]> git.ipfire.org Git - thirdparty/linux.git/commit
ext4: don't treat fhandle lookup of ea_inode as FS corruption
authorJann Horn <jannh@google.com>
Fri, 29 Nov 2024 20:20:53 +0000 (21:20 +0100)
committerTheodore Ts'o <tytso@mit.edu>
Thu, 10 Apr 2025 14:53:50 +0000 (10:53 -0400)
commit642335f3ea2b3fd6dba03e57e01fa9587843a497
treea8f247a69521644eea0db246cc26f1b717f197ae
parentd5e206778e96e8667d3bde695ad372c296dc9353
ext4: don't treat fhandle lookup of ea_inode as FS corruption

A file handle that userspace provides to open_by_handle_at() can
legitimately contain an outdated inode number that has since been reused
for another purpose - that's why the file handle also contains a generation
number.

But if the inode number has been reused for an ea_inode, check_igot_inode()
will notice, __ext4_iget() will go through ext4_error_inode(), and if the
inode was newly created, it will also be marked as bad by iget_failed().
This all happens before the point where the inode generation is checked.

ext4_error_inode() is supposed to only be used on filesystem corruption; it
should not be used when userspace just got unlucky with a stale file
handle. So when this happens, let __ext4_iget() just return an error.

Fixes: b3e6bcb94590 ("ext4: add EA_INODE checking to ext4_iget()")
Signed-off-by: Jann Horn <jannh@google.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20241129-ext4-ignore-ea-fhandle-v1-1-e532c0d1cee0@google.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
fs/ext4/inode.c