Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp995780yba; Thu, 4 Apr 2019 02:02:05 -0700 (PDT) X-Google-Smtp-Source: APXvYqz6I8EWcbzCZBjMoK2bm3/G2cKn+Lg0TMsrVEm1FZ7+ePPu+1kq9j5DCBrD69faxNoM+s7z X-Received: by 2002:a17:902:586:: with SMTP id f6mr5212628plf.68.1554368525358; Thu, 04 Apr 2019 02:02:05 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1554368525; cv=none; d=google.com; s=arc-20160816; b=YJBhwEk/IiCgq2yq1KVEPIj1+BpYHYhiDiKXVYKQUnR/HbR+90B1C6vjyJJ3I2aHE0 vHl5Wb2QL5SJq/NfU4DisWlFwR6tkps+4jIAG/EvLbclhonDJe+E6RYTwWxYJui5n40a 9AhCRlrM/Kue1VBMFg07IDt+AszzxleKGRyrPRQT/Il6vz8Ve/PaKO1Sfocly+5/KTWt 4Mm5F0tXMNlncVNzjc7GVgI/rHyXgbOEiu350/tLV863ST6oAxK0V4z+qcFtu745IbGu 23W7Iz3lA7EcRa03NDeIUZzpH1hEgewHMuaT/oNgTilXQZGqjRxRxSCEN3gt/2oAS5kR 5Khg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=tQqooAqaXTHg+Mei06K9ZX+HRRnGccEPf/Ngv7C5pcc=; b=ThazC3k4j3I8EyjDZBip2EEnsOAC7neO5W+kh2Y/a7g4PbeauMlEc6bWTVdOvv3K7g SBEimnq9jeIHqpyF1tbiqQnB+QeySu8Je2mWiiynVds6UYwJfBKv1pQE7MkbpdCK0JMW lWiwDRECaCqzMc04lMYYiqH0FIv7OithbT6ghywIcCXL1fieJ/D5+WogecLvl9h7N1pR t+hJGmpV37u5YYFBvf4CnG8ZdYZ+Aj/aYXby9q5ZjarPGbF0Yk3i2I5QbcnDkKP/YT0x DFl1577i7G9tZoYRJ+67X+YXrky3FSfKhPih6Dyct5/VkJxRlTn4Vq7d0+mL1/R/mG6U lDJg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=qyyNUZWh; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id y11si86628plg.39.2019.04.04.02.01.50; Thu, 04 Apr 2019 02:02:05 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=qyyNUZWh; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731405AbfDDJBT (ORCPT + 99 others); Thu, 4 Apr 2019 05:01:19 -0400 Received: from mail.kernel.org ([198.145.29.99]:38352 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730482AbfDDJBP (ORCPT ); Thu, 4 Apr 2019 05:01:15 -0400 Received: from localhost (83-86-89-107.cable.dynamic.v4.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 7B803218C3; Thu, 4 Apr 2019 09:01:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1554368475; bh=dAf2n/c2abUTUH0FIWNoFu3ac5Tc5AY3qslAIP3hQpQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=qyyNUZWhAIUH0VjQBmsuHe0fO5ZaeHbCIkw9aW+6H9bEEeSUAu6aLjLzLIAxXm2el 7o2Opz1zMjoe4F2mrNEYLpompN6UiQ9j39t2h9ePkXVUgEu5rcHo8k2rHQQvTW7LC4 tCdv3tW6y1Ogd1FBc+GI5lpJg+9uLFK5dgOF+ZIc= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, "Jason Cai (Xiang Feng)" , Mike Snitzer , Sasha Levin Subject: [PATCH 4.19 037/187] dm thin: add sanity checks to thin-pool and external snapshot creation Date: Thu, 4 Apr 2019 10:46:14 +0200 Message-Id: <20190404084604.827437846@linuxfoundation.org> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20190404084603.119654039@linuxfoundation.org> References: <20190404084603.119654039@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review X-Patchwork-Hint: ignore MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.19-stable review patch. If anyone has any objections, please let me know. ------------------ [ Upstream commit 70de2cbda8a5d788284469e755f8b097d339c240 ] Invoking dm_get_device() twice on the same device path with different modes is dangerous. Because in