mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Ahmad Fatoum <a.fatoum@pengutronix.de>
To: barebox@lists.infradead.org
Cc: Ahmad Fatoum <a.fatoum@barebox.org>
Subject: [PATCH 6/6] fs: ubootvarfs: handle removal of variables that are still open
Date: Fri,  2 Oct 2026 13:40:09 +0200	[thread overview]
Message-ID: <20261002114253.2906535-7-a.fatoum@pengutronix.de> (raw)
In-Reply-To: <20261002114253.2906535-1-a.fatoum@pengutronix.de>

From: Ahmad Fatoum <a.fatoum@barebox.org>

Removing a variable frees it and clears the inode's pointer to it, but
an open file keeps the inode around with the old size. Reading, writing
or truncating it then dereferences the NULL pointer. The shell can get
there with a loop mount: after mount -o loop on a variable and rm of
it, md on /dev/loop0 or reading a file from the mount crashes.

Let's set the size of a removed variable to zero and return -ENOENT
for any further access to it.

Fixes: 8daaa21b3949 ("fs: Add a driver to access U-Boot environment variables")
Assisted-by: Claude:opus-5.5
Signed-off-by: Ahmad Fatoum <a.fatoum@barebox.org>
---
 fs/ubootvarfs.c | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

diff --git a/fs/ubootvarfs.c b/fs/ubootvarfs.c
index b0353d7cedef..e2d2a2f4aa77 100644
--- a/fs/ubootvarfs.c
+++ b/fs/ubootvarfs.c
@@ -266,7 +266,9 @@ static int ubootvarfs_unlink(struct inode *dir, struct dentry *dentry)
 
 		list_del(&var->list);
 		free(var);
+		/* open files keep the inode, see ubootvarfs_io() */
 		node->var = NULL;
+		inode->i_size = 0;
 	}
 
 	return simple_unlink(dir, dentry);
@@ -348,7 +350,13 @@ static int ubootvarfs_io(struct file *f, void *buf, size_t insize, bool read)
 {
 	struct inode *inode = f->f_inode;
 	struct ubootvarfs_inode *node = inode_to_node(inode);
-	void *ptr = node->var->start + f->f_pos;
+	void *ptr;
+
+	/* the variable was removed while the file was open */
+	if (!node->var)
+		return -ENOENT;
+
+	ptr = node->var->start + f->f_pos;
 
 	if (read)
 		memcpy(buf, ptr, insize);
@@ -376,6 +384,9 @@ static int ubootvarfs_truncate(struct file *f, loff_t size)
 	struct ubootvarfs_var *var = node->var;
 	loff_t delta;
 
+	if (!var)
+		return -ENOENT;
+
 	if (size < 0)
 		return -EINVAL;
 
-- 
2.47.3




      parent reply	other threads:[~2026-10-02 12:57 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 11:40 [PATCH 0/6] fs: ubootvarfs: harden parser Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 1/6] fs: skip directory entries whose name does not fit struct dirent Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 2/6] fs: reject negative lengths in ftruncate() Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 3/6] fs: ubootvarfs: range-check the new size in truncate Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 4/6] fs: ubootvarfs: do not form pointers past the end of the environment Ahmad Fatoum
2026-10-02 11:40 ` [PATCH 5/6] fs: ubootvarfs: reject variable names containing '=' Ahmad Fatoum
2026-10-02 11:40 ` Ahmad Fatoum [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002114253.2906535-7-a.fatoum@pengutronix.de \
    --to=a.fatoum@pengutronix.de \
    --cc=a.fatoum@barebox.org \
    --cc=barebox@lists.infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox