Commit Graph
3004 Commits
Author SHA1 Message Date
Mark Brown 647a365c9a Merge branch 'sysctl-next' of https://git.kernel.org/pub/scm/linux/kernel/git/sysctl/sysctl.git 2026-07-31 16:35:34 +01:00
Mark Brown 86c0e95669 next-20260730/paulmck 2026-07-31 15:43:50 +01:00
Mark Brown fd54710217 Merge branch 'master' of https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git 2026-07-31 15:29:51 +01:00
Mark Brown 3a8916974f Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/s390/linux.git
# Conflicts:
#	arch/s390/mm/init.c
2026-07-31 14:49:55 +01:00
Ingo Molnar ed3255ee63 Merge branch into tip/master: 'timers/vdso'
# New commits in timers/vdso:
    ecacc9c8d3 ("vdso: Rename HAVE_GENERIC_VDSO to VDSO_DATASTORE")
    52447180f4 ("vdso: Drop HAVE_GENERIC_VDSO from architecture kconfig files")
    faeff8d416 ("vdso: Automatically select HAVE_GENERIC_VDSO if necessary")
    8c0015572c ("MIPS: vdso: Stop using CONFIG_HAVE_GENERIC_VDSO")
    a924263758 ("vdso: Remove the dependency on HAVE_GENERIC_VDSO from ARCH_HAS_VDSO_ARCH_DATA")
    2558084d2b ("futex: Remove dependency on HAVE_GENERIC_VDSO from FUTEX_ROBUST_UNLOCK")
    369cecd238 ("vdso/gettimeofday: Verify COMPAT_32BIT_TIME interactions")
    2700297b69 ("sparc: vdso: Respect COMPAT_32BIT_TIME")
    377e3f2d41 ("MIPS: VDSO: Respect COMPAT_32BIT_TIME")
    e01abc70af ("powerpc/vdso: Respect COMPAT_32BIT_TIME")
    95216f4647 ("ARM: VDSO: Respect COMPAT_32BIT_TIME")
    abb1537388 ("arm64: vdso32: Respect COMPAT_32BIT_TIME")
    1a4660da31 ("x86/vdso: Respect COMPAT_32BIT_TIME")
    f8b9467725 ("vdso/gettimeofday: Validate system call existence for time() and gettimeofday()")
    dce21fb3d5 ("time: Respect COMPAT_32BIT_TIME for old time type functions")
    0b50763e84 ("vdso/datastore: Simplify the mapping logic for VDSO_TIME_PAGE_OFFSET")
    c27e727c9a ("vdso/datastore: Allow prefaulting by mlockall()")
    9ab500d47f ("vdso/datastore: Explicitly prevent remote access to timens vvar page")
    43648f9f3a ("vdso/datastore: Map zeroed pages for unavailable data")
    7557273419 ("vdso/datastore: Map pages in terms of the faults pgoff")
    ff868f43eb ("vdso/datastore: Rename data pages variable")
    02475538be ("vdso: Replace __ASSEMBLY__ with __ASSEMBLER__ in header files")

Signed-off-by: Ingo Molnar <mingo@kernel.org>
2026-07-31 11:53:17 +02:00
Ingo Molnar c76b1e28c4 Merge branch into tip/master: 'timers/core'
# New commits in timers/core:
    ecc330e309 ("timers/migration: Fix bad line kernel-doc warning in struct tmigr_cpu")
    98680a85df ("posix-cpu-timers: Avoid kernel-doc warnings")
    151ce4cf88 ("posix-timers: Clean up kernel-doc warnings")
    f44ce7fdbd ("selftests: timers: Partially revert "Remove local NSEC_PER_SEC and USEC_PER_SEC defines"")
    794ddd6e15 ("ntp: Remove tick_length_base, use tick_length directly")
    34ce97c33d ("timekeeping: Settle competing time_offset and time_adjust skew")
    289d175949 ("timekeeping: Drive time_adjust skew via per-tick ntp_error transfer")
    d375af5899 ("timekeeping: Drive time_offset skew via per-tick ntp_error transfer")
    869a55e662 ("timekeeping: Account for clocksource tick quantisation via NTP")
    b7befd6d91 ("timekeeping: Account for monotonicity adjustment in ntp_error")
    79b8bd857b ("MAINTAINERS: Add Miroslav as timekeeping reviewer")
    79ced850e5 ("y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32")
    79bd39c58f ("timekeeping: Move the vDSO update declarations into a private header")
    6e43591139 ("timekeeping: Fold vdso_time_update_aux() declarations into the generic ifdeffery")
    faef65e45a ("hrtimer: Remove inclusion of hrtimer_bases.h remove from hrtimer.h")
    0c31af3d23 ("x86/speculation: Explicitly include linux/types.h")
    071993aac7 ("hrtimer: Explicitly include some necessary headers in hrtimer_rearm.h")
    95cf8bbadd ("hrtimer: Explicitly include linux/hrtimer_bases.h")
    73fcec09d1 ("tick: Explicitly include linux/hrtimer_bases.h")
    a116c7582d ("hrtimer: Move hrtimer_update_function() to hrtimer.c")
    d3dc7fabd4 ("hrtimer: Move hrtimer_callback_running() to hrtimer_bases.h")
    03b5d4c279 ("hrtimer: Rename hrtimer_defs.h to hrtimer_bases.h")
    c4415c993f ("hrtimer: Don't take cpu_base::lock in hrtimer_get_next_event() when hres_active")
    1d28a67d49 ("timer_list: Annotate print_cpu() diagnostic reads")
    06aba58e58 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
    eddfded419 ("timers/migration: Fix memory leak in tmigr_setup_groups() error path")
    f2eee7e31c ("timekeeping: Unwind aux clock sysfs children on failure")
    3dee6537e7 ("clocksource: Unregister subsystem on device registration failure")
    b4b66151a7 ("selftests: timers: leap-a-day: Fix -w option and update usage comment")
    b3afded935 ("clocksource: Remove unused WATCHDOG_INTERVAL_NS macro")
    d8966ca885 ("hrtimer: Remove unused next_timer argument from __hrtimer_reprogram()")
    e2904ddb14 ("timekeeping: Document monotonic raw timestamps in snapshots correctly")
    a73d7f98e4 ("posix-cpu-timers: Don't abuse lock_task_sighand() in handle_posix_cpu_timers()")
    034b5779b8 ("hrtimer: Remove unused clock_base_next_timer_safe()")

Signed-off-by: Ingo Molnar <mingo@kernel.org>
2026-07-31 11:53:17 +02:00
Oleg NesterovandAndrew Morton 67dc06b843 sysctl: remove CONFIG_PROC_SYSCTL, it just mirrors CONFIG_SYSCTL
CONFIG_SYSCTL used to make sense as a separate hidden bool before commit
61a47c1ad3 ("sysctl: Remove the sysctl system call"); it was selected by
both CONFIG_SYSCTL_SYSCALL and CONFIG_PROC_SYSCTL.

Today CONFIG_PROC_SYSCTL is the only selector, so the two are always
equal.  Kill the hidden bool, rename the PROC_SYSCTL prompt to SYSCTL, and
s/CONFIG_PROC_SYSCTL/CONFIG_SYSCTL/ tree-wide.

