Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1591791 > unrolled thread

[PATCH 0/3] fs, fuse subsystem refcount conversions

Started byElena Reshetova <elena.reshetova@intel.com>
First post2017-03-03 10:20 +0100
Last post2017-03-03 17:40 +0100
Articles 3 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 0/3] fs, fuse subsystem refcount conversions Elena Reshetova <elena.reshetova@intel.com> - 2017-03-03 10:20 +0100
    [PATCH 3/3] fs, fuse: convert fuse_conn.count from atomic_t to refcount_t Elena Reshetova <elena.reshetova@intel.com> - 2017-03-03 13:10 +0100
    Re: [PATCH 0/3] fs, fuse subsystem refcount conversions Miklos Szeredi <miklos@szeredi.hu> - 2017-03-03 17:40 +0100

#1591791 — [PATCH 0/3] fs, fuse subsystem refcount conversions

FromElena Reshetova <elena.reshetova@intel.com>
Date2017-03-03 10:20 +0100
Subject[PATCH 0/3] fs, fuse subsystem refcount conversions
Message-ID<tgRnP-7or-5@gated-at.bofh.it>
Now when new refcount_t type and API are finally merged
(see include/linux/refcount.h), the following
patches convert various refcounters in the fuse filesystem from atomic_t
to refcount_t. By doing this we prevent intentional or accidental
underflows or overflows that can led to use-after-free vulnerabilities.

The below patches are fully independent and can be cherry-picked separately.
Since we convert all kernel subsystems in the same fashion, resulting
in about 300 patches, we have to group them for sending at least in some
fashion to be manageable. Please excuse the long cc list.

These patches have been tested using tests supplied with libfuse.
Not sure if this is the right way to test it. No output or failures
with result to refcount conversions. refcount WARNs were on.


Elena Reshetova (3):
  fs, fuse: convert fuse_file.count from atomic_t to refcount_t
  fs, fuse: convert fuse_req.count from atomic_t to refcount_t
  fs, fuse: convert fuse_conn.count from atomic_t to refcount_t

 fs/fuse/dev.c    | 10 +++++-----
 fs/fuse/file.c   |  8 ++++----
 fs/fuse/fuse_i.h |  7 ++++---
 fs/fuse/inode.c  |  6 +++---
 4 files changed, 16 insertions(+), 15 deletions(-)

-- 
2.7.4

[toc] | [next] | [standalone]


#1591899 — [PATCH 3/3] fs, fuse: convert fuse_conn.count from atomic_t to refcount_t

FromElena Reshetova <elena.reshetova@intel.com>
Date2017-03-03 13:10 +0100
Subject[PATCH 3/3] fs, fuse: convert fuse_conn.count from atomic_t to refcount_t
Message-ID<tgUc2-102-9@gated-at.bofh.it>
In reply to#1591791
refcount_t type and corresponding API should be
used instead of atomic_t when the variable is used as
a reference counter. This allows to avoid accidental
refcounter overflows that might lead to use-after-free
situations.

Signed-off-by: Elena Reshetova <elena.reshetova@intel.com>
Signed-off-by: Hans Liljestrand <ishkamiel@gmail.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: David Windsor <dwindsor@gmail.com>
---
 fs/fuse/fuse_i.h | 2 +-
 fs/fuse/inode.c  | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
index 9d43740..6c649f0 100644
--- a/fs/fuse/fuse_i.h
+++ b/fs/fuse/fuse_i.h
@@ -449,7 +449,7 @@ struct fuse_conn {
 	spinlock_t lock;
 
 	/** Refcount */
-	atomic_t count;
+	refcount_t count;
 
 	/** Number of fuse_dev's */
 	atomic_t dev_count;
diff --git a/fs/fuse/inode.c b/fs/fuse/inode.c
index 6fe6a88..3961c5f 100644
--- a/fs/fuse/inode.c
+++ b/fs/fuse/inode.c
@@ -608,7 +608,7 @@ void fuse_conn_init(struct fuse_conn *fc)
 	memset(fc, 0, sizeof(*fc));
 	spin_lock_init(&fc->lock);
 	init_rwsem(&fc->killsb);
-	atomic_set(&fc->count, 1);
+	refcount_set(&fc->count, 1);
 	atomic_set(&fc->dev_count, 1);
 	init_waitqueue_head(&fc->blocked_waitq);
 	init_waitqueue_head(&fc->reserved_req_waitq);
@@ -631,7 +631,7 @@ EXPORT_SYMBOL_GPL(fuse_conn_init);
 
 void fuse_conn_put(struct fuse_conn *fc)
 {
-	if (atomic_dec_and_test(&fc->count)) {
+	if (refcount_dec_and_test(&fc->count)) {
 		if (fc->destroy_req)
 			fuse_request_free(fc->destroy_req);
 		fc->release(fc);
@@ -641,7 +641,7 @@ EXPORT_SYMBOL_GPL(fuse_conn_put);
 
 struct fuse_conn *fuse_conn_get(struct fuse_conn *fc)
 {
-	atomic_inc(&fc->count);
+	refcount_inc(&fc->count);
 	return fc;
 }
 EXPORT_SYMBOL_GPL(fuse_conn_get);
-- 
2.7.4

[toc] | [prev] | [next] | [standalone]


#1592121

FromMiklos Szeredi <miklos@szeredi.hu>
Date2017-03-03 17:40 +0100
Message-ID<tgYpj-3NK-7@gated-at.bofh.it>
In reply to#1591791
On Fri, Mar 3, 2017 at 10:04 AM, Elena Reshetova
<elena.reshetova@intel.com> wrote:
> Now when new refcount_t type and API are finally merged
> (see include/linux/refcount.h), the following
> patches convert various refcounters in the fuse filesystem from atomic_t
> to refcount_t. By doing this we prevent intentional or accidental
> underflows or overflows that can led to use-after-free vulnerabilities.
>
> The below patches are fully independent and can be cherry-picked separately.
> Since we convert all kernel subsystems in the same fashion, resulting
> in about 300 patches, we have to group them for sending at least in some
> fashion to be manageable. Please excuse the long cc list.
>
> These patches have been tested using tests supplied with libfuse.
> Not sure if this is the right way to test it. No output or failures
> with result to refcount conversions. refcount WARNs were on.

Thanks, queued.

Miklos

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web