mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 -next 0/2] security: Fix call security_backing_file_free second time
@ 2026-07-07  8:06 Cai Xinchen
  2026-07-07  8:06 ` [PATCH v2 -next 1/2] security: Delete dumplicate assignment Cai Xinchen
  2026-07-07  8:06 ` [PATCH v2 -next 2/2] security: Fix call security_backing_file_free second time Cai Xinchen
  0 siblings, 2 replies; 7+ messages in thread
From: Cai Xinchen @ 2026-07-07  8:06 UTC (permalink / raw)
  To: paul, jmorris, serge, amir73il, brauner, caixinchen1
  Cc: linux-security-module, linux-kernel, lujialin4

v2: Move the call_void_hook(backing_file_free, ...) call in
security_backing_file_free() into the if-statment true block before we
set the backing file's LSM blob pointer to NULL and free the LSM blob.

I found the following path:

alloc_empty_backing-file
    init_file(&ff->file, xxx)
        -> file_ref_init(&f->f_ref, 1); // only 1
    error = init_backing_file
        -> security_backing_file_alloc
        -> rc = call_int_hook(backing_file_alloc, ...)
           if (unlikely(rc))
                security_backing_file_free(backing_file); // first call
    if (unlikely(error)) {
        fput(&ff->file);
         -> if (unlikely(file_ref_put(&file->f_ref))) // zero
                __fput_deferred(file);
                 -> ____fput -> __fput -> file_free(file);
                 -> backing_file_free(backing_file(f));
                 -> security_backing_file_free(&ff->file); // second call

Currently, only SELinux has the lsm backing_file_alloc hook, and it always
return 0. When security_backing_file_free is called for the first time,
the blobs pointer is set to NULL. Therefore, double free will not occur in
the code.

Cai Xinchen (2):
  security: Delete dumplicate assignment
  security: Fix call security_backing_file_free second time

 security/lsm_init.c | 1 -
 security/security.c | 3 +--
 2 files changed, 1 insertion(+), 3 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-08-31 21:29 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-07  8:06 [PATCH v2 -next 0/2] security: Fix call security_backing_file_free second time Cai Xinchen
2026-07-07  8:06 ` [PATCH v2 -next 1/2] security: Delete dumplicate assignment Cai Xinchen
2026-08-27 16:30   ` [PATCH v2 " Paul Moore
2026-08-31 21:28     ` Paul Moore
2026-07-07  8:06 ` [PATCH v2 -next 2/2] security: Fix call security_backing_file_free second time Cai Xinchen
2026-08-27 16:30   ` [PATCH v2 " Paul Moore
2026-08-31 21:29     ` Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®