]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
f2fs: fix to check atomic_file in f2fs ioctl interfaces
authorChao Yu <chao@kernel.org>
Wed, 4 Sep 2024 03:20:47 +0000 (11:20 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 4 Oct 2024 14:33:39 +0000 (16:33 +0200)
commit bfe5c02654261bfb8bd9cb174a67f3279ea99e58 upstream.

Some f2fs ioctl interfaces like f2fs_ioc_set_pin_file(),
f2fs_move_file_range(), and f2fs_defragment_range() missed to
check atomic_write status, which may cause potential race issue,
fix it.

Cc: stable@vger.kernel.org
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/f2fs/file.c

index d4d8914db71458542e6e0840f59ebba61e38c4cd..4bee980c6d186233b7a3ff41d6f56028cdd61e6f 100644 (file)
@@ -2704,7 +2704,8 @@ static int f2fs_defragment_range(struct f2fs_sb_info *sbi,
                                (range->start + range->len) >> PAGE_SHIFT,
                                DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE));
 
-       if (is_inode_flag_set(inode, FI_COMPRESS_RELEASED)) {
+       if (is_inode_flag_set(inode, FI_COMPRESS_RELEASED) ||
+               f2fs_is_atomic_file(inode)) {
                err = -EINVAL;
                goto unlock_out;
        }
@@ -2937,6 +2938,11 @@ static int f2fs_move_file_range(struct file *file_in, loff_t pos_in,
                goto out_unlock;
        }
 
+       if (f2fs_is_atomic_file(src) || f2fs_is_atomic_file(dst)) {
+               ret = -EINVAL;
+               goto out_unlock;
+       }
+
        ret = -EINVAL;
        if (pos_in + len > src->i_size || pos_in + len < pos_in)
                goto out_unlock;
@@ -3320,6 +3326,11 @@ static int f2fs_ioc_set_pin_file(struct file *filp, unsigned long arg)
 
        inode_lock(inode);
 
+       if (f2fs_is_atomic_file(inode)) {
+               ret = -EINVAL;
+               goto out;
+       }
+
        if (!pin) {
                clear_inode_flag(inode, FI_PIN_FILE);
                f2fs_i_gc_failures_write(inode, 0);