Received: by 2002:a05:6a10:f3d0:0:0:0:0 with SMTP id a16csp5792826pxv; Wed, 7 Jul 2021 11:51:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJz91r6s2V0clFie2RKTyydx3OloBi6x0/lp8qfsdbM9gT7TcuzlijNhBgzH/19OmnaKReSt X-Received: by 2002:a17:907:94cb:: with SMTP id dn11mr16960277ejc.420.1625683883782; Wed, 07 Jul 2021 11:51:23 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1625683883; cv=none; d=google.com; s=arc-20160816; b=bijkUF/M8a+n2+j862BqtGeXDDE0LgGhTP3dJKyLVNxvHtHxpA2uxX/acAxsXxGsq6 Mb0PM1hGYL7z1uhV74K4HKXnehs+nvOMwVezMgZ/NxjJDK9JzmNG0RmhTEdjzU58AmlJ wD3SmD3N7mToMFDG49r+5ASuS67l9yIXoasYbviwn5lPMGoEG8WYuRGFPIdZ2pvFUT1Q vYHAxrme3Nj8tOGrNzhY8fB3M33M+LB4lzzo/biAiQpav1yAEMutLgobMPMaLG2zxvTD NpFgNDi26v0V4qOE+tSs0ogrURZLq+q4ld6P88T8P1iNm/HBIR2nVmpIXR0HQ9ON2bDH GzbQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=r7YGSy37fYgov/nu/eHIw5R4NrzDeOEToKWhoVDtJ3Y=; b=gipVG7XyUvXbVbB//hpk7v7Wc8nwxS37Ae0FLKILfDG1JkDk+S0HL8NYBQUNBcVSEu WJDlURlN4vcO7H0oGax7y8cswukxu0VQYdGt6W3vYW4rQjXqTIjRi41je3AIEmhTOnjg 0SMPixZyjAQDj0iho6q1KDx20V9BJ1Y/fvK5YG1HHkVEWaZ9lCBRZN5yo/wfhnTTcCWB 8Qsu3PCeCVEz32CQNcUDvR74yk4+XriYUi8+OZAzIOPLHXHsKd0PDjXyQeKYyS/XSTcj rlSaBgUZitEYHah7ml34crxNNj2Nm8f5INX9mnEWFp+T8N71mPoXDK+Y0Q2VvYSekOHR W2QA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linux-foundation.org header.s=google header.b=cb52bxmh; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id ka25si18321402ejc.354.2021.07.07.11.51.00; Wed, 07 Jul 2021 11:51:23 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linux-foundation.org header.s=google header.b=cb52bxmh; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230154AbhGGR0g (ORCPT + 99 others); Wed, 7 Jul 2021 13:26:36 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:51614 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229949AbhGGR0g (ORCPT ); Wed, 7 Jul 2021 13:26:36 -0400 Received: from mail-lf1-x12f.google.com (mail-lf1-x12f.google.com [IPv6:2a00:1450:4864:20::12f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 02409C06175F for ; Wed, 7 Jul 2021 10:23:54 -0700 (PDT) Received: by mail-lf1-x12f.google.com with SMTP id v14so5845497lfb.4 for ; Wed, 07 Jul 2021 10:23:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux-foundation.org; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=r7YGSy37fYgov/nu/eHIw5R4NrzDeOEToKWhoVDtJ3Y=; b=cb52bxmhnl9yk2czoTUjGteBUzb+GDAVEHPn/4CGxQho2sqt0F1sr4FDWRsdYs5LKb Fp/T5Kh9W+LM9kbeJL+L94H+6L0TT3CQySegbIN7K7+Rb5XRLNbgg+KVDtTxE2YFjhjN fsOmYItJxVvsHLg+IUeqRHDhcgLQurF/BEUbg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=r7YGSy37fYgov/nu/eHIw5R4NrzDeOEToKWhoVDtJ3Y=; b=lik8W+QCHOBUqPvwy823H7FVc9nHGreMK7odSqOLAJn+R7nKV6bxtPioC+yUTJiaaM Qe1MxPL7nscwsj1kroVPFAZVtSAQrH9D7jjLiLyRzWtZ08cKKR9oH78LziodFlU1v6vH xG9Voy9OHq32IZi4UGNNFHIQ+bV9Yw/nKDAaXlk//2ON9yqNMi56qocdh/3U8dICmXRU rsVcMMcHq0XK3EUaZ7OrzfwEyW+/76KM/BmKbeh2S1bn2721bmG2w/OallVbFCiK4F5v 3ZwMB6UWgrGOX9wid5tImpriIgC9KgLMuDwUhvjAxegm6/VTuXTIpJ6XaFDb1QUTuFwh dRMQ== X-Gm-Message-State: AOAM5330X7/PFgqJOiSP8uh5B0VL2KAWrgEV7WDUeng9kpHbOkhmxSyU O67ZpJzwc3b41cFFX4IiCuQGWcXv9+kn+JAv X-Received: by 2002:ac2:4356:: with SMTP id o22mr20722097lfl.309.1625678632678; Wed, 07 Jul 2021 10:23:52 -0700 (PDT) Received: from mail-lf1-f54.google.com (mail-lf1-f54.google.com. [209.85.167.54]) by smtp.gmail.com with ESMTPSA id s16sm2102029lji.131.2021.07.07.10.23.51 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 07 Jul 2021 10:23:52 -0700 (PDT) Received: by mail-lf1-f54.google.com with SMTP id n14so5787168lfu.8 for ; Wed, 07 Jul 2021 10:23:51 -0700 (PDT) X-Received: by 2002:a19:7d04:: with SMTP id y4mr19433402lfc.201.1625678631269; Wed, 07 Jul 2021 10:23:51 -0700 (PDT) MIME-Version: 1.0 References: <20210702175442.1603082-1-legion@kernel.org> <20210707165008.tym4352uw3hu7uwp@example.org> In-Reply-To: <20210707165008.tym4352uw3hu7uwp@example.org> From: Linus Torvalds Date: Wed, 7 Jul 2021 10:23:35 -0700 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH] ucounts: Fix UCOUNT_RLIMIT_SIGPENDING counter leak To: Alexey Gladkov Cc: "Eric W. Biederman" , Linux Kernel Mailing List , Linux Containers Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Jul 7, 2021 at 9:50 AM Alexey Gladkov wrote: > > > + dec_rlimit_ucounts(ucounts, UCOUNT_RLIMIT_SIGPENDING, 1); > > + fallthrough; > > + case LONG_MAX: > > I think that the counter should be decreased in this case too. > inc_rlimit_ucounts() increments the counter in all parent userns. If we > don't decrease the counter then the parent userns will have a counter > leak. Ack. So basically that patch, but move the dec_rlimit_ucounts() into the LONG_MAX case? Would you mind making a real patch with a commit message, and trying whatever test-case you had for that KASAN use-after-free report? Linus