mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org,
	"Linus Torvalds" <torvalds@linux-foundation.org>,
	"Anatol Pomozov" <anatol.pomozov@gmail.com>,
	"Al Viro" <viro@zeniv.linux.org.uk>
Subject: [51/74] loop: prevent bdev freeing while device in use
Date: Sun, 07 Apr 2013 23:45:42 +0100	[thread overview]
Message-ID: <lsq.1365374742.143558874@decadent.org.uk> (raw)
In-Reply-To: <lsq.1365374742.214522651@decadent.org.uk>

3.2.43-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Anatol Pomozov <anatol.pomozov@gmail.com>

commit c1681bf8a7b1b98edee8b862a42c19c4e53205fd upstream.

struct block_device lifecycle is defined by its inode (see fs/block_dev.c) -
block_device allocated first time we access /dev/loopXX and deallocated on
bdev_destroy_inode. When we create the device "losetup /dev/loopXX afile"
we want that block_device stay alive until we destroy the loop device
with "losetup -d".

But because we do not hold /dev/loopXX inode its counter goes 0, and
inode/bdev can be destroyed at any moment. Usually it happens at memory
pressure or when user drops inode cache (like in the test below). When later in
loop_clr_fd() we want to use bdev we have use-after-free error with following
stack:

BUG: unable to handle kernel NULL pointer dereference at 0000000000000280
  bd_set_size+0x10/0xa0
  loop_clr_fd+0x1f8/0x420 [loop]
  lo_ioctl+0x200/0x7e0 [loop]
  lo_compat_ioctl+0x47/0xe0 [loop]
  compat_blkdev_ioctl+0x341/0x1290
  do_filp_open+0x42/0xa0
  compat_sys_ioctl+0xc1/0xf20
  do_sys_open+0x16e/0x1d0
  sysenter_dispatch+0x7/0x1a

To prevent use-after-free we need to grab the device in loop_set_fd()
and put it later in loop_clr_fd().

The issue is reprodusible on current Linus head and v3.3. Here is the test:

  dd if=/dev/zero of=loop.file bs=1M count=1
  while [ true ]; do
    losetup /dev/loop0 loop.file
    echo 2 > /proc/sys/vm/drop_caches
    losetup -d /dev/loop0
  done

[ Doing bdgrab/bput in loop_set_fd/loop_clr_fd is safe, because every
  time we call loop_set_fd() we check that loop_device->lo_state is
  Lo_unbound and set it to Lo_bound If somebody will try to set_fd again
  it will get EBUSY.  And if we try to loop_clr_fd() on unbound loop
  device we'll get ENXIO.

  loop_set_fd/loop_clr_fd (and any other loop ioctl) is called under
  loop_device->lo_ctl_mutex. ]

Signed-off-by: Anatol Pomozov <anatol.pomozov@gmail.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/block/loop.c |    9 ++++++++-
 fs/block_dev.c       |    1 +
 2 files changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -907,6 +907,11 @@ static int loop_set_fd(struct loop_devic
 		lo->lo_flags |= LO_FLAGS_PARTSCAN;
 	if (lo->lo_flags & LO_FLAGS_PARTSCAN)
 		ioctl_by_bdev(bdev, BLKRRPART, 0);
+
+	/* Grab the block_device to prevent its destruction after we
+	 * put /dev/loopXX inode. Later in loop_clr_fd() we bdput(bdev).
+	 */
+	bdgrab(bdev);
 	return 0;
 
 out_clr:
@@ -1003,8 +1008,10 @@ static int loop_clr_fd(struct loop_devic
 	memset(lo->lo_encrypt_key, 0, LO_KEY_SIZE);
 	memset(lo->lo_crypt_name, 0, LO_NAME_SIZE);
 	memset(lo->lo_file_name, 0, LO_NAME_SIZE);
-	if (bdev)
+	if (bdev) {
+		bdput(bdev);
 		invalidate_bdev(bdev);
+	}
 	set_capacity(lo->lo_disk, 0);
 	loop_sysfs_exit(lo);
 	if (bdev) {
--- a/fs/block_dev.c
+++ b/fs/block_dev.c
@@ -587,6 +587,7 @@ struct block_device *bdgrab(struct block
 	ihold(bdev->bd_inode);
 	return bdev;
 }
+EXPORT_SYMBOL(bdgrab);
 
 long nr_blockdev_pages(void)
 {


  parent reply	other threads:[~2013-04-07 23:33 UTC|newest]

Thread overview: 75+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-04-07 22:45 [00/74] 3.2.43-rc1 review Ben Hutchings
2013-04-07 22:45 ` [53/74] sky2: Threshold for Pause Packet is set wrong Ben Hutchings
2013-04-07 22:45 ` [32/74] vt: synchronize_rcu() under spinlock is not nice Ben Hutchings
2013-04-07 22:45 ` [45/74] mm: prevent mmap_cache race in find_vma() Ben Hutchings
2013-04-07 22:45 ` [25/74] ASoC: dma-sh7760: Fix compile error Ben Hutchings
2013-04-07 22:45 ` [54/74] tcp: preserve ACK clocking in TSO Ben Hutchings
2013-04-07 22:45 ` [56/74] 8021q: fix a potential use-after-free Ben Hutchings
2013-04-07 22:45 ` [09/74] Bluetooth: Add support for atheros 04ca:3004 device to ath3k Ben Hutchings
2013-04-07 22:45 ` [27/74] SUNRPC: Add barriers to ensure read ordering in rpc_wake_up_task_queue_locked Ben Hutchings
2013-04-07 22:45 ` [49/74] udf: Fix bitmap overflow on large filesystems with small block size Ben Hutchings
2013-04-07 22:45 ` [41/74] virtio: console: rename cvq_lock to c_ivq_lock Ben Hutchings
2013-04-07 22:45 ` [03/74] UBIFS: make space fixup work in the remount case Ben Hutchings
2013-04-07 22:45 ` [35/74] b43: A fix for DMA transmission sequence errors Ben Hutchings
2013-04-07 22:45 ` [55/74] tcp: undo spurious timeout after SACK reneging Ben Hutchings
2013-04-07 22:45 ` [31/74] Nest rename_lock inside vfsmount_lock Ben Hutchings
2013-04-07 22:45 ` [26/74] IPoIB: Fix send lockup due to missed TX completion Ben Hutchings
2013-04-07 22:45 ` [47/74] rt2x00: error in configurations with mesh support disabled Ben Hutchings
2013-04-07 22:45 ` [14/74] HID: usbhid: quirk for MSI GX680R led panel Ben Hutchings
2013-04-07 22:45 ` [24/74] NFSv4.1: Fix a race in pNFS layoutcommit Ben Hutchings
2013-04-07 22:45 ` [44/74] EISA/PCI: Init EISA early, before PNP Ben Hutchings
2013-04-07 22:45 ` [29/74] staging: comedi: s626: fix continuous acquisition Ben Hutchings
2013-04-07 22:45 ` [40/74] tile: expect new initramfs name from hypervisor file system Ben Hutchings
2013-04-07 22:45 ` [04/74] Bluetooth: Add support for IMC Networks [13d3:3393] Ben Hutchings
2013-04-07 22:45 ` [34/74] can: sja1000: fix define conflict on SH Ben Hutchings
2013-04-07 22:45 ` [07/74] Bluetooth: Add support for Foxconn / Hon Hai [0489:e056] Ben Hutchings
2013-04-07 22:45 ` [43/74] spi/mpc512x-psc: optionally keep PSC SS asserted across xfer segmensts Ben Hutchings
2013-04-07 22:45 ` [21/74] sysfs: fix race between readdir and lseek Ben Hutchings
2013-04-07 22:45 ` [50/74] NFS: nfs_getaclargs.acl_len is a size_t Ben Hutchings
2013-04-07 22:45 ` [30/74] nfsd4: reject "negative" acl lengths Ben Hutchings
2013-04-07 22:45 ` [13/74] HID: usbhid: quirk for Realtek Multi-card reader Ben Hutchings
2013-04-07 22:45 ` [12/74] tty: atmel_serial_probe(): index of atmel_ports[] fix Ben Hutchings
2013-04-07 22:45 ` [02/74] ASoC: imx-ssi: Fix occasional AC97 reset failure Ben Hutchings
2013-04-07 22:45 ` [05/74] Bluetooth: Add support for GC-WB300D PCIe [04ca:3006] to ath3k Ben Hutchings
2013-04-07 22:45 ` [38/74] usb: ftdi_sio: Add support for Mitsubishi FX-USB-AW/-BD Ben Hutchings
2013-04-07 22:45 ` Ben Hutchings [this message]
2013-04-07 22:45 ` [17/74] ath9k_hw: revert chainmask to user configuration after calibration Ben Hutchings
2013-04-07 22:45 ` [23/74] pnfs-block: removing DM device maybe cause oops when call dev_remove Ben Hutchings
2013-04-07 22:45 ` [28/74] usb: xhci: Fix TRB transfer length macro used for Event TRB Ben Hutchings
2013-04-07 22:45 ` [52/74] sky2: Receive Overflows not counted Ben Hutchings
2013-04-07 22:45 ` [22/74] sysfs: handle failure path correctly for readdir() Ben Hutchings
2013-04-07 22:45 ` [42/74] virtio: console: add locking around c_ovq operations Ben Hutchings
2013-04-07 22:45 ` [08/74] Bluetooth device 04ca:3008 should use ath3k Ben Hutchings
2013-04-07 22:45 ` [16/74] Bluetooth: Add support for Dell[QCA 0cf3:817a] Ben Hutchings
2013-04-07 22:45 ` [11/74] Bluetooth: Add support for Dell[QCA 0cf3:0036] Ben Hutchings
2013-04-07 22:45 ` [46/74] ixgbe: fix registration order of driver and DCA nofitication Ben Hutchings
2013-04-07 22:45 ` [01/74] clockevents: Don't allow dummy broadcast timers Ben Hutchings
2013-04-07 22:45 ` [06/74] Bluetooth: Add support for Foxconn / Hon Hai [0489:e04e] Ben Hutchings
2013-04-07 22:45 ` [10/74] Bluetooth: Device 0cf3:3008 should map AR 3012 Ben Hutchings
2013-04-07 22:45 ` [20/74] net/irda: add missing error path release_sock call Ben Hutchings
2013-04-07 22:45 ` [48/74] key: Fix resource leak Ben Hutchings
2013-04-07 22:45 ` [18/74] rtlwifi: usb: add missing freeing of skbuff Ben Hutchings
2013-04-07 22:45 ` [36/74] tg3: fix length overflow in VPD firmware parsing Ben Hutchings
2013-04-07 22:45 ` [37/74] Btrfs: limit the global reserve to 512mb Ben Hutchings
2013-04-07 22:45 ` [15/74] HID: usbhid: fix build problem Ben Hutchings
2013-04-07 22:45 ` [19/74] xen-blkback: fix dispatch_rw_block_io() error path Ben Hutchings
2013-04-07 22:45 ` [33/74] iommu/amd: Make sure dma_ops are set for hotplug devices Ben Hutchings
2013-04-07 22:45 ` [39/74] reiserfs: Fix warning and inode leak when deleting inode with xattrs Ben Hutchings
2013-04-07 22:45 ` [61/74] bonding: fix disabling of arp_interval and miimon Ben Hutchings
2013-04-07 22:45 ` [72/74] smsc75xx: fix jumbo frame support Ben Hutchings
2013-04-07 22:45 ` [63/74] aoe: reserve enough headroom on skbs Ben Hutchings
2013-04-07 22:45 ` [58/74] bonding: fix miimon and arp_interval delayed work race conditions Ben Hutchings
2013-04-07 22:45 ` [74/74] HID: microsoft: do not use compound literal - fix build Ben Hutchings
2013-04-07 22:45 ` [73/74] bonding: get netdev_rx_handler_unregister out of locks Ben Hutchings
2013-04-07 22:45 ` [57/74] thermal: shorten too long mcast group name Ben Hutchings
2013-04-07 22:45 ` [64/74] atl1e: drop pci-msi support because of packet corruption Ben Hutchings
2013-04-07 22:45 ` [62/74] drivers: net: ethernet: davinci_emac: use netif_wake_queue() while restarting tx queue Ben Hutchings
2013-04-07 22:45 ` [67/74] ipv6: fix bad free of addrconf_init_net Ben Hutchings
2013-04-07 22:45 ` [65/74] DM9000B: driver initialization upgrade Ben Hutchings
2013-04-07 22:45 ` [59/74] unix: fix a race condition in unix_release() Ben Hutchings
2013-04-07 22:45 ` [71/74] pch_gbe: fix ip_summed checksum reporting on rx Ben Hutchings
2013-04-07 22:45 ` [60/74] bonding: remove already created master sysfs link on failure Ben Hutchings
2013-04-07 22:45 ` [66/74] ipv6: don't accept multicast traffic with scope 0 Ben Hutchings
2013-04-07 22:45 ` [68/74] ipv6: don't accept node local multicast traffic from the wire Ben Hutchings
2013-04-07 22:45 ` [70/74] net: add a synchronize_net() in netdev_rx_handler_unregister() Ben Hutchings
2013-04-07 22:45 ` [69/74] ks8851: Fix interpretation of rxlen field Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1365374742.143558874@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=akpm@linux-foundation.org \
    --cc=anatol.pomozov@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®