Commit 4235cb24ec1e for kernel

commit 4235cb24ec1e8e96843f3671ba4da2a6ccca2c7b
Merge: 72841e8e8345 749d7aa0377a
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Sun Jul 26 12:22:57 2026 -0700

    Merge tag 'vfs-7.2-rc5.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs

    Pull vfs fixes from Christian Brauner:

     - vfs: Preserve the ACL_DONT_CACHE state in forget_cached_acl().

       ACL_DONT_CACHE is meant to be a permanent opt-out from ACL caching
       which FUSE relies on for servers that don't negotiate FUSE_POSIX_ACL.
       The helper replaced it with ACL_NOT_CACHED, silently re-enabling the
       cache, and as fuse doesn't invalidate the cache for such servers a
       properly timed get_acl() returned stale ACLs. Comes with a fuse
       selftest reproducing this.

     - pidfs:

         - Preserve PIDFD_THREAD when a thread pidfd is reopened via
           open_by_handle_at(). PIDFD_THREAD shares the O_EXCL bit which
           do_dentry_open() strips after the flags have been validated, so
           the reopened pidfd silently became a process pidfd. Comes with a
           selftest.

         - Add a pidfs_dentry_open() helper so the regular pidfd allocation
           path and the file handle path share the code that forces O_RDWR
           and reapplies the pidfd flags that do_dentry_open() strips.

         - Handle FS_IOC32_GETVERSION in the compat ioctl path.

         - Make pidfs_ino_lock static.

     - iomap:

         - Fix the block range calculation in ifs_clear_range_dirty() so a
           partial clear doesn't drop the dirty state of blocks the range
           only partially covers.

         - Support invalidating partial folios so a partial truncate or hole
           punch with blocksize < foliosize doesn't leave stale dirty bits
           behind.

         - Only set did_zero when iomap_zero_iter() actually zeroed
           something.

         - Guard ifs_set_range_dirty() and ifs_set_range_uptodate() against
           zero-length ranges where the unsigned last-block calculation
           underflows and bitmap_set() writes far beyond the ifs->state
           allocation.

         - Don't merge ioends with different io_private values as the merge
           could leak or corrupt the private data of the individual ioends.

     - exec:

         - Raise bprm->have_execfd only once the binfmt_misc interpreter has
           actually been opened. The flag was set as soon as a matching 'O'
           or 'C' entry was found. If the interpreter open failed with
           ENOEXEC the exec fell through to the next binary format with
           have_execfd raised but no executable staged and begin_new_exec()
           NULL derefed past the point of no return.

         - Fix an unsigned loop counter wrap in transfer_args_to_stack() on
           nommu. An overlong argument or environment string pushes bprm->p
           below PAGE_SIZE, the stop index becomes zero, and the loop never
           terminates, wrapping its counter and copying garbage from in
           front of the page array into the new process stack.

         - Make binfmt_elf_fdpic only honour the first PT_INTERP like
           binfmt_elf does. Each additional PT_INTERP overwrote the previous
           interpreter, leaking the name allocation and the interpreter file
           reference together with the write denial open_exec() took,
           leaving the file unwritable for as long as the system runs.

     - overlayfs:

         - Compare the full escaped xattr prefix including the trailing dot.
           An xattr like "trusted.overlay.overlayfoo" was misclassified as
           an escaped overlay xattr.

         - Check read access to the copy_file_range() source with the
           source's mounter credentials.

     - super: Thawing a filesystem whose block device was frozen with
       bdev_freeze() deadlocked. Dropping the last block layer freeze
       reference from under s_umount ends up in fs_bdev_thaw() which
       reacquires s_umount on the same task. Pin the superblock with an
       active reference instead and call bdev_thaw() without holding
       s_umount.

     - procfs: Return EACCES instead of success when the ptrace access check
       for namespace links fails.

     - afs: Use afs_dir_get_block() rather than afs_dir_find_block() for
       block 0 in afs_edit_dir_remove(), matching afs_edit_dir_add().

     - Push the memcg gating of ->nr_cached_objects() down into the btrfs
       and shmem callbacks instead of skipping every callback during
       non-root memcg reclaim. The blanket check short-circuited XFS whose
       inode reclaim hook is intentionally driven from per-memcg contexts to
       free memcg-charged slab.

     - eventpoll: Pin files while checking reverse paths.

       Since struct file became SLAB_TYPESAFE_BY_RCU a concurrent close
       could free and recycle the file under the check which then took and
       dropped the f_lock of whatever live file now occupies that slot.

    * tag 'vfs-7.2-rc5.fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs: (24 commits)
      super: fix emergency thaw deadlock on frozen block devices
      pidfs: make pidfs_ino_lock static
      eventpoll: pin files while checking reverse paths
      fs: push nr_cached_objects memcg gating into individual filesystems
      afs: Fix afs_edit_dir_remove() to get, not find, block 0
      iomap: prevent ioend merge when io_private differs
      iomap: add comments for ifs_clear/set_range_dirty()
      iomap: fix out-of-bounds bitmap_set() with zero-length range
      iomap: fix incorrect did_zero setting in iomap_zero_iter()
      iomap: support invalidating partial folios
      iomap: correct the range of a partial dirty clear
      fs/super: fix emergency thaw double-unlock of s_umount
      pidfs: handle FS_IOC32_GETVERSION in compat ioctl
      ovl: check access to copy_file_range source with src mounter creds
      proc: Fix broken error paths for namespace links
      pidfs: add pidfs_dentry_open() helper
      selftests/pidfd: check PIDFD_THREAD survives open_by_handle_at()
      pidfs: preserve thread pidfds reopened by file handle
      ovl: fix trusted xattr escape prefix matching
      selftests/fuse: add ACL_DONT_CACHE regression test
      ...