public inbox for linux-xfs@vger.kernel.org
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: Christoph Hellwig <hch@infradead.org>
Cc: linux-xfs@vger.kernel.org
Subject: Re: [PATCH 9/9] xfs: repair obviously broken inode modes
Date: Mon, 11 Dec 2023 14:19:26 -0800	[thread overview]
Message-ID: <20231211221926.GX361584@frogsfrogsfrogs> (raw)
In-Reply-To: <ZXFhuNaLx1C8yYV+@infradead.org>

On Wed, Dec 06, 2023 at 10:10:00PM -0800, Christoph Hellwig wrote:
> I really do not thing turning an unknown mode, which means potentially
> user controlled data in regular files or symlink bodies into file system
> metadata in directories is ever a good idea.  Quite contrary, I think
> it is a security risk waiting for exploits.  So for anything that takes
> an unknown inode and turns it into a directory or block/char special
> file: NAK.

I probably shouldn't have resent this as the COVID fever set in.
Granted, I predicted (mostly correctly) that I'd still be a bit messed
in the head five days later.

block/char/special files... I guess those can just turn into zero length
regular files.

Would this NAK remain even if there were external corroborating
evidence?

For example, what if we read the dirents out of the first directory
block, seek out parent pointers in the alleged children, and confirm a
1:1 match between the alleged dirents and pptrs?  Unprivileged userspace
can certain create a regular file N that looks like a dirent block, but
it cannot create dangling pptrs back to N to trick the verification
algorithm.

(Obviously any patch implementing this will come much later in the
series)

--D

  reply	other threads:[~2023-12-11 22:19 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-12-07  2:38 [PATCHSET v28.1 0/9] xfs: online repair of inodes and forks Darrick J. Wong
2023-12-07  2:41 ` [PATCH 1/9] xfs: disable online repair quota helpers when quota not enabled Darrick J. Wong
2023-12-07  2:42 ` [PATCH 2/9] xfs: try to attach dquots to files before repairing them Darrick J. Wong
2023-12-07  2:42 ` [PATCH 3/9] xfs: add missing nrext64 inode flag check to scrub Darrick J. Wong
2023-12-07  5:31   ` Christoph Hellwig
2023-12-07  2:42 ` [PATCH 4/9] xfs: repair inode records Darrick J. Wong
2023-12-07  5:41   ` Christoph Hellwig
2023-12-11 20:04     ` Darrick J. Wong
2023-12-12  5:36       ` Christoph Hellwig
2023-12-13  1:36         ` Darrick J. Wong
2023-12-07  2:43 ` [PATCH 5/9] xfs: zap broken inode forks Darrick J. Wong
2023-12-07  6:00   ` Christoph Hellwig
2023-12-07  6:01     ` Christoph Hellwig
2023-12-07  2:43 ` [PATCH 6/9] xfs: set inode sick state flags when we zap either ondisk fork Darrick J. Wong
2023-12-07  5:58   ` Christoph Hellwig
2023-12-11 22:48     ` Darrick J. Wong
2023-12-07  2:43 ` [PATCH 7/9] xfs: abort directory parent scrub scans if we encounter a zapped directory Darrick J. Wong
2023-12-07  6:03   ` Christoph Hellwig
2023-12-11 19:19     ` Darrick J. Wong
2023-12-07  2:43 ` [PATCH 8/9] xfs: skip the rmapbt search on an empty attr fork unless we know it was zapped Darrick J. Wong
2023-12-07  6:07   ` Christoph Hellwig
2023-12-11 22:50     ` Darrick J. Wong
2023-12-07  2:44 ` [PATCH 9/9] xfs: repair obviously broken inode modes Darrick J. Wong
2023-12-07  6:10   ` Christoph Hellwig
2023-12-11 22:19     ` Darrick J. Wong [this message]
2023-12-12  5:35       ` Christoph Hellwig
2023-12-13  1:04         ` Darrick J. Wong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231211221926.GX361584@frogsfrogsfrogs \
    --to=djwong@kernel.org \
    --cc=hch@infradead.org \
    --cc=linux-xfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox