All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: Yann Droneaud <ydroneaud@opteya.com>
Cc: Gleb Natapov <gleb@redhat.com>,
	Alex Williamson <alex.williamson@redhat.com>,
	kvm@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/2] kvm: use anon_inode_getfd() with O_CLOEXEC flag
Date: Sun, 25 Aug 2013 08:49:32 +0200	[thread overview]
Message-ID: <5219A8FC.8090307@redhat.com> (raw)
In-Reply-To: <16c6c5380d543aca2aab13fdcbacaf12fdbca168.1377372576.git.ydroneaud@opteya.com>

Il 24/08/2013 22:14, Yann Droneaud ha scritto:
> KVM uses anon_inode_get() to allocate file descriptors as part
> of some of its ioctls. But those ioctls are lacking a flag argument
> allowing userspace to choose options for the newly opened file descriptor.
> 
> In such case it's advised to use O_CLOEXEC by default so that
> userspace is allowed to choose, without race, if the file descriptor
> is going to be inherited across exec().
> 
> This patch set O_CLOEXEC flag on all file descriptors created
> with anon_inode_getfd() to not leak file descriptors across exec().
> 
> Signed-off-by: Yann Droneaud <ydroneaud@opteya.com>
> Link: http://lkml.kernel.org/r/cover.1377372576.git.ydroneaud@opteya.com

Reviewed-by: Paolo Bonzini <pbonzini@redhat.com>

> ---
>  virt/kvm/kvm_main.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
> index 89f74d1..d65cc0c 100644
> --- a/virt/kvm/kvm_main.c
> +++ b/virt/kvm/kvm_main.c
> @@ -1896,7 +1896,7 @@ static struct file_operations kvm_vcpu_fops = {
>   */
>  static int create_vcpu_fd(struct kvm_vcpu *vcpu)
>  {
> -	return anon_inode_getfd("kvm-vcpu", &kvm_vcpu_fops, vcpu, O_RDWR);
> +	return anon_inode_getfd("kvm-vcpu", &kvm_vcpu_fops, vcpu, O_RDWR | O_CLOEXEC);
>  }
>  
>  /*
> @@ -2306,7 +2306,7 @@ static int kvm_ioctl_create_device(struct kvm *kvm,
>  		return ret;
>  	}
>  
> -	ret = anon_inode_getfd(ops->name, &kvm_device_fops, dev, O_RDWR);
> +	ret = anon_inode_getfd(ops->name, &kvm_device_fops, dev, O_RDWR | O_CLOEXEC);
>  	if (ret < 0) {
>  		ops->destroy(dev);
>  		return ret;
> @@ -2590,7 +2590,7 @@ static int kvm_dev_ioctl_create_vm(unsigned long type)
>  		return r;
>  	}
>  #endif
> -	r = anon_inode_getfd("kvm-vm", &kvm_vm_fops, kvm, O_RDWR);
> +	r = anon_inode_getfd("kvm-vm", &kvm_vm_fops, kvm, O_RDWR | O_CLOEXEC);
>  	if (r < 0)
>  		kvm_put_kvm(kvm);
>  
> 

  reply	other threads:[~2013-08-25  6:49 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-08-24 20:14 [PATCH 0/2] kvm: use anon_inode_getfd() with O_CLOEXEC flag Yann Droneaud
2013-08-24 20:14 ` Yann Droneaud
2013-08-24 20:14 ` Yann Droneaud
2013-08-24 20:14 ` [PATCH 1/2] " Yann Droneaud
2013-08-25  6:49   ` Paolo Bonzini [this message]
2013-08-24 20:14 ` [PATCH 2/2] ppc: " Yann Droneaud
2013-08-24 20:14   ` Yann Droneaud
2013-08-24 20:14   ` Yann Droneaud
2013-08-25 15:04   ` Alexander Graf
2013-08-25 15:04     ` Alexander Graf
2013-08-25 15:04     ` Alexander Graf
2013-08-26  7:39     ` Paolo Bonzini
2013-08-26  7:39       ` Paolo Bonzini
2013-08-26  7:39       ` Paolo Bonzini
2013-08-26  8:23       ` [PATCH 2/2] ppc: kvm: use anon_inode_getfd( =?UTF-8?Q?=29=20with=20O=5FCLOEXEC Yann Droneaud
2013-08-26  8:23         ` [PATCH 2/2] ppc: kvm: use anon_inode_getfd() with O_CLOEXEC flag Yann Droneaud
2013-08-26  8:23         ` Yann Droneaud
2013-08-26  8:28         ` Paolo Bonzini
2013-08-26  8:28           ` Paolo Bonzini
2013-08-26  8:28           ` Paolo Bonzini
2013-08-26 10:20 ` [PATCH 0/2] " Gleb Natapov
2013-08-26 10:20   ` Gleb Natapov
2013-08-26 10:20   ` Gleb Natapov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5219A8FC.8090307@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=alex.williamson@redhat.com \
    --cc=gleb@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ydroneaud@opteya.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.