mirror of
https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9.git
synced 2026-09-09 06:12:00 +08:00
JIRA: https://redhat.atlassian.net/browse/RHEL-180666 ``` commit 7987cce375ac8ce98e170a77aa2399f2cf6eb99f Author: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com> Date: Tue Feb 3 14:54:46 2026 -0800 ceph: fix NULL pointer dereference in ceph_mds_auth_match() The CephFS kernel client has regression starting from 6.18-rc1. We have issue in ceph_mds_auth_match() if fs_name == NULL: const char fs_name = mdsc->fsc->mount_options->mds_namespace; ... if (auth->match.fs_name && strcmp(auth->match.fs_name, fs_name)) { / fsname mismatch, try next one */ return 0; } Patrick Donnelly suggested that: In summary, we should definitely start decoding `fs_name` from the MDSMap and do strict authorizations checks against it. Note that the `-o mds_namespace=foo` should only be used for selecting the file system to mount and nothing else. It's possible no mds_namespace is specified but the kernel will mount the only file system that exists which may have name "foo". This patch reworks ceph_mdsmap_decode() and namespace_equals() with the goal of supporting the suggested concept. Now struct ceph_mdsmap contains m_fs_name field that receives copy of extracted FS name by ceph_extract_encoded_string(). For the case of "old" CephFS file systems, it is used "cephfs" name. [ idryomov: replace redundant %*pE with %s in ceph_mdsmap_decode(), get rid of a series of strlen() calls in ceph_namespace_match(), drop changes to namespace_equals() body to avoid treating empty mds_namespace as equal, drop changes to ceph_mdsc_handle_fsmap() as namespace_equals() isn't an equivalent substitution there ] Cc: stable@vger.kernel.org Fixes: 22c73d52a6d0 ("ceph: fix multifs mds auth caps issue") Link: https://tracker.ceph.com/issues/73886 Signed-off-by: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com> Reviewed-by: Patrick Donnelly <pdonnell@ibm.com> Tested-by: Patrick Donnelly <pdonnell@ibm.com> Signed-off-by: Ilya Dryomov <idryomov@gmail.com> ``` [Conflicts] fs/ceph/mds_client.c: - struct ceph_client *cl variable absent from ceph_mds_auth_match() scope; dout(...) context vs upstream doutc(cl, ...): tree-wide logging conversion not in RHEL9 fs/ceph/mdsmap.c: - pr_warn_client(cl, ...) -> pr_warn(...): tree-wide logging conversion not in RHEL9 include/linux/ceph/mdsmap.h: - Upstream has the CephFS mdsmap declaration under fs/ceph/mdsmap.h; RHEL9 keeps it in include/linux/ceph/mdsmap.h Signed-off-by: Alex Markuze <amarkuze@redhat.com>