Page MenuHomeFreeBSD

ufssuspend(4): mark non-passable
ClosedPublic

Authored by kib on Sun, Oct 4, 12:54 AM.
Tags
None
Referenced Files
F174907624: D60285.id188574.diff
Tue, Oct 6, 9:52 PM
F174887659: D60285.id188764.diff
Tue, Oct 6, 6:56 PM
F174874362: D60285.diff
Tue, Oct 6, 5:04 PM
F174865231: D60285.id188709.diff
Tue, Oct 6, 3:33 PM
F174816883: D60285.id188574.diff
Tue, Oct 6, 4:44 AM
Unknown Object (File)
Mon, Oct 5, 11:05 PM
Unknown Object (File)
Mon, Oct 5, 10:53 PM
Unknown Object (File)
Mon, Oct 5, 10:20 PM
Subscribers

Details

Summary
This fixes long-standing issue where ufssuspend file descriptor could
leak over fork or be passed over unix domain socket, and then closing it
in the opener would not unsuspend the file system.

It should not affect the well-behaving growfs(8) utility, but makes the
userspace API safer on principle.

Tested by: pho

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

kib requested review of this revision.Sun, Oct 4, 12:54 AM
sys/ufs/ffs/ffs_suspend.c
354 ↗(On Diff #188574)

Can we instead provide a devfs_ops_nonpassable_f table from devfs? I suspect this is not the only device file which needs this treatment. I even wonder if non-passable should be the default.

kib marked an inline comment as done.
cdevsw: add D_NONPASSABLE flag

to make the opened device files non-passable.
markj added inline comments.
sys/sys/conf.h
180
This revision is now accepted and ready to land.Mon, Oct 5, 2:21 PM
This revision was automatically updated to reflect the committed changes.