cifs: check kzalloc return
authorJoe Perches <joe@perches.com>
Fri, 21 Dec 2018 05:50:48 +0000 (23:50 -0600)
committerSteve French <stfrench@microsoft.com>
Fri, 28 Dec 2018 16:09:46 +0000 (10:09 -0600)
kzalloc can return NULL so an additional check is needed. While there
is a check for ret_buf there is no check for the allocation of
ret_buf->crfid.fid - this check is thus added. Both call-sites
of tconInfoAlloc() check for NULL return of tconInfoAlloc()
so returning NULL on failure of kzalloc() here seems appropriate.
As the kzalloc() is the only thing here that can fail it is
moved to the beginning so as not to initialize other resources
on failure of kzalloc.

Fixes: 3d4ef9a15343 ("smb3: fix redundant opens on root")
Signed-off-by: Joe Perches <joe@perches.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
fs/cifs/misc.c

index 5e315e4009e2c128ead1e24133f80645779a6448..10ae1a35b6f7f04a83269c1c61b9ebfb8f7d3b01 100644 (file)
@@ -111,21 +111,27 @@ struct cifs_tcon *
 tconInfoAlloc(void)
 {
        struct cifs_tcon *ret_buf;
-       ret_buf = kzalloc(sizeof(struct cifs_tcon), GFP_KERNEL);
-       if (ret_buf) {
-               atomic_inc(&tconInfoAllocCount);
-               ret_buf->tidStatus = CifsNew;
-               ++ret_buf->tc_count;
-               INIT_LIST_HEAD(&ret_buf->openFileList);
-               INIT_LIST_HEAD(&ret_buf->tcon_list);
-               spin_lock_init(&ret_buf->open_file_lock);
-               mutex_init(&ret_buf->crfid.fid_mutex);
-               ret_buf->crfid.fid = kzalloc(sizeof(struct cifs_fid),
-                                            GFP_KERNEL);
-               spin_lock_init(&ret_buf->stat_lock);
-               atomic_set(&ret_buf->num_local_opens, 0);
-               atomic_set(&ret_buf->num_remote_opens, 0);
+
+       ret_buf = kzalloc(sizeof(*ret_buf), GFP_KERNEL);
+       if (!ret_buf)
+               return NULL;
+       ret_buf->crfid.fid = kzalloc(sizeof(*ret_buf->crfid.fid), GFP_KERNEL);
+       if (!ret_buf->crfid.fid) {
+               kfree(ret_buf);
+               return NULL;
        }
+
+       atomic_inc(&tconInfoAllocCount);
+       ret_buf->tidStatus = CifsNew;
+       ++ret_buf->tc_count;
+       INIT_LIST_HEAD(&ret_buf->openFileList);
+       INIT_LIST_HEAD(&ret_buf->tcon_list);
+       spin_lock_init(&ret_buf->open_file_lock);
+       mutex_init(&ret_buf->crfid.fid_mutex);
+       spin_lock_init(&ret_buf->stat_lock);
+       atomic_set(&ret_buf->num_local_opens, 0);
+       atomic_set(&ret_buf->num_remote_opens, 0);
+
        return ret_buf;
 }