that case, upgrade_mode() will alloc a new 'dm_dev' and free the old one, which may be referenced by a previous caller. Dereferencing the dangling pointer will trigger kernel NULL pointer dereference. The following two cases can reproduce this issue. Actually, they are invalid setups that must be disallowed, e.g.: 1. Creating a thin-pool with read_only mode, and the same device as both metadata and data. dmsetup create thinp --table \ "0 41943040 thin-pool /dev/vdb /dev/vdb 128 0 1 read_only" BUG: unable to handle kernel NULL pointer dereference at 0000000000000080 ... Call Trace: new_read+0xfb/0x110 [dm_bufio] dm_bm_read_lock+0x43/0x190 [dm_persistent_data] ? kmem_cache_alloc_trace+0x15c/0x1e0 __create_persistent_data_objects+0x65/0x3e0 [dm_thin_pool] dm_pool_metadata_open+0x8c/0xf0 [dm_thin_pool] pool_ctr.cold.79+0x213/0x913 [dm_thin_pool] ? realloc_argv+0x50/0x70 [dm_mod] dm_table_add_target+0x14e/0x330 [dm_mod] table_load+0x122/0x2e0 [dm_mod] ? dev_status+0x40/0x40 [dm_mod] ctl_ioctl+0x1aa/0x3e0 [dm_mod] dm_ctl_ioctl+0xa/0x10 [dm_mod] do_vfs_ioctl+0xa2/0x600 ? handle_mm_fault+0xda/0x200 ? __do_page_fault+0x26c/0x4f0 ksys_ioctl+0x60/0x90 __x64_sys_ioctl+0x16/0x20 do_syscall_64+0x55/0x150 entry_SYSCALL_64_after_hwframe+0x44/0xa9 2. Creating a external snapshot using the same thin-pool device. dmsetup create thinp --table \ "0 41943040 thin-pool /dev/vdc /dev/vdb 128 0 2 ignore_discard" dmsetup message /dev/mapper/thinp 0 "create_thin 0" dmsetup create snap --table \ "0 204800 thin /dev/mapper/thinp 0 /dev/mapper/thinp" BUG: unable to handle kernel NULL pointer dereference at 0000000000000000 ... Call Trace: ? __alloc_pages_nodemask+0x13c/0x2e0 retrieve_status+0xa5/0x1f0 [dm_mod] ? dm_get_live_or_inactive_table.isra.7+0x20/0x20 [dm_mod] table_status+0x61/0xa0 [dm_mod] ctl_ioctl+0x1aa/0x3e0 [dm_mod] dm_ctl_ioctl+0xa/0x10 [dm_mod] do_vfs_ioctl+0xa2/0x600 ksys_ioctl+0x60/0x90 ? ksys_write+0x4f/0xb0 __x64_sys_ioctl+0x16/0x20 do_syscall_64+0x55/0x150 entry_SYSCALL_64_after_hwframe+0x44/0xa9 Signed-off-by: Jason Cai (Xiang Feng) Signed-off-by: Mike Snitzer Signed-off-by: Sasha Levin --- drivers/md/dm-thin.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/drivers/md/dm-thin.c b/drivers/md/dm-thin.c index cd4220ee7004..435a2ee4a392 100644 --- a/drivers/md/dm-thin.c +++ b/drivers/md/dm-thin.c @@ -3283,6 +3283,13 @@ static int pool_ctr(struct dm_target *ti, unsigned argc, char **argv) as.argc = argc; as.argv = argv; + /* make sure metadata and data are different devices */ + if (!strcmp(argv[0], argv[1])) { + ti->error = "Error setting metadata or data device"; + r = -EINVAL; + goto out_unlock; + } + /* * Set default pool features. */ @@ -4167,6 +4174,12 @@ static int thin_ctr(struct dm_target *ti, unsigned argc, char **argv) tc->sort_bio_list = RB_ROOT; if (argc == 3) { + if (!strcmp(argv[0], argv[2])) { + ti->error = "Error setting origin device"; + r = -EINVAL; + goto bad_origin_dev; + } + r = dm_get_device(ti, argv[2], FMODE_READ, &origin_dev); if (r) { ti->error = "Error opening origin device"; -- 2.19.1