[git commit] loop: fix a race when a free loop device is snatched
Denys Vlasenko
vda.linux at googlemail.com
Tue Nov 15 13:54:05 UTC 2022
commit: https://git.busybox.net/busybox/commit/?id=cb8d2ea8c91b5671b05e06ab2282496104453378
branch: https://git.busybox.net/busybox/commit/?id=refs/heads/master
When /dev/loop-control exists and *device is empty,
the mount may fail if a concurrent mount is running.
function old new delta
set_loop 809 807 -2
Signed-off-by: Xiaoming Ni <nixiaoming at huawei.com>
Signed-off-by: Denys Vlasenko <vda.linux at googlemail.com>
---
libbb/loop.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/libbb/loop.c b/libbb/loop.c
index cb8fa2442..750642ade 100644
--- a/libbb/loop.c
+++ b/libbb/loop.c
@@ -218,8 +218,17 @@ int FAST_FUNC set_loop(char **device, const char *file, unsigned long long offse
}
/* failure, undo LOOP_SET_FD */
ioctl(lfd, LOOP_CLR_FD, 0); // actually, 0 param is unnecessary
+ } else {
+ /* device is not free (rc == 0), or error other than ENXIO */
+ if (rc == 0 /* device is not free? */
+ && !*device /* racing with other mount? */
+ && try != dev /* tried a _kernel-offered_ loopN? */
+ ) {
+ free(try);
+ close(lfd);
+ goto get_free_loopN;
+ }
}
- /* else: device is not free (rc == 0) or error other than ENXIO */
close_and_try_next_loopN:
close(lfd);
try_next_loopN:
More information about the busybox-cvs
mailing list