diff mbox series

NFS: abort nfs_atomic_open_v23 if name is too long.

Message ID 171693789645.27191.13475059024941012614@noble.neil.brown.name
State Not Applicable
Headers show
Series NFS: abort nfs_atomic_open_v23 if name is too long. | expand

Commit Message

NeilBrown May 28, 2024, 11:11 p.m. UTC
An attempt to open a file with a name longer than NFS3_MAXNAMLEN will
trigger a WARN_ON_ONCE in encode_filename3() because
nfs_atomic_open_v23() doesn't have the test on ->d_name.len that
nfs_atomic_open() has.

So add that test.

Reported-by: James Clark <james.clark@arm.com>
Closes: https://lore.kernel.org/all/20240528105249.69200-1-james.clark@arm.com/
Fixes: 7c6c5249f061 ("NFS: add atomic_open for NFSv3 to handle O_TRUNC correctly.")
Signed-off-by: NeilBrown <neilb@suse.de>
---
 fs/nfs/dir.c | 3 +++
 1 file changed, 3 insertions(+)

Comments

Christoph Hellwig May 29, 2024, 6:25 a.m. UTC | #1
Looks good:

Reviewed-by: Christoph Hellwig <hch@lst.de>
diff mbox series

Patch

diff --git a/fs/nfs/dir.c b/fs/nfs/dir.c
index 342930996226..2b09b5416ef1 100644
--- a/fs/nfs/dir.c
+++ b/fs/nfs/dir.c
@@ -2255,6 +2255,9 @@  int nfs_atomic_open_v23(struct inode *dir, struct dentry *dentry,
 	 */
 	int error = 0;
 
+	if (dentry->d_name.len > NFS_SERVER(dir)->namelen)
+		return -ENAMETOOLONG;
+
 	if (open_flags & O_CREAT) {
 		file->f_mode |= FMODE_CREATED;
 		error = nfs_do_create(dir, dentry, mode, open_flags);