]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
authorChia-Ming Chang <chiamingc@synology.com>
Tue, 24 Feb 2026 09:34:42 +0000 (17:34 +0800)
committerJan Kara <jack@suse.cz>
Thu, 26 Feb 2026 14:11:50 +0000 (15:11 +0100)
When fsnotify_add_inode_mark_locked() fails in inotify_new_watch(),
the error path calls inotify_remove_from_idr() but does not call
dec_inotify_watches() to undo the preceding inc_inotify_watches().
This leaks a watch count, and repeated failures can exhaust the
max_user_watches limit with -ENOSPC even when no watches are active.

Prior to commit 1cce1eea0aff ("inotify: Convert to using per-namespace
limits"), the watch count was incremented after fsnotify_add_mark_locked()
succeeded, so this path was not affected. The conversion moved
inc_inotify_watches() before the mark insertion without adding the
corresponding rollback.

Add the missing dec_inotify_watches() call in the error path.

Fixes: 1cce1eea0aff ("inotify: Convert to using per-namespace limits")
Cc: stable@vger.kernel.org
Signed-off-by: Chia-Ming Chang <chiamingc@synology.com>
Signed-off-by: robbieko <robbieko@synology.com>
Reviewed-by: Nikolay Borisov <nik.borisov@suse.com>
Link: https://patch.msgid.link/20260224093442.3076294-1-chiamingc@synology.com
Signed-off-by: Jan Kara <jack@suse.cz>
fs/notify/inotify/inotify_user.c

index 5e1845f2c25dd2b8e5687a11e4afc9116623bc8a..2edac3b391787cb12cb35715408830b1e923620b 100644 (file)
@@ -621,6 +621,7 @@ static int inotify_new_watch(struct fsnotify_group *group,
        if (ret) {
                /* we failed to get on the inode, get off the idr */
                inotify_remove_from_idr(group, tmp_i_mark);
+               dec_inotify_watches(group->inotify_data.ucounts);
                goto out_err;
        }