Commit 548e7bcd0c54 for kernel

commit 548e7bcd0c5460ddcbca9600cea603ebeebf4da7
Merge: ce727a090be0 8fdf94644573
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Fri Aug 28 11:51:05 2026 -0700

    Merge tag 'ceph-for-7.3-rc1' of https://github.com/ceph/ceph-client

    Pull ceph updates from Ilya Dryomov:
     "A wide variety of mostly CephFS fixes and cleanups, split between
      changes that address edge cases (Sam, Xiubo, Matthew), efficiency
      improvements (Max) and AI-assisted hardening (Michael, Jeremy).

      One thing that stands out is Alex's change to how CephFS behaves in
      NEARFULL scenarios: the long-standing "make all writes synchronous"
      behavior has become opt-in. It was always somewhat controversial and
      doesn't make much sense for modern deployments; the new default is to
      continue normal operation (i.e. buffer writes as MDS allows, etc). The
      behavior in case the cluster reaches any FULL state remains the same
      as before"

    * tag 'ceph-for-7.3-rc1' of https://github.com/ceph/ceph-client: (32 commits)
      ceph: force a cap message when a deferred revoke can't be acked immediately
      libceph: reject buckets with mismatched CRUSH ids
      ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
      ceph: fix leaked inode reference on writeback abort at umount
      libceph: remove ceph_put_page_vector()
      libceph: validate banner payload length
      ceph: make nearfull sync writes opt-in
      ceph: do not repeat ceph_trim_dentries() if no progress possible
      ceph: drop mdsc->mutex before decoding the MDS reply
      ceph: fix UAF in check_new_map() on session freed during unlock
      ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
      ceph: pass inode pointer around instead of reloading it
      ceph: mark cap remove with RB_CLEAR_NODE() instead of setting ci=NULL
      ceph: add helper function ceph_cap_is_removed()
      ceph: make __ceph_remove_cap() static
      ceph: cap delegated inode count in ceph_parse_deleg_inos()
      ceph: bound num_export_targets array for mds info v2/v3
      ceph: bound MDSCapAuth path and fs_name decode in handle_session()
      ceph: bound xattr value length in __build_xattrs()
      ceph: bound copied dentry name length in NFS export get_name
      ...