mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [GIT PULL for v7.2] vfs fixes
@ 2026-07-26 15:37 Christian Brauner
  2026-07-26 19:59 ` pr-tracker-bot
  0 siblings, 1 reply; 8+ messages in thread
From: Christian Brauner @ 2026-07-26 15:37 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Christian Brauner, linux-fsdevel, linux-kernel

Hey Linus,

A bit later than intended today so no problem if we need to push this
past -rc5.

/* Summary */

This contains fixes for the current development cycle:

- vfs: Preserve the ACL_DONT_CACHE state in forget_cached_acl().
  ACL_DONT_CACHE is meant to be a permanent opt-out from ACL caching
  which FUSE relies on for servers that don't negotiate FUSE_POSIX_ACL.
  The helper replaced it with ACL_NOT_CACHED, silently re-enabling the
  cache, and as fuse doesn't invalidate the cache for such servers a
  properly timed get_acl() returned stale ACLs. Comes with a fuse
  selftest reproducing this.

- pidfs:

  * Preserve PIDFD_THREAD when a thread pidfd is reopened via
    open_by_handle_at(). PIDFD_THREAD shares the O_EXCL bit which
    do_dentry_open() strips after the flags have been validated, so the
    reopened pidfd silently became a process pidfd. Comes with a
    selftest.

  * Add a pidfs_dentry_open() helper so the regular pidfd allocation
    path and the file handle path share the code that forces O_RDWR and
    reapplies the pidfd flags that do_dentry_open() strips.

  * Handle FS_IOC32_GETVERSION in the compat ioctl path.

  * Make pidfs_ino_lock static.

- iomap:

  * Fix the block range calculation in ifs_clear_range_dirty() so a
    partial clear doesn't drop the dirty state of blocks the range only
    partially covers.

  * Support invalidating partial folios so a partial truncate or hole
    punch with blocksize < foliosize doesn't leave stale dirty bits
    behind.

  * Only set did_zero when iomap_zero_iter() actually zeroed something.

  * Guard ifs_set_range_dirty() and ifs_set_range_uptodate() against
    zero-length ranges where the unsigned last-block calculation
    underflows and bitmap_set() writes far beyond the ifs->state
    allocation.

  * Don't merge ioends with different io_private values as the merge
    could leak or corrupt the private data of the individual ioends.

- exec:

  * Raise bprm->have_execfd only once the binfmt_misc interpreter has
    actually been opened. The flag was set as soon as a matching 'O' or
    'C' entry was found. If the interpreter open failed with ENOEXEC
    the exec fell through to the next binary format with have_execfd
    raised but no executable staged and begin_new_exec() NULL derefed
    past the point of no return.

  * Fix an unsigned loop counter wrap in transfer_args_to_stack() on
    nommu. An overlong argument or environment string pushes bprm->p
    below PAGE_SIZE, the stop index becomes zero, and the loop never
    terminates, wrapping its counter and copying garbage from in front
    of the page array into the new process stack.

  * Make binfmt_elf_fdpic only honour the first PT_INTERP like
    binfmt_elf does. Each additional PT_INTERP overwrote the previous
    interpreter, leaking the name allocation and the interpreter file
    reference together with the write denial open_exec() took, leaving
    the file unwritable for as long as the system runs.

- overlayfs:

  * Compare the full escaped xattr prefix including the trailing dot.
    An xattr like "trusted.overlay.overlayfoo" was misclassified as an
    escaped overlay xattr.

  * Check read access to the copy_file_range() source with the source's
    mounter credentials.

- super: Thawing a filesystem whose block device was frozen with
  bdev_freeze() deadlocked. Dropping the last block layer freeze
  reference from under s_umount ends up in fs_bdev_thaw() which
  reacquires s_umount on the same task. Pin the superblock with an
  active reference instead and call bdev_thaw() without holding
  s_umount.

- procfs: Return EACCES instead of success when the ptrace access check
  for namespace links fails.

- afs: Use afs_dir_get_block() rather than afs_dir_find_block() for
  block 0 in afs_edit_dir_remove(), matching afs_edit_dir_add().

- Push the memcg gating of ->nr_cached_objects() down into the btrfs
  and shmem callbacks instead of skipping every callback during
  non-root memcg reclaim. The blanket check short-circuited XFS whose
  inode reclaim hook is intentionally driven from per-memcg contexts to
  free memcg-charged slab.

- eventpoll: Pin files while checking reverse paths. Since struct file
  became SLAB_TYPESAFE_BY_RCU a concurrent close could free and recycle
  the file under the check which then took and dropped the f_lock of
  whatever live file now occupies that slot.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit 1590cf0329716306e948a8fc29f1d3ee87d3989f:

  Linux 7.2-rc4 (2026-07-19 13:54:41 -0700)

are available in the Git repository at:

  git@gitolite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc5.fixes

for you to fetch changes up to 749d7aa0377aae32af8c0a4ad43371e7bf830ab5:

  super: fix emergency thaw deadlock on frozen block devices (2026-07-26 17:08:52 +0200)

----------------------------------------------------------------
vfs-7.2-rc5.fixes

Please consider pulling these changes from the signed vfs-7.2-rc5.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Amir Goldstein (3):
      fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
      selftests/fuse: add ACL_DONT_CACHE regression test
      ovl: check access to copy_file_range source with src mounter creds

Chen Changcheng (1):
      fs/super: fix emergency thaw double-unlock of s_umount

Christian Brauner (10):
      binfmt_misc: set have_execfd only once the interpreter is opened
      exec: fix unsigned loop counter wrap in transfer_args_to_stack()
      binfmt_elf_fdpic: only honour the first PT_INTERP
      Merge patch series "Fix for unintended FUSE ACL cache"
      pidfs: preserve thread pidfds reopened by file handle
      selftests/pidfd: check PIDFD_THREAD survives open_by_handle_at()
      Merge patch series "pidfs: preserve thread pidfds reopened by file handle"
      pidfs: add pidfs_dentry_open() helper
      Merge patch series "iomap: trivial fixes for ext4 conversion"
      super: fix emergency thaw deadlock on frozen block devices

David Howells (1):
      afs: Fix afs_edit_dir_remove() to get, not find, block 0

Guidong Han (1):
      eventpoll: pin files while checking reverse paths

Jann Horn (1):
      proc: Fix broken error paths for namespace links

Li Chen (1):
      pidfs: handle FS_IOC32_GETVERSION in compat ioctl

Mateusz Guzik (1):
      pidfs: make pidfs_ino_lock static

Usama Arif (1):
      fs: push nr_cached_objects memcg gating into individual filesystems

Yichong Chen (1):
      ovl: fix trusted xattr escape prefix matching

Zhang Yi (6):
      iomap: correct the range of a partial dirty clear
      iomap: support invalidating partial folios
      iomap: fix incorrect did_zero setting in iomap_zero_iter()
      iomap: fix out-of-bounds bitmap_set() with zero-length range
      iomap: add comments for ifs_clear/set_range_dirty()
      iomap: prevent ioend merge when io_private differs

 fs/afs/dir_edit.c                                  |   2 +-
 fs/binfmt_elf_fdpic.c                              |   4 +
 fs/binfmt_misc.c                                   |   5 +-
 fs/btrfs/super.c                                   |  10 +
 fs/eventpoll.c                                     |  18 +-
 fs/exec.c                                          |   2 +-
 fs/iomap/buffered-io.c                             |  58 +++-
 fs/iomap/ioend.c                                   |   2 +
 fs/overlayfs/file.c                                |  16 +-
 fs/overlayfs/xattrs.c                              |   2 +-
 fs/pidfs.c                                         |  54 +++-
 fs/posix_acl.c                                     |   7 +
 fs/proc/namespaces.c                               |   4 +-
 fs/super.c                                         |  34 +-
 include/linux/memcontrol.h                         |  21 ++
 mm/shmem.c                                         |  10 +
 tools/testing/selftests/filesystems/fuse/Makefile  |  10 +
 .../filesystems/fuse/fuse_acl_cache_test.c         | 347 +++++++++++++++++++++
 .../selftests/pidfd/pidfd_file_handle_test.c       |   1 +
 19 files changed, 553 insertions(+), 54 deletions(-)
 create mode 100644 tools/testing/selftests/filesystems/fuse/fuse_acl_cache_test.c

^ permalink raw reply	[flat|nested] 8+ messages in thread
* [GIT PULL for v7.2] vfs fixes
@ 2026-08-14 13:05 Christian Brauner
  2026-08-14 15:59 ` pr-tracker-bot
  0 siblings, 1 reply; 8+ messages in thread
From: Christian Brauner @ 2026-08-14 13:05 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Christian Brauner, linux-fsdevel, linux-kernel

Hey Linus,

/* Summary */

This contains last fixes for the current development cycle:

- Don't warn when a mount is completed from another user namespace.

  fsopen() records the caller's user namespace in fc->user_ns and hands
  back an ordinary file descriptor. The task that calls
  fsconfig(FSCONFIG_CMD_CREATE) doesn't have to be the one that created
  the context, and mount_capable() lets it through as long as the caller
  has CAP_SYS_ADMIN over fc->user_ns, which anyone in an ancestor
  namespace does. So fc->user_ns != current_user_ns() is something an
  unprivileged user can arrange.

  Both overlayfs and binfmt_misc WARN_ON() that. Overlayfs already
  has the same check as a plain error return in ovl_parse_param(). Drop
  the WARN_ON() and just refuse. Add selftests for both cases.

- Reject pid allocations through dead ancestor pid namespaces.

  Require PIDNS_ADDING in every namespace that will receive the pid
  before publishing any of them. That preserves the invariant that
  free_pid() never decrements pid_allocated in a namespace whose
  child_reaper is no longer live. The existing ENOMEM behavior is
  unchanged.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit db2ddb87143519e20a95aa36c60b36107b736a58:

  Linux 7.2-rc7 (2026-08-09 14:54:50 -0700)

are available in the Git repository at:

  git@gitolite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc8.fixes

for you to fetch changes up to b64a9f67e082e04835ddd69d422a25168d69375b:

  pid: reject allocations through dead ancestor pid namespaces (2026-08-12 12:56:30 +0200)

----------------------------------------------------------------
vfs-7.2-rc8.fixes

Please consider pulling these changes from the signed vfs-7.2-rc8.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Christian Brauner (4):
      ovl: don't warn when the mount is completed from another user namespace
      binfmt_misc: don't warn when the mount is completed from another user namespace
      selftests/filesystems: test completing a context from another user namespace
      Merge patch series "fs: don't warn when a mount is completed from another user namespace"

Jérémy Jean (1):
      pid: reject allocations through dead ancestor pid namespaces

 fs/binfmt_misc.c                                   |   3 +-
 fs/overlayfs/super.c                               |   3 +-
 kernel/pid.c                                       |   6 +-
 tools/testing/selftests/Makefile                   |   1 +
 .../selftests/filesystems/fscontext_ns/Makefile    |  10 +
 .../filesystems/fscontext_ns/fscontext_ns_test.c   | 239 +++++++++++++++++++++
 6 files changed, 258 insertions(+), 4 deletions(-)
 create mode 100644 tools/testing/selftests/filesystems/fscontext_ns/Makefile
 create mode 100644 tools/testing/selftests/filesystems/fscontext_ns/fscontext_ns_test.c

^ permalink raw reply	[flat|nested] 8+ messages in thread
* [GIT PULL for v7.2] vfs fixes
@ 2026-08-02  9:31 Christian Brauner
  2026-08-02 17:51 ` pr-tracker-bot
  0 siblings, 1 reply; 8+ messages in thread
From: Christian Brauner @ 2026-08-02  9:31 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Christian Brauner, linux-fsdevel, linux-kernel

Hey Linus,

/* Summary */

This contains fixes for the current development cycle:

- binfmt_misc:

  * Don't let an 'F' entry pin its own instance. An entry registered
    with 'F' opens its interpreter at registration time and holds that
    file until the entry is freed, so an entry nobody removes by hand
    is only closed once the binfmt_misc superblock is shut down. If the
    interpreter lives on a mount that keeps that superblock alive the
    two pin each other and the file is never closed. That's reachable
    by pointing the interpreter at the instance itself or by using the
    instance as an overlayfs lower layer, and once the mount namespace
    is gone there's nothing left to unregister through either.

  * Restore write access when removing an entry. Registering with the
    MISC_FMT_OPEN_FILE flag opens the interpreter via open_exec() which
    denies write access for as long as the entry exists, but removal
    only did filp_close() and never restored it. The inode's
    i_writecount stayed permanently negative and opening the
    interpreter for writing kept failing with ETXTBSY long after the
    entry was gone.

  * Use exe_file_deny_write_access() for the interpreter clone so both
    sides base their decision on the same mode.

