All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks
@ 2024-05-24 10:19 Christian Brauner
  2024-05-24 12:35 ` Amir Goldstein
                   ` (4 more replies)
  0 siblings, 5 replies; 14+ messages in thread
From: Christian Brauner @ 2024-05-24 10:19 UTC (permalink / raw)
  To: Amir Goldstein, Jeff Layton, Chuck Lever, Aleksa Sarai
  Cc: linux-fsdevel, Christian Brauner

A current limitation of open_by_handle_at() is that it's currently not possible
to use it from within containers at all because we require CAP_DAC_READ_SEARCH
in the initial namespace. That's unfortunate because there are scenarios where
using open_by_handle_at() from within containers.

Two examples:

(1) cgroupfs allows to encode cgroups to file handles and reopen them with
    open_by_handle_at().
(2) Fanotify allows placing filesystem watches they currently aren't usable in
    containers because the returned file handles cannot be used.

Here's a proposal for relaxing the permission check for open_by_handle_at().

(1) Opening file handles when the caller has privileges over the filesystem
    (1.1) The caller has an unobstructed view of the filesystem.
    (1.2) The caller has permissions to follow a path to the file handle.

This doesn't address the problem of opening a file handle when only a portion
of a filesystem is exposed as is common in containers by e.g., bind-mounting a
subtree. The proposal to solve this use-case is:

(2) Opening file handles when the caller has privileges over a subtree
    (2.1) The caller is able to reach the file from the provided mount fd.
    (2.2) The caller has permissions to construct an unobstructed path to the
          file handle.
    (2.3) The caller has permissions to follow a path to the file handle.

The relaxed permission checks are currently restricted to directory file
handles which are what both cgroupfs and fanotify need. Handling disconnected
non-directory file handles would lead to a potentially non-deterministic api.
If a disconnected non-directory file handle is provided we may fail to decode
a valid path that we could use for permission checking. That in itself isn't a
problem as we would just return EACCES in that case. However, confusion may
arise if a non-disconnected dentry ends up in the cache later and those opening
the file handle would suddenly succeed.

* It's potentially possible to use timing information (side-channel) to infer
  whether a given inode exists. I don't think that's particularly
  problematic. Thanks to Jann for bringing this to my attention.

* An unrelated note (IOW, these are thoughts that apply to
  open_by_handle_at() generically and are unrelated to the changes here):
  Jann pointed out that we should verify whether deleted files could
  potentially be reopened through open_by_handle_at(). I don't think that's
  possible though.

  Another potential thing to check is whether open_by_handle_at() could be
  abused to open internal stuff like memfds or gpu stuff. I don't think so
  but I haven't had the time to completely verify this.

This dates back to discussions Amir and I had quite some time ago and thanks to
him for providing a lot of details around the export code and related patches!

Signed-off-by: Christian Brauner <brauner@kernel.org>
---
 fs/exportfs/expfs.c      |   9 ++-
 fs/fhandle.c             | 162 ++++++++++++++++++++++++++++++++++++-----------
 fs/mount.h               |   1 +
 fs/namespace.c           |   2 +-
 fs/nfsd/nfsfh.c          |   2 +-
 include/linux/exportfs.h |   1 +
 6 files changed, 137 insertions(+), 40 deletions(-)

diff --git a/fs/exportfs/expfs.c b/fs/exportfs/expfs.c
index 07ea3d62b298..b23b052df715 100644
--- a/fs/exportfs/expfs.c
+++ b/fs/exportfs/expfs.c
@@ -427,7 +427,7 @@ EXPORT_SYMBOL_GPL(exportfs_encode_fh);
 
 struct dentry *
 exportfs_decode_fh_raw(struct vfsmount *mnt, struct fid *fid, int fh_len,
-		       int fileid_type,
+		       int fileid_type, bool directory,
 		       int (*acceptable)(void *, struct dentry *),
 		       void *context)
 {
@@ -445,6 +445,11 @@ exportfs_decode_fh_raw(struct vfsmount *mnt, struct fid *fid, int fh_len,
 	if (IS_ERR_OR_NULL(result))
 		return result;
 
+	if (directory && !d_is_dir(result)) {
+		err = -ENOTDIR;
+		goto err_result;
+	}
+
 	/*
 	 * If no acceptance criteria was specified by caller, a disconnected
 	 * dentry is also accepatable. Callers may use this mode to query if
@@ -581,7 +586,7 @@ struct dentry *exportfs_decode_fh(struct vfsmount *mnt, struct fid *fid,
 {
 	struct dentry *ret;
 
-	ret = exportfs_decode_fh_raw(mnt, fid, fh_len, fileid_type,
+	ret = exportfs_decode_fh_raw(mnt, fid, fh_len, fileid_type, false,
 				     acceptable, context);
 	if (IS_ERR_OR_NULL(ret)) {
 		if (ret == ERR_PTR(-ENOMEM))
diff --git a/fs/fhandle.c b/fs/fhandle.c
index 8a7f86c2139a..c6ed832ddbb8 100644
--- a/fs/fhandle.c
+++ b/fs/fhandle.c
@@ -115,88 +115,174 @@ SYSCALL_DEFINE5(name_to_handle_at, int, dfd, const char __user *, name,
 	return err;
 }
 
-static struct vfsmount *get_vfsmount_from_fd(int fd)
+static int get_path_from_fd(int fd, struct path *root)
 {
-	struct vfsmount *mnt;
-
 	if (fd == AT_FDCWD) {
 		struct fs_struct *fs = current->fs;
 		spin_lock(&fs->lock);
-		mnt = mntget(fs->pwd.mnt);
+		*root = fs->pwd;
+		path_get(root);
 		spin_unlock(&fs->lock);
 	} else {
 		struct fd f = fdget(fd);
 		if (!f.file)
-			return ERR_PTR(-EBADF);
-		mnt = mntget(f.file->f_path.mnt);
+			return -EBADF;
+		*root = f.file->f_path;
+		path_get(root);
 		fdput(f);
 	}
-	return mnt;
+
+	return 0;
 }
 
+enum handle_to_path_flags {
+	HANDLE_CHECK_PERMS   = (1 << 0),
+	HANDLE_CHECK_SUBTREE = (1 << 1),
+};
+
+struct handle_to_path_ctx {
+	struct path root;
+	enum handle_to_path_flags flags;
+	bool directory;
+};
+
 static int vfs_dentry_acceptable(void *context, struct dentry *dentry)
 {
-	return 1;
+	struct handle_to_path_ctx *ctx = context;
+	struct user_namespace *user_ns = current_user_ns();
+	struct dentry *d, *root = ctx->root.dentry;
+	struct mnt_idmap *idmap = mnt_idmap(ctx->root.mnt);
+	int retval = 0;
+
+	if (!root)
+		return 1;
+
+	/* Old permission model with global CAP_DAC_READ_SEARCH. */
+	if (!ctx->flags)
+		return 1;
+
+	/*
+	 * It's racy as we're not taking rename_lock but we're able to ignore
+	 * permissions and we just need an approximation whether we were able
+	 * to follow a path to the file.
+	 */
+	d = dget(dentry);
+	while (d != root && !IS_ROOT(d)) {
+		struct dentry *parent = dget_parent(d);
+
+		/*
+		 * We know that we have the ability to override DAC permissions
+		 * as we've verified this earlier via CAP_DAC_READ_SEARCH. But
+		 * we also need to make sure that there aren't any unmapped
+		 * inodes in the path that would prevent us from reaching the
+		 * file.
+		 */
+		if (!privileged_wrt_inode_uidgid(user_ns, idmap,
+						 d_inode(parent))) {
+			dput(d);
+			dput(parent);
+			return retval;
+		}
+
+		dput(d);
+		d = parent;
+	}
+
+	if (!(ctx->flags & HANDLE_CHECK_SUBTREE) || d == root)
+		retval = 1;
+
+	dput(d);
+	return retval;
 }
 
 static int do_handle_to_path(int mountdirfd, struct file_handle *handle,
-			     struct path *path)
+			     struct path *path, struct handle_to_path_ctx *ctx)
 {
-	int retval = 0;
 	int handle_dwords;
+	struct vfsmount *mnt = ctx->root.mnt;
 
