public inbox for linux-bcache@vger.kernel.org
 help / color / mirror / Atom feed
From: Coly Li <colyli@suse.de>
To: Stefan Priebe - Profihost AG <s.priebe@profihost.ag>
Cc: linux-bcache@vger.kernel.org, linux-block@vger.kernel.org,
	stable@vger.kernel.org, Kai Krakow <kai@kaishome.de>
Subject: Re: [PATCH] bcache: fix 0day error of setting writeback_rate by sysfs interface
Date: Sat, 11 Aug 2018 12:46:52 +0800	[thread overview]
Message-ID: <f39381fc-cb31-2979-84fa-7cc264942842@suse.de> (raw)
In-Reply-To: <16e6c566-5f4d-0d52-3c6e-aa2815baff29@profihost.ag>

On 2018/8/11 2:13 AM, Stefan Priebe - Profihost AG wrote:
> Thanks for cc. How is this exploitable? I mean only root can write to
> sysfs? Or do you mean by allowing a user via sudo to write to that entry?

Hi Stefan,

This is not a security 0day bug, this is an error reported by Linux
kernel 0day test service
(https://01.org/zh/lkp/documentation/0-day-test-service). My development
tree is registered and monitored by 0day testing service, so if there is
any static code error or boot failure, I can be noticed in very early stage.

The bug in previous patch is, writeback_rate cannot be set by sysfs
interface, because sysfs_strtoul_clamp() directly returns. This patch
fixes this and allows writeback_rate can be manually set again.

Coly Li

> 
> Am 10.08.2018 um 17:45 schrieb Coly Li:
>> Commit ea8c5356d390 ("bcache: set max writeback rate when I/O request
>> is idle") changes struct bch_ratelimit member rate from uint32_t to
>> atomic_long_t and uses atomic_long_set() in drivers/md/bcache/sysfs.c
>> to set new writeback rate, after the input is converted from memory
>> buf to long int by sysfs_strtoul_clamp().
>>
>> The above change has a problem because there is an implicit return
>> inside sysfs_strtoul_clamp() so the following atomic_long_set()
>> won't be called. This error is detected by 0day system with following
>> snipped smatch warnings:
>>
>> drivers/md/bcache/sysfs.c:271 __cached_dev_store() error: uninitialized
>> symbol 'v'.
>> 270  sysfs_strtoul_clamp(writeback_rate, v, 1, INT_MAX);
>>      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>> @271 atomic_long_set(&dc->writeback_rate.rate, v);
>>
>> This patch fixes the above error by using strtoul_safe_clamp() to
>> convert the input buffer into a long int type result.
>>
>> Fixes: Commit ea8c5356d390 ("bcache: set max writeback rate when I/O request is idle")
>> Signed-off-by: Coly Li <colyli@suse.de>
>> Cc: stable@vger.kernel.org #4.16+
>> Cc: Kai Krakow <kai@kaishome.de>
>> Cc: Stefan Priebe <s.priebe@profihost.ag>
>> ---
>>  drivers/md/bcache/sysfs.c | 13 ++++++++++---
>>  1 file changed, 10 insertions(+), 3 deletions(-)
>>
>> diff --git a/drivers/md/bcache/sysfs.c b/drivers/md/bcache/sysfs.c
>> index 543b06408321..150cf4f4cf74 100644
>> --- a/drivers/md/bcache/sysfs.c
>> +++ b/drivers/md/bcache/sysfs.c
>> @@ -267,10 +267,17 @@ STORE(__cached_dev)
>>  	sysfs_strtoul_clamp(writeback_percent, dc->writeback_percent, 0, 40);
>>  
>>  	if (attr == &sysfs_writeback_rate) {
>> -		int v;
>> +		ssize_t ret;
>> +		long int v = atomic_long_read(&dc->writeback_rate.rate);
>> +
>> +		ret = strtoul_safe_clamp(buf, v, 1, INT_MAX);
>>  
>> -		sysfs_strtoul_clamp(writeback_rate, v, 1, INT_MAX);
>> -		atomic_long_set(&dc->writeback_rate.rate, v);
>> +		if (!ret) {
>> +			atomic_long_set(&dc->writeback_rate.rate, v);
>> +			ret = size;
>> +		}
>> +
>> +		return ret;
>>  	}
>>  
>>  	sysfs_strtoul_clamp(writeback_rate_update_seconds,
>>

      reply	other threads:[~2018-08-11  4:46 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-08-10 15:45 [PATCH] bcache: fix 0day error of setting writeback_rate by sysfs interface Coly Li
2018-08-10 18:13 ` Stefan Priebe - Profihost AG
2018-08-11  4:46   ` Coly Li [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f39381fc-cb31-2979-84fa-7cc264942842@suse.de \
    --to=colyli@suse.de \
    --cc=kai@kaishome.de \
    --cc=linux-bcache@vger.kernel.org \
    --cc=linux-block@vger.kernel.org \
    --cc=s.priebe@profihost.ag \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox