@samitouri / QOSamiQemu / commits / b72d15f47c

hw/9pfs: fix missing EOPNOTSUPP on Twstat and Trenameat for fs synth driver

Renaming files/dirs is only supported by path-based fs drivers. EOPNOTSUPP should be returned on any renaming attempt for not path-based fs drivers. This was already the case for 9p "Trename" request type. However for 9p request types "Trenameat" and "Twstat" this was yet missing. So fix this by checking in Twstat and Trenameat request handlers whether the fs driver in use is really path based, if not return EOPNOTSUPP and abort further handling of the request. This fixes a crash with the 9p "synth" fs driver which is not path-based. The crash happened because the synth driver stores and expects a raw V9fsSynthNode pointer instead of a C-string on V9fsPath.data. So the C-string delivered by 9p server to synth fs driver was incorrectly casted to a V9fsSynthNode pointer, eventually causing a segfault. Reported-by: Oliver Chang <ochang@google.com> Fixes: https://issues.oss-fuzz.com/issues/477990727 Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3298 Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com> Reviewed-by: Greg Kurz <groug@kaod.org> Link: https://lore.kernel.org/qemu-devel/E1vrbaP-000Gqb-B3@kylie.crudebyte.com/

Christian Schoenebeck committed Feb 15, 2026 at 13:44 UTC b72d15f47cbd2fc93580f33fa86a7e23595a68dd
1 file changed +11
hw/9pfs/9p.c
+11
@@ -3516,6 +3516,12 @@ static void coroutine_fn v9fs_renameat(void *opaque)
3516 goto out_err;
3517 }
3518
3519 + /* if fs driver is not path based, return EOPNOTSUPP */
3520 + if (!(s->ctx.export_flags & V9FS_PATHNAME_FSCONTEXT)) {
3521 + err = -EOPNOTSUPP;
3522 + goto out_err;
3523 + }
3524 +
3525 v9fs_path_write_lock(s);
3526 err = v9fs_complete_renameat(pdu, olddirfid,
3527 &old_name, newdirfid, &new_name);
@@ -3606,6 +3612,11 @@ static void coroutine_fn v9fs_wstat(void *opaque)
3612 }
3613 }
3614 if (v9stat.name.size != 0) {
3615 + /* if fs driver is not path based, return EOPNOTSUPP */
3616 + if (!(s->ctx.export_flags & V9FS_PATHNAME_FSCONTEXT)) {
3617 + err = -EOPNOTSUPP;
3618 + goto out;
3619 + }
3620 v9fs_path_write_lock(s);
3621 err = v9fs_complete_rename(pdu, fidp, -1, &v9stat.name);
3622 v9fs_path_unlock(s);