linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-fsdevel@vger.kernel.org, linux-xfs@vger.kernel.org,
	david@fromorbit.com, linux-kernel@vger.kernel.org,
	sandeen@sandeen.net, hch@lst.de
Subject: [GIT PULL] xfs: legacy Irix ioctl housecleaning for 5.17-rc1, part 1
Date: Thu, 20 Jan 2022 10:45:53 -0800	[thread overview]
Message-ID: <20220120184553.GO13540@magnolia> (raw)

Hi Linus,

This is the second of a series of small pull requests that perform some
long overdue housecleaning of XFS ioctls.  This time, we're vacating the
implementation of all variants of the ALLOCSP and FREESP ioctls, which
are holdovers from EFS in Irix, circa 1993.  Roughly equivalent
functionality have been available for both ioctls since 2.6.25 (April
2008):

XFS_IOC_FREESP ftruncates a file.

XFS_IOC_ALLOCSP is the equivalent of fallocate.

As noted in the fix patch for CVE 2021-4155, the ALLOCSP ioctl has been
serving up stale disk blocks since 2000, and in 21 years **nobody**
noticed.  On those grounds I think it's safe to vacate the
implementation.

Note that we lose the ability to preallocate and truncate relative to
the current file position, but as nobody's ever implemented that for the
VFS, I conclude that it's not in high demand.

As usual, I did a test-merge with upstream master as of a few minutes
ago.  There's a single merge conflict due to the fixpatch that we merged
right before 5.16 that can be resolved by deleting the function.  Please
let me know if you encounter any problems.

--D

The following changes since commit 9dec0368b9640c09ef5af48214e097245e57a204:

  xfs: remove the XFS_IOC_FSSETDM definitions (2022-01-17 09:16:40 -0800)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/fs/xfs/xfs-linux.git tags/xfs-5.17-merge-5

for you to fetch changes up to 4d1b97f9ce7c0d2af2bb85b12d48e6902172a28e:

  xfs: kill the XFS_IOC_{ALLOC,FREE}SP* ioctls (2022-01-17 09:16:41 -0800)

----------------------------------------------------------------
Remove the XFS_IOC_ALLOCSP* and XFS_IOC_FREESP* ioctl families.

Linux has always used fallocate as the space management system call,
whereas these Irix legacy ioctls only ever worked on XFS, and have been
the cause of recent stale data disclosure vulnerabilities.  As
equivalent functionality is available elsewhere, remove the code.

----------------------------------------------------------------
Darrick J. Wong (1):
      xfs: kill the XFS_IOC_{ALLOC,FREE}SP* ioctls

 fs/xfs/xfs_bmap_util.c |  7 ++--
 fs/xfs/xfs_bmap_util.h |  2 +-
 fs/xfs/xfs_file.c      |  3 +-
 fs/xfs/xfs_ioctl.c     | 92 +++-----------------------------------------------
 fs/xfs/xfs_ioctl.h     |  6 ----
 fs/xfs/xfs_ioctl32.c   | 27 ---------------
 6 files changed, 10 insertions(+), 127 deletions(-)

             reply	other threads:[~2022-01-20 18:46 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-01-20 18:45 Darrick J. Wong [this message]
2022-01-21  6:56 ` [GIT PULL] xfs: legacy Irix ioctl housecleaning for 5.17-rc1, part 1 pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20220120184553.GO13540@magnolia \
    --to=djwong@kernel.org \
    --cc=david@fromorbit.com \
    --cc=hch@lst.de \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    --cc=sandeen@sandeen.net \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).