From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740290; cv=none; d=zohomail.com; s=zohoarc; b=l8hyH/+bpfcwXs1zNLymv6fPn5cVT+uCPXSJruhZsAf8/glkcQVhBa29JQNsVwxGaWQfGrFk4wQSdbN/sZ04x6+2KOF+vhK9cwtIR65mPahvhPn/s8iyEoympO06LF4pzP/uj1XZVDKEGducJXV6zt13QK2MlEOI/qimrBXuRCw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740290; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RAZvgYqnj+c9g6wWpQJSv+KlfG4CB8UOuw6DmsMXyJk=; b=D3Fzglze1h08pN0X5Lxhdfq5p2g+5+XUTubjAEsUuaaFMywvGETBIL9sKen0m4VKZmY7HHsb/H2i82WA4MU5g1vN//3BnkTlgTjTyFXhXr+hJLx5Od2qDK5m9tOf4myYiD9ojxkDKl22ghjCcaOCWIFR0E4tE0DXq1sgoFEmFY8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740289970706.9065282746916; Mon, 29 Jun 2026 06:38:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCBV-0000gR-Bn; Mon, 29 Jun 2026 09:38:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCBT-0000gC-Sm; Mon, 29 Jun 2026 09:37:59 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCBS-0003jN-HM; Mon, 29 Jun 2026 09:37:59 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=RAZvgYqnj+c9g6wWpQJSv+KlfG4CB8UOuw6DmsMXyJk=; b=G6+hK SdUJ2WkwpDNsVauxghpVQoQOZ5wMMbHkMUHUmexkBTijYOkE4Xh7JrECQWu/XWXG0YqRmFpG84S0I lK4LE8bGA7duy1s7gy+qOflLzaZJUNiXR6Y1bbUZF5iVjdbP+OSzZwWKGTxah0ww7vbL5acXRDvUJ QMEkOe20MAiF2fHS9TSUDL34MBCy/nCvPQd8t+gxqa1cRz1ReHeI9q5yczkmpXwKEE3ZbCif3zn7w 4ZjaFxo5LUhZb+SR1PG3aA8IcW4/mTJ1d/ufEuGOkufoOOoFpDdQeYLc5R0a2roPwApUxiDUfDmKH /BoFSC85eMJlB50FUAVwPyTNupwEubmR6RI+lU+8pBTSUBCADTEqF+AkoyJOGIL6dE0oFCZIQyuFY rSZAAATNFFU+mQkqTVr7nx9Ngjw/1b9srNoHb1BafpFOmTXDEtWGwdek1tIvb7KfnkouxOmLM4uJd x6zodWkR/cFhUyCucYUddcwGS4kpL69pMQSyWBvVe83TpnOhqbQ/ePCsTMyyyMKgEO9kHoWipoHoT 5w9CKmrU8mfzHN1/sodzyrwG1EyvAvgi4XPHhzvXqkR7m6wyAKUCtw1Ry0jM1AQJEdVP5NyJK1EwQ c9BnX+yJnzdHX3Og7ux78VvD1RJPWXdvTlJiocg8J0bZbsKLmIA2Pv58wp0Jck=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 01/23] hw/9pfs: add msize_limit transport callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=a1c0e5a73740566d4b9eac1f97f78b8ce470116a@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740292375158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a new callback 'msize_limit' to the V9fsTransport structure. This allows each transport implementation to provide its theoretical maximum 'msize' value, which will be used to cap the negotiated msize during Tversion handshake. Link: https://lore.kernel.org/qemu-devel/7c4e53eb73c0580d7a321dbf3823ba5647= 652298.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.h | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index b2df659b0e..d8f364fafd 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -481,6 +481,7 @@ struct V9fsTransport { void (*init_out_iov_from_pdu)(V9fsPDU *pdu, struct iovec **piov, unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); + size_t (*msize_limit)(V9fsState *s); }; =20 #endif --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740315; cv=none; d=zohomail.com; s=zohoarc; b=Y55J6yKq0uCSvHo1sAj9giz6zl9xrmK8lrfQVe/UaCnRQXKNmaKuUrje/Gxlvy1pU/EHs0a9Hk4dIru1coSTB3tkRRRN+T61A2r58ea14czxDmdCdiER2b7iSprqDyz+AEM7p6nqzqCPq/My8LqIiMQ1BoE8AwDN6slFAp/eS0Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740315; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BchJh60RdKC4rAMRfu2I4YvaIkAxMEtxsBVDs3TagXw=; b=LeZfGXB40f23y99xeMXK2zyNd74bZVud1rSWlISNv25EyiUa5r5zjirHGH9QtrCUb/VfABQkyWpV8f4IfXsvrDn50ooDrUmY0I26IzwXuR4tKQ2sxWyc8cFc1PMe794xGhGdxezr9QkuJ7Ka4tYALcc4p8A6i1qwxqdkAMNR3s4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740315466833.1639218498273; Mon, 29 Jun 2026 06:38:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCBd-0000pf-1v; Mon, 29 Jun 2026 09:38:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4a1a2fa4d351ba85628064e4a2a9cbc0c72cdbd4@kylie.crudebyte.com>) id 1weCBa-0000kG-UY; Mon, 29 Jun 2026 09:38:06 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4a1a2fa4d351ba85628064e4a2a9cbc0c72cdbd4@kylie.crudebyte.com>) id 1weCBZ-0003ms-FB; Mon, 29 Jun 2026 09:38:06 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=BchJh60RdKC4rAMRfu2I4YvaIkAxMEtxsBVDs3TagXw=; b=whUEC upYWNYcU1oonAsgmW4Q3ZNvuBlnUbzDcyt00mMUYlSCJN9KZktTyUAG+rcyCobMxcvCXs+CwtKy2Q RDuMoO2cF5Z2qVnp3iswvP4lnySHm0mtiFzb6hDhSId58943nlcUvoLvjzCNi78KFZvbFYQ4hdSZr rr0VfflbltV9yc/yuwqVi+oQd2k87ttqigUSbZrnjxgO56HrU6Iwro5whemEb5T9LvnbNjWOTD5Ss gm+XVo68aTXWTWe+SOddzwI8kRfcx3WHATSc9pjzQoCsSI0g+0ZxaV4Fz9iuAgRlFbsi6lAnrqPd2 4H30KAj2j5uv9vF2G0A06ujFc7VWMgdTKD6anoMZGQBKp5HfQMfvZmwr2G5ww6/tyJ5pdLt1rsE91 E6FKdOVH9cJEp+ppoMhVNvLRUvK+DbLqB5Qs1BLXI/6znSZrp3sT9qJFkyJxbXF741UtSDapMuhY0 n/tnKTrlgmSpUeAoYWgzM8WAZy8Dk6KyIETGDfgIjLhLKMRbBgbcnGwtvpOXpO5vooPUNx0kp+4ss ozsx3HGfWs5kI1EdVCC+mmZmEQTFrJSfTlKT7BBifsz/3nTGCXLtvyVg+ewQenJDfNyK2E5w8eToV Jp7+F400jI4RTPsvAcB9Jy0lIkcZuC1N+d/0fhfxhGvxa813YgTk6NyggG8MjU=; Message-ID: <4a1a2fa4d351ba85628064e4a2a9cbc0c72cdbd4.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 02/23] 9pfs/virtio: implement msize_limit callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=4a1a2fa4d351ba85628064e4a2a9cbc0c72cdbd4@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740316476158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the msize_limit callback for the virtio transport. This new callback function provides the theoretical maximum 'msize' value supported by this virtio transport. The limit is calculated as (VIRTQUEUE_MAX_SIZE - 2) * 4096 bytes, where 2 virtio descriptors are lost exactly for: - 1 descriptor for the original request (typically being small) - 1 descriptor as indirect table pointer (when used), which just contains a pointer to the separate sglist containing the response's actual payload data And 4096 bytes are assumed as standard page size used by Linux 9p client. This results in a maximum 'msize' of 4186112 bytes. Theoretically Linux client could support a much larger size, e.g. by using multiple consecutive pages per sg entry / descriptor. However that's currently not the case and unlikely to change any time soon. And due to recent security issues, let's handle this limit conservatively until really necessary to be raised. Link: https://lore.kernel.org/qemu-devel/4c34426bc906e19423e7e2389c419c2e97= 2d9b9b.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/virtio-9p-device.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index 9f70e2338c..8c5d86cb66 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -192,12 +192,19 @@ static void virtio_init_out_iov_from_pdu(V9fsPDU *pdu= , struct iovec **piov, *pniov =3D elem->out_num; } =20 +static size_t virtio_9p_msize_limit(V9fsState *s) +{ + const size_t guestPageSize =3D 4096; + return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, .init_in_iov_from_pdu =3D virtio_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, + .msize_limit =3D virtio_9p_msize_limit, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740340; cv=none; d=zohomail.com; s=zohoarc; b=cqKeqGyZTSSvb8pvynJA97AHV8Jh3F0Hy7EKZ2FONl9WuU3jAEZ2awBiaSuE9iw3mOlXGzBI1FjLKmNpcjqg5TslM2zU9mQ/f5EI10FO6MZv09imtCcjm5EMOfxqqiwjnlxpN3tx/axrWgdGpAXIEN7v7NVKes+796vG6Aq1Ax0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740340; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JDJlc7IO//w+TTraQ7wtDmZb2j4bqceOuIKvYV6trOY=; b=ECT5UnrSp2gm9OclqOJNmaxkwqbgNXG6AhhohUsD+vMUtUfFI7OTmZF6HcQNGh0TU1ZZvVyxlrMES1HvScf1xJOnNcxVLPMhtepy7+YP4SnukWqb2Szb0LTCHBAVfAdkmsXFkOI258M3W4K0TBTKBJyXI+Jiw4oEYtOEKsjhtCk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740340064498.38266806214085; Mon, 29 Jun 2026 06:39:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCBx-00014A-6L; Mon, 29 Jun 2026 09:38:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <815d1799c3d3d6cd058cb4634392ca5a34830450@kylie.crudebyte.com>) id 1weCBm-0000vn-5D; Mon, 29 Jun 2026 09:38:20 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <815d1799c3d3d6cd058cb4634392ca5a34830450@kylie.crudebyte.com>) id 1weCBk-0003pn-M2; Mon, 29 Jun 2026 09:38:17 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=JDJlc7IO//w+TTraQ7wtDmZb2j4bqceOuIKvYV6trOY=; b=s1xEV sekCMvkaOP/Y9uFtr9HcwhoM4FENtZWILpUjn0CpAoUpqS0bu7c9wPWc9PaP9VnIFUMfjRRWVzTBP HGXGbaaQAk/NVxUnGhR+A3mAcIsFa5zMlk9h2a3Fuxdp+UpY3k1LXmHgKZj/qSQDF+l3gBYUSz9nH yW1uq7INuUjW+0KgpYbZswlRwQpYNaLqZSy9da1Fv+d+BwHWM17MiTRYpesvMdHj75oztvgK4FAti 8wMrhf1jNxuanB4WRNTPnwfwAMjdVpG9yj7PxGTdqUotP/yFXVTfrboP9bjYb+26UyhTq+jM36FWU fBJR0OUtxvGLuokvs5NgxUiTIEzEsQWDw7oSckfBQlt7KMBqd2NQXWrzcZF3a8h96gqwG39r1axcU 8XP1Y1iS+K3NlS7FJG6IFJSicrKMfk7OKBILgZEXfJ7hntHRjR89AY4+uvZvtqanbzdRxYzZlCDYm 1kMv+GXVq+XfeB68O3SAHn3KEHOOu2HFUt1fOFwdZc4I82p049MlelDdSuJYHosz1rlTb4M/CjdmV rCKu9d6l/kLLb2qTXuAHzBHPjjhbqrMWWAU3Kugp4ZsF/VOpBXWMlNyM5QxNi9y7B7CeeLFDEfO6b EIyDnhsohyboc7R8mwbRWFF0XbgBlwkh3az8CRPhkj5gCkJNUOYxsbsjcRfXS4=; Message-ID: <815d1799c3d3d6cd058cb4634392ca5a34830450.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 03/23] 9pfs/xen: implement msize_limit callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian , Stefano Stabellini Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=815d1799c3d3d6cd058cb4634392ca5a34830450@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740342406158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the msize_limit callback for the Xen transport. The limit is calculated using XEN_FLEX_RING_SIZE() based on the negotiated ring_order. For the theoretical maximum ring_order of 9, this results in a maximum 'msize' of 1048576 bytes (1 MiB). The minimum limit of all rings is picked, because multiple rings could theoretically have different ring_orders. Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/9471786bc47b93e822f6c6233a83f2b9f6= 1e6c82.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/xen-9p-backend.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index ca0fff5fa9..e31124bcf5 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -250,12 +250,31 @@ static void xen_9pfs_push_and_notify(V9fsPDU *pdu) qemu_bh_schedule(ring->bh); } =20 +static size_t xen_9p_msize_limit(V9fsState *s) +{ + Xen9pfsDev *xen_9pfs =3D container_of(s, Xen9pfsDev, state); + size_t limit; + int i; + + if (!xen_9pfs->num_rings) { + return 0; + } + + limit =3D XEN_FLEX_RING_SIZE(xen_9pfs->rings[0].ring_order); + for (i =3D 1; i < xen_9pfs->num_rings; i++) { + limit =3D MIN(limit, XEN_FLEX_RING_SIZE(xen_9pfs->rings[i].ring_or= der)); + } + + return limit; +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, .init_in_iov_from_pdu =3D xen_9pfs_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, + .msize_limit =3D xen_9p_msize_limit, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740314; cv=none; d=zohomail.com; s=zohoarc; b=KliOBU/Q+PGKWYZZjAguA0vFDs65I5YFfnozirwi4MiQ1rBP4CttH2CJJATb0GhcX2UBPVKUbic11cxbuXABBQzptsPza33iBs7kYcN7ToRARUPasKBRJAW6rAstcJafBT4pMeUengwgf4t/jl7qP/kOhtM7IsmD5Bdm2M3saPo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740314; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=i43SCueMoWvURGj8J0iCCYrIkTESVe+MuGlxVyCSnZ0=; b=HrxJLg1O2mHHuFNvtki1UIYmi7R5XHFeFkhPG5lbixRTRe9xhLDyaXrC/QAgCZCjeQK6KCkFLLKSvuqX75eb2Mwwfvbh3TQmrYgRm2c+wTP3eQALGAqVbSf+hEF56vmsOQ5rJOMmK5qZh7E3bSOoAPhGUnwOqBGIMBRdfE33Jm8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740314616250.3095879596251; Mon, 29 Jun 2026 06:38:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCBz-00018e-G2; Mon, 29 Jun 2026 09:38:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCBp-0000wD-6v; Mon, 29 Jun 2026 09:38:22 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCBn-0003rS-LH; Mon, 29 Jun 2026 09:38:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=i43SCueMoWvURGj8J0iCCYrIkTESVe+MuGlxVyCSnZ0=; b=MuB7e IXv68qPIyKuwYx3bnBsdmJ5FVjdIJsWMzKnD2Ap5aZOjR43uneuKm2ZJzkWN6GmITLYILCQ8nGPNA i/cXCdk2R1P2AIJnhzaiBbLzEWjwYkKzKtWNsyDMnHdbohBMRdntO+yqCkEtyf8FnTwQeEGd275im lc0ZVa0Rpcj9dTS8BpK6e7TvbAT6t4dNBnPqxgJ9SEwqzNAJpLHhlDek9sR58I1xsHTcCUQoN2W/m CDIDsyDPgKwKE5nnK+ewkdqElYi+DRqbfjaCxd+kW/4uibw6YsUPdo9IctvzUv/iXjqk8Acd09mN9 T8jwwvYYGxB7LKbu204TlPJhGS43/b4iYk5+i26Jc/nCTJMWuPUJPpH5nmvaho/twH8YgIsBRU7Ku Y0J7PvMu2tIRm9h5H2vIgUCQiVRGQUbWH/gDJWOUhoYFO6ul9O/mmHj2PjN5S1CAmqFP/bEc5Cnd6 pNVD9fU1afjLwU2sNF7lrdjVlXTeH3pJdlTlHiT2pCdAracVlJXuUS0iKGzYGh9DIzPXXOJH6Aobi KPFb2f0KuatPE60Fb0s+i6lcRFZpFw82e6tWEu0CA2V8igM4PLfEv1YYv/hfQ64E2yqL3icvvGaKQ RcvBUw9HwChl5e//oaU5YFMyJaRd/Ecczloz2xTgODk1/oCusU+UigrxQaGr6s=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 04/23] hw/9pfs: cap negotiated msize to transport limit To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=bb5ab96e35a1b13a2485d239a44ff2d040e9b337@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740316494158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The 'msize' parameter negotiated during Tversion handshake can be arbitrarily large as requested by the guest. So far 9p server accepted any msize value suggested by guest, i.e. server did not cap it at all, no matter how large, as in practice the upper limit of msize is a client capability. But as subsequent's security patch shows, capping msize on server side makes sense as additional safety-net. Let's cap msize to transport's theoretical limit for msize, mainly to prevent a bad client from triggering excessive host memory allocations throughout the session. We intentionally don't cap msize to transport's current, real response buffer size, as the response buffer size may vary between individual requests. Link: https://lore.kernel.org/qemu-devel/2105e9a3578c6f751bb64af55c16dd953f= 393f20.