diff mbox

nfsd: fix bad offset use

Message ID 1363976304-26093-1-git-send-email-koverstreet@google.com (mailing list archive)
State New, archived
Headers show

Commit Message

Kent Overstreet March 22, 2013, 6:18 p.m. UTC
vfs_writev() updates the offset argument - but the code then passes the
offset to vfs_fsync_range(). Since offset now points to the offset after
what was just written, this is probably not what was intended

Signed-off-by: Kent Overstreet <koverstreet@google.com>
Cc: "J. Bruce Fields" <bfields@fieldses.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Zach Brown <zab@redhat.com>
---
 fs/nfsd/vfs.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

Comments

Zach Brown March 22, 2013, 7:14 p.m. UTC | #1
On Fri, Mar 22, 2013 at 11:18:24AM -0700, Kent Overstreet wrote:
> vfs_writev() updates the offset argument - but the code then passes the
> offset to vfs_fsync_range(). Since offset now points to the offset after
> what was just written, this is probably not what was intended

Agreed, the original code does look fishy and this fix right to me.

Reviewed-by: Zach Brown <zab@redhat.com> 

- z
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
J. Bruce Fields March 22, 2013, 8:53 p.m. UTC | #2
On Fri, Mar 22, 2013 at 11:18:24AM -0700, Kent Overstreet wrote:
> vfs_writev() updates the offset argument - but the code then passes the
> offset to vfs_fsync_range(). Since offset now points to the offset after
> what was just written, this is probably not what was intended

Whoops--thanks!  Looks like this was introduced by my
face15025ffdf664de95e86ae831544154d26c9c "nfsd: use vfs_fsync_range(),
not O_SYNC, for stable writes", in 3.8.

I'll queue up for 3.9 and stable.

--b.

> 
> Signed-off-by: Kent Overstreet <koverstreet@google.com>
> Cc: "J. Bruce Fields" <bfields@fieldses.org>
> Cc: Al Viro <viro@zeniv.linux.org.uk>
> Cc: "Eric W. Biederman" <ebiederm@xmission.com>
> Cc: Zach Brown <zab@redhat.com>
> ---
>  fs/nfsd/vfs.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
> index 2a7eb53..2b2e239 100644
> --- a/fs/nfsd/vfs.c
> +++ b/fs/nfsd/vfs.c
> @@ -1013,6 +1013,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
>  	int			host_err;
>  	int			stable = *stablep;
>  	int			use_wgather;
> +	loff_t			pos = offset;
>  
>  	dentry = file->f_path.dentry;
>  	inode = dentry->d_inode;
> @@ -1025,7 +1026,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
>  
>  	/* Write the data. */
>  	oldfs = get_fs(); set_fs(KERNEL_DS);
> -	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &offset);
> +	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &pos);
>  	set_fs(oldfs);
>  	if (host_err < 0)
>  		goto out_nfserr;
> -- 
> 1.8.1.3
> 
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
J. Bruce Fields March 22, 2013, 8:54 p.m. UTC | #3
On Fri, Mar 22, 2013 at 04:53:53PM -0400, J. Bruce Fields wrote:
> On Fri, Mar 22, 2013 at 11:18:24AM -0700, Kent Overstreet wrote:
> > vfs_writev() updates the offset argument - but the code then passes the
> > offset to vfs_fsync_range(). Since offset now points to the offset after
> > what was just written, this is probably not what was intended
> 
> Whoops--thanks!  Looks like this was introduced by my
> face15025ffdf664de95e86ae831544154d26c9c "nfsd: use vfs_fsync_range(),
> not O_SYNC, for stable writes", in 3.8.
> 
> I'll queue up for 3.9 and stable.

(By the way, out of curiosity: how did you stumble across this?)

--b.

> 
> --b.
> 
> > 
> > Signed-off-by: Kent Overstreet <koverstreet@google.com>
> > Cc: "J. Bruce Fields" <bfields@fieldses.org>
> > Cc: Al Viro <viro@zeniv.linux.org.uk>
> > Cc: "Eric W. Biederman" <ebiederm@xmission.com>
> > Cc: Zach Brown <zab@redhat.com>
> > ---
> >  fs/nfsd/vfs.c | 3 ++-
> >  1 file changed, 2 insertions(+), 1 deletion(-)
> > 
> > diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
> > index 2a7eb53..2b2e239 100644
> > --- a/fs/nfsd/vfs.c
> > +++ b/fs/nfsd/vfs.c
> > @@ -1013,6 +1013,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
> >  	int			host_err;
> >  	int			stable = *stablep;
> >  	int			use_wgather;
> > +	loff_t			pos = offset;
> >  
> >  	dentry = file->f_path.dentry;
> >  	inode = dentry->d_inode;
> > @@ -1025,7 +1026,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
> >  
> >  	/* Write the data. */
> >  	oldfs = get_fs(); set_fs(KERNEL_DS);
> > -	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &offset);
> > +	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &pos);
> >  	set_fs(oldfs);
> >  	if (host_err < 0)
> >  		goto out_nfserr;
> > -- 
> > 1.8.1.3
> > 
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Kent Overstreet March 22, 2013, 9:21 p.m. UTC | #4
On Fri, Mar 22, 2013 at 04:54:34PM -0400, J. Bruce Fields wrote:
> On Fri, Mar 22, 2013 at 04:53:53PM -0400, J. Bruce Fields wrote:
> > On Fri, Mar 22, 2013 at 11:18:24AM -0700, Kent Overstreet wrote:
> > > vfs_writev() updates the offset argument - but the code then passes the
> > > offset to vfs_fsync_range(). Since offset now points to the offset after
> > > what was just written, this is probably not what was intended
> > 
> > Whoops--thanks!  Looks like this was introduced by my
> > face15025ffdf664de95e86ae831544154d26c9c "nfsd: use vfs_fsync_range(),
> > not O_SYNC, for stable writes", in 3.8.
> > 
> > I'll queue up for 3.9 and stable.
> 
> (By the way, out of curiosity: how did you stumble across this?)

Just reading code - I've been trying to figure out how to improve the
way *pos pointers are passed around everywhere and I was looking at all
the users of various vfs code.

> --b.
> 
> > 
> > --b.
> > 
> > > 
> > > Signed-off-by: Kent Overstreet <koverstreet@google.com>
> > > Cc: "J. Bruce Fields" <bfields@fieldses.org>
> > > Cc: Al Viro <viro@zeniv.linux.org.uk>
> > > Cc: "Eric W. Biederman" <ebiederm@xmission.com>
> > > Cc: Zach Brown <zab@redhat.com>
> > > ---
> > >  fs/nfsd/vfs.c | 3 ++-
> > >  1 file changed, 2 insertions(+), 1 deletion(-)
> > > 
> > > diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
> > > index 2a7eb53..2b2e239 100644
> > > --- a/fs/nfsd/vfs.c
> > > +++ b/fs/nfsd/vfs.c
> > > @@ -1013,6 +1013,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
> > >  	int			host_err;
> > >  	int			stable = *stablep;
> > >  	int			use_wgather;
> > > +	loff_t			pos = offset;
> > >  
> > >  	dentry = file->f_path.dentry;
> > >  	inode = dentry->d_inode;
> > > @@ -1025,7 +1026,7 @@ nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
> > >  
> > >  	/* Write the data. */
> > >  	oldfs = get_fs(); set_fs(KERNEL_DS);
> > > -	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &offset);
> > > +	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &pos);
> > >  	set_fs(oldfs);
> > >  	if (host_err < 0)
> > >  		goto out_nfserr;
> > > -- 
> > > 1.8.1.3
> > > 
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
diff mbox

Patch

diff --git a/fs/nfsd/vfs.c b/fs/nfsd/vfs.c
index 2a7eb53..2b2e239 100644
--- a/fs/nfsd/vfs.c
+++ b/fs/nfsd/vfs.c
@@ -1013,6 +1013,7 @@  nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
 	int			host_err;
 	int			stable = *stablep;
 	int			use_wgather;
+	loff_t			pos = offset;
 
 	dentry = file->f_path.dentry;
 	inode = dentry->d_inode;
@@ -1025,7 +1026,7 @@  nfsd_vfs_write(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file *file,
 
 	/* Write the data. */
 	oldfs = get_fs(); set_fs(KERNEL_DS);
-	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &offset);
+	host_err = vfs_writev(file, (struct iovec __user *)vec, vlen, &pos);
 	set_fs(oldfs);
 	if (host_err < 0)
 		goto out_nfserr;