>From neilb@suse.de Thu Aug 3 17:53:52 2006 From: Neil Brown To: Greg KH Date: Fri, 4 Aug 2006 10:53:40 +1000 Message-ID: <17618.39572.764990.76181@cse.unsw.edu.au> Cc: Marcel Holtmann , Linus Torvalds , linux-kernel@vger.kernel.org, stable@kernel.org Subject: Have ext2 reject file handles with bad inode numbers early. From: Neil Brown This prevents bad inode numbers from triggering errors in ext2_get_inode. Signed-off-by: Neil Brown Signed-off-by: Greg Kroah-Hartman --- fs/ext2/super.c | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) --- linux-2.6.17.7.orig/fs/ext2/super.c +++ linux-2.6.17.7/fs/ext2/super.c @@ -252,6 +252,46 @@ static struct super_operations ext2_sops #endif }; +static struct dentry *ext2_get_dentry(struct super_block *sb, void *vobjp) +{ + __u32 *objp = vobjp; + unsigned long ino = objp[0]; + __u32 generation = objp[1]; + struct inode *inode; + struct dentry *result; + + if (ino != EXT2_ROOT_INO && ino < EXT2_FIRST_INO(sb)) + return ERR_PTR(-ESTALE); + if (ino > le32_to_cpu(EXT2_SB(sb)->s_es->s_inodes_count)) + return ERR_PTR(-ESTALE); + + /* iget isn't really right if the inode is currently unallocated!! + * ext2_read_inode currently does appropriate checks, but + * it might be "neater" to call ext2_get_inode first and check + * if the inode is valid..... + */ + inode = iget(sb, ino); + if (inode == NULL) + return ERR_PTR(-ENOMEM); + if (is_bad_inode(inode) + || (generation && inode->i_generation != generation) + ) { + /* we didn't find the right inode.. */ + iput(inode); + return ERR_PTR(-ESTALE); + } + /* now to find a dentry. + * If possible, get a well-connected one + */ + result = d_alloc_anon(inode); + if (!result) { + iput(inode); + return ERR_PTR(-ENOMEM); + } + return result; +} + + /* Yes, most of these are left as NULL!! * A NULL value implies the default, which works with ext2-like file * systems, but can be improved upon. @@ -259,6 +299,7 @@ static struct super_operations ext2_sops */ static struct export_operations ext2_export_ops = { .get_parent = ext2_get_parent, + .get_dentry = ext2_get_dentry, }; static unsigned long get_sb_block(void **data)