]> www.infradead.org Git - users/dwmw2/linux.git/commitdiff
proc: block mounting on top of /proc/<pid>/fdinfo/*
authorChristian Brauner <brauner@kernel.org>
Tue, 6 Aug 2024 16:02:32 +0000 (18:02 +0200)
committerChristian Brauner <brauner@kernel.org>
Fri, 30 Aug 2024 06:22:13 +0000 (08:22 +0200)
Entries under /proc/<pid>/fdinfo/* are ephemeral and may go away before
the process dies. As such allowing them to be used as mount points
creates the ability to leak mounts that linger until the process dies
with no ability to unmount them until then. Don't allow using them as
mountpoints.

Link: https://lore.kernel.org/r/20240806-work-procfs-v1-6-fb04e1d09f0c@kernel.org
Reviewed-by: Josef Bacik <josef@toxicpanda.com>
Signed-off-by: Christian Brauner <brauner@kernel.org>
fs/proc/fd.c

index 671a45884304cdd006e0371b09d4ad76cd829439..623780449c484391b326c3196a85f63208d5a1fc 100644 (file)
@@ -397,8 +397,8 @@ static struct dentry *proc_fdinfo_instantiate(struct dentry *dentry,
        inode->i_fop = &proc_fdinfo_file_operations;
        tid_fd_update_inode(task, inode, 0);
 
-       d_set_d_op(dentry, &tid_fd_dentry_operations);
-       return d_splice_alias(inode, dentry);
+       return proc_splice_unmountable(inode, dentry,
+                                      &tid_fd_dentry_operations);
 }
 
 static struct dentry *