<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/fs, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/fs?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/fs?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-10-02T21:04:11Z</updated>
<entry>
<title>Merge tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux</title>
<updated>2026-10-02T21:04:11Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T21:04:11Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=ff47652a4b66c067c765a7ad464d930b5a9367cc'/>
<id>urn:sha1:ff47652a4b66c067c765a7ad464d930b5a9367cc</id>
<content type='text'>
Pull smb client fixes from Paulo Alcantara:
 "Fix a series of data corruption and I/O error bugs found by running
  generic/363 (fsx) in a loop against Windows Server 2022 and Samba.

   - Stop data dirtied past EOF through an mmap from reappearing as file
     content once the file is extended by a write, truncate, zero range,
     copy range or clone range

   - Flush dirty data and drain in-flight I/O before operations that
     assume the pagecache and the server agree on the file: querying
     allocated ranges, the O_TRUNC open, interior zero range, and
     server-side copy/clone

   - Stop a genuine size-extending zero range or preallocate from being
     refused with -EOPNOTSUPP when the inode is not read caching, by
     querying the server's authoritative EOF instead of trusting a stale
     cached i_size

   - Zero the untransferred tail of a short read, both in the netfs
     read-gaps path (where stale folio content could otherwise be
     written back to the server) and in the DIO/unbuffered read
     collector, and tell a real EOF apart from a stale cached
     remote_i_size after a lease downgrade

   - Require stable pages on signed connections so a buffered write
     can't modify a folio whose signature has already been computed and
     is in flight, which the server rejected with STATUS_ACCESS_DENIED
     and the client surfaced as -EIO

   - Split several cifsFileInfo flags out of a shared bitfield byte so
     concurrent updates taken under different locks no longer clobber
     each other through a byte-level RMW"

* tag 'cifs-fixes-7.3-rc6' of https://git.manguebit.org/linux:
  smb: client: split cifsFileInfo bitfields to avoid shared-byte RMW races
  smb: client: require stable pages for signed connections
  smb: client: distinguish real EOF from a stale remote_i_size on read
  netfs: zero the tail of a short DIO/unbuffered read
  smb: client: only require read lease for size-extending preallocate
  netfs: zero gaps in read-gaps folio to avoid writing back stale data
  smb: client: only require read lease for size-extending zero range
  smb: client: drain and invalidate before server-side copy/clone
  smb: client: flush dirty data before zeroing a range
  smb: client: drain outstanding I/O before truncating on O_TRUNC open
  smb: client: flush and commit data before querying allocated ranges
  smb: client: discard post-EOF pagecache when extending a file via clone range
  smb: client: discard post-EOF pagecache when extending a file via copy range
  smb: client: discard post-EOF pagecache when extending a file via zero range
  smb: client: clear post-EOF pagecache when extending a file via truncate
  netfs: clear post-EOF pagecache when extending a file via write
</content>
</entry>
<entry>
<title>Merge tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux</title>
<updated>2026-10-02T19:17:24Z</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-10-02T19:17:24Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=3f1fe48a36b0b6722dc3fd421d93512bac138e9a'/>
<id>urn:sha1:3f1fe48a36b0b6722dc3fd421d93512bac138e9a</id>
<content type='text'>
Pull io_uring fixes from Jens Axboe:

 - Fix a task_work add use-after-free with SQPOLL.

   The sqpoll thread could pop and complete the last request while
   io_req_normal_work_add() was still looking at them after the mpscq
   push.

   Use the same approach as DEFER_TASKRUN to protect from that, holding
   an RCU read lock across the add, and have exit wait for an RCU grace
   period for SQPOLL rings as well.

 - CQE32 ring fixes: correct the free entry check for 32b CQEs, zero the
   big_cqe for aux CQEs, and only post the dummy skip CQE on CQE_MIXED
   rings

 - Mark the source filter table as COW when cloning bpf filters, so
   registering another filter on the source doesn't modify the shared
   table in place

 - Initialize the task context before running the BPF loop

 - Requeue zcrx multishot receives stopped by a local resource

 - End a TX_TIMESTAMP multishot cmd when the CQ is full (lollipopkit)

* tag 'io_uring-7.3-20261002' of git://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux:
  io_uring: fix task_work add use-after-free with SQPOLL
  io_uring/cmd_net: end TX_TIMESTAMP multishot when the CQ is full
  io_uring/zcrx: requeue multishot receives stopped by a local resource
  io_uring: initialize task context before running the BPF loop
  io_uring: zero big_cqe for aux CQEs on CQE32 rings
  io_uring: fix free entry check for 32b CQEs on CQE32 rings
  io_uring: only post the dummy skip CQE on CQE_MIXED rings
  io_uring/bpf_filter: mark source as COW when cloning filters
</content>
</entry>
<entry>
<title>smb: client: split cifsFileInfo bitfields to avoid shared-byte RMW races</title>
<updated>2026-10-01T02:17:30Z</updated>
<author>
<name>Frank Sorenson</name>
<email>sorenson@redhat.com</email>
</author>
<published>2026-09-30T20:47:15Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=19465a9aeb664f1d710d0d22c07c31bfb7c85446'/>
<id>urn:sha1:19465a9aeb664f1d710d0d22c07c31bfb7c85446</id>
<content type='text'>
The invalidHandle, swapfile, oplock_break_cancelled, offload,
and status_file_deleted fields are stored in the same bitfield byte
in struct cifsFileInfo, but are updated in different code paths that
may run simultaneously, and are protected by different locks.  Since
bitfield assignments generate byte-level read-modify-write operations,
a modification to one flag can overwrite a concurrent modification to
another flag.

To avoid these races, convert these flags from a bitfield to
separate bool fields.

Closes: https://lore.kernel.org/r/7689764e-c0f6-4016-9557-b54cf4a3de4e@redhat.com
Fixes: 3bc303c254335 ("cifs: convert oplock breaks to use slow_work facility (try #4)")
Fixes: 4e8aea30f7751 ("smb3: enable swap on SMB3 mounts")
Fixes: ffceb7640cbfe ("smb: client: do not defer close open handles to deleted files")
Fixes: 173217bd73365 ("smb3: retrying on failed server close")
Signed-off-by: Frank Sorenson &lt;sorenson@redhat.com&gt;
Cc: stable@vger.kernel.org
Reviewed-by: Namjae Jeon &lt;linkinjeon@kernel.org&gt;
Signed-off-by: Paulo Alcantara &lt;pc@manguebit.org&gt;
</content>
</entry>
<entry>
<title>smb: client: require stable pages for signed connections</title>
<updated>2026-09-30T17:24:21Z</updated>
<author>
<name>Paulo Alcantara</name>
<email>pc@manguebit.org</email>
</author>
<published>2026-09-28T13:23:00Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=53c5c2c1095eb21e214811fec16cd75f89d72ee2'/>
<id>urn:sha1:53c5c2c1095eb21e214811fec16cd75f89d72ee2</id>
<content type='text'>
When signing, cifs computes the SMB signature over the pagecache folios
in place and then hands those same folios to the socket.  If a buffered
write mutates a folio while a write subrequest is still in flight, the
signature no longer matches the data that follows it, the server rejects
the write with STATUS_ACCESS_DENIED (-EACCES), and the error is latched
in the mapping, so the next fsync()/fallocate() returns -EIO.

Mark the mapping for stable writes so netfs_perform_write() waits for
writeback to complete before modifying an in-flight folio.  This is
only needed when the connection is signed.

Fixes: 3ee1a1fc3981 ("cifs: Cut over to using netfslib")
Reviewed-by: David Howells &lt;dhowells@redhat.com&gt;
Reviewed-by: Namjae Jeon &lt;linkinjeon@kernel.org&gt;
Signed-off-by: Paulo Alcantara &lt;pc@manguebit.org&gt;
Cc: Christian Brauner &lt;brauner@kernel.org&gt;
Cc: Matthew Wilcox &lt;willy@infradead.org&gt;
Cc: Ronnie Sahlberg &lt;ronniesahlberg@gmail.com&gt;
Cc: Shyam Prasad N &lt;sprasad@microsoft.com&gt;
Cc: Tom Talpey &lt;tom@talpey.com&gt;
Cc: Bharath SM &lt;bharathsm@microsoft.com&gt;
Cc: stable@vger.kernel.org
</content>
</entry>
<entry>
<title>smb: client: distinguish real EOF from a stale remote_i_size on read</title>
<updated>2026-09-30T17:24:16Z</updated>
<author>
<name>Paulo Alcantara</name>
<email>pc@manguebit.org</email>
</author>
<published>2026-09-27T21:56:55Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=75aa4b4d557114276bb72e19a9bce5cb27b5e4b8'/>
<id>urn:sha1:75aa4b4d557114276bb72e19a9bce5cb27b5e4b8</id>
<content type='text'>
smb2_readv_callback() sets NETFS_SREQ_HIT_EOF whenever a short read
lines up with netfs_read_remote_i_size(inode), the server's EOF as the
client currently believes it. That belief can be stale: after a lease
downgrade and handle reopen, the tracked remote_i_size can sit below
the client's own i_size while an extending write hasn't reached the
server yet. A read in that gap comes back short for a reason that has
nothing to do with the file's real size, but was still marked HIT_EOF,
and netfs reports a short read for it as-is.

Only treat it as real EOF when the position is also at or past the
client's own i_size; otherwise mark it NETFS_SREQ_CLEAR_TAIL instead,
which tells netfs the shortfall is safe to zero-fill rather than
report as a short read.

This is what fsx (generic/363) sees as "short read: 0x0 bytes instead
of 0x&lt;n&gt;" against a Windows server.

Fixes: 1da29f2c39b6 ("netfs, cifs: Fix handling of short DIO read")
Reviewed-by: David Howells &lt;dhowells@redhat.com&gt;
Reviewed-by: Namjae Jeon &lt;linkinjeon@kernel.org&gt;
Signed-off-by: Paulo Alcantara &lt;pc@manguebit.org&gt;
Cc: Christian Brauner &lt;brauner@kernel.org&gt;
Cc: Matthew Wilcox &lt;willy@infradead.org&gt;
Cc: Ronnie Sahlberg &lt;ronniesahlberg@gmail.com&gt;
Cc: Shyam Prasad N &lt;sprasad@microsoft.com&gt;
Cc: Tom Talpey &lt;tom@talpey.com&gt;
Cc: Bharath SM &lt;bharathsm@microsoft.com&gt;
Cc: stable@vger.kernel.org
</content>
</entry>
<entry>
<title>netfs: zero the tail of a short DIO/unbuffered read</title>
<updated>2026-09-30T17:24:12Z</updated>
<author>
<name>Paulo Alcantara</name>
<email>pc@manguebit.org</email>
</author>
<published>2026-09-26T22:20:30Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=dd05add7b2b6004c5fa3a1f276f56d8668f86b65'/>
<id>urn:sha1:dd05add7b2b6004c5fa3a1f276f56d8668f86b65</id>
<content type='text'>
The buffered read collector zero-fills the tail of a short read that
stops below the inode's i_size (netfs_clear_unread()), so a read that
races an extending write still returns the expected number of bytes.
The non-buffered collector path does no such thing: it just records
how much was transferred.

Add the same zero-fill for the non-buffered case, gated on
NETFS_SREQ_CLEAR_TAIL: a subreq's source sets that flag when a short
result from it is known to be safe to treat as a hole, as opposed to
NETFS_SREQ_HIT_EOF, which means the read genuinely ran off the end of
the file and should be reported short as-is. Only CLEAR_TAIL should
zero-fill here; a real EOF must stay a real short read.

No source currently sets CLEAR_TAIL on an unbuffered/DIO subrequest,
so this is inert on its own -- a following change teaches cifs to set
it in the one case that needs it.

Fixes: e2d46f2ec332 ("netfs: Change the read result collector to only use one work item")
Reviewed-by: David Howells &lt;dhowells@redhat.com&gt;
Reviewed-by: Namjae Jeon &lt;linkinjeon@kernel.org&gt;
Signed-off-by: Paulo Alcantara &lt;pc@manguebit.org&gt;
Cc: Christian Brauner &lt;brauner@kernel.org&gt;
Cc: Matthew Wilcox &lt;willy@infradead.org&gt;
Cc: Ronnie Sahlberg &lt;ronniesahlberg@gmail.com&gt;
Cc: Shyam Prasad N &lt;sprasad@microsoft.com&gt;
Cc: Tom Talpey &lt;tom@talpey.com&gt;
Cc: Bharath SM &lt;bharathsm@microsoft.com&gt;
Cc: stable@vger.kernel.org
</content>
</entry>
</feed>
