Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp1812235imm; Mon, 3 Sep 2018 10:04:28 -0700 (PDT) X-Google-Smtp-Source: ANB0Vdb2VN8vE2iqfxkiJ3SOdprTc8lo12VGlRhopWSpnyuZXBdCPbYhR4sjlCtl/76I163FAMfy X-Received: by 2002:a17:902:e190:: with SMTP id cd16-v6mr29243281plb.305.1535994268285; Mon, 03 Sep 2018 10:04:28 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1535994268; cv=none; d=google.com; s=arc-20160816; b=QmJ3WrKp7L/8Dqr4ITzf5+Axbatq/ZQglffDgvCAMdBXC8wyb18euQn4OY5UvexiPj QvtXbujbYDK3ba5VexSRFCGRIvfFdG5ak1q3T5cmxU6eL/qNp+wBprjPG+6Y/BKV5pR2 K0tRKJWpzpTiyk54vYkyawsyNGwng2mtlCkkj5SFBDAUMfEBiBMqEa99gW//h/SnkOSz bK6nJBh0ao2VNaL5+VS1EU10H9dV3tOwQ0cUMtfvpZ8jeoWhKCI6o/EwTClzYXL+l9bP YQgM2xVT5Z1PqffrjzTeKgNaxPZsOutr69diWx7wUriZpQau4BLg/1LxfB3wDZUXGHfi onbg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=i4gaqvOGY8h4+zn3UYiB0W2WKnyH4Lk5e/5Odx07aUY=; b=Kb7FCwCXjuKwKe1OWtGstATt2xjGUyxQhRUPVShgvFQvwIilfRZAKlNabuvI+N13IC 5SUSpYFyTkRUhD/Oh11V1sJGmzReLiwyP/Pp7lyYwz4sMDtgR+cLueGmHNAHIIgGPoDu CVQHwHMxZFp1hKCznBQD6VSHH4epRGw/jzH5v2KGLLnjofXpjVNRfrlA7OUa2J81ta3C 0/Ewc6kQrEy0HNR5a6JJIRNMok38dhISmRRrzmgQMOH1RAmY+U/KCzdqD/YCyhA0yCQr ay8VRpxXsU9z+ieU3cMIyjxtx1VnPQoUxHbORrf20K0seTYGG2fNKWX5PVq1qh+Ol+bI Aivg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p66-v6si19716184pfp.237.2018.09.03.10.04.13; Mon, 03 Sep 2018 10:04:28 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729078AbeICVXo (ORCPT + 99 others); Mon, 3 Sep 2018 17:23:44 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:38992 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727976AbeICVXo (ORCPT ); Mon, 3 Sep 2018 17:23:44 -0400 Received: from localhost (ip-213-127-74-90.ip.prioritytelecom.net [213.127.74.90]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 69200CFF; Mon, 3 Sep 2018 17:02:43 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, syzbot , Miklos Szeredi Subject: [PATCH 4.4 61/80] fuse: Fix oops at process_init_reply() Date: Mon, 3 Sep 2018 18:49:39 +0200 Message-Id: <20180903164936.592520745@linuxfoundation.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180903164934.171677301@linuxfoundation.org> References: <20180903164934.171677301@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Miklos Szeredi commit e8f3bd773d22f488724dffb886a1618da85c2966 upstream. syzbot is hitting NULL pointer dereference at process_init_reply(). This is because deactivate_locked_super() is called before response for initial request is processed. Fix this by aborting and waiting for all requests (including FUSE_INIT) before resetting fc->sb. Original patch by Tetsuo Handa . Reported-by: syzbot Fixes: e27c9d3877a0 ("fuse: fuse: add time_gran to INIT_OUT") Cc: # v3.19 Signed-off-by: Miklos Szeredi Signed-off-by: Greg Kroah-Hartman --- fs/fuse/inode.c | 25 +++++++++++-------------- 1 file changed, 11 insertions(+), 14 deletions(-) --- a/fs/fuse/inode.c +++ b/fs/fuse/inode.c @@ -379,11 +379,6 @@ static void fuse_put_super(struct super_ { struct fuse_conn *fc = get_fuse_conn_super(sb); - fuse_send_destroy(fc); - - fuse_abort_conn(fc); - fuse_wait_aborted(fc); - mutex_lock(&fuse_mutex); list_del(&fc->entry); fuse_ctl_remove_conn(fc); @@ -1174,16 +1169,25 @@ static struct dentry *fuse_mount(struct return mount_nodev(fs_type, flags, raw_data, fuse_fill_super); } -static void fuse_kill_sb_anon(struct super_block *sb) +static void fuse_sb_destroy(struct super_block *sb) { struct fuse_conn *fc = get_fuse_conn_super(sb); if (fc) { + fuse_send_destroy(fc); + + fuse_abort_conn(fc); + fuse_wait_aborted(fc); + down_write(&fc->killsb); fc->sb = NULL; up_write(&fc->killsb); } +} +static void fuse_kill_sb_anon(struct super_block *sb) +{ + fuse_sb_destroy(sb); kill_anon_super(sb); } @@ -1206,14 +1210,7 @@ static struct dentry *fuse_mount_blk(str static void fuse_kill_sb_blk(struct super_block *sb) { - struct fuse_conn *fc = get_fuse_conn_super(sb); - - if (fc) { - down_write(&fc->killsb); - fc->sb = NULL; - up_write(&fc->killsb); - } - + fuse_sb_destroy(sb); kill_block_super(sb); }