Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 32fe905c authored by Richard Weinberger's avatar Richard Weinberger
Browse files

ubifs: Fix O_TMPFILE corner case in ubifs_link()



It is perfectly fine to link a tmpfile back using linkat().
Since tmpfiles are created with a link count of 0 they appear
on the orphan list, upon re-linking the inode has to be removed
from the orphan list again.

Ralph faced a filesystem corruption in combination with overlayfs
due to this bug.

Cc: <stable@vger.kernel.org>
Cc: Ralph Sennhauser <ralph.sennhauser@gmail.com>
Cc: Amir Goldstein <amir73il@gmail.com>
Reported-by: default avatarRalph Sennhauser <ralph.sennhauser@gmail.com>
Tested-by: default avatarRalph Sennhauser <ralph.sennhauser@gmail.com>
Reported-by: default avatarAmir Goldstein <amir73il@gmail.com>
Fixes: 474b9370 ("ubifs: Implement O_TMPFILE")
Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
parent c3d9fda6
Loading
Loading
Loading
Loading
+7 −0
Original line number Original line Diff line number Diff line
@@ -748,6 +748,11 @@ static int ubifs_link(struct dentry *old_dentry, struct inode *dir,
		goto out_fname;
		goto out_fname;


	lock_2_inodes(dir, inode);
	lock_2_inodes(dir, inode);

	/* Handle O_TMPFILE corner case, it is allowed to link a O_TMPFILE. */
	if (inode->i_nlink == 0)
		ubifs_delete_orphan(c, inode->i_ino);

	inc_nlink(inode);
	inc_nlink(inode);
	ihold(inode);
	ihold(inode);
	inode->i_ctime = ubifs_current_time(inode);
	inode->i_ctime = ubifs_current_time(inode);
@@ -768,6 +773,8 @@ static int ubifs_link(struct dentry *old_dentry, struct inode *dir,
	dir->i_size -= sz_change;
	dir->i_size -= sz_change;
	dir_ui->ui_size = dir->i_size;
	dir_ui->ui_size = dir->i_size;
	drop_nlink(inode);
	drop_nlink(inode);
	if (inode->i_nlink == 0)
		ubifs_add_orphan(c, inode->i_ino);
	unlock_2_inodes(dir, inode);
	unlock_2_inodes(dir, inode);
	ubifs_release_budget(c, &req);
	ubifs_release_budget(c, &req);
	iput(inode);
	iput(inode);