Received: by 2002:a25:7ec1:0:0:0:0:0 with SMTP id z184csp151536ybc; Mon, 18 Nov 2019 22:16:24 -0800 (PST) X-Google-Smtp-Source: APXvYqxgzCIEowlsVQLpEVmQdCHR9eUb4ztaCY+sIFG+vPReTEipRX9rEojxiMfPaTttdrkja9vY X-Received: by 2002:a17:906:b6c3:: with SMTP id ec3mr33636403ejb.27.1574144184574; Mon, 18 Nov 2019 22:16:24 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1574144184; cv=none; d=google.com; s=arc-20160816; b=hTeqi0DsKYWqbiO+N35zibyNuebQkYyGBJ9HKogeZhOuSIqLrGMKU5GHw+q70b5gCg grGFjZjn4X/d5ZW+7VGBYRXbJgdE3Yuo2t8dRF2wPt/KEyQZXj9vHd8+J6bgM1dBDD9/ 1Qu7s/2kS3YeBEPeAN5SDidp/f/EhtMW0QjItsabYYz5L6C9ZtCtLpdgE1+kcL2dzoOI tArg3GGJC4Dsqjun9iRoqwpfMzSCiGOrCW7le72BMDHZjAyR1fHqNlAxsV7+DbTjCk10 E5eKLET4Bq5oUutGoeZAPXEsCmy/AhCssQMhd3prQEPClMIDA+lCXaw5fn5pl2E1Iq83 6/xw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=eDNQNa6Zwc0F+rdvG1zlYWaa8Kl3MDmMtV+VgELvT9o=; b=IuaXZ9V1Nk2HkuoEByr4yAPVNlmt94nOXkq3M4loBohMDqARxJYfLvOG4BFtlswelF ISMUjpbsZ9KEHRBb5jnDC/JIl2cYQ/cK7y/XH5xWEJU6x1oSjTv3DUVWWOc/J29f3BRb yMP/vdRBRoUcl0magFK7AXtNLfge/i/I0qy30TEobMk09AvII8/hAxtCa/k6buLtpB70 Ettu67GU9TAedSrfY7hW1pH7N5VsNnoH9sKpERtfLF64du7GmX91XPGf/RZoJpWn1irC a4fIAX+vQUElvbk8VV3is0kAoC+gnxbPs1BGkMCdkoE/9v5eG660qKL55H81tiJjuZS7 fqMA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=xOxJzEp1; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e6si2497221ejk.66.2019.11.18.22.16.00; Mon, 18 Nov 2019 22:16:24 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=xOxJzEp1; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727687AbfKSFWN (ORCPT + 99 others); Tue, 19 Nov 2019 00:22:13 -0500 Received: from mail.kernel.org ([198.145.29.99]:37454 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727675AbfKSFWL (ORCPT ); Tue, 19 Nov 2019 00:22:11 -0500 Received: from localhost (83-86-89-107.cable.dynamic.v4.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id A721F2231A; Tue, 19 Nov 2019 05:22:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1574140931; bh=SCTuBEqWLwhkUYPmE0gc4km31qBJp+HRBi+UPqTJucc=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=xOxJzEp1WrrqR5nFCrO0OFZslnyo1iCvXTvYhuIIUBTug8AWNtWNUjuZhOGd+3AS2 YmRaGEuZR+mpX2iuep8skjEMxJrtDjnT5IF/dvZkrcjuhm3XuNO04MXZuRJ4Ie+ea1 obEaC4pbmKTxIOKAaAWxyciOZup7sYUqOAaChx24= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Al Viro Subject: [PATCH 5.3 34/48] ecryptfs_lookup_interpose(): lower_dentry->d_inode is not stable Date: Tue, 19 Nov 2019 06:19:54 +0100 Message-Id: <20191119051014.638038858@linuxfoundation.org> X-Mailer: git-send-email 2.24.0 In-Reply-To: <20191119050946.745015350@linuxfoundation.org> References: <20191119050946.745015350@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Al Viro commit e72b9dd6a5f17d0fb51f16f8685f3004361e83d0 upstream. lower_dentry can't go from positive to negative (we have it pinned), but it *can* go from negative to positive. So fetching ->d_inode into a local variable, doing a blocking allocation, checking that now ->d_inode is non-NULL and feeding the value we'd fetched earlier to a function that won't accept NULL is not a good idea. Cc: stable@vger.kernel.org Signed-off-by: Al Viro Signed-off-by: Greg Kroah-Hartman --- fs/ecryptfs/inode.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) --- a/fs/ecryptfs/inode.c +++ b/fs/ecryptfs/inode.c @@ -311,7 +311,7 @@ static int ecryptfs_i_size_read(struct d static struct dentry *ecryptfs_lookup_interpose(struct dentry *dentry, struct dentry *lower_dentry) { - struct inode *inode, *lower_inode = d_inode(lower_dentry); + struct inode *inode, *lower_inode; struct ecryptfs_dentry_info *dentry_info; struct vfsmount *lower_mnt; int rc = 0; @@ -331,7 +331,15 @@ static struct dentry *ecryptfs_lookup_in dentry_info->lower_path.mnt = lower_mnt; dentry_info->lower_path.dentry = lower_dentry; - if (d_really_is_negative(lower_dentry)) { + /* + * negative dentry can go positive under us here - its parent is not + * locked. That's OK and that could happen just as we return from + * ecryptfs_lookup() anyway. Just need to be careful and fetch + * ->d_inode only once - it's not stable here. + */ + lower_inode = READ_ONCE(lower_dentry->d_inode); + + if (!lower_inode) { /* We want to add because we couldn't find in lower */ d_add(dentry, NULL); return NULL;