@@ -456,6 +456,7 @@
#define OBD_FAIL_LLITE_CREATE_NODE_PAUSE 0x140c
#define OBD_FAIL_LLITE_IMUTEX_SEC 0x140e
#define OBD_FAIL_LLITE_IMUTEX_NOSEC 0x140f
+#define OBD_FAIL_LLITE_OPEN_BY_NAME 0x1410
#define OBD_FAIL_FID_INDIR 0x1501
#define OBD_FAIL_FID_INLMA 0x1502
@@ -513,12 +513,14 @@ static int ll_intent_file_open(struct dentry *de, void *lmm, int lmmsize,
* if server supports open-by-fid, or file name is invalid, don't pack
* name in open request
*/
- if (!(exp_connect_flags(sbi->ll_md_exp) & OBD_CONNECT_OPEN_BY_FID)) {
+ if (OBD_FAIL_CHECK(OBD_FAIL_LLITE_OPEN_BY_NAME) ||
+ !(exp_connect_flags(sbi->ll_md_exp) & OBD_CONNECT_OPEN_BY_FID)) {
retry:
len = de->d_name.len;
- name = kmalloc(len, GFP_NOFS);
+ name = kmalloc(len + 1, GFP_NOFS);
if (!name)
return -ENOMEM;
+
/* race here */
spin_lock(&de->d_lock);
if (len != de->d_name.len) {
@@ -527,12 +529,12 @@ static int ll_intent_file_open(struct dentry *de, void *lmm, int lmmsize,
goto retry;
}
memcpy(name, de->d_name.name, len);
+ name[len] = '\0';
spin_unlock(&de->d_lock);
if (!lu_name_is_valid_2(name, len)) {
kfree(name);
- name = NULL;
- len = 0;
+ return -ESTALE;
}
}