00cb8726fb
[ Upstream commit bfca5fb4e97c46503ddfc582335917b0cc228264 ] RPC client pipefs dentries cleanup is in separated rpc_remove_pipedir() workqueue,which takes care about pipefs superblock locking. In some special scenarios, when kernel frees the pipefs sb of the current client and immediately alloctes a new pipefs sb, rpc_remove_pipedir function would misjudge the existence of pipefs sb which is not the one it used to hold. As a result, the rpc_remove_pipedir would clean the released freed pipefs dentries. To fix this issue, rpc_remove_pipedir should check whether the current pipefs sb is consistent with the original pipefs sb. This error can be catched by KASAN: ========================================================= [ 250.497700] BUG: KASAN: slab-use-after-free in dget_parent+0x195/0x200 [ 250.498315] Read of size 4 at addr ffff88800a2ab804 by task kworker/0:18/106503 [ 250.500549] Workqueue: events rpc_free_client_work [ 250.501001] Call Trace: [ 250.502880] kasan_report+0xb6/0xf0 [ 250.503209] ? dget_parent+0x195/0x200 [ 250.503561] dget_parent+0x195/0x200 [ 250.503897] ? __pfx_rpc_clntdir_depopulate+0x10/0x10 [ 250.504384] rpc_rmdir_depopulate+0x1b/0x90 [ 250.504781] rpc_remove_client_dir+0xf5/0x150 [ 250.505195] rpc_free_client_work+0xe4/0x230 [ 250.505598] process_one_work+0x8ee/0x13b0 ... [ 22.039056] Allocated by task 244: [ 22.039390] kasan_save_stack+0x22/0x50 [ 22.039758] kasan_set_track+0x25/0x30 [ 22.040109] __kasan_slab_alloc+0x59/0x70 [ 22.040487] kmem_cache_alloc_lru+0xf0/0x240 [ 22.040889] __d_alloc+0x31/0x8e0 [ 22.041207] d_alloc+0x44/0x1f0 [ 22.041514] __rpc_lookup_create_exclusive+0x11c/0x140 [ 22.041987] rpc_mkdir_populate.constprop.0+0x5f/0x110 [ 22.042459] rpc_create_client_dir+0x34/0x150 [ 22.042874] rpc_setup_pipedir_sb+0x102/0x1c0 [ 22.043284] rpc_client_register+0x136/0x4e0 [ 22.043689] rpc_new_client+0x911/0x1020 [ 22.044057] rpc_create_xprt+0xcb/0x370 [ 22.044417] rpc_create+0x36b/0x6c0 ... [ 22.049524] Freed by task 0: [ 22.049803] kasan_save_stack+0x22/0x50 [ 22.050165] kasan_set_track+0x25/0x30 [ 22.050520] kasan_save_free_info+0x2b/0x50 [ 22.050921] __kasan_slab_free+0x10e/0x1a0 [ 22.051306] kmem_cache_free+0xa5/0x390 [ 22.051667] rcu_core+0x62c/0x1930 [ 22.051995] __do_softirq+0x165/0x52a [ 22.052347] [ 22.052503] Last potentially related work creation: [ 22.052952] kasan_save_stack+0x22/0x50 [ 22.053313] __kasan_record_aux_stack+0x8e/0xa0 [ 22.053739] __call_rcu_common.constprop.0+0x6b/0x8b0 [ 22.054209] dentry_free+0xb2/0x140 [ 22.054540] __dentry_kill+0x3be/0x540 [ 22.054900] shrink_dentry_list+0x199/0x510 [ 22.055293] shrink_dcache_parent+0x190/0x240 [ 22.055703] do_one_tree+0x11/0x40 [ 22.056028] shrink_dcache_for_umount+0x61/0x140 [ 22.056461] generic_shutdown_super+0x70/0x590 [ 22.056879] kill_anon_super+0x3a/0x60 [ 22.057234] rpc_kill_sb+0x121/0x200 Fixes: 0157d021d23a ("SUNRPC: handle RPC client pipefs dentries by network namespace aware routines") Signed-off-by: felix <fuzhen5@huawei.com> Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
251 lines
8.1 KiB
C
Executable file
251 lines
8.1 KiB
C
Executable file
/* SPDX-License-Identifier: GPL-2.0 */
|
|
/*
|
|
* linux/include/linux/sunrpc/clnt.h
|
|
*
|
|
* Declarations for the high-level RPC client interface
|
|
*
|
|
* Copyright (C) 1995, 1996, Olaf Kirch <okir@monad.swb.de>
|
|
*/
|
|
|
|
#ifndef _LINUX_SUNRPC_CLNT_H
|
|
#define _LINUX_SUNRPC_CLNT_H
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/socket.h>
|
|
#include <linux/in.h>
|
|
#include <linux/in6.h>
|
|
|
|
#include <linux/sunrpc/msg_prot.h>
|
|
#include <linux/sunrpc/sched.h>
|
|
#include <linux/sunrpc/xprt.h>
|
|
#include <linux/sunrpc/auth.h>
|
|
#include <linux/sunrpc/stats.h>
|
|
#include <linux/sunrpc/xdr.h>
|
|
#include <linux/sunrpc/timer.h>
|
|
#include <linux/sunrpc/rpc_pipe_fs.h>
|
|
#include <asm/signal.h>
|
|
#include <linux/path.h>
|
|
#include <net/ipv6.h>
|
|
#include <linux/sunrpc/xprtmultipath.h>
|
|
|
|
struct rpc_inode;
|
|
|
|
/*
|
|
* The high-level client handle
|
|
*/
|
|
struct rpc_clnt {
|
|
atomic_t cl_count; /* Number of references */
|
|
unsigned int cl_clid; /* client id */
|
|
struct list_head cl_clients; /* Global list of clients */
|
|
struct list_head cl_tasks; /* List of tasks */
|
|
spinlock_t cl_lock; /* spinlock */
|
|
struct rpc_xprt __rcu * cl_xprt; /* transport */
|
|
const struct rpc_procinfo *cl_procinfo; /* procedure info */
|
|
u32 cl_prog, /* RPC program number */
|
|
cl_vers, /* RPC version number */
|
|
cl_maxproc; /* max procedure number */
|
|
|
|
struct rpc_auth * cl_auth; /* authenticator */
|
|
struct rpc_stat * cl_stats; /* per-program statistics */
|
|
struct rpc_iostats * cl_metrics; /* per-client statistics */
|
|
|
|
unsigned int cl_softrtry : 1,/* soft timeouts */
|
|
cl_softerr : 1,/* Timeouts return errors */
|
|
cl_discrtry : 1,/* disconnect before retry */
|
|
cl_noretranstimeo: 1,/* No retransmit timeouts */
|
|
cl_autobind : 1,/* use getport() */
|
|
cl_chatty : 1;/* be verbose */
|
|
|
|
struct rpc_rtt * cl_rtt; /* RTO estimator data */
|
|
const struct rpc_timeout *cl_timeout; /* Timeout strategy */
|
|
|
|
atomic_t cl_swapper; /* swapfile count */
|
|
int cl_nodelen; /* nodename length */
|
|
char cl_nodename[UNX_MAXNODENAME+1];
|
|
struct rpc_pipe_dir_head cl_pipedir_objects;
|
|
struct rpc_clnt * cl_parent; /* Points to parent of clones */
|
|
struct rpc_rtt cl_rtt_default;
|
|
struct rpc_timeout cl_timeout_default;
|
|
const struct rpc_program *cl_program;
|
|
const char * cl_principal; /* use for machine cred */
|
|
#if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
|
|
struct dentry *cl_debugfs; /* debugfs directory */
|
|
#endif
|
|
/* cl_work is only needed after cl_xpi is no longer used,
|
|
* and that are of similar size
|
|
*/
|
|
union {
|
|
struct rpc_xprt_iter cl_xpi;
|
|
struct work_struct cl_work;
|
|
};
|
|
const struct cred *cl_cred;
|
|
struct super_block *pipefs_sb;
|
|
};
|
|
|
|
/*
|
|
* General RPC program info
|
|
*/
|
|
#define RPC_MAXVERSION 4
|
|
struct rpc_program {
|
|
const char * name; /* protocol name */
|
|
u32 number; /* program number */
|
|
unsigned int nrvers; /* number of versions */
|
|
const struct rpc_version ** version; /* version array */
|
|
struct rpc_stat * stats; /* statistics */
|
|
const char * pipe_dir_name; /* path to rpc_pipefs dir */
|
|
};
|
|
|
|
struct rpc_version {
|
|
u32 number; /* version number */
|
|
unsigned int nrprocs; /* number of procs */
|
|
const struct rpc_procinfo *procs; /* procedure array */
|
|
unsigned int *counts; /* call counts */
|
|
};
|
|
|
|
/*
|
|
* Procedure information
|
|
*/
|
|
struct rpc_procinfo {
|
|
u32 p_proc; /* RPC procedure number */
|
|
kxdreproc_t p_encode; /* XDR encode function */
|
|
kxdrdproc_t p_decode; /* XDR decode function */
|
|
unsigned int p_arglen; /* argument hdr length (u32) */
|
|
unsigned int p_replen; /* reply hdr length (u32) */
|
|
unsigned int p_timer; /* Which RTT timer to use */
|
|
u32 p_statidx; /* Which procedure to account */
|
|
const char * p_name; /* name of procedure */
|
|
};
|
|
|
|
struct rpc_create_args {
|
|
struct net *net;
|
|
int protocol;
|
|
struct sockaddr *address;
|
|
size_t addrsize;
|
|
struct sockaddr *saddress;
|
|
const struct rpc_timeout *timeout;
|
|
const char *servername;
|
|
const char *nodename;
|
|
const struct rpc_program *program;
|
|
u32 prognumber; /* overrides program->number */
|
|
u32 version;
|
|
rpc_authflavor_t authflavor;
|
|
u32 nconnect;
|
|
unsigned long flags;
|
|
char *client_name;
|
|
struct svc_xprt *bc_xprt; /* NFSv4.1 backchannel */
|
|
const struct cred *cred;
|
|
};
|
|
|
|
struct rpc_add_xprt_test {
|
|
void (*add_xprt_test)(struct rpc_clnt *clnt,
|
|
struct rpc_xprt *xprt,
|
|
void *calldata);
|
|
void *data;
|
|
};
|
|
|
|
/* Values for "flags" field */
|
|
#define RPC_CLNT_CREATE_HARDRTRY (1UL << 0)
|
|
#define RPC_CLNT_CREATE_AUTOBIND (1UL << 2)
|
|
#define RPC_CLNT_CREATE_NONPRIVPORT (1UL << 3)
|
|
#define RPC_CLNT_CREATE_NOPING (1UL << 4)
|
|
#define RPC_CLNT_CREATE_DISCRTRY (1UL << 5)
|
|
#define RPC_CLNT_CREATE_QUIET (1UL << 6)
|
|
#define RPC_CLNT_CREATE_INFINITE_SLOTS (1UL << 7)
|
|
#define RPC_CLNT_CREATE_NO_IDLE_TIMEOUT (1UL << 8)
|
|
#define RPC_CLNT_CREATE_NO_RETRANS_TIMEOUT (1UL << 9)
|
|
#define RPC_CLNT_CREATE_SOFTERR (1UL << 10)
|
|
#define RPC_CLNT_CREATE_REUSEPORT (1UL << 11)
|
|
|
|
struct rpc_clnt *rpc_create(struct rpc_create_args *args);
|
|
struct rpc_clnt *rpc_bind_new_program(struct rpc_clnt *,
|
|
const struct rpc_program *, u32);
|
|
struct rpc_clnt *rpc_clone_client(struct rpc_clnt *);
|
|
struct rpc_clnt *rpc_clone_client_set_auth(struct rpc_clnt *,
|
|
rpc_authflavor_t);
|
|
int rpc_switch_client_transport(struct rpc_clnt *,
|
|
struct xprt_create *,
|
|
const struct rpc_timeout *);
|
|
|
|
void rpc_shutdown_client(struct rpc_clnt *);
|
|
void rpc_release_client(struct rpc_clnt *);
|
|
void rpc_task_release_transport(struct rpc_task *);
|
|
void rpc_task_release_client(struct rpc_task *);
|
|
struct rpc_xprt *rpc_task_get_xprt(struct rpc_clnt *clnt,
|
|
struct rpc_xprt *xprt);
|
|
|
|
int rpcb_create_local(struct net *);
|
|
void rpcb_put_local(struct net *);
|
|
int rpcb_register(struct net *, u32, u32, int, unsigned short);
|
|
int rpcb_v4_register(struct net *net, const u32 program,
|
|
const u32 version,
|
|
const struct sockaddr *address,
|
|
const char *netid);
|
|
void rpcb_getport_async(struct rpc_task *);
|
|
|
|
void rpc_prepare_reply_pages(struct rpc_rqst *req, struct page **pages,
|
|
unsigned int base, unsigned int len,
|
|
unsigned int hdrsize);
|
|
void rpc_call_start(struct rpc_task *);
|
|
int rpc_call_async(struct rpc_clnt *clnt,
|
|
const struct rpc_message *msg, int flags,
|
|
const struct rpc_call_ops *tk_ops,
|
|
void *calldata);
|
|
int rpc_call_sync(struct rpc_clnt *clnt,
|
|
const struct rpc_message *msg, int flags);
|
|
struct rpc_task *rpc_call_null(struct rpc_clnt *clnt, struct rpc_cred *cred,
|
|
int flags);
|
|
int rpc_restart_call_prepare(struct rpc_task *);
|
|
int rpc_restart_call(struct rpc_task *);
|
|
void rpc_setbufsize(struct rpc_clnt *, unsigned int, unsigned int);
|
|
struct net * rpc_net_ns(struct rpc_clnt *);
|
|
size_t rpc_max_payload(struct rpc_clnt *);
|
|
size_t rpc_max_bc_payload(struct rpc_clnt *);
|
|
unsigned int rpc_num_bc_slots(struct rpc_clnt *);
|
|
void rpc_force_rebind(struct rpc_clnt *);
|
|
size_t rpc_peeraddr(struct rpc_clnt *, struct sockaddr *, size_t);
|
|
const char *rpc_peeraddr2str(struct rpc_clnt *, enum rpc_display_format_t);
|
|
int rpc_localaddr(struct rpc_clnt *, struct sockaddr *, size_t);
|
|
|
|
int rpc_clnt_iterate_for_each_xprt(struct rpc_clnt *clnt,
|
|
int (*fn)(struct rpc_clnt *, struct rpc_xprt *, void *),
|
|
void *data);
|
|
|
|
int rpc_clnt_test_and_add_xprt(struct rpc_clnt *clnt,
|
|
struct rpc_xprt_switch *xps,
|
|
struct rpc_xprt *xprt,
|
|
void *dummy);
|
|
int rpc_clnt_add_xprt(struct rpc_clnt *, struct xprt_create *,
|
|
int (*setup)(struct rpc_clnt *,
|
|
struct rpc_xprt_switch *,
|
|
struct rpc_xprt *,
|
|
void *),
|
|
void *data);
|
|
void rpc_set_connect_timeout(struct rpc_clnt *clnt,
|
|
unsigned long connect_timeout,
|
|
unsigned long reconnect_timeout);
|
|
|
|
int rpc_clnt_setup_test_and_add_xprt(struct rpc_clnt *,
|
|
struct rpc_xprt_switch *,
|
|
struct rpc_xprt *,
|
|
void *);
|
|
|
|
const char *rpc_proc_name(const struct rpc_task *task);
|
|
|
|
void rpc_clnt_xprt_switch_put(struct rpc_clnt *);
|
|
void rpc_clnt_xprt_switch_add_xprt(struct rpc_clnt *, struct rpc_xprt *);
|
|
bool rpc_clnt_xprt_switch_has_addr(struct rpc_clnt *clnt,
|
|
const struct sockaddr *sap);
|
|
void rpc_cleanup_clids(void);
|
|
|
|
static inline int rpc_reply_expected(struct rpc_task *task)
|
|
{
|
|
return (task->tk_msg.rpc_proc != NULL) &&
|
|
(task->tk_msg.rpc_proc->p_decode != NULL);
|
|
}
|
|
|
|
static inline void rpc_task_close_connection(struct rpc_task *task)
|
|
{
|
|
if (task->tk_xprt)
|
|
xprt_force_disconnect(task->tk_xprt);
|
|
}
|
|
#endif /* _LINUX_SUNRPC_CLNT_H */
|