Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1591791 > unrolled thread
| Started by | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| First post | 2017-03-03 10:20 +0100 |
| Last post | 2017-03-03 17:40 +0100 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH 0/3] fs, fuse subsystem refcount conversions Elena Reshetova <elena.reshetova@intel.com> - 2017-03-03 10:20 +0100
[PATCH 3/3] fs, fuse: convert fuse_conn.count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-03-03 13:10 +0100
Re: [PATCH 0/3] fs, fuse subsystem refcount conversions Miklos Szeredi <miklos@szeredi.hu> - 2017-03-03 17:40 +0100
| From | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| Date | 2017-03-03 10:20 +0100 |
| Subject | [PATCH 0/3] fs, fuse subsystem refcount conversions |
| Message-ID | <tgRnP-7or-5@gated-at.bofh.it> |
Now when new refcount_t type and API are finally merged (see include/linux/refcount.h), the following patches convert various refcounters in the fuse filesystem from atomic_t to refcount_t. By doing this we prevent intentional or accidental underflows or overflows that can led to use-after-free vulnerabilities. The below patches are fully independent and can be cherry-picked separately. Since we convert all kernel subsystems in the same fashion, resulting in about 300 patches, we have to group them for sending at least in some fashion to be manageable. Please excuse the long cc list. These patches have been tested using tests supplied with libfuse. Not sure if this is the right way to test it. No output or failures with result to refcount conversions. refcount WARNs were on. Elena Reshetova (3): fs, fuse: convert fuse_file.count from atomic_t to refcount_t fs, fuse: convert fuse_req.count from atomic_t to refcount_t fs, fuse: convert fuse_conn.count from atomic_t to refcount_t fs/fuse/dev.c | 10 +++++----- fs/fuse/file.c | 8 ++++---- fs/fuse/fuse_i.h | 7 ++++--- fs/fuse/inode.c | 6 +++--- 4 files changed, 16 insertions(+), 15 deletions(-) -- 2.7.4
[toc] | [next] | [standalone]
| From | Elena Reshetova <elena.reshetova@intel.com> |
|---|---|
| Date | 2017-03-03 13:10 +0100 |
| Subject | [PATCH 3/3] fs, fuse: convert fuse_conn.count from atomic_t to refcount_t |
| Message-ID | <tgUc2-102-9@gated-at.bofh.it> |
| In reply to | #1591791 |
refcount_t type and corresponding API should be
used instead of atomic_t when the variable is used as
a reference counter. This allows to avoid accidental
refcounter overflows that might lead to use-after-free
situations.
Signed-off-by: Elena Reshetova <elena.reshetova@intel.com>
Signed-off-by: Hans Liljestrand <ishkamiel@gmail.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: David Windsor <dwindsor@gmail.com>
---
fs/fuse/fuse_i.h | 2 +-
fs/fuse/inode.c | 6 +++---
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
index 9d43740..6c649f0 100644
--- a/fs/fuse/fuse_i.h
+++ b/fs/fuse/fuse_i.h
@@ -449,7 +449,7 @@ struct fuse_conn {
spinlock_t lock;
/** Refcount */
- atomic_t count;
+ refcount_t count;
/** Number of fuse_dev's */
atomic_t dev_count;
diff --git a/fs/fuse/inode.c b/fs/fuse/inode.c
index 6fe6a88..3961c5f 100644
--- a/fs/fuse/inode.c
+++ b/fs/fuse/inode.c
@@ -608,7 +608,7 @@ void fuse_conn_init(struct fuse_conn *fc)
memset(fc, 0, sizeof(*fc));
spin_lock_init(&fc->lock);
init_rwsem(&fc->killsb);
- atomic_set(&fc->count, 1);
+ refcount_set(&fc->count, 1);
atomic_set(&fc->dev_count, 1);
init_waitqueue_head(&fc->blocked_waitq);
init_waitqueue_head(&fc->reserved_req_waitq);
@@ -631,7 +631,7 @@ EXPORT_SYMBOL_GPL(fuse_conn_init);
void fuse_conn_put(struct fuse_conn *fc)
{
- if (atomic_dec_and_test(&fc->count)) {
+ if (refcount_dec_and_test(&fc->count)) {
if (fc->destroy_req)
fuse_request_free(fc->destroy_req);
fc->release(fc);
@@ -641,7 +641,7 @@ EXPORT_SYMBOL_GPL(fuse_conn_put);
struct fuse_conn *fuse_conn_get(struct fuse_conn *fc)
{
- atomic_inc(&fc->count);
+ refcount_inc(&fc->count);
return fc;
}
EXPORT_SYMBOL_GPL(fuse_conn_get);
--
2.7.4
[toc] | [prev] | [next] | [standalone]
| From | Miklos Szeredi <miklos@szeredi.hu> |
|---|---|
| Date | 2017-03-03 17:40 +0100 |
| Message-ID | <tgYpj-3NK-7@gated-at.bofh.it> |
| In reply to | #1591791 |
On Fri, Mar 3, 2017 at 10:04 AM, Elena Reshetova <elena.reshetova@intel.com> wrote: > Now when new refcount_t type and API are finally merged > (see include/linux/refcount.h), the following > patches convert various refcounters in the fuse filesystem from atomic_t > to refcount_t. By doing this we prevent intentional or accidental > underflows or overflows that can led to use-after-free vulnerabilities. > > The below patches are fully independent and can be cherry-picked separately. > Since we convert all kernel subsystems in the same fashion, resulting > in about 300 patches, we have to group them for sending at least in some > fashion to be manageable. Please excuse the long cc list. > > These patches have been tested using tests supplied with libfuse. > Not sure if this is the right way to test it. No output or failures > with result to refcount conversions. refcount WARNs were on. Thanks, queued. Miklos
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web