mirror of
https://github.com/torvalds/linux.git
synced 2026-09-13 15:40:03 +02:00
exec: Drop bprm loader before closing bprm->file
free_bprm() currently drops what may be the final reference to bprm->file before calling bprm_drop_loader(). Since bprm_drop_loader() is attachable via BPF fentry and bprm->file is exposed as a BTF_TYPE_SAFE_TRUSTED pointer, the file can be observed after its reference has been released. Move bprm_drop_loader() before do_close_execat(bprm->file), keeping the file reference held while the hook runs. This preserves the existing trusted BTF contract without changing verifier behavior. The loader file and bprm->file have independent references, so this reordering does not change their required teardown ordering. Link: https://sashiko.dev/#/patchset/20260831092305.42062-1-tasos.papagiannnis@gmail.com?part=3 Signed-off-by: Sun Jian <sun.jian.kdev@gmail.com> Link: https://patch.msgid.link/20260901114011.112375-1-sun.jian.kdev@gmail.com Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
This commit is contained in:
parent
e14d4302cb
commit
115bf3e515
|
|
@ -1469,9 +1469,9 @@ static void free_bprm(struct linux_binprm *bprm)
|
|||
/* exec swapped the mm but failed before setup_new_exec() freed it */
|
||||
if (bprm->old_mm)
|
||||
exec_mm_put_old(bprm->old_mm);
|
||||
do_close_execat(bprm->file);
|
||||
/* An unconsumed PT_INTERP substitute from a binfmt_misc loader entry. */
|
||||
bprm_drop_loader(bprm);
|
||||
do_close_execat(bprm->file);
|
||||
do_close_execat(bprm->executable);
|
||||
/* If a binfmt changed the interp, free it. */
|
||||
if (bprm->interp != bprm->filename)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user