From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 28 Aug 2026 15:02:49 +0200 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzwEK-008A6d-13 for lore@lore.pengutronix.de; Fri, 28 Aug 2026 15:02:49 +0200 Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id E16EA201D27 for ; Fri, 28 Aug 2026 15:02:48 +0200 (CEST) Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b=M2+0DtHW; dmarc=none; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:MIME-Version:Date:Message-Id:Subject:References:In-Reply-To:To: From:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=O5BFyTyHJtPbIoPBPPRsa09+ke9VRVQtBh6sI7TMdpo=; b=M2+0DtHWyRNhgxhUVlLya2hHJU WzThsGb3er//9jcBTLV2um+MQBV4NXtUqROFW8Ab+6pIsdeTp4XkIfJrCYVjrzG3OgEkKLpAminPG FitvTQa9T5qzu3fjTxI6b81KLxU9u89II/bpdkDRvk6Bu5KFNzbxWKTh1ld3VvQyOhvfzYG/hEhp0 hXK2ZAcmkmMsvUWJPBomN0jw2SnkC8js2V6HJRwye0RaJln5tSbQmVqVJrLaAZ50xuo57abXFQzYb 3X6ATzyg4Aq2Y1pFEGJI+RPHSiicrs3vs53cD19e7rK1NHTy0+LZOREf7Gb0o6RHWBAcqIWqrLgXE v0sgNTUQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzwDA-00000005mU6-3gGh; Fri, 28 Aug 2026 13:01:36 +0000 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzwD7-00000005mTS-2iUd for barebox@lists.infradead.org; Fri, 28 Aug 2026 13:01:35 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id 40AA5201D27; Fri, 28 Aug 2026 15:01:31 +0200 (CEST) Received: from dude02.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::28]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzwD5-003lxR-0a; Fri, 28 Aug 2026 15:01:31 +0200 Received: from [::1] (helo=dude02.red.stw.pengutronix.de) by dude02.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1wzwD5-00000001vYQ-0UMf; Fri, 28 Aug 2026 15:01:31 +0200 From: Sascha Hauer To: barebox@lists.infradead.org, Ahmad Fatoum In-Reply-To: <20260826094033.2545168-1-a.fatoum@pengutronix.de> References: <20260826094033.2545168-1-a.fatoum@pengutronix.de> Subject: Re: [PATCH] fs: don't leak the parent path when openat() fails after the lookup Message-Id: <178792209111.459451.4626581437630596295.b4-ty@pengutronix.de> Date: Fri, 28 Aug 2026 15:01:31 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Mailer: b4 0.14.3 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260828_060133_841261_3588E14B X-CRM114-Status: UNSURE ( 6.49 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: On Wed, 26 Aug 2026 11:40:32 +0200, Ahmad Fatoum wrote: > openat() jumps to out1 on three errors that happen after the lookup has > succeeded, and none of them drops what the lookup took: > > - creat [...] Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Spamd-Result: default: False [-57.81 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-3.00)[99.99%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; RCVD_IN_DNSWL_MED(-0.60)[2a0a:edc0:0:c01:1d::a2:received,2607:7c80:54:3::133:from,2a0a:edc0:0:1101:1d::28:received]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; MAILLIST(-0.20)[mailman]; R_SPF_ALLOW(-0.20)[+mx:c]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; DMARC_NA(0.00)[pengutronix.de]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; DKIM_TRACE(0.00)[lists.infradead.org:+]; RCVD_COUNT_FIVE(0.00)[5]; FROM_NEQ_ENVFROM(0.00)[s.hauer@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; TAGGED_FROM(0.00)[lore=pengutronix.de]; NEURAL_HAM(-0.00)[-0.997]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; TO_DN_SOME(0.00)[]; FORGED_SENDER_MAILLIST(0.00)[] X-Rspamd-Action: no action X-Rspamd-Server: mx1 X-Stat-Signature: yft3ejwz56x8o3hrth47x8b4xd819nrj X-Rspamd-Queue-Id: E16EA201D27 On Wed, 26 Aug 2026 11:40:32 +0200, Ahmad Fatoum wrote: > openat() jumps to out1 on three errors that happen after the lookup has > succeeded, and none of them drops what the lookup took: > > - create() failing leaves both the negative dentry that filename_create() > returned and the parent path it filled in. > - The -ENOENT branch dputs the dentry, which is path.dentry here, but not > the vfsmount reference held alongside it. > - The -EISDIR branch drops nothing at all. > > [...] Applied, thanks! [1/1] fs: don't leak the parent path when openat() fails after the lookup https://git.pengutronix.de/cgit/barebox/commit/?id=d1fc63ad66c4 (link may not be stable) Best regards, -- Sascha Hauer