From 4cbf9dc0b36d57ea6dca37d790a932129a6f9adf Mon Sep 17 00:00:00 2001 From: Tomas Bzatek Date: Thu, 19 Jun 2025 16:04:17 +0200 Subject: [PATCH 1/2] * Thu Jun 19 2025 Tomas Bzatek - 2.10.1-7 - Harden temporary private mounts (#2373301) --- ...slinuxfilesystemhelpers_nodev,nosuid.patch | 43 +++++++++++++++++++ udisks2.spec | 7 ++- 2 files changed, 49 insertions(+), 1 deletion(-) create mode 100644 udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch diff --git a/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch b/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch new file mode 100644 index 0000000..d6b0f9a --- /dev/null +++ b/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch @@ -0,0 +1,43 @@ +From 5e7277debea926370e587408517560afe87d28c9 Mon Sep 17 00:00:00 2001 +From: Tomas Bzatek +Date: Wed, 4 Jun 2025 15:26:46 +0200 +Subject: [PATCH] udiskslinuxfilesystemhelpers: Mount private mounts with + 'nodev,nosuid' + +The private mount done in take_filesystem_ownership() should always +default to 'nodev,nosuid' for security and 'errors=remount-ro' for +selected filesystem types to handle an corrupted filesystem. This is +consistent with mount options calculation for regular mounts. +--- + src/udiskslinuxfilesystemhelpers.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/src/udiskslinuxfilesystemhelpers.c b/src/udiskslinuxfilesystemhelpers.c +index 7c5fc037c4..9eb7742c77 100644 +--- a/src/udiskslinuxfilesystemhelpers.c ++++ b/src/udiskslinuxfilesystemhelpers.c +@@ -123,6 +123,7 @@ take_filesystem_ownership (const gchar *device, + + { + gchar *mountpoint = NULL; ++ const gchar *mount_opts; + GError *local_error = NULL; + gboolean unmount = FALSE; + gboolean success = TRUE; +@@ -151,8 +152,15 @@ take_filesystem_ownership (const gchar *device, + goto out; + } + ++ mount_opts = "nodev,nosuid"; ++ if (g_strcmp0 (fstype, "ext2") == 0 || ++ g_strcmp0 (fstype, "ext3") == 0 || ++ g_strcmp0 (fstype, "ext4") == 0 || ++ g_strcmp0 (fstype, "jfs") == 0) ++ mount_opts = "nodev,nosuid,errors=remount-ro"; ++ + /* TODO: mount to a private mount namespace */ +- if (!bd_fs_mount (device, mountpoint, fstype, NULL, NULL, &local_error)) ++ if (!bd_fs_mount (device, mountpoint, fstype, mount_opts, NULL, &local_error)) + { + g_set_error (error, UDISKS_ERROR, UDISKS_ERROR_FAILED, + "Cannot mount %s at %s: %s", diff --git a/udisks2.spec b/udisks2.spec index 0f0e534..c9dbbf5 100644 --- a/udisks2.spec +++ b/udisks2.spec @@ -26,7 +26,7 @@ Name: udisks2 Summary: Disk Manager Version: 2.10.1 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-or-later URL: https://github.com/storaged-project/udisks Source0: https://github.com/storaged-project/udisks/releases/download/udisks-%{version}/udisks-%{version}.tar.bz2 @@ -35,6 +35,8 @@ Patch0: udisks-2.11.0-BLKRRPART_harder.patch Patch1: udisks-2.11.0-targetcli_config.json_netif_timeout.patch Patch2: udisks-2.11.0-udiskslinuxmanager_use_after_free.patch Patch3: udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch +# https://bugzilla.redhat.com/show_bug.cgi?id=2373301 +Patch4: udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch BuildRequires: make BuildRequires: glib2-devel >= %{glib2_version} @@ -342,6 +344,9 @@ fi %endif %changelog +* Thu Jun 19 2025 Tomas Bzatek - 2.10.1-7 +- Harden temporary private mounts (#2373301) + * Sat Jul 20 2024 Fedora Release Engineering - 2.10.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From d2361d2b6bb5510998ad0031ab59da8834a1640d Mon Sep 17 00:00:00 2001 From: Tomas Bzatek Date: Fri, 29 Aug 2025 14:59:36 +0200 Subject: [PATCH 2/2] * Fri Aug 29 2025 Tomas Bzatek - 2.10.2-1 - Version 2.10.2 --- .gitignore | 1 + sources | 2 +- ...slinuxfilesystemhelpers_nodev,nosuid.patch | 43 ------- ...-targetcli_config.json_netif_timeout.patch | 38 ------ ...iskslinuxblock_survive_missing_fstab.patch | 32 ----- ....0-udiskslinuxmanager_use_after_free.patch | 112 ------------------ udisks2.spec | 12 +- 7 files changed, 7 insertions(+), 233 deletions(-) delete mode 100644 udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch delete mode 100644 udisks-2.11.0-targetcli_config.json_netif_timeout.patch delete mode 100644 udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch delete mode 100644 udisks-2.11.0-udiskslinuxmanager_use_after_free.patch diff --git a/.gitignore b/.gitignore index 148ecf9..b25dc22 100644 --- a/.gitignore +++ b/.gitignore @@ -19,3 +19,4 @@ /udisks-2.9.4.tar.bz2 /udisks-2.10.0.tar.bz2 /udisks-2.10.1.tar.bz2 +/udisks-2.10.2.tar.bz2 diff --git a/sources b/sources index 3712713..46f6d57 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (udisks-2.10.1.tar.bz2) = 9cdaeca4306a970c85f88d406dbe5d2dad23d72f47d9ab1c021b8c2888d4c790f680eb94388d86f9255024283b4a36e98b8aee4408d193a7d4aad1e74463356a +SHA512 (udisks-2.10.2.tar.bz2) = 8b2fb6d5a9b5c040f315073d0890cde2cad67f06684e607a31636012a515ec798c2129c3dbc8fcd6655d72b7b4a9485172e5e85795a0aeb4ff20a5ea76e690a8 diff --git a/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch b/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch deleted file mode 100644 index d6b0f9a..0000000 --- a/udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 5e7277debea926370e587408517560afe87d28c9 Mon Sep 17 00:00:00 2001 -From: Tomas Bzatek -Date: Wed, 4 Jun 2025 15:26:46 +0200 -Subject: [PATCH] udiskslinuxfilesystemhelpers: Mount private mounts with - 'nodev,nosuid' - -The private mount done in take_filesystem_ownership() should always -default to 'nodev,nosuid' for security and 'errors=remount-ro' for -selected filesystem types to handle an corrupted filesystem. This is -consistent with mount options calculation for regular mounts. ---- - src/udiskslinuxfilesystemhelpers.c | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/src/udiskslinuxfilesystemhelpers.c b/src/udiskslinuxfilesystemhelpers.c -index 7c5fc037c4..9eb7742c77 100644 ---- a/src/udiskslinuxfilesystemhelpers.c -+++ b/src/udiskslinuxfilesystemhelpers.c -@@ -123,6 +123,7 @@ take_filesystem_ownership (const gchar *device, - - { - gchar *mountpoint = NULL; -+ const gchar *mount_opts; - GError *local_error = NULL; - gboolean unmount = FALSE; - gboolean success = TRUE; -@@ -151,8 +152,15 @@ take_filesystem_ownership (const gchar *device, - goto out; - } - -+ mount_opts = "nodev,nosuid"; -+ if (g_strcmp0 (fstype, "ext2") == 0 || -+ g_strcmp0 (fstype, "ext3") == 0 || -+ g_strcmp0 (fstype, "ext4") == 0 || -+ g_strcmp0 (fstype, "jfs") == 0) -+ mount_opts = "nodev,nosuid,errors=remount-ro"; -+ - /* TODO: mount to a