Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1727595

[PATCH 1/2] fs/9p: Compare qid.path in v9fs_test_inode

From Tuomas Tynkkynen <tuomas@tuxera.com>
Newsgroups linux.kernel
Subject [PATCH 1/2] fs/9p: Compare qid.path in v9fs_test_inode
Date 2017-09-06 17:20 +0200
Message-ID <umKhs-3zl-27@gated-at.bofh.it> (permalink)
References <umKhs-3zl-13@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Commit fd2421f54423 ("fs/9p: When doing inode lookup compare qid details
and inode mode bits.") transformed v9fs_qid_iget() to use iget5_locked()
instead of iget_locked(). However, the test() callback is not checking
fid.path at all, which means that a lookup in the inode cache can now
accidentally locate a completely wrong inode from the same inode hash
bucket if the other fields (qid.type and qid.version) match.

Fixes: fd2421f54423 ("fs/9p: When doing inode lookup compare qid details and inode mode bits.")
Cc: stable@vger.kernel.org
Reviewed-by: Latchesar Ionkov <lucho@ionkov.net>
Signed-off-by: Tuomas Tynkkynen <tuomas@tuxera.com>
---
 fs/9p/vfs_inode.c      | 3 +++
 fs/9p/vfs_inode_dotl.c | 3 +++
 2 files changed, 6 insertions(+)

diff --git a/fs/9p/vfs_inode.c b/fs/9p/vfs_inode.c
index 2a5de610dd8f..bdabb2765d1b 100644
--- a/fs/9p/vfs_inode.c
+++ b/fs/9p/vfs_inode.c
@@ -483,6 +483,9 @@ static int v9fs_test_inode(struct inode *inode, void *data)
 
 	if (v9inode->qid.type != st->qid.type)
 		return 0;
+
+	if (v9inode->qid.path != st->qid.path)
+		return 0;
 	return 1;
 }
 
diff --git a/fs/9p/vfs_inode_dotl.c b/fs/9p/vfs_inode_dotl.c
index 70f9887c59a9..7f6ae21a27b3 100644
--- a/fs/9p/vfs_inode_dotl.c
+++ b/fs/9p/vfs_inode_dotl.c
@@ -87,6 +87,9 @@ static int v9fs_test_inode_dotl(struct inode *inode, void *data)
 
 	if (v9inode->qid.type != st->qid.type)
 		return 0;
+
+	if (v9inode->qid.path != st->qid.path)
+		return 0;
 	return 1;
 }
 
-- 
2.13.0

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/2] 9p: Fixes for hard-to-hit bugs Tuomas Tynkkynen <tuomas@tuxera.com> - 2017-09-06 17:20 +0200
  [PATCH 2/2] net/9p: Switch to wait_event_killable() Tuomas Tynkkynen <tuomas@tuxera.com> - 2017-09-06 17:20 +0200
  [PATCH 1/2] fs/9p: Compare qid.path in v9fs_test_inode Tuomas Tynkkynen <tuomas@tuxera.com> - 2017-09-06 17:20 +0200
  Re: [PATCH 0/2] 9p: Fixes for hard-to-hit bugs Latchesar Ionkov <lucho@ionkov.net> - 2017-09-07 17:00 +0200

csiph-web