]> www.infradead.org Git - users/jedix/linux-maple.git/commit
unix: correctly track in-flight fds in sending process user_struct
authorHannes Frederic Sowa <hannes@stressinduktion.org>
Wed, 3 Feb 2016 01:11:03 +0000 (02:11 +0100)
committerChuck Anderson <chuck.anderson@oracle.com>
Thu, 26 May 2016 22:45:18 +0000 (15:45 -0700)
commite270c7d34f0db877b2aa9e814fe131416b8d9f0d
tree8ba32574418a6e76c6cee81e27027a60b9dbba05
parent53b806295d2ea29f7ba0b35166d153af981a7412
unix: correctly track in-flight fds in sending process user_struct

Orabug: 23330946

[ Upstream commit 415e3d3e90ce9e18727e8843ae343eda5a58fad6 ]

The commit referenced in the Fixes tag incorrectly accounted the number
of in-flight fds over a unix domain socket to the original opener
of the file-descriptor. This allows another process to arbitrary
deplete the original file-openers resource limit for the maximum of
open files. Instead the sending processes and its struct cred should
be credited.

To do so, we add a reference counted struct user_struct pointer to the
scm_fp_list and use it to account for the number of inflight unix fds.

Fixes: 712f4aad406bb1 ("unix: properly account for FDs passed over unix sockets")
Reported-by: David Herrmann <dh.herrmann@gmail.com>
Cc: David Herrmann <dh.herrmann@gmail.com>
Cc: Willy Tarreau <w@1wt.eu>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
(cherry picked from commit 797c009c98dbb21127a2549d1106ed19d18661cf)

Signed-off-by: Dan Duval <dan.duval@oracle.com>
include/net/af_unix.h
include/net/scm.h
net/core/scm.c
net/unix/af_unix.c
net/unix/garbage.c