mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH -next 0/5] md: fix uaf for sync_thread
@ 2023-03-11  9:31 Yu Kuai
  2023-03-11  9:31 ` [PATCH -next 1/5] md: pass a md_thread pointer to md_register_thread() Yu Kuai
                   ` (5 more replies)
  0 siblings, 6 replies; 10+ messages in thread
From: Yu Kuai @ 2023-03-11  9:31 UTC (permalink / raw)
  To: agk, snitzer, song
  Cc: linux-kernel, linux-raid, yukuai3, yukuai1, yi.zhang, yangerkun

From: Yu Kuai <yukuai3@huawei.com>

Our test reports a uaf for 'mddev->sync_thread':

T1                      T2
md_start_sync
 md_register_thread
			raid1d
			 md_check_recovery
			  md_reap_sync_thread
			   md_unregister_thread
			    kfree

 md_wakeup_thread
  wake_up
  ->sync_thread was freed

Currently, a global spinlock 'pers_lock' is borrowed to protect
'mddev->thread', this problem can be fixed likewise, however, there might
be similar problem for other md_thread, and I really don't like the idea to
borrow a global lock.

This patchset do some refactor, and then use a disk level spinlock to
protect md_thread in relevant apis.

Yu Kuai (5):
  md: pass a md_thread pointer to md_register_thread()
  md: refactor md_wakeup_thread()
  md: use md_thread api to wake up sync_thread
  md: pass a mddev to md_unregister_thread()
  md: protect md_thread with a new disk level spin lock

 drivers/md/dm-raid.c      |   6 +-
 drivers/md/md-bitmap.c    |   6 +-
 drivers/md/md-cluster.c   |  39 +++++-----
 drivers/md/md-multipath.c |   8 +-
 drivers/md/md.c           | 157 ++++++++++++++++++++------------------
 drivers/md/md.h           |  15 ++--
 drivers/md/raid1.c        |  19 +++--
 drivers/md/raid10.c       |  31 ++++----
 drivers/md/raid5-cache.c  |  19 +++--
 drivers/md/raid5-ppl.c    |   2 +-
 drivers/md/raid5.c        |  48 ++++++------
 11 files changed, 175 insertions(+), 175 deletions(-)

-- 
2.31.1


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2023-03-14 20:08 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-03-11  9:31 [PATCH -next 0/5] md: fix uaf for sync_thread Yu Kuai
2023-03-11  9:31 ` [PATCH -next 1/5] md: pass a md_thread pointer to md_register_thread() Yu Kuai
2023-03-11  9:31 ` [PATCH -next 2/5] md: refactor md_wakeup_thread() Yu Kuai
2023-03-11  9:31 ` [PATCH -next 3/5] md: use md_thread api to wake up sync_thread Yu Kuai
2023-03-11  9:31 ` [PATCH -next 4/5] md: pass a mddev to md_unregister_thread() Yu Kuai
2023-03-11  9:31 ` [PATCH -next 5/5] md: protect md_thread with a new disk level spin lock Yu Kuai
2023-03-14 10:54   ` Yu Kuai
2023-03-14 16:58     ` Song Liu
2023-03-14 20:08       ` Song Liu
2023-03-14  0:42 ` [PATCH -next 0/5] md: fix uaf for sync_thread Song Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®