mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	Eric Paris <eparis@redhat.com>
Subject: [046/105] inotify: fix double free/corruption of stuct user
Date: Tue, 12 Apr 2011 07:34:35 -0700	[thread overview]
Message-ID: <20110412143552.865034023@clark.kroah.org> (raw)
In-Reply-To: <20110412143613.GA19478@kroah.com>

2.6.38-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Eric Paris <eparis@redhat.com>

commit d0de4dc584ec6aa3b26fffea320a8457827768fc upstream.

On an error path in inotify_init1 a normal user can trigger a double
free of struct user.  This is a regression introduced by a2ae4cc9a16e
("inotify: stop kernel memory leak on file creation failure").

We fix this by making sure that if a group exists the user reference is
dropped when the group is cleaned up.  We should not explictly drop the
reference on error and also drop the reference when the group is cleaned
up.

The new lifetime rules are that an inotify group lives from
inotify_new_group to the last fsnotify_put_group.  Since the struct user
and inotify_devs are directly tied to this lifetime they are only
changed/updated in those two locations.  We get rid of all special
casing of struct user or user->inotify_devs.

Signed-off-by: Eric Paris <eparis@redhat.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 fs/notify/inotify/inotify_fsnotify.c |    1 
 fs/notify/inotify/inotify_user.c     |   39 +++++++++++------------------------
 2 files changed, 14 insertions(+), 26 deletions(-)

--- a/fs/notify/inotify/inotify_fsnotify.c
+++ b/fs/notify/inotify/inotify_fsnotify.c
@@ -198,6 +198,7 @@ static void inotify_free_group_priv(stru
 	idr_for_each(&group->inotify_data.idr, idr_callback, group);
 	idr_remove_all(&group->inotify_data.idr);
 	idr_destroy(&group->inotify_data.idr);
+	atomic_dec(&group->inotify_data.user->inotify_devs);
 	free_uid(group->inotify_data.user);
 }
 
--- a/fs/notify/inotify/inotify_user.c
+++ b/fs/notify/inotify/inotify_user.c
@@ -290,7 +290,6 @@ static int inotify_fasync(int fd, struct
 static int inotify_release(struct inode *ignored, struct file *file)
 {
 	struct fsnotify_group *group = file->private_data;
-	struct user_struct *user = group->inotify_data.user;
 
 	pr_debug("%s: group=%p\n", __func__, group);
 
@@ -299,8 +298,6 @@ static int inotify_release(struct inode
 	/* free this group, matching get was inotify_init->fsnotify_obtain_group */
 	fsnotify_put_group(group);
 
-	atomic_dec(&user->inotify_devs);
-
 	return 0;
 }
 
@@ -697,7 +694,7 @@ retry:
 	return ret;
 }
 
-static struct fsnotify_group *inotify_new_group(struct user_struct *user, unsigned int max_events)
+static struct fsnotify_group *inotify_new_group(unsigned int max_events)
 {
 	struct fsnotify_group *group;
 
@@ -710,8 +707,14 @@ static struct fsnotify_group *inotify_ne
 	spin_lock_init(&group->inotify_data.idr_lock);
 	idr_init(&group->inotify_data.idr);
 	group->inotify_data.last_wd = 0;
-	group->inotify_data.user = user;
 	group->inotify_data.fa = NULL;
+	group->inotify_data.user = get_current_user();
+
+	if (atomic_inc_return(&group->inotify_data.user->inotify_devs) >
+	    inotify_max_user_instances) {
+		fsnotify_put_group(group);
+		return ERR_PTR(-EMFILE);
+	}
 
 	return group;
 }
@@ -721,7 +724,6 @@ static struct fsnotify_group *inotify_ne
 SYSCALL_DEFINE1(inotify_init1, int, flags)
 {
 	struct fsnotify_group *group;
-	struct user_struct *user;
 	int ret;
 
 	/* Check the IN_* constants for consistency.  */
@@ -731,31 +733,16 @@ SYSCALL_DEFINE1(inotify_init1, int, flag
 	if (flags & ~(IN_CLOEXEC | IN_NONBLOCK))
 		return -EINVAL;
 
-	user = get_current_user();
-	if (unlikely(atomic_read(&user->inotify_devs) >=
-			inotify_max_user_instances)) {
-		ret = -EMFILE;
-		goto out_free_uid;
-	}
-
 	/* fsnotify_obtain_group took a reference to group, we put this when we kill the file in the end */
-	group = inotify_new_group(user, inotify_max_queued_events);
-	if (IS_ERR(group)) {
-		ret = PTR_ERR(group);
-		goto out_free_uid;
-	}
-
-	atomic_inc(&user->inotify_devs);
+	group = inotify_new_group(inotify_max_queued_events);
+	if (IS_ERR(group))
+		return PTR_ERR(group);
 
 	ret = anon_inode_getfd("inotify", &inotify_fops, group,
 				  O_RDONLY | flags);
-	if (ret >= 0)
-		return ret;
+	if (ret < 0)
+		fsnotify_put_group(group);
 
-	fsnotify_put_group(group);
-	atomic_dec(&user->inotify_devs);
-out_free_uid:
-	free_uid(user);
 	return ret;
 }
 



  parent reply	other threads:[~2011-04-12 14:52 UTC|newest]

Thread overview: 126+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-04-12 14:36 [000/105] 2.6.38.3-stable review Greg KH
2011-04-12 14:33 ` [001/105] ALSA: HDA: New AD1984A model for Dell Precision R5500 Greg KH
2011-04-12 14:33 ` [002/105] ALSA: hda - Fix SPDIF out regression on ALC889 Greg KH
2011-04-12 14:33 ` [003/105] ALSA: Fix yet another race in disconnection Greg KH
2011-04-12 14:33 ` [004/105] ALSA: vmalloc buffers should use normal mmap Greg KH
2011-04-12 14:33 ` [005/105] perf: Better fit max unprivileged mlock pages for tools needs Greg KH
2011-04-12 14:33 ` [006/105] myri10ge: fix rmmod crash Greg KH
2011-04-12 14:33 ` [007/105] cciss: fix lost command issue Greg KH
2011-04-12 14:33 ` [008/105] ath9k: Fix kernel panic in AR2427 Greg KH
2011-04-12 14:33 ` [009/105] sound/oss/opl3: validate voice and channel indexes Greg KH
2011-04-12 14:33 ` [010/105] mac80211: initialize sta->last_rx in sta_info_alloc Greg KH
2011-04-12 14:34 ` [011/105] [SCSI] ses: show devices for enclosures with no page 7 Greg KH
2011-04-12 14:34 ` [012/105] [SCSI] ses: Avoid kernel panic when lun 0 is not mapped Greg KH
2011-04-12 14:34 ` [013/105] PCI/ACPI: Report ASPM support to BIOS if not disabled from command line Greg KH
2011-04-12 14:34 ` [014/105] x86-64, mm: Put early page table high Greg KH
2011-04-12 15:25   ` Stefano Stabellini
2011-04-12 17:23     ` Greg KH
2011-04-12 14:34 ` [015/105] eCryptfs: Unlock page in write_begin error path Greg KH
2011-04-12 14:34 ` [016/105] eCryptfs: ecryptfs_keyring_auth_tok_for_sig() bug fix Greg KH
2011-04-12 14:34 ` [017/105] crypto: aesni-intel - fixed problem with packets that are not multiple of 64bytes Greg KH
2011-04-12 14:34 ` [018/105] staging: usbip: bugfixes related to kthread conversion Greg KH
2011-04-12 14:34 ` [019/105] staging: usbip: bugfix add number of packets for isochronous frames Greg KH
2011-04-12 14:34 ` [020/105] staging: usbip: bugfix for isochronous packets and optimization Greg KH
2011-04-12 14:34 ` [021/105] staging: hv: use sync_bitops when interacting with the hypervisor Greg KH
2011-04-12 14:34 ` [022/105] staging: hv: Fix GARP not sent after Quick Migration Greg KH
2011-04-12 14:34 ` [023/105] Relax si_code check in rt_sigqueueinfo and rt_tgsigqueueinfo Greg KH
2011-04-12 14:34 ` [024/105] xfs: register the inode cache shrinker before quotachecks Greg KH
2011-04-12 14:34 ` [025/105] amd64_edac: Fix potential memleak Greg KH
2011-04-12 14:34 ` [026/105] watchdog: s3c2410_wdt.c: Convert release_resource to release_region/release_mem_region Greg KH
2011-04-12 14:34 ` [027/105] watchdog: " Greg KH
2011-04-12 14:34 ` [028/105] watchdog: sp5100_tco.c: Check if firmware has set correct value in tcobase Greg KH
2011-04-12 14:34 ` [029/105] irda: validate peer name and attribute lengths Greg KH
2011-04-12 14:34 ` [030/105] irda: prevent heap corruption on invalid nickname Greg KH
2011-04-12 14:34 ` [031/105] powerpc: Fix accounting of softirq time when idle Greg KH
2011-04-12 14:34 ` [032/105] nilfs2: fix data loss in mmap page write for hole blocks Greg KH
2011-04-12 14:34 ` [033/105] ASoC: Explicitly say registerless widgets have no register Greg KH
2011-04-12 14:34 ` [034/105] ASoC: imx: set watermarks for mx2-dma Greg KH
2011-04-12 14:34 ` [035/105] ASoC: imx: fix burstsize for DMA Greg KH
2011-04-12 14:34 ` [036/105] ASoC: Fix CODEC device name for Corgi Greg KH
2011-04-12 14:34 ` [037/105] ALSA: ens1371: fix Creative Ectiva support Greg KH
2011-04-12 14:34 ` [038/105] ALSA: pcm: fix infinite loop in snd_pcm_update_hw_ptr0() Greg KH
2011-04-12 14:34 ` [039/105] ALSA: HDA: Add dock mic quirk for Lenovo Thinkpad X220 Greg KH
2011-04-12 14:34 ` [040/105] ALSA: HDA: Fix dock mic for Lenovo X220-tablet Greg KH
2011-04-12 14:34 ` [041/105] ALSA: hda - HDMI: Fix MCP7x audio infoframe checksums Greg KH
2011-04-12 14:34 ` [042/105] ALSA: HDA: Fix single internal mic on ALC275 (Sony Vaio VPCSB1C5E) Greg KH
2011-04-12 14:34 ` [043/105] net: fix ethtool->set_flags not intended -EINVAL return value Greg KH
2011-04-12 14:34 ` [044/105] drm/radeon/kms: add some new ontario pci ids Greg KH
2011-04-12 14:34 ` [045/105] drm/radeon/kms: add some sanity checks to obj info record parsingi (v2) Greg KH
2011-04-12 14:34 ` Greg KH [this message]
2011-04-12 14:34 ` [047/105] HID: hid-magicmouse: Increase evdev buffer size Greg KH
2011-04-12 14:34 ` [048/105] perf: Fix task_struct reference leak Greg KH
2011-04-12 14:34 ` [049/105] perf: Rebase max unprivileged mlock threshold on top of page size Greg KH
2011-04-12 14:34 ` [050/105] ROSE: prevent heap corruption with bad facilities Greg KH
2011-04-12 14:34 ` [051/105] Btrfs: Fix uninitialized root flags for subvolumes Greg KH
2011-04-12 14:34 ` [052/105] x86, mtrr, pat: Fix one cpu getting out of sync during resume Greg KH
2011-04-12 14:34 ` [053/105] Input: synaptics - fix crash in synaptics_module_init() Greg KH
2011-04-12 14:34 ` [054/105] ath9k: fix a chip wakeup related crash in ath9k_start Greg KH
2011-04-12 14:34 ` [055/105] mac80211: fix a crash in minstrel_ht in HT mode with no supported MCS rates Greg KH
2011-04-12 14:34 ` [056/105] staging: IIO: IMU: ADIS16400: Fix up SPI messages cs_change behavior Greg KH
2011-04-12 14:34 ` [057/105] staging: IIO: IMU: ADIS16400: Add delay after self test Greg KH
2011-04-12 14:34 ` [058/105] staging: IIO: IMU: ADIS16400: Fix addresses of GYRO and ACCEL calibration offset Greg KH
2011-04-12 14:34 ` [059/105] staging: IIO: IMU: ADIS16400: Make sure only enabled scan_elements are pushed into the ring Greg KH
2011-04-12 14:34 ` [060/105] UBIFS: do not read flash unnecessarily Greg KH
2011-04-12 14:34 ` [061/105] UBIFS: fix oops on error path in read_pnode Greg KH
2011-04-12 14:34 ` [062/105] UBIFS: fix debugging failure in dbg_check_space_info Greg KH
2011-04-12 14:34 ` [063/105] quota: Dont write quota info in dquot_commit() Greg KH
2011-04-12 14:34 ` [064/105] mm: avoid wrapping vm_pgoff in mremap() Greg KH
2011-04-12 14:34 ` [065/105] Revert "net/sunrpc: Use static const char arrays" Greg KH
2011-04-12 14:34 ` [066/105] iwlwifi: accept EEPROM version 0x423 for iwl6000 Greg KH
2011-04-12 14:34 ` [067/105] p54usb: IDs for two new devices Greg KH
2011-04-12 14:34 ` [068/105] rt2x00: Fix radio off hang issue for PCIE interface Greg KH
2011-04-12 14:34 ` [069/105] rt2x00: fix cancelling uninitialized work Greg KH
2011-04-12 14:34 ` [070/105] wl12xx: fix potential buffer overflow in testmode nvs push Greg KH
2011-04-12 14:35 ` [071/105] [media] media/radio/wl1273: fix build errors Greg KH
2011-04-12 14:35 ` [072/105] b43: allocate receive buffers big enough for max frame len + offset Greg KH
2011-04-12 14:35 ` [073/105] Bluetooth: sco: fix information leak to userspace Greg KH
2011-04-12 14:35 ` [074/105] bridge: netfilter: fix information leak Greg KH
2011-04-12 14:35 ` [075/105] Bluetooth: bnep: fix buffer overflow Greg KH
2011-04-12 14:35 ` [076/105] Bluetooth: add support for Apple MacBook Pro 8,2 Greg KH
2011-04-13 15:57   ` Grant Likely
2011-04-13 16:18     ` [stable] [076/105] Bluetooth: add support for Apple MacBook Pro 8, 2 Greg KH
2011-04-12 14:35 ` [077/105] Treat writes as new when holes span across page boundaries Greg KH
2011-04-12 14:35 ` [078/105] char/tpm: Fix unitialized usage of data buffer Greg KH
2011-04-12 14:35 ` [079/105] netfilter: ip_tables: fix infoleak to userspace Greg KH
2011-04-12 14:35 ` [080/105] netfilter: xtables: fix reentrancy Greg KH
2011-04-12 14:35 ` [081/105] netfilter: arp_tables: fix infoleak to userspace Greg KH
2011-04-12 14:35 ` [082/105] netfilter: ipt_CLUSTERIP: fix buffer overflow Greg KH
2011-04-12 14:35 ` [083/105] ipv6: netfilter: ip6_tables: fix infoleak to userspace Greg KH
2011-04-12 14:35 ` [084/105] [SCSI] scsi_transport_iscsi: make priv_sess file writeable only by root Greg KH
2011-04-12 14:35 ` [085/105] mfd: ab8500: world-writable debugfs register-* files Greg KH
2011-04-12 14:35 ` [086/105] mfd: ab3500: " Greg KH
2011-04-12 14:35 ` [087/105] mfd: ab3100: world-writable debugfs *_priv files Greg KH
2011-04-12 14:35 ` [088/105] drivers/rtc/rtc-ds1511.c: world-writable sysfs nvram file Greg KH
2011-04-12 14:35 ` [089/105] drivers/misc/ep93xx_pwm.c: world-writable sysfs files Greg KH
2011-04-12 14:35 ` [090/105] drivers/leds/leds-lp5523.c: world-writable engine* " Greg KH
2011-04-12 14:35 ` [091/105] drivers/leds/leds-lp5521.c: world-writable sysfs engine* files Greg KH
2011-04-12 14:35 ` [092/105] econet: 4 byte infoleak to the network Greg KH
2011-04-12 14:35 ` [093/105] netfilter: h323: bug in parsing of ASN1 SEQOF field Greg KH
2011-04-12 14:35 ` [094/105] sound/oss: remove offset from load_patch callbacks Greg KH
2011-04-12 14:35 ` [095/105] [media] drivers/media/video/tlg2300/pd-video.c: Remove second mutex_unlock in pd_vidioc_s_fmt Greg KH
2011-04-12 14:35 ` [096/105] acer-wmi: does not set persistence state by rfkill_init_sw_state Greg KH
2011-04-12 14:35 ` [097/105] [PATCH] Revert "x86: Cleanup highmap after brk is concluded" Greg KH
2011-04-12 14:35 ` [098/105] Squashfs: Use vmalloc rather than kmalloc for zlib workspace Greg KH
2011-04-12 14:35 ` [099/105] Squashfs: handle corruption of directory structure Greg KH
2011-04-12 14:35 ` [100/105] atm/solos-pci: Dont include frame pseudo-header on transmit hex-dump Greg KH
2011-04-12 14:35 ` [101/105] atm/solos-pci: Dont flap VCs when carrier state changes Greg KH
2011-04-12 14:35 ` [102/105] ext4: fix a double free in ext4_register_li_request Greg KH
2011-04-12 14:35 ` [103/105] ext4: fix credits computing for indirect mapped files Greg KH
2011-04-12 14:35 ` [104/105] nfsd: fix auth_domain reference leak on nlm operations Greg KH
2011-04-12 14:35 ` [105/105] nfsd4: fix oops on lock failure Greg KH
2011-04-17 15:03   ` OGAWA Hirofumi
2011-04-17 16:10     ` Linus Torvalds
2011-04-18 15:32       ` J. Bruce Fields
2011-04-18 15:42         ` J. Bruce Fields
2011-04-18 16:08         ` OGAWA Hirofumi
2011-04-18 16:10           ` OGAWA Hirofumi
2011-04-18 16:39             ` OGAWA Hirofumi
2011-04-18 16:59               ` Linus Torvalds
2011-04-18 17:16                 ` J. Bruce Fields
2011-04-18 18:21                   ` [stable] " Greg KH
2011-04-18 21:12               ` OGAWA Hirofumi
2011-04-19  8:21                 ` OGAWA Hirofumi
2011-04-19 20:43                   ` J. Bruce Fields
2011-04-19 21:17                     ` OGAWA Hirofumi
2011-04-19 21:33                       ` J. Bruce Fields
2011-04-20 23:23                         ` nfsd bugfixes for 2.6.39 J. Bruce Fields

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110412143552.865034023@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=eparis@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®