Re: [PATCH] btrfs: return -ENOTTY for unknown ioctls on the control device
From: Qu Wenruo
Date: Fri Oct 09 2026 - 17:05:24 EST
在 2026/10/10 04:03, Hengyu Liang 写道:
Commit 5ab2b180884c ("btrfs: factor out validation of
btrfs_ioctl_vol_args::name") made btrfs_control_ioctl() store the result
of btrfs_check_ioctl_vol_args_path() in ret before it looks at the
command.
However, ret is initialized to -ENOTTY and the switch has no default
case, so this initial value was what an unknown command returned. As of
now, every unknown ioctl on /dev/btrfs-control returns 0. A tool that
tries a control ioctl which the running kernel does not have is told
that the ioctl succeeded.
The issue can be reproduced with a simple C program, run as root:
#include <fcntl.h>
#include <stdio.h>
#include <sys/ioctl.h>
int main(void)
{
static char buf[4096];
int fd = open("/dev/btrfs-control", O_RDWR);
if (ioctl(fd, TCGETS, buf) < 0)
perror("ioctl");
else
printf("ioctl succeeded\n");
return 0;
}
Before commit 5ab2b180884c ("btrfs: factor out validation of
btrfs_ioctl_vol_args::name"), the result is:
ioctl: Inappropriate ioctl for device
After that commit, the result is:
ioctl succeeded
This patch will add a default case that returns -ENOTTY.
Fixes: 5ab2b180884c ("btrfs: factor out validation of btrfs_ioctl_vol_args::name")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Hengyu Liang <hengyul@xxxxxxxxxx>
Reviewed-by: Qu Wenruo <wqu@xxxxxxxx>
Thanks,
Qu
---
fs/btrfs/super.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/btrfs/super.c b/fs/btrfs/super.c
index 823a58bd2685..acb704b20c2b 100644
--- a/fs/btrfs/super.c
+++ b/fs/btrfs/super.c
@@ -2291,6 +2291,9 @@ static long btrfs_control_ioctl(struct file *file, unsigned int cmd,
case BTRFS_IOC_GET_SUPPORTED_FEATURES:
ret = btrfs_ioctl_get_supported_features((void __user*)arg);
break;
+ default:
+ ret = -ENOTTY;
+ break;
}
out: