<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel.git/fs/9p, branch linux-4.19.y</title>
<subtitle>Hosts the 0x221E linux distro kernel.
</subtitle>
<id>https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-4.19.y</id>
<link rel='self' href='https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-4.19.y'/>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/'/>
<updated>2024-05-17T09:42:41Z</updated>
<entry>
<title>fs/9p: drop inodes immediately on non-.L too</title>
<updated>2024-05-17T09:42:41Z</updated>
<author>
<name>Joakim Sindholt</name>
</author>
<published>2024-03-18T11:22:32Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=cc3d6fbd645449298d03d96006e3e9bcae00bc1a'/>
<id>urn:sha1:cc3d6fbd645449298d03d96006e3e9bcae00bc1a</id>
<content type='text'>
[ Upstream commit 7fd524b9bd1be210fe79035800f4bd78a41b349f ]

Signed-off-by: Joakim Sindholt &lt;opensource@zhasha.com&gt;
Signed-off-by: Eric Van Hensbergen &lt;ericvh@kernel.org&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
<entry>
<title>9p: explicitly deny setlease attempts</title>
<updated>2024-05-17T09:42:41Z</updated>
<author>
<name>Jeff Layton</name>
</author>
<published>2024-03-19T16:34:45Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=1b90be6698e8d67a2edb8d260e9654d539e7cb51'/>
<id>urn:sha1:1b90be6698e8d67a2edb8d260e9654d539e7cb51</id>
<content type='text'>
[ Upstream commit 7a84602297d36617dbdadeba55a2567031e5165b ]

9p is a remote network protocol, and it doesn't support asynchronous
notifications from the server. Ensure that we don't hand out any leases
since we can't guarantee they'll be broken when a file's contents
change.

Signed-off-by: Jeff Layton &lt;jlayton@kernel.org&gt;
Signed-off-by: Eric Van Hensbergen &lt;ericvh@kernel.org&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
<entry>
<title>fs/9p: translate O_TRUNC into OTRUNC</title>
<updated>2024-05-17T09:42:41Z</updated>
<author>
<name>Joakim Sindholt</name>
</author>
<published>2024-03-18T11:22:33Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=0ce2676013818e62b18504d39211b65d8b54bc24'/>
<id>urn:sha1:0ce2676013818e62b18504d39211b65d8b54bc24</id>
<content type='text'>
[ Upstream commit 87de39e70503e04ddb58965520b15eb9efa7eef3 ]

This one hits both 9P2000 and .u as it appears v9fs has never translated
the O_TRUNC flag.

Signed-off-by: Joakim Sindholt &lt;opensource@zhasha.com&gt;
Signed-off-by: Eric Van Hensbergen &lt;ericvh@kernel.org&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
<entry>
<title>fs/9p: only translate RWX permissions for plain 9P2000</title>
<updated>2024-05-17T09:42:40Z</updated>
<author>
<name>Joakim Sindholt</name>
</author>
<published>2024-03-18T11:22:31Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=e90bc596a74bb905e0a45bf346038c3f9d1e868d'/>
<id>urn:sha1:e90bc596a74bb905e0a45bf346038c3f9d1e868d</id>
<content type='text'>
[ Upstream commit cd25e15e57e68a6b18dc9323047fe9c68b99290b ]

Garbage in plain 9P2000's perm bits is allowed through, which causes it
to be able to set (among others) the suid bit. This was presumably not
the intent since the unix extended bits are handled explicitly and
conditionally on .u.

Signed-off-by: Joakim Sindholt &lt;opensource@zhasha.com&gt;
Signed-off-by: Eric Van Hensbergen &lt;ericvh@kernel.org&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
<entry>
<title>9p: missing chunk of "fs/9p: Don't update file type when updating file attributes"</title>
<updated>2022-06-25T09:48:57Z</updated>
<author>
<name>Al Viro</name>
</author>
<published>2021-01-31T19:37:39Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=2db5cee1e12784fec4f7d562b33c3f6518ffbb5c'/>
<id>urn:sha1:2db5cee1e12784fec4f7d562b33c3f6518ffbb5c</id>
<content type='text'>
commit b577d0cd2104fdfcf0ded3707540a12be8ddd8b0 upstream.

In commit 45089142b149 Aneesh had missed one (admittedly, very unlikely
to hit) case in v9fs_stat2inode_dotl().  However, the same considerations
apply there as well - we have no business whatsoever to change -&gt;i_rdev
or the file type.

Cc: Tadeusz Struk &lt;tadeusz.struk@linaro.org&gt;
Signed-off-by: Al Viro &lt;viro@zeniv.linux.org.uk&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>9P: Cast to loff_t before multiplying</title>
<updated>2020-11-05T10:08:53Z</updated>
<author>
<name>Matthew Wilcox (Oracle)</name>
</author>
<published>2020-10-04T18:04:22Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=f870895527ae8dde12309583ebe3e5b0a3ecb8d2'/>
<id>urn:sha1:f870895527ae8dde12309583ebe3e5b0a3ecb8d2</id>
<content type='text'>
commit f5f7ab168b9a60e12a4b8f2bb6fcc91321dc23c1 upstream.

On 32-bit systems, this multiplication will overflow for files larger
than 4GB.

Link: http://lkml.kernel.org/r/20201004180428.14494-2-willy@infradead.org
Cc: stable@vger.kernel.org
Fixes: fb89b45cdfdc ("9P: introduction of a new cache=mmap model.")
Signed-off-by: Matthew Wilcox (Oracle) &lt;willy@infradead.org&gt;
Signed-off-by: Dominique Martinet &lt;asmadeus@codewreck.org&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
</entry>
<entry>
<title>9p: Fix memory leak in v9fs_mount</title>
<updated>2020-08-19T06:15:06Z</updated>
<author>
<name>Zheng Bin</name>
</author>
<published>2020-06-15T01:21:53Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=ec41ee06e9e0c9a6dbc2cf420f199fc2a522aec8'/>
<id>urn:sha1:ec41ee06e9e0c9a6dbc2cf420f199fc2a522aec8</id>
<content type='text'>
commit cb0aae0e31c632c407a2cab4307be85a001d4d98 upstream.

v9fs_mount
  v9fs_session_init
    v9fs_cache_session_get_cookie
      v9fs_random_cachetag                     --&gt;alloc cachetag
      v9ses-&gt;fscache = fscache_acquire_cookie  --&gt;maybe NULL
  sb = sget                                    --&gt;fail, goto clunk
clunk_fid:
  v9fs_session_close
    if (v9ses-&gt;fscache)                        --&gt;NULL
      kfree(v9ses-&gt;cachetag)

Thus memleak happens.

Link: http://lkml.kernel.org/r/20200615012153.89538-1-zhengbin13@huawei.com
Fixes: 60e78d2c993e ("9p: Add fscache support to 9p")
Cc: &lt;stable@vger.kernel.org&gt; # v2.6.32+
Signed-off-by: Zheng Bin &lt;zhengbin13@huawei.com&gt;
Signed-off-by: Dominique Martinet &lt;asmadeus@codewreck.org&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
</entry>
<entry>
<title>9p: avoid attaching writeback_fid on mmap with type PRIVATE</title>
<updated>2019-10-11T16:21:13Z</updated>
<author>
<name>Chengguang Xu</name>
</author>
<published>2019-08-20T10:03:25Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=18dd2b05f349a3b430791b64676374a2d490896b'/>
<id>urn:sha1:18dd2b05f349a3b430791b64676374a2d490896b</id>
<content type='text'>
[ Upstream commit c87a37ebd40b889178664c2c09cc187334146292 ]

Currently on mmap cache policy, we always attach writeback_fid
whether mmap type is SHARED or PRIVATE. However, in the use case
of kata-container which combines 9p(Guest OS) with overlayfs(Host OS),
this behavior will trigger overlayfs' copy-up when excute command
inside container.

Link: http://lkml.kernel.org/r/20190820100325.10313-1-cgxu519@zoho.com.cn
Signed-off-by: Chengguang Xu &lt;cgxu519@zoho.com.cn&gt;
Signed-off-by: Dominique Martinet &lt;dominique.martinet@cea.fr&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
<entry>
<title>9p/cache.c: Fix memory leak in v9fs_cache_session_get_cookie</title>
<updated>2019-10-07T16:57:29Z</updated>
<author>
<name>Bharath Vedartham</name>
</author>
<published>2019-05-22T19:45:19Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=5b0446c8e0a85b97148c070f73e273bc3903af5c'/>
<id>urn:sha1:5b0446c8e0a85b97148c070f73e273bc3903af5c</id>
<content type='text'>
commit 962a991c5de18452d6c429d99f3039387cf5cbb0 upstream.

v9fs_cache_session_get_cookie assigns a random cachetag to v9ses-&gt;cachetag,
if the cachetag is not assigned previously.

v9fs_random_cachetag allocates memory to v9ses-&gt;cachetag with kmalloc and uses
scnprintf to fill it up with a cachetag.

But if scnprintf fails, v9ses-&gt;cachetag is not freed in the current
code causing a memory leak.

Fix this by freeing v9ses-&gt;cachetag it v9fs_random_cachetag fails.

This was reported by syzbot, the link to the report is below:
https://syzkaller.appspot.com/bug?id=f012bdf297a7a4c860c38a88b44fbee43fd9bbf3

Link: http://lkml.kernel.org/r/20190522194519.GA5313@bharath12345-Inspiron-5559
Reported-by: syzbot+3a030a73b6c1e9833815@syzkaller.appspotmail.com
Signed-off-by: Bharath Vedartham &lt;linux.bhar@gmail.com&gt;
Signed-off-by: Dominique Martinet &lt;dominique.martinet@cea.fr&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
</entry>
<entry>
<title>9p: pass the correct prototype to read_cache_page</title>
<updated>2019-07-31T05:27:08Z</updated>
<author>
<name>Christoph Hellwig</name>
</author>
<published>2019-07-12T03:55:26Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=8be4a30e2d34435392206b1ab7665a9d7c30de72'/>
<id>urn:sha1:8be4a30e2d34435392206b1ab7665a9d7c30de72</id>
<content type='text'>
[ Upstream commit f053cbd4366051d7eb6ba1b8d529d20f719c2963 ]

Fix the callback 9p passes to read_cache_page to actually have the
proper type expected.  Casting around function pointers can easily
hide typing bugs, and defeats control flow protection.

Link: http://lkml.kernel.org/r/20190520055731.24538-5-hch@lst.de
Signed-off-by: Christoph Hellwig &lt;hch@lst.de&gt;
Reviewed-by: Kees Cook &lt;keescook@chromium.org&gt;
Cc: Sami Tolvanen &lt;samitolvanen@google.com&gt;
Cc: Nick Desaulniers &lt;ndesaulniers@google.com&gt;
Signed-off-by: Andrew Morton &lt;akpm@linux-foundation.org&gt;
Signed-off-by: Linus Torvalds &lt;torvalds@linux-foundation.org&gt;
Signed-off-by: Sasha Levin &lt;sashal@kernel.org&gt;
</content>
</entry>
</feed>
