linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Christian Brauner <brauner@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Jens Axboe <axboe@kernel.dk>, Christoph Hellwig <hch@lst.de>,
	Aleksa Sarai <cyphar@cyphar.com>,
	Al Viro <viro@zeniv.linux.org.uk>,
	Seth Forshee <sforshee@kernel.org>,
	linux-fsdevel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH] file: always lock position
Date: Mon, 24 Jul 2023 18:46:04 +0200	[thread overview]
Message-ID: <20230724-pyjama-papier-9e4cdf5359cb@brauner> (raw)
In-Reply-To: <CAHk-=whfJhag+iEscftpVq=dHTeL7rQopCvH+Pcs8vJHCGNvXQ@mail.gmail.com>

On Mon, Jul 24, 2023 at 08:53:32AM -0700, Linus Torvalds wrote:
> Is it too late to just fix pidfd_getfd() to duplicate the 'struct
> file', and act like a new open, and act like /proc/<pid>/fd/<xyz>?

So thinking a little about it I think that doesn't work.
/proc/<pid>/fd/<xyz> does a reopen and for good reasons. The original
open will have gone through the module's/subsytem's ->open() method
which might stash additional refcounted data in e.g., file->private_data
if we simply copy that file or sm then we risk UAFs. If we don't skip
->open() though and effectively emulate /proc/<pid>/fd/<xyz> completely
then we break any such use-cases where a socket or something else is
shared as they cannot be reopened. So the module/subsystem really needs
to be informed that a new struct file is created and not simply refd.

  parent reply	other threads:[~2023-07-24 16:46 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-07-24 15:00 [PATCH] file: always lock position Christian Brauner
2023-07-24 15:53 ` Linus Torvalds
2023-07-24 16:19   ` Christian Brauner
2023-07-24 16:36     ` Linus Torvalds
2023-07-24 16:51       ` Linus Torvalds
2023-09-02  4:44         ` Al Viro
2023-07-24 17:23       ` Christian Brauner
2023-07-24 17:34         ` Linus Torvalds
2023-07-24 17:46           ` Christian Brauner
2023-07-24 18:01             ` Linus Torvalds
2023-07-24 18:05               ` Jens Axboe
2023-07-24 18:27                 ` Linus Torvalds
2023-07-24 18:48                   ` Christian Brauner
2023-07-24 22:25                     ` Linus Torvalds
2023-07-24 22:56                       ` Jens Axboe
2023-07-25 18:30                         ` Linus Torvalds
2023-07-25 20:41                           ` Jens Axboe
2023-07-25 20:51                             ` Linus Torvalds
2023-07-25 20:58                               ` Jens Axboe
2023-07-26  8:36                               ` Christian Brauner
2023-07-26 10:31                                 ` David Laight
2023-07-26 12:53                                   ` Christian Brauner
2023-07-26  8:07                           ` Christian Brauner
2023-07-24 16:46   ` Christian Brauner [this message]
2023-07-24 16:59     ` Linus Torvalds
2023-07-24 17:18       ` Linus Torvalds
2023-08-03  9:53       ` Mateusz Guzik
2023-08-03 14:15         ` Christian Brauner
2023-08-03 15:17           ` Mateusz Guzik
2023-08-03 15:18             ` Mateusz Guzik
2023-08-03 15:45         ` Linus Torvalds
2023-08-03 17:54           ` Mateusz Guzik
2023-08-03 18:02           ` Christian Brauner
2023-08-03 18:35             ` Linus Torvalds
2023-08-04 13:43               ` Christian Brauner
2023-08-04 13:59                 ` Christoph Hellwig
2023-09-02  3:43               ` Al Viro
     [not found] <20230804-turnverein-helfer-ef07a4d7bbec@brauner>
2023-08-05 11:46 ` Christian Brauner
2023-08-05 18:47   ` Linus Torvalds
2023-08-05 19:46     ` Linus Torvalds
2023-08-06  6:10       ` Christian Brauner
2023-08-06 13:25         ` Christian Brauner
2023-08-06 17:48           ` Linus Torvalds

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230724-pyjama-papier-9e4cdf5359cb@brauner \
    --to=brauner@kernel.org \
    --cc=axboe@kernel.dk \
    --cc=cyphar@cyphar.com \
    --cc=hch@lst.de \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=sforshee@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).