 260a459d2e
			
		
	
	
	260a459d2e
	
	
	
		
			
			A bug was introduced with the is_mounted helper function in
commit f7a99c5b7c
Author: Al Viro <viro@zeniv.linux.org.uk>
Date:   Sat Jun 9 00:59:08 2012 -0400
    get rid of ->mnt_longterm
    it's enough to set ->mnt_ns of internal vfsmounts to something
    distinct from all struct mnt_namespace out there; then we can
    just use the check for ->mnt_ns != NULL in the fast path of
    mntput_no_expire()
    Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
The intent was to test if the real_mount(vfsmount)->mnt_ns was
NULL_OR_ERR but the code is actually testing real_mount(vfsmount)
and always returning true.
The result is d_absolute_path returning paths it should be hiding.
Cc: stable@vger.kernel.org
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
		
	
			
		
			
				
	
	
		
			111 lines
		
	
	
	
		
			2.8 KiB
			
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			111 lines
		
	
	
	
		
			2.8 KiB
			
		
	
	
	
		
			C
		
	
	
	
	
	
| #include <linux/mount.h>
 | |
| #include <linux/seq_file.h>
 | |
| #include <linux/poll.h>
 | |
| 
 | |
| struct mnt_namespace {
 | |
| 	atomic_t		count;
 | |
| 	unsigned int		proc_inum;
 | |
| 	struct mount *	root;
 | |
| 	struct list_head	list;
 | |
| 	struct user_namespace	*user_ns;
 | |
| 	u64			seq;	/* Sequence number to prevent loops */
 | |
| 	wait_queue_head_t poll;
 | |
| 	int event;
 | |
| };
 | |
| 
 | |
| struct mnt_pcp {
 | |
| 	int mnt_count;
 | |
| 	int mnt_writers;
 | |
| };
 | |
| 
 | |
| struct mountpoint {
 | |
| 	struct list_head m_hash;
 | |
| 	struct dentry *m_dentry;
 | |
| 	int m_count;
 | |
| };
 | |
| 
 | |
| struct mount {
 | |
| 	struct list_head mnt_hash;
 | |
| 	struct mount *mnt_parent;
 | |
| 	struct dentry *mnt_mountpoint;
 | |
| 	struct vfsmount mnt;
 | |
| 	struct rcu_head mnt_rcu;
 | |
| #ifdef CONFIG_SMP
 | |
| 	struct mnt_pcp __percpu *mnt_pcp;
 | |
| #else
 | |
| 	int mnt_count;
 | |
| 	int mnt_writers;
 | |
| #endif
 | |
| 	struct list_head mnt_mounts;	/* list of children, anchored here */
 | |
| 	struct list_head mnt_child;	/* and going through their mnt_child */
 | |
| 	struct list_head mnt_instance;	/* mount instance on sb->s_mounts */
 | |
| 	const char *mnt_devname;	/* Name of device e.g. /dev/dsk/hda1 */
 | |
| 	struct list_head mnt_list;
 | |
| 	struct list_head mnt_expire;	/* link in fs-specific expiry list */
 | |
| 	struct list_head mnt_share;	/* circular list of shared mounts */
 | |
| 	struct list_head mnt_slave_list;/* list of slave mounts */
 | |
| 	struct list_head mnt_slave;	/* slave list entry */
 | |
| 	struct mount *mnt_master;	/* slave is on master->mnt_slave_list */
 | |
| 	struct mnt_namespace *mnt_ns;	/* containing namespace */
 | |
| 	struct mountpoint *mnt_mp;	/* where is it mounted */
 | |
| #ifdef CONFIG_FSNOTIFY
 | |
| 	struct hlist_head mnt_fsnotify_marks;
 | |
| 	__u32 mnt_fsnotify_mask;
 | |
| #endif
 | |
| 	int mnt_id;			/* mount identifier */
 | |
| 	int mnt_group_id;		/* peer group identifier */
 | |
| 	int mnt_expiry_mark;		/* true if marked for expiry */
 | |
| 	int mnt_pinned;
 | |
| 	struct path mnt_ex_mountpoint;
 | |
| };
 | |
| 
 | |
| #define MNT_NS_INTERNAL ERR_PTR(-EINVAL) /* distinct from any mnt_namespace */
 | |
| 
 | |
| static inline struct mount *real_mount(struct vfsmount *mnt)
 | |
| {
 | |
| 	return container_of(mnt, struct mount, mnt);
 | |
| }
 | |
| 
 | |
| static inline int mnt_has_parent(struct mount *mnt)
 | |
| {
 | |
| 	return mnt != mnt->mnt_parent;
 | |
| }
 | |
| 
 | |
| static inline int is_mounted(struct vfsmount *mnt)
 | |
| {
 | |
| 	/* neither detached nor internal? */
 | |
| 	return !IS_ERR_OR_NULL(real_mount(mnt)->mnt_ns);
 | |
| }
 | |
| 
 | |
| extern struct mount *__lookup_mnt(struct vfsmount *, struct dentry *);
 | |
| extern struct mount *__lookup_mnt_last(struct vfsmount *, struct dentry *);
 | |
| 
 | |
| extern bool legitimize_mnt(struct vfsmount *, unsigned);
 | |
| 
 | |
| static inline void get_mnt_ns(struct mnt_namespace *ns)
 | |
| {
 | |
| 	atomic_inc(&ns->count);
 | |
| }
 | |
| 
 | |
| extern seqlock_t mount_lock;
 | |
| 
 | |
| static inline void lock_mount_hash(void)
 | |
| {
 | |
| 	write_seqlock(&mount_lock);
 | |
| }
 | |
| 
 | |
| static inline void unlock_mount_hash(void)
 | |
| {
 | |
| 	write_sequnlock(&mount_lock);
 | |
| }
 | |
| 
 | |
| struct proc_mounts {
 | |
| 	struct seq_file m;
 | |
| 	struct mnt_namespace *ns;
 | |
| 	struct path root;
 | |
| 	int (*show)(struct seq_file *, struct vfsmount *);
 | |
| };
 | |
| 
 | |
| #define proc_mounts(p) (container_of((p), struct proc_mounts, m))
 | |
| 
 | |
| extern const struct seq_operations mounts_op;
 |