Link: https://lore.kernel.org/amdveg1m4E4uQlGv@redhat.com
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Cc: Alexander Gordeev <agordeev@linux.ibm.com>
Cc: Alexandre Torgue <alexandre.torgue@foss.st.com>
Cc: Alexey Gladkov (Intel) <legion@kernel.org>
Cc: Balbir Singh <bsingharora@gmail.com>
Cc: "Borislav Petkov (AMD)" <bp@alien8.de>
Cc: Dave Hansen <dave.hansen@linux.intel.com>
Cc: David S. Miller <davem@davemloft.net>
Cc: Eric Biederman <ebiederm@xmission.com>
Cc: Eric Dumazet <edumazet@google.com>
Cc: Geert Uytterhoeven <geert@linux-m68k.org>
Cc: Heiko Carstens <hca@linux.ibm.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jakub Kacinski <kuba@kernel.org>
Cc: Jason A. Donenfeld <jason@zx2c4.com>
Cc: Joel Granados <joel.granados@kernel.org>
Cc: Juri Lelli <juri.lelli@redhat.com>
Cc: Kees Cook <kees@kernel.org>
Cc: Maxime Coquelin <mcoquelin.stm32@gmail.com>
Cc: Nathan Chancellor <nathan@kernel.org>
Cc: Paolo Abeni <pabeni@redhat.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Vasily Gorbik <gor@linux.ibm.com>
Cc: Vincent Guittot <vincent.guittot@linaro.org>
Cc: Yang Yang <yang.yang29@zte.com.cn>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
2026-07-30 19:50:15 -07:00
Vasily Gorbik e057c52e91 Merge branch 'features' into for-next
* features:
  s390/configs: Increase CONFIG_LOCKDEP_CHAINS_BITS
  s390: Add support for DCACHE_WORD_ACCESS (again)
  s390/mm: Use goto statement in do_secure_storage_access()
  s390/mm: Use handle_fault_error() in do_secure_storage_access()
  s390/mm: Remove folio handling for kernel faults in do_secure_storage_access()
  s390/mm: Fix handling of vmalloc area in do_secure_storage_access()
  s390/mm: Use lock_mm_and_find_vma() in do_secure_storage_access()
  s390/mm: Add missing mm check to do_secure_storage_access()
  KVM: s390: pv: Use VM_SPARSE area for guest variable storage area
  s390/spinlock: Add contention tracepoints to lock slowpath
  s390/ipl: Improve readability
  s390/ipl: Use ARRAY_SIZE macro
  s390/maccess: Use proper PTE accessors for copying old memory
  s390/pkey: Rework ioctl functions error paths
  s390/ap: Use mutex_lock_killable() in ap_bus_force_rescan()
  s390/vdso: Use symbolic constants for the PHDR permission flags
  s390/vdso: Pass --eh-frame-hdr to the linker
  s390/syscalls: Use define instead of '1' to indicate PER trap
  s390/traps: Remove PIF_GUEST_FAULT
  s390/uapi: Remove obsolete unistd_32.h from Kbuild file
  s390: Select SWIOTLB_DYNAMIC and DMA_COHERENT_POOL
  s390/pv: Enable SWIOTLB_ANY for s390 PV
  s390/traps: Add exception statistics
  s390/configs: Enable cpuidle driver on s390
  s390/idle: Introduce cpuidle for s390
  s390: Enable TIF_POLLING_NRFLAG
  tick: Remove arch_needs_cpu
  s390/tick: Remove CIF_NOHZ_DELAY flag
  s390/mm: Use set_pmd() / set_pud() for hugetlb pagetable entries

Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-30 00:32:30 +02:00
Paul E. McKenney 65f23137b6 timers: Use accessor for hrtimer_sleeper ->task field in sleep_timeout.c
The hrtimer_sleeper structure's ->task field is used as a flag to indicate
that the associated hrtimer has expired.  This means that the hrtimer
handler can be storing to this field while other code is loading from it
to check for expiry.  Note that additional races appear for hrtimers that
can be restarted, which could be argued to be a user error.  However, that
is no reason to let the compiler introduce additional confusion, and to
this end, the hrtimer_sleeper_task_get() was introduced, use of which also
has the benefit of avoiding open-code access to hrtimer_sleeper innards.

Therefore, apply this accessor to schedule_hrtimeout_range_clock().

KCSAN located this issue.

Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
Cc: Anna-Maria Behnsen <anna-maria@linutronix.de>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Thomas Gleixner <tglx@kernel.org>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
2026-07-23 10:38:43 -07:00
Paul E. McKenney 98d3f664fa hrtimer: Mark data-racy accesses to hrtimer_sleeper ->task field
The hrtimer_sleeper structure's ->task field is used as a flag to indicate
that the associated hrtimer has expired.  This means that the hrtimer
handler can be storing to this field while other code is loading from it
to check for expiry.  Note that additional races appear for hrtimers that
can be restarted, which could be argued to be a user error.  However,
that is no reason to let the compiler introduce additional confusion.

Therefore, mark data-racy accesses to the hrtimer_sleeper ->task field
using READ_ONCE() (using a new hrtimer_sleeper_task_get() access function)
and WRITE_ONCE() (using a new hrtimer_sleeper_task_set() access function).

KCSAN located this issue.

Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
Cc: Anna-Maria Behnsen <anna-maria@linutronix.de>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Thomas Gleixner <tglx@kernel.org>
2026-07-23 10:37:49 -07:00
Babanpreet SinghandThomas Gleixner ecc330e309 timers/migration: Fix bad line kernel-doc warning in struct tmigr_cpu
Running kernel-doc on timer_migration.h reports:

  Warning: kernel/time/timer_migration.h:105 bad line:

The empty line separating the @available paragraph from the @idle
member documentation in the struct tmigr_cpu kernel-doc block lacks
the " *" line prefix that kernel-doc requires on every line inside a
block. The header is not scanned by the build-time kernel-doc checks,
so the warning only shows up when kernel-doc is invoked on the file
directly.

Add the missing prefix. The empty line was introduced when the
@available documentation was expanded by commit 45a13ba52c
("timers/migration: Update stale @online doc to @available").

No functional change.

Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Claude:claude-sonnet-5
Link: https://patch.msgid.link/20260717035947.7-1-bbnpreetsingh@gmail.com
2026-07-20 16:07:39 +02:00
David WoodhouseandThomas Gleixner 794ddd6e15 ntp: Remove tick_length_base, use tick_length directly
Now that nothing inflates tick_length beyond tick_length_base (the
adjtime path was converted to use time_offset in the previous commit),
the two fields are always equal.

Remove tick_length_base and keep tick_length as the single field.
Remove the per-second reset and the delta update in
ntp_update_frequency() since there is no separate base to track.

No functional change intended.

Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.6-1m
Link: https://patch.msgid.link/20260621220051.1030462-8-dwmw2@infradead.org
2026-07-10 09:20:55 +02:00
David WoodhouseandThomas Gleixner 34ce97c33d timekeeping: Settle competing time_offset and time_adjust skew
time_offset (the exponential PLL phase slew) and time_adjust (the
linear adjtime() slew) can be asked to move the clock in opposite
directions. second_overflow() folds only their *net* into the per-tick
skew_delta, so the cancelling overlap would never be drained from
either tracker by the per-tick code — and if they cancel exactly,
skew_delta is zero and neither converges at all.

Arguably we could just let one of them entirely cancel out the other
immediately, but that would be a change in userspace-visible behaviour.

Instead, preserve the existing behaviour by calculating the "conflict"
portion between the opposing skew each second, and transferring that
amount directly from one tracker to the other.

Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.8
Link: https://patch.msgid.link/20260621220051.1030462-7-dwmw2@infradead.org
2026-07-10 09:20:55 +02:00
David WoodhouseandThomas Gleixner 289d175949 timekeeping: Drive time_adjust skew via per-tick ntp_error transfer
The legacy adjtime() slew (ADJ_OFFSET_SINGLESHOT) was the last user of
tick_length != tick_length_base: it slewed the clock by inflating
tick_length directly, which delivered the correction imprecisely (e.g.
delivering only 4997.5µs when asked for a 5ms skew).

Deliver it accurately through the same per-tick mechanism that is now
used for time_offset, allowing it to contribute to skew_delta and thus
drive the delivery through ntp_error and mult selection.

To allow for accurate accounting, store the sub-microsecond part of
time_adjust is separately, while keeping time_adjust in microseconds
as that's the external API.

Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.8
Link: https://patch.msgid.link/20260621220051.1030462-6-dwmw2@infradead.org
2026-07-10 09:20:54 +02:00
David WoodhouseandThomas Gleixner d375af5899 timekeeping: Drive time_offset skew via per-tick ntp_error transfer
Currently, the phase offset of time_offset and time_adjust is delivered
by adjusting tick_length in second_overflow(), and immediately draining
time_offset/time_adjust by the amount that the tick_length adjustment is
*estimated* to cause. This is fairly approximate, in part because it is
not always correct to assume that precisely NTP_INTERVAL_FREQ ticks will
occur between one call to second_overflow() and the next. It could also
over and under-run in the final second of delivery.

