Linux filesystem development
 help / color / mirror / Atom feed
* Race in fs/posix_acl.c posix_acl_update_mode and related checks on inode->i_mode in kernel v6.6
@ 2024-01-18 16:30 Gabriel Ryan
  2024-01-19 15:04 ` Christian Brauner
  0 siblings, 1 reply; 3+ messages in thread
From: Gabriel Ryan @ 2024-01-18 16:30 UTC (permalink / raw)
  To: viro, Christian Brauner, jack, linux-fsdevel

We found races in the fs subsystem in kernel v6.6 using a race testing
tool we are developing based on modified KCSAN. We are reporting the
races because they appear to be a potential bug. The races occur on
inode->i_mode, which is updated in

fs/posix_acl.c:722 posix_acl_update_mode

and can race with reads in the following locations:

security/selinux/hooks.c:3087 selinux_inode_permission
include/linux/fsnotify.h:65 fsnotify_parent
include/linux/device_cgroup.h:24 devcgroup_inode_permission
fs/open.c:923,931 do_dentry_open
fs/namei.c:342 acl_permission_check
fs/namei.c:3242 may_open


In cases where multiple threads are updating and accessing a single
inode simultaneously, it seems like this could potentially lead to
undefined behavior, if for example an access check is passed based on
one i_mode setting, and then the inode->imode is modified by another
thread.

Best,
Gabe

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2024-01-22 15:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-01-18 16:30 Race in fs/posix_acl.c posix_acl_update_mode and related checks on inode->i_mode in kernel v6.6 Gabriel Ryan
2024-01-19 15:04 ` Christian Brauner
     [not found]   ` <CALbthtcRoJ_mBRmEBUmyMDw-WPpLOyAEecpu6jj+1AFBEWrkoA@mail.gmail.com>
2024-01-22 15:10     ` Christian Brauner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox