Skip to content
Snippets Groups Projects
Commit 4d91d2ab authored by Roberto Bergantinos Corpas's avatar Roberto Bergantinos Corpas Committed by Ben Hutchings
Browse files

sunrpc: expiry_time should be seconds not timeval


commit 3d96208c upstream.

When upcalling gssproxy, cache_head.expiry_time is set as a
timeval, not seconds since boot. As such, RPC cache expiry
logic will not clean expired objects created under
auth.rpcsec.context cache.

This has proven to cause kernel memory leaks on field. Using
64 bit variants of getboottime/timespec

Expiration times have worked this way since 2010's c5b29f88 "sunrpc:
use seconds since boot in expiry cache".  The gssproxy code introduced
in 2012 added gss_proxy_save_rsc and introduced the bug.  That's a while
for this to lurk, but it required a bit of an extreme case to make it
obvious.

Signed-off-by: default avatarRoberto Bergantinos Corpas <rbergant@redhat.com>
Fixes: 030d794b "SUNRPC: Use gssproxy upcall for server..."
Tested-By: default avatarFrank Sorenson <sorenson@redhat.com>
Signed-off-by: default avatarJ. Bruce Fields <bfields@redhat.com>
[bwh: Backported to 3.16: Use struct timespec and getboottime()]
Signed-off-by: default avatarBen Hutchings <ben@decadent.org.uk>
parent 888865cf
No related merge requests found
......@@ -1171,6 +1171,7 @@ static int gss_proxy_save_rsc(struct cache_detail *cd,
dprintk("RPC: No creds found!\n");
goto out;
} else {
struct timespec boot;
/* steal creds */
rsci.cred = ud->creds;
......@@ -1191,6 +1192,9 @@ static int gss_proxy_save_rsc(struct cache_detail *cd,
&expiry, GFP_KERNEL);
if (status)
goto out;
getboottime(&boot);
expiry -= boot.tv_sec;
}
rsci.h.expiry_time = expiry;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment