@samitouri / QOSamiQemu / commits / 08750e31fc

hw/9pfs: reject . and .. in Twstat rename

The other Trename and Trenameat handlers already reject "." and ".." as new name on rename requests by returning -EISDIR in this case. The legacy Twstat rename handler is missing this validation. While passing "." or ".." does not trigger a crash as fixed by the previous patch (since the fs backend driver's system calls handle these gracefully), it creates a behavioral inconsistency, as it is semantically meaningless to rename a file to a directory reference in the first place. Fix this by rejecting "." and ".." in Twstat rename handler with -EISDIR to match behavior of Trename and Trenameat handlers. Fixes: 8cf89e007a ("virtio-9p: Add P9_TWSTAT support") Link: https://lore.kernel.org/qemu-devel/662333331d371c6c343c8091161de8eaa121880e.1780072238.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>

Christian Schoenebeck committed May 29, 2026 at 18:29 UTC 08750e31fcdccf5352dc3b44475ed5ba6bc80221
1 file changed +4
hw/9pfs/9p.c
+4
@@ -3642,6 +3642,10 @@ static void coroutine_fn v9fs_wstat(void *opaque)
3642 err = -ENOENT;
3643 goto out;
3644 }
3645 + if (!strcmp(".", v9stat.name.data) || !strcmp("..", v9stat.name.data)) {
3646 + err = -EISDIR;
3647 + goto out;
3648 + }
3649
3650 v9fs_path_write_lock(s);
3651 err = v9fs_complete_rename(pdu, fidp, -1, &v9stat.name);