Re: [PATCH v2 1/3] cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
Paulo Alcantara <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
Frank Sorenson <[email protected]> writes: > When the else branch of cifs_file_set_size() finds a writable file handle > via find_writable_file(), it borrows tcon and server from the handle's > tlink, attempts the handle-based set_file_size() RPC, and then releases > the handle with cifsFileInfo_put(). > > If set_file_size() fails, execution falls through to the path-based > fallback, which reuses the borrowed tcon and server under the > "if (tcon == NULL)" guard. Since tcon is not NULL at that point, the > guard is skipped. If cifsFileInfo_put() dropped the last reference on a > tlink that was already removed from the tlink tree (TCON_LINK_IN_TREE > cleared, as happens during reconnection or session teardown), > cifs_put_tlink() will have freed tcon; the subsequent set_path_size() > call is then a use-after-free. > > Setting tcon = NULL after cifsFileInfo_put() causes the existing guard > to take the cifs_sb_tlink() path, which acquires a fresh reference for > the path-based operation or fails cleanly if the session is gone. > ... Applied.