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index b486cce48a..81d9bb8c6d 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1469,6 +1469,16 @@ static void coroutine_fn v9fs_version(void *opaque) goto out; } =20 + /* cap msize to transport's theoretical limit */ + if (s->transport->msize_limit) { + size_t limit =3D s->transport->msize_limit(s); + if (s->msize > limit) { + s->msize =3D limit; + warn_report_once("9p: client msize capped to %zu (transport li= mit)", + limit); + } + } + /* 8192 is the default msize of Linux clients */ if (s->msize <=3D 8192 && !(s->ctx.export_flags & V9FS_NO_PERF_WARN)) { warn_report_once( --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740339; cv=none; d=zohomail.com; s=zohoarc; b=aHdSRadfekXWKvBzRD/0gWXIImSATmh/HDMI79Lz9kOlzVe0kfz7D59egZvDfPVD0Np+febl3dsuV91i1WOVGiJztrXjTrmxGcS3cHkHxqqC6rQZo6JpJrK93idmpJjKsFzyR/Irkw5zqywpmqZPbu+R7u4iT3baoKlpkfaNcS0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740339; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=O1zLhq6mUlcxDD4gyURp+Ui17aiGUEOzm6zq3xQ5tDU=; b=kS2t3Fli0TQ1PpifXJwY806+0K7t2No3GSw4uFm6VinJQjYqS5D1URGgui5WzChvwIkEjV008poMjR1ZO9q2epAhHY6bzdWSQXG4XVxyxOV1uebarplAf3w2jD5NcrUywbErybkeIkPgM+rW0JWaH97mzeeu77AOar6hljjkymc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740339968176.64742078671134; Mon, 29 Jun 2026 06:38:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCC0-0001Kr-QU; Mon, 29 Jun 2026 09:38:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4b615eaa1be4a54fb677c302e1a86fe09a94aecd@kylie.crudebyte.com>) id 1weCBz-00017V-5O; Mon, 29 Jun 2026 09:38:31 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4b615eaa1be4a54fb677c302e1a86fe09a94aecd@kylie.crudebyte.com>) id 1weCBw-0003s1-4J; Mon, 29 Jun 2026 09:38:29 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=O1zLhq6mUlcxDD4gyURp+Ui17aiGUEOzm6zq3xQ5tDU=; b=NM8/O qViVyKLLZMUDterdSrf4XU2HQOz0HrcKeZxiVpXaQWNCH4xv7FhaEAfGe7WSd/Wcq46snDz+orGAr XO+rwSE2HWgHMnOb4CNR49/axZ72VPy4lPf3Z3ceyR9/hKE5RUO1Oniot6HY2w7RTxob6ipoVQFW4 lk+0iRqqVMvI4FfBQJCqBzlZQ8HX8G33dp+ZggoQCBvse2h4QVgDMw5AmkDY8y9KErVRRrpZRZg/B yKdRxB7aq+52OYh9VhSMyYuIN9dJrQTMEyHj2SlWAPDWZW6qeskOtnbaiTv6qecwRSdtkwf4OD2Qe JY3MxQn+6gi+YQHj+gzRe4Or7zNY9Edsl41ShMiFqrh3vKypc1nkPotjIavLS321ofZCGXq2XgsXZ 98jjK3JJYlDfPYOr1TM8JtUhZO/9ymoH+PG97gu9k9aWfXjTh1k0S5mc+P7lCwqmINnIE/7WM7o7a d5OGPbhED49plT9UFzaikx1+ctKNXLfGVMDzSASA0rsvdUIioyzJFC1QXMmPCH2ML5/1HrrKXJdYO LDutkgfObc0cILuVNp8xCOVSW8/WaYyTz39+6VoMGtSSvfTSUFSUauWYQQQ2EnVZve0AhIXBXnQSu Ekie2UqbHZ4XDdDhKCKR2ctmJiTNNGkqZMpvn4AgdqDXX3EUwjCbXDRjLvw+BE=; Message-ID: <4b615eaa1be4a54fb677c302e1a86fe09a94aecd.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 05/23] hw/9pfs: add response_buffer_size transport callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=4b615eaa1be4a54fb677c302e1a86fe09a94aecd@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740342403158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a new callback to the V9fsTransport interface that allows each transport to provide the real size of its current response buffer. This is needed for subsequent safety guards that will limit generated responses appropriately before trying to allocate, generate, and send a response to guest. This is especially required for request handlers that need to allocate dynamic and potentially large host memory for generating a response. These safety guards are mandatory to counter bad clients that try to trick server by supplying response buffers being smaller than the previously negotiated msize value. Link: https://lore.kernel.org/qemu-devel/703ed8ce4401c4550ef2cd99f30ab80866= 5d6e85.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.h | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index d8f364fafd..1a309664f6 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -482,6 +482,7 @@ struct V9fsTransport { unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); size_t (*msize_limit)(V9fsState *s); + size_t (*response_buffer_size)(V9fsPDU *pdu); }; =20 #endif --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740354; cv=none; d=zohomail.com; s=zohoarc; b=S3KBLEJ41GFbKyUe7OGcAdrJ6M5+AfjDRxy0lU0Cv6JgK/lIqpC+Ukql9RySw0jEEdCRdIkOfZ6Zg/vbP6i56hpHguqY84KW+jZD6vN4v5/2TbytnuqQS3Cw9yuXLnsQ1+3mJ5roEgE3XA+vM0inWECeqzzT6e2+PXL3bpnIuPI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740354; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wA5WgsgKQXyassqJxRXshSb0ETANhXBadc5QCGmjXfc=; b=D8cT66KTCh7xVu0fLT2YTfcQMyI1a4JkTpclY0KMiJVPKThpH622brswEWuGguzwsLD80w8ITTxe4QtBF6k7HcPk6CidgaX+uk+ebxJdh8RkzSVzxYHoeMc7uuoGBTRQLaVD3oDhudJnfrmdGeJEYJRWkxyFScMfByG/zOg85PU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740354443868.3191417557462; Mon, 29 Jun 2026 06:39:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCC5-0001ip-50; Mon, 29 Jun 2026 09:38:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <12bcbdca8ae9fcd5fec093e8ef5e70521e85e889@kylie.crudebyte.com>) id 1weCC3-0001f2-Rv; Mon, 29 Jun 2026 09:38:35 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <12bcbdca8ae9fcd5fec093e8ef5e70521e85e889@kylie.crudebyte.com>) id 1weCC2-0003tk-BA; Mon, 29 Jun 2026 09:38:35 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=wA5WgsgKQXyassqJxRXshSb0ETANhXBadc5QCGmjXfc=; b=eFABQ rR3hRakIqvrO+RRoc2U6Bv+Wst6//+VE6aJrUudZz0XBRbu671rP7kkGnSvxdpVOYyf88r0K3uUPn 0QzLvW2JMmfjB8457rf6/nWLYNMcYtIve9yPW0L/d+BJJOvRRIxKubfCAeQf482KyGE64Rhc3eDuG EDCSrT6W3Oqi0RvTfVd+LChW9KT55/ydtxCP38aUEh4/Vj1CBVkuyM5r1hiK/CP9+o94YIjfrDREN GIvH8f6tukZQ8yiMVp2ONUTyfk8cUkVaxoT1GHJ3dNrVuQN2mmNjjkG/ZuZ7X/RLyYwoLsmz8jve0 VtbY6kkK97wugcUSQENWix8JiODjBn5uzGoNnDwupKLd4v2JZnC+w9c5beDG52P7tDTj8mVU8xZnU KXYj8jMsNU2imHUCxHzVxALSvOw2/c3RYBYxT5cwES2Tiy77+PWQd+70f/JjhNBYM6IWQVDPmZBhX UgFtcaLu/mfyLab+bRdrXwQsR7LzfU84mDTp/mPKtkcJV3q2uskcni9dRHl4qvsF9MGNCE9Sq+LYY 7R8Q9HyFjfLH7Qi/PkzGyq3Qen8WfxL3cZ/PHS9QHFUFY3XD+2vffA1hbm7txSATLcbwhP115xgn6 ygIX2d0QN0BA0NEuROSKxtGNDu2M3U8FoclLm8ogdF8qbPoNuk2jIT4pTgjqxE=; Message-ID: <12bcbdca8ae9fcd5fec093e8ef5e70521e85e889.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 06/23] 9pfs/virtio: implement response_buffer_size callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=12bcbdca8ae9fcd5fec093e8ef5e70521e85e889@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740356404158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the response_buffer_size callback for the virtio transport. Returns the actual current virtio response buffer size for the supplied PDU, which will be used as safety guard for limiting the response size when generating a 9p response. Link: https://lore.kernel.org/qemu-devel/5bbed2768f7a0da8fa2be183e75928c5d1= ef691d.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/virtio-9p-device.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index 8c5d86cb66..50dc93091d 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -198,6 +198,15 @@ static size_t virtio_9p_msize_limit(V9fsState *s) return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; } =20 +static size_t virtio_9p_response_buffer_size(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + V9fsVirtioState *v =3D container_of(s, V9fsVirtioState, state); + VirtQueueElement *elem =3D v->elems[pdu->idx]; + + return iov_size(elem->in_sg, elem->in_num); +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, @@ -205,6 +214,7 @@ static const V9fsTransport virtio_9p_transport =3D { .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, .msize_limit =3D virtio_9p_msize_limit, + .response_buffer_size =3D virtio_9p_response_buffer_size, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740361; cv=none; d=zohomail.com; s=zohoarc; b=P9bSe6RJigGQaq2KjGATpCmkfczF+ZaSr21SvcyVDhUDUctj6gRx9erv3tw4rhL+5PsSIeXc4QUg4kEeKkpd2JtSAwTF66jWdC1qIUM7gDwSvh36SGTCCGgME8I8WLQ+YnJk00zlEOdVWva2BDP459d2gj5VMn2yL5ljYio05dA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740361; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3J8Z3/ZuD35HVfkr5nQfyeSnezElwJXEdSzjILafr4E=; b=SFU/2OIWn0goJGFGsq1fCDloiaGDV3D5ywE/W8LYDjbcXx30FVx5Bf30fUavl5AVegwzeqUY6e1vsBqNFPL+b+s8foDKpepoINMIhtGZFog6JCRSnCZP+3aY6fAi/rtX6BDpow9YM0YRa+c+pCb76J9Ghc6c7xvNIJJ7/szTxLk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740361106449.81588392257436; Mon, 29 Jun 2026 06:39:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCCO-00039e-UV; Mon, 29 Jun 2026 09:38:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <69c8f5e6946f76a70b141a340c7aeb9d6a8e3c27@kylie.crudebyte.com>) id 1weCCO-00035W-2n; Mon, 29 Jun 2026 09:38:56 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <69c8f5e6946f76a70b141a340c7aeb9d6a8e3c27@kylie.crudebyte.com>) id 1weCCM-0003xP-Ft; Mon, 29 Jun 2026 09:38:55 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=3J8Z3/ZuD35HVfkr5nQfyeSnezElwJXEdSzjILafr4E=; b=pzHUl 0M5kZdTex5xN4tXUtB+tszTglZKuyg7z+fCCA94c2KrKGcCxL3zUj72uKMY9HnlX4RYWiL7jKjp2v KnBl8rOlNexdeYSz2aHed0kFiwTz+fsSfiY8BsHKUdvl5mil+6iGk+ufNbxnfYNQXMMaMJpKDIHNy GMeuyqCgXYP6aWvDPGwTnXQsC2Or6revRCIhQSENmoNGdwTvR5LoINw527tRWZ1CaKB3V5jliAadP AgB7Ay9AEKk3A+iCbo81fMuoQiqM8HJ3DsYk3XcEwSvfbL/hZlvcuE5CkPBBawuA9w1by1PB43dIN HhJsFSpYm2QBHOXdzJD3Uw6XC085aUkfE8jM4cS7FE5Ha3MKYesuWsWlSPdbQVv6n68YUXZn9fUFo /wH7vDyf8qn/VcgISqwKoPtPKhG91IiWKTtzWvTg+ruQ5Vidww5PPEr2IN0WbuITMbGKWJwJVt2ak J5fn/4WQLUlXCXJ2nBQrdabtkOSASmgSNhh1dm/02oIh/oH3Xj0Ox/GlkEuVODhmsheqTlcwFhVti QWdmQ7vHTy1xhwmMk8jw9ESjSVYZL/4IzeYV6w35HQ78ZEmoPmA42OUOkcju1HdWjzaC+rUS3GXBz R8yBUMWFLtN8xyTO/CFh5GzbCYey0qTDJdSUJ0PvTvlzxr4krm0KuBZ1JIqipg=; Message-ID: <69c8f5e6946f76a70b141a340c7aeb9d6a8e3c27.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 07/23] 9pfs/xen: implement response_buffer_size callback To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian , Stefano Stabellini Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=69c8f5e6946f76a70b141a340c7aeb9d6a8e3c27@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740362534158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the response_buffer_size callback for the Xen transport. Returns the size of the response buffer from the rings in_sg, as limit for 9p server while generating a response for supplied PDU. We use a local iovec array variable in_sg[2] instead of ring->sg, as ring->sg is only allocated by init_in_iov_from_pdu() and init_out_iov_from_pdu() during request / response processing. response_buffer_size() however may be called before those allocators, which would dereference ring->sg as NULL pointer. The local array avoids this. Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/3b139769eb1d3f9d91ee5281228e6467f9= a08b99.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/xen-9p-backend.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index e31124bcf5..24c90d97ec 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -268,6 +268,17 @@ static size_t xen_9p_msize_limit(V9fsState *s) return limit; } =20 +static size_t xen_9pfs_response_buffer_size(V9fsPDU *pdu) +{ + Xen9pfsDev *priv =3D container_of(pdu->s, Xen9pfsDev, state); + Xen9pfsRing *ring =3D &priv->rings[pdu->tag % priv->num_rings]; + struct iovec in_sg[2]; + int num; + + xen_9pfs_in_sg(ring, in_sg, &num, pdu->idx, 0); + return iov_size(in_sg, num); +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, @@ -275,6 +286,7 @@ static const V9fsTransport xen_9p_transport =3D { .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, .msize_limit =3D xen_9p_msize_limit, + .response_buffer_size =3D xen_9pfs_response_buffer_size, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740372; cv=none; d=zohomail.com; s=zohoarc; b=FgfsuwZg4QrSP5nPWx/VAYU+dG9leRHuteJiRfJRK58OdzvkYGO/gZr98JzV++qxofDyNrEjAkWvZoNnsAWmPXBPBCCNCw8CGSex80MdnYLXAfVh3MumvVG4mDqqeeGvNevNdTjEm5z39huO5cm8qXolO4GLyMsc6jdJpBe0bDk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740372; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=h5MqDz5GNrcRukA+fwCV4Ptg8NEURV8By00x0yDcRIo=; b=Zq8OwljuqBg3Eam9HUJfHvWfzLdhjxo8WV3BTZ7CZymQfFwKHcCePW3ChOWJpZfdHLQK7rNeumemYrDdtXHQOB5ekuT1C2r63Tf67Pe4DinvXKy0AeimEVdXytSHkuEquXjDgRtWAiwLIrBM0TJJXpdjYmOal/h16BXdLkytisw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740372855117.30356540695107; Mon, 29 Jun 2026 06:39:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCCj-0004NM-OP; Mon, 29 Jun 2026 09:39:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <64c6c7e0df726055fac9ed12b30f712b115193f3@kylie.crudebyte.com>) id 1weCCi-0004JF-ID; Mon, 29 Jun 2026 09:39:16 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <64c6c7e0df726055fac9ed12b30f712b115193f3@kylie.crudebyte.com>) id 1weCCg-0004Pk-SH; Mon, 29 Jun 2026 09:39:16 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=h5MqDz5GNrcRukA+fwCV4Ptg8NEURV8By00x0yDcRIo=; b=MRr73 IKn44QatR3fFz4Zrz7BAv9LayFuEfN/50wrryU6A/qYGo3GCTh/I3CXNl5ZCUivLnju1hlz+xG5ZB NjXrLfuJMjE3ZR0gSsd1T6lMdEhBJZMHzz9+MPA8awYt0eUHTcsgrUEMHels0tKBWlKxN6ABDwuIy xb/m4Sgi9+y40AbfI08GExWenbbWtJ7fuWou2+Kow3FaB4EKZvLxYq9Hduaf6Y7VCh/NQ3QvsVUcA +WHXGffx5G0lczUBdsoGDoo8TPewxSUxboYtb757YXacvoWYxxEO1VdtKcrHUsYUPD9czBCi7Kr43 F0m0upgWZBcOndzjEiaLiUIPENWsxHH88JUTRElM3xsCgbXAzsCaI4SFXBipqoZNP+iaroLzvY26s V+ConF/Kni9E/XriOJKs1lYKEpHl9KjtgChGkzbPNwQGmLhrzXcPRidPOO/PfwFWYQ4DLFeXvT4SP RfPtFCuky+OHeQEAhDfC+YpqgDaf0nIIyivSgEAt8Yu5ZaT5zFzaqCNhyVh27/9ZrbEGsxyyu+6OO 7VSYVzsusfb9q7eWsesLqmm2SgW6NsIMFQLE4zcsBxPPSt1uEq6oPw8kbsM9d8KIFybF06zHRIVYd l2bF1mUj3IvsK6fiwXZcevLhZpcb0NdwPqODYXsCxG7xGqTTPwXfw0Yd9lNIII=; Message-ID: <64c6c7e0df726055fac9ed12b30f712b115193f3.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 08/23] hw/9pfs: cap Treaddir allocation (CVE-2026-9238) To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian , Stefano Stabellini Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=64c6c7e0df726055fac9ed12b30f712b115193f3@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740374508158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Constrain max_count in v9fs_readdir() to transport's current, real response buffer size before calling v9fs_do_readdir() to prevent excessive host memory allocation for specific, crafted, huge directories (large amount of entries) by bad clients. Client may send a Treaddir request with a large 'count' parameter, and while the negotiated 'msize' provides some limit, it accounts for guest being somewhat faithful on the negotiated 'msize' value throughout the session. A bad guest client could have negotiated a large 'msize' but provide a small reply buffer for Treaddir request, causing QEMU to allocate host memory proportional to 'msize' before discovering the reply cannot fit. Possible consequence was a potential DoS by a priviliged guest, causing a disconnection of guest communication due to transport device being marked as "broken", however QEMU process would have continued to run with potentially giant host memory allocation, which might have negative impact on other services running on host. Fixes: CVE-2026-9238 Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Reported-by: Feifan Qian Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/f81a387a2de4f2172fd5830c5654f49d78= 102254.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.c | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 81d9bb8c6d..09454a5404 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -2679,6 +2679,7 @@ static void coroutine_fn v9fs_readdir(void *opaque) uint32_t max_count; V9fsPDU *pdu =3D opaque; V9fsState *s =3D pdu->s; + size_t max_resp_sz; =20 retval =3D pdu_unmarshal(pdu, offset, "dqd", &fid, &initial_offset, &max_count); @@ -2687,9 +2688,28 @@ static void coroutine_fn v9fs_readdir(void *opaque) } trace_v9fs_readdir(pdu->tag, pdu->id, fid, initial_offset, max_count); =20 + max_resp_sz =3D s->msize; + + /* + * Constrain max_count to transport's current, actual response buffer = size. + * A bad client might provide a response buffer < msize. + */ + if (s->transport->response_buffer_size) { + size_t buf_size =3D s->transport->response_buffer_size(pdu); + if (max_resp_sz > buf_size) { + max_resp_sz =3D buf_size; + } + } + /* Enough space for a R_readdir header: size[4] Rreaddir tag[2] count[= 4] */ - if (max_count > s->msize - 11) { - max_count =3D s->msize - 11; + if (max_resp_sz > 11) { + max_resp_sz -=3D 11; + } else { + max_resp_sz =3D 0; + } + + if (max_count > max_resp_sz) { + max_count =3D max_resp_sz; warn_report_once( "9p: bad client: T_readdir with count > msize - 11" ); --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740366; cv=none; d=zohomail.com; s=zohoarc; b=Kd7p/5KntY5lE4ujQ024AnpuYfmtp6rfrCpebdeZ1bCjsnbgeSWlt9l0QeK+OI8FMZXhn0pkn355KNboAT64ELjSEZyWtEoRytY5nrmWbkIuHQxuM62ejj+D5usQ70AF/AuFImgGbwAED6k7Cz/7u/3pcgeDG2cVJGchX4NBIok= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740366; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ed/gUTUSntpOl1RgXFscwZa1JEbVNq5Lj8RO8ztlHbY=; b=UVqo0KXT3IN+7lT3Hd3pxwoPuHrUQYe2RvqN4frpf5SUbBWGfCIvwEfDfrNCbCUpR+C15pIAQW6qmTW4cJlHvCYertO5tarSYEalOngdeyhOEUKHF9jcGvk/x+qtoaYXS/VcEqaAqBdzJIKS6o+Hhrck2HshNNwt5a2EMKL/D8s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740366116298.5881950588746; Mon, 29 Jun 2026 06:39:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCCq-0004pa-Pq; Mon, 29 Jun 2026 09:39:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <693b296b176d1829b10855d9831bd2ad21b2cdcf@kylie.crudebyte.com>) id 1weCCp-0004jK-Mb; Mon, 29 Jun 2026 09:39:23 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <693b296b176d1829b10855d9831bd2ad21b2cdcf@kylie.crudebyte.com>) id 1weCCn-0004QO-Q0; Mon, 29 Jun 2026 09:39:23 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=ed/gUTUSntpOl1RgXFscwZa1JEbVNq5Lj8RO8ztlHbY=; b=GgJeZ DnnK2qjVgGAGIWyeefCLwXsBejCIhYOwkCJpGbJpe49aM6YQc7cHpBPO3r1oV+V64b/5y5sD3GXEt nw4EftDmjOEP83BLQJOZLrhd2gBUaZdJCkaPMbjm5iaJyD3ZcqG34VR6HHPsZVOYPZ4PL3eK1PbJ5 oYeMEV5dtF1zcksUKmp3CM/AtQwc541DibA8JCGLyKNx4FgqxlIZavabAfQfC0S4pxNEo2jX35o13 Qfxg1KRWnIwwpIvH2s3wp2FLp9DB+58weULXEQAc0QRrOWUPU1seXCN5FuHKNXl83I1NNV3Nl/xLJ 92aRLhvbJq4x7RUt88tgyvpgqeDu1QqsuGNLJQrPobgrlUMXLY4BT8RM+0I03IpF35/LHUjmXEKLi evYWKXTkIGyD/XaREDn6t6vHU97Oa4Ay3I3QyLXMvdH6q4sHVsZIaS66zKtOD4Rd8fppxk28VcwwJ dpRWP3IiUAGsXH/VKIogcJlxMi8L6/m/t+j561WieTaglpSe9H4BuUEKEvyiodz+TSWEb1G52NiC6 lukvCUlhm+ZGcZinbOBQ5EymKKtFEqQWIbdBjRvQnLemPhocedCwsopldohkIkxzs2kGjx8tbBoKe WCKkGqlU4o5MP0O/lb9j1fhHFOPpL0vqfiiGa0YsRJKcutiEPPpKTXNRjzV0NI=; Message-ID: <693b296b176d1829b10855d9831bd2ad21b2cdcf.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 09/23] hw/9pfs: add xattr FID limit to prevent memory exhaustion To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=693b296b176d1829b10855d9831bd2ad21b2cdcf@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740368442158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a limit on the number of simultaneously open xattr FIDs to prevent host memory exhaustion attacks. Each xattr FID contains a buffer for the xattr value, and without a limit, a malicious priviliged guest with direct communication access to 9p server could create a huge number of xattr FIDs until host memory is eventually exhausted. Fix this by: - add xattr_fid_limit to struct FsContext for the max. amount - add xattr_fid_count to struct FsContext for the current amount - init xattr_fid_limit with 1024 - init xattr_fid_count with 0 - add function xattr_fid_count_inc() to increment the count - add function xattr_fid_count_decr() to decrement the count - call xattr_fid_count_inc() in Txattrcreate handler - call xattr_fid_count_inc() in Txattrwalk handler - call xattr_fid_count_decr() when a xattr FID is freed Additionally: - reset the xattr FID counter in virtfs_reset() When the limit is reached then xattr_fid_count_inc() returns -ENOSPC and the request handler is aborted on its error path without turning the FID into an xattr type and without allocating memory for the xattr. The default value of 1024 was chosen, as (sane usage of) xattr requests in the 9p protocol are usually very short-lived, and even machines with 128 cores with very high xattr activity should have plenty of head room without ever hitting this limit. Fixes: 10b468bdc5 ("virtio-9p: Implement TXATTRCREATE") Fixes: CVE-2026-8348 Reported-by: Feifan Qian Link: https://lore.kernel.org/qemu-devel/eb3787869745d47234fb662600187bf773= e1ef8a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- fsdev/file-op-9p.h | 9 +++++++ hw/9pfs/9p.c | 62 ++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 71 insertions(+) diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index e8d0661c4b..454761d81d 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -81,6 +81,11 @@ typedef struct ExtendedOps { =20 #define V9FS_SEC_MASK 0x0000003C =20 +/* + * Limits the maximum amount of simultaneously open xattr FIDs to prevent + * host memory exhaustion (as each xattr FID contains a xattr value buffer= ). + */ +#define V9FS_MAX_XATTR_DEFAULT 1024 =20 typedef struct FileOperations FileOperations; typedef struct XattrOperations XattrOperations; @@ -109,6 +114,10 @@ struct FsContext { void *private; mode_t fmode; mode_t dmode; + /* max. amount of simultaneously open xattr FIDs */ + uint32_t xattr_fid_limit; + /* current amount of open xattr FIDs */ + uint32_t xattr_fid_count; }; =20 struct V9fsPath { diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 09454a5404..e737629581 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -265,6 +265,31 @@ static size_t v9fs_string_size(V9fsString *str) return str->size; } =20 +static int xattr_fid_count_inc(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + + if (s->ctx.xattr_fid_limit > 0 && + s->ctx.xattr_fid_count >=3D s->ctx.xattr_fid_limit) { + error_report_once("9pfs: xattr_fid_count limit exceeded " + "(configurable by option 'max_xattr')."); + return -ENOSPC; + } + s->ctx.xattr_fid_count++; + return 0; +} + +static void xattr_fid_count_decr(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + + if (s->ctx.xattr_fid_count > 0) { + s->ctx.xattr_fid_count--; + } else { + error_report_once("9pfs: xattr_fid_count underflow detected"); + } +} + /* * returns 0 if fid got re-opened, 1 if not, < 0 on error */ @@ -397,6 +422,7 @@ static int coroutine_fn free_fid(V9fsPDU *pdu, V9fsFidS= tate *fidp) } } else if (fidp->fid_type =3D=3D P9_FID_XATTR) { retval =3D v9fs_xattr_fid_clunk(pdu, fidp); + xattr_fid_count_decr(pdu); } v9fs_path_free(&fidp->path); g_free(fidp); @@ -634,6 +660,14 @@ static void coroutine_fn virtfs_reset(V9fsPDU *pdu) fidp->clunked =3D true; put_fid(pdu, fidp); } + + /* + * Explicitly reset the xattr FID counter. + * + * free_fid() already decrements the counter for each P9_FID_XATTR, so= the + * counter should already be zero, hence this is just a defensive meas= ure. + */ + s->ctx.xattr_fid_count =3D 0; } =20 #define P9_QID_TYPE_DIR 0x80 @@ -4023,6 +4057,14 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) clunk_fid(s, xattr_fidp->fid); goto out; } + + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + clunk_fid(s, xattr_fidp->fid); + goto out; + } + /* * Read the xattr value */ @@ -4030,6 +4072,7 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) xattr_fidp->fid_type =3D P9_FID_XATTR; xattr_fidp->fs.xattr.xattrwalk_fid =3D true; xattr_fidp->fs.xattr.value =3D g_malloc0(size); + if (size) { err =3D v9fs_co_llistxattr(pdu, &xattr_fidp->path, xattr_fidp->fs.xattr.value, @@ -4056,6 +4099,14 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) clunk_fid(s, xattr_fidp->fid); goto out; } + + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + clunk_fid(s, xattr_fidp->fid); + goto out; + } + /* * Read the xattr value */ @@ -4063,6 +4114,7 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) xattr_fidp->fid_type =3D P9_FID_XATTR; xattr_fidp->fs.xattr.xattrwalk_fid =3D true; xattr_fidp->fs.xattr.value =3D g_malloc0(size); + if (size) { err =3D v9fs_co_lgetxattr(pdu, &xattr_fidp->path, &name, xattr_fidp->fs.xattr.value, @@ -4164,6 +4216,12 @@ static void coroutine_fn v9fs_xattrcreate(void *opaq= ue) goto out_put_fid; } =20 + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + goto out_put_fid; + } + /* Make the file fid point to xattr */ xattr_fidp =3D file_fidp; xattr_fidp->fid_type =3D P9_FID_XATTR; @@ -4425,6 +4483,10 @@ int v9fs_device_realize_common(V9fsState *s, const V= 9fsTransport *t, =20 s->reclaiming =3D false; =20 + /* init xattr FID limit */ + s->ctx.xattr_fid_limit =3D V9FS_MAX_XATTR_DEFAULT; + s->ctx.xattr_fid_count =3D 0; + rc =3D 0; out: if (rc) { --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740407; cv=none; d=zohomail.com; s=zohoarc; b=GzaW2GbCMgc4zU0RK5HZXlwVe13D1A1Ra4PjCiHqs9NY53xh2SKevhK5d1NVsStqUn6Zb/IZtRedroH+yHlM79K5YSYBBH/6k3vYhwKILw0eTWPAsLWPZBcpAUqU8uz9mskdAvibnTcMBSFLxGta61spT6MtGwZ2NasDNU0PYR0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740407; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0lgtlrURqWz5Gn2WSuhieTwwdPcSyX0FnmFV4/UGTHg=; b=byAv3Aw80vVCEr3ii6T2ChnUUkRsgdosdfmzmb8C3r1SfmElasE11N6i1w9aQVZFWHqNZTlCKuNtaK8dJmxKUCqkRpeqBb0bW9TkAcARilXxeeL320Cfpn0/LY3iXCxiGHdN3wIT0puW7jNHKBvmWdnltHHHqJ84KyyNgzXQKR4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740407322274.46003162949796; Mon, 29 Jun 2026 06:40:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCD0-0005EW-AS; Mon, 29 Jun 2026 09:39:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCCy-00059W-3E; Mon, 29 Jun 2026 09:39:32 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCCw-0004SB-8K; Mon, 29 Jun 2026 09:39:31 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=0lgtlrURqWz5Gn2WSuhieTwwdPcSyX0FnmFV4/UGTHg=; b=I3uiS h6LI1lvorb0P2DPHgxm1slY4PDz76HyfXjhAIK/BJs1rT3/FhqtDvTFE37rPW9EKTpmod+ShQlbmj 9cV8K9rfy5YOonU7+Hyr5EN/v6dxhiW82luu933UJr5ly9+rwUELlq5QOhzUKAei/t1Dvo21VGHde mg2PWfNdlLvhP+WEkAaS4IV8aEuRh58CJDCGYvfxIBGJwO0hUCe/Dd0Z4ywT5diW7LUzlqibHOM0B ulZtowNOGLYPeKkePaGEiSBKFZq57STEW3TjopD6AHw/wGscAkq7K6rflH2TwSKE/h63YHvdaiQbM jNwAeMqfi3TTGIdLiL7InJR6py4y1LSWRqenmA2qP2e8VGFY5uYd+ivFpxVpMrtCjUJmYtlhDOgV0 69Cs1P6xDue/syJv5DybmgBkv6mE2gO7cWBs+5Oqpc+mIeunt2uhhLNt2a29bRMo/pF8J//qpbvif iME2RMX8ODYCJ49jXm36Ueif4nn54KawAh8/BpV4glmKc81RUYsd9kxdypAAUsLiVHeJTLlAQA7td /5Ya9WR0MntO0+KObwGWbYUd3AqfSt5pTAhEuhpMuPlw0JSgETXqopAmEfAHeNphWOqPdxfL+fS3f VjSrFbLlIVVPyHvKj/Yd7qbnBO+Pb7VVGG/JdcFk/UyefY0nXUtukzKOTe5hB8=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 10/23] hw/9pfs: add max_xattr option To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=e6116a81f04c48af9530d984d16ef4ed4346e865@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740408627158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Previous patch introduced a limit of max. 1024 simultaneous xattr FIDs. This patch introduces an option "max_attr" that allows to override this limit, just for the case that some user might run into this limit for some reason, even if unlikely; or for reducing the limit further down (e.g. that default limit of 1024 would cap at max. 64 MiB host memory, at least on Linux hosts where the limit per xattr is 64k). This new "max_xattr" option can be specified with both -fsdev and -virtfs command line options, with the "local" and the "synth" fs drivers. The previous limit of 1024 is preserved as the default value. Link: https://lore.kernel.org/qemu-devel/b7631ac0d8dde0629bc7c4f2c4185d9f57= b962b4.