From: Jeff Layton <jlayton@kernel.org>
To: Christian Brauner <brauner@kernel.org>, linux-fsdevel@vger.kernel.org
Cc: Christoph Hellwig <hch@infradead.org>,
Mateusz Guzik <mjguzik@gmail.com>,
Penglei Jiang <superman.xpt@gmail.com>,
Al Viro <viro@zeniv.linux.org.uk>, Jan Kara <jack@suse.cz>,
Josef Bacik <josef@toxicpanda.com>,
syzbot+5d8e79d323a13aa0b248@syzkaller.appspotmail.com,
stable@vger.kernel.org
Subject: Re: [PATCH 0/9] fs: harden anon inodes
Date: Mon, 07 Apr 2025 08:37:26 -0400 [thread overview]
Message-ID: <e0bb774753cc5f273a77743060337f2c9971a0cc.camel@kernel.org> (raw)
In-Reply-To: <20250407-work-anon_inode-v1-0-53a44c20d44e@kernel.org>
On Mon, 2025-04-07 at 11:54 +0200, Christian Brauner wrote:
> * Anonymous inodes currently don't come with a proper mode causing
> issues in the kernel when we want to add useful VFS debug assert. Fix
> that by giving them a proper mode and masking it off when we report it
> to userspace which relies on them not having any mode.
>
> * Anonymous inodes currently allow to change inode attributes because
> the VFS falls back to simple_setattr() if i_op->setattr isn't
> implemented. This means the ownership and mode for every single user
> of anon_inode_inode can be changed. Block that as it's either useless
> or actively harmful. If specific ownership is needed the respective
> subsystem should allocate anonymous inodes from their own private
> superblock.
>
> * Port pidfs to the new anon_inode_{g,s}etattr() helpers.
>
> * Add proper tests for anonymous inode behavior.
>
> The anonymous inode specific fixes should ideally be backported to all
> LTS kernels.
>
> Signed-off-by: Christian Brauner <brauner@kernel.org>
> ---
> Christian Brauner (9):
> anon_inode: use a proper mode internally
> pidfs: use anon_inode_getattr()
> anon_inode: explicitly block ->setattr()
> pidfs: use anon_inode_setattr()
> anon_inode: raise SB_I_NODEV and SB_I_NOEXEC
> selftests/filesystems: add first test for anonymous inodes
> selftests/filesystems: add second test for anonymous inodes
> selftests/filesystems: add third test for anonymous inodes
> selftests/filesystems: add fourth test for anonymous inodes
>
> fs/anon_inodes.c | 45 ++++++++++++++
> fs/internal.h | 5 ++
> fs/libfs.c | 2 +-
> fs/pidfs.c | 26 +-------
> tools/testing/selftests/filesystems/.gitignore | 1 +
> tools/testing/selftests/filesystems/Makefile | 2 +-
> .../selftests/filesystems/anon_inode_test.c | 69 ++++++++++++++++++++++
> 7 files changed, 124 insertions(+), 26 deletions(-)
> ---
> base-commit: 0af2f6be1b4281385b618cb86ad946eded089ac8
> change-id: 20250407-work-anon_inode-e22bb1a74992
>
This all looks like good changes to make. I'm still a little curious
about what might be dependent on not seeing a file type in st_mode, but
if we haven't traditionally reported one, it's probably safest to
continue without doing so.
Reviewed-by: Jeff Layton <jlayton@kernel.org>
prev parent reply other threads:[~2025-04-07 12:37 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-07 9:54 [PATCH 0/9] fs: harden anon inodes Christian Brauner
2025-04-07 9:54 ` [PATCH 1/9] anon_inode: use a proper mode internally Christian Brauner
2025-04-07 12:19 ` Jeff Layton
2025-04-07 13:43 ` Christian Brauner
2025-04-07 14:04 ` Jan Kara
2025-04-11 10:31 ` Mark Brown
2025-04-11 15:03 ` Christian Brauner
2025-04-14 5:50 ` Christoph Hellwig
2025-04-18 2:15 ` Xilin Wu
2025-04-20 10:54 ` Christian Brauner
2025-04-21 8:35 ` Christian Brauner
2025-04-07 9:54 ` [PATCH 2/9] pidfs: use anon_inode_getattr() Christian Brauner
2025-04-07 14:04 ` Jan Kara
2025-04-07 9:54 ` [PATCH 3/9] anon_inode: explicitly block ->setattr() Christian Brauner
2025-04-07 14:05 ` Jan Kara
2025-04-07 9:54 ` [PATCH 4/9] pidfs: use anon_inode_setattr() Christian Brauner
2025-04-07 14:06 ` Jan Kara
2025-04-07 9:54 ` [PATCH 5/9] anon_inode: raise SB_I_NODEV and SB_I_NOEXEC Christian Brauner
2025-04-07 14:07 ` Jan Kara
2025-04-07 14:18 ` Christian Brauner
2025-04-07 9:54 ` [PATCH 6/9] selftests/filesystems: add first test for anonymous inodes Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 7/9] selftests/filesystems: add second " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 8/9] selftests/filesystems: add third " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 9:54 ` [PATCH 9/9] selftests/filesystems: add fourth " Christian Brauner
2025-04-07 14:09 ` Jan Kara
2025-04-07 10:19 ` [PATCH 0/9] fs: harden anon inodes Mateusz Guzik
2025-04-07 13:41 ` Christian Brauner
2025-04-07 12:37 ` Jeff Layton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e0bb774753cc5f273a77743060337f2c9971a0cc.camel@kernel.org \
--to=jlayton@kernel.org \
--cc=brauner@kernel.org \
--cc=hch@infradead.org \
--cc=jack@suse.cz \
--cc=josef@toxicpanda.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=mjguzik@gmail.com \
--cc=stable@vger.kernel.org \
--cc=superman.xpt@gmail.com \
--cc=syzbot+5d8e79d323a13aa0b248@syzkaller.appspotmail.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.