Skip to content

Commit a68a679

Browse files
shailend-ggvisor-bot
authored andcommitted
cgroup2fs: DecRef inodes returned by Lookup for consistency
OrderedChildren.Lookup returns the inode with a ref that the caller is expected to release (normally by handing it to a dentry via Init). Five cgroup2fs call sites that look an inode up for a transient purpose (permission checks, control-file read/write, interface-file removal) never released that ref. This is NOT a bug fix: every inode these sites can return (cgroupInterfaceFile and eventFile, both via kernfs.DynamicBytesFile, and cgroup directories themselves) embeds kernfs.InodeNoopRefCount, so IncRef/DecRef are no-ops and nothing leaks today. The change only makes the ref discipline explicit and correct, so these sites stay safe if a lookup ever returns a genuinely refcounted inode. PiperOrigin-RevId: 975402262
1 parent 80bb741 commit a68a679

3 files changed

Lines changed: 14 additions & 2 deletions

File tree

‎pkg/sentry/fsimpl/cgroup2fs/BUILD‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ go_library(
1414
"cpu.go",
1515
"cpu_mutex.go",
1616
"cpuset.go",
17+
"cpuset_mutex.go",
1718
"event.go",
1819
"filesystem.go",
1920
"memory.go",
@@ -74,3 +75,10 @@ declare_mutex(
7475
package = "cgroup2fs",
7576
prefix = "cpu",
7677
)
78+
79+
declare_mutex(
80+
name = "cpuset_mutex",
81+
out = "cpuset_mutex.go",
82+
package = "cgroup2fs",
83+
prefix = "cpuset",
84+
)

‎pkg/sentry/fsimpl/cgroup2fs/cgroup.go‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -564,6 +564,7 @@ func (c *cgroup) CanCloneInto(ctx context.Context, creds *auth.Credentials, ns *
564564
if err != nil {
565565
return err
566566
}
567+
defer inode.DecRef(ctx)
567568
if err := inode.CheckPermissions(ctx, creds, vfs.MayWrite); err != nil {
568569
return err
569570
}
@@ -682,6 +683,7 @@ func (c *cgroup) removeInterfaceFiles(ctx context.Context, ctrl controller) {
682683
for _, name := range ctrl.interfaceFileNames() {
683684
if inode, err := c.OrderedChildren.Lookup(ctx, name); err == nil {
684685
c.OrderedChildren.Unlink(ctx, name, inode)
686+
inode.DecRef(ctx)
685687
}
686688
}
687689
}
@@ -811,6 +813,7 @@ func (c *cgroup) checkMigrationPermsLocked(ctx context.Context, creds *auth.Cred
811813
if err != nil {
812814
return err
813815
}
816+
defer lcaProcs.DecRef(ctx)
814817
if err := lcaProcs.CheckPermissions(ctx, creds, vfs.MayWrite); err != nil {
815818
return err
816819
}
@@ -1163,6 +1166,7 @@ func (c *cgroup) ReadControl(ctx context.Context, name string) (string, error) {
11631166
if err != nil {
11641167
return "", fmt.Errorf("no such control file")
11651168
}
1169+
defer cfi.DecRef(ctx)
11661170
dbf, ok := cfi.(*cgroupInterfaceFile)
11671171
var data vfs.DynamicBytesSource
11681172
if ok {
@@ -1193,6 +1197,7 @@ func (c *cgroup) WriteControl(ctx context.Context, name string, val string) erro
11931197
if err != nil {
11941198
return fmt.Errorf("no such control file")
11951199
}
1200+
defer cfi.DecRef(ctx)
11961201
dbf, ok := cfi.(*cgroupInterfaceFile)
11971202
if !ok {
11981203
return fmt.Errorf("control file not writable")

‎pkg/sentry/fsimpl/cgroup2fs/cpuset.go‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,6 @@ import (
2525
"gvisor.dev/gvisor/pkg/hostarch"
2626
"gvisor.dev/gvisor/pkg/sentry/kernel"
2727
"gvisor.dev/gvisor/pkg/sentry/vfs"
28-
"gvisor.dev/gvisor/pkg/sync"
2928
"gvisor.dev/gvisor/pkg/usermem"
3029
)
3130

@@ -35,7 +34,7 @@ type cpuset struct {
3534
parent *cpuset
3635
detached atomicbitops.Bool
3736

38-
mu sync.Mutex `state:"nosave"`
37+
mu cpusetMutex `state:"nosave"`
3938

4039
cpus *bitmap.Bitmap
4140
mems *bitmap.Bitmap

0 commit comments

Comments
 (0)