NFS: Use parent's objective cred in nfs_access_login_time()
authorScott Mayhew <smayhew@redhat.com>
Tue, 5 Dec 2023 14:10:54 +0000 (09:10 -0500)
committerAnna Schumaker <Anna.Schumaker@Netapp.com>
Thu, 4 Jan 2024 15:47:56 +0000 (10:47 -0500)
The subjective cred (task->cred) can potentially be overridden and
subsquently freed in non-RCU context, which could lead to a panic if we
try to use it in cred_fscmp().  Use __task_cred(), which returns the
objective cred (task->real_cred) instead.

Fixes: 0eb43812c027 ("NFS: Clear the file access cache upon login")
Fixes: 5e9a7b9c2ea1 ("NFS: Fix up a sparse warning")
Signed-off-by: Scott Mayhew <smayhew@redhat.com>
Signed-off-by: Anna Schumaker <Anna.Schumaker@Netapp.com>
fs/nfs/dir.c

index 13dffe4201e6e98fd1d6f3bb649cc6baaa89e17a..273c0b68abf4422998eb61a8117dae38279b2b26 100644 (file)
@@ -2963,7 +2963,7 @@ static u64 nfs_access_login_time(const struct task_struct *task,
        rcu_read_lock();
        for (;;) {
                parent = rcu_dereference(task->real_parent);
-               pcred = rcu_dereference(parent->cred);
+               pcred = __task_cred(parent);
                if (parent == task || cred_fscmp(pcred, cred) != 0)
                        break;
                task = parent;