[GIT PULL for v7.2] vfs fixes

From: Christian Brauner

Date: Sun Jul 26 2026 - 11:38:39 EST


Hey Linus,

A bit later than intended today so no problem if we need to push this
past -rc5.

/* Summary */

This contains fixes for the current development cycle:

- vfs: Preserve the ACL_DONT_CACHE state in forget_cached_acl().
ACL_DONT_CACHE is meant to be a permanent opt-out from ACL caching
which FUSE relies on for servers that don't negotiate FUSE_POSIX_ACL.
The helper replaced it with ACL_NOT_CACHED, silently re-enabling the
cache, and as fuse doesn't invalidate the cache for such servers a
properly timed get_acl() returned stale ACLs. Comes with a fuse
selftest reproducing this.

- pidfs:

* Preserve PIDFD_THREAD when a thread pidfd is reopened via
open_by_handle_at(). PIDFD_THREAD shares the O_EXCL bit which
do_dentry_open() strips after the flags have been validated, so the
reopened pidfd silently became a process pidfd. Comes with a
selftest.

* Add a pidfs_dentry_open() helper so the regular pidfd allocation
path and the file handle path share the code that forces O_RDWR and
reapplies the pidfd flags that do_dentry_open() strips.

* Handle FS_IOC32_GETVERSION in the compat ioctl path.

* Make pidfs_ino_lock static.

- iomap:

* Fix the block range calculation in ifs_clear_range_dirty() so a
partial clear doesn't drop the dirty state of blocks the range only
partially covers.

* Support invalidating partial folios so a partial truncate or hole
punch with blocksize < foliosize doesn't leave stale dirty bits
behind.

* Only set did_zero when iomap_zero_iter() actually zeroed something.

* Guard ifs_set_range_dirty() and ifs_set_range_uptodate() against
zero-length ranges where the unsigned last-block calculation
underflows and bitmap_set() writes far beyond the ifs->state
allocation.

* Don't merge ioends with different io_private values as the merge
could leak or corrupt the private data of the individual ioends.

- exec:

* Raise bprm->have_execfd only once the binfmt_misc interpreter has
actually been opened. The flag was set as soon as a matching 'O' or
'C' entry was found. If the interpreter open failed with ENOEXEC
the exec fell through to the next binary format with have_execfd
raised but no executable staged and begin_new_exec() NULL derefed
past the point of no return.

* Fix an unsigned loop counter wrap in transfer_args_to_stack() on
nommu. An overlong argument or environment string pushes bprm->p
below PAGE_SIZE, the stop index becomes zero, and the loop never
terminates, wrapping its counter and copying garbage from in front
of the page array into the new process stack.

* Make binfmt_elf_fdpic only honour the first PT_INTERP like
binfmt_elf does. Each additional PT_INTERP overwrote the previous
interpreter, leaking the name allocation and the interpreter file
reference together with the write denial open_exec() took, leaving
the file unwritable for as long as the system runs.

- overlayfs:

* Compare the full escaped xattr prefix including the trailing dot.
An xattr like "trusted.overlay.overlayfoo" was misclassified as an
escaped overlay xattr.

* Check read access to the copy_file_range() source with the source's
mounter credentials.

- super: Thawing a filesystem whose block device was frozen with
bdev_freeze() deadlocked. Dropping the last block layer freeze
reference from under s_umount ends up in fs_bdev_thaw() which
reacquires s_umount on the same task. Pin the superblock with an
active reference instead and call bdev_thaw() without holding
s_umount.

- procfs: Return EACCES instead of success when the ptrace access check
for namespace links fails.

- afs: Use afs_dir_get_block() rather than afs_dir_find_block() for
block 0 in afs_edit_dir_remove(), matching afs_edit_dir_add().

- Push the memcg gating of ->nr_cached_objects() down into the btrfs
and shmem callbacks instead of skipping every callback during
non-root memcg reclaim. The blanket check short-circuited XFS whose
inode reclaim hook is intentionally driven from per-memcg contexts to
free memcg-charged slab.

- eventpoll: Pin files while checking reverse paths. Since struct file
became SLAB_TYPESAFE_BY_RCU a concurrent close could free and recycle
the file under the check which then took and dropped the f_lock of
whatever live file now occupies that slot.

/* Conflicts */

Merge conflicts with mainline
=============================

No known conflicts.

Merge conflicts with other trees
================================

No known conflicts.

The following changes since commit 1590cf0329716306e948a8fc29f1d3ee87d3989f:

Linux 7.2-rc4 (2026-07-19 13:54:41 -0700)

are available in the Git repository at:

git@xxxxxxxxxxxxxxxxxxx:pub/scm/linux/kernel/git/vfs/vfs tags/vfs-7.2-rc5.fixes

for you to fetch changes up to 749d7aa0377aae32af8c0a4ad43371e7bf830ab5:

super: fix emergency thaw deadlock on frozen block devices (2026-07-26 17:08:52 +0200)

----------------------------------------------------------------
vfs-7.2-rc5.fixes

Please consider pulling these changes from the signed vfs-7.2-rc5.fixes tag.

Thanks!
Christian

----------------------------------------------------------------
Amir Goldstein (3):
fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
selftests/fuse: add ACL_DONT_CACHE regression test
ovl: check access to copy_file_range source with src mounter creds

Chen Changcheng (1):
fs/super: fix emergency thaw double-unlock of s_umount

Christian Brauner (10):
binfmt_misc: set have_execfd only once the interpreter is opened
exec: fix unsigned loop counter wrap in transfer_args_to_stack()
binfmt_elf_fdpic: only honour the first PT_INTERP
Merge patch series "Fix for unintended FUSE ACL cache"
pidfs: preserve thread pidfds reopened by file handle
selftests/pidfd: check PIDFD_THREAD survives open_by_handle_at()
Merge patch series "pidfs: preserve thread pidfds reopened by file handle"
pidfs: add pidfs_dentry_open() helper
Merge patch series "iomap: trivial fixes for ext4 conversion"
super: fix emergency thaw deadlock on frozen block devices

David Howells (1):
afs: Fix afs_edit_dir_remove() to get, not find, block 0

Guidong Han (1):
eventpoll: pin files while checking reverse paths

Jann Horn (1):
proc: Fix broken error paths for namespace links

Li Chen (1):
pidfs: handle FS_IOC32_GETVERSION in compat ioctl

Mateusz Guzik (1):
pidfs: make pidfs_ino_lock static

Usama Arif (1):
fs: push nr_cached_objects memcg gating into individual filesystems

Yichong Chen (1):
ovl: fix trusted xattr escape prefix matching

Zhang Yi (6):
iomap: correct the range of a partial dirty clear
iomap: support invalidating partial folios
iomap: fix incorrect did_zero setting in iomap_zero_iter()
iomap: fix out-of-bounds bitmap_set() with zero-length range
iomap: add comments for ifs_clear/set_range_dirty()
iomap: prevent ioend merge when io_private differs

fs/afs/dir_edit.c | 2 +-
fs/binfmt_elf_fdpic.c | 4 +
fs/binfmt_misc.c | 5 +-
fs/btrfs/super.c | 10 +
fs/eventpoll.c | 18 +-
fs/exec.c | 2 +-
fs/iomap/buffered-io.c | 58 +++-
fs/iomap/ioend.c | 2 +
fs/overlayfs/file.c | 16 +-
fs/overlayfs/xattrs.c | 2 +-
fs/pidfs.c | 54 +++-
fs/posix_acl.c | 7 +
fs/proc/namespaces.c | 4 +-
fs/super.c | 34 +-
include/linux/memcontrol.h | 21 ++
mm/shmem.c | 10 +
tools/testing/selftests/filesystems/fuse/Makefile | 10 +
.../filesystems/fuse/fuse_acl_cache_test.c | 347 +++++++++++++++++++++
.../selftests/pidfd/pidfd_file_handle_test.c | 1 +
19 files changed, 553 insertions(+), 54 deletions(-)
create mode 100644 tools/testing/selftests/filesystems/fuse/fuse_acl_cache_test.c