Re: [PATCH] 9p: don't WARN_ONCE on racy symlink fid lookup failure
Deepanshu Kartikey <[email protected]>
| Newsgroups | dev.linux.lists.v9fs,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CADhLXY6OdJXA2-yxCbdSjcrJDDyvb=pmQKOvdGXEsg77Bm-JYA@mail.gmail.com> |
On Sat, Jul 25, 2026 at 7:14 AM Deepanshu Kartikey <[email protected]> wrote: > > v9fs_init_request() WARN_ONCE()s when v9fs_fid_lookup() fails for a > symlink read via the page cache. This is a benign TOCTOU race: a > concurrent unlink()/rename() can remove the target between the walk > finding the dentry and p9_client_walk() completing, so the lookup > legitimately fails with -ENOENT (observed: dentry=/file0, err=-2). > > With panic_on_warn=1, this WARN escalates to a full kernel panic -- > an unprivileged local DoS reachable by racing mount() against a > concurrent unlink/rename. > > Return the error directly instead of WARN_ONCE(). > > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=344c09c64fcd8d3d2782 > Signed-off-by: Deepanshu Kartikey <[email protected]> > --- > fs/9p/vfs_addr.c | 5 ++++- > 1 file changed, 4 insertions(+), 1 deletion(-) > > diff --git a/fs/9p/vfs_addr.c b/fs/9p/vfs_addr.c > index 1ac0b3dcc077..121679488ab9 100644 > --- a/fs/9p/vfs_addr.c > +++ b/fs/9p/vfs_addr.c > @@ -140,13 +140,16 @@ static int v9fs_init_request(struct netfs_io_request *rreq, struct file *file) > goto no_fid; > p9_fid_get(fid); > } else if (S_ISLNK(rreq->inode->i_mode)) { > + /* racing unlink/rename can make this fail with -ENOENT; > + * that's expected, not a kernel bug, so don't WARN > + */ > dentry = d_find_any_alias(rreq->inode); > if (!dentry) > goto no_fid; > fid = v9fs_fid_lookup(dentry); > dput(dentry); > if (IS_ERR(fid)) > - goto no_fid; > + return PTR_ERR(fid); > } else { > fid = v9fs_fid_find_inode(rreq->inode, writing, INVALID_UID, true); > if (!fid) > -- > 2.43.0 > Gentle Reminder. Let me know anythng else needed from my side. Thanks Deepanshu