Skip to content

filelock: prevent FL_LEASE and FL_DELEG flavor confusion in generic_add_lease() - #2616

Open
vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169405/vfs.base.ci
Open

vfsci-bot[bot] wants to merge 1 commit into
vfs.base.cifrom
pw/1169405/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1169405
Submitter: Hui Peng
Version: 1
Patches: 1/1
Message-ID: <20260919210617.3028917-1-benquike@gmail.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260919210617.3028917-1-benquike@gmail.com


Automated by ml2pr

…dd_lease()

generic_add_lease() searches ctx->flc_lease for an existing entry
matching (flc_file == filp && flc_owner == lease->c.flc_owner) in order
to modify an existing lease in place via lease_modify(). However, it
does not verify that the existing entry's flavor (FL_LEASE vs FL_DELEG)
matches the newly requested lease's flavor in flc_flags.

Since both F_SETLEASE and F_SETDELEG pass filp as flc_owner from
userland (fcntl_setlease() and fcntl_setdeleg()), calling F_SETDELEG on
a file descriptor that already holds an FL_LEASE modifies flc_type in
place and returns 0 without setting FL_DELEG in flc_flags. Conversely,
calling F_SETLEASE on a file descriptor that holds an active FL_DELEG
modifies the delegation in place without holding inode_lock() (which
vfs_setlease() only acquires when is_deleg is true).

Reject cross-flavor modifications in generic_add_lease() when the
existing entry on ctx->flc_lease has a different (FL_LEASE | FL_DELEG)
flag mask from the requested lease.

Fixes: 1602bad ("vfs: expose delegation support to userland")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant