Hi Christian, On 6/29/2026 6:28 AM, Christian Schoenebeck wrote: > The following changes since commit 20553466cc47af6a8c95f665b601fce3c852e503: > > Merge tag 'pbouvier/pr/docs-20260626' of https://gitlab.com/p-b-o/qemu into > staging (2026-06-27 23:28:35 -0400) > > are available in the Git repository at: > > https://github.com/cschoenebeck/qemu.git tags/pull-9p-20260629 > > for you to fetch changes up to 75893c058b21d87d1ec66bbd4e8bf84e1fd616d1: > > hw/9pfs/local: harden local_fid_fd() on FID types (2026-06-29 15:10:32 > +0200) > > ---------------------------------------------------------------- > 9pfs changes: > > - Fix DoS via Treaddir (CVE-2026-9238). > > - Add xattr FID limit (CVE-2026-8348). > > - Fix union V9fsFidOpenState type confusion. > > ---------------------------------------------------------------- > Christian Schoenebeck (23): > hw/9pfs: add msize_limit transport callback > 9pfs/virtio: implement msize_limit callback > 9pfs/xen: implement msize_limit callback > hw/9pfs: cap negotiated msize to transport limit > hw/9pfs: add response_buffer_size transport callback > 9pfs/virtio: implement response_buffer_size callback > 9pfs/xen: implement response_buffer_size callback > hw/9pfs: cap Treaddir allocation (CVE-2026-9238) > hw/9pfs: add xattr FID limit to prevent memory exhaustion > hw/9pfs: add max_xattr option > qemu-options: document 9pfs max_xattr option > tests/9p: add Tread / Rread test client functions > tests/9p: add Tclunk / Rclunk test client functions > tests/9p: add Txattrcreate / Rxattrcreate test client functions > hw/9pfs: enable xattr (mockup) support for synth fs driver > hw/9pfs: add xattr count query interface to fs synth driver > tests/9p: increase P9_MAX_SIZE for test client > tests/9p: add virtio_9p_add_synth_driver_args() test client function > tests/9p: add 3 xattr FID limit test cases (synth fs driver) > tests/9p: add 3 xattr FID limit test cases (local fs driver) > hw/9pfs: fix invalid union access by v9fs_co_fsync() > hw/9pfs: fix invalid union access by v9fs_co_fstat() > hw/9pfs/local: harden local_fid_fd() on FID types > > fsdev/file-op-9p.h | 11 ++ > fsdev/qemu-fsdev-opts.c | 6 + > fsdev/qemu-fsdev.c | 2 +- > hw/9pfs/9p-local.c | 14 +- > hw/9pfs/9p-synth.c | 51 ++++++- > hw/9pfs/9p.c | 113 ++++++++++++++- > hw/9pfs/9p.h | 2 + > hw/9pfs/virtio-9p-device.c | 17 +++ > hw/9pfs/xen-9p-backend.c | 31 ++++ > qemu-options.hx | 28 ++-- > system/vl.c | 7 +- > tests/qtest/libqos/virtio-9p-client.c | 124 ++++++++++++++++ > tests/qtest/libqos/virtio-9p-client.h | 88 +++++++++++- > tests/qtest/libqos/virtio-9p.c | 6 + > tests/qtest/libqos/virtio-9p.h | 6 + > tests/qtest/virtio-9p-test.c | 262 > +++++++++++++++++++++++++++++++++- > 16 files changed, 746 insertions(+), 22 deletions(-) >
This series brought a test regression: $ ./build/pyvenv/bin/meson test -C build \ --setup thorough --print-errorlogs \ qemu:qtest-aarch64/qos-test ... ERROR:../tests/qtest/libqos/virtio-9p-client.c:280:v9fs_req_recv: assertion failed (hdr.id == id): (7 == 121) It seems to come test added in patch 19 "tests/9p: add 3 xattr FID limit test cases (synth fs driver)" This test runs only with slow setup, so I suspect it never worked and was never ran. Could you take a look to fix or revert the concerned change? You can add me in copy, I'll be happy to review and test it. Thanks, Pierrick
