Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp1833364imm; Mon, 3 Sep 2018 10:36:35 -0700 (PDT) X-Google-Smtp-Source: ANB0VdYtsSTxEPKXaagZBqaOFMxRBq2M1jxyD9nZKcKsCDjm88w5jvGacKbl0s4mh5aDhIkt0HlS X-Received: by 2002:a63:5465:: with SMTP id e37-v6mr27586862pgm.316.1535996194986; Mon, 03 Sep 2018 10:36:34 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1535996194; cv=none; d=google.com; s=arc-20160816; b=JKoElg+5R+lQcxCm6kisjlvAc7hhTrXKAR3Q+2KuIMkE0XCELE3JwleNxkupgEYgyq +DHLalZvtswEjWk6iqxoIoVVEdZQgNj/Pgu+XjglWWcDbUeNpkr+j9x0kA+yhkrV7MP5 N6svphUomF1OX5wIwPPg+zIoe+BerNf4d/Ocl852xqnqrfCFNoX6v9yDcmJtMc1soBzr aVsdRFD1o6Peig/epSKe/kQZKE74vJgpzrs+9fQsmGCkc9NuuJRPNMMetfGGknt2S1Sp K6vgmjfNYEJ2DRYCgk37/61twM/5Ha3imvjyGxDyhdkROVpv++UMdkMduh87KHhl8AJz +sqw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=/4bG7BsIE+4yTK87R5gVuP9WgJ2/cUuUojs1uHvTVnU=; b=MzU+gZUwrPuiERKc18gw0mDImfi7uFHE6knTfvsiICfqfkiTokUBCuWw3sC9EEITIh kzPma7zJtPVPbbGjMCpFsCXUux5CeItDGr4XWyiP5KRw1a4zeHY6j6PMzhBcpcm+PMLV P1bwNehClcB4k7Mbml0+zzR1yGT7fQDkDTyzZP0H3js5K8uWDzc+jr9CqV1ImCRsydKm jwLQTcAszCmDhXJbW5/8BT40Fdxk64AaFeBZnEm1JNccK0Ax9hKLjd/hcrQfYS4pRKe1 ZEA1ZmdZPA7l3rbRyMHyqfphZDdSbVKjF6V+UVXqUs1JPdjQU7UosJiX6/8awmbqS9Q4 23tg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w12-v6si17787990pld.362.2018.09.03.10.36.19; Mon, 03 Sep 2018 10:36:34 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731474AbeICV40 (ORCPT + 99 others); Mon, 3 Sep 2018 17:56:26 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:47974 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727972AbeICV4Z (ORCPT ); Mon, 3 Sep 2018 17:56:25 -0400 Received: from localhost (ip-213-127-74-90.ip.prioritytelecom.net [213.127.74.90]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id DCFFFD1B; Mon, 3 Sep 2018 17:35:14 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, syzbot , Miklos Szeredi Subject: [PATCH 4.18 059/123] fuse: fix initial parallel dirops Date: Mon, 3 Sep 2018 18:56:43 +0200 Message-Id: <20180903165721.931355955@linuxfoundation.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180903165719.499675257@linuxfoundation.org> References: <20180903165719.499675257@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Miklos Szeredi commit 63576c13bd17848376c8ba4a98f5d5151140c4ac upstream. If parallel dirops are enabled in FUSE_INIT reply, then first operation may leave fi->mutex held. Reported-by: syzbot Fixes: 5c672ab3f0ee ("fuse: serialize dirops by default") Cc: # v4.7 Signed-off-by: Miklos Szeredi Signed-off-by: Greg Kroah-Hartman --- fs/fuse/dir.c | 10 ++++++---- fs/fuse/fuse_i.h | 4 ++-- fs/fuse/inode.c | 14 ++++++++++---- 3 files changed, 18 insertions(+), 10 deletions(-) --- a/fs/fuse/dir.c +++ b/fs/fuse/dir.c @@ -355,11 +355,12 @@ static struct dentry *fuse_lookup(struct struct inode *inode; struct dentry *newent; bool outarg_valid = true; + bool locked; - fuse_lock_inode(dir); + locked = fuse_lock_inode(dir); err = fuse_lookup_name(dir->i_sb, get_node_id(dir), &entry->d_name, &outarg, &inode); - fuse_unlock_inode(dir); + fuse_unlock_inode(dir, locked); if (err == -ENOENT) { outarg_valid = false; err = 0; @@ -1340,6 +1341,7 @@ static int fuse_readdir(struct file *fil struct fuse_conn *fc = get_fuse_conn(inode); struct fuse_req *req; u64 attr_version = 0; + bool locked; if (is_bad_inode(inode)) return -EIO; @@ -1367,9 +1369,9 @@ static int fuse_readdir(struct file *fil fuse_read_fill(req, file, ctx->pos, PAGE_SIZE, FUSE_READDIR); } - fuse_lock_inode(inode); + locked = fuse_lock_inode(inode); fuse_request_send(fc, req); - fuse_unlock_inode(inode); + fuse_unlock_inode(inode, locked); nbytes = req->out.args[0].size; err = req->out.h.error; fuse_put_request(fc, req); --- a/fs/fuse/fuse_i.h +++ b/fs/fuse/fuse_i.h @@ -974,8 +974,8 @@ int fuse_do_setattr(struct dentry *dentr void fuse_set_initialized(struct fuse_conn *fc); -void fuse_unlock_inode(struct inode *inode); -void fuse_lock_inode(struct inode *inode); +void fuse_unlock_inode(struct inode *inode, bool locked); +bool fuse_lock_inode(struct inode *inode); int fuse_setxattr(struct inode *inode, const char *name, const void *value, size_t size, int flags); --- a/fs/fuse/inode.c +++ b/fs/fuse/inode.c @@ -357,15 +357,21 @@ int fuse_reverse_inval_inode(struct supe return 0; } -void fuse_lock_inode(struct inode *inode) +bool fuse_lock_inode(struct inode *inode) { - if (!get_fuse_conn(inode)->parallel_dirops) + bool locked = false; + + if (!get_fuse_conn(inode)->parallel_dirops) { mutex_lock(&get_fuse_inode(inode)->mutex); + locked = true; + } + + return locked; } -void fuse_unlock_inode(struct inode *inode) +void fuse_unlock_inode(struct inode *inode, bool locked) { - if (!get_fuse_conn(inode)->parallel_dirops) + if (locked) mutex_unlock(&get_fuse_inode(inode)->mutex); }