svn commit: r316925 - vendor-sys/illumos/dist/uts/common/fs/zfs

Andriy Gapon avg at FreeBSD.org
Fri Apr 14 18:33:22 UTC 2017


Author: avg
Date: Fri Apr 14 18:33:20 2017
New Revision: 316925
URL: https://svnweb.freebsd.org/changeset/base/316925

Log:
  6101 attempt to lzc_create() a filesystem under a volume results in a panic
  
  illumos/illumos-gate at b127fe3c059af7adf772735498680b4f2e1405ef
  https://github.com/illumos/illumos-gate/commit/b127fe3c059af7adf772735498680b4f2e1405ef
  
  https://www.illumos.org/issues/6101
    lzc_create(), or more correctly, zfs_ioc_create() does not reject an attempt to
    create a filesystem as a child of a volume, instead it proceeds to a crash.
    A crash stack obtained on FreeBSD:
    page fault while in kernel mode
  
    zap_leaf_lookup()
    fzap_lookup()
    zap_lookup_norm()
    zap_lookup()
    zfs_get_zplprop()
    zfs_fill_zplprops_impl()
    zfs_ioc_create()
    zfsdev_ioctl()
    devfs_ioctl_f()
    kern_ioctl()
    sys_ioctl()
    This crash happened with a kernel without debugging assertions.
    The immediate cause of crash appears to an attempt to interpret a zvol object
    as a zap object.
    For filesystems:
    #define MASTER_NODE_OBJ 1
    For zvols:
    #define ZVOL_OBJ                1ULL
    #define ZVOL_ZAP_OBJ            2ULL
    So, I see two problems here:
       1. an attempt to create a filesystem under a zvol should be rejected as
          early as possible, maybe in zfs_fill_zplprops()
       2. maybe zap_lookup / zap_lockdir should reject objects that are not of one
          of the zap object types
  
  Reviewed by: Matthew Ahrens <mahrens at delphix.com>
  Approved by: Dan McDonald <danmcd at omniti.com>
  Author: Andriy Gapon <avg at FreeBSD.org>

Modified:
  vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_ioctl.c
  vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_vfsops.c

Modified: vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_ioctl.c
==============================================================================
--- vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_ioctl.c	Fri Apr 14 18:32:38 2017	(r316924)
+++ vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_ioctl.c	Fri Apr 14 18:33:20 2017	(r316925)
@@ -3035,6 +3035,9 @@ zfs_fill_zplprops_impl(objset_t *os, uin
 
 	ASSERT(zplprops != NULL);
 
+	if (os != NULL && os->os_phys->os_type != DMU_OST_ZFS)
+		return (SET_ERROR(EINVAL));
+
 	/*
 	 * Pull out creator prop choices, if any.
 	 */

Modified: vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_vfsops.c
==============================================================================
--- vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_vfsops.c	Fri Apr 14 18:32:38 2017	(r316924)
+++ vendor-sys/illumos/dist/uts/common/fs/zfs/zfs_vfsops.c	Fri Apr 14 18:33:20 2017	(r316925)
@@ -2243,8 +2243,10 @@ zfs_get_zplprop(objset_t *os, zfs_prop_t
 	else
 		pname = zfs_prop_to_name(prop);
 
-	if (os != NULL)
+	if (os != NULL) {
+		ASSERT3U(os->os_phys->os_type, ==, DMU_OST_ZFS);
 		error = zap_lookup(os, MASTER_NODE_OBJ, pname, 8, 1, value);
+	}
 
 	if (error == ENOENT) {
 		/* No value set, use the default value */


More information about the svn-src-all mailing list