From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 689331FF125 for ; Mon, 03 Aug 2026 11:08:22 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 7F1F421535; Mon, 03 Aug 2026 11:08:09 +0200 (CEST) From: Christian Ebner To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox-backup v4 09/14] datastore: add additional check for device number on lock helper Date: Mon, 3 Aug 2026 11:07:42 +0200 Message-ID: <20260803090747.265683-10-c.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260803090747.265683-1-c.ebner@proxmox.com> References: <20260803090747.265683-1-c.ebner@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785748074539 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.136 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: EMLRCEEYXG54MHBWPG5ZZBK535WNB3KO X-Message-ID-Hash: EMLRCEEYXG54MHBWPG5ZZBK535WNB3KO X-MailFrom: c.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Comparing the inodes previous and after locking the file is not guaranteed to protect against overmounting by another filesystem. Further restrict by also comparing the device number to assure uniqueness. Signed-off-by: Christian Ebner --- pbs-datastore/src/lib.rs | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pbs-datastore/src/lib.rs b/pbs-datastore/src/lib.rs index e936c7edf..5e6dca4ab 100644 --- a/pbs-datastore/src/lib.rs +++ b/pbs-datastore/src/lib.rs @@ -267,8 +267,9 @@ where let lock = lock_fn(path)?; let inode = nix::sys::stat::fstat(lock.as_raw_fd())?.st_ino; + let dev = nix::sys::stat::fstat(lock.as_raw_fd())?.st_dev; - if nix::sys::stat::stat(path).map_or(true, |st| inode != st.st_ino) { + if nix::sys::stat::stat(path).map_or(true, |st| inode != st.st_ino || dev != st.st_dev) { bail!("could not acquire lock, another thread modified the lock file"); } -- 2.47.3