mirror of
https://github.com/linux-msm/laptops-kernel.git
synced 2026-08-13 14:19:53 -07:00
create_use_gss_proxy_proc_entry() publishes /proc/net/rpc/use-gss-proxy
via proc_create_data() before init_gssp_clnt() runs mutex_init() on
sn->gssp_lock. Once the dentry is linked under proc_subdir_lock it is
immediately reachable from userspace, so a write that lands in the
window drives set_gssp_clnt() into mutex_lock() on a zero-initialized
struct mutex.
create_use_gss_proxy_proc_entry(net)
proc_create_data("use-gss-proxy", ...) /* dentry live */
init_gssp_clnt(sn)
mutex_init(&sn->gssp_lock) /* too late */
write_gssp()
set_gssp_clnt(net)
mutex_lock(&sn->gssp_lock) /* uninitialized */
gssp_rpc_create(...)
sn->gssp_clnt = clnt
mutex_unlock(&sn->gssp_lock)
The window spans only the two statements between proc_create_data()
returning and init_gssp_clnt(), so a writer reaches it only if the
registering thread is preempted there while another task is already
opening the freshly published file. register_pernet_subsys() runs in
preemptible context under pernet_ops_rwsem, so that preemption is
possible, and the window widens on auth_rpcgss module load, when the
proc entry is created for every live net namespace whose tasks are
already running. A writer that wins the race locks a zero-filled
struct mutex. On CONFIG_DEBUG_MUTEXES the missing magic value trips a
"lock used without init" splat; on a production kernel the fast path
acquires the lock via CMPXCHG(owner, 0, current). In the latter case
a second writer that arrives before init_gssp_clnt() re-zeroes owner
can enter set_gssp_clnt() concurrently, shut down the first writer's
clnt while it is still in use, and leak the loser's clnt.
Fix by initializing sn->gssp_lock in sunrpc_init_net() so its lifetime
matches the sunrpc_net it lives in. sn->gssp_clnt is already NULL from
the kzalloc that backs net_generic storage, so the lazy helper is no
longer needed; drop init_gssp_clnt(), its prototype, and the call from
create_use_gss_proxy_proc_entry(). sunrpc.ko is a build-time
dependency of auth_rpcgss.ko, so sunrpc_init_net() has always run on
every netns before any auth_gss pernet init can publish the proc
entry.
Fixes: 030d794bf4 ("SUNRPC: Use gssproxy upcall for server RPCGSS authentication.")
Cc: stable@vger.kernel.org
Assisted-by: kres:claude-opus-4-7
Signed-off-by: Chris Mason <clm@meta.com>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260530-tier2-local-v2-1-5a0fd532db57@oracle.com
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
166 lines
3.3 KiB
C
166 lines
3.3 KiB
C
// SPDX-License-Identifier: GPL-2.0-only
|
|
/*
|
|
* linux/net/sunrpc/sunrpc_syms.c
|
|
*
|
|
* Symbols exported by the sunrpc module.
|
|
*
|
|
* Copyright (C) 1997 Olaf Kirch <okir@monad.swb.de>
|
|
*/
|
|
|
|
#include <linux/module.h>
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/uio.h>
|
|
#include <linux/unistd.h>
|
|
#include <linux/init.h>
|
|
|
|
#include <linux/sunrpc/sched.h>
|
|
#include <linux/sunrpc/clnt.h>
|
|
#include <linux/sunrpc/svc.h>
|
|
#include <linux/sunrpc/svcsock.h>
|
|
#include <linux/sunrpc/auth.h>
|
|
#include <linux/workqueue.h>
|
|
#include <linux/sunrpc/rpc_pipe_fs.h>
|
|
#include <linux/sunrpc/xprtsock.h>
|
|
|
|
#include <net/genetlink.h>
|
|
|
|
#include "sunrpc.h"
|
|
#include "sysfs.h"
|
|
#include "netns.h"
|
|
#include "netlink.h"
|
|
|
|
unsigned int sunrpc_net_id;
|
|
EXPORT_SYMBOL_GPL(sunrpc_net_id);
|
|
|
|
static __net_init int sunrpc_init_net(struct net *net)
|
|
{
|
|
int err;
|
|
struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
|
|
|
|
err = rpc_proc_init(net);
|
|
if (err)
|
|
goto err_proc;
|
|
|
|
err = ip_map_cache_create(net);
|
|
if (err)
|
|
goto err_ipmap;
|
|
|
|
err = unix_gid_cache_create(net);
|
|
if (err)
|
|
goto err_unixgid;
|
|
|
|
err = rpc_pipefs_init_net(net);
|
|
if (err)
|
|
goto err_pipefs;
|
|
|
|
INIT_LIST_HEAD(&sn->all_clients);
|
|
spin_lock_init(&sn->rpc_client_lock);
|
|
spin_lock_init(&sn->rpcb_clnt_lock);
|
|
mutex_init(&sn->gssp_lock);
|
|
return 0;
|
|
|
|
err_pipefs:
|
|
unix_gid_cache_destroy(net);
|
|
err_unixgid:
|
|
ip_map_cache_destroy(net);
|
|
err_ipmap:
|
|
rpc_proc_exit(net);
|
|
err_proc:
|
|
return err;
|
|
}
|
|
|
|
static __net_exit void sunrpc_exit_net(struct net *net)
|
|
{
|
|
struct sunrpc_net *sn = net_generic(net, sunrpc_net_id);
|
|
|
|
rpc_pipefs_exit_net(net);
|
|
unix_gid_cache_destroy(net);
|
|
ip_map_cache_destroy(net);
|
|
rpc_proc_exit(net);
|
|
WARN_ON_ONCE(!list_empty(&sn->all_clients));
|
|
}
|
|
|
|
static struct pernet_operations sunrpc_net_ops = {
|
|
.init = sunrpc_init_net,
|
|
.exit = sunrpc_exit_net,
|
|
.id = &sunrpc_net_id,
|
|
.size = sizeof(struct sunrpc_net),
|
|
};
|
|
|
|
static int __init
|
|
init_sunrpc(void)
|
|
{
|
|
int err = rpc_init_mempool();
|
|
if (err)
|
|
goto out;
|
|
err = rpcauth_init_module();
|
|
if (err)
|
|
goto out2;
|
|
|
|
cache_initialize();
|
|
|
|
err = register_pernet_subsys(&sunrpc_net_ops);
|
|
if (err)
|
|
goto out3;
|
|
|
|
err = register_rpc_pipefs();
|
|
if (err)
|
|
goto out4;
|
|
|
|
err = rpc_sysfs_init();
|
|
if (err)
|
|
goto out5;
|
|
|
|
err = genl_register_family(&sunrpc_nl_family);
|
|
if (err)
|
|
goto out6;
|
|
|
|
sunrpc_debugfs_init();
|
|
#if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
|
|
rpc_register_sysctl();
|
|
#endif
|
|
svc_init_xprt_sock(); /* svc sock transport */
|
|
init_socket_xprt(); /* clnt sock transport */
|
|
return 0;
|
|
|
|
out6:
|
|
rpc_sysfs_exit();
|
|
out5:
|
|
unregister_rpc_pipefs();
|
|
out4:
|
|
unregister_pernet_subsys(&sunrpc_net_ops);
|
|
out3:
|
|
rpcauth_remove_module();
|
|
out2:
|
|
rpc_destroy_mempool();
|
|
out:
|
|
return err;
|
|
}
|
|
|
|
static void __exit
|
|
cleanup_sunrpc(void)
|
|
{
|
|
genl_unregister_family(&sunrpc_nl_family);
|
|
rpc_sysfs_exit();
|
|
rpc_cleanup_clids();
|
|
xprt_cleanup_ids();
|
|
xprt_multipath_cleanup_ids();
|
|
rpcauth_remove_module();
|
|
cleanup_socket_xprt();
|
|
svc_cleanup_xprt_sock();
|
|
sunrpc_debugfs_exit();
|
|
unregister_rpc_pipefs();
|
|
rpc_destroy_mempool();
|
|
unregister_pernet_subsys(&sunrpc_net_ops);
|
|
auth_domain_cleanup();
|
|
#if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
|
|
rpc_unregister_sysctl();
|
|
#endif
|
|
rcu_barrier(); /* Wait for completion of call_rcu()'s */
|
|
}
|
|
MODULE_DESCRIPTION("Sun RPC core");
|
|
MODULE_LICENSE("GPL");
|
|
fs_initcall(init_sunrpc); /* Ensure we're initialised before nfs */
|
|
module_exit(cleanup_sunrpc);
|