All of lore.kernel.org
 help / color / mirror / Atom feed
From: Christian Brauner <brauner@kernel.org>
To: Zicheng Qu <quzicheng@huawei.com>,
	Linus Torvalds <torvalds@linux-foundation.org>
Cc: Christian Brauner <brauner@kernel.org>,
	jlayton@kernel.org, axboe@kernel.dk, joel.granados@kernel.org,
	tglx@linutronix.de, viro@zeniv.linux.org.uk, hch@lst.de,
	len.brown@intel.com, pavel@ucw.cz, pengfei.xu@intel.com,
	rafael@kernel.org, tanghui20@huawei.com, zhangqiao22@huawei.com,
	judy.chenhui@huawei.com, linux-kernel@vger.kernel.org,
	linux-fsdevel@vger.kernel.org, syzkaller-bugs@googlegroups.com,
	linux-pm@vger.kernel.org, stable@vger.kernel.org
Subject: [PATCH 0/2] acct: don't allow access to internal filesystems
Date: Tue, 11 Feb 2025 18:15:58 +0100	[thread overview]
Message-ID: <20250211-work-acct-v1-0-1c16aecab8b3@kernel.org> (raw)
In-Reply-To: <20250210-unordnung-petersilie-90e37411db18@brauner>

In [1] it was reported that the acct(2) system call can be used to
trigger a NULL deref in cases where it is set to write to a file that
triggers an internal lookup.

This can e.g., happen when pointing acct(2) to /sys/power/resume. At the
point the where the write to this file happens the calling task has
already exited and called exit_fs() but an internal lookup might be
triggered through lookup_bdev(). This may trigger a NULL-deref
when accessing current->fs.

This series does two things:

- Reorganize the code so that the the final write happens from the
  workqueue but with the caller's credentials. This preserves the
  (strange) permission model and has almost no regression risk.

- Block access to kernel internal filesystems as well as procfs and
  sysfs in the first place.

This api should stop to exist imho.

Link: https://lore.kernel.org/r/20250127091811.3183623-1-quzicheng@huawei.com [1]

Signed-off-by: Christian Brauner <brauner@kernel.org>
---
Christian Brauner (2):
      acct: perform last write from workqueue
      acct: block access to kernel internal filesystems

 kernel/acct.c | 134 ++++++++++++++++++++++++++++++++++++----------------------
 1 file changed, 84 insertions(+), 50 deletions(-)
---
base-commit: af69e27b3c8240f7889b6c457d71084458984d8e
change-id: 20250211-work-acct-a6d8e92a5fe0


  parent reply	other threads:[~2025-02-11 17:16 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-08-10 14:04 [Syzkaller & bisect] There is general protection fault in path_init in v6.11-rc2 Pengfei Xu
2025-01-27  9:18 ` Zicheng Qu
2025-02-10 13:17   ` [PATCH] acct: Prevent NULL pointer dereference when writing to sysfs Zicheng Qu
2025-02-10 15:12     ` Christian Brauner
2025-02-10 15:21       ` Al Viro
2025-02-10 16:02         ` Christian Brauner
2025-02-10 18:19           ` Al Viro
2025-02-11  0:23             ` Al Viro
2025-02-11 10:17               ` Christian Brauner
2025-02-11 17:15       ` Christian Brauner [this message]
2025-02-11 17:15         ` [PATCH 1/2] acct: perform last write from workqueue Christian Brauner
2025-02-11 17:16         ` [PATCH 2/2] acct: block access to kernel internal filesystems Christian Brauner
2025-02-11 20:30           ` Amir Goldstein
2025-02-11 20:54           ` Al Viro
2025-02-12 10:32             ` Christian Brauner
2025-02-11 18:56         ` [PATCH 0/2] acct: don't allow access to " Jeff Layton
2025-02-12 11:16           ` Christian Brauner
2025-02-13 14:56             ` Christian Brauner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250211-work-acct-v1-0-1c16aecab8b3@kernel.org \
    --to=brauner@kernel.org \
    --cc=axboe@kernel.dk \
    --cc=hch@lst.de \
    --cc=jlayton@kernel.org \
    --cc=joel.granados@kernel.org \
    --cc=judy.chenhui@huawei.com \
    --cc=len.brown@intel.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=pavel@ucw.cz \
    --cc=pengfei.xu@intel.com \
    --cc=quzicheng@huawei.com \
    --cc=rafael@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    --cc=tanghui20@huawei.com \
    --cc=tglx@linutronix.de \
    --cc=torvalds@linux-foundation.org \
    --cc=viro@zeniv.linux.org.uk \
    --cc=zhangqiao22@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.