Files
Centos-kernel-stream-9/include/linux/ceph
Alex Markuze 56eed7d87f ceph: fix NULL pointer dereference in ceph_mds_auth_match()
JIRA: https://redhat.atlassian.net/browse/RHEL-180666

```
commit 7987cce375ac8ce98e170a77aa2399f2cf6eb99f
Author: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com>
Date:   Tue Feb 3 14:54:46 2026 -0800

    ceph: fix NULL pointer dereference in ceph_mds_auth_match()

    The CephFS kernel client has regression starting from 6.18-rc1.
    We have issue in ceph_mds_auth_match() if fs_name == NULL:

        const char fs_name = mdsc->fsc->mount_options->mds_namespace;
        ...
        if (auth->match.fs_name && strcmp(auth->match.fs_name, fs_name)) {
                / fsname mismatch, try next one */
                return 0;
        }

    Patrick Donnelly suggested that: In summary, we should definitely start
    decoding `fs_name` from the MDSMap and do strict authorizations checks
    against it. Note that the `-o mds_namespace=foo` should only be used for
    selecting the file system to mount and nothing else. It's possible
    no mds_namespace is specified but the kernel will mount the only
    file system that exists which may have name "foo".

    This patch reworks ceph_mdsmap_decode() and namespace_equals() with
    the goal of supporting the suggested concept. Now struct ceph_mdsmap
    contains m_fs_name field that receives copy of extracted FS name
    by ceph_extract_encoded_string(). For the case of "old" CephFS file
    systems, it is used "cephfs" name.

    [ idryomov: replace redundant %*pE with %s in ceph_mdsmap_decode(),
      get rid of a series of strlen() calls in ceph_namespace_match(),
      drop changes to namespace_equals() body to avoid treating empty
      mds_namespace as equal, drop changes to ceph_mdsc_handle_fsmap()
      as namespace_equals() isn't an equivalent substitution there ]

    Cc: stable@vger.kernel.org
    Fixes: 22c73d52a6d0 ("ceph: fix multifs mds auth caps issue")
    Link: https://tracker.ceph.com/issues/73886
    Signed-off-by: Viacheslav Dubeyko <Slava.Dubeyko@ibm.com>
    Reviewed-by: Patrick Donnelly <pdonnell@ibm.com>
    Tested-by: Patrick Donnelly <pdonnell@ibm.com>
    Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
```

[Conflicts]
fs/ceph/mds_client.c:
 - struct ceph_client *cl variable absent from ceph_mds_auth_match()
   scope; dout(...) context vs upstream doutc(cl, ...): tree-wide
   logging conversion not in RHEL9
fs/ceph/mdsmap.c:
 - pr_warn_client(cl, ...) -> pr_warn(...): tree-wide logging conversion not
   in RHEL9
include/linux/ceph/mdsmap.h:
 - Upstream has the CephFS mdsmap declaration under fs/ceph/mdsmap.h;
   RHEL9 keeps it in include/linux/ceph/mdsmap.h

Signed-off-by: Alex Markuze <amarkuze@redhat.com>
2026-06-30 12:40:43 +00:00
..