android_kernel_motorola_sm6375/fs
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Tadeusz Struk 013b7ed754 ANDROID: incremental-fs: fix mount_fs issue
Syzbot recently found a number of issues related to incremental-fs
(see bug numbers below). All have to do with the fact that incr-fs
allows mounts of the same source and target multiple times.
The correct behavior for a file system is to allow only one such
mount, and then every subsequent attempt should fail with a -EBUSY
error code. In case of the issues listed below the common pattern
is that the reproducer calls:

mount("./file0", "./file0", "incremental-fs", 0, NULL)

many times and then invokes a file operation like chmod, setxattr,
or open on the ./file0. This causes a recursive call for all the
mounted instances, which eventually causes a stack overflow and
a kernel crash:

BUG: stack guard page was hit at ffffc90000c0fff8
kernel stack overflow (double-fault): 0000 [#1] PREEMPT SMP KASAN

The reason why many mounts with the same source and target are
possible is because the incfs_mount_fs() as it is allocates a new
super_block for every call, regardless of whether a given mount already
exists or not. This happens every time the sget() function is called
with a test param equal to NULL.
The correct behavior for an FS mount implementation is to call
appropriate mount vfs call for it's type, i.e. mount_bdev() for
a block device backed FS, mount_single() for a pseudo file system,
like sysfs that is mounted in a single, well know location, or
mount_nodev() for other special purpose FS like overlayfs.
In case of incremental-fs the open coded mount logic doesn't check
for abusive mount attempts such as overlays.
To fix this issue the logic needs to be changed to pass a proper
test function to sget() call, which then checks if a super_block
for a mount instance has already been allocated and also allows
the VFS to properly verify invalid mount attempts.

Bug: 211066171
Bug: 213140206
Bug: 213215835
Bug: 211914587
Bug: 211213635
Bug: 213137376
Bug: 211161296

Signed-off-by: Tadeusz Struk <tadeusz.struk@linaro.org>
Change-Id: I66cfc3f1b5aaffb32b0845b2dad3ff26fe952e27
2022-01-21 12:04:15 -08:00
..
9p This is the 5.4.75 stable release 2020-11-05 13:27:24 +01:00
adfs
affs fs/affs: release old buffer head on error path 2021-03-04 10:26:48 +01:00
afs This is the 5.4.150 stable release 2021-10-01 14:08:40 +02:00
autofs
befs
bfs bfs: don't use WARNING: string when it's just info. 2021-01-06 14:48:39 +01:00
btrfs This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
cachefiles cachefiles: Handle readpage error correctly 2020-11-05 11:43:36 +01:00
ceph Merge 5.4.156 into android11-5.4-lts 2021-11-02 18:15:00 +01:00
cifs This is the 5.4.150 stable release 2021-10-01 14:08:40 +02:00
coda
configfs configfs: fix memleak in configfs_release_bin_file 2021-07-14 16:53:46 +02:00
cramfs
crypto This is the 5.4.145 stable release 2021-09-12 09:54:40 +02:00
debugfs debugfs: debugfs_create_file_size(): use IS_ERR to check for error 2021-10-06 15:42:35 +02:00
devpts
dlm fs: dlm: fix memory leak when fenced 2021-07-14 16:53:17 +02:00
ecryptfs This is the 5.4.122 stable release 2021-05-28 13:26:18 +02:00
efivarfs efivarfs: revert "fix memory leak in efivarfs_create()" 2020-12-02 08:49:53 +01:00
efs
erofs This is the 5.4.161 stable release 2021-11-21 15:34:05 +01:00
exportfs
ext2 This is the 5.4.152 stable release 2021-10-09 14:57:08 +02:00
ext4 This is the 5.4.161 stable release 2021-11-21 15:34:05 +01:00
f2fs Merge tag 'android11-5.4.161_r00' into android11-5.4 2022-01-21 08:26:49 +01:00
fat
freevxfs
fscache fscache: Fix cookie key hashing 2021-09-22 12:26:25 +02:00
fuse This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
gfs2 This is the 5.4.148 stable release 2021-09-25 14:41:58 +02:00
hfs This is the 5.4.137 stable release 2021-07-31 09:04:18 +02:00
hfsplus This is the 5.4.120 stable release 2021-05-19 10:41:47 +02:00
hostfs hostfs: fix memory handling in follow_link() 2021-04-14 08:24:14 +02:00
hpfs
hugetlbfs hugetlbfs: fix mount mode command line processing 2021-07-28 13:31:01 +02:00
incfs ANDROID: incremental-fs: fix mount_fs issue 2022-01-21 12:04:15 -08:00
iomap This is the 5.4.146 stable release 2021-09-15 14:01:16 +02:00
isofs isofs: Fix out of bound access for corrupted isofs image 2021-11-12 14:43:03 +01:00
jbd2 jbd2: fix up sparse warnings in checkpoint code 2020-11-18 19:20:30 +01:00
jffs2 This is the 5.4.118 stable release 2021-05-11 16:56:33 +02:00
jfs This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
kernfs This is the 5.4.59 stable release 2020-08-19 08:40:57 +02:00
lockd lockd: lockd server-side shouldn't set fl_ops 2021-09-22 12:26:34 +02:00
minix Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4" 2020-08-23 13:12:51 +02:00
nfs This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
nfs_common nfs_common: need lock during iterate through the list 2020-12-30 11:51:22 +01:00
nfsd NFSD: Keep existing listeners on portlist error 2021-10-27 09:54:25 +02:00
nilfs2 nilfs2: fix memory leak in nilfs_sysfs_delete_snapshot_group 2021-09-26 14:07:13 +02:00
nls
notify ANDROID: vfs: add d_canonical_path for stacked filesystem support 2020-10-30 10:02:25 +01:00
ntfs ntfs: fix validity check for file name attribute 2021-07-14 16:53:01 +02:00
ocfs2 This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
omfs
openpromfs
orangefs This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
overlayfs This is the 5.4.160 stable release 2021-11-17 10:19:21 +01:00
proc This is the 5.4.144 stable release 2021-09-03 10:17:46 +02:00
pstore pstore: Fix typo in compression option name 2021-03-04 10:26:45 +01:00
qnx4 qnx4: work around gcc false positive warning bug 2021-09-30 10:09:26 +02:00
qnx6
quota quota: correct error number in free_dqentry() 2021-11-17 09:48:26 +01:00
ramfs ramfs: fix nommu mmap with gaps in the page cache 2020-10-29 09:57:53 +01:00
reiserfs This is the 5.4.140 stable release 2021-08-12 14:00:44 +02:00
romfs romfs: fix uninitialized memory leak in romfs_dev_read() 2020-08-26 10:40:51 +02:00
squashfs This is the 5.4.120 stable release 2021-05-19 10:41:47 +02:00
sysfs ANDROID: GKI: hack up fs/sysfs/file.c to prevent GENKSYMS change 2021-03-08 10:09:14 +01:00
sysv
tracefs tracefs: Have tracefs directories not set OTH permission bits by default 2021-11-17 09:48:30 +01:00
ubifs This is the 5.4.145 stable release 2021-09-12 09:54:40 +02:00
udf udf_get_extendedattr() had no boundary checks. 2021-09-15 09:47:28 +02:00
ufs Revert "ANDROID: Revert: Merge 5.4.60 into android11-5.4" 2020-08-23 13:12:51 +02:00
unicode
verity This is the 5.4.151 stable release 2021-10-06 15:51:50 +02:00
xfs This is the 5.4.103 stable release 2021-03-07 12:51:29 +01:00
aio.c UPSTREAM: aio: fix use-after-free due to missing POLLFREE handling 2021-12-12 16:44:26 +01:00
anon_inodes.c
attr.c
bad_inode.c
binfmt_aout.c
binfmt_elf.c elf: don't use MAP_FIXED_NOREPLACE for elf interpreter mappings 2021-10-06 15:42:35 +02:00
binfmt_elf_fdpic.c
binfmt_em86.c
binfmt_flat.c binfmt_flat: revert "binfmt_flat: don't offset the data start" 2020-09-03 11:26:39 +02:00
binfmt_misc.c binfmt_misc: fix possible deadlock in bm_register_write 2021-03-17 17:03:57 +01:00
binfmt_script.c
block_dev.c block: reexpand iov_iter after read/write 2021-05-22 11:38:29 +02:00
buffer.c This is the 5.4.75 stable release 2020-11-05 13:27:24 +01:00
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c
coredump.c coredump: fix core_pattern parse error 2020-12-11 13:23:30 +01:00
d_path.c fs: fix NULL dereference due to data race in prepend_path() 2020-10-29 09:57:45 +01:00
dax.c dax: fix ENOMEM handling in grab_mapping_entry() 2021-07-14 16:53:25 +02:00
dcache.c fix dget_parent() fastpath race 2020-10-01 13:17:19 +02:00
dcookies.c
direct-io.c This is the 5.4.112 stable release 2021-04-14 12:07:53 +02:00
drop_caches.c
eventfd.c
eventpoll.c This is the 5.4.70 stable release 2020-10-07 08:50:29 +02:00
exec.c Merge 5.4.156 into android11-5.4-lts 2021-11-02 18:15:00 +01:00
fcntl.c fcntl: fix potential deadlock for &fasync_struct.fa_lock 2021-09-15 09:47:28 +02:00
fhandle.c
file.c
file_table.c
filesystems.c
fs-writeback.c writeback: fix obtain a reference to a freeing memcg css 2021-07-14 16:53:35 +02:00
fs_context.c UPSTREAM: vfs: fs_context: fix up param length parsing in legacy_parse_param 2022-01-19 09:15:31 +01:00
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
internal.h cgroup1: fix leaked context root causing sporadic NULL deref in LTP 2021-07-31 08:19:37 +02:00
io_uring.c UPSTREAM: io_uring: Fix current->fs handling in io_sq_wq_submit_work() 2021-08-17 17:05:36 +00:00
ioctl.c
Kconfig
Kconfig.binfmt
libfs.c This is the 5.4.80 stable release 2020-11-25 12:46:13 +01:00
locks.c
Makefile
mbcache.c
mount.h
mpage.c
namei.c
namespace.c Linux 5.4.143 2021-08-27 22:38:57 +02:00
no-block.c
nsfs.c
open.c
OWNERS ANDROID: Add OWNERS files referring to the respective android-mainline OWNERS 2021-04-01 13:45:14 +00:00
pipe.c pipe: increase minimum default pipe size to 2 pages 2021-08-12 13:21:02 +02:00
pnode.c
pnode.h This is the 5.4.106 stable release 2021-03-17 17:55:32 +01:00
posix_acl.c
proc_namespace.c
read_write.c
readdir.c readdir: make sure to verify directory entry for legacy interfaces too 2021-04-21 12:56:16 +02:00
select.c kernel, fs: Introduce and use set_restart_fn() and arch_set_restart_data() 2021-03-24 11:26:44 +01:00
seq_file.c seq_file: disallow extremely large seq buffer allocations 2021-07-20 16:10:54 +02:00
signalfd.c UPSTREAM: signalfd: use wake_up_pollfree() 2021-12-12 16:44:26 +01:00
splice.c
stack.c
stat.c
statfs.c
super.c vfs: remove lockdep bogosity in __sb_start_write 2020-11-24 13:29:01 +01:00
sync.c
timerfd.c
userfaultfd.c This is the 5.4.148 stable release 2021-09-25 14:41:58 +02:00
utimes.c
xattr.c This is the 5.4.58 stable release 2020-08-11 18:37:58 +02:00