Commit 2a2b5d62 authored by Josef Bacik's avatar Josef Bacik Committed by David Sterba

btrfs: hold ref on root in btrfs_ioctl_default_subvol

We look up an arbitrary fs root here, we need to hold a ref on the root
for the duration.
Signed-off-by: default avatarJosef Bacik <josef@toxicpanda.com>
Reviewed-by: default avatarDavid Sterba <dsterba@suse.com>
Signed-off-by: default avatarDavid Sterba <dsterba@suse.com>
parent 04734e84
...@@ -3986,7 +3986,7 @@ static long btrfs_ioctl_default_subvol(struct file *file, void __user *argp) ...@@ -3986,7 +3986,7 @@ static long btrfs_ioctl_default_subvol(struct file *file, void __user *argp)
struct btrfs_root *new_root; struct btrfs_root *new_root;
struct btrfs_dir_item *di; struct btrfs_dir_item *di;
struct btrfs_trans_handle *trans; struct btrfs_trans_handle *trans;
struct btrfs_path *path; struct btrfs_path *path = NULL;
struct btrfs_key location; struct btrfs_key location;
struct btrfs_disk_key disk_key; struct btrfs_disk_key disk_key;
u64 objectid = 0; u64 objectid = 0;
...@@ -4017,44 +4017,50 @@ static long btrfs_ioctl_default_subvol(struct file *file, void __user *argp) ...@@ -4017,44 +4017,50 @@ static long btrfs_ioctl_default_subvol(struct file *file, void __user *argp)
ret = PTR_ERR(new_root); ret = PTR_ERR(new_root);
goto out; goto out;
} }
if (!is_fstree(new_root->root_key.objectid)) { if (!btrfs_grab_fs_root(new_root)) {
ret = -ENOENT; ret = -ENOENT;
goto out; goto out;
} }
if (!is_fstree(new_root->root_key.objectid)) {
ret = -ENOENT;
goto out_free;
}
path = btrfs_alloc_path(); path = btrfs_alloc_path();
if (!path) { if (!path) {
ret = -ENOMEM; ret = -ENOMEM;
goto out; goto out_free;
} }
path->leave_spinning = 1; path->leave_spinning = 1;
trans = btrfs_start_transaction(root, 1); trans = btrfs_start_transaction(root, 1);
if (IS_ERR(trans)) { if (IS_ERR(trans)) {
btrfs_free_path(path);
ret = PTR_ERR(trans); ret = PTR_ERR(trans);
goto out; goto out_free;
} }
dir_id = btrfs_super_root_dir(fs_info->super_copy); dir_id = btrfs_super_root_dir(fs_info->super_copy);
di = btrfs_lookup_dir_item(trans, fs_info->tree_root, path, di = btrfs_lookup_dir_item(trans, fs_info->tree_root, path,
dir_id, "default", 7, 1); dir_id, "default", 7, 1);
if (IS_ERR_OR_NULL(di)) { if (IS_ERR_OR_NULL(di)) {
btrfs_free_path(path); btrfs_release_path(path);
btrfs_end_transaction(trans); btrfs_end_transaction(trans);
btrfs_err(fs_info, btrfs_err(fs_info,
"Umm, you don't have the default diritem, this isn't going to work"); "Umm, you don't have the default diritem, this isn't going to work");
ret = -ENOENT; ret = -ENOENT;
goto out; goto out_free;
} }
btrfs_cpu_key_to_disk(&disk_key, &new_root->root_key); btrfs_cpu_key_to_disk(&disk_key, &new_root->root_key);
btrfs_set_dir_item_key(path->nodes[0], di, &disk_key); btrfs_set_dir_item_key(path->nodes[0], di, &disk_key);
btrfs_mark_buffer_dirty(path->nodes[0]); btrfs_mark_buffer_dirty(path->nodes[0]);
btrfs_free_path(path); btrfs_release_path(path);
btrfs_set_fs_incompat(fs_info, DEFAULT_SUBVOL); btrfs_set_fs_incompat(fs_info, DEFAULT_SUBVOL);
btrfs_end_transaction(trans); btrfs_end_transaction(trans);
out_free:
btrfs_put_fs_root(new_root);
btrfs_free_path(path);
out: out:
mnt_drop_write_file(file); mnt_drop_write_file(file);
return ret; return ret;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment