All of lore.kernel.org
 help / color / mirror / Atom feed
From: Patrick McHardy <kaber@trash.net>
To: Al Viro <viro@ZenIV.linux.org.uk>
Cc: netdev@vger.kernel.org
Subject: Re: buggy check in netlink_mmap_sendmsg()
Date: Fri, 19 Jul 2013 17:38:46 +0200	[thread overview]
Message-ID: <20130719153846.GB14764@macbook.localnet> (raw)
In-Reply-To: <20130718111358.GA27488@macbook.localnet>

On Thu, Jul 18, 2013 at 01:13:58PM +0200, Patrick McHardy wrote:
> On Sun, Jul 14, 2013 at 10:36:19AM +0100, Al Viro wrote:
> > This
> >         /* Netlink messages are validated by the receiver before processing.
> >          * In order to avoid userspace changing the contents of the message
> >          * after validation, the socket and the ring may only be used by a
> >          * single process, otherwise we fall back to copying.
> >          */
> >         if (atomic_long_read(&sk->sk_socket->file->f_count) > 2 ||  
> >             atomic_read(&nlk->mapped) > 1)
> >                 excl = false;
> > looks very odd.  For one thing, descriptor table may be shared, with
> > one thread calling sendmsg() (which gives f_count equal to 2), while
> > another calls mmap() just as the first one gets past that check.
> 
> Another thread calling mmap() should be fine since validation, processing
> and mmap() all happen under the pg_vec_lock mutex.
> 
> > Moreover, we might very well have the damn thing mmapped, then clone(2)
> > creating another thread that shares address space, but not the descriptor
> > table.  Child closes the socket descriptor it got, then parent does
> > sendmsg(2) (f_count == 2, again, since this time descriptor table isn't
> > shared and sendmsg(2) doesn't grab a reference and we have 1 from descriptor
> > table and 1 from mapping).  Again, the child has it mapped and can play
> > with it as it wishes...
> 
> This is unfortunately not my area of expertise. Let me look into how we
> can prevent this.

>From what I can tell, the second check should catch the second case you
describe. If the address space is shared, dup_mmap() will invoke
netlink_mmap_ops->open, so nlk->mmaped will be > 1. Basically the intention
was to have the nlk->mmaped check catch all cases of shared address spaces,
and have the f_count check prevent socket descriptor passing using
AF_UNIX between unrelated processes.

  reply	other threads:[~2013-07-19 15:38 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-07-14  9:36 buggy check in netlink_mmap_sendmsg() Al Viro
2013-07-18 11:22 ` Patrick McHardy
2013-07-19 15:38   ` Patrick McHardy [this message]
2013-07-19 15:45     ` Al Viro
2013-07-19 15:52     ` Al Viro

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20130719153846.GB14764@macbook.localnet \
    --to=kaber@trash.net \
    --cc=netdev@vger.kernel.org \
    --cc=viro@ZenIV.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.