Re: [PATCH v4 3/3] fuse: deduplicate the oversized-request error selection

Joanne Koong <[email protected]>
Newsgroups org.kernel.vger.linux-hardening,dev.linux.lists.fuse-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <CAJnrk1YRmyaPeeBgd2HQSfmwDYm08cev__Y8LgyPyTqaTZE1vw@mail.gmail.com>
On Tue, Jul 14, 2026 at 4:54 PM Xiang Mei <[email protected]> wrote:
>
> fuse_dev_do_read() and fuse_uring_args_to_ring() both pick the error for
> a request that does not fit the server's buffer, and both special-case
> FUSE_SETXATTR.  Move that choice into a helper so the two transports
> cannot drift apart.
>
> No functional change.
>
> Signed-off-by: Xiang Mei <[email protected]>
> ---
> v4: introduce fuse_req_too_large_error as a helper
>
>  fs/fuse/dev.c        | 5 +----
>  fs/fuse/dev_uring.c  | 2 +-
>  fs/fuse/fuse_dev_i.h | 7 +++++++
>  3 files changed, 9 insertions(+), 5 deletions(-)
>
> diff --git a/fs/fuse/dev.c b/fs/fuse/dev.c
> index b8e43e374b35..56c38aca7389 100644
> --- a/fs/fuse/dev.c
> +++ b/fs/fuse/dev.c
> @@ -1584,10 +1584,7 @@ static ssize_t fuse_dev_do_read(struct fuse_dev *fud, struct file *file,
>
>         /* If request is too large, reply with an error and restart the read */
>         if (nbytes < reqsize) {
> -               req->out.h.error = -EIO;
> -               /* SETXATTR is special, since it may contain too large data */
> -               if (args->opcode == FUSE_SETXATTR)
> -                       req->out.h.error = -E2BIG;
> +               req->out.h.error = fuse_req_too_large_error(args);
>                 fuse_request_end(req);
>                 goto restart;
>         }
> diff --git a/fs/fuse/dev_uring.c b/fs/fuse/dev_uring.c
> index 4529505b2bca..cebd8f871627 100644
> --- a/fs/fuse/dev_uring.c
> +++ b/fs/fuse/dev_uring.c
> @@ -729,7 +729,7 @@ static int fuse_uring_args_to_ring(struct fuse_ring *ring, struct fuse_req *req,
>         }
>
>         if (fuse_len_args(num_args, (struct fuse_arg *)in_args) > ent->payload_sz)
> -               return args->opcode == FUSE_SETXATTR ? -E2BIG : -EIO;
> +               return fuse_req_too_large_error(args);
>
>         /* copy the payload */
>         err = fuse_copy_args(&cs, num_args, args->in_pages,
> diff --git a/fs/fuse/fuse_dev_i.h b/fs/fuse/fuse_dev_i.h
> index b511aaab6bfc..4958158c0f02 100644
> --- a/fs/fuse/fuse_dev_i.h
> +++ b/fs/fuse/fuse_dev_i.h
> @@ -13,6 +13,8 @@
>  #include <linux/workqueue.h>
>  #include <linux/fs.h>
>
> +#include "args.h"
> +
>  /* Ordinary requests have even IDs, while interrupts IDs are odd */
>  #define FUSE_INT_REQ_BIT (1ULL << 0)
>  #define FUSE_REQ_ID_STEP (1ULL << 1)
> @@ -367,6 +369,11 @@ static inline struct fuse_dev *__fuse_get_dev(struct file *file)
>         return fud;
>  }
>
> +static inline int fuse_req_too_large_error(struct fuse_args *args)
> +{
> +       return args->opcode == FUSE_SETXATTR ? -E2BIG : -EIO;
> +}

Could you add a comment to the top of this function? Maybe something
like "A request whose payload size exceeds the transport buffer size
is rejected with -EIO. The exception is FUSE_SETXATTR whose value may
legitimately be oversized and is rejected with -E2BIG, matching the
vfs setxattr path".

Reviewed-by: Joanne Koong <[email protected]>

Thanks,
Joanne
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.