From: Alessio Balsini <balsini@android.com>
To: Peng Tao <bergwolf@gmail.com>
Cc: Alessio Balsini <balsini@android.com>,
Miklos Szeredi <miklos@szeredi.hu>,
Akilesh Kailash <akailash@google.com>,
Amir Goldstein <amir73il@gmail.com>,
Antonio SJ Musumeci <trapexit@spawn.link>,
David Anderson <dvander@google.com>,
Giuseppe Scrivano <gscrivan@redhat.com>,
Jann Horn <jannh@google.com>, Jens Axboe <axboe@kernel.dk>,
Martijn Coenen <maco@android.com>,
Palmer Dabbelt <palmer@dabbelt.com>,
Paul Lawrence <paullawrence@google.com>,
Stefano Duo <duostefano93@gmail.com>,
Zimuzo Ezeozue <zezeozue@google.com>, wuyan <wu-yan@tcl.com>,
fuse-devel@lists.sourceforge.net, kernel-team@android.com,
"linux-fsdevel@vger.kernel.org" <linux-fsdevel@vger.kernel.org>,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH RESEND V12 7/8] fuse: Use daemon creds in passthrough mode
Date: Fri, 5 Feb 2021 11:21:32 +0000 [thread overview]
Message-ID: <YB0qPHVORq7bJy6G@google.com> (raw)
In-Reply-To: <CA+a=Yy71JUwWwAPEi0Ngn_kt7Gt3KZwJgx_u=CBefJJTE_mYYw@mail.gmail.com>
On Fri, Feb 05, 2021 at 05:23:56PM +0800, Peng Tao wrote:
> On Mon, Jan 25, 2021 at 11:31 PM Alessio Balsini <balsini@android.com> wrote:
> >
> > When using FUSE passthrough, read/write operations are directly
> > forwarded to the lower file system file through VFS, but there is no
> > guarantee that the process that is triggering the request has the right
> > permissions to access the lower file system. This would cause the
> > read/write access to fail.
> >
> > In passthrough file systems, where the FUSE daemon is responsible for
> > the enforcement of the lower file system access policies, often happens
> > that the process dealing with the FUSE file system doesn't have access
> > to the lower file system.
> > Being the FUSE daemon in charge of implementing the FUSE file
> > operations, that in the case of read/write operations usually simply
> > results in the copy of memory buffers from/to the lower file system
> > respectively, these operations are executed with the FUSE daemon
> > privileges.
> >
> > This patch adds a reference to the FUSE daemon credentials, referenced
> > at FUSE_DEV_IOC_PASSTHROUGH_OPEN ioctl() time so that they can be used
> > to temporarily raise the user credentials when accessing lower file
> > system files in passthrough.
> > The process accessing the FUSE file with passthrough enabled temporarily
> > receives the privileges of the FUSE daemon while performing read/write
> > operations. Similar behavior is implemented in overlayfs.
> > These privileges will be reverted as soon as the IO operation completes.
> > This feature does not provide any higher security privileges to those
> > processes accessing the FUSE file system with passthrough enabled. This
> > is because it is still the FUSE daemon responsible for enabling or not
> > the passthrough feature at file open time, and should enable the feature
> > only after appropriate access policy checks.
> >
> > Signed-off-by: Alessio Balsini <balsini@android.com>
> > ---
> > fs/fuse/fuse_i.h | 5 ++++-
> > fs/fuse/passthrough.c | 11 +++++++++++
> > 2 files changed, 15 insertions(+), 1 deletion(-)
> >
> > diff --git a/fs/fuse/fuse_i.h b/fs/fuse/fuse_i.h
> > index c4730d893324..815af1845b16 100644
> > --- a/fs/fuse/fuse_i.h
> > +++ b/fs/fuse/fuse_i.h
> > @@ -182,10 +182,13 @@ struct fuse_release_args;
> >
> > /**
> > * Reference to lower filesystem file for read/write operations handled in
> > - * passthrough mode
> > + * passthrough mode.
> > + * This struct also tracks the credentials to be used for handling read/write
> > + * operations.
> > */
> > struct fuse_passthrough {
> > struct file *filp;
> > + struct cred *cred;
> > };
> >
> > /** FUSE specific file data */
> > diff --git a/fs/fuse/passthrough.c b/fs/fuse/passthrough.c
> > index c7fa1eeb7639..24866c5fe7e2 100644
> > --- a/fs/fuse/passthrough.c
> > +++ b/fs/fuse/passthrough.c
> > @@ -52,6 +52,7 @@ ssize_t fuse_passthrough_read_iter(struct kiocb *iocb_fuse,
> > struct iov_iter *iter)
> > {
> > ssize_t ret;
> > + const struct cred *old_cred;
> > struct file *fuse_filp = iocb_fuse->ki_filp;
> > struct fuse_file *ff = fuse_filp->private_data;
> > struct file *passthrough_filp = ff->passthrough.filp;
> > @@ -59,6 +60,7 @@ ssize_t fuse_passthrough_read_iter(struct kiocb *iocb_fuse,
> > if (!iov_iter_count(iter))
> > return 0;
> >
> > + old_cred = override_creds(ff->passthrough.cred);
> > if (is_sync_kiocb(iocb_fuse)) {
> > ret = vfs_iter_read(passthrough_filp, iter, &iocb_fuse->ki_pos,
> > iocb_to_rw_flags(iocb_fuse->ki_flags,
> > @@ -77,6 +79,7 @@ ssize_t fuse_passthrough_read_iter(struct kiocb *iocb_fuse,
> > if (ret != -EIOCBQUEUED)
> > fuse_aio_cleanup_handler(aio_req);
> > }
> > + revert_creds(old_cred);
> cred should be reverted when kmalloc() fails above.
>
> Cheers,
> Tao
> --
> Into Sth. Rich & Strange
Thanks Tao, definitely!
Please find the fixup at the bottom of this email.
I keep the WIP V13 here:
https://github.com/balsini/linux/tree/fuse-passthrough-v13-v5.11-rc5
Thanks,
Alessio
---8<---
From 63797a2cc6b3946bce59989adcb8f39f70f27643 Mon Sep 17 00:00:00 2001
From: Alessio Balsini <balsini@android.com>
Date: Fri, 5 Feb 2021 10:58:49 +0000
Subject: [PATCH] fuse: Fix crediantials leak in passthrough read_iter
If the system doesn't have enough memory when fuse_passthrough_read_iter
is requested in asynchronous IO, an error is directly returned without
restoring the caller's credentials.
Fix by always ensuring credentials are restored.
Fixes: 20210125153057.3623715-8-balsini@android.com ("fuse: Use daemon creds in passthrough mode")
Signed-off-by: Alessio Balsini <balsini@android.com>
---
fs/fuse/passthrough.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/fs/fuse/passthrough.c b/fs/fuse/passthrough.c
index 284979f87747..1df94c1d8a00 100644
--- a/fs/fuse/passthrough.c
+++ b/fs/fuse/passthrough.c
@@ -69,8 +69,10 @@ ssize_t fuse_passthrough_read_iter(struct kiocb *iocb_fuse,
struct fuse_aio_req *aio_req;
aio_req = kmalloc(sizeof(struct fuse_aio_req), GFP_KERNEL);
- if (!aio_req)
- return -ENOMEM;
+ if (!aio_req) {
+ ret = -ENOMEM;
+ goto out;
+ }
aio_req->iocb_fuse = iocb_fuse;
kiocb_clone(&aio_req->iocb, iocb_fuse, passthrough_filp);
@@ -79,6 +81,7 @@ ssize_t fuse_passthrough_read_iter(struct kiocb *iocb_fuse,
if (ret != -EIOCBQUEUED)
fuse_aio_cleanup_handler(aio_req);
}
+out:
revert_creds(old_cred);
return ret;
--
2.30.0.365.g02bc693789-goog
next prev parent reply other threads:[~2021-02-05 11:25 UTC|newest]
Thread overview: 66+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-01-25 15:30 [PATCH RESEND V12 0/8] fuse: Add support for passthrough read/write Alessio Balsini
2021-01-25 15:30 ` [PATCH RESEND V12 1/8] fs: Generic function to convert iocb to rw flags Alessio Balsini
2021-01-25 16:46 ` Alessio Balsini
2021-03-24 7:43 ` Rokudo Yan
2021-03-24 14:02 ` Alessio Balsini
2021-01-25 15:30 ` [PATCH RESEND V12 2/8] fuse: 32-bit user space ioctl compat for fuse device Alessio Balsini
[not found] ` <CAMAHBGzkfEd9-1u0iKXp65ReJQgUi_=4sMpmfkwEOaMp6Ux7pg@mail.gmail.com>
2021-01-27 13:40 ` Alessio Balsini
[not found] ` <CAMAHBGwpKW+30kNQ_Apt8A-FTmr94hBOzkT21cjEHHW+t7yUMQ@mail.gmail.com>
2021-01-28 14:15 ` Alessio Balsini
2021-02-05 9:54 ` Peng Tao
2021-03-16 18:57 ` Arnd Bergmann
2021-02-17 10:21 ` Miklos Szeredi
2021-03-01 12:26 ` Alessio Balsini
2021-03-16 18:53 ` Arnd Bergmann
2021-03-18 16:13 ` Alessio Balsini
2021-03-18 21:15 ` Arnd Bergmann
2021-03-19 15:21 ` Alessio Balsini
2021-01-25 15:30 ` [PATCH RESEND V12 3/8] fuse: Definitions and ioctl for passthrough Alessio Balsini
2021-02-17 13:41 ` Miklos Szeredi
2021-02-19 7:05 ` Peng Tao
2021-02-19 8:40 ` Miklos Szeredi
2021-03-01 17:05 ` Alessio Balsini
2022-09-08 15:36 ` Amir Goldstein
2022-09-09 19:07 ` Miklos Szeredi
2022-09-10 8:52 ` Amir Goldstein
2022-09-10 13:03 ` Bernd Schubert
2022-09-12 9:29 ` Miklos Szeredi
2022-09-12 12:29 ` Amir Goldstein
2022-09-12 13:03 ` Miklos Szeredi
2022-09-12 13:05 ` Miklos Szeredi
2022-09-12 13:26 ` Amir Goldstein
2022-09-12 14:22 ` Miklos Szeredi
2022-09-12 15:39 ` Amir Goldstein
2022-09-12 17:43 ` Hao Luo
2022-09-12 18:28 ` Overlayfs with writable lower layer Amir Goldstein
2022-09-13 18:26 ` Hao Luo
2022-09-13 18:54 ` Amir Goldstein
2022-09-13 20:33 ` Hao Luo
2022-09-14 3:46 ` Amir Goldstein
2022-09-14 18:00 ` Hao Luo
2022-09-14 19:23 ` Amir Goldstein
2022-09-14 19:33 ` Hao Luo
2022-09-15 10:54 ` Amir Goldstein
2023-05-12 19:37 ` [PATCH RESEND V12 3/8] fuse: Definitions and ioctl for passthrough Amir Goldstein
2023-05-15 7:29 ` Miklos Szeredi
2023-05-15 14:00 ` Amir Goldstein
2023-05-15 20:16 ` [fuse-devel] " Nikolaus Rath
2023-05-15 21:11 ` Bernd Schubert
2023-05-15 21:45 ` Paul Lawrence
2023-05-16 8:43 ` Miklos Szeredi
2023-05-16 10:16 ` Nikolaus Rath
2023-05-16 8:48 ` Amir Goldstein
2021-01-25 15:30 ` [PATCH RESEND V12 4/8] fuse: Passthrough initialization and release Alessio Balsini
2021-02-17 13:52 ` Miklos Szeredi
2021-05-05 12:21 ` Amir Goldstein
2021-05-17 11:36 ` Alessio Balsini
2021-05-17 13:21 ` Amir Goldstein
2021-01-25 15:30 ` [PATCH RESEND V12 5/8] fuse: Introduce synchronous read and write for passthrough Alessio Balsini
2021-02-17 14:00 ` Miklos Szeredi
2021-01-25 15:30 ` [PATCH RESEND V12 6/8] fuse: Handle asynchronous read and write in passthrough Alessio Balsini
2021-01-25 15:30 ` [PATCH RESEND V12 7/8] fuse: Use daemon creds in passthrough mode Alessio Balsini
2021-02-05 9:23 ` Peng Tao
2021-02-05 11:21 ` Alessio Balsini [this message]
2021-01-25 15:30 ` [PATCH RESEND V12 8/8] fuse: Introduce passthrough for mmap Alessio Balsini
2021-02-17 14:05 ` Miklos Szeredi
2021-04-01 11:24 ` Alessio Balsini
2021-11-18 18:31 ` [PATCH RESEND V12 0/8] fuse: Add support for passthrough read/write Amir Goldstein
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YB0qPHVORq7bJy6G@google.com \
--to=balsini@android.com \
--cc=akailash@google.com \
--cc=amir73il@gmail.com \
--cc=axboe@kernel.dk \
--cc=bergwolf@gmail.com \
--cc=duostefano93@gmail.com \
--cc=dvander@google.com \
--cc=fuse-devel@lists.sourceforge.net \
--cc=gscrivan@redhat.com \
--cc=jannh@google.com \
--cc=kernel-team@android.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maco@android.com \
--cc=miklos@szeredi.hu \
--cc=palmer@dabbelt.com \
--cc=paullawrence@google.com \
--cc=trapexit@spawn.link \
--cc=wu-yan@tcl.com \
--cc=zezeozue@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).