Commit 3f1fe48a36b0 for kernel

commit 3f1fe48a36b0b6722dc3fd421d93512bac138e9a
Merge: 5d144c294ae2 a92193c91e88
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Fri Oct 2 12:17:24 2026 -0700

    Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux

    Pull io_uring fixes from Jens Axboe:

     - Fix a task_work add use-after-free with SQPOLL.

       The sqpoll thread could pop and complete the last request while
       io_req_normal_work_add() was still looking at them after the mpscq
       push.

       Use the same approach as DEFER_TASKRUN to protect from that, holding
       an RCU read lock across the add, and have exit wait for an RCU grace
       period for SQPOLL rings as well.

     - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
       big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
       rings

     - Mark the source filter table as COW when cloning bpf filters, so
       registering another filter on the source doesn't modify the shared
       table in place

     - Initialize the task context before running the BPF loop

     - Requeue zcrx multishot receives stopped by a local resource

     - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit)

    * tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
      io_uring: fix task_work add use-after-free with SQPOLL
      io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full
      io_uring/zcrx: requeue multishot receives stopped by a local resource
      io_uring: initialize task context before running the BPF loop
      io_uring: zero big_cqe for aux CQEs on CQE32 rings
      io_uring: fix free entry check for 32b CQEs on CQE32 rings
      io_uring: only post the dummy skip CQE on CQE_MIXED rings
      io_uring/bpf_filter: mark source as COW when cloning filters