From: Chao Yu <chao@xxxxxxxxxx> commit bfe5c02654261bfb8bd9cb174a67f3279ea99e58 upstream. Some f2fs ioctl interfaces like f2fs_ioc_set_pin_file(), f2fs_move_file_range(), and f2fs_defragment_range() missed to check atomic_write status, which may cause potential race issue, fix it. Cc: stable@xxxxxxxxxxxxxxx Signed-off-by: Chao Yu <chao@xxxxxxxxxx> Signed-off-by: Jaegeuk Kim <jaegeuk@xxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- fs/f2fs/file.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) --- a/fs/f2fs/file.c +++ b/fs/f2fs/file.c @@ -2703,7 +2703,8 @@ static int f2fs_defragment_range(struct (range->start + range->len) >> PAGE_SHIFT, DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE)); - if (is_inode_flag_set(inode, FI_COMPRESS_RELEASED)) { + if (is_inode_flag_set(inode, FI_COMPRESS_RELEASED) || + f2fs_is_atomic_file(inode)) { err = -EINVAL; goto unlock_out; } @@ -2936,6 +2937,11 @@ static int f2fs_move_file_range(struct f goto out_unlock; } + if (f2fs_is_atomic_file(src) || f2fs_is_atomic_file(dst)) { + ret = -EINVAL; + goto out_unlock; + } + ret = -EINVAL; if (pos_in + len > src->i_size || pos_in + len < pos_in) goto out_unlock; @@ -3319,6 +3325,11 @@ static int f2fs_ioc_set_pin_file(struct inode_lock(inode); + if (f2fs_is_atomic_file(inode)) { + ret = -EINVAL; + goto out; + } + if (!pin) { clear_inode_flag(inode, FI_PIN_FILE); f2fs_i_gc_failures_write(inode, 0); Patches currently in stable-queue which might be from chao@xxxxxxxxxx are queue-6.10/f2fs-fix-to-don-t-set-sb_rdonly-in-f2fs_handle_criti.patch queue-6.10/f2fs-fix-several-potential-integer-overflows-in-file-offsets.patch queue-6.10/f2fs-fix-to-wait-page-writeback-before-setting-gcing.patch queue-6.10/f2fs-prevent-possible-int-overflow-in-dir_block_index.patch queue-6.10/f2fs-fix-to-avoid-use-after-free-in-f2fs_stop_gc_thr.patch queue-6.10/f2fs-avoid-potential-int-overflow-in-sanity_check_area_boundary.patch queue-6.10/f2fs-fix-to-check-atomic_file-in-f2fs-ioctl-interfaces.patch queue-6.10/f2fs-create-cow-inode-from-parent-dentry-for-atomic-.patch queue-6.10/f2fs-atomic-fix-to-avoid-racing-w-gc.patch queue-6.10/f2fs-fix-to-avoid-racing-in-between-read-and-opu-dio.patch queue-6.10/f2fs-reduce-expensive-checkpoint-trigger-frequency.patch queue-6.10/f2fs-require-fmode_write-for-atomic-write-ioctls.patch queue-6.10/revert-f2fs-use-flush-command-instead-of-fua-for-zoned-device.patch queue-6.10/f2fs-get-rid-of-online-repaire-on-corrupted-director.patch queue-6.10/f2fs-compress-don-t-redirty-sparse-cluster-during-de.patch queue-6.10/f2fs-atomic-fix-to-truncate-pagecache-before-on-disk.patch queue-6.10/f2fs-check-discard-support-for-conventional-zones.patch