Commit dad0a87d79ff for kernel

commit dad0a87d79ff3e7e4ef35ebd588fe4f115329964
Merge: 981f4a2baaf1 5b602344a49e
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Fri Jul 24 13:22:41 2026 -0700

    Merge tag 'ceph-for-7.2-rc5' of https://github.com/ceph/ceph-client

    Pull ceph fixes from Ilya Dryomov:
     "A bunch of assorted fixes with the majority being hardening against
      malformed input and invalid data scenarios that don't happen in real
      deployments but can be utilized to trigger use-after-free and similar
      issues, some error path leak fixups and two patches from Max to avoid
      a potential hang in __ceph_get_caps() and unintended nesting of
      current->journal_info while handling replies from the MDS.

      All marked for stable"

    * tag 'ceph-for-7.2-rc5' of https://github.com/ceph/ceph-client:
      ceph: avoid fs reclaim while using current->journal_info
      ceph: add owner/capability checks for CEPH_IOC_SET_LAYOUT*
      ceph: fix hanging __ceph_get_caps() with stale mds_wanted
      rbd: Reset positive result codes to zero in object map update path
      libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
      libceph: refresh auth->authorizer_buf{,_len} after authorizer update
      ceph: fix refcount leak in ceph_readdir()
      libceph: guard missing CRUSH type name lookup
      libceph: remove debugfs files before client teardown
      libceph: bound get_version reply decode to front len
      ceph: fix writeback_count leak in write_folio_nounlock()
      libceph: fix two unsafe bare decodes in decode_lockers()
      ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
      libceph: Reject monmaps advertising zero monitors
      libceph: reject zero bucket types in crush_decode
      libceph: Fix multiplication overflow in decode_new_up_state_weight()