Instead of inflating tick_length, transfer the intended skew directly
into ntp_error each tick to achieve the desired rate.

In second_overflow(), calculate skew_delta which is the per-tick slew
rate, in the same units as time_offset: (ns << NTP_SCALE_SHIFT) / HZ.

In logarithmic_accumulation(), drain up to 'skew_delta' time units from
time_offset into ntp_error to drive the overall effective rate. The new
ntp_drain_skew() function returns the amount which is actually 'claimed'
by time_offset (and in a future patch, time_adjust). Any overrun which
is delivered by the changed 'mult' (as described below) but not claimed
by ntp_drain_skew() will remain in ntp_error to be corrected away in
subsequent ticks.

Simply transferring the precise amount from time_offset to ntp_error
would be sufficent to make the time *eventually* converge, however the
skew delivered is limited by the choice of { mult, mult+1 } each tick
and thus the convergence would be extremely slow.

In theory we could inflate ntp_err_mult with the magnitude of ntp_error
in the general case — but that would cause overcorrection in a tickless
kernel. Instead, in timekeeping_adjust(), take skew_delta into account
when calculating 'mult', such that the available {mult, mult+1} choices
bracket the overall effective rate *including* the skew, to avoid the
delta just building up in ntp_error.

The effect is that the inflated 'mult' causes ntp_error to grow because
xtime_interval is (e.g.) longer than the true tick_length. But then the
same delta is removed again as it's drained from time_offset.

This gives behaviour equivalent to the old tick_length += delta approach
but with exact per-tick accounting of the time_offset actually imparted
to the clock, and no overrun.

Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.8
Link: https://patch.msgid.link/20260621220051.1030462-5-dwmw2@infradead.org
2026-07-10 09:20:54 +02:00
David WoodhouseandThomas Gleixner 869a55e662 timekeeping: Account for clocksource tick quantisation via NTP
cycle_interval is an integer number of counter cycles per NTP interval,
so the real time it represents differs from the nominal
NTP_INTERVAL_LENGTH by up to half a counter period. For coarse
clocksources this is significant: the 3.579545 MHz ACPI PM timer at
HZ=1000 rounds 3579.545 cycles up to 3580, making each tick 1.000127 ms
(+127 PPM).

Commit a386b5af8e ("time: Compensate for rounding on odd-frequency
clocksources") introduced xtime_remainder to compensate for exactly
this, citing the same 127 PPM ACPI PM example. The compensation is
correct and necessary, but it was applied inside the timekeeping
accumulation in timekeeping.c: subtracted in the mult computation in
timekeeping_adjust() and folded into the ntp_error update in
logarithmic_accumulation(). That keeps the base rate correct and leaves
NTP its full symmetric +/-MAXFREQ range rather than +373/-627 PPM, but
the NTP code in ntp.c never sees it: tick_length is computed without the
correction, so ntp.c's notion of how long a tick is disagrees with the
rate timekeeping actually produces.

Make the offset an explicit part of the NTP tick_length instead. Add
ntp_data::cs_tick_adj, a fixed per-second addend that
ntp_update_frequency() includes alongside ntp_tick_adj and time_freq.
tk_setup_internals() computes it from the difference between the real
cycle_interval duration and the nominal interval, stores it in the
timekeeper, and hands it to NTP through a new argument to ntp_clear() --
which already recomputes the frequency and is invoked after every
clocksource (re)configuration. timekeeping_init() now uses TK_UPDATE_ALL
for this; clearing NTP there is otherwise redundant since ntp_init() has
just initialised it.

ntp.c now computes the true tick rate, giving a single source of truth.
Like ntp_tick_adj, cs_tick_adj stays internal to the kernel: userspace
still sees the nominal 1.000000 ms tick via adjtimex and is unaware of
the addends. timekeeping_adjust() and logarithmic_accumulation() use
ntp_tick / xtime_interval directly, and xtime_remainder is removed.

