Re: [PATCH] ceph: fix use-after-dereference of NULL ci in __ceph_remove_cap()
Viacheslav Dubeyko <[email protected]> Tue, 14 Jul 2026 10:46:07 -0700
| Newsgroups | org.kernel.vger.ceph-devel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 2026-07-14 at 14:20 +0800, Xiubo Li via B4 Relay wrote: > From: Xiubo Li <[email protected]> > > The NULL check for "ci" in __ceph_remove_cap() was dead code because > ci was dereferenced via &ci->netfs.inode before the check, and > cap->session was dereferenced via session->s_mdsc->fsc->client even > earlier. On a double-remove, both cap->ci and cap->session are set > to NULL by the first call, so the second call would crash before > ever reaching the guard. > > Move ci, session, cl, and inode initializations after the NULL check > so that the early-return actually works. > > Signed-off-by: Xiubo Li <[email protected]> > --- > fs/ceph/caps.c | 17 ++++++++++------- > 1 file changed, 10 insertions(+), 7 deletions(-) > > diff --git a/fs/ceph/caps.c b/fs/ceph/caps.c > index f8d898ad091e..8568edf494b5 100644 > --- a/fs/ceph/caps.c > +++ b/fs/ceph/caps.c > @@ -1154,18 +1154,21 @@ int ceph_is_any_caps(struct inode *inode) > */ > void __ceph_remove_cap(struct ceph_cap *cap, bool queue_release) > { > - struct ceph_mds_session *session = cap->session; > - struct ceph_client *cl = session->s_mdsc->fsc->client; > - struct ceph_inode_info *ci = cap->ci; > - struct inode *inode = &ci->netfs.inode; > + struct ceph_mds_session *session; > + struct ceph_client *cl; > + struct ceph_inode_info *ci; > + struct inode *inode; > struct ceph_mds_client *mdsc; > int removed = 0; > > /* 'ci' being NULL means the remove have already occurred */ > - if (!ci) { > - doutc(cl, "inode is NULL\n"); > + ci = cap->ci; > + if (!ci) > return; > - } > + > + session = cap->session; > + cl = session->s_mdsc->fsc->client; > + inode = &ci->netfs.inode; > > lockdep_assert_held(&ci->i_ceph_lock); > > > --- > base-commit: fc67edb66b3c9924c4e0bb366a92b32ea13c526a > change-id: 20260714-ceph-fix-remove-cap-cf7d8a7a242a > > Best regards, > -- > Xiubo Li <[email protected]> Makes sense. Reviewed-by: Viacheslav Dubeyko <[email protected]> Thanks, Slava.