From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.6 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED,USER_AGENT_MUTT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id BAB74C43613 for ; Sun, 23 Jun 2019 01:03:49 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 8333820679 for ; Sun, 23 Jun 2019 01:03:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1561251829; bh=cuwbYT8yBxuJ7pc8Ea2TdAptwyRjgPT1ZamHNhYYwwY=; h=Date:From:To:Cc:Subject:References:In-Reply-To:List-ID:From; b=QD4AJo7a/PYw+g2RjAhNa71mhPh5RHZ5mVT0okrDvBe3RgG0Lis7wufmUSPGI7jSF SI9jgFhHTFa2xeHZ5GWnrXdH8FsfLxouGkvjaj/FvfnM6rLUpDWCgLEz1t1qMQc/H5 rKRqkFNv8RpAvWPxYl9Da6xnlsQZE+jXwjlBUi/k= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726423AbfFWBDr (ORCPT ); Sat, 22 Jun 2019 21:03:47 -0400 Received: from mail.kernel.org ([198.145.29.99]:34738 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725844AbfFWBDr (ORCPT ); Sat, 22 Jun 2019 21:03:47 -0400 Received: from localhost (c-73-47-72-35.hsd1.nh.comcast.net [73.47.72.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 53A472084E; Sun, 23 Jun 2019 01:03:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1561251826; bh=cuwbYT8yBxuJ7pc8Ea2TdAptwyRjgPT1ZamHNhYYwwY=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=L24R2DEIfBcLEreg0U/G/Lx1iIAeodxZVKSaG8Buhh+Tw5gs6J2YYM+/Qpg3Wzzpr KDlru/GoMdrz2sKvUXqDatA4IDugkDGxvbPXltjeDO+jZD5kVgdMwdNiUmrHdzeuhr gt+yMvMrV7DMEsw3iDbYPE4UQ714s2dnp9IlNeH4= Date: Sat, 22 Jun 2019 21:03:45 -0400 From: Sasha Levin To: Amir Goldstein Cc: Greg KH , Miklos Szeredi , stable , overlayfs Subject: Re: FAILED: patch "[PATCH] ovl: support the FS_IOC_FS[SG]ETXATTR ioctls" failed to apply to 5.1-stable tree Message-ID: <20190623010345.GJ2226@sasha-vm> References: <1560073529193139@kroah.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.10.1 (2018-07-13) Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org On Fri, Jun 21, 2019 at 11:15:47AM +0300, Amir Goldstein wrote: >On Thu, Jun 13, 2019 at 11:49 AM Amir Goldstein wrote: >> >> On Sun, Jun 9, 2019 at 12:45 PM wrote: >> > >> > >> > The patch below does not apply to the 5.1-stable tree. >> > If someone wants it applied there, or to any other stable or longterm >> > tree, then please email the backport, including the original git commit >> > id to . >> > >> > thanks, >> > >> > greg k-h >> > >> >> FYI, the failure to apply this patch would be resolved after you >> picked up "ovl: check the capability before cred overridden" for >> stable, please hold off from taking this patch just yet, because >> it has a bug, whose fix wasn't picked upstream yet. >> > >Greg, > >Please apply these patches to stable 4.19. >They fix a docker regression (project quotas feature). > >b21d9c435f93 ovl: support the FS_IOC_FS[SG]ETXATTR ioctls >941d935ac763 ovl: fix wrong flags check in FS_IOC_FS[SG]ETXATTR ioctls > >They apply cleanly and tested on v4.19.53. I've queued these for 4.19. >While at it, I also tested that the following patches apply cleanly and solve >relevant issues on v4.19.53, but they are not clear stable candidates. > >1) /proc/locks shows incorrect ino. Only reported by xfstests (so far): >6dde1e42f497 ovl: make i_ino consistent with st_ino in more cases And this. >2) Fix output of `modinfo overlay`: >253e74833911 ovl: fix typo in MODULE_PARM_DESC But not this one. Maybe we should be including these in stable trees since the risk factor is low and it fixes something user-visible, but our current rules object this this kind of patches so I've left it out. >3) Disallow bogus layer combinations. >syzbot has started to produce repros that create bogus layer combinations. >So far it has only been able to reproduce a WARN_ON, which has already >been fixed in stable, by acf3062a7e1c ("ovl: relax WARN_ON()..."), but >other real bugs could be lurking if those setups are allowed. >We decided to detect and error on these setups on mount, to stop syzbot >(and attackers) from trying to attack overlayfs this way. >To stop syzbot from mutating this class of repros on stable kernel you >MAY apply these 3 patches, but in any case, I would wait a while to see >if more bugs are reported on master. >Although this solves a problem dating before 4.19, I have no plans >of backporting these patches further back. > >146d62e5a586 ovl: detect overlapping layers >9179c21dc6ed ovl: don't fail with disconnected lower NFS >1dac6f5b0ed2 ovl: fix bogus -Wmaybe-unitialized warning I've queued these 3 for 4.19. -- Thanks, Sasha