mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Christian Brauner <brauner@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Christian Brauner <brauner@kernel.org>,
	linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [GIT PULL for v7.2] vfs fixes
Date: Sun, 26 Jul 2026 17:37:10 +0200	[thread overview]
Message-ID: <20260726-vfs-7.2-rc5.fixes-40ccd95afb90@brauner> (raw)

Hey Linus,

A bit later than intended today so no problem if we need to push this
past -rc5.

/* Summary */

This contains fixes for the current development cycle:

- vfs: Preserve the ACL_DONT_CACHE state in forget_cached_acl().
  ACL_DONT_CACHE is meant to be a permanent opt-out from ACL caching
  which FUSE relies on for servers that don't negotiate FUSE_POSIX_ACL.
  The helper replaced it with ACL_NOT_CACHED, silently re-enabling the
  cache, and as fuse doesn't invalidate the cache for such servers a
  properly timed get_acl() returned stale ACLs. Comes with a fuse
  selftest reproducing this.

- pidfs:

  * Preserve PIDFD_THREAD when a thread pidfd is reopened via
    open_by_handle_at(). PIDFD_THREAD shares the O_EXCL bit which
    do_dentry_open() strips after the flags have been validated, so the
    reopened pidfd silently became a process pidfd. Comes with a
    selftest.

  * Add a pidfs_dentry_open() helper so the regular pidfd allocation
    path and the file handle path share the code that forces O_RDWR and
    reapplies the pidfd flags that do_dentry_open() strips.

  * Handle FS_IOC32_GETVERSION in the compat ioctl path.

  * Make pidfs_ino_lock static.

- iomap:

  * Fix the block range calculation in ifs_clear_range_dirty() so a
    partial clear doesn't drop the dirty state of blocks the range only
    partially covers.

  * Support invalidating partial folios so a partial truncate or hole
    punch with blocksize < foliosize doesn't leave stale dirty bits
    behind.

  * Only set did_zero when iomap_zero_iter() actually zeroed something.

  * Guard ifs_set_range_dirty() and ifs_set_range_uptodate() against
    zero-length ranges where the unsigned last-block calculation
    underflows and bitmap_set() writes far beyond the ifs->state
    allocation.

  * Don't merge ioends with different io_private values as the merge
    could leak or corrupt the private data of the individual ioends.

- exec:

  * Raise bprm->have_execfd only once the binfmt_misc interpreter has
    actually been opened. The flag was set as soon as a matching 'O' or
    'C' entry was found. If the interpreter open failed with ENOEXEC
    the exec fell through to the next binary format with have_execfd
    raised but no executable staged and begin_new_exec() NULL derefed
    past the point of no return.

  * Fix an unsigned loop counter wrap in transfer_args_to_stack() on
    nommu. An overlong argument or environment string pushes bprm->p
    below PAGE_SIZE, the stop index becomes zero, and the loop never
    terminates, wrapping its counter and copying garbage from in front
    of the page array into the new process stack.

  * Make binfmt_elf_fdpic only honour the first PT_INTERP like
    binfmt_elf does. Each additional PT_INTERP overwrote the previous
    interpreter, leaking the name allocation and the interpreter file
    reference together with the write denial open_exec() took, leaving
    the file unwritable for as long as the system runs.

- overlayfs:

  * Compare the full escaped xattr prefix including the trailing dot.
    An xattr like "trusted.overlay.overlayfoo" was misclassified as an
    escaped overlay xattr.

  * Check read access to the copy_file_range() source with the source's
    mounter credentials.

- super: Thawing a filesystem whose block device was frozen with
  bdev_freeze() deadlocked. Dropping the last block layer freeze
  reference from under s_umount ends up in fs_bdev_thaw() which
  reacquires s_umount on the same task. Pin the superblock with an
  active reference instead and call bdev_thaw() without holding
  s_umount.

- procfs: Return EACCES instead of success when the ptrace access check
  for namespace links fails.

- afs: Use afs_dir_get_block() rather than afs_dir_find_block() for
  block 0 in afs_edit_dir_remove(), matching afs_edit_dir_add().

- Push the memcg gating of ->nr_cached_objects() down into the btrfs
  and shmem callbacks instead of skipping every callback during
  non-root memcg reclaim. The blanket check short-circuited XFS whose
  inode reclaim hook is intentionally driven from per-memcg contexts to
  free memcg-charged slab.

- eventpoll: Pin files while checking reverse paths. Since struct file
  became SLAB_TYPESAFE_BY_RCU a concurrent close could free and recycle
  the file under the check which then took and dropped the f_lock of
  whatever live file now occupies that slot.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit 1590cf0329716306e948a8fc29f1d3ee87d3989f:

  Linux 7.2-rc4 (2026-07-19 13:54:41 -0700)

are available in the Git repository at:

  git@gitolite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc5.fixes

for you to fetch changes up to 749d7aa0377aae32af8c0a4ad43371e7bf830ab5:

  super: fix emergency thaw deadlock on frozen block devices (2026-07-26 17:08:52 +0200)

----------------------------------------------------------------
vfs-7.2-rc5.fixes

Please consider pulling these changes from the signed vfs-7.2-rc5.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Amir Goldstein (3):
      fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
      selftests/fuse: add ACL_DONT_CACHE regression test
      ovl: check access to copy_file_range source with src mounter creds

Chen Changcheng (1):
      fs/super: fix emergency thaw double-unlock of s_umount

Christian Brauner (10):
      binfmt_misc: set have_execfd only once the interpreter is opened
      exec: fix unsigned loop counter wrap in transfer_args_to_stack()
      binfmt_elf_fdpic: only honour the first PT_INTERP
      Merge patch series "Fix for unintended FUSE ACL cache"
      pidfs: preserve thread pidfds reopened by file handle
      selftests/pidfd: check PIDFD_THREAD survives open_by_handle_at()
      Merge patch series "pidfs: preserve thread pidfds reopened by file handle"
      pidfs: add pidfs_dentry_open() helper
      Merge patch series "iomap: trivial fixes for ext4 conversion"
      super: fix emergency thaw deadlock on frozen block devices

David Howells (1):
      afs: Fix afs_edit_dir_remove() to get, not find, block 0

Guidong Han (1):
      eventpoll: pin files while checking reverse paths

Jann Horn (1):
      proc: Fix broken error paths for namespace links

Li Chen (1):
      pidfs: handle FS_IOC32_GETVERSION in compat ioctl

Mateusz Guzik (1):
      pidfs: make pidfs_ino_lock static

Usama Arif (1):
      fs: push nr_cached_objects memcg gating into individual filesystems

Yichong Chen (1):
      ovl: fix trusted xattr escape prefix matching

Zhang Yi (6):
      iomap: correct the range of a partial dirty clear
      iomap: support invalidating partial folios
      iomap: fix incorrect did_zero setting in iomap_zero_iter()
      iomap: fix out-of-bounds bitmap_set() with zero-length range
      iomap: add comments for ifs_clear/set_range_dirty()
      iomap: prevent ioend merge when io_private differs

 fs/afs/dir_edit.c                                  |   2 +-
 fs/binfmt_elf_fdpic.c                              |   4 +
 fs/binfmt_misc.c                                   |   5 +-
 fs/btrfs/super.c                                   |  10 +
 fs/eventpoll.c                                     |  18 +-
 fs/exec.c                                          |   2 +-
 fs/iomap/buffered-io.c                             |  58 +++-
 fs/iomap/ioend.c                                   |   2 +
 fs/overlayfs/file.c                                |  16 +-
 fs/overlayfs/xattrs.c                              |   2 +-
 fs/pidfs.c                                         |  54 +++-
 fs/posix_acl.c                                     |   7 +
 fs/proc/namespaces.c                               |   4 +-
 fs/super.c                                         |  34 +-
 include/linux/memcontrol.h                         |  21 ++
 mm/shmem.c                                         |  10 +
 tools/testing/selftests/filesystems/fuse/Makefile  |  10 +
 .../filesystems/fuse/fuse_acl_cache_test.c         | 347 +++++++++++++++++++++
 .../selftests/pidfd/pidfd_file_handle_test.c       |   1 +
 19 files changed, 553 insertions(+), 54 deletions(-)
 create mode 100644 tools/testing/selftests/filesystems/fuse/fuse_acl_cache_test.c

             reply	other threads:[~2026-07-26 15:37 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26 15:37 Christian Brauner [this message]
2026-07-26 19:59 ` pr-tracker-bot
  -- strict thread matches above, loose matches on Subject: below --
2026-08-14 13:05 Christian Brauner
2026-08-14 15:59 ` pr-tracker-bot
2026-08-02  9:31 Christian Brauner
2026-08-02 17:51 ` pr-tracker-bot
2026-07-03 11:32 Christian Brauner
2026-07-03 15:55 ` pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260726-vfs-7.2-rc5.fixes-40ccd95afb90@brauner \
    --to=brauner@kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®