fscrypt: require that fscrypt_encrypt_symlink() already has key
authorEric Biggers <ebiggers@google.com>
Thu, 17 Sep 2020 04:11:31 +0000 (21:11 -0700)
committerEric Biggers <ebiggers@google.com>
Tue, 22 Sep 2020 13:48:41 +0000 (06:48 -0700)
Now that all filesystems have been converted to use
fscrypt_prepare_new_inode(), the encryption key for new symlink inodes
is now already set up whenever we try to encrypt the symlink target.
Enforce this rather than try to set up the key again when it may be too
late to do so safely.

Acked-by: Jeff Layton <jlayton@kernel.org>
Link: https://lore.kernel.org/r/20200917041136.178600-9-ebiggers@kernel.org
Signed-off-by: Eric Biggers <ebiggers@google.com>
fs/crypto/hooks.c

index 491b252843eb97f26cf2273899427c43676a34ea..7748db509240906dfc307a7eedb534afcdf9cfef 100644 (file)
@@ -217,9 +217,13 @@ int __fscrypt_encrypt_symlink(struct inode *inode, const char *target,
        struct fscrypt_symlink_data *sd;
        unsigned int ciphertext_len;
 
-       err = fscrypt_require_key(inode);
-       if (err)
-               return err;
+       /*
+        * fscrypt_prepare_new_inode() should have already set up the new
+        * symlink inode's encryption key.  We don't wait until now to do it,
+        * since we may be in a filesystem transaction now.
+        */
+       if (WARN_ON_ONCE(!fscrypt_has_encryption_key(inode)))
+               return -ENOKEY;
 
        if (disk_link->name) {
                /* filesystem-provided buffer */