-	path->mnt = get_vfsmount_from_fd(mountdirfd);
-	if (IS_ERR(path->mnt)) {
-		retval = PTR_ERR(path->mnt);
-		goto out_err;
-	}
 	/* change the handle size to multiple of sizeof(u32) */
 	handle_dwords = handle->handle_bytes >> 2;
-	path->dentry = exportfs_decode_fh(path->mnt,
+	path->dentry = exportfs_decode_fh_raw(mnt,
 					  (struct fid *)handle->f_handle,
 					  handle_dwords, handle->handle_type,
-					  vfs_dentry_acceptable, NULL);
-	if (IS_ERR(path->dentry)) {
-		retval = PTR_ERR(path->dentry);
-		goto out_mnt;
+					  ctx->directory,
+					  vfs_dentry_acceptable, ctx);
+	if (IS_ERR_OR_NULL(path->dentry)) {
+		if (path->dentry == ERR_PTR(-ENOMEM))
+			return -ENOMEM;
+		return -ESTALE;
 	}
+	path->mnt = mntget(mnt);
 	return 0;
-out_mnt:
-	mntput(path->mnt);
-out_err:
-	return retval;
 }
 
 static int handle_to_path(int mountdirfd, struct file_handle __user *ufh,
-		   struct path *path)
+		   struct path *path, unsigned int o_flags)
 {
 	int retval = 0;
 	struct file_handle f_handle;
 	struct file_handle *handle = NULL;
+	struct handle_to_path_ctx ctx = {};
+
+	retval = get_path_from_fd(mountdirfd, &ctx.root);
+	if (retval)
+		goto out_err;
 
-	/*
-	 * With handle we don't look at the execute bit on the
-	 * directory. Ideally we would like CAP_DAC_SEARCH.
-	 * But we don't have that
-	 */
 	if (!capable(CAP_DAC_READ_SEARCH)) {
+		/*
+		 * Allow relaxed permissions of file handles if the caller has
+		 * the ability to mount the filesystem or create a bind-mount
+		 * of the provided @mountdirfd.
+		 *
+		 * In both cases the caller may be able to get an unobstructed
+		 * way to the encoded file handle. If the caller is only able
+		 * to create a bind-mount we need to verify that there are no
+		 * locked mounts on top of it that could prevent us from
+		 * getting to the encoded file.
+		 *
+		 * In principle, locked mounts can prevent the caller from
+		 * mounting the filesystem but that only applies to procfs and
+		 * sysfs neither of which support decoding file handles.
+		 *
+		 * This is currently restricted to O_DIRECTORY to provide a
+		 * deterministic API that avoids a confusing api in the face of
+		 * disconnected non-dir dentries.
+		 */
+
 		retval = -EPERM;
-		goto out_err;
+		if (!(o_flags & O_DIRECTORY))
+			goto out_path;
+
+		if (ns_capable(ctx.root.mnt->mnt_sb->s_user_ns, CAP_SYS_ADMIN))
+			ctx.flags = HANDLE_CHECK_PERMS;
+		else if (ns_capable(real_mount(ctx.root.mnt)->mnt_ns->user_ns, CAP_SYS_ADMIN) &&
+			   !has_locked_children(real_mount(ctx.root.mnt), ctx.root.dentry))
+			ctx.flags = HANDLE_CHECK_PERMS | HANDLE_CHECK_SUBTREE;
+		else
+			goto out_path;
+
+		/* Are we able to override DAC permissions? */
+		if (!ns_capable(current_user_ns(), CAP_DAC_READ_SEARCH))
+			goto out_path;
+
+		ctx.directory = true;
 	}
+
 	if (copy_from_user(&f_handle, ufh, sizeof(struct file_handle))) {
 		retval = -EFAULT;
-		goto out_err;
+		goto out_path;
 	}
 	if ((f_handle.handle_bytes > MAX_HANDLE_SZ) ||
 	    (f_handle.handle_bytes == 0)) {
 		retval = -EINVAL;
-		goto out_err;
+		goto out_path;
 	}
 	handle = kmalloc(struct_size(handle, f_handle, f_handle.handle_bytes),
 			 GFP_KERNEL);
 	if (!handle) {
 		retval = -ENOMEM;
-		goto out_err;
+		goto out_path;
 	}
 	/* copy the full handle */
 	*handle = f_handle;
@@ -207,10 +293,14 @@ static int handle_to_path(int mountdirfd, struct file_handle __user *ufh,
 		goto out_handle;
 	}
 
-	retval = do_handle_to_path(mountdirfd, handle, path);
+	retval = do_handle_to_path(mountdirfd, handle, path, &ctx);
+	if (retval)
+		goto out_handle;
 
 out_handle:
 	kfree(handle);
+out_path:
+	path_put(&ctx.root);
 out_err:
 	return retval;
 }
@@ -223,7 +313,7 @@ static long do_handle_open(int mountdirfd, struct file_handle __user *ufh,
 	struct file *file;
 	int fd;
 
-	retval = handle_to_path(mountdirfd, ufh, &path);
+	retval = handle_to_path(mountdirfd, ufh, &path, open_flag);
 	if (retval)
 		return retval;
 
diff --git a/fs/mount.h b/fs/mount.h
index 4a42fc68f4cc..4adce73211ae 100644
--- a/fs/mount.h
+++ b/fs/mount.h
@@ -152,3 +152,4 @@ static inline void move_from_ns(struct mount *mnt, struct list_head *dt_list)
 }
 
 extern void mnt_cursor_del(struct mnt_namespace *ns, struct mount *cursor);
+bool has_locked_children(struct mount *mnt, struct dentry *dentry);
diff --git a/fs/namespace.c b/fs/namespace.c
index 5a51315c6678..4386787210c7 100644
--- a/fs/namespace.c
+++ b/fs/namespace.c
@@ -2078,7 +2078,7 @@ void drop_collected_mounts(struct vfsmount *mnt)
 	namespace_unlock();
 }
 
-static bool has_locked_children(struct mount *mnt, struct dentry *dentry)
+bool has_locked_children(struct mount *mnt, struct dentry *dentry)
 {
 	struct mount *child;
 
diff --git a/fs/nfsd/nfsfh.c b/fs/nfsd/nfsfh.c
index 0b75305fb5f5..3e7f81eb2818 100644
--- a/fs/nfsd/nfsfh.c
+++ b/fs/nfsd/nfsfh.c
@@ -247,7 +247,7 @@ static __be32 nfsd_set_fh_dentry(struct svc_rqst *rqstp, struct svc_fh *fhp)
 		dentry = dget(exp->ex_path.dentry);
 	else {
 		dentry = exportfs_decode_fh_raw(exp->ex_path.mnt, fid,
-						data_left, fileid_type,
+						data_left, fileid_type, false,
 						nfsd_acceptable, exp);
 		if (IS_ERR_OR_NULL(dentry)) {
 			trace_nfsd_set_fh_dentry_badhandle(rqstp, fhp,
diff --git a/include/linux/exportfs.h b/include/linux/exportfs.h
index bb37ad5cc954..90c4b0111218 100644
--- a/include/linux/exportfs.h
+++ b/include/linux/exportfs.h
@@ -305,6 +305,7 @@ static inline int exportfs_encode_fid(struct inode *inode, struct fid *fid,
 extern struct dentry *exportfs_decode_fh_raw(struct vfsmount *mnt,
 					     struct fid *fid, int fh_len,
 					     int fileid_type,
+					     bool directory,
 					     int (*acceptable)(void *, struct dentry *),
 					     void *context);
 extern struct dentry *exportfs_decode_fh(struct vfsmount *mnt, struct fid *fid,

---
base-commit: 8f6a15f095a63a83b096d9b29aaff4f0fbe6f6e6
change-id: 20240524-vfs-open_by_handle_at-73c20767eb4e


^ permalink raw reply related	[flat|nested] 14+ messages in thread
* Re: [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks
@ 2024-05-26  0:03 kernel test robot
  0 siblings, 0 replies; 14+ messages in thread
From: kernel test robot @ 2024-05-26  0:03 UTC (permalink / raw)
  To: oe-kbuild; +Cc: lkp, Dan Carpenter

BCC: lkp@intel.com
CC: oe-kbuild-all@lists.linux.dev
In-Reply-To: <20240524-vfs-open_by_handle_at-v1-1-3d4b7d22736b@kernel.org>
References: <20240524-vfs-open_by_handle_at-v1-1-3d4b7d22736b@kernel.org>
TO: Christian Brauner <brauner@kernel.org>

Hi Christian,

[This is a private test report for your RFC patch.]
kernel test robot noticed the following build warnings:

[auto build test WARNING on 8f6a15f095a63a83b096d9b29aaff4f0fbe6f6e6]

url:    https://github.com/intel-lab-lkp/linux/commits/Christian-Brauner/fhandle-relax-open_by_handle_at-permission-checks/20240524-182059
base:   8f6a15f095a63a83b096d9b29aaff4f0fbe6f6e6
patch link:    https://lore.kernel.org/r/20240524-vfs-open_by_handle_at-v1-1-3d4b7d22736b%40kernel.org
patch subject: [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks
:::::: branch date: 2 days ago
:::::: commit date: 2 days ago
config: i386-randconfig-141-20240525 (https://download.01.org/0day-ci/archive/20240526/202405260707.w8Nh9Nv6-lkp@intel.com/config)
compiler: gcc-12 (Ubuntu 12.3.0-9ubuntu2) 12.3.0

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Reported-by: Dan Carpenter <error27@gmail.com>
| Closes: https://lore.kernel.org/r/202405260707.w8Nh9Nv6-lkp@intel.com/

smatch warnings:
fs/fhandle.c:296 handle_to_path() warn: fd re-used after fget(): 'mountdirfd'

vim +/mountdirfd +296 fs/fhandle.c

becfd1f3754479 Aneesh Kumar K.V    2011-01-29  219  
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  220  static int handle_to_path(int mountdirfd, struct file_handle __user *ufh,
9ca8b65e411ba7 Christian Brauner   2024-05-24  221  		   struct path *path, unsigned int o_flags)
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  222  {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  223  	int retval = 0;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  224  	struct file_handle f_handle;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  225  	struct file_handle *handle = NULL;
9ca8b65e411ba7 Christian Brauner   2024-05-24  226  	struct handle_to_path_ctx ctx = {};
9ca8b65e411ba7 Christian Brauner   2024-05-24  227  
9ca8b65e411ba7 Christian Brauner   2024-05-24  228  	retval = get_path_from_fd(mountdirfd, &ctx.root);
9ca8b65e411ba7 Christian Brauner   2024-05-24  229  	if (retval)
9ca8b65e411ba7 Christian Brauner   2024-05-24  230  		goto out_err;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  231  
9ca8b65e411ba7 Christian Brauner   2024-05-24  232  	if (!capable(CAP_DAC_READ_SEARCH)) {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  233  		/*
9ca8b65e411ba7 Christian Brauner   2024-05-24  234  		 * Allow relaxed permissions of file handles if the caller has
9ca8b65e411ba7 Christian Brauner   2024-05-24  235  		 * the ability to mount the filesystem or create a bind-mount
9ca8b65e411ba7 Christian Brauner   2024-05-24  236  		 * of the provided @mountdirfd.
9ca8b65e411ba7 Christian Brauner   2024-05-24  237  		 *
9ca8b65e411ba7 Christian Brauner   2024-05-24  238  		 * In both cases the caller may be able to get an unobstructed
9ca8b65e411ba7 Christian Brauner   2024-05-24  239  		 * way to the encoded file handle. If the caller is only able
9ca8b65e411ba7 Christian Brauner   2024-05-24  240  		 * to create a bind-mount we need to verify that there are no
9ca8b65e411ba7 Christian Brauner   2024-05-24  241  		 * locked mounts on top of it that could prevent us from
9ca8b65e411ba7 Christian Brauner   2024-05-24  242  		 * getting to the encoded file.
9ca8b65e411ba7 Christian Brauner   2024-05-24  243  		 *
9ca8b65e411ba7 Christian Brauner   2024-05-24  244  		 * In principle, locked mounts can prevent the caller from
9ca8b65e411ba7 Christian Brauner   2024-05-24  245  		 * mounting the filesystem but that only applies to procfs and
9ca8b65e411ba7 Christian Brauner   2024-05-24  246  		 * sysfs neither of which support decoding file handles.
9ca8b65e411ba7 Christian Brauner   2024-05-24  247  		 *
9ca8b65e411ba7 Christian Brauner   2024-05-24  248  		 * This is currently restricted to O_DIRECTORY to provide a
9ca8b65e411ba7 Christian Brauner   2024-05-24  249  		 * deterministic API that avoids a confusing api in the face of
9ca8b65e411ba7 Christian Brauner   2024-05-24  250  		 * disconnected non-dir dentries.
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  251  		 */
9ca8b65e411ba7 Christian Brauner   2024-05-24  252  
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  253  		retval = -EPERM;
9ca8b65e411ba7 Christian Brauner   2024-05-24  254  		if (!(o_flags & O_DIRECTORY))
9ca8b65e411ba7 Christian Brauner   2024-05-24  255  			goto out_path;
9ca8b65e411ba7 Christian Brauner   2024-05-24  256  
9ca8b65e411ba7 Christian Brauner   2024-05-24  257  		if (ns_capable(ctx.root.mnt->mnt_sb->s_user_ns, CAP_SYS_ADMIN))
9ca8b65e411ba7 Christian Brauner   2024-05-24  258  			ctx.flags = HANDLE_CHECK_PERMS;
9ca8b65e411ba7 Christian Brauner   2024-05-24  259  		else if (ns_capable(real_mount(ctx.root.mnt)->mnt_ns->user_ns, CAP_SYS_ADMIN) &&
9ca8b65e411ba7 Christian Brauner   2024-05-24  260  			   !has_locked_children(real_mount(ctx.root.mnt), ctx.root.dentry))
9ca8b65e411ba7 Christian Brauner   2024-05-24  261  			ctx.flags = HANDLE_CHECK_PERMS | HANDLE_CHECK_SUBTREE;
9ca8b65e411ba7 Christian Brauner   2024-05-24  262  		else
9ca8b65e411ba7 Christian Brauner   2024-05-24  263  			goto out_path;
