From: Christian Brauner <brauner@kernel.org>
To: Mateusz Guzik <mjguzik@gmail.com>
Cc: linux-fsdevel@vger.kernel.org,
Christoph Hellwig <hch@infradead.org>,
Penglei Jiang <superman.xpt@gmail.com>,
Al Viro <viro@zeniv.linux.org.uk>, Jan Kara <jack@suse.cz>,
Jeff Layton <jlayton@kernel.org>,
Josef Bacik <josef@toxicpanda.com>,
syzbot+5d8e79d323a13aa0b248@syzkaller.appspotmail.com,
stable@vger.kernel.org
Subject: Re: [PATCH 0/9] fs: harden anon inodes
Date: Mon, 7 Apr 2025 15:41:54 +0200 [thread overview]
Message-ID: <20250407-uncool-entworfen-e9202b0f00b0@brauner> (raw)
In-Reply-To: <CAGudoHHbkbaeqTrNJZxCnpB_4zokQobWfK_AP4nU78B58e9Tow@mail.gmail.com>
On Mon, Apr 07, 2025 at 12:19:45PM +0200, Mateusz Guzik wrote:
> On Mon, Apr 7, 2025 at 11:54 AM Christian Brauner <brauner@kernel.org> wrote:
> >
> > * Anonymous inodes currently don't come with a proper mode causing
> > issues in the kernel when we want to add useful VFS debug assert. Fix
> > that by giving them a proper mode and masking it off when we report it
> > to userspace which relies on them not having any mode.
> >
> > * Anonymous inodes currently allow to change inode attributes because
> > the VFS falls back to simple_setattr() if i_op->setattr isn't
> > implemented. This means the ownership and mode for every single user
> > of anon_inode_inode can be changed. Block that as it's either useless
> > or actively harmful. If specific ownership is needed the respective
> > subsystem should allocate anonymous inodes from their own private
> > superblock.
> >
> > * Port pidfs to the new anon_inode_{g,s}etattr() helpers.
> >
> > * Add proper tests for anonymous inode behavior.
> >
> > The anonymous inode specific fixes should ideally be backported to all
> > LTS kernels.
> >
> > Signed-off-by: Christian Brauner <brauner@kernel.org>
> > ---
> > Christian Brauner (9):
> > anon_inode: use a proper mode internally
> > pidfs: use anon_inode_getattr()
> > anon_inode: explicitly block ->setattr()
> > pidfs: use anon_inode_setattr()
> > anon_inode: raise SB_I_NODEV and SB_I_NOEXEC
> > selftests/filesystems: add first test for anonymous inodes
> > selftests/filesystems: add second test for anonymous inodes
> > selftests/filesystems: add third test for anonymous inodes
> > selftests/filesystems: add fourth test for anonymous inodes
> >
>
> I have two nits, past that LGTM
>
> 1. I would add a comment explaining why S_IFREG in alloc_anon_inode()
/*
* Historically anonymous inodes didn't have a type at all and
* userspace has come to rely on this. Internally they're just
* regular files but S_IFREG is masked off when reporting
* information to userspace.
*/
> 2. commit messages for selftests could spell out what's being added
> instead of being counted, it's all one-liners
I've replaced the count with chown(), chmod(), exec(), and open().
Thanks!
next prev parent reply other threads:[~2025-04-07 13:42 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-07 9:54 [PATCH 0/9] fs: harden anon inodes Christian Brauner
2025-04-07 9:54 ` [PATCH 1/9] anon_inode: use a proper mode internally Christian Brauner
2025-04-07 12:19 ` Jeff Layton
2025-04-07 13:43 ` Christian Brauner
2025-04-07 14:04 ` Jan Kara
2025-04-11 10:31 ` Mark Brown
2025-04-11 15:03 ` Christian Brauner
2025-04-14 5:50 ` Christoph Hellwig
2025-04-18 2:15 ` Xilin Wu
2025-04-20 10:54 ` Christian Brauner
2025-04-21 8:35 ` Christian Brauner
2025-04-07 9:54 ` [PATCH 2/9] pidfs: use anon_inode_getattr() Christian Brauner
2025-04-07 14:04 ` Jan Kara
2025-04-07 9:54 ` [PATCH 3/9] anon_inode: explicitly block ->setattr() Christian Brauner
2025-04-07 14:05 ` Jan Kara
2025-04-07 9:54 ` [PATCH 4/9] pidfs: use anon_inode_setattr() Christian Brauner
2025-04-07 14:06 ` Jan Kara
2025-04-07 9:54 ` [PATCH 5/9] anon_inode: raise SB_I_NODEV and SB_I_NOEXEC Christian Brauner
2025-04-07 14:07 ` Jan Kara
2025-04-07 14:18 ` Christian Brauner
2025-04-07 9:54 ` [PATCH 6/9] selftests/filesystems: add first test for anonymous inodes Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 7/9] selftests/filesystems: add second " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 8/9] selftests/filesystems: add third " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 9/9] selftests/filesystems: add fourth " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 10:19 ` [PATCH 0/9] fs: harden anon inodes Mateusz Guzik
2025-04-07 13:41 ` Christian Brauner [this message]
2025-04-07 12:37 ` Jeff Layton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250407-uncool-entworfen-e9202b0f00b0@brauner \
--to=brauner@kernel.org \
--cc=hch@infradead.org \
--cc=jack@suse.cz \
--cc=jlayton@kernel.org \
--cc=josef@toxicpanda.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=mjguzik@gmail.com \
--cc=stable@vger.kernel.org \
--cc=superman.xpt@gmail.com \
--cc=syzbot+5d8e79d323a13aa0b248@syzkaller.appspotmail.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.