  * Reject a flag character as the field delimiter. create_entry() pads
    the buffer with the delimiter so the field parsers terminate even
    on a truncated string, but check_special_flags() consumes flag
    characters instead of scanning for the delimiter. If the delimiter
    is itself a flag character the padding stops acting as a terminator
    and the scan keeps reading past the end of the allocation. Such a
    registration was always rejected, just only after the out of bounds
    read has already happened.

  * Don't leak the user namespace when the mount fails. bm_get_tree()
    hands its reference to get_tree_keyed() and sget_fc() moves it into
    sb->s_fs_info, but generic_shutdown_super() only calls ->put_super()
    from inside the if (sb->s_root) branch and bm_fill_super() can fail
    before either s_root or s_op is in place. Drop the reference in
    ->kill_sb() instead, which runs unconditionally.

- netfs:

  * Clear PG_private_2 on a copy-to-cache append failure.

  * Handle a rolling buffer allocation failure in single-object
    writeback and drop the extra folio reference
    netfs_write_folio_single() took before the append.

  * Release the batched readahead folios when
    rolling_buffer_load_from_ra() fails in
    netfs_prepare_read_iterator() after earlier folios have already
    been batched.

  * Fix the folio_queue ENOMEM in writeback by adding a mempool and
    passing gfp flags into the rolling buffer helpers.

- iomap:

  * Add a separate bio_set for iomap_split_ioend(). It can split
    bios that already come from iomap_ioend_bioset and deadlock once that
    bioset is exhausted.

- afs:

  * Set call->async for an asynchronous afs_fs_fetch_data() the way
    afs_fs_fetch_data64() already does.

  * Subtract subreq->transferred from subreq->len in afs_fs_fetch_data()
    rather than adding it.

  * Fix a UAF when sending a message.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit 62cc90241548d5570ee68e01aaba6506964e9811:

  Merge tag 'mm-hotfixes-stable-2026-07-27-14-18' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm (2026-07-27 14:36:26 -0700)

are available in the Git repository at:

  git@gitolite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc6.fixes

for you to fetch changes up to c679ce3be6cb63763d68ab9b5d9d73ddc0a40762:

  iomap: add a separate bio_set for iomap_split_ioend (2026-07-31 11:49:09 +0200)

----------------------------------------------------------------
vfs-7.2-rc6.fixes

Please consider pulling these changes from the signed vfs-7.2-rc6.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Christian Brauner (8):
      Merge patch series "afs: Miscellaneous fixes"
      Merge patch series "netfs: Miscellaneous fixes"
      binfmt_misc: don't let an 'F' entry pin its own instance
      Merge patch series "binfmt_misc: don't let an 'F' entry pin its own instance"
      binfmt_misc: restore write access when removing an entry
      binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
      binfmt_misc: reject a flag character as the field delimiter
      binfmt_misc: don't leak the user namespace when the mount fails

Christoph Hellwig (1):
      iomap: add a separate bio_set for iomap_split_ioend

David Howells (4):
      afs: Fix afs_fs_fetch_data() to set call->async
      afs: Fix afs_fs_fetch_data() to subtract transferred from len
      afs: Fix UAF when sending a message
      netfs: Fix folio_queue ENOMEM in writeback by adding a mempool

Yichong Chen (3):
      netfs: clear PG_private_2 on copy-to-cache append failure
      netfs: handle single writeback rolling buffer allocation failure
      netfs: release readahead folios on iterator preparation failure

 fs/afs/fsclient.c              |  5 +++-
 fs/afs/internal.h              |  3 ++-
 fs/binfmt_misc.c               | 54 ++++++++++++++++++++++++++----------------
 fs/iomap/ioend.c               | 21 ++++++++++++++--
 fs/netfs/buffered_read.c       | 10 ++++----
 fs/netfs/internal.h            |  1 +
 fs/netfs/main.c                |  7 ++++++
 fs/netfs/objects.c             | 30 +++++++++++++----------
 fs/netfs/read_pgpriv2.c        |  3 ++-
 fs/netfs/rolling_buffer.c      | 22 ++++++++++-------
 fs/netfs/write_issue.c         | 15 ++++++++----
 include/linux/netfs.h          |  1 +
 include/linux/rolling_buffer.h |  6 ++---
 13 files changed, 119 insertions(+), 59 deletions(-)

^ permalink raw reply	[flat|nested] 8+ messages in thread
* [GIT PULL for v7.2] vfs fixes
@ 2026-07-03 11:32 Christian Brauner
  2026-07-03 15:55 ` pr-tracker-bot
  0 siblings, 1 reply; 8+ messages in thread
From: Christian Brauner @ 2026-07-03 11:32 UTC (permalink / raw)
  To: Linus Torvalds; +Cc: Christian Brauner, linux-fsdevel, linux-kernel

Hey Linus,

/* Summary */

This contains fixes for the current development cycle:

- netfs:

  * the decision when to disallow write-streaming with fscache in use,
    handling of asynchronous cache object creation, a double fput in
    cachefiles, clearing S_KERNEL_FILE without the inode lock held, page
    extraction bugs in the iov_iter helpers (a potential underflow, a
    missing allocation failure check, a memory leak, and a folio offset
    miscalculation), writeback error and ENOMEM handling, DIO write
    retry for filesystems without a ->prepare_write() method, and the
    replacement of the wb_lock mutex with a bit lock plus writethrough
    collection offload so that multiple asynchronous writebacks don't
    interfere with each other.

  * Fix the barriering when walking the netfs subrequest list during
    retries as it was possible to see a subrequest that was just added
    by the application thread.

- iomap:

  * Change iomap to submit read bios after each extent instead of
    building them up across extents. The old behavior was considered
    problematic for a while and now caused an actual erofs bug.

  * Guard the ioend io_size EOF trim in iomap against underflow
    when a concurrent truncate moves EOF below the start of the ioend,
    wrapping io_size to a huge value.

- overlayfs

  * Fix a stale overlayfs comment about the locking order.

  * Store the linked-in upper dentry instead of the disconnected
    O_TMPFILE dentry during overlayfs tmpfile copy-up. With a FUSE or
    virtiofs upper layer ->d_revalidate() would try to look up "/" in
    the workdir and fail, causing persistent ESTALE errors that broke
    dpkg and apt.

- vfs-bpf: Have the bpf_real_data_inode() kfunc take a struct file
  instead of a dentry so it is usable from the bprm_check_security,
  mmap_file, and file_mprotect hooks, and rename it from
  bpf_real_inode() to make the data-inode semantics explicit. The kfunc
  landed this cycle so the change is safe.

- afs: NULL pointer dereferences in the callback
  service and in afs_get_tree(), several memory and refcount leaks,
  missing locking around the dynamic root inode numbers and premature
  cell exposure through /afs, a netns destruction hang caused by a
  misplaced increment of net->cells_outstanding, a bulk lookup
  malfunction caused by the dir_emit() API change, inode
  (re)initialisation issues, and assorted smaller fixes to error codes,
  seqlock handling, and debug output.

- vfs: Refuse O_TMPFILE creation with an unmapped fsuid or fsgid and add
  a selftest for it.

- Add Jori Koolstra as vboxsf maintainer, taking over from Hans de
  Goede.

- Release the pages attached to a short atomic dio bio; the REQ_ATOMIC
  size check error path leaked them.

- procfs: Only bump the parent directory link count when registering
  directories in procfs. Registering regular files inflated the count
  and leaked a link on every create and remove cycle.

- minix: Avoid an unsigned overflow in the minix bitmap block count
  calculation that let crafted images with huge inode or zone counts
  pass superblock validation and crash the kernel during mount.

- cachefiles: Fix a double unlock in the cachefiles nomem_d_alloc error path
  left over from the start_creating() conversion.

- fat: Stop fat from reading directory entries past the 0x00
  end-of-directory marker. If the trailing on-disk slots aren't
  zero-filled the driver surfaced arbitrary garbage as directory
  entries.

- freexvfs: Don't BUG() on unknown typed-extent types in freevxfs, reachable
  via ioctl(FIBMAP) on a crafted image; fail with an I/O error instead.

- orangefs: Keep the readdir entry size 64-bit in orangefs fill_from_part().
  Truncating it to __u32 bypassed the bounds check and led to out-of-bounds
  reads triggerable by the userspace client.

- xfs: Fix the error unwind in xfs_open_devices() which released the rt
  device file twice and left dangling buftarg pointers behind that were
  freed again when the failed mount was torn down.

- exec: Fix an off-by-one in the comment documenting the maximum binfmt
  rewrite depth in exec_binprm(). The code allows five rewrites, not
  four; restricting the code would break userspace so the comment is
  fixed instead.

- file handles: Reject detached mounts in capable_wrt_mount(). A
  detached mount can be dissolved concurrently, leaving a NULL mount
  namespace that open_by_handle_at() would dereference.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit 665159e246749578d4e4bfe106ee3b74edcdab18:

  Merge tag 'probes-fixes-v7.2-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace (2026-06-30 17:50:44 -1000)

are available in the Git repository at:

  git@gitolite.kernel.org:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc2.fixes

for you to fetch changes up to 5c6ce05e406520290c1d89da97fb3cd70c09137d:

  netfs: Fix barriering when walking subrequest list (2026-07-03 11:52:41 +0200)

----------------------------------------------------------------
vfs-7.2-rc2.fixes

Please consider pulling these changes from the signed vfs-7.2-rc2.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Alan Urmancheev (1):
      exec: fix off-by-one in binfmt max rewrite depth comment

Amir Goldstein (1):
      ovl: fix comment about locking order

Bryam Vargas (1):
      orangefs: keep the readdir entry size 64-bit in fill_from_part()

Christian Brauner (8):
      fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
      selftests/filesystems: test O_TMPFILE creation on idmapped mounts
      Merge patch series "fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid"
      Merge patch series "afs: Miscellaneous fixes"
      bpf: have bpf_real_data_inode() take a struct file
      xfs: fix the error unwind in xfs_open_devices()
      Merge patch series "netfs: Miscellaneous fixes"
      Merge patch series "iomap: consolidate bio submission"

Christoph Hellwig (2):
      iomap: consolidate bio submission
      iomap: submit read bio after each extent

Dan Carpenter (1):
      afs: Fix error code in afs_extract_vl_addrs()

David Howells (31):
      afs: Fix double netfs initialisation in afs_root_iget()
      afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
      afs: Fix directory inode initialisation order
      afs: Fix bulk lookup malfunction due to change in dir_emit() API
      afs: Fix misplaced inc of net->cells_outstanding
      afs: Fix reinitialisation of the inode, in particular ->lock_work
      afs: Fix callback service message parsers to pass through -EAGAIN
      afs: Use scoped_seqlock_read() rather than manually doing seqlock stuff
      afs: Fix missing NULL pointer check in afs_break_some_callbacks()
      afs: Fix leak of ungot volume
      afs: Fix vllist leak
      afs: Fix lack of locking around modifications of net->cells_dyn_ino
      afs: Fix premature cell exposure through /afs
      afs: Fix the volume AFS_VOLUME_RM_TREE is set on
      afs: Fix unchecked-length string display in debug statement
      netfs: Fix decision whether to disallow write-streaming due to fscache use
      netfs: Fix netfs_create_write_req() to handle async cache object creation
      cachefiles: Fix double fput
      cachefiles: Fix file burial to take lock when unsetting S_KERNEL_FILE
      iov_iter: Fix potential underflow in iov_iter_extract_xarray_pages()
      iov_iter: Fix missing alloc fail check in iov_iter_extract_bvec_pages()
      iov_iter: Fix a memory leak in iov_iter_extract_user_pages()
      iov_iter: Remove unused variable in kunit_iov_iter.c
      scatterlist: Fix offset in folio calc in extract_xarray_to_sg()
      netfs: Fix kdoc warning
      netfs: Replace wb_lock with a bit lock for asynchronicity
      netfs: Fix writethrough to use collection offload
      netfs: Fix writeback error handling
      netfs: Fix folio state after ENOMEM whilst under writeback iteration
      netfs: Fix DIO write retry for filesystems without a ->prepare_write()
      netfs: Fix barriering when walking subrequest list

David Lee (1):
      fhandle: reject detached mounts in capable_wrt_mount()

Farhad Alemi (1):
      freevxfs: don't BUG() on unknown typed-extent type

Fengnan Chang (1):
      iomap: release pages on atomic dio size mismatch

Hongling Zeng (1):
      cachefiles: Fix double unlock in nomem_d_alloc error path

Joanne Koong (1):
      fuse: call fuse_send_readpages explicitly from fuse_readahead

Jori Koolstra (1):
      MAINTAINERS: take over vboxsf from Hans de Goede

Krzysztof Wilczyński (1):
      proc: only bump parent nlink when registering directories

Li RongQing (1):
      afs: Remove erroneous seq |= 1 in volume lookup loop

Matteo Croce (1):
      fat: stop reading directory entries past the end-of-directory marker

Matvey Kovalev (1):
      afs: fix NULL pointer dereference in afs_get_tree()

Michael Bommarito (1):
      minix: avoid overflow in bitmap block count calculation

Morduan Zang (1):
      iomap: guard io_size EOF trim against concurrent truncate underflow

Nan Li (1):
      afs: handle CB.InitCallBackState3 requests without a server record

Souvik Banerjee (1):
      ovl: use linked upper dentry in copy-up tmpfile

Yuto Ohnuki (1):
      afs: check for duplicate servers in VL server list

Zilin Guan (1):
      afs: use kvfree() to free memory allocated by kvcalloc()


 MAINTAINERS                                        |   2 +-
 fs/afs/callback.c                                  |  17 +--
 fs/afs/cell.c                                      |  27 +++-
 fs/afs/cmservice.c                                 |   7 +-
 fs/afs/dir.c                                       |  40 +++--
 fs/afs/dynroot.c                                   |   2 +-
 fs/afs/fs_operation.c                              |   2 +-
 fs/afs/inode.c                                     |  15 +-
 fs/afs/internal.h                                  |   3 +-
 fs/afs/super.c                                     |   5 +-
 fs/afs/symlink.c                                   |   4 +-
 fs/afs/vl_list.c                                   |  24 ++-
 fs/afs/volume.c                                    |   2 +-
 fs/bpf_fs_kfuncs.c                                 |  23 +--
 fs/cachefiles/namei.c                              |   4 +-
 fs/exec.c                                          |   2 +-
 fs/exfat/iomap.c                                   |   5 +-
 fs/fat/dir.c                                       |  44 +++++-
 fs/fhandle.c                                       |   2 +-
 fs/freevxfs/vxfs_bmap.c                            |   3 +-
 fs/fuse/file.c                                     |  14 +-
 fs/iomap/bio.c                                     |  15 +-
 fs/iomap/buffered-io.c                             |  16 +-
 fs/iomap/direct-io.c                               |   7 +-
 fs/iomap/ioend.c                                   |   8 +-
 fs/minix/minix.h                                   |   2 +-
 fs/namei.c                                         |   4 +
 fs/netfs/buffered_read.c                           |   2 +-
 fs/netfs/buffered_write.c                          |   2 +-
 fs/netfs/direct_write.c                            |  18 +--
 fs/netfs/internal.h                                |  12 ++
 fs/netfs/locking.c                                 |  95 ++++++++++++
 fs/netfs/read_retry.c                              |   7 +-
 fs/netfs/write_collect.c                           |  10 ++
 fs/netfs/write_issue.c                             |  55 +++----
 fs/netfs/write_retry.c                             |   7 +-
 fs/ntfs/aops.c                                     |   6 +-
 fs/ntfs3/inode.c                                   |   5 +-
 fs/orangefs/dir.c                                  |   7 +-
 fs/overlayfs/copy_up.c                             |  12 +-
 fs/overlayfs/inode.c                               |   4 +-
 fs/proc/generic.c                                  |   9 +-
 fs/xfs/xfs_aops.c                                  |   3 +-
 fs/xfs/xfs_super.c                                 |   3 +
 include/linux/iomap.h                              |   2 +
 include/linux/netfs.h                              |  13 +-
 lib/iov_iter.c                                     |  20 ++-
 lib/scatterlist.c                                  |   1 +
 lib/tests/kunit_iov_iter.c                         |   5 +-
 tools/testing/selftests/filesystems/.gitignore     |   1 +
 tools/testing/selftests/filesystems/Makefile       |   4 +
 .../selftests/filesystems/idmapped_tmpfile.c       | 168 +++++++++++++++++++++
 52 files changed, 592 insertions(+), 178 deletions(-)
 create mode 100644 tools/testing/selftests/filesystems/idmapped_tmpfile.c

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-08-14 16:00 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-26 15:37 [GIT PULL for v7.2] vfs fixes Christian Brauner
2026-07-26 19:59 ` pr-tracker-bot
  -- strict thread matches above, loose matches on Subject: below --
2026-08-14 13:05 Christian Brauner
2026-08-14 15:59 ` pr-tracker-bot
2026-08-02  9:31 Christian Brauner
2026-08-02 17:51 ` pr-tracker-bot
2026-07-03 11:32 Christian Brauner
2026-07-03 15:55 ` pr-tracker-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®