aboutsummaryrefslogtreecommitdiffstats
path: root/module/zfs/fm.c
diff options
context:
space:
mode:
authorRichard Yao <[email protected]>2015-04-16 09:20:02 -0400
committerBrian Behlendorf <[email protected]>2015-06-22 17:02:13 -0700
commit72540ea3148a2bc03860d7d59b2b5fdc9a5cdee7 (patch)
tree93052ce65b3fc8acccc367ecdf7f6744d602113f /module/zfs/fm.c
parent99b14de42104021f6b7d88118db010d8246bc0c0 (diff)
zfsdev_getminor() should check for invalid file handles
Unit testing at ClusterHQ found that passing an invalid file handle to zfs_ioc_hold results in a NULL pointer dereference on a system without assertions: IP: [<ffffffffa0218aa0>] zfsdev_getminor+0x10/0x20 [zfs] Call Trace: [<ffffffffa021b4b0>] zfs_onexit_fd_hold+0x20/0x40 [zfs] [<ffffffffa0214043>] zfs_ioc_hold+0x93/0xd0 [zfs] [<ffffffffa0215890>] zfsdev_ioctl+0x200/0x500 [zfs] An assertion would have caught this had they been enabled, but this is something that the kernel module should handle without failing. We resolve this by searching the linked list to ensure that the file handle's private_data points to a valid zfsdev_state_t. Signed-off-by: Richard Yao <[email protected]> Signed-off-by: Andriy Gapon <[email protected]> Signed-off-by: Brian Behlendorf <[email protected]> Closes #3506
Diffstat (limited to 'module/zfs/fm.c')
-rw-r--r--module/zfs/fm.c5
1 files changed, 3 insertions, 2 deletions
diff --git a/module/zfs/fm.c b/module/zfs/fm.c
index b67a7076d..999bd8adc 100644
--- a/module/zfs/fm.c
+++ b/module/zfs/fm.c
@@ -593,8 +593,9 @@ zfs_zevent_fd_hold(int fd, minor_t *minorp, zfs_zevent_t **ze)
if (fp == NULL)
return (EBADF);
- *minorp = zfsdev_getminor(fp->f_file);
- error = zfs_zevent_minor_to_state(*minorp, ze);
+ error = zfsdev_getminor(fp->f_file, minorp);
+ if (error == 0)
+ error = zfs_zevent_minor_to_state(*minorp, ze);
if (error)
zfs_zevent_fd_rele(fd);