* [PATCH] block: drop "sending ioctl to a partition" message
@ 2017-09-21 14:49 Paolo Bonzini
2017-09-21 14:53 ` Christoph Hellwig
2017-10-03 16:22 ` Paolo Bonzini
0 siblings, 2 replies; 5+ messages in thread
From: Paolo Bonzini @ 2017-09-21 14:49 UTC (permalink / raw)
To: linux-kernel, kvm; +Cc: axboe, linux-block
After the first few months, the message has not led to many bug reports.
It's been almost five years now, and in practice the main source of
it seems to be MTIOCGET that someone is using to detect tape devices.
While we could whitelist it just like CDROM_GET_CAPABILITY, this patch
just removes the message altogether.
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
block/scsi_ioctl.c | 18 ++----------------
1 file changed, 2 insertions(+), 16 deletions(-)
diff --git a/block/scsi_ioctl.c b/block/scsi_ioctl.c
index 7440de44dd85..eafcd67e2480 100644
--- a/block/scsi_ioctl.c
+++ b/block/scsi_ioctl.c
@@ -707,24 +707,10 @@ int scsi_verify_blk_ioctl(struct block_device *bd, unsigned int cmd)
case SG_SET_RESERVED_SIZE:
case SG_EMULATED_HOST:
return 0;
- case CDROM_GET_CAPABILITY:
- /* Keep this until we remove the printk below. udev sends it
- * and we do not want to spam dmesg about it. CD-ROMs do
- * not have partitions, so we get here only for disks.
- */
- return -ENOIOCTLCMD;
default:
- break;
+ /* In particular, rule out all resets and host-specific ioctls. */
+ return capable(CAP_SYS_RAWIO) ? 0 : -ENOIOCTLCMD;
}
-
- if (capable(CAP_SYS_RAWIO))
- return 0;
-
- /* In particular, rule out all resets and host-specific ioctls. */
- printk_ratelimited(KERN_WARNING
- "%s: sending ioctl %x to a partition!\n", current->comm, cmd);
-
- return -ENOIOCTLCMD;
}
EXPORT_SYMBOL(scsi_verify_blk_ioctl);
--
1.8.3.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH] block: drop "sending ioctl to a partition" message
2017-09-21 14:49 [PATCH] block: drop "sending ioctl to a partition" message Paolo Bonzini
@ 2017-09-21 14:53 ` Christoph Hellwig
2017-09-21 14:59 ` Paolo Bonzini
2017-10-03 16:22 ` Paolo Bonzini
1 sibling, 1 reply; 5+ messages in thread
From: Christoph Hellwig @ 2017-09-21 14:53 UTC (permalink / raw)
To: Paolo Bonzini; +Cc: linux-kernel, kvm, axboe, linux-block
This looks ok to me, but do we even need to keep the special
cases above? Is there anything relying on the safe but not very
useful ioctls?
Condensing the thing down to:
int scsi_verify_blk_ioctl(struct block_device *bd, unsigned int cmd)
{
if (bd && bd == bd->bd_contains)
return 0;
if (capable(CAP_SYS_RAWIO))
return 0;
return -ENOIOCTLCMD;
}
would certainly be nice.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] block: drop "sending ioctl to a partition" message
2017-09-21 14:53 ` Christoph Hellwig
@ 2017-09-21 14:59 ` Paolo Bonzini
0 siblings, 0 replies; 5+ messages in thread
From: Paolo Bonzini @ 2017-09-21 14:59 UTC (permalink / raw)
To: Christoph Hellwig; +Cc: linux-kernel, kvm, linux-block
On 21/09/2017 16:53, Christoph Hellwig wrote:
> This looks ok to me, but do we even need to keep the special
> cases above? Is there anything relying on the safe but not very
> useful ioctls?
No idea, I stuck to the usual "don't break userspace" rule.
Honestly I doubt anything is using most of those ioctls _in general_,
not just on a partition.
Paolo
> Condensing the thing down to:
>
> int scsi_verify_blk_ioctl(struct block_device *bd, unsigned int cmd)
> {
> if (bd && bd == bd->bd_contains)
> return 0;
> if (capable(CAP_SYS_RAWIO))
> return 0;
> return -ENOIOCTLCMD;
> }
>
> would certainly be nice.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] block: drop "sending ioctl to a partition" message
2017-09-21 14:49 [PATCH] block: drop "sending ioctl to a partition" message Paolo Bonzini
2017-09-21 14:53 ` Christoph Hellwig
@ 2017-10-03 16:22 ` Paolo Bonzini
2017-10-04 6:25 ` Christoph Hellwig
1 sibling, 1 reply; 5+ messages in thread
From: Paolo Bonzini @ 2017-10-03 16:22 UTC (permalink / raw)
To: linux-kernel, kvm; +Cc: axboe, linux-block
On 21/09/2017 16:49, Paolo Bonzini wrote:
> After the first few months, the message has not led to many bug reports.
> It's been almost five years now, and in practice the main source of
> it seems to be MTIOCGET that someone is using to detect tape devices.
> While we could whitelist it just like CDROM_GET_CAPABILITY, this patch
> just removes the message altogether.
>
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Ping (with fixed email address for Jens)...
Paolo
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] block: drop "sending ioctl to a partition" message
2017-10-03 16:22 ` Paolo Bonzini
@ 2017-10-04 6:25 ` Christoph Hellwig
0 siblings, 0 replies; 5+ messages in thread
From: Christoph Hellwig @ 2017-10-04 6:25 UTC (permalink / raw)
To: Paolo Bonzini; +Cc: linux-kernel, kvm, axboe, linux-block
On Tue, Oct 03, 2017 at 06:22:23PM +0200, Paolo Bonzini wrote:
> On 21/09/2017 16:49, Paolo Bonzini wrote:
> > After the first few months, the message has not led to many bug reports.
> > It's been almost five years now, and in practice the main source of
> > it seems to be MTIOCGET that someone is using to detect tape devices.
> > While we could whitelist it just like CDROM_GET_CAPABILITY, this patch
> > just removes the message altogether.
> >
> > Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
>
> Ping (with fixed email address for Jens)...
How about implementing the revised version I suggested?
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2017-10-04 6:25 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-09-21 14:49 [PATCH] block: drop "sending ioctl to a partition" message Paolo Bonzini
2017-09-21 14:53 ` Christoph Hellwig
2017-09-21 14:59 ` Paolo Bonzini
2017-10-03 16:22 ` Paolo Bonzini
2017-10-04 6:25 ` Christoph Hellwig
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).