nfsd: make a copy of struct iattr before calling notify_change
authorJeff Layton <jlayton@kernel.org>
Wed, 17 May 2023 16:26:44 +0000 (12:26 -0400)
committerChuck Lever <chuck.lever@oracle.com>
Tue, 23 May 2023 13:46:26 +0000 (09:46 -0400)
commitd53d70084d27f56bcdf5074328f2c9ec861be596
treefb02ea1cb60c5bb716fcdd0fea3bac06b9c3cceb
parent21a3f3328972bdb774c62b301a715b5cebf03fa2
nfsd: make a copy of struct iattr before calling notify_change

notify_change can modify the iattr structure. In particular it can
end up setting ATTR_MODE when ATTR_KILL_SUID is already set, causing
a BUG() if the same iattr is passed to notify_change more than once.

Make a copy of the struct iattr before calling notify_change.

Reported-by: Zhi Li <yieli@redhat.com>
Link: https://bugzilla.redhat.com/show_bug.cgi?id=2207969
Tested-by: Zhi Li <yieli@redhat.com>
Fixes: 34b91dda7124 ("NFSD: Make nfsd4_setattr() wait before returning NFS4ERR_DELAY")
Signed-off-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
fs/nfsd/vfs.c