No description
  • C 96.9%
  • Assembly 0.9%
  • Rust 0.6%
  • Shell 0.6%
  • Python 0.5%
  • Other 0.3%
Find a file
Eric Biggers d30f7b3fa0 ext4: fix race conditions in ->d_compare() and ->d_hash()
commit ec772f0130 upstream.

Since ->d_compare() and ->d_hash() can be called in RCU-walk mode,
->d_parent and ->d_inode can be concurrently modified, and in
particular, ->d_inode may be changed to NULL.  For ext4_d_hash() this
resulted in a reproducible NULL dereference if a lookup is done in a
directory being deleted, e.g. with:

	int main()
	{
		if (fork()) {
			for (;;) {
				mkdir("subdir", 0700);
				rmdir("subdir");
			}
		} else {
			for (;;)
				access("subdir/file", 0);
		}
	}

... or by running the 't_encrypted_d_revalidate' program from xfstests.
Both repros work in any directory on a filesystem with the encoding
feature, even if the directory doesn't actually have the casefold flag.

I couldn't reproduce a crash in ext4_d_compare(), but it appears that a
similar crash is possible there.

Fix these bugs by reading ->d_parent and ->d_inode using READ_ONCE() and
falling back to the case sensitive behavior if the inode is NULL.

Reported-by: Al Viro <viro@zeniv.linux.org.uk>
Fixes: b886ee3e77 ("ext4: Support case-insensitive file name lookups")
Cc: <stable@vger.kernel.org> # v5.2+
Signed-off-by: Eric Biggers <ebiggers@google.com>
Link: https://lore.kernel.org/r/20200124041234.159740-1-ebiggers@kernel.org
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
History 2020-02-11 04:37:02 -08:00
arch powerpc/futex: Fix incorrect user access blocking 2020-02-11 04:37:02 -08:00
block block: allow partitions on host aware zone devices 2020-01-26 09:59:08 -07:00
certs certs: Add wrapper function to check blacklisted binary hash 2019-11-12 12:25:50 +11:00
crypto crypto: api - Fix race condition in crypto_spawn_alg 2020-02-11 04:37:01 -08:00
Documentation PM / devfreq: Add new name attribute for sysfs 2020-02-04 18:18:01 +00:00
drivers scsi: qla2xxx: Fix unbound NVME response length 2020-02-11 04:37:02 -08:00
fs ext4: fix race conditions in ->d_compare() and ->d_hash() 2020-02-11 04:37:02 -08:00
include crypto: pcrypt - Avoid deadlock by using per-instance padata queues 2020-02-11 04:36:58 -08:00
init Revert "um: Enable CONFIG_CONSTRUCTORS" 2020-02-01 09:33:00 +00:00
ipc ipc/msg.c: consolidate all xxxctl_down() functions 2020-02-11 04:36:39 -08:00
kernel bpf, devmap: Pass lockdep expression to RCU lists 2020-02-11 04:36:59 -08:00
lib lib/test_kasan.c: fix memory leak in kmalloc_oob_krealloc_more() 2020-02-11 04:36:45 -08:00
LICENSES LICENSES: Rename other to deprecated 2019-05-03 06:34:32 -06:00
mm mm: move_pages: report the number of non-attempted pages 2020-02-11 04:36:44 -08:00
net flow_dissector: Fix to use new variables for port ranges in bpf hook 2020-02-11 04:36:59 -08:00
samples samples/bpf: Reintroduce missed build targets 2020-02-11 04:37:00 -08:00
scripts scripts/find-unused-docs: Fix massive false positives 2020-02-11 04:36:53 -08:00
security tomoyo: Use atomic_t for statistics counter 2020-02-04 18:18:02 +00:00
sound ASoC: SOF: core: release resources on errors in probe_continue 2020-02-11 04:36:57 -08:00
tools selftests: bpf: Ignore FIN packets for reuseport tests 2020-02-11 04:37:00 -08:00
usr gen_initramfs_list.sh: fix 'bad variable name' error 2020-01-04 00:00:48 +09:00
virt KVM: arm64: Only sign-extend MMIO up to register width 2020-02-11 04:36:47 -08:00
.clang-format clang-format: Update with the latest for_each macro list 2019-08-31 10:00:51 +02:00
.cocciconfig scripts: add Linux .cocciconfig for coccinelle 2016-07-22 12:13:39 +02:00
.get_maintainer.ignore Opt out of scripts/get_maintainer.pl 2019-05-16 10:53:40 -07:00
.gitattributes .gitattributes: use 'dts' diff driver for dts files 2019-12-04 19:44:11 -08:00
.gitignore modpost: dump missing namespaces into a single modules.nsdeps file 2019-11-11 20:10:01 +09:00
.mailmap MAINTAINERS: update my email address 2020-01-11 14:33:39 -08:00
COPYING COPYING: use the new text with points to the license files 2018-03-23 12:41:45 -06:00
CREDITS Linux 5.4-rc4 2019-10-29 04:43:29 -06:00
Kbuild kbuild: do not descend to ./Kbuild when cleaning 2019-08-21 21:03:58 +09:00
Kconfig docs: kbuild: convert docs to ReST and rename to *.rst 2019-06-14 14:21:21 -06:00
MAINTAINERS MAINTAINERS: correct entries for ISDN/mISDN section 2020-02-11 04:36:38 -08:00
Makefile Linux 5.5.2 2020-02-04 18:18:03 +00:00
README Drop all 00-INDEX files from Documentation/ 2018-09-09 15:08:58 -06:00

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.