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- fsdev/file-op-9p.h | 2 ++ fsdev/qemu-fsdev-opts.c | 6 ++++++ fsdev/qemu-fsdev.c | 2 +- hw/9pfs/9p-local.c | 9 +++++++++ hw/9pfs/9p-synth.c | 17 +++++++++++++++++ hw/9pfs/9p.c | 4 ++-- system/vl.c | 7 ++++++- 7 files changed, 43 insertions(+), 4 deletions(-) diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index 454761d81d..1d931144f4 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -101,6 +101,8 @@ typedef struct FsDriverEntry { FsThrottle fst; mode_t fmode; mode_t dmode; + /* temporary storage for parse_opts only */ + uint32_t max_xattr; } FsDriverEntry; =20 struct FsContext { diff --git a/fsdev/qemu-fsdev-opts.c b/fsdev/qemu-fsdev-opts.c index 07a18c6e48..c2c1e83611 100644 --- a/fsdev/qemu-fsdev-opts.c +++ b/fsdev/qemu-fsdev-opts.c @@ -46,6 +46,9 @@ static QemuOptsList qemu_fsdev_opts =3D { }, { .name =3D "dmode", .type =3D QEMU_OPT_NUMBER, + }, { + .name =3D "max_xattr", + .type =3D QEMU_OPT_NUMBER, }, =20 THROTTLE_OPTS, @@ -92,6 +95,9 @@ static QemuOptsList qemu_virtfs_opts =3D { }, { .name =3D "dmode", .type =3D QEMU_OPT_NUMBER, + }, { + .name =3D "max_xattr", + .type =3D QEMU_OPT_NUMBER, }, =20 { /*End of list */ } diff --git a/fsdev/qemu-fsdev.c b/fsdev/qemu-fsdev.c index 57877dad0a..f97103cf44 100644 --- a/fsdev/qemu-fsdev.c +++ b/fsdev/qemu-fsdev.c @@ -45,7 +45,7 @@ typedef struct FsDriverListEntry { static QTAILQ_HEAD(, FsDriverListEntry) fsdriver_entries =3D QTAILQ_HEAD_INITIALIZER(fsdriver_entries); =20 -#define COMMON_FS_DRIVER_OPTIONS "id", "fsdriver", "readonly" +#define COMMON_FS_DRIVER_OPTIONS "id", "fsdriver", "readonly", "max_xattr" =20 static FsDriverTable FsDrivers[] =3D { { diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index aa48306b0e..4708e170a4 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1527,6 +1527,15 @@ static int local_parse_opts(QemuOpts *opts, FsDriver= Entry *fse, Error **errp) const char *path =3D qemu_opt_get(opts, "path"); const char *multidevs =3D qemu_opt_get(opts, "multidevs"); =20 + uint64_t val =3D qemu_opt_get_number(opts, "max_xattr", + V9FS_MAX_XATTR_DEFAULT); + if (val > UINT32_MAX) { + error_setg(errp, "max_xattr value '%s' too large", + qemu_opt_get(opts, "max_xattr")); + return -1; + } + fse->max_xattr =3D val; + if (!sec_model) { error_setg(errp, "security_model property not set"); error_append_security_model_hint(errp); diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index b3743f6169..322dc3bb69 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -25,6 +25,8 @@ #include "qemu/rcu_queue.h" #include "qemu/cutils.h" #include "system/qtest.h" +#include "qapi/error.h" +#include "qemu/option.h" =20 /* Root node for synth file system */ static V9fsSynthNode synth_root =3D { @@ -629,12 +631,27 @@ static int synth_init(FsContext *ctx, Error **errp) return 0; } =20 +static int synth_parse_opts(QemuOpts *opts, FsDriverEntry *fse, Error **er= rp) +{ + uint64_t val =3D qemu_opt_get_number(opts, "max_xattr", + V9FS_MAX_XATTR_DEFAULT); + if (val > UINT32_MAX) { + error_setg(errp, "max_xattr value '%s' too large", + qemu_opt_get(opts, "max_xattr")); + return -1; + } + fse->max_xattr =3D val; + + return 0; +} + static bool synth_has_valid_file_handle(int fid_type, V9fsFidOpenState *fs) { return false; } =20 FileOperations synth_ops =3D { + .parse_opts =3D synth_parse_opts, .init =3D synth_init, .lstat =3D synth_lstat, .readlink =3D synth_readlink, diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e737629581..d1ec3c0c14 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -4483,8 +4483,8 @@ int v9fs_device_realize_common(V9fsState *s, const V9= fsTransport *t, =20 s->reclaiming =3D false; =20 - /* init xattr FID limit */ - s->ctx.xattr_fid_limit =3D V9FS_MAX_XATTR_DEFAULT; + /* init xattr FID limit from fsdev config */ + s->ctx.xattr_fid_limit =3D fse->max_xattr; s->ctx.xattr_fid_count =3D 0; =20 rc =3D 0; diff --git a/system/vl.c b/system/vl.c index 1c0da7df29..1d14e2e207 100644 --- a/system/vl.c +++ b/system/vl.c @@ -3260,7 +3260,7 @@ void qemu_init(int argc, char **argv) QemuOpts *fsdev; QemuOpts *device; const char *writeout, *sock_fd, *socket, *path, *security_= model, - *multidevs; + *multidevs, *max_xattr_str; =20 olist =3D qemu_find_opts("virtfs"); if (!olist) { @@ -3324,6 +3324,11 @@ void qemu_init(int argc, char **argv) if (multidevs) { qemu_opt_set(fsdev, "multidevs", multidevs, &error_abo= rt); } + max_xattr_str =3D qemu_opt_get(opts, "max_xattr"); + if (max_xattr_str) { + qemu_opt_set(fsdev, "max_xattr", max_xattr_str, + &error_abort); + } device =3D qemu_opts_create(qemu_find_opts("device"), NULL= , 0, &error_abort); qemu_opt_set(device, "driver", "virtio-9p-pci", &error_abo= rt); --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740385; cv=none; d=zohomail.com; s=zohoarc; b=YSh4N3hb3sd9NOnghi+aRGEFg+ofhaNNSOzA/r4DzLA/ffsKOiw1i8zD3fLr2LTUis09VNZtWMSwhLVczWqQ3URzxYpLULPLWhCNZNWvMI+4Oj9YTrLuH6vjwfZLBGJHthyUxt/mIxbvp+feEvvtcvz3S8x18Z+yuwPypBaVciA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740385; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zs07pzHmW7tkQmObc5X6hbxRDWBQWxGeCE3vT9miv2U=; b=UYY1j21B0Vat9JRjL9VdCUUATKbvdLKfLD/5F1eLkcZkaQAPylFVRB0FExECo9D0LURSCjqtTaLalRckeChSyYsfuZX/CjzZunIL06VlIiEAobmYk2c6PscF6zJbcNM91dY6z/rsX+dfCqTmgRA0VU0PyJ7Y/6n+LF1GkxBBo0U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740385904808.9276586660388; Mon, 29 Jun 2026 06:39:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCD6-0005WO-L8; Mon, 29 Jun 2026 09:39:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <44cb540d2d079ce2c785b130e163ab42b9e1a109@kylie.crudebyte.com>) id 1weCD4-0005MM-KO; Mon, 29 Jun 2026 09:39:38 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <44cb540d2d079ce2c785b130e163ab42b9e1a109@kylie.crudebyte.com>) id 1weCD2-0004Sy-V1; Mon, 29 Jun 2026 09:39:38 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=zs07pzHmW7tkQmObc5X6hbxRDWBQWxGeCE3vT9miv2U=; b=PkXLK c7lSO92VU5KYkxNVMUnQNqgEbyfpwM294tnLJKk1HahHDWEZN2xfNOiaIcbVWlFyG3TamOFL8fTWS 00tFWKgmd9MW+6aHL2pPH6J8ztrom8fVFMxUWWjj96eUKyMXXoP6itmvUDkUbYnvbWe4m03wfoo+3 sZy7AgHPO9dz08WzLxNSFsKSW71IBPaD7DG1EjhmeQv7KOSq3DtSjzfMEhoKc3e58Dx7U7sB4BQVJ FpoFbZYXo+Ml4KS4dNIICDQMuob8FCVRz2urs4y8YhTrjVpugLQs5tzLG3mKv0CcqgmBYhNQ9slmE tro3UuoZ8JspAipRbRLs6vraFbIDZLpi21cy4vM1wWyUE9+shcRlWR425K4h7CRHu/UeUdmRSwi92 i0R5VtWX4oL1XE9PTO2kYzhSTkBNvNh/1O2DlLhXxF7tX4X4cmytAALhP20fU/GmvB2YdcxyBXkdR ZIKW+YeDs61fhEgIRD3Qn7bDwwda9fr31kcJedGl+Hge9G+3XydwPL/nhv2BDBRnT1p2NTZ6iAEmn ThaWY04NaqVqq5Oc+Sfv2bjwguvPpq3wXdvXnPEMbi/HaaVJL4r5We5uSm12VDXH2mVrLg/mzj0iE 145aA8eGfSdxWDkDFWgjS3P3J/POpIu2cbvSw0o5QFeRaNOxxqDX5Be4CiNdy0=; Message-ID: <44cb540d2d079ce2c785b130e163ab42b9e1a109.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 11/23] qemu-options: document 9pfs max_xattr option To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=44cb540d2d079ce2c785b130e163ab42b9e1a109@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740386645158501 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add documentation for the new "max_xattr" command line option of 9pfs server, introduced by the previous commit. Link: https://lore.kernel.org/qemu-devel/b5a1a6ba299a49183d0032d9e4cd5e009d= 4aae47.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- qemu-options.hx | 28 ++++++++++++++++++++-------- 1 file changed, 20 insertions(+), 8 deletions(-) diff --git a/qemu-options.hx b/qemu-options.hx index f1874a0591..e44b47de68 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -1940,19 +1940,19 @@ ERST =20 DEF("fsdev", HAS_ARG, QEMU_OPTION_fsdev, "-fsdev local,id=3Did,path=3Dpath,security_model=3Dmapped-xattr|mapped= -file|passthrough|none\n" - " [,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmo= de]\n" + " [,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmo= de][,max_xattr=3Dmax]\n" " [[,throttling.bps-total=3Db]|[[,throttling.bps-read=3Dr][,throttling= .bps-write=3Dw]]]\n" " [[,throttling.iops-total=3Di]|[[,throttling.iops-read=3Dr][,throttli= ng.iops-write=3Dw]]]\n" " [[,throttling.bps-total-max=3Dbm]|[[,throttling.bps-read-max=3Drm][,= throttling.bps-write-max=3Dwm]]]\n" " [[,throttling.iops-total-max=3Dim]|[[,throttling.iops-read-max=3Dirm= ][,throttling.iops-write-max=3Diwm]]]\n" " [[,throttling.iops-size=3Dis]]\n" - "-fsdev synth,id=3Did\n", + "-fsdev synth,id=3Did[,max_xattr=3Dmax]\n", QEMU_ARCH_ALL) =20 SRST -``-fsdev local,id=3Did,path=3Dpath,security_model=3Dsecurity_model [,write= out=3Dwriteout][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmode] [,throttlin= g.option=3Dvalue[,throttling.option=3Dvalue[,...]]]`` +``-fsdev local,id=3Did,path=3Dpath,security_model=3Dsecurity_model [,write= out=3Dwriteout][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmode][,max_xattr= =3Dmax] [,throttling.option=3Dvalue[,throttling.option=3Dvalue[,...]]]`` \=20 -``-fsdev synth,id=3Did[,readonly=3Don]`` +``-fsdev synth,id=3Did[,readonly=3Don][,max_xattr=3Dmax]`` Define a new file system device. Valid options are: =20 ``local`` @@ -2026,6 +2026,12 @@ SRST Let every is bytes of a request count as a new request for iops throttling purposes. =20 + ``max_xattr=3Dmax`` + Specifies the maximum number of concurrent xattr FIDs allowed for + this export. The default is 1024. Set to 0 for allowing an infinite + number of xattr FIDs. This limit prevents host memory exhaustion + attacks by capping the number of simultaneous xattr FIDs. + -fsdev option is used along with -device driver "virtio-9p-...". =20 ``-device virtio-9p-type,fsdev=3Did,mount_tag=3Dmount_tag`` @@ -2045,14 +2051,14 @@ ERST =20 DEF("virtfs", HAS_ARG, QEMU_OPTION_virtfs, "-virtfs local,path=3Dpath,mount_tag=3Dtag,security_model=3Dmapped-xat= tr|mapped-file|passthrough|none\n" - " [,id=3Did][,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfm= ode][,dmode=3Ddmode][,multidevs=3Dremap|forbid|warn]\n" - "-virtfs synth,mount_tag=3Dtag[,id=3Did][,readonly=3Don]\n", + " [,id=3Did][,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfm= ode][,dmode=3Ddmode][,multidevs=3Dremap|forbid|warn][,max_xattr=3Dmax]\n" + "-virtfs synth,mount_tag=3Dtag[,id=3Did][,readonly=3Don][,max_xattr=3D= max]\n", QEMU_ARCH_ALL) =20 SRST -``-virtfs local,path=3Dpath,mount_tag=3Dmount_tag ,security_model=3Dsecuri= ty_model[,writeout=3Dwriteout][,readonly=3Don] [,fmode=3Dfmode][,dmode=3Ddm= ode][,multidevs=3Dmultidevs]`` +``-virtfs local,path=3Dpath,mount_tag=3Dmount_tag ,security_model=3Dsecuri= ty_model[,writeout=3Dwriteout][,readonly=3Don] [,fmode=3Dfmode][,dmode=3Ddm= ode][,multidevs=3Dmultidevs][,max_xattr=3Dmax]`` \=20 -``-virtfs synth,mount_tag=3Dmount_tag`` +``-virtfs synth,mount_tag=3Dmount_tag[,max_xattr=3Dmax]`` Define a new virtual filesystem device and expose it to the guest using a virtio-9p-device (a.k.a. 9pfs), which essentially means that a certa= in directory on host is made directly accessible by guest as a pass-throu= gh @@ -2118,6 +2124,12 @@ SRST Specifies the tag name to be used by the guest to mount this export point. =20 + ``max_xattr=3Dmax`` + Specifies the maximum number of concurrent xattr FIDs allowed for + this export. The default is 1024. Set to 0 for allowing an infinite + number of xattr FIDs. This limit prevents host memory exhaustion + attacks by capping the number of simultaneous xattr FIDs. + ``multidevs=3Dremap|forbid|warn`` Specifies how to deal with multiple devices being shared with the same 9p export in order to avoid file ID collisions on guest. --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740407; cv=none; d=zohomail.com; s=zohoarc; b=GVj4aWiWDU87Zbvp1EUy0jJ6dMAsA1DVawm/4pzNvKLSV5RgpBOJGuwk9RmfgzdrFOH/qREOoN73NHVMwfkjjIVDbvKlFRTkp67PFHao77RmnVgjwaFlhVCvg8NbUPqW1gm6STCbR6kK+0SeGw/DMm0j4CzGwAhbhqJyusKclf4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740407; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bahZBcXVLOQmQeZVYzUyGC3qGp5fyPz+QA3ZZ0QrvZs=; b=KKp3ubPa+Feu8pYG5bp8CiOLerprZzfEOp/AcH0J/j2qRR69JHbvS4aIWcHgiSah9viW5or0BxasJ1GHXatbeXt2k4QtjGuUEHEI+Vh95/go1mXk/sfne+wLO+XxKeODppUwEM/Pw7c2G9BzC3YVw1aaVaXkuMcQx+kacXJReHQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740407038936.1732759683168; Mon, 29 Jun 2026 06:40:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCDH-0005um-6n; Mon, 29 Jun 2026 09:39:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <54b8f64c422d0ed6d992387f0de419420cdb9fea@kylie.crudebyte.com>) id 1weCDE-0005tO-6A; Mon, 29 Jun 2026 09:39:48 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <54b8f64c422d0ed6d992387f0de419420cdb9fea@kylie.crudebyte.com>) id 1weCDC-0004Vt-8R; Mon, 29 Jun 2026 09:39:47 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=bahZBcXVLOQmQeZVYzUyGC3qGp5fyPz+QA3ZZ0QrvZs=; b=fyPp5 LZxIt1jZpXd1hHSuEX+Zjsrk6k2SomFP2NCHcSaRm0aavkMBp9N6+98vZrMuxfNiNKW/v8pCVjdYF 6T0KUFJYXyz7Dnnx9HoFjXGpAM6IM+wQLRN3KnJ80igI47EHfz4UAK+vffNvhC6BTifjj+Ym8H7tu yY6MIrNgbGc8twGSPFTRDDdfSNGMA4otWXXlXSzkogmO+WR+aBIM/hvkZY8bLPk+f/g5f2PNCbRiM alLEBxm6noNg70bgNfm41QnN09ZAviMkwvGYQBmuOqp1EWh88SgpiT/7/rSkDxA1rxq9CAPOB5VSd RIsgor9iYc83NcyGOOXpAzX3p7usi1cEoIZ0sa5lq/YcEhT/WDPgDH557acjRCnEIXbYZVtFGOSJn ouPoKMEn23S6gqpdTdqyGNHssoOiKMfTo3hyjtmg5jhgpz0J5wvfkHcJEb1/18ColXplEtxKe2Dvj lV5YEdKoGoZBDkUO/nF/Psh/LSwUqKnpgJo0/J69IOSha6tOVUPnJY2+YCrlMUXpqM8RuCa4IXdKR qF7tBgI0BYfSy9i0MZKWfoeq56vZJCTMABgxvainYPlVyYNZz9tPI/ye5sG9YztVCe2d1573Z3toT a6Q96Nv90Zf5HFXd1EGVpxj+kRoh9j98Ot9/A2O0VZ9BvDaO32doWZUyE3qCHQ=; Message-ID: <54b8f64c422d0ed6d992387f0de419420cdb9fea.