From: viro@parcelfarce.linux.theplanet.co.uk
To: Maneesh Soni <maneesh@in.ibm.com>,
LKML <linux-kernel@vger.kernel.org>, Greg KH <greg@kroah.com>
Subject: Re: [RFC] fix sysfs symlinks
Date: Thu, 15 Apr 2004 11:38:49 +0100 [thread overview]
Message-ID: <20040415103849.GA24997@parcelfarce.linux.theplanet.co.uk> (raw)
In-Reply-To: <20040415091752.A24815@flint.arm.linux.org.uk>
On Thu, Apr 15, 2004 at 09:17:52AM +0100, Russell King wrote:
> > Erm... If rmmod _ever_ waits for refcount on kobject to reach zero, it's
> > already broken. Do you have any examples of such behaviour?
>
> Every single module which unregisters a struct device_driver.
Ehh... So we have a pile of deadlocks (root-only, but still...) and
a lovely user-exploitable DoS. Consider the following:
open an AF_UNIX socket pair.
go through sysfs directories of all drivers, opening all of them
put obtained descriptors into SCM_RIGHTS packet and send it
close all these descriptors
sleep
Voila - later rmmod attempts will hang (not just say "busy") and no, fuser
won't catch your process. And IIRC, serialization in module.c will lead
to nasty consequences for any subsequent attempts of module insertion.
Do we really need to embed those structures? E.g. pci_driver (the main source
of those guys, AFAICS) could very well make ->driver dynamically allocated
at pci_register_driver() and have it freed by its ->release(). With no
waiting of any kind. The only places that would require changes would be
drivers/pci/pci-driver.c and definition of to_pci_driver() - nobody else
ever touches ->driver.
OTOH, eisa looks worse and the rest of them could be even uglier ;-/
Sigh...
next prev parent reply other threads:[~2004-04-15 10:38 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-13 12:40 Maneesh Soni
2004-04-13 13:36 ` viro
2004-04-14 6:40 ` Maneesh Soni
2004-04-14 7:02 ` viro
2004-04-14 7:17 ` Maneesh Soni
2004-04-14 7:27 ` viro
2004-04-15 8:17 ` Russell King
2004-04-15 10:38 ` viro [this message]
2004-04-15 15:19 ` Russell King
2004-04-15 16:10 ` Greg KH
2004-04-15 16:13 ` viro
2004-04-15 19:14 ` viro
2004-04-15 21:27 ` Greg KH
2004-04-17 6:15 ` Rusty Russell
2004-04-17 19:39 ` viro
2004-04-17 23:45 ` Rusty Russell
2004-04-15 22:02 ` Greg KH
2004-04-16 15:24 ` viro
2004-04-16 18:03 ` Horst von Brand
2004-04-16 18:07 ` viro
2004-04-16 22:37 ` Greg KH
2004-04-16 23:46 ` viro
2004-04-17 0:03 ` Jeff Garzik
2004-04-17 8:07 ` Russell King
2004-04-17 8:22 ` viro
2004-04-20 16:16 ` Greg KH
2004-04-21 10:11 ` Maneesh Soni
2004-04-22 21:37 ` viro
2004-04-23 8:52 ` Maneesh Soni
2004-04-23 9:26 ` viro
2004-04-29 13:03 ` Maneesh Soni
2004-04-29 15:41 ` viro
2004-04-30 10:05 ` Maneesh Soni
2004-04-30 10:13 ` [RFC 0/2] kobject_set_name - error handling Maneesh Soni
2004-04-30 10:14 ` [RFC 1/2] " Maneesh Soni
2004-04-30 10:17 ` [RFC 2/2] " Maneesh Soni
2004-05-04 13:08 ` Maneesh Soni
2004-04-30 12:48 ` [RFC 1/2] " Dmitry Torokhov
2004-05-04 5:39 ` Maneesh Soni
2004-05-04 9:19 ` Maneesh Soni
2004-05-07 22:25 ` Greg KH
2003-05-09 10:05 ` Maneesh Soni
2003-05-09 10:09 ` [RFC 2/2] sysfs_rename_dir-cleanup Maneesh Soni
2004-05-11 23:33 ` Greg KH
2004-10-07 5:16 ` Maneesh Soni
2004-10-07 5:38 ` Maneesh Soni
2004-05-14 19:10 ` Greg KH
2004-05-11 23:32 ` [RFC 1/2] kobject_set_name - error handling Greg KH
2004-04-17 0:15 ` [RFC] fix sysfs symlinks Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040415103849.GA24997@parcelfarce.linux.theplanet.co.uk \
--to=viro@parcelfarce.linux.theplanet.co.uk \
--cc=greg@kroah.com \
--cc=linux-kernel@vger.kernel.org \
--cc=maneesh@in.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome