hmm_make_device_exclusive_range() wrapper that loops over +each page in the region, unwinding (unlock_page/put_page) all +previously-acquired pages if any page fails, then falls back to the +old range API when make_device_exclusive() isn't exported by the +kernel (detected via the existing is_export_symbol_present_* conftest +mechanism, rather than a new custom conftest case). + +The devmem_page_to_pmm() page_pgmap() swap in uvm_pmm_gpu.c has no +upstream equivalent to port: that function doesn't exist anymore by +570.153.02 (refactored away as part of later device-p2p-memory work +not present in the 550.163.01 driver), so it's a hand-written fix +guarded the same way as fill_dst_pfn's page_pgmap() use in uvm_hmm.c. + +Unlike NVIDIA's 570.153.02 fix, the page_pgmap() call sites here stay +guarded by #if defined(NV_PAGE_PGMAP_PRESENT)/#else rather than being +unconditional, since this ebuild's defconfigs must keep building +against older kernels that predate page_pgmap(). + +The wrapper's unwind path saves PTR_ERR() before the loop reuses +'page'; otherwise a partial failure would return a page pointer +truncated to int instead of an errno. + +Signed-off-by: Sayan Chowdhury +--- +diff --git a/kernel-module-source/kernel-open/conftest.sh b/kernel-module-source/kernel-open/conftest.sh +index 1835124..24920c9 100755 +--- a/kernel-module-source/kernel-open/conftest.sh ++++ b/kernel-module-source/kernel-open/conftest.sh +@@ -7148,6 +7148,22 @@ compile_test() { + compile_check_conftest "$CODE" "NV_FOLIO_TEST_SWAPCACHE_PRESENT" "" "functions" + ;; + ++ page_pgmap) ++ # ++ # Determine if the page_pgmap() function is present. ++ # ++ # Added by commit 82ba975e4c43 ("mm: allow compound zone device ++ # pages") in v6.14 ++ # ++ CODE=" ++ #include ++ void conftest_page_pgmap(void) { ++ (void)page_pgmap(NULL); ++ }" ++ ++ compile_check_conftest "$CODE" "NV_PAGE_PGMAP_PRESENT" "" "functions" ++ ;; ++ + + drm_driver_has_date) + # +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/nvidia-uvm.Kbuild b/kernel-module-source/kernel-open/nvidia-uvm/nvidia-uvm.Kbuild +index ba99e37..25f8d42 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/nvidia-uvm.Kbuild ++++ b/kernel-module-source/kernel-open/nvidia-uvm/nvidia-uvm.Kbuild +@@ -70,6 +70,7 @@ NV_CONFTEST_FUNCTION_COMPILE_TESTS += vm_fault_to_errno + NV_CONFTEST_FUNCTION_COMPILE_TESTS += find_next_bit_wrap + NV_CONFTEST_FUNCTION_COMPILE_TESTS += iommu_is_dma_domain + NV_CONFTEST_FUNCTION_COMPILE_TESTS += folio_test_swapcache ++NV_CONFTEST_FUNCTION_COMPILE_TESTS += page_pgmap + + NV_CONFTEST_TYPE_COMPILE_TESTS += backing_dev_info + NV_CONFTEST_TYPE_COMPILE_TESTS += mm_context_t +@@ -99,3 +100,4 @@ NV_CONFTEST_TYPE_COMPILE_TESTS += mmu_interval_notifier + + NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_int_active_memcg + NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_migrate_vma_setup ++NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_make_device_exclusive +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/uvm_hmm.c b/kernel-module-source/kernel-open/nvidia-uvm/uvm_hmm.c +index 49598cf..238063c 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/uvm_hmm.c ++++ b/kernel-module-source/kernel-open/nvidia-uvm/uvm_hmm.c +@@ -51,6 +51,7 @@ module_param(uvm_disable_hmm, bool, 0444); + + #include + #include ++#include + #include + #include + #include +@@ -1986,7 +1987,11 @@ static void fill_dst_pfn(uvm_va_block_t *va_block, + + dpage = pfn_to_page(pfn); + UVM_ASSERT(is_device_private_page(dpage)); ++#if defined(NV_PAGE_PGMAP_PRESENT) ++ UVM_ASSERT(page_pgmap(dpage)->owner == &g_uvm_global); ++#else + UVM_ASSERT(dpage->pgmap->owner == &g_uvm_global); ++#endif + + hmm_mark_gpu_chunk_referenced(va_block, gpu, gpu_chunk); + UVM_ASSERT(!page_count(dpage)); +@@ -2428,6 +2433,42 @@ static void hmm_release_atomic_pages(uvm_va_block_t *va_block, + } + } + ++static int hmm_make_device_exclusive_range(struct mm_struct *mm, ++ unsigned long start, ++ unsigned long end, ++ struct page **pages) ++{ ++#if NV_IS_EXPORT_SYMBOL_PRESENT_make_device_exclusive ++ unsigned long addr; ++ int npages = 0; ++ ++ for (addr = start; addr < end; addr += PAGE_SIZE) { ++ struct folio *folio; ++ struct page *page; ++ ++ page = make_device_exclusive(mm, addr, &g_uvm_global, &folio); ++ if (IS_ERR(page)) { ++ // Grab the errno before the unwind loop reuses 'page'. ++ int err = PTR_ERR(page); ++ ++ while (npages) { ++ page = pages[--npages]; ++ unlock_page(page); ++ put_page(page); ++ } ++ npages = err; ++ break; ++ } ++ ++ pages[npages++] = page; ++ } ++ ++ return npages; ++#else ++ return make_device_exclusive_range(mm, start, end, pages, &g_uvm_global); ++#endif ++} ++ + static NV_STATUS hmm_block_atomic_fault_locked(uvm_processor_id_t processor_id, + uvm_va_block_t *va_block, + uvm_va_block_retry_t *va_block_retry, +@@ -2481,11 +2522,10 @@ static NV_STATUS hmm_block_atomic_fault_locked(uvm_processor_id_t processor_id, + + uvm_mutex_unlock(&va_block->lock); + +- npages = make_device_exclusive_range(service_context->block_context->mm, ++ npages = hmm_make_device_exclusive_range(service_context->block_context->mm, + uvm_va_block_cpu_page_address(va_block, region.first), + uvm_va_block_cpu_page_address(va_block, region.outer - 1) + PAGE_SIZE, +- pages + region.first, +- &g_uvm_global); ++ pages + region.first); + + uvm_mutex_lock(&va_block->lock); + +diff --git a/kernel-module-source/kernel-open/nvidia-uvm/uvm_pmm_gpu.c b/kernel-module-source/kernel-open/nvidia-uvm/uvm_pmm_gpu.c +index b12911c..24cb15b 100644 +--- a/kernel-module-source/kernel-open/nvidia-uvm/uvm_pmm_gpu.c ++++ b/kernel-module-source/kernel-open/nvidia-uvm/uvm_pmm_gpu.c +@@ -3309,7 +3309,11 @@ NvU32 uvm_pmm_gpu_phys_to_virt(uvm_pmm_gpu_t *pmm, NvU64 phys_addr, NvU64 region + + static uvm_pmm_gpu_t *devmem_page_to_pmm(struct page *page) + { ++#if defined(NV_PAGE_PGMAP_PRESENT) ++ return container_of(page_pgmap(page), uvm_pmm_gpu_t, devmem.pagemap); ++#else + return container_of(page->pgmap, uvm_pmm_gpu_t, devmem.pagemap); ++#endif + } + + static uvm_gpu_chunk_t *devmem_page_to_chunk_locked(struct page *page) +-- +2.53.0 diff --git a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild index 6714d29b660..22916b1baa0 100644 --- a/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild +++ b/sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild @@ -7,7 +7,7 @@ MODULES_OPTIONAL_IUSE=+modules inherit desktop dot-a eapi9-pipestatus flag-o-matic linux-mod-r1 inherit readme.gentoo-r1 systemd toolchain-funcs unpacker user-info -MODULES_KERNEL_MAX=6.14 +MODULES_KERNEL_MAX=6.18 NV_URI="https://download.nvidia.com/XFree86/" DESCRIPTION="NVIDIA Accelerated Graphics Driver" @@ -92,6 +92,12 @@ PATCHES=( "${FILESDIR}"/nvidia-modprobe-390.141-uvm-perms.patch "${FILESDIR}"/nvidia-settings-530.30.02-desktop.patch "${FILESDIR}"/nvidia-pci-resize-resource-fix-550.patch + "${FILESDIR}"/0001-mm-use-vm_flags_reset-to-avoid-GPL-only-vma_start_wr.patch + "${FILESDIR}"/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch + "${FILESDIR}"/0003-nvidia-use-hrtimer_setup-for-Linux-6.15.patch + "${FILESDIR}"/0004-nvidia-uvm-guard-iommu_dev_enable_disable_feature-fo.patch + "${FILESDIR}"/0005-nvidia-uvm-guard-SMMU-WAR-code-with-UVM_ATS_SMMU_WA.patch + "${FILESDIR}"/0006-nvidia-uvm-adapt-to-page_pgmap-and-make_device_excl.patch ) pkg_setup() { @@ -148,12 +154,35 @@ src_prepare() { rm nvidia-xconfig && mv nvidia-xconfig{-${PV},} || die mv NVIDIA-kernel-module-source-${PV} kernel-module-source || die + # Linux 6.15 removed EXTRA_CFLAGS support for out-of-tree kernel modules + # (upstream commit b2c885b9). + find "${S}" \( -name 'Kbuild' -o -name 'Makefile' \) \ + -exec sed -i 's/\bEXTRA_CFLAGS\b/ccflags-y/g' {} + || die + + # Linux 6.15 renamed del_timer_sync() to timer_delete_sync() (commit + # d4b4c87), removing the old symbol outright. + if kernel_is -ge 6 15; then + find "${S}/kernel" "${S}/kernel-module-source" \( -name '*.c' -o -name '*.h' \) \ + -exec sed -i 's/\bdel_timer_sync\b/timer_delete_sync/g' {} + || die + fi + default # prevent detection of incomplete kernel DRM support (bug #603818) sed 's/defined(CONFIG_DRM/defined(CONFIG_DRM_KMS_HELPER/g' \ -i kernel{,-module-source/kernel-open}/conftest.sh || die + # Linux 6.18 removed dma_buf_attachment_is_dynamic() but it still appears + # in a doc comment in . The conftest uses an inline + # "$CC $CFLAGS -c conftest.c" (not compile_check_conftest) and compiles + # without -Werror=implicit-function-declaration, so the implicit declaration + # is only a warning and the compilation succeeds, incorrectly defining + # NV_DMA_BUF_HAS_DYNAMIC_ATTACHMENT. Add the flag scoped to just that block. + find "${S}" -name "conftest.sh" -exec sed -i \ + '/dma_buf_has_dynamic_attachment)/,/;;/ s/\$CC \$CFLAGS -c conftest/\$CC \$CFLAGS -Werror=implicit-function-declaration -c conftest/' \ + {} + || die + + sed 's/__USER__/nvpd/' \ nvidia-persistenced/init/systemd/nvidia-persistenced.service.template \ > "${T}"/nvidia-persistenced.service || die