diff options
author | Jeff Layton <jlayton@redhat.com> | 2011-08-05 15:02:40 +0200 |
---|---|---|
committer | Steve French <sfrench@us.ibm.com> | 2011-08-05 17:03:09 +0200 |
commit | 80975d21aae2136ccae1ce914a1602dc1d8b0795 (patch) | |
tree | e2c5d8b441d3ff206c9dc671ade8f3d7c453e2d2 | |
parent | cifs: convert prefixpath delimiters in cifs_build_path_to_root (diff) | |
download | linux-80975d21aae2136ccae1ce914a1602dc1d8b0795.tar.xz linux-80975d21aae2136ccae1ce914a1602dc1d8b0795.zip |
cifs: cope with negative dentries in cifs_get_root
The loop around lookup_one_len doesn't handle the case where it might
return a negative dentry, which can cause an oops on the next pass
through the loop. Check for that and break out of the loop with an
error of -ENOENT if there is one.
Fixes the panic reported here:
https://bugzilla.redhat.com/show_bug.cgi?id=727927
Reported-by: TR Bentley <home@trarbentley.net>
Reported-by: Iain Arnell <iarnell@gmail.com>
Cc: Al Viro <viro@ZenIV.linux.org.uk>
Cc: stable@kernel.org
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
-rw-r--r-- | fs/cifs/cifsfs.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/fs/cifs/cifsfs.c b/fs/cifs/cifsfs.c index 212e5629cc1d..f93eb948d071 100644 --- a/fs/cifs/cifsfs.c +++ b/fs/cifs/cifsfs.c @@ -563,6 +563,10 @@ cifs_get_root(struct smb_vol *vol, struct super_block *sb) mutex_unlock(&dir->i_mutex); dput(dentry); dentry = child; + if (!dentry->d_inode) { + dput(dentry); + dentry = ERR_PTR(-ENOENT); + } } while (!IS_ERR(dentry)); _FreeXid(xid); kfree(full_path); |