aboutsummaryrefslogtreecommitdiffstats
path: root/fs
diff options
context:
space:
mode:
authorJeff Layton <jlayton@redhat.com>2011-08-05 09:02:40 -0400
committerGreg Kroah-Hartman <gregkh@suse.de>2011-08-15 18:31:36 -0700
commitcae28d950cc7319a7e88deccbb0c4492f0830e6e (patch)
tree603d7c619e4d7c61b8cffbc7df5bc34f812f4f5d /fs
parent6fd70fafa11fd88d5beee360395f4c0b28d7af43 (diff)
downloadkernel_samsung_aries-cae28d950cc7319a7e88deccbb0c4492f0830e6e.zip
kernel_samsung_aries-cae28d950cc7319a7e88deccbb0c4492f0830e6e.tar.gz
kernel_samsung_aries-cae28d950cc7319a7e88deccbb0c4492f0830e6e.tar.bz2
cifs: cope with negative dentries in cifs_get_root
commit 80975d21aae2136ccae1ce914a1602dc1d8b0795 upstream. The loop around lookup_one_len doesn't handle the case where it might return a negative dentry, which can cause an oops on the next pass through the loop. Check for that and break out of the loop with an error of -ENOENT if there is one. Fixes the panic reported here: https://bugzilla.redhat.com/show_bug.cgi?id=727927 Reported-by: TR Bentley <home@trarbentley.net> Reported-by: Iain Arnell <iarnell@gmail.com> Cc: Al Viro <viro@ZenIV.linux.org.uk> Signed-off-by: Jeff Layton <jlayton@redhat.com> Signed-off-by: Steve French <sfrench@us.ibm.com> Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
Diffstat (limited to 'fs')
-rw-r--r--fs/cifs/cifsfs.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/fs/cifs/cifsfs.c b/fs/cifs/cifsfs.c
index bc4b12c..fc7e57b 100644
--- a/fs/cifs/cifsfs.c
+++ b/fs/cifs/cifsfs.c
@@ -581,6 +581,10 @@ cifs_get_root(struct smb_vol *vol, struct super_block *sb)
mutex_unlock(&dir->i_mutex);
dput(dentry);
dentry = child;
+ if (!dentry->d_inode) {
+ dput(dentry);
+ dentry = ERR_PTR(-ENOENT);
+ }
} while (!IS_ERR(dentry));
_FreeXid(xid);
kfree(full_path);