Commit a0414545a2 for qemu.org

commit a0414545a212e27058fab7b057b018e75b8c4b13
Author: Christian Schoenebeck <qemu_oss@crudebyte.com>
Date:   Wed Jul 15 18:10:00 2026 +0200

    hw/9pfs: fix O_TRUNC bypass on read-only export

    Guest 9p client opening a file with O_TRUNC on a read-only 9p file
    system using 9p2000.u protocol version, allowed to bypass 9p
    server's read-only check, eventually causing file(s) being
    truncated to empty file(s) on host's read-only export.

    Root cause is that 9p server's read-only check is using Linux open
    flags like O_WRONLY, O_RDWR, O_TRUNC, but checking them against
    the 9p Topen request's "mode" parameter, which has a different
    encoding (Otrunc = 0x10 vs. O_TRUNC = 0x200).

    Fix this by checking against the "flags" variable instead of the
    protocol's "mode" option. Because the "flags" variable is already
    converted to Linux encoding by omode_to_uflags() for 9p2000.u and
    by get_dotl_openflags() for 9p2000.L protocol version.

    Only 9p2000.u was affected by this bypass, 9p2000.L uses the Linux
    format on protocol level already.

    Fixes: 2c74c2cb4b ("hw/9pfs: Read-only support for 9p export")
    Fixes: CVE-2026-63318
    Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4000
    Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
    Link: https://lore.kernel.org/qemu-devel/E1wk2Dq-0019kY-JK@kylie.crudebyte.com
    Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>

diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c
index 3119f01117..474ac6cc40 100644
--- a/hw/9pfs/9p.c
+++ b/hw/9pfs/9p.c
@@ -2181,8 +2181,8 @@ static void coroutine_fn v9fs_open(void *opaque)
             flags = omode_to_uflags(mode);
         }
         if (is_ro_export(&s->ctx)) {
-            if (mode & O_WRONLY || mode & O_RDWR ||
-                mode & O_APPEND || mode & O_TRUNC) {
+            if (flags & O_WRONLY || flags & O_RDWR ||
+                flags & O_APPEND || flags & O_TRUNC) {
                 err = -EROFS;
                 goto out;
             }