private mount namespace */ -- if (!bd_fs_mount (device, mountpoint, fstype, NULL, NULL, &local_error)) -+ if (!bd_fs_mount (device, mountpoint, fstype, mount_opts, NULL, &local_error)) - { - g_set_error (error, UDISKS_ERROR, UDISKS_ERROR_FAILED, - "Cannot mount %s at %s: %s", diff --git a/udisks-2.11.0-targetcli_config.json_netif_timeout.patch b/udisks-2.11.0-targetcli_config.json_netif_timeout.patch deleted file mode 100644 index e40f136..0000000 --- a/udisks-2.11.0-targetcli_config.json_netif_timeout.patch +++ /dev/null @@ -1,38 +0,0 @@ -From acae6bf4594f80da57855343ab325f87386178c4 Mon Sep 17 00:00:00 2001 -From: Tomas Bzatek -Date: Fri, 3 Nov 2023 16:40:54 +0100 -Subject: [PATCH] tests: Fix targetcli_config.json - -Not all attributes are available anymore in newer kernel versions. ---- - src/tests/dbus-tests/targetcli_config.json | 3 --- - 1 file changed, 3 deletions(-) - -diff --git a/src/tests/dbus-tests/targetcli_config.json b/src/tests/dbus-tests/targetcli_config.json -index 3be9eac2be..f50bf7d4d2 100644 ---- a/src/tests/dbus-tests/targetcli_config.json -+++ b/src/tests/dbus-tests/targetcli_config.json -@@ -331,7 +331,6 @@ - "demo_mode_write_protect": 0, - "generate_node_acls": 1, - "login_timeout": 15, -- "netif_timeout": 2, - "prod_mode_write_protect": 0, - "t10_pi": 0, - "tpg_enabled_sendtargets": 1 -@@ -393,7 +392,6 @@ - "demo_mode_write_protect": 1, - "generate_node_acls": 0, - "login_timeout": 15, -- "netif_timeout": 2, - "prod_mode_write_protect": 0, - "t10_pi": 0, - "tpg_enabled_sendtargets": 1 -@@ -479,7 +477,6 @@ - "demo_mode_write_protect": 1, - "generate_node_acls": 0, - "login_timeout": 15, -- "netif_timeout": 2, - "prod_mode_write_protect": 0, - "t10_pi": 0, - "tpg_enabled_sendtargets": 1 diff --git a/udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch b/udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch deleted file mode 100644 index 9acd8bd..0000000 --- a/udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 8f62f7c6888659f3b66d5861d46fb9b3a34ff169 Mon Sep 17 00:00:00 2001 -From: Marius Vollmer -Date: Thu, 22 Feb 2024 16:49:24 +0200 -Subject: [PATCH] udiskslinuxblock: Survive a missing /etc/fstab - -This is similar to b79f6840ca82551e672156153b7e13328f0ba19d, which -solved the same problem for /etc/crypttab. ---- - src/udiskslinuxblock.c | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/src/udiskslinuxblock.c b/src/udiskslinuxblock.c -index 829dd5f78..a3fa183be 100644 ---- a/src/udiskslinuxblock.c -+++ b/src/udiskslinuxblock.c -@@ -1541,7 +1541,15 @@ add_remove_fstab_entry (UDisksBlock *block, - &contents, - NULL, - error)) -- goto out; -+ { -+ if (g_error_matches (*error, G_FILE_ERROR, G_FILE_ERROR_NOENT)) -+ { -+ contents = g_strdup (""); -+ g_clear_error (error); -+ } -+ else -+ goto out; -+ } - - lines = g_strsplit (contents, "\n", 0); - diff --git a/udisks-2.11.0-udiskslinuxmanager_use_after_free.patch b/udisks-2.11.0-udiskslinuxmanager_use_after_free.patch deleted file mode 100644 index 3157b10..0000000 --- a/udisks-2.11.0-udiskslinuxmanager_use_after_free.patch +++ /dev/null @@ -1,112 +0,0 @@ -From 3dc036fb5045fc068c6abfbe4e62d0871d7ca82a Mon Sep 17 00:00:00 2001 -From: xinpeng wang -Date: Thu, 21 Sep 2023 13:57:40 +0800 -Subject: [PATCH] udiskslinuxmanager:use dbus interface after free - -In handle_get_block_devices, call get_block_objects to obtain iface_block_device -of all current UDisksLinuxBlockObject, and then obtain the corresponding -UDisksLinuxBlockObject's object_path through iface_block_device.iface_block_device -is a GDBusInterfaceSkeleton, which saves the object through -g_dbus_interface_skeleton_set_object. g_object_add_weak_pointer is used here. This -function is not thread-safe.At this time, if other threads are releasing the object, -the program will crash. -This scene can be reproduced by quickly plugging and unplugging the USB disk. -The core is as follows (the redundant stack is omitted): -When accessing object in thread 1, the object is released by thread 2 -info threads - Id Target Id Frame -* 1 Thread 0x7f80979e70 (LWP 24559) 0x0000007f8a48dda0 in -g_dbus_object_get_object_path (object=0x0) at ../../../gio/gdbusobject.c:109 - 2 Thread 0x7f88a43010 (LWP 1159) 0x0000007f8a0a6ae8 in __GI___libc_free -(mem=0x556a919c80) at malloc.c:3093 - -thread 1 -(gdb) bt -0 0x0000007f8a48dda0 in g_dbus_object_get_object_path (object=0x0) at -../../../gio/gdbusobject.c:109 -1 0x000000556a56911c in handle_get_block_devices (object=0x7f7c007ed0, invocation= -0x7f74016f20 [GDBusMethodInvocation], arg_options=) - at udiskslinuxmanager.c:1063 - -(gdb) p ((GObject*)(blocks_p->data))->ref_count -$3 = 1 -(gdb) p *((GDBusInterfaceSkeleton*)(blocks_p->data)) -$6 = {parent_instance = {g_type_instance = {g_class = 0x556a64e740 -[g_type: UDisksLinuxBlock/UDisksBlockSkeleton/GDBusInterfaceSkeleton]}, ref_count = 1, -qdata = 0x0}, priv = 0x7f7c004ac0} -(gdb) p *((GDBusInterfaceSkeleton*)(blocks_p->data))->priv -$7 = {lock = {p = 0x0, i = {0, 0}}, object = 0x0, -flags = G_DBUS_INTERFACE_SKELETON_FLAGS_HANDLE_METHOD_INVOCATIONS_IN_THREAD, -connections = 0x0, object_path = 0x0, hooked_vtable = 0x556a62b9f0} - -thread 2 -(gdb) bt -0 0x0000007f8a0a6ae8 in __GI___libc_free (mem=0x556a919c80) at malloc.c:3093 -1 0x0000007f89ff1224 in () at /lib/aarch64-linux-gnu/libudev.so.1 -2 0x0000007f89ff1348 in () at /lib/aarch64-linux-gnu/libudev.so.1 -3 0x0000007f89ff5520 in () at /lib/aarch64-linux-gnu/libudev.so.1 -4 0x0000007f89fff878 in udev_device_unref () at /lib/aarch64-linux-gnu/libudev.so.1 -5 0x0000007f8a7aeb74 in () at /lib/aarch64-linux-gnu/libgudev-1.0.so.0 -6 0x0000007f8a3193f8 in g_object_unref (_object=) at -../../../gobject/gobject.c:3346 -7 0x0000007f8a3193f8 in g_object_unref (_object=0x7f680038a0) at -../../../gobject/gobject.c:3238 -8 0x000000556a57700c in udisks_linux_device_finalize (object=0x7f5c005730 -[UDisksLinuxDevice]) at udiskslinuxdevice.c:75 -9 0x0000007f8a3193f8 in g_object_unref (_object=) at -../../../gobject/gobject.c:3346 -10 0x0000007f8a3193f8 in g_object_unref (_object=0x7f5c005730) at -../../../gobject/gobject.c:3238 -11 0x000000556a55d0fc in udisks_linux_drive_object_uevent - (object=object@entry=0x556a5df370 [UDisksLinuxDriveObject], -action=action@entry=0x556a87b120 -"remove",device=device@entry=0x7f74007610 [UDisksLinuxDevice]) - at udiskslinuxdriveobject.c:715 -12 0x000000556a54840c in handle_block_uevent_for_drive - (provider=provider@entry=0x556a5c8200 [UDisksLinuxProvider], -action=action@entry=0x556a87b120 "remove",device=device@entry=0x7f74007610 -[UDisksLinuxDevice]) at udiskslinuxprovider.c:1035 -13 0x000000556a548ab8 in handle_block_uevent (device=0x7f74007610 [UDisksLinuxDevice], -action=0x556a87b120 "remove", provider=0x556a5c8200 [UDisksLinuxProvider]) at -udiskslinuxprovider.c:1349 -14 0x000000556a548ab8 in udisks_linux_provider_handle_uevent - (provider=0x556a5c8200 [UDisksLinuxProvider], action=0x556a87b120 "remove", -device=0x7f74007610 [UDisksLinuxDevice]) at udiskslinuxprovider.c:1399 -15 0x000000556a548cac in on_idle_with_probed_uevent (user_data=0x556a7e65a0) at -udiskslinuxprovider.c:230 ---- - src/udiskslinuxmanager.c | 13 +++++++++---- - 1 file changed, 9 insertions(+), 4 deletions(-) - -diff --git a/src/udiskslinuxmanager.c b/src/udiskslinuxmanager.c -index 5bfeec103..491edb92b 100644 ---- a/src/udiskslinuxmanager.c -+++ b/src/udiskslinuxmanager.c -@@ -1196,8 +1196,11 @@ handle_get_block_devices (UDisksManager *object, - blocks = get_block_objects (object, &num_blocks); - block_paths = g_new0 (const gchar *, num_blocks + 1); - -- for (i = 0,blocks_p = blocks; blocks_p != NULL; blocks_p = blocks_p->next, i++) -- block_paths[i] = g_dbus_object_get_object_path (g_dbus_interface_get_object (G_DBUS_INTERFACE (blocks_p->data))); -+ for (blocks_p = blocks; blocks_p != NULL; blocks_p = blocks_p->next) { -+ GDBusObject * block_object = g_dbus_interface_get_object (G_DBUS_INTERFACE (blocks_p->data)); -+ if (block_object) -+ block_paths[i++] = g_dbus_object_get_object_path (block_object); -+ } - - udisks_manager_complete_get_block_devices (object, - invocation, -@@ -1284,9 +1287,11 @@ handle_resolve_device (UDisksManager *object, - } - - ret_paths = g_new0 (const gchar *, num_found + 1); -- for (i = 0,ret_p = ret; ret_p != NULL; ret_p = ret_p->next, i++) -+ for (i = 0,ret_p = ret; ret_p != NULL; ret_p = ret_p->next) - { -- ret_paths[i] = g_dbus_object_get_object_path (g_dbus_interface_get_object (G_DBUS_INTERFACE (ret_p->data))); -+ GDBusObject *block_object = g_dbus_interface_get_object (G_DBUS_INTERFACE (ret_p->data)); -+ if (block_object) -+ ret_paths[i++] = g_dbus_object_get_object_path (block_object); - } - - udisks_manager_complete_resolve_device (object, diff --git a/udisks2.spec b/udisks2.spec index c9dbbf5..96d4060 100644 --- a/udisks2.spec +++ b/udisks2.spec @@ -25,18 +25,13 @@ Name: udisks2 Summary: Disk Manager -Version: 2.10.1 -Release: 7%{?dist} +Version: 2.10.2 +Release: 1%{?dist} License: GPL-2.0-or-later URL: https://github.com/storaged-project/udisks Source0: https://github.com/storaged-project/udisks/releases/download/udisks-%{version}/udisks-%{version}.tar.bz2 Patch0: udisks-2.11.0-BLKRRPART_harder.patch -Patch1: udisks-2.11.0-targetcli_config.json_netif_timeout.patch -Patch2: udisks-2.11.0-udiskslinuxmanager_use_after_free.patch -Patch3: udisks-2.11.0-udiskslinuxblock_survive_missing_fstab.patch -# https://bugzilla.redhat.com/show_bug.cgi?id=2373301 -Patch4: udisks-2.10.91-udiskslinuxfilesystemhelpers_nodev,nosuid.patch BuildRequires: make BuildRequires: glib2-devel >= %{glib2_version} @@ -344,6 +339,9 @@ fi %endif %changelog +* Fri Aug 29 2025 Tomas Bzatek - 2.10.2-1 +- Version 2.10.2 + * Thu Jun 19 2025 Tomas Bzatek - 2.10.1-7 - Harden temporary private mounts (#2373301)