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 12/23] tests/9p: add Tread / Rread test client functions To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=54b8f64c422d0ed6d992387f0de419420cdb9fea@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740408698158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add v9fs_tread() and v9fs_rread() functions to the 9P test client for reading files from 9pfs server in test cases. Link: https://lore.kernel.org/qemu-devel/049bdd1e66416f5200fb3d59d2da5e8ec1= 49926d.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/libqos/virtio-9p-client.c | 45 +++++++++++++++++++++++++++ tests/qtest/libqos/virtio-9p-client.h | 33 ++++++++++++++++++++ tests/qtest/virtio-9p-test.c | 1 + 3 files changed, 79 insertions(+) diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index af01d4c345..b9785ef8cb 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -241,6 +241,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RUNLINKAT ? "RUNLINKAT" : id =3D=3D P9_RFLUSH ? "RFLUSH" : id =3D=3D P9_RREADDIR ? "RREADDIR" : + id =3D=3D P9_RREAD ? "RREAD" : ""; } =20 @@ -1103,3 +1104,47 @@ void v9fs_runlinkat(P9Req *req) v9fs_req_recv(req, P9_RUNLINKAT); v9fs_req_free(req); } + +/* size[4] Tread tag[2] fid[4] offset[8] count[4] */ +TReadRes v9fs_tread(TReadOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + + uint32_t body_size =3D 4 + 8 + 4; + + req =3D v9fs_req_init(opt.client, body_size, P9_TREAD, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_uint64_write(req, opt.offset); + v9fs_uint32_write(req, opt.count); + v9fs_req_send(req); + + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rread(req, opt.rread.count, opt.rread.data); + } + req =3D NULL; /* request was freed */ + } + + return (TReadRes) { + .req =3D req, + .count =3D opt.rread.count ? *opt.rread.count : 0 + }; +} + +/* size[4] Rread tag[2] count[4] data[count] */ +void v9fs_rread(P9Req *req, uint32_t *count, void *data) +{ + v9fs_req_recv(req, P9_RREAD); + v9fs_uint32_read(req, count); + if (data && *count > 0) { + v9fs_memread(req, data, *count); + } + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index e3221a3104..37f2517cff 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -473,6 +473,37 @@ typedef struct TunlinkatRes { P9Req *req; } TunlinkatRes; =20 +/* options for 'Tread' 9p request */ +typedef struct TReadOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID of file to read from (required) */ + uint32_t fid; + /* start position of read from beginning of file (optional) */ + uint64_t offset; + /* how many bytes to read (required) */ + uint32_t count; + /* data being received from 9p server as 'Rread' response (optional) */ + struct { + uint32_t *count; + void *data; + } rread; + /* only send Tread request but not wait for a reply? (optional) */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TReadOpt; + +/* result of 'Tread' 9p request */ +typedef struct TReadRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; + /* amount of bytes read */ + uint32_t count; +} TReadRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -524,5 +555,7 @@ TlinkRes v9fs_tlink(TlinkOpt); void v9fs_rlink(P9Req *req); TunlinkatRes v9fs_tunlinkat(TunlinkatOpt); void v9fs_runlinkat(P9Req *req); +TReadRes v9fs_tread(TReadOpt opt); +void v9fs_rread(P9Req *req, uint32_t *count, void *data); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 1c69d41e33..8ccec77e70 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -31,6 +31,7 @@ #define tsymlink(...) v9fs_tsymlink((TsymlinkOpt) __VA_ARGS__) #define tlink(...) v9fs_tlink((TlinkOpt) __VA_ARGS__) #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) +#define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740414; cv=none; d=zohomail.com; s=zohoarc; b=RVx9eryBI4b1BbYeUtH6XFOh1dlReaSgw5oVlA9bKrao4UXOQZcD8FPB2MCINRNNKQlNolFYUJVdV9pGSUz3fqk4Ec48bvW9BzM+a8pmstmFU0zPgEPsI0lHHCuG8GFFr67XGjQV8TOU6UG3u7L7/6V+XNazrJJ3eDly9y2W5+U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740414; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VmjlScsJMUxh/cTqMAsp/BT45yrkm2ub7EgeeSdl4HE=; b=F9BNv1BMCErrpA4W1s7jtqNCePpWxKFa0swb7hFU0g9zghtHu+IQPpULWSEV2LfQhou6lLxjML9vR/UL/jI7z6G6aQ58AidZbg+g+XS+0VI5CQlEYxJ2iSXhVzSibuVMg6BKkZ4ASEfUtIuT0freyZszYGiTe5NRWII6zz8a77s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178274041498066.20903627320479; Mon, 29 Jun 2026 06:40:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCDN-0006LX-U9; Mon, 29 Jun 2026 09:39:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCDM-0006Hr-O0; Mon, 29 Jun 2026 09:39:56 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCDK-0004Z0-VR; Mon, 29 Jun 2026 09:39:56 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=VmjlScsJMUxh/cTqMAsp/BT45yrkm2ub7EgeeSdl4HE=; b=Q2foN f4+RxjCTQo1JpNOe1oS2pUI5J/uT131G1BCnGx9G26rWSF7I2JxB0F3F9XbVSlBki8h2SLp3IZsi7 53kmq0TE7899au4xCLgA7slhmRYbvkEVBqvgBRfZj5cc3DxMkvrX+2QOvXJMpnwEfStAquMpokxs/ 6tcZGMfJGIPpWR7odvY3JpKGMCFQUJRtWoBDIBCYRDew438KFKn3Ta/mPkSy9XgMG6Yf4xg1IwzAn 2/aUP4CFJKfw5WM8ofnGc3jYsjpFZ4Pc0DlSlEL2yZZSuoYOemksppEwuu0Lkk9iqjHPwXgufshom 5VgdF6Os749CVG00z99n8LNlSg4dRtrHRq2DswvAlmCIt3WL8EL91ya/z+zzUzwNbw9gLDo42ez+S J8GvOPIqIsFg5TY7YYb/bXke0VSnXKVRgnSFLlGtc2KpZqceCaBQ0+idMAfdSQ4m2MXyX13Eq0pvb neChz0IuzyzIx1Cu4whShcDAluwfCkLErhuvNlxZ0TyFG14QoJuDL8vOzbqo9suMV5RcE8OwvZzNV 1nszAoqT0rENfEdXJaRCALwQ0YBlO9R+adzE+pR+/DTrEvKfdLvrqGwZcSWT/FhbAJ9wYKp2EDCuo 4MAcOqLgL1sGqyPJgrSblR5sfh0sNz8H//KCU2AB+4iTBOhBhASVlc5dW8Hhzk=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 13/23] tests/9p: add Tclunk / Rclunk test client functions To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=c46150530b3dd6370affa3422f2175ac4668836a@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740416737158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add v9fs_tclunk() and v9fs_rclunk() functions to the 9P test client for closing file handles (or "FIDs") in test cases. Link: https://lore.kernel.org/qemu-devel/d53f0337eb7f8525a14e394599d809ecf6= 805e5e.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/libqos/virtio-9p-client.c | 34 +++++++++++++++++++++++++++ tests/qtest/libqos/virtio-9p-client.h | 22 +++++++++++++++++ tests/qtest/virtio-9p-test.c | 1 + 3 files changed, 57 insertions(+) diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index b9785ef8cb..83af6dab5d 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -242,6 +242,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RFLUSH ? "RFLUSH" : id =3D=3D P9_RREADDIR ? "RREADDIR" : id =3D=3D P9_RREAD ? "RREAD" : + id =3D=3D P9_RCLUNK ? "RCLUNK" : ""; } =20 @@ -1148,3 +1149,36 @@ void v9fs_rread(P9Req *req, uint32_t *count, void *d= ata) } v9fs_req_free(req); } + +/* size[4] Tclunk tag[2] fid[4] */ +TClunkRes v9fs_tclunk(TClunkOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + + req =3D v9fs_req_init(opt.client, 4, P9_TCLUNK, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_req_send(req); + + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rclunk(req); + } + req =3D NULL; /* request was freed */ + } + + return (TClunkRes) { .req =3D req }; +} + +/* size[4] Rclunk tag[2] */ +void v9fs_rclunk(P9Req *req) +{ + v9fs_req_recv(req, P9_RCLUNK); + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index 37f2517cff..f7ef7f0067 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -504,6 +504,26 @@ typedef struct TReadRes { uint32_t count; } TReadRes; =20 +/* options for 'Tclunk' 9p request */ +typedef struct TClunkOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID to clunk (required) */ + uint32_t fid; + /* only send Tclunk request but not wait for a reply? (optional) */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TClunkOpt; + +/* result of 'Tclunk' 9p request */ +typedef struct TClunkRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; +} TClunkRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -557,5 +577,7 @@ TunlinkatRes v9fs_tunlinkat(TunlinkatOpt); void v9fs_runlinkat(P9Req *req); TReadRes v9fs_tread(TReadOpt opt); void v9fs_rread(P9Req *req, uint32_t *count, void *data); +TClunkRes v9fs_tclunk(TClunkOpt opt); +void v9fs_rclunk(P9Req *req); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 8ccec77e70..099c5e0ca0 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -32,6 +32,7 @@ #define tlink(...) v9fs_tlink((TlinkOpt) __VA_ARGS__) #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) #define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) +#define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740418; cv=none; d=zohomail.com; s=zohoarc; b=fmL+5z6W4LHMyJZaRn9XsnyO1LVjRO2gf5PuVdiRuxm+Ms2qEM9vFv/9SUBhwBtUfXVuobKyxZlcVrgD8iLGaybyRk0NuKdP9HgKa622WSpZO27T9CRkYht3OUh4cz09UcKvIUdwLJn/gkdyV3iLIqaMHZqwJhENRN/1sMODRmo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740418; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GwRstn34sKMvUe1KtPyZroSCibYba8HW5UZRdUMDerA=; b=V4JZI2xB9evnxP4Gb0+G9WuYVj015/jr2mbL9iaFFIkDbeex3z3fGzjnpO//sDz0Tln6+BCNjXh3RVjxJEMJz34sIax2AwofHJ0zUNSYjSpr0qWjfdS1qguazvI0v2XJEnpPWDDt62UaRo1M7342J2j2TGoi7aE6/5+ZyDdGVKs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740418207364.4308126429289; Mon, 29 Jun 2026 06:40:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCDW-0006by-6n; Mon, 29 Jun 2026 09:40:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7664feb26fef19caa4d72e07a9097fa625b593e5@kylie.crudebyte.com>) id 1weCDU-0006Wh-0A; Mon, 29 Jun 2026 09:40:04 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7664feb26fef19caa4d72e07a9097fa625b593e5@kylie.crudebyte.com>) id 1weCDR-0004ZN-UK; Mon, 29 Jun 2026 09:40:03 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=GwRstn34sKMvUe1KtPyZroSCibYba8HW5UZRdUMDerA=; b=fjWCI tSRu98WT+/q4yxyaBofZF/oaiOi0lNIypGoUh8vmY3A0CT94QeODYkjc28hGORcpTXjkK3/rhzdXU 22A+gemTyTb9Vym9b1DuMtBg6ciDzJEHTnoYTsy3p8+9RzBFIGeoR0iWsw58VLJwoc2RaFik8ww3j man48wT4Jh2ISskv4WiTxsCkYN4q+3o2AIwJxIXTtTjftsnu73yyAI/k4/01oDxri4BIlfpmtHLsU p/gRqZZNWWqOczT4ZxwG3mnEJIUE5w8sozd5r+ZG6aIFbCOxeI2nhc1abiUl+H/3Be/bWsxrLHrtZ QyEwXCcp1rY18m/KEw0RlRejOl8hC6IzLPsvPMfVpERa/7LKo8M1VxL2rpY0xuVcxuXyGOqj5i/pE BlH97iOxokz1sS2sDkME4d06De9iOrohNEblDX/TVkJsZ4WvQQmSlNIrpBOwsCDLVTd2PQpmoUMpd abr1mX9FGooivHFAtlPXXxaOMRw021gkjXihmOBvmRb/skM5TAaxda3NNkGgOUJFoEO0mk2QHfBOe HEhE/H6Mf3v89p/4VMMsCPTqP+6pU4RGIZ2xIRE0AXq9bXwWx539PHYYPpfevbJbS/DPmy7mZpqAQ Uc0Aw4gWQU2R5GTXVyipNVI5UTvAbvV/tw7B+jHZBi9dHCWSVpfyWbtiYwKTgM=; Message-ID: <7664feb26fef19caa4d72e07a9097fa625b593e5.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 14/23] tests/9p: add Txattrcreate / Rxattrcreate test client functions To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=7664feb26fef19caa4d72e07a9097fa625b593e5@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740418748158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add v9fs_txattrcreate() and v9fs_rxattrcreate() functions to the 9P test client for testing creation of xattrs with 9pfs server. Link: https://lore.kernel.org/qemu-devel/5dbc5061dab1f7829fffc40bf89d7ff443= e4bcab.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/libqos/virtio-9p-client.c | 45 +++++++++++++++++++++++++++ tests/qtest/libqos/virtio-9p-client.h | 30 ++++++++++++++++++ tests/qtest/virtio-9p-test.c | 1 + 3 files changed, 76 insertions(+) diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index 83af6dab5d..305b0dac63 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -243,6 +243,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RREADDIR ? "RREADDIR" : id =3D=3D P9_RREAD ? "RREAD" : id =3D=3D P9_RCLUNK ? "RCLUNK" : + id =3D=3D P9_RXATTRCREATE ? "RXATTRCREATE" : ""; } =20 @@ -1182,3 +1183,47 @@ void v9fs_rclunk(P9Req *req) v9fs_req_recv(req, P9_RCLUNK); v9fs_req_free(req); } + +/* size[4] Txattrcreate tag[2] fid[4] name[s] attr_size[8] flags[4] */ +TXattrCreateRes v9fs_txattrcreate(TXattrCreateOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + g_assert(opt.name); + + uint32_t body_size =3D 4 + 8 + 4; + uint16_t string_size =3D v9fs_string_size(opt.name); + + g_assert_cmpint(body_size, <=3D, UINT32_MAX - string_size); + body_size +=3D string_size; + + req =3D v9fs_req_init(opt.client, body_size, P9_TXATTRCREATE, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_string_write(req, opt.name); + v9fs_uint64_write(req, opt.size); + v9fs_uint32_write(req, opt.flags); + v9fs_req_send(req); + + err =3D 0; + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rxattrcreate(req); + } + req =3D NULL; /* request was freed */ + } + + return (TXattrCreateRes) { .req =3D req, .err =3D err }; +} + +/* size[4] Rxattrcreate tag[2] */ +void v9fs_rxattrcreate(P9Req *req) +{ + v9fs_req_recv(req, P9_RXATTRCREATE); + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index f7ef7f0067..c432b0daee 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -524,6 +524,34 @@ typedef struct TClunkRes { P9Req *req; } TClunkRes; =20 +/* options for 'Txattrcreate' 9p request */ +typedef struct TXattrCreateOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID to convert to xattr fid (required) */ + uint32_t fid; + /* name of the xattr (required) */ + const char *name; + /* size of the xattr value (required) */ + uint64_t size; + /* flags: P9_XATTR_CREATE or P9_XATTR_REPLACE (optional) */ + uint32_t flags; + /* only send Txattrcreate request but not wait for a reply? (optional)= */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TXattrCreateOpt; + +/* result of 'Txattrcreate' 9p request */ +typedef struct TXattrCreateRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; + /* error code if Rlerror received */ + uint32_t err; +} TXattrCreateRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -579,5 +607,7 @@ TReadRes v9fs_tread(TReadOpt opt); void v9fs_rread(P9Req *req, uint32_t *count, void *data); TClunkRes v9fs_tclunk(TClunkOpt opt); void v9fs_rclunk(P9Req *req); +TXattrCreateRes v9fs_txattrcreate(TXattrCreateOpt opt); +void v9fs_rxattrcreate(P9Req *req); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 099c5e0ca0..99a897b158 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -33,6 +33,7 @@ #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) #define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) #define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) +#define txattrcreate(...) v9fs_txattrcreate((TXattrCreateOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740424; cv=none; d=zohomail.com; s=zohoarc; b=XHuSJEGRwuCj1JeHOusO9vmMbeBIXrvj7TINugowSzV6ZDftClfwCrPQvab/owCPlkEoPRi8hKFT8Cf579TmN2bBv4WUn1KfTKDxtpxhDdaQX0jq2H7vNsoCxZbMbGpEd6KX7cQcKF0eqBLiprgElv3yAkSysTpvhIINHdrwb98= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740424; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JFJiWtJxyrEw3flRMhi/G/BAccH/foEXolMe42jdQ+k=; b=O1n9vFcF7FTrOnxYaZ8OPxaXwoRkgexE/0z0E6l8t2TPapjvs787mH/BppkQKF1ULl2NG+30ybdJBu80T/S3t6OorzBDQp4zsv9H+0G2lib7IikWAeiGmUKMIBvtk0ca9t8MsmLqSTlPPUr05TkeKIv77Ps78ZL8G/YsQSRw3TQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740424551449.9348547287799; Mon, 29 Jun 2026 06:40:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCDl-0007J0-Ry; Mon, 29 Jun 2026 09:40:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <0e3085ddc7fb137b727829913c20ad9d08577bdb@kylie.crudebyte.com>) id 1weCDk-0007Ht-VD; Mon, 29 Jun 2026 09:40:20 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <0e3085ddc7fb137b727829913c20ad9d08577bdb@kylie.crudebyte.com>) id 1weCDj-0004pf-9n; Mon, 29 Jun 2026 09:40:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=JFJiWtJxyrEw3flRMhi/G/BAccH/foEXolMe42jdQ+k=; b=irLz8 5/WwLPFfe7nbjfj9aY3GE6vxNlnUTpLjyi5FVJvZKeMRe0QtKkaMnr9RIR1lRjDMR5/u5sFwewNJx XV1CCAJwqLITBRL+zuohhw5bFT4LsItrFuZMM0ueSqppAEEWfX653VyVa4yi+5ykuaCR5x3VicbFM wGgeMk3R+me//juA177Qy7vigspaOpBGfHr9+VDTEF1d4n24mLeyIjPyUPw7NoupEEprPobSodY4Y 8YSEi2Uc9iMQwinn3uKQBdJ+k96y62H3N5KyyJIbFe5MGaDfg5Aq/+9F1T2ow8k5RJiwwLtrgpBMC /BlsOI4CmgsE7WDPdbAwcoLvCyQNzAFkpaVPrWuVvZ3GR65UIjiq+rFvvSiBZ04jDhcuSas6FaRTO pmzWlALdh5AHm/SldNppgkhxpBvK470ZDznpM4deB5U/Fbme0B3X3zYsI3jHYV4e+ysyr4O27RjLQ D1B4n3FRIRKNLeTpoJ4XzDAxaoq8g6YE+IdQD/Z6qKcPsbtqyl89ZTSaRvFo/7oKF+MraUXTPyvfk UuxGwAh1RhokrKhvvBr+SeEyKuyO2fYPopc33/UNQ8DLkKL51AL2IAh5issdeAJiRGJPRP5AvZfV2 LCcJ9enx4dc7gSFi2aPJeivE2hXbnbKdb9NHVVFQkmOqWwxeCoIRE+93qfxa08=; Message-ID: <0e3085ddc7fb137b727829913c20ad9d08577bdb.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 15/23] hw/9pfs: enable xattr (mockup) support for synth fs driver To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=0e3085ddc7fb137b727829913c20ad9d08577bdb@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740424958158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The synth backend is used for testing only. Enable xattr operations by making lsetxattr and lremovexattr callbacks to return success result. They are still actually not doing anything, they just pretend to be working to prevent 9pfs server from erroring out on xattr requests. This allows the subsequent test case patches to verify xattr FID limit enforcement. Link: https://lore.kernel.org/qemu-devel/9c1c7128135f3bd9c2f62a3f64bb730b6a= 94ec7a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p-synth.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index 322dc3bb69..4b0732e093 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -477,15 +477,15 @@ static int synth_lsetxattr(FsContext *ctx, V9fsPath *= path, const char *name, void *value, size_t size, int flags) { - errno =3D ENOTSUP; - return -1; + /* pretend it worked */ + return 0; } =20 static int synth_lremovexattr(FsContext *ctx, V9fsPath *path, const char *name) { - errno =3D ENOTSUP; - return -1; + /* pretend it worked */ + return 0; } =20 static int synth_name_to_path(FsContext *ctx, V9fsPath *dir_path, --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740438; cv=none; d=zohomail.com; s=zohoarc; b=SuKTfZ/RemzU/gtmpEMim8aZPAjruGtd2q4H4pDcDHfssyGKJreJuf0Xo8X//am2LYxdtxA4y+78cLcfrFBHBMv8nLVnq3vreBSg6vsl+bhMz+GO1fwzz91uPZYztLfQH5bxNeMzmQLK50qCtnIggzsz1zMQ41bI0PzQ+cuVIrQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740438; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HbXPBJCXbwc+UJtT3KR5/IXT9P+T41ck2z/jzLjzqpE=; b=gtACoAEmCdBLEcmaccMeLCkeeajmKJt4JC24pi4BFEL7c6IjJaweqxe7pwJ5Z7+ipD6ma7B6OGOHbCYxS4v0CI3g5ZKOq8ZS883qvOhw/3ut/J5Mv2ZU4LJckaygAQ0vZ6mZbg1F8DGlUR3TJbPesK4pM/BBA9XjnJEYpoKWFDs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740438483563.2673538118872; Mon, 29 Jun 2026 06:40:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCDu-0007QB-Up; Mon, 29 Jun 2026 09:40:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7e42d569a68aec6b0b6f1f068328c5c4ff20bc72@kylie.crudebyte.com>) id 1weCDt-0007Pl-HY; Mon, 29 Jun 2026 09:40:29 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7e42d569a68aec6b0b6f1f068328c5c4ff20bc72@kylie.crudebyte.com>) id 1weCDs-0004rl-2l; Mon, 29 Jun 2026 09:40:29 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=HbXPBJCXbwc+UJtT3KR5/IXT9P+T41ck2z/jzLjzqpE=; b=P62Lq neNLPD9M3H3SZsC4xJiYqXH7JeYf4/B5nVxmj9clogI6dpDWBDTD9J67hotNOR1w9wUCAvyVaKkD1 loEMBQ4gD/TaSDM59joGbYkARdxEtSkQw61yK4tf+7g7pd366Uez9jaVXyepLvP3jh+GDIlsTgC0N 5nmjZaq7jaFaRyQrvTO+4y3u2pzqDy01loIjmdf1lojA8X1r9Oy6K6cBzi+GBrgdkn2T8N89qwFqh rFKnsxfzXsxdtNZwlJAnOpdA9noAY2tapDVZa251VCiaSDA8avpq0dkhr1HA3xSQVGYeTbYoT+jbz VBbb1UW64jYFl4eRcIypyM0fXFwuQ6W0pIg0RYmbVcJOqVqayA3NQ4S+UNKK74SILYx0wgIJK3VmA BD94UvKsbSut7U3tuUDO2bw7Xa1oR1v62RTBkXcg0BLx/Af3J5H+TwFmblarkuWQTocH2rPZcn15s tWEUms6fwX5lQUt8ckl1I43oknDWTds/EiLbeVT0E80uhPRoGCwaCRpW8eEJuwY8MqTYVnVaAOK9f 2d/ZUS/4pYaecSrst/XtL/DWEjap8z7mz7qCirxkORg2WI2qwpmUcliNBKWtCzFFvMpRhyffBxqyx N/yAlqTJHnTaH4SRR8xq4zZXRnTJiamkhKFqno5SvuPYHPPBjRs7P8ouITZMl0=; Message-ID: <7e42d569a68aec6b0b6f1f068328c5c4ff20bc72.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 16/23] hw/9pfs: add xattr count query interface to fs synth driver To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=7e42d569a68aec6b0b6f1f068328c5c4ff20bc72@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740439038158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a synthetic "/stat/xattr_count" file path that, if being read by 9p client, returns the 9p server internal xattr FID counter to client. This allows to test and verify that the xattr FID limit is being enforced correctly. Link: https://lore.kernel.org/qemu-devel/357c20fc244c04dcbd36b13aa20a5c9b20= 34e9f0.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p-synth.c | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index 4b0732e093..3b3654b282 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -565,6 +565,19 @@ static ssize_t v9fs_synth_qtest_flush_write(void *buf,= int len, off_t offset, return 1; } =20 +/* transmits internal xattr counter to client */ +static ssize_t v9fs_synth_read_xattr_count(void *buf, int len, off_t offse= t, + void *arg) +{ + FsContext *ctx =3D arg; + size_t local_count =3D ctx->xattr_fid_count; + if (len < (int)sizeof(size_t)) { + return -ENOSPC; + } + memcpy(buf, &local_count, sizeof(size_t)); + return sizeof(size_t); +} + static int synth_init(FsContext *ctx, Error **errp) { QLIST_INIT(&synth_root.child); @@ -626,6 +639,19 @@ static int synth_init(FsContext *ctx, Error **errp) g_free(name); } } + + /* Directory for internal statistic queries */ + { + V9fsSynthNode *stat_dir =3D NULL; + ret =3D qemu_v9fs_synth_mkdir(NULL, 0755, "stat", &stat_dir); + assert(!ret); + + /* File for internal xattr count query */ + ret =3D qemu_v9fs_synth_add_file(stat_dir, 0444, "xattr_count", + v9fs_synth_read_xattr_count, + NULL, ctx); + assert(!ret); + } } =20 return 0; --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740521; cv=none; d=zohomail.com; s=zohoarc; b=CwJh9tSoI+phrPBfXTA3sDSsHVhwRoRTrpYsGDRTHZk+zpUSuqf3+LvE+zFWyt8HWniqzcF2FuhHGEYyxImrWFGiGZKwFwDBnoJNixL3ECzLN8zBbbUgqFbe7t/EvFeLDSRz9/cBPnJ9orFwTSviBWwqsizsjuCrgfJfD7f0WQU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740521; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t4QUJKC3tav/AW1Vk7YSwbFsYkjKNJAkyGxOrWh91zs=; b=OT824T4bz6LJvJEicMAHyf18e/5IJBxgUvvhz7LonfIzsmhYLSZdnOgNKTu55cgFdWc6biD8TxraXVLuQWS/djc0BwB8qHlZfES8FOnzOhznsnTgFXBYZe+it0J9l/JjUxQN9TqNqG8qxDKPlWoiJ5RYsKy2Q1/0hklln9RpfuY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178274052181177.83363077404795; Mon, 29 Jun 2026 06:42:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCE5-0007dS-BU; Mon, 29 Jun 2026 09:40:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCE1-0007Ys-RF; Mon, 29 Jun 2026 09:40:37 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCE0-0004tB-0p; Mon, 29 Jun 2026 09:40:37 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=t4QUJKC3tav/AW1Vk7YSwbFsYkjKNJAkyGxOrWh91zs=; b=lE0jZ OZWrdh3Cu6bm2zUwsQu68AAXFtzYCfI7tpx1qNQ9NmSQSj+ORfrT1u65k8n16bpGBzb1cbjNdFOd9 TV07Oi8uXDb4E2ayoywlpiSL0i7+j/GxdEilpSBLuelpSYWo9jNRYq+0x8XDpQU+dCSBZOp+RzecH ISaRHECGfs5bc1y0bPVw8JfJUc/+K8Agv+Jl/KnuzunYbquarx+4qnBCCZYKuzo5Y0fwyDm6CQYQD ZMKv1OYz09IVAQlyFXjddbCDxGaOIR8Vf8U93HcMUusapO4kmXrCzpfoQ6NNJPk3TQZSG1YV7A5CO r8p3AYFvl4P7CxixF9O/uIFr7GXi4XTgaQ1fouvmJ+CLn6ZSwianEW4Kdae8gIhxEBdzmp6ebR5Pi Rey6rJ1DA/TZ9e9WpcSCs/HzYFIdXDmfRVE+WGHLCZNnepyALWnpIgiE+9MXWEVm4kU5ypIFHbX1m 5/XtWLxEb8S09pG6zC6L9qhFJL/LWWq4CvUTYARyYUC5LpTbwMzzcWC8XsfTHfeVQyx0LioT66ut2 +NWtVTeuLPGQEzzPkCVxNhEWAvMHaoNJ2Hmp9jdiNZXlAplEEM0QQdknTgvPsHySdGuVFHg/3Uiwe dMNyzWLE3NNcuKF0fbItfK/s7qCTHgaChvqUERn8a0nWRwOtoO8Tfv/BFDWFvs=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 17/23] tests/9p: increase P9_MAX_SIZE for test client To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=df88255543667e7f14ac34d97e0ced142af18bdf@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740523406158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Increase the maximum 9P message size ('msize') of 9p test client from 4k to 32k to support larger messages. This is needed for the xattr tests being added with the subsequent patches which are going to transmit xattrs of size 8k. It would have also been possible to send them in multiple chunks, however let's not overcomplicate things. This new msize is still reasonable small compared to common msize values on production systems. Link: https://lore.kernel.org/qemu-devel/2dcb1243c80ea97d085af5171785850cf0= 12be36.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/libqos/virtio-9p-client.h | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index c432b0daee..4b04324503 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -21,7 +21,8 @@ #include "qgraph.h" #include "tests/qtest/libqtest-single.h" =20 -#define P9_MAX_SIZE 4096 /* Max size of a T-message or R-message */ +/* Max size of a T-message or R-message */ +#define P9_MAX_SIZE (32 * 1024) =20 typedef struct { QTestState *qts; --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740673; cv=none; d=zohomail.com; s=zohoarc; b=AJHCkFyVAwcK08D0WUxtUFMkLzZeUhEbxSWBjMaVm0cZHBE3MXuKr6w6KUZLDV2dwPFk1jLpxjYgG6d/y5W7KKo1nKragz5uOD1NJoBgho2GT20GSMJQcfVhHS6VMSgG+L7kgRpaq9MPTp5EFW1DT/MKHjh3e+5ff2T64K5ETxM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740673; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FJnTo+tWawD92WQKJyoQXjepZzMT1atyWHiIsi0MPy4=; b=Mw3112bosQauxSsUlA+nUN/ojYlK2hoiS1h1fzWDkFG/gkHiTHvq/8YQ2DDGdBUur8KUt5joYloJISfI19iWzO1f7h2yrkTe2fXfGvWCr3E9jUjM5ddsgSsGEFR9pUWeGww99X4ZLInfN1v3IZMCdYo5je4QxNSZBjnJWGelM10= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740673131649.7975442468271; Mon, 29 Jun 2026 06:44:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCEP-0007ph-Q4; Mon, 29 Jun 2026 09:41:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <84525ece6817f4e9760a1d484cab01123a546e92@kylie.crudebyte.com>) id 1weCEB-0007ky-NB; Mon, 29 Jun 2026 09:40:47 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <84525ece6817f4e9760a1d484cab01123a546e92@kylie.crudebyte.com>) id 1weCE7-0004xU-K4; Mon, 29 Jun 2026 09:40:45 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=FJnTo+tWawD92WQKJyoQXjepZzMT1atyWHiIsi0MPy4=; b=goBk8 xFMImZWfvmPRqzHwKLvWAswcQtKDlzGqYwVRKb99YXwjv0nx8BXhMuaa2sWJkJcf79LCxfr+zZLDn ba8Kl2MciQ6Ddyu8x2N8YEH1FBU3PgsrP7jcNZTY1fcF9vW8emKmhVZ+eunV3esXGpfWkPgY1/09l nGXbqOvj3Ws7OEMW6HzzcsE99p3gGM+5UxtVjiel+g8vnUKpI2cttJ0b1gMtrmi9kYNKZX5pTEc0x dEg0BAjZE8DP1yQxZ6PV6ZN+d6t8GlMQhnW5mLQ7RHP03OeRS9QKI/K2eN+VYFe6qgjVaL/iFth9K LkkQ+tOFmlnI1saFnW9NLYv3C547ls7xJe1ZBQwZjEKytzqju0RHd4IetF2W7qpZ6oaftkszztiD1 T3tKF+8fFHFgWv2FnTEe8/Sc5/eu1eWhqaIET77JXuL0e7h/0xJprc464CbGhyWwXo4jRkwp4MROd T+dd5/FD6AV95HGibMKRGxVkxluX0rHdmIT5n9BUe57N2L4XY7TikXvtTfUhCgLcAxso/6LE1P4In pxDsNjksutWo4awkxf4Ye2q1SnOo/Wdj3/+54x/JdIwT8jMkEzGmr+tmHR3OPh1M7eCsach0xDuc7 jtvUjQGPoNGO/ldXkaDoaCv3UrZI43zv53ofPgwcV6khk6IXXkAUMhXhY+D3L0=; Message-ID: <84525ece6817f4e9760a1d484cab01123a546e92.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 18/23] tests/9p: add virtio_9p_add_synth_driver_args() test client function To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=84525ece6817f4e9760a1d484cab01123a546e92@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740674583158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add virtio_9p_add_synth_driver_args() to allow appending custom QEMU options for individual 9p synth tests. Link: https://lore.kernel.org/qemu-devel/7fe3eca5d17292464676b68d0513052564= cd432a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/libqos/virtio-9p.c | 6 ++++++ tests/qtest/libqos/virtio-9p.h | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/tests/qtest/libqos/virtio-9p.c b/tests/qtest/libqos/virtio-9p.c index 186fcc1141..823756de8c 100644 --- a/tests/qtest/libqos/virtio-9p.c +++ b/tests/qtest/libqos/virtio-9p.c @@ -228,6 +228,12 @@ static void regex_replace(GString *haystack, const cha= r *pattern, g_string_assign(haystack, s); } =20 +void virtio_9p_add_synth_driver_args(GString *cmd_line, const char *args) +{ + /* append passed args to '-fsdev ...' group */ + regex_replace(cmd_line, "(-fsdev \\w[^ ]*)", "\\1,%s", args); +} + void virtio_9p_assign_local_driver(GString *cmd_line, const char *args) { g_assert_nonnull(local_test_path); diff --git a/tests/qtest/libqos/virtio-9p.h b/tests/qtest/libqos/virtio-9p.h index 480727120e..e7efeef7a1 100644 --- a/tests/qtest/libqos/virtio-9p.h +++ b/tests/qtest/libqos/virtio-9p.h @@ -44,6 +44,12 @@ struct QVirtio9PDevice { QVirtio9P v9p; }; =20 +/** + * Add required test specific args to the QEMU command line for the 9pfs + * 'synth' fs driver. + */ +void virtio_9p_add_synth_driver_args(GString *cmd_line, const char *args); + /** * Creates the directory for the 9pfs 'local' filesystem driver to access. */ --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740504; cv=none; d=zohomail.com; s=zohoarc; b=S/70Pf7uQ1Q5Z+TZXo+PV33GAsKBbq/eK4/vlQphHlUGpoxVbFlnqjzPV/2WdJ1qYO9nCHZvx0Z0mmqd2PvdgRzy6LmLOflg75b2T9XoDyRmsiQvzXl8R8SbYdwJt9nrKxZKzS92XnpxL7jjQzSCUgQ4divZhX+ohN2m+h3nvm4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740504; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KhONsg+nahNtMwSYb59cf3FhTJcdKmSnDqjMgz3VOKw=; b=m+ttNTQxfTI0D4G1O9QwDakVEP4vICy+nQhAzfbqmsyxniI4Slu8JnWJdg9RPx7etyJK5acOcWmHlf1djduxmv7+s4+K99l7Tlb5ToFBYl3uHxS5D4HOJXHLYU5olU8L7NLul6NBA/x4DTJhxNWdJPoK98PRHA8S5ZvQTFX4uh8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740504648468.9551686207333; Mon, 29 Jun 2026 06:41:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCEV-0007yH-Sj; Mon, 29 Jun 2026 09:41:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <0e1085819e444365bc3160f7b1adae3843b2da79@kylie.crudebyte.com>) id 1weCEH-0007oC-5f; Mon, 29 Jun 2026 09:40:53 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <0e1085819e444365bc3160f7b1adae3843b2da79@kylie.crudebyte.com>) id 1weCEE-00059L-Rz; Mon, 29 Jun 2026 09:40:52 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=KhONsg+nahNtMwSYb59cf3FhTJcdKmSnDqjMgz3VOKw=; b=Y795e V8D9LwmBjdEf2jCHNarVXcbdlbI8+9LqU456N7mR88h7IDnpA3/r4gebHbELiZMuMjz6BqdxO4o3I J/rIQ7HbsaDnJvZXmdynP8QJA0O9BmLoEhUx5jVn1o+zG/fEp/9uEmK9u19NOgGo6RZkz+oCqZ3Z+ FhJg4PGzqrVJKlTQAg6H3QbSw9rHI11zEz7indYhStna1BRTamr3kBKb2U19az4RGXLZDdy/O3Elj Bt4PhBNWz+a2pktV5NGjVNILtyVX4WX0RnQi3DHnhHMp7jOreoRL2TCG+OHgworlz8UBA7KZvd1T1 5VWK7Dq3ze5jRs6aHqBJWv3vIYX1DuFLom7W41GgBovvIisdXyOvhocpw3DJie5/dTRSb7lTHlkOj Ko15ocDemA0W2yn1an7PTuaQztS7T7G/PnT4FzJPfIVu40oBYxAtu+ydapVkrhV6vnVykmzu1epL4 rNWM0EpNQ28ODmCSZX8UTggXpEsn7UhbFKceRsfhACwx/bjW7Cb9MuibRDngcKmPR4/0x2r8NWB1G F7SaKDW91mhornX48I8W4Pcfir8SC4Gugr0jydBWV27pO5eHch5TSOHwyLzscu5XrIvYuMFSTQWIq lWtQAlAMpBO/bHMjAN/CjG6hTZMt3ad7zs+NMJKmPHWG0ddgi9veePZDi5bXZc=; Message-ID: <0e1085819e444365bc3160f7b1adae3843b2da79.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 19/23] tests/9p: add 3 xattr FID limit test cases (synth fs driver) To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=0e1085819e444365bc3160f7b1adae3843b2da79@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740505387158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add 3 test cases to verify correct xattr FID limit enforcement of 9pfs server. - 1. test with default max_xattr=3D1024 - 2. test with custom max_xattr=3D100 - 3. test with unlimited max_xattr=3D0 These are tests using the synth driver. Advantage: by using the synth driver the tests cannot only check when the xattr FID limit kicks in (server would return an Rlerror response with ENOSPC), but can also validate the current 9p server internal xattr FID counter at any moment. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://lore.kernel.org/qemu-devel/540c51faa074d9dd736bbf2170084a1228= 8e23ef.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/virtio-9p-test.c | 189 ++++++++++++++++++++++++++++++++++- 1 file changed, 188 insertions(+), 1 deletion(-) diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 99a897b158..2e88429dfa 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -35,6 +35,15 @@ #define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) #define txattrcreate(...) v9fs_txattrcreate((TXattrCreateOpt) __VA_ARGS__) =20 +/* + * xattr size to be used for xattr tests + * + * 64k is the max. xattr size supported by the Linux kernel, However btrfs + * for instance supports only 16219 bytes. So let's be conservative and + * just use 8k for the xattr tests. + */ +#define TEST_XATTR_SIZE (8 * 1024) + static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { QVirtio9P *v9p =3D obj; @@ -107,6 +116,42 @@ static bool fs_dirents_contain_name(struct V9fsDirent = *e, const char* name) return false; } =20 +/* + * Returns the current internal xattr FID count (works with synth driver o= nly). + */ +static size_t get_xattr_count(QVirtio9P *v9p) +{ + uint16_t nwqid; + v9fs_qid *wqid; + const char *xattr_count_path[] =3D { "stat", "xattr_count" }; + size_t xattr_count; + uint32_t bytes_read; + + /* walk to /stat/xattr_count file */ + uint32_t fid =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 2, .wnames =3D (char **)xattr_count_path, + .rwalk =3D { .nwqid =3D &nwqid, .wqid =3D &wqid } + }).newfid; + + /* open for read */ + tlopen({ + .client =3D v9p, .fid =3D fid, .flags =3D O_RDONLY, + .rlopen =3D { .qid =3D NULL, .iounit =3D NULL } + }); + + /* read the internal xattr FID count */ + tread({ + .client =3D v9p, .fid =3D fid, .offset =3D 0, .count =3D sizeof(xa= ttr_count), + .rread =3D { .count =3D &bytes_read, .data =3D &xattr_count } + }); + + /* cleanup */ + tclunk({ .client =3D v9p, .fid =3D fid }); + + return xattr_count; +} + /* basic readdir test where reply fits into a single response message */ static void fs_readdir(void *obj, void *data, QGuestAllocator *t_alloc) { @@ -248,6 +293,108 @@ static void do_readdir_split(QVirtio9P *v9p, uint32_t= count) g_free(wnames[0]); } =20 +/* + * Test 9p server's xattr FID count limit enforcement. + * + * Shared test code for both 'synth' and 'local' driver to verify correct + * behaviour of 9p server enforcing preconfigured xattr FID count limit + * correctly. + * + * @v9p: 9pfs client + * + * @max_xattr: max. allowed xattr FIDs, or -1 for infinite + * + * @check_counter: whether to verify 9p server internal xattr FID counter + * (only works with 'synth' fs driver) + */ +static void do_xattr_limit(QVirtio9P *v9p, int max_xattr, bool check_count= er) +{ + size_t count; + int i; + int limit =3D (max_xattr !=3D -1) ? max_xattr : V9FS_MAX_XATTR_DEFAULT= + 100; + g_autofree uint32_t *fids =3D g_new0(uint32_t, limit); + uint32_t err_fid =3D 0; + const char *file_path[] =3D { QTEST_V9FS_SYNTH_WRITE_FILE }; + g_autofree uint8_t *xattr_data =3D g_malloc(TEST_XATTR_SIZE); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + /* prepare xattr data with 'X' characters */ + memset(xattr_data, 'X', TEST_XATTR_SIZE); + + tattach({ .client =3D v9p }); + + /* create max. amount of permitted xattrs */ + for (i =3D 0; i < limit; i++) { + /* walk to create a new fid */ + fids[i] =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 1, .wnames =3D (char **) file_path + }).newfid; + + /* create new xattr fid */ + txattrcreate({ + .client =3D v9p, .fid =3D fids[i], .name =3D "user.test", + .size =3D TEST_XATTR_SIZE, .flags =3D 0 + }); + + /* transfer the xattr data */ + twrite({ + .client =3D v9p, .fid =3D fids[i], .offset =3D 0, + .count =3D TEST_XATTR_SIZE, .data =3D xattr_data + }); + + /* verify server internal xattr counter */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, (i + 1)); + } + + /* avoid virtio descriptor exhaustion */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* if xattrs are limited, the next xattr should fail */ + if (max_xattr !=3D -1) { + /* walk to create another fid */ + err_fid =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 1, .wnames =3D (char **) file_path + }).newfid; + + /* try to create one more xattr fid - should fail */ + txattrcreate({ + .client =3D v9p, .fid =3D err_fid, .name =3D "user.test_exceed= ", + .size =3D TEST_XATTR_SIZE, .flags =3D 0, + .expectErr =3D ENOSPC + }); + + /* verify internal xattr counter hasn't changed */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, limit); + } + } + + /* clunk all fids (should decrement xattr counter) */ + for (i =3D 0; i < limit; i++) { + tclunk({ .client =3D v9p, .fid =3D fids[i] }); + qvirtqueue_reset_pool(v9p->vq); + } + if (err_fid) { + tclunk({ .client =3D v9p, .fid =3D err_fid }); + } + + /* verify internal xattr counter is zero */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, 0); + } +} + static void fs_walk_no_slash(void *obj, void *data, QGuestAllocator *t_all= oc) { QVirtio9P *v9p =3D obj; @@ -508,6 +655,27 @@ static void fs_readdir_split_512(void *obj, void *data, do_readdir_split(obj, 512); } =20 +static void fs_synth_xattr_limit_default(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, V9FS_MAX_XATTR_DEFAULT, true); +} + +static void fs_synth_xattr_limit_custom(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, 100, true); +} + +static void fs_synth_xattr_limit_unlimited(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, -1, true); +} + =20 /* tests using the 9pfs 'local' fs driver */ =20 @@ -822,6 +990,18 @@ static void fs_deep_absolute_path(void *obj, void *dat= a, g_string_free(path, TRUE); } =20 +static void *synth_max_xattr_custom_opt(GString *cmd_line, void *arg) +{ + virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D100"); + return arg; +} + +static void *synth_max_xattr_unlimited_opt(GString *cmd_line, void *arg) +{ + virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D0"); + return arg; +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -872,7 +1052,14 @@ static void register_virtio_9p_test(void) fs_readdir_split_256, &opts); qos_add_test("synth/readdir/split_128", "virtio-9p", fs_readdir_split_128, &opts); - + qos_add_test("synth/xattr_limit/default", "virtio-9p", + fs_synth_xattr_limit_default, &opts); + opts.before =3D synth_max_xattr_custom_opt; + qos_add_test("synth/xattr_limit/custom", "virtio-9p", + fs_synth_xattr_limit_custom, &opts); + opts.before =3D synth_max_xattr_unlimited_opt; + qos_add_test("synth/xattr_limit/unlimited", "virtio-9p", + fs_synth_xattr_limit_unlimited, &opts); =20 /* 9pfs test cases using the 'local' filesystem driver */ opts.before =3D assign_9p_local_driver; --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740506; cv=none; d=zohomail.com; s=zohoarc; b=MMM27rQQshUg9N/wasVcWThcWDZyVT7gYEkQ7JG2qMuPOhqrTxEAjPM6XeeyLzjWaQIQcrHjbXjfW7LiZskqiLNIqoQroJk4ieSrnPKlJQwiTwFWbKhAHo9qdhiBFIkROLtix0LW7NLW20iNXVZRiEcJp+yggCoqfhtoRGcr6+Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740506; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7AFGGj9Ou8CnL4bL5HPzO5qkBolyqEML9C9hyGbWiu4=; b=ZD8QdDnyWtxnnT1+tgTvYU19hTuZJE2cI/a0ffINHGpcfT5WiwYoMlIuz694vGtFCgGnSvo08hroO6EJm0iOtaAaf0iTguAA+m+XyqgVTrAJONGK8TqchhqPWNZwsLQAzD/4E+q5qihmbaSQvPrGXEZeOHqSPEuCzjObXKS6ras= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740506153806.7464992935359; Mon, 29 Jun 2026 06:41:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCEn-0008Cb-0a; Mon, 29 Jun 2026 09:41:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <04a62cdfe873d07a5f264d03372bfc34bbcdddf0@kylie.crudebyte.com>) id 1weCEP-0007v8-VJ; Mon, 29 Jun 2026 09:41:03 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <04a62cdfe873d07a5f264d03372bfc34bbcdddf0@kylie.crudebyte.com>) id 1weCEN-0005I5-QU; Mon, 29 Jun 2026 09:41:01 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=7AFGGj9Ou8CnL4bL5HPzO5qkBolyqEML9C9hyGbWiu4=; b=faDdB WzRfKKwOzknjcw3ocwzIC0OHFnS9KEx3HHZvN8gfzabbB1ozDXVRQ3zSV7wqtVFMcOKqkWONltm36 D8WMMgRdHMKj1eMdpHu6ZPjE84xvLX06LMUNRrYMDoKSNHzMxM3u0X/FXREFt493Z1gc3meLQq8Ro PcBqOy4rFQSVUsxvYW7jOZurJR3bWlsfAb9mEIZXpWsEJQzkuWPBM6EhoOOl/Y+sMyzDMgV6HW3BC GRhAfFAdUgu3yasYKG6gxoYLJSjSKMEyVLD9h+mM3Bf5Geba9lakSwDqKRWOvYH59SWF2YbksO66q HPj+R0Hp4TraQRfhal7/dpMea1uPyHkZgonSWZ5wWvzpHsyKWuYoh7ri5wr7XuiqVbWmz8WoWK3g4 H2ufVd7JuMZDCxWbMXEmJLXgZZtnHuDCP6zOJtpaZG07s2BalhjdzldwNGUFldaRvjBHXy6LNkgay +jtgvr3g36MOqpLoWfrROU5LGBKngFl6w8ZblMbqAeLlIMPO2Q5pg1HhMzm3+62pkpy1u9Yo1nLXh ZAFYKyfSgZoK9qpOGKkhJAPI7FVfoxUumlhcq12Dk7bxvn1L5f1U0U5O1FcHEByd+2/AUCYlP9qAf iy6GvlSTXExQ3lNAMGMHVCc9hRVkjbqLPiNIBaL7aCGU24lCiBA7iZuo6tJLGc=; Message-ID: <04a62cdfe873d07a5f264d03372bfc34bbcdddf0.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 20/23] tests/9p: add 3 xattr FID limit test cases (local fs driver) To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=04a62cdfe873d07a5f264d03372bfc34bbcdddf0@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740507366158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Analogue to the previously added 3 synth tests, add (similar) 3 test cases using the "local" fs driver to verify correct xattr FID limit enforcement of 9pfs server with a real filesystem. These 3 new local tests use the shared test code of the previously added 3 synth tests. The only difference is that the local fs driver does not expose the current internal xattr FID counter, so we can't verify this with the local tests. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://lore.kernel.org/qemu-devel/d23fa874df4f474ee7cbe738a35c148342= 6057f0.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- tests/qtest/virtio-9p-test.c | 70 ++++++++++++++++++++++++++++++++++-- 1 file changed, 67 insertions(+), 3 deletions(-) diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 2e88429dfa..cfd3c02da4 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -395,6 +395,19 @@ static void do_xattr_limit(QVirtio9P *v9p, int max_xat= tr, bool check_counter) } } =20 +static void do_local_xattr_limit(QVirtio9P *v9p, int max_xattr) +{ + g_autofree char *test_file =3D virtio_9p_test_path("WRITE"); + + /* + * this file must be created for the test to work with the 'local' fs = driver + */ + g_file_set_contents(test_file, "", 0, NULL); + + /* the actual test code shared with the 'synth' fs driver tests */ + do_xattr_limit(v9p, max_xattr, false); +} + static void fs_walk_no_slash(void *obj, void *data, QGuestAllocator *t_all= oc) { QVirtio9P *v9p =3D obj; @@ -990,6 +1003,27 @@ static void fs_deep_absolute_path(void *obj, void *da= ta, g_string_free(path, TRUE); } =20 +static void fs_local_xattr_limit_default(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, V9FS_MAX_XATTR_DEFAULT); +} + +static void fs_local_xattr_limit_custom(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, 100); +} + +static void fs_local_xattr_limit_unlimited(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, -1); +} + static void *synth_max_xattr_custom_opt(GString *cmd_line, void *arg) { virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D100"); @@ -1008,20 +1042,42 @@ static void cleanup_9p_local_driver(void *data) virtio_9p_remove_local_test_dir(); } =20 -static void *assign_9p_local_driver(GString *cmd_line, void *arg) +static void assign_9p_local_driver_with_args(GString *cmd_line, + const char *extra_opts) { /* make sure test dir for the 'local' tests exists */ virtio_9p_create_local_test_dir(); =20 - virtio_9p_assign_local_driver(cmd_line, "security_model=3Dmapped-xattr= "); + g_autofree char *opts =3D + (extra_opts) ? + g_strdup_printf("security_model=3Dmapped-xattr,%s", extra_opts= ) : + g_strdup("security_model=3Dmapped-xattr"); + + virtio_9p_assign_local_driver(cmd_line, opts); =20 g_test_queue_destroy(cleanup_9p_local_driver, NULL); +} + +static void *assign_9p_local_driver(GString *cmd_line, void *arg) +{ + assign_9p_local_driver_with_args(cmd_line, NULL); + return arg; +} + +static void *local_max_xattr_custom_opt(GString *cmd_line, void *arg) +{ + assign_9p_local_driver_with_args(cmd_line, "max_xattr=3D100"); + return arg; +} + +static void *local_max_xattr_unlimited_opt(GString *cmd_line, void *arg) +{ + assign_9p_local_driver_with_args(cmd_line, "max_xattr=3D0"); return arg; } =20 static void register_virtio_9p_test(void) { - QOSGraphTestOptions opts =3D { }; =20 @@ -1078,6 +1134,14 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/deep_absolute_path", "virtio-9p", fs_deep_absolute_path, &opts); + qos_add_test("local/xattr_limit/default", "virtio-9p", + fs_local_xattr_limit_default, &opts); + opts.before =3D local_max_xattr_custom_opt; + qos_add_test("local/xattr_limit/custom", "virtio-9p", + fs_local_xattr_limit_custom, &opts); + opts.before =3D local_max_xattr_unlimited_opt; + qos_add_test("local/xattr_limit/unlimited", "virtio-9p", + fs_local_xattr_limit_unlimited, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740727; cv=none; d=zohomail.com; s=zohoarc; b=jmabBKGX00r1T3xKD7QrlfLLHoE8IaqCKv0xonFdgx+/rDg5A8xlgDHnZIABdHCR1T6X5/xHUr6pEHc1hmawK5cGxUUdDBLB0XJY6OS43rHvEbDcliHXw73DL5BxMSNFJYs8LB1mUI+jVYx+WIJbtzKOYDB+sr3TJZgat7em4z0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740727; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LEQEllSuWrpoBefPi0ya9mS1eZ+GpNqLPFo4p4F5poY=; b=YEm5XDSy4ZIOZ2JQ1KVg/MhCWz5nNkbqbioJ593VOd8uUwDHEeh7TKEOyC4SewXr5dsNAkh4jzKWyQHuPtF0bVwuw5uc6g6uaMgzrwLvES8GSdMxLbKNuEd2pRZJtItbwlRCnEFf1qsYAlcc89KkXyDBENoC5OGklu0YGUfQ1CY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178274072709481.2111570198299; Mon, 29 Jun 2026 06:45:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCFW-0000ug-7e; Mon, 29 Jun 2026 09:42:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <32cae47c332f88241632905e0a3abcbb35b019c3@kylie.crudebyte.com>) id 1weCEb-00084P-98; Mon, 29 Jun 2026 09:41:17 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <32cae47c332f88241632905e0a3abcbb35b019c3@kylie.crudebyte.com>) id 1weCEZ-0005JM-Sr; Mon, 29 Jun 2026 09:41:13 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=LEQEllSuWrpoBefPi0ya9mS1eZ+GpNqLPFo4p4F5poY=; b=LR+ly OLN3gfsLGSTnszRCX6UE5XP6bNqMrjlvpn0PfIrBGgCGmZyAzEZbXkooogAv6iMhO2PA2gwXerUAy o7vnzynxr28Rbrx9EeNNoyceZv7MqpFgQugTJcFxrwkh5O9IiqojGEslLjvRd3ADLKW0cngyP0pnl RBXKINbBTRfJjR0mQnSAOIyZ0RaE1SPmUWTpuLg9zeQh3SYaIKMTukQ9OA+vhCmVK1bxGxaFeiH2r 61KTdw/nUpnPUwiFN/PNP6xwP4ViINHYdxigMN3U/roJguhrSOMOams+r88/byKAlJaDbKJsIKWN1 00w4zq1LlDy5jqNBDY/Y3veecnfwM8ptVD+4Uls74xC5F29+tfIsCiX5uuB/ovHoY27wB2VN9qbf/ bgEFD/GO7UlHjqWiSjzpAL4t2o/+CjDSmSdHDGzSPTDwrNdaHOcxLXcwFVlu6IIfj0KbtU20mP8Wn m9sPo7Na6GrWjUzXLkVuFqnDSotPkuJenVeW2UOu0NJzWLTLA6A8Avo8DVRCXeBKcTE8OVZW8Y/SF q27zWlOHsSS04I2/3VrNedF/uO2g2dZj3HDzA05I34AvgTsXqzyoeCIOXoffuNud1RnfouaPfqCGt Yth2M7KqoKZWrCDvimcKqU+tRlkticql59Ykl+ZRMs/GY4tGCxkfzvALBz9Rgs=; Message-ID: <32cae47c332f88241632905e0a3abcbb35b019c3.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 21/23] hw/9pfs: fix invalid union access by v9fs_co_fsync() To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=32cae47c332f88241632905e0a3abcbb35b019c3@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740728928158501 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The individual FID types (P9_FID_NONE, P9_FID_FILE, P9_FID_DIR, P9_FID_XATT= R) share union V9fsFidOpenState with FID-type specific fields. Accessing any of the union fields must comply with the FID-type to avoid undefined behaviour or information disclosure. Fix this in v9fs_fsync() and v9fs_wstat() by checking if FID has a valid fi= le descriptor before calling v9fs_co_fsync(). Fixes: 10b468bdc533 ("virtio-9p: Implement TXATTRCREATE") Reported-by: Feifan Qian Link: https://lore.kernel.org/qemu-devel/b583e29d5a0776e41263732c93ac9f0da0= a6016d.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index d1ec3c0c14..a2b7335515 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -2305,10 +2305,15 @@ static void coroutine_fn v9fs_fsync(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fsync(pdu, fidp, datasync); if (!err) { err =3D offset; } +out: put_fid(pdu, fidp); out_nofid: pdu_complete(pdu, err); @@ -3640,6 +3645,10 @@ static void coroutine_fn v9fs_wstat(void *opaque) } /* do we need to sync the file? */ if (donttouch_stat(&v9stat)) { + if (!fid_has_valid_file_handle(s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fsync(pdu, fidp, 0); goto out; } --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740583; cv=none; d=zohomail.com; s=zohoarc; b=GSHpJF41wahyY1kyRZIGt5xQmeLRpf7E9sJD38ZShPVGhbmm1yhbcPG7VwkKsl5v3T7VdtScUaVtuY7KuqbL60vQNtHyrCSMpgLDz6a3AR8qD4kGiRkknZr/+sbbiuVP7pKUTen+1l39GT08d1ztGLc8iKNkXMkGtv6nMJHbzKI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740583; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zIK5xwOzU2OkUrM5JSFz9ht0XvrYw6wrNhpI1E1fCjI=; b=C+VH2ndOdgD5j6oON05uXs1tx7v1uvAt3wpBwg6g24CfyVxicytzxJ3sIkMEKdcAG4RwTOu+VHdYIG8UTd3qjvTylWFOiR/5NUhnsDkAxE4LRTEIK9iIO5ULwlsQnQfgFpBbMDyOuDY+1L85MzvkWtq70ws/yOFFSkIJYr3EmEI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740583291868.8051063115292; Mon, 29 Jun 2026 06:43:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCF0-0008Ly-53; Mon, 29 Jun 2026 09:41:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCEi-0008Ce-P1; Mon, 29 Jun 2026 09:41:22 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1weCEh-0005Nm-9W; Mon, 29 Jun 2026 09:41:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=zIK5xwOzU2OkUrM5JSFz9ht0XvrYw6wrNhpI1E1fCjI=; b=Fsppn FtIH8Mwo8UlXxeBSyw/nlAxMLFIDWmpnlMfPzp1CJVgaeu9T5PcYwMQ/SI3jPbFm1vDN6jKy6k22n HoldnUnIv/JpxHI7X30rP32UJKdNnRmU96J8WT7KTxmUB1Sif9sp1AlCnrF6jBJvN5pEm5o9su86R Ai3OzXzYqxMWkjDanEVE9sK2JGWpVIMzEmTGES9Wtwj3YxeQ1PQZ6niKh6Ky3nBjE249loG6fiTPX qQY/z/sHTQdVvWYIjom8NjfCWWReOORKzZs9bT4NcBR1/PKhlAl69SIga3V3cYDIq961qOb9bH4WG qYWVNWHdzB4tZ2cWvixwOMkkX3PZSjXh58zMYyw4NRebqj3h62vnoM3Ez+dI2m9H/ClPoLEo+I+Fr QZS+AG+AL0zXUpADHe7JjouaJeMmUAlgqwM3DteGAR9LkseeSPoOlDgG7Sz5byqDSSz3L6plRuLFI tNol/hxMp78xJwwbmMLvX6g40AIssPf/Zhrv/1tDKvAFl5FyZMlPdfbXPHA8fC25lWzlZHACwQmWW bbrUjLhGRO5zCJeO05yXFzkrrqvOFVoJeYflAWYX1c1gxA9T1l9VFR8QBtlrrvVmvZDIBFhXfrt9d zCDgeIsckrNTgP/Ddxt3qtalnEJ+JimjA66hlB1HcSHVzYSO/6eAiIKVMBJ9d4=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 22/23] hw/9pfs: fix invalid union access by v9fs_co_fstat() To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=c3aa2491cd2cd89e2f484d32f323ee447e782984@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740584011158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The individual FID types (P9_FID_NONE, P9_FID_FILE, P9_FID_DIR, P9_FID_XATT= R) share union V9fsFidOpenState with FID-type specific fields. Accessing any of the union fields must comply with the FID-type to avoid undefined behaviour or information disclosure. Fix this in v9fs_lock() and v9fs_getlock() by checking if FID has a valid file descriptor before calling v9fs_co_fstat(). Fixes: 10b468bdc533 ("virtio-9p: Implement TXATTRCREATE") Link: https://lore.kernel.org/qemu-devel/4b33cd1aaa2551efda220a6f651e3660d2= 7f4746.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index a2b7335515..3119f01117 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3908,6 +3908,10 @@ static void coroutine_fn v9fs_lock(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fstat(pdu, fidp, &stbuf); if (err < 0) { goto out; @@ -3953,6 +3957,10 @@ static void coroutine_fn v9fs_getlock(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fstat(pdu, fidp, &stbuf); if (err < 0) { goto out; --=20 2.47.3 From nobody Sun Jul 26 11:54:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1782740638; cv=none; d=zohomail.com; s=zohoarc; b=LfdgF9Tu6ZE7jexKFX3/w0wrANKCYXQkGEygy4ICD07NfdKebkebd7mXXswssg7357pja+vU7rzQFkslYwhwL2Bm2oxSs531lN83FKZF6Tevzh1p9EiaGFMxsocTr/BpJNIWhGAFVIp5g4CcPyuqPHD3tFIDjCfcjNWzE1ekqUg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782740638; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3fZFgoUDcW5y38BozeBzb4oblUwakWj+uCadZre4Sdw=; b=VBlUTbeOnXFKv8jQ/dxNldH5GeOnLC80wUvmeqg6XgWDOwRzw2lMduEhUPF6Bl1tNAtwBM/9LOr1WZYllYOXHsuXn38tNo6pZ6Zkr5pM1i9Ey6ZgkM47ZfF8OppYkU2uTALHfrVAnbSUbH+sByqg8iEjCaM/MALf2WNS1kYxHTs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782740638796361.5773219203228; Mon, 29 Jun 2026 06:43:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1weCFZ-0001Tb-Fv; Mon, 29 Jun 2026 09:42:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <75893c058b21d87d1ec66bbd4e8bf84e1fd616d1@kylie.crudebyte.com>) id 1weCEn-0008EP-Ee; Mon, 29 Jun 2026 09:41:27 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <75893c058b21d87d1ec66bbd4e8bf84e1fd616d1@kylie.crudebyte.com>) id 1weCEl-0005Us-Np; Mon, 29 Jun 2026 09:41:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=3fZFgoUDcW5y38BozeBzb4oblUwakWj+uCadZre4Sdw=; b=Gn8yT BK3NWZDSqSDZl3rAIS2cdKB31ax+Nzf0oi52e5Yvmhua0JCraFNfcTAEgQVkypvpOASFSPqsWH24s IF2eGBQEuyBqdW7zwdccsOC+nyR9hodusqr6AyjCUokKZdmbsKLHN/tVvTNx1kMO/VEwP3sxfWNLb GiAQ+YFGhJs82xtrXMAJma90s7XF7hvAuAaBWW/R5QpLnZKuho6PFGQvZoG+Av8d3msBPgFYvc/4i 2kRoAaKAG9rXrzsZh0YEjOYt0w6PCTzvh0Yqv3FVbSCQp1PZO9P1aBB867fxC2X53oWrp2X5GPk0t K5GbNAx8vSDTUpt3nUk1e63BOF5toywazMbT+o8Fsv6A3PW1wLp0uQCO9DCXXBcFj2aaT6wKNePxY H9KOoJUUN3BjnAlwvUMjLp/WD8DMNwbtWVfCaXUw5JesQKIMJH9JV45B2L967RUv12scCBU7Nntq5 jn/GsEwTzKzLpRdG7UlmuWCQ3m+K8N8siHb1Xg27XwVBOPOLpUgQ6Exk2Ic3v2FrEse6ZTlIRRkxM TbgNSvphqydOiaBDXDvVhMew34tIud4vC+zDQh9WYb922CuO/C/6OxAQC15OGPvIy87Y8rHrZFZe8 yfGuv7WRA7Ppt3yXvz1YwP2ASzGN5MSHD8dVMMj3BuUdhwRKhmffkx1HPAZ6kM=; Message-ID: <75893c058b21d87d1ec66bbd4e8bf84e1fd616d1.1782739719.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Mon, 29 Jun 2026 15:28:39 +0200 Subject: [PULL 23/23] hw/9pfs/local: harden local_fid_fd() on FID types To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Peter Maydell , Feifan Qian Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=75893c058b21d87d1ec66bbd4e8bf84e1fd616d1@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1782740640482158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" local_fid_fd() returns fs->fd for any FID type that is not P9_FID_DIR. Since P9_FID_XATTR and P9_FID_NONE share union V9fsFidOpenState, calling local_fid_fd() on these types misinterprets xattr state as a file descriptor, potentially leading to undefined behaviour or information disclosure. Even though we are catching these FID type mismatches on protocol level in 9p.c already, previous patches proofed this to be error prone. So let's add another safety layer in local_fid_fd() that would return -1 if the FID type would not possess a valid file descriptor, to prevent wrong file descriptors from reaching fs backend calls. Link: https://lore.kernel.org/qemu-devel/531f6b81bc1bf1a48c3d4afaa60a65db10= 511041.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p-local.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 4708e170a4..ee592b62f8 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -775,8 +775,11 @@ static int local_fid_fd(int fid_type, V9fsFidOpenState= *fs) { if (fid_type =3D=3D P9_FID_DIR) { return dirfd(fs->dir.stream); - } else { + } else if (fid_type =3D=3D P9_FID_FILE) { return fs->fd; + } else { + errno =3D EBADF; + return -1; } } =20 --=20 2.47.3