Commit 600bec25 authored by Miklos Szeredi's avatar Miklos Szeredi Committed by Greg Kroah-Hartman

ovl: fix d_real() for stacked fs

commit c4fcfc16 upstream.

Handling of recursion in d_real() is completely broken.  Recursion is only
done in the 'inode != NULL' case.  But when opening the file we have
'inode == NULL' hence d_real() will return an overlay dentry.  This won't
work since overlayfs doesn't define its own file operations, so all file
ops will fail.

Fix by doing the recursion first and the check against the inode second.

Bash script to reproduce the issue written by Quentin:

 - 8< - - - - - 8< - - - - - 8< - - - - - 8< - - - -
tmpdir=$(mktemp -d)
pushd ${tmpdir}

mkdir -p {upper,lower,work}
echo -n 'rocks' > lower/ksplice
mount -t overlay level_zero upper -o lowerdir=lower,upperdir=upper,workdir=work
cat upper/ksplice

tmpdir2=$(mktemp -d)
pushd ${tmpdir2}

mkdir -p {upper,work}
mount -t overlay level_one upper -o lowerdir=${tmpdir}/upper,upperdir=upper,workdir=work
ls -l upper/ksplice
cat upper/ksplice
 - 8< - - - - - 8< - - - - - 8< - - - - - 8< - - - -
Reported-by: default avatarQuentin Casasnovas <quentin.casasnovas@oracle.com>
Signed-off-by: default avatarMiklos Szeredi <mszeredi@redhat.com>
Fixes: 2d902671 ("vfs: merge .d_select_inode() into .d_real()")
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 5661a692
...@@ -329,11 +329,11 @@ static struct dentry *ovl_d_real(struct dentry *dentry, ...@@ -329,11 +329,11 @@ static struct dentry *ovl_d_real(struct dentry *dentry,
if (!real) if (!real)
goto bug; goto bug;
/* Handle recursion */
real = d_real(real, inode, open_flags);
if (!inode || inode == d_inode(real)) if (!inode || inode == d_inode(real))
return real; return real;
/* Handle recursion */
return d_real(real, inode, open_flags);
bug: bug:
WARN(1, "ovl_d_real(%pd4, %s:%lu): real dentry not found\n", dentry, WARN(1, "ovl_d_real(%pd4, %s:%lu): real dentry not found\n", dentry,
inode ? inode->i_sb->s_id : "NULL", inode ? inode->i_ino : 0); inode ? inode->i_sb->s_id : "NULL", inode ? inode->i_ino : 0);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment