ovl: fix wrong use of impure dir cache in ovl_iterate()
authorAmir Goldstein <amir73il@gmail.com>
Tue, 17 Jul 2018 13:05:38 +0000 (16:05 +0300)
committerMiklos Szeredi <mszeredi@redhat.com>
Tue, 17 Jul 2018 14:04:34 +0000 (16:04 +0200)
commit67810693077afc1ebf9e1646af300436cb8103c2
tree4680beac9b17af390ad8fcd176851a6eacab4877
parentce397d215ccd07b8ae3f71db689aedb85d56ab40
ovl: fix wrong use of impure dir cache in ovl_iterate()

Only upper dir can be impure, but if we are in the middle of
iterating a lower real dir, dir could be copied up and marked
impure. We only want the impure cache if we started iterating
a real upper dir to begin with.

Aditya Kali reported that the following reproducer hits the
WARN_ON(!cache->refcount) in ovl_get_cache():

 docker run --rm drupal:8.5.4-fpm-alpine \
    sh -c 'cd /var/www/html/vendor/symfony && \
           chown -R www-data:www-data . && ls -l .'

Reported-by: Aditya Kali <adityakali@google.com>
Tested-by: Aditya Kali <adityakali@google.com>
Fixes: 4edb83bb1041 ('ovl: constant d_ino for non-merge dirs')
Cc: <stable@vger.kernel.org> # v4.14
Signed-off-by: Amir Goldstein <amir73il@gmail.com>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
fs/overlayfs/readdir.c