cgroups.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Al Viro <viro-RmSDqhL/yNMiFSDQTTA3OLVCufUGDwFn@public.gmane.org>
To: Christoph Hellwig <hch-jcswGhMUV9g@public.gmane.org>
Cc: Christian Brauner
	<brauner-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>,
	Heiko Carstens <hca-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org>,
	Vasily Gorbik <gor-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org>,
	Alexander Gordeev
	<agordeev-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org>,
	Fenghua Yu <fenghua.yu-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>,
	Reinette Chatre
	<reinette.chatre-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>,
	Miquel Raynal
	<miquel.raynal-LDxbnhwyfcJBDgjK7y7TUQ@public.gmane.org>,
	Richard Weinberger <richard-/L3Ra7n9ekc@public.gmane.org>,
	Vignesh Raghavendra <vigneshr-l0cyMroinI0@public.gmane.org>,
	Dennis Dalessandro
	<dennis.dalessandro-ntyVByD3zXaTtA8H5PvdGFaTQe2KTcn/@public.gmane.org>,
	Tejun Heo <tj-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>,
	Trond Myklebust
	<trond.myklebust-F/q8l9xzQnoyLce1RVWEUA@public.gmane.org>,
	Anna Schumaker <anna-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>,
	Kees Cook <keescook-F7+t8E8rja9g9hUCZPvPmw@public.gmane.org>,
	Damien Le Moal <dlemoal-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>,
	Naohiro Aota <naohiro.aota-Sjgp3cTcYWE@public.gmane.org>,
	Greg Kroah-Hartman
	<gregkh-hQyY1W1yCW8ekmWlsbkhG0B+6BGkLq7r@public.gmane.org>,
	linux-usb-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, linux-s39
Subject: Re: [PATCH 03/19] fs: release anon dev_t in deactivate_locked_super
Date: Thu, 14 Sep 2023 00:27:12 +0100	[thread overview]
Message-ID: <20230913232712.GC800259@ZenIV> (raw)
In-Reply-To: <20230913111013.77623-4-hch-jcswGhMUV9g@public.gmane.org>

On Wed, Sep 13, 2023 at 08:09:57AM -0300, Christoph Hellwig wrote:
> Releasing an anon dev_t is a very common thing when freeing a
> super_block, as that's done for basically any not block based file
> system (modulo the odd mtd special case).  So instead of requiring
> a special ->kill_sb helper and a lot of boilerplate in more complicated
> file systems, just release the anon dev_t in deactivate_locked_super if
> the super_block was using one.
> 
> As the freeing is done after the main call to kill_super_notify, this
> removes the need for having two slightly different call sites for it.

Huh?  At this stage in your series freeing is still in ->kill_sb()
instances, after the calls of kill_anon_super() you've turned into
the calls of generic_shutdown_super().

You do split it off into a separate method later in the series, but
at this point you are reopening the same UAF that had been dealt with
in dc3216b14160 "super: ensure valid info".

Either move the introduction of ->free_sb() before that one, or
split it into lifting put_anon_bdev() (left here) and getting rid
of kill_anon_super() (after ->free_sb() introduction).

  parent reply	other threads:[~2023-09-13 23:27 UTC|newest]

Thread overview: 61+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-09-13 11:09 split up ->kill_sb Christoph Hellwig
2023-09-13 11:09 ` [PATCH 03/19] fs: release anon dev_t in deactivate_locked_super Christoph Hellwig
     [not found]   ` <20230913111013.77623-4-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 23:27     ` Al Viro [this message]
2023-09-14  2:37       ` Al Viro
2023-09-14  5:38         ` Al Viro
2023-09-14  7:56           ` Christian Brauner
2023-09-26  9:31             ` Christoph Hellwig
2023-09-26  9:31               ` Christoph Hellwig
2023-09-14 14:02           ` Christian Brauner
2023-09-14 16:58             ` Al Viro
2023-09-14 19:23               ` Al Viro
2023-09-15  7:40                 ` Christian Brauner
2023-09-15  9:44               ` Christian Brauner
2023-09-15 14:12                 ` Christian Brauner
2023-09-15 14:28                   ` Al Viro
2023-09-15 14:33                     ` Al Viro
2023-09-15 14:40                     ` Christian Brauner
2023-09-26  9:41           ` Christoph Hellwig
2023-09-26  9:41             ` Christoph Hellwig
2023-09-26  9:38       ` Christoph Hellwig
2023-09-26  9:38         ` Christoph Hellwig
2023-09-26 21:25         ` Al Viro
2023-09-27 22:29           ` Al Viro
2023-10-02  6:46           ` Christoph Hellwig
2023-10-09 21:57             ` Al Viro
2023-10-10  8:44               ` Christian Brauner
2023-10-17 19:50                 ` Al Viro
     [not found] ` <20230913111013.77623-1-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 11:09   ` [PATCH 01/19] fs: reflow deactivate_locked_super Christoph Hellwig
     [not found]     ` <20230913111013.77623-2-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 16:35       ` Christian Brauner
2023-09-26  9:24         ` Christoph Hellwig
2023-09-26  9:24           ` Christoph Hellwig
2023-09-13 11:09   ` [PATCH 02/19] fs: make ->kill_sb optional Christoph Hellwig
2023-09-13 11:09   ` [PATCH 04/19] NFS: remove the s_dev field from struct nfs_server Christoph Hellwig
2023-09-13 11:09   ` [PATCH 05/19] fs: assign an anon dev_t in common code Christoph Hellwig
     [not found]     ` <20230913111013.77623-6-hch-jcswGhMUV9g@public.gmane.org>
2023-09-14  0:34       ` Al Viro
2023-09-13 11:10   ` [PATCH 06/19] qibfs: use simple_release_fs Christoph Hellwig
     [not found]     ` <20230913111013.77623-7-hch-jcswGhMUV9g@public.gmane.org>
2023-09-18 11:41       ` Leon Romanovsky
2023-09-13 11:10   ` [PATCH 07/19] hypfs: use d_genocide to kill fs entries Christoph Hellwig
2023-09-13 11:10   ` [PATCH 08/19] pstore: shrink the pstore_sb_lock critical section in pstore_kill_sb Christoph Hellwig
     [not found]     ` <20230913111013.77623-9-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 22:07       ` Kees Cook
2023-09-13 11:10   ` [PATCH 09/19] zonefs: remove duplicate cleanup in zonefs_fill_super Christoph Hellwig
     [not found]     ` <20230913111013.77623-10-hch-jcswGhMUV9g@public.gmane.org>
2023-09-14  0:33       ` Damien Le Moal
2023-09-14  0:49       ` Al Viro
2023-09-13 11:10   ` [PATCH 10/19] USB: gadget/legacy: remove sb_mutex Christoph Hellwig
     [not found]     ` <20230913111013.77623-11-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 16:10       ` Alan Stern
     [not found]         ` <7f839be1-4898-41ad-8eda-10d5a0350bdf-nwvwT67g6+6dFdvTe/nMLpVzexx5G7lz@public.gmane.org>
2023-09-26  9:24           ` Christoph Hellwig
2023-09-26  9:24             ` Christoph Hellwig
2023-09-14 10:22     ` Sergey Shtylyov
2023-09-13 11:10   ` [PATCH 11/19] fs: add new shutdown_sb and free_sb methods Christoph Hellwig
     [not found]     ` <20230913111013.77623-12-hch-jcswGhMUV9g@public.gmane.org>
2023-09-14  2:07       ` Al Viro
2023-09-13 11:10   ` [PATCH 12/19] fs: convert kill_litter_super to litter_shutdown_sb Christoph Hellwig
     [not found]     ` <20230913111013.77623-13-hch-jcswGhMUV9g@public.gmane.org>
2023-09-13 22:07       ` Kees Cook
2023-09-13 11:10   ` [PATCH 13/19] fs: convert kill_block_super to block_free_sb Christoph Hellwig
     [not found]     ` <20230913111013.77623-14-hch-jcswGhMUV9g@public.gmane.org>
2023-09-14  2:29       ` Al Viro
2023-09-13 11:10   ` [PATCH 14/19] jffs2: convert to ->shutdown_sb and ->free_sb Christoph Hellwig
2023-09-13 11:10   ` [PATCH 15/19] kernfs: split ->kill_sb Christoph Hellwig
     [not found]     ` <20230913111013.77623-16-hch-jcswGhMUV9g@public.gmane.org>
2023-09-18 15:24       ` Michal Koutný
2023-09-13 11:10   ` [PATCH 16/19] x86/resctrl: release rdtgroup_mutex and the CPU hotplug lock in rdt_shutdown_sb Christoph Hellwig
2023-09-13 11:10   ` [PATCH 17/19] NFS: move nfs_kill_super to fs_context.c Christoph Hellwig
2023-09-13 11:10   ` [PATCH 18/19] fs: simple ->shutdown_sb and ->free_sb conversions Christoph Hellwig
2023-09-13 11:10   ` [PATCH 19/19] fs: remove ->kill_sb Christoph Hellwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230913232712.GC800259@ZenIV \
    --to=viro-rmsdqhl/ynmifsdqtta3olvcufugdwfn@public.gmane.org \
    --cc=agordeev-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org \
    --cc=anna-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org \
    --cc=brauner-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org \
    --cc=dennis.dalessandro-ntyVByD3zXaTtA8H5PvdGFaTQe2KTcn/@public.gmane.org \
    --cc=dlemoal-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org \
    --cc=fenghua.yu-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org \
    --cc=gor-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org \
    --cc=gregkh-hQyY1W1yCW8ekmWlsbkhG0B+6BGkLq7r@public.gmane.org \
    --cc=hca-tEXmvtCZX7AybS5Ee8rs3A@public.gmane.org \
    --cc=hch-jcswGhMUV9g@public.gmane.org \
    --cc=keescook-F7+t8E8rja9g9hUCZPvPmw@public.gmane.org \
    --cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=linux-usb-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=miquel.raynal-LDxbnhwyfcJBDgjK7y7TUQ@public.gmane.org \
    --cc=naohiro.aota-Sjgp3cTcYWE@public.gmane.org \
    --cc=reinette.chatre-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org \
    --cc=richard-/L3Ra7n9ekc@public.gmane.org \
    --cc=tj-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org \
    --cc=trond.myklebust-F/q8l9xzQnoyLce1RVWEUA@public.gmane.org \
    --cc=vigneshr-l0cyMroinI0@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).