9ca8b65e411ba7 Christian Brauner   2024-05-24  264  
9ca8b65e411ba7 Christian Brauner   2024-05-24  265  		/* Are we able to override DAC permissions? */
9ca8b65e411ba7 Christian Brauner   2024-05-24  266  		if (!ns_capable(current_user_ns(), CAP_DAC_READ_SEARCH))
9ca8b65e411ba7 Christian Brauner   2024-05-24  267  			goto out_path;
9ca8b65e411ba7 Christian Brauner   2024-05-24  268  
9ca8b65e411ba7 Christian Brauner   2024-05-24  269  		ctx.directory = true;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  270  	}
9ca8b65e411ba7 Christian Brauner   2024-05-24  271  
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  272  	if (copy_from_user(&f_handle, ufh, sizeof(struct file_handle))) {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  273  		retval = -EFAULT;
9ca8b65e411ba7 Christian Brauner   2024-05-24  274  		goto out_path;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  275  	}
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  276  	if ((f_handle.handle_bytes > MAX_HANDLE_SZ) ||
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  277  	    (f_handle.handle_bytes == 0)) {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  278  		retval = -EINVAL;
9ca8b65e411ba7 Christian Brauner   2024-05-24  279  		goto out_path;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  280  	}
68d6f4f3fbd9b1 Gustavo A. R. Silva 2024-03-25  281  	handle = kmalloc(struct_size(handle, f_handle, f_handle.handle_bytes),
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  282  			 GFP_KERNEL);
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  283  	if (!handle) {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  284  		retval = -ENOMEM;
9ca8b65e411ba7 Christian Brauner   2024-05-24  285  		goto out_path;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  286  	}
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  287  	/* copy the full handle */
161f873b89136e Sasha Levin         2015-01-28  288  	*handle = f_handle;
161f873b89136e Sasha Levin         2015-01-28  289  	if (copy_from_user(&handle->f_handle,
161f873b89136e Sasha Levin         2015-01-28  290  			   &ufh->f_handle,
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  291  			   f_handle.handle_bytes)) {
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  292  		retval = -EFAULT;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  293  		goto out_handle;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  294  	}
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  295  
9ca8b65e411ba7 Christian Brauner   2024-05-24 @296  	retval = do_handle_to_path(mountdirfd, handle, path, &ctx);
9ca8b65e411ba7 Christian Brauner   2024-05-24  297  	if (retval)
9ca8b65e411ba7 Christian Brauner   2024-05-24  298  		goto out_handle;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  299  
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  300  out_handle:
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  301  	kfree(handle);
9ca8b65e411ba7 Christian Brauner   2024-05-24  302  out_path:
9ca8b65e411ba7 Christian Brauner   2024-05-24  303  	path_put(&ctx.root);
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  304  out_err:
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  305  	return retval;
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  306  }
becfd1f3754479 Aneesh Kumar K.V    2011-01-29  307  

-- 
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2025-04-24 11:34 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-05-24 10:19 [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks Christian Brauner
2024-05-24 12:35 ` Amir Goldstein
2024-10-13 16:34   ` Amir Goldstein
2024-10-14 16:06     ` Jan Kara
2024-10-15 14:01     ` Christian Brauner
2024-10-16 12:45       ` fanotify sb/mount watch inside userns (Was: [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks) Amir Goldstein
2024-10-16 12:53         ` Amir Goldstein
2025-04-18 11:32           ` Amir Goldstein
2025-04-24 11:28             ` Jan Kara
2024-05-25 10:55 ` [PATCH RFC] : fhandle: relax open_by_handle_at() permission checks Jeff Layton
2024-05-27  2:49 ` kernel test robot
2024-05-27  7:28 ` Dan Carpenter
2024-05-27 11:31 ` Christoph Hellwig
  -- strict thread matches above, loose matches on Subject: below --
2024-05-26  0:03 kernel test robot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.