summaryrefslogtreecommitdiffstats
path: root/fs
diff options
context:
space:
mode:
authorAl Viro <viro@zeniv.linux.org.uk>2018-05-17 17:18:30 -0400
committerAl Viro <viro@zeniv.linux.org.uk>2018-05-21 14:30:11 -0400
commit5aa1437d2d9a068c0334bd7c9dafa8ec4f97f13b (patch)
tree1f8e9a78b800f50fef4277a7971415c1412fb6c4 /fs
parent3819bb0d79f50b05910db5bdc6d9ef512184e3b1 (diff)
ext2: fix a block leak
open file, unlink it, then use ioctl(2) to make it immutable or append only. Now close it and watch the blocks *not* freed... Immutable/append-only checks belong in ->setattr(). Note: the bug is old and backport to anything prior to 737f2e93b972 ("ext2: convert to use the new truncate convention") will need these checks lifted into ext2_setattr(). Cc: stable@kernel.org Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Diffstat (limited to 'fs')
-rw-r--r--fs/ext2/inode.c10
1 files changed, 0 insertions, 10 deletions
diff --git a/fs/ext2/inode.c b/fs/ext2/inode.c
index 1e01fabef130..71635909df3b 100644
--- a/fs/ext2/inode.c
+++ b/fs/ext2/inode.c
@@ -1264,21 +1264,11 @@ do_indirects:
1264 1264
1265static void ext2_truncate_blocks(struct inode *inode, loff_t offset) 1265static void ext2_truncate_blocks(struct inode *inode, loff_t offset)
1266{ 1266{
1267 /*
1268 * XXX: it seems like a bug here that we don't allow
1269 * IS_APPEND inode to have blocks-past-i_size trimmed off.
1270 * review and fix this.
1271 *
1272 * Also would be nice to be able to handle IO errors and such,
1273 * but that's probably too much to ask.
1274 */
1275 if (!(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode) || 1267 if (!(S_ISREG(inode->i_mode) || S_ISDIR(inode->i_mode) ||
1276 S_ISLNK(inode->i_mode))) 1268 S_ISLNK(inode->i_mode)))
1277 return; 1269 return;
1278 if (ext2_inode_is_fast_symlink(inode)) 1270 if (ext2_inode_is_fast_symlink(inode))
1279 return; 1271 return;
1280 if (IS_APPEND(inode) || IS_IMMUTABLE(inode))
1281 return;
1282 1272
1283 dax_sem_down_write(EXT2_I(inode)); 1273 dax_sem_down_write(EXT2_I(inode));
1284 __ext2_truncate_blocks(inode, offset); 1274 __ext2_truncate_blocks(inode, offset);