The branch main has been updated by rmacklem:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=ab639f2398bf7efd4dfd38cd6527e22f6e781ae9

commit ab639f2398bf7efd4dfd38cd6527e22f6e781ae9
Author:     Rick Macklem <[email protected]>
AuthorDate: 2021-12-09 22:32:22 +0000
Commit:     Rick Macklem <[email protected]>
CommitDate: 2021-12-09 22:32:22 +0000

    nfscl: Check for an error return from nfsrv_getattrbits()
    
    There were two places where the client code did not check
    for a parse error return from nfsrv_getattrbits().
    
    This patch fixes both of these cases.
    
    Reported by:    [email protected]
    Tested by:      [email protected]
    PR:     260272
    MFC after:      2 weeks
---
 sys/fs/nfsclient/nfs_clrpcops.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/sys/fs/nfsclient/nfs_clrpcops.c b/sys/fs/nfsclient/nfs_clrpcops.c
index 7646c1b404da..08bfac3575f7 100644
--- a/sys/fs/nfsclient/nfs_clrpcops.c
+++ b/sys/fs/nfsclient/nfs_clrpcops.c
@@ -2513,7 +2513,9 @@ nfsrpc_createv4(vnode_t dvp, char *name, int namelen, 
struct vattr *vap,
                stateid.other[1] = *tl++;
                stateid.other[2] = *tl;
                rflags = fxdr_unsigned(u_int32_t, *(tl + 6));
-               (void) nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
+               error = nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
+               if (error)
+                       goto nfsmout;
                NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
                deleg = fxdr_unsigned(int, *tl);
                if (deleg == NFSV4OPEN_DELEGATEREAD ||
@@ -8154,7 +8156,9 @@ nfsrpc_createlayout(vnode_t dvp, char *name, int namelen, 
struct vattr *vap,
                stateid.other[0] = *tl++;
                stateid.other[1] = *tl++;
                stateid.other[2] = *tl;
-               nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
+               error = nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
+               if (error != 0)
+                       goto nfsmout;
                NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
                deleg = fxdr_unsigned(int, *tl);
                if (deleg == NFSV4OPEN_DELEGATEREAD ||

Reply via email to