Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp1827217imm; Mon, 3 Sep 2018 10:27:22 -0700 (PDT) X-Google-Smtp-Source: ANB0VdZIVdx+DPlr6wsIpHdpe1M8Y1X/eimLM8dNrcKFXfPWUeNd6R4fFJGkKSbqoXxIs5hjrKdh X-Received: by 2002:a63:ac54:: with SMTP id z20-v6mr26385898pgn.74.1535995642939; Mon, 03 Sep 2018 10:27:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1535995642; cv=none; d=google.com; s=arc-20160816; b=FcIzPVQ7TxV8mepme7J84Ld/3Gk8dw5Ccr1P4ZpqAUx3UxJX+rPNFqL012grpqlp1A AmONtnSOjkRNxYSSPTjooLNTEz83prjH7IJRm9892z/GvARv2+IyMRzWp5kUd57mwy95 UVHIQhNj1ovcoE5i7qmlnQ9CbblhGwFsK5bpMpy/LuIk7yk3uIALfcfk0rcyYjAMqLmk rzQ60tie6EkxDegqlWfsSY5dhlhFNpFDrViWJtsFeFBslHcCtjqMDd2pfrdLr+TMjWjK m1iOs49Z7p/zscJbUH1dYtoBQwokBbFhLw4onEtceLSxK1cCyU7JjKp5ov3qCW0OP+fs PlPw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=3YirWPX7p9IXrC4kiqUOtYgKwh/h8e61DLKWsZQ3YgQ=; b=N83/serhyNDP3RVK+Y1ZHlfBAIY1UZGYzTV9m0B69T+Hp7nP/7IDcfTWL2i6WwCym0 VefchFZWbRawfHrZqna3xSld7e+KCvIzwkoZfjt8qhma1YV/bklhloHd6DeUCOjedDP2 PEvgpw2L3MKdj/HuLrWbwGBaSwleWLlNNuVCv4qvFyKH5PkZmZu78i9wFvYsc3QUs9pM z2e65p9lKR6zKC67YqxyUfNTEkyeGK6vbHk1HBXYfZsq/9TiOHZLz1VGO7dcCd0eAxxK rdDSCCeTP+o1ipsY0Ni9NIgc31BQjCvWMmYJRRRn2Tj4ze0E6jdWE1WKtCT//UNWi62q 4XBA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id k17-v6si19740752pfj.321.2018.09.03.10.27.07; Mon, 03 Sep 2018 10:27:22 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730697AbeICVqs (ORCPT + 99 others); Mon, 3 Sep 2018 17:46:48 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:45776 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728380AbeICVqr (ORCPT ); Mon, 3 Sep 2018 17:46:47 -0400 Received: from localhost (ip-213-127-74-90.ip.prioritytelecom.net [213.127.74.90]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id 41233D24; Mon, 3 Sep 2018 17:25:40 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, syzbot , Miklos Szeredi Subject: [PATCH 4.14 123/165] fuse: Fix oops at process_init_reply() Date: Mon, 3 Sep 2018 18:56:49 +0200 Message-Id: <20180903165701.721757383@linuxfoundation.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180903165655.003605184@linuxfoundation.org> References: <20180903165655.003605184@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.14-stable review patch. If anyone has any objections, please let me know. ------------------ From: Miklos Szeredi commit e8f3bd773d22f488724dffb886a1618da85c2966 upstream. syzbot is hitting NULL pointer dereference at process_init_reply(). This is because deactivate_locked_super() is called before response for initial request is processed. Fix this by aborting and waiting for all requests (including FUSE_INIT) before resetting fc->sb. Original patch by Tetsuo Handa . Reported-by: syzbot Fixes: e27c9d3877a0 ("fuse: fuse: add time_gran to INIT_OUT") Cc: # v3.19 Signed-off-by: Miklos Szeredi Signed-off-by: Greg Kroah-Hartman --- fs/fuse/inode.c | 25 +++++++++++-------------- 1 file changed, 11 insertions(+), 14 deletions(-) --- a/fs/fuse/inode.c +++ b/fs/fuse/inode.c @@ -397,11 +397,6 @@ static void fuse_put_super(struct super_ { struct fuse_conn *fc = get_fuse_conn_super(sb); - fuse_send_destroy(fc); - - fuse_abort_conn(fc); - fuse_wait_aborted(fc); - mutex_lock(&fuse_mutex); list_del(&fc->entry); fuse_ctl_remove_conn(fc); @@ -1198,16 +1193,25 @@ static struct dentry *fuse_mount(struct return mount_nodev(fs_type, flags, raw_data, fuse_fill_super); } -static void fuse_kill_sb_anon(struct super_block *sb) +static void fuse_sb_destroy(struct super_block *sb) { struct fuse_conn *fc = get_fuse_conn_super(sb); if (fc) { + fuse_send_destroy(fc); + + fuse_abort_conn(fc); + fuse_wait_aborted(fc); + down_write(&fc->killsb); fc->sb = NULL; up_write(&fc->killsb); } +} +static void fuse_kill_sb_anon(struct super_block *sb) +{ + fuse_sb_destroy(sb); kill_anon_super(sb); } @@ -1230,14 +1234,7 @@ static struct dentry *fuse_mount_blk(str static void fuse_kill_sb_blk(struct super_block *sb) { - struct fuse_conn *fc = get_fuse_conn_super(sb); - - if (fc) { - down_write(&fc->killsb); - fc->sb = NULL; - up_write(&fc->killsb); - } - + fuse_sb_destroy(sb); kill_block_super(sb); }