On Sun, Aug 13, 2017 at 05:20:05PM -0400, Ted Unangst wrote:
> - if (nmp->nm_sotype != SOCK_STREAM)
> - panic("nfscon sotype");
> + } else {
> + panic("nfscon sotype");
This panic can be reached from user land with a manipulated mount_nfs
program. This happens without you diff.
panic: nfscon sotype
Stopped at db_enter+0x5: popq %rbp
TID PID UID PRFLAGS PFLAGS CPU COMMAND
* 39774 67297 0 0x3 0 0 mount_nfs
db_enter(10,ffff800003b18890,202,8,ffffffff81251c35,0) at db_enter+0x5
panic(ffffff00020b1648,ffff8000003b9698,ffff8000003b9600,0,0,ffff800003b188a0) a
t panic+0x128
nfs_connect(0,3,ffff8000003b9600,ffff800003b18a48,ffffff00060e3010,ffffff000000
0000) at nfs_connect+0x557
nfs_receive(ffffff00060e3010,ffff8000003b9600,ffff800003b18b90,ffff800003b18a38
,ffff8000003b9640,284bfabeb69b780e) at nfs_receive+0x2c5
nfs_reply(32,ffffff00060e3010,ffff800003b18b90,ffff8000003b9600,ffff8000003b964
0,284bfabeb69b780e) at nfs_reply+0x7f
nfs_request(ffff800003b12028,ffff8000003b9600,ffff800003b18b90,ffffff00077cab40
,ffffff00058c5d28,284bfabeb69b780e) at nfs_request+0x327
nfs_fsinfo(0,ffff800003b12028,ffffff00058c5d28,ffff8000003b9600,200,284bfabeb69
b780e) at nfs_fsinfo+0x6f
nfs_statfs(ffff8000003bf000,ffffff00051c7718,ffff8000003bf000,ffff800003b12028,
0,284bfabeb69b780e) at nfs_statfs+0xae
sys_mount(ffff800003b18f20,150,ffff800003b12028,15,ffffffff81a9a2d0,284bfabeb69
b780e) at sys_mount+0x468
syscall() at syscall+0x1e4
--- syscall (number 21) ---
We should return an EPROTONOSUPPORT error here or should do propper
input validation in the nfs mount system call.
bluhm