summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAnand Jain <anand.jain@oracle.com>2022-11-10 11:36:29 +0530
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2022-12-02 17:41:12 +0100
commitf218b404fc0e06852f5aec96706518a31fd4d668 (patch)
tree5f429eb4a40ae298f71b33eb5bcd09c9d0ccd01d
parentfea9397101c164aab65cd079e734addf473ceea9 (diff)
downloadlinux-f218b404fc0e06852f5aec96706518a31fd4d668.tar.gz
linux-f218b404fc0e06852f5aec96706518a31fd4d668.tar.bz2
linux-f218b404fc0e06852f5aec96706518a31fd4d668.zip
btrfs: free btrfs_path before copying fspath to userspace
commit 8cf96b409d9b3946ece58ced13f92d0f775b0442 upstream. btrfs_ioctl_ino_to_path() frees the search path after the userspace copy from the temp buffer @ipath->fspath. Which potentially can lead to a lock splat warning. Fix this by freeing the path before we copy it to userspace. CC: stable@vger.kernel.org # 4.19+ Signed-off-by: Anand Jain <anand.jain@oracle.com> Reviewed-by: David Sterba <dsterba@suse.com> Signed-off-by: David Sterba <dsterba@suse.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--fs/btrfs/ioctl.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/fs/btrfs/ioctl.c b/fs/btrfs/ioctl.c
index 72ede0280c74..ce669ed21d54 100644
--- a/fs/btrfs/ioctl.c
+++ b/fs/btrfs/ioctl.c
@@ -3892,6 +3892,8 @@ static long btrfs_ioctl_ino_to_path(struct btrfs_root *root, void __user *arg)
ipath->fspath->val[i] = rel_ptr;
}
+ btrfs_free_path(path);
+ path = NULL;
ret = copy_to_user((void __user *)(unsigned long)ipa->fspath,
ipath->fspath, size);
if (ret) {