Trond Myklebust <[email protected]> wrote:
> > I'd be guessing that filldir64() was passed a negative namlen.
>  Why would that trigger a bug in __copy_from_user_ll()? I could see it
>  triggering errors in copy_to_user(), but not copy_from_*...

Ah.  No, I cannot see why getdents wold run copy_from_user().

I wonder why that stack trace didn't come out.  Perhaps running `dmesg -n
7' prior to triggerng the crash will help.  (It shouldn't, but we might
have broken it).

