aboutsummaryrefslogtreecommitdiffstats
path: root/net/tipc/socket.c
diff options
context:
space:
mode:
authorJann Horn <[email protected]>2024-11-29 20:20:53 +0000
committerTheodore Ts'o <[email protected]>2025-04-10 14:53:50 +0000
commit642335f3ea2b3fd6dba03e57e01fa9587843a497 (patch)
treea8f247a69521644eea0db246cc26f1b717f197ae /net/tipc/socket.c
parentext4: fix OOB read when checking dotdot dir (diff)
downloadkernel-642335f3ea2b3fd6dba03e57e01fa9587843a497.tar.gz
kernel-642335f3ea2b3fd6dba03e57e01fa9587843a497.zip
ext4: don't treat fhandle lookup of ea_inode as FS corruption
A file handle that userspace provides to open_by_handle_at() can legitimately contain an outdated inode number that has since been reused for another purpose - that's why the file handle also contains a generation number. But if the inode number has been reused for an ea_inode, check_igot_inode() will notice, __ext4_iget() will go through ext4_error_inode(), and if the inode was newly created, it will also be marked as bad by iget_failed(). This all happens before the point where the inode generation is checked. ext4_error_inode() is supposed to only be used on filesystem corruption; it should not be used when userspace just got unlucky with a stale file handle. So when this happens, let __ext4_iget() just return an error. Fixes: b3e6bcb94590 ("ext4: add EA_INODE checking to ext4_iget()") Signed-off-by: Jann Horn <[email protected]> Reviewed-by: Jan Kara <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Theodore Ts'o <[email protected]>
Diffstat (limited to 'net/tipc/socket.c')
0 files changed, 0 insertions, 0 deletions