Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932745AbcJQHqY (ORCPT ); Mon, 17 Oct 2016 03:46:24 -0400 Received: from mail-io0-f193.google.com ([209.85.223.193]:36093 "EHLO mail-io0-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932466AbcJQHqJ (ORCPT ); Mon, 17 Oct 2016 03:46:09 -0400 MIME-Version: 1.0 In-Reply-To: References: <1476371737-2116-1-git-send-email-geert@linux-m68k.org> From: Geert Uytterhoeven Date: Mon, 17 Oct 2016 09:46:07 +0200 X-Google-Sender-Auth: uRbB2FNpFzH4s734h4nAo-ABgOQ Message-ID: Subject: Re: [PATCH] ceph: Fix uninitialized dentry pointer in ceph_real_mount() To: "Yan, Zheng" Cc: Zheng Yan , Ilya Dryomov , ceph-devel , "linux-kernel@vger.kernel.org" Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from quoted-printable to 8bit by mail.home.local id u9H7kbWH032218 Content-Length: 1880 Lines: 56 Hi Zheng, On Fri, Oct 14, 2016 at 4:47 AM, Yan, Zheng wrote: > On Thu, Oct 13, 2016 at 11:15 PM, Geert Uytterhoeven > wrote: >> fs/ceph/super.c: In function ‘ceph_real_mount’: >> fs/ceph/super.c:818: warning: ‘root’ may be used uninitialized in this function >> >> If s_root is already valid, dentry pointer root is never initialized, >> and returned by ceph_real_mount(). This will cause a crash later when >> the caller dereferences the pointer. >> >> Fix this by initializing root early. >> >> Fixes: ce2728aaa82bbeba ("ceph: avoid accessing / when mounting a subpath") >> Signed-off-by: Geert Uytterhoeven >> --- >> Compile-tested only. >> --- >> fs/ceph/super.c | 3 ++- >> 1 file changed, 2 insertions(+), 1 deletion(-) >> >> diff --git a/fs/ceph/super.c b/fs/ceph/super.c >> index a29ffce981879d5f..794c5fd0e0cf5e45 100644 >> --- a/fs/ceph/super.c >> +++ b/fs/ceph/super.c >> @@ -821,7 +821,8 @@ static struct dentry *ceph_real_mount(struct ceph_fs_client *fsc) >> dout("mount start %p\n", fsc); >> mutex_lock(&fsc->client->mount_mutex); >> >> - if (!fsc->sb->s_root) { >> + root = fsc->sb->s_root; >> + if (!root) { >> const char *path; >> err = __ceph_open_session(fsc->client, started); >> if (err < 0) > > For sb->s_root is not NULL case, we also need to increase sb->s_root's > reference count. OK > I applied this patch and fixed it. Thanks for handling! Gr{oetje,eeting}s, Geert -- Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org In personal conversations with technical people, I call myself a hacker. But when I'm talking to journalists I just say "programmer" or something like that. -- Linus Torvalds