The base-rate arithmetic is unchanged: ntp_tick becomes
xtime_interval << ntp_error_shift, so the mult division yields the same
base mult and the ntp_error accumulation still nets to zero per tick.

Beyond the cleanup of treating all the tick_length contributions
(nominal interval, ntp_tick_adj, cs_tick_adj, time_freq) consistently
as addends in one place, it also prepares for feed-forward discipline:
a future timekeeping_set_reference() will set tick_length to track an
absolute external reference such as a vmclock, and that path needs
ntp.c to own a tick_length that already reflects the clocksource
quantisation, with no hidden correction applied elsewhere.

Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.8
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260621220051.1030462-4-dwmw2@infradead.org
2026-07-10 09:20:54 +02:00
Mete DurluandVasily Gorbik 2bfc9e417a tick: Remove arch_needs_cpu
Remove unused arch_needs_cpu() hook. No architectures use it after
s390 removed its use case.

Suggested-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Mete Durlu <meted@linux.ibm.com>
Reviewed-by: Heiko Carstens <hca@linux.ibm.com>
Reviewed-by: Thomas Gleixner <tglx@kernel.org>
Acked-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
2026-07-08 17:03:28 +02:00
Joel Granados 38f8bf3859 sysctl: Rename proc_doulongvec_minmax_conv to proc_doulongvec_conv
Remove "_minmax" from proc_doulongvec_minmax_conv as it does not enforce
min/max limits but serves as a generic converter for unsigned long
vectors. Update function declaration in sysctl.h, definition in
sysctl.c, and caller in jiffies.c accordingly.

Signed-off-by: Joel Granados <joel.granados@kernel.org>
2026-07-08 13:12:30 +02:00
Joel Granados a3c70a5a9f sysctl: Generate do_proc_doulongvec_minmax with do_proc_dotypevec macro
The existing do_proc_doulongvec_minmax conversions (based on conv{mul,div})
are replaced with a call to a converter callback that is passed by the
caller.

Replace the values (HZ, 1000l) passed to proc_doulongvec_minmax_conv in
jiffies.c with a new callback containing millisecond to jiffie
conversion (do_proc_ulong_conv_ms_jiffies). This effectively changes the
simple calculation based on HZ and 1000l to a more robust conversion
based on  {_,}_msecs_to_jiffies.

Change specifics
================
* sysctl.h API
 - Implement new ulong uni & bi-directional converters (proc_ulong_*);
   export them so they can be used in proc_doulongvec_ms_jiffies_minmax
   (jiffies.c).
 - Replace two arguments (conv{mul,div}) in proc_doulongvec_minmax_conv
   with a general converter callback function that will be forwarded to
   do_proc_doulongvec.

* do_proc_doulongvec
 - Replace the hardcoded uni-directional converters with a call to the
   call back converter function
 - Generate do_proc_doulongvec with do_proc_dotypevec macro
 - Rename do_proc_doulongvec_minmax to do_proc_doulongvec

* jiffies
 - Create uni and bi-directional converters for milliseconds to jiffies
   (sysctl_{u2k,k2u}_ulong_conv_ms, do_proc_ulong_conv_ms_jiffies)
 - Pass the new bi-directional converter to proc_doulongvec_minmax_conv.

Signed-off-by: Joel Granados <joel.granados@kernel.org>
2026-07-08 13:12:29 +02:00
David WoodhouseandThomas Gleixner b7befd6d91 timekeeping: Account for monotonicity adjustment in ntp_error
timekeeping_apply_adjustment() modifies xtime_nsec to ensure monotonicity
when mult changes:

    xtime_nsec -= offset

This ensures that the time reported to userspace does not jump when the
multiplier is adjusted from one tick to the next. However, the ntp_error
accumulator which tracks the difference between intended and actual
clock position was not being updated to reflect this additional
discrepancy.

An earlier attempt at this compensation existed as:

    ntp_error -= (interval - offset) << ntp_error_shift

but was removed in commit c2cda2a5bd ("timekeeping/ntp: Don't align
NTP frequency adjustments to ticks") because it was a major source of
NTP error. That's because (interval - offset) was wrong: the subtraction
of "interval" prematurely accounted for the changed xtime_interval of
the next tick, which would be correctly accounted in the next
accumulation anyway — a double subtraction.

What is actually needed is just the "offset" part: ntp_error must be
told that xtime_nsec moved by "offset" without a corresponding change
in the intended position. For the normal ±1 mult dithering this is
negligible (the adjustments cancel over time), but for larger mult
changes — such as when an external reference clock sets a new
frequency — the one-time uncompensated offset is significant.

Fix by adjusting ntp_error by the correct amount:

    ntp_error += offset << ntp_error_shift

This keeps ntp_error consistent with the actual xtime_nsec position
after the adjustment, and ensures the discrepancy is correctly smoothed
away over time and the clock returns to where it should have been.

Fixes: c2cda2a5bd ("timekeeping/ntp: Don't align NTP frequency adjustments to ticks")
Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.6-1m
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260621220051.1030462-3-dwmw2@infradead.org
2026-07-08 00:17:26 +02:00
Thomas WeißschuhandThomas Gleixner dce21fb3d5 time: Respect COMPAT_32BIT_TIME for old time type functions
The "old" time types use 32-bit seconds which are not y2038-safe.
Respect COMPAT_32BIT_TIME for functions using those types.
time(), stime() and gettimeofday() are disabled completely.

settimeofday() is kept as it is required to do the initial timewarping
after boot. However the 'tv' argument will be rejected.

Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Link: https://lore.kernel.org/lkml/e9487ebe-3730-438a-9c23-e45f75986ecc@app.fastmail.com/
Link: https://patch.msgid.link/20260702-vdso-compat_32bit_time-v3-1-db9f36d8d432@linutronix.de
2026-07-07 23:52:53 +02:00
Thomas WeißschuhandThomas Gleixner 9ab500d47f vdso/datastore: Explicitly prevent remote access to timens vvar page
The fault handler for the timens page does not have access to the target
task and therefore can not be invoked remotely.
Currently the handler relies on the fact that the vvar mapping is marked as
VM_IO and VM_PFNMAP for which the mm core always prevents remote access.
However the VM_IO and VM_PFNMAP flags are going to be removed.

Add an explicit check to prevent remote access to the mapping.

Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Nam Cao <namcao@linutronix.de>
Link: https://patch.msgid.link/20260630-vdso-mlockall-v4-4-6c93708ce723@linutronix.de
2026-07-07 23:52:52 +02:00
Thomas WeißschuhandThomas Gleixner 79bd39c58f timekeeping: Move the vDSO update declarations into a private header
All architectures are now fully using the generic vDSO infrastructure.
They don't need these declarations anymore to implement the functions
in architecture-specific code.

Move them to the private header.

Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260707-timekeeping-header-cleanup-v1-2-e85ad96409a9@linutronix.de
2026-07-07 23:48:08 +02:00
Thomas Weißschuh (Schneider Electric)andThomas Gleixner 95cf8bbadd hrtimer: Explicitly include linux/hrtimer_bases.h
This header uses some definitions from linux/hrtimer_bases.h.
Currently this header is included transitively, which will change.

Include the header explicitly.

Signed-off-by: Thomas Weißschuh (Schneider Electric) <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260702-hrtimer-header-dependencies-v1-5-c50b19bda473@linutronix.de
2026-07-07 23:43:44 +02:00
Thomas Weißschuh (Schneider Electric)andThomas Gleixner 73fcec09d1 tick: Explicitly include linux/hrtimer_bases.h
This header uses some definitions from linux/hrtimer_bases.h.
Currently this header is included transitively, which will change.

Include the header explicitly.

Signed-off-by: Thomas Weißschuh (Schneider Electric) <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260702-hrtimer-header-dependencies-v1-4-c50b19bda473@linutronix.de
2026-07-07 23:43:44 +02:00